[Sun Aug 30 03:03:55.681464 2026] [lsapi:notice] [pid 19964:tid 19964] mod_lsapi: version 1.1-92
[Sun Aug 30 03:03:55.691601 2026] [:notice] [pid 488260:tid 488260] [host root@gator3166.hostgator.com] mod_lsapi: Selfstarter 488260 started
[Sun Aug 30 03:03:55.707103 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: bcwinetrends.lastchanceland.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.725354 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-e96ecb83.ibraccountant.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.749708 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: caseyrobin.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.756222 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: socalhomessouthbay.amazingfindings.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.757457 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: sbbchomes.amazingfindings.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.758462 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: etax4u.amazingfindings.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.759489 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: casouthbayhomes.amazingfindings.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.765749 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: papeles.liff.smokinmoesbbqpty.space:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.767895 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: coloradospringsalarm.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.768912 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: smithandsonspainting.bozackclothing.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.769858 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: jasonsatterlund.registerencio.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.772962 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: lodestarpress.net.freshwritingbusinessproducts.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.773949 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: lacityhomes.amazingfindings.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.782890 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-617ef6dc.coloradospringsalarm.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.787071 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: foursevenplay.it:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.800732 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-b04d68ff.coloradospringsalarm.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.801709 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-3fa105b0.coloradospringsalarm.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.808003 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: rainfallmaintenance.spasbydesign.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.808926 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: spasbydesign.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.818802 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: breatheintent.registerencio.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.820139 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: bigpuddlefilms.registerencio.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.821247 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: artistainvertido.registerencio.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.823618 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: abracadabraproducoes.registerencio.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.824611 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: artistsallianceagency.registerencio.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.825625 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: upstreamvideoproduction.registerencio.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.826426 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: rjcorcoransportsinc.rjcorcoransportsinccom.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.908714 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: southbaylifestylehomes.amazingfindings.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.919166 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: hgbf.howardgbuffettfoundation.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.920109 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: globalwaterinitiative.howardgbuffettfoundation.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.925072 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-ee43c7e0.coloradospringsalarm.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.926242 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-dad7e700.coloradospringsalarm.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.927219 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-a7a1cc58.coloradospringsalarm.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.928192 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-6f0b5f02.coloradospringsalarm.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.930746 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-5b374232.coloradospringsalarm.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.932090 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-5a9b575a.coloradospringsalarm.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.932992 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-552ace43.coloradospringsalarm.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.934066 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-27590e58.coloradospringsalarm.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.935186 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-1d00d997.coloradospringsalarm.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.936066 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-1a992a04.coloradospringsalarm.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.944764 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: larb.greglouisonline.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.945743 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: praestitus.com.greglouisonline.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.946694 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: healthyadvices.greglouisonline.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.947726 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: therichemployed.greglouisonline.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.950899 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: healthquotemall.com.greglouisonline.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.951790 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: healthquotehq.co.uk.greglouisonline.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.952847 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: approvedhealthquote.greglouisonline.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.953848 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: tolefefoundation.org.greglouisonline.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.954772 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: easyflightrefunds.com.greglouisonline.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.955844 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: getlifeinsuranceuk.com.greglouisonline.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.956753 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: eclataccountancy.co.uk.greglouisonline.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.957673 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: needlifeinsuranceuk.com.greglouisonline.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.958778 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: top15healthinsurance.com.greglouisonline.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.959865 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: needhealthinsuranceuk.com.greglouisonline.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.961989 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: marjyandandy.andrewmar.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.971008 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: example.ibraccountant.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.972148 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: ibrgroup.ibraccountant.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.973281 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: uaeweb3.ae.ibraccountant.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:55.974210 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-770d4ac7.ibraccountant.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.003788 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: barbershopfilms.ca:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.021977 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: greglouisonline.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.022914 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: andrewmar.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.024912 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: ibraccountant.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.026090 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: freerus.greglouisonline.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.062329 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: mikesmithcreative.bozackclothing.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.068088 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: hiagtourism.kmhawaiiconnections.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.088040 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: oiclimited.eu.foursevenplay.it:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.089161 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: oltreicolori.it.foursevenplay.it:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.090250 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: oltreicolori.club.foursevenplay.it:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.133725 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: kismetrecordsstl.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.211397 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: rollerdoorsltd.rollerdoors.co.uk:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.217586 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: jsotolaw.com.smokinmoesbbqpty.space:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.219002 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: powells-e-graphics.com.smokinmoesbbqpty.space:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.220264 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: condominiocostaestados.com.smokinmoesbbqpty.space:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.226262 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: hongtex.aspire-ltd.net:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.227269 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: apex-textile.aspire-ltd.net:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.228251 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: eastboardindustry.aspire-ltd.net:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.230494 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: ballyyahoo.gracejolliffe.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.238847 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: gracelikestogarden.gracejolliffe.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.242000 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: impend.decielockers.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.299794 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: jdmpruning.rice-think.net:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.309665 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: freedomistrump.esptoday.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.310855 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: americancooler.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.312801 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: esptoday.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.375451 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: nwport.rice-think.net:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.379323 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: seanmrice.rice-think.net:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.382677 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: igfnw.com.rice-think.net:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.386952 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: tpd1250.org.rice-think.net:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.387892 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: alyssa-sean.rice-think.net:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.389866 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: shartshields.rice-think.net:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.390753 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: dailynewsword.rice-think.net:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.392762 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: writeworlds.com.rice-think.net:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.394691 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: jcpersonalised.com.rice-think.net:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.395595 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: shop.blastmerch.co.uk.rice-think.net:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.396742 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: jcaccessorieseire.com.rice-think.net:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.397727 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: games.programmerscache.com.rice-think.net:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.402476 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: healthyfinancially.esptoday.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.402827 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: datingwithtoys.com.esptoday.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.411772 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: lucxdel.delacruzimporting.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.412710 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: ezepillow.delacruzimporting.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.413537 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: jazzdreamz.delacruzimporting.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.414872 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: juuvana.com.delacruzimporting.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.415994 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: chicandraw.com.delacruzimporting.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.422619 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: thenumberonellc.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.440679 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: jennaleonardo.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.450664 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: terminusmedia.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.451515 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: rgw.wri.temporary.site:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.467244 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: 3226online.thirtytwotwentysix.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.469221 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: auctionragstoriches.com.loverummy.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.473730 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: hackneytreeservice.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.474671 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: advancingblackentrepreneurship.calvarycrossag.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.480494 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: blackfounderssummit.calvarycrossag.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.482829 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: loverummy.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.483987 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: ed-tech.com.my.my-velan.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.486870 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: ecofreight.my-velan.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.488233 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-ef3e8af8.loverummy.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.490290 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-c4126b26.loverummy.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.491364 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: primepokersites.loverummy.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.496533 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: love-texas-holdem.loverummy.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.498615 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: larkhallthistle.loverummy.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.499523 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: larkhall.loverummy.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.502489 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: maidtoglisten.calvarycrossag.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.506302 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: africadayfestival.calvarycrossag.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.507333 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: paradigmmar.calvarycrossag.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.508641 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: michaelblakeshoes.calvarycrossag.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.509753 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: eessel.calvarycrossag.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.510750 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: hebrews111.calvarycrossag.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.513936 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: michaelblakemenswear.calvarycrossag.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.514909 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: 1stsourcesecurity.calvarycrossag.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.633577 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: itagpros.com.topsourcemediaserver1.info:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.634562 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: ecolights.net.topsourcemediaserver1.info:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.635422 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: zappifybug.com.topsourcemediaserver1.info:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.636458 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: organnacbd.net.topsourcemediaserver1.info:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.637331 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: memorywave.org.topsourcemediaserver1.info:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.638240 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: ciaohealth.net.topsourcemediaserver1.info:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.639041 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: primeboosts.com.topsourcemediaserver1.info:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.639951 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: flixytvstick.net.topsourcemediaserver1.info:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.640828 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: bloodvitalss.com.topsourcemediaserver1.info:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.641852 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: 5stepformula.net.topsourcemediaserver1.info:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.642671 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: vitasealblood.com.topsourcemediaserver1.info:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.643533 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: titanrisemale.com.topsourcemediaserver1.info:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.644582 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: kickstartketos.com.topsourcemediaserver1.info:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.645485 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: zapzonedefender.net.topsourcemediaserver1.info:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.646390 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: herzp1smartring.org.topsourcemediaserver1.info:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.647332 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: circupulseblood.com.topsourcemediaserver1.info:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.648251 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: blissharmonycbd.net.topsourcemediaserver1.info:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.649120 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: healthyflowblood.com.topsourcemediaserver1.info:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.650097 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: vitalmuscleboosts.com.topsourcemediaserver1.info:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.651122 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: alphabraingummies.com.topsourcemediaserver1.info:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.651988 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: globalhealthfarmscbd.net.topsourcemediaserver1.info:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.652851 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: woodrangerpowershears.net.topsourcemediaserver1.info:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.653844 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: naturesboostcbdgummies.net.topsourcemediaserver1.info:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.654755 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: highlinewellnesscbdgummies.org.topsourcemediaserver1.info:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.655620 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: lntlog.com.my-velan.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.656545 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: capitalmari.com.my-velan.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.657502 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: unitedaxis.com.my.my-velan.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.658344 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: surayachong.com.my.my-velan.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.659386 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: snc-logistics.com.my.my-velan.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.663435 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: thermographydfw.dallasfortworthbreastthermography.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.664364 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: dfwthermography.dallasfortworthbreastthermography.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.669901 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: bac2myrootz.calvarycrossag.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.670876 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: 1899project.calvarycrossag.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.673686 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: esselwebdesign.calvarycrossag.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.674664 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-fb8819da.calvarycrossag.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.675938 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-e81de80f.calvarycrossag.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.679957 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-d65f6ff6.calvarycrossag.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.682746 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-b8895de8.calvarycrossag.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.683789 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-9f467860.calvarycrossag.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.690311 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-9467b61f.calvarycrossag.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.693660 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-5a07ed6f.calvarycrossag.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.694876 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-4a23e6e0.calvarycrossag.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.695948 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-470845a4.calvarycrossag.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.697158 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-3a0b084e.calvarycrossag.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.698106 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: memariestyle.com.calvarycrossag.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.699080 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: inspirewithangela.calvarycrossag.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.699967 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: healthonthemenu.com.calvarycrossag.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.708546 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: btallinonesecurity.com.calvarycrossag.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.751988 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: topsourcemediaserver1.info:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.754040 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: my-velan.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.759344 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: calvarycrossag.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.772551 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: wristba.betacommands.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.773463 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: wristbandnow.betacommands.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.780173 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: africamachineryforsale.ezbulbz.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.805509 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: eseperu.com.transmarcargo.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.856556 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-5d56a537.jessicakwilcox.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.858808 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: samssweetdelicacies.jessicakwilcox.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.863131 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: b2c-egypt.pixelbracket.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.873483 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: hillaryboucher.oneconsciousbirth.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.874542 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: freeourmidwives.oneconsciousbirth.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.875536 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: infinitelearners.oneconsciousbirth.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.876639 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: rdandie.triathlonlistings.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.877707 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: duathlon.triathlonlistings.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.879594 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: duathlonnet.triathlonlistings.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.880597 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: duathlon123.triathlonlistings.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.881688 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: handoftheday.triathlonlistings.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.882700 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: enduranceone.triathlonlistings.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.885918 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: triathletetraining.triathlonlistings.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.887054 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: duathlontrainingplan.triathlonlistings.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.894000 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: galitrans.transmarcargo.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.895231 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: atumesa.pe.transmarcargo.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.896314 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: servifabrickvhr.transmarcargo.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.903580 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: autoinsurancefor.247localdentist.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.904684 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: drug-alcoholhelpline.247localdentist.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.932026 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: jessicakwilcox.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.953624 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: brainstone.oneconsciousbirth.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.997120 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: officesoftwares.pdfcube.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:56.999096 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: speakthylanguage.pdfcube.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.010191 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: inspiringspeakers.online.inspiringspeakers.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.073629 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: lodestar.freshwritingbusinessproducts.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.074572 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: lenoreashwood.freshwritingbusinessproducts.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.075533 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: lodestar-media.freshwritingbusinessproducts.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.076453 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: cavendish-club.freshwritingbusinessproducts.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.078495 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: nalahenkelaislinn.freshwritingbusinessproducts.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.079612 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: lodestar-press.com.freshwritingbusinessproducts.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.080599 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: lodestarcollaboration.freshwritingbusinessproducts.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.135879 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: fasteasyloans.freearticlespot.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.137035 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: financinglaptops.freearticlespot.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.138030 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: designerplussize.freearticlespot.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.138925 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: stayandsurftofino.freefloventilation.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.139853 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: freeflohomeservices.freefloventilation.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.153598 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: athena.hohstudio.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.154602 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: djsevenevents.hohstudio.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.161171 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: southerncruzinmobility.cowboyhunny.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.186784 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: thefranklinnews.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.221225 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: hohstudio.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.237901 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: adscitys.net:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.250407 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: tgifa.kcelcorp.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.254384 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-66ba085f.homaale.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.261529 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: delicart.ict4u.co.mz:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.262559 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: ictinnovations.ict4u.co.mz:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.273357 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: url5.webentwickler-club.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.274367 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: pctipps.webentwickler-club.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.275305 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: thorbytes.webentwickler-club.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.276256 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: thorbytes4.webentwickler-club.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.277177 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: thorbytes3.webentwickler-club.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.278108 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: thorbytes2.webentwickler-club.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.278998 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: thjrichter.webentwickler-club.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.281780 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: thomas-joachim-richter.webentwickler-club.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.294454 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: ltr7.letter7brands.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.296310 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: geoffledet.letter7brands.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.303804 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: cagtu.com.homaale.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.304818 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: cagtu.com.au.homaale.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.305824 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-f9916fb9.homaale.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.306835 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-f6904aa5.homaale.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.307822 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-d55a4e2f.homaale.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.308824 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-d21427e8.homaale.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.309787 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-b1b40c0d.homaale.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.310789 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-aea7c2ba.homaale.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.311808 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-46454872.homaale.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.312797 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-2e7a772f.homaale.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.313782 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-188c578f.homaale.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.314688 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-182573aa.homaale.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.315657 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-143cf3a7.homaale.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.316721 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-052ceb17.homaale.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.319940 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: kazuna.fremantlewa.com.au:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.321233 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: cravegoldcoast.fremantlewa.com.au:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.322364 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: arcexploration.fremantlewa.com.au:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.323503 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-e09f0064.fremantlewa.com.au:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.324616 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-b900700e.fremantlewa.com.au:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.325718 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-b3f91c55.fremantlewa.com.au:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.326768 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-7d429e8a.fremantlewa.com.au:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.327947 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: website-59e81578.fremantlewa.com.au:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.329099 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: flatironmelbourne.fremantlewa.com.au:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.330402 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: catherinevalewines.fremantlewa.com.au:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.332359 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: benchcreative.com.au.fremantlewa.com.au:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.333759 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: thedevonshireteaguide.fremantlewa.com.au:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.338104 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: iamthevoiceofonecallinginthewilderness.daviddellit.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.341106 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: napatrapa.com.kcelcorp.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.342082 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: weareconnected.kcelcorp.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.359509 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: letter7brands.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.364554 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: homaale.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.386509 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: kcelcorp.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.390834 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: apexpreciousmetals.iragoldreview.com:443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.395558 2026] [ssl:warn] [pid 19964:tid 19964] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name
[Sun Aug 30 03:03:57.412891 2026] [qos:notice] [pid 19964:tid 19964] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients)
[Sun Aug 30 03:03:57.682850 2026] [http2:info] [pid 19964:tid 19964] AH03090: mod_http2 (v2.0.42, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.70.0), initializing...
[Sun Aug 30 03:03:57.687931 2026] [mpm_event:notice] [pid 19964:tid 19964] AH00489: Apache/2.4.68 (cPanel) OpenSSL/3.5.5 Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 mod_rbld2.0 configured -- resuming normal operations
[Sun Aug 30 03:03:57.687945 2026] [core:notice] [pid 19964:tid 19964] AH00094: Command line: '/usr/sbin/httpd'
[Sun Aug 30 03:03:58.741719 2026] [http2:info] [pid 488281:tid 488281] h2_workers: created with min=128 max=192 idle_ms=600000
[Sun Aug 30 03:03:58.765141 2026] [security2:error] [pid 488281:tid 488416] [client 20.48.251.3:59110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/error_log.php"] [unique_id "apPj7jIT5HeNE73zNfp9XAAAAIo"]
[Sun Aug 30 03:03:58.765155 2026] [security2:error] [pid 488281:tid 488414] [client 20.104.50.220:56714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-content/pluginswp-freeform/black2llleaf.php"] [unique_id "apPj7jIT5HeNE73zNfp9WgAAAIg"]
[Sun Aug 30 03:03:58.765189 2026] [security2:error] [pid 488281:tid 488418] [client 68.155.159.216:54727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/makeasmtp.php"] [unique_id "apPj7jIT5HeNE73zNfp9XwAAAIw"]
[Sun Aug 30 03:03:58.765216 2026] [security2:error] [pid 488281:tid 488437] [client 20.48.251.3:29997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lastmaskcenter.org"] [uri "/pass4.php"] [unique_id "apPj7jIT5HeNE73zNfp9ZwAAAJ8"]
[Sun Aug 30 03:03:58.765237 2026] [security2:error] [pid 488281:tid 488436] [client 20.104.18.15:31590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/simple.php"] [unique_id "apPj7jIT5HeNE73zNfp9ZgAAAJ4"]
[Sun Aug 30 03:03:58.765332 2026] [security2:error] [pid 488281:tid 488413] [client 20.104.50.220:62004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/aku.php"] [unique_id "apPj7jIT5HeNE73zNfp9WwAAAIc"]
[Sun Aug 30 03:03:58.765453 2026] [security2:error] [pid 488281:tid 488415] [client 20.48.251.3:55466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/guk.php"] [unique_id "apPj7jIT5HeNE73zNfp9XQAAAIk"]
[Sun Aug 30 03:03:58.765498 2026] [security2:error] [pid 488281:tid 488417] [client 68.155.159.216:59331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-includes/css/index.php"] [unique_id "apPj7jIT5HeNE73zNfp9XgAAAIs"]
[Sun Aug 30 03:03:58.765560 2026] [security2:error] [pid 488281:tid 488412] [client 20.104.50.220:62832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/edit-video.php"] [unique_id "apPj7jIT5HeNE73zNfp9WAAAAIY"]
[Sun Aug 30 03:03:58.765591 2026] [security2:error] [pid 488281:tid 488433] [client 20.104.50.220:29848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/Store.php"] [unique_id "apPj7jIT5HeNE73zNfp9YwAAAJs"]
[Sun Aug 30 03:03:58.765661 2026] [security2:error] [pid 488281:tid 488435] [client 20.104.49.130:57626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/media.php"] [unique_id "apPj7jIT5HeNE73zNfp9ZQAAAJ0"]
[Sun Aug 30 03:03:58.765670 2026] [security2:error] [pid 488281:tid 488432] [client 20.104.50.220:33591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/webshell.php"] [unique_id "apPj7jIT5HeNE73zNfp9YgAAAJo"]
[Sun Aug 30 03:03:58.765690 2026] [security2:error] [pid 488281:tid 488434] [client 20.220.10.235:47034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.centrofruttadue.it"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPj7jIT5HeNE73zNfp9ZAAAAJw"]
[Sun Aug 30 03:03:58.765856 2026] [security2:error] [pid 488281:tid 488449] [client 20.104.50.220:5928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/htaccess.php"] [unique_id "apPj7jIT5HeNE73zNfp9aQAAAKs"]
[Sun Aug 30 03:03:58.766554 2026] [security2:error] [pid 488281:tid 488469] [client 20.104.50.220:31934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/gel4y.php"] [unique_id "apPj7jIT5HeNE73zNfp9agAAAL8"]
[Sun Aug 30 03:03:58.767018 2026] [security2:error] [pid 488281:tid 488453] [client 20.104.49.130:36606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.topatrust.com"] [uri "/init.php"] [unique_id "apPj7jIT5HeNE73zNfp9awAAAK8"]
[Sun Aug 30 03:03:58.767544 2026] [security2:error] [pid 488281:tid 488452] [client 20.104.18.15:9176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/beck.php"] [unique_id "apPj7jIT5HeNE73zNfp9bAAAAK4"]
[Sun Aug 30 03:03:58.768834 2026] [security2:error] [pid 488281:tid 488463] [client 20.48.251.3:64263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/wp-config.backup.php"] [unique_id "apPj7jIT5HeNE73zNfp9bgAAALk"]
[Sun Aug 30 03:03:58.769466 2026] [security2:error] [pid 488281:tid 488464] [client 20.104.50.220:62819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/s.php"] [unique_id "apPj7jIT5HeNE73zNfp9bwAAALo"]
[Sun Aug 30 03:03:58.769822 2026] [security2:error] [pid 488281:tid 488466] [client 20.104.49.130:51560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trinitytechnologics.com"] [uri "/amax.php"] [unique_id "apPj7jIT5HeNE73zNfp9cAAAALw"]
[Sun Aug 30 03:03:58.771269 2026] [security2:error] [pid 488281:tid 488476] [client 20.48.251.3:55695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/8.php"] [unique_id "apPj7jIT5HeNE73zNfp9cgAAAMY"]
[Sun Aug 30 03:03:58.772635 2026] [security2:error] [pid 488281:tid 488485] [client 20.104.50.220:46171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-content/uploads/simple-file-list/fw.php"] [unique_id "apPj7jIT5HeNE73zNfp9dAAAAM8"]
[Sun Aug 30 03:03:58.772715 2026] [security2:error] [pid 488281:tid 488486] [client 20.48.251.3:44185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/erty.php"] [unique_id "apPj7jIT5HeNE73zNfp9dQAAANA"]
[Sun Aug 30 03:03:58.775908 2026] [security2:error] [pid 488281:tid 488504] [client 20.48.251.3:7392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/sadd.php"] [unique_id "apPj7jIT5HeNE73zNfp9ewAAAOI"]
[Sun Aug 30 03:03:58.776157 2026] [security2:error] [pid 488281:tid 488450] [client 20.151.200.44:47074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/txets.php"] [unique_id "apPj7jIT5HeNE73zNfp9fAAAAKw"]
[Sun Aug 30 03:03:58.777322 2026] [security2:error] [pid 488281:tid 488512] [client 20.104.18.15:3914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1800rlawyer.com"] [uri "/wp-load.php"] [unique_id "apPj7jIT5HeNE73zNfp9gAAAAOo"]
[Sun Aug 30 03:03:58.778141 2026] [security2:error] [pid 488281:tid 488451] [client 158.23.147.79:55210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPj7jIT5HeNE73zNfp9gwAAAK0"]
[Sun Aug 30 03:03:58.778447 2026] [security2:error] [pid 488281:tid 488431] [client 20.63.81.20:55439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/wp-login.php"] [unique_id "apPj7jIT5HeNE73zNfp9YQAAAJk"]
[Sun Aug 30 03:03:58.778743 2026] [security2:error] [pid 488281:tid 488520] [client 20.104.49.130:43137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wondertanks.com"] [uri "/bolt.php"] [unique_id "apPj7jIT5HeNE73zNfp9hQAAAPI"]
[Sun Aug 30 03:03:58.781844 2026] [security2:error] [pid 488281:tid 488536] [client 20.48.251.3:7082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/fns.php"] [unique_id "apPj7jIT5HeNE73zNfp9jAAAAQI"]
[Sun Aug 30 03:03:58.783815 2026] [security2:error] [pid 488281:tid 488472] [client 20.104.49.130:58098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/wsd.php"] [unique_id "apPj7jIT5HeNE73zNfp9jgAAAMI"]
[Sun Aug 30 03:03:58.785936 2026] [authz_core:error] [pid 488281:tid 488430] [client 216.73.216.128:19695] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:03:58.785946 2026] [authz_core:error] [pid 488281:tid 488411] [client 216.73.216.128:56935] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:03:58.786393 2026] [authz_core:error] [pid 488281:tid 488411] [client 216.73.216.128:56935] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:03:58.786393 2026] [authz_core:error] [pid 488281:tid 488430] [client 216.73.216.128:19695] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:03:58.793054 2026] [security2:error] [pid 488281:tid 488454] [client 20.104.18.15:3847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lakewoodshuttle.deevosdesigns.com"] [uri "/wefile.php"] [unique_id "apPj7jIT5HeNE73zNfp9igAAALA"]
[Sun Aug 30 03:03:58.793217 2026] [security2:error] [pid 488281:tid 488528] [client 20.104.49.130:43798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.katbacon.com"] [uri "/echkm.php"] [unique_id "apPj7jIT5HeNE73zNfp9iQAAAPo"]
[Sun Aug 30 03:03:58.793628 2026] [authz_core:error] [pid 488281:tid 488484] [client 216.73.216.128:51358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:03:58.793998 2026] [authz_core:error] [pid 488281:tid 488432] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:03:58.794077 2026] [authz_core:error] [pid 488281:tid 488484] [client 216.73.216.128:51358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:03:58.794395 2026] [authz_core:error] [pid 488281:tid 488432] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:03:58.832243 2026] [authz_core:error] [pid 488281:tid 488420] [client 66.249.66.71:46339] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:03:58.832732 2026] [authz_core:error] [pid 488281:tid 488420] [client 66.249.66.71:46339] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:03:58.835590 2026] [security2:error] [pid 488281:tid 488426] [client 52.139.37.240:15046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/wp-admin/maint/index.php"] [unique_id "apPj7jIT5HeNE73zNfp9vgAAAJQ"]
[Sun Aug 30 03:03:58.842601 2026] [authz_core:error] [pid 488281:tid 488529] [client 66.249.66.67:46675] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:03:58.843394 2026] [authz_core:error] [pid 488281:tid 488529] [client 66.249.66.67:46675] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:03:58.852035 2026] [authz_core:error] [pid 488281:tid 488513] [client 66.249.66.32:36704] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:03:58.852636 2026] [authz_core:error] [pid 488281:tid 488513] [client 66.249.66.32:36704] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:03:58.901275 2026] [security2:error] [pid 488281:tid 488439] [client 195.178.110.247:44636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ltr7.com"] [uri "/index.php"] [unique_id "apPj7jIT5HeNE73zNfp9xwAAAKE"]
[Sun Aug 30 03:03:58.918016 2026] [security2:error] [pid 488281:tid 488413] [client 158.23.147.79:55077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPj7jIT5HeNE73zNfp9yQAAAIc"]
[Sun Aug 30 03:03:58.920427 2026] [security2:error] [pid 488281:tid 488413] [client 20.63.81.20:55520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/images.php"] [unique_id "apPj7jIT5HeNE73zNfp9ygAAAIc"]
[Sun Aug 30 03:03:58.955523 2026] [security2:error] [pid 488281:tid 488449] [client 49.13.164.148:42706] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "benchcreative.com.au"] [uri "/wp-content/endurance-page-cache/_index.html"] [unique_id "apPj7jIT5HeNE73zNfp9zQAAAKs"], referer: https://benchcreative.com.au/
[Sun Aug 30 03:03:58.978019 2026] [security2:error] [pid 488281:tid 488453] [client 74.7.241.147:34958] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.enterden.den-enterprises.com"] [uri "/index.php"] [unique_id "apPj7jIT5HeNE73zNfp9vwAAryc"]
[Sun Aug 30 03:03:58.989120 2026] [security2:error] [pid 488281:tid 488326] [remote 50.87.179.84:28972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.179.87.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "americanqualityhomeinspections.com"] [uri "/wp-login.php"] [unique_id "apPj7jIT5HeNE73zNfp91AAAwSw"]
[Sun Aug 30 03:03:59.023869 2026] [security2:error] [pid 488281:tid 488532] [client 34.131.221.169:33186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/dev/phpinfo.php"] [unique_id "apPj7zIT5HeNE73zNfp92wAAAP4"]
[Sun Aug 30 03:03:59.026933 2026] [security2:error] [pid 488281:tid 488458] [client 52.139.37.240:15094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/wp-content/uploads/min.php"] [unique_id "apPj7zIT5HeNE73zNfp93AAAALQ"]
[Sun Aug 30 03:03:59.030449 2026] [security2:error] [pid 488281:tid 488446] [client 34.131.221.169:33200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/admin/phpinfo.php"] [unique_id "apPj7zIT5HeNE73zNfp93gAAAKg"]
[Sun Aug 30 03:03:59.068180 2026] [security2:error] [pid 488281:tid 488439] [client 195.178.110.247:23706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ltr7.com"] [uri "/index.php"] [unique_id "apPj7zIT5HeNE73zNfp94AAAAKE"]
[Sun Aug 30 03:03:59.126103 2026] [security2:error] [pid 488281:tid 488425] [client 178.159.37.16:50023] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "geotravel.am"] [uri "/wp-comments-post.php"] [unique_id "apPj7zIT5HeNE73zNfp94gAAAJM"], referer: https://geotravel.am/discover-armenias-hidden-gems-tufenkian-avan-marak-tsapatagh-hotel/comment-page-269968/
[Sun Aug 30 03:03:59.165042 2026] [security2:error] [pid 488281:tid 488516] [client 20.63.81.20:55449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/ops.php"] [unique_id "apPj7zIT5HeNE73zNfp94wAAAO4"]
[Sun Aug 30 03:03:59.264125 2026] [security2:error] [pid 488281:tid 488329] [remote 103.28.36.106:60500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "recoverymarine.com"] [uri "/wp-login.php"] [unique_id "apPj7zIT5HeNE73zNfp95wAAsi8"]
[Sun Aug 30 03:03:59.323149 2026] [security2:error] [pid 488281:tid 488467] [client 20.63.81.20:55499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPj7zIT5HeNE73zNfp97AAAAL0"]
[Sun Aug 30 03:03:59.326318 2026] [security2:error] [pid 488281:tid 488496] [client 52.139.37.240:15069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/zoom1.php"] [unique_id "apPj7zIT5HeNE73zNfp97gAAANo"]
[Sun Aug 30 03:03:59.413014 2026] [security2:error] [pid 488281:tid 488485] [client 20.104.49.130:30046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wondertanks.com"] [uri "/cilus.php"] [unique_id "apPj7zIT5HeNE73zNfp99wAAAM8"]
[Sun Aug 30 03:03:59.487624 2026] [security2:error] [pid 488281:tid 488484] [client 20.63.81.20:55467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPj7zIT5HeNE73zNfp9_QAAAM4"]
[Sun Aug 30 03:03:59.490041 2026] [security2:error] [pid 488281:tid 488495] [client 20.104.49.130:48373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trinitytechnologics.com"] [uri "/init.php"] [unique_id "apPj7zIT5HeNE73zNfp9_gAAANk"]
[Sun Aug 30 03:03:59.512977 2026] [authz_core:error] [pid 488281:tid 488506] [client 66.249.66.193:55983] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:03:59.513471 2026] [authz_core:error] [pid 488281:tid 488506] [client 66.249.66.193:55983] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:03:59.566930 2026] [security2:error] [pid 488281:tid 488515] [client 52.139.37.240:14393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/lock360.php"] [unique_id "apPj7zIT5HeNE73zNfp-CAAAAO0"]
[Sun Aug 30 03:03:59.574580 2026] [authz_core:error] [pid 488281:tid 488455] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:03:59.575039 2026] [authz_core:error] [pid 488281:tid 488455] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:03:59.674193 2026] [security2:error] [pid 488281:tid 488451] [client 20.63.81.20:55534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/about.php"] [unique_id "apPj7zIT5HeNE73zNfp-DgAAAK0"]
[Sun Aug 30 03:03:59.674222 2026] [security2:error] [pid 488281:tid 488489] [client 195.178.110.247:64264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/index.php"] [unique_id "apPj7zIT5HeNE73zNfp-DwAAANM"]
[Sun Aug 30 03:03:59.771414 2026] [security2:error] [pid 488281:tid 488517] [client 34.131.221.169:33226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/test/phpinfo.php"] [unique_id "apPj7zIT5HeNE73zNfp-GAAAAO8"]
[Sun Aug 30 03:03:59.776704 2026] [http2:info] [pid 488669:tid 488669] h2_workers: created with min=128 max=192 idle_ms=600000
[Sun Aug 30 03:03:59.790767 2026] [security2:error] [pid 488281:tid 488335] [remote 50.87.179.84:28984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.179.87.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "americanqualityhomeinspections.com"] [uri "/wp-login.php"] [unique_id "apPj7zIT5HeNE73zNfp-FgAA-TU"], referer: https://americanqualityhomeinspections.com/wp-login.php
[Sun Aug 30 03:03:59.803110 2026] [security2:error] [pid 488281:tid 488519] [client 34.131.221.169:33212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/old/phpinfo.php"] [unique_id "apPj7zIT5HeNE73zNfp-GgAAAPE"]
[Sun Aug 30 03:03:59.827470 2026] [security2:error] [pid 488281:tid 488517] [client 20.63.81.20:55365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/admin.php/admin.php"] [unique_id "apPj7zIT5HeNE73zNfp-GwAAAO8"]
[Sun Aug 30 03:03:59.859839 2026] [security2:error] [pid 488281:tid 488449] [client 195.178.110.247:34568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/index.php"] [unique_id "apPj7zIT5HeNE73zNfp-HwAAAKs"]
[Sun Aug 30 03:03:59.872918 2026] [security2:error] [pid 488669:tid 488809] [client 52.139.37.240:15083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/r.php"] [unique_id "apPj79Rh6OewFvqQpDk1lAAAAQw"]
[Sun Aug 30 03:03:59.872943 2026] [authz_core:error] [pid 488669:tid 488813] [client 66.249.66.194:51364] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:03:59.873388 2026] [authz_core:error] [pid 488669:tid 488813] [client 66.249.66.194:51364] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:03:59.896395 2026] [security2:error] [pid 488669:tid 488906] [client 20.48.251.3:29731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lastmaskcenter.org"] [uri "/cu.php"] [unique_id "apPj79Rh6OewFvqQpDk1lwAAAW0"]
[Sun Aug 30 03:03:59.900117 2026] [security2:error] [pid 488669:tid 488873] [client 68.155.159.216:52805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/cgi-bin/wp-login.php"] [unique_id "apPj79Rh6OewFvqQpDk1lQAAAUw"]
[Sun Aug 30 03:03:59.901091 2026] [security2:error] [pid 488669:tid 488855] [client 20.104.50.220:6121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/readme.php"] [unique_id "apPj79Rh6OewFvqQpDk1mQAAATo"]
[Sun Aug 30 03:03:59.905475 2026] [security2:error] [pid 488669:tid 488855] [client 20.104.50.220:30274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/Pdo.php"] [unique_id "apPj79Rh6OewFvqQpDk1nAAAATo"]
[Sun Aug 30 03:03:59.908985 2026] [security2:error] [pid 488669:tid 488846] [client 68.155.159.216:52720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apPj79Rh6OewFvqQpDk1nQAAATE"]
[Sun Aug 30 03:03:59.911811 2026] [security2:error] [pid 488281:tid 488484] [client 20.48.251.3:51526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/phina.php"] [unique_id "apPj7zIT5HeNE73zNfp-JAAAAM4"]
[Sun Aug 30 03:03:59.911822 2026] [security2:error] [pid 488669:tid 488924] [client 20.104.18.15:3778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1800rlawyer.com"] [uri "/robot.php"] [unique_id "apPj79Rh6OewFvqQpDk1nwAAAX8"]
[Sun Aug 30 03:03:59.911921 2026] [security2:error] [pid 488669:tid 488819] [client 20.104.18.15:9102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/t3.php"] [unique_id "apPj79Rh6OewFvqQpDk1ngAAARY"]
[Sun Aug 30 03:03:59.911924 2026] [authz_core:error] [pid 488669:tid 488812] [client 66.249.66.77:57946] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:03:59.912398 2026] [authz_core:error] [pid 488669:tid 488812] [client 66.249.66.77:57946] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:03:59.913003 2026] [security2:error] [pid 488669:tid 488819] [client 20.104.50.220:51598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/meiwei.php"] [unique_id "apPj79Rh6OewFvqQpDk1oAAAARY"]
[Sun Aug 30 03:03:59.916252 2026] [security2:error] [pid 488281:tid 488506] [client 20.48.251.3:54802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/edit.php"] [unique_id "apPj7zIT5HeNE73zNfp-JQAAAOQ"]
[Sun Aug 30 03:03:59.916656 2026] [security2:error] [pid 488281:tid 488460] [client 20.104.50.220:46645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-content/uploads/simple-file-list/alfa.php"] [unique_id "apPj7zIT5HeNE73zNfp-JgAAALY"]
[Sun Aug 30 03:03:59.919842 2026] [security2:error] [pid 488669:tid 488846] [client 20.48.251.3:59357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/thui.php"] [unique_id "apPj79Rh6OewFvqQpDk1oQAAATE"]
[Sun Aug 30 03:03:59.921197 2026] [security2:error] [pid 488669:tid 488839] [client 20.104.18.15:31694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/xty.php"] [unique_id "apPj79Rh6OewFvqQpDk1ogAAASo"]
[Sun Aug 30 03:03:59.928911 2026] [security2:error] [pid 488669:tid 488819] [client 20.104.18.15:3848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lakewoodshuttle.deevosdesigns.com"] [uri "/blog.php"] [unique_id "apPj79Rh6OewFvqQpDk1pAAAARY"]
[Sun Aug 30 03:03:59.929607 2026] [security2:error] [pid 488669:tid 488855] [client 20.48.251.3:23458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/wp-config.backup.php"] [unique_id "apPj79Rh6OewFvqQpDk1owAAATo"]
[Sun Aug 30 03:03:59.936106 2026] [security2:error] [pid 488281:tid 488462] [client 20.104.50.220:61954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/syg.php"] [unique_id "apPj7zIT5HeNE73zNfp-JwAAALg"]
[Sun Aug 30 03:03:59.937457 2026] [security2:error] [pid 488281:tid 488474] [client 20.104.50.220:33082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wso25.php"] [unique_id "apPj7zIT5HeNE73zNfp-KAAAAMQ"]
[Sun Aug 30 03:03:59.939640 2026] [security2:error] [pid 488669:tid 488846] [client 20.48.251.3:6979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/application.config.php"] [unique_id "apPj79Rh6OewFvqQpDk1pgAAATE"]
[Sun Aug 30 03:03:59.951303 2026] [security2:error] [pid 488281:tid 488492] [client 20.104.50.220:31830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/contacts.php"] [unique_id "apPj7zIT5HeNE73zNfp-LAAAANY"]
[Sun Aug 30 03:03:59.956297 2026] [security2:error] [pid 488281:tid 488449] [client 74.7.228.1:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "advanceshredding.com"] [uri "/cgi-sys/404.html"] [unique_id "apPj7zIT5HeNE73zNfp-KwAAAKs"]
[Sun Aug 30 03:03:59.969347 2026] [security2:error] [pid 488281:tid 488449] [client 20.48.251.3:55497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/config_dev.php"] [unique_id "apPj7zIT5HeNE73zNfp-MQAAAKs"]
[Sun Aug 30 03:03:59.970539 2026] [security2:error] [pid 488669:tid 488808] [client 74.7.228.1:57032] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "advanceshredding.com"] [uri "/robots.txt"] [unique_id "apPj79Rh6OewFvqQpDk1hQAAAQs"]
[Sun Aug 30 03:03:59.975341 2026] [security2:error] [pid 488281:tid 488460] [client 20.104.50.220:29581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/.well-known/up.php"] [unique_id "apPj7zIT5HeNE73zNfp-MwAAALY"]
[Sun Aug 30 03:03:59.980906 2026] [security2:error] [pid 488281:tid 488462] [client 20.63.81.20:55434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/media.php"] [unique_id "apPj7zIT5HeNE73zNfp-NAAAALg"]
[Sun Aug 30 03:03:59.982211 2026] [authz_core:error] [pid 488281:tid 488468] [client 216.73.216.128:31956] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:03:59.982761 2026] [authz_core:error] [pid 488281:tid 488468] [client 216.73.216.128:31956] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:00.034171 2026] [security2:error] [pid 488669:tid 488916] [client 20.104.50.220:52858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/t.php"] [unique_id "apPj8NRh6OewFvqQpDk1sQAAAXc"]
[Sun Aug 30 03:04:00.058147 2026] [authz_core:error] [pid 488281:tid 488483] [client 66.249.66.37:43885] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:00.058673 2026] [authz_core:error] [pid 488281:tid 488483] [client 66.249.66.37:43885] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:00.071048 2026] [security2:error] [pid 488669:tid 488855] [client 52.139.37.240:14344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/sf.php"] [unique_id "apPj8NRh6OewFvqQpDk1tgAAATo"]
[Sun Aug 30 03:04:00.077405 2026] [security2:error] [pid 488669:tid 488891] [client 114.119.142.232:33027] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jasonsatterlund.com"] [uri "/the-abandon-movie/"] [unique_id "apPj8NRh6OewFvqQpDk1uAAAAV4"], referer: https://jasonsatterlund.com/the-abandon-movie/
[Sun Aug 30 03:04:00.095188 2026] [authz_core:error] [pid 488281:tid 488534] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fnf_reject_ipv6%2Fholders
[Sun Aug 30 03:04:00.095748 2026] [authz_core:error] [pid 488281:tid 488534] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fnf_reject_ipv6%2Fholders
[Sun Aug 30 03:04:00.113521 2026] [security2:error] [pid 488669:tid 488808] [client 20.63.81.20:55446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/mac.php"] [unique_id "apPj8NRh6OewFvqQpDk1vQAAAQs"]
[Sun Aug 30 03:04:00.116756 2026] [security2:error] [pid 488669:tid 488920] [client 20.104.49.130:51535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trinitytechnologics.com"] [uri "/wen.php"] [unique_id "apPj8NRh6OewFvqQpDk1vgAAAXs"]
[Sun Aug 30 03:04:00.141305 2026] [security2:error] [pid 488281:tid 488430] [client 74.7.175.144:36172] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "orlandodecoded.com"] [uri "/robots.txt"] [unique_id "apPj8DIT5HeNE73zNfp-RwAAAJg"]
[Sun Aug 30 03:04:00.244087 2026] [security2:error] [pid 488669:tid 488815] [client 20.63.81.20:55517] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.khanwadeabutalib.org"] [uri "/1.php"] [unique_id "apPj8NRh6OewFvqQpDk11QAAARI"]
[Sun Aug 30 03:04:00.244237 2026] [security2:error] [pid 488669:tid 488815] [client 20.63.81.20:55517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/1.php"] [unique_id "apPj8NRh6OewFvqQpDk11QAAARI"]
[Sun Aug 30 03:04:00.267915 2026] [security2:error] [pid 488669:tid 488873] [client 52.139.37.240:15084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/7.php"] [unique_id "apPj8NRh6OewFvqQpDk11wAAAUw"]
[Sun Aug 30 03:04:00.372840 2026] [security2:error] [pid 488281:tid 488528] [client 20.63.81.20:55529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/classwithtostring.php"] [unique_id "apPj8DIT5HeNE73zNfp-dAAAAPo"]
[Sun Aug 30 03:04:00.460526 2026] [security2:error] [pid 488669:tid 488867] [client 52.139.37.240:15092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/b.php"] [unique_id "apPj8NRh6OewFvqQpDk15AAAAUY"]
[Sun Aug 30 03:04:00.498610 2026] [security2:error] [pid 488281:tid 488445] [client 20.63.81.20:55458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/wp-ws68.php"] [unique_id "apPj8DIT5HeNE73zNfp-mQAAAKc"]
[Sun Aug 30 03:04:00.522626 2026] [security2:error] [pid 488281:tid 488517] [client 34.131.221.169:33242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/dev/phpinfo.php"] [unique_id "apPj8DIT5HeNE73zNfp-nQAAAO8"]
[Sun Aug 30 03:04:00.523116 2026] [security2:error] [pid 488669:tid 488891] [client 20.104.49.130:52535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/133.php"] [unique_id "apPj8NRh6OewFvqQpDk16gAAAV4"]
[Sun Aug 30 03:04:00.524794 2026] [security2:error] [pid 488281:tid 488524] [client 20.104.49.130:45732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.katbacon.com"] [uri "/amax.php"] [unique_id "apPj8DIT5HeNE73zNfp-ngAAAPY"]
[Sun Aug 30 03:04:00.574170 2026] [security2:error] [pid 488281:tid 488523] [client 34.131.221.169:33250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/tmp/phpinfo.php"] [unique_id "apPj8DIT5HeNE73zNfp-qQAAAPU"]
[Sun Aug 30 03:04:00.586230 2026] [authz_core:error] [pid 488281:tid 488411] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fnf_reject_ipv4%2Fholders
[Sun Aug 30 03:04:00.586562 2026] [authz_core:error] [pid 488281:tid 488411] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fnf_reject_ipv4%2Fholders
[Sun Aug 30 03:04:00.638139 2026] [security2:error] [pid 488281:tid 488534] [client 20.63.81.20:55545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/simple.php"] [unique_id "apPj8DIT5HeNE73zNfp-swAAAQA"]
[Sun Aug 30 03:04:00.654962 2026] [security2:error] [pid 488669:tid 488826] [client 52.139.37.240:14352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/buy.php"] [unique_id "apPj8NRh6OewFvqQpDk18AAAAR0"]
[Sun Aug 30 03:04:00.707999 2026] [security2:error] [pid 488281:tid 488536] [client 127.0.0.1:17380] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "127.0.0.1"] [uri "/cgi-sys/autoconfig.cgi"] [unique_id "apPj8DIT5HeNE73zNfp-tQAAAQI"]
[Sun Aug 30 03:04:00.708203 2026] [security2:error] [pid 488281:tid 488433] [client 74.7.241.174:54358] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "autoconfig.cce.edu.ng"] [uri "/robots.txt"] [unique_id "apPj8DIT5HeNE73zNfp-tAAAmz0"]
[Sun Aug 30 03:04:00.769915 2026] [security2:error] [pid 488281:tid 488468] [client 20.63.81.20:55363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/aaa.php"] [unique_id "apPj8DIT5HeNE73zNfp-wwAAAL4"]
[Sun Aug 30 03:04:00.803008 2026] [security2:error] [pid 488281:tid 488345] [remote 103.28.36.106:60500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "recoverymarine.com"] [uri "/wp-login.php"] [unique_id "apPj8DIT5HeNE73zNfp-ygAAsD8"], referer: https://recoverymarine.com/wp-login.php
[Sun Aug 30 03:04:00.866164 2026] [security2:error] [pid 488281:tid 488524] [client 52.139.37.240:14341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/config.php"] [unique_id "apPj8DIT5HeNE73zNfp-zAAAAPY"]
[Sun Aug 30 03:04:00.938447 2026] [security2:error] [pid 488669:tid 488688] [remote 97.74.87.194:39764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "devovsbowsandties.com"] [uri "/wp-login.php"] [unique_id "apPj8NRh6OewFvqQpDk19QABMAo"]
[Sun Aug 30 03:04:01.031439 2026] [security2:error] [pid 488281:tid 488491] [client 68.155.159.216:52722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apPj8TIT5HeNE73zNfp-7gAAANU"]
[Sun Aug 30 03:04:01.035605 2026] [security2:error] [pid 488281:tid 488538] [client 180.181.244.244:42882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.244.181.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innatalybridal.com"] [uri "/wp-login.php"] [unique_id "apPj8TIT5HeNE73zNfp-6gAAAQQ"]
[Sun Aug 30 03:04:01.036266 2026] [security2:error] [pid 488281:tid 488430] [client 20.104.50.220:5557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/x50.php"] [unique_id "apPj8TIT5HeNE73zNfp-8AAAAJg"]
[Sun Aug 30 03:04:01.042663 2026] [security2:error] [pid 488281:tid 488412] [client 20.104.50.220:29861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/core.php"] [unique_id "apPj8TIT5HeNE73zNfp-8wAAAIY"]
[Sun Aug 30 03:04:01.045220 2026] [security2:error] [pid 488281:tid 488530] [client 20.48.251.3:7059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/params.php"] [unique_id "apPj8TIT5HeNE73zNfp-9AAAAPw"]
[Sun Aug 30 03:04:01.049441 2026] [security2:error] [pid 488281:tid 488505] [client 20.48.251.3:58819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/koiy.php"] [unique_id "apPj8TIT5HeNE73zNfp-9wAAAOM"]
[Sun Aug 30 03:04:01.050983 2026] [security2:error] [pid 488281:tid 488468] [client 20.48.251.3:54727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/8.php"] [unique_id "apPj8TIT5HeNE73zNfp--gAAAL4"]
[Sun Aug 30 03:04:01.051213 2026] [security2:error] [pid 488281:tid 488529] [client 20.104.50.220:46146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/Ninja.php"] [unique_id "apPj8TIT5HeNE73zNfp--wAAAPs"]
[Sun Aug 30 03:04:01.052774 2026] [security2:error] [pid 488281:tid 488445] [client 20.104.18.15:3879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1800rlawyer.com"] [uri "/sss.php"] [unique_id "apPj8TIT5HeNE73zNfp-_AAAAKc"]
[Sun Aug 30 03:04:01.057852 2026] [security2:error] [pid 488281:tid 488519] [client 20.48.251.3:55732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/file21.php"] [unique_id "apPj8TIT5HeNE73zNfp_AAAAAPE"]
[Sun Aug 30 03:04:01.058529 2026] [security2:error] [pid 488281:tid 488451] [client 52.139.37.240:14348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/num.php"] [unique_id "apPj8TIT5HeNE73zNfp_AQAAAK0"]
[Sun Aug 30 03:04:01.066806 2026] [security2:error] [pid 488281:tid 488517] [client 20.104.50.220:42765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/fonts/priv8.php"] [unique_id "apPj8TIT5HeNE73zNfp_BAAAAO8"]
[Sun Aug 30 03:04:01.067274 2026] [security2:error] [pid 488281:tid 488496] [client 20.63.81.20:55482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/shiny.php"] [unique_id "apPj8TIT5HeNE73zNfp_BQAAANo"]
[Sun Aug 30 03:04:01.067539 2026] [security2:error] [pid 488281:tid 488508] [client 20.104.18.15:31665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/sallu.php"] [unique_id "apPj8TIT5HeNE73zNfp_BgAAAOY"]
[Sun Aug 30 03:04:01.070760 2026] [security2:error] [pid 488281:tid 488459] [client 20.48.251.3:44203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/edit.php"] [unique_id "apPj8TIT5HeNE73zNfp_BwAAALU"]
[Sun Aug 30 03:04:01.074875 2026] [security2:error] [pid 488281:tid 488450] [client 20.104.50.220:59559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/contactz.php"] [unique_id "apPj8TIT5HeNE73zNfp_CAAAAKw"]
[Sun Aug 30 03:04:01.079628 2026] [security2:error] [pid 488281:tid 488429] [client 20.104.50.220:33294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wso2022_shell.php"] [unique_id "apPj8TIT5HeNE73zNfp_CgAAAJc"]
[Sun Aug 30 03:04:01.079756 2026] [security2:error] [pid 488281:tid 488524] [client 68.155.159.216:60574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-content/cong.php"] [unique_id "apPj8TIT5HeNE73zNfp_CQAAAPY"]
[Sun Aug 30 03:04:01.095517 2026] [security2:error] [pid 488281:tid 488470] [client 20.104.18.15:9057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/wp.php"] [unique_id "apPj8TIT5HeNE73zNfp_CwAAAMA"]
[Sun Aug 30 03:04:01.101501 2026] [security2:error] [pid 488281:tid 488522] [client 20.104.50.220:31885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/yo.php"] [unique_id "apPj8TIT5HeNE73zNfp_EAAAAPQ"]
[Sun Aug 30 03:04:01.106150 2026] [authz_core:error] [pid 488281:tid 488499] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:04:01.106446 2026] [authz_core:error] [pid 488281:tid 488499] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:04:01.116117 2026] [security2:error] [pid 488281:tid 488495] [client 20.104.18.15:3938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lakewoodshuttle.deevosdesigns.com"] [uri "/wp-admin/js/wp-load.php"] [unique_id "apPj8TIT5HeNE73zNfp_FwAAANk"]
[Sun Aug 30 03:04:01.132769 2026] [security2:error] [pid 488281:tid 488493] [client 20.48.251.3:55458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/aws_credentials.php"] [unique_id "apPj8TIT5HeNE73zNfp_GgAAANc"]
[Sun Aug 30 03:04:01.145148 2026] [security2:error] [pid 488669:tid 488830] [client 20.104.50.220:62805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/.well-known/shell.php"] [unique_id "apPj8dRh6OewFvqQpDk1_gAAASE"]
[Sun Aug 30 03:04:01.172541 2026] [security2:error] [pid 488281:tid 488506] [client 20.48.251.3:30147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lastmaskcenter.org"] [uri "/services.php"] [unique_id "apPj8TIT5HeNE73zNfp_MQAAAOQ"]
[Sun Aug 30 03:04:01.175207 2026] [security2:error] [pid 488281:tid 488517] [client 20.104.50.220:29624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/r.php"] [unique_id "apPj8TIT5HeNE73zNfp_NQAAAO8"]
[Sun Aug 30 03:04:01.195964 2026] [security2:error] [pid 488281:tid 488420] [client 20.63.81.20:55456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/goods.php"] [unique_id "apPj8TIT5HeNE73zNfp_QwAAAI4"]
[Sun Aug 30 03:04:01.196543 2026] [security2:error] [pid 488281:tid 488493] [client 20.48.251.3:7417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/xp.php"] [unique_id "apPj8TIT5HeNE73zNfp_RAAAANc"]
[Sun Aug 30 03:04:01.251444 2026] [security2:error] [pid 488281:tid 488417] [client 52.139.37.240:15068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/areak1.php"] [unique_id "apPj8TIT5HeNE73zNfp_VQAAAIs"]
[Sun Aug 30 03:04:01.270260 2026] [security2:error] [pid 488281:tid 488416] [client 34.131.221.169:33266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/old/phpinfo.php"] [unique_id "apPj8TIT5HeNE73zNfp_XQAAAIo"]
[Sun Aug 30 03:04:01.316450 2026] [security2:error] [pid 488281:tid 488454] [client 34.131.221.169:33276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/public/phpinfo.php"] [unique_id "apPj8TIT5HeNE73zNfp_aQAAALA"]
[Sun Aug 30 03:04:01.317582 2026] [security2:error] [pid 488281:tid 488426] [client 20.104.49.130:60964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/dehnl.php"] [unique_id "apPj8TIT5HeNE73zNfp_agAAAJQ"]
[Sun Aug 30 03:04:01.327726 2026] [security2:error] [pid 488281:tid 488431] [client 20.63.81.20:55426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/000.php/index.php"] [unique_id "apPj8TIT5HeNE73zNfp_bgAAAJk"]
[Sun Aug 30 03:04:01.332941 2026] [authz_core:error] [pid 488281:tid 488505] [client 66.249.66.204:48942] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:01.333391 2026] [authz_core:error] [pid 488281:tid 488505] [client 66.249.66.204:48942] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:01.344569 2026] [security2:error] [pid 488669:tid 488689] [remote 97.74.87.194:39764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "devovsbowsandties.com"] [uri "/wp-login.php"] [unique_id "apPj8dRh6OewFvqQpDk2LgABHgs"], referer: https://devovsbowsandties.com/wp-login.php
[Sun Aug 30 03:04:01.446135 2026] [security2:error] [pid 488669:tid 488897] [client 52.139.37.240:14364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/vc.php"] [unique_id "apPj8dRh6OewFvqQpDk2VwAAAWQ"]
[Sun Aug 30 03:04:01.459437 2026] [authz_core:error] [pid 488281:tid 488460] [client 66.249.66.34:46507] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:01.459922 2026] [authz_core:error] [pid 488281:tid 488460] [client 66.249.66.34:46507] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:01.463674 2026] [security2:error] [pid 488281:tid 488470] [client 20.63.81.20:55496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/Jcrop.php"] [unique_id "apPj8TIT5HeNE73zNfp_yAAAAMA"]
[Sun Aug 30 03:04:01.466467 2026] [security2:error] [pid 488281:tid 488480] [client 20.104.49.130:47845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wondertanks.com"] [uri "/ws78.php"] [unique_id "apPj8TIT5HeNE73zNfp_zAAAAMo"]
[Sun Aug 30 03:04:01.466508 2026] [security2:error] [pid 488281:tid 488492] [client 158.23.147.79:55178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apPj8TIT5HeNE73zNfp_ywAAANY"]
[Sun Aug 30 03:04:01.467461 2026] [security2:error] [pid 488281:tid 488432] [client 34.16.144.252:28072] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpcontacts.alchemancer.com"] [uri "/gcp-service-account.json"] [unique_id "apPj8TIT5HeNE73zNfp_zgAAAJo"]
[Sun Aug 30 03:04:01.469681 2026] [security2:error] [pid 488669:tid 488831] [client 34.16.144.252:28260] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/production/.env"] [unique_id "apPj8dRh6OewFvqQpDk2XwAAASI"]
[Sun Aug 30 03:04:01.473833 2026] [security2:error] [pid 488669:tid 488837] [client 34.16.144.252:28248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/client/.env"] [unique_id "apPj8dRh6OewFvqQpDk2aQAAASg"]
[Sun Aug 30 03:04:01.479055 2026] [security2:error] [pid 488669:tid 488865] [client 34.16.144.252:28290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/staging/.env"] [unique_id "apPj8dRh6OewFvqQpDk2bgAAAUQ"]
[Sun Aug 30 03:04:01.480789 2026] [security2:error] [pid 488281:tid 488419] [client 34.16.144.252:28254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/backup/.env"] [unique_id "apPj8TIT5HeNE73zNfp_6QAAAI0"]
[Sun Aug 30 03:04:01.483317 2026] [security2:error] [pid 488281:tid 488513] [client 34.16.144.252:28276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/dev/.env"] [unique_id "apPj8TIT5HeNE73zNfp_7gAAAOs"]
[Sun Aug 30 03:04:01.485019 2026] [security2:error] [pid 488669:tid 488826] [client 20.104.49.130:45160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trinitytechnologics.com"] [uri "/Jcrop.php"] [unique_id "apPj8dRh6OewFvqQpDk2cwAAAR0"]
[Sun Aug 30 03:04:01.523084 2026] [authz_core:error] [pid 488669:tid 488849] [client 66.249.66.205:56149] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:01.523547 2026] [authz_core:error] [pid 488669:tid 488849] [client 66.249.66.205:56149] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:01.587075 2026] [security2:error] [pid 488281:tid 488415] [client 158.23.147.79:55056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apPj8TIT5HeNE73zNfqAFAAAAIk"]
[Sun Aug 30 03:04:01.592188 2026] [security2:error] [pid 488281:tid 488526] [client 20.63.81.20:55501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/35iDq8NAjLu.php"] [unique_id "apPj8TIT5HeNE73zNfqAFwAAAPg"]
[Sun Aug 30 03:04:01.604039 2026] [authz_core:error] [pid 488281:tid 488507] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:04:01.604353 2026] [authz_core:error] [pid 488281:tid 488507] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:04:01.638945 2026] [security2:error] [pid 488281:tid 488463] [client 52.139.37.240:15050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPj8TIT5HeNE73zNfqAJwAAALk"]
[Sun Aug 30 03:04:01.720014 2026] [authz_core:error] [pid 488281:tid 488496] [client 216.73.216.128:31956] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:01.720763 2026] [authz_core:error] [pid 488281:tid 488496] [client 216.73.216.128:31956] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:01.726176 2026] [security2:error] [pid 488669:tid 488857] [client 158.23.147.79:55208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/simple.php"] [unique_id "apPj8dRh6OewFvqQpDk2nwAAATw"]
[Sun Aug 30 03:04:01.727783 2026] [security2:error] [pid 488669:tid 488917] [client 20.63.81.20:55480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/btx25.php"] [unique_id "apPj8dRh6OewFvqQpDk2oAAAAXg"]
[Sun Aug 30 03:04:01.833915 2026] [security2:error] [pid 488669:tid 488837] [client 52.139.37.240:15065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/core.php"] [unique_id "apPj8dRh6OewFvqQpDk2pgAAASg"]
[Sun Aug 30 03:04:01.858825 2026] [security2:error] [pid 488669:tid 488898] [client 20.63.81.20:55495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/radio.php"] [unique_id "apPj8dRh6OewFvqQpDk2pwAAAWU"]
[Sun Aug 30 03:04:01.992059 2026] [security2:error] [pid 488669:tid 488924] [client 20.63.81.20:55392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/dex.php"] [unique_id "apPj8dRh6OewFvqQpDk2rQAAAX8"]
[Sun Aug 30 03:04:02.026067 2026] [security2:error] [pid 488669:tid 488865] [client 34.131.221.169:33290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/tmp/phpinfo.php"] [unique_id "apPj8tRh6OewFvqQpDk2rwAAAUQ"]
[Sun Aug 30 03:04:02.039887 2026] [security2:error] [pid 488281:tid 488515] [client 52.139.37.240:14362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/wp-content/min.php"] [unique_id "apPj8jIT5HeNE73zNfqAXQAAAO0"]
[Sun Aug 30 03:04:02.068838 2026] [security2:error] [pid 488281:tid 488357] [remote 103.124.95.115:38846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.95.124.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-3a0b084e.nck.chg.temporary.site"] [uri "/wp-login.php"] [unique_id "apPj8jIT5HeNE73zNfqAZQAApEs"]
[Sun Aug 30 03:04:02.094813 2026] [authz_core:error] [pid 488669:tid 488916] [client 66.249.66.194:51364] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:02.095224 2026] [authz_core:error] [pid 488669:tid 488916] [client 66.249.66.194:51364] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:02.097958 2026] [authz_core:error] [pid 488281:tid 488428] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:04:02.098496 2026] [authz_core:error] [pid 488281:tid 488428] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:04:02.103141 2026] [security2:error] [pid 488669:tid 488863] [client 158.23.147.79:55073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-admin/about.php"] [unique_id "apPj8tRh6OewFvqQpDk2uwAAAUI"]
[Sun Aug 30 03:04:02.123604 2026] [security2:error] [pid 488669:tid 488906] [client 20.63.81.20:55479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/giodywky.php"] [unique_id "apPj8tRh6OewFvqQpDk2wgAAAW0"]
[Sun Aug 30 03:04:02.138733 2026] [security2:error] [pid 488669:tid 488864] [client 68.155.159.216:52704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-content/languages/about.php"] [unique_id "apPj8tRh6OewFvqQpDk2xAAAAUM"]
[Sun Aug 30 03:04:02.174429 2026] [security2:error] [pid 488281:tid 488519] [client 20.104.50.220:30323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/www.php"] [unique_id "apPj8jIT5HeNE73zNfqAjwAAAPE"]
[Sun Aug 30 03:04:02.180339 2026] [security2:error] [pid 488669:tid 488860] [client 20.104.50.220:5565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/fv.php"] [unique_id "apPj8tRh6OewFvqQpDk2zQAAAT8"]
[Sun Aug 30 03:04:02.189695 2026] [security2:error] [pid 488669:tid 488858] [client 20.104.50.220:46919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-incleude.php"] [unique_id "apPj8tRh6OewFvqQpDk20gAAAT0"]
[Sun Aug 30 03:04:02.202162 2026] [security2:error] [pid 488281:tid 488466] [client 20.48.251.3:59310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/mcebraed.php"] [unique_id "apPj8jIT5HeNE73zNfqAoAAAALw"]
[Sun Aug 30 03:04:02.211626 2026] [security2:error] [pid 488281:tid 488493] [client 20.48.251.3:23438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/8.php"] [unique_id "apPj8jIT5HeNE73zNfqApAAAANc"]
[Sun Aug 30 03:04:02.220777 2026] [security2:error] [pid 488281:tid 488489] [client 20.104.50.220:42011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/vendor/priv8.php"] [unique_id "apPj8jIT5HeNE73zNfqApQAAANM"]
[Sun Aug 30 03:04:02.221143 2026] [security2:error] [pid 488281:tid 488534] [client 20.48.251.3:59087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/queue.php"] [unique_id "apPj8jIT5HeNE73zNfqApgAAAQA"]
[Sun Aug 30 03:04:02.227327 2026] [security2:error] [pid 488281:tid 488517] [client 20.104.50.220:33190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wpxadmin.php"] [unique_id "apPj8jIT5HeNE73zNfqApwAAAO8"]
[Sun Aug 30 03:04:02.236399 2026] [security2:error] [pid 488281:tid 488492] [client 20.104.18.15:3906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1800rlawyer.com"] [uri "/xmini4.php"] [unique_id "apPj8jIT5HeNE73zNfqAqwAAANY"]
[Sun Aug 30 03:04:02.244335 2026] [security2:error] [pid 488669:tid 488821] [client 20.104.18.15:31621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/codex.php"] [unique_id "apPj8tRh6OewFvqQpDk25AAAARg"]
[Sun Aug 30 03:04:02.252941 2026] [security2:error] [pid 488281:tid 488433] [client 20.63.81.20:55512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/wp-kz.php"] [unique_id "apPj8jIT5HeNE73zNfqAswAAAJs"]
[Sun Aug 30 03:04:02.256046 2026] [security2:error] [pid 488281:tid 488515] [client 52.139.37.240:14373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "apPj8jIT5HeNE73zNfqAtQAAAO0"]
[Sun Aug 30 03:04:02.257204 2026] [security2:error] [pid 488281:tid 488515] [client 20.104.18.15:3852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lakewoodshuttle.deevosdesigns.com"] [uri "/robot.php"] [unique_id "apPj8jIT5HeNE73zNfqAtwAAAO0"]
[Sun Aug 30 03:04:02.263569 2026] [security2:error] [pid 488281:tid 488440] [client 20.104.50.220:32573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-content/fm.php"] [unique_id "apPj8jIT5HeNE73zNfqAuQAAAKI"]
[Sun Aug 30 03:04:02.263850 2026] [security2:error] [pid 488281:tid 488523] [client 20.48.251.3:55434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/aws-credentials.php"] [unique_id "apPj8jIT5HeNE73zNfqAugAAAPU"]
[Sun Aug 30 03:04:02.267042 2026] [security2:error] [pid 488281:tid 488529] [client 20.104.18.15:9150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/abcd.php"] [unique_id "apPj8jIT5HeNE73zNfqAvAAAAPs"]
[Sun Aug 30 03:04:02.269607 2026] [security2:error] [pid 488669:tid 488809] [client 20.104.50.220:59572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/orange.php"] [unique_id "apPj8tRh6OewFvqQpDk26wAAAQw"]
[Sun Aug 30 03:04:02.282714 2026] [security2:error] [pid 488281:tid 488502] [client 20.104.50.220:62794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/.well-known/.dha.php"] [unique_id "apPj8jIT5HeNE73zNfqAwwAAAOA"]
[Sun Aug 30 03:04:02.292531 2026] [security2:error] [pid 488669:tid 488832] [client 20.48.251.3:64303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/thui.php"] [unique_id "apPj8tRh6OewFvqQpDk28AAAASM"]
[Sun Aug 30 03:04:02.334867 2026] [security2:error] [pid 488669:tid 488839] [client 20.48.251.3:7404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/g3.php"] [unique_id "apPj8tRh6OewFvqQpDk3AQAAASo"]
[Sun Aug 30 03:04:02.337589 2026] [security2:error] [pid 488669:tid 488841] [client 34.131.221.169:33306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/php-info.php"] [unique_id "apPj8tRh6OewFvqQpDk3AwAAASw"]
[Sun Aug 30 03:04:02.338934 2026] [security2:error] [pid 488669:tid 488830] [client 20.104.50.220:29130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/q.php"] [unique_id "apPj8tRh6OewFvqQpDk3BAAAASE"]
[Sun Aug 30 03:04:02.348416 2026] [security2:error] [pid 488281:tid 488426] [client 20.48.251.3:31627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lastmaskcenter.org"] [uri "/filesystems.php"] [unique_id "apPj8jIT5HeNE73zNfqA3QAAAJQ"]
[Sun Aug 30 03:04:02.358748 2026] [security2:error] [pid 488281:tid 488451] [client 20.104.49.130:43783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.katbacon.com"] [uri "/init.php"] [unique_id "apPj8jIT5HeNE73zNfqA3wAAAK0"]
[Sun Aug 30 03:04:02.379288 2026] [security2:error] [pid 488281:tid 488440] [client 20.63.81.20:55532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/wp-includes/ID3/getid.php"] [unique_id "apPj8jIT5HeNE73zNfqA5QAAAKI"]
[Sun Aug 30 03:04:02.434121 2026] [security2:error] [pid 488669:tid 488693] [remote 52.167.144.170:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibrgroup.ae"] [uri "/voitech/category.php"] [unique_id "apPj8tRh6OewFvqQpDk3IgABUA8"]
[Sun Aug 30 03:04:02.451837 2026] [security2:error] [pid 488281:tid 488537] [client 52.139.37.240:14383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/ws37.php"] [unique_id "apPj8jIT5HeNE73zNfqBDQAAAQM"]
[Sun Aug 30 03:04:02.453520 2026] [security2:error] [pid 488281:tid 488537] [client 158.23.147.79:55069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apPj8jIT5HeNE73zNfqBEAAAAQM"]
[Sun Aug 30 03:04:02.455679 2026] [security2:error] [pid 488669:tid 488834] [client 20.104.49.130:26675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trinitytechnologics.com"] [uri "/menu.php"] [unique_id "apPj8tRh6OewFvqQpDk3PAAAASU"]
[Sun Aug 30 03:04:02.477905 2026] [security2:error] [pid 488669:tid 488910] [client 68.155.159.216:59391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPj8tRh6OewFvqQpDk3TwAAAXE"]
[Sun Aug 30 03:04:02.508468 2026] [security2:error] [pid 488669:tid 488832] [client 20.63.81.20:55414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/session.php"] [unique_id "apPj8tRh6OewFvqQpDk3ZgAAASM"]
[Sun Aug 30 03:04:02.531883 2026] [security2:error] [pid 488281:tid 488364] [remote 103.124.95.115:38846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.95.124.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-3a0b084e.nck.chg.temporary.site"] [uri "/wp-login.php"] [unique_id "apPj8jIT5HeNE73zNfqBPQAA5VI"], referer: https://website-3a0b084e.nck.chg.temporary.site/wp-login.php
[Sun Aug 30 03:04:02.600692 2026] [authz_core:error] [pid 488281:tid 488521] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:04:02.601150 2026] [authz_core:error] [pid 488281:tid 488521] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:04:02.638195 2026] [security2:error] [pid 488281:tid 488459] [client 20.63.81.20:55490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/eagle.php"] [unique_id "apPj8jIT5HeNE73zNfqBagAAALU"]
[Sun Aug 30 03:04:02.645987 2026] [security2:error] [pid 488281:tid 488419] [client 52.139.37.240:15067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/new.php"] [unique_id "apPj8jIT5HeNE73zNfqBbAAAAI0"]
[Sun Aug 30 03:04:02.757870 2026] [security2:error] [pid 488281:tid 488445] [client 20.48.251.3:7056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/gjm.php"] [unique_id "apPj8jIT5HeNE73zNfqBiAAAAKc"]
[Sun Aug 30 03:04:02.769947 2026] [security2:error] [pid 488669:tid 488908] [client 34.131.221.169:33308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/public/phpinfo.php"] [unique_id "apPj8tRh6OewFvqQpDk3iAAAAW8"]
[Sun Aug 30 03:04:02.771660 2026] [security2:error] [pid 488281:tid 488452] [client 20.63.81.20:55497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/up-kon.php"] [unique_id "apPj8jIT5HeNE73zNfqBjAAAAK4"]
[Sun Aug 30 03:04:02.838921 2026] [security2:error] [pid 488281:tid 488518] [client 158.23.147.79:55195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apPj8jIT5HeNE73zNfqBlAAAAPA"]
[Sun Aug 30 03:04:02.902550 2026] [security2:error] [pid 488281:tid 488449] [client 20.63.81.20:55481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/tinny.php"] [unique_id "apPj8jIT5HeNE73zNfqBogAAAKs"]
[Sun Aug 30 03:04:02.907889 2026] [security2:error] [pid 488281:tid 488501] [client 52.139.37.240:15056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/il.php"] [unique_id "apPj8jIT5HeNE73zNfqBpAAAAN8"]
[Sun Aug 30 03:04:03.002804 2026] [security2:error] [pid 488281:tid 488422] [client 20.104.49.130:58189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.katbacon.com"] [uri "/wen.php"] [unique_id "apPj8zIT5HeNE73zNfqBvgAAAJA"]
[Sun Aug 30 03:04:03.019025 2026] [security2:error] [pid 488281:tid 488425] [client 178.159.37.16:50023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "geotravel.am"] [uri "/wp-comments-post.php"] [unique_id "apPj7zIT5HeNE73zNfp94gAAAJM"], referer: https://geotravel.am/discover-armenias-hidden-gems-tufenkian-avan-marak-tsapatagh-hotel/comment-page-269968/
[Sun Aug 30 03:04:03.034395 2026] [security2:error] [pid 488281:tid 488369] [remote 50.87.143.111:46046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.143.87.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "texasmobileadvertising.com"] [uri "/wp-login.php"] [unique_id "apPj8zIT5HeNE73zNfqBwwAA1Fc"]
[Sun Aug 30 03:04:03.042142 2026] [security2:error] [pid 488669:tid 488822] [client 20.63.81.20:55394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/wp-easy.php"] [unique_id "apPj89Rh6OewFvqQpDk3lwAAARk"]
[Sun Aug 30 03:04:03.063678 2026] [authz_core:error] [pid 488281:tid 488467] [client 66.249.66.65:40170] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:03.064133 2026] [authz_core:error] [pid 488281:tid 488467] [client 66.249.66.65:40170] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:03.072278 2026] [authz_core:error] [pid 488281:tid 488433] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fyajl
[Sun Aug 30 03:04:03.072758 2026] [authz_core:error] [pid 488281:tid 488433] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fyajl
[Sun Aug 30 03:04:03.109923 2026] [security2:error] [pid 488281:tid 488525] [client 52.139.37.240:14388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/images/index.php"] [unique_id "apPj8zIT5HeNE73zNfqB2wAAAPc"]
[Sun Aug 30 03:04:03.110817 2026] [security2:error] [pid 488281:tid 488515] [client 34.131.221.169:33320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/phpversion.php"] [unique_id "apPj8zIT5HeNE73zNfqB3AAAAO0"]
[Sun Aug 30 03:04:03.179252 2026] [security2:error] [pid 488281:tid 488505] [client 20.63.81.20:55493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/d7.php"] [unique_id "apPj8zIT5HeNE73zNfqB_QAAAOM"]
[Sun Aug 30 03:04:03.204750 2026] [security2:error] [pid 488281:tid 488437] [client 158.23.147.79:55184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/chosen.php"] [unique_id "apPj8zIT5HeNE73zNfqCDwAAAJ8"]
[Sun Aug 30 03:04:03.260897 2026] [security2:error] [pid 488669:tid 488865] [client 68.155.159.216:54732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-content/banners/about.php"] [unique_id "apPj89Rh6OewFvqQpDk3xQAAAUQ"]
[Sun Aug 30 03:04:03.303840 2026] [security2:error] [pid 488281:tid 488463] [client 158.23.147.79:55050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/goods.php"] [unique_id "apPj8zIT5HeNE73zNfqCOgAAALk"]
[Sun Aug 30 03:04:03.304276 2026] [security2:error] [pid 488281:tid 488534] [client 20.104.50.220:29831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/Smarty.php"] [unique_id "apPj8zIT5HeNE73zNfqCPAAAAQA"]
[Sun Aug 30 03:04:03.304447 2026] [security2:error] [pid 488281:tid 488419] [client 52.139.37.240:15062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/lite.php"] [unique_id "apPj8zIT5HeNE73zNfqCOwAAAI0"]
[Sun Aug 30 03:04:03.308544 2026] [security2:error] [pid 488281:tid 488428] [client 20.63.81.20:55376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/v5.php"] [unique_id "apPj8zIT5HeNE73zNfqCPgAAAJY"]
[Sun Aug 30 03:04:03.327219 2026] [security2:error] [pid 488669:tid 488926] [client 20.104.50.220:46597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/fpebr.php"] [unique_id "apPj89Rh6OewFvqQpDk31QAAAYE"]
[Sun Aug 30 03:04:03.334247 2026] [security2:error] [pid 488281:tid 488413] [client 20.104.50.220:5920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/file.php"] [unique_id "apPj8zIT5HeNE73zNfqCRwAAAIc"]
[Sun Aug 30 03:04:03.335549 2026] [security2:error] [pid 488281:tid 488413] [client 20.48.251.3:55755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/server-info.php"] [unique_id "apPj8zIT5HeNE73zNfqCSAAAAIc"]
[Sun Aug 30 03:04:03.346549 2026] [security2:error] [pid 488281:tid 488527] [client 20.48.251.3:44183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/thui.php"] [unique_id "apPj8zIT5HeNE73zNfqCTgAAAPk"]
[Sun Aug 30 03:04:03.364567 2026] [security2:error] [pid 488669:tid 488916] [client 20.104.50.220:33173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wso2.5.php"] [unique_id "apPj89Rh6OewFvqQpDk32AAAAXc"]
[Sun Aug 30 03:04:03.374218 2026] [security2:error] [pid 488281:tid 488504] [client 20.104.50.220:63512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/css/priv8.php"] [unique_id "apPj8zIT5HeNE73zNfqCWwAAAOI"]
[Sun Aug 30 03:04:03.387431 2026] [authz_core:error] [pid 488281:tid 488426] [client 66.249.66.203:59285] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:03.387731 2026] [authz_core:error] [pid 488281:tid 488426] [client 66.249.66.203:59285] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:03.403018 2026] [security2:error] [pid 488281:tid 488474] [client 20.104.18.15:3885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1800rlawyer.com"] [uri "/gulu.php"] [unique_id "apPj8zIT5HeNE73zNfqCbAAAAMQ"]
[Sun Aug 30 03:04:03.404189 2026] [security2:error] [pid 488281:tid 488490] [client 20.48.251.3:49960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/4563.php"] [unique_id "apPj8zIT5HeNE73zNfqCcAAAANQ"]
[Sun Aug 30 03:04:03.406159 2026] [security2:error] [pid 488281:tid 488470] [client 20.104.18.15:31709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/5656.php"] [unique_id "apPj8zIT5HeNE73zNfqCcgAAAMA"]
[Sun Aug 30 03:04:03.409521 2026] [security2:error] [pid 488281:tid 488503] [client 20.104.50.220:32531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-content/a.php"] [unique_id "apPj8zIT5HeNE73zNfqCdgAAAOE"]
[Sun Aug 30 03:04:03.413446 2026] [security2:error] [pid 488281:tid 488483] [client 20.104.18.15:9146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/nofile.php"] [unique_id "apPj8zIT5HeNE73zNfqCdwAAAM0"]
[Sun Aug 30 03:04:03.419330 2026] [security2:error] [pid 488669:tid 488825] [client 20.104.18.15:4041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lakewoodshuttle.deevosdesigns.com"] [uri "/revo.php"] [unique_id "apPj89Rh6OewFvqQpDk35gAAARw"]
[Sun Aug 30 03:04:03.425850 2026] [security2:error] [pid 488281:tid 488477] [client 20.48.251.3:51466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/doc.php"] [unique_id "apPj8zIT5HeNE73zNfqCgQAAAMc"]
[Sun Aug 30 03:04:03.435169 2026] [security2:error] [pid 488669:tid 488812] [client 20.63.81.20:55511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/az.php"] [unique_id "apPj89Rh6OewFvqQpDk38AAAAQ8"]
[Sun Aug 30 03:04:03.441234 2026] [security2:error] [pid 488281:tid 488499] [client 20.104.50.220:59577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/hcd01.php"] [unique_id "apPj8zIT5HeNE73zNfqCjgAAAN0"]
[Sun Aug 30 03:04:03.483385 2026] [security2:error] [pid 488281:tid 488538] [client 20.104.50.220:29575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/p.php"] [unique_id "apPj8zIT5HeNE73zNfqCugAAAQQ"]
[Sun Aug 30 03:04:03.496793 2026] [security2:error] [pid 488669:tid 488884] [client 52.139.37.240:15051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/xda.php"] [unique_id "apPj89Rh6OewFvqQpDk4GAAAAVc"]
[Sun Aug 30 03:04:03.497173 2026] [security2:error] [pid 488281:tid 488505] [client 20.48.251.3:7420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/wp-konfig.php"] [unique_id "apPj8zIT5HeNE73zNfqCyAAAAOM"]
[Sun Aug 30 03:04:03.500843 2026] [security2:error] [pid 488669:tid 488861] [client 20.48.251.3:64264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/file21.php"] [unique_id "apPj89Rh6OewFvqQpDk4HQAAAUA"]
[Sun Aug 30 03:04:03.502014 2026] [security2:error] [pid 488281:tid 488461] [client 158.23.147.79:55043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apPj8zIT5HeNE73zNfqCyQAAALc"]
[Sun Aug 30 03:04:03.547501 2026] [security2:error] [pid 488281:tid 488422] [client 20.104.50.220:28696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/.well-known/403.php"] [unique_id "apPj8zIT5HeNE73zNfqC3wAAAJA"]
[Sun Aug 30 03:04:03.571571 2026] [security2:error] [pid 488281:tid 488448] [client 20.63.81.20:55428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/js.php"] [unique_id "apPj8zIT5HeNE73zNfqC7AAAAKo"]
[Sun Aug 30 03:04:03.589715 2026] [authz_core:error] [pid 488281:tid 488521] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:04:03.590156 2026] [authz_core:error] [pid 488281:tid 488521] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:04:03.595900 2026] [security2:error] [pid 488281:tid 488485] [client 20.48.251.3:29740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lastmaskcenter.org"] [uri "/tax.php"] [unique_id "apPj8zIT5HeNE73zNfqC8wAAAM8"]
[Sun Aug 30 03:04:03.637753 2026] [security2:error] [pid 488669:tid 488910] [client 158.23.147.79:63294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apPj89Rh6OewFvqQpDk4MQAAAXE"]
[Sun Aug 30 03:04:03.690509 2026] [security2:error] [pid 488669:tid 488930] [client 52.139.37.240:15100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/.trash7206/index.php"] [unique_id "apPj89Rh6OewFvqQpDk4NgAAAYU"]
[Sun Aug 30 03:04:03.703304 2026] [security2:error] [pid 488281:tid 488377] [remote 162.215.121.77:38998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.121.215.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.tulsaattorney.pro"] [uri "/wp-login.php"] [unique_id "apPj8zIT5HeNE73zNfqDFAAAyF8"]
[Sun Aug 30 03:04:03.705311 2026] [security2:error] [pid 488669:tid 488819] [client 20.63.81.20:55447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/hd.php"] [unique_id "apPj89Rh6OewFvqQpDk4OQAAARY"]
[Sun Aug 30 03:04:03.764603 2026] [security2:error] [pid 488669:tid 488816] [client 20.104.49.130:26933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trinitytechnologics.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPj89Rh6OewFvqQpDk4SQAAARM"]
[Sun Aug 30 03:04:03.769432 2026] [security2:error] [pid 488281:tid 488492] [client 68.155.159.216:59332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPj8zIT5HeNE73zNfqDIAAAANY"]
[Sun Aug 30 03:04:03.776978 2026] [security2:error] [pid 488669:tid 488840] [client 20.104.49.130:52336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.katbacon.com"] [uri "/Jcrop.php"] [unique_id "apPj89Rh6OewFvqQpDk4SgAAASs"]
[Sun Aug 30 03:04:03.787504 2026] [security2:error] [pid 488669:tid 488864] [client 34.131.221.169:33330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/php-info.php"] [unique_id "apPj89Rh6OewFvqQpDk4SwAAAUM"]
[Sun Aug 30 03:04:03.845891 2026] [security2:error] [pid 488281:tid 488525] [client 20.63.81.20:55550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/xl2023.php"] [unique_id "apPj8zIT5HeNE73zNfqDMgAAAPc"]
[Sun Aug 30 03:04:03.878465 2026] [security2:error] [pid 488281:tid 488475] [client 34.131.221.169:33342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/_phpinfo.php"] [unique_id "apPj8zIT5HeNE73zNfqDOgAAAMU"]
[Sun Aug 30 03:04:03.886654 2026] [security2:error] [pid 488669:tid 488934] [client 52.139.37.240:15054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/storage/index.php"] [unique_id "apPj89Rh6OewFvqQpDk4VgAAAYk"]
[Sun Aug 30 03:04:03.941830 2026] [authz_core:error] [pid 488281:tid 488449] [client 66.249.66.68:39499] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:03.942331 2026] [authz_core:error] [pid 488281:tid 488449] [client 66.249.66.68:39499] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:03.982562 2026] [security2:error] [pid 488281:tid 488481] [client 20.63.81.20:55450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/V2.php"] [unique_id "apPj8zIT5HeNE73zNfqDWQAAAMs"]
[Sun Aug 30 03:04:04.023177 2026] [security2:error] [pid 488281:tid 488382] [remote 50.87.143.111:46046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.143.87.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "texasmobileadvertising.com"] [uri "/wp-login.php"] [unique_id "apPj9DIT5HeNE73zNfqDXQAA82Q"], referer: https://texasmobileadvertising.com/wp-login.php
[Sun Aug 30 03:04:04.064197 2026] [authz_core:error] [pid 488281:tid 488426] [client 66.249.66.203:59285] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:04.064669 2026] [authz_core:error] [pid 488281:tid 488426] [client 66.249.66.203:59285] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:04.068474 2026] [authz_core:error] [pid 488281:tid 488456] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:04:04.068944 2026] [authz_core:error] [pid 488281:tid 488456] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:04:04.079096 2026] [security2:error] [pid 488281:tid 488496] [client 52.139.37.240:15082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPj9DIT5HeNE73zNfqDbgAAANo"]
[Sun Aug 30 03:04:04.138465 2026] [security2:error] [pid 488669:tid 488809] [client 20.63.81.20:55548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/mad.php"] [unique_id "apPj9NRh6OewFvqQpDk4fQAAAQw"]
[Sun Aug 30 03:04:04.141967 2026] [security2:error] [pid 488281:tid 488384] [remote 162.215.121.77:38998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.121.215.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.tulsaattorney.pro"] [uri "/wp-login.php"] [unique_id "apPj9DIT5HeNE73zNfqDgwAAmmY"], referer: https://mail.tulsaattorney.pro/wp-login.php
[Sun Aug 30 03:04:04.249572 2026] [security2:error] [pid 488669:tid 488878] [client 20.104.49.130:52332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.katbacon.com"] [uri "/menu.php"] [unique_id "apPj9NRh6OewFvqQpDk4mAAAAVE"]
[Sun Aug 30 03:04:04.276224 2026] [security2:error] [pid 488281:tid 488457] [client 20.63.81.20:55540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/st.php"] [unique_id "apPj9DIT5HeNE73zNfqDxwAAALM"]
[Sun Aug 30 03:04:04.283030 2026] [security2:error] [pid 488281:tid 488519] [client 52.139.37.240:15076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/wp-blog.php"] [unique_id "apPj9DIT5HeNE73zNfqDyQAAAPE"]
[Sun Aug 30 03:04:04.288422 2026] [security2:error] [pid 488281:tid 488505] [client 158.23.147.79:55215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apPj9DIT5HeNE73zNfqDygAAAOM"]
[Sun Aug 30 03:04:04.304877 2026] [authz_core:error] [pid 488281:tid 488496] [client 216.73.216.128:31956] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:04.305274 2026] [authz_core:error] [pid 488281:tid 488496] [client 216.73.216.128:31956] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:04.389841 2026] [security2:error] [pid 488281:tid 488518] [client 68.155.159.216:54778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apPj9DIT5HeNE73zNfqD9AAAAPA"]
[Sun Aug 30 03:04:04.404527 2026] [security2:error] [pid 488281:tid 488514] [client 20.63.81.20:55465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/alfanew.php"] [unique_id "apPj9DIT5HeNE73zNfqD_wAAAOw"]
[Sun Aug 30 03:04:04.406038 2026] [security2:error] [pid 488281:tid 488521] [client 158.23.147.79:55176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/file.php"] [unique_id "apPj9DIT5HeNE73zNfqEAQAAAPM"]
[Sun Aug 30 03:04:04.442729 2026] [security2:error] [pid 488669:tid 488891] [client 20.104.50.220:30305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/Redis.php"] [unique_id "apPj9NRh6OewFvqQpDk40AAAAV4"]
[Sun Aug 30 03:04:04.474209 2026] [security2:error] [pid 488281:tid 488525] [client 20.48.251.3:59336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/gk.php"] [unique_id "apPj9DIT5HeNE73zNfqENwAAAPc"]
[Sun Aug 30 03:04:04.478669 2026] [security2:error] [pid 488669:tid 488813] [client 20.104.50.220:46400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/snd21.php"] [unique_id "apPj9NRh6OewFvqQpDk49AAAARA"]
[Sun Aug 30 03:04:04.481770 2026] [security2:error] [pid 488281:tid 488493] [client 20.104.50.220:5609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/lsd.php"] [unique_id "apPj9DIT5HeNE73zNfqEQgAAANc"]
[Sun Aug 30 03:04:04.484223 2026] [security2:error] [pid 488281:tid 488445] [client 20.48.251.3:23300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/file21.php"] [unique_id "apPj9DIT5HeNE73zNfqERQAAAKc"]
[Sun Aug 30 03:04:04.491093 2026] [security2:error] [pid 488281:tid 488538] [client 52.139.37.240:14369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/xmlrpc.php"] [unique_id "apPj9DIT5HeNE73zNfqEUQAAAQQ"]
[Sun Aug 30 03:04:04.503389 2026] [security2:error] [pid 488669:tid 488826] [client 20.104.50.220:33168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-mode.php"] [unique_id "apPj9NRh6OewFvqQpDk4_wAAAR0"]
[Sun Aug 30 03:04:04.513935 2026] [security2:error] [pid 488669:tid 488923] [client 20.104.50.220:42805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/assets/priv8.php"] [unique_id "apPj9NRh6OewFvqQpDk5BQAAAX4"]
[Sun Aug 30 03:04:04.523272 2026] [security2:error] [pid 488281:tid 488479] [client 20.151.200.44:46993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/wp-login.php"] [unique_id "apPj9DIT5HeNE73zNfqETAAAAMk"]
[Sun Aug 30 03:04:04.533693 2026] [security2:error] [pid 488281:tid 488443] [client 20.63.81.20:55448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/ioxi.php"] [unique_id "apPj9DIT5HeNE73zNfqEZgAAAKU"]
[Sun Aug 30 03:04:04.533950 2026] [security2:error] [pid 488281:tid 488448] [client 34.131.221.169:33346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/phpversion.php"] [unique_id "apPj9DIT5HeNE73zNfqEZwAAAKo"]
[Sun Aug 30 03:04:04.540561 2026] [security2:error] [pid 488669:tid 488876] [client 20.104.18.15:31705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/w3lls.php"] [unique_id "apPj9NRh6OewFvqQpDk5DgAAAU8"]
[Sun Aug 30 03:04:04.544422 2026] [security2:error] [pid 488669:tid 488880] [client 20.104.50.220:31876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/images/sym.php"] [unique_id "apPj9NRh6OewFvqQpDk5EwAAAVM"]
[Sun Aug 30 03:04:04.552638 2026] [security2:error] [pid 488281:tid 488429] [client 20.104.18.15:3875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1800rlawyer.com"] [uri "/replace.php"] [unique_id "apPj9DIT5HeNE73zNfqEcwAAAJc"]
[Sun Aug 30 03:04:04.557633 2026] [security2:error] [pid 488281:tid 488492] [client 20.104.18.15:9149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/run.php"] [unique_id "apPj9DIT5HeNE73zNfqEdgAAANY"]
[Sun Aug 30 03:04:04.559033 2026] [security2:error] [pid 488281:tid 488467] [client 20.104.18.15:3956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lakewoodshuttle.deevosdesigns.com"] [uri "/birrs.php"] [unique_id "apPj9DIT5HeNE73zNfqEeAAAAL0"]
[Sun Aug 30 03:04:04.560309 2026] [security2:error] [pid 488281:tid 488466] [client 20.48.251.3:55439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/cp2.php"] [unique_id "apPj9DIT5HeNE73zNfqEeQAAALw"]
[Sun Aug 30 03:04:04.575298 2026] [security2:error] [pid 488281:tid 488444] [client 20.48.251.3:51518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/css.php"] [unique_id "apPj9DIT5HeNE73zNfqEgQAAAKY"]
[Sun Aug 30 03:04:04.575459 2026] [authz_core:error] [pid 488281:tid 488508] [client 66.249.66.195:44909] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:04.575902 2026] [authz_core:error] [pid 488281:tid 488508] [client 66.249.66.195:44909] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:04.584583 2026] [authz_core:error] [pid 488281:tid 488489] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Flib%2Frpm
[Sun Aug 30 03:04:04.585005 2026] [authz_core:error] [pid 488281:tid 488489] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Flib%2Frpm
[Sun Aug 30 03:04:04.601675 2026] [security2:error] [pid 488281:tid 488498] [client 158.23.147.79:55180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/file17.php"] [unique_id "apPj9DIT5HeNE73zNfqEhQAAANw"]
[Sun Aug 30 03:04:04.607525 2026] [security2:error] [pid 488669:tid 488890] [client 4.205.62.107:25517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/drykl.php"] [unique_id "apPj9NRh6OewFvqQpDk5GwAAAV0"]
[Sun Aug 30 03:04:04.627006 2026] [security2:error] [pid 488281:tid 488501] [client 34.131.221.169:33354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/old_phpinfo.php"] [unique_id "apPj9DIT5HeNE73zNfqEiQAAAN8"]
[Sun Aug 30 03:04:04.642487 2026] [security2:error] [pid 488669:tid 488899] [client 20.104.49.130:52521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.katbacon.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPj9NRh6OewFvqQpDk5IwAAAWY"]
[Sun Aug 30 03:04:04.649529 2026] [security2:error] [pid 488281:tid 488459] [client 20.48.251.3:64416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/25.php"] [unique_id "apPj9DIT5HeNE73zNfqEjwAAALU"]
[Sun Aug 30 03:04:04.653701 2026] [security2:error] [pid 488669:tid 488911] [client 20.104.50.220:61660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/prof.php"] [unique_id "apPj9NRh6OewFvqQpDk5JAAAAXI"]
[Sun Aug 30 03:04:04.666588 2026] [security2:error] [pid 488669:tid 488818] [client 20.63.81.20:55429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/TNT.php"] [unique_id "apPj9NRh6OewFvqQpDk5KAAAARU"]
[Sun Aug 30 03:04:04.667661 2026] [authz_core:error] [pid 488281:tid 488458] [client 216.73.216.128:51358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:04.668111 2026] [authz_core:error] [pid 488281:tid 488458] [client 216.73.216.128:51358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:04.684781 2026] [security2:error] [pid 488669:tid 488885] [client 52.139.37.240:15052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/lu4.php"] [unique_id "apPj9NRh6OewFvqQpDk5LAAAAVg"]
[Sun Aug 30 03:04:04.718991 2026] [security2:error] [pid 488669:tid 488829] [client 20.104.50.220:52821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/.well-known/fox.php"] [unique_id "apPj9NRh6OewFvqQpDk5NQAAASA"]
[Sun Aug 30 03:04:04.730663 2026] [security2:error] [pid 488669:tid 488918] [client 20.48.251.3:64708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lastmaskcenter.org"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPj9NRh6OewFvqQpDk5OAAAAXk"]
[Sun Aug 30 03:04:04.740624 2026] [security2:error] [pid 488669:tid 488874] [client 20.48.251.3:64286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/mcebraed.php"] [unique_id "apPj9NRh6OewFvqQpDk5PAAAAU0"]
[Sun Aug 30 03:04:04.764325 2026] [security2:error] [pid 488281:tid 488519] [client 20.104.50.220:63043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/n.php"] [unique_id "apPj9DIT5HeNE73zNfqErQAAAPE"]
[Sun Aug 30 03:04:04.793397 2026] [security2:error] [pid 488281:tid 488433] [client 20.220.10.235:51334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPj9DIT5HeNE73zNfqEtgAAAJs"]
[Sun Aug 30 03:04:04.798986 2026] [security2:error] [pid 488281:tid 488510] [client 4.205.62.107:42612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/packed.php"] [unique_id "apPj9DIT5HeNE73zNfqEuAAAAOg"]
[Sun Aug 30 03:04:04.800346 2026] [security2:error] [pid 488281:tid 488416] [client 4.205.62.107:18644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/wp-konfig.php"] [unique_id "apPj9DIT5HeNE73zNfqEuQAAAIo"]
[Sun Aug 30 03:04:04.807288 2026] [security2:error] [pid 488669:tid 488923] [client 20.63.81.20:55491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/cd.php"] [unique_id "apPj9NRh6OewFvqQpDk5QwAAAX4"]
[Sun Aug 30 03:04:04.849368 2026] [security2:error] [pid 488281:tid 488531] [client 158.23.147.79:55205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/file5.php"] [unique_id "apPj9DIT5HeNE73zNfqExQAAAP0"]
[Sun Aug 30 03:04:04.860529 2026] [security2:error] [pid 488669:tid 488914] [client 20.104.49.130:48916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wondertanks.com"] [uri "/ws58.php"] [unique_id "apPj9NRh6OewFvqQpDk5TAAAAXU"]
[Sun Aug 30 03:04:04.872880 2026] [authz_core:error] [pid 488281:tid 488449] [client 66.249.66.78:36530] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:04.873185 2026] [authz_core:error] [pid 488281:tid 488449] [client 66.249.66.78:36530] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:04.877966 2026] [security2:error] [pid 488669:tid 488890] [client 4.205.62.107:26532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/u88.php"] [unique_id "apPj9NRh6OewFvqQpDk5TgAAAV0"]
[Sun Aug 30 03:04:04.886636 2026] [security2:error] [pid 488669:tid 488889] [client 4.205.62.107:58165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/setup-config.php"] [unique_id "apPj9NRh6OewFvqQpDk5UQAAAVw"]
[Sun Aug 30 03:04:04.898012 2026] [security2:error] [pid 488669:tid 488853] [client 52.139.37.240:14355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "apPj9NRh6OewFvqQpDk5UwAAATg"]
[Sun Aug 30 03:04:04.926593 2026] [security2:error] [pid 488281:tid 488412] [client 20.220.10.235:51324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPj9DIT5HeNE73zNfqE0wAAAIY"]
[Sun Aug 30 03:04:04.943151 2026] [security2:error] [pid 488281:tid 488467] [client 158.23.147.79:55174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/file88.php"] [unique_id "apPj9DIT5HeNE73zNfqE2gAAAL0"]
[Sun Aug 30 03:04:04.943356 2026] [security2:error] [pid 488281:tid 488440] [client 20.63.81.20:55433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/luuf.php"] [unique_id "apPj9DIT5HeNE73zNfqE2wAAAKI"]
[Sun Aug 30 03:04:04.945458 2026] [security2:error] [pid 488281:tid 488512] [client 4.205.62.107:63984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/ah25.php"] [unique_id "apPj9DIT5HeNE73zNfqE3wAAAOo"]
[Sun Aug 30 03:04:05.020798 2026] [security2:error] [pid 488669:tid 488854] [client 68.155.159.216:59373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-includes/Requests/network.php"] [unique_id "apPj9dRh6OewFvqQpDk5YQAAATk"]
[Sun Aug 30 03:04:05.056582 2026] [security2:error] [pid 488281:tid 488422] [client 20.220.10.235:51274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/h02ugyh.php"] [unique_id "apPj9TIT5HeNE73zNfqE_QAAAJA"]
[Sun Aug 30 03:04:05.057704 2026] [security2:error] [pid 488281:tid 488465] [client 158.23.147.79:55076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/NewFile.php/"] [unique_id "apPj9TIT5HeNE73zNfqE_wAAALs"]
[Sun Aug 30 03:04:05.073685 2026] [authz_core:error] [pid 488281:tid 488441] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fdpkg
[Sun Aug 30 03:04:05.073965 2026] [authz_core:error] [pid 488281:tid 488441] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fdpkg
[Sun Aug 30 03:04:05.087367 2026] [security2:error] [pid 488669:tid 488908] [client 20.63.81.20:55387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/fex.php"] [unique_id "apPj9dRh6OewFvqQpDk5aQAAAW8"]
[Sun Aug 30 03:04:05.101760 2026] [security2:error] [pid 488669:tid 488869] [client 34.16.144.252:28414] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.alchemancer.com"] [uri "/service_account.json"] [unique_id "apPj9dRh6OewFvqQpDk5bQAAAUg"]
[Sun Aug 30 03:04:05.104989 2026] [security2:error] [pid 488281:tid 488471] [client 74.7.228.2:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.ilfcllc.com"] [uri "/index.php"] [unique_id "apPj8jIT5HeNE73zNfqAXgAAwUo"]
[Sun Aug 30 03:04:05.109017 2026] [security2:error] [pid 488281:tid 488489] [client 52.139.37.240:15066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/wp-content/upgrade/index.php"] [unique_id "apPj9TIT5HeNE73zNfqFEgAAANM"]
[Sun Aug 30 03:04:05.163688 2026] [security2:error] [pid 488281:tid 488485] [client 158.23.147.79:55189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/dropdown.php"] [unique_id "apPj9TIT5HeNE73zNfqFMQAAAM8"]
[Sun Aug 30 03:04:05.200422 2026] [security2:error] [pid 488281:tid 488443] [client 20.220.10.235:51300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/sf.php"] [unique_id "apPj9TIT5HeNE73zNfqFRgAAAKU"]
[Sun Aug 30 03:04:05.213818 2026] [security2:error] [pid 488669:tid 488808] [client 4.205.62.107:55241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/sale.php"] [unique_id "apPj9dRh6OewFvqQpDk5lQAAAQs"]
[Sun Aug 30 03:04:05.229160 2026] [authz_core:error] [pid 488281:tid 488434] [client 216.73.216.128:51358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:05.229605 2026] [authz_core:error] [pid 488281:tid 488434] [client 216.73.216.128:51358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:05.230737 2026] [security2:error] [pid 488669:tid 488877] [client 20.63.81.20:55533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/l.php"] [unique_id "apPj9dRh6OewFvqQpDk5nwAAAVA"]
[Sun Aug 30 03:04:05.245454 2026] [security2:error] [pid 488669:tid 488809] [client 4.205.62.107:53537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.diamondsintheroughpark.com"] [uri "/umgebung.php"] [unique_id "apPj9dRh6OewFvqQpDk5pQAAAQw"]
[Sun Aug 30 03:04:05.271411 2026] [security2:error] [pid 488669:tid 488888] [client 158.23.147.79:55054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/.well-known/index.php"] [unique_id "apPj9dRh6OewFvqQpDk5rgAAAVs"]
[Sun Aug 30 03:04:05.282491 2026] [security2:error] [pid 488669:tid 488911] [client 192.248.148.152:39628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.148.248.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vogue-couture.com"] [uri "/wp-login.php"] [unique_id "apPj9dRh6OewFvqQpDk5qQAAAXI"]
[Sun Aug 30 03:04:05.296960 2026] [security2:error] [pid 488281:tid 488446] [client 34.131.221.169:33358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/_phpinfo.php"] [unique_id "apPj9TIT5HeNE73zNfqFaAAAAKg"]
[Sun Aug 30 03:04:05.303523 2026] [security2:error] [pid 488281:tid 488474] [client 52.139.37.240:15093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "apPj9TIT5HeNE73zNfqFagAAAMQ"]
[Sun Aug 30 03:04:05.338267 2026] [security2:error] [pid 488669:tid 488818] [client 20.104.49.130:52542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.katbacon.com"] [uri "/ws85.php"] [unique_id "apPj9dRh6OewFvqQpDk5yQAAARU"]
[Sun Aug 30 03:04:05.349512 2026] [security2:error] [pid 488281:tid 488502] [client 20.220.10.235:51340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/4e.php"] [unique_id "apPj9TIT5HeNE73zNfqFdQAAAOA"]
[Sun Aug 30 03:04:05.358612 2026] [security2:error] [pid 488669:tid 488920] [client 20.63.81.20:55542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/xr.php"] [unique_id "apPj9dRh6OewFvqQpDk5zAAAAXs"]
[Sun Aug 30 03:04:05.407259 2026] [authz_core:error] [pid 488281:tid 488427] [client 216.73.216.128:35778] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:05.407736 2026] [authz_core:error] [pid 488281:tid 488427] [client 216.73.216.128:35778] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:05.429583 2026] [security2:error] [pid 488669:tid 488909] [client 34.131.221.169:33366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/server-info.php"] [unique_id "apPj9dRh6OewFvqQpDk56wAAAXA"]
[Sun Aug 30 03:04:05.439056 2026] [security2:error] [pid 488281:tid 488489] [client 4.205.62.107:22973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/xqq.php"] [unique_id "apPj9TIT5HeNE73zNfqFtAAAANM"]
[Sun Aug 30 03:04:05.441008 2026] [security2:error] [pid 488281:tid 488460] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "topglossdetail.com"] [uri "/xmlrpc.php"] [unique_id "apPj8zIT5HeNE73zNfqDFQAAtmA"]
[Sun Aug 30 03:04:05.441394 2026] [security2:error] [pid 488281:tid 488461] [client 4.205.62.107:60602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/koiy.php"] [unique_id "apPj9TIT5HeNE73zNfqFtgAAALc"]
[Sun Aug 30 03:04:05.472073 2026] [security2:error] [pid 488669:tid 488898] [client 158.23.184.117:51160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "apPj9dRh6OewFvqQpDk6DQAAAWU"]
[Sun Aug 30 03:04:05.480724 2026] [security2:error] [pid 488669:tid 488910] [client 20.220.10.235:51282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/ssss.php"] [unique_id "apPj9dRh6OewFvqQpDk6EgAAAXE"]
[Sun Aug 30 03:04:05.492938 2026] [security2:error] [pid 488281:tid 488468] [client 68.155.159.216:54751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/asd.php"] [unique_id "apPj9TIT5HeNE73zNfqF4gAAAL4"]
[Sun Aug 30 03:04:05.497291 2026] [security2:error] [pid 488281:tid 488444] [client 52.139.37.240:15091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/ant.php"] [unique_id "apPj9TIT5HeNE73zNfqF6AAAAKY"]
[Sun Aug 30 03:04:05.502270 2026] [security2:error] [pid 488281:tid 488521] [client 20.63.81.20:55391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/Q3.php"] [unique_id "apPj9TIT5HeNE73zNfqF7QAAAPM"]
[Sun Aug 30 03:04:05.503477 2026] [security2:error] [pid 488669:tid 488823] [client 4.205.62.107:43014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/asdf.php"] [unique_id "apPj9dRh6OewFvqQpDk6HgAAARo"]
[Sun Aug 30 03:04:05.524883 2026] [security2:error] [pid 488281:tid 488421] [client 158.23.184.117:51148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/light.php"] [unique_id "apPj9TIT5HeNE73zNfqF-wAAAI8"]
[Sun Aug 30 03:04:05.526917 2026] [security2:error] [pid 488281:tid 488450] [client 74.7.228.2:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ilfcllc.com"] [uri "/index.php"] [unique_id "apPj9TIT5HeNE73zNfqFdgAArHc"], referer: https://www.ilfcllc.com/robots.txt
[Sun Aug 30 03:04:05.546664 2026] [authz_core:error] [pid 488281:tid 488458] [client 66.249.66.66:51449] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:05.547078 2026] [authz_core:error] [pid 488281:tid 488458] [client 66.249.66.66:51449] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:05.571276 2026] [security2:error] [pid 488669:tid 488815] [client 158.23.147.79:55206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-content/themes/too.php"] [unique_id "apPj9dRh6OewFvqQpDk6PAAAARI"]
[Sun Aug 30 03:04:05.580132 2026] [security2:error] [pid 488669:tid 488917] [client 20.104.50.220:30327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/nginx_error.php"] [unique_id "apPj9dRh6OewFvqQpDk6QQAAAXg"]
[Sun Aug 30 03:04:05.596832 2026] [authz_core:error] [pid 488281:tid 488475] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fdpkg
[Sun Aug 30 03:04:05.597142 2026] [authz_core:error] [pid 488281:tid 488475] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fdpkg
[Sun Aug 30 03:04:05.609692 2026] [security2:error] [pid 488281:tid 488514] [client 20.48.251.3:55757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/god.php"] [unique_id "apPj9TIT5HeNE73zNfqGEwAAAOw"]
[Sun Aug 30 03:04:05.610196 2026] [security2:error] [pid 488281:tid 488528] [client 20.220.10.235:51269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/zoz.php"] [unique_id "apPj9TIT5HeNE73zNfqGFAAAAPo"]
[Sun Aug 30 03:04:05.619086 2026] [security2:error] [pid 488281:tid 488536] [client 20.104.50.220:46624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/olu.php"] [unique_id "apPj9TIT5HeNE73zNfqGGQAAAQI"]
[Sun Aug 30 03:04:05.619109 2026] [security2:error] [pid 488281:tid 488425] [client 20.104.50.220:5909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/as.php"] [unique_id "apPj9TIT5HeNE73zNfqGGgAAAJM"]
[Sun Aug 30 03:04:05.622815 2026] [security2:error] [pid 488281:tid 488423] [client 20.48.251.3:44286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/mcebraed.php"] [unique_id "apPj9TIT5HeNE73zNfqGHgAAAJE"]
[Sun Aug 30 03:04:05.629557 2026] [security2:error] [pid 488281:tid 488412] [client 4.205.62.107:51738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/file21.php"] [unique_id "apPj9TIT5HeNE73zNfqGIAAAAIY"]
[Sun Aug 30 03:04:05.631004 2026] [security2:error] [pid 488281:tid 488534] [client 4.205.62.107:2788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/8.php"] [unique_id "apPj9TIT5HeNE73zNfqGIQAAAQA"]
[Sun Aug 30 03:04:05.631882 2026] [security2:error] [pid 488281:tid 488417] [client 20.63.81.20:55438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/Q1.php"] [unique_id "apPj9TIT5HeNE73zNfqGIgAAAIs"]
[Sun Aug 30 03:04:05.635738 2026] [security2:error] [pid 488669:tid 488916] [client 4.205.62.107:5083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/chosen.php"] [unique_id "apPj9dRh6OewFvqQpDk6SwAAAXc"]
[Sun Aug 30 03:04:05.658639 2026] [security2:error] [pid 488281:tid 488490] [client 20.104.50.220:33027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-mailcek.php"] [unique_id "apPj9TIT5HeNE73zNfqGJwAAANQ"]
[Sun Aug 30 03:04:05.665014 2026] [security2:error] [pid 488281:tid 488522] [client 20.104.50.220:51628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/js/priv8.php"] [unique_id "apPj9TIT5HeNE73zNfqGKAAAAPQ"]
[Sun Aug 30 03:04:05.667360 2026] [security2:error] [pid 488281:tid 488492] [client 158.23.184.117:60323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/wp-admin/css/about.php7"] [unique_id "apPj9TIT5HeNE73zNfqGKQAAANY"]
[Sun Aug 30 03:04:05.690205 2026] [security2:error] [pid 488669:tid 488877] [client 52.139.37.240:14350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/autoload_classmap.php"] [unique_id "apPj9dRh6OewFvqQpDk6UwAAAVA"]
[Sun Aug 30 03:04:05.702191 2026] [security2:error] [pid 488281:tid 488466] [client 20.104.18.15:9129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/new.php"] [unique_id "apPj9TIT5HeNE73zNfqGOAAAALw"]
[Sun Aug 30 03:04:05.707853 2026] [security2:error] [pid 488281:tid 488538] [client 20.104.18.15:3790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lakewoodshuttle.deevosdesigns.com"] [uri "/sss.php"] [unique_id "apPj9TIT5HeNE73zNfqGOQAAAQQ"]
[Sun Aug 30 03:04:05.713743 2026] [security2:error] [pid 488281:tid 488502] [client 20.48.251.3:55501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/xda.php"] [unique_id "apPj9TIT5HeNE73zNfqGOgAAAOA"]
[Sun Aug 30 03:04:05.717917 2026] [security2:error] [pid 488669:tid 488878] [client 20.104.18.15:31574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/fpwch.php"] [unique_id "apPj9dRh6OewFvqQpDk6WAAAAVE"]
[Sun Aug 30 03:04:05.723891 2026] [security2:error] [pid 488281:tid 488482] [client 20.104.18.15:3893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1800rlawyer.com"] [uri "/c4.php"] [unique_id "apPj9TIT5HeNE73zNfqGPwAAAMw"]
[Sun Aug 30 03:04:05.742910 2026] [security2:error] [pid 488281:tid 488441] [client 20.220.10.235:51277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/kcs.php"] [unique_id "apPj9TIT5HeNE73zNfqGRgAAAKM"]
[Sun Aug 30 03:04:05.761680 2026] [security2:error] [pid 488281:tid 488440] [client 20.104.50.220:31869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/images/shell.php"] [unique_id "apPj9TIT5HeNE73zNfqGSwAAAKI"]
[Sun Aug 30 03:04:05.769318 2026] [authz_core:error] [pid 488281:tid 488468] [client 66.249.66.78:36530] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:05.769615 2026] [authz_core:error] [pid 488281:tid 488468] [client 66.249.66.78:36530] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:05.790089 2026] [security2:error] [pid 488281:tid 488449] [client 20.63.81.20:55518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/nz.php"] [unique_id "apPj9TIT5HeNE73zNfqGWAAAAKs"]
[Sun Aug 30 03:04:05.795505 2026] [security2:error] [pid 488669:tid 488830] [client 158.23.147.79:61441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/radio.php"] [unique_id "apPj9dRh6OewFvqQpDk6XgAAASE"]
[Sun Aug 30 03:04:05.796015 2026] [security2:error] [pid 488281:tid 488478] [client 20.48.251.3:7077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/nlnub.php"] [unique_id "apPj9TIT5HeNE73zNfqGWwAAAMg"]
[Sun Aug 30 03:04:05.797807 2026] [security2:error] [pid 488281:tid 488417] [client 20.48.251.3:51569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/php_info.php"] [unique_id "apPj9TIT5HeNE73zNfqGXAAAAIs"]
[Sun Aug 30 03:04:05.799002 2026] [security2:error] [pid 488281:tid 488451] [client 4.205.62.107:25892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/rpk.php"] [unique_id "apPj9TIT5HeNE73zNfqGXQAAAK0"]
[Sun Aug 30 03:04:05.802546 2026] [security2:error] [pid 488281:tid 488424] [client 20.104.50.220:61968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/AkuSayangKamu45.php"] [unique_id "apPj9TIT5HeNE73zNfqGXwAAAJI"]
[Sun Aug 30 03:04:05.808660 2026] [security2:error] [pid 488281:tid 488511] [client 158.23.184.117:51154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/alf.php"] [unique_id "apPj9TIT5HeNE73zNfqGZAAAAOk"]
[Sun Aug 30 03:04:05.874812 2026] [security2:error] [pid 488281:tid 488459] [client 20.220.10.235:51280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/tajj.php"] [unique_id "apPj9TIT5HeNE73zNfqGcwAAALU"]
[Sun Aug 30 03:04:05.882334 2026] [security2:error] [pid 488669:tid 488863] [client 52.139.37.240:14610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/storage/rip.php"] [unique_id "apPj9dRh6OewFvqQpDk6bAAAAUI"]
[Sun Aug 30 03:04:05.893953 2026] [security2:error] [pid 488669:tid 488866] [client 20.48.251.3:64707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lastmaskcenter.org"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPj9dRh6OewFvqQpDk6bQAAAUU"]
[Sun Aug 30 03:04:05.901155 2026] [security2:error] [pid 488281:tid 488521] [client 4.205.62.107:36629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/nw.php"] [unique_id "apPj9TIT5HeNE73zNfqGegAAAPM"]
[Sun Aug 30 03:04:05.918461 2026] [security2:error] [pid 488281:tid 488416] [client 20.104.50.220:62808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/o.php"] [unique_id "apPj9TIT5HeNE73zNfqGfgAAAIo"]
[Sun Aug 30 03:04:05.931206 2026] [security2:error] [pid 488669:tid 488913] [client 20.63.81.20:55445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/sg.php"] [unique_id "apPj9dRh6OewFvqQpDk6cQAAAXQ"]
[Sun Aug 30 03:04:05.932027 2026] [security2:error] [pid 488669:tid 488845] [client 4.205.62.107:18970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/25.php"] [unique_id "apPj9dRh6OewFvqQpDk6cgAAATA"]
[Sun Aug 30 03:04:05.966262 2026] [security2:error] [pid 488281:tid 488447] [client 4.205.62.107:42679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/wp-info.php"] [unique_id "apPj9TIT5HeNE73zNfqGiwAAAKk"]
[Sun Aug 30 03:04:05.967005 2026] [security2:error] [pid 488281:tid 488528] [client 20.104.50.220:52849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/.well-known/alfa.php"] [unique_id "apPj9TIT5HeNE73zNfqGjQAAAPo"]
[Sun Aug 30 03:04:05.991778 2026] [security2:error] [pid 488281:tid 488478] [client 20.48.251.3:65495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/server-info.php"] [unique_id "apPj9TIT5HeNE73zNfqGkwAAAMg"]
[Sun Aug 30 03:04:06.008341 2026] [security2:error] [pid 488281:tid 488517] [client 20.220.10.235:51304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/bge.php"] [unique_id "apPj9jIT5HeNE73zNfqGngAAAO8"]
[Sun Aug 30 03:04:06.040828 2026] [security2:error] [pid 488281:tid 488496] [client 4.205.62.107:65374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/wp-admin/sc.php"] [unique_id "apPj9jIT5HeNE73zNfqGoQAAANo"]
[Sun Aug 30 03:04:06.060980 2026] [security2:error] [pid 488281:tid 488415] [client 158.23.147.79:55057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPj9jIT5HeNE73zNfqGrgAAAIk"]
[Sun Aug 30 03:04:06.061132 2026] [security2:error] [pid 488281:tid 488466] [client 20.63.81.20:55390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/hypo.php"] [unique_id "apPj9jIT5HeNE73zNfqGrwAAALw"]
[Sun Aug 30 03:04:06.074903 2026] [authz_core:error] [pid 488281:tid 488502] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fnf_reject_ipv4%2Fholders%2Fipt_REJECT
[Sun Aug 30 03:04:06.074916 2026] [security2:error] [pid 488281:tid 488509] [client 34.131.221.169:33372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/old_phpinfo.php"] [unique_id "apPj9jIT5HeNE73zNfqGtQAAAOc"]
[Sun Aug 30 03:04:06.075915 2026] [authz_core:error] [pid 488281:tid 488502] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fnf_reject_ipv4%2Fholders%2Fipt_REJECT
[Sun Aug 30 03:04:06.076383 2026] [security2:error] [pid 488281:tid 488413] [client 52.139.37.240:14376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/tinyfilemanager.php"] [unique_id "apPj9jIT5HeNE73zNfqGtgAAAIc"]
[Sun Aug 30 03:04:06.089479 2026] [security2:error] [pid 488281:tid 488469] [client 20.104.49.130:52522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.katbacon.com"] [uri "/wp-the.php"] [unique_id "apPj9jIT5HeNE73zNfqGuAAAAL8"]
[Sun Aug 30 03:04:06.094548 2026] [security2:error] [pid 488669:tid 488814] [client 4.205.62.107:63953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/groceries/index.php"] [unique_id "apPj9tRh6OewFvqQpDk6igAAARE"]
[Sun Aug 30 03:04:06.135184 2026] [authz_core:error] [pid 488281:tid 488424] [client 66.249.66.32:60435] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:06.135531 2026] [authz_core:error] [pid 488281:tid 488424] [client 66.249.66.32:60435] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:06.139875 2026] [security2:error] [pid 488669:tid 488888] [client 20.220.10.235:51288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/ssh3ll.php"] [unique_id "apPj9tRh6OewFvqQpDk6lAAAAVs"]
[Sun Aug 30 03:04:06.182734 2026] [security2:error] [pid 488281:tid 488447] [client 158.23.147.79:55200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/makeasmtp.php"] [unique_id "apPj9jIT5HeNE73zNfqG3QAAAKk"]
[Sun Aug 30 03:04:06.191263 2026] [security2:error] [pid 488281:tid 488501] [client 20.48.251.3:7366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/configuration.php"] [unique_id "apPj9jIT5HeNE73zNfqG5QAAAN8"]
[Sun Aug 30 03:04:06.193471 2026] [security2:error] [pid 488281:tid 488505] [client 20.104.49.130:40244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.topatrust.com"] [uri "/wen.php"] [unique_id "apPj9jIT5HeNE73zNfqG6AAAAOM"]
[Sun Aug 30 03:04:06.204431 2026] [security2:error] [pid 488281:tid 488479] [client 20.63.81.20:55500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/Hd.php"] [unique_id "apPj9jIT5HeNE73zNfqG8AAAAMk"]
[Sun Aug 30 03:04:06.225923 2026] [security2:error] [pid 488281:tid 488490] [client 68.155.159.216:60550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-content/radio.php"] [unique_id "apPj9jIT5HeNE73zNfqG-wAAANQ"]
[Sun Aug 30 03:04:06.230931 2026] [security2:error] [pid 488669:tid 488851] [client 34.131.221.169:33384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/server-status.php"] [unique_id "apPj9tRh6OewFvqQpDk6rgAAATY"]
[Sun Aug 30 03:04:06.287906 2026] [security2:error] [pid 488281:tid 488466] [client 20.220.10.235:51284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/motu.php"] [unique_id "apPj9jIT5HeNE73zNfqHFwAAALw"]
[Sun Aug 30 03:04:06.303679 2026] [security2:error] [pid 488669:tid 488914] [client 158.23.147.79:55089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apPj9tRh6OewFvqQpDk6xAAAAXU"]
[Sun Aug 30 03:04:06.338149 2026] [security2:error] [pid 488281:tid 488525] [client 52.139.37.240:15096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/403.php"] [unique_id "apPj9jIT5HeNE73zNfqHMwAAAPc"]
[Sun Aug 30 03:04:06.344542 2026] [security2:error] [pid 488669:tid 488848] [client 20.63.81.20:55466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/im.php"] [unique_id "apPj9tRh6OewFvqQpDk6zQAAATM"]
[Sun Aug 30 03:04:06.359761 2026] [authz_core:error] [pid 488281:tid 488523] [client 216.73.216.128:35778] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:06.360180 2026] [authz_core:error] [pid 488281:tid 488523] [client 216.73.216.128:35778] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:06.386104 2026] [security2:error] [pid 488281:tid 488534] [client 4.205.62.107:53519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.diamondsintheroughpark.com"] [uri "/old_phpinfo.php"] [unique_id "apPj9jIT5HeNE73zNfqHTgAAAQA"]
[Sun Aug 30 03:04:06.402474 2026] [authz_core:error] [pid 488669:tid 488912] [client 66.249.66.65:61944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:06.402954 2026] [authz_core:error] [pid 488669:tid 488912] [client 66.249.66.65:61944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:06.430624 2026] [security2:error] [pid 488669:tid 488845] [client 20.220.10.235:51309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/wefile.php"] [unique_id "apPj9tRh6OewFvqQpDk66AAAATA"]
[Sun Aug 30 03:04:06.448760 2026] [security2:error] [pid 488281:tid 488505] [client 4.205.62.107:26523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/config/laravolt/css/index.php"] [unique_id "apPj9jIT5HeNE73zNfqHfgAAAOM"]
[Sun Aug 30 03:04:06.480968 2026] [security2:error] [pid 488281:tid 488487] [client 20.63.81.20:55396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/fc.php"] [unique_id "apPj9jIT5HeNE73zNfqHnQAAANE"]
[Sun Aug 30 03:04:06.527168 2026] [security2:error] [pid 488281:tid 488413] [client 158.23.147.79:55080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apPj9jIT5HeNE73zNfqHvgAAAIc"]
[Sun Aug 30 03:04:06.535556 2026] [security2:error] [pid 488281:tid 488509] [client 52.139.37.240:15085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/av.php"] [unique_id "apPj9jIT5HeNE73zNfqHwQAAAOc"]
[Sun Aug 30 03:04:06.542788 2026] [authz_core:error] [pid 488281:tid 488411] [client 216.73.216.128:51358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:06.543098 2026] [authz_core:error] [pid 488281:tid 488411] [client 216.73.216.128:51358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:06.563047 2026] [security2:error] [pid 488281:tid 488442] [client 20.220.10.235:51313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/Contrller.php"] [unique_id "apPj9jIT5HeNE73zNfqH1QAAAKQ"]
[Sun Aug 30 03:04:06.573236 2026] [security2:error] [pid 488281:tid 488496] [client 4.205.62.107:62420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/a1vx.php"] [unique_id "apPj9jIT5HeNE73zNfqH1gAAANo"]
[Sun Aug 30 03:04:06.582051 2026] [security2:error] [pid 488281:tid 488505] [client 4.205.62.107:60562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/queue.php"] [unique_id "apPj9jIT5HeNE73zNfqH2QAAAOM"]
[Sun Aug 30 03:04:06.596840 2026] [security2:error] [pid 488281:tid 488527] [client 68.155.159.216:52702] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.onthedomain.com"] [uri "/1.php"] [unique_id "apPj9jIT5HeNE73zNfqH4AAAAPk"]
[Sun Aug 30 03:04:06.596944 2026] [security2:error] [pid 488281:tid 488527] [client 68.155.159.216:52702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/1.php"] [unique_id "apPj9jIT5HeNE73zNfqH4AAAAPk"]
[Sun Aug 30 03:04:06.607164 2026] [security2:error] [pid 488281:tid 488524] [client 20.63.81.20:55454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/ke.php"] [unique_id "apPj9jIT5HeNE73zNfqH6QAAAPY"]
[Sun Aug 30 03:04:06.610872 2026] [authz_core:error] [pid 488281:tid 488455] [client 66.249.66.77:39521] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:06.611135 2026] [authz_core:error] [pid 488281:tid 488455] [client 66.249.66.77:39521] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:06.611785 2026] [authz_core:error] [pid 488281:tid 488522] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fdpkg
[Sun Aug 30 03:04:06.612218 2026] [authz_core:error] [pid 488281:tid 488522] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fdpkg
[Sun Aug 30 03:04:06.628662 2026] [security2:error] [pid 488281:tid 488511] [client 20.104.49.130:52335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.katbacon.com"] [uri "/155.php"] [unique_id "apPj9jIT5HeNE73zNfqH9AAAAOk"]
[Sun Aug 30 03:04:06.638328 2026] [security2:error] [pid 488281:tid 488458] [client 4.205.62.107:44750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apPj9jIT5HeNE73zNfqH9QAAALQ"]
[Sun Aug 30 03:04:06.691133 2026] [security2:error] [pid 488281:tid 488456] [client 158.23.147.79:55204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-content/languages/about.php"] [unique_id "apPj9jIT5HeNE73zNfqIBwAAALI"]
[Sun Aug 30 03:04:06.700335 2026] [security2:error] [pid 488669:tid 488868] [client 20.220.10.235:51272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/file66.php"] [unique_id "apPj9tRh6OewFvqQpDk7NwAAAUc"]
[Sun Aug 30 03:04:06.715730 2026] [security2:error] [pid 488669:tid 488869] [client 20.104.50.220:30286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/compat.php"] [unique_id "apPj9tRh6OewFvqQpDk7OwAAAUg"]
[Sun Aug 30 03:04:06.737828 2026] [security2:error] [pid 488669:tid 488914] [client 20.63.81.20:55432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/tf.php"] [unique_id "apPj9tRh6OewFvqQpDk7PgAAAXU"]
[Sun Aug 30 03:04:06.748969 2026] [security2:error] [pid 488281:tid 488501] [client 20.48.251.3:52811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/fff.php"] [unique_id "apPj9jIT5HeNE73zNfqIFAAAAN8"]
[Sun Aug 30 03:04:06.751514 2026] [security2:error] [pid 488281:tid 488426] [client 52.139.37.240:14365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/wp-admin/index.php"] [unique_id "apPj9jIT5HeNE73zNfqIFgAAAJQ"]
[Sun Aug 30 03:04:06.756377 2026] [security2:error] [pid 488281:tid 488484] [client 20.104.50.220:5533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wsd.php"] [unique_id "apPj9jIT5HeNE73zNfqIGwAAAM4"]
[Sun Aug 30 03:04:06.761820 2026] [security2:error] [pid 488669:tid 488850] [client 20.48.251.3:23338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/server-info.php"] [unique_id "apPj9tRh6OewFvqQpDk7QQAAATU"]
[Sun Aug 30 03:04:06.764837 2026] [security2:error] [pid 488669:tid 488891] [client 20.104.50.220:46902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/tuco.php"] [unique_id "apPj9tRh6OewFvqQpDk7QgAAAV4"]
[Sun Aug 30 03:04:06.774042 2026] [security2:error] [pid 488281:tid 488514] [client 4.205.62.107:52158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/mcebraed.php"] [unique_id "apPj9jIT5HeNE73zNfqIIwAAAOw"]
[Sun Aug 30 03:04:06.775828 2026] [security2:error] [pid 488281:tid 488521] [client 4.205.62.107:2971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/thui.php"] [unique_id "apPj9jIT5HeNE73zNfqIJQAAAPM"]
[Sun Aug 30 03:04:06.799458 2026] [security2:error] [pid 488281:tid 488475] [client 20.104.49.130:26897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trinitytechnologics.com"] [uri "/ws85.php"] [unique_id "apPj9jIT5HeNE73zNfqIMgAAAMU"]
[Sun Aug 30 03:04:06.801052 2026] [security2:error] [pid 488281:tid 488412] [client 4.205.62.107:4114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/admin-ajax.php"] [unique_id "apPj9jIT5HeNE73zNfqIMwAAAIY"]
[Sun Aug 30 03:04:06.805760 2026] [security2:error] [pid 488669:tid 488855] [client 20.104.50.220:63539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/images/priv8.php"] [unique_id "apPj9tRh6OewFvqQpDk7RgAAATo"]
[Sun Aug 30 03:04:06.811051 2026] [security2:error] [pid 488669:tid 488844] [client 20.104.50.220:33289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-config-blog.php"] [unique_id "apPj9tRh6OewFvqQpDk7RwAAAS8"]
[Sun Aug 30 03:04:06.836137 2026] [security2:error] [pid 488281:tid 488447] [client 20.220.10.235:51290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/blnux.php"] [unique_id "apPj9jIT5HeNE73zNfqIPAAAAKk"]
[Sun Aug 30 03:04:06.852678 2026] [security2:error] [pid 488281:tid 488452] [client 20.48.251.3:55518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/pinfo.php"] [unique_id "apPj9jIT5HeNE73zNfqIPwAAAK4"]
[Sun Aug 30 03:04:06.857751 2026] [security2:error] [pid 488669:tid 488830] [client 158.23.147.79:55193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-content/banners/about.php"] [unique_id "apPj9tRh6OewFvqQpDk7TAAAASE"]
[Sun Aug 30 03:04:06.861921 2026] [security2:error] [pid 488281:tid 488456] [client 158.23.184.117:51144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/wp-admin/import.php"] [unique_id "apPj9jIT5HeNE73zNfqIQgAAALI"]
[Sun Aug 30 03:04:06.862733 2026] [security2:error] [pid 488281:tid 488416] [client 20.104.18.15:9101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/inx.php"] [unique_id "apPj9jIT5HeNE73zNfqIQwAAAIo"]
[Sun Aug 30 03:04:06.866205 2026] [security2:error] [pid 488281:tid 488427] [client 20.63.81.20:55368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/px.php"] [unique_id "apPj9jIT5HeNE73zNfqIRQAAAJU"]
[Sun Aug 30 03:04:06.867656 2026] [security2:error] [pid 488281:tid 488450] [client 20.104.18.15:3881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1800rlawyer.com"] [uri "/rxr.php"] [unique_id "apPj9jIT5HeNE73zNfqIRgAAAKw"]
[Sun Aug 30 03:04:06.897432 2026] [security2:error] [pid 488281:tid 488479] [client 34.131.221.169:47460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/server-info.php"] [unique_id "apPj9jIT5HeNE73zNfqISwAAAMk"]
[Sun Aug 30 03:04:06.898767 2026] [security2:error] [pid 488281:tid 488439] [client 20.104.18.15:31575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/domvf.php"] [unique_id "apPj9jIT5HeNE73zNfqITQAAAKE"]
[Sun Aug 30 03:04:06.911249 2026] [security2:error] [pid 488281:tid 488496] [client 20.104.50.220:32085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/images/mini.php"] [unique_id "apPj9jIT5HeNE73zNfqIUgAAANo"]
[Sun Aug 30 03:04:06.944020 2026] [security2:error] [pid 488281:tid 488442] [client 52.139.37.240:14372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "apPj9jIT5HeNE73zNfqIWAAAAKQ"]
[Sun Aug 30 03:04:06.947422 2026] [security2:error] [pid 488281:tid 488464] [client 4.205.62.107:25763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/saml.php"] [unique_id "apPj9jIT5HeNE73zNfqIWwAAALo"]
[Sun Aug 30 03:04:06.950536 2026] [security2:error] [pid 488669:tid 488865] [client 20.48.251.3:7423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/mga.php"] [unique_id "apPj9tRh6OewFvqQpDk7VAAAAUQ"]
[Sun Aug 30 03:04:06.965010 2026] [security2:error] [pid 488281:tid 488475] [client 20.48.251.3:34563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/session.php"] [unique_id "apPj9jIT5HeNE73zNfqIYwAAAMU"]
[Sun Aug 30 03:04:06.968169 2026] [security2:error] [pid 488281:tid 488412] [client 158.23.147.79:55063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apPj9jIT5HeNE73zNfqIZwAAAIY"]
[Sun Aug 30 03:04:06.969423 2026] [security2:error] [pid 488669:tid 488842] [client 20.220.10.235:51369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/attack.php"] [unique_id "apPj9tRh6OewFvqQpDk7VgAAAS0"]
[Sun Aug 30 03:04:06.990191 2026] [security2:error] [pid 488281:tid 488463] [client 4.205.62.107:32034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/wp-class.php"] [unique_id "apPj9jIT5HeNE73zNfqIbwAAALk"]
[Sun Aug 30 03:04:07.000245 2026] [security2:error] [pid 488281:tid 488500] [client 20.63.81.20:55361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/jg.php"] [unique_id "apPj9jIT5HeNE73zNfqIdgAAAN4"]
[Sun Aug 30 03:04:07.002669 2026] [security2:error] [pid 488669:tid 488884] [client 20.104.50.220:61975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/googlebots.php"] [unique_id "apPj99Rh6OewFvqQpDk7YgAAAVc"]
[Sun Aug 30 03:04:07.004893 2026] [security2:error] [pid 488669:tid 488897] [client 158.23.184.117:51180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "apPj99Rh6OewFvqQpDk7YwAAAWQ"]
[Sun Aug 30 03:04:07.036350 2026] [security2:error] [pid 488669:tid 488913] [client 20.48.251.3:29981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lastmaskcenter.org"] [uri "/agg.php"] [unique_id "apPj99Rh6OewFvqQpDk7ZgAAAXQ"]
[Sun Aug 30 03:04:07.071437 2026] [security2:error] [pid 488281:tid 488503] [client 4.205.62.107:18771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/nlnub.php"] [unique_id "apPj9zIT5HeNE73zNfqIiQAAAOE"]
[Sun Aug 30 03:04:07.096800 2026] [security2:error] [pid 488669:tid 488840] [client 20.104.50.220:29345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/m.php"] [unique_id "apPj99Rh6OewFvqQpDk7cwAAASs"]
[Sun Aug 30 03:04:07.102170 2026] [security2:error] [pid 488281:tid 488480] [client 20.220.10.235:51316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/wk/index.php"] [unique_id "apPj9zIT5HeNE73zNfqIlAAAAMo"]
[Sun Aug 30 03:04:07.110686 2026] [authz_core:error] [pid 488281:tid 488468] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fwget
[Sun Aug 30 03:04:07.111129 2026] [authz_core:error] [pid 488281:tid 488468] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fwget
[Sun Aug 30 03:04:07.121258 2026] [security2:error] [pid 488281:tid 488420] [client 20.48.251.3:64313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/gk.php"] [unique_id "apPj9zIT5HeNE73zNfqInAAAAI4"]
[Sun Aug 30 03:04:07.129069 2026] [security2:error] [pid 488669:tid 488850] [client 20.63.81.20:55471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/yj.php"] [unique_id "apPj99Rh6OewFvqQpDk7eQAAATU"]
[Sun Aug 30 03:04:07.136326 2026] [security2:error] [pid 488281:tid 488509] [client 52.139.37.240:14358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/wp-content/themes/pridmag/b.php"] [unique_id "apPj9zIT5HeNE73zNfqIoQAAAOc"]
[Sun Aug 30 03:04:07.159044 2026] [cgid:error] [pid 488669:tid 488817] [client 158.23.184.117:60312] AH01265: stderr from /home1/petrajor/public_html/cgi-bin/: attempt to invoke directory as script
[Sun Aug 30 03:04:07.167764 2026] [security2:error] [pid 488281:tid 488422] [client 158.23.147.79:55207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/asd.php"] [unique_id "apPj9zIT5HeNE73zNfqItQAAAJA"]
[Sun Aug 30 03:04:07.195194 2026] [security2:error] [pid 488669:tid 488836] [client 20.104.50.220:52862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/.well-known/wso.php"] [unique_id "apPj99Rh6OewFvqQpDk7jQAAASc"]
[Sun Aug 30 03:04:07.226435 2026] [security2:error] [pid 488669:tid 488920] [client 4.205.62.107:65383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/debug.php"] [unique_id "apPj99Rh6OewFvqQpDk7lAAAAXs"]
[Sun Aug 30 03:04:07.233008 2026] [security2:error] [pid 488281:tid 488432] [client 20.220.10.235:51337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/dehnl.php"] [unique_id "apPj9zIT5HeNE73zNfqI5gAAAJo"]
[Sun Aug 30 03:04:07.233903 2026] [security2:error] [pid 488281:tid 488429] [client 4.205.62.107:64061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/konfig.php"] [unique_id "apPj9zIT5HeNE73zNfqI6AAAAJc"]
[Sun Aug 30 03:04:07.235820 2026] [security2:error] [pid 488281:tid 488416] [client 4.205.62.107:36675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/product.php"] [unique_id "apPj9zIT5HeNE73zNfqI6QAAAIo"]
[Sun Aug 30 03:04:07.263875 2026] [security2:error] [pid 488669:tid 488884] [client 20.63.81.20:55457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/zi.php"] [unique_id "apPj99Rh6OewFvqQpDk7owAAAVc"]
[Sun Aug 30 03:04:07.284481 2026] [security2:error] [pid 488669:tid 488896] [client 158.23.147.79:55067] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/1.php"] [unique_id "apPj99Rh6OewFvqQpDk7qgAAAWM"]
[Sun Aug 30 03:04:07.284625 2026] [security2:error] [pid 488669:tid 488896] [client 158.23.147.79:55067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/1.php"] [unique_id "apPj99Rh6OewFvqQpDk7qgAAAWM"]
[Sun Aug 30 03:04:07.307485 2026] [autoindex:error] [pid 488669:tid 488852] [client 158.23.184.117:60312] AH01276: Cannot serve directory /home1/petrajor/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:04:07.317488 2026] [authz_core:error] [pid 488669:tid 488824] [client 66.249.66.193:36705] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:07.317950 2026] [authz_core:error] [pid 488669:tid 488824] [client 66.249.66.193:36705] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:07.353798 2026] [security2:error] [pid 488669:tid 488832] [client 158.23.184.117:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/wp-admin/admin-post.php"] [unique_id "apPj99Rh6OewFvqQpDk7ugAAASM"]
[Sun Aug 30 03:04:07.359097 2026] [security2:error] [pid 488281:tid 488487] [client 20.220.10.235:51318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/png.php"] [unique_id "apPj9zIT5HeNE73zNfqJJAAAANE"]
[Sun Aug 30 03:04:07.362494 2026] [security2:error] [pid 488669:tid 488914] [client 20.104.49.130:57661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/zoo2.php"] [unique_id "apPj99Rh6OewFvqQpDk7uwAAAXU"]
[Sun Aug 30 03:04:07.378447 2026] [security2:error] [pid 488281:tid 488427] [client 68.155.159.216:52842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-admin/dropdown.php"] [unique_id "apPj9zIT5HeNE73zNfqJMAAAAJU"]
[Sun Aug 30 03:04:07.389772 2026] [security2:error] [pid 488281:tid 488449] [client 20.63.81.20:55544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/ue.php"] [unique_id "apPj9zIT5HeNE73zNfqJOgAAAKs"]
[Sun Aug 30 03:04:07.392714 2026] [security2:error] [pid 488669:tid 488813] [client 52.139.37.240:14392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/0.php"] [unique_id "apPj99Rh6OewFvqQpDk7xgAAARA"]
[Sun Aug 30 03:04:07.430960 2026] [security2:error] [pid 488669:tid 488877] [client 158.23.147.79:55199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/ws.php"] [unique_id "apPj99Rh6OewFvqQpDk72QAAAVA"]
[Sun Aug 30 03:04:07.490725 2026] [security2:error] [pid 488281:tid 488450] [client 158.23.184.117:60288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/favicon.php"] [unique_id "apPj9zIT5HeNE73zNfqJkAAAAKw"]
[Sun Aug 30 03:04:07.499087 2026] [security2:error] [pid 488669:tid 488844] [client 20.220.10.235:51372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/txets.php"] [unique_id "apPj99Rh6OewFvqQpDk8AAAAAS8"]
[Sun Aug 30 03:04:07.519513 2026] [security2:error] [pid 488281:tid 488412] [client 20.63.81.20:55364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/nv.php"] [unique_id "apPj9zIT5HeNE73zNfqJoAAAAIY"]
[Sun Aug 30 03:04:07.523589 2026] [security2:error] [pid 488281:tid 488436] [client 20.104.18.15:3845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lakewoodshuttle.deevosdesigns.com"] [uri "/wp-includes/ID3/moon.php"] [unique_id "apPj9zIT5HeNE73zNfqJogAAAJ4"]
[Sun Aug 30 03:04:07.526589 2026] [security2:error] [pid 488281:tid 488446] [client 4.205.62.107:53558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.diamondsintheroughpark.com"] [uri "/wp-act.php"] [unique_id "apPj9zIT5HeNE73zNfqJpgAAAKg"]
[Sun Aug 30 03:04:07.538635 2026] [security2:error] [pid 488281:tid 488472] [client 34.131.221.169:47466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/webroot/index.php/_environment"] [unique_id "apPj9zIT5HeNE73zNfqJqgAAAMI"]
[Sun Aug 30 03:04:07.572013 2026] [security2:error] [pid 488281:tid 488487] [client 4.205.62.107:42569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/fns.php"] [unique_id "apPj9zIT5HeNE73zNfqJvAAAANE"]
[Sun Aug 30 03:04:07.584367 2026] [security2:error] [pid 488281:tid 488447] [client 52.139.37.240:15087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/autoload_classmap/function.php"] [unique_id "apPj9zIT5HeNE73zNfqJvgAAAKk"]
[Sun Aug 30 03:04:07.627785 2026] [authz_core:error] [pid 488281:tid 488416] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fkmod
[Sun Aug 30 03:04:07.628227 2026] [authz_core:error] [pid 488281:tid 488416] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fkmod
[Sun Aug 30 03:04:07.630271 2026] [security2:error] [pid 488281:tid 488422] [client 20.220.10.235:51264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/wp-login.php"] [unique_id "apPj9zIT5HeNE73zNfqJzwAAAJA"]
[Sun Aug 30 03:04:07.631634 2026] [security2:error] [pid 488281:tid 488430] [client 158.23.184.117:51174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/wp-admin/css/my.php"] [unique_id "apPj9zIT5HeNE73zNfqJ0AAAAJg"]
[Sun Aug 30 03:04:07.641840 2026] [security2:error] [pid 488669:tid 488833] [client 158.23.147.79:55179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-includes/css/index.php"] [unique_id "apPj99Rh6OewFvqQpDk8GwAAASQ"]
[Sun Aug 30 03:04:07.646991 2026] [security2:error] [pid 488281:tid 488528] [client 20.63.81.20:55406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/jw.php"] [unique_id "apPj9zIT5HeNE73zNfqJ0wAAAPo"]
[Sun Aug 30 03:04:07.664923 2026] [security2:error] [pid 488669:tid 488821] [client 34.131.221.169:47468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/server-status.php"] [unique_id "apPj99Rh6OewFvqQpDk8HwAAARg"]
[Sun Aug 30 03:04:07.702015 2026] [security2:error] [pid 488281:tid 488483] [client 68.155.159.216:52675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/ws.php"] [unique_id "apPj9zIT5HeNE73zNfqJ6wAAAM0"]
[Sun Aug 30 03:04:07.710484 2026] [security2:error] [pid 488281:tid 488499] [client 4.205.62.107:22578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/public/vx.php"] [unique_id "apPj9zIT5HeNE73zNfqJ7QAAAN0"]
[Sun Aug 30 03:04:07.718297 2026] [security2:error] [pid 488281:tid 488518] [client 4.205.62.107:26556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/87.php"] [unique_id "apPj9zIT5HeNE73zNfqJ7wAAAPA"]
[Sun Aug 30 03:04:07.760982 2026] [security2:error] [pid 488669:tid 488883] [client 20.220.10.235:51308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/wp-access.php"] [unique_id "apPj99Rh6OewFvqQpDk8KQAAAVY"]
[Sun Aug 30 03:04:07.774624 2026] [security2:error] [pid 488281:tid 488427] [client 4.205.62.107:44456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/hochladen.form.php"] [unique_id "apPj9zIT5HeNE73zNfqJ_QAAAJU"]
[Sun Aug 30 03:04:07.775583 2026] [security2:error] [pid 488669:tid 488899] [client 158.23.184.117:60319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/wp-content/images/doc.php"] [unique_id "apPj99Rh6OewFvqQpDk8LAAAAWY"]
[Sun Aug 30 03:04:07.787821 2026] [security2:error] [pid 488281:tid 488431] [client 20.63.81.20:55369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/or.php"] [unique_id "apPj9zIT5HeNE73zNfqKBQAAAJk"]
[Sun Aug 30 03:04:07.795759 2026] [security2:error] [pid 488281:tid 488514] [client 52.139.37.240:14339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/dvve.php"] [unique_id "apPj9zIT5HeNE73zNfqKCQAAAOw"]
[Sun Aug 30 03:04:07.803666 2026] [security2:error] [pid 488281:tid 488538] [client 158.23.147.79:55230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apPj9zIT5HeNE73zNfqKDgAAAQQ"]
[Sun Aug 30 03:04:07.854103 2026] [security2:error] [pid 488281:tid 488481] [client 20.104.50.220:29840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/class-wpdb.php"] [unique_id "apPj9zIT5HeNE73zNfqKIAAAAMs"]
[Sun Aug 30 03:04:07.886328 2026] [security2:error] [pid 488281:tid 488429] [client 20.48.251.3:59273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/autogooey.php"] [unique_id "apPj9zIT5HeNE73zNfqKJwAAAJc"]
[Sun Aug 30 03:04:07.890260 2026] [security2:error] [pid 488281:tid 488500] [client 20.220.10.235:51333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/wp-content/admin.php"] [unique_id "apPj9zIT5HeNE73zNfqKKAAAAN4"]
[Sun Aug 30 03:04:07.911751 2026] [security2:error] [pid 488281:tid 488495] [client 20.48.251.3:23473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/gk.php"] [unique_id "apPj9zIT5HeNE73zNfqKLgAAANk"]
[Sun Aug 30 03:04:07.911849 2026] [security2:error] [pid 488281:tid 488478] [client 20.104.50.220:5583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/gtc.php"] [unique_id "apPj9zIT5HeNE73zNfqKLwAAAMg"]
[Sun Aug 30 03:04:07.912286 2026] [security2:error] [pid 488281:tid 488453] [client 20.104.50.220:47083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/ice.php"] [unique_id "apPj9zIT5HeNE73zNfqKMQAAAK8"]
[Sun Aug 30 03:04:07.912331 2026] [security2:error] [pid 488281:tid 488428] [client 4.205.62.107:2775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/file21.php"] [unique_id "apPj9zIT5HeNE73zNfqKMAAAAJY"]
[Sun Aug 30 03:04:07.928134 2026] [security2:error] [pid 488281:tid 488461] [client 4.205.62.107:56607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/server-info.php"] [unique_id "apPj9zIT5HeNE73zNfqKNwAAALc"]
[Sun Aug 30 03:04:07.928260 2026] [security2:error] [pid 488281:tid 488490] [client 20.63.81.20:55404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/ile56.php"] [unique_id "apPj9zIT5HeNE73zNfqKOAAAANQ"]
[Sun Aug 30 03:04:07.938518 2026] [security2:error] [pid 488281:tid 488413] [client 158.23.184.117:51198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/wp-comments.php"] [unique_id "apPj9zIT5HeNE73zNfqKMgAAAIc"]
[Sun Aug 30 03:04:07.940550 2026] [security2:error] [pid 488669:tid 488913] [client 20.104.50.220:51612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/Xploit.php"] [unique_id "apPj99Rh6OewFvqQpDk8NwAAAXQ"]
[Sun Aug 30 03:04:07.943341 2026] [security2:error] [pid 488281:tid 488513] [client 20.104.49.130:54356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.topatrust.com"] [uri "/Jcrop.php"] [unique_id "apPj9zIT5HeNE73zNfqKOwAAAOs"]
[Sun Aug 30 03:04:07.953834 2026] [security2:error] [pid 488281:tid 488492] [client 158.23.147.79:55191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-content/cong.php"] [unique_id "apPj9zIT5HeNE73zNfqKQQAAANY"]
[Sun Aug 30 03:04:07.964196 2026] [security2:error] [pid 488281:tid 488509] [client 20.104.50.220:32883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-thumbs.php"] [unique_id "apPj9zIT5HeNE73zNfqKTQAAAOc"]
[Sun Aug 30 03:04:07.965221 2026] [authz_core:error] [pid 488281:tid 488520] [client 66.249.66.205:53191] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:07.965513 2026] [authz_core:error] [pid 488281:tid 488520] [client 66.249.66.205:53191] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:07.986526 2026] [security2:error] [pid 488281:tid 488429] [client 20.48.251.3:55456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/X57.php"] [unique_id "apPj9zIT5HeNE73zNfqKWwAAAJc"]
[Sun Aug 30 03:04:08.006131 2026] [security2:error] [pid 488669:tid 488848] [client 20.104.18.15:3793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "1800rlawyer.com"] [uri "/reviall.php"] [unique_id "apPj-NRh6OewFvqQpDk8RAAAATM"]
[Sun Aug 30 03:04:08.007194 2026] [authz_core:error] [pid 488281:tid 488523] [client 216.73.216.128:35778] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:08.007458 2026] [authz_core:error] [pid 488281:tid 488523] [client 216.73.216.128:35778] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:08.009407 2026] [security2:error] [pid 488669:tid 488895] [client 20.104.18.15:9192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/vpn.php"] [unique_id "apPj-NRh6OewFvqQpDk8RgAAAWI"]
[Sun Aug 30 03:04:08.013020 2026] [security2:error] [pid 488669:tid 488814] [client 4.205.62.107:4119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/ms.php"] [unique_id "apPj-NRh6OewFvqQpDk8SAAAARE"]
[Sun Aug 30 03:04:08.025309 2026] [security2:error] [pid 488669:tid 488873] [client 20.220.10.235:51289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/log.php"] [unique_id "apPj-NRh6OewFvqQpDk8SwAAAUw"]
[Sun Aug 30 03:04:08.052558 2026] [security2:error] [pid 488281:tid 488449] [client 52.139.37.240:15078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/ws77.php"] [unique_id "apPj-DIT5HeNE73zNfqKbwAAAKs"]
[Sun Aug 30 03:04:08.055760 2026] [security2:error] [pid 488669:tid 488915] [client 20.104.50.220:32072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/images/mar.php"] [unique_id "apPj-NRh6OewFvqQpDk8TwAAAXY"]
[Sun Aug 30 03:04:08.056492 2026] [security2:error] [pid 488669:tid 488904] [client 20.63.81.20:55472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/emmh.php"] [unique_id "apPj-NRh6OewFvqQpDk8UAAAAWs"]
[Sun Aug 30 03:04:08.080635 2026] [security2:error] [pid 488669:tid 488823] [client 158.23.184.117:60303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/wp-includes/panel.php"] [unique_id "apPj-NRh6OewFvqQpDk8VgAAARo"]
[Sun Aug 30 03:04:08.090653 2026] [security2:error] [pid 488281:tid 488457] [client 20.48.251.3:7095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/ccou.php"] [unique_id "apPj-DIT5HeNE73zNfqKdgAAALM"]
[Sun Aug 30 03:04:08.099429 2026] [authz_core:error] [pid 488281:tid 488425] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fnf_reject_ipv6%2Fholders%2Fip6t_REJECT
[Sun Aug 30 03:04:08.099880 2026] [authz_core:error] [pid 488281:tid 488425] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fnf_reject_ipv6%2Fholders%2Fip6t_REJECT
[Sun Aug 30 03:04:08.100981 2026] [security2:error] [pid 488669:tid 488820] [client 20.104.18.15:31656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/biufile.php"] [unique_id "apPj-NRh6OewFvqQpDk8WQAAARc"]
[Sun Aug 30 03:04:08.153052 2026] [security2:error] [pid 488669:tid 488896] [client 20.220.10.235:51305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/xwpg.php"] [unique_id "apPj-NRh6OewFvqQpDk8XwAAAWM"]
[Sun Aug 30 03:04:08.163520 2026] [security2:error] [pid 488281:tid 488498] [client 4.205.62.107:25521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/aws_settings.php"] [unique_id "apPj-DIT5HeNE73zNfqKlgAAANw"]
[Sun Aug 30 03:04:08.165026 2026] [security2:error] [pid 488281:tid 488536] [client 20.48.251.3:51580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/h.php"] [unique_id "apPj-DIT5HeNE73zNfqKlwAAAQI"]
[Sun Aug 30 03:04:08.174919 2026] [security2:error] [pid 488669:tid 488874] [client 158.23.147.79:55217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPj-NRh6OewFvqQpDk8aQAAAU0"]
[Sun Aug 30 03:04:08.190246 2026] [security2:error] [pid 488669:tid 488877] [client 20.48.251.3:64718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lastmaskcenter.org"] [uri "/requirements.php"] [unique_id "apPj-NRh6OewFvqQpDk8cQAAAVA"]
[Sun Aug 30 03:04:08.196792 2026] [authz_core:error] [pid 488281:tid 488449] [client 66.249.66.197:46278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:08.197154 2026] [authz_core:error] [pid 488281:tid 488449] [client 66.249.66.197:46278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:08.208474 2026] [security2:error] [pid 488281:tid 488492] [client 4.205.62.107:18972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/mga.php"] [unique_id "apPj-DIT5HeNE73zNfqKtQAAANY"]
[Sun Aug 30 03:04:08.220076 2026] [security2:error] [pid 488281:tid 488534] [client 20.63.81.20:55362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/em.php"] [unique_id "apPj-DIT5HeNE73zNfqKvQAAAQA"]
[Sun Aug 30 03:04:08.245598 2026] [security2:error] [pid 488281:tid 488526] [client 20.104.50.220:62012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/ben.php"] [unique_id "apPj-DIT5HeNE73zNfqKyAAAAPg"]
[Sun Aug 30 03:04:08.263883 2026] [security2:error] [pid 488669:tid 488929] [client 52.139.37.240:15041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/admin/function.php"] [unique_id "apPj-NRh6OewFvqQpDk8iQAAAYQ"]
[Sun Aug 30 03:04:08.275116 2026] [security2:error] [pid 488669:tid 488876] [client 20.104.50.220:29146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/l.php"] [unique_id "apPj-NRh6OewFvqQpDk8jAAAAU8"]
[Sun Aug 30 03:04:08.279969 2026] [security2:error] [pid 488281:tid 488496] [client 158.23.184.117:51186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/www.php"] [unique_id "apPj-DIT5HeNE73zNfqK2gAAANo"]
[Sun Aug 30 03:04:08.287383 2026] [security2:error] [pid 488281:tid 488506] [client 20.220.10.235:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/sxxb.php"] [unique_id "apPj-DIT5HeNE73zNfqK3AAAAOQ"]
[Sun Aug 30 03:04:08.291905 2026] [security2:error] [pid 488281:tid 488415] [client 20.48.251.3:46259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/god.php"] [unique_id "apPj-DIT5HeNE73zNfqK3gAAAIk"]
[Sun Aug 30 03:04:08.295193 2026] [security2:error] [pid 488669:tid 488819] [client 34.131.221.169:47474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/mail/phpinfo.php"] [unique_id "apPj-NRh6OewFvqQpDk8mAAAARY"]
[Sun Aug 30 03:04:08.323696 2026] [security2:error] [pid 488281:tid 488444] [client 158.23.147.79:62836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPj-DIT5HeNE73zNfqK8QAAAKY"]
[Sun Aug 30 03:04:08.345763 2026] [security2:error] [pid 488281:tid 488436] [client 20.63.81.20:55315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/dvve.php"] [unique_id "apPj-DIT5HeNE73zNfqK_QAAAJ4"]
[Sun Aug 30 03:04:08.351656 2026] [security2:error] [pid 488281:tid 488428] [client 20.104.50.220:52817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/.well-known/java.php"] [unique_id "apPj-DIT5HeNE73zNfqLAAAAAJY"]
[Sun Aug 30 03:04:08.365964 2026] [security2:error] [pid 488669:tid 488859] [client 136.92.30.49:43808] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/.env"] [unique_id "apPj-NRh6OewFvqQpDk8pgAAAT4"]
[Sun Aug 30 03:04:08.366266 2026] [security2:error] [pid 488669:tid 488851] [client 4.205.62.107:58056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/nzv.php"] [unique_id "apPj-NRh6OewFvqQpDk8pwAAATY"]
[Sun Aug 30 03:04:08.389201 2026] [security2:error] [pid 488281:tid 488425] [client 4.205.62.107:63962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/paths.php"] [unique_id "apPj-DIT5HeNE73zNfqLFgAAAJM"]
[Sun Aug 30 03:04:08.419824 2026] [security2:error] [pid 488669:tid 488870] [client 20.220.10.235:51297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/dx.php"] [unique_id "apPj-NRh6OewFvqQpDk8vgAAAUk"]
[Sun Aug 30 03:04:08.421665 2026] [security2:error] [pid 488669:tid 488883] [client 158.23.184.117:60316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/.well-known/core.php"] [unique_id "apPj-NRh6OewFvqQpDk8wAAAAVY"]
[Sun Aug 30 03:04:08.444009 2026] [security2:error] [pid 488281:tid 488498] [client 158.23.147.79:61460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apPj-DIT5HeNE73zNfqLRAAAANw"]
[Sun Aug 30 03:04:08.455144 2026] [security2:error] [pid 488281:tid 488411] [client 52.139.37.240:14652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/xx.php"] [unique_id "apPj-DIT5HeNE73zNfqLVAAAAIU"]
[Sun Aug 30 03:04:08.478702 2026] [security2:error] [pid 488669:tid 488874] [client 20.63.81.20:55462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/doo.php"] [unique_id "apPj-NRh6OewFvqQpDk86AAAAU0"]
[Sun Aug 30 03:04:08.494871 2026] [security2:error] [pid 488669:tid 488908] [client 68.155.159.216:59389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/login.php"] [unique_id "apPj-NRh6OewFvqQpDk8-AAAAW8"]
[Sun Aug 30 03:04:08.552638 2026] [security2:error] [pid 488281:tid 488420] [client 20.220.10.235:51370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPj-DIT5HeNE73zNfqLkQAAAI4"]
[Sun Aug 30 03:04:08.562562 2026] [security2:error] [pid 488281:tid 488495] [client 158.23.184.117:51184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/akcc.php"] [unique_id "apPj-DIT5HeNE73zNfqLlwAAANk"]
[Sun Aug 30 03:04:08.568339 2026] [authz_core:error] [pid 488281:tid 488459] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fnf_reject_ipv6%2Fholders%2Fip6t_REJECT
[Sun Aug 30 03:04:08.568632 2026] [authz_core:error] [pid 488281:tid 488459] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fnf_reject_ipv6%2Fholders%2Fip6t_REJECT
[Sun Aug 30 03:04:08.584812 2026] [security2:error] [pid 488281:tid 488430] [client 158.23.147.79:55045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-content/radio.php"] [unique_id "apPj-DIT5HeNE73zNfqLnAAAAJg"]
[Sun Aug 30 03:04:08.599971 2026] [authz_core:error] [pid 488281:tid 488441] [client 66.249.66.204:39059] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:08.600332 2026] [authz_core:error] [pid 488281:tid 488441] [client 66.249.66.204:39059] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:08.610084 2026] [security2:error] [pid 488669:tid 488895] [client 20.63.81.20:55442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/adminer-4.6.6.php"] [unique_id "apPj-NRh6OewFvqQpDk9DwAAAWI"]
[Sun Aug 30 03:04:08.645361 2026] [security2:error] [pid 488281:tid 488427] [client 4.205.62.107:55245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/database.php"] [unique_id "apPj-DIT5HeNE73zNfqLqgAAAJU"]
[Sun Aug 30 03:04:08.649859 2026] [security2:error] [pid 488281:tid 488526] [client 52.139.37.240:14346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/wp-content/about.php"] [unique_id "apPj-DIT5HeNE73zNfqLrAAAAPg"]
[Sun Aug 30 03:04:08.672175 2026] [authz_core:error] [pid 488669:tid 488924] [client 66.249.66.206:40532] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:08.672469 2026] [authz_core:error] [pid 488669:tid 488924] [client 66.249.66.206:40532] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:08.677569 2026] [security2:error] [pid 488669:tid 488814] [client 20.104.18.15:3882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lakewoodshuttle.deevosdesigns.com"] [uri "/xmini4.php"] [unique_id "apPj-NRh6OewFvqQpDk9IAAAARE"]
[Sun Aug 30 03:04:08.684598 2026] [security2:error] [pid 488281:tid 488436] [client 20.220.10.235:51278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/xda.php"] [unique_id "apPj-DIT5HeNE73zNfqLwQAAAJ4"]
[Sun Aug 30 03:04:08.709468 2026] [security2:error] [pid 488281:tid 488520] [client 158.23.184.117:60306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/themes7.php"] [unique_id "apPj-DIT5HeNE73zNfqLyAAAAPI"]
[Sun Aug 30 03:04:08.727886 2026] [security2:error] [pid 488669:tid 488925] [client 195.178.110.247:59502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/index.php"] [unique_id "apPj-NRh6OewFvqQpDk9JgAAAYA"]
[Sun Aug 30 03:04:08.738178 2026] [security2:error] [pid 488669:tid 488839] [client 20.63.81.20:55400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/gelap1.php"] [unique_id "apPj-NRh6OewFvqQpDk9KQAAASo"]
[Sun Aug 30 03:04:08.778711 2026] [security2:error] [pid 488281:tid 488422] [client 158.23.147.79:55225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apPj-DIT5HeNE73zNfqL2AAAAJA"]
[Sun Aug 30 03:04:08.816970 2026] [security2:error] [pid 488669:tid 488890] [client 20.220.10.235:51276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPj-NRh6OewFvqQpDk9NAAAAV0"]
[Sun Aug 30 03:04:08.817094 2026] [authz_core:error] [pid 488669:tid 488868] [client 66.249.66.198:50254] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:08.817554 2026] [authz_core:error] [pid 488669:tid 488868] [client 66.249.66.198:50254] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:08.836061 2026] [authz_core:error] [pid 488281:tid 488447] [client 66.249.66.196:37910] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:08.836538 2026] [authz_core:error] [pid 488281:tid 488447] [client 66.249.66.196:37910] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:08.844907 2026] [security2:error] [pid 488281:tid 488482] [client 52.139.37.240:15058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/wp-the.php"] [unique_id "apPj-DIT5HeNE73zNfqL7wAAAMw"]
[Sun Aug 30 03:04:08.850407 2026] [security2:error] [pid 488281:tid 488464] [client 158.23.184.117:60314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/wp-admin/images.php"] [unique_id "apPj-DIT5HeNE73zNfqL8gAAALo"]
[Sun Aug 30 03:04:08.851406 2026] [security2:error] [pid 488281:tid 488504] [client 4.205.62.107:22533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/log.php"] [unique_id "apPj-DIT5HeNE73zNfqL8wAAAOI"]
[Sun Aug 30 03:04:08.867504 2026] [security2:error] [pid 488281:tid 488435] [client 20.63.81.20:55413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/rsjlrria.php"] [unique_id "apPj-DIT5HeNE73zNfqL-gAAAJ0"]
[Sun Aug 30 03:04:08.891153 2026] [security2:error] [pid 488669:tid 488819] [client 195.178.110.247:12598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/index.php"] [unique_id "apPj-NRh6OewFvqQpDk9OQAAARY"]
[Sun Aug 30 03:04:08.896671 2026] [security2:error] [pid 488669:tid 488873] [client 34.131.221.169:47476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/webroot/index.php/_environment"] [unique_id "apPj-NRh6OewFvqQpDk9OgAAAUw"]
[Sun Aug 30 03:04:08.912719 2026] [security2:error] [pid 488281:tid 488494] [client 4.205.62.107:44754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/debuggen.php"] [unique_id "apPj-DIT5HeNE73zNfqMAgAAANg"]
[Sun Aug 30 03:04:08.928550 2026] [security2:error] [pid 488669:tid 488853] [client 158.23.147.79:55090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/login.php"] [unique_id "apPj-NRh6OewFvqQpDk9OwAAATg"]
[Sun Aug 30 03:04:08.935280 2026] [security2:error] [pid 488281:tid 488458] [client 34.16.144.252:30616] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.alchemancer.com"] [uri "/config/application.properties"] [unique_id "apPj-DIT5HeNE73zNfqMFQAAALQ"]
[Sun Aug 30 03:04:08.936094 2026] [security2:error] [pid 488669:tid 488923] [client 34.16.144.252:30662] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.alchemancer.com"] [uri "/config.yaml"] [unique_id "apPj-NRh6OewFvqQpDk9QAAAAX4"]
[Sun Aug 30 03:04:08.941253 2026] [security2:error] [pid 488281:tid 488476] [client 4.205.62.107:35993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/fun.php"] [unique_id "apPj-DIT5HeNE73zNfqMIgAAAMY"]
[Sun Aug 30 03:04:08.948363 2026] [security2:error] [pid 488281:tid 488455] [client 20.220.10.235:51270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/t00l.php"] [unique_id "apPj-DIT5HeNE73zNfqMJgAAALE"]
[Sun Aug 30 03:04:08.991274 2026] [security2:error] [pid 488281:tid 488472] [client 158.23.184.117:7595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/wp-content/themes/haha.php"] [unique_id "apPj-DIT5HeNE73zNfqMPQAAAMI"]
[Sun Aug 30 03:04:08.995762 2026] [security2:error] [pid 488669:tid 488836] [client 4.205.62.107:42640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/params.php"] [unique_id "apPj-NRh6OewFvqQpDk9TQAAASc"]
[Sun Aug 30 03:04:09.008780 2026] [security2:error] [pid 488669:tid 488901] [client 20.104.50.220:29709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/base.php"] [unique_id "apPj-dRh6OewFvqQpDk9TwAAAWg"]
[Sun Aug 30 03:04:09.009663 2026] [autoindex:error] [pid 488281:tid 488431] [client 4.205.62.107:63792] AH01276: Cannot serve directory /home2/marazul/public_html/wp-includes/js/tinymce/themes/inlite/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:04:09.013360 2026] [security2:error] [pid 488669:tid 488905] [client 20.63.81.20:55464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/AxAo.php"] [unique_id "apPj-dRh6OewFvqQpDk9UQAAAWw"]
[Sun Aug 30 03:04:09.022781 2026] [security2:error] [pid 488281:tid 488439] [client 20.48.251.3:59374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/sdsa.php"] [unique_id "apPj-TIT5HeNE73zNfqMSAAAAKE"]
[Sun Aug 30 03:04:09.037674 2026] [security2:error] [pid 488281:tid 488486] [client 52.139.37.240:15099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/ws81.php"] [unique_id "apPj-TIT5HeNE73zNfqMSwAAANA"]
[Sun Aug 30 03:04:09.046570 2026] [security2:error] [pid 488281:tid 488412] [client 158.23.147.79:55211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/hehehehe.php"] [unique_id "apPj-TIT5HeNE73zNfqMTgAAAIY"]
[Sun Aug 30 03:04:09.049653 2026] [security2:error] [pid 488669:tid 488854] [client 20.104.50.220:46197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/codeboy1877x.php"] [unique_id "apPj-dRh6OewFvqQpDk9VwAAATk"]
[Sun Aug 30 03:04:09.053691 2026] [security2:error] [pid 488281:tid 488490] [client 34.131.221.169:47480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/cpanel/phpinfo.php"] [unique_id "apPj-TIT5HeNE73zNfqMVAAAANQ"]
[Sun Aug 30 03:04:09.063963 2026] [security2:error] [pid 488669:tid 488825] [client 4.205.62.107:56587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/gk.php"] [unique_id "apPj-dRh6OewFvqQpDk9WwAAARw"]
[Sun Aug 30 03:04:09.064818 2026] [security2:error] [pid 488669:tid 488814] [client 20.104.50.220:5516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/atx.php"] [unique_id "apPj-dRh6OewFvqQpDk9XQAAARE"]
[Sun Aug 30 03:04:09.065067 2026] [authz_core:error] [pid 488281:tid 488413] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2FHTML
[Sun Aug 30 03:04:09.065347 2026] [authz_core:error] [pid 488281:tid 488413] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2FHTML
[Sun Aug 30 03:04:09.065451 2026] [security2:error] [pid 488281:tid 488521] [client 4.205.62.107:2311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/mcebraed.php"] [unique_id "apPj-TIT5HeNE73zNfqMWQAAAPM"]
[Sun Aug 30 03:04:09.071891 2026] [security2:error] [pid 488281:tid 488426] [client 34.16.144.252:30516] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/api/openapi.json"] [unique_id "apPj-DIT5HeNE73zNfqMEQAAAJQ"]
[Sun Aug 30 03:04:09.073602 2026] [security2:error] [pid 488281:tid 488419] [client 4.205.62.107:63792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/doc.php"] [unique_id "apPj-TIT5HeNE73zNfqMXwAAAI0"]
[Sun Aug 30 03:04:09.080955 2026] [security2:error] [pid 488669:tid 488917] [client 20.220.10.235:51311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/ls.php"] [unique_id "apPj-dRh6OewFvqQpDk9YgAAAXg"]
[Sun Aug 30 03:04:09.084890 2026] [security2:error] [pid 488281:tid 488460] [client 20.48.251.3:44209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/god.php"] [unique_id "apPj-TIT5HeNE73zNfqMYgAAALY"]
[Sun Aug 30 03:04:09.103822 2026] [authz_core:error] [pid 488281:tid 488506] [client 216.73.216.128:51358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:09.104293 2026] [authz_core:error] [pid 488281:tid 488506] [client 216.73.216.128:51358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:09.109500 2026] [security2:error] [pid 488281:tid 488472] [client 20.104.50.220:56717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wso2.5.1.php"] [unique_id "apPj-TIT5HeNE73zNfqMcgAAAMI"]
[Sun Aug 30 03:04:09.132005 2026] [security2:error] [pid 488281:tid 488524] [client 158.23.184.117:51169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/wp-mail.php"] [unique_id "apPj-TIT5HeNE73zNfqMfAAAAPY"]
[Sun Aug 30 03:04:09.135579 2026] [security2:error] [pid 488281:tid 488486] [client 20.104.50.220:33291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-mobfi.php"] [unique_id "apPj-TIT5HeNE73zNfqMfgAAANA"]
[Sun Aug 30 03:04:09.144590 2026] [security2:error] [pid 488281:tid 488498] [client 20.48.251.3:49994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/register.php"] [unique_id "apPj-TIT5HeNE73zNfqMgwAAANw"]
[Sun Aug 30 03:04:09.146079 2026] [security2:error] [pid 488669:tid 488934] [client 20.63.81.20:55451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/class17.php"] [unique_id "apPj-dRh6OewFvqQpDk9cAAAAYk"]
[Sun Aug 30 03:04:09.154948 2026] [security2:error] [pid 488281:tid 488468] [client 158.23.147.79:55052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apPj-TIT5HeNE73zNfqMigAAAL4"]
[Sun Aug 30 03:04:09.177351 2026] [security2:error] [pid 488281:tid 488466] [client 34.16.144.252:30606] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/config/application.yml"] [unique_id "apPj-DIT5HeNE73zNfqMGQAAALw"]
[Sun Aug 30 03:04:09.178263 2026] [security2:error] [pid 488281:tid 488503] [client 20.104.18.15:9209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/shiny.php"] [unique_id "apPj-TIT5HeNE73zNfqMmQAAAOE"]
[Sun Aug 30 03:04:09.203231 2026] [security2:error] [pid 488669:tid 488930] [client 20.104.50.220:31903] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.38cupscreen.cover789.com"] [uri "/images/1.php"] [unique_id "apPj-dRh6OewFvqQpDk9gAAAAYU"]
[Sun Aug 30 03:04:09.203338 2026] [security2:error] [pid 488669:tid 488930] [client 20.104.50.220:31903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/images/1.php"] [unique_id "apPj-dRh6OewFvqQpDk9gAAAAYU"]
[Sun Aug 30 03:04:09.209731 2026] [security2:error] [pid 488669:tid 488863] [client 20.220.10.235:51343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/css/000.php"] [unique_id "apPj-dRh6OewFvqQpDk9gQAAAUI"]
[Sun Aug 30 03:04:09.224595 2026] [security2:error] [pid 488281:tid 488518] [client 68.155.159.216:52697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-includes/css/index.php"] [unique_id "apPj-TIT5HeNE73zNfqMtgAAAPA"]
[Sun Aug 30 03:04:09.231765 2026] [security2:error] [pid 488669:tid 488887] [client 52.139.37.240:14368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/a1.php"] [unique_id "apPj-dRh6OewFvqQpDk9iQAAAVo"]
[Sun Aug 30 03:04:09.235791 2026] [security2:error] [pid 488281:tid 488313] [remote 160.153.252.100:53300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.252.153.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/wp-login.php"] [unique_id "apPj-TIT5HeNE73zNfqMsgAAmB8"]
[Sun Aug 30 03:04:09.250754 2026] [security2:error] [pid 488281:tid 488521] [client 20.104.18.15:31622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/blacks.php"] [unique_id "apPj-TIT5HeNE73zNfqMwwAAAPM"]
[Sun Aug 30 03:04:09.269888 2026] [security2:error] [pid 488281:tid 488412] [client 158.23.184.117:51137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/root.php"] [unique_id "apPj-TIT5HeNE73zNfqMzwAAAIY"]
[Sun Aug 30 03:04:09.279773 2026] [security2:error] [pid 488281:tid 488496] [client 20.63.81.20:55372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/okxoby.php"] [unique_id "apPj-TIT5HeNE73zNfqM0wAAANo"]
[Sun Aug 30 03:04:09.301053 2026] [security2:error] [pid 488669:tid 488877] [client 158.23.147.79:55079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-content/admin.php"] [unique_id "apPj-dRh6OewFvqQpDk9owAAAVA"]
[Sun Aug 30 03:04:09.310199 2026] [security2:error] [pid 488281:tid 488467] [client 20.48.251.3:64400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/rum.or.php"] [unique_id "apPj-TIT5HeNE73zNfqM4wAAAL0"]
[Sun Aug 30 03:04:09.311088 2026] [authz_core:error] [pid 488669:tid 488816] [client 66.249.66.199:37214] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:09.311492 2026] [authz_core:error] [pid 488669:tid 488816] [client 66.249.66.199:37214] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:09.322615 2026] [security2:error] [pid 488669:tid 488844] [client 20.48.251.3:34536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/bootstrap.php"] [unique_id "apPj-dRh6OewFvqQpDk9rQAAAS8"]
[Sun Aug 30 03:04:09.329129 2026] [security2:error] [pid 488281:tid 488432] [client 20.48.251.3:31668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lastmaskcenter.org"] [uri "/var/www/wallet/index.php"] [unique_id "apPj-TIT5HeNE73zNfqM8QAAAJo"]
[Sun Aug 30 03:04:09.337018 2026] [security2:error] [pid 488669:tid 488868] [client 20.220.10.235:52218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/cy.php"] [unique_id "apPj-dRh6OewFvqQpDk9rwAAAUc"]
[Sun Aug 30 03:04:09.342745 2026] [security2:error] [pid 488281:tid 488519] [client 4.205.62.107:18634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/ccou.php"] [unique_id "apPj-TIT5HeNE73zNfqM-AAAAPE"]
[Sun Aug 30 03:04:09.374855 2026] [security2:error] [pid 488281:tid 488515] [client 4.205.62.107:26543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/plss3.php"] [unique_id "apPj-TIT5HeNE73zNfqNBgAAAO0"]
[Sun Aug 30 03:04:09.378723 2026] [security2:error] [pid 488281:tid 488512] [client 4.205.62.107:25499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/wp-konfig.backup.php"] [unique_id "apPj-TIT5HeNE73zNfqNCAAAAOo"]
[Sun Aug 30 03:04:09.389515 2026] [security2:error] [pid 488669:tid 488927] [client 20.104.50.220:61425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/9191.php"] [unique_id "apPj-dRh6OewFvqQpDk9vwAAAYI"]
[Sun Aug 30 03:04:09.411975 2026] [security2:error] [pid 488281:tid 488534] [client 158.23.184.117:60308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/ae.php"] [unique_id "apPj-TIT5HeNE73zNfqNHgAAAQA"]
[Sun Aug 30 03:04:09.412298 2026] [security2:error] [pid 488281:tid 488487] [client 4.205.62.107:5116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/fucku.php"] [unique_id "apPj-TIT5HeNE73zNfqNHwAAANE"]
[Sun Aug 30 03:04:09.417519 2026] [security2:error] [pid 488281:tid 488500] [client 20.104.50.220:29617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/k.php"] [unique_id "apPj-TIT5HeNE73zNfqNIgAAAN4"]
[Sun Aug 30 03:04:09.423536 2026] [security2:error] [pid 488281:tid 488524] [client 20.63.81.20:55303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/esuutzzx.php"] [unique_id "apPj-TIT5HeNE73zNfqNJwAAAPY"]
[Sun Aug 30 03:04:09.424892 2026] [security2:error] [pid 488669:tid 488885] [client 52.139.37.240:14371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/ca5.php"] [unique_id "apPj-dRh6OewFvqQpDk90gAAAVg"]
[Sun Aug 30 03:04:09.429473 2026] [security2:error] [pid 488669:tid 488912] [client 20.48.251.3:64271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/fff.php"] [unique_id "apPj-dRh6OewFvqQpDk91wAAAXM"]
[Sun Aug 30 03:04:09.454903 2026] [security2:error] [pid 488281:tid 488412] [client 20.104.49.130:64980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.topatrust.com"] [uri "/menu.php"] [unique_id "apPj-TIT5HeNE73zNfqNRAAAAIY"]
[Sun Aug 30 03:04:09.459586 2026] [security2:error] [pid 488281:tid 488429] [client 158.23.147.79:55088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/xmlrpc.php"] [unique_id "apPj-TIT5HeNE73zNfqNSwAAAJc"]
[Sun Aug 30 03:04:09.464874 2026] [security2:error] [pid 488281:tid 488492] [client 20.220.10.235:52164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/admin.php/pindex.php"] [unique_id "apPj-TIT5HeNE73zNfqNVAAAANY"]
[Sun Aug 30 03:04:09.505614 2026] [security2:error] [pid 488281:tid 488325] [remote 160.153.252.100:53300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.252.153.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/wp-login.php"] [unique_id "apPj-TIT5HeNE73zNfqNbgAAzCs"], referer: https://bodaciousbooze.com/wp-login.php
[Sun Aug 30 03:04:09.535723 2026] [security2:error] [pid 488669:tid 488929] [client 4.205.62.107:62032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/olfclass.php"] [unique_id "apPj-dRh6OewFvqQpDk-EgAAAYQ"]
[Sun Aug 30 03:04:09.553857 2026] [security2:error] [pid 488281:tid 488432] [client 158.23.184.117:51192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/admin/controller/extension/ultra.php"] [unique_id "apPj-TIT5HeNE73zNfqNkwAAAJo"]
[Sun Aug 30 03:04:09.555337 2026] [security2:error] [pid 488281:tid 488472] [client 20.63.81.20:55381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/replace.php"] [unique_id "apPj-TIT5HeNE73zNfqNlgAAAMI"]
[Sun Aug 30 03:04:09.585592 2026] [authz_core:error] [pid 488281:tid 488480] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flsof
[Sun Aug 30 03:04:09.585881 2026] [authz_core:error] [pid 488281:tid 488480] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flsof
[Sun Aug 30 03:04:09.602454 2026] [security2:error] [pid 488669:tid 488925] [client 20.104.49.130:53829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.cherylvalk.com"] [uri "/mh.php"] [unique_id "apPj-dRh6OewFvqQpDk-IAAAAYA"]
[Sun Aug 30 03:04:09.602515 2026] [security2:error] [pid 488281:tid 488429] [client 20.220.10.235:51312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/admin.php/csv.php"] [unique_id "apPj-TIT5HeNE73zNfqNrQAAAJc"]
[Sun Aug 30 03:04:09.609110 2026] [security2:error] [pid 488281:tid 488514] [client 68.155.159.216:59376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/hehehehe.php"] [unique_id "apPj-TIT5HeNE73zNfqNsQAAAOw"]
[Sun Aug 30 03:04:09.624307 2026] [security2:error] [pid 488281:tid 488503] [client 34.131.221.169:47484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/mail/phpinfo.php"] [unique_id "apPj-TIT5HeNE73zNfqNtwAAAOE"]
[Sun Aug 30 03:04:09.639866 2026] [security2:error] [pid 488281:tid 488434] [client 4.205.62.107:65281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/66.php"] [unique_id "apPj-TIT5HeNE73zNfqNvAAAAJw"]
[Sun Aug 30 03:04:09.641404 2026] [security2:error] [pid 488281:tid 488519] [client 52.139.37.240:14390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/install.php"] [unique_id "apPj-TIT5HeNE73zNfqNvgAAAPE"]
[Sun Aug 30 03:04:09.684840 2026] [security2:error] [pid 488281:tid 488440] [client 20.63.81.20:55407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/gulu.php"] [unique_id "apPj-TIT5HeNE73zNfqN0AAAAKI"]
[Sun Aug 30 03:04:09.696095 2026] [security2:error] [pid 488281:tid 488450] [client 158.23.184.117:51171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/wp-content/import.php"] [unique_id "apPj-TIT5HeNE73zNfqN1AAAAKw"]
[Sun Aug 30 03:04:09.700463 2026] [security2:error] [pid 488281:tid 488528] [client 158.23.147.79:55066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/atomlib.php"] [unique_id "apPj-TIT5HeNE73zNfqN1wAAAPo"]
[Sun Aug 30 03:04:09.753403 2026] [security2:error] [pid 488281:tid 488512] [client 20.220.10.235:51325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/admin.php/700.php"] [unique_id "apPj-TIT5HeNE73zNfqN5QAAAOo"]
[Sun Aug 30 03:04:09.760358 2026] [security2:error] [pid 488669:tid 488831] [client 20.104.49.130:60945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/yawa.php"] [unique_id "apPj-dRh6OewFvqQpDk-LwAAASI"]
[Sun Aug 30 03:04:09.766512 2026] [security2:error] [pid 488281:tid 488428] [client 20.104.49.130:26902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trinitytechnologics.com"] [uri "/wp-the.php"] [unique_id "apPj-TIT5HeNE73zNfqN6AAAAJY"]
[Sun Aug 30 03:04:09.782020 2026] [security2:error] [pid 488281:tid 488485] [client 34.131.221.169:47486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/hosting/phpinfo.php"] [unique_id "apPj-TIT5HeNE73zNfqN7gAAAM8"]
[Sun Aug 30 03:04:09.817348 2026] [security2:error] [pid 488669:tid 488888] [client 20.63.81.20:55528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/gtghklk.php"] [unique_id "apPj-dRh6OewFvqQpDk-NAAAAVs"]
[Sun Aug 30 03:04:09.824659 2026] [security2:error] [pid 488669:tid 488903] [client 20.104.18.15:3802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lakewoodshuttle.deevosdesigns.com"] [uri "/gulu.php"] [unique_id "apPj-dRh6OewFvqQpDk-NgAAAWo"]
[Sun Aug 30 03:04:09.837509 2026] [security2:error] [pid 488281:tid 488431] [client 158.23.184.117:51195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/wp-includes/fonts/admin.php"] [unique_id "apPj-TIT5HeNE73zNfqOAgAAAJk"]
[Sun Aug 30 03:04:09.878847 2026] [authz_core:error] [pid 488669:tid 488892] [client 66.249.66.194:62745] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:09.879161 2026] [authz_core:error] [pid 488669:tid 488892] [client 66.249.66.194:62745] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:09.888609 2026] [security2:error] [pid 488669:tid 488914] [client 20.220.10.235:51329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/admin.php/007x.php"] [unique_id "apPj-dRh6OewFvqQpDk-QAAAAXU"]
[Sun Aug 30 03:04:09.893271 2026] [rewrite:warn] [pid 488281:tid 488337] AH00665: RewriteCond: NoCase option for non-regex pattern '-d' is not supported and will be ignored. (/home3/keilan/public_html/.htaccess:12)
[Sun Aug 30 03:04:09.893290 2026] [rewrite:warn] [pid 488281:tid 488337] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home3/keilan/public_html/.htaccess:13)
[Sun Aug 30 03:04:09.900382 2026] [security2:error] [pid 488281:tid 488516] [client 52.139.37.240:15060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/wp-signin.php"] [unique_id "apPj-TIT5HeNE73zNfqOEwAAAO4"]
[Sun Aug 30 03:04:09.949438 2026] [security2:error] [pid 488281:tid 488451] [client 20.63.81.20:55430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/comand.php"] [unique_id "apPj-TIT5HeNE73zNfqOHAAAAK0"]
[Sun Aug 30 03:04:09.978341 2026] [security2:error] [pid 488281:tid 488512] [client 158.23.184.117:60293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/222.php"] [unique_id "apPj-TIT5HeNE73zNfqOLgAAAOo"]
[Sun Aug 30 03:04:09.985479 2026] [security2:error] [pid 488281:tid 488495] [client 4.205.62.107:22540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/ebahvhhh.php"] [unique_id "apPj-TIT5HeNE73zNfqOMwAAANk"]
[Sun Aug 30 03:04:10.015728 2026] [authz_core:error] [pid 488281:tid 488431] [client 216.73.216.128:51358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:10.016182 2026] [authz_core:error] [pid 488281:tid 488431] [client 216.73.216.128:51358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:10.017409 2026] [security2:error] [pid 488669:tid 488814] [client 20.220.10.235:51314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/admin.php/heex.php"] [unique_id "apPj-tRh6OewFvqQpDk-TgAAARE"]
[Sun Aug 30 03:04:10.038947 2026] [security2:error] [pid 488669:tid 488847] [client 158.23.147.79:55221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/lv.php"] [unique_id "apPj-tRh6OewFvqQpDk-UQAAATI"]
[Sun Aug 30 03:04:10.070243 2026] [authz_core:error] [pid 488281:tid 488427] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flsof
[Sun Aug 30 03:04:10.070581 2026] [authz_core:error] [pid 488281:tid 488427] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flsof
[Sun Aug 30 03:04:10.077110 2026] [security2:error] [pid 488669:tid 488897] [client 20.63.81.20:55494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/wp_motu_myk3v.php"] [unique_id "apPj-tRh6OewFvqQpDk-UwAAAWQ"]
[Sun Aug 30 03:04:10.081579 2026] [security2:error] [pid 488281:tid 488424] [client 4.205.62.107:44752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/pouhg.php"] [unique_id "apPj-jIT5HeNE73zNfqOVAAAAJI"]
[Sun Aug 30 03:04:10.091362 2026] [authz_core:error] [pid 488281:tid 488453] [client 66.249.66.195:44207] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:10.091774 2026] [authz_core:error] [pid 488281:tid 488453] [client 66.249.66.195:44207] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:10.103852 2026] [security2:error] [pid 488669:tid 488871] [client 52.139.37.240:14353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/Ov-Simple1.php"] [unique_id "apPj-tRh6OewFvqQpDk-VwAAAUo"]
[Sun Aug 30 03:04:10.119245 2026] [security2:error] [pid 488281:tid 488503] [client 158.23.184.117:51191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/wp-content/languages.php"] [unique_id "apPj-jIT5HeNE73zNfqObgAAAOE"]
[Sun Aug 30 03:04:10.145416 2026] [security2:error] [pid 488669:tid 488850] [client 4.205.62.107:42641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/gjm.php"] [unique_id "apPj-tRh6OewFvqQpDk-WwAAATU"]
[Sun Aug 30 03:04:10.146362 2026] [security2:error] [pid 488669:tid 488828] [client 20.104.50.220:30042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/Module.php"] [unique_id "apPj-tRh6OewFvqQpDk-XAAAAR8"]
[Sun Aug 30 03:04:10.161244 2026] [security2:error] [pid 488281:tid 488413] [client 20.220.10.235:51291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/tf.php"] [unique_id "apPj-jIT5HeNE73zNfqOhAAAAIc"]
[Sun Aug 30 03:04:10.166173 2026] [security2:error] [pid 488669:tid 488866] [client 20.48.251.3:59311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/sale.php"] [unique_id "apPj-tRh6OewFvqQpDk-YgAAAUU"]
[Sun Aug 30 03:04:10.198905 2026] [authz_core:error] [pid 488281:tid 488485] [client 216.73.216.128:49784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:10.199273 2026] [authz_core:error] [pid 488281:tid 488485] [client 216.73.216.128:49784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:10.200940 2026] [security2:error] [pid 488669:tid 488888] [client 4.205.62.107:63600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/css.php"] [unique_id "apPj-tRh6OewFvqQpDk-cwAAAVs"]
[Sun Aug 30 03:04:10.204137 2026] [security2:error] [pid 488281:tid 488489] [client 20.104.50.220:46403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wsanon.php"] [unique_id "apPj-jIT5HeNE73zNfqOlwAAANM"]
[Sun Aug 30 03:04:10.204678 2026] [security2:error] [pid 488669:tid 488824] [client 4.205.62.107:2320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/server-info.php"] [unique_id "apPj-tRh6OewFvqQpDk-dAAAARs"]
[Sun Aug 30 03:04:10.217079 2026] [security2:error] [pid 488281:tid 488424] [client 20.63.81.20:55366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/wp_motu_ypdat.php"] [unique_id "apPj-jIT5HeNE73zNfqOnQAAAJI"]
[Sun Aug 30 03:04:10.218237 2026] [security2:error] [pid 488669:tid 488842] [client 20.104.50.220:5456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/z60.php"] [unique_id "apPj-tRh6OewFvqQpDk-fgAAAS0"]
[Sun Aug 30 03:04:10.221993 2026] [security2:error] [pid 488669:tid 488853] [client 20.48.251.3:23483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/fff.php"] [unique_id "apPj-tRh6OewFvqQpDk-gAAAATg"]
[Sun Aug 30 03:04:10.240111 2026] [security2:error] [pid 488281:tid 488513] [client 4.205.62.107:56929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/god.php"] [unique_id "apPj-jIT5HeNE73zNfqOqQAAAOs"]
[Sun Aug 30 03:04:10.247273 2026] [security2:error] [pid 488669:tid 488917] [client 20.104.50.220:51605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wibu.php"] [unique_id "apPj-tRh6OewFvqQpDk-iwAAAXg"]
[Sun Aug 30 03:04:10.259302 2026] [authz_core:error] [pid 488281:tid 488512] [client 66.249.66.204:62420] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:10.259593 2026] [security2:error] [pid 488669:tid 488869] [client 158.23.184.117:7556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/wp-admin/install-helper.php"] [unique_id "apPj-tRh6OewFvqQpDk-jQAAAUg"]
[Sun Aug 30 03:04:10.259804 2026] [authz_core:error] [pid 488281:tid 488512] [client 66.249.66.204:62420] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:10.278736 2026] [security2:error] [pid 488281:tid 488471] [client 20.48.251.3:55481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/xqq.php"] [unique_id "apPj-jIT5HeNE73zNfqOvAAAAME"]
[Sun Aug 30 03:04:10.290019 2026] [security2:error] [pid 488281:tid 488506] [client 20.104.50.220:33571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-comments-post.php"] [unique_id "apPj-jIT5HeNE73zNfqOwQAAAOQ"]
[Sun Aug 30 03:04:10.291467 2026] [security2:error] [pid 488281:tid 488448] [client 4.205.62.107:32485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/atex1.php"] [unique_id "apPj-jIT5HeNE73zNfqOwgAAAKo"]
[Sun Aug 30 03:04:10.292018 2026] [security2:error] [pid 488281:tid 488537] [client 4.205.62.107:32449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/drykl.php"] [unique_id "apPj-jIT5HeNE73zNfqOwwAAAQM"]
[Sun Aug 30 03:04:10.305899 2026] [security2:error] [pid 488281:tid 488511] [client 20.220.10.235:51363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/update/da222.php"] [unique_id "apPj-jIT5HeNE73zNfqOzwAAAOk"]
[Sun Aug 30 03:04:10.320949 2026] [security2:error] [pid 488669:tid 488906] [client 52.139.37.240:14593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/ftde.php"] [unique_id "apPj-tRh6OewFvqQpDk-pQAAAW0"]
[Sun Aug 30 03:04:10.342745 2026] [security2:error] [pid 488281:tid 488518] [client 20.63.81.20:55374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/edit.php"] [unique_id "apPj-jIT5HeNE73zNfqO7QAAAPA"]
[Sun Aug 30 03:04:10.357714 2026] [security2:error] [pid 488281:tid 488501] [client 34.131.221.169:47498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/cpanel/phpinfo.php"] [unique_id "apPj-jIT5HeNE73zNfqO8wAAAN8"]
[Sun Aug 30 03:04:10.360275 2026] [security2:error] [pid 488281:tid 488480] [client 20.104.18.15:9107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/goods.php"] [unique_id "apPj-jIT5HeNE73zNfqO9QAAAMo"]
[Sun Aug 30 03:04:10.385063 2026] [security2:error] [pid 488281:tid 488474] [client 20.104.50.220:31905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/imageswp-init.php"] [unique_id "apPj-jIT5HeNE73zNfqPCAAAAMQ"]
[Sun Aug 30 03:04:10.399334 2026] [security2:error] [pid 488281:tid 488510] [client 158.23.184.117:7562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/wp-includes/fonts/classmap.php"] [unique_id "apPj-jIT5HeNE73zNfqPEQAAAOg"]
[Sun Aug 30 03:04:10.412385 2026] [security2:error] [pid 488281:tid 488475] [client 68.155.159.216:54773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apPj-jIT5HeNE73zNfqPHAAAAMU"]
[Sun Aug 30 03:04:10.412840 2026] [security2:error] [pid 488281:tid 488528] [client 20.104.18.15:31729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/beck.php"] [unique_id "apPj-jIT5HeNE73zNfqPHQAAAPo"]
[Sun Aug 30 03:04:10.435768 2026] [authz_core:error] [pid 488281:tid 488434] [client 66.249.66.193:35671] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:10.436232 2026] [authz_core:error] [pid 488281:tid 488434] [client 66.249.66.193:35671] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:10.437883 2026] [security2:error] [pid 488281:tid 488537] [client 20.220.10.235:51271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/qi.php"] [unique_id "apPj-jIT5HeNE73zNfqPOQAAAQM"]
[Sun Aug 30 03:04:10.454051 2026] [security2:error] [pid 488281:tid 488503] [client 20.48.251.3:7391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/xmy.php"] [unique_id "apPj-jIT5HeNE73zNfqPTgAAAOE"]
[Sun Aug 30 03:04:10.466162 2026] [security2:error] [pid 488281:tid 488440] [client 158.23.147.79:55192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apPj-jIT5HeNE73zNfqPXwAAAKI"]
[Sun Aug 30 03:04:10.467765 2026] [security2:error] [pid 488281:tid 488469] [client 20.63.81.20:55470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/tqkdqbbv.php"] [unique_id "apPj-jIT5HeNE73zNfqPYgAAAL8"]
[Sun Aug 30 03:04:10.469729 2026] [security2:error] [pid 488281:tid 488418] [client 20.48.251.3:29736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lastmaskcenter.org"] [uri "/124.php"] [unique_id "apPj-jIT5HeNE73zNfqPYwAAAIw"]
[Sun Aug 30 03:04:10.498456 2026] [security2:error] [pid 488281:tid 488520] [client 20.48.251.3:34584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/333.php"] [unique_id "apPj-jIT5HeNE73zNfqPdgAAAPI"]
[Sun Aug 30 03:04:10.498530 2026] [security2:error] [pid 488281:tid 488501] [client 4.205.62.107:18647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/rum.or.php"] [unique_id "apPj-jIT5HeNE73zNfqPdwAAAN8"]
[Sun Aug 30 03:04:10.514104 2026] [security2:error] [pid 488281:tid 488488] [client 52.139.37.240:14349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/hplfuns.php"] [unique_id "apPj-jIT5HeNE73zNfqPgwAAANI"]
[Sun Aug 30 03:04:10.539169 2026] [security2:error] [pid 488281:tid 488522] [client 20.104.50.220:61452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/kjtpoad.php"] [unique_id "apPj-jIT5HeNE73zNfqPkQAAAPQ"]
[Sun Aug 30 03:04:10.539853 2026] [security2:error] [pid 488669:tid 488866] [client 34.131.221.169:47510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/webmail/phpinfo.php"] [unique_id "apPj-tRh6OewFvqQpDk--AAAAUU"]
[Sun Aug 30 03:04:10.541457 2026] [security2:error] [pid 488281:tid 488519] [client 158.23.184.117:60318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/adminfuns.php/.well-known/acme-challenge/file.php"] [unique_id "apPj-jIT5HeNE73zNfqPlAAAAPE"]
[Sun Aug 30 03:04:10.546194 2026] [security2:error] [pid 488281:tid 488422] [client 4.205.62.107:25773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/packed.php"] [unique_id "apPj-jIT5HeNE73zNfqPmgAAAJA"]
[Sun Aug 30 03:04:10.568005 2026] [security2:error] [pid 488669:tid 488876] [client 20.220.10.235:51362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/px.php"] [unique_id "apPj-tRh6OewFvqQpDk-_wAAAU8"]
[Sun Aug 30 03:04:10.569509 2026] [authz_core:error] [pid 488669:tid 488815] [client 66.249.66.199:37214] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:10.569802 2026] [authz_core:error] [pid 488669:tid 488815] [client 66.249.66.199:37214] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:10.584971 2026] [authz_core:error] [pid 488281:tid 488457] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flsof
[Sun Aug 30 03:04:10.585244 2026] [authz_core:error] [pid 488281:tid 488457] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flsof
[Sun Aug 30 03:04:10.590912 2026] [security2:error] [pid 488281:tid 488525] [client 20.104.50.220:52827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/j.php"] [unique_id "apPj-jIT5HeNE73zNfqPqwAAAPc"]
[Sun Aug 30 03:04:10.592659 2026] [security2:error] [pid 488281:tid 488493] [client 20.63.81.20:55546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/kjyehoxl.php"] [unique_id "apPj-jIT5HeNE73zNfqPrAAAANc"]
[Sun Aug 30 03:04:10.611969 2026] [security2:error] [pid 488669:tid 488857] [client 4.205.62.107:5057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/error_log.php"] [unique_id "apPj-tRh6OewFvqQpDk_BgAAATw"]
[Sun Aug 30 03:04:10.637020 2026] [security2:error] [pid 488281:tid 488487] [client 20.48.251.3:64268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/autogooey.php"] [unique_id "apPj-jIT5HeNE73zNfqPvgAAANE"]
[Sun Aug 30 03:04:10.657797 2026] [security2:error] [pid 488281:tid 488469] [client 158.23.147.79:55173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/content.php"] [unique_id "apPj-jIT5HeNE73zNfqPxAAAAL8"]
[Sun Aug 30 03:04:10.675084 2026] [security2:error] [pid 488281:tid 488432] [client 4.205.62.107:62124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/gnmlc.php"] [unique_id "apPj-jIT5HeNE73zNfqPzgAAAJo"]
[Sun Aug 30 03:04:10.682798 2026] [security2:error] [pid 488281:tid 488443] [client 158.23.184.117:51199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/wp-content/themes/aa.php"] [unique_id "apPj-jIT5HeNE73zNfqP0QAAAKU"]
[Sun Aug 30 03:04:10.706613 2026] [security2:error] [pid 488281:tid 488506] [client 20.220.10.235:51286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/is.php"] [unique_id "apPj-jIT5HeNE73zNfqP1wAAAOQ"]
[Sun Aug 30 03:04:10.720769 2026] [security2:error] [pid 488669:tid 488814] [client 20.63.81.20:55326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/llyuxaqd.php"] [unique_id "apPj-tRh6OewFvqQpDk_EAAAARE"]
[Sun Aug 30 03:04:10.725396 2026] [security2:error] [pid 488669:tid 488836] [client 52.139.37.240:14619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/log.php"] [unique_id "apPj-tRh6OewFvqQpDk_EQAAASc"]
[Sun Aug 30 03:04:10.811869 2026] [security2:error] [pid 488281:tid 488517] [client 4.205.62.107:58142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/admin.php"] [unique_id "apPj-jIT5HeNE73zNfqP-AAAAO8"]
[Sun Aug 30 03:04:10.822572 2026] [security2:error] [pid 488281:tid 488417] [client 158.23.184.117:60317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/chosen.php"] [unique_id "apPj-jIT5HeNE73zNfqP_QAAAIs"]
[Sun Aug 30 03:04:10.854140 2026] [security2:error] [pid 488281:tid 488437] [client 4.205.62.107:36665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/kedi.php"] [unique_id "apPj-jIT5HeNE73zNfqQBwAAAJ8"]
[Sun Aug 30 03:04:10.857423 2026] [security2:error] [pid 488669:tid 488897] [client 20.63.81.20:55460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/nbwxolou.php"] [unique_id "apPj-tRh6OewFvqQpDk_JQAAAWQ"]
[Sun Aug 30 03:04:10.864976 2026] [security2:error] [pid 488669:tid 488918] [client 20.220.10.235:51358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/od.php"] [unique_id "apPj-tRh6OewFvqQpDk_JwAAAXk"]
[Sun Aug 30 03:04:10.865833 2026] [security2:error] [pid 488669:tid 488830] [client 68.155.159.216:60556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-includes/fonts/about.php"] [unique_id "apPj-tRh6OewFvqQpDk_KAAAASE"]
[Sun Aug 30 03:04:10.904687 2026] [autoindex:error] [pid 488281:tid 488453] [client 20.104.50.220:0] AH01276: Cannot serve directory /home2/egenolfm/nhlhockeybythenumbers.com/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:04:10.918006 2026] [security2:error] [pid 488281:tid 488413] [client 52.139.37.240:14367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/txets.php"] [unique_id "apPj-jIT5HeNE73zNfqQEwAAAIc"]
[Sun Aug 30 03:04:10.961968 2026] [security2:error] [pid 488281:tid 488428] [client 158.23.184.117:51136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/admin/function.php"] [unique_id "apPj-jIT5HeNE73zNfqQJAAAAJY"]
[Sun Aug 30 03:04:10.982943 2026] [authz_core:error] [pid 488281:tid 488531] [client 66.249.66.200:51713] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:10.983386 2026] [authz_core:error] [pid 488281:tid 488531] [client 66.249.66.200:51713] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:10.993842 2026] [security2:error] [pid 488669:tid 488876] [client 20.63.81.20:55393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/nsxeubyv.php"] [unique_id "apPj-tRh6OewFvqQpDk_PQAAAU8"]
[Sun Aug 30 03:04:10.996620 2026] [security2:error] [pid 488281:tid 488461] [client 20.104.18.15:3834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lakewoodshuttle.deevosdesigns.com"] [uri "/replace.php"] [unique_id "apPj-jIT5HeNE73zNfqQOgAAALc"]
[Sun Aug 30 03:04:11.006634 2026] [security2:error] [pid 488669:tid 488833] [client 20.220.10.235:51322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/wp-the.php"] [unique_id "apPj-9Rh6OewFvqQpDk_QQAAASQ"]
[Sun Aug 30 03:04:11.022725 2026] [security2:error] [pid 488281:tid 488476] [client 20.104.50.220:62842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/images/java.php"] [unique_id "apPj-zIT5HeNE73zNfqQQgAAAMY"]
[Sun Aug 30 03:04:11.051269 2026] [security2:error] [pid 488281:tid 488421] [client 20.48.251.3:7045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/server_info.php"] [unique_id "apPj-zIT5HeNE73zNfqQSgAAAI8"]
[Sun Aug 30 03:04:11.089747 2026] [authz_core:error] [pid 488281:tid 488457] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flsof
[Sun Aug 30 03:04:11.090045 2026] [authz_core:error] [pid 488281:tid 488457] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flsof
[Sun Aug 30 03:04:11.095805 2026] [security2:error] [pid 488281:tid 488425] [client 34.131.221.169:47520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/hosting/phpinfo.php"] [unique_id "apPj-zIT5HeNE73zNfqQVwAAAJM"]
[Sun Aug 30 03:04:11.102471 2026] [security2:error] [pid 488669:tid 488823] [client 158.23.184.117:60310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/wxo.php"] [unique_id "apPj-9Rh6OewFvqQpDk_VAAAARo"]
[Sun Aug 30 03:04:11.109795 2026] [security2:error] [pid 488281:tid 488464] [client 52.139.37.240:15057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/wp-admin.php"] [unique_id "apPj-zIT5HeNE73zNfqQXwAAALo"]
[Sun Aug 30 03:04:11.124919 2026] [security2:error] [pid 488281:tid 488499] [client 20.63.81.20:55325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/zfqipfss.php"] [unique_id "apPj-zIT5HeNE73zNfqQZwAAAN0"]
[Sun Aug 30 03:04:11.124956 2026] [security2:error] [pid 488281:tid 488430] [client 4.205.62.107:22548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/asa.php"] [unique_id "apPj-zIT5HeNE73zNfqQZQAAAJg"]
[Sun Aug 30 03:04:11.132206 2026] [authz_core:error] [pid 488281:tid 488477] [client 216.73.216.128:56935] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:11.132493 2026] [authz_core:error] [pid 488281:tid 488477] [client 216.73.216.128:56935] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:11.135920 2026] [security2:error] [pid 488669:tid 488817] [client 20.220.10.235:51298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/wt.php"] [unique_id "apPj-9Rh6OewFvqQpDk_WwAAARQ"]
[Sun Aug 30 03:04:11.173835 2026] [security2:error] [pid 488669:tid 488866] [client 4.205.62.107:26511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/aws.php"] [unique_id "apPj-9Rh6OewFvqQpDk_cAAAAUU"]
[Sun Aug 30 03:04:11.196307 2026] [security2:error] [pid 488281:tid 488412] [client 158.23.147.79:62803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPj-zIT5HeNE73zNfqQigAAAIY"]
[Sun Aug 30 03:04:11.212531 2026] [authz_core:error] [pid 488281:tid 488461] [client 66.249.66.192:54109] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:11.213115 2026] [authz_core:error] [pid 488281:tid 488461] [client 66.249.66.192:54109] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:11.221516 2026] [security2:error] [pid 488281:tid 488486] [client 4.205.62.107:44472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/phpversion.php"] [unique_id "apPj-zIT5HeNE73zNfqQlgAAANA"]
[Sun Aug 30 03:04:11.243003 2026] [security2:error] [pid 488281:tid 488414] [client 158.23.184.117:7552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/wp-admin/theme-editor.php"] [unique_id "apPj-zIT5HeNE73zNfqQnwAAAIg"]
[Sun Aug 30 03:04:11.263276 2026] [security2:error] [pid 488281:tid 488504] [client 20.63.81.20:55504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.khanwadeabutalib.org"] [uri "/zrjuyoos.php"] [unique_id "apPj-zIT5HeNE73zNfqQrQAAAOI"]
[Sun Aug 30 03:04:11.268338 2026] [security2:error] [pid 488281:tid 488513] [client 20.220.10.235:51268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/im.php"] [unique_id "apPj-zIT5HeNE73zNfqQrgAAAOs"]
[Sun Aug 30 03:04:11.290608 2026] [security2:error] [pid 488281:tid 488534] [client 34.131.221.169:47532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/smtp/phpinfo.php"] [unique_id "apPj-zIT5HeNE73zNfqQtQAAAQA"]
[Sun Aug 30 03:04:11.300614 2026] [security2:error] [pid 488669:tid 488909] [client 20.48.251.3:55794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/wp-class.php"] [unique_id "apPj-9Rh6OewFvqQpDk_nQAAAXA"]
[Sun Aug 30 03:04:11.303092 2026] [security2:error] [pid 488669:tid 488819] [client 20.104.50.220:29835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/Query.php"] [unique_id "apPj-9Rh6OewFvqQpDk_oQAAARY"]
[Sun Aug 30 03:04:11.316934 2026] [authz_core:error] [pid 488281:tid 488476] [client 66.249.66.195:47744] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:11.317212 2026] [authz_core:error] [pid 488281:tid 488476] [client 66.249.66.195:47744] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:11.341066 2026] [security2:error] [pid 488281:tid 488495] [client 20.104.50.220:46434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/Alfa.php"] [unique_id "apPj-zIT5HeNE73zNfqQ1AAAANk"]
[Sun Aug 30 03:04:11.348155 2026] [security2:error] [pid 488669:tid 488813] [client 4.205.62.107:63570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/php_info.php"] [unique_id "apPj-9Rh6OewFvqQpDk_sgAAARA"]
[Sun Aug 30 03:04:11.350422 2026] [security2:error] [pid 488281:tid 488475] [client 4.205.62.107:42848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/configuration.php"] [unique_id "apPj-zIT5HeNE73zNfqQ2AAAAMU"]
[Sun Aug 30 03:04:11.361052 2026] [security2:error] [pid 488281:tid 488537] [client 20.48.251.3:44204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/autogooey.php"] [unique_id "apPj-zIT5HeNE73zNfqQ3QAAAQM"]
[Sun Aug 30 03:04:11.371942 2026] [security2:error] [pid 488281:tid 488451] [client 20.104.50.220:5917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/403.php"] [unique_id "apPj-zIT5HeNE73zNfqQ5gAAAK0"]
[Sun Aug 30 03:04:11.385563 2026] [security2:error] [pid 488669:tid 488875] [client 20.104.50.220:51561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/Wop.php"] [unique_id "apPj-9Rh6OewFvqQpDk_ugAAAU4"]
[Sun Aug 30 03:04:11.387423 2026] [security2:error] [pid 488281:tid 488494] [client 4.205.62.107:51759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/fff.php"] [unique_id "apPj-zIT5HeNE73zNfqQ7wAAANg"]
[Sun Aug 30 03:04:11.404554 2026] [security2:error] [pid 488281:tid 488430] [client 4.205.62.107:2793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/gk.php"] [unique_id "apPj-zIT5HeNE73zNfqQ_gAAAJg"]
[Sun Aug 30 03:04:11.415866 2026] [security2:error] [pid 488281:tid 488443] [client 20.220.10.235:51310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/file.php"] [unique_id "apPj-zIT5HeNE73zNfqRBgAAAKU"]
[Sun Aug 30 03:04:11.417693 2026] [security2:error] [pid 488281:tid 488450] [client 20.48.251.3:55450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/a1vx.php"] [unique_id "apPj-zIT5HeNE73zNfqRCgAAAKw"]
[Sun Aug 30 03:04:11.445904 2026] [security2:error] [pid 488281:tid 488420] [client 20.104.50.220:33160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-config-style.php"] [unique_id "apPj-zIT5HeNE73zNfqRHgAAAI4"]
[Sun Aug 30 03:04:11.454509 2026] [security2:error] [pid 488281:tid 488432] [client 52.139.37.240:14360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/wp-config-sample.php"] [unique_id "apPj-zIT5HeNE73zNfqRKAAAAJo"]
[Sun Aug 30 03:04:11.514065 2026] [security2:error] [pid 488669:tid 488889] [client 68.155.159.216:52680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-content/cong.php"] [unique_id "apPj-9Rh6OewFvqQpDlACQAAAVw"]
[Sun Aug 30 03:04:11.515102 2026] [security2:error] [pid 488669:tid 488854] [client 20.104.18.15:9024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/alfa.php"] [unique_id "apPj-9Rh6OewFvqQpDlADAAAATk"]
[Sun Aug 30 03:04:11.517185 2026] [security2:error] [pid 488669:tid 488849] [client 20.104.50.220:31816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/images/upload.php"] [unique_id "apPj-9Rh6OewFvqQpDlADQAAATQ"]
[Sun Aug 30 03:04:11.542230 2026] [security2:error] [pid 488669:tid 488925] [client 136.92.30.49:43860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/.env.bak"] [unique_id "apPj-9Rh6OewFvqQpDlAFAAAAYA"]
[Sun Aug 30 03:04:11.545343 2026] [authz_core:error] [pid 488281:tid 488421] [client 66.249.66.193:35671] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:11.545836 2026] [authz_core:error] [pid 488281:tid 488421] [client 66.249.66.193:35671] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:11.546547 2026] [security2:error] [pid 488669:tid 488908] [client 20.220.10.235:51344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/ca.php"] [unique_id "apPj-9Rh6OewFvqQpDlAGAAAAW8"]
[Sun Aug 30 03:04:11.562757 2026] [security2:error] [pid 488281:tid 488453] [client 20.104.49.130:32609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trinitytechnologics.com"] [uri "/155.php"] [unique_id "apPj-zIT5HeNE73zNfqRfgAAAK8"]
[Sun Aug 30 03:04:11.571810 2026] [authz_core:error] [pid 488281:tid 488478] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Flib%2Frpm%2Fredhat
[Sun Aug 30 03:04:11.572075 2026] [authz_core:error] [pid 488281:tid 488478] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Flib%2Frpm%2Fredhat
[Sun Aug 30 03:04:11.590914 2026] [security2:error] [pid 488281:tid 488523] [client 20.104.18.15:31659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/t3.php"] [unique_id "apPj-zIT5HeNE73zNfqRhgAAAPU"]
[Sun Aug 30 03:04:11.608139 2026] [security2:error] [pid 488281:tid 488459] [client 20.48.251.3:64476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/ms-edit.php"] [unique_id "apPj-zIT5HeNE73zNfqRjAAAALU"]
[Sun Aug 30 03:04:11.647330 2026] [security2:error] [pid 488281:tid 488510] [client 52.139.37.240:14634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/wp-content/packed.php"] [unique_id "apPj-zIT5HeNE73zNfqRlwAAAOg"]
[Sun Aug 30 03:04:11.674286 2026] [security2:error] [pid 488281:tid 488517] [client 4.205.62.107:19002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/xmy.php"] [unique_id "apPj-zIT5HeNE73zNfqRogAAAO8"]
[Sun Aug 30 03:04:11.681167 2026] [security2:error] [pid 488281:tid 488417] [client 20.220.10.235:51327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/pb.php"] [unique_id "apPj-zIT5HeNE73zNfqRpQAAAIs"]
[Sun Aug 30 03:04:11.686288 2026] [security2:error] [pid 488669:tid 488878] [client 136.92.30.49:43860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/.env.backup"] [unique_id "apPj-9Rh6OewFvqQpDlALAAAAVE"]
[Sun Aug 30 03:04:11.693769 2026] [security2:error] [pid 488669:tid 488811] [client 20.151.200.44:58831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPj-9Rh6OewFvqQpDlAMAAAAQ4"]
[Sun Aug 30 03:04:11.703302 2026] [security2:error] [pid 488669:tid 488880] [client 20.104.50.220:59570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/blackcat.php"] [unique_id "apPj-9Rh6OewFvqQpDlAMgAAAVM"]
[Sun Aug 30 03:04:11.712608 2026] [security2:error] [pid 488669:tid 488827] [client 20.48.251.3:59081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/G-in.php"] [unique_id "apPj-9Rh6OewFvqQpDlANAAAAR4"]
[Sun Aug 30 03:04:11.721825 2026] [security2:error] [pid 488281:tid 488514] [client 4.205.62.107:25734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/wp-info.php"] [unique_id "apPj-zIT5HeNE73zNfqRsAAAAOw"]
[Sun Aug 30 03:04:11.750876 2026] [security2:error] [pid 488281:tid 488460] [client 20.104.50.220:28711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/i.php"] [unique_id "apPj-zIT5HeNE73zNfqRuAAAALY"]
[Sun Aug 30 03:04:11.773937 2026] [security2:error] [pid 488281:tid 488538] [client 4.205.62.107:4180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/phina.php"] [unique_id "apPj-zIT5HeNE73zNfqRvwAAAQQ"]
[Sun Aug 30 03:04:11.801005 2026] [security2:error] [pid 488281:tid 488438] [client 20.48.251.3:54728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/sdsa.php"] [unique_id "apPj-zIT5HeNE73zNfqRygAAAKA"]
[Sun Aug 30 03:04:11.805856 2026] [authz_core:error] [pid 488281:tid 488430] [client 66.249.66.1:46292] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:11.806137 2026] [authz_core:error] [pid 488281:tid 488430] [client 66.249.66.1:46292] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:11.821523 2026] [security2:error] [pid 488281:tid 488411] [client 20.220.10.235:51299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/pk.php"] [unique_id "apPj-zIT5HeNE73zNfqR0wAAAIU"]
[Sun Aug 30 03:04:11.829169 2026] [security2:error] [pid 488281:tid 488527] [client 4.205.62.107:62140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/koiy.php"] [unique_id "apPj-zIT5HeNE73zNfqR1wAAAPk"]
[Sun Aug 30 03:04:11.833696 2026] [security2:error] [pid 488281:tid 488441] [client 34.131.221.169:47548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/webmail/phpinfo.php"] [unique_id "apPj-zIT5HeNE73zNfqR2wAAAKM"]
[Sun Aug 30 03:04:11.888047 2026] [security2:error] [pid 488281:tid 488422] [client 20.48.251.3:29970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lastmaskcenter.org"] [uri "/test1.php"] [unique_id "apPj-zIT5HeNE73zNfqR5QAAAJA"]
[Sun Aug 30 03:04:11.951106 2026] [security2:error] [pid 488281:tid 488459] [client 4.205.62.107:65326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/png.php"] [unique_id "apPj-zIT5HeNE73zNfqR9wAAALU"]
[Sun Aug 30 03:04:11.962178 2026] [security2:error] [pid 488281:tid 488456] [client 20.220.10.235:51342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/ft.php"] [unique_id "apPj-zIT5HeNE73zNfqR_gAAALI"]
[Sun Aug 30 03:04:11.976502 2026] [security2:error] [pid 488281:tid 488521] [client 68.155.159.216:52746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-content/admin.php"] [unique_id "apPj-zIT5HeNE73zNfqSBgAAAPM"]
[Sun Aug 30 03:04:11.988966 2026] [security2:error] [pid 488281:tid 488527] [client 20.151.200.44:46981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/wp-access.php"] [unique_id "apPj-zIT5HeNE73zNfqSDgAAAPk"]
[Sun Aug 30 03:04:12.041302 2026] [security2:error] [pid 488281:tid 488488] [client 34.131.221.169:47556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/phpinfo.php.bak"] [unique_id "apPj_DIT5HeNE73zNfqSGAAAANI"]
[Sun Aug 30 03:04:12.048219 2026] [authz_core:error] [pid 488281:tid 488418] [client 216.73.216.128:49784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:12.048704 2026] [authz_core:error] [pid 488281:tid 488418] [client 216.73.216.128:49784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:12.052301 2026] [security2:error] [pid 488281:tid 488500] [client 20.104.49.130:36096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wondertanks.com"] [uri "/ws45.php"] [unique_id "apPj_DIT5HeNE73zNfqSGwAAAN4"]
[Sun Aug 30 03:04:12.068763 2026] [authz_core:error] [pid 488669:tid 488892] [client 66.249.66.38:50309] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:12.069204 2026] [authz_core:error] [pid 488669:tid 488892] [client 66.249.66.38:50309] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:12.098867 2026] [authz_core:error] [pid 488281:tid 488413] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fdpkg%2Fspec
[Sun Aug 30 03:04:12.099165 2026] [authz_core:error] [pid 488281:tid 488413] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fdpkg%2Fspec
[Sun Aug 30 03:04:12.103384 2026] [security2:error] [pid 488281:tid 488496] [client 20.104.49.130:57676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/btyuio.php"] [unique_id "apPj_DIT5HeNE73zNfqSLgAAANo"]
[Sun Aug 30 03:04:12.104083 2026] [security2:error] [pid 488281:tid 488531] [client 20.220.10.235:52165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/wp-ver.php"] [unique_id "apPj_DIT5HeNE73zNfqSMAAAAP0"]
[Sun Aug 30 03:04:12.133177 2026] [security2:error] [pid 488281:tid 488439] [client 20.104.18.15:3951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lakewoodshuttle.deevosdesigns.com"] [uri "/c4.php"] [unique_id "apPj_DIT5HeNE73zNfqSPwAAAKE"]
[Sun Aug 30 03:04:12.159042 2026] [security2:error] [pid 488281:tid 488431] [client 20.104.50.220:29326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/js/java.php"] [unique_id "apPj_DIT5HeNE73zNfqSTwAAAJk"]
[Sun Aug 30 03:04:12.189758 2026] [authz_core:error] [pid 488281:tid 488512] [client 66.249.66.165:48571] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:12.190162 2026] [authz_core:error] [pid 488281:tid 488512] [client 66.249.66.165:48571] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:12.211439 2026] [security2:error] [pid 488669:tid 488809] [client 20.104.49.130:64897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.topatrust.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPj_NRh6OewFvqQpDlAgwAAAQw"]
[Sun Aug 30 03:04:12.235376 2026] [security2:error] [pid 488281:tid 488517] [client 20.220.10.235:51374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/ah24.php"] [unique_id "apPj_DIT5HeNE73zNfqSdAAAAO8"]
[Sun Aug 30 03:04:12.269736 2026] [security2:error] [pid 488281:tid 488411] [client 4.205.62.107:22562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/radio.php"] [unique_id "apPj_DIT5HeNE73zNfqSggAAAIU"]
[Sun Aug 30 03:04:12.303540 2026] [security2:error] [pid 488281:tid 488478] [client 20.104.49.130:64711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trinitytechnologics.com"] [uri "/fs.php"] [unique_id "apPj_DIT5HeNE73zNfqSkQAAAMg"]
[Sun Aug 30 03:04:12.312615 2026] [security2:error] [pid 488281:tid 488447] [client 136.92.30.49:43870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/.env.old"] [unique_id "apPj_DIT5HeNE73zNfqSlgAAAKk"]
[Sun Aug 30 03:04:12.357727 2026] [security2:error] [pid 488281:tid 488453] [client 4.205.62.107:44894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/adminfus.php"] [unique_id "apPj_DIT5HeNE73zNfqStgAAAK8"]
[Sun Aug 30 03:04:12.362055 2026] [security2:error] [pid 488281:tid 488528] [client 158.23.184.117:51162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/termps.php"] [unique_id "apPj_DIT5HeNE73zNfqSuAAAAPo"]
[Sun Aug 30 03:04:12.369438 2026] [security2:error] [pid 488281:tid 488476] [client 20.220.10.235:51295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPj_DIT5HeNE73zNfqSvAAAAMY"]
[Sun Aug 30 03:04:12.451594 2026] [security2:error] [pid 488669:tid 488844] [client 20.104.50.220:30297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/DB.php"] [unique_id "apPj_NRh6OewFvqQpDlA8gAAAS8"]
[Sun Aug 30 03:04:12.456437 2026] [security2:error] [pid 488669:tid 488924] [client 20.48.251.3:59307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/database.php"] [unique_id "apPj_NRh6OewFvqQpDlA9wAAAX8"]
[Sun Aug 30 03:04:12.460322 2026] [security2:error] [pid 488281:tid 488494] [client 4.205.62.107:32506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/aws_sdk_settings.php"] [unique_id "apPj_DIT5HeNE73zNfqTCQAAANg"]
[Sun Aug 30 03:04:12.461729 2026] [security2:error] [pid 488669:tid 488934] [client 4.205.62.107:58323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/rpk.php"] [unique_id "apPj_NRh6OewFvqQpDlA_QAAAYk"]
[Sun Aug 30 03:04:12.477766 2026] [security2:error] [pid 488669:tid 488839] [client 4.205.62.107:60500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/session.php"] [unique_id "apPj_NRh6OewFvqQpDlBCQAAASo"]
[Sun Aug 30 03:04:12.481809 2026] [security2:error] [pid 488669:tid 488914] [client 20.104.50.220:47087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-admin/includes/mailer.php.php"] [unique_id "apPj_NRh6OewFvqQpDlBEAAAAXU"]
[Sun Aug 30 03:04:12.497205 2026] [security2:error] [pid 488281:tid 488439] [client 20.48.251.3:23044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/sdsa.php"] [unique_id "apPj_DIT5HeNE73zNfqTJQAAAKE"]
[Sun Aug 30 03:04:12.499043 2026] [security2:error] [pid 488281:tid 488414] [client 4.205.62.107:36682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/oc460l3x.php"] [unique_id "apPj_DIT5HeNE73zNfqTJwAAAIg"]
[Sun Aug 30 03:04:12.503712 2026] [security2:error] [pid 488281:tid 488514] [client 158.23.184.117:51151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/fix.php"] [unique_id "apPj_DIT5HeNE73zNfqTKQAAAOw"]
[Sun Aug 30 03:04:12.507265 2026] [authz_core:error] [pid 488669:tid 488926] [client 66.249.66.201:38283] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:12.507750 2026] [authz_core:error] [pid 488669:tid 488926] [client 66.249.66.201:38283] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:12.508945 2026] [security2:error] [pid 488669:tid 488932] [client 20.104.50.220:5517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/m.php"] [unique_id "apPj_NRh6OewFvqQpDlBHAAAAYc"]
[Sun Aug 30 03:04:12.515237 2026] [security2:error] [pid 488669:tid 488828] [client 20.220.10.235:51339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.needlifeinsuranceuk.com"] [uri "/waf.php"] [unique_id "apPj_NRh6OewFvqQpDlBIQAAAR8"]
[Sun Aug 30 03:04:12.524864 2026] [security2:error] [pid 488281:tid 488492] [client 20.104.50.220:41987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/pah.php"] [unique_id "apPj_DIT5HeNE73zNfqTNAAAANY"]
[Sun Aug 30 03:04:12.527166 2026] [security2:error] [pid 488281:tid 488495] [client 4.205.62.107:51775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/autogooey.php"] [unique_id "apPj_DIT5HeNE73zNfqTNgAAANk"]
[Sun Aug 30 03:04:12.542431 2026] [security2:error] [pid 488281:tid 488528] [client 4.205.62.107:2975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/god.php"] [unique_id "apPj_DIT5HeNE73zNfqTQQAAAPo"]
[Sun Aug 30 03:04:12.552788 2026] [security2:error] [pid 488281:tid 488444] [client 20.48.251.3:55429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/public/vx.php"] [unique_id "apPj_DIT5HeNE73zNfqTSgAAAKY"]
[Sun Aug 30 03:04:12.582876 2026] [security2:error] [pid 488281:tid 488475] [client 34.131.221.169:47570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/smtp/phpinfo.php"] [unique_id "apPj_DIT5HeNE73zNfqTUAAAAMU"]
[Sun Aug 30 03:04:12.606663 2026] [security2:error] [pid 488281:tid 488489] [client 20.104.50.220:33579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-logo.php"] [unique_id "apPj_DIT5HeNE73zNfqTVwAAANM"]
[Sun Aug 30 03:04:12.607925 2026] [authz_core:error] [pid 488281:tid 488468] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Flib%2Frpm%2Fredhat
[Sun Aug 30 03:04:12.608379 2026] [authz_core:error] [pid 488281:tid 488468] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Flib%2Frpm%2Fredhat
[Sun Aug 30 03:04:12.619927 2026] [security2:error] [pid 488281:tid 488478] [client 68.155.159.216:52705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPj_DIT5HeNE73zNfqTXgAAAMg"]
[Sun Aug 30 03:04:12.629154 2026] [security2:error] [pid 488281:tid 488481] [client 4.205.62.107:26517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/app.default.php"] [unique_id "apPj_DIT5HeNE73zNfqTYQAAAMs"]
[Sun Aug 30 03:04:12.650345 2026] [security2:error] [pid 488281:tid 488476] [client 158.23.184.117:51140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/wp-includes/ID3/admin.php"] [unique_id "apPj_DIT5HeNE73zNfqTaAAAAMY"]
[Sun Aug 30 03:04:12.655010 2026] [security2:error] [pid 488281:tid 488523] [client 4.205.62.107:42664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/server_info.php"] [unique_id "apPj_DIT5HeNE73zNfqTaQAAAPU"]
[Sun Aug 30 03:04:12.660151 2026] [security2:error] [pid 488281:tid 488450] [client 45.131.195.23:27793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.195.131.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "homeohealing.ca"] [uri "/wp-login.php"] [unique_id "apPj_DIT5HeNE73zNfqTZwAAAKw"]
[Sun Aug 30 03:04:12.661161 2026] [security2:error] [pid 488281:tid 488477] [client 20.104.50.220:32545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/images/fox.php"] [unique_id "apPj_DIT5HeNE73zNfqTbAAAAMc"]
[Sun Aug 30 03:04:12.670115 2026] [security2:error] [pid 488281:tid 488501] [client 20.104.18.15:9029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/33.php"] [unique_id "apPj_DIT5HeNE73zNfqTbwAAAN8"]
[Sun Aug 30 03:04:12.729790 2026] [security2:error] [pid 488281:tid 488522] [client 20.104.18.15:31728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/wp.php"] [unique_id "apPj_DIT5HeNE73zNfqTfQAAAPQ"]
[Sun Aug 30 03:04:12.758338 2026] [security2:error] [pid 488281:tid 488459] [client 20.48.251.3:6464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/sys.php"] [unique_id "apPj_DIT5HeNE73zNfqTggAAALU"]
[Sun Aug 30 03:04:12.762665 2026] [security2:error] [pid 488281:tid 488494] [client 34.131.221.169:47580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/phpinfo.php.old"] [unique_id "apPj_DIT5HeNE73zNfqTgwAAANg"]
[Sun Aug 30 03:04:12.790193 2026] [security2:error] [pid 488281:tid 488515] [client 158.23.184.117:51149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/tiny.php"] [unique_id "apPj_DIT5HeNE73zNfqTkQAAAO0"]
[Sun Aug 30 03:04:12.816056 2026] [authz_core:error] [pid 488281:tid 488485] [client 66.249.66.13:62395] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:12.816544 2026] [authz_core:error] [pid 488281:tid 488485] [client 66.249.66.13:62395] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:12.840178 2026] [authz_core:error] [pid 488281:tid 488491] [client 66.249.66.196:37910] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:12.840656 2026] [authz_core:error] [pid 488281:tid 488491] [client 66.249.66.196:37910] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:12.844593 2026] [security2:error] [pid 488281:tid 488500] [client 34.16.144.252:30754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/web.config"] [unique_id "apPj_DIT5HeNE73zNfqTpgAAAN4"]
[Sun Aug 30 03:04:12.844830 2026] [security2:error] [pid 488281:tid 488500] [client 34.16.144.252:30754] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/web.config"] [unique_id "apPj_DIT5HeNE73zNfqTpgAAAN4"]
[Sun Aug 30 03:04:12.851259 2026] [security2:error] [pid 488669:tid 488881] [client 20.104.50.220:61429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/sure.php"] [unique_id "apPj_NRh6OewFvqQpDlBXQAAAVQ"]
[Sun Aug 30 03:04:12.860457 2026] [security2:error] [pid 488669:tid 488896] [client 4.205.62.107:18950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/ms-edit.php"] [unique_id "apPj_NRh6OewFvqQpDlBXgAAAWM"]
[Sun Aug 30 03:04:12.860741 2026] [security2:error] [pid 488281:tid 488435] [client 4.205.62.107:25859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/fns.php"] [unique_id "apPj_DIT5HeNE73zNfqTrAAAAJ0"]
[Sun Aug 30 03:04:12.861446 2026] [security2:error] [pid 488669:tid 488863] [client 20.48.251.3:58836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/apikeys.php"] [unique_id "apPj_NRh6OewFvqQpDlBXwAAAUI"]
[Sun Aug 30 03:04:12.875387 2026] [security2:error] [pid 488281:tid 488435] [client 34.16.144.252:30834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.144.16.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alchemancer.com"] [uri "/configuration.php.bak"] [unique_id "apPj_DIT5HeNE73zNfqTsgAAAJ0"]
[Sun Aug 30 03:04:12.880942 2026] [security2:error] [pid 488669:tid 488858] [client 34.16.144.252:30818] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/host.key"] [unique_id "apPj_NRh6OewFvqQpDlBYAAAAT0"]
[Sun Aug 30 03:04:12.890935 2026] [security2:error] [pid 488281:tid 488531] [client 20.104.50.220:29594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/h.php"] [unique_id "apPj_DIT5HeNE73zNfqTuQAAAP0"]
[Sun Aug 30 03:04:12.900147 2026] [security2:error] [pid 488669:tid 488846] [client 158.23.147.79:55197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/goat.php"] [unique_id "apPj_NRh6OewFvqQpDlBZAAAATE"]
[Sun Aug 30 03:04:12.902122 2026] [security2:error] [pid 488669:tid 488817] [client 20.48.251.3:7389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/hosty.php"] [unique_id "apPj_NRh6OewFvqQpDlBZQAAARQ"]
[Sun Aug 30 03:04:12.913239 2026] [security2:error] [pid 488669:tid 488915] [client 34.16.144.252:30792] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/localhost.key"] [unique_id "apPj_NRh6OewFvqQpDlBYgAAAXY"]
[Sun Aug 30 03:04:12.914563 2026] [security2:error] [pid 488669:tid 488868] [client 4.205.62.107:4581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/koiy.php"] [unique_id "apPj_NRh6OewFvqQpDlBZwAAAUc"]
[Sun Aug 30 03:04:12.931098 2026] [security2:error] [pid 488281:tid 488443] [client 158.23.184.117:51175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/css/classwithtostring.php"] [unique_id "apPj_DIT5HeNE73zNfqTvwAAAKU"]
[Sun Aug 30 03:04:12.956120 2026] [security2:error] [pid 488281:tid 488470] [client 20.48.251.3:64284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/sale.php"] [unique_id "apPj_DIT5HeNE73zNfqTywAAAMA"]
[Sun Aug 30 03:04:12.984043 2026] [security2:error] [pid 488281:tid 488425] [client 4.205.62.107:64010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/w.php"] [unique_id "apPj_DIT5HeNE73zNfqT4QAAAJM"]
[Sun Aug 30 03:04:12.998385 2026] [security2:error] [pid 488281:tid 488522] [client 34.16.144.252:30754] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/amplifyconfiguration.json"] [unique_id "apPj_DIT5HeNE73zNfqTuAAAAPQ"]
[Sun Aug 30 03:04:13.025601 2026] [fcgid:warn] [pid 488669:tid 488871] (70014)End of file found: [client 152.32.175.187:54032] mod_fcgid: can't get data from http client
[Sun Aug 30 03:04:13.055877 2026] [authz_core:error] [pid 488281:tid 488460] [client 216.73.216.128:51358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:13.056291 2026] [authz_core:error] [pid 488281:tid 488460] [client 216.73.216.128:51358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:13.068893 2026] [authz_core:error] [pid 488281:tid 488507] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Flib%2Frpm%2Fredhat
[Sun Aug 30 03:04:13.069308 2026] [authz_core:error] [pid 488281:tid 488507] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Flib%2Frpm%2Fredhat
[Sun Aug 30 03:04:13.108444 2026] [security2:error] [pid 488281:tid 488528] [client 158.23.184.117:51167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/buy.php"] [unique_id "apPj_TIT5HeNE73zNfqUFgAAAPo"]
[Sun Aug 30 03:04:13.118390 2026] [security2:error] [pid 488281:tid 488499] [client 4.205.62.107:65402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/chosen.php"] [unique_id "apPj_TIT5HeNE73zNfqUIQAAAN0"]
[Sun Aug 30 03:04:13.137745 2026] [security2:error] [pid 488281:tid 488440] [client 82.25.105.77:55718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.105.25.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnenglishwithtommy.com"] [uri "/wp-login.php"] [unique_id "apPj_TIT5HeNE73zNfqUGgAAAKI"]
[Sun Aug 30 03:04:13.194960 2026] [security2:error] [pid 488281:tid 488493] [client 68.155.159.216:60548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/xmlrpc.php"] [unique_id "apPj_TIT5HeNE73zNfqURgAAANc"]
[Sun Aug 30 03:04:13.218222 2026] [security2:error] [pid 488281:tid 488467] [client 20.48.251.3:30252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lastmaskcenter.org"] [uri "/bigdump.php"] [unique_id "apPj_TIT5HeNE73zNfqUUAAAAL0"]
[Sun Aug 30 03:04:13.230896 2026] [security2:error] [pid 488281:tid 488448] [client 128.140.106.114:55804] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "lenoreashwood.com"] [uri "/index.php"] [unique_id "apPj-zIT5HeNE73zNfqRrQAAAKo"], referer: https://lenoreashwood.com
[Sun Aug 30 03:04:13.232530 2026] [security2:error] [pid 488281:tid 488516] [client 49.13.164.148:31550] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "lenoreashwood.com"] [uri "/index.php"] [unique_id "apPj-jIT5HeNE73zNfqPqgAAAO4"], referer: https://lenoreashwood.com
[Sun Aug 30 03:04:13.247810 2026] [security2:error] [pid 488281:tid 488508] [client 158.23.184.117:51170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/bk.php"] [unique_id "apPj_TIT5HeNE73zNfqUZgAAAOY"]
[Sun Aug 30 03:04:13.271313 2026] [security2:error] [pid 488281:tid 488483] [client 20.104.18.15:4010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lakewoodshuttle.deevosdesigns.com"] [uri "/rxr.php"] [unique_id "apPj_TIT5HeNE73zNfqUcwAAAM0"]
[Sun Aug 30 03:04:13.272855 2026] [security2:error] [pid 488281:tid 488469] [client 20.48.251.3:7098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPj_TIT5HeNE73zNfqUdQAAAL8"]
[Sun Aug 30 03:04:13.295084 2026] [security2:error] [pid 488669:tid 488907] [client 34.131.221.169:47584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/phpinfo.php.bak"] [unique_id "apPj_dRh6OewFvqQpDlBvAAAAW4"]
[Sun Aug 30 03:04:13.310786 2026] [security2:error] [pid 488281:tid 488414] [client 20.104.50.220:52822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-content/f0x.php"] [unique_id "apPj_TIT5HeNE73zNfqUjwAAAIg"]
[Sun Aug 30 03:04:13.331902 2026] [authz_core:error] [pid 488281:tid 488476] [client 216.73.216.128:35778] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:13.332455 2026] [authz_core:error] [pid 488281:tid 488476] [client 216.73.216.128:35778] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:13.375573 2026] [fcgid:warn] [pid 488281:tid 488536] (70014)End of file found: [client 152.32.175.187:54058] mod_fcgid: can't get data from http client
[Sun Aug 30 03:04:13.387399 2026] [security2:error] [pid 488669:tid 488844] [client 158.23.184.117:60309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/.trash7309/index.php"] [unique_id "apPj_dRh6OewFvqQpDlB2gAAAS8"]
[Sun Aug 30 03:04:13.410046 2026] [security2:error] [pid 488669:tid 488880] [client 20.104.49.130:51575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trinitytechnologics.com"] [uri "/kgoc6awap3napxxxdCdefault.php"] [unique_id "apPj_dRh6OewFvqQpDlB5AAAAVM"]
[Sun Aug 30 03:04:13.435148 2026] [security2:error] [pid 488281:tid 488514] [client 4.205.62.107:62272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/xa.php"] [unique_id "apPj_TIT5HeNE73zNfqU2gAAAOw"]
[Sun Aug 30 03:04:13.448864 2026] [authz_core:error] [pid 488281:tid 488424] [client 66.249.66.15:43514] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:13.449316 2026] [authz_core:error] [pid 488281:tid 488424] [client 66.249.66.15:43514] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:13.488218 2026] [security2:error] [pid 488281:tid 488461] [client 34.131.221.169:47600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/phpinfo.php~"] [unique_id "apPj_TIT5HeNE73zNfqVBQAAALc"]
[Sun Aug 30 03:04:13.495826 2026] [security2:error] [pid 488281:tid 488488] [client 4.205.62.107:44756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/avim.php"] [unique_id "apPj_TIT5HeNE73zNfqVDAAAANI"]
[Sun Aug 30 03:04:13.526969 2026] [security2:error] [pid 488281:tid 488513] [client 158.23.184.117:7587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/jp.php"] [unique_id "apPj_TIT5HeNE73zNfqVHwAAAOs"]
[Sun Aug 30 03:04:13.593948 2026] [security2:error] [pid 488669:tid 488833] [client 20.48.251.3:59299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/atex1.php"] [unique_id "apPj_dRh6OewFvqQpDlCTgAAASQ"]
[Sun Aug 30 03:04:13.598391 2026] [security2:error] [pid 488669:tid 488858] [client 20.104.50.220:30035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/OAuth.php"] [unique_id "apPj_dRh6OewFvqQpDlCUAAAAT0"]
[Sun Aug 30 03:04:13.607486 2026] [authz_core:error] [pid 488281:tid 488503] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fip6t_REJECT%2Fsections
[Sun Aug 30 03:04:13.607950 2026] [authz_core:error] [pid 488281:tid 488503] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fip6t_REJECT%2Fsections
[Sun Aug 30 03:04:13.615154 2026] [security2:error] [pid 488281:tid 488500] [client 4.205.62.107:63766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/h.php"] [unique_id "apPj_TIT5HeNE73zNfqVSQAAAN4"]
[Sun Aug 30 03:04:13.616856 2026] [security2:error] [pid 488281:tid 488435] [client 20.104.50.220:47058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-admin/maint/mailer.php.php"] [unique_id "apPj_TIT5HeNE73zNfqVSgAAAJ0"]
[Sun Aug 30 03:04:13.630321 2026] [security2:error] [pid 488281:tid 488510] [client 20.48.251.3:23484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/sale.php"] [unique_id "apPj_TIT5HeNE73zNfqVTgAAAOg"]
[Sun Aug 30 03:04:13.647162 2026] [autoindex:error] [pid 488669:tid 488817] [client 77.74.177.114:46340] AH01276: Cannot serve directory /home2/rabdesigns/viainboxed.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:04:13.661112 2026] [security2:error] [pid 488281:tid 488443] [client 20.104.50.220:63546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/webshell.php"] [unique_id "apPj_TIT5HeNE73zNfqVWAAAAKU"]
[Sun Aug 30 03:04:13.664028 2026] [security2:error] [pid 488669:tid 488814] [client 20.104.50.220:5466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/themes.php"] [unique_id "apPj_dRh6OewFvqQpDlCWgAAARE"]
[Sun Aug 30 03:04:13.675295 2026] [security2:error] [pid 488281:tid 488417] [client 158.23.184.117:60330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/item.php"] [unique_id "apPj_TIT5HeNE73zNfqVXwAAAIs"]
[Sun Aug 30 03:04:13.680355 2026] [security2:error] [pid 488281:tid 488422] [client 4.205.62.107:52159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/sdsa.php"] [unique_id "apPj_TIT5HeNE73zNfqVYQAAAJA"]
[Sun Aug 30 03:04:13.682114 2026] [security2:error] [pid 488281:tid 488459] [client 4.205.62.107:2766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/fff.php"] [unique_id "apPj_TIT5HeNE73zNfqVYgAAALU"]
[Sun Aug 30 03:04:13.692631 2026] [security2:error] [pid 488669:tid 488878] [client 20.48.251.3:50047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/log.php"] [unique_id "apPj_dRh6OewFvqQpDlCXgAAAVE"]
[Sun Aug 30 03:04:13.712276 2026] [security2:error] [pid 488281:tid 488512] [client 20.104.49.130:36547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.topatrust.com"] [uri "/ws85.php"] [unique_id "apPj_TIT5HeNE73zNfqVcQAAAOo"]
[Sun Aug 30 03:04:13.746771 2026] [security2:error] [pid 488281:tid 488445] [client 68.155.159.216:52735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPj_TIT5HeNE73zNfqVfQAAAKc"]
[Sun Aug 30 03:04:13.762822 2026] [security2:error] [pid 488669:tid 488807] [client 20.104.50.220:33296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-config-sample.php"] [unique_id "apPj_dRh6OewFvqQpDlCZwAAAQo"]
[Sun Aug 30 03:04:13.786129 2026] [authz_core:error] [pid 488281:tid 488496] [client 216.73.216.128:49784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:13.786503 2026] [authz_core:error] [pid 488281:tid 488496] [client 216.73.216.128:49784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:13.807026 2026] [fcgid:warn] [pid 488281:tid 488480] (70014)End of file found: [client 152.32.175.187:54074] mod_fcgid: can't get data from http client
[Sun Aug 30 03:04:13.814415 2026] [security2:error] [pid 488281:tid 488469] [client 158.23.184.117:51150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/wp-admin/controller.php"] [unique_id "apPj_TIT5HeNE73zNfqVmgAAAL8"]
[Sun Aug 30 03:04:13.865053 2026] [security2:error] [pid 488669:tid 488874] [client 20.104.18.15:9116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/133.php"] [unique_id "apPj_dRh6OewFvqQpDlCbAAAAU0"]
[Sun Aug 30 03:04:13.866582 2026] [security2:error] [pid 488281:tid 488527] [client 20.104.50.220:32090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/images/fw.php"] [unique_id "apPj_TIT5HeNE73zNfqVpwAAAPk"]
[Sun Aug 30 03:04:13.887116 2026] [security2:error] [pid 488281:tid 488479] [client 20.48.251.3:64498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/phpsysinfo.php"] [unique_id "apPj_TIT5HeNE73zNfqVrAAAAMk"]
[Sun Aug 30 03:04:13.895018 2026] [security2:error] [pid 488281:tid 488486] [client 20.104.18.15:31588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/abcd.php"] [unique_id "apPj_TIT5HeNE73zNfqVsAAAANA"]
[Sun Aug 30 03:04:13.969916 2026] [authz_core:error] [pid 488281:tid 488537] [client 216.73.216.128:35778] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:13.970360 2026] [authz_core:error] [pid 488281:tid 488537] [client 216.73.216.128:35778] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:13.972831 2026] [security2:error] [pid 488281:tid 488413] [client 4.205.62.107:42627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/hosty.php"] [unique_id "apPj_TIT5HeNE73zNfqV3wAAAIc"]
[Sun Aug 30 03:04:13.995590 2026] [security2:error] [pid 488281:tid 488492] [client 4.205.62.107:18964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/sys.php"] [unique_id "apPj_TIT5HeNE73zNfqV6gAAANY"]
[Sun Aug 30 03:04:13.998183 2026] [security2:error] [pid 488669:tid 488881] [client 4.205.62.107:25668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/params.php"] [unique_id "apPj_dRh6OewFvqQpDlCiAAAAVQ"]
[Sun Aug 30 03:04:14.008384 2026] [security2:error] [pid 488281:tid 488536] [client 20.104.50.220:61828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/dl.php"] [unique_id "apPj_jIT5HeNE73zNfqV7wAAAQI"]
[Sun Aug 30 03:04:14.010015 2026] [security2:error] [pid 488281:tid 488528] [client 20.48.251.3:51524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/motu.php"] [unique_id "apPj_jIT5HeNE73zNfqV8QAAAPo"]
[Sun Aug 30 03:04:14.029610 2026] [authz_core:error] [pid 488281:tid 488482] [client 66.249.66.161:43117] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:14.030089 2026] [authz_core:error] [pid 488281:tid 488482] [client 66.249.66.161:43117] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:14.033001 2026] [security2:error] [pid 488281:tid 488499] [client 34.131.221.169:47616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/phpinfo.php.old"] [unique_id "apPj_jIT5HeNE73zNfqV9gAAAN0"]
[Sun Aug 30 03:04:14.036956 2026] [authz_core:error] [pid 488669:tid 488869] [client 66.249.66.98:57308] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:14.037421 2026] [authz_core:error] [pid 488669:tid 488869] [client 66.249.66.98:57308] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:14.042416 2026] [security2:error] [pid 488281:tid 488502] [client 167.235.143.113:6706] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "nalahenkelaislinn.com"] [uri "/index.php"] [unique_id "apPj_DIT5HeNE73zNfqTOAAAAOA"], referer: https://nalahenkelaislinn.com/
[Sun Aug 30 03:04:14.056519 2026] [security2:error] [pid 488281:tid 488508] [client 20.48.251.3:64456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPj_jIT5HeNE73zNfqWAgAAAOY"]
[Sun Aug 30 03:04:14.059080 2026] [security2:error] [pid 488669:tid 488812] [client 20.104.50.220:28699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/g.php"] [unique_id "apPj_tRh6OewFvqQpDlCkgAAAQ8"]
[Sun Aug 30 03:04:14.071904 2026] [autoindex:error] [pid 488281:tid 488476] [client 158.23.184.117:60305] AH01276: Cannot serve directory /home1/petrajor/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:04:14.077778 2026] [security2:error] [pid 488281:tid 488466] [client 20.104.49.130:64972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.topatrust.com"] [uri "/wp-the.php"] [unique_id "apPj_jIT5HeNE73zNfqWCgAAALw"]
[Sun Aug 30 03:04:14.109909 2026] [authz_core:error] [pid 488281:tid 488436] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Flib%2Frpm%2Fredhat
[Sun Aug 30 03:04:14.110193 2026] [authz_core:error] [pid 488281:tid 488436] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Flib%2Frpm%2Fredhat
[Sun Aug 30 03:04:14.117996 2026] [security2:error] [pid 488281:tid 488415] [client 158.23.184.117:60305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/wp-configs.php"] [unique_id "apPj_jIT5HeNE73zNfqWGAAAAIk"]
[Sun Aug 30 03:04:14.121263 2026] [security2:error] [pid 488669:tid 488815] [client 4.205.62.107:64008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/btx25.php"] [unique_id "apPj_tRh6OewFvqQpDlCpAAAARI"]
[Sun Aug 30 03:04:14.133931 2026] [security2:error] [pid 488281:tid 488483] [client 4.205.62.107:5117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/queue.php"] [unique_id "apPj_jIT5HeNE73zNfqWHgAAAM0"]
[Sun Aug 30 03:04:14.140225 2026] [authz_core:error] [pid 488281:tid 488519] [client 66.249.66.70:40586] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:14.140577 2026] [authz_core:error] [pid 488281:tid 488519] [client 66.249.66.70:40586] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:14.144511 2026] [security2:error] [pid 488669:tid 488905] [client 20.48.251.3:65507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/wp-class.php"] [unique_id "apPj_tRh6OewFvqQpDlCrAAAAWw"]
[Sun Aug 30 03:04:14.148518 2026] [autoindex:error] [pid 488281:tid 488438] [client 93.159.230.84:59312] AH01276: Cannot serve directory /home2/rabdesigns/viainboxed.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:04:14.215692 2026] [security2:error] [pid 488281:tid 488483] [client 158.23.147.79:62833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apPj_jIT5HeNE73zNfqWUgAAAM0"]
[Sun Aug 30 03:04:14.232053 2026] [security2:error] [pid 488669:tid 488887] [client 34.131.221.169:47626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/info.php.bak"] [unique_id "apPj_tRh6OewFvqQpDlCzgAAAVo"]
[Sun Aug 30 03:04:14.258334 2026] [security2:error] [pid 488669:tid 488872] [client 158.23.184.117:7583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/wp-admin/user/credits.php"] [unique_id "apPj_tRh6OewFvqQpDlC2AAAAUs"]
[Sun Aug 30 03:04:14.263239 2026] [security2:error] [pid 488281:tid 488451] [client 4.205.62.107:65311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/admin-ajax.php"] [unique_id "apPj_jIT5HeNE73zNfqWbQAAAK0"]
[Sun Aug 30 03:04:14.328379 2026] [security2:error] [pid 488669:tid 488914] [client 4.205.62.107:27279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/app_local.php"] [unique_id "apPj_tRh6OewFvqQpDlC8QAAAXU"]
[Sun Aug 30 03:04:14.395849 2026] [security2:error] [pid 488281:tid 488515] [client 68.155.159.216:60587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/atomlib.php"] [unique_id "apPj_jIT5HeNE73zNfqWsAAAAO0"]
[Sun Aug 30 03:04:14.401468 2026] [security2:error] [pid 488281:tid 488445] [client 20.104.49.130:53809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.cherylvalk.com"] [uri "/press.php"] [unique_id "apPj_jIT5HeNE73zNfqWtwAAAKc"]
[Sun Aug 30 03:04:14.408850 2026] [security2:error] [pid 488281:tid 488494] [client 20.104.18.15:3849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lakewoodshuttle.deevosdesigns.com"] [uri "/reviall.php"] [unique_id "apPj_jIT5HeNE73zNfqWvwAAANg"]
[Sun Aug 30 03:04:14.410831 2026] [security2:error] [pid 488281:tid 488417] [client 20.48.251.3:7076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/cloud.php"] [unique_id "apPj_jIT5HeNE73zNfqWwAAAAIs"]
[Sun Aug 30 03:04:14.416469 2026] [security2:error] [pid 488669:tid 488926] [client 158.23.184.117:60307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "apPj_tRh6OewFvqQpDlDEAAAAYE"]
[Sun Aug 30 03:04:14.434226 2026] [security2:error] [pid 488281:tid 488451] [client 20.48.251.3:31636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lastmaskcenter.org"] [uri "/wdf.php"] [unique_id "apPj_jIT5HeNE73zNfqW3AAAAK0"]
[Sun Aug 30 03:04:14.454963 2026] [security2:error] [pid 488281:tid 488453] [client 20.104.50.220:62847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-admin/f0x.php"] [unique_id "apPj_jIT5HeNE73zNfqW6wAAAK8"]
[Sun Aug 30 03:04:14.556335 2026] [security2:error] [pid 488281:tid 488436] [client 158.23.184.117:51176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/.well-known/about/function.php"] [unique_id "apPj_jIT5HeNE73zNfqXLQAAAJ4"]
[Sun Aug 30 03:04:14.574356 2026] [security2:error] [pid 488281:tid 488434] [client 4.205.62.107:36616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/drykl.php"] [unique_id "apPj_jIT5HeNE73zNfqXNQAAAJw"]
[Sun Aug 30 03:04:14.576357 2026] [authz_core:error] [pid 488281:tid 488443] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Flib%2Frpm%2Fredhat
[Sun Aug 30 03:04:14.576483 2026] [security2:error] [pid 488281:tid 488440] [client 4.205.62.107:22571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/ws61.php"] [unique_id "apPj_jIT5HeNE73zNfqXNgAAAKI"]
[Sun Aug 30 03:04:14.576486 2026] [security2:error] [pid 488669:tid 488808] [client 20.151.200.44:58890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPj_tRh6OewFvqQpDlDZAAAAQs"]
[Sun Aug 30 03:04:14.576801 2026] [authz_core:error] [pid 488281:tid 488443] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Flib%2Frpm%2Fredhat
[Sun Aug 30 03:04:14.614939 2026] [authz_core:error] [pid 488281:tid 488513] [client 66.249.66.37:54715] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:14.615474 2026] [authz_core:error] [pid 488281:tid 488513] [client 66.249.66.37:54715] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:14.633623 2026] [authz_core:error] [pid 488281:tid 488487] [client 66.249.66.206:49723] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:14.633718 2026] [security2:error] [pid 488281:tid 488467] [client 4.205.62.107:44873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/nw.php"] [unique_id "apPj_jIT5HeNE73zNfqXTAAAAL0"]
[Sun Aug 30 03:04:14.634062 2026] [authz_core:error] [pid 488281:tid 488487] [client 66.249.66.206:49723] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:14.696660 2026] [security2:error] [pid 488281:tid 488447] [client 158.23.184.117:51164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPj_jIT5HeNE73zNfqXZgAAAKk"]
[Sun Aug 30 03:04:14.729748 2026] [security2:error] [pid 488281:tid 488527] [client 20.104.50.220:30329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/Nonce.php"] [unique_id "apPj_jIT5HeNE73zNfqXbgAAAPk"]
[Sun Aug 30 03:04:14.730992 2026] [security2:error] [pid 488281:tid 488512] [client 20.48.251.3:52805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/aws_sdk_settings.php"] [unique_id "apPj_jIT5HeNE73zNfqXbwAAAOo"]
[Sun Aug 30 03:04:14.753999 2026] [security2:error] [pid 488281:tid 488446] [client 4.205.62.107:63596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/bootstrap.php"] [unique_id "apPj_jIT5HeNE73zNfqXeQAAAKg"]
[Sun Aug 30 03:04:14.772258 2026] [security2:error] [pid 488669:tid 488818] [client 20.104.50.220:46193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-admin/css/mailer.php.php"] [unique_id "apPj_tRh6OewFvqQpDlDhgAAARU"]
[Sun Aug 30 03:04:14.773174 2026] [security2:error] [pid 488281:tid 488474] [client 20.48.251.3:23463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/wp-class.php"] [unique_id "apPj_jIT5HeNE73zNfqXfgAAAMQ"]
[Sun Aug 30 03:04:14.790038 2026] [security2:error] [pid 488669:tid 488876] [client 34.131.221.169:47642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/phpinfo.php~"] [unique_id "apPj_tRh6OewFvqQpDlDiQAAAU8"]
[Sun Aug 30 03:04:14.802437 2026] [security2:error] [pid 488281:tid 488452] [client 20.104.50.220:5505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-admin/maint/about.php"] [unique_id "apPj_jIT5HeNE73zNfqXigAAAK4"]
[Sun Aug 30 03:04:14.817017 2026] [security2:error] [pid 488669:tid 488934] [client 4.205.62.107:52119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/sale.php"] [unique_id "apPj_tRh6OewFvqQpDlDjAAAAYk"]
[Sun Aug 30 03:04:14.817756 2026] [security2:error] [pid 488669:tid 488920] [client 20.104.50.220:63523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wso25.php"] [unique_id "apPj_tRh6OewFvqQpDlDjQAAAXs"]
[Sun Aug 30 03:04:14.825352 2026] [security2:error] [pid 488669:tid 488820] [client 4.205.62.107:2969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/autogooey.php"] [unique_id "apPj_tRh6OewFvqQpDlDjgAAARc"]
[Sun Aug 30 03:04:14.828047 2026] [security2:error] [pid 488281:tid 488521] [client 20.48.251.3:55474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/ebahvhhh.php"] [unique_id "apPj_jIT5HeNE73zNfqXlQAAAPM"]
[Sun Aug 30 03:04:14.853844 2026] [security2:error] [pid 488281:tid 488490] [client 158.23.184.117:7603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/gg.php"] [unique_id "apPj_jIT5HeNE73zNfqXogAAANQ"]
[Sun Aug 30 03:04:14.861429 2026] [security2:error] [pid 488281:tid 488527] [client 4.205.62.107:32504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/saml.php"] [unique_id "apPj_jIT5HeNE73zNfqXpAAAAPk"]
[Sun Aug 30 03:04:14.902045 2026] [security2:error] [pid 488281:tid 488491] [client 4.205.62.107:32017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/setup-config.php"] [unique_id "apPj_jIT5HeNE73zNfqXsQAAANU"]
[Sun Aug 30 03:04:14.902341 2026] [autoindex:error] [pid 488281:tid 488496] [client 93.159.230.84:44160] AH01276: Cannot serve directory /home2/rabdesigns/viainboxed.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:04:14.903664 2026] [security2:error] [pid 488281:tid 488452] [client 20.104.50.220:33558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/blog/fw.php"] [unique_id "apPj_jIT5HeNE73zNfqXswAAAK4"]
[Sun Aug 30 03:04:14.956203 2026] [security2:error] [pid 488281:tid 488450] [client 68.155.159.216:54780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apPj_jIT5HeNE73zNfqXxwAAAKw"]
[Sun Aug 30 03:04:14.961436 2026] [security2:error] [pid 488281:tid 488488] [client 34.131.221.169:47650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/phpinfo.php.save"] [unique_id "apPj_jIT5HeNE73zNfqXzwAAANI"]
[Sun Aug 30 03:04:14.994624 2026] [security2:error] [pid 488281:tid 488492] [client 158.23.184.117:7588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/wp-admin/includes/post.php"] [unique_id "apPj_jIT5HeNE73zNfqX5gAAANY"]
[Sun Aug 30 03:04:14.999871 2026] [security2:error] [pid 488281:tid 488508] [client 20.104.18.15:9188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/sym.php"] [unique_id "apPj_jIT5HeNE73zNfqX6QAAAOY"]
[Sun Aug 30 03:04:15.011826 2026] [security2:error] [pid 488281:tid 488507] [client 20.104.50.220:32122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/images/alfa.php"] [unique_id "apPj_zIT5HeNE73zNfqX7QAAAOU"]
[Sun Aug 30 03:04:15.032117 2026] [security2:error] [pid 488669:tid 488884] [client 20.48.251.3:6480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/sgd.php"] [unique_id "apPj_9Rh6OewFvqQpDlDpQAAAVc"]
[Sun Aug 30 03:04:15.067245 2026] [security2:error] [pid 488281:tid 488469] [client 20.104.18.15:31708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/nofile.php"] [unique_id "apPj_zIT5HeNE73zNfqYAQAAAL8"]
[Sun Aug 30 03:04:15.113175 2026] [authz_core:error] [pid 488281:tid 488494] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flsof
[Sun Aug 30 03:04:15.113587 2026] [authz_core:error] [pid 488281:tid 488494] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flsof
[Sun Aug 30 03:04:15.138804 2026] [security2:error] [pid 488669:tid 488825] [client 4.205.62.107:18976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/phpsysinfo.php"] [unique_id "apPj_9Rh6OewFvqQpDlDuwAAARw"]
[Sun Aug 30 03:04:15.151208 2026] [security2:error] [pid 488281:tid 488414] [client 4.205.62.107:25758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/gjm.php"] [unique_id "apPj_zIT5HeNE73zNfqYJwAAAIg"]
[Sun Aug 30 03:04:15.158721 2026] [security2:error] [pid 488281:tid 488515] [client 20.48.251.3:59133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/public/mah.php.php"] [unique_id "apPj_zIT5HeNE73zNfqYLwAAAO0"]
[Sun Aug 30 03:04:15.175741 2026] [security2:error] [pid 488281:tid 488537] [client 4.205.62.107:42816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/pass4.php"] [unique_id "apPj_zIT5HeNE73zNfqYPAAAAQM"]
[Sun Aug 30 03:04:15.176507 2026] [security2:error] [pid 488669:tid 488929] [client 20.104.50.220:61642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/donate.php"] [unique_id "apPj_9Rh6OewFvqQpDlDwQAAAYQ"]
[Sun Aug 30 03:04:15.185884 2026] [security2:error] [pid 488669:tid 488892] [client 158.23.184.117:51145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "helalat-group.com"] [uri "/wp-act.php"] [unique_id "apPj_9Rh6OewFvqQpDlDyAAAAV8"]
[Sun Aug 30 03:04:15.196775 2026] [security2:error] [pid 488669:tid 488816] [client 20.104.49.130:35588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trinitytechnologics.com"] [uri "/ms-edit.php"] [unique_id "apPj_9Rh6OewFvqQpDlDzgAAARM"]
[Sun Aug 30 03:04:15.198535 2026] [security2:error] [pid 488281:tid 488505] [client 20.104.50.220:28691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/f.php"] [unique_id "apPj_zIT5HeNE73zNfqYSwAAAOM"]
[Sun Aug 30 03:04:15.201829 2026] [security2:error] [pid 488669:tid 488882] [client 20.48.251.3:7055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/rem.php"] [unique_id "apPj_9Rh6OewFvqQpDlD0AAAAVU"]
[Sun Aug 30 03:04:15.210770 2026] [security2:error] [pid 488669:tid 488826] [client 20.104.49.130:40207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.topatrust.com"] [uri "/155.php"] [unique_id "apPj_9Rh6OewFvqQpDlD0wAAAR0"]
[Sun Aug 30 03:04:15.239947 2026] [authz_core:error] [pid 488669:tid 488933] [client 66.249.66.160:55076] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:15.240365 2026] [authz_core:error] [pid 488669:tid 488933] [client 66.249.66.160:55076] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:15.249788 2026] [security2:error] [pid 488281:tid 488525] [client 158.23.147.79:55187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apPj_zIT5HeNE73zNfqYXAAAAPc"]
[Sun Aug 30 03:04:15.260864 2026] [security2:error] [pid 488281:tid 488424] [client 4.205.62.107:63970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/app_dev.php"] [unique_id "apPj_zIT5HeNE73zNfqYZgAAAJI"]
[Sun Aug 30 03:04:15.291864 2026] [security2:error] [pid 488281:tid 488517] [client 20.48.251.3:46236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/database.php"] [unique_id "apPj_zIT5HeNE73zNfqYewAAAO8"]
[Sun Aug 30 03:04:15.361450 2026] [security2:error] [pid 488281:tid 488466] [client 4.205.62.107:4566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/doc.php"] [unique_id "apPj_zIT5HeNE73zNfqYoQAAALw"]
[Sun Aug 30 03:04:15.386565 2026] [security2:error] [pid 488281:tid 488527] [client 114.119.147.74:64941] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.tulsaattorney.pro"] [uri "/Tulsa-lawyer-blog/child-abuse/"] [unique_id "apPj_zIT5HeNE73zNfqYsQAAAPk"], referer: https://www.tulsaattorney.pro/Tulsa-lawyer-blog/child-abuse/
[Sun Aug 30 03:04:15.392467 2026] [autoindex:error] [pid 488281:tid 488498] [client 77.74.177.118:43982] AH01276: Cannot serve directory /home2/rabdesigns/viainboxed.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:04:15.419005 2026] [authz_core:error] [pid 488281:tid 488430] [client 66.249.66.99:42512] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:15.419425 2026] [authz_core:error] [pid 488281:tid 488430] [client 66.249.66.99:42512] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:15.446629 2026] [security2:error] [pid 488281:tid 488427] [client 4.205.62.107:65394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/ms.php"] [unique_id "apPj_zIT5HeNE73zNfqY4wAAAJU"]
[Sun Aug 30 03:04:15.535867 2026] [security2:error] [pid 488669:tid 488910] [client 34.131.221.169:47666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/info.php.bak"] [unique_id "apPj_9Rh6OewFvqQpDlEggAAAXE"]
[Sun Aug 30 03:04:15.567768 2026] [authz_core:error] [pid 488281:tid 488506] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Flib%2Frpm%2Fredhat
[Sun Aug 30 03:04:15.568233 2026] [authz_core:error] [pid 488281:tid 488506] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Flib%2Frpm%2Fredhat
[Sun Aug 30 03:04:15.573360 2026] [security2:error] [pid 488669:tid 488841] [client 20.48.251.3:64746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lastmaskcenter.org"] [uri "/bb.php"] [unique_id "apPj_9Rh6OewFvqQpDlEkQAAASw"]
[Sun Aug 30 03:04:15.589963 2026] [security2:error] [pid 488669:tid 488851] [client 68.155.159.216:59375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/lv.php"] [unique_id "apPj_9Rh6OewFvqQpDlElgAAATY"]
[Sun Aug 30 03:04:15.614268 2026] [security2:error] [pid 488281:tid 488441] [client 20.104.50.220:62790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-content/uploads/meiwei.php"] [unique_id "apPj_zIT5HeNE73zNfqZNwAAAKM"]
[Sun Aug 30 03:04:15.626974 2026] [authz_core:error] [pid 488281:tid 488507] [client 216.73.216.128:49784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:15.627254 2026] [authz_core:error] [pid 488281:tid 488507] [client 216.73.216.128:49784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:15.670365 2026] [security2:error] [pid 488281:tid 488498] [client 20.48.251.3:7064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/min.php"] [unique_id "apPj_zIT5HeNE73zNfqZSQAAANw"]
[Sun Aug 30 03:04:15.698240 2026] [security2:error] [pid 488281:tid 488494] [client 34.131.221.169:47674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/staging/phpinfo.php"] [unique_id "apPj_zIT5HeNE73zNfqZVwAAANg"]
[Sun Aug 30 03:04:15.726841 2026] [security2:error] [pid 488669:tid 488821] [client 4.205.62.107:22936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/xza.php"] [unique_id "apPj_9Rh6OewFvqQpDlEqgAAARg"]
[Sun Aug 30 03:04:15.727688 2026] [authz_core:error] [pid 488669:tid 488894] [client 66.249.66.162:58167] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:15.727962 2026] [authz_core:error] [pid 488669:tid 488894] [client 66.249.66.162:58167] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:15.773545 2026] [security2:error] [pid 488669:tid 488903] [client 4.205.62.107:44780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/product.php"] [unique_id "apPj_9Rh6OewFvqQpDlErgAAAWo"]
[Sun Aug 30 03:04:15.873158 2026] [security2:error] [pid 488281:tid 488483] [client 20.48.251.3:59381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/setup-config.php"] [unique_id "apPj_zIT5HeNE73zNfqZigAAAM0"]
[Sun Aug 30 03:04:15.873957 2026] [security2:error] [pid 488281:tid 488448] [client 20.104.50.220:30306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/common.php"] [unique_id "apPj_zIT5HeNE73zNfqZiwAAAKo"]
[Sun Aug 30 03:04:15.890989 2026] [security2:error] [pid 488281:tid 488522] [client 4.205.62.107:63604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/333.php"] [unique_id "apPj_zIT5HeNE73zNfqZjgAAAPQ"]
[Sun Aug 30 03:04:15.906249 2026] [authz_core:error] [pid 488281:tid 488482] [client 216.73.216.128:49784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:15.906659 2026] [authz_core:error] [pid 488281:tid 488482] [client 216.73.216.128:49784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:15.910912 2026] [security2:error] [pid 488281:tid 488500] [client 20.104.50.220:46354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-includes/css/mailer.php.php"] [unique_id "apPj_zIT5HeNE73zNfqZmQAAAN4"]
[Sun Aug 30 03:04:15.912334 2026] [security2:error] [pid 488281:tid 488420] [client 20.48.251.3:23461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/database.php"] [unique_id "apPj_zIT5HeNE73zNfqZmgAAAI4"]
[Sun Aug 30 03:04:15.956143 2026] [security2:error] [pid 488281:tid 488419] [client 4.205.62.107:51734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/wp-class.php"] [unique_id "apPj_zIT5HeNE73zNfqZrwAAAI0"]
[Sun Aug 30 03:04:15.959134 2026] [security2:error] [pid 488281:tid 488446] [client 20.104.49.130:43166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wondertanks.com"] [uri "/ortasekerli1.php"] [unique_id "apPj_zIT5HeNE73zNfqZsAAAAKg"]
[Sun Aug 30 03:04:15.960011 2026] [security2:error] [pid 488281:tid 488443] [client 4.205.62.107:2988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/sdsa.php"] [unique_id "apPj_zIT5HeNE73zNfqZsQAAAKU"]
[Sun Aug 30 03:04:15.961307 2026] [security2:error] [pid 488669:tid 488879] [client 20.104.50.220:5514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-admin/network/wp-conflg.php"] [unique_id "apPj_9Rh6OewFvqQpDlEyQAAAVI"]
[Sun Aug 30 03:04:15.967615 2026] [security2:error] [pid 488669:tid 488875] [client 20.104.50.220:63542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wso2022_shell.php"] [unique_id "apPj_9Rh6OewFvqQpDlEywAAAU4"]
[Sun Aug 30 03:04:15.968901 2026] [security2:error] [pid 488669:tid 488820] [client 20.48.251.3:55543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/asa.php"] [unique_id "apPj_9Rh6OewFvqQpDlEzAAAARc"]
[Sun Aug 30 03:04:15.994065 2026] [authz_core:error] [pid 488281:tid 488513] [client 216.73.216.128:51358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:15.994222 2026] [security2:error] [pid 488281:tid 488448] [client 158.23.147.79:55071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apPj_zIT5HeNE73zNfqZyQAAAKo"]
[Sun Aug 30 03:04:15.994471 2026] [authz_core:error] [pid 488281:tid 488513] [client 216.73.216.128:51358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:16.058045 2026] [security2:error] [pid 488281:tid 488504] [client 20.104.50.220:33065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-optionss.php"] [unique_id "apPkADIT5HeNE73zNfqZ1QAAAOI"]
[Sun Aug 30 03:04:16.060567 2026] [security2:error] [pid 488281:tid 488456] [client 4.205.62.107:26501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/ws62.php"] [unique_id "apPkADIT5HeNE73zNfqZ1wAAALI"]
[Sun Aug 30 03:04:16.093243 2026] [security2:error] [pid 488281:tid 488443] [client 68.155.159.216:54721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-content/radio.php"] [unique_id "apPkADIT5HeNE73zNfqZ4AAAAKU"]
[Sun Aug 30 03:04:16.099464 2026] [authz_core:error] [pid 488281:tid 488419] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Flib%2Frpm%2Fredhat
[Sun Aug 30 03:04:16.099861 2026] [authz_core:error] [pid 488281:tid 488419] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Flib%2Frpm%2Fredhat
[Sun Aug 30 03:04:16.133508 2026] [security2:error] [pid 488281:tid 488415] [client 20.104.49.130:36558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.topatrust.com"] [uri "/fs.php"] [unique_id "apPkADIT5HeNE73zNfqZ9wAAAIk"]
[Sun Aug 30 03:04:16.143997 2026] [security2:error] [pid 488281:tid 488502] [client 20.104.18.15:9061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/8.php"] [unique_id "apPkADIT5HeNE73zNfqaAgAAAOA"]
[Sun Aug 30 03:04:16.163780 2026] [security2:error] [pid 488281:tid 488514] [client 20.104.50.220:32117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/images/alfashell.php"] [unique_id "apPkADIT5HeNE73zNfqaDAAAAOw"]
[Sun Aug 30 03:04:16.179675 2026] [security2:error] [pid 488281:tid 488499] [client 20.151.200.44:58819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/h02ugyh.php"] [unique_id "apPkADIT5HeNE73zNfqaFQAAAN0"]
[Sun Aug 30 03:04:16.190979 2026] [authz_core:error] [pid 488669:tid 488882] [client 66.249.66.160:55076] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:16.191409 2026] [authz_core:error] [pid 488669:tid 488882] [client 66.249.66.160:55076] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:16.197542 2026] [security2:error] [pid 488281:tid 488470] [client 20.48.251.3:6505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/fleen.php"] [unique_id "apPkADIT5HeNE73zNfqaLAAAAMA"]
[Sun Aug 30 03:04:16.239180 2026] [security2:error] [pid 488281:tid 488412] [client 20.104.18.15:31725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/run.php"] [unique_id "apPkADIT5HeNE73zNfqaQQAAAIY"]
[Sun Aug 30 03:04:16.270449 2026] [authz_core:error] [pid 488281:tid 488436] [client 216.73.216.128:51358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:16.270934 2026] [authz_core:error] [pid 488281:tid 488436] [client 216.73.216.128:51358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:16.272606 2026] [security2:error] [pid 488281:tid 488493] [client 4.205.62.107:18753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/sgd.php"] [unique_id "apPkADIT5HeNE73zNfqaVAAAANc"]
[Sun Aug 30 03:04:16.295858 2026] [security2:error] [pid 488281:tid 488494] [client 34.131.221.169:49416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/phpinfo.php.save"] [unique_id "apPkADIT5HeNE73zNfqaXwAAANg"]
[Sun Aug 30 03:04:16.301930 2026] [security2:error] [pid 488281:tid 488437] [client 4.205.62.107:25897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/configuration.php"] [unique_id "apPkADIT5HeNE73zNfqaZQAAAJ8"]
[Sun Aug 30 03:04:16.319960 2026] [security2:error] [pid 488669:tid 488826] [client 4.205.62.107:42852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/cu.php"] [unique_id "apPkANRh6OewFvqQpDlFLgAAAR0"]
[Sun Aug 30 03:04:16.334811 2026] [security2:error] [pid 488281:tid 488509] [client 5.231.59.180:35244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.59.231.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifecraftllc.com"] [uri "/wp-login.php"] [unique_id "apPkADIT5HeNE73zNfqaawAAAOc"]
[Sun Aug 30 03:04:16.336139 2026] [security2:error] [pid 488281:tid 488448] [client 20.104.50.220:62832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/e.php"] [unique_id "apPkADIT5HeNE73zNfqaigAAAKo"]
[Sun Aug 30 03:04:16.357877 2026] [security2:error] [pid 488669:tid 488846] [client 20.48.251.3:7372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/saiga.php"] [unique_id "apPkANRh6OewFvqQpDlFNQAAATE"]
[Sun Aug 30 03:04:16.377479 2026] [security2:error] [pid 488669:tid 488837] [client 20.151.200.44:58923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/sf.php"] [unique_id "apPkANRh6OewFvqQpDlFOAAAASg"]
[Sun Aug 30 03:04:16.379534 2026] [security2:error] [pid 488281:tid 488432] [client 20.48.251.3:51484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/zaza.php"] [unique_id "apPkADIT5HeNE73zNfqanAAAAJo"]
[Sun Aug 30 03:04:16.400583 2026] [security2:error] [pid 488669:tid 488834] [client 4.205.62.107:62133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/php-info.php"] [unique_id "apPkANRh6OewFvqQpDlFTAAAASU"]
[Sun Aug 30 03:04:16.405973 2026] [authz_core:error] [pid 488281:tid 488477] [client 66.249.66.15:56192] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:16.406237 2026] [authz_core:error] [pid 488281:tid 488477] [client 66.249.66.15:56192] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:16.407787 2026] [security2:error] [pid 488669:tid 488879] [client 20.104.50.220:63031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/tntmar.php"] [unique_id "apPkANRh6OewFvqQpDlFTgAAAVI"]
[Sun Aug 30 03:04:16.428409 2026] [security2:error] [pid 488669:tid 488906] [client 34.131.221.169:49432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/beta/phpinfo.php"] [unique_id "apPkANRh6OewFvqQpDlFXgAAAW0"]
[Sun Aug 30 03:04:16.446334 2026] [security2:error] [pid 488281:tid 488420] [client 20.48.251.3:54840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/atex1.php"] [unique_id "apPkADIT5HeNE73zNfqazgAAAI4"]
[Sun Aug 30 03:04:16.491540 2026] [security2:error] [pid 488281:tid 488461] [client 4.205.62.107:32498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/wp-admin/sc.php"] [unique_id "apPkADIT5HeNE73zNfqa9wAAALc"]
[Sun Aug 30 03:04:16.493221 2026] [security2:error] [pid 488281:tid 488521] [client 4.205.62.107:32015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/aws_settings.php"] [unique_id "apPkADIT5HeNE73zNfqa-QAAAPM"]
[Sun Aug 30 03:04:16.510190 2026] [security2:error] [pid 488669:tid 488891] [client 158.23.147.79:55201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/dropdown.php"] [unique_id "apPkANRh6OewFvqQpDlFmgAAAV4"]
[Sun Aug 30 03:04:16.515843 2026] [security2:error] [pid 488669:tid 488923] [client 4.205.62.107:36622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/rpk.php"] [unique_id "apPkANRh6OewFvqQpDlFngAAAX4"]
[Sun Aug 30 03:04:16.543602 2026] [authz_core:error] [pid 488281:tid 488417] [client 216.73.216.128:51358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:16.543931 2026] [authz_core:error] [pid 488281:tid 488417] [client 216.73.216.128:51358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:16.568700 2026] [authz_core:error] [pid 488281:tid 488476] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fdpkg
[Sun Aug 30 03:04:16.569012 2026] [authz_core:error] [pid 488281:tid 488476] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fdpkg
[Sun Aug 30 03:04:16.584751 2026] [security2:error] [pid 488281:tid 488520] [client 4.205.62.107:58055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/fucku.php"] [unique_id "apPkADIT5HeNE73zNfqbLgAAAPI"]
[Sun Aug 30 03:04:16.631438 2026] [security2:error] [pid 488281:tid 488491] [client 4.205.62.107:5111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/css.php"] [unique_id "apPkADIT5HeNE73zNfqbQgAAANU"]
[Sun Aug 30 03:04:16.720986 2026] [security2:error] [pid 488281:tid 488531] [client 158.23.147.79:55085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/sad/about.php"] [unique_id "apPkADIT5HeNE73zNfqbXgAAAP0"]
[Sun Aug 30 03:04:16.721500 2026] [security2:error] [pid 488281:tid 488443] [client 20.48.251.3:31639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lastmaskcenter.org"] [uri "/file59.php"] [unique_id "apPkADIT5HeNE73zNfqbXwAAAKU"]
[Sun Aug 30 03:04:16.724985 2026] [security2:error] [pid 488281:tid 488519] [client 20.104.49.130:63587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/dex.php"] [unique_id "apPkADIT5HeNE73zNfqbYgAAAPE"]
[Sun Aug 30 03:04:16.787500 2026] [security2:error] [pid 488281:tid 488437] [client 20.104.50.220:28689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/f0x.php"] [unique_id "apPkADIT5HeNE73zNfqbeAAAAJ8"]
[Sun Aug 30 03:04:16.789785 2026] [authz_core:error] [pid 488669:tid 488847] [client 66.249.66.37:41586] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:16.790267 2026] [authz_core:error] [pid 488669:tid 488847] [client 66.249.66.37:41586] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:16.794901 2026] [security2:error] [pid 488281:tid 488464] [client 68.155.159.216:59362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-includes/Text/index.php"] [unique_id "apPkADIT5HeNE73zNfqbfAAAALo"]
[Sun Aug 30 03:04:16.807898 2026] [security2:error] [pid 488669:tid 488871] [client 34.16.144.252:7744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.144.16.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alchemancer.com"] [uri "/config/aws.php"] [unique_id "apPkANRh6OewFvqQpDlF1gAAAUo"]
[Sun Aug 30 03:04:16.809782 2026] [security2:error] [pid 488281:tid 488508] [client 34.16.144.252:7790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/.aws/credentials.bak"] [unique_id "apPkADIT5HeNE73zNfqbjQAAAOY"]
[Sun Aug 30 03:04:16.811208 2026] [security2:error] [pid 488669:tid 488923] [client 34.16.144.252:7788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/aws/.env"] [unique_id "apPkANRh6OewFvqQpDlF3AAAAX4"]
[Sun Aug 30 03:04:16.814546 2026] [security2:error] [pid 488281:tid 488510] [client 34.16.144.252:7814] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/.aws/credentials.old"] [unique_id "apPkADIT5HeNE73zNfqblQAAAOg"]
[Sun Aug 30 03:04:16.845465 2026] [security2:error] [pid 488281:tid 488484] [client 34.16.144.252:7562] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/push_config.json"] [unique_id "apPkADIT5HeNE73zNfqbggAAAM4"]
[Sun Aug 30 03:04:16.878477 2026] [security2:error] [pid 488281:tid 488509] [client 20.151.200.44:58882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/4e.php"] [unique_id "apPkADIT5HeNE73zNfqbrAAAAOc"]
[Sun Aug 30 03:04:16.878919 2026] [security2:error] [pid 488669:tid 488820] [client 4.205.62.107:22547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/ms-edit.php"] [unique_id "apPkANRh6OewFvqQpDlF5QAAARc"]
[Sun Aug 30 03:04:16.910027 2026] [security2:error] [pid 488669:tid 488934] [client 4.205.62.107:44783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/fun.php"] [unique_id "apPkANRh6OewFvqQpDlF6gAAAYk"]
[Sun Aug 30 03:04:16.911505 2026] [security2:error] [pid 488281:tid 488453] [client 20.48.251.3:64389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/ammika.php"] [unique_id "apPkADIT5HeNE73zNfqbswAAAK8"]
[Sun Aug 30 03:04:16.963420 2026] [security2:error] [pid 488281:tid 488512] [client 74.7.175.164:45342] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "lastmaskcenter.com"] [uri "/robots.txt"] [unique_id "apPkADIT5HeNE73zNfqbugAA6nE"]
[Sun Aug 30 03:04:16.963497 2026] [security2:error] [pid 488281:tid 488415] [client 158.23.147.79:55224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/admin.php"] [unique_id "apPkADIT5HeNE73zNfqbywAAAIk"]
[Sun Aug 30 03:04:17.011970 2026] [security2:error] [pid 488281:tid 488486] [client 20.104.50.220:30031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/Block.php"] [unique_id "apPkATIT5HeNE73zNfqb7AAAANA"]
[Sun Aug 30 03:04:17.022525 2026] [security2:error] [pid 488281:tid 488505] [client 4.205.62.107:63566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/G-in.php"] [unique_id "apPkATIT5HeNE73zNfqb7wAAAOM"]
[Sun Aug 30 03:04:17.034742 2026] [security2:error] [pid 488281:tid 488413] [client 34.131.221.169:49446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/staging/phpinfo.php"] [unique_id "apPkATIT5HeNE73zNfqb8QAAAIc"]
[Sun Aug 30 03:04:17.045511 2026] [security2:error] [pid 488281:tid 488431] [client 20.48.251.3:59349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/wp-admin/sc.php"] [unique_id "apPkATIT5HeNE73zNfqb9wAAAJk"]
[Sun Aug 30 03:04:17.047283 2026] [security2:error] [pid 488281:tid 488415] [client 20.104.50.220:46156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-admin/mailer.php"] [unique_id "apPkATIT5HeNE73zNfqb-QAAAIk"]
[Sun Aug 30 03:04:17.049202 2026] [security2:error] [pid 488281:tid 488519] [client 20.48.251.3:44182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/atex1.php"] [unique_id "apPkATIT5HeNE73zNfqb-wAAAPE"]
[Sun Aug 30 03:04:17.085317 2026] [authz_core:error] [pid 488281:tid 488446] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fvar%2Flib%2Fpcp
[Sun Aug 30 03:04:17.085888 2026] [authz_core:error] [pid 488281:tid 488446] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fvar%2Flib%2Fpcp
[Sun Aug 30 03:04:17.093144 2026] [security2:error] [pid 488281:tid 488502] [client 4.205.62.107:56635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/database.php"] [unique_id "apPkATIT5HeNE73zNfqcEQAAAOA"]
[Sun Aug 30 03:04:17.104581 2026] [security2:error] [pid 488669:tid 488894] [client 20.48.251.3:55473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/radio.php"] [unique_id "apPkAdRh6OewFvqQpDlGCQAAAWE"]
[Sun Aug 30 03:04:17.108981 2026] [security2:error] [pid 488281:tid 488442] [client 20.104.50.220:5440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/click.php"] [unique_id "apPkATIT5HeNE73zNfqcHAAAAKQ"]
[Sun Aug 30 03:04:17.112544 2026] [security2:error] [pid 488281:tid 488456] [client 4.205.62.107:2131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/sale.php"] [unique_id "apPkATIT5HeNE73zNfqcHwAAALI"]
[Sun Aug 30 03:04:17.114358 2026] [security2:error] [pid 488669:tid 488916] [client 20.104.50.220:42758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wpxadmin.php"] [unique_id "apPkAdRh6OewFvqQpDlGCwAAAXc"]
[Sun Aug 30 03:04:17.139104 2026] [security2:error] [pid 488669:tid 488918] [client 20.104.49.130:65001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.topatrust.com"] [uri "/kgoc6awap3napxxxdCdefault.php"] [unique_id "apPkAdRh6OewFvqQpDlGDwAAAXk"]
[Sun Aug 30 03:04:17.166627 2026] [security2:error] [pid 488281:tid 488481] [client 34.131.221.169:49448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/uat/phpinfo.php"] [unique_id "apPkATIT5HeNE73zNfqcQQAAAMs"]
[Sun Aug 30 03:04:17.195406 2026] [security2:error] [pid 488281:tid 488425] [client 20.104.50.220:33177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/work.php"] [unique_id "apPkATIT5HeNE73zNfqcVwAAAJM"]
[Sun Aug 30 03:04:17.277595 2026] [security2:error] [pid 488281:tid 488434] [client 74.7.228.5:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webmail.marcoabreu.com"] [uri "/___proxy_subdomain_webmail/cgi-sys/404.html"] [unique_id "apPkATIT5HeNE73zNfqciQAAAJw"]
[Sun Aug 30 03:04:17.280606 2026] [security2:error] [pid 488281:tid 488475] [client 74.7.228.5:47216] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webmail.marcoabreu.com"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "apPkATIT5HeNE73zNfqcfgAAxXk"]
[Sun Aug 30 03:04:17.302834 2026] [security2:error] [pid 488281:tid 488528] [client 20.104.50.220:31899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/images/gelay.php"] [unique_id "apPkATIT5HeNE73zNfqclAAAAPo"]
[Sun Aug 30 03:04:17.309064 2026] [security2:error] [pid 488281:tid 488424] [client 20.104.18.15:9174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/goods.php"] [unique_id "apPkATIT5HeNE73zNfqcmAAAAJI"]
[Sun Aug 30 03:04:17.325493 2026] [security2:error] [pid 488669:tid 488837] [client 158.23.147.79:62786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-admin/admin.php"] [unique_id "apPkAdRh6OewFvqQpDlGSQAAASg"]
[Sun Aug 30 03:04:17.338742 2026] [security2:error] [pid 488669:tid 488848] [client 68.155.159.216:54762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apPkAdRh6OewFvqQpDlGTwAAATM"]
[Sun Aug 30 03:04:17.356046 2026] [security2:error] [pid 488281:tid 488513] [client 20.104.49.130:64758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trinitytechnologics.com"] [uri "/tool.php"] [unique_id "apPkATIT5HeNE73zNfqctgAAAOs"]
[Sun Aug 30 03:04:17.361174 2026] [security2:error] [pid 488281:tid 488524] [client 20.48.251.3:7048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/aww.php"] [unique_id "apPkATIT5HeNE73zNfqcuAAAAPY"]
[Sun Aug 30 03:04:17.377123 2026] [security2:error] [pid 488281:tid 488416] [client 20.104.18.15:31741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/new.php"] [unique_id "apPkATIT5HeNE73zNfqcxQAAAIo"]
[Sun Aug 30 03:04:17.403194 2026] [security2:error] [pid 488281:tid 488404] [remote 143.95.209.25:36794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.209.95.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "awaifiahstarlcc.com"] [uri "/wp-login.php"] [unique_id "apPkATIT5HeNE73zNfqc0wAA33o"]
[Sun Aug 30 03:04:17.443620 2026] [security2:error] [pid 488281:tid 488441] [client 158.23.147.79:55222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apPkATIT5HeNE73zNfqdAwAAAKM"]
[Sun Aug 30 03:04:17.473601 2026] [security2:error] [pid 488669:tid 488890] [client 20.104.50.220:28717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/d.php"] [unique_id "apPkAdRh6OewFvqQpDlGiwAAAV0"]
[Sun Aug 30 03:04:17.495914 2026] [security2:error] [pid 488281:tid 488419] [client 20.48.251.3:64402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/broadcasting.php"] [unique_id "apPkATIT5HeNE73zNfqdQwAAAI0"]
[Sun Aug 30 03:04:17.564974 2026] [security2:error] [pid 488669:tid 488836] [client 20.104.50.220:59556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/dd.php"] [unique_id "apPkAdRh6OewFvqQpDlGrgAAASc"]
[Sun Aug 30 03:04:17.591026 2026] [authz_core:error] [pid 488281:tid 488478] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:04:17.591442 2026] [authz_core:error] [pid 488281:tid 488478] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:04:17.603192 2026] [authz_core:error] [pid 488669:tid 488925] [client 66.249.66.13:43986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:17.603499 2026] [authz_core:error] [pid 488669:tid 488925] [client 66.249.66.13:43986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:17.654151 2026] [security2:error] [pid 488669:tid 488891] [client 20.48.251.3:65480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/aws_sdk_settings.php"] [unique_id "apPkAdRh6OewFvqQpDlGuwAAAV4"]
[Sun Aug 30 03:04:17.771037 2026] [security2:error] [pid 488281:tid 488494] [client 34.131.221.169:49454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/beta/phpinfo.php"] [unique_id "apPkATIT5HeNE73zNfqdvQAAANg"]
[Sun Aug 30 03:04:17.868027 2026] [security2:error] [pid 488669:tid 488869] [client 20.48.251.3:30010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lastmaskcenter.org"] [uri "/cli_bootstrap.php"] [unique_id "apPkAdRh6OewFvqQpDlG0QAAAUg"]
[Sun Aug 30 03:04:17.888571 2026] [security2:error] [pid 488281:tid 488441] [client 20.151.200.44:58932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/ssss.php"] [unique_id "apPkATIT5HeNE73zNfqd4wAAAKM"]
[Sun Aug 30 03:04:17.888955 2026] [security2:error] [pid 488281:tid 488406] [remote 68.66.226.89:44882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.226.66.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thecasualist.michaelegenolf.com"] [uri "/wp-login.php"] [unique_id "apPkATIT5HeNE73zNfqd4gAA_Xw"]
[Sun Aug 30 03:04:17.901010 2026] [security2:error] [pid 488281:tid 488422] [client 68.155.159.216:60552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/content.php"] [unique_id "apPkATIT5HeNE73zNfqd5gAAAJA"]
[Sun Aug 30 03:04:17.905163 2026] [security2:error] [pid 488281:tid 488474] [client 34.131.221.169:49464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/qa/phpinfo.php"] [unique_id "apPkATIT5HeNE73zNfqd6AAAAMQ"]
[Sun Aug 30 03:04:17.931915 2026] [security2:error] [pid 488281:tid 488519] [client 20.104.50.220:52855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-includes/fw.php"] [unique_id "apPkATIT5HeNE73zNfqd8wAAAPE"]
[Sun Aug 30 03:04:17.991230 2026] [security2:error] [pid 488281:tid 488472] [client 136.92.30.49:44410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/.env.swp"] [unique_id "apPkATIT5HeNE73zNfqeGQAAAMI"]
[Sun Aug 30 03:04:18.021155 2026] [authz_core:error] [pid 488281:tid 488477] [client 216.73.216.128:19696] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:18.021425 2026] [authz_core:error] [pid 488281:tid 488477] [client 216.73.216.128:19696] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:18.042918 2026] [security2:error] [pid 488669:tid 488822] [client 20.48.251.3:51458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/u88.php"] [unique_id "apPkAtRh6OewFvqQpDlG5gAAARk"]
[Sun Aug 30 03:04:18.070410 2026] [security2:error] [pid 488281:tid 488312] [remote 68.66.226.89:44882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.226.66.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thecasualist.michaelegenolf.com"] [uri "/wp-login.php"] [unique_id "apPkAjIT5HeNE73zNfqeMwAAjB4"], referer: https://thecasualist.michaelegenolf.com/wp-login.php
[Sun Aug 30 03:04:18.088683 2026] [authz_core:error] [pid 488281:tid 488515] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:04:18.088957 2026] [authz_core:error] [pid 488281:tid 488515] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:04:18.110153 2026] [security2:error] [pid 488281:tid 488451] [client 20.48.251.3:7381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/aws_config.php"] [unique_id "apPkAjIT5HeNE73zNfqeRQAAAK0"]
[Sun Aug 30 03:04:18.130219 2026] [security2:error] [pid 488669:tid 488859] [client 158.23.147.79:61458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/classwithtostring.php"] [unique_id "apPkAtRh6OewFvqQpDlG-wAAAT4"]
[Sun Aug 30 03:04:18.137390 2026] [security2:error] [pid 488281:tid 488456] [client 136.92.30.49:44410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/.env~"] [unique_id "apPkAjIT5HeNE73zNfqeTgAAALI"]
[Sun Aug 30 03:04:18.144020 2026] [security2:error] [pid 488281:tid 488518] [client 20.104.50.220:30300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/wp-Block.php"] [unique_id "apPkAjIT5HeNE73zNfqeUwAAAPA"]
[Sun Aug 30 03:04:18.177696 2026] [security2:error] [pid 488669:tid 488884] [client 20.48.251.3:59296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/debug.php"] [unique_id "apPkAtRh6OewFvqQpDlHBwAAAVc"]
[Sun Aug 30 03:04:18.188138 2026] [security2:error] [pid 488281:tid 488439] [client 20.48.251.3:23477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/aws_sdk_settings.php"] [unique_id "apPkAjIT5HeNE73zNfqecgAAAKE"]
[Sun Aug 30 03:04:18.202000 2026] [security2:error] [pid 488669:tid 488905] [client 20.151.200.44:47066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/wp-content/admin.php"] [unique_id "apPkAtRh6OewFvqQpDlHEgAAAWw"]
[Sun Aug 30 03:04:18.203104 2026] [security2:error] [pid 488281:tid 488445] [client 20.104.50.220:46869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-content/mailer.php"] [unique_id "apPkAjIT5HeNE73zNfqegAAAAKc"]
[Sun Aug 30 03:04:18.211392 2026] [authz_core:error] [pid 488281:tid 488537] [client 66.249.67.34:48984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:18.211837 2026] [authz_core:error] [pid 488281:tid 488537] [client 66.249.67.34:48984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:18.213236 2026] [security2:error] [pid 488281:tid 488526] [client 20.104.49.130:63044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.topatrust.com"] [uri "/ms-edit.php"] [unique_id "apPkAjIT5HeNE73zNfqehwAAAPg"]
[Sun Aug 30 03:04:18.239036 2026] [security2:error] [pid 488281:tid 488441] [client 20.48.251.3:55437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/xa.php"] [unique_id "apPkAjIT5HeNE73zNfqelQAAAKM"]
[Sun Aug 30 03:04:18.247008 2026] [security2:error] [pid 488669:tid 488818] [client 20.104.50.220:5526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/install.php"] [unique_id "apPkAtRh6OewFvqQpDlHJQAAARU"]
[Sun Aug 30 03:04:18.262154 2026] [security2:error] [pid 488669:tid 488822] [client 20.104.50.220:51642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wso2.5.php"] [unique_id "apPkAtRh6OewFvqQpDlHLAAAARk"]
[Sun Aug 30 03:04:18.274721 2026] [security2:error] [pid 488669:tid 488850] [client 20.104.49.130:45707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.katbacon.com"] [uri "/fs.php"] [unique_id "apPkAtRh6OewFvqQpDlHMAAAATU"]
[Sun Aug 30 03:04:18.365225 2026] [security2:error] [pid 488281:tid 488487] [client 20.104.50.220:33159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-config-pantheon.php"] [unique_id "apPkAjIT5HeNE73zNfqe4wAAANE"]
[Sun Aug 30 03:04:18.383798 2026] [security2:error] [pid 488281:tid 488415] [client 158.23.147.79:55099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/install.php"] [unique_id "apPkAjIT5HeNE73zNfqe8wAAAIk"]
[Sun Aug 30 03:04:18.455951 2026] [security2:error] [pid 488669:tid 488918] [client 20.104.18.15:9183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/ah.php"] [unique_id "apPkAtRh6OewFvqQpDlHcwAAAXk"]
[Sun Aug 30 03:04:18.466108 2026] [security2:error] [pid 488281:tid 488449] [client 20.104.50.220:32563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/images/byps.php"] [unique_id "apPkAjIT5HeNE73zNfqfQgAAAKs"]
[Sun Aug 30 03:04:18.499850 2026] [security2:error] [pid 488281:tid 488474] [client 20.48.251.3:6497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/maxro.php"] [unique_id "apPkAjIT5HeNE73zNfqfYQAAAMQ"]
[Sun Aug 30 03:04:18.516129 2026] [security2:error] [pid 488669:tid 488849] [client 20.104.18.15:31644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/inx.php"] [unique_id "apPkAtRh6OewFvqQpDlHkQAAATQ"]
[Sun Aug 30 03:04:18.547907 2026] [security2:error] [pid 488669:tid 488911] [client 20.104.49.130:43589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.cherylvalk.com"] [uri "/edit.php"] [unique_id "apPkAtRh6OewFvqQpDlHpQAAAXI"]
[Sun Aug 30 03:04:18.557972 2026] [security2:error] [pid 488281:tid 488478] [client 20.48.251.3:44376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkAjIT5HeNE73zNfqfgQAAAMg"]
[Sun Aug 30 03:04:18.565427 2026] [security2:error] [pid 488669:tid 488917] [client 34.131.221.169:49474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/uat/phpinfo.php"] [unique_id "apPkAtRh6OewFvqQpDlHqgAAAXg"]
[Sun Aug 30 03:04:18.572499 2026] [authz_core:error] [pid 488281:tid 488484] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:04:18.572890 2026] [authz_core:error] [pid 488281:tid 488484] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:04:18.578467 2026] [authz_core:error] [pid 488281:tid 488517] [client 216.73.216.128:18977] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:18.578748 2026] [authz_core:error] [pid 488281:tid 488517] [client 216.73.216.128:18977] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:18.609281 2026] [security2:error] [pid 488281:tid 488487] [client 158.23.184.117:23943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/bgymj.php"] [unique_id "apPkAjIT5HeNE73zNfqfkQAAANE"]
[Sun Aug 30 03:04:18.651287 2026] [security2:error] [pid 488281:tid 488420] [client 34.131.221.169:49478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/preview/phpinfo.php"] [unique_id "apPkAjIT5HeNE73zNfqfnwAAAI4"]
[Sun Aug 30 03:04:18.652896 2026] [security2:error] [pid 488281:tid 488490] [client 20.151.200.44:58893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/zoz.php"] [unique_id "apPkAjIT5HeNE73zNfqfogAAANQ"]
[Sun Aug 30 03:04:18.686287 2026] [security2:error] [pid 488669:tid 488830] [client 20.104.50.220:52811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/c.php"] [unique_id "apPkAtRh6OewFvqQpDlHvwAAASE"]
[Sun Aug 30 03:04:18.691822 2026] [security2:error] [pid 488281:tid 488509] [client 20.48.251.3:6494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/dialog.php"] [unique_id "apPkAjIT5HeNE73zNfqftwAAAOc"]
[Sun Aug 30 03:04:18.695840 2026] [security2:error] [pid 488669:tid 488823] [client 20.104.49.130:57527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/xa.php"] [unique_id "apPkAtRh6OewFvqQpDlHwQAAARo"]
[Sun Aug 30 03:04:18.725226 2026] [security2:error] [pid 488281:tid 488425] [client 158.23.147.79:55188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-content/x/index.php"] [unique_id "apPkAjIT5HeNE73zNfqfwQAAAJM"]
[Sun Aug 30 03:04:18.757385 2026] [security2:error] [pid 488281:tid 488511] [client 158.23.184.117:23969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/bk/index.php"] [unique_id "apPkAjIT5HeNE73zNfqf0QAAAOk"]
[Sun Aug 30 03:04:18.798666 2026] [authz_core:error] [pid 488281:tid 488494] [client 66.249.66.74:49323] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:18.798973 2026] [authz_core:error] [pid 488281:tid 488494] [client 66.249.66.74:49323] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:18.899288 2026] [security2:error] [pid 488281:tid 488492] [client 158.23.184.117:23938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/bootstrap.php"] [unique_id "apPkAjIT5HeNE73zNfqf-QAAANY"]
[Sun Aug 30 03:04:18.918327 2026] [authz_core:error] [pid 488669:tid 488869] [client 66.249.66.164:63999] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:18.918772 2026] [authz_core:error] [pid 488669:tid 488869] [client 66.249.66.164:63999] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:19.041558 2026] [security2:error] [pid 488669:tid 488885] [client 158.23.184.117:59269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/bs1.php"] [unique_id "apPkA9Rh6OewFvqQpDlIAQAAAVg"]
[Sun Aug 30 03:04:19.047110 2026] [security2:error] [pid 488281:tid 488414] [client 158.23.147.79:55172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apPkAzIT5HeNE73zNfqgJgAAAIg"]
[Sun Aug 30 03:04:19.057415 2026] [security2:error] [pid 488281:tid 488463] [client 20.104.49.130:48902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wondertanks.com"] [uri "/t.php"] [unique_id "apPkAzIT5HeNE73zNfqgLAAAALk"]
[Sun Aug 30 03:04:19.063259 2026] [security2:error] [pid 488669:tid 488932] [client 68.155.159.216:59380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPkA9Rh6OewFvqQpDlIBAAAAYc"]
[Sun Aug 30 03:04:19.084207 2026] [security2:error] [pid 488281:tid 488501] [client 20.48.251.3:31647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lastmaskcenter.org"] [uri "/dd.php"] [unique_id "apPkAzIT5HeNE73zNfqgMgAAAN8"]
[Sun Aug 30 03:04:19.090982 2026] [authz_core:error] [pid 488281:tid 488416] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:04:19.091337 2026] [authz_core:error] [pid 488281:tid 488416] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:04:19.101652 2026] [security2:error] [pid 488669:tid 488926] [client 20.104.50.220:29574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-includes/wp_wrong_datlib.php"] [unique_id "apPkA9Rh6OewFvqQpDlIDQAAAYE"]
[Sun Aug 30 03:04:19.153781 2026] [security2:error] [pid 488281:tid 488525] [client 20.104.50.220:59583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/lf.php"] [unique_id "apPkAzIT5HeNE73zNfqgWQAAAPc"]
[Sun Aug 30 03:04:19.183953 2026] [security2:error] [pid 488281:tid 488448] [client 158.23.184.117:23945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/bthil.php"] [unique_id "apPkAzIT5HeNE73zNfqgcQAAAKo"]
[Sun Aug 30 03:04:19.254146 2026] [security2:error] [pid 488669:tid 488912] [client 20.151.200.44:58929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/kcs.php"] [unique_id "apPkA9Rh6OewFvqQpDlIOwAAAXM"]
[Sun Aug 30 03:04:19.280573 2026] [security2:error] [pid 488281:tid 488477] [client 20.104.50.220:30322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/yes.php"] [unique_id "apPkAzIT5HeNE73zNfqgpwAAAMc"]
[Sun Aug 30 03:04:19.309697 2026] [security2:error] [pid 488669:tid 488902] [client 158.23.147.79:62799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apPkA9Rh6OewFvqQpDlITgAAAWk"]
[Sun Aug 30 03:04:19.315815 2026] [security2:error] [pid 488281:tid 488525] [client 20.48.251.3:55758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/nzv.php"] [unique_id "apPkAzIT5HeNE73zNfqgvwAAAPc"]
[Sun Aug 30 03:04:19.325356 2026] [security2:error] [pid 488281:tid 488487] [client 20.48.251.3:23451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/setup-config.php"] [unique_id "apPkAzIT5HeNE73zNfqgxAAAANE"]
[Sun Aug 30 03:04:19.336843 2026] [authz_core:error] [pid 488281:tid 488457] [client 66.249.66.77:46908] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:19.337147 2026] [authz_core:error] [pid 488281:tid 488457] [client 66.249.66.77:46908] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:19.340604 2026] [security2:error] [pid 488669:tid 488904] [client 34.131.221.169:49482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/qa/phpinfo.php"] [unique_id "apPkA9Rh6OewFvqQpDlIXAAAAWs"]
[Sun Aug 30 03:04:19.344250 2026] [security2:error] [pid 488281:tid 488514] [client 158.23.184.117:23936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/buy.php"] [unique_id "apPkAzIT5HeNE73zNfqg1AAAAOw"]
[Sun Aug 30 03:04:19.356699 2026] [security2:error] [pid 488281:tid 488456] [client 20.104.50.220:46410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-includes/mailer.php"] [unique_id "apPkAzIT5HeNE73zNfqg2wAAALI"]
[Sun Aug 30 03:04:19.386442 2026] [security2:error] [pid 488281:tid 488502] [client 20.104.50.220:5597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/lv.php"] [unique_id "apPkAzIT5HeNE73zNfqg6QAAAOA"]
[Sun Aug 30 03:04:19.397145 2026] [security2:error] [pid 488281:tid 488412] [client 20.104.49.130:64961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.topatrust.com"] [uri "/tool.php"] [unique_id "apPkAzIT5HeNE73zNfqg9AAAAIY"]
[Sun Aug 30 03:04:19.413026 2026] [security2:error] [pid 488281:tid 488481] [client 20.48.251.3:55511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/ws61.php"] [unique_id "apPkAzIT5HeNE73zNfqhAAAAAMs"]
[Sun Aug 30 03:04:19.413241 2026] [security2:error] [pid 488281:tid 488415] [client 20.104.50.220:63524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-mode.php"] [unique_id "apPkAzIT5HeNE73zNfqhAQAAAIk"]
[Sun Aug 30 03:04:19.415222 2026] [security2:error] [pid 488281:tid 488464] [client 34.131.221.169:49484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/www/phpinfo.php"] [unique_id "apPkAzIT5HeNE73zNfqhAwAAALo"]
[Sun Aug 30 03:04:19.440455 2026] [security2:error] [pid 488669:tid 488898] [client 20.151.200.44:58934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/tajj.php"] [unique_id "apPkA9Rh6OewFvqQpDlIgQAAAWU"]
[Sun Aug 30 03:04:19.484271 2026] [security2:error] [pid 488669:tid 488872] [client 158.23.184.117:23995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/byp.php"] [unique_id "apPkA9Rh6OewFvqQpDlIqAAAAUs"]
[Sun Aug 30 03:04:19.497196 2026] [security2:error] [pid 488669:tid 488866] [client 158.23.147.79:55064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-login.php"] [unique_id "apPkA9Rh6OewFvqQpDlIsgAAAUU"]
[Sun Aug 30 03:04:19.507979 2026] [security2:error] [pid 488281:tid 488442] [client 20.48.251.3:46227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/setup-config.php"] [unique_id "apPkAzIT5HeNE73zNfqhYQAAAKQ"]
[Sun Aug 30 03:04:19.517986 2026] [security2:error] [pid 488281:tid 488477] [client 20.104.50.220:32887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-xmlx.php"] [unique_id "apPkAzIT5HeNE73zNfqhbQAAAMc"]
[Sun Aug 30 03:04:19.593334 2026] [authz_core:error] [pid 488281:tid 488455] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:04:19.593672 2026] [authz_core:error] [pid 488281:tid 488455] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:04:19.604730 2026] [security2:error] [pid 488281:tid 488534] [client 20.104.18.15:9202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/ws55.php"] [unique_id "apPkAzIT5HeNE73zNfqhmAAAAQA"]
[Sun Aug 30 03:04:19.623570 2026] [security2:error] [pid 488281:tid 488461] [client 158.23.184.117:23965] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpanel.thebikezone.ca"] [uri "/c99.php"] [unique_id "apPkAzIT5HeNE73zNfqhoQAAALc"]
[Sun Aug 30 03:04:19.630266 2026] [security2:error] [pid 488669:tid 488813] [client 158.23.147.79:61468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apPkA9Rh6OewFvqQpDlI1AAAARA"]
[Sun Aug 30 03:04:19.639417 2026] [core:error] [pid 488669:tid 488875] [client 158.23.184.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:04:19.639433 2026] [core:error] [pid 488669:tid 488875] [client 158.23.184.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:04:19.644704 2026] [security2:error] [pid 488669:tid 488814] [client 20.104.50.220:31854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/images/bypass.php"] [unique_id "apPkA9Rh6OewFvqQpDlI1gAAARE"]
[Sun Aug 30 03:04:19.652202 2026] [security2:error] [pid 488281:tid 488501] [client 20.48.251.3:64511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/brc.php"] [unique_id "apPkAzIT5HeNE73zNfqhqAAAAN8"]
[Sun Aug 30 03:04:19.663832 2026] [authz_core:error] [pid 488281:tid 488425] [client 66.249.66.98:47212] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:19.664183 2026] [authz_core:error] [pid 488281:tid 488425] [client 66.249.66.98:47212] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:19.698762 2026] [security2:error] [pid 488281:tid 488428] [client 20.48.251.3:44297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkAzIT5HeNE73zNfqhvwAAAJY"]
[Sun Aug 30 03:04:19.712895 2026] [security2:error] [pid 488281:tid 488487] [client 20.104.18.15:31562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/vpn.php"] [unique_id "apPkAzIT5HeNE73zNfqhwgAAANE"]
[Sun Aug 30 03:04:19.755746 2026] [security2:error] [pid 488281:tid 488421] [client 158.23.147.79:55194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-admin/images/about.php"] [unique_id "apPkAzIT5HeNE73zNfqh2AAAAI8"]
[Sun Aug 30 03:04:19.762495 2026] [security2:error] [pid 488281:tid 488527] [client 158.23.184.117:23949] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpanel.thebikezone.ca"] [uri "/c99.php"] [unique_id "apPkAzIT5HeNE73zNfqh2gAAAPk"]
[Sun Aug 30 03:04:19.768105 2026] [security2:error] [pid 488281:tid 488470] [client 20.48.251.3:64496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/phpinfo01.php"] [unique_id "apPkAzIT5HeNE73zNfqh3gAAAMA"]
[Sun Aug 30 03:04:19.820547 2026] [authz_core:error] [pid 488281:tid 488478] [client 74.7.243.204:33990] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fsys%2Fdevices%2Fpnp0%2F00%3A03%2Fcmos_nvram0%2Fpower
[Sun Aug 30 03:04:19.820990 2026] [authz_core:error] [pid 488281:tid 488478] [client 74.7.243.204:33990] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fsys%2Fdevices%2Fpnp0%2F00%3A03%2Fcmos_nvram0%2Fpower
[Sun Aug 30 03:04:19.848463 2026] [security2:error] [pid 488669:tid 488821] [client 20.48.251.3:6525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/cxc.php"] [unique_id "apPkA9Rh6OewFvqQpDlI6QAAARg"]
[Sun Aug 30 03:04:19.894951 2026] [security2:error] [pid 488281:tid 488515] [client 20.104.49.130:57473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/m.php"] [unique_id "apPkAzIT5HeNE73zNfqiBgAAAO0"]
[Sun Aug 30 03:04:19.905386 2026] [security2:error] [pid 488669:tid 488808] [client 158.23.184.117:59265] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpanel.thebikezone.ca"] [uri "/c99.php"] [unique_id "apPkA9Rh6OewFvqQpDlI7gAAAQs"]
[Sun Aug 30 03:04:19.930741 2026] [security2:error] [pid 488669:tid 488889] [client 20.151.200.44:58901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/bge.php"] [unique_id "apPkA9Rh6OewFvqQpDlI8QAAAVw"]
[Sun Aug 30 03:04:19.983591 2026] [security2:error] [pid 488669:tid 488870] [client 20.104.50.220:52840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/b.php"] [unique_id "apPkA9Rh6OewFvqQpDlI-QAAAUk"]
[Sun Aug 30 03:04:20.046122 2026] [security2:error] [pid 488281:tid 488521] [client 158.23.184.117:23958] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpanel.thebikezone.ca"] [uri "/c99.php"] [unique_id "apPkBDIT5HeNE73zNfqiQwAAAPM"]
[Sun Aug 30 03:04:20.059762 2026] [security2:error] [pid 488281:tid 488414] [client 158.23.147.79:61446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPkBDIT5HeNE73zNfqiSQAAAIg"]
[Sun Aug 30 03:04:20.091022 2026] [security2:error] [pid 488281:tid 488463] [client 34.131.221.169:49490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/preview/phpinfo.php"] [unique_id "apPkBDIT5HeNE73zNfqiTwAAALk"]
[Sun Aug 30 03:04:20.113536 2026] [authz_core:error] [pid 488281:tid 488501] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fvar%2Flib%2Fcloud
[Sun Aug 30 03:04:20.113858 2026] [authz_core:error] [pid 488281:tid 488501] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fvar%2Flib%2Fcloud
[Sun Aug 30 03:04:20.132468 2026] [security2:error] [pid 488281:tid 488528] [client 34.131.221.169:49494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/htdocs/phpinfo.php"] [unique_id "apPkBDIT5HeNE73zNfqiYQAAAPo"]
[Sun Aug 30 03:04:20.170399 2026] [authz_core:error] [pid 488281:tid 488503] [client 66.249.67.36:40972] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:20.170776 2026] [authz_core:error] [pid 488281:tid 488503] [client 66.249.67.36:40972] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:20.172713 2026] [security2:error] [pid 488281:tid 488489] [client 20.48.251.3:34609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/config/laravolt/css/index.php"] [unique_id "apPkBDIT5HeNE73zNfqifwAAANM"]
[Sun Aug 30 03:04:20.233380 2026] [security2:error] [pid 488281:tid 488411] [client 68.155.159.216:60572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/goat.php"] [unique_id "apPkBDIT5HeNE73zNfqiowAAAIU"]
[Sun Aug 30 03:04:20.268441 2026] [security2:error] [pid 488281:tid 488519] [client 20.48.251.3:31634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lastmaskcenter.org"] [uri "/wp-tem.php"] [unique_id "apPkBDIT5HeNE73zNfqitgAAAPE"]
[Sun Aug 30 03:04:20.294018 2026] [authz_core:error] [pid 488281:tid 488414] [client 74.7.243.204:33990] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2F%2Flib64
[Sun Aug 30 03:04:20.294498 2026] [authz_core:error] [pid 488281:tid 488414] [client 74.7.243.204:33990] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2F%2Flib64
[Sun Aug 30 03:04:20.318512 2026] [security2:error] [pid 488669:tid 488912] [client 20.104.50.220:61495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/saya.php"] [unique_id "apPkBNRh6OewFvqQpDlJUQAAAXM"]
[Sun Aug 30 03:04:20.328667 2026] [security2:error] [pid 488281:tid 488528] [client 158.23.184.117:23991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/cache/cache/min.php"] [unique_id "apPkBDIT5HeNE73zNfqi2QAAAPo"]
[Sun Aug 30 03:04:20.339622 2026] [security2:error] [pid 488281:tid 488411] [client 20.104.50.220:62788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-admin/wp_wrong_datlib.php"] [unique_id "apPkBDIT5HeNE73zNfqi4gAAAIU"]
[Sun Aug 30 03:04:20.344020 2026] [security2:error] [pid 488281:tid 488466] [client 20.104.49.130:52479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/css.php"] [unique_id "apPkBDIT5HeNE73zNfqi5AAAALw"]
[Sun Aug 30 03:04:20.413803 2026] [security2:error] [pid 488281:tid 488498] [client 20.104.50.220:29696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/2008.php"] [unique_id "apPkBDIT5HeNE73zNfqjHwAAANw"]
[Sun Aug 30 03:04:20.427875 2026] [security2:error] [pid 488281:tid 488511] [client 20.104.49.130:51575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trinitytechnologics.com"] [uri "/abc.php"] [unique_id "apPkBDIT5HeNE73zNfqjMAAAAOk"]
[Sun Aug 30 03:04:20.466577 2026] [security2:error] [pid 488281:tid 488469] [client 20.48.251.3:59313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/66.php"] [unique_id "apPkBDIT5HeNE73zNfqjaAAAAL8"]
[Sun Aug 30 03:04:20.470729 2026] [security2:error] [pid 488281:tid 488455] [client 158.23.184.117:23989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/catalogbypass.php"] [unique_id "apPkBDIT5HeNE73zNfqjbwAAALE"]
[Sun Aug 30 03:04:20.532072 2026] [security2:error] [pid 488281:tid 488445] [client 20.48.251.3:23342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/wp-admin/sc.php"] [unique_id "apPkBDIT5HeNE73zNfqjmwAAAKc"]
[Sun Aug 30 03:04:20.538661 2026] [security2:error] [pid 488281:tid 488534] [client 20.104.50.220:5529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/simple.php"] [unique_id "apPkBDIT5HeNE73zNfqjngAAAQA"]
[Sun Aug 30 03:04:20.541246 2026] [security2:error] [pid 488281:tid 488478] [client 20.48.251.3:55465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/xza.php"] [unique_id "apPkBDIT5HeNE73zNfqjogAAAMg"]
[Sun Aug 30 03:04:20.565437 2026] [security2:error] [pid 488281:tid 488434] [client 34.16.144.252:7854] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpcontacts.alchemancer.com"] [uri "/terraform.tfstate"] [unique_id "apPkBDIT5HeNE73zNfqjswAAAJw"]
[Sun Aug 30 03:04:20.571446 2026] [security2:error] [pid 488669:tid 488861] [client 20.104.50.220:51593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-mailcek.php"] [unique_id "apPkBNRh6OewFvqQpDlJrgAAAUA"]
[Sun Aug 30 03:04:20.575554 2026] [security2:error] [pid 488281:tid 488529] [client 34.16.144.252:7882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/var/www/.env"] [unique_id "apPkBDIT5HeNE73zNfqjtgAAAPs"]
[Sun Aug 30 03:04:20.587171 2026] [authz_core:error] [pid 488281:tid 488440] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fopt%2FPUC%2Ft
[Sun Aug 30 03:04:20.587449 2026] [authz_core:error] [pid 488281:tid 488440] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fopt%2FPUC%2Ft
[Sun Aug 30 03:04:20.587877 2026] [security2:error] [pid 488281:tid 488438] [client 34.16.144.252:7882] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.alchemancer.com"] [uri "/config/sendgrid.env"] [unique_id "apPkBDIT5HeNE73zNfqjvgAAAKA"]
[Sun Aug 30 03:04:20.588796 2026] [security2:error] [pid 488281:tid 488460] [client 34.16.144.252:7906] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/sendgrid/.env"] [unique_id "apPkBDIT5HeNE73zNfqjvQAAALY"]
[Sun Aug 30 03:04:20.589487 2026] [security2:error] [pid 488669:tid 488809] [client 34.16.144.252:7910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/mail/.env"] [unique_id "apPkBNRh6OewFvqQpDlJuAAAAQw"]
[Sun Aug 30 03:04:20.590926 2026] [security2:error] [pid 488281:tid 488491] [client 34.16.144.252:7866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/var/www/html/.env"] [unique_id "apPkBDIT5HeNE73zNfqjvwAAANU"]
[Sun Aug 30 03:04:20.596186 2026] [security2:error] [pid 488281:tid 488528] [client 20.104.50.220:46168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/ym.php"] [unique_id "apPkBDIT5HeNE73zNfqjwAAAAPo"]
[Sun Aug 30 03:04:20.598200 2026] [security2:error] [pid 488669:tid 488855] [client 34.16.144.252:7844] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/terraform.tfvars"] [unique_id "apPkBNRh6OewFvqQpDlJrQAAATo"]
[Sun Aug 30 03:04:20.603181 2026] [security2:error] [pid 488669:tid 488884] [client 34.16.144.252:7830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/email/.env"] [unique_id "apPkBNRh6OewFvqQpDlJuwAAAVc"]
[Sun Aug 30 03:04:20.612236 2026] [security2:error] [pid 488281:tid 488444] [client 158.23.184.117:23998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/cc.php"] [unique_id "apPkBDIT5HeNE73zNfqjzQAAAKY"]
[Sun Aug 30 03:04:20.622942 2026] [security2:error] [pid 488281:tid 488478] [client 158.23.147.79:55198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-admin.php"] [unique_id "apPkBDIT5HeNE73zNfqj1QAAAMg"]
[Sun Aug 30 03:04:20.626250 2026] [security2:error] [pid 488669:tid 488867] [client 34.16.144.252:7830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/stripe/.env"] [unique_id "apPkBNRh6OewFvqQpDlJvgAAAUY"]
[Sun Aug 30 03:04:20.671561 2026] [authz_core:error] [pid 488281:tid 488536] [client 216.73.216.128:49784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:20.671864 2026] [authz_core:error] [pid 488281:tid 488536] [client 216.73.216.128:49784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:20.712662 2026] [security2:error] [pid 488669:tid 488834] [client 20.104.49.130:63089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.topatrust.com"] [uri "/abc.php"] [unique_id "apPkBNRh6OewFvqQpDlJyAAAASU"]
[Sun Aug 30 03:04:20.752727 2026] [security2:error] [pid 488281:tid 488479] [client 158.23.184.117:24194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/cgi-bin/admin.php"] [unique_id "apPkBDIT5HeNE73zNfqkAAAAAMk"]
[Sun Aug 30 03:04:20.768415 2026] [authz_core:error] [pid 488281:tid 488472] [client 74.7.243.204:33990] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2F%2Flib64
[Sun Aug 30 03:04:20.768857 2026] [authz_core:error] [pid 488281:tid 488472] [client 74.7.243.204:33990] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2F%2Flib64
[Sun Aug 30 03:04:20.786749 2026] [security2:error] [pid 488281:tid 488493] [client 20.48.251.3:7378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/vx.php"] [unique_id "apPkBDIT5HeNE73zNfqkEgAAANc"]
[Sun Aug 30 03:04:20.787624 2026] [security2:error] [pid 488281:tid 488529] [client 20.104.18.15:9100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/drykl.php"] [unique_id "apPkBDIT5HeNE73zNfqkFAAAAPs"]
[Sun Aug 30 03:04:20.790524 2026] [security2:error] [pid 488281:tid 488508] [client 20.48.251.3:54817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/wp-admin/sc.php"] [unique_id "apPkBDIT5HeNE73zNfqkFgAAAOY"]
[Sun Aug 30 03:04:20.806051 2026] [security2:error] [pid 488669:tid 488828] [client 20.104.50.220:32066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/images/x.php"] [unique_id "apPkBNRh6OewFvqQpDlJ2QAAAR8"]
[Sun Aug 30 03:04:20.832303 2026] [security2:error] [pid 488281:tid 488420] [client 34.131.221.169:49496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/www/phpinfo.php"] [unique_id "apPkBDIT5HeNE73zNfqkIwAAAI4"]
[Sun Aug 30 03:04:20.861040 2026] [authz_core:error] [pid 488281:tid 488486] [client 216.73.216.128:18977] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:20.861442 2026] [authz_core:error] [pid 488281:tid 488486] [client 216.73.216.128:18977] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:20.862815 2026] [security2:error] [pid 488281:tid 488443] [client 20.151.200.44:58925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/ssh3ll.php"] [unique_id "apPkBDIT5HeNE73zNfqkLwAAAKU"]
[Sun Aug 30 03:04:20.864766 2026] [security2:error] [pid 488281:tid 488514] [client 34.131.221.169:49500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/public_html/phpinfo.php"] [unique_id "apPkBDIT5HeNE73zNfqkMAAAAOw"]
[Sun Aug 30 03:04:20.906631 2026] [security2:error] [pid 488281:tid 488414] [client 20.104.49.130:52341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.katbacon.com"] [uri "/kgoc6awap3napxxxdCdefault.php"] [unique_id "apPkBDIT5HeNE73zNfqkPwAAAIg"]
[Sun Aug 30 03:04:20.916988 2026] [security2:error] [pid 488281:tid 488419] [client 20.104.18.15:31678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/shiny.php"] [unique_id "apPkBDIT5HeNE73zNfqkQgAAAI0"]
[Sun Aug 30 03:04:20.950936 2026] [security2:error] [pid 488669:tid 488910] [client 158.23.184.117:59289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/config.php"] [unique_id "apPkBNRh6OewFvqQpDlJ5AAAAXE"]
[Sun Aug 30 03:04:20.973742 2026] [security2:error] [pid 488281:tid 488443] [client 20.48.251.3:44321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/cloud.php"] [unique_id "apPkBDIT5HeNE73zNfqkYwAAAKU"]
[Sun Aug 30 03:04:21.001100 2026] [security2:error] [pid 488281:tid 488446] [client 158.23.147.79:62838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apPkBTIT5HeNE73zNfqkbwAAAKg"]
[Sun Aug 30 03:04:21.070478 2026] [authz_core:error] [pid 488281:tid 488417] [client 66.249.66.71:58027] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:21.072268 2026] [authz_core:error] [pid 488281:tid 488417] [client 66.249.66.71:58027] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:21.091611 2026] [security2:error] [pid 488669:tid 488843] [client 158.23.184.117:23983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/login.php"] [unique_id "apPkBdRh6OewFvqQpDlKAQAAAS4"]
[Sun Aug 30 03:04:21.093458 2026] [security2:error] [pid 488669:tid 488759] [remote 156.59.198.135:41338] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "direcorgigames.com"] [uri "/wp-content/uploads/2019/08/Character-Planner-Fillable.pdf"] [unique_id "apPkBdRh6OewFvqQpDlKAwABalE"]
[Sun Aug 30 03:04:21.144053 2026] [authz_core:error] [pid 488281:tid 488470] [client 66.249.66.69:59599] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:21.144485 2026] [authz_core:error] [pid 488281:tid 488470] [client 66.249.66.69:59599] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:21.164580 2026] [authz_core:error] [pid 488281:tid 488419] [client 66.249.66.34:59085] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:21.164930 2026] [authz_core:error] [pid 488281:tid 488419] [client 66.249.66.34:59085] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:21.204449 2026] [security2:error] [pid 488281:tid 488530] [client 20.104.50.220:62799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/indexc.php"] [unique_id "apPkBTIT5HeNE73zNfqk2gAAAPw"]
[Sun Aug 30 03:04:21.224986 2026] [authz_core:error] [pid 488281:tid 488493] [client 216.73.216.128:49784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:21.225359 2026] [authz_core:error] [pid 488281:tid 488493] [client 216.73.216.128:49784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:21.230246 2026] [security2:error] [pid 488281:tid 488466] [client 158.23.184.117:59270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/index.php"] [unique_id "apPkBTIT5HeNE73zNfqk7QAAALw"]
[Sun Aug 30 03:04:21.236840 2026] [security2:error] [pid 488281:tid 488444] [client 20.63.81.20:59015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkBTIT5HeNE73zNfqk8gAAAKY"]
[Sun Aug 30 03:04:21.300610 2026] [authz_core:error] [pid 488281:tid 488438] [client 74.7.243.204:33990] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2F%2Flib64
[Sun Aug 30 03:04:21.301073 2026] [authz_core:error] [pid 488281:tid 488438] [client 74.7.243.204:33990] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2F%2Flib64
[Sun Aug 30 03:04:21.319701 2026] [authz_core:error] [pid 488281:tid 488514] [client 216.73.216.128:51358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:21.320166 2026] [authz_core:error] [pid 488281:tid 488514] [client 216.73.216.128:51358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:21.320472 2026] [authz_core:error] [pid 488281:tid 488412] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Frun%2Fudev%2Flinks
[Sun Aug 30 03:04:21.320973 2026] [authz_core:error] [pid 488281:tid 488412] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Frun%2Fudev%2Flinks
[Sun Aug 30 03:04:21.340345 2026] [security2:error] [pid 488669:tid 488869] [client 20.104.49.130:47987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/33.php"] [unique_id "apPkBdRh6OewFvqQpDlKSAAAAUg"]
[Sun Aug 30 03:04:21.343156 2026] [security2:error] [pid 488281:tid 488518] [client 68.155.159.216:59378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apPkBTIT5HeNE73zNfqlOgAAAPA"]
[Sun Aug 30 03:04:21.372003 2026] [security2:error] [pid 488669:tid 488867] [client 158.23.184.117:59277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/min.php"] [unique_id "apPkBdRh6OewFvqQpDlKSgAAAUY"]
[Sun Aug 30 03:04:21.403126 2026] [security2:error] [pid 488281:tid 488466] [client 20.63.81.20:59024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkBTIT5HeNE73zNfqlYAAAALw"]
[Sun Aug 30 03:04:21.412211 2026] [security2:error] [pid 488281:tid 488503] [client 20.48.251.3:51559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/87.php"] [unique_id "apPkBTIT5HeNE73zNfqlZgAAAOE"]
[Sun Aug 30 03:04:21.437595 2026] [security2:error] [pid 488281:tid 488460] [client 20.48.251.3:29974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lastmaskcenter.org"] [uri "/txets.php"] [unique_id "apPkBTIT5HeNE73zNfqlgQAAALY"]
[Sun Aug 30 03:04:21.479729 2026] [security2:error] [pid 488281:tid 488415] [client 68.155.159.216:59913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkBTIT5HeNE73zNfqlpwAAAIk"]
[Sun Aug 30 03:04:21.488503 2026] [security2:error] [pid 488281:tid 488525] [client 20.104.50.220:61472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/do.php"] [unique_id "apPkBTIT5HeNE73zNfqlsgAAAPc"]
[Sun Aug 30 03:04:21.490501 2026] [security2:error] [pid 488281:tid 488522] [client 20.104.50.220:29178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-content/wp_wrong_datlib.php"] [unique_id "apPkBTIT5HeNE73zNfqlswAAAPQ"]
[Sun Aug 30 03:04:21.517217 2026] [security2:error] [pid 488281:tid 488498] [client 158.23.184.117:59282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/options.php"] [unique_id "apPkBTIT5HeNE73zNfqlxgAAANw"]
[Sun Aug 30 03:04:21.535587 2026] [security2:error] [pid 488281:tid 488481] [client 20.63.81.20:59123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/ser.php"] [unique_id "apPkBTIT5HeNE73zNfql0wAAAMs"]
[Sun Aug 30 03:04:21.553817 2026] [security2:error] [pid 488281:tid 488507] [client 20.104.50.220:30291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/wp-cli.php"] [unique_id "apPkBTIT5HeNE73zNfql5QAAAOU"]
[Sun Aug 30 03:04:21.572705 2026] [authz_core:error] [pid 488281:tid 488530] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule
[Sun Aug 30 03:04:21.572990 2026] [security2:error] [pid 488281:tid 488428] [client 34.131.221.169:49508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/htdocs/phpinfo.php"] [unique_id "apPkBTIT5HeNE73zNfql9QAAAJY"]
[Sun Aug 30 03:04:21.573001 2026] [authz_core:error] [pid 488281:tid 488530] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule
[Sun Aug 30 03:04:21.589692 2026] [authz_core:error] [pid 488669:tid 488844] [client 66.249.67.40:61307] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:21.590130 2026] [authz_core:error] [pid 488669:tid 488844] [client 66.249.67.40:61307] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:21.594614 2026] [security2:error] [pid 488281:tid 488528] [client 34.131.221.169:49512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/site/phpinfo.php"] [unique_id "apPkBTIT5HeNE73zNfql-gAAAPo"]
[Sun Aug 30 03:04:21.599306 2026] [authz_core:error] [pid 488281:tid 488518] [client 66.249.66.34:57468] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:21.599610 2026] [authz_core:error] [pid 488281:tid 488518] [client 66.249.66.34:57468] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:21.609562 2026] [security2:error] [pid 488281:tid 488515] [client 20.48.251.3:55786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/admin.php"] [unique_id "apPkBTIT5HeNE73zNfqmAwAAAO0"]
[Sun Aug 30 03:04:21.628400 2026] [security2:error] [pid 488281:tid 488319] [remote 143.95.209.25:36794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.209.95.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "awaifiahstarlcc.com"] [uri "/wp-login.php"] [unique_id "apPkBTIT5HeNE73zNfqmCgAAwSU"], referer: https://awaifiahstarlcc.com/wp-login.php
[Sun Aug 30 03:04:21.657419 2026] [security2:error] [pid 488669:tid 488872] [client 158.23.184.117:23948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/pk.php"] [unique_id "apPkBdRh6OewFvqQpDlKzgAAAUs"]
[Sun Aug 30 03:04:21.667427 2026] [security2:error] [pid 488281:tid 488463] [client 20.63.81.20:59027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/431.php"] [unique_id "apPkBTIT5HeNE73zNfqmGQAAALk"]
[Sun Aug 30 03:04:21.676889 2026] [security2:error] [pid 488281:tid 488460] [client 20.104.50.220:5908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/css.php"] [unique_id "apPkBTIT5HeNE73zNfqmIgAAALY"]
[Sun Aug 30 03:04:21.677706 2026] [security2:error] [pid 488281:tid 488501] [client 20.151.200.44:58780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/motu.php"] [unique_id "apPkBTIT5HeNE73zNfqmIwAAAN8"]
[Sun Aug 30 03:04:21.680049 2026] [security2:error] [pid 488281:tid 488486] [client 20.48.251.3:44275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/debug.php"] [unique_id "apPkBTIT5HeNE73zNfqmJAAAANA"]
[Sun Aug 30 03:04:21.690416 2026] [security2:error] [pid 488281:tid 488466] [client 20.48.251.3:55546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/ms-edit.php"] [unique_id "apPkBTIT5HeNE73zNfqmKQAAALw"]
[Sun Aug 30 03:04:21.720314 2026] [security2:error] [pid 488669:tid 488859] [client 158.23.147.79:55042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/lock.php"] [unique_id "apPkBdRh6OewFvqQpDlK0wAAAT4"]
[Sun Aug 30 03:04:21.729583 2026] [security2:error] [pid 488669:tid 488883] [client 20.104.50.220:63519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-config-blog.php"] [unique_id "apPkBdRh6OewFvqQpDlK1wAAAVY"]
[Sun Aug 30 03:04:21.753523 2026] [authz_core:error] [pid 488281:tid 488454] [client 66.249.66.69:53184] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:21.753812 2026] [authz_core:error] [pid 488281:tid 488454] [client 66.249.66.69:53184] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:21.759723 2026] [security2:error] [pid 488669:tid 488835] [client 136.92.30.49:44498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/app/.env"] [unique_id "apPkBdRh6OewFvqQpDlK2gAAASY"]
[Sun Aug 30 03:04:21.785857 2026] [authz_core:error] [pid 488281:tid 488471] [client 216.73.216.128:18977] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:21.786138 2026] [authz_core:error] [pid 488281:tid 488471] [client 216.73.216.128:18977] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:21.793782 2026] [security2:error] [pid 488281:tid 488478] [client 20.63.81.20:59079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/rxr.php"] [unique_id "apPkBTIT5HeNE73zNfqmSQAAAMg"]
[Sun Aug 30 03:04:21.797992 2026] [security2:error] [pid 488669:tid 488900] [client 158.23.184.117:23959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/cgi-bin/cgi-bin/cgi-bin/index.php"] [unique_id "apPkBdRh6OewFvqQpDlK5AAAAWc"]
[Sun Aug 30 03:04:21.804991 2026] [security2:error] [pid 488281:tid 488444] [client 20.104.50.220:46612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/alfa1.php"] [unique_id "apPkBTIT5HeNE73zNfqmTQAAAKY"]
[Sun Aug 30 03:04:21.829062 2026] [security2:error] [pid 488669:tid 488813] [client 20.104.49.130:35650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trinitytechnologics.com"] [uri "/ioxi-o.php"] [unique_id "apPkBdRh6OewFvqQpDlK6gAAARA"]
[Sun Aug 30 03:04:21.904262 2026] [security2:error] [pid 488669:tid 488903] [client 136.92.30.49:44498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/apps/.env"] [unique_id "apPkBdRh6OewFvqQpDlK8QAAAWo"]
[Sun Aug 30 03:04:21.919103 2026] [authz_core:error] [pid 488281:tid 488452] [client 66.249.66.196:39243] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:21.919445 2026] [authz_core:error] [pid 488281:tid 488452] [client 66.249.66.196:39243] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:21.920300 2026] [security2:error] [pid 488669:tid 488843] [client 20.63.81.20:59122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/csst.php"] [unique_id "apPkBdRh6OewFvqQpDlK9QAAAS4"]
[Sun Aug 30 03:04:21.922526 2026] [security2:error] [pid 488281:tid 488416] [client 20.48.251.3:64454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/ty.php"] [unique_id "apPkBTIT5HeNE73zNfqmcAAAAIo"]
[Sun Aug 30 03:04:21.939736 2026] [security2:error] [pid 488281:tid 488430] [client 158.23.184.117:59324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/cgi-bin/index.php"] [unique_id "apPkBTIT5HeNE73zNfqmcgAAAJg"]
[Sun Aug 30 03:04:21.941852 2026] [security2:error] [pid 488669:tid 488870] [client 20.104.18.15:9097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/backup.php"] [unique_id "apPkBdRh6OewFvqQpDlK-gAAAUk"]
[Sun Aug 30 03:04:21.982226 2026] [security2:error] [pid 488281:tid 488420] [client 20.104.50.220:32083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/images/leaf.php"] [unique_id "apPkBTIT5HeNE73zNfqmkAAAAI4"]
[Sun Aug 30 03:04:21.987872 2026] [security2:error] [pid 488281:tid 488521] [client 158.23.147.79:55196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/index/function.php"] [unique_id "apPkBTIT5HeNE73zNfqmkwAAAPM"]
[Sun Aug 30 03:04:22.014821 2026] [security2:error] [pid 488669:tid 488832] [client 20.48.251.3:54829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/debug.php"] [unique_id "apPkBtRh6OewFvqQpDlLDgAAASM"]
[Sun Aug 30 03:04:22.032581 2026] [security2:error] [pid 488281:tid 488504] [client 20.104.50.220:32848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/pwp-.myluv.php"] [unique_id "apPkBjIT5HeNE73zNfqmogAAAOI"]
[Sun Aug 30 03:04:22.047303 2026] [security2:error] [pid 488669:tid 488859] [client 136.92.30.49:44498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/api/.env"] [unique_id "apPkBtRh6OewFvqQpDlLEQAAAT4"]
[Sun Aug 30 03:04:22.049898 2026] [security2:error] [pid 488281:tid 488441] [client 20.63.81.20:59014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp-includes/blocks/query-title/footer.php"] [unique_id "apPkBjIT5HeNE73zNfqmqwAAAKM"]
[Sun Aug 30 03:04:22.077072 2026] [security2:error] [pid 488281:tid 488499] [client 74.7.244.59:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "easegout.com"] [uri "/index.php"] [unique_id "apPkADIT5HeNE73zNfqbqgAA3XI"]
[Sun Aug 30 03:04:22.078655 2026] [security2:error] [pid 488669:tid 488861] [client 20.104.18.15:31696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/goods.php"] [unique_id "apPkBtRh6OewFvqQpDlLFwAAAUA"]
[Sun Aug 30 03:04:22.080789 2026] [security2:error] [pid 488281:tid 488514] [client 158.23.184.117:59273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/cgi-bin/load.php"] [unique_id "apPkBjIT5HeNE73zNfqmtgAAAOw"]
[Sun Aug 30 03:04:22.111180 2026] [security2:error] [pid 488669:tid 488821] [client 20.48.251.3:44355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/kerang.php"] [unique_id "apPkBtRh6OewFvqQpDlLIAAAARg"]
[Sun Aug 30 03:04:22.131311 2026] [authz_core:error] [pid 488281:tid 488528] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Frpm
[Sun Aug 30 03:04:22.131727 2026] [authz_core:error] [pid 488281:tid 488528] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Frpm
[Sun Aug 30 03:04:22.180744 2026] [security2:error] [pid 488281:tid 488505] [client 20.63.81.20:59085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp-content/uploads/indoex.php"] [unique_id "apPkBjIT5HeNE73zNfqm7QAAAOM"]
[Sun Aug 30 03:04:22.190124 2026] [security2:error] [pid 488669:tid 488893] [client 136.92.30.49:44498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/web/.env"] [unique_id "apPkBtRh6OewFvqQpDlLOQAAAWA"]
[Sun Aug 30 03:04:22.221085 2026] [security2:error] [pid 488669:tid 488847] [client 158.23.184.117:23966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/cgi-bin/ms-files.php"] [unique_id "apPkBtRh6OewFvqQpDlLQwAAATI"]
[Sun Aug 30 03:04:22.223383 2026] [security2:error] [pid 488281:tid 488489] [client 158.23.147.79:62829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/.well-known/content.php"] [unique_id "apPkBjIT5HeNE73zNfqnCwAAANM"]
[Sun Aug 30 03:04:22.294887 2026] [security2:error] [pid 488281:tid 488451] [client 34.131.221.169:49526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/public_html/phpinfo.php"] [unique_id "apPkBjIT5HeNE73zNfqnLQAAAK0"]
[Sun Aug 30 03:04:22.307725 2026] [security2:error] [pid 488281:tid 488496] [client 20.63.81.20:59077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPkBjIT5HeNE73zNfqnQAAAANo"]
[Sun Aug 30 03:04:22.321461 2026] [security2:error] [pid 488669:tid 488854] [client 34.131.221.169:49528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/docs/phpinfo.php"] [unique_id "apPkBtRh6OewFvqQpDlLaAAAATk"]
[Sun Aug 30 03:04:22.340974 2026] [security2:error] [pid 488669:tid 488877] [client 136.92.30.49:44498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/site/.env"] [unique_id "apPkBtRh6OewFvqQpDlLcgAAAVA"]
[Sun Aug 30 03:04:22.362927 2026] [security2:error] [pid 488669:tid 488828] [client 158.23.184.117:23952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/cgi-bin/wp-activate.php"] [unique_id "apPkBtRh6OewFvqQpDlLdQAAAR8"]
[Sun Aug 30 03:04:22.440222 2026] [security2:error] [pid 488281:tid 488484] [client 20.63.81.20:59028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/haxor.php"] [unique_id "apPkBjIT5HeNE73zNfqnrAAAAM4"]
[Sun Aug 30 03:04:22.444204 2026] [authz_core:error] [pid 488281:tid 488499] [client 66.249.66.161:51168] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:22.444633 2026] [authz_core:error] [pid 488281:tid 488499] [client 66.249.66.161:51168] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:22.449406 2026] [security2:error] [pid 488281:tid 488446] [client 20.104.50.220:29124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/147w3sdtB9D.php"] [unique_id "apPkBjIT5HeNE73zNfqnvwAAAKg"]
[Sun Aug 30 03:04:22.462860 2026] [security2:error] [pid 488281:tid 488517] [client 158.23.147.79:55227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/cong.php"] [unique_id "apPkBjIT5HeNE73zNfqn0QAAAO8"]
[Sun Aug 30 03:04:22.483804 2026] [security2:error] [pid 488669:tid 488888] [client 136.92.30.49:44498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/public/.env"] [unique_id "apPkBtRh6OewFvqQpDlLqwAAAVs"]
[Sun Aug 30 03:04:22.502064 2026] [security2:error] [pid 488281:tid 488412] [client 158.23.184.117:23941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/cgi-bin/wp-load.php"] [unique_id "apPkBjIT5HeNE73zNfqn-wAAAIY"]
[Sun Aug 30 03:04:22.509786 2026] [security2:error] [pid 488281:tid 488494] [client 68.155.159.216:59368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-content/uploads/about.php"] [unique_id "apPkBjIT5HeNE73zNfqoAQAAANg"]
[Sun Aug 30 03:04:22.549878 2026] [security2:error] [pid 488281:tid 488508] [client 20.48.251.3:58847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/plss3.php"] [unique_id "apPkBjIT5HeNE73zNfqoHgAAAOY"]
[Sun Aug 30 03:04:22.571229 2026] [security2:error] [pid 488281:tid 488534] [client 20.63.81.20:59109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/google.php"] [unique_id "apPkBjIT5HeNE73zNfqoLQAAAQA"]
[Sun Aug 30 03:04:22.577435 2026] [authz_core:error] [pid 488281:tid 488435] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fvar%2Flib%2Fpcp%2Fconfig
[Sun Aug 30 03:04:22.577734 2026] [authz_core:error] [pid 488281:tid 488435] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fvar%2Flib%2Fpcp%2Fconfig
[Sun Aug 30 03:04:22.600215 2026] [security2:error] [pid 488669:tid 488882] [client 158.23.147.79:55220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-includes/js/index.php"] [unique_id "apPkBtRh6OewFvqQpDlL1QAAAVU"]
[Sun Aug 30 03:04:22.609591 2026] [security2:error] [pid 488281:tid 488466] [client 68.155.159.216:59986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkBjIT5HeNE73zNfqoOgAAALw"]
[Sun Aug 30 03:04:22.643932 2026] [security2:error] [pid 488281:tid 488507] [client 158.23.184.117:23970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/cgi-bin/wp-mail.php"] [unique_id "apPkBjIT5HeNE73zNfqoRQAAAOU"]
[Sun Aug 30 03:04:22.648225 2026] [security2:error] [pid 488281:tid 488450] [client 20.104.50.220:61993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/funtion.php"] [unique_id "apPkBjIT5HeNE73zNfqoRgAAAKw"]
[Sun Aug 30 03:04:22.648569 2026] [security2:error] [pid 488281:tid 488415] [client 20.48.251.3:31678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lastmaskcenter.org"] [uri "/time.php"] [unique_id "apPkBjIT5HeNE73zNfqoRwAAAIk"]
[Sun Aug 30 03:04:22.697593 2026] [security2:error] [pid 488281:tid 488451] [client 20.104.50.220:62808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-content/fw.php"] [unique_id "apPkBjIT5HeNE73zNfqoXQAAAK0"]
[Sun Aug 30 03:04:22.697892 2026] [security2:error] [pid 488669:tid 488906] [client 20.104.50.220:29826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/cong.php"] [unique_id "apPkBtRh6OewFvqQpDlL4gAAAW0"]
[Sun Aug 30 03:04:22.700706 2026] [fcgid:warn] [pid 488281:tid 488431] (70014)End of file found: [client 152.32.175.187:55598] mod_fcgid: can't get data from http client
[Sun Aug 30 03:04:22.704511 2026] [security2:error] [pid 488281:tid 488455] [client 20.63.81.20:59105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "apPkBjIT5HeNE73zNfqoYAAAALE"]
[Sun Aug 30 03:04:22.745253 2026] [security2:error] [pid 488281:tid 488529] [client 20.48.251.3:59284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/png.php"] [unique_id "apPkBjIT5HeNE73zNfqobQAAAPs"]
[Sun Aug 30 03:04:22.746078 2026] [security2:error] [pid 488281:tid 488490] [client 158.23.147.79:55074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-content/index.php"] [unique_id "apPkBjIT5HeNE73zNfqobgAAANQ"]
[Sun Aug 30 03:04:22.780017 2026] [authz_core:error] [pid 488281:tid 488415] [client 74.7.243.204:33990] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fopt%2Falt%2Fphp55%2Fusr%2Fshare%2Fdoc%2Fpear%2FTwigBridge%2FSymfony%2FBridge
[Sun Aug 30 03:04:22.780468 2026] [authz_core:error] [pid 488281:tid 488415] [client 74.7.243.204:33990] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fopt%2Falt%2Fphp55%2Fusr%2Fshare%2Fdoc%2Fpear%2FTwigBridge%2FSymfony%2FBridge
[Sun Aug 30 03:04:22.784752 2026] [security2:error] [pid 488281:tid 488448] [client 158.23.184.117:23954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "apPkBjIT5HeNE73zNfqogAAAAKo"]
[Sun Aug 30 03:04:22.816980 2026] [security2:error] [pid 488669:tid 488879] [client 20.104.50.220:5512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/cong.php"] [unique_id "apPkBtRh6OewFvqQpDlL8wAAAVI"]
[Sun Aug 30 03:04:22.825901 2026] [security2:error] [pid 488669:tid 488849] [client 20.104.49.130:48383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trinitytechnologics.com"] [uri "/bthil.php"] [unique_id "apPkBtRh6OewFvqQpDlL9gAAATQ"]
[Sun Aug 30 03:04:22.827403 2026] [security2:error] [pid 488281:tid 488421] [client 20.48.251.3:50014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/lmfi2.php"] [unique_id "apPkBjIT5HeNE73zNfqoiAAAAI8"]
[Sun Aug 30 03:04:22.831817 2026] [security2:error] [pid 488281:tid 488482] [client 20.63.81.20:59095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/robots.php"] [unique_id "apPkBjIT5HeNE73zNfqoiQAAAMw"]
[Sun Aug 30 03:04:22.838070 2026] [security2:error] [pid 488281:tid 488486] [client 20.48.251.3:44254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/nzv.php"] [unique_id "apPkBjIT5HeNE73zNfqojAAAANA"]
[Sun Aug 30 03:04:22.892441 2026] [security2:error] [pid 488281:tid 488424] [client 20.104.50.220:41986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-thumbs.php"] [unique_id "apPkBjIT5HeNE73zNfqolgAAAJI"]
[Sun Aug 30 03:04:22.904129 2026] [security2:error] [pid 488669:tid 488875] [client 158.23.147.79:62835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/about/function.php"] [unique_id "apPkBtRh6OewFvqQpDlL_wAAAU4"]
[Sun Aug 30 03:04:22.925254 2026] [security2:error] [pid 488281:tid 488440] [client 158.23.184.117:23993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/chosen.php"] [unique_id "apPkBjIT5HeNE73zNfqooAAAAKI"]
[Sun Aug 30 03:04:22.943815 2026] [security2:error] [pid 488669:tid 488813] [client 20.104.50.220:46609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/159.php"] [unique_id "apPkBtRh6OewFvqQpDlMBQAAARA"]
[Sun Aug 30 03:04:22.958635 2026] [security2:error] [pid 488281:tid 488458] [client 20.63.81.20:59047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp-content/plugins/ccx/index.php"] [unique_id "apPkBjIT5HeNE73zNfqosgAAALQ"]
[Sun Aug 30 03:04:22.969936 2026] [authz_core:error] [pid 488281:tid 488477] [client 66.249.66.195:60438] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:22.970401 2026] [authz_core:error] [pid 488281:tid 488477] [client 66.249.66.195:60438] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:23.024701 2026] [security2:error] [pid 488281:tid 488478] [client 34.131.221.169:49540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/site/phpinfo.php"] [unique_id "apPkBzIT5HeNE73zNfqo0wAAAMg"]
[Sun Aug 30 03:04:23.035136 2026] [security2:error] [pid 488281:tid 488509] [client 34.131.221.169:49542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "apPkBzIT5HeNE73zNfqo1gAAAOc"]
[Sun Aug 30 03:04:23.076853 2026] [security2:error] [pid 488281:tid 488527] [client 20.48.251.3:64466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/goods.php"] [unique_id "apPkBzIT5HeNE73zNfqo6AAAAPk"]
[Sun Aug 30 03:04:23.079169 2026] [security2:error] [pid 488281:tid 488448] [client 20.104.18.15:9141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/indo.php"] [unique_id "apPkBzIT5HeNE73zNfqo6QAAAKo"]
[Sun Aug 30 03:04:23.080575 2026] [security2:error] [pid 488669:tid 488829] [client 158.23.147.79:55053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apPkB9Rh6OewFvqQpDlMHgAAASA"]
[Sun Aug 30 03:04:23.084987 2026] [security2:error] [pid 488281:tid 488508] [client 20.63.81.20:58952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp-admin/css/colors/maro.php"] [unique_id "apPkBzIT5HeNE73zNfqo7AAAAOY"]
[Sun Aug 30 03:04:23.094015 2026] [security2:error] [pid 488281:tid 488415] [client 20.104.49.130:48326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trinitytechnologics.com"] [uri "/xwx1.php"] [unique_id "apPkBzIT5HeNE73zNfqo8AAAAIk"]
[Sun Aug 30 03:04:23.100766 2026] [authz_core:error] [pid 488281:tid 488452] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Frpm
[Sun Aug 30 03:04:23.101219 2026] [authz_core:error] [pid 488281:tid 488452] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Frpm
[Sun Aug 30 03:04:23.113703 2026] [security2:error] [pid 488669:tid 488811] [client 158.23.184.117:23942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/class-wp-logo-new.php"] [unique_id "apPkB9Rh6OewFvqQpDlMJgAAAQ4"]
[Sun Aug 30 03:04:23.118512 2026] [security2:error] [pid 488281:tid 488422] [client 136.92.30.49:42454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/backend/.env"] [unique_id "apPkBzIT5HeNE73zNfqpAAAAAJA"]
[Sun Aug 30 03:04:23.134856 2026] [security2:error] [pid 488669:tid 488817] [client 20.104.50.220:31910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/images/wso.php"] [unique_id "apPkB9Rh6OewFvqQpDlMKQAAARQ"]
[Sun Aug 30 03:04:23.168972 2026] [security2:error] [pid 488669:tid 488876] [client 20.48.251.3:46218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/nzv.php"] [unique_id "apPkB9Rh6OewFvqQpDlMMgAAAU8"]
[Sun Aug 30 03:04:23.188381 2026] [authz_core:error] [pid 488281:tid 488530] [client 66.249.66.204:47266] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:23.188670 2026] [authz_core:error] [pid 488281:tid 488530] [client 66.249.66.204:47266] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:23.215573 2026] [security2:error] [pid 488281:tid 488441] [client 195.178.110.247:62058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.luxielectronics.com"] [uri "/index.php"] [unique_id "apPkBzIT5HeNE73zNfqpRAAAAKM"]
[Sun Aug 30 03:04:23.217290 2026] [security2:error] [pid 488281:tid 488526] [client 20.63.81.20:59013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp-admin/css/colors/coffee/marijuana.php"] [unique_id "apPkBzIT5HeNE73zNfqpRgAAAPg"]
[Sun Aug 30 03:04:23.248802 2026] [security2:error] [pid 488669:tid 488922] [client 20.104.18.15:31660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/alfa.php"] [unique_id "apPkB9Rh6OewFvqQpDlMTwAAAX0"]
[Sun Aug 30 03:04:23.254507 2026] [security2:error] [pid 488669:tid 488808] [client 158.23.184.117:23947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/classwithtostring.php"] [unique_id "apPkB9Rh6OewFvqQpDlMUwAAAQs"]
[Sun Aug 30 03:04:23.260233 2026] [security2:error] [pid 488281:tid 488506] [client 74.7.243.204:33990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/main/"] [unique_id "apPkBzIT5HeNE73zNfqpaAAAAOQ"], referer: http://mail.letter7brands.com/main/?p=%2F%2Fetc
[Sun Aug 30 03:04:23.262198 2026] [security2:error] [pid 488281:tid 488489] [client 136.92.30.49:42454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/server/.env"] [unique_id "apPkBzIT5HeNE73zNfqpbAAAANM"]
[Sun Aug 30 03:04:23.282731 2026] [security2:error] [pid 488281:tid 488520] [client 158.23.147.79:55047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-admin/index.php"] [unique_id "apPkBzIT5HeNE73zNfqpegAAAPI"]
[Sun Aug 30 03:04:23.306233 2026] [security2:error] [pid 488669:tid 488874] [client 20.48.251.3:44331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/rem.php"] [unique_id "apPkB9Rh6OewFvqQpDlMYgAAAU0"]
[Sun Aug 30 03:04:23.352932 2026] [security2:error] [pid 488281:tid 488485] [client 20.63.81.20:59075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp-admin/css/colors/coffee/mari.php"] [unique_id "apPkBzIT5HeNE73zNfqpsAAAAM8"]
[Sun Aug 30 03:04:23.374835 2026] [security2:error] [pid 488281:tid 488430] [client 195.178.110.247:31422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.luxielectronics.com"] [uri "/index.php"] [unique_id "apPkBzIT5HeNE73zNfqpugAAAJg"]
[Sun Aug 30 03:04:23.392492 2026] [security2:error] [pid 488281:tid 488520] [client 158.23.184.117:23892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/cms.php"] [unique_id "apPkBzIT5HeNE73zNfqpyQAAAPI"]
[Sun Aug 30 03:04:23.407424 2026] [security2:error] [pid 488281:tid 488498] [client 136.92.30.49:42454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/frontend/.env"] [unique_id "apPkBzIT5HeNE73zNfqp2gAAANw"]
[Sun Aug 30 03:04:23.440355 2026] [security2:error] [pid 488281:tid 488325] [remote 47.128.26.13:61722] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.lisaariotti.com"] [uri "/robots.txt"] [unique_id "apPkBzIT5HeNE73zNfqp8gAAmCs"]
[Sun Aug 30 03:04:23.481052 2026] [security2:error] [pid 488281:tid 488508] [client 94.154.43.129:44330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.eessel.com"] [uri "/.env"] [unique_id "apPkBzIT5HeNE73zNfqqKAAAAOY"]
[Sun Aug 30 03:04:23.483582 2026] [security2:error] [pid 488669:tid 488887] [client 20.104.50.220:32842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wihp1.php"] [unique_id "apPkB9Rh6OewFvqQpDlMtgAAAVo"]
[Sun Aug 30 03:04:23.489085 2026] [security2:error] [pid 488281:tid 488434] [client 158.23.147.79:55075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPkBzIT5HeNE73zNfqqLgAAAJw"]
[Sun Aug 30 03:04:23.497993 2026] [security2:error] [pid 488281:tid 488524] [client 20.63.81.20:59081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp-includes/images/crystal/option.php"] [unique_id "apPkBzIT5HeNE73zNfqqOQAAAPY"]
[Sun Aug 30 03:04:23.551681 2026] [security2:error] [pid 488281:tid 488529] [client 158.23.184.117:59318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/config.php"] [unique_id "apPkBzIT5HeNE73zNfqqYgAAAPs"]
[Sun Aug 30 03:04:23.559561 2026] [security2:error] [pid 488281:tid 488466] [client 136.92.30.49:42454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/src/.env"] [unique_id "apPkBzIT5HeNE73zNfqqZgAAALw"]
[Sun Aug 30 03:04:23.591626 2026] [security2:error] [pid 488669:tid 488932] [client 20.104.50.220:62837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/12htKbyVOUv.php"] [unique_id "apPkB9Rh6OewFvqQpDlM2QAAAYc"]
[Sun Aug 30 03:04:23.599268 2026] [authz_core:error] [pid 488281:tid 488538] [client 66.249.66.203:42750] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:23.599706 2026] [authz_core:error] [pid 488281:tid 488538] [client 66.249.66.203:42750] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:23.625216 2026] [security2:error] [pid 488281:tid 488486] [client 94.154.43.135:58502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.eessel.com"] [uri "/.env"] [unique_id "apPkBzIT5HeNE73zNfqqgQAAANA"]
[Sun Aug 30 03:04:23.625576 2026] [security2:error] [pid 488281:tid 488525] [client 68.155.159.216:52861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-admin/maint/index.php"] [unique_id "apPkBzIT5HeNE73zNfqqggAAAPc"]
[Sun Aug 30 03:04:23.629380 2026] [security2:error] [pid 488281:tid 488451] [client 20.63.81.20:59120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp-includes/pomo/xxx.php"] [unique_id "apPkBzIT5HeNE73zNfqqhQAAAK0"]
[Sun Aug 30 03:04:23.657786 2026] [security2:error] [pid 488281:tid 488437] [client 114.119.146.220:31375] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.artbyroslyn.on.ca"] [uri "/images-opt/flowers-garden/2022/dancing-iris.jpg"] [unique_id "apPkBzIT5HeNE73zNfqqjAAAAJ8"], referer: http://www.artbyroslyn.on.ca/gallery/flowers-garden.html
[Sun Aug 30 03:04:23.683012 2026] [security2:error] [pid 488281:tid 488522] [client 158.23.147.79:55075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/about.php"] [unique_id "apPkBzIT5HeNE73zNfqqmAAAAPQ"]
[Sun Aug 30 03:04:23.691745 2026] [security2:error] [pid 488281:tid 488485] [client 158.23.184.117:23944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/configs.php"] [unique_id "apPkBzIT5HeNE73zNfqqngAAAM8"]
[Sun Aug 30 03:04:23.691965 2026] [security2:error] [pid 488669:tid 488919] [client 20.48.251.3:64464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/oiko6u.php"] [unique_id "apPkB9Rh6OewFvqQpDlM4AAAAXo"]
[Sun Aug 30 03:04:23.713552 2026] [security2:error] [pid 488281:tid 488416] [client 136.92.30.49:42454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/core/.env"] [unique_id "apPkBzIT5HeNE73zNfqqpwAAAIo"]
[Sun Aug 30 03:04:23.719247 2026] [security2:error] [pid 488669:tid 488860] [client 20.48.251.3:34595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/aws.php"] [unique_id "apPkB9Rh6OewFvqQpDlM5AAAAT8"]
[Sun Aug 30 03:04:23.747828 2026] [security2:error] [pid 488281:tid 488439] [client 34.131.221.169:49572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/administrator/phpinfo.php"] [unique_id "apPkBzIT5HeNE73zNfqqrwAAAKE"]
[Sun Aug 30 03:04:23.752119 2026] [security2:error] [pid 488281:tid 488519] [client 34.131.221.169:49556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/docs/phpinfo.php"] [unique_id "apPkBzIT5HeNE73zNfqqswAAAPE"]
[Sun Aug 30 03:04:23.763109 2026] [security2:error] [pid 488281:tid 488498] [client 20.63.81.20:59106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/650.php"] [unique_id "apPkBzIT5HeNE73zNfqquAAAANw"]
[Sun Aug 30 03:04:23.778847 2026] [security2:error] [pid 488281:tid 488537] [client 20.48.251.3:31669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lastmaskcenter.org"] [uri "/doc.php"] [unique_id "apPkBzIT5HeNE73zNfqqwgAAAQM"]
[Sun Aug 30 03:04:23.782062 2026] [security2:error] [pid 488281:tid 488437] [client 20.104.49.130:48353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trinitytechnologics.com"] [uri "/bolt.php"] [unique_id "apPkBzIT5HeNE73zNfqqxgAAAJ8"]
[Sun Aug 30 03:04:23.783503 2026] [security2:error] [pid 488281:tid 488478] [client 74.7.243.204:33990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/main/"] [unique_id "apPkBzIT5HeNE73zNfqqyAAAAMg"], referer: http://mail.letter7brands.com/main/?p=%2F%2Fetc
[Sun Aug 30 03:04:23.804463 2026] [authz_core:error] [pid 488281:tid 488417] [client 216.73.216.128:49784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:23.804739 2026] [authz_core:error] [pid 488281:tid 488417] [client 216.73.216.128:49784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:23.818003 2026] [security2:error] [pid 488669:tid 488859] [client 68.155.159.216:60005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apPkB9Rh6OewFvqQpDlM8QAAAT4"]
[Sun Aug 30 03:04:23.832968 2026] [security2:error] [pid 488281:tid 488487] [client 20.104.50.220:29865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/getid3s.php"] [unique_id "apPkBzIT5HeNE73zNfqq3wAAANE"]
[Sun Aug 30 03:04:23.834183 2026] [security2:error] [pid 488281:tid 488440] [client 158.23.184.117:23957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/configuration.php"] [unique_id "apPkBzIT5HeNE73zNfqq4AAAAKI"]
[Sun Aug 30 03:04:23.854510 2026] [security2:error] [pid 488281:tid 488494] [client 20.104.50.220:61471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/xixi.php"] [unique_id "apPkBzIT5HeNE73zNfqq5gAAANg"]
[Sun Aug 30 03:04:23.860309 2026] [security2:error] [pid 488281:tid 488448] [client 136.92.30.49:42454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/core/app/.env"] [unique_id "apPkBzIT5HeNE73zNfqq6QAAAKo"]
[Sun Aug 30 03:04:23.860542 2026] [security2:error] [pid 488281:tid 488483] [client 20.104.50.220:62822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-admin/fw.php"] [unique_id "apPkBzIT5HeNE73zNfqq6gAAAM0"]
[Sun Aug 30 03:04:23.875997 2026] [authz_core:error] [pid 488281:tid 488519] [client 66.249.66.69:53184] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:23.876252 2026] [authz_core:error] [pid 488281:tid 488519] [client 66.249.66.69:53184] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:23.887927 2026] [security2:error] [pid 488281:tid 488531] [client 20.48.251.3:59305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/chosen.php"] [unique_id "apPkBzIT5HeNE73zNfqq9gAAAP0"]
[Sun Aug 30 03:04:23.889903 2026] [security2:error] [pid 488281:tid 488520] [client 20.63.81.20:59031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/nakrip.php"] [unique_id "apPkBzIT5HeNE73zNfqq9wAAAPI"]
[Sun Aug 30 03:04:23.946500 2026] [security2:error] [pid 488281:tid 488424] [client 158.23.147.79:62802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apPkBzIT5HeNE73zNfqrDQAAAJI"]
[Sun Aug 30 03:04:23.966421 2026] [security2:error] [pid 488281:tid 488483] [client 20.48.251.3:55475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/wpver.php"] [unique_id "apPkBzIT5HeNE73zNfqrIAAAAM0"]
[Sun Aug 30 03:04:23.973878 2026] [security2:error] [pid 488669:tid 488914] [client 158.23.184.117:23950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/content.php"] [unique_id "apPkB9Rh6OewFvqQpDlNAAAAAXU"]
[Sun Aug 30 03:04:23.987430 2026] [security2:error] [pid 488281:tid 488468] [client 20.48.251.3:44258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/66.php"] [unique_id "apPkBzIT5HeNE73zNfqrMgAAAL4"]
[Sun Aug 30 03:04:24.003346 2026] [security2:error] [pid 488281:tid 488499] [client 136.92.30.49:42454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/config/.env"] [unique_id "apPkCDIT5HeNE73zNfqrPQAAAN0"]
[Sun Aug 30 03:04:24.020693 2026] [security2:error] [pid 488281:tid 488487] [client 20.63.81.20:59099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp-includes/interactivity-api/flower.php"] [unique_id "apPkCDIT5HeNE73zNfqrQwAAANE"]
[Sun Aug 30 03:04:24.028001 2026] [security2:error] [pid 488669:tid 488823] [client 20.104.50.220:63494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-mobfi.php"] [unique_id "apPkCNRh6OewFvqQpDlNBQAAARo"]
[Sun Aug 30 03:04:24.028316 2026] [security2:error] [pid 488669:tid 488867] [client 20.104.50.220:5542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPkB9Rh6OewFvqQpDlNAQAAAUY"]
[Sun Aug 30 03:04:24.072292 2026] [authz_core:error] [pid 488281:tid 488418] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx
[Sun Aug 30 03:04:24.072613 2026] [authz_core:error] [pid 488281:tid 488418] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx
[Sun Aug 30 03:04:24.081630 2026] [security2:error] [pid 488281:tid 488469] [client 20.104.50.220:46445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/tesla1.php"] [unique_id "apPkCDIT5HeNE73zNfqrWwAAAL8"]
[Sun Aug 30 03:04:24.081945 2026] [security2:error] [pid 488281:tid 488432] [client 20.220.204.93:34630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkCDIT5HeNE73zNfqrXAAAAJo"]
[Sun Aug 30 03:04:24.115957 2026] [security2:error] [pid 488281:tid 488506] [client 158.23.184.117:23937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/core.php"] [unique_id "apPkCDIT5HeNE73zNfqrdAAAAOQ"]
[Sun Aug 30 03:04:24.142531 2026] [security2:error] [pid 488281:tid 488502] [client 158.23.147.79:62834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/themes.php"] [unique_id "apPkCDIT5HeNE73zNfqrggAAAOA"]
[Sun Aug 30 03:04:24.146682 2026] [security2:error] [pid 488281:tid 488488] [client 136.92.30.49:42454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/private/.env"] [unique_id "apPkCDIT5HeNE73zNfqrhwAAANI"]
[Sun Aug 30 03:04:24.155143 2026] [security2:error] [pid 488669:tid 488916] [client 20.63.81.20:59084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/xcc.php"] [unique_id "apPkCNRh6OewFvqQpDlNGgAAAXc"]
[Sun Aug 30 03:04:24.213462 2026] [security2:error] [pid 488281:tid 488524] [client 81.68.127.28:58144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.127.68.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "buythebookkawkawlin.com"] [uri "/wp-login.php"] [unique_id "apPkCDIT5HeNE73zNfqrrQAAAPY"]
[Sun Aug 30 03:04:24.252119 2026] [security2:error] [pid 488281:tid 488520] [client 20.104.18.15:9214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/sign.php"] [unique_id "apPkCDIT5HeNE73zNfqr0gAAAPI"]
[Sun Aug 30 03:04:24.256730 2026] [security2:error] [pid 488281:tid 488428] [client 158.23.184.117:23985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/data.php"] [unique_id "apPkCDIT5HeNE73zNfqr1QAAAJY"]
[Sun Aug 30 03:04:24.257888 2026] [security2:error] [pid 488669:tid 488889] [client 20.48.251.3:7017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/loxi-o.php"] [unique_id "apPkCNRh6OewFvqQpDlNQAAAAVw"]
[Sun Aug 30 03:04:24.267456 2026] [authz_core:error] [pid 488669:tid 488842] [client 66.249.66.204:42790] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:24.267762 2026] [authz_core:error] [pid 488669:tid 488842] [client 66.249.66.204:42790] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:24.280792 2026] [security2:error] [pid 488281:tid 488411] [client 20.104.50.220:32408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/images/sym403.php"] [unique_id "apPkCDIT5HeNE73zNfqr4QAAAIU"]
[Sun Aug 30 03:04:24.288021 2026] [security2:error] [pid 488669:tid 488881] [client 20.63.81.20:59102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp-includes/Text/Diff/Engine/aaa.php"] [unique_id "apPkCNRh6OewFvqQpDlNUQAAAVQ"]
[Sun Aug 30 03:04:24.292804 2026] [security2:error] [pid 488281:tid 488530] [client 136.92.30.49:42454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/application/.env"] [unique_id "apPkCDIT5HeNE73zNfqr6AAAAPw"]
[Sun Aug 30 03:04:24.333995 2026] [security2:error] [pid 488281:tid 488454] [client 158.23.147.79:62815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-mail.php"] [unique_id "apPkCDIT5HeNE73zNfqsCAAAALA"]
[Sun Aug 30 03:04:24.368268 2026] [security2:error] [pid 488669:tid 488919] [client 20.104.49.130:36102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wondertanks.com"] [uri "/wp-good.php"] [unique_id "apPkCNRh6OewFvqQpDlNbAAAAXo"]
[Sun Aug 30 03:04:24.381768 2026] [security2:error] [pid 488281:tid 488474] [client 20.104.18.15:31733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/33.php"] [unique_id "apPkCDIT5HeNE73zNfqsIwAAAMQ"]
[Sun Aug 30 03:04:24.382437 2026] [security2:error] [pid 488669:tid 488852] [client 20.48.251.3:54730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/admin.php"] [unique_id "apPkCNRh6OewFvqQpDlNcAAAATc"]
[Sun Aug 30 03:04:24.388389 2026] [security2:error] [pid 488281:tid 488487] [client 20.151.200.44:58905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/wefile.php"] [unique_id "apPkCDIT5HeNE73zNfqsKQAAANE"]
[Sun Aug 30 03:04:24.395118 2026] [security2:error] [pid 488669:tid 488932] [client 158.23.184.117:23963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/database.php"] [unique_id "apPkCNRh6OewFvqQpDlNeAAAAYc"]
[Sun Aug 30 03:04:24.422629 2026] [security2:error] [pid 488669:tid 488871] [client 157.66.27.63:53270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.27.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "chamirgimenez.com"] [uri "/wp-login.php"] [unique_id "apPkCNRh6OewFvqQpDlNgAAAAUo"]
[Sun Aug 30 03:04:24.430727 2026] [security2:error] [pid 488281:tid 488417] [client 20.63.81.20:59009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp-includes/style-engine/gecko-new.php"] [unique_id "apPkCDIT5HeNE73zNfqsWAAAAIs"]
[Sun Aug 30 03:04:24.438025 2026] [security2:error] [pid 488281:tid 488477] [client 136.92.30.49:42454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/bootstrap/.env"] [unique_id "apPkCDIT5HeNE73zNfqsZAAAAMc"]
[Sun Aug 30 03:04:24.438537 2026] [authz_core:error] [pid 488281:tid 488455] [client 66.249.66.205:52735] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:24.439008 2026] [authz_core:error] [pid 488281:tid 488455] [client 66.249.66.205:52735] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:24.447880 2026] [security2:error] [pid 488281:tid 488463] [client 34.16.144.252:7990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/backend-api/.env"] [unique_id "apPkCDIT5HeNE73zNfqscQAAALk"]
[Sun Aug 30 03:04:24.449397 2026] [security2:error] [pid 488281:tid 488445] [client 34.16.144.252:8068] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpcontacts.alchemancer.com"] [uri "/backend/api/.env"] [unique_id "apPkCDIT5HeNE73zNfqsdwAAAKc"]
[Sun Aug 30 03:04:24.449416 2026] [security2:error] [pid 488281:tid 488530] [client 34.16.144.252:8016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/test/.env"] [unique_id "apPkCDIT5HeNE73zNfqscgAAAPw"]
[Sun Aug 30 03:04:24.449435 2026] [security2:error] [pid 488281:tid 488487] [client 34.16.144.252:8036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/services/.env"] [unique_id "apPkCDIT5HeNE73zNfqscwAAANE"]
[Sun Aug 30 03:04:24.450288 2026] [security2:error] [pid 488281:tid 488500] [client 34.16.144.252:7974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/back/.env"] [unique_id "apPkCDIT5HeNE73zNfqseAAAAN4"]
[Sun Aug 30 03:04:24.451397 2026] [security2:error] [pid 488281:tid 488537] [client 34.16.144.252:8010] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/stage/.env"] [unique_id "apPkCDIT5HeNE73zNfqseQAAAQM"]
[Sun Aug 30 03:04:24.452449 2026] [security2:error] [pid 488281:tid 488503] [client 34.16.144.252:7994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/development/.env"] [unique_id "apPkCDIT5HeNE73zNfqsfQAAAOE"]
[Sun Aug 30 03:04:24.453332 2026] [security2:error] [pid 488281:tid 488521] [client 34.16.144.252:8132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/src/api/.env"] [unique_id "apPkCDIT5HeNE73zNfqsfgAAAPM"]
[Sun Aug 30 03:04:24.453747 2026] [security2:error] [pid 488669:tid 488851] [client 34.16.144.252:8054] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.alchemancer.com"] [uri "/frontend/.env.production"] [unique_id "apPkCNRh6OewFvqQpDlNlwAAATY"]
[Sun Aug 30 03:04:24.454614 2026] [security2:error] [pid 488669:tid 488883] [client 34.16.144.252:8028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/node/.env"] [unique_id "apPkCNRh6OewFvqQpDlNmAAAAVY"]
[Sun Aug 30 03:04:24.455212 2026] [security2:error] [pid 488669:tid 488888] [client 34.16.144.252:8082] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/app/backend/.env"] [unique_id "apPkCNRh6OewFvqQpDlNmgAAAVs"]
[Sun Aug 30 03:04:24.455670 2026] [security2:error] [pid 488669:tid 488889] [client 34.16.144.252:8006] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/prod/.env"] [unique_id "apPkCNRh6OewFvqQpDlNlgAAAVw"]
[Sun Aug 30 03:04:24.455745 2026] [security2:error] [pid 488669:tid 488839] [client 34.16.144.252:8138] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/apps/backend/.env"] [unique_id "apPkCNRh6OewFvqQpDlNmwAAASo"]
[Sun Aug 30 03:04:24.456391 2026] [security2:error] [pid 488281:tid 488534] [client 34.16.144.252:8076] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpcontacts.alchemancer.com"] [uri "/internal/.env"] [unique_id "apPkCDIT5HeNE73zNfqshQAAAQA"]
[Sun Aug 30 03:04:24.458285 2026] [security2:error] [pid 488281:tid 488434] [client 34.16.144.252:8148] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/apps/api/.env"] [unique_id "apPkCDIT5HeNE73zNfqshgAAAJw"]
[Sun Aug 30 03:04:24.458920 2026] [security2:error] [pid 488669:tid 488846] [client 34.16.144.252:8130] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.alchemancer.com"] [uri "/admin/.env.local"] [unique_id "apPkCNRh6OewFvqQpDlNpgAAATE"]
[Sun Aug 30 03:04:24.459606 2026] [security2:error] [pid 488669:tid 488825] [client 34.16.144.252:8048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/private/.env"] [unique_id "apPkCNRh6OewFvqQpDlNpAAAARw"]
[Sun Aug 30 03:04:24.460422 2026] [security2:error] [pid 488669:tid 488890] [client 34.16.144.252:8190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.144.16.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alchemancer.com"] [uri "/config/env.php"] [unique_id "apPkCNRh6OewFvqQpDlNrQAAAV0"]
[Sun Aug 30 03:04:24.460860 2026] [security2:error] [pid 488669:tid 488826] [client 34.16.144.252:8164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/database/.env"] [unique_id "apPkCNRh6OewFvqQpDlNqAAAAR0"]
[Sun Aug 30 03:04:24.461985 2026] [security2:error] [pid 488669:tid 488925] [client 34.16.144.252:8128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/app/api/.env"] [unique_id "apPkCNRh6OewFvqQpDlNrwAAAYA"]
[Sun Aug 30 03:04:24.473474 2026] [security2:error] [pid 488281:tid 488518] [client 34.131.221.169:49586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "apPkCDIT5HeNE73zNfqsmAAAAPA"]
[Sun Aug 30 03:04:24.479053 2026] [security2:error] [pid 488281:tid 488509] [client 34.131.221.169:49580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/core/phpinfo.php"] [unique_id "apPkCDIT5HeNE73zNfqsnwAAAOc"]
[Sun Aug 30 03:04:24.482203 2026] [security2:error] [pid 488281:tid 488527] [client 20.220.10.235:21579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkCDIT5HeNE73zNfqsowAAAPk"]
[Sun Aug 30 03:04:24.485189 2026] [security2:error] [pid 488669:tid 488906] [client 34.16.144.252:8102] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/src/.env.local"] [unique_id "apPkCNRh6OewFvqQpDlNnQAAAW0"]
[Sun Aug 30 03:04:24.485573 2026] [security2:error] [pid 488281:tid 488463] [client 158.23.147.79:55101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/cgi-bin/index.php"] [unique_id "apPkCDIT5HeNE73zNfqspgAAALk"]
[Sun Aug 30 03:04:24.493019 2026] [security2:error] [pid 488281:tid 488444] [client 34.16.144.252:8206] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/credentials.ini"] [unique_id "apPkCDIT5HeNE73zNfqsiQAAAKY"]
[Sun Aug 30 03:04:24.496550 2026] [security2:error] [pid 488669:tid 488881] [client 34.16.144.252:8110] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/server/.env.production"] [unique_id "apPkCNRh6OewFvqQpDlNogAAAVQ"]
[Sun Aug 30 03:04:24.508291 2026] [security2:error] [pid 488669:tid 488879] [client 34.16.144.252:8126] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/frontend/.env.local"] [unique_id "apPkCNRh6OewFvqQpDlNoAAAAVI"]
[Sun Aug 30 03:04:24.523862 2026] [security2:error] [pid 488669:tid 488822] [client 34.16.144.252:8094] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/src/.env.production"] [unique_id "apPkCNRh6OewFvqQpDlNpQAAARk"]
[Sun Aug 30 03:04:24.535262 2026] [security2:error] [pid 488281:tid 488446] [client 158.23.184.117:59288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/db.php"] [unique_id "apPkCDIT5HeNE73zNfqs0QAAAKg"]
[Sun Aug 30 03:04:24.569721 2026] [authz_core:error] [pid 488281:tid 488513] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx
[Sun Aug 30 03:04:24.569987 2026] [authz_core:error] [pid 488281:tid 488513] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx
[Sun Aug 30 03:04:24.575133 2026] [security2:error] [pid 488669:tid 488808] [client 34.16.144.252:8176] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/config/credentials.json"] [unique_id "apPkCNRh6OewFvqQpDlNsQAAAQs"]
[Sun Aug 30 03:04:24.576838 2026] [security2:error] [pid 488281:tid 488435] [client 20.63.81.20:59098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp-settings.php"] [unique_id "apPkCDIT5HeNE73zNfqs6QAAAJ0"]
[Sun Aug 30 03:04:24.582568 2026] [security2:error] [pid 488281:tid 488496] [client 136.92.30.49:42454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/database/.env"] [unique_id "apPkCDIT5HeNE73zNfqs6wAAANo"]
[Sun Aug 30 03:04:24.621556 2026] [security2:error] [pid 488281:tid 488457] [client 20.220.10.235:21572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkCDIT5HeNE73zNfqs_gAAALM"]
[Sun Aug 30 03:04:24.637964 2026] [security2:error] [pid 488281:tid 488501] [client 20.104.50.220:33195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-blog.php"] [unique_id "apPkCDIT5HeNE73zNfqtCAAAAN8"]
[Sun Aug 30 03:04:24.651703 2026] [security2:error] [pid 488281:tid 488468] [client 158.23.147.79:62823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPkCDIT5HeNE73zNfqtDwAAAL4"]
[Sun Aug 30 03:04:24.679761 2026] [security2:error] [pid 488281:tid 488420] [client 158.23.184.117:59275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/default.php"] [unique_id "apPkCDIT5HeNE73zNfqtHQAAAI4"]
[Sun Aug 30 03:04:24.695284 2026] [security2:error] [pid 488281:tid 488458] [client 20.220.204.93:34685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkCDIT5HeNE73zNfqtIwAAALQ"]
[Sun Aug 30 03:04:24.709679 2026] [security2:error] [pid 488281:tid 488453] [client 20.63.81.20:59048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp-signup.php"] [unique_id "apPkCDIT5HeNE73zNfqtJwAAAK8"]
[Sun Aug 30 03:04:24.727462 2026] [security2:error] [pid 488281:tid 488419] [client 136.92.30.49:42454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/storage/.env"] [unique_id "apPkCDIT5HeNE73zNfqtLgAAAI0"]
[Sun Aug 30 03:04:24.763339 2026] [security2:error] [pid 488281:tid 488510] [client 20.220.10.235:21624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/h02ugyh.php"] [unique_id "apPkCDIT5HeNE73zNfqtOgAAAOg"]
[Sun Aug 30 03:04:24.777600 2026] [security2:error] [pid 488669:tid 488863] [client 68.155.159.216:52673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/login.php"] [unique_id "apPkCNRh6OewFvqQpDlN-gAAAUI"]
[Sun Aug 30 03:04:24.782696 2026] [security2:error] [pid 488669:tid 488859] [client 20.104.50.220:28695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/0PeeTQW2sZ.php"] [unique_id "apPkCNRh6OewFvqQpDlN-wAAAT4"]
[Sun Aug 30 03:04:24.794367 2026] [security2:error] [pid 488281:tid 488413] [client 68.155.159.216:59374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/dropdown.php"] [unique_id "apPkCDIT5HeNE73zNfqtRgAAAIc"]
[Sun Aug 30 03:04:24.818327 2026] [authz_core:error] [pid 488281:tid 488490] [client 66.249.66.202:55124] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:24.818587 2026] [authz_core:error] [pid 488281:tid 488490] [client 66.249.66.202:55124] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:24.820543 2026] [security2:error] [pid 488281:tid 488491] [client 158.23.184.117:23976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/dev1s.php"] [unique_id "apPkCDIT5HeNE73zNfqtTgAAANU"]
[Sun Aug 30 03:04:24.848127 2026] [security2:error] [pid 488281:tid 488515] [client 20.63.81.20:59019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp-conffg.php"] [unique_id "apPkCDIT5HeNE73zNfqtWwAAAO0"]
[Sun Aug 30 03:04:24.871130 2026] [security2:error] [pid 488281:tid 488489] [client 136.92.30.49:42454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/var/www/.env"] [unique_id "apPkCDIT5HeNE73zNfqtZAAAANM"]
[Sun Aug 30 03:04:24.873055 2026] [security2:error] [pid 488281:tid 488417] [client 20.48.251.3:44323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/min.php"] [unique_id "apPkCDIT5HeNE73zNfqtZQAAAIs"]
[Sun Aug 30 03:04:24.879340 2026] [security2:error] [pid 488281:tid 488419] [client 158.23.147.79:55094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-includes/content.php"] [unique_id "apPkCDIT5HeNE73zNfqtZwAAAI0"]
[Sun Aug 30 03:04:24.913983 2026] [security2:error] [pid 488281:tid 488493] [client 20.220.10.235:21764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/sf.php"] [unique_id "apPkCDIT5HeNE73zNfqtdgAAANc"]
[Sun Aug 30 03:04:24.921686 2026] [security2:error] [pid 488281:tid 488514] [client 68.155.159.216:59917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apPkCDIT5HeNE73zNfqteQAAAOw"]
[Sun Aug 30 03:04:24.930473 2026] [security2:error] [pid 488281:tid 488434] [client 20.48.251.3:34500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/app.default.php"] [unique_id "apPkCDIT5HeNE73zNfqtfgAAAJw"]
[Sun Aug 30 03:04:24.960375 2026] [security2:error] [pid 488281:tid 488476] [client 158.23.184.117:59284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/dex.php"] [unique_id "apPkCDIT5HeNE73zNfqtjwAAAMY"]
[Sun Aug 30 03:04:24.960414 2026] [security2:error] [pid 488281:tid 488495] [client 20.48.251.3:31643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lastmaskcenter.org"] [uri "/classsmtps.php"] [unique_id "apPkCDIT5HeNE73zNfqtkQAAANk"]
[Sun Aug 30 03:04:24.968934 2026] [authz_core:error] [pid 488281:tid 488451] [client 66.249.66.193:64093] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:24.969190 2026] [authz_core:error] [pid 488281:tid 488451] [client 66.249.66.193:64093] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:24.970803 2026] [security2:error] [pid 488669:tid 488867] [client 20.104.50.220:29881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/row.php"] [unique_id "apPkCNRh6OewFvqQpDlOFQAAAUY"]
[Sun Aug 30 03:04:24.983881 2026] [security2:error] [pid 488281:tid 488538] [client 20.63.81.20:59097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp-validate.php"] [unique_id "apPkCDIT5HeNE73zNfqtpQAAAQQ"]
[Sun Aug 30 03:04:24.996135 2026] [security2:error] [pid 488669:tid 488823] [client 158.23.147.79:55068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-admin/css/index.php"] [unique_id "apPkCNRh6OewFvqQpDlOGQAAARo"]
[Sun Aug 30 03:04:24.998279 2026] [security2:error] [pid 488281:tid 488510] [client 20.104.50.220:52820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wordpress/fw.php"] [unique_id "apPkCDIT5HeNE73zNfqtqgAAAOg"]
[Sun Aug 30 03:04:25.021517 2026] [security2:error] [pid 488281:tid 488514] [client 20.48.251.3:55787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/admin-ajax.php"] [unique_id "apPkCTIT5HeNE73zNfqtswAAAOw"]
[Sun Aug 30 03:04:25.021807 2026] [security2:error] [pid 488281:tid 488484] [client 20.104.50.220:61654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-cli.php"] [unique_id "apPkCTIT5HeNE73zNfqttAAAAM4"]
[Sun Aug 30 03:04:25.026154 2026] [security2:error] [pid 488281:tid 488477] [client 136.92.30.49:42454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/var/www/html/.env"] [unique_id "apPkCTIT5HeNE73zNfqttgAAAMc"]
[Sun Aug 30 03:04:25.050505 2026] [security2:error] [pid 488281:tid 488499] [client 20.220.10.235:21626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/4e.php"] [unique_id "apPkCTIT5HeNE73zNfqtwQAAAN0"]
[Sun Aug 30 03:04:25.055192 2026] [security2:error] [pid 488669:tid 488835] [client 20.220.204.93:34684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/ff1.php"] [unique_id "apPkCdRh6OewFvqQpDlOHgAAASY"]
[Sun Aug 30 03:04:25.065797 2026] [authz_core:error] [pid 488281:tid 488469] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx
[Sun Aug 30 03:04:25.066260 2026] [authz_core:error] [pid 488281:tid 488469] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx
[Sun Aug 30 03:04:25.069824 2026] [security2:error] [pid 488281:tid 488515] [client 20.151.200.44:58918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/Contrller.php"] [unique_id "apPkCTIT5HeNE73zNfqtzgAAAO0"]
[Sun Aug 30 03:04:25.099952 2026] [security2:error] [pid 488281:tid 488495] [client 158.23.184.117:59323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/disagrsxr.php"] [unique_id "apPkCTIT5HeNE73zNfqt4AAAANk"]
[Sun Aug 30 03:04:25.103519 2026] [security2:error] [pid 488669:tid 488903] [client 20.48.251.3:55472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/ah25.php"] [unique_id "apPkCdRh6OewFvqQpDlOKAAAAWo"]
[Sun Aug 30 03:04:25.111101 2026] [security2:error] [pid 488281:tid 488510] [client 20.63.81.20:59074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/700.php"] [unique_id "apPkCTIT5HeNE73zNfqt5wAAAOg"]
[Sun Aug 30 03:04:25.126796 2026] [security2:error] [pid 488281:tid 488486] [client 20.48.251.3:22749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/admin.php"] [unique_id "apPkCTIT5HeNE73zNfqt7gAAANA"]
[Sun Aug 30 03:04:25.140811 2026] [authz_core:error] [pid 488281:tid 488471] [client 66.249.66.200:59211] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:25.141253 2026] [authz_core:error] [pid 488281:tid 488471] [client 66.249.66.200:59211] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:25.169739 2026] [security2:error] [pid 488281:tid 488448] [client 20.104.50.220:5615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/cong.php"] [unique_id "apPkCTIT5HeNE73zNfquFAAAAKo"]
[Sun Aug 30 03:04:25.174907 2026] [security2:error] [pid 488281:tid 488440] [client 136.92.30.49:42454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/current/.env"] [unique_id "apPkCTIT5HeNE73zNfquFwAAAKI"]
[Sun Aug 30 03:04:25.193928 2026] [security2:error] [pid 488281:tid 488521] [client 20.220.10.235:21592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/ssss.php"] [unique_id "apPkCTIT5HeNE73zNfquJAAAAPM"]
[Sun Aug 30 03:04:25.197418 2026] [security2:error] [pid 488669:tid 488912] [client 20.104.50.220:63491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-comments-post.php"] [unique_id "apPkCdRh6OewFvqQpDlOSQAAAXM"]
[Sun Aug 30 03:04:25.200836 2026] [authz_core:error] [pid 488281:tid 488480] [client 216.73.216.128:51358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:25.201299 2026] [authz_core:error] [pid 488281:tid 488480] [client 216.73.216.128:51358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:25.209706 2026] [security2:error] [pid 488669:tid 488875] [client 34.131.221.169:49612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer.com"] [uri "/includes/phpinfo.php"] [unique_id "apPkCdRh6OewFvqQpDlOTQAAAU4"]
[Sun Aug 30 03:04:25.214861 2026] [security2:error] [pid 488669:tid 488885] [client 34.131.221.169:49602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/administrator/phpinfo.php"] [unique_id "apPkCdRh6OewFvqQpDlOUgAAAVg"]
[Sun Aug 30 03:04:25.235491 2026] [security2:error] [pid 488281:tid 488500] [client 20.104.50.220:46610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/shadowx.php"] [unique_id "apPkCTIT5HeNE73zNfquNQAAAN4"]
[Sun Aug 30 03:04:25.240897 2026] [security2:error] [pid 488669:tid 488864] [client 158.23.184.117:23939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/domvf.php"] [unique_id "apPkCdRh6OewFvqQpDlOYQAAAUM"]
[Sun Aug 30 03:04:25.242202 2026] [security2:error] [pid 488281:tid 488514] [client 20.63.81.20:59021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/c4.php"] [unique_id "apPkCTIT5HeNE73zNfquOgAAAOw"]
[Sun Aug 30 03:04:25.269735 2026] [security2:error] [pid 488281:tid 488478] [client 34.16.144.252:52406] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcalendars.ilfcllc.net"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ"] [unique_id "apPkCTIT5HeNE73zNfquTAAAAMg"]
[Sun Aug 30 03:04:25.271019 2026] [security2:error] [pid 488281:tid 488525] [client 34.16.144.252:52426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpcalendars.ilfcllc.net"] [uri "/@fs/../.env"] [unique_id "apPkCTIT5HeNE73zNfquTwAAAPc"]
[Sun Aug 30 03:04:25.272528 2026] [security2:error] [pid 488281:tid 488443] [client 34.16.144.252:52366] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcalendars.ilfcllc.net"] [uri "/@fs/proc/self/environ"] [unique_id "apPkCTIT5HeNE73zNfquUwAAAKU"]
[Sun Aug 30 03:04:25.274117 2026] [security2:error] [pid 488281:tid 488419] [client 34.16.144.252:52414] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpcalendars.ilfcllc.net"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "apPkCTIT5HeNE73zNfquWAAAAI0"]
[Sun Aug 30 03:04:25.274717 2026] [security2:error] [pid 488669:tid 488815] [client 34.16.144.252:52436] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.ilfcllc.net"] [uri "/@fs/../../.env"] [unique_id "apPkCdRh6OewFvqQpDlOcAAAARI"]
[Sun Aug 30 03:04:25.275194 2026] [security2:error] [pid 488281:tid 488419] [client 158.23.147.79:62837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-admin/images/index.php"] [unique_id "apPkCTIT5HeNE73zNfquWgAAAI0"]
[Sun Aug 30 03:04:25.278138 2026] [security2:error] [pid 488669:tid 488905] [client 34.16.144.252:52582] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpcalendars.ilfcllc.net"] [uri "/@fs/home/www-data/.aws/credentials"] [unique_id "apPkCdRh6OewFvqQpDlOdQAAAWw"]
[Sun Aug 30 03:04:25.319536 2026] [security2:error] [pid 488281:tid 488414] [client 136.92.30.49:42454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/release/.env"] [unique_id "apPkCTIT5HeNE73zNfqugAAAAIg"]
[Sun Aug 30 03:04:25.328076 2026] [security2:error] [pid 488669:tid 488827] [client 20.220.10.235:21609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/zoz.php"] [unique_id "apPkCdRh6OewFvqQpDlOjwAAAR4"]
[Sun Aug 30 03:04:25.368811 2026] [security2:error] [pid 488281:tid 488439] [client 20.63.81.20:59111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp-tymanage.php"] [unique_id "apPkCTIT5HeNE73zNfquqAAAAKE"]
[Sun Aug 30 03:04:25.376423 2026] [security2:error] [pid 488281:tid 488478] [client 195.178.110.247:24198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.luxtiny.com"] [uri "/index.php"] [unique_id "apPkCTIT5HeNE73zNfquqwAAAMg"]
[Sun Aug 30 03:04:25.378747 2026] [security2:error] [pid 488669:tid 488877] [client 158.23.184.117:23975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/donate.php"] [unique_id "apPkCdRh6OewFvqQpDlOmQAAAVA"]
[Sun Aug 30 03:04:25.408538 2026] [security2:error] [pid 488669:tid 488903] [client 20.104.18.15:9156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/wnnjpsby.php"] [unique_id "apPkCdRh6OewFvqQpDlOqAAAAWo"]
[Sun Aug 30 03:04:25.442987 2026] [security2:error] [pid 488281:tid 488439] [client 20.104.50.220:32108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/images/leafmailer2.8.php"] [unique_id "apPkCTIT5HeNE73zNfqu3AAAAKE"]
[Sun Aug 30 03:04:25.447578 2026] [security2:error] [pid 488281:tid 488414] [client 158.23.147.79:55226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-includes/index.php"] [unique_id "apPkCTIT5HeNE73zNfqu4AAAAIg"]
[Sun Aug 30 03:04:25.462572 2026] [security2:error] [pid 488281:tid 488464] [client 136.92.30.49:42454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/releases/.env"] [unique_id "apPkCTIT5HeNE73zNfqu9AAAALo"]
[Sun Aug 30 03:04:25.463041 2026] [security2:error] [pid 488669:tid 488923] [client 20.220.10.235:21604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/kcs.php"] [unique_id "apPkCdRh6OewFvqQpDlO1gAAAX4"]
[Sun Aug 30 03:04:25.479409 2026] [authz_core:error] [pid 488281:tid 488437] [client 66.249.66.36:60960] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:25.479868 2026] [authz_core:error] [pid 488281:tid 488437] [client 66.249.66.36:60960] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:25.482912 2026] [security2:error] [pid 488669:tid 488896] [client 20.48.251.3:6489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/f35.php"] [unique_id "apPkCdRh6OewFvqQpDlO4gAAAWM"]
[Sun Aug 30 03:04:25.513470 2026] [security2:error] [pid 488669:tid 488872] [client 20.63.81.20:59100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/ajfto.php"] [unique_id "apPkCdRh6OewFvqQpDlO8gAAAUs"]
[Sun Aug 30 03:04:25.520241 2026] [security2:error] [pid 488669:tid 488824] [client 158.23.184.117:59271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/dropdown.php"] [unique_id "apPkCdRh6OewFvqQpDlO9gAAARs"]
[Sun Aug 30 03:04:25.534410 2026] [security2:error] [pid 488669:tid 488863] [client 20.48.251.3:64275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/png.php"] [unique_id "apPkCdRh6OewFvqQpDlO_gAAAUI"]
[Sun Aug 30 03:04:25.541146 2026] [security2:error] [pid 488281:tid 488529] [client 195.178.110.247:17308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.luxtiny.com"] [uri "/index.php"] [unique_id "apPkCTIT5HeNE73zNfqvNQAAAPs"]
[Sun Aug 30 03:04:25.544617 2026] [security2:error] [pid 488669:tid 488857] [client 20.104.18.15:31642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/133.php"] [unique_id "apPkCdRh6OewFvqQpDlPBAAAATw"]
[Sun Aug 30 03:04:25.569381 2026] [authz_core:error] [pid 488281:tid 488468] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fvar%2Flib%2Fcloud%2Fdata
[Sun Aug 30 03:04:25.569838 2026] [authz_core:error] [pid 488281:tid 488468] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fvar%2Flib%2Fcloud%2Fdata
[Sun Aug 30 03:04:25.569983 2026] [security2:error] [pid 488281:tid 488537] [client 158.23.147.79:55091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/mah.php"] [unique_id "apPkCTIT5HeNE73zNfqvSgAAAQM"]
[Sun Aug 30 03:04:25.600596 2026] [security2:error] [pid 488669:tid 488808] [client 20.220.204.93:34680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/t.php"] [unique_id "apPkCdRh6OewFvqQpDlPFQAAAQs"]
[Sun Aug 30 03:04:25.606289 2026] [security2:error] [pid 488281:tid 488449] [client 136.92.30.49:42454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/shared/.env"] [unique_id "apPkCTIT5HeNE73zNfqvTgAAAKs"]
[Sun Aug 30 03:04:25.621003 2026] [security2:error] [pid 488281:tid 488490] [client 20.220.10.235:21605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/tajj.php"] [unique_id "apPkCTIT5HeNE73zNfqvWAAAANQ"]
[Sun Aug 30 03:04:25.630828 2026] [security2:error] [pid 488281:tid 488492] [client 20.48.251.3:7052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/fraro.php"] [unique_id "apPkCTIT5HeNE73zNfqvXQAAANY"]
[Sun Aug 30 03:04:25.661567 2026] [security2:error] [pid 488281:tid 488527] [client 158.23.184.117:59286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/edit.php"] [unique_id "apPkCTIT5HeNE73zNfqvawAAAPk"]
[Sun Aug 30 03:04:25.669677 2026] [security2:error] [pid 488669:tid 488884] [client 20.63.81.20:59125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp_KwIW0U5F.php"] [unique_id "apPkCdRh6OewFvqQpDlPHQAAAVc"]
[Sun Aug 30 03:04:25.676769 2026] [security2:error] [pid 488281:tid 488536] [client 20.151.200.44:58943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/file66.php"] [unique_id "apPkCTIT5HeNE73zNfqvcgAAAQI"]
[Sun Aug 30 03:04:25.683617 2026] [security2:error] [pid 488281:tid 488428] [client 20.196.209.81:5258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/data.php"] [unique_id "apPkCTIT5HeNE73zNfqvdQAAAJY"]
[Sun Aug 30 03:04:25.746469 2026] [authz_core:error] [pid 488281:tid 488482] [client 216.73.216.128:51358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:25.746800 2026] [authz_core:error] [pid 488281:tid 488482] [client 216.73.216.128:51358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:25.752453 2026] [security2:error] [pid 488281:tid 488478] [client 136.92.30.49:42454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/deploy/.env"] [unique_id "apPkCTIT5HeNE73zNfqvjAAAAMg"]
[Sun Aug 30 03:04:25.761226 2026] [security2:error] [pid 488281:tid 488525] [client 20.220.10.235:21610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/bge.php"] [unique_id "apPkCTIT5HeNE73zNfqvkQAAAPc"]
[Sun Aug 30 03:04:25.798348 2026] [security2:error] [pid 488281:tid 488450] [client 20.104.50.220:33210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-utchershill.php"] [unique_id "apPkCTIT5HeNE73zNfqvpQAAAKw"]
[Sun Aug 30 03:04:25.800762 2026] [security2:error] [pid 488281:tid 488491] [client 20.63.81.20:59126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp_xiPu52Ut.php"] [unique_id "apPkCTIT5HeNE73zNfqvqQAAANU"]
[Sun Aug 30 03:04:25.804376 2026] [security2:error] [pid 488281:tid 488490] [client 158.23.184.117:23990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/ee.php"] [unique_id "apPkCTIT5HeNE73zNfqvqwAAANQ"]
[Sun Aug 30 03:04:25.817967 2026] [security2:error] [pid 488281:tid 488464] [client 158.23.147.79:55182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-blog-header.php"] [unique_id "apPkCTIT5HeNE73zNfqvrQAAALo"]
[Sun Aug 30 03:04:25.847250 2026] [security2:error] [pid 488281:tid 488499] [client 20.220.204.93:11004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/erty.php"] [unique_id "apPkCTIT5HeNE73zNfqvuwAAAN0"]
[Sun Aug 30 03:04:25.897076 2026] [security2:error] [pid 488281:tid 488500] [client 136.92.30.49:42454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/build/.env"] [unique_id "apPkCTIT5HeNE73zNfqvzAAAAN4"]
[Sun Aug 30 03:04:25.903671 2026] [security2:error] [pid 488281:tid 488487] [client 20.220.10.235:21568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/ssh3ll.php"] [unique_id "apPkCTIT5HeNE73zNfqv0QAAANE"]
[Sun Aug 30 03:04:25.920107 2026] [security2:error] [pid 488281:tid 488495] [client 20.104.50.220:52853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/.561988674612251.php"] [unique_id "apPkCTIT5HeNE73zNfqv2QAAANk"]
[Sun Aug 30 03:04:25.924091 2026] [authz_core:error] [pid 488281:tid 488525] [client 66.249.66.205:41370] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:25.924352 2026] [authz_core:error] [pid 488281:tid 488525] [client 66.249.66.205:41370] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:25.926782 2026] [security2:error] [pid 488281:tid 488443] [client 20.63.81.20:59104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp_n5VD7XDh.php"] [unique_id "apPkCTIT5HeNE73zNfqv3QAAAKU"]
[Sun Aug 30 03:04:25.930242 2026] [security2:error] [pid 488281:tid 488509] [client 158.23.147.79:55052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apPkCTIT5HeNE73zNfqv3gAAAOc"]
[Sun Aug 30 03:04:25.940608 2026] [security2:error] [pid 488281:tid 488431] [client 34.131.221.169:49624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/core/phpinfo.php"] [unique_id "apPkCTIT5HeNE73zNfqv4wAAAJk"]
[Sun Aug 30 03:04:25.942087 2026] [security2:error] [pid 488281:tid 488494] [client 68.155.159.216:60596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/sad/about.php"] [unique_id "apPkCTIT5HeNE73zNfqv5AAAANg"]
[Sun Aug 30 03:04:25.945693 2026] [security2:error] [pid 488669:tid 488909] [client 158.23.184.117:23994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/elp.php"] [unique_id "apPkCdRh6OewFvqQpDlPOwAAAXA"]
[Sun Aug 30 03:04:25.992031 2026] [security2:error] [pid 488669:tid 488851] [client 20.104.49.130:43373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wondertanks.com"] [uri "/as.php"] [unique_id "apPkCdRh6OewFvqQpDlPQwAAATY"]
[Sun Aug 30 03:04:26.031229 2026] [security2:error] [pid 488669:tid 488828] [client 20.48.251.3:44343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/saiga.php"] [unique_id "apPkCtRh6OewFvqQpDlPRwAAAR8"]
[Sun Aug 30 03:04:26.036716 2026] [security2:error] [pid 488281:tid 488440] [client 20.220.10.235:21622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/motu.php"] [unique_id "apPkCjIT5HeNE73zNfqwIwAAAKI"]
[Sun Aug 30 03:04:26.040986 2026] [security2:error] [pid 488281:tid 488490] [client 136.92.30.49:42454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/dist/.env"] [unique_id "apPkCjIT5HeNE73zNfqwJQAAANQ"]
[Sun Aug 30 03:04:26.051045 2026] [security2:error] [pid 488669:tid 488916] [client 20.151.200.44:58828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/blnux.php"] [unique_id "apPkCtRh6OewFvqQpDlPSgAAAXc"]
[Sun Aug 30 03:04:26.053075 2026] [security2:error] [pid 488669:tid 488865] [client 158.23.147.79:62795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-admin/user/index.php"] [unique_id "apPkCtRh6OewFvqQpDlPSwAAAUQ"]
[Sun Aug 30 03:04:26.058104 2026] [security2:error] [pid 488281:tid 488421] [client 20.63.81.20:59017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp-mini.php"] [unique_id "apPkCjIT5HeNE73zNfqwMQAAAI8"]
[Sun Aug 30 03:04:26.074758 2026] [security2:error] [pid 488281:tid 488469] [client 20.48.251.3:51465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/app_local.php"] [unique_id "apPkCjIT5HeNE73zNfqwOgAAAL8"]
[Sun Aug 30 03:04:26.077408 2026] [authz_core:error] [pid 488281:tid 488425] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fbind
[Sun Aug 30 03:04:26.079629 2026] [authz_core:error] [pid 488281:tid 488425] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fbind
[Sun Aug 30 03:04:26.084038 2026] [security2:error] [pid 488281:tid 488484] [client 20.196.209.81:23661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/dt-the7/css/static-less/plugins/admin.php"] [unique_id "apPkCjIT5HeNE73zNfqwPwAAAM4"]
[Sun Aug 30 03:04:26.087876 2026] [security2:error] [pid 488281:tid 488430] [client 158.23.184.117:23999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/en.php"] [unique_id "apPkCjIT5HeNE73zNfqwQwAAAJg"]
[Sun Aug 30 03:04:26.101953 2026] [security2:error] [pid 488669:tid 488839] [client 20.48.251.3:29710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lastmaskcenter.org"] [uri "/cache-compat.php"] [unique_id "apPkCtRh6OewFvqQpDlPVQAAASo"]
[Sun Aug 30 03:04:26.109979 2026] [security2:error] [pid 488281:tid 488453] [client 20.104.50.220:29699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/export.php"] [unique_id "apPkCjIT5HeNE73zNfqwUgAAAK8"]
[Sun Aug 30 03:04:26.143827 2026] [security2:error] [pid 488281:tid 488502] [client 20.104.50.220:52850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-content/dg.php"] [unique_id "apPkCjIT5HeNE73zNfqwaAAAAOA"]
[Sun Aug 30 03:04:26.161083 2026] [security2:error] [pid 488669:tid 488905] [client 20.48.251.3:55800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/ms.php"] [unique_id "apPkCtRh6OewFvqQpDlPXQAAAWw"]
[Sun Aug 30 03:04:26.182737 2026] [security2:error] [pid 488669:tid 488911] [client 20.220.10.235:21767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/wefile.php"] [unique_id "apPkCtRh6OewFvqQpDlPZAAAAXI"]
[Sun Aug 30 03:04:26.182827 2026] [security2:error] [pid 488281:tid 488450] [client 20.104.50.220:61436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/IP.php"] [unique_id "apPkCjIT5HeNE73zNfqwhgAAAKw"]
[Sun Aug 30 03:04:26.185594 2026] [security2:error] [pid 488281:tid 488420] [client 136.92.30.49:42454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/public_html/.env"] [unique_id "apPkCjIT5HeNE73zNfqwiAAAAI4"]
[Sun Aug 30 03:04:26.190225 2026] [security2:error] [pid 488281:tid 488412] [client 20.63.81.20:59134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/xmini4.php"] [unique_id "apPkCjIT5HeNE73zNfqwjAAAAIY"]
[Sun Aug 30 03:04:26.199719 2026] [security2:error] [pid 488281:tid 488471] [client 68.155.159.216:59911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/simple.php"] [unique_id "apPkCjIT5HeNE73zNfqwlQAAAME"]
[Sun Aug 30 03:04:26.200619 2026] [security2:error] [pid 488281:tid 488457] [client 158.23.147.79:55081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-includes/plugins.php"] [unique_id "apPkCjIT5HeNE73zNfqwlgAAALM"]
[Sun Aug 30 03:04:26.229374 2026] [security2:error] [pid 488669:tid 488882] [client 158.23.184.117:24211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thebikezone.ca"] [uri "/error.php"] [unique_id "apPkCtRh6OewFvqQpDlPeQAAAVU"]
[Sun Aug 30 03:04:26.237641 2026] [security2:error] [pid 488281:tid 488434] [client 20.48.251.3:55551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/groceries/index.php"] [unique_id "apPkCjIT5HeNE73zNfqwpwAAAJw"]
[Sun Aug 30 03:04:26.265460 2026] [security2:error] [pid 488281:tid 488474] [client 20.48.251.3:44284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/png.php"] [unique_id "apPkCjIT5HeNE73zNfqwwQAAAMQ"]
[Sun Aug 30 03:04:26.295975 2026] [security2:error] [pid 488281:tid 488504] [client 114.119.146.230:55251] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "eseperu.com"] [uri "/shop/"] [unique_id "apPkCjIT5HeNE73zNfqw1wAAAOI"], referer: https://eseperu.com/shop/
[Sun Aug 30 03:04:26.309682 2026] [security2:error] [pid 488281:tid 488416] [client 20.220.10.235:21577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/Contrller.php"] [unique_id "apPkCjIT5HeNE73zNfqw3wAAAIo"]
[Sun Aug 30 03:04:26.323171 2026] [security2:error] [pid 488281:tid 488432] [client 20.104.50.220:5906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/w.php"] [unique_id "apPkCjIT5HeNE73zNfqw7QAAAJo"]
[Sun Aug 30 03:04:26.323983 2026] [security2:error] [pid 488281:tid 488437] [client 158.23.147.79:52356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apPkCjIT5HeNE73zNfqw8AAAAJ8"]
[Sun Aug 30 03:04:26.327404 2026] [security2:error] [pid 488281:tid 488496] [client 20.63.81.20:59076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/reop3.php"] [unique_id "apPkCjIT5HeNE73zNfqw9QAAANo"]
[Sun Aug 30 03:04:26.337539 2026] [security2:error] [pid 488281:tid 488443] [client 136.92.30.49:42454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/htdocs/.env"] [unique_id "apPkCjIT5HeNE73zNfqxAAAAAKU"]
[Sun Aug 30 03:04:26.362582 2026] [security2:error] [pid 488281:tid 488504] [client 20.151.200.44:58895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/attack.php"] [unique_id "apPkCjIT5HeNE73zNfqxDwAAAOI"]
[Sun Aug 30 03:04:26.389308 2026] [security2:error] [pid 488669:tid 488840] [client 20.220.204.93:34625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/0x.php"] [unique_id "apPkCtRh6OewFvqQpDlPqAAAASs"]
[Sun Aug 30 03:04:26.389730 2026] [security2:error] [pid 488281:tid 488478] [client 20.104.50.220:46172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/hexor.php"] [unique_id "apPkCjIT5HeNE73zNfqxHQAAAMg"]
[Sun Aug 30 03:04:26.447147 2026] [security2:error] [pid 488669:tid 488850] [client 20.220.10.235:21596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/file66.php"] [unique_id "apPkCtRh6OewFvqQpDlPxQAAATU"]
[Sun Aug 30 03:04:26.462243 2026] [security2:error] [pid 488669:tid 488861] [client 20.63.81.20:58957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp-mail.php"] [unique_id "apPkCtRh6OewFvqQpDlP1AAAAUA"]
[Sun Aug 30 03:04:26.475025 2026] [security2:error] [pid 488281:tid 488517] [client 20.196.209.81:17598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/hideo/network.php"] [unique_id "apPkCjIT5HeNE73zNfqxcQAAAO8"]
[Sun Aug 30 03:04:26.482114 2026] [security2:error] [pid 488281:tid 488525] [client 136.92.30.49:42454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/www/.env"] [unique_id "apPkCjIT5HeNE73zNfqxfQAAAPc"]
[Sun Aug 30 03:04:26.543072 2026] [security2:error] [pid 488281:tid 488452] [client 20.104.18.15:9123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/gigi.php"] [unique_id "apPkCjIT5HeNE73zNfqxsgAAAK4"]
[Sun Aug 30 03:04:26.548838 2026] [security2:error] [pid 488669:tid 488901] [client 158.23.147.79:55100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/goat1.php"] [unique_id "apPkCtRh6OewFvqQpDlQAQAAAWg"]
[Sun Aug 30 03:04:26.549057 2026] [security2:error] [pid 488281:tid 488476] [client 20.104.50.220:63534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-config-style.php"] [unique_id "apPkCjIT5HeNE73zNfqxtwAAAMY"]
[Sun Aug 30 03:04:26.579743 2026] [security2:error] [pid 488281:tid 488422] [client 20.104.50.220:31902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/images/lux.php"] [unique_id "apPkCjIT5HeNE73zNfqxzQAAAJA"]
[Sun Aug 30 03:04:26.586677 2026] [security2:error] [pid 488669:tid 488915] [client 20.220.10.235:21591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/blnux.php"] [unique_id "apPkCtRh6OewFvqQpDlQCgAAAXY"]
[Sun Aug 30 03:04:26.626094 2026] [security2:error] [pid 488281:tid 488517] [client 20.63.81.20:59023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp-conffg.php"] [unique_id "apPkCjIT5HeNE73zNfqx3AAAAO8"]
[Sun Aug 30 03:04:26.629179 2026] [authz_core:error] [pid 488281:tid 488477] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fvar%2Flib%2Fcloud%2Fdata
[Sun Aug 30 03:04:26.629469 2026] [authz_core:error] [pid 488281:tid 488477] [client 74.7.227.8:49200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fvar%2Flib%2Fcloud%2Fdata
[Sun Aug 30 03:04:26.633462 2026] [security2:error] [pid 488281:tid 488486] [client 136.92.30.49:42454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/html/.env"] [unique_id "apPkCjIT5HeNE73zNfqx4AAAANA"]
[Sun Aug 30 03:04:26.645218 2026] [security2:error] [pid 488669:tid 488864] [client 20.151.200.44:58820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/wk/index.php"] [unique_id "apPkCtRh6OewFvqQpDlQFQAAAUM"]
[Sun Aug 30 03:04:26.659564 2026] [security2:error] [pid 488669:tid 488842] [client 20.48.251.3:7393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/api.php"] [unique_id "apPkCtRh6OewFvqQpDlQGQAAAS0"]
[Sun Aug 30 03:04:26.666397 2026] [security2:error] [pid 488669:tid 488848] [client 34.131.221.169:39914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.221.131.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "royal-polymer-com.emetech.com"] [uri "/includes/phpinfo.php"] [unique_id "apPkCtRh6OewFvqQpDlQGwAAATM"]
[Sun Aug 30 03:04:26.683289 2026] [security2:error] [pid 488281:tid 488521] [client 20.104.18.15:31658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/sym.php"] [unique_id "apPkCjIT5HeNE73zNfqx9QAAAPM"]
[Sun Aug 30 03:04:26.685080 2026] [authz_core:error] [pid 488281:tid 488464] [client 66.249.66.72:64703] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:26.685325 2026] [authz_core:error] [pid 488281:tid 488464] [client 66.249.66.72:64703] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:26.705222 2026] [security2:error] [pid 488281:tid 488443] [client 20.48.251.3:64300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/chosen.php"] [unique_id "apPkCjIT5HeNE73zNfqx_AAAAKU"]
[Sun Aug 30 03:04:26.715058 2026] [security2:error] [pid 488281:tid 488421] [client 20.220.10.235:21604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/attack.php"] [unique_id "apPkCjIT5HeNE73zNfqyAAAAAI8"]
[Sun Aug 30 03:04:26.715783 2026] [security2:error] [pid 488281:tid 488490] [client 20.220.204.93:61326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/66.php"] [unique_id "apPkCjIT5HeNE73zNfqyAgAAANQ"]
[Sun Aug 30 03:04:26.746474 2026] [security2:error] [pid 488281:tid 488495] [client 20.104.49.130:48338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trinitytechnologics.com"] [uri "/cilus.php"] [unique_id "apPkCjIT5HeNE73zNfqyCAAAANk"]
[Sun Aug 30 03:04:26.759115 2026] [security2:error] [pid 488281:tid 488493] [client 20.63.81.20:59094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/filefuns.php"] [unique_id "apPkCjIT5HeNE73zNfqyEQAAANc"]
[Sun Aug 30 03:04:26.776568 2026] [security2:error] [pid 488281:tid 488472] [client 136.92.30.49:42454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/live/.env"] [unique_id "apPkCjIT5HeNE73zNfqyGgAAAMI"]
[Sun Aug 30 03:04:26.860776 2026] [security2:error] [pid 488669:tid 488830] [client 20.220.10.235:21607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/wk/index.php"] [unique_id "apPkCtRh6OewFvqQpDlQNwAAASE"]
[Sun Aug 30 03:04:26.865328 2026] [security2:error] [pid 488281:tid 488489] [client 20.196.209.81:11638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/index.php"] [unique_id "apPkCjIT5HeNE73zNfqyOAAAANM"]
[Sun Aug 30 03:04:26.877416 2026] [security2:error] [pid 488669:tid 488920] [client 158.23.147.79:62812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apPkCtRh6OewFvqQpDlQOAAAAXs"]
[Sun Aug 30 03:04:26.887054 2026] [security2:error] [pid 488669:tid 488898] [client 20.63.81.20:59116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp-cron.php"] [unique_id "apPkCtRh6OewFvqQpDlQOgAAAWU"]
[Sun Aug 30 03:04:26.919514 2026] [security2:error] [pid 488281:tid 488484] [client 136.92.30.49:42454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/prod/.env"] [unique_id "apPkCjIT5HeNE73zNfqyTwAAAM4"]
[Sun Aug 30 03:04:26.933152 2026] [security2:error] [pid 488281:tid 488448] [client 20.104.49.130:58215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.katbacon.com"] [uri "/ms-edit.php"] [unique_id "apPkCjIT5HeNE73zNfqyVAAAAKo"]
[Sun Aug 30 03:04:26.948125 2026] [security2:error] [pid 488281:tid 488480] [client 20.104.50.220:33206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-log.php"] [unique_id "apPkCjIT5HeNE73zNfqyWwAAAMo"]
[Sun Aug 30 03:04:26.979338 2026] [security2:error] [pid 488669:tid 488847] [client 20.151.200.44:46983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/log.php"] [unique_id "apPkCtRh6OewFvqQpDlQSwAAATI"]
[Sun Aug 30 03:04:26.991373 2026] [security2:error] [pid 488669:tid 488934] [client 20.220.10.235:21619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/dehnl.php"] [unique_id "apPkCtRh6OewFvqQpDlQTwAAAYk"]
[Sun Aug 30 03:04:27.020715 2026] [security2:error] [pid 488669:tid 488903] [client 20.63.81.20:59108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/lock360.php"] [unique_id "apPkC9Rh6OewFvqQpDlQWwAAAWo"]
[Sun Aug 30 03:04:27.027925 2026] [security2:error] [pid 488669:tid 488873] [client 158.23.147.79:62790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-admin/network/index.php"] [unique_id "apPkC9Rh6OewFvqQpDlQXwAAAUw"]
[Sun Aug 30 03:04:27.035500 2026] [security2:error] [pid 488669:tid 488879] [client 198.235.24.134:53861] ModSecurity: Warning. Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "82"] [id "331030"] [rev "2"] [msg "Atomicorp.com WAF Rules: Suspicious activity detected - HTTP Request Missing a Host Header"] [severity "NOTICE"] [tag "no_ar"] [hostname "gator3166.hostgator.com"] [uri "/"] [unique_id "apPkC9Rh6OewFvqQpDlQZAAAAVI"]
[Sun Aug 30 03:04:27.051242 2026] [security2:error] [pid 488669:tid 488840] [client 20.220.204.93:61332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/f35.php"] [unique_id "apPkC9Rh6OewFvqQpDlQaAAAASs"]
[Sun Aug 30 03:04:27.056778 2026] [authz_core:error] [pid 488669:tid 488905] [client 66.249.66.64:52366] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:27.057079 2026] [authz_core:error] [pid 488669:tid 488905] [client 66.249.66.64:52366] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:27.070507 2026] [security2:error] [pid 488669:tid 488836] [client 20.104.50.220:52813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/indexw.php"] [unique_id "apPkC9Rh6OewFvqQpDlQawAAASc"]
[Sun Aug 30 03:04:27.089406 2026] [security2:error] [pid 488669:tid 488872] [client 68.155.159.216:60592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/admin.php"] [unique_id "apPkC9Rh6OewFvqQpDlQdAAAAUs"]
[Sun Aug 30 03:04:27.106944 2026] [authz_core:error] [pid 488669:tid 488920] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus
[Sun Aug 30 03:04:27.107224 2026] [authz_core:error] [pid 488669:tid 488920] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus
[Sun Aug 30 03:04:27.124268 2026] [security2:error] [pid 488669:tid 488927] [client 158.23.147.79:61445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apPkC9Rh6OewFvqQpDlQhAAAAYI"]
[Sun Aug 30 03:04:27.124336 2026] [security2:error] [pid 488669:tid 488863] [client 20.220.10.235:21594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/png.php"] [unique_id "apPkC9Rh6OewFvqQpDlQhQAAAUI"]
[Sun Aug 30 03:04:27.126599 2026] [security2:error] [pid 488669:tid 488912] [client 20.104.49.130:43161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wondertanks.com"] [uri "/mh.php"] [unique_id "apPkC9Rh6OewFvqQpDlQhgAAAXM"]
[Sun Aug 30 03:04:27.150866 2026] [security2:error] [pid 488669:tid 488825] [client 20.63.81.20:59072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp-theme.php"] [unique_id "apPkC9Rh6OewFvqQpDlQigAAARw"]
[Sun Aug 30 03:04:27.177199 2026] [authz_core:error] [pid 488669:tid 488844] [client 216.73.216.128:34158] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:27.177512 2026] [authz_core:error] [pid 488669:tid 488844] [client 216.73.216.128:34158] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:27.177588 2026] [security2:error] [pid 488669:tid 488858] [client 20.48.251.3:44303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/ammika.php"] [unique_id "apPkC9Rh6OewFvqQpDlQlAAAAT0"]
[Sun Aug 30 03:04:27.212812 2026] [authz_core:error] [pid 488669:tid 488873] [client 66.249.66.69:39700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:27.213734 2026] [authz_core:error] [pid 488669:tid 488873] [client 66.249.66.69:39700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:27.218565 2026] [security2:error] [pid 488669:tid 488813] [client 20.48.251.3:58817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/ws62.php"] [unique_id "apPkC9Rh6OewFvqQpDlQpQAAARA"]
[Sun Aug 30 03:04:27.252622 2026] [security2:error] [pid 488669:tid 488902] [client 20.104.50.220:29873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/boot-fs.php"] [unique_id "apPkC9Rh6OewFvqQpDlQwwAAAWk"]
[Sun Aug 30 03:04:27.256204 2026] [security2:error] [pid 488669:tid 488853] [client 20.196.209.81:6082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/intense/block-css.php"] [unique_id "apPkC9Rh6OewFvqQpDlQxQAAATg"]
[Sun Aug 30 03:04:27.259372 2026] [security2:error] [pid 488669:tid 488875] [client 20.48.251.3:29719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lastmaskcenter.org"] [uri "/aws_keys.php"] [unique_id "apPkC9Rh6OewFvqQpDlQxgAAAU4"]
[Sun Aug 30 03:04:27.266294 2026] [security2:error] [pid 488669:tid 488858] [client 20.220.10.235:21606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/txets.php"] [unique_id "apPkC9Rh6OewFvqQpDlQzQAAAT0"]
[Sun Aug 30 03:04:27.279826 2026] [security2:error] [pid 488669:tid 488813] [client 20.63.81.20:59073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/2d7433/index.php"] [unique_id "apPkC9Rh6OewFvqQpDlQ1AAAARA"]
[Sun Aug 30 03:04:27.322206 2026] [security2:error] [pid 488669:tid 488814] [client 68.155.159.216:60006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-admin/about.php"] [unique_id "apPkC9Rh6OewFvqQpDlQ9QAAARE"]
[Sun Aug 30 03:04:27.325473 2026] [security2:error] [pid 488669:tid 488914] [client 20.48.251.3:59270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/fucku.php"] [unique_id "apPkC9Rh6OewFvqQpDlQ-AAAAXU"]
[Sun Aug 30 03:04:27.326425 2026] [security2:error] [pid 488669:tid 488875] [client 20.104.50.220:61431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/XiXi.php"] [unique_id "apPkC9Rh6OewFvqQpDlQ-QAAAU4"]
[Sun Aug 30 03:04:27.327127 2026] [security2:error] [pid 488669:tid 488915] [client 20.104.49.130:59544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.infinitelearners.com"] [uri "/cilus.php"] [unique_id "apPkC9Rh6OewFvqQpDlQ-gAAAXY"]
[Sun Aug 30 03:04:27.330849 2026] [security2:error] [pid 488669:tid 488898] [client 158.23.147.79:55186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/.well-knownold/index.php"] [unique_id "apPkC9Rh6OewFvqQpDlQ_gAAAWU"]
[Sun Aug 30 03:04:27.335111 2026] [security2:error] [pid 488669:tid 488934] [client 20.48.251.3:64414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/thui.php"] [unique_id "apPkC9Rh6OewFvqQpDlRAgAAAYk"]
[Sun Aug 30 03:04:27.355846 2026] [security2:error] [pid 488669:tid 488827] [client 20.104.50.220:52838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-content/mek.php"] [unique_id "apPkC9Rh6OewFvqQpDlRCAAAAR4"]
[Sun Aug 30 03:04:27.364911 2026] [authz_core:error] [pid 488669:tid 488851] [client 216.73.216.128:15072] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:27.365319 2026] [authz_core:error] [pid 488669:tid 488851] [client 216.73.216.128:15072] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:27.375979 2026] [security2:error] [pid 488669:tid 488887] [client 20.220.10.235:49605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkC9Rh6OewFvqQpDlRCwAAAVo"]
[Sun Aug 30 03:04:27.379285 2026] [security2:error] [pid 488669:tid 488903] [client 20.48.251.3:55476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/konfig.php"] [unique_id "apPkC9Rh6OewFvqQpDlRDAAAAWo"]
[Sun Aug 30 03:04:27.388841 2026] [security2:error] [pid 488669:tid 488917] [client 20.220.204.93:32685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/wen.php"] [unique_id "apPkC9Rh6OewFvqQpDlRFgAAAXg"]
[Sun Aug 30 03:04:27.392495 2026] [security2:error] [pid 488669:tid 488907] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/staging/.env"] [unique_id "apPkC9Rh6OewFvqQpDlRGQAAAW4"]
[Sun Aug 30 03:04:27.396734 2026] [security2:error] [pid 488669:tid 488843] [client 20.220.10.235:21761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/wp-login.php"] [unique_id "apPkC9Rh6OewFvqQpDlRHwAAAS4"]
[Sun Aug 30 03:04:27.401052 2026] [security2:error] [pid 488669:tid 488830] [client 20.48.251.3:23440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/chosen.php"] [unique_id "apPkC9Rh6OewFvqQpDlRJgAAASE"]
[Sun Aug 30 03:04:27.408652 2026] [security2:error] [pid 488669:tid 488877] [client 20.63.81.20:59083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp-login.php"] [unique_id "apPkC9Rh6OewFvqQpDlRJwAAAVA"]
[Sun Aug 30 03:04:27.448511 2026] [security2:error] [pid 488669:tid 488828] [client 161.118.226.254:61399] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "myediblecravings.com"] [uri "/"] [unique_id "apPkC9Rh6OewFvqQpDlRTQAAAR8"]
[Sun Aug 30 03:04:27.460525 2026] [security2:error] [pid 488669:tid 488908] [client 20.104.50.220:5555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/404.php"] [unique_id "apPkC9Rh6OewFvqQpDlRWwAAAW8"]
[Sun Aug 30 03:04:27.510994 2026] [security2:error] [pid 488669:tid 488828] [client 20.220.10.235:49655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkC9Rh6OewFvqQpDlRhAAAAR8"]
[Sun Aug 30 03:04:27.525915 2026] [security2:error] [pid 488669:tid 488870] [client 20.220.10.235:21775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/wp-access.php"] [unique_id "apPkC9Rh6OewFvqQpDlRjQAAAUk"]
[Sun Aug 30 03:04:27.535521 2026] [security2:error] [pid 488669:tid 488819] [client 20.63.81.20:59026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/images.php"] [unique_id "apPkC9Rh6OewFvqQpDlRjwAAARY"]
[Sun Aug 30 03:04:27.536745 2026] [security2:error] [pid 488669:tid 488820] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/opt/.env"] [unique_id "apPkC9Rh6OewFvqQpDlRkgAAARc"]
[Sun Aug 30 03:04:27.558533 2026] [security2:error] [pid 488669:tid 488830] [client 20.104.50.220:46186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/leaf.php"] [unique_id "apPkC9Rh6OewFvqQpDlRogAAASE"]
[Sun Aug 30 03:04:27.564970 2026] [authz_core:error] [pid 488669:tid 488867] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus
[Sun Aug 30 03:04:27.565248 2026] [authz_core:error] [pid 488669:tid 488867] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus
[Sun Aug 30 03:04:27.587467 2026] [security2:error] [pid 488669:tid 488824] [client 20.104.49.130:64911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.topatrust.com"] [uri "/ioxi-o.php"] [unique_id "apPkC9Rh6OewFvqQpDlRrwAAARs"]
[Sun Aug 30 03:04:27.637699 2026] [security2:error] [pid 488669:tid 488869] [client 20.104.49.130:48370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trinitytechnologics.com"] [uri "/ws78.php"] [unique_id "apPkC9Rh6OewFvqQpDlRuQAAAUg"]
[Sun Aug 30 03:04:27.641042 2026] [security2:error] [pid 488669:tid 488917] [client 20.220.10.235:49629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/h02ugyh.php"] [unique_id "apPkC9Rh6OewFvqQpDlRugAAAXg"]
[Sun Aug 30 03:04:27.645146 2026] [security2:error] [pid 488669:tid 488872] [client 20.196.209.81:23618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/login.php"] [unique_id "apPkC9Rh6OewFvqQpDlRvQAAAUs"]
[Sun Aug 30 03:04:27.655076 2026] [security2:error] [pid 488669:tid 488880] [client 20.220.10.235:21585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/wp-content/admin.php"] [unique_id "apPkC9Rh6OewFvqQpDlRwQAAAVM"]
[Sun Aug 30 03:04:27.666732 2026] [security2:error] [pid 488669:tid 488843] [client 20.48.251.3:7051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/lala.php"] [unique_id "apPkC9Rh6OewFvqQpDlRxQAAAS4"]
[Sun Aug 30 03:04:27.668900 2026] [security2:error] [pid 488669:tid 488855] [client 20.63.81.20:59080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/ops.php"] [unique_id "apPkC9Rh6OewFvqQpDlRxwAAATo"]
[Sun Aug 30 03:04:27.679597 2026] [security2:error] [pid 488669:tid 488923] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/laravel/.env"] [unique_id "apPkC9Rh6OewFvqQpDlRywAAAX4"]
[Sun Aug 30 03:04:27.685995 2026] [security2:error] [pid 488669:tid 488930] [client 20.104.18.15:9211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/info.php/new.php"] [unique_id "apPkC9Rh6OewFvqQpDlRzAAAAYU"]
[Sun Aug 30 03:04:27.717848 2026] [security2:error] [pid 488669:tid 488822] [client 158.23.147.79:62806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apPkC9Rh6OewFvqQpDlR0wAAARk"]
[Sun Aug 30 03:04:27.718379 2026] [security2:error] [pid 488669:tid 488912] [client 20.104.50.220:32536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/w3llstore.php"] [unique_id "apPkC9Rh6OewFvqQpDlR1AAAAXM"]
[Sun Aug 30 03:04:27.766140 2026] [authz_core:error] [pid 488669:tid 488813] [client 66.249.66.76:50834] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:27.766443 2026] [authz_core:error] [pid 488669:tid 488813] [client 66.249.66.76:50834] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:27.778556 2026] [security2:error] [pid 488669:tid 488899] [client 20.220.10.235:49106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/sf.php"] [unique_id "apPkC9Rh6OewFvqQpDlR6gAAAWY"]
[Sun Aug 30 03:04:27.782698 2026] [security2:error] [pid 488669:tid 488901] [client 20.220.10.235:21822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/log.php"] [unique_id "apPkC9Rh6OewFvqQpDlR6wAAAWg"]
[Sun Aug 30 03:04:27.790099 2026] [security2:error] [pid 488669:tid 488863] [client 20.220.204.93:5023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/inc.php"] [unique_id "apPkC9Rh6OewFvqQpDlR7wAAAUI"]
[Sun Aug 30 03:04:27.798330 2026] [security2:error] [pid 488669:tid 488844] [client 20.63.81.20:59020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPkC9Rh6OewFvqQpDlR8AAAAS8"]
[Sun Aug 30 03:04:27.811984 2026] [security2:error] [pid 488669:tid 488914] [client 20.104.18.15:31490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/8.php"] [unique_id "apPkC9Rh6OewFvqQpDlR9QAAAXU"]
[Sun Aug 30 03:04:27.819413 2026] [security2:error] [pid 488669:tid 488815] [client 20.48.251.3:6524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/temp.php"] [unique_id "apPkC9Rh6OewFvqQpDlR-AAAARI"]
[Sun Aug 30 03:04:27.825829 2026] [security2:error] [pid 488669:tid 488917] [client 161.118.226.254:61974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "myediblecravings.com"] [uri "/"] [unique_id "apPkC9Rh6OewFvqQpDlR_AAAAXg"]
[Sun Aug 30 03:04:27.825991 2026] [security2:error] [pid 488669:tid 488869] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/symfony/.env"] [unique_id "apPkC9Rh6OewFvqQpDlR-gAAAUg"]
[Sun Aug 30 03:04:27.834704 2026] [security2:error] [pid 488669:tid 488828] [client 20.151.200.44:58931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/dehnl.php"] [unique_id "apPkC9Rh6OewFvqQpDlR_wAAAR8"]
[Sun Aug 30 03:04:27.857763 2026] [security2:error] [pid 488669:tid 488809] [client 20.48.251.3:46224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/admin-ajax.php"] [unique_id "apPkC9Rh6OewFvqQpDlSAwAAAQw"]
[Sun Aug 30 03:04:27.863370 2026] [security2:error] [pid 488669:tid 488882] [client 158.23.147.79:55231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPkC9Rh6OewFvqQpDlSBQAAAVU"]
[Sun Aug 30 03:04:27.885140 2026] [security2:error] [pid 488669:tid 488930] [client 20.104.50.220:51539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-logo.php"] [unique_id "apPkC9Rh6OewFvqQpDlSBwAAAYU"]
[Sun Aug 30 03:04:27.909055 2026] [security2:error] [pid 488669:tid 488857] [client 20.220.10.235:21620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/xwpg.php"] [unique_id "apPkC9Rh6OewFvqQpDlSDQAAATw"]
[Sun Aug 30 03:04:27.917610 2026] [security2:error] [pid 488669:tid 488896] [client 20.220.10.235:49635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/4e.php"] [unique_id "apPkC9Rh6OewFvqQpDlSEAAAAWM"]
[Sun Aug 30 03:04:27.930186 2026] [security2:error] [pid 488669:tid 488890] [client 20.63.81.20:59040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPkC9Rh6OewFvqQpDlSFAAAAV0"]
[Sun Aug 30 03:04:27.956063 2026] [authz_core:error] [pid 488669:tid 488840] [client 216.73.216.128:34158] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:27.956346 2026] [authz_core:error] [pid 488669:tid 488840] [client 216.73.216.128:34158] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:27.970682 2026] [security2:error] [pid 488669:tid 488816] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/wordpress/.env"] [unique_id "apPkC9Rh6OewFvqQpDlSHQAAARM"]
[Sun Aug 30 03:04:28.041053 2026] [security2:error] [pid 488669:tid 488850] [client 20.220.10.235:21613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/sxxb.php"] [unique_id "apPkDNRh6OewFvqQpDlSMwAAATU"]
[Sun Aug 30 03:04:28.048506 2026] [security2:error] [pid 488669:tid 488865] [client 20.220.10.235:49657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/ssss.php"] [unique_id "apPkDNRh6OewFvqQpDlSNgAAAUQ"]
[Sun Aug 30 03:04:28.061900 2026] [security2:error] [pid 488669:tid 488839] [client 20.63.81.20:59129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/about.php"] [unique_id "apPkDNRh6OewFvqQpDlSOwAAASo"]
[Sun Aug 30 03:04:28.070756 2026] [security2:error] [pid 488669:tid 488918] [client 20.196.209.81:23651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/min.php"] [unique_id "apPkDNRh6OewFvqQpDlSPwAAAXk"]
[Sun Aug 30 03:04:28.095434 2026] [security2:error] [pid 488669:tid 488882] [client 34.16.144.252:14634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/terraform.tfstate.backup"] [unique_id "apPkDNRh6OewFvqQpDlSSwAAAVU"]
[Sun Aug 30 03:04:28.097595 2026] [security2:error] [pid 488669:tid 488854] [client 34.16.144.252:14640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/backup.sql"] [unique_id "apPkDNRh6OewFvqQpDlSTQAAATk"]
[Sun Aug 30 03:04:28.098517 2026] [security2:error] [pid 488669:tid 488930] [client 34.16.144.252:14612] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.alchemancer.com"] [uri "/k8s/secrets.yaml"] [unique_id "apPkDNRh6OewFvqQpDlSUAAAAYU"]
[Sun Aug 30 03:04:28.101150 2026] [security2:error] [pid 488669:tid 488908] [client 34.16.144.252:14646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/dump.sql"] [unique_id "apPkDNRh6OewFvqQpDlSUgAAAW8"]
[Sun Aug 30 03:04:28.105942 2026] [security2:error] [pid 488669:tid 488822] [client 34.16.144.252:14668] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.alchemancer.com"] [uri "/static../.env"] [unique_id "apPkDNRh6OewFvqQpDlSVwAAARk"]
[Sun Aug 30 03:04:28.106629 2026] [security2:error] [pid 488669:tid 488821] [client 34.16.144.252:14700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/files../.env"] [unique_id "apPkDNRh6OewFvqQpDlSWAAAARg"]
[Sun Aug 30 03:04:28.107618 2026] [security2:error] [pid 488669:tid 488933] [client 34.16.144.252:14716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/media../.env"] [unique_id "apPkDNRh6OewFvqQpDlSWQAAAYg"]
[Sun Aug 30 03:04:28.108989 2026] [core:error] [pid 488669:tid 488896] [client 34.16.144.252:14724] AH10244: invalid URI path (/assets../../../.env)
[Sun Aug 30 03:04:28.110522 2026] [security2:error] [pid 488669:tid 488808] [client 34.16.144.252:14640] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.alchemancer.com"] [uri "/proc/self/environ"] [unique_id "apPkDNRh6OewFvqQpDlSXQAAAQs"]
[Sun Aug 30 03:04:28.113617 2026] [security2:error] [pid 488669:tid 488889] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/wp/.env"] [unique_id "apPkDNRh6OewFvqQpDlSYAAAAVw"]
[Sun Aug 30 03:04:28.118781 2026] [authz_core:error] [pid 488669:tid 488919] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fvar%2Flib%2Fpcp%2Fconfig%2Fderived
[Sun Aug 30 03:04:28.119036 2026] [authz_core:error] [pid 488669:tid 488919] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fvar%2Flib%2Fpcp%2Fconfig%2Fderived
[Sun Aug 30 03:04:28.122861 2026] [security2:error] [pid 488669:tid 488871] [client 34.16.144.252:14716] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.alchemancer.com"] [uri "/proc/self/environ"] [unique_id "apPkDNRh6OewFvqQpDlSYwAAAUo"]
[Sun Aug 30 03:04:28.135887 2026] [security2:error] [pid 488669:tid 488898] [client 34.16.144.252:14572] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.alchemancer.com"] [uri "/proc/self/environ"] [unique_id "apPkDNRh6OewFvqQpDlSZgAAAWU"]
[Sun Aug 30 03:04:28.149631 2026] [security2:error] [pid 488669:tid 488925] [client 34.16.144.252:14598] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.alchemancer.com"] [uri "/proc/self/environ"] [unique_id "apPkDNRh6OewFvqQpDlSbAAAAYA"]
[Sun Aug 30 03:04:28.161535 2026] [security2:error] [pid 488669:tid 488863] [client 20.220.204.93:11193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/6bcwiqwj.php"] [unique_id "apPkDNRh6OewFvqQpDlSbgAAAUI"]
[Sun Aug 30 03:04:28.164285 2026] [security2:error] [pid 488669:tid 488831] [client 34.16.144.252:14618] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.alchemancer.com"] [uri "/proc/self/environ"] [unique_id "apPkDNRh6OewFvqQpDlScAAAASI"]
[Sun Aug 30 03:04:28.176343 2026] [security2:error] [pid 488669:tid 488838] [client 20.220.10.235:49100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/zoz.php"] [unique_id "apPkDNRh6OewFvqQpDlSdgAAASk"]
[Sun Aug 30 03:04:28.178515 2026] [security2:error] [pid 488669:tid 488874] [client 34.16.144.252:14654] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.alchemancer.com"] [uri "/proc/self/environ"] [unique_id "apPkDNRh6OewFvqQpDlSeAAAAU0"]
[Sun Aug 30 03:04:28.187302 2026] [security2:error] [pid 488669:tid 488828] [client 158.23.147.79:55214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/images/index.php"] [unique_id "apPkDNRh6OewFvqQpDlSgQAAAR8"]
[Sun Aug 30 03:04:28.191308 2026] [security2:error] [pid 488669:tid 488904] [client 34.16.144.252:14660] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.alchemancer.com"] [uri "/proc/self/environ"] [unique_id "apPkDNRh6OewFvqQpDlShQAAAWs"]
[Sun Aug 30 03:04:28.203722 2026] [security2:error] [pid 488669:tid 488897] [client 34.16.144.252:14634] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.alchemancer.com"] [uri "/proc/self/environ"] [unique_id "apPkDNRh6OewFvqQpDlSiwAAAWQ"]
[Sun Aug 30 03:04:28.210661 2026] [security2:error] [pid 488669:tid 488860] [client 20.63.81.20:58956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/admin.php/admin.php"] [unique_id "apPkDNRh6OewFvqQpDlSjQAAAT8"]
[Sun Aug 30 03:04:28.216319 2026] [security2:error] [pid 488669:tid 488826] [client 34.16.144.252:14700] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.alchemancer.com"] [uri "/proc/self/environ"] [unique_id "apPkDNRh6OewFvqQpDlSkwAAAR0"]
[Sun Aug 30 03:04:28.221541 2026] [security2:error] [pid 488669:tid 488822] [client 20.104.50.220:29589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/.284214373991941.php"] [unique_id "apPkDNRh6OewFvqQpDlSlwAAARk"]
[Sun Aug 30 03:04:28.228573 2026] [security2:error] [pid 488669:tid 488884] [client 34.16.144.252:14582] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.alchemancer.com"] [uri "/proc/self/environ"] [unique_id "apPkDNRh6OewFvqQpDlSmwAAAVc"]
[Sun Aug 30 03:04:28.232069 2026] [security2:error] [pid 488669:tid 488891] [client 68.155.159.216:60551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-admin/admin.php"] [unique_id "apPkDNRh6OewFvqQpDlSoAAAAV4"]
[Sun Aug 30 03:04:28.232888 2026] [security2:error] [pid 488669:tid 488841] [client 20.220.10.235:21631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/dx.php"] [unique_id "apPkDNRh6OewFvqQpDlSowAAASw"]
[Sun Aug 30 03:04:28.242053 2026] [security2:error] [pid 488669:tid 488835] [client 34.16.144.252:14646] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.alchemancer.com"] [uri "/proc/self/environ"] [unique_id "apPkDNRh6OewFvqQpDlSqgAAASY"]
[Sun Aug 30 03:04:28.254265 2026] [security2:error] [pid 488669:tid 488896] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/bgymj.php"] [unique_id "apPkDNRh6OewFvqQpDlSsAAAAWM"]
[Sun Aug 30 03:04:28.257011 2026] [security2:error] [pid 488669:tid 488902] [client 34.16.144.252:14740] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.alchemancer.com"] [uri "/proc/self/environ"] [unique_id "apPkDNRh6OewFvqQpDlSsgAAAWk"]
[Sun Aug 30 03:04:28.258110 2026] [security2:error] [pid 488669:tid 488876] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/cms/.env"] [unique_id "apPkDNRh6OewFvqQpDlSsQAAAU8"]
[Sun Aug 30 03:04:28.272088 2026] [security2:error] [pid 488669:tid 488867] [client 34.16.144.252:14684] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.alchemancer.com"] [uri "/proc/self/environ"] [unique_id "apPkDNRh6OewFvqQpDlSugAAAUY"]
[Sun Aug 30 03:04:28.306414 2026] [security2:error] [pid 488669:tid 488849] [client 20.220.10.235:49641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/kcs.php"] [unique_id "apPkDNRh6OewFvqQpDlS0QAAATQ"]
[Sun Aug 30 03:04:28.311097 2026] [security2:error] [pid 488669:tid 488814] [client 34.16.144.252:14742] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpcontacts.alchemancer.com"] [uri "/proc/self/environ"] [unique_id "apPkDNRh6OewFvqQpDlS1QAAARE"]
[Sun Aug 30 03:04:28.323299 2026] [authz_core:error] [pid 488669:tid 488908] [client 216.73.216.128:34158] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:28.323574 2026] [authz_core:error] [pid 488669:tid 488908] [client 216.73.216.128:34158] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:28.350164 2026] [security2:error] [pid 488669:tid 488838] [client 20.63.81.20:58948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/media.php"] [unique_id "apPkDNRh6OewFvqQpDlS7QAAASk"]
[Sun Aug 30 03:04:28.360764 2026] [security2:error] [pid 488669:tid 488824] [client 20.220.10.235:21597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPkDNRh6OewFvqQpDlS8QAAARs"]
[Sun Aug 30 03:04:28.367632 2026] [security2:error] [pid 488669:tid 488850] [client 20.48.251.3:34583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/grsiuk.php"] [unique_id "apPkDNRh6OewFvqQpDlS9AAAATU"]
[Sun Aug 30 03:04:28.376415 2026] [security2:error] [pid 488669:tid 488871] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/bk/index.php"] [unique_id "apPkDNRh6OewFvqQpDlS9QAAAUo"]
[Sun Aug 30 03:04:28.396811 2026] [authz_core:error] [pid 488669:tid 488870] [client 66.249.66.69:60351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:28.397192 2026] [authz_core:error] [pid 488669:tid 488870] [client 66.249.66.69:60351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:28.402219 2026] [security2:error] [pid 488669:tid 488819] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/drupal/.env"] [unique_id "apPkDNRh6OewFvqQpDlTDAAAARY"]
[Sun Aug 30 03:04:28.402585 2026] [security2:error] [pid 488669:tid 488855] [client 20.104.50.220:30285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/taxonomy.php"] [unique_id "apPkDNRh6OewFvqQpDlTDgAAATo"]
[Sun Aug 30 03:04:28.410818 2026] [security2:error] [pid 488669:tid 488890] [client 20.48.251.3:64736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lastmaskcenter.org"] [uri "/umgebung.php"] [unique_id "apPkDNRh6OewFvqQpDlTFAAAAV0"]
[Sun Aug 30 03:04:28.433761 2026] [security2:error] [pid 488669:tid 488811] [client 20.220.10.235:49620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/tajj.php"] [unique_id "apPkDNRh6OewFvqQpDlTKAAAAQ4"]
[Sun Aug 30 03:04:28.462815 2026] [security2:error] [pid 488669:tid 488912] [client 68.155.159.216:60021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apPkDNRh6OewFvqQpDlTRgAAAXM"]
[Sun Aug 30 03:04:28.466754 2026] [security2:error] [pid 488669:tid 488906] [client 20.48.251.3:55761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/error_log.php"] [unique_id "apPkDNRh6OewFvqQpDlTSgAAAW0"]
[Sun Aug 30 03:04:28.467954 2026] [security2:error] [pid 488669:tid 488925] [client 20.196.209.81:23668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/module.php"] [unique_id "apPkDNRh6OewFvqQpDlTTAAAAYA"]
[Sun Aug 30 03:04:28.476387 2026] [security2:error] [pid 488669:tid 488873] [client 20.104.50.220:61412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/.piongroup.php"] [unique_id "apPkDNRh6OewFvqQpDlTVgAAAUw"]
[Sun Aug 30 03:04:28.488792 2026] [security2:error] [pid 488669:tid 488900] [client 20.63.81.20:59034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/mac.php"] [unique_id "apPkDNRh6OewFvqQpDlTYQAAAWc"]
[Sun Aug 30 03:04:28.495182 2026] [security2:error] [pid 488669:tid 488858] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/bootstrap.php"] [unique_id "apPkDNRh6OewFvqQpDlTaQAAAT0"]
[Sun Aug 30 03:04:28.499098 2026] [security2:error] [pid 488669:tid 488844] [client 20.220.10.235:21783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/xda.php"] [unique_id "apPkDNRh6OewFvqQpDlTbgAAAS8"]
[Sun Aug 30 03:04:28.502256 2026] [security2:error] [pid 488669:tid 488904] [client 20.220.204.93:10505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/easy.php"] [unique_id "apPkDNRh6OewFvqQpDlTcQAAAWs"]
[Sun Aug 30 03:04:28.503761 2026] [security2:error] [pid 488669:tid 488831] [client 20.48.251.3:4700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/broadcasting.php"] [unique_id "apPkDNRh6OewFvqQpDlTcgAAASI"]
[Sun Aug 30 03:04:28.520335 2026] [security2:error] [pid 488669:tid 488887] [client 20.48.251.3:55461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/paths.php"] [unique_id "apPkDNRh6OewFvqQpDlTegAAAVo"]
[Sun Aug 30 03:04:28.538975 2026] [security2:error] [pid 488669:tid 488890] [client 20.48.251.3:44273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/admin-ajax.php"] [unique_id "apPkDNRh6OewFvqQpDlThgAAAV0"]
[Sun Aug 30 03:04:28.545736 2026] [security2:error] [pid 488669:tid 488845] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/joomla/.env"] [unique_id "apPkDNRh6OewFvqQpDlTiQAAATA"]
[Sun Aug 30 03:04:28.572823 2026] [security2:error] [pid 488669:tid 488830] [client 20.220.10.235:49641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/bge.php"] [unique_id "apPkDNRh6OewFvqQpDlTlwAAASE"]
[Sun Aug 30 03:04:28.576388 2026] [security2:error] [pid 488669:tid 488914] [client 20.104.49.130:57600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/wsd.php"] [unique_id "apPkDNRh6OewFvqQpDlTmQAAAXU"]
[Sun Aug 30 03:04:28.576959 2026] [security2:error] [pid 488669:tid 488902] [client 20.104.50.220:28703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/bypass.php"] [unique_id "apPkDNRh6OewFvqQpDlTmgAAAWk"]
[Sun Aug 30 03:04:28.586537 2026] [authz_core:error] [pid 488669:tid 488930] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fvar%2Flib%2Fpcp%2Fconfig%2Fderived
[Sun Aug 30 03:04:28.586998 2026] [authz_core:error] [pid 488669:tid 488930] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fvar%2Flib%2Fpcp%2Fconfig%2Fderived
[Sun Aug 30 03:04:28.590771 2026] [security2:error] [pid 488669:tid 488893] [client 158.23.147.79:55229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apPkDNRh6OewFvqQpDlTnwAAAWA"]
[Sun Aug 30 03:04:28.623156 2026] [security2:error] [pid 488669:tid 488852] [client 20.63.81.20:59119] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.auscreen.com.au"] [uri "/1.php"] [unique_id "apPkDNRh6OewFvqQpDlTqwAAATc"]
[Sun Aug 30 03:04:28.623248 2026] [security2:error] [pid 488669:tid 488835] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/bs1.php"] [unique_id "apPkDNRh6OewFvqQpDlTqgAAASY"]
[Sun Aug 30 03:04:28.623262 2026] [security2:error] [pid 488669:tid 488852] [client 20.63.81.20:59119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/1.php"] [unique_id "apPkDNRh6OewFvqQpDlTqwAAATc"]
[Sun Aug 30 03:04:28.626776 2026] [security2:error] [pid 488669:tid 488876] [client 20.104.50.220:5554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/ioxi-o.php"] [unique_id "apPkDNRh6OewFvqQpDlTrgAAAU8"]
[Sun Aug 30 03:04:28.630020 2026] [authz_core:error] [pid 488669:tid 488920] [client 66.249.66.72:56674] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:28.630050 2026] [security2:error] [pid 488669:tid 488883] [client 20.220.10.235:21772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/wp-admin/js/index.php"] [unique_id "apPkDNRh6OewFvqQpDlTsAAAAVY"]
[Sun Aug 30 03:04:28.630303 2026] [authz_core:error] [pid 488669:tid 488920] [client 66.249.66.72:56674] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:28.640065 2026] [security2:error] [pid 488669:tid 488839] [client 20.220.204.93:49199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/fresh3.php"] [unique_id "apPkDNRh6OewFvqQpDlTswAAASo"]
[Sun Aug 30 03:04:28.657765 2026] [security2:error] [pid 488669:tid 488897] [client 20.197.61.180:4077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/data.php"] [unique_id "apPkDNRh6OewFvqQpDlTvAAAAWQ"]
[Sun Aug 30 03:04:28.689723 2026] [security2:error] [pid 488669:tid 488932] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/magento/.env"] [unique_id "apPkDNRh6OewFvqQpDlTwQAAAYc"]
[Sun Aug 30 03:04:28.704772 2026] [security2:error] [pid 488669:tid 488933] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/bthil.php"] [unique_id "apPkDNRh6OewFvqQpDlTxAAAAYg"]
[Sun Aug 30 03:04:28.705400 2026] [security2:error] [pid 488669:tid 488817] [client 20.220.10.235:49616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/ssh3ll.php"] [unique_id "apPkDNRh6OewFvqQpDlTxQAAARQ"]
[Sun Aug 30 03:04:28.717329 2026] [security2:error] [pid 488669:tid 488899] [client 20.104.50.220:46630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/FoxWSOv1.php"] [unique_id "apPkDNRh6OewFvqQpDlT0gAAAWY"]
[Sun Aug 30 03:04:28.719754 2026] [security2:error] [pid 488669:tid 488877] [client 20.151.200.44:47002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/xwpg.php"] [unique_id "apPkDNRh6OewFvqQpDlT0wAAAVA"]
[Sun Aug 30 03:04:28.735114 2026] [security2:error] [pid 488669:tid 488793] [remote 74.7.242.63:51114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.ltr7.com"] [uri "/xml/3D\\"https:/www.law360.com/media/articles/images/tile.jpg"] [unique_id "apPkDNRh6OewFvqQpDlT2wABH3M"], referer: https://mail.ltr7.com/xml/3D%22https:/www.law360.com/media/articles/images/tile.jpg?p=%2F%2Fetc
[Sun Aug 30 03:04:28.749170 2026] [security2:error] [pid 488669:tid 488927] [client 158.23.147.79:61482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apPkDNRh6OewFvqQpDlT4AAAAYI"]
[Sun Aug 30 03:04:28.751137 2026] [security2:error] [pid 488669:tid 488898] [client 20.63.81.20:59118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/classwithtostring.php"] [unique_id "apPkDNRh6OewFvqQpDlT4gAAAWU"]
[Sun Aug 30 03:04:28.754180 2026] [security2:error] [pid 488669:tid 488831] [client 34.16.144.252:60798] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpcalendars.ilfcllc.net"] [uri "/@fs/app/serverless.yml"] [unique_id "apPkDNRh6OewFvqQpDlT5AAAASI"]
[Sun Aug 30 03:04:28.762854 2026] [security2:error] [pid 488669:tid 488835] [client 34.16.144.252:60732] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.ilfcllc.net"] [uri "/@fs/app/aws-exports.js"] [unique_id "apPkDNRh6OewFvqQpDlT6AAAASY"]
[Sun Aug 30 03:04:28.763022 2026] [security2:error] [pid 488669:tid 488852] [client 20.220.10.235:21587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/t00l.php"] [unique_id "apPkDNRh6OewFvqQpDlT5wAAATc"]
[Sun Aug 30 03:04:28.773956 2026] [security2:error] [pid 488669:tid 488812] [client 20.48.251.3:64463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/public/bnn_.php.php"] [unique_id "apPkDNRh6OewFvqQpDlT7gAAAQ8"]
[Sun Aug 30 03:04:28.808773 2026] [security2:error] [pid 488669:tid 488890] [client 20.220.10.235:33673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkDNRh6OewFvqQpDlT-gAAAV0"]
[Sun Aug 30 03:04:28.823611 2026] [security2:error] [pid 488669:tid 488861] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/buy.php"] [unique_id "apPkDNRh6OewFvqQpDlT_wAAAUA"]
[Sun Aug 30 03:04:28.832577 2026] [security2:error] [pid 488669:tid 488829] [client 20.220.10.235:49610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/motu.php"] [unique_id "apPkDNRh6OewFvqQpDlUAwAAASA"]
[Sun Aug 30 03:04:28.838041 2026] [security2:error] [pid 488669:tid 488836] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/shopify/.env"] [unique_id "apPkDNRh6OewFvqQpDlUBQAAASc"]
[Sun Aug 30 03:04:28.858854 2026] [security2:error] [pid 488669:tid 488830] [client 20.196.209.81:23616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/ms-files.php"] [unique_id "apPkDNRh6OewFvqQpDlUCQAAASE"]
[Sun Aug 30 03:04:28.862930 2026] [security2:error] [pid 488669:tid 488893] [client 20.104.50.220:31858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/alfi.php"] [unique_id "apPkDNRh6OewFvqQpDlUCwAAAWA"]
[Sun Aug 30 03:04:28.879080 2026] [security2:error] [pid 488669:tid 488828] [client 20.63.81.20:58889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp-ws68.php"] [unique_id "apPkDNRh6OewFvqQpDlUDAAAAR8"]
[Sun Aug 30 03:04:28.900340 2026] [security2:error] [pid 488669:tid 488908] [client 20.104.18.15:9080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/w.php"] [unique_id "apPkDNRh6OewFvqQpDlUDwAAAW8"]
[Sun Aug 30 03:04:28.900685 2026] [security2:error] [pid 488669:tid 488906] [client 20.197.61.180:4089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/dt-the7/css/static-less/plugins/admin.php"] [unique_id "apPkDNRh6OewFvqQpDlUEAAAAW0"]
[Sun Aug 30 03:04:28.904269 2026] [security2:error] [pid 488669:tid 488847] [client 20.220.10.235:21769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/ls.php"] [unique_id "apPkDNRh6OewFvqQpDlUEgAAATI"]
[Sun Aug 30 03:04:28.946992 2026] [security2:error] [pid 488669:tid 488901] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/byp.php"] [unique_id "apPkDNRh6OewFvqQpDlUGgAAAWg"]
[Sun Aug 30 03:04:28.947211 2026] [security2:error] [pid 488669:tid 488852] [client 20.220.10.235:33681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkDNRh6OewFvqQpDlUGQAAATc"]
[Sun Aug 30 03:04:28.951274 2026] [security2:error] [pid 488669:tid 488849] [client 20.104.18.15:31668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/goods.php"] [unique_id "apPkDNRh6OewFvqQpDlUHQAAATQ"]
[Sun Aug 30 03:04:28.966889 2026] [security2:error] [pid 488669:tid 488850] [client 20.220.10.235:49096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/wefile.php"] [unique_id "apPkDNRh6OewFvqQpDlUJAAAATU"]
[Sun Aug 30 03:04:28.969035 2026] [authz_core:error] [pid 488669:tid 488808] [client 66.249.66.64:52366] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:28.969296 2026] [authz_core:error] [pid 488669:tid 488808] [client 66.249.66.64:52366] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:28.981178 2026] [security2:error] [pid 488669:tid 488892] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/prestashop/.env"] [unique_id "apPkDNRh6OewFvqQpDlUJwAAAV8"]
[Sun Aug 30 03:04:29.006988 2026] [security2:error] [pid 488669:tid 488834] [client 20.63.81.20:58959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/simple.php"] [unique_id "apPkDdRh6OewFvqQpDlULwAAASU"]
[Sun Aug 30 03:04:29.009980 2026] [security2:error] [pid 488669:tid 488897] [client 20.220.204.93:10958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/bgymj.php"] [unique_id "apPkDdRh6OewFvqQpDlUMgAAAWQ"]
[Sun Aug 30 03:04:29.033578 2026] [security2:error] [pid 488669:tid 488837] [client 20.220.10.235:21777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/css/000.php"] [unique_id "apPkDdRh6OewFvqQpDlUPQAAASg"]
[Sun Aug 30 03:04:29.064016 2026] [security2:error] [pid 488669:tid 488828] [client 158.23.147.79:61466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apPkDdRh6OewFvqQpDlUSgAAAR8"]
[Sun Aug 30 03:04:29.065766 2026] [authz_core:error] [pid 488669:tid 488821] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fvar%2Flib%2Fpcp%2Fconfig%2Fderived
[Sun Aug 30 03:04:29.066338 2026] [authz_core:error] [pid 488669:tid 488821] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fvar%2Flib%2Fpcp%2Fconfig%2Fderived
[Sun Aug 30 03:04:29.067454 2026] [security2:error] [pid 488669:tid 488903] [client 158.23.184.117:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpanel.getchellgarden.com"] [uri "/c99.php"] [unique_id "apPkDdRh6OewFvqQpDlUSwAAAWo"]
[Sun Aug 30 03:04:29.075683 2026] [security2:error] [pid 488669:tid 488906] [client 20.220.10.235:33679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/h02ugyh.php"] [unique_id "apPkDdRh6OewFvqQpDlUTgAAAW0"]
[Sun Aug 30 03:04:29.096493 2026] [security2:error] [pid 488669:tid 488907] [client 20.220.10.235:49097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/Contrller.php"] [unique_id "apPkDdRh6OewFvqQpDlUXgAAAW4"]
[Sun Aug 30 03:04:29.101004 2026] [security2:error] [pid 488669:tid 488918] [client 20.48.251.3:54772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/ms.php"] [unique_id "apPkDdRh6OewFvqQpDlUYgAAAXk"]
[Sun Aug 30 03:04:29.118855 2026] [security2:error] [pid 488669:tid 488897] [client 20.48.251.3:6519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/fm.php"] [unique_id "apPkDdRh6OewFvqQpDlUbAAAAWQ"]
[Sun Aug 30 03:04:29.129009 2026] [security2:error] [pid 488669:tid 488840] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/codeigniter/.env"] [unique_id "apPkDdRh6OewFvqQpDlUbQAAASs"]
[Sun Aug 30 03:04:29.135685 2026] [security2:error] [pid 488669:tid 488933] [client 20.63.81.20:59117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/aaa.php"] [unique_id "apPkDdRh6OewFvqQpDlUcgAAAYg"]
[Sun Aug 30 03:04:29.146918 2026] [security2:error] [pid 488669:tid 488902] [client 20.104.50.220:42809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-config-sample.php"] [unique_id "apPkDdRh6OewFvqQpDlUeAAAAWk"]
[Sun Aug 30 03:04:29.157970 2026] [security2:error] [pid 488669:tid 488820] [client 20.104.49.130:40200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.topatrust.com"] [uri "/bthil.php"] [unique_id "apPkDdRh6OewFvqQpDlUegAAARc"]
[Sun Aug 30 03:04:29.204870 2026] [security2:error] [pid 488669:tid 488843] [client 20.220.10.235:33854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/sf.php"] [unique_id "apPkDdRh6OewFvqQpDlUjAAAAS4"]
[Sun Aug 30 03:04:29.225764 2026] [security2:error] [pid 488669:tid 488854] [client 20.220.10.235:21570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/cy.php"] [unique_id "apPkDdRh6OewFvqQpDlUnAAAATk"]
[Sun Aug 30 03:04:29.231470 2026] [authz_core:error] [pid 488669:tid 488832] [client 216.73.216.128:43831] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:29.231817 2026] [authz_core:error] [pid 488669:tid 488832] [client 216.73.216.128:43831] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:29.234321 2026] [security2:error] [pid 488669:tid 488926] [client 20.220.10.235:49094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/file66.php"] [unique_id "apPkDdRh6OewFvqQpDlUpQAAAYE"]
[Sun Aug 30 03:04:29.251270 2026] [security2:error] [pid 488669:tid 488823] [client 158.23.147.79:62792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apPkDdRh6OewFvqQpDlUsAAAARo"]
[Sun Aug 30 03:04:29.260393 2026] [security2:error] [pid 488669:tid 488900] [client 74.7.243.204:48278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/main/"] [unique_id "apPkDdRh6OewFvqQpDlUswAAAWc"], referer: http://mail.letter7brands.com/main/?p=%2F%2Fetc
[Sun Aug 30 03:04:29.269588 2026] [authz_core:error] [pid 488669:tid 488870] [client 66.249.66.65:41850] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:29.270014 2026] [authz_core:error] [pid 488669:tid 488870] [client 66.249.66.65:41850] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:29.273040 2026] [security2:error] [pid 488669:tid 488820] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/cakephp/.env"] [unique_id "apPkDdRh6OewFvqQpDlUugAAARc"]
[Sun Aug 30 03:04:29.326114 2026] [security2:error] [pid 488669:tid 488883] [client 20.196.209.81:23679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/news-portal/error.php"] [unique_id "apPkDdRh6OewFvqQpDlU3QAAAVY"]
[Sun Aug 30 03:04:29.336300 2026] [security2:error] [pid 488669:tid 488881] [client 20.220.10.235:33851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/4e.php"] [unique_id "apPkDdRh6OewFvqQpDlU6QAAAVQ"]
[Sun Aug 30 03:04:29.362318 2026] [security2:error] [pid 488669:tid 488845] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/cache/cache/min.php"] [unique_id "apPkDdRh6OewFvqQpDlU7gAAATA"]
[Sun Aug 30 03:04:29.364042 2026] [security2:error] [pid 488669:tid 488924] [client 20.220.10.235:49656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/blnux.php"] [unique_id "apPkDdRh6OewFvqQpDlU7wAAAX8"]
[Sun Aug 30 03:04:29.365739 2026] [security2:error] [pid 488669:tid 488900] [client 20.104.50.220:29136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/.109753674214724.php"] [unique_id "apPkDdRh6OewFvqQpDlU8AAAAWc"]
[Sun Aug 30 03:04:29.384538 2026] [security2:error] [pid 488669:tid 488841] [client 68.155.159.216:60605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-includes/IXR/index.php"] [unique_id "apPkDdRh6OewFvqQpDlU9wAAASw"]
[Sun Aug 30 03:04:29.395439 2026] [security2:error] [pid 488669:tid 488890] [client 20.220.10.235:21630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/admin.php/pindex.php"] [unique_id "apPkDdRh6OewFvqQpDlVBgAAAV0"]
[Sun Aug 30 03:04:29.398671 2026] [authz_core:error] [pid 488669:tid 488910] [client 66.249.66.45:52313] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:29.398930 2026] [authz_core:error] [pid 488669:tid 488910] [client 66.249.66.45:52313] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:29.416293 2026] [security2:error] [pid 488669:tid 488933] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/zend/.env"] [unique_id "apPkDdRh6OewFvqQpDlVEQAAAYg"]
[Sun Aug 30 03:04:29.423112 2026] [authz_core:error] [pid 488669:tid 488880] [client 216.73.216.128:10097] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:29.423380 2026] [authz_core:error] [pid 488669:tid 488880] [client 216.73.216.128:10097] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:29.426075 2026] [security2:error] [pid 488669:tid 488866] [client 20.63.81.20:59114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/shiny.php"] [unique_id "apPkDdRh6OewFvqQpDlVGwAAAUU"]
[Sun Aug 30 03:04:29.461914 2026] [security2:error] [pid 488669:tid 488902] [client 20.151.200.44:58829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/png.php"] [unique_id "apPkDdRh6OewFvqQpDlVQgAAAWk"]
[Sun Aug 30 03:04:29.462496 2026] [security2:error] [pid 488669:tid 488883] [client 20.220.204.93:10257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/ws69.php"] [unique_id "apPkDdRh6OewFvqQpDlVRAAAAVY"]
[Sun Aug 30 03:04:29.470687 2026] [security2:error] [pid 488669:tid 488844] [client 20.220.10.235:33677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/ssss.php"] [unique_id "apPkDdRh6OewFvqQpDlVSwAAAS8"]
[Sun Aug 30 03:04:29.471773 2026] [security2:error] [pid 488669:tid 488927] [client 20.104.50.220:33573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/web-setting.php"] [unique_id "apPkDdRh6OewFvqQpDlVTgAAAYI"]
[Sun Aug 30 03:04:29.480782 2026] [security2:error] [pid 488669:tid 488892] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/catalogbypass.php"] [unique_id "apPkDdRh6OewFvqQpDlVVwAAAV8"]
[Sun Aug 30 03:04:29.494762 2026] [security2:error] [pid 488669:tid 488869] [client 20.220.10.235:49604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/attack.php"] [unique_id "apPkDdRh6OewFvqQpDlVZAAAAUg"]
[Sun Aug 30 03:04:29.512026 2026] [security2:error] [pid 488669:tid 488863] [client 158.23.147.79:55181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/nf_tracking.php"] [unique_id "apPkDdRh6OewFvqQpDlVcAAAAUI"]
[Sun Aug 30 03:04:29.527079 2026] [security2:error] [pid 488669:tid 488934] [client 20.220.10.235:21770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/admin.php/csv.php"] [unique_id "apPkDdRh6OewFvqQpDlVeQAAAYk"]
[Sun Aug 30 03:04:29.563917 2026] [security2:error] [pid 488669:tid 488864] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/yii/.env"] [unique_id "apPkDdRh6OewFvqQpDlVjgAAAUM"]
[Sun Aug 30 03:04:29.564094 2026] [security2:error] [pid 488669:tid 488903] [client 20.151.200.44:37860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkDdRh6OewFvqQpDlVjwAAAWo"]
[Sun Aug 30 03:04:29.565921 2026] [authz_core:error] [pid 488669:tid 488908] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fvar%2Flib%2Fpcp%2Fconfig%2Fderived
[Sun Aug 30 03:04:29.566198 2026] [authz_core:error] [pid 488669:tid 488908] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fvar%2Flib%2Fpcp%2Fconfig%2Fderived
[Sun Aug 30 03:04:29.569147 2026] [security2:error] [pid 488669:tid 488809] [client 20.104.50.220:30299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/g3.php"] [unique_id "apPkDdRh6OewFvqQpDlVkwAAAQw"]
[Sun Aug 30 03:04:29.571827 2026] [security2:error] [pid 488669:tid 488812] [client 20.63.81.20:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/goods.php"] [unique_id "apPkDdRh6OewFvqQpDlVlAAAAQ8"]
[Sun Aug 30 03:04:29.579276 2026] [security2:error] [pid 488669:tid 488851] [client 20.48.251.3:30346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lastmaskcenter.org"] [uri "/old_phpinfo.php"] [unique_id "apPkDdRh6OewFvqQpDlVmAAAATY"]
[Sun Aug 30 03:04:29.589311 2026] [security2:error] [pid 488669:tid 488911] [client 68.155.159.216:60000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apPkDdRh6OewFvqQpDlVnQAAAXI"]
[Sun Aug 30 03:04:29.601519 2026] [security2:error] [pid 488669:tid 488849] [client 20.220.10.235:33813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/zoz.php"] [unique_id "apPkDdRh6OewFvqQpDlVoQAAATQ"]
[Sun Aug 30 03:04:29.602906 2026] [security2:error] [pid 488669:tid 488850] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/cc.php"] [unique_id "apPkDdRh6OewFvqQpDlVowAAATU"]
[Sun Aug 30 03:04:29.604404 2026] [security2:error] [pid 488669:tid 488836] [client 20.48.251.3:55694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/phina.php"] [unique_id "apPkDdRh6OewFvqQpDlVpAAAASc"]
[Sun Aug 30 03:04:29.617715 2026] [security2:error] [pid 488669:tid 488861] [client 20.197.61.180:9166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/hideo/network.php"] [unique_id "apPkDdRh6OewFvqQpDlVpQAAAUA"]
[Sun Aug 30 03:04:29.647427 2026] [security2:error] [pid 488669:tid 488924] [client 20.48.251.3:51574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/paypal.php"] [unique_id "apPkDdRh6OewFvqQpDlVqwAAAX8"]
[Sun Aug 30 03:04:29.651806 2026] [security2:error] [pid 488669:tid 488871] [client 20.220.204.93:5048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/ccs.php"] [unique_id "apPkDdRh6OewFvqQpDlVrAAAAUo"]
[Sun Aug 30 03:04:29.655766 2026] [security2:error] [pid 488669:tid 488922] [client 20.220.10.235:49103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/wk/index.php"] [unique_id "apPkDdRh6OewFvqQpDlVrgAAAX0"]
[Sun Aug 30 03:04:29.656700 2026] [security2:error] [pid 488669:tid 488847] [client 20.220.10.235:21600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/admin.php/700.php"] [unique_id "apPkDdRh6OewFvqQpDlVrwAAATI"]
[Sun Aug 30 03:04:29.671775 2026] [security2:error] [pid 488669:tid 488926] [client 20.48.251.3:55451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/olfclass.php"] [unique_id "apPkDdRh6OewFvqQpDlVtgAAAYE"]
[Sun Aug 30 03:04:29.676487 2026] [security2:error] [pid 488669:tid 488912] [client 20.48.251.3:23311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/ms.php"] [unique_id "apPkDdRh6OewFvqQpDlVuAAAAXM"]
[Sun Aug 30 03:04:29.677792 2026] [security2:error] [pid 488669:tid 488835] [client 20.48.251.3:44378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/aws_config.php"] [unique_id "apPkDdRh6OewFvqQpDlVuQAAASY"]
[Sun Aug 30 03:04:29.698633 2026] [security2:error] [pid 488669:tid 488933] [client 20.63.81.20:59046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/000.php/index.php"] [unique_id "apPkDdRh6OewFvqQpDlVvAAAAYg"]
[Sun Aug 30 03:04:29.707288 2026] [security2:error] [pid 488669:tid 488877] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/laravel5/.env"] [unique_id "apPkDdRh6OewFvqQpDlVvwAAAVA"]
[Sun Aug 30 03:04:29.721907 2026] [security2:error] [pid 488669:tid 488823] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/cgi-bin/admin.php"] [unique_id "apPkDdRh6OewFvqQpDlVxwAAARo"]
[Sun Aug 30 03:04:29.726578 2026] [security2:error] [pid 488669:tid 488824] [client 20.196.209.81:6088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/nvt/includes/plugins/wp-blog-header.php"] [unique_id "apPkDdRh6OewFvqQpDlVzQAAARs"]
[Sun Aug 30 03:04:29.727228 2026] [security2:error] [pid 488669:tid 488919] [client 20.104.50.220:63037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/oke.php"] [unique_id "apPkDdRh6OewFvqQpDlVzgAAAXo"]
[Sun Aug 30 03:04:29.733234 2026] [security2:error] [pid 488669:tid 488904] [client 20.220.10.235:33818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/kcs.php"] [unique_id "apPkDdRh6OewFvqQpDlVzwAAAWs"]
[Sun Aug 30 03:04:29.734190 2026] [security2:error] [pid 488669:tid 488800] [remote 74.7.242.63:51114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.ltr7.com"] [uri "/xml/3D\\"https:/www.law360.com/media/articles/images/tile.jpg"] [unique_id "apPkDdRh6OewFvqQpDlV0AABhHo"], referer: https://mail.ltr7.com/xml/3D%22https:/www.law360.com/media/articles/images/tile.jpg?p=%2F%2Fetc
[Sun Aug 30 03:04:29.769819 2026] [authz_core:error] [pid 488669:tid 488851] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fspa-0.2%2Falsa
[Sun Aug 30 03:04:29.770251 2026] [authz_core:error] [pid 488669:tid 488851] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fspa-0.2%2Falsa
[Sun Aug 30 03:04:29.782956 2026] [security2:error] [pid 488669:tid 488840] [client 20.220.10.235:49101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/dehnl.php"] [unique_id "apPkDdRh6OewFvqQpDlV2wAAASs"]
[Sun Aug 30 03:04:29.785657 2026] [authz_core:error] [pid 488669:tid 488809] [client 66.249.66.35:38197] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:29.785906 2026] [authz_core:error] [pid 488669:tid 488809] [client 66.249.66.35:38197] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:29.795400 2026] [security2:error] [pid 488669:tid 488836] [client 20.104.50.220:5549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/0x.php"] [unique_id "apPkDdRh6OewFvqQpDlV3gAAASc"]
[Sun Aug 30 03:04:29.803073 2026] [security2:error] [pid 488669:tid 488818] [client 20.220.10.235:21799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/admin.php/007x.php"] [unique_id "apPkDdRh6OewFvqQpDlV4AAAARU"]
[Sun Aug 30 03:04:29.826209 2026] [security2:error] [pid 488669:tid 488859] [client 20.63.81.20:59043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/Jcrop.php"] [unique_id "apPkDdRh6OewFvqQpDlV5AAAAT4"]
[Sun Aug 30 03:04:29.836303 2026] [security2:error] [pid 488669:tid 488845] [client 20.104.50.220:28711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/w50.php"] [unique_id "apPkDdRh6OewFvqQpDlV5wAAATA"]
[Sun Aug 30 03:04:29.850777 2026] [security2:error] [pid 488669:tid 488838] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/v1/.env"] [unique_id "apPkDdRh6OewFvqQpDlV6wAAASk"]
[Sun Aug 30 03:04:29.855543 2026] [security2:error] [pid 488669:tid 488847] [client 20.104.50.220:46170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/foxwsov1.php"] [unique_id "apPkDdRh6OewFvqQpDlV7QAAATI"]
[Sun Aug 30 03:04:29.865957 2026] [security2:error] [pid 488669:tid 488884] [client 20.220.10.235:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/tajj.php"] [unique_id "apPkDdRh6OewFvqQpDlV7wAAAVc"]
[Sun Aug 30 03:04:29.877324 2026] [security2:error] [pid 488669:tid 488875] [client 20.220.204.93:10993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/mar.php"] [unique_id "apPkDdRh6OewFvqQpDlV8gAAAU4"]
[Sun Aug 30 03:04:29.911482 2026] [security2:error] [pid 488669:tid 488830] [client 20.220.10.235:49626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/png.php"] [unique_id "apPkDdRh6OewFvqQpDlV9wAAASE"]
[Sun Aug 30 03:04:29.937189 2026] [security2:error] [pid 488669:tid 488823] [client 20.220.10.235:21780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/admin.php/heex.php"] [unique_id "apPkDdRh6OewFvqQpDlV-wAAARo"]
[Sun Aug 30 03:04:29.940616 2026] [security2:error] [pid 488669:tid 488813] [client 158.23.147.79:55065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wzy.php"] [unique_id "apPkDdRh6OewFvqQpDlV_AAAARA"]
[Sun Aug 30 03:04:29.960742 2026] [security2:error] [pid 488669:tid 488842] [client 20.63.81.20:59110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/35iDq8NAjLu.php"] [unique_id "apPkDdRh6OewFvqQpDlWAgAAAS0"]
[Sun Aug 30 03:04:29.984567 2026] [security2:error] [pid 488669:tid 488904] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/config.php"] [unique_id "apPkDdRh6OewFvqQpDlWBgAAAWs"]
[Sun Aug 30 03:04:29.993042 2026] [security2:error] [pid 488669:tid 488817] [client 20.220.10.235:33704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/bge.php"] [unique_id "apPkDdRh6OewFvqQpDlWBwAAARQ"]
[Sun Aug 30 03:04:29.994510 2026] [security2:error] [pid 488669:tid 488929] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/v2/.env"] [unique_id "apPkDdRh6OewFvqQpDlWCAAAAYQ"]
[Sun Aug 30 03:04:30.011761 2026] [security2:error] [pid 488669:tid 488911] [client 20.104.50.220:31873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/DC.php"] [unique_id "apPkDtRh6OewFvqQpDlWEAAAAXI"]
[Sun Aug 30 03:04:30.040110 2026] [security2:error] [pid 488669:tid 488905] [client 20.220.10.235:49796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/txets.php"] [unique_id "apPkDtRh6OewFvqQpDlWGgAAAWw"]
[Sun Aug 30 03:04:30.043494 2026] [security2:error] [pid 488669:tid 488915] [client 20.104.18.15:9064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/x.php"] [unique_id "apPkDtRh6OewFvqQpDlWGwAAAXY"]
[Sun Aug 30 03:04:30.087260 2026] [security2:error] [pid 488669:tid 488884] [client 20.220.10.235:21578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/tf.php"] [unique_id "apPkDtRh6OewFvqQpDlWKgAAAVc"]
[Sun Aug 30 03:04:30.088220 2026] [security2:error] [pid 488669:tid 488873] [client 20.104.18.15:31655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/ah.php"] [unique_id "apPkDtRh6OewFvqQpDlWKwAAAUw"]
[Sun Aug 30 03:04:30.089347 2026] [authz_core:error] [pid 488669:tid 488896] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fdocs
[Sun Aug 30 03:04:30.089650 2026] [authz_core:error] [pid 488669:tid 488896] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fdocs
[Sun Aug 30 03:04:30.089817 2026] [security2:error] [pid 488669:tid 488874] [client 20.63.81.20:58979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/btx25.php"] [unique_id "apPkDtRh6OewFvqQpDlWLQAAAU0"]
[Sun Aug 30 03:04:30.098705 2026] [security2:error] [pid 488669:tid 488831] [client 20.48.251.3:7362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/tax.php"] [unique_id "apPkDtRh6OewFvqQpDlWNQAAASI"]
[Sun Aug 30 03:04:30.100213 2026] [security2:error] [pid 488669:tid 488877] [client 20.48.251.3:64384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/wsws.php"] [unique_id "apPkDtRh6OewFvqQpDlWNwAAAVA"]
[Sun Aug 30 03:04:30.112194 2026] [security2:error] [pid 488669:tid 488814] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/login.php"] [unique_id "apPkDtRh6OewFvqQpDlWPQAAARE"]
[Sun Aug 30 03:04:30.113916 2026] [security2:error] [pid 488669:tid 488848] [client 20.220.204.93:10957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/ccu.php"] [unique_id "apPkDtRh6OewFvqQpDlWPwAAATM"]
[Sun Aug 30 03:04:30.122510 2026] [security2:error] [pid 488669:tid 488897] [client 20.220.10.235:33844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/ssh3ll.php"] [unique_id "apPkDtRh6OewFvqQpDlWQgAAAWQ"]
[Sun Aug 30 03:04:30.137563 2026] [security2:error] [pid 488669:tid 488908] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/v3/.env"] [unique_id "apPkDtRh6OewFvqQpDlWRQAAAW8"]
[Sun Aug 30 03:04:30.149805 2026] [security2:error] [pid 488669:tid 488898] [client 20.196.209.81:6083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/oceanwp/sass/components/plugins/panel.php"] [unique_id "apPkDtRh6OewFvqQpDlWSgAAAWU"]
[Sun Aug 30 03:04:30.169751 2026] [security2:error] [pid 488669:tid 488932] [client 20.220.10.235:49658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/wp-login.php"] [unique_id "apPkDtRh6OewFvqQpDlWTgAAAYc"]
[Sun Aug 30 03:04:30.204993 2026] [security2:error] [pid 488669:tid 488826] [client 158.23.147.79:62840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apPkDtRh6OewFvqQpDlWYgAAAR0"]
[Sun Aug 30 03:04:30.220567 2026] [security2:error] [pid 488669:tid 488808] [client 20.63.81.20:59127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/radio.php"] [unique_id "apPkDtRh6OewFvqQpDlWbAAAAQs"]
[Sun Aug 30 03:04:30.237975 2026] [security2:error] [pid 488669:tid 488899] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/index.php"] [unique_id "apPkDtRh6OewFvqQpDlWdwAAAWY"]
[Sun Aug 30 03:04:30.238048 2026] [security2:error] [pid 488669:tid 488829] [client 20.48.251.3:54795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/fucku.php"] [unique_id "apPkDtRh6OewFvqQpDlWeAAAASA"]
[Sun Aug 30 03:04:30.248522 2026] [security2:error] [pid 488669:tid 488865] [client 20.220.10.235:21779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/update/da222.php"] [unique_id "apPkDtRh6OewFvqQpDlWgQAAAUQ"]
[Sun Aug 30 03:04:30.253247 2026] [security2:error] [pid 488669:tid 488815] [client 20.48.251.3:7062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/tinyfilemanager.php"] [unique_id "apPkDtRh6OewFvqQpDlWgwAAARI"]
[Sun Aug 30 03:04:30.256515 2026] [security2:error] [pid 488669:tid 488908] [client 20.220.10.235:33831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/motu.php"] [unique_id "apPkDtRh6OewFvqQpDlWhQAAAW8"]
[Sun Aug 30 03:04:30.282265 2026] [security2:error] [pid 488669:tid 488878] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/api/v1/.env"] [unique_id "apPkDtRh6OewFvqQpDlWkgAAAVE"]
[Sun Aug 30 03:04:30.282676 2026] [authz_core:error] [pid 488669:tid 488820] [client 66.249.66.65:56975] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:30.283060 2026] [authz_core:error] [pid 488669:tid 488820] [client 66.249.66.65:56975] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:30.301441 2026] [security2:error] [pid 488669:tid 488839] [client 20.104.50.220:51553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/blog/fw.php"] [unique_id "apPkDtRh6OewFvqQpDlWoQAAASo"]
[Sun Aug 30 03:04:30.301665 2026] [security2:error] [pid 488669:tid 488915] [client 20.220.10.235:49654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/wp-access.php"] [unique_id "apPkDtRh6OewFvqQpDlWogAAAXY"]
[Sun Aug 30 03:04:30.324144 2026] [security2:error] [pid 488669:tid 488912] [client 20.104.49.130:26943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trinitytechnologics.com"] [uri "/ws58.php"] [unique_id "apPkDtRh6OewFvqQpDlWtgAAAXM"]
[Sun Aug 30 03:04:30.342514 2026] [security2:error] [pid 488669:tid 488851] [client 20.197.61.180:13908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPkDtRh6OewFvqQpDlWwgAAATY"]
[Sun Aug 30 03:04:30.350113 2026] [security2:error] [pid 488669:tid 488850] [client 20.63.81.20:59065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/dex.php"] [unique_id "apPkDtRh6OewFvqQpDlWxAAAATU"]
[Sun Aug 30 03:04:30.364113 2026] [security2:error] [pid 488669:tid 488852] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/min.php"] [unique_id "apPkDtRh6OewFvqQpDlWyQAAATc"]
[Sun Aug 30 03:04:30.377843 2026] [security2:error] [pid 488669:tid 488861] [client 20.220.10.235:21778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/qi.php"] [unique_id "apPkDtRh6OewFvqQpDlWzAAAAUA"]
[Sun Aug 30 03:04:30.398455 2026] [security2:error] [pid 488669:tid 488823] [client 20.220.10.235:33797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/wefile.php"] [unique_id "apPkDtRh6OewFvqQpDlW3wAAARo"]
[Sun Aug 30 03:04:30.408451 2026] [security2:error] [pid 488669:tid 488868] [client 20.220.204.93:46920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/ak.php"] [unique_id "apPkDtRh6OewFvqQpDlW5QAAAUc"]
[Sun Aug 30 03:04:30.425800 2026] [security2:error] [pid 488669:tid 488912] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/api/v2/.env"] [unique_id "apPkDtRh6OewFvqQpDlW7wAAAXM"]
[Sun Aug 30 03:04:30.428902 2026] [security2:error] [pid 488669:tid 488899] [client 20.220.10.235:49606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/wp-content/admin.php"] [unique_id "apPkDtRh6OewFvqQpDlW9QAAAWY"]
[Sun Aug 30 03:04:30.482997 2026] [security2:error] [pid 488669:tid 488865] [client 20.63.81.20:59022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/giodywky.php"] [unique_id "apPkDtRh6OewFvqQpDlXLQAAAUQ"]
[Sun Aug 30 03:04:30.486796 2026] [security2:error] [pid 488669:tid 488811] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/options.php"] [unique_id "apPkDtRh6OewFvqQpDlXLwAAAQ4"]
[Sun Aug 30 03:04:30.512920 2026] [security2:error] [pid 488669:tid 488861] [client 20.220.10.235:21586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/px.php"] [unique_id "apPkDtRh6OewFvqQpDlXSwAAAUA"]
[Sun Aug 30 03:04:30.527268 2026] [security2:error] [pid 488669:tid 488840] [client 20.220.10.235:33846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/Contrller.php"] [unique_id "apPkDtRh6OewFvqQpDlXUwAAASs"]
[Sun Aug 30 03:04:30.532672 2026] [security2:error] [pid 488669:tid 488849] [client 68.155.159.216:60549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/classwithtostring.php"] [unique_id "apPkDtRh6OewFvqQpDlXVAAAATQ"]
[Sun Aug 30 03:04:30.540014 2026] [security2:error] [pid 488669:tid 488873] [client 20.196.209.81:6086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/options.php"] [unique_id "apPkDtRh6OewFvqQpDlXXQAAAUw"]
[Sun Aug 30 03:04:30.558246 2026] [security2:error] [pid 488669:tid 488875] [client 77.238.239.20:61797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.239.238.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueljsimmons.com"] [uri "/wp-comments-post.php"] [unique_id "apPkDtRh6OewFvqQpDlXXgAAAU4"]
[Sun Aug 30 03:04:30.558320 2026] [security2:error] [pid 488669:tid 488875] [client 77.238.239.20:61797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "samueljsimmons.com"] [uri "/wp-comments-post.php"] [unique_id "apPkDtRh6OewFvqQpDlXXgAAAU4"]
[Sun Aug 30 03:04:30.566533 2026] [security2:error] [pid 488669:tid 488930] [client 20.220.10.235:49659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/log.php"] [unique_id "apPkDtRh6OewFvqQpDlXagAAAYU"]
[Sun Aug 30 03:04:30.569539 2026] [security2:error] [pid 488669:tid 488926] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/rest/.env"] [unique_id "apPkDtRh6OewFvqQpDlXbAAAAYE"]
[Sun Aug 30 03:04:30.574318 2026] [security2:error] [pid 488669:tid 488870] [client 20.220.204.93:32690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/lib.php"] [unique_id "apPkDtRh6OewFvqQpDlXbQAAAUk"]
[Sun Aug 30 03:04:30.595945 2026] [security2:error] [pid 488669:tid 488880] [client 20.104.50.220:29183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/kjihe.php"] [unique_id "apPkDtRh6OewFvqQpDlXcwAAAVM"]
[Sun Aug 30 03:04:30.605851 2026] [authz_core:error] [pid 488669:tid 488879] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Ftest
[Sun Aug 30 03:04:30.606114 2026] [authz_core:error] [pid 488669:tid 488879] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Ftest
[Sun Aug 30 03:04:30.608665 2026] [security2:error] [pid 488669:tid 488889] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/pk.php"] [unique_id "apPkDtRh6OewFvqQpDlXeQAAAVw"]
[Sun Aug 30 03:04:30.639102 2026] [security2:error] [pid 488669:tid 488858] [client 20.63.81.20:59132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp-kz.php"] [unique_id "apPkDtRh6OewFvqQpDlXfwAAAT0"]
[Sun Aug 30 03:04:30.640691 2026] [security2:error] [pid 488669:tid 488884] [client 20.104.50.220:33536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-ettoyag.php"] [unique_id "apPkDtRh6OewFvqQpDlXgAAAAVc"]
[Sun Aug 30 03:04:30.641291 2026] [security2:error] [pid 488669:tid 488850] [client 20.220.10.235:21766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/is.php"] [unique_id "apPkDtRh6OewFvqQpDlXggAAATU"]
[Sun Aug 30 03:04:30.656297 2026] [security2:error] [pid 488669:tid 488885] [client 20.220.10.235:33801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/file66.php"] [unique_id "apPkDtRh6OewFvqQpDlXiAAAAVg"]
[Sun Aug 30 03:04:30.681189 2026] [security2:error] [pid 488669:tid 488827] [client 158.23.147.79:62800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apPkDtRh6OewFvqQpDlXjQAAAR4"]
[Sun Aug 30 03:04:30.701733 2026] [security2:error] [pid 488669:tid 488922] [client 20.220.10.235:49643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/xwpg.php"] [unique_id "apPkDtRh6OewFvqQpDlXlAAAAX0"]
[Sun Aug 30 03:04:30.706309 2026] [authz_core:error] [pid 488669:tid 488873] [client 216.73.216.128:34158] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:30.706592 2026] [authz_core:error] [pid 488669:tid 488873] [client 216.73.216.128:34158] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:30.708814 2026] [security2:error] [pid 488669:tid 488854] [client 20.104.50.220:29877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/Yamarket.php"] [unique_id "apPkDtRh6OewFvqQpDlXmAAAATk"]
[Sun Aug 30 03:04:30.714293 2026] [security2:error] [pid 488669:tid 488848] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/graphql/.env"] [unique_id "apPkDtRh6OewFvqQpDlXmgAAATM"]
[Sun Aug 30 03:04:30.720911 2026] [security2:error] [pid 488669:tid 488925] [client 20.48.251.3:31622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.lastmaskcenter.org"] [uri "/wp-act.php"] [unique_id "apPkDtRh6OewFvqQpDlXngAAAYA"]
[Sun Aug 30 03:04:30.730917 2026] [security2:error] [pid 488669:tid 488834] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/index.php"] [unique_id "apPkDtRh6OewFvqQpDlXogAAASU"]
[Sun Aug 30 03:04:30.737087 2026] [security2:error] [pid 488669:tid 488923] [client 20.220.204.93:10250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/wp-style.php"] [unique_id "apPkDtRh6OewFvqQpDlXpQAAAX4"]
[Sun Aug 30 03:04:30.744579 2026] [security2:error] [pid 488669:tid 488905] [client 20.48.251.3:55776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/koiy.php"] [unique_id "apPkDtRh6OewFvqQpDlXpgAAAWw"]
[Sun Aug 30 03:04:30.765521 2026] [security2:error] [pid 488669:tid 488817] [client 68.155.159.216:59931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/chosen.php"] [unique_id "apPkDtRh6OewFvqQpDlXqQAAARQ"]
[Sun Aug 30 03:04:30.770854 2026] [security2:error] [pid 488669:tid 488815] [client 20.220.10.235:21762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/od.php"] [unique_id "apPkDtRh6OewFvqQpDlXqwAAARI"]
[Sun Aug 30 03:04:30.771220 2026] [security2:error] [pid 488669:tid 488916] [client 20.63.81.20:59063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp-includes/ID3/getid.php"] [unique_id "apPkDtRh6OewFvqQpDlXrAAAAXc"]
[Sun Aug 30 03:04:30.801576 2026] [authz_core:error] [pid 488669:tid 488894] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fhome4%2Fletter7%2Fmail%2Fletter7brands.com%2Fartemm
[Sun Aug 30 03:04:30.801870 2026] [authz_core:error] [pid 488669:tid 488894] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fhome4%2Fletter7%2Fmail%2Fletter7brands.com%2Fartemm
[Sun Aug 30 03:04:30.802322 2026] [security2:error] [pid 488669:tid 488822] [client 20.220.10.235:33676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/blnux.php"] [unique_id "apPkDtRh6OewFvqQpDlXuQAAARk"]
[Sun Aug 30 03:04:30.810761 2026] [security2:error] [pid 488669:tid 488858] [client 20.48.251.3:55490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/gnmlc.php"] [unique_id "apPkDtRh6OewFvqQpDlXvQAAAT0"]
[Sun Aug 30 03:04:30.812444 2026] [security2:error] [pid 488669:tid 488920] [client 20.48.251.3:51474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/userfuns.php"] [unique_id "apPkDtRh6OewFvqQpDlXvwAAAXs"]
[Sun Aug 30 03:04:30.815706 2026] [security2:error] [pid 488669:tid 488863] [client 20.48.251.3:22729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/fucku.php"] [unique_id "apPkDtRh6OewFvqQpDlXwgAAAUI"]
[Sun Aug 30 03:04:30.835818 2026] [security2:error] [pid 488669:tid 488887] [client 20.220.10.235:49797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/sxxb.php"] [unique_id "apPkDtRh6OewFvqQpDlXxwAAAVo"]
[Sun Aug 30 03:04:30.859575 2026] [security2:error] [pid 488669:tid 488855] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/gateway/.env"] [unique_id "apPkDtRh6OewFvqQpDlXzgAAATo"]
[Sun Aug 30 03:04:30.898823 2026] [security2:error] [pid 488669:tid 488838] [client 20.220.10.235:21821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/wp-the.php"] [unique_id "apPkDtRh6OewFvqQpDlX1AAAASk"]
[Sun Aug 30 03:04:30.908409 2026] [security2:error] [pid 488669:tid 488811] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/cgi-bin/index.php"] [unique_id "apPkDtRh6OewFvqQpDlX2AAAAQ4"]
[Sun Aug 30 03:04:30.910046 2026] [security2:error] [pid 488669:tid 488874] [client 20.63.81.20:59088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/session.php"] [unique_id "apPkDtRh6OewFvqQpDlX2QAAAU0"]
[Sun Aug 30 03:04:30.932534 2026] [security2:error] [pid 488669:tid 488907] [client 20.220.10.235:33816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/attack.php"] [unique_id "apPkDtRh6OewFvqQpDlX3wAAAW4"]
[Sun Aug 30 03:04:30.932578 2026] [security2:error] [pid 488669:tid 488872] [client 20.196.209.81:11590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/panel.php"] [unique_id "apPkDtRh6OewFvqQpDlX3gAAAUs"]
[Sun Aug 30 03:04:30.953474 2026] [security2:error] [pid 488669:tid 488816] [client 20.104.50.220:5934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/css.php"] [unique_id "apPkDtRh6OewFvqQpDlX5wAAARM"]
[Sun Aug 30 03:04:30.964553 2026] [security2:error] [pid 488669:tid 488870] [client 20.220.10.235:49637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/dx.php"] [unique_id "apPkDtRh6OewFvqQpDlX6AAAAUk"]
[Sun Aug 30 03:04:30.965609 2026] [security2:error] [pid 488669:tid 488871] [client 20.104.50.220:61377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/MKY.php"] [unique_id "apPkDtRh6OewFvqQpDlX6QAAAUo"]
[Sun Aug 30 03:04:30.974177 2026] [security2:error] [pid 488669:tid 488882] [client 20.104.50.220:29325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/xccc.php"] [unique_id "apPkDtRh6OewFvqQpDlX7QAAAVU"]
[Sun Aug 30 03:04:30.987919 2026] [security2:error] [pid 488669:tid 488828] [client 20.220.204.93:5035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/browse.php"] [unique_id "apPkDtRh6OewFvqQpDlX7wAAAR8"]
[Sun Aug 30 03:04:30.990192 2026] [security2:error] [pid 488669:tid 488835] [client 20.48.251.3:44401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/dialog.php"] [unique_id "apPkDtRh6OewFvqQpDlX8AAAASY"]
[Sun Aug 30 03:04:31.002007 2026] [security2:error] [pid 488669:tid 488861] [client 20.104.50.220:46421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/FoxWSOv2.php"] [unique_id "apPkD9Rh6OewFvqQpDlX9wAAAUA"]
[Sun Aug 30 03:04:31.002578 2026] [security2:error] [pid 488669:tid 488820] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/microservice/.env"] [unique_id "apPkD9Rh6OewFvqQpDlX-AAAARc"]
[Sun Aug 30 03:04:31.027173 2026] [security2:error] [pid 488669:tid 488911] [client 20.220.10.235:21571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/wt.php"] [unique_id "apPkD9Rh6OewFvqQpDlYBgAAAXI"]
[Sun Aug 30 03:04:31.033785 2026] [security2:error] [pid 488669:tid 488855] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/cgi-bin/load.php"] [unique_id "apPkD9Rh6OewFvqQpDlYCgAAATo"]
[Sun Aug 30 03:04:31.038087 2026] [security2:error] [pid 488669:tid 488849] [client 158.23.147.79:55048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apPkD9Rh6OewFvqQpDlYDQAAATQ"]
[Sun Aug 30 03:04:31.039999 2026] [security2:error] [pid 488669:tid 488917] [client 20.63.81.20:59025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/eagle.php"] [unique_id "apPkD9Rh6OewFvqQpDlYDgAAAXg"]
[Sun Aug 30 03:04:31.060419 2026] [security2:error] [pid 488669:tid 488809] [client 20.220.10.235:33825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/wk/index.php"] [unique_id "apPkD9Rh6OewFvqQpDlYEQAAAQw"]
[Sun Aug 30 03:04:31.063837 2026] [security2:error] [pid 488669:tid 488807] [client 20.197.61.180:13916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/intense/block-css.php"] [unique_id "apPkD9Rh6OewFvqQpDlYEwAAAQo"]
[Sun Aug 30 03:04:31.096876 2026] [security2:error] [pid 488669:tid 488880] [client 20.220.10.235:49134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPkD9Rh6OewFvqQpDlYIAAAAVM"]
[Sun Aug 30 03:04:31.140699 2026] [authz_core:error] [pid 488669:tid 488924] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Ftest
[Sun Aug 30 03:04:31.140967 2026] [authz_core:error] [pid 488669:tid 488924] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Ftest
[Sun Aug 30 03:04:31.146587 2026] [security2:error] [pid 488669:tid 488850] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/service/.env"] [unique_id "apPkD9Rh6OewFvqQpDlYLQAAATU"]
[Sun Aug 30 03:04:31.148593 2026] [security2:error] [pid 488669:tid 488893] [client 20.104.50.220:32556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-content/uploads/simple-file-list/DC.php"] [unique_id "apPkD9Rh6OewFvqQpDlYLgAAAWA"]
[Sun Aug 30 03:04:31.150094 2026] [security2:error] [pid 488669:tid 488861] [client 20.151.200.44:37833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkD9Rh6OewFvqQpDlYLwAAAUA"]
[Sun Aug 30 03:04:31.151675 2026] [security2:error] [pid 488669:tid 488820] [client 20.220.204.93:46945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/zoo.php"] [unique_id "apPkD9Rh6OewFvqQpDlYMAAAARc"]
[Sun Aug 30 03:04:31.155003 2026] [security2:error] [pid 488669:tid 488884] [client 20.220.10.235:21771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/im.php"] [unique_id "apPkD9Rh6OewFvqQpDlYMgAAAVc"]
[Sun Aug 30 03:04:31.160490 2026] [security2:error] [pid 488669:tid 488908] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/cgi-bin/ms-files.php"] [unique_id "apPkD9Rh6OewFvqQpDlYNQAAAW8"]
[Sun Aug 30 03:04:31.170352 2026] [security2:error] [pid 488669:tid 488819] [client 20.63.81.20:58958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/up-kon.php"] [unique_id "apPkD9Rh6OewFvqQpDlYPAAAARY"]
[Sun Aug 30 03:04:31.186897 2026] [security2:error] [pid 488669:tid 488830] [client 20.104.18.15:9119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/ssla.php"] [unique_id "apPkD9Rh6OewFvqQpDlYRgAAASE"]
[Sun Aug 30 03:04:31.198006 2026] [security2:error] [pid 488669:tid 488912] [client 20.220.10.235:33799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/dehnl.php"] [unique_id "apPkD9Rh6OewFvqQpDlYTgAAAXM"]
[Sun Aug 30 03:04:31.229404 2026] [security2:error] [pid 488669:tid 488883] [client 20.220.10.235:49639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/xda.php"] [unique_id "apPkD9Rh6OewFvqQpDlYZAAAAVY"]
[Sun Aug 30 03:04:31.254661 2026] [security2:error] [pid 488669:tid 488889] [client 20.104.18.15:31640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/ws55.php"] [unique_id "apPkD9Rh6OewFvqQpDlYcAAAAVw"]
[Sun Aug 30 03:04:31.271044 2026] [authz_core:error] [pid 488669:tid 488900] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:04:31.271294 2026] [authz_core:error] [pid 488669:tid 488900] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:04:31.285929 2026] [security2:error] [pid 488669:tid 488838] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/cgi-bin/wp-activate.php"] [unique_id "apPkD9Rh6OewFvqQpDlYggAAASk"]
[Sun Aug 30 03:04:31.289761 2026] [security2:error] [pid 488669:tid 488922] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/api/v3/.env"] [unique_id "apPkD9Rh6OewFvqQpDlYhwAAAX0"]
[Sun Aug 30 03:04:31.294978 2026] [security2:error] [pid 488669:tid 488865] [client 20.220.10.235:21784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/file.php"] [unique_id "apPkD9Rh6OewFvqQpDlYiQAAAUQ"]
[Sun Aug 30 03:04:31.297420 2026] [security2:error] [pid 488669:tid 488879] [client 20.63.81.20:58955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/tinny.php"] [unique_id "apPkD9Rh6OewFvqQpDlYjQAAAVI"]
[Sun Aug 30 03:04:31.309837 2026] [security2:error] [pid 488669:tid 488864] [client 20.220.204.93:10975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/elp.php"] [unique_id "apPkD9Rh6OewFvqQpDlYmgAAAUM"]
[Sun Aug 30 03:04:31.324013 2026] [security2:error] [pid 488669:tid 488917] [client 20.196.209.81:23674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/reboot/assets/js/plugins/home.php"] [unique_id "apPkD9Rh6OewFvqQpDlYpAAAAXg"]
[Sun Aug 30 03:04:31.326153 2026] [security2:error] [pid 488669:tid 488820] [client 158.23.147.79:55185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apPkD9Rh6OewFvqQpDlYpgAAARc"]
[Sun Aug 30 03:04:31.330742 2026] [security2:error] [pid 488669:tid 488934] [client 20.220.10.235:33832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/png.php"] [unique_id "apPkD9Rh6OewFvqQpDlYqwAAAYk"]
[Sun Aug 30 03:04:31.359112 2026] [security2:error] [pid 488669:tid 488933] [client 20.220.10.235:49095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPkD9Rh6OewFvqQpDlYuAAAAYg"]
[Sun Aug 30 03:04:31.406687 2026] [security2:error] [pid 488669:tid 488849] [client 20.48.251.3:54751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/error_log.php"] [unique_id "apPkD9Rh6OewFvqQpDlY0wAAATQ"]
[Sun Aug 30 03:04:31.407861 2026] [security2:error] [pid 488669:tid 488868] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/cgi-bin/wp-load.php"] [unique_id "apPkD9Rh6OewFvqQpDlY1AAAAUc"]
[Sun Aug 30 03:04:31.428395 2026] [security2:error] [pid 488669:tid 488832] [client 20.63.81.20:59022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp-easy.php"] [unique_id "apPkD9Rh6OewFvqQpDlY4QAAASM"]
[Sun Aug 30 03:04:31.429290 2026] [security2:error] [pid 488669:tid 488897] [client 20.48.251.3:7397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/05.php"] [unique_id "apPkD9Rh6OewFvqQpDlY4gAAAWQ"]
[Sun Aug 30 03:04:31.433513 2026] [security2:error] [pid 488669:tid 488817] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/api/dev/.env"] [unique_id "apPkD9Rh6OewFvqQpDlY6AAAARQ"]
[Sun Aug 30 03:04:31.434991 2026] [security2:error] [pid 488669:tid 488877] [client 20.220.10.235:21584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/ca.php"] [unique_id "apPkD9Rh6OewFvqQpDlY7AAAAVA"]
[Sun Aug 30 03:04:31.436547 2026] [security2:error] [pid 488669:tid 488833] [client 20.104.49.130:26661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trinitytechnologics.com"] [uri "/ws45.php"] [unique_id "apPkD9Rh6OewFvqQpDlY8AAAASQ"]
[Sun Aug 30 03:04:31.438130 2026] [security2:error] [pid 488669:tid 488815] [client 20.104.50.220:42806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-optionss.php"] [unique_id "apPkD9Rh6OewFvqQpDlY8gAAARI"]
[Sun Aug 30 03:04:31.440031 2026] [security2:error] [pid 488669:tid 488876] [client 20.220.204.93:32668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/666.php"] [unique_id "apPkD9Rh6OewFvqQpDlY9wAAAU8"]
[Sun Aug 30 03:04:31.463474 2026] [security2:error] [pid 488669:tid 488884] [client 20.220.10.235:33805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/txets.php"] [unique_id "apPkD9Rh6OewFvqQpDlZFgAAAVc"]
[Sun Aug 30 03:04:31.485957 2026] [security2:error] [pid 488669:tid 488836] [client 20.220.10.235:49653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/t00l.php"] [unique_id "apPkD9Rh6OewFvqQpDlZKAAAASc"]
[Sun Aug 30 03:04:31.531897 2026] [security2:error] [pid 488669:tid 488852] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/cgi-bin/wp-mail.php"] [unique_id "apPkD9Rh6OewFvqQpDlZTgAAATc"]
[Sun Aug 30 03:04:31.558803 2026] [security2:error] [pid 488669:tid 488816] [client 20.63.81.20:58976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/d7.php"] [unique_id "apPkD9Rh6OewFvqQpDlZYQAAARM"]
[Sun Aug 30 03:04:31.566111 2026] [security2:error] [pid 488669:tid 488918] [client 20.220.10.235:21718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/pb.php"] [unique_id "apPkD9Rh6OewFvqQpDlZZgAAAXk"]
[Sun Aug 30 03:04:31.568231 2026] [authz_core:error] [pid 488669:tid 488909] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fbind%2Fsample
[Sun Aug 30 03:04:31.568669 2026] [authz_core:error] [pid 488669:tid 488909] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fbind%2Fsample
[Sun Aug 30 03:04:31.576362 2026] [security2:error] [pid 488669:tid 488842] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/api/staging/.env"] [unique_id "apPkD9Rh6OewFvqQpDlZagAAAS0"]
[Sun Aug 30 03:04:31.590873 2026] [security2:error] [pid 488669:tid 488906] [client 20.220.10.235:33794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/wp-login.php"] [unique_id "apPkD9Rh6OewFvqQpDlZcAAAAW0"]
[Sun Aug 30 03:04:31.618176 2026] [security2:error] [pid 488669:tid 488853] [client 20.220.10.235:49121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/ls.php"] [unique_id "apPkD9Rh6OewFvqQpDlZcwAAATg"]
[Sun Aug 30 03:04:31.630705 2026] [security2:error] [pid 488669:tid 488908] [client 20.220.204.93:10977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/knmt.php"] [unique_id "apPkD9Rh6OewFvqQpDlZdwAAAW8"]
[Sun Aug 30 03:04:31.646674 2026] [security2:error] [pid 488669:tid 488861] [client 68.155.159.216:59360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/install.php"] [unique_id "apPkD9Rh6OewFvqQpDlZegAAAUA"]
[Sun Aug 30 03:04:31.655277 2026] [security2:error] [pid 488669:tid 488871] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "apPkD9Rh6OewFvqQpDlZfgAAAUo"]
[Sun Aug 30 03:04:31.655635 2026] [authz_core:error] [pid 488669:tid 488821] [client 66.249.66.73:50305] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:31.655921 2026] [authz_core:error] [pid 488669:tid 488821] [client 66.249.66.73:50305] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:31.670101 2026] [security2:error] [pid 488669:tid 488934] [client 20.151.200.44:58830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/txets.php"] [unique_id "apPkD9Rh6OewFvqQpDlZgwAAAYk"]
[Sun Aug 30 03:04:31.677588 2026] [security2:error] [pid 488669:tid 488866] [client 34.16.144.252:14772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/.env.production.bak"] [unique_id "apPkD9Rh6OewFvqQpDlZhgAAAUU"]
[Sun Aug 30 03:04:31.677706 2026] [security2:error] [pid 488669:tid 488866] [client 34.16.144.252:14772] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/.env.production.bak"] [unique_id "apPkD9Rh6OewFvqQpDlZhgAAAUU"]
[Sun Aug 30 03:04:31.689613 2026] [security2:error] [pid 488669:tid 488857] [client 34.16.144.252:14790] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/.env.development.local"] [unique_id "apPkD9Rh6OewFvqQpDlZhQAAATw"]
[Sun Aug 30 03:04:31.698445 2026] [security2:error] [pid 488669:tid 488882] [client 20.220.10.235:21614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/pk.php"] [unique_id "apPkD9Rh6OewFvqQpDlZjAAAAVU"]
[Sun Aug 30 03:04:31.698947 2026] [security2:error] [pid 488669:tid 488839] [client 20.63.81.20:58977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/v5.php"] [unique_id "apPkD9Rh6OewFvqQpDlZjQAAASo"]
[Sun Aug 30 03:04:31.702974 2026] [security2:error] [pid 488669:tid 488867] [client 34.16.144.252:14790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/service/.env"] [unique_id "apPkD9Rh6OewFvqQpDlZjwAAAUY"]
[Sun Aug 30 03:04:31.717025 2026] [security2:error] [pid 488669:tid 488904] [client 34.16.144.252:14790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/.env.orig"] [unique_id "apPkD9Rh6OewFvqQpDlZlgAAAWs"]
[Sun Aug 30 03:04:31.718658 2026] [security2:error] [pid 488669:tid 488807] [client 20.220.10.235:33835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/wp-access.php"] [unique_id "apPkD9Rh6OewFvqQpDlZmAAAAQo"]
[Sun Aug 30 03:04:31.719298 2026] [security2:error] [pid 488669:tid 488819] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/vendor/.env"] [unique_id "apPkD9Rh6OewFvqQpDlZmQAAARY"]
[Sun Aug 30 03:04:31.720578 2026] [security2:error] [pid 488669:tid 488894] [client 20.196.209.81:11596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/salient/css/build/plugins/login.php"] [unique_id "apPkD9Rh6OewFvqQpDlZnAAAAWE"]
[Sun Aug 30 03:04:31.725274 2026] [security2:error] [pid 488669:tid 488697] [remote 74.7.242.63:51114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.ltr7.com"] [uri "/xml/3D\\"https:/www.law360.com/media/articles/images/top.jpg"] [unique_id "apPkD9Rh6OewFvqQpDlZnwABHhM"], referer: https://mail.ltr7.com/xml/3D%22https:/www.law360.com/media/articles/images/top.jpg?p=%2F%2Fetc
[Sun Aug 30 03:04:31.729293 2026] [security2:error] [pid 488669:tid 488840] [client 34.16.144.252:14790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.144.16.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alchemancer.com"] [uri "/.env.php"] [unique_id "apPkD9Rh6OewFvqQpDlZpAAAASs"]
[Sun Aug 30 03:04:31.734201 2026] [security2:error] [pid 488669:tid 488927] [client 20.104.50.220:52820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/Uploading.php"] [unique_id "apPkD9Rh6OewFvqQpDlZpgAAAYI"]
[Sun Aug 30 03:04:31.757577 2026] [security2:error] [pid 488669:tid 488812] [client 20.220.10.235:49617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/css/000.php"] [unique_id "apPkD9Rh6OewFvqQpDlZqwAAAQ8"]
[Sun Aug 30 03:04:31.771344 2026] [security2:error] [pid 488669:tid 488891] [client 20.197.61.180:3907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/login.php"] [unique_id "apPkD9Rh6OewFvqQpDlZsAAAAV4"]
[Sun Aug 30 03:04:31.774148 2026] [security2:error] [pid 488669:tid 488923] [client 20.220.204.93:10962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/sbhu.php"] [unique_id "apPkD9Rh6OewFvqQpDlZswAAAX4"]
[Sun Aug 30 03:04:31.775352 2026] [authz_core:error] [pid 488669:tid 488849] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fman%2Fman7
[Sun Aug 30 03:04:31.775725 2026] [authz_core:error] [pid 488669:tid 488849] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fman%2Fman7
[Sun Aug 30 03:04:31.777372 2026] [security2:error] [pid 488669:tid 488897] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/chosen.php"] [unique_id "apPkD9Rh6OewFvqQpDlZtAAAAWQ"]
[Sun Aug 30 03:04:31.780702 2026] [security2:error] [pid 488669:tid 488826] [client 34.16.144.252:14772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/deploy/.env"] [unique_id "apPkD9Rh6OewFvqQpDlZtQAAAR0"]
[Sun Aug 30 03:04:31.784728 2026] [security2:error] [pid 488669:tid 488824] [client 20.104.50.220:33042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/venom.php"] [unique_id "apPkD9Rh6OewFvqQpDlZtwAAARs"]
[Sun Aug 30 03:04:31.825497 2026] [security2:error] [pid 488669:tid 488857] [client 20.63.81.20:59133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/az.php"] [unique_id "apPkD9Rh6OewFvqQpDlZwAAAATw"]
[Sun Aug 30 03:04:31.826377 2026] [security2:error] [pid 488669:tid 488832] [client 20.220.10.235:21794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/ft.php"] [unique_id "apPkD9Rh6OewFvqQpDlZwQAAASM"]
[Sun Aug 30 03:04:31.830005 2026] [security2:error] [pid 488669:tid 488859] [client 34.16.144.252:14772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/app/.env.backup"] [unique_id "apPkD9Rh6OewFvqQpDlZwgAAAT4"]
[Sun Aug 30 03:04:31.842473 2026] [security2:error] [pid 488669:tid 488896] [client 34.16.144.252:14752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/backend/.env.backup"] [unique_id "apPkD9Rh6OewFvqQpDlZyAAAAWM"]
[Sun Aug 30 03:04:31.848731 2026] [security2:error] [pid 488669:tid 488814] [client 20.220.10.235:33843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/wp-content/admin.php"] [unique_id "apPkD9Rh6OewFvqQpDlZywAAARE"]
[Sun Aug 30 03:04:31.854877 2026] [authz_core:error] [pid 488669:tid 488837] [client 66.249.66.99:46633] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:31.855168 2026] [authz_core:error] [pid 488669:tid 488837] [client 66.249.66.99:46633] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:31.860100 2026] [security2:error] [pid 488669:tid 488865] [client 20.104.50.220:29748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/globales.php"] [unique_id "apPkD9Rh6OewFvqQpDlZzwAAAUQ"]
[Sun Aug 30 03:04:31.866053 2026] [security2:error] [pid 488669:tid 488807] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/lib/.env"] [unique_id "apPkD9Rh6OewFvqQpDlZ0QAAAQo"]
[Sun Aug 30 03:04:31.869223 2026] [security2:error] [pid 488669:tid 488894] [client 20.104.49.130:63568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/ab.php"] [unique_id "apPkD9Rh6OewFvqQpDlZ1AAAAWE"]
[Sun Aug 30 03:04:31.881215 2026] [security2:error] [pid 488669:tid 488926] [client 20.48.251.3:59319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/queue.php"] [unique_id "apPkD9Rh6OewFvqQpDlZ1gAAAYE"]
[Sun Aug 30 03:04:31.882496 2026] [security2:error] [pid 488669:tid 488875] [client 34.16.144.252:14772] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/services/.env.production"] [unique_id "apPkD9Rh6OewFvqQpDlZ1QAAAU4"]
[Sun Aug 30 03:04:31.882610 2026] [security2:error] [pid 488669:tid 488874] [client 34.16.144.252:14752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/env.bak"] [unique_id "apPkD9Rh6OewFvqQpDlZ1wAAAU0"]
[Sun Aug 30 03:04:31.888236 2026] [security2:error] [pid 488669:tid 488869] [client 20.220.10.235:49649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/cy.php"] [unique_id "apPkD9Rh6OewFvqQpDlZ2AAAAUg"]
[Sun Aug 30 03:04:31.894868 2026] [security2:error] [pid 488669:tid 488843] [client 34.16.144.252:14752] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpcontacts.alchemancer.com"] [uri "/services/api/.env"] [unique_id "apPkD9Rh6OewFvqQpDlZ2QAAAS4"]
[Sun Aug 30 03:04:31.896971 2026] [security2:error] [pid 488669:tid 488816] [client 34.16.144.252:14772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpcontacts.alchemancer.com"] [uri "/___proxy_subdomain_cpcontacts/env.old"] [unique_id "apPkD9Rh6OewFvqQpDlZ2gAAARM"]
[Sun Aug 30 03:04:31.906934 2026] [security2:error] [pid 488669:tid 488900] [client 68.155.159.216:59905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/goods.php"] [unique_id "apPkD9Rh6OewFvqQpDlZ3gAAAWc"]
[Sun Aug 30 03:04:31.910121 2026] [security2:error] [pid 488669:tid 488903] [client 34.16.144.252:14772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.144.16.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alchemancer.com"] [uri "/config/config.php"] [unique_id "apPkD9Rh6OewFvqQpDlZ3wAAAWo"]
[Sun Aug 30 03:04:31.941211 2026] [security2:error] [pid 488669:tid 488825] [client 20.220.204.93:46921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/a332.php"] [unique_id "apPkD9Rh6OewFvqQpDlZ5AAAARw"]
[Sun Aug 30 03:04:31.952466 2026] [security2:error] [pid 488669:tid 488811] [client 20.48.251.3:44250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/error_log.php"] [unique_id "apPkD9Rh6OewFvqQpDlZ5wAAAQ4"]
[Sun Aug 30 03:04:31.956104 2026] [security2:error] [pid 488669:tid 488815] [client 20.63.81.20:59113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/js.php"] [unique_id "apPkD9Rh6OewFvqQpDlZ6AAAARI"]
[Sun Aug 30 03:04:31.963809 2026] [security2:error] [pid 488669:tid 488851] [client 158.23.147.79:55049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apPkD9Rh6OewFvqQpDlZ7QAAATY"]
[Sun Aug 30 03:04:31.966333 2026] [security2:error] [pid 488669:tid 488845] [client 20.48.251.3:49970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/koiy.php"] [unique_id "apPkD9Rh6OewFvqQpDlZ7gAAATA"]
[Sun Aug 30 03:04:31.967563 2026] [security2:error] [pid 488669:tid 488842] [client 20.220.10.235:21809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/wp-ver.php"] [unique_id "apPkD9Rh6OewFvqQpDlZ7wAAAS0"]
[Sun Aug 30 03:04:31.977756 2026] [security2:error] [pid 488669:tid 488836] [client 20.220.10.235:33806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/log.php"] [unique_id "apPkD9Rh6OewFvqQpDlZ8gAAASc"]
[Sun Aug 30 03:04:31.978966 2026] [security2:error] [pid 488669:tid 488929] [client 20.48.251.3:7083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/localconf.php"] [unique_id "apPkD9Rh6OewFvqQpDlZ8wAAAYQ"]
[Sun Aug 30 03:04:32.009736 2026] [security2:error] [pid 488669:tid 488853] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/resources/.env"] [unique_id "apPkENRh6OewFvqQpDlZ_QAAATg"]
[Sun Aug 30 03:04:32.017815 2026] [security2:error] [pid 488669:tid 488910] [client 20.220.10.235:49092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/admin.php/pindex.php"] [unique_id "apPkENRh6OewFvqQpDlaBAAAAXE"]
[Sun Aug 30 03:04:32.017904 2026] [security2:error] [pid 488669:tid 488813] [client 20.48.251.3:59094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/mamzi.php"] [unique_id "apPkENRh6OewFvqQpDlaBQAAARA"]
[Sun Aug 30 03:04:32.025505 2026] [security2:error] [pid 488669:tid 488832] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/class-wp-logo-new.php"] [unique_id "apPkENRh6OewFvqQpDlaBwAAASM"]
[Sun Aug 30 03:04:32.065352 2026] [authz_core:error] [pid 488669:tid 488843] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fbind%2Fsample
[Sun Aug 30 03:04:32.065622 2026] [authz_core:error] [pid 488669:tid 488843] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fbind%2Fsample
[Sun Aug 30 03:04:32.085019 2026] [authz_core:error] [pid 488669:tid 488830] [client 216.73.216.128:43831] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:32.085305 2026] [authz_core:error] [pid 488669:tid 488830] [client 216.73.216.128:43831] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:32.087989 2026] [security2:error] [pid 488669:tid 488811] [client 20.63.81.20:59086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/hd.php"] [unique_id "apPkENRh6OewFvqQpDlaIQAAAQ4"]
[Sun Aug 30 03:04:32.092129 2026] [security2:error] [pid 488669:tid 488922] [client 20.104.50.220:5531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/222.php"] [unique_id "apPkENRh6OewFvqQpDlaIwAAAX0"]
[Sun Aug 30 03:04:32.093880 2026] [security2:error] [pid 488669:tid 488907] [client 20.220.204.93:49177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/ws66.php"] [unique_id "apPkENRh6OewFvqQpDlaJQAAAW4"]
[Sun Aug 30 03:04:32.094726 2026] [security2:error] [pid 488669:tid 488927] [client 20.220.10.235:21628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/ah24.php"] [unique_id "apPkENRh6OewFvqQpDlaJwAAAYI"]
[Sun Aug 30 03:04:32.108861 2026] [security2:error] [pid 488669:tid 488877] [client 20.220.10.235:33697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/xwpg.php"] [unique_id "apPkENRh6OewFvqQpDlaLwAAAVA"]
[Sun Aug 30 03:04:32.116214 2026] [security2:error] [pid 488669:tid 488909] [client 20.196.209.81:17541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/security.php"] [unique_id "apPkENRh6OewFvqQpDlaMQAAAXA"]
[Sun Aug 30 03:04:32.120717 2026] [security2:error] [pid 488669:tid 488920] [client 20.104.50.220:61447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/xl33t.php"] [unique_id "apPkENRh6OewFvqQpDlaMwAAAXs"]
[Sun Aug 30 03:04:32.143398 2026] [security2:error] [pid 488669:tid 488844] [client 20.104.50.220:47082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/foxwsov2.php"] [unique_id "apPkENRh6OewFvqQpDlaOQAAAS8"]
[Sun Aug 30 03:04:32.147873 2026] [security2:error] [pid 488669:tid 488871] [client 20.220.10.235:49624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/admin.php/csv.php"] [unique_id "apPkENRh6OewFvqQpDlaOwAAAUo"]
[Sun Aug 30 03:04:32.148055 2026] [security2:error] [pid 488669:tid 488934] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/classwithtostring.php"] [unique_id "apPkENRh6OewFvqQpDlaPAAAAYk"]
[Sun Aug 30 03:04:32.150039 2026] [security2:error] [pid 488669:tid 488925] [client 20.104.50.220:29121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/moon.php"] [unique_id "apPkENRh6OewFvqQpDlaPQAAAYA"]
[Sun Aug 30 03:04:32.152749 2026] [security2:error] [pid 488669:tid 488848] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/assets/.env"] [unique_id "apPkENRh6OewFvqQpDlaPgAAATM"]
[Sun Aug 30 03:04:32.156090 2026] [security2:error] [pid 488669:tid 488866] [client 20.48.251.3:44340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/phpinfo01.php"] [unique_id "apPkENRh6OewFvqQpDlaQAAAAUU"]
[Sun Aug 30 03:04:32.179050 2026] [security2:error] [pid 488669:tid 488876] [client 158.23.147.79:61448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/packed.php"] [unique_id "apPkENRh6OewFvqQpDlaSgAAAU8"]
[Sun Aug 30 03:04:32.235419 2026] [security2:error] [pid 488669:tid 488920] [client 20.63.81.20:59112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/xl2023.php"] [unique_id "apPkENRh6OewFvqQpDlaagAAAXs"]
[Sun Aug 30 03:04:32.237128 2026] [security2:error] [pid 488669:tid 488822] [client 20.220.10.235:33820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/sxxb.php"] [unique_id "apPkENRh6OewFvqQpDlabQAAARk"]
[Sun Aug 30 03:04:32.265686 2026] [security2:error] [pid 488669:tid 488823] [client 20.220.10.235:21598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/wp-admin/zwso.php"] [unique_id "apPkENRh6OewFvqQpDlafAAAARo"]
[Sun Aug 30 03:04:32.266948 2026] [authz_core:error] [pid 488669:tid 488873] [client 216.73.216.128:43831] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:32.267224 2026] [authz_core:error] [pid 488669:tid 488873] [client 216.73.216.128:43831] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:32.269657 2026] [security2:error] [pid 488669:tid 488917] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/cms.php"] [unique_id "apPkENRh6OewFvqQpDlafwAAAXg"]
[Sun Aug 30 03:04:32.276576 2026] [security2:error] [pid 488669:tid 488880] [client 20.220.10.235:49618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/admin.php/700.php"] [unique_id "apPkENRh6OewFvqQpDlaggAAAVM"]
[Sun Aug 30 03:04:32.289854 2026] [security2:error] [pid 488669:tid 488860] [client 20.104.50.220:32539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-content/uploads/simple-file-list/shell.php"] [unique_id "apPkENRh6OewFvqQpDlahgAAAT8"]
[Sun Aug 30 03:04:32.296817 2026] [security2:error] [pid 488669:tid 488833] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/uploads/.env"] [unique_id "apPkENRh6OewFvqQpDlajQAAASQ"]
[Sun Aug 30 03:04:32.302128 2026] [authz_core:error] [pid 488669:tid 488874] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fman%2Fman7
[Sun Aug 30 03:04:32.302603 2026] [authz_core:error] [pid 488669:tid 488874] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fman%2Fman7
[Sun Aug 30 03:04:32.319285 2026] [security2:error] [pid 488669:tid 488918] [client 20.220.204.93:10286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/ws68.php"] [unique_id "apPkENRh6OewFvqQpDlaowAAAXk"]
[Sun Aug 30 03:04:32.328974 2026] [security2:error] [pid 488669:tid 488821] [client 20.104.18.15:9032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apPkENRh6OewFvqQpDlarQAAARg"]
[Sun Aug 30 03:04:32.363124 2026] [security2:error] [pid 488669:tid 488891] [client 20.63.81.20:59101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/V2.php"] [unique_id "apPkENRh6OewFvqQpDlatwAAAV4"]
[Sun Aug 30 03:04:32.368536 2026] [security2:error] [pid 488669:tid 488860] [client 20.151.200.44:46977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/sxxb.php"] [unique_id "apPkENRh6OewFvqQpDlauwAAAT8"]
[Sun Aug 30 03:04:32.368690 2026] [security2:error] [pid 488669:tid 488926] [client 20.220.10.235:33792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/dx.php"] [unique_id "apPkENRh6OewFvqQpDlauQAAAYE"]
[Sun Aug 30 03:04:32.381293 2026] [security2:error] [pid 488669:tid 488814] [client 20.104.49.130:34499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/133.php"] [unique_id "apPkENRh6OewFvqQpDlavwAAARE"]
[Sun Aug 30 03:04:32.391784 2026] [security2:error] [pid 488669:tid 488847] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/config.php"] [unique_id "apPkENRh6OewFvqQpDlazQAAATI"]
[Sun Aug 30 03:04:32.396232 2026] [security2:error] [pid 488669:tid 488919] [client 20.220.10.235:21569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.andrewharrison.net"] [uri "/waf.php"] [unique_id "apPkENRh6OewFvqQpDla0gAAAXo"]
[Sun Aug 30 03:04:32.405429 2026] [security2:error] [pid 488669:tid 488850] [client 20.220.10.235:49645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/admin.php/007x.php"] [unique_id "apPkENRh6OewFvqQpDla2gAAATU"]
[Sun Aug 30 03:04:32.441675 2026] [security2:error] [pid 488669:tid 488897] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/internal/.env"] [unique_id "apPkENRh6OewFvqQpDla_QAAAWQ"]
[Sun Aug 30 03:04:32.442205 2026] [security2:error] [pid 488669:tid 488827] [client 20.104.18.15:31671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/drykl.php"] [unique_id "apPkENRh6OewFvqQpDlbAgAAAR4"]
[Sun Aug 30 03:04:32.445179 2026] [security2:error] [pid 488669:tid 488882] [client 4.205.62.107:18639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/upload.form.php"] [unique_id "apPkENRh6OewFvqQpDlbBgAAAVU"]
[Sun Aug 30 03:04:32.467255 2026] [security2:error] [pid 488669:tid 488909] [client 20.197.61.180:9169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/min.php"] [unique_id "apPkENRh6OewFvqQpDlbHQAAAXA"]
[Sun Aug 30 03:04:32.482721 2026] [security2:error] [pid 488669:tid 488866] [client 158.23.147.79:61498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-content/packed.php"] [unique_id "apPkENRh6OewFvqQpDlbKQAAAUU"]
[Sun Aug 30 03:04:32.491230 2026] [security2:error] [pid 488669:tid 488878] [client 20.63.81.20:58970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/mad.php"] [unique_id "apPkENRh6OewFvqQpDlbMAAAAVE"]
[Sun Aug 30 03:04:32.502234 2026] [security2:error] [pid 488669:tid 488872] [client 20.220.10.235:33726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPkENRh6OewFvqQpDlbOwAAAUs"]
[Sun Aug 30 03:04:32.505533 2026] [security2:error] [pid 488669:tid 488894] [client 20.196.209.81:5919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "apPkENRh6OewFvqQpDlbQAAAAWE"]
[Sun Aug 30 03:04:32.509491 2026] [security2:error] [pid 488669:tid 488920] [client 4.205.62.107:25779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/hosty.php"] [unique_id "apPkENRh6OewFvqQpDlbQQAAAXs"]
[Sun Aug 30 03:04:32.514113 2026] [security2:error] [pid 488669:tid 488850] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/configs.php"] [unique_id "apPkENRh6OewFvqQpDlbRQAAATU"]
[Sun Aug 30 03:04:32.519441 2026] [security2:error] [pid 488669:tid 488814] [client 20.220.204.93:10268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/users.php"] [unique_id "apPkENRh6OewFvqQpDlbSQAAARE"]
[Sun Aug 30 03:04:32.540851 2026] [security2:error] [pid 488669:tid 488807] [client 20.220.10.235:49090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/admin.php/heex.php"] [unique_id "apPkENRh6OewFvqQpDlbWgAAAQo"]
[Sun Aug 30 03:04:32.544462 2026] [security2:error] [pid 488669:tid 488848] [client 4.205.62.107:27269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/paypal.php"] [unique_id "apPkENRh6OewFvqQpDlbWwAAATM"]
[Sun Aug 30 03:04:32.550327 2026] [security2:error] [pid 488669:tid 488861] [client 20.104.49.130:26893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trinitytechnologics.com"] [uri "/ortasekerli1.php"] [unique_id "apPkENRh6OewFvqQpDlbXwAAAUA"]
[Sun Aug 30 03:04:32.571635 2026] [security2:error] [pid 488669:tid 488859] [client 20.48.251.3:64500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/wp-blog.php"] [unique_id "apPkENRh6OewFvqQpDlbZwAAAT4"]
[Sun Aug 30 03:04:32.574573 2026] [security2:error] [pid 488669:tid 488855] [client 20.104.50.220:51577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/work.php"] [unique_id "apPkENRh6OewFvqQpDlbaQAAATo"]
[Sun Aug 30 03:04:32.574902 2026] [security2:error] [pid 488669:tid 488876] [client 4.205.62.107:64053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/env.php"] [unique_id "apPkENRh6OewFvqQpDlbagAAAU8"]
[Sun Aug 30 03:04:32.580754 2026] [security2:error] [pid 488669:tid 488880] [client 20.48.251.3:54749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/phina.php"] [unique_id "apPkENRh6OewFvqQpDlbbAAAAVM"]
[Sun Aug 30 03:04:32.584841 2026] [security2:error] [pid 488669:tid 488841] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/tools/.env"] [unique_id "apPkENRh6OewFvqQpDlbcgAAASw"]
[Sun Aug 30 03:04:32.606567 2026] [authz_core:error] [pid 488669:tid 488889] [client 66.249.66.77:56656] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:32.607011 2026] [authz_core:error] [pid 488669:tid 488889] [client 66.249.66.77:56656] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:32.609448 2026] [authz_core:error] [pid 488669:tid 488815] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fdocs
[Sun Aug 30 03:04:32.609769 2026] [authz_core:error] [pid 488669:tid 488815] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fdocs
[Sun Aug 30 03:04:32.629697 2026] [security2:error] [pid 488669:tid 488915] [client 20.220.10.235:33810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/xda.php"] [unique_id "apPkENRh6OewFvqQpDlbfwAAAXY"]
[Sun Aug 30 03:04:32.641026 2026] [security2:error] [pid 488669:tid 488918] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/configuration.php"] [unique_id "apPkENRh6OewFvqQpDlbhAAAAXk"]
[Sun Aug 30 03:04:32.641933 2026] [security2:error] [pid 488669:tid 488909] [client 20.63.81.20:58969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/st.php"] [unique_id "apPkENRh6OewFvqQpDlbhQAAAXA"]
[Sun Aug 30 03:04:32.660249 2026] [security2:error] [pid 488669:tid 488857] [client 20.104.49.130:58195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.katbacon.com"] [uri "/tool.php"] [unique_id "apPkENRh6OewFvqQpDlbjQAAATw"]
[Sun Aug 30 03:04:32.668719 2026] [security2:error] [pid 488669:tid 488860] [client 20.220.10.235:49614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/tf.php"] [unique_id "apPkENRh6OewFvqQpDlbjgAAAT8"]
[Sun Aug 30 03:04:32.681770 2026] [security2:error] [pid 488669:tid 488848] [client 20.220.204.93:10365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/bzjdlofz.php"] [unique_id "apPkENRh6OewFvqQpDlbkAAAATM"]
[Sun Aug 30 03:04:32.723131 2026] [security2:error] [pid 488669:tid 488809] [client 158.23.147.79:61464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-l0gin.php"] [unique_id "apPkENRh6OewFvqQpDlbmwAAAQw"]
[Sun Aug 30 03:04:32.733003 2026] [security2:error] [pid 488669:tid 488839] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/scripts/.env"] [unique_id "apPkENRh6OewFvqQpDlbngAAASo"]
[Sun Aug 30 03:04:32.763853 2026] [security2:error] [pid 488669:tid 488826] [client 68.155.159.216:52816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-content/x/index.php"] [unique_id "apPkENRh6OewFvqQpDlbowAAAR0"]
[Sun Aug 30 03:04:32.766032 2026] [security2:error] [pid 488669:tid 488904] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/content.php"] [unique_id "apPkENRh6OewFvqQpDlbpAAAAWs"]
[Sun Aug 30 03:04:32.767372 2026] [security2:error] [pid 488669:tid 488892] [client 20.220.10.235:33815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPkENRh6OewFvqQpDlbpQAAAV8"]
[Sun Aug 30 03:04:32.769227 2026] [authz_core:error] [pid 488669:tid 488929] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fman%2Fman7
[Sun Aug 30 03:04:32.769535 2026] [authz_core:error] [pid 488669:tid 488929] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fman%2Fman7
[Sun Aug 30 03:04:32.778624 2026] [security2:error] [pid 488669:tid 488901] [client 20.63.81.20:58950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/alfanew.php"] [unique_id "apPkENRh6OewFvqQpDlbqwAAAWg"]
[Sun Aug 30 03:04:32.795753 2026] [security2:error] [pid 488669:tid 488835] [client 20.220.10.235:49638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/update/da222.php"] [unique_id "apPkENRh6OewFvqQpDlbrwAAASY"]
[Sun Aug 30 03:04:32.831667 2026] [security2:error] [pid 488669:tid 488881] [client 4.205.62.107:5065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/session.php"] [unique_id "apPkENRh6OewFvqQpDlbtQAAAVQ"]
[Sun Aug 30 03:04:32.840438 2026] [security2:error] [pid 488669:tid 488909] [client 20.220.204.93:49155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/selesai.php"] [unique_id "apPkENRh6OewFvqQpDlbuQAAAXA"]
[Sun Aug 30 03:04:32.848068 2026] [security2:error] [pid 488669:tid 488908] [client 4.205.62.107:58328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/packed.php"] [unique_id "apPkENRh6OewFvqQpDlbvAAAAW8"]
[Sun Aug 30 03:04:32.855793 2026] [security2:error] [pid 488669:tid 488877] [client 4.205.62.107:58162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/phina.php"] [unique_id "apPkENRh6OewFvqQpDlbvQAAAVA"]
[Sun Aug 30 03:04:32.872938 2026] [security2:error] [pid 488669:tid 488916] [client 20.104.50.220:52837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/ip.php"] [unique_id "apPkENRh6OewFvqQpDlbvwAAAXc"]
[Sun Aug 30 03:04:32.877764 2026] [security2:error] [pid 488669:tid 488824] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/bin/.env"] [unique_id "apPkENRh6OewFvqQpDlbwAAAARs"]
[Sun Aug 30 03:04:32.891733 2026] [security2:error] [pid 488669:tid 488899] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/core.php"] [unique_id "apPkENRh6OewFvqQpDlbwQAAAWY"]
[Sun Aug 30 03:04:32.893746 2026] [security2:error] [pid 488669:tid 488811] [client 20.104.49.130:34508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/one.php"] [unique_id "apPkENRh6OewFvqQpDlbwgAAAQ4"]
[Sun Aug 30 03:04:32.899252 2026] [security2:error] [pid 488669:tid 488857] [client 158.23.147.79:55168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apPkENRh6OewFvqQpDlbwwAAATw"]
[Sun Aug 30 03:04:32.902909 2026] [security2:error] [pid 488669:tid 488861] [client 20.220.10.235:33666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/t00l.php"] [unique_id "apPkENRh6OewFvqQpDlbxgAAAUA"]
[Sun Aug 30 03:04:32.906972 2026] [authz_core:error] [pid 488669:tid 488860] [client 66.249.66.73:50305] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:32.907228 2026] [security2:error] [pid 488669:tid 488812] [client 20.63.81.20:59030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/ioxi.php"] [unique_id "apPkENRh6OewFvqQpDlbyQAAAQ8"]
[Sun Aug 30 03:04:32.907232 2026] [authz_core:error] [pid 488669:tid 488860] [client 66.249.66.73:50305] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:32.924455 2026] [security2:error] [pid 488669:tid 488914] [client 20.196.209.81:6099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/system.php"] [unique_id "apPkENRh6OewFvqQpDlbzAAAAXU"]
[Sun Aug 30 03:04:32.946486 2026] [security2:error] [pid 488669:tid 488809] [client 20.220.10.235:49662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/qi.php"] [unique_id "apPkENRh6OewFvqQpDlb0wAAAQw"]
[Sun Aug 30 03:04:32.999673 2026] [security2:error] [pid 488669:tid 488825] [client 20.104.50.220:30040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/init.php"] [unique_id "apPkENRh6OewFvqQpDlb5wAAARw"]
[Sun Aug 30 03:04:33.019718 2026] [security2:error] [pid 488669:tid 488870] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/data.php"] [unique_id "apPkEdRh6OewFvqQpDlb8gAAAUk"]
[Sun Aug 30 03:04:33.023892 2026] [security2:error] [pid 488669:tid 488847] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/sbin/.env"] [unique_id "apPkEdRh6OewFvqQpDlb9AAAATI"]
[Sun Aug 30 03:04:33.026720 2026] [security2:error] [pid 488669:tid 488881] [client 20.104.49.130:47852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wondertanks.com"] [uri "/press.php"] [unique_id "apPkEdRh6OewFvqQpDlb9QAAAVQ"]
[Sun Aug 30 03:04:33.028660 2026] [security2:error] [pid 488669:tid 488909] [client 20.220.10.235:33829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/ls.php"] [unique_id "apPkEdRh6OewFvqQpDlb9wAAAXA"]
[Sun Aug 30 03:04:33.038671 2026] [security2:error] [pid 488669:tid 488934] [client 20.63.81.20:58971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/TNT.php"] [unique_id "apPkEdRh6OewFvqQpDlb_gAAAYk"]
[Sun Aug 30 03:04:33.060909 2026] [security2:error] [pid 488669:tid 488812] [client 20.220.204.93:10260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/shlo.php"] [unique_id "apPkEdRh6OewFvqQpDlcBwAAAQ8"]
[Sun Aug 30 03:04:33.072161 2026] [security2:error] [pid 488669:tid 488858] [client 20.48.251.3:64423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/bengi.php"] [unique_id "apPkEdRh6OewFvqQpDlcCwAAAT0"]
[Sun Aug 30 03:04:33.076221 2026] [security2:error] [pid 488669:tid 488822] [client 20.220.10.235:49104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/px.php"] [unique_id "apPkEdRh6OewFvqQpDlcDAAAARk"]
[Sun Aug 30 03:04:33.086335 2026] [security2:error] [pid 488669:tid 488838] [client 4.205.62.107:22928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/wpver.php"] [unique_id "apPkEdRh6OewFvqQpDlcEgAAASk"]
[Sun Aug 30 03:04:33.086615 2026] [security2:error] [pid 488669:tid 488839] [client 4.205.62.107:44876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/oc460l3x.php"] [unique_id "apPkEdRh6OewFvqQpDlcFAAAASo"]
[Sun Aug 30 03:04:33.086664 2026] [security2:error] [pid 488669:tid 488842] [client 216.73.216.128:43831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts2/wp-admin/install.php"] [unique_id "apPkEdRh6OewFvqQpDlcEwAAAS0"]
[Sun Aug 30 03:04:33.091806 2026] [security2:error] [pid 488669:tid 488925] [client 68.155.159.216:59910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apPkEdRh6OewFvqQpDlcFwAAAYA"]
[Sun Aug 30 03:04:33.091841 2026] [security2:error] [pid 488669:tid 488841] [client 20.48.251.3:44253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/phina.php"] [unique_id "apPkEdRh6OewFvqQpDlcFgAAASw"]
[Sun Aug 30 03:04:33.096396 2026] [security2:error] [pid 488669:tid 488872] [client 20.48.251.3:52843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/doc.php"] [unique_id "apPkEdRh6OewFvqQpDlcGgAAAUs"]
[Sun Aug 30 03:04:33.101243 2026] [security2:error] [pid 488669:tid 488844] [client 20.48.251.3:55542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/w.php"] [unique_id "apPkEdRh6OewFvqQpDlcIgAAAS8"]
[Sun Aug 30 03:04:33.106938 2026] [authz_core:error] [pid 488669:tid 488922] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fdocs
[Sun Aug 30 03:04:33.107273 2026] [authz_core:error] [pid 488669:tid 488922] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fdocs
[Sun Aug 30 03:04:33.147910 2026] [security2:error] [pid 488669:tid 488852] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/database.php"] [unique_id "apPkEdRh6OewFvqQpDlcLgAAATc"]
[Sun Aug 30 03:04:33.157163 2026] [security2:error] [pid 488669:tid 488934] [client 20.48.251.3:51576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/public/rip.php.php"] [unique_id "apPkEdRh6OewFvqQpDlcMAAAAYk"]
[Sun Aug 30 03:04:33.169434 2026] [security2:error] [pid 488669:tid 488918] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/local/.env"] [unique_id "apPkEdRh6OewFvqQpDlcNgAAAXk"]
[Sun Aug 30 03:04:33.173397 2026] [security2:error] [pid 488669:tid 488857] [client 20.63.81.20:59096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/cd.php"] [unique_id "apPkEdRh6OewFvqQpDlcOQAAATw"]
[Sun Aug 30 03:04:33.177839 2026] [security2:error] [pid 488669:tid 488893] [client 216.73.216.128:15072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts2/wp-admin/import.php"] [unique_id "apPkEdRh6OewFvqQpDlcOwAAAWA"]
[Sun Aug 30 03:04:33.183503 2026] [security2:error] [pid 488669:tid 488807] [client 20.220.10.235:33665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/css/000.php"] [unique_id "apPkEdRh6OewFvqQpDlcQQAAAQo"]
[Sun Aug 30 03:04:33.193679 2026] [security2:error] [pid 488669:tid 488880] [client 20.197.61.180:4040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/module.php"] [unique_id "apPkEdRh6OewFvqQpDlcSgAAAVM"]
[Sun Aug 30 03:04:33.207608 2026] [security2:error] [pid 488669:tid 488834] [client 20.220.10.235:49119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/is.php"] [unique_id "apPkEdRh6OewFvqQpDlcUgAAASU"]
[Sun Aug 30 03:04:33.212028 2026] [security2:error] [pid 488669:tid 488897] [client 20.104.50.220:32860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/vuln.php"] [unique_id "apPkEdRh6OewFvqQpDlcVAAAAWQ"]
[Sun Aug 30 03:04:33.213964 2026] [security2:error] [pid 488669:tid 488871] [client 4.205.62.107:60497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/motu.php"] [unique_id "apPkEdRh6OewFvqQpDlcVQAAAUo"]
[Sun Aug 30 03:04:33.231113 2026] [security2:error] [pid 488669:tid 488912] [client 20.104.50.220:5527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-content/index.php"] [unique_id "apPkEdRh6OewFvqQpDlcZAAAAXM"]
[Sun Aug 30 03:04:33.257749 2026] [security2:error] [pid 488669:tid 488827] [client 20.220.204.93:10332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/asax.php"] [unique_id "apPkEdRh6OewFvqQpDlccgAAAR4"]
[Sun Aug 30 03:04:33.257818 2026] [security2:error] [pid 488669:tid 488824] [client 20.104.50.220:61497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/1n73ct10n.php"] [unique_id "apPkEdRh6OewFvqQpDlccwAAARs"]
[Sun Aug 30 03:04:33.268078 2026] [authz_core:error] [pid 488669:tid 488893] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fman%2Fman7
[Sun Aug 30 03:04:33.268441 2026] [authz_core:error] [pid 488669:tid 488893] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fman%2Fman7
[Sun Aug 30 03:04:33.268825 2026] [security2:error] [pid 488669:tid 488807] [client 216.73.216.128:34158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts2/wp-admin/update-core.php"] [unique_id "apPkEdRh6OewFvqQpDlceQAAAQo"]
[Sun Aug 30 03:04:33.270540 2026] [security2:error] [pid 488669:tid 488923] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/db.php"] [unique_id "apPkEdRh6OewFvqQpDlcegAAAX4"]
[Sun Aug 30 03:04:33.280208 2026] [security2:error] [pid 488669:tid 488901] [client 20.104.49.130:48364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trinitytechnologics.com"] [uri "/t.php"] [unique_id "apPkEdRh6OewFvqQpDlcgQAAAWg"]
[Sun Aug 30 03:04:33.281132 2026] [security2:error] [pid 488669:tid 488808] [client 20.104.50.220:46863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/shellx.php"] [unique_id "apPkEdRh6OewFvqQpDlcgwAAAQs"]
[Sun Aug 30 03:04:33.295349 2026] [security2:error] [pid 488669:tid 488823] [client 20.48.251.3:44354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/cxc.php"] [unique_id "apPkEdRh6OewFvqQpDlcigAAARo"]
[Sun Aug 30 03:04:33.298430 2026] [security2:error] [pid 488669:tid 488825] [client 20.104.50.220:29143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wkwk.php"] [unique_id "apPkEdRh6OewFvqQpDlcjwAAARw"]
[Sun Aug 30 03:04:33.301087 2026] [security2:error] [pid 488669:tid 488867] [client 20.63.81.20:59131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/luuf.php"] [unique_id "apPkEdRh6OewFvqQpDlckwAAAUY"]
[Sun Aug 30 03:04:33.312249 2026] [security2:error] [pid 488669:tid 488840] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/portal/.env"] [unique_id "apPkEdRh6OewFvqQpDlcngAAASs"]
[Sun Aug 30 03:04:33.312631 2026] [security2:error] [pid 488669:tid 488863] [client 20.220.10.235:33847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/cy.php"] [unique_id "apPkEdRh6OewFvqQpDlcnwAAAUI"]
[Sun Aug 30 03:04:33.319638 2026] [security2:error] [pid 488669:tid 488812] [client 20.196.209.81:18496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/tflow/min.php"] [unique_id "apPkEdRh6OewFvqQpDlcoQAAAQ8"]
[Sun Aug 30 03:04:33.342879 2026] [security2:error] [pid 488669:tid 488807] [client 4.205.62.107:52121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/aws_sdk_settings.php"] [unique_id "apPkEdRh6OewFvqQpDlcsAAAAQo"]
[Sun Aug 30 03:04:33.343116 2026] [security2:error] [pid 488669:tid 488857] [client 4.205.62.107:2770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/database.php"] [unique_id "apPkEdRh6OewFvqQpDlcsQAAATw"]
[Sun Aug 30 03:04:33.345586 2026] [security2:error] [pid 488669:tid 488880] [client 20.220.10.235:49137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/od.php"] [unique_id "apPkEdRh6OewFvqQpDlctAAAAVM"]
[Sun Aug 30 03:04:33.359274 2026] [security2:error] [pid 488669:tid 488848] [client 216.73.216.128:10097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts2/wp-admin/upgrade.php"] [unique_id "apPkEdRh6OewFvqQpDlctQAAATM"]
[Sun Aug 30 03:04:33.376821 2026] [security2:error] [pid 488669:tid 488839] [client 4.205.62.107:35979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/aws_settings.php"] [unique_id "apPkEdRh6OewFvqQpDlcugAAASo"]
[Sun Aug 30 03:04:33.390783 2026] [security2:error] [pid 488669:tid 488873] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/default.php"] [unique_id "apPkEdRh6OewFvqQpDlczAAAAUw"]
[Sun Aug 30 03:04:33.391786 2026] [authz_core:error] [pid 488669:tid 488833] [client 66.249.66.45:52313] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:33.392067 2026] [authz_core:error] [pid 488669:tid 488833] [client 66.249.66.45:52313] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:33.423519 2026] [security2:error] [pid 488669:tid 488910] [client 20.104.50.220:31834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-content/uploads/simple-file-list/fox.php"] [unique_id "apPkEdRh6OewFvqQpDlc5AAAAXE"]
[Sun Aug 30 03:04:33.432588 2026] [security2:error] [pid 488669:tid 488901] [client 20.63.81.20:58882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/fex.php"] [unique_id "apPkEdRh6OewFvqQpDlc8QAAAWg"]
[Sun Aug 30 03:04:33.444153 2026] [security2:error] [pid 488669:tid 488912] [client 158.23.147.79:62801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPkEdRh6OewFvqQpDldAwAAAXM"]
[Sun Aug 30 03:04:33.446275 2026] [security2:error] [pid 488669:tid 488822] [client 20.220.204.93:49156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/fetch.php"] [unique_id "apPkEdRh6OewFvqQpDldBwAAARk"]
[Sun Aug 30 03:04:33.447745 2026] [security2:error] [pid 488669:tid 488844] [client 20.220.10.235:33850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/admin.php/pindex.php"] [unique_id "apPkEdRh6OewFvqQpDldCQAAAS8"]
[Sun Aug 30 03:04:33.455926 2026] [security2:error] [pid 488669:tid 488834] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/dashboard/.env"] [unique_id "apPkEdRh6OewFvqQpDldEgAAASU"]
[Sun Aug 30 03:04:33.469828 2026] [security2:error] [pid 488669:tid 488868] [client 20.104.18.15:9155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/wp-aothait.php"] [unique_id "apPkEdRh6OewFvqQpDldIgAAAUc"]
[Sun Aug 30 03:04:33.472987 2026] [security2:error] [pid 488669:tid 488923] [client 20.220.10.235:49825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/wp-the.php"] [unique_id "apPkEdRh6OewFvqQpDldJgAAAX4"]
[Sun Aug 30 03:04:33.510818 2026] [security2:error] [pid 488669:tid 488851] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/dev1s.php"] [unique_id "apPkEdRh6OewFvqQpDldSQAAATY"]
[Sun Aug 30 03:04:33.565849 2026] [security2:error] [pid 488669:tid 488846] [client 20.63.81.20:59055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/l.php"] [unique_id "apPkEdRh6OewFvqQpDldZgAAATE"]
[Sun Aug 30 03:04:33.565915 2026] [security2:error] [pid 488669:tid 488891] [client 20.104.49.130:52533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/100.php"] [unique_id "apPkEdRh6OewFvqQpDldZwAAAV4"]
[Sun Aug 30 03:04:33.576561 2026] [security2:error] [pid 488669:tid 488857] [client 20.220.10.235:33812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/admin.php/csv.php"] [unique_id "apPkEdRh6OewFvqQpDldagAAATw"]
[Sun Aug 30 03:04:33.578744 2026] [security2:error] [pid 488669:tid 488826] [client 158.23.147.79:61477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/ans.php"] [unique_id "apPkEdRh6OewFvqQpDldawAAAR0"]
[Sun Aug 30 03:04:33.584600 2026] [security2:error] [pid 488669:tid 488905] [client 4.205.62.107:18979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/aws_auth.php"] [unique_id "apPkEdRh6OewFvqQpDldcAAAAWw"]
[Sun Aug 30 03:04:33.591755 2026] [security2:error] [pid 488669:tid 488721] [remote 103.156.21.26:48092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.21.156.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/wp-login.php"] [unique_id "apPkEdRh6OewFvqQpDldbAABJis"]
[Sun Aug 30 03:04:33.600155 2026] [security2:error] [pid 488669:tid 488922] [client 20.104.49.130:64738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trinitytechnologics.com"] [uri "/wp-good.php"] [unique_id "apPkEdRh6OewFvqQpDlddQAAAX0"]
[Sun Aug 30 03:04:33.600519 2026] [security2:error] [pid 488669:tid 488892] [client 20.220.10.235:49619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/wt.php"] [unique_id "apPkEdRh6OewFvqQpDlddgAAAV8"]
[Sun Aug 30 03:04:33.602467 2026] [security2:error] [pid 488669:tid 488875] [client 20.220.204.93:10275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/vx.php"] [unique_id "apPkEdRh6OewFvqQpDldegAAAU4"]
[Sun Aug 30 03:04:33.605730 2026] [security2:error] [pid 488669:tid 488832] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/panel/.env"] [unique_id "apPkEdRh6OewFvqQpDldfQAAASM"]
[Sun Aug 30 03:04:33.608612 2026] [authz_core:error] [pid 488669:tid 488852] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fdocs
[Sun Aug 30 03:04:33.608910 2026] [authz_core:error] [pid 488669:tid 488852] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fdocs
[Sun Aug 30 03:04:33.623958 2026] [security2:error] [pid 488669:tid 488882] [client 20.104.18.15:31717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/backup.php"] [unique_id "apPkEdRh6OewFvqQpDldgQAAAVU"]
[Sun Aug 30 03:04:33.630250 2026] [security2:error] [pid 488669:tid 488871] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/dex.php"] [unique_id "apPkEdRh6OewFvqQpDldhQAAAUo"]
[Sun Aug 30 03:04:33.649391 2026] [security2:error] [pid 488669:tid 488910] [client 4.205.62.107:25902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/pass4.php"] [unique_id "apPkEdRh6OewFvqQpDldigAAAXE"]
[Sun Aug 30 03:04:33.654678 2026] [security2:error] [pid 488669:tid 488917] [client 216.73.216.128:43086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts2/wp-login.php"] [unique_id "apPkEdRh6OewFvqQpDldcgAAAXg"]
[Sun Aug 30 03:04:33.677160 2026] [security2:error] [pid 488669:tid 488829] [client 216.244.66.238:34704] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arcaneguardians.com"] [uri "/tdbhc/antique-record-player-with-horn"] [unique_id "apPkEdRh6OewFvqQpDldkgAAASA"]
[Sun Aug 30 03:04:33.677241 2026] [security2:error] [pid 488669:tid 488829] [client 216.244.66.238:34704] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "arcaneguardians.com"] [uri "/tdbhc/antique-record-player-with-horn"] [unique_id "apPkEdRh6OewFvqQpDldkgAAASA"]
[Sun Aug 30 03:04:33.703950 2026] [security2:error] [pid 488669:tid 488854] [client 20.220.10.235:33708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/admin.php/700.php"] [unique_id "apPkEdRh6OewFvqQpDldmgAAATk"]
[Sun Aug 30 03:04:33.712805 2026] [security2:error] [pid 488669:tid 488916] [client 20.63.81.20:59059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/xr.php"] [unique_id "apPkEdRh6OewFvqQpDldnAAAAXc"]
[Sun Aug 30 03:04:33.714787 2026] [security2:error] [pid 488669:tid 488918] [client 20.104.50.220:42804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-config-pantheon.php"] [unique_id "apPkEdRh6OewFvqQpDldnwAAAXk"]
[Sun Aug 30 03:04:33.718165 2026] [security2:error] [pid 488669:tid 488840] [client 20.196.209.81:6125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/tflow/pk.php"] [unique_id "apPkEdRh6OewFvqQpDldoQAAASs"]
[Sun Aug 30 03:04:33.723608 2026] [security2:error] [pid 488669:tid 488855] [client 20.48.251.3:6984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/erty.php"] [unique_id "apPkEdRh6OewFvqQpDldogAAATo"]
[Sun Aug 30 03:04:33.724386 2026] [security2:error] [pid 488669:tid 488932] [client 4.205.62.107:64012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/xve22.php"] [unique_id "apPkEdRh6OewFvqQpDldpQAAAYc"]
[Sun Aug 30 03:04:33.730953 2026] [authz_core:error] [pid 488669:tid 488860] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fman%2Fman7
[Sun Aug 30 03:04:33.731240 2026] [authz_core:error] [pid 488669:tid 488860] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fman%2Fman7
[Sun Aug 30 03:04:33.731240 2026] [security2:error] [pid 488669:tid 488826] [client 20.48.251.3:54771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/koiy.php"] [unique_id "apPkEdRh6OewFvqQpDldqQAAAR0"]
[Sun Aug 30 03:04:33.738478 2026] [security2:error] [pid 488669:tid 488881] [client 20.220.10.235:49608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/im.php"] [unique_id "apPkEdRh6OewFvqQpDldqwAAAVQ"]
[Sun Aug 30 03:04:33.748786 2026] [security2:error] [pid 488669:tid 488834] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/crm/.env"] [unique_id "apPkEdRh6OewFvqQpDldrQAAASU"]
[Sun Aug 30 03:04:33.749030 2026] [security2:error] [pid 488669:tid 488850] [client 158.23.147.79:61453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/worksec.php"] [unique_id "apPkEdRh6OewFvqQpDldrgAAATU"]
[Sun Aug 30 03:04:33.755738 2026] [security2:error] [pid 488669:tid 488842] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/disagrsxr.php"] [unique_id "apPkEdRh6OewFvqQpDldrwAAAS0"]
[Sun Aug 30 03:04:33.823522 2026] [security2:error] [pid 488669:tid 488863] [client 20.104.18.15:33746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkEdRh6OewFvqQpDldwgAAAUI"]
[Sun Aug 30 03:04:33.834350 2026] [security2:error] [pid 488669:tid 488815] [client 20.220.204.93:10309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/global.php"] [unique_id "apPkEdRh6OewFvqQpDldyAAAARI"]
[Sun Aug 30 03:04:33.836924 2026] [security2:error] [pid 488669:tid 488838] [client 20.220.10.235:33689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/admin.php/007x.php"] [unique_id "apPkEdRh6OewFvqQpDldyQAAASk"]
[Sun Aug 30 03:04:33.839168 2026] [security2:error] [pid 488669:tid 488929] [client 20.63.81.20:58946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/Q3.php"] [unique_id "apPkEdRh6OewFvqQpDldywAAAYQ"]
[Sun Aug 30 03:04:33.858606 2026] [security2:error] [pid 488669:tid 488849] [client 20.151.200.44:58924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/wp-login.php"] [unique_id "apPkEdRh6OewFvqQpDld0AAAATQ"]
[Sun Aug 30 03:04:33.864032 2026] [security2:error] [pid 488669:tid 488896] [client 162.254.25.38:53249] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "acgcomunicaciones.com"] [uri "/"] [unique_id "apPkEdRh6OewFvqQpDld0QAAAWM"]
[Sun Aug 30 03:04:33.866386 2026] [security2:error] [pid 488669:tid 488912] [client 20.220.10.235:49609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/file.php"] [unique_id "apPkEdRh6OewFvqQpDld0gAAAXM"]
[Sun Aug 30 03:04:33.869923 2026] [security2:error] [pid 488669:tid 488918] [client 68.155.159.216:52837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-includes/Requests/about.php"] [unique_id "apPkEdRh6OewFvqQpDld0wAAAXk"]
[Sun Aug 30 03:04:33.882773 2026] [security2:error] [pid 488669:tid 488878] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/domvf.php"] [unique_id "apPkEdRh6OewFvqQpDld1gAAAVE"]
[Sun Aug 30 03:04:33.892277 2026] [security2:error] [pid 488669:tid 488811] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/erp/.env"] [unique_id "apPkEdRh6OewFvqQpDld2gAAAQ4"]
[Sun Aug 30 03:04:33.902065 2026] [security2:error] [pid 488669:tid 488891] [client 158.23.147.79:62841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/x.php"] [unique_id "apPkEdRh6OewFvqQpDld2wAAAV4"]
[Sun Aug 30 03:04:33.908208 2026] [security2:error] [pid 488669:tid 488826] [client 162.254.25.38:53258] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "acgcomunicaciones.com"] [uri "/"] [unique_id "apPkEdRh6OewFvqQpDld3wAAAR0"]
[Sun Aug 30 03:04:33.915328 2026] [security2:error] [pid 488669:tid 488899] [client 20.197.61.180:9157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/ms-files.php"] [unique_id "apPkEdRh6OewFvqQpDld4QAAAWY"]
[Sun Aug 30 03:04:33.966097 2026] [security2:error] [pid 488669:tid 488822] [client 20.220.10.235:33817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/admin.php/heex.php"] [unique_id "apPkEdRh6OewFvqQpDld6QAAARk"]
[Sun Aug 30 03:04:33.969502 2026] [security2:error] [pid 488669:tid 488861] [client 20.63.81.20:59041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/Q1.php"] [unique_id "apPkEdRh6OewFvqQpDld6wAAAUA"]
[Sun Aug 30 03:04:33.989375 2026] [security2:error] [pid 488669:tid 488726] [remote 103.156.21.26:48092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.21.156.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/wp-login.php"] [unique_id "apPkEdRh6OewFvqQpDld8QABSTA"], referer: https://littlebunnycleaning.com/wp-login.php
[Sun Aug 30 03:04:34.007257 2026] [authz_core:error] [pid 488669:tid 488902] [client 216.73.216.128:6735] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:34.007709 2026] [authz_core:error] [pid 488669:tid 488902] [client 216.73.216.128:6735] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:34.007907 2026] [security2:error] [pid 488669:tid 488864] [client 20.220.10.235:49622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/ca.php"] [unique_id "apPkEtRh6OewFvqQpDld-wAAAUM"]
[Sun Aug 30 03:04:34.020589 2026] [security2:error] [pid 488669:tid 488829] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/donate.php"] [unique_id "apPkEtRh6OewFvqQpDleBAAAASA"]
[Sun Aug 30 03:04:34.020626 2026] [security2:error] [pid 488669:tid 488903] [client 4.205.62.107:5074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/h.php"] [unique_id "apPkEtRh6OewFvqQpDleBQAAAWo"]
[Sun Aug 30 03:04:34.025945 2026] [security2:error] [pid 488669:tid 488883] [client 20.104.50.220:28723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/__1975.php"] [unique_id "apPkEtRh6OewFvqQpDleBwAAAVY"]
[Sun Aug 30 03:04:34.030557 2026] [security2:error] [pid 488669:tid 488843] [client 20.151.200.44:37850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/h02ugyh.php"] [unique_id "apPkEtRh6OewFvqQpDleCgAAAS4"]
[Sun Aug 30 03:04:34.034799 2026] [security2:error] [pid 488669:tid 488877] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/shop/.env"] [unique_id "apPkEtRh6OewFvqQpDleDgAAAVA"]
[Sun Aug 30 03:04:34.082301 2026] [authz_core:error] [pid 488669:tid 488930] [client 66.249.66.198:48223] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:34.082574 2026] [authz_core:error] [pid 488669:tid 488930] [client 66.249.66.198:48223] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:34.099528 2026] [security2:error] [pid 488669:tid 488845] [client 20.220.204.93:52770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/fs.php"] [unique_id "apPkEtRh6OewFvqQpDleIgAAATA"]
[Sun Aug 30 03:04:34.100564 2026] [security2:error] [pid 488669:tid 488872] [client 20.63.81.20:58947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/nz.php"] [unique_id "apPkEtRh6OewFvqQpDleJAAAAUs"]
[Sun Aug 30 03:04:34.100940 2026] [security2:error] [pid 488669:tid 488859] [client 20.220.10.235:33675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/tf.php"] [unique_id "apPkEtRh6OewFvqQpDleJwAAAT4"]
[Sun Aug 30 03:04:34.108009 2026] [authz_core:error] [pid 488669:tid 488926] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fdocs
[Sun Aug 30 03:04:34.108281 2026] [authz_core:error] [pid 488669:tid 488926] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fdocs
[Sun Aug 30 03:04:34.116259 2026] [security2:error] [pid 488669:tid 488819] [client 20.196.209.81:23646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/theme-check/theme-check.php"] [unique_id "apPkEtRh6OewFvqQpDleLAAAARY"]
[Sun Aug 30 03:04:34.139469 2026] [security2:error] [pid 488669:tid 488838] [client 20.104.50.220:29735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/inicio.php"] [unique_id "apPkEtRh6OewFvqQpDleNAAAASk"]
[Sun Aug 30 03:04:34.147930 2026] [security2:error] [pid 488669:tid 488874] [client 158.23.147.79:61486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-content/x.php"] [unique_id "apPkEtRh6OewFvqQpDleOAAAAU0"]
[Sun Aug 30 03:04:34.154505 2026] [security2:error] [pid 488669:tid 488893] [client 20.104.49.130:45121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trinitytechnologics.com"] [uri "/as.php"] [unique_id "apPkEtRh6OewFvqQpDleOQAAAWA"]
[Sun Aug 30 03:04:34.169548 2026] [security2:error] [pid 488669:tid 488894] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/dropdown.php"] [unique_id "apPkEtRh6OewFvqQpDlePQAAAWE"]
[Sun Aug 30 03:04:34.184877 2026] [security2:error] [pid 488669:tid 488844] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/store/.env"] [unique_id "apPkEtRh6OewFvqQpDleRgAAAS8"]
[Sun Aug 30 03:04:34.190089 2026] [authz_core:error] [pid 488669:tid 488847] [client 216.73.216.128:63883] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:34.190351 2026] [authz_core:error] [pid 488669:tid 488847] [client 216.73.216.128:63883] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:34.194804 2026] [security2:error] [pid 488669:tid 488889] [client 4.205.62.107:58139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/koiy.php"] [unique_id "apPkEtRh6OewFvqQpDleTAAAAVw"]
[Sun Aug 30 03:04:34.198542 2026] [authz_core:error] [pid 488669:tid 488904] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fman%2Fman7
[Sun Aug 30 03:04:34.198849 2026] [authz_core:error] [pid 488669:tid 488904] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fman%2Fman7
[Sun Aug 30 03:04:34.215606 2026] [security2:error] [pid 488669:tid 488840] [client 4.205.62.107:44469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/drykl.php"] [unique_id "apPkEtRh6OewFvqQpDleUgAAASs"]
[Sun Aug 30 03:04:34.230870 2026] [security2:error] [pid 488669:tid 488825] [client 20.48.251.3:44243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/koiy.php"] [unique_id "apPkEtRh6OewFvqQpDleYgAAARw"]
[Sun Aug 30 03:04:34.237063 2026] [security2:error] [pid 488669:tid 488816] [client 20.48.251.3:55798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/css.php"] [unique_id "apPkEtRh6OewFvqQpDleZwAAARM"]
[Sun Aug 30 03:04:34.237512 2026] [security2:error] [pid 488669:tid 488850] [client 4.205.62.107:22570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/ah25.php"] [unique_id "apPkEtRh6OewFvqQpDleaAAAATU"]
[Sun Aug 30 03:04:34.245561 2026] [security2:error] [pid 488669:tid 488817] [client 20.63.81.20:59068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/sg.php"] [unique_id "apPkEtRh6OewFvqQpDlebgAAARQ"]
[Sun Aug 30 03:04:34.255783 2026] [security2:error] [pid 488669:tid 488876] [client 20.48.251.3:49941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/btx25.php"] [unique_id "apPkEtRh6OewFvqQpDledAAAAU8"]
[Sun Aug 30 03:04:34.291035 2026] [security2:error] [pid 488669:tid 488811] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/edit.php"] [unique_id "apPkEtRh6OewFvqQpDleiQAAAQ4"]
[Sun Aug 30 03:04:34.327845 2026] [security2:error] [pid 488669:tid 488896] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/saas/.env"] [unique_id "apPkEtRh6OewFvqQpDlepQAAAWM"]
[Sun Aug 30 03:04:34.344604 2026] [security2:error] [pid 488669:tid 488914] [client 4.205.62.107:26503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/userfuns.php"] [unique_id "apPkEtRh6OewFvqQpDlerAAAAXU"]
[Sun Aug 30 03:04:34.344770 2026] [security2:error] [pid 488669:tid 488823] [client 4.205.62.107:63790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/public/mah.php.php"] [unique_id "apPkEtRh6OewFvqQpDlerQAAARo"]
[Sun Aug 30 03:04:34.362475 2026] [security2:error] [pid 488669:tid 488878] [client 20.104.50.220:33057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/V5.php"] [unique_id "apPkEtRh6OewFvqQpDlesAAAAVE"]
[Sun Aug 30 03:04:34.378393 2026] [security2:error] [pid 488669:tid 488900] [client 20.63.81.20:59078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/hypo.php"] [unique_id "apPkEtRh6OewFvqQpDletQAAAWc"]
[Sun Aug 30 03:04:34.383480 2026] [security2:error] [pid 488669:tid 488901] [client 20.104.50.220:6084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/admin.php"] [unique_id "apPkEtRh6OewFvqQpDleugAAAWg"]
[Sun Aug 30 03:04:34.387399 2026] [security2:error] [pid 488669:tid 488874] [client 4.205.62.107:32461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/wp-info.php"] [unique_id "apPkEtRh6OewFvqQpDlewgAAAU0"]
[Sun Aug 30 03:04:34.388897 2026] [security2:error] [pid 488669:tid 488872] [client 68.155.159.216:60015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apPkEtRh6OewFvqQpDlexAAAAUs"]
[Sun Aug 30 03:04:34.397230 2026] [security2:error] [pid 488669:tid 488813] [client 20.104.50.220:59549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/not_acceptable.php"] [unique_id "apPkEtRh6OewFvqQpDlezAAAARA"]
[Sun Aug 30 03:04:34.413689 2026] [security2:error] [pid 488669:tid 488904] [client 20.220.204.93:33926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/ioxi.php"] [unique_id "apPkEtRh6OewFvqQpDle1gAAAWs"]
[Sun Aug 30 03:04:34.415291 2026] [security2:error] [pid 488669:tid 488817] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/ee.php"] [unique_id "apPkEtRh6OewFvqQpDle2AAAARQ"]
[Sun Aug 30 03:04:34.416844 2026] [security2:error] [pid 488669:tid 488910] [client 158.23.147.79:62796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPkEtRh6OewFvqQpDle2gAAAXE"]
[Sun Aug 30 03:04:34.419898 2026] [security2:error] [pid 488669:tid 488918] [client 20.104.50.220:46616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/1index.php"] [unique_id "apPkEtRh6OewFvqQpDle3gAAAXk"]
[Sun Aug 30 03:04:34.443609 2026] [security2:error] [pid 488669:tid 488808] [client 20.48.251.3:44319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/oiko6u.php"] [unique_id "apPkEtRh6OewFvqQpDle_QAAAQs"]
[Sun Aug 30 03:04:34.472724 2026] [security2:error] [pid 488669:tid 488807] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/client/.env"] [unique_id "apPkEtRh6OewFvqQpDlfIAAAAQo"]
[Sun Aug 30 03:04:34.479732 2026] [security2:error] [pid 488669:tid 488808] [client 4.205.62.107:52113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/setup-config.php"] [unique_id "apPkEtRh6OewFvqQpDlfJgAAAQs"]
[Sun Aug 30 03:04:34.481661 2026] [security2:error] [pid 488669:tid 488883] [client 4.205.62.107:3001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/atex1.php"] [unique_id "apPkEtRh6OewFvqQpDlfLAAAAVY"]
[Sun Aug 30 03:04:34.495774 2026] [security2:error] [pid 488669:tid 488835] [client 20.48.251.3:58822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/environment.php"] [unique_id "apPkEtRh6OewFvqQpDlfOQAAASY"]
[Sun Aug 30 03:04:34.506546 2026] [security2:error] [pid 488669:tid 488809] [client 20.196.209.81:6122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/theme/about.php"] [unique_id "apPkEtRh6OewFvqQpDlfQAAAAQw"]
[Sun Aug 30 03:04:34.515625 2026] [security2:error] [pid 488669:tid 488855] [client 20.104.50.220:62796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wpvitamins.php"] [unique_id "apPkEtRh6OewFvqQpDlfSAAAATo"]
[Sun Aug 30 03:04:34.518323 2026] [security2:error] [pid 488669:tid 488839] [client 20.63.81.20:59135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/Hd.php"] [unique_id "apPkEtRh6OewFvqQpDlfSwAAASo"]
[Sun Aug 30 03:04:34.540118 2026] [security2:error] [pid 488669:tid 488864] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/elp.php"] [unique_id "apPkEtRh6OewFvqQpDlfWQAAAUM"]
[Sun Aug 30 03:04:34.561196 2026] [security2:error] [pid 488669:tid 488819] [client 20.104.50.220:31928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-content/uploads/simple-file-list/fw.php"] [unique_id "apPkEtRh6OewFvqQpDlfbwAAARY"]
[Sun Aug 30 03:04:34.577638 2026] [authz_core:error] [pid 488669:tid 488905] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fdocs
[Sun Aug 30 03:04:34.577941 2026] [authz_core:error] [pid 488669:tid 488905] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fdocs
[Sun Aug 30 03:04:34.610692 2026] [security2:error] [pid 488669:tid 488904] [client 20.104.18.15:9110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/wp-includes/index.php"] [unique_id "apPkEtRh6OewFvqQpDlfgAAAAWs"]
[Sun Aug 30 03:04:34.616725 2026] [security2:error] [pid 488669:tid 488822] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/project/.env"] [unique_id "apPkEtRh6OewFvqQpDlfggAAARk"]
[Sun Aug 30 03:04:34.634351 2026] [security2:error] [pid 488669:tid 488926] [client 20.48.250.41:53313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkEtRh6OewFvqQpDlfiQAAAYE"]
[Sun Aug 30 03:04:34.636467 2026] [security2:error] [pid 488669:tid 488830] [client 20.197.61.180:4036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/news-portal/error.php"] [unique_id "apPkEtRh6OewFvqQpDlfiwAAASE"]
[Sun Aug 30 03:04:34.645514 2026] [security2:error] [pid 488669:tid 488933] [client 158.23.147.79:55078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/log-mama/function.php"] [unique_id "apPkEtRh6OewFvqQpDlfjgAAAYg"]
[Sun Aug 30 03:04:34.659078 2026] [security2:error] [pid 488669:tid 488844] [client 20.220.204.93:42420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/bootstrap.php"] [unique_id "apPkEtRh6OewFvqQpDlflAAAAS8"]
[Sun Aug 30 03:04:34.663145 2026] [security2:error] [pid 488669:tid 488872] [client 20.63.81.20:59054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/im.php"] [unique_id "apPkEtRh6OewFvqQpDlflwAAAUs"]
[Sun Aug 30 03:04:34.663167 2026] [security2:error] [pid 488669:tid 488903] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/en.php"] [unique_id "apPkEtRh6OewFvqQpDlflgAAAWo"]
[Sun Aug 30 03:04:34.668172 2026] [security2:error] [pid 488669:tid 488813] [client 34.15.145.202:59786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/phpinfo.php"] [unique_id "apPkEtRh6OewFvqQpDlfmQAAARA"]
[Sun Aug 30 03:04:34.709262 2026] [authz_core:error] [pid 488669:tid 488853] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fman%2Fman7
[Sun Aug 30 03:04:34.709542 2026] [authz_core:error] [pid 488669:tid 488853] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fman%2Fman7
[Sun Aug 30 03:04:34.725502 2026] [security2:error] [pid 488669:tid 488916] [client 4.205.62.107:18975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/hiquido.com/index.php"] [unique_id "apPkEtRh6OewFvqQpDlfqgAAAXc"]
[Sun Aug 30 03:04:34.729958 2026] [autoindex:error] [pid 488669:tid 488882] [client 65.181.116.2:40238] AH01276: Cannot serve directory /home3/tavig44/public_html/www.wellday.net/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:04:34.748165 2026] [security2:error] [pid 488669:tid 488901] [client 20.48.251.3:7070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/i.php"] [unique_id "apPkEtRh6OewFvqQpDlfswAAAWg"]
[Sun Aug 30 03:04:34.759971 2026] [security2:error] [pid 488669:tid 488897] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/admin-panel/.env"] [unique_id "apPkEtRh6OewFvqQpDlftQAAAWQ"]
[Sun Aug 30 03:04:34.760578 2026] [security2:error] [pid 488669:tid 488920] [client 20.104.18.15:31670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/indo.php"] [unique_id "apPkEtRh6OewFvqQpDlftgAAAXs"]
[Sun Aug 30 03:04:34.768971 2026] [security2:error] [pid 488669:tid 488885] [client 20.48.250.41:53341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkEtRh6OewFvqQpDlftwAAAVg"]
[Sun Aug 30 03:04:34.786552 2026] [security2:error] [pid 488669:tid 488827] [client 4.205.62.107:25525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/cu.php"] [unique_id "apPkEtRh6OewFvqQpDlfvwAAAR4"]
[Sun Aug 30 03:04:34.788330 2026] [security2:error] [pid 488669:tid 488857] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getchellgarden.com"] [uri "/error.php"] [unique_id "apPkEtRh6OewFvqQpDlfwAAAATw"]
[Sun Aug 30 03:04:34.791013 2026] [security2:error] [pid 488669:tid 488829] [client 20.63.81.20:58953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/fc.php"] [unique_id "apPkEtRh6OewFvqQpDlfwQAAASA"]
[Sun Aug 30 03:04:34.816636 2026] [security2:error] [pid 488669:tid 488847] [client 158.23.147.79:55058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/bk/index.php"] [unique_id "apPkEtRh6OewFvqQpDlfyAAAATI"]
[Sun Aug 30 03:04:34.856832 2026] [security2:error] [pid 488669:tid 488860] [client 62.60.130.247:58670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "whatwouldderriawear.com"] [uri "/wp-login.php"] [unique_id "apPkEtRh6OewFvqQpDlf0gAAAT8"], referer: https://www.google.com/search?q=wordpress
[Sun Aug 30 03:04:34.861092 2026] [security2:error] [pid 488669:tid 488819] [client 4.205.62.107:64054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/06.php"] [unique_id "apPkEtRh6OewFvqQpDlf1gAAARY"]
[Sun Aug 30 03:04:34.867640 2026] [security2:error] [pid 488669:tid 488893] [client 20.104.50.220:42014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-xmlx.php"] [unique_id "apPkEtRh6OewFvqQpDlf1wAAAWA"]
[Sun Aug 30 03:04:34.872844 2026] [security2:error] [pid 488669:tid 488877] [client 20.104.49.130:26914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trinitytechnologics.com"] [uri "/mh.php"] [unique_id "apPkEtRh6OewFvqQpDlf2QAAAVA"]
[Sun Aug 30 03:04:34.881021 2026] [security2:error] [pid 488669:tid 488839] [client 20.48.251.3:7379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/guk.php"] [unique_id "apPkEtRh6OewFvqQpDlf2gAAASo"]
[Sun Aug 30 03:04:34.902182 2026] [security2:error] [pid 488669:tid 488916] [client 20.48.251.3:64501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/wp-config.backup.php"] [unique_id "apPkEtRh6OewFvqQpDlf2wAAAXc"]
[Sun Aug 30 03:04:34.904952 2026] [security2:error] [pid 488669:tid 488894] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/control-panel/.env"] [unique_id "apPkEtRh6OewFvqQpDlf3QAAAWE"]
[Sun Aug 30 03:04:34.917179 2026] [security2:error] [pid 488669:tid 488899] [client 20.48.250.41:53369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/ff1.php"] [unique_id "apPkEtRh6OewFvqQpDlf4AAAAWY"]
[Sun Aug 30 03:04:34.925810 2026] [security2:error] [pid 488669:tid 488863] [client 20.196.209.81:11586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/theme/min.php"] [unique_id "apPkEtRh6OewFvqQpDlf4gAAAUI"]
[Sun Aug 30 03:04:34.931369 2026] [security2:error] [pid 488669:tid 488932] [client 68.155.159.216:54779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/hehehehe.php"] [unique_id "apPkEtRh6OewFvqQpDlf5QAAAYc"]
[Sun Aug 30 03:04:34.935592 2026] [security2:error] [pid 488669:tid 488870] [client 20.63.81.20:58880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/ke.php"] [unique_id "apPkEtRh6OewFvqQpDlf5wAAAUk"]
[Sun Aug 30 03:04:34.942286 2026] [security2:error] [pid 488669:tid 488866] [client 20.48.251.3:65526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/queue.php"] [unique_id "apPkEtRh6OewFvqQpDlf6AAAAUU"]
[Sun Aug 30 03:04:34.944053 2026] [security2:error] [pid 488669:tid 488837] [client 20.220.204.93:34650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/export.php"] [unique_id "apPkEtRh6OewFvqQpDlf6QAAASg"]
[Sun Aug 30 03:04:34.977419 2026] [security2:error] [pid 488669:tid 488897] [client 20.104.18.15:33736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkEtRh6OewFvqQpDlf7wAAAWQ"]
[Sun Aug 30 03:04:34.986605 2026] [security2:error] [pid 488669:tid 488922] [client 68.155.159.216:60544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-admin/includes/index.php"] [unique_id "apPkEtRh6OewFvqQpDlf8QAAAX0"]
[Sun Aug 30 03:04:35.019480 2026] [security2:error] [pid 488669:tid 488847] [client 158.23.147.79:52381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildatlanticstories.gracejolliffe.com"] [uri "/first.php"] [unique_id "apPkE9Rh6OewFvqQpDlgBQAAATI"]
[Sun Aug 30 03:04:35.056748 2026] [security2:error] [pid 488669:tid 488869] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/user-panel/.env"] [unique_id "apPkE9Rh6OewFvqQpDlgEAAAAUg"]
[Sun Aug 30 03:04:35.064579 2026] [security2:error] [pid 488669:tid 488887] [client 20.63.81.20:59056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/tf.php"] [unique_id "apPkE9Rh6OewFvqQpDlgEwAAAVo"]
[Sun Aug 30 03:04:35.073636 2026] [authz_core:error] [pid 488669:tid 488893] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fdocs
[Sun Aug 30 03:04:35.074091 2026] [authz_core:error] [pid 488669:tid 488893] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fdocs
[Sun Aug 30 03:04:35.079602 2026] [security2:error] [pid 488669:tid 488848] [client 20.48.250.41:53343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/t.php"] [unique_id "apPkE9Rh6OewFvqQpDlgFQAAATM"]
[Sun Aug 30 03:04:35.100264 2026] [security2:error] [pid 488669:tid 488817] [client 20.220.204.93:49205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/gk.php"] [unique_id "apPkE9Rh6OewFvqQpDlgHwAAARQ"]
[Sun Aug 30 03:04:35.172241 2026] [security2:error] [pid 488669:tid 488808] [client 62.60.130.247:57786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "whatwouldderriawear.com"] [uri "/wp-login.php"] [unique_id "apPkE9Rh6OewFvqQpDlgMQAAAQs"], referer: https://www.google.com/
[Sun Aug 30 03:04:35.180525 2026] [security2:error] [pid 488669:tid 488898] [client 20.104.50.220:29152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/gaya.php"] [unique_id "apPkE9Rh6OewFvqQpDlgNgAAAWU"]
[Sun Aug 30 03:04:35.195710 2026] [security2:error] [pid 488669:tid 488814] [client 4.205.62.107:5114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/bootstrap.php"] [unique_id "apPkE9Rh6OewFvqQpDlgQgAAARE"]
[Sun Aug 30 03:04:35.195876 2026] [security2:error] [pid 488669:tid 488906] [client 20.63.81.20:59044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/px.php"] [unique_id "apPkE9Rh6OewFvqQpDlgQwAAAW0"]
[Sun Aug 30 03:04:35.199477 2026] [security2:error] [pid 488669:tid 488813] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/node/.env"] [unique_id "apPkE9Rh6OewFvqQpDlgRAAAARA"]
[Sun Aug 30 03:04:35.204521 2026] [authz_core:error] [pid 488669:tid 488809] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fman%2Fman7
[Sun Aug 30 03:04:35.204975 2026] [authz_core:error] [pid 488669:tid 488809] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fman%2Fman7
[Sun Aug 30 03:04:35.221405 2026] [security2:error] [pid 488669:tid 488860] [client 20.48.250.41:53342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/erty.php"] [unique_id "apPkE9Rh6OewFvqQpDlgUAAAAT8"]
[Sun Aug 30 03:04:35.265237 2026] [security2:error] [pid 488669:tid 488807] [client 20.220.204.93:37189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/logs1.php"] [unique_id "apPkE9Rh6OewFvqQpDlgbAAAAQo"]
[Sun Aug 30 03:04:35.274770 2026] [security2:error] [pid 488669:tid 488833] [client 34.15.145.202:59796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/info.php"] [unique_id "apPkE9Rh6OewFvqQpDlgcQAAASQ"]
[Sun Aug 30 03:04:35.275081 2026] [security2:error] [pid 488669:tid 488908] [client 20.104.50.220:30056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/Model.php"] [unique_id "apPkE9Rh6OewFvqQpDlgcgAAAW8"]
[Sun Aug 30 03:04:35.276840 2026] [security2:error] [pid 488669:tid 488811] [client 216.73.216.128:63883] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPkE9Rh6OewFvqQpDlgcwAAAQ4"]
[Sun Aug 30 03:04:35.318726 2026] [security2:error] [pid 488669:tid 488836] [client 20.196.209.81:6113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/themes/about.php"] [unique_id "apPkE9Rh6OewFvqQpDlgkAAAASc"]
[Sun Aug 30 03:04:35.322612 2026] [security2:error] [pid 488669:tid 488896] [client 20.104.49.130:64741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trinitytechnologics.com"] [uri "/press.php"] [unique_id "apPkE9Rh6OewFvqQpDlgkgAAAWM"]
[Sun Aug 30 03:04:35.328561 2026] [security2:error] [pid 488669:tid 488871] [client 20.63.81.20:59130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/jg.php"] [unique_id "apPkE9Rh6OewFvqQpDlglwAAAUo"]
[Sun Aug 30 03:04:35.342096 2026] [security2:error] [pid 488669:tid 488848] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/express/.env"] [unique_id "apPkE9Rh6OewFvqQpDlgogAAATM"]
[Sun Aug 30 03:04:35.353222 2026] [security2:error] [pid 488669:tid 488839] [client 4.205.62.107:44875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/rpk.php"] [unique_id "apPkE9Rh6OewFvqQpDlgpQAAASo"]
[Sun Aug 30 03:04:35.356442 2026] [security2:error] [pid 488669:tid 488821] [client 20.197.61.180:13900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/nvt/includes/plugins/wp-blog-header.php"] [unique_id "apPkE9Rh6OewFvqQpDlgpgAAARg"]
[Sun Aug 30 03:04:35.369210 2026] [security2:error] [pid 488669:tid 488827] [client 20.48.251.3:23467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/queue.php"] [unique_id "apPkE9Rh6OewFvqQpDlgqgAAAR4"]
[Sun Aug 30 03:04:35.374416 2026] [security2:error] [pid 488669:tid 488894] [client 20.48.251.3:55789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/php_info.php"] [unique_id "apPkE9Rh6OewFvqQpDlgrQAAAWE"]
[Sun Aug 30 03:04:35.381853 2026] [security2:error] [pid 488669:tid 488846] [client 4.205.62.107:22583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/groceries/index.php"] [unique_id "apPkE9Rh6OewFvqQpDlgsQAAATE"]
[Sun Aug 30 03:04:35.398078 2026] [security2:error] [pid 488669:tid 488826] [client 4.205.62.107:36624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/wp-konfig.backup.php"] [unique_id "apPkE9Rh6OewFvqQpDlgxwAAAR0"]
[Sun Aug 30 03:04:35.402114 2026] [security2:error] [pid 488669:tid 488911] [client 20.48.251.3:55444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/app_dev.php"] [unique_id "apPkE9Rh6OewFvqQpDlgyQAAAXI"]
[Sun Aug 30 03:04:35.416873 2026] [security2:error] [pid 488669:tid 488923] [client 114.119.136.111:55333] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "littlebousquet.com"] [uri "/"] [unique_id "apPkE9Rh6OewFvqQpDlg0gAAAX4"], referer: https://littlebousquet.com/
[Sun Aug 30 03:04:35.421217 2026] [authz_core:error] [pid 488669:tid 488912] [client 66.249.66.65:54701] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:35.421526 2026] [authz_core:error] [pid 488669:tid 488912] [client 66.249.66.65:54701] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:35.427308 2026] [security2:error] [pid 488669:tid 488916] [client 4.205.62.107:65373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/queue.php"] [unique_id "apPkE9Rh6OewFvqQpDlg2gAAAXc"]
[Sun Aug 30 03:04:35.454384 2026] [security2:error] [pid 488669:tid 488813] [client 20.48.250.41:53330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/0x.php"] [unique_id "apPkE9Rh6OewFvqQpDlg_QAAARA"]
[Sun Aug 30 03:04:35.456340 2026] [security2:error] [pid 488669:tid 488908] [client 20.63.81.20:59051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/yj.php"] [unique_id "apPkE9Rh6OewFvqQpDlg_wAAAW8"]
[Sun Aug 30 03:04:35.463779 2026] [security2:error] [pid 488669:tid 488850] [client 20.220.204.93:11155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/inege.php"] [unique_id "apPkE9Rh6OewFvqQpDlhCgAAATU"]
[Sun Aug 30 03:04:35.483839 2026] [security2:error] [pid 488669:tid 488869] [client 4.205.62.107:63807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/zaza.php"] [unique_id "apPkE9Rh6OewFvqQpDlhHQAAAUg"]
[Sun Aug 30 03:04:35.487367 2026] [security2:error] [pid 488669:tid 488852] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/next/.env"] [unique_id "apPkE9Rh6OewFvqQpDlhHwAAATc"]
[Sun Aug 30 03:04:35.505632 2026] [security2:error] [pid 488669:tid 488894] [client 20.104.49.130:52342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.katbacon.com"] [uri "/abc.php"] [unique_id "apPkE9Rh6OewFvqQpDlhLAAAAWE"]
[Sun Aug 30 03:04:35.515345 2026] [security2:error] [pid 488669:tid 488908] [client 20.104.50.220:33308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/v5.php"] [unique_id "apPkE9Rh6OewFvqQpDlhNAAAAW8"]
[Sun Aug 30 03:04:35.537319 2026] [security2:error] [pid 488669:tid 488851] [client 20.104.50.220:6110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-admin/maint/maint.php"] [unique_id "apPkE9Rh6OewFvqQpDlhQgAAATY"]
[Sun Aug 30 03:04:35.556711 2026] [security2:error] [pid 488669:tid 488932] [client 20.104.50.220:46654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/2index.php"] [unique_id "apPkE9Rh6OewFvqQpDlhVAAAAYc"]
[Sun Aug 30 03:04:35.557459 2026] [authz_core:error] [pid 488669:tid 488848] [client 216.73.216.128:41722] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:35.557764 2026] [authz_core:error] [pid 488669:tid 488848] [client 216.73.216.128:41722] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:35.569800 2026] [authz_core:error] [pid 488669:tid 488859] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fdocs
[Sun Aug 30 03:04:35.570072 2026] [authz_core:error] [pid 488669:tid 488859] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fdocs
[Sun Aug 30 03:04:35.584506 2026] [security2:error] [pid 488669:tid 488882] [client 20.63.81.20:58984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/zi.php"] [unique_id "apPkE9Rh6OewFvqQpDlhYAAAAVU"]
[Sun Aug 30 03:04:35.586754 2026] [security2:error] [pid 488669:tid 488854] [client 68.155.159.216:59945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/file.php"] [unique_id "apPkE9Rh6OewFvqQpDlhYgAAATk"]
[Sun Aug 30 03:04:35.594081 2026] [security2:error] [pid 488669:tid 488894] [client 20.48.250.41:53332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/66.php"] [unique_id "apPkE9Rh6OewFvqQpDlhZgAAAWE"]
[Sun Aug 30 03:04:35.604812 2026] [security2:error] [pid 488669:tid 488909] [client 20.104.50.220:61413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/dada.php"] [unique_id "apPkE9Rh6OewFvqQpDlhawAAAXA"]
[Sun Aug 30 03:04:35.621679 2026] [security2:error] [pid 488669:tid 488911] [client 4.205.62.107:2984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/aws_sdk_settings.php"] [unique_id "apPkE9Rh6OewFvqQpDlhcgAAAXI"]
[Sun Aug 30 03:04:35.632022 2026] [security2:error] [pid 488669:tid 488839] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/nuxt/.env"] [unique_id "apPkE9Rh6OewFvqQpDlhcwAAASo"]
[Sun Aug 30 03:04:35.638326 2026] [security2:error] [pid 488669:tid 488808] [client 20.48.251.3:44368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/fraro.php"] [unique_id "apPkE9Rh6OewFvqQpDlhdgAAAQs"]
[Sun Aug 30 03:04:35.647002 2026] [security2:error] [pid 488669:tid 488900] [client 4.205.62.107:51750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/wp-admin/sc.php"] [unique_id "apPkE9Rh6OewFvqQpDlheAAAAWc"]
[Sun Aug 30 03:04:35.666102 2026] [authz_core:error] [pid 488669:tid 488835] [client 66.249.66.72:60731] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:35.666479 2026] [authz_core:error] [pid 488669:tid 488835] [client 66.249.66.72:60731] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:35.700091 2026] [authz_core:error] [pid 488669:tid 488870] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fman%2Fman7
[Sun Aug 30 03:04:35.700545 2026] [authz_core:error] [pid 488669:tid 488870] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fman%2Fman7
[Sun Aug 30 03:04:35.700555 2026] [security2:error] [pid 488669:tid 488863] [client 20.104.50.220:31917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-content/uploads/simple-file-list/alfa.php"] [unique_id "apPkE9Rh6OewFvqQpDlhhwAAAUI"]
[Sun Aug 30 03:04:35.709133 2026] [security2:error] [pid 488669:tid 488917] [client 20.196.209.81:12067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/themes/panel.php"] [unique_id "apPkE9Rh6OewFvqQpDlhjAAAAXg"]
[Sun Aug 30 03:04:35.711466 2026] [security2:error] [pid 488669:tid 488812] [client 20.104.50.220:29575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-content/pluginswp-freeform/black2llleaf.php"] [unique_id "apPkE9Rh6OewFvqQpDlhjgAAAQ8"]
[Sun Aug 30 03:04:35.720376 2026] [security2:error] [pid 488669:tid 488827] [client 20.48.251.3:51577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/aws_secret_config.php"] [unique_id "apPkE9Rh6OewFvqQpDlhkwAAAR4"]
[Sun Aug 30 03:04:35.743153 2026] [security2:error] [pid 488669:tid 488853] [client 20.63.81.20:59062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/ue.php"] [unique_id "apPkE9Rh6OewFvqQpDlhmwAAATg"]
[Sun Aug 30 03:04:35.747075 2026] [security2:error] [pid 488669:tid 488833] [client 20.104.18.15:9140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/file31.php"] [unique_id "apPkE9Rh6OewFvqQpDlhnQAAASQ"]
[Sun Aug 30 03:04:35.770812 2026] [security2:error] [pid 488669:tid 488816] [client 20.104.49.130:57715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/abcd.php"] [unique_id "apPkE9Rh6OewFvqQpDlhoAAAARM"]
[Sun Aug 30 03:04:35.775579 2026] [security2:error] [pid 488669:tid 488846] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/nest/.env"] [unique_id "apPkE9Rh6OewFvqQpDlhowAAATE"]
[Sun Aug 30 03:04:35.779493 2026] [security2:error] [pid 488669:tid 488813] [client 20.151.200.44:58881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/wp-access.php"] [unique_id "apPkE9Rh6OewFvqQpDlhpAAAARA"]
[Sun Aug 30 03:04:35.820456 2026] [security2:error] [pid 488669:tid 488906] [client 20.48.250.41:53261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/f35.php"] [unique_id "apPkE9Rh6OewFvqQpDlhqgAAAW0"]
[Sun Aug 30 03:04:35.865059 2026] [security2:error] [pid 488669:tid 488900] [client 4.205.62.107:18986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/ws79.php"] [unique_id "apPkE9Rh6OewFvqQpDlhtwAAAWc"]
[Sun Aug 30 03:04:35.870430 2026] [security2:error] [pid 488669:tid 488858] [client 20.63.81.20:59011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/nv.php"] [unique_id "apPkE9Rh6OewFvqQpDlhuAAAAT0"]
[Sun Aug 30 03:04:35.879512 2026] [security2:error] [pid 488669:tid 488836] [client 34.15.145.202:59800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/php.php"] [unique_id "apPkE9Rh6OewFvqQpDlhvAAAASc"]
[Sun Aug 30 03:04:35.892095 2026] [security2:error] [pid 488669:tid 488830] [client 20.104.18.15:31732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/sign.php"] [unique_id "apPkE9Rh6OewFvqQpDlhvgAAASE"]
[Sun Aug 30 03:04:35.916346 2026] [security2:error] [pid 488669:tid 488869] [client 4.205.62.107:26555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/mamzi.php"] [unique_id "apPkE9Rh6OewFvqQpDlhxAAAAUg"]
[Sun Aug 30 03:04:35.919521 2026] [security2:error] [pid 488669:tid 488827] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/react/.env"] [unique_id "apPkE9Rh6OewFvqQpDlhxQAAAR4"]
[Sun Aug 30 03:04:35.925928 2026] [security2:error] [pid 488669:tid 488924] [client 4.205.62.107:25476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/services.php"] [unique_id "apPkE9Rh6OewFvqQpDlhxwAAAX8"]
[Sun Aug 30 03:04:35.941870 2026] [security2:error] [pid 488669:tid 488871] [client 20.48.251.3:64504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/config_dev.php"] [unique_id "apPkE9Rh6OewFvqQpDlhygAAAUo"]
[Sun Aug 30 03:04:35.946219 2026] [security2:error] [pid 488669:tid 488883] [client 20.104.49.130:36155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wondertanks.com"] [uri "/edit.php"] [unique_id "apPkE9Rh6OewFvqQpDlhzAAAAVY"]
[Sun Aug 30 03:04:35.949542 2026] [security2:error] [pid 488669:tid 488826] [client 20.220.204.93:10952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/wp-link10.php"] [unique_id "apPkE9Rh6OewFvqQpDlhzQAAAR0"]
[Sun Aug 30 03:04:35.960577 2026] [security2:error] [pid 488669:tid 488909] [client 20.48.250.41:53346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/wen.php"] [unique_id "apPkE9Rh6OewFvqQpDlh0AAAAXA"]
[Sun Aug 30 03:04:35.999942 2026] [security2:error] [pid 488669:tid 488809] [client 4.205.62.107:63956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/xin1.php"] [unique_id "apPkE9Rh6OewFvqQpDlh1QAAAQw"]
[Sun Aug 30 03:04:36.002572 2026] [security2:error] [pid 488669:tid 488824] [client 20.63.81.20:58966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/jw.php"] [unique_id "apPkFNRh6OewFvqQpDlh1gAAARs"]
[Sun Aug 30 03:04:36.031581 2026] [security2:error] [pid 488669:tid 488827] [client 20.48.251.3:6515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/edit.php"] [unique_id "apPkFNRh6OewFvqQpDlh5QAAAR4"]
[Sun Aug 30 03:04:36.063228 2026] [security2:error] [pid 488669:tid 488877] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/vue/.env"] [unique_id "apPkFNRh6OewFvqQpDlh5wAAAVA"]
[Sun Aug 30 03:04:36.068395 2026] [security2:error] [pid 488669:tid 488834] [client 20.197.61.180:13936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/oceanwp/sass/components/plugins/panel.php"] [unique_id "apPkFNRh6OewFvqQpDlh6AAAASU"]
[Sun Aug 30 03:04:36.076226 2026] [security2:error] [pid 488669:tid 488807] [client 20.104.50.220:42752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/pwp-.myluv.php"] [unique_id "apPkFNRh6OewFvqQpDlh6wAAAQo"]
[Sun Aug 30 03:04:36.076744 2026] [authz_core:error] [pid 488669:tid 488908] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fdocs
[Sun Aug 30 03:04:36.083838 2026] [authz_core:error] [pid 488669:tid 488908] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fdocs
[Sun Aug 30 03:04:36.088736 2026] [security2:error] [pid 488669:tid 488905] [client 20.48.250.41:53315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/inc.php"] [unique_id "apPkFNRh6OewFvqQpDlh7AAAAWw"]
[Sun Aug 30 03:04:36.090137 2026] [security2:error] [pid 488669:tid 488899] [client 20.104.49.130:52319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.katbacon.com"] [uri "/ioxi-o.php"] [unique_id "apPkFNRh6OewFvqQpDlh7QAAAWY"]
[Sun Aug 30 03:04:36.139235 2026] [security2:error] [pid 488669:tid 488911] [client 20.63.81.20:59093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/or.php"] [unique_id "apPkFNRh6OewFvqQpDlh9gAAAXI"]
[Sun Aug 30 03:04:36.142478 2026] [security2:error] [pid 488669:tid 488825] [client 68.155.159.216:59350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-login.php"] [unique_id "apPkFNRh6OewFvqQpDlh9wAAARw"]
[Sun Aug 30 03:04:36.169817 2026] [security2:error] [pid 488669:tid 488885] [client 20.48.251.3:64473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/aws_credentials.php"] [unique_id "apPkFNRh6OewFvqQpDlh-gAAAVg"]
[Sun Aug 30 03:04:36.171051 2026] [security2:error] [pid 488669:tid 488885] [client 20.48.251.3:54759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/doc.php"] [unique_id "apPkFNRh6OewFvqQpDlh-wAAAVg"]
[Sun Aug 30 03:04:36.200185 2026] [authz_core:error] [pid 488669:tid 488875] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fman%2Fman7
[Sun Aug 30 03:04:36.200628 2026] [authz_core:error] [pid 488669:tid 488875] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fman%2Fman7
[Sun Aug 30 03:04:36.206273 2026] [security2:error] [pid 488669:tid 488840] [client 20.220.204.93:33959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/ww.php"] [unique_id "apPkFNRh6OewFvqQpDliAAAAASs"]
[Sun Aug 30 03:04:36.206744 2026] [security2:error] [pid 488669:tid 488831] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/angular/.env"] [unique_id "apPkFNRh6OewFvqQpDlh_wAAASI"]
[Sun Aug 30 03:04:36.213822 2026] [security2:error] [pid 488669:tid 488925] [client 20.104.18.15:33747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/ap.php"] [unique_id "apPkFNRh6OewFvqQpDliAQAAAYA"]
[Sun Aug 30 03:04:36.218410 2026] [security2:error] [pid 488669:tid 488883] [client 20.48.250.41:53345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/6bcwiqwj.php"] [unique_id "apPkFNRh6OewFvqQpDliAgAAAVY"]
[Sun Aug 30 03:04:36.260055 2026] [security2:error] [pid 488669:tid 488813] [client 20.196.209.81:23638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/twentytwentyfive/styles/sections/pk.php"] [unique_id "apPkFNRh6OewFvqQpDliCgAAARA"]
[Sun Aug 30 03:04:36.269128 2026] [security2:error] [pid 488669:tid 488819] [client 20.63.81.20:58886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/ile56.php"] [unique_id "apPkFNRh6OewFvqQpDliDQAAARY"]
[Sun Aug 30 03:04:36.349864 2026] [security2:error] [pid 488669:tid 488904] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/svelte/.env"] [unique_id "apPkFNRh6OewFvqQpDliHQAAAWs"]
[Sun Aug 30 03:04:36.360520 2026] [security2:error] [pid 488669:tid 488836] [client 20.48.250.41:53321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/easy.php"] [unique_id "apPkFNRh6OewFvqQpDliIAAAASc"]
[Sun Aug 30 03:04:36.381549 2026] [security2:error] [pid 488669:tid 488905] [client 20.104.50.220:29162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/jal.php"] [unique_id "apPkFNRh6OewFvqQpDliJgAAAWw"]
[Sun Aug 30 03:04:36.388341 2026] [security2:error] [pid 488669:tid 488808] [client 20.104.49.130:45145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.trinitytechnologics.com"] [uri "/edit.php"] [unique_id "apPkFNRh6OewFvqQpDliJwAAAQs"]
[Sun Aug 30 03:04:36.392074 2026] [security2:error] [pid 488669:tid 488932] [client 4.205.62.107:32482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/fns.php"] [unique_id "apPkFNRh6OewFvqQpDliKAAAAYc"]
[Sun Aug 30 03:04:36.405331 2026] [security2:error] [pid 488669:tid 488896] [client 20.63.81.20:59107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/emmh.php"] [unique_id "apPkFNRh6OewFvqQpDliKgAAAWM"]
[Sun Aug 30 03:04:36.413576 2026] [security2:error] [pid 488669:tid 488917] [client 20.104.50.220:29756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/Kernel.php"] [unique_id "apPkFNRh6OewFvqQpDliLAAAAXg"]
[Sun Aug 30 03:04:36.417596 2026] [security2:error] [pid 488669:tid 488867] [client 4.205.62.107:4554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/333.php"] [unique_id "apPkFNRh6OewFvqQpDliLQAAAUY"]
[Sun Aug 30 03:04:36.460913 2026] [security2:error] [pid 488669:tid 488918] [client 20.220.204.93:42392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/w1px.php"] [unique_id "apPkFNRh6OewFvqQpDliMgAAAXk"]
[Sun Aug 30 03:04:36.482084 2026] [security2:error] [pid 488669:tid 488916] [client 34.15.145.202:59810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/i.php"] [unique_id "apPkFNRh6OewFvqQpDliMwAAAXc"]
[Sun Aug 30 03:04:36.491781 2026] [security2:error] [pid 488669:tid 488902] [client 4.205.62.107:44758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/saml.php"] [unique_id "apPkFNRh6OewFvqQpDliNgAAAWk"]
[Sun Aug 30 03:04:36.494568 2026] [security2:error] [pid 488669:tid 488885] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/vite/.env"] [unique_id "apPkFNRh6OewFvqQpDliNwAAAVg"]
[Sun Aug 30 03:04:36.514342 2026] [security2:error] [pid 488669:tid 488820] [client 20.48.251.3:55762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/session.php"] [unique_id "apPkFNRh6OewFvqQpDliOgAAARc"]
[Sun Aug 30 03:04:36.519277 2026] [security2:error] [pid 488669:tid 488828] [client 20.48.250.41:53263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/fresh3.php"] [unique_id "apPkFNRh6OewFvqQpDliOwAAAR8"]
[Sun Aug 30 03:04:36.523970 2026] [security2:error] [pid 488669:tid 488816] [client 4.205.62.107:22930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/konfig.php"] [unique_id "apPkFNRh6OewFvqQpDliPAAAARM"]
[Sun Aug 30 03:04:36.534331 2026] [security2:error] [pid 488669:tid 488880] [client 20.48.251.3:55426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/php-info.php"] [unique_id "apPkFNRh6OewFvqQpDliPQAAAVM"]
[Sun Aug 30 03:04:36.536493 2026] [security2:error] [pid 488669:tid 488871] [client 20.196.209.81:8010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/data.php"] [unique_id "apPkFNRh6OewFvqQpDliPgAAAUo"]
[Sun Aug 30 03:04:36.538120 2026] [security2:error] [pid 488669:tid 488840] [client 20.63.81.20:58917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/em.php"] [unique_id "apPkFNRh6OewFvqQpDliPwAAASs"]
[Sun Aug 30 03:04:36.551096 2026] [security2:error] [pid 488669:tid 488883] [client 20.104.49.130:58233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/load.php"] [unique_id "apPkFNRh6OewFvqQpDliQAAAAVY"]
[Sun Aug 30 03:04:36.568036 2026] [authz_core:error] [pid 488669:tid 488833] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fdocs
[Sun Aug 30 03:04:36.568367 2026] [authz_core:error] [pid 488669:tid 488884] [client 66.249.66.78:50187] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:36.568507 2026] [authz_core:error] [pid 488669:tid 488833] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fdocs
[Sun Aug 30 03:04:36.568837 2026] [authz_core:error] [pid 488669:tid 488884] [client 66.249.66.78:50187] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:36.570613 2026] [authz_core:error] [pid 488669:tid 488843] [client 66.249.66.33:57696] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:36.571042 2026] [authz_core:error] [pid 488669:tid 488843] [client 66.249.66.33:57696] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:36.590625 2026] [security2:error] [pid 488669:tid 488909] [client 20.48.251.3:44174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/doc.php"] [unique_id "apPkFNRh6OewFvqQpDliRwAAAXA"]
[Sun Aug 30 03:04:36.625664 2026] [security2:error] [pid 488669:tid 488870] [client 4.205.62.107:63574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/u88.php"] [unique_id "apPkFNRh6OewFvqQpDliSQAAAUk"]
[Sun Aug 30 03:04:36.640546 2026] [security2:error] [pid 488669:tid 488839] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/backup/.env"] [unique_id "apPkFNRh6OewFvqQpDliSwAAASo"]
[Sun Aug 30 03:04:36.645652 2026] [security2:error] [pid 488669:tid 488912] [client 20.48.250.41:53351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/bgymj.php"] [unique_id "apPkFNRh6OewFvqQpDliTQAAAXM"]
[Sun Aug 30 03:04:36.660969 2026] [security2:error] [pid 488669:tid 488877] [client 20.104.50.220:33193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/Unknown45.php"] [unique_id "apPkFNRh6OewFvqQpDliTwAAAVA"]
[Sun Aug 30 03:04:36.672130 2026] [security2:error] [pid 488669:tid 488822] [client 20.220.204.93:5047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/to.php"] [unique_id "apPkFNRh6OewFvqQpDliUAAAARk"]
[Sun Aug 30 03:04:36.673863 2026] [security2:error] [pid 488669:tid 488925] [client 20.196.209.81:7960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/dt-the7/css/static-less/plugins/admin.php"] [unique_id "apPkFNRh6OewFvqQpDliUQAAAYA"]
[Sun Aug 30 03:04:36.676262 2026] [security2:error] [pid 488669:tid 488817] [client 20.104.50.220:5535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/classwithtostring.php"] [unique_id "apPkFNRh6OewFvqQpDliUgAAARQ"]
[Sun Aug 30 03:04:36.680942 2026] [security2:error] [pid 488669:tid 488835] [client 20.63.81.20:59008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/dvve.php"] [unique_id "apPkFNRh6OewFvqQpDliVAAAASY"]
[Sun Aug 30 03:04:36.694557 2026] [security2:error] [pid 488669:tid 488894] [client 20.104.50.220:47076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/3index.php"] [unique_id "apPkFNRh6OewFvqQpDliVwAAAWE"]
[Sun Aug 30 03:04:36.701913 2026] [authz_core:error] [pid 488669:tid 488900] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fpython3-dnf-plugins-core
[Sun Aug 30 03:04:36.702193 2026] [authz_core:error] [pid 488669:tid 488900] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fpython3-dnf-plugins-core
[Sun Aug 30 03:04:36.739514 2026] [authz_core:error] [pid 488669:tid 488862] [client 216.73.216.128:63883] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:36.739814 2026] [authz_core:error] [pid 488669:tid 488862] [client 216.73.216.128:63883] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:36.766980 2026] [security2:error] [pid 488669:tid 488874] [client 20.104.50.220:59574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/0x1337.php"] [unique_id "apPkFNRh6OewFvqQpDliXgAAAU0"]
[Sun Aug 30 03:04:36.778812 2026] [security2:error] [pid 488669:tid 488932] [client 4.205.62.107:2162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/setup-config.php"] [unique_id "apPkFNRh6OewFvqQpDliYAAAAYc"]
[Sun Aug 30 03:04:36.790015 2026] [security2:error] [pid 488669:tid 488896] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/backups/.env"] [unique_id "apPkFNRh6OewFvqQpDliYQAAAWM"]
[Sun Aug 30 03:04:36.790129 2026] [security2:error] [pid 488669:tid 488845] [client 4.205.62.107:51732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/debug.php"] [unique_id "apPkFNRh6OewFvqQpDliYgAAATA"]
[Sun Aug 30 03:04:36.797611 2026] [security2:error] [pid 488669:tid 488846] [client 20.197.61.180:4055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/options.php"] [unique_id "apPkFNRh6OewFvqQpDliZAAAATE"]
[Sun Aug 30 03:04:36.818641 2026] [security2:error] [pid 488669:tid 488867] [client 20.48.250.41:53266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/ws69.php"] [unique_id "apPkFNRh6OewFvqQpDliZgAAAUY"]
[Sun Aug 30 03:04:36.823552 2026] [security2:error] [pid 488669:tid 488812] [client 20.63.81.20:59057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/doo.php"] [unique_id "apPkFNRh6OewFvqQpDliZwAAAQ8"]
[Sun Aug 30 03:04:36.838035 2026] [security2:error] [pid 488669:tid 488821] [client 20.196.209.81:6116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/twentytwentythree/patterns/index.php"] [unique_id "apPkFNRh6OewFvqQpDliaQAAARg"]
[Sun Aug 30 03:04:36.854208 2026] [security2:error] [pid 488669:tid 488918] [client 20.104.50.220:32513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/Ninja.php"] [unique_id "apPkFNRh6OewFvqQpDliawAAAXk"]
[Sun Aug 30 03:04:36.860669 2026] [security2:error] [pid 488669:tid 488825] [client 20.104.50.220:28701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/meiwei.php"] [unique_id "apPkFNRh6OewFvqQpDlibQAAARw"]
[Sun Aug 30 03:04:36.862685 2026] [security2:error] [pid 488669:tid 488849] [client 20.48.251.3:44366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/thui.php"] [unique_id "apPkFNRh6OewFvqQpDlibgAAATQ"]
[Sun Aug 30 03:04:36.885412 2026] [security2:error] [pid 488669:tid 488820] [client 20.48.251.3:51572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/snq.php"] [unique_id "apPkFNRh6OewFvqQpDlibwAAARc"]
[Sun Aug 30 03:04:36.886702 2026] [security2:error] [pid 488669:tid 488828] [client 20.104.18.15:9093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/dk.php"] [unique_id "apPkFNRh6OewFvqQpDlicQAAAR8"]
[Sun Aug 30 03:04:36.920827 2026] [security2:error] [pid 488669:tid 488871] [client 68.155.159.216:59907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/file17.php"] [unique_id "apPkFNRh6OewFvqQpDlidgAAAUo"]
[Sun Aug 30 03:04:36.935575 2026] [security2:error] [pid 488669:tid 488834] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/old/.env"] [unique_id "apPkFNRh6OewFvqQpDlidwAAASU"]
[Sun Aug 30 03:04:36.952559 2026] [security2:error] [pid 488669:tid 488826] [client 20.63.81.20:59089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/adminer-4.6.6.php"] [unique_id "apPkFNRh6OewFvqQpDlieAAAAR0"]
[Sun Aug 30 03:04:36.974993 2026] [security2:error] [pid 488669:tid 488842] [client 20.48.250.41:53292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/ccs.php"] [unique_id "apPkFNRh6OewFvqQpDliegAAAS0"]
[Sun Aug 30 03:04:36.977513 2026] [security2:error] [pid 488669:tid 488898] [client 20.220.204.93:42427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/thui.php"] [unique_id "apPkFNRh6OewFvqQpDlifAAAAWU"]
[Sun Aug 30 03:04:37.000796 2026] [security2:error] [pid 488669:tid 488906] [client 4.205.62.107:18655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/public/wp-blog.php"] [unique_id "apPkFNRh6OewFvqQpDlifgAAAW0"]
[Sun Aug 30 03:04:37.030845 2026] [security2:error] [pid 488669:tid 488882] [client 20.104.18.15:31647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/wnnjpsby.php"] [unique_id "apPkFdRh6OewFvqQpDligAAAAVU"]
[Sun Aug 30 03:04:37.063957 2026] [security2:error] [pid 488669:tid 488878] [client 4.205.62.107:25479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/filesystems.php"] [unique_id "apPkFdRh6OewFvqQpDliggAAAVE"]
[Sun Aug 30 03:04:37.069957 2026] [security2:error] [pid 488669:tid 488890] [client 20.196.209.81:11869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/hideo/network.php"] [unique_id "apPkFdRh6OewFvqQpDligwAAAV0"]
[Sun Aug 30 03:04:37.074673 2026] [authz_core:error] [pid 488669:tid 488907] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fbind%2Fsample%2Fetc
[Sun Aug 30 03:04:37.075126 2026] [authz_core:error] [pid 488669:tid 488907] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fbind%2Fsample%2Fetc
[Sun Aug 30 03:04:37.078871 2026] [security2:error] [pid 488669:tid 488852] [client 20.48.251.3:64459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/aws-credentials.php"] [unique_id "apPkFdRh6OewFvqQpDlihQAAATc"]
[Sun Aug 30 03:04:37.078960 2026] [security2:error] [pid 488669:tid 488912] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/tmp/.env"] [unique_id "apPkFdRh6OewFvqQpDlihAAAAXM"]
[Sun Aug 30 03:04:37.087147 2026] [security2:error] [pid 488669:tid 488885] [client 34.15.145.202:59824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/pi.php"] [unique_id "apPkFdRh6OewFvqQpDlihgAAAVg"]
[Sun Aug 30 03:04:37.088481 2026] [security2:error] [pid 488669:tid 488928] [client 20.63.81.20:59018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/gelap1.php"] [unique_id "apPkFdRh6OewFvqQpDlihwAAAYM"]
[Sun Aug 30 03:04:37.095887 2026] [authz_core:error] [pid 488669:tid 488877] [client 66.249.66.35:41278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:37.096179 2026] [authz_core:error] [pid 488669:tid 488877] [client 66.249.66.35:41278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:37.108526 2026] [security2:error] [pid 488669:tid 488920] [client 20.48.250.41:53365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/mar.php"] [unique_id "apPkFdRh6OewFvqQpDliigAAAXs"]
[Sun Aug 30 03:04:37.119624 2026] [security2:error] [pid 488669:tid 488934] [client 20.220.204.93:33982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/Jcrop.php"] [unique_id "apPkFdRh6OewFvqQpDliiwAAAYk"]
[Sun Aug 30 03:04:37.137440 2026] [security2:error] [pid 488669:tid 488930] [client 20.151.200.44:58878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/wp-content/admin.php"] [unique_id "apPkFdRh6OewFvqQpDlijwAAAYU"]
[Sun Aug 30 03:04:37.151494 2026] [security2:error] [pid 488669:tid 488903] [client 4.205.62.107:62128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/sadd.php"] [unique_id "apPkFdRh6OewFvqQpDlikAAAAWo"]
[Sun Aug 30 03:04:37.180768 2026] [security2:error] [pid 488669:tid 488836] [client 20.48.251.3:7065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/8.php"] [unique_id "apPkFdRh6OewFvqQpDlikwAAASc"]
[Sun Aug 30 03:04:37.201228 2026] [authz_core:error] [pid 488669:tid 488851] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fpython3-dnf-plugins-core
[Sun Aug 30 03:04:37.201679 2026] [authz_core:error] [pid 488669:tid 488851] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fpython3-dnf-plugins-core
[Sun Aug 30 03:04:37.205877 2026] [security2:error] [pid 488669:tid 488915] [client 20.151.200.44:47082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/dx.php"] [unique_id "apPkFdRh6OewFvqQpDlimAAAAXY"]
[Sun Aug 30 03:04:37.223306 2026] [security2:error] [pid 488669:tid 488808] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/temp/.env"] [unique_id "apPkFdRh6OewFvqQpDlimQAAAQs"]
[Sun Aug 30 03:04:37.226685 2026] [security2:error] [pid 488669:tid 488893] [client 20.63.81.20:59000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/rsjlrria.php"] [unique_id "apPkFdRh6OewFvqQpDlimwAAAWA"]
[Sun Aug 30 03:04:37.241705 2026] [security2:error] [pid 488669:tid 488859] [client 20.48.250.41:53339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/ccu.php"] [unique_id "apPkFdRh6OewFvqQpDlinQAAAT4"]
[Sun Aug 30 03:04:37.272640 2026] [security2:error] [pid 488669:tid 488818] [client 68.155.159.216:52854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apPkFdRh6OewFvqQpDlioQAAARU"]
[Sun Aug 30 03:04:37.295772 2026] [security2:error] [pid 488669:tid 488865] [client 20.104.50.220:42785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wihp1.php"] [unique_id "apPkFdRh6OewFvqQpDlipgAAAUQ"]
[Sun Aug 30 03:04:37.332470 2026] [security2:error] [pid 488669:tid 488900] [client 20.48.251.3:6517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/4563.php"] [unique_id "apPkFdRh6OewFvqQpDlipwAAAWc"]
[Sun Aug 30 03:04:37.347073 2026] [security2:error] [pid 488669:tid 488902] [client 20.48.251.3:54805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/css.php"] [unique_id "apPkFdRh6OewFvqQpDliqAAAAWk"]
[Sun Aug 30 03:04:37.348715 2026] [security2:error] [pid 488669:tid 488820] [client 20.104.18.15:33015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/media.php"] [unique_id "apPkFdRh6OewFvqQpDliqQAAARc"]
[Sun Aug 30 03:04:37.359540 2026] [security2:error] [pid 488669:tid 488871] [client 20.63.81.20:59124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/AxAo.php"] [unique_id "apPkFdRh6OewFvqQpDlirAAAAUo"]
[Sun Aug 30 03:04:37.367750 2026] [security2:error] [pid 488669:tid 488809] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/lab/.env"] [unique_id "apPkFdRh6OewFvqQpDlirQAAAQw"]
[Sun Aug 30 03:04:37.374977 2026] [security2:error] [pid 488669:tid 488826] [client 20.48.250.41:53354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/ak.php"] [unique_id "apPkFdRh6OewFvqQpDlirwAAAR0"]
[Sun Aug 30 03:04:37.398443 2026] [security2:error] [pid 488669:tid 488864] [client 20.196.209.81:6101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/users.php"] [unique_id "apPkFdRh6OewFvqQpDlisQAAAUM"]
[Sun Aug 30 03:04:37.409317 2026] [security2:error] [pid 488669:tid 488879] [client 20.220.204.93:42384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/ws58.php"] [unique_id "apPkFdRh6OewFvqQpDlisgAAAVI"]
[Sun Aug 30 03:04:37.425414 2026] [authz_core:error] [pid 488669:tid 488862] [client 66.249.66.71:55386] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:37.425722 2026] [authz_core:error] [pid 488669:tid 488862] [client 66.249.66.71:55386] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:37.461488 2026] [security2:error] [pid 488669:tid 488924] [client 20.196.209.81:7941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPkFdRh6OewFvqQpDlitQAAAX8"]
[Sun Aug 30 03:04:37.486160 2026] [security2:error] [pid 488669:tid 488884] [client 195.178.110.247:41070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.m2advisor.com"] [uri "/index.php"] [unique_id "apPkFdRh6OewFvqQpDliuAAAAVc"]
[Sun Aug 30 03:04:37.491212 2026] [security2:error] [pid 488669:tid 488908] [client 20.63.81.20:59128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/class17.php"] [unique_id "apPkFdRh6OewFvqQpDliugAAAW8"]
[Sun Aug 30 03:04:37.512058 2026] [security2:error] [pid 488669:tid 488878] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/cronlab/.env"] [unique_id "apPkFdRh6OewFvqQpDlivQAAAVE"]
[Sun Aug 30 03:04:37.514134 2026] [security2:error] [pid 488669:tid 488860] [client 20.197.61.180:9183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/panel.php"] [unique_id "apPkFdRh6OewFvqQpDlivgAAAT8"]
[Sun Aug 30 03:04:37.515956 2026] [security2:error] [pid 488669:tid 488890] [client 20.151.200.44:37866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/sf.php"] [unique_id "apPkFdRh6OewFvqQpDliwAAAAV0"]
[Sun Aug 30 03:04:37.516066 2026] [security2:error] [pid 488669:tid 488854] [client 20.48.250.41:53349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/lib.php"] [unique_id "apPkFdRh6OewFvqQpDlivwAAATk"]
[Sun Aug 30 03:04:37.520171 2026] [security2:error] [pid 488669:tid 488852] [client 20.104.50.220:52834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/pfa.php"] [unique_id "apPkFdRh6OewFvqQpDliwQAAATc"]
[Sun Aug 30 03:04:37.552710 2026] [security2:error] [pid 488669:tid 488920] [client 20.104.50.220:29870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/Builder.php"] [unique_id "apPkFdRh6OewFvqQpDliwwAAAXs"]
[Sun Aug 30 03:04:37.563328 2026] [security2:error] [pid 488669:tid 488817] [client 4.205.62.107:4549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/G-in.php"] [unique_id "apPkFdRh6OewFvqQpDlixAAAARQ"]
[Sun Aug 30 03:04:37.566574 2026] [security2:error] [pid 488669:tid 488930] [client 4.205.62.107:36673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/packed.php"] [unique_id "apPkFdRh6OewFvqQpDlixQAAAYU"]
[Sun Aug 30 03:04:37.594106 2026] [authz_core:error] [pid 488669:tid 488903] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fbind%2Fsample%2Fetc
[Sun Aug 30 03:04:37.594547 2026] [authz_core:error] [pid 488669:tid 488903] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fbind%2Fsample%2Fetc
[Sun Aug 30 03:04:37.631799 2026] [security2:error] [pid 488669:tid 488808] [client 4.205.62.107:26798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/public/rip.php.php"] [unique_id "apPkFdRh6OewFvqQpDli0AAAAQs"]
[Sun Aug 30 03:04:37.645467 2026] [security2:error] [pid 488669:tid 488845] [client 4.205.62.107:44866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/aws_settings.php"] [unique_id "apPkFdRh6OewFvqQpDli1QAAATA"]
[Sun Aug 30 03:04:37.652712 2026] [security2:error] [pid 488669:tid 488819] [client 195.178.110.247:49254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.m2advisor.com"] [uri "/index.php"] [unique_id "apPkFdRh6OewFvqQpDli1wAAARY"]
[Sun Aug 30 03:04:37.656389 2026] [security2:error] [pid 488669:tid 488822] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/cron/.env"] [unique_id "apPkFdRh6OewFvqQpDli2QAAARk"]
[Sun Aug 30 03:04:37.663876 2026] [security2:error] [pid 488669:tid 488916] [client 20.63.81.20:59039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/okxoby.php"] [unique_id "apPkFdRh6OewFvqQpDli2wAAAXc"]
[Sun Aug 30 03:04:37.670296 2026] [security2:error] [pid 488669:tid 488847] [client 20.48.250.41:53320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/wp-style.php"] [unique_id "apPkFdRh6OewFvqQpDli3QAAATI"]
[Sun Aug 30 03:04:37.673476 2026] [security2:error] [pid 488669:tid 488891] [client 20.48.251.3:55533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/infos.php"] [unique_id "apPkFdRh6OewFvqQpDli3gAAAV4"]
[Sun Aug 30 03:04:37.686949 2026] [security2:error] [pid 488669:tid 488882] [client 34.15.145.202:57802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/pinfo.php"] [unique_id "apPkFdRh6OewFvqQpDli4gAAAVU"]
[Sun Aug 30 03:04:37.690003 2026] [security2:error] [pid 488669:tid 488820] [client 4.205.62.107:22545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/paths.php"] [unique_id "apPkFdRh6OewFvqQpDli4wAAARc"]
[Sun Aug 30 03:04:37.690988 2026] [security2:error] [pid 488669:tid 488883] [client 20.220.204.93:46949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/xs.php"] [unique_id "apPkFdRh6OewFvqQpDli5AAAAVY"]
[Sun Aug 30 03:04:37.693392 2026] [security2:error] [pid 488669:tid 488871] [client 20.48.251.3:59301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/h.php"] [unique_id "apPkFdRh6OewFvqQpDli5gAAAUo"]
[Sun Aug 30 03:04:37.698557 2026] [security2:error] [pid 488669:tid 488816] [client 64.89.161.160:61947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.161.89.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ninjacommandapp.com"] [uri "/plugins/file-uploader/server/php/index.php"] [unique_id "apPkFdRh6OewFvqQpDli5wAAARM"]
[Sun Aug 30 03:04:37.700923 2026] [authz_core:error] [pid 488669:tid 488828] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fman%2Fman7
[Sun Aug 30 03:04:37.701196 2026] [authz_core:error] [pid 488669:tid 488828] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fman%2Fman7
[Sun Aug 30 03:04:37.721387 2026] [security2:error] [pid 488669:tid 488898] [client 20.48.251.3:23452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/css.php"] [unique_id "apPkFdRh6OewFvqQpDli7wAAAWU"]
[Sun Aug 30 03:04:37.758717 2026] [security2:error] [pid 488669:tid 488854] [client 4.205.62.107:60557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/config/laravolt/css/index.php"] [unique_id "apPkFdRh6OewFvqQpDli8wAAATk"]
[Sun Aug 30 03:04:37.792313 2026] [security2:error] [pid 488669:tid 488867] [client 20.196.209.81:6138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/wp-cron.php"] [unique_id "apPkFdRh6OewFvqQpDli9gAAAUY"]
[Sun Aug 30 03:04:37.793661 2026] [security2:error] [pid 488669:tid 488817] [client 20.63.81.20:58996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/esuutzzx.php"] [unique_id "apPkFdRh6OewFvqQpDli-AAAARQ"]
[Sun Aug 30 03:04:37.798477 2026] [authz_core:error] [pid 488669:tid 488908] [client 66.249.66.64:50135] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:37.798925 2026] [authz_core:error] [pid 488669:tid 488908] [client 66.249.66.64:50135] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:37.801959 2026] [security2:error] [pid 488669:tid 488877] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/en/.env"] [unique_id "apPkFdRh6OewFvqQpDli-wAAAVA"]
[Sun Aug 30 03:04:37.807635 2026] [security2:error] [pid 488669:tid 488840] [client 20.104.50.220:33312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/vinus.php"] [unique_id "apPkFdRh6OewFvqQpDli_AAAASs"]
[Sun Aug 30 03:04:37.813636 2026] [security2:error] [pid 488669:tid 488836] [client 20.104.50.220:5608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/abcd.php"] [unique_id "apPkFdRh6OewFvqQpDli_wAAASc"]
[Sun Aug 30 03:04:37.837831 2026] [security2:error] [pid 488669:tid 488845] [client 20.48.250.41:53363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/browse.php"] [unique_id "apPkFdRh6OewFvqQpDljAwAAATA"]
[Sun Aug 30 03:04:37.849724 2026] [security2:error] [pid 488669:tid 488819] [client 20.104.50.220:46428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/4index.php"] [unique_id "apPkFdRh6OewFvqQpDljBAAAARY"]
[Sun Aug 30 03:04:37.853901 2026] [security2:error] [pid 488669:tid 488829] [client 20.196.209.81:13921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/intense/block-css.php"] [unique_id "apPkFdRh6OewFvqQpDljBQAAASA"]
[Sun Aug 30 03:04:37.906303 2026] [security2:error] [pid 488669:tid 488883] [client 4.205.62.107:32036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/params.php"] [unique_id "apPkFdRh6OewFvqQpDljDQAAAVY"]
[Sun Aug 30 03:04:37.911517 2026] [security2:error] [pid 488669:tid 488816] [client 4.205.62.107:2963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/wp-admin/sc.php"] [unique_id "apPkFdRh6OewFvqQpDljDgAAARM"]
[Sun Aug 30 03:04:37.923046 2026] [security2:error] [pid 488669:tid 488823] [client 20.151.200.44:58922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/log.php"] [unique_id "apPkFdRh6OewFvqQpDljEgAAARo"]
[Sun Aug 30 03:04:37.927795 2026] [security2:error] [pid 488669:tid 488898] [client 20.63.81.20:59033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/replace.php"] [unique_id "apPkFdRh6OewFvqQpDljEwAAAWU"]
[Sun Aug 30 03:04:37.947028 2026] [security2:error] [pid 488669:tid 488878] [client 4.205.62.107:52122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/nzv.php"] [unique_id "apPkFdRh6OewFvqQpDljFQAAAVE"]
[Sun Aug 30 03:04:37.953541 2026] [security2:error] [pid 488669:tid 488860] [client 20.220.204.93:10277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/zu.php"] [unique_id "apPkFdRh6OewFvqQpDljFgAAAT8"]
[Sun Aug 30 03:04:37.961011 2026] [security2:error] [pid 488669:tid 488911] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/administrator/.env"] [unique_id "apPkFdRh6OewFvqQpDljFAAAAXI"]
[Sun Aug 30 03:04:37.971398 2026] [security2:error] [pid 488669:tid 488928] [client 20.104.50.220:61646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/xltavrat.php"] [unique_id "apPkFdRh6OewFvqQpDljGQAAAYM"]
[Sun Aug 30 03:04:37.972624 2026] [security2:error] [pid 488669:tid 488903] [client 20.48.250.41:53358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/zoo.php"] [unique_id "apPkFdRh6OewFvqQpDljGgAAAWo"]
[Sun Aug 30 03:04:38.003481 2026] [autoindex:error] [pid 488669:tid 488841] [client 4.205.62.107:65401] AH01276: Cannot serve directory /home2/oliveranin/public_html/wp-includes/js/tinymce/themes/inlite/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:04:38.004226 2026] [security2:error] [pid 488669:tid 488859] [client 20.48.251.3:44375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/lala.php"] [unique_id "apPkFtRh6OewFvqQpDljIwAAAT4"]
[Sun Aug 30 03:04:38.004250 2026] [security2:error] [pid 488669:tid 488828] [client 20.104.50.220:63040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/fonts/priv8.php"] [unique_id "apPkFtRh6OewFvqQpDljIgAAAR8"]
[Sun Aug 30 03:04:38.013307 2026] [security2:error] [pid 488669:tid 488793] [remote 70.32.23.67:40008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.23.32.70.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/wp-login.php"] [unique_id "apPkFdRh6OewFvqQpDljIQABa3M"]
[Sun Aug 30 03:04:38.023828 2026] [security2:error] [pid 488669:tid 488845] [client 20.104.50.220:32074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-incleude.php"] [unique_id "apPkFtRh6OewFvqQpDljKAAAATA"]
[Sun Aug 30 03:04:38.038964 2026] [security2:error] [pid 488669:tid 488917] [client 4.205.62.107:31708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/nzv.php"] [unique_id "apPkFtRh6OewFvqQpDljLAAAAXg"]
[Sun Aug 30 03:04:38.047211 2026] [security2:error] [pid 488669:tid 488855] [client 20.104.49.130:52351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.katbacon.com"] [uri "/bthil.php"] [unique_id "apPkFtRh6OewFvqQpDljLgAAATo"]
[Sun Aug 30 03:04:38.058235 2026] [security2:error] [pid 488669:tid 488870] [client 20.104.18.15:9187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/ta.php"] [unique_id "apPkFtRh6OewFvqQpDljMQAAAUk"]
[Sun Aug 30 03:04:38.066826 2026] [security2:error] [pid 488669:tid 488812] [client 20.63.81.20:58939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/gulu.php"] [unique_id "apPkFtRh6OewFvqQpDljMwAAAQ8"]
[Sun Aug 30 03:04:38.069603 2026] [authz_core:error] [pid 488669:tid 488825] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fbind%2Fsample%2Fvar
[Sun Aug 30 03:04:38.069714 2026] [security2:error] [pid 488669:tid 488849] [client 4.205.62.107:65314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/doc.php"] [unique_id "apPkFtRh6OewFvqQpDljNAAAATQ"]
[Sun Aug 30 03:04:38.070071 2026] [authz_core:error] [pid 488669:tid 488825] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fbind%2Fsample%2Fvar
[Sun Aug 30 03:04:38.079733 2026] [security2:error] [pid 488669:tid 488848] [client 20.48.251.3:51525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/wp-access.php"] [unique_id "apPkFtRh6OewFvqQpDljNQAAATM"]
[Sun Aug 30 03:04:38.092913 2026] [security2:error] [pid 488669:tid 488826] [client 68.155.159.216:59982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/file5.php"] [unique_id "apPkFtRh6OewFvqQpDljNwAAAR0"]
[Sun Aug 30 03:04:38.104499 2026] [security2:error] [pid 488669:tid 488864] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/psnlink/.env"] [unique_id "apPkFtRh6OewFvqQpDljOQAAAUM"]
[Sun Aug 30 03:04:38.105683 2026] [security2:error] [pid 488669:tid 488853] [client 20.48.250.41:53323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/elp.php"] [unique_id "apPkFtRh6OewFvqQpDljOgAAATg"]
[Sun Aug 30 03:04:38.155809 2026] [security2:error] [pid 488669:tid 488877] [client 4.205.62.107:18961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/php-details.php"] [unique_id "apPkFtRh6OewFvqQpDljPQAAAVA"]
[Sun Aug 30 03:04:38.185079 2026] [security2:error] [pid 488669:tid 488836] [client 20.104.18.15:31566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/gigi.php"] [unique_id "apPkFtRh6OewFvqQpDljPgAAASc"]
[Sun Aug 30 03:04:38.185834 2026] [security2:error] [pid 488669:tid 488865] [client 20.196.209.81:23650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/wp-links-opml.php"] [unique_id "apPkFtRh6OewFvqQpDljQAAAAUQ"]
[Sun Aug 30 03:04:38.193122 2026] [security2:error] [pid 488669:tid 488797] [remote 70.32.23.67:40008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.23.32.70.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/wp-login.php"] [unique_id "apPkFtRh6OewFvqQpDljQwABYXc"], referer: https://medicaidassistants.com/wp-login.php
[Sun Aug 30 03:04:38.199523 2026] [authz_core:error] [pid 488669:tid 488808] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fman%2Fman7
[Sun Aug 30 03:04:38.199884 2026] [authz_core:error] [pid 488669:tid 488808] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fman%2Fman7
[Sun Aug 30 03:04:38.206607 2026] [security2:error] [pid 488669:tid 488841] [client 20.63.81.20:58908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/gtghklk.php"] [unique_id "apPkFtRh6OewFvqQpDljRwAAASw"]
[Sun Aug 30 03:04:38.218508 2026] [security2:error] [pid 488669:tid 488828] [client 20.48.251.3:7386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/cp2.php"] [unique_id "apPkFtRh6OewFvqQpDljSAAAAR8"]
[Sun Aug 30 03:04:38.219391 2026] [security2:error] [pid 488669:tid 488840] [client 20.197.61.180:9209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/reboot/assets/js/plugins/home.php"] [unique_id "apPkFtRh6OewFvqQpDljSQAAASs"]
[Sun Aug 30 03:04:38.229631 2026] [security2:error] [pid 488669:tid 488889] [client 20.220.204.93:42423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/lanka.php"] [unique_id "apPkFtRh6OewFvqQpDljSgAAAVw"]
[Sun Aug 30 03:04:38.231319 2026] [security2:error] [pid 488669:tid 488829] [client 20.104.49.130:52490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/82.php"] [unique_id "apPkFtRh6OewFvqQpDljSwAAASA"]
[Sun Aug 30 03:04:38.249160 2026] [security2:error] [pid 488669:tid 488917] [client 136.92.30.49:42456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/exapi/.env"] [unique_id "apPkFtRh6OewFvqQpDljTgAAAXg"]
[Sun Aug 30 03:04:38.253853 2026] [security2:error] [pid 488669:tid 488916] [client 20.48.250.41:53360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/666.php"] [unique_id "apPkFtRh6OewFvqQpDljTwAAAXc"]
[Sun Aug 30 03:04:38.258766 2026] [security2:error] [pid 488669:tid 488931] [client 20.104.49.130:57688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/100.php"] [unique_id "apPkFtRh6OewFvqQpDljUAAAAYY"]
[Sun Aug 30 03:04:38.272570 2026] [security2:error] [pid 488669:tid 488822] [client 4.205.62.107:25884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/tax.php"] [unique_id "apPkFtRh6OewFvqQpDljUQAAARk"]
[Sun Aug 30 03:04:38.280112 2026] [security2:error] [pid 488669:tid 488854] [client 20.196.209.81:13917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/login.php"] [unique_id "apPkFtRh6OewFvqQpDljUgAAATk"]
[Sun Aug 30 03:04:38.287056 2026] [security2:error] [pid 488669:tid 488868] [client 34.15.145.202:57806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/test.php"] [unique_id "apPkFtRh6OewFvqQpDljVAAAAUc"]
[Sun Aug 30 03:04:38.291572 2026] [security2:error] [pid 488669:tid 488855] [client 4.205.62.107:63977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/application.config.php"] [unique_id "apPkFtRh6OewFvqQpDljVgAAATo"]
[Sun Aug 30 03:04:38.339616 2026] [security2:error] [pid 488669:tid 488875] [client 20.63.81.20:59091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/comand.php"] [unique_id "apPkFtRh6OewFvqQpDljWwAAAU4"]
[Sun Aug 30 03:04:38.405685 2026] [security2:error] [pid 488669:tid 488832] [client 20.48.250.41:53289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/knmt.php"] [unique_id "apPkFtRh6OewFvqQpDljZQAAASM"]
[Sun Aug 30 03:04:38.408377 2026] [security2:error] [pid 488669:tid 488877] [client 68.155.159.216:60595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-admin/images/about.php"] [unique_id "apPkFtRh6OewFvqQpDljZgAAAVA"]
[Sun Aug 30 03:04:38.424788 2026] [security2:error] [pid 488669:tid 488836] [client 20.104.50.220:51574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-blog.php"] [unique_id "apPkFtRh6OewFvqQpDljaQAAASc"]
[Sun Aug 30 03:04:38.429811 2026] [security2:error] [pid 488669:tid 488873] [client 20.220.204.93:10331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/gettest.php"] [unique_id "apPkFtRh6OewFvqQpDljagAAAUw"]
[Sun Aug 30 03:04:38.470942 2026] [security2:error] [pid 488669:tid 488819] [client 20.63.81.20:59045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp_motu_myk3v.php"] [unique_id "apPkFtRh6OewFvqQpDljcgAAARY"]
[Sun Aug 30 03:04:38.480346 2026] [security2:error] [pid 488669:tid 488866] [client 20.48.251.3:7061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/thui.php"] [unique_id "apPkFtRh6OewFvqQpDljdAAAAUU"]
[Sun Aug 30 03:04:38.487834 2026] [security2:error] [pid 488669:tid 488907] [client 20.104.18.15:33743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/adminfuns.php"] [unique_id "apPkFtRh6OewFvqQpDljdgAAAW4"]
[Sun Aug 30 03:04:38.493786 2026] [security2:error] [pid 488669:tid 488916] [client 20.48.251.3:54770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/php_info.php"] [unique_id "apPkFtRh6OewFvqQpDljeAAAAXc"]
[Sun Aug 30 03:04:38.501442 2026] [security2:error] [pid 488669:tid 488908] [client 20.48.251.3:64393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/xda.php"] [unique_id "apPkFtRh6OewFvqQpDljeQAAAW8"]
[Sun Aug 30 03:04:38.526433 2026] [security2:error] [pid 488669:tid 488869] [client 47.128.119.238:16650] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.munsterland.net"] [uri "/robots.txt"] [unique_id "apPkFtRh6OewFvqQpDljewAAAUg"]
[Sun Aug 30 03:04:38.528600 2026] [authz_core:error] [pid 488669:tid 488872] [client 66.249.66.193:39230] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:38.528895 2026] [authz_core:error] [pid 488669:tid 488872] [client 66.249.66.193:39230] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:38.578532 2026] [security2:error] [pid 488669:tid 488857] [client 20.196.209.81:5290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/wp-load.php"] [unique_id "apPkFtRh6OewFvqQpDljgQAAATw"]
[Sun Aug 30 03:04:38.580799 2026] [security2:error] [pid 488669:tid 488883] [client 20.220.204.93:10985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/35.php"] [unique_id "apPkFtRh6OewFvqQpDljggAAAVY"]
[Sun Aug 30 03:04:38.594896 2026] [authz_core:error] [pid 488669:tid 488881] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fdocs
[Sun Aug 30 03:04:38.595155 2026] [authz_core:error] [pid 488669:tid 488881] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fdocs
[Sun Aug 30 03:04:38.600634 2026] [security2:error] [pid 488669:tid 488826] [client 20.63.81.20:59049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/wp_motu_ypdat.php"] [unique_id "apPkFtRh6OewFvqQpDljhQAAAR0"]
[Sun Aug 30 03:04:38.615076 2026] [security2:error] [pid 488669:tid 488886] [client 20.48.250.41:53312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/sbhu.php"] [unique_id "apPkFtRh6OewFvqQpDljhgAAAVk"]
[Sun Aug 30 03:04:38.672284 2026] [security2:error] [pid 488669:tid 488823] [client 20.151.200.44:58853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/xwpg.php"] [unique_id "apPkFtRh6OewFvqQpDljjAAAARo"]
[Sun Aug 30 03:04:38.674158 2026] [security2:error] [pid 488669:tid 488837] [client 20.196.209.81:7951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/min.php"] [unique_id "apPkFtRh6OewFvqQpDljjQAAASg"]
[Sun Aug 30 03:04:38.682283 2026] [security2:error] [pid 488669:tid 488807] [client 136.92.30.49:34604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/sitemaps/.env"] [unique_id "apPkFtRh6OewFvqQpDljjwAAAQo"]
[Sun Aug 30 03:04:38.690122 2026] [security2:error] [pid 488669:tid 488914] [client 20.104.50.220:29853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "michelleshell.com"] [uri "/View.php"] [unique_id "apPkFtRh6OewFvqQpDljkAAAAXU"]
[Sun Aug 30 03:04:38.701511 2026] [authz_core:error] [pid 488669:tid 488928] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fman%2Fman7
[Sun Aug 30 03:04:38.701824 2026] [authz_core:error] [pid 488669:tid 488928] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fman%2Fman7
[Sun Aug 30 03:04:38.708082 2026] [security2:error] [pid 488669:tid 488910] [client 20.104.50.220:29322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/advanced-cf7-db.php"] [unique_id "apPkFtRh6OewFvqQpDljlAAAAXE"]
[Sun Aug 30 03:04:38.746526 2026] [security2:error] [pid 488669:tid 488831] [client 20.48.250.41:53366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/a332.php"] [unique_id "apPkFtRh6OewFvqQpDljlQAAASI"]
[Sun Aug 30 03:04:38.751633 2026] [security2:error] [pid 488669:tid 488894] [client 4.205.62.107:4138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/apikeys.php"] [unique_id "apPkFtRh6OewFvqQpDljlwAAAWE"]
[Sun Aug 30 03:04:38.761736 2026] [authz_core:error] [pid 488669:tid 488813] [client 66.249.66.68:59986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:38.762243 2026] [authz_core:error] [pid 488669:tid 488813] [client 66.249.66.68:59986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:38.763401 2026] [security2:error] [pid 488669:tid 488858] [client 20.63.81.20:59035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/edit.php"] [unique_id "apPkFtRh6OewFvqQpDljmgAAAT0"]
[Sun Aug 30 03:04:38.773738 2026] [security2:error] [pid 488669:tid 488812] [client 114.119.155.64:51057] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thomas-joachim-richter.info"] [uri "/"] [unique_id "apPkFtRh6OewFvqQpDljmwAAAQ8"], referer: https://www.thomas-joachim-richter.info/
[Sun Aug 30 03:04:38.783500 2026] [security2:error] [pid 488669:tid 488841] [client 4.205.62.107:44895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/wp-konfig.backup.php"] [unique_id "apPkFtRh6OewFvqQpDljnQAAASw"]
[Sun Aug 30 03:04:38.789252 2026] [security2:error] [pid 488669:tid 488889] [client 20.151.200.44:37883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/4e.php"] [unique_id "apPkFtRh6OewFvqQpDljnwAAAVw"]
[Sun Aug 30 03:04:38.803624 2026] [security2:error] [pid 488669:tid 488845] [client 20.220.204.93:52746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/maraz.php"] [unique_id "apPkFtRh6OewFvqQpDljowAAATA"]
[Sun Aug 30 03:04:38.808809 2026] [security2:error] [pid 488669:tid 488929] [client 20.48.251.3:55515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/env.php"] [unique_id "apPkFtRh6OewFvqQpDljpgAAAYQ"]
[Sun Aug 30 03:04:38.824288 2026] [security2:error] [pid 488669:tid 488869] [client 20.48.251.3:59278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/bootstrap.php"] [unique_id "apPkFtRh6OewFvqQpDljqwAAAUg"]
[Sun Aug 30 03:04:38.837458 2026] [security2:error] [pid 488669:tid 488848] [client 4.205.62.107:22965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/olfclass.php"] [unique_id "apPkFtRh6OewFvqQpDljsQAAATM"]
[Sun Aug 30 03:04:38.875627 2026] [security2:error] [pid 488669:tid 488840] [client 20.48.250.41:53316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/ws66.php"] [unique_id "apPkFtRh6OewFvqQpDljtgAAASs"]
[Sun Aug 30 03:04:38.880214 2026] [security2:error] [pid 488669:tid 488811] [client 20.48.251.3:23469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/php_info.php"] [unique_id "apPkFtRh6OewFvqQpDljtwAAAQ4"]
[Sun Aug 30 03:04:38.896076 2026] [security2:error] [pid 488669:tid 488837] [client 20.63.81.20:58981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/tqkdqbbv.php"] [unique_id "apPkFtRh6OewFvqQpDljuQAAASg"]
[Sun Aug 30 03:04:38.896108 2026] [security2:error] [pid 488669:tid 488923] [client 4.205.62.107:63752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/87.php"] [unique_id "apPkFtRh6OewFvqQpDljugAAAX4"]
[Sun Aug 30 03:04:38.935606 2026] [security2:error] [pid 488669:tid 488911] [client 20.197.61.180:9205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/salient/css/build/plugins/login.php"] [unique_id "apPkFtRh6OewFvqQpDljwAAAAXI"]
[Sun Aug 30 03:04:38.945726 2026] [security2:error] [pid 488669:tid 488817] [client 20.104.50.220:33175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/store.php"] [unique_id "apPkFtRh6OewFvqQpDljwwAAARQ"]
[Sun Aug 30 03:04:38.967522 2026] [security2:error] [pid 488669:tid 488859] [client 20.104.50.220:5621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/autoload_classmap.php"] [unique_id "apPkFtRh6OewFvqQpDljyAAAAT4"]
[Sun Aug 30 03:04:38.969721 2026] [security2:error] [pid 488669:tid 488843] [client 20.196.209.81:6104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/wp-settings.php"] [unique_id "apPkFtRh6OewFvqQpDljygAAAS4"]
[Sun Aug 30 03:04:39.000127 2026] [security2:error] [pid 488669:tid 488907] [client 20.104.50.220:46181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/5index.php"] [unique_id "apPkFtRh6OewFvqQpDljzwAAAW4"]
[Sun Aug 30 03:04:39.010744 2026] [security2:error] [pid 488669:tid 488838] [client 20.220.204.93:42418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/kbfr.php"] [unique_id "apPkF9Rh6OewFvqQpDlj0gAAASk"]
[Sun Aug 30 03:04:39.026575 2026] [security2:error] [pid 488669:tid 488869] [client 20.63.81.20:59061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/kjyehoxl.php"] [unique_id "apPkF9Rh6OewFvqQpDlj1QAAAUg"]
[Sun Aug 30 03:04:39.028378 2026] [security2:error] [pid 488669:tid 488928] [client 20.48.250.41:53322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/ws68.php"] [unique_id "apPkF9Rh6OewFvqQpDlj1wAAAYM"]
[Sun Aug 30 03:04:39.050842 2026] [security2:error] [pid 488669:tid 488857] [client 4.205.62.107:2970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/debug.php"] [unique_id "apPkF9Rh6OewFvqQpDlj2wAAATw"]
[Sun Aug 30 03:04:39.066112 2026] [security2:error] [pid 488669:tid 488824] [client 20.196.209.81:7956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/module.php"] [unique_id "apPkF9Rh6OewFvqQpDlj3AAAARs"]
[Sun Aug 30 03:04:39.077235 2026] [security2:error] [pid 488669:tid 488884] [client 4.205.62.107:51749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/66.php"] [unique_id "apPkF9Rh6OewFvqQpDlj4QAAAVc"]
[Sun Aug 30 03:04:39.090459 2026] [authz_core:error] [pid 488669:tid 488822] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fdocs
[Sun Aug 30 03:04:39.090753 2026] [authz_core:error] [pid 488669:tid 488822] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fdocs
[Sun Aug 30 03:04:39.100449 2026] [security2:error] [pid 488669:tid 488865] [client 34.15.145.202:57812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/p.php"] [unique_id "apPkF9Rh6OewFvqQpDlj5wAAAUQ"]
[Sun Aug 30 03:04:39.127724 2026] [security2:error] [pid 488669:tid 488914] [client 20.104.50.220:61673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/12j.php"] [unique_id "apPkF9Rh6OewFvqQpDlj6wAAAXU"]
[Sun Aug 30 03:04:39.145265 2026] [security2:error] [pid 488669:tid 488934] [client 20.48.251.3:4688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/public/bnn_.php.php"] [unique_id "apPkF9Rh6OewFvqQpDlj7QAAAYk"]
[Sun Aug 30 03:04:39.145276 2026] [security2:error] [pid 488669:tid 488831] [client 20.220.204.93:11198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/wp-act.php"] [unique_id "apPkF9Rh6OewFvqQpDlj7wAAASI"]
[Sun Aug 30 03:04:39.164020 2026] [security2:error] [pid 488669:tid 488859] [client 20.63.81.20:58986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/llyuxaqd.php"] [unique_id "apPkF9Rh6OewFvqQpDlj8gAAAT4"]
[Sun Aug 30 03:04:39.164628 2026] [security2:error] [pid 488669:tid 488881] [client 20.48.250.41:53372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/users.php"] [unique_id "apPkF9Rh6OewFvqQpDlj8wAAAVQ"]
[Sun Aug 30 03:04:39.169931 2026] [security2:error] [pid 488669:tid 488812] [client 4.205.62.107:27286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/environment.php"] [unique_id "apPkF9Rh6OewFvqQpDlj9QAAAQ8"]
[Sun Aug 30 03:04:39.177865 2026] [security2:error] [pid 488669:tid 488887] [client 20.104.50.220:32294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/fpebr.php"] [unique_id "apPkF9Rh6OewFvqQpDlj9wAAAVo"]
[Sun Aug 30 03:04:39.201424 2026] [authz_core:error] [pid 488669:tid 488917] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:39.201730 2026] [authz_core:error] [pid 488669:tid 488917] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:39.205084 2026] [security2:error] [pid 488669:tid 488869] [client 4.205.62.107:65291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/css.php"] [unique_id "apPkF9Rh6OewFvqQpDlj_wAAAUg"]
[Sun Aug 30 03:04:39.211311 2026] [security2:error] [pid 488669:tid 488851] [client 20.104.18.15:9117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/bo.php"] [unique_id "apPkF9Rh6OewFvqQpDlkAgAAATY"]
[Sun Aug 30 03:04:39.223567 2026] [security2:error] [pid 488669:tid 488824] [client 20.104.50.220:29174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/vendor/priv8.php"] [unique_id "apPkF9Rh6OewFvqQpDlkAwAAARs"]
[Sun Aug 30 03:04:39.264260 2026] [security2:error] [pid 488669:tid 488807] [client 20.48.251.3:34596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/otuz1.php"] [unique_id "apPkF9Rh6OewFvqQpDlkDQAAAQo"]
[Sun Aug 30 03:04:39.276841 2026] [security2:error] [pid 488669:tid 488934] [client 20.151.200.44:58942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/sxxb.php"] [unique_id "apPkF9Rh6OewFvqQpDlkEQAAAYk"]
[Sun Aug 30 03:04:39.280173 2026] [security2:error] [pid 488669:tid 488881] [client 68.155.159.216:59938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/file88.php"] [unique_id "apPkF9Rh6OewFvqQpDlkEwAAAVQ"]
[Sun Aug 30 03:04:39.281318 2026] [security2:error] [pid 488669:tid 488881] [client 20.220.204.93:64316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkF9Rh6OewFvqQpDlkFAAAAVQ"]
[Sun Aug 30 03:04:39.304635 2026] [security2:error] [pid 488669:tid 488887] [client 4.205.62.107:18685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/routes.php"] [unique_id "apPkF9Rh6OewFvqQpDlkGgAAAVo"]
[Sun Aug 30 03:04:39.304969 2026] [security2:error] [pid 488669:tid 488929] [client 20.63.81.20:58904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/nbwxolou.php"] [unique_id "apPkF9Rh6OewFvqQpDlkGwAAAYQ"]
[Sun Aug 30 03:04:39.325962 2026] [security2:error] [pid 488669:tid 488870] [client 20.104.18.15:31686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/info.php/new.php"] [unique_id "apPkF9Rh6OewFvqQpDlkHwAAAUk"]
[Sun Aug 30 03:04:39.327813 2026] [security2:error] [pid 488669:tid 488899] [client 20.220.204.93:5022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/24.php"] [unique_id "apPkF9Rh6OewFvqQpDlkIAAAAWY"]
[Sun Aug 30 03:04:39.331509 2026] [security2:error] [pid 488669:tid 488827] [client 158.23.184.117:12443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/wp-includes/ID3/config.php"] [unique_id "apPkF9Rh6OewFvqQpDlkIwAAAR4"]
[Sun Aug 30 03:04:39.340232 2026] [security2:error] [pid 488669:tid 488857] [client 20.48.250.41:53352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/bzjdlofz.php"] [unique_id "apPkF9Rh6OewFvqQpDlkJQAAATw"]
[Sun Aug 30 03:04:39.369021 2026] [security2:error] [pid 488669:tid 488811] [client 20.196.209.81:23653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/themes/wp-signup.php"] [unique_id "apPkF9Rh6OewFvqQpDlkMAAAAQ4"]
[Sun Aug 30 03:04:39.372065 2026] [security2:error] [pid 488669:tid 488839] [client 20.48.251.3:7075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/pinfo.php"] [unique_id "apPkF9Rh6OewFvqQpDlkMQAAASo"]
[Sun Aug 30 03:04:39.382451 2026] [security2:error] [pid 488669:tid 488851] [client 158.23.184.117:12440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/test1.php"] [unique_id "apPkF9Rh6OewFvqQpDlkNAAAATY"]
[Sun Aug 30 03:04:39.425525 2026] [security2:error] [pid 488669:tid 488831] [client 20.220.204.93:63844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkF9Rh6OewFvqQpDlkOQAAASI"]
[Sun Aug 30 03:04:39.429056 2026] [security2:error] [pid 488669:tid 488887] [client 4.205.62.107:63965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/xp.php"] [unique_id "apPkF9Rh6OewFvqQpDlkOgAAAVo"]
[Sun Aug 30 03:04:39.435505 2026] [security2:error] [pid 488669:tid 488891] [client 20.63.81.20:58989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/nsxeubyv.php"] [unique_id "apPkF9Rh6OewFvqQpDlkPQAAAV4"]
[Sun Aug 30 03:04:39.451333 2026] [security2:error] [pid 488669:tid 488844] [client 4.205.62.107:25886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPkF9Rh6OewFvqQpDlkQgAAAS8"]
[Sun Aug 30 03:04:39.457145 2026] [security2:error] [pid 488669:tid 488894] [client 20.151.200.44:47057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPkF9Rh6OewFvqQpDlkRgAAAWE"]
[Sun Aug 30 03:04:39.468413 2026] [security2:error] [pid 488669:tid 488893] [client 4.205.62.107:36029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/wp-info.php"] [unique_id "apPkF9Rh6OewFvqQpDlkSgAAAWA"]
[Sun Aug 30 03:04:39.488710 2026] [security2:error] [pid 488669:tid 488873] [client 20.48.250.41:53338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/selesai.php"] [unique_id "apPkF9Rh6OewFvqQpDlkTwAAAUw"]
[Sun Aug 30 03:04:39.489469 2026] [security2:error] [pid 488669:tid 488824] [client 20.196.209.81:13890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/ms-files.php"] [unique_id "apPkF9Rh6OewFvqQpDlkUAAAARs"]
[Sun Aug 30 03:04:39.525868 2026] [security2:error] [pid 488669:tid 488839] [client 158.23.184.117:12472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/wp-admin/edit-tags.php"] [unique_id "apPkF9Rh6OewFvqQpDlkVAAAASo"]
[Sun Aug 30 03:04:39.538879 2026] [security2:error] [pid 488669:tid 488881] [client 20.220.204.93:10613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/155.php"] [unique_id "apPkF9Rh6OewFvqQpDlkVQAAAVQ"]
[Sun Aug 30 03:04:39.562747 2026] [security2:error] [pid 488669:tid 488897] [client 20.104.50.220:51613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-utchershill.php"] [unique_id "apPkF9Rh6OewFvqQpDlkVwAAAWQ"]
[Sun Aug 30 03:04:39.570203 2026] [security2:error] [pid 488669:tid 488817] [client 20.63.81.20:58831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/zfqipfss.php"] [unique_id "apPkF9Rh6OewFvqQpDlkWgAAARQ"]
[Sun Aug 30 03:04:39.576223 2026] [authz_core:error] [pid 488669:tid 488917] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fdocs
[Sun Aug 30 03:04:39.576682 2026] [authz_core:error] [pid 488669:tid 488917] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fdocs
[Sun Aug 30 03:04:39.587473 2026] [security2:error] [pid 488669:tid 488925] [client 20.104.49.130:52291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.katbacon.com"] [uri "/xwx1.php"] [unique_id "apPkF9Rh6OewFvqQpDlkYgAAAYA"]
[Sun Aug 30 03:04:39.594613 2026] [security2:error] [pid 488669:tid 488899] [client 68.155.159.216:60557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPkF9Rh6OewFvqQpDlkZAAAAWY"]
[Sun Aug 30 03:04:39.626195 2026] [security2:error] [pid 488669:tid 488825] [client 20.220.204.93:65019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/ff1.php"] [unique_id "apPkF9Rh6OewFvqQpDlkaQAAARw"]
[Sun Aug 30 03:04:39.629329 2026] [security2:error] [pid 488669:tid 488824] [client 20.48.250.41:53257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/shlo.php"] [unique_id "apPkF9Rh6OewFvqQpDlkagAAARs"]
[Sun Aug 30 03:04:39.631903 2026] [security2:error] [pid 488669:tid 488871] [client 20.48.251.3:65517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/session.php"] [unique_id "apPkF9Rh6OewFvqQpDlkbAAAAUo"]
[Sun Aug 30 03:04:39.642117 2026] [security2:error] [pid 488669:tid 488808] [client 20.48.251.3:6526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/X57.php"] [unique_id "apPkF9Rh6OewFvqQpDlkbgAAAQs"]
[Sun Aug 30 03:04:39.645336 2026] [security2:error] [pid 488669:tid 488839] [client 20.104.18.15:32992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/classwithtostring.php"] [unique_id "apPkF9Rh6OewFvqQpDlkbwAAASo"]
[Sun Aug 30 03:04:39.652936 2026] [security2:error] [pid 488669:tid 488828] [client 20.104.49.130:45747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/read.php"] [unique_id "apPkF9Rh6OewFvqQpDlkcQAAAR8"]
[Sun Aug 30 03:04:39.653593 2026] [security2:error] [pid 488669:tid 488846] [client 20.197.61.180:9213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/security.php"] [unique_id "apPkF9Rh6OewFvqQpDlkcwAAATE"]
[Sun Aug 30 03:04:39.665625 2026] [security2:error] [pid 488669:tid 488834] [client 158.23.184.117:12429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/xmlrpc.php"] [unique_id "apPkF9Rh6OewFvqQpDlkdQAAASU"]
[Sun Aug 30 03:04:39.672012 2026] [security2:error] [pid 488669:tid 488869] [client 20.48.251.3:7072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/file21.php"] [unique_id "apPkF9Rh6OewFvqQpDlkdgAAAUg"]
[Sun Aug 30 03:04:39.677724 2026] [security2:error] [pid 488669:tid 488922] [client 20.220.204.93:49201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/file.php"] [unique_id "apPkF9Rh6OewFvqQpDlkeAAAAX0"]
[Sun Aug 30 03:04:39.705386 2026] [security2:error] [pid 488669:tid 488826] [client 34.15.145.202:57824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/debug.php"] [unique_id "apPkF9Rh6OewFvqQpDlkfAAAAR0"]
[Sun Aug 30 03:04:39.713095 2026] [authz_core:error] [pid 488669:tid 488899] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:39.713418 2026] [authz_core:error] [pid 488669:tid 488899] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:39.714420 2026] [security2:error] [pid 488669:tid 488932] [client 20.63.81.20:59067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.auscreen.com.au"] [uri "/zrjuyoos.php"] [unique_id "apPkF9Rh6OewFvqQpDlkfgAAAYc"]
[Sun Aug 30 03:04:39.750882 2026] [security2:error] [pid 488669:tid 488928] [client 4.205.62.107:32510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/gjm.php"] [unique_id "apPkF9Rh6OewFvqQpDlkggAAAYM"]
[Sun Aug 30 03:04:39.756694 2026] [security2:error] [pid 488669:tid 488921] [client 20.48.250.41:53262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/asax.php"] [unique_id "apPkF9Rh6OewFvqQpDlkhAAAAXw"]
[Sun Aug 30 03:04:39.762724 2026] [security2:error] [pid 488669:tid 488889] [client 20.196.209.81:6090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/updraft/about.php"] [unique_id "apPkF9Rh6OewFvqQpDlkiAAAAVw"]
[Sun Aug 30 03:04:39.770055 2026] [authz_core:error] [pid 488669:tid 488871] [client 66.249.66.37:36116] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:39.770475 2026] [authz_core:error] [pid 488669:tid 488871] [client 66.249.66.37:36116] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:39.784884 2026] [security2:error] [pid 488669:tid 488851] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/logs/.env"] [unique_id "apPkF9Rh6OewFvqQpDlkiwAAATY"]
[Sun Aug 30 03:04:39.821185 2026] [security2:error] [pid 488669:tid 488922] [client 20.220.204.93:64972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/t.php"] [unique_id "apPkF9Rh6OewFvqQpDlklQAAAX0"]
[Sun Aug 30 03:04:39.829567 2026] [http2:info] [pid 491656:tid 491656] h2_workers: created with min=128 max=192 idle_ms=600000
[Sun Aug 30 03:04:39.860861 2026] [security2:error] [pid 488669:tid 488864] [client 20.104.50.220:29608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/Astagaaaaa.php"] [unique_id "apPkF9Rh6OewFvqQpDlknQAAAUM"]
[Sun Aug 30 03:04:39.882010 2026] [security2:error] [pid 488669:tid 488933] [client 20.196.209.81:7943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/news-portal/error.php"] [unique_id "apPkF9Rh6OewFvqQpDlknwAAAYg"]
[Sun Aug 30 03:04:39.883718 2026] [security2:error] [pid 488669:tid 488919] [client 158.23.184.117:12442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/wp-admin/.cfg_aae.php"] [unique_id "apPkF9Rh6OewFvqQpDlkoAAAAXo"]
[Sun Aug 30 03:04:39.921241 2026] [security2:error] [pid 491656:tid 491791] [client 20.48.250.41:53282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/fetch.php"] [unique_id "apPkF4vX_L6VjdbvkkSY_gAAApk"]
[Sun Aug 30 03:04:39.921747 2026] [security2:error] [pid 491656:tid 491793] [client 4.205.62.107:4101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/motu.php"] [unique_id "apPkF4vX_L6VjdbvkkSY_wAAAps"]
[Sun Aug 30 03:04:39.921776 2026] [security2:error] [pid 491656:tid 491794] [client 4.205.62.107:44422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/packed.php"] [unique_id "apPkF4vX_L6VjdbvkkSZAAAAApw"]
[Sun Aug 30 03:04:39.929515 2026] [security2:error] [pid 488669:tid 488867] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/cache/.env"] [unique_id "apPkF9Rh6OewFvqQpDlkqQAAAUY"]
[Sun Aug 30 03:04:39.956282 2026] [security2:error] [pid 488669:tid 488922] [client 20.48.251.3:50032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/xve22.php"] [unique_id "apPkF9Rh6OewFvqQpDlksQAAAX0"]
[Sun Aug 30 03:04:39.960456 2026] [security2:error] [pid 491656:tid 491804] [client 20.220.204.93:63832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/erty.php"] [unique_id "apPkF4vX_L6VjdbvkkSZBAAAAqY"]
[Sun Aug 30 03:04:39.974886 2026] [security2:error] [pid 488669:tid 488817] [client 20.48.251.3:55772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/333.php"] [unique_id "apPkF9Rh6OewFvqQpDlkuAAAARQ"]
[Sun Aug 30 03:04:39.976538 2026] [security2:error] [pid 491656:tid 491807] [client 4.205.62.107:55261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/66.php"] [unique_id "apPkF4vX_L6VjdbvkkSZBwAAAqk"]
[Sun Aug 30 03:04:39.979628 2026] [security2:error] [pid 491656:tid 491810] [client 20.220.204.93:5041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPkF4vX_L6VjdbvkkSZCQAAAqw"]
[Sun Aug 30 03:04:40.002727 2026] [security2:error] [pid 491656:tid 491821] [client 4.205.62.107:22962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/gnmlc.php"] [unique_id "apPkGIvX_L6VjdbvkkSZDQAAArc"]
[Sun Aug 30 03:04:40.014454 2026] [security2:error] [pid 488669:tid 488933] [client 20.48.251.3:23424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/session.php"] [unique_id "apPkGNRh6OewFvqQpDlkvQAAAYg"]
[Sun Aug 30 03:04:40.025262 2026] [security2:error] [pid 491656:tid 491809] [client 158.23.184.117:12431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/wp-content/.wp_a1f.php"] [unique_id "apPkGIvX_L6VjdbvkkSZDgAAAqs"]
[Sun Aug 30 03:04:40.031156 2026] [security2:error] [pid 488669:tid 488824] [client 4.205.62.107:60555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/plss3.php"] [unique_id "apPkGNRh6OewFvqQpDlkwAAAARs"]
[Sun Aug 30 03:04:40.042775 2026] [authz_core:error] [pid 488669:tid 488831] [client 66.249.66.192:59966] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:40.043214 2026] [authz_core:error] [pid 488669:tid 488831] [client 66.249.66.192:59966] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:40.053475 2026] [security2:error] [pid 491656:tid 491837] [client 20.48.250.41:53368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/vx.php"] [unique_id "apPkGIvX_L6VjdbvkkSZEwAAAsc"]
[Sun Aug 30 03:04:40.075007 2026] [security2:error] [pid 488669:tid 488885] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/mailer/.env"] [unique_id "apPkGNRh6OewFvqQpDlkxwAAAVg"]
[Sun Aug 30 03:04:40.084546 2026] [security2:error] [pid 491656:tid 491847] [client 20.104.50.220:33213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/unzip.php"] [unique_id "apPkGIvX_L6VjdbvkkSZFwAAAtE"]
[Sun Aug 30 03:04:40.090956 2026] [authz_core:error] [pid 488669:tid 488889] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus
[Sun Aug 30 03:04:40.091311 2026] [authz_core:error] [pid 488669:tid 488889] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus
[Sun Aug 30 03:04:40.101699 2026] [security2:error] [pid 491656:tid 491854] [client 20.220.204.93:64350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/0x.php"] [unique_id "apPkGIvX_L6VjdbvkkSZGQAAAtg"]
[Sun Aug 30 03:04:40.125121 2026] [security2:error] [pid 488669:tid 488838] [client 20.104.50.220:5540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/inputs.php"] [unique_id "apPkGNRh6OewFvqQpDlk0AAAASk"]
[Sun Aug 30 03:04:40.140278 2026] [security2:error] [pid 488669:tid 488811] [client 20.104.50.220:46196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/6index.php"] [unique_id "apPkGNRh6OewFvqQpDlk1QAAAQ4"]
[Sun Aug 30 03:04:40.162296 2026] [security2:error] [pid 491656:tid 491825] [client 20.196.209.81:6093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/upgrade-temp-backup/min.php"] [unique_id "apPkGIvX_L6VjdbvkkSZIgAAArs"]
[Sun Aug 30 03:04:40.167634 2026] [security2:error] [pid 488669:tid 488878] [client 158.23.184.117:12450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/12.php"] [unique_id "apPkGNRh6OewFvqQpDlk2AAAAVE"]
[Sun Aug 30 03:04:40.177434 2026] [security2:error] [pid 488669:tid 488925] [client 20.220.204.93:5018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/06.php"] [unique_id "apPkGNRh6OewFvqQpDlk2wAAAYA"]
[Sun Aug 30 03:04:40.188596 2026] [security2:error] [pid 491656:tid 491878] [client 4.205.62.107:2815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/nzv.php"] [unique_id "apPkGIvX_L6VjdbvkkSZJAAAAvA"]
[Sun Aug 30 03:04:40.194862 2026] [security2:error] [pid 491656:tid 491882] [client 20.48.250.41:53367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/global.php"] [unique_id "apPkGIvX_L6VjdbvkkSZJgAAAvQ"]
[Sun Aug 30 03:04:40.219796 2026] [security2:error] [pid 491656:tid 491895] [client 4.205.62.107:56580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/admin.php"] [unique_id "apPkGIvX_L6VjdbvkkSZLAAAAwE"]
[Sun Aug 30 03:04:40.222569 2026] [security2:error] [pid 488669:tid 488864] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/mail/.env"] [unique_id "apPkGNRh6OewFvqQpDlk4gAAAUM"]
[Sun Aug 30 03:04:40.236905 2026] [security2:error] [pid 488669:tid 488933] [client 20.220.204.93:64964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/66.php"] [unique_id "apPkGNRh6OewFvqQpDlk5AAAAYg"]
[Sun Aug 30 03:04:40.243220 2026] [authz_core:error] [pid 488669:tid 488923] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:40.243604 2026] [authz_core:error] [pid 488669:tid 488923] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:40.271056 2026] [security2:error] [pid 491656:tid 491869] [client 20.196.209.81:16466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/nvt/includes/plugins/wp-blog-header.php"] [unique_id "apPkGIvX_L6VjdbvkkSZMQAAAuc"]
[Sun Aug 30 03:04:40.310167 2026] [security2:error] [pid 491656:tid 491856] [client 34.15.145.202:57836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/admin/phpinfo.php"] [unique_id "apPkGIvX_L6VjdbvkkSZNQAAAto"]
[Sun Aug 30 03:04:40.310334 2026] [security2:error] [pid 491656:tid 491900] [client 158.23.184.117:13276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/colour.php"] [unique_id "apPkGIvX_L6VjdbvkkSZNgAAAwY"]
[Sun Aug 30 03:04:40.314311 2026] [security2:error] [pid 488669:tid 488919] [client 20.220.204.93:40393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/class.php"] [unique_id "apPkGNRh6OewFvqQpDlk7QAAAXo"]
[Sun Aug 30 03:04:40.329885 2026] [security2:error] [pid 488669:tid 488873] [client 20.104.50.220:32564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/snd21.php"] [unique_id "apPkGNRh6OewFvqQpDlk7wAAAUw"]
[Sun Aug 30 03:04:40.334235 2026] [security2:error] [pid 491656:tid 491913] [client 20.104.50.220:61448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/danon.php"] [unique_id "apPkGIvX_L6VjdbvkkSZOAAAAxM"]
[Sun Aug 30 03:04:40.335397 2026] [authz_core:error] [pid 491656:tid 491911] [client 66.249.66.67:46866] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:40.335842 2026] [authz_core:error] [pid 491656:tid 491911] [client 66.249.66.67:46866] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:40.344386 2026] [security2:error] [pid 491656:tid 491915] [client 20.48.250.41:53264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/fs.php"] [unique_id "apPkGIvX_L6VjdbvkkSZOQAAAxU"]
[Sun Aug 30 03:04:40.348319 2026] [security2:error] [pid 488669:tid 488828] [client 20.48.251.3:44325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/wsws.php"] [unique_id "apPkGNRh6OewFvqQpDlk8wAAAR8"]
[Sun Aug 30 03:04:40.359556 2026] [security2:error] [pid 491656:tid 491918] [client 4.205.62.107:65297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/php_info.php"] [unique_id "apPkGIvX_L6VjdbvkkSZOwAAAxg"]
[Sun Aug 30 03:04:40.364457 2026] [security2:error] [pid 491656:tid 491864] [client 20.197.61.180:4045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "apPkGIvX_L6VjdbvkkSZPAAAAuI"]
[Sun Aug 30 03:04:40.365248 2026] [security2:error] [pid 491656:tid 491794] [client 20.104.50.220:52857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/css/priv8.php"] [unique_id "apPkGIvX_L6VjdbvkkSZPQAAApw"]
[Sun Aug 30 03:04:40.371813 2026] [security2:error] [pid 488669:tid 488822] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/email/.env"] [unique_id "apPkGNRh6OewFvqQpDlk9wAAARk"]
[Sun Aug 30 03:04:40.391689 2026] [security2:error] [pid 488669:tid 488834] [client 20.104.18.15:9096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/44.php"] [unique_id "apPkGNRh6OewFvqQpDlk-wAAASU"]
[Sun Aug 30 03:04:40.406507 2026] [security2:error] [pid 488669:tid 488860] [client 20.220.204.93:65011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/f35.php"] [unique_id "apPkGNRh6OewFvqQpDlk_AAAAT8"]
[Sun Aug 30 03:04:40.410014 2026] [security2:error] [pid 491656:tid 491797] [client 20.48.251.3:51497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/update.php"] [unique_id "apPkGIvX_L6VjdbvkkSZQwAAAp8"]
[Sun Aug 30 03:04:40.416585 2026] [security2:error] [pid 488669:tid 488811] [client 68.155.159.216:59956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/NewFile.php/"] [unique_id "apPkGNRh6OewFvqQpDlk_wAAAQ4"]
[Sun Aug 30 03:04:40.445553 2026] [security2:error] [pid 491656:tid 491830] [client 4.205.62.107:18999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/aww.php"] [unique_id "apPkGIvX_L6VjdbvkkSZSQAAAsA"]
[Sun Aug 30 03:04:40.452102 2026] [security2:error] [pid 491656:tid 491811] [client 158.23.184.117:13269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/wp-admin/network/themes.php"] [unique_id "apPkGIvX_L6VjdbvkkSZSgAAAq0"]
[Sun Aug 30 03:04:40.474557 2026] [security2:error] [pid 488669:tid 488933] [client 20.48.250.41:53355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/ioxi.php"] [unique_id "apPkGNRh6OewFvqQpDllDgAAAYg"]
[Sun Aug 30 03:04:40.487210 2026] [security2:error] [pid 491656:tid 491839] [client 20.220.204.93:10244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/8.php"] [unique_id "apPkGIvX_L6VjdbvkkSZTwAAAsk"]
[Sun Aug 30 03:04:40.521561 2026] [security2:error] [pid 488669:tid 488849] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/smtp/.env"] [unique_id "apPkGNRh6OewFvqQpDllEgAAATQ"]
[Sun Aug 30 03:04:40.547921 2026] [security2:error] [pid 491656:tid 491847] [client 20.151.200.44:37847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/ssss.php"] [unique_id "apPkGIvX_L6VjdbvkkSZUQAAAtE"]
[Sun Aug 30 03:04:40.553168 2026] [autoindex:error] [pid 488669:tid 488882] [client 20.104.18.15:31676] AH01276: Cannot serve directory /home4/devstol/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:04:40.554266 2026] [security2:error] [pid 488669:tid 488869] [client 20.196.209.81:14402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/upgrade-temp-backup/pk.php"] [unique_id "apPkGNRh6OewFvqQpDllGAAAAUg"]
[Sun Aug 30 03:04:40.567432 2026] [security2:error] [pid 491656:tid 491854] [client 4.205.62.107:63980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/g3.php"] [unique_id "apPkGIvX_L6VjdbvkkSZVAAAAtg"]
[Sun Aug 30 03:04:40.575337 2026] [authz_core:error] [pid 488669:tid 488928] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx
[Sun Aug 30 03:04:40.575750 2026] [authz_core:error] [pid 488669:tid 488928] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx
[Sun Aug 30 03:04:40.594663 2026] [security2:error] [pid 488669:tid 488853] [client 158.23.184.117:13252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/wp-admin/post.php"] [unique_id "apPkGNRh6OewFvqQpDllIQAAATg"]
[Sun Aug 30 03:04:40.594663 2026] [security2:error] [pid 488669:tid 488919] [client 20.48.251.3:7390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/register.php"] [unique_id "apPkGNRh6OewFvqQpDllFwAAAXo"]
[Sun Aug 30 03:04:40.618436 2026] [security2:error] [pid 491656:tid 491871] [client 20.48.250.41:53344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/bootstrap.php"] [unique_id "apPkGIvX_L6VjdbvkkSZWQAAAuk"]
[Sun Aug 30 03:04:40.632814 2026] [security2:error] [pid 491656:tid 491825] [client 20.220.204.93:42422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/0x0x.php"] [unique_id "apPkGIvX_L6VjdbvkkSZWwAAArs"]
[Sun Aug 30 03:04:40.651836 2026] [security2:error] [pid 488669:tid 488923] [client 20.104.18.15:31676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/w.php"] [unique_id "apPkGNRh6OewFvqQpDllLAAAAX4"]
[Sun Aug 30 03:04:40.662700 2026] [security2:error] [pid 491656:tid 491846] [client 20.196.209.81:7593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/oceanwp/sass/components/plugins/panel.php"] [unique_id "apPkGIvX_L6VjdbvkkSZXQAAAtA"]
[Sun Aug 30 03:04:40.666790 2026] [security2:error] [pid 488669:tid 488878] [client 20.220.204.93:64379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/wen.php"] [unique_id "apPkGNRh6OewFvqQpDllMAAAAVE"]
[Sun Aug 30 03:04:40.667376 2026] [security2:error] [pid 488669:tid 488925] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/mailing/.env"] [unique_id "apPkGNRh6OewFvqQpDllMQAAAYA"]
[Sun Aug 30 03:04:40.696189 2026] [security2:error] [pid 491656:tid 491887] [client 4.205.62.107:25484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPkGIvX_L6VjdbvkkSZYQAAAvk"]
[Sun Aug 30 03:04:40.705892 2026] [authz_core:error] [pid 488669:tid 488858] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:40.706194 2026] [authz_core:error] [pid 488669:tid 488858] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:40.717045 2026] [security2:error] [pid 488669:tid 488911] [client 20.104.50.220:63489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-log.php"] [unique_id "apPkGNRh6OewFvqQpDllOgAAAXI"]
[Sun Aug 30 03:04:40.727325 2026] [security2:error] [pid 491656:tid 491897] [client 20.151.200.44:58817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/dx.php"] [unique_id "apPkGIvX_L6VjdbvkkSZZQAAAwM"]
[Sun Aug 30 03:04:40.736009 2026] [security2:error] [pid 488669:tid 488814] [client 158.23.184.117:12474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPkGNRh6OewFvqQpDllPAAAARE"]
[Sun Aug 30 03:04:40.748624 2026] [security2:error] [pid 491656:tid 491899] [client 20.48.250.41:53356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/export.php"] [unique_id "apPkGIvX_L6VjdbvkkSZZwAAAwU"]
[Sun Aug 30 03:04:40.748807 2026] [authz_core:error] [pid 491656:tid 491898] [client 66.249.66.74:51656] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:40.749249 2026] [authz_core:error] [pid 491656:tid 491898] [client 66.249.66.74:51656] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:40.767066 2026] [security2:error] [pid 491656:tid 491906] [client 20.48.251.3:54809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/h.php"] [unique_id "apPkGIvX_L6VjdbvkkSZagAAAww"]
[Sun Aug 30 03:04:40.794876 2026] [security2:error] [pid 491656:tid 491916] [client 20.104.49.130:52312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.katbacon.com"] [uri "/bolt.php"] [unique_id "apPkGIvX_L6VjdbvkkSZbgAAAxY"]
[Sun Aug 30 03:04:40.812711 2026] [security2:error] [pid 488669:tid 488917] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/notifications/.env"] [unique_id "apPkGNRh6OewFvqQpDllTgAAAXg"]
[Sun Aug 30 03:04:40.818917 2026] [authz_core:error] [pid 488669:tid 488919] [client 66.249.66.71:55386] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:40.819282 2026] [authz_core:error] [pid 488669:tid 488919] [client 66.249.66.71:55386] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:40.823219 2026] [security2:error] [pid 488669:tid 488897] [client 62.60.130.247:61933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.whatwouldderriawear.com"] [uri "/wp-login.php"] [unique_id "apPkGNRh6OewFvqQpDllUAAAAWQ"]
[Sun Aug 30 03:04:40.857294 2026] [security2:error] [pid 491656:tid 491833] [client 20.48.251.3:64493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/mcebraed.php"] [unique_id "apPkGIvX_L6VjdbvkkSZewAAAsM"]
[Sun Aug 30 03:04:40.868570 2026] [security2:error] [pid 488669:tid 488818] [client 20.220.204.93:10356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/166.php"] [unique_id "apPkGNRh6OewFvqQpDllVgAAARU"]
[Sun Aug 30 03:04:40.876241 2026] [security2:error] [pid 491656:tid 491836] [client 68.155.159.216:59365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-admin.php"] [unique_id "apPkGIvX_L6VjdbvkkSZfQAAAsY"]
[Sun Aug 30 03:04:40.879858 2026] [security2:error] [pid 488669:tid 488922] [client 20.48.250.41:53348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/gk.php"] [unique_id "apPkGNRh6OewFvqQpDllVwAAAX0"]
[Sun Aug 30 03:04:40.880278 2026] [security2:error] [pid 491656:tid 491802] [client 20.220.204.93:64933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/inc.php"] [unique_id "apPkGIvX_L6VjdbvkkSZfgAAAqQ"]
[Sun Aug 30 03:04:40.885707 2026] [security2:error] [pid 491656:tid 491837] [client 20.104.18.15:32984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPkGIvX_L6VjdbvkkSZfwAAAsc"]
[Sun Aug 30 03:04:40.887585 2026] [security2:error] [pid 488669:tid 488932] [client 20.48.251.3:64507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/var/www/wallet/index.php"] [unique_id "apPkGNRh6OewFvqQpDllWwAAAYc"]
[Sun Aug 30 03:04:40.910417 2026] [security2:error] [pid 491656:tid 491877] [client 34.15.145.202:57844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/test/phpinfo.php"] [unique_id "apPkGIvX_L6VjdbvkkSZggAAAu8"]
[Sun Aug 30 03:04:40.946848 2026] [security2:error] [pid 491656:tid 491806] [client 20.196.209.81:23657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/upgrade-temp-backup/plugins/security.php"] [unique_id "apPkGIvX_L6VjdbvkkSZhwAAAqg"]
[Sun Aug 30 03:04:40.956435 2026] [security2:error] [pid 491656:tid 491866] [client 158.23.184.117:12423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/wp-content/post.php"] [unique_id "apPkGIvX_L6VjdbvkkSZiAAAAuQ"]
[Sun Aug 30 03:04:40.959872 2026] [security2:error] [pid 488669:tid 488900] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/notify/.env"] [unique_id "apPkGNRh6OewFvqQpDllYwAAAWc"]
[Sun Aug 30 03:04:40.977032 2026] [security2:error] [pid 488669:tid 488894] [client 20.151.200.44:47006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/xda.php"] [unique_id "apPkGNRh6OewFvqQpDllbgAAAWE"]
[Sun Aug 30 03:04:40.996515 2026] [security2:error] [pid 491656:tid 491888] [client 20.104.50.220:29142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-user.php"] [unique_id "apPkGIvX_L6VjdbvkkSZkgAAAvo"]
[Sun Aug 30 03:04:41.013401 2026] [security2:error] [pid 491656:tid 491893] [client 20.48.250.41:53286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/logs1.php"] [unique_id "apPkGYvX_L6VjdbvkkSZlQAAAv8"]
[Sun Aug 30 03:04:41.055315 2026] [security2:error] [pid 491656:tid 491852] [client 20.196.209.81:16551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/options.php"] [unique_id "apPkGYvX_L6VjdbvkkSZmQAAAtY"]
[Sun Aug 30 03:04:41.059715 2026] [security2:error] [pid 488669:tid 488897] [client 4.205.62.107:44426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/wp-info.php"] [unique_id "apPkGdRh6OewFvqQpDllfAAAAWQ"]
[Sun Aug 30 03:04:41.072073 2026] [security2:error] [pid 491656:tid 491817] [client 4.205.62.107:4140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/public/mah.php.php"] [unique_id "apPkGYvX_L6VjdbvkkSZmgAAArM"]
[Sun Aug 30 03:04:41.077241 2026] [authz_core:error] [pid 488669:tid 488860] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus
[Sun Aug 30 03:04:41.077774 2026] [authz_core:error] [pid 488669:tid 488860] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus
[Sun Aug 30 03:04:41.080466 2026] [security2:error] [pid 491656:tid 491809] [client 20.197.61.180:13902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/system.php"] [unique_id "apPkGYvX_L6VjdbvkkSZmwAAAqs"]
[Sun Aug 30 03:04:41.084321 2026] [authz_core:error] [pid 488669:tid 488839] [client 216.73.216.128:63883] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:41.084610 2026] [authz_core:error] [pid 488669:tid 488839] [client 216.73.216.128:63883] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:41.105252 2026] [security2:error] [pid 488669:tid 488906] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/sender/.env"] [unique_id "apPkGdRh6OewFvqQpDllhwAAAW0"]
[Sun Aug 30 03:04:41.105754 2026] [security2:error] [pid 488669:tid 488934] [client 20.48.251.3:55470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/06.php"] [unique_id "apPkGdRh6OewFvqQpDlliAAAAYk"]
[Sun Aug 30 03:04:41.112294 2026] [security2:error] [pid 491656:tid 491912] [client 20.48.251.3:59355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/G-in.php"] [unique_id "apPkGYvX_L6VjdbvkkSZnwAAAxI"]
[Sun Aug 30 03:04:41.114995 2026] [security2:error] [pid 491656:tid 491913] [client 20.220.204.93:37191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/h2a2ck.php"] [unique_id "apPkGYvX_L6VjdbvkkSZoAAAAxM"]
[Sun Aug 30 03:04:41.151355 2026] [security2:error] [pid 491656:tid 491810] [client 158.23.184.117:13284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "apPkGYvX_L6VjdbvkkSZqwAAAqw"]
[Sun Aug 30 03:04:41.151400 2026] [security2:error] [pid 491656:tid 491793] [client 4.205.62.107:22549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/koiy.php"] [unique_id "apPkGYvX_L6VjdbvkkSZrAAAAps"]
[Sun Aug 30 03:04:41.166272 2026] [security2:error] [pid 488669:tid 488929] [client 4.205.62.107:60587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/aws.php"] [unique_id "apPkGdRh6OewFvqQpDlllAAAAYQ"]
[Sun Aug 30 03:04:41.169332 2026] [security2:error] [pid 488669:tid 488866] [client 216.73.216.128:37909] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPkGdRh6OewFvqQpDlllQAAAUU"]
[Sun Aug 30 03:04:41.174890 2026] [security2:error] [pid 491656:tid 491816] [client 20.220.204.93:65003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/6bcwiqwj.php"] [unique_id "apPkGYvX_L6VjdbvkkSZrwAAArI"]
[Sun Aug 30 03:04:41.216721 2026] [authz_core:error] [pid 488669:tid 488831] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:41.216779 2026] [security2:error] [pid 488669:tid 488882] [client 20.48.251.3:23435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/h.php"] [unique_id "apPkGdRh6OewFvqQpDllowAAAVU"]
[Sun Aug 30 03:04:41.217078 2026] [authz_core:error] [pid 488669:tid 488831] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:41.221244 2026] [security2:error] [pid 488669:tid 488844] [client 20.104.50.220:33059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/think.php"] [unique_id "apPkGdRh6OewFvqQpDllpAAAAS8"]
[Sun Aug 30 03:04:41.229214 2026] [security2:error] [pid 491656:tid 491866] [client 4.205.62.107:27266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/aws_secret_config.php"] [unique_id "apPkGYvX_L6VjdbvkkSZuAAAAuQ"]
[Sun Aug 30 03:04:41.242684 2026] [security2:error] [pid 491656:tid 491863] [client 20.48.250.41:53293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/inege.php"] [unique_id "apPkGYvX_L6VjdbvkkSZugAAAuE"]
[Sun Aug 30 03:04:41.260211 2026] [security2:error] [pid 488669:tid 488861] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/campaign/.env"] [unique_id "apPkGdRh6OewFvqQpDllqgAAAUA"]
[Sun Aug 30 03:04:41.292799 2026] [security2:error] [pid 491656:tid 491888] [client 20.104.50.220:6117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/about.php"] [unique_id "apPkGYvX_L6VjdbvkkSZwQAAAvo"]
[Sun Aug 30 03:04:41.294675 2026] [security2:error] [pid 488669:tid 488859] [client 20.104.50.220:46414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/7index.php"] [unique_id "apPkGdRh6OewFvqQpDllswAAAT4"]
[Sun Aug 30 03:04:41.315586 2026] [security2:error] [pid 491656:tid 491832] [client 20.220.204.93:40438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/error_log.php"] [unique_id "apPkGYvX_L6VjdbvkkSZyAAAAsI"]
[Sun Aug 30 03:04:41.335440 2026] [security2:error] [pid 488669:tid 488808] [client 4.205.62.107:2333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/66.php"] [unique_id "apPkGdRh6OewFvqQpDlltwAAAQs"]
[Sun Aug 30 03:04:41.347373 2026] [security2:error] [pid 491656:tid 491856] [client 158.23.184.117:12456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/ma.php"] [unique_id "apPkGYvX_L6VjdbvkkSZywAAAto"]
[Sun Aug 30 03:04:41.367450 2026] [security2:error] [pid 491656:tid 491906] [client 4.205.62.107:51760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/png.php"] [unique_id "apPkGYvX_L6VjdbvkkSZzQAAAww"]
[Sun Aug 30 03:04:41.372842 2026] [security2:error] [pid 491656:tid 491904] [client 4.205.62.107:31704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/configuration.php"] [unique_id "apPkGYvX_L6VjdbvkkSZ0AAAAwo"]
[Sun Aug 30 03:04:41.373945 2026] [security2:error] [pid 491656:tid 491855] [client 20.196.209.81:11618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/upgrade-temp-backup/plugins/users.php"] [unique_id "apPkGYvX_L6VjdbvkkSZ0QAAAtk"]
[Sun Aug 30 03:04:41.405123 2026] [security2:error] [pid 488669:tid 488919] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/newsletter/.env"] [unique_id "apPkGdRh6OewFvqQpDllwgAAAXo"]
[Sun Aug 30 03:04:41.433670 2026] [security2:error] [pid 491656:tid 491797] [client 20.48.250.41:53333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/wp-link10.php"] [unique_id "apPkGYvX_L6VjdbvkkSZ2QAAAp8"]
[Sun Aug 30 03:04:41.447157 2026] [security2:error] [pid 491656:tid 491899] [client 20.196.209.81:7957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/panel.php"] [unique_id "apPkGYvX_L6VjdbvkkSZ2wAAAwU"]
[Sun Aug 30 03:04:41.472554 2026] [security2:error] [pid 491656:tid 491848] [client 20.104.50.220:61490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/xd.php"] [unique_id "apPkGYvX_L6VjdbvkkSZ4AAAAtI"]
[Sun Aug 30 03:04:41.482032 2026] [security2:error] [pid 491656:tid 491802] [client 20.48.251.3:44288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/localconf.php"] [unique_id "apPkGYvX_L6VjdbvkkSZ4QAAAqQ"]
[Sun Aug 30 03:04:41.483467 2026] [security2:error] [pid 491656:tid 491801] [client 4.205.62.107:31707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/admin.php"] [unique_id "apPkGYvX_L6VjdbvkkSZ4gAAAqM"]
[Sun Aug 30 03:04:41.492071 2026] [security2:error] [pid 491656:tid 491837] [client 20.220.204.93:40396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/403.php"] [unique_id "apPkGYvX_L6VjdbvkkSZ4wAAAsc"]
[Sun Aug 30 03:04:41.515602 2026] [security2:error] [pid 491656:tid 491897] [client 34.15.145.202:57854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/dev/phpinfo.php"] [unique_id "apPkGYvX_L6VjdbvkkSZ5wAAAwM"]
[Sun Aug 30 03:04:41.516278 2026] [security2:error] [pid 491656:tid 491833] [client 68.155.159.216:60007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/dropdown.php"] [unique_id "apPkGYvX_L6VjdbvkkSZ6AAAAsM"]
[Sun Aug 30 03:04:41.518953 2026] [security2:error] [pid 491656:tid 491806] [client 20.104.50.220:31825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/olu.php"] [unique_id "apPkGYvX_L6VjdbvkkSZ6QAAAqg"]
[Sun Aug 30 03:04:41.533903 2026] [security2:error] [pid 491656:tid 491818] [client 20.104.50.220:62811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/assets/priv8.php"] [unique_id "apPkGYvX_L6VjdbvkkSZ7AAAArQ"]
[Sun Aug 30 03:04:41.541428 2026] [security2:error] [pid 491656:tid 491825] [client 4.205.62.107:58143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/session.php"] [unique_id "apPkGYvX_L6VjdbvkkSZ7QAAArs"]
[Sun Aug 30 03:04:41.546326 2026] [security2:error] [pid 488669:tid 488817] [client 158.23.184.117:12424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/xleet.php"] [unique_id "apPkGdRh6OewFvqQpDll1QAAARQ"]
[Sun Aug 30 03:04:41.549421 2026] [security2:error] [pid 488669:tid 488871] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/ses/.env"] [unique_id "apPkGdRh6OewFvqQpDll1gAAAUo"]
[Sun Aug 30 03:04:41.551185 2026] [security2:error] [pid 491656:tid 491823] [client 20.104.18.15:9163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/h2.php"] [unique_id "apPkGYvX_L6VjdbvkkSZ7wAAArk"]
[Sun Aug 30 03:04:41.572556 2026] [authz_core:error] [pid 488669:tid 488845] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus
[Sun Aug 30 03:04:41.572914 2026] [authz_core:error] [pid 488669:tid 488845] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus
[Sun Aug 30 03:04:41.604393 2026] [security2:error] [pid 488669:tid 488850] [client 4.205.62.107:18781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/maxro.php"] [unique_id "apPkGdRh6OewFvqQpDll4wAAATU"]
[Sun Aug 30 03:04:41.622340 2026] [security2:error] [pid 491656:tid 491879] [client 20.48.251.3:34577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/channels.php"] [unique_id "apPkGYvX_L6VjdbvkkSZ9AAAAvE"]
[Sun Aug 30 03:04:41.654335 2026] [security2:error] [pid 488669:tid 488863] [client 20.220.204.93:42416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/cytyr.php"] [unique_id "apPkGdRh6OewFvqQpDll7wAAAUI"]
[Sun Aug 30 03:04:41.655917 2026] [security2:error] [pid 488669:tid 488858] [client 4.205.62.107:36683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/fns.php"] [unique_id "apPkGdRh6OewFvqQpDll8AAAAT0"]
[Sun Aug 30 03:04:41.658358 2026] [security2:error] [pid 491656:tid 491795] [client 20.220.204.93:63820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/easy.php"] [unique_id "apPkGYvX_L6VjdbvkkSZ-wAAAp0"]
[Sun Aug 30 03:04:41.687685 2026] [security2:error] [pid 491656:tid 491913] [client 158.23.184.117:12445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/.well-known/pki-validation/fm.php"] [unique_id "apPkGYvX_L6VjdbvkkSaAAAAAxM"]
[Sun Aug 30 03:04:41.693983 2026] [security2:error] [pid 488669:tid 488905] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/sendgrid/.env"] [unique_id "apPkGdRh6OewFvqQpDll9wAAAWw"]
[Sun Aug 30 03:04:41.702305 2026] [security2:error] [pid 491656:tid 491801] [client 20.48.250.41:53229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/ww.php"] [unique_id "apPkGYvX_L6VjdbvkkSaBQAAAqM"]
[Sun Aug 30 03:04:41.706246 2026] [security2:error] [pid 491656:tid 491793] [client 4.205.62.107:62090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/wp-konfig.php"] [unique_id "apPkGYvX_L6VjdbvkkSaBwAAAps"]
[Sun Aug 30 03:04:41.722964 2026] [authz_core:error] [pid 488669:tid 488898] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:41.723520 2026] [authz_core:error] [pid 488669:tid 488898] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:41.773222 2026] [security2:error] [pid 491656:tid 491906] [client 20.196.209.81:23678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/upgrade-temp-backup/plugins/wp-blog-header.php"] [unique_id "apPkGYvX_L6VjdbvkkSaFAAAAww"]
[Sun Aug 30 03:04:41.788430 2026] [security2:error] [pid 491656:tid 491878] [client 20.104.18.15:31734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/x.php"] [unique_id "apPkGYvX_L6VjdbvkkSaGAAAAvA"]
[Sun Aug 30 03:04:41.792698 2026] [security2:error] [pid 488669:tid 488841] [client 20.104.49.130:45702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.katbacon.com"] [uri "/cilus.php"] [unique_id "apPkGdRh6OewFvqQpDlmCgAAASw"]
[Sun Aug 30 03:04:41.798105 2026] [security2:error] [pid 491656:tid 491870] [client 20.48.251.3:7092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/124.php"] [unique_id "apPkGYvX_L6VjdbvkkSaGgAAAug"]
[Sun Aug 30 03:04:41.809736 2026] [security2:error] [pid 491656:tid 491890] [client 20.197.61.180:13913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/tflow/min.php"] [unique_id "apPkGYvX_L6VjdbvkkSaHgAAAvw"]
[Sun Aug 30 03:04:41.819330 2026] [security2:error] [pid 488669:tid 488814] [client 20.220.204.93:42387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/galer.php"] [unique_id "apPkGdRh6OewFvqQpDlmFAAAARE"]
[Sun Aug 30 03:04:41.827784 2026] [security2:error] [pid 491656:tid 491862] [client 158.23.184.117:12419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/wp-admin/user.php"] [unique_id "apPkGYvX_L6VjdbvkkSaIQAAAuA"]
[Sun Aug 30 03:04:41.832343 2026] [security2:error] [pid 488669:tid 488849] [client 20.48.250.41:53325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/w1px.php"] [unique_id "apPkGdRh6OewFvqQpDlmFgAAATQ"]
[Sun Aug 30 03:04:41.837567 2026] [security2:error] [pid 488669:tid 488915] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/sparkpost/.env"] [unique_id "apPkGdRh6OewFvqQpDlmGgAAAXY"]
[Sun Aug 30 03:04:41.838149 2026] [security2:error] [pid 491656:tid 491917] [client 20.196.209.81:7608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/reboot/assets/js/plugins/home.php"] [unique_id "apPkGYvX_L6VjdbvkkSaJQAAAxc"]
[Sun Aug 30 03:04:41.838973 2026] [security2:error] [pid 488669:tid 488915] [client 4.205.62.107:25910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/agg.php"] [unique_id "apPkGdRh6OewFvqQpDlmHAAAAXY"]
[Sun Aug 30 03:04:41.896249 2026] [authz_core:error] [pid 491656:tid 491795] [client 66.249.66.75:35380] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:41.896719 2026] [authz_core:error] [pid 491656:tid 491795] [client 66.249.66.75:35380] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:41.905059 2026] [authz_core:error] [pid 488669:tid 488819] [client 216.73.216.128:37909] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:41.905486 2026] [authz_core:error] [pid 488669:tid 488819] [client 216.73.216.128:37909] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:41.907520 2026] [security2:error] [pid 491656:tid 491797] [client 20.48.251.3:64260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/bootstrap.php"] [unique_id "apPkGYvX_L6VjdbvkkSaLgAAAp8"]
[Sun Aug 30 03:04:41.940064 2026] [security2:error] [pid 488669:tid 488863] [client 20.104.50.220:51647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/web-setting.php"] [unique_id "apPkGdRh6OewFvqQpDlmKgAAAUI"]
[Sun Aug 30 03:04:41.961669 2026] [security2:error] [pid 491656:tid 491820] [client 20.48.250.41:53258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/to.php"] [unique_id "apPkGYvX_L6VjdbvkkSaOAAAArY"]
[Sun Aug 30 03:04:41.969780 2026] [security2:error] [pid 491656:tid 491801] [client 158.23.184.117:12425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/wp-admin/radio.php"] [unique_id "apPkGYvX_L6VjdbvkkSaOQAAAqM"]
[Sun Aug 30 03:04:41.981970 2026] [security2:error] [pid 488669:tid 488825] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/postmark/.env"] [unique_id "apPkGdRh6OewFvqQpDlmNwAAARw"]
[Sun Aug 30 03:04:42.011081 2026] [security2:error] [pid 491656:tid 491887] [client 20.48.251.3:6521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/server-info.php"] [unique_id "apPkGovX_L6VjdbvkkSaRgAAAvk"]
[Sun Aug 30 03:04:42.014773 2026] [security2:error] [pid 491656:tid 491832] [client 20.104.18.15:32966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/5PJcpMFsD8B.php"] [unique_id "apPkGovX_L6VjdbvkkSaSAAAAsI"]
[Sun Aug 30 03:04:42.068716 2026] [authz_core:error] [pid 488669:tid 488884] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help
[Sun Aug 30 03:04:42.069198 2026] [authz_core:error] [pid 488669:tid 488884] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help
[Sun Aug 30 03:04:42.092162 2026] [security2:error] [pid 491656:tid 491898] [client 20.48.250.41:53217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/thui.php"] [unique_id "apPkGovX_L6VjdbvkkSaUgAAAwQ"]
[Sun Aug 30 03:04:42.110484 2026] [security2:error] [pid 491656:tid 491798] [client 20.220.204.93:64352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/fresh3.php"] [unique_id "apPkGovX_L6VjdbvkkSaVwAAAqA"]
[Sun Aug 30 03:04:42.120671 2026] [security2:error] [pid 491656:tid 491918] [client 34.15.145.202:57868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/old/phpinfo.php"] [unique_id "apPkGovX_L6VjdbvkkSaXQAAAxg"]
[Sun Aug 30 03:04:42.126041 2026] [security2:error] [pid 488669:tid 488896] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/mailgun/.env"] [unique_id "apPkGtRh6OewFvqQpDlmWAAAAWM"]
[Sun Aug 30 03:04:42.165311 2026] [security2:error] [pid 488669:tid 488853] [client 20.196.209.81:23649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/upgrade-temp-backup/plugins/wp-mail.php"] [unique_id "apPkGtRh6OewFvqQpDlmZgAAATg"]
[Sun Aug 30 03:04:42.190831 2026] [security2:error] [pid 488669:tid 488820] [client 68.155.159.216:52843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-includes/assets/index.php"] [unique_id "apPkGtRh6OewFvqQpDlmbQAAARc"]
[Sun Aug 30 03:04:42.195477 2026] [security2:error] [pid 491656:tid 491822] [client 20.151.200.44:58928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPkGovX_L6VjdbvkkSacgAAArg"]
[Sun Aug 30 03:04:42.197213 2026] [security2:error] [pid 491656:tid 491883] [client 4.205.62.107:44902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/fns.php"] [unique_id "apPkGovX_L6VjdbvkkSadAAAAvU"]
[Sun Aug 30 03:04:42.222408 2026] [authz_core:error] [pid 488669:tid 488880] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:42.222682 2026] [authz_core:error] [pid 488669:tid 488880] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:42.225439 2026] [security2:error] [pid 488669:tid 488815] [client 20.48.250.41:53187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/Jcrop.php"] [unique_id "apPkGtRh6OewFvqQpDlmcwAAARI"]
[Sun Aug 30 03:04:42.228057 2026] [security2:error] [pid 491656:tid 491844] [client 20.196.209.81:7558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/salient/css/build/plugins/login.php"] [unique_id "apPkGovX_L6VjdbvkkSaewAAAs4"]
[Sun Aug 30 03:04:42.230303 2026] [security2:error] [pid 488669:tid 488890] [client 20.104.50.220:28673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/theme-insnhpf.php"] [unique_id "apPkGtRh6OewFvqQpDlmdAAAAV0"]
[Sun Aug 30 03:04:42.237220 2026] [security2:error] [pid 491656:tid 491858] [client 20.151.200.44:37851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/zoz.php"] [unique_id "apPkGovX_L6VjdbvkkSafgAAAtw"]
[Sun Aug 30 03:04:42.239015 2026] [security2:error] [pid 491656:tid 491909] [client 20.48.251.3:55488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/xin1.php"] [unique_id "apPkGovX_L6VjdbvkkSafwAAAw8"]
[Sun Aug 30 03:04:42.249966 2026] [security2:error] [pid 491656:tid 491914] [client 158.23.184.117:13277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/bypass.php7"] [unique_id "apPkGovX_L6VjdbvkkSaggAAAxQ"]
[Sun Aug 30 03:04:42.254407 2026] [security2:error] [pid 488669:tid 488891] [client 20.48.251.3:59361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/apikeys.php"] [unique_id "apPkGtRh6OewFvqQpDlmfAAAAV4"]
[Sun Aug 30 03:04:42.258833 2026] [security2:error] [pid 491656:tid 491812] [client 20.220.204.93:46936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/baixy.php"] [unique_id "apPkGovX_L6VjdbvkkSahAAAAq4"]
[Sun Aug 30 03:04:42.270747 2026] [security2:error] [pid 488669:tid 488887] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/mandrill/.env"] [unique_id "apPkGtRh6OewFvqQpDlmggAAAVo"]
[Sun Aug 30 03:04:42.274185 2026] [security2:error] [pid 491656:tid 491830] [client 4.205.62.107:5113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/zaza.php"] [unique_id "apPkGovX_L6VjdbvkkSahgAAAsA"]
[Sun Aug 30 03:04:42.292063 2026] [security2:error] [pid 488669:tid 488882] [client 4.205.62.107:22921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/w.php"] [unique_id "apPkGtRh6OewFvqQpDlmiQAAAVU"]
[Sun Aug 30 03:04:42.301990 2026] [security2:error] [pid 491656:tid 491843] [client 4.205.62.107:63609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/app.default.php"] [unique_id "apPkGovX_L6VjdbvkkSajgAAAs0"]
[Sun Aug 30 03:04:42.357557 2026] [security2:error] [pid 491656:tid 491886] [client 20.48.251.3:23296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/bootstrap.php"] [unique_id "apPkGovX_L6VjdbvkkSamAAAAvg"]
[Sun Aug 30 03:04:42.365456 2026] [security2:error] [pid 491656:tid 491841] [client 20.104.50.220:32852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/tod.php"] [unique_id "apPkGovX_L6VjdbvkkSanAAAAss"]
[Sun Aug 30 03:04:42.390805 2026] [security2:error] [pid 491656:tid 491831] [client 158.23.184.117:12452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/wp-admin/css/colors/midnight/wp-login.php"] [unique_id "apPkGovX_L6VjdbvkkSangAAAsE"]
[Sun Aug 30 03:04:42.411479 2026] [security2:error] [pid 491656:tid 491836] [client 20.48.250.41:53353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/ws58.php"] [unique_id "apPkGovX_L6VjdbvkkSapQAAAsY"]
[Sun Aug 30 03:04:42.415144 2026] [security2:error] [pid 488669:tid 488842] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/mailjet/.env"] [unique_id "apPkGtRh6OewFvqQpDlmpAAAAS0"]
[Sun Aug 30 03:04:42.431076 2026] [security2:error] [pid 488669:tid 488890] [client 20.104.50.220:46637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/8index.php"] [unique_id "apPkGtRh6OewFvqQpDlmpgAAAV0"]
[Sun Aug 30 03:04:42.452761 2026] [security2:error] [pid 488669:tid 488832] [client 74.7.175.157:59440] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "turismoresponsable.org"] [uri "/robots.txt"] [unique_id "apPkGtRh6OewFvqQpDlmqQAAASM"]
[Sun Aug 30 03:04:42.457925 2026] [security2:error] [pid 488669:tid 488869] [client 20.104.50.220:5563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/alfa.php"] [unique_id "apPkGtRh6OewFvqQpDlmrAAAAUg"]
[Sun Aug 30 03:04:42.474088 2026] [security2:error] [pid 491656:tid 491812] [client 20.220.204.93:5033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/ava.php"] [unique_id "apPkGovX_L6VjdbvkkSarQAAAq4"]
[Sun Aug 30 03:04:42.502475 2026] [security2:error] [pid 488669:tid 488841] [client 20.48.251.3:64426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/test1.php"] [unique_id "apPkGtRh6OewFvqQpDlmtAAAASw"]
[Sun Aug 30 03:04:42.508333 2026] [security2:error] [pid 488669:tid 488887] [client 4.205.62.107:56685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/chosen.php"] [unique_id "apPkGtRh6OewFvqQpDlmtQAAAVo"]
[Sun Aug 30 03:04:42.532403 2026] [security2:error] [pid 491656:tid 491913] [client 20.197.61.180:4065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/tflow/pk.php"] [unique_id "apPkGovX_L6VjdbvkkSasgAAAxM"]
[Sun Aug 30 03:04:42.532964 2026] [security2:error] [pid 488669:tid 488907] [client 158.23.184.117:12433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/leafmailer.php"] [unique_id "apPkGtRh6OewFvqQpDlmuAAAAW4"]
[Sun Aug 30 03:04:42.548994 2026] [security2:error] [pid 491656:tid 491813] [client 4.205.62.107:2347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/admin.php"] [unique_id "apPkGovX_L6VjdbvkkSatgAAAq8"]
[Sun Aug 30 03:04:42.555364 2026] [security2:error] [pid 488669:tid 488838] [client 20.48.250.41:53373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/xs.php"] [unique_id "apPkGtRh6OewFvqQpDlmvgAAASk"]
[Sun Aug 30 03:04:42.559666 2026] [security2:error] [pid 488669:tid 488915] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/brevo/.env"] [unique_id "apPkGtRh6OewFvqQpDlmvwAAAXY"]
[Sun Aug 30 03:04:42.565710 2026] [authz_core:error] [pid 488669:tid 488817] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fvar%2Flib%2Fcloud%2Fdata
[Sun Aug 30 03:04:42.565997 2026] [authz_core:error] [pid 488669:tid 488817] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fvar%2Flib%2Fcloud%2Fdata
[Sun Aug 30 03:04:42.595768 2026] [authz_core:error] [pid 491656:tid 491807] [client 66.249.66.77:39278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:42.596019 2026] [security2:error] [pid 491656:tid 491802] [client 20.196.209.81:11610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/upgrade-temp-backup/themes/admin.php"] [unique_id "apPkGovX_L6VjdbvkkSaxAAAAqQ"]
[Sun Aug 30 03:04:42.596032 2026] [authz_core:error] [pid 491656:tid 491807] [client 66.249.66.77:39278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:42.601120 2026] [security2:error] [pid 488669:tid 488860] [client 4.205.62.107:26780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/snq.php"] [unique_id "apPkGtRh6OewFvqQpDlmxwAAAT8"]
[Sun Aug 30 03:04:42.618999 2026] [security2:error] [pid 491656:tid 491831] [client 20.48.251.3:44406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/bengi.php"] [unique_id "apPkGovX_L6VjdbvkkSazQAAAsE"]
[Sun Aug 30 03:04:42.622124 2026] [security2:error] [pid 491656:tid 491808] [client 20.196.209.81:16454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/security.php"] [unique_id "apPkGovX_L6VjdbvkkSazwAAAqo"]
[Sun Aug 30 03:04:42.626976 2026] [security2:error] [pid 491656:tid 491806] [client 20.104.50.220:61633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/dada.php"] [unique_id "apPkGovX_L6VjdbvkkSa0QAAAqg"]
[Sun Aug 30 03:04:42.660313 2026] [security2:error] [pid 491656:tid 491864] [client 20.220.10.235:24526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkGovX_L6VjdbvkkSa3AAAAuI"]
[Sun Aug 30 03:04:42.674009 2026] [security2:error] [pid 491656:tid 491852] [client 20.104.50.220:29314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/js/priv8.php"] [unique_id "apPkGovX_L6VjdbvkkSa4gAAAtY"]
[Sun Aug 30 03:04:42.674313 2026] [security2:error] [pid 491656:tid 491917] [client 158.23.184.117:12475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/hplfuns.php"] [unique_id "apPkGovX_L6VjdbvkkSa5AAAAxc"]
[Sun Aug 30 03:04:42.683775 2026] [security2:error] [pid 488669:tid 488832] [client 4.205.62.107:65329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/h.php"] [unique_id "apPkGtRh6OewFvqQpDlm5AAAASM"]
[Sun Aug 30 03:04:42.685957 2026] [security2:error] [pid 488669:tid 488922] [client 20.220.204.93:64979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/bgymj.php"] [unique_id "apPkGtRh6OewFvqQpDlm5QAAAX0"]
[Sun Aug 30 03:04:42.689659 2026] [security2:error] [pid 491656:tid 491870] [client 20.104.18.15:9139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apPkGovX_L6VjdbvkkSa6wAAAug"]
[Sun Aug 30 03:04:42.702628 2026] [security2:error] [pid 491656:tid 491819] [client 20.104.50.220:32522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/tuco.php"] [unique_id "apPkGovX_L6VjdbvkkSa8gAAArU"]
[Sun Aug 30 03:04:42.703084 2026] [security2:error] [pid 488669:tid 488870] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/transactional/.env"] [unique_id "apPkGtRh6OewFvqQpDlm6AAAAUk"]
[Sun Aug 30 03:04:42.714412 2026] [authz_core:error] [pid 488669:tid 488923] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:42.714686 2026] [authz_core:error] [pid 488669:tid 488923] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:42.720087 2026] [security2:error] [pid 491656:tid 491797] [client 34.15.145.202:57880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/tmp/phpinfo.php"] [unique_id "apPkGovX_L6VjdbvkkSa9gAAAp8"]
[Sun Aug 30 03:04:42.729232 2026] [security2:error] [pid 491656:tid 491868] [client 20.48.250.41:53268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/zu.php"] [unique_id "apPkGovX_L6VjdbvkkSa-AAAAuY"]
[Sun Aug 30 03:04:42.741618 2026] [security2:error] [pid 491656:tid 491858] [client 4.205.62.107:18998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/brc.php"] [unique_id "apPkGovX_L6VjdbvkkSa_wAAAtw"]
[Sun Aug 30 03:04:42.765670 2026] [security2:error] [pid 491656:tid 491913] [client 20.220.204.93:51541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/gdn.php"] [unique_id "apPkGovX_L6VjdbvkkSbCAAAAxM"]
[Sun Aug 30 03:04:42.792108 2026] [security2:error] [pid 491656:tid 491911] [client 20.220.10.235:24527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkGovX_L6VjdbvkkSbDgAAAxE"]
[Sun Aug 30 03:04:42.819783 2026] [security2:error] [pid 491656:tid 491816] [client 20.48.251.3:51582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/zz.php"] [unique_id "apPkGovX_L6VjdbvkkSbHAAAArI"]
[Sun Aug 30 03:04:42.822519 2026] [security2:error] [pid 488669:tid 488811] [client 68.155.159.216:54106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/.well-known/index.php"] [unique_id "apPkGtRh6OewFvqQpDlnAQAAAQ4"]
[Sun Aug 30 03:04:42.839073 2026] [security2:error] [pid 488669:tid 488934] [client 20.104.49.130:52298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.katbacon.com"] [uri "/ws78.php"] [unique_id "apPkGtRh6OewFvqQpDlnBQAAAYk"]
[Sun Aug 30 03:04:42.845216 2026] [security2:error] [pid 488669:tid 488816] [client 4.205.62.107:64018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/25.php"] [unique_id "apPkGtRh6OewFvqQpDlnCAAAARM"]
[Sun Aug 30 03:04:42.847851 2026] [security2:error] [pid 488669:tid 488858] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/bulk/.env"] [unique_id "apPkGtRh6OewFvqQpDlnCQAAAT0"]
[Sun Aug 30 03:04:42.885530 2026] [security2:error] [pid 491656:tid 491872] [client 20.48.250.41:53260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/lanka.php"] [unique_id "apPkGovX_L6VjdbvkkSbLQAAAuo"]
[Sun Aug 30 03:04:42.920090 2026] [security2:error] [pid 491656:tid 491874] [client 20.220.10.235:24555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/h02ugyh.php"] [unique_id "apPkGovX_L6VjdbvkkSbNAAAAuw"]
[Sun Aug 30 03:04:42.926439 2026] [security2:error] [pid 491656:tid 491839] [client 158.23.184.117:12420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/autoload_classmap/function.php"] [unique_id "apPkGovX_L6VjdbvkkSbNgAAAsk"]
[Sun Aug 30 03:04:42.951875 2026] [authz_core:error] [pid 491656:tid 491879] [client 66.249.66.75:35380] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:42.952186 2026] [authz_core:error] [pid 491656:tid 491879] [client 66.249.66.75:35380] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:42.955216 2026] [security2:error] [pid 491656:tid 491813] [client 20.104.18.15:31645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/ssla.php"] [unique_id "apPkGovX_L6VjdbvkkSbQAAAAq8"]
[Sun Aug 30 03:04:42.986884 2026] [security2:error] [pid 488669:tid 488807] [client 4.205.62.107:25506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/requirements.php"] [unique_id "apPkGtRh6OewFvqQpDlnJAAAAQo"]
[Sun Aug 30 03:04:42.991295 2026] [security2:error] [pid 488669:tid 488868] [client 20.196.209.81:23653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/upgrade-temp-backup/themes/login.php"] [unique_id "apPkGtRh6OewFvqQpDlnJgAAAUc"]
[Sun Aug 30 03:04:42.996068 2026] [security2:error] [pid 488669:tid 488865] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/aws/.env"] [unique_id "apPkGtRh6OewFvqQpDlnKwAAAUQ"]
[Sun Aug 30 03:04:42.999171 2026] [authz_core:error] [pid 488669:tid 488871] [client 216.73.216.128:6735] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:42.999531 2026] [authz_core:error] [pid 488669:tid 488871] [client 216.73.216.128:6735] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:43.013848 2026] [security2:error] [pid 491656:tid 491862] [client 20.196.209.81:7984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "apPkG4vX_L6VjdbvkkSbUwAAAuA"]
[Sun Aug 30 03:04:43.014980 2026] [security2:error] [pid 488669:tid 488861] [client 20.48.250.41:53259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/gettest.php"] [unique_id "apPkG9Rh6OewFvqQpDlnMgAAAUA"]
[Sun Aug 30 03:04:43.044744 2026] [security2:error] [pid 491656:tid 491869] [client 20.220.204.93:63839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/ws69.php"] [unique_id "apPkG4vX_L6VjdbvkkSbXwAAAuc"]
[Sun Aug 30 03:04:43.047553 2026] [security2:error] [pid 491656:tid 491804] [client 20.220.10.235:24564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/sf.php"] [unique_id "apPkG4vX_L6VjdbvkkSbYQAAAqY"]
[Sun Aug 30 03:04:43.049238 2026] [security2:error] [pid 491656:tid 491795] [client 20.48.251.3:54790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/333.php"] [unique_id "apPkG4vX_L6VjdbvkkSbYwAAAp0"]
[Sun Aug 30 03:04:43.055799 2026] [security2:error] [pid 491656:tid 491898] [client 20.220.204.93:10333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/f2.php"] [unique_id "apPkG4vX_L6VjdbvkkSbaQAAAwQ"]
[Sun Aug 30 03:04:43.069802 2026] [authz_core:error] [pid 488669:tid 488860] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Ftest
[Sun Aug 30 03:04:43.070267 2026] [authz_core:error] [pid 488669:tid 488860] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Ftest
[Sun Aug 30 03:04:43.086958 2026] [security2:error] [pid 488669:tid 488821] [client 20.104.50.220:51615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-ettoyag.php"] [unique_id "apPkG9Rh6OewFvqQpDlnRAAAARg"]
[Sun Aug 30 03:04:43.144468 2026] [security2:error] [pid 488669:tid 488822] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/azure/.env"] [unique_id "apPkG9Rh6OewFvqQpDlnVgAAARk"]
[Sun Aug 30 03:04:43.148790 2026] [security2:error] [pid 491656:tid 491875] [client 20.48.250.41:53251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/35.php"] [unique_id "apPkG4vX_L6VjdbvkkSbiQAAAu0"]
[Sun Aug 30 03:04:43.170911 2026] [authz_core:error] [pid 491656:tid 491820] [client 66.249.66.75:45892] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:43.171358 2026] [authz_core:error] [pid 491656:tid 491820] [client 66.249.66.75:45892] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:43.176353 2026] [security2:error] [pid 488669:tid 488931] [client 20.220.10.235:24448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/4e.php"] [unique_id "apPkG9Rh6OewFvqQpDlnYAAAAYY"]
[Sun Aug 30 03:04:43.179191 2026] [security2:error] [pid 491656:tid 491812] [client 158.23.184.117:13248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/wp-includes/wp-includes/box.php"] [unique_id "apPkG4vX_L6VjdbvkkSbmwAAAq4"]
[Sun Aug 30 03:04:43.182819 2026] [authz_core:error] [pid 488669:tid 488875] [client 216.73.216.128:37909] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:43.183089 2026] [authz_core:error] [pid 488669:tid 488875] [client 216.73.216.128:37909] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:43.201965 2026] [security2:error] [pid 491656:tid 491796] [client 20.48.251.3:64508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/gk.php"] [unique_id "apPkG4vX_L6VjdbvkkSbpAAAAp4"]
[Sun Aug 30 03:04:43.235387 2026] [security2:error] [pid 491656:tid 491814] [client 4.205.62.107:36726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/params.php"] [unique_id "apPkG4vX_L6VjdbvkkSbrQAAArA"]
[Sun Aug 30 03:04:43.236071 2026] [authz_core:error] [pid 488669:tid 488835] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:43.236603 2026] [authz_core:error] [pid 488669:tid 488835] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:43.237876 2026] [security2:error] [pid 488669:tid 488834] [client 20.104.18.15:33007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPkG9Rh6OewFvqQpDlnbAAAASU"]
[Sun Aug 30 03:04:43.258282 2026] [security2:error] [pid 488669:tid 488915] [client 20.197.61.180:13920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/theme-check/theme-check.php"] [unique_id "apPkG9Rh6OewFvqQpDlncQAAAXY"]
[Sun Aug 30 03:04:43.291057 2026] [security2:error] [pid 488669:tid 488867] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/gcp/.env"] [unique_id "apPkG9Rh6OewFvqQpDlnfwAAAUY"]
[Sun Aug 30 03:04:43.293957 2026] [security2:error] [pid 491656:tid 491915] [client 68.155.159.216:59345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/lock.php"] [unique_id "apPkG4vX_L6VjdbvkkSbwwAAAxU"]
[Sun Aug 30 03:04:43.302461 2026] [security2:error] [pid 491656:tid 491910] [client 20.104.49.130:60928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/well.php"] [unique_id "apPkG4vX_L6VjdbvkkSbyAAAAxA"]
[Sun Aug 30 03:04:43.303490 2026] [security2:error] [pid 488669:tid 488836] [client 20.48.250.41:53336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/maraz.php"] [unique_id "apPkG9Rh6OewFvqQpDlnhAAAASc"]
[Sun Aug 30 03:04:43.314337 2026] [security2:error] [pid 488669:tid 488934] [client 20.220.10.235:24544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/ssss.php"] [unique_id "apPkG9Rh6OewFvqQpDlnjAAAAYk"]
[Sun Aug 30 03:04:43.324484 2026] [security2:error] [pid 491656:tid 491877] [client 34.15.145.202:57894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/public/phpinfo.php"] [unique_id "apPkG4vX_L6VjdbvkkSbzgAAAu8"]
[Sun Aug 30 03:04:43.334624 2026] [security2:error] [pid 488669:tid 488893] [client 20.151.200.44:37840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/kcs.php"] [unique_id "apPkG9Rh6OewFvqQpDlnkAAAAWA"]
[Sun Aug 30 03:04:43.335069 2026] [security2:error] [pid 491656:tid 491792] [client 4.205.62.107:44763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/params.php"] [unique_id "apPkG4vX_L6VjdbvkkSb0AAAApo"]
[Sun Aug 30 03:04:43.338927 2026] [security2:error] [pid 491656:tid 491874] [client 20.220.204.93:33981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/grsiuk.php"] [unique_id "apPkG4vX_L6VjdbvkkSb0gAAAuw"]
[Sun Aug 30 03:04:43.339948 2026] [security2:error] [pid 491656:tid 491817] [client 158.23.184.117:12462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/wp-content/uploads/wp.php"] [unique_id "apPkG4vX_L6VjdbvkkSb0wAAArM"]
[Sun Aug 30 03:04:43.359071 2026] [authz_core:error] [pid 491656:tid 491812] [client 66.249.66.44:59630] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:43.359533 2026] [authz_core:error] [pid 491656:tid 491812] [client 66.249.66.44:59630] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:43.360973 2026] [security2:error] [pid 491656:tid 491819] [client 20.151.200.44:47043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPkG4vX_L6VjdbvkkSb1wAAArU"]
[Sun Aug 30 03:04:43.367869 2026] [security2:error] [pid 491656:tid 491825] [client 20.104.50.220:52821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/process_login.php"] [unique_id "apPkG4vX_L6VjdbvkkSb3AAAArs"]
[Sun Aug 30 03:04:43.377342 2026] [security2:error] [pid 491656:tid 491895] [client 20.48.251.3:55491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/sadd.php"] [unique_id "apPkG4vX_L6VjdbvkkSb4AAAAwE"]
[Sun Aug 30 03:04:43.379204 2026] [security2:error] [pid 491656:tid 491843] [client 20.220.204.93:64364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/ccs.php"] [unique_id "apPkG4vX_L6VjdbvkkSb4QAAAs0"]
[Sun Aug 30 03:04:43.388535 2026] [security2:error] [pid 488669:tid 488904] [client 20.48.251.3:52822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/motu.php"] [unique_id "apPkG9Rh6OewFvqQpDlnlwAAAWs"]
[Sun Aug 30 03:04:43.408368 2026] [security2:error] [pid 491656:tid 491806] [client 4.205.62.107:32502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/server_info.php"] [unique_id "apPkG4vX_L6VjdbvkkSb5QAAAqg"]
[Sun Aug 30 03:04:43.412528 2026] [security2:error] [pid 488669:tid 488814] [client 20.196.209.81:23619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/upgrade-temp-backup/themes/test.php"] [unique_id "apPkG9Rh6OewFvqQpDlnmwAAARE"]
[Sun Aug 30 03:04:43.415338 2026] [security2:error] [pid 488669:tid 488902] [client 20.196.209.81:7560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/system.php"] [unique_id "apPkG9Rh6OewFvqQpDlnnAAAAWk"]
[Sun Aug 30 03:04:43.435867 2026] [security2:error] [pid 488669:tid 488840] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/cloud/.env"] [unique_id "apPkG9Rh6OewFvqQpDlnngAAASs"]
[Sun Aug 30 03:04:43.441178 2026] [security2:error] [pid 491656:tid 491860] [client 4.205.62.107:32022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/png.php"] [unique_id "apPkG4vX_L6VjdbvkkSb6QAAAt4"]
[Sun Aug 30 03:04:43.441469 2026] [security2:error] [pid 491656:tid 491834] [client 20.220.10.235:24514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/zoz.php"] [unique_id "apPkG4vX_L6VjdbvkkSb6gAAAsQ"]
[Sun Aug 30 03:04:43.442489 2026] [security2:error] [pid 491656:tid 491906] [client 4.205.62.107:63775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/app_local.php"] [unique_id "apPkG4vX_L6VjdbvkkSb6wAAAww"]
[Sun Aug 30 03:04:43.466712 2026] [security2:error] [pid 491656:tid 491838] [client 4.205.62.107:22947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/btx25.php"] [unique_id "apPkG4vX_L6VjdbvkkSb8QAAAsg"]
[Sun Aug 30 03:04:43.471306 2026] [security2:error] [pid 488669:tid 488834] [client 20.48.250.41:53362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/kbfr.php"] [unique_id "apPkG9Rh6OewFvqQpDlnqQAAASU"]
[Sun Aug 30 03:04:43.481371 2026] [security2:error] [pid 488669:tid 488807] [client 158.23.184.117:13251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/wp-includes/css//index.php"] [unique_id "apPkG9Rh6OewFvqQpDlnqgAAAQo"]
[Sun Aug 30 03:04:43.492095 2026] [security2:error] [pid 488669:tid 488873] [client 20.48.251.3:22734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/333.php"] [unique_id "apPkG9Rh6OewFvqQpDlnrQAAAUw"]
[Sun Aug 30 03:04:43.500536 2026] [security2:error] [pid 491656:tid 491845] [client 4.205.62.107:5079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/u88.php"] [unique_id "apPkG4vX_L6VjdbvkkSb9gAAAs8"]
[Sun Aug 30 03:04:43.524374 2026] [security2:error] [pid 491656:tid 491815] [client 20.104.50.220:32868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/setor.php"] [unique_id "apPkG4vX_L6VjdbvkkSb9wAAArE"]
[Sun Aug 30 03:04:43.571147 2026] [security2:error] [pid 488669:tid 488927] [client 20.104.50.220:46878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/9index.php"] [unique_id "apPkG9Rh6OewFvqQpDlnuwAAAYI"]
[Sun Aug 30 03:04:43.571993 2026] [security2:error] [pid 488669:tid 488816] [client 20.220.10.235:24566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/kcs.php"] [unique_id "apPkG9Rh6OewFvqQpDlnvAAAARM"]
[Sun Aug 30 03:04:43.581797 2026] [security2:error] [pid 488669:tid 488917] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/infrastructure/.env"] [unique_id "apPkG9Rh6OewFvqQpDlnvwAAAXg"]
[Sun Aug 30 03:04:43.599902 2026] [authz_core:error] [pid 491656:tid 491884] [client 66.249.66.32:45136] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:43.600280 2026] [authz_core:error] [pid 491656:tid 491884] [client 66.249.66.32:45136] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:43.600721 2026] [authz_core:error] [pid 488669:tid 488877] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fbind%2Fsample%2Fvar%2Fnamed
[Sun Aug 30 03:04:43.601018 2026] [authz_core:error] [pid 488669:tid 488877] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fbind%2Fsample%2Fvar%2Fnamed
[Sun Aug 30 03:04:43.604393 2026] [security2:error] [pid 491656:tid 491888] [client 20.48.250.41:53199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/wp-act.php"] [unique_id "apPkG4vX_L6VjdbvkkScAwAAAvo"]
[Sun Aug 30 03:04:43.613942 2026] [security2:error] [pid 491656:tid 491806] [client 20.104.50.220:5930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/themes/twentytwentytwo/index.php"] [unique_id "apPkG4vX_L6VjdbvkkScCgAAAqg"]
[Sun Aug 30 03:04:43.618943 2026] [security2:error] [pid 488669:tid 488811] [client 158.23.184.117:13281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/index2.php"] [unique_id "apPkG9Rh6OewFvqQpDlnywAAAQ4"]
[Sun Aug 30 03:04:43.647082 2026] [security2:error] [pid 488669:tid 488842] [client 4.205.62.107:56905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/admin-ajax.php"] [unique_id "apPkG9Rh6OewFvqQpDln1QAAAS0"]
[Sun Aug 30 03:04:43.660961 2026] [security2:error] [pid 491656:tid 491896] [client 178.16.55.109:56485] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "calchampsoccer.org"] [uri "/index.php"] [unique_id "apPkG4vX_L6VjdbvkkScGQAAAwI"]
[Sun Aug 30 03:04:43.700194 2026] [security2:error] [pid 491656:tid 491845] [client 20.104.49.130:57682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/load.php"] [unique_id "apPkG4vX_L6VjdbvkkScIwAAAs8"]
[Sun Aug 30 03:04:43.702729 2026] [security2:error] [pid 491656:tid 491813] [client 4.205.62.107:2331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/png.php"] [unique_id "apPkG4vX_L6VjdbvkkScJAAAAq8"]
[Sun Aug 30 03:04:43.705619 2026] [security2:error] [pid 488669:tid 488885] [client 20.220.10.235:24464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/tajj.php"] [unique_id "apPkG9Rh6OewFvqQpDln4gAAAVg"]
[Sun Aug 30 03:04:43.726599 2026] [security2:error] [pid 488669:tid 488904] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/docker/.env"] [unique_id "apPkG9Rh6OewFvqQpDln5wAAAWs"]
[Sun Aug 30 03:04:43.735715 2026] [security2:error] [pid 491656:tid 491875] [client 20.48.250.41:53359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/24.php"] [unique_id "apPkG4vX_L6VjdbvkkScMAAAAu0"]
[Sun Aug 30 03:04:43.737433 2026] [authz_core:error] [pid 488669:tid 488845] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:43.737887 2026] [authz_core:error] [pid 488669:tid 488845] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:43.745940 2026] [security2:error] [pid 488669:tid 488878] [client 20.220.204.93:63857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/mar.php"] [unique_id "apPkG9Rh6OewFvqQpDln8QAAAVE"]
[Sun Aug 30 03:04:43.757935 2026] [security2:error] [pid 488669:tid 488920] [client 20.48.251.3:44367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/i.php"] [unique_id "apPkG9Rh6OewFvqQpDln-AAAAXs"]
[Sun Aug 30 03:04:43.806248 2026] [security2:error] [pid 491656:tid 491898] [client 20.196.209.81:6129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/upgrade-temp-backup/themes/wp-links-opml.php"] [unique_id "apPkG4vX_L6VjdbvkkScRwAAAwQ"]
[Sun Aug 30 03:04:43.810152 2026] [security2:error] [pid 491656:tid 491913] [client 20.196.209.81:7999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/tflow/min.php"] [unique_id "apPkG4vX_L6VjdbvkkScSQAAAxM"]
[Sun Aug 30 03:04:43.812587 2026] [security2:error] [pid 491656:tid 491910] [client 20.104.50.220:52826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/images/priv8.php"] [unique_id "apPkG4vX_L6VjdbvkkScTAAAAxA"]
[Sun Aug 30 03:04:43.812714 2026] [security2:error] [pid 491656:tid 491900] [client 158.23.184.117:12447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/wp-admin/images/about.php"] [unique_id "apPkG4vX_L6VjdbvkkScSwAAAwY"]
[Sun Aug 30 03:04:43.838920 2026] [security2:error] [pid 491656:tid 491852] [client 20.220.10.235:24550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/bge.php"] [unique_id "apPkG4vX_L6VjdbvkkScUwAAAtY"]
[Sun Aug 30 03:04:43.855865 2026] [security2:error] [pid 491656:tid 491915] [client 20.104.50.220:31823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/ice.php"] [unique_id "apPkG4vX_L6VjdbvkkScWgAAAxU"]
[Sun Aug 30 03:04:43.857963 2026] [security2:error] [pid 491656:tid 491897] [client 20.104.18.15:9144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/sao.php"] [unique_id "apPkG4vX_L6VjdbvkkScXAAAAwM"]
[Sun Aug 30 03:04:43.870145 2026] [security2:error] [pid 491656:tid 491907] [client 4.205.62.107:65399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/bootstrap.php"] [unique_id "apPkG4vX_L6VjdbvkkScYAAAAw0"]
[Sun Aug 30 03:04:43.871063 2026] [security2:error] [pid 488669:tid 488885] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/k8s/.env"] [unique_id "apPkG9Rh6OewFvqQpDloFAAAAVg"]
[Sun Aug 30 03:04:43.881918 2026] [security2:error] [pid 491656:tid 491827] [client 20.104.49.130:59566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.infinitelearners.com"] [uri "/ws58.php"] [unique_id "apPkG4vX_L6VjdbvkkScYgAAAr0"]
[Sun Aug 30 03:04:43.889223 2026] [security2:error] [pid 488669:tid 488847] [client 4.205.62.107:18674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/vx.php"] [unique_id "apPkG9Rh6OewFvqQpDloGQAAATI"]
[Sun Aug 30 03:04:43.919051 2026] [authz_core:error] [pid 488669:tid 488861] [client 216.73.216.128:63883] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:43.919503 2026] [authz_core:error] [pid 488669:tid 488861] [client 216.73.216.128:63883] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:43.929424 2026] [security2:error] [pid 488669:tid 488823] [client 20.104.50.220:61981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/xml.php"] [unique_id "apPkG9Rh6OewFvqQpDloJgAAARo"]
[Sun Aug 30 03:04:43.934389 2026] [security2:error] [pid 488669:tid 488878] [client 20.48.250.41:53270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/155.php"] [unique_id "apPkG9Rh6OewFvqQpDloKAAAAVE"]
[Sun Aug 30 03:04:43.936437 2026] [security2:error] [pid 488669:tid 488919] [client 20.220.204.93:64372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/ccu.php"] [unique_id "apPkG9Rh6OewFvqQpDloKQAAAXo"]
[Sun Aug 30 03:04:43.944260 2026] [security2:error] [pid 491656:tid 491900] [client 68.155.159.216:59981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-content/themes/too.php"] [unique_id "apPkG4vX_L6VjdbvkkScdgAAAwY"]
[Sun Aug 30 03:04:43.970087 2026] [security2:error] [pid 488669:tid 488898] [client 20.220.10.235:24556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/ssh3ll.php"] [unique_id "apPkG9Rh6OewFvqQpDloMAAAAWU"]
[Sun Aug 30 03:04:43.970294 2026] [security2:error] [pid 488669:tid 488808] [client 20.48.251.3:64444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/bigdump.php"] [unique_id "apPkG9Rh6OewFvqQpDloMQAAAQs"]
[Sun Aug 30 03:04:43.980530 2026] [security2:error] [pid 488669:tid 488884] [client 20.197.61.180:9155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/theme/about.php"] [unique_id "apPkG9Rh6OewFvqQpDloNgAAAVc"]
[Sun Aug 30 03:04:43.981622 2026] [security2:error] [pid 488669:tid 488889] [client 4.205.62.107:62120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/nlnub.php"] [unique_id "apPkG9Rh6OewFvqQpDloOgAAAVw"]
[Sun Aug 30 03:04:43.996837 2026] [security2:error] [pid 488669:tid 488877] [client 216.73.216.128:37909] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/\\""] [unique_id "apPkG9Rh6OewFvqQpDloPwAAAVA"]
[Sun Aug 30 03:04:44.005305 2026] [security2:error] [pid 491656:tid 491828] [client 20.48.251.3:51537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/test.php"] [unique_id "apPkHIvX_L6VjdbvkkScjAAAAr4"]
[Sun Aug 30 03:04:44.005378 2026] [security2:error] [pid 491656:tid 491847] [client 158.23.184.117:12471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/wp-includes/theme-compat.php"] [unique_id "apPkHIvX_L6VjdbvkkScjgAAAtE"]
[Sun Aug 30 03:04:44.016027 2026] [security2:error] [pid 488669:tid 488848] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/kubernetes/.env"] [unique_id "apPkHNRh6OewFvqQpDloRQAAATM"]
[Sun Aug 30 03:04:44.062444 2026] [security2:error] [pid 491656:tid 491810] [client 20.48.250.41:53250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/file.php"] [unique_id "apPkHIvX_L6VjdbvkkScogAAAqw"]
[Sun Aug 30 03:04:44.065425 2026] [security2:error] [pid 491656:tid 491832] [client 4.205.62.107:26507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/wp-access.php"] [unique_id "apPkHIvX_L6VjdbvkkScpQAAAsI"]
[Sun Aug 30 03:04:44.095705 2026] [security2:error] [pid 488669:tid 488834] [client 20.104.18.15:31674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apPkHNRh6OewFvqQpDloVwAAASU"]
[Sun Aug 30 03:04:44.098259 2026] [security2:error] [pid 491656:tid 491847] [client 20.220.10.235:24528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/motu.php"] [unique_id "apPkHIvX_L6VjdbvkkSctQAAAtE"]
[Sun Aug 30 03:04:44.113396 2026] [authz_core:error] [pid 488669:tid 488932] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fbind%2Fsample%2Fvar%2Fnamed
[Sun Aug 30 03:04:44.113842 2026] [authz_core:error] [pid 488669:tid 488932] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fbind%2Fsample%2Fvar%2Fnamed
[Sun Aug 30 03:04:44.114395 2026] [security2:error] [pid 491656:tid 491867] [client 20.220.204.93:64266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/ak.php"] [unique_id "apPkHIvX_L6VjdbvkkScuwAAAuU"]
[Sun Aug 30 03:04:44.139131 2026] [security2:error] [pid 491656:tid 491793] [client 34.15.145.202:57906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/php-info.php"] [unique_id "apPkHIvX_L6VjdbvkkScwwAAAps"]
[Sun Aug 30 03:04:44.143528 2026] [security2:error] [pid 491656:tid 491828] [client 158.23.184.117:13261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/NewFile.php"] [unique_id "apPkHIvX_L6VjdbvkkScygAAAr4"]
[Sun Aug 30 03:04:44.159708 2026] [security2:error] [pid 488669:tid 488910] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/terraform/.env"] [unique_id "apPkHNRh6OewFvqQpDlobgAAAXE"]
[Sun Aug 30 03:04:44.176306 2026] [security2:error] [pid 488669:tid 488816] [client 4.205.62.107:26957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/var/www/wallet/index.php"] [unique_id "apPkHNRh6OewFvqQpDlocwAAARM"]
[Sun Aug 30 03:04:44.190523 2026] [authz_core:error] [pid 488669:tid 488889] [client 216.73.216.128:63883] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:44.190898 2026] [authz_core:error] [pid 488669:tid 488889] [client 216.73.216.128:63883] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:44.203763 2026] [security2:error] [pid 488669:tid 488875] [client 20.196.209.81:7574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/tflow/pk.php"] [unique_id "apPkHNRh6OewFvqQpDloegAAAU4"]
[Sun Aug 30 03:04:44.208281 2026] [security2:error] [pid 491656:tid 491860] [client 20.196.209.81:19356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/upgrade-temp-backup/themes/wp-settings.php"] [unique_id "apPkHIvX_L6VjdbvkkSc5wAAAt4"]
[Sun Aug 30 03:04:44.215414 2026] [security2:error] [pid 491656:tid 491804] [client 20.48.251.3:54775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/G-in.php"] [unique_id "apPkHIvX_L6VjdbvkkSc6QAAAqY"]
[Sun Aug 30 03:04:44.225568 2026] [security2:error] [pid 488669:tid 488903] [client 20.104.50.220:63521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/venom.php"] [unique_id "apPkHNRh6OewFvqQpDlofgAAAWo"]
[Sun Aug 30 03:04:44.225907 2026] [security2:error] [pid 491656:tid 491793] [client 20.48.250.41:53361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPkHIvX_L6VjdbvkkSc7AAAAps"]
[Sun Aug 30 03:04:44.228453 2026] [security2:error] [pid 491656:tid 491816] [client 20.220.10.235:24539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/wefile.php"] [unique_id "apPkHIvX_L6VjdbvkkSc7gAAArI"]
[Sun Aug 30 03:04:44.247857 2026] [authz_core:error] [pid 488669:tid 488827] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:44.248389 2026] [authz_core:error] [pid 488669:tid 488827] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:44.277860 2026] [security2:error] [pid 488669:tid 488924] [client 216.73.216.128:37909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPkHNRh6OewFvqQpDlokgAAAX8"]
[Sun Aug 30 03:04:44.303750 2026] [security2:error] [pid 491656:tid 491810] [client 158.23.184.117:13307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/wp-admin/css/colors/sunrise.php"] [unique_id "apPkHIvX_L6VjdbvkkSdDwAAAqw"]
[Sun Aug 30 03:04:44.304907 2026] [security2:error] [pid 488669:tid 488865] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/ansible/.env"] [unique_id "apPkHNRh6OewFvqQpDlonAAAAUQ"]
[Sun Aug 30 03:04:44.314744 2026] [security2:error] [pid 491656:tid 491800] [client 20.220.204.93:42448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/wp-scr1pts.php"] [unique_id "apPkHIvX_L6VjdbvkkSdHAAAAqI"]
[Sun Aug 30 03:04:44.359836 2026] [security2:error] [pid 488669:tid 488851] [client 20.220.10.235:24547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/Contrller.php"] [unique_id "apPkHNRh6OewFvqQpDlopgAAATY"]
[Sun Aug 30 03:04:44.392634 2026] [security2:error] [pid 491656:tid 491854] [client 20.48.250.41:53334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/06.php"] [unique_id "apPkHIvX_L6VjdbvkkSdNQAAAtg"]
[Sun Aug 30 03:04:44.400583 2026] [security2:error] [pid 491656:tid 491877] [client 68.155.159.216:52778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/index/function.php"] [unique_id "apPkHIvX_L6VjdbvkkSdOAAAAu8"]
[Sun Aug 30 03:04:44.414496 2026] [security2:error] [pid 488669:tid 488816] [client 20.220.204.93:64290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/lib.php"] [unique_id "apPkHNRh6OewFvqQpDlorQAAARM"]
[Sun Aug 30 03:04:44.433232 2026] [security2:error] [pid 491656:tid 491812] [client 20.48.251.3:7365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/god.php"] [unique_id "apPkHIvX_L6VjdbvkkSdQQAAAq4"]
[Sun Aug 30 03:04:44.448758 2026] [security2:error] [pid 488669:tid 488824] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/.git/.env"] [unique_id "apPkHNRh6OewFvqQpDloswAAARs"]
[Sun Aug 30 03:04:44.473115 2026] [security2:error] [pid 491656:tid 491852] [client 4.205.62.107:44477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/gjm.php"] [unique_id "apPkHIvX_L6VjdbvkkSdSwAAAtY"]
[Sun Aug 30 03:04:44.488967 2026] [security2:error] [pid 488669:tid 488917] [client 158.23.184.117:13310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/ova.php"] [unique_id "apPkHNRh6OewFvqQpDlowAAAAXg"]
[Sun Aug 30 03:04:44.493133 2026] [security2:error] [pid 488669:tid 488880] [client 20.220.10.235:24459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/file66.php"] [unique_id "apPkHNRh6OewFvqQpDlowQAAAVM"]
[Sun Aug 30 03:04:44.527033 2026] [security2:error] [pid 491656:tid 491820] [client 20.48.251.3:59386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/public/mah.php.php"] [unique_id "apPkHIvX_L6VjdbvkkSdUAAAArY"]
[Sun Aug 30 03:04:44.539199 2026] [security2:error] [pid 491656:tid 491918] [client 20.104.50.220:62805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/liverpool-health.php"] [unique_id "apPkHIvX_L6VjdbvkkSdVQAAAxg"]
[Sun Aug 30 03:04:44.545125 2026] [security2:error] [pid 488669:tid 488920] [client 20.48.250.41:53249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/class.php"] [unique_id "apPkHNRh6OewFvqQpDloyAAAAXs"]
[Sun Aug 30 03:04:44.551611 2026] [security2:error] [pid 491656:tid 491851] [client 20.104.18.15:32975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/wsd.php"] [unique_id "apPkHIvX_L6VjdbvkkSdWAAAAtU"]
[Sun Aug 30 03:04:44.554368 2026] [authz_core:error] [pid 488669:tid 488861] [client 216.73.216.128:41722] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:44.554794 2026] [authz_core:error] [pid 488669:tid 488861] [client 216.73.216.128:41722] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:44.579109 2026] [security2:error] [pid 491656:tid 491881] [client 4.205.62.107:60590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/ws62.php"] [unique_id "apPkHIvX_L6VjdbvkkSdYgAAAvM"]
[Sun Aug 30 03:04:44.580309 2026] [security2:error] [pid 491656:tid 491907] [client 20.220.204.93:63852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/wp-style.php"] [unique_id "apPkHIvX_L6VjdbvkkSdYwAAAw0"]
[Sun Aug 30 03:04:44.593306 2026] [security2:error] [pid 488669:tid 488910] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/ci/.env"] [unique_id "apPkHNRh6OewFvqQpDlo3gAAAXE"]
[Sun Aug 30 03:04:44.604096 2026] [security2:error] [pid 491656:tid 491905] [client 20.196.209.81:13008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/theme-check/theme-check.php"] [unique_id "apPkHIvX_L6VjdbvkkSdagAAAws"]
[Sun Aug 30 03:04:44.608768 2026] [authz_core:error] [pid 491656:tid 491833] [client 66.249.66.194:59456] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:44.609049 2026] [authz_core:error] [pid 491656:tid 491833] [client 66.249.66.194:59456] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:44.609652 2026] [authz_core:error] [pid 488669:tid 488889] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fbind%2Fsample%2Fvar%2Fnamed
[Sun Aug 30 03:04:44.610096 2026] [authz_core:error] [pid 488669:tid 488889] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fbind%2Fsample%2Fvar%2Fnamed
[Sun Aug 30 03:04:44.616983 2026] [security2:error] [pid 491656:tid 491901] [client 4.205.62.107:22959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/app_dev.php"] [unique_id "apPkHIvX_L6VjdbvkkSdcQAAAwc"]
[Sun Aug 30 03:04:44.619287 2026] [security2:error] [pid 488669:tid 488876] [client 20.220.10.235:24462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/blnux.php"] [unique_id "apPkHNRh6OewFvqQpDlo6QAAAU8"]
[Sun Aug 30 03:04:44.629771 2026] [security2:error] [pid 491656:tid 491806] [client 158.23.184.117:12451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/wp-admin/network/about.php"] [unique_id "apPkHIvX_L6VjdbvkkSdewAAAqg"]
[Sun Aug 30 03:04:44.631660 2026] [security2:error] [pid 488669:tid 488808] [client 20.48.251.3:55449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/application.config.php"] [unique_id "apPkHNRh6OewFvqQpDlo7QAAAQs"]
[Sun Aug 30 03:04:44.644557 2026] [security2:error] [pid 491656:tid 491873] [client 20.48.251.3:23447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/G-in.php"] [unique_id "apPkHIvX_L6VjdbvkkSdgAAAAus"]
[Sun Aug 30 03:04:44.649086 2026] [security2:error] [pid 491656:tid 491843] [client 4.205.62.107:4145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/config/laravolt/css/index.php"] [unique_id "apPkHIvX_L6VjdbvkkSdhAAAAs0"]
[Sun Aug 30 03:04:44.668835 2026] [authz_core:error] [pid 491656:tid 491851] [client 66.249.66.66:36452] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:44.669090 2026] [authz_core:error] [pid 491656:tid 491851] [client 66.249.66.66:36452] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:44.671756 2026] [security2:error] [pid 488669:tid 488893] [client 20.104.50.220:32925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/thr.php"] [unique_id "apPkHNRh6OewFvqQpDlpBgAAAWA"]
[Sun Aug 30 03:04:44.700454 2026] [security2:error] [pid 488669:tid 488858] [client 20.197.61.180:3934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/theme/min.php"] [unique_id "apPkHNRh6OewFvqQpDlpEgAAAT0"]
[Sun Aug 30 03:04:44.701694 2026] [authz_core:error] [pid 488669:tid 488908] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:44.702133 2026] [authz_core:error] [pid 488669:tid 488908] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:44.727750 2026] [security2:error] [pid 488669:tid 488815] [client 20.104.50.220:47047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/index4.php"] [unique_id "apPkHNRh6OewFvqQpDlpHQAAARI"]
[Sun Aug 30 03:04:44.733069 2026] [security2:error] [pid 488669:tid 488838] [client 20.48.250.41:53350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/8.php"] [unique_id "apPkHNRh6OewFvqQpDlpHwAAASk"]
[Sun Aug 30 03:04:44.737931 2026] [security2:error] [pid 488669:tid 488867] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/cd/.env"] [unique_id "apPkHNRh6OewFvqQpDlpIQAAAUY"]
[Sun Aug 30 03:04:44.738600 2026] [security2:error] [pid 491656:tid 491903] [client 34.15.145.202:57914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/phpversion.php"] [unique_id "apPkHIvX_L6VjdbvkkSdogAAAwk"]
[Sun Aug 30 03:04:44.769305 2026] [security2:error] [pid 488669:tid 488831] [client 20.196.209.81:23678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/upgrade/about.php"] [unique_id "apPkHNRh6OewFvqQpDlpKAAAASI"]
[Sun Aug 30 03:04:44.770511 2026] [security2:error] [pid 491656:tid 491836] [client 158.23.184.117:13272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/dashboard.php"] [unique_id "apPkHIvX_L6VjdbvkkSduwAAAsY"]
[Sun Aug 30 03:04:44.775413 2026] [security2:error] [pid 491656:tid 491850] [client 20.220.204.93:64940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/browse.php"] [unique_id "apPkHIvX_L6VjdbvkkSdvAAAAtQ"]
[Sun Aug 30 03:04:44.783444 2026] [security2:error] [pid 488669:tid 488878] [client 20.104.50.220:5916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-admin/js/wp-conflg.php"] [unique_id "apPkHNRh6OewFvqQpDlpLAAAAVE"]
[Sun Aug 30 03:04:44.784741 2026] [security2:error] [pid 488669:tid 488890] [client 4.205.62.107:51729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/ms.php"] [unique_id "apPkHNRh6OewFvqQpDlpLQAAAV0"]
[Sun Aug 30 03:04:44.788540 2026] [security2:error] [pid 491656:tid 491886] [client 20.220.10.235:24553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/attack.php"] [unique_id "apPkHIvX_L6VjdbvkkSdvwAAAvg"]
[Sun Aug 30 03:04:44.819593 2026] [security2:error] [pid 488669:tid 488912] [client 216.73.216.128:41722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPkHNRh6OewFvqQpDlpOQAAAXM"]
[Sun Aug 30 03:04:44.823545 2026] [security2:error] [pid 488669:tid 488918] [client 20.48.251.3:64494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/log.php"] [unique_id "apPkHNRh6OewFvqQpDlpOgAAAXk"]
[Sun Aug 30 03:04:44.837204 2026] [security2:error] [pid 491656:tid 491874] [client 4.205.62.107:2152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/chosen.php"] [unique_id "apPkHIvX_L6VjdbvkkSd0AAAAuw"]
[Sun Aug 30 03:04:44.868477 2026] [security2:error] [pid 491656:tid 491889] [client 20.220.204.93:37185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/num.php"] [unique_id "apPkHIvX_L6VjdbvkkSd5AAAAvs"]
[Sun Aug 30 03:04:44.881890 2026] [security2:error] [pid 488669:tid 488861] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/jenkins/.env"] [unique_id "apPkHNRh6OewFvqQpDlpTwAAAUA"]
[Sun Aug 30 03:04:44.897416 2026] [security2:error] [pid 491656:tid 491892] [client 20.48.250.41:53331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/0x0x.php"] [unique_id "apPkHIvX_L6VjdbvkkSd7wAAAv4"]
[Sun Aug 30 03:04:44.926300 2026] [security2:error] [pid 491656:tid 491874] [client 20.220.10.235:24529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/wk/index.php"] [unique_id "apPkHIvX_L6VjdbvkkSd9AAAAuw"]
[Sun Aug 30 03:04:44.928892 2026] [security2:error] [pid 488669:tid 488864] [client 4.205.62.107:36639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/gjm.php"] [unique_id "apPkHNRh6OewFvqQpDlpXgAAAUM"]
[Sun Aug 30 03:04:44.938926 2026] [security2:error] [pid 488669:tid 488838] [client 158.23.184.117:13263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/wp-content/plugins/sid/sidwso.php"] [unique_id "apPkHNRh6OewFvqQpDlpYgAAASk"]
[Sun Aug 30 03:04:44.943641 2026] [security2:error] [pid 491656:tid 491839] [client 20.48.251.3:44387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/guk.php"] [unique_id "apPkHIvX_L6VjdbvkkSd-QAAAsk"]
[Sun Aug 30 03:04:44.990568 2026] [security2:error] [pid 491656:tid 491906] [client 20.104.50.220:62795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/Xploit.php"] [unique_id "apPkHIvX_L6VjdbvkkSeDAAAAww"]
[Sun Aug 30 03:04:44.994762 2026] [security2:error] [pid 491656:tid 491887] [client 20.196.209.81:13896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/theme/about.php"] [unique_id "apPkHIvX_L6VjdbvkkSeDwAAAvk"]
[Sun Aug 30 03:04:45.001313 2026] [security2:error] [pid 488669:tid 488866] [client 216.73.216.128:63883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPkHdRh6OewFvqQpDlpdwAAAUU"]
[Sun Aug 30 03:04:45.001732 2026] [security2:error] [pid 491656:tid 491829] [client 20.104.50.220:32097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/codeboy1877x.php"] [unique_id "apPkHYvX_L6VjdbvkkSeEwAAAr8"]
[Sun Aug 30 03:04:45.026323 2026] [security2:error] [pid 488669:tid 488892] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/gitlab/.env"] [unique_id "apPkHdRh6OewFvqQpDlpeQAAAV8"]
[Sun Aug 30 03:04:45.031928 2026] [security2:error] [pid 488669:tid 488809] [client 20.220.204.93:65004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/zoo.php"] [unique_id "apPkHdRh6OewFvqQpDlpewAAAQw"]
[Sun Aug 30 03:04:45.032011 2026] [security2:error] [pid 488669:tid 488817] [client 4.205.62.107:18762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/ty.php"] [unique_id "apPkHdRh6OewFvqQpDlpfAAAARQ"]
[Sun Aug 30 03:04:45.044408 2026] [security2:error] [pid 491656:tid 491830] [client 20.104.49.130:58184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.katbacon.com"] [uri "/ws58.php"] [unique_id "apPkHYvX_L6VjdbvkkSeIgAAAsA"]
[Sun Aug 30 03:04:45.052420 2026] [security2:error] [pid 491656:tid 491912] [client 20.151.200.44:37778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/tajj.php"] [unique_id "apPkHYvX_L6VjdbvkkSeJwAAAxI"]
[Sun Aug 30 03:04:45.061860 2026] [security2:error] [pid 491656:tid 491916] [client 4.205.62.107:65379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/333.php"] [unique_id "apPkHYvX_L6VjdbvkkSeLQAAAxY"]
[Sun Aug 30 03:04:45.069912 2026] [security2:error] [pid 491656:tid 491889] [client 20.220.10.235:24496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/dehnl.php"] [unique_id "apPkHYvX_L6VjdbvkkSeMgAAAvs"]
[Sun Aug 30 03:04:45.074535 2026] [authz_core:error] [pid 491656:tid 491820] [client 66.249.66.44:54845] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:45.074832 2026] [authz_core:error] [pid 491656:tid 491820] [client 66.249.66.44:54845] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:45.076203 2026] [security2:error] [pid 491656:tid 491906] [client 68.155.159.216:60030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/radio.php"] [unique_id "apPkHYvX_L6VjdbvkkSeNAAAAww"]
[Sun Aug 30 03:04:45.105747 2026] [authz_core:error] [pid 488669:tid 488831] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fbind%2Fsample%2Fvar%2Fnamed
[Sun Aug 30 03:04:45.106217 2026] [authz_core:error] [pid 488669:tid 488831] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fbind%2Fsample%2Fvar%2Fnamed
[Sun Aug 30 03:04:45.115502 2026] [security2:error] [pid 491656:tid 491841] [client 20.104.50.220:61651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/xm.php"] [unique_id "apPkHYvX_L6VjdbvkkSePQAAAss"]
[Sun Aug 30 03:04:45.118190 2026] [security2:error] [pid 488669:tid 488825] [client 4.205.62.107:62123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/mga.php"] [unique_id "apPkHdRh6OewFvqQpDlpnAAAARw"]
[Sun Aug 30 03:04:45.121806 2026] [security2:error] [pid 491656:tid 491808] [client 20.48.250.41:53375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/166.php"] [unique_id "apPkHYvX_L6VjdbvkkSeQgAAAqo"]
[Sun Aug 30 03:04:45.132086 2026] [security2:error] [pid 488669:tid 488875] [client 158.23.184.117:12422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/admin/index.php"] [unique_id "apPkHdRh6OewFvqQpDlpowAAAU4"]
[Sun Aug 30 03:04:45.146497 2026] [security2:error] [pid 488669:tid 488895] [client 20.48.251.3:51476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/cloud.php"] [unique_id "apPkHdRh6OewFvqQpDlppwAAAWI"]
[Sun Aug 30 03:04:45.161028 2026] [security2:error] [pid 488669:tid 488832] [client 20.196.209.81:6118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hoslercorp.net"] [uri "/wp-content/upgrade/index.php"] [unique_id "apPkHdRh6OewFvqQpDlprQAAASM"]
[Sun Aug 30 03:04:45.171762 2026] [security2:error] [pid 491656:tid 491906] [client 20.220.204.93:64995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/elp.php"] [unique_id "apPkHYvX_L6VjdbvkkSeXQAAAww"]
[Sun Aug 30 03:04:45.171781 2026] [security2:error] [pid 488669:tid 488866] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/github/.env"] [unique_id "apPkHdRh6OewFvqQpDlpsAAAAUU"]
[Sun Aug 30 03:04:45.189557 2026] [security2:error] [pid 491656:tid 491897] [client 4.205.62.107:32490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/chosen.php"] [unique_id "apPkHYvX_L6VjdbvkkSeawAAAwM"]
[Sun Aug 30 03:04:45.200843 2026] [security2:error] [pid 488669:tid 488845] [client 20.220.10.235:24536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/png.php"] [unique_id "apPkHdRh6OewFvqQpDlpuwAAATA"]
[Sun Aug 30 03:04:45.232171 2026] [authz_core:error] [pid 488669:tid 488887] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:45.232488 2026] [authz_core:error] [pid 488669:tid 488887] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:45.235911 2026] [security2:error] [pid 491656:tid 491899] [client 20.104.18.15:31634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/wp-aothait.php"] [unique_id "apPkHYvX_L6VjdbvkkSefwAAAwU"]
[Sun Aug 30 03:04:45.317166 2026] [security2:error] [pid 488669:tid 488815] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/actions/.env"] [unique_id "apPkHdRh6OewFvqQpDlp6AAAARI"]
[Sun Aug 30 03:04:45.323766 2026] [security2:error] [pid 491656:tid 491850] [client 158.23.184.117:13106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/wp-includes/blocks/block/index.php"] [unique_id "apPkHYvX_L6VjdbvkkSepAAAAtQ"]
[Sun Aug 30 03:04:45.324816 2026] [security2:error] [pid 491656:tid 491881] [client 20.48.250.41:53253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/h2a2ck.php"] [unique_id "apPkHYvX_L6VjdbvkkSepgAAAvM"]
[Sun Aug 30 03:04:45.328502 2026] [security2:error] [pid 488669:tid 488878] [client 20.220.10.235:24513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/txets.php"] [unique_id "apPkHdRh6OewFvqQpDlp7AAAAVE"]
[Sun Aug 30 03:04:45.332808 2026] [security2:error] [pid 488669:tid 488881] [client 158.23.147.79:63285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-admin/about.php"] [unique_id "apPkHdRh6OewFvqQpDlp7QAAAVQ"]
[Sun Aug 30 03:04:45.338241 2026] [security2:error] [pid 491656:tid 491806] [client 34.15.145.202:57918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/_phpinfo.php"] [unique_id "apPkHYvX_L6VjdbvkkSeqQAAAqg"]
[Sun Aug 30 03:04:45.347056 2026] [security2:error] [pid 491656:tid 491808] [client 20.104.18.15:9173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/dapa.php"] [unique_id "apPkHYvX_L6VjdbvkkSerAAAAqo"]
[Sun Aug 30 03:04:45.359776 2026] [security2:error] [pid 488669:tid 488925] [client 20.220.204.93:65006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/666.php"] [unique_id "apPkHdRh6OewFvqQpDlp9gAAAYA"]
[Sun Aug 30 03:04:45.363743 2026] [security2:error] [pid 491656:tid 491812] [client 20.48.251.3:64317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/apikeys.php"] [unique_id "apPkHYvX_L6VjdbvkkSetAAAAq4"]
[Sun Aug 30 03:04:45.366734 2026] [security2:error] [pid 491656:tid 491809] [client 216.73.216.128:51719] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPkHYvX_L6VjdbvkkSetQAAAqs"]
[Sun Aug 30 03:04:45.379642 2026] [security2:error] [pid 491656:tid 491793] [client 4.205.62.107:25747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/124.php"] [unique_id "apPkHYvX_L6VjdbvkkSewAAAAps"]
[Sun Aug 30 03:04:45.390095 2026] [security2:error] [pid 488669:tid 488912] [client 20.196.209.81:14938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/theme/min.php"] [unique_id "apPkHdRh6OewFvqQpDlp_gAAAXM"]
[Sun Aug 30 03:04:45.391413 2026] [security2:error] [pid 488669:tid 488819] [client 20.197.61.180:9195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/themes/about.php"] [unique_id "apPkHdRh6OewFvqQpDlqAAAAARY"]
[Sun Aug 30 03:04:45.435514 2026] [security2:error] [pid 488669:tid 488831] [client 20.104.50.220:42013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/vuln.php"] [unique_id "apPkHdRh6OewFvqQpDlqCgAAASI"]
[Sun Aug 30 03:04:45.436258 2026] [authz_core:error] [pid 491656:tid 491875] [client 66.249.66.68:44895] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:45.436601 2026] [authz_core:error] [pid 491656:tid 491875] [client 66.249.66.68:44895] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:45.461592 2026] [security2:error] [pid 488669:tid 488896] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/circleci/.env"] [unique_id "apPkHdRh6OewFvqQpDlqEQAAAWM"]
[Sun Aug 30 03:04:45.469299 2026] [security2:error] [pid 488669:tid 488846] [client 20.220.10.235:24449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/wp-login.php"] [unique_id "apPkHdRh6OewFvqQpDlqDwAAATE"]
[Sun Aug 30 03:04:45.480244 2026] [security2:error] [pid 488669:tid 488835] [client 158.23.184.117:13259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gilkeyart.com"] [uri "/bolt.php"] [unique_id "apPkHdRh6OewFvqQpDlqFQAAASY"]
[Sun Aug 30 03:04:45.484754 2026] [security2:error] [pid 491656:tid 491812] [client 20.48.250.41:53184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/error_log.php"] [unique_id "apPkHYvX_L6VjdbvkkSe4QAAAq4"]
[Sun Aug 30 03:04:45.498513 2026] [security2:error] [pid 491656:tid 491854] [client 20.151.200.44:58833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/xda.php"] [unique_id "apPkHYvX_L6VjdbvkkSe5wAAAtg"]
[Sun Aug 30 03:04:45.565218 2026] [security2:error] [pid 491656:tid 491894] [client 20.48.251.3:64417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/fff.php"] [unique_id "apPkHYvX_L6VjdbvkkSe-QAAAwA"]
[Sun Aug 30 03:04:45.587197 2026] [authz_core:error] [pid 488669:tid 488903] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fbind%2Fsample%2Fvar%2Fnamed
[Sun Aug 30 03:04:45.587744 2026] [authz_core:error] [pid 488669:tid 488903] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fbind%2Fsample%2Fvar%2Fnamed
[Sun Aug 30 03:04:45.588686 2026] [security2:error] [pid 491656:tid 491857] [client 4.205.62.107:31717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/admin-ajax.php"] [unique_id "apPkHYvX_L6VjdbvkkSfAAAAAts"]
[Sun Aug 30 03:04:45.602104 2026] [security2:error] [pid 491656:tid 491812] [client 20.220.10.235:24520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/wp-access.php"] [unique_id "apPkHYvX_L6VjdbvkkSfBAAAAq4"]
[Sun Aug 30 03:04:45.607136 2026] [security2:error] [pid 488669:tid 488907] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/travis/.env"] [unique_id "apPkHdRh6OewFvqQpDlqKwAAAW4"]
[Sun Aug 30 03:04:45.612189 2026] [security2:error] [pid 491656:tid 491854] [client 4.205.62.107:44922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/configuration.php"] [unique_id "apPkHYvX_L6VjdbvkkSfDAAAAtg"]
[Sun Aug 30 03:04:45.658022 2026] [security2:error] [pid 488669:tid 488842] [client 20.48.250.41:53310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/403.php"] [unique_id "apPkHdRh6OewFvqQpDlqPwAAAS0"]
[Sun Aug 30 03:04:45.661576 2026] [security2:error] [pid 488669:tid 488880] [client 68.155.159.216:52765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/.well-known/content.php"] [unique_id "apPkHdRh6OewFvqQpDlqQwAAAVM"]
[Sun Aug 30 03:04:45.665351 2026] [security2:error] [pid 491656:tid 491840] [client 20.48.251.3:52804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/zaza.php"] [unique_id "apPkHYvX_L6VjdbvkkSfLwAAAso"]
[Sun Aug 30 03:04:45.687339 2026] [security2:error] [pid 491656:tid 491856] [client 68.155.159.216:52695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apPkHYvX_L6VjdbvkkSfOQAAAto"]
[Sun Aug 30 03:04:45.687797 2026] [security2:error] [pid 488669:tid 488893] [client 20.104.18.15:32983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/bulet.php"] [unique_id "apPkHdRh6OewFvqQpDlqSQAAAWA"]
[Sun Aug 30 03:04:45.693633 2026] [security2:error] [pid 488669:tid 488887] [client 20.104.50.220:29180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/.012263646060568.php"] [unique_id "apPkHdRh6OewFvqQpDlqTQAAAVo"]
[Sun Aug 30 03:04:45.702674 2026] [authz_core:error] [pid 488669:tid 488835] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:45.703156 2026] [authz_core:error] [pid 488669:tid 488835] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:45.717797 2026] [security2:error] [pid 491656:tid 491808] [client 4.205.62.107:63800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/grsiuk.php"] [unique_id "apPkHYvX_L6VjdbvkkSfQwAAAqo"]
[Sun Aug 30 03:04:45.730304 2026] [security2:error] [pid 488669:tid 488895] [client 20.220.204.93:63808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/knmt.php"] [unique_id "apPkHdRh6OewFvqQpDlqWAAAAWI"]
[Sun Aug 30 03:04:45.733247 2026] [security2:error] [pid 488669:tid 488904] [client 20.220.10.235:24463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/wp-content/admin.php"] [unique_id "apPkHdRh6OewFvqQpDlqWQAAAWs"]
[Sun Aug 30 03:04:45.743311 2026] [security2:error] [pid 488669:tid 488830] [client 40.83.93.50:8602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/aaa.php"] [unique_id "apPkHdRh6OewFvqQpDlqXAAAASE"]
[Sun Aug 30 03:04:45.752495 2026] [security2:error] [pid 488669:tid 488878] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/buildkite/.env"] [unique_id "apPkHdRh6OewFvqQpDlqYQAAAVE"]
[Sun Aug 30 03:04:45.753661 2026] [security2:error] [pid 488669:tid 488925] [client 4.205.62.107:22952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/php-info.php"] [unique_id "apPkHdRh6OewFvqQpDlqYgAAAYA"]
[Sun Aug 30 03:04:45.760800 2026] [security2:error] [pid 491656:tid 491904] [client 4.205.62.107:26496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/otuz1.php"] [unique_id "apPkHYvX_L6VjdbvkkSfYwAAAwo"]
[Sun Aug 30 03:04:45.763483 2026] [security2:error] [pid 491656:tid 491806] [client 20.220.204.93:51561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/a4.php"] [unique_id "apPkHYvX_L6VjdbvkkSfaQAAAqg"]
[Sun Aug 30 03:04:45.763575 2026] [security2:error] [pid 491656:tid 491891] [client 20.104.49.130:43777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/gecko-new.php"] [unique_id "apPkHYvX_L6VjdbvkkSfagAAAv0"]
[Sun Aug 30 03:04:45.782801 2026] [security2:error] [pid 491656:tid 491862] [client 20.48.251.3:23429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/apikeys.php"] [unique_id "apPkHYvX_L6VjdbvkkSfdQAAAuA"]
[Sun Aug 30 03:04:45.785626 2026] [security2:error] [pid 491656:tid 491851] [client 4.205.62.107:5063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/87.php"] [unique_id "apPkHYvX_L6VjdbvkkSfdwAAAtU"]
[Sun Aug 30 03:04:45.787042 2026] [security2:error] [pid 491656:tid 491792] [client 20.196.209.81:7972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/themes/about.php"] [unique_id "apPkHYvX_L6VjdbvkkSfeAAAApo"]
[Sun Aug 30 03:04:45.821996 2026] [security2:error] [pid 491656:tid 491906] [client 20.104.50.220:33179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/tmv.php"] [unique_id "apPkHYvX_L6VjdbvkkSfiAAAAww"]
[Sun Aug 30 03:04:45.822987 2026] [security2:error] [pid 491656:tid 491815] [client 20.48.251.3:55529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/xp.php"] [unique_id "apPkHYvX_L6VjdbvkkSfiQAAArE"]
[Sun Aug 30 03:04:45.857742 2026] [security2:error] [pid 491656:tid 491870] [client 20.220.204.93:63830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/sbhu.php"] [unique_id "apPkHYvX_L6VjdbvkkSfngAAAug"]
[Sun Aug 30 03:04:45.858242 2026] [security2:error] [pid 488669:tid 488843] [client 20.48.250.41:53186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/cytyr.php"] [unique_id "apPkHdRh6OewFvqQpDlqhgAAAS4"]
[Sun Aug 30 03:04:45.866110 2026] [security2:error] [pid 491656:tid 491867] [client 20.104.50.220:46604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/index5.php"] [unique_id "apPkHYvX_L6VjdbvkkSfpAAAAuU"]
[Sun Aug 30 03:04:45.882736 2026] [security2:error] [pid 488669:tid 488883] [client 20.220.10.235:24454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/log.php"] [unique_id "apPkHdRh6OewFvqQpDlqkAAAAVY"]
[Sun Aug 30 03:04:45.898778 2026] [security2:error] [pid 488669:tid 488850] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/mysql/.env"] [unique_id "apPkHdRh6OewFvqQpDlqlQAAATU"]
[Sun Aug 30 03:04:45.909773 2026] [security2:error] [pid 491656:tid 491850] [client 40.83.93.50:8596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/atomlib.php"] [unique_id "apPkHYvX_L6VjdbvkkSfrgAAAtQ"]
[Sun Aug 30 03:04:45.944006 2026] [security2:error] [pid 491656:tid 491823] [client 34.15.145.202:57928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/old_phpinfo.php"] [unique_id "apPkHYvX_L6VjdbvkkSfvAAAArk"]
[Sun Aug 30 03:04:45.950380 2026] [security2:error] [pid 488669:tid 488931] [client 4.205.62.107:52132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/fucku.php"] [unique_id "apPkHdRh6OewFvqQpDlqqQAAAYY"]
[Sun Aug 30 03:04:45.950979 2026] [security2:error] [pid 491656:tid 491840] [client 20.104.50.220:5944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-admin/wp-conflg.php"] [unique_id "apPkHYvX_L6VjdbvkkSfvgAAAso"]
[Sun Aug 30 03:04:46.011844 2026] [security2:error] [pid 491656:tid 491880] [client 20.220.10.235:24473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/xwpg.php"] [unique_id "apPkHovX_L6VjdbvkkSf2AAAAvI"]
[Sun Aug 30 03:04:46.028035 2026] [security2:error] [pid 491656:tid 491810] [client 20.48.250.41:53357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/galer.php"] [unique_id "apPkHovX_L6VjdbvkkSf3wAAAqw"]
[Sun Aug 30 03:04:46.037084 2026] [security2:error] [pid 488669:tid 488929] [client 20.220.204.93:63841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/a332.php"] [unique_id "apPkHtRh6OewFvqQpDlqzgAAAYQ"]
[Sun Aug 30 03:04:46.043386 2026] [authz_core:error] [pid 488669:tid 488876] [client 66.249.66.43:44519] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:46.043777 2026] [authz_core:error] [pid 488669:tid 488876] [client 66.249.66.43:44519] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:46.046790 2026] [security2:error] [pid 488669:tid 488858] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/postgres/.env"] [unique_id "apPkHtRh6OewFvqQpDlq0gAAAT0"]
[Sun Aug 30 03:04:46.082242 2026] [security2:error] [pid 491656:tid 491822] [client 20.48.251.3:44386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/config_dev.php"] [unique_id "apPkHovX_L6VjdbvkkSf8wAAArg"]
[Sun Aug 30 03:04:46.091875 2026] [authz_core:error] [pid 488669:tid 488828] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:46.092369 2026] [authz_core:error] [pid 488669:tid 488828] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:46.116584 2026] [security2:error] [pid 491656:tid 491841] [client 20.197.61.180:4038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/themes/panel.php"] [unique_id "apPkHovX_L6VjdbvkkSgBAAAAss"]
[Sun Aug 30 03:04:46.142793 2026] [security2:error] [pid 488669:tid 488899] [client 20.220.10.235:24561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/sxxb.php"] [unique_id "apPkHtRh6OewFvqQpDlrAAAAAWY"]
[Sun Aug 30 03:04:46.151182 2026] [security2:error] [pid 491656:tid 491848] [client 20.104.50.220:28699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wso2.5.1.php"] [unique_id "apPkHovX_L6VjdbvkkSgIAAAAtI"]
[Sun Aug 30 03:04:46.162413 2026] [security2:error] [pid 491656:tid 491884] [client 20.48.250.41:53265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/baixy.php"] [unique_id "apPkHovX_L6VjdbvkkSgJwAAAvY"]
[Sun Aug 30 03:04:46.177603 2026] [security2:error] [pid 488669:tid 488851] [client 20.196.209.81:7585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/themes/panel.php"] [unique_id "apPkHtRh6OewFvqQpDlrEAAAATY"]
[Sun Aug 30 03:04:46.179247 2026] [security2:error] [pid 491656:tid 491802] [client 20.104.50.220:32262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wsanon.php"] [unique_id "apPkHovX_L6VjdbvkkSgLgAAAqQ"]
[Sun Aug 30 03:04:46.187726 2026] [security2:error] [pid 491656:tid 491861] [client 20.220.204.93:63822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/ws66.php"] [unique_id "apPkHovX_L6VjdbvkkSgMwAAAt8"]
[Sun Aug 30 03:04:46.191871 2026] [security2:error] [pid 488669:tid 488863] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/mongodb/.env"] [unique_id "apPkHtRh6OewFvqQpDlrFgAAAUI"]
[Sun Aug 30 03:04:46.225614 2026] [authz_core:error] [pid 488669:tid 488853] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:46.225892 2026] [authz_core:error] [pid 488669:tid 488853] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:46.243242 2026] [security2:error] [pid 491656:tid 491826] [client 68.155.159.216:59941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPkHovX_L6VjdbvkkSgTAAAArw"]
[Sun Aug 30 03:04:46.266290 2026] [security2:error] [pid 491656:tid 491811] [client 20.104.50.220:61974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/xamp.php"] [unique_id "apPkHovX_L6VjdbvkkSgXQAAAq0"]
[Sun Aug 30 03:04:46.271136 2026] [security2:error] [pid 491656:tid 491847] [client 20.220.10.235:24569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/dx.php"] [unique_id "apPkHovX_L6VjdbvkkSgYAAAAtE"]
[Sun Aug 30 03:04:46.275396 2026] [security2:error] [pid 491656:tid 491893] [client 20.48.251.3:58879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/asdf.php"] [unique_id "apPkHovX_L6VjdbvkkSgZAAAAv8"]
[Sun Aug 30 03:04:46.353297 2026] [security2:error] [pid 488669:tid 488849] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/redis/.env"] [unique_id "apPkHtRh6OewFvqQpDlrWQAAATQ"]
[Sun Aug 30 03:04:46.369290 2026] [security2:error] [pid 491656:tid 491796] [client 216.73.216.128:45228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPkHovX_L6VjdbvkkSghQAAAp4"]
[Sun Aug 30 03:04:46.379964 2026] [security2:error] [pid 488669:tid 488835] [client 20.220.204.93:65012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/ws68.php"] [unique_id "apPkHtRh6OewFvqQpDlrZAAAASY"]
[Sun Aug 30 03:04:46.382992 2026] [security2:error] [pid 488669:tid 488826] [client 20.48.250.41:53285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/ava.php"] [unique_id "apPkHtRh6OewFvqQpDlraQAAAR0"]
[Sun Aug 30 03:04:46.399754 2026] [security2:error] [pid 488669:tid 488926] [client 20.220.10.235:24481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPkHtRh6OewFvqQpDlrdQAAAYE"]
[Sun Aug 30 03:04:46.408461 2026] [authz_core:error] [pid 491656:tid 491892] [client 66.249.66.74:62629] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:46.408927 2026] [authz_core:error] [pid 491656:tid 491892] [client 66.249.66.74:62629] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:46.411994 2026] [security2:error] [pid 488669:tid 488899] [client 40.83.93.50:8590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/buy.php"] [unique_id "apPkHtRh6OewFvqQpDlrfgAAAWY"]
[Sun Aug 30 03:04:46.463380 2026] [security2:error] [pid 488669:tid 488912] [client 20.104.18.15:31602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/wp-includes/index.php"] [unique_id "apPkHtRh6OewFvqQpDlrkgAAAXM"]
[Sun Aug 30 03:04:46.478013 2026] [security2:error] [pid 491656:tid 491881] [client 20.151.200.44:58941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPkHovX_L6VjdbvkkSgoQAAAvM"]
[Sun Aug 30 03:04:46.498493 2026] [security2:error] [pid 488669:tid 488904] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/elasticsearch/.env"] [unique_id "apPkHtRh6OewFvqQpDlrnAAAAWs"]
[Sun Aug 30 03:04:46.511473 2026] [security2:error] [pid 491656:tid 491914] [client 20.48.251.3:46215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/motu.php"] [unique_id "apPkHovX_L6VjdbvkkSgqQAAAxQ"]
[Sun Aug 30 03:04:46.527496 2026] [security2:error] [pid 488669:tid 488817] [client 20.48.250.41:53191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/gdn.php"] [unique_id "apPkHtRh6OewFvqQpDlrogAAARQ"]
[Sun Aug 30 03:04:46.527814 2026] [security2:error] [pid 491656:tid 491802] [client 20.220.204.93:63815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/users.php"] [unique_id "apPkHovX_L6VjdbvkkSgsgAAAqQ"]
[Sun Aug 30 03:04:46.527814 2026] [security2:error] [pid 491656:tid 491864] [client 20.104.18.15:9157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/wp-content/l.php"] [unique_id "apPkHovX_L6VjdbvkkSgsAAAAuI"]
[Sun Aug 30 03:04:46.529292 2026] [security2:error] [pid 491656:tid 491797] [client 20.220.10.235:24570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/xda.php"] [unique_id "apPkHovX_L6VjdbvkkSgtAAAAp8"]
[Sun Aug 30 03:04:46.537931 2026] [authz_core:error] [pid 491656:tid 491836] [client 66.249.66.206:37732] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:46.538282 2026] [authz_core:error] [pid 491656:tid 491836] [client 66.249.66.206:37732] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:46.547265 2026] [security2:error] [pid 491656:tid 491880] [client 34.15.145.202:57942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/server-info.php"] [unique_id "apPkHovX_L6VjdbvkkSgtQAAAvI"]
[Sun Aug 30 03:04:46.572190 2026] [authz_core:error] [pid 488669:tid 488843] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:46.572683 2026] [authz_core:error] [pid 488669:tid 488843] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:46.577483 2026] [security2:error] [pid 491656:tid 491843] [client 20.104.50.220:41991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/V5.php"] [unique_id "apPkHovX_L6VjdbvkkSgxgAAAs0"]
[Sun Aug 30 03:04:46.642268 2026] [security2:error] [pid 488669:tid 488863] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/rabbitmq/.env"] [unique_id "apPkHtRh6OewFvqQpDlr0gAAAUI"]
[Sun Aug 30 03:04:46.651633 2026] [security2:error] [pid 491656:tid 491801] [client 158.23.147.79:63234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apPkHovX_L6VjdbvkkSg8QAAAqM"]
[Sun Aug 30 03:04:46.655828 2026] [security2:error] [pid 491656:tid 491875] [client 20.220.204.93:20832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/tfm.php"] [unique_id "apPkHovX_L6VjdbvkkSg8wAAAu0"]
[Sun Aug 30 03:04:46.661377 2026] [security2:error] [pid 491656:tid 491899] [client 20.220.10.235:24533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPkHovX_L6VjdbvkkSg-gAAAwU"]
[Sun Aug 30 03:04:46.669053 2026] [security2:error] [pid 491656:tid 491792] [client 20.220.204.93:63853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/bzjdlofz.php"] [unique_id "apPkHovX_L6VjdbvkkShAQAAApo"]
[Sun Aug 30 03:04:46.669700 2026] [security2:error] [pid 491656:tid 491814] [client 20.48.251.3:6498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/ebahvhhh.php"] [unique_id "apPkHovX_L6VjdbvkkShAgAAArA"]
[Sun Aug 30 03:04:46.696897 2026] [authz_core:error] [pid 488669:tid 488895] [client 66.249.66.64:61955] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:46.697199 2026] [authz_core:error] [pid 488669:tid 488895] [client 66.249.66.64:61955] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:46.737095 2026] [authz_core:error] [pid 488669:tid 488910] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:46.737354 2026] [authz_core:error] [pid 488669:tid 488910] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:46.742658 2026] [security2:error] [pid 488669:tid 488835] [client 20.48.251.3:7078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/autogooey.php"] [unique_id "apPkHtRh6OewFvqQpDlr-QAAASY"]
[Sun Aug 30 03:04:46.742822 2026] [security2:error] [pid 488669:tid 488861] [client 20.48.250.41:53307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/f2.php"] [unique_id "apPkHtRh6OewFvqQpDlr-AAAAUA"]
[Sun Aug 30 03:04:46.747037 2026] [security2:error] [pid 491656:tid 491917] [client 20.196.209.81:7953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/twentytwentyfive/styles/sections/pk.php"] [unique_id "apPkHovX_L6VjdbvkkShIgAAAxc"]
[Sun Aug 30 03:04:46.782198 2026] [security2:error] [pid 491656:tid 491801] [client 20.104.49.130:34545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/82.php"] [unique_id "apPkHovX_L6VjdbvkkShNAAAAqM"]
[Sun Aug 30 03:04:46.790463 2026] [security2:error] [pid 491656:tid 491886] [client 20.220.10.235:24548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/t00l.php"] [unique_id "apPkHovX_L6VjdbvkkShNwAAAvg"]
[Sun Aug 30 03:04:46.792032 2026] [security2:error] [pid 488669:tid 488886] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/kafka/.env"] [unique_id "apPkHtRh6OewFvqQpDlsHAAAAVk"]
[Sun Aug 30 03:04:46.802709 2026] [security2:error] [pid 491656:tid 491793] [client 20.220.204.93:64322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/selesai.php"] [unique_id "apPkHovX_L6VjdbvkkShPAAAAps"]
[Sun Aug 30 03:04:46.803293 2026] [security2:error] [pid 488669:tid 488828] [client 20.48.251.3:55791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/u88.php"] [unique_id "apPkHtRh6OewFvqQpDlsIgAAAR8"]
[Sun Aug 30 03:04:46.860364 2026] [security2:error] [pid 488669:tid 488890] [client 20.104.50.220:52852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/jmbt.php"] [unique_id "apPkHtRh6OewFvqQpDlsOwAAAV0"]
[Sun Aug 30 03:04:46.861416 2026] [authz_core:error] [pid 491656:tid 491835] [client 66.249.66.193:42160] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:46.861563 2026] [security2:error] [pid 491656:tid 491843] [client 68.155.159.216:59335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/cong.php"] [unique_id "apPkHovX_L6VjdbvkkShYAAAAs0"]
[Sun Aug 30 03:04:46.861793 2026] [authz_core:error] [pid 491656:tid 491835] [client 66.249.66.193:42160] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:46.866614 2026] [security2:error] [pid 491656:tid 491793] [client 20.104.18.15:33728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/av.php"] [unique_id "apPkHovX_L6VjdbvkkShZgAAAps"]
[Sun Aug 30 03:04:46.921244 2026] [security2:error] [pid 491656:tid 491915] [client 40.83.93.50:8370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/hello.php"] [unique_id "apPkHovX_L6VjdbvkkShgAAAAxU"]
[Sun Aug 30 03:04:46.921955 2026] [security2:error] [pid 491656:tid 491856] [client 20.48.251.3:44228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/motu.php"] [unique_id "apPkHovX_L6VjdbvkkShgQAAAto"]
[Sun Aug 30 03:04:46.927885 2026] [security2:error] [pid 488669:tid 488882] [client 20.220.10.235:24465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/ls.php"] [unique_id "apPkHtRh6OewFvqQpDlsRwAAAVU"]
[Sun Aug 30 03:04:46.936080 2026] [security2:error] [pid 491656:tid 491842] [client 20.48.250.41:53288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/grsiuk.php"] [unique_id "apPkHovX_L6VjdbvkkShhwAAAsw"]
[Sun Aug 30 03:04:46.936372 2026] [security2:error] [pid 491656:tid 491902] [client 20.220.204.93:64277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/shlo.php"] [unique_id "apPkHovX_L6VjdbvkkShiAAAAwg"]
[Sun Aug 30 03:04:46.937492 2026] [security2:error] [pid 488669:tid 488865] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/queue/.env"] [unique_id "apPkHtRh6OewFvqQpDlsSwAAAUQ"]
[Sun Aug 30 03:04:46.960179 2026] [security2:error] [pid 488669:tid 488894] [client 20.104.50.220:33313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/terminal.php"] [unique_id "apPkHtRh6OewFvqQpDlsVgAAAWE"]
[Sun Aug 30 03:04:47.001968 2026] [security2:error] [pid 491656:tid 491828] [client 20.104.50.220:46653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/index6.php"] [unique_id "apPkH4vX_L6VjdbvkkShowAAAr4"]
[Sun Aug 30 03:04:47.008852 2026] [security2:error] [pid 491656:tid 491902] [client 216.73.216.128:13201] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPkH4vX_L6VjdbvkkShpAAAAwg"]
[Sun Aug 30 03:04:47.027074 2026] [security2:error] [pid 491656:tid 491886] [client 20.151.200.44:37698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/bge.php"] [unique_id "apPkH4vX_L6VjdbvkkShtAAAAvg"]
[Sun Aug 30 03:04:47.061967 2026] [security2:error] [pid 488669:tid 488877] [client 20.48.251.3:50025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/g3.php"] [unique_id "apPkH9Rh6OewFvqQpDlsfQAAAVA"]
[Sun Aug 30 03:04:47.069395 2026] [security2:error] [pid 491656:tid 491827] [client 20.48.250.41:53256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/wp-scr1pts.php"] [unique_id "apPkH4vX_L6VjdbvkkShxQAAAr0"]
[Sun Aug 30 03:04:47.069497 2026] [security2:error] [pid 491656:tid 491880] [client 20.220.10.235:24551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/css/000.php"] [unique_id "apPkH4vX_L6VjdbvkkShxAAAAvI"]
[Sun Aug 30 03:04:47.081163 2026] [authz_core:error] [pid 488669:tid 488828] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:47.081445 2026] [authz_core:error] [pid 488669:tid 488828] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:47.082614 2026] [security2:error] [pid 488669:tid 488894] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/worker/.env"] [unique_id "apPkH9Rh6OewFvqQpDlsgQAAAWE"]
[Sun Aug 30 03:04:47.085532 2026] [security2:error] [pid 491656:tid 491884] [client 20.220.204.93:64968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/asax.php"] [unique_id "apPkH4vX_L6VjdbvkkShygAAAvY"]
[Sun Aug 30 03:04:47.091796 2026] [security2:error] [pid 488669:tid 488815] [client 68.155.159.216:52625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-content/admin.php"] [unique_id "apPkH9Rh6OewFvqQpDlshAAAARI"]
[Sun Aug 30 03:04:47.094976 2026] [security2:error] [pid 491656:tid 491869] [client 20.197.61.180:9152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/twentytwentyfive/styles/sections/pk.php"] [unique_id "apPkH4vX_L6VjdbvkkShzAAAAuc"]
[Sun Aug 30 03:04:47.124451 2026] [security2:error] [pid 488669:tid 488848] [client 20.104.50.220:6103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-admin/css/wp-conflg.php"] [unique_id "apPkH9Rh6OewFvqQpDlslQAAATM"]
[Sun Aug 30 03:04:47.158286 2026] [security2:error] [pid 491656:tid 491901] [client 34.15.145.202:57954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/server-status.php"] [unique_id "apPkH4vX_L6VjdbvkkSh7QAAAwc"]
[Sun Aug 30 03:04:47.190691 2026] [security2:error] [pid 488669:tid 488818] [client 216.73.216.128:6735] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPkH9Rh6OewFvqQpDlswQAAARU"]
[Sun Aug 30 03:04:47.199092 2026] [security2:error] [pid 491656:tid 491855] [client 20.220.10.235:24457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/cy.php"] [unique_id "apPkH4vX_L6VjdbvkkSh_QAAAtk"]
[Sun Aug 30 03:04:47.219447 2026] [security2:error] [pid 488669:tid 488920] [client 20.48.251.3:44374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/aws_credentials.php"] [unique_id "apPkH9Rh6OewFvqQpDls1wAAAXs"]
[Sun Aug 30 03:04:47.222620 2026] [authz_core:error] [pid 488669:tid 488820] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:47.223115 2026] [authz_core:error] [pid 488669:tid 488820] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:47.226182 2026] [security2:error] [pid 491656:tid 491909] [client 20.48.250.41:53272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/num.php"] [unique_id "apPkH4vX_L6VjdbvkkSiBgAAAw8"]
[Sun Aug 30 03:04:47.232265 2026] [security2:error] [pid 488669:tid 488910] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/job/.env"] [unique_id "apPkH9Rh6OewFvqQpDls2QAAAXE"]
[Sun Aug 30 03:04:47.255432 2026] [authz_core:error] [pid 491656:tid 491884] [client 66.249.66.73:38501] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:47.255862 2026] [authz_core:error] [pid 491656:tid 491884] [client 66.249.66.73:38501] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:47.278717 2026] [security2:error] [pid 491656:tid 491801] [client 20.196.209.81:7598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/twentytwentythree/patterns/index.php"] [unique_id "apPkH4vX_L6VjdbvkkSiJQAAAqM"]
[Sun Aug 30 03:04:47.292874 2026] [security2:error] [pid 488669:tid 488931] [client 20.104.50.220:29609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wibu.php"] [unique_id "apPkH9Rh6OewFvqQpDltAQAAAYY"]
[Sun Aug 30 03:04:47.306522 2026] [security2:error] [pid 488669:tid 488811] [client 20.220.204.93:64950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/fetch.php"] [unique_id "apPkH9Rh6OewFvqQpDltCgAAAQ4"]
[Sun Aug 30 03:04:47.337451 2026] [security2:error] [pid 488669:tid 488900] [client 20.104.49.130:48046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.infinitelearners.com"] [uri "/ws45.php"] [unique_id "apPkH9Rh6OewFvqQpDltFwAAAWc"]
[Sun Aug 30 03:04:47.337472 2026] [security2:error] [pid 488669:tid 488846] [client 20.104.50.220:31875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/Alfa.php"] [unique_id "apPkH9Rh6OewFvqQpDltFgAAATE"]
[Sun Aug 30 03:04:47.338853 2026] [security2:error] [pid 491656:tid 491797] [client 20.220.10.235:24565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/admin.php/pindex.php"] [unique_id "apPkH4vX_L6VjdbvkkSiOQAAAp8"]
[Sun Aug 30 03:04:47.376820 2026] [security2:error] [pid 488669:tid 488928] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/test/.env"] [unique_id "apPkH9Rh6OewFvqQpDltIgAAAYM"]
[Sun Aug 30 03:04:47.379692 2026] [authz_core:error] [pid 491656:tid 491838] [client 216.73.216.128:45228] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:47.380076 2026] [authz_core:error] [pid 491656:tid 491838] [client 216.73.216.128:45228] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:47.408533 2026] [security2:error] [pid 488669:tid 488746] [remote 162.215.121.77:25026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.121.215.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "writelake.com"] [uri "/wp-login.php"] [unique_id "apPkH9Rh6OewFvqQpDltJgABREQ"]
[Sun Aug 30 03:04:47.432779 2026] [security2:error] [pid 488669:tid 488863] [client 190.121.23.218:58304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.23.121.190.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "freeourmidwives.org"] [uri "/wp-login.php"] [unique_id "apPkH9Rh6OewFvqQpDltIwAAAUI"]
[Sun Aug 30 03:04:47.449838 2026] [security2:error] [pid 488669:tid 488893] [client 40.83.93.50:8608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/g.php"] [unique_id "apPkH9Rh6OewFvqQpDltMgAAAWA"]
[Sun Aug 30 03:04:47.520451 2026] [security2:error] [pid 488669:tid 488827] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/qa/.env"] [unique_id "apPkH9Rh6OewFvqQpDltPAAAAR4"]
[Sun Aug 30 03:04:47.576666 2026] [security2:error] [pid 491656:tid 491825] [client 178.16.55.109:53507] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "calchampsoccer.org"] [uri "/index.php"] [unique_id "apPkH4vX_L6VjdbvkkSiWQAAArs"]
[Sun Aug 30 03:04:47.646567 2026] [qos:error] [pid 488669:tid 488807] [client 103.61.18.6:56554] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.61.18.6, id=apPkH9Rh6OewFvqQpDltWgAAAQo
[Sun Aug 30 03:04:47.647588 2026] [qos:error] [pid 488669:tid 488811] [client 12.232.227.99:38237] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=12.232.227.99, id=apPkH9Rh6OewFvqQpDltWwAAAQ4
[Sun Aug 30 03:04:47.647758 2026] [qos:error] [pid 491656:tid 491837] [client 185.94.83.249:38862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=185.94.83.249, id=apPkH4vX_L6VjdbvkkSiZwAAAsc
[Sun Aug 30 03:04:47.649868 2026] [qos:error] [pid 491656:tid 491832] [client 42.96.18.62:55162] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=42.96.18.62, id=apPkH4vX_L6VjdbvkkSiaAAAAsI
[Sun Aug 30 03:04:47.652301 2026] [qos:error] [pid 491656:tid 491901] [client 163.181.207.226:50174] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=163.181.207.226, id=apPkH4vX_L6VjdbvkkSiaQAAAwc
[Sun Aug 30 03:04:47.653699 2026] [qos:error] [pid 488669:tid 488827] [client 203.76.112.107:49450] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=203.76.112.107, id=apPkH9Rh6OewFvqQpDltXAAAAR4
[Sun Aug 30 03:04:47.658203 2026] [qos:error] [pid 491656:tid 491863] [client 194.44.117.160:43318] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=194.44.117.160, id=apPkH4vX_L6VjdbvkkSiagAAAuE
[Sun Aug 30 03:04:47.659679 2026] [qos:error] [pid 491656:tid 491797] [client 195.62.50.140:58586] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=195.62.50.140, id=apPkH4vX_L6VjdbvkkSiawAAAp8
[Sun Aug 30 03:04:47.670521 2026] [security2:error] [pid 488669:tid 488823] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/preview/.env"] [unique_id "apPkH9Rh6OewFvqQpDltXgAAARo"]
[Sun Aug 30 03:04:47.676714 2026] [qos:error] [pid 488669:tid 488855] [client 117.236.124.166:45188] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=117.236.124.166, id=apPkH9Rh6OewFvqQpDltXwAAATo
[Sun Aug 30 03:04:47.677448 2026] [qos:error] [pid 488669:tid 488885] [client 213.148.22.154:49398] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=213.148.22.154, id=apPkH9Rh6OewFvqQpDltYQAAAVg
[Sun Aug 30 03:04:47.677872 2026] [qos:error] [pid 488669:tid 488819] [client 205.209.65.105:53898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=205.209.65.105, id=apPkH9Rh6OewFvqQpDltYAAAARY
[Sun Aug 30 03:04:47.685496 2026] [qos:error] [pid 488669:tid 488918] [client 103.140.207.186:41584] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.140.207.186, id=apPkH9Rh6OewFvqQpDltYgAAAXk
[Sun Aug 30 03:04:47.690572 2026] [qos:error] [pid 491656:tid 491829] [client 176.114.125.96:44142] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=176.114.125.96, id=apPkH4vX_L6VjdbvkkSibAAAAr8
[Sun Aug 30 03:04:47.693105 2026] [qos:error] [pid 491656:tid 491902] [client 103.179.252.81:48248] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.179.252.81, id=apPkH4vX_L6VjdbvkkSibQAAAwg
[Sun Aug 30 03:04:47.693110 2026] [qos:error] [pid 488669:tid 488828] [client 103.168.35.196:43686] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=103.168.35.196, id=apPkH9Rh6OewFvqQpDltYwAAAR8
[Sun Aug 30 03:04:47.695895 2026] [qos:error] [pid 491656:tid 491886] [client 45.172.226.48:47122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.172.226.48, id=apPkH4vX_L6VjdbvkkSibgAAAvg
[Sun Aug 30 03:04:47.697409 2026] [qos:error] [pid 488669:tid 488858] [client 194.37.88.115:43556] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=194.37.88.115, id=apPkH9Rh6OewFvqQpDltZAAAAT0
[Sun Aug 30 03:04:47.702945 2026] [qos:error] [pid 491656:tid 491839] [client 181.174.228.175:60960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=181.174.228.175, id=apPkH4vX_L6VjdbvkkSibwAAAsk
[Sun Aug 30 03:04:47.704619 2026] [qos:error] [pid 488669:tid 488930] [client 35.78.66.144:13068] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=35.78.66.144, id=apPkH9Rh6OewFvqQpDltZQAAAYU
[Sun Aug 30 03:04:47.712069 2026] [authz_core:error] [pid 488669:tid 488869] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus%2Fsections
[Sun Aug 30 03:04:47.712380 2026] [authz_core:error] [pid 488669:tid 488869] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus%2Fsections
[Sun Aug 30 03:04:47.717943 2026] [qos:error] [pid 491656:tid 491844] [client 160.191.12.214:49362] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=160.191.12.214, id=apPkH4vX_L6VjdbvkkSicAAAAs4
[Sun Aug 30 03:04:47.720311 2026] [qos:error] [pid 488669:tid 488882] [client 180.191.233.145:35086] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=180.191.233.145, id=apPkH9Rh6OewFvqQpDltZwAAAVU
[Sun Aug 30 03:04:47.725105 2026] [qos:error] [pid 491656:tid 491805] [client 43.134.141.85:52782] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=43.134.141.85, id=apPkH4vX_L6VjdbvkkSicgAAAqc
[Sun Aug 30 03:04:47.725111 2026] [qos:error] [pid 491656:tid 491879] [client 94.131.92.155:46362] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=94.131.92.155, id=apPkH4vX_L6VjdbvkkSicQAAAvE
[Sun Aug 30 03:04:47.727634 2026] [qos:error] [pid 488669:tid 488931] [client 169.150.224.227:38906] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=169.150.224.227, id=apPkH9Rh6OewFvqQpDltaAAAAYY
[Sun Aug 30 03:04:47.729433 2026] [qos:error] [pid 491656:tid 491880] [client 181.13.210.60:33616] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=181.13.210.60, id=apPkH4vX_L6VjdbvkkSicwAAAvI
[Sun Aug 30 03:04:47.729969 2026] [qos:error] [pid 488669:tid 488894] [client 157.15.116.26:47230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=157.15.116.26, id=apPkH9Rh6OewFvqQpDltaQAAAWE
[Sun Aug 30 03:04:47.733680 2026] [qos:error] [pid 488669:tid 488925] [client 189.194.250.98:33223] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=189.194.250.98, id=apPkH9Rh6OewFvqQpDltagAAAYA
[Sun Aug 30 03:04:47.733880 2026] [qos:error] [pid 488669:tid 488898] [client 203.175.103.45:52862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=203.175.103.45, id=apPkH9Rh6OewFvqQpDltawAAAWU
[Sun Aug 30 03:04:47.735509 2026] [qos:error] [pid 491656:tid 491793] [client 37.29.12.198:34939] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=37.29.12.198, id=apPkH4vX_L6VjdbvkkSidQAAAps
[Sun Aug 30 03:04:47.738321 2026] [qos:error] [pid 488669:tid 488851] [client 117.2.121.198:60490] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=117.2.121.198, id=apPkH9Rh6OewFvqQpDltbQAAATY
[Sun Aug 30 03:04:47.742358 2026] [qos:error] [pid 488669:tid 488811] [client 112.197.57.3:38792] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=112.197.57.3, id=apPkH9Rh6OewFvqQpDltbgAAAQ4
[Sun Aug 30 03:04:47.745371 2026] [qos:error] [pid 491656:tid 491827] [client 108.165.173.211:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=108.165.173.211, id=apPkH4vX_L6VjdbvkkSidgAAAr0
[Sun Aug 30 03:04:47.745374 2026] [qos:error] [pid 491656:tid 491820] [client 190.83.3.10:45194] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=190.83.3.10, id=apPkH4vX_L6VjdbvkkSidwAAArY
[Sun Aug 30 03:04:47.750747 2026] [qos:error] [pid 491656:tid 491854] [client 78.40.199.121:36542] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=78.40.199.121, id=apPkH4vX_L6VjdbvkkSieAAAAtg
[Sun Aug 30 03:04:47.752605 2026] [qos:error] [pid 488669:tid 488906] [client 79.145.253.67:35612] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=79.145.253.67, id=apPkH9Rh6OewFvqQpDltbwAAAW0
[Sun Aug 30 03:04:47.752928 2026] [qos:error] [pid 491656:tid 491905] [client 177.54.40.12:52814] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=177.54.40.12, id=apPkH4vX_L6VjdbvkkSieQAAAws
[Sun Aug 30 03:04:47.753242 2026] [qos:error] [pid 488669:tid 488852] [client 103.68.214.141:58846] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.68.214.141, id=apPkH9Rh6OewFvqQpDltcAAAATc
[Sun Aug 30 03:04:47.754037 2026] [qos:error] [pid 491656:tid 491906] [client 5.253.196.143:50126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=5.253.196.143, id=apPkH4vX_L6VjdbvkkSiegAAAww
[Sun Aug 30 03:04:47.757237 2026] [qos:error] [pid 488669:tid 488827] [client 113.174.113.56:38097] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=113.174.113.56, id=apPkH9Rh6OewFvqQpDltcQAAAR4
[Sun Aug 30 03:04:47.762801 2026] [qos:error] [pid 491656:tid 491801] [client 38.65.174.247:43360] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.65.174.247, id=apPkH4vX_L6VjdbvkkSiewAAAqM
[Sun Aug 30 03:04:47.762882 2026] [qos:error] [pid 488669:tid 488908] [client 175.100.34.190:35601] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=175.100.34.190, id=apPkH9Rh6OewFvqQpDltcwAAAW8
[Sun Aug 30 03:04:47.763796 2026] [security2:error] [pid 488669:tid 488743] [remote 162.215.121.77:25026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.121.215.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "writelake.com"] [uri "/wp-login.php"] [unique_id "apPkH9Rh6OewFvqQpDltcgABaUE"], referer: https://writelake.com/wp-login.php
[Sun Aug 30 03:04:47.767039 2026] [qos:error] [pid 488669:tid 488823] [client 123.20.38.145:41814] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=123.20.38.145, id=apPkH9Rh6OewFvqQpDltdAAAARo
[Sun Aug 30 03:04:47.770639 2026] [qos:error] [pid 488669:tid 488855] [client 212.19.10.44:33411] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=212.19.10.44, id=apPkH9Rh6OewFvqQpDltdQAAATo
[Sun Aug 30 03:04:47.773730 2026] [qos:error] [pid 488669:tid 488885] [client 216.250.105.26:60176] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=216.250.105.26, id=apPkH9Rh6OewFvqQpDltdgAAAVg
[Sun Aug 30 03:04:47.774380 2026] [qos:error] [pid 491656:tid 491914] [client 23.129.64.160:12189] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=23.129.64.160, id=apPkH4vX_L6VjdbvkkSifAAAAxQ
[Sun Aug 30 03:04:47.774469 2026] [qos:error] [pid 491656:tid 491835] [client 103.178.194.95:55396] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.178.194.95, id=apPkH4vX_L6VjdbvkkSifQAAAsU
[Sun Aug 30 03:04:47.778880 2026] [qos:error] [pid 491656:tid 491841] [client 149.28.251.187:47464] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=149.28.251.187, id=apPkH4vX_L6VjdbvkkSifgAAAss
[Sun Aug 30 03:04:47.782662 2026] [qos:error] [pid 488669:tid 488819] [client 203.91.118.6:58768] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=203.91.118.6, id=apPkH9Rh6OewFvqQpDltdwAAARY
[Sun Aug 30 03:04:47.783361 2026] [qos:error] [pid 488669:tid 488868] [client 38.191.211.56:38126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.191.211.56, id=apPkH9Rh6OewFvqQpDlteAAAAUc
[Sun Aug 30 03:04:47.786596 2026] [qos:error] [pid 491656:tid 491916] [client 185.225.42.73:48746] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=185.225.42.73, id=apPkH4vX_L6VjdbvkkSifwAAAxY
[Sun Aug 30 03:04:47.789231 2026] [qos:error] [pid 491656:tid 491868] [client 188.161.188.144:36266] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=188.161.188.144, id=apPkH4vX_L6VjdbvkkSigAAAAuY
[Sun Aug 30 03:04:47.792894 2026] [qos:error] [pid 488669:tid 488918] [client 111.230.27.213:43082] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=111.230.27.213, id=apPkH9Rh6OewFvqQpDlteQAAAXk
[Sun Aug 30 03:04:47.794696 2026] [qos:error] [pid 488669:tid 488828] [client 23.138.88.86:59762] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=23.138.88.86, id=apPkH9Rh6OewFvqQpDltewAAAR8
[Sun Aug 30 03:04:47.795318 2026] [qos:error] [pid 488669:tid 488825] [client 36.253.25.10:59122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=36.253.25.10, id=apPkH9Rh6OewFvqQpDltegAAARw
[Sun Aug 30 03:04:47.796815 2026] [qos:error] [pid 488669:tid 488858] [client 193.233.247.104:35641] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=193.233.247.104, id=apPkH9Rh6OewFvqQpDltfAAAAT0
[Sun Aug 30 03:04:47.800178 2026] [qos:error] [pid 491656:tid 491836] [client 43.159.37.201:50760] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=43.159.37.201, id=apPkH4vX_L6VjdbvkkSigQAAAsY
[Sun Aug 30 03:04:47.803762 2026] [qos:error] [pid 491656:tid 491813] [client 104.28.194.6:44314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=104.28.194.6, id=apPkH4vX_L6VjdbvkkSiggAAAq8
[Sun Aug 30 03:04:47.808265 2026] [qos:error] [pid 488669:tid 488930] [client 212.34.233.150:41286] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=212.34.233.150, id=apPkH9Rh6OewFvqQpDltfQAAAYU
[Sun Aug 30 03:04:47.810852 2026] [qos:error] [pid 491656:tid 491856] [client 45.230.169.22:38234] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.230.169.22, id=apPkH4vX_L6VjdbvkkSigwAAAto
[Sun Aug 30 03:04:47.811941 2026] [qos:error] [pid 488669:tid 488926] [client 27.66.27.114:54412] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=27.66.27.114, id=apPkH9Rh6OewFvqQpDltfwAAAYE
[Sun Aug 30 03:04:47.811939 2026] [qos:error] [pid 488669:tid 488901] [client 203.115.123.163:58574] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=203.115.123.163, id=apPkH9Rh6OewFvqQpDltfgAAAWg
[Sun Aug 30 03:04:47.814577 2026] [security2:error] [pid 488669:tid 488882] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/beta/.env"] [unique_id "apPkH9Rh6OewFvqQpDltgAAAAVU"]
[Sun Aug 30 03:04:47.822230 2026] [qos:error] [pid 491656:tid 491875] [client 45.70.236.194:33035] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.70.236.194, id=apPkH4vX_L6VjdbvkkSihAAAAu0
[Sun Aug 30 03:04:47.824880 2026] [qos:error] [pid 488669:tid 488914] [client 38.172.170.121:52174] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.172.170.121, id=apPkH9Rh6OewFvqQpDltgQAAAXU
[Sun Aug 30 03:04:47.833470 2026] [qos:error] [pid 488669:tid 488894] [client 135.136.63.218:55486] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=135.136.63.218, id=apPkH9Rh6OewFvqQpDltggAAAWE
[Sun Aug 30 03:04:47.833476 2026] [qos:error] [pid 488669:tid 488925] [client 138.117.85.133:36446] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=138.117.85.133, id=apPkH9Rh6OewFvqQpDltgwAAAYA
[Sun Aug 30 03:04:47.833693 2026] [qos:error] [pid 491656:tid 491837] [client 85.133.190.40:34894] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=85.133.190.40, id=apPkH4vX_L6VjdbvkkSihwAAAsc
[Sun Aug 30 03:04:47.834624 2026] [qos:error] [pid 491656:tid 491823] [client 181.115.147.68:60059] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=181.115.147.68, id=apPkH4vX_L6VjdbvkkSiiAAAArk
[Sun Aug 30 03:04:47.837211 2026] [qos:error] [pid 491656:tid 491821] [client 85.159.94.124:43727] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=85.159.94.124, id=apPkH4vX_L6VjdbvkkSiiQAAArc
[Sun Aug 30 03:04:47.838266 2026] [qos:error] [pid 491656:tid 491832] [client 118.179.87.193:44662] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=118.179.87.193, id=apPkH4vX_L6VjdbvkkSiigAAAsI
[Sun Aug 30 03:04:47.840214 2026] [qos:error] [pid 491656:tid 491901] [client 103.224.65.89:39312] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.224.65.89, id=apPkH4vX_L6VjdbvkkSiiwAAAwc
[Sun Aug 30 03:04:47.844238 2026] [http2:info] [pid 492549:tid 492549] h2_workers: created with min=128 max=192 idle_ms=600000
[Sun Aug 30 03:04:47.845186 2026] [qos:error] [pid 488669:tid 488898] [client 159.89.53.119:34916] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=159.89.53.119, id=apPkH9Rh6OewFvqQpDlthAAAAWU
[Sun Aug 30 03:04:47.846284 2026] [qos:error] [pid 491656:tid 491863] [client 103.156.75.243:38876] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.156.75.243, id=apPkH4vX_L6VjdbvkkSijAAAAuE
[Sun Aug 30 03:04:47.846292 2026] [qos:error] [pid 491656:tid 491797] [client 85.137.91.120:47194] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=85.137.91.120, id=apPkH4vX_L6VjdbvkkSijQAAAp8
[Sun Aug 30 03:04:47.861048 2026] [qos:error] [pid 491656:tid 491795] [client 213.21.57.244:56608] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=213.21.57.244, id=apPkH4vX_L6VjdbvkkSijgAAAp0
[Sun Aug 30 03:04:47.864366 2026] [qos:error] [pid 491656:tid 491884] [client 199.7.149.90:60216] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=199.7.149.90, id=apPkH4vX_L6VjdbvkkSijwAAAvY
[Sun Aug 30 03:04:47.866059 2026] [security2:error] [pid 492549:tid 492690] [client 68.155.159.216:59972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/makeasmtp.php"] [unique_id "apPkHzqFvOdCFO2AmwpCMwAAA6o"]
[Sun Aug 30 03:04:47.866078 2026] [security2:error] [pid 492549:tid 492684] [client 20.48.251.3:54782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/public/mah.php.php"] [unique_id "apPkHzqFvOdCFO2AmwpCLwAAA6Q"]
[Sun Aug 30 03:04:47.866214 2026] [security2:error] [pid 492549:tid 492687] [client 20.220.10.235:24469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/admin.php/csv.php"] [unique_id "apPkHzqFvOdCFO2AmwpCMQAAA6c"]
[Sun Aug 30 03:04:47.866254 2026] [security2:error] [pid 492549:tid 492702] [client 158.23.147.79:62564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apPkHzqFvOdCFO2AmwpCNwAAA7Y"]
[Sun Aug 30 03:04:47.866303 2026] [security2:error] [pid 492549:tid 492705] [client 20.104.18.15:31715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/file31.php"] [unique_id "apPkHzqFvOdCFO2AmwpCOAAAA7k"]
[Sun Aug 30 03:04:47.866354 2026] [security2:error] [pid 492549:tid 492693] [client 20.104.18.15:9082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/wp-admin/w.php"] [unique_id "apPkHzqFvOdCFO2AmwpCNQAAA60"]
[Sun Aug 30 03:04:47.866403 2026] [security2:error] [pid 492549:tid 492686] [client 20.104.50.220:61962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/ya.php"] [unique_id "apPkHzqFvOdCFO2AmwpCMAAAA6Y"]
[Sun Aug 30 03:04:47.866436 2026] [security2:error] [pid 492549:tid 492694] [client 20.220.204.93:64383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/vx.php"] [unique_id "apPkHzqFvOdCFO2AmwpCNAAAA64"]
[Sun Aug 30 03:04:47.866487 2026] [security2:error] [pid 492549:tid 492688] [client 20.48.251.3:51517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apPkHzqFvOdCFO2AmwpCMgAAA6g"]
[Sun Aug 30 03:04:47.866603 2026] [security2:error] [pid 492549:tid 492683] [client 20.48.250.41:53269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/a4.php"] [unique_id "apPkHzqFvOdCFO2AmwpCLgAAA6M"]
[Sun Aug 30 03:04:47.867614 2026] [security2:error] [pid 492549:tid 492709] [client 20.104.50.220:51616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/v5.php"] [unique_id "apPkHzqFvOdCFO2AmwpCOQAAA70"]
[Sun Aug 30 03:04:47.868061 2026] [security2:error] [pid 492549:tid 492712] [client 20.151.200.44:46979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/t00l.php"] [unique_id "apPkHzqFvOdCFO2AmwpCOgAAA8A"]
[Sun Aug 30 03:04:47.869387 2026] [qos:error] [pid 491656:tid 491908] [client 185.135.83.178:57899] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=185.135.83.178, id=apPkH4vX_L6VjdbvkkSikAAAAw4
[Sun Aug 30 03:04:47.874425 2026] [qos:error] [pid 492549:tid 492687] [client 203.76.117.230:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkHzqFvOdCFO2AmwpCRwAAA6c
[Sun Aug 30 03:04:47.875353 2026] [qos:error] [pid 492549:tid 492723] [client 103.157.79.9:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkHzqFvOdCFO2AmwpCSAAAA8s
[Sun Aug 30 03:04:47.876258 2026] [security2:error] [pid 492549:tid 492687] [client 20.220.204.93:10266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/Geforce.php"] [unique_id "apPkHzqFvOdCFO2AmwpCTQAAA6c"]
[Sun Aug 30 03:04:47.877825 2026] [qos:error] [pid 488669:tid 488811] [client 202.47.59.80:42301] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=202.47.59.80, id=apPkH9Rh6OewFvqQpDlthgAAAQ4
[Sun Aug 30 03:04:47.877879 2026] [qos:error] [pid 491656:tid 491829] [client 181.67.122.157:31752] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=181.67.122.157, id=apPkH4vX_L6VjdbvkkSikQAAAr8
[Sun Aug 30 03:04:47.880891 2026] [qos:error] [pid 488669:tid 488852] [client 154.90.70.238:50284] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=154.90.70.238, id=apPkH9Rh6OewFvqQpDltiAAAATc
[Sun Aug 30 03:04:47.880894 2026] [qos:error] [pid 488669:tid 488906] [client 2.144.6.22:38986] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=2.144.6.22, id=apPkH9Rh6OewFvqQpDlthwAAAW0
[Sun Aug 30 03:04:47.881550 2026] [qos:error] [pid 488669:tid 488814] [client 162.4.16.174:53336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=162.4.16.174, id=apPkH9Rh6OewFvqQpDltiQAAARE
[Sun Aug 30 03:04:47.884849 2026] [qos:error] [pid 491656:tid 491902] [client 200.71.111.157:60016] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=200.71.111.157, id=apPkH4vX_L6VjdbvkkSikgAAAwg
[Sun Aug 30 03:04:47.895749 2026] [qos:error] [pid 488669:tid 488827] [client 177.46.170.57:48448] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=177.46.170.57, id=apPkH9Rh6OewFvqQpDltigAAAR4
[Sun Aug 30 03:04:47.896549 2026] [qos:error] [pid 488669:tid 488908] [client 101.36.104.239:51562] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=101.36.104.239, id=apPkH9Rh6OewFvqQpDltiwAAAW8
[Sun Aug 30 03:04:47.898870 2026] [qos:error] [pid 492549:tid 492715] [client 38.9.184.180:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkHzqFvOdCFO2AmwpCQQAAA8M
[Sun Aug 30 03:04:47.899452 2026] [qos:error] [pid 492549:tid 492713] [client 164.163.188.113:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.44, id=apPkHzqFvOdCFO2AmwpCZQAAA8E
[Sun Aug 30 03:04:47.900480 2026] [security2:error] [pid 492549:tid 492774] [client 20.151.200.44:58838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/t00l.php"] [unique_id "apPkHzqFvOdCFO2AmwpCkwAAA_4"]
[Sun Aug 30 03:04:47.900744 2026] [security2:error] [pid 492549:tid 492708] [client 20.48.251.3:6983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/sdsa.php"] [unique_id "apPkHzqFvOdCFO2AmwpClAAAA7w"]
[Sun Aug 30 03:04:47.904031 2026] [qos:error] [pid 491656:tid 491846] [client 160.202.152.5:59822] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=160.202.152.5, id=apPkH4vX_L6VjdbvkkSikwAAAtA
[Sun Aug 30 03:04:47.904260 2026] [qos:error] [pid 492549:tid 492719] [client 109.172.55.227:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkHzqFvOdCFO2AmwpCmwAAA8c
[Sun Aug 30 03:04:47.904289 2026] [qos:error] [pid 492549:tid 492713] [client 109.123.251.109:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.44, id=apPkHzqFvOdCFO2AmwpCmgAAA8E
[Sun Aug 30 03:04:47.904298 2026] [qos:error] [pid 492549:tid 492774] [client 37.202.16.238:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=50.6.92.44, id=apPkHzqFvOdCFO2AmwpCnAAAA_4
[Sun Aug 30 03:04:47.904728 2026] [qos:error] [pid 488669:tid 488921] [client 200.58.214.100:57288] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=200.58.214.100, id=apPkH9Rh6OewFvqQpDltjAAAAXw
[Sun Aug 30 03:04:47.904836 2026] [qos:error] [pid 492549:tid 492721] [client 85.8.47.211:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkHzqFvOdCFO2AmwpCngAAA8k
[Sun Aug 30 03:04:47.907805 2026] [qos:error] [pid 492549:tid 492774] [client 103.157.78.190:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkHzqFvOdCFO2AmwpCoAAAA_4
[Sun Aug 30 03:04:47.918161 2026] [authz_core:error] [pid 488669:tid 488885] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:47.918601 2026] [authz_core:error] [pid 488669:tid 488885] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:47.919614 2026] [authz_core:error] [pid 492549:tid 492733] [client 66.249.66.192:58324] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:47.920079 2026] [authz_core:error] [pid 492549:tid 492733] [client 66.249.66.192:58324] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:47.929784 2026] [authz_core:error] [pid 491656:tid 491880] [client 216.73.216.128:51719] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:47.930137 2026] [authz_core:error] [pid 491656:tid 491880] [client 216.73.216.128:51719] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:47.937001 2026] [security2:error] [pid 491656:tid 491868] [client 20.48.251.3:59276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/config/laravolt/css/index.php"] [unique_id "apPkH4vX_L6VjdbvkkSiogAAAuY"]
[Sun Aug 30 03:04:47.959164 2026] [security2:error] [pid 488669:tid 488811] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/uat/.env"] [unique_id "apPkH9Rh6OewFvqQpDltpAAAAQ4"]
[Sun Aug 30 03:04:47.976874 2026] [security2:error] [pid 488669:tid 488914] [client 114.119.138.36:54785] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.munsterland.net"] [uri "/josephpevney.html"] [unique_id "apPkH9Rh6OewFvqQpDlttgAAAXU"], referer: http://www.munsterland.net/josephpevney.html
[Sun Aug 30 03:04:47.995681 2026] [security2:error] [pid 488669:tid 488837] [client 20.48.250.41:53328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/tfm.php"] [unique_id "apPkH9Rh6OewFvqQpDltxgAAASg"]
[Sun Aug 30 03:04:48.008976 2026] [security2:error] [pid 491656:tid 491908] [client 20.220.10.235:24574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/admin.php/700.php"] [unique_id "apPkIIvX_L6VjdbvkkSizQAAAw4"]
[Sun Aug 30 03:04:48.028676 2026] [security2:error] [pid 492549:tid 492707] [client 40.83.93.50:8605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/cc.php"] [unique_id "apPkIDqFvOdCFO2AmwpC7gAAA7s"]
[Sun Aug 30 03:04:48.035866 2026] [authz_core:error] [pid 488669:tid 488919] [client 66.249.66.206:39556] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:48.036140 2026] [security2:error] [pid 488669:tid 488892] [client 20.104.18.15:32971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/images.php"] [unique_id "apPkINRh6OewFvqQpDlt4AAAAV8"]
[Sun Aug 30 03:04:48.036190 2026] [authz_core:error] [pid 488669:tid 488919] [client 66.249.66.206:39556] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:48.043149 2026] [security2:error] [pid 491656:tid 491910] [client 20.220.204.93:64340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/global.php"] [unique_id "apPkIIvX_L6VjdbvkkSi3gAAAxA"]
[Sun Aug 30 03:04:48.051286 2026] [security2:error] [pid 488669:tid 488894] [client 20.104.50.220:62822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/maho.php"] [unique_id "apPkINRh6OewFvqQpDlt5gAAAWE"]
[Sun Aug 30 03:04:48.058853 2026] [security2:error] [pid 488669:tid 488840] [client 20.48.251.3:23475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/public/mah.php.php"] [unique_id "apPkINRh6OewFvqQpDlt7AAAASs"]
[Sun Aug 30 03:04:48.064505 2026] [security2:error] [pid 492549:tid 492556] [remote 168.63.79.147:47956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "richardmudzingwa.com"] [uri "/wp-login.php"] [unique_id "apPkIDqFvOdCFO2AmwpC7wADpQM"]
[Sun Aug 30 03:04:48.104710 2026] [security2:error] [pid 488669:tid 488899] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/stage/.env"] [unique_id "apPkINRh6OewFvqQpDluBwAAAWY"]
[Sun Aug 30 03:04:48.105252 2026] [security2:error] [pid 491656:tid 491844] [client 20.104.50.220:32889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/titid.php"] [unique_id "apPkIIvX_L6VjdbvkkSi8QAAAs4"]
[Sun Aug 30 03:04:48.111617 2026] [authz_core:error] [pid 491656:tid 491855] [client 216.73.216.128:13201] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:48.112047 2026] [authz_core:error] [pid 491656:tid 491855] [client 216.73.216.128:13201] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:48.141819 2026] [security2:error] [pid 491656:tid 491825] [client 20.104.50.220:47055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/index7.php"] [unique_id "apPkIIvX_L6VjdbvkkSjAQAAArs"]
[Sun Aug 30 03:04:48.148300 2026] [security2:error] [pid 492549:tid 492702] [client 20.220.10.235:24535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/admin.php/007x.php"] [unique_id "apPkIDqFvOdCFO2AmwpDAAAAA7Y"]
[Sun Aug 30 03:04:48.152796 2026] [security2:error] [pid 492549:tid 492788] [client 20.196.209.81:7611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/users.php"] [unique_id "apPkIDqFvOdCFO2AmwpDAQAABAw"]
[Sun Aug 30 03:04:48.162731 2026] [security2:error] [pid 488669:tid 488905] [client 20.48.250.41:53319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/Geforce.php"] [unique_id "apPkINRh6OewFvqQpDluJQAAAWw"]
[Sun Aug 30 03:04:48.182401 2026] [security2:error] [pid 491656:tid 491856] [client 20.220.204.93:64289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/fs.php"] [unique_id "apPkIIvX_L6VjdbvkkSjEAAAAto"]
[Sun Aug 30 03:04:48.194159 2026] [security2:error] [pid 488669:tid 488814] [client 20.48.251.3:55531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/wp-konfig.php"] [unique_id "apPkINRh6OewFvqQpDluOQAAARE"]
[Sun Aug 30 03:04:48.231390 2026] [security2:error] [pid 492549:tid 492750] [client 68.155.159.216:52845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-includes/js/index.php"] [unique_id "apPkIDqFvOdCFO2AmwpDCAAAA-Y"]
[Sun Aug 30 03:04:48.241909 2026] [security2:error] [pid 492549:tid 492557] [remote 168.63.79.147:47956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "richardmudzingwa.com"] [uri "/wp-login.php"] [unique_id "apPkIDqFvOdCFO2AmwpDCgADzQQ"], referer: https://richardmudzingwa.com/wp-login.php
[Sun Aug 30 03:04:48.247501 2026] [security2:error] [pid 491656:tid 491739] [remote 143.95.209.25:45276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.209.95.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "demandthetruth.org"] [uri "/wp-login.php"] [unique_id "apPkIIvX_L6VjdbvkkSjKAAC3U0"]
[Sun Aug 30 03:04:48.249808 2026] [security2:error] [pid 488669:tid 488931] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/development/.env"] [unique_id "apPkINRh6OewFvqQpDluYgAAAYY"]
[Sun Aug 30 03:04:48.262221 2026] [security2:error] [pid 491656:tid 491914] [client 20.104.50.220:5560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/manager.php"] [unique_id "apPkIIvX_L6VjdbvkkSjMAAAAxQ"]
[Sun Aug 30 03:04:48.284403 2026] [security2:error] [pid 492549:tid 492684] [client 20.220.10.235:24524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/admin.php/heex.php"] [unique_id "apPkIDqFvOdCFO2AmwpDEAAAA6Q"]
[Sun Aug 30 03:04:48.288759 2026] [security2:error] [pid 491656:tid 491869] [client 158.23.147.79:63260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/chosen.php"] [unique_id "apPkIIvX_L6VjdbvkkSjQQAAAuc"]
[Sun Aug 30 03:04:48.298466 2026] [security2:error] [pid 488669:tid 488871] [client 20.48.250.41:53267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/click.php"] [unique_id "apPkINRh6OewFvqQpDlueQAAAUo"]
[Sun Aug 30 03:04:48.315190 2026] [security2:error] [pid 491656:tid 491871] [client 178.16.55.109:65378] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "calchampsoccer.org"] [uri "/index.php"] [unique_id "apPkIIvX_L6VjdbvkkSjVQAAAuk"]
[Sun Aug 30 03:04:48.330087 2026] [security2:error] [pid 488669:tid 488875] [client 20.220.204.93:64303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/ioxi.php"] [unique_id "apPkINRh6OewFvqQpDlujAAAAU4"]
[Sun Aug 30 03:04:48.330450 2026] [security2:error] [pid 488669:tid 488883] [client 68.155.159.216:52619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/xmlrpc.php"] [unique_id "apPkINRh6OewFvqQpDlujQAAAVY"]
[Sun Aug 30 03:04:48.347615 2026] [authz_core:error] [pid 488669:tid 488862] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:04:48.347975 2026] [authz_core:error] [pid 488669:tid 488862] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:04:48.351322 2026] [security2:error] [pid 492549:tid 492757] [client 20.197.61.180:13888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/twentytwentythree/patterns/index.php"] [unique_id "apPkIDqFvOdCFO2AmwpDGwAAA-0"]
[Sun Aug 30 03:04:48.395372 2026] [security2:error] [pid 488669:tid 488885] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/production/.env"] [unique_id "apPkINRh6OewFvqQpDlusgAAAVg"]
[Sun Aug 30 03:04:48.413406 2026] [security2:error] [pid 488669:tid 488928] [client 20.220.10.235:24540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/tf.php"] [unique_id "apPkINRh6OewFvqQpDluvQAAAYM"]
[Sun Aug 30 03:04:48.420322 2026] [authz_core:error] [pid 488669:tid 488912] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:48.420815 2026] [authz_core:error] [pid 488669:tid 488912] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:48.422789 2026] [security2:error] [pid 488669:tid 488909] [client 20.48.251.3:44395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/aws-credentials.php"] [unique_id "apPkINRh6OewFvqQpDluwwAAAXA"]
[Sun Aug 30 03:04:48.427767 2026] [security2:error] [pid 488669:tid 488861] [client 20.104.50.220:29583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/Wop.php"] [unique_id "apPkINRh6OewFvqQpDluxwAAAUA"]
[Sun Aug 30 03:04:48.432298 2026] [security2:error] [pid 488669:tid 488831] [client 20.48.250.41:53275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/ms.php"] [unique_id "apPkINRh6OewFvqQpDluyQAAASI"]
[Sun Aug 30 03:04:48.471400 2026] [security2:error] [pid 488669:tid 488837] [client 20.104.50.220:32079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-admin/includes/mailer.php.php"] [unique_id "apPkINRh6OewFvqQpDlu3QAAASg"]
[Sun Aug 30 03:04:48.474957 2026] [security2:error] [pid 488669:tid 488822] [client 20.48.251.3:7069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/asa.php"] [unique_id "apPkINRh6OewFvqQpDlu4AAAARk"]
[Sun Aug 30 03:04:48.476960 2026] [security2:error] [pid 488669:tid 488823] [client 20.220.204.93:64261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/bootstrap.php"] [unique_id "apPkINRh6OewFvqQpDlu4wAAARo"]
[Sun Aug 30 03:04:48.477461 2026] [authz_core:error] [pid 488669:tid 488838] [client 216.73.216.128:6735] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:48.477946 2026] [authz_core:error] [pid 488669:tid 488838] [client 216.73.216.128:6735] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:48.490364 2026] [security2:error] [pid 492549:tid 492692] [client 34.15.145.202:43434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/webroot/index.php/_environment"] [unique_id "apPkIDqFvOdCFO2AmwpDIgAAA6w"]
[Sun Aug 30 03:04:48.539529 2026] [security2:error] [pid 488669:tid 488884] [client 136.92.30.49:34630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jazminanderson.com"] [uri "/config/app/.env"] [unique_id "apPkINRh6OewFvqQpDlvBQAAAVc"]
[Sun Aug 30 03:04:48.547451 2026] [security2:error] [pid 491656:tid 491812] [client 20.220.10.235:24541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/update/da222.php"] [unique_id "apPkIIvX_L6VjdbvkkSjpgAAAq4"]
[Sun Aug 30 03:04:48.549380 2026] [security2:error] [pid 488669:tid 488812] [client 20.196.209.81:7402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/wp-cron.php"] [unique_id "apPkINRh6OewFvqQpDlvBwAAAQ8"]
[Sun Aug 30 03:04:48.572234 2026] [security2:error] [pid 488669:tid 488895] [client 40.83.93.50:9147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/f35.php"] [unique_id "apPkINRh6OewFvqQpDlvGwAAAWI"]
[Sun Aug 30 03:04:48.573659 2026] [security2:error] [pid 492549:tid 492732] [client 20.48.250.41:53309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/zxekqlxb.php"] [unique_id "apPkIDqFvOdCFO2AmwpDJgAAA9Q"]
[Sun Aug 30 03:04:48.616940 2026] [security2:error] [pid 488669:tid 488837] [client 20.220.204.93:64943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/export.php"] [unique_id "apPkINRh6OewFvqQpDlvNwAAASg"]
[Sun Aug 30 03:04:48.648304 2026] [authz_core:error] [pid 488669:tid 488850] [client 66.249.66.205:57806] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:48.648690 2026] [authz_core:error] [pid 488669:tid 488850] [client 66.249.66.205:57806] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:48.649446 2026] [security2:error] [pid 488669:tid 488895] [client 216.73.216.128:5208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mysqlupgrade"] [unique_id "apPkINRh6OewFvqQpDlvRQAAAWI"]
[Sun Aug 30 03:04:48.660856 2026] [security2:error] [pid 488669:tid 488752] [remote 168.63.79.147:47970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "trulydeluxe.com"] [uri "/wp-login.php"] [unique_id "apPkINRh6OewFvqQpDlvRgABWEo"]
[Sun Aug 30 03:04:48.679435 2026] [security2:error] [pid 488669:tid 488877] [client 20.220.10.235:24478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/qi.php"] [unique_id "apPkINRh6OewFvqQpDlvTwAAAVA"]
[Sun Aug 30 03:04:48.683885 2026] [security2:error] [pid 488669:tid 488920] [client 136.92.30.49:34630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/phpinfo.php"] [unique_id "apPkINRh6OewFvqQpDlvVAAAAXs"]
[Sun Aug 30 03:04:48.700408 2026] [security2:error] [pid 488669:tid 488858] [client 20.48.250.41:53340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/init.php"] [unique_id "apPkINRh6OewFvqQpDlvWgAAAT0"]
[Sun Aug 30 03:04:48.772915 2026] [security2:error] [pid 488669:tid 488809] [client 158.23.147.79:63245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/goods.php"] [unique_id "apPkINRh6OewFvqQpDlveQAAAQw"]
[Sun Aug 30 03:04:48.778481 2026] [security2:error] [pid 488669:tid 488847] [client 20.220.204.93:64965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/gk.php"] [unique_id "apPkINRh6OewFvqQpDlvfAAAATI"]
[Sun Aug 30 03:04:48.808449 2026] [security2:error] [pid 488669:tid 488891] [client 20.220.10.235:24494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/px.php"] [unique_id "apPkINRh6OewFvqQpDlviQAAAV4"]
[Sun Aug 30 03:04:48.832267 2026] [security2:error] [pid 488669:tid 488755] [remote 168.63.79.147:47970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "trulydeluxe.com"] [uri "/wp-login.php"] [unique_id "apPkINRh6OewFvqQpDlvlQABiE0"], referer: https://trulydeluxe.com/wp-login.php
[Sun Aug 30 03:04:48.839863 2026] [authz_core:error] [pid 491656:tid 491866] [client 216.73.216.128:51719] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:48.840312 2026] [authz_core:error] [pid 491656:tid 491866] [client 216.73.216.128:51719] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:48.858283 2026] [security2:error] [pid 488669:tid 488843] [client 20.48.250.41:53278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/term.php"] [unique_id "apPkINRh6OewFvqQpDlvmwAAAS4"]
[Sun Aug 30 03:04:48.871214 2026] [security2:error] [pid 491656:tid 491907] [client 20.220.204.93:28955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/click.php"] [unique_id "apPkIIvX_L6VjdbvkkSkKAAAAw0"]
[Sun Aug 30 03:04:48.872462 2026] [core:alert] [pid 491656:tid 491743] [remote 69.171.231.25:57610] /home3/lordrcan/public_html/.htaccess: without matching section
[Sun Aug 30 03:04:48.899591 2026] [authz_core:error] [pid 488669:tid 488931] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus%2Fdrivers
[Sun Aug 30 03:04:48.900050 2026] [authz_core:error] [pid 488669:tid 488931] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus%2Fdrivers
[Sun Aug 30 03:04:48.923351 2026] [security2:error] [pid 492549:tid 492773] [client 20.220.204.93:64356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/logs1.php"] [unique_id "apPkIDqFvOdCFO2AmwpDSAAAA_0"]
[Sun Aug 30 03:04:48.937685 2026] [security2:error] [pid 492549:tid 492720] [client 20.220.10.235:24493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/is.php"] [unique_id "apPkIDqFvOdCFO2AmwpDSgAAA8g"]
[Sun Aug 30 03:04:48.959551 2026] [authz_core:error] [pid 488669:tid 488912] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:48.959903 2026] [authz_core:error] [pid 488669:tid 488912] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:48.969549 2026] [security2:error] [pid 491656:tid 491869] [client 20.196.209.81:7964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/wp-links-opml.php"] [unique_id "apPkIIvX_L6VjdbvkkSkVAAAAuc"]
[Sun Aug 30 03:04:48.985453 2026] [security2:error] [pid 491656:tid 491906] [client 68.155.159.216:60008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apPkIIvX_L6VjdbvkkSkXgAAAww"]
[Sun Aug 30 03:04:48.990595 2026] [security2:error] [pid 492549:tid 492795] [client 20.48.250.41:53301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/aaa.php"] [unique_id "apPkIDqFvOdCFO2AmwpDXwAABBM"]
[Sun Aug 30 03:04:49.009023 2026] [authz_core:error] [pid 488669:tid 488817] [client 66.249.66.37:47381] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:49.009420 2026] [authz_core:error] [pid 488669:tid 488817] [client 66.249.66.37:47381] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:49.016462 2026] [security2:error] [pid 492549:tid 492684] [client 20.104.18.15:31626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/dk.php"] [unique_id "apPkITqFvOdCFO2AmwpDZQAAA6Q"]
[Sun Aug 30 03:04:49.017764 2026] [security2:error] [pid 491656:tid 491877] [client 20.104.50.220:51631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/Unknown45.php"] [unique_id "apPkIYvX_L6VjdbvkkSkbQAAAu8"]
[Sun Aug 30 03:04:49.023059 2026] [security2:error] [pid 492549:tid 492716] [client 20.48.251.3:54833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/zaza.php"] [unique_id "apPkITqFvOdCFO2AmwpDZgAAA8Q"]
[Sun Aug 30 03:04:49.041170 2026] [security2:error] [pid 491656:tid 491889] [client 20.104.50.220:62008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/zer0.php"] [unique_id "apPkIYvX_L6VjdbvkkSkewAAAvs"]
[Sun Aug 30 03:04:49.069089 2026] [security2:error] [pid 491656:tid 491795] [client 20.48.251.3:7099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/sale.php"] [unique_id "apPkIYvX_L6VjdbvkkSkiwAAAp0"]
[Sun Aug 30 03:04:49.072255 2026] [security2:error] [pid 488669:tid 488869] [client 20.220.10.235:24523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/od.php"] [unique_id "apPkIdRh6OewFvqQpDlv7gAAAUg"]
[Sun Aug 30 03:04:49.074615 2026] [security2:error] [pid 491656:tid 491909] [client 20.48.251.3:64434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/radio.php"] [unique_id "apPkIYvX_L6VjdbvkkSkkAAAAw8"]
[Sun Aug 30 03:04:49.079288 2026] [security2:error] [pid 488669:tid 488845] [client 178.16.55.109:58888] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "calchampsoccer.org"] [uri "/index.php"] [unique_id "apPkIdRh6OewFvqQpDlv8gAAATA"]
[Sun Aug 30 03:04:49.083798 2026] [security2:error] [pid 488669:tid 488874] [client 20.151.200.44:46995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/ls.php"] [unique_id "apPkIdRh6OewFvqQpDlv9AAAAU0"]
[Sun Aug 30 03:04:49.084756 2026] [security2:error] [pid 488669:tid 488851] [client 20.48.251.3:55699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/87.php"] [unique_id "apPkIdRh6OewFvqQpDlv9QAAATY"]
[Sun Aug 30 03:04:49.086559 2026] [security2:error] [pid 488669:tid 488816] [client 20.48.251.3:59075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/hochladen.form.php"] [unique_id "apPkIdRh6OewFvqQpDlv-QAAARM"]
[Sun Aug 30 03:04:49.091210 2026] [security2:error] [pid 491656:tid 491817] [client 40.83.93.50:8346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/classsmtps.php"] [unique_id "apPkIYvX_L6VjdbvkkSkmgAAArM"]
[Sun Aug 30 03:04:49.101571 2026] [security2:error] [pid 491656:tid 491848] [client 34.15.145.202:43448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/mail/phpinfo.php"] [unique_id "apPkIYvX_L6VjdbvkkSkngAAAtI"]
[Sun Aug 30 03:04:49.124698 2026] [security2:error] [pid 492549:tid 492797] [client 20.220.204.93:64999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/inege.php"] [unique_id "apPkITqFvOdCFO2AmwpDkAAABBU"]
[Sun Aug 30 03:04:49.127615 2026] [security2:error] [pid 492549:tid 492698] [client 136.92.30.49:43148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/info.php"] [unique_id "apPkITqFvOdCFO2AmwpDkgAAA7I"]
[Sun Aug 30 03:04:49.155210 2026] [security2:error] [pid 492549:tid 492736] [client 20.151.200.44:37886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/ssh3ll.php"] [unique_id "apPkITqFvOdCFO2AmwpDoAAAA9g"]
[Sun Aug 30 03:04:49.177393 2026] [security2:error] [pid 492549:tid 492765] [client 20.104.18.15:33744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/ops.php"] [unique_id "apPkITqFvOdCFO2AmwpDpwAAA_U"]
[Sun Aug 30 03:04:49.183879 2026] [security2:error] [pid 492549:tid 492787] [client 20.48.250.41:53374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/xsox.php"] [unique_id "apPkITqFvOdCFO2AmwpDqAAABAs"]
[Sun Aug 30 03:04:49.193367 2026] [security2:error] [pid 492549:tid 492715] [client 20.151.200.44:58835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/ls.php"] [unique_id "apPkITqFvOdCFO2AmwpDsAAAA8M"]
[Sun Aug 30 03:04:49.198559 2026] [security2:error] [pid 491656:tid 491918] [client 20.104.50.220:62785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/mia.php"] [unique_id "apPkIYvX_L6VjdbvkkSk1wAAAxg"]
[Sun Aug 30 03:04:49.205591 2026] [security2:error] [pid 492549:tid 492728] [client 20.48.251.3:44212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/zaza.php"] [unique_id "apPkITqFvOdCFO2AmwpDtwAAA9A"]
[Sun Aug 30 03:04:49.220303 2026] [security2:error] [pid 488669:tid 488834] [client 20.220.10.235:24491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/wp-the.php"] [unique_id "apPkIdRh6OewFvqQpDlwNwAAASU"]
[Sun Aug 30 03:04:49.228200 2026] [security2:error] [pid 491656:tid 491814] [client 20.220.10.235:49123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/pk.php"] [unique_id "apPkIYvX_L6VjdbvkkSk4wAAArA"]
[Sun Aug 30 03:04:49.252965 2026] [security2:error] [pid 492549:tid 492789] [client 20.104.50.220:33338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/sllolx.php"] [unique_id "apPkITqFvOdCFO2AmwpDzAAABA0"]
[Sun Aug 30 03:04:49.253103 2026] [security2:error] [pid 488669:tid 488820] [client 20.104.18.15:9111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/wp-content/k.php"] [unique_id "apPkIdRh6OewFvqQpDlwSAAAARc"]
[Sun Aug 30 03:04:49.292172 2026] [security2:error] [pid 488669:tid 488858] [client 20.220.204.93:64292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/wp-link10.php"] [unique_id "apPkIdRh6OewFvqQpDlwXwAAAT0"]
[Sun Aug 30 03:04:49.292182 2026] [security2:error] [pid 488669:tid 488920] [client 20.220.10.235:33802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/qi.php"] [unique_id "apPkIdRh6OewFvqQpDlwYAAAAXs"]
[Sun Aug 30 03:04:49.292553 2026] [security2:error] [pid 492549:tid 492774] [client 114.119.128.6:39365] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "1stsourcesecurity.com"] [uri "/request-service/"] [unique_id "apPkITqFvOdCFO2AmwpD2wAAA_4"], referer: https://1stsourcesecurity.com/services/
[Sun Aug 30 03:04:49.293316 2026] [security2:error] [pid 491656:tid 491871] [client 20.104.50.220:46623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/index8.php"] [unique_id "apPkIYvX_L6VjdbvkkSlFgAAAuk"]
[Sun Aug 30 03:04:49.312372 2026] [security2:error] [pid 491656:tid 491889] [client 20.197.61.180:14772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/users.php"] [unique_id "apPkIYvX_L6VjdbvkkSlLQAAAvs"]
[Sun Aug 30 03:04:49.341829 2026] [security2:error] [pid 488669:tid 488928] [client 20.48.251.3:55479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/25.php"] [unique_id "apPkIdRh6OewFvqQpDlwdAAAAYM"]
[Sun Aug 30 03:04:49.348724 2026] [security2:error] [pid 488669:tid 488827] [client 20.220.10.235:24489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/wt.php"] [unique_id "apPkIdRh6OewFvqQpDlweQAAAR4"]
[Sun Aug 30 03:04:49.350900 2026] [authz_core:error] [pid 488669:tid 488820] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:49.351315 2026] [authz_core:error] [pid 488669:tid 488820] [client 74.7.227.8:46534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:49.379809 2026] [security2:error] [pid 491656:tid 491889] [client 20.48.250.41:53271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/lkui.php"] [unique_id "apPkIYvX_L6VjdbvkkSlSgAAAvs"]
[Sun Aug 30 03:04:49.402888 2026] [security2:error] [pid 492549:tid 492787] [client 20.196.209.81:7588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/wp-load.php"] [unique_id "apPkITqFvOdCFO2AmwpD8wAABAs"]
[Sun Aug 30 03:04:49.415497 2026] [security2:error] [pid 491656:tid 491911] [client 68.155.159.216:60576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-content/index.php"] [unique_id "apPkIYvX_L6VjdbvkkSlZgAAAxE"]
[Sun Aug 30 03:04:49.422373 2026] [authz_core:error] [pid 492549:tid 492726] [client 66.249.66.68:45603] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:49.422773 2026] [authz_core:error] [pid 492549:tid 492726] [client 66.249.66.68:45603] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:49.426227 2026] [security2:error] [pid 491656:tid 491805] [client 20.220.10.235:33830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/px.php"] [unique_id "apPkIYvX_L6VjdbvkkSlbgAAAqc"]
[Sun Aug 30 03:04:49.430434 2026] [security2:error] [pid 491656:tid 491912] [client 20.104.50.220:5939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/item.php"] [unique_id "apPkIYvX_L6VjdbvkkSlcgAAAxI"]
[Sun Aug 30 03:04:49.433082 2026] [security2:error] [pid 492549:tid 492752] [client 20.220.204.93:64903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/ww.php"] [unique_id "apPkITqFvOdCFO2AmwpD-AAAA-g"]
[Sun Aug 30 03:04:49.437093 2026] [authz_core:error] [pid 488669:tid 488827] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:49.437358 2026] [authz_core:error] [pid 488669:tid 488827] [client 74.7.243.204:48278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:49.440083 2026] [security2:error] [pid 491656:tid 491893] [client 68.155.159.216:52637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/atomlib.php"] [unique_id "apPkIYvX_L6VjdbvkkSldwAAAv8"]
[Sun Aug 30 03:04:49.457705 2026] [security2:error] [pid 491656:tid 491825] [client 20.220.10.235:49088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/ft.php"] [unique_id "apPkIYvX_L6VjdbvkkSlhQAAArs"]
[Sun Aug 30 03:04:49.479903 2026] [security2:error] [pid 491656:tid 491891] [client 20.220.10.235:24460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/im.php"] [unique_id "apPkIYvX_L6VjdbvkkSlkwAAAv0"]
[Sun Aug 30 03:04:49.539226 2026] [security2:error] [pid 491656:tid 491820] [client 20.48.250.41:53318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apPkIYvX_L6VjdbvkkSlxAAAArY"]
[Sun Aug 30 03:04:49.555877 2026] [security2:error] [pid 491656:tid 491909] [client 20.220.10.235:33684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/is.php"] [unique_id "apPkIYvX_L6VjdbvkkSlyQAAAw8"]
[Sun Aug 30 03:04:49.557376 2026] [security2:error] [pid 488669:tid 488902] [client 136.92.30.49:43164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/php.php"] [unique_id "apPkIdRh6OewFvqQpDlwzAAAAWk"]
[Sun Aug 30 03:04:49.564414 2026] [security2:error] [pid 488669:tid 488886] [client 20.104.50.220:62785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/pah.php"] [unique_id "apPkIdRh6OewFvqQpDlw1QAAAVk"]
[Sun Aug 30 03:04:49.579791 2026] [security2:error] [pid 488669:tid 488840] [client 20.220.204.93:63818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/w1px.php"] [unique_id "apPkIdRh6OewFvqQpDlw3QAAASs"]
[Sun Aug 30 03:04:49.583070 2026] [security2:error] [pid 492549:tid 492725] [client 40.83.93.50:9136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/install.php"] [unique_id "apPkITqFvOdCFO2AmwpEBgAAA80"]
[Sun Aug 30 03:04:49.588075 2026] [security2:error] [pid 491656:tid 491915] [client 20.220.10.235:49122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/wp-ver.php"] [unique_id "apPkIYvX_L6VjdbvkkSl3wAAAxU"]
[Sun Aug 30 03:04:49.600807 2026] [security2:error] [pid 492549:tid 492729] [client 20.48.251.3:44344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/4563.php"] [unique_id "apPkITqFvOdCFO2AmwpECgAAA9E"]
[Sun Aug 30 03:04:49.609257 2026] [security2:error] [pid 492549:tid 492748] [client 20.104.50.220:31897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-admin/maint/mailer.php.php"] [unique_id "apPkITqFvOdCFO2AmwpECwAAA-Q"]
[Sun Aug 30 03:04:49.613673 2026] [security2:error] [pid 491656:tid 491817] [client 20.220.10.235:24568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/file.php"] [unique_id "apPkIYvX_L6VjdbvkkSl7AAAArM"]
[Sun Aug 30 03:04:49.656479 2026] [authz_core:error] [pid 491656:tid 491912] [client 216.73.216.128:13201] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:49.656780 2026] [authz_core:error] [pid 491656:tid 491912] [client 216.73.216.128:13201] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:49.685008 2026] [security2:error] [pid 488669:tid 488929] [client 20.220.10.235:33826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/od.php"] [unique_id "apPkIdRh6OewFvqQpDlxCQAAAYQ"]
[Sun Aug 30 03:04:49.701114 2026] [security2:error] [pid 491656:tid 491798] [client 34.15.145.202:43456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/cpanel/phpinfo.php"] [unique_id "apPkIYvX_L6VjdbvkkSmNgAAAqA"]
[Sun Aug 30 03:04:49.719413 2026] [security2:error] [pid 491656:tid 491827] [client 20.220.10.235:49636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/ah24.php"] [unique_id "apPkIYvX_L6VjdbvkkSmPwAAAr0"]
[Sun Aug 30 03:04:49.721947 2026] [security2:error] [pid 488669:tid 488854] [client 20.220.204.93:64362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/to.php"] [unique_id "apPkIdRh6OewFvqQpDlxFQAAATk"]
[Sun Aug 30 03:04:49.724054 2026] [security2:error] [pid 491656:tid 491916] [client 158.23.147.79:63252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apPkIYvX_L6VjdbvkkSmQwAAAxY"]
[Sun Aug 30 03:04:49.730520 2026] [security2:error] [pid 488669:tid 488863] [client 20.48.250.41:53371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/motu.php"] [unique_id "apPkIdRh6OewFvqQpDlxGAAAAUI"]
[Sun Aug 30 03:04:49.738080 2026] [security2:error] [pid 491656:tid 491886] [client 20.48.251.3:7097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/xa.php"] [unique_id "apPkIYvX_L6VjdbvkkSmSgAAAvg"]
[Sun Aug 30 03:04:49.740108 2026] [authz_core:error] [pid 488669:tid 488921] [client 66.249.66.72:39464] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:49.740383 2026] [authz_core:error] [pid 488669:tid 488921] [client 66.249.66.72:39464] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:49.745118 2026] [security2:error] [pid 491656:tid 491847] [client 20.220.10.235:24461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/ca.php"] [unique_id "apPkIYvX_L6VjdbvkkSmTQAAAtE"]
[Sun Aug 30 03:04:49.795737 2026] [security2:error] [pid 491656:tid 491881] [client 20.196.209.81:12330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/wp-settings.php"] [unique_id "apPkIYvX_L6VjdbvkkSmZQAAAvM"]
[Sun Aug 30 03:04:49.827747 2026] [security2:error] [pid 491656:tid 491834] [client 20.220.10.235:33809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/wp-the.php"] [unique_id "apPkIYvX_L6VjdbvkkSmbgAAAsQ"]
[Sun Aug 30 03:04:49.857778 2026] [security2:error] [pid 491656:tid 491902] [client 20.220.10.235:49114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPkIYvX_L6VjdbvkkSmggAAAwg"]
[Sun Aug 30 03:04:49.875702 2026] [security2:error] [pid 491656:tid 491882] [client 20.220.10.235:24558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/pb.php"] [unique_id "apPkIYvX_L6VjdbvkkSmiwAAAvQ"]
[Sun Aug 30 03:04:49.880221 2026] [security2:error] [pid 491656:tid 491825] [client 20.220.204.93:43248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/ms.php"] [unique_id "apPkIYvX_L6VjdbvkkSmjAAAArs"]
[Sun Aug 30 03:04:49.907998 2026] [security2:error] [pid 491656:tid 491848] [client 20.48.250.41:53248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/Ov-Simple1.php"] [unique_id "apPkIYvX_L6VjdbvkkSmmgAAAtI"]
[Sun Aug 30 03:04:49.910166 2026] [authz_core:error] [pid 492549:tid 492695] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:49.910632 2026] [authz_core:error] [pid 492549:tid 492695] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:49.923323 2026] [security2:error] [pid 492549:tid 492714] [client 20.220.204.93:64342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/thui.php"] [unique_id "apPkITqFvOdCFO2AmwpEMAAAA8I"]
[Sun Aug 30 03:04:49.963040 2026] [security2:error] [pid 491656:tid 491854] [client 20.220.10.235:33703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/wt.php"] [unique_id "apPkIYvX_L6VjdbvkkSmsAAAAtg"]
[Sun Aug 30 03:04:49.967260 2026] [authz_core:error] [pid 491656:tid 491808] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:49.967559 2026] [authz_core:error] [pid 491656:tid 491808] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:49.988424 2026] [security2:error] [pid 491656:tid 491805] [client 136.92.30.49:43180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/i.php"] [unique_id "apPkIYvX_L6VjdbvkkSmtwAAAqc"]
[Sun Aug 30 03:04:49.988922 2026] [security2:error] [pid 491656:tid 491803] [client 20.220.10.235:49147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.nateofamerican.com"] [uri "/waf.php"] [unique_id "apPkIYvX_L6VjdbvkkSmuAAAAqU"]
[Sun Aug 30 03:04:50.014357 2026] [security2:error] [pid 491656:tid 491875] [client 20.220.10.235:24537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/pk.php"] [unique_id "apPkIovX_L6VjdbvkkSmwgAAAu0"]
[Sun Aug 30 03:04:50.029210 2026] [security2:error] [pid 491656:tid 491843] [client 20.197.61.180:14776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/wp-cron.php"] [unique_id "apPkIovX_L6VjdbvkkSmywAAAs0"]
[Sun Aug 30 03:04:50.081021 2026] [security2:error] [pid 492549:tid 492693] [client 40.83.93.50:8603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/wp.php"] [unique_id "apPkIjqFvOdCFO2AmwpEagAAA60"]
[Sun Aug 30 03:04:50.086773 2026] [security2:error] [pid 492549:tid 492740] [client 20.220.204.93:63856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/Jcrop.php"] [unique_id "apPkIjqFvOdCFO2AmwpEbQAAA9w"]
[Sun Aug 30 03:04:50.089373 2026] [security2:error] [pid 492549:tid 492696] [client 68.155.159.216:59964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apPkIjqFvOdCFO2AmwpEcQAAA7A"]
[Sun Aug 30 03:04:50.089601 2026] [security2:error] [pid 492549:tid 492745] [client 20.220.10.235:33853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/im.php"] [unique_id "apPkIjqFvOdCFO2AmwpEcwAAA-E"]
[Sun Aug 30 03:04:50.100000 2026] [security2:error] [pid 491656:tid 491888] [client 31.40.195.113:15129] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "gregrickard.com"] [uri "/wp-comments-post.php"] [unique_id "apPkIovX_L6VjdbvkkSmxwAAAvo"], referer: https://gregrickard.com/2021/05/30/rainbow-connection-w-harmony/
[Sun Aug 30 03:04:50.108665 2026] [security2:error] [pid 492549:tid 492746] [client 20.48.250.41:53198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/wp-blogs.php"] [unique_id "apPkIjqFvOdCFO2AmwpEegAAA-I"]
[Sun Aug 30 03:04:50.117993 2026] [authz_core:error] [pid 492549:tid 492799] [client 66.249.66.72:45694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:50.118270 2026] [authz_core:error] [pid 492549:tid 492799] [client 66.249.66.72:45694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:50.153057 2026] [security2:error] [pid 492549:tid 492792] [client 20.220.10.235:24543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/ft.php"] [unique_id "apPkIjqFvOdCFO2AmwpEogAABBA"]
[Sun Aug 30 03:04:50.153585 2026] [security2:error] [pid 492549:tid 492731] [client 20.104.18.15:31584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/ta.php"] [unique_id "apPkIjqFvOdCFO2AmwpEoAAAA9M"]
[Sun Aug 30 03:04:50.160901 2026] [security2:error] [pid 492549:tid 492712] [client 20.48.251.3:54801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/u88.php"] [unique_id "apPkIjqFvOdCFO2AmwpEpgAAA8A"]
[Sun Aug 30 03:04:50.166569 2026] [security2:error] [pid 492549:tid 492781] [client 20.104.50.220:42045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/vinus.php"] [unique_id "apPkIjqFvOdCFO2AmwpErwAABAU"]
[Sun Aug 30 03:04:50.193376 2026] [security2:error] [pid 491656:tid 491889] [client 20.196.209.81:12288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/themes/wp-signup.php"] [unique_id "apPkIovX_L6VjdbvkkSm_AAAAvs"]
[Sun Aug 30 03:04:50.206458 2026] [security2:error] [pid 492549:tid 492792] [client 20.104.50.220:61689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/63dor.php"] [unique_id "apPkIjqFvOdCFO2AmwpExgAABBA"]
[Sun Aug 30 03:04:50.207698 2026] [authz_core:error] [pid 492549:tid 492696] [client 216.73.216.128:9188] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:50.208115 2026] [authz_core:error] [pid 492549:tid 492696] [client 216.73.216.128:9188] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:50.217592 2026] [security2:error] [pid 492549:tid 492801] [client 20.48.251.3:55696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/plss3.php"] [unique_id "apPkIjqFvOdCFO2AmwpEzgAABBk"]
[Sun Aug 30 03:04:50.218745 2026] [security2:error] [pid 492549:tid 492788] [client 20.220.10.235:33669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/file.php"] [unique_id "apPkIjqFvOdCFO2AmwpE0AAABAw"]
[Sun Aug 30 03:04:50.225997 2026] [security2:error] [pid 492549:tid 492781] [client 20.48.251.3:51530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/debuggen.php"] [unique_id "apPkIjqFvOdCFO2AmwpE0wAABAU"]
[Sun Aug 30 03:04:50.233911 2026] [security2:error] [pid 492549:tid 492780] [client 20.220.204.93:64982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/ws58.php"] [unique_id "apPkIjqFvOdCFO2AmwpE1AAABAQ"]
[Sun Aug 30 03:04:50.239442 2026] [security2:error] [pid 491656:tid 491861] [client 20.48.251.3:64475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/wp-class.php"] [unique_id "apPkIovX_L6VjdbvkkSnCAAAAt8"]
[Sun Aug 30 03:04:50.279042 2026] [authz_core:error] [pid 492549:tid 492718] [client 66.249.66.195:52691] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:50.279325 2026] [authz_core:error] [pid 492549:tid 492718] [client 66.249.66.195:52691] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:50.288699 2026] [security2:error] [pid 491656:tid 491840] [client 20.220.10.235:24451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/wp-ver.php"] [unique_id "apPkIovX_L6VjdbvkkSnIwAAAso"]
[Sun Aug 30 03:04:50.300378 2026] [security2:error] [pid 492549:tid 492704] [client 20.220.204.93:40426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/zxekqlxb.php"] [unique_id "apPkIjqFvOdCFO2AmwpE5gAAA7g"]
[Sun Aug 30 03:04:50.308094 2026] [security2:error] [pid 492549:tid 492782] [client 34.15.145.202:43470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/hosting/phpinfo.php"] [unique_id "apPkIjqFvOdCFO2AmwpE6wAABAY"]
[Sun Aug 30 03:04:50.313846 2026] [security2:error] [pid 492549:tid 492703] [client 20.48.250.41:53298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/mini.php"] [unique_id "apPkIjqFvOdCFO2AmwpE8QAAA7c"]
[Sun Aug 30 03:04:50.338532 2026] [security2:error] [pid 492549:tid 492766] [client 20.48.251.3:23425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/u88.php"] [unique_id "apPkIjqFvOdCFO2AmwpE_gAAA_Y"]
[Sun Aug 30 03:04:50.347745 2026] [security2:error] [pid 492549:tid 492773] [client 20.220.10.235:33671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/ca.php"] [unique_id "apPkIjqFvOdCFO2AmwpFAwAAA_0"]
[Sun Aug 30 03:04:50.360321 2026] [security2:error] [pid 492549:tid 492794] [client 20.104.18.15:33023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/coffexium.php"] [unique_id "apPkIjqFvOdCFO2AmwpFCwAABBI"]
[Sun Aug 30 03:04:50.364188 2026] [security2:error] [pid 492549:tid 492684] [client 20.104.50.220:62791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/qwe.php"] [unique_id "apPkIjqFvOdCFO2AmwpFDwAAA6Q"]
[Sun Aug 30 03:04:50.380516 2026] [security2:error] [pid 492549:tid 492767] [client 20.220.204.93:65010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/xs.php"] [unique_id "apPkIjqFvOdCFO2AmwpFFgAAA_c"]
[Sun Aug 30 03:04:50.386269 2026] [authz_core:error] [pid 492549:tid 492771] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:50.386727 2026] [authz_core:error] [pid 492549:tid 492771] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:50.405331 2026] [security2:error] [pid 491656:tid 491904] [client 20.104.50.220:32873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/small.php"] [unique_id "apPkIovX_L6VjdbvkkSnWgAAAwo"]
[Sun Aug 30 03:04:50.419177 2026] [security2:error] [pid 492549:tid 492739] [client 20.220.10.235:24512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/ah24.php"] [unique_id "apPkIjqFvOdCFO2AmwpFJAAAA9s"]
[Sun Aug 30 03:04:50.423881 2026] [authz_core:error] [pid 491656:tid 491835] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:50.424173 2026] [authz_core:error] [pid 491656:tid 491835] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:50.428699 2026] [security2:error] [pid 492549:tid 492745] [client 136.92.30.49:43190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/pi.php"] [unique_id "apPkIjqFvOdCFO2AmwpFLAAAA-E"]
[Sun Aug 30 03:04:50.429784 2026] [security2:error] [pid 492549:tid 492685] [client 20.104.50.220:47093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/index9.php"] [unique_id "apPkIjqFvOdCFO2AmwpFLQAAA6U"]
[Sun Aug 30 03:04:50.474971 2026] [security2:error] [pid 491656:tid 491880] [client 20.220.10.235:33683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/pb.php"] [unique_id "apPkIovX_L6VjdbvkkSnegAAAvI"]
[Sun Aug 30 03:04:50.498396 2026] [security2:error] [pid 492549:tid 492733] [client 20.48.251.3:55548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/nlnub.php"] [unique_id "apPkIjqFvOdCFO2AmwpFTQAAA9U"]
[Sun Aug 30 03:04:50.510748 2026] [security2:error] [pid 492549:tid 492746] [client 20.220.204.93:64969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/zu.php"] [unique_id "apPkIjqFvOdCFO2AmwpFVAAAA-I"]
[Sun Aug 30 03:04:50.540119 2026] [security2:error] [pid 492549:tid 492726] [client 20.48.250.41:53254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/amp.php"] [unique_id "apPkIjqFvOdCFO2AmwpFYAAAA84"]
[Sun Aug 30 03:04:50.542455 2026] [security2:error] [pid 491656:tid 491849] [client 68.155.159.216:54758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/lv.php"] [unique_id "apPkIovX_L6VjdbvkkSnmAAAAtM"]
[Sun Aug 30 03:04:50.548749 2026] [security2:error] [pid 492549:tid 492698] [client 20.151.200.44:37848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/motu.php"] [unique_id "apPkIjqFvOdCFO2AmwpFYQAAA7I"]
[Sun Aug 30 03:04:50.552429 2026] [security2:error] [pid 491656:tid 491857] [client 20.220.204.93:20042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/init.php"] [unique_id "apPkIovX_L6VjdbvkkSnmgAAAts"]
[Sun Aug 30 03:04:50.557108 2026] [security2:error] [pid 492549:tid 492704] [client 20.220.10.235:24388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPkIjqFvOdCFO2AmwpFYwAAA7g"]
[Sun Aug 30 03:04:50.570450 2026] [authz_core:error] [pid 491656:tid 491824] [client 216.73.216.128:51719] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:50.570720 2026] [authz_core:error] [pid 491656:tid 491824] [client 216.73.216.128:51719] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:50.571960 2026] [security2:error] [pid 492549:tid 492727] [client 40.83.93.50:8592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/error.php"] [unique_id "apPkIjqFvOdCFO2AmwpFbAAAA88"]
[Sun Aug 30 03:04:50.584969 2026] [security2:error] [pid 491656:tid 491869] [client 20.104.50.220:5506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/plugins/Cache/footer.php"] [unique_id "apPkIovX_L6VjdbvkkSnpwAAAuc"]
[Sun Aug 30 03:04:50.585546 2026] [security2:error] [pid 491656:tid 491810] [client 20.196.209.81:12310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/updraft/about.php"] [unique_id "apPkIovX_L6VjdbvkkSnqAAAAqw"]
[Sun Aug 30 03:04:50.598925 2026] [security2:error] [pid 491656:tid 491794] [client 68.155.159.216:60586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/about/function.php"] [unique_id "apPkIovX_L6VjdbvkkSnqgAAApw"]
[Sun Aug 30 03:04:50.600844 2026] [security2:error] [pid 491656:tid 491859] [client 20.220.10.235:33804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/pk.php"] [unique_id "apPkIovX_L6VjdbvkkSnqwAAAt0"]
[Sun Aug 30 03:04:50.648674 2026] [security2:error] [pid 491656:tid 491906] [client 20.220.204.93:64313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/lanka.php"] [unique_id "apPkIovX_L6VjdbvkkSnvgAAAww"]
[Sun Aug 30 03:04:50.670453 2026] [security2:error] [pid 492549:tid 492758] [client 20.48.250.41:53190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/cc13.php"] [unique_id "apPkIjqFvOdCFO2AmwpFkQAAA-4"]
[Sun Aug 30 03:04:50.676573 2026] [security2:error] [pid 491656:tid 491809] [client 20.104.18.15:9058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/os.php"] [unique_id "apPkIovX_L6VjdbvkkSnyQAAAqs"]
[Sun Aug 30 03:04:50.680145 2026] [authz_core:error] [pid 491656:tid 491902] [client 66.249.66.42:35619] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:50.680584 2026] [authz_core:error] [pid 491656:tid 491902] [client 66.249.66.42:35619] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:50.687204 2026] [security2:error] [pid 492549:tid 492695] [client 20.220.10.235:24557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.memariestyle.com"] [uri "/waf.php"] [unique_id "apPkIjqFvOdCFO2AmwpFlwAAA68"]
[Sun Aug 30 03:04:50.722992 2026] [security2:error] [pid 492549:tid 492746] [client 20.151.200.44:47084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/css/000.php"] [unique_id "apPkIjqFvOdCFO2AmwpFpAAAA-I"]
[Sun Aug 30 03:04:50.726941 2026] [security2:error] [pid 492549:tid 492734] [client 20.104.50.220:29142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/webshell.php"] [unique_id "apPkIjqFvOdCFO2AmwpFpgAAA9Y"]
[Sun Aug 30 03:04:50.727046 2026] [security2:error] [pid 492549:tid 492794] [client 20.220.10.235:33848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/ft.php"] [unique_id "apPkIjqFvOdCFO2AmwpFqAAABBI"]
[Sun Aug 30 03:04:50.756385 2026] [security2:error] [pid 491656:tid 491799] [client 20.197.61.180:9165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/wp-links-opml.php"] [unique_id "apPkIovX_L6VjdbvkkSn3QAAAqE"]
[Sun Aug 30 03:04:50.761866 2026] [security2:error] [pid 492549:tid 492718] [client 20.104.50.220:32566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-admin/css/mailer.php.php"] [unique_id "apPkIjqFvOdCFO2AmwpFvAAAA8Y"]
[Sun Aug 30 03:04:50.817705 2026] [security2:error] [pid 492549:tid 492777] [client 20.220.204.93:46964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/term.php"] [unique_id "apPkIjqFvOdCFO2AmwpFzAAABAE"]
[Sun Aug 30 03:04:50.826381 2026] [security2:error] [pid 492549:tid 492691] [client 20.220.204.93:64331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/gettest.php"] [unique_id "apPkIjqFvOdCFO2AmwpFzgAAA6s"]
[Sun Aug 30 03:04:50.827847 2026] [security2:error] [pid 491656:tid 491848] [client 20.48.251.3:44413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/cp2.php"] [unique_id "apPkIovX_L6VjdbvkkSn8wAAAtI"]
[Sun Aug 30 03:04:50.858491 2026] [security2:error] [pid 491656:tid 491911] [client 20.220.10.235:33738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/wp-ver.php"] [unique_id "apPkIovX_L6VjdbvkkSoBQAAAxE"]
[Sun Aug 30 03:04:50.863237 2026] [security2:error] [pid 492549:tid 492774] [client 136.92.30.49:43192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/pinfo.php"] [unique_id "apPkIjqFvOdCFO2AmwpF1gAAA_4"]
[Sun Aug 30 03:04:50.889779 2026] [security2:error] [pid 492549:tid 492732] [client 20.48.250.41:53304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/aa.php"] [unique_id "apPkIjqFvOdCFO2AmwpF5AAAA9Q"]
[Sun Aug 30 03:04:50.891487 2026] [authz_core:error] [pid 492549:tid 492742] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:50.891811 2026] [authz_core:error] [pid 492549:tid 492742] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:50.915991 2026] [security2:error] [pid 492549:tid 492712] [client 34.15.145.202:43476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/webmail/phpinfo.php"] [unique_id "apPkIjqFvOdCFO2AmwpF6wAAA8A"]
[Sun Aug 30 03:04:50.919066 2026] [authz_core:error] [pid 491656:tid 491812] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:50.919528 2026] [authz_core:error] [pid 491656:tid 491812] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:50.927693 2026] [authz_core:error] [pid 491656:tid 491909] [client 66.249.66.65:43318] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:50.928130 2026] [authz_core:error] [pid 491656:tid 491909] [client 66.249.66.65:43318] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:50.958334 2026] [security2:error] [pid 492549:tid 492777] [client 20.220.204.93:65007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/35.php"] [unique_id "apPkIjqFvOdCFO2AmwpF9gAABAE"]
[Sun Aug 30 03:04:50.977163 2026] [security2:error] [pid 491656:tid 491857] [client 20.196.209.81:7566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/upgrade-temp-backup/min.php"] [unique_id "apPkIovX_L6VjdbvkkSoLgAAAts"]
[Sun Aug 30 03:04:50.991030 2026] [security2:error] [pid 492549:tid 492758] [client 34.15.141.119:55256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/phpinfo.php"] [unique_id "apPkIjqFvOdCFO2AmwpGAQAAA-4"]
[Sun Aug 30 03:04:50.993433 2026] [security2:error] [pid 492549:tid 492721] [client 20.151.200.44:58935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/css/000.php"] [unique_id "apPkIjqFvOdCFO2AmwpGBQAAA8k"]
[Sun Aug 30 03:04:50.997123 2026] [security2:error] [pid 492549:tid 492686] [client 20.220.10.235:33814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/ah24.php"] [unique_id "apPkIjqFvOdCFO2AmwpGBwAAA6Y"]
[Sun Aug 30 03:04:51.037127 2026] [security2:error] [pid 492549:tid 492803] [client 20.48.250.41:53189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/s1.php"] [unique_id "apPkIzqFvOdCFO2AmwpGHAAABBs"]
[Sun Aug 30 03:04:51.043751 2026] [security2:error] [pid 492549:tid 492772] [client 40.83.93.50:9093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/profile.php"] [unique_id "apPkIzqFvOdCFO2AmwpGIQAAA_w"]
[Sun Aug 30 03:04:51.068652 2026] [security2:error] [pid 491656:tid 491866] [client 158.23.147.79:62551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apPkI4vX_L6VjdbvkkSoSAAAAuQ"]
[Sun Aug 30 03:04:51.093769 2026] [security2:error] [pid 492549:tid 492807] [client 20.220.204.93:63848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/maraz.php"] [unique_id "apPkIzqFvOdCFO2AmwpGPAAABB8"]
[Sun Aug 30 03:04:51.109962 2026] [security2:error] [pid 492549:tid 492801] [client 20.48.251.3:7050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/ws61.php"] [unique_id "apPkIzqFvOdCFO2AmwpGRgAABBk"]
[Sun Aug 30 03:04:51.124829 2026] [security2:error] [pid 492549:tid 492768] [client 20.220.10.235:33839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPkIzqFvOdCFO2AmwpGTgAAA_g"]
[Sun Aug 30 03:04:51.166386 2026] [security2:error] [pid 491656:tid 491913] [client 20.48.250.41:53196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/0byte.php"] [unique_id "apPkI4vX_L6VjdbvkkSobAAAAxM"]
[Sun Aug 30 03:04:51.175292 2026] [security2:error] [pid 492549:tid 492738] [client 20.220.204.93:27117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/aaa.php"] [unique_id "apPkIzqFvOdCFO2AmwpGcQAAA9o"]
[Sun Aug 30 03:04:51.190979 2026] [authz_core:error] [pid 492549:tid 492771] [client 66.249.66.68:45603] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:51.191299 2026] [authz_core:error] [pid 492549:tid 492771] [client 66.249.66.68:45603] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:51.221367 2026] [security2:error] [pid 492549:tid 492791] [client 45.205.1.124:54777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.1.205.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaseroach.site"] [uri "/assets/plugins/file-uploader/server/php/index.php"] [unique_id "apPkIzqFvOdCFO2AmwpGjQAABA8"]
[Sun Aug 30 03:04:51.226284 2026] [security2:error] [pid 491656:tid 491816] [client 20.220.204.93:63184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/kbfr.php"] [unique_id "apPkI4vX_L6VjdbvkkSogAAAArI"]
[Sun Aug 30 03:04:51.254305 2026] [security2:error] [pid 491656:tid 491884] [client 20.220.10.235:33793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "troop678.basichoa.com"] [uri "/waf.php"] [unique_id "apPkI4vX_L6VjdbvkkSoiQAAAvY"]
[Sun Aug 30 03:04:51.302608 2026] [security2:error] [pid 492549:tid 492786] [client 136.92.30.49:43194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/test.php"] [unique_id "apPkIzqFvOdCFO2AmwpGwgAABAo"]
[Sun Aug 30 03:04:51.318918 2026] [security2:error] [pid 492549:tid 492781] [client 20.48.250.41:53370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/xr.php"] [unique_id "apPkIzqFvOdCFO2AmwpG0QAABAU"]
[Sun Aug 30 03:04:51.320794 2026] [security2:error] [pid 492549:tid 492747] [client 20.104.50.220:51627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/store.php"] [unique_id "apPkIzqFvOdCFO2AmwpG1AAAA-M"]
[Sun Aug 30 03:04:51.338183 2026] [authz_core:error] [pid 492549:tid 492732] [client 66.249.66.64:65460] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:51.338497 2026] [authz_core:error] [pid 492549:tid 492732] [client 66.249.66.64:65460] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:51.339927 2026] [security2:error] [pid 492549:tid 492701] [client 20.104.18.15:31661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/bo.php"] [unique_id "apPkIzqFvOdCFO2AmwpG5AAAA7U"]
[Sun Aug 30 03:04:51.354283 2026] [security2:error] [pid 492549:tid 492764] [client 20.48.251.3:52750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/aws.php"] [unique_id "apPkIzqFvOdCFO2AmwpG6wAAA_Q"]
[Sun Aug 30 03:04:51.361907 2026] [security2:error] [pid 491656:tid 491823] [client 68.155.159.216:59924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-content/languages/about.php"] [unique_id "apPkI4vX_L6VjdbvkkSotQAAArk"]
[Sun Aug 30 03:04:51.368010 2026] [security2:error] [pid 492549:tid 492782] [client 20.196.209.81:18703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/upgrade-temp-backup/pk.php"] [unique_id "apPkIzqFvOdCFO2AmwpG8gAABAY"]
[Sun Aug 30 03:04:51.371440 2026] [security2:error] [pid 492549:tid 492747] [client 20.104.50.220:61643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/dh.php"] [unique_id "apPkIzqFvOdCFO2AmwpG9QAAA-M"]
[Sun Aug 30 03:04:51.372239 2026] [security2:error] [pid 491656:tid 491824] [client 20.48.251.3:54834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/config/laravolt/css/index.php"] [unique_id "apPkI4vX_L6VjdbvkkSovAAAAro"]
[Sun Aug 30 03:04:51.381827 2026] [authz_core:error] [pid 492549:tid 492743] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:51.382198 2026] [authz_core:error] [pid 492549:tid 492743] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:51.386970 2026] [security2:error] [pid 491656:tid 491893] [client 158.23.147.79:62559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/file.php"] [unique_id "apPkI4vX_L6VjdbvkkSowgAAAv8"]
[Sun Aug 30 03:04:51.389939 2026] [authz_core:error] [pid 491656:tid 491917] [client 216.73.216.128:51719] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:51.390237 2026] [authz_core:error] [pid 491656:tid 491917] [client 216.73.216.128:51719] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:51.404710 2026] [security2:error] [pid 492549:tid 492786] [client 20.48.251.3:7406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/database.php"] [unique_id "apPkIzqFvOdCFO2AmwpHBAAABAo"]
[Sun Aug 30 03:04:51.407103 2026] [security2:error] [pid 492549:tid 492715] [client 20.151.200.44:37857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/wefile.php"] [unique_id "apPkIzqFvOdCFO2AmwpHBQAAA8M"]
[Sun Aug 30 03:04:51.409966 2026] [security2:error] [pid 492549:tid 492758] [client 20.48.251.3:22217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/pouhg.php"] [unique_id "apPkIzqFvOdCFO2AmwpHBgAAA-4"]
[Sun Aug 30 03:04:51.436142 2026] [authz_core:error] [pid 491656:tid 491832] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:51.436578 2026] [authz_core:error] [pid 491656:tid 491832] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:51.439044 2026] [security2:error] [pid 491656:tid 491833] [client 20.48.251.3:64392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/xza.php"] [unique_id "apPkI4vX_L6VjdbvkkSo2QAAAsM"]
[Sun Aug 30 03:04:51.476150 2026] [core:error] [pid 492549:tid 492796] [client 158.23.184.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:04:51.476168 2026] [core:error] [pid 492549:tid 492796] [client 158.23.184.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:04:51.478996 2026] [security2:error] [pid 491656:tid 491880] [client 20.220.204.93:64994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/wp-act.php"] [unique_id "apPkI4vX_L6VjdbvkkSo6wAAAvI"]
[Sun Aug 30 03:04:51.479010 2026] [security2:error] [pid 492549:tid 492686] [client 20.197.61.180:9180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/wp-load.php"] [unique_id "apPkIzqFvOdCFO2AmwpHMQAAA6Y"]
[Sun Aug 30 03:04:51.505956 2026] [security2:error] [pid 492549:tid 492777] [client 20.48.251.3:44224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/config/laravolt/css/index.php"] [unique_id "apPkIzqFvOdCFO2AmwpHPAAABAE"]
[Sun Aug 30 03:04:51.508237 2026] [security2:error] [pid 492549:tid 492685] [client 20.104.50.220:62801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/shell_finder.php"] [unique_id "apPkIzqFvOdCFO2AmwpHPQAAA6U"]
[Sun Aug 30 03:04:51.521325 2026] [security2:error] [pid 492549:tid 492767] [client 20.48.250.41:53324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/h02ugyh.php"] [unique_id "apPkIzqFvOdCFO2AmwpHRwAAA_c"]
[Sun Aug 30 03:04:51.525389 2026] [security2:error] [pid 492549:tid 492742] [client 34.15.145.202:43480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/smtp/phpinfo.php"] [unique_id "apPkIzqFvOdCFO2AmwpHSwAAA94"]
[Sun Aug 30 03:04:51.535832 2026] [security2:error] [pid 492549:tid 492796] [client 20.104.18.15:32961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/BDKR28WP.php"] [unique_id "apPkIzqFvOdCFO2AmwpHUQAABBQ"]
[Sun Aug 30 03:04:51.546450 2026] [security2:error] [pid 492549:tid 492745] [client 40.83.93.50:8357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/sql.php"] [unique_id "apPkIzqFvOdCFO2AmwpHVQAAA-E"]
[Sun Aug 30 03:04:51.560118 2026] [security2:error] [pid 492549:tid 492790] [client 20.104.50.220:33153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/style-js.php"] [unique_id "apPkIzqFvOdCFO2AmwpHWQAABA4"]
[Sun Aug 30 03:04:51.574540 2026] [security2:error] [pid 492549:tid 492750] [client 20.104.50.220:47103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/indeex.php"] [unique_id "apPkIzqFvOdCFO2AmwpHYgAAA-Y"]
[Sun Aug 30 03:04:51.589800 2026] [authz_core:error] [pid 492549:tid 492709] [client 66.249.66.201:59524] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:51.590327 2026] [authz_core:error] [pid 492549:tid 492709] [client 66.249.66.201:59524] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:51.600401 2026] [security2:error] [pid 492549:tid 492734] [client 34.15.141.119:55266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/info.php"] [unique_id "apPkIzqFvOdCFO2AmwpHbwAAA9Y"]
[Sun Aug 30 03:04:51.610936 2026] [security2:error] [pid 491656:tid 491908] [client 20.220.204.93:64280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/24.php"] [unique_id "apPkI4vX_L6VjdbvkkSpDQAAAw4"]
[Sun Aug 30 03:04:51.645039 2026] [security2:error] [pid 491656:tid 491864] [client 20.48.251.3:49992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/mga.php"] [unique_id "apPkI4vX_L6VjdbvkkSpGgAAAuI"]
[Sun Aug 30 03:04:51.660160 2026] [security2:error] [pid 492549:tid 492787] [client 68.155.159.216:52730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apPkIzqFvOdCFO2AmwpHkwAABAs"]
[Sun Aug 30 03:04:51.677720 2026] [security2:error] [pid 491656:tid 491799] [client 20.48.250.41:53327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/xxw.php"] [unique_id "apPkI4vX_L6VjdbvkkSpJQAAAqE"]
[Sun Aug 30 03:04:51.711692 2026] [security2:error] [pid 491656:tid 491829] [client 20.220.204.93:59672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/xsox.php"] [unique_id "apPkI4vX_L6VjdbvkkSpNQAAAr8"]
[Sun Aug 30 03:04:51.753638 2026] [security2:error] [pid 492549:tid 492807] [client 68.155.159.216:52834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-includes/customize/index.php"] [unique_id "apPkIzqFvOdCFO2AmwpHtAAABB8"]
[Sun Aug 30 03:04:51.764722 2026] [security2:error] [pid 492549:tid 492743] [client 20.196.209.81:12318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/upgrade-temp-backup/plugins/security.php"] [unique_id "apPkIzqFvOdCFO2AmwpHuAAAA98"]
[Sun Aug 30 03:04:51.785140 2026] [security2:error] [pid 492549:tid 492754] [client 20.220.204.93:64959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/155.php"] [unique_id "apPkIzqFvOdCFO2AmwpHvgAAA-o"]
[Sun Aug 30 03:04:51.792484 2026] [authz_core:error] [pid 492549:tid 492698] [client 66.249.66.39:58218] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:51.792950 2026] [authz_core:error] [pid 492549:tid 492698] [client 66.249.66.39:58218] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:51.805482 2026] [security2:error] [pid 491656:tid 491841] [client 20.104.50.220:5530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/404.php"] [unique_id "apPkI4vX_L6VjdbvkkSpZQAAAss"]
[Sun Aug 30 03:04:51.811197 2026] [security2:error] [pid 491656:tid 491875] [client 20.104.49.130:57703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/read.php"] [unique_id "apPkI4vX_L6VjdbvkkSpawAAAu0"]
[Sun Aug 30 03:04:51.838707 2026] [security2:error] [pid 491656:tid 491902] [client 20.48.250.41:53222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/bolt.php"] [unique_id "apPkI4vX_L6VjdbvkkSpdQAAAwg"]
[Sun Aug 30 03:04:51.857586 2026] [security2:error] [pid 491656:tid 491895] [client 158.23.147.79:63262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/file17.php"] [unique_id "apPkI4vX_L6VjdbvkkSpgAAAAwE"]
[Sun Aug 30 03:04:51.869254 2026] [authz_core:error] [pid 492549:tid 492739] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:51.869555 2026] [authz_core:error] [pid 492549:tid 492739] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:51.873081 2026] [security2:error] [pid 491656:tid 491816] [client 20.104.50.220:28681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wso25.php"] [unique_id "apPkI4vX_L6VjdbvkkSpiwAAArI"]
[Sun Aug 30 03:04:51.917780 2026] [security2:error] [pid 492549:tid 492760] [client 20.104.50.220:31822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-includes/css/mailer.php.php"] [unique_id "apPkIzqFvOdCFO2AmwpH5QAAA_A"]
[Sun Aug 30 03:04:51.926269 2026] [security2:error] [pid 491656:tid 491862] [client 20.220.204.93:64256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/file.php"] [unique_id "apPkI4vX_L6VjdbvkkSpowAAAuA"]
[Sun Aug 30 03:04:51.932095 2026] [authz_core:error] [pid 491656:tid 491807] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:51.932411 2026] [authz_core:error] [pid 491656:tid 491807] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:51.955517 2026] [authz_core:error] [pid 491656:tid 491901] [client 66.249.66.74:39237] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:51.955795 2026] [authz_core:error] [pid 491656:tid 491901] [client 66.249.66.74:39237] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:51.963826 2026] [security2:error] [pid 492549:tid 492786] [client 20.48.251.3:44352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/xda.php"] [unique_id "apPkIzqFvOdCFO2AmwpH9wAABAo"]
[Sun Aug 30 03:04:51.970379 2026] [authz_core:error] [pid 491656:tid 491811] [client 66.249.66.193:41040] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:51.970585 2026] [security2:error] [pid 492549:tid 492802] [client 20.220.204.93:33953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/lkui.php"] [unique_id "apPkIzqFvOdCFO2AmwpH_AAABBo"]
[Sun Aug 30 03:04:51.970818 2026] [authz_core:error] [pid 491656:tid 491811] [client 66.249.66.193:41040] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:52.004499 2026] [security2:error] [pid 492549:tid 492794] [client 20.48.250.41:53317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/rtx.php"] [unique_id "apPkJDqFvOdCFO2AmwpIDQAABBI"]
[Sun Aug 30 03:04:52.043712 2026] [security2:error] [pid 492549:tid 492714] [client 40.83.93.50:8595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/index.bak.php"] [unique_id "apPkJDqFvOdCFO2AmwpIHwAAA8I"]
[Sun Aug 30 03:04:52.097031 2026] [security2:error] [pid 492549:tid 492807] [client 20.151.200.44:37845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/Contrller.php"] [unique_id "apPkJDqFvOdCFO2AmwpINwAABB8"]
[Sun Aug 30 03:04:52.103039 2026] [security2:error] [pid 492549:tid 492797] [client 20.220.204.93:64335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPkJDqFvOdCFO2AmwpIPAAABBU"]
[Sun Aug 30 03:04:52.110239 2026] [security2:error] [pid 491656:tid 491867] [client 216.73.216.128:13201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPkJIvX_L6VjdbvkkSp6gAAAuU"]
[Sun Aug 30 03:04:52.129575 2026] [security2:error] [pid 492549:tid 492781] [client 34.15.145.202:43482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/phpinfo.php.bak"] [unique_id "apPkJDqFvOdCFO2AmwpISwAABAU"]
[Sun Aug 30 03:04:52.141386 2026] [security2:error] [pid 492549:tid 492787] [client 20.104.18.15:9125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/htio.php"] [unique_id "apPkJDqFvOdCFO2AmwpIXAAABAs"]
[Sun Aug 30 03:04:52.154801 2026] [security2:error] [pid 491656:tid 491894] [client 20.196.209.81:18727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/upgrade-temp-backup/plugins/users.php"] [unique_id "apPkJIvX_L6VjdbvkkSp_gAAAwA"]
[Sun Aug 30 03:04:52.159545 2026] [security2:error] [pid 492549:tid 492706] [client 20.151.200.44:58888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/cy.php"] [unique_id "apPkJDqFvOdCFO2AmwpIZwAAA7o"]
[Sun Aug 30 03:04:52.179345 2026] [security2:error] [pid 492549:tid 492692] [client 158.23.147.79:62530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/file5.php"] [unique_id "apPkJDqFvOdCFO2AmwpIdQAAA6w"]
[Sun Aug 30 03:04:52.190535 2026] [security2:error] [pid 492549:tid 492757] [client 20.48.250.41:53306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/ckk.php"] [unique_id "apPkJDqFvOdCFO2AmwpIfgAAA-0"]
[Sun Aug 30 03:04:52.200248 2026] [security2:error] [pid 492549:tid 492695] [client 20.197.61.180:9194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/wp-settings.php"] [unique_id "apPkJDqFvOdCFO2AmwpIjwAAA68"]
[Sun Aug 30 03:04:52.203762 2026] [security2:error] [pid 492549:tid 492778] [client 34.15.141.119:55282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/php.php"] [unique_id "apPkJDqFvOdCFO2AmwpIlwAABAI"]
[Sun Aug 30 03:04:52.231961 2026] [security2:error] [pid 492549:tid 492755] [client 136.92.30.49:43222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/p.php"] [unique_id "apPkJDqFvOdCFO2AmwpIpQAAA-s"]
[Sun Aug 30 03:04:52.256961 2026] [authz_core:error] [pid 491656:tid 491873] [client 66.249.66.73:55133] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:52.257392 2026] [authz_core:error] [pid 491656:tid 491873] [client 66.249.66.73:55133] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:52.293114 2026] [security2:error] [pid 491656:tid 491903] [client 20.220.204.93:64345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/06.php"] [unique_id "apPkJIvX_L6VjdbvkkSqRgAAAwk"]
[Sun Aug 30 03:04:52.320401 2026] [security2:error] [pid 491656:tid 491888] [client 31.40.195.113:15129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "gregrickard.com"] [uri "/wp-comments-post.php"] [unique_id "apPkIovX_L6VjdbvkkSmxwAAAvo"], referer: https://gregrickard.com/2021/05/30/rainbow-connection-w-harmony/
[Sun Aug 30 03:04:52.332684 2026] [security2:error] [pid 492549:tid 492775] [client 20.48.250.41:53284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-3071a794.ucdss.com"] [uri "/R57.php"] [unique_id "apPkJDqFvOdCFO2AmwpI5gAAA_8"]
[Sun Aug 30 03:04:52.366863 2026] [security2:error] [pid 491656:tid 491855] [client 20.220.204.93:26493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apPkJIvX_L6VjdbvkkSqfQAAAtk"]
[Sun Aug 30 03:04:52.375117 2026] [authz_core:error] [pid 492549:tid 492772] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:52.375560 2026] [authz_core:error] [pid 492549:tid 492772] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:52.421006 2026] [security2:error] [pid 491656:tid 491860] [client 20.220.204.93:64902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/class.php"] [unique_id "apPkJIvX_L6VjdbvkkSqngAAAt4"]
[Sun Aug 30 03:04:52.433362 2026] [authz_core:error] [pid 491656:tid 491837] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:52.433730 2026] [authz_core:error] [pid 491656:tid 491837] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:52.456986 2026] [security2:error] [pid 492549:tid 492775] [client 20.104.50.220:51626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/unzip.php"] [unique_id "apPkJDqFvOdCFO2AmwpJDgAAA_8"]
[Sun Aug 30 03:04:52.479784 2026] [security2:error] [pid 491656:tid 491812] [client 20.48.251.3:7383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/ms-edit.php"] [unique_id "apPkJIvX_L6VjdbvkkSqvgAAAq4"]
[Sun Aug 30 03:04:52.493403 2026] [security2:error] [pid 492549:tid 492765] [client 20.48.251.3:55687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/app.default.php"] [unique_id "apPkJDqFvOdCFO2AmwpJHwAAA_U"]
[Sun Aug 30 03:04:52.495554 2026] [security2:error] [pid 492549:tid 492783] [client 20.104.18.15:31521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/44.php"] [unique_id "apPkJDqFvOdCFO2AmwpJIQAABAc"]
[Sun Aug 30 03:04:52.510168 2026] [security2:error] [pid 491656:tid 491835] [client 20.104.50.220:61657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/%E5%B9%B3%E4%BB%AE%E5%90%8Ds.php"] [unique_id "apPkJIvX_L6VjdbvkkSq0AAAAsU"]
[Sun Aug 30 03:04:52.512469 2026] [security2:error] [pid 492549:tid 492787] [client 158.23.147.79:40267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkJDqFvOdCFO2AmwpJLAAABAs"]
[Sun Aug 30 03:04:52.514030 2026] [security2:error] [pid 492549:tid 492758] [client 40.83.93.50:8617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/log.php"] [unique_id "apPkJDqFvOdCFO2AmwpJLwAAA-4"]
[Sun Aug 30 03:04:52.526376 2026] [security2:error] [pid 492549:tid 492744] [client 68.155.159.216:59944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-content/banners/about.php"] [unique_id "apPkJDqFvOdCFO2AmwpJNQAAA-A"]
[Sun Aug 30 03:04:52.527803 2026] [security2:error] [pid 491656:tid 491916] [client 20.48.251.3:65512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/87.php"] [unique_id "apPkJIvX_L6VjdbvkkSq3wAAAxY"]
[Sun Aug 30 03:04:52.549370 2026] [security2:error] [pid 491656:tid 491848] [client 20.220.204.93:28963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/motu.php"] [unique_id "apPkJIvX_L6VjdbvkkSq6QAAAtI"]
[Sun Aug 30 03:04:52.552269 2026] [security2:error] [pid 491656:tid 491897] [client 20.48.251.3:59118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/phpversion.php"] [unique_id "apPkJIvX_L6VjdbvkkSq6gAAAwM"]
[Sun Aug 30 03:04:52.554930 2026] [security2:error] [pid 491656:tid 491911] [client 158.23.147.79:63265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/file88.php"] [unique_id "apPkJIvX_L6VjdbvkkSq7QAAAxE"]
[Sun Aug 30 03:04:52.576401 2026] [security2:error] [pid 492549:tid 492716] [client 20.196.209.81:18701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/upgrade-temp-backup/plugins/wp-blog-header.php"] [unique_id "apPkJDqFvOdCFO2AmwpJRwAAA8Q"]
[Sun Aug 30 03:04:52.605993 2026] [security2:error] [pid 491656:tid 491815] [client 20.220.204.93:64932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/8.php"] [unique_id "apPkJIvX_L6VjdbvkkSrAQAAArE"]
[Sun Aug 30 03:04:52.636769 2026] [security2:error] [pid 492549:tid 492732] [client 20.48.251.3:64424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/atex1.php"] [unique_id "apPkJDqFvOdCFO2AmwpJYQAAA9Q"]
[Sun Aug 30 03:04:52.646277 2026] [security2:error] [pid 491656:tid 491857] [client 20.104.50.220:28680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/cfinder.php"] [unique_id "apPkJIvX_L6VjdbvkkSrGQAAAts"]
[Sun Aug 30 03:04:52.657809 2026] [security2:error] [pid 491656:tid 491874] [client 20.48.251.3:23485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/87.php"] [unique_id "apPkJIvX_L6VjdbvkkSrIQAAAuw"]
[Sun Aug 30 03:04:52.671635 2026] [security2:error] [pid 491656:tid 491893] [client 136.92.30.49:43234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/debug.php"] [unique_id "apPkJIvX_L6VjdbvkkSrJgAAAv8"]
[Sun Aug 30 03:04:52.683617 2026] [security2:error] [pid 492549:tid 492716] [client 20.104.18.15:32967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/sf.php"] [unique_id "apPkJDqFvOdCFO2AmwpJcAAAA8Q"]
[Sun Aug 30 03:04:52.696759 2026] [security2:error] [pid 491656:tid 491794] [client 20.104.50.220:32857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/style.php"] [unique_id "apPkJIvX_L6VjdbvkkSrLgAAApw"]
[Sun Aug 30 03:04:52.708326 2026] [security2:error] [pid 491656:tid 491860] [client 20.48.251.3:64506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/lmfi2.php"] [unique_id "apPkJIvX_L6VjdbvkkSrNgAAAt4"]
[Sun Aug 30 03:04:52.722509 2026] [security2:error] [pid 492549:tid 492730] [client 20.104.50.220:47097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/jindex.php"] [unique_id "apPkJDqFvOdCFO2AmwpJfQAAA9I"]
[Sun Aug 30 03:04:52.730716 2026] [security2:error] [pid 492549:tid 492775] [client 34.15.145.202:43486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/phpinfo.php.old"] [unique_id "apPkJDqFvOdCFO2AmwpJgAAAA_8"]
[Sun Aug 30 03:04:52.735085 2026] [security2:error] [pid 492549:tid 492732] [client 20.220.204.93:64344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/0x0x.php"] [unique_id "apPkJDqFvOdCFO2AmwpJggAAA9Q"]
[Sun Aug 30 03:04:52.773680 2026] [security2:error] [pid 491656:tid 491879] [client 158.23.184.117:58082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/wp-admin/css/bolt.php"] [unique_id "apPkJIvX_L6VjdbvkkSrSQAAAvE"]
[Sun Aug 30 03:04:52.797636 2026] [security2:error] [pid 492549:tid 492781] [client 20.48.251.3:55441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/ccou.php"] [unique_id "apPkJDqFvOdCFO2AmwpJngAABAU"]
[Sun Aug 30 03:04:52.809148 2026] [security2:error] [pid 492549:tid 492720] [client 34.15.141.119:55288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/i.php"] [unique_id "apPkJDqFvOdCFO2AmwpJpwAAA8g"]
[Sun Aug 30 03:04:52.819212 2026] [security2:error] [pid 492549:tid 492727] [client 158.23.184.117:58065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/light.php"] [unique_id "apPkJDqFvOdCFO2AmwpJqQAAA88"]
[Sun Aug 30 03:04:52.860811 2026] [security2:error] [pid 491656:tid 491892] [client 20.220.204.93:64952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/166.php"] [unique_id "apPkJIvX_L6VjdbvkkSreAAAAv4"]
[Sun Aug 30 03:04:52.890542 2026] [authz_core:error] [pid 492549:tid 492810] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:52.890874 2026] [authz_core:error] [pid 492549:tid 492810] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:52.896059 2026] [security2:error] [pid 492549:tid 492795] [client 20.197.61.180:14752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/themes/wp-signup.php"] [unique_id "apPkJDqFvOdCFO2AmwpJzAAABBM"]
[Sun Aug 30 03:04:52.901629 2026] [security2:error] [pid 491656:tid 491859] [client 158.23.147.79:63275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/NewFile.php/"] [unique_id "apPkJIvX_L6VjdbvkkSrigAAAt0"]
[Sun Aug 30 03:04:52.914708 2026] [authz_core:error] [pid 491656:tid 491872] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:52.915006 2026] [authz_core:error] [pid 491656:tid 491872] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:52.918427 2026] [security2:error] [pid 491656:tid 491901] [client 68.155.159.216:52689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/content.php"] [unique_id "apPkJIvX_L6VjdbvkkSrkgAAAwc"]
[Sun Aug 30 03:04:52.935960 2026] [security2:error] [pid 492549:tid 492727] [client 20.151.200.44:47047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkJDqFvOdCFO2AmwpJ0wAAA88"]
[Sun Aug 30 03:04:52.977668 2026] [security2:error] [pid 492549:tid 492683] [client 68.155.159.216:52844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-admin/index.php"] [unique_id "apPkJDqFvOdCFO2AmwpJ5AAAA6M"]
[Sun Aug 30 03:04:52.978435 2026] [security2:error] [pid 492549:tid 492738] [client 158.23.184.117:58051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/wp-admin/css/about.php7"] [unique_id "apPkJDqFvOdCFO2AmwpJ5QAAA9o"]
[Sun Aug 30 03:04:52.994140 2026] [security2:error] [pid 492549:tid 492798] [client 20.220.204.93:56259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/Ov-Simple1.php"] [unique_id "apPkJDqFvOdCFO2AmwpJ7wAABBY"]
[Sun Aug 30 03:04:52.998949 2026] [security2:error] [pid 492549:tid 492742] [client 20.151.200.44:58842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/admin.php/pindex.php"] [unique_id "apPkJDqFvOdCFO2AmwpJ8gAAA94"]
[Sun Aug 30 03:04:53.002474 2026] [security2:error] [pid 492549:tid 492766] [client 20.196.209.81:12993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/upgrade-temp-backup/plugins/wp-mail.php"] [unique_id "apPkJTqFvOdCFO2AmwpJ8wAAA_Y"]
[Sun Aug 30 03:04:53.012278 2026] [security2:error] [pid 492549:tid 492734] [client 20.104.50.220:62809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wso2022_shell.php"] [unique_id "apPkJTqFvOdCFO2AmwpJ_QAAA9Y"]
[Sun Aug 30 03:04:53.025785 2026] [security2:error] [pid 492549:tid 492728] [client 20.220.204.93:63206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/h2a2ck.php"] [unique_id "apPkJTqFvOdCFO2AmwpKDAAAA9A"]
[Sun Aug 30 03:04:53.069207 2026] [security2:error] [pid 491656:tid 491850] [client 20.104.50.220:31916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-admin/mailer.php"] [unique_id "apPkJYvX_L6VjdbvkkSrsgAAAtQ"]
[Sun Aug 30 03:04:53.107854 2026] [security2:error] [pid 492549:tid 492774] [client 136.92.30.49:50334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/admin/phpinfo.php"] [unique_id "apPkJTqFvOdCFO2AmwpKUwAAA_4"]
[Sun Aug 30 03:04:53.112482 2026] [security2:error] [pid 492549:tid 492792] [client 20.104.50.220:5519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/mail.php"] [unique_id "apPkJTqFvOdCFO2AmwpKVwAABBA"]
[Sun Aug 30 03:04:53.119034 2026] [security2:error] [pid 491656:tid 491827] [client 158.23.184.117:58097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/alf.php"] [unique_id "apPkJYvX_L6VjdbvkkSrzwAAAr0"]
[Sun Aug 30 03:04:53.124058 2026] [security2:error] [pid 492549:tid 492800] [client 40.83.93.50:9129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/bak.php"] [unique_id "apPkJTqFvOdCFO2AmwpKagAABBg"]
[Sun Aug 30 03:04:53.132423 2026] [security2:error] [pid 492549:tid 492768] [client 20.48.251.3:44337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/pinfo.php"] [unique_id "apPkJTqFvOdCFO2AmwpKbwAAA_g"]
[Sun Aug 30 03:04:53.136849 2026] [security2:error] [pid 491656:tid 491815] [client 158.23.147.79:63292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/dropdown.php"] [unique_id "apPkJYvX_L6VjdbvkkSr2QAAArE"]
[Sun Aug 30 03:04:53.137416 2026] [security2:error] [pid 491656:tid 491820] [client 158.23.147.79:40283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkJYvX_L6VjdbvkkSr2gAAArY"]
[Sun Aug 30 03:04:53.146687 2026] [authz_core:error] [pid 491656:tid 491838] [client 66.249.66.196:37386] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:53.147112 2026] [authz_core:error] [pid 491656:tid 491838] [client 66.249.66.196:37386] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:53.162840 2026] [security2:error] [pid 491656:tid 491811] [client 20.220.204.93:64921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/error_log.php"] [unique_id "apPkJYvX_L6VjdbvkkSr7QAAAq0"]
[Sun Aug 30 03:04:53.236873 2026] [authz_core:error] [pid 492549:tid 492778] [client 66.249.66.204:43556] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:53.237356 2026] [authz_core:error] [pid 492549:tid 492778] [client 66.249.66.204:43556] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:53.279172 2026] [security2:error] [pid 492549:tid 492584] [remote 115.187.18.185:52452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.18.187.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rampd.co"] [uri "/wp-login.php"] [unique_id "apPkJTqFvOdCFO2AmwpKuwAECx8"]
[Sun Aug 30 03:04:53.299935 2026] [authz_core:error] [pid 492549:tid 492737] [client 216.73.216.128:9188] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:53.300293 2026] [authz_core:error] [pid 492549:tid 492737] [client 216.73.216.128:9188] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:53.322682 2026] [security2:error] [pid 492549:tid 492775] [client 20.220.204.93:64338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/403.php"] [unique_id "apPkJTqFvOdCFO2AmwpK5wAAA_8"]
[Sun Aug 30 03:04:53.332937 2026] [security2:error] [pid 492549:tid 492718] [client 34.15.145.202:43488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/phpinfo.php~"] [unique_id "apPkJTqFvOdCFO2AmwpK8gAAA8Y"]
[Sun Aug 30 03:04:53.346006 2026] [security2:error] [pid 491656:tid 491863] [client 20.220.204.93:42450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/wp-blogs.php"] [unique_id "apPkJYvX_L6VjdbvkkSsaAAAAuE"]
[Sun Aug 30 03:04:53.352918 2026] [authz_core:error] [pid 492549:tid 492742] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:53.353204 2026] [authz_core:error] [pid 492549:tid 492742] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:53.386278 2026] [security2:error] [pid 491656:tid 491808] [client 216.73.216.128:51719] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPkJYvX_L6VjdbvkkSsewAAAqo"]
[Sun Aug 30 03:04:53.397879 2026] [security2:error] [pid 492549:tid 492729] [client 20.196.209.81:16732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/upgrade-temp-backup/themes/admin.php"] [unique_id "apPkJTqFvOdCFO2AmwpLEQAAA9E"]
[Sun Aug 30 03:04:53.411754 2026] [security2:error] [pid 492549:tid 492766] [client 34.15.141.119:55296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/pi.php"] [unique_id "apPkJTqFvOdCFO2AmwpLHgAAA_Y"]
[Sun Aug 30 03:04:53.419866 2026] [authz_core:error] [pid 491656:tid 491866] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:53.420121 2026] [authz_core:error] [pid 491656:tid 491866] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:53.431519 2026] [security2:error] [pid 491656:tid 491861] [client 20.151.200.44:58896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/admin.php/csv.php"] [unique_id "apPkJYvX_L6VjdbvkkSsmAAAAt8"]
[Sun Aug 30 03:04:53.459986 2026] [security2:error] [pid 492549:tid 492700] [client 20.220.204.93:63860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/cytyr.php"] [unique_id "apPkJTqFvOdCFO2AmwpLOwAAA7Q"]
[Sun Aug 30 03:04:53.460049 2026] [security2:error] [pid 492549:tid 492792] [client 158.23.147.79:63269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/.well-known/index.php"] [unique_id "apPkJTqFvOdCFO2AmwpLPAAABBA"]
[Sun Aug 30 03:04:53.508105 2026] [security2:error] [pid 492549:tid 492803] [client 158.23.184.117:60490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/wp-admin/import.php"] [unique_id "apPkJTqFvOdCFO2AmwpLZQAABBs"]
[Sun Aug 30 03:04:53.530260 2026] [security2:error] [pid 492549:tid 492698] [client 158.23.147.79:40287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apPkJTqFvOdCFO2AmwpLdwAAA7I"]
[Sun Aug 30 03:04:53.558247 2026] [security2:error] [pid 491656:tid 491825] [client 136.92.30.49:50348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/test/phpinfo.php"] [unique_id "apPkJYvX_L6VjdbvkkSsxwAAArs"]
[Sun Aug 30 03:04:53.575367 2026] [authz_core:error] [pid 492549:tid 492733] [client 216.73.216.128:9188] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:53.575821 2026] [authz_core:error] [pid 492549:tid 492733] [client 216.73.216.128:9188] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:53.594186 2026] [security2:error] [pid 491656:tid 491904] [client 20.104.50.220:51610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/think.php"] [unique_id "apPkJYvX_L6VjdbvkkSs0QAAAwo"]
[Sun Aug 30 03:04:53.608430 2026] [security2:error] [pid 491656:tid 491801] [client 20.220.204.93:64946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/galer.php"] [unique_id "apPkJYvX_L6VjdbvkkSs1QAAAqM"]
[Sun Aug 30 03:04:53.619110 2026] [security2:error] [pid 491656:tid 491909] [client 20.197.61.180:9177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/updraft/about.php"] [unique_id "apPkJYvX_L6VjdbvkkSs2wAAAw8"]
[Sun Aug 30 03:04:53.623083 2026] [security2:error] [pid 492549:tid 492703] [client 40.83.93.50:8331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/pages.php"] [unique_id "apPkJTqFvOdCFO2AmwpLrgAAA7c"]
[Sun Aug 30 03:04:53.629493 2026] [security2:error] [pid 491656:tid 491834] [client 20.48.251.3:59351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/app_local.php"] [unique_id "apPkJYvX_L6VjdbvkkSs4gAAAsQ"]
[Sun Aug 30 03:04:53.633261 2026] [authz_core:error] [pid 492549:tid 492791] [client 66.249.66.42:43289] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:53.633725 2026] [authz_core:error] [pid 492549:tid 492791] [client 66.249.66.42:43289] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:53.637777 2026] [security2:error] [pid 492549:tid 492746] [client 158.23.147.79:40947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apPkJTqFvOdCFO2AmwpLvAAAA-I"]
[Sun Aug 30 03:04:53.648439 2026] [security2:error] [pid 491656:tid 491892] [client 158.23.184.117:60480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "apPkJYvX_L6VjdbvkkSs6gAAAv4"]
[Sun Aug 30 03:04:53.648824 2026] [security2:error] [pid 491656:tid 491847] [client 20.104.50.220:61978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-includes/rest-api/fields/anbu.php"] [unique_id "apPkJYvX_L6VjdbvkkSs6wAAAtE"]
[Sun Aug 30 03:04:53.654488 2026] [security2:error] [pid 491656:tid 491852] [client 20.104.18.15:31553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/h2.php"] [unique_id "apPkJYvX_L6VjdbvkkSs8AAAAtY"]
[Sun Aug 30 03:04:53.666525 2026] [security2:error] [pid 491656:tid 491805] [client 20.220.204.93:20056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/mini.php"] [unique_id "apPkJYvX_L6VjdbvkkSs-wAAAqc"]
[Sun Aug 30 03:04:53.681675 2026] [security2:error] [pid 491656:tid 491865] [client 20.151.200.44:58937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/admin.php/700.php"] [unique_id "apPkJYvX_L6VjdbvkkStAAAAAuM"]
[Sun Aug 30 03:04:53.682531 2026] [security2:error] [pid 492549:tid 492723] [client 158.23.147.79:63279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-content/themes/too.php"] [unique_id "apPkJTqFvOdCFO2AmwpLygAAA8s"]
[Sun Aug 30 03:04:53.683235 2026] [security2:error] [pid 492549:tid 492750] [client 20.104.18.15:9114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/dev.php"] [unique_id "apPkJTqFvOdCFO2AmwpLywAAA-Y"]
[Sun Aug 30 03:04:53.685553 2026] [security2:error] [pid 491656:tid 491910] [client 68.155.159.216:54083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apPkJYvX_L6VjdbvkkStAgAAAxA"]
[Sun Aug 30 03:04:53.721079 2026] [security2:error] [pid 492549:tid 492731] [client 20.48.251.3:65518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/plss3.php"] [unique_id "apPkJTqFvOdCFO2AmwpL2QAAA9M"]
[Sun Aug 30 03:04:53.740005 2026] [security2:error] [pid 492549:tid 492751] [client 158.23.147.79:40899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/simple.php"] [unique_id "apPkJTqFvOdCFO2AmwpL3gAAA-c"]
[Sun Aug 30 03:04:53.752556 2026] [security2:error] [pid 492549:tid 492745] [client 20.220.204.93:63809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/baixy.php"] [unique_id "apPkJTqFvOdCFO2AmwpL7gAAA-E"]
[Sun Aug 30 03:04:53.764534 2026] [security2:error] [pid 492549:tid 492739] [client 20.48.251.3:58821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/adminfus.php"] [unique_id "apPkJTqFvOdCFO2AmwpL9QAAA9s"]
[Sun Aug 30 03:04:53.765244 2026] [security2:error] [pid 492549:tid 492594] [remote 115.187.18.185:52452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.18.187.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rampd.co"] [uri "/wp-login.php"] [unique_id "apPkJTqFvOdCFO2AmwpL9wAD8Sk"], referer: https://rampd.co/wp-login.php
[Sun Aug 30 03:04:53.781119 2026] [security2:error] [pid 491656:tid 491814] [client 20.48.251.3:6502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/aws_sdk_settings.php"] [unique_id "apPkJYvX_L6VjdbvkkStJAAAArA"]
[Sun Aug 30 03:04:53.795832 2026] [security2:error] [pid 491656:tid 491859] [client 20.196.209.81:16764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/upgrade-temp-backup/themes/login.php"] [unique_id "apPkJYvX_L6VjdbvkkStLAAAAt0"]
[Sun Aug 30 03:04:53.801169 2026] [security2:error] [pid 491656:tid 491794] [client 20.104.49.130:57712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/gecko-new.php"] [unique_id "apPkJYvX_L6VjdbvkkStMAAAApw"]
[Sun Aug 30 03:04:53.822539 2026] [security2:error] [pid 491656:tid 491874] [client 20.104.18.15:32960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/k.php"] [unique_id "apPkJYvX_L6VjdbvkkStOwAAAuw"]
[Sun Aug 30 03:04:53.830405 2026] [cgid:error] [pid 492549:tid 492740] [client 158.23.184.117:0] AH01265: stderr from /home3/mvdb/public_html/cgi-bin/: attempt to invoke directory as script
[Sun Aug 30 03:04:53.840129 2026] [security2:error] [pid 491656:tid 491791] [client 20.48.251.3:23476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/plss3.php"] [unique_id "apPkJYvX_L6VjdbvkkStRQAAApk"]
[Sun Aug 30 03:04:53.854377 2026] [security2:error] [pid 492549:tid 492709] [client 20.104.50.220:32888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/Success.php"] [unique_id "apPkJTqFvOdCFO2AmwpMKAAAA70"]
[Sun Aug 30 03:04:53.858578 2026] [security2:error] [pid 491656:tid 491877] [client 20.48.251.3:6499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/wpver.php"] [unique_id "apPkJYvX_L6VjdbvkkStTQAAAu8"]
[Sun Aug 30 03:04:53.860852 2026] [security2:error] [pid 492549:tid 492773] [client 20.104.50.220:46601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/p0wny-shell.php"] [unique_id "apPkJTqFvOdCFO2AmwpMKwAAA_0"]
[Sun Aug 30 03:04:53.868714 2026] [security2:error] [pid 492549:tid 492804] [client 20.104.50.220:28694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/pasired.php"] [unique_id "apPkJTqFvOdCFO2AmwpMLgAABBw"]
[Sun Aug 30 03:04:53.882573 2026] [security2:error] [pid 492549:tid 492720] [client 158.23.147.79:40268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-admin/about.php"] [unique_id "apPkJTqFvOdCFO2AmwpMMwAAA8g"]
[Sun Aug 30 03:04:53.908661 2026] [security2:error] [pid 491656:tid 491813] [client 20.220.204.93:40395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/amp.php"] [unique_id "apPkJYvX_L6VjdbvkkStaQAAAq8"]
[Sun Aug 30 03:04:53.920708 2026] [authz_core:error] [pid 491656:tid 491845] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:53.920975 2026] [authz_core:error] [pid 491656:tid 491845] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:53.927923 2026] [security2:error] [pid 491656:tid 491798] [client 20.220.204.93:63144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/ava.php"] [unique_id "apPkJYvX_L6VjdbvkkStcgAAAqA"]
[Sun Aug 30 03:04:53.935740 2026] [security2:error] [pid 492549:tid 492703] [client 34.15.145.202:43504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/info.php.bak"] [unique_id "apPkJTqFvOdCFO2AmwpMSgAAA7c"]
[Sun Aug 30 03:04:53.946151 2026] [security2:error] [pid 491656:tid 491797] [client 20.48.251.3:55512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/rum.or.php"] [unique_id "apPkJYvX_L6VjdbvkkStfgAAAp8"]
[Sun Aug 30 03:04:53.981488 2026] [autoindex:error] [pid 492549:tid 492772] [client 158.23.184.117:58087] AH01276: Cannot serve directory /home3/mvdb/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:04:54.007278 2026] [security2:error] [pid 492549:tid 492778] [client 136.92.30.49:50360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/dev/phpinfo.php"] [unique_id "apPkJjqFvOdCFO2AmwpMXgAABAI"]
[Sun Aug 30 03:04:54.015944 2026] [security2:error] [pid 491656:tid 491910] [client 34.15.141.119:55310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/pinfo.php"] [unique_id "apPkJovX_L6VjdbvkkStogAAAxA"]
[Sun Aug 30 03:04:54.028871 2026] [security2:error] [pid 492549:tid 492756] [client 158.23.184.117:58087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/wp-admin/admin-post.php"] [unique_id "apPkJjqFvOdCFO2AmwpMaQAAA-w"]
[Sun Aug 30 03:04:54.040358 2026] [security2:error] [pid 492549:tid 492745] [client 68.155.159.216:52663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPkJjqFvOdCFO2AmwpMdQAAA-E"]
[Sun Aug 30 03:04:54.042371 2026] [security2:error] [pid 492549:tid 492699] [client 158.23.147.79:63289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/radio.php"] [unique_id "apPkJjqFvOdCFO2AmwpMeQAAA7M"]
[Sun Aug 30 03:04:54.058039 2026] [security2:error] [pid 492549:tid 492709] [client 158.23.147.79:40278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apPkJjqFvOdCFO2AmwpMiwAAA70"]
[Sun Aug 30 03:04:54.063262 2026] [security2:error] [pid 491656:tid 491890] [client 20.220.204.93:63812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/gdn.php"] [unique_id "apPkJovX_L6VjdbvkkStuAAAAvw"]
[Sun Aug 30 03:04:54.072345 2026] [security2:error] [pid 491656:tid 491806] [client 20.48.251.3:64432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/ah25.php"] [unique_id "apPkJovX_L6VjdbvkkStwQAAAqg"]
[Sun Aug 30 03:04:54.077681 2026] [authz_core:error] [pid 492549:tid 492789] [client 66.249.66.38:41938] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:54.077979 2026] [authz_core:error] [pid 492549:tid 492789] [client 66.249.66.38:41938] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:54.081661 2026] [security2:error] [pid 491656:tid 491766] [remote 209.42.18.223:56836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oklahomapersonalinjuryattorney.pro"] [uri "/wp-login.php"] [unique_id "apPkJovX_L6VjdbvkkStvAAC6Wg"]
[Sun Aug 30 03:04:54.107765 2026] [security2:error] [pid 491656:tid 491843] [client 40.83.93.50:8579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/albin.php"] [unique_id "apPkJovX_L6VjdbvkkSt1gAAAs0"]
[Sun Aug 30 03:04:54.164097 2026] [security2:error] [pid 491656:tid 491863] [client 20.104.50.220:29135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wpxadmin.php"] [unique_id "apPkJovX_L6VjdbvkkSuCQAAAuE"]
[Sun Aug 30 03:04:54.168641 2026] [security2:error] [pid 492549:tid 492781] [client 158.23.184.117:60495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/favicon.php"] [unique_id "apPkJjqFvOdCFO2AmwpMxAAABAU"]
[Sun Aug 30 03:04:54.173888 2026] [security2:error] [pid 492549:tid 492731] [client 158.23.147.79:40264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apPkJjqFvOdCFO2AmwpMygAAA9M"]
[Sun Aug 30 03:04:54.204659 2026] [security2:error] [pid 492549:tid 492733] [client 20.220.204.93:64917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/f2.php"] [unique_id "apPkJjqFvOdCFO2AmwpM3QAAA9U"]
[Sun Aug 30 03:04:54.207701 2026] [security2:error] [pid 492549:tid 492741] [client 158.23.147.79:62567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPkJjqFvOdCFO2AmwpM4QAAA90"]
[Sun Aug 30 03:04:54.224996 2026] [security2:error] [pid 491656:tid 491869] [client 68.155.159.216:52749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-content/themes/index.php"] [unique_id "apPkJovX_L6VjdbvkkSuNgAAAuc"]
[Sun Aug 30 03:04:54.225235 2026] [security2:error] [pid 492549:tid 492793] [client 20.196.209.81:7839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/upgrade-temp-backup/themes/test.php"] [unique_id "apPkJjqFvOdCFO2AmwpM6gAABBE"]
[Sun Aug 30 03:04:54.243168 2026] [security2:error] [pid 492549:tid 492744] [client 20.104.50.220:32064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-content/mailer.php"] [unique_id "apPkJjqFvOdCFO2AmwpM8gAAA-A"]
[Sun Aug 30 03:04:54.260589 2026] [security2:error] [pid 492549:tid 492756] [client 20.151.200.44:58921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/admin.php/007x.php"] [unique_id "apPkJjqFvOdCFO2AmwpM-AAAA-w"]
[Sun Aug 30 03:04:54.279658 2026] [security2:error] [pid 492549:tid 492747] [client 20.220.204.93:20035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/cc13.php"] [unique_id "apPkJjqFvOdCFO2AmwpNBAAAA-M"]
[Sun Aug 30 03:04:54.285809 2026] [security2:error] [pid 491656:tid 491767] [remote 209.42.18.223:56836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oklahomapersonalinjuryattorney.pro"] [uri "/wp-login.php"] [unique_id "apPkJovX_L6VjdbvkkSuXwAC_Wk"], referer: https://oklahomapersonalinjuryattorney.pro/wp-login.php
[Sun Aug 30 03:04:54.307234 2026] [security2:error] [pid 492549:tid 492746] [client 158.23.184.117:60505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/wp-admin/css/my.php"] [unique_id "apPkJjqFvOdCFO2AmwpNGQAAA-I"]
[Sun Aug 30 03:04:54.328027 2026] [security2:error] [pid 492549:tid 492767] [client 158.23.147.79:40284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/chosen.php"] [unique_id "apPkJjqFvOdCFO2AmwpNNgAAA_c"]
[Sun Aug 30 03:04:54.334836 2026] [security2:error] [pid 492549:tid 492779] [client 20.197.61.180:21075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/upgrade-temp-backup/min.php"] [unique_id "apPkJjqFvOdCFO2AmwpNOQAABAM"]
[Sun Aug 30 03:04:54.335729 2026] [security2:error] [pid 491656:tid 491918] [client 158.23.147.79:62532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/makeasmtp.php"] [unique_id "apPkJovX_L6VjdbvkkSujAAAAxg"]
[Sun Aug 30 03:04:54.358501 2026] [authz_core:error] [pid 492549:tid 492804] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus%2Fdrivers%2Fi2c%3Asmbus_alert
[Sun Aug 30 03:04:54.358993 2026] [authz_core:error] [pid 492549:tid 492804] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus%2Fdrivers%2Fi2c%3Asmbus_alert
[Sun Aug 30 03:04:54.377414 2026] [security2:error] [pid 491656:tid 491807] [client 20.220.204.93:63144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/grsiuk.php"] [unique_id "apPkJovX_L6VjdbvkkSusQAAAqk"]
[Sun Aug 30 03:04:54.400503 2026] [security2:error] [pid 491656:tid 491886] [client 20.104.50.220:5464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apPkJovX_L6VjdbvkkSuwQAAAvg"]
[Sun Aug 30 03:04:54.429268 2026] [security2:error] [pid 491656:tid 491865] [client 20.104.18.15:43299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkJovX_L6VjdbvkkSu0QAAAuM"]
[Sun Aug 30 03:04:54.448023 2026] [security2:error] [pid 491656:tid 491904] [client 158.23.184.117:58052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/wp-content/images/doc.php"] [unique_id "apPkJovX_L6VjdbvkkSu3AAAAwo"]
[Sun Aug 30 03:04:54.462473 2026] [security2:error] [pid 491656:tid 491869] [client 136.92.30.49:50372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/old/phpinfo.php"] [unique_id "apPkJovX_L6VjdbvkkSu5QAAAuc"]
[Sun Aug 30 03:04:54.476612 2026] [security2:error] [pid 492549:tid 492740] [client 20.48.251.3:44412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/X57.php"] [unique_id "apPkJjqFvOdCFO2AmwpNhgAAA9w"]
[Sun Aug 30 03:04:54.481617 2026] [authz_core:error] [pid 492549:tid 492742] [client 66.249.66.78:53580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:54.482059 2026] [authz_core:error] [pid 492549:tid 492742] [client 66.249.66.78:53580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:54.484015 2026] [security2:error] [pid 491656:tid 491872] [client 216.73.216.128:45228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPkJovX_L6VjdbvkkSu7QAAAuo"]
[Sun Aug 30 03:04:54.485167 2026] [authz_core:error] [pid 491656:tid 491917] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:54.485681 2026] [authz_core:error] [pid 491656:tid 491917] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:54.495847 2026] [security2:error] [pid 492549:tid 492731] [client 158.23.147.79:40956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/goods.php"] [unique_id "apPkJjqFvOdCFO2AmwpNmQAAA9M"]
[Sun Aug 30 03:04:54.539660 2026] [security2:error] [pid 492549:tid 492775] [client 34.15.145.202:43508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/phpinfo.php.save"] [unique_id "apPkJjqFvOdCFO2AmwpNtQAAA_8"]
[Sun Aug 30 03:04:54.542144 2026] [security2:error] [pid 491656:tid 491838] [client 20.220.204.93:64960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/wp-scr1pts.php"] [unique_id "apPkJovX_L6VjdbvkkSvCAAAAsg"]
[Sun Aug 30 03:04:54.571469 2026] [security2:error] [pid 492549:tid 492802] [client 20.220.204.93:51542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/aa.php"] [unique_id "apPkJjqFvOdCFO2AmwpNvwAABBo"]
[Sun Aug 30 03:04:54.588261 2026] [security2:error] [pid 492549:tid 492726] [client 158.23.184.117:58077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/wp-comments.php"] [unique_id "apPkJjqFvOdCFO2AmwpNyAAAA84"]
[Sun Aug 30 03:04:54.622885 2026] [security2:error] [pid 491656:tid 491877] [client 34.15.141.119:55316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/test.php"] [unique_id "apPkJovX_L6VjdbvkkSvLwAAAu8"]
[Sun Aug 30 03:04:54.644632 2026] [security2:error] [pid 492549:tid 492722] [client 20.196.209.81:18709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/upgrade-temp-backup/themes/wp-links-opml.php"] [unique_id "apPkJjqFvOdCFO2AmwpN8AAAA8o"]
[Sun Aug 30 03:04:54.680363 2026] [security2:error] [pid 491656:tid 491906] [client 158.23.147.79:40949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apPkJovX_L6VjdbvkkSvUwAAAww"]
[Sun Aug 30 03:04:54.688975 2026] [security2:error] [pid 491656:tid 491874] [client 20.220.204.93:64293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/num.php"] [unique_id "apPkJovX_L6VjdbvkkSvWAAAAuw"]
[Sun Aug 30 03:04:54.722753 2026] [security2:error] [pid 492549:tid 492698] [client 158.23.147.79:62578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apPkJjqFvOdCFO2AmwpOCwAAA7I"]
[Sun Aug 30 03:04:54.727459 2026] [security2:error] [pid 491656:tid 491875] [client 158.23.184.117:58055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/wp-includes/panel.php"] [unique_id "apPkJovX_L6VjdbvkkSvbAAAAu0"]
[Sun Aug 30 03:04:54.731386 2026] [security2:error] [pid 491656:tid 491844] [client 20.151.200.44:58754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/admin.php/heex.php"] [unique_id "apPkJovX_L6VjdbvkkSvcgAAAs4"]
[Sun Aug 30 03:04:54.732354 2026] [security2:error] [pid 491656:tid 491807] [client 20.104.50.220:51573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/tod.php"] [unique_id "apPkJovX_L6VjdbvkkSvdQAAAqk"]
[Sun Aug 30 03:04:54.770349 2026] [security2:error] [pid 491656:tid 491896] [client 20.48.251.3:55792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/ws62.php"] [unique_id "apPkJovX_L6VjdbvkkSvlQAAAwI"]
[Sun Aug 30 03:04:54.774009 2026] [authz_core:error] [pid 491656:tid 491894] [client 216.73.216.128:51719] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:54.774549 2026] [authz_core:error] [pid 491656:tid 491894] [client 216.73.216.128:51719] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:54.779850 2026] [security2:error] [pid 492549:tid 492752] [client 40.83.93.50:8588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/an.php"] [unique_id "apPkJjqFvOdCFO2AmwpOFgAAA-g"]
[Sun Aug 30 03:04:54.784212 2026] [security2:error] [pid 491656:tid 491826] [client 20.104.18.15:31564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apPkJovX_L6VjdbvkkSvngAAArw"]
[Sun Aug 30 03:04:54.801751 2026] [security2:error] [pid 491656:tid 491860] [client 68.155.159.216:60028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/asd.php"] [unique_id "apPkJovX_L6VjdbvkkSvrAAAAt4"]
[Sun Aug 30 03:04:54.812814 2026] [security2:error] [pid 492549:tid 492771] [client 20.104.50.220:61972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/anbu.php"] [unique_id "apPkJjqFvOdCFO2AmwpOJwAAA_s"]
[Sun Aug 30 03:04:54.852455 2026] [security2:error] [pid 492549:tid 492801] [client 20.220.204.93:43262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/s1.php"] [unique_id "apPkJjqFvOdCFO2AmwpOOQAABBk"]
[Sun Aug 30 03:04:54.857030 2026] [authz_core:error] [pid 492549:tid 492765] [client 66.249.66.68:43350] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:54.857451 2026] [authz_core:error] [pid 492549:tid 492765] [client 66.249.66.68:43350] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:54.873840 2026] [security2:error] [pid 491656:tid 491826] [client 20.220.204.93:63194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/a4.php"] [unique_id "apPkJovX_L6VjdbvkkSv1QAAArw"]
[Sun Aug 30 03:04:54.893429 2026] [authz_core:error] [pid 492549:tid 492785] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus%2Fdrivers%2Fi2c%3Asmbus_alert
[Sun Aug 30 03:04:54.893787 2026] [authz_core:error] [pid 492549:tid 492785] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus%2Fdrivers%2Fi2c%3Asmbus_alert
[Sun Aug 30 03:04:54.902639 2026] [security2:error] [pid 491656:tid 491915] [client 136.92.30.49:50378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/tmp/phpinfo.php"] [unique_id "apPkJovX_L6VjdbvkkSv6wAAAxU"]
[Sun Aug 30 03:04:54.907591 2026] [security2:error] [pid 491656:tid 491890] [client 20.151.200.44:58889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/tf.php"] [unique_id "apPkJovX_L6VjdbvkkSv7gAAAvw"]
[Sun Aug 30 03:04:54.914935 2026] [security2:error] [pid 491656:tid 491917] [client 20.48.251.3:7395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/setup-config.php"] [unique_id "apPkJovX_L6VjdbvkkSv8gAAAxc"]
[Sun Aug 30 03:04:54.919174 2026] [security2:error] [pid 491656:tid 491870] [client 158.23.147.79:40896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apPkJovX_L6VjdbvkkSv9gAAAug"]
[Sun Aug 30 03:04:54.919833 2026] [security2:error] [pid 491656:tid 491909] [client 20.48.251.3:51554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/avim.php"] [unique_id "apPkJovX_L6VjdbvkkSv9wAAAw8"]
[Sun Aug 30 03:04:54.930456 2026] [security2:error] [pid 491656:tid 491884] [client 158.23.184.117:60491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/www.php"] [unique_id "apPkJovX_L6VjdbvkkSv_AAAAvY"]
[Sun Aug 30 03:04:54.957519 2026] [authz_core:error] [pid 491656:tid 491834] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:54.957949 2026] [authz_core:error] [pid 491656:tid 491834] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:54.960363 2026] [security2:error] [pid 491656:tid 491854] [client 20.104.18.15:33016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/82.php"] [unique_id "apPkJovX_L6VjdbvkkSwDwAAAtg"]
[Sun Aug 30 03:04:54.976535 2026] [authz_core:error] [pid 491656:tid 491792] [client 66.249.66.43:51143] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:54.976812 2026] [authz_core:error] [pid 491656:tid 491792] [client 66.249.66.43:51143] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:54.986429 2026] [security2:error] [pid 492549:tid 492770] [client 20.48.251.3:44251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/aws.php"] [unique_id "apPkJjqFvOdCFO2AmwpOZwAAA_o"]
[Sun Aug 30 03:04:54.998625 2026] [security2:error] [pid 492549:tid 492794] [client 20.104.50.220:47050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/ex0shell.php"] [unique_id "apPkJjqFvOdCFO2AmwpOagAABBI"]
[Sun Aug 30 03:04:55.004475 2026] [security2:error] [pid 491656:tid 491914] [client 20.104.50.220:29120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/adm.php"] [unique_id "apPkJ4vX_L6VjdbvkkSwLgAAAxQ"]
[Sun Aug 30 03:04:55.009959 2026] [security2:error] [pid 491656:tid 491865] [client 20.104.50.220:33215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/syad.php"] [unique_id "apPkJ4vX_L6VjdbvkkSwNAAAAuM"]
[Sun Aug 30 03:04:55.033959 2026] [security2:error] [pid 492549:tid 492734] [client 20.196.209.81:12305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/upgrade-temp-backup/themes/wp-settings.php"] [unique_id "apPkJzqFvOdCFO2AmwpOdgAAA9Y"]
[Sun Aug 30 03:04:55.036529 2026] [security2:error] [pid 491656:tid 491800] [client 20.197.61.180:14770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/upgrade-temp-backup/pk.php"] [unique_id "apPkJ4vX_L6VjdbvkkSwSQAAAqI"]
[Sun Aug 30 03:04:55.090271 2026] [security2:error] [pid 491656:tid 491871] [client 158.23.184.117:60485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/.well-known/core.php"] [unique_id "apPkJ4vX_L6VjdbvkkSwdQAAAuk"]
[Sun Aug 30 03:04:55.101593 2026] [security2:error] [pid 492549:tid 492793] [client 20.48.251.3:49922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/xmy.php"] [unique_id "apPkJzqFvOdCFO2AmwpOjQAABBE"]
[Sun Aug 30 03:04:55.102326 2026] [security2:error] [pid 492549:tid 492713] [client 158.23.147.79:40950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/file.php"] [unique_id "apPkJzqFvOdCFO2AmwpOjgAAA8E"]
[Sun Aug 30 03:04:55.112903 2026] [security2:error] [pid 491656:tid 491840] [client 20.151.200.44:58914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/update/da222.php"] [unique_id "apPkJ4vX_L6VjdbvkkSwiwAAAso"]
[Sun Aug 30 03:04:55.112994 2026] [security2:error] [pid 491656:tid 491887] [client 20.220.204.93:20041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/0byte.php"] [unique_id "apPkJ4vX_L6VjdbvkkSwjQAAAvk"]
[Sun Aug 30 03:04:55.119963 2026] [security2:error] [pid 491656:tid 491917] [client 20.104.49.130:58063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/dehnl.php"] [unique_id "apPkJ4vX_L6VjdbvkkSwlwAAAxc"]
[Sun Aug 30 03:04:55.120521 2026] [security2:error] [pid 492549:tid 492798] [client 216.73.216.128:16152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPkJzqFvOdCFO2AmwpOkQAABBY"]
[Sun Aug 30 03:04:55.122034 2026] [security2:error] [pid 491656:tid 491908] [client 158.23.147.79:63276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apPkJ4vX_L6VjdbvkkSwmQAAAw4"]
[Sun Aug 30 03:04:55.138814 2026] [security2:error] [pid 492549:tid 492791] [client 34.15.145.202:43522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/staging/phpinfo.php"] [unique_id "apPkJzqFvOdCFO2AmwpOmQAABA8"]
[Sun Aug 30 03:04:55.139234 2026] [security2:error] [pid 491656:tid 491845] [client 20.220.204.93:64297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/tfm.php"] [unique_id "apPkJ4vX_L6VjdbvkkSwpwAAAs8"]
[Sun Aug 30 03:04:55.150244 2026] [security2:error] [pid 491656:tid 491878] [client 20.48.251.3:45872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/groceries/index.php"] [unique_id "apPkJ4vX_L6VjdbvkkSwtQAAAvA"]
[Sun Aug 30 03:04:55.154193 2026] [authz_core:error] [pid 492549:tid 492732] [client 66.249.66.77:64029] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:55.154661 2026] [authz_core:error] [pid 492549:tid 492732] [client 66.249.66.77:64029] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:55.157834 2026] [security2:error] [pid 492549:tid 492770] [client 20.48.251.3:54826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/aws.php"] [unique_id "apPkJzqFvOdCFO2AmwpOqgAAA_o"]
[Sun Aug 30 03:04:55.206414 2026] [security2:error] [pid 491656:tid 491904] [client 158.23.147.79:40935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/file17.php"] [unique_id "apPkJ4vX_L6VjdbvkkSw4wAAAwo"]
[Sun Aug 30 03:04:55.231422 2026] [security2:error] [pid 492549:tid 492694] [client 158.23.184.117:58103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/akcc.php"] [unique_id "apPkJzqFvOdCFO2AmwpO0AAAA64"]
[Sun Aug 30 03:04:55.242611 2026] [security2:error] [pid 491656:tid 491864] [client 68.155.159.216:52664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/goat.php"] [unique_id "apPkJ4vX_L6VjdbvkkSw-QAAAuI"]
[Sun Aug 30 03:04:55.272877 2026] [security2:error] [pid 492549:tid 492787] [client 20.151.200.44:58827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/qi.php"] [unique_id "apPkJzqFvOdCFO2AmwpO5wAABAs"]
[Sun Aug 30 03:04:55.274882 2026] [security2:error] [pid 492549:tid 492802] [client 20.220.204.93:56272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/xr.php"] [unique_id "apPkJzqFvOdCFO2AmwpO6wAABBo"]
[Sun Aug 30 03:04:55.276957 2026] [security2:error] [pid 491656:tid 491843] [client 40.83.93.50:8372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/mini.php"] [unique_id "apPkJ4vX_L6VjdbvkkSxFgAAAs0"]
[Sun Aug 30 03:04:55.302999 2026] [security2:error] [pid 491656:tid 491909] [client 158.23.147.79:40920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/file5.php"] [unique_id "apPkJ4vX_L6VjdbvkkSxLQAAAw8"]
[Sun Aug 30 03:04:55.304936 2026] [security2:error] [pid 492549:tid 492753] [client 20.220.204.93:65003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/Geforce.php"] [unique_id "apPkJzqFvOdCFO2AmwpPAQAAA-k"]
[Sun Aug 30 03:04:55.319018 2026] [security2:error] [pid 492549:tid 492748] [client 20.104.50.220:63045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wso2.5.php"] [unique_id "apPkJzqFvOdCFO2AmwpPGAAAA-Q"]
[Sun Aug 30 03:04:55.322567 2026] [security2:error] [pid 492549:tid 492783] [client 158.23.147.79:63271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-content/languages/about.php"] [unique_id "apPkJzqFvOdCFO2AmwpPHwAABAc"]
[Sun Aug 30 03:04:55.342538 2026] [security2:error] [pid 492549:tid 492752] [client 68.155.159.216:60573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/about.php"] [unique_id "apPkJzqFvOdCFO2AmwpPLgAAA-g"]
[Sun Aug 30 03:04:55.342878 2026] [security2:error] [pid 492549:tid 492686] [client 136.92.30.49:50386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/public/phpinfo.php"] [unique_id "apPkJzqFvOdCFO2AmwpPLwAAA6Y"]
[Sun Aug 30 03:04:55.373895 2026] [security2:error] [pid 491656:tid 491811] [client 158.23.184.117:60538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/themes7.php"] [unique_id "apPkJ4vX_L6VjdbvkkSxXAAAAq0"]
[Sun Aug 30 03:04:55.386788 2026] [security2:error] [pid 491656:tid 491814] [client 20.48.251.3:7377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/konfig.php"] [unique_id "apPkJ4vX_L6VjdbvkkSxZgAAArA"]
[Sun Aug 30 03:04:55.415109 2026] [security2:error] [pid 491656:tid 491825] [client 20.151.200.44:47003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/cy.php"] [unique_id "apPkJ4vX_L6VjdbvkkSxegAAArs"]
[Sun Aug 30 03:04:55.417664 2026] [authz_core:error] [pid 492549:tid 492726] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus%2Fdrivers%2Fi2c%3Asmbus_alert
[Sun Aug 30 03:04:55.417955 2026] [authz_core:error] [pid 492549:tid 492726] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus%2Fdrivers%2Fi2c%3Asmbus_alert
[Sun Aug 30 03:04:55.427310 2026] [security2:error] [pid 492549:tid 492711] [client 34.15.141.119:55320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/p.php"] [unique_id "apPkJzqFvOdCFO2AmwpPWgAAA78"]
[Sun Aug 30 03:04:55.435013 2026] [security2:error] [pid 491656:tid 491791] [client 20.104.50.220:31862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-includes/mailer.php"] [unique_id "apPkJ4vX_L6VjdbvkkSxhwAAApk"]
[Sun Aug 30 03:04:55.437195 2026] [security2:error] [pid 491656:tid 491843] [client 20.151.200.44:58900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/px.php"] [unique_id "apPkJ4vX_L6VjdbvkkSxigAAAs0"]
[Sun Aug 30 03:04:55.461756 2026] [security2:error] [pid 492549:tid 492686] [client 158.23.147.79:40281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/file88.php"] [unique_id "apPkJzqFvOdCFO2AmwpPbQAAA6Y"]
[Sun Aug 30 03:04:55.478587 2026] [security2:error] [pid 492549:tid 492714] [client 20.220.204.93:64353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/click.php"] [unique_id "apPkJzqFvOdCFO2AmwpPdwAAA8I"]
[Sun Aug 30 03:04:55.499449 2026] [security2:error] [pid 491656:tid 491803] [client 20.220.204.93:20081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/h02ugyh.php"] [unique_id "apPkJ4vX_L6VjdbvkkSxoQAAAqU"]
[Sun Aug 30 03:04:55.528520 2026] [security2:error] [pid 492549:tid 492698] [client 20.104.18.15:9044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/gos.php"] [unique_id "apPkJzqFvOdCFO2AmwpPrQAAA7I"]
[Sun Aug 30 03:04:55.532913 2026] [security2:error] [pid 492549:tid 492720] [client 158.23.184.117:58068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/wp-admin/images.php"] [unique_id "apPkJzqFvOdCFO2AmwpPrwAAA8g"]
[Sun Aug 30 03:04:55.534941 2026] [authz_core:error] [pid 491656:tid 491863] [client 66.249.66.32:52459] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:55.535391 2026] [authz_core:error] [pid 491656:tid 491863] [client 66.249.66.32:52459] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:55.539295 2026] [security2:error] [pid 492549:tid 492731] [client 158.23.147.79:62542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-content/banners/about.php"] [unique_id "apPkJzqFvOdCFO2AmwpPsgAAA9M"]
[Sun Aug 30 03:04:55.565439 2026] [security2:error] [pid 491656:tid 491813] [client 20.196.209.81:12320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/upgrade/about.php"] [unique_id "apPkJ4vX_L6VjdbvkkSxxAAAAq8"]
[Sun Aug 30 03:04:55.592227 2026] [security2:error] [pid 491656:tid 491917] [client 20.104.18.15:43291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkJ4vX_L6VjdbvkkSx0wAAAxc"]
[Sun Aug 30 03:04:55.598406 2026] [security2:error] [pid 492549:tid 492754] [client 20.151.200.44:58848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/is.php"] [unique_id "apPkJzqFvOdCFO2AmwpPxwAAA-o"]
[Sun Aug 30 03:04:55.612995 2026] [authz_core:error] [pid 491656:tid 491909] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:55.613364 2026] [authz_core:error] [pid 491656:tid 491909] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:55.634836 2026] [security2:error] [pid 492549:tid 492792] [client 20.48.251.3:44404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/register.php"] [unique_id "apPkJzqFvOdCFO2AmwpP4QAABBA"]
[Sun Aug 30 03:04:55.665765 2026] [security2:error] [pid 492549:tid 492749] [client 20.220.204.93:63813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/ms.php"] [unique_id "apPkJzqFvOdCFO2AmwpP8AAAA-U"]
[Sun Aug 30 03:04:55.669147 2026] [security2:error] [pid 491656:tid 491830] [client 20.104.50.220:5498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/sx.php"] [unique_id "apPkJ4vX_L6VjdbvkkSx_gAAAsA"]
[Sun Aug 30 03:04:55.673147 2026] [security2:error] [pid 492549:tid 492723] [client 158.23.147.79:40922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/NewFile.php/"] [unique_id "apPkJzqFvOdCFO2AmwpP9gAAA8s"]
[Sun Aug 30 03:04:55.674594 2026] [security2:error] [pid 492549:tid 492799] [client 158.23.184.117:58102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/wp-content/themes/haha.php"] [unique_id "apPkJzqFvOdCFO2AmwpP-gAABBc"]
[Sun Aug 30 03:04:55.739445 2026] [security2:error] [pid 492549:tid 492745] [client 34.15.145.202:43536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/beta/phpinfo.php"] [unique_id "apPkJzqFvOdCFO2AmwpQCAAAA-E"]
[Sun Aug 30 03:04:55.742096 2026] [security2:error] [pid 491656:tid 491912] [client 20.197.61.180:13928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/upgrade-temp-backup/plugins/security.php"] [unique_id "apPkJ4vX_L6VjdbvkkSyIQAAAxI"]
[Sun Aug 30 03:04:55.775132 2026] [security2:error] [pid 491656:tid 491843] [client 158.23.147.79:40936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/dropdown.php"] [unique_id "apPkJ4vX_L6VjdbvkkSyNgAAAs0"]
[Sun Aug 30 03:04:55.796933 2026] [security2:error] [pid 491656:tid 491827] [client 20.220.204.93:43232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/xxw.php"] [unique_id "apPkJ4vX_L6VjdbvkkSyRwAAAr0"]
[Sun Aug 30 03:04:55.810885 2026] [security2:error] [pid 491656:tid 491812] [client 158.23.184.117:60482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/wp-mail.php"] [unique_id "apPkJ4vX_L6VjdbvkkSyUgAAAq4"]
[Sun Aug 30 03:04:55.818915 2026] [security2:error] [pid 492549:tid 492689] [client 20.220.204.93:63834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/zxekqlxb.php"] [unique_id "apPkJzqFvOdCFO2AmwpQNQAAA6k"]
[Sun Aug 30 03:04:55.825113 2026] [security2:error] [pid 491656:tid 491850] [client 40.83.93.50:9118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/robots.php"] [unique_id "apPkJ4vX_L6VjdbvkkSyWwAAAtQ"]
[Sun Aug 30 03:04:55.877501 2026] [security2:error] [pid 492549:tid 492720] [client 158.23.147.79:40908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/.well-known/index.php"] [unique_id "apPkJzqFvOdCFO2AmwpQWgAAA8g"]
[Sun Aug 30 03:04:55.885841 2026] [security2:error] [pid 491656:tid 491799] [client 20.104.50.220:56719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/setor.php"] [unique_id "apPkJ4vX_L6VjdbvkkSyegAAAqE"]
[Sun Aug 30 03:04:55.902411 2026] [authz_core:error] [pid 491656:tid 491904] [client 66.249.66.37:55833] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:55.902684 2026] [authz_core:error] [pid 491656:tid 491904] [client 66.249.66.37:55833] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:55.906690 2026] [security2:error] [pid 492549:tid 492765] [client 20.48.251.3:55703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/grsiuk.php"] [unique_id "apPkJzqFvOdCFO2AmwpQagAAA_U"]
[Sun Aug 30 03:04:55.911452 2026] [security2:error] [pid 492549:tid 492808] [client 68.155.159.216:54119] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.krisestep.com"] [uri "/1.php"] [unique_id "apPkJzqFvOdCFO2AmwpQbAAABCA"]
[Sun Aug 30 03:04:55.911551 2026] [security2:error] [pid 492549:tid 492808] [client 68.155.159.216:54119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/1.php"] [unique_id "apPkJzqFvOdCFO2AmwpQbAAABCA"]
[Sun Aug 30 03:04:55.929204 2026] [security2:error] [pid 491656:tid 491910] [client 158.23.184.117:23993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/bgymj.php"] [unique_id "apPkJ4vX_L6VjdbvkkSyjwAAAxA"]
[Sun Aug 30 03:04:55.930980 2026] [security2:error] [pid 491656:tid 491867] [client 20.104.18.15:31695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/sao.php"] [unique_id "apPkJ4vX_L6VjdbvkkSykQAAAuU"]
[Sun Aug 30 03:04:55.931230 2026] [authz_core:error] [pid 492549:tid 492758] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus%2Fdrivers%2Fi2c%3Asmbus_alert
[Sun Aug 30 03:04:55.931500 2026] [authz_core:error] [pid 492549:tid 492758] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus%2Fdrivers%2Fi2c%3Asmbus_alert
[Sun Aug 30 03:04:55.935998 2026] [security2:error] [pid 491656:tid 491850] [client 20.151.200.44:58897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/od.php"] [unique_id "apPkJ4vX_L6VjdbvkkSylQAAAtQ"]
[Sun Aug 30 03:04:55.950427 2026] [security2:error] [pid 491656:tid 491815] [client 158.23.184.117:58093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/root.php"] [unique_id "apPkJ4vX_L6VjdbvkkSynwAAArE"]
[Sun Aug 30 03:04:55.955632 2026] [security2:error] [pid 492549:tid 492713] [client 20.104.50.220:61988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-content/%E5%B9%B3%E4%BB%AE%E5%90%8Ds.php"] [unique_id "apPkJzqFvOdCFO2AmwpQegAAA8E"]
[Sun Aug 30 03:04:55.958789 2026] [security2:error] [pid 491656:tid 491845] [client 20.196.209.81:7959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "apPkJ4vX_L6VjdbvkkSyqAAAAs8"]
[Sun Aug 30 03:04:55.974484 2026] [security2:error] [pid 492549:tid 492755] [client 158.23.184.117:23954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/bk/index.php"] [unique_id "apPkJzqFvOdCFO2AmwpQfQAAA-s"]
[Sun Aug 30 03:04:56.012285 2026] [security2:error] [pid 491656:tid 491833] [client 20.220.204.93:28942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/bolt.php"] [unique_id "apPkKIvX_L6VjdbvkkSyxQAAAsM"]
[Sun Aug 30 03:04:56.027558 2026] [security2:error] [pid 491656:tid 491811] [client 34.15.141.119:54072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/debug.php"] [unique_id "apPkKIvX_L6VjdbvkkSyzwAAAq0"]
[Sun Aug 30 03:04:56.031817 2026] [security2:error] [pid 492549:tid 492778] [client 158.23.147.79:62554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apPkKDqFvOdCFO2AmwpQlQAABAI"]
[Sun Aug 30 03:04:56.043373 2026] [security2:error] [pid 491656:tid 491901] [client 20.220.204.93:62552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/init.php"] [unique_id "apPkKIvX_L6VjdbvkkSy3gAAAwc"]
[Sun Aug 30 03:04:56.062837 2026] [security2:error] [pid 492549:tid 492766] [client 20.48.251.3:34592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/nw.php"] [unique_id "apPkKDqFvOdCFO2AmwpQngAAA_Y"]
[Sun Aug 30 03:04:56.079941 2026] [security2:error] [pid 491656:tid 491791] [client 20.48.251.3:45837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/wp-admin/sc.php"] [unique_id "apPkKIvX_L6VjdbvkkSy-QAAApk"]
[Sun Aug 30 03:04:56.087151 2026] [authz_core:error] [pid 491656:tid 491869] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:56.087638 2026] [authz_core:error] [pid 491656:tid 491869] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:56.090374 2026] [security2:error] [pid 491656:tid 491915] [client 158.23.184.117:60523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/ae.php"] [unique_id "apPkKIvX_L6VjdbvkkSzBgAAAxU"]
[Sun Aug 30 03:04:56.115821 2026] [security2:error] [pid 491656:tid 491863] [client 158.23.184.117:23986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/bootstrap.php"] [unique_id "apPkKIvX_L6VjdbvkkSzFwAAAuE"]
[Sun Aug 30 03:04:56.133686 2026] [security2:error] [pid 492549:tid 492692] [client 158.23.147.79:40931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-content/themes/too.php"] [unique_id "apPkKDqFvOdCFO2AmwpQwAAAA6w"]
[Sun Aug 30 03:04:56.135309 2026] [security2:error] [pid 491656:tid 491885] [client 20.48.251.3:44184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/app.default.php"] [unique_id "apPkKIvX_L6VjdbvkkSzLAAAAvc"]
[Sun Aug 30 03:04:56.136293 2026] [security2:error] [pid 491656:tid 491885] [client 20.104.50.220:47054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/exp.php"] [unique_id "apPkKIvX_L6VjdbvkkSzLQAAAvc"]
[Sun Aug 30 03:04:56.146033 2026] [security2:error] [pid 492549:tid 492726] [client 20.104.18.15:33005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/dex.php"] [unique_id "apPkKDqFvOdCFO2AmwpQ0AAAA84"]
[Sun Aug 30 03:04:56.158591 2026] [security2:error] [pid 492549:tid 492699] [client 20.104.50.220:29123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/noob.php"] [unique_id "apPkKDqFvOdCFO2AmwpQ2wAAA7M"]
[Sun Aug 30 03:04:56.181210 2026] [security2:error] [pid 492549:tid 492741] [client 20.104.50.220:33032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/success.php"] [unique_id "apPkKDqFvOdCFO2AmwpQ7AAAA90"]
[Sun Aug 30 03:04:56.228225 2026] [security2:error] [pid 492549:tid 492775] [client 20.220.204.93:63833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/term.php"] [unique_id "apPkKDqFvOdCFO2AmwpRBAAAA_8"]
[Sun Aug 30 03:04:56.228539 2026] [authz_core:error] [pid 491656:tid 491896] [client 216.73.216.128:11796] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:56.229009 2026] [authz_core:error] [pid 491656:tid 491896] [client 216.73.216.128:11796] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:56.232824 2026] [security2:error] [pid 491656:tid 491883] [client 158.23.184.117:58098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/admin/controller/extension/ultra.php"] [unique_id "apPkKIvX_L6VjdbvkkSzeQAAAvU"]
[Sun Aug 30 03:04:56.249326 2026] [security2:error] [pid 491656:tid 491848] [client 158.23.147.79:63266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/asd.php"] [unique_id "apPkKIvX_L6VjdbvkkSziAAAAtI"]
[Sun Aug 30 03:04:56.255099 2026] [security2:error] [pid 491656:tid 491812] [client 20.48.251.3:55519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/ms-edit.php"] [unique_id "apPkKIvX_L6VjdbvkkSzjAAAAq4"]
[Sun Aug 30 03:04:56.256106 2026] [security2:error] [pid 491656:tid 491899] [client 158.23.184.117:23941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/bs1.php"] [unique_id "apPkKIvX_L6VjdbvkkSzjwAAAwU"]
[Sun Aug 30 03:04:56.260416 2026] [security2:error] [pid 492549:tid 492780] [client 136.92.30.49:50414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/php-info.php"] [unique_id "apPkKDqFvOdCFO2AmwpRDgAABAQ"]
[Sun Aug 30 03:04:56.304799 2026] [security2:error] [pid 492549:tid 492761] [client 40.83.93.50:9123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/cron.php"] [unique_id "apPkKDqFvOdCFO2AmwpRLQAAA_E"]
[Sun Aug 30 03:04:56.336661 2026] [security2:error] [pid 491656:tid 491832] [client 20.48.251.3:7407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/paths.php"] [unique_id "apPkKIvX_L6VjdbvkkSzywAAAsI"]
[Sun Aug 30 03:04:56.341998 2026] [security2:error] [pid 491656:tid 491852] [client 158.23.147.79:40271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/radio.php"] [unique_id "apPkKIvX_L6VjdbvkkSzzwAAAtY"]
[Sun Aug 30 03:04:56.353057 2026] [security2:error] [pid 492549:tid 492687] [client 34.15.145.202:43552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/uat/phpinfo.php"] [unique_id "apPkKDqFvOdCFO2AmwpRVwAAA6c"]
[Sun Aug 30 03:04:56.366001 2026] [security2:error] [pid 491656:tid 491835] [client 20.220.204.93:64381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/aaa.php"] [unique_id "apPkKIvX_L6VjdbvkkSz2wAAAsU"]
[Sun Aug 30 03:04:56.373316 2026] [security2:error] [pid 492549:tid 492712] [client 158.23.184.117:60510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/wp-content/import.php"] [unique_id "apPkKDqFvOdCFO2AmwpRYQAAA8A"]
[Sun Aug 30 03:04:56.396806 2026] [security2:error] [pid 492549:tid 492748] [client 158.23.184.117:23985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/bthil.php"] [unique_id "apPkKDqFvOdCFO2AmwpRbwAAA-Q"]
[Sun Aug 30 03:04:56.402650 2026] [security2:error] [pid 492549:tid 492699] [client 20.220.204.93:43765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/rtx.php"] [unique_id "apPkKDqFvOdCFO2AmwpRdgAAA7M"]
[Sun Aug 30 03:04:56.415637 2026] [security2:error] [pid 492549:tid 492684] [client 20.104.49.130:59527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.infinitelearners.com"] [uri "/ortasekerli1.php"] [unique_id "apPkKDqFvOdCFO2AmwpRewAAA6Q"]
[Sun Aug 30 03:04:56.416098 2026] [security2:error] [pid 492549:tid 492725] [client 20.48.251.3:54787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/app.default.php"] [unique_id "apPkKDqFvOdCFO2AmwpRfAAAA80"]
[Sun Aug 30 03:04:56.427427 2026] [security2:error] [pid 492549:tid 492770] [client 68.155.159.216:52620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apPkKDqFvOdCFO2AmwpRiQAAA_o"]
[Sun Aug 30 03:04:56.430893 2026] [security2:error] [pid 491656:tid 491874] [client 158.23.147.79:62540] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "hwsoffice.basichoa.com"] [uri "/1.php"] [unique_id "apPkKIvX_L6VjdbvkkS0BgAAAuw"]
[Sun Aug 30 03:04:56.430990 2026] [security2:error] [pid 491656:tid 491874] [client 158.23.147.79:62540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/1.php"] [unique_id "apPkKIvX_L6VjdbvkkS0BgAAAuw"]
[Sun Aug 30 03:04:56.434508 2026] [security2:error] [pid 491656:tid 491849] [client 20.197.61.180:21058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/upgrade-temp-backup/plugins/users.php"] [unique_id "apPkKIvX_L6VjdbvkkS0CgAAAtM"]
[Sun Aug 30 03:04:56.435757 2026] [security2:error] [pid 491656:tid 491862] [client 20.151.200.44:37709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/file66.php"] [unique_id "apPkKIvX_L6VjdbvkkS0DAAAAuA"]
[Sun Aug 30 03:04:56.447955 2026] [authz_core:error] [pid 492549:tid 492778] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:56.448407 2026] [authz_core:error] [pid 492549:tid 492778] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:56.456293 2026] [security2:error] [pid 492549:tid 492766] [client 20.104.50.220:29129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-mode.php"] [unique_id "apPkKDqFvOdCFO2AmwpRpAAAA_Y"]
[Sun Aug 30 03:04:56.487267 2026] [security2:error] [pid 491656:tid 491874] [client 158.23.147.79:40906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPkKIvX_L6VjdbvkkS0OgAAAuw"]
[Sun Aug 30 03:04:56.501403 2026] [security2:error] [pid 491656:tid 491895] [client 20.220.204.93:64996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/xsox.php"] [unique_id "apPkKIvX_L6VjdbvkkS0RgAAAwE"]
[Sun Aug 30 03:04:56.513804 2026] [security2:error] [pid 491656:tid 491886] [client 158.23.184.117:58106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/wp-includes/fonts/admin.php"] [unique_id "apPkKIvX_L6VjdbvkkS0UgAAAvg"]
[Sun Aug 30 03:04:56.513806 2026] [security2:error] [pid 492549:tid 492754] [client 68.155.159.216:60603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apPkKDqFvOdCFO2AmwpRuwAAA-o"]
[Sun Aug 30 03:04:56.536569 2026] [security2:error] [pid 491656:tid 491825] [client 158.23.184.117:23939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/buy.php"] [unique_id "apPkKIvX_L6VjdbvkkS0ZAAAArs"]
[Sun Aug 30 03:04:56.541121 2026] [security2:error] [pid 491656:tid 491798] [client 20.220.204.93:28970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/ckk.php"] [unique_id "apPkKIvX_L6VjdbvkkS0ZQAAAqA"]
[Sun Aug 30 03:04:56.568521 2026] [security2:error] [pid 492549:tid 492692] [client 20.48.251.3:64505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/olfclass.php"] [unique_id "apPkKDqFvOdCFO2AmwpR0gAAA6w"]
[Sun Aug 30 03:04:56.595973 2026] [authz_core:error] [pid 491656:tid 491886] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:56.596342 2026] [authz_core:error] [pid 491656:tid 491886] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:56.609991 2026] [security2:error] [pid 492549:tid 492790] [client 20.104.50.220:31879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/ym.php"] [unique_id "apPkKDqFvOdCFO2AmwpR3QAABA4"]
[Sun Aug 30 03:04:56.628844 2026] [security2:error] [pid 492549:tid 492744] [client 34.15.141.119:54074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/admin/phpinfo.php"] [unique_id "apPkKDqFvOdCFO2AmwpR7AAAA-A"]
[Sun Aug 30 03:04:56.638854 2026] [security2:error] [pid 492549:tid 492754] [client 20.220.204.93:65018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/lkui.php"] [unique_id "apPkKDqFvOdCFO2AmwpR9AAAA-o"]
[Sun Aug 30 03:04:56.652938 2026] [security2:error] [pid 491656:tid 491867] [client 158.23.184.117:60493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/222.php"] [unique_id "apPkKIvX_L6VjdbvkkS0pAAAAuU"]
[Sun Aug 30 03:04:56.673312 2026] [security2:error] [pid 492549:tid 492699] [client 158.23.184.117:59265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/byp.php"] [unique_id "apPkKDqFvOdCFO2AmwpSCQAAA7M"]
[Sun Aug 30 03:04:56.697399 2026] [security2:error] [pid 491656:tid 491910] [client 158.23.147.79:63270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/ws.php"] [unique_id "apPkKIvX_L6VjdbvkkS0vQAAAxA"]
[Sun Aug 30 03:04:56.700110 2026] [security2:error] [pid 492549:tid 492807] [client 136.92.30.49:50428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/phpversion.php"] [unique_id "apPkKDqFvOdCFO2AmwpSFAAABB8"]
[Sun Aug 30 03:04:56.705342 2026] [security2:error] [pid 492549:tid 492794] [client 158.23.147.79:40286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/makeasmtp.php"] [unique_id "apPkKDqFvOdCFO2AmwpSFQAABBI"]
[Sun Aug 30 03:04:56.708109 2026] [security2:error] [pid 492549:tid 492758] [client 20.104.18.15:9035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/132.php"] [unique_id "apPkKDqFvOdCFO2AmwpSFgAAA-4"]
[Sun Aug 30 03:04:56.749652 2026] [authz_core:error] [pid 491656:tid 491895] [client 66.249.66.71:61696] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:56.750202 2026] [authz_core:error] [pid 491656:tid 491895] [client 66.249.66.71:61696] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:56.765187 2026] [security2:error] [pid 491656:tid 491813] [client 216.73.216.128:7790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPkKIvX_L6VjdbvkkS06AAAAq8"]
[Sun Aug 30 03:04:56.772488 2026] [security2:error] [pid 492549:tid 492727] [client 20.104.18.15:43318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/ap.php"] [unique_id "apPkKDqFvOdCFO2AmwpSLwAAA88"]
[Sun Aug 30 03:04:56.783393 2026] [security2:error] [pid 492549:tid 492696] [client 40.83.93.50:8334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/goat.php"] [unique_id "apPkKDqFvOdCFO2AmwpSPAAAA7A"]
[Sun Aug 30 03:04:56.790228 2026] [security2:error] [pid 492549:tid 492761] [client 20.151.200.44:58818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/wp-the.php"] [unique_id "apPkKDqFvOdCFO2AmwpSPQAAA_E"]
[Sun Aug 30 03:04:56.791961 2026] [security2:error] [pid 491656:tid 491855] [client 158.23.184.117:58057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/wp-content/languages.php"] [unique_id "apPkKIvX_L6VjdbvkkS09wAAAtk"]
[Sun Aug 30 03:04:56.817321 2026] [security2:error] [pid 491656:tid 491909] [client 158.23.184.117:23951] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "direcorgigames.lordrcane.com"] [uri "/c99.php"] [unique_id "apPkKIvX_L6VjdbvkkS1BwAAAw8"]
[Sun Aug 30 03:04:56.820394 2026] [security2:error] [pid 492549:tid 492724] [client 20.220.204.93:63850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apPkKDqFvOdCFO2AmwpSVAAAA8w"]
[Sun Aug 30 03:04:56.853170 2026] [authz_core:error] [pid 491656:tid 491793] [client 66.249.66.74:54407] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:56.853576 2026] [authz_core:error] [pid 491656:tid 491793] [client 66.249.66.74:54407] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:56.869593 2026] [security2:error] [pid 491656:tid 491840] [client 158.23.147.79:40945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apPkKIvX_L6VjdbvkkS1KwAAAso"]
[Sun Aug 30 03:04:56.923794 2026] [security2:error] [pid 492549:tid 492715] [client 20.48.251.3:44302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/xqq.php"] [unique_id "apPkKDqFvOdCFO2AmwpSjAAAA8M"]
[Sun Aug 30 03:04:56.936124 2026] [security2:error] [pid 492549:tid 492689] [client 158.23.184.117:58048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/wp-config-sample.php"] [unique_id "apPkKDqFvOdCFO2AmwpSkQAAA6k"]
[Sun Aug 30 03:04:56.939294 2026] [authz_core:error] [pid 492549:tid 492728] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:56.939825 2026] [authz_core:error] [pid 492549:tid 492728] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:56.958914 2026] [security2:error] [pid 492549:tid 492736] [client 34.15.145.202:43568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/qa/phpinfo.php"] [unique_id "apPkKDqFvOdCFO2AmwpSmwAAA9g"]
[Sun Aug 30 03:04:56.961905 2026] [security2:error] [pid 492549:tid 492766] [client 158.23.184.117:59265] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "direcorgigames.lordrcane.com"] [uri "/c99.php"] [unique_id "apPkKDqFvOdCFO2AmwpSnQAAA_Y"]
[Sun Aug 30 03:04:56.969511 2026] [security2:error] [pid 491656:tid 491907] [client 158.23.147.79:40900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apPkKIvX_L6VjdbvkkS1YAAAAw0"]
[Sun Aug 30 03:04:56.992488 2026] [security2:error] [pid 491656:tid 491796] [client 20.220.204.93:63183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/motu.php"] [unique_id "apPkKIvX_L6VjdbvkkS1agAAAp4"]
[Sun Aug 30 03:04:57.001729 2026] [security2:error] [pid 492549:tid 492711] [client 20.104.50.220:5448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "apPkKTqFvOdCFO2AmwpSrQAAA78"]
[Sun Aug 30 03:04:57.003229 2026] [security2:error] [pid 491656:tid 491828] [client 20.104.18.15:13705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkKYvX_L6VjdbvkkS1cAAAAr4"]
[Sun Aug 30 03:04:57.058261 2026] [security2:error] [pid 492549:tid 492779] [client 20.104.50.220:51544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/thr.php"] [unique_id "apPkKTqFvOdCFO2AmwpS1QAABAM"]
[Sun Aug 30 03:04:57.076489 2026] [security2:error] [pid 491656:tid 491893] [client 20.48.251.3:52739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/paypal.php"] [unique_id "apPkKYvX_L6VjdbvkkS1kwAAAv8"]
[Sun Aug 30 03:04:57.076986 2026] [security2:error] [pid 492549:tid 492743] [client 158.23.184.117:58107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/wp-admin/install-helper.php"] [unique_id "apPkKTqFvOdCFO2AmwpS4wAAA98"]
[Sun Aug 30 03:04:57.078266 2026] [security2:error] [pid 491656:tid 491823] [client 68.155.159.216:59914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/ws.php"] [unique_id "apPkKYvX_L6VjdbvkkS1lQAAArk"]
[Sun Aug 30 03:04:57.081002 2026] [security2:error] [pid 491656:tid 491883] [client 20.220.204.93:43226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marazulpm.pa"] [uri "/R57.php"] [unique_id "apPkKYvX_L6VjdbvkkS1lgAAAvU"]
[Sun Aug 30 03:04:57.089236 2026] [security2:error] [pid 491656:tid 491836] [client 20.104.18.15:31679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/dapa.php"] [unique_id "apPkKYvX_L6VjdbvkkS1nQAAAsY"]
[Sun Aug 30 03:04:57.100652 2026] [security2:error] [pid 491656:tid 491850] [client 158.23.184.117:23938] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "direcorgigames.lordrcane.com"] [uri "/c99.php"] [unique_id "apPkKYvX_L6VjdbvkkS1pQAAAtQ"]
[Sun Aug 30 03:04:57.109941 2026] [security2:error] [pid 491656:tid 491868] [client 20.104.50.220:61463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-admin/%E5%B9%B3%E4%BB%AE%E5%90%8Ds.php"] [unique_id "apPkKYvX_L6VjdbvkkS1pgAAAuY"]
[Sun Aug 30 03:04:57.114880 2026] [security2:error] [pid 492549:tid 492775] [client 20.151.200.44:47086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkKTqFvOdCFO2AmwpTAgAAA_8"]
[Sun Aug 30 03:04:57.145507 2026] [security2:error] [pid 492549:tid 492692] [client 158.23.147.79:40911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-content/languages/about.php"] [unique_id "apPkKTqFvOdCFO2AmwpTHAAAA6w"]
[Sun Aug 30 03:04:57.149551 2026] [security2:error] [pid 492549:tid 492791] [client 20.197.61.180:21063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/upgrade-temp-backup/plugins/wp-blog-header.php"] [unique_id "apPkKTqFvOdCFO2AmwpTJAAABA8"]
[Sun Aug 30 03:04:57.158630 2026] [security2:error] [pid 491656:tid 491805] [client 136.92.30.49:50432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/_phpinfo.php"] [unique_id "apPkKYvX_L6VjdbvkkS1xQAAAqc"]
[Sun Aug 30 03:04:57.172375 2026] [security2:error] [pid 492549:tid 492807] [client 20.220.204.93:65023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/Ov-Simple1.php"] [unique_id "apPkKTqFvOdCFO2AmwpTPwAABB8"]
[Sun Aug 30 03:04:57.217304 2026] [security2:error] [pid 492549:tid 492734] [client 158.23.184.117:58076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/wp-includes/fonts/classmap.php"] [unique_id "apPkKTqFvOdCFO2AmwpTbwAAA9Y"]
[Sun Aug 30 03:04:57.220590 2026] [security2:error] [pid 492549:tid 492806] [client 158.23.147.79:63274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-includes/css/index.php"] [unique_id "apPkKTqFvOdCFO2AmwpTcQAABB4"]
[Sun Aug 30 03:04:57.229917 2026] [security2:error] [pid 491656:tid 491855] [client 20.48.251.3:7038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/debug.php"] [unique_id "apPkKYvX_L6VjdbvkkS19AAAAtk"]
[Sun Aug 30 03:04:57.234821 2026] [security2:error] [pid 492549:tid 492799] [client 34.15.141.119:54086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/test/phpinfo.php"] [unique_id "apPkKTqFvOdCFO2AmwpTfAAABBc"]
[Sun Aug 30 03:04:57.261173 2026] [security2:error] [pid 492549:tid 492752] [client 20.48.251.3:59091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/product.php"] [unique_id "apPkKTqFvOdCFO2AmwpTjQAAA-g"]
[Sun Aug 30 03:04:57.266295 2026] [authz_core:error] [pid 491656:tid 491821] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:57.266806 2026] [authz_core:error] [pid 491656:tid 491821] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:57.274050 2026] [security2:error] [pid 491656:tid 491873] [client 20.48.251.3:44220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/app_local.php"] [unique_id "apPkKYvX_L6VjdbvkkS2DgAAAus"]
[Sun Aug 30 03:04:57.275167 2026] [security2:error] [pid 492549:tid 492800] [client 20.104.50.220:46909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/pHpINJ.php"] [unique_id "apPkKTqFvOdCFO2AmwpTlgAABBg"]
[Sun Aug 30 03:04:57.289504 2026] [security2:error] [pid 492549:tid 492770] [client 158.23.147.79:40257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-content/banners/about.php"] [unique_id "apPkKTqFvOdCFO2AmwpTnwAAA_o"]
[Sun Aug 30 03:04:57.329724 2026] [security2:error] [pid 492549:tid 492773] [client 20.104.50.220:33035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/swm@asd365.php"] [unique_id "apPkKTqFvOdCFO2AmwpT1QAAA_0"]
[Sun Aug 30 03:04:57.330473 2026] [security2:error] [pid 492549:tid 492771] [client 20.104.18.15:33774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/inso.php"] [unique_id "apPkKTqFvOdCFO2AmwpT2QAAA_s"]
[Sun Aug 30 03:04:57.337257 2026] [security2:error] [pid 491656:tid 491882] [client 20.220.204.93:63792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/wp-blogs.php"] [unique_id "apPkKYvX_L6VjdbvkkS2MwAAAvQ"]
[Sun Aug 30 03:04:57.339299 2026] [security2:error] [pid 492549:tid 492791] [client 40.83.93.50:8327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/gg.php"] [unique_id "apPkKTqFvOdCFO2AmwpT4wAABA8"]
[Sun Aug 30 03:04:57.341149 2026] [security2:error] [pid 491656:tid 491849] [client 20.104.50.220:28684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/..php"] [unique_id "apPkKYvX_L6VjdbvkkS2NwAAAtM"]
[Sun Aug 30 03:04:57.356214 2026] [lsapi:warn] [pid 491656:tid 491779] [remote 116.179.32.207:52205] [host tastylandscape.com] Backend log: PHP Warning: Use of undefined constant user_level - assumed 'user_level' (this will throw an Error in a future version of PHP) in /home4/tommed/public_html/wp-content/plugins/ultimate-google-analytics/ultimate_ga.php on line 524\n
[Sun Aug 30 03:04:57.359418 2026] [security2:error] [pid 492549:tid 492810] [client 158.23.184.117:58063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/adminfuns.php/.well-known/acme-challenge/file.php"] [unique_id "apPkKTqFvOdCFO2AmwpT8QAABCI"]
[Sun Aug 30 03:04:57.401060 2026] [security2:error] [pid 492549:tid 492713] [client 20.48.251.3:55447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/sys.php"] [unique_id "apPkKTqFvOdCFO2AmwpUCwAAA8E"]
[Sun Aug 30 03:04:57.415191 2026] [authz_core:error] [pid 492549:tid 492778] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:57.415489 2026] [authz_core:error] [pid 492549:tid 492778] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:57.497020 2026] [security2:error] [pid 492549:tid 492775] [client 20.220.204.93:64296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/mini.php"] [unique_id "apPkKTqFvOdCFO2AmwpUNwAAA_8"]
[Sun Aug 30 03:04:57.497159 2026] [security2:error] [pid 492549:tid 492770] [client 158.23.147.79:40273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apPkKTqFvOdCFO2AmwpUNgAAA_o"]
[Sun Aug 30 03:04:57.517163 2026] [security2:error] [pid 492549:tid 492683] [client 158.23.184.117:58086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/wp-content/themes/aa.php"] [unique_id "apPkKTqFvOdCFO2AmwpUUgAAA6M"]
[Sun Aug 30 03:04:57.562084 2026] [security2:error] [pid 491656:tid 491818] [client 20.48.251.3:54739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/app_local.php"] [unique_id "apPkKYvX_L6VjdbvkkS2xgAAArQ"]
[Sun Aug 30 03:04:57.564223 2026] [security2:error] [pid 491656:tid 491842] [client 34.15.145.202:60458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/preview/phpinfo.php"] [unique_id "apPkKYvX_L6VjdbvkkS2ygAAAsw"]
[Sun Aug 30 03:04:57.590569 2026] [security2:error] [pid 492549:tid 492718] [client 136.92.30.49:50442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/old_phpinfo.php"] [unique_id "apPkKTqFvOdCFO2AmwpUcAAAA8Y"]
[Sun Aug 30 03:04:57.597197 2026] [security2:error] [pid 491656:tid 491812] [client 20.104.50.220:62837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-mailcek.php"] [unique_id "apPkKYvX_L6VjdbvkkS24wAAAq4"]
[Sun Aug 30 03:04:57.644836 2026] [security2:error] [pid 491656:tid 491835] [client 68.155.159.216:60578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/themes.php"] [unique_id "apPkKYvX_L6VjdbvkkS3DAAAAsU"]
[Sun Aug 30 03:04:57.653084 2026] [security2:error] [pid 491656:tid 491860] [client 20.151.200.44:58887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/wt.php"] [unique_id "apPkKYvX_L6VjdbvkkS3EgAAAt4"]
[Sun Aug 30 03:04:57.654163 2026] [security2:error] [pid 491656:tid 491907] [client 158.23.184.117:58111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/chosen.php"] [unique_id "apPkKYvX_L6VjdbvkkS3FQAAAw0"]
[Sun Aug 30 03:04:57.659050 2026] [authz_core:error] [pid 491656:tid 491911] [client 66.249.66.34:59485] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:57.659487 2026] [authz_core:error] [pid 491656:tid 491911] [client 66.249.66.34:59485] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:57.680868 2026] [security2:error] [pid 492549:tid 492726] [client 158.23.147.79:40955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/asd.php"] [unique_id "apPkKTqFvOdCFO2AmwpUmAAAA84"]
[Sun Aug 30 03:04:57.694767 2026] [security2:error] [pid 492549:tid 492809] [client 20.220.204.93:64942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/amp.php"] [unique_id "apPkKTqFvOdCFO2AmwpUoAAABCE"]
[Sun Aug 30 03:04:57.728319 2026] [security2:error] [pid 491656:tid 491847] [client 68.155.159.216:52649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apPkKYvX_L6VjdbvkkS3QgAAAtE"]
[Sun Aug 30 03:04:57.745785 2026] [authz_core:error] [pid 491656:tid 491869] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:57.746087 2026] [authz_core:error] [pid 491656:tid 491869] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:57.794461 2026] [security2:error] [pid 492549:tid 492724] [client 158.23.184.117:60511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/admin/function.php"] [unique_id "apPkKTqFvOdCFO2AmwpUzAAAA8w"]
[Sun Aug 30 03:04:57.798507 2026] [security2:error] [pid 491656:tid 491818] [client 20.104.50.220:31852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/alfa1.php"] [unique_id "apPkKYvX_L6VjdbvkkS3cAAAArQ"]
[Sun Aug 30 03:04:57.799375 2026] [security2:error] [pid 492549:tid 492776] [client 158.23.147.79:62477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apPkKTqFvOdCFO2AmwpUuAAABAA"]
[Sun Aug 30 03:04:57.823751 2026] [security2:error] [pid 491656:tid 491853] [client 158.23.147.79:40934] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/1.php"] [unique_id "apPkKYvX_L6VjdbvkkS3iwAAAtc"]
[Sun Aug 30 03:04:57.823834 2026] [security2:error] [pid 491656:tid 491853] [client 158.23.147.79:40934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/1.php"] [unique_id "apPkKYvX_L6VjdbvkkS3iwAAAtc"]
[Sun Aug 30 03:04:57.839749 2026] [security2:error] [pid 492549:tid 492805] [client 34.15.141.119:54100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/dev/phpinfo.php"] [unique_id "apPkKTqFvOdCFO2AmwpU3gAABB0"]
[Sun Aug 30 03:04:57.842319 2026] [security2:error] [pid 492549:tid 492717] [client 20.104.18.15:9071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/v22.php"] [unique_id "apPkKTqFvOdCFO2AmwpU3wAAA8U"]
[Sun Aug 30 03:04:57.847120 2026] [security2:error] [pid 491656:tid 491825] [client 40.83.93.50:9131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/defaults.php"] [unique_id "apPkKYvX_L6VjdbvkkS3ogAAArs"]
[Sun Aug 30 03:04:57.852627 2026] [security2:error] [pid 491656:tid 491903] [client 20.197.61.180:14727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/upgrade-temp-backup/plugins/wp-mail.php"] [unique_id "apPkKYvX_L6VjdbvkkS3qQAAAwk"]
[Sun Aug 30 03:04:57.887584 2026] [security2:error] [pid 492549:tid 492688] [client 20.220.204.93:63843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/cc13.php"] [unique_id "apPkKTqFvOdCFO2AmwpU9gAAA6g"]
[Sun Aug 30 03:04:57.894557 2026] [authz_core:error] [pid 492549:tid 492788] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fbind%2Fsample%2Fvar%2Fnamed
[Sun Aug 30 03:04:57.894868 2026] [authz_core:error] [pid 492549:tid 492788] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fbind%2Fsample%2Fvar%2Fnamed
[Sun Aug 30 03:04:57.932139 2026] [security2:error] [pid 491656:tid 491910] [client 20.104.18.15:43282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/media.php"] [unique_id "apPkKYvX_L6VjdbvkkS37AAAAxA"]
[Sun Aug 30 03:04:57.933896 2026] [security2:error] [pid 491656:tid 491824] [client 158.23.184.117:15253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/wxo.php"] [unique_id "apPkKYvX_L6VjdbvkkS37wAAAro"]
[Sun Aug 30 03:04:57.957464 2026] [authz_core:error] [pid 491656:tid 491858] [client 216.73.216.128:51719] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:57.957929 2026] [authz_core:error] [pid 491656:tid 491858] [client 216.73.216.128:51719] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:58.021825 2026] [security2:error] [pid 491656:tid 491885] [client 158.23.147.79:40907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/ws.php"] [unique_id "apPkKovX_L6VjdbvkkS4KAAAAvc"]
[Sun Aug 30 03:04:58.025387 2026] [security2:error] [pid 492549:tid 492729] [client 136.92.30.49:50456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/server-info.php"] [unique_id "apPkKjqFvOdCFO2AmwpVGAAAA9E"]
[Sun Aug 30 03:04:58.029465 2026] [security2:error] [pid 492549:tid 492717] [client 158.23.147.79:63284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-content/cong.php"] [unique_id "apPkKjqFvOdCFO2AmwpVHwAAA8U"]
[Sun Aug 30 03:04:58.033238 2026] [security2:error] [pid 492549:tid 492798] [client 20.220.204.93:64990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/aa.php"] [unique_id "apPkKjqFvOdCFO2AmwpVJQAABBY"]
[Sun Aug 30 03:04:58.075190 2026] [security2:error] [pid 492549:tid 492731] [client 158.23.184.117:60484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/wp-admin/theme-editor.php"] [unique_id "apPkKjqFvOdCFO2AmwpVOgAAA9M"]
[Sun Aug 30 03:04:58.083874 2026] [security2:error] [pid 492549:tid 492690] [client 20.48.251.3:6478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/gnmlc.php"] [unique_id "apPkKjqFvOdCFO2AmwpVQQAAA6o"]
[Sun Aug 30 03:04:58.101497 2026] [security2:error] [pid 492549:tid 492701] [client 20.48.251.3:7369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/wp-tem.php"] [unique_id "apPkKjqFvOdCFO2AmwpVSgAAA7U"]
[Sun Aug 30 03:04:58.115299 2026] [security2:error] [pid 491656:tid 491853] [client 20.151.200.44:47005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/admin.php/pindex.php"] [unique_id "apPkKovX_L6VjdbvkkS4bAAAAtc"]
[Sun Aug 30 03:04:58.117721 2026] [security2:error] [pid 491656:tid 491821] [client 158.23.147.79:40944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-includes/css/index.php"] [unique_id "apPkKovX_L6VjdbvkkS4bwAAArc"]
[Sun Aug 30 03:04:58.125844 2026] [authz_core:error] [pid 491656:tid 491866] [client 66.249.66.194:50732] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:58.126257 2026] [authz_core:error] [pid 491656:tid 491866] [client 66.249.66.194:50732] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:58.139510 2026] [security2:error] [pid 492549:tid 492810] [client 20.104.50.220:5919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/alfa.php"] [unique_id "apPkKjqFvOdCFO2AmwpVagAABCI"]
[Sun Aug 30 03:04:58.156243 2026] [security2:error] [pid 492549:tid 492791] [client 20.104.18.15:13734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkKjqFvOdCFO2AmwpVegAABA8"]
[Sun Aug 30 03:04:58.167977 2026] [security2:error] [pid 491656:tid 491863] [client 34.15.145.202:60460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/www/phpinfo.php"] [unique_id "apPkKovX_L6VjdbvkkS4mAAAAuE"]
[Sun Aug 30 03:04:58.217952 2026] [security2:error] [pid 491656:tid 491847] [client 20.48.251.3:55747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/userfuns.php"] [unique_id "apPkKovX_L6VjdbvkkS4wgAAAtE"]
[Sun Aug 30 03:04:58.222666 2026] [security2:error] [pid 492549:tid 492713] [client 20.48.251.3:4678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/a1vx.php"] [unique_id "apPkKjqFvOdCFO2AmwpVogAAA8E"]
[Sun Aug 30 03:04:58.238421 2026] [security2:error] [pid 492549:tid 492797] [client 68.155.159.216:59933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-includes/css/index.php"] [unique_id "apPkKjqFvOdCFO2AmwpVqgAABBU"]
[Sun Aug 30 03:04:58.245360 2026] [security2:error] [pid 492549:tid 492708] [client 158.23.147.79:26610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apPkKjqFvOdCFO2AmwpVtAAAA7w"]
[Sun Aug 30 03:04:58.247988 2026] [security2:error] [pid 491656:tid 491803] [client 20.104.50.220:61418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/plugins.php"] [unique_id "apPkKovX_L6VjdbvkkS42AAAAqU"]
[Sun Aug 30 03:04:58.248559 2026] [authz_core:error] [pid 491656:tid 491880] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:58.248897 2026] [authz_core:error] [pid 491656:tid 491880] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:58.261950 2026] [security2:error] [pid 492549:tid 492737] [client 20.104.18.15:31684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/wp-content/l.php"] [unique_id "apPkKjqFvOdCFO2AmwpVugAAA9k"]
[Sun Aug 30 03:04:58.264375 2026] [security2:error] [pid 492549:tid 492717] [client 20.104.50.220:51596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/tmv.php"] [unique_id "apPkKjqFvOdCFO2AmwpVvgAAA8U"]
[Sun Aug 30 03:04:58.292175 2026] [security2:error] [pid 492549:tid 492809] [client 20.220.204.93:64337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/s1.php"] [unique_id "apPkKjqFvOdCFO2AmwpVzQAABCE"]
[Sun Aug 30 03:04:58.340887 2026] [security2:error] [pid 492549:tid 492758] [client 158.23.147.79:40312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-content/cong.php"] [unique_id "apPkKjqFvOdCFO2AmwpWEQAAA-4"]
[Sun Aug 30 03:04:58.351198 2026] [security2:error] [pid 491656:tid 491818] [client 40.83.93.50:14279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/h.php"] [unique_id "apPkKovX_L6VjdbvkkS5CwAAArQ"]
[Sun Aug 30 03:04:58.365399 2026] [security2:error] [pid 491656:tid 491886] [client 20.48.251.3:44126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/nzv.php"] [unique_id "apPkKovX_L6VjdbvkkS5FwAAAvg"]
[Sun Aug 30 03:04:58.388846 2026] [security2:error] [pid 491656:tid 491786] [remote 170.64.135.172:38784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.135.64.170.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "invehicleinfotainments.com.maarifado.com"] [uri "/wp-login.php"] [unique_id "apPkKovX_L6VjdbvkkS5IwACvnw"]
[Sun Aug 30 03:04:58.412097 2026] [security2:error] [pid 491656:tid 491851] [client 20.48.251.3:23052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/ws62.php"] [unique_id "apPkKovX_L6VjdbvkkS5QAAAAtU"]
[Sun Aug 30 03:04:58.414053 2026] [security2:error] [pid 492549:tid 492776] [client 20.104.50.220:46648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/robot.php"] [unique_id "apPkKjqFvOdCFO2AmwpWOQAABAA"]
[Sun Aug 30 03:04:58.424762 2026] [authz_core:error] [pid 492549:tid 492704] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus%2Fdrivers%2Fi2c%3Asmbus_alert
[Sun Aug 30 03:04:58.425062 2026] [authz_core:error] [pid 492549:tid 492704] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus%2Fdrivers%2Fi2c%3Asmbus_alert
[Sun Aug 30 03:04:58.432561 2026] [security2:error] [pid 491656:tid 491816] [client 20.48.251.3:51480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/fun.php"] [unique_id "apPkKovX_L6VjdbvkkS5TgAAArI"]
[Sun Aug 30 03:04:58.438127 2026] [security2:error] [pid 492549:tid 492774] [client 34.15.141.119:54104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/old/phpinfo.php"] [unique_id "apPkKjqFvOdCFO2AmwpWSAAAA_4"]
[Sun Aug 30 03:04:58.450225 2026] [security2:error] [pid 492549:tid 492716] [client 20.220.204.93:64355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/0byte.php"] [unique_id "apPkKjqFvOdCFO2AmwpWVwAAA8Q"]
[Sun Aug 30 03:04:58.453750 2026] [security2:error] [pid 492549:tid 492717] [client 158.23.184.117:60489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/termps.php"] [unique_id "apPkKjqFvOdCFO2AmwpWXAAAA8U"]
[Sun Aug 30 03:04:58.459040 2026] [security2:error] [pid 492549:tid 492789] [client 136.92.30.49:50464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/server-status.php"] [unique_id "apPkKjqFvOdCFO2AmwpWXwAABA0"]
[Sun Aug 30 03:04:58.464877 2026] [security2:error] [pid 492549:tid 492688] [client 158.23.147.79:40285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPkKjqFvOdCFO2AmwpWZQAAA6g"]
[Sun Aug 30 03:04:58.490224 2026] [security2:error] [pid 491656:tid 491818] [client 20.104.50.220:33537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/smtphec.php"] [unique_id "apPkKovX_L6VjdbvkkS5ewAAArQ"]
[Sun Aug 30 03:04:58.492909 2026] [security2:error] [pid 491656:tid 491832] [client 20.104.50.220:28686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/Lol.php"] [unique_id "apPkKovX_L6VjdbvkkS5gAAAAsI"]
[Sun Aug 30 03:04:58.508249 2026] [authz_core:error] [pid 491656:tid 491842] [client 66.249.66.76:42656] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:58.508626 2026] [authz_core:error] [pid 491656:tid 491842] [client 66.249.66.76:42656] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:58.537091 2026] [security2:error] [pid 491656:tid 491793] [client 20.104.18.15:32998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/aa.php"] [unique_id "apPkKovX_L6VjdbvkkS5oAAAAps"]
[Sun Aug 30 03:04:58.548736 2026] [security2:error] [pid 491656:tid 491914] [client 20.48.251.3:50011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/phpsysinfo.php"] [unique_id "apPkKovX_L6VjdbvkkS5qAAAAxQ"]
[Sun Aug 30 03:04:58.562690 2026] [security2:error] [pid 492549:tid 492741] [client 20.197.61.180:21109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/upgrade-temp-backup/themes/admin.php"] [unique_id "apPkKjqFvOdCFO2AmwpWlQAAA90"]
[Sun Aug 30 03:04:58.591717 2026] [security2:error] [pid 492549:tid 492716] [client 158.23.184.117:60494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/fix.php"] [unique_id "apPkKjqFvOdCFO2AmwpWoAAAA8Q"]
[Sun Aug 30 03:04:58.603579 2026] [security2:error] [pid 492549:tid 492768] [client 158.23.147.79:40262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPkKjqFvOdCFO2AmwpWogAAA_g"]
[Sun Aug 30 03:04:58.679821 2026] [security2:error] [pid 491656:tid 491875] [client 216.73.216.128:31165] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPkKovX_L6VjdbvkkS5_gAAAu0"]
[Sun Aug 30 03:04:58.729283 2026] [security2:error] [pid 492549:tid 492774] [client 158.23.184.117:58056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/wp-includes/ID3/admin.php"] [unique_id "apPkKjqFvOdCFO2AmwpW3wAAA_4"]
[Sun Aug 30 03:04:58.742987 2026] [security2:error] [pid 492549:tid 492783] [client 20.48.251.3:65515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/ws62.php"] [unique_id "apPkKjqFvOdCFO2AmwpW5wAABAc"]
[Sun Aug 30 03:04:58.746269 2026] [security2:error] [pid 491656:tid 491808] [client 20.220.204.93:64347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/xr.php"] [unique_id "apPkKovX_L6VjdbvkkS6LQAAAqo"]
[Sun Aug 30 03:04:58.766506 2026] [authz_core:error] [pid 491656:tid 491811] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:58.766925 2026] [authz_core:error] [pid 491656:tid 491811] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:58.769200 2026] [security2:error] [pid 491656:tid 491821] [client 34.15.145.202:60462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/htdocs/phpinfo.php"] [unique_id "apPkKovX_L6VjdbvkkS6PAAAArc"]
[Sun Aug 30 03:04:58.797279 2026] [security2:error] [pid 492549:tid 492747] [client 20.104.50.220:62839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-config-blog.php"] [unique_id "apPkKjqFvOdCFO2AmwpXGQAAA-M"]
[Sun Aug 30 03:04:58.818158 2026] [security2:error] [pid 492549:tid 492761] [client 68.155.159.216:52777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-mail.php"] [unique_id "apPkKjqFvOdCFO2AmwpXMQAAA_E"]
[Sun Aug 30 03:04:58.826248 2026] [security2:error] [pid 491656:tid 491829] [client 158.23.147.79:40912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apPkKovX_L6VjdbvkkS6WwAAAr8"]
[Sun Aug 30 03:04:58.864089 2026] [security2:error] [pid 491656:tid 491880] [client 40.83.93.50:9105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/num.php"] [unique_id "apPkKovX_L6VjdbvkkS6cAAAAvI"]
[Sun Aug 30 03:04:58.868702 2026] [security2:error] [pid 492549:tid 492779] [client 158.23.184.117:60528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/tiny.php"] [unique_id "apPkKjqFvOdCFO2AmwpXRwAABAM"]
[Sun Aug 30 03:04:58.887737 2026] [security2:error] [pid 492549:tid 492701] [client 68.155.159.216:52726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apPkKjqFvOdCFO2AmwpXVgAAA7U"]
[Sun Aug 30 03:04:58.905309 2026] [authz_core:error] [pid 492549:tid 492791] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fbind%2Fsample%2Fvar%2Fnamed
[Sun Aug 30 03:04:58.905836 2026] [authz_core:error] [pid 492549:tid 492791] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fbind%2Fsample%2Fvar%2Fnamed
[Sun Aug 30 03:04:58.923318 2026] [security2:error] [pid 491656:tid 491805] [client 158.23.147.79:40280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-content/radio.php"] [unique_id "apPkKovX_L6VjdbvkkS6kQAAAqc"]
[Sun Aug 30 03:04:58.946758 2026] [security2:error] [pid 492549:tid 492730] [client 20.104.50.220:31893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/159.php"] [unique_id "apPkKjqFvOdCFO2AmwpXbgAAA9I"]
[Sun Aug 30 03:04:58.959413 2026] [authz_core:error] [pid 491656:tid 491803] [client 66.249.66.37:56908] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:58.959856 2026] [authz_core:error] [pid 491656:tid 491803] [client 66.249.66.37:56908] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:58.961872 2026] [security2:error] [pid 492549:tid 492776] [client 158.23.147.79:62531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPkKjqFvOdCFO2AmwpXcgAABAA"]
[Sun Aug 30 03:04:58.983359 2026] [security2:error] [pid 491656:tid 491846] [client 20.104.18.15:8968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/wp-activate.php"] [unique_id "apPkKovX_L6VjdbvkkS6twAAAtA"]
[Sun Aug 30 03:04:58.994856 2026] [security2:error] [pid 491656:tid 491830] [client 20.151.200.44:58891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/im.php"] [unique_id "apPkKovX_L6VjdbvkkS6wQAAAsA"]
[Sun Aug 30 03:04:59.008664 2026] [security2:error] [pid 492549:tid 492700] [client 158.23.184.117:15253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/css/classwithtostring.php"] [unique_id "apPkKzqFvOdCFO2AmwpXggAAA7Q"]
[Sun Aug 30 03:04:59.021747 2026] [security2:error] [pid 491656:tid 491811] [client 158.23.147.79:40932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apPkK4vX_L6VjdbvkkS60gAAAq0"]
[Sun Aug 30 03:04:59.038180 2026] [security2:error] [pid 492549:tid 492750] [client 34.15.141.119:54116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/tmp/phpinfo.php"] [unique_id "apPkKzqFvOdCFO2AmwpXiwAAA-Y"]
[Sun Aug 30 03:04:59.089719 2026] [security2:error] [pid 491656:tid 491884] [client 20.104.18.15:43325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/adminfuns.php"] [unique_id "apPkK4vX_L6VjdbvkkS7AgAAAvY"]
[Sun Aug 30 03:04:59.132007 2026] [security2:error] [pid 492549:tid 492725] [client 158.23.147.79:40910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/login.php"] [unique_id "apPkKzqFvOdCFO2AmwpXywAAA80"]
[Sun Aug 30 03:04:59.136801 2026] [authz_core:error] [pid 491656:tid 491911] [client 66.249.66.70:52831] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:59.137282 2026] [authz_core:error] [pid 491656:tid 491911] [client 66.249.66.70:52831] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:59.148980 2026] [security2:error] [pid 491656:tid 491661] [remote 170.64.135.172:38784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.135.64.170.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "invehicleinfotainments.com.maarifado.com"] [uri "/wp-login.php"] [unique_id "apPkK4vX_L6VjdbvkkS7MgACowA"], referer: https://invehicleinfotainments.com.maarifado.com/wp-login.php
[Sun Aug 30 03:04:59.149751 2026] [security2:error] [pid 492549:tid 492760] [client 158.23.184.117:58100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/buy.php"] [unique_id "apPkKzqFvOdCFO2AmwpX3wAAA_A"]
[Sun Aug 30 03:04:59.198012 2026] [security2:error] [pid 492549:tid 492798] [client 20.63.219.114:10660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/data.php"] [unique_id "apPkKzqFvOdCFO2AmwpYDAAABBY"]
[Sun Aug 30 03:04:59.247591 2026] [authz_core:error] [pid 491656:tid 491834] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:59.248024 2026] [authz_core:error] [pid 491656:tid 491834] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:59.249760 2026] [security2:error] [pid 492549:tid 492787] [client 158.23.147.79:40308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/hehehehe.php"] [unique_id "apPkKzqFvOdCFO2AmwpYLgAABAs"]
[Sun Aug 30 03:04:59.284901 2026] [security2:error] [pid 491656:tid 491892] [client 20.220.204.93:64258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/h02ugyh.php"] [unique_id "apPkK4vX_L6VjdbvkkS7cAAAAv4"]
[Sun Aug 30 03:04:59.285820 2026] [security2:error] [pid 492549:tid 492783] [client 20.197.61.180:13924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/upgrade-temp-backup/themes/login.php"] [unique_id "apPkKzqFvOdCFO2AmwpYTAAABAc"]
[Sun Aug 30 03:04:59.292901 2026] [security2:error] [pid 492549:tid 492766] [client 158.23.184.117:15234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/bk.php"] [unique_id "apPkKzqFvOdCFO2AmwpYUQAAA_Y"]
[Sun Aug 30 03:04:59.307634 2026] [security2:error] [pid 492549:tid 492778] [client 20.104.50.220:5443] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.camboconsulting.cover789.com"] [uri "/1.php"] [unique_id "apPkKzqFvOdCFO2AmwpYaQAABAI"]
[Sun Aug 30 03:04:59.307733 2026] [security2:error] [pid 492549:tid 492778] [client 20.104.50.220:5443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/1.php"] [unique_id "apPkKzqFvOdCFO2AmwpYaQAABAI"]
[Sun Aug 30 03:04:59.326777 2026] [security2:error] [pid 492549:tid 492768] [client 20.104.18.15:13704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/ap.php"] [unique_id "apPkKzqFvOdCFO2AmwpYiAAAA_g"]
[Sun Aug 30 03:04:59.352883 2026] [security2:error] [pid 491656:tid 491906] [client 20.48.251.3:55731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/mamzi.php"] [unique_id "apPkK4vX_L6VjdbvkkS7lAAAAww"]
[Sun Aug 30 03:04:59.354394 2026] [security2:error] [pid 491656:tid 491827] [client 20.151.200.44:58902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/file.php"] [unique_id "apPkK4vX_L6VjdbvkkS7lwAAAr0"]
[Sun Aug 30 03:04:59.360872 2026] [security2:error] [pid 492549:tid 492775] [client 20.48.251.3:44336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/public/vx.php"] [unique_id "apPkKzqFvOdCFO2AmwpYrQAAA_8"]
[Sun Aug 30 03:04:59.372315 2026] [security2:error] [pid 492549:tid 492767] [client 34.15.145.202:60472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/public_html/phpinfo.php"] [unique_id "apPkKzqFvOdCFO2AmwpYuwAAA_c"]
[Sun Aug 30 03:04:59.385579 2026] [security2:error] [pid 491656:tid 491821] [client 68.155.159.216:54088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apPkK4vX_L6VjdbvkkS7rAAAArc"]
[Sun Aug 30 03:04:59.389952 2026] [security2:error] [pid 492549:tid 492797] [client 20.104.50.220:61636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-content/priv8.php"] [unique_id "apPkKzqFvOdCFO2AmwpYxAAABBU"]
[Sun Aug 30 03:04:59.395179 2026] [authz_core:error] [pid 492549:tid 492778] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:59.395636 2026] [authz_core:error] [pid 492549:tid 492778] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:04:59.405697 2026] [security2:error] [pid 492549:tid 492765] [client 40.83.93.50:8349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/abc.php"] [unique_id "apPkKzqFvOdCFO2AmwpYyQAAA_U"]
[Sun Aug 30 03:04:59.406236 2026] [security2:error] [pid 491656:tid 491905] [client 20.104.18.15:31650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/wp-admin/w.php"] [unique_id "apPkK4vX_L6VjdbvkkS7uwAAAws"]
[Sun Aug 30 03:04:59.406672 2026] [security2:error] [pid 491656:tid 491874] [client 216.73.216.128:51719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPkK4vX_L6VjdbvkkS7vAAAAuw"]
[Sun Aug 30 03:04:59.409678 2026] [security2:error] [pid 491656:tid 491904] [client 20.104.50.220:42798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/terminal.php"] [unique_id "apPkK4vX_L6VjdbvkkS7wAAAAwo"]
[Sun Aug 30 03:04:59.426723 2026] [security2:error] [pid 492549:tid 492770] [client 158.23.147.79:40279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apPkKzqFvOdCFO2AmwpY4AAAA_o"]
[Sun Aug 30 03:04:59.433315 2026] [security2:error] [pid 492549:tid 492758] [client 158.23.184.117:58074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/.trash7309/index.php"] [unique_id "apPkKzqFvOdCFO2AmwpY5AAAA-4"]
[Sun Aug 30 03:04:59.528804 2026] [security2:error] [pid 492549:tid 492756] [client 158.23.147.79:26584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-content/admin.php"] [unique_id "apPkKzqFvOdCFO2AmwpZIAAAA-w"]
[Sun Aug 30 03:04:59.532508 2026] [security2:error] [pid 491656:tid 491807] [client 20.151.200.44:58926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/ca.php"] [unique_id "apPkK4vX_L6VjdbvkkS8CwAAAqk"]
[Sun Aug 30 03:04:59.549965 2026] [security2:error] [pid 491656:tid 491886] [client 20.63.219.114:17202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/hideo/network.php"] [unique_id "apPkK4vX_L6VjdbvkkS8FAAAAvg"]
[Sun Aug 30 03:04:59.552720 2026] [security2:error] [pid 491656:tid 491815] [client 20.48.251.3:6516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/66.php"] [unique_id "apPkK4vX_L6VjdbvkkS8FQAAArE"]
[Sun Aug 30 03:04:59.552755 2026] [security2:error] [pid 491656:tid 491917] [client 20.104.50.220:47067] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "523"] [id "900207"] [msg "Sys[0-9]+ Mailer"] [hostname "cpanel.ianegenolf.com"] [uri "/sys32.php"] [unique_id "apPkK4vX_L6VjdbvkkS8FgAAAxc"]
[Sun Aug 30 03:04:59.563257 2026] [security2:error] [pid 491656:tid 491890] [client 20.48.251.3:23472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/grsiuk.php"] [unique_id "apPkK4vX_L6VjdbvkkS8HwAAAvw"]
[Sun Aug 30 03:04:59.569260 2026] [security2:error] [pid 491656:tid 491907] [client 20.48.251.3:59095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/kedi.php"] [unique_id "apPkK4vX_L6VjdbvkkS8JAAAAw0"]
[Sun Aug 30 03:04:59.572289 2026] [security2:error] [pid 492549:tid 492732] [client 158.23.184.117:58064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/jp.php"] [unique_id "apPkKzqFvOdCFO2AmwpZLwAAA9Q"]
[Sun Aug 30 03:04:59.638564 2026] [security2:error] [pid 492549:tid 492750] [client 34.15.141.119:54132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/public/phpinfo.php"] [unique_id "apPkKzqFvOdCFO2AmwpZVwAAA-Y"]
[Sun Aug 30 03:04:59.638564 2026] [security2:error] [pid 491656:tid 491827] [client 20.104.50.220:33181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/s_on.php"] [unique_id "apPkK4vX_L6VjdbvkkS8SgAAAr0"]
[Sun Aug 30 03:04:59.639872 2026] [security2:error] [pid 492549:tid 492780] [client 20.104.50.220:27086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkKzqFvOdCFO2AmwpZWAAABAQ"]
[Sun Aug 30 03:04:59.653002 2026] [authz_core:error] [pid 491656:tid 491824] [client 66.249.66.32:52459] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:59.653335 2026] [authz_core:error] [pid 491656:tid 491824] [client 66.249.66.32:52459] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:59.659123 2026] [security2:error] [pid 491656:tid 491841] [client 20.151.200.44:47095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/admin.php/csv.php"] [unique_id "apPkK4vX_L6VjdbvkkS8WAAAAss"]
[Sun Aug 30 03:04:59.660404 2026] [security2:error] [pid 491656:tid 491890] [client 158.23.147.79:40917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/xmlrpc.php"] [unique_id "apPkK4vX_L6VjdbvkkS8WgAAAvw"]
[Sun Aug 30 03:04:59.683739 2026] [security2:error] [pid 491656:tid 491826] [client 20.104.18.15:32993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/img.php"] [unique_id "apPkK4vX_L6VjdbvkkS8YgAAArw"]
[Sun Aug 30 03:04:59.695604 2026] [security2:error] [pid 492549:tid 492752] [client 20.48.251.3:55448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/sgd.php"] [unique_id "apPkKzqFvOdCFO2AmwpZdQAAA-g"]
[Sun Aug 30 03:04:59.709750 2026] [security2:error] [pid 491656:tid 491907] [client 158.23.184.117:58095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/item.php"] [unique_id "apPkK4vX_L6VjdbvkkS8dAAAAw0"]
[Sun Aug 30 03:04:59.746783 2026] [authz_core:error] [pid 491656:tid 491845] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:59.747216 2026] [authz_core:error] [pid 491656:tid 491845] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:04:59.771409 2026] [security2:error] [pid 491656:tid 491797] [client 216.73.216.128:6479] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPkK4vX_L6VjdbvkkS8mwAAAp8"]
[Sun Aug 30 03:04:59.793179 2026] [authz_core:error] [pid 491656:tid 491799] [client 66.249.66.43:64542] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:04:59.793719 2026] [authz_core:error] [pid 491656:tid 491799] [client 66.249.66.43:64542] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:04:59.811942 2026] [security2:error] [pid 492549:tid 492689] [client 158.23.147.79:40946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/atomlib.php"] [unique_id "apPkKzqFvOdCFO2AmwpZxwAAA6k"]
[Sun Aug 30 03:04:59.820851 2026] [security2:error] [pid 491656:tid 491840] [client 20.104.50.220:28688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/b2.php"] [unique_id "apPkK4vX_L6VjdbvkkS8vAAAAso"]
[Sun Aug 30 03:04:59.850775 2026] [security2:error] [pid 492549:tid 492789] [client 158.23.184.117:58094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/wp-admin/controller.php"] [unique_id "apPkKzqFvOdCFO2AmwpZ5gAABA0"]
[Sun Aug 30 03:04:59.850985 2026] [security2:error] [pid 492549:tid 492719] [client 136.92.30.49:50490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/webroot/index.php/_environment"] [unique_id "apPkKzqFvOdCFO2AmwpZ5wAAA8c"]
[Sun Aug 30 03:04:59.870107 2026] [security2:error] [pid 492549:tid 492747] [client 20.220.204.93:63824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/xxw.php"] [unique_id "apPkKzqFvOdCFO2AmwpZ6wAAA-M"]
[Sun Aug 30 03:04:59.900275 2026] [security2:error] [pid 491656:tid 491901] [client 20.48.251.3:46265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/grsiuk.php"] [unique_id "apPkK4vX_L6VjdbvkkS88AAAAwc"]
[Sun Aug 30 03:04:59.905959 2026] [security2:error] [pid 492549:tid 492740] [client 20.63.219.114:10669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/index.php"] [unique_id "apPkKzqFvOdCFO2AmwpaAgAAA9w"]
[Sun Aug 30 03:04:59.907413 2026] [authz_core:error] [pid 492549:tid 492810] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fbind%2Fsample%2Fvar%2Fnamed
[Sun Aug 30 03:04:59.907705 2026] [authz_core:error] [pid 492549:tid 492810] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Fbind%2Fsample%2Fvar%2Fnamed
[Sun Aug 30 03:04:59.914465 2026] [security2:error] [pid 492549:tid 492730] [client 40.83.93.50:8350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/default.php"] [unique_id "apPkKzqFvOdCFO2AmwpaBQAAA9I"]
[Sun Aug 30 03:04:59.922142 2026] [core:error] [pid 491656:tid 491870] [client 158.23.184.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:04:59.922156 2026] [core:error] [pid 491656:tid 491870] [client 158.23.184.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:04:59.933126 2026] [security2:error] [pid 492549:tid 492707] [client 20.151.200.44:58915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/pb.php"] [unique_id "apPkKzqFvOdCFO2AmwpaBwAAA7s"]
[Sun Aug 30 03:04:59.940343 2026] [security2:error] [pid 492549:tid 492697] [client 68.155.159.216:60580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/cgi-bin/index.php"] [unique_id "apPkKzqFvOdCFO2AmwpaCwAAA7E"]
[Sun Aug 30 03:04:59.951680 2026] [security2:error] [pid 491656:tid 491853] [client 20.104.50.220:52840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-thumbs.php"] [unique_id "apPkK4vX_L6VjdbvkkS9BAAAAtc"]
[Sun Aug 30 03:04:59.971213 2026] [security2:error] [pid 491656:tid 491813] [client 34.15.145.202:60476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/site/phpinfo.php"] [unique_id "apPkK4vX_L6VjdbvkkS9DQAAAq8"]
[Sun Aug 30 03:04:59.988747 2026] [security2:error] [pid 492549:tid 492809] [client 158.23.147.79:40261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/lv.php"] [unique_id "apPkKzqFvOdCFO2AmwpaJwAABCE"]
[Sun Aug 30 03:05:00.016992 2026] [security2:error] [pid 492549:tid 492757] [client 20.197.61.180:13905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/upgrade-temp-backup/themes/test.php"] [unique_id "apPkLDqFvOdCFO2AmwpaPAAAA-0"]
[Sun Aug 30 03:05:00.046349 2026] [security2:error] [pid 492549:tid 492723] [client 68.155.159.216:52634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/dropdown.php"] [unique_id "apPkLDqFvOdCFO2AmwpaTQAAA8s"]
[Sun Aug 30 03:05:00.085410 2026] [autoindex:error] [pid 492549:tid 492782] [client 158.23.184.117:60497] AH01276: Cannot serve directory /home3/mvdb/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:05:00.109696 2026] [security2:error] [pid 492549:tid 492696] [client 158.23.147.79:40263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apPkLDqFvOdCFO2AmwpajQAAA7A"]
[Sun Aug 30 03:05:00.111323 2026] [authz_core:error] [pid 491656:tid 491840] [client 66.249.66.41:53471] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:00.111695 2026] [authz_core:error] [pid 491656:tid 491840] [client 66.249.66.41:53471] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:00.131512 2026] [security2:error] [pid 492549:tid 492683] [client 158.23.184.117:60497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/wp-configs.php"] [unique_id "apPkLDqFvOdCFO2AmwpaoQAAA6M"]
[Sun Aug 30 03:05:00.133065 2026] [security2:error] [pid 492549:tid 492779] [client 20.151.200.44:58824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/pk.php"] [unique_id "apPkLDqFvOdCFO2AmwpaowAABAM"]
[Sun Aug 30 03:05:00.178018 2026] [security2:error] [pid 492549:tid 492750] [client 20.104.18.15:9027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/wp-trackback.php"] [unique_id "apPkLDqFvOdCFO2Amwpa2QAAA-Y"]
[Sun Aug 30 03:05:00.198885 2026] [security2:error] [pid 492549:tid 492795] [client 20.104.50.220:32546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/tesla1.php"] [unique_id "apPkLDqFvOdCFO2Amwpa8gAABBM"]
[Sun Aug 30 03:05:00.228169 2026] [security2:error] [pid 491656:tid 491875] [client 158.23.147.79:40302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/content.php"] [unique_id "apPkLIvX_L6VjdbvkkS9iQAAAu0"]
[Sun Aug 30 03:05:00.252416 2026] [security2:error] [pid 492549:tid 492692] [client 20.104.18.15:43313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/classwithtostring.php"] [unique_id "apPkLDqFvOdCFO2AmwpbEwAAA6w"]
[Sun Aug 30 03:05:00.254311 2026] [security2:error] [pid 491656:tid 491865] [client 20.63.219.114:17171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/intense/block-css.php"] [unique_id "apPkLIvX_L6VjdbvkkS9kgAAAuM"]
[Sun Aug 30 03:05:00.273824 2026] [security2:error] [pid 492549:tid 492750] [client 158.23.184.117:58085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/wp-admin/user/credits.php"] [unique_id "apPkLDqFvOdCFO2AmwpbJQAAA-Y"]
[Sun Aug 30 03:05:00.293556 2026] [security2:error] [pid 492549:tid 492801] [client 136.92.30.49:50500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/mail/phpinfo.php"] [unique_id "apPkLDqFvOdCFO2AmwpbOwAABBk"]
[Sun Aug 30 03:05:00.299112 2026] [authz_core:error] [pid 491656:tid 491813] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:05:00.299445 2026] [authz_core:error] [pid 491656:tid 491813] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:05:00.317856 2026] [security2:error] [pid 491656:tid 491874] [client 216.73.216.128:31165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/sasl/developer/programming.html"] [unique_id "apPkLIvX_L6VjdbvkkS9tQAAAuw"]
[Sun Aug 30 03:05:00.320268 2026] [security2:error] [pid 492549:tid 492707] [client 20.151.200.44:58823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/ft.php"] [unique_id "apPkLDqFvOdCFO2AmwpbYwAAA7s"]
[Sun Aug 30 03:05:00.327851 2026] [security2:error] [pid 491656:tid 491798] [client 4.205.62.107:31699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/pass4.php"] [unique_id "apPkLIvX_L6VjdbvkkS9ugAAAqA"]
[Sun Aug 30 03:05:00.336833 2026] [security2:error] [pid 491656:tid 491826] [client 4.205.62.107:32032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/ms.php"] [unique_id "apPkLIvX_L6VjdbvkkS9vwAAArw"]
[Sun Aug 30 03:05:00.339855 2026] [security2:error] [pid 492549:tid 492732] [client 158.23.147.79:40266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPkLDqFvOdCFO2AmwpbfAAAA9Q"]
[Sun Aug 30 03:05:00.347813 2026] [security2:error] [pid 492549:tid 492730] [client 20.220.204.93:64378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/bolt.php"] [unique_id "apPkLDqFvOdCFO2AmwpbggAAA9I"]
[Sun Aug 30 03:05:00.392179 2026] [security2:error] [pid 492549:tid 492797] [client 40.83.93.50:9090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/cloud.php"] [unique_id "apPkLDqFvOdCFO2AmwpboAAABBU"]
[Sun Aug 30 03:05:00.394141 2026] [authz_core:error] [pid 492549:tid 492782] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:05:00.394418 2026] [authz_core:error] [pid 492549:tid 492782] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:05:00.411544 2026] [security2:error] [pid 492549:tid 492714] [client 158.23.184.117:60487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "apPkLDqFvOdCFO2AmwpbpgAAA8I"]
[Sun Aug 30 03:05:00.446208 2026] [security2:error] [pid 491656:tid 491818] [client 20.104.50.220:5546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/byp.php"] [unique_id "apPkLIvX_L6VjdbvkkS-BwAAArQ"]
[Sun Aug 30 03:05:00.452683 2026] [security2:error] [pid 492549:tid 492723] [client 34.15.141.119:54140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/php-info.php"] [unique_id "apPkLDqFvOdCFO2AmwpbyQAAA8s"]
[Sun Aug 30 03:05:00.453894 2026] [security2:error] [pid 492549:tid 492692] [client 158.23.147.79:26595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/goat.php"] [unique_id "apPkLDqFvOdCFO2AmwpbywAAA6w"]
[Sun Aug 30 03:05:00.465022 2026] [security2:error] [pid 492549:tid 492792] [client 20.104.18.15:13711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/media.php"] [unique_id "apPkLDqFvOdCFO2Amwpb2gAABBA"]
[Sun Aug 30 03:05:00.491180 2026] [security2:error] [pid 491656:tid 491890] [client 20.48.251.3:55715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/public/rip.php.php"] [unique_id "apPkLIvX_L6VjdbvkkS-JgAAAvw"]
[Sun Aug 30 03:05:00.514917 2026] [security2:error] [pid 492549:tid 492746] [client 20.48.251.3:44359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/log.php"] [unique_id "apPkLDqFvOdCFO2Amwpb9gAAA-I"]
[Sun Aug 30 03:05:00.522230 2026] [security2:error] [pid 492549:tid 492736] [client 20.104.49.130:57513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/dehnl.php"] [unique_id "apPkLDqFvOdCFO2AmwpcAQAAA9g"]
[Sun Aug 30 03:05:00.550500 2026] [security2:error] [pid 491656:tid 491837] [client 158.23.184.117:60519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/.well-known/about/function.php"] [unique_id "apPkLIvX_L6VjdbvkkS-RgAAAsc"]
[Sun Aug 30 03:05:00.562614 2026] [security2:error] [pid 492549:tid 492697] [client 20.104.18.15:31578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/wp-content/k.php"] [unique_id "apPkLDqFvOdCFO2AmwpcFAAAA7E"]
[Sun Aug 30 03:05:00.563494 2026] [security2:error] [pid 491656:tid 491796] [client 20.104.50.220:51536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/titid.php"] [unique_id "apPkLIvX_L6VjdbvkkS-SwAAAp4"]
[Sun Aug 30 03:05:00.575634 2026] [security2:error] [pid 491656:tid 491839] [client 34.15.145.202:60488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/docs/phpinfo.php"] [unique_id "apPkLIvX_L6VjdbvkkS-UgAAAsk"]
[Sun Aug 30 03:05:00.588617 2026] [security2:error] [pid 492549:tid 492796] [client 68.155.159.216:59927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-content/cong.php"] [unique_id "apPkLDqFvOdCFO2AmwpcIwAABBQ"]
[Sun Aug 30 03:05:00.589692 2026] [security2:error] [pid 492549:tid 492803] [client 158.23.147.79:40927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apPkLDqFvOdCFO2AmwpcJAAABBs"]
[Sun Aug 30 03:05:00.600185 2026] [security2:error] [pid 492549:tid 492732] [client 20.151.200.44:58936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/wp-ver.php"] [unique_id "apPkLDqFvOdCFO2AmwpcKAAAA9Q"]
[Sun Aug 30 03:05:00.600216 2026] [security2:error] [pid 491656:tid 491880] [client 20.63.219.114:15599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/login.php"] [unique_id "apPkLIvX_L6VjdbvkkS-WQAAAvI"]
[Sun Aug 30 03:05:00.605387 2026] [security2:error] [pid 492549:tid 492746] [client 20.104.50.220:61662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-admin/priv8.php"] [unique_id "apPkLDqFvOdCFO2AmwpcKgAAA-I"]
[Sun Aug 30 03:05:00.627929 2026] [security2:error] [pid 492549:tid 492786] [client 20.104.50.220:47041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkLDqFvOdCFO2AmwpcRwAABAo"]
[Sun Aug 30 03:05:00.650164 2026] [security2:error] [pid 491656:tid 491918] [client 20.220.204.93:63831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/rtx.php"] [unique_id "apPkLIvX_L6VjdbvkkS-cwAAAxg"]
[Sun Aug 30 03:05:00.688399 2026] [security2:error] [pid 491656:tid 491897] [client 20.104.50.220:46456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/simple_cmd.php"] [unique_id "apPkLIvX_L6VjdbvkkS-jwAAAwM"]
[Sun Aug 30 03:05:00.690622 2026] [security2:error] [pid 492549:tid 492775] [client 158.23.184.117:58071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPkLDqFvOdCFO2AmwpcaAAAA_8"]
[Sun Aug 30 03:05:00.704088 2026] [security2:error] [pid 492549:tid 492747] [client 20.48.251.3:22736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/paypal.php"] [unique_id "apPkLDqFvOdCFO2AmwpcbgAAA-M"]
[Sun Aug 30 03:05:00.707726 2026] [security2:error] [pid 492549:tid 492807] [client 20.48.251.3:34564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/oc460l3x.php"] [unique_id "apPkLDqFvOdCFO2AmwpccgAABB8"]
[Sun Aug 30 03:05:00.717033 2026] [security2:error] [pid 491656:tid 491812] [client 20.48.251.3:64465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/admin.php"] [unique_id "apPkLIvX_L6VjdbvkkS-nwAAAq4"]
[Sun Aug 30 03:05:00.731545 2026] [security2:error] [pid 492549:tid 492687] [client 136.92.30.49:50514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/cpanel/phpinfo.php"] [unique_id "apPkLDqFvOdCFO2AmwpcegAAA6c"]
[Sun Aug 30 03:05:00.741122 2026] [security2:error] [pid 492549:tid 492754] [client 20.197.61.180:14746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/upgrade-temp-backup/themes/wp-links-opml.php"] [unique_id "apPkLDqFvOdCFO2AmwpcgAAAA-o"]
[Sun Aug 30 03:05:00.749190 2026] [security2:error] [pid 491656:tid 491838] [client 158.23.147.79:26576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apPkLIvX_L6VjdbvkkS-tAAAAsg"]
[Sun Aug 30 03:05:00.776933 2026] [security2:error] [pid 492549:tid 492689] [client 20.104.50.220:27419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkLDqFvOdCFO2AmwpcmwAAA6k"]
[Sun Aug 30 03:05:00.782904 2026] [authz_core:error] [pid 491656:tid 491855] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:05:00.783199 2026] [authz_core:error] [pid 491656:tid 491855] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:05:00.790387 2026] [security2:error] [pid 492549:tid 492701] [client 20.104.50.220:33182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/selaras.php"] [unique_id "apPkLDqFvOdCFO2AmwpcpAAAA7U"]
[Sun Aug 30 03:05:00.817065 2026] [security2:error] [pid 492549:tid 492740] [client 20.104.18.15:33020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/222.php"] [unique_id "apPkLDqFvOdCFO2AmwpcwQAAA9w"]
[Sun Aug 30 03:05:00.831502 2026] [security2:error] [pid 491656:tid 491851] [client 20.48.251.3:55487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/fleen.php"] [unique_id "apPkLIvX_L6VjdbvkkS-6gAAAtU"]
[Sun Aug 30 03:05:00.832640 2026] [security2:error] [pid 491656:tid 491865] [client 158.23.184.117:58067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/gg.php"] [unique_id "apPkLIvX_L6VjdbvkkS-6wAAAuM"]
[Sun Aug 30 03:05:00.855879 2026] [security2:error] [pid 492549:tid 492751] [client 158.23.147.79:26596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apPkLDqFvOdCFO2Amwpc1AAAA-c"]
[Sun Aug 30 03:05:00.864158 2026] [security2:error] [pid 491656:tid 491908] [client 216.73.216.128:6479] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPkLIvX_L6VjdbvkkS-_AAAAw4"]
[Sun Aug 30 03:05:00.889246 2026] [security2:error] [pid 491656:tid 491829] [client 40.83.93.50:9100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/admin.php"] [unique_id "apPkLIvX_L6VjdbvkkS_DAAAAr8"]
[Sun Aug 30 03:05:00.897817 2026] [authz_core:error] [pid 492549:tid 492789] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:05:00.898125 2026] [authz_core:error] [pid 492549:tid 492789] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:05:00.912979 2026] [security2:error] [pid 491656:tid 491803] [client 158.23.184.117:59277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/cache/cache/min.php"] [unique_id "apPkLIvX_L6VjdbvkkS_FAAAAqU"]
[Sun Aug 30 03:05:00.920698 2026] [security2:error] [pid 492549:tid 492697] [client 20.220.204.93:64925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/ckk.php"] [unique_id "apPkLDqFvOdCFO2Amwpc-AAAA7E"]
[Sun Aug 30 03:05:00.948833 2026] [security2:error] [pid 491656:tid 491864] [client 20.63.219.114:10665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/min.php"] [unique_id "apPkLIvX_L6VjdbvkkS_KgAAAuI"]
[Sun Aug 30 03:05:00.963951 2026] [security2:error] [pid 491656:tid 491800] [client 20.104.50.220:64451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/ex.php"] [unique_id "apPkLIvX_L6VjdbvkkS_NwAAAqI"]
[Sun Aug 30 03:05:00.965131 2026] [security2:error] [pid 491656:tid 491833] [client 158.23.147.79:26608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/dropdown.php"] [unique_id "apPkLIvX_L6VjdbvkkS_OgAAAsM"]
[Sun Aug 30 03:05:00.974527 2026] [security2:error] [pid 491656:tid 491793] [client 158.23.184.117:58058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/wp-admin/includes/post.php"] [unique_id "apPkLIvX_L6VjdbvkkS_PwAAAps"]
[Sun Aug 30 03:05:01.043193 2026] [security2:error] [pid 492549:tid 492735] [client 158.23.147.79:62486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPkLTqFvOdCFO2AmwpdHAAAA9c"]
[Sun Aug 30 03:05:01.050870 2026] [security2:error] [pid 492549:tid 492741] [client 20.48.251.3:54779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/paypal.php"] [unique_id "apPkLTqFvOdCFO2AmwpdKgAAA90"]
[Sun Aug 30 03:05:01.054032 2026] [authz_core:error] [pid 491656:tid 491864] [client 216.73.216.128:6479] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:01.054490 2026] [authz_core:error] [pid 491656:tid 491864] [client 216.73.216.128:6479] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:01.054698 2026] [security2:error] [pid 492549:tid 492743] [client 158.23.184.117:23981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/catalogbypass.php"] [unique_id "apPkLTqFvOdCFO2AmwpdLQAAA98"]
[Sun Aug 30 03:05:01.060060 2026] [security2:error] [pid 492549:tid 492737] [client 34.15.141.119:54144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/phpversion.php"] [unique_id "apPkLTqFvOdCFO2AmwpdMQAAA9k"]
[Sun Aug 30 03:05:01.068266 2026] [security2:error] [pid 492549:tid 492716] [client 4.205.62.107:2350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/ms.php"] [unique_id "apPkLTqFvOdCFO2AmwpdOwAAA8Q"]
[Sun Aug 30 03:05:01.073483 2026] [autoindex:error] [pid 492549:tid 492773] [client 193.56.113.32:51012] AH01276: Cannot serve directory /home4/marcoabreuh/smartmenu.pro/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:05:01.097002 2026] [security2:error] [pid 492549:tid 492721] [client 20.104.50.220:62823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-mobfi.php"] [unique_id "apPkLTqFvOdCFO2AmwpdUgAAA8k"]
[Sun Aug 30 03:05:01.127592 2026] [security2:error] [pid 491656:tid 491801] [client 68.155.159.216:52830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPkLYvX_L6VjdbvkkS_oAAAAqM"]
[Sun Aug 30 03:05:01.151195 2026] [security2:error] [pid 492549:tid 492805] [client 158.23.147.79:40259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/sad/about.php"] [unique_id "apPkLTqFvOdCFO2AmwpdfgAABB0"]
[Sun Aug 30 03:05:01.157527 2026] [security2:error] [pid 492549:tid 492712] [client 20.48.251.3:7376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/txets.php"] [unique_id "apPkLTqFvOdCFO2AmwpdigAAA8A"]
[Sun Aug 30 03:05:01.164076 2026] [security2:error] [pid 491656:tid 491854] [client 158.23.184.117:60518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naccgl.org"] [uri "/wp-act.php"] [unique_id "apPkLYvX_L6VjdbvkkS_uAAAAtg"]
[Sun Aug 30 03:05:01.181450 2026] [security2:error] [pid 491656:tid 491828] [client 34.15.145.202:60504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/wp-admin/phpinfo.php"] [unique_id "apPkLYvX_L6VjdbvkkS_xAAAAr4"]
[Sun Aug 30 03:05:01.187676 2026] [security2:error] [pid 492549:tid 492724] [client 136.92.30.49:50530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/hosting/phpinfo.php"] [unique_id "apPkLTqFvOdCFO2AmwpdpgAAA8w"]
[Sun Aug 30 03:05:01.193106 2026] [security2:error] [pid 492549:tid 492761] [client 158.23.184.117:23966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/cc.php"] [unique_id "apPkLTqFvOdCFO2AmwpdqwAAA_E"]
[Sun Aug 30 03:05:01.210800 2026] [security2:error] [pid 492549:tid 492685] [client 68.155.159.216:54764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/sad/about.php"] [unique_id "apPkLTqFvOdCFO2AmwpduwAAA6U"]
[Sun Aug 30 03:05:01.250017 2026] [security2:error] [pid 491656:tid 491850] [client 158.23.147.79:40938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/admin.php"] [unique_id "apPkLYvX_L6VjdbvkkS_7QAAAtQ"]
[Sun Aug 30 03:05:01.258690 2026] [security2:error] [pid 492549:tid 492783] [client 4.205.62.107:18791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/phpi.php"] [unique_id "apPkLTqFvOdCFO2Amwpd0QAABAc"]
[Sun Aug 30 03:05:01.261930 2026] [authz_core:error] [pid 491656:tid 491903] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:05:01.262374 2026] [authz_core:error] [pid 491656:tid 491903] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:05:01.277196 2026] [security2:error] [pid 491656:tid 491815] [client 20.151.200.44:58845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/ah24.php"] [unique_id "apPkLYvX_L6VjdbvkkS__AAAArE"]
[Sun Aug 30 03:05:01.285826 2026] [security2:error] [pid 492549:tid 492797] [client 20.220.204.93:64317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.meilianfuinc.com"] [uri "/R57.php"] [unique_id "apPkLTqFvOdCFO2Amwpd6wAABBU"]
[Sun Aug 30 03:05:01.296094 2026] [security2:error] [pid 492549:tid 492793] [client 20.63.219.114:17196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/module.php"] [unique_id "apPkLTqFvOdCFO2Amwpd8QAABBE"]
[Sun Aug 30 03:05:01.305738 2026] [autoindex:error] [pid 492549:tid 492781] [client 193.56.113.32:51012] AH01276: Cannot serve directory /home4/marcoabreuh/smartmenu.pro/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:05:01.309662 2026] [security2:error] [pid 492549:tid 492758] [client 4.205.62.107:62080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/rum.or.php"] [unique_id "apPkLTqFvOdCFO2AmwpeBwAAA-4"]
[Sun Aug 30 03:05:01.311343 2026] [security2:error] [pid 492549:tid 492700] [client 4.205.62.107:65300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/apikeys.php"] [unique_id "apPkLTqFvOdCFO2AmwpeCQAAA7Q"]
[Sun Aug 30 03:05:01.332264 2026] [security2:error] [pid 491656:tid 491907] [client 158.23.184.117:59285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/cgi-bin/admin.php"] [unique_id "apPkLYvX_L6VjdbvkkTAJgAAAw0"]
[Sun Aug 30 03:05:01.342564 2026] [security2:error] [pid 492549:tid 492768] [client 20.104.18.15:9160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/pri.php"] [unique_id "apPkLTqFvOdCFO2AmwpeNQAAA_g"]
[Sun Aug 30 03:05:01.353432 2026] [security2:error] [pid 491656:tid 491865] [client 158.23.147.79:40269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-admin/admin.php"] [unique_id "apPkLYvX_L6VjdbvkkTANAAAAuM"]
[Sun Aug 30 03:05:01.353776 2026] [security2:error] [pid 491656:tid 491874] [client 20.104.50.220:31865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/shadowx.php"] [unique_id "apPkLYvX_L6VjdbvkkTANQAAAuw"]
[Sun Aug 30 03:05:01.420002 2026] [security2:error] [pid 491656:tid 491814] [client 20.104.18.15:43283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPkLYvX_L6VjdbvkkTAZgAAArA"]
[Sun Aug 30 03:05:01.436202 2026] [authz_core:error] [pid 492549:tid 492738] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:05:01.436664 2026] [authz_core:error] [pid 492549:tid 492738] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:05:01.472528 2026] [security2:error] [pid 492549:tid 492717] [client 158.23.147.79:40294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apPkLTqFvOdCFO2AmwpekQAAA8U"]
[Sun Aug 30 03:05:01.474100 2026] [security2:error] [pid 492549:tid 492710] [client 20.197.61.180:9167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/upgrade-temp-backup/themes/wp-settings.php"] [unique_id "apPkLTqFvOdCFO2AmwpekgAAA74"]
[Sun Aug 30 03:05:01.479539 2026] [security2:error] [pid 492549:tid 492730] [client 40.83.93.50:8322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/index.php"] [unique_id "apPkLTqFvOdCFO2AmwpelwAAA9I"]
[Sun Aug 30 03:05:01.524919 2026] [security2:error] [pid 492549:tid 492795] [client 193.56.113.32:51012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "smartmenu.pro"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "apPkLTqFvOdCFO2AmwpexQAABBM"]
[Sun Aug 30 03:05:01.525222 2026] [security2:error] [pid 492549:tid 492687] [client 20.151.200.44:58837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPkLTqFvOdCFO2AmwpexgAAA6c"]
[Sun Aug 30 03:05:01.541540 2026] [security2:error] [pid 492549:tid 492790] [client 158.23.147.79:63282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apPkLTqFvOdCFO2AmwpezAAABA4"]
[Sun Aug 30 03:05:01.565765 2026] [security2:error] [pid 492549:tid 492711] [client 4.205.62.107:25508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/bigdump.php"] [unique_id "apPkLTqFvOdCFO2Amwpe4QAAA78"]
[Sun Aug 30 03:05:01.572477 2026] [security2:error] [pid 492549:tid 492728] [client 158.23.147.79:40313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/classwithtostring.php"] [unique_id "apPkLTqFvOdCFO2Amwpe7QAAA9A"]
[Sun Aug 30 03:05:01.600973 2026] [security2:error] [pid 491656:tid 491858] [client 20.104.50.220:5564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-trackback.php"] [unique_id "apPkLYvX_L6VjdbvkkTAsAAAAtw"]
[Sun Aug 30 03:05:01.602817 2026] [authz_core:error] [pid 491656:tid 491804] [client 216.73.216.128:7790] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:01.603624 2026] [authz_core:error] [pid 491656:tid 491804] [client 216.73.216.128:7790] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:01.604707 2026] [security2:error] [pid 492549:tid 492687] [client 20.104.18.15:13660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/adminfuns.php"] [unique_id "apPkLTqFvOdCFO2AmwpfAwAAA6c"]
[Sun Aug 30 03:05:01.627163 2026] [security2:error] [pid 492549:tid 492733] [client 136.92.30.49:50544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/webmail/phpinfo.php"] [unique_id "apPkLTqFvOdCFO2AmwpfEQAAA9U"]
[Sun Aug 30 03:05:01.628910 2026] [security2:error] [pid 492549:tid 492692] [client 20.48.251.3:59280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/environment.php"] [unique_id "apPkLTqFvOdCFO2AmwpfEwAAA6w"]
[Sun Aug 30 03:05:01.643721 2026] [security2:error] [pid 492549:tid 492718] [client 20.63.219.114:15556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/ms-files.php"] [unique_id "apPkLTqFvOdCFO2AmwpfIwAAA8Y"]
[Sun Aug 30 03:05:01.662578 2026] [security2:error] [pid 492549:tid 492685] [client 34.15.141.119:54160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/_phpinfo.php"] [unique_id "apPkLTqFvOdCFO2AmwpfLQAAA6U"]
[Sun Aug 30 03:05:01.670050 2026] [security2:error] [pid 491656:tid 491830] [client 158.23.147.79:62563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-content/radio.php"] [unique_id "apPkLYvX_L6VjdbvkkTA4gAAAsA"]
[Sun Aug 30 03:05:01.682724 2026] [security2:error] [pid 491656:tid 491861] [client 158.23.147.79:40282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/install.php"] [unique_id "apPkLYvX_L6VjdbvkkTA5gAAAt8"]
[Sun Aug 30 03:05:01.702614 2026] [security2:error] [pid 492549:tid 492771] [client 20.104.50.220:63495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/sllolx.php"] [unique_id "apPkLTqFvOdCFO2AmwpfPwAAA_s"]
[Sun Aug 30 03:05:01.724081 2026] [security2:error] [pid 491656:tid 491909] [client 20.104.18.15:31693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/os.php"] [unique_id "apPkLYvX_L6VjdbvkkTBAgAAAw8"]
[Sun Aug 30 03:05:01.770745 2026] [security2:error] [pid 491656:tid 491897] [client 68.155.159.216:54107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPkLYvX_L6VjdbvkkTBKgAAAwM"]
[Sun Aug 30 03:05:01.777317 2026] [authz_core:error] [pid 491656:tid 491829] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:05:01.777845 2026] [authz_core:error] [pid 491656:tid 491829] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:05:01.782967 2026] [security2:error] [pid 491656:tid 491912] [client 20.151.200.44:58913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.districtdumplings.com"] [uri "/waf.php"] [unique_id "apPkLYvX_L6VjdbvkkTBMQAAAxI"]
[Sun Aug 30 03:05:01.790986 2026] [security2:error] [pid 491656:tid 491824] [client 34.15.145.202:60512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/administrator/phpinfo.php"] [unique_id "apPkLYvX_L6VjdbvkkTBNQAAAro"]
[Sun Aug 30 03:05:01.795803 2026] [security2:error] [pid 491656:tid 491855] [client 158.23.147.79:26618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-content/x/index.php"] [unique_id "apPkLYvX_L6VjdbvkkTBOQAAAtk"]
[Sun Aug 30 03:05:01.805021 2026] [security2:error] [pid 492549:tid 492774] [client 20.104.50.220:62237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/403.php"] [unique_id "apPkLTqFvOdCFO2AmwpfdQAAA_4"]
[Sun Aug 30 03:05:01.820462 2026] [security2:error] [pid 491656:tid 491853] [client 158.23.147.79:63281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apPkLYvX_L6VjdbvkkTBSwAAAtc"]
[Sun Aug 30 03:05:01.824625 2026] [security2:error] [pid 492549:tid 492740] [client 20.104.50.220:47049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/alpa.php"] [unique_id "apPkLTqFvOdCFO2AmwpfigAAA9w"]
[Sun Aug 30 03:05:01.826702 2026] [security2:error] [pid 492549:tid 492745] [client 4.205.62.107:44441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/hosty.php"] [unique_id "apPkLTqFvOdCFO2AmwpfiwAAA-E"]
[Sun Aug 30 03:05:01.843755 2026] [security2:error] [pid 492549:tid 492782] [client 158.23.184.117:59267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/config.php"] [unique_id "apPkLTqFvOdCFO2AmwpfmQAABAY"]
[Sun Aug 30 03:05:01.847057 2026] [security2:error] [pid 492549:tid 492689] [client 20.48.251.3:51505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/drykl.php"] [unique_id "apPkLTqFvOdCFO2AmwpfogAAA6k"]
[Sun Aug 30 03:05:01.853560 2026] [security2:error] [pid 491656:tid 491878] [client 64.89.161.160:56300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.161.89.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kazuna.com.au"] [uri "/plugins/file-uploader/server/php/index.php"] [unique_id "apPkLYvX_L6VjdbvkkTBXAAAAvA"]
[Sun Aug 30 03:05:01.869212 2026] [security2:error] [pid 492549:tid 492695] [client 20.48.251.3:7096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/png.php"] [unique_id "apPkLTqFvOdCFO2AmwpfrQAAA68"]
[Sun Aug 30 03:05:01.890472 2026] [security2:error] [pid 492549:tid 492761] [client 4.205.62.107:63777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/userfuns.php"] [unique_id "apPkLTqFvOdCFO2AmwpfuQAAA_E"]
[Sun Aug 30 03:05:01.906373 2026] [authz_core:error] [pid 492549:tid 492700] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus%2Fsections
[Sun Aug 30 03:05:01.906845 2026] [authz_core:error] [pid 492549:tid 492700] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus%2Fsections
[Sun Aug 30 03:05:01.914820 2026] [security2:error] [pid 492549:tid 492808] [client 20.104.50.220:27098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/images/cong.php"] [unique_id "apPkLTqFvOdCFO2AmwpfyAAABCA"]
[Sun Aug 30 03:05:01.923415 2026] [security2:error] [pid 492549:tid 492699] [client 158.23.147.79:40305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apPkLTqFvOdCFO2AmwpfzgAAA7M"]
[Sun Aug 30 03:05:01.932689 2026] [security2:error] [pid 491656:tid 491791] [client 20.48.251.3:23448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/userfuns.php"] [unique_id "apPkLYvX_L6VjdbvkkTBgQAAApk"]
[Sun Aug 30 03:05:01.932763 2026] [security2:error] [pid 491656:tid 491801] [client 20.104.50.220:33018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/ssh.php"] [unique_id "apPkLYvX_L6VjdbvkkTBggAAAqM"]
[Sun Aug 30 03:05:01.938736 2026] [authz_core:error] [pid 492549:tid 492687] [client 66.249.66.68:62132] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:01.939124 2026] [authz_core:error] [pid 492549:tid 492687] [client 66.249.66.68:62132] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:01.951939 2026] [security2:error] [pid 492549:tid 492780] [client 4.205.62.107:22544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/env.php"] [unique_id "apPkLTqFvOdCFO2Amwpf2gAABAQ"]
[Sun Aug 30 03:05:01.963549 2026] [authz_core:error] [pid 491656:tid 491841] [client 216.73.216.128:6479] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:01.963845 2026] [authz_core:error] [pid 491656:tid 491841] [client 216.73.216.128:6479] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:01.965421 2026] [security2:error] [pid 491656:tid 491813] [client 4.205.62.107:5105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/aws.php"] [unique_id "apPkLYvX_L6VjdbvkkTBlQAAAq8"]
[Sun Aug 30 03:05:01.969281 2026] [security2:error] [pid 492549:tid 492767] [client 40.83.93.50:9095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/php8.php"] [unique_id "apPkLTqFvOdCFO2Amwpf4gAAA_c"]
[Sun Aug 30 03:05:01.979555 2026] [security2:error] [pid 492549:tid 492697] [client 20.48.251.3:49977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/upload.form.php"] [unique_id "apPkLTqFvOdCFO2Amwpf5wAAA7E"]
[Sun Aug 30 03:05:01.981017 2026] [security2:error] [pid 491656:tid 491812] [client 20.104.18.15:33730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/key.php"] [unique_id "apPkLYvX_L6VjdbvkkTBngAAAq4"]
[Sun Aug 30 03:05:01.985160 2026] [security2:error] [pid 491656:tid 491828] [client 158.23.184.117:23972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/login.php"] [unique_id "apPkLYvX_L6VjdbvkkTBoQAAAr4"]
[Sun Aug 30 03:05:01.996741 2026] [security2:error] [pid 492549:tid 492774] [client 20.63.219.114:16782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/news-portal/error.php"] [unique_id "apPkLTqFvOdCFO2Amwpf7wAAA_4"]
[Sun Aug 30 03:05:01.998528 2026] [security2:error] [pid 492549:tid 492750] [client 193.56.113.32:51020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.113.56.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smartmenu.pro"] [uri "/xmlrpc.php"] [unique_id "apPkLTqFvOdCFO2Amwpf5QAAA-Y"]
[Sun Aug 30 03:05:02.039134 2026] [security2:error] [pid 492549:tid 492732] [client 158.23.147.79:62568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/login.php"] [unique_id "apPkLjqFvOdCFO2AmwpgBQAAA9Q"]
[Sun Aug 30 03:05:02.069772 2026] [security2:error] [pid 491656:tid 491901] [client 4.205.62.107:32455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/cu.php"] [unique_id "apPkLovX_L6VjdbvkkTB3AAAAwc"]
[Sun Aug 30 03:05:02.076490 2026] [security2:error] [pid 491656:tid 491821] [client 136.92.30.49:50550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/smtp/phpinfo.php"] [unique_id "apPkLovX_L6VjdbvkkTB4QAAArc"]
[Sun Aug 30 03:05:02.087534 2026] [security2:error] [pid 491656:tid 491897] [client 20.104.49.130:63268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.infinitelearners.com"] [uri "/t.php"] [unique_id "apPkLovX_L6VjdbvkkTB7wAAAwM"]
[Sun Aug 30 03:05:02.093348 2026] [security2:error] [pid 491656:tid 491912] [client 158.23.147.79:26597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apPkLovX_L6VjdbvkkTB8QAAAxI"]
[Sun Aug 30 03:05:02.102534 2026] [security2:error] [pid 492549:tid 492754] [client 20.104.50.220:52853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/dhanush.php"] [unique_id "apPkLjqFvOdCFO2AmwpgMgAAA-o"]
[Sun Aug 30 03:05:02.130571 2026] [security2:error] [pid 491656:tid 491845] [client 158.23.184.117:59271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/index.php"] [unique_id "apPkLovX_L6VjdbvkkTCDQAAAs8"]
[Sun Aug 30 03:05:02.145377 2026] [security2:error] [pid 492549:tid 492805] [client 4.205.62.107:35974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/server_info.php"] [unique_id "apPkLjqFvOdCFO2AmwpgUAAABB0"]
[Sun Aug 30 03:05:02.201346 2026] [security2:error] [pid 492549:tid 492807] [client 20.48.251.3:54725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/userfuns.php"] [unique_id "apPkLjqFvOdCFO2AmwpghQAABB8"]
[Sun Aug 30 03:05:02.205845 2026] [security2:error] [pid 492549:tid 492779] [client 4.205.62.107:52134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/phina.php"] [unique_id "apPkLjqFvOdCFO2AmwpghwAABAM"]
[Sun Aug 30 03:05:02.215412 2026] [security2:error] [pid 492549:tid 492733] [client 158.23.147.79:62539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/hehehehe.php"] [unique_id "apPkLjqFvOdCFO2AmwpgjgAAA9U"]
[Sun Aug 30 03:05:02.233287 2026] [security2:error] [pid 492549:tid 492695] [client 68.155.159.216:52803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-includes/content.php"] [unique_id "apPkLjqFvOdCFO2AmwpgmgAAA68"]
[Sun Aug 30 03:05:02.239554 2026] [authz_core:error] [pid 491656:tid 491864] [client 216.73.216.128:11796] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:02.240032 2026] [authz_core:error] [pid 491656:tid 491864] [client 216.73.216.128:11796] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:02.250229 2026] [authz_core:error] [pid 491656:tid 491803] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:05:02.250711 2026] [authz_core:error] [pid 491656:tid 491803] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:05:02.253904 2026] [security2:error] [pid 492549:tid 492736] [client 158.23.147.79:40918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-login.php"] [unique_id "apPkLjqFvOdCFO2AmwpgpwAAA9g"]
[Sun Aug 30 03:05:02.268407 2026] [security2:error] [pid 492549:tid 492685] [client 34.15.141.119:54174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/old_phpinfo.php"] [unique_id "apPkLjqFvOdCFO2AmwpgsQAAA6U"]
[Sun Aug 30 03:05:02.270177 2026] [security2:error] [pid 491656:tid 491797] [client 158.23.184.117:23975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/min.php"] [unique_id "apPkLovX_L6VjdbvkkTCVgAAAp8"]
[Sun Aug 30 03:05:02.271263 2026] [security2:error] [pid 492549:tid 492801] [client 20.104.50.220:29163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-comments-post.php"] [unique_id "apPkLjqFvOdCFO2AmwpgswAABBk"]
[Sun Aug 30 03:05:02.295420 2026] [security2:error] [pid 492549:tid 492702] [client 4.205.62.107:2759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/fucku.php"] [unique_id "apPkLjqFvOdCFO2Amwpg1wAAA7Y"]
[Sun Aug 30 03:05:02.347942 2026] [security2:error] [pid 492549:tid 492766] [client 20.63.219.114:16773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/nvt/includes/plugins/wp-blog-header.php"] [unique_id "apPkLjqFvOdCFO2AmwphIwAAA_Y"]
[Sun Aug 30 03:05:02.394237 2026] [security2:error] [pid 492549:tid 492799] [client 34.15.145.202:60524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/core/phpinfo.php"] [unique_id "apPkLjqFvOdCFO2AmwphQAAABBc"]
[Sun Aug 30 03:05:02.395030 2026] [authz_core:error] [pid 492549:tid 492737] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus%2Fsections
[Sun Aug 30 03:05:02.395524 2026] [authz_core:error] [pid 492549:tid 492737] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus%2Fsections
[Sun Aug 30 03:05:02.397308 2026] [security2:error] [pid 492549:tid 492721] [client 68.155.159.216:52661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/admin.php"] [unique_id "apPkLjqFvOdCFO2AmwphRAAAA8k"]
[Sun Aug 30 03:05:02.411744 2026] [security2:error] [pid 492549:tid 492785] [client 158.23.147.79:40301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apPkLjqFvOdCFO2AmwphSwAABAk"]
[Sun Aug 30 03:05:02.411829 2026] [security2:error] [pid 492549:tid 492751] [client 158.23.184.117:59280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/options.php"] [unique_id "apPkLjqFvOdCFO2AmwphTAAAA-c"]
[Sun Aug 30 03:05:02.420364 2026] [security2:error] [pid 492549:tid 492802] [client 20.104.49.130:52322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/yawa.php"] [unique_id "apPkLjqFvOdCFO2AmwphWgAABBo"]
[Sun Aug 30 03:05:02.421015 2026] [security2:error] [pid 492549:tid 492789] [client 20.197.61.180:13921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/upgrade/about.php"] [unique_id "apPkLjqFvOdCFO2AmwphXAAABA0"]
[Sun Aug 30 03:05:02.432314 2026] [security2:error] [pid 492549:tid 492690] [client 4.205.62.107:58312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/fucku.php"] [unique_id "apPkLjqFvOdCFO2AmwphaAAAA6o"]
[Sun Aug 30 03:05:02.450276 2026] [authz_core:error] [pid 491656:tid 491875] [client 66.249.66.76:49768] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:02.450793 2026] [authz_core:error] [pid 491656:tid 491875] [client 66.249.66.76:49768] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:02.464257 2026] [autoindex:error] [pid 492549:tid 492705] [client 193.56.113.32:51022] AH01276: Cannot serve directory /home4/marcoabreuh/smartmenu.pro/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:05:02.465317 2026] [security2:error] [pid 492549:tid 492799] [client 4.205.62.107:65293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/motu.php"] [unique_id "apPkLjqFvOdCFO2AmwphhQAABBc"]
[Sun Aug 30 03:05:02.466172 2026] [security2:error] [pid 492549:tid 492810] [client 4.205.62.107:63959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/xmy.php"] [unique_id "apPkLjqFvOdCFO2AmwphhgAABCI"]
[Sun Aug 30 03:05:02.470548 2026] [security2:error] [pid 492549:tid 492765] [client 40.83.93.50:9150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/function.php"] [unique_id "apPkLjqFvOdCFO2AmwphjgAAA_U"]
[Sun Aug 30 03:05:02.483936 2026] [security2:error] [pid 491656:tid 491806] [client 4.205.62.107:26508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/channels.php"] [unique_id "apPkLovX_L6VjdbvkkTCwgAAAqg"]
[Sun Aug 30 03:05:02.505949 2026] [security2:error] [pid 492549:tid 492798] [client 136.92.30.49:50552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/phpinfo.php.bak"] [unique_id "apPkLjqFvOdCFO2AmwphugAABBY"]
[Sun Aug 30 03:05:02.529925 2026] [security2:error] [pid 491656:tid 491801] [client 158.23.147.79:40276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-admin/images/about.php"] [unique_id "apPkLovX_L6VjdbvkkTC4QAAAqM"]
[Sun Aug 30 03:05:02.537582 2026] [security2:error] [pid 491656:tid 491903] [client 20.104.18.15:9052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/wp_blog_footer.php"] [unique_id "apPkLovX_L6VjdbvkkTC6QAAAwk"]
[Sun Aug 30 03:05:02.546558 2026] [security2:error] [pid 491656:tid 491899] [client 158.23.147.79:63291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apPkLovX_L6VjdbvkkTC7wAAAwU"]
[Sun Aug 30 03:05:02.553543 2026] [security2:error] [pid 492549:tid 492704] [client 158.23.184.117:23991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/pk.php"] [unique_id "apPkLjqFvOdCFO2Amwph3QAAA7g"]
[Sun Aug 30 03:05:02.569860 2026] [security2:error] [pid 492549:tid 492767] [client 20.104.18.15:43302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/5PJcpMFsD8B.php"] [unique_id "apPkLjqFvOdCFO2Amwph6AAAA_c"]
[Sun Aug 30 03:05:02.685876 2026] [security2:error] [pid 492549:tid 492768] [client 193.56.113.32:51022] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "smartmenu.pro"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "apPkLjqFvOdCFO2AmwpiPAAAA_g"]
[Sun Aug 30 03:05:02.693654 2026] [security2:error] [pid 492549:tid 492687] [client 158.23.184.117:23974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/index.php"] [unique_id "apPkLjqFvOdCFO2AmwpiQwAAA6c"]
[Sun Aug 30 03:05:02.704944 2026] [security2:error] [pid 492549:tid 492765] [client 20.63.219.114:17183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/oceanwp/sass/components/plugins/panel.php"] [unique_id "apPkLjqFvOdCFO2AmwpiTAAAA_U"]
[Sun Aug 30 03:05:02.706559 2026] [security2:error] [pid 491656:tid 491793] [client 4.205.62.107:25483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/wdf.php"] [unique_id "apPkLovX_L6VjdbvkkTDSgAAAps"]
[Sun Aug 30 03:05:02.712153 2026] [security2:error] [pid 491656:tid 491910] [client 158.23.147.79:40916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPkLovX_L6VjdbvkkTDUAAAAxA"]
[Sun Aug 30 03:05:02.713435 2026] [security2:error] [pid 491656:tid 491884] [client 4.205.62.107:18645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/wp-admin/css/bolt.php"] [unique_id "apPkLovX_L6VjdbvkkTDUQAAAvY"]
[Sun Aug 30 03:05:02.717906 2026] [security2:error] [pid 492549:tid 492704] [client 20.104.50.220:32263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/hexor.php"] [unique_id "apPkLjqFvOdCFO2AmwpiUAAAA7g"]
[Sun Aug 30 03:05:02.743151 2026] [security2:error] [pid 491656:tid 491835] [client 20.104.18.15:13735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/classwithtostring.php"] [unique_id "apPkLovX_L6VjdbvkkTDZwAAAsU"]
[Sun Aug 30 03:05:02.753912 2026] [authz_core:error] [pid 492549:tid 492781] [client 66.249.66.43:50932] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:02.754229 2026] [authz_core:error] [pid 492549:tid 492781] [client 66.249.66.43:50932] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:02.766862 2026] [security2:error] [pid 492549:tid 492713] [client 20.104.104.62:37475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkLjqFvOdCFO2AmwpieQAAA8E"]
[Sun Aug 30 03:05:02.766865 2026] [security2:error] [pid 492549:tid 492791] [client 20.48.251.3:55807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/aws_secret_config.php"] [unique_id "apPkLjqFvOdCFO2AmwpiegAABA8"]
[Sun Aug 30 03:05:02.773062 2026] [security2:error] [pid 491656:tid 491874] [client 20.151.200.44:47093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/admin.php/700.php"] [unique_id "apPkLovX_L6VjdbvkkTDdgAAAuw"]
[Sun Aug 30 03:05:02.779010 2026] [security2:error] [pid 492549:tid 492774] [client 20.104.50.220:5461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/index.php"] [unique_id "apPkLjqFvOdCFO2AmwpigQAAA_4"]
[Sun Aug 30 03:05:02.781374 2026] [authz_core:error] [pid 492549:tid 492740] [client 66.249.66.69:54276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:02.781906 2026] [authz_core:error] [pid 492549:tid 492740] [client 66.249.66.69:54276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:02.788052 2026] [authz_core:error] [pid 491656:tid 491892] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:05:02.788491 2026] [authz_core:error] [pid 491656:tid 491892] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:05:02.835019 2026] [security2:error] [pid 492549:tid 492810] [client 158.23.184.117:23980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/cgi-bin/index.php"] [unique_id "apPkLjqFvOdCFO2AmwpitAAABCI"]
[Sun Aug 30 03:05:02.841346 2026] [security2:error] [pid 492549:tid 492744] [client 158.23.147.79:40897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-admin.php"] [unique_id "apPkLjqFvOdCFO2AmwpiwAAAA-A"]
[Sun Aug 30 03:05:02.863250 2026] [security2:error] [pid 491656:tid 491811] [client 20.104.18.15:31623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/htio.php"] [unique_id "apPkLovX_L6VjdbvkkTDpQAAAq0"]
[Sun Aug 30 03:05:02.868448 2026] [security2:error] [pid 491656:tid 491868] [client 20.104.50.220:51639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/small.php"] [unique_id "apPkLovX_L6VjdbvkkTDpwAAAuY"]
[Sun Aug 30 03:05:02.871365 2026] [security2:error] [pid 492549:tid 492759] [client 34.15.141.119:54186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/server-info.php"] [unique_id "apPkLjqFvOdCFO2AmwpizwAAA-8"]
[Sun Aug 30 03:05:02.894282 2026] [security2:error] [pid 492549:tid 492806] [client 158.23.147.79:63290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-content/admin.php"] [unique_id "apPkLjqFvOdCFO2Amwpi3gAABB4"]
[Sun Aug 30 03:05:02.914908 2026] [security2:error] [pid 492549:tid 492778] [client 20.104.104.62:37501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkLjqFvOdCFO2Amwpi6AAABAI"]
[Sun Aug 30 03:05:02.926078 2026] [security2:error] [pid 492549:tid 492787] [client 68.155.159.216:60010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPkLjqFvOdCFO2Amwpi7QAABAs"]
[Sun Aug 30 03:05:02.932384 2026] [authz_core:error] [pid 492549:tid 492808] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Ftest
[Sun Aug 30 03:05:02.932662 2026] [authz_core:error] [pid 492549:tid 492808] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Ftest
[Sun Aug 30 03:05:02.935830 2026] [security2:error] [pid 492549:tid 492782] [client 40.83.93.50:8325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/about.php"] [unique_id "apPkLjqFvOdCFO2Amwpi9gAABAY"]
[Sun Aug 30 03:05:02.958085 2026] [security2:error] [pid 491656:tid 491902] [client 20.104.50.220:61649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-includes/priv8.php"] [unique_id "apPkLovX_L6VjdbvkkTDxQAAAwg"]
[Sun Aug 30 03:05:02.964006 2026] [security2:error] [pid 492549:tid 492751] [client 136.92.30.49:51954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/phpinfo.php.old"] [unique_id "apPkLjqFvOdCFO2AmwpjBwAAA-c"]
[Sun Aug 30 03:05:02.964391 2026] [security2:error] [pid 492549:tid 492730] [client 20.104.50.220:46594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/themes/antioch/acces.php"] [unique_id "apPkLjqFvOdCFO2AmwpjCAAAA9I"]
[Sun Aug 30 03:05:02.964971 2026] [security2:error] [pid 492549:tid 492759] [client 4.205.62.107:44915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/pass4.php"] [unique_id "apPkLjqFvOdCFO2AmwpjCQAAA-8"]
[Sun Aug 30 03:05:02.975840 2026] [security2:error] [pid 492549:tid 492716] [client 52.139.37.240:19791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apPkLjqFvOdCFO2AmwpjGQAAA8Q"]
[Sun Aug 30 03:05:02.978023 2026] [security2:error] [pid 492549:tid 492767] [client 158.23.184.117:59312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/cgi-bin/load.php"] [unique_id "apPkLjqFvOdCFO2AmwpjHwAAA_c"]
[Sun Aug 30 03:05:02.994388 2026] [security2:error] [pid 492549:tid 492785] [client 34.15.145.202:60536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.145.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.kno.fnh.temporary.site"] [uri "/includes/phpinfo.php"] [unique_id "apPkLjqFvOdCFO2AmwpjJgAABAk"]
[Sun Aug 30 03:05:03.008376 2026] [security2:error] [pid 492549:tid 492751] [client 158.23.147.79:40929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apPkLzqFvOdCFO2AmwpjLwAAA-c"]
[Sun Aug 30 03:05:03.008510 2026] [security2:error] [pid 491656:tid 491809] [client 93.123.109.165:8850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulgarrigan.com"] [uri "/index.php"] [unique_id "apPkL4vX_L6VjdbvkkTD4gAAAqs"]
[Sun Aug 30 03:05:03.009276 2026] [security2:error] [pid 492549:tid 492701] [client 20.48.251.3:7081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/chosen.php"] [unique_id "apPkLzqFvOdCFO2AmwpjMAAAA7U"]
[Sun Aug 30 03:05:03.020219 2026] [security2:error] [pid 492549:tid 492693] [client 4.205.62.107:63560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/mamzi.php"] [unique_id "apPkLzqFvOdCFO2AmwpjOAAAA60"]
[Sun Aug 30 03:05:03.053142 2026] [security2:error] [pid 492549:tid 492692] [client 20.104.50.220:27077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/wp-admin/load-styles.php"] [unique_id "apPkLzqFvOdCFO2AmwpjSwAAA6w"]
[Sun Aug 30 03:05:03.054379 2026] [security2:error] [pid 492549:tid 492744] [client 20.63.219.114:16824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/options.php"] [unique_id "apPkLzqFvOdCFO2AmwpjTQAAA-A"]
[Sun Aug 30 03:05:03.057725 2026] [security2:error] [pid 491656:tid 491910] [client 20.104.104.62:37482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/h02ugyh.php"] [unique_id "apPkL4vX_L6VjdbvkkTEAwAAAxA"]
[Sun Aug 30 03:05:03.059724 2026] [security2:error] [pid 492549:tid 492707] [client 20.48.251.3:44292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/ebahvhhh.php"] [unique_id "apPkLzqFvOdCFO2AmwpjUwAAA7s"]
[Sun Aug 30 03:05:03.067425 2026] [security2:error] [pid 492549:tid 492768] [client 20.104.50.220:33540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/s4d.php"] [unique_id "apPkLzqFvOdCFO2AmwpjXwAAA_g"]
[Sun Aug 30 03:05:03.086831 2026] [security2:error] [pid 491656:tid 491913] [client 158.23.147.79:63287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/xmlrpc.php"] [unique_id "apPkL4vX_L6VjdbvkkTEEgAAAxM"]
[Sun Aug 30 03:05:03.097228 2026] [security2:error] [pid 492549:tid 492732] [client 4.205.62.107:4594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/app.default.php"] [unique_id "apPkLzqFvOdCFO2AmwpjcQAAA9Q"]
[Sun Aug 30 03:05:03.100951 2026] [security2:error] [pid 492549:tid 492772] [client 20.48.251.3:51568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/rpk.php"] [unique_id "apPkLzqFvOdCFO2AmwpjdwAAA_w"]
[Sun Aug 30 03:05:03.115297 2026] [security2:error] [pid 491656:tid 491895] [client 4.205.62.107:54435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/xve22.php"] [unique_id "apPkL4vX_L6VjdbvkkTEJwAAAwE"]
[Sun Aug 30 03:05:03.120481 2026] [security2:error] [pid 492549:tid 492751] [client 158.23.184.117:59270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/cgi-bin/ms-files.php"] [unique_id "apPkLzqFvOdCFO2AmwpjgwAAA-c"]
[Sun Aug 30 03:05:03.120588 2026] [security2:error] [pid 492549:tid 492707] [client 20.48.251.3:55509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/aws_auth.php"] [unique_id "apPkLzqFvOdCFO2AmwpjhAAAA7s"]
[Sun Aug 30 03:05:03.127455 2026] [security2:error] [pid 492549:tid 492792] [client 193.56.113.32:51038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "smartmenu.pro"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "apPkLzqFvOdCFO2AmwpjiAAABBA"]
[Sun Aug 30 03:05:03.133966 2026] [security2:error] [pid 492549:tid 492791] [client 20.48.251.3:22774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/mamzi.php"] [unique_id "apPkLzqFvOdCFO2AmwpjiwAABA8"]
[Sun Aug 30 03:05:03.149546 2026] [security2:error] [pid 492549:tid 492727] [client 158.23.147.79:26593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/lock.php"] [unique_id "apPkLzqFvOdCFO2AmwpjmwAAA88"]
[Sun Aug 30 03:05:03.149818 2026] [security2:error] [pid 492549:tid 492687] [client 20.197.61.180:13930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospheretravel.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "apPkLzqFvOdCFO2AmwpjnAAAA6c"]
[Sun Aug 30 03:05:03.152853 2026] [security2:error] [pid 492549:tid 492689] [client 20.104.18.15:32987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/chosen.php"] [unique_id "apPkLzqFvOdCFO2AmwpjngAAA6k"]
[Sun Aug 30 03:05:03.154620 2026] [security2:error] [pid 492549:tid 492739] [client 93.123.109.165:8866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulgarrigan.com"] [uri "/index.php"] [unique_id "apPkLzqFvOdCFO2AmwpjoQAAA9s"]
[Sun Aug 30 03:05:03.168156 2026] [security2:error] [pid 492549:tid 492735] [client 52.139.37.240:19818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/wp-content/uploads/min.php"] [unique_id "apPkLzqFvOdCFO2AmwpjvAAAA9c"]
[Sun Aug 30 03:05:03.175897 2026] [authz_core:error] [pid 492549:tid 492713] [client 66.249.66.35:42990] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:03.176404 2026] [authz_core:error] [pid 492549:tid 492713] [client 66.249.66.35:42990] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:03.208630 2026] [security2:error] [pid 491656:tid 491849] [client 20.104.104.62:37446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/sf.php"] [unique_id "apPkL4vX_L6VjdbvkkTEagAAAtM"]
[Sun Aug 30 03:05:03.247270 2026] [authz_core:error] [pid 491656:tid 491829] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:05:03.247769 2026] [authz_core:error] [pid 491656:tid 491829] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fpython3.9%2F__pycache__
[Sun Aug 30 03:05:03.247849 2026] [security2:error] [pid 492549:tid 492695] [client 158.23.147.79:40303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/index/function.php"] [unique_id "apPkLzqFvOdCFO2Amwpj6QAAA68"]
[Sun Aug 30 03:05:03.261681 2026] [security2:error] [pid 491656:tid 491842] [client 158.23.184.117:23976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/cgi-bin/wp-activate.php"] [unique_id "apPkL4vX_L6VjdbvkkTEiQAAAsw"]
[Sun Aug 30 03:05:03.271549 2026] [security2:error] [pid 492549:tid 492684] [client 20.104.50.220:29593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/asw.php"] [unique_id "apPkLzqFvOdCFO2Amwpj-gAAA6Q"]
[Sun Aug 30 03:05:03.333996 2026] [authz_core:error] [pid 491656:tid 491879] [client 216.73.216.128:11796] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:03.334490 2026] [authz_core:error] [pid 491656:tid 491879] [client 216.73.216.128:11796] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:03.365621 2026] [security2:error] [pid 492549:tid 492761] [client 52.139.37.240:61138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/zoom1.php"] [unique_id "apPkLzqFvOdCFO2AmwpkcAAAA_E"]
[Sun Aug 30 03:05:03.382714 2026] [security2:error] [pid 491656:tid 491864] [client 20.104.104.62:35328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/4e.php"] [unique_id "apPkL4vX_L6VjdbvkkTE0gAAAuI"]
[Sun Aug 30 03:05:03.395127 2026] [security2:error] [pid 492549:tid 492692] [client 158.23.147.79:40295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/.well-known/content.php"] [unique_id "apPkLzqFvOdCFO2AmwpkfgAAA6w"]
[Sun Aug 30 03:05:03.404349 2026] [security2:error] [pid 492549:tid 492716] [client 158.23.184.117:59287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/cgi-bin/wp-load.php"] [unique_id "apPkLzqFvOdCFO2AmwpkggAAA8Q"]
[Sun Aug 30 03:05:03.406673 2026] [security2:error] [pid 492549:tid 492730] [client 136.92.30.49:51970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/phpinfo.php~"] [unique_id "apPkLzqFvOdCFO2AmwpkgwAAA9I"]
[Sun Aug 30 03:05:03.408003 2026] [security2:error] [pid 492549:tid 492786] [client 20.63.219.114:10637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/panel.php"] [unique_id "apPkLzqFvOdCFO2AmwpkhQAABAo"]
[Sun Aug 30 03:05:03.410260 2026] [security2:error] [pid 492549:tid 492748] [client 40.83.93.50:8622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/new.php"] [unique_id "apPkLzqFvOdCFO2AmwpkiAAAA-Q"]
[Sun Aug 30 03:05:03.416550 2026] [security2:error] [pid 491656:tid 491811] [client 20.104.50.220:52856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-config-style.php"] [unique_id "apPkL4vX_L6VjdbvkkTE5gAAAq0"]
[Sun Aug 30 03:05:03.421641 2026] [security2:error] [pid 492549:tid 492696] [client 158.23.147.79:62547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/atomlib.php"] [unique_id "apPkLzqFvOdCFO2AmwpklgAAA7A"]
[Sun Aug 30 03:05:03.428262 2026] [authz_core:error] [pid 492549:tid 492687] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Ftest
[Sun Aug 30 03:05:03.428340 2026] [security2:error] [pid 491656:tid 491849] [client 4.205.62.107:52154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/koiy.php"] [unique_id "apPkL4vX_L6VjdbvkkTE7AAAAtM"]
[Sun Aug 30 03:05:03.428531 2026] [authz_core:error] [pid 492549:tid 492687] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Ftest
[Sun Aug 30 03:05:03.437125 2026] [security2:error] [pid 492549:tid 492739] [client 68.155.159.216:60559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-admin/css/index.php"] [unique_id "apPkLzqFvOdCFO2AmwpkqAAAA9s"]
[Sun Aug 30 03:05:03.450006 2026] [security2:error] [pid 491656:tid 491871] [client 20.48.251.3:46221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/mamzi.php"] [unique_id "apPkL4vX_L6VjdbvkkTE_gAAAuk"]
[Sun Aug 30 03:05:03.469768 2026] [security2:error] [pid 492549:tid 492754] [client 34.15.141.119:54188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/server-status.php"] [unique_id "apPkLzqFvOdCFO2AmwpkvQAAA-o"]
[Sun Aug 30 03:05:03.484569 2026] [authz_core:error] [pid 492549:tid 492719] [client 66.249.66.202:44518] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:03.485039 2026] [authz_core:error] [pid 492549:tid 492719] [client 66.249.66.202:44518] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:03.510514 2026] [security2:error] [pid 492549:tid 492701] [client 68.155.159.216:52646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-admin/admin.php"] [unique_id "apPkLzqFvOdCFO2Amwpk2wAAA7U"]
[Sun Aug 30 03:05:03.512504 2026] [authz_core:error] [pid 491656:tid 491897] [client 216.73.216.128:7790] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:03.512887 2026] [authz_core:error] [pid 491656:tid 491897] [client 216.73.216.128:7790] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:03.513816 2026] [security2:error] [pid 491656:tid 491871] [client 20.104.104.62:37476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/ssss.php"] [unique_id "apPkL4vX_L6VjdbvkkTFNwAAAuk"]
[Sun Aug 30 03:05:03.536223 2026] [security2:error] [pid 491656:tid 491818] [client 158.23.147.79:40957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/cong.php"] [unique_id "apPkL4vX_L6VjdbvkkTFTAAAArQ"]
[Sun Aug 30 03:05:03.547116 2026] [security2:error] [pid 491656:tid 491835] [client 158.23.184.117:23940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/cgi-bin/wp-mail.php"] [unique_id "apPkL4vX_L6VjdbvkkTFTgAAAsU"]
[Sun Aug 30 03:05:03.558894 2026] [security2:error] [pid 491656:tid 491891] [client 52.139.37.240:61133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/lock360.php"] [unique_id "apPkL4vX_L6VjdbvkkTFVAAAAv0"]
[Sun Aug 30 03:05:03.572866 2026] [security2:error] [pid 491656:tid 491792] [client 193.56.113.32:51054] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "smartmenu.pro"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "apPkL4vX_L6VjdbvkkTFXwAAApo"]
[Sun Aug 30 03:05:03.586748 2026] [security2:error] [pid 492549:tid 492757] [client 4.205.62.107:2335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/error_log.php"] [unique_id "apPkLzqFvOdCFO2AmwplCAAAA-0"]
[Sun Aug 30 03:05:03.604729 2026] [authz_core:error] [pid 491656:tid 491811] [client 66.249.66.204:47690] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:03.605226 2026] [authz_core:error] [pid 491656:tid 491811] [client 66.249.66.204:47690] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:03.615815 2026] [security2:error] [pid 491656:tid 491805] [client 4.205.62.107:63978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/ms-edit.php"] [unique_id "apPkL4vX_L6VjdbvkkTFewAAAqc"]
[Sun Aug 30 03:05:03.646503 2026] [security2:error] [pid 492549:tid 492718] [client 20.104.104.62:37487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/zoz.php"] [unique_id "apPkLzqFvOdCFO2AmwplOwAAA8Y"]
[Sun Aug 30 03:05:03.660931 2026] [security2:error] [pid 492549:tid 492685] [client 4.205.62.107:65285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/public/mah.php.php"] [unique_id "apPkLzqFvOdCFO2AmwplSQAAA6U"]
[Sun Aug 30 03:05:03.706173 2026] [security2:error] [pid 491656:tid 491836] [client 20.104.18.15:9148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/sushi.php"] [unique_id "apPkL4vX_L6VjdbvkkTFtAAAAsY"]
[Sun Aug 30 03:05:03.708711 2026] [security2:error] [pid 492549:tid 492731] [client 158.23.184.117:59286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "apPkLzqFvOdCFO2AmwplYAAAA9M"]
[Sun Aug 30 03:05:03.721403 2026] [security2:error] [pid 492549:tid 492704] [client 4.205.62.107:36027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/hosty.php"] [unique_id "apPkLzqFvOdCFO2AmwplaQAAA7g"]
[Sun Aug 30 03:05:03.725665 2026] [security2:error] [pid 491656:tid 491879] [client 20.104.18.15:43305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPkL4vX_L6VjdbvkkTFuwAAAvE"]
[Sun Aug 30 03:05:03.752717 2026] [security2:error] [pid 491656:tid 491820] [client 52.139.37.240:60855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/r.php"] [unique_id "apPkL4vX_L6VjdbvkkTFywAAArY"]
[Sun Aug 30 03:05:03.762987 2026] [security2:error] [pid 492549:tid 492698] [client 20.63.219.114:15561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/reboot/assets/js/plugins/home.php"] [unique_id "apPkLzqFvOdCFO2AmwplkAAAA7I"]
[Sun Aug 30 03:05:03.775034 2026] [security2:error] [pid 491656:tid 491912] [client 158.23.147.79:40905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-includes/js/index.php"] [unique_id "apPkL4vX_L6VjdbvkkTF3gAAAxI"]
[Sun Aug 30 03:05:03.790883 2026] [security2:error] [pid 492549:tid 492684] [client 20.104.104.62:37496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/kcs.php"] [unique_id "apPkLzqFvOdCFO2AmwplpwAAA6Q"]
[Sun Aug 30 03:05:03.819823 2026] [authz_core:error] [pid 492549:tid 492712] [client 66.249.66.205:61298] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:03.820257 2026] [authz_core:error] [pid 492549:tid 492712] [client 66.249.66.205:61298] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:03.821345 2026] [security2:error] [pid 491656:tid 491895] [client 20.196.209.81:16834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/data.php"] [unique_id "apPkL4vX_L6VjdbvkkTF_QAAAwE"]
[Sun Aug 30 03:05:03.827946 2026] [security2:error] [pid 491656:tid 491820] [client 4.205.62.107:32030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/error_log.php"] [unique_id "apPkL4vX_L6VjdbvkkTGBAAAArY"]
[Sun Aug 30 03:05:03.840786 2026] [security2:error] [pid 492549:tid 492761] [client 136.92.30.49:51974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/info.php.bak"] [unique_id "apPkLzqFvOdCFO2Amwpl3AAAA_E"]
[Sun Aug 30 03:05:03.850464 2026] [security2:error] [pid 492549:tid 492697] [client 158.23.184.117:23964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/chosen.php"] [unique_id "apPkLzqFvOdCFO2Amwpl4gAAA7E"]
[Sun Aug 30 03:05:03.866187 2026] [security2:error] [pid 491656:tid 491822] [client 4.205.62.107:25770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/bb.php"] [unique_id "apPkL4vX_L6VjdbvkkTGHQAAArg"]
[Sun Aug 30 03:05:03.876920 2026] [security2:error] [pid 492549:tid 492766] [client 40.83.93.50:8628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/goods.php"] [unique_id "apPkLzqFvOdCFO2Amwpl6wAAA_Y"]
[Sun Aug 30 03:05:03.879003 2026] [security2:error] [pid 492549:tid 492806] [client 4.205.62.107:26500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/zz.php"] [unique_id "apPkLzqFvOdCFO2Amwpl7QAABB4"]
[Sun Aug 30 03:05:03.904753 2026] [security2:error] [pid 491656:tid 491914] [client 20.48.251.3:55790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/snq.php"] [unique_id "apPkL4vX_L6VjdbvkkTGNQAAAxQ"]
[Sun Aug 30 03:05:03.919515 2026] [authz_core:error] [pid 492549:tid 492797] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus%2Fsections
[Sun Aug 30 03:05:03.919778 2026] [authz_core:error] [pid 492549:tid 492797] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus%2Fsections
[Sun Aug 30 03:05:03.926613 2026] [security2:error] [pid 491656:tid 491883] [client 20.104.18.15:13748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPkL4vX_L6VjdbvkkTGQAAAAvU"]
[Sun Aug 30 03:05:03.941191 2026] [security2:error] [pid 492549:tid 492810] [client 158.23.147.79:26567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-content/index.php"] [unique_id "apPkLzqFvOdCFO2AmwpmBwAABCI"]
[Sun Aug 30 03:05:03.951132 2026] [security2:error] [pid 492549:tid 492752] [client 20.104.104.62:41119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/tajj.php"] [unique_id "apPkLzqFvOdCFO2AmwpmCwAAA-g"]
[Sun Aug 30 03:05:03.957512 2026] [security2:error] [pid 492549:tid 492735] [client 20.104.50.220:6141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "apPkLzqFvOdCFO2AmwpmDgAAA9c"]
[Sun Aug 30 03:05:03.961309 2026] [security2:error] [pid 491656:tid 491829] [client 20.104.50.220:32548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/leaf.php"] [unique_id "apPkL4vX_L6VjdbvkkTGVwAAAr8"]
[Sun Aug 30 03:05:03.973400 2026] [security2:error] [pid 491656:tid 491918] [client 52.139.37.240:19785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/sf.php"] [unique_id "apPkL4vX_L6VjdbvkkTGXQAAAxg"]
[Sun Aug 30 03:05:04.018369 2026] [security2:error] [pid 492549:tid 492782] [client 193.56.113.32:51068] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "smartmenu.pro"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "apPkMDqFvOdCFO2AmwpmMwAABAY"]
[Sun Aug 30 03:05:04.018659 2026] [security2:error] [pid 492549:tid 492737] [client 20.151.200.44:47030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/admin.php/007x.php"] [unique_id "apPkMDqFvOdCFO2AmwpmNAAAA9k"]
[Sun Aug 30 03:05:04.026031 2026] [security2:error] [pid 491656:tid 491895] [client 20.104.50.220:51560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/style-js.php"] [unique_id "apPkMIvX_L6VjdbvkkTGcQAAAwE"]
[Sun Aug 30 03:05:04.033291 2026] [security2:error] [pid 492549:tid 492716] [client 68.155.159.216:60011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apPkMDqFvOdCFO2AmwpmSgAAA8Q"]
[Sun Aug 30 03:05:04.038045 2026] [security2:error] [pid 492549:tid 492708] [client 158.23.147.79:26619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/about/function.php"] [unique_id "apPkMDqFvOdCFO2AmwpmTgAAA7w"]
[Sun Aug 30 03:05:04.041112 2026] [security2:error] [pid 492549:tid 492767] [client 20.104.18.15:31592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/dev.php"] [unique_id "apPkMDqFvOdCFO2AmwpmUgAAA_c"]
[Sun Aug 30 03:05:04.041878 2026] [security2:error] [pid 492549:tid 492689] [client 4.205.62.107:18767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/myfile.php"] [unique_id "apPkMDqFvOdCFO2AmwpmUwAAA6k"]
[Sun Aug 30 03:05:04.051292 2026] [security2:error] [pid 492549:tid 492721] [client 20.48.251.3:6467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/koiy.php"] [unique_id "apPkMDqFvOdCFO2AmwpmWwAAA8k"]
[Sun Aug 30 03:05:04.103602 2026] [security2:error] [pid 492549:tid 492741] [client 20.104.50.220:46651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/su.php"] [unique_id "apPkMDqFvOdCFO2AmwpmkQAAA90"]
[Sun Aug 30 03:05:04.104103 2026] [security2:error] [pid 492549:tid 492701] [client 4.205.62.107:43039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/cu.php"] [unique_id "apPkMDqFvOdCFO2AmwpmkgAAA7U"]
[Sun Aug 30 03:05:04.113894 2026] [security2:error] [pid 492549:tid 492688] [client 20.63.219.114:17215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/salient/css/build/plugins/login.php"] [unique_id "apPkMDqFvOdCFO2AmwpmlwAAA6g"]
[Sun Aug 30 03:05:04.120446 2026] [security2:error] [pid 492549:tid 492808] [client 20.104.104.62:35361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/bge.php"] [unique_id "apPkMDqFvOdCFO2AmwpmnAAABCA"]
[Sun Aug 30 03:05:04.150170 2026] [security2:error] [pid 492549:tid 492767] [client 20.48.251.3:64438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/ms.php"] [unique_id "apPkMDqFvOdCFO2AmwpmvQAAA_c"]
[Sun Aug 30 03:05:04.155782 2026] [security2:error] [pid 492549:tid 492774] [client 4.205.62.107:63805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/public/rip.php.php"] [unique_id "apPkMDqFvOdCFO2AmwpmxQAAA_4"]
[Sun Aug 30 03:05:04.161819 2026] [security2:error] [pid 492549:tid 492777] [client 20.104.50.220:61683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/00.php"] [unique_id "apPkMDqFvOdCFO2AmwpmyQAABAE"]
[Sun Aug 30 03:05:04.165503 2026] [security2:error] [pid 492549:tid 492753] [client 52.139.37.240:19800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/7.php"] [unique_id "apPkMDqFvOdCFO2Amwpm0AAAA-k"]
[Sun Aug 30 03:05:04.189390 2026] [security2:error] [pid 491656:tid 491878] [client 20.104.50.220:27079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/images/wp-2019.php"] [unique_id "apPkMIvX_L6VjdbvkkTG3AAAAvA"]
[Sun Aug 30 03:05:04.203308 2026] [security2:error] [pid 492549:tid 492722] [client 158.23.147.79:62560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/lv.php"] [unique_id "apPkMDqFvOdCFO2Amwpm7AAAA8o"]
[Sun Aug 30 03:05:04.204561 2026] [security2:error] [pid 491656:tid 491837] [client 4.205.62.107:58366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/phina.php"] [unique_id "apPkMIvX_L6VjdbvkkTG6AAAAsc"]
[Sun Aug 30 03:05:04.204675 2026] [security2:error] [pid 491656:tid 491822] [client 20.104.50.220:33039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/slot.php"] [unique_id "apPkMIvX_L6VjdbvkkTG6QAAArg"]
[Sun Aug 30 03:05:04.213941 2026] [security2:error] [pid 491656:tid 491800] [client 20.196.209.81:21153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/dt-the7/css/static-less/plugins/admin.php"] [unique_id "apPkMIvX_L6VjdbvkkTG8wAAAqI"]
[Sun Aug 30 03:05:04.227231 2026] [security2:error] [pid 492549:tid 492699] [client 158.23.147.79:40275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apPkMDqFvOdCFO2Amwpm-AAAA7M"]
[Sun Aug 30 03:05:04.235003 2026] [security2:error] [pid 491656:tid 491849] [client 4.205.62.107:5082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/app_local.php"] [unique_id "apPkMIvX_L6VjdbvkkTHCAAAAtM"]
[Sun Aug 30 03:05:04.239738 2026] [authz_core:error] [pid 491656:tid 491914] [client 216.73.216.128:7790] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:04.240033 2026] [authz_core:error] [pid 491656:tid 491914] [client 216.73.216.128:7790] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:04.251827 2026] [authz_core:error] [pid 492549:tid 492685] [client 66.249.66.78:58016] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:04.252152 2026] [authz_core:error] [pid 492549:tid 492685] [client 66.249.66.78:58016] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:04.255076 2026] [security2:error] [pid 492549:tid 492724] [client 4.205.62.107:22535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/06.php"] [unique_id "apPkMDqFvOdCFO2AmwpnBQAAA8w"]
[Sun Aug 30 03:05:04.255912 2026] [security2:error] [pid 492549:tid 492797] [client 20.48.251.3:50008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/hiquido.com/index.php"] [unique_id "apPkMDqFvOdCFO2AmwpnBgAABBU"]
[Sun Aug 30 03:05:04.283185 2026] [security2:error] [pid 492549:tid 492804] [client 136.92.30.49:51978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/phpinfo.php.save"] [unique_id "apPkMDqFvOdCFO2AmwpnHwAABBw"]
[Sun Aug 30 03:05:04.291308 2026] [security2:error] [pid 491656:tid 491909] [client 20.48.251.3:44332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/asa.php"] [unique_id "apPkMIvX_L6VjdbvkkTHNwAAAw8"]
[Sun Aug 30 03:05:04.291911 2026] [security2:error] [pid 491656:tid 491877] [client 20.104.104.62:35337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/ssh3ll.php"] [unique_id "apPkMIvX_L6VjdbvkkTHOQAAAu8"]
[Sun Aug 30 03:05:04.311653 2026] [security2:error] [pid 491656:tid 491884] [client 158.23.184.117:24208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/class-wp-logo-new.php"] [unique_id "apPkMIvX_L6VjdbvkkTHUQAAAvY"]
[Sun Aug 30 03:05:04.316248 2026] [security2:error] [pid 492549:tid 492730] [client 20.48.251.3:34570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/saml.php"] [unique_id "apPkMDqFvOdCFO2AmwpnPwAAA9I"]
[Sun Aug 30 03:05:04.353691 2026] [security2:error] [pid 492549:tid 492716] [client 40.83.93.50:9140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/m.php"] [unique_id "apPkMDqFvOdCFO2AmwpnbgAAA8Q"]
[Sun Aug 30 03:05:04.358880 2026] [security2:error] [pid 491656:tid 491814] [client 52.139.37.240:60850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/b.php"] [unique_id "apPkMIvX_L6VjdbvkkTHcAAAArA"]
[Sun Aug 30 03:05:04.367024 2026] [security2:error] [pid 492549:tid 492704] [client 20.104.18.15:33731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/file1221.php"] [unique_id "apPkMDqFvOdCFO2AmwpnfwAAA7g"]
[Sun Aug 30 03:05:04.376723 2026] [security2:error] [pid 491656:tid 491873] [client 158.23.147.79:63278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apPkMIvX_L6VjdbvkkTHewAAAus"]
[Sun Aug 30 03:05:04.387036 2026] [security2:error] [pid 492549:tid 492761] [client 20.48.251.3:44262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/public/rip.php.php"] [unique_id "apPkMDqFvOdCFO2AmwpnhgAAA_E"]
[Sun Aug 30 03:05:04.421383 2026] [authz_core:error] [pid 492549:tid 492722] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus%2Fsections
[Sun Aug 30 03:05:04.421720 2026] [authz_core:error] [pid 492549:tid 492722] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus%2Fsections
[Sun Aug 30 03:05:04.422150 2026] [authz_core:error] [pid 491656:tid 491797] [client 66.249.66.206:61117] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:04.422519 2026] [security2:error] [pid 492549:tid 492792] [client 20.104.50.220:29137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/mini.php5"] [unique_id "apPkMDqFvOdCFO2AmwpnnwAABBA"]
[Sun Aug 30 03:05:04.422594 2026] [authz_core:error] [pid 491656:tid 491797] [client 66.249.66.206:61117] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:04.452871 2026] [security2:error] [pid 492549:tid 492793] [client 20.104.104.62:37498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/motu.php"] [unique_id "apPkMDqFvOdCFO2AmwpnugAABBE"]
[Sun Aug 30 03:05:04.453388 2026] [security2:error] [pid 491656:tid 491803] [client 158.23.184.117:59278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/classwithtostring.php"] [unique_id "apPkMIvX_L6VjdbvkkTHsQAAAqU"]
[Sun Aug 30 03:05:04.473036 2026] [security2:error] [pid 491656:tid 491828] [client 193.56.113.32:51074] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "smartmenu.pro"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "apPkMIvX_L6VjdbvkkTHxgAAAr4"]
[Sun Aug 30 03:05:04.488283 2026] [security2:error] [pid 492549:tid 492709] [client 20.63.219.114:16788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/security.php"] [unique_id "apPkMDqFvOdCFO2Amwpn1QAAA70"]
[Sun Aug 30 03:05:04.493383 2026] [security2:error] [pid 491656:tid 491882] [client 34.15.141.119:54192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/webroot/index.php/_environment"] [unique_id "apPkMIvX_L6VjdbvkkTH1wAAAvQ"]
[Sun Aug 30 03:05:04.538227 2026] [authz_core:error] [pid 492549:tid 492696] [client 66.249.66.77:60786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:04.538534 2026] [authz_core:error] [pid 492549:tid 492696] [client 66.249.66.77:60786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:04.550377 2026] [security2:error] [pid 491656:tid 491910] [client 52.139.37.240:19806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/buy.php"] [unique_id "apPkMIvX_L6VjdbvkkTH_gAAAxA"]
[Sun Aug 30 03:05:04.551404 2026] [security2:error] [pid 491656:tid 491847] [client 20.151.200.44:47017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/h02ugyh.php"] [unique_id "apPkMIvX_L6VjdbvkkTIAAAAAtE"]
[Sun Aug 30 03:05:04.567774 2026] [security2:error] [pid 491656:tid 491673] [remote 50.6.137.53:57942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.137.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apperutech.com"] [uri "/wp-login.php"] [unique_id "apPkMIvX_L6VjdbvkkTIDAACtww"]
[Sun Aug 30 03:05:04.573789 2026] [security2:error] [pid 492549:tid 492709] [client 4.205.62.107:52106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/queue.php"] [unique_id "apPkMDqFvOdCFO2AmwpoDgAAA70"]
[Sun Aug 30 03:05:04.579018 2026] [security2:error] [pid 491656:tid 491871] [client 20.104.50.220:52816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-logo.php"] [unique_id "apPkMIvX_L6VjdbvkkTIGAAAAuk"]
[Sun Aug 30 03:05:04.592170 2026] [security2:error] [pid 491656:tid 491901] [client 158.23.184.117:23969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/cms.php"] [unique_id "apPkMIvX_L6VjdbvkkTIHgAAAwc"]
[Sun Aug 30 03:05:04.611235 2026] [security2:error] [pid 491656:tid 491897] [client 20.48.251.3:64302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/public/rip.php.php"] [unique_id "apPkMIvX_L6VjdbvkkTIJwAAAwM"]
[Sun Aug 30 03:05:04.620413 2026] [security2:error] [pid 491656:tid 491870] [client 20.196.209.81:21132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/hideo/network.php"] [unique_id "apPkMIvX_L6VjdbvkkTIMAAAAug"]
[Sun Aug 30 03:05:04.626807 2026] [security2:error] [pid 492549:tid 492728] [client 20.104.104.62:37490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/wefile.php"] [unique_id "apPkMDqFvOdCFO2AmwpoJgAAA9A"]
[Sun Aug 30 03:05:04.632218 2026] [security2:error] [pid 492549:tid 492771] [client 68.155.159.216:52745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-admin/images/index.php"] [unique_id "apPkMDqFvOdCFO2AmwpoMwAAA_s"]
[Sun Aug 30 03:05:04.679671 2026] [security2:error] [pid 491656:tid 491851] [client 68.155.159.216:52708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apPkMIvX_L6VjdbvkkTIYQAAAtU"]
[Sun Aug 30 03:05:04.718394 2026] [security2:error] [pid 492549:tid 492795] [client 136.92.30.49:51980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/staging/phpinfo.php"] [unique_id "apPkMDqFvOdCFO2AmwpoYwAABBM"]
[Sun Aug 30 03:05:04.734914 2026] [security2:error] [pid 492549:tid 492767] [client 158.23.184.117:24211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/config.php"] [unique_id "apPkMDqFvOdCFO2AmwpobQAAA_c"]
[Sun Aug 30 03:05:04.736360 2026] [security2:error] [pid 492549:tid 492691] [client 158.23.147.79:26588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-admin/index.php"] [unique_id "apPkMDqFvOdCFO2AmwpobgAAA6s"]
[Sun Aug 30 03:05:04.743035 2026] [security2:error] [pid 492549:tid 492791] [client 52.139.37.240:19795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/config.php"] [unique_id "apPkMDqFvOdCFO2AmwpodAAABA8"]
[Sun Aug 30 03:05:04.751575 2026] [security2:error] [pid 491656:tid 491798] [client 4.205.62.107:64048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/sys.php"] [unique_id "apPkMIvX_L6VjdbvkkTIjgAAAqA"]
[Sun Aug 30 03:05:04.762570 2026] [authz_core:error] [pid 492549:tid 492753] [client 66.249.66.68:40455] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:04.763039 2026] [authz_core:error] [pid 492549:tid 492753] [client 66.249.66.68:40455] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:04.771776 2026] [security2:error] [pid 492549:tid 492685] [client 20.104.104.62:37470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/Contrller.php"] [unique_id "apPkMDqFvOdCFO2AmwpojQAAA6U"]
[Sun Aug 30 03:05:04.830180 2026] [security2:error] [pid 491656:tid 491675] [remote 50.6.137.53:57942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.137.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apperutech.com"] [uri "/wp-login.php"] [unique_id "apPkMIvX_L6VjdbvkkTItwADCQ4"], referer: https://apperutech.com/wp-login.php
[Sun Aug 30 03:05:04.836540 2026] [security2:error] [pid 491656:tid 491882] [client 20.151.200.44:47050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/sf.php"] [unique_id "apPkMIvX_L6VjdbvkkTIwQAAAvQ"]
[Sun Aug 30 03:05:04.838280 2026] [security2:error] [pid 492549:tid 492804] [client 40.83.93.50:14292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/doc.php"] [unique_id "apPkMDqFvOdCFO2AmwpovwAABBw"]
[Sun Aug 30 03:05:04.838358 2026] [security2:error] [pid 491656:tid 491874] [client 4.205.62.107:42633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/filesystems.php"] [unique_id "apPkMIvX_L6VjdbvkkTIxAAAAuw"]
[Sun Aug 30 03:05:04.840096 2026] [security2:error] [pid 492549:tid 492745] [client 20.63.219.114:16819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "apPkMDqFvOdCFO2AmwpowAAAA-E"]
[Sun Aug 30 03:05:04.846950 2026] [security2:error] [pid 491656:tid 491902] [client 4.205.62.107:58051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/zaza.php"] [unique_id "apPkMIvX_L6VjdbvkkTIyAAAAwg"]
[Sun Aug 30 03:05:04.876673 2026] [security2:error] [pid 491656:tid 491879] [client 158.23.184.117:23983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/configs.php"] [unique_id "apPkMIvX_L6VjdbvkkTI1wAAAvE"]
[Sun Aug 30 03:05:04.876995 2026] [security2:error] [pid 492549:tid 492726] [client 20.104.18.15:43297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/wsd.php"] [unique_id "apPkMDqFvOdCFO2Amwpo3AAAA84"]
[Sun Aug 30 03:05:04.909067 2026] [security2:error] [pid 491656:tid 491872] [client 20.104.104.62:35351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/file66.php"] [unique_id "apPkMIvX_L6VjdbvkkTI6gAAAuo"]
[Sun Aug 30 03:05:04.917679 2026] [security2:error] [pid 492549:tid 492784] [client 193.56.113.32:50970] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "smartmenu.pro"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "apPkMDqFvOdCFO2Amwpo8QAABAg"]
[Sun Aug 30 03:05:04.918652 2026] [security2:error] [pid 492549:tid 492779] [client 20.104.18.15:9086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/manga.php"] [unique_id "apPkMDqFvOdCFO2Amwpo8gAABAM"]
[Sun Aug 30 03:05:04.927573 2026] [security2:error] [pid 492549:tid 492711] [client 20.151.200.44:37835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/blnux.php"] [unique_id "apPkMDqFvOdCFO2Amwpo9wAAA78"]
[Sun Aug 30 03:05:04.933006 2026] [authz_core:error] [pid 492549:tid 492689] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:05:04.933395 2026] [authz_core:error] [pid 492549:tid 492689] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fsamples
[Sun Aug 30 03:05:04.937228 2026] [security2:error] [pid 491656:tid 491828] [client 52.139.37.240:60857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/num.php"] [unique_id "apPkMIvX_L6VjdbvkkTI9wAAAr4"]
[Sun Aug 30 03:05:04.969138 2026] [authz_core:error] [pid 491656:tid 491905] [client 216.73.216.128:11796] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:04.969400 2026] [authz_core:error] [pid 491656:tid 491905] [client 216.73.216.128:11796] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:04.978025 2026] [security2:error] [pid 492549:tid 492789] [client 158.23.147.79:62545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/content.php"] [unique_id "apPkMDqFvOdCFO2AmwppCAAABA0"]
[Sun Aug 30 03:05:05.018895 2026] [security2:error] [pid 492549:tid 492750] [client 20.196.209.81:21124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPkMTqFvOdCFO2AmwppKAAAA-Y"]
[Sun Aug 30 03:05:05.020142 2026] [security2:error] [pid 491656:tid 491868] [client 158.23.184.117:23945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/configuration.php"] [unique_id "apPkMYvX_L6VjdbvkkTJIQAAAuY"]
[Sun Aug 30 03:05:05.044110 2026] [security2:error] [pid 492549:tid 492706] [client 4.205.62.107:25857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/file59.php"] [unique_id "apPkMTqFvOdCFO2AmwppPAAAA7o"]
[Sun Aug 30 03:05:05.056166 2026] [security2:error] [pid 492549:tid 492719] [client 20.48.251.3:59356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/wp-access.php"] [unique_id "apPkMTqFvOdCFO2AmwppQgAAA8c"]
[Sun Aug 30 03:05:05.062321 2026] [security2:error] [pid 492549:tid 492792] [client 20.104.104.62:41091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/blnux.php"] [unique_id "apPkMTqFvOdCFO2AmwppSAAABBA"]
[Sun Aug 30 03:05:05.065690 2026] [security2:error] [pid 492549:tid 492793] [client 4.205.62.107:2782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/phina.php"] [unique_id "apPkMTqFvOdCFO2AmwppTAAABBE"]
[Sun Aug 30 03:05:05.070399 2026] [security2:error] [pid 492549:tid 492733] [client 20.104.18.15:13721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/5PJcpMFsD8B.php"] [unique_id "apPkMTqFvOdCFO2AmwppWQAAA9U"]
[Sun Aug 30 03:05:05.092323 2026] [security2:error] [pid 492549:tid 492721] [client 34.15.141.119:54194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/mail/phpinfo.php"] [unique_id "apPkMTqFvOdCFO2AmwppbgAAA8k"]
[Sun Aug 30 03:05:05.109505 2026] [authz_core:error] [pid 492549:tid 492778] [client 66.249.66.68:43418] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:05.109991 2026] [authz_core:error] [pid 492549:tid 492778] [client 66.249.66.68:43418] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:05.110750 2026] [security2:error] [pid 492549:tid 492712] [client 20.104.50.220:5467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-admin/about.php"] [unique_id "apPkMTqFvOdCFO2AmwpphAAAA8A"]
[Sun Aug 30 03:05:05.152407 2026] [security2:error] [pid 492549:tid 492734] [client 52.139.37.240:61148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/areak1.php"] [unique_id "apPkMTqFvOdCFO2AmwppvAAAA9Y"]
[Sun Aug 30 03:05:05.157471 2026] [security2:error] [pid 492549:tid 492732] [client 136.92.30.49:51996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/beta/phpinfo.php"] [unique_id "apPkMTqFvOdCFO2AmwppvwAAA9Q"]
[Sun Aug 30 03:05:05.162561 2026] [security2:error] [pid 492549:tid 492754] [client 20.104.50.220:32549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/FoxWSOv1.php"] [unique_id "apPkMTqFvOdCFO2AmwppxwAAA-o"]
[Sun Aug 30 03:05:05.164459 2026] [security2:error] [pid 492549:tid 492735] [client 158.23.184.117:23937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/content.php"] [unique_id "apPkMTqFvOdCFO2AmwppywAAA9c"]
[Sun Aug 30 03:05:05.181213 2026] [security2:error] [pid 492549:tid 492760] [client 20.104.18.15:31664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/gos.php"] [unique_id "apPkMTqFvOdCFO2Amwpp3gAAA_A"]
[Sun Aug 30 03:05:05.186476 2026] [authz_core:error] [pid 492549:tid 492758] [client 66.249.66.205:61298] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:05.186792 2026] [authz_core:error] [pid 492549:tid 492758] [client 66.249.66.205:61298] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:05.202735 2026] [security2:error] [pid 492549:tid 492787] [client 20.104.50.220:51636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/style.php"] [unique_id "apPkMTqFvOdCFO2Amwpp8wAABAs"]
[Sun Aug 30 03:05:05.216660 2026] [security2:error] [pid 492549:tid 492700] [client 20.63.219.114:17169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/system.php"] [unique_id "apPkMTqFvOdCFO2AmwpqBAAAA7Q"]
[Sun Aug 30 03:05:05.216799 2026] [security2:error] [pid 492549:tid 492772] [client 20.104.104.62:35366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/attack.php"] [unique_id "apPkMTqFvOdCFO2AmwpqBQAAA_w"]
[Sun Aug 30 03:05:05.218190 2026] [authz_core:error] [pid 492549:tid 492723] [client 66.249.66.44:64466] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:05.218521 2026] [authz_core:error] [pid 492549:tid 492723] [client 66.249.66.44:64466] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:05.220721 2026] [security2:error] [pid 491656:tid 491872] [client 68.155.159.216:60027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-content/radio.php"] [unique_id "apPkMYvX_L6VjdbvkkTJgwAAAuo"]
[Sun Aug 30 03:05:05.245968 2026] [security2:error] [pid 491656:tid 491893] [client 4.205.62.107:44765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/services.php"] [unique_id "apPkMYvX_L6VjdbvkkTJkgAAAv8"]
[Sun Aug 30 03:05:05.258960 2026] [security2:error] [pid 492549:tid 492784] [client 20.104.50.220:47072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/xx.php"] [unique_id "apPkMTqFvOdCFO2AmwpqIwAABAg"]
[Sun Aug 30 03:05:05.259957 2026] [security2:error] [pid 492549:tid 492797] [client 4.205.62.107:36702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/pass4.php"] [unique_id "apPkMTqFvOdCFO2AmwpqJAAABBU"]
[Sun Aug 30 03:05:05.261540 2026] [security2:error] [pid 492549:tid 492714] [client 4.205.62.107:18803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/lm15.php"] [unique_id "apPkMTqFvOdCFO2AmwpqJwAAA8I"]
[Sun Aug 30 03:05:05.293090 2026] [security2:error] [pid 492549:tid 492773] [client 4.205.62.107:60507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/environment.php"] [unique_id "apPkMTqFvOdCFO2AmwpqTgAAA_0"]
[Sun Aug 30 03:05:05.298196 2026] [security2:error] [pid 492549:tid 492692] [client 20.104.50.220:63029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/000.php"] [unique_id "apPkMTqFvOdCFO2AmwpqVgAAA6w"]
[Sun Aug 30 03:05:05.310421 2026] [security2:error] [pid 492549:tid 492697] [client 158.23.184.117:23995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/core.php"] [unique_id "apPkMTqFvOdCFO2AmwpqaQAAA7E"]
[Sun Aug 30 03:05:05.312402 2026] [security2:error] [pid 492549:tid 492749] [client 20.48.251.3:7089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/fucku.php"] [unique_id "apPkMTqFvOdCFO2AmwpqbwAAA-U"]
[Sun Aug 30 03:05:05.337930 2026] [security2:error] [pid 491656:tid 491909] [client 40.83.93.50:8629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/users.php"] [unique_id "apPkMYvX_L6VjdbvkkTJuQAAAw8"]
[Sun Aug 30 03:05:05.341258 2026] [security2:error] [pid 492549:tid 492699] [client 20.104.50.220:27439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/images/getid3s.php"] [unique_id "apPkMTqFvOdCFO2AmwpqlgAAA7M"]
[Sun Aug 30 03:05:05.343292 2026] [security2:error] [pid 492549:tid 492775] [client 20.104.50.220:33335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/sad.php"] [unique_id "apPkMTqFvOdCFO2AmwpqmAAAA_8"]
[Sun Aug 30 03:05:05.345569 2026] [security2:error] [pid 492549:tid 492789] [client 52.139.37.240:19776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/vc.php"] [unique_id "apPkMTqFvOdCFO2AmwpqmgAABA0"]
[Sun Aug 30 03:05:05.358611 2026] [security2:error] [pid 491656:tid 491825] [client 20.104.104.62:35365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/wk/index.php"] [unique_id "apPkMYvX_L6VjdbvkkTJvwAAArs"]
[Sun Aug 30 03:05:05.374432 2026] [security2:error] [pid 492549:tid 492712] [client 193.56.113.32:50974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "smartmenu.pro"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "apPkMTqFvOdCFO2AmwpqvAAAA8A"]
[Sun Aug 30 03:05:05.381443 2026] [security2:error] [pid 492549:tid 492733] [client 4.205.62.107:4616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/ws62.php"] [unique_id "apPkMTqFvOdCFO2AmwpqxgAAA9U"]
[Sun Aug 30 03:05:05.398582 2026] [security2:error] [pid 491656:tid 491828] [client 4.205.62.107:22964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/xin1.php"] [unique_id "apPkMYvX_L6VjdbvkkTJ3QAAAr4"]
[Sun Aug 30 03:05:05.402298 2026] [authz_core:error] [pid 492549:tid 492684] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:05.402585 2026] [authz_core:error] [pid 492549:tid 492684] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:05.409998 2026] [security2:error] [pid 492549:tid 492688] [client 20.196.209.81:17738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/intense/block-css.php"] [unique_id "apPkMTqFvOdCFO2Amwpq2gAAA6g"]
[Sun Aug 30 03:05:05.415478 2026] [security2:error] [pid 492549:tid 492727] [client 20.48.251.3:55547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/ws79.php"] [unique_id "apPkMTqFvOdCFO2Amwpq3QAAA88"]
[Sun Aug 30 03:05:05.452671 2026] [security2:error] [pid 491656:tid 491903] [client 158.23.184.117:23970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/data.php"] [unique_id "apPkMYvX_L6VjdbvkkTJ-AAAAwk"]
[Sun Aug 30 03:05:05.506434 2026] [security2:error] [pid 491656:tid 491849] [client 158.23.147.79:63288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPkMYvX_L6VjdbvkkTKFwAAAtM"]
[Sun Aug 30 03:05:05.507134 2026] [security2:error] [pid 492549:tid 492722] [client 20.48.251.3:51551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/aws_settings.php"] [unique_id "apPkMTqFvOdCFO2AmwprRQAAA8o"]
[Sun Aug 30 03:05:05.508824 2026] [security2:error] [pid 491656:tid 491872] [client 20.104.104.62:35329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/dehnl.php"] [unique_id "apPkMYvX_L6VjdbvkkTKGwAAAuo"]
[Sun Aug 30 03:05:05.524290 2026] [security2:error] [pid 491656:tid 491792] [client 20.48.251.3:44181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/environment.php"] [unique_id "apPkMYvX_L6VjdbvkkTKJgAAApo"]
[Sun Aug 30 03:05:05.537063 2026] [security2:error] [pid 492549:tid 492798] [client 52.139.37.240:61125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPkMTqFvOdCFO2AmwprYAAABBY"]
[Sun Aug 30 03:05:05.558299 2026] [security2:error] [pid 491656:tid 491890] [client 20.104.18.15:33735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/nox.php"] [unique_id "apPkMYvX_L6VjdbvkkTKOAAAAvw"]
[Sun Aug 30 03:05:05.579101 2026] [security2:error] [pid 492549:tid 492745] [client 20.104.50.220:29326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/ler.php"] [unique_id "apPkMTqFvOdCFO2AmwprdwAAA-E"]
[Sun Aug 30 03:05:05.589456 2026] [security2:error] [pid 491656:tid 491794] [client 136.92.30.49:52010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/uat/phpinfo.php"] [unique_id "apPkMYvX_L6VjdbvkkTKTQAAApw"]
[Sun Aug 30 03:05:05.591125 2026] [security2:error] [pid 492549:tid 492714] [client 20.63.219.114:17209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/tflow/min.php"] [unique_id "apPkMTqFvOdCFO2AmwprfAAAA8I"]
[Sun Aug 30 03:05:05.591651 2026] [authz_core:error] [pid 492549:tid 492708] [client 66.249.66.193:49805] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:05.591951 2026] [authz_core:error] [pid 492549:tid 492708] [client 66.249.66.193:49805] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:05.592503 2026] [security2:error] [pid 491656:tid 491805] [client 158.23.184.117:24212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/database.php"] [unique_id "apPkMYvX_L6VjdbvkkTKUAAAAqc"]
[Sun Aug 30 03:05:05.641231 2026] [security2:error] [pid 491656:tid 491871] [client 20.104.104.62:37489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/png.php"] [unique_id "apPkMYvX_L6VjdbvkkTKZgAAAuk"]
[Sun Aug 30 03:05:05.669141 2026] [security2:error] [pid 492549:tid 492709] [client 20.48.251.3:44301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/radio.php"] [unique_id "apPkMTqFvOdCFO2AmwprvQAAA70"]
[Sun Aug 30 03:05:05.695732 2026] [security2:error] [pid 492549:tid 492735] [client 34.15.141.119:45918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/cpanel/phpinfo.php"] [unique_id "apPkMTqFvOdCFO2AmwprzQAAA9c"]
[Sun Aug 30 03:05:05.732839 2026] [security2:error] [pid 491656:tid 491916] [client 158.23.184.117:24207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/db.php"] [unique_id "apPkMYvX_L6VjdbvkkTKmAAAAxY"]
[Sun Aug 30 03:05:05.738334 2026] [security2:error] [pid 492549:tid 492758] [client 20.104.50.220:62824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-config-sample.php"] [unique_id "apPkMTqFvOdCFO2Amwpr8AAAA-4"]
[Sun Aug 30 03:05:05.749204 2026] [security2:error] [pid 491656:tid 491911] [client 52.139.37.240:19781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/core.php"] [unique_id "apPkMYvX_L6VjdbvkkTKogAAAxE"]
[Sun Aug 30 03:05:05.751236 2026] [security2:error] [pid 491656:tid 491836] [client 158.23.147.79:62528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/goat.php"] [unique_id "apPkMYvX_L6VjdbvkkTKpAAAAsY"]
[Sun Aug 30 03:05:05.758476 2026] [security2:error] [pid 492549:tid 492724] [client 68.155.159.216:52766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-includes/index.php"] [unique_id "apPkMTqFvOdCFO2Amwpr_wAAA8w"]
[Sun Aug 30 03:05:05.779199 2026] [security2:error] [pid 492549:tid 492706] [client 20.104.104.62:37440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/txets.php"] [unique_id "apPkMTqFvOdCFO2AmwpsDwAAA7o"]
[Sun Aug 30 03:05:05.785364 2026] [security2:error] [pid 491656:tid 491902] [client 68.155.159.216:52687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/classwithtostring.php"] [unique_id "apPkMYvX_L6VjdbvkkTKuQAAAwg"]
[Sun Aug 30 03:05:05.801811 2026] [security2:error] [pid 492549:tid 492753] [client 20.196.209.81:17736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/login.php"] [unique_id "apPkMTqFvOdCFO2AmwpsJwAAA-k"]
[Sun Aug 30 03:05:05.813404 2026] [security2:error] [pid 492549:tid 492792] [client 40.83.93.50:8339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/class.php"] [unique_id "apPkMTqFvOdCFO2AmwpsOAAABBA"]
[Sun Aug 30 03:05:05.820268 2026] [security2:error] [pid 491656:tid 491812] [client 4.205.62.107:26502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/test.php"] [unique_id "apPkMYvX_L6VjdbvkkTKxwAAAq4"]
[Sun Aug 30 03:05:05.821966 2026] [security2:error] [pid 491656:tid 491863] [client 4.205.62.107:52108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/doc.php"] [unique_id "apPkMYvX_L6VjdbvkkTKyQAAAuE"]
[Sun Aug 30 03:05:05.823361 2026] [security2:error] [pid 491656:tid 491866] [client 193.56.113.32:50984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "smartmenu.pro"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "apPkMYvX_L6VjdbvkkTKygAAAuQ"]
[Sun Aug 30 03:05:05.830904 2026] [security2:error] [pid 492549:tid 492765] [client 20.48.251.3:46210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/environment.php"] [unique_id "apPkMTqFvOdCFO2AmwpsSAAAA_U"]
[Sun Aug 30 03:05:05.874512 2026] [security2:error] [pid 491656:tid 491869] [client 158.23.184.117:23990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/default.php"] [unique_id "apPkMYvX_L6VjdbvkkTK5AAAAuc"]
[Sun Aug 30 03:05:05.887693 2026] [security2:error] [pid 492549:tid 492780] [client 216.244.66.239:45270] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.pctipps.info"] [uri "/blog/internet/thunderbird-spamfilter-mit-googlemail-realisieren.html"] [unique_id "apPkMTqFvOdCFO2AmwpscgAABAQ"]
[Sun Aug 30 03:05:05.887774 2026] [security2:error] [pid 492549:tid 492780] [client 216.244.66.239:45270] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.pctipps.info"] [uri "/blog/internet/thunderbird-spamfilter-mit-googlemail-realisieren.html"] [unique_id "apPkMTqFvOdCFO2AmwpscgAABAQ"]
[Sun Aug 30 03:05:05.898482 2026] [security2:error] [pid 491656:tid 491842] [client 4.205.62.107:64057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/phpsysinfo.php"] [unique_id "apPkMYvX_L6VjdbvkkTK7gAAAsw"]
[Sun Aug 30 03:05:05.902890 2026] [authz_core:error] [pid 492549:tid 492742] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:05.903152 2026] [authz_core:error] [pid 492549:tid 492742] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:05.917176 2026] [authz_core:error] [pid 492549:tid 492711] [client 66.249.66.197:51570] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:05.917624 2026] [authz_core:error] [pid 492549:tid 492711] [client 66.249.66.197:51570] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:05.938632 2026] [security2:error] [pid 491656:tid 491814] [client 20.63.219.114:17155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/tflow/pk.php"] [unique_id "apPkMYvX_L6VjdbvkkTK-gAAArA"]
[Sun Aug 30 03:05:05.946242 2026] [security2:error] [pid 492549:tid 492685] [client 52.139.37.240:61129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/wp-content/min.php"] [unique_id "apPkMTqFvOdCFO2AmwpslgAAA6U"]
[Sun Aug 30 03:05:05.960221 2026] [security2:error] [pid 492549:tid 492748] [client 20.104.104.62:37445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/wp-login.php"] [unique_id "apPkMTqFvOdCFO2AmwpsggAAA-Q"]
[Sun Aug 30 03:05:05.982346 2026] [security2:error] [pid 491656:tid 491896] [client 4.205.62.107:65290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/u88.php"] [unique_id "apPkMYvX_L6VjdbvkkTLCwAAAwI"]
[Sun Aug 30 03:05:06.016542 2026] [security2:error] [pid 492549:tid 492807] [client 158.23.184.117:23988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/dev1s.php"] [unique_id "apPkMjqFvOdCFO2AmwpsxgAABB8"]
[Sun Aug 30 03:05:06.028758 2026] [security2:error] [pid 492549:tid 492707] [client 136.92.30.49:52022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/qa/phpinfo.php"] [unique_id "apPkMjqFvOdCFO2Amwps1AAAA7s"]
[Sun Aug 30 03:05:06.048263 2026] [security2:error] [pid 492549:tid 492689] [client 20.104.18.15:43326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/bulet.php"] [unique_id "apPkMjqFvOdCFO2Amwps5AAAA6k"]
[Sun Aug 30 03:05:06.057879 2026] [security2:error] [pid 492549:tid 492751] [client 158.23.147.79:62500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apPkMjqFvOdCFO2Amwps7wAAA-c"]
[Sun Aug 30 03:05:06.090176 2026] [security2:error] [pid 492549:tid 492731] [client 20.104.104.62:37448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/wp-access.php"] [unique_id "apPkMjqFvOdCFO2AmwptCwAAA9M"]
[Sun Aug 30 03:05:06.152869 2026] [security2:error] [pid 492549:tid 492720] [client 52.139.37.240:19813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "apPkMjqFvOdCFO2AmwptKgAAA8g"]
[Sun Aug 30 03:05:06.156056 2026] [security2:error] [pid 492549:tid 492772] [client 158.23.184.117:24232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/dex.php"] [unique_id "apPkMjqFvOdCFO2AmwptKwAAA_w"]
[Sun Aug 30 03:05:06.157465 2026] [security2:error] [pid 492549:tid 492761] [client 4.205.62.107:32035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/filesystems.php"] [unique_id "apPkMjqFvOdCFO2AmwptLAAAA_E"]
[Sun Aug 30 03:05:06.157858 2026] [security2:error] [pid 492549:tid 492705] [client 20.104.18.15:9038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/asdfghj.php"] [unique_id "apPkMjqFvOdCFO2AmwptLQAAA7k"]
[Sun Aug 30 03:05:06.158839 2026] [security2:error] [pid 492549:tid 492793] [client 4.205.62.107:32026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/koiy.php"] [unique_id "apPkMjqFvOdCFO2AmwptLgAABBE"]
[Sun Aug 30 03:05:06.193023 2026] [security2:error] [pid 492549:tid 492708] [client 20.196.209.81:21129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/min.php"] [unique_id "apPkMjqFvOdCFO2AmwptOwAAA7w"]
[Sun Aug 30 03:05:06.194547 2026] [security2:error] [pid 492549:tid 492693] [client 4.205.62.107:25858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/cli_bootstrap.php"] [unique_id "apPkMjqFvOdCFO2AmwptPAAAA60"]
[Sun Aug 30 03:05:06.280254 2026] [security2:error] [pid 492549:tid 492730] [client 40.83.93.50:8647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/auth.php"] [unique_id "apPkMjqFvOdCFO2AmwptSAAAA9I"]
[Sun Aug 30 03:05:06.282184 2026] [qos:error] [pid 491656:tid 491873] [client 103.133.61.239:40512] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.133.61.239, id=apPkMovX_L6VjdbvkkTLfQAAAus
[Sun Aug 30 03:05:06.282450 2026] [qos:error] [pid 491656:tid 491916] [client 38.172.184.144:45062] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.172.184.144, id=apPkMovX_L6VjdbvkkTLfgAAAxY
[Sun Aug 30 03:05:06.282865 2026] [qos:error] [pid 492549:tid 492688] [client 36.37.155.160:59523] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=36.37.155.160, id=apPkMjqFvOdCFO2AmwptSQAAA6g
[Sun Aug 30 03:05:06.286080 2026] [security2:error] [pid 492549:tid 492804] [client 20.63.219.114:17176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/theme-check/theme-check.php"] [unique_id "apPkMjqFvOdCFO2AmwptSgAABBw"]
[Sun Aug 30 03:05:06.286238 2026] [qos:error] [pid 491656:tid 491905] [client 168.243.77.81:59800] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=168.243.77.81, id=apPkMovX_L6VjdbvkkTLfwAAAws
[Sun Aug 30 03:05:06.287346 2026] [qos:error] [pid 491656:tid 491899] [client 181.224.175.224:34586] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=181.224.175.224, id=apPkMovX_L6VjdbvkkTLgQAAAwU
[Sun Aug 30 03:05:06.287357 2026] [qos:error] [pid 491656:tid 491871] [client 122.8.44.2:12399] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=122.8.44.2, id=apPkMovX_L6VjdbvkkTLgAAAAuk
[Sun Aug 30 03:05:06.288693 2026] [qos:error] [pid 492549:tid 492698] [client 103.157.78.85:37592] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.157.78.85, id=apPkMjqFvOdCFO2AmwptSwAAA7I
[Sun Aug 30 03:05:06.290825 2026] [qos:error] [pid 492549:tid 492776] [client 42.240.136.180:54328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=42.240.136.180, id=apPkMjqFvOdCFO2AmwptTAAABAA
[Sun Aug 30 03:05:06.292463 2026] [qos:error] [pid 491656:tid 491797] [client 109.172.55.227:57608] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=109.172.55.227, id=apPkMovX_L6VjdbvkkTLggAAAp8
[Sun Aug 30 03:05:06.294973 2026] [qos:error] [pid 491656:tid 491799] [client 31.25.11.143:47096] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=31.25.11.143, id=apPkMovX_L6VjdbvkkTLgwAAAqE
[Sun Aug 30 03:05:06.295409 2026] [qos:error] [pid 491656:tid 491832] [client 132.145.207.194:45214] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=132.145.207.194, id=apPkMovX_L6VjdbvkkTLhAAAAsI
[Sun Aug 30 03:05:06.296142 2026] [qos:error] [pid 492549:tid 492694] [client 160.19.19.122:53134] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=160.19.19.122, id=apPkMjqFvOdCFO2AmwptTQAAA64
[Sun Aug 30 03:05:06.298092 2026] [qos:error] [pid 491656:tid 491911] [client 43.160.242.118:50892] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=43.160.242.118, id=apPkMovX_L6VjdbvkkTLhQAAAxE
[Sun Aug 30 03:05:06.299217 2026] [qos:error] [pid 491656:tid 491852] [client 45.151.106.226:60073] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.151.106.226, id=apPkMovX_L6VjdbvkkTLhgAAAtY
[Sun Aug 30 03:05:06.300418 2026] [qos:error] [pid 491656:tid 491828] [client 37.221.241.115:47958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=37.221.241.115, id=apPkMovX_L6VjdbvkkTLhwAAAr4
[Sun Aug 30 03:05:06.300768 2026] [qos:error] [pid 492549:tid 492740] [client 160.22.17.4:40574] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=160.22.17.4, id=apPkMjqFvOdCFO2AmwptUAAAA9w
[Sun Aug 30 03:05:06.301215 2026] [qos:error] [pid 491656:tid 491908] [client 38.210.179.190:56747] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.210.179.190, id=apPkMovX_L6VjdbvkkTLiAAAAw4
[Sun Aug 30 03:05:06.301812 2026] [qos:error] [pid 492549:tid 492781] [client 103.179.252.161:60512] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.179.252.161, id=apPkMjqFvOdCFO2AmwptTwAABAU
[Sun Aug 30 03:05:06.302580 2026] [security2:error] [pid 492549:tid 492733] [client 34.15.141.119:45930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/hosting/phpinfo.php"] [unique_id "apPkMjqFvOdCFO2AmwptUQAAA9U"]
[Sun Aug 30 03:05:06.302703 2026] [qos:error] [pid 491656:tid 491874] [client 79.121.102.227:34273] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=79.121.102.227, id=apPkMovX_L6VjdbvkkTLiQAAAuw
[Sun Aug 30 03:05:06.303231 2026] [qos:error] [pid 491656:tid 491811] [client 116.204.229.66:53492] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=116.204.229.66, id=apPkMovX_L6VjdbvkkTLigAAAq0
[Sun Aug 30 03:05:06.306057 2026] [qos:error] [pid 491656:tid 491818] [client 187.13.218.112:17874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=187.13.218.112, id=apPkMovX_L6VjdbvkkTLiwAAArQ
[Sun Aug 30 03:05:06.306220 2026] [qos:error] [pid 492549:tid 492702] [client 38.191.194.27:57168] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.191.194.27, id=apPkMjqFvOdCFO2AmwptUgAAA7Y
[Sun Aug 30 03:05:06.307304 2026] [qos:error] [pid 492549:tid 492775] [client 78.159.131.108:46036] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=78.159.131.108, id=apPkMjqFvOdCFO2AmwptUwAAA_8
[Sun Aug 30 03:05:06.307817 2026] [qos:error] [pid 491656:tid 491840] [client 45.175.137.141:43392] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.175.137.141, id=apPkMovX_L6VjdbvkkTLjAAAAso
[Sun Aug 30 03:05:06.312291 2026] [qos:error] [pid 491656:tid 491869] [client 181.13.221.154:60360] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=181.13.221.154, id=apPkMovX_L6VjdbvkkTLjwAAAuc
[Sun Aug 30 03:05:06.312780 2026] [qos:error] [pid 491656:tid 491875] [client 203.76.117.230:51700] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=203.76.117.230, id=apPkMovX_L6VjdbvkkTLjgAAAu0
[Sun Aug 30 03:05:06.315022 2026] [qos:error] [pid 491656:tid 491823] [client 102.223.22.130:33794] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=102.223.22.130, id=apPkMovX_L6VjdbvkkTLkAAAArk
[Sun Aug 30 03:05:06.315173 2026] [qos:error] [pid 491656:tid 491795] [client 164.163.188.113:43856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=164.163.188.113, id=apPkMovX_L6VjdbvkkTLkQAAAp0
[Sun Aug 30 03:05:06.317653 2026] [qos:error] [pid 492549:tid 492807] [client 148.230.166.137:55084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=148.230.166.137, id=apPkMjqFvOdCFO2AmwptVAAABB8
[Sun Aug 30 03:05:06.319845 2026] [qos:error] [pid 491656:tid 491906] [client 41.72.199.106:49874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=41.72.199.106, id=apPkMovX_L6VjdbvkkTLkgAAAww
[Sun Aug 30 03:05:06.320521 2026] [qos:error] [pid 492549:tid 492757] [client 193.32.176.109:59125] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=193.32.176.109, id=apPkMjqFvOdCFO2AmwptVQAAA-0
[Sun Aug 30 03:05:06.320557 2026] [qos:error] [pid 491656:tid 491893] [client 72.62.59.63:46660] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=72.62.59.63, id=apPkMovX_L6VjdbvkkTLkwAAAv8
[Sun Aug 30 03:05:06.321217 2026] [qos:error] [pid 492549:tid 492718] [client 189.206.156.174:45952] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=189.206.156.174, id=apPkMjqFvOdCFO2AmwptVgAAA8Y
[Sun Aug 30 03:05:06.321347 2026] [qos:error] [pid 491656:tid 491901] [client 38.51.207.118:45420] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.51.207.118, id=apPkMovX_L6VjdbvkkTLlAAAAwc
[Sun Aug 30 03:05:06.323100 2026] [qos:error] [pid 491656:tid 491827] [client 45.173.207.126:55059] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.173.207.126, id=apPkMovX_L6VjdbvkkTLlQAAAr0
[Sun Aug 30 03:05:06.325064 2026] [qos:error] [pid 492549:tid 492771] [client 154.113.209.162:52398] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=154.113.209.162, id=apPkMjqFvOdCFO2AmwptVwAAA_s
[Sun Aug 30 03:05:06.326924 2026] [qos:error] [pid 492549:tid 492789] [client 181.205.205.170:45958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=181.205.205.170, id=apPkMjqFvOdCFO2AmwptWAAABA0
[Sun Aug 30 03:05:06.328573 2026] [qos:error] [pid 492549:tid 492806] [client 122.43.226.106:63268] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=122.43.226.106, id=apPkMjqFvOdCFO2AmwptWQAABB4
[Sun Aug 30 03:05:06.339058 2026] [qos:error] [pid 491656:tid 491907] [client 94.178.188.236:60288] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=94.178.188.236, id=apPkMovX_L6VjdbvkkTLlwAAAw0
[Sun Aug 30 03:05:06.340673 2026] [qos:error] [pid 491656:tid 491844] [client 103.157.78.190:50542] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.157.78.190, id=apPkMovX_L6VjdbvkkTLmAAAAs4
[Sun Aug 30 03:05:06.341511 2026] [qos:error] [pid 492549:tid 492691] [client 45.167.125.62:39776] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.167.125.62, id=apPkMjqFvOdCFO2AmwptWgAAA6s
[Sun Aug 30 03:05:06.346930 2026] [qos:error] [pid 492549:tid 492784] [client 113.192.1.154:38058] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=113.192.1.154, id=apPkMjqFvOdCFO2AmwptWwAABAg
[Sun Aug 30 03:05:06.350313 2026] [qos:error] [pid 492549:tid 492738] [client 177.53.154.51:60588] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=177.53.154.51, id=apPkMjqFvOdCFO2AmwptXAAAA9o
[Sun Aug 30 03:05:06.353381 2026] [qos:error] [pid 492549:tid 492745] [client 38.137.232.138:37311] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.137.232.138, id=apPkMjqFvOdCFO2AmwptXQAAA-E
[Sun Aug 30 03:05:06.355236 2026] [qos:error] [pid 491656:tid 491834] [client 186.1.173.12:55408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=186.1.173.12, id=apPkMovX_L6VjdbvkkTLmQAAAsQ
[Sun Aug 30 03:05:06.356041 2026] [qos:error] [pid 492549:tid 492808] [client 45.144.54.40:34434] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.144.54.40, id=apPkMjqFvOdCFO2AmwptXgAABCA
[Sun Aug 30 03:05:06.357359 2026] [qos:error] [pid 492549:tid 492751] [client 103.67.84.58:50502] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.67.84.58, id=apPkMjqFvOdCFO2AmwptXwAAA-c
[Sun Aug 30 03:05:06.357979 2026] [qos:error] [pid 491656:tid 491873] [client 91.239.208.190:48530] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=91.239.208.190, id=apPkMovX_L6VjdbvkkTLmgAAAus
[Sun Aug 30 03:05:06.358037 2026] [qos:error] [pid 491656:tid 491836] [client 222.254.58.94:54616] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=222.254.58.94, id=apPkMovX_L6VjdbvkkTLmwAAAsY
[Sun Aug 30 03:05:06.358200 2026] [qos:error] [pid 491656:tid 491916] [client 102.210.1.158:37204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=102.210.1.158, id=apPkMovX_L6VjdbvkkTLnAAAAxY
[Sun Aug 30 03:05:06.358477 2026] [qos:error] [pid 491656:tid 491803] [client 139.84.133.240:46348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=139.84.133.240, id=apPkMovX_L6VjdbvkkTLnQAAAqU
[Sun Aug 30 03:05:06.359516 2026] [qos:error] [pid 492549:tid 492722] [client 138.124.240.198:54878] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=138.124.240.198, id=apPkMjqFvOdCFO2AmwptYAAAA8o
[Sun Aug 30 03:05:06.361019 2026] [qos:error] [pid 492549:tid 492720] [client 45.174.169.4:47882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.174.169.4, id=apPkMjqFvOdCFO2AmwptYQAAA8g
[Sun Aug 30 03:05:06.361215 2026] [qos:error] [pid 492549:tid 492772] [client 220.158.232.118:45730] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=220.158.232.118, id=apPkMjqFvOdCFO2AmwptYgAAA_w
[Sun Aug 30 03:05:06.369091 2026] [qos:error] [pid 491656:tid 491905] [client 190.11.250.136:58078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=190.11.250.136, id=apPkMovX_L6VjdbvkkTLngAAAws
[Sun Aug 30 03:05:06.373376 2026] [qos:error] [pid 492549:tid 492761] [client 112.17.53.103:55896] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=112.17.53.103, id=apPkMjqFvOdCFO2AmwptYwAAA_E
[Sun Aug 30 03:05:06.374731 2026] [qos:error] [pid 492549:tid 492705] [client 75.109.189.86:59652] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=75.109.189.86, id=apPkMjqFvOdCFO2AmwptZAAAA7k
[Sun Aug 30 03:05:06.375950 2026] [qos:error] [pid 488669:tid 488821] [client 176.53.182.170:40604] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=176.53.182.170, id=apPkMtRh6OewFvqQpDlxOQAAARg
[Sun Aug 30 03:05:06.376416 2026] [qos:error] [pid 492549:tid 492793] [client 202.47.189.40:60096] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=202.47.189.40, id=apPkMjqFvOdCFO2AmwptZQAABBE
[Sun Aug 30 03:05:06.377681 2026] [qos:error] [pid 492549:tid 492726] [client 49.151.178.42:39222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=49.151.178.42, id=apPkMjqFvOdCFO2AmwptZgAAA84
[Sun Aug 30 03:05:06.380628 2026] [qos:error] [pid 491656:tid 491899] [client 179.225.55.3:58500] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=179.225.55.3, id=apPkMovX_L6VjdbvkkTLnwAAAwU
[Sun Aug 30 03:05:06.382166 2026] [qos:error] [pid 491656:tid 491871] [client 170.246.144.196:57044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=170.246.144.196, id=apPkMovX_L6VjdbvkkTLoAAAAuk
[Sun Aug 30 03:05:06.389142 2026] [qos:error] [pid 491656:tid 491797] [client 179.1.98.61:51582] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=179.1.98.61, id=apPkMovX_L6VjdbvkkTLoQAAAp8
[Sun Aug 30 03:05:06.389387 2026] [qos:error] [pid 491656:tid 491801] [client 189.4.65.74:60456] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=189.4.65.74, id=apPkMovX_L6VjdbvkkTLogAAAqM
[Sun Aug 30 03:05:06.398202 2026] [qos:error] [pid 491656:tid 491883] [client 198.15.30.122:57814] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=198.15.30.122, id=apPkMovX_L6VjdbvkkTLowAAAvU
[Sun Aug 30 03:05:06.401750 2026] [authz_core:error] [pid 492549:tid 492810] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:06.402018 2026] [authz_core:error] [pid 492549:tid 492810] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:06.404562 2026] [qos:error] [pid 492549:tid 492797] [client 185.220.101.174:19229] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=185.220.101.174, id=apPkMjqFvOdCFO2AmwptaQAABBU
[Sun Aug 30 03:05:06.406214 2026] [qos:error] [pid 492549:tid 492790] [client 103.150.64.71:34963] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.150.64.71, id=apPkMjqFvOdCFO2AmwptagAABA4
[Sun Aug 30 03:05:06.407925 2026] [qos:error] [pid 492549:tid 492755] [client 168.194.147.18:47326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=168.194.147.18, id=apPkMjqFvOdCFO2AmwptawAAA-s
[Sun Aug 30 03:05:06.409535 2026] [qos:error] [pid 491656:tid 491832] [client 154.113.208.190:40461] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=154.113.208.190, id=apPkMovX_L6VjdbvkkTLpQAAAsI
[Sun Aug 30 03:05:06.409582 2026] [qos:error] [pid 491656:tid 491799] [client 130.110.103.245:53100] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=130.110.103.245, id=apPkMovX_L6VjdbvkkTLpAAAAqE
[Sun Aug 30 03:05:06.411249 2026] [qos:error] [pid 492549:tid 492697] [client 82.102.11.164:47110] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=82.102.11.164, id=apPkMjqFvOdCFO2AmwptbAAAA7E
[Sun Aug 30 03:05:06.411680 2026] [qos:error] [pid 492549:tid 492782] [client 204.186.254.106:42584] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=204.186.254.106, id=apPkMjqFvOdCFO2AmwptbQAABAY
[Sun Aug 30 03:05:06.414091 2026] [qos:error] [pid 491656:tid 491911] [client 157.15.40.252:38165] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=157.15.40.252, id=apPkMovX_L6VjdbvkkTLpgAAAxE
[Sun Aug 30 03:05:06.415005 2026] [qos:error] [pid 491656:tid 491852] [client 195.135.255.98:51350] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=195.135.255.98, id=apPkMovX_L6VjdbvkkTLpwAAAtY
[Sun Aug 30 03:05:06.415165 2026] [qos:error] [pid 492549:tid 492762] [client 157.20.252.154:34310] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=157.20.252.154, id=apPkMjqFvOdCFO2AmwptbgAAA_I
[Sun Aug 30 03:05:06.415807 2026] [qos:error] [pid 492549:tid 492689] [client 103.185.147.199:43950] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.185.147.199, id=apPkMjqFvOdCFO2AmwptbwAAA6k
[Sun Aug 30 03:05:06.416317 2026] [qos:error] [pid 491656:tid 491828] [client 1.53.159.155:38987] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=1.53.159.155, id=apPkMovX_L6VjdbvkkTLqAAAAr4
[Sun Aug 30 03:05:06.418599 2026] [qos:error] [pid 492549:tid 492690] [client 95.135.140.98:56693] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=95.135.140.98, id=apPkMjqFvOdCFO2AmwptcAAAA6o
[Sun Aug 30 03:05:06.422414 2026] [qos:error] [pid 492549:tid 492712] [client 190.7.24.103:46159] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=190.7.24.103, id=apPkMjqFvOdCFO2AmwptcQAAA8A
[Sun Aug 30 03:05:06.422797 2026] [qos:error] [pid 492549:tid 492734] [client 126.209.13.194:42174] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=126.209.13.194, id=apPkMjqFvOdCFO2AmwptcgAAA9Y
[Sun Aug 30 03:05:06.423023 2026] [qos:error] [pid 492549:tid 492798] [client 104.28.251.138:53280] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=104.28.251.138, id=apPkMjqFvOdCFO2AmwptcwAABBY
[Sun Aug 30 03:05:06.426145 2026] [qos:error] [pid 492549:tid 492692] [client 89.37.63.17:40962] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=89.37.63.17, id=apPkMjqFvOdCFO2AmwptdAAAA6w
[Sun Aug 30 03:05:06.426150 2026] [qos:error] [pid 492549:tid 492805] [client 43.156.114.4:54378] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=43.156.114.4, id=apPkMjqFvOdCFO2AmwptdQAABB0
[Sun Aug 30 03:05:06.431754 2026] [qos:error] [pid 492549:tid 492699] [client 159.195.43.169:35158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=159.195.43.169, id=apPkMjqFvOdCFO2AmwptdgAAA7M
[Sun Aug 30 03:05:06.432308 2026] [qos:error] [pid 491656:tid 491874] [client 58.63.243.11:50636] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=58.63.243.11, id=apPkMovX_L6VjdbvkkTLqgAAAuw
[Sun Aug 30 03:05:06.432313 2026] [qos:error] [pid 492549:tid 492711] [client 146.70.137.34:63433] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=146.70.137.34, id=apPkMjqFvOdCFO2AmwptdwAAA78
[Sun Aug 30 03:05:06.432613 2026] [qos:error] [pid 491656:tid 491811] [client 148.224.90.8:58233] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=148.224.90.8, id=apPkMovX_L6VjdbvkkTLqwAAAq0
[Sun Aug 30 03:05:06.436710 2026] [qos:error] [pid 492549:tid 492708] [client 45.162.230.58:50948] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.162.230.58, id=apPkMjqFvOdCFO2AmwpteAAAA7w
[Sun Aug 30 03:05:06.437197 2026] [qos:error] [pid 492549:tid 492708] [client 45.162.230.58:50948] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.162.230.58, id=apPkMjqFvOdCFO2AmwpteQAAA7w
[Sun Aug 30 03:05:06.441027 2026] [qos:error] [pid 492549:tid 492729] [client 217.177.33.53:49415] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=217.177.33.53, id=apPkMjqFvOdCFO2AmwptegAAA9E
[Sun Aug 30 03:05:06.441843 2026] [qos:error] [pid 491656:tid 491818] [client 45.189.36.6:57718] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.189.36.6, id=apPkMovX_L6VjdbvkkTLrAAAArQ
[Sun Aug 30 03:05:06.442814 2026] [qos:error] [pid 492549:tid 492710] [client 45.127.58.70:37910] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.127.58.70, id=apPkMjqFvOdCFO2AmwptewAAA74
[Sun Aug 30 03:05:06.446348 2026] [qos:error] [pid 492549:tid 492779] [client 187.108.236.70:34938] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=187.108.236.70, id=apPkMjqFvOdCFO2AmwptfAAABAM
[Sun Aug 30 03:05:06.447861 2026] [qos:error] [pid 491656:tid 491840] [client 34.134.26.114:34818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=34.134.26.114, id=apPkMovX_L6VjdbvkkTLrQAAAso
[Sun Aug 30 03:05:06.448660 2026] [qos:error] [pid 492549:tid 492730] [client 82.114.228.67:53058] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=82.114.228.67, id=apPkMjqFvOdCFO2AmwptfQAAA9I
[Sun Aug 30 03:05:06.451316 2026] [qos:error] [pid 492549:tid 492688] [client 202.154.241.199:33095] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=202.154.241.199, id=apPkMjqFvOdCFO2AmwptfgAAA6g
[Sun Aug 30 03:05:06.451682 2026] [qos:error] [pid 491656:tid 491869] [client 14.241.37.80:43540] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=14.241.37.80, id=apPkMovX_L6VjdbvkkTLrgAAAuc
[Sun Aug 30 03:05:06.456359 2026] [qos:error] [pid 492549:tid 492804] [client 172.239.18.67:53546] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=172.239.18.67, id=apPkMjqFvOdCFO2AmwptfwAABBw
[Sun Aug 30 03:05:06.457677 2026] [qos:error] [pid 491656:tid 491875] [client 31.7.86.35:53710] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=31.7.86.35, id=apPkMovX_L6VjdbvkkTLrwAAAu0
[Sun Aug 30 03:05:06.458990 2026] [qos:error] [pid 491656:tid 491823] [client 160.202.42.156:43947] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=160.202.42.156, id=apPkMovX_L6VjdbvkkTLsAAAArk
[Sun Aug 30 03:05:06.461476 2026] [qos:error] [pid 492549:tid 492698] [client 103.156.17.171:59518] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.156.17.171, id=apPkMjqFvOdCFO2AmwptgAAAA7I
[Sun Aug 30 03:05:06.462472 2026] [qos:error] [pid 491656:tid 491795] [client 36.93.143.241:52536] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=36.93.143.241, id=apPkMovX_L6VjdbvkkTLsQAAAp0
[Sun Aug 30 03:05:06.466165 2026] [qos:error] [pid 491656:tid 491872] [client 62.201.217.243:36733] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=62.201.217.243, id=apPkMovX_L6VjdbvkkTLsgAAAuo
[Sun Aug 30 03:05:06.467016 2026] [qos:error] [pid 492549:tid 492694] [client 64.76.73.131:34540] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=64.76.73.131, id=apPkMjqFvOdCFO2AmwptgQAAA64
[Sun Aug 30 03:05:06.470416 2026] [qos:error] [pid 491656:tid 491906] [client 190.188.131.87:56977] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=190.188.131.87, id=apPkMovX_L6VjdbvkkTLswAAAww
[Sun Aug 30 03:05:06.474927 2026] [qos:error] [pid 491656:tid 491893] [client 200.146.199.106:41760] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=200.146.199.106, id=apPkMovX_L6VjdbvkkTLtAAAAv8
[Sun Aug 30 03:05:06.476046 2026] [qos:error] [pid 492549:tid 492781] [client 37.58.221.247:58709] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=37.58.221.247, id=apPkMjqFvOdCFO2AmwptggAABAU
[Sun Aug 30 03:05:06.476557 2026] [qos:error] [pid 492549:tid 492733] [client 121.169.46.116:58546] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=121.169.46.116, id=apPkMjqFvOdCFO2AmwpthAAAA9U
[Sun Aug 30 03:05:06.478568 2026] [qos:error] [pid 491656:tid 491901] [client 72.56.60.134:36912] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=72.56.60.134, id=apPkMovX_L6VjdbvkkTLtQAAAwc
[Sun Aug 30 03:05:06.483682 2026] [qos:error] [pid 491656:tid 491827] [client 14.235.249.191:47916] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=14.235.249.191, id=apPkMovX_L6VjdbvkkTLtgAAAr0
[Sun Aug 30 03:05:06.487386 2026] [qos:error] [pid 491656:tid 491907] [client 185.222.2.10:33672] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=185.222.2.10, id=apPkMovX_L6VjdbvkkTLtwAAAw0
[Sun Aug 30 03:05:06.487405 2026] [qos:error] [pid 491656:tid 491844] [client 103.248.210.28:55052] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=103.248.210.28, id=apPkMovX_L6VjdbvkkTLuAAAAs4
[Sun Aug 30 03:05:06.487750 2026] [qos:error] [pid 491656:tid 491807] [client 103.155.62.227:58522] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.155.62.227, id=apPkMovX_L6VjdbvkkTLuQAAAqk
[Sun Aug 30 03:05:06.492046 2026] [qos:error] [pid 491656:tid 491834] [client 38.172.170.82:58902] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.172.170.82, id=apPkMovX_L6VjdbvkkTLugAAAsQ
[Sun Aug 30 03:05:06.497777 2026] [qos:error] [pid 491656:tid 491873] [client 185.225.42.73:48746] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=185.225.42.73, id=apPkMovX_L6VjdbvkkTLuwAAAus
[Sun Aug 30 03:05:06.498607 2026] [qos:error] [pid 491656:tid 491836] [client 123.25.252.5:44749] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=123.25.252.5, id=apPkMovX_L6VjdbvkkTLvAAAAsY
[Sun Aug 30 03:05:06.498857 2026] [qos:error] [pid 492549:tid 492702] [client 126.209.84.5:52756] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=126.209.84.5, id=apPkMjqFvOdCFO2AmwpthQAAA7Y
[Sun Aug 30 03:05:06.499155 2026] [qos:error] [pid 492549:tid 492775] [client 50.110.229.125:50276] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.110.229.125, id=apPkMjqFvOdCFO2AmwpthgAAA_8
[Sun Aug 30 03:05:06.499570 2026] [qos:error] [pid 492549:tid 492748] [client 82.193.116.160:40420] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=82.193.116.160, id=apPkMjqFvOdCFO2AmwpthwAAA-Q
[Sun Aug 30 03:05:06.499855 2026] [qos:error] [pid 492549:tid 492807] [client 192.145.124.230:17878] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=192.145.124.230, id=apPkMjqFvOdCFO2AmwptiAAABB8
[Sun Aug 30 03:05:06.500910 2026] [qos:error] [pid 492549:tid 492802] [client 95.3.69.222:53386] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=95.3.69.222, id=apPkMjqFvOdCFO2AmwptiQAABBo
[Sun Aug 30 03:05:06.507349 2026] [qos:error] [pid 491656:tid 491916] [client 157.15.62.173:47620] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=157.15.62.173, id=apPkMovX_L6VjdbvkkTLvQAAAxY
[Sun Aug 30 03:05:06.510258 2026] [qos:error] [pid 491656:tid 491803] [client 37.193.101.148:65064] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=37.193.101.148, id=apPkMovX_L6VjdbvkkTLvgAAAqU
[Sun Aug 30 03:05:06.510261 2026] [qos:error] [pid 491656:tid 491905] [client 122.201.27.91:60800] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=122.201.27.91, id=apPkMovX_L6VjdbvkkTLvwAAAws
[Sun Aug 30 03:05:06.511570 2026] [qos:error] [pid 491656:tid 491871] [client 106.51.56.127:38848] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=106.51.56.127, id=apPkMovX_L6VjdbvkkTLwQAAAuk
[Sun Aug 30 03:05:06.513742 2026] [qos:error] [pid 491656:tid 491797] [client 43.109.48.179:33412] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=43.109.48.179, id=apPkMovX_L6VjdbvkkTLwgAAAp8
[Sun Aug 30 03:05:06.514780 2026] [qos:error] [pid 492549:tid 492737] [client 45.180.62.250:53562] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.180.62.250, id=apPkMjqFvOdCFO2AmwptigAAA9k
[Sun Aug 30 03:05:06.515167 2026] [qos:error] [pid 491656:tid 491801] [client 114.9.26.202:51726] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=114.9.26.202, id=apPkMovX_L6VjdbvkkTLwwAAAqM
[Sun Aug 30 03:05:06.516421 2026] [qos:error] [pid 492549:tid 492718] [client 87.239.251.202:36519] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=87.239.251.202, id=apPkMjqFvOdCFO2AmwptiwAAA8Y
[Sun Aug 30 03:05:06.516655 2026] [qos:error] [pid 491656:tid 491883] [client 43.156.228.168:49864] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=43.156.228.168, id=apPkMovX_L6VjdbvkkTLxAAAAvU
[Sun Aug 30 03:05:06.517608 2026] [qos:error] [pid 491656:tid 491832] [client 23.172.217.26:53588] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=23.172.217.26, id=apPkMovX_L6VjdbvkkTLxQAAAsI
[Sun Aug 30 03:05:06.518349 2026] [qos:error] [pid 491656:tid 491799] [client 14.179.32.219:50843] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=14.179.32.219, id=apPkMovX_L6VjdbvkkTLxgAAAqE
[Sun Aug 30 03:05:06.530738 2026] [qos:error] [pid 492549:tid 492789] [client 187.190.58.124:36190] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=187.190.58.124, id=apPkMjqFvOdCFO2AmwptjAAABA0
[Sun Aug 30 03:05:06.531884 2026] [qos:error] [pid 491656:tid 491911] [client 159.89.53.119:34930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=159.89.53.119, id=apPkMovX_L6VjdbvkkTLxwAAAxE
[Sun Aug 30 03:05:06.540306 2026] [qos:error] [pid 492549:tid 492806] [client 38.19.43.106:46336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.19.43.106, id=apPkMjqFvOdCFO2AmwptjQAABB4
[Sun Aug 30 03:05:06.543882 2026] [qos:error] [pid 491656:tid 491852] [client 154.53.161.191:60348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=154.53.161.191, id=apPkMovX_L6VjdbvkkTLyAAAAtY
[Sun Aug 30 03:05:06.544600 2026] [qos:error] [pid 492549:tid 492691] [client 45.127.58.70:38450] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.127.58.70, id=apPkMjqFvOdCFO2AmwptjgAAA6s
[Sun Aug 30 03:05:06.550655 2026] [qos:error] [pid 491656:tid 491828] [client 12.218.209.130:53697] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=12.218.209.130, id=apPkMovX_L6VjdbvkkTLyQAAAr4
[Sun Aug 30 03:05:06.551502 2026] [qos:error] [pid 492549:tid 492721] [client 49.48.65.231:48630] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=49.48.65.231, id=apPkMjqFvOdCFO2AmwptjwAAA8k
[Sun Aug 30 03:05:06.553474 2026] [qos:error] [pid 492549:tid 492784] [client 142.93.174.35:60085] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=142.93.174.35, id=apPkMjqFvOdCFO2AmwptkAAABAg
[Sun Aug 30 03:05:06.558206 2026] [qos:error] [pid 491656:tid 491870] [client 138.97.250.237:50738] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=138.97.250.237, id=apPkMovX_L6VjdbvkkTLygAAAug
[Sun Aug 30 03:05:06.561454 2026] [qos:error] [pid 491656:tid 491874] [client 117.5.47.62:57164] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=117.5.47.62, id=apPkMovX_L6VjdbvkkTLywAAAuw
[Sun Aug 30 03:05:06.561488 2026] [qos:error] [pid 492549:tid 492738] [client 103.133.201.223:41526] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=103.133.201.223, id=apPkMjqFvOdCFO2AmwptkQAAA9o
[Sun Aug 30 03:05:06.561907 2026] [qos:error] [pid 491656:tid 491811] [client 73.109.227.116:46938] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=73.109.227.116, id=apPkMovX_L6VjdbvkkTLzAAAAq0
[Sun Aug 30 03:05:06.563367 2026] [qos:error] [pid 492549:tid 492745] [client 160.187.221.222:42274] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=160.187.221.222, id=apPkMjqFvOdCFO2AmwptkgAAA-E
[Sun Aug 30 03:05:06.568863 2026] [qos:error] [pid 492549:tid 492808] [client 35.235.153.76:16384] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=35.235.153.76, id=apPkMjqFvOdCFO2AmwptkwAABCA
[Sun Aug 30 03:05:06.570537 2026] [qos:error] [pid 491656:tid 491791] [client 209.178.136.142:50966] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=209.178.136.142, id=apPkMovX_L6VjdbvkkTLzQAAApk
[Sun Aug 30 03:05:06.570543 2026] [qos:error] [pid 492549:tid 492751] [client 190.97.239.60:40308] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=190.97.239.60, id=apPkMjqFvOdCFO2AmwptlAAAA-c
[Sun Aug 30 03:05:06.572567 2026] [qos:error] [pid 491656:tid 491818] [client 103.38.182.242:33541] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.38.182.242, id=apPkMovX_L6VjdbvkkTLzgAAArQ
[Sun Aug 30 03:05:06.574874 2026] [qos:error] [pid 491656:tid 491878] [client 45.195.249.154:55080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.195.249.154, id=apPkMovX_L6VjdbvkkTLzwAAAvA
[Sun Aug 30 03:05:06.575871 2026] [qos:error] [pid 492549:tid 492722] [client 160.19.145.101:38532] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=160.19.145.101, id=apPkMjqFvOdCFO2AmwptlQAAA8o
[Sun Aug 30 03:05:06.581185 2026] [qos:error] [pid 491656:tid 491840] [client 14.169.77.73:46962] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=14.169.77.73, id=apPkMovX_L6VjdbvkkTL0AAAAso
[Sun Aug 30 03:05:06.588588 2026] [qos:error] [pid 491656:tid 491869] [client 8.219.64.236:52258] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=8.219.64.236, id=apPkMovX_L6VjdbvkkTL0QAAAuc
[Sun Aug 30 03:05:06.601555 2026] [qos:error] [pid 492549:tid 492761] [client 49.145.53.184:58670] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=49.145.53.184, id=apPkMjqFvOdCFO2AmwptlgAAA_E
[Sun Aug 30 03:05:06.603348 2026] [qos:error] [pid 491656:tid 491875] [client 27.76.160.76:35290] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=27.76.160.76, id=apPkMovX_L6VjdbvkkTL0gAAAu0
[Sun Aug 30 03:05:06.604160 2026] [qos:error] [pid 491656:tid 491823] [client 171.5.130.187:35438] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=171.5.130.187, id=apPkMovX_L6VjdbvkkTL0wAAArk
[Sun Aug 30 03:05:06.608282 2026] [qos:error] [pid 491656:tid 491795] [client 213.244.95.175:35386] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=213.244.95.175, id=apPkMovX_L6VjdbvkkTL1AAAAp0
[Sun Aug 30 03:05:06.611206 2026] [qos:error] [pid 491656:tid 491872] [client 85.117.63.207:51300] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=85.117.63.207, id=apPkMovX_L6VjdbvkkTL1QAAAuo
[Sun Aug 30 03:05:06.614008 2026] [qos:error] [pid 492549:tid 492793] [client 49.156.22.231:36166] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=49.156.22.231, id=apPkMjqFvOdCFO2AmwptmAAABBE
[Sun Aug 30 03:05:06.614314 2026] [qos:error] [pid 492549:tid 492726] [client 163.227.149.135:50920] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=163.227.149.135, id=apPkMjqFvOdCFO2AmwptmQAAA84
[Sun Aug 30 03:05:06.615133 2026] [qos:error] [pid 491656:tid 491906] [client 45.176.99.58:41272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.176.99.58, id=apPkMovX_L6VjdbvkkTL1gAAAww
[Sun Aug 30 03:05:06.617874 2026] [qos:error] [pid 492549:tid 492758] [client 160.19.18.127:52588] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=160.19.18.127, id=apPkMjqFvOdCFO2AmwptmgAAA-4
[Sun Aug 30 03:05:06.619859 2026] [qos:error] [pid 492549:tid 492797] [client 103.188.173.66:53696] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.188.173.66, id=apPkMjqFvOdCFO2AmwptmwAABBU
[Sun Aug 30 03:05:06.620788 2026] [qos:error] [pid 492549:tid 492790] [client 103.138.123.199:37472] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.138.123.199, id=apPkMjqFvOdCFO2AmwptnAAABA4
[Sun Aug 30 03:05:06.621266 2026] [qos:error] [pid 491656:tid 491893] [client 190.100.200.3:44882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=190.100.200.3, id=apPkMovX_L6VjdbvkkTL1wAAAv8
[Sun Aug 30 03:05:06.622144 2026] [qos:error] [pid 491656:tid 491901] [client 38.210.179.77:32822] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.210.179.77, id=apPkMovX_L6VjdbvkkTL2AAAAwc
[Sun Aug 30 03:05:06.622243 2026] [qos:error] [pid 491656:tid 491827] [client 203.91.118.210:52830] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=203.91.118.210, id=apPkMovX_L6VjdbvkkTL2QAAAr0
[Sun Aug 30 03:05:06.624026 2026] [qos:error] [pid 491656:tid 491844] [client 45.127.58.70:37554] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.127.58.70, id=apPkMovX_L6VjdbvkkTL2gAAAs4
[Sun Aug 30 03:05:06.625765 2026] [qos:error] [pid 492549:tid 492697] [client 165.0.69.116:43204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=165.0.69.116, id=apPkMjqFvOdCFO2AmwptnQAAA7E
[Sun Aug 30 03:05:06.626152 2026] [qos:error] [pid 491656:tid 491907] [client 205.209.65.102:60882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=205.209.65.102, id=apPkMovX_L6VjdbvkkTL2wAAAw0
[Sun Aug 30 03:05:06.628369 2026] [qos:error] [pid 492549:tid 492782] [client 38.3.162.153:53154] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.3.162.153, id=apPkMjqFvOdCFO2AmwptngAABAY
[Sun Aug 30 03:05:06.629337 2026] [qos:error] [pid 491656:tid 491807] [client 202.47.189.40:59348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=202.47.189.40, id=apPkMovX_L6VjdbvkkTL3AAAAqk
[Sun Aug 30 03:05:06.629343 2026] [qos:error] [pid 491656:tid 491834] [client 1.116.47.171:36074] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=1.116.47.171, id=apPkMovX_L6VjdbvkkTL3QAAAsQ
[Sun Aug 30 03:05:06.635546 2026] [qos:error] [pid 491656:tid 491873] [client 187.251.222.69:44098] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=187.251.222.69, id=apPkMovX_L6VjdbvkkTL3gAAAus
[Sun Aug 30 03:05:06.635732 2026] [qos:error] [pid 491656:tid 491836] [client 42.96.18.62:55162] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=42.96.18.62, id=apPkMovX_L6VjdbvkkTL3wAAAsY
[Sun Aug 30 03:05:06.636103 2026] [qos:error] [pid 491656:tid 491916] [client 109.72.55.69:47406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=109.72.55.69, id=apPkMovX_L6VjdbvkkTL4AAAAxY
[Sun Aug 30 03:05:06.641025 2026] [qos:error] [pid 492549:tid 492762] [client 116.196.150.180:55974] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=116.196.150.180, id=apPkMjqFvOdCFO2AmwptnwAAA_I
[Sun Aug 30 03:05:06.641244 2026] [qos:error] [pid 492549:tid 492689] [client 181.224.175.200:56642] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=181.224.175.200, id=apPkMjqFvOdCFO2AmwptoAAAA6k
[Sun Aug 30 03:05:06.649303 2026] [qos:error] [pid 492549:tid 492690] [client 113.192.48.11:40884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=113.192.48.11, id=apPkMjqFvOdCFO2AmwptoQAAA6o
[Sun Aug 30 03:05:06.652049 2026] [qos:error] [pid 491656:tid 491905] [client 187.190.114.40:52886] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=187.190.114.40, id=apPkMovX_L6VjdbvkkTL4QAAAws
[Sun Aug 30 03:05:06.652358 2026] [qos:error] [pid 491656:tid 491797] [client 139.135.170.23:36650] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=139.135.170.23, id=apPkMovX_L6VjdbvkkTL4wAAAp8
[Sun Aug 30 03:05:06.652362 2026] [qos:error] [pid 491656:tid 491871] [client 163.181.207.226:50174] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=163.181.207.226, id=apPkMovX_L6VjdbvkkTL4gAAAuk
[Sun Aug 30 03:05:06.660530 2026] [qos:error] [pid 491656:tid 491801] [client 194.44.117.160:43318] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=194.44.117.160, id=apPkMovX_L6VjdbvkkTL5AAAAqM
[Sun Aug 30 03:05:06.663127 2026] [qos:error] [pid 491656:tid 491883] [client 195.62.50.140:58586] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=195.62.50.140, id=apPkMovX_L6VjdbvkkTL5QAAAvU
[Sun Aug 30 03:05:06.665556 2026] [qos:error] [pid 492549:tid 492712] [client 202.21.124.129:42862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=202.21.124.129, id=apPkMjqFvOdCFO2AmwptogAAA8A
[Sun Aug 30 03:05:06.669613 2026] [qos:error] [pid 492549:tid 492798] [client 86.53.111.249:43200] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=86.53.111.249, id=apPkMjqFvOdCFO2AmwptpAAABBY
[Sun Aug 30 03:05:06.669651 2026] [qos:error] [pid 492549:tid 492734] [client 38.10.107.117:39050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=38.10.107.117, id=apPkMjqFvOdCFO2AmwptowAAA9Y
[Sun Aug 30 03:05:06.673050 2026] [qos:error] [pid 492549:tid 492692] [client 38.45.67.95:53206] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.45.67.95, id=apPkMjqFvOdCFO2AmwptpQAAA6w
[Sun Aug 30 03:05:06.685286 2026] [qos:error] [pid 492549:tid 492699] [client 41.162.70.210:35352] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=41.162.70.210, id=apPkMjqFvOdCFO2AmwptpwAAA7M
[Sun Aug 30 03:05:06.685290 2026] [qos:error] [pid 492549:tid 492805] [client 200.30.130.50:50625] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=200.30.130.50, id=apPkMjqFvOdCFO2AmwptpgAABB0
[Sun Aug 30 03:05:06.687075 2026] [qos:error] [pid 491656:tid 491832] [client 150.241.70.103:56014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=150.241.70.103, id=apPkMovX_L6VjdbvkkTL5gAAAsI
[Sun Aug 30 03:05:06.690570 2026] [qos:error] [pid 491656:tid 491799] [client 219.148.171.178:4672] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=219.148.171.178, id=apPkMovX_L6VjdbvkkTL5wAAAqE
[Sun Aug 30 03:05:06.693344 2026] [qos:error] [pid 491656:tid 491911] [client 103.179.252.81:48248] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.179.252.81, id=apPkMovX_L6VjdbvkkTL6AAAAxE
[Sun Aug 30 03:05:06.696787 2026] [qos:error] [pid 491656:tid 491828] [client 45.172.226.48:47122] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.172.226.48, id=apPkMovX_L6VjdbvkkTL6gAAAr4
[Sun Aug 30 03:05:06.697688 2026] [qos:error] [pid 491656:tid 491870] [client 190.97.35.249:47060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=190.97.35.249, id=apPkMovX_L6VjdbvkkTL6wAAAug
[Sun Aug 30 03:05:06.699057 2026] [qos:error] [pid 491656:tid 491874] [client 45.225.89.190:41956] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.225.89.190, id=apPkMovX_L6VjdbvkkTL7AAAAuw
[Sun Aug 30 03:05:06.708713 2026] [qos:error] [pid 491656:tid 491811] [client 37.150.97.11:52550] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=37.150.97.11, id=apPkMovX_L6VjdbvkkTL7QAAAq0
[Sun Aug 30 03:05:06.708963 2026] [qos:error] [pid 492549:tid 492711] [client 163.61.241.26:57548] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=163.61.241.26, id=apPkMjqFvOdCFO2AmwptqAAAA78
[Sun Aug 30 03:05:06.717059 2026] [qos:error] [pid 491656:tid 491791] [client 160.191.12.214:49362] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=160.191.12.214, id=apPkMovX_L6VjdbvkkTL7gAAApk
[Sun Aug 30 03:05:06.717111 2026] [qos:error] [pid 492549:tid 492708] [client 157.66.16.38:37640] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=157.66.16.38, id=apPkMjqFvOdCFO2AmwptqgAAA7w
[Sun Aug 30 03:05:06.718321 2026] [qos:error] [pid 492549:tid 492729] [client 201.20.42.46:55490] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=201.20.42.46, id=apPkMjqFvOdCFO2AmwptqwAAA9E
[Sun Aug 30 03:05:06.721270 2026] [qos:error] [pid 492549:tid 492710] [client 38.19.40.31:60585] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.19.40.31, id=apPkMjqFvOdCFO2AmwptrAAAA74
[Sun Aug 30 03:05:06.727586 2026] [qos:error] [pid 492549:tid 492787] [client 181.78.169.129:56178] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=181.78.169.129, id=apPkMjqFvOdCFO2AmwptrQAABAs
[Sun Aug 30 03:05:06.728763 2026] [qos:error] [pid 491656:tid 491818] [client 209.61.50.3:54360] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=209.61.50.3, id=apPkMovX_L6VjdbvkkTL7wAAArQ
[Sun Aug 30 03:05:06.729174 2026] [qos:error] [pid 491656:tid 491878] [client 181.13.210.60:33616] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=181.13.210.60, id=apPkMovX_L6VjdbvkkTL8AAAAvA
[Sun Aug 30 03:05:06.730977 2026] [qos:error] [pid 491656:tid 491840] [client 103.111.116.233:52398] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.111.116.233, id=apPkMovX_L6VjdbvkkTL8QAAAso
[Sun Aug 30 03:05:06.732864 2026] [qos:error] [pid 491656:tid 491869] [client 35.219.106.152:1056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=35.219.106.152, id=apPkMovX_L6VjdbvkkTL8gAAAuc
[Sun Aug 30 03:05:06.736852 2026] [qos:error] [pid 491656:tid 491908] [client 152.32.168.221:46876] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=152.32.168.221, id=apPkMovX_L6VjdbvkkTL8wAAAw4
[Sun Aug 30 03:05:06.738409 2026] [qos:error] [pid 491656:tid 491875] [client 37.29.12.198:34939] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=37.29.12.198, id=apPkMovX_L6VjdbvkkTL9AAAAu0
[Sun Aug 30 03:05:06.739272 2026] [qos:error] [pid 491656:tid 491823] [client 108.165.173.211:35356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=108.165.173.211, id=apPkMovX_L6VjdbvkkTL9QAAArk
[Sun Aug 30 03:05:06.741340 2026] [qos:error] [pid 491656:tid 491872] [client 124.105.110.243:48528] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=124.105.110.243, id=apPkMovX_L6VjdbvkkTL9wAAAuo
[Sun Aug 30 03:05:06.742252 2026] [qos:error] [pid 492549:tid 492779] [client 103.155.116.238:57651] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.155.116.238, id=apPkMjqFvOdCFO2AmwptrgAABAM
[Sun Aug 30 03:05:06.745724 2026] [qos:error] [pid 492549:tid 492730] [client 202.84.39.98:37051] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=202.84.39.98, id=apPkMjqFvOdCFO2AmwptrwAAA9I
[Sun Aug 30 03:05:06.745749 2026] [qos:error] [pid 492549:tid 492688] [client 102.216.236.58:47700] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=102.216.236.58, id=apPkMjqFvOdCFO2AmwptsAAAA6g
[Sun Aug 30 03:05:06.746350 2026] [qos:error] [pid 492549:tid 492716] [client 47.88.94.79:36072] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=47.88.94.79, id=apPkMjqFvOdCFO2AmwptsQAAA8Q
[Sun Aug 30 03:05:06.748190 2026] [qos:error] [pid 491656:tid 491906] [client 5.253.196.143:50126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=5.253.196.143, id=apPkMovX_L6VjdbvkkTL-AAAAww
[Sun Aug 30 03:05:06.757563 2026] [qos:error] [pid 492549:tid 492804] [client 154.126.213.152:52778] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=154.126.213.152, id=apPkMjqFvOdCFO2AmwptsgAABBw
[Sun Aug 30 03:05:06.760512 2026] [qos:error] [pid 491656:tid 491893] [client 78.40.199.121:36542] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=78.40.199.121, id=apPkMovX_L6VjdbvkkTL-QAAAv8
[Sun Aug 30 03:05:06.760914 2026] [qos:error] [pid 491656:tid 491901] [client 45.115.41.158:41220] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.115.41.158, id=apPkMovX_L6VjdbvkkTL-gAAAwc
[Sun Aug 30 03:05:06.761172 2026] [qos:error] [pid 492549:tid 492698] [client 27.72.244.228:38440] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=27.72.244.228, id=apPkMjqFvOdCFO2AmwptswAAA7I
[Sun Aug 30 03:05:06.761507 2026] [qos:error] [pid 492549:tid 492776] [client 103.190.113.70:49314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.190.113.70, id=apPkMjqFvOdCFO2AmwpttAAABAA
[Sun Aug 30 03:05:06.761775 2026] [qos:error] [pid 491656:tid 491827] [client 45.59.120.70:48677] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.59.120.70, id=apPkMovX_L6VjdbvkkTL-wAAAr0
[Sun Aug 30 03:05:06.762117 2026] [qos:error] [pid 492549:tid 492694] [client 143.198.85.218:59216] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=143.198.85.218, id=apPkMjqFvOdCFO2AmwpttQAAA64
[Sun Aug 30 03:05:06.764274 2026] [qos:error] [pid 491656:tid 491899] [client 65.20.160.87:41266] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=65.20.160.87, id=apPkMovX_L6VjdbvkkTL_AAAAwU
[Sun Aug 30 03:05:06.765536 2026] [qos:error] [pid 491656:tid 491844] [client 103.247.22.114:52634] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.247.22.114, id=apPkMovX_L6VjdbvkkTL_QAAAs4
[Sun Aug 30 03:05:06.768285 2026] [qos:error] [pid 491656:tid 491907] [client 103.147.77.212:48513] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.147.77.212, id=apPkMovX_L6VjdbvkkTL_gAAAw0
[Sun Aug 30 03:05:06.775556 2026] [qos:error] [pid 492549:tid 492781] [client 200.79.151.19:54232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=200.79.151.19, id=apPkMjqFvOdCFO2AmwpttgAABAU
[Sun Aug 30 03:05:06.775774 2026] [qos:error] [pid 492549:tid 492733] [client 185.222.2.51:45248] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=185.222.2.51, id=apPkMjqFvOdCFO2AmwpttwAAA9U
[Sun Aug 30 03:05:06.778543 2026] [qos:error] [pid 491656:tid 491834] [client 149.28.251.187:47464] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=149.28.251.187, id=apPkMovX_L6VjdbvkkTL_wAAAsQ
[Sun Aug 30 03:05:06.780917 2026] [qos:error] [pid 492549:tid 492702] [client 38.172.181.22:40566] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.172.181.22, id=apPkMjqFvOdCFO2AmwptuAAAA7Y
[Sun Aug 30 03:05:06.784372 2026] [qos:error] [pid 492549:tid 492775] [client 38.75.82.210:55766] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.75.82.210, id=apPkMjqFvOdCFO2AmwptuQAAA_8
[Sun Aug 30 03:05:06.785218 2026] [qos:error] [pid 491656:tid 491873] [client 38.65.174.247:43360] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.65.174.247, id=apPkMovX_L6VjdbvkkTMAQAAAus
[Sun Aug 30 03:05:06.789338 2026] [qos:error] [pid 492549:tid 492748] [client 45.173.12.103:48880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.173.12.103, id=apPkMjqFvOdCFO2AmwptugAAA-Q
[Sun Aug 30 03:05:06.790967 2026] [qos:error] [pid 491656:tid 491836] [client 31.77.204.223:56643] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=31.77.204.223, id=apPkMovX_L6VjdbvkkTMAgAAAsY
[Sun Aug 30 03:05:06.794157 2026] [qos:error] [pid 492549:tid 492807] [client 103.235.109.122:38477] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.235.109.122, id=apPkMjqFvOdCFO2AmwptuwAABB8
[Sun Aug 30 03:05:06.794792 2026] [qos:error] [pid 491656:tid 491916] [client 43.164.136.189:56542] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=43.164.136.189, id=apPkMovX_L6VjdbvkkTMAwAAAxY
[Sun Aug 30 03:05:06.796051 2026] [qos:error] [pid 492549:tid 492802] [client 203.81.81.226:32805] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=203.81.81.226, id=apPkMjqFvOdCFO2AmwptvAAABBo
[Sun Aug 30 03:05:06.797663 2026] [qos:error] [pid 491656:tid 491803] [client 63.250.52.167:38682] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=63.250.52.167, id=apPkMovX_L6VjdbvkkTMBAAAAqU
[Sun Aug 30 03:05:06.800601 2026] [qos:error] [pid 491656:tid 491905] [client 123.21.119.146:53408] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=123.21.119.146, id=apPkMovX_L6VjdbvkkTMBQAAAws
[Sun Aug 30 03:05:06.800722 2026] [qos:error] [pid 491656:tid 491871] [client 43.159.37.201:50760] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=43.159.37.201, id=apPkMovX_L6VjdbvkkTMBgAAAuk
[Sun Aug 30 03:05:06.802225 2026] [qos:error] [pid 492549:tid 492757] [client 103.204.211.49:55752] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.204.211.49, id=apPkMjqFvOdCFO2AmwptvQAAA-0
[Sun Aug 30 03:05:06.803868 2026] [qos:error] [pid 491656:tid 491797] [client 190.83.3.10:45194] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=190.83.3.10, id=apPkMovX_L6VjdbvkkTMBwAAAp8
[Sun Aug 30 03:05:06.804257 2026] [qos:error] [pid 491656:tid 491801] [client 104.28.194.6:44314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=104.28.194.6, id=apPkMovX_L6VjdbvkkTMCAAAAqM
[Sun Aug 30 03:05:06.806065 2026] [qos:error] [pid 492549:tid 492763] [client 185.220.100.254:48512] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=185.220.100.254, id=apPkMjqFvOdCFO2AmwptvgAAA_M
[Sun Aug 30 03:05:06.807612 2026] [qos:error] [pid 492549:tid 492737] [client 123.58.219.171:42416] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=123.58.219.171, id=apPkMjqFvOdCFO2AmwptvwAAA9k
[Sun Aug 30 03:05:06.807733 2026] [qos:error] [pid 492549:tid 492718] [client 103.167.176.106:56632] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.167.176.106, id=apPkMjqFvOdCFO2AmwptwAAAA8Y
[Sun Aug 30 03:05:06.808237 2026] [qos:error] [pid 492549:tid 492718] [client 165.99.195.32:46532] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=165.99.195.32, id=apPkMjqFvOdCFO2AmwptwQAAA8Y
[Sun Aug 30 03:05:06.813292 2026] [qos:error] [pid 491656:tid 491883] [client 111.229.126.163:55689] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=111.229.126.163, id=apPkMovX_L6VjdbvkkTMCQAAAvU
[Sun Aug 30 03:05:06.821465 2026] [qos:error] [pid 492549:tid 492771] [client 103.9.148.198:44330] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.9.148.198, id=apPkMjqFvOdCFO2AmwptwgAAA_s
[Sun Aug 30 03:05:06.821830 2026] [qos:error] [pid 491656:tid 491832] [client 125.27.192.162:52659] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=125.27.192.162, id=apPkMovX_L6VjdbvkkTMCgAAAsI
[Sun Aug 30 03:05:06.827030 2026] [qos:error] [pid 491656:tid 491799] [client 188.161.188.144:36266] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=188.161.188.144, id=apPkMovX_L6VjdbvkkTMCwAAAqE
[Sun Aug 30 03:05:06.828182 2026] [qos:error] [pid 491656:tid 491911] [client 81.168.119.85:34766] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=81.168.119.85, id=apPkMovX_L6VjdbvkkTMDAAAAxE
[Sun Aug 30 03:05:06.835065 2026] [qos:error] [pid 492549:tid 492806] [client 103.51.205.117:58344] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.51.205.117, id=apPkMjqFvOdCFO2AmwptwwAABB4
[Sun Aug 30 03:05:06.835824 2026] [qos:error] [pid 492549:tid 492691] [client 103.214.102.154:36138] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.214.102.154, id=apPkMjqFvOdCFO2AmwptxAAAA6s
[Sun Aug 30 03:05:06.837203 2026] [qos:error] [pid 491656:tid 491828] [client 85.159.94.124:43727] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=85.159.94.124, id=apPkMovX_L6VjdbvkkTMDQAAAr4
[Sun Aug 30 03:05:06.838016 2026] [qos:error] [pid 492549:tid 492721] [client 117.4.137.168:53336] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=117.4.137.168, id=apPkMjqFvOdCFO2AmwptxQAAA8k
[Sun Aug 30 03:05:06.839672 2026] [qos:error] [pid 491656:tid 491870] [client 94.131.92.155:46362] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=94.131.92.155, id=apPkMovX_L6VjdbvkkTMDgAAAug
[Sun Aug 30 03:05:06.845175 2026] [qos:error] [pid 492549:tid 492784] [client 109.237.27.11:51204] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=109.237.27.11, id=apPkMjqFvOdCFO2AmwptxgAABAg
[Sun Aug 30 03:05:06.846969 2026] [qos:error] [pid 492549:tid 492738] [client 20.253.94.223:3878] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=20.253.94.223, id=apPkMjqFvOdCFO2AmwptxwAAA9o
[Sun Aug 30 03:05:06.850450 2026] [qos:error] [pid 491656:tid 491874] [client 181.115.147.68:60059] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=181.115.147.68, id=apPkMovX_L6VjdbvkkTMDwAAAuw
[Sun Aug 30 03:05:06.851571 2026] [qos:error] [pid 491656:tid 491811] [client 181.174.228.175:60960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=181.174.228.175, id=apPkMovX_L6VjdbvkkTMEAAAAq0
[Sun Aug 30 03:05:06.859136 2026] [qos:error] [pid 491656:tid 491791] [client 43.134.141.85:52782] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=43.134.141.85, id=apPkMovX_L6VjdbvkkTMEQAAApk
[Sun Aug 30 03:05:06.864096 2026] [qos:error] [pid 492549:tid 492745] [client 154.19.38.154:37551] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=154.19.38.154, id=apPkMjqFvOdCFO2AmwptyAAAA-E
[Sun Aug 30 03:05:06.865262 2026] [qos:error] [pid 491656:tid 491818] [client 85.133.190.40:34894] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=85.133.190.40, id=apPkMovX_L6VjdbvkkTMEgAAArQ
[Sun Aug 30 03:05:06.869782 2026] [qos:error] [pid 491656:tid 491878] [client 36.66.180.186:40953] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=36.66.180.186, id=apPkMovX_L6VjdbvkkTMEwAAAvA
[Sun Aug 30 03:05:06.871692 2026] [qos:error] [pid 492549:tid 492808] [client 41.217.205.126:52248] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=41.217.205.126, id=apPkMjqFvOdCFO2AmwptyQAABCA
[Sun Aug 30 03:05:06.872007 2026] [http2:info] [pid 493992:tid 493992] h2_workers: created with min=128 max=192 idle_ms=600000
[Sun Aug 30 03:05:06.874494 2026] [qos:error] [pid 491656:tid 491840] [client 165.99.162.10:43570] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=165.99.162.10, id=apPkMovX_L6VjdbvkkTMFAAAAso
[Sun Aug 30 03:05:06.876921 2026] [qos:error] [pid 491656:tid 491908] [client 103.178.194.95:55396] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.178.194.95, id=apPkMovX_L6VjdbvkkTMFgAAAw4
[Sun Aug 30 03:05:06.888379 2026] [qos:error] [pid 492549:tid 492751] [client 103.39.51.190:50081] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.39.51.190, id=apPkMjqFvOdCFO2AmwptygAAA-c
[Sun Aug 30 03:05:06.888411 2026] [qos:error] [pid 491656:tid 491875] [client 181.67.122.157:31752] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=181.67.122.157, id=apPkMovX_L6VjdbvkkTMFwAAAu0
[Sun Aug 30 03:05:06.889282 2026] [qos:error] [pid 491656:tid 491823] [client 140.238.32.108:60384] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=140.238.32.108, id=apPkMovX_L6VjdbvkkTMGAAAArk
[Sun Aug 30 03:05:06.889423 2026] [security2:error] [pid 493992:tid 494122] [client 193.56.113.32:50996] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "smartmenu.pro"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "apPkMmbB9pEqk7z7RJlVDAAAAx4"]
[Sun Aug 30 03:05:06.889915 2026] [qos:error] [pid 491656:tid 491872] [client 200.71.111.157:60016] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=200.71.111.157, id=apPkMovX_L6VjdbvkkTMGQAAAuo
[Sun Aug 30 03:05:06.889991 2026] [security2:error] [pid 493992:tid 494123] [client 20.104.50.220:5469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/gmo.php"] [unique_id "apPkMmbB9pEqk7z7RJlVDQAAAx8"]
[Sun Aug 30 03:05:06.890356 2026] [qos:error] [pid 491656:tid 491906] [client 103.224.65.89:39312] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=103.224.65.89, id=apPkMovX_L6VjdbvkkTMGgAAAww
[Sun Aug 30 03:05:06.890394 2026] [security2:error] [pid 493992:tid 494124] [client 20.104.50.220:32946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/sec.php"] [unique_id "apPkMmbB9pEqk7z7RJlVDgAAAyA"]
[Sun Aug 30 03:05:06.891006 2026] [security2:error] [pid 493992:tid 494125] [client 20.104.50.220:51638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/Success.php"] [unique_id "apPkMmbB9pEqk7z7RJlVDwAAAyE"]
[Sun Aug 30 03:05:06.891054 2026] [qos:error] [pid 491656:tid 491893] [client 103.156.75.243:38876] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=103.156.75.243, id=apPkMovX_L6VjdbvkkTMGwAAAv8
[Sun Aug 30 03:05:06.891942 2026] [security2:error] [pid 493992:tid 494126] [client 4.205.62.107:22972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/sadd.php"] [unique_id "apPkMmbB9pEqk7z7RJlVEAAAAyI"]
[Sun Aug 30 03:05:06.892761 2026] [security2:error] [pid 493992:tid 494127] [client 68.155.159.216:59934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apPkMmbB9pEqk7z7RJlVEQAAAyM"]
[Sun Aug 30 03:05:06.892852 2026] [security2:error] [pid 493992:tid 494128] [client 20.48.251.3:52848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/otuz1.php"] [unique_id "apPkMmbB9pEqk7z7RJlVEgAAAyQ"]
[Sun Aug 30 03:05:06.893101 2026] [security2:error] [pid 493992:tid 494130] [client 20.104.50.220:27432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPkMmbB9pEqk7z7RJlVEwAAAyY"]
[Sun Aug 30 03:05:06.893393 2026] [security2:error] [pid 493992:tid 494139] [client 4.205.62.107:2947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/koiy.php"] [unique_id "apPkMmbB9pEqk7z7RJlVFQAAAy8"]
[Sun Aug 30 03:05:06.893443 2026] [security2:error] [pid 493992:tid 494140] [client 20.104.50.220:61995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/okkk.php"] [unique_id "apPkMmbB9pEqk7z7RJlVFgAAAzA"]
[Sun Aug 30 03:05:06.893726 2026] [security2:error] [pid 493992:tid 494141] [client 20.151.200.44:47004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/4e.php"] [unique_id "apPkMmbB9pEqk7z7RJlVFwAAAzE"]
[Sun Aug 30 03:05:06.893815 2026] [security2:error] [pid 493992:tid 494142] [client 20.48.251.3:59089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/wp-konfig.backup.php"] [unique_id "apPkMmbB9pEqk7z7RJlVGAAAAzI"]
[Sun Aug 30 03:05:06.893928 2026] [security2:error] [pid 493992:tid 494143] [client 20.48.251.3:49991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/public/wp-blog.php"] [unique_id "apPkMmbB9pEqk7z7RJlVGQAAAzM"]
[Sun Aug 30 03:05:06.894193 2026] [security2:error] [pid 493992:tid 494145] [client 20.104.18.15:13706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPkMmbB9pEqk7z7RJlVGgAAAzU"]
[Sun Aug 30 03:05:06.895531 2026] [qos:error] [pid 492549:tid 492722] [client 201.71.2.27:44640] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=201.71.2.27, id=apPkMjqFvOdCFO2AmwptzAAAA8o
[Sun Aug 30 03:05:06.896259 2026] [qos:error] [pid 492549:tid 492772] [client 38.52.148.18:45654] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.52.148.18, id=apPkMjqFvOdCFO2AmwptzQAAA_w
[Sun Aug 30 03:05:06.896359 2026] [security2:error] [pid 493992:tid 494153] [client 20.104.50.220:46457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/byps.php"] [unique_id "apPkMmbB9pEqk7z7RJlVHAAAAz0"]
[Sun Aug 30 03:05:06.896855 2026] [security2:error] [pid 493992:tid 494154] [client 158.23.147.79:62536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apPkMmbB9pEqk7z7RJlVHQAAAz4"]
[Sun Aug 30 03:05:06.896960 2026] [security2:error] [pid 493992:tid 494155] [client 20.104.104.62:35348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/wp-content/admin.php"] [unique_id "apPkMmbB9pEqk7z7RJlVHwAAAz8"]
[Sun Aug 30 03:05:06.898204 2026] [qos:error] [pid 491656:tid 491901] [client 177.54.40.12:52814] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=177.54.40.12, id=apPkMovX_L6VjdbvkkTMHAAAAwc
[Sun Aug 30 03:05:06.898491 2026] [security2:error] [pid 493992:tid 494161] [client 20.151.200.44:63606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkMmbB9pEqk7z7RJlVIgAAA0U"]
[Sun Aug 30 03:05:06.898735 2026] [qos:error] [pid 493992:tid 494136] [client 103.162.54.91:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkMmbB9pEqk7z7RJlVIAAAAyw
[Sun Aug 30 03:05:06.898787 2026] [security2:error] [pid 493992:tid 494162] [client 20.104.50.220:32721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/foxwsov1.php"] [unique_id "apPkMmbB9pEqk7z7RJlVIwAAA0Y"]
[Sun Aug 30 03:05:06.898858 2026] [security2:error] [pid 493992:tid 494163] [client 20.104.18.15:31543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/132.php"] [unique_id "apPkMmbB9pEqk7z7RJlVJAAAA0c"]
[Sun Aug 30 03:05:06.899153 2026] [security2:error] [pid 493992:tid 494167] [client 4.205.62.107:63785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/aws_secret_config.php"] [unique_id "apPkMmbB9pEqk7z7RJlVJgAAA0s"]
[Sun Aug 30 03:05:06.899321 2026] [security2:error] [pid 493992:tid 494168] [client 4.205.62.107:43013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/filesystems.php"] [unique_id "apPkMmbB9pEqk7z7RJlVKAAAA0w"]
[Sun Aug 30 03:05:06.900373 2026] [security2:error] [pid 493992:tid 494172] [client 20.104.50.220:28704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/blog/fw.php"] [unique_id "apPkMmbB9pEqk7z7RJlVKgAAA1A"]
[Sun Aug 30 03:05:06.900434 2026] [security2:error] [pid 493992:tid 494173] [client 4.205.62.107:18977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/test.config.php"] [unique_id "apPkMmbB9pEqk7z7RJlVKwAAA1E"]
[Sun Aug 30 03:05:06.901069 2026] [security2:error] [pid 493992:tid 494177] [client 20.48.251.3:64440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/error_log.php"] [unique_id "apPkMmbB9pEqk7z7RJlVLgAAA1U"]
[Sun Aug 30 03:05:06.901700 2026] [qos:error] [pid 493992:tid 494170] [client 177.10.59.156:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkMmbB9pEqk7z7RJlVLwAAA04
[Sun Aug 30 03:05:06.901814 2026] [security2:error] [pid 493992:tid 494181] [client 4.205.62.107:5108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/grsiuk.php"] [unique_id "apPkMmbB9pEqk7z7RJlVMQAAA1k"]
[Sun Aug 30 03:05:06.902461 2026] [security2:error] [pid 493992:tid 494184] [client 158.23.147.79:40288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPkMmbB9pEqk7z7RJlVMwAAA1w"]
[Sun Aug 30 03:05:06.903422 2026] [security2:error] [pid 493992:tid 494187] [client 20.48.251.3:22767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/aws_secret_config.php"] [unique_id "apPkMmbB9pEqk7z7RJlVOAAAA18"]
[Sun Aug 30 03:05:06.904167 2026] [security2:error] [pid 493992:tid 494190] [client 20.104.18.15:33002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/akismet.php"] [unique_id "apPkMmbB9pEqk7z7RJlVOQAAA2I"]
[Sun Aug 30 03:05:06.904481 2026] [security2:error] [pid 493992:tid 494193] [client 20.104.50.220:62810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/def.php"] [unique_id "apPkMmbB9pEqk7z7RJlVOwAAA2U"]
[Sun Aug 30 03:05:06.913470 2026] [qos:error] [pid 491656:tid 491899] [client 85.1.75.2:45046] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=85.1.75.2, id=apPkMovX_L6VjdbvkkTMHgAAAwU
[Sun Aug 30 03:05:06.913682 2026] [qos:error] [pid 492549:tid 492758] [client 185.191.239.248:42754] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=185.191.239.248, id=apPkMjqFvOdCFO2Amwpt0AAAA-4
[Sun Aug 30 03:05:06.916411 2026] [qos:error] [pid 491656:tid 491844] [client 27.185.218.213:51400] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=27.185.218.213, id=apPkMovX_L6VjdbvkkTMHwAAAs4
[Sun Aug 30 03:05:06.918058 2026] [security2:error] [pid 493992:tid 494144] [client 20.104.49.130:60740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/sxxb.php"] [unique_id "apPkMmbB9pEqk7z7RJlVdgAAAzQ"]
[Sun Aug 30 03:05:06.918059 2026] [security2:error] [pid 493992:tid 494196] [client 68.155.159.216:52810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/mah.php"] [unique_id "apPkMmbB9pEqk7z7RJlVPgAAA2g"]
[Sun Aug 30 03:05:06.918562 2026] [qos:error] [pid 493992:tid 494197] [client 83.147.216.208:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkMmbB9pEqk7z7RJlVQgAAA2k
[Sun Aug 30 03:05:06.918564 2026] [qos:error] [pid 493992:tid 494219] [client 223.109.39.105:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.44, id=apPkMmbB9pEqk7z7RJlVYgAAA38
[Sun Aug 30 03:05:06.918682 2026] [qos:error] [pid 493992:tid 494185] [client 160.202.152.5:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.44, id=apPkMmbB9pEqk7z7RJlVPwAAA10
[Sun Aug 30 03:05:06.918750 2026] [qos:error] [pid 493992:tid 494211] [client 122.52.35.84:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=50.6.92.44, id=apPkMmbB9pEqk7z7RJlVUwAAA3c
[Sun Aug 30 03:05:06.918755 2026] [qos:error] [pid 493992:tid 494215] [client 103.165.123.109:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=50.6.92.44, id=apPkMmbB9pEqk7z7RJlVXQAAA3s
[Sun Aug 30 03:05:06.919137 2026] [qos:error] [pid 493992:tid 494212] [client 161.153.45.81:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=50.6.92.44, id=apPkMmbB9pEqk7z7RJlVVwAAA3g
[Sun Aug 30 03:05:06.919336 2026] [qos:error] [pid 493992:tid 494188] [client 222.127.68.126:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=50.6.92.44, id=apPkMmbB9pEqk7z7RJlVPQAAA2A
[Sun Aug 30 03:05:06.921177 2026] [qos:error] [pid 493992:tid 494151] [client 190.112.160.23:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkMmbB9pEqk7z7RJlVJQAAAzs
[Sun Aug 30 03:05:06.921574 2026] [qos:error] [pid 493992:tid 494159] [client 103.174.122.102:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.44, id=apPkMmbB9pEqk7z7RJlVJwAAA0M
[Sun Aug 30 03:05:06.922204 2026] [qos:error] [pid 493992:tid 494165] [client 103.162.54.147:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=50.6.92.44, id=apPkMmbB9pEqk7z7RJlVLQAAA0k
[Sun Aug 30 03:05:06.923511 2026] [qos:error] [pid 492549:tid 492697] [client 192.255.201.183:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=50.6.92.44, id=apPkMjqFvOdCFO2Amwpt0gAAA7E
[Sun Aug 30 03:05:06.923819 2026] [qos:error] [pid 493992:tid 494212] [client 217.171.94.166:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=50.6.92.44, id=apPkMmbB9pEqk7z7RJlVhwAAA3g
[Sun Aug 30 03:05:06.923987 2026] [qos:error] [pid 493992:tid 494175] [client 43.109.48.180:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=50.6.92.44, id=apPkMmbB9pEqk7z7RJlVMgAAA1M
[Sun Aug 30 03:05:06.924237 2026] [qos:error] [pid 493992:tid 494179] [client 213.147.98.110:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=50.6.92.44, id=apPkMmbB9pEqk7z7RJlVNQAAA1c
[Sun Aug 30 03:05:06.924898 2026] [qos:error] [pid 493992:tid 494182] [client 202.58.79.237:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=50.6.92.44, id=apPkMmbB9pEqk7z7RJlVNwAAA1o
[Sun Aug 30 03:05:06.925148 2026] [qos:error] [pid 493992:tid 494217] [client 103.10.60.178:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=50.6.92.44, id=apPkMmbB9pEqk7z7RJlVYAAAA30
[Sun Aug 30 03:05:06.925154 2026] [qos:error] [pid 493992:tid 494209] [client 43.164.3.124:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=106, c=50.6.92.44, id=apPkMmbB9pEqk7z7RJlVUAAAA3U
[Sun Aug 30 03:05:06.925160 2026] [qos:error] [pid 493992:tid 494191] [client 190.14.147.19:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=107, c=50.6.92.44, id=apPkMmbB9pEqk7z7RJlVSgAAA2M
[Sun Aug 30 03:05:06.925283 2026] [authz_core:error] [pid 492549:tid 492797] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:06.925545 2026] [qos:error] [pid 493992:tid 494194] [client 181.78.203.3:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=50.6.92.44, id=apPkMmbB9pEqk7z7RJlVSQAAA2Y
[Sun Aug 30 03:05:06.925693 2026] [qos:error] [pid 493992:tid 494221] [client 191.97.10.148:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=50.6.92.44, id=apPkMmbB9pEqk7z7RJlVWQAAA4E
[Sun Aug 30 03:05:06.925712 2026] [authz_core:error] [pid 492549:tid 492797] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:06.926273 2026] [qos:error] [pid 493992:tid 494203] [client 14.224.175.159:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=50.6.92.44, id=apPkMmbB9pEqk7z7RJlVTwAAA28
[Sun Aug 30 03:05:06.930198 2026] [qos:error] [pid 491656:tid 491834] [client 118.179.87.193:44662] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=118.179.87.193, id=apPkMovX_L6VjdbvkkTMIQAAAsQ
[Sun Aug 30 03:05:06.930271 2026] [security2:error] [pid 493992:tid 494167] [client 68.155.159.216:52653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/install.php"] [unique_id "apPkMmbB9pEqk7z7RJlVlAAAA0s"]
[Sun Aug 30 03:05:06.931703 2026] [authz_core:error] [pid 493992:tid 494138] [client 66.249.66.205:56244] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:06.932205 2026] [authz_core:error] [pid 493992:tid 494138] [client 66.249.66.205:56244] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:06.942846 2026] [security2:error] [pid 493992:tid 494131] [client 158.23.184.117:24212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/disagrsxr.php"] [unique_id "apPkMmbB9pEqk7z7RJlVpAAAAyc"]
[Sun Aug 30 03:05:06.954443 2026] [authz_core:error] [pid 493992:tid 494146] [client 66.249.66.72:58418] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:06.954882 2026] [authz_core:error] [pid 493992:tid 494146] [client 66.249.66.72:58418] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:06.961579 2026] [security2:error] [pid 493992:tid 494134] [client 52.139.37.240:19803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/ws37.php"] [unique_id "apPkMmbB9pEqk7z7RJlVwQAAAyo"]
[Sun Aug 30 03:05:06.966194 2026] [authz_core:error] [pid 493992:tid 494129] [client 66.249.66.194:45534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:06.966685 2026] [authz_core:error] [pid 493992:tid 494129] [client 66.249.66.194:45534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:06.971272 2026] [security2:error] [pid 492549:tid 492779] [client 4.205.62.107:52147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/css.php"] [unique_id "apPkMjqFvOdCFO2AmwpuAAAABAM"]
[Sun Aug 30 03:05:06.989463 2026] [security2:error] [pid 492549:tid 492793] [client 4.205.62.107:36627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/cu.php"] [unique_id "apPkMjqFvOdCFO2AmwpuEQAABBE"]
[Sun Aug 30 03:05:07.012620 2026] [security2:error] [pid 492549:tid 492771] [client 20.48.251.3:65477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/aws_secret_config.php"] [unique_id "apPkMzqFvOdCFO2AmwpuHwAAA_s"]
[Sun Aug 30 03:05:07.020873 2026] [security2:error] [pid 493992:tid 494147] [client 20.63.219.114:10626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/theme/about.php"] [unique_id "apPkM2bB9pEqk7z7RJlV3AAAAzc"]
[Sun Aug 30 03:05:07.028457 2026] [security2:error] [pid 493992:tid 494148] [client 20.196.209.81:4553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/module.php"] [unique_id "apPkM2bB9pEqk7z7RJlV3gAAAzg"]
[Sun Aug 30 03:05:07.033407 2026] [security2:error] [pid 492549:tid 492697] [client 20.48.251.3:44312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/xa.php"] [unique_id "apPkMzqFvOdCFO2AmwpuKgAAA7E"]
[Sun Aug 30 03:05:07.039402 2026] [security2:error] [pid 493992:tid 494135] [client 136.92.30.49:52038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/preview/phpinfo.php"] [unique_id "apPkM2bB9pEqk7z7RJlV4AAAAys"]
[Sun Aug 30 03:05:07.046453 2026] [security2:error] [pid 492549:tid 492719] [client 4.205.62.107:64042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/sgd.php"] [unique_id "apPkMzqFvOdCFO2AmwpuNQAAA8c"]
[Sun Aug 30 03:05:07.049920 2026] [security2:error] [pid 493992:tid 494150] [client 40.83.93.50:11291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/adminfuns.php"] [unique_id "apPkM2bB9pEqk7z7RJlV5QAAAzo"]
[Sun Aug 30 03:05:07.081041 2026] [security2:error] [pid 492549:tid 492688] [client 158.23.184.117:23978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/domvf.php"] [unique_id "apPkMzqFvOdCFO2AmwpuTQAAA6g"]
[Sun Aug 30 03:05:07.085832 2026] [security2:error] [pid 493992:tid 494218] [client 20.104.104.62:35387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/log.php"] [unique_id "apPkM2bB9pEqk7z7RJlV8gAAA34"]
[Sun Aug 30 03:05:07.096124 2026] [security2:error] [pid 493992:tid 494149] [client 34.15.141.119:45946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/webmail/phpinfo.php"] [unique_id "apPkM2bB9pEqk7z7RJlV9gAAAzk"]
[Sun Aug 30 03:05:07.134829 2026] [security2:error] [pid 492549:tid 492683] [client 4.205.62.107:65354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/config/laravolt/css/index.php"] [unique_id "apPkMzqFvOdCFO2AmwpuewAAA6M"]
[Sun Aug 30 03:05:07.156855 2026] [security2:error] [pid 493992:tid 494125] [client 52.139.37.240:61120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/new.php"] [unique_id "apPkM2bB9pEqk7z7RJlWBQAAAyE"]
[Sun Aug 30 03:05:07.178064 2026] [authz_core:error] [pid 492549:tid 492705] [client 66.249.66.64:35578] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:07.178508 2026] [authz_core:error] [pid 492549:tid 492705] [client 66.249.66.64:35578] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:07.196283 2026] [security2:error] [pid 493992:tid 494214] [client 20.104.18.15:43285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/av.php"] [unique_id "apPkM2bB9pEqk7z7RJlWCgAAA3o"]
[Sun Aug 30 03:05:07.201545 2026] [security2:error] [pid 491656:tid 491677] [remote 66.116.251.167:52470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.251.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "patrickstaehle.com"] [uri "/wp-login.php"] [unique_id "apPkM4vX_L6VjdbvkkTMogADChA"]
[Sun Aug 30 03:05:07.219697 2026] [security2:error] [pid 493992:tid 494174] [client 20.104.104.62:37457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/xwpg.php"] [unique_id "apPkM2bB9pEqk7z7RJlWEgAAA1I"]
[Sun Aug 30 03:05:07.220694 2026] [security2:error] [pid 492549:tid 492737] [client 158.23.184.117:23973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/donate.php"] [unique_id "apPkMzqFvOdCFO2AmwputwAAA9k"]
[Sun Aug 30 03:05:07.227385 2026] [security2:error] [pid 492549:tid 492796] [client 20.104.49.130:58084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.katbacon.com"] [uri "/ortasekerli1.php"] [unique_id "apPkMzqFvOdCFO2AmwpuuwAABBQ"]
[Sun Aug 30 03:05:07.271835 2026] [authz_core:error] [pid 492549:tid 492802] [client 66.249.66.72:51564] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:07.272243 2026] [authz_core:error] [pid 492549:tid 492802] [client 66.249.66.72:51564] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:07.272481 2026] [authz_core:error] [pid 492549:tid 492721] [client 66.249.66.33:42288] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:07.272875 2026] [authz_core:error] [pid 492549:tid 492721] [client 66.249.66.33:42288] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:07.284851 2026] [security2:error] [pid 491656:tid 491841] [client 4.205.62.107:65290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/87.php"] [unique_id "apPkM4vX_L6VjdbvkkTMxwAAAss"]
[Sun Aug 30 03:05:07.337462 2026] [security2:error] [pid 492549:tid 492727] [client 4.205.62.107:25765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/dd.php"] [unique_id "apPkMzqFvOdCFO2AmwpvIwAAA88"]
[Sun Aug 30 03:05:07.339734 2026] [security2:error] [pid 493992:tid 494226] [client 193.56.113.32:51002] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "smartmenu.pro"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "apPkM2bB9pEqk7z7RJlWSAAAA4Y"]
[Sun Aug 30 03:05:07.341179 2026] [security2:error] [pid 493992:tid 494222] [client 158.23.147.79:62557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apPkM2bB9pEqk7z7RJlWSgAAA4I"]
[Sun Aug 30 03:05:07.349985 2026] [security2:error] [pid 492549:tid 492784] [client 20.104.104.62:37452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/sxxb.php"] [unique_id "apPkMzqFvOdCFO2AmwpvOgAABAg"]
[Sun Aug 30 03:05:07.354513 2026] [security2:error] [pid 492549:tid 492790] [client 20.104.18.15:9077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/dragonshell.php"] [unique_id "apPkMzqFvOdCFO2AmwpvPQAABA4"]
[Sun Aug 30 03:05:07.362108 2026] [security2:error] [pid 492549:tid 492685] [client 158.23.184.117:23976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/dropdown.php"] [unique_id "apPkMzqFvOdCFO2AmwpvQwAAA6U"]
[Sun Aug 30 03:05:07.397448 2026] [security2:error] [pid 491656:tid 491910] [client 20.151.200.44:62997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkM4vX_L6VjdbvkkTM_gAAAxA"]
[Sun Aug 30 03:05:07.397805 2026] [security2:error] [pid 492549:tid 492687] [client 20.63.219.114:17201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/theme/min.php"] [unique_id "apPkMzqFvOdCFO2AmwpvWwAAA6c"]
[Sun Aug 30 03:05:07.399364 2026] [security2:error] [pid 491656:tid 491824] [client 4.205.62.107:26551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/cloud.php"] [unique_id "apPkM4vX_L6VjdbvkkTNAAAAAro"]
[Sun Aug 30 03:05:07.418425 2026] [security2:error] [pid 491656:tid 491793] [client 20.196.209.81:17745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/ms-files.php"] [unique_id "apPkM4vX_L6VjdbvkkTNDgAAAps"]
[Sun Aug 30 03:05:07.422152 2026] [security2:error] [pid 491656:tid 491896] [client 216.73.216.128:11796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPkM4vX_L6VjdbvkkTNEAAAAwI"]
[Sun Aug 30 03:05:07.434343 2026] [authz_core:error] [pid 492549:tid 492797] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fdocs
[Sun Aug 30 03:05:07.434755 2026] [authz_core:error] [pid 492549:tid 492797] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Fdocs
[Sun Aug 30 03:05:07.449581 2026] [autoindex:error] [pid 491656:tid 491869] [client 52.139.37.240:63131] AH01276: Cannot serve directory /home4/littling/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:05:07.487694 2026] [security2:error] [pid 492549:tid 492704] [client 136.92.30.49:52040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/www/phpinfo.php"] [unique_id "apPkMzqFvOdCFO2AmwpvrQAAA7g"]
[Sun Aug 30 03:05:07.489818 2026] [security2:error] [pid 492549:tid 492700] [client 20.104.104.62:37443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/dx.php"] [unique_id "apPkMzqFvOdCFO2AmwpvrwAAA7Q"]
[Sun Aug 30 03:05:07.493267 2026] [security2:error] [pid 492549:tid 492711] [client 20.151.200.44:47078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/admin.php/heex.php"] [unique_id "apPkMzqFvOdCFO2AmwpvswAAA78"]
[Sun Aug 30 03:05:07.500668 2026] [security2:error] [pid 492549:tid 492748] [client 158.23.184.117:59275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/edit.php"] [unique_id "apPkMzqFvOdCFO2AmwpvuwAAA-Q"]
[Sun Aug 30 03:05:07.513218 2026] [security2:error] [pid 491656:tid 491835] [client 52.139.37.240:63131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/il.php"] [unique_id "apPkM4vX_L6VjdbvkkTNQwAAAsU"]
[Sun Aug 30 03:05:07.563730 2026] [security2:error] [pid 492549:tid 492738] [client 40.83.93.50:9115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/rip.php"] [unique_id "apPkMzqFvOdCFO2Amwpv7gAAA9o"]
[Sun Aug 30 03:05:07.598832 2026] [authz_core:error] [pid 491656:tid 491847] [client 66.249.66.41:58310] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:07.599135 2026] [authz_core:error] [pid 491656:tid 491847] [client 66.249.66.41:58310] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:07.612760 2026] [authz_core:error] [pid 492549:tid 492728] [client 216.73.216.128:57208] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:07.613153 2026] [authz_core:error] [pid 492549:tid 492728] [client 216.73.216.128:57208] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:07.618362 2026] [security2:error] [pid 492549:tid 492719] [client 20.104.104.62:35354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPkMzqFvOdCFO2AmwpwCAAAA8c"]
[Sun Aug 30 03:05:07.640811 2026] [security2:error] [pid 491656:tid 491880] [client 158.23.184.117:23982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/ee.php"] [unique_id "apPkM4vX_L6VjdbvkkTNkQAAAvI"]
[Sun Aug 30 03:05:07.642680 2026] [security2:error] [pid 492549:tid 492684] [client 20.104.49.130:63585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/3.php"] [unique_id "apPkMzqFvOdCFO2AmwpwHQAAA6Q"]
[Sun Aug 30 03:05:07.676417 2026] [security2:error] [pid 492549:tid 492807] [client 20.151.200.44:23605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/h02ugyh.php"] [unique_id "apPkMzqFvOdCFO2AmwpwMAAABB8"]
[Sun Aug 30 03:05:07.698707 2026] [security2:error] [pid 493992:tid 494159] [client 34.15.141.119:45962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/smtp/phpinfo.php"] [unique_id "apPkM2bB9pEqk7z7RJlWjQAAA0M"]
[Sun Aug 30 03:05:07.706314 2026] [security2:error] [pid 491656:tid 491806] [client 52.139.37.240:60852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/images/index.php"] [unique_id "apPkM4vX_L6VjdbvkkTNwAAAAqg"]
[Sun Aug 30 03:05:07.716983 2026] [security2:error] [pid 491656:tid 491886] [client 20.104.49.130:48016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.infinitelearners.com"] [uri "/wp-good.php"] [unique_id "apPkM4vX_L6VjdbvkkTNxwAAAvg"]
[Sun Aug 30 03:05:07.732100 2026] [security2:error] [pid 493992:tid 494151] [client 145.239.10.137:42248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jackasssawhorse.com"] [uri "/fleen.php"] [unique_id "apPkM2bB9pEqk7z7RJlWjwAAAzs"], referer: http://jackasssawhorse.com/fleen.php
[Sun Aug 30 03:05:07.745177 2026] [security2:error] [pid 493992:tid 494156] [client 158.23.147.79:63240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/dropdown.php"] [unique_id "apPkM2bB9pEqk7z7RJlWlQAAA0A"]
[Sun Aug 30 03:05:07.747664 2026] [security2:error] [pid 493992:tid 494223] [client 20.104.104.62:35382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/xda.php"] [unique_id "apPkM2bB9pEqk7z7RJlWmAAAA4M"]
[Sun Aug 30 03:05:07.752017 2026] [security2:error] [pid 491656:tid 491798] [client 20.63.219.114:17158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/themes/about.php"] [unique_id "apPkM4vX_L6VjdbvkkTN3AAAAqA"]
[Sun Aug 30 03:05:07.779738 2026] [security2:error] [pid 492549:tid 492691] [client 158.23.184.117:23967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/elp.php"] [unique_id "apPkMzqFvOdCFO2AmwpwaAAAA6s"]
[Sun Aug 30 03:05:07.787969 2026] [security2:error] [pid 491656:tid 491825] [client 193.56.113.32:51018] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "smartmenu.pro"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "apPkM4vX_L6VjdbvkkTN9gAAArs"]
[Sun Aug 30 03:05:07.838713 2026] [security2:error] [pid 491656:tid 491870] [client 20.196.209.81:21154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/news-portal/error.php"] [unique_id "apPkM4vX_L6VjdbvkkTOEgAAAug"]
[Sun Aug 30 03:05:07.878352 2026] [security2:error] [pid 492549:tid 492799] [client 20.104.104.62:37453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPkMzqFvOdCFO2AmwpwogAABBc"]
[Sun Aug 30 03:05:07.897459 2026] [security2:error] [pid 491656:tid 491850] [client 20.48.160.90:40013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkM4vX_L6VjdbvkkTOOAAAAtQ"]
[Sun Aug 30 03:05:07.901240 2026] [security2:error] [pid 491656:tid 491805] [client 52.139.37.240:19810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/lite.php"] [unique_id "apPkM4vX_L6VjdbvkkTOOwAAAqc"]
[Sun Aug 30 03:05:07.913292 2026] [authz_core:error] [pid 492549:tid 492709] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:07.913722 2026] [authz_core:error] [pid 492549:tid 492709] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:07.919024 2026] [security2:error] [pid 492549:tid 492804] [client 158.23.184.117:23959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/en.php"] [unique_id "apPkMzqFvOdCFO2AmwpwtgAABBw"]
[Sun Aug 30 03:05:07.941834 2026] [security2:error] [pid 492549:tid 492735] [client 136.92.30.49:52054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/htdocs/phpinfo.php"] [unique_id "apPkMzqFvOdCFO2AmwpwvAAAA9c"]
[Sun Aug 30 03:05:07.984224 2026] [security2:error] [pid 493992:tid 494123] [client 20.151.200.44:63014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/sf.php"] [unique_id "apPkM2bB9pEqk7z7RJlWrAAAAx8"]
[Sun Aug 30 03:05:08.011445 2026] [security2:error] [pid 491656:tid 491816] [client 20.104.104.62:41114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/t00l.php"] [unique_id "apPkNIvX_L6VjdbvkkTObAAAArI"]
[Sun Aug 30 03:05:08.029220 2026] [security2:error] [pid 493992:tid 494170] [client 20.104.50.220:27440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/404.php"] [unique_id "apPkNGbB9pEqk7z7RJlWsAAAA04"]
[Sun Aug 30 03:05:08.030670 2026] [security2:error] [pid 491656:tid 491875] [client 20.104.50.220:47078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/themes/authentic/gud.php/themes/antioch/shell.php"] [unique_id "apPkNIvX_L6VjdbvkkTOdAAAAu0"]
[Sun Aug 30 03:05:08.030770 2026] [security2:error] [pid 491656:tid 491823] [client 4.205.62.107:60568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/snq.php"] [unique_id "apPkNIvX_L6VjdbvkkTOdQAAArk"]
[Sun Aug 30 03:05:08.030927 2026] [security2:error] [pid 492549:tid 492789] [client 20.104.50.220:32858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/shapes.php"] [unique_id "apPkNDqFvOdCFO2Amwpw-AAABA0"]
[Sun Aug 30 03:05:08.031270 2026] [security2:error] [pid 493992:tid 494226] [client 4.205.62.107:2325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/queue.php"] [unique_id "apPkNGbB9pEqk7z7RJlWsQAAA4Y"]
[Sun Aug 30 03:05:08.031715 2026] [security2:error] [pid 492549:tid 492763] [client 20.104.18.15:13700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/wsd.php"] [unique_id "apPkNDqFvOdCFO2Amwpw-QAAA_M"]
[Sun Aug 30 03:05:08.035118 2026] [security2:error] [pid 492549:tid 492770] [client 20.104.18.15:33739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/ajax.php"] [unique_id "apPkNDqFvOdCFO2Amwpw-gAAA_o"]
[Sun Aug 30 03:05:08.038476 2026] [security2:error] [pid 492549:tid 492706] [client 20.48.251.3:23319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/snq.php"] [unique_id "apPkNDqFvOdCFO2Amwpw-wAAA7o"]
[Sun Aug 30 03:05:08.038760 2026] [security2:error] [pid 492549:tid 492748] [client 20.48.251.3:55682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/update.php"] [unique_id "apPkNDqFvOdCFO2Amwpw_AAAA-Q"]
[Sun Aug 30 03:05:08.039342 2026] [security2:error] [pid 492549:tid 492716] [client 4.205.62.107:62278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/application.config.php"] [unique_id "apPkNDqFvOdCFO2Amwpw_QAAA8Q"]
[Sun Aug 30 03:05:08.039400 2026] [security2:error] [pid 492549:tid 492740] [client 20.104.50.220:51606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/syad.php"] [unique_id "apPkNDqFvOdCFO2Amwpw_gAAA9w"]
[Sun Aug 30 03:05:08.046510 2026] [security2:error] [pid 493992:tid 494171] [client 158.23.147.79:63255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/sad/about.php"] [unique_id "apPkNGbB9pEqk7z7RJlWtAAAA08"]
[Sun Aug 30 03:05:08.050096 2026] [security2:error] [pid 492549:tid 492750] [client 20.104.50.220:62001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/yamate.php"] [unique_id "apPkNDqFvOdCFO2AmwpxAgAAA-Y"]
[Sun Aug 30 03:05:08.052049 2026] [security2:error] [pid 492549:tid 492746] [client 20.104.50.220:31921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/FoxWSOv2.php"] [unique_id "apPkNDqFvOdCFO2AmwpxBQAAA-I"]
[Sun Aug 30 03:05:08.054191 2026] [security2:error] [pid 492549:tid 492720] [client 20.48.160.90:40017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkNDqFvOdCFO2AmwpxCQAAA8g"]
[Sun Aug 30 03:05:08.060790 2026] [security2:error] [pid 492549:tid 492792] [client 4.205.62.107:4122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/paypal.php"] [unique_id "apPkNDqFvOdCFO2AmwpxDgAABBA"]
[Sun Aug 30 03:05:08.064992 2026] [security2:error] [pid 492549:tid 492695] [client 20.104.50.220:52863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-optionss.php"] [unique_id "apPkNDqFvOdCFO2AmwpxEQAAA68"]
[Sun Aug 30 03:05:08.065276 2026] [security2:error] [pid 492549:tid 492771] [client 158.23.184.117:23958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.lordrcane.com"] [uri "/error.php"] [unique_id "apPkNDqFvOdCFO2AmwpxEgAAA_s"]
[Sun Aug 30 03:05:08.067523 2026] [security2:error] [pid 492549:tid 492791] [client 20.48.251.3:64397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/phina.php"] [unique_id "apPkNDqFvOdCFO2AmwpxFAAABA8"]
[Sun Aug 30 03:05:08.078075 2026] [security2:error] [pid 491656:tid 491872] [client 68.155.159.216:52827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-blog-header.php"] [unique_id "apPkNIvX_L6VjdbvkkTOjgAAAuo"]
[Sun Aug 30 03:05:08.081445 2026] [security2:error] [pid 492549:tid 492794] [client 20.104.18.15:31559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/v22.php"] [unique_id "apPkNDqFvOdCFO2AmwpxHQAABBI"]
[Sun Aug 30 03:05:08.086700 2026] [security2:error] [pid 491656:tid 491890] [client 20.104.50.220:29133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/extremecrw.php"] [unique_id "apPkNIvX_L6VjdbvkkTOlQAAAvw"]
[Sun Aug 30 03:05:08.094483 2026] [security2:error] [pid 493992:tid 494126] [client 52.139.37.240:61142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/xda.php"] [unique_id "apPkNGbB9pEqk7z7RJlWwwAAAyI"]
[Sun Aug 30 03:05:08.095172 2026] [security2:error] [pid 492549:tid 492775] [client 20.104.50.220:5492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "apPkNDqFvOdCFO2AmwpxLAAAA_8"]
[Sun Aug 30 03:05:08.098928 2026] [security2:error] [pid 493992:tid 494141] [client 20.63.219.114:15559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/themes/panel.php"] [unique_id "apPkNGbB9pEqk7z7RJlWxAAAAzE"]
[Sun Aug 30 03:05:08.100111 2026] [security2:error] [pid 492549:tid 492759] [client 4.205.62.107:18666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/gecko-litespeed.php"] [unique_id "apPkNDqFvOdCFO2AmwpxLwAAA-8"]
[Sun Aug 30 03:05:08.113894 2026] [security2:error] [pid 492549:tid 492556] [remote 51.89.83.144:37809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.83.89.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "calchampsoccer.calchampsoccer.org"] [uri "/assets/images/accesson.php"] [unique_id "apPkNDqFvOdCFO2AmwpxQwAEIAM"]
[Sun Aug 30 03:05:08.127641 2026] [security2:error] [pid 491656:tid 491837] [client 40.83.93.50:9117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/ws.php"] [unique_id "apPkNIvX_L6VjdbvkkTOrgAAAsc"]
[Sun Aug 30 03:05:08.141302 2026] [security2:error] [pid 491656:tid 491861] [client 68.155.159.216:52617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-content/x/index.php"] [unique_id "apPkNIvX_L6VjdbvkkTOuQAAAt8"]
[Sun Aug 30 03:05:08.149023 2026] [security2:error] [pid 492549:tid 492726] [client 20.48.251.3:55435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/php-details.php"] [unique_id "apPkNDqFvOdCFO2AmwpxXgAAA84"]
[Sun Aug 30 03:05:08.149197 2026] [security2:error] [pid 492549:tid 492728] [client 20.48.251.3:34567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/packed.php"] [unique_id "apPkNDqFvOdCFO2AmwpxYAAAA9A"]
[Sun Aug 30 03:05:08.150981 2026] [security2:error] [pid 491656:tid 491824] [client 216.73.216.128:7790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPkNIvX_L6VjdbvkkTOwQAAAro"]
[Sun Aug 30 03:05:08.153072 2026] [security2:error] [pid 492549:tid 492730] [client 20.48.251.3:46228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/snq.php"] [unique_id "apPkNDqFvOdCFO2AmwpxYwAAA9I"]
[Sun Aug 30 03:05:08.166521 2026] [security2:error] [pid 491656:tid 491818] [client 20.104.104.62:37450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/ls.php"] [unique_id "apPkNIvX_L6VjdbvkkTOxwAAArQ"]
[Sun Aug 30 03:05:08.179424 2026] [security2:error] [pid 493992:tid 494156] [client 4.205.62.107:56623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/php_info.php"] [unique_id "apPkNGbB9pEqk7z7RJlWzwAAA0A"]
[Sun Aug 30 03:05:08.193124 2026] [security2:error] [pid 492549:tid 492776] [client 4.205.62.107:64011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/fleen.php"] [unique_id "apPkNDqFvOdCFO2AmwpxigAABAA"]
[Sun Aug 30 03:05:08.193701 2026] [security2:error] [pid 491656:tid 491874] [client 20.48.160.90:39966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/ser.php"] [unique_id "apPkNIvX_L6VjdbvkkTO3AAAAuw"]
[Sun Aug 30 03:05:08.232710 2026] [security2:error] [pid 492549:tid 492800] [client 193.56.113.32:51024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "smartmenu.pro"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "apPkNDqFvOdCFO2AmwpxpQAABBg"]
[Sun Aug 30 03:05:08.247686 2026] [authz_core:error] [pid 491656:tid 491822] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fsys%2Ffs%2Fcgroup%2Fsys-fs-fuse-connections.mount
[Sun Aug 30 03:05:08.248124 2026] [authz_core:error] [pid 491656:tid 491822] [client 74.7.243.204:56424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fsys%2Ffs%2Fcgroup%2Fsys-fs-fuse-connections.mount
[Sun Aug 30 03:05:08.250461 2026] [authz_core:error] [pid 491656:tid 491816] [client 216.73.216.128:6479] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:08.250737 2026] [authz_core:error] [pid 491656:tid 491816] [client 216.73.216.128:6479] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:08.256675 2026] [security2:error] [pid 492549:tid 492691] [client 68.155.159.216:59932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/login.php"] [unique_id "apPkNDqFvOdCFO2AmwpxswAAA6s"]
[Sun Aug 30 03:05:08.260533 2026] [security2:error] [pid 492549:tid 492741] [client 20.196.209.81:4562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/nvt/includes/plugins/wp-blog-header.php"] [unique_id "apPkNDqFvOdCFO2AmwpxtgAAA90"]
[Sun Aug 30 03:05:08.263484 2026] [security2:error] [pid 493992:tid 494164] [client 20.151.200.44:63035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/4e.php"] [unique_id "apPkNGbB9pEqk7z7RJlW2wAAA0g"]
[Sun Aug 30 03:05:08.274356 2026] [security2:error] [pid 491656:tid 491801] [client 4.205.62.107:43066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/tax.php"] [unique_id "apPkNIvX_L6VjdbvkkTPEgAAAqM"]
[Sun Aug 30 03:05:08.275012 2026] [security2:error] [pid 492549:tid 492684] [client 158.23.147.79:62575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/admin.php"] [unique_id "apPkNDqFvOdCFO2AmwpxwQAAA6Q"]
[Sun Aug 30 03:05:08.294386 2026] [security2:error] [pid 492549:tid 492749] [client 20.104.104.62:37454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/css/000.php"] [unique_id "apPkNDqFvOdCFO2Amwpx0wAAA-U"]
[Sun Aug 30 03:05:08.296433 2026] [security2:error] [pid 492549:tid 492701] [client 20.104.49.130:57685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/dex.php"] [unique_id "apPkNDqFvOdCFO2Amwpx2QAAA7U"]
[Sun Aug 30 03:05:08.301583 2026] [security2:error] [pid 492549:tid 492752] [client 34.15.141.119:45976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/phpinfo.php.bak"] [unique_id "apPkNDqFvOdCFO2Amwpx4AAAA-g"]
[Sun Aug 30 03:05:08.307594 2026] [security2:error] [pid 491656:tid 491906] [client 52.139.37.240:61150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/.trash7206/index.php"] [unique_id "apPkNIvX_L6VjdbvkkTPLAAAAww"]
[Sun Aug 30 03:05:08.325276 2026] [security2:error] [pid 492549:tid 492686] [client 20.48.160.90:45942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/431.php"] [unique_id "apPkNDqFvOdCFO2AmwpyAAAAA6Y"]
[Sun Aug 30 03:05:08.334838 2026] [security2:error] [pid 492549:tid 492784] [client 20.104.18.15:43307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/images.php"] [unique_id "apPkNDqFvOdCFO2AmwpyDgAABAg"]
[Sun Aug 30 03:05:08.356357 2026] [security2:error] [pid 492549:tid 492775] [client 20.48.251.3:44345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/ws61.php"] [unique_id "apPkNDqFvOdCFO2AmwpyHgAAA_8"]
[Sun Aug 30 03:05:08.379102 2026] [security2:error] [pid 492549:tid 492783] [client 136.92.30.49:52062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/public_html/phpinfo.php"] [unique_id "apPkNDqFvOdCFO2AmwpyOAAABAc"]
[Sun Aug 30 03:05:08.394984 2026] [authz_core:error] [pid 492549:tid 492761] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:08.395415 2026] [authz_core:error] [pid 492549:tid 492761] [client 74.7.227.8:33276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:08.430365 2026] [security2:error] [pid 492549:tid 492708] [client 20.104.104.62:37472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/cy.php"] [unique_id "apPkNDqFvOdCFO2AmwpyYwAAA7w"]
[Sun Aug 30 03:05:08.462990 2026] [security2:error] [pid 492549:tid 492711] [client 20.48.160.90:45908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/rxr.php"] [unique_id "apPkNDqFvOdCFO2AmwpyfAAAA78"]
[Sun Aug 30 03:05:08.464399 2026] [autoindex:error] [pid 491656:tid 491827] [client 20.63.219.114:17165] AH01276: Cannot serve directory /home2/nalah/cavendish-club.com.lodestar.media/wp-content/themes/twentytwentyfive/styles/sections/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:05:08.475667 2026] [security2:error] [pid 492549:tid 492802] [client 4.205.62.107:58171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/plss3.php"] [unique_id "apPkNDqFvOdCFO2AmwpyiAAABBo"]
[Sun Aug 30 03:05:08.490204 2026] [security2:error] [pid 491656:tid 491877] [client 158.23.147.79:62475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-admin/admin.php"] [unique_id "apPkNIvX_L6VjdbvkkTPkwAAAu8"]
[Sun Aug 30 03:05:08.499980 2026] [security2:error] [pid 491656:tid 491884] [client 52.139.37.240:19811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/storage/index.php"] [unique_id "apPkNIvX_L6VjdbvkkTPnQAAAvY"]
[Sun Aug 30 03:05:08.508407 2026] [security2:error] [pid 491656:tid 491833] [client 4.205.62.107:25746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/wp-tem.php"] [unique_id "apPkNIvX_L6VjdbvkkTPoAAAAsM"]
[Sun Aug 30 03:05:08.565042 2026] [security2:error] [pid 492549:tid 492721] [client 20.104.104.62:37503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/admin.php/pindex.php"] [unique_id "apPkNDqFvOdCFO2AmwpyzgAAA8k"]
[Sun Aug 30 03:05:08.579539 2026] [security2:error] [pid 491656:tid 491892] [client 20.63.219.114:17165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/twentytwentyfive/styles/sections/pk.php"] [unique_id "apPkNIvX_L6VjdbvkkTPwgAAAv4"]
[Sun Aug 30 03:05:08.592721 2026] [security2:error] [pid 491656:tid 491880] [client 20.48.160.90:40016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/csst.php"] [unique_id "apPkNIvX_L6VjdbvkkTPyQAAAvI"]
[Sun Aug 30 03:05:08.593066 2026] [security2:error] [pid 491656:tid 491837] [client 4.205.62.107:36646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/services.php"] [unique_id "apPkNIvX_L6VjdbvkkTPygAAAsc"]
[Sun Aug 30 03:05:08.604739 2026] [security2:error] [pid 492549:tid 492783] [client 40.83.93.50:9094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/t.php"] [unique_id "apPkNDqFvOdCFO2Amwpy5QAABAc"]
[Sun Aug 30 03:05:08.649710 2026] [security2:error] [pid 491656:tid 491860] [client 20.104.18.15:9113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/wp-safe.php"] [unique_id "apPkNIvX_L6VjdbvkkTP6AAAAt4"]
[Sun Aug 30 03:05:08.657410 2026] [security2:error] [pid 491656:tid 491816] [client 20.196.209.81:17741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/oceanwp/sass/components/plugins/panel.php"] [unique_id "apPkNIvX_L6VjdbvkkTP7wAAArI"]
[Sun Aug 30 03:05:08.685210 2026] [security2:error] [pid 491656:tid 491834] [client 193.56.113.32:51030] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "smartmenu.pro"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "apPkNIvX_L6VjdbvkkTP-wAAAsQ"]
[Sun Aug 30 03:05:08.687704 2026] [lsapi:warn] [pid 493992:tid 494249] [client 116.179.37.50:44676] [host tastylandscape.com] Backend log: PHP Warning: Use of undefined constant user_level - assumed 'user_level' (this will throw an Error in a future version of PHP) in /home4/tommed/public_html/wp-content/plugins/ultimate-google-analytics/ultimate_ga.php on line 524\n, referer: https://tastylandscape.com/tag/tarocco-sun/
[Sun Aug 30 03:05:08.691912 2026] [security2:error] [pid 491656:tid 491844] [client 52.139.37.240:61144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPkNIvX_L6VjdbvkkTP_QAAAs4"]
[Sun Aug 30 03:05:08.699452 2026] [security2:error] [pid 491656:tid 491904] [client 20.104.104.62:37488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/admin.php/csv.php"] [unique_id "apPkNIvX_L6VjdbvkkTQBAAAAwo"]
[Sun Aug 30 03:05:08.733807 2026] [security2:error] [pid 493992:tid 494140] [client 20.48.160.90:40033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-includes/blocks/query-title/footer.php"] [unique_id "apPkNGbB9pEqk7z7RJlXQgAAAzA"]
[Sun Aug 30 03:05:08.736376 2026] [security2:error] [pid 493992:tid 494182] [client 158.23.147.79:62483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apPkNGbB9pEqk7z7RJlXRgAAA1o"]
[Sun Aug 30 03:05:08.809440 2026] [security2:error] [pid 493992:tid 494176] [client 136.92.30.49:52064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/site/phpinfo.php"] [unique_id "apPkNGbB9pEqk7z7RJlXaQAAA1Q"]
[Sun Aug 30 03:05:08.837959 2026] [security2:error] [pid 493992:tid 494195] [client 20.104.104.62:41141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/admin.php/700.php"] [unique_id "apPkNGbB9pEqk7z7RJlXegAAA2c"]
[Sun Aug 30 03:05:08.874642 2026] [security2:error] [pid 491656:tid 491821] [client 20.48.160.90:45910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-content/uploads/indoex.php"] [unique_id "apPkNIvX_L6VjdbvkkTQRAAAArc"]
[Sun Aug 30 03:05:08.883313 2026] [security2:error] [pid 491656:tid 491816] [client 52.139.37.240:61135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/wp-blog.php"] [unique_id "apPkNIvX_L6VjdbvkkTQSAAAArI"]
[Sun Aug 30 03:05:08.888548 2026] [security2:error] [pid 493992:tid 494202] [client 158.23.147.79:63258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/classwithtostring.php"] [unique_id "apPkNGbB9pEqk7z7RJlXjQAAA24"]
[Sun Aug 30 03:05:08.904698 2026] [security2:error] [pid 493992:tid 494130] [client 34.15.141.119:45992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/phpinfo.php.old"] [unique_id "apPkNGbB9pEqk7z7RJlXmAAAAyY"]
[Sun Aug 30 03:05:08.971929 2026] [autoindex:error] [pid 493992:tid 494167] [client 20.63.219.114:17153] AH01276: Cannot serve directory /home2/nalah/cavendish-club.com.lodestar.media/wp-content/themes/twentytwentythree/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:05:08.972813 2026] [security2:error] [pid 491656:tid 491859] [client 20.104.104.62:41093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/admin.php/007x.php"] [unique_id "apPkNIvX_L6VjdbvkkTQZwAAAt0"]
[Sun Aug 30 03:05:09.002429 2026] [authz_core:error] [pid 491656:tid 491867] [client 74.7.227.8:54904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:09.002764 2026] [authz_core:error] [pid 491656:tid 491867] [client 74.7.227.8:54904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:09.009470 2026] [security2:error] [pid 493992:tid 494139] [client 158.23.147.79:62514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/install.php"] [unique_id "apPkNWbB9pEqk7z7RJlXsAAAAy8"]
[Sun Aug 30 03:05:09.010246 2026] [security2:error] [pid 493992:tid 494134] [client 20.48.160.90:45941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPkNWbB9pEqk7z7RJlXsQAAAyo"]
[Sun Aug 30 03:05:09.077702 2026] [security2:error] [pid 493992:tid 494238] [client 20.196.209.81:21159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/options.php"] [unique_id "apPkNWbB9pEqk7z7RJlX1wAAA5I"]
[Sun Aug 30 03:05:09.086021 2026] [security2:error] [pid 493992:tid 494246] [client 20.151.200.44:62912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/ssss.php"] [unique_id "apPkNWbB9pEqk7z7RJlX2gAAA5o"]
[Sun Aug 30 03:05:09.088259 2026] [security2:error] [pid 493992:tid 494241] [client 4.205.62.107:27271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/asdf.php"] [unique_id "apPkNWbB9pEqk7z7RJlX2wAAA5U"]
[Sun Aug 30 03:05:09.090492 2026] [security2:error] [pid 493992:tid 494199] [client 40.83.93.50:9088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/fw.php"] [unique_id "apPkNWbB9pEqk7z7RJlX3gAAA2s"]
[Sun Aug 30 03:05:09.091680 2026] [security2:error] [pid 493992:tid 494160] [client 52.139.37.240:19815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/xmlrpc.php"] [unique_id "apPkNWbB9pEqk7z7RJlX1gAAA0Q"]
[Sun Aug 30 03:05:09.095518 2026] [security2:error] [pid 493992:tid 494220] [client 20.63.219.114:17153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/twentytwentythree/patterns/index.php"] [unique_id "apPkNWbB9pEqk7z7RJlX3wAAA4A"]
[Sun Aug 30 03:05:09.112487 2026] [security2:error] [pid 491656:tid 491881] [client 20.104.104.62:35331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/admin.php/heex.php"] [unique_id "apPkNYvX_L6VjdbvkkTQrQAAAvM"]
[Sun Aug 30 03:05:09.137313 2026] [security2:error] [pid 491656:tid 491911] [client 193.56.113.32:51038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "smartmenu.pro"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "apPkNYvX_L6VjdbvkkTQuAAAAxE"]
[Sun Aug 30 03:05:09.145405 2026] [security2:error] [pid 493992:tid 494143] [client 20.48.160.90:45896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/haxor.php"] [unique_id "apPkNWbB9pEqk7z7RJlYBQAAAzM"]
[Sun Aug 30 03:05:09.150420 2026] [authz_core:error] [pid 493992:tid 494201] [client 66.249.66.72:58418] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:09.150722 2026] [authz_core:error] [pid 493992:tid 494201] [client 66.249.66.72:58418] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:09.159408 2026] [authz_core:error] [pid 491656:tid 491830] [client 216.73.216.128:7790] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:09.159921 2026] [authz_core:error] [pid 491656:tid 491830] [client 216.73.216.128:7790] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:09.160496 2026] [security2:error] [pid 493992:tid 494225] [client 158.23.147.79:52989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-content/x/index.php"] [unique_id "apPkNWbB9pEqk7z7RJlYEQAAA4U"]
[Sun Aug 30 03:05:09.165440 2026] [security2:error] [pid 493992:tid 494161] [client 4.205.62.107:63745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/wp-access.php"] [unique_id "apPkNWbB9pEqk7z7RJlYFgAAA0U"]
[Sun Aug 30 03:05:09.175471 2026] [security2:error] [pid 493992:tid 494154] [client 20.48.251.3:23302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/wp-access.php"] [unique_id "apPkNWbB9pEqk7z7RJlYHgAAAz4"]
[Sun Aug 30 03:05:09.176517 2026] [security2:error] [pid 493992:tid 494178] [client 4.205.62.107:22569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/xp.php"] [unique_id "apPkNWbB9pEqk7z7RJlYIQAAA1Y"]
[Sun Aug 30 03:05:09.176964 2026] [security2:error] [pid 493992:tid 494215] [client 20.104.50.220:46198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/and.php"] [unique_id "apPkNWbB9pEqk7z7RJlYIgAAA3s"]
[Sun Aug 30 03:05:09.178028 2026] [security2:error] [pid 493992:tid 494226] [client 20.104.50.220:27404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/wp-includes/post.php"] [unique_id "apPkNWbB9pEqk7z7RJlYJQAAA4Y"]
[Sun Aug 30 03:05:09.182390 2026] [security2:error] [pid 493992:tid 494134] [client 20.104.50.220:33038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/sos.php"] [unique_id "apPkNWbB9pEqk7z7RJlYKQAAAyo"]
[Sun Aug 30 03:05:09.189384 2026] [security2:error] [pid 493992:tid 494124] [client 20.48.251.3:59370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/channels.php"] [unique_id "apPkNWbB9pEqk7z7RJlYMAAAAyA"]
[Sun Aug 30 03:05:09.189689 2026] [security2:error] [pid 493992:tid 494209] [client 20.104.18.15:33019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/atomlib.php"] [unique_id "apPkNWbB9pEqk7z7RJlYMQAAA3U"]
[Sun Aug 30 03:05:09.194689 2026] [security2:error] [pid 493992:tid 494190] [client 20.104.50.220:51619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/success.php"] [unique_id "apPkNWbB9pEqk7z7RJlYNQAAA2I"]
[Sun Aug 30 03:05:09.196499 2026] [core:error] [pid 493992:tid 494235] [client 4.205.62.107:2757] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:05:09.196518 2026] [core:error] [pid 493992:tid 494235] [client 4.205.62.107:2757] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:05:09.205621 2026] [security2:error] [pid 493992:tid 494243] [client 20.48.251.3:7085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/koiy.php"] [unique_id "apPkNWbB9pEqk7z7RJlYQgAAA5c"]
[Sun Aug 30 03:05:09.206366 2026] [security2:error] [pid 491656:tid 491809] [client 20.104.50.220:32716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/foxwsov2.php"] [unique_id "apPkNYvX_L6VjdbvkkTQ3wAAAqs"]
[Sun Aug 30 03:05:09.207846 2026] [security2:error] [pid 491656:tid 491890] [client 4.205.62.107:4629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/userfuns.php"] [unique_id "apPkNYvX_L6VjdbvkkTQ4QAAAvw"]
[Sun Aug 30 03:05:09.209024 2026] [security2:error] [pid 491656:tid 491803] [client 20.104.18.15:13648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/bulet.php"] [unique_id "apPkNYvX_L6VjdbvkkTQ4gAAAqU"]
[Sun Aug 30 03:05:09.216485 2026] [security2:error] [pid 491656:tid 491892] [client 20.104.50.220:29177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/work.php"] [unique_id "apPkNYvX_L6VjdbvkkTQ5wAAAv4"]
[Sun Aug 30 03:05:09.220032 2026] [security2:error] [pid 493992:tid 494159] [client 20.104.18.15:31577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/wp-activate.php"] [unique_id "apPkNWbB9pEqk7z7RJlYRgAAA0M"]
[Sun Aug 30 03:05:09.221441 2026] [security2:error] [pid 493992:tid 494164] [client 20.104.50.220:59553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/upppp.php"] [unique_id "apPkNWbB9pEqk7z7RJlYRwAAA0g"]
[Sun Aug 30 03:05:09.234693 2026] [security2:error] [pid 493992:tid 494180] [client 20.104.50.220:5202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/css/index.php"] [unique_id "apPkNWbB9pEqk7z7RJlYSgAAA1g"]
[Sun Aug 30 03:05:09.238814 2026] [security2:error] [pid 493992:tid 494165] [client 4.205.62.107:18967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/goods.php"] [unique_id "apPkNWbB9pEqk7z7RJlYTAAAA0k"]
[Sun Aug 30 03:05:09.250757 2026] [authz_core:error] [pid 491656:tid 491842] [client 216.73.216.128:6479] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:09.251045 2026] [authz_core:error] [pid 491656:tid 491842] [client 216.73.216.128:6479] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:09.252464 2026] [security2:error] [pid 493992:tid 494154] [client 20.104.50.220:52863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/indx.php"] [unique_id "apPkNWbB9pEqk7z7RJlYVgAAAz4"]
[Sun Aug 30 03:05:09.254427 2026] [security2:error] [pid 491656:tid 491799] [client 158.23.147.79:52929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apPkNYvX_L6VjdbvkkTQ_AAAAqE"]
[Sun Aug 30 03:05:09.261242 2026] [security2:error] [pid 493992:tid 494163] [client 136.92.30.49:52076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/docs/phpinfo.php"] [unique_id "apPkNWbB9pEqk7z7RJlYWQAAA0c"]
[Sun Aug 30 03:05:09.261469 2026] [security2:error] [pid 493992:tid 494217] [client 68.155.159.216:52656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apPkNWbB9pEqk7z7RJlYWgAAA30"]
[Sun Aug 30 03:05:09.275672 2026] [security2:error] [pid 493992:tid 494156] [client 20.104.104.62:37486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/tf.php"] [unique_id "apPkNWbB9pEqk7z7RJlYZgAAA0A"]
[Sun Aug 30 03:05:09.279772 2026] [security2:error] [pid 491656:tid 491801] [client 20.48.160.90:40019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/google.php"] [unique_id "apPkNYvX_L6VjdbvkkTRCQAAAqM"]
[Sun Aug 30 03:05:09.283885 2026] [security2:error] [pid 493992:tid 494169] [client 52.139.37.240:61134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/lu4.php"] [unique_id "apPkNWbB9pEqk7z7RJlYawAAA00"]
[Sun Aug 30 03:05:09.289788 2026] [security2:error] [pid 493992:tid 494202] [client 20.48.251.3:49996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/routes.php"] [unique_id "apPkNWbB9pEqk7z7RJlYcQAAA24"]
[Sun Aug 30 03:05:09.290372 2026] [security2:error] [pid 493992:tid 494173] [client 20.48.251.3:51460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/wp-info.php"] [unique_id "apPkNWbB9pEqk7z7RJlYcwAAA1E"]
[Sun Aug 30 03:05:09.291560 2026] [security2:error] [pid 493992:tid 494139] [client 20.48.251.3:43204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/wp-access.php"] [unique_id "apPkNWbB9pEqk7z7RJlYdQAAAy8"]
[Sun Aug 30 03:05:09.317204 2026] [security2:error] [pid 493992:tid 494183] [client 4.205.62.107:51731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/session.php"] [unique_id "apPkNWbB9pEqk7z7RJlYigAAA1s"]
[Sun Aug 30 03:05:09.322079 2026] [security2:error] [pid 493992:tid 494182] [client 68.155.159.216:59388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apPkNWbB9pEqk7z7RJlYkwAAA1o"]
[Sun Aug 30 03:05:09.337058 2026] [security2:error] [pid 493992:tid 494195] [client 4.205.62.107:62069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/upload.form.php"] [unique_id "apPkNWbB9pEqk7z7RJlYogAAA2c"]
[Sun Aug 30 03:05:09.379023 2026] [security2:error] [pid 493992:tid 494126] [client 158.23.147.79:62489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apPkNWbB9pEqk7z7RJlYsQAAAyI"]
[Sun Aug 30 03:05:09.393059 2026] [security2:error] [pid 491656:tid 491828] [client 68.155.159.216:60013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/hehehehe.php"] [unique_id "apPkNYvX_L6VjdbvkkTRMgAAAr4"]
[Sun Aug 30 03:05:09.405710 2026] [security2:error] [pid 493992:tid 494154] [client 20.104.104.62:37484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/update/da222.php"] [unique_id "apPkNWbB9pEqk7z7RJlYvAAAAz4"]
[Sun Aug 30 03:05:09.411034 2026] [security2:error] [pid 493992:tid 494165] [client 20.48.160.90:45926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "apPkNWbB9pEqk7z7RJlYvQAAA0k"]
[Sun Aug 30 03:05:09.414442 2026] [security2:error] [pid 493992:tid 494228] [client 4.205.62.107:44742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPkNWbB9pEqk7z7RJlYwQAAA4g"]
[Sun Aug 30 03:05:09.432764 2026] [authz_core:error] [pid 491656:tid 491865] [client 74.7.227.8:54904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:09.433027 2026] [authz_core:error] [pid 491656:tid 491865] [client 74.7.227.8:54904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:09.458014 2026] [autoindex:error] [pid 493992:tid 494141] [client 20.63.219.114:17197] AH01276: Cannot serve directory /home2/nalah/cavendish-club.com.lodestar.media/wp-content/themes/twentytwentytwo/parts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:05:09.470474 2026] [security2:error] [pid 491656:tid 491826] [client 20.196.209.81:16851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/panel.php"] [unique_id "apPkNYvX_L6VjdbvkkTRVwAAArw"]
[Sun Aug 30 03:05:09.494388 2026] [security2:error] [pid 493992:tid 494242] [client 52.139.37.240:19817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "apPkNWbB9pEqk7z7RJlY7QAAA5Y"]
[Sun Aug 30 03:05:09.498499 2026] [authz_core:error] [pid 493992:tid 494188] [client 66.249.66.67:44881] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:09.498788 2026] [authz_core:error] [pid 493992:tid 494188] [client 66.249.66.67:44881] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:09.507840 2026] [security2:error] [pid 493992:tid 494162] [client 34.15.141.119:46006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/phpinfo.php~"] [unique_id "apPkNWbB9pEqk7z7RJlY8QAAA0Y"]
[Sun Aug 30 03:05:09.509679 2026] [security2:error] [pid 493992:tid 494208] [client 20.104.18.15:43294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/ops.php"] [unique_id "apPkNWbB9pEqk7z7RJlY8wAAA3Q"]
[Sun Aug 30 03:05:09.540359 2026] [security2:error] [pid 493992:tid 494210] [client 20.48.160.90:40018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/robots.php"] [unique_id "apPkNWbB9pEqk7z7RJlZDgAAA3Y"]
[Sun Aug 30 03:05:09.544632 2026] [security2:error] [pid 491656:tid 491893] [client 20.48.251.3:4704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/xza.php"] [unique_id "apPkNYvX_L6VjdbvkkTReQAAAv8"]
[Sun Aug 30 03:05:09.572305 2026] [security2:error] [pid 493992:tid 494170] [client 20.104.104.62:35387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/qi.php"] [unique_id "apPkNWbB9pEqk7z7RJlZFAAAA04"]
[Sun Aug 30 03:05:09.572555 2026] [security2:error] [pid 493992:tid 494153] [client 20.63.219.114:17197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/users.php"] [unique_id "apPkNWbB9pEqk7z7RJlZFQAAAz0"]
[Sun Aug 30 03:05:09.587275 2026] [security2:error] [pid 493992:tid 494169] [client 193.56.113.32:51052] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "smartmenu.pro"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "apPkNWbB9pEqk7z7RJlZGwAAA00"]
[Sun Aug 30 03:05:09.624382 2026] [security2:error] [pid 491656:tid 491877] [client 40.83.93.50:9098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/test.php"] [unique_id "apPkNYvX_L6VjdbvkkTRoAAAAu8"]
[Sun Aug 30 03:05:09.633786 2026] [security2:error] [pid 493992:tid 494151] [client 158.23.147.79:62550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-login.php"] [unique_id "apPkNWbB9pEqk7z7RJlZJwAAAzs"]
[Sun Aug 30 03:05:09.636896 2026] [security2:error] [pid 491656:tid 491843] [client 4.205.62.107:30340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/aws.php"] [unique_id "apPkNYvX_L6VjdbvkkTRqwAAAs0"]
[Sun Aug 30 03:05:09.671500 2026] [security2:error] [pid 493992:tid 494133] [client 4.205.62.107:42564] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/retu11.PhP"] [unique_id "apPkNWbB9pEqk7z7RJlZOQAAAyk"]
[Sun Aug 30 03:05:09.677259 2026] [security2:error] [pid 491656:tid 491893] [client 20.48.160.90:40034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-content/plugins/ccx/index.php"] [unique_id "apPkNYvX_L6VjdbvkkTRvAAAAv8"]
[Sun Aug 30 03:05:09.682476 2026] [security2:error] [pid 491656:tid 491809] [client 20.151.200.44:47102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/tf.php"] [unique_id "apPkNYvX_L6VjdbvkkTRvwAAAqs"]
[Sun Aug 30 03:05:09.686526 2026] [security2:error] [pid 491656:tid 491904] [client 4.205.62.107:25473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/txets.php"] [unique_id "apPkNYvX_L6VjdbvkkTRwQAAAwo"]
[Sun Aug 30 03:05:09.686695 2026] [security2:error] [pid 493992:tid 494173] [client 52.139.37.240:63122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "apPkNWbB9pEqk7z7RJlZPgAAA1E"]
[Sun Aug 30 03:05:09.696010 2026] [authz_core:error] [pid 491656:tid 491841] [client 66.249.66.77:62184] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:09.696355 2026] [authz_core:error] [pid 491656:tid 491841] [client 66.249.66.77:62184] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:09.697699 2026] [security2:error] [pid 491656:tid 491905] [client 136.92.30.49:52084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "apPkNYvX_L6VjdbvkkTRygAAAws"]
[Sun Aug 30 03:05:09.701228 2026] [security2:error] [pid 493992:tid 494152] [client 20.104.104.62:35335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/px.php"] [unique_id "apPkNWbB9pEqk7z7RJlZPwAAAzw"]
[Sun Aug 30 03:05:09.751432 2026] [security2:error] [pid 493992:tid 494146] [client 20.151.200.44:23608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/zoz.php"] [unique_id "apPkNWbB9pEqk7z7RJlZVQAAAzY"]
[Sun Aug 30 03:05:09.842240 2026] [security2:error] [pid 493992:tid 494199] [client 20.104.104.62:35207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/is.php"] [unique_id "apPkNWbB9pEqk7z7RJlZcwAAA2s"]
[Sun Aug 30 03:05:09.865707 2026] [security2:error] [pid 491656:tid 491821] [client 158.23.147.79:40915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/about.php"] [unique_id "apPkNYvX_L6VjdbvkkTSFgAAArc"]
[Sun Aug 30 03:05:09.869603 2026] [security2:error] [pid 491656:tid 491844] [client 20.48.160.90:45834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-admin/css/colors/maro.php"] [unique_id "apPkNYvX_L6VjdbvkkTSGQAAAs4"]
[Sun Aug 30 03:05:09.876822 2026] [security2:error] [pid 493992:tid 494131] [client 20.104.49.130:58096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.katbacon.com"] [uri "/t.php"] [unique_id "apPkNWbB9pEqk7z7RJlZdwAAAyc"]
[Sun Aug 30 03:05:09.884083 2026] [security2:error] [pid 493992:tid 494166] [client 52.139.37.240:19797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "apPkNWbB9pEqk7z7RJlZfAAAA0o"]
[Sun Aug 30 03:05:09.890041 2026] [authz_core:error] [pid 491656:tid 491902] [client 216.73.216.128:7790] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:09.890500 2026] [authz_core:error] [pid 491656:tid 491902] [client 216.73.216.128:7790] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:09.895513 2026] [security2:error] [pid 493992:tid 494240] [client 20.104.18.15:9037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/gjewuagf.php"] [unique_id "apPkNWbB9pEqk7z7RJlZgwAAA5Q"]
[Sun Aug 30 03:05:09.897699 2026] [security2:error] [pid 493992:tid 494125] [client 20.196.209.81:4586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/reboot/assets/js/plugins/home.php"] [unique_id "apPkNWbB9pEqk7z7RJlZhQAAAyE"]
[Sun Aug 30 03:05:09.920514 2026] [authz_core:error] [pid 491656:tid 491853] [client 74.7.227.8:54904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:09.920822 2026] [authz_core:error] [pid 491656:tid 491853] [client 74.7.227.8:54904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:09.921741 2026] [security2:error] [pid 493992:tid 494177] [client 20.63.219.114:15572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/wp-cron.php"] [unique_id "apPkNWbB9pEqk7z7RJlZiwAAA1U"]
[Sun Aug 30 03:05:09.924847 2026] [rewrite:warn] [pid 493992:tid 494002] AH00665: RewriteCond: NoCase option for non-regex pattern '-d' is not supported and will be ignored. (/home3/keilan/public_html/.htaccess:12)
[Sun Aug 30 03:05:09.924862 2026] [rewrite:warn] [pid 493992:tid 494002] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home3/keilan/public_html/.htaccess:13)
[Sun Aug 30 03:05:09.972136 2026] [security2:error] [pid 493992:tid 494245] [client 20.104.104.62:41127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/od.php"] [unique_id "apPkNWbB9pEqk7z7RJlZmgAAA5k"]
[Sun Aug 30 03:05:09.989592 2026] [security2:error] [pid 491656:tid 491792] [client 158.23.147.79:63249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apPkNYvX_L6VjdbvkkTSSAAAApo"]
[Sun Aug 30 03:05:10.006861 2026] [security2:error] [pid 493992:tid 494205] [client 20.48.160.90:45844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-admin/css/colors/coffee/marijuana.php"] [unique_id "apPkNmbB9pEqk7z7RJlZogAAA3E"]
[Sun Aug 30 03:05:10.063258 2026] [security2:error] [pid 491656:tid 491842] [client 216.73.216.128:7790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/sasl/developer/programming.html"] [unique_id "apPkNovX_L6VjdbvkkTSYgAAAsw"]
[Sun Aug 30 03:05:10.080301 2026] [security2:error] [pid 493992:tid 494241] [client 52.139.37.240:19787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/ant.php"] [unique_id "apPkNmbB9pEqk7z7RJlZxAAAA5U"]
[Sun Aug 30 03:05:10.093359 2026] [security2:error] [pid 491656:tid 491867] [client 40.83.93.50:9032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/dropdown.php"] [unique_id "apPkNovX_L6VjdbvkkTSbQAAAuU"]
[Sun Aug 30 03:05:10.111749 2026] [security2:error] [pid 491656:tid 491812] [client 34.15.141.119:46008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/info.php.bak"] [unique_id "apPkNovX_L6VjdbvkkTScQAAAq4"]
[Sun Aug 30 03:05:10.115720 2026] [security2:error] [pid 493992:tid 494132] [client 20.104.104.62:35330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/wp-the.php"] [unique_id "apPkNmbB9pEqk7z7RJlZ0wAAAyg"]
[Sun Aug 30 03:05:10.140493 2026] [security2:error] [pid 493992:tid 494190] [client 20.48.160.90:45866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-admin/css/colors/coffee/mari.php"] [unique_id "apPkNmbB9pEqk7z7RJlZ7AAAA2I"]
[Sun Aug 30 03:05:10.161684 2026] [security2:error] [pid 493992:tid 494236] [client 136.92.30.49:52094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/administrator/phpinfo.php"] [unique_id "apPkNmbB9pEqk7z7RJlaFgAAA5A"]
[Sun Aug 30 03:05:10.162511 2026] [security2:error] [pid 493992:tid 494220] [client 20.104.49.130:53623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.infinitelearners.com"] [uri "/as.php"] [unique_id "apPkNmbB9pEqk7z7RJlaGgAAA4A"]
[Sun Aug 30 03:05:10.270487 2026] [security2:error] [pid 493992:tid 494204] [client 20.63.219.114:10679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/wp-links-opml.php"] [unique_id "apPkNmbB9pEqk7z7RJlabwAAA3A"]
[Sun Aug 30 03:05:10.270566 2026] [security2:error] [pid 493992:tid 494245] [client 4.205.62.107:36638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/filesystems.php"] [unique_id "apPkNmbB9pEqk7z7RJlacAAAA5k"]
[Sun Aug 30 03:05:10.272726 2026] [security2:error] [pid 493992:tid 494213] [client 52.139.37.240:60859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/autoload_classmap.php"] [unique_id "apPkNmbB9pEqk7z7RJlacQAAA3k"]
[Sun Aug 30 03:05:10.275770 2026] [security2:error] [pid 493992:tid 494157] [client 20.48.160.90:45949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-includes/images/crystal/option.php"] [unique_id "apPkNmbB9pEqk7z7RJladAAAA0E"]
[Sun Aug 30 03:05:10.297450 2026] [security2:error] [pid 491656:tid 491866] [client 20.104.104.62:37497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/wt.php"] [unique_id "apPkNovX_L6VjdbvkkTSwgAAAuQ"]
[Sun Aug 30 03:05:10.303486 2026] [security2:error] [pid 493992:tid 494199] [client 4.205.62.107:63580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/otuz1.php"] [unique_id "apPkNmbB9pEqk7z7RJlajwAAA2s"]
[Sun Aug 30 03:05:10.314422 2026] [security2:error] [pid 493992:tid 494213] [client 4.205.62.107:62282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/g3.php"] [unique_id "apPkNmbB9pEqk7z7RJlamQAAA3k"]
[Sun Aug 30 03:05:10.315047 2026] [security2:error] [pid 493992:tid 494194] [client 20.104.50.220:46621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/skizoo.php"] [unique_id "apPkNmbB9pEqk7z7RJlamgAAA2Y"]
[Sun Aug 30 03:05:10.317894 2026] [security2:error] [pid 493992:tid 494166] [client 20.48.251.3:44165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/otuz1.php"] [unique_id "apPkNmbB9pEqk7z7RJlaoAAAA0o"]
[Sun Aug 30 03:05:10.321620 2026] [security2:error] [pid 491656:tid 491899] [client 20.196.209.81:17732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/salient/css/build/plugins/login.php"] [unique_id "apPkNovX_L6VjdbvkkTS0AAAAwU"]
[Sun Aug 30 03:05:10.322560 2026] [security2:error] [pid 493992:tid 494123] [client 20.104.50.220:33053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/print.php"] [unique_id "apPkNmbB9pEqk7z7RJlaqwAAAx8"]
[Sun Aug 30 03:05:10.328393 2026] [security2:error] [pid 493992:tid 494156] [client 20.104.18.15:33732] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "tether-comic.com"] [uri "/1.php"] [unique_id "apPkNmbB9pEqk7z7RJlarwAAA0A"]
[Sun Aug 30 03:05:10.328489 2026] [security2:error] [pid 493992:tid 494156] [client 20.104.18.15:33732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/1.php"] [unique_id "apPkNmbB9pEqk7z7RJlarwAAA0A"]
[Sun Aug 30 03:05:10.333619 2026] [security2:error] [pid 491656:tid 491915] [client 20.104.50.220:27403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/filefuns.php"] [unique_id "apPkNovX_L6VjdbvkkTS1wAAAxU"]
[Sun Aug 30 03:05:10.333968 2026] [security2:error] [pid 493992:tid 494167] [client 20.104.50.220:51637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/swm@asd365.php"] [unique_id "apPkNmbB9pEqk7z7RJlasgAAA0s"]
[Sun Aug 30 03:05:10.334698 2026] [security2:error] [pid 493992:tid 494234] [client 4.205.62.107:2771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/doc.php"] [unique_id "apPkNmbB9pEqk7z7RJlaswAAA44"]
[Sun Aug 30 03:05:10.338421 2026] [authz_core:error] [pid 493992:tid 494210] [client 66.249.66.71:58552] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:10.338774 2026] [authz_core:error] [pid 493992:tid 494210] [client 66.249.66.71:58552] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:10.339554 2026] [security2:error] [pid 491656:tid 491846] [client 4.205.62.107:4124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/mamzi.php"] [unique_id "apPkNovX_L6VjdbvkkTS2gAAAtA"]
[Sun Aug 30 03:05:10.344466 2026] [security2:error] [pid 491656:tid 491891] [client 20.48.251.3:7374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/queue.php"] [unique_id "apPkNovX_L6VjdbvkkTS3AAAAv0"]
[Sun Aug 30 03:05:10.346403 2026] [security2:error] [pid 493992:tid 494231] [client 20.104.18.15:13649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/av.php"] [unique_id "apPkNmbB9pEqk7z7RJlatwAAA4s"]
[Sun Aug 30 03:05:10.350762 2026] [security2:error] [pid 493992:tid 494147] [client 20.104.50.220:32512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/shellx.php"] [unique_id "apPkNmbB9pEqk7z7RJlauQAAAzc"]
[Sun Aug 30 03:05:10.351414 2026] [security2:error] [pid 491656:tid 491892] [client 20.48.251.3:55689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/zz.php"] [unique_id "apPkNovX_L6VjdbvkkTS3QAAAv4"]
[Sun Aug 30 03:05:10.373939 2026] [security2:error] [pid 491656:tid 491801] [client 68.155.159.216:54768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apPkNovX_L6VjdbvkkTS6wAAAqM"]
[Sun Aug 30 03:05:10.384512 2026] [security2:error] [pid 493992:tid 494225] [client 20.104.18.15:31643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/wp-trackback.php"] [unique_id "apPkNmbB9pEqk7z7RJlavgAAA4U"]
[Sun Aug 30 03:05:10.387477 2026] [security2:error] [pid 491656:tid 491879] [client 20.104.50.220:5567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-includes/SimplePie/wp-login.php"] [unique_id "apPkNovX_L6VjdbvkkTS9AAAAvE"]
[Sun Aug 30 03:05:10.391687 2026] [security2:error] [pid 491656:tid 491880] [client 20.104.50.220:61422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/up.php"] [unique_id "apPkNovX_L6VjdbvkkTS-AAAAvI"]
[Sun Aug 30 03:05:10.405494 2026] [security2:error] [pid 491656:tid 491807] [client 20.104.50.220:62828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-config-pantheon.php"] [unique_id "apPkNovX_L6VjdbvkkTTAQAAAqk"]
[Sun Aug 30 03:05:10.412857 2026] [security2:error] [pid 491656:tid 491812] [client 20.48.160.90:26711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-includes/pomo/xxx.php"] [unique_id "apPkNovX_L6VjdbvkkTTCAAAAq4"]
[Sun Aug 30 03:05:10.414473 2026] [authz_core:error] [pid 491656:tid 491867] [client 74.7.227.8:54904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus%2Fsections
[Sun Aug 30 03:05:10.414832 2026] [authz_core:error] [pid 491656:tid 491867] [client 74.7.227.8:54904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus%2Fsections
[Sun Aug 30 03:05:10.420328 2026] [security2:error] [pid 493992:tid 494184] [client 20.104.50.220:29602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/bv7binary.php"] [unique_id "apPkNmbB9pEqk7z7RJlayQAAA1w"]
[Sun Aug 30 03:05:10.425778 2026] [security2:error] [pid 493992:tid 494122] [client 20.104.104.62:37468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/im.php"] [unique_id "apPkNmbB9pEqk7z7RJlazQAAAx4"]
[Sun Aug 30 03:05:10.436226 2026] [security2:error] [pid 493992:tid 494123] [client 20.48.251.3:12047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/aww.php"] [unique_id "apPkNmbB9pEqk7z7RJla0gAAAx8"]
[Sun Aug 30 03:05:10.441250 2026] [authz_core:error] [pid 493992:tid 494228] [client 66.249.66.70:45468] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:10.441699 2026] [authz_core:error] [pid 493992:tid 494228] [client 66.249.66.70:45468] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:10.458240 2026] [security2:error] [pid 493992:tid 494246] [client 68.155.159.216:60604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-admin/user/index.php"] [unique_id "apPkNmbB9pEqk7z7RJla2AAAA5o"]
[Sun Aug 30 03:05:10.458436 2026] [security2:error] [pid 493992:tid 494181] [client 20.48.251.3:54847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/otuz1.php"] [unique_id "apPkNmbB9pEqk7z7RJla2QAAA1k"]
[Sun Aug 30 03:05:10.465196 2026] [security2:error] [pid 493992:tid 494220] [client 52.139.37.240:20073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/storage/rip.php"] [unique_id "apPkNmbB9pEqk7z7RJla4gAAA4A"]
[Sun Aug 30 03:05:10.472571 2026] [security2:error] [pid 493992:tid 494169] [client 4.205.62.107:52114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/h.php"] [unique_id "apPkNmbB9pEqk7z7RJla5QAAA00"]
[Sun Aug 30 03:05:10.489221 2026] [security2:error] [pid 491656:tid 491843] [client 4.205.62.107:17832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/loxi-o.php"] [unique_id "apPkNovX_L6VjdbvkkTTNAAAAs0"]
[Sun Aug 30 03:05:10.496993 2026] [security2:error] [pid 491656:tid 491793] [client 4.205.62.107:63936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/aws_auth.php"] [unique_id "apPkNovX_L6VjdbvkkTTPAAAAps"]
[Sun Aug 30 03:05:10.505424 2026] [security2:error] [pid 491656:tid 491811] [client 68.155.159.216:60029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apPkNovX_L6VjdbvkkTTQgAAAq0"]
[Sun Aug 30 03:05:10.531919 2026] [security2:error] [pid 491656:tid 491878] [client 20.48.251.3:58873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/fns.php"] [unique_id "apPkNovX_L6VjdbvkkTTUwAAAvA"]
[Sun Aug 30 03:05:10.541663 2026] [security2:error] [pid 493992:tid 494230] [client 158.23.147.79:62544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-admin/images/about.php"] [unique_id "apPkNmbB9pEqk7z7RJlbAgAAA4o"]
[Sun Aug 30 03:05:10.550801 2026] [security2:error] [pid 491656:tid 491894] [client 20.48.160.90:45903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/650.php"] [unique_id "apPkNovX_L6VjdbvkkTTXgAAAwA"]
[Sun Aug 30 03:05:10.551408 2026] [security2:error] [pid 491656:tid 491808] [client 4.205.62.107:44746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPkNovX_L6VjdbvkkTTXwAAAqo"]
[Sun Aug 30 03:05:10.554433 2026] [security2:error] [pid 491656:tid 491821] [client 20.104.104.62:37447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/file.php"] [unique_id "apPkNovX_L6VjdbvkkTTYgAAArc"]
[Sun Aug 30 03:05:10.569187 2026] [security2:error] [pid 491656:tid 491799] [client 4.205.62.107:26557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apPkNovX_L6VjdbvkkTTawAAAqE"]
[Sun Aug 30 03:05:10.578538 2026] [security2:error] [pid 493992:tid 494179] [client 40.83.93.50:9081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/mar.php"] [unique_id "apPkNmbB9pEqk7z7RJlbDQAAA1c"]
[Sun Aug 30 03:05:10.609301 2026] [security2:error] [pid 493992:tid 494213] [client 136.92.30.49:52098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/core/phpinfo.php"] [unique_id "apPkNmbB9pEqk7z7RJlbEgAAA3k"]
[Sun Aug 30 03:05:10.645668 2026] [security2:error] [pid 493992:tid 494182] [client 20.63.219.114:17190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/wp-load.php"] [unique_id "apPkNmbB9pEqk7z7RJlbJgAAA1o"]
[Sun Aug 30 03:05:10.650783 2026] [authz_core:error] [pid 493992:tid 494192] [client 66.249.66.70:37386] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:10.651091 2026] [authz_core:error] [pid 493992:tid 494192] [client 66.249.66.70:37386] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:10.657252 2026] [security2:error] [pid 491656:tid 491843] [client 52.139.37.240:63129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/tinyfilemanager.php"] [unique_id "apPkNovX_L6VjdbvkkTToAAAAs0"]
[Sun Aug 30 03:05:10.680229 2026] [security2:error] [pid 491656:tid 491799] [client 20.48.160.90:45906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/nakrip.php"] [unique_id "apPkNovX_L6VjdbvkkTTqAAAAqE"]
[Sun Aug 30 03:05:10.689708 2026] [security2:error] [pid 491656:tid 491881] [client 20.104.104.62:41088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/ca.php"] [unique_id "apPkNovX_L6VjdbvkkTTrQAAAvM"]
[Sun Aug 30 03:05:10.690129 2026] [security2:error] [pid 491656:tid 491914] [client 20.104.18.15:43320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/coffexium.php"] [unique_id "apPkNovX_L6VjdbvkkTTrwAAAxQ"]
[Sun Aug 30 03:05:10.710240 2026] [security2:error] [pid 491656:tid 491861] [client 34.15.141.119:46022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/phpinfo.php.save"] [unique_id "apPkNovX_L6VjdbvkkTTvwAAAt8"]
[Sun Aug 30 03:05:10.713923 2026] [security2:error] [pid 493992:tid 494186] [client 20.196.209.81:21127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/security.php"] [unique_id "apPkNmbB9pEqk7z7RJlbNQAAA14"]
[Sun Aug 30 03:05:10.786081 2026] [security2:error] [pid 493992:tid 494202] [client 4.205.62.107:58136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/app.default.php"] [unique_id "apPkNmbB9pEqk7z7RJlbWQAAA24"]
[Sun Aug 30 03:05:10.804484 2026] [authz_core:error] [pid 493992:tid 494156] [client 66.249.66.65:57280] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:10.805008 2026] [authz_core:error] [pid 493992:tid 494156] [client 66.249.66.65:57280] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:10.820150 2026] [security2:error] [pid 491656:tid 491814] [client 20.48.160.90:40003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-includes/interactivity-api/flower.php"] [unique_id "apPkNovX_L6VjdbvkkTT7AAAArA"]
[Sun Aug 30 03:05:10.822049 2026] [security2:error] [pid 493992:tid 494214] [client 20.104.104.62:37478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/pb.php"] [unique_id "apPkNmbB9pEqk7z7RJlbbwAAA3o"]
[Sun Aug 30 03:05:10.827791 2026] [security2:error] [pid 493992:tid 494228] [client 20.151.200.44:47023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/update/da222.php"] [unique_id "apPkNmbB9pEqk7z7RJlbcAAAA4g"]
[Sun Aug 30 03:05:10.829115 2026] [authz_core:error] [pid 493992:tid 494222] [client 66.249.66.195:57483] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:10.829541 2026] [authz_core:error] [pid 493992:tid 494222] [client 66.249.66.195:57483] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:10.864720 2026] [security2:error] [pid 491656:tid 491861] [client 4.205.62.107:25783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/time.php"] [unique_id "apPkNovX_L6VjdbvkkTT_gAAAt8"]
[Sun Aug 30 03:05:10.892070 2026] [authz_core:error] [pid 491656:tid 491903] [client 74.7.227.8:54904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Frun%2Fudev%2Flinks%2Frtc
[Sun Aug 30 03:05:10.892395 2026] [authz_core:error] [pid 491656:tid 491903] [client 74.7.227.8:54904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Frun%2Fudev%2Flinks%2Frtc
[Sun Aug 30 03:05:10.900824 2026] [security2:error] [pid 491656:tid 491878] [client 4.205.62.107:32057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/queue.php"] [unique_id "apPkNovX_L6VjdbvkkTUEQAAAvA"]
[Sun Aug 30 03:05:10.952131 2026] [security2:error] [pid 493992:tid 494128] [client 20.104.104.62:35344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/pk.php"] [unique_id "apPkNmbB9pEqk7z7RJlblgAAAyQ"]
[Sun Aug 30 03:05:10.972707 2026] [security2:error] [pid 493992:tid 494147] [client 20.48.160.90:45830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/xcc.php"] [unique_id "apPkNmbB9pEqk7z7RJlboAAAAzc"]
[Sun Aug 30 03:05:10.992285 2026] [security2:error] [pid 493992:tid 494130] [client 20.63.219.114:10635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/wp-settings.php"] [unique_id "apPkNmbB9pEqk7z7RJlbowAAAyY"]
[Sun Aug 30 03:05:11.042583 2026] [security2:error] [pid 493992:tid 494167] [client 136.92.30.49:52104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.30.92.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jazminanderson.com"] [uri "/includes/phpinfo.php"] [unique_id "apPkN2bB9pEqk7z7RJlbugAAA0s"]
[Sun Aug 30 03:05:11.078361 2026] [security2:error] [pid 491656:tid 491804] [client 20.104.104.62:41139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/ft.php"] [unique_id "apPkN4vX_L6VjdbvkkTUVQAAAqY"]
[Sun Aug 30 03:05:11.085385 2026] [security2:error] [pid 493992:tid 494194] [client 20.104.18.15:9041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/tnglzqmv.php"] [unique_id "apPkN2bB9pEqk7z7RJlbzwAAA2Y"]
[Sun Aug 30 03:05:11.104351 2026] [security2:error] [pid 493992:tid 494239] [client 20.196.209.81:16850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "apPkN2bB9pEqk7z7RJlb3gAAA5M"]
[Sun Aug 30 03:05:11.106411 2026] [security2:error] [pid 493992:tid 494200] [client 20.48.160.90:45848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-includes/Text/Diff/Engine/aaa.php"] [unique_id "apPkN2bB9pEqk7z7RJlb4gAAA2w"]
[Sun Aug 30 03:05:11.172532 2026] [security2:error] [pid 493992:tid 494174] [client 20.48.251.3:44400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/ms-edit.php"] [unique_id "apPkN2bB9pEqk7z7RJlcEgAAA1I"]
[Sun Aug 30 03:05:11.175744 2026] [security2:error] [pid 491656:tid 491914] [client 20.104.49.130:63609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/df.php"] [unique_id "apPkN4vX_L6VjdbvkkTUigAAAxQ"]
[Sun Aug 30 03:05:11.194464 2026] [security2:error] [pid 493992:tid 494211] [client 4.205.62.107:42589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/tax.php"] [unique_id "apPkN2bB9pEqk7z7RJlcIAAAA3c"]
[Sun Aug 30 03:05:11.224436 2026] [security2:error] [pid 491656:tid 491869] [client 20.104.104.62:41105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/wp-ver.php"] [unique_id "apPkN4vX_L6VjdbvkkTUogAAAuc"]
[Sun Aug 30 03:05:11.242571 2026] [security2:error] [pid 493992:tid 494174] [client 20.151.200.44:37875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/attack.php"] [unique_id "apPkN2bB9pEqk7z7RJlcQAAAA1I"]
[Sun Aug 30 03:05:11.243242 2026] [security2:error] [pid 493992:tid 494210] [client 20.48.160.90:40001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-includes/style-engine/gecko-new.php"] [unique_id "apPkN2bB9pEqk7z7RJlcQgAAA3Y"]
[Sun Aug 30 03:05:11.314699 2026] [security2:error] [pid 493992:tid 494192] [client 34.15.141.119:46032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/staging/phpinfo.php"] [unique_id "apPkN2bB9pEqk7z7RJlcdwAAA2Q"]
[Sun Aug 30 03:05:11.318793 2026] [security2:error] [pid 493992:tid 494214] [client 40.83.93.50:8338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/css.php"] [unique_id "apPkN2bB9pEqk7z7RJlcfAAAA3o"]
[Sun Aug 30 03:05:11.345719 2026] [security2:error] [pid 493992:tid 494173] [client 20.63.219.114:15608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/themes/wp-signup.php"] [unique_id "apPkN2bB9pEqk7z7RJlclwAAA1E"]
[Sun Aug 30 03:05:11.356733 2026] [security2:error] [pid 491656:tid 491794] [client 20.104.104.62:35340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/ah24.php"] [unique_id "apPkN4vX_L6VjdbvkkTU2AAAApw"]
[Sun Aug 30 03:05:11.379689 2026] [security2:error] [pid 491656:tid 491891] [client 20.48.160.90:45891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-settings.php"] [unique_id "apPkN4vX_L6VjdbvkkTU4gAAAv0"]
[Sun Aug 30 03:05:11.421270 2026] [authz_core:error] [pid 491656:tid 491804] [client 74.7.227.8:54904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:11.421541 2026] [authz_core:error] [pid 491656:tid 491804] [client 74.7.227.8:54904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:11.437365 2026] [security2:error] [pid 491656:tid 491838] [client 158.23.147.79:62584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPkN4vX_L6VjdbvkkTVAwAAAsg"]
[Sun Aug 30 03:05:11.439259 2026] [security2:error] [pid 493992:tid 494140] [client 4.205.62.107:63802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/update.php"] [unique_id "apPkN2bB9pEqk7z7RJlcwAAAAzA"]
[Sun Aug 30 03:05:11.450672 2026] [security2:error] [pid 491656:tid 491890] [client 20.48.251.3:44227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/update.php"] [unique_id "apPkN4vX_L6VjdbvkkTVCAAAAvw"]
[Sun Aug 30 03:05:11.452451 2026] [security2:error] [pid 493992:tid 494212] [client 4.205.62.107:62419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/wp-konfig.php"] [unique_id "apPkN2bB9pEqk7z7RJlcwwAAA3g"]
[Sun Aug 30 03:05:11.467846 2026] [security2:error] [pid 493992:tid 494247] [client 20.104.50.220:46336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wsmini.php"] [unique_id "apPkN2bB9pEqk7z7RJlcyAAAA5s"]
[Sun Aug 30 03:05:11.468214 2026] [security2:error] [pid 493992:tid 494152] [client 20.104.50.220:63535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/smtphec.php"] [unique_id "apPkN2bB9pEqk7z7RJlcyQAAAzw"]
[Sun Aug 30 03:05:11.469223 2026] [security2:error] [pid 493992:tid 494237] [client 20.104.18.15:33765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/samll.php"] [unique_id "apPkN2bB9pEqk7z7RJlcywAAA5E"]
[Sun Aug 30 03:05:11.469462 2026] [security2:error] [pid 493992:tid 494173] [client 4.205.62.107:2304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/css.php"] [unique_id "apPkN2bB9pEqk7z7RJlczQAAA1E"]
[Sun Aug 30 03:05:11.471140 2026] [security2:error] [pid 491656:tid 491833] [client 20.104.50.220:27392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/wp-admin/load-scripts.php"] [unique_id "apPkN4vX_L6VjdbvkkTVFQAAAsM"]
[Sun Aug 30 03:05:11.475390 2026] [security2:error] [pid 493992:tid 494124] [client 4.205.62.107:4137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/public/rip.php.php"] [unique_id "apPkN2bB9pEqk7z7RJlc0gAAAyA"]
[Sun Aug 30 03:05:11.475584 2026] [security2:error] [pid 493992:tid 494214] [client 20.104.50.220:33156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/pdi.php"] [unique_id "apPkN2bB9pEqk7z7RJlc0wAAA3o"]
[Sun Aug 30 03:05:11.484625 2026] [security2:error] [pid 493992:tid 494192] [client 20.104.18.15:13650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/images.php"] [unique_id "apPkN2bB9pEqk7z7RJlc3wAAA2Q"]
[Sun Aug 30 03:05:11.486917 2026] [security2:error] [pid 493992:tid 494246] [client 20.48.251.3:55778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/test.php"] [unique_id "apPkN2bB9pEqk7z7RJlc4gAAA5o"]
[Sun Aug 30 03:05:11.487342 2026] [security2:error] [pid 493992:tid 494203] [client 20.104.104.62:37480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPkN2bB9pEqk7z7RJlc5AAAA28"]
[Sun Aug 30 03:05:11.494031 2026] [security2:error] [pid 493992:tid 494187] [client 68.155.159.216:52710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-login.php"] [unique_id "apPkN2bB9pEqk7z7RJlc5wAAA18"]
[Sun Aug 30 03:05:11.496236 2026] [security2:error] [pid 493992:tid 494143] [client 20.196.209.81:21137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/system.php"] [unique_id "apPkN2bB9pEqk7z7RJlc6QAAAzM"]
[Sun Aug 30 03:05:11.510588 2026] [security2:error] [pid 493992:tid 494226] [client 20.48.160.90:45887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-signup.php"] [unique_id "apPkN2bB9pEqk7z7RJlc9gAAA4Y"]
[Sun Aug 30 03:05:11.517013 2026] [security2:error] [pid 493992:tid 494133] [client 20.104.50.220:32561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/1index.php"] [unique_id "apPkN2bB9pEqk7z7RJlc_AAAAyk"]
[Sun Aug 30 03:05:11.526444 2026] [security2:error] [pid 493992:tid 494144] [client 20.104.50.220:61672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/l3.php"] [unique_id "apPkN2bB9pEqk7z7RJldBQAAAzQ"]
[Sun Aug 30 03:05:11.554200 2026] [security2:error] [pid 493992:tid 494137] [client 20.48.251.3:64386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/doc.php"] [unique_id "apPkN2bB9pEqk7z7RJldGAAAAy0"]
[Sun Aug 30 03:05:11.554453 2026] [security2:error] [pid 493992:tid 494160] [client 20.104.50.220:63043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-xmlx.php"] [unique_id "apPkN2bB9pEqk7z7RJldGgAAA0Q"]
[Sun Aug 30 03:05:11.556344 2026] [security2:error] [pid 493992:tid 494142] [client 20.104.50.220:29568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/webroot.php"] [unique_id "apPkN2bB9pEqk7z7RJldHAAAAzI"]
[Sun Aug 30 03:05:11.557772 2026] [security2:error] [pid 491656:tid 491849] [client 20.104.50.220:5896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-content/themes/about.php"] [unique_id "apPkN4vX_L6VjdbvkkTVMQAAAtM"]
[Sun Aug 30 03:05:11.578248 2026] [security2:error] [pid 493992:tid 494232] [client 20.104.18.15:31685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/pri.php"] [unique_id "apPkN2bB9pEqk7z7RJldJQAAA4w"]
[Sun Aug 30 03:05:11.600275 2026] [security2:error] [pid 493992:tid 494139] [client 20.48.251.3:46247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/update.php"] [unique_id "apPkN2bB9pEqk7z7RJldKgAAAy8"]
[Sun Aug 30 03:05:11.610774 2026] [security2:error] [pid 493992:tid 494245] [client 4.205.62.107:51743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/bootstrap.php"] [unique_id "apPkN2bB9pEqk7z7RJldLwAAA5k"]
[Sun Aug 30 03:05:11.612482 2026] [security2:error] [pid 493992:tid 494247] [client 20.48.251.3:55428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/maxro.php"] [unique_id "apPkN2bB9pEqk7z7RJldMQAAA5s"]
[Sun Aug 30 03:05:11.613510 2026] [security2:error] [pid 493992:tid 494225] [client 20.104.104.62:37458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.avenuelesrogim.com"] [uri "/waf.php"] [unique_id "apPkN2bB9pEqk7z7RJldMgAAA4U"]
[Sun Aug 30 03:05:11.621737 2026] [security2:error] [pid 493992:tid 494154] [client 68.155.159.216:59953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-content/admin.php"] [unique_id "apPkN2bB9pEqk7z7RJldNgAAAz4"]
[Sun Aug 30 03:05:11.625885 2026] [security2:error] [pid 493992:tid 494224] [client 4.205.62.107:18654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/f35.php"] [unique_id "apPkN2bB9pEqk7z7RJldOAAAA4Q"]
[Sun Aug 30 03:05:11.642678 2026] [security2:error] [pid 493992:tid 494242] [client 20.48.160.90:45902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-conffg.php"] [unique_id "apPkN2bB9pEqk7z7RJldPwAAA5Y"]
[Sun Aug 30 03:05:11.642967 2026] [security2:error] [pid 493992:tid 494191] [client 4.205.62.107:62016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/hiquido.com/index.php"] [unique_id "apPkN2bB9pEqk7z7RJldQAAAA2M"]
[Sun Aug 30 03:05:11.688716 2026] [security2:error] [pid 493992:tid 494160] [client 20.104.49.130:58053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.katbacon.com"] [uri "/wp-good.php"] [unique_id "apPkN2bB9pEqk7z7RJldUwAAA0Q"]
[Sun Aug 30 03:05:11.694122 2026] [security2:error] [pid 493992:tid 494230] [client 20.48.251.3:58872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/params.php"] [unique_id "apPkN2bB9pEqk7z7RJldWgAAA4o"]
[Sun Aug 30 03:05:11.694486 2026] [security2:error] [pid 493992:tid 494163] [client 4.205.62.107:43016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/agg.php"] [unique_id "apPkN2bB9pEqk7z7RJldWwAAA0c"]
[Sun Aug 30 03:05:11.696477 2026] [authz_core:error] [pid 493992:tid 494236] [client 66.249.66.37:54401] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:11.696783 2026] [authz_core:error] [pid 493992:tid 494236] [client 66.249.66.37:54401] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:11.699035 2026] [security2:error] [pid 493992:tid 494184] [client 20.63.219.114:10654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/updraft/about.php"] [unique_id "apPkN2bB9pEqk7z7RJldXwAAA1w"]
[Sun Aug 30 03:05:11.705259 2026] [authz_core:error] [pid 493992:tid 494176] [client 66.249.66.78:46031] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:11.705694 2026] [authz_core:error] [pid 493992:tid 494176] [client 66.249.66.78:46031] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:11.747416 2026] [security2:error] [pid 493992:tid 494210] [client 68.155.159.216:52801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-includes/plugins.php"] [unique_id "apPkN2bB9pEqk7z7RJldkwAAA3Y"]
[Sun Aug 30 03:05:11.777215 2026] [security2:error] [pid 491656:tid 491828] [client 20.151.200.44:46989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/ssss.php"] [unique_id "apPkN4vX_L6VjdbvkkTVdgAAAr4"]
[Sun Aug 30 03:05:11.797794 2026] [security2:error] [pid 491656:tid 491824] [client 216.73.216.128:6479] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPkN4vX_L6VjdbvkkTVggAAAro"]
[Sun Aug 30 03:05:11.803727 2026] [security2:error] [pid 493992:tid 494126] [client 40.83.93.50:14299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/autoload_classmap.php"] [unique_id "apPkN2bB9pEqk7z7RJldowAAAyI"]
[Sun Aug 30 03:05:11.828735 2026] [security2:error] [pid 491656:tid 491870] [client 20.48.160.90:45938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-validate.php"] [unique_id "apPkN4vX_L6VjdbvkkTVjgAAAug"]
[Sun Aug 30 03:05:11.829064 2026] [security2:error] [pid 491656:tid 491822] [client 20.104.18.15:43977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/BDKR28WP.php"] [unique_id "apPkN4vX_L6VjdbvkkTVjwAAArg"]
[Sun Aug 30 03:05:11.888166 2026] [security2:error] [pid 491656:tid 491807] [client 20.196.209.81:17750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/tflow/min.php"] [unique_id "apPkN4vX_L6VjdbvkkTVqQAAAqk"]
[Sun Aug 30 03:05:11.896544 2026] [authz_core:error] [pid 493992:tid 494196] [client 66.249.66.66:60452] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:11.896831 2026] [authz_core:error] [pid 493992:tid 494196] [client 66.249.66.66:60452] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:11.905695 2026] [authz_core:error] [pid 491656:tid 491895] [client 74.7.227.8:54904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:11.906012 2026] [authz_core:error] [pid 491656:tid 491895] [client 74.7.227.8:54904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:11.913735 2026] [security2:error] [pid 493992:tid 494155] [client 4.205.62.107:65362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/app_local.php"] [unique_id "apPkN2bB9pEqk7z7RJldzAAAAz8"]
[Sun Aug 30 03:05:11.920160 2026] [security2:error] [pid 493992:tid 494211] [client 34.15.141.119:46044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/beta/phpinfo.php"] [unique_id "apPkN2bB9pEqk7z7RJldzwAAA3c"]
[Sun Aug 30 03:05:11.942451 2026] [authz_core:error] [pid 491656:tid 491851] [client 66.249.66.37:38391] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:11.942728 2026] [authz_core:error] [pid 491656:tid 491851] [client 66.249.66.37:38391] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:11.956748 2026] [security2:error] [pid 491656:tid 491803] [client 20.48.160.90:45831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/700.php"] [unique_id "apPkN4vX_L6VjdbvkkTVvwAAAqU"]
[Sun Aug 30 03:05:12.008454 2026] [security2:error] [pid 493992:tid 494226] [client 4.205.62.107:25879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/doc.php"] [unique_id "apPkOGbB9pEqk7z7RJld7QAAA4Y"]
[Sun Aug 30 03:05:12.052444 2026] [security2:error] [pid 493992:tid 494146] [client 20.63.219.114:10685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/upgrade-temp-backup/min.php"] [unique_id "apPkOGbB9pEqk7z7RJleBgAAAzY"]
[Sun Aug 30 03:05:12.087276 2026] [security2:error] [pid 493992:tid 494148] [client 20.48.160.90:45913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/c4.php"] [unique_id "apPkOGbB9pEqk7z7RJleFQAAAzg"]
[Sun Aug 30 03:05:12.199409 2026] [security2:error] [pid 493992:tid 494179] [client 4.205.62.107:26754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/hochladen.form.php"] [unique_id "apPkOGbB9pEqk7z7RJleewAAA1c"]
[Sun Aug 30 03:05:12.220689 2026] [security2:error] [pid 493992:tid 494151] [client 20.48.160.90:45861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-tymanage.php"] [unique_id "apPkOGbB9pEqk7z7RJlehwAAAzs"]
[Sun Aug 30 03:05:12.267875 2026] [security2:error] [pid 493992:tid 494236] [client 20.104.18.15:9075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/wefile.php"] [unique_id "apPkOGbB9pEqk7z7RJleqQAAA5A"]
[Sun Aug 30 03:05:12.279742 2026] [security2:error] [pid 493992:tid 494176] [client 20.196.209.81:4592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/tflow/pk.php"] [unique_id "apPkOGbB9pEqk7z7RJletAAAA1Q"]
[Sun Aug 30 03:05:12.312560 2026] [security2:error] [pid 493992:tid 494185] [client 40.83.93.50:9124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/info.php"] [unique_id "apPkOGbB9pEqk7z7RJle0AAAA10"]
[Sun Aug 30 03:05:12.328619 2026] [security2:error] [pid 493992:tid 494227] [client 4.205.62.107:42678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPkOGbB9pEqk7z7RJle4QAAA4c"]
[Sun Aug 30 03:05:12.353166 2026] [authz_core:error] [pid 493992:tid 494226] [client 66.249.66.37:54401] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:12.353457 2026] [authz_core:error] [pid 493992:tid 494226] [client 66.249.66.37:54401] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:12.358792 2026] [security2:error] [pid 493992:tid 494203] [client 20.48.160.90:45872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/ajfto.php"] [unique_id "apPkOGbB9pEqk7z7RJle7AAAA28"]
[Sun Aug 30 03:05:12.400582 2026] [security2:error] [pid 493992:tid 494154] [client 158.23.147.79:62562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-admin.php"] [unique_id "apPkOGbB9pEqk7z7RJle_QAAAz4"]
[Sun Aug 30 03:05:12.404565 2026] [security2:error] [pid 493992:tid 494181] [client 20.63.219.114:10652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/upgrade-temp-backup/pk.php"] [unique_id "apPkOGbB9pEqk7z7RJlfAAAAA1k"]
[Sun Aug 30 03:05:12.421421 2026] [authz_core:error] [pid 491656:tid 491864] [client 74.7.227.8:54904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:12.421717 2026] [authz_core:error] [pid 491656:tid 491864] [client 74.7.227.8:54904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:12.497045 2026] [security2:error] [pid 493992:tid 494235] [client 20.48.160.90:45839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp_KwIW0U5F.php"] [unique_id "apPkOGbB9pEqk7z7RJlfNAAAA48"]
[Sun Aug 30 03:05:12.497551 2026] [security2:error] [pid 493992:tid 494225] [client 20.104.49.130:60615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.infinitelearners.com"] [uri "/mh.php"] [unique_id "apPkOGbB9pEqk7z7RJlfNgAAA4U"]
[Sun Aug 30 03:05:12.518496 2026] [security2:error] [pid 493992:tid 494132] [client 34.15.141.119:46052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/uat/phpinfo.php"] [unique_id "apPkOGbB9pEqk7z7RJlfSQAAAyg"]
[Sun Aug 30 03:05:12.561379 2026] [security2:error] [pid 493992:tid 494142] [client 118.189.242.201:54053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.242.189.118.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "geotravel.am"] [uri "/wp-comments-post.php"] [unique_id "apPkOGbB9pEqk7z7RJlfMgAAAzI"], referer: https://geotravel.am/discover-armenias-hidden-gems-tufenkian-avan-marak-tsapatagh-hotel/comment-page-269967/
[Sun Aug 30 03:05:12.561476 2026] [security2:error] [pid 493992:tid 494142] [client 118.189.242.201:54053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "geotravel.am"] [uri "/wp-comments-post.php"] [unique_id "apPkOGbB9pEqk7z7RJlfMgAAAzI"], referer: https://geotravel.am/discover-armenias-hidden-gems-tufenkian-avan-marak-tsapatagh-hotel/comment-page-269967/
[Sun Aug 30 03:05:12.574179 2026] [security2:error] [pid 493992:tid 494147] [client 4.205.62.107:63757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/channels.php"] [unique_id "apPkOGbB9pEqk7z7RJlfZgAAAzc"]
[Sun Aug 30 03:05:12.583743 2026] [security2:error] [pid 493992:tid 494208] [client 20.48.251.3:4674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/lmfi2.php"] [unique_id "apPkOGbB9pEqk7z7RJlfcAAAA3Q"]
[Sun Aug 30 03:05:12.589086 2026] [security2:error] [pid 493992:tid 494132] [client 20.48.251.3:23456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/channels.php"] [unique_id "apPkOGbB9pEqk7z7RJlfdAAAAyg"]
[Sun Aug 30 03:05:12.605243 2026] [security2:error] [pid 493992:tid 494176] [client 20.104.18.15:33006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/she11.php"] [unique_id "apPkOGbB9pEqk7z7RJlffAAAA1Q"]
[Sun Aug 30 03:05:12.607265 2026] [security2:error] [pid 493992:tid 494203] [client 20.104.50.220:46864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/86.php"] [unique_id "apPkOGbB9pEqk7z7RJlffgAAA28"]
[Sun Aug 30 03:05:12.609054 2026] [security2:error] [pid 491656:tid 491884] [client 20.104.50.220:27087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/wp-cron.php"] [unique_id "apPkOIvX_L6VjdbvkkTWvAAAAvY"]
[Sun Aug 30 03:05:12.613786 2026] [security2:error] [pid 493992:tid 494151] [client 20.104.50.220:33207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/rayzky.php"] [unique_id "apPkOGbB9pEqk7z7RJlfgAAAAzs"]
[Sun Aug 30 03:05:12.621104 2026] [security2:error] [pid 493992:tid 494247] [client 4.205.62.107:35995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/tax.php"] [unique_id "apPkOGbB9pEqk7z7RJlfiAAAA5s"]
[Sun Aug 30 03:05:12.622428 2026] [security2:error] [pid 493992:tid 494207] [client 20.104.18.15:13639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/ops.php"] [unique_id "apPkOGbB9pEqk7z7RJlfiQAAA3M"]
[Sun Aug 30 03:05:12.625513 2026] [security2:error] [pid 493992:tid 494195] [client 4.205.62.107:4605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/environment.php"] [unique_id "apPkOGbB9pEqk7z7RJlfigAAA2c"]
[Sun Aug 30 03:05:12.627300 2026] [security2:error] [pid 493992:tid 494131] [client 4.205.62.107:62446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/25.php"] [unique_id "apPkOGbB9pEqk7z7RJlfjQAAAyc"]
[Sun Aug 30 03:05:12.629021 2026] [security2:error] [pid 493992:tid 494218] [client 20.48.160.90:40009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp_xiPu52Ut.php"] [unique_id "apPkOGbB9pEqk7z7RJlfkAAAA34"]
[Sun Aug 30 03:05:12.629387 2026] [security2:error] [pid 493992:tid 494162] [client 20.104.50.220:51569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/s_on.php"] [unique_id "apPkOGbB9pEqk7z7RJlfkgAAA0Y"]
[Sun Aug 30 03:05:12.633415 2026] [security2:error] [pid 493992:tid 494224] [client 68.155.159.216:54722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apPkOGbB9pEqk7z7RJlflgAAA4Q"]
[Sun Aug 30 03:05:12.635655 2026] [security2:error] [pid 493992:tid 494199] [client 20.48.251.3:52841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/cloud.php"] [unique_id "apPkOGbB9pEqk7z7RJlfmAAAA2s"]
[Sun Aug 30 03:05:12.659174 2026] [authz_core:error] [pid 491656:tid 491901] [client 216.73.216.128:6479] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:12.659634 2026] [authz_core:error] [pid 491656:tid 491901] [client 216.73.216.128:6479] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:12.668388 2026] [security2:error] [pid 493992:tid 494234] [client 20.104.50.220:32524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/2index.php"] [unique_id "apPkOGbB9pEqk7z7RJlfrQAAA44"]
[Sun Aug 30 03:05:12.671891 2026] [security2:error] [pid 491656:tid 491886] [client 20.196.209.81:4582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/theme-check/theme-check.php"] [unique_id "apPkOIvX_L6VjdbvkkTW1AAAAvg"]
[Sun Aug 30 03:05:12.672598 2026] [security2:error] [pid 493992:tid 494156] [client 4.205.62.107:2361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/php_info.php"] [unique_id "apPkOGbB9pEqk7z7RJlfrwAAA0A"]
[Sun Aug 30 03:05:12.685687 2026] [security2:error] [pid 491656:tid 491823] [client 20.48.251.3:64437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/css.php"] [unique_id "apPkOIvX_L6VjdbvkkTW1gAAArk"]
[Sun Aug 30 03:05:12.696442 2026] [security2:error] [pid 493992:tid 494177] [client 20.104.50.220:61952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/fellganteng.php"] [unique_id "apPkOGbB9pEqk7z7RJlfvAAAA1U"]
[Sun Aug 30 03:05:12.711975 2026] [security2:error] [pid 493992:tid 494249] [client 20.104.50.220:5465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/filemanager/dialog.php"] [unique_id "apPkOGbB9pEqk7z7RJlfxgAAA50"]
[Sun Aug 30 03:05:12.715140 2026] [security2:error] [pid 493992:tid 494128] [client 20.220.10.235:28647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkOGbB9pEqk7z7RJlfyAAAAyQ"]
[Sun Aug 30 03:05:12.718216 2026] [security2:error] [pid 491656:tid 491794] [client 20.104.50.220:52842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/h4cker.php"] [unique_id "apPkOIvX_L6VjdbvkkTW5AAAApw"]
[Sun Aug 30 03:05:12.732166 2026] [security2:error] [pid 493992:tid 494156] [client 20.104.18.15:31556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/wp_blog_footer.php"] [unique_id "apPkOGbB9pEqk7z7RJlf0QAAA0A"]
[Sun Aug 30 03:05:12.733583 2026] [security2:error] [pid 493992:tid 494229] [client 158.23.147.79:63253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apPkOGbB9pEqk7z7RJlf1QAAA4k"]
[Sun Aug 30 03:05:12.740922 2026] [security2:error] [pid 493992:tid 494154] [client 216.73.216.128:9876] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPkOGbB9pEqk7z7RJlf2QAAAz4"]
[Sun Aug 30 03:05:12.744256 2026] [security2:error] [pid 493992:tid 494230] [client 20.48.251.3:54746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/channels.php"] [unique_id "apPkOGbB9pEqk7z7RJlf4AAAA4o"]
[Sun Aug 30 03:05:12.747677 2026] [security2:error] [pid 493992:tid 494240] [client 4.205.62.107:51767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/333.php"] [unique_id "apPkOGbB9pEqk7z7RJlf4wAAA5Q"]
[Sun Aug 30 03:05:12.748728 2026] [security2:error] [pid 493992:tid 494131] [client 68.155.159.216:54126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/xmlrpc.php"] [unique_id "apPkOGbB9pEqk7z7RJlf5AAAAyc"]
[Sun Aug 30 03:05:12.749406 2026] [security2:error] [pid 493992:tid 494169] [client 20.48.251.3:55452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/brc.php"] [unique_id "apPkOGbB9pEqk7z7RJlf5QAAA00"]
[Sun Aug 30 03:05:12.752982 2026] [security2:error] [pid 493992:tid 494157] [client 20.63.219.114:16805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/upgrade-temp-backup/plugins/security.php"] [unique_id "apPkOGbB9pEqk7z7RJlf5gAAA0E"]
[Sun Aug 30 03:05:12.767841 2026] [security2:error] [pid 493992:tid 494183] [client 20.48.160.90:45852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp_n5VD7XDh.php"] [unique_id "apPkOGbB9pEqk7z7RJlf6wAAA1s"]
[Sun Aug 30 03:05:12.783042 2026] [security2:error] [pid 493992:tid 494239] [client 4.205.62.107:64060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/ws79.php"] [unique_id "apPkOGbB9pEqk7z7RJlf9gAAA5M"]
[Sun Aug 30 03:05:12.791840 2026] [security2:error] [pid 493992:tid 494128] [client 4.205.62.107:18672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/api.php"] [unique_id "apPkOGbB9pEqk7z7RJlf-gAAAyQ"]
[Sun Aug 30 03:05:12.822992 2026] [security2:error] [pid 493992:tid 494232] [client 40.83.93.50:9122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/b.php"] [unique_id "apPkOGbB9pEqk7z7RJlgEgAAA4w"]
[Sun Aug 30 03:05:12.827878 2026] [security2:error] [pid 491656:tid 491839] [client 4.205.62.107:44462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/requirements.php"] [unique_id "apPkOIvX_L6VjdbvkkTXDwAAAsk"]
[Sun Aug 30 03:05:12.843047 2026] [security2:error] [pid 493992:tid 494147] [client 20.220.10.235:28547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkOGbB9pEqk7z7RJlgHwAAAzc"]
[Sun Aug 30 03:05:12.902743 2026] [security2:error] [pid 493992:tid 494225] [client 20.48.160.90:50564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkOGbB9pEqk7z7RJlgMAAAA4U"]
[Sun Aug 30 03:05:12.922448 2026] [authz_core:error] [pid 491656:tid 491835] [client 74.7.227.8:54904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:12.922740 2026] [authz_core:error] [pid 491656:tid 491835] [client 74.7.227.8:54904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:12.925512 2026] [authz_core:error] [pid 491656:tid 491823] [client 66.249.66.75:59949] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:12.925956 2026] [authz_core:error] [pid 491656:tid 491823] [client 66.249.66.75:59949] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:12.930288 2026] [security2:error] [pid 493992:tid 494133] [client 68.155.159.216:59385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apPkOGbB9pEqk7z7RJlgOQAAAyk"]
[Sun Aug 30 03:05:12.934978 2026] [security2:error] [pid 493992:tid 494242] [client 20.48.160.90:45914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-mini.php"] [unique_id "apPkOGbB9pEqk7z7RJlgOgAAA5Y"]
[Sun Aug 30 03:05:12.969854 2026] [security2:error] [pid 493992:tid 494220] [client 20.220.10.235:28656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/h02ugyh.php"] [unique_id "apPkOGbB9pEqk7z7RJlgUwAAA4A"]
[Sun Aug 30 03:05:12.983154 2026] [security2:error] [pid 493992:tid 494164] [client 20.104.18.15:43277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/sf.php"] [unique_id "apPkOGbB9pEqk7z7RJlgVwAAA0g"]
[Sun Aug 30 03:05:12.990089 2026] [security2:error] [pid 493992:tid 494138] [client 20.48.251.3:34560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/gjm.php"] [unique_id "apPkOGbB9pEqk7z7RJlgWgAAAy4"]
[Sun Aug 30 03:05:13.055996 2026] [security2:error] [pid 493992:tid 494175] [client 4.205.62.107:58112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/ws62.php"] [unique_id "apPkOWbB9pEqk7z7RJlghwAAA1M"]
[Sun Aug 30 03:05:13.065298 2026] [security2:error] [pid 493992:tid 494247] [client 20.196.209.81:11158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/theme/about.php"] [unique_id "apPkOWbB9pEqk7z7RJlgjgAAA5s"]
[Sun Aug 30 03:05:13.068048 2026] [security2:error] [pid 493992:tid 494249] [client 20.48.160.90:45915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/xmini4.php"] [unique_id "apPkOWbB9pEqk7z7RJlgkAAAA50"]
[Sun Aug 30 03:05:13.096520 2026] [security2:error] [pid 493992:tid 494127] [client 20.48.160.90:50563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkOWbB9pEqk7z7RJlgnAAAAyM"]
[Sun Aug 30 03:05:13.106710 2026] [security2:error] [pid 493992:tid 494196] [client 20.63.219.114:10644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/upgrade-temp-backup/plugins/users.php"] [unique_id "apPkOWbB9pEqk7z7RJlgqwAAA2g"]
[Sun Aug 30 03:05:13.124152 2026] [security2:error] [pid 493992:tid 494203] [client 34.15.141.119:46062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/qa/phpinfo.php"] [unique_id "apPkOWbB9pEqk7z7RJlgswAAA28"]
[Sun Aug 30 03:05:13.131798 2026] [security2:error] [pid 493992:tid 494129] [client 118.189.242.201:54077] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "geotravel.am"] [uri "/wp-comments-post.php"] [unique_id "apPkOWbB9pEqk7z7RJlgtgAAAyU"], referer: https://geotravel.am/discover-armenias-hidden-gems-tufenkian-avan-marak-tsapatagh-hotel/comment-page-269967/
[Sun Aug 30 03:05:13.133065 2026] [security2:error] [pid 493992:tid 494227] [client 20.220.10.235:28613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/sf.php"] [unique_id "apPkOWbB9pEqk7z7RJlgvgAAA4c"]
[Sun Aug 30 03:05:13.141235 2026] [security2:error] [pid 493992:tid 494126] [client 4.205.62.107:25904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/classsmtps.php"] [unique_id "apPkOWbB9pEqk7z7RJlgwwAAAyI"]
[Sun Aug 30 03:05:13.198242 2026] [security2:error] [pid 493992:tid 494226] [client 20.48.160.90:40025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/reop3.php"] [unique_id "apPkOWbB9pEqk7z7RJlg9AAAA4Y"]
[Sun Aug 30 03:05:13.217716 2026] [security2:error] [pid 493992:tid 494138] [client 158.23.147.79:62580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/lock.php"] [unique_id "apPkOWbB9pEqk7z7RJlhAQAAAy4"]
[Sun Aug 30 03:05:13.232955 2026] [authz_core:error] [pid 491656:tid 491792] [client 66.249.66.71:62145] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:13.233254 2026] [authz_core:error] [pid 491656:tid 491792] [client 66.249.66.71:62145] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:13.242365 2026] [security2:error] [pid 491656:tid 491854] [client 20.48.160.90:50640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/ap.php"] [unique_id "apPkOYvX_L6VjdbvkkTXtwAAAtg"]
[Sun Aug 30 03:05:13.264807 2026] [security2:error] [pid 493992:tid 494206] [client 20.220.10.235:28634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/4e.php"] [unique_id "apPkOWbB9pEqk7z7RJlhGgAAA3I"]
[Sun Aug 30 03:05:13.286980 2026] [security2:error] [pid 493992:tid 494211] [client 216.73.216.128:9876] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPkOWbB9pEqk7z7RJlhKgAAA3c"]
[Sun Aug 30 03:05:13.297170 2026] [authz_core:error] [pid 493992:tid 494159] [client 66.249.66.77:44286] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:13.297457 2026] [authz_core:error] [pid 493992:tid 494159] [client 66.249.66.77:44286] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:13.331490 2026] [security2:error] [pid 493992:tid 494178] [client 40.83.93.50:9035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/wp-login.php"] [unique_id "apPkOWbB9pEqk7z7RJlhRgAAA1Y"]
[Sun Aug 30 03:05:13.332048 2026] [security2:error] [pid 493992:tid 494133] [client 20.48.160.90:45878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-mail.php"] [unique_id "apPkOWbB9pEqk7z7RJlhVAAAAyk"]
[Sun Aug 30 03:05:13.355767 2026] [authz_core:error] [pid 493992:tid 494175] [client 66.249.66.40:39016] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:13.356174 2026] [authz_core:error] [pid 493992:tid 494175] [client 66.249.66.40:39016] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:13.377851 2026] [security2:error] [pid 493992:tid 494180] [client 216.73.216.128:43710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPkOWbB9pEqk7z7RJlhawAAA1g"]
[Sun Aug 30 03:05:13.379825 2026] [security2:error] [pid 493992:tid 494164] [client 20.48.160.90:50584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/media.php"] [unique_id "apPkOWbB9pEqk7z7RJlhbAAAA0g"]
[Sun Aug 30 03:05:13.393862 2026] [authz_core:error] [pid 491656:tid 491868] [client 74.7.227.8:54904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:13.394126 2026] [authz_core:error] [pid 491656:tid 491868] [client 74.7.227.8:54904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:13.396831 2026] [security2:error] [pid 493992:tid 494145] [client 20.220.10.235:28664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/ssss.php"] [unique_id "apPkOWbB9pEqk7z7RJlhdgAAAzU"]
[Sun Aug 30 03:05:13.454218 2026] [security2:error] [pid 493992:tid 494150] [client 20.63.219.114:16798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/upgrade-temp-backup/plugins/wp-blog-header.php"] [unique_id "apPkOWbB9pEqk7z7RJlhqAAAAzo"]
[Sun Aug 30 03:05:13.472027 2026] [security2:error] [pid 493992:tid 494218] [client 4.205.62.107:42561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPkOWbB9pEqk7z7RJlhtwAAA34"]
[Sun Aug 30 03:05:13.472450 2026] [security2:error] [pid 493992:tid 494202] [client 20.196.209.81:4597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/theme/min.php"] [unique_id "apPkOWbB9pEqk7z7RJlhuAAAA24"]
[Sun Aug 30 03:05:13.473981 2026] [security2:error] [pid 491656:tid 491818] [client 20.48.160.90:45951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-conffg.php"] [unique_id "apPkOYvX_L6VjdbvkkTYFAAAArQ"]
[Sun Aug 30 03:05:13.474142 2026] [security2:error] [pid 493992:tid 494134] [client 20.104.18.15:9033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/blog.php"] [unique_id "apPkOWbB9pEqk7z7RJlhuQAAAyo"]
[Sun Aug 30 03:05:13.492484 2026] [authz_core:error] [pid 491656:tid 491885] [client 66.249.66.35:43557] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:13.492941 2026] [authz_core:error] [pid 491656:tid 491885] [client 66.249.66.35:43557] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:13.510214 2026] [security2:error] [pid 493992:tid 494225] [client 4.205.62.107:27308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/debuggen.php"] [unique_id "apPkOWbB9pEqk7z7RJlh0QAAA4U"]
[Sun Aug 30 03:05:13.526430 2026] [security2:error] [pid 493992:tid 494235] [client 20.220.10.235:28557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/zoz.php"] [unique_id "apPkOWbB9pEqk7z7RJlh5gAAA48"]
[Sun Aug 30 03:05:13.604726 2026] [security2:error] [pid 493992:tid 494156] [client 20.48.160.90:45929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/filefuns.php"] [unique_id "apPkOWbB9pEqk7z7RJliBQAAA0A"]
[Sun Aug 30 03:05:13.629584 2026] [security2:error] [pid 493992:tid 494200] [client 20.48.160.90:50662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/adminfuns.php"] [unique_id "apPkOWbB9pEqk7z7RJliFAAAA2w"]
[Sun Aug 30 03:05:13.631600 2026] [autoindex:error] [pid 493992:tid 494210] [client 4.205.62.107:32488] AH01276: Cannot serve directory /home4/suite103/recoverymarine.com/wp-includes/js/tinymce/themes/inlite/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:05:13.664525 2026] [security2:error] [pid 493992:tid 494244] [client 20.220.10.235:28639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/kcs.php"] [unique_id "apPkOWbB9pEqk7z7RJliLAAAA5g"]
[Sun Aug 30 03:05:13.715050 2026] [security2:error] [pid 491656:tid 491861] [client 4.205.62.107:63746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/zz.php"] [unique_id "apPkOYvX_L6VjdbvkkTYYAAAAt8"]
[Sun Aug 30 03:05:13.725831 2026] [security2:error] [pid 493992:tid 494193] [client 20.48.251.3:23325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/zz.php"] [unique_id "apPkOWbB9pEqk7z7RJliSwAAA2U"]
[Sun Aug 30 03:05:13.729267 2026] [security2:error] [pid 493992:tid 494202] [client 34.15.141.119:46074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/preview/phpinfo.php"] [unique_id "apPkOWbB9pEqk7z7RJliTAAAA24"]
[Sun Aug 30 03:05:13.735995 2026] [security2:error] [pid 493992:tid 494204] [client 20.48.160.90:40055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-cron.php"] [unique_id "apPkOWbB9pEqk7z7RJliUgAAA3A"]
[Sun Aug 30 03:05:13.738685 2026] [security2:error] [pid 491656:tid 491910] [client 68.155.159.216:52719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-admin/images/about.php"] [unique_id "apPkOYvX_L6VjdbvkkTYaAAAAxA"]
[Sun Aug 30 03:05:13.746605 2026] [security2:error] [pid 493992:tid 494190] [client 20.104.50.220:27096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/btx25.php"] [unique_id "apPkOWbB9pEqk7z7RJliWgAAA2I"]
[Sun Aug 30 03:05:13.746730 2026] [security2:error] [pid 493992:tid 494244] [client 20.104.50.220:47098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/min.php"] [unique_id "apPkOWbB9pEqk7z7RJliWQAAA5g"]
[Sun Aug 30 03:05:13.751298 2026] [security2:error] [pid 493992:tid 494209] [client 20.104.50.220:32853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/repair.php"] [unique_id "apPkOWbB9pEqk7z7RJliXgAAA3U"]
[Sun Aug 30 03:05:13.759131 2026] [security2:error] [pid 493992:tid 494221] [client 20.48.160.90:50667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/classwithtostring.php"] [unique_id "apPkOWbB9pEqk7z7RJliYAAAA4E"]
[Sun Aug 30 03:05:13.775855 2026] [security2:error] [pid 493992:tid 494218] [client 20.104.50.220:42464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/selaras.php"] [unique_id "apPkOWbB9pEqk7z7RJliaAAAA34"]
[Sun Aug 30 03:05:13.776301 2026] [security2:error] [pid 493992:tid 494147] [client 20.104.18.15:13695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/coffexium.php"] [unique_id "apPkOWbB9pEqk7z7RJliagAAAzc"]
[Sun Aug 30 03:05:13.786042 2026] [security2:error] [pid 491656:tid 491826] [client 4.205.62.107:22577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/nlnub.php"] [unique_id "apPkOYvX_L6VjdbvkkTYeAAAArw"]
[Sun Aug 30 03:05:13.788110 2026] [security2:error] [pid 493992:tid 494150] [client 4.205.62.107:4546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/aws_secret_config.php"] [unique_id "apPkOWbB9pEqk7z7RJlibwAAAzo"]
[Sun Aug 30 03:05:13.790672 2026] [security2:error] [pid 491656:tid 491843] [client 20.48.251.3:55796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/asdf.php"] [unique_id "apPkOYvX_L6VjdbvkkTYewAAAs0"]
[Sun Aug 30 03:05:13.791304 2026] [security2:error] [pid 493992:tid 494208] [client 20.220.10.235:28641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/tajj.php"] [unique_id "apPkOWbB9pEqk7z7RJlicgAAA3Q"]
[Sun Aug 30 03:05:13.792436 2026] [security2:error] [pid 491656:tid 491829] [client 20.48.251.3:44305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/wpver.php"] [unique_id "apPkOYvX_L6VjdbvkkTYfQAAAr8"]
[Sun Aug 30 03:05:13.804487 2026] [security2:error] [pid 491656:tid 491909] [client 20.104.18.15:33729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/kerang.php"] [unique_id "apPkOYvX_L6VjdbvkkTYgQAAAw8"]
[Sun Aug 30 03:05:13.808938 2026] [security2:error] [pid 493992:tid 494195] [client 4.205.62.107:2342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/session.php"] [unique_id "apPkOWbB9pEqk7z7RJliewAAA2c"]
[Sun Aug 30 03:05:13.821922 2026] [security2:error] [pid 493992:tid 494181] [client 20.104.50.220:32280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/3index.php"] [unique_id "apPkOWbB9pEqk7z7RJlihAAAA1k"]
[Sun Aug 30 03:05:13.836286 2026] [security2:error] [pid 493992:tid 494137] [client 20.63.219.114:10634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/upgrade-temp-backup/plugins/wp-mail.php"] [unique_id "apPkOWbB9pEqk7z7RJliigAAAy0"]
[Sun Aug 30 03:05:13.837208 2026] [security2:error] [pid 493992:tid 494154] [client 20.48.251.3:6986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/php_info.php"] [unique_id "apPkOWbB9pEqk7z7RJliiwAAAz4"]
[Sun Aug 30 03:05:13.841201 2026] [security2:error] [pid 493992:tid 494156] [client 158.23.147.79:62491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/index/function.php"] [unique_id "apPkOWbB9pEqk7z7RJlijQAAA0A"]
[Sun Aug 30 03:05:13.850325 2026] [security2:error] [pid 493992:tid 494134] [client 20.104.50.220:61695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/fell.php"] [unique_id "apPkOWbB9pEqk7z7RJlikwAAAyo"]
[Sun Aug 30 03:05:13.858459 2026] [security2:error] [pid 493992:tid 494163] [client 40.83.93.50:9099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/aa.php"] [unique_id "apPkOWbB9pEqk7z7RJlilwAAA0c"]
[Sun Aug 30 03:05:13.859081 2026] [security2:error] [pid 493992:tid 494155] [client 20.104.50.220:5455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apPkOWbB9pEqk7z7RJlimAAAAz8"]
[Sun Aug 30 03:05:13.870716 2026] [security2:error] [pid 493992:tid 494241] [client 4.205.62.107:32488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/doc.php"] [unique_id "apPkOWbB9pEqk7z7RJlinwAAA5U"]
[Sun Aug 30 03:05:13.884865 2026] [security2:error] [pid 493992:tid 494128] [client 4.205.62.107:52143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/G-in.php"] [unique_id "apPkOWbB9pEqk7z7RJliqgAAAyQ"]
[Sun Aug 30 03:05:13.889032 2026] [security2:error] [pid 493992:tid 494204] [client 20.48.251.3:55510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/vx.php"] [unique_id "apPkOWbB9pEqk7z7RJlirgAAA3A"]
[Sun Aug 30 03:05:13.893884 2026] [security2:error] [pid 493992:tid 494131] [client 20.196.209.81:21170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/themes/about.php"] [unique_id "apPkOWbB9pEqk7z7RJliswAAAyc"]
[Sun Aug 30 03:05:13.895221 2026] [security2:error] [pid 493992:tid 494177] [client 20.104.50.220:29156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/gazashell.php"] [unique_id "apPkOWbB9pEqk7z7RJlitQAAA1U"]
[Sun Aug 30 03:05:13.899118 2026] [security2:error] [pid 493992:tid 494209] [client 20.104.18.15:31706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/sushi.php"] [unique_id "apPkOWbB9pEqk7z7RJliuAAAA3U"]
[Sun Aug 30 03:05:13.902979 2026] [security2:error] [pid 493992:tid 494247] [client 20.48.160.90:45851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/lock360.php"] [unique_id "apPkOWbB9pEqk7z7RJlivAAAA5s"]
[Sun Aug 30 03:05:13.903055 2026] [security2:error] [pid 493992:tid 494151] [client 20.48.160.90:50572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPkOWbB9pEqk7z7RJlivQAAAzs"]
[Sun Aug 30 03:05:13.918284 2026] [security2:error] [pid 493992:tid 494122] [client 20.48.251.3:65519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/zz.php"] [unique_id "apPkOWbB9pEqk7z7RJliwwAAAx4"]
[Sun Aug 30 03:05:13.922232 2026] [security2:error] [pid 493992:tid 494224] [client 20.220.10.235:28570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/bge.php"] [unique_id "apPkOWbB9pEqk7z7RJlixgAAA4Q"]
[Sun Aug 30 03:05:13.924406 2026] [security2:error] [pid 493992:tid 494218] [client 20.151.200.44:47421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkOWbB9pEqk7z7RJliyAAAA34"]
[Sun Aug 30 03:05:13.924953 2026] [security2:error] [pid 493992:tid 494163] [client 4.205.62.107:63996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/public/wp-blog.php"] [unique_id "apPkOWbB9pEqk7z7RJliyQAAA0c"]
[Sun Aug 30 03:05:13.935722 2026] [security2:error] [pid 493992:tid 494200] [client 68.155.159.216:59966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/atomlib.php"] [unique_id "apPkOWbB9pEqk7z7RJli0gAAA2w"]
[Sun Aug 30 03:05:13.939548 2026] [security2:error] [pid 493992:tid 494138] [client 4.205.62.107:18987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/temp.php"] [unique_id "apPkOWbB9pEqk7z7RJli0wAAAy4"]
[Sun Aug 30 03:05:13.941367 2026] [authz_core:error] [pid 491656:tid 491833] [client 74.7.227.8:54904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:13.941782 2026] [authz_core:error] [pid 491656:tid 491833] [client 74.7.227.8:54904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:13.966039 2026] [security2:error] [pid 493992:tid 494133] [client 4.205.62.107:44435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/var/www/wallet/index.php"] [unique_id "apPkOWbB9pEqk7z7RJli4gAAAyk"]
[Sun Aug 30 03:05:13.968183 2026] [security2:error] [pid 493992:tid 494177] [client 52.139.37.240:19778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/403.php"] [unique_id "apPkOWbB9pEqk7z7RJli5gAAA1U"]
[Sun Aug 30 03:05:13.984278 2026] [authz_core:error] [pid 493992:tid 494184] [client 66.249.66.201:43027] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:13.984692 2026] [authz_core:error] [pid 493992:tid 494184] [client 66.249.66.201:43027] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:14.038224 2026] [security2:error] [pid 493992:tid 494167] [client 20.48.160.90:50619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/5PJcpMFsD8B.php"] [unique_id "apPkOmbB9pEqk7z7RJljEQAAA0s"]
[Sun Aug 30 03:05:14.047268 2026] [security2:error] [pid 493992:tid 494153] [client 20.48.160.90:45843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-theme.php"] [unique_id "apPkOmbB9pEqk7z7RJljGAAAAz0"]
[Sun Aug 30 03:05:14.056603 2026] [security2:error] [pid 493992:tid 494224] [client 68.155.159.216:52741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/goat1.php"] [unique_id "apPkOmbB9pEqk7z7RJljJAAAA4Q"]
[Sun Aug 30 03:05:14.063163 2026] [security2:error] [pid 493992:tid 494213] [client 20.220.10.235:28648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/ssh3ll.php"] [unique_id "apPkOmbB9pEqk7z7RJljLAAAA3k"]
[Sun Aug 30 03:05:14.090846 2026] [security2:error] [pid 493992:tid 494175] [client 20.151.200.44:47044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/qi.php"] [unique_id "apPkOmbB9pEqk7z7RJljOgAAA1M"]
[Sun Aug 30 03:05:14.128130 2026] [security2:error] [pid 493992:tid 494213] [client 20.104.18.15:43981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/k.php"] [unique_id "apPkOmbB9pEqk7z7RJljWQAAA3k"]
[Sun Aug 30 03:05:14.154992 2026] [authz_core:error] [pid 493992:tid 494189] [client 66.249.66.45:52005] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:14.155271 2026] [authz_core:error] [pid 493992:tid 494189] [client 66.249.66.45:52005] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:14.161001 2026] [security2:error] [pid 493992:tid 494244] [client 52.139.37.240:61124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/av.php"] [unique_id "apPkOmbB9pEqk7z7RJljfQAAA5g"]
[Sun Aug 30 03:05:14.161755 2026] [security2:error] [pid 493992:tid 494192] [client 158.23.147.79:63295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkOmbB9pEqk7z7RJljfgAAA2Q"]
[Sun Aug 30 03:05:14.173727 2026] [security2:error] [pid 493992:tid 494126] [client 158.23.147.79:62481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/.well-known/content.php"] [unique_id "apPkOmbB9pEqk7z7RJljiwAAAyI"]
[Sun Aug 30 03:05:14.177015 2026] [security2:error] [pid 493992:tid 494242] [client 20.48.160.90:45935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/2d7433/index.php"] [unique_id "apPkOmbB9pEqk7z7RJljkAAAA5Y"]
[Sun Aug 30 03:05:14.183238 2026] [security2:error] [pid 493992:tid 494194] [client 20.63.219.114:10686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/upgrade-temp-backup/themes/admin.php"] [unique_id "apPkOmbB9pEqk7z7RJljlgAAA2Y"]
[Sun Aug 30 03:05:14.188889 2026] [security2:error] [pid 493992:tid 494180] [client 20.48.160.90:50638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPkOmbB9pEqk7z7RJljmwAAA1g"]
[Sun Aug 30 03:05:14.197339 2026] [security2:error] [pid 491656:tid 491809] [client 216.73.216.128:6479] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPkOovX_L6VjdbvkkTY_QAAAqs"]
[Sun Aug 30 03:05:14.206576 2026] [security2:error] [pid 493992:tid 494139] [client 20.220.10.235:28560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/motu.php"] [unique_id "apPkOmbB9pEqk7z7RJljsAAAAy8"]
[Sun Aug 30 03:05:14.208272 2026] [security2:error] [pid 493992:tid 494211] [client 4.205.62.107:65372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/grsiuk.php"] [unique_id "apPkOmbB9pEqk7z7RJljsQAAA3c"]
[Sun Aug 30 03:05:14.257232 2026] [security2:error] [pid 493992:tid 494140] [client 158.23.147.79:63270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkOmbB9pEqk7z7RJlj2AAAAzA"]
[Sun Aug 30 03:05:14.261192 2026] [security2:error] [pid 493992:tid 494146] [client 20.48.251.3:51459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/configuration.php"] [unique_id "apPkOmbB9pEqk7z7RJlj2wAAAzY"]
[Sun Aug 30 03:05:14.282122 2026] [security2:error] [pid 493992:tid 494232] [client 20.196.209.81:4601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/themes/panel.php"] [unique_id "apPkOmbB9pEqk7z7RJlj8gAAA4w"]
[Sun Aug 30 03:05:14.292963 2026] [security2:error] [pid 493992:tid 494229] [client 4.205.62.107:25762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/cache-compat.php"] [unique_id "apPkOmbB9pEqk7z7RJlj-QAAA4k"]
[Sun Aug 30 03:05:14.321510 2026] [security2:error] [pid 493992:tid 494181] [client 20.48.160.90:40041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-login.php"] [unique_id "apPkOmbB9pEqk7z7RJlkCAAAA1k"]
[Sun Aug 30 03:05:14.321700 2026] [security2:error] [pid 493992:tid 494228] [client 20.48.160.90:50654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/wsd.php"] [unique_id "apPkOmbB9pEqk7z7RJlkIAAAA4g"]
[Sun Aug 30 03:05:14.335202 2026] [security2:error] [pid 493992:tid 494169] [client 34.15.141.119:46082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/www/phpinfo.php"] [unique_id "apPkOmbB9pEqk7z7RJlkLQAAA00"]
[Sun Aug 30 03:05:14.353264 2026] [security2:error] [pid 493992:tid 494247] [client 52.139.37.240:61130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/wp-admin/index.php"] [unique_id "apPkOmbB9pEqk7z7RJlkPQAAA5s"]
[Sun Aug 30 03:05:14.355067 2026] [security2:error] [pid 493992:tid 494159] [client 20.220.10.235:28559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/wefile.php"] [unique_id "apPkOmbB9pEqk7z7RJlkPgAAA0M"]
[Sun Aug 30 03:05:14.362121 2026] [security2:error] [pid 493992:tid 494136] [client 20.151.200.44:47388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkOmbB9pEqk7z7RJlkRAAAAyw"]
[Sun Aug 30 03:05:14.369926 2026] [authz_core:error] [pid 491656:tid 491833] [client 66.249.66.71:62145] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:14.370299 2026] [authz_core:error] [pid 491656:tid 491833] [client 66.249.66.71:62145] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:14.400260 2026] [security2:error] [pid 493992:tid 494238] [client 158.23.147.79:62546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/cong.php"] [unique_id "apPkOmbB9pEqk7z7RJlkYAAAA5I"]
[Sun Aug 30 03:05:14.437748 2026] [authz_core:error] [pid 491656:tid 491878] [client 74.7.227.8:54904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:14.438044 2026] [authz_core:error] [pid 491656:tid 491878] [client 74.7.227.8:54904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:14.445350 2026] [security2:error] [pid 493992:tid 494178] [client 20.104.49.130:59562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.infinitelearners.com"] [uri "/press.php"] [unique_id "apPkOmbB9pEqk7z7RJlkiAAAA1Y"]
[Sun Aug 30 03:05:14.463658 2026] [security2:error] [pid 493992:tid 494225] [client 20.48.160.90:39946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/images.php"] [unique_id "apPkOmbB9pEqk7z7RJlklQAAA4U"]
[Sun Aug 30 03:05:14.488608 2026] [security2:error] [pid 493992:tid 494189] [client 20.220.10.235:28666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/Contrller.php"] [unique_id "apPkOmbB9pEqk7z7RJlkpQAAA2E"]
[Sun Aug 30 03:05:14.494628 2026] [security2:error] [pid 493992:tid 494207] [client 20.48.160.90:50661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/bulet.php"] [unique_id "apPkOmbB9pEqk7z7RJlkqwAAA3M"]
[Sun Aug 30 03:05:14.534101 2026] [security2:error] [pid 493992:tid 494212] [client 20.63.219.114:15609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/upgrade-temp-backup/themes/login.php"] [unique_id "apPkOmbB9pEqk7z7RJlk0AAAA3g"]
[Sun Aug 30 03:05:14.545627 2026] [security2:error] [pid 493992:tid 494205] [client 40.83.93.50:8321] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpanel.homedesigner.org"] [uri "/c99.php"] [unique_id "apPkOmbB9pEqk7z7RJlk1wAAA3E"]
[Sun Aug 30 03:05:14.546882 2026] [security2:error] [pid 493992:tid 494239] [client 52.139.37.240:19788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "apPkOmbB9pEqk7z7RJlk2AAAA5M"]
[Sun Aug 30 03:05:14.602377 2026] [security2:error] [pid 493992:tid 494228] [client 20.48.160.90:40002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/ops.php"] [unique_id "apPkOmbB9pEqk7z7RJlk9QAAA4g"]
[Sun Aug 30 03:05:14.609259 2026] [security2:error] [pid 491656:tid 491893] [client 20.104.18.15:9206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/wp-admin/js/wp-load.php"] [unique_id "apPkOovX_L6VjdbvkkTZfgAAAv8"]
[Sun Aug 30 03:05:14.627698 2026] [security2:error] [pid 493992:tid 494230] [client 20.220.10.235:28550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/file66.php"] [unique_id "apPkOmbB9pEqk7z7RJllBAAAA4o"]
[Sun Aug 30 03:05:14.638559 2026] [security2:error] [pid 493992:tid 494242] [client 4.205.62.107:42843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/agg.php"] [unique_id "apPkOmbB9pEqk7z7RJllEQAAA5Y"]
[Sun Aug 30 03:05:14.642192 2026] [security2:error] [pid 493992:tid 494174] [client 20.48.160.90:50659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/av.php"] [unique_id "apPkOmbB9pEqk7z7RJllFQAAA1I"]
[Sun Aug 30 03:05:14.682116 2026] [authz_core:error] [pid 493992:tid 494189] [client 66.249.66.196:63753] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:14.682570 2026] [authz_core:error] [pid 493992:tid 494189] [client 66.249.66.196:63753] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:14.698331 2026] [security2:error] [pid 493992:tid 494133] [client 158.23.147.79:62492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-includes/js/index.php"] [unique_id "apPkOmbB9pEqk7z7RJllNAAAAyk"]
[Sun Aug 30 03:05:14.740714 2026] [security2:error] [pid 493992:tid 494180] [client 52.139.37.240:19822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/wp-content/themes/pridmag/b.php"] [unique_id "apPkOmbB9pEqk7z7RJllSwAAA1g"]
[Sun Aug 30 03:05:14.744195 2026] [security2:error] [pid 493992:tid 494233] [client 20.48.160.90:45912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPkOmbB9pEqk7z7RJllTQAAA40"]
[Sun Aug 30 03:05:14.758856 2026] [security2:error] [pid 493992:tid 494230] [client 20.220.10.235:28661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/blnux.php"] [unique_id "apPkOmbB9pEqk7z7RJllWAAAA4o"]
[Sun Aug 30 03:05:14.770862 2026] [security2:error] [pid 493992:tid 494210] [client 20.48.160.90:50567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/images.php"] [unique_id "apPkOmbB9pEqk7z7RJllYAAAA3Y"]
[Sun Aug 30 03:05:14.779359 2026] [security2:error] [pid 493992:tid 494247] [client 4.205.62.107:36619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPkOmbB9pEqk7z7RJllZwAAA5s"]
[Sun Aug 30 03:05:14.796052 2026] [authz_core:error] [pid 493992:tid 494155] [client 66.249.66.194:43120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:14.796412 2026] [authz_core:error] [pid 493992:tid 494155] [client 66.249.66.194:43120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:14.805743 2026] [security2:error] [pid 493992:tid 494153] [client 20.196.209.81:4560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/twentytwentyfive/styles/sections/pk.php"] [unique_id "apPkOmbB9pEqk7z7RJlldQAAAz0"]
[Sun Aug 30 03:05:14.851892 2026] [authz_core:error] [pid 493992:tid 494218] [client 66.249.66.69:35999] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:14.852182 2026] [security2:error] [pid 493992:tid 494124] [client 4.205.62.107:60574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/test.php"] [unique_id "apPkOmbB9pEqk7z7RJllmAAAAyA"]
[Sun Aug 30 03:05:14.852282 2026] [authz_core:error] [pid 493992:tid 494218] [client 66.249.66.69:35999] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:14.866789 2026] [security2:error] [pid 493992:tid 494183] [client 20.48.251.3:22720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/test.php"] [unique_id "apPkOmbB9pEqk7z7RJllnwAAA1s"]
[Sun Aug 30 03:05:14.887070 2026] [security2:error] [pid 493992:tid 494142] [client 20.63.219.114:15553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/upgrade-temp-backup/themes/test.php"] [unique_id "apPkOmbB9pEqk7z7RJllrQAAAzI"]
[Sun Aug 30 03:05:14.892231 2026] [security2:error] [pid 493992:tid 494249] [client 20.220.10.235:28571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/attack.php"] [unique_id "apPkOmbB9pEqk7z7RJllsQAAA50"]
[Sun Aug 30 03:05:14.898880 2026] [security2:error] [pid 493992:tid 494229] [client 20.104.50.220:47071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-backup-sql-302.php"] [unique_id "apPkOmbB9pEqk7z7RJlltQAAA4k"]
[Sun Aug 30 03:05:14.901532 2026] [security2:error] [pid 493992:tid 494202] [client 20.104.50.220:27097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/images/g3.php"] [unique_id "apPkOmbB9pEqk7z7RJlltwAAA24"]
[Sun Aug 30 03:05:14.906037 2026] [security2:error] [pid 493992:tid 494139] [client 20.104.50.220:32849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/raw.php"] [unique_id "apPkOmbB9pEqk7z7RJlluQAAAy8"]
[Sun Aug 30 03:05:14.907106 2026] [security2:error] [pid 493992:tid 494193] [client 68.155.159.216:52683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPkOmbB9pEqk7z7RJllugAAA2U"]
[Sun Aug 30 03:05:14.907508 2026] [authz_core:error] [pid 491656:tid 491822] [client 74.7.227.8:54904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus
[Sun Aug 30 03:05:14.907919 2026] [authz_core:error] [pid 491656:tid 491822] [client 74.7.227.8:54904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fi2c_smbus
[Sun Aug 30 03:05:14.909106 2026] [security2:error] [pid 493992:tid 494224] [client 20.48.160.90:45855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPkOmbB9pEqk7z7RJllvAAAA4Q"]
[Sun Aug 30 03:05:14.925412 2026] [security2:error] [pid 493992:tid 494184] [client 216.73.216.128:9876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mysqlupgrade"] [unique_id "apPkOmbB9pEqk7z7RJllwQAAA1w"]
[Sun Aug 30 03:05:14.930520 2026] [security2:error] [pid 493992:tid 494247] [client 20.104.50.220:51535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/ssh.php"] [unique_id "apPkOmbB9pEqk7z7RJllwgAAA5s"]
[Sun Aug 30 03:05:14.942268 2026] [security2:error] [pid 493992:tid 494208] [client 20.48.251.3:55730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apPkOmbB9pEqk7z7RJllyQAAA3Q"]
[Sun Aug 30 03:05:14.943577 2026] [security2:error] [pid 493992:tid 494225] [client 34.15.141.119:46096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/htdocs/phpinfo.php"] [unique_id "apPkOmbB9pEqk7z7RJllzAAAA4U"]
[Sun Aug 30 03:05:14.944890 2026] [security2:error] [pid 493992:tid 494174] [client 4.205.62.107:4569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/snq.php"] [unique_id "apPkOmbB9pEqk7z7RJllzQAAA1I"]
[Sun Aug 30 03:05:14.945402 2026] [security2:error] [pid 493992:tid 494160] [client 4.205.62.107:22584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/mga.php"] [unique_id "apPkOmbB9pEqk7z7RJllzgAAA0Q"]
[Sun Aug 30 03:05:14.956868 2026] [security2:error] [pid 493992:tid 494239] [client 20.104.18.15:13576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/BDKR28WP.php"] [unique_id "apPkOmbB9pEqk7z7RJll0wAAA5M"]
[Sun Aug 30 03:05:14.961254 2026] [security2:error] [pid 493992:tid 494183] [client 20.104.50.220:31880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/4index.php"] [unique_id "apPkOmbB9pEqk7z7RJll1QAAA1s"]
[Sun Aug 30 03:05:14.962947 2026] [security2:error] [pid 493992:tid 494128] [client 20.104.18.15:32985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/m.php"] [unique_id "apPkOmbB9pEqk7z7RJll2QAAAyQ"]
[Sun Aug 30 03:05:14.973959 2026] [security2:error] [pid 493992:tid 494138] [client 4.205.62.107:26808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/pouhg.php"] [unique_id "apPkOmbB9pEqk7z7RJll4AAAAy4"]
[Sun Aug 30 03:05:14.976998 2026] [security2:error] [pid 493992:tid 494197] [client 20.48.251.3:7060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/session.php"] [unique_id "apPkOmbB9pEqk7z7RJll5wAAA2k"]
[Sun Aug 30 03:05:14.979094 2026] [security2:error] [pid 493992:tid 494178] [client 20.48.160.90:50583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/ops.php"] [unique_id "apPkOmbB9pEqk7z7RJll6QAAA1Y"]
[Sun Aug 30 03:05:15.004237 2026] [security2:error] [pid 493992:tid 494191] [client 20.104.50.220:61991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/ok.php"] [unique_id "apPkO2bB9pEqk7z7RJll-gAAA2M"]
[Sun Aug 30 03:05:15.004263 2026] [security2:error] [pid 493992:tid 494123] [client 20.104.50.220:6135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-includes/customize/about.php"] [unique_id "apPkO2bB9pEqk7z7RJll-QAAAx8"]
[Sun Aug 30 03:05:15.021451 2026] [security2:error] [pid 493992:tid 494222] [client 40.83.93.50:18061] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpanel.homedesigner.org"] [uri "/c99.php"] [unique_id "apPkO2bB9pEqk7z7RJlmDAAAA4I"]
[Sun Aug 30 03:05:15.025360 2026] [security2:error] [pid 493992:tid 494185] [client 20.220.10.235:28642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/wk/index.php"] [unique_id "apPkO2bB9pEqk7z7RJlmEAAAA10"]
[Sun Aug 30 03:05:15.025724 2026] [security2:error] [pid 493992:tid 494248] [client 20.48.251.3:55499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/ty.php"] [unique_id "apPkO2bB9pEqk7z7RJlmEQAAA5w"]
[Sun Aug 30 03:05:15.030424 2026] [security2:error] [pid 493992:tid 494166] [client 158.23.147.79:62576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-content/index.php"] [unique_id "apPkO2bB9pEqk7z7RJlmFgAAA0o"]
[Sun Aug 30 03:05:15.049302 2026] [security2:error] [pid 493992:tid 494217] [client 20.48.160.90:39947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/about.php"] [unique_id "apPkO2bB9pEqk7z7RJlmIgAAA30"]
[Sun Aug 30 03:05:15.050546 2026] [security2:error] [pid 493992:tid 494186] [client 20.104.50.220:62842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/syrianshell.php"] [unique_id "apPkO2bB9pEqk7z7RJlmIwAAA14"]
[Sun Aug 30 03:05:15.055493 2026] [security2:error] [pid 493992:tid 494193] [client 20.104.18.15:31591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/manga.php"] [unique_id "apPkO2bB9pEqk7z7RJlmKwAAA2U"]
[Sun Aug 30 03:05:15.083074 2026] [security2:error] [pid 493992:tid 494145] [client 20.48.251.3:44356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/ah25.php"] [unique_id "apPkO2bB9pEqk7z7RJlmQQAAAzU"]
[Sun Aug 30 03:05:15.089202 2026] [security2:error] [pid 493992:tid 494210] [client 20.48.251.3:64273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/test.php"] [unique_id "apPkO2bB9pEqk7z7RJlmRAAAA3Y"]
[Sun Aug 30 03:05:15.124422 2026] [security2:error] [pid 493992:tid 494176] [client 20.48.160.90:50653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/coffexium.php"] [unique_id "apPkO2bB9pEqk7z7RJlmXwAAA1Q"]
[Sun Aug 30 03:05:15.160283 2026] [security2:error] [pid 493992:tid 494201] [client 68.155.159.216:59977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/lv.php"] [unique_id "apPkO2bB9pEqk7z7RJlmfAAAA20"]
[Sun Aug 30 03:05:15.165446 2026] [security2:error] [pid 493992:tid 494160] [client 20.220.10.235:28615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/dehnl.php"] [unique_id "apPkO2bB9pEqk7z7RJlmfwAAA0Q"]
[Sun Aug 30 03:05:15.189569 2026] [security2:error] [pid 493992:tid 494210] [client 20.48.160.90:45827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/admin.php/admin.php"] [unique_id "apPkO2bB9pEqk7z7RJlmnQAAA3Y"]
[Sun Aug 30 03:05:15.227460 2026] [authz_core:error] [pid 493992:tid 494205] [client 66.249.66.34:49323] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:15.227930 2026] [authz_core:error] [pid 493992:tid 494205] [client 66.249.66.34:49323] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:15.235496 2026] [security2:error] [pid 493992:tid 494142] [client 20.63.219.114:16769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/upgrade-temp-backup/themes/wp-links-opml.php"] [unique_id "apPkO2bB9pEqk7z7RJlmwAAAAzI"]
[Sun Aug 30 03:05:15.246296 2026] [security2:error] [pid 493992:tid 494219] [client 68.155.159.216:52855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-includes/certificates/index.php"] [unique_id "apPkO2bB9pEqk7z7RJlmyAAAA38"]
[Sun Aug 30 03:05:15.263181 2026] [security2:error] [pid 493992:tid 494166] [client 20.48.160.90:50582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/BDKR28WP.php"] [unique_id "apPkO2bB9pEqk7z7RJlm1wAAA0o"]
[Sun Aug 30 03:05:15.274184 2026] [security2:error] [pid 493992:tid 494235] [client 52.139.37.240:61137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/0.php"] [unique_id "apPkO2bB9pEqk7z7RJlm5wAAA48"]
[Sun Aug 30 03:05:15.276713 2026] [security2:error] [pid 493992:tid 494185] [client 20.104.18.15:43273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/82.php"] [unique_id "apPkO2bB9pEqk7z7RJlm7QAAA10"]
[Sun Aug 30 03:05:15.304193 2026] [security2:error] [pid 493992:tid 494208] [client 20.220.10.235:28548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/png.php"] [unique_id "apPkO2bB9pEqk7z7RJlnCQAAA3Q"]
[Sun Aug 30 03:05:15.316413 2026] [security2:error] [pid 493992:tid 494231] [client 20.220.10.235:4072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkO2bB9pEqk7z7RJlnHQAAA4s"]
[Sun Aug 30 03:05:15.320588 2026] [security2:error] [pid 493992:tid 494172] [client 20.48.160.90:40053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/media.php"] [unique_id "apPkO2bB9pEqk7z7RJlnIgAAA1A"]
[Sun Aug 30 03:05:15.334949 2026] [security2:error] [pid 493992:tid 494230] [client 20.196.209.81:16853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/twentytwentythree/patterns/index.php"] [unique_id "apPkO2bB9pEqk7z7RJlnLAAAA4o"]
[Sun Aug 30 03:05:15.390161 2026] [security2:error] [pid 493992:tid 494210] [client 158.23.147.79:62572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/about/function.php"] [unique_id "apPkO2bB9pEqk7z7RJlnUQAAA3Y"]
[Sun Aug 30 03:05:15.406121 2026] [security2:error] [pid 493992:tid 494168] [client 20.48.251.3:51509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/server_info.php"] [unique_id "apPkO2bB9pEqk7z7RJlnZAAAA0w"]
[Sun Aug 30 03:05:15.438414 2026] [security2:error] [pid 493992:tid 494246] [client 20.220.10.235:28556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/txets.php"] [unique_id "apPkO2bB9pEqk7z7RJlngAAAA5o"]
[Sun Aug 30 03:05:15.439659 2026] [security2:error] [pid 493992:tid 494200] [client 20.48.160.90:50620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/sf.php"] [unique_id "apPkO2bB9pEqk7z7RJlngwAAA2w"]
[Sun Aug 30 03:05:15.443604 2026] [authz_core:error] [pid 491656:tid 491904] [client 74.7.227.8:54904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:15.444067 2026] [authz_core:error] [pid 491656:tid 491904] [client 74.7.227.8:54904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdoc%2Flynx%2Flynx_help%2Fkeystrokes
[Sun Aug 30 03:05:15.451588 2026] [security2:error] [pid 493992:tid 494123] [client 20.48.160.90:45860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/mac.php"] [unique_id "apPkO2bB9pEqk7z7RJlnjQAAAx8"]
[Sun Aug 30 03:05:15.451612 2026] [security2:error] [pid 493992:tid 494236] [client 20.220.10.235:4075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkO2bB9pEqk7z7RJlnjgAAA5A"]
[Sun Aug 30 03:05:15.473182 2026] [security2:error] [pid 493992:tid 494240] [client 52.139.37.240:60848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/autoload_classmap/function.php"] [unique_id "apPkO2bB9pEqk7z7RJlnngAAA5Q"]
[Sun Aug 30 03:05:15.548966 2026] [security2:error] [pid 493992:tid 494177] [client 34.15.141.119:45994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/public_html/phpinfo.php"] [unique_id "apPkO2bB9pEqk7z7RJln4QAAA1U"]
[Sun Aug 30 03:05:15.562521 2026] [security2:error] [pid 491656:tid 491863] [client 216.73.216.128:6479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPkO4vX_L6VjdbvkkTaqAAAAuE"]
[Sun Aug 30 03:05:15.582653 2026] [security2:error] [pid 493992:tid 494215] [client 20.220.10.235:28609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/wp-login.php"] [unique_id "apPkO2bB9pEqk7z7RJln8QAAA3s"]
[Sun Aug 30 03:05:15.584652 2026] [security2:error] [pid 493992:tid 494175] [client 20.48.160.90:45885] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.sygnius.com.pa"] [uri "/1.php"] [unique_id "apPkO2bB9pEqk7z7RJln9AAAA1M"]
[Sun Aug 30 03:05:15.584748 2026] [security2:error] [pid 493992:tid 494175] [client 20.48.160.90:45885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/1.php"] [unique_id "apPkO2bB9pEqk7z7RJln9AAAA1M"]
[Sun Aug 30 03:05:15.585733 2026] [security2:error] [pid 493992:tid 494157] [client 20.48.160.90:50621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/k.php"] [unique_id "apPkO2bB9pEqk7z7RJln9QAAA0E"]
[Sun Aug 30 03:05:15.586303 2026] [security2:error] [pid 493992:tid 494175] [client 20.220.10.235:4032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/h02ugyh.php"] [unique_id "apPkO2bB9pEqk7z7RJln9gAAA1M"]
[Sun Aug 30 03:05:15.589726 2026] [security2:error] [pid 493992:tid 494169] [client 20.63.219.114:4475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/upgrade-temp-backup/themes/wp-settings.php"] [unique_id "apPkO2bB9pEqk7z7RJln-gAAA00"]
[Sun Aug 30 03:05:15.668302 2026] [security2:error] [pid 491656:tid 491838] [client 52.139.37.240:19779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/dvve.php"] [unique_id "apPkO4vX_L6VjdbvkkTaywAAAsg"]
[Sun Aug 30 03:05:15.715542 2026] [security2:error] [pid 493992:tid 494217] [client 20.220.10.235:28622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/wp-access.php"] [unique_id "apPkO2bB9pEqk7z7RJloOQAAA30"]
[Sun Aug 30 03:05:15.717441 2026] [security2:error] [pid 493992:tid 494199] [client 20.48.160.90:45859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/classwithtostring.php"] [unique_id "apPkO2bB9pEqk7z7RJloOwAAA2s"]
[Sun Aug 30 03:05:15.718380 2026] [security2:error] [pid 493992:tid 494218] [client 20.220.10.235:3981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/sf.php"] [unique_id "apPkO2bB9pEqk7z7RJloPAAAA34"]
[Sun Aug 30 03:05:15.746736 2026] [security2:error] [pid 493992:tid 494133] [client 20.104.18.15:8985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/robot.php"] [unique_id "apPkO2bB9pEqk7z7RJloTwAAAyk"]
[Sun Aug 30 03:05:15.754912 2026] [security2:error] [pid 493992:tid 494169] [client 20.48.160.90:50669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/82.php"] [unique_id "apPkO2bB9pEqk7z7RJloVQAAA00"]
[Sun Aug 30 03:05:15.820002 2026] [security2:error] [pid 493992:tid 494184] [client 198.38.83.46:39680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.83.38.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "betsydunlap.com"] [uri "/wp-login.php"] [unique_id "apPkO2bB9pEqk7z7RJlocAAAA1w"]
[Sun Aug 30 03:05:15.847709 2026] [security2:error] [pid 493992:tid 494210] [client 20.220.10.235:28660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/wp-content/admin.php"] [unique_id "apPkO2bB9pEqk7z7RJlogAAAA3Y"]
[Sun Aug 30 03:05:15.848228 2026] [security2:error] [pid 493992:tid 494185] [client 40.83.93.50:8330] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpanel.homedesigner.org"] [uri "/c99.php"] [unique_id "apPkO2bB9pEqk7z7RJlogwAAA10"]
[Sun Aug 30 03:05:15.851715 2026] [security2:error] [pid 493992:tid 494163] [client 20.48.160.90:45884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-ws68.php"] [unique_id "apPkO2bB9pEqk7z7RJlohAAAA0c"]
[Sun Aug 30 03:05:15.859903 2026] [security2:error] [pid 493992:tid 494228] [client 20.220.10.235:3986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/4e.php"] [unique_id "apPkO2bB9pEqk7z7RJloiAAAA4g"]
[Sun Aug 30 03:05:15.863991 2026] [security2:error] [pid 491656:tid 491855] [client 20.196.209.81:4568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/users.php"] [unique_id "apPkO4vX_L6VjdbvkkTbGQAAAtk"]
[Sun Aug 30 03:05:15.868863 2026] [authz_core:error] [pid 493992:tid 494194] [client 66.249.66.37:52886] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:15.869391 2026] [authz_core:error] [pid 493992:tid 494194] [client 66.249.66.37:52886] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:15.916275 2026] [autoindex:error] [pid 493992:tid 494124] [client 52.139.37.240:0] AH01276: Cannot serve directory /home4/littling/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:05:15.924211 2026] [authz_core:error] [pid 491656:tid 491899] [client 74.7.227.8:54904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fvar%2Flib%2Fcloud%2Fdata
[Sun Aug 30 03:05:15.924697 2026] [authz_core:error] [pid 491656:tid 491899] [client 74.7.227.8:54904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fvar%2Flib%2Fcloud%2Fdata
[Sun Aug 30 03:05:15.932118 2026] [security2:error] [pid 493992:tid 494144] [client 158.23.147.79:62532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apPkO2bB9pEqk7z7RJloqgAAAzQ"]
[Sun Aug 30 03:05:15.936993 2026] [security2:error] [pid 493992:tid 494239] [client 20.104.50.220:28724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/pwp-.myluv.php"] [unique_id "apPkO2bB9pEqk7z7RJlorQAAA5M"]
[Sun Aug 30 03:05:15.937997 2026] [security2:error] [pid 493992:tid 494191] [client 20.48.160.90:50651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/dex.php"] [unique_id "apPkO2bB9pEqk7z7RJlorwAAA2M"]
[Sun Aug 30 03:05:15.962336 2026] [autoindex:error] [pid 493992:tid 494123] [client 20.63.219.114:16770] AH01276: Cannot serve directory /home2/nalah/cavendish-club.com.lodestar.media/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:05:15.969005 2026] [security2:error] [pid 493992:tid 494138] [client 20.151.200.44:47304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/h02ugyh.php"] [unique_id "apPkO2bB9pEqk7z7RJlougAAAy4"]
[Sun Aug 30 03:05:15.977746 2026] [security2:error] [pid 493992:tid 494146] [client 20.220.10.235:28657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/log.php"] [unique_id "apPkO2bB9pEqk7z7RJloxAAAAzY"]
[Sun Aug 30 03:05:15.987145 2026] [security2:error] [pid 493992:tid 494153] [client 20.220.10.235:3984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/ssss.php"] [unique_id "apPkO2bB9pEqk7z7RJloyAAAAz0"]
[Sun Aug 30 03:05:15.996536 2026] [security2:error] [pid 493992:tid 494169] [client 52.139.37.240:20088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/ws77.php"] [unique_id "apPkO2bB9pEqk7z7RJloywAAA00"]
[Sun Aug 30 03:05:16.004355 2026] [security2:error] [pid 491656:tid 491881] [client 20.48.251.3:23322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/cloud.php"] [unique_id "apPkPIvX_L6VjdbvkkTbQQAAAvM"]
[Sun Aug 30 03:05:16.031554 2026] [security2:error] [pid 493992:tid 494174] [client 20.104.50.220:27443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/wp-theme.php"] [unique_id "apPkPGbB9pEqk7z7RJlo3AAAA1I"]
[Sun Aug 30 03:05:16.034762 2026] [security2:error] [pid 491656:tid 491809] [client 68.155.159.216:52691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-admin.php"] [unique_id "apPkPIvX_L6VjdbvkkTbTwAAAqs"]
[Sun Aug 30 03:05:16.035225 2026] [security2:error] [pid 493992:tid 494218] [client 20.48.160.90:40010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/simple.php"] [unique_id "apPkPGbB9pEqk7z7RJlo4QAAA34"]
[Sun Aug 30 03:05:16.043720 2026] [security2:error] [pid 491656:tid 491833] [client 20.104.50.220:33321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/py.php"] [unique_id "apPkPIvX_L6VjdbvkkTbVAAAAsM"]
[Sun Aug 30 03:05:16.052716 2026] [security2:error] [pid 493992:tid 494232] [client 20.104.50.220:47085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/json-php.php"] [unique_id "apPkPGbB9pEqk7z7RJlo7AAAA4w"]
[Sun Aug 30 03:05:16.080380 2026] [security2:error] [pid 493992:tid 494145] [client 20.63.219.114:16770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/upgrade/about.php"] [unique_id "apPkPGbB9pEqk7z7RJlpAAAAAzU"]
[Sun Aug 30 03:05:16.080871 2026] [security2:error] [pid 493992:tid 494195] [client 158.23.147.79:62476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apPkPGbB9pEqk7z7RJlpAQAAA2c"]
[Sun Aug 30 03:05:16.084149 2026] [security2:error] [pid 491656:tid 491917] [client 20.104.50.220:42770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/s4d.php"] [unique_id "apPkPIvX_L6VjdbvkkTbZgAAAxc"]
[Sun Aug 30 03:05:16.094003 2026] [security2:error] [pid 493992:tid 494172] [client 20.104.50.220:31930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/5index.php"] [unique_id "apPkPGbB9pEqk7z7RJlpAwAAA1A"]
[Sun Aug 30 03:05:16.108717 2026] [security2:error] [pid 493992:tid 494168] [client 20.104.18.15:13722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/sf.php"] [unique_id "apPkPGbB9pEqk7z7RJlpEgAAA0w"]
[Sun Aug 30 03:05:16.114052 2026] [security2:error] [pid 493992:tid 494160] [client 20.104.18.15:33791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/fling.php"] [unique_id "apPkPGbB9pEqk7z7RJlpGAAAA0Q"]
[Sun Aug 30 03:05:16.118392 2026] [security2:error] [pid 493992:tid 494167] [client 20.220.10.235:28629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/xwpg.php"] [unique_id "apPkPGbB9pEqk7z7RJlpHQAAA0s"]
[Sun Aug 30 03:05:16.118500 2026] [authz_core:error] [pid 493992:tid 494196] [client 216.73.216.128:29761] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:16.118879 2026] [authz_core:error] [pid 493992:tid 494196] [client 216.73.216.128:29761] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:16.141042 2026] [security2:error] [pid 493992:tid 494165] [client 20.104.50.220:5935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/index/function.php"] [unique_id "apPkPGbB9pEqk7z7RJlpMAAAA0k"]
[Sun Aug 30 03:05:16.150592 2026] [security2:error] [pid 493992:tid 494242] [client 20.220.10.235:4043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/zoz.php"] [unique_id "apPkPGbB9pEqk7z7RJlpNgAAA5Y"]
[Sun Aug 30 03:05:16.156286 2026] [security2:error] [pid 493992:tid 494134] [client 34.15.141.119:46002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/site/phpinfo.php"] [unique_id "apPkPGbB9pEqk7z7RJlpPgAAAyo"]
[Sun Aug 30 03:05:16.159711 2026] [security2:error] [pid 493992:tid 494138] [client 20.48.251.3:49993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/adminer-4.7.6-en.php"] [unique_id "apPkPGbB9pEqk7z7RJlpQAAAAy4"]
[Sun Aug 30 03:05:16.164177 2026] [security2:error] [pid 491656:tid 491863] [client 20.48.251.3:64408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/h.php"] [unique_id "apPkPIvX_L6VjdbvkkTbjgAAAuE"]
[Sun Aug 30 03:05:16.167589 2026] [security2:error] [pid 493992:tid 494143] [client 20.48.160.90:40023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/aaa.php"] [unique_id "apPkPGbB9pEqk7z7RJlpQQAAAzM"]
[Sun Aug 30 03:05:16.175844 2026] [security2:error] [pid 493992:tid 494205] [client 20.104.50.220:61641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/herp.php"] [unique_id "apPkPGbB9pEqk7z7RJlpRwAAA3E"]
[Sun Aug 30 03:05:16.184904 2026] [security2:error] [pid 493992:tid 494233] [client 20.48.251.3:52851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/hochladen.form.php"] [unique_id "apPkPGbB9pEqk7z7RJlpUwAAA40"]
[Sun Aug 30 03:05:16.186034 2026] [security2:error] [pid 493992:tid 494233] [client 20.48.160.90:45915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkPGbB9pEqk7z7RJlpVQAAA40"]
[Sun Aug 30 03:05:16.191874 2026] [security2:error] [pid 493992:tid 494238] [client 52.139.37.240:61123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/admin/function.php"] [unique_id "apPkPGbB9pEqk7z7RJlpXQAAA5I"]
[Sun Aug 30 03:05:16.193608 2026] [security2:error] [pid 493992:tid 494122] [client 20.104.18.15:31586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/asdfghj.php"] [unique_id "apPkPGbB9pEqk7z7RJlpYAAAAx4"]
[Sun Aug 30 03:05:16.197521 2026] [security2:error] [pid 493992:tid 494189] [client 20.48.160.90:50591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/inso.php"] [unique_id "apPkPGbB9pEqk7z7RJlpagAAA2E"]
[Sun Aug 30 03:05:16.203233 2026] [security2:error] [pid 493992:tid 494187] [client 20.104.50.220:28679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/locus7shell.php"] [unique_id "apPkPGbB9pEqk7z7RJlpdQAAA18"]
[Sun Aug 30 03:05:16.253476 2026] [security2:error] [pid 493992:tid 494186] [client 20.196.209.81:21131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/wp-cron.php"] [unique_id "apPkPGbB9pEqk7z7RJlpmAAAA14"]
[Sun Aug 30 03:05:16.270278 2026] [security2:error] [pid 493992:tid 494236] [client 20.220.10.235:28625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/sxxb.php"] [unique_id "apPkPGbB9pEqk7z7RJlppAAAA5A"]
[Sun Aug 30 03:05:16.274339 2026] [security2:error] [pid 493992:tid 494221] [client 20.48.251.3:54768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/cloud.php"] [unique_id "apPkPGbB9pEqk7z7RJlpqwAAA4E"]
[Sun Aug 30 03:05:16.281234 2026] [security2:error] [pid 493992:tid 494208] [client 20.220.10.235:4031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/kcs.php"] [unique_id "apPkPGbB9pEqk7z7RJlpsgAAA3Q"]
[Sun Aug 30 03:05:16.286623 2026] [security2:error] [pid 493992:tid 494191] [client 68.155.159.216:59930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apPkPGbB9pEqk7z7RJlptgAAA2M"]
[Sun Aug 30 03:05:16.299836 2026] [security2:error] [pid 493992:tid 494134] [client 20.48.160.90:40014] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-admin/css/colors/modern/"] [unique_id "apPkPGbB9pEqk7z7RJlpwAAAAyo"]
[Sun Aug 30 03:05:16.314390 2026] [security2:error] [pid 493992:tid 494165] [client 20.48.160.90:45903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkPGbB9pEqk7z7RJlp0wAAA0k"]
[Sun Aug 30 03:05:16.343685 2026] [security2:error] [pid 493992:tid 494219] [client 40.83.93.50:18075] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpanel.homedesigner.org"] [uri "/c99.php"] [unique_id "apPkPGbB9pEqk7z7RJlp8wAAA38"]
[Sun Aug 30 03:05:16.361768 2026] [security2:error] [pid 493992:tid 494166] [client 20.48.160.90:50670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/aa.php"] [unique_id "apPkPGbB9pEqk7z7RJlp_wAAA0o"]
[Sun Aug 30 03:05:16.386989 2026] [security2:error] [pid 493992:tid 494176] [client 52.139.37.240:20058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/xx.php"] [unique_id "apPkPGbB9pEqk7z7RJlqDgAAA1Q"]
[Sun Aug 30 03:05:16.408916 2026] [security2:error] [pid 493992:tid 494233] [client 20.220.10.235:27477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/dx.php"] [unique_id "apPkPGbB9pEqk7z7RJlqHwAAA40"]
[Sun Aug 30 03:05:16.419604 2026] [security2:error] [pid 493992:tid 494232] [client 68.155.159.216:59379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-admin/network/index.php"] [unique_id "apPkPGbB9pEqk7z7RJlqJwAAA4w"]
[Sun Aug 30 03:05:16.419672 2026] [security2:error] [pid 493992:tid 494181] [client 20.220.10.235:4065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/tajj.php"] [unique_id "apPkPGbB9pEqk7z7RJlqKQAAA1k"]
[Sun Aug 30 03:05:16.426027 2026] [security2:error] [pid 493992:tid 494166] [client 20.48.251.3:5066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/groceries/index.php"] [unique_id "apPkPGbB9pEqk7z7RJlqLgAAA0o"]
[Sun Aug 30 03:05:16.430047 2026] [security2:error] [pid 493992:tid 494215] [client 20.63.219.114:15597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cavendish-club.com.lodestar.media"] [uri "/wp-content/upgrade/index.php"] [unique_id "apPkPGbB9pEqk7z7RJlqNQAAA3s"]
[Sun Aug 30 03:05:16.430219 2026] [security2:error] [pid 493992:tid 494150] [client 20.48.160.90:45928] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "apPkPGbB9pEqk7z7RJlqNgAAAzo"]
[Sun Aug 30 03:05:16.449565 2026] [security2:error] [pid 491656:tid 491845] [client 20.48.160.90:45871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/ser.php"] [unique_id "apPkPIvX_L6VjdbvkkTb_wAAAs8"]
[Sun Aug 30 03:05:16.464463 2026] [security2:error] [pid 493992:tid 494230] [client 20.104.18.15:43980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/dex.php"] [unique_id "apPkPGbB9pEqk7z7RJlqTgAAA4o"]
[Sun Aug 30 03:05:16.477793 2026] [security2:error] [pid 491656:tid 491807] [client 20.48.251.3:64404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/w.php"] [unique_id "apPkPIvX_L6VjdbvkkTcCwAAAqk"]
[Sun Aug 30 03:05:16.519592 2026] [authz_core:error] [pid 493992:tid 494244] [client 66.249.66.69:35999] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:16.519912 2026] [authz_core:error] [pid 493992:tid 494244] [client 66.249.66.69:35999] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:16.533550 2026] [security2:error] [pid 491656:tid 491918] [client 20.48.160.90:50606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/img.php"] [unique_id "apPkPIvX_L6VjdbvkkTcJQAAAxg"]
[Sun Aug 30 03:05:16.542409 2026] [security2:error] [pid 491656:tid 491899] [client 20.220.10.235:28594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPkPIvX_L6VjdbvkkTcKQAAAwU"]
[Sun Aug 30 03:05:16.543739 2026] [security2:error] [pid 491656:tid 491840] [client 20.48.251.3:51538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/hosty.php"] [unique_id "apPkPIvX_L6VjdbvkkTcKgAAAso"]
[Sun Aug 30 03:05:16.546878 2026] [security2:error] [pid 491656:tid 491799] [client 158.23.147.79:63273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apPkPIvX_L6VjdbvkkTcLAAAAqE"]
[Sun Aug 30 03:05:16.551128 2026] [security2:error] [pid 493992:tid 494152] [client 20.220.10.235:3969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/bge.php"] [unique_id "apPkPGbB9pEqk7z7RJlqjgAAAzw"]
[Sun Aug 30 03:05:16.570220 2026] [security2:error] [pid 493992:tid 494224] [client 20.48.160.90:45879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/shiny.php"] [unique_id "apPkPGbB9pEqk7z7RJlqkwAAA4Q"]
[Sun Aug 30 03:05:16.578893 2026] [security2:error] [pid 493992:tid 494248] [client 52.139.37.240:19812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/wp-content/about.php"] [unique_id "apPkPGbB9pEqk7z7RJlqmgAAA5w"]
[Sun Aug 30 03:05:16.582881 2026] [security2:error] [pid 491656:tid 491873] [client 20.48.160.90:40027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/431.php"] [unique_id "apPkPIvX_L6VjdbvkkTcPQAAAus"]
[Sun Aug 30 03:05:16.593397 2026] [security2:error] [pid 493992:tid 494129] [client 118.189.242.201:54077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "geotravel.am"] [uri "/wp-comments-post.php"] [unique_id "apPkOWbB9pEqk7z7RJlgtgAAAyU"], referer: https://geotravel.am/discover-armenias-hidden-gems-tufenkian-avan-marak-tsapatagh-hotel/comment-page-269967/
[Sun Aug 30 03:05:16.610868 2026] [security2:error] [pid 491656:tid 491896] [client 20.104.49.130:57606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/css.php"] [unique_id "apPkPIvX_L6VjdbvkkTcSAAAAwI"]
[Sun Aug 30 03:05:16.647697 2026] [security2:error] [pid 493992:tid 494161] [client 20.196.209.81:21144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/wp-links-opml.php"] [unique_id "apPkPGbB9pEqk7z7RJlquAAAA0U"]
[Sun Aug 30 03:05:16.674589 2026] [security2:error] [pid 491656:tid 491852] [client 20.220.10.235:28555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/xda.php"] [unique_id "apPkPIvX_L6VjdbvkkTcZgAAAtY"]
[Sun Aug 30 03:05:16.678163 2026] [security2:error] [pid 493992:tid 494248] [client 20.220.10.235:4047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/ssh3ll.php"] [unique_id "apPkPGbB9pEqk7z7RJlqxgAAA5w"]
[Sun Aug 30 03:05:16.689402 2026] [security2:error] [pid 491656:tid 491910] [client 20.48.160.90:50616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/222.php"] [unique_id "apPkPIvX_L6VjdbvkkTcawAAAxA"]
[Sun Aug 30 03:05:16.696345 2026] [security2:error] [pid 491656:tid 491859] [client 20.48.160.90:26680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/goods.php"] [unique_id "apPkPIvX_L6VjdbvkkTccgAAAt0"]
[Sun Aug 30 03:05:16.710954 2026] [security2:error] [pid 491656:tid 491874] [client 158.23.147.79:62563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/simple.php"] [unique_id "apPkPIvX_L6VjdbvkkTcdwAAAuw"]
[Sun Aug 30 03:05:16.712535 2026] [security2:error] [pid 493992:tid 494240] [client 20.48.160.90:45832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/rxr.php"] [unique_id "apPkPGbB9pEqk7z7RJlq1QAAA5Q"]
[Sun Aug 30 03:05:16.721202 2026] [security2:error] [pid 493992:tid 494122] [client 20.151.200.44:47046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/px.php"] [unique_id "apPkPGbB9pEqk7z7RJlq3AAAAx4"]
[Sun Aug 30 03:05:16.759712 2026] [security2:error] [pid 493992:tid 494138] [client 34.15.141.119:46014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/docs/phpinfo.php"] [unique_id "apPkPGbB9pEqk7z7RJlq9AAAAy4"]
[Sun Aug 30 03:05:16.791296 2026] [security2:error] [pid 491656:tid 491813] [client 52.139.37.240:20049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/wp-the.php"] [unique_id "apPkPIvX_L6VjdbvkkTclAAAAq8"]
[Sun Aug 30 03:05:16.806863 2026] [security2:error] [pid 493992:tid 494173] [client 20.220.10.235:4094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/motu.php"] [unique_id "apPkPGbB9pEqk7z7RJlrCAAAA1E"]
[Sun Aug 30 03:05:16.811206 2026] [security2:error] [pid 493992:tid 494191] [client 20.220.10.235:28553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/wp-admin/js/index.php"] [unique_id "apPkPGbB9pEqk7z7RJlrDQAAA2M"]
[Sun Aug 30 03:05:16.815601 2026] [security2:error] [pid 493992:tid 494149] [client 20.48.160.90:50639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/key.php"] [unique_id "apPkPGbB9pEqk7z7RJlrEAAAAzk"]
[Sun Aug 30 03:05:16.829419 2026] [security2:error] [pid 493992:tid 494162] [client 20.48.160.90:45850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/000.php/index.php"] [unique_id "apPkPGbB9pEqk7z7RJlrGQAAA0Y"]
[Sun Aug 30 03:05:16.830821 2026] [security2:error] [pid 493992:tid 494145] [client 4.205.62.107:32004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/css.php"] [unique_id "apPkPGbB9pEqk7z7RJlrHAAAAzU"]
[Sun Aug 30 03:05:16.844123 2026] [security2:error] [pid 491656:tid 491805] [client 20.48.160.90:45866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/csst.php"] [unique_id "apPkPIvX_L6VjdbvkkTcqQAAAqc"]
[Sun Aug 30 03:05:16.855663 2026] [security2:error] [pid 493992:tid 494179] [client 216.73.216.128:38882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPkPGbB9pEqk7z7RJlrKgAAA1c"]
[Sun Aug 30 03:05:16.884567 2026] [security2:error] [pid 493992:tid 494143] [client 20.104.18.15:9094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/revo.php"] [unique_id "apPkPGbB9pEqk7z7RJlrMwAAAzM"]
[Sun Aug 30 03:05:16.937179 2026] [security2:error] [pid 491656:tid 491881] [client 158.23.147.79:63252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-admin/about.php"] [unique_id "apPkPIvX_L6VjdbvkkTczAAAAvM"]
[Sun Aug 30 03:05:16.940250 2026] [security2:error] [pid 491656:tid 491889] [client 20.220.10.235:4088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/wefile.php"] [unique_id "apPkPIvX_L6VjdbvkkTczgAAAvs"]
[Sun Aug 30 03:05:16.942010 2026] [security2:error] [pid 493992:tid 494202] [client 40.83.93.50:18077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/test1.php"] [unique_id "apPkPGbB9pEqk7z7RJlrSAAAA24"]
[Sun Aug 30 03:05:16.947403 2026] [security2:error] [pid 493992:tid 494184] [client 20.220.10.235:28659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/t00l.php"] [unique_id "apPkPGbB9pEqk7z7RJlrTQAAA1w"]
[Sun Aug 30 03:05:16.975905 2026] [security2:error] [pid 491656:tid 491871] [client 20.151.200.44:63594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/kcs.php"] [unique_id "apPkPIvX_L6VjdbvkkTc2wAAAuk"]
[Sun Aug 30 03:05:16.976895 2026] [security2:error] [pid 493992:tid 494194] [client 20.48.160.90:33226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/chosen.php"] [unique_id "apPkPGbB9pEqk7z7RJlrVgAAA2Y"]
[Sun Aug 30 03:05:16.978234 2026] [security2:error] [pid 491656:tid 491895] [client 20.48.160.90:45834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp-includes/blocks/query-title/footer.php"] [unique_id "apPkPIvX_L6VjdbvkkTc3AAAAwE"]
[Sun Aug 30 03:05:16.981240 2026] [security2:error] [pid 491656:tid 491806] [client 20.48.160.90:45870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/Jcrop.php"] [unique_id "apPkPIvX_L6VjdbvkkTc3QAAAqg"]
[Sun Aug 30 03:05:16.984896 2026] [security2:error] [pid 493992:tid 494235] [client 52.139.37.240:60851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/ws81.php"] [unique_id "apPkPGbB9pEqk7z7RJlrWwAAA48"]
[Sun Aug 30 03:05:17.030511 2026] [security2:error] [pid 491656:tid 491826] [client 20.151.200.44:47412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/sf.php"] [unique_id "apPkPYvX_L6VjdbvkkTc7AAAArw"]
[Sun Aug 30 03:05:17.031542 2026] [security2:error] [pid 491656:tid 491809] [client 158.23.147.79:62556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-admin/index.php"] [unique_id "apPkPYvX_L6VjdbvkkTc7QAAAqs"]
[Sun Aug 30 03:05:17.032069 2026] [security2:error] [pid 493992:tid 494123] [client 148.222.185.49:59289] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "148.222.185.49" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "den-enterprises.com"] [uri "/wp-comments-post.php"] [unique_id "apPkPWbB9pEqk7z7RJlrfgAAAx8"], referer: http://den-enterprises.com/2020/06/27/hello-world/#comment-10226
[Sun Aug 30 03:05:17.032146 2026] [security2:error] [pid 493992:tid 494123] [client 148.222.185.49:59289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "den-enterprises.com"] [uri "/wp-comments-post.php"] [unique_id "apPkPWbB9pEqk7z7RJlrfgAAAx8"], referer: http://den-enterprises.com/2020/06/27/hello-world/#comment-10226
[Sun Aug 30 03:05:17.037742 2026] [security2:error] [pid 493992:tid 494163] [client 20.196.209.81:21175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/wp-load.php"] [unique_id "apPkPWbB9pEqk7z7RJlrgAAAA0c"]
[Sun Aug 30 03:05:17.048621 2026] [security2:error] [pid 493992:tid 494136] [client 20.151.200.44:47016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/zoz.php"] [unique_id "apPkPWbB9pEqk7z7RJlrigAAAyw"]
[Sun Aug 30 03:05:17.087349 2026] [security2:error] [pid 493992:tid 494151] [client 20.220.10.235:3974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/Contrller.php"] [unique_id "apPkPWbB9pEqk7z7RJlrnAAAAzs"]
[Sun Aug 30 03:05:17.089480 2026] [security2:error] [pid 493992:tid 494148] [client 20.220.10.235:28616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/ls.php"] [unique_id "apPkPWbB9pEqk7z7RJlrnwAAAzg"]
[Sun Aug 30 03:05:17.123394 2026] [security2:error] [pid 493992:tid 494138] [client 20.48.160.90:45881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/35iDq8NAjLu.php"] [unique_id "apPkPWbB9pEqk7z7RJlrvQAAAy4"]
[Sun Aug 30 03:05:17.126563 2026] [security2:error] [pid 493992:tid 494185] [client 20.48.160.90:33257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/file1221.php"] [unique_id "apPkPWbB9pEqk7z7RJlrwgAAA10"]
[Sun Aug 30 03:05:17.127355 2026] [security2:error] [pid 493992:tid 494177] [client 20.48.160.90:45877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp-content/uploads/indoex.php"] [unique_id "apPkPWbB9pEqk7z7RJlrwwAAA1U"]
[Sun Aug 30 03:05:17.132076 2026] [authz_core:error] [pid 493992:tid 494178] [client 66.249.66.199:64433] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:17.132546 2026] [authz_core:error] [pid 493992:tid 494178] [client 66.249.66.199:64433] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:17.133806 2026] [security2:error] [pid 493992:tid 494131] [client 20.104.49.130:52446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/xmini4.php"] [unique_id "apPkPWbB9pEqk7z7RJlryQAAAyc"]
[Sun Aug 30 03:05:17.157139 2026] [security2:error] [pid 493992:tid 494208] [client 20.48.251.3:44191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/asdf.php"] [unique_id "apPkPWbB9pEqk7z7RJlr3AAAA3Q"]
[Sun Aug 30 03:05:17.159079 2026] [security2:error] [pid 493992:tid 494161] [client 20.104.50.220:27401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/admin.php/admin.php"] [unique_id "apPkPWbB9pEqk7z7RJlr4gAAA0U"]
[Sun Aug 30 03:05:17.168163 2026] [security2:error] [pid 493992:tid 494232] [client 68.155.159.216:54727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apPkPWbB9pEqk7z7RJlr9gAAA4w"]
[Sun Aug 30 03:05:17.177063 2026] [security2:error] [pid 493992:tid 494204] [client 52.139.37.240:19808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/a1.php"] [unique_id "apPkPWbB9pEqk7z7RJlsAAAAA3A"]
[Sun Aug 30 03:05:17.182558 2026] [security2:error] [pid 493992:tid 494246] [client 20.104.50.220:46620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/0x0.php"] [unique_id "apPkPWbB9pEqk7z7RJlsBQAAA5o"]
[Sun Aug 30 03:05:17.197134 2026] [security2:error] [pid 493992:tid 494181] [client 20.104.50.220:33341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/ray.php"] [unique_id "apPkPWbB9pEqk7z7RJlsGAAAA1k"]
[Sun Aug 30 03:05:17.223464 2026] [security2:error] [pid 493992:tid 494172] [client 20.104.50.220:51595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/slot.php"] [unique_id "apPkPWbB9pEqk7z7RJlsOwAAA1A"]
[Sun Aug 30 03:05:17.233817 2026] [security2:error] [pid 493992:tid 494158] [client 20.220.10.235:4007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/file66.php"] [unique_id "apPkPWbB9pEqk7z7RJlsQgAAA0I"]
[Sun Aug 30 03:05:17.244922 2026] [security2:error] [pid 493992:tid 494126] [client 20.104.18.15:33758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/btyuio.php"] [unique_id "apPkPWbB9pEqk7z7RJlsSAAAAyI"]
[Sun Aug 30 03:05:17.245847 2026] [security2:error] [pid 493992:tid 494127] [client 20.220.10.235:28655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/css/000.php"] [unique_id "apPkPWbB9pEqk7z7RJlsSgAAAyM"]
[Sun Aug 30 03:05:17.252013 2026] [security2:error] [pid 493992:tid 494195] [client 20.104.50.220:32553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/6index.php"] [unique_id "apPkPWbB9pEqk7z7RJlsVQAAA2c"]
[Sun Aug 30 03:05:17.253431 2026] [security2:error] [pid 493992:tid 494150] [client 20.48.160.90:40062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/btx25.php"] [unique_id "apPkPWbB9pEqk7z7RJlsVwAAAzo"]
[Sun Aug 30 03:05:17.259838 2026] [security2:error] [pid 493992:tid 494148] [client 20.48.160.90:45855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPkPWbB9pEqk7z7RJlsXgAAAzg"]
[Sun Aug 30 03:05:17.269695 2026] [security2:error] [pid 493992:tid 494183] [client 158.23.147.79:63241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apPkPWbB9pEqk7z7RJlsaQAAA1s"]
[Sun Aug 30 03:05:17.277829 2026] [authz_core:error] [pid 493992:tid 494158] [client 66.249.66.70:37386] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:17.278125 2026] [authz_core:error] [pid 493992:tid 494158] [client 66.249.66.70:37386] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:17.279700 2026] [security2:error] [pid 493992:tid 494128] [client 20.104.50.220:6096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/uploads/autoload_classmap.php"] [unique_id "apPkPWbB9pEqk7z7RJlsdgAAAyQ"]
[Sun Aug 30 03:05:17.300356 2026] [security2:error] [pid 493992:tid 494139] [client 20.48.251.3:55454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/phpi.php"] [unique_id "apPkPWbB9pEqk7z7RJlsiAAAAy8"]
[Sun Aug 30 03:05:17.304905 2026] [security2:error] [pid 493992:tid 494240] [client 20.48.251.3:7034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/bootstrap.php"] [unique_id "apPkPWbB9pEqk7z7RJlsjgAAA5Q"]
[Sun Aug 30 03:05:17.328846 2026] [security2:error] [pid 493992:tid 494131] [client 20.104.50.220:61686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/nptice.php"] [unique_id "apPkPWbB9pEqk7z7RJlsswAAAyc"]
[Sun Aug 30 03:05:17.330508 2026] [security2:error] [pid 493992:tid 494174] [client 20.104.18.15:31719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/dragonshell.php"] [unique_id "apPkPWbB9pEqk7z7RJlstQAAA1I"]
[Sun Aug 30 03:05:17.340334 2026] [security2:error] [pid 493992:tid 494225] [client 20.104.18.15:13736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/k.php"] [unique_id "apPkPWbB9pEqk7z7RJlsvwAAA4U"]
[Sun Aug 30 03:05:17.343382 2026] [security2:error] [pid 493992:tid 494210] [client 20.104.50.220:62811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/cyberwarrior.php"] [unique_id "apPkPWbB9pEqk7z7RJlswgAAA3Y"]
[Sun Aug 30 03:05:17.350906 2026] [security2:error] [pid 493992:tid 494126] [client 20.48.160.90:50623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/nox.php"] [unique_id "apPkPWbB9pEqk7z7RJlsxAAAAyI"]
[Sun Aug 30 03:05:17.362220 2026] [security2:error] [pid 493992:tid 494170] [client 20.220.10.235:3977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/blnux.php"] [unique_id "apPkPWbB9pEqk7z7RJlszgAAA04"]
[Sun Aug 30 03:05:17.365142 2026] [security2:error] [pid 493992:tid 494235] [client 34.15.141.119:46026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/wp-admin/phpinfo.php"] [unique_id "apPkPWbB9pEqk7z7RJls0QAAA48"]
[Sun Aug 30 03:05:17.373784 2026] [security2:error] [pid 493992:tid 494249] [client 20.48.251.3:52819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/debuggen.php"] [unique_id "apPkPWbB9pEqk7z7RJls1wAAA50"]
[Sun Aug 30 03:05:17.377162 2026] [security2:error] [pid 493992:tid 494205] [client 20.220.10.235:28607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/cy.php"] [unique_id "apPkPWbB9pEqk7z7RJls3AAAA3E"]
[Sun Aug 30 03:05:17.385918 2026] [security2:error] [pid 493992:tid 494165] [client 52.139.37.240:63134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/ca5.php"] [unique_id "apPkPWbB9pEqk7z7RJls4QAAA0k"]
[Sun Aug 30 03:05:17.385972 2026] [security2:error] [pid 493992:tid 494133] [client 20.48.160.90:39955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/radio.php"] [unique_id "apPkPWbB9pEqk7z7RJls4AAAAyk"]
[Sun Aug 30 03:05:17.393493 2026] [security2:error] [pid 493992:tid 494183] [client 20.48.160.90:40003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/haxor.php"] [unique_id "apPkPWbB9pEqk7z7RJls6QAAA1s"]
[Sun Aug 30 03:05:17.422787 2026] [security2:error] [pid 493992:tid 494196] [client 68.155.159.216:59922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/content.php"] [unique_id "apPkPWbB9pEqk7z7RJltBQAAA2g"]
[Sun Aug 30 03:05:17.429519 2026] [security2:error] [pid 493992:tid 494156] [client 20.196.209.81:21155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/wp-settings.php"] [unique_id "apPkPWbB9pEqk7z7RJltCwAAA0A"]
[Sun Aug 30 03:05:17.444672 2026] [security2:error] [pid 493992:tid 494141] [client 40.83.93.50:18111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/data.php"] [unique_id "apPkPWbB9pEqk7z7RJltFQAAAzE"]
[Sun Aug 30 03:05:17.452116 2026] [security2:error] [pid 493992:tid 494233] [client 20.104.50.220:28676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wihp1.php"] [unique_id "apPkPWbB9pEqk7z7RJltGgAAA40"]
[Sun Aug 30 03:05:17.461468 2026] [security2:error] [pid 493992:tid 494124] [client 20.48.251.3:54804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/asdf.php"] [unique_id "apPkPWbB9pEqk7z7RJltIgAAAyA"]
[Sun Aug 30 03:05:17.497098 2026] [security2:error] [pid 493992:tid 494184] [client 216.73.216.128:12920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPkPWbB9pEqk7z7RJltPgAAA1w"]
[Sun Aug 30 03:05:17.497352 2026] [security2:error] [pid 493992:tid 494206] [client 158.23.147.79:62590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPkPWbB9pEqk7z7RJltPwAAA3I"]
[Sun Aug 30 03:05:17.499027 2026] [security2:error] [pid 493992:tid 494204] [client 20.220.10.235:4025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/attack.php"] [unique_id "apPkPWbB9pEqk7z7RJltQAAAA3A"]
[Sun Aug 30 03:05:17.505457 2026] [security2:error] [pid 493992:tid 494181] [client 20.220.10.235:28646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/admin.php/pindex.php"] [unique_id "apPkPWbB9pEqk7z7RJltRgAAA1k"]
[Sun Aug 30 03:05:17.508862 2026] [security2:error] [pid 493992:tid 494144] [client 20.151.200.44:47389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/4e.php"] [unique_id "apPkPWbB9pEqk7z7RJltSgAAAzQ"]
[Sun Aug 30 03:05:17.508886 2026] [security2:error] [pid 493992:tid 494169] [client 20.48.160.90:50673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/akismet.php"] [unique_id "apPkPWbB9pEqk7z7RJltSwAAA00"]
[Sun Aug 30 03:05:17.515157 2026] [security2:error] [pid 493992:tid 494128] [client 20.48.160.90:40059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/dex.php"] [unique_id "apPkPWbB9pEqk7z7RJltUAAAAyQ"]
[Sun Aug 30 03:05:17.529405 2026] [security2:error] [pid 493992:tid 494219] [client 20.48.160.90:45911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/google.php"] [unique_id "apPkPWbB9pEqk7z7RJltYQAAA38"]
[Sun Aug 30 03:05:17.541727 2026] [security2:error] [pid 493992:tid 494177] [client 68.155.159.216:52835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apPkPWbB9pEqk7z7RJltawAAA1U"]
[Sun Aug 30 03:05:17.579431 2026] [security2:error] [pid 493992:tid 494191] [client 52.139.37.240:63485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/install.php"] [unique_id "apPkPWbB9pEqk7z7RJltgQAAA2M"]
[Sun Aug 30 03:05:17.640008 2026] [security2:error] [pid 493992:tid 494133] [client 20.220.10.235:28562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/admin.php/csv.php"] [unique_id "apPkPWbB9pEqk7z7RJltoAAAAyk"]
[Sun Aug 30 03:05:17.643584 2026] [security2:error] [pid 493992:tid 494192] [client 20.220.10.235:4050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/wk/index.php"] [unique_id "apPkPWbB9pEqk7z7RJltqQAAA2Q"]
[Sun Aug 30 03:05:17.645049 2026] [security2:error] [pid 493992:tid 494172] [client 20.48.160.90:45932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/giodywky.php"] [unique_id "apPkPWbB9pEqk7z7RJltqwAAA1A"]
[Sun Aug 30 03:05:17.645885 2026] [security2:error] [pid 493992:tid 494239] [client 20.104.18.15:43290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/inso.php"] [unique_id "apPkPWbB9pEqk7z7RJltrAAAA5M"]
[Sun Aug 30 03:05:17.661210 2026] [security2:error] [pid 493992:tid 494150] [client 20.48.160.90:45887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "apPkPWbB9pEqk7z7RJltsQAAAzo"]
[Sun Aug 30 03:05:17.661621 2026] [security2:error] [pid 493992:tid 494191] [client 20.48.160.90:50603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/ajax.php"] [unique_id "apPkPWbB9pEqk7z7RJltsgAAA2M"]
[Sun Aug 30 03:05:17.727986 2026] [security2:error] [pid 493992:tid 494236] [client 20.48.251.3:44398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/konfig.php"] [unique_id "apPkPWbB9pEqk7z7RJlt0gAAA5A"]
[Sun Aug 30 03:05:17.772508 2026] [security2:error] [pid 493992:tid 494167] [client 20.220.10.235:4090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/dehnl.php"] [unique_id "apPkPWbB9pEqk7z7RJlt9AAAA0s"]
[Sun Aug 30 03:05:17.775883 2026] [security2:error] [pid 493992:tid 494141] [client 20.48.160.90:40063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-kz.php"] [unique_id "apPkPWbB9pEqk7z7RJlt9wAAAzE"]
[Sun Aug 30 03:05:17.787772 2026] [security2:error] [pid 493992:tid 494178] [client 20.220.10.235:28584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/admin.php/700.php"] [unique_id "apPkPWbB9pEqk7z7RJlt_wAAA1Y"]
[Sun Aug 30 03:05:17.794408 2026] [security2:error] [pid 493992:tid 494162] [client 20.48.160.90:40014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/robots.php"] [unique_id "apPkPWbB9pEqk7z7RJluAwAAA0Y"]
[Sun Aug 30 03:05:17.824760 2026] [security2:error] [pid 493992:tid 494122] [client 20.48.160.90:50657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/atomlib.php"] [unique_id "apPkPWbB9pEqk7z7RJluFQAAAx4"]
[Sun Aug 30 03:05:17.837497 2026] [security2:error] [pid 493992:tid 494173] [client 20.196.209.81:16866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/themes/wp-signup.php"] [unique_id "apPkPWbB9pEqk7z7RJluHAAAA1E"]
[Sun Aug 30 03:05:17.855890 2026] [security2:error] [pid 493992:tid 494234] [client 20.48.251.3:34608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/pass4.php"] [unique_id "apPkPWbB9pEqk7z7RJluIwAAA44"]
[Sun Aug 30 03:05:17.860442 2026] [autoindex:error] [pid 491656:tid 491908] [client 52.139.37.240:19799] AH01276: Cannot serve directory /home4/littling/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:05:17.863452 2026] [security2:error] [pid 491656:tid 491685] [remote 20.237.251.56:14230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.251.237.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "truclearpools.com"] [uri "/wp-login.php"] [unique_id "apPkPYvX_L6VjdbvkkTd-gADDBg"]
[Sun Aug 30 03:05:17.902531 2026] [security2:error] [pid 491656:tid 491915] [client 20.220.10.235:4068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/png.php"] [unique_id "apPkPYvX_L6VjdbvkkTeCgAAAxU"]
[Sun Aug 30 03:05:17.922552 2026] [security2:error] [pid 493992:tid 494158] [client 20.48.160.90:45869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-includes/ID3/getid.php"] [unique_id "apPkPWbB9pEqk7z7RJluVAAAA0I"]
[Sun Aug 30 03:05:17.923747 2026] [security2:error] [pid 491656:tid 491880] [client 52.139.37.240:19799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/wp-signin.php"] [unique_id "apPkPYvX_L6VjdbvkkTeEAAAAvI"]
[Sun Aug 30 03:05:17.937150 2026] [security2:error] [pid 493992:tid 494244] [client 20.220.10.235:28565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/admin.php/007x.php"] [unique_id "apPkPWbB9pEqk7z7RJluVQAAA5g"]
[Sun Aug 30 03:05:17.940636 2026] [security2:error] [pid 493992:tid 494145] [client 158.23.147.79:63281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/about.php"] [unique_id "apPkPWbB9pEqk7z7RJluWQAAAzU"]
[Sun Aug 30 03:05:17.942323 2026] [security2:error] [pid 493992:tid 494127] [client 20.48.160.90:45910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp-content/plugins/ccx/index.php"] [unique_id "apPkPWbB9pEqk7z7RJluWwAAAyM"]
[Sun Aug 30 03:05:17.968223 2026] [security2:error] [pid 493992:tid 494183] [client 34.15.141.119:46028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/administrator/phpinfo.php"] [unique_id "apPkPWbB9pEqk7z7RJluaAAAA1s"]
[Sun Aug 30 03:05:17.978492 2026] [security2:error] [pid 493992:tid 494184] [client 20.48.160.90:50630] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "wristbandsnow.com"] [uri "/1.php"] [unique_id "apPkPWbB9pEqk7z7RJlubwAAA1w"]
[Sun Aug 30 03:05:17.978587 2026] [security2:error] [pid 493992:tid 494184] [client 20.48.160.90:50630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/1.php"] [unique_id "apPkPWbB9pEqk7z7RJlubwAAA1w"]
[Sun Aug 30 03:05:18.032160 2026] [security2:error] [pid 491656:tid 491886] [client 20.220.10.235:3988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/txets.php"] [unique_id "apPkPovX_L6VjdbvkkTeMQAAAvg"]
[Sun Aug 30 03:05:18.038744 2026] [security2:error] [pid 493992:tid 494202] [client 20.104.18.15:9031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/birrs.php"] [unique_id "apPkPmbB9pEqk7z7RJlukAAAA24"]
[Sun Aug 30 03:05:18.044759 2026] [security2:error] [pid 493992:tid 494183] [client 158.23.147.79:40926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apPkPmbB9pEqk7z7RJlulQAAA1s"]
[Sun Aug 30 03:05:18.054076 2026] [security2:error] [pid 491656:tid 491687] [remote 20.237.251.56:14230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.251.237.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "truclearpools.com"] [uri "/wp-login.php"] [unique_id "apPkPovX_L6VjdbvkkTeNwACvRo"], referer: https://truclearpools.com/wp-login.php
[Sun Aug 30 03:05:18.066401 2026] [security2:error] [pid 493992:tid 494155] [client 40.83.93.50:9077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/classwithtostring.php"] [unique_id "apPkPmbB9pEqk7z7RJluqgAAAz8"]
[Sun Aug 30 03:05:18.084215 2026] [security2:error] [pid 491656:tid 491906] [client 20.220.10.235:28645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/admin.php/heex.php"] [unique_id "apPkPovX_L6VjdbvkkTeSQAAAww"]
[Sun Aug 30 03:05:18.104715 2026] [security2:error] [pid 493992:tid 494220] [client 158.23.147.79:62559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apPkPmbB9pEqk7z7RJluwQAAA4A"]
[Sun Aug 30 03:05:18.106824 2026] [security2:error] [pid 493992:tid 494247] [client 20.48.160.90:40038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/session.php"] [unique_id "apPkPmbB9pEqk7z7RJluxAAAA5s"]
[Sun Aug 30 03:05:18.107138 2026] [security2:error] [pid 493992:tid 494130] [client 20.48.160.90:45892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp-admin/css/colors/maro.php"] [unique_id "apPkPmbB9pEqk7z7RJluxQAAAyY"]
[Sun Aug 30 03:05:18.116160 2026] [security2:error] [pid 493992:tid 494216] [client 52.139.37.240:61127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/Ov-Simple1.php"] [unique_id "apPkPmbB9pEqk7z7RJluzQAAA3w"]
[Sun Aug 30 03:05:18.125589 2026] [security2:error] [pid 493992:tid 494215] [client 20.48.160.90:50592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/samll.php"] [unique_id "apPkPmbB9pEqk7z7RJlu0QAAA3s"]
[Sun Aug 30 03:05:18.155135 2026] [security2:error] [pid 493992:tid 494178] [client 158.23.147.79:63898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkPmbB9pEqk7z7RJlu8QAAA1Y"]
[Sun Aug 30 03:05:18.224703 2026] [security2:error] [pid 493992:tid 494143] [client 216.73.216.128:38291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPkPmbB9pEqk7z7RJlvMAAAAzM"]
[Sun Aug 30 03:05:18.235156 2026] [security2:error] [pid 493992:tid 494241] [client 20.196.209.81:16886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/updraft/about.php"] [unique_id "apPkPmbB9pEqk7z7RJlvOAAAA5U"]
[Sun Aug 30 03:05:18.237288 2026] [security2:error] [pid 493992:tid 494153] [client 20.48.160.90:40024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/eagle.php"] [unique_id "apPkPmbB9pEqk7z7RJlvOwAAAz0"]
[Sun Aug 30 03:05:18.239032 2026] [security2:error] [pid 493992:tid 494156] [client 158.23.147.79:63246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apPkPmbB9pEqk7z7RJlvPQAAA0A"]
[Sun Aug 30 03:05:18.239422 2026] [security2:error] [pid 493992:tid 494145] [client 20.48.160.90:45876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp-admin/css/colors/coffee/marijuana.php"] [unique_id "apPkPmbB9pEqk7z7RJlvPgAAAzU"]
[Sun Aug 30 03:05:18.240929 2026] [security2:error] [pid 493992:tid 494223] [client 20.220.10.235:4071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/wp-login.php"] [unique_id "apPkPmbB9pEqk7z7RJlvQAAAA4M"]
[Sun Aug 30 03:05:18.276194 2026] [security2:error] [pid 493992:tid 494240] [client 20.48.160.90:50684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/she11.php"] [unique_id "apPkPmbB9pEqk7z7RJlvaQAAA5Q"]
[Sun Aug 30 03:05:18.276546 2026] [security2:error] [pid 493992:tid 494164] [client 68.155.159.216:52696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/lock.php"] [unique_id "apPkPmbB9pEqk7z7RJlvagAAA0g"]
[Sun Aug 30 03:05:18.286164 2026] [security2:error] [pid 493992:tid 494165] [client 20.220.10.235:28623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/tf.php"] [unique_id "apPkPmbB9pEqk7z7RJlveAAAA0k"]
[Sun Aug 30 03:05:18.289148 2026] [security2:error] [pid 493992:tid 494130] [client 158.23.147.79:63906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkPmbB9pEqk7z7RJlvewAAAyY"]
[Sun Aug 30 03:05:18.297225 2026] [security2:error] [pid 493992:tid 494222] [client 20.104.50.220:27434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/simple.php"] [unique_id "apPkPmbB9pEqk7z7RJlvggAAA4I"]
[Sun Aug 30 03:05:18.308968 2026] [security2:error] [pid 493992:tid 494163] [client 52.139.37.240:19792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/ftde.php"] [unique_id "apPkPmbB9pEqk7z7RJlvmQAAA0c"]
[Sun Aug 30 03:05:18.312311 2026] [security2:error] [pid 493992:tid 494212] [client 20.104.50.220:47051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/0z.php"] [unique_id "apPkPmbB9pEqk7z7RJlvnAAAA3g"]
[Sun Aug 30 03:05:18.313804 2026] [security2:error] [pid 493992:tid 494179] [client 20.48.251.3:23436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apPkPmbB9pEqk7z7RJlvnQAAA1c"]
[Sun Aug 30 03:05:18.331341 2026] [authz_core:error] [pid 493992:tid 494148] [client 216.73.216.128:29761] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:18.331629 2026] [authz_core:error] [pid 493992:tid 494148] [client 216.73.216.128:29761] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:18.334192 2026] [security2:error] [pid 493992:tid 494172] [client 20.104.50.220:33568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/Q2-.php"] [unique_id "apPkPmbB9pEqk7z7RJlvtQAAA1A"]
[Sun Aug 30 03:05:18.369546 2026] [security2:error] [pid 493992:tid 494232] [client 20.220.10.235:4093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/wp-access.php"] [unique_id "apPkPmbB9pEqk7z7RJlvwQAAA4w"]
[Sun Aug 30 03:05:18.371843 2026] [security2:error] [pid 493992:tid 494175] [client 20.48.160.90:40029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp-admin/css/colors/coffee/mari.php"] [unique_id "apPkPmbB9pEqk7z7RJlvxgAAA1M"]
[Sun Aug 30 03:05:18.372623 2026] [security2:error] [pid 493992:tid 494208] [client 20.48.160.90:45856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/up-kon.php"] [unique_id "apPkPmbB9pEqk7z7RJlvxwAAA3Q"]
[Sun Aug 30 03:05:18.375717 2026] [security2:error] [pid 493992:tid 494212] [client 20.104.50.220:51638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/sad.php"] [unique_id "apPkPmbB9pEqk7z7RJlvygAAA3g"]
[Sun Aug 30 03:05:18.402956 2026] [security2:error] [pid 493992:tid 494165] [client 158.23.147.79:63989] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-includes/blocks/post-excerpt/alfa-rex.PHP"] [unique_id "apPkPmbB9pEqk7z7RJlv2wAAA0k"]
[Sun Aug 30 03:05:18.416613 2026] [security2:error] [pid 493992:tid 494219] [client 20.104.50.220:5520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-includes/style-engine/about.php"] [unique_id "apPkPmbB9pEqk7z7RJlv5wAAA38"]
[Sun Aug 30 03:05:18.421434 2026] [security2:error] [pid 493992:tid 494168] [client 20.104.50.220:31809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/7index.php"] [unique_id "apPkPmbB9pEqk7z7RJlv6gAAA0w"]
[Sun Aug 30 03:05:18.429926 2026] [security2:error] [pid 493992:tid 494192] [client 20.220.10.235:28654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/update/da222.php"] [unique_id "apPkPmbB9pEqk7z7RJlv8gAAA2Q"]
[Sun Aug 30 03:05:18.446843 2026] [security2:error] [pid 493992:tid 494149] [client 20.48.251.3:55463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "apPkPmbB9pEqk7z7RJlv-gAAAzk"]
[Sun Aug 30 03:05:18.464249 2026] [security2:error] [pid 493992:tid 494198] [client 20.48.251.3:7414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/333.php"] [unique_id "apPkPmbB9pEqk7z7RJlwBwAAA2o"]
[Sun Aug 30 03:05:18.467039 2026] [security2:error] [pid 493992:tid 494165] [client 20.104.50.220:61989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/tuyul.php"] [unique_id "apPkPmbB9pEqk7z7RJlwCwAAA0k"]
[Sun Aug 30 03:05:18.471449 2026] [security2:error] [pid 493992:tid 494145] [client 20.48.160.90:50655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/kerang.php"] [unique_id "apPkPmbB9pEqk7z7RJlwDwAAAzU"]
[Sun Aug 30 03:05:18.479265 2026] [security2:error] [pid 493992:tid 494249] [client 20.104.50.220:62795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/ernebypass.php"] [unique_id "apPkPmbB9pEqk7z7RJlwFQAAA50"]
[Sun Aug 30 03:05:18.489252 2026] [security2:error] [pid 493992:tid 494174] [client 20.104.18.15:32965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/dehnl.php"] [unique_id "apPkPmbB9pEqk7z7RJlwGAAAA1I"]
[Sun Aug 30 03:05:18.499184 2026] [security2:error] [pid 493992:tid 494207] [client 20.220.10.235:3991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/wp-content/admin.php"] [unique_id "apPkPmbB9pEqk7z7RJlwHwAAA3M"]
[Sun Aug 30 03:05:18.500897 2026] [security2:error] [pid 493992:tid 494161] [client 20.104.18.15:31618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/wp-safe.php"] [unique_id "apPkPmbB9pEqk7z7RJlwIQAAA0U"]
[Sun Aug 30 03:05:18.503636 2026] [security2:error] [pid 493992:tid 494157] [client 52.139.37.240:19782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/hplfuns.php"] [unique_id "apPkPmbB9pEqk7z7RJlwJAAAA0E"]
[Sun Aug 30 03:05:18.504284 2026] [security2:error] [pid 493992:tid 494136] [client 20.48.160.90:45878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp-includes/images/crystal/option.php"] [unique_id "apPkPmbB9pEqk7z7RJlwJQAAAyw"]
[Sun Aug 30 03:05:18.505611 2026] [security2:error] [pid 491656:tid 491896] [client 20.48.160.90:39974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/tinny.php"] [unique_id "apPkPovX_L6VjdbvkkTe-AAAAwI"]
[Sun Aug 30 03:05:18.520839 2026] [security2:error] [pid 493992:tid 494150] [client 20.104.18.15:13715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/82.php"] [unique_id "apPkPmbB9pEqk7z7RJlwOAAAAzo"]
[Sun Aug 30 03:05:18.528823 2026] [security2:error] [pid 493992:tid 494181] [client 20.48.251.3:59272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/pouhg.php"] [unique_id "apPkPmbB9pEqk7z7RJlwQgAAA1k"]
[Sun Aug 30 03:05:18.559912 2026] [security2:error] [pid 493992:tid 494152] [client 158.23.147.79:62574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/themes.php"] [unique_id "apPkPmbB9pEqk7z7RJlwVwAAAzw"]
[Sun Aug 30 03:05:18.567977 2026] [security2:error] [pid 491656:tid 491893] [client 158.23.147.79:63903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apPkPovX_L6VjdbvkkTfFQAAAv8"]
[Sun Aug 30 03:05:18.572434 2026] [security2:error] [pid 493992:tid 494150] [client 20.220.10.235:28569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/qi.php"] [unique_id "apPkPmbB9pEqk7z7RJlwXQAAAzo"]
[Sun Aug 30 03:05:18.574129 2026] [security2:error] [pid 493992:tid 494213] [client 34.15.141.119:46044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/core/phpinfo.php"] [unique_id "apPkPmbB9pEqk7z7RJlwYQAAA3k"]
[Sun Aug 30 03:05:18.589741 2026] [security2:error] [pid 491656:tid 491863] [client 20.104.50.220:62810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-blog.php"] [unique_id "apPkPovX_L6VjdbvkkTfHgAAAuE"]
[Sun Aug 30 03:05:18.604254 2026] [security2:error] [pid 491656:tid 491841] [client 20.104.49.130:52529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.katbacon.com"] [uri "/as.php"] [unique_id "apPkPovX_L6VjdbvkkTfIgAAAss"]
[Sun Aug 30 03:05:18.626509 2026] [security2:error] [pid 493992:tid 494193] [client 40.83.93.50:18060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/en.php"] [unique_id "apPkPmbB9pEqk7z7RJlwewAAA2U"]
[Sun Aug 30 03:05:18.629040 2026] [security2:error] [pid 493992:tid 494210] [client 20.196.209.81:9157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/upgrade-temp-backup/min.php"] [unique_id "apPkPmbB9pEqk7z7RJlwfwAAA3Y"]
[Sun Aug 30 03:05:18.631948 2026] [security2:error] [pid 491656:tid 491862] [client 68.155.159.216:54081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPkPovX_L6VjdbvkkTfNQAAAuA"]
[Sun Aug 30 03:05:18.635984 2026] [security2:error] [pid 493992:tid 494186] [client 20.48.160.90:45934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp-includes/pomo/xxx.php"] [unique_id "apPkPmbB9pEqk7z7RJlwiQAAA14"]
[Sun Aug 30 03:05:18.638407 2026] [security2:error] [pid 493992:tid 494157] [client 20.48.160.90:45849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp-easy.php"] [unique_id "apPkPmbB9pEqk7z7RJlwjQAAA0E"]
[Sun Aug 30 03:05:18.642487 2026] [security2:error] [pid 493992:tid 494133] [client 20.220.10.235:4091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/log.php"] [unique_id "apPkPmbB9pEqk7z7RJlwlAAAAyk"]
[Sun Aug 30 03:05:18.649160 2026] [authz_core:error] [pid 493992:tid 494185] [client 66.249.66.194:58810] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:18.649438 2026] [authz_core:error] [pid 493992:tid 494185] [client 66.249.66.194:58810] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:18.667794 2026] [security2:error] [pid 493992:tid 494156] [client 20.48.160.90:50646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/m.php"] [unique_id "apPkPmbB9pEqk7z7RJlwpAAAA0A"]
[Sun Aug 30 03:05:18.669941 2026] [security2:error] [pid 491656:tid 491849] [client 158.23.147.79:63985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apPkPovX_L6VjdbvkkTfQwAAAtM"]
[Sun Aug 30 03:05:18.695081 2026] [security2:error] [pid 491656:tid 491911] [client 52.139.37.240:61147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/log.php"] [unique_id "apPkPovX_L6VjdbvkkTfUQAAAxE"]
[Sun Aug 30 03:05:18.710545 2026] [security2:error] [pid 493992:tid 494174] [client 20.220.10.235:28554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/px.php"] [unique_id "apPkPmbB9pEqk7z7RJlwtQAAA1I"]
[Sun Aug 30 03:05:18.730296 2026] [security2:error] [pid 493992:tid 494152] [client 68.155.159.216:52758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/.well-knownold/index.php"] [unique_id "apPkPmbB9pEqk7z7RJlwwwAAAzw"]
[Sun Aug 30 03:05:18.763795 2026] [security2:error] [pid 493992:tid 494151] [client 93.123.109.165:6934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulgarrigan.com"] [uri "/wp-login.php"] [unique_id "apPkPmbB9pEqk7z7RJlwuwAAAzs"]
[Sun Aug 30 03:05:18.766413 2026] [security2:error] [pid 493992:tid 494232] [client 20.48.160.90:45947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/d7.php"] [unique_id "apPkPmbB9pEqk7z7RJlw2gAAA4w"]
[Sun Aug 30 03:05:18.766500 2026] [security2:error] [pid 493992:tid 494179] [client 158.23.147.79:63959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/simple.php"] [unique_id "apPkPmbB9pEqk7z7RJlw2wAAA1c"]
[Sun Aug 30 03:05:18.767972 2026] [security2:error] [pid 493992:tid 494131] [client 20.48.160.90:45947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/650.php"] [unique_id "apPkPmbB9pEqk7z7RJlw3gAAAyc"]
[Sun Aug 30 03:05:18.771525 2026] [security2:error] [pid 493992:tid 494177] [client 20.220.10.235:3979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/xwpg.php"] [unique_id "apPkPmbB9pEqk7z7RJlw4gAAA1U"]
[Sun Aug 30 03:05:18.782966 2026] [security2:error] [pid 493992:tid 494127] [client 20.104.18.15:43982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/aa.php"] [unique_id "apPkPmbB9pEqk7z7RJlw5gAAAyM"]
[Sun Aug 30 03:05:18.801748 2026] [security2:error] [pid 493992:tid 494193] [client 20.48.160.90:33193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/fling.php"] [unique_id "apPkPmbB9pEqk7z7RJlw7gAAA2U"]
[Sun Aug 30 03:05:18.843420 2026] [security2:error] [pid 493992:tid 494179] [client 20.220.10.235:28619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/is.php"] [unique_id "apPkPmbB9pEqk7z7RJlxFAAAA1c"]
[Sun Aug 30 03:05:18.855112 2026] [security2:error] [pid 493992:tid 494147] [client 20.48.251.3:64295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apPkPmbB9pEqk7z7RJlxHQAAAzc"]
[Sun Aug 30 03:05:18.863381 2026] [security2:error] [pid 491656:tid 491883] [client 158.23.147.79:63895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-admin/about.php"] [unique_id "apPkPovX_L6VjdbvkkTflwAAAvU"]
[Sun Aug 30 03:05:18.905745 2026] [security2:error] [pid 493992:tid 494165] [client 52.139.37.240:20068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/txets.php"] [unique_id "apPkPmbB9pEqk7z7RJlxOwAAA0k"]
[Sun Aug 30 03:05:18.909704 2026] [security2:error] [pid 491656:tid 491816] [client 20.48.160.90:45861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/nakrip.php"] [unique_id "apPkPovX_L6VjdbvkkTfrgAAArI"]
[Sun Aug 30 03:05:18.911116 2026] [security2:error] [pid 491656:tid 491847] [client 20.48.160.90:45930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/v5.php"] [unique_id "apPkPovX_L6VjdbvkkTfrwAAAtE"]
[Sun Aug 30 03:05:18.913122 2026] [security2:error] [pid 493992:tid 494245] [client 20.220.10.235:3975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/sxxb.php"] [unique_id "apPkPmbB9pEqk7z7RJlxPAAAA5k"]
[Sun Aug 30 03:05:18.932199 2026] [security2:error] [pid 493992:tid 494158] [client 20.104.49.130:57639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/wp-css.php"] [unique_id "apPkPmbB9pEqk7z7RJlxQQAAA0I"]
[Sun Aug 30 03:05:18.954102 2026] [security2:error] [pid 491656:tid 491799] [client 20.104.50.220:34004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "darkarcana.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkPovX_L6VjdbvkkTfuAAAAqE"]
[Sun Aug 30 03:05:18.960167 2026] [security2:error] [pid 491656:tid 491851] [client 20.48.160.90:33279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/btyuio.php"] [unique_id "apPkPovX_L6VjdbvkkTfuwAAAtU"]
[Sun Aug 30 03:05:18.980585 2026] [security2:error] [pid 491656:tid 491811] [client 20.220.10.235:27407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/od.php"] [unique_id "apPkPovX_L6VjdbvkkTfxAAAAq0"]
[Sun Aug 30 03:05:18.980742 2026] [authz_core:error] [pid 493992:tid 494189] [client 216.73.216.128:27548] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:18.981102 2026] [authz_core:error] [pid 493992:tid 494189] [client 216.73.216.128:27548] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:18.983639 2026] [security2:error] [pid 491656:tid 491886] [client 158.23.147.79:62579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-mail.php"] [unique_id "apPkPovX_L6VjdbvkkTfxQAAAvg"]
[Sun Aug 30 03:05:18.998539 2026] [security2:error] [pid 491656:tid 491832] [client 20.48.251.3:58855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/cu.php"] [unique_id "apPkPovX_L6VjdbvkkTfzAAAAsI"]
[Sun Aug 30 03:05:19.023903 2026] [security2:error] [pid 493992:tid 494172] [client 20.196.209.81:4590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/upgrade-temp-backup/pk.php"] [unique_id "apPkP2bB9pEqk7z7RJlxcgAAA1A"]
[Sun Aug 30 03:05:19.039022 2026] [security2:error] [pid 493992:tid 494131] [client 158.23.147.79:63882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apPkP2bB9pEqk7z7RJlxeAAAAyc"]
[Sun Aug 30 03:05:19.042251 2026] [security2:error] [pid 493992:tid 494221] [client 20.220.10.235:3992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/dx.php"] [unique_id "apPkP2bB9pEqk7z7RJlxewAAA4E"]
[Sun Aug 30 03:05:19.044083 2026] [security2:error] [pid 493992:tid 494236] [client 20.48.160.90:39940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/az.php"] [unique_id "apPkP2bB9pEqk7z7RJlxfgAAA5A"]
[Sun Aug 30 03:05:19.065108 2026] [security2:error] [pid 493992:tid 494226] [client 20.48.160.90:45825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp-includes/interactivity-api/flower.php"] [unique_id "apPkP2bB9pEqk7z7RJlxkQAAA4Y"]
[Sun Aug 30 03:05:19.092323 2026] [security2:error] [pid 493992:tid 494168] [client 20.48.160.90:50676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/dehnl.php"] [unique_id "apPkP2bB9pEqk7z7RJlxowAAA0w"]
[Sun Aug 30 03:05:19.098464 2026] [security2:error] [pid 493992:tid 494200] [client 52.139.37.240:63132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/wp-admin.php"] [unique_id "apPkP2bB9pEqk7z7RJlxqQAAA2w"]
[Sun Aug 30 03:05:19.114262 2026] [security2:error] [pid 491656:tid 491869] [client 20.220.10.235:27507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/wp-the.php"] [unique_id "apPkP4vX_L6VjdbvkkTgCAAAAuc"]
[Sun Aug 30 03:05:19.158063 2026] [security2:error] [pid 493992:tid 494186] [client 40.83.93.50:9064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/13.php"] [unique_id "apPkP2bB9pEqk7z7RJlx5AAAA14"]
[Sun Aug 30 03:05:19.175089 2026] [security2:error] [pid 493992:tid 494247] [client 34.15.141.119:46052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.141.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cpl.chg.temporary.site"] [uri "/includes/phpinfo.php"] [unique_id "apPkP2bB9pEqk7z7RJlx9gAAA5s"]
[Sun Aug 30 03:05:19.176466 2026] [security2:error] [pid 493992:tid 494210] [client 20.48.160.90:45846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/js.php"] [unique_id "apPkP2bB9pEqk7z7RJlx-wAAA3Y"]
[Sun Aug 30 03:05:19.188452 2026] [security2:error] [pid 493992:tid 494127] [client 20.104.18.15:8964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/sss.php"] [unique_id "apPkP2bB9pEqk7z7RJlyBgAAAyM"]
[Sun Aug 30 03:05:19.194974 2026] [security2:error] [pid 493992:tid 494206] [client 20.151.200.44:46941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/kcs.php"] [unique_id "apPkP2bB9pEqk7z7RJlyEAAAA3I"]
[Sun Aug 30 03:05:19.200626 2026] [security2:error] [pid 493992:tid 494126] [client 20.48.160.90:45886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/xcc.php"] [unique_id "apPkP2bB9pEqk7z7RJlyGAAAAyI"]
[Sun Aug 30 03:05:19.223690 2026] [security2:error] [pid 493992:tid 494206] [client 158.23.147.79:63266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/chosen.php"] [unique_id "apPkP2bB9pEqk7z7RJlyMwAAA3I"]
[Sun Aug 30 03:05:19.239685 2026] [security2:error] [pid 493992:tid 494239] [client 20.220.10.235:4078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPkP2bB9pEqk7z7RJlyPgAAA5M"]
[Sun Aug 30 03:05:19.253872 2026] [security2:error] [pid 491656:tid 491863] [client 158.23.147.79:63980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apPkP4vX_L6VjdbvkkTgUQAAAuE"]
[Sun Aug 30 03:05:19.256151 2026] [security2:error] [pid 493992:tid 494197] [client 20.220.10.235:28658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/wt.php"] [unique_id "apPkP2bB9pEqk7z7RJlyUQAAA2k"]
[Sun Aug 30 03:05:19.303667 2026] [security2:error] [pid 493992:tid 494160] [client 20.48.160.90:50599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/zoo2.php"] [unique_id "apPkP2bB9pEqk7z7RJlyeAAAA0Q"]
[Sun Aug 30 03:05:19.305063 2026] [security2:error] [pid 493992:tid 494133] [client 20.48.160.90:40012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/hd.php"] [unique_id "apPkP2bB9pEqk7z7RJlyewAAAyk"]
[Sun Aug 30 03:05:19.332605 2026] [security2:error] [pid 493992:tid 494126] [client 20.48.160.90:45891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp-includes/Text/Diff/Engine/aaa.php"] [unique_id "apPkP2bB9pEqk7z7RJlyoAAAAyI"]
[Sun Aug 30 03:05:19.384991 2026] [security2:error] [pid 493992:tid 494207] [client 68.155.159.216:52712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/index/function.php"] [unique_id "apPkP2bB9pEqk7z7RJlyxAAAA3M"]
[Sun Aug 30 03:05:19.387092 2026] [security2:error] [pid 493992:tid 494139] [client 20.151.200.44:62977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/tajj.php"] [unique_id "apPkP2bB9pEqk7z7RJlyxQAAAy8"]
[Sun Aug 30 03:05:19.389581 2026] [security2:error] [pid 491656:tid 491844] [client 20.220.10.235:28637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/im.php"] [unique_id "apPkP4vX_L6VjdbvkkTgjAAAAs4"]
[Sun Aug 30 03:05:19.393729 2026] [autoindex:error] [pid 493992:tid 494155] [client 52.139.37.240:61121] AH01276: Cannot serve directory /home4/littling/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:05:19.398186 2026] [security2:error] [pid 493992:tid 494147] [client 158.23.147.79:63992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/chosen.php"] [unique_id "apPkP2bB9pEqk7z7RJlyzgAAAzc"]
[Sun Aug 30 03:05:19.415506 2026] [security2:error] [pid 493992:tid 494176] [client 20.220.10.235:3978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/xda.php"] [unique_id "apPkP2bB9pEqk7z7RJly1gAAA1Q"]
[Sun Aug 30 03:05:19.427674 2026] [security2:error] [pid 491656:tid 491826] [client 158.23.147.79:62479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/cgi-bin/index.php"] [unique_id "apPkP4vX_L6VjdbvkkTgngAAArw"]
[Sun Aug 30 03:05:19.433993 2026] [security2:error] [pid 493992:tid 494127] [client 20.104.50.220:27418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/wp-ws68.php"] [unique_id "apPkP2bB9pEqk7z7RJly5QAAAyM"]
[Sun Aug 30 03:05:19.435531 2026] [security2:error] [pid 493992:tid 494220] [client 20.48.160.90:45922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/xl2023.php"] [unique_id "apPkP2bB9pEqk7z7RJly6AAAA4A"]
[Sun Aug 30 03:05:19.438663 2026] [security2:error] [pid 493992:tid 494239] [client 20.196.209.81:21164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/upgrade-temp-backup/plugins/security.php"] [unique_id "apPkP2bB9pEqk7z7RJly6wAAA5M"]
[Sun Aug 30 03:05:19.451083 2026] [security2:error] [pid 493992:tid 494185] [client 20.104.50.220:46632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/13.php"] [unique_id "apPkP2bB9pEqk7z7RJly8wAAA10"]
[Sun Aug 30 03:05:19.454679 2026] [security2:error] [pid 493992:tid 494207] [client 20.48.160.90:33258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/zoo1.php"] [unique_id "apPkP2bB9pEqk7z7RJly9wAAA3M"]
[Sun Aug 30 03:05:19.473078 2026] [security2:error] [pid 491656:tid 491804] [client 20.104.50.220:33052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/python.php"] [unique_id "apPkP4vX_L6VjdbvkkTgtgAAAqY"]
[Sun Aug 30 03:05:19.480328 2026] [security2:error] [pid 493992:tid 494225] [client 20.48.251.3:23478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/hochladen.form.php"] [unique_id "apPkP2bB9pEqk7z7RJlzCQAAA4U"]
[Sun Aug 30 03:05:19.497241 2026] [security2:error] [pid 493992:tid 494222] [client 20.48.251.3:44306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/paths.php"] [unique_id "apPkP2bB9pEqk7z7RJlzEwAAA4I"]
[Sun Aug 30 03:05:19.514798 2026] [security2:error] [pid 493992:tid 494214] [client 20.151.200.44:47398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/ssss.php"] [unique_id "apPkP2bB9pEqk7z7RJlzIwAAA3o"]
[Sun Aug 30 03:05:19.520786 2026] [security2:error] [pid 493992:tid 494194] [client 20.220.10.235:28620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/file.php"] [unique_id "apPkP2bB9pEqk7z7RJlzLQAAA2Y"]
[Sun Aug 30 03:05:19.528052 2026] [security2:error] [pid 493992:tid 494217] [client 20.104.50.220:51611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/sec.php"] [unique_id "apPkP2bB9pEqk7z7RJlzMwAAA30"]
[Sun Aug 30 03:05:19.559997 2026] [security2:error] [pid 493992:tid 494228] [client 158.23.147.79:62566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPkP2bB9pEqk7z7RJlzRgAAA4g"]
[Sun Aug 30 03:05:19.563298 2026] [security2:error] [pid 493992:tid 494181] [client 158.23.147.79:62322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/goods.php"] [unique_id "apPkP2bB9pEqk7z7RJlzSwAAA1k"]
[Sun Aug 30 03:05:19.564728 2026] [security2:error] [pid 493992:tid 494195] [client 20.220.10.235:3994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPkP2bB9pEqk7z7RJlzTQAAA2c"]
[Sun Aug 30 03:05:19.569410 2026] [security2:error] [pid 491656:tid 491911] [client 20.104.50.220:32514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/8index.php"] [unique_id "apPkP4vX_L6VjdbvkkTg3QAAAxE"]
[Sun Aug 30 03:05:19.570611 2026] [security2:error] [pid 491656:tid 491914] [client 20.104.50.220:5596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/ww1.php"] [unique_id "apPkP4vX_L6VjdbvkkTg3gAAAxQ"]
[Sun Aug 30 03:05:19.577160 2026] [security2:error] [pid 491656:tid 491819] [client 20.48.251.3:55467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/myfile.php"] [unique_id "apPkP4vX_L6VjdbvkkTg4gAAArU"]
[Sun Aug 30 03:05:19.604407 2026] [security2:error] [pid 491656:tid 491816] [client 20.104.50.220:61650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/nikung.php"] [unique_id "apPkP4vX_L6VjdbvkkTg6wAAArI"]
[Sun Aug 30 03:05:19.615573 2026] [security2:error] [pid 493992:tid 494232] [client 20.104.50.220:64452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/g6shell.php"] [unique_id "apPkP2bB9pEqk7z7RJlzbAAAA4w"]
[Sun Aug 30 03:05:19.629909 2026] [security2:error] [pid 493992:tid 494177] [client 20.48.251.3:64396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/G-in.php"] [unique_id "apPkP2bB9pEqk7z7RJlzewAAA1U"]
[Sun Aug 30 03:05:19.642286 2026] [security2:error] [pid 493992:tid 494132] [client 20.104.18.15:32972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/zoo2.php"] [unique_id "apPkP2bB9pEqk7z7RJlzhgAAAyg"]
[Sun Aug 30 03:05:19.654050 2026] [security2:error] [pid 493992:tid 494164] [client 20.220.10.235:28624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/ca.php"] [unique_id "apPkP2bB9pEqk7z7RJlzjAAAA0g"]
[Sun Aug 30 03:05:19.663666 2026] [security2:error] [pid 493992:tid 494139] [client 20.104.18.15:13757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/dex.php"] [unique_id "apPkP2bB9pEqk7z7RJlzkwAAAy8"]
[Sun Aug 30 03:05:19.666437 2026] [security2:error] [pid 493992:tid 494140] [client 20.104.49.130:63053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.topatrust.com"] [uri "/bolt.php"] [unique_id "apPkP2bB9pEqk7z7RJlzlgAAAzA"]
[Sun Aug 30 03:05:19.682529 2026] [security2:error] [pid 493992:tid 494199] [client 158.23.147.79:63909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apPkP2bB9pEqk7z7RJlzmwAAA2s"]
[Sun Aug 30 03:05:19.686213 2026] [security2:error] [pid 491656:tid 491874] [client 20.48.251.3:55784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/phpversion.php"] [unique_id "apPkP4vX_L6VjdbvkkThCAAAAuw"]
[Sun Aug 30 03:05:19.693702 2026] [security2:error] [pid 493992:tid 494175] [client 20.220.10.235:4005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/t00l.php"] [unique_id "apPkP2bB9pEqk7z7RJlzoQAAA1M"]
[Sun Aug 30 03:05:19.694734 2026] [security2:error] [pid 491656:tid 491828] [client 40.83.93.50:9073] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.homedesigner.org"] [uri "/1.php"] [unique_id "apPkP4vX_L6VjdbvkkThEQAAAr4"]
[Sun Aug 30 03:05:19.694813 2026] [security2:error] [pid 491656:tid 491828] [client 40.83.93.50:9073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/1.php"] [unique_id "apPkP4vX_L6VjdbvkkThEQAAAr4"]
[Sun Aug 30 03:05:19.721300 2026] [security2:error] [pid 491656:tid 491904] [client 20.104.18.15:31672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/gjewuagf.php"] [unique_id "apPkP4vX_L6VjdbvkkThHQAAAwo"]
[Sun Aug 30 03:05:19.727926 2026] [security2:error] [pid 493992:tid 494235] [client 20.104.50.220:62793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-utchershill.php"] [unique_id "apPkP2bB9pEqk7z7RJlzwwAAA48"]
[Sun Aug 30 03:05:19.770416 2026] [authz_core:error] [pid 493992:tid 494123] [client 66.249.66.71:39149] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:19.770832 2026] [authz_core:error] [pid 493992:tid 494123] [client 66.249.66.71:39149] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:19.783444 2026] [security2:error] [pid 491656:tid 491830] [client 20.220.10.235:28668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/pb.php"] [unique_id "apPkP4vX_L6VjdbvkkThOwAAAsA"]
[Sun Aug 30 03:05:19.788412 2026] [security2:error] [pid 493992:tid 494213] [client 68.155.159.216:59998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/goat.php"] [unique_id "apPkP2bB9pEqk7z7RJlz7gAAA3k"]
[Sun Aug 30 03:05:19.825173 2026] [security2:error] [pid 493992:tid 494249] [client 20.220.10.235:4069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/ls.php"] [unique_id "apPkP2bB9pEqk7z7RJl0BQAAA50"]
[Sun Aug 30 03:05:19.833448 2026] [security2:error] [pid 493992:tid 494198] [client 20.196.209.81:4544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/upgrade-temp-backup/plugins/users.php"] [unique_id "apPkP2bB9pEqk7z7RJl0EAAAA2o"]
[Sun Aug 30 03:05:19.859834 2026] [security2:error] [pid 493992:tid 494191] [client 158.23.147.79:63968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apPkP2bB9pEqk7z7RJl0HgAAA2M"]
[Sun Aug 30 03:05:19.901407 2026] [authz_core:error] [pid 493992:tid 494189] [client 66.249.66.71:60081] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:19.901874 2026] [authz_core:error] [pid 493992:tid 494189] [client 66.249.66.71:60081] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:19.903664 2026] [security2:error] [pid 491656:tid 491905] [client 68.155.159.216:52800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apPkP4vX_L6VjdbvkkThagAAAws"]
[Sun Aug 30 03:05:19.913690 2026] [security2:error] [pid 493992:tid 494202] [client 20.220.10.235:28621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/pk.php"] [unique_id "apPkP2bB9pEqk7z7RJl0OwAAA24"]
[Sun Aug 30 03:05:19.913794 2026] [security2:error] [pid 493992:tid 494206] [client 52.139.37.240:61121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/wp-config-sample.php"] [unique_id "apPkP2bB9pEqk7z7RJl0OgAAA3I"]
[Sun Aug 30 03:05:19.938445 2026] [security2:error] [pid 491656:tid 491855] [client 20.104.18.15:43304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/img.php"] [unique_id "apPkP4vX_L6VjdbvkkTheAAAAtk"]
[Sun Aug 30 03:05:19.957087 2026] [security2:error] [pid 491656:tid 491822] [client 20.220.10.235:3976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/css/000.php"] [unique_id "apPkP4vX_L6VjdbvkkThfwAAArg"]
[Sun Aug 30 03:05:19.964026 2026] [security2:error] [pid 493992:tid 494217] [client 158.23.147.79:63249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/goods.php"] [unique_id "apPkP2bB9pEqk7z7RJl0SQAAA30"]
[Sun Aug 30 03:05:19.995150 2026] [security2:error] [pid 491656:tid 491890] [client 20.48.251.3:54722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/hochladen.form.php"] [unique_id "apPkP4vX_L6VjdbvkkThjwAAAvw"]
[Sun Aug 30 03:05:20.014065 2026] [security2:error] [pid 493992:tid 494137] [client 158.23.147.79:63878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/file.php"] [unique_id "apPkQGbB9pEqk7z7RJl0ZgAAAy0"]
[Sun Aug 30 03:05:20.038698 2026] [security2:error] [pid 493992:tid 494179] [client 158.23.147.79:63286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-includes/content.php"] [unique_id "apPkQGbB9pEqk7z7RJl0cgAAA1c"]
[Sun Aug 30 03:05:20.051498 2026] [authz_core:error] [pid 493992:tid 494214] [client 66.249.66.69:35999] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:20.051788 2026] [authz_core:error] [pid 493992:tid 494214] [client 66.249.66.69:35999] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:20.052039 2026] [security2:error] [pid 493992:tid 494143] [client 20.220.10.235:28650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/ft.php"] [unique_id "apPkQGbB9pEqk7z7RJl0fgAAAzM"]
[Sun Aug 30 03:05:20.094433 2026] [security2:error] [pid 493992:tid 494198] [client 20.220.10.235:4063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/cy.php"] [unique_id "apPkQGbB9pEqk7z7RJl0lQAAA2o"]
[Sun Aug 30 03:05:20.109819 2026] [security2:error] [pid 493992:tid 494185] [client 52.139.37.240:61131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littlebunnycleaning.com"] [uri "/wp-content/packed.php"] [unique_id "apPkQGbB9pEqk7z7RJl0pQAAA10"]
[Sun Aug 30 03:05:20.166770 2026] [core:error] [pid 493992:tid 494242] [client 158.23.184.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:05:20.166791 2026] [core:error] [pid 493992:tid 494242] [client 158.23.184.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:05:20.181620 2026] [security2:error] [pid 493992:tid 494163] [client 20.220.10.235:28567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/wp-ver.php"] [unique_id "apPkQGbB9pEqk7z7RJl06QAAA0c"]
[Sun Aug 30 03:05:20.190633 2026] [authz_core:error] [pid 493992:tid 494153] [client 216.73.216.128:29761] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:20.190993 2026] [authz_core:error] [pid 493992:tid 494153] [client 216.73.216.128:29761] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:20.204250 2026] [authz_core:error] [pid 493992:tid 494157] [client 66.249.66.203:61123] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:20.204578 2026] [authz_core:error] [pid 493992:tid 494157] [client 66.249.66.203:61123] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:20.223972 2026] [security2:error] [pid 493992:tid 494186] [client 20.48.251.3:34618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/services.php"] [unique_id "apPkQGbB9pEqk7z7RJl1HgAAA14"]
[Sun Aug 30 03:05:20.251722 2026] [security2:error] [pid 493992:tid 494187] [client 20.196.209.81:4573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/upgrade-temp-backup/plugins/wp-blog-header.php"] [unique_id "apPkQGbB9pEqk7z7RJl1NQAAA18"]
[Sun Aug 30 03:05:20.254282 2026] [security2:error] [pid 493992:tid 494194] [client 158.23.147.79:63891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/file17.php"] [unique_id "apPkQGbB9pEqk7z7RJl1OAAAA2Y"]
[Sun Aug 30 03:05:20.256044 2026] [security2:error] [pid 493992:tid 494210] [client 20.220.10.235:3990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/admin.php/pindex.php"] [unique_id "apPkQGbB9pEqk7z7RJl1OgAAA3Y"]
[Sun Aug 30 03:05:20.262836 2026] [security2:error] [pid 493992:tid 494241] [client 158.23.147.79:40318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/themes.php"] [unique_id "apPkQGbB9pEqk7z7RJl1PAAAA5U"]
[Sun Aug 30 03:05:20.270193 2026] [security2:error] [pid 493992:tid 494122] [client 20.104.49.130:57700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/ab.php"] [unique_id "apPkQGbB9pEqk7z7RJl1RAAAAx4"]
[Sun Aug 30 03:05:20.272813 2026] [security2:error] [pid 493992:tid 494201] [client 93.123.109.165:6948] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "paulgarrigan.com"] [uri "/"] [unique_id "apPkQGbB9pEqk7z7RJl1QgAAA20"]
[Sun Aug 30 03:05:20.274772 2026] [security2:error] [pid 493992:tid 494151] [client 216.73.216.128:13885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPkQGbB9pEqk7z7RJl1SQAAAzs"]
[Sun Aug 30 03:05:20.276510 2026] [security2:error] [pid 491656:tid 491792] [client 40.83.93.50:12089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/as.php"] [unique_id "apPkQIvX_L6VjdbvkkTiEwAAApo"]
[Sun Aug 30 03:05:20.341360 2026] [autoindex:error] [pid 493992:tid 494231] [client 52.139.37.240:0] AH01276: Cannot serve directory /home4/littling/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:05:20.362932 2026] [security2:error] [pid 493992:tid 494133] [client 158.23.147.79:63232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apPkQGbB9pEqk7z7RJl1tQAAAyk"]
[Sun Aug 30 03:05:20.366207 2026] [security2:error] [pid 493992:tid 494191] [client 216.73.216.128:57138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPkQGbB9pEqk7z7RJl1uwAAA2M"]
[Sun Aug 30 03:05:20.369253 2026] [security2:error] [pid 493992:tid 494236] [client 20.220.10.235:28546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/ah24.php"] [unique_id "apPkQGbB9pEqk7z7RJl1vgAAA5A"]
[Sun Aug 30 03:05:20.386685 2026] [security2:error] [pid 493992:tid 494122] [client 20.220.10.235:3996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/admin.php/csv.php"] [unique_id "apPkQGbB9pEqk7z7RJl1ywAAAx4"]
[Sun Aug 30 03:05:20.397614 2026] [security2:error] [pid 491656:tid 491897] [client 158.23.147.79:63948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/file5.php"] [unique_id "apPkQIvX_L6VjdbvkkTiPwAAAwM"]
[Sun Aug 30 03:05:20.420720 2026] [security2:error] [pid 493992:tid 494238] [client 20.104.18.15:9137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/wp-includes/ID3/moon.php"] [unique_id "apPkQGbB9pEqk7z7RJl18AAAA5I"]
[Sun Aug 30 03:05:20.423460 2026] [security2:error] [pid 493992:tid 494153] [client 93.123.109.165:6948] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "paulgarrigan.com"] [uri "/"] [unique_id "apPkQGbB9pEqk7z7RJl17gAAAz0"]
[Sun Aug 30 03:05:20.493026 2026] [security2:error] [pid 491656:tid 491914] [client 68.155.159.216:54743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/.well-known/content.php"] [unique_id "apPkQIvX_L6VjdbvkkTiawAAAxQ"]
[Sun Aug 30 03:05:20.499046 2026] [authz_core:error] [pid 493992:tid 494172] [client 66.249.66.36:41719] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:20.499333 2026] [authz_core:error] [pid 493992:tid 494172] [client 66.249.66.36:41719] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:20.516489 2026] [security2:error] [pid 493992:tid 494146] [client 20.220.10.235:28544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/wp-admin/zwso.php"] [unique_id "apPkQGbB9pEqk7z7RJl2MgAAAzY"]
[Sun Aug 30 03:05:20.520339 2026] [security2:error] [pid 493992:tid 494200] [client 158.23.147.79:62555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-admin/css/index.php"] [unique_id "apPkQGbB9pEqk7z7RJl2OAAAA2w"]
[Sun Aug 30 03:05:20.523089 2026] [security2:error] [pid 493992:tid 494154] [client 20.220.10.235:4054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/admin.php/700.php"] [unique_id "apPkQGbB9pEqk7z7RJl2PAAAAz4"]
[Sun Aug 30 03:05:20.557955 2026] [authz_core:error] [pid 493992:tid 494147] [client 216.73.216.128:27548] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:20.558230 2026] [authz_core:error] [pid 493992:tid 494147] [client 216.73.216.128:27548] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:20.569657 2026] [security2:error] [pid 493992:tid 494187] [client 20.104.50.220:27394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/mac.php"] [unique_id "apPkQGbB9pEqk7z7RJl2WQAAA18"]
[Sun Aug 30 03:05:20.589214 2026] [security2:error] [pid 493992:tid 494168] [client 20.104.50.220:46425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/1index.php"] [unique_id "apPkQGbB9pEqk7z7RJl2ZQAAA0w"]
[Sun Aug 30 03:05:20.598269 2026] [security2:error] [pid 493992:tid 494200] [client 158.23.147.79:63900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/file88.php"] [unique_id "apPkQGbB9pEqk7z7RJl2ZwAAA2w"]
[Sun Aug 30 03:05:20.598933 2026] [security2:error] [pid 493992:tid 494245] [client 20.151.200.44:46980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/is.php"] [unique_id "apPkQGbB9pEqk7z7RJl2aAAAA5k"]
[Sun Aug 30 03:05:20.613294 2026] [security2:error] [pid 493992:tid 494240] [client 20.104.50.220:33553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-pop.php"] [unique_id "apPkQGbB9pEqk7z7RJl2dgAAA5Q"]
[Sun Aug 30 03:05:20.632756 2026] [security2:error] [pid 493992:tid 494126] [client 20.48.251.3:22756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/debuggen.php"] [unique_id "apPkQGbB9pEqk7z7RJl2igAAAyI"]
[Sun Aug 30 03:05:20.654298 2026] [security2:error] [pid 491656:tid 491895] [client 20.220.10.235:28545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bigbuba.it"] [uri "/waf.php"] [unique_id "apPkQIvX_L6VjdbvkkTisQAAAwE"]
[Sun Aug 30 03:05:20.654749 2026] [security2:error] [pid 491656:tid 491911] [client 20.220.10.235:3904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/admin.php/007x.php"] [unique_id "apPkQIvX_L6VjdbvkkTiswAAAxE"]
[Sun Aug 30 03:05:20.671753 2026] [security2:error] [pid 493992:tid 494196] [client 20.196.209.81:17747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/upgrade-temp-backup/plugins/wp-mail.php"] [unique_id "apPkQGbB9pEqk7z7RJl2oQAAA2g"]
[Sun Aug 30 03:05:20.674296 2026] [security2:error] [pid 493992:tid 494235] [client 20.151.200.44:62989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/bge.php"] [unique_id "apPkQGbB9pEqk7z7RJl2owAAA48"]
[Sun Aug 30 03:05:20.682305 2026] [security2:error] [pid 491656:tid 491914] [client 20.104.50.220:51538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/shapes.php"] [unique_id "apPkQIvX_L6VjdbvkkTiuAAAAxQ"]
[Sun Aug 30 03:05:20.711142 2026] [security2:error] [pid 493992:tid 494158] [client 20.104.50.220:5510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/about/function.php"] [unique_id "apPkQGbB9pEqk7z7RJl2uAAAA0I"]
[Sun Aug 30 03:05:20.714680 2026] [security2:error] [pid 493992:tid 494143] [client 20.48.251.3:55530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/lm15.php"] [unique_id "apPkQGbB9pEqk7z7RJl2uwAAAzM"]
[Sun Aug 30 03:05:20.729102 2026] [security2:error] [pid 493992:tid 494136] [client 158.23.147.79:63969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/NewFile.php/"] [unique_id "apPkQGbB9pEqk7z7RJl2xgAAAyw"]
[Sun Aug 30 03:05:20.729247 2026] [security2:error] [pid 493992:tid 494155] [client 20.104.50.220:31843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/9index.php"] [unique_id "apPkQGbB9pEqk7z7RJl2xwAAAz8"]
[Sun Aug 30 03:05:20.738168 2026] [security2:error] [pid 491656:tid 491844] [client 158.23.147.79:63279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apPkQIvX_L6VjdbvkkTiywAAAs4"]
[Sun Aug 30 03:05:20.739639 2026] [security2:error] [pid 493992:tid 494186] [client 20.63.219.114:15160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/aaa.php"] [unique_id "apPkQGbB9pEqk7z7RJl2zwAAA14"]
[Sun Aug 30 03:05:20.751411 2026] [authz_core:error] [pid 493992:tid 494170] [client 216.73.216.128:29761] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:20.751757 2026] [authz_core:error] [pid 493992:tid 494170] [client 216.73.216.128:29761] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:20.759594 2026] [security2:error] [pid 493992:tid 494242] [client 20.104.50.220:61484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/tertykung.php"] [unique_id "apPkQGbB9pEqk7z7RJl24gAAA5Y"]
[Sun Aug 30 03:05:20.765287 2026] [security2:error] [pid 493992:tid 494143] [client 20.48.251.3:6467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/apikeys.php"] [unique_id "apPkQGbB9pEqk7z7RJl25wAAAzM"]
[Sun Aug 30 03:05:20.772041 2026] [security2:error] [pid 493992:tid 494209] [client 51.254.132.238:58146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.132.254.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "den-enterprises.com"] [uri "/wp-comments-post.php"] [unique_id "apPkQGbB9pEqk7z7RJl2zgAAA3U"], referer: http://den-enterprises.com/2020/06/27/hello-world/#comment-10226
[Sun Aug 30 03:05:20.772120 2026] [security2:error] [pid 493992:tid 494209] [client 51.254.132.238:58146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "den-enterprises.com"] [uri "/wp-comments-post.php"] [unique_id "apPkQGbB9pEqk7z7RJl2zgAAA3U"], referer: http://den-enterprises.com/2020/06/27/hello-world/#comment-10226
[Sun Aug 30 03:05:20.787919 2026] [security2:error] [pid 493992:tid 494132] [client 20.104.50.220:63044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/pouyaserver.php"] [unique_id "apPkQGbB9pEqk7z7RJl3AgAAAyg"]
[Sun Aug 30 03:05:20.804762 2026] [security2:error] [pid 493992:tid 494128] [client 158.23.147.79:63241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-admin/images/index.php"] [unique_id "apPkQGbB9pEqk7z7RJl3DgAAAyQ"]
[Sun Aug 30 03:05:20.808372 2026] [security2:error] [pid 493992:tid 494189] [client 20.220.10.235:4041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/admin.php/heex.php"] [unique_id "apPkQGbB9pEqk7z7RJl3EQAAA2E"]
[Sun Aug 30 03:05:20.815707 2026] [security2:error] [pid 493992:tid 494173] [client 20.104.18.15:33669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/zoo1.php"] [unique_id "apPkQGbB9pEqk7z7RJl3FwAAA1E"]
[Sun Aug 30 03:05:20.827195 2026] [security2:error] [pid 493992:tid 494130] [client 40.83.93.50:12072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/credits.php"] [unique_id "apPkQGbB9pEqk7z7RJl3HAAAAyY"]
[Sun Aug 30 03:05:20.834099 2026] [security2:error] [pid 493992:tid 494190] [client 185.191.171.15:28196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arcaneguardians.com"] [uri "/tdbhc/most-reliable-midsize-luxury-suv-2022"] [unique_id "apPkQGbB9pEqk7z7RJl3HwAAA2I"]
[Sun Aug 30 03:05:20.834224 2026] [security2:error] [pid 493992:tid 494190] [client 185.191.171.15:28196] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "arcaneguardians.com"] [uri "/tdbhc/most-reliable-midsize-luxury-suv-2022"] [unique_id "apPkQGbB9pEqk7z7RJl3HwAAA2I"]
[Sun Aug 30 03:05:20.835777 2026] [security2:error] [pid 493992:tid 494249] [client 20.104.18.15:13601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/inso.php"] [unique_id "apPkQGbB9pEqk7z7RJl3IAAAA50"]
[Sun Aug 30 03:05:20.838886 2026] [security2:error] [pid 493992:tid 494229] [client 20.104.49.130:52297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/css.php"] [unique_id "apPkQGbB9pEqk7z7RJl3IgAAA4k"]
[Sun Aug 30 03:05:20.855833 2026] [security2:error] [pid 493992:tid 494214] [client 20.104.18.15:31641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/tnglzqmv.php"] [unique_id "apPkQGbB9pEqk7z7RJl3LAAAA3o"]
[Sun Aug 30 03:05:20.858755 2026] [security2:error] [pid 493992:tid 494200] [client 20.63.219.114:18502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/atomlib.php"] [unique_id "apPkQGbB9pEqk7z7RJl3MAAAA2w"]
[Sun Aug 30 03:05:20.861104 2026] [security2:error] [pid 493992:tid 494210] [client 158.23.147.79:62315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/dropdown.php"] [unique_id "apPkQGbB9pEqk7z7RJl3MwAAA3Y"]
[Sun Aug 30 03:05:20.867059 2026] [security2:error] [pid 493992:tid 494183] [client 20.104.50.220:52832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-log.php"] [unique_id "apPkQGbB9pEqk7z7RJl3NQAAA1s"]
[Sun Aug 30 03:05:20.868265 2026] [security2:error] [pid 493992:tid 494176] [client 20.48.251.3:4733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/olfclass.php"] [unique_id "apPkQGbB9pEqk7z7RJl3NwAAA1Q"]
[Sun Aug 30 03:05:20.877010 2026] [authz_core:error] [pid 491656:tid 491801] [client 66.249.66.76:50024] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:20.877490 2026] [authz_core:error] [pid 491656:tid 491801] [client 66.249.66.76:50024] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:20.883562 2026] [authz_core:error] [pid 493992:tid 494234] [client 66.249.66.71:60081] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:20.883841 2026] [authz_core:error] [pid 493992:tid 494234] [client 66.249.66.71:60081] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:20.914056 2026] [authz_core:error] [pid 493992:tid 494154] [client 66.249.66.76:36240] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:20.914358 2026] [authz_core:error] [pid 493992:tid 494154] [client 66.249.66.76:36240] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:20.926625 2026] [security2:error] [pid 493992:tid 494202] [client 20.48.251.3:52776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/adminfus.php"] [unique_id "apPkQGbB9pEqk7z7RJl3SAAAA24"]
[Sun Aug 30 03:05:20.936858 2026] [security2:error] [pid 493992:tid 494165] [client 68.155.159.216:59920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apPkQGbB9pEqk7z7RJl3SgAAA0k"]
[Sun Aug 30 03:05:20.938797 2026] [security2:error] [pid 493992:tid 494160] [client 20.220.10.235:3913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/tf.php"] [unique_id "apPkQGbB9pEqk7z7RJl3TAAAA0Q"]
[Sun Aug 30 03:05:20.968890 2026] [security2:error] [pid 493992:tid 494162] [client 158.23.147.79:63921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/.well-known/index.php"] [unique_id "apPkQGbB9pEqk7z7RJl3UgAAA0Y"]
[Sun Aug 30 03:05:21.053097 2026] [authz_core:error] [pid 493992:tid 494193] [client 66.249.66.206:44668] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:21.053409 2026] [authz_core:error] [pid 493992:tid 494193] [client 66.249.66.206:44668] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:21.071183 2026] [security2:error] [pid 493992:tid 494142] [client 20.196.209.81:13685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/upgrade-temp-backup/themes/admin.php"] [unique_id "apPkQWbB9pEqk7z7RJl3aQAAAzI"]
[Sun Aug 30 03:05:21.076950 2026] [security2:error] [pid 493992:tid 494147] [client 20.220.10.235:4012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/update/da222.php"] [unique_id "apPkQWbB9pEqk7z7RJl3agAAAzc"]
[Sun Aug 30 03:05:21.101515 2026] [security2:error] [pid 493992:tid 494195] [client 20.104.18.15:43286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/222.php"] [unique_id "apPkQWbB9pEqk7z7RJl3cAAAA2c"]
[Sun Aug 30 03:05:21.121548 2026] [security2:error] [pid 493992:tid 494134] [client 68.155.159.216:9225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPkQWbB9pEqk7z7RJl3ewAAAyo"]
[Sun Aug 30 03:05:21.123904 2026] [security2:error] [pid 493992:tid 494198] [client 216.73.216.128:29761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/about.html"] [unique_id "apPkQWbB9pEqk7z7RJl3fAAAA2o"]
[Sun Aug 30 03:05:21.134484 2026] [security2:error] [pid 493992:tid 494241] [client 20.48.251.3:54758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/debuggen.php"] [unique_id "apPkQWbB9pEqk7z7RJl3fQAAA5U"]
[Sun Aug 30 03:05:21.135828 2026] [security2:error] [pid 493992:tid 494227] [client 158.23.147.79:62555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/file.php"] [unique_id "apPkQWbB9pEqk7z7RJl3fgAAA4c"]
[Sun Aug 30 03:05:21.138610 2026] [security2:error] [pid 493992:tid 494189] [client 20.151.200.44:46923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/tajj.php"] [unique_id "apPkQWbB9pEqk7z7RJl3fwAAA2E"]
[Sun Aug 30 03:05:21.210891 2026] [security2:error] [pid 493992:tid 494152] [client 20.220.10.235:3929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/qi.php"] [unique_id "apPkQWbB9pEqk7z7RJl3jwAAAzw"]
[Sun Aug 30 03:05:21.212664 2026] [security2:error] [pid 493992:tid 494209] [client 158.23.147.79:63886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-content/themes/too.php"] [unique_id "apPkQWbB9pEqk7z7RJl3kQAAA3U"]
[Sun Aug 30 03:05:21.263828 2026] [security2:error] [pid 493992:tid 494210] [client 158.23.147.79:63287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/file17.php"] [unique_id "apPkQWbB9pEqk7z7RJl3owAAA3Y"]
[Sun Aug 30 03:05:21.264600 2026] [security2:error] [pid 493992:tid 494186] [client 158.23.147.79:63293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-includes/index.php"] [unique_id "apPkQWbB9pEqk7z7RJl3pAAAA14"]
[Sun Aug 30 03:05:21.317174 2026] [security2:error] [pid 493992:tid 494226] [client 20.63.219.114:15142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/buy.php"] [unique_id "apPkQWbB9pEqk7z7RJl3sQAAA4Y"]
[Sun Aug 30 03:05:21.372971 2026] [security2:error] [pid 493992:tid 494152] [client 20.220.10.235:4074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/is.php"] [unique_id "apPkQWbB9pEqk7z7RJl3vgAAAzw"]
[Sun Aug 30 03:05:21.379850 2026] [security2:error] [pid 493992:tid 494220] [client 158.23.147.79:63965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/radio.php"] [unique_id "apPkQWbB9pEqk7z7RJl3vwAAA4A"]
[Sun Aug 30 03:05:21.399933 2026] [security2:error] [pid 493992:tid 494249] [client 158.23.147.79:63245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/file5.php"] [unique_id "apPkQWbB9pEqk7z7RJl3xAAAA50"]
[Sun Aug 30 03:05:21.435462 2026] [authz_core:error] [pid 493992:tid 494122] [client 66.249.66.44:65309] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:21.435784 2026] [authz_core:error] [pid 493992:tid 494122] [client 66.249.66.44:65309] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:21.468328 2026] [security2:error] [pid 493992:tid 494219] [client 20.196.209.81:21157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/upgrade-temp-backup/themes/login.php"] [unique_id "apPkQWbB9pEqk7z7RJl39QAAA38"]
[Sun Aug 30 03:05:21.494612 2026] [security2:error] [pid 493992:tid 494231] [client 158.23.147.79:63958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPkQWbB9pEqk7z7RJl3-wAAA4s"]
[Sun Aug 30 03:05:21.508653 2026] [authz_core:error] [pid 493992:tid 494133] [client 216.73.216.128:10586] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:21.508925 2026] [authz_core:error] [pid 493992:tid 494133] [client 216.73.216.128:10586] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:21.509847 2026] [security2:error] [pid 493992:tid 494001] [remote 160.153.252.100:52138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.252.153.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "killmigraine.com"] [uri "/wp-login.php"] [unique_id "apPkQWbB9pEqk7z7RJl3-gADUAg"]
[Sun Aug 30 03:05:21.532569 2026] [security2:error] [pid 493992:tid 494209] [client 40.83.93.50:12045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/cache.php"] [unique_id "apPkQWbB9pEqk7z7RJl4BgAAA3U"]
[Sun Aug 30 03:05:21.537557 2026] [security2:error] [pid 493992:tid 494130] [client 20.220.10.235:3998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/od.php"] [unique_id "apPkQWbB9pEqk7z7RJl4CQAAAyY"]
[Sun Aug 30 03:05:21.577710 2026] [security2:error] [pid 493992:tid 494238] [client 158.23.147.79:62473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/mah.php"] [unique_id "apPkQWbB9pEqk7z7RJl4GAAAA5I"]
[Sun Aug 30 03:05:21.577940 2026] [security2:error] [pid 493992:tid 494196] [client 158.23.147.79:63233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/file88.php"] [unique_id "apPkQWbB9pEqk7z7RJl4GQAAA2g"]
[Sun Aug 30 03:05:21.578753 2026] [security2:error] [pid 493992:tid 494171] [client 20.104.49.130:40246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.topatrust.com"] [uri "/cilus.php"] [unique_id "apPkQWbB9pEqk7z7RJl4HAAAA08"]
[Sun Aug 30 03:05:21.586879 2026] [security2:error] [pid 493992:tid 494139] [client 20.48.251.3:58853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/filesystems.php"] [unique_id "apPkQWbB9pEqk7z7RJl4IQAAAy8"]
[Sun Aug 30 03:05:21.594638 2026] [security2:error] [pid 493992:tid 494140] [client 158.23.147.79:63970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/makeasmtp.php"] [unique_id "apPkQWbB9pEqk7z7RJl4JQAAAzA"]
[Sun Aug 30 03:05:21.600239 2026] [authz_core:error] [pid 493992:tid 494183] [client 216.73.216.128:27548] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:21.600686 2026] [authz_core:error] [pid 493992:tid 494183] [client 216.73.216.128:27548] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:21.606622 2026] [security2:error] [pid 493992:tid 494163] [client 20.104.18.15:9197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/xmini4.php"] [unique_id "apPkQWbB9pEqk7z7RJl4JwAAA0c"]
[Sun Aug 30 03:05:21.644418 2026] [security2:error] [pid 493992:tid 494157] [client 68.155.159.216:54766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/cong.php"] [unique_id "apPkQWbB9pEqk7z7RJl4KwAAA0E"]
[Sun Aug 30 03:05:21.673233 2026] [security2:error] [pid 493992:tid 494209] [client 20.220.10.235:4080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/wp-the.php"] [unique_id "apPkQWbB9pEqk7z7RJl4NwAAA3U"]
[Sun Aug 30 03:05:21.697071 2026] [security2:error] [pid 493992:tid 494005] [remote 160.153.252.100:52138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.252.153.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "killmigraine.com"] [uri "/wp-login.php"] [unique_id "apPkQWbB9pEqk7z7RJl4QgADegw"], referer: https://killmigraine.com/wp-login.php
[Sun Aug 30 03:05:21.716951 2026] [security2:error] [pid 493992:tid 494204] [client 20.104.50.220:27453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/aaa.php"] [unique_id "apPkQWbB9pEqk7z7RJl4SwAAA3A"]
[Sun Aug 30 03:05:21.727535 2026] [security2:error] [pid 493992:tid 494235] [client 158.23.147.79:26515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-mail.php"] [unique_id "apPkQWbB9pEqk7z7RJl4TwAAA48"]
[Sun Aug 30 03:05:21.744228 2026] [security2:error] [pid 493992:tid 494141] [client 20.104.50.220:47042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/22xc.php"] [unique_id "apPkQWbB9pEqk7z7RJl4UwAAAzE"]
[Sun Aug 30 03:05:21.753949 2026] [security2:error] [pid 493992:tid 494177] [client 158.23.147.79:52935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-blog-header.php"] [unique_id "apPkQWbB9pEqk7z7RJl4VwAAA1U"]
[Sun Aug 30 03:05:21.766254 2026] [security2:error] [pid 493992:tid 494151] [client 20.63.219.114:1344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/hello.php"] [unique_id "apPkQWbB9pEqk7z7RJl4WgAAAzs"]
[Sun Aug 30 03:05:21.770748 2026] [security2:error] [pid 493992:tid 494185] [client 20.104.50.220:33026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/marjan.php"] [unique_id "apPkQWbB9pEqk7z7RJl4XQAAA10"]
[Sun Aug 30 03:05:21.774159 2026] [security2:error] [pid 493992:tid 494156] [client 20.48.251.3:23482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/pouhg.php"] [unique_id "apPkQWbB9pEqk7z7RJl4YQAAA0A"]
[Sun Aug 30 03:05:21.779085 2026] [security2:error] [pid 493992:tid 494210] [client 158.23.147.79:63915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apPkQWbB9pEqk7z7RJl4ZAAAA3Y"]
[Sun Aug 30 03:05:21.805336 2026] [security2:error] [pid 493992:tid 494146] [client 20.220.10.235:4076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/wt.php"] [unique_id "apPkQWbB9pEqk7z7RJl4bAAAAzY"]
[Sun Aug 30 03:05:21.835842 2026] [security2:error] [pid 493992:tid 494148] [client 20.104.50.220:42764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/sos.php"] [unique_id "apPkQWbB9pEqk7z7RJl4dAAAAzg"]
[Sun Aug 30 03:05:21.846785 2026] [security2:error] [pid 493992:tid 494206] [client 20.104.50.220:5586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/admin/function.php"] [unique_id "apPkQWbB9pEqk7z7RJl4dwAAA3I"]
[Sun Aug 30 03:05:21.861952 2026] [security2:error] [pid 493992:tid 494217] [client 20.196.209.81:16852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/upgrade-temp-backup/themes/test.php"] [unique_id "apPkQWbB9pEqk7z7RJl4ewAAA30"]
[Sun Aug 30 03:05:21.863246 2026] [security2:error] [pid 493992:tid 494136] [client 20.48.251.3:50003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/test.config.php"] [unique_id "apPkQWbB9pEqk7z7RJl4fAAAAyw"]
[Sun Aug 30 03:05:21.874907 2026] [security2:error] [pid 493992:tid 494225] [client 158.23.147.79:63976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apPkQWbB9pEqk7z7RJl4gQAAA4U"]
[Sun Aug 30 03:05:21.886600 2026] [security2:error] [pid 493992:tid 494140] [client 158.23.147.79:62549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/NewFile.php/"] [unique_id "apPkQWbB9pEqk7z7RJl4iAAAAzA"]
[Sun Aug 30 03:05:21.917831 2026] [security2:error] [pid 493992:tid 494168] [client 20.104.50.220:62014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/goods.php"] [unique_id "apPkQWbB9pEqk7z7RJl4jAAAA0w"]
[Sun Aug 30 03:05:21.920845 2026] [security2:error] [pid 493992:tid 494151] [client 20.104.50.220:32295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/index4.php"] [unique_id "apPkQWbB9pEqk7z7RJl4jQAAAzs"]
[Sun Aug 30 03:05:21.950467 2026] [security2:error] [pid 493992:tid 494185] [client 20.48.251.3:64421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/motu.php"] [unique_id "apPkQWbB9pEqk7z7RJl4kQAAA10"]
[Sun Aug 30 03:05:21.961615 2026] [security2:error] [pid 493992:tid 494198] [client 20.104.50.220:29573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/saudishell.php"] [unique_id "apPkQWbB9pEqk7z7RJl4lQAAA2o"]
[Sun Aug 30 03:05:21.969706 2026] [security2:error] [pid 493992:tid 494197] [client 20.220.10.235:4062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/im.php"] [unique_id "apPkQWbB9pEqk7z7RJl4lwAAA2k"]
[Sun Aug 30 03:05:21.973426 2026] [security2:error] [pid 493992:tid 494130] [client 158.23.147.79:52931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apPkQWbB9pEqk7z7RJl4mQAAAyY"]
[Sun Aug 30 03:05:21.978873 2026] [security2:error] [pid 493992:tid 494229] [client 158.23.147.79:62291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-content/languages/about.php"] [unique_id "apPkQWbB9pEqk7z7RJl4mwAAA4k"]
[Sun Aug 30 03:05:21.986286 2026] [security2:error] [pid 493992:tid 494131] [client 20.104.18.15:32977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/radio.php"] [unique_id "apPkQWbB9pEqk7z7RJl4ngAAAyc"]
[Sun Aug 30 03:05:21.996137 2026] [security2:error] [pid 493992:tid 494126] [client 158.23.147.79:62539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/dropdown.php"] [unique_id "apPkQWbB9pEqk7z7RJl4oAAAAyI"]
[Sun Aug 30 03:05:22.013568 2026] [security2:error] [pid 493992:tid 494147] [client 20.104.18.15:31573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/wefile.php"] [unique_id "apPkQmbB9pEqk7z7RJl4qQAAAzc"]
[Sun Aug 30 03:05:22.027195 2026] [security2:error] [pid 493992:tid 494230] [client 40.83.93.50:18099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/fix.php"] [unique_id "apPkQmbB9pEqk7z7RJl4rAAAA4o"]
[Sun Aug 30 03:05:22.034080 2026] [security2:error] [pid 493992:tid 494191] [client 20.104.18.15:13758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/aa.php"] [unique_id "apPkQmbB9pEqk7z7RJl4rQAAA2M"]
[Sun Aug 30 03:05:22.071148 2026] [security2:error] [pid 493992:tid 494140] [client 158.23.147.79:63971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-content/banners/about.php"] [unique_id "apPkQmbB9pEqk7z7RJl4twAAAzA"]
[Sun Aug 30 03:05:22.072104 2026] [security2:error] [pid 493992:tid 494219] [client 20.48.251.3:52844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/avim.php"] [unique_id "apPkQmbB9pEqk7z7RJl4uAAAA38"]
[Sun Aug 30 03:05:22.078367 2026] [security2:error] [pid 493992:tid 494141] [client 68.155.159.216:59990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apPkQmbB9pEqk7z7RJl4uQAAAzE"]
[Sun Aug 30 03:05:22.113031 2026] [security2:error] [pid 493992:tid 494183] [client 158.23.147.79:62555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/.well-known/index.php"] [unique_id "apPkQmbB9pEqk7z7RJl4yQAAA1s"]
[Sun Aug 30 03:05:22.115679 2026] [security2:error] [pid 493992:tid 494174] [client 20.220.10.235:4066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/file.php"] [unique_id "apPkQmbB9pEqk7z7RJl4zAAAA1I"]
[Sun Aug 30 03:05:22.135674 2026] [security2:error] [pid 493992:tid 494208] [client 20.63.219.114:18121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/g.php"] [unique_id "apPkQmbB9pEqk7z7RJl4zQAAA3Q"]
[Sun Aug 30 03:05:22.146916 2026] [security2:error] [pid 493992:tid 494131] [client 158.23.147.79:63261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-admin/user/index.php"] [unique_id "apPkQmbB9pEqk7z7RJl4zwAAAyc"]
[Sun Aug 30 03:05:22.172972 2026] [authz_core:error] [pid 493992:tid 494126] [client 66.249.66.67:58148] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:22.173278 2026] [authz_core:error] [pid 493992:tid 494126] [client 66.249.66.67:58148] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:22.173969 2026] [security2:error] [pid 493992:tid 494237] [client 158.23.147.79:63913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apPkQmbB9pEqk7z7RJl40wAAA5E"]
[Sun Aug 30 03:05:22.233384 2026] [security2:error] [pid 493992:tid 494160] [client 216.73.216.128:27548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPkQmbB9pEqk7z7RJl46AAAA0Q"]
[Sun Aug 30 03:05:22.242521 2026] [security2:error] [pid 493992:tid 494213] [client 20.104.49.130:65002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.topatrust.com"] [uri "/ws78.php"] [unique_id "apPkQmbB9pEqk7z7RJl47AAAA3k"]
[Sun Aug 30 03:05:22.246853 2026] [security2:error] [pid 493992:tid 494204] [client 68.155.159.216:59357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/images/index.php"] [unique_id "apPkQmbB9pEqk7z7RJl47gAAA3A"]
[Sun Aug 30 03:05:22.250970 2026] [security2:error] [pid 493992:tid 494235] [client 158.23.147.79:52944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-includes/plugins.php"] [unique_id "apPkQmbB9pEqk7z7RJl47wAAA48"]
[Sun Aug 30 03:05:22.262899 2026] [security2:error] [pid 493992:tid 494189] [client 20.196.209.81:17728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/upgrade-temp-backup/themes/wp-links-opml.php"] [unique_id "apPkQmbB9pEqk7z7RJl49QAAA2E"]
[Sun Aug 30 03:05:22.267087 2026] [security2:error] [pid 493992:tid 494138] [client 20.104.18.15:43997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/key.php"] [unique_id "apPkQmbB9pEqk7z7RJl49wAAAy4"]
[Sun Aug 30 03:05:22.279426 2026] [security2:error] [pid 493992:tid 494122] [client 20.48.251.3:54845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/pouhg.php"] [unique_id "apPkQmbB9pEqk7z7RJl5AgAAAx4"]
[Sun Aug 30 03:05:22.283665 2026] [security2:error] [pid 493992:tid 494212] [client 20.220.10.235:4051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/ca.php"] [unique_id "apPkQmbB9pEqk7z7RJl5BAAAA3g"]
[Sun Aug 30 03:05:22.303156 2026] [security2:error] [pid 493992:tid 494166] [client 20.151.200.44:23592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/ssh3ll.php"] [unique_id "apPkQmbB9pEqk7z7RJl5CwAAA0o"]
[Sun Aug 30 03:05:22.307331 2026] [security2:error] [pid 493992:tid 494142] [client 158.23.147.79:63962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/asd.php"] [unique_id "apPkQmbB9pEqk7z7RJl5DAAAAzI"]
[Sun Aug 30 03:05:22.367129 2026] [security2:error] [pid 493992:tid 494193] [client 158.23.147.79:63269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-content/themes/too.php"] [unique_id "apPkQmbB9pEqk7z7RJl5FAAAA2U"]
[Sun Aug 30 03:05:22.408600 2026] [security2:error] [pid 493992:tid 494136] [client 158.23.147.79:63922] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/1.php"] [unique_id "apPkQmbB9pEqk7z7RJl5IAAAAyw"]
[Sun Aug 30 03:05:22.408694 2026] [security2:error] [pid 493992:tid 494136] [client 158.23.147.79:63922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/1.php"] [unique_id "apPkQmbB9pEqk7z7RJl5IAAAAyw"]
[Sun Aug 30 03:05:22.429009 2026] [security2:error] [pid 493992:tid 494213] [client 20.220.10.235:4073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/pb.php"] [unique_id "apPkQmbB9pEqk7z7RJl5KAAAA3k"]
[Sun Aug 30 03:05:22.444799 2026] [authz_core:error] [pid 493992:tid 494234] [client 66.249.66.32:58039] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:22.445066 2026] [authz_core:error] [pid 493992:tid 494234] [client 66.249.66.32:58039] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:22.475955 2026] [security2:error] [pid 493992:tid 494162] [client 20.48.251.3:44308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/gnmlc.php"] [unique_id "apPkQmbB9pEqk7z7RJl5RAAAA0Y"]
[Sun Aug 30 03:05:22.492349 2026] [security2:error] [pid 493992:tid 494202] [client 158.23.147.79:40924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/cgi-bin/index.php"] [unique_id "apPkQmbB9pEqk7z7RJl5SAAAA24"]
[Sun Aug 30 03:05:22.500092 2026] [security2:error] [pid 493992:tid 494128] [client 20.63.219.114:18514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/cc.php"] [unique_id "apPkQmbB9pEqk7z7RJl5SwAAAyQ"]
[Sun Aug 30 03:05:22.516924 2026] [security2:error] [pid 493992:tid 494123] [client 40.83.93.50:9091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/alfa.php"] [unique_id "apPkQmbB9pEqk7z7RJl5TwAAAx8"]
[Sun Aug 30 03:05:22.535410 2026] [security2:error] [pid 493992:tid 494136] [client 158.23.147.79:63901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/ws.php"] [unique_id "apPkQmbB9pEqk7z7RJl5UwAAAyw"]
[Sun Aug 30 03:05:22.556085 2026] [security2:error] [pid 493992:tid 494125] [client 20.220.10.235:4083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/pk.php"] [unique_id "apPkQmbB9pEqk7z7RJl5WgAAAyE"]
[Sun Aug 30 03:05:22.587681 2026] [security2:error] [pid 493992:tid 494209] [client 158.23.147.79:63291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/radio.php"] [unique_id "apPkQmbB9pEqk7z7RJl5agAAA3U"]
[Sun Aug 30 03:05:22.607132 2026] [security2:error] [pid 493992:tid 494198] [client 216.73.216.128:10586] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPkQmbB9pEqk7z7RJl5bwAAA2o"]
[Sun Aug 30 03:05:22.616696 2026] [security2:error] [pid 493992:tid 494191] [client 158.23.147.79:62502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apPkQmbB9pEqk7z7RJl5cgAAA2M"]
[Sun Aug 30 03:05:22.637390 2026] [security2:error] [pid 493992:tid 494165] [client 158.23.147.79:63961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-includes/css/index.php"] [unique_id "apPkQmbB9pEqk7z7RJl5eAAAA0k"]
[Sun Aug 30 03:05:22.642187 2026] [security2:error] [pid 493992:tid 494240] [client 158.23.147.79:26607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPkQmbB9pEqk7z7RJl5egAAA5Q"]
[Sun Aug 30 03:05:22.684756 2026] [security2:error] [pid 493992:tid 494173] [client 20.220.10.235:4017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/ft.php"] [unique_id "apPkQmbB9pEqk7z7RJl5gQAAA1E"]
[Sun Aug 30 03:05:22.685032 2026] [security2:error] [pid 493992:tid 494244] [client 20.196.209.81:16879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/upgrade-temp-backup/themes/wp-settings.php"] [unique_id "apPkQmbB9pEqk7z7RJl5gAAAA5g"]
[Sun Aug 30 03:05:22.754356 2026] [security2:error] [pid 493992:tid 494227] [client 20.104.18.15:9201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/gulu.php"] [unique_id "apPkQmbB9pEqk7z7RJl5mAAAA4c"]
[Sun Aug 30 03:05:22.757985 2026] [security2:error] [pid 493992:tid 494212] [client 158.23.147.79:62557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPkQmbB9pEqk7z7RJl5mQAAA3g"]
[Sun Aug 30 03:05:22.766371 2026] [security2:error] [pid 493992:tid 494134] [client 68.155.159.216:19433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-includes/js/index.php"] [unique_id "apPkQmbB9pEqk7z7RJl5nAAAAyo"]
[Sun Aug 30 03:05:22.785952 2026] [security2:error] [pid 493992:tid 494245] [client 158.23.147.79:63983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apPkQmbB9pEqk7z7RJl5owAAA5k"]
[Sun Aug 30 03:05:22.798046 2026] [authz_core:error] [pid 493992:tid 494160] [client 74.7.243.204:34658] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fman%2Fman7
[Sun Aug 30 03:05:22.798319 2026] [authz_core:error] [pid 493992:tid 494160] [client 74.7.243.204:34658] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fman%2Fman7
[Sun Aug 30 03:05:22.821800 2026] [security2:error] [pid 493992:tid 494177] [client 20.220.10.235:4009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/wp-ver.php"] [unique_id "apPkQmbB9pEqk7z7RJl5sQAAA1U"]
[Sun Aug 30 03:05:22.840487 2026] [security2:error] [pid 493992:tid 494186] [client 20.104.50.220:27100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/mail.php"] [unique_id "apPkQmbB9pEqk7z7RJl5uAAAA14"]
[Sun Aug 30 03:05:22.871987 2026] [security2:error] [pid 493992:tid 494141] [client 20.63.219.114:18503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/f35.php"] [unique_id "apPkQmbB9pEqk7z7RJl5wAAAAzE"]
[Sun Aug 30 03:05:22.873774 2026] [security2:error] [pid 493992:tid 494221] [client 158.23.147.79:26585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-includes/content.php"] [unique_id "apPkQmbB9pEqk7z7RJl5wQAAA4E"]
[Sun Aug 30 03:05:22.903272 2026] [security2:error] [pid 493992:tid 494239] [client 158.23.147.79:63939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-content/cong.php"] [unique_id "apPkQmbB9pEqk7z7RJl50gAAA5M"]
[Sun Aug 30 03:05:22.903429 2026] [security2:error] [pid 493992:tid 494209] [client 158.23.147.79:63282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/makeasmtp.php"] [unique_id "apPkQmbB9pEqk7z7RJl50wAAA3U"]
[Sun Aug 30 03:05:22.910146 2026] [security2:error] [pid 493992:tid 494134] [client 20.104.50.220:46157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/26.php"] [unique_id "apPkQmbB9pEqk7z7RJl51wAAAyo"]
[Sun Aug 30 03:05:22.912794 2026] [security2:error] [pid 493992:tid 494247] [client 20.48.251.3:44201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/phpversion.php"] [unique_id "apPkQmbB9pEqk7z7RJl52AAAA5s"]
[Sun Aug 30 03:05:22.919664 2026] [security2:error] [pid 493992:tid 494184] [client 20.104.50.220:33060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/on.php"] [unique_id "apPkQmbB9pEqk7z7RJl52QAAA1w"]
[Sun Aug 30 03:05:22.938802 2026] [security2:error] [pid 493992:tid 494165] [client 158.23.147.79:62517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/goat1.php"] [unique_id "apPkQmbB9pEqk7z7RJl53AAAA0k"]
[Sun Aug 30 03:05:22.954377 2026] [security2:error] [pid 493992:tid 494210] [client 20.220.10.235:4026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/ah24.php"] [unique_id "apPkQmbB9pEqk7z7RJl53wAAA3Y"]
[Sun Aug 30 03:05:22.969630 2026] [security2:error] [pid 493992:tid 494122] [client 158.23.147.79:40897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-admin/css/index.php"] [unique_id "apPkQmbB9pEqk7z7RJl54gAAAx4"]
[Sun Aug 30 03:05:22.974344 2026] [security2:error] [pid 493992:tid 494153] [client 20.48.251.3:34605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/tax.php"] [unique_id "apPkQmbB9pEqk7z7RJl55AAAAz0"]
[Sun Aug 30 03:05:22.984597 2026] [security2:error] [pid 493992:tid 494157] [client 20.104.50.220:5522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPkQmbB9pEqk7z7RJl55gAAA0E"]
[Sun Aug 30 03:05:22.992489 2026] [security2:error] [pid 493992:tid 494176] [client 20.151.200.44:62982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/motu.php"] [unique_id "apPkQmbB9pEqk7z7RJl56QAAA1Q"]
[Sun Aug 30 03:05:23.003784 2026] [security2:error] [pid 493992:tid 494186] [client 20.104.50.220:63490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/print.php"] [unique_id "apPkQ2bB9pEqk7z7RJl56wAAA14"]
[Sun Aug 30 03:05:23.005595 2026] [security2:error] [pid 493992:tid 494202] [client 20.48.251.3:55477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/gecko-litespeed.php"] [unique_id "apPkQ2bB9pEqk7z7RJl57AAAA24"]
[Sun Aug 30 03:05:23.040860 2026] [security2:error] [pid 493992:tid 494193] [client 158.23.147.79:63943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPkQ2bB9pEqk7z7RJl58QAAA2U"]
[Sun Aug 30 03:05:23.041622 2026] [security2:error] [pid 493992:tid 494126] [client 40.83.93.50:18050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/wp-blog-header.php"] [unique_id "apPkQ2bB9pEqk7z7RJl58gAAAyI"]
[Sun Aug 30 03:05:23.048938 2026] [security2:error] [pid 493992:tid 494222] [client 158.23.147.79:52930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apPkQ2bB9pEqk7z7RJl59AAAA4I"]
[Sun Aug 30 03:05:23.070047 2026] [security2:error] [pid 493992:tid 494205] [client 20.104.50.220:59552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/codrs.php"] [unique_id "apPkQ2bB9pEqk7z7RJl5-wAAA3E"]
[Sun Aug 30 03:05:23.081985 2026] [security2:error] [pid 493992:tid 494129] [client 20.220.10.235:3968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPkQ2bB9pEqk7z7RJl5_wAAAyU"]
[Sun Aug 30 03:05:23.115983 2026] [security2:error] [pid 493992:tid 494247] [client 20.104.50.220:31881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/index5.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6EwAAA5s"]
[Sun Aug 30 03:05:23.122470 2026] [security2:error] [pid 493992:tid 494172] [client 158.23.147.79:26583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-admin/images/index.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6FQAAA1A"]
[Sun Aug 30 03:05:23.124046 2026] [security2:error] [pid 493992:tid 494219] [client 20.48.251.3:6992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/public/mah.php.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6FgAAA38"]
[Sun Aug 30 03:05:23.125441 2026] [security2:error] [pid 493992:tid 494228] [client 20.104.18.15:32999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/one.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6FwAAA4g"]
[Sun Aug 30 03:05:23.155262 2026] [security2:error] [pid 493992:tid 494124] [client 20.104.18.15:31637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/blog.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6GwAAAyA"]
[Sun Aug 30 03:05:23.160098 2026] [security2:error] [pid 493992:tid 494173] [client 20.104.50.220:62826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/sosyeteshell.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6HgAAA1E"]
[Sun Aug 30 03:05:23.175150 2026] [security2:error] [pid 493992:tid 494201] [client 158.23.147.79:62509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6IwAAA20"]
[Sun Aug 30 03:05:23.186053 2026] [authz_core:error] [pid 493992:tid 494165] [client 66.249.66.32:61584] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:23.186521 2026] [authz_core:error] [pid 493992:tid 494165] [client 66.249.66.32:61584] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:23.201008 2026] [security2:error] [pid 493992:tid 494128] [client 158.23.147.79:62313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6LAAAAyQ"]
[Sun Aug 30 03:05:23.216482 2026] [security2:error] [pid 493992:tid 494221] [client 68.155.159.216:59967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6MQAAA4E"]
[Sun Aug 30 03:05:23.218383 2026] [security2:error] [pid 493992:tid 494175] [client 158.23.147.79:26589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-includes/index.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6NAAAA1M"]
[Sun Aug 30 03:05:23.218838 2026] [security2:error] [pid 493992:tid 494155] [client 20.196.209.81:21173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/upgrade/about.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6NQAAAz8"]
[Sun Aug 30 03:05:23.220407 2026] [security2:error] [pid 493992:tid 494136] [client 20.220.10.235:4058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ballyyahoo.com"] [uri "/waf.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6NgAAAyw"]
[Sun Aug 30 03:05:23.225236 2026] [security2:error] [pid 493992:tid 494148] [client 20.63.219.114:15148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/classsmtps.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6NwAAAzg"]
[Sun Aug 30 03:05:23.226926 2026] [security2:error] [pid 493992:tid 494242] [client 158.23.147.79:63253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6OAAAA5Y"]
[Sun Aug 30 03:05:23.243960 2026] [security2:error] [pid 493992:tid 494199] [client 20.48.251.3:55797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/nw.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6PwAAA2s"]
[Sun Aug 30 03:05:23.248677 2026] [security2:error] [pid 493992:tid 494131] [client 51.38.230.115:54636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.230.38.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "buythebookbookstore.com"] [uri "/wp-login.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6OwAAAyc"]
[Sun Aug 30 03:05:23.339862 2026] [security2:error] [pid 493992:tid 494166] [client 74.7.243.204:34658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/blog/Linux-PAM_ADG.html"] [unique_id "apPkQ2bB9pEqk7z7RJl6XwAAA0o"], referer: http://mail.letter7brands.com/blog/Linux-PAM_ADG.html?p=%2Fhome4%2Fletter7%2Fpublic_html%2Fwp-includes%2Fphp-ai-client%2Fsrc%2FProviders%2FContracts
[Sun Aug 30 03:05:23.378752 2026] [security2:error] [pid 493992:tid 494155] [client 158.23.147.79:40959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/mah.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6bQAAAz8"]
[Sun Aug 30 03:05:23.392716 2026] [security2:error] [pid 493992:tid 494129] [client 158.23.147.79:62541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-content/languages/about.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6cQAAAyU"]
[Sun Aug 30 03:05:23.400885 2026] [authz_core:error] [pid 493992:tid 494168] [client 66.249.66.75:43956] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:23.401356 2026] [authz_core:error] [pid 493992:tid 494168] [client 66.249.66.75:43956] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:23.410538 2026] [security2:error] [pid 493992:tid 494183] [client 20.151.200.44:62990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/wefile.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6dwAAA1s"]
[Sun Aug 30 03:05:23.422516 2026] [security2:error] [pid 493992:tid 494145] [client 20.104.49.130:58229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/wp-css.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6fQAAAzU"]
[Sun Aug 30 03:05:23.433689 2026] [security2:error] [pid 493992:tid 494138] [client 20.104.18.15:44016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/chosen.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6hQAAAy4"]
[Sun Aug 30 03:05:23.446809 2026] [security2:error] [pid 493992:tid 494219] [client 20.48.251.3:6980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/doc.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6jgAAA38"]
[Sun Aug 30 03:05:23.446914 2026] [security2:error] [pid 493992:tid 494186] [client 158.23.147.79:63915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6jQAAA14"]
[Sun Aug 30 03:05:23.466776 2026] [security2:error] [pid 493992:tid 494198] [client 20.104.49.130:59532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.infinitelearners.com"] [uri "/edit.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6mwAAA2o"]
[Sun Aug 30 03:05:23.484467 2026] [security2:error] [pid 493992:tid 494226] [client 68.155.159.216:9263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-includes/widgets/index.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6ngAAA4Y"]
[Sun Aug 30 03:05:23.511461 2026] [security2:error] [pid 493992:tid 494184] [client 20.151.200.44:37868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/wk/index.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6oQAAA1w"]
[Sun Aug 30 03:05:23.515740 2026] [security2:error] [pid 493992:tid 494148] [client 20.104.50.220:62820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/web-setting.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6owAAAzg"]
[Sun Aug 30 03:05:23.529348 2026] [security2:error] [pid 493992:tid 494213] [client 158.23.147.79:62571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-admin/network/index.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6qQAAA3k"]
[Sun Aug 30 03:05:23.537587 2026] [security2:error] [pid 493992:tid 494133] [client 20.48.251.3:54747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/phpversion.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6rQAAAyk"]
[Sun Aug 30 03:05:23.554017 2026] [rewrite:warn] [pid 493992:tid 494027] AH00665: RewriteCond: NoCase option for non-regex pattern '-d' is not supported and will be ignored. (/home3/keilan/public_html/.htaccess:12)
[Sun Aug 30 03:05:23.554035 2026] [rewrite:warn] [pid 493992:tid 494027] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home3/keilan/public_html/.htaccess:13)
[Sun Aug 30 03:05:23.560801 2026] [security2:error] [pid 493992:tid 494192] [client 40.83.93.50:12056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/s.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6swAAA2Q"]
[Sun Aug 30 03:05:23.574852 2026] [security2:error] [pid 493992:tid 494205] [client 20.63.219.114:15138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/install.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6uAAAA3E"]
[Sun Aug 30 03:05:23.584503 2026] [security2:error] [pid 493992:tid 494176] [client 158.23.147.79:63945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-content/radio.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6vgAAA1Q"]
[Sun Aug 30 03:05:23.620138 2026] [security2:error] [pid 493992:tid 494222] [client 158.23.147.79:62550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-content/banners/about.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6xwAAA4I"]
[Sun Aug 30 03:05:23.620348 2026] [security2:error] [pid 493992:tid 494207] [client 20.196.209.81:21125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ideeforza.webnet-hosting4.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6yAAAA3M"]
[Sun Aug 30 03:05:23.673685 2026] [security2:error] [pid 493992:tid 494162] [client 20.151.200.44:46924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/bge.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6zwAAA0Y"]
[Sun Aug 30 03:05:23.694562 2026] [security2:error] [pid 493992:tid 494127] [client 158.23.147.79:26600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-blog-header.php"] [unique_id "apPkQ2bB9pEqk7z7RJl62wAAAyM"]
[Sun Aug 30 03:05:23.706732 2026] [authz_core:error] [pid 493992:tid 494146] [client 66.249.66.68:36920] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:23.707019 2026] [authz_core:error] [pid 493992:tid 494146] [client 66.249.66.68:36920] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:23.754863 2026] [security2:error] [pid 493992:tid 494247] [client 158.23.147.79:63973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apPkQ2bB9pEqk7z7RJl67wAAA5s"]
[Sun Aug 30 03:05:23.791433 2026] [security2:error] [pid 493992:tid 494210] [client 20.151.200.44:23578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/Contrller.php"] [unique_id "apPkQ2bB9pEqk7z7RJl6_wAAA3Y"]
[Sun Aug 30 03:05:23.825845 2026] [security2:error] [pid 493992:tid 494164] [client 216.73.216.128:35105] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPkQ2bB9pEqk7z7RJl7BQAAA0g"]
[Sun Aug 30 03:05:23.854091 2026] [security2:error] [pid 493992:tid 494225] [client 20.48.251.3:64415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/btx25.php"] [unique_id "apPkQ2bB9pEqk7z7RJl7EAAAA4U"]
[Sun Aug 30 03:05:23.868757 2026] [security2:error] [pid 493992:tid 494194] [client 158.23.147.79:63993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/login.php"] [unique_id "apPkQ2bB9pEqk7z7RJl7FQAAA2Y"]
[Sun Aug 30 03:05:23.873228 2026] [authz_core:error] [pid 493992:tid 494228] [client 74.7.243.204:34666] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fhome4%2Fletter7%2Fpublic_html%2Fwp-content%2Fuploads%2F2014%2F06
[Sun Aug 30 03:05:23.873529 2026] [security2:error] [pid 493992:tid 494236] [client 68.155.159.216:54757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-content/index.php"] [unique_id "apPkQ2bB9pEqk7z7RJl7GAAAA5A"]
[Sun Aug 30 03:05:23.873571 2026] [authz_core:error] [pid 493992:tid 494228] [client 74.7.243.204:34666] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fhome4%2Fletter7%2Fpublic_html%2Fwp-content%2Fuploads%2F2014%2F06
[Sun Aug 30 03:05:23.881271 2026] [rewrite:warn] [pid 493992:tid 494036] AH00665: RewriteCond: NoCase option for non-regex pattern '-d' is not supported and will be ignored. (/home3/keilan/public_html/.htaccess:12)
[Sun Aug 30 03:05:23.881283 2026] [rewrite:warn] [pid 493992:tid 494036] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home3/keilan/public_html/.htaccess:13)
[Sun Aug 30 03:05:23.902132 2026] [security2:error] [pid 493992:tid 494240] [client 20.104.18.15:9128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/replace.php"] [unique_id "apPkQ2bB9pEqk7z7RJl7KQAAA5Q"]
[Sun Aug 30 03:05:23.909357 2026] [security2:error] [pid 493992:tid 494151] [client 20.104.18.15:13568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/img.php"] [unique_id "apPkQ2bB9pEqk7z7RJl7LAAAAzs"]
[Sun Aug 30 03:05:23.926139 2026] [security2:error] [pid 493992:tid 494131] [client 158.23.147.79:62470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apPkQ2bB9pEqk7z7RJl7MQAAAyc"]
[Sun Aug 30 03:05:23.932169 2026] [authz_core:error] [pid 493992:tid 494150] [client 216.73.216.128:35105] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:23.932466 2026] [authz_core:error] [pid 493992:tid 494150] [client 216.73.216.128:35105] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:23.957008 2026] [security2:error] [pid 493992:tid 494237] [client 20.63.219.114:9635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/wp.php"] [unique_id "apPkQ2bB9pEqk7z7RJl7NQAAA5E"]
[Sun Aug 30 03:05:23.968169 2026] [security2:error] [pid 493992:tid 494186] [client 158.23.147.79:40954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apPkQ2bB9pEqk7z7RJl7OgAAA14"]
[Sun Aug 30 03:05:23.973083 2026] [security2:error] [pid 493992:tid 494191] [client 20.151.200.44:23570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/file66.php"] [unique_id "apPkQ2bB9pEqk7z7RJl7OwAAA2M"]
[Sun Aug 30 03:05:23.981913 2026] [security2:error] [pid 493992:tid 494198] [client 20.104.50.220:27397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/images/yes.php"] [unique_id "apPkQ2bB9pEqk7z7RJl7PQAAA2o"]
[Sun Aug 30 03:05:24.010194 2026] [security2:error] [pid 493992:tid 494217] [client 158.23.147.79:62553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apPkRGbB9pEqk7z7RJl7RgAAA30"]
[Sun Aug 30 03:05:24.032462 2026] [security2:error] [pid 493992:tid 494193] [client 40.83.93.50:12040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/php.php"] [unique_id "apPkRGbB9pEqk7z7RJl7UgAAA2U"]
[Sun Aug 30 03:05:24.035215 2026] [security2:error] [pid 493992:tid 494236] [client 20.104.50.220:47044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/2index.php"] [unique_id "apPkRGbB9pEqk7z7RJl7UwAAA5A"]
[Sun Aug 30 03:05:24.049619 2026] [security2:error] [pid 493992:tid 494165] [client 20.48.251.3:23443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/adminfus.php"] [unique_id "apPkRGbB9pEqk7z7RJl7VQAAA0k"]
[Sun Aug 30 03:05:24.049626 2026] [security2:error] [pid 493992:tid 494161] [client 158.23.147.79:63936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/hehehehe.php"] [unique_id "apPkRGbB9pEqk7z7RJl7VAAAA0U"]
[Sun Aug 30 03:05:24.058002 2026] [security2:error] [pid 493992:tid 494221] [client 20.104.50.220:33297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/mari.php"] [unique_id "apPkRGbB9pEqk7z7RJl7WgAAA4E"]
[Sun Aug 30 03:05:24.123044 2026] [security2:error] [pid 493992:tid 494210] [client 20.104.50.220:5189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/css/colors/blue/index.php"] [unique_id "apPkRGbB9pEqk7z7RJl7cQAAA3Y"]
[Sun Aug 30 03:05:24.145586 2026] [security2:error] [pid 493992:tid 494198] [client 20.48.251.3:49997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/goods.php"] [unique_id "apPkRGbB9pEqk7z7RJl7cgAAA2o"]
[Sun Aug 30 03:05:24.159853 2026] [security2:error] [pid 493992:tid 494246] [client 20.104.50.220:42031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/pdi.php"] [unique_id "apPkRGbB9pEqk7z7RJl7dQAAA5o"]
[Sun Aug 30 03:05:24.164288 2026] [security2:error] [pid 493992:tid 494242] [client 158.23.147.79:40314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-admin/user/index.php"] [unique_id "apPkRGbB9pEqk7z7RJl7dgAAA5Y"]
[Sun Aug 30 03:05:24.169655 2026] [security2:error] [pid 493992:tid 494201] [client 20.48.251.3:59107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPkRGbB9pEqk7z7RJl7ewAAA20"]
[Sun Aug 30 03:05:24.206984 2026] [security2:error] [pid 493992:tid 494206] [client 20.48.251.3:44371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/koiy.php"] [unique_id "apPkRGbB9pEqk7z7RJl7kAAAA3I"]
[Sun Aug 30 03:05:24.207533 2026] [security2:error] [pid 493992:tid 494196] [client 158.23.147.79:63883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apPkRGbB9pEqk7z7RJl7kQAAA2g"]
[Sun Aug 30 03:05:24.211338 2026] [authz_core:error] [pid 493992:tid 494129] [client 216.73.216.128:35105] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:24.211761 2026] [authz_core:error] [pid 493992:tid 494129] [client 216.73.216.128:35105] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:24.235300 2026] [security2:error] [pid 493992:tid 494158] [client 20.104.50.220:61419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/jingan.php"] [unique_id "apPkRGbB9pEqk7z7RJl7mAAAA0I"]
[Sun Aug 30 03:05:24.245903 2026] [security2:error] [pid 493992:tid 494176] [client 20.151.200.44:63584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/blnux.php"] [unique_id "apPkRGbB9pEqk7z7RJl7nAAAA1Q"]
[Sun Aug 30 03:05:24.251629 2026] [authz_core:error] [pid 493992:tid 494229] [client 66.249.66.36:34932] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:24.252144 2026] [authz_core:error] [pid 493992:tid 494229] [client 66.249.66.36:34932] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:24.256159 2026] [security2:error] [pid 493992:tid 494187] [client 20.48.251.3:64481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/zaza.php"] [unique_id "apPkRGbB9pEqk7z7RJl7nwAAA18"]
[Sun Aug 30 03:05:24.269223 2026] [security2:error] [pid 493992:tid 494153] [client 20.104.50.220:31915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/index6.php"] [unique_id "apPkRGbB9pEqk7z7RJl7pgAAAz0"]
[Sun Aug 30 03:05:24.270700 2026] [security2:error] [pid 493992:tid 494181] [client 216.244.66.238:52286] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arcaneguardians.com"] [uri "/tdbhc/convert-struct-to-matrix---matlab"] [unique_id "apPkRGbB9pEqk7z7RJl7qAAAA1k"]
[Sun Aug 30 03:05:24.270775 2026] [security2:error] [pid 493992:tid 494181] [client 216.244.66.238:52286] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "arcaneguardians.com"] [uri "/tdbhc/convert-struct-to-matrix---matlab"] [unique_id "apPkRGbB9pEqk7z7RJl7qAAAA1k"]
[Sun Aug 30 03:05:24.276044 2026] [security2:error] [pid 493992:tid 494134] [client 20.151.200.44:47313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/zoz.php"] [unique_id "apPkRGbB9pEqk7z7RJl7rAAAAyo"]
[Sun Aug 30 03:05:24.278373 2026] [security2:error] [pid 493992:tid 494140] [client 20.104.18.15:33022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/503.php"] [unique_id "apPkRGbB9pEqk7z7RJl7rgAAAzA"]
[Sun Aug 30 03:05:24.285764 2026] [security2:error] [pid 493992:tid 494198] [client 20.104.18.15:31649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/wp-admin/js/wp-load.php"] [unique_id "apPkRGbB9pEqk7z7RJl7sAAAA2o"]
[Sun Aug 30 03:05:24.297672 2026] [security2:error] [pid 493992:tid 494199] [client 20.104.50.220:52839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/tryagshell.php"] [unique_id "apPkRGbB9pEqk7z7RJl7tQAAA2s"]
[Sun Aug 30 03:05:24.317690 2026] [security2:error] [pid 493992:tid 494217] [client 158.23.147.79:40311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-includes/plugins.php"] [unique_id "apPkRGbB9pEqk7z7RJl7vQAAA30"]
[Sun Aug 30 03:05:24.329704 2026] [security2:error] [pid 493992:tid 494124] [client 20.63.219.114:1389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/error.php"] [unique_id "apPkRGbB9pEqk7z7RJl7vwAAAyA"]
[Sun Aug 30 03:05:24.332118 2026] [security2:error] [pid 493992:tid 494249] [client 158.23.147.79:63251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/asd.php"] [unique_id "apPkRGbB9pEqk7z7RJl7wAAAA50"]
[Sun Aug 30 03:05:24.332677 2026] [security2:error] [pid 493992:tid 494236] [client 158.23.147.79:63890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-content/admin.php"] [unique_id "apPkRGbB9pEqk7z7RJl7wQAAA5A"]
[Sun Aug 30 03:05:24.337129 2026] [rewrite:warn] [pid 493992:tid 494045] AH00665: RewriteCond: NoCase option for non-regex pattern '-d' is not supported and will be ignored. (/home3/keilan/public_html/.htaccess:12)
[Sun Aug 30 03:05:24.337146 2026] [rewrite:warn] [pid 493992:tid 494045] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home3/keilan/public_html/.htaccess:13)
[Sun Aug 30 03:05:24.350603 2026] [security2:error] [pid 493992:tid 494145] [client 68.155.159.216:60017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/dropdown.php"] [unique_id "apPkRGbB9pEqk7z7RJl7xgAAAzU"]
[Sun Aug 30 03:05:24.394320 2026] [security2:error] [pid 493992:tid 494215] [client 20.48.251.3:55793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/product.php"] [unique_id "apPkRGbB9pEqk7z7RJl71gAAA3s"]
[Sun Aug 30 03:05:24.435195 2026] [security2:error] [pid 493992:tid 494155] [client 20.104.49.130:45738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.katbacon.com"] [uri "/mh.php"] [unique_id "apPkRGbB9pEqk7z7RJl75QAAAz8"]
[Sun Aug 30 03:05:24.440249 2026] [security2:error] [pid 493992:tid 494208] [client 158.23.147.79:63995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/xmlrpc.php"] [unique_id "apPkRGbB9pEqk7z7RJl76AAAA3Q"]
[Sun Aug 30 03:05:24.480135 2026] [security2:error] [pid 493992:tid 494124] [client 158.23.147.79:26566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apPkRGbB9pEqk7z7RJl7_gAAAyA"]
[Sun Aug 30 03:05:24.522786 2026] [security2:error] [pid 493992:tid 494171] [client 40.83.93.50:18098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/system_log.php"] [unique_id "apPkRGbB9pEqk7z7RJl8DAAAA08"]
[Sun Aug 30 03:05:24.530184 2026] [security2:error] [pid 493992:tid 494224] [client 158.23.147.79:62565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/.well-knownold/index.php"] [unique_id "apPkRGbB9pEqk7z7RJl8DwAAA4Q"]
[Sun Aug 30 03:05:24.534502 2026] [security2:error] [pid 493992:tid 494150] [client 158.23.147.79:63996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/atomlib.php"] [unique_id "apPkRGbB9pEqk7z7RJl8EQAAAzo"]
[Sun Aug 30 03:05:24.554204 2026] [security2:error] [pid 493992:tid 494241] [client 20.151.200.44:63005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/attack.php"] [unique_id "apPkRGbB9pEqk7z7RJl8EwAAA5U"]
[Sun Aug 30 03:05:24.585774 2026] [security2:error] [pid 493992:tid 494201] [client 20.104.18.15:43300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/file1221.php"] [unique_id "apPkRGbB9pEqk7z7RJl8HgAAA20"]
[Sun Aug 30 03:05:24.590444 2026] [security2:error] [pid 493992:tid 494190] [client 74.7.243.204:34666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/cms/"] [unique_id "apPkRGbB9pEqk7z7RJl8IAAAA2I"], referer: http://mail.letter7brands.com/cms/?p=%2F%2Fetc
[Sun Aug 30 03:05:24.592044 2026] [security2:error] [pid 493992:tid 494199] [client 158.23.147.79:26523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/goat1.php"] [unique_id "apPkRGbB9pEqk7z7RJl8IQAAA2s"]
[Sun Aug 30 03:05:24.605162 2026] [authz_core:error] [pid 493992:tid 494205] [client 66.249.66.70:49750] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:24.605633 2026] [authz_core:error] [pid 493992:tid 494205] [client 66.249.66.70:49750] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:24.645607 2026] [security2:error] [pid 493992:tid 494160] [client 158.23.147.79:63883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/lv.php"] [unique_id "apPkRGbB9pEqk7z7RJl8NwAAA0Q"]
[Sun Aug 30 03:05:24.663238 2026] [security2:error] [pid 493992:tid 494163] [client 20.104.50.220:52818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-ettoyag.php"] [unique_id "apPkRGbB9pEqk7z7RJl8OQAAA0c"]
[Sun Aug 30 03:05:24.682989 2026] [security2:error] [pid 493992:tid 494193] [client 68.155.159.216:59339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apPkRGbB9pEqk7z7RJl8PAAAA2U"]
[Sun Aug 30 03:05:24.684135 2026] [security2:error] [pid 493992:tid 494139] [client 20.63.219.114:1368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/profile.php"] [unique_id "apPkRGbB9pEqk7z7RJl8PgAAAy8"]
[Sun Aug 30 03:05:24.697724 2026] [security2:error] [pid 493992:tid 494129] [client 20.48.251.3:46248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/adminfus.php"] [unique_id "apPkRGbB9pEqk7z7RJl8RAAAAyU"]
[Sun Aug 30 03:05:24.704335 2026] [authz_core:error] [pid 493992:tid 494151] [client 66.249.66.72:58418] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:24.704595 2026] [authz_core:error] [pid 493992:tid 494151] [client 66.249.66.72:58418] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:24.722073 2026] [security2:error] [pid 493992:tid 494208] [client 158.23.147.79:40297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apPkRGbB9pEqk7z7RJl8TQAAA3Q"]
[Sun Aug 30 03:05:24.794571 2026] [security2:error] [pid 493992:tid 494166] [client 158.23.147.79:63916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apPkRGbB9pEqk7z7RJl8ZgAAA0o"]
[Sun Aug 30 03:05:24.836328 2026] [security2:error] [pid 493992:tid 494037] [remote 66.116.251.167:56408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.251.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "calchampsoccer.org"] [uri "/wp-login.php"] [unique_id "apPkRGbB9pEqk7z7RJl8bwADQSw"]
[Sun Aug 30 03:05:24.841055 2026] [security2:error] [pid 493992:tid 494136] [client 158.23.147.79:40904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-admin/network/index.php"] [unique_id "apPkRGbB9pEqk7z7RJl8cAAAAyw"]
[Sun Aug 30 03:05:24.846187 2026] [security2:error] [pid 493992:tid 494131] [client 216.73.216.128:35105] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPkRGbB9pEqk7z7RJl8cwAAAyc"]
[Sun Aug 30 03:05:24.884389 2026] [security2:error] [pid 493992:tid 494224] [client 20.151.200.44:37843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/dehnl.php"] [unique_id "apPkRGbB9pEqk7z7RJl8iAAAA4Q"]
[Sun Aug 30 03:05:24.915760 2026] [security2:error] [pid 493992:tid 494212] [client 158.23.147.79:63902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/content.php"] [unique_id "apPkRGbB9pEqk7z7RJl8jAAAA3g"]
[Sun Aug 30 03:05:24.967499 2026] [security2:error] [pid 493992:tid 494161] [client 158.23.147.79:63262] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.redlandspawninc.com"] [uri "/1.php"] [unique_id "apPkRGbB9pEqk7z7RJl8lwAAA0U"]
[Sun Aug 30 03:05:24.967595 2026] [security2:error] [pid 493992:tid 494161] [client 158.23.147.79:63262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/1.php"] [unique_id "apPkRGbB9pEqk7z7RJl8lwAAA0U"]
[Sun Aug 30 03:05:24.980988 2026] [security2:error] [pid 493992:tid 494137] [client 68.155.159.216:52633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/about/function.php"] [unique_id "apPkRGbB9pEqk7z7RJl8mgAAAy0"]
[Sun Aug 30 03:05:24.995977 2026] [security2:error] [pid 493992:tid 494179] [client 20.104.49.130:40245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.topatrust.com"] [uri "/ws58.php"] [unique_id "apPkRGbB9pEqk7z7RJl8oQAAA1c"]
[Sun Aug 30 03:05:25.007781 2026] [security2:error] [pid 493992:tid 494166] [client 20.151.200.44:62947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/wk/index.php"] [unique_id "apPkRWbB9pEqk7z7RJl8pwAAA0o"]
[Sun Aug 30 03:05:25.028584 2026] [security2:error] [pid 493992:tid 494227] [client 40.83.93.50:9024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/w.php"] [unique_id "apPkRWbB9pEqk7z7RJl8sgAAA4c"]
[Sun Aug 30 03:05:25.047577 2026] [security2:error] [pid 493992:tid 494218] [client 20.104.18.15:9040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/c4.php"] [unique_id "apPkRWbB9pEqk7z7RJl8swAAA34"]
[Sun Aug 30 03:05:25.049728 2026] [security2:error] [pid 493992:tid 494193] [client 158.23.147.79:63894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPkRWbB9pEqk7z7RJl8tAAAA2U"]
[Sun Aug 30 03:05:25.094225 2026] [security2:error] [pid 493992:tid 494208] [client 20.104.18.15:13716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/222.php"] [unique_id "apPkRWbB9pEqk7z7RJl8wgAAA3Q"]
[Sun Aug 30 03:05:25.117264 2026] [security2:error] [pid 493992:tid 494235] [client 20.104.50.220:27084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/media.php"] [unique_id "apPkRWbB9pEqk7z7RJl8zwAAA48"]
[Sun Aug 30 03:05:25.136385 2026] [security2:error] [pid 493992:tid 494198] [client 20.63.219.114:1350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/sql.php"] [unique_id "apPkRWbB9pEqk7z7RJl81gAAA2o"]
[Sun Aug 30 03:05:25.167220 2026] [security2:error] [pid 493992:tid 494197] [client 158.23.147.79:62208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/goat.php"] [unique_id "apPkRWbB9pEqk7z7RJl83AAAA2k"]
[Sun Aug 30 03:05:25.172468 2026] [security2:error] [pid 493992:tid 494162] [client 20.104.50.220:46182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/32.php"] [unique_id "apPkRWbB9pEqk7z7RJl83wAAA0Y"]
[Sun Aug 30 03:05:25.184463 2026] [security2:error] [pid 493992:tid 494153] [client 158.23.147.79:62495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apPkRWbB9pEqk7z7RJl84wAAAz0"]
[Sun Aug 30 03:05:25.187381 2026] [security2:error] [pid 493992:tid 494225] [client 20.48.251.3:23303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/avim.php"] [unique_id "apPkRWbB9pEqk7z7RJl85AAAA4U"]
[Sun Aug 30 03:05:25.189397 2026] [security2:error] [pid 493992:tid 494163] [client 74.7.243.204:34666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/cms/"] [unique_id "apPkRWbB9pEqk7z7RJl85QAAA0c"], referer: http://mail.letter7brands.com/cms/?p=%2F%2Fetc
[Sun Aug 30 03:05:25.213432 2026] [security2:error] [pid 493992:tid 494143] [client 20.104.50.220:33309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/old-index.php"] [unique_id "apPkRWbB9pEqk7z7RJl87wAAAzM"]
[Sun Aug 30 03:05:25.220606 2026] [authz_core:error] [pid 493992:tid 494170] [client 216.73.216.128:35105] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:25.221030 2026] [authz_core:error] [pid 493992:tid 494170] [client 216.73.216.128:35105] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:25.221567 2026] [security2:error] [pid 493992:tid 494185] [client 158.23.147.79:26500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apPkRWbB9pEqk7z7RJl88wAAA10"]
[Sun Aug 30 03:05:25.261418 2026] [security2:error] [pid 493992:tid 494199] [client 158.23.147.79:63954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apPkRWbB9pEqk7z7RJl9AAAAA2s"]
[Sun Aug 30 03:05:25.272432 2026] [security2:error] [pid 493992:tid 494142] [client 195.178.110.247:12734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "concordservices-bali.com"] [uri "/index.php"] [unique_id "apPkRWbB9pEqk7z7RJl9BAAAAzI"]
[Sun Aug 30 03:05:25.274440 2026] [security2:error] [pid 493992:tid 494219] [client 20.104.50.220:5553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/security.php"] [unique_id "apPkRWbB9pEqk7z7RJl9BgAAA38"]
[Sun Aug 30 03:05:25.301561 2026] [security2:error] [pid 493992:tid 494198] [client 20.48.251.3:49934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/loxi-o.php"] [unique_id "apPkRWbB9pEqk7z7RJl9EwAAA2o"]
[Sun Aug 30 03:05:25.307547 2026] [authz_core:error] [pid 493992:tid 494164] [client 216.73.216.128:3468] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:25.307874 2026] [authz_core:error] [pid 493992:tid 494164] [client 216.73.216.128:3468] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:25.324566 2026] [security2:error] [pid 493992:tid 494147] [client 20.48.251.3:51515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPkRWbB9pEqk7z7RJl9GgAAAzc"]
[Sun Aug 30 03:05:25.327834 2026] [security2:error] [pid 493992:tid 494194] [client 20.104.50.220:63527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/rayzky.php"] [unique_id "apPkRWbB9pEqk7z7RJl9HAAAA2Y"]
[Sun Aug 30 03:05:25.363237 2026] [security2:error] [pid 493992:tid 494185] [client 158.23.147.79:40909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/.well-knownold/index.php"] [unique_id "apPkRWbB9pEqk7z7RJl9JAAAA10"]
[Sun Aug 30 03:05:25.395292 2026] [security2:error] [pid 493992:tid 494130] [client 20.48.251.3:7418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/u88.php"] [unique_id "apPkRWbB9pEqk7z7RJl9LwAAAyY"]
[Sun Aug 30 03:05:25.411868 2026] [security2:error] [pid 493992:tid 494244] [client 20.104.18.15:33785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/504.php"] [unique_id "apPkRWbB9pEqk7z7RJl9NgAAA5g"]
[Sun Aug 30 03:05:25.426096 2026] [security2:error] [pid 493992:tid 494177] [client 20.104.50.220:61461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/chan.php"] [unique_id "apPkRWbB9pEqk7z7RJl9OwAAA1U"]
[Sun Aug 30 03:05:25.436607 2026] [security2:error] [pid 493992:tid 494181] [client 195.178.110.247:56642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "concordservices-bali.com"] [uri "/index.php"] [unique_id "apPkRWbB9pEqk7z7RJl9QwAAA1k"]
[Sun Aug 30 03:05:25.438109 2026] [security2:error] [pid 493992:tid 494156] [client 20.151.200.44:46999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/od.php"] [unique_id "apPkRWbB9pEqk7z7RJl9RQAAA0A"]
[Sun Aug 30 03:05:25.443564 2026] [security2:error] [pid 493992:tid 494214] [client 20.104.18.15:31632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/robot.php"] [unique_id "apPkRWbB9pEqk7z7RJl9SQAAA3o"]
[Sun Aug 30 03:05:25.443977 2026] [security2:error] [pid 493992:tid 494215] [client 20.104.50.220:31828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/index7.php"] [unique_id "apPkRWbB9pEqk7z7RJl9SgAAA3s"]
[Sun Aug 30 03:05:25.445555 2026] [security2:error] [pid 493992:tid 494216] [client 158.23.147.79:63872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apPkRWbB9pEqk7z7RJl9TAAAA3w"]
[Sun Aug 30 03:05:25.461562 2026] [security2:error] [pid 493992:tid 494136] [client 20.104.50.220:63047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/uploadshell.php"] [unique_id "apPkRWbB9pEqk7z7RJl9WwAAAyw"]
[Sun Aug 30 03:05:25.462287 2026] [security2:error] [pid 493992:tid 494225] [client 158.23.147.79:40942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apPkRWbB9pEqk7z7RJl9XAAAA4U"]
[Sun Aug 30 03:05:25.481999 2026] [security2:error] [pid 493992:tid 494053] [remote 74.208.74.35:59740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.74.208.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "octechnologysolutionscenter.com"] [uri "/wp-login.php"] [unique_id "apPkRWbB9pEqk7z7RJl9YAADnDw"]
[Sun Aug 30 03:05:25.524118 2026] [security2:error] [pid 493992:tid 494155] [client 20.63.219.114:15129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/index.bak.php"] [unique_id "apPkRWbB9pEqk7z7RJl9bgAAAz8"]
[Sun Aug 30 03:05:25.546113 2026] [security2:error] [pid 493992:tid 494218] [client 40.83.93.50:18089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/wp.php"] [unique_id "apPkRWbB9pEqk7z7RJl9cwAAA34"]
[Sun Aug 30 03:05:25.566293 2026] [security2:error] [pid 493992:tid 494233] [client 20.48.251.3:55769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/fun.php"] [unique_id "apPkRWbB9pEqk7z7RJl9egAAA40"]
[Sun Aug 30 03:05:25.568277 2026] [security2:error] [pid 493992:tid 494152] [client 68.155.159.216:60012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/sad/about.php"] [unique_id "apPkRWbB9pEqk7z7RJl9ewAAAzw"]
[Sun Aug 30 03:05:25.642557 2026] [security2:error] [pid 493992:tid 494164] [client 158.23.147.79:63938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apPkRWbB9pEqk7z7RJl9lgAAA0g"]
[Sun Aug 30 03:05:25.642613 2026] [security2:error] [pid 493992:tid 494248] [client 158.23.147.79:40292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPkRWbB9pEqk7z7RJl9lwAAA5w"]
[Sun Aug 30 03:05:25.643197 2026] [security2:error] [pid 493992:tid 494165] [client 158.23.147.79:62533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/ws.php"] [unique_id "apPkRWbB9pEqk7z7RJl9mAAAA0k"]
[Sun Aug 30 03:05:25.682294 2026] [security2:error] [pid 493992:tid 494171] [client 158.23.147.79:63257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPkRWbB9pEqk7z7RJl9ngAAA08"]
[Sun Aug 30 03:05:25.712261 2026] [security2:error] [pid 493992:tid 494235] [client 20.151.200.44:63636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/dehnl.php"] [unique_id "apPkRWbB9pEqk7z7RJl9qwAAA48"]
[Sun Aug 30 03:05:25.726998 2026] [security2:error] [pid 493992:tid 494229] [client 20.48.251.3:44294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/w.php"] [unique_id "apPkRWbB9pEqk7z7RJl9rwAAA4k"]
[Sun Aug 30 03:05:25.755544 2026] [security2:error] [pid 493992:tid 494179] [client 158.23.147.79:40898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/images/index.php"] [unique_id "apPkRWbB9pEqk7z7RJl9ugAAA1c"]
[Sun Aug 30 03:05:25.756225 2026] [security2:error] [pid 493992:tid 494139] [client 20.104.18.15:43321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/nox.php"] [unique_id "apPkRWbB9pEqk7z7RJl9uwAAAy8"]
[Sun Aug 30 03:05:25.788301 2026] [security2:error] [pid 493992:tid 494060] [remote 66.116.251.167:56408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.251.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "calchampsoccer.org"] [uri "/wp-login.php"] [unique_id "apPkRWbB9pEqk7z7RJl9wgADekM"], referer: https://calchampsoccer.org/wp-login.php
[Sun Aug 30 03:05:25.791272 2026] [security2:error] [pid 493992:tid 494207] [client 68.155.159.216:60591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apPkRWbB9pEqk7z7RJl9xQAAA3M"]
[Sun Aug 30 03:05:25.811018 2026] [authz_core:error] [pid 493992:tid 494185] [client 66.249.66.64:47831] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:25.811302 2026] [authz_core:error] [pid 493992:tid 494185] [client 66.249.66.64:47831] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:25.822133 2026] [security2:error] [pid 493992:tid 494202] [client 158.23.147.79:63881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/dropdown.php"] [unique_id "apPkRWbB9pEqk7z7RJl9zgAAA24"]
[Sun Aug 30 03:05:25.825693 2026] [security2:error] [pid 493992:tid 494141] [client 20.104.50.220:62786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/venom.php"] [unique_id "apPkRWbB9pEqk7z7RJl9zwAAAzE"]
[Sun Aug 30 03:05:25.830658 2026] [security2:error] [pid 493992:tid 494129] [client 74.7.243.204:34666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/site/"] [unique_id "apPkRWbB9pEqk7z7RJl90gAAAyU"], referer: http://mail.letter7brands.com/site/?p=%2F%2Fetc
[Sun Aug 30 03:05:25.855808 2026] [security2:error] [pid 493992:tid 494237] [client 20.48.251.3:54738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/avim.php"] [unique_id "apPkRWbB9pEqk7z7RJl93QAAA5E"]
[Sun Aug 30 03:05:25.881204 2026] [security2:error] [pid 493992:tid 494227] [client 20.63.219.114:1400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/log.php"] [unique_id "apPkRWbB9pEqk7z7RJl96gAAA4c"]
[Sun Aug 30 03:05:25.910209 2026] [authz_core:error] [pid 493992:tid 494187] [client 66.249.66.75:43956] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:25.910508 2026] [authz_core:error] [pid 493992:tid 494187] [client 66.249.66.75:43956] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:25.912687 2026] [security2:error] [pid 493992:tid 494156] [client 158.23.147.79:40270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apPkRWbB9pEqk7z7RJl99gAAA0A"]
[Sun Aug 30 03:05:25.952188 2026] [authz_core:error] [pid 493992:tid 494122] [client 216.73.216.128:35105] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:25.952737 2026] [authz_core:error] [pid 493992:tid 494122] [client 216.73.216.128:35105] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:25.980477 2026] [security2:error] [pid 493992:tid 494132] [client 158.23.147.79:63999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/sad/about.php"] [unique_id "apPkRWbB9pEqk7z7RJl-AwAAAyg"]
[Sun Aug 30 03:05:26.020576 2026] [security2:error] [pid 493992:tid 494248] [client 158.23.147.79:40317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apPkRmbB9pEqk7z7RJl-EwAAA5w"]
[Sun Aug 30 03:05:26.108673 2026] [security2:error] [pid 493992:tid 494155] [client 68.155.159.216:52701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apPkRmbB9pEqk7z7RJl-KwAAAz8"]
[Sun Aug 30 03:05:26.116956 2026] [security2:error] [pid 493992:tid 494162] [client 40.83.93.50:9041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/composer.php"] [unique_id "apPkRmbB9pEqk7z7RJl-LwAAA0Y"]
[Sun Aug 30 03:05:26.137936 2026] [security2:error] [pid 493992:tid 494184] [client 20.151.200.44:62913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/png.php"] [unique_id "apPkRmbB9pEqk7z7RJl-MwAAA1w"]
[Sun Aug 30 03:05:26.140939 2026] [security2:error] [pid 493992:tid 494242] [client 158.23.147.79:63879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/admin.php"] [unique_id "apPkRmbB9pEqk7z7RJl-NAAAA5Y"]
[Sun Aug 30 03:05:26.152692 2026] [security2:error] [pid 493992:tid 494068] [remote 74.208.74.35:59740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.74.208.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "octechnologysolutionscenter.com"] [uri "/wp-login.php"] [unique_id "apPkRmbB9pEqk7z7RJl-NQADLUs"], referer: https://octechnologysolutionscenter.com/wp-login.php
[Sun Aug 30 03:05:26.168002 2026] [security2:error] [pid 493992:tid 494163] [client 158.23.147.79:62566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-includes/css/index.php"] [unique_id "apPkRmbB9pEqk7z7RJl-OAAAA0c"]
[Sun Aug 30 03:05:26.216234 2026] [security2:error] [pid 493992:tid 494206] [client 20.104.18.15:9053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/rxr.php"] [unique_id "apPkRmbB9pEqk7z7RJl-SQAAA3I"]
[Sun Aug 30 03:05:26.234725 2026] [security2:error] [pid 493992:tid 494236] [client 20.104.18.15:13702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/key.php"] [unique_id "apPkRmbB9pEqk7z7RJl-TAAAA5A"]
[Sun Aug 30 03:05:26.252190 2026] [security2:error] [pid 493992:tid 494181] [client 20.63.219.114:9608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/bak.php"] [unique_id "apPkRmbB9pEqk7z7RJl-UQAAA1k"]
[Sun Aug 30 03:05:26.255025 2026] [security2:error] [pid 493992:tid 494199] [client 20.104.50.220:27073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/images/class-config.php"] [unique_id "apPkRmbB9pEqk7z7RJl-UwAAA2s"]
[Sun Aug 30 03:05:26.310731 2026] [security2:error] [pid 493992:tid 494134] [client 20.104.50.220:46460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/404.php"] [unique_id "apPkRmbB9pEqk7z7RJl-ZQAAAyo"]
[Sun Aug 30 03:05:26.339749 2026] [security2:error] [pid 493992:tid 494242] [client 20.48.251.3:23481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/nw.php"] [unique_id "apPkRmbB9pEqk7z7RJl-agAAA5Y"]
[Sun Aug 30 03:05:26.366249 2026] [security2:error] [pid 493992:tid 494167] [client 20.104.50.220:32879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/ocgi.php"] [unique_id "apPkRmbB9pEqk7z7RJl-cwAAA0s"]
[Sun Aug 30 03:05:26.416161 2026] [security2:error] [pid 493992:tid 494165] [client 20.104.50.220:6134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-admin/user/about.php"] [unique_id "apPkRmbB9pEqk7z7RJl-hgAAA0k"]
[Sun Aug 30 03:05:26.446358 2026] [security2:error] [pid 493992:tid 494218] [client 20.48.251.3:49920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/f35.php"] [unique_id "apPkRmbB9pEqk7z7RJl-lAAAA34"]
[Sun Aug 30 03:05:26.486966 2026] [security2:error] [pid 493992:tid 494167] [client 20.48.160.90:40013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp-includes/style-engine/gecko-new.php"] [unique_id "apPkRmbB9pEqk7z7RJl-qwAAA0s"]
[Sun Aug 30 03:05:26.487070 2026] [authz_core:error] [pid 493992:tid 494154] [client 66.249.66.64:47831] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:26.487364 2026] [authz_core:error] [pid 493992:tid 494154] [client 66.249.66.64:47831] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:26.495377 2026] [security2:error] [pid 493992:tid 494216] [client 20.104.50.220:42754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/repair.php"] [unique_id "apPkRmbB9pEqk7z7RJl-rgAAA3w"]
[Sun Aug 30 03:05:26.519723 2026] [security2:error] [pid 493992:tid 494131] [client 195.178.110.247:12758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "concordservices-bali.com.concordconsultingbali.com"] [uri "/index.php"] [unique_id "apPkRmbB9pEqk7z7RJl-twAAAyc"]
[Sun Aug 30 03:05:26.557074 2026] [security2:error] [pid 493992:tid 494171] [client 20.48.251.3:7067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/config/laravolt/css/index.php"] [unique_id "apPkRmbB9pEqk7z7RJl-xgAAA08"]
[Sun Aug 30 03:05:26.558195 2026] [security2:error] [pid 493992:tid 494202] [client 20.48.251.3:34590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/agg.php"] [unique_id "apPkRmbB9pEqk7z7RJl-yAAAA24"]
[Sun Aug 30 03:05:26.565250 2026] [security2:error] [pid 493992:tid 494231] [client 20.104.18.15:32991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/admin.php"] [unique_id "apPkRmbB9pEqk7z7RJl-ygAAA4s"]
[Sun Aug 30 03:05:26.575614 2026] [security2:error] [pid 493992:tid 494218] [client 20.104.50.220:63033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/losX.php"] [unique_id "apPkRmbB9pEqk7z7RJl-0QAAA34"]
[Sun Aug 30 03:05:26.587136 2026] [authz_core:error] [pid 493992:tid 494177] [client 216.73.216.128:10586] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:26.587554 2026] [authz_core:error] [pid 493992:tid 494177] [client 216.73.216.128:10586] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:26.588922 2026] [security2:error] [pid 493992:tid 494146] [client 20.104.50.220:32091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/index8.php"] [unique_id "apPkRmbB9pEqk7z7RJl-2QAAAzY"]
[Sun Aug 30 03:05:26.601055 2026] [security2:error] [pid 493992:tid 494144] [client 20.48.160.90:40028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/V2.php"] [unique_id "apPkRmbB9pEqk7z7RJl-3QAAAzQ"]
[Sun Aug 30 03:05:26.602869 2026] [security2:error] [pid 493992:tid 494195] [client 20.104.50.220:29570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/zehir4shell.php"] [unique_id "apPkRmbB9pEqk7z7RJl-3wAAA2c"]
[Sun Aug 30 03:05:26.605074 2026] [security2:error] [pid 493992:tid 494133] [client 20.63.219.114:15140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/pages.php"] [unique_id "apPkRmbB9pEqk7z7RJl-4QAAAyk"]
[Sun Aug 30 03:05:26.617396 2026] [security2:error] [pid 493992:tid 494194] [client 20.104.18.15:31563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/revo.php"] [unique_id "apPkRmbB9pEqk7z7RJl-5AAAA2Y"]
[Sun Aug 30 03:05:26.623096 2026] [security2:error] [pid 493992:tid 494205] [client 20.48.160.90:45936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp-settings.php"] [unique_id "apPkRmbB9pEqk7z7RJl-5gAAA3E"]
[Sun Aug 30 03:05:26.645840 2026] [security2:error] [pid 493992:tid 494126] [client 20.48.160.90:50573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/radio.php"] [unique_id "apPkRmbB9pEqk7z7RJl-6gAAAyI"]
[Sun Aug 30 03:05:26.646380 2026] [security2:error] [pid 493992:tid 494225] [client 40.83.93.50:18055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/abcd.php"] [unique_id "apPkRmbB9pEqk7z7RJl-6wAAA4U"]
[Sun Aug 30 03:05:26.683607 2026] [security2:error] [pid 493992:tid 494168] [client 195.178.110.247:56646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "concordservices-bali.com.concordconsultingbali.com"] [uri "/index.php"] [unique_id "apPkRmbB9pEqk7z7RJl-8QAAA0w"]
[Sun Aug 30 03:05:26.684225 2026] [security2:error] [pid 493992:tid 494246] [client 68.155.159.216:59929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/admin.php"] [unique_id "apPkRmbB9pEqk7z7RJl-8gAAA5o"]
[Sun Aug 30 03:05:26.723237 2026] [security2:error] [pid 493992:tid 494157] [client 20.48.251.3:55785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/kedi.php"] [unique_id "apPkRmbB9pEqk7z7RJl_AQAAA0E"]
[Sun Aug 30 03:05:26.736730 2026] [security2:error] [pid 493992:tid 494181] [client 20.48.160.90:45886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/mad.php"] [unique_id "apPkRmbB9pEqk7z7RJl_BQAAA1k"]
[Sun Aug 30 03:05:26.742766 2026] [authz_core:error] [pid 493992:tid 494210] [client 66.249.66.200:43050] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:26.743229 2026] [authz_core:error] [pid 493992:tid 494210] [client 66.249.66.200:43050] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:26.765425 2026] [security2:error] [pid 493992:tid 494161] [client 20.48.160.90:45858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp-signup.php"] [unique_id "apPkRmbB9pEqk7z7RJl_EQAAA0U"]
[Sun Aug 30 03:05:26.782253 2026] [authz_core:error] [pid 493992:tid 494240] [client 66.249.66.76:46659] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:26.782554 2026] [authz_core:error] [pid 493992:tid 494240] [client 66.249.66.76:46659] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:26.797259 2026] [security2:error] [pid 493992:tid 494167] [client 20.48.160.90:50615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/one.php"] [unique_id "apPkRmbB9pEqk7z7RJl_IwAAA0s"]
[Sun Aug 30 03:05:26.856589 2026] [authz_core:error] [pid 493992:tid 494208] [client 216.73.216.128:10586] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:26.856892 2026] [authz_core:error] [pid 493992:tid 494208] [client 216.73.216.128:10586] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:26.858038 2026] [security2:error] [pid 493992:tid 494165] [client 20.151.200.44:47418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/kcs.php"] [unique_id "apPkRmbB9pEqk7z7RJl_NQAAA0k"]
[Sun Aug 30 03:05:26.873365 2026] [security2:error] [pid 493992:tid 494176] [client 20.48.160.90:26629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/st.php"] [unique_id "apPkRmbB9pEqk7z7RJl_OgAAA1Q"]
[Sun Aug 30 03:05:26.895916 2026] [security2:error] [pid 493992:tid 494227] [client 20.48.160.90:45846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp-conffg.php"] [unique_id "apPkRmbB9pEqk7z7RJl_SgAAA4c"]
[Sun Aug 30 03:05:26.905962 2026] [security2:error] [pid 493992:tid 494123] [client 20.48.251.3:44394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/btx25.php"] [unique_id "apPkRmbB9pEqk7z7RJl_TQAAAx8"]
[Sun Aug 30 03:05:26.929906 2026] [security2:error] [pid 493992:tid 494224] [client 20.48.160.90:50650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/503.php"] [unique_id "apPkRmbB9pEqk7z7RJl_UwAAA4Q"]
[Sun Aug 30 03:05:26.970873 2026] [security2:error] [pid 493992:tid 494214] [client 20.104.18.15:43323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/akismet.php"] [unique_id "apPkRmbB9pEqk7z7RJl_XwAAA3o"]
[Sun Aug 30 03:05:27.001559 2026] [security2:error] [pid 493992:tid 494217] [client 20.48.160.90:40020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/alfanew.php"] [unique_id "apPkR2bB9pEqk7z7RJl_agAAA30"]
[Sun Aug 30 03:05:27.015769 2026] [security2:error] [pid 493992:tid 494142] [client 20.48.251.3:64306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/nw.php"] [unique_id "apPkR2bB9pEqk7z7RJl_dwAAAzI"]
[Sun Aug 30 03:05:27.024221 2026] [security2:error] [pid 493992:tid 494181] [client 20.48.160.90:45853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp-validate.php"] [unique_id "apPkR2bB9pEqk7z7RJl_egAAA1k"]
[Sun Aug 30 03:05:27.026976 2026] [authz_core:error] [pid 493992:tid 494159] [client 66.249.66.192:39335] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:27.027247 2026] [authz_core:error] [pid 493992:tid 494159] [client 66.249.66.192:39335] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:27.081146 2026] [lsapi:error] [pid 493992:tid 494046] [remote 57.141.14.91:26492] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n
[Sun Aug 30 03:05:27.119797 2026] [security2:error] [pid 493992:tid 494122] [client 20.63.219.114:18511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/albin.php"] [unique_id "apPkR2bB9pEqk7z7RJl_oQAAAx4"]
[Sun Aug 30 03:05:27.132621 2026] [security2:error] [pid 493992:tid 494178] [client 40.83.93.50:18067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/sf.php"] [unique_id "apPkR2bB9pEqk7z7RJl_qAAAA1Y"]
[Sun Aug 30 03:05:27.208380 2026] [security2:error] [pid 493992:tid 494239] [client 68.155.159.216:52711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-admin/index.php"] [unique_id "apPkR2bB9pEqk7z7RJl_vAAAA5M"]
[Sun Aug 30 03:05:27.212534 2026] [security2:error] [pid 493992:tid 494218] [client 68.155.159.216:52769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-includes/pomo/index.php"] [unique_id "apPkR2bB9pEqk7z7RJl_vgAAA34"]
[Sun Aug 30 03:05:27.219227 2026] [security2:error] [pid 493992:tid 494236] [client 216.73.216.128:35105] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPkR2bB9pEqk7z7RJl_wAAAA5A"]
[Sun Aug 30 03:05:27.274697 2026] [security2:error] [pid 493992:tid 494199] [client 20.104.50.220:29150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/vuln.php"] [unique_id "apPkR2bB9pEqk7z7RJl_0wAAA2s"]
[Sun Aug 30 03:05:27.388012 2026] [security2:error] [pid 493992:tid 494230] [client 20.104.18.15:13751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/chosen.php"] [unique_id "apPkR2bB9pEqk7z7RJl_7AAAA4o"]
[Sun Aug 30 03:05:27.399340 2026] [security2:error] [pid 493992:tid 494148] [client 20.104.50.220:27445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/kill.php"] [unique_id "apPkR2bB9pEqk7z7RJl_9QAAAzg"]
[Sun Aug 30 03:05:27.424860 2026] [security2:error] [pid 493992:tid 494140] [client 20.104.18.15:9122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.reinerrecipes.com"] [uri "/reviall.php"] [unique_id "apPkR2bB9pEqk7z7RJmAAgAAAzA"]
[Sun Aug 30 03:05:27.465604 2026] [security2:error] [pid 493992:tid 494241] [client 20.104.50.220:46166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/4x4.php"] [unique_id "apPkR2bB9pEqk7z7RJmAFwAAA5U"]
[Sun Aug 30 03:05:27.479442 2026] [security2:error] [pid 493992:tid 494151] [client 20.48.251.3:22737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/product.php"] [unique_id "apPkR2bB9pEqk7z7RJmAGwAAAzs"]
[Sun Aug 30 03:05:27.505450 2026] [security2:error] [pid 493992:tid 494164] [client 20.104.50.220:33300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/ngocokpeli.php"] [unique_id "apPkR2bB9pEqk7z7RJmAIwAAA0g"]
[Sun Aug 30 03:05:27.552700 2026] [security2:error] [pid 493992:tid 494147] [client 20.63.219.114:18554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/an.php"] [unique_id "apPkR2bB9pEqk7z7RJmAMAAAAzc"]
[Sun Aug 30 03:05:27.569851 2026] [security2:error] [pid 493992:tid 494207] [client 20.104.50.220:5591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPkR2bB9pEqk7z7RJmANwAAA3M"]
[Sun Aug 30 03:05:27.592714 2026] [security2:error] [pid 493992:tid 494170] [client 20.48.251.3:50033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/api.php"] [unique_id "apPkR2bB9pEqk7z7RJmASQAAA04"]
[Sun Aug 30 03:05:27.639825 2026] [security2:error] [pid 493992:tid 494127] [client 20.104.50.220:63506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/raw.php"] [unique_id "apPkR2bB9pEqk7z7RJmAVgAAAyM"]
[Sun Aug 30 03:05:27.648705 2026] [security2:error] [pid 493992:tid 494239] [client 20.151.200.44:37832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/png.php"] [unique_id "apPkR2bB9pEqk7z7RJmAVwAAA5M"]
[Sun Aug 30 03:05:27.687156 2026] [security2:error] [pid 493992:tid 494249] [client 40.83.93.50:12042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/gel4y.php"] [unique_id "apPkR2bB9pEqk7z7RJmAXgAAA50"]
[Sun Aug 30 03:05:27.707731 2026] [security2:error] [pid 493992:tid 494175] [client 20.48.251.3:59077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/requirements.php"] [unique_id "apPkR2bB9pEqk7z7RJmAZwAAA1M"]
[Sun Aug 30 03:05:27.720411 2026] [security2:error] [pid 493992:tid 494232] [client 20.104.18.15:33734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/ws85.php"] [unique_id "apPkR2bB9pEqk7z7RJmAbgAAA4w"]
[Sun Aug 30 03:05:27.723268 2026] [security2:error] [pid 493992:tid 494191] [client 20.104.50.220:61692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/mom.php"] [unique_id "apPkR2bB9pEqk7z7RJmAbwAAA2M"]
[Sun Aug 30 03:05:27.735178 2026] [security2:error] [pid 493992:tid 494150] [client 20.104.50.220:31927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/index9.php"] [unique_id "apPkR2bB9pEqk7z7RJmAcQAAAzo"]
[Sun Aug 30 03:05:27.737419 2026] [security2:error] [pid 493992:tid 494144] [client 20.48.251.3:64442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/87.php"] [unique_id "apPkR2bB9pEqk7z7RJmAcwAAAzQ"]
[Sun Aug 30 03:05:27.742436 2026] [security2:error] [pid 493992:tid 494124] [client 20.104.50.220:28715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/lostdcshell.php"] [unique_id "apPkR2bB9pEqk7z7RJmAdgAAAyA"]
[Sun Aug 30 03:05:27.751185 2026] [security2:error] [pid 493992:tid 494170] [client 20.104.18.15:31743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/birrs.php"] [unique_id "apPkR2bB9pEqk7z7RJmAewAAA04"]
[Sun Aug 30 03:05:27.754708 2026] [security2:error] [pid 493992:tid 494208] [client 20.151.200.44:63571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/txets.php"] [unique_id "apPkR2bB9pEqk7z7RJmAfAAAA3Q"]
[Sun Aug 30 03:05:27.789788 2026] [security2:error] [pid 493992:tid 494193] [client 68.155.159.216:59993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-admin/admin.php"] [unique_id "apPkR2bB9pEqk7z7RJmAjAAAA2U"]
[Sun Aug 30 03:05:27.870615 2026] [security2:error] [pid 493992:tid 494142] [client 20.48.251.3:59309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/oc460l3x.php"] [unique_id "apPkR2bB9pEqk7z7RJmAqwAAAzI"]
[Sun Aug 30 03:05:27.876515 2026] [security2:error] [pid 493992:tid 494108] [remote 93.123.109.228:57742] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jaretdock.com"] [uri "/.env"] [unique_id "apPkR2bB9pEqk7z7RJmAtAADZ3M"]
[Sun Aug 30 03:05:27.987884 2026] [security2:error] [pid 493992:tid 494186] [client 20.63.219.114:1347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/mini.php"] [unique_id "apPkR2bB9pEqk7z7RJmAvgAAA14"]
[Sun Aug 30 03:05:28.033518 2026] [security2:error] [pid 493992:tid 494162] [client 134.185.86.231:62249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.86.185.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.districtdumplings.com"] [uri "/wp-login.php"] [unique_id "apPkSGbB9pEqk7z7RJmAvwAAA0Y"], referer: https://www.bing.com/
[Sun Aug 30 03:05:28.904682 2026] [http2:info] [pid 495314:tid 495314] h2_workers: created with min=128 max=192 idle_ms=600000
[Sun Aug 30 03:05:28.928095 2026] [security2:error] [pid 495314:tid 495466] [client 20.48.251.3:55480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/temp.php"] [unique_id "apPkSEmtdPfUFP1akVE1LgAABD4"]
[Sun Aug 30 03:05:28.928116 2026] [security2:error] [pid 495314:tid 495452] [client 68.155.159.216:54754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPkSEmtdPfUFP1akVE1KQAABDA"]
[Sun Aug 30 03:05:28.928152 2026] [security2:error] [pid 495314:tid 495464] [client 20.104.50.220:33165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/new_license.php"] [unique_id "apPkSEmtdPfUFP1akVE1LAAABDw"]
[Sun Aug 30 03:05:28.928188 2026] [security2:error] [pid 495314:tid 495468] [client 20.104.50.220:27426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/166.php"] [unique_id "apPkSEmtdPfUFP1akVE1MAAABEA"]
[Sun Aug 30 03:05:28.928279 2026] [security2:error] [pid 495314:tid 495463] [client 20.104.50.220:29622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/V5.php"] [unique_id "apPkSEmtdPfUFP1akVE1KwAABDs"]
[Sun Aug 30 03:05:28.928524 2026] [security2:error] [pid 495314:tid 495465] [client 20.151.200.44:47011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/ssh3ll.php"] [unique_id "apPkSEmtdPfUFP1akVE1LQAABD0"]
[Sun Aug 30 03:05:28.928292 2026] [security2:error] [pid 495314:tid 495444] [client 20.48.251.3:54836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/product.php"] [unique_id "apPkSEmtdPfUFP1akVE1JAAABCg"]
[Sun Aug 30 03:05:28.928361 2026] [security2:error] [pid 495314:tid 495451] [client 20.48.251.3:44391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/app_dev.php"] [unique_id "apPkSEmtdPfUFP1akVE1KAAABC8"]
[Sun Aug 30 03:05:28.928391 2026] [security2:error] [pid 495314:tid 495447] [client 20.48.160.90:50585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/504.php"] [unique_id "apPkSEmtdPfUFP1akVE1IwAABCs"]
[Sun Aug 30 03:05:28.928456 2026] [security2:error] [pid 495314:tid 495448] [client 20.48.160.90:45917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/ioxi.php"] [unique_id "apPkSEmtdPfUFP1akVE1JQAABCw"]
[Sun Aug 30 03:05:28.928482 2026] [security2:error] [pid 495314:tid 495449] [client 20.48.251.3:59124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/var/www/wallet/index.php"] [unique_id "apPkSEmtdPfUFP1akVE1JgAABC0"]
[Sun Aug 30 03:05:28.928510 2026] [security2:error] [pid 495314:tid 495446] [client 20.104.18.15:43272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/ajax.php"] [unique_id "apPkSEmtdPfUFP1akVE1IQAABCo"]
[Sun Aug 30 03:05:28.928279 2026] [security2:error] [pid 495314:tid 495467] [client 20.48.160.90:45837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/700.php"] [unique_id "apPkSEmtdPfUFP1akVE1LwAABD8"]
[Sun Aug 30 03:05:28.929091 2026] [security2:error] [pid 495314:tid 495478] [client 134.185.86.231:62973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.86.185.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.districtdumplings.com"] [uri "/wp-login.php"] [unique_id "apPkSEmtdPfUFP1akVE1MwAABEo"]
[Sun Aug 30 03:05:28.931220 2026] [security2:error] [pid 495314:tid 495483] [client 68.155.159.216:52822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/nf_tracking.php"] [unique_id "apPkSEmtdPfUFP1akVE1OAAABE8"]
[Sun Aug 30 03:05:28.932005 2026] [security2:error] [pid 495314:tid 495479] [client 20.104.50.220:51551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/py.php"] [unique_id "apPkSEmtdPfUFP1akVE1OQAABEs"]
[Sun Aug 30 03:05:28.932397 2026] [security2:error] [pid 495314:tid 495492] [client 20.104.50.220:46905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/73.php"] [unique_id "apPkSEmtdPfUFP1akVE1PgAABFg"]
[Sun Aug 30 03:05:28.932792 2026] [security2:error] [pid 495314:tid 495493] [client 20.48.251.3:7044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/app_dev.php"] [unique_id "apPkSEmtdPfUFP1akVE1QAAABFk"]
[Sun Aug 30 03:05:28.934022 2026] [security2:error] [pid 495314:tid 495500] [client 20.104.50.220:5478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-content/upgrade/about.php"] [unique_id "apPkSEmtdPfUFP1akVE1QgAABGA"]
[Sun Aug 30 03:05:28.934217 2026] [security2:error] [pid 495314:tid 495501] [client 20.104.18.15:13745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/file1221.php"] [unique_id "apPkSEmtdPfUFP1akVE1QwAABGE"]
[Sun Aug 30 03:05:28.935156 2026] [security2:error] [pid 495314:tid 495508] [client 20.104.50.220:32292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/indeex.php"] [unique_id "apPkSEmtdPfUFP1akVE1RgAABGg"]
[Sun Aug 30 03:05:28.935436 2026] [security2:error] [pid 495314:tid 495509] [client 20.48.251.3:44264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/fun.php"] [unique_id "apPkSEmtdPfUFP1akVE1RwAABGk"]
[Sun Aug 30 03:05:28.935546 2026] [security2:error] [pid 495314:tid 495480] [client 20.104.50.220:61496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/killer.php"] [unique_id "apPkSEmtdPfUFP1akVE1SAAABEw"]
[Sun Aug 30 03:05:28.935748 2026] [security2:error] [pid 495314:tid 495477] [client 74.7.243.204:34678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/site/"] [unique_id "apPkSEmtdPfUFP1akVE1MQAABEk"], referer: http://mail.letter7brands.com/site/?p=%2F%2Fetc
[Sun Aug 30 03:05:28.936658 2026] [security2:error] [pid 495314:tid 495481] [client 68.155.159.216:59978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apPkSEmtdPfUFP1akVE1SQAABE0"]
[Sun Aug 30 03:05:28.936988 2026] [security2:error] [pid 495314:tid 495515] [client 20.48.251.3:7043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/plss3.php"] [unique_id "apPkSEmtdPfUFP1akVE1SwAABG8"]
[Sun Aug 30 03:05:28.937605 2026] [security2:error] [pid 495314:tid 495519] [client 20.104.18.15:33009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/ffs.php"] [unique_id "apPkSEmtdPfUFP1akVE1TQAABHM"]
[Sun Aug 30 03:05:28.938639 2026] [security2:error] [pid 495314:tid 495524] [client 20.104.49.130:58216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/ab.php"] [unique_id "apPkSEmtdPfUFP1akVE1TgAABHg"]
[Sun Aug 30 03:05:28.938745 2026] [security2:error] [pid 495314:tid 495525] [client 20.104.50.220:62793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/commandshell.php"] [unique_id "apPkSEmtdPfUFP1akVE1TwAABHk"]
[Sun Aug 30 03:05:28.939441 2026] [security2:error] [pid 495314:tid 495530] [client 20.104.18.15:31675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/sss.php"] [unique_id "apPkSEmtdPfUFP1akVE1UQAABH4"]
[Sun Aug 30 03:05:28.949772 2026] [authz_core:error] [pid 495314:tid 495499] [client 66.249.66.35:61252] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:28.950213 2026] [authz_core:error] [pid 495314:tid 495499] [client 66.249.66.35:61252] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:28.991056 2026] [authz_core:error] [pid 495314:tid 495494] [client 66.249.66.45:49803] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:28.991511 2026] [authz_core:error] [pid 495314:tid 495494] [client 66.249.66.45:49803] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:28.994398 2026] [authz_core:error] [pid 495314:tid 495484] [client 66.249.66.38:63038] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:28.994741 2026] [authz_core:error] [pid 495314:tid 495484] [client 66.249.66.38:63038] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:29.003437 2026] [authz_core:error] [pid 495314:tid 495531] [client 66.249.66.197:55337] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:29.003915 2026] [authz_core:error] [pid 495314:tid 495531] [client 66.249.66.197:55337] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:29.024137 2026] [security2:error] [pid 495314:tid 495538] [client 20.48.251.3:59287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/drykl.php"] [unique_id "apPkSUmtdPfUFP1akVE1egAABIY"]
[Sun Aug 30 03:05:29.044275 2026] [security2:error] [pid 495314:tid 495453] [client 20.63.219.114:9661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/robots.php"] [unique_id "apPkSUmtdPfUFP1akVE1fAAABDE"]
[Sun Aug 30 03:05:29.060110 2026] [security2:error] [pid 495314:tid 495554] [client 20.48.160.90:45925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/c4.php"] [unique_id "apPkSUmtdPfUFP1akVE1fwAABJY"]
[Sun Aug 30 03:05:29.062735 2026] [security2:error] [pid 495314:tid 495553] [client 20.48.160.90:40061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/TNT.php"] [unique_id "apPkSUmtdPfUFP1akVE1gAAABJU"]
[Sun Aug 30 03:05:29.068775 2026] [security2:error] [pid 495314:tid 495457] [client 20.48.160.90:33234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/admin.php"] [unique_id "apPkSUmtdPfUFP1akVE1gQAABDU"]
[Sun Aug 30 03:05:29.119829 2026] [security2:error] [pid 495314:tid 495474] [client 40.83.93.50:18101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/leaf.php"] [unique_id "apPkSUmtdPfUFP1akVE1gwAABEY"]
[Sun Aug 30 03:05:29.148595 2026] [authz_core:error] [pid 495314:tid 495544] [client 66.249.66.38:60250] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:29.149042 2026] [authz_core:error] [pid 495314:tid 495544] [client 66.249.66.38:60250] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:29.209368 2026] [security2:error] [pid 495314:tid 495562] [client 20.48.160.90:45873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp-tymanage.php"] [unique_id "apPkSUmtdPfUFP1akVE1hwAABJ4"]
[Sun Aug 30 03:05:29.211365 2026] [security2:error] [pid 495314:tid 495567] [client 20.48.160.90:50642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/ws85.php"] [unique_id "apPkSUmtdPfUFP1akVE1iAAABKM"]
[Sun Aug 30 03:05:29.212401 2026] [security2:error] [pid 495314:tid 495563] [client 20.48.160.90:40040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/cd.php"] [unique_id "apPkSUmtdPfUFP1akVE1iQAABJ8"]
[Sun Aug 30 03:05:29.324579 2026] [authz_core:error] [pid 495314:tid 495527] [client 216.73.216.128:18243] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:29.324952 2026] [authz_core:error] [pid 495314:tid 495527] [client 216.73.216.128:18243] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:29.340572 2026] [security2:error] [pid 495314:tid 495497] [client 20.151.200.44:47308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/tajj.php"] [unique_id "apPkSUmtdPfUFP1akVE1kgAABF0"]
[Sun Aug 30 03:05:29.350255 2026] [security2:error] [pid 495314:tid 495536] [client 20.48.160.90:50648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/ffs.php"] [unique_id "apPkSUmtdPfUFP1akVE1lgAABIQ"]
[Sun Aug 30 03:05:29.352164 2026] [security2:error] [pid 495314:tid 495338] [remote 93.123.109.228:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jaretdock.com"] [uri "/backend/.env"] [unique_id "apPkSUmtdPfUFP1akVE1mQAEWRc"]
[Sun Aug 30 03:05:29.357543 2026] [security2:error] [pid 495314:tid 495509] [client 20.48.160.90:45845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/ajfto.php"] [unique_id "apPkSUmtdPfUFP1akVE1mgAABGk"]
[Sun Aug 30 03:05:29.365188 2026] [security2:error] [pid 495314:tid 495480] [client 20.48.160.90:39964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/luuf.php"] [unique_id "apPkSUmtdPfUFP1akVE1mwAABEw"]
[Sun Aug 30 03:05:29.426208 2026] [security2:error] [pid 495314:tid 495479] [client 20.63.219.114:18517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/cron.php"] [unique_id "apPkSUmtdPfUFP1akVE1nQAABEs"]
[Sun Aug 30 03:05:29.487181 2026] [security2:error] [pid 495314:tid 495453] [client 20.48.160.90:50587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/nano.php"] [unique_id "apPkSUmtdPfUFP1akVE1pAAABDE"]
[Sun Aug 30 03:05:29.506530 2026] [core:error] [pid 495314:tid 495483] [client 134.185.86.231:64034] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:05:29.506552 2026] [core:error] [pid 495314:tid 495483] [client 134.185.86.231:64034] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:05:29.511906 2026] [security2:error] [pid 495314:tid 495461] [client 20.48.160.90:45885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp_KwIW0U5F.php"] [unique_id "apPkSUmtdPfUFP1akVE1pwAABDk"]
[Sun Aug 30 03:05:29.523481 2026] [security2:error] [pid 495314:tid 495554] [client 20.48.160.90:40021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/fex.php"] [unique_id "apPkSUmtdPfUFP1akVE1qQAABJY"]
[Sun Aug 30 03:05:29.548140 2026] [ssl:error] [pid 495314:tid 495482] [client 98.88.137.2:40847] AH02032: Hostname gator3166.hostgator.com (default host as no SNI was provided) and hostname cpanel.xn--12caqf1dfbnati9gbnk8a0jk8cq4dmfdq4h5hua7psc.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Sun Aug 30 03:05:29.604827 2026] [security2:error] [pid 495314:tid 495546] [client 40.83.93.50:9056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/k.php"] [unique_id "apPkSUmtdPfUFP1akVE1rgAABI4"]
[Sun Aug 30 03:05:29.631232 2026] [security2:error] [pid 495314:tid 495472] [client 20.48.160.90:50590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/ano.php"] [unique_id "apPkSUmtdPfUFP1akVE1sQAABEQ"]
[Sun Aug 30 03:05:29.632563 2026] [authz_core:error] [pid 495314:tid 495514] [client 66.249.66.65:46732] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:29.632865 2026] [authz_core:error] [pid 495314:tid 495514] [client 66.249.66.65:46732] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:29.649451 2026] [security2:error] [pid 495314:tid 495474] [client 20.48.160.90:45909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp_xiPu52Ut.php"] [unique_id "apPkSUmtdPfUFP1akVE1swAABEY"]
[Sun Aug 30 03:05:29.674407 2026] [security2:error] [pid 495314:tid 495455] [client 20.48.160.90:45863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/l.php"] [unique_id "apPkSUmtdPfUFP1akVE1tgAABDM"]
[Sun Aug 30 03:05:29.724968 2026] [security2:error] [pid 495314:tid 495561] [client 20.151.200.44:47007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/wp-the.php"] [unique_id "apPkSUmtdPfUFP1akVE1uwAABJ0"]
[Sun Aug 30 03:05:29.737697 2026] [security2:error] [pid 495314:tid 495458] [client 20.48.251.3:7367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/classsmtps.php"] [unique_id "apPkSUmtdPfUFP1akVE1vAAABDY"]
[Sun Aug 30 03:05:29.749818 2026] [authz_core:error] [pid 495314:tid 495567] [client 66.249.66.68:55670] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:29.750085 2026] [authz_core:error] [pid 495314:tid 495567] [client 66.249.66.68:55670] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:29.760547 2026] [security2:error] [pid 495314:tid 495476] [client 20.48.160.90:33269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/mgrr.php"] [unique_id "apPkSUmtdPfUFP1akVE1vwAABEg"]
[Sun Aug 30 03:05:29.778845 2026] [security2:error] [pid 495314:tid 495558] [client 20.63.219.114:18544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/goat.php"] [unique_id "apPkSUmtdPfUFP1akVE1wQAABJo"]
[Sun Aug 30 03:05:29.783124 2026] [security2:error] [pid 495314:tid 495568] [client 20.48.160.90:45882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp_n5VD7XDh.php"] [unique_id "apPkSUmtdPfUFP1akVE1wgAABKQ"]
[Sun Aug 30 03:05:29.803575 2026] [security2:error] [pid 495314:tid 495518] [client 20.48.160.90:39957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/xr.php"] [unique_id "apPkSUmtdPfUFP1akVE1xgAABHI"]
[Sun Aug 30 03:05:29.881386 2026] [security2:error] [pid 495314:tid 495353] [remote 93.123.109.228:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jaretdock.com"] [uri "/.docker/laravel/app/.env"] [unique_id "apPkSUmtdPfUFP1akVE1zgAEoiY"]
[Sun Aug 30 03:05:29.893298 2026] [security2:error] [pid 495314:tid 495358] [remote 93.123.109.228:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jaretdock.com"] [uri "/.env"] [unique_id "apPkSUmtdPfUFP1akVE11AAEais"]
[Sun Aug 30 03:05:29.903149 2026] [security2:error] [pid 495314:tid 495570] [client 20.48.160.90:50645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/mac.php"] [unique_id "apPkSUmtdPfUFP1akVE11gAABKY"]
[Sun Aug 30 03:05:29.925876 2026] [security2:error] [pid 495314:tid 495551] [client 20.48.160.90:40024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp-mini.php"] [unique_id "apPkSUmtdPfUFP1akVE12AAABJM"]
[Sun Aug 30 03:05:29.935815 2026] [security2:error] [pid 495314:tid 495490] [client 20.48.160.90:39961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/Q3.php"] [unique_id "apPkSUmtdPfUFP1akVE12gAABFY"]
[Sun Aug 30 03:05:29.983299 2026] [security2:error] [pid 495314:tid 495520] [client 4.205.62.107:2780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/bootstrap.php"] [unique_id "apPkSUmtdPfUFP1akVE13AAABHQ"]
[Sun Aug 30 03:05:29.992935 2026] [security2:error] [pid 495314:tid 495454] [client 74.7.243.204:34678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/new/"] [unique_id "apPkSUmtdPfUFP1akVE13gAABDI"], referer: http://mail.letter7brands.com/new/?p=%2F%2Fetc
[Sun Aug 30 03:05:30.028346 2026] [authz_core:error] [pid 495314:tid 495548] [client 66.249.66.38:63038] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:30.028770 2026] [authz_core:error] [pid 495314:tid 495548] [client 66.249.66.38:63038] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:30.037365 2026] [security2:error] [pid 495314:tid 495508] [client 68.155.159.216:52717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/about.php"] [unique_id "apPkSkmtdPfUFP1akVE14QAABGg"]
[Sun Aug 30 03:05:30.041635 2026] [security2:error] [pid 495314:tid 495497] [client 68.155.159.216:54025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/classwithtostring.php"] [unique_id "apPkSkmtdPfUFP1akVE14gAABF0"]
[Sun Aug 30 03:05:30.059569 2026] [security2:error] [pid 495314:tid 495493] [client 20.48.251.3:55549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/fm.php"] [unique_id "apPkSkmtdPfUFP1akVE15AAABFk"]
[Sun Aug 30 03:05:30.063571 2026] [security2:error] [pid 495314:tid 495509] [client 68.155.159.216:59329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wzy.php"] [unique_id "apPkSkmtdPfUFP1akVE15QAABGk"]
[Sun Aug 30 03:05:30.064534 2026] [security2:error] [pid 495314:tid 495480] [client 20.104.50.220:27455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/ops.php"] [unique_id "apPkSkmtdPfUFP1akVE15gAABEw"]
[Sun Aug 30 03:05:30.066639 2026] [security2:error] [pid 495314:tid 495515] [client 20.48.160.90:45917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/xmini4.php"] [unique_id "apPkSkmtdPfUFP1akVE15wAABG8"]
[Sun Aug 30 03:05:30.067964 2026] [security2:error] [pid 495314:tid 495494] [client 20.104.50.220:29169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/v5.php"] [unique_id "apPkSkmtdPfUFP1akVE16AAABFo"]
[Sun Aug 30 03:05:30.068111 2026] [security2:error] [pid 495314:tid 495516] [client 20.48.251.3:46262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/fun.php"] [unique_id "apPkSkmtdPfUFP1akVE16QAABHA"]
[Sun Aug 30 03:05:30.069940 2026] [security2:error] [pid 495314:tid 495538] [client 20.48.251.3:23317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/kedi.php"] [unique_id "apPkSkmtdPfUFP1akVE16gAABIY"]
[Sun Aug 30 03:05:30.070211 2026] [security2:error] [pid 495314:tid 495519] [client 20.48.160.90:45945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/Q1.php"] [unique_id "apPkSkmtdPfUFP1akVE16wAABHM"]
[Sun Aug 30 03:05:30.072545 2026] [security2:error] [pid 495314:tid 495465] [client 20.104.50.220:46867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/al.php"] [unique_id "apPkSkmtdPfUFP1akVE17AAABD0"]
[Sun Aug 30 03:05:30.072663 2026] [security2:error] [pid 495314:tid 495524] [client 20.104.50.220:31870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/jindex.php"] [unique_id "apPkSkmtdPfUFP1akVE17QAABHg"]
[Sun Aug 30 03:05:30.075815 2026] [security2:error] [pid 495314:tid 495466] [client 20.104.18.15:13686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/nox.php"] [unique_id "apPkSkmtdPfUFP1akVE17gAABD4"]
[Sun Aug 30 03:05:30.078635 2026] [security2:error] [pid 495314:tid 495525] [client 20.48.251.3:6982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/aws.php"] [unique_id "apPkSkmtdPfUFP1akVE17wAABHk"]
[Sun Aug 30 03:05:30.079799 2026] [security2:error] [pid 495314:tid 495530] [client 20.48.160.90:33238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/simple.php"] [unique_id "apPkSkmtdPfUFP1akVE18AAABH4"]
[Sun Aug 30 03:05:30.080280 2026] [security2:error] [pid 495314:tid 495505] [client 20.104.50.220:6129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apPkSkmtdPfUFP1akVE18QAABGU"]
[Sun Aug 30 03:05:30.080327 2026] [security2:error] [pid 495314:tid 495475] [client 20.104.50.220:33212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/miyabajingankoe.php"] [unique_id "apPkSkmtdPfUFP1akVE18gAABEc"]
[Sun Aug 30 03:05:30.084120 2026] [security2:error] [pid 495314:tid 495477] [client 20.104.18.15:33741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/nano.php"] [unique_id "apPkSkmtdPfUFP1akVE18wAABEk"]
[Sun Aug 30 03:05:30.084404 2026] [security2:error] [pid 495314:tid 495479] [client 20.104.50.220:29592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/mailershell.php"] [unique_id "apPkSkmtdPfUFP1akVE19AAABEs"]
[Sun Aug 30 03:05:30.085116 2026] [security2:error] [pid 495314:tid 495446] [client 20.104.50.220:51559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/ray.php"] [unique_id "apPkSkmtdPfUFP1akVE19gAABCo"]
[Sun Aug 30 03:05:30.095710 2026] [security2:error] [pid 495314:tid 495461] [client 20.104.18.15:43296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/atomlib.php"] [unique_id "apPkSkmtdPfUFP1akVE19wAABDk"]
[Sun Aug 30 03:05:30.099164 2026] [security2:error] [pid 495314:tid 495554] [client 20.104.50.220:59544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/Sh3ll.php"] [unique_id "apPkSkmtdPfUFP1akVE1-AAABJY"]
[Sun Aug 30 03:05:30.110723 2026] [security2:error] [pid 495314:tid 495460] [client 4.205.62.107:63989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/routes.php"] [unique_id "apPkSkmtdPfUFP1akVE1-gAABDg"]
[Sun Aug 30 03:05:30.110902 2026] [security2:error] [pid 495314:tid 495451] [client 4.205.62.107:18974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/tinyfilemanager.php"] [unique_id "apPkSkmtdPfUFP1akVE1-wAABC8"]
[Sun Aug 30 03:05:30.111245 2026] [security2:error] [pid 495314:tid 495544] [client 4.205.62.107:52100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/motu.php"] [unique_id "apPkSkmtdPfUFP1akVE1_AAABIw"]
[Sun Aug 30 03:05:30.121262 2026] [core:error] [pid 495314:tid 495526] [client 20.104.18.15:31653] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:05:30.121276 2026] [core:error] [pid 495314:tid 495526] [client 20.104.18.15:31653] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:05:30.145501 2026] [security2:error] [pid 495314:tid 495528] [client 20.48.251.3:59084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/124.php"] [unique_id "apPkSkmtdPfUFP1akVE2AQAABHw"]
[Sun Aug 30 03:05:30.163510 2026] [security2:error] [pid 495314:tid 495561] [client 20.48.251.3:52817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/rpk.php"] [unique_id "apPkSkmtdPfUFP1akVE2AgAABJ0"]
[Sun Aug 30 03:05:30.173965 2026] [security2:error] [pid 495314:tid 495458] [client 4.205.62.107:44909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/test1.php"] [unique_id "apPkSkmtdPfUFP1akVE2AwAABDY"]
[Sun Aug 30 03:05:30.180192 2026] [security2:error] [pid 495314:tid 495532] [client 40.83.93.50:9089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/chosen.php"] [unique_id "apPkSkmtdPfUFP1akVE2BAAABIA"]
[Sun Aug 30 03:05:30.200381 2026] [security2:error] [pid 495314:tid 495492] [client 20.48.160.90:40031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/nz.php"] [unique_id "apPkSkmtdPfUFP1akVE2BQAABFg"]
[Sun Aug 30 03:05:30.200446 2026] [security2:error] [pid 495314:tid 495448] [client 20.63.219.114:15134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/gg.php"] [unique_id "apPkSkmtdPfUFP1akVE2BgAABCw"]
[Sun Aug 30 03:05:30.201277 2026] [security2:error] [pid 495314:tid 495569] [client 20.48.251.3:44402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/php-info.php"] [unique_id "apPkSkmtdPfUFP1akVE2BwAABKU"]
[Sun Aug 30 03:05:30.211131 2026] [security2:error] [pid 495314:tid 495499] [client 20.48.160.90:45919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/reop3.php"] [unique_id "apPkSkmtdPfUFP1akVE2CgAABF8"]
[Sun Aug 30 03:05:30.211295 2026] [security2:error] [pid 495314:tid 495518] [client 20.48.160.90:50687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/xty.php"] [unique_id "apPkSkmtdPfUFP1akVE2CQAABHI"]
[Sun Aug 30 03:05:30.241424 2026] [security2:error] [pid 495314:tid 495552] [client 20.104.49.130:58239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/well.php"] [unique_id "apPkSkmtdPfUFP1akVE2DAAABJQ"]
[Sun Aug 30 03:05:30.242660 2026] [authz_core:error] [pid 495314:tid 495444] [client 216.73.216.128:7370] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:30.243093 2026] [authz_core:error] [pid 495314:tid 495444] [client 216.73.216.128:7370] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:30.272876 2026] [security2:error] [pid 493992:tid 494246] [client 74.7.241.130:38674] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "orders.lastmaskcenter.org"] [uri "/index.php"] [unique_id "apPkR2bB9pEqk7z7RJl_4QADmlw"]
[Sun Aug 30 03:05:30.334057 2026] [authz_core:error] [pid 495314:tid 495501] [client 66.249.66.206:40610] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:30.334373 2026] [authz_core:error] [pid 495314:tid 495501] [client 66.249.66.206:40610] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:30.345433 2026] [security2:error] [pid 495314:tid 495463] [client 20.48.160.90:33244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/sallu.php"] [unique_id "apPkSkmtdPfUFP1akVE2EAAABDs"]
[Sun Aug 30 03:05:30.353855 2026] [security2:error] [pid 495314:tid 495491] [client 20.48.160.90:45833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/sg.php"] [unique_id "apPkSkmtdPfUFP1akVE2EgAABFc"]
[Sun Aug 30 03:05:30.354240 2026] [security2:error] [pid 495314:tid 495509] [client 20.48.160.90:45926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp-mail.php"] [unique_id "apPkSkmtdPfUFP1akVE2EwAABGk"]
[Sun Aug 30 03:05:30.364076 2026] [authz_core:error] [pid 495314:tid 495536] [client 66.249.66.200:63829] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:30.364537 2026] [authz_core:error] [pid 495314:tid 495536] [client 66.249.66.200:63829] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:30.382557 2026] [security2:error] [pid 495314:tid 495480] [client 4.205.62.107:32465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/tax.php"] [unique_id "apPkSkmtdPfUFP1akVE2FQAABEw"]
[Sun Aug 30 03:05:30.449219 2026] [security2:error] [pid 495314:tid 495525] [client 4.205.62.107:65287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/userfuns.php"] [unique_id "apPkSkmtdPfUFP1akVE2GAAABHk"]
[Sun Aug 30 03:05:30.483037 2026] [security2:error] [pid 495314:tid 495477] [client 20.48.160.90:50686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/codex.php"] [unique_id "apPkSkmtdPfUFP1akVE2GgAABEk"]
[Sun Aug 30 03:05:30.484136 2026] [security2:error] [pid 495314:tid 495479] [client 20.48.160.90:45865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp-conffg.php"] [unique_id "apPkSkmtdPfUFP1akVE2HAAABEs"]
[Sun Aug 30 03:05:30.492499 2026] [security2:error] [pid 495314:tid 495550] [client 20.48.160.90:39982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/hypo.php"] [unique_id "apPkSkmtdPfUFP1akVE2HwAABJI"]
[Sun Aug 30 03:05:30.498376 2026] [security2:error] [pid 495314:tid 495461] [client 4.205.62.107:25732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/umgebung.php"] [unique_id "apPkSkmtdPfUFP1akVE2IAAABDk"]
[Sun Aug 30 03:05:30.513988 2026] [security2:error] [pid 495314:tid 495502] [client 20.151.200.44:23593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/wp-login.php"] [unique_id "apPkSkmtdPfUFP1akVE2HgAABGI"]
[Sun Aug 30 03:05:30.579503 2026] [security2:error] [pid 495314:tid 495530] [client 20.63.219.114:18509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/defaults.php"] [unique_id "apPkSkmtdPfUFP1akVE2JwAABH4"]
[Sun Aug 30 03:05:30.594867 2026] [security2:error] [pid 495314:tid 495474] [client 216.73.216.128:7370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPkSkmtdPfUFP1akVE2KAAABEY"]
[Sun Aug 30 03:05:30.627500 2026] [security2:error] [pid 495314:tid 495455] [client 20.48.160.90:39961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/filefuns.php"] [unique_id "apPkSkmtdPfUFP1akVE2KgAABDM"]
[Sun Aug 30 03:05:30.654976 2026] [security2:error] [pid 495314:tid 495483] [client 40.83.93.50:18079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/radio.php"] [unique_id "apPkSkmtdPfUFP1akVE2LQAABE8"]
[Sun Aug 30 03:05:30.669047 2026] [security2:error] [pid 495314:tid 495537] [client 20.48.160.90:50674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/5656.php"] [unique_id "apPkSkmtdPfUFP1akVE2LwAABIU"]
[Sun Aug 30 03:05:30.698459 2026] [lsapi:warn] [pid 495314:tid 495363] [remote 186.236.19.31:43501] [host tastylandscape.com] Backend log: PHP Warning: Use of undefined constant user_level - assumed 'user_level' (this will throw an Error in a future version of PHP) in /home4/tommed/public_html/wp-content/plugins/ultimate-google-analytics/ultimate_ga.php on line 524\n
[Sun Aug 30 03:05:30.886865 2026] [security2:error] [pid 495314:tid 495551] [client 4.205.62.107:42583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/var/www/wallet/index.php"] [unique_id "apPkSkmtdPfUFP1akVE2QwAABJM"]
[Sun Aug 30 03:05:30.934594 2026] [security2:error] [pid 495314:tid 495567] [client 20.63.219.114:1354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/h.php"] [unique_id "apPkSkmtdPfUFP1akVE2RAAABKM"]
[Sun Aug 30 03:05:30.968206 2026] [authz_core:error] [pid 495314:tid 495520] [client 216.73.216.128:18243] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:30.968473 2026] [authz_core:error] [pid 495314:tid 495520] [client 216.73.216.128:18243] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:31.070908 2026] [security2:error] [pid 495314:tid 495516] [client 4.205.62.107:60506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/asdf.php"] [unique_id "apPkS0mtdPfUFP1akVE2UQAABHA"]
[Sun Aug 30 03:05:31.090858 2026] [authz_core:error] [pid 495314:tid 495538] [client 66.249.66.32:38584] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:31.091131 2026] [authz_core:error] [pid 495314:tid 495538] [client 66.249.66.32:38584] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:31.114452 2026] [security2:error] [pid 495314:tid 495550] [client 4.205.62.107:2950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/333.php"] [unique_id "apPkS0mtdPfUFP1akVE2VwAABJI"]
[Sun Aug 30 03:05:31.139692 2026] [security2:error] [pid 495314:tid 495502] [client 4.205.62.107:5078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/otuz1.php"] [unique_id "apPkS0mtdPfUFP1akVE2WgAABGI"]
[Sun Aug 30 03:05:31.148478 2026] [security2:error] [pid 495314:tid 495553] [client 68.155.159.216:59915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/install.php"] [unique_id "apPkS0mtdPfUFP1akVE2XAAABJU"]
[Sun Aug 30 03:05:31.189943 2026] [security2:error] [pid 495314:tid 495565] [client 40.83.93.50:18074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/functions.php"] [unique_id "apPkS0mtdPfUFP1akVE2XgAABKE"]
[Sun Aug 30 03:05:31.197558 2026] [security2:error] [pid 495314:tid 495526] [client 20.48.251.3:55464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/tinyfilemanager.php"] [unique_id "apPkS0mtdPfUFP1akVE2XwAABHo"]
[Sun Aug 30 03:05:31.204056 2026] [authz_core:error] [pid 495314:tid 495452] [client 66.249.66.198:44128] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:31.204354 2026] [authz_core:error] [pid 495314:tid 495452] [client 66.249.66.198:44128] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:31.205889 2026] [security2:error] [pid 495314:tid 495497] [client 4.205.62.107:62451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/rum.or.php"] [unique_id "apPkS0mtdPfUFP1akVE2YQAABF0"]
[Sun Aug 30 03:05:31.205975 2026] [security2:error] [pid 495314:tid 495495] [client 68.155.159.216:52660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apPkS0mtdPfUFP1akVE2YgAABFs"]
[Sun Aug 30 03:05:31.207051 2026] [security2:error] [pid 495314:tid 495478] [client 20.48.251.3:65483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/kedi.php"] [unique_id "apPkS0mtdPfUFP1akVE2YwAABEo"]
[Sun Aug 30 03:05:31.211551 2026] [security2:error] [pid 495314:tid 495486] [client 20.104.50.220:47064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/alf.php"] [unique_id "apPkS0mtdPfUFP1akVE2ZQAABFI"]
[Sun Aug 30 03:05:31.217671 2026] [authz_core:error] [pid 495314:tid 495510] [client 66.249.66.33:50529] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:31.217976 2026] [authz_core:error] [pid 495314:tid 495510] [client 66.249.66.33:50529] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:31.219624 2026] [security2:error] [pid 495314:tid 495485] [client 20.48.251.3:23301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/oc460l3x.php"] [unique_id "apPkS0mtdPfUFP1akVE2ZgAABFE"]
[Sun Aug 30 03:05:31.222400 2026] [security2:error] [pid 495314:tid 495484] [client 20.104.50.220:52844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/Unknown45.php"] [unique_id "apPkS0mtdPfUFP1akVE2ZwAABFA"]
[Sun Aug 30 03:05:31.222726 2026] [security2:error] [pid 495314:tid 495546] [client 20.104.50.220:52822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/cwshell.php"] [unique_id "apPkS0mtdPfUFP1akVE2aAAABI4"]
[Sun Aug 30 03:05:31.225532 2026] [security2:error] [pid 495314:tid 495481] [client 20.104.50.220:32525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/p0wny-shell.php"] [unique_id "apPkS0mtdPfUFP1akVE2aQAABE0"]
[Sun Aug 30 03:05:31.231492 2026] [security2:error] [pid 495314:tid 495530] [client 20.104.18.15:13739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/akismet.php"] [unique_id "apPkS0mtdPfUFP1akVE2agAABH4"]
[Sun Aug 30 03:05:31.232712 2026] [security2:error] [pid 495314:tid 495472] [client 68.155.159.216:59359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-admin/setup-config.php"] [unique_id "apPkS0mtdPfUFP1akVE2awAABEQ"]
[Sun Aug 30 03:05:31.234229 2026] [security2:error] [pid 495314:tid 495474] [client 20.104.50.220:33189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/done.php"] [unique_id "apPkS0mtdPfUFP1akVE2bQAABEY"]
[Sun Aug 30 03:05:31.234323 2026] [security2:error] [pid 495314:tid 495531] [client 20.104.50.220:5446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-content/radio.php"] [unique_id "apPkS0mtdPfUFP1akVE2bwAABH8"]
[Sun Aug 30 03:05:31.237717 2026] [security2:error] [pid 495314:tid 495473] [client 20.104.50.220:27437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/403.php"] [unique_id "apPkS0mtdPfUFP1akVE2cAAABEU"]
[Sun Aug 30 03:05:31.240962 2026] [security2:error] [pid 495314:tid 495483] [client 4.205.62.107:51721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/public/mah.php.php"] [unique_id "apPkS0mtdPfUFP1akVE2cgAABE8"]
[Sun Aug 30 03:05:31.249409 2026] [security2:error] [pid 495314:tid 495465] [client 4.205.62.107:18757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/05.php"] [unique_id "apPkS0mtdPfUFP1akVE2dQAABD0"]
[Sun Aug 30 03:05:31.251824 2026] [security2:error] [pid 495314:tid 495447] [client 20.151.200.44:46988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/motu.php"] [unique_id "apPkS0mtdPfUFP1akVE2dgAABCs"]
[Sun Aug 30 03:05:31.253824 2026] [security2:error] [pid 495314:tid 495561] [client 4.205.62.107:63938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/aww.php"] [unique_id "apPkS0mtdPfUFP1akVE2dwAABJ0"]
[Sun Aug 30 03:05:31.254239 2026] [security2:error] [pid 495314:tid 495532] [client 195.178.110.247:19966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mainstayglobal.com"] [uri "/index.php"] [unique_id "apPkS0mtdPfUFP1akVE2eAAABIA"]
[Sun Aug 30 03:05:31.254388 2026] [security2:error] [pid 495314:tid 495545] [client 20.104.50.220:63504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/Q2-.php"] [unique_id "apPkS0mtdPfUFP1akVE2eQAABI0"]
[Sun Aug 30 03:05:31.258903 2026] [security2:error] [pid 495314:tid 495569] [client 20.104.50.220:61663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/new.php"] [unique_id "apPkS0mtdPfUFP1akVE2ewAABKU"]
[Sun Aug 30 03:05:31.258960 2026] [security2:error] [pid 495314:tid 495499] [client 20.104.18.15:31627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/wp-includes/ID3/moon.php"] [unique_id "apPkS0mtdPfUFP1akVE2fAAABF8"]
[Sun Aug 30 03:05:31.265298 2026] [security2:error] [pid 495314:tid 495460] [client 20.48.251.3:64405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/app.default.php"] [unique_id "apPkS0mtdPfUFP1akVE2fgAABDg"]
[Sun Aug 30 03:05:31.266173 2026] [security2:error] [pid 495314:tid 495528] [client 20.104.18.15:43303] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "garypia.co"] [uri "/1.php"] [unique_id "apPkS0mtdPfUFP1akVE2fwAABHw"]
[Sun Aug 30 03:05:31.266237 2026] [security2:error] [pid 495314:tid 495528] [client 20.104.18.15:43303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/1.php"] [unique_id "apPkS0mtdPfUFP1akVE2fwAABHw"]
[Sun Aug 30 03:05:31.286404 2026] [security2:error] [pid 495314:tid 495523] [client 20.104.18.15:32964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/ano.php"] [unique_id "apPkS0mtdPfUFP1akVE2gQAABHc"]
[Sun Aug 30 03:05:31.300113 2026] [security2:error] [pid 495314:tid 495508] [client 20.48.251.3:55735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/saml.php"] [unique_id "apPkS0mtdPfUFP1akVE2ggAABGg"]
[Sun Aug 30 03:05:31.301141 2026] [security2:error] [pid 495314:tid 495500] [client 20.63.219.114:9604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/num.php"] [unique_id "apPkS0mtdPfUFP1akVE2gwAABGA"]
[Sun Aug 30 03:05:31.323207 2026] [security2:error] [pid 495314:tid 495480] [client 4.205.62.107:44444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/bigdump.php"] [unique_id "apPkS0mtdPfUFP1akVE2hAAABEw"]
[Sun Aug 30 03:05:31.333124 2026] [authz_core:error] [pid 495314:tid 495450] [client 216.73.216.128:25676] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:31.333399 2026] [authz_core:error] [pid 495314:tid 495450] [client 216.73.216.128:25676] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:31.344771 2026] [security2:error] [pid 495314:tid 495550] [client 4.205.62.107:36024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/agg.php"] [unique_id "apPkS0mtdPfUFP1akVE2hgAABJI"]
[Sun Aug 30 03:05:31.398897 2026] [authz_core:error] [pid 495314:tid 495445] [client 66.249.66.41:38180] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:31.399364 2026] [authz_core:error] [pid 495314:tid 495445] [client 66.249.66.41:38180] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:31.419349 2026] [security2:error] [pid 495314:tid 495496] [client 216.73.216.128:18243] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPkS0mtdPfUFP1akVE2igAABFw"]
[Sun Aug 30 03:05:31.425770 2026] [security2:error] [pid 495314:tid 495519] [client 195.178.110.247:14452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mainstayglobal.com"] [uri "/index.php"] [unique_id "apPkS0mtdPfUFP1akVE2iwAABHM"]
[Sun Aug 30 03:05:31.436167 2026] [security2:error] [pid 495314:tid 495497] [client 20.48.251.3:44342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/infos.php"] [unique_id "apPkS0mtdPfUFP1akVE2jQAABF0"]
[Sun Aug 30 03:05:31.436230 2026] [security2:error] [pid 495314:tid 495482] [client 20.48.251.3:34510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/test1.php"] [unique_id "apPkS0mtdPfUFP1akVE2jAAABE4"]
[Sun Aug 30 03:05:31.563291 2026] [security2:error] [pid 495314:tid 495556] [client 4.205.62.107:27322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/adminfus.php"] [unique_id "apPkS0mtdPfUFP1akVE2lwAABJg"]
[Sun Aug 30 03:05:31.600324 2026] [security2:error] [pid 495314:tid 495514] [client 216.73.216.128:25676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/_about"] [unique_id "apPkS0mtdPfUFP1akVE2mwAABG4"]
[Sun Aug 30 03:05:31.618102 2026] [core:alert] [pid 495314:tid 495444] [client 190.172.96.96:33838] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:05:31.631746 2026] [security2:error] [pid 495314:tid 495499] [client 20.104.49.130:52531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.katbacon.com"] [uri "/press.php"] [unique_id "apPkS0mtdPfUFP1akVE2nwAABF8"]
[Sun Aug 30 03:05:31.640727 2026] [security2:error] [pid 495314:tid 495518] [client 20.48.160.90:45923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/Hd.php"] [unique_id "apPkS0mtdPfUFP1akVE2oAAABHI"]
[Sun Aug 30 03:05:31.654613 2026] [security2:error] [pid 495314:tid 495460] [client 68.155.159.216:63502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkS0mtdPfUFP1akVE2oQAABDg"]
[Sun Aug 30 03:05:31.686875 2026] [security2:error] [pid 495314:tid 495475] [client 4.205.62.107:58144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/mamzi.php"] [unique_id "apPkS0mtdPfUFP1akVE2ogAABEc"]
[Sun Aug 30 03:05:31.706117 2026] [security2:error] [pid 495314:tid 495557] [client 20.63.219.114:9624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/abc.php"] [unique_id "apPkS0mtdPfUFP1akVE2pQAABJk"]
[Sun Aug 30 03:05:31.766379 2026] [security2:error] [pid 495314:tid 495448] [client 20.48.160.90:39999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp-cron.php"] [unique_id "apPkS0mtdPfUFP1akVE2qAAABCw"]
[Sun Aug 30 03:05:31.768056 2026] [security2:error] [pid 495314:tid 495508] [client 20.48.160.90:45875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/im.php"] [unique_id "apPkS0mtdPfUFP1akVE2qQAABGg"]
[Sun Aug 30 03:05:31.802088 2026] [security2:error] [pid 495314:tid 495385] [remote 213.32.77.104:59170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.77.32.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giantcameraphotobooth.ca"] [uri "/wp-login.php"] [unique_id "apPkS0mtdPfUFP1akVE2qwAEnUY"]
[Sun Aug 30 03:05:31.815756 2026] [security2:error] [pid 495314:tid 495528] [client 40.83.93.50:12081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/elp.php"] [unique_id "apPkS0mtdPfUFP1akVE2rAAABHw"]
[Sun Aug 30 03:05:31.854595 2026] [security2:error] [pid 495314:tid 495386] [remote 93.123.109.228:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "jaretdock.com"] [uri "/.env.backup"] [unique_id "apPkS0mtdPfUFP1akVE2rQAEZEc"]
[Sun Aug 30 03:05:31.879215 2026] [authz_core:error] [pid 495314:tid 495509] [client 66.249.66.44:65315] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:31.879485 2026] [authz_core:error] [pid 495314:tid 495509] [client 66.249.66.44:65315] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:31.897932 2026] [security2:error] [pid 495314:tid 495466] [client 20.48.160.90:40010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/lock360.php"] [unique_id "apPkS0mtdPfUFP1akVE2sAAABD4"]
[Sun Aug 30 03:05:31.901519 2026] [security2:error] [pid 495314:tid 495549] [client 20.48.160.90:40022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/fc.php"] [unique_id "apPkS0mtdPfUFP1akVE2sgAABJE"]
[Sun Aug 30 03:05:31.910480 2026] [security2:error] [pid 495314:tid 495524] [client 20.48.160.90:33228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/w3lls.php"] [unique_id "apPkS0mtdPfUFP1akVE2tAAABHg"]
[Sun Aug 30 03:05:31.934871 2026] [security2:error] [pid 495314:tid 495388] [remote 69.16.218.67:48370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.218.16.69.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "selectingwinners.com"] [uri "/wp-login.php"] [unique_id "apPkS0mtdPfUFP1akVE2tgAEjUk"]
[Sun Aug 30 03:05:31.967999 2026] [security2:error] [pid 495314:tid 495548] [client 4.205.62.107:25903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/old_phpinfo.php"] [unique_id "apPkS0mtdPfUFP1akVE2uQAABJA"]
[Sun Aug 30 03:05:31.981734 2026] [authz_core:error] [pid 495314:tid 495496] [client 216.73.216.128:18243] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:31.982004 2026] [authz_core:error] [pid 495314:tid 495496] [client 216.73.216.128:18243] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:31.996272 2026] [security2:error] [pid 495314:tid 495389] [remote 213.32.77.104:59170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.77.32.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giantcameraphotobooth.ca"] [uri "/wp-login.php"] [unique_id "apPkS0mtdPfUFP1akVE2vAAEc0o"], referer: https://giantcameraphotobooth.ca/wp-login.php
[Sun Aug 30 03:05:31.997558 2026] [security2:error] [pid 495314:tid 495390] [remote 93.123.109.228:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "jaretdock.com"] [uri "/.env.bak"] [unique_id "apPkS0mtdPfUFP1akVE2vgAEXUs"]
[Sun Aug 30 03:05:32.028707 2026] [security2:error] [pid 495314:tid 495502] [client 4.205.62.107:32012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPkTEmtdPfUFP1akVE2xAAABGI"]
[Sun Aug 30 03:05:32.028786 2026] [security2:error] [pid 495314:tid 495570] [client 20.48.160.90:45889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp-theme.php"] [unique_id "apPkTEmtdPfUFP1akVE2xQAABKY"]
[Sun Aug 30 03:05:32.037996 2026] [security2:error] [pid 495314:tid 495473] [client 20.48.160.90:40057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/ke.php"] [unique_id "apPkTEmtdPfUFP1akVE2ygAABEU"]
[Sun Aug 30 03:05:32.055590 2026] [security2:error] [pid 495314:tid 495478] [client 20.48.160.90:33216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/fpwch.php"] [unique_id "apPkTEmtdPfUFP1akVE2zQAABEo"]
[Sun Aug 30 03:05:32.066679 2026] [security2:error] [pid 495314:tid 495550] [client 20.63.219.114:1351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/default.php"] [unique_id "apPkTEmtdPfUFP1akVE2zwAABJI"]
[Sun Aug 30 03:05:32.070523 2026] [security2:error] [pid 495314:tid 495556] [client 4.205.62.107:42587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/124.php"] [unique_id "apPkTEmtdPfUFP1akVE20QAABJg"]
[Sun Aug 30 03:05:32.075745 2026] [security2:error] [pid 495314:tid 495541] [client 74.7.243.204:34678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/site/"] [unique_id "apPkTEmtdPfUFP1akVE20wAABIk"], referer: http://mail.letter7brands.com/site/?p=%2F%2Fetc
[Sun Aug 30 03:05:32.079021 2026] [authz_core:error] [pid 495314:tid 495538] [client 66.249.66.78:36784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:32.079286 2026] [authz_core:error] [pid 495314:tid 495538] [client 66.249.66.78:36784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:32.158550 2026] [security2:error] [pid 495314:tid 495540] [client 20.48.160.90:45844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/2d7433/index.php"] [unique_id "apPkTEmtdPfUFP1akVE24gAABIg"]
[Sun Aug 30 03:05:32.166943 2026] [security2:error] [pid 495314:tid 495458] [client 20.48.160.90:45877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/tf.php"] [unique_id "apPkTEmtdPfUFP1akVE24wAABDY"]
[Sun Aug 30 03:05:32.193236 2026] [security2:error] [pid 495314:tid 495500] [client 20.48.160.90:33176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/domvf.php"] [unique_id "apPkTEmtdPfUFP1akVE25wAABGA"]
[Sun Aug 30 03:05:32.203554 2026] [security2:error] [pid 495314:tid 495445] [client 4.205.62.107:60541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apPkTEmtdPfUFP1akVE26AAABCk"]
[Sun Aug 30 03:05:32.252138 2026] [security2:error] [pid 495314:tid 495395] [remote 69.16.218.67:48370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.218.16.69.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "selectingwinners.com"] [uri "/wp-login.php"] [unique_id "apPkTEmtdPfUFP1akVE26gAEVlA"], referer: https://selectingwinners.com/wp-login.php
[Sun Aug 30 03:05:32.256543 2026] [security2:error] [pid 495314:tid 495532] [client 4.205.62.107:2797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/G-in.php"] [unique_id "apPkTEmtdPfUFP1akVE26wAABIA"]
[Sun Aug 30 03:05:32.269889 2026] [security2:error] [pid 495314:tid 495558] [client 68.155.159.216:54090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-content/x/index.php"] [unique_id "apPkTEmtdPfUFP1akVE27AAABJo"]
[Sun Aug 30 03:05:32.280709 2026] [security2:error] [pid 495314:tid 495505] [client 4.205.62.107:4117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/update.php"] [unique_id "apPkTEmtdPfUFP1akVE27QAABGU"]
[Sun Aug 30 03:05:32.284574 2026] [security2:error] [pid 495314:tid 495511] [client 20.48.160.90:40028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp-login.php"] [unique_id "apPkTEmtdPfUFP1akVE27gAABGs"]
[Sun Aug 30 03:05:32.293114 2026] [security2:error] [pid 495314:tid 495463] [client 20.48.160.90:45836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/px.php"] [unique_id "apPkTEmtdPfUFP1akVE28AAABDs"]
[Sun Aug 30 03:05:32.293759 2026] [security2:error] [pid 495314:tid 495549] [client 20.48.251.3:7370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/cache-compat.php"] [unique_id "apPkTEmtdPfUFP1akVE28QAABJE"]
[Sun Aug 30 03:05:32.301338 2026] [security2:error] [pid 495314:tid 495545] [client 20.104.49.130:61376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.topatrust.com"] [uri "/ws45.php"] [unique_id "apPkTEmtdPfUFP1akVE28wAABI0"]
[Sun Aug 30 03:05:32.316802 2026] [security2:error] [pid 495314:tid 495548] [client 68.155.159.216:52716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/themes.php"] [unique_id "apPkTEmtdPfUFP1akVE29QAABJA"]
[Sun Aug 30 03:05:32.316825 2026] [security2:error] [pid 495314:tid 495567] [client 40.83.93.50:8371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/options-reading.php"] [unique_id "apPkTEmtdPfUFP1akVE29gAABKM"]
[Sun Aug 30 03:05:32.325264 2026] [security2:error] [pid 495314:tid 495520] [client 20.48.160.90:50589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/biufile.php"] [unique_id "apPkTEmtdPfUFP1akVE29wAABHQ"]
[Sun Aug 30 03:05:32.333427 2026] [security2:error] [pid 495314:tid 495562] [client 20.48.251.3:12069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/05.php"] [unique_id "apPkTEmtdPfUFP1akVE2-AAABJ4"]
[Sun Aug 30 03:05:32.348379 2026] [security2:error] [pid 495314:tid 495455] [client 20.104.50.220:46860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/alf4.php"] [unique_id "apPkTEmtdPfUFP1akVE2-gAABDM"]
[Sun Aug 30 03:05:32.349744 2026] [security2:error] [pid 495314:tid 495519] [client 20.48.251.3:23339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/drykl.php"] [unique_id "apPkTEmtdPfUFP1akVE2-wAABHM"]
[Sun Aug 30 03:05:32.359868 2026] [security2:error] [pid 495314:tid 495495] [client 20.104.50.220:52827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/vinus.php"] [unique_id "apPkTEmtdPfUFP1akVE2_AAABFs"]
[Sun Aug 30 03:05:32.361171 2026] [security2:error] [pid 495314:tid 495526] [client 20.104.50.220:62805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/iranshell.php"] [unique_id "apPkTEmtdPfUFP1akVE2_QAABHo"]
[Sun Aug 30 03:05:32.363051 2026] [security2:error] [pid 495314:tid 495485] [client 20.48.251.3:65511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/oc460l3x.php"] [unique_id "apPkTEmtdPfUFP1akVE2_gAABFE"]
[Sun Aug 30 03:05:32.366152 2026] [security2:error] [pid 495314:tid 495484] [client 68.155.159.216:60581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apPkTEmtdPfUFP1akVE2_wAABFA"]
[Sun Aug 30 03:05:32.366630 2026] [security2:error] [pid 495314:tid 495502] [client 20.104.50.220:32559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/ex0shell.php"] [unique_id "apPkTEmtdPfUFP1akVE3AAAABGI"]
[Sun Aug 30 03:05:32.371650 2026] [security2:error] [pid 495314:tid 495531] [client 20.104.50.220:27393] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/images/c99.php"] [unique_id "apPkTEmtdPfUFP1akVE3AgAABH8"]
[Sun Aug 30 03:05:32.386856 2026] [security2:error] [pid 495314:tid 495473] [client 4.205.62.107:63945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/maxro.php"] [unique_id "apPkTEmtdPfUFP1akVE3AwAABEU"]
[Sun Aug 30 03:05:32.388038 2026] [security2:error] [pid 495314:tid 495537] [client 4.205.62.107:56577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/zaza.php"] [unique_id "apPkTEmtdPfUFP1akVE3BAAABIU"]
[Sun Aug 30 03:05:32.388906 2026] [security2:error] [pid 495314:tid 495472] [client 20.104.50.220:33305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/eviltwin.php"] [unique_id "apPkTEmtdPfUFP1akVE3BQAABEQ"]
[Sun Aug 30 03:05:32.388930 2026] [security2:error] [pid 495314:tid 495521] [client 4.205.62.107:19001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/wp-blog.php"] [unique_id "apPkTEmtdPfUFP1akVE3BgAABHU"]
[Sun Aug 30 03:05:32.399615 2026] [security2:error] [pid 495314:tid 495450] [client 20.104.50.220:61439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/Sym.php"] [unique_id "apPkTEmtdPfUFP1akVE3BwAABC4"]
[Sun Aug 30 03:05:32.399956 2026] [security2:error] [pid 495314:tid 495530] [client 20.104.18.15:31607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/xmini4.php"] [unique_id "apPkTEmtdPfUFP1akVE3CQAABH4"]
[Sun Aug 30 03:05:32.400244 2026] [security2:error] [pid 495314:tid 495474] [client 20.104.18.15:13636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/ajax.php"] [unique_id "apPkTEmtdPfUFP1akVE3CAAABEY"]
[Sun Aug 30 03:05:32.405010 2026] [security2:error] [pid 495314:tid 495546] [client 20.104.50.220:5482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "apPkTEmtdPfUFP1akVE3CgAABI4"]
[Sun Aug 30 03:05:32.406327 2026] [security2:error] [pid 495314:tid 495478] [client 20.104.18.15:43988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/samll.php"] [unique_id "apPkTEmtdPfUFP1akVE3CwAABEo"]
[Sun Aug 30 03:05:32.409960 2026] [security2:error] [pid 495314:tid 495550] [client 4.205.62.107:22967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/xmy.php"] [unique_id "apPkTEmtdPfUFP1akVE3DAAABJI"]
[Sun Aug 30 03:05:32.414592 2026] [security2:error] [pid 495314:tid 495469] [client 20.48.251.3:6492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/app_local.php"] [unique_id "apPkTEmtdPfUFP1akVE3DQAABEE"]
[Sun Aug 30 03:05:32.414777 2026] [security2:error] [pid 495314:tid 495503] [client 20.104.50.220:63541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/python.php"] [unique_id "apPkTEmtdPfUFP1akVE3DgAABGM"]
[Sun Aug 30 03:05:32.415600 2026] [security2:error] [pid 495314:tid 495514] [client 20.104.18.15:32962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/mgrr.php"] [unique_id "apPkTEmtdPfUFP1akVE3DwAABG4"]
[Sun Aug 30 03:05:32.416687 2026] [security2:error] [pid 495314:tid 495524] [client 20.63.219.114:18532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/cloud.php"] [unique_id "apPkTEmtdPfUFP1akVE3EAAABHg"]
[Sun Aug 30 03:05:32.416777 2026] [security2:error] [pid 495314:tid 495467] [client 20.48.160.90:45839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/images.php"] [unique_id "apPkTEmtdPfUFP1akVE3EQAABD8"]
[Sun Aug 30 03:05:32.422043 2026] [security2:error] [pid 495314:tid 495539] [client 20.48.160.90:39990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/jg.php"] [unique_id "apPkTEmtdPfUFP1akVE3EwAABIc"]
[Sun Aug 30 03:05:32.437796 2026] [security2:error] [pid 495314:tid 495475] [client 20.48.251.3:59323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/aws_settings.php"] [unique_id "apPkTEmtdPfUFP1akVE3FwAABEc"]
[Sun Aug 30 03:05:32.457099 2026] [security2:error] [pid 495314:tid 495536] [client 4.205.62.107:44423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/wdf.php"] [unique_id "apPkTEmtdPfUFP1akVE3GAAABIQ"]
[Sun Aug 30 03:05:32.462055 2026] [security2:error] [pid 495314:tid 495554] [client 20.48.160.90:33230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/blacks.php"] [unique_id "apPkTEmtdPfUFP1akVE3GgAABJY"]
[Sun Aug 30 03:05:32.548538 2026] [security2:error] [pid 495314:tid 495461] [client 20.48.160.90:26706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/ops.php"] [unique_id "apPkTEmtdPfUFP1akVE3IAAABDk"]
[Sun Aug 30 03:05:32.558394 2026] [security2:error] [pid 495314:tid 495532] [client 20.48.160.90:39960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/yj.php"] [unique_id "apPkTEmtdPfUFP1akVE3IQAABIA"]
[Sun Aug 30 03:05:32.575659 2026] [security2:error] [pid 495314:tid 495462] [client 20.48.251.3:4695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/env.php"] [unique_id "apPkTEmtdPfUFP1akVE3IgAABDo"]
[Sun Aug 30 03:05:32.612183 2026] [security2:error] [pid 495314:tid 495511] [client 4.205.62.107:36576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/requirements.php"] [unique_id "apPkTEmtdPfUFP1akVE3JQAABGs"]
[Sun Aug 30 03:05:32.613761 2026] [authz_core:error] [pid 495314:tid 495504] [client 66.249.66.202:39113] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:32.614050 2026] [authz_core:error] [pid 495314:tid 495504] [client 66.249.66.202:39113] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:32.669189 2026] [security2:error] [pid 495314:tid 495557] [client 20.151.200.44:63668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/wp-access.php"] [unique_id "apPkTEmtdPfUFP1akVE3JwAABJk"]
[Sun Aug 30 03:05:32.676260 2026] [security2:error] [pid 495314:tid 495562] [client 20.48.160.90:45932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPkTEmtdPfUFP1akVE3KAAABJ4"]
[Sun Aug 30 03:05:32.692718 2026] [security2:error] [pid 495314:tid 495555] [client 20.48.160.90:40035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/zi.php"] [unique_id "apPkTEmtdPfUFP1akVE3KQAABJc"]
[Sun Aug 30 03:05:32.713027 2026] [security2:error] [pid 495314:tid 495519] [client 20.48.160.90:50598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/beck.php"] [unique_id "apPkTEmtdPfUFP1akVE3KwAABHM"]
[Sun Aug 30 03:05:32.767135 2026] [security2:error] [pid 495314:tid 495520] [client 20.63.219.114:1358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/admin.php"] [unique_id "apPkTEmtdPfUFP1akVE3LQAABHQ"]
[Sun Aug 30 03:05:32.784901 2026] [authz_core:error] [pid 495314:tid 495485] [client 66.249.66.33:60564] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:32.785166 2026] [authz_core:error] [pid 495314:tid 495485] [client 66.249.66.33:60564] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:32.801325 2026] [security2:error] [pid 495314:tid 495533] [client 40.83.93.50:9071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/db.php"] [unique_id "apPkTEmtdPfUFP1akVE3MgAABIE"]
[Sun Aug 30 03:05:32.802220 2026] [security2:error] [pid 495314:tid 495484] [client 20.48.251.3:34573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/bigdump.php"] [unique_id "apPkTEmtdPfUFP1akVE3MwAABFA"]
[Sun Aug 30 03:05:32.803826 2026] [security2:error] [pid 495314:tid 495398] [remote 108.167.161.148:11960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.161.167.108.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "texascleanteam.com"] [uri "/wp-login.php"] [unique_id "apPkTEmtdPfUFP1akVE3MAAEMlM"]
[Sun Aug 30 03:05:32.806591 2026] [security2:error] [pid 495314:tid 495502] [client 20.48.160.90:45842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPkTEmtdPfUFP1akVE3NAAABGI"]
[Sun Aug 30 03:05:32.819864 2026] [security2:error] [pid 495314:tid 495570] [client 20.48.160.90:45900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/ue.php"] [unique_id "apPkTEmtdPfUFP1akVE3NQAABKY"]
[Sun Aug 30 03:05:32.860849 2026] [security2:error] [pid 495314:tid 495487] [client 20.48.160.90:50602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/t3.php"] [unique_id "apPkTEmtdPfUFP1akVE3OAAABFM"]
[Sun Aug 30 03:05:32.874800 2026] [security2:error] [pid 495314:tid 495522] [client 90.28.192.77:52566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.192.28.90.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "filtagreen.com"] [uri "/wp-login.php"] [unique_id "apPkTEmtdPfUFP1akVE3NgAABHY"]
[Sun Aug 30 03:05:32.899448 2026] [security2:error] [pid 495314:tid 495450] [client 68.155.159.216:62293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkTEmtdPfUFP1akVE3OgAABC4"]
[Sun Aug 30 03:05:32.911583 2026] [security2:error] [pid 495314:tid 495538] [client 4.205.62.107:65312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/public/rip.php.php"] [unique_id "apPkTEmtdPfUFP1akVE3OwAABIY"]
[Sun Aug 30 03:05:32.936334 2026] [security2:error] [pid 495314:tid 495571] [client 20.48.160.90:45937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/about.php"] [unique_id "apPkTEmtdPfUFP1akVE3PQAABKc"]
[Sun Aug 30 03:05:32.949265 2026] [security2:error] [pid 495314:tid 495503] [client 20.48.160.90:39937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/nv.php"] [unique_id "apPkTEmtdPfUFP1akVE3PwAABGM"]
[Sun Aug 30 03:05:32.975728 2026] [authz_core:error] [pid 495314:tid 495546] [client 66.249.66.32:42638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:32.976071 2026] [authz_core:error] [pid 495314:tid 495546] [client 66.249.66.32:42638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:32.993456 2026] [security2:error] [pid 495314:tid 495401] [remote 108.167.161.148:11960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.161.167.108.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "texascleanteam.com"] [uri "/wp-login.php"] [unique_id "apPkTEmtdPfUFP1akVE3RAAEN1Y"], referer: https://texascleanteam.com/wp-login.php
[Sun Aug 30 03:05:33.001111 2026] [security2:error] [pid 495314:tid 495475] [client 20.48.160.90:19936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/wp.php"] [unique_id "apPkTUmtdPfUFP1akVE3SAAABEc"]
[Sun Aug 30 03:05:33.063707 2026] [security2:error] [pid 495314:tid 495512] [client 20.48.160.90:45869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/admin.php/admin.php"] [unique_id "apPkTUmtdPfUFP1akVE3UwAABGw"]
[Sun Aug 30 03:05:33.064532 2026] [security2:error] [pid 495314:tid 495542] [client 20.48.251.3:6485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/aws_keys.php"] [unique_id "apPkTUmtdPfUFP1akVE3VQAABIo"]
[Sun Aug 30 03:05:33.075688 2026] [security2:error] [pid 495314:tid 495528] [client 20.48.160.90:45894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/jw.php"] [unique_id "apPkTUmtdPfUFP1akVE3WgAABHw"]
[Sun Aug 30 03:05:33.099506 2026] [security2:error] [pid 495314:tid 495532] [client 20.151.200.44:47081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/wefile.php"] [unique_id "apPkTUmtdPfUFP1akVE3XAAABIA"]
[Sun Aug 30 03:05:33.125991 2026] [security2:error] [pid 495314:tid 495444] [client 20.63.219.114:1401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/index.php"] [unique_id "apPkTUmtdPfUFP1akVE3YAAABCg"]
[Sun Aug 30 03:05:33.165857 2026] [security2:error] [pid 495314:tid 495448] [client 4.205.62.107:26536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/avim.php"] [unique_id "apPkTUmtdPfUFP1akVE3ZgAABCw"]
[Sun Aug 30 03:05:33.167955 2026] [security2:error] [pid 495314:tid 495562] [client 20.48.160.90:50595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/abcd.php"] [unique_id "apPkTUmtdPfUFP1akVE3ZwAABJ4"]
[Sun Aug 30 03:05:33.173924 2026] [security2:error] [pid 495314:tid 495519] [client 4.205.62.107:25516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.timallport.com"] [uri "/wp-act.php"] [unique_id "apPkTUmtdPfUFP1akVE3aQAABHM"]
[Sun Aug 30 03:05:33.198404 2026] [security2:error] [pid 495314:tid 495520] [client 20.48.160.90:40005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/media.php"] [unique_id "apPkTUmtdPfUFP1akVE3agAABHQ"]
[Sun Aug 30 03:05:33.209122 2026] [security2:error] [pid 495314:tid 495516] [client 20.48.160.90:45948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/or.php"] [unique_id "apPkTUmtdPfUFP1akVE3bAAABHA"]
[Sun Aug 30 03:05:33.245066 2026] [security2:error] [pid 495314:tid 495410] [remote 93.123.109.228:57772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "jaretdock.com"] [uri "/.env.swp"] [unique_id "apPkTUmtdPfUFP1akVE3dQAEhV8"]
[Sun Aug 30 03:05:33.249486 2026] [security2:error] [pid 495314:tid 495507] [client 216.73.216.128:46464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPkTUmtdPfUFP1akVE3dgAABGc"]
[Sun Aug 30 03:05:33.280710 2026] [security2:error] [pid 495314:tid 495501] [client 40.83.93.50:12034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/server.php"] [unique_id "apPkTUmtdPfUFP1akVE3eQAABGE"]
[Sun Aug 30 03:05:33.308279 2026] [security2:error] [pid 495314:tid 495478] [client 4.205.62.107:31734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPkTUmtdPfUFP1akVE3ewAABEo"]
[Sun Aug 30 03:05:33.309446 2026] [security2:error] [pid 495314:tid 495564] [client 4.205.62.107:42856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/test1.php"] [unique_id "apPkTUmtdPfUFP1akVE3fQAABKA"]
[Sun Aug 30 03:05:33.319174 2026] [security2:error] [pid 495314:tid 495469] [client 20.48.160.90:50663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/nofile.php"] [unique_id "apPkTUmtdPfUFP1akVE3fwAABEE"]
[Sun Aug 30 03:05:33.330844 2026] [security2:error] [pid 495314:tid 495514] [client 20.48.160.90:45896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/mac.php"] [unique_id "apPkTUmtdPfUFP1akVE3gAAABG4"]
[Sun Aug 30 03:05:33.342496 2026] [security2:error] [pid 495314:tid 495565] [client 4.205.62.107:60518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/hochladen.form.php"] [unique_id "apPkTUmtdPfUFP1akVE3gQAABKE"]
[Sun Aug 30 03:05:33.346319 2026] [security2:error] [pid 495314:tid 495459] [client 20.48.160.90:26710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/ile56.php"] [unique_id "apPkTUmtdPfUFP1akVE3gwAABDc"]
[Sun Aug 30 03:05:33.378458 2026] [security2:error] [pid 495314:tid 495462] [client 43.119.100.103:43461] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "tastylandscape.com"] [uri "/wp-content/plugins/burst-statistics/endpoint.php"] [unique_id "apPkTUmtdPfUFP1akVE3hQAABDo"], referer: https://tastylandscape.com/2014/11/29/best-way-propagate-geranium/
[Sun Aug 30 03:05:33.417809 2026] [security2:error] [pid 495314:tid 495518] [client 4.205.62.107:4118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/channels.php"] [unique_id "apPkTUmtdPfUFP1akVE3iAAABHI"]
[Sun Aug 30 03:05:33.420990 2026] [security2:error] [pid 495314:tid 495568] [client 68.155.159.216:54724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-mail.php"] [unique_id "apPkTUmtdPfUFP1akVE3iQAABKQ"]
[Sun Aug 30 03:05:33.444311 2026] [lsapi:warn] [pid 495314:tid 495510] [client 43.119.104.194:41423] [host tastylandscape.com] Backend log: PHP Warning: Use of undefined constant user_level - assumed 'user_level' (this will throw an Error in a future version of PHP) in /home4/tommed/public_html/wp-content/plugins/ultimate-google-analytics/ultimate_ga.php on line 524\n, referer: https://tastylandscape.com/2014/11/29/best-way-propagate-geranium/
[Sun Aug 30 03:05:33.453259 2026] [security2:error] [pid 495314:tid 495517] [client 20.48.160.90:50611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/run.php"] [unique_id "apPkTUmtdPfUFP1akVE3jwAABHE"]
[Sun Aug 30 03:05:33.465670 2026] [security2:error] [pid 495314:tid 495458] [client 4.205.62.107:31701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/session.php"] [unique_id "apPkTUmtdPfUFP1akVE3kAAABDY"]
[Sun Aug 30 03:05:33.467003 2026] [security2:error] [pid 495314:tid 495468] [client 20.48.160.90:45897] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.appsneakpeek.com"] [uri "/1.php"] [unique_id "apPkTUmtdPfUFP1akVE3kQAABEA"]
[Sun Aug 30 03:05:33.467113 2026] [security2:error] [pid 495314:tid 495468] [client 20.48.160.90:45897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/1.php"] [unique_id "apPkTUmtdPfUFP1akVE3kQAABEA"]
[Sun Aug 30 03:05:33.472941 2026] [security2:error] [pid 495314:tid 495542] [client 68.155.159.216:59973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apPkTUmtdPfUFP1akVE3kgAABIo"]
[Sun Aug 30 03:05:33.474218 2026] [security2:error] [pid 495314:tid 495499] [client 20.63.219.114:15123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/php8.php"] [unique_id "apPkTUmtdPfUFP1akVE3kwAABF8"]
[Sun Aug 30 03:05:33.475248 2026] [security2:error] [pid 495314:tid 495445] [client 20.48.251.3:49949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/wp-blog.php"] [unique_id "apPkTUmtdPfUFP1akVE3lAAABCk"]
[Sun Aug 30 03:05:33.475287 2026] [security2:error] [pid 495314:tid 495528] [client 68.155.159.216:60567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apPkTUmtdPfUFP1akVE3lQAABHw"]
[Sun Aug 30 03:05:33.478668 2026] [security2:error] [pid 495314:tid 495481] [client 20.48.160.90:45950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/emmh.php"] [unique_id "apPkTUmtdPfUFP1akVE3lgAABE0"]
[Sun Aug 30 03:05:33.483567 2026] [security2:error] [pid 495314:tid 495476] [client 20.48.251.3:22768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/rpk.php"] [unique_id "apPkTUmtdPfUFP1akVE3mAAABEg"]
[Sun Aug 30 03:05:33.484665 2026] [security2:error] [pid 495314:tid 495532] [client 4.205.62.107:2791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/apikeys.php"] [unique_id "apPkTUmtdPfUFP1akVE3mQAABIA"]
[Sun Aug 30 03:05:33.486522 2026] [security2:error] [pid 495314:tid 495504] [client 20.104.50.220:47060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/alfa-shell-v4.php"] [unique_id "apPkTUmtdPfUFP1akVE3nAAABGQ"]
[Sun Aug 30 03:05:33.501386 2026] [security2:error] [pid 495314:tid 495444] [client 20.48.251.3:65502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/drykl.php"] [unique_id "apPkTUmtdPfUFP1akVE3ngAABCg"]
[Sun Aug 30 03:05:33.501442 2026] [security2:error] [pid 495314:tid 495560] [client 20.104.50.220:28713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/indishell.php"] [unique_id "apPkTUmtdPfUFP1akVE3nwAABJw"]
[Sun Aug 30 03:05:33.502957 2026] [security2:error] [pid 495314:tid 495558] [client 20.104.50.220:27441] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/images/c99.php"] [unique_id "apPkTUmtdPfUFP1akVE3oAAABJo"]
[Sun Aug 30 03:05:33.503118 2026] [security2:error] [pid 495314:tid 495479] [client 20.104.50.220:29165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/store.php"] [unique_id "apPkTUmtdPfUFP1akVE3oQAABEs"]
[Sun Aug 30 03:05:33.517954 2026] [security2:error] [pid 495314:tid 495448] [client 20.104.50.220:31883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/exp.php"] [unique_id "apPkTUmtdPfUFP1akVE3pAAABCw"]
[Sun Aug 30 03:05:33.520699 2026] [security2:error] [pid 495314:tid 495555] [client 4.205.62.107:63968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/brc.php"] [unique_id "apPkTUmtdPfUFP1akVE3pQAABJc"]
[Sun Aug 30 03:05:33.533321 2026] [authz_core:error] [pid 495314:tid 495488] [client 216.73.216.128:18698] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:33.533601 2026] [authz_core:error] [pid 495314:tid 495488] [client 216.73.216.128:18698] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:33.536628 2026] [security2:error] [pid 495314:tid 495519] [client 20.104.18.15:31714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/gulu.php"] [unique_id "apPkTUmtdPfUFP1akVE3pwAABHM"]
[Sun Aug 30 03:05:33.542362 2026] [security2:error] [pid 495314:tid 495566] [client 20.104.50.220:32881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/manage.php"] [unique_id "apPkTUmtdPfUFP1akVE3qAAABKI"]
[Sun Aug 30 03:05:33.542697 2026] [security2:error] [pid 495314:tid 495520] [client 20.104.50.220:5214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/admin.php"] [unique_id "apPkTUmtdPfUFP1akVE3qQAABHQ"]
[Sun Aug 30 03:05:33.546051 2026] [security2:error] [pid 495314:tid 495540] [client 20.104.50.220:61878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/dom.php"] [unique_id "apPkTUmtdPfUFP1akVE3qgAABIg"]
[Sun Aug 30 03:05:33.546501 2026] [security2:error] [pid 495314:tid 495495] [client 4.205.62.107:56603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/u88.php"] [unique_id "apPkTUmtdPfUFP1akVE3qwAABFs"]
[Sun Aug 30 03:05:33.555702 2026] [security2:error] [pid 495314:tid 495454] [client 20.104.18.15:13641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/atomlib.php"] [unique_id "apPkTUmtdPfUFP1akVE3rAAABDI"]
[Sun Aug 30 03:05:33.559604 2026] [security2:error] [pid 495314:tid 495570] [client 20.104.18.15:43983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/she11.php"] [unique_id "apPkTUmtdPfUFP1akVE3rQAABKY"]
[Sun Aug 30 03:05:33.563471 2026] [security2:error] [pid 495314:tid 495533] [client 20.104.50.220:56712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-pop.php"] [unique_id "apPkTUmtdPfUFP1akVE3rwAABIE"]
[Sun Aug 30 03:05:33.563606 2026] [security2:error] [pid 495314:tid 495453] [client 20.48.251.3:6508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/ws62.php"] [unique_id "apPkTUmtdPfUFP1akVE3sAAABDE"]
[Sun Aug 30 03:05:33.565577 2026] [security2:error] [pid 495314:tid 495497] [client 4.205.62.107:18760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/erty.php"] [unique_id "apPkTUmtdPfUFP1akVE3sQAABF0"]
[Sun Aug 30 03:05:33.575008 2026] [security2:error] [pid 495314:tid 495500] [client 20.104.18.15:32989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/mac.php"] [unique_id "apPkTUmtdPfUFP1akVE3swAABGA"]
[Sun Aug 30 03:05:33.576588 2026] [security2:error] [pid 495314:tid 495522] [client 20.48.251.3:52764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/wp-konfig.backup.php"] [unique_id "apPkTUmtdPfUFP1akVE3tAAABHY"]
[Sun Aug 30 03:05:33.582745 2026] [security2:error] [pid 495314:tid 495507] [client 4.205.62.107:22536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/ms-edit.php"] [unique_id "apPkTUmtdPfUFP1akVE3tgAABGc"]
[Sun Aug 30 03:05:33.595391 2026] [security2:error] [pid 495314:tid 495541] [client 4.205.62.107:44748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/bb.php"] [unique_id "apPkTUmtdPfUFP1akVE3uAAABIk"]
[Sun Aug 30 03:05:33.600880 2026] [security2:error] [pid 495314:tid 495474] [client 20.48.160.90:50607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/new.php"] [unique_id "apPkTUmtdPfUFP1akVE3uQAABEY"]
[Sun Aug 30 03:05:33.606402 2026] [security2:error] [pid 495314:tid 495564] [client 20.48.160.90:45872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/classwithtostring.php"] [unique_id "apPkTUmtdPfUFP1akVE3ugAABKA"]
[Sun Aug 30 03:05:33.628919 2026] [authz_core:error] [pid 495314:tid 495473] [client 66.249.66.70:59178] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:33.629362 2026] [authz_core:error] [pid 495314:tid 495473] [client 66.249.66.70:59178] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:33.632389 2026] [security2:error] [pid 495314:tid 495452] [client 20.48.160.90:26691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/em.php"] [unique_id "apPkTUmtdPfUFP1akVE3vgAABDA"]
[Sun Aug 30 03:05:33.698657 2026] [security2:error] [pid 495314:tid 495505] [client 20.104.50.220:63541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/marjan.php"] [unique_id "apPkTUmtdPfUFP1akVE3wQAABGU"]
[Sun Aug 30 03:05:33.727296 2026] [security2:error] [pid 495314:tid 495468] [client 20.48.251.3:4676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/xve22.php"] [unique_id "apPkTUmtdPfUFP1akVE3xAAABEA"]
[Sun Aug 30 03:05:33.748770 2026] [security2:error] [pid 495314:tid 495445] [client 20.48.160.90:45857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp-ws68.php"] [unique_id "apPkTUmtdPfUFP1akVE3xgAABCk"]
[Sun Aug 30 03:05:33.748923 2026] [security2:error] [pid 495314:tid 495450] [client 40.83.93.50:9078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/favicon.php"] [unique_id "apPkTUmtdPfUFP1akVE3xwAABC4"]
[Sun Aug 30 03:05:33.761892 2026] [security2:error] [pid 495314:tid 495491] [client 20.48.160.90:39948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/dvve.php"] [unique_id "apPkTUmtdPfUFP1akVE3ygAABFc"]
[Sun Aug 30 03:05:33.769292 2026] [security2:error] [pid 495314:tid 495532] [client 20.151.200.44:37838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/txets.php"] [unique_id "apPkTUmtdPfUFP1akVE3ywAABIA"]
[Sun Aug 30 03:05:33.775327 2026] [security2:error] [pid 495314:tid 495460] [client 20.48.160.90:33247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/inx.php"] [unique_id "apPkTUmtdPfUFP1akVE3zAAABDg"]
[Sun Aug 30 03:05:33.779343 2026] [security2:error] [pid 495314:tid 495463] [client 20.151.200.44:62988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/wp-content/admin.php"] [unique_id "apPkTUmtdPfUFP1akVE3zQAABDs"]
[Sun Aug 30 03:05:33.800248 2026] [security2:error] [pid 495314:tid 495444] [client 216.73.216.128:18698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPkTUmtdPfUFP1akVE3zgAABCg"]
[Sun Aug 30 03:05:33.816405 2026] [authz_core:error] [pid 495314:tid 495559] [client 66.249.66.74:45822] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:33.816775 2026] [authz_core:error] [pid 495314:tid 495559] [client 66.249.66.74:45822] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:33.824880 2026] [security2:error] [pid 495314:tid 495494] [client 20.63.219.114:9640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/function.php"] [unique_id "apPkTUmtdPfUFP1akVE30QAABFo"]
[Sun Aug 30 03:05:33.883656 2026] [security2:error] [pid 495314:tid 495477] [client 20.48.160.90:45849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/simple.php"] [unique_id "apPkTUmtdPfUFP1akVE31AAABEk"]
[Sun Aug 30 03:05:33.890951 2026] [security2:error] [pid 495314:tid 495562] [client 20.48.160.90:39967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/doo.php"] [unique_id "apPkTUmtdPfUFP1akVE31gAABJ4"]
[Sun Aug 30 03:05:33.959627 2026] [security2:error] [pid 495314:tid 495500] [client 20.48.160.90:50618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/vpn.php"] [unique_id "apPkTUmtdPfUFP1akVE32wAABGA"]
[Sun Aug 30 03:05:33.977255 2026] [authz_core:error] [pid 495314:tid 495529] [client 66.249.66.206:45075] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:33.977565 2026] [authz_core:error] [pid 495314:tid 495529] [client 66.249.66.206:45075] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:34.012148 2026] [security2:error] [pid 495314:tid 495496] [client 20.48.160.90:45933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/aaa.php"] [unique_id "apPkTkmtdPfUFP1akVE35AAABFw"]
[Sun Aug 30 03:05:34.025902 2026] [security2:error] [pid 495314:tid 495553] [client 20.48.160.90:45826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/adminer-4.6.6.php"] [unique_id "apPkTkmtdPfUFP1akVE35wAABJU"]
[Sun Aug 30 03:05:34.039886 2026] [security2:error] [pid 495314:tid 495475] [client 4.205.62.107:36610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/var/www/wallet/index.php"] [unique_id "apPkTkmtdPfUFP1akVE36wAABEc"]
[Sun Aug 30 03:05:34.057234 2026] [security2:error] [pid 495314:tid 495535] [client 4.205.62.107:65351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/environment.php"] [unique_id "apPkTkmtdPfUFP1akVE37wAABIM"]
[Sun Aug 30 03:05:34.066390 2026] [security2:error] [pid 495314:tid 495456] [client 20.48.251.3:59116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/wdf.php"] [unique_id "apPkTkmtdPfUFP1akVE38QAABDQ"]
[Sun Aug 30 03:05:34.082753 2026] [authz_core:error] [pid 495314:tid 495505] [client 216.73.216.128:29535] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:34.083152 2026] [authz_core:error] [pid 495314:tid 495505] [client 216.73.216.128:29535] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:34.108540 2026] [security2:error] [pid 495314:tid 495457] [client 20.48.160.90:33225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/shiny.php"] [unique_id "apPkTkmtdPfUFP1akVE3-AAABDU"]
[Sun Aug 30 03:05:34.125808 2026] [security2:error] [pid 495314:tid 495491] [client 68.155.159.216:63494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apPkTkmtdPfUFP1akVE3_AAABFc"]
[Sun Aug 30 03:05:34.158082 2026] [security2:error] [pid 495314:tid 495460] [client 20.48.160.90:26736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/gelap1.php"] [unique_id "apPkTkmtdPfUFP1akVE4AAAABDg"]
[Sun Aug 30 03:05:34.166890 2026] [security2:error] [pid 495314:tid 495511] [client 216.73.216.128:18243] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPkTkmtdPfUFP1akVE4AQAABGs"]
[Sun Aug 30 03:05:34.259416 2026] [security2:error] [pid 495314:tid 495451] [client 20.63.219.114:9644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/about.php"] [unique_id "apPkTkmtdPfUFP1akVE4BgAABC8"]
[Sun Aug 30 03:05:34.277916 2026] [security2:error] [pid 495314:tid 495486] [client 40.83.93.50:12046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/gecko.php"] [unique_id "apPkTkmtdPfUFP1akVE4CAAABFI"]
[Sun Aug 30 03:05:34.284903 2026] [security2:error] [pid 495314:tid 495487] [client 20.48.160.90:45898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/rsjlrria.php"] [unique_id "apPkTkmtdPfUFP1akVE4CgAABFM"]
[Sun Aug 30 03:05:34.289032 2026] [security2:error] [pid 495314:tid 495502] [client 20.48.160.90:50579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/goods.php"] [unique_id "apPkTkmtdPfUFP1akVE4DAAABGI"]
[Sun Aug 30 03:05:34.301380 2026] [security2:error] [pid 495314:tid 495557] [client 20.48.160.90:39944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/shiny.php"] [unique_id "apPkTkmtdPfUFP1akVE4DgAABJk"]
[Sun Aug 30 03:05:34.417058 2026] [security2:error] [pid 495314:tid 495497] [client 20.48.160.90:26716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/AxAo.php"] [unique_id "apPkTkmtdPfUFP1akVE4EQAABF0"]
[Sun Aug 30 03:05:34.429378 2026] [security2:error] [pid 495314:tid 495500] [client 20.48.160.90:39954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/goods.php"] [unique_id "apPkTkmtdPfUFP1akVE4EgAABGA"]
[Sun Aug 30 03:05:34.452386 2026] [security2:error] [pid 495314:tid 495522] [client 20.48.160.90:50570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/alfa.php"] [unique_id "apPkTkmtdPfUFP1akVE4FQAABHY"]
[Sun Aug 30 03:05:34.472080 2026] [authz_core:error] [pid 495314:tid 495447] [client 66.249.66.75:36232] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:34.472376 2026] [authz_core:error] [pid 495314:tid 495447] [client 66.249.66.75:36232] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:34.481404 2026] [security2:error] [pid 495314:tid 495527] [client 4.205.62.107:63774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/debuggen.php"] [unique_id "apPkTkmtdPfUFP1akVE4FwAABHs"]
[Sun Aug 30 03:05:34.517825 2026] [security2:error] [pid 495314:tid 495514] [client 20.151.200.44:62930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/log.php"] [unique_id "apPkTkmtdPfUFP1akVE4HAAABG4"]
[Sun Aug 30 03:05:34.529524 2026] [security2:error] [pid 495314:tid 495515] [client 68.155.159.216:52631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/cgi-bin/index.php"] [unique_id "apPkTkmtdPfUFP1akVE4HQAABG8"]
[Sun Aug 30 03:05:34.549194 2026] [security2:error] [pid 495314:tid 495508] [client 20.48.160.90:39981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/class17.php"] [unique_id "apPkTkmtdPfUFP1akVE4IAAABGg"]
[Sun Aug 30 03:05:34.580156 2026] [security2:error] [pid 495314:tid 495470] [client 4.205.62.107:4156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/zz.php"] [unique_id "apPkTkmtdPfUFP1akVE4IgAABEI"]
[Sun Aug 30 03:05:34.582259 2026] [security2:error] [pid 495314:tid 495448] [client 20.48.160.90:45847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/000.php/index.php"] [unique_id "apPkTkmtdPfUFP1akVE4IwAABCw"]
[Sun Aug 30 03:05:34.624767 2026] [security2:error] [pid 495314:tid 495468] [client 20.48.251.3:23333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/saml.php"] [unique_id "apPkTkmtdPfUFP1akVE4KAAABEA"]
[Sun Aug 30 03:05:34.628624 2026] [security2:error] [pid 495314:tid 495449] [client 20.48.160.90:50660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/33.php"] [unique_id "apPkTkmtdPfUFP1akVE4KQAABC0"]
[Sun Aug 30 03:05:34.633658 2026] [security2:error] [pid 495314:tid 495512] [client 20.104.50.220:27447] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/images/c99.php"] [unique_id "apPkTkmtdPfUFP1akVE4KgAABGw"]
[Sun Aug 30 03:05:34.637323 2026] [security2:error] [pid 495314:tid 495549] [client 20.48.251.3:65527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/rpk.php"] [unique_id "apPkTkmtdPfUFP1akVE4KwAABJE"]
[Sun Aug 30 03:05:34.637883 2026] [security2:error] [pid 495314:tid 495554] [client 20.104.50.220:46337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/alfakun.php"] [unique_id "apPkTkmtdPfUFP1akVE4LAAABJY"]
[Sun Aug 30 03:05:34.643731 2026] [security2:error] [pid 495314:tid 495473] [client 20.104.50.220:28726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/zehirshell.php"] [unique_id "apPkTkmtdPfUFP1akVE4LgAABEU"]
[Sun Aug 30 03:05:34.643775 2026] [security2:error] [pid 495314:tid 495551] [client 20.104.50.220:29162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/unzip.php"] [unique_id "apPkTkmtdPfUFP1akVE4LQAABJM"]
[Sun Aug 30 03:05:34.645920 2026] [security2:error] [pid 495314:tid 495450] [client 4.205.62.107:2310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/motu.php"] [unique_id "apPkTkmtdPfUFP1akVE4LwAABC4"]
[Sun Aug 30 03:05:34.648655 2026] [security2:error] [pid 495314:tid 495550] [client 20.63.219.114:18530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/new.php"] [unique_id "apPkTkmtdPfUFP1akVE4MAAABJI"]
[Sun Aug 30 03:05:34.657161 2026] [security2:error] [pid 495314:tid 495491] [client 68.155.159.216:59992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apPkTkmtdPfUFP1akVE4MQAABFc"]
[Sun Aug 30 03:05:34.658710 2026] [security2:error] [pid 495314:tid 495531] [client 68.155.159.216:52849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apPkTkmtdPfUFP1akVE4MgAABH8"]
[Sun Aug 30 03:05:34.661549 2026] [security2:error] [pid 495314:tid 495476] [client 4.205.62.107:63995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/vx.php"] [unique_id "apPkTkmtdPfUFP1akVE4MwAABEg"]
[Sun Aug 30 03:05:34.668670 2026] [security2:error] [pid 495314:tid 495532] [client 20.104.49.130:36330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.katbacon.com"] [uri "/edit.php"] [unique_id "apPkTkmtdPfUFP1akVE4NQAABIA"]
[Sun Aug 30 03:05:34.669954 2026] [security2:error] [pid 495314:tid 495504] [client 20.104.50.220:31935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/pHpINJ.php"] [unique_id "apPkTkmtdPfUFP1akVE4NgAABGQ"]
[Sun Aug 30 03:05:34.681995 2026] [security2:error] [pid 495314:tid 495445] [client 4.205.62.107:27273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/nw.php"] [unique_id "apPkTkmtdPfUFP1akVE4OAAABCk"]
[Sun Aug 30 03:05:34.685043 2026] [security2:error] [pid 495314:tid 495463] [client 20.104.50.220:61491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/v4ga.php"] [unique_id "apPkTkmtdPfUFP1akVE4OQAABDs"]
[Sun Aug 30 03:05:34.686745 2026] [security2:error] [pid 495314:tid 495460] [client 4.205.62.107:52153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/config/laravolt/css/index.php"] [unique_id "apPkTkmtdPfUFP1akVE4OgAABDg"]
[Sun Aug 30 03:05:34.692349 2026] [security2:error] [pid 495314:tid 495511] [client 20.104.18.15:13635] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/1.php"] [unique_id "apPkTkmtdPfUFP1akVE4OwAABGs"]
[Sun Aug 30 03:05:34.692494 2026] [security2:error] [pid 495314:tid 495511] [client 20.104.18.15:13635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/1.php"] [unique_id "apPkTkmtdPfUFP1akVE4OwAABGs"]
[Sun Aug 30 03:05:34.693274 2026] [security2:error] [pid 495314:tid 495444] [client 20.48.251.3:64401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/grsiuk.php"] [unique_id "apPkTkmtdPfUFP1akVE4PAAABCg"]
[Sun Aug 30 03:05:34.695862 2026] [security2:error] [pid 495314:tid 495498] [client 20.104.50.220:5561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-content/admin.php"] [unique_id "apPkTkmtdPfUFP1akVE4PQAABF4"]
[Sun Aug 30 03:05:34.699176 2026] [security2:error] [pid 495314:tid 495541] [client 20.104.49.130:61399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.topatrust.com"] [uri "/ortasekerli1.php"] [unique_id "apPkTkmtdPfUFP1akVE4PgAABIk"]
[Sun Aug 30 03:05:34.706204 2026] [security2:error] [pid 495314:tid 495494] [client 4.205.62.107:18759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/wp-config.backup.php"] [unique_id "apPkTkmtdPfUFP1akVE4PwAABFo"]
[Sun Aug 30 03:05:34.707695 2026] [security2:error] [pid 495314:tid 495462] [client 20.104.50.220:32878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/mforh.php"] [unique_id "apPkTkmtdPfUFP1akVE4QAAABDo"]
[Sun Aug 30 03:05:34.708425 2026] [security2:error] [pid 495314:tid 495461] [client 20.104.18.15:31691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/replace.php"] [unique_id "apPkTkmtdPfUFP1akVE4QgAABDk"]
[Sun Aug 30 03:05:34.708523 2026] [security2:error] [pid 495314:tid 495547] [client 20.104.18.15:33011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/simple.php"] [unique_id "apPkTkmtdPfUFP1akVE4QQAABI8"]
[Sun Aug 30 03:05:34.708598 2026] [security2:error] [pid 495314:tid 495539] [client 20.104.18.15:43308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/kerang.php"] [unique_id "apPkTkmtdPfUFP1akVE4QwAABIc"]
[Sun Aug 30 03:05:34.709486 2026] [security2:error] [pid 495314:tid 495477] [client 20.48.160.90:40023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/Jcrop.php"] [unique_id "apPkTkmtdPfUFP1akVE4RAAABEk"]
[Sun Aug 30 03:05:34.717223 2026] [security2:error] [pid 495314:tid 495505] [client 20.48.160.90:45925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/okxoby.php"] [unique_id "apPkTkmtdPfUFP1akVE4RgAABGU"]
[Sun Aug 30 03:05:34.720494 2026] [authz_core:error] [pid 495314:tid 495567] [client 216.73.216.128:58018] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:34.720814 2026] [authz_core:error] [pid 495314:tid 495567] [client 216.73.216.128:58018] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:34.723004 2026] [security2:error] [pid 495314:tid 495451] [client 4.205.62.107:22956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/sys.php"] [unique_id "apPkTkmtdPfUFP1akVE4RwAABC8"]
[Sun Aug 30 03:05:34.731875 2026] [security2:error] [pid 495314:tid 495561] [client 4.205.62.107:44467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/file59.php"] [unique_id "apPkTkmtdPfUFP1akVE4SAAABJ0"]
[Sun Aug 30 03:05:34.732490 2026] [security2:error] [pid 495314:tid 495486] [client 20.48.251.3:55698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/packed.php"] [unique_id "apPkTkmtdPfUFP1akVE4SQAABFI"]
[Sun Aug 30 03:05:34.750129 2026] [security2:error] [pid 495314:tid 495502] [client 4.205.62.107:42839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/bigdump.php"] [unique_id "apPkTkmtdPfUFP1akVE4SgAABGI"]
[Sun Aug 30 03:05:34.756127 2026] [security2:error] [pid 495314:tid 495520] [client 20.48.160.90:50641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/133.php"] [unique_id "apPkTkmtdPfUFP1akVE4SwAABHQ"]
[Sun Aug 30 03:05:34.778561 2026] [security2:error] [pid 495314:tid 495466] [client 40.83.93.50:9083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/ioxi-o.php"] [unique_id "apPkTkmtdPfUFP1akVE4TgAABD4"]
[Sun Aug 30 03:05:34.788426 2026] [security2:error] [pid 495314:tid 495521] [client 20.48.251.3:55525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/erty.php"] [unique_id "apPkTkmtdPfUFP1akVE4UAAABHU"]
[Sun Aug 30 03:05:34.842965 2026] [security2:error] [pid 495314:tid 495571] [client 20.104.50.220:63526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/on.php"] [unique_id "apPkTkmtdPfUFP1akVE4VAAABKc"]
[Sun Aug 30 03:05:34.847245 2026] [security2:error] [pid 495314:tid 495546] [client 20.48.160.90:45840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/35iDq8NAjLu.php"] [unique_id "apPkTkmtdPfUFP1akVE4VQAABI4"]
[Sun Aug 30 03:05:34.851905 2026] [security2:error] [pid 495314:tid 495469] [client 20.48.160.90:45893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/esuutzzx.php"] [unique_id "apPkTkmtdPfUFP1akVE4VgAABEE"]
[Sun Aug 30 03:05:34.902236 2026] [security2:error] [pid 495314:tid 495508] [client 20.48.251.3:44324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/06.php"] [unique_id "apPkTkmtdPfUFP1akVE4WgAABGg"]
[Sun Aug 30 03:05:34.930785 2026] [security2:error] [pid 495314:tid 495558] [client 20.48.160.90:50594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/sym.php"] [unique_id "apPkTkmtdPfUFP1akVE4XAAABJo"]
[Sun Aug 30 03:05:34.977745 2026] [security2:error] [pid 495314:tid 495481] [client 20.48.160.90:40052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/btx25.php"] [unique_id "apPkTkmtdPfUFP1akVE4YAAABE0"]
[Sun Aug 30 03:05:34.990608 2026] [security2:error] [pid 495314:tid 495478] [client 20.48.160.90:26674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/replace.php"] [unique_id "apPkTkmtdPfUFP1akVE4YwAABEo"]
[Sun Aug 30 03:05:34.996368 2026] [authz_core:error] [pid 495314:tid 495504] [client 216.73.216.128:58018] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:34.996652 2026] [authz_core:error] [pid 495314:tid 495504] [client 216.73.216.128:58018] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:35.031606 2026] [security2:error] [pid 495314:tid 495492] [client 20.63.219.114:18533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/goods.php"] [unique_id "apPkT0mtdPfUFP1akVE4aQAABFg"]
[Sun Aug 30 03:05:35.060152 2026] [security2:error] [pid 495314:tid 495539] [client 20.48.160.90:50612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/8.php"] [unique_id "apPkT0mtdPfUFP1akVE4agAABIc"]
[Sun Aug 30 03:05:35.077305 2026] [security2:error] [pid 495314:tid 495465] [client 3.77.67.4:1600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "arcexploration.com.au"] [uri "/wp-content/endurance-page-cache/_index.html"] [unique_id "apPkT0mtdPfUFP1akVE4awAABD0"], referer: https://arcexploration.com.au/
[Sun Aug 30 03:05:35.085851 2026] [authz_core:error] [pid 495314:tid 495505] [client 216.73.216.128:29535] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:35.086129 2026] [authz_core:error] [pid 495314:tid 495505] [client 216.73.216.128:29535] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:35.105765 2026] [security2:error] [pid 495314:tid 495486] [client 20.48.160.90:40031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/radio.php"] [unique_id "apPkT0mtdPfUFP1akVE4cQAABFI"]
[Sun Aug 30 03:05:35.125887 2026] [security2:error] [pid 495314:tid 495502] [client 20.48.160.90:26648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/gulu.php"] [unique_id "apPkT0mtdPfUFP1akVE4dAAABGI"]
[Sun Aug 30 03:05:35.181988 2026] [security2:error] [pid 495314:tid 495548] [client 4.205.62.107:32503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/h.php"] [unique_id "apPkT0mtdPfUFP1akVE4eAAABJA"]
[Sun Aug 30 03:05:35.183043 2026] [security2:error] [pid 495314:tid 495513] [client 4.205.62.107:32471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/agg.php"] [unique_id "apPkT0mtdPfUFP1akVE4eQAABG0"]
[Sun Aug 30 03:05:35.200959 2026] [security2:error] [pid 495314:tid 495570] [client 4.205.62.107:65403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/aws_secret_config.php"] [unique_id "apPkT0mtdPfUFP1akVE4egAABKY"]
[Sun Aug 30 03:05:35.236677 2026] [security2:error] [pid 495314:tid 495497] [client 20.104.49.130:45757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/forum.php"] [unique_id "apPkT0mtdPfUFP1akVE4fAAABF0"]
[Sun Aug 30 03:05:35.236691 2026] [security2:error] [pid 495314:tid 495562] [client 20.48.160.90:39966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/dex.php"] [unique_id "apPkT0mtdPfUFP1akVE4fQAABJ4"]
[Sun Aug 30 03:05:35.248671 2026] [security2:error] [pid 495314:tid 495451] [client 40.83.93.50:9060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.homedesigner.org"] [uri "/lock.php"] [unique_id "apPkT0mtdPfUFP1akVE4fgAABC8"]
[Sun Aug 30 03:05:35.262573 2026] [security2:error] [pid 495314:tid 495529] [client 20.48.160.90:45845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/gtghklk.php"] [unique_id "apPkT0mtdPfUFP1akVE4hAAABH0"]
[Sun Aug 30 03:05:35.263746 2026] [security2:error] [pid 495314:tid 495446] [client 20.48.251.3:34593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/bb.php"] [unique_id "apPkT0mtdPfUFP1akVE4hQAABCo"]
[Sun Aug 30 03:05:35.264028 2026] [security2:error] [pid 495314:tid 495500] [client 68.155.159.216:63529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-content/plugins/index.php"] [unique_id "apPkT0mtdPfUFP1akVE4hgAABGA"]
[Sun Aug 30 03:05:35.326779 2026] [security2:error] [pid 495314:tid 495484] [client 4.205.62.107:36633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/124.php"] [unique_id "apPkT0mtdPfUFP1akVE4igAABFA"]
[Sun Aug 30 03:05:35.334614 2026] [security2:error] [pid 495314:tid 495508] [client 20.48.160.90:33159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/goods.php"] [unique_id "apPkT0mtdPfUFP1akVE4iwAABGg"]
[Sun Aug 30 03:05:35.345095 2026] [authz_core:error] [pid 495314:tid 495564] [client 66.249.66.34:45263] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:35.345374 2026] [authz_core:error] [pid 495314:tid 495564] [client 66.249.66.34:45263] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:35.373683 2026] [security2:error] [pid 495314:tid 495455] [client 144.126.156.70:46362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.156.126.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aquagreenautospa.com"] [uri "/wp-login.php"] [unique_id "apPkT0mtdPfUFP1akVE4kQAABDM"]
[Sun Aug 30 03:05:35.388863 2026] [security2:error] [pid 495314:tid 495527] [client 20.63.219.114:15131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/m.php"] [unique_id "apPkT0mtdPfUFP1akVE4kwAABHs"]
[Sun Aug 30 03:05:35.515441 2026] [security2:error] [pid 495314:tid 495494] [client 20.151.200.44:23595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/xwpg.php"] [unique_id "apPkT0mtdPfUFP1akVE4owAABFo"]
[Sun Aug 30 03:05:35.515731 2026] [authz_core:error] [pid 495314:tid 495476] [client 66.249.66.45:41481] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:35.516023 2026] [authz_core:error] [pid 495314:tid 495476] [client 66.249.66.45:41481] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:35.572189 2026] [security2:error] [pid 495314:tid 495555] [client 20.151.200.44:47402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/bge.php"] [unique_id "apPkT0mtdPfUFP1akVE4qgAABJc"]
[Sun Aug 30 03:05:35.616165 2026] [security2:error] [pid 495314:tid 495486] [client 4.205.62.107:63577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/pouhg.php"] [unique_id "apPkT0mtdPfUFP1akVE4rQAABFI"]
[Sun Aug 30 03:05:35.634398 2026] [authz_core:error] [pid 495314:tid 495487] [client 216.73.216.128:58018] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:35.634690 2026] [authz_core:error] [pid 495314:tid 495487] [client 216.73.216.128:58018] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:35.701311 2026] [security2:error] [pid 495314:tid 495480] [client 68.155.159.216:52724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPkT0mtdPfUFP1akVE4rwAABEw"]
[Sun Aug 30 03:05:35.716253 2026] [security2:error] [pid 495314:tid 495559] [client 4.205.62.107:5090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/test.php"] [unique_id "apPkT0mtdPfUFP1akVE4sQAABJs"]
[Sun Aug 30 03:05:35.745241 2026] [security2:error] [pid 495314:tid 495502] [client 20.63.219.114:9620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/doc.php"] [unique_id "apPkT0mtdPfUFP1akVE4swAABGI"]
[Sun Aug 30 03:05:35.760701 2026] [security2:error] [pid 495314:tid 495531] [client 87.106.133.89:60502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.133.106.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dqnorthshore.com"] [uri "/wp-login.php"] [unique_id "apPkT0mtdPfUFP1akVE4tAAABH8"]
[Sun Aug 30 03:05:35.771033 2026] [security2:error] [pid 495314:tid 495562] [client 20.104.50.220:27431] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/images/c99.php"] [unique_id "apPkT0mtdPfUFP1akVE4tgAABJ4"]
[Sun Aug 30 03:05:35.774955 2026] [security2:error] [pid 495314:tid 495444] [client 20.48.251.3:22761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/aws_settings.php"] [unique_id "apPkT0mtdPfUFP1akVE4uAAABCg"]
[Sun Aug 30 03:05:35.775472 2026] [security2:error] [pid 495314:tid 495519] [client 20.104.50.220:62841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/g6sshell.php"] [unique_id "apPkT0mtdPfUFP1akVE4uQAABHM"]
[Sun Aug 30 03:05:35.776348 2026] [security2:error] [pid 495314:tid 495451] [client 4.205.62.107:2754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/public/mah.php.php"] [unique_id "apPkT0mtdPfUFP1akVE4ugAABC8"]
[Sun Aug 30 03:05:35.778390 2026] [security2:error] [pid 495314:tid 495490] [client 20.104.50.220:46169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/alfatesla.php"] [unique_id "apPkT0mtdPfUFP1akVE4uwAABFY"]
[Sun Aug 30 03:05:35.778679 2026] [security2:error] [pid 495314:tid 495453] [client 68.155.159.216:60020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-login.php"] [unique_id "apPkT0mtdPfUFP1akVE4tQAABDE"]
[Sun Aug 30 03:05:35.778715 2026] [security2:error] [pid 495314:tid 495569] [client 68.155.159.216:52771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apPkT0mtdPfUFP1akVE4vAAABKU"]
[Sun Aug 30 03:05:35.790993 2026] [security2:error] [pid 495314:tid 495542] [client 20.104.50.220:28714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/think.php"] [unique_id "apPkT0mtdPfUFP1akVE4vQAABIo"]
[Sun Aug 30 03:05:35.792969 2026] [security2:error] [pid 495314:tid 495446] [client 20.48.251.3:54731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/saml.php"] [unique_id "apPkT0mtdPfUFP1akVE4vgAABCo"]
[Sun Aug 30 03:05:35.822332 2026] [security2:error] [pid 495314:tid 495521] [client 20.104.50.220:61637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/s3c.php"] [unique_id "apPkT0mtdPfUFP1akVE4wgAABHU"]
[Sun Aug 30 03:05:35.827590 2026] [security2:error] [pid 495314:tid 495571] [client 20.104.50.220:31817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/robot.php"] [unique_id "apPkT0mtdPfUFP1akVE4xAAABKc"]
[Sun Aug 30 03:05:35.832613 2026] [security2:error] [pid 495314:tid 495469] [client 20.48.251.3:7086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/paypal.php"] [unique_id "apPkT0mtdPfUFP1akVE4xQAABEE"]
[Sun Aug 30 03:05:35.832631 2026] [security2:error] [pid 495314:tid 495515] [client 4.205.62.107:51714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/87.php"] [unique_id "apPkT0mtdPfUFP1akVE4xgAABG8"]
[Sun Aug 30 03:05:35.834389 2026] [security2:error] [pid 495314:tid 495484] [client 20.104.50.220:5630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPkT0mtdPfUFP1akVE4yAAABFA"]
[Sun Aug 30 03:05:35.845208 2026] [security2:error] [pid 495314:tid 495470] [client 20.104.18.15:31587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/c4.php"] [unique_id "apPkT0mtdPfUFP1akVE4yQAABEI"]
[Sun Aug 30 03:05:35.849291 2026] [security2:error] [pid 495314:tid 495455] [client 4.205.62.107:18624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/edit.php"] [unique_id "apPkT0mtdPfUFP1akVE4ygAABDM"]
[Sun Aug 30 03:05:35.860605 2026] [security2:error] [pid 495314:tid 495507] [client 4.205.62.107:62440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/phpsysinfo.php"] [unique_id "apPkT0mtdPfUFP1akVE4zQAABGc"]
[Sun Aug 30 03:05:35.866383 2026] [security2:error] [pid 495314:tid 495457] [client 20.104.18.15:13647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/samll.php"] [unique_id "apPkT0mtdPfUFP1akVE40AAABDU"]
[Sun Aug 30 03:05:35.870567 2026] [security2:error] [pid 495314:tid 495481] [client 4.205.62.107:44865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/cli_bootstrap.php"] [unique_id "apPkT0mtdPfUFP1akVE40QAABE0"]
[Sun Aug 30 03:05:35.879295 2026] [security2:error] [pid 495314:tid 495538] [client 20.104.18.15:33666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/xty.php"] [unique_id "apPkT0mtdPfUFP1akVE40wAABIY"]
[Sun Aug 30 03:05:35.881331 2026] [security2:error] [pid 495314:tid 495483] [client 20.48.251.3:55774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/wp-info.php"] [unique_id "apPkT0mtdPfUFP1akVE41AAABE8"]
[Sun Aug 30 03:05:35.888017 2026] [security2:error] [pid 495314:tid 495448] [client 20.104.18.15:43984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/m.php"] [unique_id "apPkT0mtdPfUFP1akVE41gAABCw"]
[Sun Aug 30 03:05:35.904264 2026] [authz_core:error] [pid 495314:tid 495541] [client 66.249.66.204:40855] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:35.904890 2026] [authz_core:error] [pid 495314:tid 495541] [client 66.249.66.204:40855] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:35.916774 2026] [security2:error] [pid 495314:tid 495479] [client 4.205.62.107:64046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/ty.php"] [unique_id "apPkT0mtdPfUFP1akVE43QAABEs"]
[Sun Aug 30 03:05:35.921746 2026] [security2:error] [pid 495314:tid 495539] [client 20.104.49.130:36601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.topatrust.com"] [uri "/t.php"] [unique_id "apPkT0mtdPfUFP1akVE43gAABIc"]
[Sun Aug 30 03:05:35.923382 2026] [security2:error] [pid 495314:tid 495493] [client 20.48.251.3:55507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/wp-config.backup.php"] [unique_id "apPkT0mtdPfUFP1akVE43wAABFk"]
[Sun Aug 30 03:05:35.994922 2026] [security2:error] [pid 495314:tid 495461] [client 20.104.50.220:51635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/mari.php"] [unique_id "apPkT0mtdPfUFP1akVE46AAABDk"]
[Sun Aug 30 03:05:36.004909 2026] [security2:error] [pid 495314:tid 495466] [client 4.205.62.107:42610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/wdf.php"] [unique_id "apPkUEmtdPfUFP1akVE47AAABD4"]
[Sun Aug 30 03:05:36.058478 2026] [security2:error] [pid 495314:tid 495521] [client 20.48.251.3:5063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/xin1.php"] [unique_id "apPkUEmtdPfUFP1akVE49wAABHU"]
[Sun Aug 30 03:05:36.100218 2026] [security2:error] [pid 495314:tid 495511] [client 20.63.219.114:9616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/users.php"] [unique_id "apPkUEmtdPfUFP1akVE4_gAABGs"]
[Sun Aug 30 03:05:36.182442 2026] [authz_core:error] [pid 495314:tid 495498] [client 216.73.216.128:58018] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:36.182872 2026] [authz_core:error] [pid 495314:tid 495498] [client 216.73.216.128:58018] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:36.293106 2026] [security2:error] [pid 495314:tid 495565] [client 20.104.49.130:61425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.topatrust.com"] [uri "/wp-good.php"] [unique_id "apPkUEmtdPfUFP1akVE5DQAABKE"]
[Sun Aug 30 03:05:36.324467 2026] [authz_core:error] [pid 495314:tid 495456] [client 66.249.66.74:51713] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:36.324847 2026] [authz_core:error] [pid 495314:tid 495456] [client 66.249.66.74:51713] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:36.339508 2026] [security2:error] [pid 495314:tid 495547] [client 4.205.62.107:58152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/snq.php"] [unique_id "apPkUEmtdPfUFP1akVE5DwAABI8"]
[Sun Aug 30 03:05:36.374957 2026] [security2:error] [pid 495314:tid 495485] [client 4.205.62.107:27313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/product.php"] [unique_id "apPkUEmtdPfUFP1akVE5EQAABFE"]
[Sun Aug 30 03:05:36.379521 2026] [security2:error] [pid 495314:tid 495526] [client 68.155.159.216:63540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/simple.php"] [unique_id "apPkUEmtdPfUFP1akVE5EgAABHo"]
[Sun Aug 30 03:05:36.409493 2026] [security2:error] [pid 495314:tid 495480] [client 93.123.109.165:53852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paulgarrigan.com"] [uri "/index.php"] [unique_id "apPkUEmtdPfUFP1akVE5FAAABEw"]
[Sun Aug 30 03:05:36.425676 2026] [security2:error] [pid 495314:tid 495461] [client 20.48.251.3:59132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/file59.php"] [unique_id "apPkUEmtdPfUFP1akVE5FwAABDk"]
[Sun Aug 30 03:05:36.452758 2026] [security2:error] [pid 495314:tid 495477] [client 20.63.219.114:9612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/class.php"] [unique_id "apPkUEmtdPfUFP1akVE5GQAABEk"]
[Sun Aug 30 03:05:36.455067 2026] [authz_core:error] [pid 495314:tid 495533] [client 216.73.216.128:58018] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:36.455453 2026] [authz_core:error] [pid 495314:tid 495533] [client 216.73.216.128:58018] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:36.464081 2026] [authz_core:error] [pid 495314:tid 495496] [client 66.249.66.192:64727] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:36.464440 2026] [authz_core:error] [pid 495314:tid 495496] [client 66.249.66.192:64727] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:36.535394 2026] [security2:error] [pid 495314:tid 495484] [client 20.151.200.44:62213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/sxxb.php"] [unique_id "apPkUEmtdPfUFP1akVE5LAAABFA"]
[Sun Aug 30 03:05:36.589278 2026] [authz_core:error] [pid 495314:tid 495567] [client 66.249.66.201:56296] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:36.589578 2026] [authz_core:error] [pid 495314:tid 495567] [client 66.249.66.201:56296] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:36.623101 2026] [security2:error] [pid 495314:tid 495470] [client 20.151.200.44:47071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/wt.php"] [unique_id "apPkUEmtdPfUFP1akVE5NAAABEI"]
[Sun Aug 30 03:05:36.663110 2026] [security2:error] [pid 495314:tid 495448] [client 20.104.49.130:64918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.topatrust.com"] [uri "/as.php"] [unique_id "apPkUEmtdPfUFP1akVE5NwAABCw"]
[Sun Aug 30 03:05:36.664719 2026] [security2:error] [pid 495314:tid 495551] [client 4.205.62.107:58362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/bootstrap.php"] [unique_id "apPkUEmtdPfUFP1akVE5OAAABJM"]
[Sun Aug 30 03:05:36.755408 2026] [security2:error] [pid 495314:tid 495534] [client 4.205.62.107:63585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/phpversion.php"] [unique_id "apPkUEmtdPfUFP1akVE5OwAABII"]
[Sun Aug 30 03:05:36.798332 2026] [authz_core:error] [pid 495314:tid 495536] [client 66.249.66.204:44896] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:36.798795 2026] [authz_core:error] [pid 495314:tid 495536] [client 66.249.66.204:44896] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:36.811717 2026] [security2:error] [pid 495314:tid 495510] [client 4.205.62.107:32010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/requirements.php"] [unique_id "apPkUEmtdPfUFP1akVE5PgAABGo"]
[Sun Aug 30 03:05:36.814439 2026] [security2:error] [pid 495314:tid 495560] [client 68.155.159.216:52679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-includes/content.php"] [unique_id "apPkUEmtdPfUFP1akVE5PwAABJw"]
[Sun Aug 30 03:05:36.835389 2026] [security2:error] [pid 495314:tid 495553] [client 20.63.219.114:9606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/auth.php"] [unique_id "apPkUEmtdPfUFP1akVE5QQAABJU"]
[Sun Aug 30 03:05:36.867287 2026] [security2:error] [pid 495314:tid 495473] [client 4.205.62.107:5070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/cloud.php"] [unique_id "apPkUEmtdPfUFP1akVE5RQAABEU"]
[Sun Aug 30 03:05:36.898723 2026] [security2:error] [pid 495314:tid 495565] [client 68.155.159.216:60602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/packed.php"] [unique_id "apPkUEmtdPfUFP1akVE5SAAABKE"]
[Sun Aug 30 03:05:36.903825 2026] [security2:error] [pid 495314:tid 495557] [client 68.155.159.216:54080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apPkUEmtdPfUFP1akVE5SgAABJk"]
[Sun Aug 30 03:05:36.909170 2026] [security2:error] [pid 495314:tid 495566] [client 20.104.50.220:27408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/images/ty.php"] [unique_id "apPkUEmtdPfUFP1akVE5SwAABKI"]
[Sun Aug 30 03:05:36.916139 2026] [security2:error] [pid 495314:tid 495547] [client 4.205.62.107:2323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/zaza.php"] [unique_id "apPkUEmtdPfUFP1akVE5TQAABI8"]
[Sun Aug 30 03:05:36.916715 2026] [security2:error] [pid 495314:tid 495564] [client 20.104.50.220:47077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/alfateslav4.php"] [unique_id "apPkUEmtdPfUFP1akVE5TgAABKA"]
[Sun Aug 30 03:05:36.930245 2026] [security2:error] [pid 495314:tid 495499] [client 20.104.50.220:52813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/tod.php"] [unique_id "apPkUEmtdPfUFP1akVE5TwAABF8"]
[Sun Aug 30 03:05:36.930793 2026] [security2:error] [pid 495314:tid 495498] [client 20.48.251.3:44259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/wp-konfig.backup.php"] [unique_id "apPkUEmtdPfUFP1akVE5UAAABF4"]
[Sun Aug 30 03:05:36.949446 2026] [security2:error] [pid 495314:tid 495503] [client 20.48.251.3:64280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/aws_settings.php"] [unique_id "apPkUEmtdPfUFP1akVE5VgAABGM"]
[Sun Aug 30 03:05:36.959136 2026] [security2:error] [pid 495314:tid 495505] [client 20.104.50.220:62843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/sqlshell.php"] [unique_id "apPkUEmtdPfUFP1akVE5WQAABGU"]
[Sun Aug 30 03:05:36.972374 2026] [security2:error] [pid 495314:tid 495461] [client 20.104.50.220:31836] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "523"] [id "900207"] [msg "Sys[0-9]+ Mailer"] [hostname "www.38cupscreen.cover789.com"] [uri "/sys32.php"] [unique_id "apPkUEmtdPfUFP1akVE5WgAABDk"]
[Sun Aug 30 03:05:36.976698 2026] [security2:error] [pid 495314:tid 495531] [client 20.48.251.3:64418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/userfuns.php"] [unique_id "apPkUEmtdPfUFP1akVE5WwAABH8"]
[Sun Aug 30 03:05:36.982425 2026] [security2:error] [pid 495314:tid 495502] [client 4.205.62.107:52118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/plss3.php"] [unique_id "apPkUEmtdPfUFP1akVE5XQAABGI"]
[Sun Aug 30 03:05:36.987091 2026] [security2:error] [pid 495314:tid 495562] [client 20.104.50.220:5501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-content/themes/twentytwentytwo/index.php"] [unique_id "apPkUEmtdPfUFP1akVE5XwAABJ4"]
[Sun Aug 30 03:05:36.987124 2026] [security2:error] [pid 495314:tid 495537] [client 4.205.62.107:18994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/8.php"] [unique_id "apPkUEmtdPfUFP1akVE5YAAABIU"]
[Sun Aug 30 03:05:36.987664 2026] [security2:error] [pid 495314:tid 495561] [client 20.104.50.220:61488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/madspotshell.php"] [unique_id "apPkUEmtdPfUFP1akVE5YQAABJ0"]
[Sun Aug 30 03:05:37.010015 2026] [security2:error] [pid 495314:tid 495516] [client 4.205.62.107:44925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/dd.php"] [unique_id "apPkUUmtdPfUFP1akVE5ZgAABHA"]
[Sun Aug 30 03:05:37.010992 2026] [security2:error] [pid 495314:tid 495556] [client 4.205.62.107:62298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/sgd.php"] [unique_id "apPkUUmtdPfUFP1akVE5aAAABJg"]
[Sun Aug 30 03:05:37.016283 2026] [security2:error] [pid 495314:tid 495515] [client 20.104.18.15:32994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/sallu.php"] [unique_id "apPkUUmtdPfUFP1akVE5bAAABG8"]
[Sun Aug 30 03:05:37.019687 2026] [authz_core:error] [pid 495314:tid 495508] [client 66.249.66.64:50945] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:37.019959 2026] [authz_core:error] [pid 495314:tid 495508] [client 66.249.66.64:50945] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:37.021313 2026] [security2:error] [pid 495314:tid 495542] [client 20.104.18.15:43293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/fling.php"] [unique_id "apPkUUmtdPfUFP1akVE5bgAABIo"]
[Sun Aug 30 03:05:37.024686 2026] [security2:error] [pid 495314:tid 495533] [client 20.104.18.15:31673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/rxr.php"] [unique_id "apPkUUmtdPfUFP1akVE5bwAABIE"]
[Sun Aug 30 03:05:37.053681 2026] [security2:error] [pid 495314:tid 495551] [client 20.104.18.15:13746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/she11.php"] [unique_id "apPkUUmtdPfUFP1akVE5dwAABJM"]
[Sun Aug 30 03:05:37.061384 2026] [security2:error] [pid 495314:tid 495446] [client 93.123.109.165:53858] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "paulgarrigan.com"] [uri "/wp/"] [unique_id "apPkUUmtdPfUFP1akVE5eQAABCo"]
[Sun Aug 30 03:05:37.064720 2026] [security2:error] [pid 495314:tid 495525] [client 4.205.62.107:64004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/adminer-4.7.6-en.php"] [unique_id "apPkUUmtdPfUFP1akVE5fAAABHk"]
[Sun Aug 30 03:05:37.069961 2026] [security2:error] [pid 495314:tid 495534] [client 20.48.251.3:55433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/edit.php"] [unique_id "apPkUUmtdPfUFP1akVE5fQAABII"]
[Sun Aug 30 03:05:37.106556 2026] [security2:error] [pid 495314:tid 495546] [client 4.205.62.107:35977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/test1.php"] [unique_id "apPkUUmtdPfUFP1akVE5gwAABI4"]
[Sun Aug 30 03:05:37.126325 2026] [authz_core:error] [pid 495314:tid 495460] [client 66.249.66.65:56229] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:37.126811 2026] [authz_core:error] [pid 495314:tid 495460] [client 66.249.66.65:56229] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:37.135849 2026] [security2:error] [pid 495314:tid 495488] [client 20.48.251.3:52802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/fns.php"] [unique_id "apPkUUmtdPfUFP1akVE5iQAABFQ"]
[Sun Aug 30 03:05:37.153499 2026] [security2:error] [pid 495314:tid 495499] [client 20.104.50.220:42479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/old-index.php"] [unique_id "apPkUUmtdPfUFP1akVE5igAABF8"]
[Sun Aug 30 03:05:37.191108 2026] [security2:error] [pid 495314:tid 495518] [client 20.63.219.114:15115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/adminfuns.php"] [unique_id "apPkUUmtdPfUFP1akVE5jgAABHI"]
[Sun Aug 30 03:05:37.195176 2026] [security2:error] [pid 495314:tid 495545] [client 4.205.62.107:42819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/bb.php"] [unique_id "apPkUUmtdPfUFP1akVE5jwAABI0"]
[Sun Aug 30 03:05:37.251050 2026] [security2:error] [pid 495314:tid 495513] [client 20.104.50.220:33583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/mygagal.php"] [unique_id "apPkUUmtdPfUFP1akVE5lwAABG0"]
[Sun Aug 30 03:05:37.268677 2026] [security2:error] [pid 495314:tid 495476] [client 20.48.251.3:5098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/sadd.php"] [unique_id "apPkUUmtdPfUFP1akVE5mwAABEg"]
[Sun Aug 30 03:05:37.278140 2026] [authz_core:error] [pid 495314:tid 495512] [client 66.249.66.200:38997] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:37.278692 2026] [authz_core:error] [pid 495314:tid 495512] [client 66.249.66.200:38997] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:37.411158 2026] [authz_core:error] [pid 495314:tid 495515] [client 66.249.66.64:55524] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:37.411340 2026] [authz_core:error] [pid 495314:tid 495457] [client 66.249.66.203:56627] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:37.411419 2026] [authz_core:error] [pid 495314:tid 495515] [client 66.249.66.64:55524] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:37.411583 2026] [authz_core:error] [pid 495314:tid 495457] [client 66.249.66.203:56627] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:37.473870 2026] [security2:error] [pid 495314:tid 495463] [client 93.123.109.165:53858] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "paulgarrigan.com"] [uri "/wordpress/"] [unique_id "apPkUUmtdPfUFP1akVE5qgAABDs"]
[Sun Aug 30 03:05:37.530040 2026] [security2:error] [pid 495314:tid 495547] [client 68.155.159.216:63524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-admin/about.php"] [unique_id "apPkUUmtdPfUFP1akVE5uQAABI8"]
[Sun Aug 30 03:05:37.571530 2026] [security2:error] [pid 495314:tid 495499] [client 20.151.200.44:47021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/Contrller.php"] [unique_id "apPkUUmtdPfUFP1akVE5uwAABF8"]
[Sun Aug 30 03:05:37.578977 2026] [security2:error] [pid 495314:tid 495470] [client 20.63.219.114:1347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/rip.php"] [unique_id "apPkUUmtdPfUFP1akVE5vQAABEI"]
[Sun Aug 30 03:05:37.583105 2026] [authz_core:error] [pid 495314:tid 495549] [client 216.73.216.128:14358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:37.583389 2026] [authz_core:error] [pid 495314:tid 495549] [client 216.73.216.128:14358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:37.604423 2026] [authz_core:error] [pid 495314:tid 495518] [client 66.249.66.68:37313] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:37.604893 2026] [authz_core:error] [pid 495314:tid 495518] [client 66.249.66.68:37313] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:37.616952 2026] [security2:error] [pid 495314:tid 495505] [client 20.48.251.3:51479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/cli_bootstrap.php"] [unique_id "apPkUUmtdPfUFP1akVE5wwAABGU"]
[Sun Aug 30 03:05:37.678947 2026] [security2:error] [pid 495314:tid 495537] [client 4.205.62.107:65339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/wp-access.php"] [unique_id "apPkUUmtdPfUFP1akVE5ygAABIU"]
[Sun Aug 30 03:05:37.873535 2026] [security2:error] [pid 495314:tid 495521] [client 93.123.109.165:53858] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "paulgarrigan.com"] [uri "/blog/"] [unique_id "apPkUUmtdPfUFP1akVE50gAABHU"]
[Sun Aug 30 03:05:37.878926 2026] [authz_core:error] [pid 495314:tid 495556] [client 66.249.66.40:48827] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:37.879238 2026] [authz_core:error] [pid 495314:tid 495556] [client 66.249.66.40:48827] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:37.893059 2026] [security2:error] [pid 495314:tid 495533] [client 4.205.62.107:63786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/adminfus.php"] [unique_id "apPkUUmtdPfUFP1akVE51AAABIE"]
[Sun Aug 30 03:05:37.904612 2026] [security2:error] [pid 495314:tid 495453] [client 158.69.118.189:54599] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "158.69.118.189" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPkUUmtdPfUFP1akVE51QAABDE"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:05:37.904738 2026] [security2:error] [pid 495314:tid 495453] [client 158.69.118.189:54599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPkUUmtdPfUFP1akVE51QAABDE"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:05:37.918765 2026] [security2:error] [pid 495314:tid 495527] [client 68.155.159.216:52676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-admin/css/index.php"] [unique_id "apPkUUmtdPfUFP1akVE52AAABHs"]
[Sun Aug 30 03:05:37.937057 2026] [security2:error] [pid 495314:tid 495465] [client 20.63.219.114:18552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/ws.php"] [unique_id "apPkUUmtdPfUFP1akVE53AAABD0"]
[Sun Aug 30 03:05:37.982722 2026] [security2:error] [pid 495314:tid 495546] [client 4.205.62.107:32047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/var/www/wallet/index.php"] [unique_id "apPkUUmtdPfUFP1akVE55QAABI4"]
[Sun Aug 30 03:05:38.013419 2026] [security2:error] [pid 495314:tid 495462] [client 4.205.62.107:4106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/asdf.php"] [unique_id "apPkUkmtdPfUFP1akVE56wAABDo"]
[Sun Aug 30 03:05:38.046411 2026] [security2:error] [pid 495314:tid 495564] [client 20.104.50.220:27117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/dex.php"] [unique_id "apPkUkmtdPfUFP1akVE57gAABKA"]
[Sun Aug 30 03:05:38.055824 2026] [security2:error] [pid 495314:tid 495503] [client 20.104.50.220:46449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/alwso.php"] [unique_id "apPkUkmtdPfUFP1akVE57wAABGM"]
[Sun Aug 30 03:05:38.061346 2026] [security2:error] [pid 495314:tid 495541] [client 4.205.62.107:58334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/333.php"] [unique_id "apPkUkmtdPfUFP1akVE58AAABIk"]
[Sun Aug 30 03:05:38.069035 2026] [security2:error] [pid 495314:tid 495566] [client 4.205.62.107:2339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/u88.php"] [unique_id "apPkUkmtdPfUFP1akVE58QAABKI"]
[Sun Aug 30 03:05:38.069714 2026] [security2:error] [pid 495314:tid 495447] [client 68.155.159.216:59926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-admin/images/about.php"] [unique_id "apPkUkmtdPfUFP1akVE58gAABCs"]
[Sun Aug 30 03:05:38.073578 2026] [security2:error] [pid 495314:tid 495561] [client 20.48.251.3:22745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/packed.php"] [unique_id "apPkUkmtdPfUFP1akVE59AAABJ0"]
[Sun Aug 30 03:05:38.080996 2026] [security2:error] [pid 495314:tid 495508] [client 20.104.50.220:62802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/setor.php"] [unique_id "apPkUkmtdPfUFP1akVE59wAABGg"]
[Sun Aug 30 03:05:38.089841 2026] [security2:error] [pid 495314:tid 495570] [client 4.205.62.107:26519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/fun.php"] [unique_id "apPkUkmtdPfUFP1akVE5_AAABKY"]
[Sun Aug 30 03:05:38.090449 2026] [security2:error] [pid 495314:tid 495539] [client 68.155.159.216:52812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-content/packed.php"] [unique_id "apPkUkmtdPfUFP1akVE5_gAABIc"]
[Sun Aug 30 03:05:38.110170 2026] [security2:error] [pid 495314:tid 495548] [client 20.104.50.220:29125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/simshell.php"] [unique_id "apPkUkmtdPfUFP1akVE6AwAABJA"]
[Sun Aug 30 03:05:38.116246 2026] [security2:error] [pid 495314:tid 495562] [client 20.104.50.220:32530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/simple_cmd.php"] [unique_id "apPkUkmtdPfUFP1akVE6BwAABJ4"]
[Sun Aug 30 03:05:38.126270 2026] [security2:error] [pid 495314:tid 495557] [client 20.48.251.3:46235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/wp-konfig.backup.php"] [unique_id "apPkUkmtdPfUFP1akVE6CQAABJk"]
[Sun Aug 30 03:05:38.131109 2026] [security2:error] [pid 495314:tid 495476] [client 20.48.251.3:7054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/mamzi.php"] [unique_id "apPkUkmtdPfUFP1akVE6CgAABEg"]
[Sun Aug 30 03:05:38.133323 2026] [security2:error] [pid 495314:tid 495485] [client 4.205.62.107:52126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/aws.php"] [unique_id "apPkUkmtdPfUFP1akVE6CwAABFE"]
[Sun Aug 30 03:05:38.133484 2026] [security2:error] [pid 495314:tid 495467] [client 20.104.50.220:5577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/log.php"] [unique_id "apPkUkmtdPfUFP1akVE6DAAABD8"]
[Sun Aug 30 03:05:38.140396 2026] [security2:error] [pid 495314:tid 495453] [client 20.104.50.220:61435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/sa.php"] [unique_id "apPkUkmtdPfUFP1akVE6EAAABDE"]
[Sun Aug 30 03:05:38.142840 2026] [authz_core:error] [pid 495314:tid 495474] [client 66.249.66.77:55205] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:38.143154 2026] [authz_core:error] [pid 495314:tid 495474] [client 66.249.66.77:55205] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:38.150846 2026] [security2:error] [pid 495314:tid 495555] [client 4.205.62.107:44921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/wp-tem.php"] [unique_id "apPkUkmtdPfUFP1akVE6EQAABJc"]
[Sun Aug 30 03:05:38.151179 2026] [security2:error] [pid 495314:tid 495540] [client 4.205.62.107:18671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/thui.php"] [unique_id "apPkUkmtdPfUFP1akVE6EgAABIg"]
[Sun Aug 30 03:05:38.168315 2026] [security2:error] [pid 495314:tid 495472] [client 20.104.18.15:43985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/btyuio.php"] [unique_id "apPkUkmtdPfUFP1akVE6EwAABEQ"]
[Sun Aug 30 03:05:38.178619 2026] [security2:error] [pid 495314:tid 495538] [client 20.104.18.15:31493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.avenuelesrogim.com"] [uri "/reviall.php"] [unique_id "apPkUkmtdPfUFP1akVE6FQAABIY"]
[Sun Aug 30 03:05:38.185526 2026] [security2:error] [pid 495314:tid 495455] [client 20.104.18.15:32996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/codex.php"] [unique_id "apPkUkmtdPfUFP1akVE6FgAABDM"]
[Sun Aug 30 03:05:38.189173 2026] [security2:error] [pid 495314:tid 495498] [client 20.151.200.44:63011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/dx.php"] [unique_id "apPkUkmtdPfUFP1akVE6FwAABF4"]
[Sun Aug 30 03:05:38.198822 2026] [security2:error] [pid 495314:tid 495490] [client 4.205.62.107:63955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/phpi.php"] [unique_id "apPkUkmtdPfUFP1akVE6GAAABFY"]
[Sun Aug 30 03:05:38.199593 2026] [security2:error] [pid 495314:tid 495528] [client 20.48.251.3:49944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/8.php"] [unique_id "apPkUkmtdPfUFP1akVE6GQAABHw"]
[Sun Aug 30 03:05:38.216694 2026] [security2:error] [pid 495314:tid 495513] [client 20.104.18.15:13685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/kerang.php"] [unique_id "apPkUkmtdPfUFP1akVE6GwAABG0"]
[Sun Aug 30 03:05:38.234523 2026] [security2:error] [pid 495314:tid 495526] [client 158.69.118.189:54609] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "158.69.118.189" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPkUkmtdPfUFP1akVE6HQAABHo"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:05:38.234663 2026] [security2:error] [pid 495314:tid 495526] [client 158.69.118.189:54609] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPkUkmtdPfUFP1akVE6HQAABHo"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:05:38.259873 2026] [security2:error] [pid 495314:tid 495473] [client 4.205.62.107:62435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/fleen.php"] [unique_id "apPkUkmtdPfUFP1akVE6IgAABEU"]
[Sun Aug 30 03:05:38.287216 2026] [security2:error] [pid 495314:tid 495447] [client 20.48.251.3:52756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/params.php"] [unique_id "apPkUkmtdPfUFP1akVE6JwAABCs"]
[Sun Aug 30 03:05:38.306070 2026] [authz_core:error] [pid 495314:tid 495504] [client 66.249.66.200:38997] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:38.306388 2026] [authz_core:error] [pid 495314:tid 495504] [client 66.249.66.200:38997] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:38.333557 2026] [security2:error] [pid 495314:tid 495479] [client 20.63.219.114:1348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/t.php"] [unique_id "apPkUkmtdPfUFP1akVE6LwAABEs"]
[Sun Aug 30 03:05:38.338625 2026] [security2:error] [pid 495314:tid 495445] [client 20.104.50.220:51607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/ocgi.php"] [unique_id "apPkUkmtdPfUFP1akVE6MAAABCk"]
[Sun Aug 30 03:05:38.358441 2026] [security2:error] [pid 495314:tid 495470] [client 20.48.251.3:6476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/umgebung.php"] [unique_id "apPkUkmtdPfUFP1akVE6MQAABEI"]
[Sun Aug 30 03:05:38.417909 2026] [security2:error] [pid 495314:tid 495548] [client 20.48.251.3:44411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/application.config.php"] [unique_id "apPkUkmtdPfUFP1akVE6NQAABJA"]
[Sun Aug 30 03:05:38.421333 2026] [security2:error] [pid 495314:tid 495456] [client 4.205.62.107:42874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/file59.php"] [unique_id "apPkUkmtdPfUFP1akVE6NgAABDQ"]
[Sun Aug 30 03:05:38.425914 2026] [security2:error] [pid 495314:tid 495571] [client 20.104.50.220:32855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/manda.php"] [unique_id "apPkUkmtdPfUFP1akVE6NwAABKc"]
[Sun Aug 30 03:05:38.511482 2026] [authz_core:error] [pid 495314:tid 495528] [client 216.73.216.128:18243] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:38.511821 2026] [authz_core:error] [pid 495314:tid 495528] [client 216.73.216.128:18243] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:38.609580 2026] [security2:error] [pid 495314:tid 495506] [client 40.83.93.50:18093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/aaa.php"] [unique_id "apPkUkmtdPfUFP1akVE6UQAABGY"]
[Sun Aug 30 03:05:38.696426 2026] [security2:error] [pid 495314:tid 495553] [client 4.205.62.107:35997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/bigdump.php"] [unique_id "apPkUkmtdPfUFP1akVE6WwAABJU"]
[Sun Aug 30 03:05:38.705989 2026] [security2:error] [pid 495314:tid 495479] [client 68.155.159.216:63495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-content/uploads/index.php"] [unique_id "apPkUkmtdPfUFP1akVE6XQAABEs"]
[Sun Aug 30 03:05:38.719399 2026] [security2:error] [pid 495314:tid 495559] [client 20.63.219.114:15109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/fw.php"] [unique_id "apPkUkmtdPfUFP1akVE6YAAABJs"]
[Sun Aug 30 03:05:38.788022 2026] [security2:error] [pid 495314:tid 495485] [client 20.48.251.3:51506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/dd.php"] [unique_id "apPkUkmtdPfUFP1akVE6agAABFE"]
[Sun Aug 30 03:05:38.789804 2026] [authz_core:error] [pid 495314:tid 495557] [client 216.73.216.128:58018] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:38.790260 2026] [authz_core:error] [pid 495314:tid 495557] [client 216.73.216.128:58018] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:38.835704 2026] [security2:error] [pid 495314:tid 495509] [client 40.83.93.50:8717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/atomlib.php"] [unique_id "apPkUkmtdPfUFP1akVE6awAABGk"]
[Sun Aug 30 03:05:38.910852 2026] [security2:error] [pid 495314:tid 495444] [client 20.151.200.44:37836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/wp-login.php"] [unique_id "apPkUkmtdPfUFP1akVE6bgAABCg"]
[Sun Aug 30 03:05:38.910956 2026] [security2:error] [pid 495314:tid 495450] [client 4.205.62.107:58161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/otuz1.php"] [unique_id "apPkUkmtdPfUFP1akVE6bQAABC4"]
[Sun Aug 30 03:05:38.946956 2026] [security2:error] [pid 495314:tid 495468] [client 20.48.251.3:7018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/old_phpinfo.php"] [unique_id "apPkUkmtdPfUFP1akVE6cAAABEA"]
[Sun Aug 30 03:05:38.966436 2026] [security2:error] [pid 495314:tid 495534] [client 216.73.216.128:29535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/_static/css/theme.css"] [unique_id "apPkUkmtdPfUFP1akVE6dwAABII"]
[Sun Aug 30 03:05:38.980479 2026] [security2:error] [pid 495314:tid 495514] [client 20.172.38.178:58416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.38.172.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "persidabookstore.com"] [uri "/ss.php"] [unique_id "apPkUkmtdPfUFP1akVE6egAABG4"]
[Sun Aug 30 03:05:39.029655 2026] [security2:error] [pid 495314:tid 495447] [client 4.205.62.107:60591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/avim.php"] [unique_id "apPkU0mtdPfUFP1akVE6hQAABCs"]
[Sun Aug 30 03:05:39.038062 2026] [security2:error] [pid 495314:tid 495490] [client 68.155.159.216:52632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-admin/images/index.php"] [unique_id "apPkU0mtdPfUFP1akVE6hgAABFY"]
[Sun Aug 30 03:05:39.073537 2026] [authz_core:error] [pid 495314:tid 495499] [client 216.73.216.128:58018] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:39.073959 2026] [authz_core:error] [pid 495314:tid 495499] [client 216.73.216.128:58018] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:39.098693 2026] [security2:error] [pid 495314:tid 495549] [client 20.104.49.130:64923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.topatrust.com"] [uri "/mh.php"] [unique_id "apPkU0mtdPfUFP1akVE6jAAABJE"]
[Sun Aug 30 03:05:39.121092 2026] [security2:error] [pid 495314:tid 495529] [client 20.63.219.114:18537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/test.php"] [unique_id "apPkU0mtdPfUFP1akVE6jwAABH0"]
[Sun Aug 30 03:05:39.130584 2026] [security2:error] [pid 495314:tid 495545] [client 20.104.49.130:47986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/forum.php"] [unique_id "apPkU0mtdPfUFP1akVE6kQAABI0"]
[Sun Aug 30 03:05:39.157757 2026] [security2:error] [pid 495314:tid 495522] [client 4.205.62.107:4107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apPkU0mtdPfUFP1akVE6lQAABHY"]
[Sun Aug 30 03:05:39.186066 2026] [security2:error] [pid 495314:tid 495541] [client 20.104.50.220:27088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/images/13.php"] [unique_id "apPkU0mtdPfUFP1akVE6mAAABIk"]
[Sun Aug 30 03:05:39.187084 2026] [security2:error] [pid 495314:tid 495570] [client 68.155.159.216:59923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPkU0mtdPfUFP1akVE6mQAABKY"]
[Sun Aug 30 03:05:39.192840 2026] [security2:error] [pid 495314:tid 495539] [client 20.104.50.220:46593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/anjay.php"] [unique_id "apPkU0mtdPfUFP1akVE6mgAABIc"]
[Sun Aug 30 03:05:39.206787 2026] [security2:error] [pid 495314:tid 495469] [client 4.205.62.107:2318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/config/laravolt/css/index.php"] [unique_id "apPkU0mtdPfUFP1akVE6nAAABEE"]
[Sun Aug 30 03:05:39.212146 2026] [security2:error] [pid 495314:tid 495444] [client 20.48.251.3:23082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/wp-info.php"] [unique_id "apPkU0mtdPfUFP1akVE6ngAABCg"]
[Sun Aug 30 03:05:39.221049 2026] [security2:error] [pid 495314:tid 495486] [client 20.104.50.220:28682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/thr.php"] [unique_id "apPkU0mtdPfUFP1akVE6oAAABFI"]
[Sun Aug 30 03:05:39.252576 2026] [security2:error] [pid 495314:tid 495513] [client 20.104.50.220:62789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/k2ll33d.php"] [unique_id "apPkU0mtdPfUFP1akVE6pAAABG0"]
[Sun Aug 30 03:05:39.260526 2026] [authz_core:error] [pid 495314:tid 495515] [client 66.249.66.64:55524] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:39.260993 2026] [authz_core:error] [pid 495314:tid 495515] [client 66.249.66.64:55524] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:39.261699 2026] [security2:error] [pid 495314:tid 495557] [client 20.48.251.3:46225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/packed.php"] [unique_id "apPkU0mtdPfUFP1akVE6pQAABJk"]
[Sun Aug 30 03:05:39.262592 2026] [security2:error] [pid 495314:tid 495448] [client 20.48.251.3:7090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/public/rip.php.php"] [unique_id "apPkU0mtdPfUFP1akVE6pgAABCw"]
[Sun Aug 30 03:05:39.269300 2026] [security2:error] [pid 495314:tid 495449] [client 20.104.50.220:31901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/alpa.php"] [unique_id "apPkU0mtdPfUFP1akVE6pwAABC0"]
[Sun Aug 30 03:05:39.270101 2026] [security2:error] [pid 495314:tid 495458] [client 4.205.62.107:52137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/app.default.php"] [unique_id "apPkU0mtdPfUFP1akVE6qAAABDY"]
[Sun Aug 30 03:05:39.275673 2026] [security2:error] [pid 495314:tid 495483] [client 68.155.159.216:60589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-l0gin.php"] [unique_id "apPkU0mtdPfUFP1akVE6qQAABE8"]
[Sun Aug 30 03:05:39.279132 2026] [security2:error] [pid 495314:tid 495518] [client 20.104.50.220:5568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/class.php"] [unique_id "apPkU0mtdPfUFP1akVE6qgAABHI"]
[Sun Aug 30 03:05:39.290326 2026] [security2:error] [pid 495314:tid 495558] [client 20.104.50.220:61493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/noname.php"] [unique_id "apPkU0mtdPfUFP1akVE6qwAABJo"]
[Sun Aug 30 03:05:39.301145 2026] [security2:error] [pid 495314:tid 495554] [client 4.205.62.107:44786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/txets.php"] [unique_id "apPkU0mtdPfUFP1akVE6rQAABJY"]
[Sun Aug 30 03:05:39.318017 2026] [security2:error] [pid 495314:tid 495456] [client 40.83.93.50:8757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/buy.php"] [unique_id "apPkU0mtdPfUFP1akVE6sQAABDQ"]
[Sun Aug 30 03:05:39.336986 2026] [security2:error] [pid 495314:tid 495488] [client 20.48.251.3:49975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/thui.php"] [unique_id "apPkU0mtdPfUFP1akVE6tAAABFQ"]
[Sun Aug 30 03:05:39.352231 2026] [security2:error] [pid 495314:tid 495506] [client 4.205.62.107:18991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/file21.php"] [unique_id "apPkU0mtdPfUFP1akVE6tgAABGY"]
[Sun Aug 30 03:05:39.354221 2026] [security2:error] [pid 495314:tid 495556] [client 4.205.62.107:64028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/wp-admin/css/bolt.php"] [unique_id "apPkU0mtdPfUFP1akVE6twAABJg"]
[Sun Aug 30 03:05:39.360108 2026] [security2:error] [pid 495314:tid 495500] [client 20.104.18.15:13697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/m.php"] [unique_id "apPkU0mtdPfUFP1akVE6uAAABGA"]
[Sun Aug 30 03:05:39.368521 2026] [security2:error] [pid 495314:tid 495544] [client 20.104.18.15:32986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/5656.php"] [unique_id "apPkU0mtdPfUFP1akVE6uQAABIw"]
[Sun Aug 30 03:05:39.377760 2026] [security2:error] [pid 495314:tid 495504] [client 20.104.18.15:43265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/dehnl.php"] [unique_id "apPkU0mtdPfUFP1akVE6uwAABGQ"]
[Sun Aug 30 03:05:39.397033 2026] [security2:error] [pid 495314:tid 495553] [client 4.205.62.107:32470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/G-in.php"] [unique_id "apPkU0mtdPfUFP1akVE6vAAABJU"]
[Sun Aug 30 03:05:39.425530 2026] [security2:error] [pid 495314:tid 495476] [client 20.48.251.3:55685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/gjm.php"] [unique_id "apPkU0mtdPfUFP1akVE6wQAABEg"]
[Sun Aug 30 03:05:39.431596 2026] [security2:error] [pid 495314:tid 495522] [client 4.205.62.107:22541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/upload.form.php"] [unique_id "apPkU0mtdPfUFP1akVE6wwAABHY"]
[Sun Aug 30 03:05:39.452498 2026] [authz_core:error] [pid 495314:tid 495467] [client 66.249.66.32:39545] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:39.452973 2026] [authz_core:error] [pid 495314:tid 495467] [client 66.249.66.32:39545] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:39.486672 2026] [security2:error] [pid 495314:tid 495516] [client 20.63.219.114:8065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/dropdown.php"] [unique_id "apPkU0mtdPfUFP1akVE6zAAABHA"]
[Sun Aug 30 03:05:39.488392 2026] [security2:error] [pid 495314:tid 495472] [client 20.104.50.220:42002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/ngocokpeli.php"] [unique_id "apPkU0mtdPfUFP1akVE6zwAABEQ"]
[Sun Aug 30 03:05:39.532206 2026] [authz_core:error] [pid 495314:tid 495448] [client 216.73.216.128:14358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:39.532553 2026] [authz_core:error] [pid 495314:tid 495448] [client 216.73.216.128:14358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:39.536717 2026] [security2:error] [pid 495314:tid 495449] [client 4.205.62.107:27297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/kedi.php"] [unique_id "apPkU0mtdPfUFP1akVE62QAABC0"]
[Sun Aug 30 03:05:39.560697 2026] [security2:error] [pid 495314:tid 495483] [client 4.205.62.107:42611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/cli_bootstrap.php"] [unique_id "apPkU0mtdPfUFP1akVE62gAABE8"]
[Sun Aug 30 03:05:39.582234 2026] [security2:error] [pid 495314:tid 495514] [client 20.104.50.220:32882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/pmemek.php"] [unique_id "apPkU0mtdPfUFP1akVE63QAABG4"]
[Sun Aug 30 03:05:39.583061 2026] [security2:error] [pid 495314:tid 495475] [client 20.151.200.44:46992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/im.php"] [unique_id "apPkU0mtdPfUFP1akVE63gAABEc"]
[Sun Aug 30 03:05:39.633381 2026] [security2:error] [pid 495314:tid 495560] [client 20.151.200.44:47417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/ssh3ll.php"] [unique_id "apPkU0mtdPfUFP1akVE64AAABJw"]
[Sun Aug 30 03:05:39.639053 2026] [security2:error] [pid 495314:tid 495446] [client 20.48.251.3:44338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/xp.php"] [unique_id "apPkU0mtdPfUFP1akVE64QAABCo"]
[Sun Aug 30 03:05:39.691879 2026] [security2:error] [pid 495314:tid 495535] [client 20.104.49.130:40242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.topatrust.com"] [uri "/press.php"] [unique_id "apPkU0mtdPfUFP1akVE64wAABIM"]
[Sun Aug 30 03:05:39.721170 2026] [authz_core:error] [pid 495314:tid 495568] [client 216.73.216.128:14358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:39.721519 2026] [authz_core:error] [pid 495314:tid 495568] [client 216.73.216.128:14358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:39.737359 2026] [security2:error] [pid 495314:tid 495490] [client 4.205.62.107:58325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/apikeys.php"] [unique_id "apPkU0mtdPfUFP1akVE66gAABFY"]
[Sun Aug 30 03:05:39.738511 2026] [authz_core:error] [pid 495314:tid 495347] [remote 216.73.217.178:41524] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:39.738827 2026] [authz_core:error] [pid 495314:tid 495347] [remote 216.73.217.178:41524] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:39.824388 2026] [security2:error] [pid 495314:tid 495456] [client 40.83.93.50:18109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/hello.php"] [unique_id "apPkU0mtdPfUFP1akVE67QAABDQ"]
[Sun Aug 30 03:05:39.830667 2026] [security2:error] [pid 495314:tid 495504] [client 68.155.159.216:56430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkU0mtdPfUFP1akVE67wAABGQ"]
[Sun Aug 30 03:05:39.869808 2026] [security2:error] [pid 495314:tid 495502] [client 20.151.200.44:23601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPkU0mtdPfUFP1akVE68wAABGI"]
[Sun Aug 30 03:05:39.894502 2026] [security2:error] [pid 495314:tid 495556] [client 20.63.219.114:1422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/mar.php"] [unique_id "apPkU0mtdPfUFP1akVE69AAABJg"]
[Sun Aug 30 03:05:39.898725 2026] [security2:error] [pid 495314:tid 495527] [client 68.155.159.216:63535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apPkU0mtdPfUFP1akVE69gAABHs"]
[Sun Aug 30 03:05:39.929091 2026] [security2:error] [pid 495314:tid 495473] [client 20.48.251.3:51481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/wp-tem.php"] [unique_id "apPkU0mtdPfUFP1akVE6-gAABEU"]
[Sun Aug 30 03:05:39.996340 2026] [authz_core:error] [pid 495314:tid 495571] [client 216.73.216.128:58018] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:39.996634 2026] [authz_core:error] [pid 495314:tid 495571] [client 216.73.216.128:58018] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:40.088032 2026] [authz_core:error] [pid 495314:tid 495537] [client 216.73.216.128:18243] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:40.088317 2026] [authz_core:error] [pid 495314:tid 495537] [client 216.73.216.128:18243] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:40.116802 2026] [authz_core:error] [pid 495314:tid 495526] [client 66.249.66.195:35284] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:40.117096 2026] [authz_core:error] [pid 495314:tid 495526] [client 66.249.66.195:35284] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:40.158575 2026] [security2:error] [pid 495314:tid 495475] [client 4.205.62.107:60570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/nw.php"] [unique_id "apPkVEmtdPfUFP1akVE7FQAABEc"]
[Sun Aug 30 03:05:40.160399 2026] [security2:error] [pid 495314:tid 495492] [client 68.155.159.216:54772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-includes/index.php"] [unique_id "apPkVEmtdPfUFP1akVE7FwAABFg"]
[Sun Aug 30 03:05:40.180468 2026] [authz_core:error] [pid 495314:tid 495558] [client 216.73.216.128:58018] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:40.180841 2026] [authz_core:error] [pid 495314:tid 495558] [client 216.73.216.128:58018] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:40.244390 2026] [security2:error] [pid 495314:tid 495536] [client 4.205.62.107:58071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/update.php"] [unique_id "apPkVEmtdPfUFP1akVE7GgAABIQ"]
[Sun Aug 30 03:05:40.270792 2026] [authz_core:error] [pid 495314:tid 495535] [client 216.73.216.128:14358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:40.271096 2026] [authz_core:error] [pid 495314:tid 495535] [client 216.73.216.128:14358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:40.289231 2026] [authz_core:error] [pid 495314:tid 495448] [client 66.249.66.43:60536] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:40.289501 2026] [authz_core:error] [pid 495314:tid 495448] [client 66.249.66.43:60536] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:40.303523 2026] [security2:error] [pid 495314:tid 495518] [client 40.83.93.50:8764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/g.php"] [unique_id "apPkVEmtdPfUFP1akVE7IAAABHI"]
[Sun Aug 30 03:05:40.311182 2026] [security2:error] [pid 495314:tid 495524] [client 4.205.62.107:5094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/hochladen.form.php"] [unique_id "apPkVEmtdPfUFP1akVE7IQAABHg"]
[Sun Aug 30 03:05:40.322303 2026] [security2:error] [pid 495314:tid 495521] [client 20.104.50.220:27413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/inx.php"] [unique_id "apPkVEmtdPfUFP1akVE7IgAABHU"]
[Sun Aug 30 03:05:40.331473 2026] [security2:error] [pid 495314:tid 495567] [client 20.104.50.220:46165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/anons79.php"] [unique_id "apPkVEmtdPfUFP1akVE7JAAABKM"]
[Sun Aug 30 03:05:40.343701 2026] [security2:error] [pid 495314:tid 495457] [client 68.155.159.216:59971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-admin.php"] [unique_id "apPkVEmtdPfUFP1akVE7JQAABDU"]
[Sun Aug 30 03:05:40.346349 2026] [security2:error] [pid 495314:tid 495456] [client 4.205.62.107:2944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/87.php"] [unique_id "apPkVEmtdPfUFP1akVE7JgAABDQ"]
[Sun Aug 30 03:05:40.354090 2026] [security2:error] [pid 495314:tid 495504] [client 20.48.251.3:44266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/fns.php"] [unique_id "apPkVEmtdPfUFP1akVE7JwAABGQ"]
[Sun Aug 30 03:05:40.358340 2026] [security2:error] [pid 495314:tid 495553] [client 4.205.62.107:36001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/wdf.php"] [unique_id "apPkVEmtdPfUFP1akVE7KQAABJU"]
[Sun Aug 30 03:05:40.358841 2026] [security2:error] [pid 495314:tid 495467] [client 20.104.50.220:62831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/tmv.php"] [unique_id "apPkVEmtdPfUFP1akVE7KgAABD8"]
[Sun Aug 30 03:05:40.363172 2026] [authz_core:error] [pid 495314:tid 495568] [client 216.73.216.128:58018] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:40.363444 2026] [authz_core:error] [pid 495314:tid 495568] [client 216.73.216.128:58018] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:40.389640 2026] [security2:error] [pid 495314:tid 495529] [client 20.104.50.220:29569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/b1n4ry.php"] [unique_id "apPkVEmtdPfUFP1akVE7LAAABH0"]
[Sun Aug 30 03:05:40.407442 2026] [security2:error] [pid 495314:tid 495451] [client 20.48.251.3:46230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/wp-info.php"] [unique_id "apPkVEmtdPfUFP1akVE7MAAABC8"]
[Sun Aug 30 03:05:40.408497 2026] [security2:error] [pid 495314:tid 495559] [client 4.205.62.107:51752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/app_local.php"] [unique_id "apPkVEmtdPfUFP1akVE7MQAABJs"]
[Sun Aug 30 03:05:40.413142 2026] [security2:error] [pid 495314:tid 495519] [client 68.155.159.216:59333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apPkVEmtdPfUFP1akVE7MwAABHM"]
[Sun Aug 30 03:05:40.413946 2026] [security2:error] [pid 495314:tid 495538] [client 20.104.50.220:31811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/themes/antioch/acces.php"] [unique_id "apPkVEmtdPfUFP1akVE7NAAABIY"]
[Sun Aug 30 03:05:40.417323 2026] [security2:error] [pid 495314:tid 495570] [client 20.48.251.3:6495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/environment.php"] [unique_id "apPkVEmtdPfUFP1akVE7NQAABKY"]
[Sun Aug 30 03:05:40.427484 2026] [security2:error] [pid 495314:tid 495455] [client 20.104.50.220:62000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/kntol.php"] [unique_id "apPkVEmtdPfUFP1akVE7OAAABDM"]
[Sun Aug 30 03:05:40.438215 2026] [security2:error] [pid 495314:tid 495450] [client 4.205.62.107:44238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/time.php"] [unique_id "apPkVEmtdPfUFP1akVE7OgAABC4"]
[Sun Aug 30 03:05:40.449542 2026] [security2:error] [pid 495314:tid 495505] [client 20.104.50.220:6086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/bless5.php"] [unique_id "apPkVEmtdPfUFP1akVE7PwAABGU"]
[Sun Aug 30 03:05:40.474383 2026] [security2:error] [pid 495314:tid 495515] [client 20.63.219.114:14419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/css.php"] [unique_id "apPkVEmtdPfUFP1akVE7QgAABG8"]
[Sun Aug 30 03:05:40.478145 2026] [security2:error] [pid 495314:tid 495476] [client 20.48.251.3:55424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/file21.php"] [unique_id "apPkVEmtdPfUFP1akVE7QwAABEg"]
[Sun Aug 30 03:05:40.489955 2026] [security2:error] [pid 495314:tid 495445] [client 4.205.62.107:64000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/myfile.php"] [unique_id "apPkVEmtdPfUFP1akVE7TQAABCk"]
[Sun Aug 30 03:05:40.497845 2026] [security2:error] [pid 495314:tid 495449] [client 4.205.62.107:18681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/mcebraed.php"] [unique_id "apPkVEmtdPfUFP1akVE7TgAABC0"]
[Sun Aug 30 03:05:40.517734 2026] [security2:error] [pid 495314:tid 495446] [client 20.104.18.15:43327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/zoo2.php"] [unique_id "apPkVEmtdPfUFP1akVE7VgAABCo"]
[Sun Aug 30 03:05:40.523899 2026] [security2:error] [pid 495314:tid 495569] [client 20.104.18.15:33737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/w3lls.php"] [unique_id "apPkVEmtdPfUFP1akVE7VwAABKU"]
[Sun Aug 30 03:05:40.544124 2026] [security2:error] [pid 495314:tid 495548] [client 20.104.18.15:13658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/fling.php"] [unique_id "apPkVEmtdPfUFP1akVE7WwAABJA"]
[Sun Aug 30 03:05:40.545060 2026] [authz_core:error] [pid 495314:tid 495528] [client 66.249.66.195:65055] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:40.545447 2026] [authz_core:error] [pid 495314:tid 495528] [client 66.249.66.195:65055] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:40.550920 2026] [security2:error] [pid 495314:tid 495551] [client 146.70.194.236:35026] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alchemancer.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "apPkVEmtdPfUFP1akVE7XAAABJM"]
[Sun Aug 30 03:05:40.563917 2026] [security2:error] [pid 495314:tid 495503] [client 20.48.251.3:52774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/configuration.php"] [unique_id "apPkVEmtdPfUFP1akVE7YAAABGM"]
[Sun Aug 30 03:05:40.567860 2026] [security2:error] [pid 495314:tid 495567] [client 4.205.62.107:22567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/aws_auth.php"] [unique_id "apPkVEmtdPfUFP1akVE7YgAABKM"]
[Sun Aug 30 03:05:40.658963 2026] [security2:error] [pid 495314:tid 495519] [client 20.104.50.220:42803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/new_license.php"] [unique_id "apPkVEmtdPfUFP1akVE7agAABHM"]
[Sun Aug 30 03:05:40.703222 2026] [security2:error] [pid 495314:tid 495565] [client 4.205.62.107:42859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/dd.php"] [unique_id "apPkVEmtdPfUFP1akVE7bwAABKE"]
[Sun Aug 30 03:05:40.736453 2026] [security2:error] [pid 495314:tid 495516] [client 20.104.50.220:33587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/mmk.php"] [unique_id "apPkVEmtdPfUFP1akVE7dAAABHA"]
[Sun Aug 30 03:05:40.802225 2026] [security2:error] [pid 495314:tid 495527] [client 40.83.93.50:12060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/cc.php"] [unique_id "apPkVEmtdPfUFP1akVE7gQAABHs"]
[Sun Aug 30 03:05:40.825051 2026] [security2:error] [pid 495314:tid 495493] [client 20.151.200.44:37856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/wp-access.php"] [unique_id "apPkVEmtdPfUFP1akVE7hAAABFk"]
[Sun Aug 30 03:05:40.830185 2026] [authz_core:error] [pid 495314:tid 495465] [client 66.249.66.78:64519] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:40.830468 2026] [authz_core:error] [pid 495314:tid 495465] [client 66.249.66.78:64519] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:40.832079 2026] [security2:error] [pid 495314:tid 495475] [client 20.48.251.3:4693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/g3.php"] [unique_id "apPkVEmtdPfUFP1akVE7hgAABEc"]
[Sun Aug 30 03:05:40.879451 2026] [security2:error] [pid 495314:tid 495483] [client 68.155.159.216:61337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkVEmtdPfUFP1akVE7igAABE8"]
[Sun Aug 30 03:05:40.911931 2026] [authz_core:error] [pid 495314:tid 495469] [client 216.73.216.128:18243] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:40.912397 2026] [authz_core:error] [pid 495314:tid 495469] [client 216.73.216.128:18243] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:40.927820 2026] [security2:error] [pid 495314:tid 495536] [client 146.70.194.236:35042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.194.70.146.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alchemancer.com"] [uri "/xmlrpc.php"] [unique_id "apPkVEmtdPfUFP1akVE7kAAABIQ"]
[Sun Aug 30 03:05:40.947094 2026] [authz_core:error] [pid 495314:tid 495548] [client 66.249.66.206:51031] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:40.947374 2026] [authz_core:error] [pid 495314:tid 495548] [client 66.249.66.206:51031] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:40.959804 2026] [security2:error] [pid 495314:tid 495551] [client 68.155.159.216:56393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkVEmtdPfUFP1akVE7kwAABJM"]
[Sun Aug 30 03:05:40.978986 2026] [security2:error] [pid 495314:tid 495500] [client 4.205.62.107:32457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/motu.php"] [unique_id "apPkVEmtdPfUFP1akVE7lwAABGA"]
[Sun Aug 30 03:05:40.985390 2026] [security2:error] [pid 495314:tid 495564] [client 20.63.219.114:1458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/autoload_classmap.php"] [unique_id "apPkVEmtdPfUFP1akVE7mAAABKA"]
[Sun Aug 30 03:05:40.992701 2026] [security2:error] [pid 495314:tid 495549] [client 216.73.216.128:14358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts2/updateconf"] [unique_id "apPkVEmtdPfUFP1akVE7mgAABJE"]
[Sun Aug 30 03:05:41.115174 2026] [authz_core:error] [pid 495314:tid 495464] [client 66.249.66.68:53052] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:41.115469 2026] [authz_core:error] [pid 495314:tid 495464] [client 66.249.66.68:53052] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:41.157274 2026] [security2:error] [pid 495314:tid 495449] [client 68.155.159.216:62304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/chosen.php"] [unique_id "apPkVUmtdPfUFP1akVE7rwAABC0"]
[Sun Aug 30 03:05:41.162221 2026] [security2:error] [pid 495314:tid 495563] [client 158.23.147.79:40300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apPkVUmtdPfUFP1akVE7sAAABJ8"]
[Sun Aug 30 03:05:41.173373 2026] [security2:error] [pid 495314:tid 495561] [client 4.205.62.107:26516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/oc460l3x.php"] [unique_id "apPkVUmtdPfUFP1akVE7sQAABJ0"]
[Sun Aug 30 03:05:41.224342 2026] [security2:error] [pid 495314:tid 495546] [client 20.48.251.3:59135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/txets.php"] [unique_id "apPkVUmtdPfUFP1akVE7twAABI4"]
[Sun Aug 30 03:05:41.224677 2026] [security2:error] [pid 495314:tid 495487] [client 158.23.147.79:52879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apPkVUmtdPfUFP1akVE7uQAABFM"]
[Sun Aug 30 03:05:41.267241 2026] [security2:error] [pid 495314:tid 495446] [client 68.155.159.216:54767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/mah.php"] [unique_id "apPkVUmtdPfUFP1akVE7wAAABCo"]
[Sun Aug 30 03:05:41.270254 2026] [security2:error] [pid 495314:tid 495569] [client 158.23.147.79:26441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/nf_tracking.php"] [unique_id "apPkVUmtdPfUFP1akVE7wQAABKU"]
[Sun Aug 30 03:05:41.283882 2026] [security2:error] [pid 495314:tid 495532] [client 40.83.93.50:8752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/f35.php"] [unique_id "apPkVUmtdPfUFP1akVE7xAAABIA"]
[Sun Aug 30 03:05:41.286756 2026] [security2:error] [pid 495314:tid 495533] [client 158.23.147.79:62321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apPkVUmtdPfUFP1akVE7xQAABIE"]
[Sun Aug 30 03:05:41.288172 2026] [security2:error] [pid 495314:tid 495482] [client 4.205.62.107:63565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/product.php"] [unique_id "apPkVUmtdPfUFP1akVE7xgAABE4"]
[Sun Aug 30 03:05:41.337268 2026] [proxy:warn] [pid 495314:tid 495459] [client 199.45.154.116:52408] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be cherylvalk.com for uri /400.shtml
[Sun Aug 30 03:05:41.337319 2026] [proxy:error] [pid 495314:tid 495459] (70014)End of file found: [client 199.45.154.116:52408] AH01095: prefetch request body failed to 127.0.0.1:8080 (127.0.0.1) from 199.45.154.116 ()
[Sun Aug 30 03:05:41.401044 2026] [security2:error] [pid 495314:tid 495557] [client 158.23.147.79:26533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wzy.php"] [unique_id "apPkVUmtdPfUFP1akVE7ywAABJk"]
[Sun Aug 30 03:05:41.416112 2026] [security2:error] [pid 495314:tid 495519] [client 158.23.147.79:62307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/classwithtostring.php"] [unique_id "apPkVUmtdPfUFP1akVE7zwAABHM"]
[Sun Aug 30 03:05:41.449254 2026] [security2:error] [pid 495314:tid 495505] [client 4.205.62.107:4127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/debuggen.php"] [unique_id "apPkVUmtdPfUFP1akVE70wAABGU"]
[Sun Aug 30 03:05:41.452485 2026] [security2:error] [pid 495314:tid 495506] [client 4.205.62.107:32005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/public/mah.php.php"] [unique_id "apPkVUmtdPfUFP1akVE71AAABGY"]
[Sun Aug 30 03:05:41.453384 2026] [authz_core:error] [pid 495314:tid 495492] [client 216.73.216.128:58018] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:41.453714 2026] [authz_core:error] [pid 495314:tid 495492] [client 216.73.216.128:58018] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:41.454585 2026] [security2:error] [pid 495314:tid 495450] [client 68.155.159.216:59965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apPkVUmtdPfUFP1akVE71QAABC4"]
[Sun Aug 30 03:05:41.470184 2026] [security2:error] [pid 495314:tid 495479] [client 20.104.50.220:46622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/base.php"] [unique_id "apPkVUmtdPfUFP1akVE72QAABEs"]
[Sun Aug 30 03:05:41.473533 2026] [security2:error] [pid 495314:tid 495515] [client 20.104.50.220:27089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/images/mar.php"] [unique_id "apPkVUmtdPfUFP1akVE72gAABG8"]
[Sun Aug 30 03:05:41.483817 2026] [security2:error] [pid 495314:tid 495473] [client 4.205.62.107:2364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/plss3.php"] [unique_id "apPkVUmtdPfUFP1akVE73QAABEU"]
[Sun Aug 30 03:05:41.483951 2026] [security2:error] [pid 495314:tid 495516] [client 158.23.147.79:63239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-content/cong.php"] [unique_id "apPkVUmtdPfUFP1akVE73gAABHA"]
[Sun Aug 30 03:05:41.498215 2026] [security2:error] [pid 495314:tid 495524] [client 20.104.50.220:29124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/terminal.php"] [unique_id "apPkVUmtdPfUFP1akVE76gAABHg"]
[Sun Aug 30 03:05:41.498749 2026] [security2:error] [pid 495314:tid 495563] [client 20.48.251.3:23331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/params.php"] [unique_id "apPkVUmtdPfUFP1akVE76wAABJ8"]
[Sun Aug 30 03:05:41.505143 2026] [security2:error] [pid 495314:tid 495546] [client 146.70.194.236:35056] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alchemancer.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "apPkVUmtdPfUFP1akVE77gAABI4"]
[Sun Aug 30 03:05:41.506788 2026] [security2:error] [pid 495314:tid 495553] [client 20.63.219.114:1446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/info.php"] [unique_id "apPkVUmtdPfUFP1akVE77wAABJU"]
[Sun Aug 30 03:05:41.511006 2026] [security2:error] [pid 495314:tid 495487] [client 158.23.147.79:40260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apPkVUmtdPfUFP1akVE78AAABFM"]
[Sun Aug 30 03:05:41.520429 2026] [security2:error] [pid 495314:tid 495512] [client 158.23.147.79:63966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/install.php"] [unique_id "apPkVUmtdPfUFP1akVE78wAABGw"]
[Sun Aug 30 03:05:41.528889 2026] [security2:error] [pid 495314:tid 495461] [client 20.104.50.220:29595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/default.php"] [unique_id "apPkVUmtdPfUFP1akVE79AAABDk"]
[Sun Aug 30 03:05:41.539684 2026] [security2:error] [pid 495314:tid 495462] [client 4.205.62.107:58074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/channels.php"] [unique_id "apPkVUmtdPfUFP1akVE79wAABDo"]
[Sun Aug 30 03:05:41.545674 2026] [authz_core:error] [pid 495314:tid 495569] [client 216.73.216.128:18243] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:41.545949 2026] [authz_core:error] [pid 495314:tid 495569] [client 216.73.216.128:18243] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:41.560074 2026] [security2:error] [pid 495314:tid 495566] [client 4.205.62.107:51715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/ws62.php"] [unique_id "apPkVUmtdPfUFP1akVE7-AAABKI"]
[Sun Aug 30 03:05:41.560896 2026] [security2:error] [pid 495314:tid 495458] [client 20.104.50.220:32534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/su.php"] [unique_id "apPkVUmtdPfUFP1akVE7-QAABDY"]
[Sun Aug 30 03:05:41.566525 2026] [security2:error] [pid 495314:tid 495527] [client 101.78.141.110:60302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.141.78.101.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "1899project.com"] [uri "/wp-login.php"] [unique_id "apPkVUmtdPfUFP1akVE7-gAABHs"]
[Sun Aug 30 03:05:41.574152 2026] [security2:error] [pid 495314:tid 495465] [client 20.48.251.3:46159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/fns.php"] [unique_id "apPkVUmtdPfUFP1akVE7_AAABD0"]
[Sun Aug 30 03:05:41.574185 2026] [security2:error] [pid 495314:tid 495541] [client 20.48.251.3:7020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/aws_secret_config.php"] [unique_id "apPkVUmtdPfUFP1akVE7-wAABIk"]
[Sun Aug 30 03:05:41.575094 2026] [security2:error] [pid 495314:tid 495507] [client 4.205.62.107:44868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/doc.php"] [unique_id "apPkVUmtdPfUFP1akVE7_QAABGc"]
[Sun Aug 30 03:05:41.579248 2026] [security2:error] [pid 495314:tid 495551] [client 74.7.243.204:34678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/cms/"] [unique_id "apPkVUmtdPfUFP1akVE7_gAABJM"], referer: http://mail.letter7brands.com/cms/?p=%2F%2Fetc
[Sun Aug 30 03:05:41.598951 2026] [security2:error] [pid 495314:tid 495456] [client 20.104.50.220:6130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-includes/js/codemirror/index.php"] [unique_id "apPkVUmtdPfUFP1akVE8AQAABDQ"]
[Sun Aug 30 03:05:41.617125 2026] [security2:error] [pid 495314:tid 495564] [client 68.155.159.216:52804] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/ioxi002.PhP7"] [unique_id "apPkVUmtdPfUFP1akVE8BAAABKA"]
[Sun Aug 30 03:05:41.622489 2026] [security2:error] [pid 495314:tid 495537] [client 20.104.50.220:61835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/WSO.php"] [unique_id "apPkVUmtdPfUFP1akVE8BQAABIU"]
[Sun Aug 30 03:05:41.629383 2026] [security2:error] [pid 495314:tid 495481] [client 4.205.62.107:64023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/lm15.php"] [unique_id "apPkVUmtdPfUFP1akVE8BgAABE0"]
[Sun Aug 30 03:05:41.645969 2026] [security2:error] [pid 495314:tid 495519] [client 20.48.251.3:49995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/mcebraed.php"] [unique_id "apPkVUmtdPfUFP1akVE8CwAABHM"]
[Sun Aug 30 03:05:41.650575 2026] [security2:error] [pid 495314:tid 495478] [client 4.205.62.107:18997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/server-info.php"] [unique_id "apPkVUmtdPfUFP1akVE8DQAABEo"]
[Sun Aug 30 03:05:41.663306 2026] [security2:error] [pid 495314:tid 495499] [client 20.104.18.15:44011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/zoo1.php"] [unique_id "apPkVUmtdPfUFP1akVE8DwAABF8"]
[Sun Aug 30 03:05:41.669283 2026] [security2:error] [pid 495314:tid 495544] [client 20.104.18.15:33682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/fpwch.php"] [unique_id "apPkVUmtdPfUFP1akVE8EAAABIw"]
[Sun Aug 30 03:05:41.680575 2026] [authz_core:error] [pid 495314:tid 495567] [client 66.249.66.206:54488] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:41.681036 2026] [authz_core:error] [pid 495314:tid 495567] [client 66.249.66.206:54488] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:41.697917 2026] [security2:error] [pid 495314:tid 495468] [client 158.23.147.79:62299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-content/x/index.php"] [unique_id "apPkVUmtdPfUFP1akVE8EgAABEA"]
[Sun Aug 30 03:05:41.702850 2026] [security2:error] [pid 495314:tid 495479] [client 20.48.251.3:52863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/server_info.php"] [unique_id "apPkVUmtdPfUFP1akVE8EwAABEs"]
[Sun Aug 30 03:05:41.703791 2026] [security2:error] [pid 495314:tid 495515] [client 158.23.147.79:40943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apPkVUmtdPfUFP1akVE8FAAABG8"]
[Sun Aug 30 03:05:41.707109 2026] [security2:error] [pid 495314:tid 495525] [client 4.205.62.107:22576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/hiquido.com/index.php"] [unique_id "apPkVUmtdPfUFP1akVE8FgAABHk"]
[Sun Aug 30 03:05:41.747315 2026] [security2:error] [pid 495314:tid 495485] [client 20.151.200.44:63649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/xda.php"] [unique_id "apPkVUmtdPfUFP1akVE8GAAABFE"]
[Sun Aug 30 03:05:41.765489 2026] [security2:error] [pid 495314:tid 495463] [client 158.23.147.79:62587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPkVUmtdPfUFP1akVE8GQAABDs"]
[Sun Aug 30 03:05:41.766032 2026] [security2:error] [pid 495314:tid 495559] [client 40.83.93.50:18072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/classsmtps.php"] [unique_id "apPkVUmtdPfUFP1akVE8GgAABJs"]
[Sun Aug 30 03:05:41.805968 2026] [security2:error] [pid 495314:tid 495512] [client 158.23.147.79:62301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apPkVUmtdPfUFP1akVE8HwAABGw"]
[Sun Aug 30 03:05:41.806546 2026] [security2:error] [pid 495314:tid 495461] [client 158.23.147.79:40937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apPkVUmtdPfUFP1akVE8IAAABDk"]
[Sun Aug 30 03:05:41.809845 2026] [security2:error] [pid 495314:tid 495464] [client 20.104.50.220:63520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/miyabajingankoe.php"] [unique_id "apPkVUmtdPfUFP1akVE8IQAABDw"]
[Sun Aug 30 03:05:41.823504 2026] [security2:error] [pid 495314:tid 495493] [client 158.23.147.79:63235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apPkVUmtdPfUFP1akVE8IwAABFk"]
[Sun Aug 30 03:05:41.837581 2026] [security2:error] [pid 495314:tid 495446] [client 4.205.62.107:42073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/wp-tem.php"] [unique_id "apPkVUmtdPfUFP1akVE8JAAABCo"]
[Sun Aug 30 03:05:41.858070 2026] [security2:error] [pid 495314:tid 495560] [client 146.70.194.236:35064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alchemancer.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "apPkVUmtdPfUFP1akVE8JgAABJw"]
[Sun Aug 30 03:05:41.871281 2026] [authz_core:error] [pid 495314:tid 495477] [client 66.249.66.65:60580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:41.871762 2026] [authz_core:error] [pid 495314:tid 495477] [client 66.249.66.65:60580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:41.886329 2026] [security2:error] [pid 495314:tid 495528] [client 20.104.50.220:33171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/EvilTwin.php"] [unique_id "apPkVUmtdPfUFP1akVE8LQAABHw"]
[Sun Aug 30 03:05:41.898819 2026] [security2:error] [pid 495314:tid 495459] [client 20.104.49.130:57478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/sxxb.php"] [unique_id "apPkVUmtdPfUFP1akVE8MAAABDc"]
[Sun Aug 30 03:05:41.917351 2026] [security2:error] [pid 495314:tid 495519] [client 158.23.147.79:63949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apPkVUmtdPfUFP1akVE8OAAABHM"]
[Sun Aug 30 03:05:41.940206 2026] [security2:error] [pid 495314:tid 495556] [client 158.23.147.79:26611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apPkVUmtdPfUFP1akVE8PQAABJg"]
[Sun Aug 30 03:05:41.944484 2026] [security2:error] [pid 495314:tid 495526] [client 20.151.200.44:47422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/motu.php"] [unique_id "apPkVUmtdPfUFP1akVE8PgAABHo"]
[Sun Aug 30 03:05:41.956107 2026] [security2:error] [pid 495314:tid 495547] [client 20.63.219.114:14440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/b.php"] [unique_id "apPkVUmtdPfUFP1akVE8QgAABI8"]
[Sun Aug 30 03:05:41.964653 2026] [security2:error] [pid 495314:tid 495450] [client 20.48.251.3:44341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/wp-konfig.php"] [unique_id "apPkVUmtdPfUFP1akVE8RAAABC4"]
[Sun Aug 30 03:05:41.982058 2026] [security2:error] [pid 495314:tid 495468] [client 20.104.18.15:13753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/btyuio.php"] [unique_id "apPkVUmtdPfUFP1akVE8SAAABEA"]
[Sun Aug 30 03:05:42.002940 2026] [authz_core:error] [pid 495314:tid 495569] [client 216.73.216.128:63200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:42.003211 2026] [authz_core:error] [pid 495314:tid 495569] [client 216.73.216.128:63200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:42.016281 2026] [security2:error] [pid 495314:tid 495532] [client 107.189.14.87:54666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.14.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whatwouldderriawear.stylemederria.com"] [uri "/wp-login.php"] [unique_id "apPkVkmtdPfUFP1akVE8TAAABIA"]
[Sun Aug 30 03:05:42.018847 2026] [security2:error] [pid 495314:tid 495559] [client 20.151.200.44:62938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPkVkmtdPfUFP1akVE8TwAABJs"]
[Sun Aug 30 03:05:42.034320 2026] [security2:error] [pid 495314:tid 495565] [client 20.151.200.44:47088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/file.php"] [unique_id "apPkVkmtdPfUFP1akVE8UwAABKE"]
[Sun Aug 30 03:05:42.038508 2026] [security2:error] [pid 495314:tid 495539] [client 4.205.62.107:36672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/bb.php"] [unique_id "apPkVkmtdPfUFP1akVE8VAAABIc"]
[Sun Aug 30 03:05:42.043819 2026] [security2:error] [pid 495314:tid 495517] [client 158.23.147.79:26561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apPkVkmtdPfUFP1akVE8VQAABHE"]
[Sun Aug 30 03:05:42.066474 2026] [autoindex:error] [pid 495314:tid 495494] [client 158.23.184.117:7290] AH01276: Cannot serve directory /home1/tommy99/public_html/c/centrofruttadue_it/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:05:42.075922 2026] [security2:error] [pid 495314:tid 495535] [client 68.155.159.216:61318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkVkmtdPfUFP1akVE8WQAABIM"]
[Sun Aug 30 03:05:42.076694 2026] [security2:error] [pid 495314:tid 495512] [client 20.48.251.3:7030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/php-info.php"] [unique_id "apPkVkmtdPfUFP1akVE8WgAABGw"]
[Sun Aug 30 03:05:42.087520 2026] [security2:error] [pid 495314:tid 495475] [client 158.23.147.79:63874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-login.php"] [unique_id "apPkVkmtdPfUFP1akVE8WwAABEc"]
[Sun Aug 30 03:05:42.158246 2026] [security2:error] [pid 495314:tid 495492] [client 158.23.147.79:40265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/packed.php"] [unique_id "apPkVkmtdPfUFP1akVE8agAABFg"]
[Sun Aug 30 03:05:42.174570 2026] [security2:error] [pid 495314:tid 495505] [client 68.155.159.216:56410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apPkVkmtdPfUFP1akVE8bQAABGU"]
[Sun Aug 30 03:05:42.203772 2026] [security2:error] [pid 495314:tid 495544] [client 146.70.194.236:35076] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alchemancer.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "apPkVkmtdPfUFP1akVE8cQAABIw"]
[Sun Aug 30 03:05:42.243115 2026] [security2:error] [pid 495314:tid 495490] [client 40.83.93.50:12064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/install.php"] [unique_id "apPkVkmtdPfUFP1akVE8dQAABFY"]
[Sun Aug 30 03:05:42.253348 2026] [security2:error] [pid 495314:tid 495484] [client 158.23.147.79:62277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apPkVkmtdPfUFP1akVE8dgAABFA"]
[Sun Aug 30 03:05:42.257148 2026] [security2:error] [pid 495314:tid 495485] [client 158.23.147.79:26444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-content/packed.php"] [unique_id "apPkVkmtdPfUFP1akVE8dwAABFE"]
[Sun Aug 30 03:05:42.292767 2026] [security2:error] [pid 495314:tid 495554] [client 158.23.147.79:63277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPkVkmtdPfUFP1akVE8fgAABJY"]
[Sun Aug 30 03:05:42.359684 2026] [security2:error] [pid 495314:tid 495567] [client 20.63.219.114:14400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/wp-login.php"] [unique_id "apPkVkmtdPfUFP1akVE8gAAABKM"]
[Sun Aug 30 03:05:42.367460 2026] [security2:error] [pid 495314:tid 495494] [client 20.48.251.3:51571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/time.php"] [unique_id "apPkVkmtdPfUFP1akVE8gwAABFo"]
[Sun Aug 30 03:05:42.382775 2026] [security2:error] [pid 495314:tid 495460] [client 68.155.159.216:52624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-blog-header.php"] [unique_id "apPkVkmtdPfUFP1akVE8hAAABDg"]
[Sun Aug 30 03:05:42.385132 2026] [security2:error] [pid 495314:tid 495535] [client 158.23.147.79:40903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-l0gin.php"] [unique_id "apPkVkmtdPfUFP1akVE8hQAABIM"]
[Sun Aug 30 03:05:42.389457 2026] [security2:error] [pid 495314:tid 495512] [client 20.48.160.90:40018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/giodywky.php"] [unique_id "apPkVkmtdPfUFP1akVE8hgAABGw"]
[Sun Aug 30 03:05:42.407738 2026] [security2:error] [pid 495314:tid 495466] [client 158.23.147.79:53302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkVkmtdPfUFP1akVE8igAABD4"]
[Sun Aug 30 03:05:42.422077 2026] [security2:error] [pid 495314:tid 495569] [client 20.48.160.90:45931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/comand.php"] [unique_id "apPkVkmtdPfUFP1akVE8jgAABKU"]
[Sun Aug 30 03:05:42.425949 2026] [security2:error] [pid 495314:tid 495507] [client 4.205.62.107:63578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/fun.php"] [unique_id "apPkVkmtdPfUFP1akVE8jwAABGc"]
[Sun Aug 30 03:05:42.445965 2026] [security2:error] [pid 495314:tid 495488] [client 158.23.147.79:62278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-admin/images/about.php"] [unique_id "apPkVkmtdPfUFP1akVE8kwAABFQ"]
[Sun Aug 30 03:05:42.447077 2026] [security2:error] [pid 495314:tid 495566] [client 158.23.147.79:52940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apPkVkmtdPfUFP1akVE8lQAABKI"]
[Sun Aug 30 03:05:42.466532 2026] [security2:error] [pid 495314:tid 495454] [client 4.205.62.107:32495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/zaza.php"] [unique_id "apPkVkmtdPfUFP1akVE8lwAABDI"]
[Sun Aug 30 03:05:42.473734 2026] [security2:error] [pid 495314:tid 495539] [client 107.189.14.87:54798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.14.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whatwouldderriawear.stylemederria.com"] [uri "/wp-login.php"] [unique_id "apPkVkmtdPfUFP1akVE8mAAABIc"]
[Sun Aug 30 03:05:42.496312 2026] [security2:error] [pid 495314:tid 495558] [client 4.205.62.107:27274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/drykl.php"] [unique_id "apPkVkmtdPfUFP1akVE8owAABJo"]
[Sun Aug 30 03:05:42.526393 2026] [security2:error] [pid 495314:tid 495518] [client 158.23.147.79:53281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkVkmtdPfUFP1akVE8qAAABHI"]
[Sun Aug 30 03:05:42.526743 2026] [security2:error] [pid 495314:tid 495520] [client 20.48.160.90:39936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp-kz.php"] [unique_id "apPkVkmtdPfUFP1akVE8qQAABHQ"]
[Sun Aug 30 03:05:42.528066 2026] [security2:error] [pid 495314:tid 495544] [client 158.23.147.79:26612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apPkVkmtdPfUFP1akVE8qgAABIw"]
[Sun Aug 30 03:05:42.532965 2026] [security2:error] [pid 495314:tid 495468] [client 20.48.160.90:33262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/ah.php"] [unique_id "apPkVkmtdPfUFP1akVE8rAAABEA"]
[Sun Aug 30 03:05:42.543138 2026] [security2:error] [pid 495314:tid 495504] [client 158.23.147.79:63910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPkVkmtdPfUFP1akVE8rQAABGQ"]
[Sun Aug 30 03:05:42.563727 2026] [security2:error] [pid 495314:tid 495511] [client 146.70.194.236:35086] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alchemancer.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "apPkVkmtdPfUFP1akVE8rwAABGs"]
[Sun Aug 30 03:05:42.568356 2026] [security2:error] [pid 495314:tid 495457] [client 20.48.160.90:40037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp_motu_myk3v.php"] [unique_id "apPkVkmtdPfUFP1akVE8sQAABDU"]
[Sun Aug 30 03:05:42.594537 2026] [security2:error] [pid 495314:tid 495470] [client 68.155.159.216:59968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/lock.php"] [unique_id "apPkVkmtdPfUFP1akVE8sgAABEI"]
[Sun Aug 30 03:05:42.607563 2026] [security2:error] [pid 495314:tid 495445] [client 20.104.50.220:46603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/batm.php"] [unique_id "apPkVkmtdPfUFP1akVE8swAABCk"]
[Sun Aug 30 03:05:42.610527 2026] [security2:error] [pid 495314:tid 495498] [client 4.205.62.107:4146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/pouhg.php"] [unique_id "apPkVkmtdPfUFP1akVE8tAAABF4"]
[Sun Aug 30 03:05:42.615018 2026] [security2:error] [pid 495314:tid 495538] [client 20.104.50.220:27076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/shiny.php"] [unique_id "apPkVkmtdPfUFP1akVE8tgAABIY"]
[Sun Aug 30 03:05:42.636366 2026] [security2:error] [pid 495314:tid 495513] [client 20.48.251.3:44187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/gjm.php"] [unique_id "apPkVkmtdPfUFP1akVE8uAAABG0"]
[Sun Aug 30 03:05:42.649343 2026] [security2:error] [pid 495314:tid 495477] [client 20.104.50.220:29602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/titid.php"] [unique_id "apPkVkmtdPfUFP1akVE8ugAABEk"]
[Sun Aug 30 03:05:42.653267 2026] [security2:error] [pid 495314:tid 495506] [client 158.23.147.79:62477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apPkVkmtdPfUFP1akVE8vAAABGY"]
[Sun Aug 30 03:05:42.653593 2026] [security2:error] [pid 495314:tid 495494] [client 4.205.62.107:2360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/aws.php"] [unique_id "apPkVkmtdPfUFP1akVE8vQAABFo"]
[Sun Aug 30 03:05:42.655177 2026] [security2:error] [pid 495314:tid 495487] [client 20.48.160.90:45854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp-includes/ID3/getid.php"] [unique_id "apPkVkmtdPfUFP1akVE8vgAABFM"]
[Sun Aug 30 03:05:42.665279 2026] [security2:error] [pid 495314:tid 495512] [client 158.23.147.79:63917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-admin.php"] [unique_id "apPkVkmtdPfUFP1akVE8wAAABGw"]
[Sun Aug 30 03:05:42.665978 2026] [security2:error] [pid 495314:tid 495557] [client 20.104.50.220:62817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/blank.php"] [unique_id "apPkVkmtdPfUFP1akVE8wQAABJk"]
[Sun Aug 30 03:05:42.671321 2026] [security2:error] [pid 495314:tid 495571] [client 20.48.160.90:50633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/ws55.php"] [unique_id "apPkVkmtdPfUFP1akVE8wwAABKc"]
[Sun Aug 30 03:05:42.696397 2026] [security2:error] [pid 495314:tid 495537] [client 68.155.159.216:62292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/goods.php"] [unique_id "apPkVkmtdPfUFP1akVE8yAAABIU"]
[Sun Aug 30 03:05:42.699522 2026] [security2:error] [pid 495314:tid 495465] [client 4.205.62.107:56593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/grsiuk.php"] [unique_id "apPkVkmtdPfUFP1akVE8yQAABD0"]
[Sun Aug 30 03:05:42.706541 2026] [security2:error] [pid 495314:tid 495475] [client 158.23.147.79:53282] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-includes/blocks/post-excerpt/alfa-rex.PHP"] [unique_id "apPkVkmtdPfUFP1akVE8ygAABEc"]
[Sun Aug 30 03:05:42.709743 2026] [security2:error] [pid 495314:tid 495488] [client 20.48.251.3:64472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/snq.php"] [unique_id "apPkVkmtdPfUFP1akVE8ywAABFQ"]
[Sun Aug 30 03:05:42.713491 2026] [security2:error] [pid 495314:tid 495561] [client 20.104.50.220:32529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/xx.php"] [unique_id "apPkVkmtdPfUFP1akVE8zAAABJ0"]
[Sun Aug 30 03:05:42.714032 2026] [security2:error] [pid 495314:tid 495534] [client 4.205.62.107:44429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/classsmtps.php"] [unique_id "apPkVkmtdPfUFP1akVE8zQAABII"]
[Sun Aug 30 03:05:42.722969 2026] [security2:error] [pid 495314:tid 495459] [client 158.23.147.79:26613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPkVkmtdPfUFP1akVE8zgAABDc"]
[Sun Aug 30 03:05:42.724946 2026] [security2:error] [pid 495314:tid 495497] [client 20.48.160.90:45828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/wp_motu_ypdat.php"] [unique_id "apPkVkmtdPfUFP1akVE8zwAABF0"]
[Sun Aug 30 03:05:42.736424 2026] [security2:error] [pid 495314:tid 495458] [client 20.48.251.3:46243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/params.php"] [unique_id "apPkVkmtdPfUFP1akVE80AAABDY"]
[Sun Aug 30 03:05:42.739763 2026] [security2:error] [pid 495314:tid 495467] [client 20.104.50.220:6126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-includes/block-patterns/index.php"] [unique_id "apPkVkmtdPfUFP1akVE80QAABD8"]
[Sun Aug 30 03:05:42.750360 2026] [security2:error] [pid 495314:tid 495524] [client 20.63.219.114:14436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/aa.php"] [unique_id "apPkVkmtdPfUFP1akVE80gAABHg"]
[Sun Aug 30 03:05:42.760430 2026] [security2:error] [pid 495314:tid 495533] [client 20.151.200.44:47316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/wefile.php"] [unique_id "apPkVkmtdPfUFP1akVE80wAABIE"]
[Sun Aug 30 03:05:42.765840 2026] [security2:error] [pid 495314:tid 495482] [client 68.155.159.216:52831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPkVkmtdPfUFP1akVE81QAABE4"]
[Sun Aug 30 03:05:42.774407 2026] [security2:error] [pid 495314:tid 495519] [client 4.205.62.107:62025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/test.config.php"] [unique_id "apPkVkmtdPfUFP1akVE82QAABHM"]
[Sun Aug 30 03:05:42.778438 2026] [security2:error] [pid 495314:tid 495556] [client 20.104.50.220:61432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/IndoXploit.php"] [unique_id "apPkVkmtdPfUFP1akVE82gAABJg"]
[Sun Aug 30 03:05:42.786668 2026] [security2:error] [pid 495314:tid 495541] [client 20.48.251.3:55535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/server-info.php"] [unique_id "apPkVkmtdPfUFP1akVE82wAABIk"]
[Sun Aug 30 03:05:42.805779 2026] [security2:error] [pid 495314:tid 495499] [client 20.48.160.90:50680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/drykl.php"] [unique_id "apPkVkmtdPfUFP1akVE83AAABF8"]
[Sun Aug 30 03:05:42.817599 2026] [security2:error] [pid 495314:tid 495555] [client 158.23.147.79:63932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apPkVkmtdPfUFP1akVE83QAABJc"]
[Sun Aug 30 03:05:42.827138 2026] [security2:error] [pid 495314:tid 495521] [client 20.104.18.15:44010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/radio.php"] [unique_id "apPkVkmtdPfUFP1akVE83gAABHU"]
[Sun Aug 30 03:05:42.827358 2026] [security2:error] [pid 495314:tid 495520] [client 20.48.160.90:45881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/session.php"] [unique_id "apPkVkmtdPfUFP1akVE83wAABHQ"]
[Sun Aug 30 03:05:42.836611 2026] [security2:error] [pid 495314:tid 495468] [client 4.205.62.107:18682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/gk.php"] [unique_id "apPkVkmtdPfUFP1akVE84AAABEA"]
[Sun Aug 30 03:05:42.839373 2026] [security2:error] [pid 495314:tid 495568] [client 20.48.251.3:59298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/hosty.php"] [unique_id "apPkVkmtdPfUFP1akVE84QAABKQ"]
[Sun Aug 30 03:05:42.841884 2026] [security2:error] [pid 495314:tid 495504] [client 4.205.62.107:62409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/ws79.php"] [unique_id "apPkVkmtdPfUFP1akVE84gAABGQ"]
[Sun Aug 30 03:05:42.843809 2026] [security2:error] [pid 495314:tid 495564] [client 40.83.93.50:8740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/wp.php"] [unique_id "apPkVkmtdPfUFP1akVE84wAABKA"]
[Sun Aug 30 03:05:42.850929 2026] [security2:error] [pid 495314:tid 495473] [client 20.104.18.15:33763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/domvf.php"] [unique_id "apPkVkmtdPfUFP1akVE85AAABEU"]
[Sun Aug 30 03:05:42.864871 2026] [security2:error] [pid 495314:tid 495511] [client 20.48.160.90:40026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/edit.php"] [unique_id "apPkVkmtdPfUFP1akVE85gAABGs"]
[Sun Aug 30 03:05:42.905414 2026] [security2:error] [pid 495314:tid 495517] [client 158.23.147.79:40315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/ans.php"] [unique_id "apPkVkmtdPfUFP1akVE87QAABHE"]
[Sun Aug 30 03:05:42.911990 2026] [security2:error] [pid 495314:tid 495513] [client 4.205.62.107:65335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/zz.php"] [unique_id "apPkVkmtdPfUFP1akVE87gAABG0"]
[Sun Aug 30 03:05:42.913147 2026] [security2:error] [pid 495314:tid 495523] [client 146.70.194.236:35098] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alchemancer.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "apPkVkmtdPfUFP1akVE88AAABHc"]
[Sun Aug 30 03:05:42.922909 2026] [security2:error] [pid 495314:tid 495444] [client 158.23.147.79:62272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/lock.php"] [unique_id "apPkVkmtdPfUFP1akVE88QAABCg"]
[Sun Aug 30 03:05:42.963202 2026] [security2:error] [pid 495314:tid 495512] [client 20.48.160.90:50633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/backup.php"] [unique_id "apPkVkmtdPfUFP1akVE89AAABGw"]
[Sun Aug 30 03:05:42.965641 2026] [security2:error] [pid 495314:tid 495557] [client 20.104.50.220:63522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/done.php"] [unique_id "apPkVkmtdPfUFP1akVE89QAABJk"]
[Sun Aug 30 03:05:42.975746 2026] [security2:error] [pid 495314:tid 495462] [client 4.205.62.107:42591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/txets.php"] [unique_id "apPkVkmtdPfUFP1akVE8-QAABDo"]
[Sun Aug 30 03:05:42.977402 2026] [security2:error] [pid 495314:tid 495562] [client 158.23.147.79:62570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-content/radio.php"] [unique_id "apPkVkmtdPfUFP1akVE8-gAABJ4"]
[Sun Aug 30 03:05:43.002885 2026] [security2:error] [pid 495314:tid 495459] [client 158.23.147.79:26508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/worksec.php"] [unique_id "apPkV0mtdPfUFP1akVE8_wAABDc"]
[Sun Aug 30 03:05:43.026045 2026] [security2:error] [pid 495314:tid 495524] [client 20.104.50.220:33049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/da111.php"] [unique_id "apPkV0mtdPfUFP1akVE9BAAABHg"]
[Sun Aug 30 03:05:43.052748 2026] [security2:error] [pid 495314:tid 495510] [client 158.23.147.79:63876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/index/function.php"] [unique_id "apPkV0mtdPfUFP1akVE9DAAABGo"]
[Sun Aug 30 03:05:43.056542 2026] [authz_core:error] [pid 495314:tid 495541] [client 66.249.66.65:60580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:43.056845 2026] [authz_core:error] [pid 495314:tid 495541] [client 66.249.66.65:60580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:43.111730 2026] [security2:error] [pid 495314:tid 495468] [client 158.23.147.79:40901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/x.php"] [unique_id "apPkV0mtdPfUFP1akVE9FwAABEA"]
[Sun Aug 30 03:05:43.117595 2026] [security2:error] [pid 495314:tid 495504] [client 158.23.147.79:62573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apPkV0mtdPfUFP1akVE9GQAABGQ"]
[Sun Aug 30 03:05:43.118156 2026] [security2:error] [pid 495314:tid 495564] [client 20.48.251.3:44347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/25.php"] [unique_id "apPkV0mtdPfUFP1akVE9GgAABKA"]
[Sun Aug 30 03:05:43.118720 2026] [security2:error] [pid 495314:tid 495525] [client 20.104.18.15:13644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/dehnl.php"] [unique_id "apPkV0mtdPfUFP1akVE9GwAABHk"]
[Sun Aug 30 03:05:43.131085 2026] [security2:error] [pid 495314:tid 495561] [client 20.63.219.114:18135] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cavendish-club.com.lodestar.media"] [uri "/c99.php"] [unique_id "apPkV0mtdPfUFP1akVE9HwAABJ0"]
[Sun Aug 30 03:05:43.170030 2026] [security2:error] [pid 495314:tid 495484] [client 158.23.147.79:53256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apPkV0mtdPfUFP1akVE9IQAABFA"]
[Sun Aug 30 03:05:43.207605 2026] [security2:error] [pid 495314:tid 495563] [client 158.23.147.79:63888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/.well-known/content.php"] [unique_id "apPkV0mtdPfUFP1akVE9JwAABJ8"]
[Sun Aug 30 03:05:43.214001 2026] [security2:error] [pid 495314:tid 495474] [client 158.23.147.79:63246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/login.php"] [unique_id "apPkV0mtdPfUFP1akVE9KAAABEY"]
[Sun Aug 30 03:05:43.239672 2026] [security2:error] [pid 495314:tid 495449] [client 158.23.147.79:40913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-content/x.php"] [unique_id "apPkV0mtdPfUFP1akVE9KwAABC0"]
[Sun Aug 30 03:05:43.253039 2026] [authz_core:error] [pid 495314:tid 495513] [client 66.249.66.76:40007] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:43.253383 2026] [security2:error] [pid 495314:tid 495506] [client 20.151.200.44:63612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/t00l.php"] [unique_id "apPkV0mtdPfUFP1akVE9LwAABGY"]
[Sun Aug 30 03:05:43.253407 2026] [authz_core:error] [pid 495314:tid 495513] [client 66.249.66.76:40007] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:43.258331 2026] [security2:error] [pid 495314:tid 495540] [client 20.151.200.44:46994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/ca.php"] [unique_id "apPkV0mtdPfUFP1akVE9MgAABIg"]
[Sun Aug 30 03:05:43.279889 2026] [security2:error] [pid 495314:tid 495453] [client 4.205.62.107:32511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/u88.php"] [unique_id "apPkV0mtdPfUFP1akVE9NQAABDE"]
[Sun Aug 30 03:05:43.281350 2026] [security2:error] [pid 495314:tid 495462] [client 146.70.194.236:35108] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alchemancer.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "apPkV0mtdPfUFP1akVE9NgAABDo"]
[Sun Aug 30 03:05:43.331400 2026] [security2:error] [pid 495314:tid 495559] [client 40.83.93.50:8742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/error.php"] [unique_id "apPkV0mtdPfUFP1akVE9QAAABJs"]
[Sun Aug 30 03:05:43.337603 2026] [security2:error] [pid 495314:tid 495458] [client 158.23.147.79:62502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/hehehehe.php"] [unique_id "apPkV0mtdPfUFP1akVE9QQAABDY"]
[Sun Aug 30 03:05:43.353134 2026] [security2:error] [pid 495314:tid 495533] [client 158.23.147.79:62537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apPkV0mtdPfUFP1akVE9RgAABIE"]
[Sun Aug 30 03:05:43.417103 2026] [security2:error] [pid 495314:tid 495528] [client 158.23.147.79:42063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-content/plugins/index.php"] [unique_id "apPkV0mtdPfUFP1akVE9TwAABHw"]
[Sun Aug 30 03:05:43.420519 2026] [security2:error] [pid 495314:tid 495520] [client 158.23.147.79:26565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPkV0mtdPfUFP1akVE9UQAABHQ"]
[Sun Aug 30 03:05:43.458067 2026] [security2:error] [pid 495314:tid 495463] [client 68.155.159.216:56342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apPkV0mtdPfUFP1akVE9WQAABDs"]
[Sun Aug 30 03:05:43.493214 2026] [security2:error] [pid 495314:tid 495498] [client 68.155.159.216:54725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apPkV0mtdPfUFP1akVE9YAAABF4"]
[Sun Aug 30 03:05:43.495486 2026] [security2:error] [pid 495314:tid 495538] [client 216.73.216.128:58018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/about.html"] [unique_id "apPkV0mtdPfUFP1akVE9YQAABIY"]
[Sun Aug 30 03:05:43.499773 2026] [security2:error] [pid 495314:tid 495563] [client 158.23.147.79:63957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/cong.php"] [unique_id "apPkV0mtdPfUFP1akVE9ZAAABJ8"]
[Sun Aug 30 03:05:43.518538 2026] [security2:error] [pid 495314:tid 495569] [client 20.48.251.3:51477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/doc.php"] [unique_id "apPkV0mtdPfUFP1akVE9aAAABKU"]
[Sun Aug 30 03:05:43.525394 2026] [security2:error] [pid 495314:tid 495493] [client 158.23.147.79:62484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apPkV0mtdPfUFP1akVE9agAABFk"]
[Sun Aug 30 03:05:43.535895 2026] [security2:error] [pid 495314:tid 495446] [client 158.23.147.79:40274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/log-mama/function.php"] [unique_id "apPkV0mtdPfUFP1akVE9bAAABCo"]
[Sun Aug 30 03:05:43.536340 2026] [security2:error] [pid 495314:tid 495500] [client 20.104.49.130:36614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.topatrust.com"] [uri "/edit.php"] [unique_id "apPkV0mtdPfUFP1akVE9bQAABGA"]
[Sun Aug 30 03:05:43.537470 2026] [security2:error] [pid 495314:tid 495479] [client 20.63.219.114:9614] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cavendish-club.com.lodestar.media"] [uri "/c99.php"] [unique_id "apPkV0mtdPfUFP1akVE9bgAABEs"]
[Sun Aug 30 03:05:43.565820 2026] [security2:error] [pid 495314:tid 495465] [client 74.7.243.204:34678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/site/"] [unique_id "apPkV0mtdPfUFP1akVE9cgAABD0"], referer: http://mail.letter7brands.com/site/?p=%2F%2Fetc
[Sun Aug 30 03:05:43.606832 2026] [security2:error] [pid 495314:tid 495455] [client 158.23.147.79:62329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-includes/js/index.php"] [unique_id "apPkV0mtdPfUFP1akVE9dgAABDM"]
[Sun Aug 30 03:05:43.628618 2026] [security2:error] [pid 495314:tid 495528] [client 146.70.194.236:35116] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alchemancer.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "apPkV0mtdPfUFP1akVE9ewAABHw"]
[Sun Aug 30 03:05:43.650973 2026] [security2:error] [pid 495314:tid 495521] [client 158.23.147.79:40291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/bk/index.php"] [unique_id "apPkV0mtdPfUFP1akVE9fgAABHU"]
[Sun Aug 30 03:05:43.677629 2026] [authz_core:error] [pid 495314:tid 495562] [client 66.249.66.44:52158] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:43.677962 2026] [authz_core:error] [pid 495314:tid 495562] [client 66.249.66.44:52158] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:43.690103 2026] [security2:error] [pid 495314:tid 495515] [client 158.23.147.79:53249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/simple.php"] [unique_id "apPkV0mtdPfUFP1akVE9gwAABG8"]
[Sun Aug 30 03:05:43.718900 2026] [security2:error] [pid 495314:tid 495482] [client 68.155.159.216:59996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/index/function.php"] [unique_id "apPkV0mtdPfUFP1akVE9hQAABE4"]
[Sun Aug 30 03:05:43.737904 2026] [authz_core:error] [pid 495314:tid 495564] [client 66.249.66.45:35091] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:43.738406 2026] [authz_core:error] [pid 495314:tid 495564] [client 66.249.66.45:35091] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:43.739933 2026] [security2:error] [pid 495314:tid 495510] [client 158.23.147.79:63256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-content/admin.php"] [unique_id "apPkV0mtdPfUFP1akVE9iAAABGo"]
[Sun Aug 30 03:05:43.743435 2026] [security2:error] [pid 495314:tid 495478] [client 20.104.50.220:46643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/bj.php"] [unique_id "apPkV0mtdPfUFP1akVE9igAABEo"]
[Sun Aug 30 03:05:43.750896 2026] [security2:error] [pid 495314:tid 495568] [client 20.104.50.220:27526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPkV0mtdPfUFP1akVE9iwAABKQ"]
[Sun Aug 30 03:05:43.758547 2026] [security2:error] [pid 495314:tid 495463] [client 158.23.147.79:62293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-content/index.php"] [unique_id "apPkV0mtdPfUFP1akVE9jAAABDs"]
[Sun Aug 30 03:05:43.775609 2026] [security2:error] [pid 495314:tid 495456] [client 20.48.251.3:44268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/configuration.php"] [unique_id "apPkV0mtdPfUFP1akVE9jwAABDQ"]
[Sun Aug 30 03:05:43.783714 2026] [security2:error] [pid 495314:tid 495566] [client 158.23.147.79:62558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/nf_tracking.php"] [unique_id "apPkV0mtdPfUFP1akVE9kQAABKI"]
[Sun Aug 30 03:05:43.788840 2026] [security2:error] [pid 495314:tid 495461] [client 20.104.50.220:29120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/sllolx.php"] [unique_id "apPkV0mtdPfUFP1akVE9kgAABDk"]
[Sun Aug 30 03:05:43.816552 2026] [security2:error] [pid 495314:tid 495474] [client 158.23.147.79:26598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.websitesbyjeremy.com"] [uri "/first.php"] [unique_id "apPkV0mtdPfUFP1akVE9lAAABEY"]
[Sun Aug 30 03:05:43.826458 2026] [security2:error] [pid 495314:tid 495523] [client 20.104.50.220:62816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/admin-demo/index.php"] [unique_id "apPkV0mtdPfUFP1akVE9lQAABHc"]
[Sun Aug 30 03:05:43.840816 2026] [security2:error] [pid 495314:tid 495519] [client 40.83.93.50:9109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/profile.php"] [unique_id "apPkV0mtdPfUFP1akVE9lwAABHM"]
[Sun Aug 30 03:05:43.850814 2026] [security2:error] [pid 495314:tid 495516] [client 20.48.251.3:64482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/wp-access.php"] [unique_id "apPkV0mtdPfUFP1akVE9mQAABHA"]
[Sun Aug 30 03:05:43.852130 2026] [security2:error] [pid 495314:tid 495449] [client 20.104.50.220:31864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/byps.php"] [unique_id "apPkV0mtdPfUFP1akVE9mgAABC0"]
[Sun Aug 30 03:05:43.891874 2026] [security2:error] [pid 495314:tid 495556] [client 68.155.159.216:52850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/ans.php"] [unique_id "apPkV0mtdPfUFP1akVE9mwAABJg"]
[Sun Aug 30 03:05:43.894384 2026] [security2:error] [pid 495314:tid 495569] [client 20.104.50.220:6105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/lock360.php"] [unique_id "apPkV0mtdPfUFP1akVE9nAAABKU"]
[Sun Aug 30 03:05:43.903172 2026] [security2:error] [pid 495314:tid 495571] [client 158.23.147.79:63899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/about/function.php"] [unique_id "apPkV0mtdPfUFP1akVE9oAAABKc"]
[Sun Aug 30 03:05:43.912911 2026] [security2:error] [pid 495314:tid 495522] [client 20.63.219.114:1445] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cavendish-club.com.lodestar.media"] [uri "/c99.php"] [unique_id "apPkV0mtdPfUFP1akVE9pAAABHY"]
[Sun Aug 30 03:05:43.918664 2026] [security2:error] [pid 495314:tid 495479] [client 20.48.251.3:54820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/gjm.php"] [unique_id "apPkV0mtdPfUFP1akVE9pQAABEs"]
[Sun Aug 30 03:05:43.929925 2026] [security2:error] [pid 495314:tid 495532] [client 20.104.50.220:61440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/bajingan.php"] [unique_id "apPkV0mtdPfUFP1akVE9pwAABIA"]
[Sun Aug 30 03:05:43.943003 2026] [security2:error] [pid 495314:tid 495542] [client 20.48.251.3:55539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/gk.php"] [unique_id "apPkV0mtdPfUFP1akVE9qQAABIo"]
[Sun Aug 30 03:05:43.969992 2026] [security2:error] [pid 495314:tid 495549] [client 20.104.18.15:44001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/one.php"] [unique_id "apPkV0mtdPfUFP1akVE9qwAABJE"]
[Sun Aug 30 03:05:43.977713 2026] [security2:error] [pid 495314:tid 495528] [client 20.48.251.3:55701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/pass4.php"] [unique_id "apPkV0mtdPfUFP1akVE9rAAABHw"]
[Sun Aug 30 03:05:43.979715 2026] [security2:error] [pid 495314:tid 495520] [client 146.70.194.236:35120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alchemancer.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "apPkV0mtdPfUFP1akVE9rgAABHQ"]
[Sun Aug 30 03:05:43.981353 2026] [security2:error] [pid 495314:tid 495536] [client 20.104.49.130:52518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/sxxb.php"] [unique_id "apPkV0mtdPfUFP1akVE9sAAABIQ"]
[Sun Aug 30 03:05:43.987985 2026] [authz_core:error] [pid 495314:tid 495465] [client 66.249.66.78:49494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:43.988257 2026] [authz_core:error] [pid 495314:tid 495465] [client 66.249.66.78:49494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:44.015232 2026] [security2:error] [pid 495314:tid 495560] [client 158.23.147.79:63998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apPkWEmtdPfUFP1akVE9uAAABJw"]
[Sun Aug 30 03:05:44.054025 2026] [security2:error] [pid 495314:tid 495502] [client 20.104.18.15:32968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/biufile.php"] [unique_id "apPkWEmtdPfUFP1akVE9vQAABGI"]
[Sun Aug 30 03:05:44.060263 2026] [authz_core:error] [pid 495314:tid 495508] [client 66.249.66.192:41277] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:44.060561 2026] [authz_core:error] [pid 495314:tid 495508] [client 66.249.66.192:41277] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:44.107588 2026] [security2:error] [pid 495314:tid 495481] [client 216.73.216.128:43717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPkWEmtdPfUFP1akVE9ygAABE0"]
[Sun Aug 30 03:05:44.120079 2026] [security2:error] [pid 495314:tid 495490] [client 20.104.50.220:63505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/eviltwin.php"] [unique_id "apPkWEmtdPfUFP1akVE9zgAABFY"]
[Sun Aug 30 03:05:44.129273 2026] [security2:error] [pid 495314:tid 495487] [client 158.23.147.79:63924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-admin/index.php"] [unique_id "apPkWEmtdPfUFP1akVE9zwAABFM"]
[Sun Aug 30 03:05:44.166428 2026] [authz_core:error] [pid 495314:tid 495571] [client 66.249.66.37:41548] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:44.166721 2026] [authz_core:error] [pid 495314:tid 495571] [client 66.249.66.37:41548] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:44.229251 2026] [security2:error] [pid 495314:tid 495458] [client 158.23.147.79:63930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPkWEmtdPfUFP1akVE92AAABDY"]
[Sun Aug 30 03:05:44.230727 2026] [security2:error] [pid 495314:tid 495479] [client 158.23.147.79:63276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/xmlrpc.php"] [unique_id "apPkWEmtdPfUFP1akVE92wAABEs"]
[Sun Aug 30 03:05:44.232710 2026] [security2:error] [pid 495314:tid 495562] [client 158.23.147.79:53290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-admin/about.php"] [unique_id "apPkWEmtdPfUFP1akVE93AAABJ4"]
[Sun Aug 30 03:05:44.254116 2026] [security2:error] [pid 495314:tid 495503] [client 20.48.251.3:44408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/nlnub.php"] [unique_id "apPkWEmtdPfUFP1akVE93wAABGM"]
[Sun Aug 30 03:05:44.255236 2026] [security2:error] [pid 495314:tid 495570] [client 20.104.18.15:13726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/zoo2.php"] [unique_id "apPkWEmtdPfUFP1akVE94AAABKY"]
[Sun Aug 30 03:05:44.297185 2026] [security2:error] [pid 495314:tid 495522] [client 20.63.219.114:14454] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cavendish-club.com.lodestar.media"] [uri "/c99.php"] [unique_id "apPkWEmtdPfUFP1akVE96gAABHY"]
[Sun Aug 30 03:05:44.313906 2026] [security2:error] [pid 495314:tid 495534] [client 146.70.194.236:35122] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alchemancer.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "apPkWEmtdPfUFP1akVE97gAABII"]
[Sun Aug 30 03:05:44.318208 2026] [security2:error] [pid 495314:tid 495500] [client 40.83.93.50:18064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/sql.php"] [unique_id "apPkWEmtdPfUFP1akVE97wAABGA"]
[Sun Aug 30 03:05:44.370611 2026] [security2:error] [pid 495314:tid 495515] [client 158.23.147.79:63987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/about.php"] [unique_id "apPkWEmtdPfUFP1akVE98gAABG8"]
[Sun Aug 30 03:05:44.470619 2026] [security2:error] [pid 495314:tid 495511] [client 158.23.147.79:63875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apPkWEmtdPfUFP1akVE9-AAABGs"]
[Sun Aug 30 03:05:44.487149 2026] [security2:error] [pid 495314:tid 495494] [client 158.23.147.79:53305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-content/uploads/index.php"] [unique_id "apPkWEmtdPfUFP1akVE9_gAABFo"]
[Sun Aug 30 03:05:44.496412 2026] [security2:error] [pid 495314:tid 495509] [client 68.155.159.216:63516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apPkWEmtdPfUFP1akVE-AQAABGk"]
[Sun Aug 30 03:05:44.506526 2026] [authz_core:error] [pid 495314:tid 495523] [client 66.249.66.72:57950] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:44.506826 2026] [authz_core:error] [pid 495314:tid 495523] [client 66.249.66.72:57950] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:44.512340 2026] [security2:error] [pid 495314:tid 495516] [client 74.7.243.204:34678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/new/"] [unique_id "apPkWEmtdPfUFP1akVE-CAAABHA"], referer: http://mail.letter7brands.com/new/?p=%2F%2Fetc
[Sun Aug 30 03:05:44.517114 2026] [security2:error] [pid 495314:tid 495506] [client 20.151.200.44:23583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/ls.php"] [unique_id "apPkWEmtdPfUFP1akVE-CgAABGY"]
[Sun Aug 30 03:05:44.573790 2026] [security2:error] [pid 495314:tid 495548] [client 68.155.159.216:56446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/simple.php"] [unique_id "apPkWEmtdPfUFP1akVE-DQAABJA"]
[Sun Aug 30 03:05:44.618707 2026] [security2:error] [pid 495314:tid 495479] [client 158.23.147.79:53276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apPkWEmtdPfUFP1akVE-EgAABEs"]
[Sun Aug 30 03:05:44.638637 2026] [security2:error] [pid 495314:tid 495570] [client 158.23.147.79:63885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/themes.php"] [unique_id "apPkWEmtdPfUFP1akVE-FAAABKY"]
[Sun Aug 30 03:05:44.649058 2026] [security2:error] [pid 495314:tid 495452] [client 68.155.159.216:54748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-admin/user/index.php"] [unique_id "apPkWEmtdPfUFP1akVE-FgAABDA"]
[Sun Aug 30 03:05:44.675874 2026] [security2:error] [pid 495314:tid 495546] [client 158.23.147.79:62497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wzy.php"] [unique_id "apPkWEmtdPfUFP1akVE-FwAABI4"]
[Sun Aug 30 03:05:44.686191 2026] [security2:error] [pid 495314:tid 495448] [client 146.70.194.236:35134] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alchemancer.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "apPkWEmtdPfUFP1akVE-GAAABCw"]
[Sun Aug 30 03:05:44.687184 2026] [security2:error] [pid 495314:tid 495483] [client 216.73.216.128:63200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPkWEmtdPfUFP1akVE-GQAABE8"]
[Sun Aug 30 03:05:44.733863 2026] [security2:error] [pid 495314:tid 495517] [client 20.48.251.3:51461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/classsmtps.php"] [unique_id "apPkWEmtdPfUFP1akVE-JAAABHE"]
[Sun Aug 30 03:05:44.741074 2026] [authz_core:error] [pid 495314:tid 495429] [remote 216.73.217.178:41524] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:44.741344 2026] [authz_core:error] [pid 495314:tid 495429] [remote 216.73.217.178:41524] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:44.755360 2026] [security2:error] [pid 495314:tid 495473] [client 158.23.147.79:52934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/atomlib.php"] [unique_id "apPkWEmtdPfUFP1akVE-JgAABEU"]
[Sun Aug 30 03:05:44.771811 2026] [security2:error] [pid 495314:tid 495511] [client 158.23.147.79:62305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-mail.php"] [unique_id "apPkWEmtdPfUFP1akVE-KwAABGs"]
[Sun Aug 30 03:05:44.794430 2026] [security2:error] [pid 495314:tid 495503] [client 40.83.93.50:12087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/index.bak.php"] [unique_id "apPkWEmtdPfUFP1akVE-MAAABGM"]
[Sun Aug 30 03:05:44.807701 2026] [security2:error] [pid 495314:tid 495457] [client 158.23.147.79:42062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/chosen.php"] [unique_id "apPkWEmtdPfUFP1akVE-MQAABDU"]
[Sun Aug 30 03:05:44.825943 2026] [authz_core:error] [pid 495314:tid 495468] [client 66.249.66.193:46245] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:44.826334 2026] [authz_core:error] [pid 495314:tid 495468] [client 66.249.66.193:46245] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:44.843363 2026] [security2:error] [pid 495314:tid 495535] [client 20.63.219.114:1427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/test1.php"] [unique_id "apPkWEmtdPfUFP1akVE-NQAABIM"]
[Sun Aug 30 03:05:44.873903 2026] [security2:error] [pid 495314:tid 495565] [client 158.23.147.79:63907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/cgi-bin/index.php"] [unique_id "apPkWEmtdPfUFP1akVE-NgAABKE"]
[Sun Aug 30 03:05:44.888186 2026] [security2:error] [pid 495314:tid 495484] [client 20.104.50.220:46393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/black.php"] [unique_id "apPkWEmtdPfUFP1akVE-OAAABFA"]
[Sun Aug 30 03:05:44.889992 2026] [security2:error] [pid 495314:tid 495506] [client 20.104.50.220:27558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/lock360.php"] [unique_id "apPkWEmtdPfUFP1akVE-OQAABGY"]
[Sun Aug 30 03:05:44.927473 2026] [security2:error] [pid 495314:tid 495460] [client 20.48.251.3:23346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/server_info.php"] [unique_id "apPkWEmtdPfUFP1akVE-PgAABDg"]
[Sun Aug 30 03:05:44.930073 2026] [security2:error] [pid 495314:tid 495469] [client 158.23.147.79:62542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/lv.php"] [unique_id "apPkWEmtdPfUFP1akVE-QAAABEE"]
[Sun Aug 30 03:05:44.930115 2026] [security2:error] [pid 495314:tid 495569] [client 20.104.50.220:29136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/small.php"] [unique_id "apPkWEmtdPfUFP1akVE-PwAABKU"]
[Sun Aug 30 03:05:44.934349 2026] [security2:error] [pid 495314:tid 495548] [client 158.23.147.79:42079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/goods.php"] [unique_id "apPkWEmtdPfUFP1akVE-QQAABJA"]
[Sun Aug 30 03:05:44.969790 2026] [security2:error] [pid 495314:tid 495570] [client 68.155.159.216:59906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/.well-known/content.php"] [unique_id "apPkWEmtdPfUFP1akVE-SAAABKY"]
[Sun Aug 30 03:05:44.990746 2026] [security2:error] [pid 495314:tid 495507] [client 158.23.147.79:63877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPkWEmtdPfUFP1akVE-SwAABGc"]
[Sun Aug 30 03:05:45.003591 2026] [security2:error] [pid 495314:tid 495521] [client 20.48.251.3:64390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/otuz1.php"] [unique_id "apPkWUmtdPfUFP1akVE-TgAABHU"]
[Sun Aug 30 03:05:45.027227 2026] [security2:error] [pid 495314:tid 495520] [client 20.104.50.220:31900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/themes/authentic/gud.php/themes/antioch/shell.php"] [unique_id "apPkWUmtdPfUFP1akVE-UwAABHQ"]
[Sun Aug 30 03:05:45.032943 2026] [security2:error] [pid 495314:tid 495510] [client 20.104.50.220:5444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/f35.php"] [unique_id "apPkWUmtdPfUFP1akVE-VAAABGo"]
[Sun Aug 30 03:05:45.033302 2026] [security2:error] [pid 495314:tid 495514] [client 146.70.194.236:35148] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alchemancer.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "apPkWUmtdPfUFP1akVE-VQAABG4"]
[Sun Aug 30 03:05:45.056572 2026] [security2:error] [pid 495314:tid 495498] [client 20.48.251.3:64270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/configuration.php"] [unique_id "apPkWUmtdPfUFP1akVE-WAAABF4"]
[Sun Aug 30 03:05:45.059068 2026] [security2:error] [pid 495314:tid 495539] [client 158.23.147.79:53271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apPkWUmtdPfUFP1akVE-WgAABIc"]
[Sun Aug 30 03:05:45.068368 2026] [security2:error] [pid 495314:tid 495466] [client 158.23.147.79:63258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apPkWUmtdPfUFP1akVE-XAAABD4"]
[Sun Aug 30 03:05:45.085997 2026] [security2:error] [pid 495314:tid 495535] [client 158.23.147.79:62335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-includes/content.php"] [unique_id "apPkWUmtdPfUFP1akVE-YgAABIM"]
[Sun Aug 30 03:05:45.086514 2026] [security2:error] [pid 495314:tid 495537] [client 20.48.251.3:50044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/god.php"] [unique_id "apPkWUmtdPfUFP1akVE-ZAAABIU"]
[Sun Aug 30 03:05:45.086598 2026] [security2:error] [pid 495314:tid 495477] [client 68.155.159.216:52809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/worksec.php"] [unique_id "apPkWUmtdPfUFP1akVE-ZgAABEk"]
[Sun Aug 30 03:05:45.124001 2026] [security2:error] [pid 495314:tid 495476] [client 20.104.50.220:61652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/Good.php"] [unique_id "apPkWUmtdPfUFP1akVE-bwAABEg"]
[Sun Aug 30 03:05:45.145792 2026] [security2:error] [pid 495314:tid 495479] [client 20.104.18.15:43987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/503.php"] [unique_id "apPkWUmtdPfUFP1akVE-cQAABEs"]
[Sun Aug 30 03:05:45.164125 2026] [security2:error] [pid 495314:tid 495458] [client 158.23.147.79:53300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-admin/includes/nav.php"] [unique_id "apPkWUmtdPfUFP1akVE-cwAABDY"]
[Sun Aug 30 03:05:45.191451 2026] [security2:error] [pid 495314:tid 495527] [client 158.23.147.79:63896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-admin/css/index.php"] [unique_id "apPkWUmtdPfUFP1akVE-dQAABHs"]
[Sun Aug 30 03:05:45.214955 2026] [security2:error] [pid 495314:tid 495521] [client 20.48.251.3:55725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/cu.php"] [unique_id "apPkWUmtdPfUFP1akVE-dwAABHU"]
[Sun Aug 30 03:05:45.215904 2026] [security2:error] [pid 495314:tid 495505] [client 20.104.18.15:33762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/blacks.php"] [unique_id "apPkWUmtdPfUFP1akVE-eAAABGU"]
[Sun Aug 30 03:05:45.222232 2026] [security2:error] [pid 495314:tid 495467] [client 20.63.219.114:1414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/data.php"] [unique_id "apPkWUmtdPfUFP1akVE-eQAABD8"]
[Sun Aug 30 03:05:45.242474 2026] [security2:error] [pid 495314:tid 495465] [client 158.23.147.79:63280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/content.php"] [unique_id "apPkWUmtdPfUFP1akVE-ewAABD0"]
[Sun Aug 30 03:05:45.266019 2026] [security2:error] [pid 495314:tid 495490] [client 158.23.147.79:53250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/file.php"] [unique_id "apPkWUmtdPfUFP1akVE-fwAABFY"]
[Sun Aug 30 03:05:45.274584 2026] [authz_core:error] [pid 495314:tid 495510] [client 66.249.66.193:42163] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:45.276209 2026] [security2:error] [pid 495314:tid 495445] [client 40.83.93.50:18087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/log.php"] [unique_id "apPkWUmtdPfUFP1akVE-gQAABCk"]
[Sun Aug 30 03:05:45.277097 2026] [authz_core:error] [pid 495314:tid 495510] [client 66.249.66.193:42163] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:45.291616 2026] [security2:error] [pid 495314:tid 495472] [client 20.104.50.220:51633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/manage.php"] [unique_id "apPkWUmtdPfUFP1akVE-hAAABEQ"]
[Sun Aug 30 03:05:45.299530 2026] [security2:error] [pid 495314:tid 495538] [client 158.23.147.79:63964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-admin/images/index.php"] [unique_id "apPkWUmtdPfUFP1akVE-hwAABIY"]
[Sun Aug 30 03:05:45.353393 2026] [security2:error] [pid 495314:tid 495560] [client 158.23.147.79:63247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPkWUmtdPfUFP1akVE-kwAABJw"]
[Sun Aug 30 03:05:45.386056 2026] [security2:error] [pid 495314:tid 495476] [client 146.70.194.236:35160] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alchemancer.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "apPkWUmtdPfUFP1akVE-nQAABEg"]
[Sun Aug 30 03:05:45.386286 2026] [security2:error] [pid 495314:tid 495469] [client 20.151.200.44:47067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/pb.php"] [unique_id "apPkWUmtdPfUFP1akVE-nAAABEE"]
[Sun Aug 30 03:05:45.400260 2026] [security2:error] [pid 495314:tid 495493] [client 158.23.147.79:62304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-includes/index.php"] [unique_id "apPkWUmtdPfUFP1akVE-oAAABFk"]
[Sun Aug 30 03:05:45.405891 2026] [security2:error] [pid 495314:tid 495512] [client 158.23.147.79:53279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/file17.php"] [unique_id "apPkWUmtdPfUFP1akVE-ogAABGw"]
[Sun Aug 30 03:05:45.477762 2026] [authz_core:error] [pid 495314:tid 495445] [client 66.249.66.44:52158] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:45.478109 2026] [authz_core:error] [pid 495314:tid 495445] [client 66.249.66.44:52158] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:45.488251 2026] [security2:error] [pid 495314:tid 495509] [client 20.104.18.15:13708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/zoo1.php"] [unique_id "apPkWUmtdPfUFP1akVE-tgAABGk"]
[Sun Aug 30 03:05:45.538186 2026] [security2:error] [pid 495314:tid 495540] [client 158.23.147.79:62308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/mah.php"] [unique_id "apPkWUmtdPfUFP1akVE-wQAABIg"]
[Sun Aug 30 03:05:45.545148 2026] [security2:error] [pid 495314:tid 495504] [client 20.48.251.3:44414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/mga.php"] [unique_id "apPkWUmtdPfUFP1akVE-xAAABGQ"]
[Sun Aug 30 03:05:45.554436 2026] [security2:error] [pid 495314:tid 495567] [client 20.104.50.220:33161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/DA.php"] [unique_id "apPkWUmtdPfUFP1akVE-xgAABKM"]
[Sun Aug 30 03:05:45.605394 2026] [security2:error] [pid 495314:tid 495474] [client 158.23.147.79:63293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/goat.php"] [unique_id "apPkWUmtdPfUFP1akVE-yQAABEY"]
[Sun Aug 30 03:05:45.612061 2026] [authz_core:error] [pid 495314:tid 495547] [client 216.73.216.128:18243] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:45.612355 2026] [authz_core:error] [pid 495314:tid 495547] [client 216.73.216.128:18243] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:45.647679 2026] [security2:error] [pid 495314:tid 495461] [client 20.63.219.114:14459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/classwithtostring.php"] [unique_id "apPkWUmtdPfUFP1akVE-zwAABDk"]
[Sun Aug 30 03:05:45.658487 2026] [security2:error] [pid 495314:tid 495553] [client 158.23.147.79:63967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-blog-header.php"] [unique_id "apPkWUmtdPfUFP1akVE-0QAABJU"]
[Sun Aug 30 03:05:45.682285 2026] [security2:error] [pid 495314:tid 495452] [client 68.155.159.216:56348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-admin/about.php"] [unique_id "apPkWUmtdPfUFP1akVE-1QAABDA"]
[Sun Aug 30 03:05:45.687492 2026] [security2:error] [pid 495314:tid 495556] [client 158.23.147.79:42078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/file5.php"] [unique_id "apPkWUmtdPfUFP1akVE-1wAABJg"]
[Sun Aug 30 03:05:45.706868 2026] [security2:error] [pid 495314:tid 495467] [client 158.23.147.79:62530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apPkWUmtdPfUFP1akVE-3QAABD8"]
[Sun Aug 30 03:05:45.758485 2026] [security2:error] [pid 495314:tid 495472] [client 146.70.194.236:35170] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alchemancer.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "apPkWUmtdPfUFP1akVE-4wAABEQ"]
[Sun Aug 30 03:05:45.775431 2026] [security2:error] [pid 495314:tid 495545] [client 40.83.93.50:18078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/bak.php"] [unique_id "apPkWUmtdPfUFP1akVE-5gAABI0"]
[Sun Aug 30 03:05:45.784074 2026] [security2:error] [pid 495314:tid 495561] [client 158.23.147.79:62332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apPkWUmtdPfUFP1akVE-6AAABJ0"]
[Sun Aug 30 03:05:45.810026 2026] [security2:error] [pid 495314:tid 495464] [client 68.155.159.216:52620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-includes/plugins.php"] [unique_id "apPkWUmtdPfUFP1akVE-7AAABDw"]
[Sun Aug 30 03:05:45.817119 2026] [security2:error] [pid 495314:tid 495498] [client 68.155.159.216:63496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-admin/includes/nav.php"] [unique_id "apPkWUmtdPfUFP1akVE-7gAABF4"]
[Sun Aug 30 03:05:45.857980 2026] [security2:error] [pid 495314:tid 495485] [client 68.155.159.216:65501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkWUmtdPfUFP1akVE-8QAABFE"]
[Sun Aug 30 03:05:45.898750 2026] [security2:error] [pid 495314:tid 495518] [client 158.23.147.79:42075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/file88.php"] [unique_id "apPkWUmtdPfUFP1akVE-9gAABHI"]
[Sun Aug 30 03:05:45.912569 2026] [security2:error] [pid 495314:tid 495488] [client 158.23.147.79:62284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-admin/user/index.php"] [unique_id "apPkWUmtdPfUFP1akVE--gAABFQ"]
[Sun Aug 30 03:05:45.921300 2026] [authz_core:error] [pid 495314:tid 495470] [client 66.249.66.69:56392] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:45.921556 2026] [authz_core:error] [pid 495314:tid 495470] [client 66.249.66.69:56392] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:45.947773 2026] [security2:error] [pid 495314:tid 495568] [client 20.48.251.3:22238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/cache-compat.php"] [unique_id "apPkWUmtdPfUFP1akVE-_AAABKQ"]
[Sun Aug 30 03:05:45.956423 2026] [security2:error] [pid 495314:tid 495481] [client 68.155.159.216:63980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apPkWUmtdPfUFP1akVE-_QAABE0"]
[Sun Aug 30 03:05:45.984569 2026] [security2:error] [pid 495314:tid 495474] [client 20.48.160.90:26720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/eagle.php"] [unique_id "apPkWUmtdPfUFP1akVE_AgAABEY"]
[Sun Aug 30 03:05:46.021977 2026] [security2:error] [pid 495314:tid 495532] [client 20.104.50.220:46647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/by.php"] [unique_id "apPkWkmtdPfUFP1akVE_DQAABIA"]
[Sun Aug 30 03:05:46.027709 2026] [security2:error] [pid 495314:tid 495569] [client 20.104.50.220:27423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/giodywky.php"] [unique_id "apPkWkmtdPfUFP1akVE_EAAABKU"]
[Sun Aug 30 03:05:46.036490 2026] [security2:error] [pid 495314:tid 495558] [client 158.23.147.79:4033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/NewFile.php/"] [unique_id "apPkWkmtdPfUFP1akVE_EQAABJo"]
[Sun Aug 30 03:05:46.051136 2026] [security2:error] [pid 495314:tid 495517] [client 158.23.147.79:63975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-includes/plugins.php"] [unique_id "apPkWkmtdPfUFP1akVE_EgAABHE"]
[Sun Aug 30 03:05:46.052096 2026] [security2:error] [pid 495314:tid 495526] [client 20.48.160.90:40027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/tqkdqbbv.php"] [unique_id "apPkWkmtdPfUFP1akVE_EwAABHo"]
[Sun Aug 30 03:05:46.068474 2026] [security2:error] [pid 495314:tid 495486] [client 20.104.50.220:29629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/style-js.php"] [unique_id "apPkWkmtdPfUFP1akVE_FQAABFI"]
[Sun Aug 30 03:05:46.072228 2026] [security2:error] [pid 495314:tid 495459] [client 20.48.251.3:23344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/hosty.php"] [unique_id "apPkWkmtdPfUFP1akVE_FgAABDc"]
[Sun Aug 30 03:05:46.085585 2026] [security2:error] [pid 495314:tid 495473] [client 158.23.147.79:52928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apPkWkmtdPfUFP1akVE_GQAABEU"]
[Sun Aug 30 03:05:46.097526 2026] [security2:error] [pid 495314:tid 495456] [client 158.23.147.79:62549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apPkWkmtdPfUFP1akVE_HQAABDQ"]
[Sun Aug 30 03:05:46.115039 2026] [security2:error] [pid 495314:tid 495480] [client 20.48.160.90:50636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/indo.php"] [unique_id "apPkWkmtdPfUFP1akVE_JAAABEw"]
[Sun Aug 30 03:05:46.121160 2026] [security2:error] [pid 495314:tid 495485] [client 68.155.159.216:54030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/cong.php"] [unique_id "apPkWkmtdPfUFP1akVE_JgAABFE"]
[Sun Aug 30 03:05:46.134770 2026] [security2:error] [pid 495314:tid 495563] [client 20.48.160.90:45880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/up-kon.php"] [unique_id "apPkWkmtdPfUFP1akVE_KgAABJ8"]
[Sun Aug 30 03:05:46.142759 2026] [security2:error] [pid 495314:tid 495551] [client 20.48.251.3:45841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/update.php"] [unique_id "apPkWkmtdPfUFP1akVE_KwAABJM"]
[Sun Aug 30 03:05:46.149820 2026] [security2:error] [pid 495314:tid 495542] [client 158.23.147.79:4090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/dropdown.php"] [unique_id "apPkWkmtdPfUFP1akVE_LAAABIo"]
[Sun Aug 30 03:05:46.175185 2026] [security2:error] [pid 495314:tid 495474] [client 20.104.50.220:31874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/and.php"] [unique_id "apPkWkmtdPfUFP1akVE_MgAABEY"]
[Sun Aug 30 03:05:46.180305 2026] [security2:error] [pid 495314:tid 495493] [client 20.104.50.220:5566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/ioxi-o1.php"] [unique_id "apPkWkmtdPfUFP1akVE_MwAABFk"]
[Sun Aug 30 03:05:46.196561 2026] [security2:error] [pid 495314:tid 495510] [client 20.48.160.90:39942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/kjyehoxl.php"] [unique_id "apPkWkmtdPfUFP1akVE_NQAABGo"]
[Sun Aug 30 03:05:46.220901 2026] [security2:error] [pid 495314:tid 495457] [client 158.23.147.79:63941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apPkWkmtdPfUFP1akVE_NgAABDU"]
[Sun Aug 30 03:05:46.223429 2026] [security2:error] [pid 495314:tid 495569] [client 20.48.251.3:54830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/server_info.php"] [unique_id "apPkWkmtdPfUFP1akVE_NwAABKU"]
[Sun Aug 30 03:05:46.224170 2026] [security2:error] [pid 495314:tid 495506] [client 20.104.50.220:29583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-login.php"] [unique_id "apPkWkmtdPfUFP1akVE_MAAABGY"]
[Sun Aug 30 03:05:46.231227 2026] [security2:error] [pid 495314:tid 495512] [client 20.48.251.3:55457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/fff.php"] [unique_id "apPkWkmtdPfUFP1akVE_OQAABGw"]
[Sun Aug 30 03:05:46.252201 2026] [security2:error] [pid 495314:tid 495479] [client 20.63.219.114:1453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/en.php"] [unique_id "apPkWkmtdPfUFP1akVE_PQAABEs"]
[Sun Aug 30 03:05:46.259222 2026] [security2:error] [pid 495314:tid 495486] [client 158.23.147.79:42082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/.well-known/index.php"] [unique_id "apPkWkmtdPfUFP1akVE_QAAABFI"]
[Sun Aug 30 03:05:46.271792 2026] [security2:error] [pid 495314:tid 495472] [client 20.48.160.90:40053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/tinny.php"] [unique_id "apPkWkmtdPfUFP1akVE_RQAABEQ"]
[Sun Aug 30 03:05:46.277576 2026] [security2:error] [pid 495314:tid 495466] [client 68.155.159.216:52806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/x.php"] [unique_id "apPkWkmtdPfUFP1akVE_SAAABD4"]
[Sun Aug 30 03:05:46.301422 2026] [security2:error] [pid 495314:tid 495540] [client 20.104.18.15:44022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/504.php"] [unique_id "apPkWkmtdPfUFP1akVE_TgAABIg"]
[Sun Aug 30 03:05:46.303220 2026] [security2:error] [pid 495314:tid 495455] [client 20.48.160.90:50636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/sign.php"] [unique_id "apPkWkmtdPfUFP1akVE_UAAABDM"]
[Sun Aug 30 03:05:46.320815 2026] [security2:error] [pid 495314:tid 495519] [client 40.83.93.50:12076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/pages.php"] [unique_id "apPkWkmtdPfUFP1akVE_UwAABHM"]
[Sun Aug 30 03:05:46.344804 2026] [security2:error] [pid 495314:tid 495483] [client 158.23.147.79:62554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apPkWkmtdPfUFP1akVE_WQAABE8"]
[Sun Aug 30 03:05:46.345658 2026] [security2:error] [pid 495314:tid 495481] [client 20.48.160.90:26624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/llyuxaqd.php"] [unique_id "apPkWkmtdPfUFP1akVE_WgAABE0"]
[Sun Aug 30 03:05:46.348467 2026] [authz_core:error] [pid 495314:tid 495498] [client 66.249.66.68:64502] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:46.348975 2026] [authz_core:error] [pid 495314:tid 495498] [client 66.249.66.68:64502] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:46.350068 2026] [security2:error] [pid 495314:tid 495474] [client 20.48.251.3:55702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/services.php"] [unique_id "apPkWkmtdPfUFP1akVE_XQAABEY"]
[Sun Aug 30 03:05:46.378564 2026] [security2:error] [pid 495314:tid 495476] [client 158.23.147.79:62305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/goat1.php"] [unique_id "apPkWkmtdPfUFP1akVE_XgAABEg"]
[Sun Aug 30 03:05:46.381217 2026] [security2:error] [pid 495314:tid 495541] [client 158.23.147.79:53260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-content/themes/too.php"] [unique_id "apPkWkmtdPfUFP1akVE_XwAABIk"]
[Sun Aug 30 03:05:46.384533 2026] [security2:error] [pid 495314:tid 495532] [client 20.104.18.15:33604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/beck.php"] [unique_id "apPkWkmtdPfUFP1akVE_YAAABIA"]
[Sun Aug 30 03:05:46.405395 2026] [security2:error] [pid 495314:tid 495458] [client 20.48.160.90:40009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp-easy.php"] [unique_id "apPkWkmtdPfUFP1akVE_YwAABDY"]
[Sun Aug 30 03:05:46.439637 2026] [security2:error] [pid 495314:tid 495558] [client 20.104.50.220:51600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/mforh.php"] [unique_id "apPkWkmtdPfUFP1akVE_agAABJo"]
[Sun Aug 30 03:05:46.443318 2026] [authz_core:error] [pid 495314:tid 495546] [client 216.73.216.128:35966] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:46.443779 2026] [authz_core:error] [pid 495314:tid 495546] [client 216.73.216.128:35966] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:46.450689 2026] [security2:error] [pid 495314:tid 495505] [client 20.48.160.90:33223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/wnnjpsby.php"] [unique_id "apPkWkmtdPfUFP1akVE_awAABGU"]
[Sun Aug 30 03:05:46.483923 2026] [security2:error] [pid 495314:tid 495561] [client 158.23.147.79:42073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/radio.php"] [unique_id "apPkWkmtdPfUFP1akVE_cQAABJ0"]
[Sun Aug 30 03:05:46.489522 2026] [security2:error] [pid 495314:tid 495451] [client 20.48.160.90:40005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/nbwxolou.php"] [unique_id "apPkWkmtdPfUFP1akVE_dQAABC8"]
[Sun Aug 30 03:05:46.526053 2026] [security2:error] [pid 495314:tid 495536] [client 158.23.147.79:63981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apPkWkmtdPfUFP1akVE_gQAABIQ"]
[Sun Aug 30 03:05:46.533588 2026] [security2:error] [pid 495314:tid 495515] [client 158.23.147.79:52875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apPkWkmtdPfUFP1akVE_ggAABG8"]
[Sun Aug 30 03:05:46.538765 2026] [security2:error] [pid 495314:tid 495567] [client 20.48.160.90:39995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/d7.php"] [unique_id "apPkWkmtdPfUFP1akVE_hAAABKM"]
[Sun Aug 30 03:05:46.591226 2026] [security2:error] [pid 495314:tid 495467] [client 158.23.147.79:53306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPkWkmtdPfUFP1akVE_iAAABD8"]
[Sun Aug 30 03:05:46.624784 2026] [security2:error] [pid 495314:tid 495448] [client 158.23.147.79:63983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-admin/network/index.php"] [unique_id "apPkWkmtdPfUFP1akVE_jgAABCw"]
[Sun Aug 30 03:05:46.630300 2026] [security2:error] [pid 495314:tid 495539] [client 20.48.160.90:45829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/nsxeubyv.php"] [unique_id "apPkWkmtdPfUFP1akVE_kAAABIc"]
[Sun Aug 30 03:05:46.643527 2026] [security2:error] [pid 495314:tid 495513] [client 20.63.219.114:1420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/13.php"] [unique_id "apPkWkmtdPfUFP1akVE_kQAABG0"]
[Sun Aug 30 03:05:46.647792 2026] [security2:error] [pid 495314:tid 495461] [client 20.48.160.90:33246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/gigi.php"] [unique_id "apPkWkmtdPfUFP1akVE_kgAABDk"]
[Sun Aug 30 03:05:46.677662 2026] [security2:error] [pid 495314:tid 495556] [client 20.48.160.90:26708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/v5.php"] [unique_id "apPkWkmtdPfUFP1akVE_kwAABJg"]
[Sun Aug 30 03:05:46.694749 2026] [security2:error] [pid 495314:tid 495554] [client 20.104.50.220:33063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/bismilah.php"] [unique_id "apPkWkmtdPfUFP1akVE_lQAABJY"]
[Sun Aug 30 03:05:46.708624 2026] [security2:error] [pid 495314:tid 495479] [client 216.73.216.128:35966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPkWkmtdPfUFP1akVE_lgAABEs"]
[Sun Aug 30 03:05:46.717166 2026] [security2:error] [pid 495314:tid 495553] [client 20.104.18.15:13640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/radio.php"] [unique_id "apPkWkmtdPfUFP1akVE_lwAABJU"]
[Sun Aug 30 03:05:46.731815 2026] [security2:error] [pid 495314:tid 495459] [client 20.48.251.3:44291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/ccou.php"] [unique_id "apPkWkmtdPfUFP1akVE_mQAABDc"]
[Sun Aug 30 03:05:46.732763 2026] [security2:error] [pid 495314:tid 495549] [client 158.23.147.79:62324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apPkWkmtdPfUFP1akVE_mgAABJE"]
[Sun Aug 30 03:05:46.764736 2026] [security2:error] [pid 495314:tid 495564] [client 20.48.160.90:45916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/zfqipfss.php"] [unique_id "apPkWkmtdPfUFP1akVE_nwAABKA"]
[Sun Aug 30 03:05:46.767344 2026] [authz_core:error] [pid 495314:tid 495505] [client 66.249.66.70:59406] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:46.767603 2026] [authz_core:error] [pid 495314:tid 495505] [client 66.249.66.70:59406] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:46.772181 2026] [security2:error] [pid 495314:tid 495477] [client 158.23.147.79:62500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/dropdown.php"] [unique_id "apPkWkmtdPfUFP1akVE_oAAABEk"]
[Sun Aug 30 03:05:46.775543 2026] [security2:error] [pid 495314:tid 495490] [client 20.48.160.90:50634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/info.php/new.php"] [unique_id "apPkWkmtdPfUFP1akVE_oQAABFY"]
[Sun Aug 30 03:05:46.817103 2026] [authz_core:error] [pid 495314:tid 495472] [client 216.73.216.128:15344] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:46.817574 2026] [authz_core:error] [pid 495314:tid 495472] [client 216.73.216.128:15344] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:46.825556 2026] [security2:error] [pid 495314:tid 495520] [client 158.23.147.79:42072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/makeasmtp.php"] [unique_id "apPkWkmtdPfUFP1akVE_qQAABHQ"]
[Sun Aug 30 03:05:46.826311 2026] [security2:error] [pid 495314:tid 495510] [client 40.83.93.50:8710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/albin.php"] [unique_id "apPkWkmtdPfUFP1akVE_qgAABGo"]
[Sun Aug 30 03:05:46.851560 2026] [security2:error] [pid 495314:tid 495533] [client 68.155.159.216:56444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apPkWkmtdPfUFP1akVE_rgAABIE"]
[Sun Aug 30 03:05:46.852552 2026] [security2:error] [pid 495314:tid 495519] [client 20.48.160.90:26725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/az.php"] [unique_id "apPkWkmtdPfUFP1akVE_rwAABHM"]
[Sun Aug 30 03:05:46.854546 2026] [security2:error] [pid 495314:tid 495540] [client 158.23.147.79:32768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/.well-knownold/index.php"] [unique_id "apPkWkmtdPfUFP1akVE_sAAABIg"]
[Sun Aug 30 03:05:46.889114 2026] [security2:error] [pid 495314:tid 495516] [client 20.104.50.220:61421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/pas.php"] [unique_id "apPkWkmtdPfUFP1akVE_sQAABHA"]
[Sun Aug 30 03:05:46.923547 2026] [security2:error] [pid 495314:tid 495476] [client 20.48.160.90:26734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sygnius.com.pa"] [uri "/zrjuyoos.php"] [unique_id "apPkWkmtdPfUFP1akVE_twAABEg"]
[Sun Aug 30 03:05:46.953584 2026] [security2:error] [pid 495314:tid 495506] [client 158.23.147.79:62288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apPkWkmtdPfUFP1akVE_uQAABGY"]
[Sun Aug 30 03:05:46.953920 2026] [security2:error] [pid 495314:tid 495470] [client 158.23.147.79:54258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkWkmtdPfUFP1akVE_ugAABEI"]
[Sun Aug 30 03:05:46.961375 2026] [security2:error] [pid 495314:tid 495513] [client 158.23.147.79:63263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/sad/about.php"] [unique_id "apPkWkmtdPfUFP1akVE_vAAABG0"]
[Sun Aug 30 03:05:46.999103 2026] [security2:error] [pid 495314:tid 495468] [client 20.63.219.114:9605] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cavendish-club.com.lodestar.media"] [uri "/1.php"] [unique_id "apPkWkmtdPfUFP1akVE_wgAABEA"]
[Sun Aug 30 03:05:46.999197 2026] [security2:error] [pid 495314:tid 495468] [client 20.63.219.114:9605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/1.php"] [unique_id "apPkWkmtdPfUFP1akVE_wgAABEA"]
[Sun Aug 30 03:05:47.000120 2026] [security2:error] [pid 495314:tid 495454] [client 20.48.160.90:33188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apPkWkmtdPfUFP1akVE_wwAABDI"]
[Sun Aug 30 03:05:47.003394 2026] [authz_core:error] [pid 495314:tid 495535] [client 216.73.216.128:6506] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:47.003834 2026] [authz_core:error] [pid 495314:tid 495535] [client 216.73.216.128:6506] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:47.008195 2026] [security2:error] [pid 495314:tid 495452] [client 20.151.200.44:46978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/pk.php"] [unique_id "apPkW0mtdPfUFP1akVE_xgAABDA"]
[Sun Aug 30 03:05:47.025666 2026] [security2:error] [pid 495314:tid 495511] [client 68.155.159.216:54756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apPkW0mtdPfUFP1akVE_zQAABGs"]
[Sun Aug 30 03:05:47.028340 2026] [security2:error] [pid 495314:tid 495562] [client 20.48.160.90:45841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/js.php"] [unique_id "apPkW0mtdPfUFP1akVE_zgAABJ4"]
[Sun Aug 30 03:05:47.062006 2026] [security2:error] [pid 495314:tid 495466] [client 68.155.159.216:65488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkW0mtdPfUFP1akVE_0QAABD4"]
[Sun Aug 30 03:05:47.063667 2026] [security2:error] [pid 495314:tid 495564] [client 158.23.147.79:42051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apPkW0mtdPfUFP1akVE_0gAABKA"]
[Sun Aug 30 03:05:47.069894 2026] [security2:error] [pid 495314:tid 495460] [client 68.155.159.216:63526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/file.php"] [unique_id "apPkW0mtdPfUFP1akVE_1AAABDg"]
[Sun Aug 30 03:05:47.078583 2026] [security2:error] [pid 495314:tid 495523] [client 68.155.159.216:61345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apPkW0mtdPfUFP1akVE_2AAABHc"]
[Sun Aug 30 03:05:47.079551 2026] [security2:error] [pid 495314:tid 495523] [client 158.23.147.79:63956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPkW0mtdPfUFP1akVE_2QAABHc"]
[Sun Aug 30 03:05:47.132208 2026] [security2:error] [pid 495314:tid 495444] [client 20.48.251.3:59114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/aws_keys.php"] [unique_id "apPkW0mtdPfUFP1akVE_5wAABCg"]
[Sun Aug 30 03:05:47.136680 2026] [security2:error] [pid 495314:tid 495485] [client 20.48.160.90:50685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/w.php"] [unique_id "apPkW0mtdPfUFP1akVE_6QAABFE"]
[Sun Aug 30 03:05:47.161595 2026] [security2:error] [pid 495314:tid 495558] [client 20.104.50.220:46173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/byp.php"] [unique_id "apPkW0mtdPfUFP1akVE_6wAABJo"]
[Sun Aug 30 03:05:47.165364 2026] [security2:error] [pid 495314:tid 495492] [client 20.104.50.220:27411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/images/images/cache.php"] [unique_id "apPkW0mtdPfUFP1akVE_7QAABFg"]
[Sun Aug 30 03:05:47.166815 2026] [security2:error] [pid 495314:tid 495461] [client 20.48.160.90:40030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/hd.php"] [unique_id "apPkW0mtdPfUFP1akVE_7gAABDk"]
[Sun Aug 30 03:05:47.170823 2026] [security2:error] [pid 495314:tid 495472] [client 158.23.147.79:53294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apPkW0mtdPfUFP1akVE_7wAABEQ"]
[Sun Aug 30 03:05:47.202216 2026] [security2:error] [pid 495314:tid 495483] [client 20.104.50.220:52851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/style.php"] [unique_id "apPkW0mtdPfUFP1akVE_8QAABE8"]
[Sun Aug 30 03:05:47.203941 2026] [security2:error] [pid 495314:tid 495566] [client 158.23.147.79:54245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkW0mtdPfUFP1akVE_8gAABKI"]
[Sun Aug 30 03:05:47.215931 2026] [security2:error] [pid 495314:tid 495554] [client 158.23.147.79:63277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apPkW0mtdPfUFP1akVE_9AAABJY"]
[Sun Aug 30 03:05:47.219592 2026] [security2:error] [pid 495314:tid 495544] [client 158.23.147.79:62540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/admin.php"] [unique_id "apPkW0mtdPfUFP1akVE_9QAABIw"]
[Sun Aug 30 03:05:47.229541 2026] [security2:error] [pid 495314:tid 495456] [client 158.23.147.79:63889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/images/index.php"] [unique_id "apPkW0mtdPfUFP1akVE_-AAABDQ"]
[Sun Aug 30 03:05:47.243710 2026] [security2:error] [pid 495314:tid 495509] [client 68.155.159.216:59912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-includes/js/index.php"] [unique_id "apPkW0mtdPfUFP1akVE__QAABGk"]
[Sun Aug 30 03:05:47.250706 2026] [security2:error] [pid 495314:tid 495477] [client 20.48.251.3:23426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/pass4.php"] [unique_id "apPkW0mtdPfUFP1akVE__wAABEk"]
[Sun Aug 30 03:05:47.266983 2026] [security2:error] [pid 495314:tid 495542] [client 20.151.200.44:37879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/wp-content/admin.php"] [unique_id "apPkW0mtdPfUFP1akVFABQAABIo"]
[Sun Aug 30 03:05:47.267514 2026] [security2:error] [pid 495314:tid 495548] [client 20.48.160.90:50597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/x.php"] [unique_id "apPkW0mtdPfUFP1akVFABwAABJA"]
[Sun Aug 30 03:05:47.274799 2026] [security2:error] [pid 495314:tid 495464] [client 158.23.147.79:53285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-content/languages/about.php"] [unique_id "apPkW0mtdPfUFP1akVFADAAABDw"]
[Sun Aug 30 03:05:47.294174 2026] [security2:error] [pid 495314:tid 495531] [client 20.48.160.90:40026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/xl2023.php"] [unique_id "apPkW0mtdPfUFP1akVFAEQAABH8"]
[Sun Aug 30 03:05:47.301733 2026] [security2:error] [pid 495314:tid 495470] [client 40.83.93.50:18066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/an.php"] [unique_id "apPkW0mtdPfUFP1akVFAEwAABEI"]
[Sun Aug 30 03:05:47.310129 2026] [security2:error] [pid 495314:tid 495493] [client 20.48.251.3:64385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/channels.php"] [unique_id "apPkW0mtdPfUFP1akVFAFgAABFk"]
[Sun Aug 30 03:05:47.312448 2026] [security2:error] [pid 495314:tid 495481] [client 20.104.50.220:31827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/skizoo.php"] [unique_id "apPkW0mtdPfUFP1akVFAFwAABE0"]
[Sun Aug 30 03:05:47.317478 2026] [authz_core:error] [pid 495314:tid 495569] [client 66.249.66.34:44843] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:47.318032 2026] [authz_core:error] [pid 495314:tid 495569] [client 66.249.66.34:44843] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:47.333802 2026] [security2:error] [pid 495314:tid 495476] [client 158.23.147.79:63289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-admin/admin.php"] [unique_id "apPkW0mtdPfUFP1akVFAGAAABEg"]
[Sun Aug 30 03:05:47.340387 2026] [security2:error] [pid 495314:tid 495512] [client 20.104.50.220:5892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/juuuu.php"] [unique_id "apPkW0mtdPfUFP1akVFAGgAABGw"]
[Sun Aug 30 03:05:47.364620 2026] [security2:error] [pid 495314:tid 495492] [client 158.23.147.79:63984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apPkW0mtdPfUFP1akVFAHQAABFg"]
[Sun Aug 30 03:05:47.376017 2026] [security2:error] [pid 495314:tid 495553] [client 20.104.50.220:29153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/01.php"] [unique_id "apPkW0mtdPfUFP1akVFAHgAABJU"]
[Sun Aug 30 03:05:47.383849 2026] [security2:error] [pid 495314:tid 495468] [client 20.48.251.3:46217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/hosty.php"] [unique_id "apPkW0mtdPfUFP1akVFAHwAABEA"]
[Sun Aug 30 03:05:47.403985 2026] [security2:error] [pid 495314:tid 495503] [client 158.23.147.79:54218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apPkW0mtdPfUFP1akVFAIQAABGM"]
[Sun Aug 30 03:05:47.417707 2026] [security2:error] [pid 495314:tid 495566] [client 20.48.251.3:55534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/autogooey.php"] [unique_id "apPkW0mtdPfUFP1akVFAJAAABKI"]
[Sun Aug 30 03:05:47.423828 2026] [security2:error] [pid 495314:tid 495473] [client 20.48.160.90:39957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/V2.php"] [unique_id "apPkW0mtdPfUFP1akVFAJQAABEU"]
[Sun Aug 30 03:05:47.438332 2026] [security2:error] [pid 495314:tid 495544] [client 20.48.160.90:33182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/ssla.php"] [unique_id "apPkW0mtdPfUFP1akVFAJwAABIw"]
[Sun Aug 30 03:05:47.461889 2026] [security2:error] [pid 495314:tid 495469] [client 20.104.18.15:43998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/admin.php"] [unique_id "apPkW0mtdPfUFP1akVFAKQAABEE"]
[Sun Aug 30 03:05:47.488085 2026] [security2:error] [pid 495314:tid 495536] [client 20.48.251.3:52812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/filesystems.php"] [unique_id "apPkW0mtdPfUFP1akVFALgAABIQ"]
[Sun Aug 30 03:05:47.488509 2026] [security2:error] [pid 495314:tid 495465] [client 158.23.147.79:53301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-content/banners/about.php"] [unique_id "apPkW0mtdPfUFP1akVFAMAAABD0"]
[Sun Aug 30 03:05:47.504604 2026] [authz_core:error] [pid 495314:tid 495464] [client 66.249.66.205:59810] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:47.504903 2026] [authz_core:error] [pid 495314:tid 495464] [client 66.249.66.205:59810] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:47.515198 2026] [security2:error] [pid 495314:tid 495447] [client 20.63.219.114:1469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/as.php"] [unique_id "apPkW0mtdPfUFP1akVFANwAABCs"]
[Sun Aug 30 03:05:47.532546 2026] [security2:error] [pid 495314:tid 495466] [client 158.23.147.79:54222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-content/plugins/index.php"] [unique_id "apPkW0mtdPfUFP1akVFAQAAABD4"]
[Sun Aug 30 03:05:47.534329 2026] [security2:error] [pid 495314:tid 495508] [client 20.104.18.15:33003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/t3.php"] [unique_id "apPkW0mtdPfUFP1akVFAQQAABGg"]
[Sun Aug 30 03:05:47.545370 2026] [security2:error] [pid 495314:tid 495444] [client 158.23.147.79:63960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apPkW0mtdPfUFP1akVFARQAABCg"]
[Sun Aug 30 03:05:47.565533 2026] [security2:error] [pid 495314:tid 495463] [client 20.48.160.90:45829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/mad.php"] [unique_id "apPkW0mtdPfUFP1akVFARwAABDs"]
[Sun Aug 30 03:05:47.582296 2026] [security2:error] [pid 495314:tid 495462] [client 20.48.160.90:33200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apPkW0mtdPfUFP1akVFASgAABDo"]
[Sun Aug 30 03:05:47.591571 2026] [security2:error] [pid 495314:tid 495461] [client 158.23.147.79:62572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apPkW0mtdPfUFP1akVFATAAABDk"]
[Sun Aug 30 03:05:47.617940 2026] [security2:error] [pid 495314:tid 495506] [client 158.23.147.79:52936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apPkW0mtdPfUFP1akVFAUAAABGY"]
[Sun Aug 30 03:05:47.624271 2026] [security2:error] [pid 495314:tid 495452] [client 20.151.200.44:47318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/Contrller.php"] [unique_id "apPkW0mtdPfUFP1akVFAUQAABDA"]
[Sun Aug 30 03:05:47.641923 2026] [security2:error] [pid 495314:tid 495478] [client 158.23.147.79:54239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/simple.php"] [unique_id "apPkW0mtdPfUFP1akVFAVAAABEo"]
[Sun Aug 30 03:05:47.657862 2026] [security2:error] [pid 495314:tid 495544] [client 158.23.147.79:4070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-includes/Text/about.php"] [unique_id "apPkW0mtdPfUFP1akVFAVQAABIw"]
[Sun Aug 30 03:05:47.663974 2026] [security2:error] [pid 495314:tid 495505] [client 68.155.159.216:60571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-content/x.php"] [unique_id "apPkW0mtdPfUFP1akVFAVgAABGU"]
[Sun Aug 30 03:05:47.672179 2026] [security2:error] [pid 495314:tid 495511] [client 158.23.147.79:62302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apPkW0mtdPfUFP1akVFAVwAABGs"]
[Sun Aug 30 03:05:47.686385 2026] [security2:error] [pid 495314:tid 495563] [client 20.104.50.220:51646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/mygagal.php"] [unique_id "apPkW0mtdPfUFP1akVFAWAAABJ8"]
[Sun Aug 30 03:05:47.700011 2026] [security2:error] [pid 495314:tid 495460] [client 20.48.160.90:40035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/st.php"] [unique_id "apPkW0mtdPfUFP1akVFAWQAABDg"]
[Sun Aug 30 03:05:47.716334 2026] [security2:error] [pid 495314:tid 495536] [client 20.48.160.90:33253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/wp-aothait.php"] [unique_id "apPkW0mtdPfUFP1akVFAWgAABIQ"]
[Sun Aug 30 03:05:47.727574 2026] [security2:error] [pid 495314:tid 495532] [client 158.23.147.79:62584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/classwithtostring.php"] [unique_id "apPkW0mtdPfUFP1akVFAXQAABIA"]
[Sun Aug 30 03:05:47.739139 2026] [security2:error] [pid 495314:tid 495555] [client 158.23.147.79:54217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-admin/about.php"] [unique_id "apPkW0mtdPfUFP1akVFAXwAABJc"]
[Sun Aug 30 03:05:47.771224 2026] [security2:error] [pid 495314:tid 495454] [client 40.83.93.50:9148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/mini.php"] [unique_id "apPkW0mtdPfUFP1akVFAYgAABDI"]
[Sun Aug 30 03:05:47.833165 2026] [security2:error] [pid 495314:tid 495521] [client 20.104.50.220:33196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/.dha.php"] [unique_id "apPkW0mtdPfUFP1akVFAawAABHU"]
[Sun Aug 30 03:05:47.839413 2026] [security2:error] [pid 495314:tid 495493] [client 20.48.160.90:26631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/alfanew.php"] [unique_id "apPkW0mtdPfUFP1akVFAbAAABFk"]
[Sun Aug 30 03:05:47.861299 2026] [security2:error] [pid 495314:tid 495534] [client 20.104.18.15:13642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/one.php"] [unique_id "apPkW0mtdPfUFP1akVFAcwAABII"]
[Sun Aug 30 03:05:47.888977 2026] [security2:error] [pid 495314:tid 495470] [client 20.48.160.90:33162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/wp-includes/index.php"] [unique_id "apPkW0mtdPfUFP1akVFAdwAABEI"]
[Sun Aug 30 03:05:47.891059 2026] [security2:error] [pid 495314:tid 495515] [client 20.63.219.114:14414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/credits.php"] [unique_id "apPkW0mtdPfUFP1akVFAeAAABG8"]
[Sun Aug 30 03:05:47.906584 2026] [security2:error] [pid 495314:tid 495492] [client 216.73.216.128:6506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPkW0mtdPfUFP1akVFAfAAABFg"]
[Sun Aug 30 03:05:47.916002 2026] [security2:error] [pid 495314:tid 495504] [client 20.48.251.3:4821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/rum.or.php"] [unique_id "apPkW0mtdPfUFP1akVFAfwAABGQ"]
[Sun Aug 30 03:05:47.956946 2026] [security2:error] [pid 495314:tid 495490] [client 68.155.159.216:56447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apPkW0mtdPfUFP1akVFAggAABFY"]
[Sun Aug 30 03:05:47.972238 2026] [security2:error] [pid 495314:tid 495505] [client 20.48.160.90:45890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/ioxi.php"] [unique_id "apPkW0mtdPfUFP1akVFAhAAABGU"]
[Sun Aug 30 03:05:47.986212 2026] [authz_core:error] [pid 495314:tid 495456] [client 66.249.66.41:44960] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:47.986590 2026] [authz_core:error] [pid 495314:tid 495456] [client 66.249.66.41:44960] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:48.016561 2026] [security2:error] [pid 495314:tid 495542] [client 20.48.160.90:50561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/file31.php"] [unique_id "apPkXEmtdPfUFP1akVFAkQAABIo"]
[Sun Aug 30 03:05:48.019043 2026] [security2:error] [pid 495314:tid 495360] [remote 192.42.116.19:47909] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ((?:submit(?:\\\\+| )?(request)?(?:\\\\+| )?>+|<<(?:\\\\+| )remove|(?:sign ?in|log ?(?:in|out)|next|modifier|envoyer|add|continue|weiter|account|results|select)(?:\\\\+| )?>+)$|^< ?\\\\??(?: |\\\\+)?xml|^> ?$)" against "ARGS:author" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1093"] [id "350147"] [rev "155"] [msg "Atomicorp.com WAF Rules: Potentially Untrusted Web Content Detected"] [severity "CRITICAL"] [hostname "pnggaq.org"] [uri "/"] [unique_id "apPkXEmtdPfUFP1akVFAkAAEkS0"], referer: https://pnggaq.org?email=ds5xczgju1uv0e%40emalupe.com&author=%F0%9F%93%89+%281%29+MESSAGE+for+you+%E2%84%96H8447+READ+-%3E%3E%3E+graph.org%2FCloud-Mining-08-27%3Fhs%3D76c180c3c6ddd911dde46a168523060f%26++%F0%9F%93%89&url=graph.org%2FCloud-Mining-08-27&submit=Post+Comment&comment=%F0%9F%93%89+%281%29+MESSAGE+for+you+%E2%84%96H8447+READ+-%3E%3E%3E+graph.org%2FCloud-Mining-08-27%3Fhs%3D76c180c3c6ddd911dde46a168523060f%26++%F0%9F%93%89
[Sun Aug 30 03:05:48.056092 2026] [security2:error] [pid 495314:tid 495502] [client 20.104.50.220:61634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/abc.php"] [unique_id "apPkXEmtdPfUFP1akVFAlgAABGI"]
[Sun Aug 30 03:05:48.118090 2026] [security2:error] [pid 495314:tid 495534] [client 20.48.160.90:26688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/TNT.php"] [unique_id "apPkXEmtdPfUFP1akVFApgAABII"]
[Sun Aug 30 03:05:48.168588 2026] [core:alert] [pid 495314:tid 495459] [client 34.237.50.25:0] /home3/fremant1/thedevonshireteaguide.com.au/.htaccess: without matching section
[Sun Aug 30 03:05:48.199987 2026] [security2:error] [pid 495314:tid 495535] [client 20.48.160.90:50635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/dk.php"] [unique_id "apPkXEmtdPfUFP1akVFAsQAABIM"]
[Sun Aug 30 03:05:48.238893 2026] [security2:error] [pid 495314:tid 495539] [client 68.155.159.216:61349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/simple.php"] [unique_id "apPkXEmtdPfUFP1akVFAtQAABIc"]
[Sun Aug 30 03:05:48.243801 2026] [security2:error] [pid 495314:tid 495567] [client 40.83.93.50:8762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/robots.php"] [unique_id "apPkXEmtdPfUFP1akVFAtgAABKM"]
[Sun Aug 30 03:05:48.253752 2026] [security2:error] [pid 495314:tid 495490] [client 68.155.159.216:52725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/goat1.php"] [unique_id "apPkXEmtdPfUFP1akVFAuAAABFY"]
[Sun Aug 30 03:05:48.262267 2026] [security2:error] [pid 495314:tid 495465] [client 20.48.160.90:45895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/cd.php"] [unique_id "apPkXEmtdPfUFP1akVFAvwAABD0"]
[Sun Aug 30 03:05:48.265364 2026] [security2:error] [pid 495314:tid 495532] [client 20.151.200.44:62995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/css/000.php"] [unique_id "apPkXEmtdPfUFP1akVFAwwAABIA"]
[Sun Aug 30 03:05:48.267874 2026] [security2:error] [pid 495314:tid 495515] [client 20.63.219.114:18534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/cache.php"] [unique_id "apPkXEmtdPfUFP1akVFAxAAABG8"]
[Sun Aug 30 03:05:48.272808 2026] [security2:error] [pid 495314:tid 495455] [client 68.155.159.216:63523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/file17.php"] [unique_id "apPkXEmtdPfUFP1akVFAzAAABDM"]
[Sun Aug 30 03:05:48.274509 2026] [security2:error] [pid 495314:tid 495477] [client 20.48.251.3:51498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/umgebung.php"] [unique_id "apPkXEmtdPfUFP1akVFAzQAABEk"]
[Sun Aug 30 03:05:48.298002 2026] [security2:error] [pid 495314:tid 495502] [client 20.104.50.220:46179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/con.php"] [unique_id "apPkXEmtdPfUFP1akVFA0AAABGI"]
[Sun Aug 30 03:05:48.302075 2026] [security2:error] [pid 495314:tid 495560] [client 20.104.50.220:27400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/wp-includes/version.php"] [unique_id "apPkXEmtdPfUFP1akVFA0gAABJw"]
[Sun Aug 30 03:05:48.316559 2026] [security2:error] [pid 495314:tid 495518] [client 68.155.159.216:65494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apPkXEmtdPfUFP1akVFA0wAABHI"]
[Sun Aug 30 03:05:48.350971 2026] [security2:error] [pid 495314:tid 495508] [client 68.155.159.216:59979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-content/index.php"] [unique_id "apPkXEmtdPfUFP1akVFA1wAABGg"]
[Sun Aug 30 03:05:48.352728 2026] [security2:error] [pid 495314:tid 495562] [client 20.104.50.220:29153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/Success.php"] [unique_id "apPkXEmtdPfUFP1akVFA2AAABJ4"]
[Sun Aug 30 03:05:48.385986 2026] [security2:error] [pid 495314:tid 495480] [client 20.48.160.90:33236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/ta.php"] [unique_id "apPkXEmtdPfUFP1akVFA3AAABEw"]
[Sun Aug 30 03:05:48.402221 2026] [security2:error] [pid 495314:tid 495533] [client 20.48.160.90:45883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/luuf.php"] [unique_id "apPkXEmtdPfUFP1akVFA3wAABIE"]
[Sun Aug 30 03:05:48.415060 2026] [security2:error] [pid 495314:tid 495544] [client 20.48.251.3:23459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/cu.php"] [unique_id "apPkXEmtdPfUFP1akVFA4wAABIw"]
[Sun Aug 30 03:05:48.465397 2026] [authz_core:error] [pid 495314:tid 495538] [client 216.73.216.128:18243] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:48.465853 2026] [authz_core:error] [pid 495314:tid 495538] [client 216.73.216.128:18243] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:48.467498 2026] [security2:error] [pid 495314:tid 495452] [client 20.104.50.220:31847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wsmini.php"] [unique_id "apPkXEmtdPfUFP1akVFA5gAABDA"]
[Sun Aug 30 03:05:48.479777 2026] [security2:error] [pid 495314:tid 495566] [client 20.104.50.220:5594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/ha.php"] [unique_id "apPkXEmtdPfUFP1akVFA6AAABKI"]
[Sun Aug 30 03:05:48.493890 2026] [security2:error] [pid 495314:tid 495514] [client 20.48.251.3:6475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/zz.php"] [unique_id "apPkXEmtdPfUFP1akVFA7wAABG4"]
[Sun Aug 30 03:05:48.532722 2026] [security2:error] [pid 495314:tid 495511] [client 20.48.160.90:45879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/fex.php"] [unique_id "apPkXEmtdPfUFP1akVFA-gAABGs"]
[Sun Aug 30 03:05:48.534171 2026] [security2:error] [pid 495314:tid 495537] [client 20.48.160.90:33270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/bo.php"] [unique_id "apPkXEmtdPfUFP1akVFA_AAABIU"]
[Sun Aug 30 03:05:48.544387 2026] [security2:error] [pid 495314:tid 495502] [client 20.48.251.3:46240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/pass4.php"] [unique_id "apPkXEmtdPfUFP1akVFA_QAABGI"]
[Sun Aug 30 03:05:48.554072 2026] [security2:error] [pid 495314:tid 495560] [client 20.104.49.130:57501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/3.php"] [unique_id "apPkXEmtdPfUFP1akVFA_wAABJw"]
[Sun Aug 30 03:05:48.565518 2026] [security2:error] [pid 495314:tid 495551] [client 20.48.251.3:49963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/sdsa.php"] [unique_id "apPkXEmtdPfUFP1akVFBAAAABJM"]
[Sun Aug 30 03:05:48.576547 2026] [security2:error] [pid 495314:tid 495487] [client 20.104.50.220:29607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/xs.php"] [unique_id "apPkXEmtdPfUFP1akVFBAQAABFM"]
[Sun Aug 30 03:05:48.644933 2026] [authz_core:error] [pid 495314:tid 495526] [client 216.73.216.128:15344] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:48.645385 2026] [authz_core:error] [pid 495314:tid 495526] [client 216.73.216.128:15344] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:48.647021 2026] [security2:error] [pid 495314:tid 495520] [client 20.104.18.15:43309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/ws85.php"] [unique_id "apPkXEmtdPfUFP1akVFBCQAABHQ"]
[Sun Aug 30 03:05:48.653183 2026] [security2:error] [pid 495314:tid 495545] [client 20.63.219.114:1424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/fix.php"] [unique_id "apPkXEmtdPfUFP1akVFBCwAABI0"]
[Sun Aug 30 03:05:48.661951 2026] [security2:error] [pid 495314:tid 495471] [client 20.48.160.90:40063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/l.php"] [unique_id "apPkXEmtdPfUFP1akVFBDQAABEM"]
[Sun Aug 30 03:05:48.690235 2026] [security2:error] [pid 495314:tid 495475] [client 20.104.18.15:32981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/wp.php"] [unique_id "apPkXEmtdPfUFP1akVFBDgAABEc"]
[Sun Aug 30 03:05:48.705826 2026] [security2:error] [pid 495314:tid 495544] [client 20.48.251.3:55805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/tax.php"] [unique_id "apPkXEmtdPfUFP1akVFBDwAABIw"]
[Sun Aug 30 03:05:48.710246 2026] [security2:error] [pid 495314:tid 495541] [client 20.48.160.90:50565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/44.php"] [unique_id "apPkXEmtdPfUFP1akVFBEAAABIk"]
[Sun Aug 30 03:05:48.727049 2026] [security2:error] [pid 495314:tid 495463] [client 216.73.216.128:18243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPkXEmtdPfUFP1akVFBEQAABDs"]
[Sun Aug 30 03:05:48.753112 2026] [security2:error] [pid 495314:tid 495481] [client 40.83.93.50:8748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/cron.php"] [unique_id "apPkXEmtdPfUFP1akVFBEgAABE0"]
[Sun Aug 30 03:05:48.799105 2026] [security2:error] [pid 495314:tid 495448] [client 20.151.200.44:63602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/cy.php"] [unique_id "apPkXEmtdPfUFP1akVFBGAAABCw"]
[Sun Aug 30 03:05:48.799482 2026] [security2:error] [pid 495314:tid 495514] [client 20.48.160.90:45943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/xr.php"] [unique_id "apPkXEmtdPfUFP1akVFBGQAABG4"]
[Sun Aug 30 03:05:48.845628 2026] [security2:error] [pid 495314:tid 495490] [client 20.48.160.90:33231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/h2.php"] [unique_id "apPkXEmtdPfUFP1akVFBIAAABFY"]
[Sun Aug 30 03:05:48.845780 2026] [security2:error] [pid 495314:tid 495564] [client 20.104.18.15:33604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/abcd.php"] [unique_id "apPkXEmtdPfUFP1akVFBIQAABKA"]
[Sun Aug 30 03:05:48.862975 2026] [security2:error] [pid 495314:tid 495528] [client 20.104.50.220:51542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/manda.php"] [unique_id "apPkXEmtdPfUFP1akVFBJwAABHw"]
[Sun Aug 30 03:05:48.954565 2026] [security2:error] [pid 495314:tid 495568] [client 20.48.160.90:45951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/Q3.php"] [unique_id "apPkXEmtdPfUFP1akVFBNgAABKQ"]
[Sun Aug 30 03:05:48.985234 2026] [security2:error] [pid 495314:tid 495464] [client 20.104.50.220:33178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/cpanel.php"] [unique_id "apPkXEmtdPfUFP1akVFBPAAABDw"]
[Sun Aug 30 03:05:48.988171 2026] [security2:error] [pid 495314:tid 495513] [client 68.155.159.216:52863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPkXEmtdPfUFP1akVFBPQAABG0"]
[Sun Aug 30 03:05:48.993554 2026] [security2:error] [pid 495314:tid 495475] [client 20.48.160.90:33217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apPkXEmtdPfUFP1akVFBPgAABEc"]
[Sun Aug 30 03:05:48.999970 2026] [security2:error] [pid 495314:tid 495541] [client 20.104.18.15:13638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/503.php"] [unique_id "apPkXEmtdPfUFP1akVFBQgAABIk"]
[Sun Aug 30 03:05:49.046711 2026] [security2:error] [pid 495314:tid 495556] [client 20.48.251.3:44296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/xmy.php"] [unique_id "apPkXUmtdPfUFP1akVFBSwAABJg"]
[Sun Aug 30 03:05:49.090224 2026] [security2:error] [pid 495314:tid 495564] [client 20.48.160.90:40015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/Q1.php"] [unique_id "apPkXUmtdPfUFP1akVFBUQAABKA"]
[Sun Aug 30 03:05:49.091447 2026] [security2:error] [pid 495314:tid 495492] [client 20.63.219.114:18545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/alfa.php"] [unique_id "apPkXUmtdPfUFP1akVFBUwAABFg"]
[Sun Aug 30 03:05:49.097036 2026] [security2:error] [pid 495314:tid 495529] [client 20.104.49.130:60655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkXUmtdPfUFP1akVFBVQAABH0"]
[Sun Aug 30 03:05:49.173366 2026] [security2:error] [pid 495314:tid 495477] [client 68.155.159.216:56399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/chosen.php"] [unique_id "apPkXUmtdPfUFP1akVFBYQAABEk"]
[Sun Aug 30 03:05:49.174442 2026] [security2:error] [pid 495314:tid 495555] [client 20.48.160.90:33164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/sao.php"] [unique_id "apPkXUmtdPfUFP1akVFBYgAABJc"]
[Sun Aug 30 03:05:49.249023 2026] [security2:error] [pid 495314:tid 495508] [client 20.48.160.90:45939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/nz.php"] [unique_id "apPkXUmtdPfUFP1akVFBdAAABGg"]
[Sun Aug 30 03:05:49.266532 2026] [security2:error] [pid 495314:tid 495469] [client 40.83.93.50:12094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/goat.php"] [unique_id "apPkXUmtdPfUFP1akVFBewAABEE"]
[Sun Aug 30 03:05:49.291770 2026] [security2:error] [pid 495314:tid 495453] [client 20.104.50.220:61635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/indexx.php"] [unique_id "apPkXUmtdPfUFP1akVFBggAABDE"]
[Sun Aug 30 03:05:49.358240 2026] [security2:error] [pid 495314:tid 495531] [client 68.155.159.216:54738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apPkXUmtdPfUFP1akVFBiAAABH8"]
[Sun Aug 30 03:05:49.363797 2026] [security2:error] [pid 495314:tid 495564] [client 216.73.216.128:42569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPkXUmtdPfUFP1akVFBigAABKA"]
[Sun Aug 30 03:05:49.366402 2026] [security2:error] [pid 495314:tid 495510] [client 20.48.160.90:50628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/dapa.php"] [unique_id "apPkXUmtdPfUFP1akVFBiwAABGo"]
[Sun Aug 30 03:05:49.376055 2026] [security2:error] [pid 495314:tid 495526] [client 20.48.160.90:26694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/sg.php"] [unique_id "apPkXUmtdPfUFP1akVFBjQAABHo"]
[Sun Aug 30 03:05:49.399930 2026] [security2:error] [pid 495314:tid 495529] [client 20.48.251.3:7021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/infos.php"] [unique_id "apPkXUmtdPfUFP1akVFBjwAABH0"]
[Sun Aug 30 03:05:49.424909 2026] [security2:error] [pid 495314:tid 495537] [client 68.155.159.216:12309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apPkXUmtdPfUFP1akVFBlQAABIU"]
[Sun Aug 30 03:05:49.427556 2026] [security2:error] [pid 495314:tid 495503] [client 20.48.251.3:58856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/old_phpinfo.php"] [unique_id "apPkXUmtdPfUFP1akVFBlgAABGM"]
[Sun Aug 30 03:05:49.438460 2026] [security2:error] [pid 495314:tid 495522] [client 20.104.50.220:27131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/images/index.php"] [unique_id "apPkXUmtdPfUFP1akVFBlwAABHY"]
[Sun Aug 30 03:05:49.444224 2026] [security2:error] [pid 495314:tid 495512] [client 20.63.219.114:14407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/wp-blog-header.php"] [unique_id "apPkXUmtdPfUFP1akVFBmQAABGw"]
[Sun Aug 30 03:05:49.451535 2026] [security2:error] [pid 495314:tid 495567] [client 20.104.50.220:46433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/con7ext.php"] [unique_id "apPkXUmtdPfUFP1akVFBmgAABKM"]
[Sun Aug 30 03:05:49.469491 2026] [security2:error] [pid 495314:tid 495484] [client 68.155.159.216:61354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-admin/about.php"] [unique_id "apPkXUmtdPfUFP1akVFBnAAABFA"]
[Sun Aug 30 03:05:49.496034 2026] [security2:error] [pid 495314:tid 495497] [client 20.104.50.220:29134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/syad.php"] [unique_id "apPkXUmtdPfUFP1akVFBpwAABF0"]
[Sun Aug 30 03:05:49.508154 2026] [authz_core:error] [pid 495314:tid 495555] [client 66.249.66.71:35548] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:49.508627 2026] [authz_core:error] [pid 495314:tid 495555] [client 66.249.66.71:35548] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:49.514974 2026] [security2:error] [pid 495314:tid 495508] [client 20.48.160.90:39972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/hypo.php"] [unique_id "apPkXUmtdPfUFP1akVFBqwAABGg"]
[Sun Aug 30 03:05:49.515227 2026] [security2:error] [pid 495314:tid 495480] [client 20.48.160.90:50643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/wp-content/l.php"] [unique_id "apPkXUmtdPfUFP1akVFBrQAABEw"]
[Sun Aug 30 03:05:49.571263 2026] [security2:error] [pid 495314:tid 495448] [client 20.48.251.3:23341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/services.php"] [unique_id "apPkXUmtdPfUFP1akVFBtwAABCw"]
[Sun Aug 30 03:05:49.605737 2026] [security2:error] [pid 495314:tid 495481] [client 20.104.50.220:32521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/86.php"] [unique_id "apPkXUmtdPfUFP1akVFBuQAABE0"]
[Sun Aug 30 03:05:49.610161 2026] [security2:error] [pid 495314:tid 495532] [client 68.155.159.216:59925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/about/function.php"] [unique_id "apPkXUmtdPfUFP1akVFBugAABIA"]
[Sun Aug 30 03:05:49.616833 2026] [security2:error] [pid 495314:tid 495526] [client 20.104.50.220:5524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/gg.php"] [unique_id "apPkXUmtdPfUFP1akVFBvAAABHo"]
[Sun Aug 30 03:05:49.625717 2026] [security2:error] [pid 495314:tid 495528] [client 20.48.251.3:7003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/test.php"] [unique_id "apPkXUmtdPfUFP1akVFBvgAABHw"]
[Sun Aug 30 03:05:49.645857 2026] [security2:error] [pid 495314:tid 495523] [client 20.48.160.90:40041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/Hd.php"] [unique_id "apPkXUmtdPfUFP1akVFBwAAABHc"]
[Sun Aug 30 03:05:49.667529 2026] [security2:error] [pid 495314:tid 495571] [client 20.48.160.90:33202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/wp-admin/w.php"] [unique_id "apPkXUmtdPfUFP1akVFBwQAABKc"]
[Sun Aug 30 03:05:49.683421 2026] [authz_core:error] [pid 495314:tid 495529] [client 66.249.66.41:37639] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:49.683887 2026] [authz_core:error] [pid 495314:tid 495529] [client 66.249.66.41:37639] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:49.693116 2026] [security2:error] [pid 495314:tid 495484] [client 20.48.251.3:65498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/cu.php"] [unique_id "apPkXUmtdPfUFP1akVFBxAAABFA"]
[Sun Aug 30 03:05:49.707238 2026] [security2:error] [pid 495314:tid 495557] [client 20.48.251.3:50022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/sale.php"] [unique_id "apPkXUmtdPfUFP1akVFBxQAABJk"]
[Sun Aug 30 03:05:49.715965 2026] [security2:error] [pid 495314:tid 495474] [client 20.104.50.220:29305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/data.php"] [unique_id "apPkXUmtdPfUFP1akVFBxgAABEY"]
[Sun Aug 30 03:05:49.781092 2026] [security2:error] [pid 495314:tid 495476] [client 20.48.160.90:45922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/im.php"] [unique_id "apPkXUmtdPfUFP1akVFBzAAABEg"]
[Sun Aug 30 03:05:49.799410 2026] [security2:error] [pid 495314:tid 495544] [client 20.63.219.114:9636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/s.php"] [unique_id "apPkXUmtdPfUFP1akVFBzgAABIw"]
[Sun Aug 30 03:05:49.803674 2026] [security2:error] [pid 495314:tid 495466] [client 20.48.160.90:33211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/wp-content/k.php"] [unique_id "apPkXUmtdPfUFP1akVFBzwAABD4"]
[Sun Aug 30 03:05:49.810507 2026] [security2:error] [pid 495314:tid 495513] [client 20.104.18.15:43971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/ffs.php"] [unique_id "apPkXUmtdPfUFP1akVFB0AAABG0"]
[Sun Aug 30 03:05:49.821725 2026] [security2:error] [pid 495314:tid 495460] [client 40.83.93.50:8718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/gg.php"] [unique_id "apPkXUmtdPfUFP1akVFB1AAABDg"]
[Sun Aug 30 03:05:49.826506 2026] [authz_core:error] [pid 495314:tid 495545] [client 216.73.216.128:15344] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:49.826876 2026] [authz_core:error] [pid 495314:tid 495545] [client 216.73.216.128:15344] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:49.835425 2026] [security2:error] [pid 495314:tid 495508] [client 20.104.49.130:60985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/kerang.php"] [unique_id "apPkXUmtdPfUFP1akVFB1gAABGg"]
[Sun Aug 30 03:05:49.840118 2026] [security2:error] [pid 495314:tid 495480] [client 20.151.200.44:62942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/admin.php/pindex.php"] [unique_id "apPkXUmtdPfUFP1akVFB1wAABEw"]
[Sun Aug 30 03:05:49.842559 2026] [security2:error] [pid 495314:tid 495464] [client 20.48.251.3:55711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPkXUmtdPfUFP1akVFB2AAABDw"]
[Sun Aug 30 03:05:49.921826 2026] [security2:error] [pid 495314:tid 495492] [client 20.48.160.90:39952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/fc.php"] [unique_id "apPkXUmtdPfUFP1akVFB6gAABFg"]
[Sun Aug 30 03:05:49.935558 2026] [security2:error] [pid 495314:tid 495467] [client 20.48.160.90:50574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/os.php"] [unique_id "apPkXUmtdPfUFP1akVFB6wAABD8"]
[Sun Aug 30 03:05:50.008050 2026] [authz_core:error] [pid 495314:tid 495571] [client 216.73.216.128:15344] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:50.008421 2026] [authz_core:error] [pid 495314:tid 495571] [client 216.73.216.128:15344] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:50.031542 2026] [security2:error] [pid 495314:tid 495509] [client 20.104.18.15:33778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/nofile.php"] [unique_id "apPkXkmtdPfUFP1akVFB_AAABGk"]
[Sun Aug 30 03:05:50.057859 2026] [security2:error] [pid 495314:tid 495479] [client 20.48.160.90:45863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/ke.php"] [unique_id "apPkXkmtdPfUFP1akVFCBAAABEs"]
[Sun Aug 30 03:05:50.068024 2026] [security2:error] [pid 495314:tid 495482] [client 20.48.160.90:50617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/htio.php"] [unique_id "apPkXkmtdPfUFP1akVFCBgAABE4"]
[Sun Aug 30 03:05:50.093321 2026] [security2:error] [pid 495314:tid 495508] [client 20.104.50.220:42790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/pmemek.php"] [unique_id "apPkXkmtdPfUFP1akVFCDQAABGg"]
[Sun Aug 30 03:05:50.099144 2026] [authz_core:error] [pid 495314:tid 495468] [client 216.73.216.128:33529] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:50.099464 2026] [authz_core:error] [pid 495314:tid 495468] [client 216.73.216.128:33529] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:50.109197 2026] [security2:error] [pid 495314:tid 495554] [client 68.155.159.216:59387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/log-mama/function.php"] [unique_id "apPkXkmtdPfUFP1akVFCEQAABJY"]
[Sun Aug 30 03:05:50.138737 2026] [security2:error] [pid 495314:tid 495510] [client 20.104.50.220:33208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/devill.php"] [unique_id "apPkXkmtdPfUFP1akVFCHAAABGo"]
[Sun Aug 30 03:05:50.155521 2026] [security2:error] [pid 495314:tid 495528] [client 20.104.18.15:13724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/504.php"] [unique_id "apPkXkmtdPfUFP1akVFCHwAABHw"]
[Sun Aug 30 03:05:50.156806 2026] [security2:error] [pid 495314:tid 495368] [remote 193.202.44.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.44.202.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alphabraingummies.com"] [uri "/wp-login.php"] [unique_id "apPkXkmtdPfUFP1akVFCHQAELDU"]
[Sun Aug 30 03:05:50.191440 2026] [security2:error] [pid 495314:tid 495562] [client 20.48.160.90:45918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/tf.php"] [unique_id "apPkXkmtdPfUFP1akVFCJwAABJ4"]
[Sun Aug 30 03:05:50.198505 2026] [security2:error] [pid 495314:tid 495522] [client 20.48.251.3:44317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/ms-edit.php"] [unique_id "apPkXkmtdPfUFP1akVFCKgAABHY"]
[Sun Aug 30 03:05:50.241311 2026] [security2:error] [pid 495314:tid 495483] [client 20.63.219.114:9601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/php.php"] [unique_id "apPkXkmtdPfUFP1akVFCMQAABE8"]
[Sun Aug 30 03:05:50.259423 2026] [security2:error] [pid 495314:tid 495538] [client 20.48.160.90:50596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/dev.php"] [unique_id "apPkXkmtdPfUFP1akVFCOQAABIY"]
[Sun Aug 30 03:05:50.273963 2026] [security2:error] [pid 495314:tid 495463] [client 20.151.200.44:47098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/ft.php"] [unique_id "apPkXkmtdPfUFP1akVFCPgAABDs"]
[Sun Aug 30 03:05:50.286205 2026] [authz_core:error] [pid 495314:tid 495557] [client 66.249.66.195:47602] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:50.286562 2026] [authz_core:error] [pid 495314:tid 495557] [client 66.249.66.195:47602] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:50.287035 2026] [security2:error] [pid 495314:tid 495481] [client 68.155.159.216:56413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/goods.php"] [unique_id "apPkXkmtdPfUFP1akVFCQwAABE0"]
[Sun Aug 30 03:05:50.292354 2026] [security2:error] [pid 495314:tid 495531] [client 40.83.93.50:18100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/defaults.php"] [unique_id "apPkXkmtdPfUFP1akVFCRQAABH8"]
[Sun Aug 30 03:05:50.345820 2026] [security2:error] [pid 495314:tid 495451] [client 20.48.160.90:45930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/px.php"] [unique_id "apPkXkmtdPfUFP1akVFCRwAABC8"]
[Sun Aug 30 03:05:50.399026 2026] [security2:error] [pid 495314:tid 495564] [client 20.104.49.130:52532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/3.php"] [unique_id "apPkXkmtdPfUFP1akVFCTwAABKA"]
[Sun Aug 30 03:05:50.411820 2026] [security2:error] [pid 495314:tid 495493] [client 20.48.160.90:50679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/gos.php"] [unique_id "apPkXkmtdPfUFP1akVFCVgAABFk"]
[Sun Aug 30 03:05:50.438668 2026] [security2:error] [pid 495314:tid 495530] [client 20.104.50.220:59573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/browse.php"] [unique_id "apPkXkmtdPfUFP1akVFCWAAABH4"]
[Sun Aug 30 03:05:50.476137 2026] [security2:error] [pid 495314:tid 495477] [client 20.48.160.90:40006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/jg.php"] [unique_id "apPkXkmtdPfUFP1akVFCWwAABEk"]
[Sun Aug 30 03:05:50.534848 2026] [security2:error] [pid 495314:tid 495466] [client 68.155.159.216:19407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-admin/network/index.php"] [unique_id "apPkXkmtdPfUFP1akVFCbgAABD4"]
[Sun Aug 30 03:05:50.547364 2026] [security2:error] [pid 495314:tid 495517] [client 68.155.159.216:65490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/simple.php"] [unique_id "apPkXkmtdPfUFP1akVFCcAAABHE"]
[Sun Aug 30 03:05:50.547399 2026] [security2:error] [pid 495314:tid 495544] [client 20.48.160.90:33251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/132.php"] [unique_id "apPkXkmtdPfUFP1akVFCbwAABIw"]
[Sun Aug 30 03:05:50.577772 2026] [security2:error] [pid 495314:tid 495464] [client 20.104.50.220:27082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/images/2008.php"] [unique_id "apPkXkmtdPfUFP1akVFCegAABDw"]
[Sun Aug 30 03:05:50.599017 2026] [security2:error] [pid 495314:tid 495465] [client 20.63.219.114:14406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/system_log.php"] [unique_id "apPkXkmtdPfUFP1akVFCfQAABD0"]
[Sun Aug 30 03:05:50.601079 2026] [authz_core:error] [pid 495314:tid 495555] [client 66.249.66.199:36888] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:50.601368 2026] [authz_core:error] [pid 495314:tid 495555] [client 66.249.66.199:36888] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:50.604926 2026] [security2:error] [pid 495314:tid 495514] [client 20.104.50.220:46442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/loader/ff.php"] [unique_id "apPkXkmtdPfUFP1akVFCfwAABG4"]
[Sun Aug 30 03:05:50.605972 2026] [security2:error] [pid 495314:tid 495556] [client 20.48.160.90:45944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/yj.php"] [unique_id "apPkXkmtdPfUFP1akVFCgAAABJg"]
[Sun Aug 30 03:05:50.627217 2026] [security2:error] [pid 495314:tid 495564] [client 68.155.159.216:62282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/file5.php"] [unique_id "apPkXkmtdPfUFP1akVFChQAABKA"]
[Sun Aug 30 03:05:50.647092 2026] [security2:error] [pid 495314:tid 495493] [client 20.104.50.220:52852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/success.php"] [unique_id "apPkXkmtdPfUFP1akVFChwAABFk"]
[Sun Aug 30 03:05:50.674684 2026] [security2:error] [pid 495314:tid 495540] [client 68.155.159.216:63936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apPkXkmtdPfUFP1akVFCiAAABIg"]
[Sun Aug 30 03:05:50.681186 2026] [security2:error] [pid 495314:tid 495486] [client 20.48.160.90:50666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/v22.php"] [unique_id "apPkXkmtdPfUFP1akVFCiQAABFI"]
[Sun Aug 30 03:05:50.713045 2026] [security2:error] [pid 495314:tid 495563] [client 20.48.251.3:23347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/filesystems.php"] [unique_id "apPkXkmtdPfUFP1akVFCjQAABJ8"]
[Sun Aug 30 03:05:50.721154 2026] [security2:error] [pid 495314:tid 495562] [client 68.155.159.216:54105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apPkXkmtdPfUFP1akVFCjgAABJ4"]
[Sun Aug 30 03:05:50.729531 2026] [security2:error] [pid 495314:tid 495512] [client 20.151.200.44:23609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/admin.php/csv.php"] [unique_id "apPkXkmtdPfUFP1akVFCjwAABGw"]
[Sun Aug 30 03:05:50.734900 2026] [security2:error] [pid 495314:tid 495483] [client 20.48.160.90:45870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/zi.php"] [unique_id "apPkXkmtdPfUFP1akVFCkQAABE8"]
[Sun Aug 30 03:05:50.735618 2026] [authz_core:error] [pid 495314:tid 495477] [client 216.73.216.128:32444] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:50.735882 2026] [authz_core:error] [pid 495314:tid 495477] [client 216.73.216.128:32444] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:50.742541 2026] [security2:error] [pid 495314:tid 495553] [client 20.104.50.220:31868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/min.php"] [unique_id "apPkXkmtdPfUFP1akVFCkgAABJU"]
[Sun Aug 30 03:05:50.761149 2026] [security2:error] [pid 495314:tid 495485] [client 20.48.251.3:7005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/cloud.php"] [unique_id "apPkXkmtdPfUFP1akVFCkwAABFE"]
[Sun Aug 30 03:05:50.764764 2026] [security2:error] [pid 495314:tid 495444] [client 20.104.49.130:57691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/df.php"] [unique_id "apPkXkmtdPfUFP1akVFClAAABCg"]
[Sun Aug 30 03:05:50.770104 2026] [security2:error] [pid 495314:tid 495509] [client 20.48.251.3:51541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertpitti.webnet-hosting4.com"] [uri "/wp-act.php"] [unique_id "apPkXkmtdPfUFP1akVFClgAABGk"]
[Sun Aug 30 03:05:50.772576 2026] [security2:error] [pid 495314:tid 495487] [client 20.104.50.220:5470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/we2.php"] [unique_id "apPkXkmtdPfUFP1akVFCmQAABFM"]
[Sun Aug 30 03:05:50.835514 2026] [security2:error] [pid 495314:tid 495526] [client 40.83.93.50:8725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/h.php"] [unique_id "apPkXkmtdPfUFP1akVFCpAAABHo"]
[Sun Aug 30 03:05:50.843196 2026] [security2:error] [pid 495314:tid 495478] [client 20.48.251.3:65478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/services.php"] [unique_id "apPkXkmtdPfUFP1akVFCpQAABEo"]
[Sun Aug 30 03:05:50.845565 2026] [security2:error] [pid 495314:tid 495529] [client 20.48.251.3:55528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/wp-class.php"] [unique_id "apPkXkmtdPfUFP1akVFCpgAABH0"]
[Sun Aug 30 03:05:50.864300 2026] [security2:error] [pid 495314:tid 495550] [client 20.48.160.90:39989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/ue.php"] [unique_id "apPkXkmtdPfUFP1akVFCrAAABJI"]
[Sun Aug 30 03:05:50.869561 2026] [security2:error] [pid 495314:tid 495514] [client 20.104.50.220:62821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/dph.php"] [unique_id "apPkXkmtdPfUFP1akVFCrwAABG4"]
[Sun Aug 30 03:05:50.881740 2026] [security2:error] [pid 495314:tid 495506] [client 20.48.160.90:33273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/wp-activate.php"] [unique_id "apPkXkmtdPfUFP1akVFCtAAABGY"]
[Sun Aug 30 03:05:50.892493 2026] [security2:error] [pid 495314:tid 495564] [client 74.7.241.186:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "balancebyplants365.com"] [uri "/robots.txt"] [unique_id "apPkXkmtdPfUFP1akVFCtQAABKA"]
[Sun Aug 30 03:05:50.893701 2026] [security2:error] [pid 495314:tid 495546] [client 74.7.241.186:49692] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "balancebyplants365.com"] [uri "/robots.txt"] [unique_id "apPkXkmtdPfUFP1akVFCsAAABI4"]
[Sun Aug 30 03:05:50.920412 2026] [authz_core:error] [pid 495314:tid 495536] [client 216.73.216.128:32444] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:50.920703 2026] [authz_core:error] [pid 495314:tid 495536] [client 216.73.216.128:32444] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:50.958680 2026] [security2:error] [pid 495314:tid 495500] [client 20.63.219.114:9607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/w.php"] [unique_id "apPkXkmtdPfUFP1akVFCxAAABGA"]
[Sun Aug 30 03:05:50.966515 2026] [security2:error] [pid 495314:tid 495487] [client 20.104.18.15:44030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/nano.php"] [unique_id "apPkXkmtdPfUFP1akVFCxwAABFM"]
[Sun Aug 30 03:05:50.982290 2026] [security2:error] [pid 495314:tid 495469] [client 20.48.251.3:52814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPkXkmtdPfUFP1akVFCzQAABEE"]
[Sun Aug 30 03:05:50.983118 2026] [authz_core:error] [pid 495314:tid 495479] [client 66.249.66.34:58720] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:50.983387 2026] [authz_core:error] [pid 495314:tid 495479] [client 66.249.66.34:58720] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:50.984122 2026] [security2:error] [pid 495314:tid 495472] [client 174.138.57.168:54297] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.brantinghamlaw.com"] [uri "/wp-login.php"] [unique_id "apPkXkmtdPfUFP1akVFCvAAABEQ"]
[Sun Aug 30 03:05:50.992256 2026] [security2:error] [pid 495314:tid 495553] [client 74.7.241.186:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "balancebyplants365.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "apPkXkmtdPfUFP1akVFCwwAABJU"], referer: https://balancebyplants365.com/robots.txt
[Sun Aug 30 03:05:50.993009 2026] [security2:error] [pid 495314:tid 495498] [client 74.7.241.186:49692] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "balancebyplants365.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "apPkXkmtdPfUFP1akVFCwAAABF4"], referer: https://balancebyplants365.com/robots.txt
[Sun Aug 30 03:05:51.009891 2026] [authz_core:error] [pid 495314:tid 495481] [client 216.73.216.128:33529] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:51.010171 2026] [authz_core:error] [pid 495314:tid 495481] [client 216.73.216.128:33529] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:51.013365 2026] [security2:error] [pid 495314:tid 495470] [client 20.48.160.90:19922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/wp-trackback.php"] [unique_id "apPkX0mtdPfUFP1akVFC1wAABEI"]
[Sun Aug 30 03:05:51.015567 2026] [security2:error] [pid 495314:tid 495526] [client 20.48.160.90:45833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/nv.php"] [unique_id "apPkX0mtdPfUFP1akVFC2QAABHo"]
[Sun Aug 30 03:05:51.101530 2026] [authz_core:error] [pid 495314:tid 495511] [client 66.249.66.41:44960] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:51.102018 2026] [authz_core:error] [pid 495314:tid 495511] [client 66.249.66.41:44960] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:51.174067 2026] [security2:error] [pid 495314:tid 495377] [remote 193.202.44.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.44.202.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alphabraingummies.com"] [uri "/wp-login.php"] [unique_id "apPkX0mtdPfUFP1akVFC-gAEez4"], referer: https://alphabraingummies.com/wp-login.php
[Sun Aug 30 03:05:51.175704 2026] [security2:error] [pid 495314:tid 495485] [client 20.48.160.90:40050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/jw.php"] [unique_id "apPkX0mtdPfUFP1akVFC_AAABFE"]
[Sun Aug 30 03:05:51.201344 2026] [security2:error] [pid 495314:tid 495565] [client 20.104.18.15:33000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/run.php"] [unique_id "apPkX0mtdPfUFP1akVFDAAAABKE"]
[Sun Aug 30 03:05:51.214837 2026] [security2:error] [pid 495314:tid 495517] [client 20.48.160.90:50576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/pri.php"] [unique_id "apPkX0mtdPfUFP1akVFDAgAABHE"]
[Sun Aug 30 03:05:51.237967 2026] [security2:error] [pid 495314:tid 495499] [client 68.155.159.216:52847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/bk/index.php"] [unique_id "apPkX0mtdPfUFP1akVFDBQAABF8"]
[Sun Aug 30 03:05:51.247127 2026] [security2:error] [pid 495314:tid 495460] [client 20.104.50.220:42438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/mmk.php"] [unique_id "apPkX0mtdPfUFP1akVFDCwAABDg"]
[Sun Aug 30 03:05:51.276252 2026] [security2:error] [pid 495314:tid 495564] [client 20.104.50.220:33163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/dikne.php"] [unique_id "apPkX0mtdPfUFP1akVFDGgAABKA"]
[Sun Aug 30 03:05:51.285910 2026] [authz_core:error] [pid 495314:tid 495491] [client 216.73.216.128:15344] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:51.286201 2026] [authz_core:error] [pid 495314:tid 495491] [client 216.73.216.128:15344] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:51.291709 2026] [authz_core:error] [pid 495314:tid 495480] [client 66.249.66.68:52249] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:51.291981 2026] [authz_core:error] [pid 495314:tid 495480] [client 66.249.66.68:52249] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:51.293716 2026] [security2:error] [pid 495314:tid 495522] [client 20.104.18.15:13582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/admin.php"] [unique_id "apPkX0mtdPfUFP1akVFDIAAABHY"]
[Sun Aug 30 03:05:51.308567 2026] [security2:error] [pid 495314:tid 495445] [client 20.48.160.90:39949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/or.php"] [unique_id "apPkX0mtdPfUFP1akVFDIwAABCk"]
[Sun Aug 30 03:05:51.326581 2026] [security2:error] [pid 495314:tid 495452] [client 20.63.219.114:9663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/wp.php"] [unique_id "apPkX0mtdPfUFP1akVFDJAAABDA"]
[Sun Aug 30 03:05:51.341333 2026] [security2:error] [pid 495314:tid 495469] [client 40.83.93.50:12055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/num.php"] [unique_id "apPkX0mtdPfUFP1akVFDJwAABEE"]
[Sun Aug 30 03:05:51.345803 2026] [security2:error] [pid 495314:tid 495509] [client 20.48.160.90:33171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/wp_blog_footer.php"] [unique_id "apPkX0mtdPfUFP1akVFDKAAABGk"]
[Sun Aug 30 03:05:51.429877 2026] [security2:error] [pid 495314:tid 495478] [client 20.151.200.44:47056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/file66.php"] [unique_id "apPkX0mtdPfUFP1akVFDOwAABEo"]
[Sun Aug 30 03:05:51.430397 2026] [authz_core:error] [pid 495314:tid 495470] [client 216.73.216.128:32409] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:51.430832 2026] [authz_core:error] [pid 495314:tid 495470] [client 216.73.216.128:32409] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:51.440466 2026] [security2:error] [pid 495314:tid 495556] [client 20.48.160.90:45838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/ile56.php"] [unique_id "apPkX0mtdPfUFP1akVFDPQAABJg"]
[Sun Aug 30 03:05:51.466031 2026] [security2:error] [pid 495314:tid 495567] [client 68.155.159.216:56335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apPkX0mtdPfUFP1akVFDPwAABKM"]
[Sun Aug 30 03:05:51.504441 2026] [authz_core:error] [pid 495314:tid 495445] [client 66.249.66.192:51138] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:51.504713 2026] [authz_core:error] [pid 495314:tid 495445] [client 66.249.66.192:51138] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:51.512594 2026] [security2:error] [pid 495314:tid 495509] [client 20.48.160.90:50675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/sushi.php"] [unique_id "apPkX0mtdPfUFP1akVFDTwAABGk"]
[Sun Aug 30 03:05:51.557661 2026] [security2:error] [pid 495314:tid 495471] [client 167.235.27.8:57076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.27.235.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smithfieldicecreamplace.com"] [uri "/wp-login.php"] [unique_id "apPkX0mtdPfUFP1akVFDVwAABEM"]
[Sun Aug 30 03:05:51.598062 2026] [security2:error] [pid 495314:tid 495482] [client 20.48.160.90:45949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/emmh.php"] [unique_id "apPkX0mtdPfUFP1akVFDZwAABE4"]
[Sun Aug 30 03:05:51.612098 2026] [security2:error] [pid 495314:tid 495478] [client 20.104.50.220:61997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/up1.php"] [unique_id "apPkX0mtdPfUFP1akVFDagAABEo"]
[Sun Aug 30 03:05:51.642431 2026] [security2:error] [pid 495314:tid 495479] [client 20.48.160.90:33179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/manga.php"] [unique_id "apPkX0mtdPfUFP1akVFDbgAABEs"]
[Sun Aug 30 03:05:51.654618 2026] [security2:error] [pid 495314:tid 495542] [client 68.155.159.216:12316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-admin/about.php"] [unique_id "apPkX0mtdPfUFP1akVFDcgAABIo"]
[Sun Aug 30 03:05:51.715791 2026] [security2:error] [pid 495314:tid 495455] [client 20.104.50.220:27422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/wp-content/plugins/hello.php"] [unique_id "apPkX0mtdPfUFP1akVFDdAAABDM"]
[Sun Aug 30 03:05:51.734984 2026] [security2:error] [pid 495314:tid 495564] [client 20.48.160.90:39980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/em.php"] [unique_id "apPkX0mtdPfUFP1akVFDdQAABKA"]
[Sun Aug 30 03:05:51.742047 2026] [security2:error] [pid 495314:tid 495554] [client 20.104.50.220:46655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/dbx.php"] [unique_id "apPkX0mtdPfUFP1akVFDeQAABJY"]
[Sun Aug 30 03:05:51.748992 2026] [security2:error] [pid 495314:tid 495452] [client 20.104.49.130:52343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/df.php"] [unique_id "apPkX0mtdPfUFP1akVFDegAABDA"]
[Sun Aug 30 03:05:51.771659 2026] [security2:error] [pid 495314:tid 495538] [client 68.155.159.216:52698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apPkX0mtdPfUFP1akVFDfQAABIY"]
[Sun Aug 30 03:05:51.772340 2026] [security2:error] [pid 495314:tid 495456] [client 20.48.160.90:33260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/asdfghj.php"] [unique_id "apPkX0mtdPfUFP1akVFDfgAABDQ"]
[Sun Aug 30 03:05:51.784937 2026] [security2:error] [pid 495314:tid 495464] [client 20.104.50.220:29317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/swm@asd365.php"] [unique_id "apPkX0mtdPfUFP1akVFDgQAABDw"]
[Sun Aug 30 03:05:51.807959 2026] [security2:error] [pid 495314:tid 495546] [client 40.83.93.50:9051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/abc.php"] [unique_id "apPkX0mtdPfUFP1akVFDggAABI4"]
[Sun Aug 30 03:05:51.831048 2026] [authz_core:error] [pid 495314:tid 495498] [client 66.249.66.36:43527] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:51.831325 2026] [authz_core:error] [pid 495314:tid 495498] [client 66.249.66.36:43527] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:51.866550 2026] [security2:error] [pid 495314:tid 495560] [client 20.48.160.90:40058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/dvve.php"] [unique_id "apPkX0mtdPfUFP1akVFDlAAABJw"]
[Sun Aug 30 03:05:51.875022 2026] [security2:error] [pid 495314:tid 495486] [client 68.155.159.216:54140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-admin/index.php"] [unique_id "apPkX0mtdPfUFP1akVFDlgAABFI"]
[Sun Aug 30 03:05:51.878950 2026] [security2:error] [pid 495314:tid 495479] [client 20.48.251.3:4689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/sys.php"] [unique_id "apPkX0mtdPfUFP1akVFDmQAABEs"]
[Sun Aug 30 03:05:51.892330 2026] [security2:error] [pid 495314:tid 495559] [client 20.63.219.114:18556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/composer.php"] [unique_id "apPkX0mtdPfUFP1akVFDmgAABJs"]
[Sun Aug 30 03:05:51.892474 2026] [security2:error] [pid 495314:tid 495544] [client 20.104.50.220:31929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-backup-sql-302.php"] [unique_id "apPkX0mtdPfUFP1akVFDmwAABIw"]
[Sun Aug 30 03:05:51.899677 2026] [security2:error] [pid 495314:tid 495506] [client 20.48.160.90:50632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/dragonshell.php"] [unique_id "apPkX0mtdPfUFP1akVFDnQAABGY"]
[Sun Aug 30 03:05:51.899773 2026] [security2:error] [pid 495314:tid 495542] [client 20.48.251.3:7026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/asdf.php"] [unique_id "apPkX0mtdPfUFP1akVFDngAABIo"]
[Sun Aug 30 03:05:51.906423 2026] [security2:error] [pid 495314:tid 495495] [client 20.104.50.220:5523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/04.php"] [unique_id "apPkX0mtdPfUFP1akVFDogAABFs"]
[Sun Aug 30 03:05:51.925987 2026] [security2:error] [pid 495314:tid 495465] [client 68.155.159.216:61341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apPkX0mtdPfUFP1akVFDqAAABD0"]
[Sun Aug 30 03:05:51.928245 2026] [security2:error] [pid 495314:tid 495503] [client 20.48.251.3:22764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/tax.php"] [unique_id "apPkX0mtdPfUFP1akVFDqQAABGM"]
[Sun Aug 30 03:05:51.984522 2026] [security2:error] [pid 495314:tid 495460] [client 20.48.251.3:49957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/database.php"] [unique_id "apPkX0mtdPfUFP1akVFDuQAABDg"]
[Sun Aug 30 03:05:51.998251 2026] [security2:error] [pid 495314:tid 495486] [client 20.48.160.90:26748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/doo.php"] [unique_id "apPkX0mtdPfUFP1akVFDvgAABFI"]
[Sun Aug 30 03:05:51.998796 2026] [security2:error] [pid 495314:tid 495473] [client 74.7.243.204:34678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/new/"] [unique_id "apPkX0mtdPfUFP1akVFDvQAABEU"], referer: http://mail.letter7brands.com/new/?p=%2F%2Fetc
[Sun Aug 30 03:05:52.038833 2026] [security2:error] [pid 495314:tid 495521] [client 20.104.50.220:29144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/todo.php"] [unique_id "apPkYEmtdPfUFP1akVFDzgAABHU"]
[Sun Aug 30 03:05:52.101149 2026] [security2:error] [pid 495314:tid 495546] [client 20.48.160.90:33264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/wp-safe.php"] [unique_id "apPkYEmtdPfUFP1akVFD3wAABI4"]
[Sun Aug 30 03:05:52.111266 2026] [authz_core:error] [pid 495314:tid 495567] [client 216.73.216.128:15344] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:52.111532 2026] [authz_core:error] [pid 495314:tid 495567] [client 216.73.216.128:15344] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:52.117997 2026] [security2:error] [pid 495314:tid 495545] [client 20.48.251.3:52807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/agg.php"] [unique_id "apPkYEmtdPfUFP1akVFD5QAABI0"]
[Sun Aug 30 03:05:52.123758 2026] [security2:error] [pid 495314:tid 495487] [client 20.104.18.15:43931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/ano.php"] [unique_id "apPkYEmtdPfUFP1akVFD6AAABFM"]
[Sun Aug 30 03:05:52.135936 2026] [security2:error] [pid 495314:tid 495560] [client 20.48.160.90:40057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/adminer-4.6.6.php"] [unique_id "apPkYEmtdPfUFP1akVFD7AAABJw"]
[Sun Aug 30 03:05:52.165196 2026] [security2:error] [pid 495314:tid 495457] [client 20.48.251.3:46266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/filesystems.php"] [unique_id "apPkYEmtdPfUFP1akVFD8gAABDU"]
[Sun Aug 30 03:05:52.203658 2026] [authz_core:error] [pid 495314:tid 495548] [client 216.73.216.128:32409] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:52.204033 2026] [authz_core:error] [pid 495314:tid 495548] [client 216.73.216.128:32409] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:52.245101 2026] [authz_core:error] [pid 495314:tid 495564] [client 66.249.66.202:60239] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:52.245548 2026] [authz_core:error] [pid 495314:tid 495564] [client 66.249.66.202:60239] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:52.259854 2026] [security2:error] [pid 495314:tid 495494] [client 20.63.219.114:18558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/abcd.php"] [unique_id "apPkYEmtdPfUFP1akVFEEAAABFo"]
[Sun Aug 30 03:05:52.271076 2026] [security2:error] [pid 495314:tid 495490] [client 20.48.160.90:19920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/gjewuagf.php"] [unique_id "apPkYEmtdPfUFP1akVFEEwAABFY"]
[Sun Aug 30 03:05:52.273879 2026] [security2:error] [pid 495314:tid 495537] [client 20.48.160.90:39979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/gelap1.php"] [unique_id "apPkYEmtdPfUFP1akVFEFAAABIU"]
[Sun Aug 30 03:05:52.292217 2026] [security2:error] [pid 495314:tid 495520] [client 40.83.93.50:8736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/default.php"] [unique_id "apPkYEmtdPfUFP1akVFEHAAABHQ"]
[Sun Aug 30 03:05:52.335335 2026] [security2:error] [pid 495314:tid 495541] [client 20.104.18.15:33742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/new.php"] [unique_id "apPkYEmtdPfUFP1akVFEHwAABIk"]
[Sun Aug 30 03:05:52.339670 2026] [security2:error] [pid 495314:tid 495479] [client 20.151.200.44:37871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/log.php"] [unique_id "apPkYEmtdPfUFP1akVFEIgAABEs"]
[Sun Aug 30 03:05:52.401026 2026] [security2:error] [pid 495314:tid 495456] [client 20.104.50.220:42039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/EvilTwin.php"] [unique_id "apPkYEmtdPfUFP1akVFELwAABDQ"]
[Sun Aug 30 03:05:52.402880 2026] [security2:error] [pid 495314:tid 495465] [client 20.48.160.90:50614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/tnglzqmv.php"] [unique_id "apPkYEmtdPfUFP1akVFEMAAABD0"]
[Sun Aug 30 03:05:52.404366 2026] [security2:error] [pid 495314:tid 495516] [client 68.155.159.216:52834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.buurtsportcoachamsterdam.nl"] [uri "/first.php"] [unique_id "apPkYEmtdPfUFP1akVFEMQAABHA"]
[Sun Aug 30 03:05:52.405498 2026] [security2:error] [pid 495314:tid 495558] [client 20.48.160.90:40032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/rsjlrria.php"] [unique_id "apPkYEmtdPfUFP1akVFEMgAABJo"]
[Sun Aug 30 03:05:52.414077 2026] [security2:error] [pid 495314:tid 495539] [client 20.104.50.220:33306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/cPanel.php"] [unique_id "apPkYEmtdPfUFP1akVFEOAAABIc"]
[Sun Aug 30 03:05:52.445229 2026] [authz_core:error] [pid 495314:tid 495538] [client 66.249.66.78:64093] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:52.445490 2026] [authz_core:error] [pid 495314:tid 495538] [client 66.249.66.78:64093] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:52.453228 2026] [security2:error] [pid 495314:tid 495535] [client 20.104.18.15:13730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/ws85.php"] [unique_id "apPkYEmtdPfUFP1akVFEQwAABIM"]
[Sun Aug 30 03:05:52.477414 2026] [authz_core:error] [pid 495314:tid 495485] [client 216.73.216.128:32409] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:52.477708 2026] [authz_core:error] [pid 495314:tid 495485] [client 216.73.216.128:32409] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:52.522810 2026] [security2:error] [pid 495314:tid 495452] [client 74.7.243.204:34678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/cms/"] [unique_id "apPkYEmtdPfUFP1akVFEWgAABDA"], referer: http://mail.letter7brands.com/cms/?p=%2F%2Fetc
[Sun Aug 30 03:05:52.537607 2026] [security2:error] [pid 495314:tid 495539] [client 20.48.160.90:40021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/AxAo.php"] [unique_id "apPkYEmtdPfUFP1akVFEYQAABIc"]
[Sun Aug 30 03:05:52.548155 2026] [security2:error] [pid 495314:tid 495546] [client 20.48.160.90:50608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/wefile.php"] [unique_id "apPkYEmtdPfUFP1akVFEYwAABI4"]
[Sun Aug 30 03:05:52.572665 2026] [security2:error] [pid 495314:tid 495490] [client 68.155.159.216:56351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apPkYEmtdPfUFP1akVFEawAABFY"]
[Sun Aug 30 03:05:52.637075 2026] [security2:error] [pid 495314:tid 495504] [client 20.63.219.114:14455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/sf.php"] [unique_id "apPkYEmtdPfUFP1akVFEdwAABGQ"]
[Sun Aug 30 03:05:52.664384 2026] [security2:error] [pid 495314:tid 495541] [client 20.48.160.90:45938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/class17.php"] [unique_id "apPkYEmtdPfUFP1akVFEfQAABIk"]
[Sun Aug 30 03:05:52.753919 2026] [security2:error] [pid 495314:tid 495448] [client 20.104.50.220:61677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/haha.php"] [unique_id "apPkYEmtdPfUFP1akVFEgwAABCw"]
[Sun Aug 30 03:05:52.775117 2026] [security2:error] [pid 495314:tid 495523] [client 68.155.159.216:65507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apPkYEmtdPfUFP1akVFEhAAABHc"]
[Sun Aug 30 03:05:52.778639 2026] [security2:error] [pid 495314:tid 495476] [client 40.83.93.50:14283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/cloud.php"] [unique_id "apPkYEmtdPfUFP1akVFEhgAABEg"]
[Sun Aug 30 03:05:52.796100 2026] [security2:error] [pid 495314:tid 495469] [client 20.48.160.90:33267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/blog.php"] [unique_id "apPkYEmtdPfUFP1akVFEiQAABEE"]
[Sun Aug 30 03:05:52.806997 2026] [security2:error] [pid 495314:tid 495464] [client 20.48.160.90:40019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/okxoby.php"] [unique_id "apPkYEmtdPfUFP1akVFEiwAABDw"]
[Sun Aug 30 03:05:52.852049 2026] [security2:error] [pid 495314:tid 495517] [client 20.104.50.220:27406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/wp-includes/class-wp.php"] [unique_id "apPkYEmtdPfUFP1akVFEnQAABHE"]
[Sun Aug 30 03:05:52.859701 2026] [authz_core:error] [pid 495314:tid 495461] [client 66.249.66.196:44709] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:52.859981 2026] [authz_core:error] [pid 495314:tid 495461] [client 66.249.66.196:44709] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:52.876017 2026] [security2:error] [pid 495314:tid 495519] [client 20.48.251.3:64429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/env.php"] [unique_id "apPkYEmtdPfUFP1akVFEpAAABHM"]
[Sun Aug 30 03:05:52.881809 2026] [security2:error] [pid 495314:tid 495504] [client 20.104.50.220:47092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/degeselih.php"] [unique_id "apPkYEmtdPfUFP1akVFEpQAABGQ"]
[Sun Aug 30 03:05:52.882666 2026] [security2:error] [pid 495314:tid 495563] [client 68.155.159.216:54726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/.well-knownold/index.php"] [unique_id "apPkYEmtdPfUFP1akVFEpgAABJ8"]
[Sun Aug 30 03:05:52.925188 2026] [security2:error] [pid 495314:tid 495562] [client 20.104.50.220:52853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/smtphec.php"] [unique_id "apPkYEmtdPfUFP1akVFEswAABJ4"]
[Sun Aug 30 03:05:52.925188 2026] [security2:error] [pid 495314:tid 495469] [client 20.151.200.44:63554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/admin.php/700.php"] [unique_id "apPkYEmtdPfUFP1akVFEtAAABEE"]
[Sun Aug 30 03:05:52.948113 2026] [security2:error] [pid 495314:tid 495480] [client 20.48.160.90:45899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/esuutzzx.php"] [unique_id "apPkYEmtdPfUFP1akVFEuwAABEw"]
[Sun Aug 30 03:05:52.979259 2026] [security2:error] [pid 495314:tid 495527] [client 20.48.160.90:50681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/wp-admin/js/wp-load.php"] [unique_id "apPkYEmtdPfUFP1akVFEwAAABHs"]
[Sun Aug 30 03:05:53.018258 2026] [security2:error] [pid 495314:tid 495532] [client 20.104.49.130:48004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkYUmtdPfUFP1akVFE1AAABIA"]
[Sun Aug 30 03:05:53.028703 2026] [security2:error] [pid 495314:tid 495539] [client 68.155.159.216:60014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPkYUmtdPfUFP1akVFE2AAABIc"]
[Sun Aug 30 03:05:53.037828 2026] [security2:error] [pid 495314:tid 495450] [client 20.48.251.3:7068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apPkYUmtdPfUFP1akVFE3AAABC4"]
[Sun Aug 30 03:05:53.045077 2026] [security2:error] [pid 495314:tid 495462] [client 20.104.50.220:5454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/333.php"] [unique_id "apPkYUmtdPfUFP1akVFE3wAABDo"]
[Sun Aug 30 03:05:53.047622 2026] [security2:error] [pid 495314:tid 495469] [client 20.48.251.3:44299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/phpsysinfo.php"] [unique_id "apPkYUmtdPfUFP1akVFE4QAABEE"]
[Sun Aug 30 03:05:53.049900 2026] [security2:error] [pid 495314:tid 495544] [client 20.104.50.220:32125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/json-php.php"] [unique_id "apPkYUmtdPfUFP1akVFE4gAABIw"]
[Sun Aug 30 03:05:53.065821 2026] [security2:error] [pid 495314:tid 495540] [client 20.48.251.3:23308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPkYUmtdPfUFP1akVFE6AAABIg"]
[Sun Aug 30 03:05:53.079353 2026] [security2:error] [pid 495314:tid 495557] [client 20.48.160.90:45852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/replace.php"] [unique_id "apPkYUmtdPfUFP1akVFE7wAABJk"]
[Sun Aug 30 03:05:53.083615 2026] [security2:error] [pid 495314:tid 495472] [client 68.155.159.216:61362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/chosen.php"] [unique_id "apPkYUmtdPfUFP1akVFE8AAABEQ"]
[Sun Aug 30 03:05:53.102747 2026] [security2:error] [pid 495314:tid 495486] [client 20.63.219.114:9632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/gel4y.php"] [unique_id "apPkYUmtdPfUFP1akVFE9QAABFI"]
[Sun Aug 30 03:05:53.123378 2026] [security2:error] [pid 495314:tid 495532] [client 20.48.251.3:55522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/atex1.php"] [unique_id "apPkYUmtdPfUFP1akVFE_gAABIA"]
[Sun Aug 30 03:05:53.125638 2026] [security2:error] [pid 495314:tid 495539] [client 20.48.160.90:33190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/robot.php"] [unique_id "apPkYUmtdPfUFP1akVFE_wAABIc"]
[Sun Aug 30 03:05:53.175158 2026] [security2:error] [pid 495314:tid 495569] [client 20.104.49.130:42197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/xmini4.php"] [unique_id "apPkYUmtdPfUFP1akVFFCwAABKU"]
[Sun Aug 30 03:05:53.207971 2026] [security2:error] [pid 495314:tid 495557] [client 20.104.50.220:29314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/shoop.php"] [unique_id "apPkYUmtdPfUFP1akVFFEgAABJk"]
[Sun Aug 30 03:05:53.215178 2026] [security2:error] [pid 495314:tid 495472] [client 20.48.160.90:40051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/gulu.php"] [unique_id "apPkYUmtdPfUFP1akVFFFAAABEQ"]
[Sun Aug 30 03:05:53.216776 2026] [authz_core:error] [pid 495314:tid 495535] [client 216.73.216.128:32444] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:53.217208 2026] [authz_core:error] [pid 495314:tid 495535] [client 216.73.216.128:32444] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:53.221628 2026] [security2:error] [pid 495314:tid 495445] [client 20.151.200.44:55624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkYUmtdPfUFP1akVFFGAAABCk"]
[Sun Aug 30 03:05:53.260677 2026] [security2:error] [pid 495314:tid 495513] [client 40.83.93.50:12050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/admin.php"] [unique_id "apPkYUmtdPfUFP1akVFFJwAABG0"]
[Sun Aug 30 03:05:53.265381 2026] [security2:error] [pid 495314:tid 495541] [client 20.48.251.3:55736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/requirements.php"] [unique_id "apPkYUmtdPfUFP1akVFFLwAABIk"]
[Sun Aug 30 03:05:53.286001 2026] [security2:error] [pid 495314:tid 495472] [client 20.104.18.15:43927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/mgrr.php"] [unique_id "apPkYUmtdPfUFP1akVFFOAAABEQ"]
[Sun Aug 30 03:05:53.348266 2026] [security2:error] [pid 495314:tid 495555] [client 20.48.160.90:39990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/gtghklk.php"] [unique_id "apPkYUmtdPfUFP1akVFFSQAABJc"]
[Sun Aug 30 03:05:53.367214 2026] [security2:error] [pid 495314:tid 495523] [client 20.48.251.3:46270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/tax.php"] [unique_id "apPkYUmtdPfUFP1akVFFUgAABHc"]
[Sun Aug 30 03:05:53.384920 2026] [security2:error] [pid 495314:tid 495533] [client 20.104.49.130:58061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/xmini4.php"] [unique_id "apPkYUmtdPfUFP1akVFFVQAABIE"]
[Sun Aug 30 03:05:53.408187 2026] [security2:error] [pid 495314:tid 495565] [client 20.48.160.90:33243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/revo.php"] [unique_id "apPkYUmtdPfUFP1akVFFXAAABKE"]
[Sun Aug 30 03:05:53.458272 2026] [security2:error] [pid 495314:tid 495520] [client 20.151.200.44:47383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/file66.php"] [unique_id "apPkYUmtdPfUFP1akVFFaQAABHQ"]
[Sun Aug 30 03:05:53.471138 2026] [security2:error] [pid 495314:tid 495548] [client 20.104.18.15:32970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/inx.php"] [unique_id "apPkYUmtdPfUFP1akVFFawAABJA"]
[Sun Aug 30 03:05:53.478060 2026] [security2:error] [pid 495314:tid 495555] [client 20.48.160.90:45848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/comand.php"] [unique_id "apPkYUmtdPfUFP1akVFFbQAABJc"]
[Sun Aug 30 03:05:53.487986 2026] [authz_core:error] [pid 495314:tid 495559] [client 216.73.216.128:32444] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:53.488236 2026] [authz_core:error] [pid 495314:tid 495559] [client 216.73.216.128:32444] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:53.503635 2026] [security2:error] [pid 495314:tid 495463] [client 20.63.219.114:1423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/leaf.php"] [unique_id "apPkYUmtdPfUFP1akVFFfAAABDs"]
[Sun Aug 30 03:05:53.513982 2026] [authz_core:error] [pid 495314:tid 495454] [client 66.249.66.195:47602] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:53.514414 2026] [authz_core:error] [pid 495314:tid 495454] [client 66.249.66.195:47602] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:53.538012 2026] [security2:error] [pid 495314:tid 495480] [client 20.104.50.220:42786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/da111.php"] [unique_id "apPkYUmtdPfUFP1akVFFjwAABEw"]
[Sun Aug 30 03:05:53.543265 2026] [security2:error] [pid 495314:tid 495520] [client 20.48.160.90:50569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/birrs.php"] [unique_id "apPkYUmtdPfUFP1akVFFkAAABHQ"]
[Sun Aug 30 03:05:53.559384 2026] [security2:error] [pid 495314:tid 495468] [client 20.104.50.220:32876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/cargo.php"] [unique_id "apPkYUmtdPfUFP1akVFFlwAABEA"]
[Sun Aug 30 03:05:53.579171 2026] [authz_core:error] [pid 495314:tid 495547] [client 216.73.216.128:33529] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:53.579450 2026] [authz_core:error] [pid 495314:tid 495547] [client 216.73.216.128:33529] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:53.585599 2026] [security2:error] [pid 495314:tid 495519] [client 20.104.18.15:13719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/ffs.php"] [unique_id "apPkYUmtdPfUFP1akVFFngAABHM"]
[Sun Aug 30 03:05:53.610248 2026] [security2:error] [pid 495314:tid 495541] [client 20.48.160.90:40044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp_motu_myk3v.php"] [unique_id "apPkYUmtdPfUFP1akVFFpwAABIk"]
[Sun Aug 30 03:05:53.670521 2026] [authz_core:error] [pid 495314:tid 495468] [client 216.73.216.128:32409] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:53.670807 2026] [authz_core:error] [pid 495314:tid 495468] [client 216.73.216.128:32409] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:53.685515 2026] [security2:error] [pid 495314:tid 495533] [client 68.155.159.216:56419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/file.php"] [unique_id "apPkYUmtdPfUFP1akVFFuwAABIE"]
[Sun Aug 30 03:05:53.721378 2026] [authz_core:error] [pid 495314:tid 495548] [client 66.249.66.197:57957] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:53.721698 2026] [authz_core:error] [pid 495314:tid 495548] [client 66.249.66.197:57957] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:53.742078 2026] [security2:error] [pid 495314:tid 495535] [client 20.48.160.90:40047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/wp_motu_ypdat.php"] [unique_id "apPkYUmtdPfUFP1akVFFxAAABIM"]
[Sun Aug 30 03:05:53.758639 2026] [security2:error] [pid 495314:tid 495444] [client 40.83.93.50:18058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/index.php"] [unique_id "apPkYUmtdPfUFP1akVFFxgAABCg"]
[Sun Aug 30 03:05:53.761267 2026] [security2:error] [pid 495314:tid 495482] [client 20.48.160.90:33201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/sss.php"] [unique_id "apPkYUmtdPfUFP1akVFFxwAABE4"]
[Sun Aug 30 03:05:53.875560 2026] [security2:error] [pid 495314:tid 495509] [client 20.48.160.90:45916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/edit.php"] [unique_id "apPkYUmtdPfUFP1akVFF6wAABGk"]
[Sun Aug 30 03:05:53.890474 2026] [security2:error] [pid 495314:tid 495487] [client 20.63.219.114:9638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/k.php"] [unique_id "apPkYUmtdPfUFP1akVFF7gAABFM"]
[Sun Aug 30 03:05:53.900255 2026] [security2:error] [pid 495314:tid 495527] [client 20.104.50.220:62262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/sc.php"] [unique_id "apPkYUmtdPfUFP1akVFF8AAABHs"]
[Sun Aug 30 03:05:53.937906 2026] [security2:error] [pid 495314:tid 495512] [client 216.73.216.128:32409] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPkYUmtdPfUFP1akVFF_gAABGw"]
[Sun Aug 30 03:05:53.961358 2026] [security2:error] [pid 495314:tid 495538] [client 68.155.159.216:65500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apPkYUmtdPfUFP1akVFGBgAABIY"]
[Sun Aug 30 03:05:53.982979 2026] [security2:error] [pid 495314:tid 495522] [client 20.104.50.220:27118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/classwithtostring.php"] [unique_id "apPkYUmtdPfUFP1akVFGFgAABHY"]
[Sun Aug 30 03:05:53.994209 2026] [security2:error] [pid 495314:tid 495454] [client 68.155.159.216:52677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apPkYUmtdPfUFP1akVFGHAAABDI"]
[Sun Aug 30 03:05:54.009908 2026] [security2:error] [pid 495314:tid 495447] [client 20.48.160.90:45828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/tqkdqbbv.php"] [unique_id "apPkYkmtdPfUFP1akVFGJAAABCs"]
[Sun Aug 30 03:05:54.014296 2026] [authz_core:error] [pid 495314:tid 495504] [client 66.249.66.199:61444] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:54.014760 2026] [authz_core:error] [pid 495314:tid 495504] [client 66.249.66.199:61444] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:54.018401 2026] [security2:error] [pid 495314:tid 495518] [client 20.104.50.220:46350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/doc.php"] [unique_id "apPkYkmtdPfUFP1akVFGKQAABHI"]
[Sun Aug 30 03:05:54.037144 2026] [security2:error] [pid 495314:tid 495498] [client 20.151.200.44:63623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/admin.php/007x.php"] [unique_id "apPkYkmtdPfUFP1akVFGMwAABF4"]
[Sun Aug 30 03:05:54.069948 2026] [security2:error] [pid 495314:tid 495455] [client 20.48.160.90:50625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/wp-content/themes/gaukingo/index.php"] [unique_id "apPkYkmtdPfUFP1akVFGPwAABDM"]
[Sun Aug 30 03:05:54.076525 2026] [security2:error] [pid 495314:tid 495541] [client 20.104.50.220:52841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/s_on.php"] [unique_id "apPkYkmtdPfUFP1akVFGRAAABIk"]
[Sun Aug 30 03:05:54.160239 2026] [security2:error] [pid 495314:tid 495483] [client 20.48.160.90:39948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/kjyehoxl.php"] [unique_id "apPkYkmtdPfUFP1akVFGYQAABE8"]
[Sun Aug 30 03:05:54.161454 2026] [security2:error] [pid 495314:tid 495457] [client 3.12.251.153:20660] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "omconsulting-group.com"] [uri "/index.php"] [unique_id "apPkYEmtdPfUFP1akVFEfgAABDU"], referer: https://omconsulting-group.com
[Sun Aug 30 03:05:54.168342 2026] [security2:error] [pid 495314:tid 495553] [client 68.155.159.216:54093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/about.php"] [unique_id "apPkYkmtdPfUFP1akVFGYwAABJU"]
[Sun Aug 30 03:05:54.183641 2026] [security2:error] [pid 495314:tid 495554] [client 20.48.251.3:44335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/sgd.php"] [unique_id "apPkYkmtdPfUFP1akVFGaAAABJY"]
[Sun Aug 30 03:05:54.203457 2026] [security2:error] [pid 495314:tid 495560] [client 20.104.50.220:32123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/0x0.php"] [unique_id "apPkYkmtdPfUFP1akVFGcQAABJw"]
[Sun Aug 30 03:05:54.204914 2026] [security2:error] [pid 495314:tid 495473] [client 20.48.251.3:22769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPkYkmtdPfUFP1akVFGcgAABEU"]
[Sun Aug 30 03:05:54.213508 2026] [security2:error] [pid 495314:tid 495518] [client 20.104.50.220:5550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/520.php"] [unique_id "apPkYkmtdPfUFP1akVFGeAAABHI"]
[Sun Aug 30 03:05:54.220803 2026] [security2:error] [pid 495314:tid 495512] [client 68.155.159.216:63533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/file88.php"] [unique_id "apPkYkmtdPfUFP1akVFGfAAABGw"]
[Sun Aug 30 03:05:54.240445 2026] [security2:error] [pid 495314:tid 495509] [client 40.83.93.50:12065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/php8.php"] [unique_id "apPkYkmtdPfUFP1akVFGhQAABGk"]
[Sun Aug 30 03:05:54.243291 2026] [security2:error] [pid 495314:tid 495533] [client 20.48.160.90:33249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/wp-includes/ID3/moon.php"] [unique_id "apPkYkmtdPfUFP1akVFGiAAABIE"]
[Sun Aug 30 03:05:54.259463 2026] [security2:error] [pid 495314:tid 495466] [client 20.48.251.3:7374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/hochladen.form.php"] [unique_id "apPkYkmtdPfUFP1akVFGjgAABD4"]
[Sun Aug 30 03:05:54.260024 2026] [security2:error] [pid 495314:tid 495457] [client 20.48.251.3:55504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/aws_sdk_settings.php"] [unique_id "apPkYkmtdPfUFP1akVFGjwAABDU"]
[Sun Aug 30 03:05:54.269951 2026] [authz_core:error] [pid 495314:tid 495485] [client 66.249.66.196:57344] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:54.270227 2026] [authz_core:error] [pid 495314:tid 495485] [client 66.249.66.196:57344] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:54.276311 2026] [security2:error] [pid 495314:tid 495529] [client 20.151.200.44:46985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/wp-ver.php"] [unique_id "apPkYkmtdPfUFP1akVFGmgAABH0"]
[Sun Aug 30 03:05:54.292051 2026] [security2:error] [pid 495314:tid 495459] [client 20.48.160.90:45862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/llyuxaqd.php"] [unique_id "apPkYkmtdPfUFP1akVFGpwAABDc"]
[Sun Aug 30 03:05:54.310702 2026] [security2:error] [pid 495314:tid 495486] [client 68.155.159.216:61364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/goods.php"] [unique_id "apPkYkmtdPfUFP1akVFGrAAABFI"]
[Sun Aug 30 03:05:54.392290 2026] [security2:error] [pid 495314:tid 495476] [client 20.104.50.220:62830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wsa.php"] [unique_id "apPkYkmtdPfUFP1akVFG0wAABEg"]
[Sun Aug 30 03:05:54.410524 2026] [security2:error] [pid 495314:tid 495561] [client 20.48.251.3:55733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/var/www/wallet/index.php"] [unique_id "apPkYkmtdPfUFP1akVFG3wAABJ0"]
[Sun Aug 30 03:05:54.430745 2026] [security2:error] [pid 495314:tid 495454] [client 20.104.18.15:44026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/mac.php"] [unique_id "apPkYkmtdPfUFP1akVFG5wAABDI"]
[Sun Aug 30 03:05:54.431766 2026] [security2:error] [pid 495314:tid 495459] [client 20.48.160.90:26724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/nbwxolou.php"] [unique_id "apPkYkmtdPfUFP1akVFG6AAABDc"]
[Sun Aug 30 03:05:54.435128 2026] [security2:error] [pid 495314:tid 495456] [client 20.63.219.114:9654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/chosen.php"] [unique_id "apPkYkmtdPfUFP1akVFG6QAABDQ"]
[Sun Aug 30 03:05:54.446360 2026] [security2:error] [pid 495314:tid 495444] [client 20.48.160.90:50652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/xmini4.php"] [unique_id "apPkYkmtdPfUFP1akVFG7AAABCg"]
[Sun Aug 30 03:05:54.479671 2026] [security2:error] [pid 495314:tid 495520] [client 20.151.200.44:37827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/xwpg.php"] [unique_id "apPkYkmtdPfUFP1akVFG8AAABHQ"]
[Sun Aug 30 03:05:54.573765 2026] [security2:error] [pid 495314:tid 495493] [client 20.48.160.90:45905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/nsxeubyv.php"] [unique_id "apPkYkmtdPfUFP1akVFHFAAABFk"]
[Sun Aug 30 03:05:54.614226 2026] [security2:error] [pid 495314:tid 495460] [client 20.104.18.15:33012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/vpn.php"] [unique_id "apPkYkmtdPfUFP1akVFHKwAABDg"]
[Sun Aug 30 03:05:54.662622 2026] [security2:error] [pid 495314:tid 495506] [client 3.12.251.153:20674] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "omconsulting-group.com"] [uri "/index.php"] [unique_id "apPkYkmtdPfUFP1akVFGqwAABGY"], referer: https://omconsulting-group.com
[Sun Aug 30 03:05:54.685673 2026] [security2:error] [pid 495314:tid 495539] [client 20.48.251.3:46258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPkYkmtdPfUFP1akVFHRwAABIc"]
[Sun Aug 30 03:05:54.707913 2026] [security2:error] [pid 495314:tid 495540] [client 20.104.50.220:33029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/col1.php"] [unique_id "apPkYkmtdPfUFP1akVFHSgAABIg"]
[Sun Aug 30 03:05:54.710810 2026] [security2:error] [pid 495314:tid 495562] [client 20.48.160.90:40056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/zfqipfss.php"] [unique_id "apPkYkmtdPfUFP1akVFHTAAABJ4"]
[Sun Aug 30 03:05:54.718027 2026] [security2:error] [pid 495314:tid 495454] [client 40.83.93.50:18082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/function.php"] [unique_id "apPkYkmtdPfUFP1akVFHTgAABDI"]
[Sun Aug 30 03:05:54.724111 2026] [security2:error] [pid 495314:tid 495453] [client 20.104.18.15:13664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/nano.php"] [unique_id "apPkYkmtdPfUFP1akVFHTwAABDE"]
[Sun Aug 30 03:05:54.765859 2026] [authz_core:error] [pid 495314:tid 495550] [client 216.73.216.128:15344] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:54.766114 2026] [authz_core:error] [pid 495314:tid 495550] [client 216.73.216.128:15344] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:54.777906 2026] [authz_core:error] [pid 495314:tid 495495] [client 66.249.66.35:54722] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:54.778164 2026] [authz_core:error] [pid 495314:tid 495495] [client 66.249.66.35:54722] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:54.783546 2026] [security2:error] [pid 495314:tid 495505] [client 20.48.160.90:50568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/gulu.php"] [unique_id "apPkYkmtdPfUFP1akVFHXgAABGU"]
[Sun Aug 30 03:05:54.796315 2026] [security2:error] [pid 495314:tid 495522] [client 68.155.159.216:56347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/file17.php"] [unique_id "apPkYkmtdPfUFP1akVFHZQAABHY"]
[Sun Aug 30 03:05:54.822401 2026] [security2:error] [pid 495314:tid 495525] [client 20.63.219.114:18548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/radio.php"] [unique_id "apPkYkmtdPfUFP1akVFHcQAABHk"]
[Sun Aug 30 03:05:54.838564 2026] [security2:error] [pid 495314:tid 495473] [client 20.48.160.90:26723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.appsneakpeek.com"] [uri "/zrjuyoos.php"] [unique_id "apPkYkmtdPfUFP1akVFHewAABEU"]
[Sun Aug 30 03:05:54.930863 2026] [security2:error] [pid 495314:tid 495511] [client 20.104.50.220:51528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/DA.php"] [unique_id "apPkYkmtdPfUFP1akVFHmQAABGs"]
[Sun Aug 30 03:05:54.984723 2026] [security2:error] [pid 495314:tid 495453] [client 20.48.160.90:33219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/replace.php"] [unique_id "apPkYkmtdPfUFP1akVFHrAAABDE"]
[Sun Aug 30 03:05:55.011864 2026] [authz_core:error] [pid 495314:tid 495519] [client 66.249.66.73:46976] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:55.012130 2026] [authz_core:error] [pid 495314:tid 495519] [client 66.249.66.73:46976] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:55.106250 2026] [security2:error] [pid 495314:tid 495565] [client 20.104.50.220:61957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/fvck.php"] [unique_id "apPkY0mtdPfUFP1akVFH6AAABKE"]
[Sun Aug 30 03:05:55.122445 2026] [security2:error] [pid 495314:tid 495528] [client 216.73.216.128:33529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPkY0mtdPfUFP1akVFH8QAABHw"]
[Sun Aug 30 03:05:55.126492 2026] [security2:error] [pid 495314:tid 495538] [client 20.104.50.220:27431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/images.php"] [unique_id "apPkY0mtdPfUFP1akVFH9QAABIY"]
[Sun Aug 30 03:05:55.136981 2026] [security2:error] [pid 495314:tid 495482] [client 68.155.159.216:65503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/chosen.php"] [unique_id "apPkY0mtdPfUFP1akVFH-wAABE4"]
[Sun Aug 30 03:05:55.172574 2026] [security2:error] [pid 495314:tid 495491] [client 20.104.50.220:46376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/docindex.php"] [unique_id "apPkY0mtdPfUFP1akVFIDAAABFc"]
[Sun Aug 30 03:05:55.189771 2026] [security2:error] [pid 495314:tid 495417] [remote 60.136.93.49:34194] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "tastylandscape.com"] [uri "/wp-content/plugins/burst-statistics/endpoint.php"] [unique_id "apPkY0mtdPfUFP1akVFIEQAEimY"], referer: https://tastylandscape.com/2014/11/29/best-way-propagate-geranium/
[Sun Aug 30 03:05:55.212249 2026] [security2:error] [pid 495314:tid 495549] [client 20.63.219.114:9656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/functions.php"] [unique_id "apPkY0mtdPfUFP1akVFIHAAABJE"]
[Sun Aug 30 03:05:55.227240 2026] [security2:error] [pid 495314:tid 495450] [client 40.83.93.50:9082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/about.php"] [unique_id "apPkY0mtdPfUFP1akVFIJAAABC4"]
[Sun Aug 30 03:05:55.231466 2026] [security2:error] [pid 495314:tid 495490] [client 20.104.50.220:29572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/selaras.php"] [unique_id "apPkY0mtdPfUFP1akVFIKgAABFY"]
[Sun Aug 30 03:05:55.275451 2026] [security2:error] [pid 495314:tid 495563] [client 68.155.159.216:54101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apPkY0mtdPfUFP1akVFIPwAABJ8"]
[Sun Aug 30 03:05:55.342453 2026] [security2:error] [pid 495314:tid 495540] [client 20.48.251.3:22747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/agg.php"] [unique_id "apPkY0mtdPfUFP1akVFIawAABIg"]
[Sun Aug 30 03:05:55.351021 2026] [security2:error] [pid 495314:tid 495508] [client 20.104.50.220:31895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/0z.php"] [unique_id "apPkY0mtdPfUFP1akVFIbwAABGg"]
[Sun Aug 30 03:05:55.352742 2026] [security2:error] [pid 495314:tid 495561] [client 20.104.50.220:6113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/ar.php"] [unique_id "apPkY0mtdPfUFP1akVFIcAAABJ0"]
[Sun Aug 30 03:05:55.365608 2026] [security2:error] [pid 495314:tid 495447] [client 68.155.159.216:52615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPkY0mtdPfUFP1akVFIeQAABCs"]
[Sun Aug 30 03:05:55.372835 2026] [security2:error] [pid 495314:tid 495506] [client 20.48.251.3:4731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/fleen.php"] [unique_id "apPkY0mtdPfUFP1akVFIfgAABGY"]
[Sun Aug 30 03:05:55.379042 2026] [authz_core:error] [pid 495314:tid 495479] [client 66.249.66.35:61236] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:55.379521 2026] [authz_core:error] [pid 495314:tid 495479] [client 66.249.66.35:61236] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:55.399374 2026] [security2:error] [pid 495314:tid 495569] [client 20.48.251.3:49921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/setup-config.php"] [unique_id "apPkY0mtdPfUFP1akVFIjAAABKU"]
[Sun Aug 30 03:05:55.421329 2026] [security2:error] [pid 495314:tid 495475] [client 20.48.251.3:7080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/debuggen.php"] [unique_id "apPkY0mtdPfUFP1akVFImQAABEc"]
[Sun Aug 30 03:05:55.473649 2026] [authz_core:error] [pid 495314:tid 495502] [client 66.249.66.65:59286] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:55.473928 2026] [authz_core:error] [pid 495314:tid 495502] [client 66.249.66.65:59286] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:55.499799 2026] [security2:error] [pid 495314:tid 495556] [client 74.7.243.204:34678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/new/"] [unique_id "apPkY0mtdPfUFP1akVFIrwAABJg"], referer: http://mail.letter7brands.com/new/?p=%2F%2Fetc
[Sun Aug 30 03:05:55.512765 2026] [security2:error] [pid 495314:tid 495462] [client 68.155.159.216:61374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apPkY0mtdPfUFP1akVFIsgAABDo"]
[Sun Aug 30 03:05:55.555787 2026] [security2:error] [pid 495314:tid 495478] [client 20.48.251.3:59383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/124.php"] [unique_id "apPkY0mtdPfUFP1akVFIwwAABEo"]
[Sun Aug 30 03:05:55.557881 2026] [authz_core:error] [pid 495314:tid 495559] [client 66.249.66.195:65484] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:55.558301 2026] [authz_core:error] [pid 495314:tid 495559] [client 66.249.66.195:65484] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:55.562738 2026] [security2:error] [pid 495314:tid 495465] [client 20.104.50.220:29182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/22625814acb09634e45d67c98c55a6a2f6e2532c_0.file.painel.html.php"] [unique_id "apPkY0mtdPfUFP1akVFIxwAABD0"]
[Sun Aug 30 03:05:55.570920 2026] [security2:error] [pid 495314:tid 495560] [client 20.63.219.114:14427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/elp.php"] [unique_id "apPkY0mtdPfUFP1akVFIygAABJw"]
[Sun Aug 30 03:05:55.583534 2026] [authz_core:error] [pid 495314:tid 495554] [client 216.73.216.128:32409] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:55.583854 2026] [authz_core:error] [pid 495314:tid 495554] [client 216.73.216.128:32409] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:55.616622 2026] [security2:error] [pid 495314:tid 495530] [client 20.104.18.15:43986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/simple.php"] [unique_id "apPkY0mtdPfUFP1akVFI3gAABH4"]
[Sun Aug 30 03:05:55.745636 2026] [security2:error] [pid 495314:tid 495503] [client 40.83.93.50:18056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/new.php"] [unique_id "apPkY0mtdPfUFP1akVFJBQAABGM"]
[Sun Aug 30 03:05:55.798839 2026] [security2:error] [pid 495314:tid 495520] [client 20.104.18.15:32963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/shiny.php"] [unique_id "apPkY0mtdPfUFP1akVFJGAAABHQ"]
[Sun Aug 30 03:05:55.844479 2026] [security2:error] [pid 495314:tid 495556] [client 20.104.50.220:33317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/coli.php"] [unique_id "apPkY0mtdPfUFP1akVFJKwAABJg"]
[Sun Aug 30 03:05:55.861058 2026] [security2:error] [pid 495314:tid 495454] [client 20.104.18.15:13583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/ano.php"] [unique_id "apPkY0mtdPfUFP1akVFJOAAABDI"]
[Sun Aug 30 03:05:55.926397 2026] [security2:error] [pid 495314:tid 495544] [client 68.155.159.216:56439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/file5.php"] [unique_id "apPkY0mtdPfUFP1akVFJTwAABIw"]
[Sun Aug 30 03:05:55.928509 2026] [security2:error] [pid 495314:tid 495565] [client 20.48.251.3:64279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPkY0mtdPfUFP1akVFJUAAABKE"]
[Sun Aug 30 03:05:55.948892 2026] [authz_core:error] [pid 495314:tid 495567] [client 216.73.216.128:32409] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:55.949184 2026] [authz_core:error] [pid 495314:tid 495567] [client 216.73.216.128:32409] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:55.977126 2026] [authz_core:error] [pid 495314:tid 495478] [client 66.249.66.194:53219] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:55.977434 2026] [authz_core:error] [pid 495314:tid 495478] [client 66.249.66.194:53219] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:55.997808 2026] [security2:error] [pid 495314:tid 495508] [client 20.104.49.130:45730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/xwpg.php"] [unique_id "apPkY0mtdPfUFP1akVFJcQAABGg"]
[Sun Aug 30 03:05:56.105589 2026] [security2:error] [pid 495314:tid 495457] [client 20.63.219.114:18507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/options-reading.php"] [unique_id "apPkZEmtdPfUFP1akVFJpQAABDU"]
[Sun Aug 30 03:05:56.117530 2026] [security2:error] [pid 495314:tid 495415] [remote 51.89.83.144:28194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.83.89.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "calchampsoccer.calchampsoccer.org"] [uri "/images/images/cache.php"] [unique_id "apPkZEmtdPfUFP1akVFJqwAEP2Q"]
[Sun Aug 30 03:05:56.131892 2026] [security2:error] [pid 495314:tid 495445] [client 20.104.50.220:63492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/bismilah.php"] [unique_id "apPkZEmtdPfUFP1akVFJswAABCk"]
[Sun Aug 30 03:05:56.134423 2026] [security2:error] [pid 495314:tid 495482] [client 216.73.216.128:32409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mysqlupgrade"] [unique_id "apPkZEmtdPfUFP1akVFJtgAABE4"]
[Sun Aug 30 03:05:56.188882 2026] [security2:error] [pid 495314:tid 495497] [client 20.220.204.93:64153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkZEmtdPfUFP1akVFJ0AAABF0"]
[Sun Aug 30 03:05:56.250580 2026] [security2:error] [pid 495314:tid 495450] [client 68.155.159.216:65523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/goods.php"] [unique_id "apPkZEmtdPfUFP1akVFJ9gAABC4"]
[Sun Aug 30 03:05:56.263771 2026] [security2:error] [pid 495314:tid 495511] [client 20.104.50.220:27122] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/1.php"] [unique_id "apPkZEmtdPfUFP1akVFJ_gAABGs"]
[Sun Aug 30 03:05:56.263868 2026] [security2:error] [pid 495314:tid 495511] [client 20.104.50.220:27122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/1.php"] [unique_id "apPkZEmtdPfUFP1akVFJ_gAABGs"]
[Sun Aug 30 03:05:56.275773 2026] [security2:error] [pid 495314:tid 495536] [client 20.104.50.220:61964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/0x.php"] [unique_id "apPkZEmtdPfUFP1akVFKCQAABIQ"]
[Sun Aug 30 03:05:56.282824 2026] [security2:error] [pid 495314:tid 495541] [client 68.155.159.216:63527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/NewFile.php/"] [unique_id "apPkZEmtdPfUFP1akVFKDwAABIk"]
[Sun Aug 30 03:05:56.328346 2026] [security2:error] [pid 495314:tid 495568] [client 20.220.204.93:64222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkZEmtdPfUFP1akVFKMQAABKQ"]
[Sun Aug 30 03:05:56.339385 2026] [security2:error] [pid 495314:tid 495457] [client 20.104.50.220:47052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/dosya.php"] [unique_id "apPkZEmtdPfUFP1akVFKOgAABDU"]
[Sun Aug 30 03:05:56.343594 2026] [security2:error] [pid 495314:tid 495521] [client 40.83.93.50:8577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/goods.php"] [unique_id "apPkZEmtdPfUFP1akVFKPQAABHU"]
[Sun Aug 30 03:05:56.469622 2026] [security2:error] [pid 495314:tid 495495] [client 114.119.129.235:38655] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "servifabrickvhr.com.pe"] [uri "/lfkoj/two-plus-two-equals-four-1984.html"] [unique_id "apPkZEmtdPfUFP1akVFKdQAABFs"], referer: https://servifabrickvhr.com.pe/lfkoj/two-plus-two-equals-four-1984.html
[Sun Aug 30 03:05:56.471464 2026] [security2:error] [pid 495314:tid 495447] [client 20.220.204.93:64133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/ff1.php"] [unique_id "apPkZEmtdPfUFP1akVFKeAAABCs"]
[Sun Aug 30 03:05:56.473005 2026] [security2:error] [pid 495314:tid 495540] [client 68.155.159.216:19442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/images/index.php"] [unique_id "apPkZEmtdPfUFP1akVFKeQAABIg"]
[Sun Aug 30 03:05:56.483533 2026] [security2:error] [pid 495314:tid 495499] [client 68.155.159.216:60001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/themes.php"] [unique_id "apPkZEmtdPfUFP1akVFKgAAABF8"]
[Sun Aug 30 03:05:56.494254 2026] [security2:error] [pid 495314:tid 495534] [client 20.63.219.114:1444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/db.php"] [unique_id "apPkZEmtdPfUFP1akVFKiAAABII"]
[Sun Aug 30 03:05:56.496015 2026] [security2:error] [pid 495314:tid 495554] [client 20.104.50.220:32557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/13.php"] [unique_id "apPkZEmtdPfUFP1akVFKiwAABJY"]
[Sun Aug 30 03:05:56.504927 2026] [security2:error] [pid 495314:tid 495533] [client 20.104.50.220:6143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/x.php"] [unique_id "apPkZEmtdPfUFP1akVFKkgAABIE"]
[Sun Aug 30 03:05:56.505186 2026] [security2:error] [pid 495314:tid 495502] [client 20.104.50.220:62806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/ssh.php"] [unique_id "apPkZEmtdPfUFP1akVFKkwAABGI"]
[Sun Aug 30 03:05:56.508561 2026] [security2:error] [pid 495314:tid 495529] [client 20.104.104.62:22085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkZEmtdPfUFP1akVFKlAAABH0"]
[Sun Aug 30 03:05:56.520092 2026] [authz_core:error] [pid 495314:tid 495565] [client 66.249.66.195:40511] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:56.520554 2026] [authz_core:error] [pid 495314:tid 495565] [client 66.249.66.195:40511] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:56.529346 2026] [security2:error] [pid 495314:tid 495450] [client 20.48.251.3:5057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/upload.form.php"] [unique_id "apPkZEmtdPfUFP1akVFKnwAABC4"]
[Sun Aug 30 03:05:56.529574 2026] [security2:error] [pid 495314:tid 495556] [client 20.48.251.3:23050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/requirements.php"] [unique_id "apPkZEmtdPfUFP1akVFKoAAABJg"]
[Sun Aug 30 03:05:56.539588 2026] [security2:error] [pid 495314:tid 495470] [client 74.7.243.204:34678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/site/"] [unique_id "apPkZEmtdPfUFP1akVFKpAAABEI"], referer: http://mail.letter7brands.com/site/?p=%2F%2Fetc
[Sun Aug 30 03:05:56.557969 2026] [security2:error] [pid 495314:tid 495481] [client 20.48.251.3:45824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/pouhg.php"] [unique_id "apPkZEmtdPfUFP1akVFKrwAABE0"]
[Sun Aug 30 03:05:56.565329 2026] [security2:error] [pid 495314:tid 495505] [client 20.48.251.3:50019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/wp-admin/sc.php"] [unique_id "apPkZEmtdPfUFP1akVFKswAABGU"]
[Sun Aug 30 03:05:56.576224 2026] [security2:error] [pid 495314:tid 495434] [remote 192.250.232.93:48888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.232.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "iwd.chg.temporary.site"] [uri "/wp-login.php"] [unique_id "apPkZEmtdPfUFP1akVFKtgAEpnc"]
[Sun Aug 30 03:05:56.607391 2026] [security2:error] [pid 495314:tid 495568] [client 20.220.204.93:64157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/t.php"] [unique_id "apPkZEmtdPfUFP1akVFKxAAABKQ"]
[Sun Aug 30 03:05:56.611272 2026] [authz_core:error] [pid 495314:tid 495459] [client 66.249.66.34:43943] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:56.611700 2026] [authz_core:error] [pid 495314:tid 495459] [client 66.249.66.34:43943] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:56.655981 2026] [security2:error] [pid 495314:tid 495456] [client 68.155.159.216:63979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apPkZEmtdPfUFP1akVFK1QAABDQ"]
[Sun Aug 30 03:05:56.684940 2026] [security2:error] [pid 495314:tid 495519] [client 20.48.251.3:52745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/test1.php"] [unique_id "apPkZEmtdPfUFP1akVFK6QAABHM"]
[Sun Aug 30 03:05:56.686508 2026] [authz_core:error] [pid 495314:tid 495531] [client 216.73.216.128:32444] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:56.686779 2026] [authz_core:error] [pid 495314:tid 495531] [client 216.73.216.128:32444] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:56.699041 2026] [security2:error] [pid 495314:tid 495534] [client 20.104.104.62:21744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkZEmtdPfUFP1akVFK7QAABII"]
[Sun Aug 30 03:05:56.700952 2026] [security2:error] [pid 495314:tid 495568] [client 20.104.50.220:62806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/m4m4nkmud4.php"] [unique_id "apPkZEmtdPfUFP1akVFK7gAABKQ"]
[Sun Aug 30 03:05:56.751306 2026] [security2:error] [pid 495314:tid 495506] [client 20.220.204.93:64212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/erty.php"] [unique_id "apPkZEmtdPfUFP1akVFK_wAABGY"]
[Sun Aug 30 03:05:56.804037 2026] [security2:error] [pid 495314:tid 495536] [client 20.104.18.15:43276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/xty.php"] [unique_id "apPkZEmtdPfUFP1akVFLFAAABIQ"]
[Sun Aug 30 03:05:56.887254 2026] [security2:error] [pid 495314:tid 495560] [client 40.83.93.50:9280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/m.php"] [unique_id "apPkZEmtdPfUFP1akVFLRgAABJw"]
[Sun Aug 30 03:05:56.891958 2026] [security2:error] [pid 495314:tid 495549] [client 20.220.204.93:64194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/0x.php"] [unique_id "apPkZEmtdPfUFP1akVFLSQAABJE"]
[Sun Aug 30 03:05:56.908960 2026] [security2:error] [pid 495314:tid 495453] [client 20.104.49.130:48522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/xwpg.php"] [unique_id "apPkZEmtdPfUFP1akVFLVQAABDE"]
[Sun Aug 30 03:05:56.914202 2026] [security2:error] [pid 495314:tid 495550] [client 20.63.219.114:15129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/server.php"] [unique_id "apPkZEmtdPfUFP1akVFLVwAABJI"]
[Sun Aug 30 03:05:56.921132 2026] [authz_core:error] [pid 495314:tid 495519] [client 216.73.216.128:49464] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:56.921418 2026] [authz_core:error] [pid 495314:tid 495519] [client 216.73.216.128:49464] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:56.945249 2026] [security2:error] [pid 495314:tid 495465] [client 20.151.200.44:47085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/ah24.php"] [unique_id "apPkZEmtdPfUFP1akVFLZAAABD0"]
[Sun Aug 30 03:05:56.949861 2026] [security2:error] [pid 495314:tid 495457] [client 20.104.18.15:33001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/goods.php"] [unique_id "apPkZEmtdPfUFP1akVFLaAAABDU"]
[Sun Aug 30 03:05:56.990351 2026] [security2:error] [pid 495314:tid 495547] [client 20.104.50.220:32838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/cylul.php"] [unique_id "apPkZEmtdPfUFP1akVFLewAABI8"]
[Sun Aug 30 03:05:56.991466 2026] [security2:error] [pid 495314:tid 495462] [client 20.151.200.44:47415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/blnux.php"] [unique_id "apPkZEmtdPfUFP1akVFLfAAABDo"]
[Sun Aug 30 03:05:57.004409 2026] [security2:error] [pid 495314:tid 495538] [client 20.104.18.15:13581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/mgrr.php"] [unique_id "apPkZUmtdPfUFP1akVFLigAABIY"]
[Sun Aug 30 03:05:57.012967 2026] [security2:error] [pid 495314:tid 495525] [client 4.205.62.107:32045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/config/laravolt/css/index.php"] [unique_id "apPkZUmtdPfUFP1akVFLkgAABHk"]
[Sun Aug 30 03:05:57.033787 2026] [security2:error] [pid 495314:tid 495529] [client 20.104.104.62:22099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/h02ugyh.php"] [unique_id "apPkZUmtdPfUFP1akVFLnwAABH0"]
[Sun Aug 30 03:05:57.045701 2026] [security2:error] [pid 495314:tid 495561] [client 20.220.204.93:62283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/66.php"] [unique_id "apPkZUmtdPfUFP1akVFLpwAABJ0"]
[Sun Aug 30 03:05:57.050845 2026] [security2:error] [pid 495314:tid 495441] [remote 192.250.232.93:48888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.232.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "iwd.chg.temporary.site"] [uri "/wp-login.php"] [unique_id "apPkZUmtdPfUFP1akVFLrQAEYH4"], referer: https://iwd.chg.temporary.site/wp-login.php
[Sun Aug 30 03:05:57.052835 2026] [authz_core:error] [pid 495314:tid 495495] [client 216.73.216.128:23351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:57.053107 2026] [authz_core:error] [pid 495314:tid 495495] [client 216.73.216.128:23351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:57.061270 2026] [security2:error] [pid 495314:tid 495490] [client 68.155.159.216:56388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/file88.php"] [unique_id "apPkZUmtdPfUFP1akVFLtQAABFY"]
[Sun Aug 30 03:05:57.073805 2026] [security2:error] [pid 495314:tid 495468] [client 20.48.251.3:46256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/agg.php"] [unique_id "apPkZUmtdPfUFP1akVFLuwAABEA"]
[Sun Aug 30 03:05:57.178556 2026] [security2:error] [pid 495314:tid 495549] [client 20.220.204.93:62293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/f35.php"] [unique_id "apPkZUmtdPfUFP1akVFL8wAABJE"]
[Sun Aug 30 03:05:57.263115 2026] [security2:error] [pid 495314:tid 495460] [client 20.104.49.130:53628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/coffexium.php"] [unique_id "apPkZUmtdPfUFP1akVFMJgAABDg"]
[Sun Aug 30 03:05:57.283315 2026] [security2:error] [pid 495314:tid 495477] [client 20.104.50.220:42018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/.dha.php"] [unique_id "apPkZUmtdPfUFP1akVFMNgAABEk"]
[Sun Aug 30 03:05:57.304931 2026] [authz_core:error] [pid 495314:tid 495444] [client 66.249.66.44:58469] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:57.305243 2026] [authz_core:error] [pid 495314:tid 495444] [client 66.249.66.44:58469] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:57.315083 2026] [security2:error] [pid 495314:tid 495495] [client 20.220.204.93:64187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/wen.php"] [unique_id "apPkZUmtdPfUFP1akVFMTQAABFs"]
[Sun Aug 30 03:05:57.365806 2026] [security2:error] [pid 495314:tid 495555] [client 40.83.93.50:8719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/doc.php"] [unique_id "apPkZUmtdPfUFP1akVFMaAAABJc"]
[Sun Aug 30 03:05:57.382248 2026] [security2:error] [pid 495314:tid 495541] [client 20.63.219.114:9647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/favicon.php"] [unique_id "apPkZUmtdPfUFP1akVFMcQAABIk"]
[Sun Aug 30 03:05:57.384909 2026] [security2:error] [pid 495314:tid 495523] [client 68.155.159.216:65504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apPkZUmtdPfUFP1akVFMcgAABHc"]
[Sun Aug 30 03:05:57.397890 2026] [security2:error] [pid 495314:tid 495487] [client 20.104.104.62:22101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/sf.php"] [unique_id "apPkZUmtdPfUFP1akVFMeQAABFM"]
[Sun Aug 30 03:05:57.399908 2026] [security2:error] [pid 495314:tid 495445] [client 20.151.200.44:63627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/admin.php/heex.php"] [unique_id "apPkZUmtdPfUFP1akVFMegAABCk"]
[Sun Aug 30 03:05:57.401345 2026] [security2:error] [pid 495314:tid 495557] [client 20.104.50.220:27395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/images/wp.php"] [unique_id "apPkZUmtdPfUFP1akVFMfQAABJk"]
[Sun Aug 30 03:05:57.414311 2026] [security2:error] [pid 495314:tid 495513] [client 68.155.159.216:62286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/dropdown.php"] [unique_id "apPkZUmtdPfUFP1akVFMhgAABG0"]
[Sun Aug 30 03:05:57.417244 2026] [authz_core:error] [pid 495314:tid 495480] [client 216.73.216.128:32444] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:57.417504 2026] [authz_core:error] [pid 495314:tid 495480] [client 216.73.216.128:32444] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:57.445230 2026] [security2:error] [pid 495314:tid 495502] [client 20.104.50.220:62011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/up.php5"] [unique_id "apPkZUmtdPfUFP1akVFMlgAABGI"]
[Sun Aug 30 03:05:57.466046 2026] [security2:error] [pid 495314:tid 495535] [client 20.220.204.93:64139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/inc.php"] [unique_id "apPkZUmtdPfUFP1akVFMoQAABIM"]
[Sun Aug 30 03:05:57.483415 2026] [security2:error] [pid 495314:tid 495520] [client 20.104.50.220:47059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/error.php"] [unique_id "apPkZUmtdPfUFP1akVFMqwAABHQ"]
[Sun Aug 30 03:05:57.581560 2026] [security2:error] [pid 495314:tid 495520] [client 68.155.159.216:54761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apPkZUmtdPfUFP1akVFM1wAABHQ"]
[Sun Aug 30 03:05:57.605884 2026] [security2:error] [pid 495314:tid 495452] [client 68.155.159.216:54109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-mail.php"] [unique_id "apPkZUmtdPfUFP1akVFM5gAABDA"]
[Sun Aug 30 03:05:57.611978 2026] [security2:error] [pid 495314:tid 495447] [client 20.220.204.93:64167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/6bcwiqwj.php"] [unique_id "apPkZUmtdPfUFP1akVFM6QAABCs"]
[Sun Aug 30 03:05:57.633856 2026] [security2:error] [pid 495314:tid 495502] [client 20.104.50.220:31933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/1index.php"] [unique_id "apPkZUmtdPfUFP1akVFNAwAABGI"]
[Sun Aug 30 03:05:57.653355 2026] [security2:error] [pid 495314:tid 495472] [client 20.104.50.220:64450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/s4d.php"] [unique_id "apPkZUmtdPfUFP1akVFNCAAABEQ"]
[Sun Aug 30 03:05:57.658979 2026] [security2:error] [pid 495314:tid 495536] [client 20.104.50.220:6104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/xx.php"] [unique_id "apPkZUmtdPfUFP1akVFNCgAABIQ"]
[Sun Aug 30 03:05:57.690925 2026] [authz_core:error] [pid 495314:tid 495532] [client 216.73.216.128:23351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:57.691202 2026] [authz_core:error] [pid 495314:tid 495532] [client 216.73.216.128:23351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:57.696398 2026] [security2:error] [pid 495314:tid 495538] [client 20.48.251.3:23320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/var/www/wallet/index.php"] [unique_id "apPkZUmtdPfUFP1akVFNHgAABIY"]
[Sun Aug 30 03:05:57.697692 2026] [security2:error] [pid 495314:tid 495569] [client 20.48.251.3:45833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/phpversion.php"] [unique_id "apPkZUmtdPfUFP1akVFNIAAABKU"]
[Sun Aug 30 03:05:57.712546 2026] [security2:error] [pid 495314:tid 495562] [client 20.48.251.3:55517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/debug.php"] [unique_id "apPkZUmtdPfUFP1akVFNJgAABJ4"]
[Sun Aug 30 03:05:57.712603 2026] [security2:error] [pid 495314:tid 495508] [client 20.104.49.130:60749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/berlin.php"] [unique_id "apPkZUmtdPfUFP1akVFNJwAABGg"]
[Sun Aug 30 03:05:57.749618 2026] [authz_core:error] [pid 495314:tid 495453] [client 66.249.66.192:53821] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:57.749914 2026] [authz_core:error] [pid 495314:tid 495453] [client 66.249.66.192:53821] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:57.761920 2026] [security2:error] [pid 495314:tid 495522] [client 20.63.219.114:1386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/gecko.php"] [unique_id "apPkZUmtdPfUFP1akVFNNgAABHY"]
[Sun Aug 30 03:05:57.775564 2026] [security2:error] [pid 495314:tid 495479] [client 68.155.159.216:65450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/file.php"] [unique_id "apPkZUmtdPfUFP1akVFNPAAABEs"]
[Sun Aug 30 03:05:57.799012 2026] [security2:error] [pid 495314:tid 495510] [client 20.104.104.62:22096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/4e.php"] [unique_id "apPkZUmtdPfUFP1akVFNRQAABGo"]
[Sun Aug 30 03:05:57.847561 2026] [security2:error] [pid 495314:tid 495509] [client 20.151.200.44:37702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/sxxb.php"] [unique_id "apPkZUmtdPfUFP1akVFNUwAABGk"]
[Sun Aug 30 03:05:57.848854 2026] [security2:error] [pid 495314:tid 495539] [client 20.48.251.3:4691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/aws_auth.php"] [unique_id "apPkZUmtdPfUFP1akVFNVQAABIc"]
[Sun Aug 30 03:05:57.952784 2026] [http2:info] [pid 496962:tid 496962] h2_workers: created with min=128 max=192 idle_ms=600000
[Sun Aug 30 03:05:57.967508 2026] [authz_core:error] [pid 495314:tid 495522] [client 216.73.216.128:32444] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:57.967841 2026] [authz_core:error] [pid 495314:tid 495522] [client 216.73.216.128:32444] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:57.972353 2026] [security2:error] [pid 496962:tid 497092] [client 20.48.251.3:52768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/bigdump.php"] [unique_id "apPkZY6aRhSu8gis9LlrogAABK0"]
[Sun Aug 30 03:05:57.972460 2026] [security2:error] [pid 496962:tid 497094] [client 20.220.204.93:64135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/easy.php"] [unique_id "apPkZY6aRhSu8gis9LlrowAABK8"]
[Sun Aug 30 03:05:57.973444 2026] [security2:error] [pid 496962:tid 497098] [client 20.104.50.220:62839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-go.php"] [unique_id "apPkZY6aRhSu8gis9LlrpAAABLM"]
[Sun Aug 30 03:05:57.984254 2026] [security2:error] [pid 496962:tid 497132] [client 20.104.18.15:43322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/sallu.php"] [unique_id "apPkZY6aRhSu8gis9LlruAAABNU"]
[Sun Aug 30 03:05:57.990725 2026] [security2:error] [pid 496962:tid 497144] [client 20.104.104.62:22108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/ssss.php"] [unique_id "apPkZY6aRhSu8gis9Llr0AAABOE"]
[Sun Aug 30 03:05:58.042524 2026] [security2:error] [pid 495314:tid 495560] [client 4.205.62.107:58326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/87.php"] [unique_id "apPkZkmtdPfUFP1akVFNlwAABJw"]
[Sun Aug 30 03:05:58.125182 2026] [security2:error] [pid 495314:tid 495506] [client 20.63.219.114:18543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/ioxi-o.php"] [unique_id "apPkZkmtdPfUFP1akVFNvgAABGY"]
[Sun Aug 30 03:05:58.136523 2026] [security2:error] [pid 496962:tid 497163] [client 20.220.204.93:64147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/fresh3.php"] [unique_id "apPkZo6aRhSu8gis9Llr8wAABPQ"]
[Sun Aug 30 03:05:58.137397 2026] [security2:error] [pid 495314:tid 495555] [client 20.104.18.15:13687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/mac.php"] [unique_id "apPkZkmtdPfUFP1akVFNxQAABJc"]
[Sun Aug 30 03:05:58.138160 2026] [security2:error] [pid 496962:tid 497095] [client 40.83.93.50:12075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/users.php"] [unique_id "apPkZo6aRhSu8gis9Llr9AAABLA"]
[Sun Aug 30 03:05:58.142179 2026] [security2:error] [pid 495314:tid 495542] [client 20.104.18.15:43276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/codex.php"] [unique_id "apPkZkmtdPfUFP1akVFNyAAABIo"]
[Sun Aug 30 03:05:58.149190 2026] [security2:error] [pid 496962:tid 497178] [client 20.104.50.220:33051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/Cylul007.php"] [unique_id "apPkZo6aRhSu8gis9Llr-AAABQM"]
[Sun Aug 30 03:05:58.173868 2026] [security2:error] [pid 496962:tid 497181] [client 68.155.159.216:56425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/NewFile.php/"] [unique_id "apPkZo6aRhSu8gis9Llr_QAABQY"]
[Sun Aug 30 03:05:58.174507 2026] [security2:error] [pid 495314:tid 495449] [client 20.104.49.130:58053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/berlin.php"] [unique_id "apPkZkmtdPfUFP1akVFN1wAABC0"]
[Sun Aug 30 03:05:58.178364 2026] [security2:error] [pid 495314:tid 495557] [client 20.104.18.15:33679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/alfa.php"] [unique_id "apPkZkmtdPfUFP1akVFN2QAABJk"]
[Sun Aug 30 03:05:58.193284 2026] [security2:error] [pid 495314:tid 495511] [client 20.48.160.90:33163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/c4.php"] [unique_id "apPkZkmtdPfUFP1akVFN4gAABGs"]
[Sun Aug 30 03:05:58.204192 2026] [security2:error] [pid 495314:tid 495498] [client 20.104.104.62:21752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/zoz.php"] [unique_id "apPkZkmtdPfUFP1akVFN6AAABF4"]
[Sun Aug 30 03:05:58.239771 2026] [authz_core:error] [pid 495314:tid 495524] [client 216.73.216.128:32444] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:58.240145 2026] [authz_core:error] [pid 495314:tid 495524] [client 216.73.216.128:32444] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:58.310464 2026] [security2:error] [pid 495314:tid 495567] [client 20.220.204.93:64129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/bgymj.php"] [unique_id "apPkZkmtdPfUFP1akVFOLgAABKM"]
[Sun Aug 30 03:05:58.318986 2026] [authz_core:error] [pid 495314:tid 495467] [client 66.249.66.202:47066] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:58.319328 2026] [authz_core:error] [pid 495314:tid 495467] [client 66.249.66.202:47066] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:58.329333 2026] [security2:error] [pid 496962:tid 497137] [client 20.151.200.44:47315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/attack.php"] [unique_id "apPkZo6aRhSu8gis9LlsCgAABNo"]
[Sun Aug 30 03:05:58.335878 2026] [security2:error] [pid 495314:tid 495563] [client 20.48.251.3:54781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/requirements.php"] [unique_id "apPkZkmtdPfUFP1akVFOOwAABJ8"]
[Sun Aug 30 03:05:58.351486 2026] [security2:error] [pid 495314:tid 495456] [client 20.48.160.90:50683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/rxr.php"] [unique_id "apPkZkmtdPfUFP1akVFORgAABDQ"]
[Sun Aug 30 03:05:58.359727 2026] [security2:error] [pid 495314:tid 495549] [client 20.104.104.62:22114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/kcs.php"] [unique_id "apPkZkmtdPfUFP1akVFOSQAABJE"]
[Sun Aug 30 03:05:58.422480 2026] [security2:error] [pid 495314:tid 495444] [client 20.104.50.220:42777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/cpanel.php"] [unique_id "apPkZkmtdPfUFP1akVFOaQAABCg"]
[Sun Aug 30 03:05:58.423245 2026] [authz_core:error] [pid 495314:tid 495460] [client 216.73.216.128:15344] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:58.423735 2026] [authz_core:error] [pid 495314:tid 495460] [client 216.73.216.128:15344] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:58.500745 2026] [security2:error] [pid 496962:tid 497098] [client 68.155.159.216:12291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apPkZo6aRhSu8gis9LlsGwAABLM"]
[Sun Aug 30 03:05:58.508185 2026] [security2:error] [pid 496962:tid 497199] [client 20.151.200.44:23564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/tf.php"] [unique_id "apPkZo6aRhSu8gis9LlsHAAABRg"]
[Sun Aug 30 03:05:58.515175 2026] [security2:error] [pid 495314:tid 495523] [client 20.104.104.62:22106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/tajj.php"] [unique_id "apPkZkmtdPfUFP1akVFOnwAABHc"]
[Sun Aug 30 03:05:58.538265 2026] [security2:error] [pid 496962:tid 497145] [client 20.104.50.220:27444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/000.php/index.php"] [unique_id "apPkZo6aRhSu8gis9LlsIwAABOI"]
[Sun Aug 30 03:05:58.544293 2026] [security2:error] [pid 495314:tid 495510] [client 20.220.204.93:64236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/ws69.php"] [unique_id "apPkZkmtdPfUFP1akVFOrQAABGo"]
[Sun Aug 30 03:05:58.567396 2026] [security2:error] [pid 496962:tid 497150] [client 68.155.159.216:63547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/.well-known/index.php"] [unique_id "apPkZo6aRhSu8gis9LlsJQAABOc"]
[Sun Aug 30 03:05:58.578588 2026] [security2:error] [pid 495314:tid 495464] [client 20.63.219.114:9649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavendish-club.com.lodestar.media"] [uri "/lock.php"] [unique_id "apPkZkmtdPfUFP1akVFOuAAABDw"]
[Sun Aug 30 03:05:58.599157 2026] [security2:error] [pid 496962:tid 497115] [client 20.48.160.90:33243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wristbandsnow.com"] [uri "/reviall.php"] [unique_id "apPkZo6aRhSu8gis9LlsKgAABMQ"]
[Sun Aug 30 03:05:58.611493 2026] [authz_core:error] [pid 495314:tid 495473] [client 216.73.216.128:23351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:58.611913 2026] [authz_core:error] [pid 495314:tid 495473] [client 216.73.216.128:23351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:58.619252 2026] [security2:error] [pid 496962:tid 497175] [client 20.104.50.220:46646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/evil.php"] [unique_id "apPkZo6aRhSu8gis9LlsLwAABQA"]
[Sun Aug 30 03:05:58.623561 2026] [security2:error] [pid 496962:tid 497164] [client 20.104.50.220:61434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/shell.php5"] [unique_id "apPkZo6aRhSu8gis9LlsMgAABPU"]
[Sun Aug 30 03:05:58.624247 2026] [security2:error] [pid 495314:tid 495496] [client 40.83.93.50:8711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/class.php"] [unique_id "apPkZkmtdPfUFP1akVFOygAABFw"]
[Sun Aug 30 03:05:58.655377 2026] [security2:error] [pid 495314:tid 495504] [client 4.205.62.107:63575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/oc460l3x.php"] [unique_id "apPkZkmtdPfUFP1akVFO0wAABGQ"]
[Sun Aug 30 03:05:58.674473 2026] [security2:error] [pid 495314:tid 495523] [client 20.220.204.93:64184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/ccs.php"] [unique_id "apPkZkmtdPfUFP1akVFO3QAABHc"]
[Sun Aug 30 03:05:58.688288 2026] [security2:error] [pid 495314:tid 495524] [client 20.104.104.62:22134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/bge.php"] [unique_id "apPkZkmtdPfUFP1akVFO4gAABHg"]
[Sun Aug 30 03:05:58.730041 2026] [security2:error] [pid 495314:tid 495541] [client 4.205.62.107:36012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/cli_bootstrap.php"] [unique_id "apPkZkmtdPfUFP1akVFO7QAABIk"]
[Sun Aug 30 03:05:58.752732 2026] [security2:error] [pid 495314:tid 495502] [client 68.155.159.216:60009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/cgi-bin/index.php"] [unique_id "apPkZkmtdPfUFP1akVFO8wAABGI"]
[Sun Aug 30 03:05:58.756862 2026] [security2:error] [pid 495314:tid 495469] [client 68.155.159.216:19409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apPkZkmtdPfUFP1akVFO9AAABEE"]
[Sun Aug 30 03:05:58.771392 2026] [security2:error] [pid 495314:tid 495460] [client 20.104.50.220:32075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/22xc.php"] [unique_id "apPkZkmtdPfUFP1akVFO9gAABDg"]
[Sun Aug 30 03:05:58.781460 2026] [security2:error] [pid 495314:tid 495561] [client 4.205.62.107:5087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/adminfus.php"] [unique_id "apPkZkmtdPfUFP1akVFO-wAABJ0"]
[Sun Aug 30 03:05:58.805025 2026] [security2:error] [pid 495314:tid 495447] [client 20.104.50.220:6097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/gifclass4.php"] [unique_id "apPkZkmtdPfUFP1akVFPBAAABCs"]
[Sun Aug 30 03:05:58.834235 2026] [security2:error] [pid 495314:tid 495530] [client 20.104.104.62:21698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/ssh3ll.php"] [unique_id "apPkZkmtdPfUFP1akVFPGAAABH4"]
[Sun Aug 30 03:05:58.835790 2026] [security2:error] [pid 495314:tid 495498] [client 20.48.251.3:45839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/adminfus.php"] [unique_id "apPkZkmtdPfUFP1akVFPGgAABF4"]
[Sun Aug 30 03:05:58.838821 2026] [security2:error] [pid 495314:tid 495451] [client 20.48.251.3:44230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/124.php"] [unique_id "apPkZkmtdPfUFP1akVFPGwAABC8"]
[Sun Aug 30 03:05:58.844439 2026] [security2:error] [pid 496962:tid 497192] [client 20.48.251.3:55436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/nzv.php"] [unique_id "apPkZo6aRhSu8gis9LlsQAAABRE"]
[Sun Aug 30 03:05:58.847423 2026] [security2:error] [pid 496962:tid 497104] [client 4.205.62.107:2121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/app_local.php"] [unique_id "apPkZo6aRhSu8gis9LlsQgAABLk"]
[Sun Aug 30 03:05:58.851137 2026] [security2:error] [pid 496962:tid 497193] [client 20.220.204.93:64176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/mar.php"] [unique_id "apPkZo6aRhSu8gis9LlsRQAABRI"]
[Sun Aug 30 03:05:58.885622 2026] [authz_core:error] [pid 495314:tid 495510] [client 216.73.216.128:32444] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:58.885982 2026] [authz_core:error] [pid 495314:tid 495510] [client 216.73.216.128:32444] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:58.910594 2026] [security2:error] [pid 495314:tid 495570] [client 4.205.62.107:52101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/userfuns.php"] [unique_id "apPkZkmtdPfUFP1akVFPQgAABKY"]
[Sun Aug 30 03:05:58.910938 2026] [security2:error] [pid 495314:tid 495550] [client 4.205.62.107:44904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/aws_keys.php"] [unique_id "apPkZkmtdPfUFP1akVFPQwAABJI"]
[Sun Aug 30 03:05:58.923799 2026] [security2:error] [pid 495314:tid 495525] [client 20.104.50.220:28713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/slot.php"] [unique_id "apPkZkmtdPfUFP1akVFPUAAABHk"]
[Sun Aug 30 03:05:58.937168 2026] [security2:error] [pid 496962:tid 497205] [client 68.155.159.216:63986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/file17.php"] [unique_id "apPkZo6aRhSu8gis9LlsRwAABR4"]
[Sun Aug 30 03:05:58.988903 2026] [security2:error] [pid 495314:tid 495481] [client 20.48.251.3:44316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/hiquido.com/index.php"] [unique_id "apPkZkmtdPfUFP1akVFPfQAABE0"]
[Sun Aug 30 03:05:58.991599 2026] [security2:error] [pid 495314:tid 495520] [client 4.205.62.107:62029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/goods.php"] [unique_id "apPkZkmtdPfUFP1akVFPfgAABHQ"]
[Sun Aug 30 03:05:58.998942 2026] [security2:error] [pid 495314:tid 495478] [client 74.7.243.204:34678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/cms/"] [unique_id "apPkZkmtdPfUFP1akVFPgAAABEo"], referer: http://mail.letter7brands.com/cms/?p=%2F%2Fetc
[Sun Aug 30 03:05:59.016480 2026] [security2:error] [pid 495314:tid 495503] [client 20.104.104.62:21756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/motu.php"] [unique_id "apPkZ0mtdPfUFP1akVFPjAAABGM"]
[Sun Aug 30 03:05:59.016792 2026] [authz_core:error] [pid 495314:tid 495538] [client 66.249.66.201:42589] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:59.017051 2026] [authz_core:error] [pid 495314:tid 495538] [client 66.249.66.201:42589] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:59.024104 2026] [security2:error] [pid 496962:tid 497097] [client 20.220.204.93:64137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/ccu.php"] [unique_id "apPkZ46aRhSu8gis9LlsTAAABLI"]
[Sun Aug 30 03:05:59.039997 2026] [security2:error] [pid 495314:tid 495477] [client 4.205.62.107:62280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/php-details.php"] [unique_id "apPkZ0mtdPfUFP1akVFPoQAABEk"]
[Sun Aug 30 03:05:59.069871 2026] [authz_core:error] [pid 495314:tid 495474] [client 216.73.216.128:23351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:59.070327 2026] [authz_core:error] [pid 495314:tid 495474] [client 216.73.216.128:23351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:59.101576 2026] [security2:error] [pid 495314:tid 495500] [client 20.48.251.3:52777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/wdf.php"] [unique_id "apPkZ0mtdPfUFP1akVFPwwAABGA"]
[Sun Aug 30 03:05:59.102571 2026] [security2:error] [pid 495314:tid 495504] [client 4.205.62.107:19007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/fff.php"] [unique_id "apPkZ0mtdPfUFP1akVFPxAAABGQ"]
[Sun Aug 30 03:05:59.108756 2026] [security2:error] [pid 496962:tid 497208] [client 40.83.93.50:9330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/auth.php"] [unique_id "apPkZ46aRhSu8gis9LlsUQAABSE"]
[Sun Aug 30 03:05:59.119635 2026] [security2:error] [pid 495314:tid 495453] [client 20.104.50.220:52825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/red404.php"] [unique_id "apPkZ0mtdPfUFP1akVFPzQAABDE"]
[Sun Aug 30 03:05:59.162126 2026] [security2:error] [pid 496962:tid 497145] [client 4.205.62.107:27311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/saml.php"] [unique_id "apPkZ46aRhSu8gis9LlsWQAABOI"]
[Sun Aug 30 03:05:59.162631 2026] [security2:error] [pid 495314:tid 495496] [client 20.220.204.93:62310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/ak.php"] [unique_id "apPkZ0mtdPfUFP1akVFP4QAABFw"]
[Sun Aug 30 03:05:59.163529 2026] [authz_core:error] [pid 495314:tid 495506] [client 216.73.216.128:32444] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:59.163970 2026] [authz_core:error] [pid 495314:tid 495506] [client 216.73.216.128:32444] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:59.165585 2026] [security2:error] [pid 495314:tid 495481] [client 4.205.62.107:42684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/doc.php"] [unique_id "apPkZ0mtdPfUFP1akVFP5AAABE0"]
[Sun Aug 30 03:05:59.207086 2026] [security2:error] [pid 496962:tid 497147] [client 20.104.104.62:22089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/wefile.php"] [unique_id "apPkZ46aRhSu8gis9LlsXwAABOQ"]
[Sun Aug 30 03:05:59.262172 2026] [security2:error] [pid 495314:tid 495488] [client 4.205.62.107:65319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/cloud.php"] [unique_id "apPkZ0mtdPfUFP1akVFQEAAABFQ"]
[Sun Aug 30 03:05:59.269090 2026] [security2:error] [pid 496962:tid 497159] [client 20.151.200.44:63677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/update/da222.php"] [unique_id "apPkZ46aRhSu8gis9LlsbQAABPA"]
[Sun Aug 30 03:05:59.274576 2026] [security2:error] [pid 496962:tid 497174] [client 68.155.159.216:56386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/dropdown.php"] [unique_id "apPkZ46aRhSu8gis9LlsbgAABP8"]
[Sun Aug 30 03:05:59.274988 2026] [security2:error] [pid 496962:tid 497163] [client 20.104.18.15:13749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/simple.php"] [unique_id "apPkZ46aRhSu8gis9LlsbwAABPQ"]
[Sun Aug 30 03:05:59.289795 2026] [security2:error] [pid 495314:tid 495508] [client 20.104.18.15:43301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/5656.php"] [unique_id "apPkZ0mtdPfUFP1akVFQIwAABGg"]
[Sun Aug 30 03:05:59.295447 2026] [security2:error] [pid 495314:tid 495553] [client 20.104.50.220:33209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/cgi-alfa.php"] [unique_id "apPkZ0mtdPfUFP1akVFQJgAABJU"]
[Sun Aug 30 03:05:59.297766 2026] [security2:error] [pid 495314:tid 495548] [client 20.220.204.93:62300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/lib.php"] [unique_id "apPkZ0mtdPfUFP1akVFQKQAABJA"]
[Sun Aug 30 03:05:59.339658 2026] [security2:error] [pid 495314:tid 495541] [client 20.104.18.15:33788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/33.php"] [unique_id "apPkZ0mtdPfUFP1akVFQQwAABIk"]
[Sun Aug 30 03:05:59.389223 2026] [security2:error] [pid 496962:tid 497207] [client 20.104.104.62:21747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/Contrller.php"] [unique_id "apPkZ46aRhSu8gis9LlsgAAABSA"]
[Sun Aug 30 03:05:59.440079 2026] [security2:error] [pid 495314:tid 495527] [client 20.151.200.44:37770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/dx.php"] [unique_id "apPkZ0mtdPfUFP1akVFQcAAABHs"]
[Sun Aug 30 03:05:59.490705 2026] [security2:error] [pid 495314:tid 495549] [client 20.48.251.3:54823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/var/www/wallet/index.php"] [unique_id "apPkZ0mtdPfUFP1akVFQhQAABJE"]
[Sun Aug 30 03:05:59.499749 2026] [security2:error] [pid 495314:tid 495494] [client 74.7.243.204:34678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/new/"] [unique_id "apPkZ0mtdPfUFP1akVFQjQAABFo"], referer: http://mail.letter7brands.com/new/?p=%2F%2Fetc
[Sun Aug 30 03:05:59.505686 2026] [security2:error] [pid 495314:tid 495472] [client 20.220.204.93:62305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/wp-style.php"] [unique_id "apPkZ0mtdPfUFP1akVFQkwAABEQ"]
[Sun Aug 30 03:05:59.555242 2026] [security2:error] [pid 495314:tid 495492] [client 20.104.104.62:22086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/file66.php"] [unique_id "apPkZ0mtdPfUFP1akVFQrQAABFg"]
[Sun Aug 30 03:05:59.559164 2026] [security2:error] [pid 495314:tid 495532] [client 20.104.50.220:51576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/devill.php"] [unique_id "apPkZ0mtdPfUFP1akVFQrwAABIA"]
[Sun Aug 30 03:05:59.600195 2026] [security2:error] [pid 495314:tid 495545] [client 4.205.62.107:32491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/plss3.php"] [unique_id "apPkZ0mtdPfUFP1akVFQwQAABI0"]
[Sun Aug 30 03:05:59.619072 2026] [security2:error] [pid 495314:tid 495472] [client 20.151.200.44:55627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkZ0mtdPfUFP1akVFQzAAABEQ"]
[Sun Aug 30 03:05:59.643885 2026] [security2:error] [pid 495314:tid 495561] [client 94.154.43.158:60708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.hiagtourism.org"] [uri "/.env"] [unique_id "apPkZ0mtdPfUFP1akVFQ1QAABJ0"]
[Sun Aug 30 03:05:59.648497 2026] [security2:error] [pid 496962:tid 497154] [client 20.220.204.93:62280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/browse.php"] [unique_id "apPkZ46aRhSu8gis9LlsnwAABOs"]
[Sun Aug 30 03:05:59.655173 2026] [security2:error] [pid 496962:tid 497197] [client 40.83.93.50:9314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/adminfuns.php"] [unique_id "apPkZ46aRhSu8gis9LlsoAAABRY"]
[Sun Aug 30 03:05:59.656261 2026] [security2:error] [pid 496962:tid 497148] [client 68.155.159.216:12332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/file.php"] [unique_id "apPkZ46aRhSu8gis9LlsoQAABOU"]
[Sun Aug 30 03:05:59.675793 2026] [security2:error] [pid 496962:tid 497115] [client 20.104.50.220:27420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/2d7433/index.php"] [unique_id "apPkZ46aRhSu8gis9LlsogAABMQ"]
[Sun Aug 30 03:05:59.707992 2026] [authz_core:error] [pid 495314:tid 495523] [client 216.73.216.128:32444] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:59.708251 2026] [authz_core:error] [pid 495314:tid 495523] [client 216.73.216.128:32444] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:59.715446 2026] [security2:error] [pid 495314:tid 495444] [client 20.104.104.62:21718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/blnux.php"] [unique_id "apPkZ0mtdPfUFP1akVFQ6wAABCg"]
[Sun Aug 30 03:05:59.722094 2026] [core:alert] [pid 495314:tid 495556] [client 94.154.43.129:17694] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>'
[Sun Aug 30 03:05:59.724476 2026] [authz_core:error] [pid 496962:tid 497144] [client 66.249.66.193:36941] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:59.724760 2026] [authz_core:error] [pid 496962:tid 497144] [client 66.249.66.193:36941] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:59.732079 2026] [security2:error] [pid 495314:tid 495454] [client 74.7.244.43:47554] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.kamiaiibeautycom.nattdesign.com"] [uri "/index.php"] [unique_id "apPkZkmtdPfUFP1akVFOUQAEMjI"]
[Sun Aug 30 03:05:59.756973 2026] [security2:error] [pid 495314:tid 495482] [client 20.104.50.220:46854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/file.php"] [unique_id "apPkZ0mtdPfUFP1akVFQ9gAABE4"]
[Sun Aug 30 03:05:59.767875 2026] [security2:error] [pid 495314:tid 495458] [client 20.104.50.220:61403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/inc/config.php"] [unique_id "apPkZ0mtdPfUFP1akVFQ_AAABDY"]
[Sun Aug 30 03:05:59.786744 2026] [security2:error] [pid 496962:tid 497164] [client 4.205.62.107:63576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/drykl.php"] [unique_id "apPkZ46aRhSu8gis9LlspwAABPU"]
[Sun Aug 30 03:05:59.799297 2026] [security2:error] [pid 495314:tid 495448] [client 20.220.204.93:62299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/zoo.php"] [unique_id "apPkZ0mtdPfUFP1akVFRDAAABCw"]
[Sun Aug 30 03:05:59.831853 2026] [security2:error] [pid 495314:tid 495557] [client 68.155.159.216:62272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-content/themes/too.php"] [unique_id "apPkZ0mtdPfUFP1akVFRHgAABJk"]
[Sun Aug 30 03:05:59.835567 2026] [security2:error] [pid 495314:tid 495541] [client 20.48.251.3:45865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/06.php"] [unique_id "apPkZ0mtdPfUFP1akVFRIAAABIk"]
[Sun Aug 30 03:05:59.873743 2026] [security2:error] [pid 495314:tid 495496] [client 68.155.159.216:60026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPkZ0mtdPfUFP1akVFRMgAABFw"]
[Sun Aug 30 03:05:59.875161 2026] [authz_core:error] [pid 496962:tid 497095] [client 66.249.66.35:59394] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:59.875641 2026] [authz_core:error] [pid 496962:tid 497095] [client 66.249.66.35:59394] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:59.876822 2026] [security2:error] [pid 496962:tid 497176] [client 20.104.104.62:21705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/attack.php"] [unique_id "apPkZ46aRhSu8gis9LlstgAABQE"]
[Sun Aug 30 03:05:59.893624 2026] [security2:error] [pid 495314:tid 495487] [client 68.155.159.216:54728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apPkZ0mtdPfUFP1akVFRPQAABFM"]
[Sun Aug 30 03:05:59.912087 2026] [security2:error] [pid 496962:tid 497104] [client 20.151.200.44:55695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/h02ugyh.php"] [unique_id "apPkZ46aRhSu8gis9LlsuwAABLk"]
[Sun Aug 30 03:05:59.916184 2026] [security2:error] [pid 495314:tid 495551] [client 4.205.62.107:4600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/avim.php"] [unique_id "apPkZ0mtdPfUFP1akVFRRgAABJM"]
[Sun Aug 30 03:05:59.927344 2026] [security2:error] [pid 495314:tid 495492] [client 20.104.50.220:31855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/26.php"] [unique_id "apPkZ0mtdPfUFP1akVFRTAAABFg"]
[Sun Aug 30 03:05:59.934389 2026] [security2:error] [pid 495314:tid 495485] [client 20.220.204.93:64201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/elp.php"] [unique_id "apPkZ0mtdPfUFP1akVFRUQAABFE"]
[Sun Aug 30 03:05:59.951467 2026] [security2:error] [pid 496962:tid 497201] [client 20.104.50.220:5921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/2clas.php"] [unique_id "apPkZ46aRhSu8gis9LlswQAABRo"]
[Sun Aug 30 03:05:59.956390 2026] [security2:error] [pid 495314:tid 495464] [client 20.151.200.44:23580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/qi.php"] [unique_id "apPkZ0mtdPfUFP1akVFRWAAABDw"]
[Sun Aug 30 03:05:59.973952 2026] [security2:error] [pid 496962:tid 497106] [client 20.48.251.3:23351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/test1.php"] [unique_id "apPkZ46aRhSu8gis9LlsxgAABLs"]
[Sun Aug 30 03:05:59.983360 2026] [security2:error] [pid 496962:tid 497209] [client 20.48.251.3:55445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/66.php"] [unique_id "apPkZ46aRhSu8gis9LlsxwAABSI"]
[Sun Aug 30 03:05:59.984201 2026] [authz_core:error] [pid 495314:tid 495556] [client 216.73.216.128:15344] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:05:59.984472 2026] [authz_core:error] [pid 495314:tid 495556] [client 216.73.216.128:15344] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:05:59.992621 2026] [security2:error] [pid 495314:tid 495496] [client 4.205.62.107:2809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/ws62.php"] [unique_id "apPkZ0mtdPfUFP1akVFRZwAABFw"]
[Sun Aug 30 03:06:00.008574 2026] [security2:error] [pid 496962:tid 497212] [client 20.104.104.62:21729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/wk/index.php"] [unique_id "apPkaI6aRhSu8gis9LlsygAABSU"]
[Sun Aug 30 03:06:00.009630 2026] [security2:error] [pid 495314:tid 495469] [client 20.48.251.3:6988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/avim.php"] [unique_id "apPkaEmtdPfUFP1akVFRbgAABEE"]
[Sun Aug 30 03:06:00.040361 2026] [security2:error] [pid 496962:tid 497215] [client 4.205.62.107:51755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/mamzi.php"] [unique_id "apPkaI6aRhSu8gis9LlszgAABSg"]
[Sun Aug 30 03:06:00.050401 2026] [security2:error] [pid 495314:tid 495541] [client 4.205.62.107:44918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/umgebung.php"] [unique_id "apPkaEmtdPfUFP1akVFRiwAABIk"]
[Sun Aug 30 03:06:00.065778 2026] [security2:error] [pid 495314:tid 495532] [client 20.104.50.220:29131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/sad.php"] [unique_id "apPkaEmtdPfUFP1akVFRlQAABIA"]
[Sun Aug 30 03:06:00.086290 2026] [security2:error] [pid 495314:tid 495486] [client 20.220.204.93:64197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/666.php"] [unique_id "apPkaEmtdPfUFP1akVFRowAABFI"]
[Sun Aug 30 03:06:00.120948 2026] [security2:error] [pid 495314:tid 495478] [client 94.154.43.84:60658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.hiagtourism.org"] [uri "/.env"] [unique_id "apPkaEmtdPfUFP1akVFRsgAABEo"]
[Sun Aug 30 03:06:00.121370 2026] [security2:error] [pid 495314:tid 495456] [client 20.104.49.130:45752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/makeasmtp.php"] [unique_id "apPkaEmtdPfUFP1akVFRswAABDQ"]
[Sun Aug 30 03:06:00.123841 2026] [security2:error] [pid 496962:tid 497203] [client 40.83.93.50:12049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/rip.php"] [unique_id "apPkaI6aRhSu8gis9Lls1gAABRw"]
[Sun Aug 30 03:06:00.152056 2026] [security2:error] [pid 495314:tid 495509] [client 68.155.159.216:61313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/file5.php"] [unique_id "apPkaEmtdPfUFP1akVFRxwAABGk"]
[Sun Aug 30 03:06:00.166012 2026] [authz_core:error] [pid 495314:tid 495506] [client 216.73.216.128:15344] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:00.166328 2026] [authz_core:error] [pid 495314:tid 495506] [client 216.73.216.128:15344] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:00.180814 2026] [security2:error] [pid 495314:tid 495450] [client 4.205.62.107:22561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/routes.php"] [unique_id "apPkaEmtdPfUFP1akVFR0wAABC4"]
[Sun Aug 30 03:06:00.192430 2026] [security2:error] [pid 495314:tid 495488] [client 4.205.62.107:32038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/aws.php"] [unique_id "apPkaEmtdPfUFP1akVFR2AAABFQ"]
[Sun Aug 30 03:06:00.202977 2026] [security2:error] [pid 495314:tid 495455] [client 20.104.104.62:63378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/dehnl.php"] [unique_id "apPkaEmtdPfUFP1akVFR3gAABDM"]
[Sun Aug 30 03:06:00.206764 2026] [security2:error] [pid 495314:tid 495497] [client 20.151.200.44:37881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPkaEmtdPfUFP1akVFR4AAABF0"]
[Sun Aug 30 03:06:00.224711 2026] [security2:error] [pid 495314:tid 495561] [client 20.220.204.93:64242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/knmt.php"] [unique_id "apPkaEmtdPfUFP1akVFR6QAABJ0"]
[Sun Aug 30 03:06:00.242263 2026] [security2:error] [pid 495314:tid 495564] [client 20.48.251.3:55683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/bb.php"] [unique_id "apPkaEmtdPfUFP1akVFR-gAABKA"]
[Sun Aug 30 03:06:00.256204 2026] [security2:error] [pid 496962:tid 497115] [client 4.205.62.107:18628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/autogooey.php"] [unique_id "apPkaI6aRhSu8gis9Lls3wAABMQ"]
[Sun Aug 30 03:06:00.258443 2026] [security2:error] [pid 496962:tid 497168] [client 20.104.50.220:52856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/kdoor.php"] [unique_id "apPkaI6aRhSu8gis9Lls4AAABPk"]
[Sun Aug 30 03:06:00.271045 2026] [security2:error] [pid 496962:tid 497164] [client 4.205.62.107:36630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/dd.php"] [unique_id "apPkaI6aRhSu8gis9Lls5gAABPU"]
[Sun Aug 30 03:06:00.284315 2026] [security2:error] [pid 495314:tid 495516] [client 20.48.251.3:44349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/ws79.php"] [unique_id "apPkaEmtdPfUFP1akVFSFwAABHA"]
[Sun Aug 30 03:06:00.307221 2026] [security2:error] [pid 495314:tid 495567] [client 4.205.62.107:42838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/classsmtps.php"] [unique_id "apPkaEmtdPfUFP1akVFSJAAABKM"]
[Sun Aug 30 03:06:00.361004 2026] [security2:error] [pid 495314:tid 495558] [client 20.220.204.93:64199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/sbhu.php"] [unique_id "apPkaEmtdPfUFP1akVFSTQAABJo"]
[Sun Aug 30 03:06:00.362467 2026] [security2:error] [pid 496962:tid 497178] [client 20.151.200.44:23606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/px.php"] [unique_id "apPkaI6aRhSu8gis9Lls8gAABQM"]
[Sun Aug 30 03:06:00.369200 2026] [security2:error] [pid 495314:tid 495490] [client 20.104.104.62:21742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/png.php"] [unique_id "apPkaEmtdPfUFP1akVFSUQAABFY"]
[Sun Aug 30 03:06:00.370923 2026] [security2:error] [pid 495314:tid 495469] [client 20.104.49.130:48021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/simple.php"] [unique_id "apPkaEmtdPfUFP1akVFSUwAABEE"]
[Sun Aug 30 03:06:00.392239 2026] [security2:error] [pid 495314:tid 495460] [client 4.205.62.107:62119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/loxi-o.php"] [unique_id "apPkaEmtdPfUFP1akVFSWQAABDg"]
[Sun Aug 30 03:06:00.398464 2026] [security2:error] [pid 496962:tid 497133] [client 68.155.159.216:56408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/.well-known/index.php"] [unique_id "apPkaI6aRhSu8gis9Lls9QAABNY"]
[Sun Aug 30 03:06:00.415666 2026] [security2:error] [pid 495314:tid 495557] [client 20.104.18.15:13747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/xty.php"] [unique_id "apPkaEmtdPfUFP1akVFSZAAABJk"]
[Sun Aug 30 03:06:00.429936 2026] [security2:error] [pid 495314:tid 495448] [client 20.104.50.220:33545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/cok.php"] [unique_id "apPkaEmtdPfUFP1akVFSaQAABCw"]
[Sun Aug 30 03:06:00.445976 2026] [security2:error] [pid 496962:tid 497142] [client 20.104.18.15:43311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/w3lls.php"] [unique_id "apPkaI6aRhSu8gis9Lls_wAABN8"]
[Sun Aug 30 03:06:00.458348 2026] [security2:error] [pid 495314:tid 495526] [client 4.205.62.107:26541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/aws_settings.php"] [unique_id "apPkaEmtdPfUFP1akVFSegAABHo"]
[Sun Aug 30 03:06:00.477983 2026] [security2:error] [pid 495314:tid 495513] [client 20.104.18.15:33749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/133.php"] [unique_id "apPkaEmtdPfUFP1akVFShwAABG0"]
[Sun Aug 30 03:06:00.490193 2026] [security2:error] [pid 495314:tid 495446] [client 20.220.204.93:64221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/a332.php"] [unique_id "apPkaEmtdPfUFP1akVFSkQAABCo"]
[Sun Aug 30 03:06:00.504157 2026] [security2:error] [pid 495314:tid 495485] [client 20.104.104.62:22098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/txets.php"] [unique_id "apPkaEmtdPfUFP1akVFSmQAABFE"]
[Sun Aug 30 03:06:00.536837 2026] [authz_core:error] [pid 495314:tid 495453] [client 216.73.216.128:32444] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:00.537317 2026] [authz_core:error] [pid 495314:tid 495453] [client 216.73.216.128:32444] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:00.571767 2026] [security2:error] [pid 495314:tid 495469] [client 4.205.62.107:65292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/asdf.php"] [unique_id "apPkaEmtdPfUFP1akVFStAAABEE"]
[Sun Aug 30 03:06:00.619051 2026] [security2:error] [pid 496962:tid 497204] [client 40.83.93.50:18072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/ws.php"] [unique_id "apPkaI6aRhSu8gis9LltEQAABR0"]
[Sun Aug 30 03:06:00.625429 2026] [authz_core:error] [pid 495314:tid 495568] [client 216.73.216.128:15344] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:00.625728 2026] [authz_core:error] [pid 495314:tid 495568] [client 216.73.216.128:15344] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:00.644024 2026] [security2:error] [pid 495314:tid 495472] [client 20.48.251.3:54821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/124.php"] [unique_id "apPkaEmtdPfUFP1akVFS0wAABEQ"]
[Sun Aug 30 03:06:00.644045 2026] [security2:error] [pid 495314:tid 495496] [client 20.220.204.93:64233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/ws66.php"] [unique_id "apPkaEmtdPfUFP1akVFS1AAABFw"]
[Sun Aug 30 03:06:00.677999 2026] [security2:error] [pid 496962:tid 497110] [client 20.104.104.62:22123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/wp-login.php"] [unique_id "apPkaI6aRhSu8gis9LltFQAABL8"]
[Sun Aug 30 03:06:00.715868 2026] [security2:error] [pid 495314:tid 495513] [client 20.151.200.44:63639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/is.php"] [unique_id "apPkaEmtdPfUFP1akVFS7wAABG0"]
[Sun Aug 30 03:06:00.720533 2026] [security2:error] [pid 495314:tid 495529] [client 20.104.50.220:51537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/dikne.php"] [unique_id "apPkaEmtdPfUFP1akVFS8AAABH0"]
[Sun Aug 30 03:06:00.778543 2026] [security2:error] [pid 495314:tid 495460] [client 20.220.204.93:61798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/ws68.php"] [unique_id "apPkaEmtdPfUFP1akVFTAQAABDg"]
[Sun Aug 30 03:06:00.793575 2026] [security2:error] [pid 496962:tid 497125] [client 68.155.159.216:12352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/file17.php"] [unique_id "apPkaI6aRhSu8gis9LltHgAABM4"]
[Sun Aug 30 03:06:00.813794 2026] [security2:error] [pid 496962:tid 497173] [client 20.104.50.220:27548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/radio.php"] [unique_id "apPkaI6aRhSu8gis9LltIQAABP4"]
[Sun Aug 30 03:06:00.813986 2026] [security2:error] [pid 495314:tid 495535] [client 20.104.104.62:21757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/wp-access.php"] [unique_id "apPkaEmtdPfUFP1akVFTFwAABIM"]
[Sun Aug 30 03:06:00.831923 2026] [security2:error] [pid 495314:tid 495465] [client 20.104.49.130:34524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/berlin.php"] [unique_id "apPkaEmtdPfUFP1akVFTIQAABD0"]
[Sun Aug 30 03:06:00.910845 2026] [security2:error] [pid 496962:tid 497185] [client 20.104.50.220:46412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/FoxWSO-full.php"] [unique_id "apPkaI6aRhSu8gis9LltLAAABQo"]
[Sun Aug 30 03:06:00.913441 2026] [security2:error] [pid 496962:tid 497121] [client 20.220.204.93:64214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/users.php"] [unique_id "apPkaI6aRhSu8gis9LltLgAABMo"]
[Sun Aug 30 03:06:00.923464 2026] [security2:error] [pid 495314:tid 495453] [client 20.104.50.220:59562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/ix.php"] [unique_id "apPkaEmtdPfUFP1akVFTUAAABDE"]
[Sun Aug 30 03:06:00.925056 2026] [security2:error] [pid 496962:tid 497176] [client 4.205.62.107:63573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/rpk.php"] [unique_id "apPkaI6aRhSu8gis9LltMAAABQE"]
[Sun Aug 30 03:06:00.965625 2026] [security2:error] [pid 496962:tid 497196] [client 20.104.104.62:22083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/wp-content/admin.php"] [unique_id "apPkaI6aRhSu8gis9LltPAAABRU"]
[Sun Aug 30 03:06:01.032119 2026] [security2:error] [pid 496962:tid 497101] [client 68.155.159.216:59904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-includes/content.php"] [unique_id "apPkaY6aRhSu8gis9LltRQAABLY"]
[Sun Aug 30 03:06:01.046908 2026] [security2:error] [pid 495314:tid 495466] [client 20.220.204.93:62285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/bzjdlofz.php"] [unique_id "apPkaUmtdPfUFP1akVFTfgAABD4"]
[Sun Aug 30 03:06:01.056331 2026] [security2:error] [pid 495314:tid 495511] [client 62.60.130.228:58692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ballroomology.com"] [uri "/wp-login.php"] [unique_id "apPkaUmtdPfUFP1akVFTfAAABGs"], referer: https://twitter.com/
[Sun Aug 30 03:06:01.077813 2026] [security2:error] [pid 496962:tid 497099] [client 20.104.50.220:31898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/2index.php"] [unique_id "apPkaY6aRhSu8gis9LltUgAABLQ"]
[Sun Aug 30 03:06:01.082253 2026] [security2:error] [pid 496962:tid 497118] [client 20.151.200.44:63574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/od.php"] [unique_id "apPkaY6aRhSu8gis9LltWQAABMc"]
[Sun Aug 30 03:06:01.089066 2026] [security2:error] [pid 496962:tid 497132] [client 20.104.49.130:60967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/makeasmtp.php"] [unique_id "apPkaY6aRhSu8gis9LltXAAABNU"]
[Sun Aug 30 03:06:01.108542 2026] [security2:error] [pid 496962:tid 497156] [client 20.104.50.220:5552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/ave.php"] [unique_id "apPkaY6aRhSu8gis9LltZAAABO0"]
[Sun Aug 30 03:06:01.112658 2026] [security2:error] [pid 496962:tid 497173] [client 20.104.104.62:22092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/log.php"] [unique_id "apPkaY6aRhSu8gis9LltZgAABP4"]
[Sun Aug 30 03:06:01.114797 2026] [security2:error] [pid 496962:tid 497175] [client 20.48.251.3:23090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/bigdump.php"] [unique_id "apPkaY6aRhSu8gis9LltZwAABQA"]
[Sun Aug 30 03:06:01.115364 2026] [security2:error] [pid 496962:tid 497158] [client 4.205.62.107:4158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/nw.php"] [unique_id "apPkaY6aRhSu8gis9LltaAAABO8"]
[Sun Aug 30 03:06:01.127815 2026] [security2:error] [pid 496962:tid 497170] [client 20.48.251.3:55425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/admin.php"] [unique_id "apPkaY6aRhSu8gis9LltbgAABPs"]
[Sun Aug 30 03:06:01.136781 2026] [security2:error] [pid 495314:tid 495469] [client 4.205.62.107:2781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/grsiuk.php"] [unique_id "apPkaUmtdPfUFP1akVFTlgAABEE"]
[Sun Aug 30 03:06:01.152903 2026] [security2:error] [pid 496962:tid 497137] [client 20.48.251.3:64419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/nw.php"] [unique_id "apPkaY6aRhSu8gis9LltewAABNo"]
[Sun Aug 30 03:06:01.179334 2026] [security2:error] [pid 495314:tid 495446] [client 4.205.62.107:52138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/public/rip.php.php"] [unique_id "apPkaUmtdPfUFP1akVFTqgAABCo"]
[Sun Aug 30 03:06:01.187724 2026] [security2:error] [pid 495314:tid 495487] [client 4.205.62.107:44890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/old_phpinfo.php"] [unique_id "apPkaUmtdPfUFP1akVFTrgAABFM"]
[Sun Aug 30 03:06:01.205977 2026] [security2:error] [pid 495314:tid 495449] [client 34.34.225.205:53156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "192.254.186.130"] [uri "/"] [unique_id "apPkaUmtdPfUFP1akVFTugAABC0"]
[Sun Aug 30 03:06:01.206230 2026] [security2:error] [pid 495314:tid 495447] [client 20.220.204.93:64230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/selesai.php"] [unique_id "apPkaUmtdPfUFP1akVFTuQAABCs"]
[Sun Aug 30 03:06:01.207776 2026] [security2:error] [pid 495314:tid 495546] [client 20.104.50.220:52829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/sec.php"] [unique_id "apPkaUmtdPfUFP1akVFTvAAABI4"]
[Sun Aug 30 03:06:01.273343 2026] [authz_core:error] [pid 496962:tid 497210] [client 66.249.66.43:53092] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:01.273762 2026] [authz_core:error] [pid 496962:tid 497210] [client 66.249.66.43:53092] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:01.276798 2026] [security2:error] [pid 496962:tid 497169] [client 68.155.159.216:19397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apPkaY6aRhSu8gis9LltmAAABPo"]
[Sun Aug 30 03:06:01.279679 2026] [security2:error] [pid 496962:tid 497160] [client 40.83.93.50:9309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/t.php"] [unique_id "apPkaY6aRhSu8gis9LltnAAABPE"]
[Sun Aug 30 03:06:01.287166 2026] [authz_core:error] [pid 495314:tid 495488] [client 66.249.66.39:61376] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:01.287452 2026] [authz_core:error] [pid 495314:tid 495488] [client 66.249.66.39:61376] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:01.308577 2026] [security2:error] [pid 495314:tid 495546] [client 20.104.104.62:63405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/xwpg.php"] [unique_id "apPkaUmtdPfUFP1akVFT8QAABI4"]
[Sun Aug 30 03:06:01.317754 2026] [authz_core:error] [pid 495314:tid 495473] [client 66.249.66.78:62832] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:01.318219 2026] [authz_core:error] [pid 495314:tid 495473] [client 66.249.66.78:62832] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:01.364207 2026] [security2:error] [pid 495314:tid 495444] [client 20.220.204.93:62331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/shlo.php"] [unique_id "apPkaUmtdPfUFP1akVFUFQAABCg"]
[Sun Aug 30 03:06:01.368504 2026] [security2:error] [pid 495314:tid 495526] [client 4.205.62.107:62308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/aww.php"] [unique_id "apPkaUmtdPfUFP1akVFUGQAABHo"]
[Sun Aug 30 03:06:01.380597 2026] [security2:error] [pid 496962:tid 497105] [client 20.48.251.3:55721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/file59.php"] [unique_id "apPkaY6aRhSu8gis9LltugAABLo"]
[Sun Aug 30 03:06:01.402825 2026] [security2:error] [pid 496962:tid 497147] [client 4.205.62.107:18651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/sdsa.php"] [unique_id "apPkaY6aRhSu8gis9LltwgAABOQ"]
[Sun Aug 30 03:06:01.410983 2026] [security2:error] [pid 496962:tid 497168] [client 20.104.50.220:29588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/years.php"] [unique_id "apPkaY6aRhSu8gis9LltxgAABPk"]
[Sun Aug 30 03:06:01.420612 2026] [security2:error] [pid 496962:tid 497175] [client 62.60.130.228:58789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.130.60.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ballroomology.com"] [uri "/wp-login.php"] [unique_id "apPkaY6aRhSu8gis9LltzAAABQA"], referer: https://www.reddit.com/
[Sun Aug 30 03:06:01.446142 2026] [security2:error] [pid 495314:tid 495451] [client 4.205.62.107:42050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/cache-compat.php"] [unique_id "apPkaUmtdPfUFP1akVFURAAABC8"]
[Sun Aug 30 03:06:01.449361 2026] [security2:error] [pid 495314:tid 495541] [client 20.104.104.62:21727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/sxxb.php"] [unique_id "apPkaUmtdPfUFP1akVFURgAABIk"]
[Sun Aug 30 03:06:01.452527 2026] [authz_core:error] [pid 495314:tid 495568] [client 216.73.216.128:32444] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:01.452827 2026] [authz_core:error] [pid 495314:tid 495568] [client 216.73.216.128:32444] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:01.455723 2026] [security2:error] [pid 495314:tid 495555] [client 68.155.159.216:63963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/file88.php"] [unique_id "apPkaUmtdPfUFP1akVFUSgAABJc"]
[Sun Aug 30 03:06:01.471743 2026] [security2:error] [pid 495314:tid 495531] [client 20.48.251.3:5097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/public/wp-blog.php"] [unique_id "apPkaUmtdPfUFP1akVFUVQAABH8"]
[Sun Aug 30 03:06:01.502529 2026] [security2:error] [pid 495314:tid 495538] [client 20.220.204.93:64223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/asax.php"] [unique_id "apPkaUmtdPfUFP1akVFUawAABIY"]
[Sun Aug 30 03:06:01.525731 2026] [security2:error] [pid 495314:tid 495451] [client 68.155.159.216:56404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-content/themes/too.php"] [unique_id "apPkaUmtdPfUFP1akVFUeAAABC8"]
[Sun Aug 30 03:06:01.529916 2026] [security2:error] [pid 495314:tid 495507] [client 4.205.62.107:64019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/f35.php"] [unique_id "apPkaUmtdPfUFP1akVFUegAABGc"]
[Sun Aug 30 03:06:01.536125 2026] [authz_core:error] [pid 495314:tid 495541] [client 66.249.66.39:54495] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:01.536587 2026] [authz_core:error] [pid 495314:tid 495541] [client 66.249.66.39:54495] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:01.547887 2026] [security2:error] [pid 496962:tid 497109] [client 4.205.62.107:31736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/app.default.php"] [unique_id "apPkaY6aRhSu8gis9Llt3gAABL4"]
[Sun Aug 30 03:06:01.572143 2026] [security2:error] [pid 496962:tid 497207] [client 20.104.18.15:13580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/sallu.php"] [unique_id "apPkaY6aRhSu8gis9Llt4wAABSA"]
[Sun Aug 30 03:06:01.602002 2026] [security2:error] [pid 496962:tid 497212] [client 20.104.50.220:33307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/cgipro.php"] [unique_id "apPkaY6aRhSu8gis9Llt6wAABSU"]
[Sun Aug 30 03:06:01.613139 2026] [security2:error] [pid 495314:tid 495450] [client 20.104.18.15:43280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/fpwch.php"] [unique_id "apPkaUmtdPfUFP1akVFUlQAABC4"]
[Sun Aug 30 03:06:01.616206 2026] [security2:error] [pid 495314:tid 495476] [client 20.104.104.62:22080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/dx.php"] [unique_id "apPkaUmtdPfUFP1akVFUmQAABEg"]
[Sun Aug 30 03:06:01.628789 2026] [security2:error] [pid 495314:tid 495502] [client 20.104.18.15:33771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/sym.php"] [unique_id "apPkaUmtdPfUFP1akVFUoAAABGI"]
[Sun Aug 30 03:06:01.647255 2026] [security2:error] [pid 495314:tid 495500] [client 20.220.204.93:64183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/fetch.php"] [unique_id "apPkaUmtdPfUFP1akVFUqQAABGA"]
[Sun Aug 30 03:06:01.717214 2026] [core:alert] [pid 495314:tid 495454] [client 201.20.78.38:44497] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:06:01.717267 2026] [security2:error] [pid 495314:tid 495477] [client 68.155.159.216:63546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/radio.php"] [unique_id "apPkaUmtdPfUFP1akVFUzAAABEk"]
[Sun Aug 30 03:06:01.717972 2026] [security2:error] [pid 495314:tid 495528] [client 216.73.216.128:15344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/nameserverconfig"] [unique_id "apPkaUmtdPfUFP1akVFUzQAABHw"]
[Sun Aug 30 03:06:01.737220 2026] [security2:error] [pid 496962:tid 497145] [client 4.205.62.107:32509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/wdf.php"] [unique_id "apPkaY6aRhSu8gis9Llt-QAABOI"]
[Sun Aug 30 03:06:01.753077 2026] [security2:error] [pid 496962:tid 497201] [client 40.83.93.50:8728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/fw.php"] [unique_id "apPkaY6aRhSu8gis9Llt_gAABRo"]
[Sun Aug 30 03:06:01.776173 2026] [security2:error] [pid 496962:tid 497092] [client 20.220.204.93:64196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/vx.php"] [unique_id "apPkaY6aRhSu8gis9LluAQAABK0"]
[Sun Aug 30 03:06:01.777127 2026] [security2:error] [pid 495314:tid 495529] [client 20.104.104.62:21696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPkaUmtdPfUFP1akVFU1gAABH0"]
[Sun Aug 30 03:06:01.779242 2026] [security2:error] [pid 495314:tid 495462] [client 4.205.62.107:36004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/wp-tem.php"] [unique_id "apPkaUmtdPfUFP1akVFU2gAABDo"]
[Sun Aug 30 03:06:01.785048 2026] [security2:error] [pid 495314:tid 495498] [client 20.48.251.3:54806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/test1.php"] [unique_id "apPkaUmtdPfUFP1akVFU3wAABF4"]
[Sun Aug 30 03:06:01.820253 2026] [authz_core:error] [pid 495314:tid 495508] [client 216.73.216.128:23351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:01.820733 2026] [authz_core:error] [pid 495314:tid 495508] [client 216.73.216.128:23351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:01.868748 2026] [security2:error] [pid 496962:tid 497135] [client 20.104.50.220:42763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/cPanel.php"] [unique_id "apPkaY6aRhSu8gis9LluCwAABNg"]
[Sun Aug 30 03:06:01.911689 2026] [security2:error] [pid 496962:tid 497157] [client 20.220.204.93:64245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/global.php"] [unique_id "apPkaY6aRhSu8gis9LluDwAABO4"]
[Sun Aug 30 03:06:01.912797 2026] [security2:error] [pid 496962:tid 497190] [client 68.155.159.216:12324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/file5.php"] [unique_id "apPkaY6aRhSu8gis9LluEAAABQ8"]
[Sun Aug 30 03:06:01.943992 2026] [security2:error] [pid 495314:tid 495486] [client 20.104.104.62:21733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/xda.php"] [unique_id "apPkaUmtdPfUFP1akVFVJwAABFI"]
[Sun Aug 30 03:06:01.945983 2026] [security2:error] [pid 495314:tid 495505] [client 20.151.200.44:63019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/wp-the.php"] [unique_id "apPkaUmtdPfUFP1akVFVKAAABGU"]
[Sun Aug 30 03:06:01.946117 2026] [security2:error] [pid 495314:tid 495561] [client 4.205.62.107:26547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/wp-konfig.backup.php"] [unique_id "apPkaUmtdPfUFP1akVFVKQAABJ0"]
[Sun Aug 30 03:06:01.956610 2026] [security2:error] [pid 495314:tid 495558] [client 20.104.50.220:27094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/wp-includes/user.php"] [unique_id "apPkaUmtdPfUFP1akVFVNAAABJo"]
[Sun Aug 30 03:06:01.969658 2026] [proxy:warn] [pid 495314:tid 495483] [client 199.45.154.116:41472] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be cherylvalk.com for uri /400.shtml
[Sun Aug 30 03:06:01.969690 2026] [proxy:error] [pid 495314:tid 495483] (70014)End of file found: [client 199.45.154.116:41472] AH01095: prefetch request body failed to 127.0.0.1:8080 (127.0.0.1) from 199.45.154.116 ()
[Sun Aug 30 03:06:01.997379 2026] [security2:error] [pid 495314:tid 495523] [client 4.205.62.107:65405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apPkaUmtdPfUFP1akVFVUgAABHc"]
[Sun Aug 30 03:06:02.047758 2026] [security2:error] [pid 495314:tid 495494] [client 20.104.50.220:46355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/FoxWSO.php"] [unique_id "apPkakmtdPfUFP1akVFVdAAABFo"]
[Sun Aug 30 03:06:02.064904 2026] [security2:error] [pid 496962:tid 497114] [client 4.205.62.107:63793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/saml.php"] [unique_id "apPkao6aRhSu8gis9LluJAAABMM"]
[Sun Aug 30 03:06:02.086971 2026] [security2:error] [pid 496962:tid 497177] [client 20.220.204.93:64169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/fs.php"] [unique_id "apPkao6aRhSu8gis9LluKAAABQI"]
[Sun Aug 30 03:06:02.087767 2026] [security2:error] [pid 495314:tid 495461] [client 20.104.50.220:62263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/r0x.php"] [unique_id "apPkakmtdPfUFP1akVFVhwAABDk"]
[Sun Aug 30 03:06:02.103034 2026] [security2:error] [pid 496962:tid 497211] [client 20.104.104.62:21739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/wp-admin/js/index.php"] [unique_id "apPkao6aRhSu8gis9LluKwAABSQ"]
[Sun Aug 30 03:06:02.137488 2026] [authz_core:error] [pid 495314:tid 495542] [client 66.249.66.70:49460] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:02.137780 2026] [authz_core:error] [pid 495314:tid 495542] [client 66.249.66.70:49460] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:02.153962 2026] [security2:error] [pid 495314:tid 495515] [client 20.151.200.44:46984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPkakmtdPfUFP1akVFVsAAABG8"]
[Sun Aug 30 03:06:02.180084 2026] [security2:error] [pid 495314:tid 495504] [client 68.155.159.216:59937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-admin/css/index.php"] [unique_id "apPkakmtdPfUFP1akVFVwAAABGQ"]
[Sun Aug 30 03:06:02.216040 2026] [security2:error] [pid 496962:tid 497094] [client 20.104.50.220:32270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/32.php"] [unique_id "apPkao6aRhSu8gis9LluOgAABK8"]
[Sun Aug 30 03:06:02.230852 2026] [security2:error] [pid 496962:tid 497215] [client 20.220.204.93:62295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/ioxi.php"] [unique_id "apPkao6aRhSu8gis9LluPAAABSg"]
[Sun Aug 30 03:06:02.254569 2026] [security2:error] [pid 496962:tid 497194] [client 40.83.93.50:8377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/test.php"] [unique_id "apPkao6aRhSu8gis9LluQgAABRM"]
[Sun Aug 30 03:06:02.256700 2026] [security2:error] [pid 495314:tid 495458] [client 20.104.104.62:21743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/t00l.php"] [unique_id "apPkakmtdPfUFP1akVFV4wAABDY"]
[Sun Aug 30 03:06:02.258201 2026] [security2:error] [pid 495314:tid 495481] [client 20.48.251.3:23349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/wdf.php"] [unique_id "apPkakmtdPfUFP1akVFV6AAABE0"]
[Sun Aug 30 03:06:02.258817 2026] [authz_core:error] [pid 495314:tid 495449] [client 66.249.66.199:59520] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:02.259296 2026] [authz_core:error] [pid 495314:tid 495449] [client 66.249.66.199:59520] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:02.263654 2026] [authz_core:error] [pid 495314:tid 495548] [client 216.73.216.128:49464] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:02.263912 2026] [authz_core:error] [pid 495314:tid 495548] [client 216.73.216.128:49464] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:02.264183 2026] [security2:error] [pid 495314:tid 495472] [client 4.205.62.107:4116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/product.php"] [unique_id "apPkakmtdPfUFP1akVFV7QAABEQ"]
[Sun Aug 30 03:06:02.265075 2026] [security2:error] [pid 496962:tid 497173] [client 20.48.251.3:55545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/png.php"] [unique_id "apPkao6aRhSu8gis9LluRAAABP4"]
[Sun Aug 30 03:06:02.274625 2026] [security2:error] [pid 496962:tid 497162] [client 20.104.50.220:6095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wrt.php"] [unique_id "apPkao6aRhSu8gis9LluSwAABPM"]
[Sun Aug 30 03:06:02.286523 2026] [security2:error] [pid 496962:tid 497161] [client 20.48.251.3:7035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/product.php"] [unique_id "apPkao6aRhSu8gis9LluUwAABPI"]
[Sun Aug 30 03:06:02.288057 2026] [security2:error] [pid 496962:tid 497104] [client 4.205.62.107:2765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/paypal.php"] [unique_id "apPkao6aRhSu8gis9LluVwAABLk"]
[Sun Aug 30 03:06:02.316683 2026] [security2:error] [pid 495314:tid 495551] [client 4.205.62.107:56595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/environment.php"] [unique_id "apPkakmtdPfUFP1akVFWBgAABJM"]
[Sun Aug 30 03:06:02.358190 2026] [security2:error] [pid 495314:tid 495483] [client 4.205.62.107:44874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.senseoc.com"] [uri "/wp-act.php"] [unique_id "apPkakmtdPfUFP1akVFWIAAABE8"]
[Sun Aug 30 03:06:02.362831 2026] [security2:error] [pid 495314:tid 495450] [client 20.104.50.220:62800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/shapes.php"] [unique_id "apPkakmtdPfUFP1akVFWJAAABC4"]
[Sun Aug 30 03:06:02.383850 2026] [security2:error] [pid 496962:tid 497101] [client 20.220.204.93:62309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/bootstrap.php"] [unique_id "apPkao6aRhSu8gis9LluawAABLY"]
[Sun Aug 30 03:06:02.415217 2026] [security2:error] [pid 496962:tid 497146] [client 20.104.104.62:22109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/ls.php"] [unique_id "apPkao6aRhSu8gis9LlucQAABOM"]
[Sun Aug 30 03:06:02.460677 2026] [authz_core:error] [pid 495314:tid 495481] [client 66.249.66.194:55981] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:02.460968 2026] [authz_core:error] [pid 495314:tid 495481] [client 66.249.66.194:55981] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:02.505703 2026] [security2:error] [pid 495314:tid 495518] [client 20.151.200.44:24591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/wk/index.php"] [unique_id "apPkakmtdPfUFP1akVFWagAABHI"]
[Sun Aug 30 03:06:02.519620 2026] [security2:error] [pid 496962:tid 497136] [client 4.205.62.107:22587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/maxro.php"] [unique_id "apPkao6aRhSu8gis9LluigAABNk"]
[Sun Aug 30 03:06:02.534350 2026] [security2:error] [pid 495314:tid 495460] [client 20.48.251.3:52743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/cli_bootstrap.php"] [unique_id "apPkakmtdPfUFP1akVFWggAABDg"]
[Sun Aug 30 03:06:02.544416 2026] [security2:error] [pid 496962:tid 497126] [client 20.104.104.62:22116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/css/000.php"] [unique_id "apPkao6aRhSu8gis9LlujAAABM8"]
[Sun Aug 30 03:06:02.552766 2026] [security2:error] [pid 495314:tid 495454] [client 68.155.159.216:52703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/nf_tracking.php"] [unique_id "apPkakmtdPfUFP1akVFWiwAABDI"]
[Sun Aug 30 03:06:02.555883 2026] [security2:error] [pid 495314:tid 495528] [client 20.104.50.220:52847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/galekjaya.php"] [unique_id "apPkakmtdPfUFP1akVFWjgAABHw"]
[Sun Aug 30 03:06:02.561696 2026] [security2:error] [pid 495314:tid 495482] [client 4.205.62.107:18971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/sale.php"] [unique_id "apPkakmtdPfUFP1akVFWkAAABE4"]
[Sun Aug 30 03:06:02.601957 2026] [security2:error] [pid 495314:tid 495462] [client 20.220.204.93:64206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/export.php"] [unique_id "apPkakmtdPfUFP1akVFWrgAABDo"]
[Sun Aug 30 03:06:02.619414 2026] [security2:error] [pid 495314:tid 495504] [client 4.205.62.107:42067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/aws_keys.php"] [unique_id "apPkakmtdPfUFP1akVFWuQAABGQ"]
[Sun Aug 30 03:06:02.658852 2026] [security2:error] [pid 495314:tid 495461] [client 20.151.200.44:55619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/sf.php"] [unique_id "apPkakmtdPfUFP1akVFWxQAABDk"]
[Sun Aug 30 03:06:02.667512 2026] [security2:error] [pid 496962:tid 497211] [client 4.205.62.107:63957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/api.php"] [unique_id "apPkao6aRhSu8gis9LluogAABSQ"]
[Sun Aug 30 03:06:02.683760 2026] [authz_core:error] [pid 495314:tid 495476] [client 66.249.66.194:42660] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:02.684288 2026] [authz_core:error] [pid 495314:tid 495476] [client 66.249.66.194:42660] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:02.686368 2026] [security2:error] [pid 495314:tid 495527] [client 20.48.251.3:44379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/php-details.php"] [unique_id "apPkakmtdPfUFP1akVFW4QAABHs"]
[Sun Aug 30 03:06:02.689724 2026] [security2:error] [pid 495314:tid 495559] [client 20.104.104.62:22100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/cy.php"] [unique_id "apPkakmtdPfUFP1akVFW4gAABJs"]
[Sun Aug 30 03:06:02.712124 2026] [security2:error] [pid 496962:tid 497213] [client 20.104.18.15:13725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/codex.php"] [unique_id "apPkao6aRhSu8gis9LlupQAABSY"]
[Sun Aug 30 03:06:02.721064 2026] [security2:error] [pid 496962:tid 497208] [client 68.155.159.216:56375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/radio.php"] [unique_id "apPkao6aRhSu8gis9LluqAAABSE"]
[Sun Aug 30 03:06:02.732326 2026] [security2:error] [pid 495314:tid 495496] [client 40.83.93.50:9287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/dropdown.php"] [unique_id "apPkakmtdPfUFP1akVFW8gAABFw"]
[Sun Aug 30 03:06:02.736260 2026] [security2:error] [pid 495314:tid 495515] [client 20.104.50.220:33575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/css.php"] [unique_id "apPkakmtdPfUFP1akVFW8wAABG8"]
[Sun Aug 30 03:06:02.743953 2026] [security2:error] [pid 495314:tid 495554] [client 20.220.204.93:64175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/gk.php"] [unique_id "apPkakmtdPfUFP1akVFW-QAABJY"]
[Sun Aug 30 03:06:02.771456 2026] [security2:error] [pid 495314:tid 495550] [client 20.104.18.15:33738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/8.php"] [unique_id "apPkakmtdPfUFP1akVFW_gAABJI"]
[Sun Aug 30 03:06:02.806789 2026] [security2:error] [pid 495314:tid 495470] [client 158.23.147.79:53258] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.auscreen.com.au"] [uri "/1.php"] [unique_id "apPkakmtdPfUFP1akVFXFQAABEI"]
[Sun Aug 30 03:06:02.806892 2026] [security2:error] [pid 495314:tid 495470] [client 158.23.147.79:53258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/1.php"] [unique_id "apPkakmtdPfUFP1akVFXFQAABEI"]
[Sun Aug 30 03:06:02.830475 2026] [security2:error] [pid 496962:tid 497201] [client 20.104.18.15:43306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/domvf.php"] [unique_id "apPkao6aRhSu8gis9LlusAAABRo"]
[Sun Aug 30 03:06:02.831986 2026] [security2:error] [pid 496962:tid 497132] [client 20.104.104.62:21714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/admin.php/pindex.php"] [unique_id "apPkao6aRhSu8gis9LlusgAABNU"]
[Sun Aug 30 03:06:02.836839 2026] [security2:error] [pid 496962:tid 497215] [client 68.155.159.216:63990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/NewFile.php/"] [unique_id "apPkao6aRhSu8gis9LlutAAABSg"]
[Sun Aug 30 03:06:02.864518 2026] [security2:error] [pid 495314:tid 495447] [client 20.104.49.130:52426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wpxml.php"] [unique_id "apPkakmtdPfUFP1akVFXOAAABCs"]
[Sun Aug 30 03:06:02.888193 2026] [authz_core:error] [pid 496962:tid 497199] [client 66.249.66.194:60089] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:02.888690 2026] [authz_core:error] [pid 496962:tid 497199] [client 66.249.66.194:60089] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:02.891757 2026] [security2:error] [pid 495314:tid 495508] [client 158.23.147.79:54268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apPkakmtdPfUFP1akVFXRwAABGg"]
[Sun Aug 30 03:06:02.921383 2026] [security2:error] [pid 495314:tid 495536] [client 158.23.147.79:62512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-content/x/index.php"] [unique_id "apPkakmtdPfUFP1akVFXUwAABIQ"]
[Sun Aug 30 03:06:02.926114 2026] [security2:error] [pid 495314:tid 495566] [client 20.48.251.3:46194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/bigdump.php"] [unique_id "apPkakmtdPfUFP1akVFXVQAABKI"]
[Sun Aug 30 03:06:02.932660 2026] [security2:error] [pid 496962:tid 497153] [client 158.23.147.79:63914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/nf_tracking.php"] [unique_id "apPkao6aRhSu8gis9LluyAAABOo"]
[Sun Aug 30 03:06:02.952686 2026] [security2:error] [pid 495314:tid 495493] [client 68.155.159.216:62287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPkakmtdPfUFP1akVFXZQAABFk"]
[Sun Aug 30 03:06:02.964355 2026] [security2:error] [pid 496962:tid 497214] [client 20.104.104.62:63381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/admin.php/csv.php"] [unique_id "apPkao6aRhSu8gis9LluygAABSc"]
[Sun Aug 30 03:06:02.984264 2026] [security2:error] [pid 495314:tid 495453] [client 20.220.204.93:62316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/logs1.php"] [unique_id "apPkakmtdPfUFP1akVFXfQAABDE"]
[Sun Aug 30 03:06:02.987500 2026] [core:error] [pid 495314:tid 495533] [client 40.83.93.50:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:06:02.987520 2026] [core:error] [pid 495314:tid 495533] [client 40.83.93.50:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:06:02.989307 2026] [security2:error] [pid 495314:tid 495527] [client 158.23.147.79:53264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/ws.php"] [unique_id "apPkakmtdPfUFP1akVFXggAABHs"]
[Sun Aug 30 03:06:02.995249 2026] [security2:error] [pid 495314:tid 495535] [client 158.23.147.79:53535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/chosen.php"] [unique_id "apPkakmtdPfUFP1akVFXhgAABIM"]
[Sun Aug 30 03:06:03.020087 2026] [security2:error] [pid 495314:tid 495562] [client 20.104.50.220:63496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/cargo.php"] [unique_id "apPka0mtdPfUFP1akVFXlQAABJ4"]
[Sun Aug 30 03:06:03.037999 2026] [security2:error] [pid 495314:tid 495503] [client 158.23.147.79:63928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wzy.php"] [unique_id "apPka0mtdPfUFP1akVFXqAAABGM"]
[Sun Aug 30 03:06:03.081700 2026] [security2:error] [pid 496962:tid 497202] [client 158.23.147.79:62552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/packed.php"] [unique_id "apPka46aRhSu8gis9Llu3gAABRs"]
[Sun Aug 30 03:06:03.085299 2026] [security2:error] [pid 495314:tid 495550] [client 68.155.159.216:12321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/file88.php"] [unique_id "apPka0mtdPfUFP1akVFXwAAABJI"]
[Sun Aug 30 03:06:03.085949 2026] [authz_core:error] [pid 495314:tid 495504] [client 216.73.216.128:23351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:03.086198 2026] [authz_core:error] [pid 495314:tid 495504] [client 216.73.216.128:23351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:03.087742 2026] [security2:error] [pid 496962:tid 497137] [client 20.104.50.220:27402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/images/wp-login.php"] [unique_id "apPka46aRhSu8gis9Llu4AAABNo"]
[Sun Aug 30 03:06:03.095390 2026] [security2:error] [pid 496962:tid 497159] [client 158.23.147.79:42054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-includes/css/index.php"] [unique_id "apPka46aRhSu8gis9Llu5AAABPA"]
[Sun Aug 30 03:06:03.103801 2026] [security2:error] [pid 495314:tid 495532] [client 158.23.147.79:54263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/goods.php"] [unique_id "apPka0mtdPfUFP1akVFXxwAABIA"]
[Sun Aug 30 03:06:03.107848 2026] [security2:error] [pid 496962:tid 497099] [client 20.104.104.62:21755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/admin.php/700.php"] [unique_id "apPka46aRhSu8gis9Llu5wAABLQ"]
[Sun Aug 30 03:06:03.126096 2026] [authz_core:error] [pid 495314:tid 495488] [client 66.249.66.37:42553] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:03.126527 2026] [authz_core:error] [pid 495314:tid 495488] [client 66.249.66.37:42553] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:03.137031 2026] [security2:error] [pid 496962:tid 497187] [client 158.23.147.79:63991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apPka46aRhSu8gis9Llu6gAABQw"]
[Sun Aug 30 03:06:03.137821 2026] [security2:error] [pid 496962:tid 497145] [client 20.220.204.93:61791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/inege.php"] [unique_id "apPka46aRhSu8gis9Llu6wAABOI"]
[Sun Aug 30 03:06:03.145093 2026] [security2:error] [pid 495314:tid 495484] [client 4.205.62.107:65359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/hochladen.form.php"] [unique_id "apPka0mtdPfUFP1akVFX3wAABFA"]
[Sun Aug 30 03:06:03.174669 2026] [authz_core:error] [pid 495314:tid 495475] [client 216.73.216.128:49464] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:03.174936 2026] [authz_core:error] [pid 495314:tid 495475] [client 216.73.216.128:49464] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:03.185601 2026] [security2:error] [pid 495314:tid 495551] [client 20.104.50.220:46417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/foxwso.php"] [unique_id "apPka0mtdPfUFP1akVFX9wAABJM"]
[Sun Aug 30 03:06:03.198000 2026] [security2:error] [pid 495314:tid 495547] [client 4.205.62.107:63589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/aws_settings.php"] [unique_id "apPka0mtdPfUFP1akVFYAAAABI8"]
[Sun Aug 30 03:06:03.198194 2026] [security2:error] [pid 495314:tid 495525] [client 158.23.147.79:62512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apPka0mtdPfUFP1akVFYAgAABHk"]
[Sun Aug 30 03:06:03.199953 2026] [security2:error] [pid 496962:tid 497133] [client 40.83.93.50:8743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/mar.php"] [unique_id "apPka46aRhSu8gis9Llu8QAABNY"]
[Sun Aug 30 03:06:03.205761 2026] [security2:error] [pid 495314:tid 495538] [client 158.23.147.79:42067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/cgi-bin/wp-login.php"] [unique_id "apPka0mtdPfUFP1akVFX-gAABIY"]
[Sun Aug 30 03:06:03.232303 2026] [security2:error] [pid 495314:tid 495533] [client 20.104.50.220:61953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/bn.php"] [unique_id "apPka0mtdPfUFP1akVFYGQAABIE"]
[Sun Aug 30 03:06:03.240530 2026] [security2:error] [pid 496962:tid 497156] [client 158.23.147.79:54269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apPka46aRhSu8gis9Llu8wAABO0"]
[Sun Aug 30 03:06:03.242019 2026] [security2:error] [pid 495314:tid 495542] [client 158.23.147.79:62317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apPka0mtdPfUFP1akVFYJwAABIo"]
[Sun Aug 30 03:06:03.275352 2026] [security2:error] [pid 495314:tid 495511] [client 158.23.147.79:63232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-content/packed.php"] [unique_id "apPka0mtdPfUFP1akVFYPgAABGs"]
[Sun Aug 30 03:06:03.287342 2026] [security2:error] [pid 495314:tid 495556] [client 20.104.104.62:21723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/admin.php/007x.php"] [unique_id "apPka0mtdPfUFP1akVFYSAAABJg"]
[Sun Aug 30 03:06:03.301317 2026] [security2:error] [pid 495314:tid 495530] [client 158.23.147.79:53299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-content/cong.php"] [unique_id "apPka0mtdPfUFP1akVFYTwAABH4"]
[Sun Aug 30 03:06:03.322682 2026] [security2:error] [pid 495314:tid 495526] [client 68.155.159.216:54123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-admin/images/index.php"] [unique_id "apPka0mtdPfUFP1akVFYXwAABHo"]
[Sun Aug 30 03:06:03.327974 2026] [security2:error] [pid 496962:tid 497134] [client 20.220.204.93:62235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/wp-link10.php"] [unique_id "apPka46aRhSu8gis9LlvAgAABNc"]
[Sun Aug 30 03:06:03.344471 2026] [security2:error] [pid 496962:tid 497122] [client 209.141.32.143:41764] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "londynsfinancial.com"] [uri "/wp-content/plugins/tutor/readme.txt"] [unique_id "apPka46aRhSu8gis9LlvDAAABMs"]
[Sun Aug 30 03:06:03.346385 2026] [security2:error] [pid 495314:tid 495466] [client 158.23.147.79:54243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-admin/includes/nav.php"] [unique_id "apPka0mtdPfUFP1akVFYdAAABD4"]
[Sun Aug 30 03:06:03.352800 2026] [security2:error] [pid 495314:tid 495525] [client 158.23.147.79:62286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apPka0mtdPfUFP1akVFYeAAABHk"]
[Sun Aug 30 03:06:03.372814 2026] [security2:error] [pid 496962:tid 497128] [client 20.104.50.220:32555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/404.php"] [unique_id "apPka46aRhSu8gis9LlvFAAABNE"]
[Sun Aug 30 03:06:03.384912 2026] [security2:error] [pid 495314:tid 495448] [client 20.151.200.44:37863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/xda.php"] [unique_id "apPka0mtdPfUFP1akVFYjAAABCw"]
[Sun Aug 30 03:06:03.402033 2026] [security2:error] [pid 496962:tid 497159] [client 20.48.251.3:55440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/chosen.php"] [unique_id "apPka46aRhSu8gis9LlvHQAABPA"]
[Sun Aug 30 03:06:03.405453 2026] [security2:error] [pid 496962:tid 497108] [client 158.23.147.79:52946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-l0gin.php"] [unique_id "apPka46aRhSu8gis9LlvIAAABL0"]
[Sun Aug 30 03:06:03.405492 2026] [security2:error] [pid 496962:tid 497105] [client 20.48.251.3:23450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/bb.php"] [unique_id "apPka46aRhSu8gis9LlvIQAABLo"]
[Sun Aug 30 03:06:03.406393 2026] [security2:error] [pid 496962:tid 497181] [client 158.23.147.79:53291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPka46aRhSu8gis9LlvIgAABQY"]
[Sun Aug 30 03:06:03.407697 2026] [security2:error] [pid 496962:tid 497143] [client 4.205.62.107:4144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/fun.php"] [unique_id "apPka46aRhSu8gis9LlvIwAABOA"]
[Sun Aug 30 03:06:03.412382 2026] [security2:error] [pid 496962:tid 497187] [client 20.104.50.220:5623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/bibil.php"] [unique_id "apPka46aRhSu8gis9LlvJQAABQw"]
[Sun Aug 30 03:06:03.426259 2026] [security2:error] [pid 495314:tid 495445] [client 4.205.62.107:2345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/userfuns.php"] [unique_id "apPka0mtdPfUFP1akVFYogAABCk"]
[Sun Aug 30 03:06:03.427742 2026] [security2:error] [pid 496962:tid 497147] [client 20.48.251.3:6985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/fun.php"] [unique_id "apPka46aRhSu8gis9LlvJgAABOQ"]
[Sun Aug 30 03:06:03.433517 2026] [security2:error] [pid 496962:tid 497094] [client 20.104.104.62:63414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/admin.php/heex.php"] [unique_id "apPka46aRhSu8gis9LlvJwAABK8"]
[Sun Aug 30 03:06:03.461109 2026] [security2:error] [pid 495314:tid 495566] [client 158.23.147.79:53522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/file.php"] [unique_id "apPka0mtdPfUFP1akVFYswAABKI"]
[Sun Aug 30 03:06:03.467184 2026] [security2:error] [pid 495314:tid 495562] [client 4.205.62.107:52152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/aws_secret_config.php"] [unique_id "apPka0mtdPfUFP1akVFYtwAABJ4"]
[Sun Aug 30 03:06:03.468099 2026] [security2:error] [pid 496962:tid 497215] [client 20.220.204.93:62251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/ww.php"] [unique_id "apPka46aRhSu8gis9LlvKgAABSg"]
[Sun Aug 30 03:06:03.499251 2026] [security2:error] [pid 496962:tid 497216] [client 158.23.147.79:62217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apPka46aRhSu8gis9LlvNAAABSk"]
[Sun Aug 30 03:06:03.518162 2026] [security2:error] [pid 495314:tid 495449] [client 4.205.62.107:36023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/txets.php"] [unique_id "apPka0mtdPfUFP1akVFY0QAABC0"]
[Sun Aug 30 03:06:03.518654 2026] [security2:error] [pid 496962:tid 497176] [client 158.23.147.79:42089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPka46aRhSu8gis9LlvQAAABQE"]
[Sun Aug 30 03:06:03.536381 2026] [security2:error] [pid 496962:tid 497103] [client 20.104.50.220:28734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/sos.php"] [unique_id "apPka46aRhSu8gis9LlvRAAABLg"]
[Sun Aug 30 03:06:03.551962 2026] [security2:error] [pid 495314:tid 495445] [client 158.23.147.79:63233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apPka0mtdPfUFP1akVFY1wAABCk"]
[Sun Aug 30 03:06:03.553654 2026] [security2:error] [pid 495314:tid 495495] [client 4.205.62.107:32044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/bb.php"] [unique_id "apPka0mtdPfUFP1akVFY2AAABFs"]
[Sun Aug 30 03:06:03.554736 2026] [security2:error] [pid 495314:tid 495482] [client 158.23.147.79:62569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apPka0mtdPfUFP1akVFY2QAABE4"]
[Sun Aug 30 03:06:03.572298 2026] [security2:error] [pid 496962:tid 497109] [client 20.104.104.62:21748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/tf.php"] [unique_id "apPka46aRhSu8gis9LlvTAAABL4"]
[Sun Aug 30 03:06:03.612916 2026] [security2:error] [pid 496962:tid 497131] [client 20.220.204.93:64209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/w1px.php"] [unique_id "apPka46aRhSu8gis9LlvWAAABNQ"]
[Sun Aug 30 03:06:03.626215 2026] [security2:error] [pid 496962:tid 497202] [client 158.23.147.79:53288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-includes/Requests/network.php"] [unique_id "apPka46aRhSu8gis9LlvXQAABRs"]
[Sun Aug 30 03:06:03.656419 2026] [security2:error] [pid 496962:tid 497143] [client 158.23.147.79:53543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/file17.php"] [unique_id "apPka46aRhSu8gis9LlvZgAABOA"]
[Sun Aug 30 03:06:03.657777 2026] [security2:error] [pid 496962:tid 497184] [client 158.23.147.79:62536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-login.php"] [unique_id "apPka46aRhSu8gis9LlvaAAABQk"]
[Sun Aug 30 03:06:03.659441 2026] [security2:error] [pid 496962:tid 497208] [client 4.205.62.107:62456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/brc.php"] [unique_id "apPka46aRhSu8gis9LlvagAABSE"]
[Sun Aug 30 03:06:03.670613 2026] [security2:error] [pid 496962:tid 497132] [client 158.23.147.79:63977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apPka46aRhSu8gis9LlvcQAABNU"]
[Sun Aug 30 03:06:03.671809 2026] [security2:error] [pid 496962:tid 497204] [client 20.48.251.3:59347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/dd.php"] [unique_id "apPka46aRhSu8gis9LlvdAAABR0"]
[Sun Aug 30 03:06:03.691046 2026] [security2:error] [pid 496962:tid 497176] [client 4.205.62.107:27306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/packed.php"] [unique_id "apPka46aRhSu8gis9LlvgQAABQE"]
[Sun Aug 30 03:06:03.715414 2026] [security2:error] [pid 495314:tid 495503] [client 40.83.93.50:8377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/css.php"] [unique_id "apPka0mtdPfUFP1akVFZFgAABGM"]
[Sun Aug 30 03:06:03.725714 2026] [security2:error] [pid 495314:tid 495467] [client 4.205.62.107:18798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/wp-class.php"] [unique_id "apPka0mtdPfUFP1akVFZHQAABD8"]
[Sun Aug 30 03:06:03.727174 2026] [security2:error] [pid 496962:tid 497196] [client 20.104.104.62:21704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/update/da222.php"] [unique_id "apPka46aRhSu8gis9LlvigAABRU"]
[Sun Aug 30 03:06:03.748911 2026] [security2:error] [pid 496962:tid 497209] [client 20.220.204.93:62298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/to.php"] [unique_id "apPka46aRhSu8gis9LlvjAAABSI"]
[Sun Aug 30 03:06:03.749454 2026] [security2:error] [pid 496962:tid 497139] [client 158.23.147.79:53268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-content/radio.php"] [unique_id "apPka46aRhSu8gis9LlvjQAABNw"]
[Sun Aug 30 03:06:03.769821 2026] [security2:error] [pid 496962:tid 497115] [client 20.104.50.220:29143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-admin/evil.php"] [unique_id "apPka46aRhSu8gis9LlvjwAABMQ"]
[Sun Aug 30 03:06:03.792521 2026] [security2:error] [pid 496962:tid 497131] [client 158.23.147.79:62533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPka46aRhSu8gis9LlvkAAABNQ"]
[Sun Aug 30 03:06:03.800308 2026] [security2:error] [pid 496962:tid 497120] [client 158.23.147.79:63904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/packed.php"] [unique_id "apPka46aRhSu8gis9LlvkQAABMk"]
[Sun Aug 30 03:06:03.803502 2026] [security2:error] [pid 496962:tid 497150] [client 4.205.62.107:42613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/umgebung.php"] [unique_id "apPka46aRhSu8gis9LlvkgAABOc"]
[Sun Aug 30 03:06:03.804556 2026] [security2:error] [pid 496962:tid 497211] [client 4.205.62.107:63986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/temp.php"] [unique_id "apPka46aRhSu8gis9LlvkwAABSQ"]
[Sun Aug 30 03:06:03.806546 2026] [security2:error] [pid 495314:tid 495534] [client 20.104.49.130:48036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPka0mtdPfUFP1akVFZMgAABII"]
[Sun Aug 30 03:06:03.825483 2026] [security2:error] [pid 496962:tid 497204] [client 158.23.147.79:54249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/file5.php"] [unique_id "apPka46aRhSu8gis9LlvmwAABR0"]
[Sun Aug 30 03:06:03.826678 2026] [security2:error] [pid 496962:tid 497107] [client 20.48.251.3:44385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/routes.php"] [unique_id "apPka46aRhSu8gis9LlvnQAABLw"]
[Sun Aug 30 03:06:03.842156 2026] [security2:error] [pid 496962:tid 497160] [client 68.155.159.216:56432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPka46aRhSu8gis9LlvpwAABPE"]
[Sun Aug 30 03:06:03.859398 2026] [security2:error] [pid 496962:tid 497174] [client 158.23.147.79:62546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apPka46aRhSu8gis9LlvrgAABP8"]
[Sun Aug 30 03:06:03.860869 2026] [authz_core:error] [pid 495314:tid 495459] [client 66.249.66.37:58294] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:03.861134 2026] [authz_core:error] [pid 495314:tid 495459] [client 66.249.66.37:58294] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:03.861284 2026] [security2:error] [pid 496962:tid 497098] [client 158.23.147.79:42093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-admin/dropdown.php"] [unique_id "apPka46aRhSu8gis9LlvsQAABLM"]
[Sun Aug 30 03:06:03.870150 2026] [security2:error] [pid 495314:tid 495559] [client 68.155.159.216:52678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wzy.php"] [unique_id "apPka0mtdPfUFP1akVFZTAAABJs"]
[Sun Aug 30 03:06:03.876107 2026] [security2:error] [pid 496962:tid 497103] [client 20.104.18.15:13655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/5656.php"] [unique_id "apPka46aRhSu8gis9LlvuQAABLg"]
[Sun Aug 30 03:06:03.876350 2026] [security2:error] [pid 495314:tid 495503] [client 20.104.50.220:33328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/cp.php"] [unique_id "apPka0mtdPfUFP1akVFZTgAABGM"]
[Sun Aug 30 03:06:03.878002 2026] [security2:error] [pid 495314:tid 495553] [client 20.220.204.93:64185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/thui.php"] [unique_id "apPka0mtdPfUFP1akVFZUAAABJU"]
[Sun Aug 30 03:06:03.882899 2026] [security2:error] [pid 495314:tid 495495] [client 20.104.104.62:22104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/qi.php"] [unique_id "apPka0mtdPfUFP1akVFZUwAABFs"]
[Sun Aug 30 03:06:03.899578 2026] [security2:error] [pid 495314:tid 495462] [client 158.23.147.79:63893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-content/packed.php"] [unique_id "apPka0mtdPfUFP1akVFZWAAABDo"]
[Sun Aug 30 03:06:03.933356 2026] [security2:error] [pid 495314:tid 495488] [client 158.23.147.79:54250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/file88.php"] [unique_id "apPka0mtdPfUFP1akVFZaAAABFQ"]
[Sun Aug 30 03:06:03.940231 2026] [security2:error] [pid 495314:tid 495486] [client 20.104.18.15:33673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/goods.php"] [unique_id "apPka0mtdPfUFP1akVFZbgAABFI"]
[Sun Aug 30 03:06:03.974035 2026] [security2:error] [pid 496962:tid 497118] [client 20.104.18.15:43974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/biufile.php"] [unique_id "apPka46aRhSu8gis9LlvygAABMc"]
[Sun Aug 30 03:06:03.981771 2026] [security2:error] [pid 495314:tid 495564] [client 158.23.147.79:52938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/ans.php"] [unique_id "apPka0mtdPfUFP1akVFZhgAABKA"]
[Sun Aug 30 03:06:03.995108 2026] [security2:error] [pid 495314:tid 495444] [client 158.23.147.79:53280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/login.php"] [unique_id "apPka0mtdPfUFP1akVFZjgAABCg"]
[Sun Aug 30 03:06:03.999022 2026] [security2:error] [pid 496962:tid 497096] [client 158.23.147.79:63250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-admin/images/about.php"] [unique_id "apPka46aRhSu8gis9Llv0AAABLE"]
[Sun Aug 30 03:06:04.022016 2026] [security2:error] [pid 496962:tid 497104] [client 158.23.147.79:62232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-l0gin.php"] [unique_id "apPkbI6aRhSu8gis9Llv1AAABLk"]
[Sun Aug 30 03:06:04.027105 2026] [security2:error] [pid 496962:tid 497169] [client 20.104.104.62:63383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/px.php"] [unique_id "apPkbI6aRhSu8gis9Llv2QAABPo"]
[Sun Aug 30 03:06:04.039178 2026] [security2:error] [pid 496962:tid 497163] [client 158.23.147.79:54231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/NewFile.php/"] [unique_id "apPkbI6aRhSu8gis9Llv3wAABPQ"]
[Sun Aug 30 03:06:04.055906 2026] [security2:error] [pid 496962:tid 497152] [client 20.220.204.93:62297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/Jcrop.php"] [unique_id "apPkbI6aRhSu8gis9Llv6gAABOk"]
[Sun Aug 30 03:06:04.067935 2026] [security2:error] [pid 496962:tid 497113] [client 68.155.159.216:63548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/makeasmtp.php"] [unique_id "apPkbI6aRhSu8gis9Llv9AAABMI"]
[Sun Aug 30 03:06:04.080135 2026] [security2:error] [pid 496962:tid 497097] [client 158.23.147.79:62466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/worksec.php"] [unique_id "apPkbI6aRhSu8gis9Llv9QAABLI"]
[Sun Aug 30 03:06:04.090056 2026] [security2:error] [pid 495314:tid 495545] [client 158.23.147.79:53284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/hehehehe.php"] [unique_id "apPkbEmtdPfUFP1akVFZvgAABI0"]
[Sun Aug 30 03:06:04.098531 2026] [security2:error] [pid 496962:tid 497131] [client 20.48.251.3:54846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/wdf.php"] [unique_id "apPkbI6aRhSu8gis9Llv-gAABNQ"]
[Sun Aug 30 03:06:04.105555 2026] [authz_core:error] [pid 496962:tid 497149] [client 66.249.66.68:38691] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:04.105840 2026] [authz_core:error] [pid 496962:tid 497149] [client 66.249.66.68:38691] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:04.132802 2026] [security2:error] [pid 495314:tid 495542] [client 158.23.147.79:62561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPkbEmtdPfUFP1akVFZzgAABIo"]
[Sun Aug 30 03:06:04.140069 2026] [authz_core:error] [pid 496962:tid 497106] [client 66.249.66.64:47758] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:04.140376 2026] [authz_core:error] [pid 496962:tid 497106] [client 66.249.66.64:47758] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:04.147043 2026] [security2:error] [pid 495314:tid 495519] [client 158.23.147.79:53542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/dropdown.php"] [unique_id "apPkbEmtdPfUFP1akVFZ1wAABHM"]
[Sun Aug 30 03:06:04.175013 2026] [security2:error] [pid 495314:tid 495508] [client 20.104.50.220:42768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/col1.php"] [unique_id "apPkbEmtdPfUFP1akVFZ6AAABGg"]
[Sun Aug 30 03:06:04.186598 2026] [security2:error] [pid 495314:tid 495499] [client 4.205.62.107:32499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/file59.php"] [unique_id "apPkbEmtdPfUFP1akVFZ8wAABF8"]
[Sun Aug 30 03:06:04.191210 2026] [security2:error] [pid 496962:tid 497156] [client 158.23.147.79:62279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apPkbI6aRhSu8gis9LlwCQAABO0"]
[Sun Aug 30 03:06:04.192422 2026] [security2:error] [pid 495314:tid 495449] [client 20.104.104.62:21734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/is.php"] [unique_id "apPkbEmtdPfUFP1akVFZ-AAABC0"]
[Sun Aug 30 03:06:04.204869 2026] [security2:error] [pid 495314:tid 495462] [client 68.155.159.216:12302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/NewFile.php/"] [unique_id "apPkbEmtdPfUFP1akVFaAgAABDo"]
[Sun Aug 30 03:06:04.208408 2026] [authz_core:error] [pid 495314:tid 495456] [client 66.249.66.40:46164] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:04.208682 2026] [authz_core:error] [pid 495314:tid 495456] [client 66.249.66.40:46164] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:04.213441 2026] [security2:error] [pid 496962:tid 497174] [client 40.83.93.50:9042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/autoload_classmap.php"] [unique_id "apPkbI6aRhSu8gis9LlwDwAABP8"]
[Sun Aug 30 03:06:04.222060 2026] [security2:error] [pid 496962:tid 497092] [client 20.104.50.220:27091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/wp-includes/option.php"] [unique_id "apPkbI6aRhSu8gis9LlwEgAABK0"]
[Sun Aug 30 03:06:04.224392 2026] [authz_core:error] [pid 495314:tid 495498] [client 66.249.66.202:53929] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:04.224821 2026] [authz_core:error] [pid 495314:tid 495498] [client 66.249.66.202:53929] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:04.226674 2026] [security2:error] [pid 495314:tid 495554] [client 20.151.200.44:47416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/dehnl.php"] [unique_id "apPkbEmtdPfUFP1akVFaEQAABJY"]
[Sun Aug 30 03:06:04.240942 2026] [security2:error] [pid 495314:tid 495513] [client 158.23.147.79:53261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-includes/fonts/about.php"] [unique_id "apPkbEmtdPfUFP1akVFaGwAABG0"]
[Sun Aug 30 03:06:04.252664 2026] [security2:error] [pid 496962:tid 497186] [client 20.220.204.93:64156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/ws58.php"] [unique_id "apPkbI6aRhSu8gis9LlwIAAABQs"]
[Sun Aug 30 03:06:04.269613 2026] [security2:error] [pid 496962:tid 497216] [client 158.23.147.79:62552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-admin.php"] [unique_id "apPkbI6aRhSu8gis9LlwIQAABSk"]
[Sun Aug 30 03:06:04.300799 2026] [authz_core:error] [pid 495314:tid 495512] [client 66.249.66.71:63634] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:04.301096 2026] [authz_core:error] [pid 495314:tid 495512] [client 66.249.66.71:63634] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:04.303444 2026] [security2:error] [pid 496962:tid 497148] [client 158.23.147.79:53508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/.well-known/index.php"] [unique_id "apPkbI6aRhSu8gis9LlwMwAABOU"]
[Sun Aug 30 03:06:04.304248 2026] [security2:error] [pid 496962:tid 497159] [client 158.23.147.79:62510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/x.php"] [unique_id "apPkbI6aRhSu8gis9LlwNAAABPA"]
[Sun Aug 30 03:06:04.323801 2026] [security2:error] [pid 496962:tid 497120] [client 20.104.50.220:46635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/gank.php"] [unique_id "apPkbI6aRhSu8gis9LlwOQAABMk"]
[Sun Aug 30 03:06:04.327799 2026] [security2:error] [pid 496962:tid 497208] [client 4.205.62.107:30360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/debuggen.php"] [unique_id "apPkbI6aRhSu8gis9LlwPAAABSE"]
[Sun Aug 30 03:06:04.332023 2026] [security2:error] [pid 495314:tid 495550] [client 158.23.147.79:63937] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/ioxi002.PhP7"] [unique_id "apPkbEmtdPfUFP1akVFaSAAABJI"]
[Sun Aug 30 03:06:04.339900 2026] [security2:error] [pid 495314:tid 495543] [client 4.205.62.107:63559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/wp-konfig.backup.php"] [unique_id "apPkbEmtdPfUFP1akVFaUwAABIs"]
[Sun Aug 30 03:06:04.349851 2026] [security2:error] [pid 496962:tid 497180] [client 68.155.159.216:63973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/dropdown.php"] [unique_id "apPkbI6aRhSu8gis9LlwSAAABQU"]
[Sun Aug 30 03:06:04.376897 2026] [authz_core:error] [pid 495314:tid 495508] [client 216.73.216.128:23351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:04.377295 2026] [authz_core:error] [pid 495314:tid 495508] [client 216.73.216.128:23351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:04.380144 2026] [security2:error] [pid 496962:tid 497109] [client 20.104.50.220:61961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/dm.php"] [unique_id "apPkbI6aRhSu8gis9LlwVgAABL4"]
[Sun Aug 30 03:06:04.387204 2026] [security2:error] [pid 496962:tid 497182] [client 20.220.204.93:64128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/xs.php"] [unique_id "apPkbI6aRhSu8gis9LlwWAAABQc"]
[Sun Aug 30 03:06:04.392489 2026] [security2:error] [pid 496962:tid 497128] [client 20.104.104.62:21704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/od.php"] [unique_id "apPkbI6aRhSu8gis9LlwWQAABNE"]
[Sun Aug 30 03:06:04.397341 2026] [security2:error] [pid 495314:tid 495450] [client 158.23.147.79:62562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apPkbEmtdPfUFP1akVFabQAABC4"]
[Sun Aug 30 03:06:04.400786 2026] [security2:error] [pid 496962:tid 497196] [client 158.23.147.79:4069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-content/admin.php"] [unique_id "apPkbI6aRhSu8gis9LlwXwAABRU"]
[Sun Aug 30 03:06:04.418148 2026] [security2:error] [pid 496962:tid 497148] [client 158.23.147.79:63237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-content/x.php"] [unique_id "apPkbI6aRhSu8gis9LlwaAAABOU"]
[Sun Aug 30 03:06:04.423309 2026] [security2:error] [pid 496962:tid 497101] [client 158.23.147.79:53531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-content/themes/too.php"] [unique_id "apPkbI6aRhSu8gis9LlwawAABLY"]
[Sun Aug 30 03:06:04.423507 2026] [security2:error] [pid 496962:tid 497125] [client 20.151.200.44:63585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/wt.php"] [unique_id "apPkbI6aRhSu8gis9LlwbAAABM4"]
[Sun Aug 30 03:06:04.489084 2026] [security2:error] [pid 496962:tid 497124] [client 158.23.147.79:62211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPkbI6aRhSu8gis9LlwhQAABM0"]
[Sun Aug 30 03:06:04.495968 2026] [security2:error] [pid 496962:tid 497207] [client 68.155.159.216:59951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-includes/index.php"] [unique_id "apPkbI6aRhSu8gis9LlwiAAABSA"]
[Sun Aug 30 03:06:04.507807 2026] [security2:error] [pid 496962:tid 497114] [client 20.104.50.220:32096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/4x4.php"] [unique_id "apPkbI6aRhSu8gis9LlwkQAABMM"]
[Sun Aug 30 03:06:04.507985 2026] [security2:error] [pid 496962:tid 497198] [client 158.23.147.79:53310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/xmlrpc.php"] [unique_id "apPkbI6aRhSu8gis9LlwkgAABRc"]
[Sun Aug 30 03:06:04.517329 2026] [security2:error] [pid 496962:tid 497101] [client 158.23.147.79:54259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/radio.php"] [unique_id "apPkbI6aRhSu8gis9LlwlQAABLY"]
[Sun Aug 30 03:06:04.535424 2026] [security2:error] [pid 496962:tid 497200] [client 20.48.251.3:50015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/admin-ajax.php"] [unique_id "apPkbI6aRhSu8gis9LlwmwAABRk"]
[Sun Aug 30 03:06:04.541737 2026] [security2:error] [pid 495314:tid 495516] [client 20.220.204.93:64216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/zu.php"] [unique_id "apPkbEmtdPfUFP1akVFapAAABHA"]
[Sun Aug 30 03:06:04.543014 2026] [security2:error] [pid 495314:tid 495535] [client 20.48.251.3:23449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/file59.php"] [unique_id "apPkbEmtdPfUFP1akVFapQAABIM"]
[Sun Aug 30 03:06:04.549553 2026] [security2:error] [pid 495314:tid 495530] [client 20.104.50.220:6094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/radio.php"] [unique_id "apPkbEmtdPfUFP1akVFaqAAABH4"]
[Sun Aug 30 03:06:04.558161 2026] [security2:error] [pid 495314:tid 495474] [client 20.104.104.62:21700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/wp-the.php"] [unique_id "apPkbEmtdPfUFP1akVFarQAABEY"]
[Sun Aug 30 03:06:04.563112 2026] [security2:error] [pid 496962:tid 497120] [client 4.205.62.107:5100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/kedi.php"] [unique_id "apPkbI6aRhSu8gis9LlwoQAABMk"]
[Sun Aug 30 03:06:04.570720 2026] [security2:error] [pid 495314:tid 495496] [client 158.23.147.79:62583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/lock.php"] [unique_id "apPkbEmtdPfUFP1akVFasAAABFw"]
[Sun Aug 30 03:06:04.573333 2026] [security2:error] [pid 495314:tid 495494] [client 158.23.147.79:62541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPkbEmtdPfUFP1akVFasQAABFo"]
[Sun Aug 30 03:06:04.575383 2026] [security2:error] [pid 496962:tid 497184] [client 20.48.251.3:64452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/rpk.php"] [unique_id "apPkbI6aRhSu8gis9LlwpgAABQk"]
[Sun Aug 30 03:06:04.592019 2026] [security2:error] [pid 495314:tid 495531] [client 4.205.62.107:2786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/mamzi.php"] [unique_id "apPkbEmtdPfUFP1akVFauQAABH8"]
[Sun Aug 30 03:06:04.600719 2026] [security2:error] [pid 496962:tid 497155] [client 158.23.147.79:63978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/ans.php"] [unique_id "apPkbI6aRhSu8gis9LlwrQAABOw"]
[Sun Aug 30 03:06:04.606893 2026] [security2:error] [pid 495314:tid 495446] [client 4.205.62.107:56588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/snq.php"] [unique_id "apPkbEmtdPfUFP1akVFawgAABCo"]
[Sun Aug 30 03:06:04.613085 2026] [security2:error] [pid 496962:tid 497217] [client 158.23.147.79:42081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/atomlib.php"] [unique_id "apPkbI6aRhSu8gis9LlwtQAABSo"]
[Sun Aug 30 03:06:04.615554 2026] [security2:error] [pid 496962:tid 497124] [client 20.48.251.3:7364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/xin1.php"] [unique_id "apPkbI6aRhSu8gis9LlwuAAABM0"]
[Sun Aug 30 03:06:04.629099 2026] [authz_core:error] [pid 495314:tid 495482] [client 66.249.66.194:55981] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:04.629523 2026] [authz_core:error] [pid 495314:tid 495482] [client 66.249.66.194:55981] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:04.649021 2026] [authz_core:error] [pid 495314:tid 495502] [client 66.249.66.198:53278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:04.649326 2026] [authz_core:error] [pid 495314:tid 495502] [client 66.249.66.198:53278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:04.652656 2026] [security2:error] [pid 495314:tid 495524] [client 158.23.147.79:53537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPkbEmtdPfUFP1akVFa2AAABHg"]
[Sun Aug 30 03:06:04.678956 2026] [security2:error] [pid 496962:tid 497134] [client 20.220.204.93:64226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/lanka.php"] [unique_id "apPkbI6aRhSu8gis9LlwzQAABNc"]
[Sun Aug 30 03:06:04.697607 2026] [authz_core:error] [pid 495314:tid 495530] [client 66.249.66.67:41746] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:04.697903 2026] [authz_core:error] [pid 495314:tid 495530] [client 66.249.66.67:41746] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:04.719916 2026] [security2:error] [pid 496962:tid 497180] [client 20.104.49.130:36315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/wpxml.php"] [unique_id "apPkbI6aRhSu8gis9Llw3AAABQU"]
[Sun Aug 30 03:06:04.722331 2026] [security2:error] [pid 496962:tid 497194] [client 20.104.104.62:63369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/wt.php"] [unique_id "apPkbI6aRhSu8gis9Llw3wAABRM"]
[Sun Aug 30 03:06:04.723005 2026] [security2:error] [pid 495314:tid 495505] [client 20.104.50.220:52825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/print.php"] [unique_id "apPkbEmtdPfUFP1akVFa9QAABGU"]
[Sun Aug 30 03:06:04.725670 2026] [security2:error] [pid 495314:tid 495531] [client 158.23.147.79:63920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/worksec.php"] [unique_id "apPkbEmtdPfUFP1akVFa9wAABH8"]
[Sun Aug 30 03:06:04.741308 2026] [security2:error] [pid 495314:tid 495470] [client 40.83.93.50:9037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/info.php"] [unique_id "apPkbEmtdPfUFP1akVFa_gAABEI"]
[Sun Aug 30 03:06:04.770261 2026] [security2:error] [pid 495314:tid 495526] [client 34.34.225.205:18480] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/"] [unique_id "apPkbEmtdPfUFP1akVFbAgAABHo"]
[Sun Aug 30 03:06:04.784816 2026] [security2:error] [pid 496962:tid 497186] [client 158.23.147.79:54610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/makeasmtp.php"] [unique_id "apPkbI6aRhSu8gis9Llw5AAABQs"]
[Sun Aug 30 03:06:04.796035 2026] [security2:error] [pid 496962:tid 497112] [client 4.205.62.107:62463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/vx.php"] [unique_id "apPkbI6aRhSu8gis9Llw6AAABME"]
[Sun Aug 30 03:06:04.804577 2026] [authz_core:error] [pid 496962:tid 497217] [client 66.249.66.34:63891] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:04.804881 2026] [authz_core:error] [pid 496962:tid 497217] [client 66.249.66.34:63891] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:04.810682 2026] [security2:error] [pid 496962:tid 497109] [client 20.48.251.3:55713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/wp-tem.php"] [unique_id "apPkbI6aRhSu8gis9Llw6wAABL4"]
[Sun Aug 30 03:06:04.820697 2026] [security2:error] [pid 496962:tid 497110] [client 158.23.147.79:4066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/lv.php"] [unique_id "apPkbI6aRhSu8gis9Llw9AAABL8"]
[Sun Aug 30 03:06:04.828354 2026] [security2:error] [pid 496962:tid 497104] [client 158.23.147.79:52900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/log-mama/function.php"] [unique_id "apPkbI6aRhSu8gis9Llw9wAABLk"]
[Sun Aug 30 03:06:04.845763 2026] [security2:error] [pid 496962:tid 497125] [client 20.104.49.130:63258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/chosen.php"] [unique_id "apPkbI6aRhSu8gis9LlxAAAABM4"]
[Sun Aug 30 03:06:04.845782 2026] [security2:error] [pid 496962:tid 497154] [client 158.23.147.79:63257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/index/function.php"] [unique_id "apPkbI6aRhSu8gis9LlxAQAABOs"]
[Sun Aug 30 03:06:04.884829 2026] [security2:error] [pid 495314:tid 495498] [client 158.23.147.79:54238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apPkbEmtdPfUFP1akVFbNAAABF4"]
[Sun Aug 30 03:06:04.886884 2026] [security2:error] [pid 496962:tid 497093] [client 20.104.104.62:22084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/im.php"] [unique_id "apPkbI6aRhSu8gis9LlxGAAABK4"]
[Sun Aug 30 03:06:04.913216 2026] [security2:error] [pid 496962:tid 497112] [client 158.23.147.79:53311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-includes/Text/index.php"] [unique_id "apPkbI6aRhSu8gis9LlxGQAABME"]
[Sun Aug 30 03:06:04.916378 2026] [security2:error] [pid 496962:tid 497109] [client 20.151.200.44:47321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/png.php"] [unique_id "apPkbI6aRhSu8gis9LlxGgAABL4"]
[Sun Aug 30 03:06:04.918220 2026] [security2:error] [pid 495314:tid 495470] [client 4.205.62.107:18632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/database.php"] [unique_id "apPkbEmtdPfUFP1akVFbSAAABEI"]
[Sun Aug 30 03:06:04.924635 2026] [authz_core:error] [pid 495314:tid 495479] [client 216.73.216.128:23351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:04.924927 2026] [authz_core:error] [pid 495314:tid 495479] [client 216.73.216.128:23351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:04.936895 2026] [security2:error] [pid 495314:tid 495514] [client 158.23.147.79:63986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/x.php"] [unique_id "apPkbEmtdPfUFP1akVFbUwAABG4"]
[Sun Aug 30 03:06:04.951327 2026] [security2:error] [pid 495314:tid 495571] [client 68.155.159.216:56400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/makeasmtp.php"] [unique_id "apPkbEmtdPfUFP1akVFbXQAABKc"]
[Sun Aug 30 03:06:04.954898 2026] [security2:error] [pid 496962:tid 497147] [client 4.205.62.107:62132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/fm.php"] [unique_id "apPkbI6aRhSu8gis9LlxHwAABOQ"]
[Sun Aug 30 03:06:04.955412 2026] [security2:error] [pid 496962:tid 497114] [client 20.220.204.93:64173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/gettest.php"] [unique_id "apPkbI6aRhSu8gis9LlxIAAABMM"]
[Sun Aug 30 03:06:04.957181 2026] [authz_core:error] [pid 495314:tid 495510] [client 66.249.66.36:53319] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:04.957513 2026] [authz_core:error] [pid 495314:tid 495510] [client 66.249.66.36:53319] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:04.965817 2026] [security2:error] [pid 495314:tid 495465] [client 20.48.251.3:44393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/aww.php"] [unique_id "apPkbEmtdPfUFP1akVFbZgAABD0"]
[Sun Aug 30 03:06:04.975551 2026] [security2:error] [pid 496962:tid 497197] [client 4.205.62.107:42614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/old_phpinfo.php"] [unique_id "apPkbI6aRhSu8gis9LlxJAAABRY"]
[Sun Aug 30 03:06:04.981178 2026] [security2:error] [pid 496962:tid 497200] [client 4.205.62.107:27300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/wp-info.php"] [unique_id "apPkbI6aRhSu8gis9LlxKAAABRk"]
[Sun Aug 30 03:06:04.991786 2026] [security2:error] [pid 495314:tid 495497] [client 158.23.147.79:54227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apPkbEmtdPfUFP1akVFbeAAABF0"]
[Sun Aug 30 03:06:05.008094 2026] [security2:error] [pid 495314:tid 495558] [client 216.73.216.128:32444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPkbUmtdPfUFP1akVFbhwAABJo"]
[Sun Aug 30 03:06:05.011880 2026] [security2:error] [pid 495314:tid 495481] [client 20.104.50.220:33183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/cyto.php"] [unique_id "apPkbUmtdPfUFP1akVFbiAAABE0"]
[Sun Aug 30 03:06:05.018974 2026] [security2:error] [pid 495314:tid 495568] [client 68.155.159.216:52659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apPkbUmtdPfUFP1akVFbjQAABKQ"]
[Sun Aug 30 03:06:05.027610 2026] [security2:error] [pid 495314:tid 495540] [client 20.104.50.220:29600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-admin/ichi.php"] [unique_id "apPkbUmtdPfUFP1akVFblQAABIg"]
[Sun Aug 30 03:06:05.036432 2026] [security2:error] [pid 495314:tid 495465] [client 20.104.18.15:13714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/w3lls.php"] [unique_id "apPkbUmtdPfUFP1akVFbngAABD0"]
[Sun Aug 30 03:06:05.054612 2026] [security2:error] [pid 495314:tid 495497] [client 20.104.104.62:21709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/file.php"] [unique_id "apPkbUmtdPfUFP1akVFbrAAABF0"]
[Sun Aug 30 03:06:05.064862 2026] [security2:error] [pid 495314:tid 495444] [client 158.23.147.79:42094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/content.php"] [unique_id "apPkbUmtdPfUFP1akVFbtAAABCg"]
[Sun Aug 30 03:06:05.081711 2026] [security2:error] [pid 495314:tid 495481] [client 20.104.18.15:33751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/ah.php"] [unique_id "apPkbUmtdPfUFP1akVFbwwAABE0"]
[Sun Aug 30 03:06:05.087107 2026] [security2:error] [pid 495314:tid 495446] [client 158.23.147.79:63260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/.well-known/content.php"] [unique_id "apPkbUmtdPfUFP1akVFbxwAABCo"]
[Sun Aug 30 03:06:05.088154 2026] [security2:error] [pid 495314:tid 495458] [client 4.205.62.107:36631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/time.php"] [unique_id "apPkbUmtdPfUFP1akVFbyQAABDY"]
[Sun Aug 30 03:06:05.090606 2026] [security2:error] [pid 495314:tid 495502] [client 158.23.147.79:62569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/bk/index.php"] [unique_id "apPkbUmtdPfUFP1akVFbzAAABGI"]
[Sun Aug 30 03:06:05.094904 2026] [security2:error] [pid 495314:tid 495544] [client 20.220.204.93:64151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/35.php"] [unique_id "apPkbUmtdPfUFP1akVFbzQAABIw"]
[Sun Aug 30 03:06:05.105533 2026] [authz_core:error] [pid 495314:tid 495518] [client 216.73.216.128:23351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:05.105818 2026] [authz_core:error] [pid 495314:tid 495518] [client 216.73.216.128:23351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:05.106234 2026] [security2:error] [pid 495314:tid 495554] [client 158.23.147.79:54229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-content/languages/about.php"] [unique_id "apPkbUmtdPfUFP1akVFb0gAABJY"]
[Sun Aug 30 03:06:05.136431 2026] [security2:error] [pid 495314:tid 495480] [client 20.104.18.15:43314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/blacks.php"] [unique_id "apPkbUmtdPfUFP1akVFb5QAABEw"]
[Sun Aug 30 03:06:05.190425 2026] [security2:error] [pid 495314:tid 495519] [client 216.73.216.128:49464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/',b,'"] [unique_id "apPkbUmtdPfUFP1akVFcCQAABHM"]
[Sun Aug 30 03:06:05.200416 2026] [security2:error] [pid 496962:tid 497137] [client 20.104.104.62:22113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/ca.php"] [unique_id "apPkbY6aRhSu8gis9LlxPwAABNo"]
[Sun Aug 30 03:06:05.215056 2026] [security2:error] [pid 495314:tid 495562] [client 158.23.147.79:54225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-content/banners/about.php"] [unique_id "apPkbUmtdPfUFP1akVFcFgAABJ4"]
[Sun Aug 30 03:06:05.216599 2026] [security2:error] [pid 496962:tid 497101] [client 40.83.93.50:9317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/b.php"] [unique_id "apPkbY6aRhSu8gis9LlxQQAABLY"]
[Sun Aug 30 03:06:05.222050 2026] [security2:error] [pid 495314:tid 495553] [client 158.23.147.79:42053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPkbUmtdPfUFP1akVFcHAAABJU"]
[Sun Aug 30 03:06:05.239580 2026] [security2:error] [pid 495314:tid 495453] [client 20.220.204.93:62308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/maraz.php"] [unique_id "apPkbUmtdPfUFP1akVFcLQAABDE"]
[Sun Aug 30 03:06:05.258330 2026] [security2:error] [pid 496962:tid 497155] [client 20.151.200.44:47419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/txets.php"] [unique_id "apPkbY6aRhSu8gis9LlxRAAABOw"]
[Sun Aug 30 03:06:05.276131 2026] [security2:error] [pid 495314:tid 495477] [client 158.23.147.79:62581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/cong.php"] [unique_id "apPkbUmtdPfUFP1akVFcRgAABEk"]
[Sun Aug 30 03:06:05.295266 2026] [security2:error] [pid 496962:tid 497169] [client 20.48.251.3:64269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/bb.php"] [unique_id "apPkbY6aRhSu8gis9LlxSwAABPo"]
[Sun Aug 30 03:06:05.300189 2026] [security2:error] [pid 496962:tid 497156] [client 158.23.147.79:63880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-content/x.php"] [unique_id "apPkbY6aRhSu8gis9LlxUAAABO0"]
[Sun Aug 30 03:06:05.311068 2026] [security2:error] [pid 495314:tid 495543] [client 158.23.147.79:53509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-includes/Text/about.php"] [unique_id "apPkbUmtdPfUFP1akVFcWwAABIs"]
[Sun Aug 30 03:06:05.315851 2026] [authz_core:error] [pid 495314:tid 495557] [client 66.249.66.73:63300] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:05.316184 2026] [authz_core:error] [pid 495314:tid 495557] [client 66.249.66.73:63300] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:05.316787 2026] [security2:error] [pid 495314:tid 495492] [client 68.155.159.216:62297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apPkbUmtdPfUFP1akVFcYgAABFg"]
[Sun Aug 30 03:06:05.320688 2026] [security2:error] [pid 495314:tid 495508] [client 158.23.147.79:53262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/goat.php"] [unique_id "apPkbUmtdPfUFP1akVFcZgAABGg"]
[Sun Aug 30 03:06:05.327725 2026] [security2:error] [pid 495314:tid 495499] [client 20.104.50.220:42796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/coli.php"] [unique_id "apPkbUmtdPfUFP1akVFcbQAABF8"]
[Sun Aug 30 03:06:05.328905 2026] [security2:error] [pid 495314:tid 495457] [client 68.155.159.216:65515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/dropdown.php"] [unique_id "apPkbUmtdPfUFP1akVFccAAABDU"]
[Sun Aug 30 03:06:05.336902 2026] [authz_core:error] [pid 495314:tid 495459] [client 216.73.216.128:37637] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:05.337393 2026] [authz_core:error] [pid 495314:tid 495459] [client 216.73.216.128:37637] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:05.361127 2026] [security2:error] [pid 495314:tid 495550] [client 20.104.104.62:22091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/pb.php"] [unique_id "apPkbUmtdPfUFP1akVFcjgAABJI"]
[Sun Aug 30 03:06:05.362309 2026] [security2:error] [pid 495314:tid 495548] [client 20.104.50.220:27454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/images/mail.php"] [unique_id "apPkbUmtdPfUFP1akVFcjwAABJA"]
[Sun Aug 30 03:06:05.380437 2026] [authz_core:error] [pid 495314:tid 495553] [client 216.73.216.128:23351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:05.380808 2026] [authz_core:error] [pid 495314:tid 495553] [client 216.73.216.128:23351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:05.407318 2026] [security2:error] [pid 495314:tid 495457] [client 158.23.147.79:54232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/asd.php"] [unique_id "apPkbUmtdPfUFP1akVFcqwAABDU"]
[Sun Aug 30 03:06:05.412525 2026] [security2:error] [pid 495314:tid 495555] [client 158.23.147.79:52963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hwsoffice.basichoa.com"] [uri "/first.php"] [unique_id "apPkbUmtdPfUFP1akVFcsQAABJc"]
[Sun Aug 30 03:06:05.427856 2026] [security2:error] [pid 496962:tid 497142] [client 158.23.147.79:53308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apPkbY6aRhSu8gis9LlxZQAABN8"]
[Sun Aug 30 03:06:05.443158 2026] [security2:error] [pid 495314:tid 495564] [client 20.220.204.93:64142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/kbfr.php"] [unique_id "apPkbUmtdPfUFP1akVFcwQAABKA"]
[Sun Aug 30 03:06:05.449540 2026] [security2:error] [pid 496962:tid 497130] [client 20.151.200.44:47314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/wp-login.php"] [unique_id "apPkbY6aRhSu8gis9LlxZgAABNM"]
[Sun Aug 30 03:06:05.464696 2026] [security2:error] [pid 495314:tid 495524] [client 20.104.50.220:46413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/gank.php.PhP"] [unique_id "apPkbUmtdPfUFP1akVFczQAABHg"]
[Sun Aug 30 03:06:05.468404 2026] [security2:error] [pid 495314:tid 495542] [client 4.205.62.107:65400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/pouhg.php"] [unique_id "apPkbUmtdPfUFP1akVFc0AAABIo"]
[Sun Aug 30 03:06:05.478234 2026] [security2:error] [pid 496962:tid 497202] [client 4.205.62.107:63602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/packed.php"] [unique_id "apPkbY6aRhSu8gis9LlxaQAABRs"]
[Sun Aug 30 03:06:05.506347 2026] [security2:error] [pid 496962:tid 497214] [client 158.23.147.79:53518] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.sculpturealley.net"] [uri "/1.php"] [unique_id "apPkbY6aRhSu8gis9LlxdwAABSc"]
[Sun Aug 30 03:06:05.506442 2026] [security2:error] [pid 496962:tid 497214] [client 158.23.147.79:53518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/1.php"] [unique_id "apPkbY6aRhSu8gis9LlxdwAABSc"]
[Sun Aug 30 03:06:05.517742 2026] [security2:error] [pid 496962:tid 497190] [client 20.104.104.62:22081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/pk.php"] [unique_id "apPkbY6aRhSu8gis9LlxegAABQ8"]
[Sun Aug 30 03:06:05.523005 2026] [security2:error] [pid 496962:tid 497101] [client 20.104.50.220:61967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/gator.php"] [unique_id "apPkbY6aRhSu8gis9LlxfgAABLY"]
[Sun Aug 30 03:06:05.551572 2026] [security2:error] [pid 495314:tid 495545] [client 158.23.147.79:42074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-content/uploads/about.php"] [unique_id "apPkbUmtdPfUFP1akVFc-AAABI0"]
[Sun Aug 30 03:06:05.575598 2026] [security2:error] [pid 495314:tid 495459] [client 20.220.204.93:64232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/wp-act.php"] [unique_id "apPkbUmtdPfUFP1akVFdAQAABDc"]
[Sun Aug 30 03:06:05.592664 2026] [security2:error] [pid 496962:tid 497183] [client 158.23.147.79:63905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPkbY6aRhSu8gis9LlxiAAABQg"]
[Sun Aug 30 03:06:05.592863 2026] [security2:error] [pid 495314:tid 495477] [client 20.151.200.44:55690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/4e.php"] [unique_id "apPkbUmtdPfUFP1akVFdDQAABEk"]
[Sun Aug 30 03:06:05.598948 2026] [authz_core:error] [pid 495314:tid 495456] [client 66.249.66.71:42195] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:05.599212 2026] [authz_core:error] [pid 495314:tid 495456] [client 66.249.66.71:42195] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:05.602513 2026] [security2:error] [pid 496962:tid 497175] [client 158.23.147.79:53504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/ws.php"] [unique_id "apPkbY6aRhSu8gis9LlxkAAABQA"]
[Sun Aug 30 03:06:05.647157 2026] [security2:error] [pid 495314:tid 495507] [client 20.104.50.220:31832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/73.php"] [unique_id "apPkbUmtdPfUFP1akVFdIAAABGc"]
[Sun Aug 30 03:06:05.654861 2026] [authz_core:error] [pid 495314:tid 495466] [client 216.73.216.128:23351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:05.655316 2026] [authz_core:error] [pid 495314:tid 495466] [client 216.73.216.128:23351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:05.655813 2026] [security2:error] [pid 495314:tid 495448] [client 158.23.147.79:42110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-admin/maint/index.php"] [unique_id "apPkbUmtdPfUFP1akVFdJgAABCw"]
[Sun Aug 30 03:06:05.656860 2026] [security2:error] [pid 495314:tid 495516] [client 158.23.147.79:62481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-includes/js/index.php"] [unique_id "apPkbUmtdPfUFP1akVFdJwAABHA"]
[Sun Aug 30 03:06:05.668744 2026] [security2:error] [pid 496962:tid 497096] [client 20.104.104.62:22082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/ft.php"] [unique_id "apPkbY6aRhSu8gis9LlxrwAABLE"]
[Sun Aug 30 03:06:05.669792 2026] [authz_core:error] [pid 496962:tid 497128] [client 66.249.66.71:58892] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:05.670062 2026] [authz_core:error] [pid 496962:tid 497128] [client 66.249.66.71:58892] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:05.674252 2026] [security2:error] [pid 496962:tid 497158] [client 20.48.251.3:50021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/ms.php"] [unique_id "apPkbY6aRhSu8gis9LlxsQAABO8"]
[Sun Aug 30 03:06:05.677073 2026] [security2:error] [pid 496962:tid 497191] [client 68.155.159.216:54091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/mah.php"] [unique_id "apPkbY6aRhSu8gis9LlxtwAABRA"]
[Sun Aug 30 03:06:05.678604 2026] [security2:error] [pid 496962:tid 497137] [client 20.48.251.3:44184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/cli_bootstrap.php"] [unique_id "apPkbY6aRhSu8gis9LlxuAAABNo"]
[Sun Aug 30 03:06:05.693653 2026] [security2:error] [pid 496962:tid 497143] [client 20.104.50.220:5593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/files.php"] [unique_id "apPkbY6aRhSu8gis9LlxugAABOA"]
[Sun Aug 30 03:06:05.702066 2026] [security2:error] [pid 496962:tid 497167] [client 20.48.251.3:45843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/saml.php"] [unique_id "apPkbY6aRhSu8gis9LlxvAAABPg"]
[Sun Aug 30 03:06:05.702487 2026] [security2:error] [pid 495314:tid 495495] [client 40.83.93.50:9053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/wp-login.php"] [unique_id "apPkbUmtdPfUFP1akVFdPgAABFs"]
[Sun Aug 30 03:06:05.709376 2026] [security2:error] [pid 495314:tid 495550] [client 68.155.159.216:63944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/.well-known/index.php"] [unique_id "apPkbUmtdPfUFP1akVFdQQAABJI"]
[Sun Aug 30 03:06:05.718905 2026] [security2:error] [pid 495314:tid 495559] [client 4.205.62.107:4149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/oc460l3x.php"] [unique_id "apPkbUmtdPfUFP1akVFdSQAABJs"]
[Sun Aug 30 03:06:05.728772 2026] [security2:error] [pid 496962:tid 497169] [client 4.205.62.107:2142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/public/rip.php.php"] [unique_id "apPkbY6aRhSu8gis9LlxwAAABPo"]
[Sun Aug 30 03:06:05.754903 2026] [security2:error] [pid 495314:tid 495556] [client 158.23.147.79:4057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/dropdown.php"] [unique_id "apPkbUmtdPfUFP1akVFdWwAABJg"]
[Sun Aug 30 03:06:05.758695 2026] [security2:error] [pid 496962:tid 497207] [client 158.23.147.79:63887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/log-mama/function.php"] [unique_id "apPkbY6aRhSu8gis9LlxwgAABSA"]
[Sun Aug 30 03:06:05.758848 2026] [security2:error] [pid 496962:tid 497156] [client 4.205.62.107:56615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/wp-access.php"] [unique_id "apPkbY6aRhSu8gis9LlxwwAABO0"]
[Sun Aug 30 03:06:05.764956 2026] [security2:error] [pid 496962:tid 497170] [client 20.220.204.93:64207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/24.php"] [unique_id "apPkbY6aRhSu8gis9LlxxgAABPs"]
[Sun Aug 30 03:06:05.787619 2026] [access_compat:error] [pid 495314:tid 495452] [client 164.92.244.132:0] AH01797: client denied by server configuration: /home3/fremant1/public_html/website_b3f91c55/server-status
[Sun Aug 30 03:06:05.815488 2026] [security2:error] [pid 496962:tid 497171] [client 20.104.104.62:21711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/wp-ver.php"] [unique_id "apPkbY6aRhSu8gis9Llx2QAABPw"]
[Sun Aug 30 03:06:05.845569 2026] [security2:error] [pid 495314:tid 495558] [client 4.205.62.107:58315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/cli_bootstrap.php"] [unique_id "apPkbUmtdPfUFP1akVFdfQAABJo"]
[Sun Aug 30 03:06:05.849346 2026] [security2:error] [pid 496962:tid 497097] [client 158.23.147.79:4008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/sad/about.php"] [unique_id "apPkbY6aRhSu8gis9Llx6AAABLI"]
[Sun Aug 30 03:06:05.859243 2026] [security2:error] [pid 496962:tid 497094] [client 20.104.50.220:62818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/pdi.php"] [unique_id "apPkbY6aRhSu8gis9Llx8AAABK8"]
[Sun Aug 30 03:06:05.873351 2026] [security2:error] [pid 496962:tid 497186] [client 158.23.147.79:63923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/bk/index.php"] [unique_id "apPkbY6aRhSu8gis9Llx-QAABQs"]
[Sun Aug 30 03:06:05.880062 2026] [security2:error] [pid 496962:tid 497219] [client 158.23.147.79:53526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-includes/css/index.php"] [unique_id "apPkbY6aRhSu8gis9Llx-wAABSw"]
[Sun Aug 30 03:06:05.916608 2026] [security2:error] [pid 496962:tid 497104] [client 20.220.204.93:64225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/155.php"] [unique_id "apPkbY6aRhSu8gis9LlyCAAABLk"]
[Sun Aug 30 03:06:05.957154 2026] [security2:error] [pid 496962:tid 497199] [client 4.205.62.107:62431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/ty.php"] [unique_id "apPkbY6aRhSu8gis9LlyEwAABRg"]
[Sun Aug 30 03:06:05.960973 2026] [security2:error] [pid 496962:tid 497148] [client 20.48.251.3:55763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/txets.php"] [unique_id "apPkbY6aRhSu8gis9LlyFAAABOU"]
[Sun Aug 30 03:06:05.962546 2026] [security2:error] [pid 496962:tid 497196] [client 158.23.147.79:53263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/admin.php"] [unique_id "apPkbY6aRhSu8gis9LlyFQAABRU"]
[Sun Aug 30 03:06:05.975766 2026] [authz_core:error] [pid 495314:tid 495499] [client 66.249.66.74:64771] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:05.976264 2026] [authz_core:error] [pid 495314:tid 495499] [client 66.249.66.74:64771] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:05.996230 2026] [security2:error] [pid 496962:tid 497094] [client 20.104.104.62:22095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/ah24.php"] [unique_id "apPkbY6aRhSu8gis9LlyJQAABK8"]
[Sun Aug 30 03:06:05.997490 2026] [security2:error] [pid 496962:tid 497099] [client 158.23.147.79:62219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sustainabletourismgoals.com"] [uri "/first.php"] [unique_id "apPkbY6aRhSu8gis9LlyJgAABLQ"]
[Sun Aug 30 03:06:06.049885 2026] [security2:error] [pid 496962:tid 497115] [client 4.205.62.107:18633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/atex1.php"] [unique_id "apPkbo6aRhSu8gis9LlyRgAABMQ"]
[Sun Aug 30 03:06:06.067753 2026] [security2:error] [pid 495314:tid 495535] [client 158.23.147.79:44237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/cgi-bin/wp-login.php"] [unique_id "apPkbkmtdPfUFP1akVFdxwAABIM"]
[Sun Aug 30 03:06:06.092813 2026] [security2:error] [pid 496962:tid 497097] [client 68.155.159.216:56416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apPkbo6aRhSu8gis9LlyWQAABLI"]
[Sun Aug 30 03:06:06.097436 2026] [security2:error] [pid 495314:tid 495555] [client 4.205.62.107:64030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/tinyfilemanager.php"] [unique_id "apPkbkmtdPfUFP1akVFd0AAABJc"]
[Sun Aug 30 03:06:06.109161 2026] [security2:error] [pid 496962:tid 497122] [client 158.23.147.79:4012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-admin/admin.php"] [unique_id "apPkbo6aRhSu8gis9LlyWwAABMs"]
[Sun Aug 30 03:06:06.112069 2026] [security2:error] [pid 495314:tid 495449] [client 4.205.62.107:42681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.avenuelesrogim.com"] [uri "/wp-act.php"] [unique_id "apPkbkmtdPfUFP1akVFd1AAABC0"]
[Sun Aug 30 03:06:06.121458 2026] [security2:error] [pid 495314:tid 495519] [client 68.155.159.216:52638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apPkbkmtdPfUFP1akVFd3QAABHM"]
[Sun Aug 30 03:06:06.122510 2026] [security2:error] [pid 496962:tid 497203] [client 20.48.251.3:44328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/maxro.php"] [unique_id "apPkbo6aRhSu8gis9LlyXQAABRw"]
[Sun Aug 30 03:06:06.139099 2026] [security2:error] [pid 496962:tid 497119] [client 20.104.104.62:21724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/wp-admin/zwso.php"] [unique_id "apPkbo6aRhSu8gis9LlyZgAABMg"]
[Sun Aug 30 03:06:06.151511 2026] [security2:error] [pid 496962:tid 497207] [client 20.104.50.220:33071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/con7.php"] [unique_id "apPkbo6aRhSu8gis9LlyZwAABSA"]
[Sun Aug 30 03:06:06.171600 2026] [security2:error] [pid 496962:tid 497205] [client 20.104.18.15:13669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/fpwch.php"] [unique_id "apPkbo6aRhSu8gis9LlybAAABR4"]
[Sun Aug 30 03:06:06.180688 2026] [security2:error] [pid 496962:tid 497211] [client 20.104.50.220:28676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/turkiye.php"] [unique_id "apPkbo6aRhSu8gis9LlybQAABSQ"]
[Sun Aug 30 03:06:06.233701 2026] [security2:error] [pid 496962:tid 497118] [client 40.83.93.50:12073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/aa.php"] [unique_id "apPkbo6aRhSu8gis9LlydwAABMc"]
[Sun Aug 30 03:06:06.236420 2026] [security2:error] [pid 496962:tid 497112] [client 158.23.147.79:42068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-includes/IXR/index.php"] [unique_id "apPkbo6aRhSu8gis9LlyegAABME"]
[Sun Aug 30 03:06:06.249213 2026] [security2:error] [pid 495314:tid 495500] [client 20.220.204.93:62231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/file.php"] [unique_id "apPkbkmtdPfUFP1akVFeMAAABGA"]
[Sun Aug 30 03:06:06.253959 2026] [security2:error] [pid 496962:tid 497139] [client 20.104.18.15:33014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/ws55.php"] [unique_id "apPkbo6aRhSu8gis9LlyfAAABNw"]
[Sun Aug 30 03:06:06.258708 2026] [security2:error] [pid 496962:tid 497184] [client 158.23.147.79:53523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-content/cong.php"] [unique_id "apPkbo6aRhSu8gis9LlyfgAABQk"]
[Sun Aug 30 03:06:06.290199 2026] [security2:error] [pid 496962:tid 497163] [client 158.23.147.79:62575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-content/index.php"] [unique_id "apPkbo6aRhSu8gis9LlykQAABPQ"]
[Sun Aug 30 03:06:06.303206 2026] [security2:error] [pid 495314:tid 495456] [client 216.73.216.128:37637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPkbkmtdPfUFP1akVFeSQAABDQ"]
[Sun Aug 30 03:06:06.319997 2026] [security2:error] [pid 496962:tid 497168] [client 20.104.18.15:43992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/beck.php"] [unique_id "apPkbo6aRhSu8gis9LlymQAABPk"]
[Sun Aug 30 03:06:06.348141 2026] [security2:error] [pid 496962:tid 497209] [client 20.104.104.62:21741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cairotech.net"] [uri "/waf.php"] [unique_id "apPkbo6aRhSu8gis9LlypgAABSI"]
[Sun Aug 30 03:06:06.365582 2026] [security2:error] [pid 496962:tid 497178] [client 4.205.62.107:32037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/dd.php"] [unique_id "apPkbo6aRhSu8gis9LlyrQAABQM"]
[Sun Aug 30 03:06:06.375025 2026] [security2:error] [pid 496962:tid 497113] [client 158.23.147.79:53560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPkbo6aRhSu8gis9LlysgAABMI"]
[Sun Aug 30 03:06:06.383053 2026] [security2:error] [pid 496962:tid 497212] [client 4.205.62.107:26776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/fns.php"] [unique_id "apPkbo6aRhSu8gis9LlytgAABSU"]
[Sun Aug 30 03:06:06.385684 2026] [security2:error] [pid 496962:tid 497110] [client 20.220.204.93:61784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPkbo6aRhSu8gis9LlytwAABL8"]
[Sun Aug 30 03:06:06.386954 2026] [security2:error] [pid 496962:tid 497200] [client 20.104.49.130:60671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkbo6aRhSu8gis9LlyuQAABRk"]
[Sun Aug 30 03:06:06.404437 2026] [security2:error] [pid 495314:tid 495458] [client 158.23.147.79:42104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/classwithtostring.php"] [unique_id "apPkbkmtdPfUFP1akVFedgAABDY"]
[Sun Aug 30 03:06:06.413368 2026] [authz_core:error] [pid 495314:tid 495487] [client 66.249.66.197:40192] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:06.413627 2026] [authz_core:error] [pid 495314:tid 495487] [client 66.249.66.197:40192] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:06.419245 2026] [security2:error] [pid 496962:tid 497215] [client 20.151.200.44:47296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/wp-access.php"] [unique_id "apPkbo6aRhSu8gis9LlyyAAABSg"]
[Sun Aug 30 03:06:06.432533 2026] [security2:error] [pid 496962:tid 497202] [client 20.151.200.44:62932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/im.php"] [unique_id "apPkbo6aRhSu8gis9LlyzgAABRs"]
[Sun Aug 30 03:06:06.436080 2026] [security2:error] [pid 496962:tid 497130] [client 68.155.159.216:65519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/.well-known/index.php"] [unique_id "apPkbo6aRhSu8gis9LlyzwAABNM"]
[Sun Aug 30 03:06:06.462759 2026] [security2:error] [pid 495314:tid 495499] [client 20.104.50.220:51609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/cylul.php"] [unique_id "apPkbkmtdPfUFP1akVFeiAAABF8"]
[Sun Aug 30 03:06:06.500116 2026] [security2:error] [pid 496962:tid 497164] [client 20.104.50.220:27424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/themes/Divi/page.php"] [unique_id "apPkbo6aRhSu8gis9Lly7AAABPU"]
[Sun Aug 30 03:06:06.511240 2026] [security2:error] [pid 495314:tid 495538] [client 158.23.147.79:54215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPkbkmtdPfUFP1akVFeoQAABIY"]
[Sun Aug 30 03:06:06.520383 2026] [security2:error] [pid 495314:tid 495510] [client 158.23.147.79:4078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/install.php"] [unique_id "apPkbkmtdPfUFP1akVFerQAABGo"]
[Sun Aug 30 03:06:06.600364 2026] [security2:error] [pid 496962:tid 497134] [client 20.104.50.220:46598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/gh.php"] [unique_id "apPkbo6aRhSu8gis9Lly_gAABNc"]
[Sun Aug 30 03:06:06.615005 2026] [security2:error] [pid 496962:tid 497138] [client 4.205.62.107:63780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/wp-info.php"] [unique_id "apPkbo6aRhSu8gis9LlzBQAABNs"]
[Sun Aug 30 03:06:06.633797 2026] [authz_core:error] [pid 495314:tid 495529] [client 66.249.66.35:55848] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:06.634262 2026] [authz_core:error] [pid 495314:tid 495529] [client 66.249.66.35:55848] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:06.640596 2026] [security2:error] [pid 496962:tid 497151] [client 20.151.200.44:64617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkbo6aRhSu8gis9LlzDgAABOg"]
[Sun Aug 30 03:06:06.643448 2026] [security2:error] [pid 496962:tid 497120] [client 4.205.62.107:65294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/phpversion.php"] [unique_id "apPkbo6aRhSu8gis9LlzDwAABMk"]
[Sun Aug 30 03:06:06.645821 2026] [security2:error] [pid 496962:tid 497133] [client 158.23.147.79:54255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-includes/Requests/network.php"] [unique_id "apPkbo6aRhSu8gis9LlzEgAABNY"]
[Sun Aug 30 03:06:06.681630 2026] [security2:error] [pid 496962:tid 497107] [client 20.220.204.93:64253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/06.php"] [unique_id "apPkbo6aRhSu8gis9LlzIQAABLw"]
[Sun Aug 30 03:06:06.692917 2026] [security2:error] [pid 495314:tid 495452] [client 158.23.147.79:42085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-content/x/index.php"] [unique_id "apPkbkmtdPfUFP1akVFe8gAABDA"]
[Sun Aug 30 03:06:06.700669 2026] [security2:error] [pid 495314:tid 495480] [client 68.155.159.216:62301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apPkbkmtdPfUFP1akVFe-AAABEw"]
[Sun Aug 30 03:06:06.746219 2026] [security2:error] [pid 495314:tid 495517] [client 40.83.93.50:9302] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webmail.swmpainters.com"] [uri "/c99.php"] [unique_id "apPkbkmtdPfUFP1akVFfCAAABHE"]
[Sun Aug 30 03:06:06.747466 2026] [security2:error] [pid 495314:tid 495535] [client 158.23.147.79:54270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-content/radio.php"] [unique_id "apPkbkmtdPfUFP1akVFfCQAABIM"]
[Sun Aug 30 03:06:06.754843 2026] [security2:error] [pid 496962:tid 497210] [client 4.205.62.107:36643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/doc.php"] [unique_id "apPkbo6aRhSu8gis9LlzOAAABSM"]
[Sun Aug 30 03:06:06.782743 2026] [security2:error] [pid 495314:tid 495468] [client 20.104.50.220:31871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/al.php"] [unique_id "apPkbkmtdPfUFP1akVFfGAAABEA"]
[Sun Aug 30 03:06:06.785933 2026] [security2:error] [pid 496962:tid 497186] [client 68.155.159.216:59991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-blog-header.php"] [unique_id "apPkbo6aRhSu8gis9LlzPAAABQs"]
[Sun Aug 30 03:06:06.817046 2026] [security2:error] [pid 496962:tid 497161] [client 20.48.251.3:49978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/fucku.php"] [unique_id "apPkbo6aRhSu8gis9LlzRAAABPI"]
[Sun Aug 30 03:06:06.825289 2026] [security2:error] [pid 496962:tid 497110] [client 20.104.50.220:5603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/file7.php"] [unique_id "apPkbo6aRhSu8gis9LlzSQAABL8"]
[Sun Aug 30 03:06:06.832396 2026] [security2:error] [pid 496962:tid 497154] [client 158.23.147.79:42102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-includes/Requests/about.php"] [unique_id "apPkbo6aRhSu8gis9LlzUAAABOs"]
[Sun Aug 30 03:06:06.836283 2026] [security2:error] [pid 496962:tid 497174] [client 20.48.251.3:46153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/file59.php"] [unique_id "apPkbo6aRhSu8gis9LlzVAAABP8"]
[Sun Aug 30 03:06:06.840376 2026] [security2:error] [pid 496962:tid 497144] [client 20.48.251.3:7382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/aws_settings.php"] [unique_id "apPkbo6aRhSu8gis9LlzWgAABOE"]
[Sun Aug 30 03:06:06.849127 2026] [security2:error] [pid 496962:tid 497170] [client 20.151.200.44:64586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkbo6aRhSu8gis9LlzYQAABPs"]
[Sun Aug 30 03:06:06.856674 2026] [security2:error] [pid 496962:tid 497177] [client 4.205.62.107:4547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/drykl.php"] [unique_id "apPkbo6aRhSu8gis9LlzZQAABQI"]
[Sun Aug 30 03:06:06.857672 2026] [security2:error] [pid 496962:tid 497171] [client 68.155.159.216:61336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-content/themes/too.php"] [unique_id "apPkbo6aRhSu8gis9LlzZwAABPw"]
[Sun Aug 30 03:06:06.866617 2026] [security2:error] [pid 496962:tid 497168] [client 4.205.62.107:2955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/environment.php"] [unique_id "apPkbo6aRhSu8gis9LlzbgAABPk"]
[Sun Aug 30 03:06:06.896361 2026] [security2:error] [pid 495314:tid 495461] [client 20.48.251.3:23474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/dd.php"] [unique_id "apPkbkmtdPfUFP1akVFfRAAABDk"]
[Sun Aug 30 03:06:06.903468 2026] [security2:error] [pid 496962:tid 497219] [client 4.205.62.107:56631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/otuz1.php"] [unique_id "apPkbo6aRhSu8gis9LlzeAAABSw"]
[Sun Aug 30 03:06:06.953812 2026] [security2:error] [pid 495314:tid 495509] [client 158.23.147.79:53277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-admin/includes/index.php"] [unique_id "apPkbkmtdPfUFP1akVFfXQAABGk"]
[Sun Aug 30 03:06:07.002881 2026] [security2:error] [pid 495314:tid 495513] [client 20.220.204.93:62307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/class.php"] [unique_id "apPkb0mtdPfUFP1akVFfdwAABG0"]
[Sun Aug 30 03:06:07.027905 2026] [security2:error] [pid 496962:tid 497192] [client 20.104.50.220:29159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/rayzky.php"] [unique_id "apPkb46aRhSu8gis9LlzsAAABRE"]
[Sun Aug 30 03:06:07.040590 2026] [security2:error] [pid 496962:tid 497154] [client 216.73.216.128:63631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts2/updateconf"] [unique_id "apPkb46aRhSu8gis9LlztgAABOs"]
[Sun Aug 30 03:06:07.050578 2026] [security2:error] [pid 495314:tid 495559] [client 158.23.147.79:53556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-admin/dropdown.php"] [unique_id "apPkb0mtdPfUFP1akVFflgAABJs"]
[Sun Aug 30 03:06:07.070163 2026] [security2:error] [pid 495314:tid 495524] [client 158.23.147.79:42066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-login.php"] [unique_id "apPkb0mtdPfUFP1akVFfnwAABHg"]
[Sun Aug 30 03:06:07.074972 2026] [security2:error] [pid 496962:tid 497139] [client 20.151.200.44:65226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/h02ugyh.php"] [unique_id "apPkb46aRhSu8gis9LlzwQAABNw"]
[Sun Aug 30 03:06:07.101504 2026] [security2:error] [pid 495314:tid 495477] [client 4.205.62.107:22558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/adminer-4.7.6-en.php"] [unique_id "apPkb0mtdPfUFP1akVFfsAAABEk"]
[Sun Aug 30 03:06:07.103220 2026] [authz_core:error] [pid 496962:tid 497121] [client 66.249.66.37:48214] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:07.103681 2026] [authz_core:error] [pid 496962:tid 497121] [client 66.249.66.37:48214] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:07.107626 2026] [security2:error] [pid 495314:tid 495476] [client 20.48.251.3:55688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/time.php"] [unique_id "apPkb0mtdPfUFP1akVFfsgAABEg"]
[Sun Aug 30 03:06:07.126395 2026] [security2:error] [pid 495314:tid 495531] [client 158.23.147.79:62503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/about/function.php"] [unique_id "apPkb0mtdPfUFP1akVFfvQAABH8"]
[Sun Aug 30 03:06:07.137342 2026] [security2:error] [pid 496962:tid 497199] [client 20.104.50.220:61976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/mail.php"] [unique_id "apPkb46aRhSu8gis9LlzxwAABRg"]
[Sun Aug 30 03:06:07.169682 2026] [security2:error] [pid 495314:tid 495530] [client 158.23.147.79:42070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apPkb0mtdPfUFP1akVFf2AAABH4"]
[Sun Aug 30 03:06:07.178618 2026] [security2:error] [pid 495314:tid 495482] [client 20.220.204.93:61761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/8.php"] [unique_id "apPkb0mtdPfUFP1akVFf4AAABE4"]
[Sun Aug 30 03:06:07.180147 2026] [security2:error] [pid 495314:tid 495499] [client 20.151.200.44:55721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/ssss.php"] [unique_id "apPkb0mtdPfUFP1akVFf4gAABF8"]
[Sun Aug 30 03:06:07.186028 2026] [security2:error] [pid 495314:tid 495467] [client 4.205.62.107:18956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/aws_sdk_settings.php"] [unique_id "apPkb0mtdPfUFP1akVFf6AAABD8"]
[Sun Aug 30 03:06:07.195029 2026] [security2:error] [pid 496962:tid 497126] [client 68.155.159.216:56437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apPkb46aRhSu8gis9Llz0wAABM8"]
[Sun Aug 30 03:06:07.224056 2026] [authz_core:error] [pid 495314:tid 495459] [client 66.249.66.68:44835] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:07.224330 2026] [authz_core:error] [pid 495314:tid 495459] [client 66.249.66.68:44835] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:07.244359 2026] [security2:error] [pid 495314:tid 495556] [client 40.83.93.50:8707] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webmail.swmpainters.com"] [uri "/c99.php"] [unique_id "apPkb0mtdPfUFP1akVFgGgAABJg"]
[Sun Aug 30 03:06:07.252119 2026] [security2:error] [pid 496962:tid 497186] [client 4.205.62.107:62125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/05.php"] [unique_id "apPkb46aRhSu8gis9Llz5AAABQs"]
[Sun Aug 30 03:06:07.263926 2026] [security2:error] [pid 496962:tid 497214] [client 158.23.147.79:54213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/login.php"] [unique_id "apPkb46aRhSu8gis9Llz7QAABSc"]
[Sun Aug 30 03:06:07.271576 2026] [security2:error] [pid 496962:tid 497116] [client 158.23.147.79:4036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-admin/images/about.php"] [unique_id "apPkb46aRhSu8gis9Llz9AAABMU"]
[Sun Aug 30 03:06:07.275107 2026] [security2:error] [pid 496962:tid 497164] [client 68.155.159.216:52685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apPkb46aRhSu8gis9Llz9wAABPU"]
[Sun Aug 30 03:06:07.288922 2026] [security2:error] [pid 495314:tid 495521] [client 20.104.50.220:33330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/locale.php"] [unique_id "apPkb0mtdPfUFP1akVFgNAAABHU"]
[Sun Aug 30 03:06:07.291343 2026] [security2:error] [pid 495314:tid 495538] [client 20.48.251.3:4700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/brc.php"] [unique_id "apPkb0mtdPfUFP1akVFgOAAABIY"]
[Sun Aug 30 03:06:07.293395 2026] [security2:error] [pid 495314:tid 495487] [client 20.151.200.44:63556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/file.php"] [unique_id "apPkb0mtdPfUFP1akVFgOQAABFM"]
[Sun Aug 30 03:06:07.316032 2026] [security2:error] [pid 495314:tid 495476] [client 216.73.216.128:23351] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPkb0mtdPfUFP1akVFgQgAABEg"]
[Sun Aug 30 03:06:07.326197 2026] [security2:error] [pid 496962:tid 497113] [client 20.104.50.220:62796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/max.php"] [unique_id "apPkb46aRhSu8gis9Ll0BQAABMI"]
[Sun Aug 30 03:06:07.339594 2026] [security2:error] [pid 496962:tid 497209] [client 20.104.18.15:13717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/domvf.php"] [unique_id "apPkb46aRhSu8gis9Ll0CwAABSI"]
[Sun Aug 30 03:06:07.347798 2026] [security2:error] [pid 496962:tid 497213] [client 20.220.204.93:64180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/0x0x.php"] [unique_id "apPkb46aRhSu8gis9Ll0FAAABSY"]
[Sun Aug 30 03:06:07.375071 2026] [security2:error] [pid 496962:tid 497132] [client 158.23.147.79:53269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPkb46aRhSu8gis9Ll0JAAABNU"]
[Sun Aug 30 03:06:07.399949 2026] [security2:error] [pid 495314:tid 495555] [client 20.104.18.15:33754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/drykl.php"] [unique_id "apPkb0mtdPfUFP1akVFgcwAABJc"]
[Sun Aug 30 03:06:07.413535 2026] [authz_core:error] [pid 495314:tid 495468] [client 216.73.216.128:23351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:07.413800 2026] [authz_core:error] [pid 495314:tid 495468] [client 216.73.216.128:23351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:07.414905 2026] [authz_core:error] [pid 496962:tid 497174] [client 66.249.66.202:54272] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:07.415348 2026] [authz_core:error] [pid 496962:tid 497174] [client 66.249.66.202:54272] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:07.472395 2026] [security2:error] [pid 495314:tid 495541] [client 20.104.18.15:43284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/t3.php"] [unique_id "apPkb0mtdPfUFP1akVFgoAAABIk"]
[Sun Aug 30 03:06:07.482409 2026] [security2:error] [pid 495314:tid 495519] [client 4.205.62.107:58322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/wp-tem.php"] [unique_id "apPkb0mtdPfUFP1akVFgpQAABHM"]
[Sun Aug 30 03:06:07.513150 2026] [security2:error] [pid 495314:tid 495545] [client 20.220.204.93:62317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/166.php"] [unique_id "apPkb0mtdPfUFP1akVFguAAABI0"]
[Sun Aug 30 03:06:07.544731 2026] [security2:error] [pid 496962:tid 497110] [client 158.23.147.79:53272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-admin.php"] [unique_id "apPkb46aRhSu8gis9Ll0XQAABL8"]
[Sun Aug 30 03:06:07.602683 2026] [security2:error] [pid 496962:tid 497108] [client 20.104.50.220:42772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/Cylul007.php"] [unique_id "apPkb46aRhSu8gis9Ll0dgAABL0"]
[Sun Aug 30 03:06:07.637009 2026] [security2:error] [pid 496962:tid 497194] [client 20.104.50.220:27442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/class-wp-hook.php"] [unique_id "apPkb46aRhSu8gis9Ll0jAAABRM"]
[Sun Aug 30 03:06:07.643289 2026] [security2:error] [pid 496962:tid 497134] [client 20.220.204.93:64145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/h2a2ck.php"] [unique_id "apPkb46aRhSu8gis9Ll0jwAABNc"]
[Sun Aug 30 03:06:07.658617 2026] [security2:error] [pid 496962:tid 497205] [client 68.155.159.216:12303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-content/themes/too.php"] [unique_id "apPkb46aRhSu8gis9Ll0lAAABR4"]
[Sun Aug 30 03:06:07.682378 2026] [security2:error] [pid 495314:tid 495506] [client 158.23.147.79:54233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/hehehehe.php"] [unique_id "apPkb0mtdPfUFP1akVFg7QAABGY"]
[Sun Aug 30 03:06:07.707542 2026] [authz_core:error] [pid 495314:tid 495539] [client 66.249.66.197:40192] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:07.707837 2026] [authz_core:error] [pid 495314:tid 495539] [client 66.249.66.197:40192] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:07.734804 2026] [security2:error] [pid 495314:tid 495447] [client 158.23.147.79:53272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-includes/assets/index.php"] [unique_id "apPkb0mtdPfUFP1akVFhAAAABCs"]
[Sun Aug 30 03:06:07.739257 2026] [security2:error] [pid 495314:tid 495467] [client 40.83.93.50:12043] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webmail.swmpainters.com"] [uri "/c99.php"] [unique_id "apPkb0mtdPfUFP1akVFhAgAABD8"]
[Sun Aug 30 03:06:07.742436 2026] [security2:error] [pid 496962:tid 497189] [client 20.104.50.220:46194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/id.php"] [unique_id "apPkb46aRhSu8gis9Ll0uAAABQ4"]
[Sun Aug 30 03:06:07.742680 2026] [security2:error] [pid 496962:tid 497155] [client 4.205.62.107:58338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/ws62.php"] [unique_id "apPkb46aRhSu8gis9Ll0uQAABOw"]
[Sun Aug 30 03:06:07.742816 2026] [security2:error] [pid 496962:tid 497162] [client 4.205.62.107:63801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/fns.php"] [unique_id "apPkb46aRhSu8gis9Ll0ugAABPM"]
[Sun Aug 30 03:06:07.771465 2026] [security2:error] [pid 496962:tid 497149] [client 4.205.62.107:27298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/params.php"] [unique_id "apPkb46aRhSu8gis9Ll0yAAABOY"]
[Sun Aug 30 03:06:07.772171 2026] [security2:error] [pid 496962:tid 497133] [client 20.220.204.93:64227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/error_log.php"] [unique_id "apPkb46aRhSu8gis9Ll0ywAABNY"]
[Sun Aug 30 03:06:07.802356 2026] [security2:error] [pid 495314:tid 495452] [client 20.151.200.44:64689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/sf.php"] [unique_id "apPkb0mtdPfUFP1akVFhGAAABDA"]
[Sun Aug 30 03:06:07.802421 2026] [security2:error] [pid 495314:tid 495536] [client 20.151.200.44:24589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/wp-content/admin.php"] [unique_id "apPkb0mtdPfUFP1akVFhGQAABIQ"]
[Sun Aug 30 03:06:07.814196 2026] [security2:error] [pid 495314:tid 495457] [client 4.205.62.107:65382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/adminfus.php"] [unique_id "apPkb0mtdPfUFP1akVFhHAAABDU"]
[Sun Aug 30 03:06:07.828380 2026] [authz_core:error] [pid 496962:tid 497131] [client 216.73.216.128:9601] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:07.828662 2026] [authz_core:error] [pid 496962:tid 497131] [client 216.73.216.128:9601] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:07.840514 2026] [security2:error] [pid 496962:tid 497123] [client 158.23.147.79:54234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-includes/fonts/about.php"] [unique_id "apPkb46aRhSu8gis9Ll05gAABMw"]
[Sun Aug 30 03:06:07.846321 2026] [security2:error] [pid 496962:tid 497166] [client 158.23.147.79:42055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/lock.php"] [unique_id "apPkb46aRhSu8gis9Ll07AAABPc"]
[Sun Aug 30 03:06:07.910344 2026] [security2:error] [pid 496962:tid 497106] [client 68.155.159.216:54055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apPkb46aRhSu8gis9Ll1EQAABLs"]
[Sun Aug 30 03:06:07.922840 2026] [security2:error] [pid 496962:tid 497184] [client 20.104.50.220:32740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/alf.php"] [unique_id "apPkb46aRhSu8gis9Ll1GQAABQk"]
[Sun Aug 30 03:06:07.929204 2026] [authz_core:error] [pid 496962:tid 497116] [client 66.249.66.64:46533] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:07.929486 2026] [authz_core:error] [pid 496962:tid 497116] [client 66.249.66.64:46533] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:07.953521 2026] [security2:error] [pid 496962:tid 497097] [client 158.23.147.79:53292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/index/function.php"] [unique_id "apPkb46aRhSu8gis9Ll1JQAABLI"]
[Sun Aug 30 03:06:07.979604 2026] [security2:error] [pid 496962:tid 497143] [client 20.104.50.220:6125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/gifclass.php"] [unique_id "apPkb46aRhSu8gis9Ll1LgAABOA"]
[Sun Aug 30 03:06:07.981574 2026] [security2:error] [pid 496962:tid 497134] [client 20.48.251.3:64455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/wp-konfig.backup.php"] [unique_id "apPkb46aRhSu8gis9Ll1MAAABNc"]
[Sun Aug 30 03:06:07.983799 2026] [security2:error] [pid 496962:tid 497166] [client 94.154.43.125:31490] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.needhealthinsuranceuk.com"] [uri "/.env"] [unique_id "apPkb46aRhSu8gis9Ll1MgAABPc"]
[Sun Aug 30 03:06:07.985605 2026] [security2:error] [pid 495314:tid 495513] [client 20.220.204.93:64238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/403.php"] [unique_id "apPkb0mtdPfUFP1akVFhXQAABG0"]
[Sun Aug 30 03:06:07.987893 2026] [security2:error] [pid 495314:tid 495538] [client 20.220.10.235:24666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkb0mtdPfUFP1akVFhYAAABIY"]
[Sun Aug 30 03:06:07.993534 2026] [security2:error] [pid 495314:tid 495468] [client 4.205.62.107:4558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/rpk.php"] [unique_id "apPkb0mtdPfUFP1akVFhYQAABEA"]
[Sun Aug 30 03:06:08.009374 2026] [security2:error] [pid 496962:tid 497168] [client 158.23.147.79:54266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-content/admin.php"] [unique_id "apPkcI6aRhSu8gis9Ll1OwAABPk"]
[Sun Aug 30 03:06:08.015508 2026] [security2:error] [pid 496962:tid 497159] [client 20.151.200.44:37849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPkcI6aRhSu8gis9Ll1PQAABPA"]
[Sun Aug 30 03:06:08.015850 2026] [security2:error] [pid 496962:tid 497118] [client 20.48.251.3:50042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/error_log.php"] [unique_id "apPkcI6aRhSu8gis9Ll1PgAABMc"]
[Sun Aug 30 03:06:08.033470 2026] [security2:error] [pid 496962:tid 497128] [client 20.48.251.3:44270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/wp-tem.php"] [unique_id "apPkcI6aRhSu8gis9Ll1SgAABNE"]
[Sun Aug 30 03:06:08.036435 2026] [security2:error] [pid 495314:tid 495533] [client 68.155.159.216:62298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-content/languages/about.php"] [unique_id "apPkcEmtdPfUFP1akVFhfQAABIE"]
[Sun Aug 30 03:06:08.039285 2026] [security2:error] [pid 496962:tid 497155] [client 68.155.159.216:63976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/radio.php"] [unique_id "apPkcI6aRhSu8gis9Ll1TgAABOw"]
[Sun Aug 30 03:06:08.054253 2026] [security2:error] [pid 495314:tid 495519] [client 4.205.62.107:2763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/aws_secret_config.php"] [unique_id "apPkcEmtdPfUFP1akVFhhgAABHM"]
[Sun Aug 30 03:06:08.055301 2026] [security2:error] [pid 496962:tid 497149] [client 4.205.62.107:56898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/update.php"] [unique_id "apPkcI6aRhSu8gis9Ll1VAAABOY"]
[Sun Aug 30 03:06:08.065848 2026] [security2:error] [pid 495314:tid 495461] [client 158.23.147.79:53296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/.well-known/content.php"] [unique_id "apPkcEmtdPfUFP1akVFhjQAABDk"]
[Sun Aug 30 03:06:08.108580 2026] [security2:error] [pid 495314:tid 495509] [client 20.151.200.44:47394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/log.php"] [unique_id "apPkcEmtdPfUFP1akVFhngAABGk"]
[Sun Aug 30 03:06:08.117862 2026] [authz_core:error] [pid 496962:tid 497214] [client 66.249.66.71:58892] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:08.118139 2026] [authz_core:error] [pid 496962:tid 497214] [client 66.249.66.71:58892] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:08.128976 2026] [security2:error] [pid 496962:tid 497103] [client 158.23.147.79:53521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/xmlrpc.php"] [unique_id "apPkcI6aRhSu8gis9Ll1YAAABLg"]
[Sun Aug 30 03:06:08.135804 2026] [security2:error] [pid 496962:tid 497127] [client 20.220.204.93:64254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/cytyr.php"] [unique_id "apPkcI6aRhSu8gis9Ll1ZAAABNA"]
[Sun Aug 30 03:06:08.141782 2026] [security2:error] [pid 496962:tid 497199] [client 20.220.10.235:24699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkcI6aRhSu8gis9Ll1ZQAABRg"]
[Sun Aug 30 03:06:08.165848 2026] [security2:error] [pid 495314:tid 495512] [client 20.104.50.220:62821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/repair.php"] [unique_id "apPkcEmtdPfUFP1akVFhuwAABGw"]
[Sun Aug 30 03:06:08.181010 2026] [security2:error] [pid 496962:tid 497170] [client 20.151.200.44:65257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/4e.php"] [unique_id "apPkcI6aRhSu8gis9Ll1dAAABPs"]
[Sun Aug 30 03:06:08.219618 2026] [security2:error] [pid 495314:tid 495555] [client 40.83.93.50:8761] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webmail.swmpainters.com"] [uri "/c99.php"] [unique_id "apPkcEmtdPfUFP1akVFh2QAABJc"]
[Sun Aug 30 03:06:08.241755 2026] [security2:error] [pid 496962:tid 497192] [client 4.205.62.107:22924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/phpi.php"] [unique_id "apPkcI6aRhSu8gis9Ll1iwAABRE"]
[Sun Aug 30 03:06:08.254871 2026] [security2:error] [pid 496962:tid 497134] [client 20.48.251.3:59327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/doc.php"] [unique_id "apPkcI6aRhSu8gis9Ll1kQAABNc"]
[Sun Aug 30 03:06:08.260515 2026] [security2:error] [pid 495314:tid 495536] [client 158.23.147.79:42069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/cong.php"] [unique_id "apPkcEmtdPfUFP1akVFh7QAABIQ"]
[Sun Aug 30 03:06:08.272821 2026] [security2:error] [pid 495314:tid 495452] [client 20.220.10.235:24652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/h02ugyh.php"] [unique_id "apPkcEmtdPfUFP1akVFh-QAABDA"]
[Sun Aug 30 03:06:08.280062 2026] [fcgid:warn] [pid 496962:tid 497178] (70014)End of file found: [client 34.14.114.20:7832] mod_fcgid: can't get data from http client
[Sun Aug 30 03:06:08.297136 2026] [security2:error] [pid 496962:tid 497145] [client 20.104.50.220:61379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/mailer.php"] [unique_id "apPkcI6aRhSu8gis9Ll1oAAABOI"]
[Sun Aug 30 03:06:08.317603 2026] [security2:error] [pid 495314:tid 495488] [client 158.23.147.79:54253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/atomlib.php"] [unique_id "apPkcEmtdPfUFP1akVFiDgAABFQ"]
[Sun Aug 30 03:06:08.318535 2026] [security2:error] [pid 496962:tid 497193] [client 68.155.159.216:56405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-content/languages/about.php"] [unique_id "apPkcI6aRhSu8gis9Ll1ogAABRI"]
[Sun Aug 30 03:06:08.319554 2026] [security2:error] [pid 496962:tid 497185] [client 4.205.62.107:18782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/setup-config.php"] [unique_id "apPkcI6aRhSu8gis9Ll1pAAABQo"]
[Sun Aug 30 03:06:08.357052 2026] [security2:error] [pid 496962:tid 497097] [client 20.48.251.3:54773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/cli_bootstrap.php"] [unique_id "apPkcI6aRhSu8gis9Ll1uwAABLI"]
[Sun Aug 30 03:06:08.365728 2026] [security2:error] [pid 496962:tid 497217] [client 20.220.204.93:62296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/galer.php"] [unique_id "apPkcI6aRhSu8gis9Ll1xQAABSo"]
[Sun Aug 30 03:06:08.378853 2026] [security2:error] [pid 496962:tid 497108] [client 158.23.147.79:53303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-includes/js/index.php"] [unique_id "apPkcI6aRhSu8gis9Ll10QAABL0"]
[Sun Aug 30 03:06:08.380624 2026] [security2:error] [pid 495314:tid 495457] [client 68.155.159.216:52621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apPkcEmtdPfUFP1akVFiNgAABDU"]
[Sun Aug 30 03:06:08.393281 2026] [security2:error] [pid 495314:tid 495498] [client 4.205.62.107:63975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/wp-blog.php"] [unique_id "apPkcEmtdPfUFP1akVFiOgAABF4"]
[Sun Aug 30 03:06:08.416449 2026] [security2:error] [pid 495314:tid 495445] [client 158.23.147.79:62574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apPkcEmtdPfUFP1akVFiSAAABCk"]
[Sun Aug 30 03:06:08.421006 2026] [security2:error] [pid 495314:tid 495461] [client 20.220.10.235:24667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/sf.php"] [unique_id "apPkcEmtdPfUFP1akVFiSwAABDk"]
[Sun Aug 30 03:06:08.426506 2026] [security2:error] [pid 495314:tid 495486] [client 20.48.251.3:4673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/vx.php"] [unique_id "apPkcEmtdPfUFP1akVFiTwAABFI"]
[Sun Aug 30 03:06:08.426565 2026] [security2:error] [pid 495314:tid 495511] [client 20.104.50.220:32898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/enter.php"] [unique_id "apPkcEmtdPfUFP1akVFiTgAABGs"]
[Sun Aug 30 03:06:08.475452 2026] [security2:error] [pid 495314:tid 495535] [client 20.151.200.44:64634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/ssss.php"] [unique_id "apPkcEmtdPfUFP1akVFibgAABIM"]
[Sun Aug 30 03:06:08.494359 2026] [security2:error] [pid 496962:tid 497109] [client 20.104.18.15:13759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/biufile.php"] [unique_id "apPkcI6aRhSu8gis9Ll1_QAABL4"]
[Sun Aug 30 03:06:08.496417 2026] [security2:error] [pid 496962:tid 497103] [client 20.104.50.220:29319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/you.php"] [unique_id "apPkcI6aRhSu8gis9Ll1_gAABLg"]
[Sun Aug 30 03:06:08.498463 2026] [security2:error] [pid 495314:tid 495496] [client 74.7.243.204:48120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/new/"] [unique_id "apPkcEmtdPfUFP1akVFiggAABFw"], referer: http://mail.letter7brands.com/new/?p=%2F%2Fetc
[Sun Aug 30 03:06:08.509557 2026] [security2:error] [pid 495314:tid 495569] [client 20.220.204.93:62239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/baixy.php"] [unique_id "apPkcEmtdPfUFP1akVFiiAAABKU"]
[Sun Aug 30 03:06:08.517527 2026] [security2:error] [pid 495314:tid 495562] [client 158.23.147.79:54253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/lv.php"] [unique_id "apPkcEmtdPfUFP1akVFijgAABJ4"]
[Sun Aug 30 03:06:08.523966 2026] [security2:error] [pid 495314:tid 495511] [client 20.151.200.44:62919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/ca.php"] [unique_id "apPkcEmtdPfUFP1akVFilQAABGs"]
[Sun Aug 30 03:06:08.528158 2026] [security2:error] [pid 496962:tid 497137] [client 4.205.62.107:36623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/classsmtps.php"] [unique_id "apPkcI6aRhSu8gis9Ll2DAAABNo"]
[Sun Aug 30 03:06:08.561001 2026] [security2:error] [pid 495314:tid 495521] [client 20.220.10.235:24778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/4e.php"] [unique_id "apPkcEmtdPfUFP1akVFioAAABHU"]
[Sun Aug 30 03:06:08.573918 2026] [security2:error] [pid 496962:tid 497193] [client 20.104.18.15:33677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/backup.php"] [unique_id "apPkcI6aRhSu8gis9Ll2FgAABRI"]
[Sun Aug 30 03:06:08.597617 2026] [security2:error] [pid 496962:tid 497163] [client 158.23.147.79:42058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-content/index.php"] [unique_id "apPkcI6aRhSu8gis9Ll2IQAABPQ"]
[Sun Aug 30 03:06:08.608074 2026] [authz_core:error] [pid 496962:tid 497200] [client 66.249.66.38:58339] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:08.608492 2026] [authz_core:error] [pid 496962:tid 497200] [client 66.249.66.38:58339] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:08.639296 2026] [security2:error] [pid 496962:tid 497110] [client 20.104.18.15:43312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/wp.php"] [unique_id "apPkcI6aRhSu8gis9Ll2PQAABL8"]
[Sun Aug 30 03:06:08.640440 2026] [security2:error] [pid 496962:tid 497146] [client 20.220.204.93:62287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/ava.php"] [unique_id "apPkcI6aRhSu8gis9Ll2PwAABOM"]
[Sun Aug 30 03:06:08.692193 2026] [security2:error] [pid 495314:tid 495512] [client 158.23.147.79:42071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/about/function.php"] [unique_id "apPkcEmtdPfUFP1akVFi0wAABGw"]
[Sun Aug 30 03:06:08.692479 2026] [security2:error] [pid 496962:tid 497139] [client 20.151.200.44:47099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "btallinonesecurity.com"] [uri "/waf.php"] [unique_id "apPkcI6aRhSu8gis9Ll2ZAAABNw"]
[Sun Aug 30 03:06:08.697412 2026] [security2:error] [pid 495314:tid 495528] [client 158.23.147.79:54247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-includes/Text/index.php"] [unique_id "apPkcEmtdPfUFP1akVFi1wAABHw"]
[Sun Aug 30 03:06:08.699554 2026] [security2:error] [pid 496962:tid 497123] [client 20.220.10.235:24701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/ssss.php"] [unique_id "apPkcI6aRhSu8gis9Ll2ZwAABMw"]
[Sun Aug 30 03:06:08.737296 2026] [security2:error] [pid 495314:tid 495539] [client 40.83.93.50:9333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/test1.php"] [unique_id "apPkcEmtdPfUFP1akVFi6QAABIc"]
[Sun Aug 30 03:06:08.759763 2026] [security2:error] [pid 495314:tid 495527] [client 20.104.50.220:51620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/cgi-alfa.php"] [unique_id "apPkcEmtdPfUFP1akVFi8gAABHs"]
[Sun Aug 30 03:06:08.763764 2026] [security2:error] [pid 496962:tid 497010] [remote 160.153.252.100:59564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.252.153.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "markblome.com"] [uri "/wp-login.php"] [unique_id "apPkcI6aRhSu8gis9Ll2gwAFDS8"]
[Sun Aug 30 03:06:08.766388 2026] [security2:error] [pid 496962:tid 497211] [client 20.104.50.220:27417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/Jcrop.php"] [unique_id "apPkcI6aRhSu8gis9Ll2hgAABSQ"]
[Sun Aug 30 03:06:08.767600 2026] [security2:error] [pid 495314:tid 495469] [client 20.220.204.93:61771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/gdn.php"] [unique_id "apPkcEmtdPfUFP1akVFi9AAABEE"]
[Sun Aug 30 03:06:08.792936 2026] [security2:error] [pid 495314:tid 495566] [client 68.155.159.216:65492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/radio.php"] [unique_id "apPkcEmtdPfUFP1akVFjAwAABKI"]
[Sun Aug 30 03:06:08.796971 2026] [security2:error] [pid 495314:tid 495549] [client 158.23.147.79:42056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-includes/customize/index.php"] [unique_id "apPkcEmtdPfUFP1akVFjBAAABJE"]
[Sun Aug 30 03:06:08.830101 2026] [security2:error] [pid 496962:tid 497164] [client 20.220.10.235:24661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/zoz.php"] [unique_id "apPkcI6aRhSu8gis9Ll2lwAABPU"]
[Sun Aug 30 03:06:08.876130 2026] [security2:error] [pid 496962:tid 497122] [client 20.104.50.220:46602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/ids.php"] [unique_id "apPkcI6aRhSu8gis9Ll2uQAABMs"]
[Sun Aug 30 03:06:08.876495 2026] [security2:error] [pid 495314:tid 495542] [client 4.205.62.107:63606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/params.php"] [unique_id "apPkcEmtdPfUFP1akVFjIgAABIo"]
[Sun Aug 30 03:06:08.902086 2026] [security2:error] [pid 495314:tid 495449] [client 20.220.204.93:62318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/f2.php"] [unique_id "apPkcEmtdPfUFP1akVFjMgAABC0"]
[Sun Aug 30 03:06:08.986069 2026] [security2:error] [pid 495314:tid 495458] [client 20.220.10.235:24696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/kcs.php"] [unique_id "apPkcEmtdPfUFP1akVFjWgAABDY"]
[Sun Aug 30 03:06:09.007056 2026] [security2:error] [pid 495314:tid 495461] [client 4.205.62.107:65398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/avim.php"] [unique_id "apPkcUmtdPfUFP1akVFjZgAABDk"]
[Sun Aug 30 03:06:09.029569 2026] [security2:error] [pid 496962:tid 497194] [client 68.155.159.216:54020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-admin/user/index.php"] [unique_id "apPkcY6aRhSu8gis9Ll29AAABRM"]
[Sun Aug 30 03:06:09.033718 2026] [security2:error] [pid 496962:tid 497168] [client 20.220.204.93:62322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/grsiuk.php"] [unique_id "apPkcY6aRhSu8gis9Ll29QAABPk"]
[Sun Aug 30 03:06:09.063043 2026] [authz_core:error] [pid 496962:tid 497184] [client 216.73.216.128:9601] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:09.063515 2026] [authz_core:error] [pid 496962:tid 497184] [client 216.73.216.128:9601] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:09.067014 2026] [authz_core:error] [pid 496962:tid 497149] [client 66.249.66.41:39762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:09.067326 2026] [authz_core:error] [pid 496962:tid 497149] [client 66.249.66.41:39762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:09.075584 2026] [security2:error] [pid 496962:tid 497102] [client 20.104.50.220:32726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/alf4.php"] [unique_id "apPkcY6aRhSu8gis9Ll3EQAABLc"]
[Sun Aug 30 03:06:09.077355 2026] [security2:error] [pid 496962:tid 497163] [client 20.151.200.44:23565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/pb.php"] [unique_id "apPkcY6aRhSu8gis9Ll3FgAABPQ"]
[Sun Aug 30 03:06:09.097418 2026] [security2:error] [pid 496962:tid 497134] [client 20.151.200.44:47384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/xwpg.php"] [unique_id "apPkcY6aRhSu8gis9Ll3HwAABNc"]
[Sun Aug 30 03:06:09.117132 2026] [security2:error] [pid 496962:tid 497130] [client 20.220.10.235:24787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/tajj.php"] [unique_id "apPkcY6aRhSu8gis9Ll3JQAABNM"]
[Sun Aug 30 03:06:09.120498 2026] [security2:error] [pid 496962:tid 497092] [client 20.48.251.3:6510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/packed.php"] [unique_id "apPkcY6aRhSu8gis9Ll3JwAABK0"]
[Sun Aug 30 03:06:09.134058 2026] [security2:error] [pid 495314:tid 495535] [client 20.104.50.220:5585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "apPkcUmtdPfUFP1akVFjkQAABIM"]
[Sun Aug 30 03:06:09.146792 2026] [security2:error] [pid 496962:tid 497143] [client 4.205.62.107:5068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/saml.php"] [unique_id "apPkcY6aRhSu8gis9Ll3MAAABOA"]
[Sun Aug 30 03:06:09.170478 2026] [security2:error] [pid 495314:tid 495522] [client 20.220.204.93:64164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/wp-scr1pts.php"] [unique_id "apPkcUmtdPfUFP1akVFjpAAABHY"]
[Sun Aug 30 03:06:09.172857 2026] [security2:error] [pid 495314:tid 495558] [client 20.48.251.3:50027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/phina.php"] [unique_id "apPkcUmtdPfUFP1akVFjpwAABJo"]
[Sun Aug 30 03:06:09.187729 2026] [security2:error] [pid 496962:tid 497155] [client 20.48.251.3:44247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/txets.php"] [unique_id "apPkcY6aRhSu8gis9Ll3QQAABOw"]
[Sun Aug 30 03:06:09.192760 2026] [security2:error] [pid 496962:tid 497111] [client 4.205.62.107:56600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/channels.php"] [unique_id "apPkcY6aRhSu8gis9Ll3RQAABMA"]
[Sun Aug 30 03:06:09.205849 2026] [security2:error] [pid 496962:tid 497179] [client 4.205.62.107:2774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/snq.php"] [unique_id "apPkcY6aRhSu8gis9Ll3SgAABQQ"]
[Sun Aug 30 03:06:09.208529 2026] [security2:error] [pid 495314:tid 495554] [client 4.205.62.107:27272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/gjm.php"] [unique_id "apPkcUmtdPfUFP1akVFjvAAABJY"]
[Sun Aug 30 03:06:09.238132 2026] [security2:error] [pid 496962:tid 497156] [client 20.48.251.3:64388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/application.config.php"] [unique_id "apPkcY6aRhSu8gis9Ll3WAAABO0"]
[Sun Aug 30 03:06:09.243264 2026] [security2:error] [pid 496962:tid 497095] [client 68.155.159.216:63512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-content/banners/about.php"] [unique_id "apPkcY6aRhSu8gis9Ll3XAAABLA"]
[Sun Aug 30 03:06:09.245687 2026] [authz_core:error] [pid 496962:tid 497151] [client 216.73.216.128:57093] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:09.245731 2026] [security2:error] [pid 496962:tid 497187] [client 20.220.10.235:24686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/bge.php"] [unique_id "apPkcY6aRhSu8gis9Ll3XwAABQw"]
[Sun Aug 30 03:06:09.246099 2026] [authz_core:error] [pid 496962:tid 497151] [client 216.73.216.128:57093] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:09.262902 2026] [security2:error] [pid 496962:tid 497131] [client 4.205.62.107:58350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/grsiuk.php"] [unique_id "apPkcY6aRhSu8gis9Ll3ZgAABNQ"]
[Sun Aug 30 03:06:09.288262 2026] [security2:error] [pid 495314:tid 495496] [client 40.83.93.50:12088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/data.php"] [unique_id "apPkcUmtdPfUFP1akVFj3QAABFw"]
[Sun Aug 30 03:06:09.300479 2026] [security2:error] [pid 496962:tid 497197] [client 20.220.204.93:62272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/num.php"] [unique_id "apPkcY6aRhSu8gis9Ll3gQAABRY"]
[Sun Aug 30 03:06:09.307772 2026] [security2:error] [pid 495314:tid 495547] [client 20.104.50.220:29592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/raw.php"] [unique_id "apPkcUmtdPfUFP1akVFj4QAABI8"]
[Sun Aug 30 03:06:09.338380 2026] [security2:error] [pid 496962:tid 497104] [client 68.155.159.216:61326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPkcY6aRhSu8gis9Ll3lQAABLk"]
[Sun Aug 30 03:06:09.378249 2026] [security2:error] [pid 496962:tid 497194] [client 20.220.10.235:24771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/ssh3ll.php"] [unique_id "apPkcY6aRhSu8gis9Ll3sQAABRM"]
[Sun Aug 30 03:06:09.395125 2026] [security2:error] [pid 496962:tid 497196] [client 20.48.251.3:59340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/classsmtps.php"] [unique_id "apPkcY6aRhSu8gis9Ll3uwAABRU"]
[Sun Aug 30 03:06:09.395987 2026] [security2:error] [pid 496962:tid 497174] [client 4.205.62.107:22582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "apPkcY6aRhSu8gis9Ll3vAAABP8"]
[Sun Aug 30 03:06:09.428168 2026] [authz_core:error] [pid 496962:tid 497181] [client 20.104.50.220:61427] AH01630: client denied by server configuration: /home1/mwarifa/richardmudzingwa.com/php.ini
[Sun Aug 30 03:06:09.431349 2026] [security2:error] [pid 496962:tid 497139] [client 20.220.204.93:64186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/a4.php"] [unique_id "apPkcY6aRhSu8gis9Ll32gAABNw"]
[Sun Aug 30 03:06:09.441498 2026] [security2:error] [pid 495314:tid 495462] [client 68.155.159.216:11205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-content/banners/about.php"] [unique_id "apPkcUmtdPfUFP1akVFkEQAABDo"]
[Sun Aug 30 03:06:09.464190 2026] [authz_core:error] [pid 495314:tid 495543] [client 66.249.66.71:42195] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:09.464634 2026] [authz_core:error] [pid 495314:tid 495543] [client 66.249.66.71:42195] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:09.482106 2026] [security2:error] [pid 496962:tid 497137] [client 4.205.62.107:18788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/wp-admin/sc.php"] [unique_id "apPkcY6aRhSu8gis9Ll36wAABNo"]
[Sun Aug 30 03:06:09.491545 2026] [security2:error] [pid 496962:tid 497153] [client 20.104.50.220:61427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/modul.php"] [unique_id "apPkcY6aRhSu8gis9Ll38QAABOo"]
[Sun Aug 30 03:06:09.496938 2026] [security2:error] [pid 496962:tid 497173] [client 20.151.200.44:55739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/zoz.php"] [unique_id "apPkcY6aRhSu8gis9Ll38gAABP4"]
[Sun Aug 30 03:06:09.511835 2026] [security2:error] [pid 496962:tid 497103] [client 216.73.216.128:9601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPkcY6aRhSu8gis9Ll3-gAABLg"]
[Sun Aug 30 03:06:09.519432 2026] [security2:error] [pid 496962:tid 497214] [client 20.48.251.3:43250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/dd.php"] [unique_id "apPkcY6aRhSu8gis9Ll4AAAABSc"]
[Sun Aug 30 03:06:09.531490 2026] [security2:error] [pid 496962:tid 497132] [client 4.205.62.107:62135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/erty.php"] [unique_id "apPkcY6aRhSu8gis9Ll4AgAABNU"]
[Sun Aug 30 03:06:09.539083 2026] [security2:error] [pid 495314:tid 495537] [client 20.220.10.235:24653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/motu.php"] [unique_id "apPkcUmtdPfUFP1akVFkPwAABIU"]
[Sun Aug 30 03:06:09.548498 2026] [security2:error] [pid 495314:tid 495446] [client 68.155.159.216:54769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apPkcUmtdPfUFP1akVFkQgAABCo"]
[Sun Aug 30 03:06:09.564572 2026] [security2:error] [pid 496962:tid 497170] [client 20.220.204.93:62324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/tfm.php"] [unique_id "apPkcY6aRhSu8gis9Ll4DwAABPs"]
[Sun Aug 30 03:06:09.596855 2026] [security2:error] [pid 495314:tid 495541] [client 20.104.50.220:32864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-enter.php"] [unique_id "apPkcUmtdPfUFP1akVFkXQAABIk"]
[Sun Aug 30 03:06:09.634559 2026] [security2:error] [pid 495314:tid 495518] [client 20.104.50.220:52836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/a.php"] [unique_id "apPkcUmtdPfUFP1akVFkdAAABHI"]
[Sun Aug 30 03:06:09.643804 2026] [security2:error] [pid 496962:tid 497109] [client 20.48.251.3:5078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/ty.php"] [unique_id "apPkcY6aRhSu8gis9Ll4KAAABL4"]
[Sun Aug 30 03:06:09.646215 2026] [security2:error] [pid 496962:tid 497020] [remote 160.153.252.100:59564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.252.153.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "markblome.com"] [uri "/wp-login.php"] [unique_id "apPkcY6aRhSu8gis9Ll4KQAEyjk"], referer: https://markblome.com/wp-login.php
[Sun Aug 30 03:06:09.653746 2026] [security2:error] [pid 495314:tid 495514] [client 20.151.200.44:64011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/zoz.php"] [unique_id "apPkcUmtdPfUFP1akVFkfwAABG4"]
[Sun Aug 30 03:06:09.665754 2026] [security2:error] [pid 495314:tid 495462] [client 4.205.62.107:32018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/paypal.php"] [unique_id "apPkcUmtdPfUFP1akVFkjAAABDo"]
[Sun Aug 30 03:06:09.665929 2026] [security2:error] [pid 495314:tid 495478] [client 20.104.18.15:13713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/blacks.php"] [unique_id "apPkcUmtdPfUFP1akVFkjQAABEo"]
[Sun Aug 30 03:06:09.674969 2026] [security2:error] [pid 496962:tid 497214] [client 20.220.10.235:24642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/wefile.php"] [unique_id "apPkcY6aRhSu8gis9Ll4MgAABSc"]
[Sun Aug 30 03:06:09.682194 2026] [authz_core:error] [pid 495314:tid 495494] [client 66.249.66.77:53492] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:09.682573 2026] [authz_core:error] [pid 495314:tid 495494] [client 66.249.66.77:53492] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:09.699898 2026] [security2:error] [pid 496962:tid 497116] [client 20.220.204.93:64130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/Geforce.php"] [unique_id "apPkcY6aRhSu8gis9Ll4PgAABMU"]
[Sun Aug 30 03:06:09.750792 2026] [security2:error] [pid 496962:tid 497119] [client 20.104.18.15:33760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/indo.php"] [unique_id "apPkcY6aRhSu8gis9Ll4SQAABMg"]
[Sun Aug 30 03:06:09.752335 2026] [authz_core:error] [pid 495314:tid 495522] [client 216.73.216.128:38799] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:09.752764 2026] [authz_core:error] [pid 495314:tid 495522] [client 216.73.216.128:38799] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:09.779047 2026] [security2:error] [pid 495314:tid 495462] [client 20.151.200.44:62183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/pk.php"] [unique_id "apPkcUmtdPfUFP1akVFkywAABDo"]
[Sun Aug 30 03:06:09.782820 2026] [security2:error] [pid 495314:tid 495533] [client 20.151.200.44:64014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/kcs.php"] [unique_id "apPkcUmtdPfUFP1akVFkzgAABIE"]
[Sun Aug 30 03:06:09.807521 2026] [security2:error] [pid 495314:tid 495488] [client 20.104.18.15:43932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/abcd.php"] [unique_id "apPkcUmtdPfUFP1akVFk1AAABFQ"]
[Sun Aug 30 03:06:09.807688 2026] [security2:error] [pid 496962:tid 497165] [client 20.220.10.235:24770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/Contrller.php"] [unique_id "apPkcY6aRhSu8gis9Ll4XQAABPY"]
[Sun Aug 30 03:06:09.817840 2026] [security2:error] [pid 495314:tid 495570] [client 40.83.93.50:8720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/classwithtostring.php"] [unique_id "apPkcUmtdPfUFP1akVFk3gAABKY"]
[Sun Aug 30 03:06:09.838466 2026] [security2:error] [pid 496962:tid 497145] [client 20.220.204.93:61773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/click.php"] [unique_id "apPkcY6aRhSu8gis9Ll4dAAABOI"]
[Sun Aug 30 03:06:09.898117 2026] [security2:error] [pid 495314:tid 495475] [client 20.104.50.220:27092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/Debug.php"] [unique_id "apPkcUmtdPfUFP1akVFlCQAABEc"]
[Sun Aug 30 03:06:09.904919 2026] [security2:error] [pid 496962:tid 497158] [client 158.23.147.79:4034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-admin/index.php"] [unique_id "apPkcY6aRhSu8gis9Ll4jAAABO8"]
[Sun Aug 30 03:06:09.910681 2026] [security2:error] [pid 496962:tid 497165] [client 20.104.50.220:51625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/cok.php"] [unique_id "apPkcY6aRhSu8gis9Ll4kQAABPY"]
[Sun Aug 30 03:06:09.911029 2026] [rewrite:warn] [pid 495314:tid 495339] AH00665: RewriteCond: NoCase option for non-regex pattern '-d' is not supported and will be ignored. (/home3/keilan/public_html/.htaccess:12)
[Sun Aug 30 03:06:09.911040 2026] [rewrite:warn] [pid 495314:tid 495339] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home3/keilan/public_html/.htaccess:13)
[Sun Aug 30 03:06:09.920960 2026] [security2:error] [pid 495314:tid 495488] [client 68.155.159.216:12310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPkcUmtdPfUFP1akVFlGwAABFQ"]
[Sun Aug 30 03:06:09.936406 2026] [security2:error] [pid 496962:tid 497194] [client 158.23.147.79:53524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/content.php"] [unique_id "apPkcY6aRhSu8gis9Ll4lQAABRM"]
[Sun Aug 30 03:06:09.936872 2026] [security2:error] [pid 495314:tid 495530] [client 20.220.10.235:24776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/file66.php"] [unique_id "apPkcUmtdPfUFP1akVFlJQAABH4"]
[Sun Aug 30 03:06:09.954592 2026] [authz_core:error] [pid 495314:tid 495450] [client 66.249.66.75:57789] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:09.954931 2026] [authz_core:error] [pid 495314:tid 495450] [client 66.249.66.75:57789] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:09.977890 2026] [security2:error] [pid 496962:tid 497121] [client 20.220.204.93:62312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/ms.php"] [unique_id "apPkcY6aRhSu8gis9Ll4oQAABMo"]
[Sun Aug 30 03:06:10.002062 2026] [security2:error] [pid 495314:tid 495533] [client 158.23.147.79:53259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-content/themes/index.php"] [unique_id "apPkckmtdPfUFP1akVFlSgAABIE"]
[Sun Aug 30 03:06:10.013897 2026] [security2:error] [pid 495314:tid 495561] [client 20.104.50.220:46898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/idx.php"] [unique_id "apPkckmtdPfUFP1akVFlVgAABJ0"]
[Sun Aug 30 03:06:10.013963 2026] [security2:error] [pid 495314:tid 495521] [client 4.205.62.107:63750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/gjm.php"] [unique_id "apPkckmtdPfUFP1akVFlVwAABHU"]
[Sun Aug 30 03:06:10.038477 2026] [security2:error] [pid 496962:tid 497209] [client 158.23.147.79:53541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPkco6aRhSu8gis9Ll4vgAABSI"]
[Sun Aug 30 03:06:10.073322 2026] [security2:error] [pid 496962:tid 497107] [client 20.220.10.235:24774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/blnux.php"] [unique_id "apPkco6aRhSu8gis9Ll4zQAABLw"]
[Sun Aug 30 03:06:10.083486 2026] [security2:error] [pid 496962:tid 497106] [client 20.151.200.44:64660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/tajj.php"] [unique_id "apPkco6aRhSu8gis9Ll40gAABLs"]
[Sun Aug 30 03:06:10.133957 2026] [security2:error] [pid 496962:tid 497212] [client 20.220.204.93:62292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/zxekqlxb.php"] [unique_id "apPkco6aRhSu8gis9Ll44wAABSU"]
[Sun Aug 30 03:06:10.142432 2026] [security2:error] [pid 496962:tid 497201] [client 20.151.200.44:63560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/ft.php"] [unique_id "apPkco6aRhSu8gis9Ll46AAABRo"]
[Sun Aug 30 03:06:10.153073 2026] [security2:error] [pid 496962:tid 497124] [client 4.205.62.107:65313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/nw.php"] [unique_id "apPkco6aRhSu8gis9Ll47AAABM0"]
[Sun Aug 30 03:06:10.153098 2026] [security2:error] [pid 496962:tid 497114] [client 68.155.159.216:54041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-includes/plugins.php"] [unique_id "apPkco6aRhSu8gis9Ll46wAABMM"]
[Sun Aug 30 03:06:10.205820 2026] [security2:error] [pid 496962:tid 497139] [client 20.220.10.235:24780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/attack.php"] [unique_id "apPkco6aRhSu8gis9Ll5EAAABNw"]
[Sun Aug 30 03:06:10.218699 2026] [authz_core:error] [pid 496962:tid 497169] [client 216.73.216.128:36424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:10.219164 2026] [authz_core:error] [pid 496962:tid 497169] [client 216.73.216.128:36424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:10.230115 2026] [security2:error] [pid 495314:tid 495448] [client 20.104.50.220:32092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/alfa-shell-v4.php"] [unique_id "apPkckmtdPfUFP1akVFlvgAABCw"]
[Sun Aug 30 03:06:10.255569 2026] [security2:error] [pid 495314:tid 495485] [client 20.48.251.3:7047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/wp-info.php"] [unique_id "apPkckmtdPfUFP1akVFlygAABFE"]
[Sun Aug 30 03:06:10.256854 2026] [security2:error] [pid 496962:tid 497099] [client 4.205.62.107:35992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/cache-compat.php"] [unique_id "apPkco6aRhSu8gis9Ll5IQAABLQ"]
[Sun Aug 30 03:06:10.259689 2026] [authz_core:error] [pid 496962:tid 497198] [client 216.73.216.128:57093] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:10.260030 2026] [authz_core:error] [pid 496962:tid 497198] [client 216.73.216.128:57093] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:10.269582 2026] [autoindex:error] [pid 496962:tid 497128] [client 34.34.225.205:10859] AH01276: Cannot serve directory /var/www/html/images/: No matching DirectoryIndex (index.cgi,index.php,index.html,index.htm) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:06:10.305371 2026] [security2:error] [pid 495314:tid 495536] [client 20.104.50.220:5582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/nox.php"] [unique_id "apPkckmtdPfUFP1akVFl6wAABIQ"]
[Sun Aug 30 03:06:10.306519 2026] [security2:error] [pid 496962:tid 497120] [client 20.48.251.3:55495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/koiy.php"] [unique_id "apPkco6aRhSu8gis9Ll5NQAABMk"]
[Sun Aug 30 03:06:10.309900 2026] [security2:error] [pid 495314:tid 495549] [client 20.220.204.93:62257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/init.php"] [unique_id "apPkckmtdPfUFP1akVFl7QAABJE"]
[Sun Aug 30 03:06:10.330933 2026] [security2:error] [pid 496962:tid 497092] [client 4.205.62.107:56625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/zz.php"] [unique_id "apPkco6aRhSu8gis9Ll5PAAABK0"]
[Sun Aug 30 03:06:10.336747 2026] [security2:error] [pid 496962:tid 497163] [client 20.220.10.235:24671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/wk/index.php"] [unique_id "apPkco6aRhSu8gis9Ll5PgAABPQ"]
[Sun Aug 30 03:06:10.337606 2026] [security2:error] [pid 496962:tid 497186] [client 20.48.251.3:23336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/time.php"] [unique_id "apPkco6aRhSu8gis9Ll5PwAABQs"]
[Sun Aug 30 03:06:10.347132 2026] [security2:error] [pid 496962:tid 497107] [client 4.205.62.107:2359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/wp-access.php"] [unique_id "apPkco6aRhSu8gis9Ll5RAAABLw"]
[Sun Aug 30 03:06:10.370906 2026] [security2:error] [pid 495314:tid 495531] [client 68.155.159.216:63521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-includes/Text/about.php"] [unique_id "apPkckmtdPfUFP1akVFmHwAABH8"]
[Sun Aug 30 03:06:10.382444 2026] [security2:error] [pid 496962:tid 497174] [client 20.151.200.44:63618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/wp-ver.php"] [unique_id "apPkco6aRhSu8gis9Ll5YQAABP8"]
[Sun Aug 30 03:06:10.384550 2026] [security2:error] [pid 496962:tid 497154] [client 4.205.62.107:4617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/aws_settings.php"] [unique_id "apPkco6aRhSu8gis9Ll5YwAABOs"]
[Sun Aug 30 03:06:10.420770 2026] [security2:error] [pid 495314:tid 495459] [client 40.83.93.50:8767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/en.php"] [unique_id "apPkckmtdPfUFP1akVFmPQAABDc"]
[Sun Aug 30 03:06:10.443041 2026] [security2:error] [pid 495314:tid 495453] [client 20.151.200.44:64040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/bge.php"] [unique_id "apPkckmtdPfUFP1akVFmSQAABDE"]
[Sun Aug 30 03:06:10.450138 2026] [authz_core:error] [pid 496962:tid 497100] [client 66.249.66.200:41173] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:10.450625 2026] [authz_core:error] [pid 496962:tid 497100] [client 66.249.66.200:41173] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:10.469170 2026] [security2:error] [pid 496962:tid 497095] [client 20.220.10.235:24730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/dehnl.php"] [unique_id "apPkco6aRhSu8gis9Ll5gwAABLA"]
[Sun Aug 30 03:06:10.472469 2026] [security2:error] [pid 495314:tid 495455] [client 20.104.50.220:62843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/py.php"] [unique_id "apPkckmtdPfUFP1akVFmWwAABDM"]
[Sun Aug 30 03:06:10.483233 2026] [security2:error] [pid 495314:tid 495487] [client 20.220.204.93:62240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/term.php"] [unique_id "apPkckmtdPfUFP1akVFmYwAABFM"]
[Sun Aug 30 03:06:10.523027 2026] [security2:error] [pid 496962:tid 497174] [client 20.104.49.130:53588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/coffexium.php"] [unique_id "apPkco6aRhSu8gis9Ll5kgAABP8"]
[Sun Aug 30 03:06:10.528034 2026] [security2:error] [pid 495314:tid 495542] [client 20.151.200.44:47376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/sxxb.php"] [unique_id "apPkckmtdPfUFP1akVFmfAAABIo"]
[Sun Aug 30 03:06:10.528544 2026] [security2:error] [pid 495314:tid 495522] [client 68.155.159.216:63966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/makeasmtp.php"] [unique_id "apPkckmtdPfUFP1akVFmfQAABHY"]
[Sun Aug 30 03:06:10.532865 2026] [security2:error] [pid 495314:tid 495500] [client 20.48.251.3:59292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/cache-compat.php"] [unique_id "apPkckmtdPfUFP1akVFmgAAABGA"]
[Sun Aug 30 03:06:10.543402 2026] [security2:error] [pid 495314:tid 495473] [client 68.155.159.216:11218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apPkckmtdPfUFP1akVFmgwAABEU"]
[Sun Aug 30 03:06:10.558886 2026] [security2:error] [pid 495314:tid 495546] [client 4.205.62.107:62306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/myfile.php"] [unique_id "apPkckmtdPfUFP1akVFmiQAABI4"]
[Sun Aug 30 03:06:10.609423 2026] [security2:error] [pid 495314:tid 495365] [remote 66.116.199.98:52630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.199.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jackasssawhorse.com"] [uri "/wp-login.php"] [unique_id "apPkckmtdPfUFP1akVFmogAEpDI"]
[Sun Aug 30 03:06:10.613936 2026] [security2:error] [pid 495314:tid 495446] [client 20.220.10.235:24798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/png.php"] [unique_id "apPkckmtdPfUFP1akVFmqAAABCo"]
[Sun Aug 30 03:06:10.617599 2026] [security2:error] [pid 496962:tid 497163] [client 20.220.204.93:64170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/aaa.php"] [unique_id "apPkco6aRhSu8gis9Ll5sAAABPQ"]
[Sun Aug 30 03:06:10.629804 2026] [security2:error] [pid 496962:tid 497172] [client 4.205.62.107:18963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/debug.php"] [unique_id "apPkco6aRhSu8gis9Ll5tAAABP0"]
[Sun Aug 30 03:06:10.645138 2026] [security2:error] [pid 495314:tid 495537] [client 20.104.50.220:61460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/configuration.php"] [unique_id "apPkckmtdPfUFP1akVFmvQAABIU"]
[Sun Aug 30 03:06:10.649496 2026] [security2:error] [pid 496962:tid 497189] [client 20.151.200.44:63569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/ah24.php"] [unique_id "apPkco6aRhSu8gis9Ll5wAAABQ4"]
[Sun Aug 30 03:06:10.660313 2026] [security2:error] [pid 495314:tid 495528] [client 20.48.251.3:64291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/wp-tem.php"] [unique_id "apPkckmtdPfUFP1akVFmzAAABHw"]
[Sun Aug 30 03:06:10.667093 2026] [security2:error] [pid 495314:tid 495507] [client 4.205.62.107:64038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/wp-config.backup.php"] [unique_id "apPkckmtdPfUFP1akVFm0wAABGc"]
[Sun Aug 30 03:06:10.680327 2026] [security2:error] [pid 496962:tid 497174] [client 68.155.159.216:52690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/packed.php"] [unique_id "apPkco6aRhSu8gis9Ll5zQAABP8"]
[Sun Aug 30 03:06:10.734428 2026] [security2:error] [pid 495314:tid 495461] [client 20.104.50.220:33560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/cakt.php"] [unique_id "apPkckmtdPfUFP1akVFm_wAABDk"]
[Sun Aug 30 03:06:10.745227 2026] [security2:error] [pid 495314:tid 495484] [client 20.220.10.235:24772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/txets.php"] [unique_id "apPkckmtdPfUFP1akVFnBAAABFA"]
[Sun Aug 30 03:06:10.749775 2026] [security2:error] [pid 495314:tid 495451] [client 20.220.204.93:64146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/xsox.php"] [unique_id "apPkckmtdPfUFP1akVFnCgAABC8"]
[Sun Aug 30 03:06:10.789390 2026] [security2:error] [pid 496962:tid 497197] [client 20.104.50.220:62807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/ap.php"] [unique_id "apPkco6aRhSu8gis9Ll54gAABRY"]
[Sun Aug 30 03:06:10.800973 2026] [security2:error] [pid 495314:tid 495444] [client 20.104.18.15:13720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/beck.php"] [unique_id "apPkckmtdPfUFP1akVFnKQAABCg"]
[Sun Aug 30 03:06:10.814317 2026] [security2:error] [pid 495314:tid 495479] [client 20.48.251.3:4727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/adminer-4.7.6-en.php"] [unique_id "apPkckmtdPfUFP1akVFnLwAABEs"]
[Sun Aug 30 03:06:10.834557 2026] [security2:error] [pid 496962:tid 497162] [client 20.48.251.3:45844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/xp.php"] [unique_id "apPkco6aRhSu8gis9Ll58wAABPM"]
[Sun Aug 30 03:06:10.850228 2026] [authz_core:error] [pid 496962:tid 497195] [client 66.249.66.45:44832] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:10.850692 2026] [authz_core:error] [pid 496962:tid 497195] [client 66.249.66.45:44832] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:10.876681 2026] [security2:error] [pid 496962:tid 497128] [client 4.205.62.107:58345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/userfuns.php"] [unique_id "apPkco6aRhSu8gis9Ll6EAAABNE"]
[Sun Aug 30 03:06:10.881785 2026] [security2:error] [pid 496962:tid 497210] [client 20.104.18.15:33772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/sign.php"] [unique_id "apPkco6aRhSu8gis9Ll6EwAABSM"]
[Sun Aug 30 03:06:10.890918 2026] [security2:error] [pid 496962:tid 497142] [client 20.220.204.93:64211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/lkui.php"] [unique_id "apPkco6aRhSu8gis9Ll6GQAABN8"]
[Sun Aug 30 03:06:10.906354 2026] [security2:error] [pid 496962:tid 497204] [client 20.220.10.235:24781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/wp-login.php"] [unique_id "apPkco6aRhSu8gis9Ll6EgAABR0"]
[Sun Aug 30 03:06:10.950239 2026] [security2:error] [pid 495314:tid 495467] [client 20.151.200.44:63001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPkckmtdPfUFP1akVFnZgAABD8"]
[Sun Aug 30 03:06:10.979366 2026] [security2:error] [pid 496962:tid 497114] [client 20.104.18.15:43968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/nofile.php"] [unique_id "apPkco6aRhSu8gis9Ll6QQAABMM"]
[Sun Aug 30 03:06:10.988121 2026] [security2:error] [pid 495314:tid 495450] [client 4.205.62.107:26513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/configuration.php"] [unique_id "apPkckmtdPfUFP1akVFnfgAABC4"]
[Sun Aug 30 03:06:11.020791 2026] [security2:error] [pid 496962:tid 497096] [client 68.155.159.216:12381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/makeasmtp.php"] [unique_id "apPkc46aRhSu8gis9Ll6SwAABLE"]
[Sun Aug 30 03:06:11.022849 2026] [security2:error] [pid 496962:tid 497207] [client 20.220.204.93:61763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apPkc46aRhSu8gis9Ll6TAAABSA"]
[Sun Aug 30 03:06:11.034068 2026] [security2:error] [pid 496962:tid 497133] [client 20.104.50.220:27119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/canonical.php"] [unique_id "apPkc46aRhSu8gis9Ll6VAAABNY"]
[Sun Aug 30 03:06:11.037409 2026] [security2:error] [pid 495314:tid 495447] [client 20.220.10.235:24687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/wp-access.php"] [unique_id "apPkc0mtdPfUFP1akVFnnwAABCs"]
[Sun Aug 30 03:06:11.048542 2026] [security2:error] [pid 495314:tid 495455] [client 74.7.243.204:48120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/new/"] [unique_id "apPkc0mtdPfUFP1akVFnowAABDM"], referer: http://mail.letter7brands.com/new/?p=%2F%2Fetc
[Sun Aug 30 03:06:11.076030 2026] [authz_core:error] [pid 496962:tid 497117] [client 216.73.216.128:36424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:11.076539 2026] [authz_core:error] [pid 496962:tid 497117] [client 216.73.216.128:36424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:11.094727 2026] [security2:error] [pid 495314:tid 495516] [client 20.104.50.220:51581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/cgipro.php"] [unique_id "apPkc0mtdPfUFP1akVFnwwAABHA"]
[Sun Aug 30 03:06:11.100160 2026] [security2:error] [pid 496962:tid 497102] [client 40.83.93.50:9038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/13.php"] [unique_id "apPkc46aRhSu8gis9Ll6dwAABLc"]
[Sun Aug 30 03:06:11.121041 2026] [security2:error] [pid 495314:tid 495510] [client 20.151.200.44:64583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/ssh3ll.php"] [unique_id "apPkc0mtdPfUFP1akVFnyQAABGo"]
[Sun Aug 30 03:06:11.151096 2026] [security2:error] [pid 496962:tid 497158] [client 4.205.62.107:60525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/configuration.php"] [unique_id "apPkc46aRhSu8gis9Ll6gQAABO8"]
[Sun Aug 30 03:06:11.151638 2026] [security2:error] [pid 496962:tid 497169] [client 20.104.50.220:47075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/init.php"] [unique_id "apPkc46aRhSu8gis9Ll6gwAABPo"]
[Sun Aug 30 03:06:11.182093 2026] [security2:error] [pid 496962:tid 497159] [client 20.220.10.235:24830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/wp-content/admin.php"] [unique_id "apPkc46aRhSu8gis9Ll6mgAABPA"]
[Sun Aug 30 03:06:11.197333 2026] [security2:error] [pid 496962:tid 497181] [client 20.220.204.93:64148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/motu.php"] [unique_id "apPkc46aRhSu8gis9Ll6oAAABQY"]
[Sun Aug 30 03:06:11.258417 2026] [authz_core:error] [pid 496962:tid 497105] [client 216.73.216.128:57093] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:11.258716 2026] [authz_core:error] [pid 496962:tid 497105] [client 216.73.216.128:57093] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:11.274776 2026] [security2:error] [pid 495314:tid 495547] [client 68.155.159.216:54129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apPkc0mtdPfUFP1akVFoIgAABI8"]
[Sun Aug 30 03:06:11.276916 2026] [security2:error] [pid 495314:tid 495487] [client 20.104.49.130:53627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/ops.php"] [unique_id "apPkc0mtdPfUFP1akVFoKAAABFM"]
[Sun Aug 30 03:06:11.285519 2026] [security2:error] [pid 495314:tid 495529] [client 4.205.62.107:58150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/product.php"] [unique_id "apPkc0mtdPfUFP1akVFoMwAABH0"]
[Sun Aug 30 03:06:11.312049 2026] [security2:error] [pid 495314:tid 495556] [client 20.220.10.235:24695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/log.php"] [unique_id "apPkc0mtdPfUFP1akVFoRgAABJg"]
[Sun Aug 30 03:06:11.329493 2026] [security2:error] [pid 496962:tid 497131] [client 4.205.62.107:31738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/mamzi.php"] [unique_id "apPkc46aRhSu8gis9Ll6wAAABNQ"]
[Sun Aug 30 03:06:11.389896 2026] [security2:error] [pid 495314:tid 495451] [client 20.220.204.93:64172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/Ov-Simple1.php"] [unique_id "apPkc0mtdPfUFP1akVFodQAABC8"]
[Sun Aug 30 03:06:11.390254 2026] [security2:error] [pid 495314:tid 495488] [client 20.48.251.3:64398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/fns.php"] [unique_id "apPkc0mtdPfUFP1akVFodgAABFQ"]
[Sun Aug 30 03:06:11.397174 2026] [security2:error] [pid 495314:tid 495562] [client 20.104.50.220:31839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/alfakun.php"] [unique_id "apPkc0mtdPfUFP1akVFofgAABJ4"]
[Sun Aug 30 03:06:11.431879 2026] [security2:error] [pid 495314:tid 495520] [client 20.151.200.44:23602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.basichoa.com"] [uri "/waf.php"] [unique_id "apPkc0mtdPfUFP1akVFojwAABHQ"]
[Sun Aug 30 03:06:11.439533 2026] [authz_core:error] [pid 496962:tid 497198] [client 216.73.216.128:59380] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:11.439923 2026] [authz_core:error] [pid 496962:tid 497198] [client 216.73.216.128:59380] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:11.440949 2026] [security2:error] [pid 496962:tid 497189] [client 20.220.10.235:24680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/xwpg.php"] [unique_id "apPkc46aRhSu8gis9Ll7BQAABQ4"]
[Sun Aug 30 03:06:11.442096 2026] [security2:error] [pid 496962:tid 497218] [client 20.151.200.44:47319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/dx.php"] [unique_id "apPkc46aRhSu8gis9Ll7BgAABSs"]
[Sun Aug 30 03:06:11.443834 2026] [security2:error] [pid 495314:tid 495515] [client 20.48.251.3:55482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/queue.php"] [unique_id "apPkc0mtdPfUFP1akVFomAAABG8"]
[Sun Aug 30 03:06:11.453238 2026] [security2:error] [pid 496962:tid 497177] [client 20.104.50.220:5584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/file48.php"] [unique_id "apPkc46aRhSu8gis9Ll7CQAABQI"]
[Sun Aug 30 03:06:11.468697 2026] [security2:error] [pid 495314:tid 495453] [client 4.205.62.107:51739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/test.php"] [unique_id "apPkc0mtdPfUFP1akVFoqAAABDE"]
[Sun Aug 30 03:06:11.478279 2026] [security2:error] [pid 495314:tid 495517] [client 20.48.251.3:44169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/doc.php"] [unique_id "apPkc0mtdPfUFP1akVForwAABHE"]
[Sun Aug 30 03:06:11.510367 2026] [authz_core:error] [pid 496962:tid 497092] [client 66.249.66.200:42565] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:11.510637 2026] [authz_core:error] [pid 496962:tid 497092] [client 66.249.66.200:42565] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:11.514806 2026] [security2:error] [pid 495314:tid 495450] [client 4.205.62.107:3005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/otuz1.php"] [unique_id "apPkc0mtdPfUFP1akVFovwAABC4"]
[Sun Aug 30 03:06:11.518940 2026] [security2:error] [pid 495314:tid 495550] [client 4.205.62.107:4613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/wp-konfig.backup.php"] [unique_id "apPkc0mtdPfUFP1akVFoxwAABJI"]
[Sun Aug 30 03:06:11.539593 2026] [security2:error] [pid 495314:tid 495491] [client 74.7.243.204:48120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/new/"] [unique_id "apPkc0mtdPfUFP1akVFozwAABFc"], referer: http://mail.letter7brands.com/new/?p=%2F%2Fetc
[Sun Aug 30 03:06:11.567729 2026] [security2:error] [pid 496962:tid 497127] [client 20.220.204.93:62230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/wp-blogs.php"] [unique_id "apPkc46aRhSu8gis9Ll7OwAABNA"]
[Sun Aug 30 03:06:11.588437 2026] [security2:error] [pid 496962:tid 497115] [client 20.220.10.235:24692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/sxxb.php"] [unique_id "apPkc46aRhSu8gis9Ll7QwAABMQ"]
[Sun Aug 30 03:06:11.609344 2026] [security2:error] [pid 496962:tid 497119] [client 20.104.50.220:28708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/ray.php"] [unique_id "apPkc46aRhSu8gis9Ll7SgAABMg"]
[Sun Aug 30 03:06:11.654376 2026] [security2:error] [pid 496962:tid 497181] [client 68.155.159.216:56428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/asd.php"] [unique_id "apPkc46aRhSu8gis9Ll7YwAABQY"]
[Sun Aug 30 03:06:11.671228 2026] [security2:error] [pid 496962:tid 497134] [client 20.48.251.3:55743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/aws_keys.php"] [unique_id "apPkc46aRhSu8gis9Ll7dAAABNc"]
[Sun Aug 30 03:06:11.676634 2026] [core:alert] [pid 496962:tid 497188] [client 39.60.120.81:34108] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:06:11.681227 2026] [authz_core:error] [pid 496962:tid 497183] [client 66.249.66.32:35005] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:11.681712 2026] [authz_core:error] [pid 496962:tid 497183] [client 66.249.66.32:35005] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:11.700767 2026] [security2:error] [pid 496962:tid 497162] [client 40.83.93.50:18094] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.swmpainters.com"] [uri "/1.php"] [unique_id "apPkc46aRhSu8gis9Ll7gQAABPM"]
[Sun Aug 30 03:06:11.700875 2026] [security2:error] [pid 496962:tid 497162] [client 40.83.93.50:18094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/1.php"] [unique_id "apPkc46aRhSu8gis9Ll7gQAABPM"]
[Sun Aug 30 03:06:11.702306 2026] [security2:error] [pid 496962:tid 497104] [client 20.220.204.93:62290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/mini.php"] [unique_id "apPkc46aRhSu8gis9Ll7gwAABLk"]
[Sun Aug 30 03:06:11.702828 2026] [security2:error] [pid 496962:tid 497202] [client 4.205.62.107:22543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/lm15.php"] [unique_id "apPkc46aRhSu8gis9Ll7hAAABRs"]
[Sun Aug 30 03:06:11.704530 2026] [security2:error] [pid 496962:tid 497121] [client 68.155.159.216:63942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apPkc46aRhSu8gis9Ll7hQAABMo"]
[Sun Aug 30 03:06:11.723094 2026] [security2:error] [pid 496962:tid 497171] [client 20.220.10.235:24773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/dx.php"] [unique_id "apPkc46aRhSu8gis9Ll7lwAABPw"]
[Sun Aug 30 03:06:11.761494 2026] [authz_core:error] [pid 496962:tid 497167] [client 66.249.66.42:35301] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:11.761980 2026] [authz_core:error] [pid 496962:tid 497167] [client 66.249.66.42:35301] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:11.773845 2026] [security2:error] [pid 495314:tid 495458] [client 4.205.62.107:17824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/nzv.php"] [unique_id "apPkc0mtdPfUFP1akVFpLAAABDY"]
[Sun Aug 30 03:06:11.806995 2026] [security2:error] [pid 495314:tid 495454] [client 4.205.62.107:64022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/edit.php"] [unique_id "apPkc0mtdPfUFP1akVFpPAAABDI"]
[Sun Aug 30 03:06:11.810365 2026] [security2:error] [pid 496962:tid 497112] [client 20.104.50.220:61485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/tai.php"] [unique_id "apPkc46aRhSu8gis9Ll7wwAABME"]
[Sun Aug 30 03:06:11.815512 2026] [authz_core:error] [pid 496962:tid 497107] [client 216.73.216.128:57093] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:11.815974 2026] [authz_core:error] [pid 496962:tid 497107] [client 216.73.216.128:57093] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:11.826190 2026] [security2:error] [pid 496962:tid 497150] [client 20.48.251.3:65509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/txets.php"] [unique_id "apPkc46aRhSu8gis9Ll7yAAABOc"]
[Sun Aug 30 03:06:11.833586 2026] [security2:error] [pid 496962:tid 497172] [client 20.220.204.93:61778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/amp.php"] [unique_id "apPkc46aRhSu8gis9Ll7zQAABP0"]
[Sun Aug 30 03:06:11.837052 2026] [security2:error] [pid 495314:tid 495519] [client 68.155.159.216:54734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-content/packed.php"] [unique_id "apPkc0mtdPfUFP1akVFpUQAABHM"]
[Sun Aug 30 03:06:11.850349 2026] [security2:error] [pid 496962:tid 497121] [client 20.220.10.235:24663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPkc46aRhSu8gis9Ll71AAABMo"]
[Sun Aug 30 03:06:11.874837 2026] [security2:error] [pid 495314:tid 495505] [client 20.104.50.220:32869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/CytoXploit.php"] [unique_id "apPkc0mtdPfUFP1akVFpYAAABGU"]
[Sun Aug 30 03:06:11.885165 2026] [security2:error] [pid 495314:tid 495503] [client 20.104.49.130:53603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/simple.php"] [unique_id "apPkc0mtdPfUFP1akVFpYwAABGM"]
[Sun Aug 30 03:06:11.897300 2026] [security2:error] [pid 495314:tid 495520] [client 20.151.200.44:64593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/motu.php"] [unique_id "apPkc0mtdPfUFP1akVFpagAABHQ"]
[Sun Aug 30 03:06:11.952957 2026] [security2:error] [pid 495314:tid 495523] [client 20.48.251.3:4681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/phpi.php"] [unique_id "apPkc0mtdPfUFP1akVFpgQAABHc"]
[Sun Aug 30 03:06:11.954887 2026] [security2:error] [pid 496962:tid 497152] [client 20.104.18.15:13633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/t3.php"] [unique_id "apPkc46aRhSu8gis9Ll8CQAABOk"]
[Sun Aug 30 03:06:11.957512 2026] [security2:error] [pid 495314:tid 495453] [client 20.104.50.220:52846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/000000.php"] [unique_id "apPkc0mtdPfUFP1akVFphQAABDE"]
[Sun Aug 30 03:06:11.963876 2026] [security2:error] [pid 496962:tid 497214] [client 20.220.204.93:64160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/cc13.php"] [unique_id "apPkc46aRhSu8gis9Ll8EAAABSc"]
[Sun Aug 30 03:06:11.981944 2026] [security2:error] [pid 496962:tid 497180] [client 20.220.10.235:24675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/xda.php"] [unique_id "apPkc46aRhSu8gis9Ll8EwAABQU"]
[Sun Aug 30 03:06:11.984742 2026] [security2:error] [pid 495314:tid 495461] [client 68.155.159.216:62309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/asd.php"] [unique_id "apPkc0mtdPfUFP1akVFpmAAABDk"]
[Sun Aug 30 03:06:11.998838 2026] [security2:error] [pid 495314:tid 495481] [client 20.48.251.3:45885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/g3.php"] [unique_id "apPkc0mtdPfUFP1akVFpoQAABE0"]
[Sun Aug 30 03:06:12.078530 2026] [security2:error] [pid 495314:tid 495534] [client 20.104.18.15:33703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/wnnjpsby.php"] [unique_id "apPkdEmtdPfUFP1akVFp1AAABII"]
[Sun Aug 30 03:06:12.079236 2026] [security2:error] [pid 496962:tid 497155] [client 20.197.61.180:21095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/data.php"] [unique_id "apPkdI6aRhSu8gis9Ll8LwAABOw"]
[Sun Aug 30 03:06:12.092695 2026] [security2:error] [pid 496962:tid 497208] [client 4.205.62.107:35975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/aws_keys.php"] [unique_id "apPkdI6aRhSu8gis9Ll8NgAABSE"]
[Sun Aug 30 03:06:12.100528 2026] [security2:error] [pid 496962:tid 497217] [client 20.220.204.93:64168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/aa.php"] [unique_id "apPkdI6aRhSu8gis9Ll8OAAABSo"]
[Sun Aug 30 03:06:12.122766 2026] [security2:error] [pid 495314:tid 495556] [client 20.220.10.235:24802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/wp-admin/js/index.php"] [unique_id "apPkdEmtdPfUFP1akVFp5wAABJg"]
[Sun Aug 30 03:06:12.147180 2026] [authz_core:error] [pid 496962:tid 497214] [client 66.249.66.71:58892] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:12.147449 2026] [authz_core:error] [pid 496962:tid 497214] [client 66.249.66.71:58892] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:12.165422 2026] [security2:error] [pid 496962:tid 497219] [client 20.104.18.15:43266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/run.php"] [unique_id "apPkdI6aRhSu8gis9Ll8SwAABSw"]
[Sun Aug 30 03:06:12.172141 2026] [security2:error] [pid 495314:tid 495567] [client 20.104.50.220:27421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/connection.php"] [unique_id "apPkdEmtdPfUFP1akVFp-gAABKM"]
[Sun Aug 30 03:06:12.176869 2026] [security2:error] [pid 496962:tid 497128] [client 20.151.200.44:64039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/wefile.php"] [unique_id "apPkdI6aRhSu8gis9Ll8UAAABNE"]
[Sun Aug 30 03:06:12.180849 2026] [authz_core:error] [pid 496962:tid 497198] [client 216.73.216.128:59380] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:12.181294 2026] [authz_core:error] [pid 496962:tid 497198] [client 216.73.216.128:59380] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:12.190094 2026] [security2:error] [pid 496962:tid 497210] [client 68.155.159.216:12417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apPkdI6aRhSu8gis9Ll8WQAABSM"]
[Sun Aug 30 03:06:12.235224 2026] [security2:error] [pid 496962:tid 497202] [client 20.220.204.93:64195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/s1.php"] [unique_id "apPkdI6aRhSu8gis9Ll8agAABRs"]
[Sun Aug 30 03:06:12.249906 2026] [security2:error] [pid 496962:tid 497200] [client 20.104.50.220:42458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/css.php"] [unique_id "apPkdI6aRhSu8gis9Ll8eAAABRk"]
[Sun Aug 30 03:06:12.250293 2026] [security2:error] [pid 496962:tid 497165] [client 20.220.10.235:24648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/t00l.php"] [unique_id "apPkdI6aRhSu8gis9Ll8eQAABPY"]
[Sun Aug 30 03:06:12.286721 2026] [security2:error] [pid 495314:tid 495505] [client 4.205.62.107:63603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/server_info.php"] [unique_id "apPkdEmtdPfUFP1akVFqJQAABGU"]
[Sun Aug 30 03:06:12.307122 2026] [security2:error] [pid 496962:tid 497218] [client 20.104.50.220:46205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/kepo.php"] [unique_id "apPkdI6aRhSu8gis9Ll8nQAABSs"]
[Sun Aug 30 03:06:12.368780 2026] [security2:error] [pid 496962:tid 497101] [client 20.220.204.93:64198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/0byte.php"] [unique_id "apPkdI6aRhSu8gis9Ll8xgAABLY"]
[Sun Aug 30 03:06:12.383438 2026] [security2:error] [pid 496962:tid 497176] [client 68.155.159.216:59940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/goat1.php"] [unique_id "apPkdI6aRhSu8gis9Ll81QAABQE"]
[Sun Aug 30 03:06:12.383995 2026] [security2:error] [pid 496962:tid 497192] [client 20.220.10.235:24783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/ls.php"] [unique_id "apPkdI6aRhSu8gis9Ll81wAABRE"]
[Sun Aug 30 03:06:12.405954 2026] [security2:error] [pid 496962:tid 497143] [client 20.151.200.44:64594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/Contrller.php"] [unique_id "apPkdI6aRhSu8gis9Ll84wAABOA"]
[Sun Aug 30 03:06:12.411221 2026] [security2:error] [pid 496962:tid 497165] [client 4.205.62.107:26752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/server_info.php"] [unique_id "apPkdI6aRhSu8gis9Ll85wAABPY"]
[Sun Aug 30 03:06:12.429228 2026] [authz_core:error] [pid 496962:tid 497131] [client 66.249.66.34:59236] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:12.429715 2026] [authz_core:error] [pid 496962:tid 497131] [client 66.249.66.34:59236] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:12.441733 2026] [security2:error] [pid 496962:tid 497186] [client 4.205.62.107:31722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/public/rip.php.php"] [unique_id "apPkdI6aRhSu8gis9Ll8-QAABQs"]
[Sun Aug 30 03:06:12.481061 2026] [security2:error] [pid 495314:tid 495505] [client 4.205.62.107:58066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/fun.php"] [unique_id "apPkdEmtdPfUFP1akVFqawAABGU"]
[Sun Aug 30 03:06:12.510461 2026] [security2:error] [pid 496962:tid 497156] [client 20.220.204.93:64237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/xr.php"] [unique_id "apPkdI6aRhSu8gis9Ll9FgAABO0"]
[Sun Aug 30 03:06:12.510951 2026] [security2:error] [pid 496962:tid 497138] [client 40.83.93.50:9291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/as.php"] [unique_id "apPkdI6aRhSu8gis9Ll9FwAABNs"]
[Sun Aug 30 03:06:12.511869 2026] [security2:error] [pid 496962:tid 497183] [client 20.220.10.235:24722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/css/000.php"] [unique_id "apPkdI6aRhSu8gis9Ll9GAAABQg"]
[Sun Aug 30 03:06:12.534546 2026] [security2:error] [pid 495314:tid 495541] [client 94.23.61.200:52270] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "94.23.61.200" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPkdEmtdPfUFP1akVFqfgAABIk"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:06:12.534666 2026] [security2:error] [pid 495314:tid 495541] [client 94.23.61.200:52270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPkdEmtdPfUFP1akVFqfgAABIk"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:06:12.537898 2026] [security2:error] [pid 495314:tid 495500] [client 20.104.50.220:31841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/alfatesla.php"] [unique_id "apPkdEmtdPfUFP1akVFqfwAABGA"]
[Sun Aug 30 03:06:12.538802 2026] [security2:error] [pid 496962:tid 497116] [client 20.197.61.180:14724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/dt-the7/css/static-less/plugins/admin.php"] [unique_id "apPkdI6aRhSu8gis9Ll9KwAABMU"]
[Sun Aug 30 03:06:12.550317 2026] [security2:error] [pid 495314:tid 495555] [client 20.48.251.3:7416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/params.php"] [unique_id "apPkdEmtdPfUFP1akVFqgwAABJc"]
[Sun Aug 30 03:06:12.597215 2026] [security2:error] [pid 495314:tid 495482] [client 20.104.50.220:5897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/info.php"] [unique_id "apPkdEmtdPfUFP1akVFqlgAABE4"]
[Sun Aug 30 03:06:12.598897 2026] [authz_core:error] [pid 496962:tid 497138] [client 66.249.66.45:44832] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:12.599371 2026] [authz_core:error] [pid 496962:tid 497138] [client 66.249.66.45:44832] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:12.606123 2026] [security2:error] [pid 496962:tid 497095] [client 4.205.62.107:51747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/cloud.php"] [unique_id "apPkdI6aRhSu8gis9Ll9SwAABLA"]
[Sun Aug 30 03:06:12.621045 2026] [security2:error] [pid 496962:tid 497101] [client 20.48.251.3:23334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/classsmtps.php"] [unique_id "apPkdI6aRhSu8gis9Ll9VgAABLY"]
[Sun Aug 30 03:06:12.634915 2026] [authz_core:error] [pid 496962:tid 497194] [client 66.249.66.38:65465] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:12.635198 2026] [authz_core:error] [pid 496962:tid 497194] [client 66.249.66.38:65465] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:12.639762 2026] [security2:error] [pid 496962:tid 497146] [client 20.220.10.235:24809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/cy.php"] [unique_id "apPkdI6aRhSu8gis9Ll9ZAAABOM"]
[Sun Aug 30 03:06:12.652015 2026] [security2:error] [pid 496962:tid 497196] [client 4.205.62.107:2785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/update.php"] [unique_id "apPkdI6aRhSu8gis9Ll9bQAABRU"]
[Sun Aug 30 03:06:12.652415 2026] [security2:error] [pid 495314:tid 495542] [client 20.220.204.93:61739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/h02ugyh.php"] [unique_id "apPkdEmtdPfUFP1akVFqrgAABIo"]
[Sun Aug 30 03:06:12.658326 2026] [security2:error] [pid 495314:tid 495505] [client 34.34.225.205:39953] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/"] [unique_id "apPkdEmtdPfUFP1akVFqsQAABGU"]
[Sun Aug 30 03:06:12.666708 2026] [security2:error] [pid 495314:tid 495568] [client 20.48.251.3:55485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/doc.php"] [unique_id "apPkdEmtdPfUFP1akVFquwAABKQ"]
[Sun Aug 30 03:06:12.731479 2026] [security2:error] [pid 495314:tid 495485] [client 20.151.200.44:64631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/file66.php"] [unique_id "apPkdEmtdPfUFP1akVFqzAAABFE"]
[Sun Aug 30 03:06:12.752406 2026] [security2:error] [pid 495314:tid 495521] [client 4.205.62.107:4576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/packed.php"] [unique_id "apPkdEmtdPfUFP1akVFq1wAABHU"]
[Sun Aug 30 03:06:12.763501 2026] [security2:error] [pid 495314:tid 495477] [client 20.104.50.220:64451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/Q2-.php"] [unique_id "apPkdEmtdPfUFP1akVFq3wAABEk"]
[Sun Aug 30 03:06:12.765271 2026] [security2:error] [pid 495314:tid 495469] [client 34.34.225.205:39953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.225.34.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "192.254.186.130"] [uri "/index.php"] [unique_id "apPkdEmtdPfUFP1akVFq2QAABEE"]
[Sun Aug 30 03:06:12.778467 2026] [security2:error] [pid 496962:tid 497201] [client 20.220.10.235:24657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/admin.php/pindex.php"] [unique_id "apPkdI6aRhSu8gis9Ll9nwAABRo"]
[Sun Aug 30 03:06:12.809400 2026] [security2:error] [pid 495314:tid 495508] [client 20.48.251.3:55710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/umgebung.php"] [unique_id "apPkdEmtdPfUFP1akVFq8gAABGg"]
[Sun Aug 30 03:06:12.827500 2026] [authz_core:error] [pid 496962:tid 497212] [client 216.73.216.128:36424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:12.827902 2026] [authz_core:error] [pid 496962:tid 497212] [client 216.73.216.128:36424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:12.847528 2026] [security2:error] [pid 495314:tid 495476] [client 20.220.204.93:64217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/xxw.php"] [unique_id "apPkdEmtdPfUFP1akVFrDAAABEg"]
[Sun Aug 30 03:06:12.858296 2026] [security2:error] [pid 496962:tid 497115] [client 4.205.62.107:22591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/test.config.php"] [unique_id "apPkdI6aRhSu8gis9Ll9tAAABMQ"]
[Sun Aug 30 03:06:12.878126 2026] [security2:error] [pid 496962:tid 497116] [client 68.155.159.216:56325] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.orbainsurance.com"] [uri "/1.php"] [unique_id "apPkdI6aRhSu8gis9Ll9vAAABMU"]
[Sun Aug 30 03:06:12.878215 2026] [security2:error] [pid 496962:tid 497116] [client 68.155.159.216:56325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/1.php"] [unique_id "apPkdI6aRhSu8gis9Ll9vAAABMU"]
[Sun Aug 30 03:06:12.882300 2026] [security2:error] [pid 496962:tid 497108] [client 158.23.184.117:7874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "apPkdI6aRhSu8gis9Ll9wwAABL0"]
[Sun Aug 30 03:06:12.910535 2026] [security2:error] [pid 495314:tid 495545] [client 20.220.10.235:24785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/admin.php/csv.php"] [unique_id "apPkdEmtdPfUFP1akVFrLgAABI0"]
[Sun Aug 30 03:06:12.913124 2026] [security2:error] [pid 496962:tid 497148] [client 4.205.62.107:18983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/66.php"] [unique_id "apPkdI6aRhSu8gis9Ll9zQAABOU"]
[Sun Aug 30 03:06:12.923700 2026] [security2:error] [pid 496962:tid 497187] [client 4.205.62.107:32027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/environment.php"] [unique_id "apPkdI6aRhSu8gis9Ll9zgAABQw"]
[Sun Aug 30 03:06:12.935870 2026] [security2:error] [pid 495314:tid 495484] [client 158.23.184.117:54513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/light.php"] [unique_id "apPkdEmtdPfUFP1akVFrOQAABFA"]
[Sun Aug 30 03:06:12.944588 2026] [security2:error] [pid 495314:tid 495467] [client 4.205.62.107:64026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/8.php"] [unique_id "apPkdEmtdPfUFP1akVFrPQAABD8"]
[Sun Aug 30 03:06:12.958048 2026] [security2:error] [pid 496962:tid 497124] [client 68.155.159.216:61359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apPkdI6aRhSu8gis9Ll92QAABM0"]
[Sun Aug 30 03:06:12.964658 2026] [security2:error] [pid 496962:tid 497132] [client 20.48.251.3:65508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/time.php"] [unique_id "apPkdI6aRhSu8gis9Ll93QAABNU"]
[Sun Aug 30 03:06:12.965224 2026] [security2:error] [pid 496962:tid 497198] [client 34.34.225.205:10933] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/index.html"] [unique_id "apPkdI6aRhSu8gis9Ll93AAABRc"]
[Sun Aug 30 03:06:12.966981 2026] [security2:error] [pid 496962:tid 497135] [client 68.155.159.216:54740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-l0gin.php"] [unique_id "apPkdI6aRhSu8gis9Ll93gAABNg"]
[Sun Aug 30 03:06:12.974009 2026] [security2:error] [pid 496962:tid 497169] [client 20.104.50.220:61469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/www.php"] [unique_id "apPkdI6aRhSu8gis9Ll94QAABPo"]
[Sun Aug 30 03:06:12.978397 2026] [security2:error] [pid 496962:tid 497151] [client 20.220.204.93:62288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/bolt.php"] [unique_id "apPkdI6aRhSu8gis9Ll94gAABOg"]
[Sun Aug 30 03:06:13.023617 2026] [security2:error] [pid 496962:tid 497101] [client 40.83.93.50:8754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/credits.php"] [unique_id "apPkdY6aRhSu8gis9Ll9-QAABLY"]
[Sun Aug 30 03:06:13.026006 2026] [security2:error] [pid 495314:tid 495506] [client 20.104.50.220:32962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/ccc.php"] [unique_id "apPkdUmtdPfUFP1akVFraAAABGY"]
[Sun Aug 30 03:06:13.043177 2026] [security2:error] [pid 495314:tid 495450] [client 20.220.10.235:24643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/admin.php/700.php"] [unique_id "apPkdUmtdPfUFP1akVFrcwAABC4"]
[Sun Aug 30 03:06:13.054361 2026] [security2:error] [pid 495314:tid 495484] [client 20.151.200.44:64703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/blnux.php"] [unique_id "apPkdUmtdPfUFP1akVFreQAABFA"]
[Sun Aug 30 03:06:13.076534 2026] [security2:error] [pid 496962:tid 497109] [client 158.23.184.117:54465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/wp-admin/css/about.php7"] [unique_id "apPkdY6aRhSu8gis9Ll-DAAABL4"]
[Sun Aug 30 03:06:13.095042 2026] [security2:error] [pid 496962:tid 497102] [client 20.104.50.220:28672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/mosok.php"] [unique_id "apPkdY6aRhSu8gis9Ll-GAAABLc"]
[Sun Aug 30 03:06:13.100415 2026] [authz_core:error] [pid 495314:tid 495544] [client 216.73.216.128:38709] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:13.100861 2026] [authz_core:error] [pid 495314:tid 495544] [client 216.73.216.128:38709] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:13.110078 2026] [security2:error] [pid 495314:tid 495444] [client 20.220.204.93:64134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/rtx.php"] [unique_id "apPkdUmtdPfUFP1akVFrjgAABCg"]
[Sun Aug 30 03:06:13.110078 2026] [security2:error] [pid 495314:tid 495563] [client 20.104.18.15:13679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/wp.php"] [unique_id "apPkdUmtdPfUFP1akVFrjwAABJ8"]
[Sun Aug 30 03:06:13.153121 2026] [authz_core:error] [pid 495314:tid 495455] [client 66.249.66.193:59512] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:13.153568 2026] [authz_core:error] [pid 495314:tid 495455] [client 66.249.66.193:59512] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:13.173468 2026] [security2:error] [pid 496962:tid 497144] [client 20.220.10.235:24583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/admin.php/007x.php"] [unique_id "apPkdY6aRhSu8gis9Ll-KQAABOE"]
[Sun Aug 30 03:06:13.184413 2026] [security2:error] [pid 495314:tid 495517] [client 20.48.251.3:4719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "apPkdUmtdPfUFP1akVFruAAABHE"]
[Sun Aug 30 03:06:13.187435 2026] [security2:error] [pid 496962:tid 497155] [client 34.34.225.205:26177] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/app/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-LQAABOw"]
[Sun Aug 30 03:06:13.188347 2026] [security2:error] [pid 495314:tid 495516] [client 34.34.225.205:47893] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/api/.git/config"] [unique_id "apPkdUmtdPfUFP1akVFrugAABHA"]
[Sun Aug 30 03:06:13.191002 2026] [security2:error] [pid 496962:tid 497197] [client 34.34.225.205:14100] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/src/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-MQAABRY"]
[Sun Aug 30 03:06:13.191759 2026] [security2:error] [pid 496962:tid 497117] [client 34.34.225.205:39227] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/laravel/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-NAAABMY"]
[Sun Aug 30 03:06:13.191861 2026] [security2:error] [pid 496962:tid 497101] [client 34.34.225.205:11358] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/application/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-NgAABLY"]
[Sun Aug 30 03:06:13.191898 2026] [security2:error] [pid 496962:tid 497100] [client 34.34.225.205:46124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/config/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-MgAABLU"]
[Sun Aug 30 03:06:13.192604 2026] [security2:error] [pid 496962:tid 497148] [client 34.34.225.205:18459] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/mojo/core/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-NQAABOU"]
[Sun Aug 30 03:06:13.192605 2026] [security2:error] [pid 496962:tid 497107] [client 34.34.225.205:47224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/src/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-OAAABLw"]
[Sun Aug 30 03:06:13.193478 2026] [security2:error] [pid 496962:tid 497100] [client 34.34.225.205:58351] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/wordpress/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-PQAABLU"]
[Sun Aug 30 03:06:13.194538 2026] [security2:error] [pid 496962:tid 497186] [client 34.34.225.205:30999] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/wordpress/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-OgAABQs"]
[Sun Aug 30 03:06:13.194600 2026] [security2:error] [pid 496962:tid 497110] [client 34.34.225.205:10034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/backend/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-PAAABL8"]
[Sun Aug 30 03:06:13.194839 2026] [security2:error] [pid 496962:tid 497092] [client 34.34.225.205:56391] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/config/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-PgAABK0"]
[Sun Aug 30 03:06:13.196014 2026] [security2:error] [pid 496962:tid 497190] [client 34.34.225.205:49125] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-OwAABQ8"]
[Sun Aug 30 03:06:13.196125 2026] [security2:error] [pid 496962:tid 497210] [client 34.34.225.205:18303] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-PwAABSM"]
[Sun Aug 30 03:06:13.196349 2026] [security2:error] [pid 495314:tid 495383] [remote 152.53.108.193:56546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.108.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "flashflooring.co.uk"] [uri "/wp-login.php"] [unique_id "apPkdUmtdPfUFP1akVFrvAAER0Q"]
[Sun Aug 30 03:06:13.196697 2026] [security2:error] [pid 496962:tid 497194] [client 34.34.225.205:15123] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/server/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-QAAABRM"]
[Sun Aug 30 03:06:13.196900 2026] [security2:error] [pid 496962:tid 497104] [client 34.34.225.205:23945] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/application/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-QQAABLk"]
[Sun Aug 30 03:06:13.197227 2026] [security2:error] [pid 496962:tid 497165] [client 34.34.225.205:18439] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/internal/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-QgAABPY"]
[Sun Aug 30 03:06:13.199823 2026] [security2:error] [pid 496962:tid 497174] [client 34.34.225.205:41714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/site/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-RAAABP8"]
[Sun Aug 30 03:06:13.200090 2026] [security2:error] [pid 496962:tid 497124] [client 34.34.225.205:46119] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/cms/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-QwAABM0"]
[Sun Aug 30 03:06:13.200939 2026] [security2:error] [pid 496962:tid 497094] [client 34.34.225.205:44620] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/public/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-RgAABK8"]
[Sun Aug 30 03:06:13.201444 2026] [security2:error] [pid 496962:tid 497093] [client 34.34.225.205:51241] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/mojo/core/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-RwAABK4"]
[Sun Aug 30 03:06:13.201451 2026] [security2:error] [pid 496962:tid 497109] [client 34.34.225.205:57735] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/server/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-RQAABL4"]
[Sun Aug 30 03:06:13.202280 2026] [security2:error] [pid 496962:tid 497193] [client 34.34.225.205:53582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/wp-content/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-SgAABRI"]
[Sun Aug 30 03:06:13.202376 2026] [security2:error] [pid 496962:tid 497130] [client 34.34.225.205:61485] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/web/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-SAAABNM"]
[Sun Aug 30 03:06:13.205505 2026] [security2:error] [pid 496962:tid 497201] [client 34.34.225.205:9531] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/wp-content/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-SwAABRo"]
[Sun Aug 30 03:06:13.205929 2026] [security2:error] [pid 496962:tid 497191] [client 34.34.225.205:38482] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/admin/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-SQAABRA"]
[Sun Aug 30 03:06:13.206337 2026] [security2:error] [pid 496962:tid 497096] [client 34.34.225.205:57240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/app/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-TQAABLE"]
[Sun Aug 30 03:06:13.208683 2026] [security2:error] [pid 496962:tid 497218] [client 34.34.225.205:5069] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/vendor/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-UQAABSs"]
[Sun Aug 30 03:06:13.209598 2026] [security2:error] [pid 496962:tid 497196] [client 34.34.225.205:14065] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/api/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-VQAABRU"]
[Sun Aug 30 03:06:13.209785 2026] [security2:error] [pid 496962:tid 497173] [client 34.34.225.205:31881] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/web/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-VwAABP4"]
[Sun Aug 30 03:06:13.209864 2026] [security2:error] [pid 496962:tid 497160] [client 34.34.225.205:37281] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/laravel/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-VgAABPE"]
[Sun Aug 30 03:06:13.211036 2026] [security2:error] [pid 496962:tid 497197] [client 34.34.225.205:47404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/public/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-WAAABRY"]
[Sun Aug 30 03:06:13.211548 2026] [security2:error] [pid 496962:tid 497185] [client 34.34.225.205:8888] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/internal/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-WgAABQo"]
[Sun Aug 30 03:06:13.212358 2026] [security2:error] [pid 496962:tid 497181] [client 94.23.61.200:52301] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "94.23.61.200" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPkdY6aRhSu8gis9Ll-XwAABQY"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:06:13.212473 2026] [security2:error] [pid 496962:tid 497181] [client 94.23.61.200:52301] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPkdY6aRhSu8gis9Ll-XwAABQY"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:06:13.212574 2026] [security2:error] [pid 496962:tid 497139] [client 34.34.225.205:9504] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/site/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-WwAABNw"]
[Sun Aug 30 03:06:13.212869 2026] [security2:error] [pid 496962:tid 497209] [client 34.34.225.205:53531] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/vendor/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-XQAABSI"]
[Sun Aug 30 03:06:13.213826 2026] [security2:error] [pid 496962:tid 497095] [client 34.34.225.205:34085] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/cms/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-WQAABLA"]
[Sun Aug 30 03:06:13.214424 2026] [security2:error] [pid 496962:tid 497097] [client 34.34.225.205:33046] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/admin/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-UgAABLI"]
[Sun Aug 30 03:06:13.214908 2026] [security2:error] [pid 496962:tid 497118] [client 34.34.225.205:15985] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/core/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-YAAABMc"]
[Sun Aug 30 03:06:13.215106 2026] [security2:error] [pid 496962:tid 497214] [client 34.34.225.205:18115] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/core/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-YQAABSc"]
[Sun Aug 30 03:06:13.219002 2026] [security2:error] [pid 496962:tid 497207] [client 34.34.225.205:48107] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/backend/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-ZAAABSA"]
[Sun Aug 30 03:06:13.221713 2026] [security2:error] [pid 496962:tid 497143] [client 158.23.184.117:54522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/alf.php"] [unique_id "apPkdY6aRhSu8gis9Ll-aQAABOA"]
[Sun Aug 30 03:06:13.256119 2026] [security2:error] [pid 496962:tid 497158] [client 34.34.225.205:26177] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/storage/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-dQAABO8"]
[Sun Aug 30 03:06:13.257031 2026] [security2:error] [pid 496962:tid 497100] [client 34.34.225.205:30999] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/resources/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-eQAABLU"]
[Sun Aug 30 03:06:13.257734 2026] [security2:error] [pid 496962:tid 497121] [client 34.34.225.205:14100] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/assets/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-ewAABMo"]
[Sun Aug 30 03:06:13.258355 2026] [security2:error] [pid 496962:tid 497115] [client 34.34.225.205:61485] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/static/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-fAAABMQ"]
[Sun Aug 30 03:06:13.258683 2026] [security2:error] [pid 496962:tid 497186] [client 34.34.225.205:53582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/static/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-fQAABQs"]
[Sun Aug 30 03:06:13.259207 2026] [security2:error] [pid 496962:tid 497170] [client 34.34.225.205:46124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/assets/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-fgAABPs"]
[Sun Aug 30 03:06:13.259567 2026] [security2:error] [pid 496962:tid 497110] [client 34.34.225.205:18459] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/resources/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-gAAABL8"]
[Sun Aug 30 03:06:13.259681 2026] [security2:error] [pid 496962:tid 497183] [client 34.34.225.205:39227] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/storage/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-fwAABQg"]
[Sun Aug 30 03:06:13.260970 2026] [security2:error] [pid 496962:tid 497092] [client 20.220.204.93:62281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/ckk.php"] [unique_id "apPkdY6aRhSu8gis9Ll-gQAABK0"]
[Sun Aug 30 03:06:13.261706 2026] [security2:error] [pid 496962:tid 497104] [client 34.34.225.205:41714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/common/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-ggAABLk"]
[Sun Aug 30 03:06:13.262129 2026] [security2:error] [pid 496962:tid 497194] [client 34.34.225.205:57735] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/shared/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-gwAABRM"]
[Sun Aug 30 03:06:13.262505 2026] [security2:error] [pid 496962:tid 497094] [client 34.34.225.205:11358] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/uploads/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-hgAABK8"]
[Sun Aug 30 03:06:13.262725 2026] [security2:error] [pid 496962:tid 497093] [client 34.34.225.205:23945] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/uploads/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-hwAABK4"]
[Sun Aug 30 03:06:13.262974 2026] [security2:error] [pid 496962:tid 497126] [client 34.34.225.205:10034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/shared/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-iAAABM8"]
[Sun Aug 30 03:06:13.262987 2026] [security2:error] [pid 496962:tid 497124] [client 34.34.225.205:46119] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/lib/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-hQAABM0"]
[Sun Aug 30 03:06:13.263053 2026] [security2:error] [pid 495314:tid 495532] [client 20.104.18.15:33759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/gigi.php"] [unique_id "apPkdUmtdPfUFP1akVFr3gAABIA"]
[Sun Aug 30 03:06:13.263529 2026] [security2:error] [pid 495314:tid 495505] [client 34.34.225.205:47893] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/common/.git/config"] [unique_id "apPkdUmtdPfUFP1akVFr3QAABGU"]
[Sun Aug 30 03:06:13.263986 2026] [security2:error] [pid 496962:tid 497194] [client 34.34.225.205:18439] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/lib/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-iQAABRM"]
[Sun Aug 30 03:06:13.264652 2026] [security2:error] [pid 496962:tid 497096] [client 34.34.225.205:56391] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/include/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-iwAABLE"]
[Sun Aug 30 03:06:13.264972 2026] [security2:error] [pid 496962:tid 497179] [client 34.34.225.205:51241] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/htdocs/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-jAAABQQ"]
[Sun Aug 30 03:06:13.265421 2026] [security2:error] [pid 496962:tid 497211] [client 34.34.225.205:44620] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/html/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-jQAABSQ"]
[Sun Aug 30 03:06:13.265750 2026] [security2:error] [pid 496962:tid 497096] [client 34.34.225.205:49125] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/www/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-kQAABLE"]
[Sun Aug 30 03:06:13.265809 2026] [security2:error] [pid 496962:tid 497218] [client 34.34.225.205:18303] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/include/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-jgAABSs"]
[Sun Aug 30 03:06:13.266053 2026] [security2:error] [pid 496962:tid 497173] [client 34.34.225.205:47224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/www/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-kAAABP4"]
[Sun Aug 30 03:06:13.266131 2026] [security2:error] [pid 496962:tid 497181] [client 34.34.225.205:58351] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/html/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-lAAABQY"]
[Sun Aug 30 03:06:13.266720 2026] [security2:error] [pid 496962:tid 497179] [client 34.34.225.205:9531] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/webroot/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-kwAABQQ"]
[Sun Aug 30 03:06:13.266723 2026] [security2:error] [pid 496962:tid 497151] [client 34.34.225.205:38482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/webapp/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-lQAABOg"]
[Sun Aug 30 03:06:13.266854 2026] [security2:error] [pid 496962:tid 497196] [client 34.34.225.205:57240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/webroot/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-kgAABRU"]
[Sun Aug 30 03:06:13.267041 2026] [security2:error] [pid 496962:tid 497218] [client 34.34.225.205:31881] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/seed/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-lgAABSs"]
[Sun Aug 30 03:06:13.267687 2026] [security2:error] [pid 496962:tid 497176] [client 34.34.225.205:53531] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/database/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-lwAABQE"]
[Sun Aug 30 03:06:13.267844 2026] [security2:error] [pid 496962:tid 497114] [client 34.34.225.205:15123] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/htdocs/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-jwAABMM"]
[Sun Aug 30 03:06:13.268763 2026] [security2:error] [pid 496962:tid 497151] [client 34.34.225.205:14065] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/project/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-mAAABOg"]
[Sun Aug 30 03:06:13.268916 2026] [security2:error] [pid 496962:tid 497213] [client 34.34.225.205:5069] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/project/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-mgAABSY"]
[Sun Aug 30 03:06:13.268969 2026] [security2:error] [pid 496962:tid 497175] [client 34.34.225.205:18115] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/db/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-oAAABQA"]
[Sun Aug 30 03:06:13.269009 2026] [security2:error] [pid 496962:tid 497167] [client 20.197.61.180:14053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/hideo/network.php"] [unique_id "apPkdY6aRhSu8gis9Ll-oQAABPg"]
[Sun Aug 30 03:06:13.269181 2026] [security2:error] [pid 496962:tid 497174] [client 34.34.225.205:33046] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/database/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-ngAABP8"]
[Sun Aug 30 03:06:13.269462 2026] [security2:error] [pid 496962:tid 497134] [client 34.34.225.205:9504] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/seed/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-nAAABNc"]
[Sun Aug 30 03:06:13.269694 2026] [security2:error] [pid 496962:tid 497218] [client 34.34.225.205:8888] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/data/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-nQAABSs"]
[Sun Aug 30 03:06:13.269931 2026] [security2:error] [pid 496962:tid 497188] [client 34.34.225.205:47404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/data/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-mwAABQ0"]
[Sun Aug 30 03:06:13.271190 2026] [security2:error] [pid 496962:tid 497095] [client 34.34.225.205:37281] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/webapp/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-mQAABLA"]
[Sun Aug 30 03:06:13.271197 2026] [security2:error] [pid 496962:tid 497097] [client 34.34.225.205:48107] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/env/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-owAABLI"]
[Sun Aug 30 03:06:13.271685 2026] [security2:error] [pid 496962:tid 497108] [client 34.34.225.205:34085] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/env/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-pAAABL0"]
[Sun Aug 30 03:06:13.271886 2026] [security2:error] [pid 496962:tid 497129] [client 34.34.225.205:15985] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/db/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-pQAABNI"]
[Sun Aug 30 03:06:13.304063 2026] [security2:error] [pid 496962:tid 497203] [client 20.220.10.235:24679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/admin.php/heex.php"] [unique_id "apPkdY6aRhSu8gis9Ll-uAAABRw"]
[Sun Aug 30 03:06:13.309722 2026] [security2:error] [pid 496962:tid 497186] [client 20.104.50.220:27531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/I18N/Arabic.php"] [unique_id "apPkdY6aRhSu8gis9Ll-ugAABQs"]
[Sun Aug 30 03:06:13.314184 2026] [security2:error] [pid 495314:tid 495467] [client 20.104.18.15:43911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/new.php"] [unique_id "apPkdUmtdPfUFP1akVFr-AAABD8"]
[Sun Aug 30 03:06:13.329370 2026] [security2:error] [pid 495314:tid 495542] [client 68.155.159.216:12312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apPkdUmtdPfUFP1akVFsAwAABIo"]
[Sun Aug 30 03:06:13.360379 2026] [security2:error] [pid 496962:tid 497181] [client 34.34.225.205:14100] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/setup/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-yAAABQY"]
[Sun Aug 30 03:06:13.360971 2026] [security2:error] [pid 496962:tid 497214] [client 34.34.225.205:61485] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/release/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-ywAABSc"]
[Sun Aug 30 03:06:13.361352 2026] [security2:error] [pid 496962:tid 497114] [client 34.34.225.205:30999] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/deploy/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-zQAABMM"]
[Sun Aug 30 03:06:13.361881 2026] [security2:error] [pid 496962:tid 497096] [client 34.34.225.205:26177] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/install/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-xwAABLE"]
[Sun Aug 30 03:06:13.361939 2026] [security2:error] [pid 496962:tid 497214] [client 34.34.225.205:41714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/dist/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-0gAABSc"]
[Sun Aug 30 03:06:13.361960 2026] [security2:error] [pid 495314:tid 495505] [client 34.34.225.205:47893] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/temp/.git/config"] [unique_id "apPkdUmtdPfUFP1akVFsHAAABGU"]
[Sun Aug 30 03:06:13.362208 2026] [security2:error] [pid 496962:tid 497175] [client 34.34.225.205:46119] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/build/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-1AAABQA"]
[Sun Aug 30 03:06:13.362419 2026] [security2:error] [pid 496962:tid 497118] [client 34.34.225.205:51241] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/cache/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-1QAABMc"]
[Sun Aug 30 03:06:13.362520 2026] [security2:error] [pid 496962:tid 497114] [client 34.34.225.205:44620] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/logs/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-1gAABMM"]
[Sun Aug 30 03:06:13.362958 2026] [security2:error] [pid 496962:tid 497213] [client 34.34.225.205:39227] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/deploy/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-0AAABSY"]
[Sun Aug 30 03:06:13.363316 2026] [security2:error] [pid 496962:tid 497129] [client 34.34.225.205:10034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/tmp/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-3QAABNI"]
[Sun Aug 30 03:06:13.363321 2026] [security2:error] [pid 496962:tid 497116] [client 34.34.225.205:18303] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/cache/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-3wAABMU"]
[Sun Aug 30 03:06:13.363440 2026] [security2:error] [pid 496962:tid 497126] [client 34.34.225.205:46124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/release/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-0wAABM8"]
[Sun Aug 30 03:06:13.363464 2026] [security2:error] [pid 496962:tid 497218] [client 34.34.225.205:56391] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/log/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-1wAABSs"]
[Sun Aug 30 03:06:13.363544 2026] [security2:error] [pid 496962:tid 497097] [client 34.34.225.205:23945] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/tmp/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-2gAABLI"]
[Sun Aug 30 03:06:13.363655 2026] [security2:error] [pid 496962:tid 497197] [client 34.34.225.205:53582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/setup/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-ygAABRY"]
[Sun Aug 30 03:06:13.363704 2026] [security2:error] [pid 496962:tid 497177] [client 34.34.225.205:18439] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/temp/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-2wAABQI"]
[Sun Aug 30 03:06:13.363784 2026] [security2:error] [pid 496962:tid 497188] [client 34.34.225.205:47224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/logs/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-4QAABQ0"]
[Sun Aug 30 03:06:13.363816 2026] [security2:error] [pid 496962:tid 497143] [client 34.34.225.205:31881] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/tools/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-4wAABOA"]
[Sun Aug 30 03:06:13.363867 2026] [security2:error] [pid 496962:tid 497106] [client 34.34.225.205:38482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/helpers/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-5AAABLs"]
[Sun Aug 30 03:06:13.363926 2026] [security2:error] [pid 496962:tid 497134] [client 34.34.225.205:57240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/log/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-2AAABNc"]
[Sun Aug 30 03:06:13.363998 2026] [security2:error] [pid 496962:tid 497119] [client 34.34.225.205:58351] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/scripts/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-4AAABMg"]
[Sun Aug 30 03:06:13.364088 2026] [security2:error] [pid 496962:tid 497167] [client 34.34.225.205:57735] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/dist/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-0QAABPg"]
[Sun Aug 30 03:06:13.364098 2026] [security2:error] [pid 496962:tid 497213] [client 34.34.225.205:53531] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/utils/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-5QAABSY"]
[Sun Aug 30 03:06:13.364376 2026] [security2:error] [pid 496962:tid 497147] [client 34.34.225.205:9531] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/tools/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-5gAABOQ"]
[Sun Aug 30 03:06:13.364392 2026] [security2:error] [pid 496962:tid 497108] [client 34.34.225.205:49125] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/scripts/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-3gAABL0"]
[Sun Aug 30 03:06:13.365050 2026] [security2:error] [pid 496962:tid 497180] [client 34.34.225.205:14065] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/services/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-6AAABQU"]
[Sun Aug 30 03:06:13.365238 2026] [security2:error] [pid 496962:tid 497156] [client 34.34.225.205:18115] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/packages/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-6QAABO0"]
[Sun Aug 30 03:06:13.365292 2026] [security2:error] [pid 496962:tid 497204] [client 34.34.225.205:15123] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/modules/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-7QAABR0"]
[Sun Aug 30 03:06:13.365358 2026] [security2:error] [pid 496962:tid 497167] [client 34.34.225.205:34085] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/components/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-7gAABPg"]
[Sun Aug 30 03:06:13.365373 2026] [security2:error] [pid 496962:tid 497103] [client 34.34.225.205:33046] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/utils/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-6gAABLg"]
[Sun Aug 30 03:06:13.365442 2026] [security2:error] [pid 496962:tid 497155] [client 34.34.225.205:11358] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/build/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-3AAABOw"]
[Sun Aug 30 03:06:13.365523 2026] [security2:error] [pid 496962:tid 497147] [client 34.34.225.205:5069] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/services/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-7wAABOQ"]
[Sun Aug 30 03:06:13.365540 2026] [security2:error] [pid 496962:tid 497129] [client 34.34.225.205:48107] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/modules/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-5wAABNI"]
[Sun Aug 30 03:06:13.365793 2026] [security2:error] [pid 496962:tid 497213] [client 34.34.225.205:47404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/plugins/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-7AAABSY"]
[Sun Aug 30 03:06:13.366024 2026] [security2:error] [pid 496962:tid 497123] [client 34.34.225.205:15985] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/plugins/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-8gAABMw"]
[Sun Aug 30 03:06:13.366354 2026] [security2:error] [pid 496962:tid 497095] [client 34.34.225.205:8888] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/components/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-9AAABLA"]
[Sun Aug 30 03:06:13.366394 2026] [security2:error] [pid 496962:tid 497108] [client 34.34.225.205:37281] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/packages/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-8AAABL0"]
[Sun Aug 30 03:06:13.367971 2026] [security2:error] [pid 496962:tid 497162] [client 34.34.225.205:9504] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/helpers/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll-8QAABPM"]
[Sun Aug 30 03:06:13.368241 2026] [security2:error] [pid 496962:tid 497181] [client 34.34.225.205:18459] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/install/.env"] [unique_id "apPkdY6aRhSu8gis9Ll-zwAABQY"]
[Sun Aug 30 03:06:13.375108 2026] [authz_core:error] [pid 495314:tid 495527] [client 216.73.216.128:38709] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:13.375550 2026] [authz_core:error] [pid 495314:tid 495527] [client 216.73.216.128:38709] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:13.393090 2026] [security2:error] [pid 496962:tid 497153] [client 20.220.204.93:61781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.greenvillenazarene.org"] [uri "/R57.php"] [unique_id "apPkdY6aRhSu8gis9Ll_CQAABOo"]
[Sun Aug 30 03:06:13.401450 2026] [security2:error] [pid 495314:tid 495521] [client 68.155.159.216:63488] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.bigbuba.it"] [uri "/1.php"] [unique_id "apPkdUmtdPfUFP1akVFsNwAABHU"]
[Sun Aug 30 03:06:13.401560 2026] [security2:error] [pid 495314:tid 495521] [client 68.155.159.216:63488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/1.php"] [unique_id "apPkdUmtdPfUFP1akVFsNwAABHU"]
[Sun Aug 30 03:06:13.404580 2026] [security2:error] [pid 496962:tid 497146] [client 20.104.50.220:42460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/cp.php"] [unique_id "apPkdY6aRhSu8gis9Ll_EAAABOM"]
[Sun Aug 30 03:06:13.427005 2026] [security2:error] [pid 495314:tid 495484] [client 4.205.62.107:63794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/hosty.php"] [unique_id "apPkdUmtdPfUFP1akVFsRAAABFA"]
[Sun Aug 30 03:06:13.439788 2026] [security2:error] [pid 495314:tid 495507] [client 20.220.10.235:24694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/tf.php"] [unique_id "apPkdUmtdPfUFP1akVFsSwAABGc"]
[Sun Aug 30 03:06:13.441929 2026] [security2:error] [pid 496962:tid 497103] [client 20.151.200.44:37802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/t00l.php"] [unique_id "apPkdY6aRhSu8gis9Ll_HAAABLg"]
[Sun Aug 30 03:06:13.449836 2026] [security2:error] [pid 495314:tid 495503] [client 20.151.200.44:47397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPkdUmtdPfUFP1akVFsUQAABGM"]
[Sun Aug 30 03:06:13.456403 2026] [security2:error] [pid 496962:tid 497195] [client 34.34.225.205:14100] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/extensions/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_HgAABRQ"]
[Sun Aug 30 03:06:13.463030 2026] [security2:error] [pid 496962:tid 497123] [client 20.104.50.220:46888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/kk.php"] [unique_id "apPkdY6aRhSu8gis9Ll_IwAABMw"]
[Sun Aug 30 03:06:13.463869 2026] [security2:error] [pid 496962:tid 497162] [client 34.34.225.205:41714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/themes/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_KAAABPM"]
[Sun Aug 30 03:06:13.463869 2026] [security2:error] [pid 496962:tid 497191] [client 34.34.225.205:31881] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/models/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_JwAABRA"]
[Sun Aug 30 03:06:13.464046 2026] [security2:error] [pid 496962:tid 497213] [client 34.34.225.205:53582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/users/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_LgAABSY"]
[Sun Aug 30 03:06:13.464119 2026] [security2:error] [pid 496962:tid 497123] [client 34.34.225.205:38482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/shop/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_LwAABMw"]
[Sun Aug 30 03:06:13.464124 2026] [security2:error] [pid 496962:tid 497160] [client 34.34.225.205:44620] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/themes/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_JgAABPE"]
[Sun Aug 30 03:06:13.464126 2026] [security2:error] [pid 496962:tid 497169] [client 34.34.225.205:57735] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/auth/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_LAAABPo"]
[Sun Aug 30 03:06:13.464125 2026] [security2:error] [pid 496962:tid 497108] [client 34.34.225.205:61485] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/views/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_JQAABL0"]
[Sun Aug 30 03:06:13.464253 2026] [security2:error] [pid 496962:tid 497127] [client 34.34.225.205:53531] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/views/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_KwAABNA"]
[Sun Aug 30 03:06:13.464293 2026] [security2:error] [pid 496962:tid 497102] [client 34.34.225.205:51241] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/models/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_KgAABLc"]
[Sun Aug 30 03:06:13.464474 2026] [security2:error] [pid 496962:tid 497142] [client 34.34.225.205:46119] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/routes/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_KQAABN8"]
[Sun Aug 30 03:06:13.464960 2026] [security2:error] [pid 496962:tid 497094] [client 34.34.225.205:18303] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/templates/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_MQAABK8"]
[Sun Aug 30 03:06:13.464978 2026] [security2:error] [pid 496962:tid 497206] [client 34.34.225.205:11358] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/middleware/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_MwAABR8"]
[Sun Aug 30 03:06:13.465159 2026] [security2:error] [pid 496962:tid 497135] [client 34.34.225.205:30999] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/templates/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_MgAABNg"]
[Sun Aug 30 03:06:13.465186 2026] [security2:error] [pid 496962:tid 497162] [client 34.34.225.205:56391] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/payment/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_NQAABPM"]
[Sun Aug 30 03:06:13.465304 2026] [security2:error] [pid 496962:tid 497181] [client 34.34.225.205:9531] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/shop/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_MAAABQY"]
[Sun Aug 30 03:06:13.466021 2026] [security2:error] [pid 496962:tid 497163] [client 34.34.225.205:18459] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/routes/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_OAAABPQ"]
[Sun Aug 30 03:06:13.466053 2026] [security2:error] [pid 496962:tid 497191] [client 34.34.225.205:39227] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/extensions/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_NAAABRA"]
[Sun Aug 30 03:06:13.466067 2026] [security2:error] [pid 496962:tid 497184] [client 34.34.225.205:10034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/store/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_QAAABQk"]
[Sun Aug 30 03:06:13.466198 2026] [security2:error] [pid 496962:tid 497206] [client 34.34.225.205:37281] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/store/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_PgAABR8"]
[Sun Aug 30 03:06:13.466239 2026] [security2:error] [pid 496962:tid 497121] [client 34.34.225.205:5069] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/checkout/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_QQAABMo"]
[Sun Aug 30 03:06:13.466300 2026] [security2:error] [pid 496962:tid 497181] [client 34.34.225.205:15123] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/checkout/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_QwAABQY"]
[Sun Aug 30 03:06:13.466329 2026] [security2:error] [pid 496962:tid 497107] [client 34.34.225.205:47224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/payment/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_RAAABLw"]
[Sun Aug 30 03:06:13.466395 2026] [security2:error] [pid 496962:tid 497176] [client 34.34.225.205:57240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/product/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_PQAABQE"]
[Sun Aug 30 03:06:13.466495 2026] [security2:error] [pid 496962:tid 497144] [client 34.34.225.205:18439] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/user/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_NgAABOE"]
[Sun Aug 30 03:06:13.466563 2026] [security2:error] [pid 496962:tid 497138] [client 34.34.225.205:49125] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/product/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_RQAABNs"]
[Sun Aug 30 03:06:13.466622 2026] [security2:error] [pid 496962:tid 497162] [client 34.34.225.205:18115] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/cart/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_QgAABPM"]
[Sun Aug 30 03:06:13.466694 2026] [security2:error] [pid 496962:tid 497179] [client 34.34.225.205:46124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/controllers/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_NwAABQQ"]
[Sun Aug 30 03:06:13.466720 2026] [security2:error] [pid 496962:tid 497094] [client 34.34.225.205:23945] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/cart/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_PwAABK8"]
[Sun Aug 30 03:06:13.466812 2026] [security2:error] [pid 496962:tid 497185] [client 34.34.225.205:8888] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/order/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_RgAABQo"]
[Sun Aug 30 03:06:13.466928 2026] [security2:error] [pid 496962:tid 497095] [client 34.34.225.205:26177] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/controllers/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_JAAABLA"]
[Sun Aug 30 03:06:13.467085 2026] [security2:error] [pid 496962:tid 497122] [client 34.34.225.205:15985] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/catalog/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_SAAABMs"]
[Sun Aug 30 03:06:13.467092 2026] [security2:error] [pid 496962:tid 497142] [client 34.34.225.205:9504] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/user/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_OgAABN8"]
[Sun Aug 30 03:06:13.467093 2026] [security2:error] [pid 496962:tid 497151] [client 34.34.225.205:48107] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/users/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_LQAABOg"]
[Sun Aug 30 03:06:13.467113 2026] [security2:error] [pid 496962:tid 497191] [client 34.34.225.205:47404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/catalog/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_SQAABRA"]
[Sun Aug 30 03:06:13.467201 2026] [security2:error] [pid 496962:tid 497203] [client 34.34.225.205:33046] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/account/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_OQAABRw"]
[Sun Aug 30 03:06:13.468788 2026] [security2:error] [pid 496962:tid 497172] [client 34.34.225.205:14065] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/account/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_PAAABP0"]
[Sun Aug 30 03:06:13.468786 2026] [security2:error] [pid 495314:tid 495559] [client 34.34.225.205:47893] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/middleware/.git/config"] [unique_id "apPkdUmtdPfUFP1akVFsVwAABJs"]
[Sun Aug 30 03:06:13.468806 2026] [security2:error] [pid 496962:tid 497170] [client 34.34.225.205:34085] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/auth/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_OwAABPs"]
[Sun Aug 30 03:06:13.469793 2026] [security2:error] [pid 496962:tid 497178] [client 34.34.225.205:58351] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/order/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_RwAABQM"]
[Sun Aug 30 03:06:13.485850 2026] [security2:error] [pid 495314:tid 495515] [client 68.155.159.216:54139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apPkdUmtdPfUFP1akVFsYQAABG8"]
[Sun Aug 30 03:06:13.493718 2026] [authz_core:error] [pid 496962:tid 497153] [client 66.249.66.71:58892] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:13.494144 2026] [authz_core:error] [pid 496962:tid 497153] [client 66.249.66.71:58892] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:13.500743 2026] [security2:error] [pid 496962:tid 497093] [client 20.151.200.44:64688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/attack.php"] [unique_id "apPkdY6aRhSu8gis9Ll_WwAABK4"]
[Sun Aug 30 03:06:13.508794 2026] [security2:error] [pid 496962:tid 497173] [client 34.34.225.205:14100] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/media/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_XwAABP4"]
[Sun Aug 30 03:06:13.515899 2026] [security2:error] [pid 496962:tid 497101] [client 34.34.225.205:53531] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/media/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_ZgAABLY"]
[Sun Aug 30 03:06:13.516004 2026] [security2:error] [pid 496962:tid 497204] [client 34.34.225.205:31881] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/images/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_ZAAABR0"]
[Sun Aug 30 03:06:13.516242 2026] [security2:error] [pid 496962:tid 497103] [client 34.34.225.205:44620] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/images/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_ZQAABLg"]
[Sun Aug 30 03:06:13.530611 2026] [security2:error] [pid 495314:tid 495448] [client 74.7.243.204:48120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/cms/"] [unique_id "apPkdUmtdPfUFP1akVFscwAABCw"], referer: http://mail.letter7brands.com/cms/?p=%2F%2Fetc
[Sun Aug 30 03:06:13.553811 2026] [autoindex:error] [pid 495314:tid 495526] [client 20.63.219.114:9646] AH01276: Cannot serve directory /home1/lehugh/public_html/hbhousevalue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:06:13.554875 2026] [security2:error] [pid 496962:tid 497179] [client 34.34.225.205:11358] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/files/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_cAAABQQ"]
[Sun Aug 30 03:06:13.555730 2026] [security2:error] [pid 496962:tid 497162] [client 34.34.225.205:57735] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/files/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_bwAABPM"]
[Sun Aug 30 03:06:13.556415 2026] [security2:error] [pid 496962:tid 497210] [client 34.34.225.205:53582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/test/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_dQAABSM"]
[Sun Aug 30 03:06:13.556481 2026] [security2:error] [pid 496962:tid 497184] [client 34.34.225.205:38482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/tests/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_dAAABQk"]
[Sun Aug 30 03:06:13.556522 2026] [security2:error] [pid 496962:tid 497094] [client 34.34.225.205:41714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/docs/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_cgAABK8"]
[Sun Aug 30 03:06:13.557082 2026] [security2:error] [pid 496962:tid 497185] [client 34.34.225.205:51241] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/docs/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_cwAABQo"]
[Sun Aug 30 03:06:13.557299 2026] [security2:error] [pid 496962:tid 497095] [client 34.34.225.205:18303] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/documentation/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_dwAABLA"]
[Sun Aug 30 03:06:13.558037 2026] [security2:error] [pid 496962:tid 497162] [client 34.34.225.205:46119] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/documentation/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_dgAABPM"]
[Sun Aug 30 03:06:13.558925 2026] [security2:error] [pid 496962:tid 497122] [client 34.34.225.205:61485] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/tests/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_eQAABMs"]
[Sun Aug 30 03:06:13.559421 2026] [security2:error] [pid 496962:tid 497191] [client 34.34.225.205:56391] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/staging/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_egAABRA"]
[Sun Aug 30 03:06:13.560379 2026] [security2:error] [pid 496962:tid 497203] [client 34.34.225.205:39227] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/prod/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_fQAABRw"]
[Sun Aug 30 03:06:13.560410 2026] [security2:error] [pid 496962:tid 497151] [client 34.34.225.205:18459] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/staging/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_fAAABOg"]
[Sun Aug 30 03:06:13.560693 2026] [security2:error] [pid 496962:tid 497142] [client 34.34.225.205:30999] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/test/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_ewAABN8"]
[Sun Aug 30 03:06:13.560997 2026] [security2:error] [pid 496962:tid 497170] [client 34.34.225.205:57240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/production/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_gAAABPs"]
[Sun Aug 30 03:06:13.561096 2026] [security2:error] [pid 496962:tid 497172] [client 34.34.225.205:9531] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/production/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_fwAABP0"]
[Sun Aug 30 03:06:13.561960 2026] [security2:error] [pid 496962:tid 497178] [client 34.34.225.205:26177] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/secure/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_gQAABQM"]
[Sun Aug 30 03:06:13.562410 2026] [security2:error] [pid 496962:tid 497198] [client 34.34.225.205:37281] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/prod/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_ggAABRc"]
[Sun Aug 30 03:06:13.563981 2026] [security2:error] [pid 496962:tid 497166] [client 34.34.225.205:47404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/private/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_igAABPc"]
[Sun Aug 30 03:06:13.564088 2026] [security2:error] [pid 496962:tid 497129] [client 34.34.225.205:18115] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/development/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_hwAABNI"]
[Sun Aug 30 03:06:13.564108 2026] [security2:error] [pid 496962:tid 497147] [client 34.34.225.205:15123] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/local/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_iQAABOQ"]
[Sun Aug 30 03:06:13.564112 2026] [security2:error] [pid 496962:tid 497118] [client 34.34.225.205:8888] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/dev/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_hAAABMc"]
[Sun Aug 30 03:06:13.564249 2026] [security2:error] [pid 496962:tid 497117] [client 34.34.225.205:47224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/dev/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_hQAABMY"]
[Sun Aug 30 03:06:13.564463 2026] [security2:error] [pid 496962:tid 497116] [client 34.34.225.205:9504] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/secret/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_jgAABMU"]
[Sun Aug 30 03:06:13.564463 2026] [security2:error] [pid 496962:tid 497158] [client 34.34.225.205:15985] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/local/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_iAAABO8"]
[Sun Aug 30 03:06:13.564630 2026] [security2:error] [pid 496962:tid 497128] [client 34.34.225.205:58351] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/protected/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_kgAABNE"]
[Sun Aug 30 03:06:13.564702 2026] [security2:error] [pid 496962:tid 497139] [client 34.34.225.205:10034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/secure/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_iwAABNw"]
[Sun Aug 30 03:06:13.564703 2026] [security2:error] [pid 496962:tid 497211] [client 34.34.225.205:46124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/secret/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_jwAABSQ"]
[Sun Aug 30 03:06:13.564811 2026] [security2:error] [pid 496962:tid 497166] [client 34.34.225.205:14065] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/v2/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_lAAABPc"]
[Sun Aug 30 03:06:13.565012 2026] [security2:error] [pid 496962:tid 497219] [client 34.34.225.205:23945] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/v2/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_kwAABSw"]
[Sun Aug 30 03:06:13.565055 2026] [security2:error] [pid 496962:tid 497129] [client 34.34.225.205:34085] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/v3/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_lQAABNI"]
[Sun Aug 30 03:06:13.565092 2026] [security2:error] [pid 496962:tid 497214] [client 34.34.225.205:33046] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/protected/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_kQAABSc"]
[Sun Aug 30 03:06:13.565219 2026] [security2:error] [pid 496962:tid 497183] [client 34.34.225.205:48107] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/v3/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_jAAABQg"]
[Sun Aug 30 03:06:13.565342 2026] [security2:error] [pid 496962:tid 497190] [client 34.34.225.205:18439] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/v1/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_kAAABQ8"]
[Sun Aug 30 03:06:13.565364 2026] [security2:error] [pid 496962:tid 497192] [client 34.34.225.205:14100] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/api/v1/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_lgAABRE"]
[Sun Aug 30 03:06:13.565777 2026] [security2:error] [pid 495314:tid 495486] [client 34.34.225.205:47893] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/v1/.git/config"] [unique_id "apPkdUmtdPfUFP1akVFshQAABFI"]
[Sun Aug 30 03:06:13.565968 2026] [security2:error] [pid 496962:tid 497093] [client 20.220.10.235:24669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/update/da222.php"] [unique_id "apPkdY6aRhSu8gis9Ll_lwAABK4"]
[Sun Aug 30 03:06:13.565998 2026] [security2:error] [pid 496962:tid 497146] [client 34.34.225.205:5069] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/private/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_jQAABOM"]
[Sun Aug 30 03:06:13.566176 2026] [security2:error] [pid 496962:tid 497109] [client 34.34.225.205:49125] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/development/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_hgAABL4"]
[Sun Aug 30 03:06:13.567123 2026] [security2:error] [pid 496962:tid 497109] [client 34.34.225.205:44620] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/api/v2/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_mwAABL4"]
[Sun Aug 30 03:06:13.567238 2026] [security2:error] [pid 496962:tid 497217] [client 34.34.225.205:53531] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/api/v1/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_mgAABSo"]
[Sun Aug 30 03:06:13.567398 2026] [security2:error] [pid 496962:tid 497196] [client 34.34.225.205:31881] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/api/v2/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_mQAABRU"]
[Sun Aug 30 03:06:13.583797 2026] [security2:error] [pid 495314:tid 495540] [client 20.104.49.130:48035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/chosen.php"] [unique_id "apPkdUmtdPfUFP1akVFskgAABIg"]
[Sun Aug 30 03:06:13.607558 2026] [security2:error] [pid 496962:tid 497103] [client 34.34.225.205:57735] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/rest/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_qgAABLg"]
[Sun Aug 30 03:06:13.609031 2026] [security2:error] [pid 496962:tid 497103] [client 34.34.225.205:53582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/graphql/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_rQAABLg"]
[Sun Aug 30 03:06:13.609121 2026] [security2:error] [pid 496962:tid 497213] [client 34.34.225.205:38482] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/\\",/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_rgAABSY"]
[Sun Aug 30 03:06:13.609610 2026] [security2:error] [pid 496962:tid 497180] [client 34.34.225.205:51241] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/graphql/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_rAAABQU"]
[Sun Aug 30 03:06:13.610107 2026] [security2:error] [pid 496962:tid 497160] [client 34.34.225.205:46119] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "192.254.186.130"] [uri "/\\",/.git/config"] [unique_id "apPkdY6aRhSu8gis9Ll_sAAABPE"]
[Sun Aug 30 03:06:13.610157 2026] [security2:error] [pid 496962:tid 497103] [client 34.34.225.205:11358] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "192.254.186.130"] [uri "/rest/.env"] [unique_id "apPkdY6aRhSu8gis9Ll_sQAABLg"]
[Sun Aug 30 03:06:13.629089 2026] [security2:error] [pid 496962:tid 497137] [client 4.205.62.107:65307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/kedi.php"] [unique_id "apPkdY6aRhSu8gis9Ll_uwAABNo"]
[Sun Aug 30 03:06:13.639702 2026] [core:error] [pid 496962:tid 497052] [remote 40.83.93.50:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:06:13.639730 2026] [core:error] [pid 496962:tid 497052] [remote 40.83.93.50:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:06:13.652791 2026] [security2:error] [pid 495314:tid 495545] [client 20.151.200.44:65268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/wk/index.php"] [unique_id "apPkdUmtdPfUFP1akVFssgAABI0"]
[Sun Aug 30 03:06:13.666468 2026] [security2:error] [pid 495314:tid 495530] [client 40.83.93.50:9285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/cache.php"] [unique_id "apPkdUmtdPfUFP1akVFsugAABH4"]
[Sun Aug 30 03:06:13.687052 2026] [security2:error] [pid 496962:tid 497140] [client 20.48.251.3:6523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/gjm.php"] [unique_id "apPkdY6aRhSu8gis9Ll_3gAABN0"]
[Sun Aug 30 03:06:13.693080 2026] [security2:error] [pid 496962:tid 497142] [client 20.104.50.220:32541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/alfateslav4.php"] [unique_id "apPkdY6aRhSu8gis9Ll_5AAABN8"]
[Sun Aug 30 03:06:13.701899 2026] [security2:error] [pid 495314:tid 495541] [client 20.220.10.235:24698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/qi.php"] [unique_id "apPkdUmtdPfUFP1akVFszAAABIk"]
[Sun Aug 30 03:06:13.733064 2026] [security2:error] [pid 495314:tid 495514] [client 20.104.50.220:6088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/class9.php"] [unique_id "apPkdUmtdPfUFP1akVFs2AAABG4"]
[Sun Aug 30 03:06:13.741322 2026] [authz_core:error] [pid 496962:tid 497152] [client 216.73.216.128:57093] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:13.741743 2026] [authz_core:error] [pid 496962:tid 497152] [client 216.73.216.128:57093] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:13.758019 2026] [security2:error] [pid 496962:tid 497193] [client 20.48.251.3:23326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/cache-compat.php"] [unique_id "apPkdY6aRhSu8gis9Ll_8wAABRI"]
[Sun Aug 30 03:06:13.762752 2026] [security2:error] [pid 496962:tid 497202] [client 128.140.106.114:45062] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.sjbauthority.com"] [uri "/index.php"] [unique_id "apPkdY6aRhSu8gis9Ll-HQAABRs"], referer: http://www.sjbauthority.com
[Sun Aug 30 03:06:13.796227 2026] [security2:error] [pid 495314:tid 495565] [client 20.151.200.44:64659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/dehnl.php"] [unique_id "apPkdUmtdPfUFP1akVFs-wAABKE"]
[Sun Aug 30 03:06:13.815470 2026] [security2:error] [pid 496962:tid 497111] [client 20.48.251.3:55520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/css.php"] [unique_id "apPkdY6aRhSu8gis9Ll_-wAABMA"]
[Sun Aug 30 03:06:13.847642 2026] [security2:error] [pid 495314:tid 495522] [client 20.220.10.235:24655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/px.php"] [unique_id "apPkdUmtdPfUFP1akVFtFAAABHY"]
[Sun Aug 30 03:06:13.925033 2026] [authz_core:error] [pid 496962:tid 497190] [client 66.249.66.32:64059] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:13.925382 2026] [authz_core:error] [pid 496962:tid 497190] [client 66.249.66.32:64059] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:13.929849 2026] [security2:error] [pid 496962:tid 497160] [client 20.151.200.44:65219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/png.php"] [unique_id "apPkdY6aRhSu8gis9LmAKwAABPE"]
[Sun Aug 30 03:06:13.946035 2026] [security2:error] [pid 495314:tid 495453] [client 20.48.251.3:52800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/old_phpinfo.php"] [unique_id "apPkdUmtdPfUFP1akVFtSAAABDE"]
[Sun Aug 30 03:06:13.973532 2026] [security2:error] [pid 495314:tid 495486] [client 20.220.10.235:24769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/is.php"] [unique_id "apPkdUmtdPfUFP1akVFtWgAABFI"]
[Sun Aug 30 03:06:13.981315 2026] [security2:error] [pid 495314:tid 495458] [client 20.197.61.180:21099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPkdUmtdPfUFP1akVFtXwAABDY"]
[Sun Aug 30 03:06:13.996361 2026] [security2:error] [pid 496962:tid 497195] [client 68.155.159.216:56443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/ws.php"] [unique_id "apPkdY6aRhSu8gis9LmARgAABRQ"]
[Sun Aug 30 03:06:13.997692 2026] [security2:error] [pid 496962:tid 497119] [client 20.151.200.44:55700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/kcs.php"] [unique_id "apPkdY6aRhSu8gis9LmARwAABMg"]
[Sun Aug 30 03:06:14.014567 2026] [security2:error] [pid 495314:tid 495469] [client 4.205.62.107:35973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/umgebung.php"] [unique_id "apPkdkmtdPfUFP1akVFtdwAABEE"]
[Sun Aug 30 03:06:14.014580 2026] [security2:error] [pid 496962:tid 497147] [client 20.104.50.220:29155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/python.php"] [unique_id "apPkdo6aRhSu8gis9LmAUQAABOQ"]
[Sun Aug 30 03:06:14.052655 2026] [authz_core:error] [pid 496962:tid 497176] [client 66.249.66.35:38883] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:14.053101 2026] [authz_core:error] [pid 496962:tid 497176] [client 66.249.66.35:38883] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:14.076114 2026] [security2:error] [pid 496962:tid 497126] [client 20.48.251.3:7031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/wp-konfig.php"] [unique_id "apPkdo6aRhSu8gis9LmAewAABM8"]
[Sun Aug 30 03:06:14.100804 2026] [security2:error] [pid 495314:tid 495551] [client 20.220.10.235:24814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/od.php"] [unique_id "apPkdkmtdPfUFP1akVFtmwAABJM"]
[Sun Aug 30 03:06:14.102606 2026] [security2:error] [pid 495314:tid 495557] [client 20.48.251.3:46176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/doc.php"] [unique_id "apPkdkmtdPfUFP1akVFtnAAABJk"]
[Sun Aug 30 03:06:14.106959 2026] [authz_core:error] [pid 496962:tid 497218] [client 216.73.216.128:57093] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:14.107463 2026] [authz_core:error] [pid 496962:tid 497218] [client 216.73.216.128:57093] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:14.130994 2026] [security2:error] [pid 495314:tid 495495] [client 216.244.66.238:58560] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arcaneguardians.com"] [uri "/sblx/platinum-card-breaks-address"] [unique_id "apPkdkmtdPfUFP1akVFtpwAABFs"]
[Sun Aug 30 03:06:14.131145 2026] [security2:error] [pid 495314:tid 495495] [client 216.244.66.238:58560] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "arcaneguardians.com"] [uri "/sblx/platinum-card-breaks-address"] [unique_id "apPkdkmtdPfUFP1akVFtpwAABFs"]
[Sun Aug 30 03:06:14.154581 2026] [security2:error] [pid 495314:tid 495515] [client 40.83.93.50:12092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/fix.php"] [unique_id "apPkdkmtdPfUFP1akVFtsAAABG8"]
[Sun Aug 30 03:06:14.155532 2026] [security2:error] [pid 496962:tid 497127] [client 20.104.49.130:34548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/wpxml.php"] [unique_id "apPkdo6aRhSu8gis9LmAmwAABNA"]
[Sun Aug 30 03:06:14.156934 2026] [security2:error] [pid 496962:tid 497093] [client 20.104.50.220:61986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/x13.php"] [unique_id "apPkdo6aRhSu8gis9LmAnAAABK4"]
[Sun Aug 30 03:06:14.168018 2026] [security2:error] [pid 495314:tid 495524] [client 68.155.159.216:52666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apPkdkmtdPfUFP1akVFttwAABHg"]
[Sun Aug 30 03:06:14.179247 2026] [security2:error] [pid 496962:tid 497125] [client 20.151.200.44:64669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/txets.php"] [unique_id "apPkdo6aRhSu8gis9LmApAAABM4"]
[Sun Aug 30 03:06:14.180129 2026] [security2:error] [pid 496962:tid 497092] [client 20.104.50.220:33548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/cxc.php"] [unique_id "apPkdo6aRhSu8gis9LmAqAAABK0"]
[Sun Aug 30 03:06:14.233356 2026] [security2:error] [pid 496962:tid 497206] [client 20.220.10.235:24672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/wp-the.php"] [unique_id "apPkdo6aRhSu8gis9LmAvgAABR8"]
[Sun Aug 30 03:06:14.249942 2026] [security2:error] [pid 496962:tid 497116] [client 20.104.18.15:13675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/abcd.php"] [unique_id "apPkdo6aRhSu8gis9LmAxQAABMU"]
[Sun Aug 30 03:06:14.264917 2026] [security2:error] [pid 496962:tid 497114] [client 68.155.159.216:63992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-content/languages/about.php"] [unique_id "apPkdo6aRhSu8gis9LmAzgAABMM"]
[Sun Aug 30 03:06:14.268710 2026] [security2:error] [pid 496962:tid 497129] [client 20.104.50.220:52838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/kamu.php"] [unique_id "apPkdo6aRhSu8gis9LmA0AAABNI"]
[Sun Aug 30 03:06:14.312909 2026] [security2:error] [pid 496962:tid 497171] [client 20.151.200.44:64591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/wp-login.php"] [unique_id "apPkdo6aRhSu8gis9LmA4wAABPw"]
[Sun Aug 30 03:06:14.363825 2026] [security2:error] [pid 496962:tid 497096] [client 20.220.10.235:24700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/wt.php"] [unique_id "apPkdo6aRhSu8gis9LmBCgAABLE"]
[Sun Aug 30 03:06:14.381850 2026] [authz_core:error] [pid 496962:tid 497219] [client 216.73.216.128:57093] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:14.382131 2026] [authz_core:error] [pid 496962:tid 497219] [client 216.73.216.128:57093] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:14.449094 2026] [security2:error] [pid 496962:tid 497203] [client 20.104.50.220:27115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/include/footer.php"] [unique_id "apPkdo6aRhSu8gis9LmBOQAABRw"]
[Sun Aug 30 03:06:14.449597 2026] [security2:error] [pid 496962:tid 497124] [client 20.48.251.3:5104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/myfile.php"] [unique_id "apPkdo6aRhSu8gis9LmBOgAABM0"]
[Sun Aug 30 03:06:14.472710 2026] [security2:error] [pid 495314:tid 495549] [client 20.104.18.15:43921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/inx.php"] [unique_id "apPkdkmtdPfUFP1akVFuSgAABJE"]
[Sun Aug 30 03:06:14.491534 2026] [security2:error] [pid 496962:tid 497114] [client 20.104.18.15:33008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/info.php/new.php"] [unique_id "apPkdo6aRhSu8gis9LmBQQAABMM"]
[Sun Aug 30 03:06:14.493659 2026] [security2:error] [pid 496962:tid 497135] [client 20.220.10.235:24689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/im.php"] [unique_id "apPkdo6aRhSu8gis9LmBQgAABNg"]
[Sun Aug 30 03:06:14.503428 2026] [security2:error] [pid 496962:tid 497132] [client 68.155.159.216:65473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-content/languages/about.php"] [unique_id "apPkdo6aRhSu8gis9LmBTgAABNU"]
[Sun Aug 30 03:06:14.552515 2026] [authz_core:error] [pid 495314:tid 495570] [client 66.249.66.193:46810] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:14.552985 2026] [authz_core:error] [pid 495314:tid 495570] [client 66.249.66.193:46810] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:14.560104 2026] [security2:error] [pid 496962:tid 497185] [client 20.104.50.220:42782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/cyto.php"] [unique_id "apPkdo6aRhSu8gis9LmBXgAABQo"]
[Sun Aug 30 03:06:14.595248 2026] [security2:error] [pid 496962:tid 497146] [client 68.155.159.216:54133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-admin/network/index.php"] [unique_id "apPkdo6aRhSu8gis9LmBcQAABOM"]
[Sun Aug 30 03:06:14.613781 2026] [security2:error] [pid 496962:tid 497138] [client 20.104.50.220:46404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/kndw1.php"] [unique_id "apPkdo6aRhSu8gis9LmBfAAABNs"]
[Sun Aug 30 03:06:14.619854 2026] [security2:error] [pid 495314:tid 495510] [client 20.151.200.44:65228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/wp-access.php"] [unique_id "apPkdkmtdPfUFP1akVFukgAABGo"]
[Sun Aug 30 03:06:14.630604 2026] [security2:error] [pid 496962:tid 497160] [client 20.220.10.235:24650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/file.php"] [unique_id "apPkdo6aRhSu8gis9LmBgQAABPE"]
[Sun Aug 30 03:06:14.637414 2026] [security2:error] [pid 495314:tid 495485] [client 40.83.93.50:8758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/alfa.php"] [unique_id "apPkdkmtdPfUFP1akVFunAAABFE"]
[Sun Aug 30 03:06:14.642548 2026] [security2:error] [pid 495314:tid 495568] [client 68.155.159.216:62284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/ws.php"] [unique_id "apPkdkmtdPfUFP1akVFuoAAABKQ"]
[Sun Aug 30 03:06:14.705575 2026] [security2:error] [pid 495314:tid 495544] [client 20.197.61.180:21082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/intense/block-css.php"] [unique_id "apPkdkmtdPfUFP1akVFuuwAABIw"]
[Sun Aug 30 03:06:14.727315 2026] [authz_core:error] [pid 496962:tid 497177] [client 66.249.66.76:46460] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:14.727870 2026] [authz_core:error] [pid 496962:tid 497177] [client 66.249.66.76:46460] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:14.763425 2026] [security2:error] [pid 495314:tid 495457] [client 20.220.10.235:24824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/ca.php"] [unique_id "apPkdkmtdPfUFP1akVFu0QAABDU"]
[Sun Aug 30 03:06:14.796538 2026] [security2:error] [pid 496962:tid 497186] [client 20.151.200.44:65325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/wp-content/admin.php"] [unique_id "apPkdo6aRhSu8gis9LmB0QAABQs"]
[Sun Aug 30 03:06:14.825735 2026] [security2:error] [pid 495314:tid 495448] [client 20.48.251.3:6465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/configuration.php"] [unique_id "apPkdkmtdPfUFP1akVFu6QAABCw"]
[Sun Aug 30 03:06:14.846943 2026] [security2:error] [pid 495314:tid 495420] [remote 152.53.108.193:56546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.108.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "flashflooring.co.uk"] [uri "/wp-login.php"] [unique_id "apPkdkmtdPfUFP1akVFu9QAEhWk"], referer: https://flashflooring.co.uk/wp-login.php
[Sun Aug 30 03:06:14.848788 2026] [security2:error] [pid 495314:tid 495544] [client 20.104.50.220:32575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/alwso.php"] [unique_id "apPkdkmtdPfUFP1akVFu9gAABIw"]
[Sun Aug 30 03:06:14.870390 2026] [security2:error] [pid 496962:tid 497165] [client 20.104.50.220:5198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/la.php"] [unique_id "apPkdo6aRhSu8gis9LmB6wAABPY"]
[Sun Aug 30 03:06:14.892189 2026] [security2:error] [pid 495314:tid 495462] [client 20.48.251.3:44283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/aws_keys.php"] [unique_id "apPkdkmtdPfUFP1akVFvFQAABDo"]
[Sun Aug 30 03:06:14.892730 2026] [security2:error] [pid 496962:tid 497097] [client 20.220.10.235:24782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/pb.php"] [unique_id "apPkdo6aRhSu8gis9LmB8gAABLI"]
[Sun Aug 30 03:06:14.952233 2026] [security2:error] [pid 495314:tid 495518] [client 20.48.251.3:50006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/php_info.php"] [unique_id "apPkdkmtdPfUFP1akVFvOwAABHI"]
[Sun Aug 30 03:06:15.004234 2026] [security2:error] [pid 495314:tid 495447] [client 20.151.200.44:64038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/log.php"] [unique_id "apPkd0mtdPfUFP1akVFvXgAABCs"]
[Sun Aug 30 03:06:15.021159 2026] [security2:error] [pid 495314:tid 495531] [client 20.220.10.235:24775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/pk.php"] [unique_id "apPkd0mtdPfUFP1akVFvZwAABH8"]
[Sun Aug 30 03:06:15.084948 2026] [security2:error] [pid 495314:tid 495543] [client 20.48.251.3:59308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mizunewyork.com"] [uri "/wp-act.php"] [unique_id "apPkd0mtdPfUFP1akVFvjAAABIs"]
[Sun Aug 30 03:06:15.116138 2026] [security2:error] [pid 496962:tid 497109] [client 68.155.159.216:56338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-includes/css/index.php"] [unique_id "apPkd46aRhSu8gis9LmCMQAABL4"]
[Sun Aug 30 03:06:15.149844 2026] [security2:error] [pid 496962:tid 497170] [client 20.220.10.235:24793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/ft.php"] [unique_id "apPkd46aRhSu8gis9LmCPQAABPs"]
[Sun Aug 30 03:06:15.156081 2026] [security2:error] [pid 495314:tid 495568] [client 40.83.93.50:12033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/wp-blog-header.php"] [unique_id "apPkd0mtdPfUFP1akVFvqgAABKQ"]
[Sun Aug 30 03:06:15.163097 2026] [security2:error] [pid 496962:tid 497173] [client 20.104.50.220:62826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-pop.php"] [unique_id "apPkd46aRhSu8gis9LmCRQAABP4"]
[Sun Aug 30 03:06:15.201878 2026] [authz_core:error] [pid 495314:tid 495461] [client 216.73.216.128:23351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:15.202225 2026] [authz_core:error] [pid 495314:tid 495461] [client 216.73.216.128:23351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:15.235660 2026] [security2:error] [pid 496962:tid 497210] [client 45.3.55.204:47003] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "belloinsights.com"] [uri "/"] [unique_id "apPkd46aRhSu8gis9LmCZgAABSM"]
[Sun Aug 30 03:06:15.262396 2026] [security2:error] [pid 496962:tid 497186] [client 20.151.200.44:64026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/xwpg.php"] [unique_id "apPkd46aRhSu8gis9LmCawAABQs"]
[Sun Aug 30 03:06:15.285388 2026] [security2:error] [pid 496962:tid 497160] [client 20.220.10.235:24819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/wp-ver.php"] [unique_id "apPkd46aRhSu8gis9LmCcQAABPE"]
[Sun Aug 30 03:06:15.292227 2026] [security2:error] [pid 496962:tid 497102] [client 20.104.50.220:61400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/ntaps.php"] [unique_id "apPkd46aRhSu8gis9LmCdAAABLc"]
[Sun Aug 30 03:06:15.292569 2026] [security2:error] [pid 495314:tid 495470] [client 20.48.251.3:65494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/classsmtps.php"] [unique_id "apPkd0mtdPfUFP1akVFv_wAABEI"]
[Sun Aug 30 03:06:15.297110 2026] [authz_core:error] [pid 495314:tid 495569] [client 66.249.66.38:64039] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:15.297559 2026] [authz_core:error] [pid 495314:tid 495569] [client 66.249.66.38:64039] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:15.349921 2026] [security2:error] [pid 496962:tid 497135] [client 20.104.50.220:33157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/constant.php"] [unique_id "apPkd46aRhSu8gis9LmCggAABNg"]
[Sun Aug 30 03:06:15.356443 2026] [security2:error] [pid 495314:tid 495511] [client 68.155.159.216:52727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPkd0mtdPfUFP1akVFwLwAABGs"]
[Sun Aug 30 03:06:15.397932 2026] [security2:error] [pid 495314:tid 495513] [client 20.104.18.15:13727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/nofile.php"] [unique_id "apPkd0mtdPfUFP1akVFwRQAABG0"]
[Sun Aug 30 03:06:15.410585 2026] [security2:error] [pid 495314:tid 495565] [client 20.197.61.180:14048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/login.php"] [unique_id "apPkd0mtdPfUFP1akVFwUAAABKE"]
[Sun Aug 30 03:06:15.414290 2026] [authz_core:error] [pid 495314:tid 495514] [client 66.249.66.44:47095] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:15.414583 2026] [authz_core:error] [pid 495314:tid 495514] [client 66.249.66.44:47095] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:15.415515 2026] [security2:error] [pid 495314:tid 495544] [client 20.220.10.235:24791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/ah24.php"] [unique_id "apPkd0mtdPfUFP1akVFwUwAABIw"]
[Sun Aug 30 03:06:15.419486 2026] [security2:error] [pid 495314:tid 495470] [client 20.104.50.220:62809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/inject.php"] [unique_id "apPkd0mtdPfUFP1akVFwVQAABEI"]
[Sun Aug 30 03:06:15.475551 2026] [authz_core:error] [pid 496962:tid 497202] [client 216.73.216.128:57093] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:15.475888 2026] [authz_core:error] [pid 496962:tid 497202] [client 216.73.216.128:57093] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:15.479623 2026] [security2:error] [pid 495314:tid 495527] [client 68.155.159.216:63956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-content/banners/about.php"] [unique_id "apPkd0mtdPfUFP1akVFweQAABHs"]
[Sun Aug 30 03:06:15.543528 2026] [security2:error] [pid 496962:tid 497163] [client 20.220.10.235:24676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/wp-admin/zwso.php"] [unique_id "apPkd46aRhSu8gis9LmCzQAABPQ"]
[Sun Aug 30 03:06:15.569212 2026] [authz_core:error] [pid 495314:tid 495562] [client 216.73.216.128:23351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:15.569672 2026] [authz_core:error] [pid 495314:tid 495562] [client 216.73.216.128:23351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:15.586832 2026] [security2:error] [pid 496962:tid 497109] [client 20.104.50.220:27134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/include/header.php"] [unique_id "apPkd46aRhSu8gis9LmC3gAABL4"]
[Sun Aug 30 03:06:15.604706 2026] [security2:error] [pid 496962:tid 497103] [client 68.155.159.216:65527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-content/banners/about.php"] [unique_id "apPkd46aRhSu8gis9LmC6gAABLg"]
[Sun Aug 30 03:06:15.611290 2026] [security2:error] [pid 496962:tid 497093] [client 20.104.18.15:43990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/vpn.php"] [unique_id "apPkd46aRhSu8gis9LmC8AAABK4"]
[Sun Aug 30 03:06:15.646203 2026] [security2:error] [pid 495314:tid 495565] [client 20.48.251.3:4675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/lm15.php"] [unique_id "apPkd0mtdPfUFP1akVFwzwAABKE"]
[Sun Aug 30 03:06:15.690761 2026] [security2:error] [pid 495314:tid 495462] [client 40.83.93.50:9290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/s.php"] [unique_id "apPkd0mtdPfUFP1akVFw4QAABDo"]
[Sun Aug 30 03:06:15.696040 2026] [security2:error] [pid 495314:tid 495478] [client 20.104.49.130:57721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/ty.php"] [unique_id "apPkd0mtdPfUFP1akVFw4wAABEo"]
[Sun Aug 30 03:06:15.710653 2026] [security2:error] [pid 495314:tid 495507] [client 20.220.10.235:24727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/waf.php"] [unique_id "apPkd0mtdPfUFP1akVFw6AAABGc"]
[Sun Aug 30 03:06:15.710939 2026] [security2:error] [pid 496962:tid 497175] [client 20.104.50.220:42775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/con7.php"] [unique_id "apPkd46aRhSu8gis9LmDIQAABQA"]
[Sun Aug 30 03:06:15.750595 2026] [security2:error] [pid 495314:tid 495539] [client 20.104.18.15:33021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/w.php"] [unique_id "apPkd0mtdPfUFP1akVFw-QAABIc"]
[Sun Aug 30 03:06:15.753932 2026] [security2:error] [pid 495314:tid 495551] [client 68.155.159.216:63506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-includes/css/index.php"] [unique_id "apPkd0mtdPfUFP1akVFw_AAABJM"]
[Sun Aug 30 03:06:15.764266 2026] [security2:error] [pid 496962:tid 497116] [client 20.104.50.220:47041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/la.php"] [unique_id "apPkd46aRhSu8gis9LmDLwAABMU"]
[Sun Aug 30 03:06:15.770073 2026] [security2:error] [pid 495314:tid 495485] [client 68.155.159.216:60023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apPkd0mtdPfUFP1akVFxBAAABFE"]
[Sun Aug 30 03:06:15.800681 2026] [security2:error] [pid 496962:tid 497123] [client 20.48.251.3:45862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/25.php"] [unique_id "apPkd46aRhSu8gis9LmDNAAABMw"]
[Sun Aug 30 03:06:15.832861 2026] [security2:error] [pid 496962:tid 497170] [client 216.73.216.128:57093] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPkd46aRhSu8gis9LmDPwAABPs"]
[Sun Aug 30 03:06:15.841873 2026] [security2:error] [pid 496962:tid 497139] [client 20.151.200.44:64696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/sxxb.php"] [unique_id "apPkd46aRhSu8gis9LmDRgAABNw"]
[Sun Aug 30 03:06:15.963548 2026] [security2:error] [pid 495314:tid 495448] [client 20.48.251.3:64509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/server_info.php"] [unique_id "apPkd0mtdPfUFP1akVFxegAABCw"]
[Sun Aug 30 03:06:15.999155 2026] [security2:error] [pid 496962:tid 497130] [client 20.104.50.220:31922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/anjay.php"] [unique_id "apPkd46aRhSu8gis9LmDbwAABNM"]
[Sun Aug 30 03:06:16.007370 2026] [security2:error] [pid 495314:tid 495546] [client 20.104.50.220:5601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/bless11.php"] [unique_id "apPkeEmtdPfUFP1akVFxlQAABI4"]
[Sun Aug 30 03:06:16.021076 2026] [authz_core:error] [pid 495314:tid 495556] [client 216.73.216.128:38709] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:16.021358 2026] [authz_core:error] [pid 495314:tid 495556] [client 216.73.216.128:38709] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:16.022964 2026] [security2:error] [pid 495314:tid 495467] [client 74.7.243.204:48120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/cms/"] [unique_id "apPkeEmtdPfUFP1akVFxngAABD8"], referer: http://mail.letter7brands.com/cms/?p=%2F%2Fetc
[Sun Aug 30 03:06:16.032315 2026] [security2:error] [pid 495314:tid 495535] [client 20.48.251.3:23355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/umgebung.php"] [unique_id "apPkeEmtdPfUFP1akVFxpAAABIM"]
[Sun Aug 30 03:06:16.034400 2026] [authz_core:error] [pid 496962:tid 497189] [client 66.249.66.74:50845] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:16.034887 2026] [authz_core:error] [pid 496962:tid 497189] [client 66.249.66.74:50845] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:16.069855 2026] [security2:error] [pid 495314:tid 495533] [client 20.151.200.44:47375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/xda.php"] [unique_id "apPkeEmtdPfUFP1akVFxvgAABIE"]
[Sun Aug 30 03:06:16.101173 2026] [security2:error] [pid 496962:tid 497191] [client 20.48.251.3:50030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/session.php"] [unique_id "apPkeI6aRhSu8gis9LmDogAABRA"]
[Sun Aug 30 03:06:16.113863 2026] [authz_core:error] [pid 496962:tid 497116] [client 216.73.216.128:57093] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:16.114256 2026] [authz_core:error] [pid 496962:tid 497116] [client 216.73.216.128:57093] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:16.126972 2026] [security2:error] [pid 495314:tid 495554] [client 20.197.61.180:14034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/min.php"] [unique_id "apPkeEmtdPfUFP1akVFx3QAABJY"]
[Sun Aug 30 03:06:16.197542 2026] [authz_core:error] [pid 495314:tid 495535] [client 66.249.66.200:45192] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:16.197988 2026] [authz_core:error] [pid 495314:tid 495535] [client 66.249.66.200:45192] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:16.203613 2026] [authz_core:error] [pid 495314:tid 495455] [client 216.73.216.128:23351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:16.203936 2026] [authz_core:error] [pid 495314:tid 495455] [client 216.73.216.128:23351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:16.216516 2026] [security2:error] [pid 496962:tid 497205] [client 40.83.93.50:9342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/php.php"] [unique_id "apPkeI6aRhSu8gis9LmDxwAABR4"]
[Sun Aug 30 03:06:16.232953 2026] [security2:error] [pid 496962:tid 497211] [client 20.151.200.44:55635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/tajj.php"] [unique_id "apPkeI6aRhSu8gis9LmDzQAABSQ"]
[Sun Aug 30 03:06:16.241176 2026] [security2:error] [pid 495314:tid 495480] [client 68.155.159.216:56324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apPkeEmtdPfUFP1akVFyHgAABEw"]
[Sun Aug 30 03:06:16.297461 2026] [authz_core:error] [pid 495314:tid 495491] [client 216.73.216.128:38709] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:16.297905 2026] [authz_core:error] [pid 495314:tid 495491] [client 216.73.216.128:38709] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:16.317842 2026] [security2:error] [pid 495314:tid 495472] [client 20.104.50.220:29148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/marjan.php"] [unique_id "apPkeEmtdPfUFP1akVFySQAABEQ"]
[Sun Aug 30 03:06:16.427328 2026] [security2:error] [pid 495314:tid 495510] [client 20.48.251.3:46164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/cache-compat.php"] [unique_id "apPkeEmtdPfUFP1akVFygwAABGo"]
[Sun Aug 30 03:06:16.459680 2026] [security2:error] [pid 495314:tid 495502] [client 20.104.50.220:63035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/zip.php"] [unique_id "apPkeEmtdPfUFP1akVFykgAABGI"]
[Sun Aug 30 03:06:16.476129 2026] [authz_core:error] [pid 495314:tid 495527] [client 66.249.66.38:64039] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:16.476585 2026] [authz_core:error] [pid 495314:tid 495527] [client 66.249.66.38:64039] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:16.490430 2026] [security2:error] [pid 496962:tid 497189] [client 68.155.159.216:52611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/ans.php"] [unique_id "apPkeI6aRhSu8gis9LmEQgAABQ4"]
[Sun Aug 30 03:06:16.504191 2026] [security2:error] [pid 496962:tid 497126] [client 20.104.50.220:32837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/celeng.php"] [unique_id "apPkeI6aRhSu8gis9LmEUQAABM8"]
[Sun Aug 30 03:06:16.539671 2026] [security2:error] [pid 495314:tid 495551] [client 45.3.55.204:30885] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "belloinsights.com"] [uri "/"] [unique_id "apPkeEmtdPfUFP1akVFyxAAABJM"]
[Sun Aug 30 03:06:16.548489 2026] [security2:error] [pid 495314:tid 495537] [client 74.7.243.204:48120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/cms/"] [unique_id "apPkeEmtdPfUFP1akVFyxQAABIU"], referer: http://mail.letter7brands.com/cms/?p=%2F%2Fetc
[Sun Aug 30 03:06:16.604531 2026] [security2:error] [pid 496962:tid 497167] [client 158.23.184.117:54483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/wp-admin/import.php"] [unique_id "apPkeI6aRhSu8gis9LmEawAABPg"]
[Sun Aug 30 03:06:16.626344 2026] [authz_core:error] [pid 495314:tid 495547] [client 66.249.66.192:36056] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:16.626784 2026] [authz_core:error] [pid 495314:tid 495547] [client 66.249.66.192:36056] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:16.652276 2026] [security2:error] [pid 495314:tid 495473] [client 20.104.18.15:13624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/run.php"] [unique_id "apPkeEmtdPfUFP1akVFzCAAABEU"]
[Sun Aug 30 03:06:16.670866 2026] [security2:error] [pid 495314:tid 495533] [client 20.151.200.44:65241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/dx.php"] [unique_id "apPkeEmtdPfUFP1akVFzFwAABIE"]
[Sun Aug 30 03:06:16.723102 2026] [security2:error] [pid 496962:tid 497117] [client 20.104.50.220:27528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/global.php"] [unique_id "apPkeI6aRhSu8gis9LmEoQAABMY"]
[Sun Aug 30 03:06:16.741850 2026] [security2:error] [pid 496962:tid 497201] [client 68.155.159.216:12293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apPkeI6aRhSu8gis9LmEpwAABRo"]
[Sun Aug 30 03:06:16.756718 2026] [security2:error] [pid 496962:tid 497165] [client 68.155.159.216:63952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apPkeI6aRhSu8gis9LmEqQAABPY"]
[Sun Aug 30 03:06:16.761187 2026] [security2:error] [pid 496962:tid 497198] [client 20.151.200.44:37846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/ls.php"] [unique_id "apPkeI6aRhSu8gis9LmEqwAABRc"]
[Sun Aug 30 03:06:16.762021 2026] [security2:error] [pid 495314:tid 495467] [client 158.23.184.117:7892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "apPkeEmtdPfUFP1akVFzMgAABD8"]
[Sun Aug 30 03:06:16.763863 2026] [security2:error] [pid 496962:tid 497126] [client 20.104.18.15:43989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/shiny.php"] [unique_id "apPkeI6aRhSu8gis9LmErAAABM8"]
[Sun Aug 30 03:06:16.775919 2026] [security2:error] [pid 495314:tid 495503] [client 40.83.93.50:8766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/system_log.php"] [unique_id "apPkeEmtdPfUFP1akVFzNAAABGM"]
[Sun Aug 30 03:06:16.817634 2026] [security2:error] [pid 496962:tid 497142] [client 20.48.251.3:44310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/test.config.php"] [unique_id "apPkeI6aRhSu8gis9LmEsgAABN8"]
[Sun Aug 30 03:06:16.843368 2026] [security2:error] [pid 496962:tid 497120] [client 20.197.61.180:21089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/module.php"] [unique_id "apPkeI6aRhSu8gis9LmEuQAABMk"]
[Sun Aug 30 03:06:16.889236 2026] [security2:error] [pid 496962:tid 497219] [client 20.104.18.15:33770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/x.php"] [unique_id "apPkeI6aRhSu8gis9LmEwgAABSw"]
[Sun Aug 30 03:06:16.892743 2026] [security2:error] [pid 496962:tid 497139] [client 20.104.50.220:42770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/locale.php"] [unique_id "apPkeI6aRhSu8gis9LmEwwAABNw"]
[Sun Aug 30 03:06:16.893717 2026] [security2:error] [pid 496962:tid 497124] [client 20.104.50.220:47066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/lnedx.php"] [unique_id "apPkeI6aRhSu8gis9LmExAAABM0"]
[Sun Aug 30 03:06:16.906255 2026] [security2:error] [pid 496962:tid 497131] [client 68.155.159.216:63507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/cgi-bin/wp-login.php"] [unique_id "apPkeI6aRhSu8gis9LmEyAAABNQ"]
[Sun Aug 30 03:06:16.915328 2026] [cgid:error] [pid 496962:tid 497206] [client 158.23.184.117:7879] AH01265: stderr from /home1/cteteacher/OCTutoringcenter.com/cgi-bin/: attempt to invoke directory as script
[Sun Aug 30 03:06:16.949385 2026] [security2:error] [pid 496962:tid 497133] [client 68.155.159.216:59984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/.well-knownold/index.php"] [unique_id "apPkeI6aRhSu8gis9LmEzwAABNY"]
[Sun Aug 30 03:06:17.029029 2026] [authz_core:error] [pid 496962:tid 497214] [client 216.73.216.128:36424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:17.029496 2026] [authz_core:error] [pid 496962:tid 497214] [client 216.73.216.128:36424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:17.065536 2026] [security2:error] [pid 496962:tid 497176] [client 20.104.49.130:60649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/av.php"] [unique_id "apPkeY6aRhSu8gis9LmE5wAABQE"]
[Sun Aug 30 03:06:17.067145 2026] [authz_core:error] [pid 496962:tid 497157] [client 66.249.66.75:61786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:17.067464 2026] [authz_core:error] [pid 496962:tid 497157] [client 66.249.66.75:61786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:17.069984 2026] [autoindex:error] [pid 496962:tid 497196] [client 158.23.184.117:7879] AH01276: Cannot serve directory /home1/cteteacher/OCTutoringcenter.com/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:06:17.103158 2026] [security2:error] [pid 496962:tid 497140] [client 20.48.251.3:64407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/hosty.php"] [unique_id "apPkeY6aRhSu8gis9LmE8gAABN0"]
[Sun Aug 30 03:06:17.117755 2026] [security2:error] [pid 496962:tid 497212] [client 158.23.184.117:7879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/wp-admin/admin-post.php"] [unique_id "apPkeY6aRhSu8gis9LmE9QAABSU"]
[Sun Aug 30 03:06:17.138282 2026] [security2:error] [pid 496962:tid 497159] [client 20.104.50.220:32518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/anons79.php"] [unique_id "apPkeY6aRhSu8gis9LmE9wAABPA"]
[Sun Aug 30 03:06:17.148672 2026] [security2:error] [pid 496962:tid 497184] [client 20.104.50.220:5595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/ccou.php"] [unique_id "apPkeY6aRhSu8gis9LmE-QAABQk"]
[Sun Aug 30 03:06:17.187954 2026] [security2:error] [pid 496962:tid 497102] [client 20.48.251.3:44172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/old_phpinfo.php"] [unique_id "apPkeY6aRhSu8gis9LmE_AAABLc"]
[Sun Aug 30 03:06:17.245109 2026] [security2:error] [pid 496962:tid 497171] [client 20.48.251.3:55508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/h.php"] [unique_id "apPkeY6aRhSu8gis9LmFAgAABPw"]
[Sun Aug 30 03:06:17.266491 2026] [security2:error] [pid 496962:tid 497144] [client 40.83.93.50:9294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/w.php"] [unique_id "apPkeY6aRhSu8gis9LmFBwAABOE"]
[Sun Aug 30 03:06:17.267552 2026] [security2:error] [pid 496962:tid 497158] [client 158.23.184.117:54507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/favicon.php"] [unique_id "apPkeY6aRhSu8gis9LmFCAAABO8"]
[Sun Aug 30 03:06:17.321614 2026] [authz_core:error] [pid 496962:tid 497169] [client 66.249.66.39:42137] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:17.322019 2026] [authz_core:error] [pid 496962:tid 497169] [client 66.249.66.39:42137] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:17.390780 2026] [security2:error] [pid 496962:tid 497126] [client 20.151.200.44:55705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/bge.php"] [unique_id "apPkeY6aRhSu8gis9LmFIQAABM8"]
[Sun Aug 30 03:06:17.410580 2026] [security2:error] [pid 496962:tid 497181] [client 158.23.184.117:54493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/wp-admin/css/my.php"] [unique_id "apPkeY6aRhSu8gis9LmFKwAABQY"]
[Sun Aug 30 03:06:17.431437 2026] [security2:error] [pid 496962:tid 497173] [client 68.155.159.216:56378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-content/cong.php"] [unique_id "apPkeY6aRhSu8gis9LmFLQAABP4"]
[Sun Aug 30 03:06:17.454030 2026] [security2:error] [pid 496962:tid 497139] [client 164.92.244.132:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.heavyvehicles.com.au"] [uri "/.env"] [unique_id "apPkeY6aRhSu8gis9LmFMwAABNw"]
[Sun Aug 30 03:06:17.471208 2026] [security2:error] [pid 496962:tid 497096] [client 20.104.50.220:29590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/on.php"] [unique_id "apPkeY6aRhSu8gis9LmFOAAABLE"]
[Sun Aug 30 03:06:17.472983 2026] [security2:error] [pid 496962:tid 497171] [client 216.73.216.128:57093] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPkeY6aRhSu8gis9LmFOQAABPw"]
[Sun Aug 30 03:06:17.563072 2026] [security2:error] [pid 496962:tid 497167] [client 158.23.184.117:54501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/wp-content/images/doc.php"] [unique_id "apPkeY6aRhSu8gis9LmFVQAABPg"]
[Sun Aug 30 03:06:17.568529 2026] [security2:error] [pid 496962:tid 497134] [client 20.197.61.180:14021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/ms-files.php"] [unique_id "apPkeY6aRhSu8gis9LmFWQAABNc"]
[Sun Aug 30 03:06:17.572473 2026] [security2:error] [pid 496962:tid 497126] [client 20.48.251.3:46268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/aws_keys.php"] [unique_id "apPkeY6aRhSu8gis9LmFXAAABM8"]
[Sun Aug 30 03:06:17.601584 2026] [security2:error] [pid 496962:tid 497104] [client 68.155.159.216:52655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/worksec.php"] [unique_id "apPkeY6aRhSu8gis9LmFYwAABLk"]
[Sun Aug 30 03:06:17.631771 2026] [security2:error] [pid 496962:tid 497217] [client 20.104.50.220:61378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/@.php"] [unique_id "apPkeY6aRhSu8gis9LmFbAAABSo"]
[Sun Aug 30 03:06:17.658136 2026] [security2:error] [pid 496962:tid 497147] [client 45.3.55.204:19699] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "belloinsights.com"] [uri "/"] [unique_id "apPkeY6aRhSu8gis9LmFdwAABOQ"]
[Sun Aug 30 03:06:17.661042 2026] [security2:error] [pid 496962:tid 497209] [client 20.104.50.220:33187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/bypassing.php"] [unique_id "apPkeY6aRhSu8gis9LmFeAAABSI"]
[Sun Aug 30 03:06:17.747791 2026] [security2:error] [pid 496962:tid 497103] [client 158.23.184.117:54485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/wp-comments.php"] [unique_id "apPkeY6aRhSu8gis9LmFfQAABLg"]
[Sun Aug 30 03:06:17.789284 2026] [security2:error] [pid 496962:tid 497124] [client 40.83.93.50:9296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/wp.php"] [unique_id "apPkeY6aRhSu8gis9LmFjQAABM0"]
[Sun Aug 30 03:06:17.819449 2026] [security2:error] [pid 496962:tid 497193] [client 20.151.200.44:64643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPkeY6aRhSu8gis9LmFjgAABRI"]
[Sun Aug 30 03:06:17.822246 2026] [security2:error] [pid 496962:tid 497168] [client 20.104.18.15:13634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/new.php"] [unique_id "apPkeY6aRhSu8gis9LmFjwAABPk"]
[Sun Aug 30 03:06:17.861689 2026] [security2:error] [pid 496962:tid 497153] [client 20.104.50.220:27415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/wp-settings.php"] [unique_id "apPkeY6aRhSu8gis9LmFlwAABOo"]
[Sun Aug 30 03:06:17.889435 2026] [security2:error] [pid 496962:tid 497152] [client 158.23.184.117:54526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/wp-includes/panel.php"] [unique_id "apPkeY6aRhSu8gis9LmFnAAABOk"]
[Sun Aug 30 03:06:17.920745 2026] [security2:error] [pid 496962:tid 497119] [client 20.104.18.15:43979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/goods.php"] [unique_id "apPkeY6aRhSu8gis9LmFngAABMg"]
[Sun Aug 30 03:06:17.929748 2026] [security2:error] [pid 496962:tid 497102] [client 68.155.159.216:65518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/asd.php"] [unique_id "apPkeY6aRhSu8gis9LmFoQAABLc"]
[Sun Aug 30 03:06:17.960375 2026] [security2:error] [pid 496962:tid 497114] [client 20.48.251.3:4810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/gecko-litespeed.php"] [unique_id "apPkeY6aRhSu8gis9LmFrAAABMM"]
[Sun Aug 30 03:06:17.993186 2026] [security2:error] [pid 496962:tid 497190] [client 216.73.216.128:56834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPkeY6aRhSu8gis9LmFsAAABQ8"]
[Sun Aug 30 03:06:18.023721 2026] [authz_core:error] [pid 496962:tid 497099] [client 66.249.66.197:37338] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:18.024162 2026] [authz_core:error] [pid 496962:tid 497099] [client 66.249.66.197:37338] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:18.033665 2026] [security2:error] [pid 496962:tid 497127] [client 20.104.50.220:63536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/enter.php"] [unique_id "apPkeo6aRhSu8gis9LmFuAAABNA"]
[Sun Aug 30 03:06:18.043551 2026] [security2:error] [pid 496962:tid 497121] [client 20.151.200.44:47324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPkeo6aRhSu8gis9LmFvAAABMo"]
[Sun Aug 30 03:06:18.044809 2026] [security2:error] [pid 496962:tid 497124] [client 20.104.50.220:47048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/local.php"] [unique_id "apPkeo6aRhSu8gis9LmFvQAABM0"]
[Sun Aug 30 03:06:18.051116 2026] [security2:error] [pid 496962:tid 497097] [client 20.104.18.15:33017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/ssla.php"] [unique_id "apPkeo6aRhSu8gis9LmFvgAABLI"]
[Sun Aug 30 03:06:18.079247 2026] [security2:error] [pid 496962:tid 497214] [client 68.155.159.216:59962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apPkeo6aRhSu8gis9LmFwwAABSc"]
[Sun Aug 30 03:06:18.094523 2026] [security2:error] [pid 496962:tid 497153] [client 158.23.184.117:54495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/www.php"] [unique_id "apPkeo6aRhSu8gis9LmFyAAABOo"]
[Sun Aug 30 03:06:18.142503 2026] [security2:error] [pid 496962:tid 497119] [client 20.151.200.44:37859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/css/000.php"] [unique_id "apPkeo6aRhSu8gis9LmFzgAABMg"]
[Sun Aug 30 03:06:18.215833 2026] [security2:error] [pid 496962:tid 497129] [client 216.73.216.128:57093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/'%20+%20this.controller.state().get('src')%20+%20'"] [unique_id "apPkeo6aRhSu8gis9LmF1wAABNI"]
[Sun Aug 30 03:06:18.234622 2026] [security2:error] [pid 496962:tid 497150] [client 158.23.184.117:54468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/.well-known/core.php"] [unique_id "apPkeo6aRhSu8gis9LmF2AAABOc"]
[Sun Aug 30 03:06:18.239526 2026] [security2:error] [pid 496962:tid 497192] [client 20.48.251.3:64422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/cu.php"] [unique_id "apPkeo6aRhSu8gis9LmF2QAABRE"]
[Sun Aug 30 03:06:18.271896 2026] [security2:error] [pid 496962:tid 497093] [client 68.155.159.216:63493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-content/cong.php"] [unique_id "apPkeo6aRhSu8gis9LmF3AAABK4"]
[Sun Aug 30 03:06:18.283744 2026] [security2:error] [pid 496962:tid 497165] [client 20.104.50.220:6114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/ton.php"] [unique_id "apPkeo6aRhSu8gis9LmF3gAABPY"]
[Sun Aug 30 03:06:18.289957 2026] [security2:error] [pid 496962:tid 497149] [client 20.104.50.220:31860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/base.php"] [unique_id "apPkeo6aRhSu8gis9LmF3wAABOY"]
[Sun Aug 30 03:06:18.295589 2026] [security2:error] [pid 496962:tid 497101] [client 20.197.61.180:21093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/news-portal/error.php"] [unique_id "apPkeo6aRhSu8gis9LmF4AAABLY"]
[Sun Aug 30 03:06:18.334989 2026] [security2:error] [pid 496962:tid 497126] [client 40.83.93.50:18092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/composer.php"] [unique_id "apPkeo6aRhSu8gis9LmF6gAABM8"]
[Sun Aug 30 03:06:18.336169 2026] [security2:error] [pid 496962:tid 497214] [client 20.48.251.3:23358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.wondertanks.com"] [uri "/wp-act.php"] [unique_id "apPkeo6aRhSu8gis9LmF6wAABSc"]
[Sun Aug 30 03:06:18.377462 2026] [security2:error] [pid 496962:tid 497125] [client 158.23.184.117:54479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/akcc.php"] [unique_id "apPkeo6aRhSu8gis9LmF9gAABM4"]
[Sun Aug 30 03:06:18.378211 2026] [authz_core:error] [pid 496962:tid 497183] [client 66.249.66.40:60931] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:18.378496 2026] [authz_core:error] [pid 496962:tid 497183] [client 66.249.66.40:60931] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:18.382600 2026] [security2:error] [pid 496962:tid 497152] [client 20.48.251.3:55532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/bootstrap.php"] [unique_id "apPkeo6aRhSu8gis9LmF-wAABOk"]
[Sun Aug 30 03:06:18.415957 2026] [security2:error] [pid 496962:tid 497171] [client 20.151.200.44:47325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/t00l.php"] [unique_id "apPkeo6aRhSu8gis9LmGDgAABPw"]
[Sun Aug 30 03:06:18.520136 2026] [security2:error] [pid 496962:tid 497105] [client 158.23.184.117:54508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/themes7.php"] [unique_id "apPkeo6aRhSu8gis9LmGMAAABLo"]
[Sun Aug 30 03:06:18.541432 2026] [security2:error] [pid 496962:tid 497219] [client 68.155.159.216:56406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPkeo6aRhSu8gis9LmGOAAABSw"]
[Sun Aug 30 03:06:18.627735 2026] [security2:error] [pid 496962:tid 497206] [client 20.104.50.220:29578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/mari.php"] [unique_id "apPkeo6aRhSu8gis9LmGUQAABR8"]
[Sun Aug 30 03:06:18.660500 2026] [security2:error] [pid 496962:tid 497147] [client 20.104.49.130:57488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/dk.php"] [unique_id "apPkeo6aRhSu8gis9LmGXQAABOQ"]
[Sun Aug 30 03:06:18.662460 2026] [security2:error] [pid 496962:tid 497133] [client 158.23.184.117:54471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/wp-admin/images.php"] [unique_id "apPkeo6aRhSu8gis9LmGXgAABNY"]
[Sun Aug 30 03:06:18.715246 2026] [security2:error] [pid 496962:tid 497169] [client 20.48.251.3:46241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/umgebung.php"] [unique_id "apPkeo6aRhSu8gis9LmGaAAABPo"]
[Sun Aug 30 03:06:18.720961 2026] [security2:error] [pid 496962:tid 497110] [client 216.73.216.128:2141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts2/updateconf"] [unique_id "apPkeo6aRhSu8gis9LmGbAAABL8"]
[Sun Aug 30 03:06:18.775478 2026] [security2:error] [pid 496962:tid 497196] [client 20.104.50.220:61661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/ea.php"] [unique_id "apPkeo6aRhSu8gis9LmGdwAABRU"]
[Sun Aug 30 03:06:18.776633 2026] [security2:error] [pid 496962:tid 497112] [client 68.155.159.216:52650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/x.php"] [unique_id "apPkeo6aRhSu8gis9LmGeAAABME"]
[Sun Aug 30 03:06:18.804631 2026] [security2:error] [pid 496962:tid 497099] [client 20.104.50.220:33174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/bypshell.php"] [unique_id "apPkeo6aRhSu8gis9LmGgAAABLQ"]
[Sun Aug 30 03:06:18.804682 2026] [security2:error] [pid 496962:tid 497122] [client 158.23.184.117:7890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/wp-content/themes/haha.php"] [unique_id "apPkeo6aRhSu8gis9LmGgQAABMs"]
[Sun Aug 30 03:06:18.814008 2026] [security2:error] [pid 496962:tid 497135] [client 45.3.55.204:32969] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "belloinsights.com"] [uri "/"] [unique_id "apPkeo6aRhSu8gis9LmGhAAABNg"]
[Sun Aug 30 03:06:18.895247 2026] [authz_core:error] [pid 496962:tid 497198] [client 66.249.66.33:53450] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:18.895252 2026] [security2:error] [pid 496962:tid 497149] [client 40.83.93.50:8747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/abcd.php"] [unique_id "apPkeo6aRhSu8gis9LmGkgAABOY"]
[Sun Aug 30 03:06:18.895845 2026] [authz_core:error] [pid 496962:tid 497198] [client 66.249.66.33:53450] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:18.912023 2026] [security2:error] [pid 496962:tid 497120] [client 20.104.50.220:29145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/iya.php"] [unique_id "apPkeo6aRhSu8gis9LmGlQAABMk"]
[Sun Aug 30 03:06:18.956015 2026] [security2:error] [pid 496962:tid 497107] [client 158.23.184.117:7905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/wp-mail.php"] [unique_id "apPkeo6aRhSu8gis9LmGnQAABLw"]
[Sun Aug 30 03:06:18.978686 2026] [security2:error] [pid 496962:tid 497214] [client 20.104.18.15:13703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/inx.php"] [unique_id "apPkeo6aRhSu8gis9LmGpQAABSc"]
[Sun Aug 30 03:06:18.998742 2026] [security2:error] [pid 496962:tid 497111] [client 20.104.50.220:27410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/wp-config.php"] [unique_id "apPkeo6aRhSu8gis9LmGqgAABMA"]
[Sun Aug 30 03:06:19.009825 2026] [security2:error] [pid 496962:tid 497109] [client 20.197.61.180:3298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/nvt/includes/plugins/wp-blog-header.php"] [unique_id "apPke46aRhSu8gis9LmGrAAABL4"]
[Sun Aug 30 03:06:19.071150 2026] [security2:error] [pid 496962:tid 497171] [client 20.104.18.15:43278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/alfa.php"] [unique_id "apPke46aRhSu8gis9LmGugAABPw"]
[Sun Aug 30 03:06:19.084626 2026] [authz_core:error] [pid 496962:tid 497093] [client 66.249.66.66:35358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:19.084974 2026] [authz_core:error] [pid 496962:tid 497093] [client 66.249.66.66:35358] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:19.085528 2026] [security2:error] [pid 496962:tid 497208] [client 68.155.159.216:12294] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "wildcard.fenderhordes.com"] [uri "/1.php"] [unique_id "apPke46aRhSu8gis9LmGwQAABSE"]
[Sun Aug 30 03:06:19.085624 2026] [security2:error] [pid 496962:tid 497208] [client 68.155.159.216:12294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/1.php"] [unique_id "apPke46aRhSu8gis9LmGwQAABSE"]
[Sun Aug 30 03:06:19.095879 2026] [security2:error] [pid 496962:tid 497124] [client 158.23.184.117:7886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/root.php"] [unique_id "apPke46aRhSu8gis9LmGwwAABM0"]
[Sun Aug 30 03:06:19.107655 2026] [authz_core:error] [pid 496962:tid 497203] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fvim%2Fvim82%2Flang
[Sun Aug 30 03:06:19.107945 2026] [authz_core:error] [pid 496962:tid 497203] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fvim%2Fvim82%2Flang
[Sun Aug 30 03:06:19.112061 2026] [security2:error] [pid 496962:tid 497125] [client 158.23.147.79:53515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPke46aRhSu8gis9LmGxgAABM4"]
[Sun Aug 30 03:06:19.129232 2026] [security2:error] [pid 496962:tid 497118] [client 20.48.251.3:44369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/goods.php"] [unique_id "apPke46aRhSu8gis9LmGyAAABMc"]
[Sun Aug 30 03:06:19.132062 2026] [security2:error] [pid 496962:tid 497205] [client 20.151.200.44:65332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/xda.php"] [unique_id "apPke46aRhSu8gis9LmGyQAABR4"]
[Sun Aug 30 03:06:19.157572 2026] [security2:error] [pid 496962:tid 497127] [client 20.151.200.44:47018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/attack.php"] [unique_id "apPke46aRhSu8gis9LmGzAAABNA"]
[Sun Aug 30 03:06:19.173701 2026] [security2:error] [pid 496962:tid 497128] [client 20.104.50.220:42027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-enter.php"] [unique_id "apPke46aRhSu8gis9LmG0QAABNE"]
[Sun Aug 30 03:06:19.198875 2026] [security2:error] [pid 496962:tid 497213] [client 20.104.50.220:46426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/lolzk.php"] [unique_id "apPke46aRhSu8gis9LmG1gAABSY"]
[Sun Aug 30 03:06:19.228457 2026] [security2:error] [pid 496962:tid 497154] [client 20.104.18.15:33667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apPke46aRhSu8gis9LmG3AAABOs"]
[Sun Aug 30 03:06:19.241651 2026] [security2:error] [pid 496962:tid 497193] [client 158.23.184.117:54490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/ae.php"] [unique_id "apPke46aRhSu8gis9LmG3gAABRI"]
[Sun Aug 30 03:06:19.306897 2026] [security2:error] [pid 496962:tid 497094] [client 158.23.147.79:53539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPke46aRhSu8gis9LmG6AAABK8"]
[Sun Aug 30 03:06:19.376808 2026] [security2:error] [pid 496962:tid 497099] [client 20.48.251.3:64411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/services.php"] [unique_id "apPke46aRhSu8gis9LmG_QAABLQ"]
[Sun Aug 30 03:06:19.386872 2026] [security2:error] [pid 496962:tid 497189] [client 158.23.184.117:54494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/admin/controller/extension/ultra.php"] [unique_id "apPke46aRhSu8gis9LmHAAAABQ4"]
[Sun Aug 30 03:06:19.422895 2026] [security2:error] [pid 496962:tid 497095] [client 20.104.50.220:5579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/403.php"] [unique_id "apPke46aRhSu8gis9LmHCgAABLA"]
[Sun Aug 30 03:06:19.428244 2026] [security2:error] [pid 496962:tid 497134] [client 68.155.159.216:54132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPke46aRhSu8gis9LmHDAAABNc"]
[Sun Aug 30 03:06:19.444612 2026] [security2:error] [pid 496962:tid 497164] [client 20.104.50.220:32532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/batm.php"] [unique_id "apPke46aRhSu8gis9LmHEAAABPU"]
[Sun Aug 30 03:06:19.468279 2026] [security2:error] [pid 496962:tid 497132] [client 68.155.159.216:62299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPke46aRhSu8gis9LmHFwAABNU"]
[Sun Aug 30 03:06:19.518372 2026] [security2:error] [pid 496962:tid 497109] [client 20.48.251.3:49943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/333.php"] [unique_id "apPke46aRhSu8gis9LmHJgAABL4"]
[Sun Aug 30 03:06:19.529140 2026] [security2:error] [pid 496962:tid 497156] [client 158.23.184.117:54476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/wp-content/import.php"] [unique_id "apPke46aRhSu8gis9LmHKQAABO0"]
[Sun Aug 30 03:06:19.560213 2026] [authz_core:error] [pid 496962:tid 497206] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fvim%2Fvim82%2Flang
[Sun Aug 30 03:06:19.560693 2026] [authz_core:error] [pid 496962:tid 497206] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fvim%2Fvim82%2Flang
[Sun Aug 30 03:06:19.632576 2026] [security2:error] [pid 496962:tid 497184] [client 20.48.251.3:64395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/mga.php"] [unique_id "apPke46aRhSu8gis9LmHTwAABQk"]
[Sun Aug 30 03:06:19.636435 2026] [authz_core:error] [pid 496962:tid 497176] [client 216.73.216.128:50876] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:19.636859 2026] [authz_core:error] [pid 496962:tid 497176] [client 216.73.216.128:50876] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:19.669920 2026] [security2:error] [pid 496962:tid 497213] [client 68.155.159.216:56343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPke46aRhSu8gis9LmHXgAABSY"]
[Sun Aug 30 03:06:19.669945 2026] [security2:error] [pid 496962:tid 497107] [client 158.23.184.117:54484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/wp-includes/fonts/admin.php"] [unique_id "apPke46aRhSu8gis9LmHXwAABLw"]
[Sun Aug 30 03:06:19.710106 2026] [security2:error] [pid 496962:tid 497104] [client 158.23.147.79:54216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apPke46aRhSu8gis9LmHZAAABLk"]
[Sun Aug 30 03:06:19.717677 2026] [security2:error] [pid 496962:tid 497170] [client 20.197.61.180:21058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/oceanwp/sass/components/plugins/panel.php"] [unique_id "apPke46aRhSu8gis9LmHaAAABPs"]
[Sun Aug 30 03:06:19.730212 2026] [authz_core:error] [pid 496962:tid 497202] [client 216.73.216.128:39775] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:19.730690 2026] [authz_core:error] [pid 496962:tid 497202] [client 216.73.216.128:39775] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:19.767592 2026] [security2:error] [pid 496962:tid 497178] [client 20.104.50.220:28698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/old-index.php"] [unique_id "apPke46aRhSu8gis9LmHeQAABQM"]
[Sun Aug 30 03:06:19.811175 2026] [security2:error] [pid 496962:tid 497199] [client 158.23.184.117:7242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/222.php"] [unique_id "apPke46aRhSu8gis9LmHgAAABRg"]
[Sun Aug 30 03:06:19.814664 2026] [authz_core:error] [pid 496962:tid 497155] [client 66.249.66.64:61098] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:19.815165 2026] [authz_core:error] [pid 496962:tid 497155] [client 66.249.66.64:61098] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:19.821840 2026] [authz_core:error] [pid 496962:tid 497185] [client 216.73.216.128:59856] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:19.822280 2026] [authz_core:error] [pid 496962:tid 497185] [client 216.73.216.128:59856] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:19.842582 2026] [security2:error] [pid 496962:tid 497106] [client 20.48.251.3:64281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/old_phpinfo.php"] [unique_id "apPke46aRhSu8gis9LmHhwAABLs"]
[Sun Aug 30 03:06:19.877450 2026] [security2:error] [pid 496962:tid 497110] [client 40.83.93.50:12037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/sf.php"] [unique_id "apPke46aRhSu8gis9LmHkgAABL8"]
[Sun Aug 30 03:06:19.893289 2026] [security2:error] [pid 496962:tid 497129] [client 20.151.200.44:55712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/ssh3ll.php"] [unique_id "apPke46aRhSu8gis9LmHlQAABNI"]
[Sun Aug 30 03:06:19.937928 2026] [security2:error] [pid 496962:tid 497192] [client 68.155.159.216:52668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-content/x.php"] [unique_id "apPke46aRhSu8gis9LmHngAABRE"]
[Sun Aug 30 03:06:19.946113 2026] [security2:error] [pid 496962:tid 497145] [client 158.23.147.79:54227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-content/plugins/index.php"] [unique_id "apPke46aRhSu8gis9LmHoQAABOI"]
[Sun Aug 30 03:06:19.960937 2026] [security2:error] [pid 496962:tid 497154] [client 158.23.184.117:7901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/wp-content/languages.php"] [unique_id "apPke46aRhSu8gis9LmHpgAABOs"]
[Sun Aug 30 03:06:19.962398 2026] [security2:error] [pid 496962:tid 497134] [client 20.104.50.220:32899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/bingo.php"] [unique_id "apPke46aRhSu8gis9LmHqAAABNc"]
[Sun Aug 30 03:06:19.966426 2026] [security2:error] [pid 496962:tid 497208] [client 20.104.50.220:61389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/aaaa.php"] [unique_id "apPke46aRhSu8gis9LmHqgAABSE"]
[Sun Aug 30 03:06:19.983069 2026] [security2:error] [pid 496962:tid 497206] [client 68.155.159.216:61351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/asd.php"] [unique_id "apPke46aRhSu8gis9LmHrgAABR8"]
[Sun Aug 30 03:06:19.995286 2026] [security2:error] [pid 496962:tid 497147] [client 45.3.55.204:12169] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "belloinsights.com"] [uri "/"] [unique_id "apPke46aRhSu8gis9LmHsgAABOQ"]
[Sun Aug 30 03:06:20.000595 2026] [authz_core:error] [pid 496962:tid 497135] [client 216.73.216.128:50876] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:20.000940 2026] [authz_core:error] [pid 496962:tid 497135] [client 216.73.216.128:50876] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:20.073248 2026] [security2:error] [pid 496962:tid 497156] [client 20.104.50.220:52835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/sj.php"] [unique_id "apPkfI6aRhSu8gis9LmHwAAABO0"]
[Sun Aug 30 03:06:20.074312 2026] [authz_core:error] [pid 496962:tid 497126] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fvim%2Fvim82%2Flang
[Sun Aug 30 03:06:20.074758 2026] [authz_core:error] [pid 496962:tid 497126] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fvim%2Fvim82%2Flang
[Sun Aug 30 03:06:20.091170 2026] [authz_core:error] [pid 496962:tid 497100] [client 216.73.216.128:13319] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:20.091485 2026] [authz_core:error] [pid 496962:tid 497100] [client 216.73.216.128:13319] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:20.103118 2026] [security2:error] [pid 496962:tid 497205] [client 158.23.184.117:7899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/wp-config-sample.php"] [unique_id "apPkfI6aRhSu8gis9LmHxgAABR4"]
[Sun Aug 30 03:06:20.129316 2026] [security2:error] [pid 496962:tid 497192] [client 20.104.18.15:13672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/vpn.php"] [unique_id "apPkfI6aRhSu8gis9LmHygAABRE"]
[Sun Aug 30 03:06:20.149127 2026] [security2:error] [pid 496962:tid 497122] [client 20.104.50.220:27430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/var/sites/gtag.php"] [unique_id "apPkfI6aRhSu8gis9LmHzAAABMs"]
[Sun Aug 30 03:06:20.164605 2026] [authz_core:error] [pid 496962:tid 497188] [client 66.249.66.42:54329] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:20.164911 2026] [authz_core:error] [pid 496962:tid 497188] [client 66.249.66.42:54329] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:20.230177 2026] [security2:error] [pid 496962:tid 497128] [client 20.104.18.15:43910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/33.php"] [unique_id "apPkfI6aRhSu8gis9LmH5wAABNE"]
[Sun Aug 30 03:06:20.243960 2026] [security2:error] [pid 496962:tid 497206] [client 158.23.184.117:7894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/wp-admin/install-helper.php"] [unique_id "apPkfI6aRhSu8gis9LmH6gAABR8"]
[Sun Aug 30 03:06:20.272867 2026] [security2:error] [pid 496962:tid 497110] [client 114.119.148.64:35937] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "redlandspawninc.com"] [uri "/jewelry/"] [unique_id "apPkfI6aRhSu8gis9LmH8gAABL8"], referer: https://redlandspawninc.com/jewelry/
[Sun Aug 30 03:06:20.273138 2026] [authz_core:error] [pid 496962:tid 497104] [client 216.73.216.128:39775] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:20.273516 2026] [authz_core:error] [pid 496962:tid 497104] [client 216.73.216.128:39775] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:20.290440 2026] [security2:error] [pid 496962:tid 497170] [client 20.48.251.3:4845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/loxi-o.php"] [unique_id "apPkfI6aRhSu8gis9LmH9AAABPs"]
[Sun Aug 30 03:06:20.341760 2026] [security2:error] [pid 496962:tid 497181] [client 20.104.50.220:42022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/cakt.php"] [unique_id "apPkfI6aRhSu8gis9LmH_AAABQY"]
[Sun Aug 30 03:06:20.353876 2026] [security2:error] [pid 496962:tid 497168] [client 20.104.50.220:46192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/marijuana.php"] [unique_id "apPkfI6aRhSu8gis9LmH_wAABPk"]
[Sun Aug 30 03:06:20.372474 2026] [security2:error] [pid 496962:tid 497173] [client 68.155.159.216:65496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/ws.php"] [unique_id "apPkfI6aRhSu8gis9LmIBgAABP4"]
[Sun Aug 30 03:06:20.387483 2026] [security2:error] [pid 496962:tid 497193] [client 158.23.184.117:54520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/wp-includes/fonts/classmap.php"] [unique_id "apPkfI6aRhSu8gis9LmICgAABRI"]
[Sun Aug 30 03:06:20.410823 2026] [security2:error] [pid 496962:tid 497176] [client 20.104.18.15:32978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/wp-aothait.php"] [unique_id "apPkfI6aRhSu8gis9LmIEwAABQE"]
[Sun Aug 30 03:06:20.422587 2026] [security2:error] [pid 496962:tid 497159] [client 20.197.61.180:14064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/options.php"] [unique_id "apPkfI6aRhSu8gis9LmIFwAABPA"]
[Sun Aug 30 03:06:20.432422 2026] [security2:error] [pid 496962:tid 497184] [client 20.104.49.130:63249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/sym.php"] [unique_id "apPkfI6aRhSu8gis9LmIHQAABQk"]
[Sun Aug 30 03:06:20.497928 2026] [security2:error] [pid 496962:tid 497209] [client 40.83.93.50:9312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/gel4y.php"] [unique_id "apPkfI6aRhSu8gis9LmIMAAABSI"]
[Sun Aug 30 03:06:20.516136 2026] [security2:error] [pid 496962:tid 497217] [client 20.48.251.3:44123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/filesystems.php"] [unique_id "apPkfI6aRhSu8gis9LmIOQAABSo"]
[Sun Aug 30 03:06:20.526122 2026] [security2:error] [pid 496962:tid 497148] [client 158.23.147.79:54231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/simple.php"] [unique_id "apPkfI6aRhSu8gis9LmIPwAABOU"]
[Sun Aug 30 03:06:20.529221 2026] [security2:error] [pid 496962:tid 497187] [client 158.23.184.117:7257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/adminfuns.php/.well-known/acme-challenge/file.php"] [unique_id "apPkfI6aRhSu8gis9LmIQQAABQw"]
[Sun Aug 30 03:06:20.560368 2026] [security2:error] [pid 496962:tid 497137] [client 20.151.200.44:65333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/wp-admin/js/index.php"] [unique_id "apPkfI6aRhSu8gis9LmISwAABNo"]
[Sun Aug 30 03:06:20.575979 2026] [security2:error] [pid 496962:tid 497119] [client 20.104.50.220:5911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/file9.php"] [unique_id "apPkfI6aRhSu8gis9LmIUAAABMg"]
[Sun Aug 30 03:06:20.583022 2026] [security2:error] [pid 496962:tid 497147] [client 20.104.50.220:31909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/bj.php"] [unique_id "apPkfI6aRhSu8gis9LmIVgAABOQ"]
[Sun Aug 30 03:06:20.605970 2026] [security2:error] [pid 496962:tid 497216] [client 68.155.159.216:54112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/images/index.php"] [unique_id "apPkfI6aRhSu8gis9LmIYQAABSk"]
[Sun Aug 30 03:06:20.609654 2026] [security2:error] [pid 496962:tid 497107] [client 143.244.166.58:43216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.166.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dqnorthshore.com"] [uri "/wp-login.php"] [unique_id "apPkfI6aRhSu8gis9LmIWAAABLw"]
[Sun Aug 30 03:06:20.658774 2026] [security2:error] [pid 496962:tid 497195] [client 20.48.251.3:55431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/G-in.php"] [unique_id "apPkfI6aRhSu8gis9LmIewAABRQ"]
[Sun Aug 30 03:06:20.671175 2026] [security2:error] [pid 496962:tid 497149] [client 158.23.184.117:7907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/wp-content/themes/aa.php"] [unique_id "apPkfI6aRhSu8gis9LmIfAAABOY"]
[Sun Aug 30 03:06:20.689760 2026] [authz_core:error] [pid 496962:tid 497147] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fvim%2Fvim82%2Flang
[Sun Aug 30 03:06:20.690046 2026] [authz_core:error] [pid 496962:tid 497147] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fvim%2Fvim82%2Flang
[Sun Aug 30 03:06:20.692313 2026] [security2:error] [pid 496962:tid 497205] [client 68.155.159.216:62310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPkfI6aRhSu8gis9LmIfgAABR4"]
[Sun Aug 30 03:06:20.798691 2026] [security2:error] [pid 496962:tid 497099] [client 4.205.62.107:51713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/asdf.php"] [unique_id "apPkfI6aRhSu8gis9LmImAAABLQ"]
[Sun Aug 30 03:06:20.813536 2026] [security2:error] [pid 496962:tid 497135] [client 158.23.184.117:7909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/chosen.php"] [unique_id "apPkfI6aRhSu8gis9LmInQAABNg"]
[Sun Aug 30 03:06:20.844748 2026] [security2:error] [pid 496962:tid 497096] [client 68.155.159.216:11243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apPkfI6aRhSu8gis9LmIpQAABLE"]
[Sun Aug 30 03:06:20.905196 2026] [security2:error] [pid 496962:tid 497186] [client 20.104.50.220:28712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/ocgi.php"] [unique_id "apPkfI6aRhSu8gis9LmItQAABQs"]
[Sun Aug 30 03:06:20.909945 2026] [authz_core:error] [pid 496962:tid 497190] [client 216.73.216.128:21593] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:20.910287 2026] [authz_core:error] [pid 496962:tid 497190] [client 216.73.216.128:21593] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:20.914179 2026] [security2:error] [pid 496962:tid 497162] [client 51.68.236.68:10959] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "1899project.com"] [uri "/robots.txt"] [unique_id "apPkfI6aRhSu8gis9LmIuAAABPM"]
[Sun Aug 30 03:06:20.914300 2026] [security2:error] [pid 496962:tid 497162] [client 51.68.236.68:10959] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "1899project.com"] [uri "/robots.txt"] [unique_id "apPkfI6aRhSu8gis9LmIuAAABPM"]
[Sun Aug 30 03:06:20.947159 2026] [security2:error] [pid 496962:tid 497135] [client 158.23.147.79:54234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-admin/about.php"] [unique_id "apPkfI6aRhSu8gis9LmIwAAABNg"]
[Sun Aug 30 03:06:20.953534 2026] [security2:error] [pid 496962:tid 497176] [client 158.23.184.117:7916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/admin/function.php"] [unique_id "apPkfI6aRhSu8gis9LmIwwAABQE"]
[Sun Aug 30 03:06:20.954157 2026] [security2:error] [pid 496962:tid 497122] [client 20.104.49.130:48011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/ops.php"] [unique_id "apPkfI6aRhSu8gis9LmIxAAABMs"]
[Sun Aug 30 03:06:20.961976 2026] [security2:error] [pid 496962:tid 497180] [client 20.104.49.130:57646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/txets.php"] [unique_id "apPkfI6aRhSu8gis9LmIxwAABQU"]
[Sun Aug 30 03:06:20.982033 2026] [security2:error] [pid 496962:tid 497211] [client 20.48.251.3:54753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.direcorgigames.com"] [uri "/wp-act.php"] [unique_id "apPkfI6aRhSu8gis9LmIyQAABSQ"]
[Sun Aug 30 03:06:21.003660 2026] [security2:error] [pid 496962:tid 497198] [client 40.83.93.50:12039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/leaf.php"] [unique_id "apPkfY6aRhSu8gis9LmI1AAABRc"]
[Sun Aug 30 03:06:21.044860 2026] [security2:error] [pid 496962:tid 497205] [client 68.155.159.216:54774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPkfY6aRhSu8gis9LmI3QAABR4"]
[Sun Aug 30 03:06:21.094732 2026] [security2:error] [pid 496962:tid 497149] [client 158.23.184.117:7903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/wxo.php"] [unique_id "apPkfY6aRhSu8gis9LmI5wAABOY"]
[Sun Aug 30 03:06:21.103471 2026] [security2:error] [pid 496962:tid 497162] [client 20.104.50.220:33203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/backd00rshit.php"] [unique_id "apPkfY6aRhSu8gis9LmI6AAABPM"]
[Sun Aug 30 03:06:21.111174 2026] [security2:error] [pid 496962:tid 497111] [client 20.104.50.220:61648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/cinfo.php"] [unique_id "apPkfY6aRhSu8gis9LmI6QAABMA"]
[Sun Aug 30 03:06:21.148117 2026] [security2:error] [pid 496962:tid 497212] [client 20.197.61.180:21066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/panel.php"] [unique_id "apPkfY6aRhSu8gis9LmI7wAABSU"]
[Sun Aug 30 03:06:21.164083 2026] [security2:error] [pid 496962:tid 497114] [client 158.23.147.79:54243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-content/uploads/index.php"] [unique_id "apPkfY6aRhSu8gis9LmI9AAABMM"]
[Sun Aug 30 03:06:21.171241 2026] [authz_core:error] [pid 496962:tid 497155] [client 66.249.66.71:39040] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:21.171477 2026] [security2:error] [pid 496962:tid 497163] [client 20.220.10.235:47029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.centrofruttadue.it"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkfY6aRhSu8gis9LmI9wAABPQ"]
[Sun Aug 30 03:06:21.171534 2026] [authz_core:error] [pid 496962:tid 497155] [client 66.249.66.71:39040] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:21.183626 2026] [authz_core:error] [pid 496962:tid 497171] [client 216.73.216.128:38092] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:21.184109 2026] [authz_core:error] [pid 496962:tid 497171] [client 216.73.216.128:38092] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:21.224377 2026] [security2:error] [pid 496962:tid 497182] [client 20.104.50.220:29140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/gca.php"] [unique_id "apPkfY6aRhSu8gis9LmJAAAABQc"]
[Sun Aug 30 03:06:21.230712 2026] [security2:error] [pid 496962:tid 497199] [client 45.3.55.204:50229] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "belloinsights.com"] [uri "/wp-json/batch/v1"] [unique_id "apPkfY6aRhSu8gis9LmJAQAABRg"]
[Sun Aug 30 03:06:21.238459 2026] [security2:error] [pid 496962:tid 497119] [client 158.23.184.117:7875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/wp-admin/theme-editor.php"] [unique_id "apPkfY6aRhSu8gis9LmJAgAABMg"]
[Sun Aug 30 03:06:21.290100 2026] [security2:error] [pid 496962:tid 497195] [client 20.104.50.220:27452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/wp-load.php"] [unique_id "apPkfY6aRhSu8gis9LmJEAAABRQ"]
[Sun Aug 30 03:06:21.296895 2026] [security2:error] [pid 496962:tid 497129] [client 20.104.18.15:13673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/shiny.php"] [unique_id "apPkfY6aRhSu8gis9LmJEgAABNI"]
[Sun Aug 30 03:06:21.368118 2026] [security2:error] [pid 496962:tid 497120] [client 20.104.18.15:43275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/133.php"] [unique_id "apPkfY6aRhSu8gis9LmJJAAABMk"]
[Sun Aug 30 03:06:21.436983 2026] [security2:error] [pid 496962:tid 497219] [client 20.48.251.3:4721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/f35.php"] [unique_id "apPkfY6aRhSu8gis9LmJOwAABSw"]
[Sun Aug 30 03:06:21.451480 2026] [authz_core:error] [pid 496962:tid 497178] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fvim%2Fvim82%2Flang
[Sun Aug 30 03:06:21.451780 2026] [authz_core:error] [pid 496962:tid 497178] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fvim%2Fvim82%2Flang
[Sun Aug 30 03:06:21.473923 2026] [security2:error] [pid 496962:tid 497196] [client 158.23.147.79:54270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apPkfY6aRhSu8gis9LmJRwAABRU"]
[Sun Aug 30 03:06:21.480581 2026] [security2:error] [pid 496962:tid 497123] [client 20.104.50.220:51587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/CytoXploit.php"] [unique_id "apPkfY6aRhSu8gis9LmJSQAABMw"]
[Sun Aug 30 03:06:21.482709 2026] [security2:error] [pid 496962:tid 497101] [client 158.23.184.117:54477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/termps.php"] [unique_id "apPkfY6aRhSu8gis9LmJSgAABLY"]
[Sun Aug 30 03:06:21.502519 2026] [security2:error] [pid 496962:tid 497143] [client 20.104.50.220:46429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/mas.php"] [unique_id "apPkfY6aRhSu8gis9LmJUQAABOA"]
[Sun Aug 30 03:06:21.523861 2026] [security2:error] [pid 496962:tid 497193] [client 195.160.216.121:35704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.216.160.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "migrationconsultants.net"] [uri "/wp-login.php"] [unique_id "apPkfY6aRhSu8gis9LmJXAAABRI"]
[Sun Aug 30 03:06:21.533485 2026] [security2:error] [pid 496962:tid 497096] [client 68.155.159.216:12349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-includes/css/index.php"] [unique_id "apPkfY6aRhSu8gis9LmJXwAABLE"]
[Sun Aug 30 03:06:21.553224 2026] [security2:error] [pid 496962:tid 497106] [client 20.104.18.15:32982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/wp-includes/index.php"] [unique_id "apPkfY6aRhSu8gis9LmJZgAABLs"]
[Sun Aug 30 03:06:21.584014 2026] [security2:error] [pid 496962:tid 497121] [client 158.23.147.79:54213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/chosen.php"] [unique_id "apPkfY6aRhSu8gis9LmJdAAABMo"]
[Sun Aug 30 03:06:21.639964 2026] [security2:error] [pid 496962:tid 497216] [client 20.151.200.44:64684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/t00l.php"] [unique_id "apPkfY6aRhSu8gis9LmJiQAABSk"]
[Sun Aug 30 03:06:21.642801 2026] [security2:error] [pid 496962:tid 497194] [client 158.23.184.117:54517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/fix.php"] [unique_id "apPkfY6aRhSu8gis9LmJjQAABRM"]
[Sun Aug 30 03:06:21.653126 2026] [authz_core:error] [pid 496962:tid 497148] [client 66.249.66.32:58443] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:21.653604 2026] [authz_core:error] [pid 496962:tid 497148] [client 66.249.66.32:58443] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:21.706557 2026] [security2:error] [pid 496962:tid 497145] [client 158.23.147.79:54238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/goods.php"] [unique_id "apPkfY6aRhSu8gis9LmJnAAABOI"]
[Sun Aug 30 03:06:21.736347 2026] [security2:error] [pid 496962:tid 497123] [client 20.104.50.220:32398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/black.php"] [unique_id "apPkfY6aRhSu8gis9LmJqgAABMw"]
[Sun Aug 30 03:06:21.746746 2026] [security2:error] [pid 496962:tid 497156] [client 20.104.50.220:5627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/ac.php"] [unique_id "apPkfY6aRhSu8gis9LmJrgAABO0"]
[Sun Aug 30 03:06:21.766225 2026] [security2:error] [pid 496962:tid 497183] [client 40.83.93.50:9310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/k.php"] [unique_id "apPkfY6aRhSu8gis9LmJtAAABQg"]
[Sun Aug 30 03:06:21.788251 2026] [security2:error] [pid 496962:tid 497101] [client 158.23.184.117:7880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/wp-includes/ID3/admin.php"] [unique_id "apPkfY6aRhSu8gis9LmJvQAABLY"]
[Sun Aug 30 03:06:21.796180 2026] [security2:error] [pid 496962:tid 497134] [client 20.48.251.3:55498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/apikeys.php"] [unique_id "apPkfY6aRhSu8gis9LmJxQAABNc"]
[Sun Aug 30 03:06:21.848062 2026] [security2:error] [pid 496962:tid 497159] [client 158.23.147.79:54255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apPkfY6aRhSu8gis9LmJ0gAABPA"]
[Sun Aug 30 03:06:21.872585 2026] [security2:error] [pid 496962:tid 497116] [client 20.104.50.220:31909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/by.php"] [unique_id "apPkfY6aRhSu8gis9LmJ2wAABMU"]
[Sun Aug 30 03:06:21.875909 2026] [security2:error] [pid 496962:tid 497204] [client 20.197.61.180:21061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/reboot/assets/js/plugins/home.php"] [unique_id "apPkfY6aRhSu8gis9LmJ3QAABR0"]
[Sun Aug 30 03:06:21.904058 2026] [security2:error] [pid 496962:tid 497128] [client 68.155.159.216:59943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apPkfY6aRhSu8gis9LmJ4QAABNE"]
[Sun Aug 30 03:06:21.909113 2026] [security2:error] [pid 496962:tid 497131] [client 20.151.200.44:47392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/ls.php"] [unique_id "apPkfY6aRhSu8gis9LmJ4gAABNQ"]
[Sun Aug 30 03:06:21.929974 2026] [security2:error] [pid 496962:tid 497207] [client 158.23.184.117:7897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/tiny.php"] [unique_id "apPkfY6aRhSu8gis9LmJ7gAABSA"]
[Sun Aug 30 03:06:21.949297 2026] [security2:error] [pid 496962:tid 497135] [client 158.23.147.79:54224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-admin/includes/nav.php"] [unique_id "apPkfY6aRhSu8gis9LmJ-AAABNg"]
[Sun Aug 30 03:06:21.955105 2026] [authz_core:error] [pid 496962:tid 497163] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fsasl2
[Sun Aug 30 03:06:21.955533 2026] [authz_core:error] [pid 496962:tid 497163] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib64%2Fsasl2
[Sun Aug 30 03:06:21.968241 2026] [security2:error] [pid 496962:tid 497112] [client 68.155.159.216:62274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-includes/Requests/network.php"] [unique_id "apPkfY6aRhSu8gis9LmJ_gAABME"]
[Sun Aug 30 03:06:21.971617 2026] [security2:error] [pid 496962:tid 497138] [client 68.155.159.216:56360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-content/radio.php"] [unique_id "apPkfY6aRhSu8gis9LmJ_wAABNs"]
[Sun Aug 30 03:06:22.069809 2026] [security2:error] [pid 496962:tid 497205] [client 158.23.184.117:7878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/css/classwithtostring.php"] [unique_id "apPkfo6aRhSu8gis9LmKHQAABR4"]
[Sun Aug 30 03:06:22.075855 2026] [security2:error] [pid 496962:tid 497127] [client 20.104.50.220:29607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/ngocokpeli.php"] [unique_id "apPkfo6aRhSu8gis9LmKIQAABNA"]
[Sun Aug 30 03:06:22.161762 2026] [autoindex:error] [pid 496962:tid 497160] [client 34.230.146.223:6866] AH01276: Cannot serve directory /home3/errestor/theone2call.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:06:22.179033 2026] [security2:error] [pid 496962:tid 497182] [client 68.155.159.216:19349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/log-mama/function.php"] [unique_id "apPkfo6aRhSu8gis9LmKMQAABQc"]
[Sun Aug 30 03:06:22.211722 2026] [security2:error] [pid 496962:tid 497197] [client 158.23.184.117:54516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/buy.php"] [unique_id "apPkfo6aRhSu8gis9LmKOQAABRY"]
[Sun Aug 30 03:06:22.211918 2026] [security2:error] [pid 496962:tid 497116] [client 158.23.147.79:54245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/file.php"] [unique_id "apPkfo6aRhSu8gis9LmKOgAABMU"]
[Sun Aug 30 03:06:22.230104 2026] [security2:error] [pid 496962:tid 497128] [client 68.155.159.216:61333] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "djsevenevents.com"] [uri "/1.php"] [unique_id "apPkfo6aRhSu8gis9LmKPQAABNE"]
[Sun Aug 30 03:06:22.230236 2026] [security2:error] [pid 496962:tid 497128] [client 68.155.159.216:61333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/1.php"] [unique_id "apPkfo6aRhSu8gis9LmKPQAABNE"]
[Sun Aug 30 03:06:22.242703 2026] [security2:error] [pid 496962:tid 497109] [client 20.104.50.220:33078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/ichi.php"] [unique_id "apPkfo6aRhSu8gis9LmKPwAABL4"]
[Sun Aug 30 03:06:22.261013 2026] [security2:error] [pid 496962:tid 497131] [client 20.151.200.44:64600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/ls.php"] [unique_id "apPkfo6aRhSu8gis9LmKRQAABNQ"]
[Sun Aug 30 03:06:22.270122 2026] [security2:error] [pid 496962:tid 497094] [client 20.104.50.220:61994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/newfile.php"] [unique_id "apPkfo6aRhSu8gis9LmKSQAABK8"]
[Sun Aug 30 03:06:22.276328 2026] [security2:error] [pid 496962:tid 497155] [client 216.73.216.128:38092] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPkfo6aRhSu8gis9LmKSgAABOw"]
[Sun Aug 30 03:06:22.346083 2026] [security2:error] [pid 496962:tid 497188] [client 45.3.55.204:54203] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "belloinsights.com"] [uri "/"] [unique_id "apPkfo6aRhSu8gis9LmKUwAABQ0"]
[Sun Aug 30 03:06:22.350812 2026] [security2:error] [pid 496962:tid 497146] [client 158.23.147.79:54257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/file17.php"] [unique_id "apPkfo6aRhSu8gis9LmKVAAABOM"]
[Sun Aug 30 03:06:22.353109 2026] [security2:error] [pid 496962:tid 497201] [client 158.23.184.117:7906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/bk.php"] [unique_id "apPkfo6aRhSu8gis9LmKVwAABRo"]
[Sun Aug 30 03:06:22.358839 2026] [security2:error] [pid 496962:tid 497185] [client 20.104.50.220:28698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/koe.php"] [unique_id "apPkfo6aRhSu8gis9LmKWwAABQo"]
[Sun Aug 30 03:06:22.385226 2026] [security2:error] [pid 496962:tid 497203] [client 40.83.93.50:12085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/chosen.php"] [unique_id "apPkfo6aRhSu8gis9LmKZAAABRw"]
[Sun Aug 30 03:06:22.428873 2026] [security2:error] [pid 496962:tid 497168] [client 20.104.50.220:27093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/admin/login.php"] [unique_id "apPkfo6aRhSu8gis9LmKbwAABPk"]
[Sun Aug 30 03:06:22.441659 2026] [security2:error] [pid 496962:tid 497195] [client 20.151.200.44:47000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/wk/index.php"] [unique_id "apPkfo6aRhSu8gis9LmKdAAABRQ"]
[Sun Aug 30 03:06:22.465811 2026] [authz_core:error] [pid 496962:tid 497094] [client 216.73.216.128:47242] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:22.466092 2026] [authz_core:error] [pid 496962:tid 497094] [client 216.73.216.128:47242] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:22.467387 2026] [security2:error] [pid 496962:tid 497189] [client 20.104.18.15:13707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/goods.php"] [unique_id "apPkfo6aRhSu8gis9LmKewAABQ4"]
[Sun Aug 30 03:06:22.506041 2026] [authz_core:error] [pid 496962:tid 497151] [client 66.249.66.39:36813] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:22.506387 2026] [authz_core:error] [pid 496962:tid 497151] [client 66.249.66.39:36813] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:22.510565 2026] [security2:error] [pid 496962:tid 497115] [client 158.23.184.117:54486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/.trash7309/index.php"] [unique_id "apPkfo6aRhSu8gis9LmKjAAABMQ"]
[Sun Aug 30 03:06:22.526154 2026] [security2:error] [pid 496962:tid 497126] [client 20.104.18.15:44008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/sym.php"] [unique_id "apPkfo6aRhSu8gis9LmKlAAABM8"]
[Sun Aug 30 03:06:22.574753 2026] [security2:error] [pid 496962:tid 497109] [client 20.48.251.3:44357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/api.php"] [unique_id "apPkfo6aRhSu8gis9LmKogAABL4"]
[Sun Aug 30 03:06:22.597743 2026] [security2:error] [pid 496962:tid 497144] [client 20.197.61.180:14068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/salient/css/build/plugins/login.php"] [unique_id "apPkfo6aRhSu8gis9LmKqgAABOE"]
[Sun Aug 30 03:06:22.614494 2026] [security2:error] [pid 496962:tid 497129] [client 158.23.147.79:54251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/file5.php"] [unique_id "apPkfo6aRhSu8gis9LmKrQAABNI"]
[Sun Aug 30 03:06:22.631969 2026] [security2:error] [pid 496962:tid 497196] [client 20.104.50.220:42783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/ccc.php"] [unique_id "apPkfo6aRhSu8gis9LmKtAAABRU"]
[Sun Aug 30 03:06:22.643392 2026] [security2:error] [pid 496962:tid 497170] [client 20.104.50.220:46638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/mini.php"] [unique_id "apPkfo6aRhSu8gis9LmKvQAABPs"]
[Sun Aug 30 03:06:22.649029 2026] [authz_core:error] [pid 496962:tid 497164] [client 216.73.216.128:47242] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:22.649309 2026] [authz_core:error] [pid 496962:tid 497164] [client 216.73.216.128:47242] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:22.654895 2026] [security2:error] [pid 496962:tid 497209] [client 158.23.184.117:54510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/jp.php"] [unique_id "apPkfo6aRhSu8gis9LmKwQAABSI"]
[Sun Aug 30 03:06:22.688812 2026] [security2:error] [pid 496962:tid 497185] [client 68.155.159.216:12306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apPkfo6aRhSu8gis9LmKxwAABQo"]
[Sun Aug 30 03:06:22.719353 2026] [security2:error] [pid 496962:tid 497142] [client 20.104.18.15:33018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/file31.php"] [unique_id "apPkfo6aRhSu8gis9LmKzQAABN8"]
[Sun Aug 30 03:06:22.742448 2026] [core:alert] [pid 496962:tid 497117] [client 176.105.217.117:27362] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:06:22.793997 2026] [security2:error] [pid 496962:tid 497104] [client 158.23.184.117:7887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/item.php"] [unique_id "apPkfo6aRhSu8gis9LmK8QAABLk"]
[Sun Aug 30 03:06:22.795415 2026] [security2:error] [pid 496962:tid 497210] [client 158.23.147.79:54229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/file88.php"] [unique_id "apPkfo6aRhSu8gis9LmK8gAABSM"]
[Sun Aug 30 03:06:22.892388 2026] [security2:error] [pid 496962:tid 497197] [client 40.83.93.50:12070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/radio.php"] [unique_id "apPkfo6aRhSu8gis9LmLDgAABRY"]
[Sun Aug 30 03:06:22.893494 2026] [authz_core:error] [pid 496962:tid 497094] [client 66.249.66.32:58443] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:22.893783 2026] [authz_core:error] [pid 496962:tid 497094] [client 66.249.66.32:58443] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:22.899071 2026] [security2:error] [pid 496962:tid 497151] [client 20.104.50.220:5923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/new4.php"] [unique_id "apPkfo6aRhSu8gis9LmLEAAABOg"]
[Sun Aug 30 03:06:22.902081 2026] [security2:error] [pid 496962:tid 497191] [client 158.23.147.79:53532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/NewFile.php/"] [unique_id "apPkfo6aRhSu8gis9LmLEQAABRA"]
[Sun Aug 30 03:06:22.912193 2026] [security2:error] [pid 496962:tid 497168] [client 20.151.200.44:24581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/css/000.php"] [unique_id "apPkfo6aRhSu8gis9LmLFQAABPk"]
[Sun Aug 30 03:06:22.929532 2026] [security2:error] [pid 496962:tid 497144] [client 20.48.251.3:7413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/tax.php"] [unique_id "apPkfo6aRhSu8gis9LmLGwAABOE"]
[Sun Aug 30 03:06:22.933293 2026] [security2:error] [pid 496962:tid 497117] [client 158.23.184.117:7891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/wp-admin/controller.php"] [unique_id "apPkfo6aRhSu8gis9LmLHQAABMY"]
[Sun Aug 30 03:06:22.946427 2026] [security2:error] [pid 496962:tid 497133] [client 20.48.251.3:50001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/motu.php"] [unique_id "apPkfo6aRhSu8gis9LmLIAAABNY"]
[Sun Aug 30 03:06:22.966452 2026] [security2:error] [pid 496962:tid 497179] [client 68.155.159.216:62071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkfo6aRhSu8gis9LmLJQAABQQ"]
[Sun Aug 30 03:06:23.013789 2026] [security2:error] [pid 496962:tid 497116] [client 158.23.147.79:54239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/dropdown.php"] [unique_id "apPkf46aRhSu8gis9LmLNQAABMU"]
[Sun Aug 30 03:06:23.015315 2026] [security2:error] [pid 496962:tid 497111] [client 20.104.50.220:31878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/byp.php"] [unique_id "apPkf46aRhSu8gis9LmLNgAABMA"]
[Sun Aug 30 03:06:23.048738 2026] [security2:error] [pid 496962:tid 497150] [client 68.155.159.216:59994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apPkf46aRhSu8gis9LmLPAAABOc"]
[Sun Aug 30 03:06:23.063412 2026] [security2:error] [pid 496962:tid 497119] [client 20.151.200.44:64642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/css/000.php"] [unique_id "apPkf46aRhSu8gis9LmLQQAABMg"]
[Sun Aug 30 03:06:23.067464 2026] [security2:error] [pid 496962:tid 497200] [client 68.155.159.216:56331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apPkf46aRhSu8gis9LmLQgAABRk"]
[Sun Aug 30 03:06:23.072378 2026] [security2:error] [pid 496962:tid 497120] [client 157.90.155.240:33668] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "atstechsolution.com"] [uri "/index.html"] [unique_id "apPkf46aRhSu8gis9LmLQwAABMk"], referer: https://atstechsolution.com
[Sun Aug 30 03:06:23.151155 2026] [autoindex:error] [pid 496962:tid 497182] [client 158.23.184.117:7885] AH01276: Cannot serve directory /home1/cteteacher/OCTutoringcenter.com/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:06:23.197090 2026] [authz_core:error] [pid 496962:tid 497146] [client 216.73.216.128:5523] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:23.197327 2026] [security2:error] [pid 496962:tid 497139] [client 158.23.147.79:53504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/.well-known/index.php"] [unique_id "apPkf46aRhSu8gis9LmLYQAABNw"]
[Sun Aug 30 03:06:23.197374 2026] [security2:error] [pid 496962:tid 497149] [client 158.23.184.117:7885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/wp-configs.php"] [unique_id "apPkf46aRhSu8gis9LmLYgAABOY"]
[Sun Aug 30 03:06:23.197394 2026] [authz_core:error] [pid 496962:tid 497146] [client 216.73.216.128:5523] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:23.232686 2026] [security2:error] [pid 496962:tid 497111] [client 20.104.50.220:28687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/new_license.php"] [unique_id "apPkf46aRhSu8gis9LmLaQAABMA"]
[Sun Aug 30 03:06:23.287328 2026] [security2:error] [pid 496962:tid 497131] [client 68.155.159.216:52623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/bk/index.php"] [unique_id "apPkf46aRhSu8gis9LmLdwAABNQ"]
[Sun Aug 30 03:06:23.295547 2026] [security2:error] [pid 496962:tid 497151] [client 68.155.159.216:61634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-content/radio.php"] [unique_id "apPkf46aRhSu8gis9LmLewAABOg"]
[Sun Aug 30 03:06:23.315767 2026] [security2:error] [pid 496962:tid 497216] [client 20.197.61.180:3276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/security.php"] [unique_id "apPkf46aRhSu8gis9LmLgAAABSk"]
[Sun Aug 30 03:06:23.343943 2026] [security2:error] [pid 496962:tid 497142] [client 158.23.184.117:54469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/wp-admin/user/credits.php"] [unique_id "apPkf46aRhSu8gis9LmLiwAABN8"]
[Sun Aug 30 03:06:23.369960 2026] [security2:error] [pid 496962:tid 497092] [client 158.23.147.79:54246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-content/themes/too.php"] [unique_id "apPkf46aRhSu8gis9LmLlAAABK0"]
[Sun Aug 30 03:06:23.393182 2026] [security2:error] [pid 496962:tid 497149] [client 20.151.200.44:37769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/cy.php"] [unique_id "apPkf46aRhSu8gis9LmLnAAABOY"]
[Sun Aug 30 03:06:23.396402 2026] [security2:error] [pid 496962:tid 497173] [client 20.104.50.220:33073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/~.php"] [unique_id "apPkf46aRhSu8gis9LmLnwAABP4"]
[Sun Aug 30 03:06:23.396693 2026] [authz_core:error] [pid 496962:tid 497133] [client 216.73.216.128:5523] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:23.396965 2026] [authz_core:error] [pid 496962:tid 497133] [client 216.73.216.128:5523] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:23.398392 2026] [authz_core:error] [pid 496962:tid 497188] [client 66.249.66.41:35593] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:23.398798 2026] [authz_core:error] [pid 496962:tid 497188] [client 66.249.66.41:35593] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:23.456212 2026] [authz_core:error] [pid 496962:tid 497115] [client 66.249.66.73:62695] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:23.456477 2026] [authz_core:error] [pid 496962:tid 497115] [client 66.249.66.73:62695] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:23.458665 2026] [security2:error] [pid 496962:tid 497203] [client 20.104.50.220:61982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/pro.php"] [unique_id "apPkf46aRhSu8gis9LmLrAAABRw"]
[Sun Aug 30 03:06:23.474696 2026] [security2:error] [pid 496962:tid 497131] [client 158.23.147.79:54259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/radio.php"] [unique_id "apPkf46aRhSu8gis9LmLsQAABNQ"]
[Sun Aug 30 03:06:23.484021 2026] [security2:error] [pid 496962:tid 497180] [client 158.23.184.117:7919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "apPkf46aRhSu8gis9LmLtgAABQU"]
[Sun Aug 30 03:06:23.484491 2026] [security2:error] [pid 496962:tid 497121] [client 45.3.55.204:38115] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "belloinsights.com"] [uri "/"] [unique_id "apPkf46aRhSu8gis9LmLuAAABMo"]
[Sun Aug 30 03:06:23.484561 2026] [security2:error] [pid 496962:tid 497213] [client 216.73.216.128:38092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPkf46aRhSu8gis9LmLtwAABSY"]
[Sun Aug 30 03:06:23.507989 2026] [security2:error] [pid 496962:tid 497147] [client 68.155.159.216:61357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/ws.php"] [unique_id "apPkf46aRhSu8gis9LmLyAAABOQ"]
[Sun Aug 30 03:06:23.515245 2026] [security2:error] [pid 496962:tid 497126] [client 40.83.93.50:18073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/functions.php"] [unique_id "apPkf46aRhSu8gis9LmLzgAABM8"]
[Sun Aug 30 03:06:23.527841 2026] [security2:error] [pid 496962:tid 497171] [client 20.104.50.220:52809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/konten.php"] [unique_id "apPkf46aRhSu8gis9LmL0QAABPw"]
[Sun Aug 30 03:06:23.574417 2026] [security2:error] [pid 496962:tid 497111] [client 20.104.50.220:27085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/elrekt.php"] [unique_id "apPkf46aRhSu8gis9LmL4QAABMA"]
[Sun Aug 30 03:06:23.592987 2026] [security2:error] [pid 496962:tid 497211] [client 158.23.147.79:53505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPkf46aRhSu8gis9LmL6wAABSQ"]
[Sun Aug 30 03:06:23.644312 2026] [security2:error] [pid 496962:tid 497117] [client 158.23.184.117:54500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/.well-known/about/function.php"] [unique_id "apPkf46aRhSu8gis9LmL_AAABMY"]
[Sun Aug 30 03:06:23.646495 2026] [security2:error] [pid 496962:tid 497198] [client 20.104.18.15:13617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/alfa.php"] [unique_id "apPkf46aRhSu8gis9LmMAAAABRc"]
[Sun Aug 30 03:06:23.676497 2026] [security2:error] [pid 496962:tid 497207] [client 20.104.18.15:44005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/8.php"] [unique_id "apPkf46aRhSu8gis9LmMCAAABSA"]
[Sun Aug 30 03:06:23.713167 2026] [security2:error] [pid 496962:tid 497204] [client 20.48.251.3:5089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/temp.php"] [unique_id "apPkf46aRhSu8gis9LmMCwAABR0"]
[Sun Aug 30 03:06:23.718306 2026] [security2:error] [pid 496962:tid 497139] [client 158.23.147.79:53531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/makeasmtp.php"] [unique_id "apPkf46aRhSu8gis9LmMDwAABNw"]
[Sun Aug 30 03:06:23.757494 2026] [security2:error] [pid 496962:tid 497133] [client 20.151.200.44:55616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/motu.php"] [unique_id "apPkf46aRhSu8gis9LmMHgAABNY"]
[Sun Aug 30 03:06:23.773552 2026] [security2:error] [pid 496962:tid 497205] [client 20.104.50.220:51534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/cxc.php"] [unique_id "apPkf46aRhSu8gis9LmMJQAABR4"]
[Sun Aug 30 03:06:23.781126 2026] [security2:error] [pid 496962:tid 497106] [client 20.104.50.220:46462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/minik.php"] [unique_id "apPkf46aRhSu8gis9LmMKgAABLs"]
[Sun Aug 30 03:06:23.783612 2026] [core:error] [pid 496962:tid 497082] [remote 74.7.175.145:43610] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:06:23.783629 2026] [core:error] [pid 496962:tid 497082] [remote 74.7.175.145:43610] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:06:23.783790 2026] [security2:error] [pid 496962:tid 497152] [client 74.7.175.145:43610] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "www.website-7f8b0c5c.ucdss.com"] [uri "/website_7f8b0c5c/index.php"] [unique_id "apPkf46aRhSu8gis9LmMKAAE6Xc"]
[Sun Aug 30 03:06:23.785454 2026] [security2:error] [pid 496962:tid 497186] [client 158.23.184.117:7236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPkf46aRhSu8gis9LmMLAAABQs"]
[Sun Aug 30 03:06:23.800682 2026] [authz_core:error] [pid 496962:tid 497132] [client 66.249.66.65:62148] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:23.800997 2026] [authz_core:error] [pid 496962:tid 497132] [client 66.249.66.65:62148] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:23.841486 2026] [security2:error] [pid 496962:tid 497111] [client 158.23.147.79:54237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apPkf46aRhSu8gis9LmMOwAABMA"]
[Sun Aug 30 03:06:23.850109 2026] [security2:error] [pid 496962:tid 497131] [client 68.155.159.216:12323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-content/cong.php"] [unique_id "apPkf46aRhSu8gis9LmMPwAABNQ"]
[Sun Aug 30 03:06:23.866801 2026] [security2:error] [pid 496962:tid 497203] [client 20.104.49.130:57507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/kj.php"] [unique_id "apPkf46aRhSu8gis9LmMRQAABRw"]
[Sun Aug 30 03:06:23.871145 2026] [security2:error] [pid 496962:tid 497215] [client 20.104.18.15:33755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/dk.php"] [unique_id "apPkf46aRhSu8gis9LmMSQAABSg"]
[Sun Aug 30 03:06:23.923992 2026] [security2:error] [pid 496962:tid 497212] [client 158.23.184.117:7925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/gg.php"] [unique_id "apPkf46aRhSu8gis9LmMWAAABSU"]
[Sun Aug 30 03:06:23.983922 2026] [security2:error] [pid 496962:tid 497173] [client 20.151.200.44:64628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/cy.php"] [unique_id "apPkf46aRhSu8gis9LmMaAAABP4"]
[Sun Aug 30 03:06:23.988763 2026] [security2:error] [pid 496962:tid 497127] [client 40.83.93.50:18054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/elp.php"] [unique_id "apPkf46aRhSu8gis9LmMawAABNA"]
[Sun Aug 30 03:06:24.037157 2026] [security2:error] [pid 496962:tid 497126] [client 20.104.50.220:6138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/pop.php"] [unique_id "apPkgI6aRhSu8gis9LmMdwAABM8"]
[Sun Aug 30 03:06:24.038639 2026] [security2:error] [pid 496962:tid 497093] [client 20.197.61.180:21109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "apPkgI6aRhSu8gis9LmMeAAABK4"]
[Sun Aug 30 03:06:24.069732 2026] [security2:error] [pid 496962:tid 497157] [client 158.23.184.117:54492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/wp-admin/includes/post.php"] [unique_id "apPkgI6aRhSu8gis9LmMgAAABO4"]
[Sun Aug 30 03:06:24.076373 2026] [security2:error] [pid 496962:tid 497137] [client 158.23.147.79:53528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apPkgI6aRhSu8gis9LmMhQAABNo"]
[Sun Aug 30 03:06:24.088790 2026] [security2:error] [pid 496962:tid 497138] [client 20.48.251.3:55505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/public/mah.php.php"] [unique_id "apPkgI6aRhSu8gis9LmMiAAABNs"]
[Sun Aug 30 03:06:24.093602 2026] [security2:error] [pid 496962:tid 497099] [client 20.48.251.3:44098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPkgI6aRhSu8gis9LmMiQAABLQ"]
[Sun Aug 30 03:06:24.154699 2026] [security2:error] [pid 496962:tid 497195] [client 20.104.50.220:31924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/con.php"] [unique_id "apPkgI6aRhSu8gis9LmMlwAABRQ"]
[Sun Aug 30 03:06:24.191923 2026] [security2:error] [pid 496962:tid 497181] [client 68.155.159.216:11234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/login.php"] [unique_id "apPkgI6aRhSu8gis9LmMpQAABQY"]
[Sun Aug 30 03:06:24.255925 2026] [security2:error] [pid 496962:tid 497200] [client 158.23.184.117:7251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.octutoringcenter.octechnologysolutionscenter.com"] [uri "/wp-act.php"] [unique_id "apPkgI6aRhSu8gis9LmMtgAABRk"]
[Sun Aug 30 03:06:24.319684 2026] [authz_core:error] [pid 496962:tid 497147] [client 216.73.216.128:50876] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:24.320052 2026] [authz_core:error] [pid 496962:tid 497147] [client 216.73.216.128:50876] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:24.321395 2026] [authz_core:error] [pid 496962:tid 497106] [client 66.249.66.205:43355] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:24.321826 2026] [authz_core:error] [pid 496962:tid 497106] [client 66.249.66.205:43355] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:24.332930 2026] [security2:error] [pid 496962:tid 497110] [client 158.23.147.79:54608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-content/languages/about.php"] [unique_id "apPkgI6aRhSu8gis9LmMxgAABL8"]
[Sun Aug 30 03:06:24.334903 2026] [security2:error] [pid 496962:tid 497118] [client 68.155.159.216:59989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apPkgI6aRhSu8gis9LmMxwAABMc"]
[Sun Aug 30 03:06:24.396156 2026] [security2:error] [pid 496962:tid 497120] [client 68.155.159.216:52686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.onthedomain.com"] [uri "/first.php"] [unique_id "apPkgI6aRhSu8gis9LmM2wAABMk"]
[Sun Aug 30 03:06:24.409501 2026] [authz_core:error] [pid 496962:tid 497166] [client 216.73.216.128:5523] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:24.409789 2026] [authz_core:error] [pid 496962:tid 497166] [client 216.73.216.128:5523] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:24.426930 2026] [security2:error] [pid 496962:tid 497206] [client 20.104.50.220:63042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/miyabajingankoe.php"] [unique_id "apPkgI6aRhSu8gis9LmM5AAABR8"]
[Sun Aug 30 03:06:24.439346 2026] [security2:error] [pid 496962:tid 497112] [client 158.23.147.79:63286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPkgI6aRhSu8gis9LmM6wAABME"]
[Sun Aug 30 03:06:24.463104 2026] [authz_core:error] [pid 496962:tid 497200] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fhome4%2Fletter7%2Fpublic_html%2Fvintageconcertshirt.com
[Sun Aug 30 03:06:24.463384 2026] [authz_core:error] [pid 496962:tid 497200] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fhome4%2Fletter7%2Fpublic_html%2Fvintageconcertshirt.com
[Sun Aug 30 03:06:24.470235 2026] [security2:error] [pid 496962:tid 497119] [client 68.155.159.216:60898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkgI6aRhSu8gis9LmM9AAABMg"]
[Sun Aug 30 03:06:24.489181 2026] [security2:error] [pid 496962:tid 497096] [client 40.83.93.50:9335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/options-reading.php"] [unique_id "apPkgI6aRhSu8gis9LmM_gAABLE"]
[Sun Aug 30 03:06:24.496679 2026] [security2:error] [pid 496962:tid 497135] [client 158.23.147.79:53545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-content/banners/about.php"] [unique_id "apPkgI6aRhSu8gis9LmNAgAABNg"]
[Sun Aug 30 03:06:24.505548 2026] [security2:error] [pid 496962:tid 497129] [client 20.151.200.44:55687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/wefile.php"] [unique_id "apPkgI6aRhSu8gis9LmNBwAABNI"]
[Sun Aug 30 03:06:24.538558 2026] [security2:error] [pid 496962:tid 497197] [client 20.104.50.220:33081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/lock360.php"] [unique_id "apPkgI6aRhSu8gis9LmNFwAABRY"]
[Sun Aug 30 03:06:24.603286 2026] [security2:error] [pid 496962:tid 497168] [client 158.23.147.79:53525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-includes/Text/about.php"] [unique_id "apPkgI6aRhSu8gis9LmNMwAABPk"]
[Sun Aug 30 03:06:24.615550 2026] [security2:error] [pid 496962:tid 497144] [client 68.155.159.216:61632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-admin/dropdown.php"] [unique_id "apPkgI6aRhSu8gis9LmNNwAABOE"]
[Sun Aug 30 03:06:24.619011 2026] [security2:error] [pid 496962:tid 497123] [client 20.104.50.220:61980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/edit.php"] [unique_id "apPkgI6aRhSu8gis9LmNOAAABMw"]
[Sun Aug 30 03:06:24.685305 2026] [security2:error] [pid 496962:tid 497181] [client 20.104.50.220:62788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/bekdur.php"] [unique_id "apPkgI6aRhSu8gis9LmNTAAABQY"]
[Sun Aug 30 03:06:24.690959 2026] [authz_core:error] [pid 496962:tid 497196] [client 216.73.216.128:5523] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:24.691326 2026] [authz_core:error] [pid 496962:tid 497196] [client 216.73.216.128:5523] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:24.703374 2026] [security2:error] [pid 496962:tid 497143] [client 20.104.50.220:27535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/manager/login.php"] [unique_id "apPkgI6aRhSu8gis9LmNUAAABOA"]
[Sun Aug 30 03:06:24.708218 2026] [security2:error] [pid 496962:tid 497169] [client 20.151.200.44:65323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/admin.php/pindex.php"] [unique_id "apPkgI6aRhSu8gis9LmNUgAABPo"]
[Sun Aug 30 03:06:24.732202 2026] [security2:error] [pid 496962:tid 497211] [client 158.23.147.79:53560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/asd.php"] [unique_id "apPkgI6aRhSu8gis9LmNYwAABSQ"]
[Sun Aug 30 03:06:24.750240 2026] [security2:error] [pid 496962:tid 497104] [client 20.197.61.180:14063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/system.php"] [unique_id "apPkgI6aRhSu8gis9LmNawAABLk"]
[Sun Aug 30 03:06:24.754130 2026] [security2:error] [pid 496962:tid 497163] [client 158.23.147.79:63268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/about.php"] [unique_id "apPkgI6aRhSu8gis9LmNbgAABPQ"]
[Sun Aug 30 03:06:24.781053 2026] [authz_core:error] [pid 496962:tid 497190] [client 216.73.216.128:39775] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:24.781341 2026] [authz_core:error] [pid 496962:tid 497190] [client 216.73.216.128:39775] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:24.791700 2026] [security2:error] [pid 496962:tid 497093] [client 20.104.18.15:13756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/33.php"] [unique_id "apPkgI6aRhSu8gis9LmNewAABK4"]
[Sun Aug 30 03:06:24.811130 2026] [security2:error] [pid 496962:tid 497095] [client 68.155.159.216:63961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-includes/css/index.php"] [unique_id "apPkgI6aRhSu8gis9LmNgAAABLA"]
[Sun Aug 30 03:06:24.832699 2026] [security2:error] [pid 496962:tid 497169] [client 20.104.18.15:44013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/goods.php"] [unique_id "apPkgI6aRhSu8gis9LmNiwAABPo"]
[Sun Aug 30 03:06:24.851167 2026] [security2:error] [pid 496962:tid 497097] [client 20.48.251.3:44382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/fm.php"] [unique_id "apPkgI6aRhSu8gis9LmNkwAABLI"]
[Sun Aug 30 03:06:24.875109 2026] [authz_core:error] [pid 496962:tid 497137] [client 216.73.216.128:5523] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:24.875487 2026] [authz_core:error] [pid 496962:tid 497137] [client 216.73.216.128:5523] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:24.918515 2026] [security2:error] [pid 496962:tid 497123] [client 20.104.50.220:46443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/minishell.php"] [unique_id "apPkgI6aRhSu8gis9LmNtQAABMw"]
[Sun Aug 30 03:06:24.925280 2026] [security2:error] [pid 496962:tid 497142] [client 20.104.50.220:63500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/constant.php"] [unique_id "apPkgI6aRhSu8gis9LmNtgAABN8"]
[Sun Aug 30 03:06:24.954962 2026] [security2:error] [pid 496962:tid 497178] [client 40.83.93.50:9334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/db.php"] [unique_id "apPkgI6aRhSu8gis9LmNvwAABQM"]
[Sun Aug 30 03:06:24.955673 2026] [authz_core:error] [pid 496962:tid 497160] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fdev%2Fbsg
[Sun Aug 30 03:06:24.956079 2026] [authz_core:error] [pid 496962:tid 497160] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fdev%2Fbsg
[Sun Aug 30 03:06:24.959296 2026] [security2:error] [pid 496962:tid 497205] [client 4.205.62.107:51766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apPkgI6aRhSu8gis9LmNwgAABR4"]
[Sun Aug 30 03:06:24.964003 2026] [security2:error] [pid 496962:tid 497093] [client 68.155.159.216:65502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPkgI6aRhSu8gis9LmNxAAABK4"]
[Sun Aug 30 03:06:24.978568 2026] [security2:error] [pid 496962:tid 497109] [client 158.23.147.79:54215] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/1.php"] [unique_id "apPkgI6aRhSu8gis9LmNxQAABL4"]
[Sun Aug 30 03:06:24.978667 2026] [security2:error] [pid 496962:tid 497109] [client 158.23.147.79:54215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/1.php"] [unique_id "apPkgI6aRhSu8gis9LmNxQAABL4"]
[Sun Aug 30 03:06:24.990440 2026] [security2:error] [pid 496962:tid 497115] [client 20.104.18.15:28555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkgI6aRhSu8gis9LmNzAAABMQ"]
[Sun Aug 30 03:06:25.014081 2026] [security2:error] [pid 496962:tid 497116] [client 20.104.18.15:33764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/ta.php"] [unique_id "apPkgY6aRhSu8gis9LmN1QAABMU"]
[Sun Aug 30 03:06:25.019794 2026] [security2:error] [pid 496962:tid 497138] [client 20.104.49.130:58073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/dk.php"] [unique_id "apPkgY6aRhSu8gis9LmN2AAABNs"]
[Sun Aug 30 03:06:25.026936 2026] [authz_core:error] [pid 496962:tid 497177] [client 74.7.227.8:56966] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fm17n
[Sun Aug 30 03:06:25.027208 2026] [authz_core:error] [pid 496962:tid 497177] [client 74.7.227.8:56966] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fm17n
[Sun Aug 30 03:06:25.060038 2026] [authz_core:error] [pid 496962:tid 497127] [client 66.249.66.194:42085] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:25.060481 2026] [authz_core:error] [pid 496962:tid 497127] [client 66.249.66.194:42085] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:25.126520 2026] [security2:error] [pid 496962:tid 497188] [client 45.3.55.204:59405] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "belloinsights.com"] [uri "/"] [unique_id "apPkgY6aRhSu8gis9LmOAAAABQ0"]
[Sun Aug 30 03:06:25.174510 2026] [security2:error] [pid 496962:tid 497146] [client 20.104.50.220:5946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/az.php"] [unique_id "apPkgY6aRhSu8gis9LmOFQAABOM"]
[Sun Aug 30 03:06:25.186488 2026] [security2:error] [pid 496962:tid 497184] [client 158.23.147.79:53275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apPkgY6aRhSu8gis9LmOGQAABQk"]
[Sun Aug 30 03:06:25.229024 2026] [security2:error] [pid 496962:tid 497185] [client 20.48.251.3:49986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/zaza.php"] [unique_id "apPkgY6aRhSu8gis9LmOHQAABQo"]
[Sun Aug 30 03:06:25.229327 2026] [security2:error] [pid 496962:tid 497181] [client 20.48.251.3:64443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPkgY6aRhSu8gis9LmOHgAABQY"]
[Sun Aug 30 03:06:25.278846 2026] [security2:error] [pid 496962:tid 497142] [client 158.23.147.79:54226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apPkgY6aRhSu8gis9LmOKgAABN8"]
[Sun Aug 30 03:06:25.278865 2026] [security2:error] [pid 496962:tid 497198] [client 158.23.147.79:53523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/ws.php"] [unique_id "apPkgY6aRhSu8gis9LmOKwAABRc"]
[Sun Aug 30 03:06:25.290481 2026] [security2:error] [pid 496962:tid 497175] [client 158.23.147.79:4052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/themes.php"] [unique_id "apPkgY6aRhSu8gis9LmOLAAABQA"]
[Sun Aug 30 03:06:25.291701 2026] [security2:error] [pid 496962:tid 497210] [client 20.104.50.220:32519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/con7ext.php"] [unique_id "apPkgY6aRhSu8gis9LmOLQAABSM"]
[Sun Aug 30 03:06:25.292864 2026] [security2:error] [pid 496962:tid 497214] [client 20.151.200.44:24603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/cy.php"] [unique_id "apPkgY6aRhSu8gis9LmOLgAABSc"]
[Sun Aug 30 03:06:25.316160 2026] [security2:error] [pid 496962:tid 497170] [client 68.155.159.216:56340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/hehehehe.php"] [unique_id "apPkgY6aRhSu8gis9LmOMAAABPs"]
[Sun Aug 30 03:06:25.382574 2026] [security2:error] [pid 496962:tid 497165] [client 74.7.241.135:47366] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.cover789com.nattdesign.com"] [uri "/robots.txt"] [unique_id "apPkgY6aRhSu8gis9LmORAAE9jI"]
[Sun Aug 30 03:06:25.390200 2026] [security2:error] [pid 496962:tid 497212] [client 158.23.147.79:53509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-includes/css/index.php"] [unique_id "apPkgY6aRhSu8gis9LmORQAABSU"]
[Sun Aug 30 03:06:25.419124 2026] [authz_core:error] [pid 496962:tid 497138] [client 216.73.216.128:39775] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:25.419419 2026] [authz_core:error] [pid 496962:tid 497138] [client 216.73.216.128:39775] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:25.422119 2026] [authz_core:error] [pid 496962:tid 497145] [client 66.249.66.206:47767] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:25.422391 2026] [authz_core:error] [pid 496962:tid 497145] [client 66.249.66.206:47767] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:25.437539 2026] [security2:error] [pid 496962:tid 497176] [client 40.83.93.50:12084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/server.php"] [unique_id "apPkgY6aRhSu8gis9LmOVwAABQE"]
[Sun Aug 30 03:06:25.454145 2026] [authz_core:error] [pid 496962:tid 497183] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fdev%2Fbsg
[Sun Aug 30 03:06:25.454445 2026] [authz_core:error] [pid 496962:tid 497183] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fdev%2Fbsg
[Sun Aug 30 03:06:25.455003 2026] [security2:error] [pid 496962:tid 497133] [client 68.155.159.216:59961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apPkgY6aRhSu8gis9LmOWwAABNY"]
[Sun Aug 30 03:06:25.477170 2026] [security2:error] [pid 496962:tid 497174] [client 20.197.61.180:3269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/tflow/min.php"] [unique_id "apPkgY6aRhSu8gis9LmOYQAABP8"]
[Sun Aug 30 03:06:25.486618 2026] [security2:error] [pid 496962:tid 497142] [client 158.23.147.79:53551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/cgi-bin/wp-login.php"] [unique_id "apPkgY6aRhSu8gis9LmOZgAABN8"]
[Sun Aug 30 03:06:25.501128 2026] [security2:error] [pid 496962:tid 497190] [client 158.23.147.79:62548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apPkgY6aRhSu8gis9LmObQAABQ8"]
[Sun Aug 30 03:06:25.521588 2026] [security2:error] [pid 496962:tid 497178] [client 158.23.147.79:4076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-mail.php"] [unique_id "apPkgY6aRhSu8gis9LmOdwAABQM"]
[Sun Aug 30 03:06:25.537727 2026] [security2:error] [pid 496962:tid 497093] [client 20.151.200.44:63312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/admin.php/csv.php"] [unique_id "apPkgY6aRhSu8gis9LmOeQAABK4"]
[Sun Aug 30 03:06:25.588705 2026] [security2:error] [pid 496962:tid 497097] [client 20.104.50.220:62841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/done.php"] [unique_id "apPkgY6aRhSu8gis9LmOlQAABLI"]
[Sun Aug 30 03:06:25.593597 2026] [security2:error] [pid 496962:tid 497192] [client 20.104.49.130:60651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/av.php"] [unique_id "apPkgY6aRhSu8gis9LmOmQAABRE"]
[Sun Aug 30 03:06:25.601496 2026] [authz_core:error] [pid 496962:tid 497142] [client 216.73.216.128:5523] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:25.601807 2026] [authz_core:error] [pid 496962:tid 497142] [client 216.73.216.128:5523] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:25.637012 2026] [security2:error] [pid 496962:tid 497137] [client 158.23.147.79:53510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-content/cong.php"] [unique_id "apPkgY6aRhSu8gis9LmOqgAABNo"]
[Sun Aug 30 03:06:25.641589 2026] [security2:error] [pid 496962:tid 497132] [client 68.155.159.216:62023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apPkgY6aRhSu8gis9LmOrwAABNU"]
[Sun Aug 30 03:06:25.653926 2026] [security2:error] [pid 496962:tid 497213] [client 158.23.147.79:53287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/cgi-bin/index.php"] [unique_id "apPkgY6aRhSu8gis9LmOtwAABSY"]
[Sun Aug 30 03:06:25.690783 2026] [security2:error] [pid 496962:tid 497166] [client 20.104.50.220:32836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/licensi.php"] [unique_id "apPkgY6aRhSu8gis9LmOwAAABPc"]
[Sun Aug 30 03:06:25.750048 2026] [security2:error] [pid 496962:tid 497135] [client 74.7.241.135:47380] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.nattdesign.com"] [uri "/cgi-sys/404.html"] [unique_id "apPkgY6aRhSu8gis9LmO0QAE2DE"], referer: https://www.cover789com.nattdesign.com/robots.txt
[Sun Aug 30 03:06:25.754363 2026] [security2:error] [pid 496962:tid 497164] [client 158.23.147.79:53257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPkgY6aRhSu8gis9LmO1AAABPU"]
[Sun Aug 30 03:06:25.760465 2026] [authz_core:error] [pid 496962:tid 497143] [client 66.249.66.70:39911] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:25.760849 2026] [authz_core:error] [pid 496962:tid 497143] [client 66.249.66.70:39911] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:25.807037 2026] [security2:error] [pid 496962:tid 497165] [client 158.23.147.79:54211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPkgY6aRhSu8gis9LmO6wAABPY"]
[Sun Aug 30 03:06:25.824958 2026] [security2:error] [pid 496962:tid 497107] [client 20.104.50.220:61426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/11.php"] [unique_id "apPkgY6aRhSu8gis9LmO7wAABLw"]
[Sun Aug 30 03:06:25.839443 2026] [security2:error] [pid 496962:tid 497118] [client 20.104.50.220:29161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/webadmin.php"] [unique_id "apPkgY6aRhSu8gis9LmO8gAABMc"]
[Sun Aug 30 03:06:25.840534 2026] [security2:error] [pid 496962:tid 497147] [client 20.104.50.220:27074] ModSecurity: Access denied with connection close (phase 1). Pattern match "/_?#?(?:(?:p(?:ma_?(?:bd)?)?(?:hp)?)?\\\\d?)?-?(?:mya?d?)?(?:sql)?\\\\d?_?-?(?:php(?:as)?)?(?:db)?(?:(database)?ad?mm??i?n?s?(?:istrator)?(?:\\\\.old)?)?-?_?(?:(?:(?:\\\\d\\\\.?){1,5})?-?(?:pl\\\\d?|rc\\\\d?|beta\\\\d?)?)/(scripts/setup|config/config\\\\.inc)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1305"] [id "999995"] [rev "2"] [msg "PHPMyadmin Script Attack"] [severity "WARNING"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/phpMyAdmin/scripts/setup.php"] [unique_id "apPkgY6aRhSu8gis9LmO9AAABOQ"]
[Sun Aug 30 03:06:25.846673 2026] [security2:error] [pid 496962:tid 497179] [client 158.23.147.79:52950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/themes.php"] [unique_id "apPkgY6aRhSu8gis9LmO9gAABQQ"]
[Sun Aug 30 03:06:25.877333 2026] [security2:error] [pid 496962:tid 497175] [client 158.23.147.79:53255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-includes/content.php"] [unique_id "apPkgY6aRhSu8gis9LmPBQAABQA"]
[Sun Aug 30 03:06:25.917961 2026] [security2:error] [pid 496962:tid 497103] [client 158.23.147.79:54596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-content/uploads/about.php"] [unique_id "apPkgY6aRhSu8gis9LmPFgAABLg"]
[Sun Aug 30 03:06:25.929333 2026] [security2:error] [pid 496962:tid 497163] [client 40.83.93.50:9321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/favicon.php"] [unique_id "apPkgY6aRhSu8gis9LmPGgAABPQ"]
[Sun Aug 30 03:06:25.930987 2026] [security2:error] [pid 496962:tid 497183] [client 20.104.18.15:13574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/133.php"] [unique_id "apPkgY6aRhSu8gis9LmPHAAABQg"]
[Sun Aug 30 03:06:25.966370 2026] [authz_core:error] [pid 496962:tid 497169] [client 216.73.216.128:5523] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:25.966673 2026] [authz_core:error] [pid 496962:tid 497169] [client 216.73.216.128:5523] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:25.973154 2026] [authz_core:error] [pid 496962:tid 497162] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fperl5%2Fvendor_perl%2FLog%2FLog4perl%2FAppender
[Sun Aug 30 03:06:25.973604 2026] [authz_core:error] [pid 496962:tid 497162] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fperl5%2Fvendor_perl%2FLog%2FLog4perl%2FAppender
[Sun Aug 30 03:06:25.991411 2026] [security2:error] [pid 496962:tid 497126] [client 20.104.18.15:43310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/ah.php"] [unique_id "apPkgY6aRhSu8gis9LmPKwAABM8"]
[Sun Aug 30 03:06:25.997907 2026] [security2:error] [pid 496962:tid 497118] [client 158.23.147.79:53507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPkgY6aRhSu8gis9LmPLwAABMc"]
[Sun Aug 30 03:06:26.051717 2026] [security2:error] [pid 496962:tid 497180] [client 20.48.251.3:44415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/tinyfilemanager.php"] [unique_id "apPkgo6aRhSu8gis9LmPRQAABQU"]
[Sun Aug 30 03:06:26.053309 2026] [security2:error] [pid 496962:tid 497132] [client 158.23.147.79:63285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-mail.php"] [unique_id "apPkgo6aRhSu8gis9LmPRgAABNU"]
[Sun Aug 30 03:06:26.070430 2026] [security2:error] [pid 496962:tid 497174] [client 68.155.159.216:65412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apPkgo6aRhSu8gis9LmPSwAABP8"]
[Sun Aug 30 03:06:26.070508 2026] [security2:error] [pid 496962:tid 497192] [client 158.23.147.79:53309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-admin/css/index.php"] [unique_id "apPkgo6aRhSu8gis9LmPTQAABRE"]
[Sun Aug 30 03:06:26.076202 2026] [security2:error] [pid 496962:tid 497183] [client 20.104.50.220:46650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/mrjn.php"] [unique_id "apPkgo6aRhSu8gis9LmPUAAABQg"]
[Sun Aug 30 03:06:26.094044 2026] [security2:error] [pid 496962:tid 497112] [client 20.104.50.220:51602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/celeng.php"] [unique_id "apPkgo6aRhSu8gis9LmPWgAABME"]
[Sun Aug 30 03:06:26.096382 2026] [authz_core:error] [pid 496962:tid 497097] [client 66.249.66.67:50714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:26.096816 2026] [authz_core:error] [pid 496962:tid 497097] [client 66.249.66.67:50714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:26.106117 2026] [security2:error] [pid 496962:tid 497139] [client 4.205.62.107:51733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/hochladen.form.php"] [unique_id "apPkgo6aRhSu8gis9LmPYAAABNw"]
[Sun Aug 30 03:06:26.123030 2026] [authz_core:error] [pid 496962:tid 497204] [client 66.249.66.66:62948] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:26.123369 2026] [authz_core:error] [pid 496962:tid 497204] [client 66.249.66.66:62948] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:26.133935 2026] [security2:error] [pid 496962:tid 497107] [client 158.23.147.79:54241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-includes/Requests/network.php"] [unique_id "apPkgo6aRhSu8gis9LmPZAAABLw"]
[Sun Aug 30 03:06:26.143258 2026] [security2:error] [pid 496962:tid 497151] [client 20.104.18.15:28669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkgo6aRhSu8gis9LmPZwAABOg"]
[Sun Aug 30 03:06:26.152369 2026] [security2:error] [pid 496962:tid 497205] [client 68.155.159.216:65475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPkgo6aRhSu8gis9LmPawAABR4"]
[Sun Aug 30 03:06:26.153716 2026] [security2:error] [pid 496962:tid 497117] [client 158.23.147.79:62547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/cgi-bin/index.php"] [unique_id "apPkgo6aRhSu8gis9LmPbAAABMY"]
[Sun Aug 30 03:06:26.176593 2026] [security2:error] [pid 496962:tid 497156] [client 20.197.61.180:21085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/tflow/pk.php"] [unique_id "apPkgo6aRhSu8gis9LmPdgAABO0"]
[Sun Aug 30 03:06:26.191109 2026] [security2:error] [pid 496962:tid 497100] [client 158.23.147.79:4045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-admin/images/index.php"] [unique_id "apPkgo6aRhSu8gis9LmPewAABLU"]
[Sun Aug 30 03:06:26.200210 2026] [security2:error] [pid 496962:tid 497116] [client 20.104.18.15:33786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/bo.php"] [unique_id "apPkgo6aRhSu8gis9LmPfgAABMU"]
[Sun Aug 30 03:06:26.253317 2026] [security2:error] [pid 496962:tid 497213] [client 158.23.147.79:53533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-content/radio.php"] [unique_id "apPkgo6aRhSu8gis9LmPhwAABSY"]
[Sun Aug 30 03:06:26.311472 2026] [security2:error] [pid 496962:tid 497119] [client 20.104.50.220:5616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/xaz.php"] [unique_id "apPkgo6aRhSu8gis9LmPkAAABMg"]
[Sun Aug 30 03:06:26.328894 2026] [security2:error] [pid 496962:tid 497107] [client 158.23.147.79:42086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-includes/index.php"] [unique_id "apPkgo6aRhSu8gis9LmPlgAABLw"]
[Sun Aug 30 03:06:26.330137 2026] [authz_core:error] [pid 496962:tid 497202] [client 216.73.216.128:47242] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:26.330433 2026] [authz_core:error] [pid 496962:tid 497202] [client 216.73.216.128:47242] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:26.367412 2026] [security2:error] [pid 496962:tid 497214] [client 20.48.251.3:6987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/agg.php"] [unique_id "apPkgo6aRhSu8gis9LmPowAABSc"]
[Sun Aug 30 03:06:26.372349 2026] [security2:error] [pid 496962:tid 497170] [client 158.23.147.79:62528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPkgo6aRhSu8gis9LmPpQAABPs"]
[Sun Aug 30 03:06:26.396093 2026] [security2:error] [pid 496962:tid 497094] [client 4.205.62.107:32473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/doc.php"] [unique_id "apPkgo6aRhSu8gis9LmPrgAABK8"]
[Sun Aug 30 03:06:26.409723 2026] [security2:error] [pid 496962:tid 497181] [client 20.48.251.3:50028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/u88.php"] [unique_id "apPkgo6aRhSu8gis9LmPswAABQY"]
[Sun Aug 30 03:06:26.412112 2026] [security2:error] [pid 496962:tid 497178] [client 158.23.147.79:53521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-admin/dropdown.php"] [unique_id "apPkgo6aRhSu8gis9LmPtQAABQM"]
[Sun Aug 30 03:06:26.425236 2026] [security2:error] [pid 496962:tid 497142] [client 158.23.147.79:42061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/mah.php"] [unique_id "apPkgo6aRhSu8gis9LmPuAAABN8"]
[Sun Aug 30 03:06:26.453096 2026] [security2:error] [pid 496962:tid 497183] [client 68.155.159.216:56321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apPkgo6aRhSu8gis9LmPxgAABQg"]
[Sun Aug 30 03:06:26.457031 2026] [authz_core:error] [pid 496962:tid 497123] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fperl5%2Fvendor_perl%2FLog%2FLog4perl%2FAppender
[Sun Aug 30 03:06:26.457500 2026] [authz_core:error] [pid 496962:tid 497123] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fperl5%2Fvendor_perl%2FLog%2FLog4perl%2FAppender
[Sun Aug 30 03:06:26.462672 2026] [security2:error] [pid 496962:tid 497093] [client 40.83.93.50:12061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/gecko.php"] [unique_id "apPkgo6aRhSu8gis9LmPywAABK4"]
[Sun Aug 30 03:06:26.463073 2026] [security2:error] [pid 496962:tid 497112] [client 20.104.50.220:31904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/loader/ff.php"] [unique_id "apPkgo6aRhSu8gis9LmPzAAABME"]
[Sun Aug 30 03:06:26.533955 2026] [security2:error] [pid 496962:tid 497094] [client 158.23.147.79:4080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-blog-header.php"] [unique_id "apPkgo6aRhSu8gis9LmP4wAABK8"]
[Sun Aug 30 03:06:26.537547 2026] [authz_core:error] [pid 496962:tid 497219] [client 74.7.227.8:56966] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2F%2Flib64
[Sun Aug 30 03:06:26.538029 2026] [authz_core:error] [pid 496962:tid 497219] [client 74.7.227.8:56966] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2F%2Flib64
[Sun Aug 30 03:06:26.541047 2026] [authz_core:error] [pid 496962:tid 497107] [client 66.249.66.76:59904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:26.541336 2026] [authz_core:error] [pid 496962:tid 497107] [client 66.249.66.76:59904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:26.546627 2026] [security2:error] [pid 496962:tid 497135] [client 158.23.147.79:62588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-includes/content.php"] [unique_id "apPkgo6aRhSu8gis9LmP6AAABNg"]
[Sun Aug 30 03:06:26.575541 2026] [security2:error] [pid 496962:tid 497208] [client 158.23.147.79:54617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/login.php"] [unique_id "apPkgo6aRhSu8gis9LmP-gAABSE"]
[Sun Aug 30 03:06:26.604820 2026] [security2:error] [pid 496962:tid 497117] [client 158.23.147.79:54244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-admin/maint/index.php"] [unique_id "apPkgo6aRhSu8gis9LmQBwAABMY"]
[Sun Aug 30 03:06:26.648929 2026] [security2:error] [pid 496962:tid 497135] [client 158.23.147.79:4041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apPkgo6aRhSu8gis9LmQGQAABNg"]
[Sun Aug 30 03:06:26.671785 2026] [security2:error] [pid 496962:tid 497177] [client 158.23.147.79:54250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/hehehehe.php"] [unique_id "apPkgo6aRhSu8gis9LmQJAAABQI"]
[Sun Aug 30 03:06:26.673839 2026] [security2:error] [pid 496962:tid 497116] [client 45.3.55.204:10711] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "belloinsights.com"] [uri "/index.php"] [unique_id "apPkgo6aRhSu8gis9LmQJwAABMU"]
[Sun Aug 30 03:06:26.680664 2026] [security2:error] [pid 496962:tid 497120] [client 158.23.147.79:63254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-admin/css/index.php"] [unique_id "apPkgo6aRhSu8gis9LmQKQAABMk"]
[Sun Aug 30 03:06:26.738370 2026] [security2:error] [pid 496962:tid 497140] [client 68.155.159.216:54079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/nf_tracking.php"] [unique_id "apPkgo6aRhSu8gis9LmQPQAABN0"]
[Sun Aug 30 03:06:26.740539 2026] [security2:error] [pid 496962:tid 497131] [client 20.104.50.220:62827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/eviltwin.php"] [unique_id "apPkgo6aRhSu8gis9LmQPwAABNQ"]
[Sun Aug 30 03:06:26.746870 2026] [security2:error] [pid 496962:tid 497094] [client 158.23.147.79:42086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-admin/user/index.php"] [unique_id "apPkgo6aRhSu8gis9LmQQgAABK8"]
[Sun Aug 30 03:06:26.760398 2026] [authz_core:error] [pid 496962:tid 497178] [client 66.249.66.192:62413] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:26.760870 2026] [authz_core:error] [pid 496962:tid 497178] [client 66.249.66.192:62413] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:26.779700 2026] [security2:error] [pid 496962:tid 497156] [client 68.155.159.216:60910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apPkgo6aRhSu8gis9LmQTgAABO0"]
[Sun Aug 30 03:06:26.783953 2026] [security2:error] [pid 496962:tid 497185] [client 158.23.147.79:54225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-includes/fonts/about.php"] [unique_id "apPkgo6aRhSu8gis9LmQUQAABQo"]
[Sun Aug 30 03:06:26.834705 2026] [security2:error] [pid 496962:tid 497155] [client 20.104.50.220:33180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/Marvins.php"] [unique_id "apPkgo6aRhSu8gis9LmQXQAABOw"]
[Sun Aug 30 03:06:26.871774 2026] [security2:error] [pid 496962:tid 497131] [client 158.23.147.79:4059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-includes/plugins.php"] [unique_id "apPkgo6aRhSu8gis9LmQawAABNQ"]
[Sun Aug 30 03:06:26.886651 2026] [security2:error] [pid 496962:tid 497167] [client 20.197.61.180:21100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/theme-check/theme-check.php"] [unique_id "apPkgo6aRhSu8gis9LmQcgAABPg"]
[Sun Aug 30 03:06:26.903084 2026] [security2:error] [pid 496962:tid 497156] [client 158.23.147.79:62491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-admin/images/index.php"] [unique_id "apPkgo6aRhSu8gis9LmQeQAABO0"]
[Sun Aug 30 03:06:26.919598 2026] [security2:error] [pid 496962:tid 497202] [client 158.23.147.79:54210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/dropdown.php"] [unique_id "apPkgo6aRhSu8gis9LmQggAABRs"]
[Sun Aug 30 03:06:26.954933 2026] [authz_core:error] [pid 496962:tid 497176] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fperl5%2Fvendor_perl%2FLog%2FLog4perl%2FFilter
[Sun Aug 30 03:06:26.955218 2026] [authz_core:error] [pid 496962:tid 497176] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fperl5%2Fvendor_perl%2FLog%2FLog4perl%2FFilter
[Sun Aug 30 03:06:26.969517 2026] [authz_core:error] [pid 496962:tid 497196] [client 216.73.216.128:50876] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:26.969815 2026] [authz_core:error] [pid 496962:tid 497196] [client 216.73.216.128:50876] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:26.971522 2026] [security2:error] [pid 496962:tid 497184] [client 20.104.50.220:61477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/title.php"] [unique_id "apPkgo6aRhSu8gis9LmQmAAABQk"]
[Sun Aug 30 03:06:26.975872 2026] [security2:error] [pid 496962:tid 497138] [client 158.23.147.79:42111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apPkgo6aRhSu8gis9LmQmQAABNs"]
[Sun Aug 30 03:06:26.979332 2026] [security2:error] [pid 496962:tid 497140] [client 20.104.50.220:27090] ModSecurity: Access denied with connection close (phase 1). Pattern match "/_?#?(?:(?:p(?:ma_?(?:bd)?)?(?:hp)?)?\\\\d?)?-?(?:mya?d?)?(?:sql)?\\\\d?_?-?(?:php(?:as)?)?(?:db)?(?:(database)?ad?mm??i?n?s?(?:istrator)?(?:\\\\.old)?)?-?_?(?:(?:(?:\\\\d\\\\.?){1,5})?-?(?:pl\\\\d?|rc\\\\d?|beta\\\\d?)?)/(scripts/setup|config/config\\\\.inc)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1305"] [id "999995"] [rev "2"] [msg "PHPMyadmin Script Attack"] [severity "WARNING"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/phpMyAdmin/scripts/setup.php"] [unique_id "apPkgo6aRhSu8gis9LmQmwAABN0"]
[Sun Aug 30 03:06:26.984480 2026] [security2:error] [pid 496962:tid 497150] [client 20.104.49.130:57693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/new.php"] [unique_id "apPkgo6aRhSu8gis9LmQngAABOc"]
[Sun Aug 30 03:06:26.991537 2026] [security2:error] [pid 496962:tid 497148] [client 20.104.50.220:29357] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "www.prod.sapientbydesign.com"] [uri "/r57.php"] [unique_id "apPkgo6aRhSu8gis9LmQoAAABOU"]
[Sun Aug 30 03:06:27.017351 2026] [security2:error] [pid 496962:tid 497129] [client 40.83.93.50:12086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/ioxi-o.php"] [unique_id "apPkg46aRhSu8gis9LmQqwAABNI"]
[Sun Aug 30 03:06:27.069621 2026] [security2:error] [pid 496962:tid 497192] [client 20.104.18.15:13612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/sym.php"] [unique_id "apPkg46aRhSu8gis9LmQuwAABRE"]
[Sun Aug 30 03:06:27.086788 2026] [security2:error] [pid 496962:tid 497100] [client 158.23.147.79:54218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-content/admin.php"] [unique_id "apPkg46aRhSu8gis9LmQwwAABLU"]
[Sun Aug 30 03:06:27.129700 2026] [security2:error] [pid 496962:tid 497165] [client 158.23.147.79:42109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/goat1.php"] [unique_id "apPkg46aRhSu8gis9LmQ0QAABPY"]
[Sun Aug 30 03:06:27.134224 2026] [security2:error] [pid 496962:tid 497131] [client 20.104.18.15:44015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/ws55.php"] [unique_id "apPkg46aRhSu8gis9LmQ0wAABNQ"]
[Sun Aug 30 03:06:27.170233 2026] [security2:error] [pid 496962:tid 497121] [client 68.155.159.216:65424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-content/cong.php"] [unique_id "apPkg46aRhSu8gis9LmQ4gAABMo"]
[Sun Aug 30 03:06:27.187540 2026] [authz_core:error] [pid 496962:tid 497101] [client 74.7.227.8:56966] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fserio%2Fdrivers%2Fatkbd%2Fserio0
[Sun Aug 30 03:06:27.187887 2026] [authz_core:error] [pid 496962:tid 497101] [client 74.7.227.8:56966] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fserio%2Fdrivers%2Fatkbd%2Fserio0
[Sun Aug 30 03:06:27.190191 2026] [security2:error] [pid 496962:tid 497202] [client 20.48.251.3:44360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/05.php"] [unique_id "apPkg46aRhSu8gis9LmQ7QAABRs"]
[Sun Aug 30 03:06:27.208602 2026] [security2:error] [pid 496962:tid 497149] [client 158.23.147.79:62465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-includes/index.php"] [unique_id "apPkg46aRhSu8gis9LmQ8QAABOY"]
[Sun Aug 30 03:06:27.210724 2026] [security2:error] [pid 496962:tid 497102] [client 20.104.50.220:46161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/ninja.php"] [unique_id "apPkg46aRhSu8gis9LmQ9AAABLc"]
[Sun Aug 30 03:06:27.249337 2026] [authz_core:error] [pid 496962:tid 497173] [client 66.249.66.71:59251] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:27.249626 2026] [authz_core:error] [pid 496962:tid 497173] [client 66.249.66.71:59251] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:27.254694 2026] [security2:error] [pid 496962:tid 497118] [client 158.23.147.79:54267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/sad/about.php"] [unique_id "apPkg46aRhSu8gis9LmRAAAABMc"]
[Sun Aug 30 03:06:27.255952 2026] [security2:error] [pid 496962:tid 497106] [client 4.205.62.107:52104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/debuggen.php"] [unique_id "apPkg46aRhSu8gis9LmRAQAABLs"]
[Sun Aug 30 03:06:27.259992 2026] [security2:error] [pid 496962:tid 497127] [client 20.104.50.220:51640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/bypassing.php"] [unique_id "apPkg46aRhSu8gis9LmRAwAABNA"]
[Sun Aug 30 03:06:27.276905 2026] [security2:error] [pid 496962:tid 497151] [client 158.23.147.79:54242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/xmlrpc.php"] [unique_id "apPkg46aRhSu8gis9LmRCAAABOg"]
[Sun Aug 30 03:06:27.281442 2026] [security2:error] [pid 496962:tid 497093] [client 158.23.147.79:42083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-includes/certificates/index.php"] [unique_id "apPkg46aRhSu8gis9LmRCQAABK4"]
[Sun Aug 30 03:06:27.283924 2026] [security2:error] [pid 496962:tid 497099] [client 20.104.18.15:28650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/adminfuns.php"] [unique_id "apPkg46aRhSu8gis9LmRCgAABLQ"]
[Sun Aug 30 03:06:27.309256 2026] [security2:error] [pid 496962:tid 497116] [client 158.23.147.79:62464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/mah.php"] [unique_id "apPkg46aRhSu8gis9LmRDQAABMU"]
[Sun Aug 30 03:06:27.311226 2026] [security2:error] [pid 496962:tid 497201] [client 20.151.200.44:65309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/admin.php/700.php"] [unique_id "apPkg46aRhSu8gis9LmRDgAABRo"]
[Sun Aug 30 03:06:27.315594 2026] [security2:error] [pid 496962:tid 497210] [client 20.151.200.44:47360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/admin.php/pindex.php"] [unique_id "apPkg46aRhSu8gis9LmREAAABSM"]
[Sun Aug 30 03:06:27.331037 2026] [security2:error] [pid 496962:tid 497129] [client 20.151.200.44:37872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/admin.php/pindex.php"] [unique_id "apPkg46aRhSu8gis9LmRFgAABNI"]
[Sun Aug 30 03:06:27.405939 2026] [security2:error] [pid 496962:tid 497111] [client 158.23.147.79:4061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-admin/network/index.php"] [unique_id "apPkg46aRhSu8gis9LmRKgAABMA"]
[Sun Aug 30 03:06:27.423719 2026] [security2:error] [pid 496962:tid 497127] [client 20.104.18.15:33775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/44.php"] [unique_id "apPkg46aRhSu8gis9LmRMAAABNA"]
[Sun Aug 30 03:06:27.450203 2026] [security2:error] [pid 496962:tid 497180] [client 20.104.50.220:5442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/up4.php"] [unique_id "apPkg46aRhSu8gis9LmROAAABQU"]
[Sun Aug 30 03:06:27.455749 2026] [authz_core:error] [pid 496962:tid 497103] [client 66.249.66.193:55507] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:27.456025 2026] [authz_core:error] [pid 496962:tid 497103] [client 66.249.66.193:55507] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:27.456640 2026] [authz_core:error] [pid 496962:tid 497155] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fperl5%2Fvendor_perl%2FLog%2FLog4perl%2FAppender
[Sun Aug 30 03:06:27.456941 2026] [authz_core:error] [pid 496962:tid 497155] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fperl5%2Fvendor_perl%2FLog%2FLog4perl%2FAppender
[Sun Aug 30 03:06:27.471746 2026] [security2:error] [pid 496962:tid 497191] [client 20.104.49.130:53598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/sym.php"] [unique_id "apPkg46aRhSu8gis9LmRPwAABRA"]
[Sun Aug 30 03:06:27.478978 2026] [security2:error] [pid 496962:tid 497163] [client 158.23.147.79:62514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-blog-header.php"] [unique_id "apPkg46aRhSu8gis9LmRQgAABPQ"]
[Sun Aug 30 03:06:27.505440 2026] [security2:error] [pid 496962:tid 497101] [client 158.23.147.79:4074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apPkg46aRhSu8gis9LmRUQAABLY"]
[Sun Aug 30 03:06:27.532272 2026] [security2:error] [pid 496962:tid 497111] [client 20.48.251.3:64489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/requirements.php"] [unique_id "apPkg46aRhSu8gis9LmRXQAABMA"]
[Sun Aug 30 03:06:27.536423 2026] [security2:error] [pid 496962:tid 497186] [client 40.83.93.50:9141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.swmpainters.com"] [uri "/lock.php"] [unique_id "apPkg46aRhSu8gis9LmRXwAABQs"]
[Sun Aug 30 03:06:27.549559 2026] [security2:error] [pid 496962:tid 497106] [client 158.23.147.79:53517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/admin.php"] [unique_id "apPkg46aRhSu8gis9LmRYQAABLs"]
[Sun Aug 30 03:06:27.549734 2026] [security2:error] [pid 496962:tid 497162] [client 20.48.251.3:55494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/config/laravolt/css/index.php"] [unique_id "apPkg46aRhSu8gis9LmRYwAABPM"]
[Sun Aug 30 03:06:27.557682 2026] [security2:error] [pid 496962:tid 497208] [client 68.155.159.216:56339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-content/admin.php"] [unique_id "apPkg46aRhSu8gis9LmRaQAABSE"]
[Sun Aug 30 03:06:27.595292 2026] [security2:error] [pid 496962:tid 497165] [client 68.155.159.216:65474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apPkg46aRhSu8gis9LmRfgAABPY"]
[Sun Aug 30 03:06:27.596604 2026] [security2:error] [pid 496962:tid 497126] [client 158.23.147.79:53524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/atomlib.php"] [unique_id "apPkg46aRhSu8gis9LmRgAAABM8"]
[Sun Aug 30 03:06:27.600264 2026] [security2:error] [pid 496962:tid 497177] [client 20.104.50.220:32120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/dbx.php"] [unique_id "apPkg46aRhSu8gis9LmRhQAABQI"]
[Sun Aug 30 03:06:27.604726 2026] [security2:error] [pid 496962:tid 497154] [client 158.23.147.79:42080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/.well-knownold/index.php"] [unique_id "apPkg46aRhSu8gis9LmRhwAABOs"]
[Sun Aug 30 03:06:27.604806 2026] [authz_core:error] [pid 496962:tid 497212] [client 216.73.216.128:50876] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:27.605126 2026] [authz_core:error] [pid 496962:tid 497212] [client 216.73.216.128:50876] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:27.606309 2026] [security2:error] [pid 496962:tid 497139] [client 20.197.61.180:14078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/theme/about.php"] [unique_id "apPkg46aRhSu8gis9LmRiQAABNw"]
[Sun Aug 30 03:06:27.638260 2026] [security2:error] [pid 496962:tid 497202] [client 158.23.147.79:52875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apPkg46aRhSu8gis9LmRkgAABRs"]
[Sun Aug 30 03:06:27.679105 2026] [authz_core:error] [pid 496962:tid 497191] [client 74.7.227.8:56966] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fxml%2Fiso-codes
[Sun Aug 30 03:06:27.679557 2026] [authz_core:error] [pid 496962:tid 497191] [client 74.7.227.8:56966] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fxml%2Fiso-codes
[Sun Aug 30 03:06:27.699960 2026] [security2:error] [pid 496962:tid 497148] [client 158.23.147.79:4062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apPkg46aRhSu8gis9LmRowAABOU"]
[Sun Aug 30 03:06:27.774254 2026] [security2:error] [pid 496962:tid 497156] [client 20.48.251.3:7091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/ccou.php"] [unique_id "apPkg46aRhSu8gis9LmRvQAABO0"]
[Sun Aug 30 03:06:27.804927 2026] [security2:error] [pid 496962:tid 497106] [client 158.23.147.79:4037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPkg46aRhSu8gis9LmRyAAABLs"]
[Sun Aug 30 03:06:27.845694 2026] [security2:error] [pid 496962:tid 497110] [client 4.205.62.107:58308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/classsmtps.php"] [unique_id "apPkg46aRhSu8gis9LmRzwAABL8"]
[Sun Aug 30 03:06:27.848449 2026] [security2:error] [pid 496962:tid 497100] [client 158.23.147.79:54221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-admin/admin.php"] [unique_id "apPkg46aRhSu8gis9LmR0QAABLU"]
[Sun Aug 30 03:06:27.864791 2026] [security2:error] [pid 496962:tid 497194] [client 68.155.159.216:54018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wzy.php"] [unique_id "apPkg46aRhSu8gis9LmR1gAABRM"]
[Sun Aug 30 03:06:27.881214 2026] [security2:error] [pid 496962:tid 497140] [client 158.23.147.79:62558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-admin/user/index.php"] [unique_id "apPkg46aRhSu8gis9LmR3AAABN0"]
[Sun Aug 30 03:06:27.916830 2026] [security2:error] [pid 496962:tid 497192] [client 158.23.147.79:53512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/lv.php"] [unique_id "apPkg46aRhSu8gis9LmR7wAABRE"]
[Sun Aug 30 03:06:27.925582 2026] [security2:error] [pid 496962:tid 497200] [client 158.23.147.79:3990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/images/index.php"] [unique_id "apPkg46aRhSu8gis9LmR8gAABRk"]
[Sun Aug 30 03:06:27.926945 2026] [security2:error] [pid 496962:tid 497195] [client 68.155.159.216:60905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/simple.php"] [unique_id "apPkg46aRhSu8gis9LmR9AAABRQ"]
[Sun Aug 30 03:06:27.935238 2026] [security2:error] [pid 496962:tid 497206] [client 20.104.50.220:29570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/manage.php"] [unique_id "apPkg46aRhSu8gis9LmR9wAABR8"]
[Sun Aug 30 03:06:27.968812 2026] [security2:error] [pid 496962:tid 497219] [client 45.3.55.204:21015] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "belloinsights.com"] [uri "/"] [unique_id "apPkg46aRhSu8gis9LmSBQAABSw"]
[Sun Aug 30 03:06:27.980823 2026] [security2:error] [pid 496962:tid 497102] [client 20.104.50.220:32892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/lolz.php"] [unique_id "apPkg46aRhSu8gis9LmSBwAABLc"]
[Sun Aug 30 03:06:27.986612 2026] [authz_core:error] [pid 496962:tid 497112] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:06:27.986892 2026] [authz_core:error] [pid 496962:tid 497112] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:06:28.024483 2026] [security2:error] [pid 496962:tid 497129] [client 158.23.147.79:4067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-includes/widgets/index.php"] [unique_id "apPkhI6aRhSu8gis9LmSGAAABNI"]
[Sun Aug 30 03:06:28.061426 2026] [authz_core:error] [pid 496962:tid 497168] [client 216.73.216.128:50876] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:28.061722 2026] [authz_core:error] [pid 496962:tid 497168] [client 216.73.216.128:50876] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:28.063355 2026] [security2:error] [pid 496962:tid 497177] [client 158.23.147.79:53528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-includes/IXR/index.php"] [unique_id "apPkhI6aRhSu8gis9LmSJQAABQI"]
[Sun Aug 30 03:06:28.124311 2026] [security2:error] [pid 496962:tid 497164] [client 20.104.50.220:27120] ModSecurity: Access denied with connection close (phase 1). Pattern match "/_?#?(?:(?:p(?:ma_?(?:bd)?)?(?:hp)?)?\\\\d?)?-?(?:mya?d?)?(?:sql)?\\\\d?_?-?(?:php(?:as)?)?(?:db)?(?:(database)?ad?mm??i?n?s?(?:istrator)?(?:\\\\.old)?)?-?_?(?:(?:(?:\\\\d\\\\.?){1,5})?-?(?:pl\\\\d?|rc\\\\d?|beta\\\\d?)?)/(scripts/setup|config/config\\\\.inc)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1305"] [id "999995"] [rev "2"] [msg "PHPMyadmin Script Attack"] [severity "WARNING"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/phpMyAdmin/scripts/setup.php"] [unique_id "apPkhI6aRhSu8gis9LmSOQAABPU"]
[Sun Aug 30 03:06:28.126856 2026] [security2:error] [pid 496962:tid 497210] [client 158.23.147.79:63242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-includes/plugins.php"] [unique_id "apPkhI6aRhSu8gis9LmSOgAABSM"]
[Sun Aug 30 03:06:28.142697 2026] [security2:error] [pid 496962:tid 497105] [client 158.23.147.79:53286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apPkhI6aRhSu8gis9LmSPAAABLo"]
[Sun Aug 30 03:06:28.162597 2026] [security2:error] [pid 496962:tid 497152] [client 20.104.50.220:29134] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "www.prod.sapientbydesign.com"] [uri "/r57.php"] [unique_id "apPkhI6aRhSu8gis9LmSRAAABOk"]
[Sun Aug 30 03:06:28.183213 2026] [authz_core:error] [pid 496962:tid 497163] [client 66.249.66.202:62977] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:28.183512 2026] [authz_core:error] [pid 496962:tid 497163] [client 66.249.66.202:62977] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:28.185800 2026] [security2:error] [pid 496962:tid 497207] [client 158.23.147.79:54217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-includes/Text/index.php"] [unique_id "apPkhI6aRhSu8gis9LmSUQAABSA"]
[Sun Aug 30 03:06:28.221556 2026] [security2:error] [pid 496962:tid 497120] [client 20.104.18.15:13579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/8.php"] [unique_id "apPkhI6aRhSu8gis9LmSXwAABMk"]
[Sun Aug 30 03:06:28.246819 2026] [security2:error] [pid 496962:tid 497208] [client 158.23.147.79:4071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apPkhI6aRhSu8gis9LmSZwAABSE"]
[Sun Aug 30 03:06:28.262554 2026] [security2:error] [pid 496962:tid 497193] [client 20.104.50.220:61410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/xmlrpc.php"] [unique_id "apPkhI6aRhSu8gis9LmSbAAABRI"]
[Sun Aug 30 03:06:28.264004 2026] [security2:error] [pid 496962:tid 497170] [client 158.23.147.79:53505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/classwithtostring.php"] [unique_id "apPkhI6aRhSu8gis9LmSbQAABPs"]
[Sun Aug 30 03:06:28.266230 2026] [security2:error] [pid 496962:tid 497198] [client 158.23.147.79:62534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apPkhI6aRhSu8gis9LmSbgAABRc"]
[Sun Aug 30 03:06:28.273448 2026] [security2:error] [pid 496962:tid 497105] [client 20.104.18.15:43317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/drykl.php"] [unique_id "apPkhI6aRhSu8gis9LmScgAABLo"]
[Sun Aug 30 03:06:28.302086 2026] [security2:error] [pid 496962:tid 497112] [client 158.23.147.79:54222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/content.php"] [unique_id "apPkhI6aRhSu8gis9LmSdAAABME"]
[Sun Aug 30 03:06:28.322053 2026] [authz_core:error] [pid 496962:tid 497093] [client 66.249.66.42:38764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:28.322340 2026] [authz_core:error] [pid 496962:tid 497093] [client 66.249.66.42:38764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:28.327850 2026] [security2:error] [pid 496962:tid 497122] [client 20.197.61.180:3275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/theme/min.php"] [unique_id "apPkhI6aRhSu8gis9LmSfgAABMs"]
[Sun Aug 30 03:06:28.333787 2026] [security2:error] [pid 496962:tid 497192] [client 20.151.200.44:47060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/dehnl.php"] [unique_id "apPkhI6aRhSu8gis9LmSgAAABRE"]
[Sun Aug 30 03:06:28.336263 2026] [security2:error] [pid 496962:tid 497114] [client 68.155.159.216:63984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPkhI6aRhSu8gis9LmSggAABMM"]
[Sun Aug 30 03:06:28.349868 2026] [security2:error] [pid 496962:tid 497098] [client 20.104.50.220:46608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/ohayo.php"] [unique_id "apPkhI6aRhSu8gis9LmShAAABLM"]
[Sun Aug 30 03:06:28.354031 2026] [security2:error] [pid 496962:tid 497166] [client 158.23.147.79:4051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-includes/pomo/index.php"] [unique_id "apPkhI6aRhSu8gis9LmShgAABPc"]
[Sun Aug 30 03:06:28.408158 2026] [security2:error] [pid 496962:tid 497173] [client 158.23.147.79:54226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPkhI6aRhSu8gis9LmSngAABP4"]
[Sun Aug 30 03:06:28.413603 2026] [security2:error] [pid 496962:tid 497128] [client 4.205.62.107:52144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/pouhg.php"] [unique_id "apPkhI6aRhSu8gis9LmSoAAABNE"]
[Sun Aug 30 03:06:28.415116 2026] [security2:error] [pid 496962:tid 497183] [client 20.104.50.220:51601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/bypshell.php"] [unique_id "apPkhI6aRhSu8gis9LmSoQAABQg"]
[Sun Aug 30 03:06:28.416366 2026] [security2:error] [pid 496962:tid 497197] [client 20.48.251.3:4697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/wp-blog.php"] [unique_id "apPkhI6aRhSu8gis9LmSogAABRY"]
[Sun Aug 30 03:06:28.420990 2026] [security2:error] [pid 496962:tid 497142] [client 158.23.147.79:63248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/goat1.php"] [unique_id "apPkhI6aRhSu8gis9LmSpAAABN8"]
[Sun Aug 30 03:06:28.425750 2026] [security2:error] [pid 496962:tid 497099] [client 20.104.18.15:28545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/goods.php"] [unique_id "apPkhI6aRhSu8gis9LmSpQAABLQ"]
[Sun Aug 30 03:06:28.474378 2026] [security2:error] [pid 496962:tid 497132] [client 158.23.147.79:54604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/install.php"] [unique_id "apPkhI6aRhSu8gis9LmStwAABNU"]
[Sun Aug 30 03:06:28.495653 2026] [authz_core:error] [pid 496962:tid 497098] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:06:28.495933 2026] [authz_core:error] [pid 496962:tid 497098] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:06:28.500708 2026] [security2:error] [pid 496962:tid 497178] [client 158.23.147.79:53298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/nf_tracking.php"] [unique_id "apPkhI6aRhSu8gis9LmSwwAABQM"]
[Sun Aug 30 03:06:28.515889 2026] [authz_core:error] [pid 496962:tid 497201] [client 216.73.216.128:50876] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:28.516184 2026] [authz_core:error] [pid 496962:tid 497201] [client 216.73.216.128:50876] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:28.517960 2026] [security2:error] [pid 496962:tid 497196] [client 158.23.147.79:54235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/goat.php"] [unique_id "apPkhI6aRhSu8gis9LmSzAAABRU"]
[Sun Aug 30 03:06:28.546361 2026] [security2:error] [pid 496962:tid 497165] [client 20.151.200.44:55726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/Contrller.php"] [unique_id "apPkhI6aRhSu8gis9LmS0wAABPY"]
[Sun Aug 30 03:06:28.577742 2026] [security2:error] [pid 496962:tid 497122] [client 20.104.18.15:33680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/h2.php"] [unique_id "apPkhI6aRhSu8gis9LmS5wAABMs"]
[Sun Aug 30 03:06:28.578050 2026] [security2:error] [pid 496962:tid 497109] [client 158.23.147.79:62564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apPkhI6aRhSu8gis9LmS6QAABL4"]
[Sun Aug 30 03:06:28.588090 2026] [security2:error] [pid 496962:tid 497123] [client 20.104.50.220:5195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/1aa.php"] [unique_id "apPkhI6aRhSu8gis9LmS7AAABMw"]
[Sun Aug 30 03:06:28.612196 2026] [security2:error] [pid 496962:tid 497162] [client 158.23.147.79:3981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wzy.php"] [unique_id "apPkhI6aRhSu8gis9LmS9wAABPM"]
[Sun Aug 30 03:06:28.634678 2026] [security2:error] [pid 496962:tid 497103] [client 158.23.147.79:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apPkhI6aRhSu8gis9LmS_AAABLg"]
[Sun Aug 30 03:06:28.684911 2026] [security2:error] [pid 496962:tid 497122] [client 20.104.49.130:52313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/txets.php"] [unique_id "apPkhI6aRhSu8gis9LmTEwAABMs"]
[Sun Aug 30 03:06:28.687978 2026] [security2:error] [pid 496962:tid 497197] [client 20.48.251.3:55469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/87.php"] [unique_id "apPkhI6aRhSu8gis9LmTFAAABRY"]
[Sun Aug 30 03:06:28.691308 2026] [security2:error] [pid 496962:tid 497194] [client 20.48.251.3:45869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/var/www/wallet/index.php"] [unique_id "apPkhI6aRhSu8gis9LmTFQAABRM"]
[Sun Aug 30 03:06:28.698725 2026] [authz_core:error] [pid 496962:tid 497194] [client 216.73.216.128:50876] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:28.699005 2026] [authz_core:error] [pid 496962:tid 497194] [client 216.73.216.128:50876] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:28.710583 2026] [security2:error] [pid 496962:tid 497193] [client 68.155.159.216:11211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/xmlrpc.php"] [unique_id "apPkhI6aRhSu8gis9LmTGAAABRI"]
[Sun Aug 30 03:06:28.712199 2026] [security2:error] [pid 496962:tid 497128] [client 158.23.147.79:42108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-admin/setup-config.php"] [unique_id "apPkhI6aRhSu8gis9LmTGgAABNE"]
[Sun Aug 30 03:06:28.723519 2026] [security2:error] [pid 496962:tid 497101] [client 158.23.147.79:54624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-content/x/index.php"] [unique_id "apPkhI6aRhSu8gis9LmTIgAABLY"]
[Sun Aug 30 03:06:28.737591 2026] [security2:error] [pid 496962:tid 497162] [client 20.104.50.220:32106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/degeselih.php"] [unique_id "apPkhI6aRhSu8gis9LmTKgAABPM"]
[Sun Aug 30 03:06:28.738785 2026] [security2:error] [pid 496962:tid 497160] [client 158.23.147.79:54595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-content/uploads/about.php"] [unique_id "apPkhI6aRhSu8gis9LmTKwAABPE"]
[Sun Aug 30 03:06:28.817841 2026] [security2:error] [pid 496962:tid 497133] [client 158.23.147.79:4087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apPkhI6aRhSu8gis9LmTQwAABNY"]
[Sun Aug 30 03:06:28.834049 2026] [security2:error] [pid 496962:tid 497119] [client 68.155.159.216:12353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-content/radio.php"] [unique_id "apPkhI6aRhSu8gis9LmTRgAABMg"]
[Sun Aug 30 03:06:28.854705 2026] [security2:error] [pid 496962:tid 497101] [client 158.23.147.79:54618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-includes/Requests/about.php"] [unique_id "apPkhI6aRhSu8gis9LmTTwAABLY"]
[Sun Aug 30 03:06:28.856504 2026] [authz_core:error] [pid 496962:tid 497126] [client 66.249.66.75:61997] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:28.856934 2026] [authz_core:error] [pid 496962:tid 497126] [client 66.249.66.75:61997] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:28.863106 2026] [security2:error] [pid 496962:tid 497105] [client 4.205.62.107:2338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/zz.php"] [unique_id "apPkhI6aRhSu8gis9LmTUgAABLo"]
[Sun Aug 30 03:06:28.875525 2026] [security2:error] [pid 496962:tid 497195] [client 158.23.147.79:53549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-admin/maint/index.php"] [unique_id "apPkhI6aRhSu8gis9LmTWQAABRQ"]
[Sun Aug 30 03:06:28.879215 2026] [security2:error] [pid 496962:tid 497134] [client 158.23.147.79:62543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-admin/network/index.php"] [unique_id "apPkhI6aRhSu8gis9LmTWwAABNc"]
[Sun Aug 30 03:06:28.935245 2026] [ssl:error] [pid 496962:tid 497172] [client 3.233.59.216:4403] AH02032: Hostname gator3166.hostgator.com (default host as no SNI was provided) and hostname denalimedia.mikeshell.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Sun Aug 30 03:06:28.956057 2026] [security2:error] [pid 496962:tid 497115] [client 158.23.147.79:42107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apPkhI6aRhSu8gis9LmTeQAABMQ"]
[Sun Aug 30 03:06:28.979755 2026] [security2:error] [pid 496962:tid 497121] [client 4.205.62.107:26531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/pass4.php"] [unique_id "apPkhI6aRhSu8gis9LmTgQAABMo"]
[Sun Aug 30 03:06:29.020464 2026] [security2:error] [pid 496962:tid 497134] [client 68.155.159.216:54082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apPkhY6aRhSu8gis9LmTjwAABNc"]
[Sun Aug 30 03:06:29.021205 2026] [security2:error] [pid 496962:tid 497120] [client 158.23.147.79:53536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-admin/includes/index.php"] [unique_id "apPkhY6aRhSu8gis9LmTkAAABMk"]
[Sun Aug 30 03:06:29.023858 2026] [authz_core:error] [pid 496962:tid 497167] [client 66.249.66.41:36880] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:29.024145 2026] [authz_core:error] [pid 496962:tid 497167] [client 66.249.66.41:36880] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:29.040615 2026] [security2:error] [pid 496962:tid 497148] [client 158.23.147.79:62534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apPkhY6aRhSu8gis9LmTlAAABOU"]
[Sun Aug 30 03:06:29.054705 2026] [security2:error] [pid 496962:tid 497176] [client 20.197.61.180:3268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/themes/about.php"] [unique_id "apPkhY6aRhSu8gis9LmTmAAABQE"]
[Sun Aug 30 03:06:29.054968 2026] [security2:error] [pid 496962:tid 497099] [client 4.205.62.107:4129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/fns.php"] [unique_id "apPkhY6aRhSu8gis9LmTlwAABLQ"]
[Sun Aug 30 03:06:29.071260 2026] [security2:error] [pid 496962:tid 497097] [client 20.151.200.44:64673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/admin.php/007x.php"] [unique_id "apPkhY6aRhSu8gis9LmTogAABLI"]
[Sun Aug 30 03:06:29.076758 2026] [authz_core:error] [pid 496962:tid 497139] [client 74.7.227.8:56966] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule
[Sun Aug 30 03:06:29.077065 2026] [authz_core:error] [pid 496962:tid 497139] [client 74.7.227.8:56966] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule
[Sun Aug 30 03:06:29.096002 2026] [security2:error] [pid 496962:tid 497107] [client 20.104.50.220:29138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/mforh.php"] [unique_id "apPkhY6aRhSu8gis9LmTrwAABLw"]
[Sun Aug 30 03:06:29.114271 2026] [security2:error] [pid 496962:tid 497154] [client 158.23.147.79:4065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apPkhY6aRhSu8gis9LmTugAABOs"]
[Sun Aug 30 03:06:29.119767 2026] [security2:error] [pid 496962:tid 497142] [client 4.205.62.107:18796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/png.php"] [unique_id "apPkhY6aRhSu8gis9LmTvAAABN8"]
[Sun Aug 30 03:06:29.127364 2026] [security2:error] [pid 496962:tid 497147] [client 4.205.62.107:22564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/goods.php"] [unique_id "apPkhY6aRhSu8gis9LmTwQAABOQ"]
[Sun Aug 30 03:06:29.128627 2026] [security2:error] [pid 496962:tid 497112] [client 158.23.147.79:53510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-login.php"] [unique_id "apPkhY6aRhSu8gis9LmTwgAABME"]
[Sun Aug 30 03:06:29.133834 2026] [security2:error] [pid 496962:tid 497213] [client 20.104.50.220:32914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/libs-func.php"] [unique_id "apPkhY6aRhSu8gis9LmTwwAABSY"]
[Sun Aug 30 03:06:29.152912 2026] [security2:error] [pid 496962:tid 497166] [client 158.23.147.79:53559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/dropdown.php"] [unique_id "apPkhY6aRhSu8gis9LmTywAABPc"]
[Sun Aug 30 03:06:29.162621 2026] [security2:error] [pid 496962:tid 497149] [client 158.23.147.79:62535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/.well-knownold/index.php"] [unique_id "apPkhY6aRhSu8gis9LmT0QAABOY"]
[Sun Aug 30 03:06:29.187527 2026] [security2:error] [pid 496962:tid 497127] [client 4.205.62.107:64006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/file21.php"] [unique_id "apPkhY6aRhSu8gis9LmT2gAABNA"]
[Sun Aug 30 03:06:29.245981 2026] [authz_core:error] [pid 496962:tid 497174] [client 216.73.216.128:50876] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:29.246145 2026] [security2:error] [pid 496962:tid 497129] [client 68.155.159.216:62053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-admin/about.php"] [unique_id "apPkhY6aRhSu8gis9LmT7gAABNI"]
[Sun Aug 30 03:06:29.246388 2026] [authz_core:error] [pid 496962:tid 497174] [client 216.73.216.128:50876] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:29.249019 2026] [security2:error] [pid 496962:tid 497151] [client 158.23.147.79:42065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apPkhY6aRhSu8gis9LmT8AAABOg"]
[Sun Aug 30 03:06:29.249397 2026] [security2:error] [pid 496962:tid 497157] [client 158.23.147.79:54235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apPkhY6aRhSu8gis9LmT8QAABO4"]
[Sun Aug 30 03:06:29.254468 2026] [security2:error] [pid 496962:tid 497123] [client 20.104.50.220:27409] ModSecurity: Access denied with connection close (phase 1). Pattern match "/_?#?(?:(?:p(?:ma_?(?:bd)?)?(?:hp)?)?\\\\d?)?-?(?:mya?d?)?(?:sql)?\\\\d?_?-?(?:php(?:as)?)?(?:db)?(?:(database)?ad?mm??i?n?s?(?:istrator)?(?:\\\\.old)?)?-?_?(?:(?:(?:\\\\d\\\\.?){1,5})?-?(?:pl\\\\d?|rc\\\\d?|beta\\\\d?)?)/(scripts/setup|config/config\\\\.inc)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1305"] [id "999995"] [rev "2"] [msg "PHPMyadmin Script Attack"] [severity "WARNING"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/phpMyAdmin/scripts/setup.php"] [unique_id "apPkhY6aRhSu8gis9LmT8wAABMw"]
[Sun Aug 30 03:06:29.255814 2026] [security2:error] [pid 496962:tid 497198] [client 45.3.55.204:54691] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "belloinsights.com"] [uri "/"] [unique_id "apPkhY6aRhSu8gis9LmT9QAABRc"]
[Sun Aug 30 03:06:29.271556 2026] [security2:error] [pid 496962:tid 497099] [client 158.23.147.79:53552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/sad/about.php"] [unique_id "apPkhY6aRhSu8gis9LmT-AAABLQ"]
[Sun Aug 30 03:06:29.299621 2026] [security2:error] [pid 496962:tid 497195] [client 20.104.50.220:29584] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "www.prod.sapientbydesign.com"] [uri "/r57.php"] [unique_id "apPkhY6aRhSu8gis9LmT_gAABRQ"]
[Sun Aug 30 03:06:29.308126 2026] [security2:error] [pid 496962:tid 497138] [client 158.23.147.79:62492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apPkhY6aRhSu8gis9LmUAQAABNs"]
[Sun Aug 30 03:06:29.330176 2026] [security2:error] [pid 496962:tid 497206] [client 216.73.216.128:47242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPkhY6aRhSu8gis9LmUBwAABR8"]
[Sun Aug 30 03:06:29.330585 2026] [security2:error] [pid 496962:tid 497193] [client 20.151.200.44:65254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/admin.php/heex.php"] [unique_id "apPkhY6aRhSu8gis9LmUCQAABRI"]
[Sun Aug 30 03:06:29.354780 2026] [security2:error] [pid 496962:tid 497179] [client 158.23.147.79:54615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-admin/images/about.php"] [unique_id "apPkhY6aRhSu8gis9LmUEgAABQQ"]
[Sun Aug 30 03:06:29.355799 2026] [security2:error] [pid 496962:tid 497184] [client 158.23.147.79:3996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/packed.php"] [unique_id "apPkhY6aRhSu8gis9LmUEwAABQk"]
[Sun Aug 30 03:06:29.393491 2026] [security2:error] [pid 496962:tid 497208] [client 20.104.18.15:13591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/goods.php"] [unique_id "apPkhY6aRhSu8gis9LmUIQAABSE"]
[Sun Aug 30 03:06:29.398840 2026] [security2:error] [pid 496962:tid 497187] [client 4.205.62.107:32053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/cache-compat.php"] [unique_id "apPkhY6aRhSu8gis9LmUJwAABQw"]
[Sun Aug 30 03:06:29.411774 2026] [authz_core:error] [pid 496962:tid 497191] [client 66.249.66.76:57277] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:29.412066 2026] [authz_core:error] [pid 496962:tid 497191] [client 66.249.66.76:57277] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:29.424332 2026] [security2:error] [pid 496962:tid 497145] [client 158.23.147.79:63288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPkhY6aRhSu8gis9LmULQAABOI"]
[Sun Aug 30 03:06:29.427902 2026] [security2:error] [pid 496962:tid 497171] [client 20.104.50.220:59548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/pass.php"] [unique_id "apPkhY6aRhSu8gis9LmULwAABPw"]
[Sun Aug 30 03:06:29.431531 2026] [security2:error] [pid 496962:tid 497165] [client 20.104.18.15:44023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/backup.php"] [unique_id "apPkhY6aRhSu8gis9LmUMQAABPY"]
[Sun Aug 30 03:06:29.444607 2026] [security2:error] [pid 496962:tid 497166] [client 68.155.159.216:61365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPkhY6aRhSu8gis9LmUNgAABPc"]
[Sun Aug 30 03:06:29.454546 2026] [security2:error] [pid 496962:tid 497189] [client 158.23.147.79:54212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPkhY6aRhSu8gis9LmUOgAABQ4"]
[Sun Aug 30 03:06:29.456601 2026] [security2:error] [pid 496962:tid 497172] [client 158.23.147.79:42076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-content/packed.php"] [unique_id "apPkhY6aRhSu8gis9LmUOwAABP0"]
[Sun Aug 30 03:06:29.486813 2026] [security2:error] [pid 496962:tid 497133] [client 20.104.50.220:46649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/olux.php"] [unique_id "apPkhY6aRhSu8gis9LmUSAAABNY"]
[Sun Aug 30 03:06:29.489321 2026] [security2:error] [pid 496962:tid 497184] [client 158.23.147.79:54606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/admin.php"] [unique_id "apPkhY6aRhSu8gis9LmUSwAABQk"]
[Sun Aug 30 03:06:29.536136 2026] [security2:error] [pid 496962:tid 497160] [client 20.151.200.44:64686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/tf.php"] [unique_id "apPkhY6aRhSu8gis9LmUYAAABPE"]
[Sun Aug 30 03:06:29.546372 2026] [security2:error] [pid 496962:tid 497171] [client 20.48.251.3:44300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/erty.php"] [unique_id "apPkhY6aRhSu8gis9LmUYwAABPw"]
[Sun Aug 30 03:06:29.553137 2026] [security2:error] [pid 496962:tid 497097] [client 4.205.62.107:56579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/phpversion.php"] [unique_id "apPkhY6aRhSu8gis9LmUZgAABLI"]
[Sun Aug 30 03:06:29.554042 2026] [security2:error] [pid 496962:tid 497166] [client 20.104.50.220:56713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/bingo.php"] [unique_id "apPkhY6aRhSu8gis9LmUZwAABPc"]
[Sun Aug 30 03:06:29.559095 2026] [security2:error] [pid 496962:tid 497207] [client 158.23.147.79:53540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-admin.php"] [unique_id "apPkhY6aRhSu8gis9LmUbgAABSA"]
[Sun Aug 30 03:06:29.565878 2026] [security2:error] [pid 496962:tid 497095] [client 158.23.147.79:62489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/images/index.php"] [unique_id "apPkhY6aRhSu8gis9LmUcwAABLA"]
[Sun Aug 30 03:06:29.566304 2026] [authz_core:error] [pid 496962:tid 497100] [client 66.249.66.70:50168] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:29.566590 2026] [authz_core:error] [pid 496962:tid 497100] [client 66.249.66.70:50168] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:29.577190 2026] [security2:error] [pid 496962:tid 497184] [client 20.104.18.15:28619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/100.php"] [unique_id "apPkhY6aRhSu8gis9LmUfgAABQk"]
[Sun Aug 30 03:06:29.579198 2026] [security2:error] [pid 496962:tid 497156] [client 158.23.147.79:4038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-l0gin.php"] [unique_id "apPkhY6aRhSu8gis9LmUgAAABO0"]
[Sun Aug 30 03:06:29.603445 2026] [security2:error] [pid 496962:tid 497199] [client 4.205.62.107:32456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/snq.php"] [unique_id "apPkhY6aRhSu8gis9LmUjQAABRg"]
[Sun Aug 30 03:06:29.630869 2026] [security2:error] [pid 496962:tid 497178] [client 4.205.62.107:60558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/cu.php"] [unique_id "apPkhY6aRhSu8gis9LmUlQAABQM"]
[Sun Aug 30 03:06:29.673022 2026] [security2:error] [pid 496962:tid 497117] [client 158.23.147.79:54643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-includes/assets/index.php"] [unique_id "apPkhY6aRhSu8gis9LmUqgAABMY"]
[Sun Aug 30 03:06:29.679678 2026] [security2:error] [pid 496962:tid 497172] [client 158.23.147.79:54649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-admin/admin.php"] [unique_id "apPkhY6aRhSu8gis9LmUqwAABP0"]
[Sun Aug 30 03:06:29.686974 2026] [authz_core:error] [pid 496962:tid 497200] [client 66.249.66.70:39911] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:29.687279 2026] [authz_core:error] [pid 496962:tid 497200] [client 66.249.66.70:39911] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:29.694698 2026] [security2:error] [pid 496962:tid 497180] [client 20.151.200.44:64033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/update/da222.php"] [unique_id "apPkhY6aRhSu8gis9LmUrgAABQU"]
[Sun Aug 30 03:06:29.703240 2026] [security2:error] [pid 496962:tid 497163] [client 158.23.147.79:42091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apPkhY6aRhSu8gis9LmUrwAABPQ"]
[Sun Aug 30 03:06:29.738866 2026] [security2:error] [pid 496962:tid 497155] [client 20.104.50.220:5590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/elp.php"] [unique_id "apPkhY6aRhSu8gis9LmUwAAABOw"]
[Sun Aug 30 03:06:29.740902 2026] [security2:error] [pid 496962:tid 497148] [client 20.104.18.15:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apPkhY6aRhSu8gis9LmUwwAABOU"]
[Sun Aug 30 03:06:29.759237 2026] [security2:error] [pid 496962:tid 497097] [client 4.205.62.107:31683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/wp-access.php"] [unique_id "apPkhY6aRhSu8gis9LmUyQAABLI"]
[Sun Aug 30 03:06:29.765798 2026] [security2:error] [pid 496962:tid 497196] [client 20.197.61.180:14062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/themes/panel.php"] [unique_id "apPkhY6aRhSu8gis9LmUzAAABRU"]
[Sun Aug 30 03:06:29.797296 2026] [security2:error] [pid 496962:tid 497109] [client 158.23.147.79:4040] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.auscreen.com.au"] [uri "/ioxi002.PhP7"] [unique_id "apPkhY6aRhSu8gis9LmU2QAABL4"]
[Sun Aug 30 03:06:29.822278 2026] [security2:error] [pid 496962:tid 497134] [client 20.48.251.3:50045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/plss3.php"] [unique_id "apPkhY6aRhSu8gis9LmU3gAABNc"]
[Sun Aug 30 03:06:29.839129 2026] [security2:error] [pid 496962:tid 497180] [client 20.151.200.44:64036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/qi.php"] [unique_id "apPkhY6aRhSu8gis9LmU4wAABQU"]
[Sun Aug 30 03:06:29.850892 2026] [security2:error] [pid 496962:tid 497096] [client 158.23.147.79:53518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-includes/IXR/index.php"] [unique_id "apPkhY6aRhSu8gis9LmU6AAABLE"]
[Sun Aug 30 03:06:29.882418 2026] [authz_core:error] [pid 496962:tid 497118] [client 216.73.216.128:5523] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:29.882810 2026] [authz_core:error] [pid 496962:tid 497118] [client 216.73.216.128:5523] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:29.892829 2026] [security2:error] [pid 496962:tid 497213] [client 158.23.147.79:62499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apPkhY6aRhSu8gis9LmU9gAABSY"]
[Sun Aug 30 03:06:29.895985 2026] [security2:error] [pid 496962:tid 497097] [client 20.104.50.220:32107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/doc.php"] [unique_id "apPkhY6aRhSu8gis9LmU-QAABLI"]
[Sun Aug 30 03:06:29.907258 2026] [security2:error] [pid 496962:tid 497189] [client 20.48.251.3:64484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/124.php"] [unique_id "apPkhY6aRhSu8gis9LmU_wAABQ4"]
[Sun Aug 30 03:06:29.939496 2026] [security2:error] [pid 496962:tid 497173] [client 68.155.159.216:56442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/atomlib.php"] [unique_id "apPkhY6aRhSu8gis9LmVCwAABP4"]
[Sun Aug 30 03:06:29.941410 2026] [security2:error] [pid 496962:tid 497110] [client 4.205.62.107:58129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/drykl.php"] [unique_id "apPkhY6aRhSu8gis9LmVDAAABL8"]
[Sun Aug 30 03:06:29.969931 2026] [security2:error] [pid 496962:tid 497193] [client 20.151.200.44:64607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/px.php"] [unique_id "apPkhY6aRhSu8gis9LmVFwAABRI"]
[Sun Aug 30 03:06:29.986461 2026] [security2:error] [pid 496962:tid 497122] [client 85.208.96.198:33050] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arcaneguardians.com"] [uri "/caayjc/types-of-interface-specification-in-software-engineering"] [unique_id "apPkhY6aRhSu8gis9LmVHwAABMs"]
[Sun Aug 30 03:06:29.986623 2026] [security2:error] [pid 496962:tid 497122] [client 85.208.96.198:33050] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "arcaneguardians.com"] [uri "/caayjc/types-of-interface-specification-in-software-engineering"] [unique_id "apPkhY6aRhSu8gis9LmVHwAABMs"]
[Sun Aug 30 03:06:30.028038 2026] [security2:error] [pid 496962:tid 497099] [client 4.205.62.107:2982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/test.php"] [unique_id "apPkho6aRhSu8gis9LmVLAAABLQ"]
[Sun Aug 30 03:06:30.054195 2026] [security2:error] [pid 496962:tid 497194] [client 20.151.200.44:47413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/admin.php/csv.php"] [unique_id "apPkho6aRhSu8gis9LmVMAAABRM"]
[Sun Aug 30 03:06:30.091293 2026] [autoindex:error] [pid 496962:tid 497208] [client 3.85.196.206:25182] AH01276: Cannot serve directory /home3/antgre7/public_html/therichemployed.info/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:06:30.109426 2026] [security2:error] [pid 496962:tid 497117] [client 68.155.159.216:12320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apPkho6aRhSu8gis9LmVSgAABMY"]
[Sun Aug 30 03:06:30.130261 2026] [security2:error] [pid 496962:tid 497096] [client 20.151.200.44:63939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/is.php"] [unique_id "apPkho6aRhSu8gis9LmVUAAABLE"]
[Sun Aug 30 03:06:30.160932 2026] [authz_core:error] [pid 496962:tid 497135] [client 216.73.216.128:39775] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:30.161239 2026] [authz_core:error] [pid 496962:tid 497135] [client 216.73.216.128:39775] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:30.242696 2026] [authz_core:error] [pid 496962:tid 497139] [client 66.249.66.65:48934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:30.243079 2026] [authz_core:error] [pid 496962:tid 497139] [client 66.249.66.65:48934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:30.260105 2026] [security2:error] [pid 496962:tid 497181] [client 20.151.200.44:64663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/od.php"] [unique_id "apPkho6aRhSu8gis9LmVgAAABQY"]
[Sun Aug 30 03:06:30.269567 2026] [security2:error] [pid 496962:tid 497216] [client 4.205.62.107:18653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/chosen.php"] [unique_id "apPkho6aRhSu8gis9LmVhQAABSk"]
[Sun Aug 30 03:06:30.276053 2026] [security2:error] [pid 496962:tid 497146] [client 4.205.62.107:22957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/loxi-o.php"] [unique_id "apPkho6aRhSu8gis9LmViQAABOM"]
[Sun Aug 30 03:06:30.282206 2026] [authz_core:error] [pid 496962:tid 497191] [client 66.249.66.70:50168] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:30.282494 2026] [authz_core:error] [pid 496962:tid 497191] [client 66.249.66.70:50168] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:30.315967 2026] [security2:error] [pid 496962:tid 497122] [client 68.155.159.216:17351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apPkho6aRhSu8gis9LmVkwAABMs"]
[Sun Aug 30 03:06:30.342086 2026] [authz_core:error] [pid 496962:tid 497096] [client 66.249.66.36:50007] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:30.342551 2026] [authz_core:error] [pid 496962:tid 497096] [client 66.249.66.36:50007] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:30.350962 2026] [security2:error] [pid 496962:tid 497185] [client 4.205.62.107:5075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/params.php"] [unique_id "apPkho6aRhSu8gis9LmVpAAABQo"]
[Sun Aug 30 03:06:30.351800 2026] [security2:error] [pid 496962:tid 497107] [client 68.155.159.216:60865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apPkho6aRhSu8gis9LmVpQAABLw"]
[Sun Aug 30 03:06:30.382802 2026] [security2:error] [pid 496962:tid 497104] [client 4.205.62.107:64055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/mcebraed.php"] [unique_id "apPkho6aRhSu8gis9LmVsQAABLk"]
[Sun Aug 30 03:06:30.391825 2026] [security2:error] [pid 496962:tid 497215] [client 20.104.50.220:27532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/dede/login.php"] [unique_id "apPkho6aRhSu8gis9LmVtQAABSg"]
[Sun Aug 30 03:06:30.399577 2026] [authz_core:error] [pid 496962:tid 497207] [client 66.249.66.69:45983] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:30.399863 2026] [authz_core:error] [pid 496962:tid 497207] [client 66.249.66.69:45983] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:30.415147 2026] [core:alert] [pid 496962:tid 497180] [client 5.36.162.99:53420] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:06:30.440989 2026] [security2:error] [pid 496962:tid 497132] [client 20.104.50.220:29174] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "www.prod.sapientbydesign.com"] [uri "/r57.php"] [unique_id "apPkho6aRhSu8gis9LmVxQAABNU"]
[Sun Aug 30 03:06:30.444535 2026] [security2:error] [pid 496962:tid 497177] [client 20.104.49.130:52423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/dk.php"] [unique_id "apPkho6aRhSu8gis9LmVyAAABQI"]
[Sun Aug 30 03:06:30.486838 2026] [security2:error] [pid 496962:tid 497094] [client 45.3.55.204:15873] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "belloinsights.com"] [uri "/"] [unique_id "apPkho6aRhSu8gis9LmV3QAABK8"]
[Sun Aug 30 03:06:30.489849 2026] [security2:error] [pid 496962:tid 497140] [client 20.151.200.44:64000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/wp-the.php"] [unique_id "apPkho6aRhSu8gis9LmV4AAABN0"]
[Sun Aug 30 03:06:30.534240 2026] [security2:error] [pid 496962:tid 497172] [client 20.104.18.15:13696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/ah.php"] [unique_id "apPkho6aRhSu8gis9LmV8gAABP0"]
[Sun Aug 30 03:06:30.560662 2026] [security2:error] [pid 496962:tid 497095] [client 68.155.159.216:61352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apPkho6aRhSu8gis9LmV_wAABLA"]
[Sun Aug 30 03:06:30.575269 2026] [security2:error] [pid 496962:tid 497143] [client 4.205.62.107:26522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/cu.php"] [unique_id "apPkho6aRhSu8gis9LmWBQAABOA"]
[Sun Aug 30 03:06:30.612384 2026] [security2:error] [pid 496962:tid 497156] [client 20.104.50.220:59555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/Cpanel.php"] [unique_id "apPkho6aRhSu8gis9LmWFwAABO0"]
[Sun Aug 30 03:06:30.614324 2026] [security2:error] [pid 496962:tid 497137] [client 20.104.18.15:43999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/indo.php"] [unique_id "apPkho6aRhSu8gis9LmWGAAABNo"]
[Sun Aug 30 03:06:30.625299 2026] [security2:error] [pid 496962:tid 497157] [client 20.104.50.220:47062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/phpinfo.php"] [unique_id "apPkho6aRhSu8gis9LmWIAAABO4"]
[Sun Aug 30 03:06:30.692376 2026] [security2:error] [pid 496962:tid 497169] [client 20.104.50.220:51645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/backd00rshit.php"] [unique_id "apPkho6aRhSu8gis9LmWPAAABPo"]
[Sun Aug 30 03:06:30.710887 2026] [authz_core:error] [pid 496962:tid 497129] [client 66.249.66.43:49752] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:30.711360 2026] [authz_core:error] [pid 496962:tid 497129] [client 66.249.66.43:49752] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:30.714552 2026] [security2:error] [pid 496962:tid 497157] [client 20.104.18.15:28557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/about.php"] [unique_id "apPkho6aRhSu8gis9LmWRwAABO4"]
[Sun Aug 30 03:06:30.717863 2026] [authz_core:error] [pid 496962:tid 497123] [client 66.249.66.65:56667] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:30.718150 2026] [authz_core:error] [pid 496962:tid 497123] [client 66.249.66.65:56667] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:30.719441 2026] [security2:error] [pid 496962:tid 497111] [client 4.205.62.107:51724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/adminfus.php"] [unique_id "apPkho6aRhSu8gis9LmWSQAABMA"]
[Sun Aug 30 03:06:30.725345 2026] [security2:error] [pid 496962:tid 497193] [client 216.73.216.128:50876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPkho6aRhSu8gis9LmWTgAABRI"]
[Sun Aug 30 03:06:30.733975 2026] [security2:error] [pid 496962:tid 497215] [client 20.197.61.180:14037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/twentytwentyfive/styles/sections/pk.php"] [unique_id "apPkho6aRhSu8gis9LmWUgAABSg"]
[Sun Aug 30 03:06:30.750263 2026] [security2:error] [pid 496962:tid 497165] [client 20.151.200.44:64582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/wt.php"] [unique_id "apPkho6aRhSu8gis9LmWVQAABPY"]
[Sun Aug 30 03:06:30.754323 2026] [security2:error] [pid 496962:tid 497115] [client 20.48.251.3:4680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/wp-config.backup.php"] [unique_id "apPkho6aRhSu8gis9LmWVgAABMQ"]
[Sun Aug 30 03:06:30.760531 2026] [security2:error] [pid 496962:tid 497176] [client 4.205.62.107:60549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/services.php"] [unique_id "apPkho6aRhSu8gis9LmWWQAABQE"]
[Sun Aug 30 03:06:30.805639 2026] [security2:error] [pid 496962:tid 497139] [client 20.220.10.235:39847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkho6aRhSu8gis9LmWbgAABNw"]
[Sun Aug 30 03:06:30.831788 2026] [authz_core:error] [pid 496962:tid 497109] [client 66.249.66.38:43330] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:30.832243 2026] [authz_core:error] [pid 496962:tid 497109] [client 66.249.66.38:43330] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:30.879635 2026] [security2:error] [pid 496962:tid 497171] [client 20.104.18.15:32973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/sao.php"] [unique_id "apPkho6aRhSu8gis9LmWiQAABPw"]
[Sun Aug 30 03:06:30.879677 2026] [security2:error] [pid 496962:tid 497110] [client 20.104.50.220:5611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wtz.php"] [unique_id "apPkho6aRhSu8gis9LmWigAABL8"]
[Sun Aug 30 03:06:30.915380 2026] [authz_core:error] [pid 496962:tid 497213] [client 216.73.216.128:39775] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:30.915674 2026] [authz_core:error] [pid 496962:tid 497213] [client 216.73.216.128:39775] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:30.933183 2026] [security2:error] [pid 496962:tid 497102] [client 20.220.10.235:40771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkho6aRhSu8gis9LmWrAAABLc"]
[Sun Aug 30 03:06:30.956112 2026] [authz_core:error] [pid 496962:tid 497174] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fopt%2Fcpanel%2Fea-php81%2Froot%2Fvar%2Flib%2Fpear%2Fpkgxml
[Sun Aug 30 03:06:30.956400 2026] [authz_core:error] [pid 496962:tid 497174] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fopt%2Fcpanel%2Fea-php81%2Froot%2Fvar%2Flib%2Fpear%2Fpkgxml
[Sun Aug 30 03:06:30.963899 2026] [security2:error] [pid 496962:tid 497103] [client 20.48.251.3:12094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/aws.php"] [unique_id "apPkho6aRhSu8gis9LmWuAAABLg"]
[Sun Aug 30 03:06:31.033334 2026] [security2:error] [pid 496962:tid 497112] [client 20.104.50.220:31849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/docindex.php"] [unique_id "apPkh46aRhSu8gis9LmWzgAABME"]
[Sun Aug 30 03:06:31.038287 2026] [security2:error] [pid 496962:tid 497134] [client 20.48.251.3:45880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/test1.php"] [unique_id "apPkh46aRhSu8gis9LmW0AAABNc"]
[Sun Aug 30 03:06:31.052662 2026] [security2:error] [pid 496962:tid 497155] [client 68.155.159.216:56441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/lv.php"] [unique_id "apPkh46aRhSu8gis9LmW0wAABOw"]
[Sun Aug 30 03:06:31.062307 2026] [security2:error] [pid 496962:tid 497215] [client 20.220.10.235:40784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/h02ugyh.php"] [unique_id "apPkh46aRhSu8gis9LmW1gAABSg"]
[Sun Aug 30 03:06:31.067828 2026] [security2:error] [pid 496962:tid 497145] [client 20.104.104.62:48702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkh46aRhSu8gis9LmW2AAABOI"]
[Sun Aug 30 03:06:31.076600 2026] [security2:error] [pid 496962:tid 497192] [client 20.151.200.44:64611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/im.php"] [unique_id "apPkh46aRhSu8gis9LmW3QAABRE"]
[Sun Aug 30 03:06:31.150946 2026] [security2:error] [pid 496962:tid 497106] [client 4.205.62.107:36007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cce.edu.ng"] [uri "/wp-act.php"] [unique_id "apPkh46aRhSu8gis9LmW9wAABLs"]
[Sun Aug 30 03:06:31.159234 2026] [security2:error] [pid 496962:tid 497166] [client 4.205.62.107:65346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/rpk.php"] [unique_id "apPkh46aRhSu8gis9LmW_QAABPc"]
[Sun Aug 30 03:06:31.168159 2026] [security2:error] [pid 496962:tid 497112] [client 4.205.62.107:2309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/cloud.php"] [unique_id "apPkh46aRhSu8gis9LmXAgAABME"]
[Sun Aug 30 03:06:31.195237 2026] [security2:error] [pid 496962:tid 497207] [client 20.220.10.235:40775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/sf.php"] [unique_id "apPkh46aRhSu8gis9LmXFgAABSA"]
[Sun Aug 30 03:06:31.196389 2026] [security2:error] [pid 496962:tid 497107] [client 4.205.62.107:58310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/otuz1.php"] [unique_id "apPkh46aRhSu8gis9LmXFwAABLw"]
[Sun Aug 30 03:06:31.202224 2026] [security2:error] [pid 496962:tid 497103] [client 20.104.104.62:48670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkh46aRhSu8gis9LmXHAAABLg"]
[Sun Aug 30 03:06:31.222695 2026] [security2:error] [pid 496962:tid 497121] [client 68.155.159.216:65487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/login.php"] [unique_id "apPkh46aRhSu8gis9LmXJAAABMo"]
[Sun Aug 30 03:06:31.234399 2026] [security2:error] [pid 496962:tid 497122] [client 74.7.230.5:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "rib.chg.temporary.site"] [uri "/robots.txt"] [unique_id "apPkh46aRhSu8gis9LmXJgAABMs"]
[Sun Aug 30 03:06:31.235303 2026] [security2:error] [pid 496962:tid 497217] [client 74.7.230.5:33174] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "rib.chg.temporary.site"] [uri "/robots.txt"] [unique_id "apPkh46aRhSu8gis9LmXIQAABSo"]
[Sun Aug 30 03:06:31.256381 2026] [authz_core:error] [pid 496962:tid 497191] [client 66.249.66.65:41542] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:31.256718 2026] [authz_core:error] [pid 496962:tid 497191] [client 66.249.66.65:41542] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:31.288147 2026] [authz_core:error] [pid 496962:tid 497169] [client 66.249.66.76:63021] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:31.288435 2026] [authz_core:error] [pid 496962:tid 497169] [client 66.249.66.76:63021] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:31.325171 2026] [security2:error] [pid 496962:tid 497135] [client 20.220.10.235:40803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/4e.php"] [unique_id "apPkh46aRhSu8gis9LmXQQAABNg"]
[Sun Aug 30 03:06:31.338118 2026] [security2:error] [pid 496962:tid 497212] [client 20.104.104.62:48475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/h02ugyh.php"] [unique_id "apPkh46aRhSu8gis9LmXRQAABSU"]
[Sun Aug 30 03:06:31.339080 2026] [security2:error] [pid 496962:tid 497128] [client 74.7.230.5:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rib.chg.temporary.site"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "apPkh46aRhSu8gis9LmXOQAABNE"], referer: https://rib.chg.temporary.site/robots.txt
[Sun Aug 30 03:06:31.352699 2026] [authz_core:error] [pid 496962:tid 497140] [client 66.249.66.195:36816] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:31.352981 2026] [authz_core:error] [pid 496962:tid 497140] [client 66.249.66.195:36816] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:31.375286 2026] [security2:error] [pid 496962:tid 497167] [client 74.7.230.5:33174] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rib.chg.temporary.site"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "apPkh46aRhSu8gis9LmXMwAABPg"], referer: https://rib.chg.temporary.site/robots.txt
[Sun Aug 30 03:06:31.378667 2026] [security2:error] [pid 496962:tid 497078] [remote 192.42.116.145:49691] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 145.116.42.192.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "shreaves.com"] [uri "/wp-comments-post.php"] [unique_id "apPkh46aRhSu8gis9LmXSQAFI3M"], referer: https://shreaves.com/wp-comments-post.php
[Sun Aug 30 03:06:31.378909 2026] [security2:error] [pid 496962:tid 497210] [client 192.42.116.145:49691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "shreaves.com"] [uri "/wp-comments-post.php"] [unique_id "apPkh46aRhSu8gis9LmXSQAFI3M"], referer: https://shreaves.com/wp-comments-post.php
[Sun Aug 30 03:06:31.415085 2026] [security2:error] [pid 496962:tid 497183] [client 4.205.62.107:18673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/admin-ajax.php"] [unique_id "apPkh46aRhSu8gis9LmXYgAABQg"]
[Sun Aug 30 03:06:31.458268 2026] [security2:error] [pid 496962:tid 497143] [client 4.205.62.107:22953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/f35.php"] [unique_id "apPkh46aRhSu8gis9LmXcQAABOA"]
[Sun Aug 30 03:06:31.461153 2026] [security2:error] [pid 496962:tid 497204] [client 20.220.10.235:39867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/ssss.php"] [unique_id "apPkh46aRhSu8gis9LmXcwAABR0"]
[Sun Aug 30 03:06:31.483782 2026] [security2:error] [pid 496962:tid 497207] [client 20.104.104.62:48460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/sf.php"] [unique_id "apPkh46aRhSu8gis9LmXewAABSA"]
[Sun Aug 30 03:06:31.485034 2026] [security2:error] [pid 496962:tid 497107] [client 4.205.62.107:5101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/gjm.php"] [unique_id "apPkh46aRhSu8gis9LmXfAAABLw"]
[Sun Aug 30 03:06:31.491022 2026] [security2:error] [pid 496962:tid 497105] [client 68.155.159.216:60908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apPkh46aRhSu8gis9LmXgQAABLo"]
[Sun Aug 30 03:06:31.497092 2026] [security2:error] [pid 496962:tid 497098] [client 68.155.159.216:54130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apPkh46aRhSu8gis9LmXgwAABLM"]
[Sun Aug 30 03:06:31.530601 2026] [security2:error] [pid 496962:tid 497184] [client 20.104.50.220:27081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/admindede/login.php"] [unique_id "apPkh46aRhSu8gis9LmXmQAABQk"]
[Sun Aug 30 03:06:31.532451 2026] [security2:error] [pid 496962:tid 497103] [client 4.205.62.107:63961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/server-info.php"] [unique_id "apPkh46aRhSu8gis9LmXmgAABLg"]
[Sun Aug 30 03:06:31.570964 2026] [authz_core:error] [pid 496962:tid 497188] [client 216.73.216.128:5523] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:31.571251 2026] [authz_core:error] [pid 496962:tid 497188] [client 216.73.216.128:5523] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:31.575292 2026] [security2:error] [pid 496962:tid 497214] [client 20.104.50.220:52823] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "www.prod.sapientbydesign.com"] [uri "/c99.php"] [unique_id "apPkh46aRhSu8gis9LmXsQAABSc"]
[Sun Aug 30 03:06:31.577974 2026] [security2:error] [pid 496962:tid 497127] [client 4.205.62.107:32061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/update.php"] [unique_id "apPkh46aRhSu8gis9LmXsgAABNA"]
[Sun Aug 30 03:06:31.598338 2026] [security2:error] [pid 496962:tid 497173] [client 20.220.10.235:39815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/zoz.php"] [unique_id "apPkh46aRhSu8gis9LmXvQAABP4"]
[Sun Aug 30 03:06:31.599820 2026] [security2:error] [pid 496962:tid 497146] [client 20.151.200.44:37877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/admin.php/csv.php"] [unique_id "apPkh46aRhSu8gis9LmXwQAABOM"]
[Sun Aug 30 03:06:31.625914 2026] [security2:error] [pid 496962:tid 497164] [client 20.104.104.62:48595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/4e.php"] [unique_id "apPkh46aRhSu8gis9LmX0AAABPU"]
[Sun Aug 30 03:06:31.670349 2026] [security2:error] [pid 496962:tid 497163] [client 20.104.18.15:13731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/ws55.php"] [unique_id "apPkh46aRhSu8gis9LmX5QAABPQ"]
[Sun Aug 30 03:06:31.688099 2026] [security2:error] [pid 496962:tid 497176] [client 20.197.61.180:13906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/twentytwentythree/patterns/index.php"] [unique_id "apPkh46aRhSu8gis9LmX6AAABQE"]
[Sun Aug 30 03:06:31.692283 2026] [security2:error] [pid 496962:tid 497139] [client 68.155.159.216:63953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-content/radio.php"] [unique_id "apPkh46aRhSu8gis9LmX6QAABNw"]
[Sun Aug 30 03:06:31.694879 2026] [security2:error] [pid 496962:tid 497131] [client 74.7.241.128:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.giftballs.bayoutents.com"] [uri "/index.php"] [unique_id "apPkho6aRhSu8gis9LmWcQAABNQ"]
[Sun Aug 30 03:06:31.696031 2026] [security2:error] [pid 496962:tid 497180] [client 74.7.241.128:60078] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.giftballs.bayoutents.com"] [uri "/robots.txt"] [unique_id "apPkho6aRhSu8gis9LmWaQAFBWw"]
[Sun Aug 30 03:06:31.708866 2026] [security2:error] [pid 496962:tid 497195] [client 45.3.55.204:39771] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "belloinsights.com"] [uri "/"] [unique_id "apPkh46aRhSu8gis9LmX6wAABRQ"]
[Sun Aug 30 03:06:31.724237 2026] [security2:error] [pid 496962:tid 497192] [client 20.220.10.235:39827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/kcs.php"] [unique_id "apPkh46aRhSu8gis9LmX9QAABRE"]
[Sun Aug 30 03:06:31.729299 2026] [security2:error] [pid 496962:tid 497153] [client 20.104.50.220:33285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/anu.php"] [unique_id "apPkh46aRhSu8gis9LmX-gAABOo"]
[Sun Aug 30 03:06:31.763327 2026] [security2:error] [pid 496962:tid 497106] [client 20.104.50.220:46642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/postfs.php"] [unique_id "apPkh46aRhSu8gis9LmYAQAABLs"]
[Sun Aug 30 03:06:31.765800 2026] [security2:error] [pid 496962:tid 497101] [client 20.104.104.62:48506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/ssss.php"] [unique_id "apPkh46aRhSu8gis9LmYAwAABLY"]
[Sun Aug 30 03:06:31.767209 2026] [security2:error] [pid 496962:tid 497101] [client 20.151.200.44:64010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/file.php"] [unique_id "apPkh46aRhSu8gis9LmYBAAABLY"]
[Sun Aug 30 03:06:31.786100 2026] [security2:error] [pid 496962:tid 497183] [client 20.151.200.44:47061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/png.php"] [unique_id "apPkh46aRhSu8gis9LmYEgAABQg"]
[Sun Aug 30 03:06:31.797730 2026] [security2:error] [pid 496962:tid 497152] [client 20.104.50.220:59547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/unknown.php"] [unique_id "apPkh46aRhSu8gis9LmYFAAABOk"]
[Sun Aug 30 03:06:31.798334 2026] [security2:error] [pid 496962:tid 497107] [client 20.151.200.44:47310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/admin.php/700.php"] [unique_id "apPkh46aRhSu8gis9LmYFwAABLw"]
[Sun Aug 30 03:06:31.802790 2026] [security2:error] [pid 496962:tid 497216] [client 20.104.18.15:43287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/sign.php"] [unique_id "apPkh46aRhSu8gis9LmYGQAABSk"]
[Sun Aug 30 03:06:31.835905 2026] [security2:error] [pid 496962:tid 497219] [client 20.104.50.220:63532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/ichi.php"] [unique_id "apPkh46aRhSu8gis9LmYJAAABSw"]
[Sun Aug 30 03:06:31.849140 2026] [authz_core:error] [pid 496962:tid 497160] [client 216.73.216.128:5523] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:31.849599 2026] [authz_core:error] [pid 496962:tid 497160] [client 216.73.216.128:5523] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:31.856604 2026] [security2:error] [pid 496962:tid 497105] [client 20.104.18.15:28646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/about.php"] [unique_id "apPkh46aRhSu8gis9LmYLAAABLo"]
[Sun Aug 30 03:06:31.858348 2026] [security2:error] [pid 496962:tid 497121] [client 20.220.10.235:40800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/tajj.php"] [unique_id "apPkh46aRhSu8gis9LmYLQAABMo"]
[Sun Aug 30 03:06:31.860094 2026] [security2:error] [pid 496962:tid 497110] [client 4.205.62.107:51720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/avim.php"] [unique_id "apPkh46aRhSu8gis9LmYLwAABL8"]
[Sun Aug 30 03:06:31.882553 2026] [security2:error] [pid 496962:tid 497190] [client 20.104.50.220:62798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/mygagal.php"] [unique_id "apPkh46aRhSu8gis9LmYOQAABQ8"]
[Sun Aug 30 03:06:31.901592 2026] [security2:error] [pid 496962:tid 497149] [client 20.48.251.3:4685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/edit.php"] [unique_id "apPkh46aRhSu8gis9LmYRQAABOY"]
[Sun Aug 30 03:06:31.902043 2026] [security2:error] [pid 496962:tid 497199] [client 20.104.104.62:48696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/zoz.php"] [unique_id "apPkh46aRhSu8gis9LmYRgAABRg"]
[Sun Aug 30 03:06:31.909424 2026] [security2:error] [pid 496962:tid 497129] [client 4.205.62.107:63584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/filesystems.php"] [unique_id "apPkh46aRhSu8gis9LmYTAAABNI"]
[Sun Aug 30 03:06:31.939009 2026] [authz_core:error] [pid 496962:tid 497111] [client 66.249.66.45:43898] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:31.939468 2026] [authz_core:error] [pid 496962:tid 497111] [client 66.249.66.45:43898] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:31.966898 2026] [security2:error] [pid 496962:tid 497173] [client 4.205.62.107:27312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/services.php"] [unique_id "apPkh46aRhSu8gis9LmYYwAABP4"]
[Sun Aug 30 03:06:31.988268 2026] [security2:error] [pid 496962:tid 497094] [client 20.220.10.235:39808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/bge.php"] [unique_id "apPkh46aRhSu8gis9LmYbAAABK8"]
[Sun Aug 30 03:06:32.013049 2026] [security2:error] [pid 496962:tid 497156] [client 20.151.200.44:27274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkiI6aRhSu8gis9LmYcgAABO0"]
[Sun Aug 30 03:06:32.016944 2026] [security2:error] [pid 496962:tid 497102] [client 20.104.50.220:5532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/galex.php"] [unique_id "apPkiI6aRhSu8gis9LmYdAAABLc"]
[Sun Aug 30 03:06:32.021113 2026] [security2:error] [pid 496962:tid 497150] [client 216.73.216.128:35744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPkiI6aRhSu8gis9LmYdQAABOc"]
[Sun Aug 30 03:06:32.034007 2026] [security2:error] [pid 496962:tid 497154] [client 20.151.200.44:65229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/ca.php"] [unique_id "apPkiI6aRhSu8gis9LmYeAAABOs"]
[Sun Aug 30 03:06:32.051119 2026] [security2:error] [pid 496962:tid 497199] [client 20.104.104.62:48648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/kcs.php"] [unique_id "apPkiI6aRhSu8gis9LmYfQAABRg"]
[Sun Aug 30 03:06:32.097624 2026] [security2:error] [pid 496962:tid 497197] [client 20.104.18.15:33745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/dapa.php"] [unique_id "apPkiI6aRhSu8gis9LmYjwAABRY"]
[Sun Aug 30 03:06:32.101716 2026] [security2:error] [pid 496962:tid 497219] [client 20.48.251.3:49936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/app.default.php"] [unique_id "apPkiI6aRhSu8gis9LmYlAAABSw"]
[Sun Aug 30 03:06:32.102261 2026] [security2:error] [pid 496962:tid 497212] [client 185.179.142.219:45208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.142.179.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "laserfx.ae"] [uri "/wp-login.php"] [unique_id "apPkiI6aRhSu8gis9LmYhgAABSU"]
[Sun Aug 30 03:06:32.107663 2026] [authz_core:error] [pid 496962:tid 497185] [client 74.7.227.8:56966] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare
[Sun Aug 30 03:06:32.107930 2026] [authz_core:error] [pid 496962:tid 497185] [client 74.7.227.8:56966] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare
[Sun Aug 30 03:06:32.125090 2026] [security2:error] [pid 496962:tid 497128] [client 20.220.10.235:39821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/ssh3ll.php"] [unique_id "apPkiI6aRhSu8gis9LmYnAAABNE"]
[Sun Aug 30 03:06:32.167411 2026] [security2:error] [pid 496962:tid 497101] [client 68.155.159.216:11236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apPkiI6aRhSu8gis9LmYqQAABLY"]
[Sun Aug 30 03:06:32.185426 2026] [security2:error] [pid 496962:tid 497143] [client 20.104.50.220:32119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/dosya.php"] [unique_id "apPkiI6aRhSu8gis9LmYsgAABOA"]
[Sun Aug 30 03:06:32.187458 2026] [security2:error] [pid 496962:tid 497165] [client 20.48.251.3:44109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/bigdump.php"] [unique_id "apPkiI6aRhSu8gis9LmYtAAABPY"]
[Sun Aug 30 03:06:32.187631 2026] [security2:error] [pid 496962:tid 497179] [client 20.104.104.62:48666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/tajj.php"] [unique_id "apPkiI6aRhSu8gis9LmYtgAABQQ"]
[Sun Aug 30 03:06:32.210867 2026] [authz_core:error] [pid 496962:tid 497127] [client 66.249.66.36:59301] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:32.211137 2026] [authz_core:error] [pid 496962:tid 497127] [client 66.249.66.36:59301] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:32.251379 2026] [security2:error] [pid 496962:tid 497146] [client 20.220.10.235:39849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/motu.php"] [unique_id "apPkiI6aRhSu8gis9LmYzQAABOM"]
[Sun Aug 30 03:06:32.314712 2026] [security2:error] [pid 496962:tid 497126] [client 4.205.62.107:2752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/asdf.php"] [unique_id "apPkiI6aRhSu8gis9LmY4AAABM8"]
[Sun Aug 30 03:06:32.317180 2026] [security2:error] [pid 496962:tid 497150] [client 20.104.104.62:48587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/bge.php"] [unique_id "apPkiI6aRhSu8gis9LmY4QAABOc"]
[Sun Aug 30 03:06:32.358902 2026] [security2:error] [pid 496962:tid 497093] [client 68.155.159.216:12314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/hehehehe.php"] [unique_id "apPkiI6aRhSu8gis9LmY7QAABK4"]
[Sun Aug 30 03:06:32.379878 2026] [security2:error] [pid 496962:tid 497135] [client 20.220.10.235:39810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/wefile.php"] [unique_id "apPkiI6aRhSu8gis9LmY9AAABNg"]
[Sun Aug 30 03:06:32.394549 2026] [security2:error] [pid 496962:tid 497197] [client 20.104.49.130:57532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/memberfuns.php"] [unique_id "apPkiI6aRhSu8gis9LmY-wAABRY"]
[Sun Aug 30 03:06:32.400320 2026] [security2:error] [pid 496962:tid 497162] [client 68.155.159.216:63528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/login.php"] [unique_id "apPkiI6aRhSu8gis9LmY_wAABPM"]
[Sun Aug 30 03:06:32.413910 2026] [security2:error] [pid 496962:tid 497131] [client 4.205.62.107:65282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/saml.php"] [unique_id "apPkiI6aRhSu8gis9LmZBgAABNQ"]
[Sun Aug 30 03:06:32.425035 2026] [authz_core:error] [pid 496962:tid 497140] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fopt%2Fcpanel%2Fea-php83%2Froot%2Fvar%2Flib%2Fpear%2Fpkgxml
[Sun Aug 30 03:06:32.425410 2026] [authz_core:error] [pid 496962:tid 497140] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fopt%2Fcpanel%2Fea-php83%2Froot%2Fvar%2Flib%2Fpear%2Fpkgxml
[Sun Aug 30 03:06:32.460993 2026] [security2:error] [pid 496962:tid 497168] [client 20.151.200.44:64637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/pb.php"] [unique_id "apPkiI6aRhSu8gis9LmZEgAABPk"]
[Sun Aug 30 03:06:32.461066 2026] [security2:error] [pid 496962:tid 497103] [client 20.104.104.62:48644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/ssh3ll.php"] [unique_id "apPkiI6aRhSu8gis9LmZEQAABLg"]
[Sun Aug 30 03:06:32.483059 2026] [authz_core:error] [pid 496962:tid 497119] [client 216.73.216.128:14362] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:32.483366 2026] [authz_core:error] [pid 496962:tid 497119] [client 216.73.216.128:14362] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:32.514011 2026] [security2:error] [pid 496962:tid 497159] [client 20.220.10.235:39858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/Contrller.php"] [unique_id "apPkiI6aRhSu8gis9LmZKQAABPA"]
[Sun Aug 30 03:06:32.561364 2026] [security2:error] [pid 496962:tid 497176] [client 4.205.62.107:19004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/ms.php"] [unique_id "apPkiI6aRhSu8gis9LmZOAAABQE"]
[Sun Aug 30 03:06:32.614904 2026] [security2:error] [pid 496962:tid 497123] [client 4.205.62.107:22940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/api.php"] [unique_id "apPkiI6aRhSu8gis9LmZVwAABMw"]
[Sun Aug 30 03:06:32.621849 2026] [security2:error] [pid 496962:tid 497102] [client 20.151.200.44:55737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/file66.php"] [unique_id "apPkiI6aRhSu8gis9LmZWQAABLc"]
[Sun Aug 30 03:06:32.625346 2026] [security2:error] [pid 496962:tid 497174] [client 20.104.104.62:48504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/motu.php"] [unique_id "apPkiI6aRhSu8gis9LmZWgAABP8"]
[Sun Aug 30 03:06:32.638897 2026] [security2:error] [pid 496962:tid 497190] [client 4.205.62.107:5073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/configuration.php"] [unique_id "apPkiI6aRhSu8gis9LmZXQAABQ8"]
[Sun Aug 30 03:06:32.641730 2026] [security2:error] [pid 496962:tid 497215] [client 20.197.61.180:3305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/users.php"] [unique_id "apPkiI6aRhSu8gis9LmZYAAABSg"]
[Sun Aug 30 03:06:32.651878 2026] [security2:error] [pid 496962:tid 497098] [client 68.155.159.216:59936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apPkiI6aRhSu8gis9LmZaAAABLM"]
[Sun Aug 30 03:06:32.653653 2026] [security2:error] [pid 496962:tid 497134] [client 20.220.10.235:39865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/file66.php"] [unique_id "apPkiI6aRhSu8gis9LmZawAABNc"]
[Sun Aug 30 03:06:32.664821 2026] [authz_core:error] [pid 496962:tid 497167] [client 216.73.216.128:14362] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:32.665088 2026] [authz_core:error] [pid 496962:tid 497167] [client 216.73.216.128:14362] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:32.669428 2026] [security2:error] [pid 496962:tid 497148] [client 20.104.50.220:27083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/phpinfo.php"] [unique_id "apPkiI6aRhSu8gis9LmZcgAABOU"]
[Sun Aug 30 03:06:32.670484 2026] [security2:error] [pid 496962:tid 497176] [client 4.205.62.107:62094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/gk.php"] [unique_id "apPkiI6aRhSu8gis9LmZcwAABQE"]
[Sun Aug 30 03:06:32.676474 2026] [security2:error] [pid 496962:tid 497162] [client 68.155.159.216:62028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/chosen.php"] [unique_id "apPkiI6aRhSu8gis9LmZdAAABPM"]
[Sun Aug 30 03:06:32.719022 2026] [security2:error] [pid 496962:tid 497131] [client 20.104.50.220:62826] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "www.prod.sapientbydesign.com"] [uri "/c99.php"] [unique_id "apPkiI6aRhSu8gis9LmZfAAABNQ"]
[Sun Aug 30 03:06:32.753401 2026] [security2:error] [pid 496962:tid 497119] [client 20.104.104.62:48664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/wefile.php"] [unique_id "apPkiI6aRhSu8gis9LmZhAAABMg"]
[Sun Aug 30 03:06:32.784494 2026] [security2:error] [pid 496962:tid 497102] [client 4.205.62.107:32008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/channels.php"] [unique_id "apPkiI6aRhSu8gis9LmZmAAABLc"]
[Sun Aug 30 03:06:32.794896 2026] [security2:error] [pid 496962:tid 497093] [client 20.220.10.235:40783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/blnux.php"] [unique_id "apPkiI6aRhSu8gis9LmZnAAABK4"]
[Sun Aug 30 03:06:32.818705 2026] [security2:error] [pid 496962:tid 497106] [client 68.155.159.216:61375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apPkiI6aRhSu8gis9LmZowAABLs"]
[Sun Aug 30 03:06:32.822236 2026] [security2:error] [pid 496962:tid 497135] [client 20.104.18.15:13740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/drykl.php"] [unique_id "apPkiI6aRhSu8gis9LmZpAAABNg"]
[Sun Aug 30 03:06:32.863999 2026] [security2:error] [pid 496962:tid 497194] [client 45.3.55.204:51003] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "belloinsights.com"] [uri "/"] [unique_id "apPkiI6aRhSu8gis9LmZtgAABRM"]
[Sun Aug 30 03:06:32.865776 2026] [security2:error] [pid 496962:tid 497138] [client 20.104.50.220:33155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/loip2.php"] [unique_id "apPkiI6aRhSu8gis9LmZuAAABNs"]
[Sun Aug 30 03:06:32.895927 2026] [security2:error] [pid 496962:tid 497133] [client 20.104.104.62:48496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/Contrller.php"] [unique_id "apPkiI6aRhSu8gis9LmZxQAABNY"]
[Sun Aug 30 03:06:32.901846 2026] [security2:error] [pid 496962:tid 497139] [client 20.104.50.220:46391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/pref.php"] [unique_id "apPkiI6aRhSu8gis9LmZyQAABNw"]
[Sun Aug 30 03:06:32.929508 2026] [security2:error] [pid 496962:tid 497215] [client 20.220.10.235:39823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/attack.php"] [unique_id "apPkiI6aRhSu8gis9LmZ2AAABSg"]
[Sun Aug 30 03:06:32.955708 2026] [security2:error] [pid 496962:tid 497198] [client 20.151.200.44:65286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/pk.php"] [unique_id "apPkiI6aRhSu8gis9LmZ5QAABRc"]
[Sun Aug 30 03:06:32.959039 2026] [security2:error] [pid 496962:tid 497179] [client 20.104.18.15:44000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/wnnjpsby.php"] [unique_id "apPkiI6aRhSu8gis9LmZ6AAABQQ"]
[Sun Aug 30 03:06:32.973010 2026] [security2:error] [pid 496962:tid 497149] [client 20.151.200.44:27151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkiI6aRhSu8gis9LmZ7wAABOY"]
[Sun Aug 30 03:06:32.982986 2026] [security2:error] [pid 496962:tid 497169] [client 20.104.50.220:51558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/~.php"] [unique_id "apPkiI6aRhSu8gis9LmZ8gAABPo"]
[Sun Aug 30 03:06:32.989918 2026] [security2:error] [pid 496962:tid 497192] [client 20.104.50.220:61990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/sel.php"] [unique_id "apPkiI6aRhSu8gis9LmZ-AAABRE"]
[Sun Aug 30 03:06:32.997068 2026] [security2:error] [pid 496962:tid 497208] [client 20.104.18.15:28560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/admin.php"] [unique_id "apPkiI6aRhSu8gis9LmZ-gAABSE"]
[Sun Aug 30 03:06:33.014681 2026] [security2:error] [pid 496962:tid 497111] [client 4.205.62.107:52103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/nw.php"] [unique_id "apPkiY6aRhSu8gis9LmaBQAABMA"]
[Sun Aug 30 03:06:33.022216 2026] [security2:error] [pid 496962:tid 497117] [client 20.104.50.220:29168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/manda.php"] [unique_id "apPkiY6aRhSu8gis9LmaBwAABMY"]
[Sun Aug 30 03:06:33.026618 2026] [security2:error] [pid 496962:tid 497212] [client 20.104.104.62:48467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/file66.php"] [unique_id "apPkiY6aRhSu8gis9LmaCgAABSU"]
[Sun Aug 30 03:06:33.059218 2026] [security2:error] [pid 496962:tid 497211] [client 20.220.10.235:39845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/wk/index.php"] [unique_id "apPkiY6aRhSu8gis9LmaFwAABSQ"]
[Sun Aug 30 03:06:33.081065 2026] [security2:error] [pid 496962:tid 497191] [client 20.48.251.3:44397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/8.php"] [unique_id "apPkiY6aRhSu8gis9LmaIAAABRA"]
[Sun Aug 30 03:06:33.086231 2026] [security2:error] [pid 496962:tid 497114] [client 198.37.118.2:50605] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "geotravel.am"] [uri "/wp-comments-post.php"] [unique_id "apPkiY6aRhSu8gis9LmaAQAABMM"], referer: https://geotravel.am/discover-armenias-hidden-gems-tufenkian-avan-marak-tsapatagh-hotel/
[Sun Aug 30 03:06:33.102190 2026] [authz_core:error] [pid 496962:tid 497193] [client 74.7.227.8:56966] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule
[Sun Aug 30 03:06:33.102486 2026] [authz_core:error] [pid 496962:tid 497193] [client 74.7.227.8:56966] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule
[Sun Aug 30 03:06:33.119745 2026] [authz_core:error] [pid 496962:tid 497133] [client 216.73.216.128:5523] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:33.120017 2026] [authz_core:error] [pid 496962:tid 497133] [client 216.73.216.128:5523] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:33.160000 2026] [security2:error] [pid 496962:tid 497183] [client 20.104.104.62:48590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/blnux.php"] [unique_id "apPkiY6aRhSu8gis9LmaQQAABQg"]
[Sun Aug 30 03:06:33.172172 2026] [security2:error] [pid 496962:tid 497104] [client 20.104.50.220:5929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/xb.php"] [unique_id "apPkiY6aRhSu8gis9LmaRQAABLk"]
[Sun Aug 30 03:06:33.192785 2026] [security2:error] [pid 496962:tid 497159] [client 20.220.10.235:39851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/dehnl.php"] [unique_id "apPkiY6aRhSu8gis9LmaUQAABPA"]
[Sun Aug 30 03:06:33.248685 2026] [security2:error] [pid 496962:tid 497118] [client 20.48.251.3:49999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/app_local.php"] [unique_id "apPkiY6aRhSu8gis9LmaYwAABMc"]
[Sun Aug 30 03:06:33.260296 2026] [security2:error] [pid 496962:tid 497109] [client 20.104.18.15:33705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/wp-content/l.php"] [unique_id "apPkiY6aRhSu8gis9LmaZQAABL4"]
[Sun Aug 30 03:06:33.281196 2026] [security2:error] [pid 496962:tid 497152] [client 68.155.159.216:56433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/content.php"] [unique_id "apPkiY6aRhSu8gis9LmaaAAABOk"]
[Sun Aug 30 03:06:33.289324 2026] [security2:error] [pid 496962:tid 497137] [client 20.104.104.62:48694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/attack.php"] [unique_id "apPkiY6aRhSu8gis9LmaaQAABNo"]
[Sun Aug 30 03:06:33.322028 2026] [security2:error] [pid 496962:tid 497103] [client 20.48.251.3:45856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/wdf.php"] [unique_id "apPkiY6aRhSu8gis9LmadQAABLg"]
[Sun Aug 30 03:06:33.324640 2026] [security2:error] [pid 496962:tid 497124] [client 20.220.10.235:39844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/png.php"] [unique_id "apPkiY6aRhSu8gis9LmadwAABM0"]
[Sun Aug 30 03:06:33.326851 2026] [security2:error] [pid 496962:tid 497156] [client 20.104.50.220:32567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/error.php"] [unique_id "apPkiY6aRhSu8gis9LmaeQAABO0"]
[Sun Aug 30 03:06:33.367798 2026] [authz_core:error] [pid 496962:tid 497146] [client 66.249.66.72:50902] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:33.368256 2026] [authz_core:error] [pid 496962:tid 497146] [client 66.249.66.72:50902] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:33.374388 2026] [security2:error] [pid 496962:tid 497171] [client 20.197.61.180:3280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/wp-cron.php"] [unique_id "apPkiY6aRhSu8gis9LmajgAABPw"]
[Sun Aug 30 03:06:33.377452 2026] [security2:error] [pid 496962:tid 497096] [client 4.205.62.107:58332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/zz.php"] [unique_id "apPkiY6aRhSu8gis9LmakAAABLE"]
[Sun Aug 30 03:06:33.418149 2026] [security2:error] [pid 496962:tid 497164] [client 20.104.104.62:48493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/wk/index.php"] [unique_id "apPkiY6aRhSu8gis9LmangAABPU"]
[Sun Aug 30 03:06:33.453464 2026] [security2:error] [pid 496962:tid 497205] [client 20.220.10.235:39857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/txets.php"] [unique_id "apPkiY6aRhSu8gis9LmaqQAABR4"]
[Sun Aug 30 03:06:33.453942 2026] [security2:error] [pid 496962:tid 497149] [client 4.205.62.107:2124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apPkiY6aRhSu8gis9LmaqwAABOY"]
[Sun Aug 30 03:06:33.458965 2026] [security2:error] [pid 496962:tid 497175] [client 20.104.49.130:64623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/kj.php"] [unique_id "apPkiY6aRhSu8gis9LmarAAABQA"]
[Sun Aug 30 03:06:33.481881 2026] [authz_core:error] [pid 496962:tid 497156] [client 66.249.66.67:62726] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:33.482157 2026] [authz_core:error] [pid 496962:tid 497156] [client 66.249.66.67:62726] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:33.484488 2026] [security2:error] [pid 496962:tid 497166] [client 20.48.251.3:56323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkiY6aRhSu8gis9LmauQAABPc"]
[Sun Aug 30 03:06:33.506817 2026] [security2:error] [pid 496962:tid 497093] [client 4.205.62.107:26553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/filesystems.php"] [unique_id "apPkiY6aRhSu8gis9LmayQAABK4"]
[Sun Aug 30 03:06:33.533274 2026] [security2:error] [pid 496962:tid 497163] [client 68.155.159.216:65495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apPkiY6aRhSu8gis9LmazgAABPQ"]
[Sun Aug 30 03:06:33.574965 2026] [security2:error] [pid 496962:tid 497205] [client 4.205.62.107:58113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/aws_settings.php"] [unique_id "apPkiY6aRhSu8gis9Lma5QAABR4"]
[Sun Aug 30 03:06:33.584972 2026] [authz_core:error] [pid 496962:tid 497094] [client 74.7.227.8:56966] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Flib
[Sun Aug 30 03:06:33.585356 2026] [authz_core:error] [pid 496962:tid 497094] [client 74.7.227.8:56966] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Flib
[Sun Aug 30 03:06:33.596627 2026] [security2:error] [pid 496962:tid 497170] [client 20.220.10.235:40781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/wp-login.php"] [unique_id "apPkiY6aRhSu8gis9Lma8wAABPs"]
[Sun Aug 30 03:06:33.633528 2026] [security2:error] [pid 496962:tid 497129] [client 20.104.104.62:48584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/dehnl.php"] [unique_id "apPkiY6aRhSu8gis9Lma_gAABNI"]
[Sun Aug 30 03:06:33.666838 2026] [security2:error] [pid 496962:tid 497152] [client 68.155.159.216:63534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/hehehehe.php"] [unique_id "apPkiY6aRhSu8gis9LmbDQAABOk"]
[Sun Aug 30 03:06:33.699587 2026] [security2:error] [pid 496962:tid 497149] [client 4.205.62.107:18648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/fucku.php"] [unique_id "apPkiY6aRhSu8gis9LmbEgAABOY"]
[Sun Aug 30 03:06:33.725410 2026] [security2:error] [pid 496962:tid 497103] [client 20.220.10.235:39860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/wp-access.php"] [unique_id "apPkiY6aRhSu8gis9LmbHwAABLg"]
[Sun Aug 30 03:06:33.726058 2026] [security2:error] [pid 496962:tid 497139] [client 20.48.251.3:7102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/rum.or.php"] [unique_id "apPkiY6aRhSu8gis9LmbIAAABNw"]
[Sun Aug 30 03:06:33.760168 2026] [authz_core:error] [pid 496962:tid 497180] [client 216.73.216.128:5523] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:33.760462 2026] [authz_core:error] [pid 496962:tid 497180] [client 216.73.216.128:5523] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:33.766091 2026] [security2:error] [pid 496962:tid 497178] [client 20.104.104.62:48661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/png.php"] [unique_id "apPkiY6aRhSu8gis9LmbLQAABQM"]
[Sun Aug 30 03:06:33.772638 2026] [security2:error] [pid 496962:tid 497175] [client 68.155.159.216:54037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apPkiY6aRhSu8gis9LmbMQAABQA"]
[Sun Aug 30 03:06:33.787335 2026] [security2:error] [pid 496962:tid 497123] [client 4.205.62.107:4113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/server_info.php"] [unique_id "apPkiY6aRhSu8gis9LmbOAAABMw"]
[Sun Aug 30 03:06:33.793521 2026] [security2:error] [pid 496962:tid 497132] [client 20.151.200.44:63296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/ft.php"] [unique_id "apPkiY6aRhSu8gis9LmbOwAABNU"]
[Sun Aug 30 03:06:33.793871 2026] [security2:error] [pid 496962:tid 497212] [client 4.205.62.107:62414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/temp.php"] [unique_id "apPkiY6aRhSu8gis9LmbPAAABSU"]
[Sun Aug 30 03:06:33.811015 2026] [security2:error] [pid 496962:tid 497142] [client 4.205.62.107:63976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/god.php"] [unique_id "apPkiY6aRhSu8gis9LmbQQAABN8"]
[Sun Aug 30 03:06:33.851971 2026] [authz_core:error] [pid 496962:tid 497119] [client 216.73.216.128:39775] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:33.852365 2026] [authz_core:error] [pid 496962:tid 497119] [client 216.73.216.128:39775] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:33.853628 2026] [security2:error] [pid 496962:tid 497159] [client 20.104.50.220:62833] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "www.prod.sapientbydesign.com"] [uri "/c99.php"] [unique_id "apPkiY6aRhSu8gis9LmbTwAABPA"]
[Sun Aug 30 03:06:33.855024 2026] [security2:error] [pid 496962:tid 497099] [client 20.220.10.235:40768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/wp-content/admin.php"] [unique_id "apPkiY6aRhSu8gis9LmbUQAABLQ"]
[Sun Aug 30 03:06:33.872406 2026] [security2:error] [pid 496962:tid 497170] [client 68.155.159.216:60911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/goods.php"] [unique_id "apPkiY6aRhSu8gis9LmbWgAABPs"]
[Sun Aug 30 03:06:33.909494 2026] [security2:error] [pid 496962:tid 497175] [client 20.104.104.62:48671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/txets.php"] [unique_id "apPkiY6aRhSu8gis9LmbagAABQA"]
[Sun Aug 30 03:06:33.928777 2026] [access_compat:error] [pid 496962:tid 496980] [remote 74.7.175.150:60668] AH01797: client denied by server configuration: /home1/joshuapz/public_html/allieandjosh.love/robots.txt
[Sun Aug 30 03:06:33.930144 2026] [security2:error] [pid 496962:tid 497138] [client 74.7.175.150:60668] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "403"] [hostname "allieandjosh.love"] [uri "/cgi-sys/403.html"] [unique_id "apPkiY6aRhSu8gis9LmbdAAE2xE"]
[Sun Aug 30 03:06:33.933068 2026] [security2:error] [pid 496962:tid 497171] [client 68.155.159.216:61328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/login.php"] [unique_id "apPkiY6aRhSu8gis9LmbeQAABPw"]
[Sun Aug 30 03:06:33.933470 2026] [security2:error] [pid 496962:tid 497216] [client 20.104.50.220:27425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/installer.php"] [unique_id "apPkiY6aRhSu8gis9LmbegAABSk"]
[Sun Aug 30 03:06:33.953273 2026] [security2:error] [pid 496962:tid 497208] [client 20.104.18.15:23517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkiY6aRhSu8gis9LmbgQAABSE"]
[Sun Aug 30 03:06:33.966166 2026] [security2:error] [pid 496962:tid 497164] [client 20.104.18.15:13632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/backup.php"] [unique_id "apPkiY6aRhSu8gis9LmbhAAABPU"]
[Sun Aug 30 03:06:33.990102 2026] [security2:error] [pid 496962:tid 497092] [client 20.220.10.235:39830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/log.php"] [unique_id "apPkiY6aRhSu8gis9LmbkAAABK0"]
[Sun Aug 30 03:06:34.002037 2026] [authz_core:error] [pid 496962:tid 497170] [client 66.249.66.196:44574] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:34.002433 2026] [security2:error] [pid 496962:tid 497168] [client 20.104.50.220:33044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/json.php"] [unique_id "apPkio6aRhSu8gis9LmbmAAABPk"]
[Sun Aug 30 03:06:34.002456 2026] [authz_core:error] [pid 496962:tid 497170] [client 66.249.66.196:44574] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:34.005833 2026] [security2:error] [pid 496962:tid 497194] [client 20.151.200.44:27141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/h02ugyh.php"] [unique_id "apPkio6aRhSu8gis9LmbmgAABRM"]
[Sun Aug 30 03:06:34.038919 2026] [security2:error] [pid 496962:tid 497214] [client 20.104.50.220:46416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/priv.php"] [unique_id "apPkio6aRhSu8gis9LmbogAABSc"]
[Sun Aug 30 03:06:34.042817 2026] [security2:error] [pid 496962:tid 497129] [client 20.151.200.44:65218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/wp-ver.php"] [unique_id "apPkio6aRhSu8gis9LmbpAAABNI"]
[Sun Aug 30 03:06:34.063823 2026] [authz_core:error] [pid 496962:tid 497134] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fopt%2Fcpanel%2Fea-php84%2Froot%2Fvar%2Flib%2Fpear%2Fpkgxml
[Sun Aug 30 03:06:34.064107 2026] [authz_core:error] [pid 496962:tid 497134] [client 74.7.243.204:35804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fopt%2Fcpanel%2Fea-php84%2Froot%2Fvar%2Flib%2Fpear%2Fpkgxml
[Sun Aug 30 03:06:34.101437 2026] [security2:error] [pid 496962:tid 497126] [client 20.104.104.62:48474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/wp-login.php"] [unique_id "apPkio6aRhSu8gis9LmbpwAABM8"]
[Sun Aug 30 03:06:34.101716 2026] [security2:error] [pid 496962:tid 497120] [client 20.104.18.15:43268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/gigi.php"] [unique_id "apPkio6aRhSu8gis9LmbvAAABMk"]
[Sun Aug 30 03:06:34.104082 2026] [security2:error] [pid 496962:tid 497139] [client 20.197.61.180:3282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/wp-links-opml.php"] [unique_id "apPkio6aRhSu8gis9LmbvgAABNw"]
[Sun Aug 30 03:06:34.118016 2026] [authz_core:error] [pid 496962:tid 497195] [client 66.249.66.44:55069] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:34.118293 2026] [authz_core:error] [pid 496962:tid 497195] [client 66.249.66.44:55069] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:34.119457 2026] [security2:error] [pid 496962:tid 497184] [client 20.220.10.235:40778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/xwpg.php"] [unique_id "apPkio6aRhSu8gis9LmbxQAABQk"]
[Sun Aug 30 03:06:34.130347 2026] [security2:error] [pid 496962:tid 497115] [client 20.104.18.15:28565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/admin.php"] [unique_id "apPkio6aRhSu8gis9LmbywAABMQ"]
[Sun Aug 30 03:06:34.135014 2026] [authz_core:error] [pid 496962:tid 497160] [client 74.7.227.8:56966] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fopt%2Fbart
[Sun Aug 30 03:06:34.135294 2026] [authz_core:error] [pid 496962:tid 497160] [client 74.7.227.8:56966] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fopt%2Fbart
[Sun Aug 30 03:06:34.159895 2026] [security2:error] [pid 496962:tid 497137] [client 4.205.62.107:56899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/product.php"] [unique_id "apPkio6aRhSu8gis9Lmb1QAABNo"]
[Sun Aug 30 03:06:34.167297 2026] [security2:error] [pid 496962:tid 497117] [client 20.104.50.220:29158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/pmemek.php"] [unique_id "apPkio6aRhSu8gis9Lmb2QAABMY"]
[Sun Aug 30 03:06:34.169550 2026] [security2:error] [pid 496962:tid 497191] [client 20.104.50.220:51621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/lock360.php"] [unique_id "apPkio6aRhSu8gis9Lmb3AAABRA"]
[Sun Aug 30 03:06:34.224235 2026] [security2:error] [pid 496962:tid 497150] [client 20.48.251.3:44309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/thui.php"] [unique_id "apPkio6aRhSu8gis9Lmb8wAABOc"]
[Sun Aug 30 03:06:34.233257 2026] [security2:error] [pid 496962:tid 497132] [client 20.104.104.62:48585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/wp-access.php"] [unique_id "apPkio6aRhSu8gis9Lmb9gAABNU"]
[Sun Aug 30 03:06:34.255027 2026] [security2:error] [pid 496962:tid 497180] [client 45.3.55.204:46801] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "belloinsights.com"] [uri "/"] [unique_id "apPkio6aRhSu8gis9Lmb_gAABQU"]
[Sun Aug 30 03:06:34.258651 2026] [security2:error] [pid 496962:tid 497163] [client 20.220.10.235:39854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/sxxb.php"] [unique_id "apPkio6aRhSu8gis9Lmb_wAABPQ"]
[Sun Aug 30 03:06:34.321890 2026] [security2:error] [pid 496962:tid 497124] [client 20.104.50.220:61659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/14.php"] [unique_id "apPkio6aRhSu8gis9LmcDQAABM0"]
[Sun Aug 30 03:06:34.324654 2026] [security2:error] [pid 496962:tid 497117] [client 20.104.50.220:5548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/ova.php"] [unique_id "apPkio6aRhSu8gis9LmcDgAABMY"]
[Sun Aug 30 03:06:34.375075 2026] [security2:error] [pid 496962:tid 497157] [client 20.104.104.62:48464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/wp-content/admin.php"] [unique_id "apPkio6aRhSu8gis9LmcIgAABO4"]
[Sun Aug 30 03:06:34.995751 2026] [http2:info] [pid 499145:tid 499145] h2_workers: created with min=128 max=192 idle_ms=600000
[Sun Aug 30 03:06:35.022096 2026] [security2:error] [pid 499145:tid 499310] [client 68.155.159.216:65497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-content/admin.php"] [unique_id "apPki1JNq1G5uRhTNnskFAAAACM"]
[Sun Aug 30 03:06:35.022099 2026] [security2:error] [pid 499145:tid 499309] [client 20.48.251.3:33312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPki1JNq1G5uRhTNnskEgAAACI"]
[Sun Aug 30 03:06:35.022133 2026] [security2:error] [pid 499145:tid 499282] [client 20.104.104.62:48458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/log.php"] [unique_id "apPki1JNq1G5uRhTNnskBAAAAAc"]
[Sun Aug 30 03:06:35.022195 2026] [security2:error] [pid 499145:tid 499293] [client 4.205.62.107:58304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/umgebung.php"] [unique_id "apPki1JNq1G5uRhTNnskCAAAABI"]
[Sun Aug 30 03:06:35.022266 2026] [security2:error] [pid 499145:tid 499292] [client 4.205.62.107:2341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/hochladen.form.php"] [unique_id "apPki1JNq1G5uRhTNnskBwAAABE"]
[Sun Aug 30 03:06:35.022280 2026] [security2:error] [pid 499145:tid 499303] [client 4.205.62.107:22915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/fm.php"] [unique_id "apPki1JNq1G5uRhTNnskDwAAABw"]
[Sun Aug 30 03:06:35.022377 2026] [security2:error] [pid 499145:tid 499281] [client 20.220.10.235:39829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/dx.php"] [unique_id "apPki1JNq1G5uRhTNnskAwAAAAY"]
[Sun Aug 30 03:06:35.022491 2026] [security2:error] [pid 499145:tid 499295] [client 20.48.251.3:12061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/ws62.php"] [unique_id "apPki1JNq1G5uRhTNnskCgAAABQ"]
[Sun Aug 30 03:06:35.022532 2026] [security2:error] [pid 499145:tid 499305] [client 20.104.50.220:16725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPki1JNq1G5uRhTNnskEAAAAB4"]
[Sun Aug 30 03:06:35.022550 2026] [security2:error] [pid 499145:tid 499304] [client 20.48.251.3:6990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/bb.php"] [unique_id "apPki1JNq1G5uRhTNnskEQAAAB0"]
[Sun Aug 30 03:06:35.022677 2026] [security2:error] [pid 499145:tid 499280] [client 68.155.159.216:62295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-includes/fonts/about.php"] [unique_id "apPki1JNq1G5uRhTNnskAgAAAAU"]
[Sun Aug 30 03:06:35.022696 2026] [security2:error] [pid 499145:tid 499277] [client 4.205.62.107:32483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/test.php"] [unique_id "apPki1JNq1G5uRhTNnskAAAAAAI"]
[Sun Aug 30 03:06:35.022739 2026] [security2:error] [pid 499145:tid 499296] [client 20.104.18.15:33748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/wp-admin/w.php"] [unique_id "apPki1JNq1G5uRhTNnskCwAAABU"]
[Sun Aug 30 03:06:35.022792 2026] [security2:error] [pid 499145:tid 499301] [client 20.151.200.44:64612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/ah24.php"] [unique_id "apPki1JNq1G5uRhTNnskDQAAABo"]
[Sun Aug 30 03:06:35.022830 2026] [security2:error] [pid 499145:tid 499285] [client 68.155.159.216:56421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPki1JNq1G5uRhTNnskBQAAAAo"]
[Sun Aug 30 03:06:35.022866 2026] [security2:error] [pid 499145:tid 499294] [client 4.205.62.107:58125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/wp-konfig.backup.php"] [unique_id "apPki1JNq1G5uRhTNnskCQAAABM"]
[Sun Aug 30 03:06:35.022873 2026] [security2:error] [pid 499145:tid 499279] [client 4.205.62.107:62109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/fff.php"] [unique_id "apPki1JNq1G5uRhTNnskAQAAAAQ"]
[Sun Aug 30 03:06:35.023281 2026] [security2:error] [pid 499145:tid 499276] [client 20.104.50.220:32276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/evil.php"] [unique_id "apPki1JNq1G5uRhTNnsj_gAAAAE"]
[Sun Aug 30 03:06:35.023550 2026] [security2:error] [pid 499145:tid 499313] [client 68.155.159.216:54113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/packed.php"] [unique_id "apPki1JNq1G5uRhTNnskGgAAACY"]
[Sun Aug 30 03:06:35.023804 2026] [security2:error] [pid 499145:tid 499315] [client 4.205.62.107:17797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/error_log.php"] [unique_id "apPki1JNq1G5uRhTNnskGwAAACg"]
[Sun Aug 30 03:06:35.024019 2026] [security2:error] [pid 499145:tid 499279] [client 4.205.62.107:4559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/hosty.php"] [unique_id "apPki1JNq1G5uRhTNnskHQAAAAQ"]
[Sun Aug 30 03:06:35.024609 2026] [security2:error] [pid 499145:tid 499318] [client 20.104.50.220:29571] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "www.prod.sapientbydesign.com"] [uri "/c99.php"] [unique_id "apPki1JNq1G5uRhTNnskHwAAACs"]
[Sun Aug 30 03:06:35.025063 2026] [security2:error] [pid 499145:tid 499323] [client 20.104.49.130:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/fling.php"] [unique_id "apPki1JNq1G5uRhTNnskIAAAADA"]
[Sun Aug 30 03:06:35.029675 2026] [authz_core:error] [pid 499145:tid 499291] [client 66.249.66.70:43098] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:35.029985 2026] [authz_core:error] [pid 499145:tid 499291] [client 66.249.66.70:43098] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:35.031737 2026] [authz_core:error] [pid 499145:tid 499300] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fmemory_hotplug
[Sun Aug 30 03:06:35.032114 2026] [authz_core:error] [pid 499145:tid 499300] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fmemory_hotplug
[Sun Aug 30 03:06:35.033900 2026] [authz_core:error] [pid 499145:tid 499326] [client 216.73.216.128:28014] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:35.034257 2026] [authz_core:error] [pid 499145:tid 499326] [client 216.73.216.128:28014] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:35.067255 2026] [security2:error] [pid 499145:tid 499336] [client 20.104.50.220:27080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/web/index.php"] [unique_id "apPki1JNq1G5uRhTNnskKwAAAD0"]
[Sun Aug 30 03:06:35.077108 2026] [authz_core:error] [pid 499145:tid 499284] [client 66.249.66.197:44094] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:35.077551 2026] [authz_core:error] [pid 499145:tid 499284] [client 66.249.66.197:44094] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:35.079735 2026] [security2:error] [pid 499145:tid 499340] [client 68.155.159.216:62076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apPki1JNq1G5uRhTNnskLgAAAEE"]
[Sun Aug 30 03:06:35.103032 2026] [security2:error] [pid 499145:tid 499362] [client 68.155.159.216:65423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/hehehehe.php"] [unique_id "apPki1JNq1G5uRhTNnskMAAAAFc"]
[Sun Aug 30 03:06:35.109501 2026] [security2:error] [pid 499145:tid 499363] [client 20.151.200.44:27314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/sf.php"] [unique_id "apPki1JNq1G5uRhTNnskMQAAAFg"]
[Sun Aug 30 03:06:35.116906 2026] [security2:error] [pid 499145:tid 499366] [client 20.104.18.15:13661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/indo.php"] [unique_id "apPki1JNq1G5uRhTNnskMwAAAFs"]
[Sun Aug 30 03:06:35.139235 2026] [security2:error] [pid 499145:tid 499373] [client 20.151.200.44:37776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/admin.php/700.php"] [unique_id "apPki1JNq1G5uRhTNnskNgAAAGI"]
[Sun Aug 30 03:06:35.153771 2026] [security2:error] [pid 499145:tid 499376] [client 20.104.18.15:23430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPki1JNq1G5uRhTNnskOAAAAGU"]
[Sun Aug 30 03:06:35.157859 2026] [security2:error] [pid 499145:tid 499377] [client 20.104.50.220:32891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/java.php"] [unique_id "apPki1JNq1G5uRhTNnskOQAAAGY"]
[Sun Aug 30 03:06:35.161661 2026] [security2:error] [pid 499145:tid 499378] [client 20.220.10.235:39848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPki1JNq1G5uRhTNnskOgAAAGc"]
[Sun Aug 30 03:06:35.178168 2026] [security2:error] [pid 499145:tid 499382] [client 20.104.50.220:46618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/priv8.php"] [unique_id "apPki1JNq1G5uRhTNnskPgAAAGs"]
[Sun Aug 30 03:06:35.186043 2026] [security2:error] [pid 499145:tid 499383] [client 20.104.104.62:48704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/xwpg.php"] [unique_id "apPki1JNq1G5uRhTNnskPwAAAGw"]
[Sun Aug 30 03:06:35.219869 2026] [security2:error] [pid 499145:tid 499390] [client 4.205.62.107:26499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/tax.php"] [unique_id "apPki1JNq1G5uRhTNnskQwAAAHM"]
[Sun Aug 30 03:06:35.221014 2026] [authz_core:error] [pid 499145:tid 499387] [client 216.73.216.128:28014] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:35.221512 2026] [authz_core:error] [pid 499145:tid 499387] [client 216.73.216.128:28014] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:35.250900 2026] [security2:error] [pid 499145:tid 499399] [client 20.104.18.15:43319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/info.php/new.php"] [unique_id "apPki1JNq1G5uRhTNnskRAAAAHw"]
[Sun Aug 30 03:06:35.251953 2026] [security2:error] [pid 499145:tid 499400] [client 20.151.200.44:64622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/wp-admin/zwso.php"] [unique_id "apPki1JNq1G5uRhTNnskRQAAAH0"]
[Sun Aug 30 03:06:35.261986 2026] [security2:error] [pid 499145:tid 499402] [client 20.104.18.15:28487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/themes.php"] [unique_id "apPki1JNq1G5uRhTNnskRgAAAH8"]
[Sun Aug 30 03:06:35.262718 2026] [security2:error] [pid 499145:tid 499286] [client 20.197.61.180:14071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/wp-load.php"] [unique_id "apPki1JNq1G5uRhTNnskRwAAAAs"]
[Sun Aug 30 03:06:35.289401 2026] [security2:error] [pid 499145:tid 499282] [client 20.220.10.235:40786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/xda.php"] [unique_id "apPki1JNq1G5uRhTNnskTAAAAAc"]
[Sun Aug 30 03:06:35.291902 2026] [security2:error] [pid 499145:tid 499293] [client 4.205.62.107:51769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/fun.php"] [unique_id "apPki1JNq1G5uRhTNnskTQAAABI"]
[Sun Aug 30 03:06:35.302532 2026] [authz_core:error] [pid 499145:tid 499281] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fmemory_hotplug
[Sun Aug 30 03:06:35.302836 2026] [authz_core:error] [pid 499145:tid 499281] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fmemory_hotplug
[Sun Aug 30 03:06:35.311691 2026] [authz_core:error] [pid 499145:tid 499305] [client 216.73.216.128:33592] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:35.312036 2026] [authz_core:error] [pid 499145:tid 499305] [client 216.73.216.128:33592] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:35.316255 2026] [security2:error] [pid 499145:tid 499296] [client 20.104.104.62:48697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/sxxb.php"] [unique_id "apPki1JNq1G5uRhTNnskUgAAABU"]
[Sun Aug 30 03:06:35.335839 2026] [security2:error] [pid 499145:tid 499322] [client 20.104.50.220:42006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/licensi.php"] [unique_id "apPki1JNq1G5uRhTNnskUwAAAC8"]
[Sun Aug 30 03:06:35.336545 2026] [security2:error] [pid 499145:tid 499276] [client 20.104.50.220:29172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/mmk.php"] [unique_id "apPki1JNq1G5uRhTNnskVAAAAAE"]
[Sun Aug 30 03:06:35.380325 2026] [security2:error] [pid 499145:tid 499328] [client 20.48.251.3:4672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/file21.php"] [unique_id "apPki1JNq1G5uRhTNnskWQAAADU"]
[Sun Aug 30 03:06:35.419040 2026] [security2:error] [pid 499145:tid 499334] [client 20.220.10.235:40812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPki1JNq1G5uRhTNnskXQAAADs"]
[Sun Aug 30 03:06:35.454302 2026] [security2:error] [pid 499145:tid 499340] [client 20.104.104.62:48662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/dx.php"] [unique_id "apPki1JNq1G5uRhTNnskXwAAAEE"]
[Sun Aug 30 03:06:35.464274 2026] [security2:error] [pid 499145:tid 499344] [client 20.104.50.220:5602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/vx.php"] [unique_id "apPki1JNq1G5uRhTNnskYAAAAEU"]
[Sun Aug 30 03:06:35.482786 2026] [security2:error] [pid 499145:tid 499347] [client 20.151.200.44:64700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bell.wirelessland.ca"] [uri "/waf.php"] [unique_id "apPki1JNq1G5uRhTNnskYQAAAEg"]
[Sun Aug 30 03:06:35.484275 2026] [security2:error] [pid 499145:tid 499349] [client 20.104.50.220:61956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/about.php"] [unique_id "apPki1JNq1G5uRhTNnskYwAAAEo"]
[Sun Aug 30 03:06:35.518502 2026] [authz_core:error] [pid 499145:tid 499342] [client 66.249.66.75:56071] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:35.518989 2026] [authz_core:error] [pid 499145:tid 499342] [client 66.249.66.75:56071] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:35.552226 2026] [security2:error] [pid 499145:tid 499280] [client 45.3.55.204:32171] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "belloinsights.com"] [uri "/"] [unique_id "apPki1JNq1G5uRhTNnskaQAAAAU"]
[Sun Aug 30 03:06:35.557368 2026] [security2:error] [pid 499145:tid 499298] [client 20.220.10.235:39866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/t00l.php"] [unique_id "apPki1JNq1G5uRhTNnskagAAABc"]
[Sun Aug 30 03:06:35.578003 2026] [authz_core:error] [pid 499145:tid 499364] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:06:35.578414 2026] [authz_core:error] [pid 499145:tid 499364] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:06:35.583680 2026] [authz_core:error] [pid 499145:tid 499366] [client 216.73.216.128:50607] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:35.584104 2026] [authz_core:error] [pid 499145:tid 499366] [client 216.73.216.128:50607] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:35.606366 2026] [authz_core:error] [pid 499145:tid 499367] [client 66.249.66.196:46489] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:35.606835 2026] [authz_core:error] [pid 499145:tid 499367] [client 66.249.66.196:46489] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:35.616993 2026] [security2:error] [pid 499145:tid 499372] [client 20.104.104.62:48576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPki1JNq1G5uRhTNnskbwAAAGE"]
[Sun Aug 30 03:06:35.678660 2026] [authz_core:error] [pid 499145:tid 499301] [client 216.73.216.128:33592] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:35.679131 2026] [authz_core:error] [pid 499145:tid 499301] [client 216.73.216.128:33592] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:35.692036 2026] [security2:error] [pid 499145:tid 499378] [client 20.220.10.235:40812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/ls.php"] [unique_id "apPki1JNq1G5uRhTNnskdAAAAGc"]
[Sun Aug 30 03:06:35.777371 2026] [authz_core:error] [pid 499145:tid 499386] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fvar%2Flog
[Sun Aug 30 03:06:35.777664 2026] [authz_core:error] [pid 499145:tid 499386] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fvar%2Flog
[Sun Aug 30 03:06:35.787715 2026] [security2:error] [pid 499145:tid 499325] [client 20.104.104.62:48489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/xda.php"] [unique_id "apPki1JNq1G5uRhTNnskeQAAADI"]
[Sun Aug 30 03:06:35.798361 2026] [security2:error] [pid 499145:tid 499369] [client 114.119.159.237:54347] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "onesprayaway.com"] [uri "/how-ai3-works-natural-fast-acting-roll-on-relief-for-joint-muscle-pain/"] [unique_id "apPki1JNq1G5uRhTNnskewAAAF4"], referer: https://onesprayaway.com/how-ai3-works-natural-fast-acting-roll-on-relief-for-joint-muscle-pain/
[Sun Aug 30 03:06:35.826506 2026] [authz_core:error] [pid 499145:tid 499312] [client 66.249.66.40:38688] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:35.826790 2026] [authz_core:error] [pid 499145:tid 499312] [client 66.249.66.40:38688] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:35.846004 2026] [security2:error] [pid 499145:tid 499324] [client 20.220.10.235:39856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/css/000.php"] [unique_id "apPki1JNq1G5uRhTNnskfgAAADE"]
[Sun Aug 30 03:06:35.921935 2026] [security2:error] [pid 499145:tid 499396] [client 20.104.104.62:48659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPki1JNq1G5uRhTNnskggAAAHk"]
[Sun Aug 30 03:06:35.930841 2026] [security2:error] [pid 496962:tid 497114] [client 198.37.118.2:50605] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "geotravel.am"] [uri "/wp-comments-post.php"] [unique_id "apPkiY6aRhSu8gis9LmaAQAABMM"], referer: https://geotravel.am/discover-armenias-hidden-gems-tufenkian-avan-marak-tsapatagh-hotel/
[Sun Aug 30 03:06:35.959518 2026] [security2:error] [pid 499145:tid 499385] [client 20.197.61.180:14044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/wp-settings.php"] [unique_id "apPki1JNq1G5uRhTNnskhAAAAG4"]
[Sun Aug 30 03:06:35.975287 2026] [authz_core:error] [pid 499145:tid 499399] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:06:35.975637 2026] [authz_core:error] [pid 499145:tid 499399] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:06:35.976994 2026] [security2:error] [pid 499145:tid 499400] [client 20.220.10.235:39864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/cy.php"] [unique_id "apPki1JNq1G5uRhTNnskhwAAAH0"]
[Sun Aug 30 03:06:36.031071 2026] [security2:error] [pid 499145:tid 499310] [client 20.104.49.130:63569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/txets.php"] [unique_id "apPkjFJNq1G5uRhTNnskiwAAACM"]
[Sun Aug 30 03:06:36.053592 2026] [security2:error] [pid 499145:tid 499303] [client 20.104.49.130:60626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/samll.php"] [unique_id "apPkjFJNq1G5uRhTNnskjQAAABw"]
[Sun Aug 30 03:06:36.063873 2026] [security2:error] [pid 499145:tid 499314] [client 20.104.104.62:48591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/t00l.php"] [unique_id "apPkjFJNq1G5uRhTNnskkAAAACc"]
[Sun Aug 30 03:06:36.124113 2026] [security2:error] [pid 499145:tid 499323] [client 20.220.10.235:40742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/admin.php/pindex.php"] [unique_id "apPkjFJNq1G5uRhTNnsklQAAADA"]
[Sun Aug 30 03:06:36.132871 2026] [authz_core:error] [pid 499145:tid 499279] [client 216.73.216.128:39914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:36.133294 2026] [authz_core:error] [pid 499145:tid 499279] [client 216.73.216.128:39914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:36.140912 2026] [security2:error] [pid 499145:tid 499284] [client 68.155.159.216:65499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/xmlrpc.php"] [unique_id "apPkjFJNq1G5uRhTNnsklgAAAAk"]
[Sun Aug 30 03:06:36.150362 2026] [security2:error] [pid 499145:tid 499285] [client 68.155.159.216:56333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/goat.php"] [unique_id "apPkjFJNq1G5uRhTNnsklwAAAAo"]
[Sun Aug 30 03:06:36.154856 2026] [security2:error] [pid 499145:tid 499327] [client 20.48.251.3:6491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/file59.php"] [unique_id "apPkjFJNq1G5uRhTNnskmAAAADQ"]
[Sun Aug 30 03:06:36.157318 2026] [security2:error] [pid 499145:tid 499335] [client 20.48.251.3:33280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/cloud.php"] [unique_id "apPkjFJNq1G5uRhTNnskmQAAADw"]
[Sun Aug 30 03:06:36.158473 2026] [security2:error] [pid 499145:tid 499306] [client 4.205.62.107:63988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/autogooey.php"] [unique_id "apPkjFJNq1G5uRhTNnskmgAAAB8"]
[Sun Aug 30 03:06:36.158500 2026] [security2:error] [pid 499145:tid 499333] [client 20.104.50.220:16739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkjFJNq1G5uRhTNnskmwAAADo"]
[Sun Aug 30 03:06:36.158793 2026] [security2:error] [pid 499145:tid 499283] [client 4.205.62.107:5085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/pass4.php"] [unique_id "apPkjFJNq1G5uRhTNnsknAAAAAg"]
[Sun Aug 30 03:06:36.158864 2026] [security2:error] [pid 499145:tid 499299] [client 4.205.62.107:18752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/phina.php"] [unique_id "apPkjFJNq1G5uRhTNnsknQAAABg"]
[Sun Aug 30 03:06:36.160504 2026] [security2:error] [pid 499145:tid 499328] [client 20.104.50.220:32306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/file.php"] [unique_id "apPkjFJNq1G5uRhTNnskngAAADU"]
[Sun Aug 30 03:06:36.163045 2026] [security2:error] [pid 499145:tid 499297] [client 4.205.62.107:65368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/packed.php"] [unique_id "apPkjFJNq1G5uRhTNnsknwAAABY"]
[Sun Aug 30 03:06:36.165202 2026] [security2:error] [pid 499145:tid 499332] [client 20.48.251.3:55468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/grsiuk.php"] [unique_id "apPkjFJNq1G5uRhTNnskoAAAADk"]
[Sun Aug 30 03:06:36.175259 2026] [security2:error] [pid 499145:tid 499290] [client 68.155.159.216:62324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-content/admin.php"] [unique_id "apPkjFJNq1G5uRhTNnskoQAAAA8"]
[Sun Aug 30 03:06:36.177040 2026] [security2:error] [pid 499145:tid 499334] [client 20.104.18.15:33761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/wp-content/k.php"] [unique_id "apPkjFJNq1G5uRhTNnskogAAADs"]
[Sun Aug 30 03:06:36.185561 2026] [security2:error] [pid 499145:tid 499337] [client 20.151.200.44:24593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/admin.php/007x.php"] [unique_id "apPkjFJNq1G5uRhTNnskowAAAD4"]
[Sun Aug 30 03:06:36.189199 2026] [security2:error] [pid 499145:tid 499339] [client 4.205.62.107:2798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/debuggen.php"] [unique_id "apPkjFJNq1G5uRhTNnskpAAAAEA"]
[Sun Aug 30 03:06:36.191905 2026] [security2:error] [pid 499145:tid 499340] [client 20.104.50.220:64449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/xxx.php"] [unique_id "apPkjFJNq1G5uRhTNnskpQAAAEE"]
[Sun Aug 30 03:06:36.195630 2026] [security2:error] [pid 499145:tid 499344] [client 4.205.62.107:54425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/tinyfilemanager.php"] [unique_id "apPkjFJNq1G5uRhTNnskpgAAAEU"]
[Sun Aug 30 03:06:36.200784 2026] [security2:error] [pid 499145:tid 499347] [client 20.104.104.62:48657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/ls.php"] [unique_id "apPkjFJNq1G5uRhTNnskpwAAAEg"]
[Sun Aug 30 03:06:36.204268 2026] [security2:error] [pid 499145:tid 499349] [client 20.104.50.220:27407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/unzip.php"] [unique_id "apPkjFJNq1G5uRhTNnskqAAAAEo"]
[Sun Aug 30 03:06:36.225482 2026] [security2:error] [pid 499145:tid 499358] [client 68.155.159.216:61331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apPkjFJNq1G5uRhTNnskrAAAAFM"]
[Sun Aug 30 03:06:36.239005 2026] [security2:error] [pid 499145:tid 499365] [client 4.205.62.107:58356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/old_phpinfo.php"] [unique_id "apPkjFJNq1G5uRhTNnskrQAAAFo"]
[Sun Aug 30 03:06:36.254008 2026] [security2:error] [pid 499145:tid 499305] [client 20.220.10.235:39839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/admin.php/csv.php"] [unique_id "apPkjFJNq1G5uRhTNnskrgAAAB4"]
[Sun Aug 30 03:06:36.259531 2026] [security2:error] [pid 499145:tid 499374] [client 68.155.159.216:62050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apPkjFJNq1G5uRhTNnskrwAAAGM"]
[Sun Aug 30 03:06:36.261247 2026] [security2:error] [pid 499145:tid 499373] [client 20.104.18.15:13701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/sign.php"] [unique_id "apPkjFJNq1G5uRhTNnsksAAAAGI"]
[Sun Aug 30 03:06:36.283586 2026] [authz_core:error] [pid 499145:tid 499350] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare
[Sun Aug 30 03:06:36.284065 2026] [authz_core:error] [pid 499145:tid 499350] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare
[Sun Aug 30 03:06:36.296763 2026] [security2:error] [pid 499145:tid 499389] [client 20.104.50.220:33070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/kntl.php"] [unique_id "apPkjFJNq1G5uRhTNnsktwAAAHI"]
[Sun Aug 30 03:06:36.316326 2026] [security2:error] [pid 499145:tid 499300] [client 20.104.50.220:46599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/qindex.php"] [unique_id "apPkjFJNq1G5uRhTNnskuQAAABk"]
[Sun Aug 30 03:06:36.350009 2026] [security2:error] [pid 499145:tid 499320] [client 20.104.104.62:48469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/css/000.php"] [unique_id "apPkjFJNq1G5uRhTNnskuwAAAC0"]
[Sun Aug 30 03:06:36.353995 2026] [security2:error] [pid 499145:tid 499371] [client 68.155.159.216:54100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-content/packed.php"] [unique_id "apPkjFJNq1G5uRhTNnskvAAAAGA"]
[Sun Aug 30 03:06:36.366879 2026] [security2:error] [pid 499145:tid 499360] [client 20.104.18.15:23424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/ap.php"] [unique_id "apPkjFJNq1G5uRhTNnskvQAAAFU"]
[Sun Aug 30 03:06:36.391094 2026] [security2:error] [pid 499145:tid 499396] [client 20.220.10.235:39825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/admin.php/700.php"] [unique_id "apPkjFJNq1G5uRhTNnskvwAAAHk"]
[Sun Aug 30 03:06:36.405893 2026] [security2:error] [pid 499145:tid 499385] [client 164.92.244.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.244.92.164.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.heavyvehicles.com.au"] [uri "/info.php"] [unique_id "apPkjFJNq1G5uRhTNnskwAAAAG4"]
[Sun Aug 30 03:06:36.407967 2026] [security2:error] [pid 499145:tid 499286] [client 20.104.18.15:28563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/biufile.php"] [unique_id "apPkjFJNq1G5uRhTNnskxgAAAAs"]
[Sun Aug 30 03:06:36.431737 2026] [security2:error] [pid 499145:tid 499280] [client 4.205.62.107:56632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/kedi.php"] [unique_id "apPkjFJNq1G5uRhTNnskyAAAAAU"]
[Sun Aug 30 03:06:36.486370 2026] [security2:error] [pid 499145:tid 499314] [client 4.205.62.107:32007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/wp-act.php"] [unique_id "apPkjFJNq1G5uRhTNnskygAAACc"]
[Sun Aug 30 03:06:36.494074 2026] [security2:error] [pid 499145:tid 499392] [client 20.104.50.220:51572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/Marvins.php"] [unique_id "apPkjFJNq1G5uRhTNnskzQAAAHU"]
[Sun Aug 30 03:06:36.499842 2026] [authz_core:error] [pid 499145:tid 499367] [client 216.73.216.128:50607] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:36.500310 2026] [authz_core:error] [pid 499145:tid 499367] [client 216.73.216.128:50607] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:36.501066 2026] [authz_core:error] [pid 499145:tid 499331] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fperl-Compress-Raw-Zlib
[Sun Aug 30 03:06:36.501492 2026] [authz_core:error] [pid 499145:tid 499331] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fperl-Compress-Raw-Zlib
[Sun Aug 30 03:06:36.517046 2026] [security2:error] [pid 499145:tid 499282] [client 20.48.251.3:44351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/mcebraed.php"] [unique_id "apPkjFJNq1G5uRhTNnskzgAAAAc"]
[Sun Aug 30 03:06:36.530746 2026] [security2:error] [pid 499145:tid 499315] [client 20.220.10.235:40780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/admin.php/007x.php"] [unique_id "apPkjFJNq1G5uRhTNnskzwAAACg"]
[Sun Aug 30 03:06:36.531839 2026] [security2:error] [pid 499145:tid 499323] [client 20.104.104.62:48610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/cy.php"] [unique_id "apPkjFJNq1G5uRhTNnsk0AAAADA"]
[Sun Aug 30 03:06:36.535166 2026] [security2:error] [pid 499145:tid 499318] [client 20.104.50.220:29152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/EvilTwin.php"] [unique_id "apPkjFJNq1G5uRhTNnsk0QAAACs"]
[Sun Aug 30 03:06:36.601117 2026] [security2:error] [pid 499145:tid 499297] [client 20.104.50.220:6089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/rh.php"] [unique_id "apPkjFJNq1G5uRhTNnsk1AAAABY"]
[Sun Aug 30 03:06:36.623309 2026] [security2:error] [pid 499145:tid 499277] [client 45.3.55.204:38397] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "belloinsights.com"] [uri "/"] [unique_id "apPkjFJNq1G5uRhTNnsk1QAAAAI"]
[Sun Aug 30 03:06:36.679571 2026] [security2:error] [pid 499145:tid 499380] [client 4.205.62.107:27310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPkjFJNq1G5uRhTNnsk2wAAAGk"]
[Sun Aug 30 03:06:36.679602 2026] [security2:error] [pid 499145:tid 499317] [client 20.197.61.180:14060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/themes/wp-signup.php"] [unique_id "apPkjFJNq1G5uRhTNnsk2gAAACo"]
[Sun Aug 30 03:06:36.680714 2026] [security2:error] [pid 499145:tid 499344] [client 20.104.104.62:48682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/admin.php/pindex.php"] [unique_id "apPkjFJNq1G5uRhTNnsk3AAAAEU"]
[Sun Aug 30 03:06:36.696117 2026] [security2:error] [pid 499145:tid 499349] [client 20.104.50.220:61963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/angel.php"] [unique_id "apPkjFJNq1G5uRhTNnsk3gAAAEo"]
[Sun Aug 30 03:06:36.696962 2026] [security2:error] [pid 499145:tid 499354] [client 20.220.10.235:39824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/admin.php/heex.php"] [unique_id "apPkjFJNq1G5uRhTNnsk3wAAAE8"]
[Sun Aug 30 03:06:36.701216 2026] [security2:error] [pid 499145:tid 499355] [client 20.151.200.44:27177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/4e.php"] [unique_id "apPkjFJNq1G5uRhTNnsk4AAAAFA"]
[Sun Aug 30 03:06:36.766427 2026] [authz_core:error] [pid 499145:tid 499368] [client 216.73.216.128:50607] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:36.766738 2026] [authz_core:error] [pid 499145:tid 499368] [client 216.73.216.128:50607] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:36.798843 2026] [authz_core:error] [pid 499145:tid 499305] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare
[Sun Aug 30 03:06:36.799134 2026] [authz_core:error] [pid 499145:tid 499305] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare
[Sun Aug 30 03:06:36.832588 2026] [security2:error] [pid 499145:tid 499375] [client 20.220.10.235:40796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/tf.php"] [unique_id "apPkjFJNq1G5uRhTNnsk6QAAAGQ"]
[Sun Aug 30 03:06:36.837349 2026] [security2:error] [pid 499145:tid 499275] [client 20.104.104.62:48699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/admin.php/csv.php"] [unique_id "apPkjFJNq1G5uRhTNnsk6gAAAAA"]
[Sun Aug 30 03:06:36.932551 2026] [authz_core:error] [pid 499145:tid 499373] [client 66.249.66.198:53932] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:36.932845 2026] [authz_core:error] [pid 499145:tid 499373] [client 66.249.66.198:53932] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:36.948064 2026] [authz_core:error] [pid 499145:tid 499390] [client 216.73.216.128:28014] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:36.948339 2026] [authz_core:error] [pid 499145:tid 499390] [client 216.73.216.128:28014] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:36.964883 2026] [security2:error] [pid 499145:tid 499321] [client 20.220.10.235:40806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/update/da222.php"] [unique_id "apPkjFJNq1G5uRhTNnsk8wAAAC4"]
[Sun Aug 30 03:06:36.981259 2026] [security2:error] [pid 499145:tid 499324] [client 20.104.104.62:48491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/admin.php/700.php"] [unique_id "apPkjFJNq1G5uRhTNnsk9AAAADE"]
[Sun Aug 30 03:06:37.010607 2026] [authz_core:error] [pid 499145:tid 499371] [client 66.249.66.74:50050] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:37.010996 2026] [authz_core:error] [pid 499145:tid 499371] [client 66.249.66.74:50050] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:37.012374 2026] [authz_core:error] [pid 499145:tid 499393] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fperl-List-MoreUtils-XS
[Sun Aug 30 03:06:37.012702 2026] [authz_core:error] [pid 499145:tid 499393] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fperl-List-MoreUtils-XS
[Sun Aug 30 03:06:37.107867 2026] [security2:error] [pid 499145:tid 499395] [client 20.220.10.235:40808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/qi.php"] [unique_id "apPkjVJNq1G5uRhTNnsk_QAAAHg"]
[Sun Aug 30 03:06:37.128060 2026] [security2:error] [pid 499145:tid 499286] [client 20.104.104.62:48720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/admin.php/007x.php"] [unique_id "apPkjVJNq1G5uRhTNnslAAAAAAs"]
[Sun Aug 30 03:06:37.131290 2026] [authz_core:error] [pid 499145:tid 499385] [client 216.73.216.128:39914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:37.131541 2026] [authz_core:error] [pid 499145:tid 499385] [client 216.73.216.128:39914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:37.160083 2026] [security2:error] [pid 499145:tid 499310] [client 20.151.200.44:47094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/txets.php"] [unique_id "apPkjVJNq1G5uRhTNnslBAAAACM"]
[Sun Aug 30 03:06:37.239576 2026] [security2:error] [pid 499145:tid 499319] [client 20.220.10.235:39838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/px.php"] [unique_id "apPkjVJNq1G5uRhTNnslBwAAACw"]
[Sun Aug 30 03:06:37.265849 2026] [security2:error] [pid 499145:tid 499392] [client 68.155.159.216:12298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/atomlib.php"] [unique_id "apPkjVJNq1G5uRhTNnslCQAAAHU"]
[Sun Aug 30 03:06:37.271381 2026] [security2:error] [pid 499145:tid 499276] [client 68.155.159.216:56438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apPkjVJNq1G5uRhTNnslCgAAAAE"]
[Sun Aug 30 03:06:37.276508 2026] [security2:error] [pid 499145:tid 499282] [client 20.104.104.62:48651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/admin.php/heex.php"] [unique_id "apPkjVJNq1G5uRhTNnslCwAAAAc"]
[Sun Aug 30 03:06:37.287410 2026] [security2:error] [pid 499145:tid 499315] [client 4.205.62.107:18813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/koiy.php"] [unique_id "apPkjVJNq1G5uRhTNnslDAAAACg"]
[Sun Aug 30 03:06:37.289397 2026] [security2:error] [pid 499145:tid 499323] [client 20.104.50.220:17306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/x.php"] [unique_id "apPkjVJNq1G5uRhTNnslDQAAADA"]
[Sun Aug 30 03:06:37.291566 2026] [security2:error] [pid 499145:tid 499318] [client 20.48.251.3:7033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/cli_bootstrap.php"] [unique_id "apPkjVJNq1G5uRhTNnslDgAAACs"]
[Sun Aug 30 03:06:37.303327 2026] [security2:error] [pid 499145:tid 499284] [client 4.205.62.107:39455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/sdsa.php"] [unique_id "apPkjVJNq1G5uRhTNnslDwAAAAk"]
[Sun Aug 30 03:06:37.303478 2026] [security2:error] [pid 499145:tid 499285] [client 20.48.251.3:49955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/paypal.php"] [unique_id "apPkjVJNq1G5uRhTNnslEAAAAAo"]
[Sun Aug 30 03:06:37.310323 2026] [security2:error] [pid 499145:tid 499335] [client 20.104.18.15:33686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/os.php"] [unique_id "apPkjVJNq1G5uRhTNnslEgAAADw"]
[Sun Aug 30 03:06:37.320817 2026] [security2:error] [pid 499145:tid 499353] [client 4.205.62.107:4104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/cu.php"] [unique_id "apPkjVJNq1G5uRhTNnslEwAAAE4"]
[Sun Aug 30 03:06:37.322501 2026] [security2:error] [pid 499145:tid 499283] [client 20.48.251.3:33309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/kerang.php"] [unique_id "apPkjVJNq1G5uRhTNnslFAAAAAg"]
[Sun Aug 30 03:06:37.326146 2026] [security2:error] [pid 499145:tid 499299] [client 20.104.50.220:32533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/FoxWSO-full.php"] [unique_id "apPkjVJNq1G5uRhTNnslFQAAABg"]
[Sun Aug 30 03:06:37.330028 2026] [security2:error] [pid 499145:tid 499297] [client 20.104.50.220:29139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/arab.php"] [unique_id "apPkjVJNq1G5uRhTNnslFwAAABY"]
[Sun Aug 30 03:06:37.334638 2026] [authz_core:error] [pid 499145:tid 499328] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule
[Sun Aug 30 03:06:37.335011 2026] [authz_core:error] [pid 499145:tid 499328] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule
[Sun Aug 30 03:06:37.338585 2026] [security2:error] [pid 499145:tid 499290] [client 4.205.62.107:65366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/wp-info.php"] [unique_id "apPkjVJNq1G5uRhTNnslGgAAAA8"]
[Sun Aug 30 03:06:37.344404 2026] [security2:error] [pid 499145:tid 499369] [client 20.104.50.220:27114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/info.php"] [unique_id "apPkjVJNq1G5uRhTNnslGwAAAF4"]
[Sun Aug 30 03:06:37.355312 2026] [security2:error] [pid 499145:tid 499331] [client 4.205.62.107:22553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/05.php"] [unique_id "apPkjVJNq1G5uRhTNnslHAAAADg"]
[Sun Aug 30 03:06:37.369497 2026] [security2:error] [pid 499145:tid 499336] [client 20.104.49.130:60738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/kj.php"] [unique_id "apPkjVJNq1G5uRhTNnslHQAAAD0"]
[Sun Aug 30 03:06:37.371949 2026] [security2:error] [pid 499145:tid 499349] [client 68.155.159.216:62062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/file.php"] [unique_id "apPkjVJNq1G5uRhTNnslHgAAAEo"]
[Sun Aug 30 03:06:37.372817 2026] [security2:error] [pid 499145:tid 499355] [client 20.220.10.235:40807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/is.php"] [unique_id "apPkjVJNq1G5uRhTNnslHwAAAFA"]
[Sun Aug 30 03:06:37.373634 2026] [security2:error] [pid 499145:tid 499334] [client 68.155.159.216:61343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-content/admin.php"] [unique_id "apPkjVJNq1G5uRhTNnslIAAAADs"]
[Sun Aug 30 03:06:37.374154 2026] [security2:error] [pid 499145:tid 499309] [client 4.205.62.107:2996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/pouhg.php"] [unique_id "apPkjVJNq1G5uRhTNnslIgAAACI"]
[Sun Aug 30 03:06:37.381301 2026] [security2:error] [pid 499145:tid 499388] [client 20.197.61.180:3265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/updraft/about.php"] [unique_id "apPkjVJNq1G5uRhTNnslIwAAAHE"]
[Sun Aug 30 03:06:37.411885 2026] [security2:error] [pid 499145:tid 499279] [client 20.104.18.15:13619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/wnnjpsby.php"] [unique_id "apPkjVJNq1G5uRhTNnslJgAAAAQ"]
[Sun Aug 30 03:06:37.419046 2026] [security2:error] [pid 499145:tid 499333] [client 20.104.104.62:48579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/tf.php"] [unique_id "apPkjVJNq1G5uRhTNnslKAAAADo"]
[Sun Aug 30 03:06:37.438176 2026] [security2:error] [pid 499145:tid 499337] [client 20.104.50.220:33284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/klee.php"] [unique_id "apPkjVJNq1G5uRhTNnslKgAAAD4"]
[Sun Aug 30 03:06:37.454784 2026] [security2:error] [pid 499145:tid 499362] [client 20.104.50.220:46615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/radio.php"] [unique_id "apPkjVJNq1G5uRhTNnslKwAAAFc"]
[Sun Aug 30 03:06:37.486125 2026] [security2:error] [pid 499145:tid 499345] [client 68.155.159.216:59959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-l0gin.php"] [unique_id "apPkjVJNq1G5uRhTNnslLAAAAEY"]
[Sun Aug 30 03:06:37.487802 2026] [security2:error] [pid 499145:tid 499325] [client 216.73.216.128:33592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/summary.csv"] [unique_id "apPkjVJNq1G5uRhTNnslLQAAADI"]
[Sun Aug 30 03:06:37.489910 2026] [security2:error] [pid 499145:tid 499389] [client 68.155.159.216:63530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/xmlrpc.php"] [unique_id "apPkjVJNq1G5uRhTNnslLgAAAHI"]
[Sun Aug 30 03:06:37.509626 2026] [security2:error] [pid 499145:tid 499289] [client 20.220.10.235:40717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/od.php"] [unique_id "apPkjVJNq1G5uRhTNnslMgAAAA4"]
[Sun Aug 30 03:06:37.539788 2026] [security2:error] [pid 499145:tid 499322] [client 20.104.18.15:23521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/media.php"] [unique_id "apPkjVJNq1G5uRhTNnslNAAAAC8"]
[Sun Aug 30 03:06:37.545694 2026] [security2:error] [pid 499145:tid 499361] [client 20.104.18.15:28666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/coffexium.php"] [unique_id "apPkjVJNq1G5uRhTNnslNgAAAFY"]
[Sun Aug 30 03:06:37.568494 2026] [security2:error] [pid 499145:tid 499395] [client 4.205.62.107:52140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/oc460l3x.php"] [unique_id "apPkjVJNq1G5uRhTNnslOgAAAHg"]
[Sun Aug 30 03:06:37.581298 2026] [security2:error] [pid 499145:tid 499294] [client 20.104.104.62:48701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/update/da222.php"] [unique_id "apPkjVJNq1G5uRhTNnslPAAAABM"]
[Sun Aug 30 03:06:37.643992 2026] [security2:error] [pid 499145:tid 499319] [client 20.220.10.235:39861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/wp-the.php"] [unique_id "apPkjVJNq1G5uRhTNnslRQAAACw"]
[Sun Aug 30 03:06:37.649379 2026] [security2:error] [pid 499145:tid 499370] [client 20.104.50.220:42801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/lolz.php"] [unique_id "apPkjVJNq1G5uRhTNnslRwAAAF8"]
[Sun Aug 30 03:06:37.656092 2026] [security2:error] [pid 499145:tid 499314] [client 20.48.251.3:44329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/server-info.php"] [unique_id "apPkjVJNq1G5uRhTNnslSAAAACc"]
[Sun Aug 30 03:06:37.656440 2026] [security2:error] [pid 499145:tid 499392] [client 4.205.62.107:32040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/asdf.php"] [unique_id "apPkjVJNq1G5uRhTNnslSgAAAHU"]
[Sun Aug 30 03:06:37.679982 2026] [security2:error] [pid 499145:tid 499278] [client 20.104.50.220:29346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/da111.php"] [unique_id "apPkjVJNq1G5uRhTNnslTQAAAAM"]
[Sun Aug 30 03:06:37.695270 2026] [security2:error] [pid 499145:tid 499284] [client 20.104.49.130:63287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/images.php"] [unique_id "apPkjVJNq1G5uRhTNnslTwAAAAk"]
[Sun Aug 30 03:06:37.737770 2026] [security2:error] [pid 499145:tid 499338] [client 20.104.50.220:5950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/,init.php"] [unique_id "apPkjVJNq1G5uRhTNnslVAAAAD8"]
[Sun Aug 30 03:06:37.738522 2026] [autoindex:error] [pid 499145:tid 499299] [client 20.104.18.15:0] AH01276: Cannot serve directory /home1/garypia/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:06:37.746149 2026] [security2:error] [pid 499145:tid 499331] [client 20.104.104.62:48502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/qi.php"] [unique_id "apPkjVJNq1G5uRhTNnslVQAAADg"]
[Sun Aug 30 03:06:37.746960 2026] [security2:error] [pid 499145:tid 499348] [client 20.151.200.44:27281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/ssss.php"] [unique_id "apPkjVJNq1G5uRhTNnslVgAAAEk"]
[Sun Aug 30 03:06:37.774819 2026] [security2:error] [pid 499145:tid 499336] [client 20.220.10.235:40799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/wt.php"] [unique_id "apPkjVJNq1G5uRhTNnslWAAAAD0"]
[Sun Aug 30 03:06:37.793919 2026] [authz_core:error] [pid 499145:tid 499334] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fgrub
[Sun Aug 30 03:06:37.794368 2026] [authz_core:error] [pid 499145:tid 499334] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fgrub
[Sun Aug 30 03:06:37.795872 2026] [security2:error] [pid 499145:tid 499388] [client 20.104.49.130:52320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/new.php"] [unique_id "apPkjVJNq1G5uRhTNnslXQAAAHE"]
[Sun Aug 30 03:06:37.813588 2026] [security2:error] [pid 499145:tid 499352] [client 20.104.18.15:43295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/w.php"] [unique_id "apPkjVJNq1G5uRhTNnslXgAAAE0"]
[Sun Aug 30 03:06:37.857182 2026] [authz_core:error] [pid 499145:tid 499281] [client 216.73.216.128:46036] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:37.857459 2026] [authz_core:error] [pid 499145:tid 499281] [client 216.73.216.128:46036] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:37.905547 2026] [security2:error] [pid 499145:tid 499387] [client 20.104.104.62:48654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/px.php"] [unique_id "apPkjVJNq1G5uRhTNnslYwAAAHA"]
[Sun Aug 30 03:06:37.927328 2026] [security2:error] [pid 499145:tid 499389] [client 20.220.10.235:39871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/im.php"] [unique_id "apPkjVJNq1G5uRhTNnslZwAAAHI"]
[Sun Aug 30 03:06:37.936276 2026] [authz_core:error] [pid 499145:tid 499365] [client 66.249.66.68:51776] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:37.936543 2026] [authz_core:error] [pid 499145:tid 499365] [client 66.249.66.68:51776] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:37.963431 2026] [security2:error] [pid 499145:tid 499379] [client 20.104.50.220:62005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/c100.php"] [unique_id "apPkjVJNq1G5uRhTNnslbQAAAGg"]
[Sun Aug 30 03:06:37.969588 2026] [authz_core:error] [pid 499145:tid 499330] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fperl-Compress-Raw-Zlib
[Sun Aug 30 03:06:37.969857 2026] [authz_core:error] [pid 499145:tid 499330] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fperl-Compress-Raw-Zlib
[Sun Aug 30 03:06:38.001160 2026] [security2:error] [pid 499145:tid 499326] [client 20.151.200.44:27327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/zoz.php"] [unique_id "apPkjlJNq1G5uRhTNnslbwAAADM"]
[Sun Aug 30 03:06:38.044269 2026] [authz_core:error] [pid 499145:tid 499381] [client 216.73.216.128:50607] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:38.044728 2026] [authz_core:error] [pid 499145:tid 499381] [client 216.73.216.128:50607] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:38.050460 2026] [authz_core:error] [pid 499145:tid 499301] [client 66.249.66.68:41362] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:38.050861 2026] [authz_core:error] [pid 499145:tid 499301] [client 66.249.66.68:41362] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:38.057462 2026] [security2:error] [pid 499145:tid 499390] [client 20.220.10.235:39840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/file.php"] [unique_id "apPkjlJNq1G5uRhTNnsldAAAAHM"]
[Sun Aug 30 03:06:38.099326 2026] [security2:error] [pid 499145:tid 499392] [client 20.151.200.44:37783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/admin.php/007x.php"] [unique_id "apPkjlJNq1G5uRhTNnsleQAAAHU"]
[Sun Aug 30 03:06:38.108607 2026] [security2:error] [pid 499145:tid 499323] [client 4.205.62.107:64673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkjlJNq1G5uRhTNnslegAAADA"]
[Sun Aug 30 03:06:38.117659 2026] [security2:error] [pid 499145:tid 499374] [client 20.197.61.180:14769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/upgrade-temp-backup/min.php"] [unique_id "apPkjlJNq1G5uRhTNnslewAAAGM"]
[Sun Aug 30 03:06:38.156228 2026] [security2:error] [pid 499145:tid 499283] [client 20.104.104.62:48462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/is.php"] [unique_id "apPkjlJNq1G5uRhTNnslggAAAAg"]
[Sun Aug 30 03:06:38.189806 2026] [security2:error] [pid 499145:tid 499299] [client 20.220.10.235:39863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/ca.php"] [unique_id "apPkjlJNq1G5uRhTNnslhgAAABg"]
[Sun Aug 30 03:06:38.226885 2026] [security2:error] [pid 499145:tid 499348] [client 4.205.62.107:27309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPkjlJNq1G5uRhTNnsliQAAAEk"]
[Sun Aug 30 03:06:38.270793 2026] [security2:error] [pid 499145:tid 499298] [client 45.3.55.204:21147] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "belloinsights.com"] [uri "/"] [unique_id "apPkjlJNq1G5uRhTNnsljwAAABc"]
[Sun Aug 30 03:06:38.279506 2026] [authz_core:error] [pid 499145:tid 499311] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare
[Sun Aug 30 03:06:38.279884 2026] [authz_core:error] [pid 499145:tid 499311] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare
[Sun Aug 30 03:06:38.290925 2026] [authz_core:error] [pid 499145:tid 499356] [client 66.249.66.42:46345] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:38.291356 2026] [authz_core:error] [pid 499145:tid 499356] [client 66.249.66.42:46345] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:38.306715 2026] [security2:error] [pid 499145:tid 499399] [client 20.104.104.62:48494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/od.php"] [unique_id "apPkjlJNq1G5uRhTNnslkgAAAHw"]
[Sun Aug 30 03:06:38.323539 2026] [security2:error] [pid 499145:tid 499275] [client 20.220.10.235:40818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/pb.php"] [unique_id "apPkjlJNq1G5uRhTNnsllAAAAAA"]
[Sun Aug 30 03:06:38.402410 2026] [security2:error] [pid 499145:tid 499347] [client 68.155.159.216:65489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/lv.php"] [unique_id "apPkjlJNq1G5uRhTNnsloAAAAEg"]
[Sun Aug 30 03:06:38.426904 2026] [security2:error] [pid 499145:tid 499279] [client 20.104.50.220:17290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/by.php"] [unique_id "apPkjlJNq1G5uRhTNnslowAAAAQ"]
[Sun Aug 30 03:06:38.440641 2026] [security2:error] [pid 499145:tid 499302] [client 68.155.159.216:11204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apPkjlJNq1G5uRhTNnslpAAAABs"]
[Sun Aug 30 03:06:38.442082 2026] [security2:error] [pid 499145:tid 499344] [client 4.205.62.107:63949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/sale.php"] [unique_id "apPkjlJNq1G5uRhTNnslpQAAAEU"]
[Sun Aug 30 03:06:38.444154 2026] [security2:error] [pid 499145:tid 499281] [client 20.48.251.3:6995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/dd.php"] [unique_id "apPkjlJNq1G5uRhTNnslpgAAAAY"]
[Sun Aug 30 03:06:38.457832 2026] [security2:error] [pid 499145:tid 499390] [client 20.48.251.3:55438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/userfuns.php"] [unique_id "apPkjlJNq1G5uRhTNnslpwAAAHM"]
[Sun Aug 30 03:06:38.458821 2026] [security2:error] [pid 499145:tid 499373] [client 4.205.62.107:4102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/services.php"] [unique_id "apPkjlJNq1G5uRhTNnslqQAAAGI"]
[Sun Aug 30 03:06:38.458924 2026] [security2:error] [pid 499145:tid 499368] [client 4.205.62.107:18960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/queue.php"] [unique_id "apPkjlJNq1G5uRhTNnslqAAAAF0"]
[Sun Aug 30 03:06:38.465133 2026] [security2:error] [pid 499145:tid 499351] [client 20.220.10.235:39852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/pk.php"] [unique_id "apPkjlJNq1G5uRhTNnslqgAAAEw"]
[Sun Aug 30 03:06:38.469911 2026] [security2:error] [pid 499145:tid 499396] [client 20.104.18.15:33648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/htio.php"] [unique_id "apPkjlJNq1G5uRhTNnslqwAAAHk"]
[Sun Aug 30 03:06:38.477174 2026] [authz_core:error] [pid 499145:tid 499307] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fperl-List-MoreUtils-XS
[Sun Aug 30 03:06:38.477435 2026] [authz_core:error] [pid 499145:tid 499307] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fperl-List-MoreUtils-XS
[Sun Aug 30 03:06:38.493967 2026] [security2:error] [pid 499145:tid 499341] [client 20.104.50.220:32540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/FoxWSO.php"] [unique_id "apPkjlJNq1G5uRhTNnslrQAAAEI"]
[Sun Aug 30 03:06:38.493967 2026] [security2:error] [pid 499145:tid 499401] [client 20.104.50.220:27116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/up.php"] [unique_id "apPkjlJNq1G5uRhTNnslrgAAAH4"]
[Sun Aug 30 03:06:38.495359 2026] [security2:error] [pid 499145:tid 499323] [client 4.205.62.107:58160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/fns.php"] [unique_id "apPkjlJNq1G5uRhTNnslsQAAADA"]
[Sun Aug 30 03:06:38.495479 2026] [security2:error] [pid 499145:tid 499391] [client 20.104.50.220:28719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/bd.php"] [unique_id "apPkjlJNq1G5uRhTNnslsAAAAHQ"]
[Sun Aug 30 03:06:38.496557 2026] [security2:error] [pid 499145:tid 499278] [client 4.205.62.107:22975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/wp-blog.php"] [unique_id "apPkjlJNq1G5uRhTNnslsgAAAAM"]
[Sun Aug 30 03:06:38.511936 2026] [security2:error] [pid 499145:tid 499304] [client 4.205.62.107:2768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/phpversion.php"] [unique_id "apPkjlJNq1G5uRhTNnsltAAAAB0"]
[Sun Aug 30 03:06:38.514854 2026] [security2:error] [pid 499145:tid 499285] [client 20.48.251.3:33300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/rem.php"] [unique_id "apPkjlJNq1G5uRhTNnsltQAAAAo"]
[Sun Aug 30 03:06:38.525492 2026] [security2:error] [pid 499145:tid 499325] [client 20.104.104.62:48695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/wp-the.php"] [unique_id "apPkjlJNq1G5uRhTNnsltgAAADI"]
[Sun Aug 30 03:06:38.551706 2026] [security2:error] [pid 499145:tid 499310] [client 20.151.200.44:27140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/kcs.php"] [unique_id "apPkjlJNq1G5uRhTNnsltwAAACM"]
[Sun Aug 30 03:06:38.580520 2026] [security2:error] [pid 499145:tid 499352] [client 20.104.18.15:13577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/gigi.php"] [unique_id "apPkjlJNq1G5uRhTNnslvgAAAE0"]
[Sun Aug 30 03:06:38.594655 2026] [security2:error] [pid 499145:tid 499383] [client 20.104.50.220:32850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/kalokataitusayagatauya.php"] [unique_id "apPkjlJNq1G5uRhTNnslwAAAAGw"]
[Sun Aug 30 03:06:38.604986 2026] [security2:error] [pid 499145:tid 499377] [client 20.220.10.235:40787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/ft.php"] [unique_id "apPkjlJNq1G5uRhTNnslwwAAAGY"]
[Sun Aug 30 03:06:38.610011 2026] [security2:error] [pid 499145:tid 499287] [client 20.104.50.220:46592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/shell20211028.php"] [unique_id "apPkjlJNq1G5uRhTNnslxQAAAAw"]
[Sun Aug 30 03:06:38.681697 2026] [security2:error] [pid 499145:tid 499294] [client 68.155.159.216:63542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/atomlib.php"] [unique_id "apPkjlJNq1G5uRhTNnslywAAABM"]
[Sun Aug 30 03:06:38.683676 2026] [security2:error] [pid 499145:tid 499279] [client 20.104.18.15:28649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/coffee.php"] [unique_id "apPkjlJNq1G5uRhTNnslzAAAAAQ"]
[Sun Aug 30 03:06:38.693507 2026] [security2:error] [pid 499145:tid 499302] [client 68.155.159.216:60890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/file17.php"] [unique_id "apPkjlJNq1G5uRhTNnslzQAAABs"]
[Sun Aug 30 03:06:38.694731 2026] [security2:error] [pid 499145:tid 499344] [client 20.104.104.62:48653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/wt.php"] [unique_id "apPkjlJNq1G5uRhTNnslzgAAAEU"]
[Sun Aug 30 03:06:38.722825 2026] [security2:error] [pid 499145:tid 499382] [client 68.155.159.216:60002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apPkjlJNq1G5uRhTNnslzwAAAGs"]
[Sun Aug 30 03:06:38.731155 2026] [security2:error] [pid 499145:tid 499373] [client 20.104.18.15:23509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/adminfuns.php"] [unique_id "apPkjlJNq1G5uRhTNnsl0AAAAGI"]
[Sun Aug 30 03:06:38.741447 2026] [security2:error] [pid 499145:tid 499368] [client 20.220.10.235:40817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/wp-ver.php"] [unique_id "apPkjlJNq1G5uRhTNnsl0QAAAF0"]
[Sun Aug 30 03:06:38.793013 2026] [security2:error] [pid 499145:tid 499323] [client 20.48.251.3:4725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/gk.php"] [unique_id "apPkjlJNq1G5uRhTNnsl1AAAADA"]
[Sun Aug 30 03:06:38.801048 2026] [authz_core:error] [pid 499145:tid 499391] [client 66.249.66.77:55329] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:38.801326 2026] [authz_core:error] [pid 499145:tid 499391] [client 66.249.66.77:55329] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:38.816175 2026] [security2:error] [pid 499145:tid 499304] [client 20.104.50.220:42009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/libs-func.php"] [unique_id "apPkjlJNq1G5uRhTNnsl1wAAAB0"]
[Sun Aug 30 03:06:38.818035 2026] [authz_core:error] [pid 499145:tid 499374] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fmsr
[Sun Aug 30 03:06:38.818321 2026] [authz_core:error] [pid 499145:tid 499374] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fmsr
[Sun Aug 30 03:06:38.833160 2026] [security2:error] [pid 499145:tid 499283] [client 4.205.62.107:56633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/drykl.php"] [unique_id "apPkjlJNq1G5uRhTNnsl3AAAAAg"]
[Sun Aug 30 03:06:38.846771 2026] [security2:error] [pid 499145:tid 499314] [client 68.155.159.216:61317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/xmlrpc.php"] [unique_id "apPkjlJNq1G5uRhTNnsl3QAAACc"]
[Sun Aug 30 03:06:38.847039 2026] [security2:error] [pid 499145:tid 499363] [client 20.197.61.180:9164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/upgrade-temp-backup/pk.php"] [unique_id "apPkjlJNq1G5uRhTNnsl3gAAAFg"]
[Sun Aug 30 03:06:38.860812 2026] [security2:error] [pid 499145:tid 499338] [client 20.104.104.62:48599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/im.php"] [unique_id "apPkjlJNq1G5uRhTNnsl4AAAAD8"]
[Sun Aug 30 03:06:38.868743 2026] [security2:error] [pid 499145:tid 499299] [client 20.151.200.44:27277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/tajj.php"] [unique_id "apPkjlJNq1G5uRhTNnsl4QAAABg"]
[Sun Aug 30 03:06:38.893393 2026] [security2:error] [pid 499145:tid 499317] [client 20.220.10.235:40824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/ah24.php"] [unique_id "apPkjlJNq1G5uRhTNnsl4gAAACo"]
[Sun Aug 30 03:06:38.894224 2026] [security2:error] [pid 499145:tid 499364] [client 20.104.50.220:5576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/env.php"] [unique_id "apPkjlJNq1G5uRhTNnsl5AAAAFk"]
[Sun Aug 30 03:06:38.900895 2026] [authz_core:error] [pid 499145:tid 499348] [client 66.249.66.67:47658] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:38.901177 2026] [authz_core:error] [pid 499145:tid 499348] [client 66.249.66.67:47658] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:38.935787 2026] [security2:error] [pid 499145:tid 499336] [client 20.151.200.44:55633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/blnux.php"] [unique_id "apPkjlJNq1G5uRhTNnsl5gAAAD0"]
[Sun Aug 30 03:06:38.942601 2026] [security2:error] [pid 499145:tid 499349] [client 20.151.200.44:47337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/admin.php/heex.php"] [unique_id "apPkjlJNq1G5uRhTNnsl5wAAAEo"]
[Sun Aug 30 03:06:38.957515 2026] [security2:error] [pid 499145:tid 499356] [client 20.104.18.15:43841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/x.php"] [unique_id "apPkjlJNq1G5uRhTNnsl7AAAAFE"]
[Sun Aug 30 03:06:38.993615 2026] [authz_core:error] [pid 499145:tid 499322] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fperl-List-MoreUtils-XS
[Sun Aug 30 03:06:38.993966 2026] [authz_core:error] [pid 499145:tid 499322] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fperl-List-MoreUtils-XS
[Sun Aug 30 03:06:39.028139 2026] [security2:error] [pid 499145:tid 499334] [client 20.104.104.62:48693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/file.php"] [unique_id "apPkj1JNq1G5uRhTNnsl9wAAADs"]
[Sun Aug 30 03:06:39.035708 2026] [security2:error] [pid 499145:tid 499294] [client 20.220.10.235:40779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPkj1JNq1G5uRhTNnsl-gAAABM"]
[Sun Aug 30 03:06:39.041766 2026] [authz_core:error] [pid 499145:tid 499307] [client 216.73.216.128:50607] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:39.042035 2026] [authz_core:error] [pid 499145:tid 499307] [client 216.73.216.128:50607] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:39.099360 2026] [security2:error] [pid 499145:tid 499371] [client 20.104.50.220:61407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/simattacker.php"] [unique_id "apPkj1JNq1G5uRhTNnsmBgAAAGA"]
[Sun Aug 30 03:06:39.133588 2026] [authz_core:error] [pid 499145:tid 499285] [client 216.73.216.128:45526] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:39.133866 2026] [authz_core:error] [pid 499145:tid 499285] [client 216.73.216.128:45526] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:39.139817 2026] [security2:error] [pid 499145:tid 499385] [client 20.104.49.130:63270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/ano.php"] [unique_id "apPkj1JNq1G5uRhTNnsmCwAAAG4"]
[Sun Aug 30 03:06:39.169318 2026] [security2:error] [pid 499145:tid 499364] [client 20.220.10.235:40776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/waf.php"] [unique_id "apPkj1JNq1G5uRhTNnsmEgAAAFk"]
[Sun Aug 30 03:06:39.178044 2026] [security2:error] [pid 499145:tid 499330] [client 20.104.104.62:48620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/ca.php"] [unique_id "apPkj1JNq1G5uRhTNnsmFQAAADc"]
[Sun Aug 30 03:06:39.207381 2026] [security2:error] [pid 499145:tid 499356] [client 4.205.62.107:32009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apPkj1JNq1G5uRhTNnsmGgAAAFE"]
[Sun Aug 30 03:06:39.249197 2026] [security2:error] [pid 499145:tid 499327] [client 4.205.62.107:64456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkj1JNq1G5uRhTNnsmHAAAADQ"]
[Sun Aug 30 03:06:39.295598 2026] [security2:error] [pid 499145:tid 499345] [client 4.205.62.107:60576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/tax.php"] [unique_id "apPkj1JNq1G5uRhTNnsmIQAAAEY"]
[Sun Aug 30 03:06:39.302272 2026] [authz_core:error] [pid 499145:tid 499361] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Flib%2Fkernel
[Sun Aug 30 03:06:39.302552 2026] [authz_core:error] [pid 499145:tid 499361] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Flib%2Fkernel
[Sun Aug 30 03:06:39.352512 2026] [security2:error] [pid 499145:tid 499382] [client 20.104.104.62:48684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/pb.php"] [unique_id "apPkj1JNq1G5uRhTNnsmKgAAAGs"]
[Sun Aug 30 03:06:39.401457 2026] [authz_core:error] [pid 499145:tid 499384] [client 66.249.66.66:42458] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:39.401902 2026] [authz_core:error] [pid 499145:tid 499384] [client 66.249.66.66:42458] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:39.471727 2026] [authz_core:error] [pid 499145:tid 499310] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:06:39.472128 2026] [authz_core:error] [pid 499145:tid 499310] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:06:39.503669 2026] [security2:error] [pid 499145:tid 499377] [client 20.104.104.62:48510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/pk.php"] [unique_id "apPkj1JNq1G5uRhTNnsmQQAAAGY"]
[Sun Aug 30 03:06:39.507561 2026] [security2:error] [pid 499145:tid 499362] [client 68.155.159.216:65522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apPkj1JNq1G5uRhTNnsmQgAAAFc"]
[Sun Aug 30 03:06:39.540557 2026] [security2:error] [pid 499145:tid 499399] [client 68.155.159.216:56337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apPkj1JNq1G5uRhTNnsmQwAAAHw"]
[Sun Aug 30 03:06:39.556278 2026] [security2:error] [pid 499145:tid 499315] [client 4.205.62.107:27305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/agg.php"] [unique_id "apPkj1JNq1G5uRhTNnsmRAAAACg"]
[Sun Aug 30 03:06:39.565554 2026] [security2:error] [pid 499145:tid 499311] [client 20.151.200.44:47069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/wp-login.php"] [unique_id "apPkj1JNq1G5uRhTNnsmRQAAACQ"]
[Sun Aug 30 03:06:39.567389 2026] [security2:error] [pid 499145:tid 499366] [client 20.104.50.220:17282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/cxs.php"] [unique_id "apPkj1JNq1G5uRhTNnsmRwAAAFs"]
[Sun Aug 30 03:06:39.576301 2026] [security2:error] [pid 499145:tid 499380] [client 20.197.61.180:21056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/upgrade-temp-backup/plugins/security.php"] [unique_id "apPkj1JNq1G5uRhTNnsmSAAAAGk"]
[Sun Aug 30 03:06:39.583530 2026] [security2:error] [pid 499145:tid 499280] [client 20.48.251.3:64490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/wp-tem.php"] [unique_id "apPkj1JNq1G5uRhTNnsmSwAAAAU"]
[Sun Aug 30 03:06:39.584190 2026] [security2:error] [pid 499145:tid 499391] [client 4.205.62.107:63997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/wp-class.php"] [unique_id "apPkj1JNq1G5uRhTNnsmTAAAAHQ"]
[Sun Aug 30 03:06:39.588582 2026] [authz_core:error] [pid 499145:tid 499389] [client 66.249.66.71:61620] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:39.589054 2026] [authz_core:error] [pid 499145:tid 499389] [client 66.249.66.71:61620] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:39.600848 2026] [security2:error] [pid 499145:tid 499343] [client 4.205.62.107:4128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/filesystems.php"] [unique_id "apPkj1JNq1G5uRhTNnsmTQAAAEQ"]
[Sun Aug 30 03:06:39.610586 2026] [security2:error] [pid 499145:tid 499291] [client 20.48.251.3:49990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/mamzi.php"] [unique_id "apPkj1JNq1G5uRhTNnsmTwAAABA"]
[Sun Aug 30 03:06:39.621538 2026] [security2:error] [pid 499145:tid 499294] [client 20.104.18.15:33790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/dev.php"] [unique_id "apPkj1JNq1G5uRhTNnsmUAAAABM"]
[Sun Aug 30 03:06:39.630666 2026] [security2:error] [pid 499145:tid 499374] [client 20.104.50.220:27562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/unzipper.php"] [unique_id "apPkj1JNq1G5uRhTNnsmUQAAAGM"]
[Sun Aug 30 03:06:39.640075 2026] [security2:error] [pid 499145:tid 499382] [client 20.104.50.220:52829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/komet.php"] [unique_id "apPkj1JNq1G5uRhTNnsmUgAAAGs"]
[Sun Aug 30 03:06:39.645799 2026] [security2:error] [pid 499145:tid 499376] [client 20.104.50.220:31892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/foxwso.php"] [unique_id "apPkj1JNq1G5uRhTNnsmUwAAAGU"]
[Sun Aug 30 03:06:39.650353 2026] [security2:error] [pid 499145:tid 499368] [client 4.205.62.107:2789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/adminfus.php"] [unique_id "apPkj1JNq1G5uRhTNnsmVAAAAF0"]
[Sun Aug 30 03:06:39.656350 2026] [security2:error] [pid 499145:tid 499328] [client 20.48.251.3:56334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/min.php"] [unique_id "apPkj1JNq1G5uRhTNnsmVQAAADU"]
[Sun Aug 30 03:06:39.662451 2026] [security2:error] [pid 499145:tid 499288] [client 4.205.62.107:22925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/erty.php"] [unique_id "apPkj1JNq1G5uRhTNnsmVwAAAA0"]
[Sun Aug 30 03:06:39.678024 2026] [security2:error] [pid 499145:tid 499290] [client 4.205.62.107:18945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/doc.php"] [unique_id "apPkj1JNq1G5uRhTNnsmWwAAAA8"]
[Sun Aug 30 03:06:39.685954 2026] [authz_core:error] [pid 499145:tid 499344] [client 66.249.66.78:38043] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:39.686223 2026] [authz_core:error] [pid 499145:tid 499344] [client 66.249.66.78:38043] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:39.717291 2026] [security2:error] [pid 499145:tid 499361] [client 20.104.104.62:48650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/ft.php"] [unique_id "apPkj1JNq1G5uRhTNnsmYgAAAFY"]
[Sun Aug 30 03:06:39.719815 2026] [security2:error] [pid 499145:tid 499296] [client 20.104.18.15:13689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/info.php/new.php"] [unique_id "apPkj1JNq1G5uRhTNnsmYwAAABU"]
[Sun Aug 30 03:06:39.742698 2026] [security2:error] [pid 499145:tid 499300] [client 20.104.50.220:33304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/jpg.php"] [unique_id "apPkj1JNq1G5uRhTNnsmZQAAABk"]
[Sun Aug 30 03:06:39.760982 2026] [security2:error] [pid 499145:tid 499324] [client 20.104.50.220:47079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/shells.php"] [unique_id "apPkj1JNq1G5uRhTNnsmaAAAADE"]
[Sun Aug 30 03:06:39.786725 2026] [authz_core:error] [pid 499145:tid 499375] [client 66.249.66.76:38091] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:39.787158 2026] [authz_core:error] [pid 499145:tid 499375] [client 66.249.66.76:38091] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:39.798671 2026] [authz_core:error] [pid 499145:tid 499386] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fmsr
[Sun Aug 30 03:06:39.798980 2026] [authz_core:error] [pid 499145:tid 499386] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fmsr
[Sun Aug 30 03:06:39.826016 2026] [security2:error] [pid 499145:tid 499288] [client 68.155.159.216:62302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/lv.php"] [unique_id "apPkj1JNq1G5uRhTNnsmfAAAAA0"]
[Sun Aug 30 03:06:39.827551 2026] [security2:error] [pid 499145:tid 499383] [client 20.104.18.15:28628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/classwithtostring.php"] [unique_id "apPkj1JNq1G5uRhTNnsmfQAAAGw"]
[Sun Aug 30 03:06:39.837270 2026] [security2:error] [pid 499145:tid 499290] [client 68.155.159.216:60872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/file5.php"] [unique_id "apPkj1JNq1G5uRhTNnsmgAAAAA8"]
[Sun Aug 30 03:06:39.838742 2026] [security2:error] [pid 499145:tid 499302] [client 45.3.55.204:39901] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "belloinsights.com"] [uri "/"] [unique_id "apPkj1JNq1G5uRhTNnsmgQAAABs"]
[Sun Aug 30 03:06:39.861222 2026] [authz_core:error] [pid 499145:tid 499336] [client 216.73.216.128:46036] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:39.861494 2026] [authz_core:error] [pid 499145:tid 499336] [client 216.73.216.128:46036] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:39.871359 2026] [security2:error] [pid 499145:tid 499301] [client 20.104.18.15:23541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/classwithtostring.php"] [unique_id "apPkj1JNq1G5uRhTNnsmhwAAABo"]
[Sun Aug 30 03:06:39.918692 2026] [security2:error] [pid 499145:tid 499339] [client 20.48.251.3:6972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/xmy.php"] [unique_id "apPkj1JNq1G5uRhTNnsmkQAAAEA"]
[Sun Aug 30 03:06:39.924945 2026] [security2:error] [pid 499145:tid 499298] [client 20.104.104.62:48645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/wp-ver.php"] [unique_id "apPkj1JNq1G5uRhTNnsmkwAAABc"]
[Sun Aug 30 03:06:39.931197 2026] [security2:error] [pid 499145:tid 499276] [client 68.155.159.216:59909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPkj1JNq1G5uRhTNnsmlAAAAAE"]
[Sun Aug 30 03:06:39.931227 2026] [security2:error] [pid 499145:tid 499313] [client 20.48.251.3:4705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/god.php"] [unique_id "apPkj1JNq1G5uRhTNnsmlQAAACY"]
[Sun Aug 30 03:06:39.984605 2026] [authz_core:error] [pid 499145:tid 499394] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:06:39.984936 2026] [authz_core:error] [pid 499145:tid 499394] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:06:40.028375 2026] [security2:error] [pid 499145:tid 499300] [client 4.205.62.107:56612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/rpk.php"] [unique_id "apPkkFJNq1G5uRhTNnsmtQAAABk"]
[Sun Aug 30 03:06:40.045800 2026] [security2:error] [pid 499145:tid 499332] [client 20.104.50.220:6133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/elf.php"] [unique_id "apPkkFJNq1G5uRhTNnsmuwAAADk"]
[Sun Aug 30 03:06:40.079961 2026] [security2:error] [pid 499145:tid 499391] [client 20.104.104.62:48678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/ah24.php"] [unique_id "apPkkFJNq1G5uRhTNnsmwwAAAHQ"]
[Sun Aug 30 03:06:40.098534 2026] [security2:error] [pid 499145:tid 499376] [client 20.104.18.15:43913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/ssla.php"] [unique_id "apPkkFJNq1G5uRhTNnsmxwAAAGU"]
[Sun Aug 30 03:06:40.138888 2026] [authz_core:error] [pid 499145:tid 499343] [client 216.73.216.128:45526] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:40.139395 2026] [authz_core:error] [pid 499145:tid 499343] [client 216.73.216.128:45526] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:40.157914 2026] [security2:error] [pid 499145:tid 499335] [client 20.104.50.220:63543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/anu.php"] [unique_id "apPkkFJNq1G5uRhTNnsmzwAAADw"]
[Sun Aug 30 03:06:40.228944 2026] [security2:error] [pid 499145:tid 499318] [client 20.104.104.62:48468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPkkFJNq1G5uRhTNnsm4AAAACs"]
[Sun Aug 30 03:06:40.282922 2026] [authz_core:error] [pid 499145:tid 499391] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fmemory_hotplug%2Fparameters
[Sun Aug 30 03:06:40.283178 2026] [authz_core:error] [pid 499145:tid 499391] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fmemory_hotplug%2Fparameters
[Sun Aug 30 03:06:40.284912 2026] [security2:error] [pid 499145:tid 499355] [client 20.104.50.220:61388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wsoshell.php"] [unique_id "apPkkFJNq1G5uRhTNnsm7wAAAFA"]
[Sun Aug 30 03:06:40.290229 2026] [authz_core:error] [pid 499145:tid 499330] [client 66.249.66.197:50241] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:40.290663 2026] [authz_core:error] [pid 499145:tid 499330] [client 66.249.66.197:50241] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:40.293564 2026] [security2:error] [pid 499145:tid 499356] [client 20.197.61.180:21105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/upgrade-temp-backup/plugins/users.php"] [unique_id "apPkkFJNq1G5uRhTNnsm8AAAAFE"]
[Sun Aug 30 03:06:40.301858 2026] [security2:error] [pid 499145:tid 499344] [client 20.104.50.220:28691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/DA.php"] [unique_id "apPkkFJNq1G5uRhTNnsm9AAAAEU"]
[Sun Aug 30 03:06:40.353670 2026] [security2:error] [pid 499145:tid 499305] [client 68.155.159.216:64794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/atomlib.php"] [unique_id "apPkkFJNq1G5uRhTNnsm_QAAAB4"]
[Sun Aug 30 03:06:40.383211 2026] [security2:error] [pid 499145:tid 499372] [client 4.205.62.107:64701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/cloud.php"] [unique_id "apPkkFJNq1G5uRhTNnsnBgAAAGE"]
[Sun Aug 30 03:06:40.392895 2026] [security2:error] [pid 499145:tid 499369] [client 20.104.104.62:48723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.b6standards.com"] [uri "/waf.php"] [unique_id "apPkkFJNq1G5uRhTNnsnDQAAAF4"]
[Sun Aug 30 03:06:40.430972 2026] [security2:error] [pid 499145:tid 499355] [client 4.205.62.107:63753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPkkFJNq1G5uRhTNnsnFQAAAFA"]
[Sun Aug 30 03:06:40.453819 2026] [security2:error] [pid 499145:tid 499332] [client 20.151.200.44:27144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/bge.php"] [unique_id "apPkkFJNq1G5uRhTNnsnGgAAADk"]
[Sun Aug 30 03:06:40.535609 2026] [authz_core:error] [pid 499145:tid 499360] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:06:40.535891 2026] [authz_core:error] [pid 499145:tid 499360] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:06:40.582289 2026] [security2:error] [pid 499145:tid 499402] [client 20.151.200.44:37764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/admin.php/heex.php"] [unique_id "apPkkFJNq1G5uRhTNnsnJAAAAH8"]
[Sun Aug 30 03:06:40.641698 2026] [security2:error] [pid 499145:tid 499301] [client 68.155.159.216:12307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/content.php"] [unique_id "apPkkFJNq1G5uRhTNnsnJwAAABo"]
[Sun Aug 30 03:06:40.669134 2026] [security2:error] [pid 499145:tid 499367] [client 68.155.159.216:56323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/dropdown.php"] [unique_id "apPkkFJNq1G5uRhTNnsnKAAAAFw"]
[Sun Aug 30 03:06:40.687399 2026] [authz_core:error] [pid 499145:tid 499276] [client 216.73.216.128:45526] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:40.687819 2026] [authz_core:error] [pid 499145:tid 499276] [client 216.73.216.128:45526] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:40.701424 2026] [security2:error] [pid 499145:tid 499392] [client 20.104.50.220:16705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/coffexium.php"] [unique_id "apPkkFJNq1G5uRhTNnsnMgAAAHU"]
[Sun Aug 30 03:06:40.723497 2026] [security2:error] [pid 499145:tid 499275] [client 4.205.62.107:63991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/database.php"] [unique_id "apPkkFJNq1G5uRhTNnsnNwAAAAA"]
[Sun Aug 30 03:06:40.756548 2026] [security2:error] [pid 499145:tid 499386] [client 20.48.251.3:64420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/txets.php"] [unique_id "apPkkFJNq1G5uRhTNnsnOwAAAG8"]
[Sun Aug 30 03:06:40.765918 2026] [security2:error] [pid 499145:tid 499399] [client 20.104.50.220:27449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/upload.php"] [unique_id "apPkkFJNq1G5uRhTNnsnPwAAAHw"]
[Sun Aug 30 03:06:40.780793 2026] [security2:error] [pid 499145:tid 499308] [client 20.104.18.15:33690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/gos.php"] [unique_id "apPkkFJNq1G5uRhTNnsnRwAAACE"]
[Sun Aug 30 03:06:40.788359 2026] [security2:error] [pid 499145:tid 499401] [client 4.205.62.107:2355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/avim.php"] [unique_id "apPkkFJNq1G5uRhTNnsnSgAAAH4"]
[Sun Aug 30 03:06:40.789078 2026] [security2:error] [pid 499145:tid 499297] [client 20.48.251.3:49968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/public/rip.php.php"] [unique_id "apPkkFJNq1G5uRhTNnsnSwAAABY"]
[Sun Aug 30 03:06:40.792797 2026] [security2:error] [pid 499145:tid 499316] [client 20.48.251.3:56327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/saiga.php"] [unique_id "apPkkFJNq1G5uRhTNnsnTAAAACk"]
[Sun Aug 30 03:06:40.800380 2026] [security2:error] [pid 499145:tid 499301] [client 20.104.50.220:62797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/1337.php"] [unique_id "apPkkFJNq1G5uRhTNnsnUQAAABo"]
[Sun Aug 30 03:06:40.803319 2026] [security2:error] [pid 499145:tid 499321] [client 20.104.50.220:31859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/gank.php"] [unique_id "apPkkFJNq1G5uRhTNnsnVAAAAC4"]
[Sun Aug 30 03:06:40.812999 2026] [authz_core:error] [pid 499145:tid 499306] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fmemory_hotplug%2Fparameters
[Sun Aug 30 03:06:40.813249 2026] [authz_core:error] [pid 499145:tid 499306] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fmemory_hotplug%2Fparameters
[Sun Aug 30 03:06:40.813654 2026] [security2:error] [pid 499145:tid 499387] [client 4.205.62.107:19003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/css.php"] [unique_id "apPkkFJNq1G5uRhTNnsnWQAAAHA"]
[Sun Aug 30 03:06:40.820006 2026] [security2:error] [pid 499145:tid 499317] [client 4.205.62.107:32024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/hochladen.form.php"] [unique_id "apPkkFJNq1G5uRhTNnsnWwAAACo"]
[Sun Aug 30 03:06:40.830671 2026] [security2:error] [pid 499145:tid 499275] [client 4.205.62.107:22539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/wp-config.backup.php"] [unique_id "apPkkFJNq1G5uRhTNnsnYAAAAAA"]
[Sun Aug 30 03:06:40.844032 2026] [security2:error] [pid 499145:tid 499362] [client 4.205.62.107:4147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/tax.php"] [unique_id "apPkkFJNq1G5uRhTNnsnYgAAAFc"]
[Sun Aug 30 03:06:40.860863 2026] [authz_core:error] [pid 499145:tid 499298] [client 66.249.66.70:53633] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:40.861311 2026] [authz_core:error] [pid 499145:tid 499298] [client 66.249.66.70:53633] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:40.880970 2026] [security2:error] [pid 499145:tid 499308] [client 20.104.50.220:33320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/jak.php"] [unique_id "apPkkFJNq1G5uRhTNnsnbgAAACE"]
[Sun Aug 30 03:06:40.899448 2026] [security2:error] [pid 499145:tid 499401] [client 20.104.50.220:46145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/stupid.php"] [unique_id "apPkkFJNq1G5uRhTNnsncwAAAH4"]
[Sun Aug 30 03:06:40.900986 2026] [security2:error] [pid 499145:tid 499384] [client 20.104.49.130:48543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/tiny2.php"] [unique_id "apPkkFJNq1G5uRhTNnsndAAAAG0"]
[Sun Aug 30 03:06:40.924731 2026] [security2:error] [pid 499145:tid 499387] [client 68.155.159.216:63510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-includes/Text/index.php"] [unique_id "apPkkFJNq1G5uRhTNnsneAAAAHA"]
[Sun Aug 30 03:06:40.934841 2026] [security2:error] [pid 499145:tid 499373] [client 20.104.18.15:13588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/w.php"] [unique_id "apPkkFJNq1G5uRhTNnsnfgAAAGI"]
[Sun Aug 30 03:06:40.959197 2026] [security2:error] [pid 499145:tid 499360] [client 20.104.18.15:28612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/wp-ws68.php"] [unique_id "apPkkFJNq1G5uRhTNnsnhQAAAFU"]
[Sun Aug 30 03:06:40.981635 2026] [authz_core:error] [pid 499145:tid 499337] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_PH
[Sun Aug 30 03:06:40.982051 2026] [authz_core:error] [pid 499145:tid 499337] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_PH
[Sun Aug 30 03:06:41.000415 2026] [security2:error] [pid 499145:tid 499384] [client 20.104.18.15:23498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPkkFJNq1G5uRhTNnsnmQAAAG0"]
[Sun Aug 30 03:06:41.006095 2026] [security2:error] [pid 499145:tid 499369] [client 217.182.71.160:59000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.71.182.217.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pritchardislandhoa.com"] [uri "/wp-login.php"] [unique_id "apPkkFJNq1G5uRhTNnsnigAAAF4"]
[Sun Aug 30 03:06:41.012043 2026] [security2:error] [pid 499145:tid 499281] [client 20.197.61.180:14749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/upgrade-temp-backup/plugins/wp-blog-header.php"] [unique_id "apPkkVJNq1G5uRhTNnsnoQAAAAY"]
[Sun Aug 30 03:06:41.025314 2026] [security2:error] [pid 499145:tid 499400] [client 4.205.62.107:26785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/requirements.php"] [unique_id "apPkkVJNq1G5uRhTNnsnpQAAAH0"]
[Sun Aug 30 03:06:41.069795 2026] [security2:error] [pid 499145:tid 499364] [client 68.155.159.216:60876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/file88.php"] [unique_id "apPkkVJNq1G5uRhTNnsnsQAAAFk"]
[Sun Aug 30 03:06:41.069889 2026] [security2:error] [pid 499145:tid 499344] [client 20.48.251.3:44293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/autogooey.php"] [unique_id "apPkkVJNq1G5uRhTNnsnsgAAAEU"]
[Sun Aug 30 03:06:41.112963 2026] [security2:error] [pid 499145:tid 499380] [client 68.155.159.216:54039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/ans.php"] [unique_id "apPkkVJNq1G5uRhTNnsnvwAAAGk"]
[Sun Aug 30 03:06:41.142885 2026] [authz_core:error] [pid 499145:tid 499345] [client 216.73.216.128:39914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:41.143164 2026] [authz_core:error] [pid 499145:tid 499345] [client 216.73.216.128:39914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:41.178040 2026] [security2:error] [pid 499145:tid 499335] [client 4.205.62.107:52131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/saml.php"] [unique_id "apPkkVJNq1G5uRhTNnsn1QAAADw"]
[Sun Aug 30 03:06:41.183905 2026] [security2:error] [pid 499145:tid 499344] [client 20.104.50.220:6132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/cyr6l.php"] [unique_id "apPkkVJNq1G5uRhTNnsn2QAAAEU"]
[Sun Aug 30 03:06:41.267462 2026] [authz_core:error] [pid 499145:tid 499328] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fmemory_hotplug%2Fparameters
[Sun Aug 30 03:06:41.267753 2026] [authz_core:error] [pid 499145:tid 499328] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fmemory_hotplug%2Fparameters
[Sun Aug 30 03:06:41.331338 2026] [security2:error] [pid 499145:tid 499360] [client 20.104.18.15:43970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apPkkVJNq1G5uRhTNnsoAQAAAFU"]
[Sun Aug 30 03:06:41.361888 2026] [security2:error] [pid 499145:tid 499277] [client 20.104.50.220:42800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/loip2.php"] [unique_id "apPkkVJNq1G5uRhTNnsoCQAAAAI"]
[Sun Aug 30 03:06:41.444904 2026] [security2:error] [pid 499145:tid 499293] [client 20.104.50.220:59578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/autoload_classmap.php"] [unique_id "apPkkVJNq1G5uRhTNnsoJAAAABI"]
[Sun Aug 30 03:06:41.467746 2026] [security2:error] [pid 499145:tid 499351] [client 20.63.81.20:43357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkkVJNq1G5uRhTNnsoKQAAAEw"]
[Sun Aug 30 03:06:41.469667 2026] [security2:error] [pid 499145:tid 499367] [client 20.104.50.220:29149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/bismilah.php"] [unique_id "apPkkVJNq1G5uRhTNnsoKgAAAFw"]
[Sun Aug 30 03:06:41.472596 2026] [authz_core:error] [pid 499145:tid 499323] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NZ
[Sun Aug 30 03:06:41.472900 2026] [authz_core:error] [pid 499145:tid 499323] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NZ
[Sun Aug 30 03:06:41.519434 2026] [security2:error] [pid 499145:tid 499339] [client 4.205.62.107:64689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/kerang.php"] [unique_id "apPkkVJNq1G5uRhTNnsoMgAAAEA"]
[Sun Aug 30 03:06:41.562313 2026] [authz_core:error] [pid 499145:tid 499338] [client 66.249.66.35:46008] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:41.562607 2026] [authz_core:error] [pid 499145:tid 499338] [client 66.249.66.35:46008] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:41.568150 2026] [security2:error] [pid 499145:tid 499334] [client 4.205.62.107:60516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPkkVJNq1G5uRhTNnsoPwAAADs"]
[Sun Aug 30 03:06:41.688391 2026] [authz_core:error] [pid 499145:tid 499352] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:41.688678 2026] [authz_core:error] [pid 499145:tid 499352] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:41.716951 2026] [security2:error] [pid 499145:tid 499277] [client 20.63.81.20:43335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkkVJNq1G5uRhTNnsoVgAAAAI"]
[Sun Aug 30 03:06:41.721408 2026] [security2:error] [pid 499145:tid 499386] [client 20.197.61.180:14728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/upgrade-temp-backup/plugins/wp-mail.php"] [unique_id "apPkkVJNq1G5uRhTNnsoWAAAAG8"]
[Sun Aug 30 03:06:41.744581 2026] [security2:error] [pid 499145:tid 499304] [client 20.151.200.44:27318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/ssh3ll.php"] [unique_id "apPkkVJNq1G5uRhTNnsoXgAAAB0"]
[Sun Aug 30 03:06:41.767248 2026] [security2:error] [pid 499145:tid 499276] [client 68.155.159.216:56415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/sad/about.php"] [unique_id "apPkkVJNq1G5uRhTNnsoZQAAAAE"]
[Sun Aug 30 03:06:41.786424 2026] [authz_core:error] [pid 499145:tid 499319] [client 66.249.66.68:51679] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:41.786888 2026] [authz_core:error] [pid 499145:tid 499319] [client 66.249.66.68:51679] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:41.795934 2026] [security2:error] [pid 499145:tid 499297] [client 68.155.159.216:12325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPkkVJNq1G5uRhTNnsodwAAABY"]
[Sun Aug 30 03:06:41.808496 2026] [security2:error] [pid 499145:tid 499345] [client 20.48.251.3:6976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/ms-edit.php"] [unique_id "apPkkVJNq1G5uRhTNnsoggAAAEY"]
[Sun Aug 30 03:06:41.812288 2026] [security2:error] [pid 499145:tid 499279] [client 20.151.200.44:37831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/tf.php"] [unique_id "apPkkVJNq1G5uRhTNnsogwAAAAQ"]
[Sun Aug 30 03:06:41.825422 2026] [authz_core:error] [pid 499145:tid 499401] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdpkg
[Sun Aug 30 03:06:41.825705 2026] [authz_core:error] [pid 499145:tid 499401] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdpkg
[Sun Aug 30 03:06:41.836416 2026] [security2:error] [pid 499145:tid 499390] [client 20.104.50.220:17293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/asdf.php"] [unique_id "apPkkVJNq1G5uRhTNnsoiQAAAHM"]
[Sun Aug 30 03:06:41.843336 2026] [security2:error] [pid 499145:tid 499300] [client 20.63.81.20:43386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/ser.php"] [unique_id "apPkkVJNq1G5uRhTNnsojAAAABk"]
[Sun Aug 30 03:06:41.858231 2026] [security2:error] [pid 499145:tid 499336] [client 4.205.62.107:63950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/atex1.php"] [unique_id "apPkkVJNq1G5uRhTNnsokAAAAD0"]
[Sun Aug 30 03:06:41.867854 2026] [security2:error] [pid 499145:tid 499379] [client 68.155.159.216:61324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/lv.php"] [unique_id "apPkkVJNq1G5uRhTNnsokwAAAGg"]
[Sun Aug 30 03:06:41.882970 2026] [authz_core:error] [pid 499145:tid 499335] [client 216.73.216.128:39914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:41.883436 2026] [authz_core:error] [pid 499145:tid 499335] [client 216.73.216.128:39914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:41.891483 2026] [authz_core:error] [pid 499145:tid 499341] [client 66.249.66.78:38043] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:41.891914 2026] [authz_core:error] [pid 499145:tid 499341] [client 66.249.66.78:38043] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:41.905650 2026] [security2:error] [pid 499145:tid 499304] [client 20.104.50.220:27414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/panel/settings.php"] [unique_id "apPkkVJNq1G5uRhTNnsopgAAAB0"]
[Sun Aug 30 03:06:41.918825 2026] [security2:error] [pid 499145:tid 499371] [client 20.48.251.3:50029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/environment.php"] [unique_id "apPkkVJNq1G5uRhTNnsoqgAAAGA"]
[Sun Aug 30 03:06:41.925388 2026] [security2:error] [pid 499145:tid 499352] [client 4.205.62.107:2784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/nw.php"] [unique_id "apPkkVJNq1G5uRhTNnsorAAAAE0"]
[Sun Aug 30 03:06:41.937128 2026] [security2:error] [pid 499145:tid 499301] [client 20.104.50.220:31837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/gank.php.PhP"] [unique_id "apPkkVJNq1G5uRhTNnsotQAAABo"]
[Sun Aug 30 03:06:41.944585 2026] [security2:error] [pid 499145:tid 499345] [client 20.104.50.220:29352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/backd00r.php"] [unique_id "apPkkVJNq1G5uRhTNnsotwAAAEY"]
[Sun Aug 30 03:06:41.950057 2026] [security2:error] [pid 499145:tid 499369] [client 20.104.18.15:33704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/132.php"] [unique_id "apPkkVJNq1G5uRhTNnsovQAAAF4"]
[Sun Aug 30 03:06:41.951223 2026] [security2:error] [pid 499145:tid 499305] [client 4.205.62.107:18952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/php_info.php"] [unique_id "apPkkVJNq1G5uRhTNnsovgAAAB4"]
[Sun Aug 30 03:06:41.959193 2026] [security2:error] [pid 499145:tid 499347] [client 20.48.251.3:33324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/ammika.php"] [unique_id "apPkkVJNq1G5uRhTNnsovwAAAEg"]
[Sun Aug 30 03:06:41.970268 2026] [security2:error] [pid 499145:tid 499277] [client 4.205.62.107:62444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/edit.php"] [unique_id "apPkkVJNq1G5uRhTNnsoxgAAAAI"]
[Sun Aug 30 03:06:41.973031 2026] [security2:error] [pid 499145:tid 499342] [client 20.63.81.20:43359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/431.php"] [unique_id "apPkkVJNq1G5uRhTNnsoyAAAAEM"]
[Sun Aug 30 03:06:41.973783 2026] [security2:error] [pid 499145:tid 499389] [client 20.48.251.3:7053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/time.php"] [unique_id "apPkkVJNq1G5uRhTNnsoygAAAHI"]
[Sun Aug 30 03:06:41.977858 2026] [authz_core:error] [pid 499145:tid 499318] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_PH
[Sun Aug 30 03:06:41.978162 2026] [authz_core:error] [pid 499145:tid 499318] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_PH
[Sun Aug 30 03:06:41.979887 2026] [authz_core:error] [pid 499145:tid 499339] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:41.980541 2026] [authz_core:error] [pid 499145:tid 499339] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:41.986963 2026] [security2:error] [pid 499145:tid 499371] [client 4.205.62.107:5093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPkkVJNq1G5uRhTNnso0AAAAGA"]
[Sun Aug 30 03:06:42.027152 2026] [http2:info] [pid 499751:tid 499751] h2_workers: created with min=128 max=192 idle_ms=600000
[Sun Aug 30 03:06:42.027181 2026] [security2:error] [pid 499145:tid 499329] [client 168.119.123.75:10608] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.cravegoldcoast.com.au"] [uri "/wp-content/endurance-page-cache/_index.html"] [unique_id "apPkklJNq1G5uRhTNnso3gAAADY"], referer: http://www.cravegoldcoast.com.au/
[Sun Aug 30 03:06:42.056902 2026] [security2:error] [pid 499751:tid 499896] [client 20.104.50.220:46150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/sys.php"] [unique_id "apPkkjmmjdkPfMeJsKOttgAAA6U"]
[Sun Aug 30 03:06:42.057819 2026] [security2:error] [pid 499751:tid 499897] [client 20.104.50.220:32895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/image.php"] [unique_id "apPkkjmmjdkPfMeJsKOttwAAA6Y"]
[Sun Aug 30 03:06:42.064162 2026] [authz_core:error] [pid 499145:tid 499279] [client 216.73.216.128:39914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:42.064494 2026] [authz_core:error] [pid 499145:tid 499279] [client 216.73.216.128:39914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:42.071586 2026] [security2:error] [pid 499145:tid 499327] [client 4.205.62.107:32501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/debuggen.php"] [unique_id "apPkklJNq1G5uRhTNnso6wAAADQ"]
[Sun Aug 30 03:06:42.079124 2026] [security2:error] [pid 499145:tid 499278] [client 68.155.159.216:62300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/content.php"] [unique_id "apPkklJNq1G5uRhTNnso7gAAAAM"]
[Sun Aug 30 03:06:42.099917 2026] [security2:error] [pid 499751:tid 499905] [client 20.63.81.20:43373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/rxr.php"] [unique_id "apPkkjmmjdkPfMeJsKOtuwAAA64"]
[Sun Aug 30 03:06:42.103495 2026] [security2:error] [pid 499751:tid 499906] [client 20.104.18.15:28494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/mgrr.php"] [unique_id "apPkkjmmjdkPfMeJsKOtvAAAA68"]
[Sun Aug 30 03:06:42.113728 2026] [authz_core:error] [pid 499751:tid 499898] [client 66.249.66.76:56627] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:42.114069 2026] [authz_core:error] [pid 499751:tid 499898] [client 66.249.66.76:56627] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:42.117391 2026] [security2:error] [pid 499145:tid 499295] [client 20.104.18.15:13666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/x.php"] [unique_id "apPkklJNq1G5uRhTNnso8gAAABQ"]
[Sun Aug 30 03:06:42.135705 2026] [security2:error] [pid 499145:tid 499355] [client 20.104.49.130:59569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/mac.php"] [unique_id "apPkklJNq1G5uRhTNnso9AAAAFA"]
[Sun Aug 30 03:06:42.155819 2026] [security2:error] [pid 499145:tid 499281] [client 20.104.18.15:23519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/5PJcpMFsD8B.php"] [unique_id "apPkklJNq1G5uRhTNnso-wAAAAY"]
[Sun Aug 30 03:06:42.158967 2026] [security2:error] [pid 499145:tid 499394] [client 195.178.110.247:26590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marazul.com.pa"] [uri "/index.php"] [unique_id "apPkklJNq1G5uRhTNnso_QAAAHc"]
[Sun Aug 30 03:06:42.223191 2026] [security2:error] [pid 499145:tid 499340] [client 20.48.251.3:44372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/sdsa.php"] [unique_id "apPkklJNq1G5uRhTNnspCwAAAEE"]
[Sun Aug 30 03:06:42.231668 2026] [security2:error] [pid 499751:tid 499948] [client 20.63.81.20:43377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/csst.php"] [unique_id "apPkkjmmjdkPfMeJsKOt0AAAA9g"]
[Sun Aug 30 03:06:42.320766 2026] [security2:error] [pid 499751:tid 499976] [client 4.205.62.107:58154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/params.php"] [unique_id "apPkkjmmjdkPfMeJsKOt3AAAA_Q"]
[Sun Aug 30 03:06:42.321145 2026] [security2:error] [pid 499145:tid 499371] [client 20.104.50.220:6119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/51whn.php"] [unique_id "apPkklJNq1G5uRhTNnspIAAAAGA"]
[Sun Aug 30 03:06:42.329406 2026] [security2:error] [pid 499145:tid 499320] [client 195.178.110.247:29398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marazul.com.pa"] [uri "/index.php"] [unique_id "apPkklJNq1G5uRhTNnspIgAAAC0"]
[Sun Aug 30 03:06:42.335616 2026] [authz_core:error] [pid 499145:tid 499302] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:42.336086 2026] [authz_core:error] [pid 499145:tid 499302] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:42.341822 2026] [authz_core:error] [pid 499145:tid 499392] [client 66.249.66.64:46826] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:42.342092 2026] [authz_core:error] [pid 499145:tid 499392] [client 66.249.66.64:46826] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:42.360273 2026] [security2:error] [pid 499751:tid 499995] [client 68.155.159.216:60888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/NewFile.php/"] [unique_id "apPkkjmmjdkPfMeJsKOt5QAABAc"]
[Sun Aug 30 03:06:42.362480 2026] [security2:error] [pid 499751:tid 499996] [client 20.63.81.20:43365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp-includes/blocks/query-title/footer.php"] [unique_id "apPkkjmmjdkPfMeJsKOt5gAABAg"]
[Sun Aug 30 03:06:42.370087 2026] [security2:error] [pid 499145:tid 499311] [client 4.205.62.107:52127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/aws_settings.php"] [unique_id "apPkklJNq1G5uRhTNnspKgAAACQ"]
[Sun Aug 30 03:06:42.429560 2026] [security2:error] [pid 499145:tid 499289] [client 68.155.159.216:59908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/worksec.php"] [unique_id "apPkklJNq1G5uRhTNnspOwAAAA4"]
[Sun Aug 30 03:06:42.435233 2026] [security2:error] [pid 499751:tid 499941] [client 20.197.61.180:3323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/upgrade-temp-backup/themes/admin.php"] [unique_id "apPkkjmmjdkPfMeJsKOt9gAAA9E"]
[Sun Aug 30 03:06:42.445010 2026] [security2:error] [pid 499751:tid 499919] [client 4.205.62.107:27292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/var/www/wallet/index.php"] [unique_id "apPkkjmmjdkPfMeJsKOt-gAAA7s"]
[Sun Aug 30 03:06:42.481227 2026] [authz_core:error] [pid 499145:tid 499337] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NZ
[Sun Aug 30 03:06:42.481743 2026] [authz_core:error] [pid 499145:tid 499337] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NZ
[Sun Aug 30 03:06:42.485447 2026] [authz_core:error] [pid 499751:tid 499937] [client 66.249.66.200:47210] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:42.485876 2026] [authz_core:error] [pid 499751:tid 499937] [client 66.249.66.200:47210] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:42.510717 2026] [security2:error] [pid 499145:tid 499318] [client 20.63.81.20:43356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp-content/uploads/indoex.php"] [unique_id "apPkklJNq1G5uRhTNnspTQAAACs"]
[Sun Aug 30 03:06:42.529911 2026] [security2:error] [pid 499145:tid 499304] [client 20.104.50.220:51575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/json.php"] [unique_id "apPkklJNq1G5uRhTNnspUgAAAB0"]
[Sun Aug 30 03:06:42.530406 2026] [security2:error] [pid 499751:tid 499949] [client 20.104.18.15:43936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/wp-aothait.php"] [unique_id "apPkkjmmjdkPfMeJsKOuCQAAA9k"]
[Sun Aug 30 03:06:42.535995 2026] [authz_core:error] [pid 499751:tid 499936] [client 66.249.66.75:45378] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:42.536313 2026] [authz_core:error] [pid 499751:tid 499936] [client 66.249.66.75:45378] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:42.595014 2026] [security2:error] [pid 499751:tid 499963] [client 20.104.50.220:61482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/12.php"] [unique_id "apPkkjmmjdkPfMeJsKOuDwAAA-c"]
[Sun Aug 30 03:06:42.624091 2026] [security2:error] [pid 499145:tid 499366] [client 20.104.50.220:62833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/.dha.php"] [unique_id "apPkklJNq1G5uRhTNnspXwAAAFs"]
[Sun Aug 30 03:06:42.637164 2026] [security2:error] [pid 499751:tid 499977] [client 20.63.81.20:43265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPkkjmmjdkPfMeJsKOuEgAAA_U"]
[Sun Aug 30 03:06:42.662500 2026] [security2:error] [pid 499145:tid 499319] [client 4.205.62.107:64475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/rem.php"] [unique_id "apPkklJNq1G5uRhTNnspYgAAACw"]
[Sun Aug 30 03:06:42.677588 2026] [authz_core:error] [pid 499145:tid 499330] [client 66.249.66.43:58757] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:42.677869 2026] [authz_core:error] [pid 499145:tid 499330] [client 66.249.66.43:58757] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:42.704662 2026] [security2:error] [pid 499751:tid 499990] [client 4.205.62.107:60551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/agg.php"] [unique_id "apPkkjmmjdkPfMeJsKOuFwAABAI"]
[Sun Aug 30 03:06:42.764036 2026] [security2:error] [pid 499145:tid 499350] [client 20.63.81.20:43285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/haxor.php"] [unique_id "apPkklJNq1G5uRhTNnspcwAAAEs"]
[Sun Aug 30 03:06:42.781826 2026] [authz_core:error] [pid 499145:tid 499314] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:42.782184 2026] [authz_core:error] [pid 499145:tid 499314] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:42.890981 2026] [security2:error] [pid 499751:tid 499931] [client 68.155.159.216:56420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/admin.php"] [unique_id "apPkkjmmjdkPfMeJsKOuLwAAA8c"]
[Sun Aug 30 03:06:42.891484 2026] [security2:error] [pid 499145:tid 499374] [client 20.63.81.20:43344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/google.php"] [unique_id "apPkklJNq1G5uRhTNnspiAAAAGM"]
[Sun Aug 30 03:06:42.895959 2026] [security2:error] [pid 499145:tid 499289] [client 20.104.49.130:63292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/ccc.php"] [unique_id "apPkklJNq1G5uRhTNnspiQAAAA4"]
[Sun Aug 30 03:06:42.897827 2026] [security2:error] [pid 499145:tid 499316] [client 68.155.159.216:12339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/goat.php"] [unique_id "apPkklJNq1G5uRhTNnspiwAAACk"]
[Sun Aug 30 03:06:42.986846 2026] [security2:error] [pid 499751:tid 499926] [client 20.104.50.220:17332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/red.php"] [unique_id "apPkkjmmjdkPfMeJsKOuNgAAA8I"]
[Sun Aug 30 03:06:43.006491 2026] [security2:error] [pid 499145:tid 499353] [client 4.205.62.107:63972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/aws_sdk_settings.php"] [unique_id "apPkk1JNq1G5uRhTNnspwgAAAE4"]
[Sun Aug 30 03:06:43.014711 2026] [authz_core:error] [pid 499145:tid 499304] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NZ
[Sun Aug 30 03:06:43.015005 2026] [authz_core:error] [pid 499145:tid 499304] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NZ
[Sun Aug 30 03:06:43.019281 2026] [security2:error] [pid 499145:tid 499287] [client 20.63.81.20:43264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "apPkk1JNq1G5uRhTNnspyAAAAAw"]
[Sun Aug 30 03:06:43.043843 2026] [security2:error] [pid 499751:tid 499953] [client 20.104.50.220:27121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/uploader.php"] [unique_id "apPkkzmmjdkPfMeJsKOuOgAAA90"]
[Sun Aug 30 03:06:43.057184 2026] [security2:error] [pid 499145:tid 499372] [client 20.48.251.3:12060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/aws_secret_config.php"] [unique_id "apPkk1JNq1G5uRhTNnsp2wAAAGE"]
[Sun Aug 30 03:06:43.062846 2026] [security2:error] [pid 499145:tid 499379] [client 4.205.62.107:2790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/product.php"] [unique_id "apPkk1JNq1G5uRhTNnsp4QAAAGg"]
[Sun Aug 30 03:06:43.071752 2026] [security2:error] [pid 499145:tid 499291] [client 20.104.50.220:31919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/gh.php"] [unique_id "apPkk1JNq1G5uRhTNnsp5QAAABA"]
[Sun Aug 30 03:06:43.083507 2026] [security2:error] [pid 499145:tid 499307] [client 20.104.50.220:62824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/backdoor.php"] [unique_id "apPkk1JNq1G5uRhTNnsp7AAAACA"]
[Sun Aug 30 03:06:43.094206 2026] [security2:error] [pid 499145:tid 499338] [client 4.205.62.107:18773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/session.php"] [unique_id "apPkk1JNq1G5uRhTNnsp8QAAAD8"]
[Sun Aug 30 03:06:43.096538 2026] [security2:error] [pid 499751:tid 499968] [client 20.151.200.44:37700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/update/da222.php"] [unique_id "apPkkzmmjdkPfMeJsKOuQAAAA-w"]
[Sun Aug 30 03:06:43.100918 2026] [security2:error] [pid 499751:tid 499973] [client 20.104.18.15:33717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/v22.php"] [unique_id "apPkkzmmjdkPfMeJsKOuQwAAA_E"]
[Sun Aug 30 03:06:43.102562 2026] [security2:error] [pid 499145:tid 499381] [client 20.48.251.3:56350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/broadcasting.php"] [unique_id "apPkk1JNq1G5uRhTNnsp9QAAAGo"]
[Sun Aug 30 03:06:43.114451 2026] [security2:error] [pid 499145:tid 499378] [client 4.205.62.107:22966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/8.php"] [unique_id "apPkk1JNq1G5uRhTNnsp9wAAAGc"]
[Sun Aug 30 03:06:43.124674 2026] [security2:error] [pid 499751:tid 499964] [client 4.205.62.107:4666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPkkzmmjdkPfMeJsKOuRQAAA-g"]
[Sun Aug 30 03:06:43.124703 2026] [security2:error] [pid 499751:tid 499978] [client 20.48.251.3:6483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/doc.php"] [unique_id "apPkkzmmjdkPfMeJsKOuRAAAA_Y"]
[Sun Aug 30 03:06:43.153304 2026] [security2:error] [pid 499145:tid 499323] [client 20.63.81.20:43362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/robots.php"] [unique_id "apPkk1JNq1G5uRhTNnsqBgAAADA"]
[Sun Aug 30 03:06:43.160921 2026] [security2:error] [pid 499145:tid 499337] [client 20.197.61.180:3295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/upgrade-temp-backup/themes/login.php"] [unique_id "apPkk1JNq1G5uRhTNnsqDgAAAD4"]
[Sun Aug 30 03:06:43.181769 2026] [authz_core:error] [pid 499751:tid 499965] [client 66.249.66.66:46790] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:43.182085 2026] [authz_core:error] [pid 499751:tid 499965] [client 66.249.66.66:46790] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:43.198630 2026] [security2:error] [pid 499145:tid 499347] [client 20.104.50.220:47099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/tes.php"] [unique_id "apPkk1JNq1G5uRhTNnsqIwAAAEg"]
[Sun Aug 30 03:06:43.198633 2026] [security2:error] [pid 499751:tid 500008] [client 20.104.50.220:32865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/images.php"] [unique_id "apPkkzmmjdkPfMeJsKOuUgAABBQ"]
[Sun Aug 30 03:06:43.202714 2026] [security2:error] [pid 499751:tid 500005] [client 68.155.159.216:63505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPkkzmmjdkPfMeJsKOuUwAABBE"]
[Sun Aug 30 03:06:43.210166 2026] [security2:error] [pid 499751:tid 500016] [client 195.178.110.247:63352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ermes-it-com.webnet-hosting4.com"] [uri "/index.php"] [unique_id "apPkkzmmjdkPfMeJsKOuVQAABBw"]
[Sun Aug 30 03:06:43.239531 2026] [security2:error] [pid 499145:tid 499314] [client 20.104.18.15:28615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/55.php"] [unique_id "apPkk1JNq1G5uRhTNnsqMQAAACc"]
[Sun Aug 30 03:06:43.280732 2026] [security2:error] [pid 499145:tid 499289] [client 20.104.18.15:13668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/ssla.php"] [unique_id "apPkk1JNq1G5uRhTNnsqQAAAAA4"]
[Sun Aug 30 03:06:43.280755 2026] [security2:error] [pid 499145:tid 499358] [client 20.63.81.20:43350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp-content/plugins/ccx/index.php"] [unique_id "apPkk1JNq1G5uRhTNnsqPwAAAFM"]
[Sun Aug 30 03:06:43.308958 2026] [authz_core:error] [pid 499145:tid 499301] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:43.309287 2026] [authz_core:error] [pid 499145:tid 499301] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:43.312404 2026] [security2:error] [pid 499145:tid 499371] [client 20.104.18.15:23524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPkk1JNq1G5uRhTNnsqSAAAAGA"]
[Sun Aug 30 03:06:43.353985 2026] [security2:error] [pid 499145:tid 499323] [client 20.104.49.130:45726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/memberfuns.php"] [unique_id "apPkk1JNq1G5uRhTNnsqWQAAADA"]
[Sun Aug 30 03:06:43.360898 2026] [security2:error] [pid 499145:tid 499382] [client 20.48.251.3:44290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/sale.php"] [unique_id "apPkk1JNq1G5uRhTNnsqXAAAAGs"]
[Sun Aug 30 03:06:43.375633 2026] [security2:error] [pid 499751:tid 500015] [client 195.178.110.247:6972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ermes-it-com.webnet-hosting4.com"] [uri "/index.php"] [unique_id "apPkkzmmjdkPfMeJsKOuawAABBs"]
[Sun Aug 30 03:06:43.380438 2026] [security2:error] [pid 499145:tid 499349] [client 20.151.200.44:55621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/attack.php"] [unique_id "apPkk1JNq1G5uRhTNnsqaAAAAEo"]
[Sun Aug 30 03:06:43.401137 2026] [security2:error] [pid 499145:tid 499370] [client 4.205.62.107:32481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/pouhg.php"] [unique_id "apPkk1JNq1G5uRhTNnsqdgAAAF8"]
[Sun Aug 30 03:06:43.410267 2026] [security2:error] [pid 499145:tid 499291] [client 20.63.81.20:43279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp-admin/css/colors/maro.php"] [unique_id "apPkk1JNq1G5uRhTNnsqegAAABA"]
[Sun Aug 30 03:06:43.454623 2026] [security2:error] [pid 499751:tid 499976] [client 20.104.50.220:6140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/alfa-rex.php7"] [unique_id "apPkkzmmjdkPfMeJsKOudQAAA_Q"]
[Sun Aug 30 03:06:43.464171 2026] [security2:error] [pid 499145:tid 499344] [client 68.155.159.216:65448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apPkk1JNq1G5uRhTNnsqjgAAAEU"]
[Sun Aug 30 03:06:43.468913 2026] [security2:error] [pid 499145:tid 499393] [client 20.104.49.130:63561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/new.php"] [unique_id "apPkk1JNq1G5uRhTNnsqkwAAAHY"]
[Sun Aug 30 03:06:43.472057 2026] [authz_core:error] [pid 499145:tid 499290] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NZ
[Sun Aug 30 03:06:43.472383 2026] [authz_core:error] [pid 499145:tid 499290] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NZ
[Sun Aug 30 03:06:43.482034 2026] [security2:error] [pid 499751:tid 499984] [client 4.205.62.107:65286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/gjm.php"] [unique_id "apPkkzmmjdkPfMeJsKOuewAAA_w"]
[Sun Aug 30 03:06:43.512598 2026] [authz_core:error] [pid 499145:tid 499312] [client 66.249.66.77:43085] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:43.512923 2026] [authz_core:error] [pid 499145:tid 499312] [client 66.249.66.77:43085] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:43.520298 2026] [security2:error] [pid 499145:tid 499360] [client 68.155.159.216:60886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/dropdown.php"] [unique_id "apPkk1JNq1G5uRhTNnsqrAAAAFU"]
[Sun Aug 30 03:06:43.520552 2026] [authz_core:error] [pid 499145:tid 499339] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:43.521068 2026] [authz_core:error] [pid 499145:tid 499339] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:43.539394 2026] [security2:error] [pid 499145:tid 499304] [client 20.63.81.20:43369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp-admin/css/colors/coffee/marijuana.php"] [unique_id "apPkk1JNq1G5uRhTNnsqtgAAAB0"]
[Sun Aug 30 03:06:43.542495 2026] [security2:error] [pid 499145:tid 499338] [client 4.205.62.107:51735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/wp-konfig.backup.php"] [unique_id "apPkk1JNq1G5uRhTNnsqtwAAAD8"]
[Sun Aug 30 03:06:43.616306 2026] [security2:error] [pid 499145:tid 499325] [client 20.151.200.44:37861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/qi.php"] [unique_id "apPkk1JNq1G5uRhTNnsq0wAAADI"]
[Sun Aug 30 03:06:43.660685 2026] [security2:error] [pid 499751:tid 500018] [client 20.151.200.44:47075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/wp-access.php"] [unique_id "apPkkzmmjdkPfMeJsKOuhQAABB4"]
[Sun Aug 30 03:06:43.666892 2026] [security2:error] [pid 499751:tid 500021] [client 20.63.81.20:43345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp-admin/css/colors/coffee/mari.php"] [unique_id "apPkkzmmjdkPfMeJsKOuhwAABCE"]
[Sun Aug 30 03:06:43.680545 2026] [security2:error] [pid 499751:tid 500013] [client 20.104.18.15:43939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/wp-includes/index.php"] [unique_id "apPkkzmmjdkPfMeJsKOuigAABBk"]
[Sun Aug 30 03:06:43.692702 2026] [security2:error] [pid 499145:tid 499340] [client 20.104.50.220:51623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/java.php"] [unique_id "apPkk1JNq1G5uRhTNnsq3gAAAEE"]
[Sun Aug 30 03:06:43.702119 2026] [authz_core:error] [pid 499145:tid 499304] [client 66.249.66.196:40507] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:43.702521 2026] [authz_core:error] [pid 499145:tid 499304] [client 66.249.66.196:40507] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:43.703893 2026] [authz_core:error] [pid 499145:tid 499289] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:43.704313 2026] [authz_core:error] [pid 499145:tid 499289] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:43.767736 2026] [security2:error] [pid 499145:tid 499341] [client 20.104.50.220:29182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/cpanel.php"] [unique_id "apPkk1JNq1G5uRhTNnsq6wAAAEI"]
[Sun Aug 30 03:06:43.780108 2026] [security2:error] [pid 499751:tid 499923] [client 20.48.251.3:7037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/sys.php"] [unique_id "apPkkzmmjdkPfMeJsKOukwAAA78"]
[Sun Aug 30 03:06:43.794156 2026] [security2:error] [pid 499751:tid 499925] [client 20.63.81.20:43376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp-includes/images/crystal/option.php"] [unique_id "apPkkzmmjdkPfMeJsKOulgAAA8E"]
[Sun Aug 30 03:06:43.794295 2026] [security2:error] [pid 499751:tid 499934] [client 20.104.50.220:61457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wikiindex.php"] [unique_id "apPkkzmmjdkPfMeJsKOulwAAA8o"]
[Sun Aug 30 03:06:43.804063 2026] [authz_core:error] [pid 499145:tid 499396] [client 66.249.66.74:47189] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:43.804350 2026] [authz_core:error] [pid 499145:tid 499396] [client 66.249.66.74:47189] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:43.807400 2026] [security2:error] [pid 499751:tid 499935] [client 4.205.62.107:61819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/min.php"] [unique_id "apPkkzmmjdkPfMeJsKOumgAAA8s"]
[Sun Aug 30 03:06:43.815194 2026] [authz_core:error] [pid 499751:tid 499928] [client 66.249.66.67:52181] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:43.815508 2026] [authz_core:error] [pid 499751:tid 499928] [client 66.249.66.67:52181] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:43.815802 2026] [authz_core:error] [pid 499145:tid 499335] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Ffile
[Sun Aug 30 03:06:43.816243 2026] [authz_core:error] [pid 499145:tid 499335] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Ffile
[Sun Aug 30 03:06:43.838224 2026] [security2:error] [pid 499145:tid 499311] [client 4.205.62.107:63787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/requirements.php"] [unique_id "apPkk1JNq1G5uRhTNnsrEAAAACQ"]
[Sun Aug 30 03:06:43.879050 2026] [security2:error] [pid 499751:tid 500007] [client 20.197.61.180:14735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/upgrade-temp-backup/themes/test.php"] [unique_id "apPkkzmmjdkPfMeJsKOunwAABBM"]
[Sun Aug 30 03:06:43.889871 2026] [authz_core:error] [pid 499145:tid 499399] [client 216.73.216.128:39914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:43.890324 2026] [authz_core:error] [pid 499145:tid 499399] [client 216.73.216.128:39914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:43.923158 2026] [security2:error] [pid 499145:tid 499287] [client 20.63.81.20:43296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp-includes/pomo/xxx.php"] [unique_id "apPkk1JNq1G5uRhTNnsrHgAAAAw"]
[Sun Aug 30 03:06:43.968872 2026] [authz_core:error] [pid 499145:tid 499292] [client 66.249.66.34:63202] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:43.969153 2026] [authz_core:error] [pid 499145:tid 499292] [client 66.249.66.34:63202] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:43.971852 2026] [authz_core:error] [pid 499145:tid 499362] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NZ
[Sun Aug 30 03:06:43.972302 2026] [authz_core:error] [pid 499145:tid 499362] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NZ
[Sun Aug 30 03:06:43.979148 2026] [security2:error] [pid 499145:tid 499282] [client 20.151.200.44:47305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/tf.php"] [unique_id "apPkk1JNq1G5uRhTNnsrOQAAAAc"]
[Sun Aug 30 03:06:44.000352 2026] [security2:error] [pid 499145:tid 499280] [client 4.205.62.107:26760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/124.php"] [unique_id "apPkk1JNq1G5uRhTNnsrRwAAAAU"]
[Sun Aug 30 03:06:44.000449 2026] [security2:error] [pid 499145:tid 499302] [client 195.178.110.247:63360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ermes-it-net.webnet-hosting4.com"] [uri "/index.php"] [unique_id "apPkk1JNq1G5uRhTNnsrSAAAABs"]
[Sun Aug 30 03:06:44.002577 2026] [security2:error] [pid 499145:tid 499369] [client 68.155.159.216:56345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-admin/admin.php"] [unique_id "apPklFJNq1G5uRhTNnsrSQAAAF4"]
[Sun Aug 30 03:06:44.051686 2026] [security2:error] [pid 499145:tid 499311] [client 20.63.81.20:43381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/650.php"] [unique_id "apPklFJNq1G5uRhTNnsrZQAAACQ"]
[Sun Aug 30 03:06:44.055352 2026] [security2:error] [pid 499145:tid 499344] [client 68.155.159.216:65485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apPklFJNq1G5uRhTNnsrZgAAAEU"]
[Sun Aug 30 03:06:44.146998 2026] [security2:error] [pid 499145:tid 499287] [client 4.205.62.107:63971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/setup-config.php"] [unique_id "apPklFJNq1G5uRhTNnsrkgAAAAw"]
[Sun Aug 30 03:06:44.159203 2026] [security2:error] [pid 499145:tid 499370] [client 195.178.110.247:6974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ermes-it-net.webnet-hosting4.com"] [uri "/index.php"] [unique_id "apPklFJNq1G5uRhTNnsrmQAAAF8"]
[Sun Aug 30 03:06:44.159446 2026] [authz_core:error] [pid 499145:tid 499383] [client 216.73.216.128:39914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:44.159907 2026] [authz_core:error] [pid 499145:tid 499383] [client 216.73.216.128:39914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:44.179524 2026] [security2:error] [pid 499145:tid 499380] [client 20.104.50.220:27132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/page-footer.php"] [unique_id "apPklFJNq1G5uRhTNnsrrQAAAGk"]
[Sun Aug 30 03:06:44.181925 2026] [security2:error] [pid 499145:tid 499306] [client 20.63.81.20:43286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/nakrip.php"] [unique_id "apPklFJNq1G5uRhTNnsrrgAAAB8"]
[Sun Aug 30 03:06:44.181994 2026] [security2:error] [pid 499751:tid 499895] [client 54.39.18.217:61039] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "54.39.18.217" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPklDmmjdkPfMeJsKOu1wAAA6Q"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:06:44.182083 2026] [security2:error] [pid 499751:tid 499895] [client 54.39.18.217:61039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPklDmmjdkPfMeJsKOu1wAAA6Q"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:06:44.196464 2026] [security2:error] [pid 499751:tid 500016] [client 20.48.251.3:12087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/snq.php"] [unique_id "apPklDmmjdkPfMeJsKOu3QAABBw"]
[Sun Aug 30 03:06:44.202434 2026] [security2:error] [pid 499145:tid 499351] [client 4.205.62.107:2354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/fun.php"] [unique_id "apPklFJNq1G5uRhTNnsrtQAAAEw"]
[Sun Aug 30 03:06:44.203992 2026] [security2:error] [pid 499751:tid 499978] [client 20.104.50.220:16730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "apPklDmmjdkPfMeJsKOu3wAAA_Y"]
[Sun Aug 30 03:06:44.211957 2026] [security2:error] [pid 499145:tid 499328] [client 20.104.50.220:31808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/id.php"] [unique_id "apPklFJNq1G5uRhTNnsruwAAADU"]
[Sun Aug 30 03:06:44.238943 2026] [security2:error] [pid 499145:tid 499325] [client 20.104.18.15:33768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/wp-activate.php"] [unique_id "apPklFJNq1G5uRhTNnsrxgAAADI"]
[Sun Aug 30 03:06:44.240384 2026] [security2:error] [pid 499145:tid 499315] [client 4.205.62.107:18948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/h.php"] [unique_id "apPklFJNq1G5uRhTNnsryAAAACg"]
[Sun Aug 30 03:06:44.242895 2026] [security2:error] [pid 499145:tid 499280] [client 20.104.50.220:62804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/andela.php"] [unique_id "apPklFJNq1G5uRhTNnsrygAAAAU"]
[Sun Aug 30 03:06:44.243270 2026] [security2:error] [pid 499145:tid 499388] [client 20.48.251.3:13388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/aws_config.php"] [unique_id "apPklFJNq1G5uRhTNnsrywAAAHE"]
[Sun Aug 30 03:06:44.260307 2026] [security2:error] [pid 499145:tid 499342] [client 4.205.62.107:62293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/thui.php"] [unique_id "apPklFJNq1G5uRhTNnsr2AAAAEM"]
[Sun Aug 30 03:06:44.263600 2026] [security2:error] [pid 499145:tid 499307] [client 4.205.62.107:4575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/agg.php"] [unique_id "apPklFJNq1G5uRhTNnsr2gAAACA"]
[Sun Aug 30 03:06:44.277772 2026] [security2:error] [pid 499751:tid 499998] [client 20.48.251.3:6978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/classsmtps.php"] [unique_id "apPklDmmjdkPfMeJsKOu6AAABAo"]
[Sun Aug 30 03:06:44.312869 2026] [security2:error] [pid 499751:tid 499991] [client 20.63.81.20:43277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp-includes/interactivity-api/flower.php"] [unique_id "apPklDmmjdkPfMeJsKOu7AAABAM"]
[Sun Aug 30 03:06:44.317315 2026] [authz_core:error] [pid 499145:tid 499350] [client 66.249.66.68:51679] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:44.317577 2026] [authz_core:error] [pid 499145:tid 499350] [client 66.249.66.68:51679] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:44.321076 2026] [authz_core:error] [pid 499145:tid 499388] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:44.321338 2026] [authz_core:error] [pid 499145:tid 499388] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:44.326320 2026] [security2:error] [pid 499145:tid 499338] [client 68.155.159.216:62305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/goat.php"] [unique_id "apPklFJNq1G5uRhTNnsr-QAAAD8"]
[Sun Aug 30 03:06:44.338017 2026] [authz_core:error] [pid 499145:tid 499294] [client 216.73.216.128:39914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:44.338306 2026] [authz_core:error] [pid 499145:tid 499294] [client 216.73.216.128:39914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:44.340574 2026] [security2:error] [pid 499145:tid 499374] [client 20.104.50.220:33204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/htdocs.php"] [unique_id "apPklFJNq1G5uRhTNnssBAAAAGM"]
[Sun Aug 30 03:06:44.345078 2026] [security2:error] [pid 499145:tid 499376] [client 20.104.50.220:46611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/teslav.php"] [unique_id "apPklFJNq1G5uRhTNnssBgAAAGU"]
[Sun Aug 30 03:06:44.375584 2026] [security2:error] [pid 499145:tid 499370] [client 20.104.18.15:28556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/yj09.php"] [unique_id "apPklFJNq1G5uRhTNnssFgAAAF8"]
[Sun Aug 30 03:06:44.402421 2026] [authz_core:error] [pid 499751:tid 499993] [client 66.249.66.71:57772] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:44.402681 2026] [authz_core:error] [pid 499751:tid 499993] [client 66.249.66.71:57772] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:44.430061 2026] [authz_core:error] [pid 499145:tid 499290] [client 216.73.216.128:45526] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:44.430344 2026] [authz_core:error] [pid 499145:tid 499290] [client 216.73.216.128:45526] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:44.441260 2026] [security2:error] [pid 499145:tid 499278] [client 20.63.81.20:43341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/xcc.php"] [unique_id "apPklFJNq1G5uRhTNnssOwAAAAM"]
[Sun Aug 30 03:06:44.445844 2026] [security2:error] [pid 499145:tid 499299] [client 20.104.18.15:13646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apPklFJNq1G5uRhTNnssPwAAABg"]
[Sun Aug 30 03:06:44.449610 2026] [security2:error] [pid 499751:tid 500020] [client 20.104.18.15:23490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/wsd.php"] [unique_id "apPklDmmjdkPfMeJsKOu_QAABCA"]
[Sun Aug 30 03:06:44.477587 2026] [security2:error] [pid 499751:tid 499979] [client 20.104.50.220:32895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/hello.php"] [unique_id "apPklDmmjdkPfMeJsKOvBAAAA_c"]
[Sun Aug 30 03:06:44.495586 2026] [authz_core:error] [pid 499145:tid 499370] [client 66.249.66.69:59817] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:44.495864 2026] [authz_core:error] [pid 499145:tid 499370] [client 66.249.66.69:59817] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:44.499746 2026] [security2:error] [pid 499145:tid 499394] [client 54.39.18.217:61051] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "54.39.18.217" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPklFJNq1G5uRhTNnssWAAAAHc"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:06:44.499841 2026] [security2:error] [pid 499145:tid 499394] [client 54.39.18.217:61051] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPklFJNq1G5uRhTNnssWAAAAHc"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:06:44.499933 2026] [security2:error] [pid 499145:tid 499362] [client 20.151.200.44:27591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/motu.php"] [unique_id "apPklFJNq1G5uRhTNnssWQAAAFc"]
[Sun Aug 30 03:06:44.514019 2026] [authz_core:error] [pid 499145:tid 499318] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NZ
[Sun Aug 30 03:06:44.514505 2026] [authz_core:error] [pid 499145:tid 499318] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NZ
[Sun Aug 30 03:06:44.519805 2026] [authz_core:error] [pid 499145:tid 499343] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:44.520069 2026] [authz_core:error] [pid 499145:tid 499343] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:44.531366 2026] [security2:error] [pid 499145:tid 499366] [client 20.48.251.3:5061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/wp-class.php"] [unique_id "apPklFJNq1G5uRhTNnssbAAAAFs"]
[Sun Aug 30 03:06:44.567356 2026] [security2:error] [pid 499751:tid 500014] [client 20.63.81.20:43268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp-includes/Text/Diff/Engine/aaa.php"] [unique_id "apPklDmmjdkPfMeJsKOvDgAABBo"]
[Sun Aug 30 03:06:44.588985 2026] [security2:error] [pid 499751:tid 500005] [client 20.197.61.180:21071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/upgrade-temp-backup/themes/wp-links-opml.php"] [unique_id "apPklDmmjdkPfMeJsKOvFQAABBE"]
[Sun Aug 30 03:06:44.598415 2026] [security2:error] [pid 499751:tid 499980] [client 20.104.50.220:5471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/alfanew.php7"] [unique_id "apPklDmmjdkPfMeJsKOvGAAAA_g"]
[Sun Aug 30 03:06:44.615731 2026] [authz_core:error] [pid 499145:tid 499314] [client 216.73.216.128:39914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:44.616204 2026] [authz_core:error] [pid 499145:tid 499314] [client 216.73.216.128:39914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:44.651328 2026] [security2:error] [pid 499751:tid 499998] [client 4.205.62.107:65358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/configuration.php"] [unique_id "apPklDmmjdkPfMeJsKOvHQAABAo"]
[Sun Aug 30 03:06:44.686380 2026] [security2:error] [pid 499751:tid 500002] [client 4.205.62.107:51740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/packed.php"] [unique_id "apPklDmmjdkPfMeJsKOvHgAABA4"]
[Sun Aug 30 03:06:44.694447 2026] [security2:error] [pid 499751:tid 499952] [client 20.63.81.20:43330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp-includes/style-engine/gecko-new.php"] [unique_id "apPklDmmjdkPfMeJsKOvIAAAA9w"]
[Sun Aug 30 03:06:44.767986 2026] [authz_core:error] [pid 499145:tid 499388] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdpkg
[Sun Aug 30 03:06:44.768260 2026] [authz_core:error] [pid 499145:tid 499388] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdpkg
[Sun Aug 30 03:06:44.785459 2026] [security2:error] [pid 499751:tid 500005] [client 68.155.159.216:62069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/.well-known/index.php"] [unique_id "apPklDmmjdkPfMeJsKOvSgAABBE"]
[Sun Aug 30 03:06:44.806491 2026] [security2:error] [pid 499751:tid 499985] [client 20.151.200.44:47373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/update/da222.php"] [unique_id "apPklDmmjdkPfMeJsKOvVQAAA_0"]
[Sun Aug 30 03:06:44.818513 2026] [security2:error] [pid 499145:tid 499330] [client 20.104.18.15:43952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/file31.php"] [unique_id "apPklFJNq1G5uRhTNnsssQAAADc"]
[Sun Aug 30 03:06:44.820026 2026] [security2:error] [pid 499145:tid 499347] [client 20.63.81.20:43388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp-settings.php"] [unique_id "apPklFJNq1G5uRhTNnsssgAAAEg"]
[Sun Aug 30 03:06:44.820523 2026] [security2:error] [pid 499751:tid 500019] [client 4.205.62.107:32472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/phpversion.php"] [unique_id "apPklDmmjdkPfMeJsKOvWQAABB8"]
[Sun Aug 30 03:06:44.855638 2026] [security2:error] [pid 499145:tid 499276] [client 20.104.50.220:42025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/kntl.php"] [unique_id "apPklFJNq1G5uRhTNnssuQAAAAE"]
[Sun Aug 30 03:06:44.886850 2026] [authz_core:error] [pid 499145:tid 499318] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:44.887250 2026] [authz_core:error] [pid 499145:tid 499318] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:44.910852 2026] [security2:error] [pid 499145:tid 499285] [client 20.104.50.220:29137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/devill.php"] [unique_id "apPklFJNq1G5uRhTNnssxwAAAAo"]
[Sun Aug 30 03:06:44.950042 2026] [security2:error] [pid 499751:tid 499918] [client 4.205.62.107:64505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/saiga.php"] [unique_id "apPklDmmjdkPfMeJsKOvZAAAA7o"]
[Sun Aug 30 03:06:44.950388 2026] [security2:error] [pid 499751:tid 499979] [client 20.63.81.20:43270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp-signup.php"] [unique_id "apPklDmmjdkPfMeJsKOvZgAAA_c"]
[Sun Aug 30 03:06:44.953131 2026] [security2:error] [pid 499751:tid 500021] [client 20.104.50.220:61670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/alex.php"] [unique_id "apPklDmmjdkPfMeJsKOvaQAABCE"]
[Sun Aug 30 03:06:44.964605 2026] [security2:error] [pid 499751:tid 499913] [client 4.205.62.107:63791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/var/www/wallet/index.php"] [unique_id "apPklDmmjdkPfMeJsKOvcgAAA7U"]
[Sun Aug 30 03:06:44.977813 2026] [authz_core:error] [pid 499145:tid 499347] [client 216.73.216.128:45526] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:44.978269 2026] [authz_core:error] [pid 499145:tid 499347] [client 216.73.216.128:45526] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:44.995025 2026] [security2:error] [pid 499751:tid 499992] [client 158.23.147.79:42049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/ans.php"] [unique_id "apPklDmmjdkPfMeJsKOvfAAABAQ"]
[Sun Aug 30 03:06:45.004414 2026] [authz_core:error] [pid 499145:tid 499322] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_BW
[Sun Aug 30 03:06:45.004890 2026] [authz_core:error] [pid 499145:tid 499322] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_BW
[Sun Aug 30 03:06:45.064638 2026] [security2:error] [pid 499751:tid 499925] [client 20.151.200.44:47408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/qi.php"] [unique_id "apPklTmmjdkPfMeJsKOvngAAA8E"]
[Sun Aug 30 03:06:45.082969 2026] [security2:error] [pid 499145:tid 499345] [client 20.63.81.20:43385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp-conffg.php"] [unique_id "apPklVJNq1G5uRhTNnstIAAAAEY"]
[Sun Aug 30 03:06:45.131737 2026] [security2:error] [pid 499751:tid 499902] [client 158.23.147.79:53567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/index/function.php"] [unique_id "apPklTmmjdkPfMeJsKOvrgAAA6s"]
[Sun Aug 30 03:06:45.132903 2026] [security2:error] [pid 499751:tid 499902] [client 158.23.147.79:62469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apPklTmmjdkPfMeJsKOvrwAAA6s"]
[Sun Aug 30 03:06:45.156839 2026] [security2:error] [pid 499145:tid 499361] [client 68.155.159.216:56387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apPklVJNq1G5uRhTNnstRwAAAFY"]
[Sun Aug 30 03:06:45.165426 2026] [security2:error] [pid 499751:tid 499994] [client 68.155.159.216:12335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apPklTmmjdkPfMeJsKOvtwAABAY"]
[Sun Aug 30 03:06:45.181508 2026] [security2:error] [pid 499751:tid 499948] [client 20.151.200.44:37876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/px.php"] [unique_id "apPklTmmjdkPfMeJsKOvxAAAA9g"]
[Sun Aug 30 03:06:45.199579 2026] [security2:error] [pid 499145:tid 499347] [client 20.104.18.15:34760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPklVJNq1G5uRhTNnstWwAAAEg"]
[Sun Aug 30 03:06:45.210098 2026] [security2:error] [pid 499145:tid 499372] [client 20.63.81.20:43331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp-validate.php"] [unique_id "apPklVJNq1G5uRhTNnstYQAAAGE"]
[Sun Aug 30 03:06:45.248786 2026] [authz_core:error] [pid 499145:tid 499365] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:45.249052 2026] [authz_core:error] [pid 499145:tid 499365] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:45.260738 2026] [authz_core:error] [pid 499751:tid 499936] [client 66.249.66.43:52228] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:45.261016 2026] [authz_core:error] [pid 499751:tid 499936] [client 66.249.66.43:52228] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:45.273861 2026] [authz_core:error] [pid 499145:tid 499275] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fmsr%2Fparameters
[Sun Aug 30 03:06:45.274216 2026] [authz_core:error] [pid 499145:tid 499275] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fmsr%2Fparameters
[Sun Aug 30 03:06:45.285225 2026] [security2:error] [pid 499751:tid 499985] [client 4.205.62.107:63952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/wp-admin/sc.php"] [unique_id "apPklTmmjdkPfMeJsKOv4wAAA_0"]
[Sun Aug 30 03:06:45.292637 2026] [security2:error] [pid 499751:tid 499955] [client 20.197.61.180:21107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/upgrade-temp-backup/themes/wp-settings.php"] [unique_id "apPklTmmjdkPfMeJsKOv5gAAA98"]
[Sun Aug 30 03:06:45.309247 2026] [security2:error] [pid 499145:tid 499367] [client 20.104.50.220:27399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/attachment.php"] [unique_id "apPklVJNq1G5uRhTNnstiAAAAFw"]
[Sun Aug 30 03:06:45.334965 2026] [security2:error] [pid 499751:tid 499979] [client 158.23.147.79:53295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/worksec.php"] [unique_id "apPklTmmjdkPfMeJsKOv7gAAA_c"]
[Sun Aug 30 03:06:45.338498 2026] [security2:error] [pid 499145:tid 499286] [client 20.63.81.20:43288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/700.php"] [unique_id "apPklVJNq1G5uRhTNnstmAAAAAs"]
[Sun Aug 30 03:06:45.340201 2026] [security2:error] [pid 499751:tid 499950] [client 4.205.62.107:2801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/kedi.php"] [unique_id "apPklTmmjdkPfMeJsKOv8wAAA9o"]
[Sun Aug 30 03:06:45.340894 2026] [authz_core:error] [pid 499145:tid 499392] [client 216.73.216.128:50607] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:45.341191 2026] [authz_core:error] [pid 499145:tid 499392] [client 216.73.216.128:50607] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:45.363834 2026] [security2:error] [pid 499145:tid 499321] [client 20.104.50.220:31890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/ids.php"] [unique_id "apPklVJNq1G5uRhTNnstowAAAC4"]
[Sun Aug 30 03:06:45.374694 2026] [security2:error] [pid 499751:tid 499913] [client 20.48.251.3:55460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/wp-access.php"] [unique_id "apPklTmmjdkPfMeJsKOv_AAAA7U"]
[Sun Aug 30 03:06:45.374832 2026] [security2:error] [pid 499145:tid 499361] [client 20.104.18.15:33789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/wp-trackback.php"] [unique_id "apPklVJNq1G5uRhTNnstpgAAAFY"]
[Sun Aug 30 03:06:45.375776 2026] [security2:error] [pid 499145:tid 499370] [client 4.205.62.107:18957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/bootstrap.php"] [unique_id "apPklVJNq1G5uRhTNnstqAAAAF8"]
[Sun Aug 30 03:06:45.375860 2026] [security2:error] [pid 499751:tid 499959] [client 20.104.50.220:62825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/jkt48.php"] [unique_id "apPklTmmjdkPfMeJsKOv_QAAA-M"]
[Sun Aug 30 03:06:45.380953 2026] [security2:error] [pid 499145:tid 499378] [client 20.151.200.44:47379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/px.php"] [unique_id "apPklVJNq1G5uRhTNnstrwAAAGc"]
[Sun Aug 30 03:06:45.400863 2026] [authz_core:error] [pid 499751:tid 499966] [client 66.249.66.41:62775] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:45.401149 2026] [authz_core:error] [pid 499751:tid 499966] [client 66.249.66.41:62775] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:45.411946 2026] [security2:error] [pid 499145:tid 499312] [client 4.205.62.107:62326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/file21.php"] [unique_id "apPklVJNq1G5uRhTNnstvQAAACU"]
[Sun Aug 30 03:06:45.416283 2026] [security2:error] [pid 499145:tid 499363] [client 4.205.62.107:5098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/requirements.php"] [unique_id "apPklVJNq1G5uRhTNnstvgAAAFg"]
[Sun Aug 30 03:06:45.417577 2026] [security2:error] [pid 499145:tid 499330] [client 20.48.251.3:7388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/cache-compat.php"] [unique_id "apPklVJNq1G5uRhTNnstwAAAADc"]
[Sun Aug 30 03:06:45.417600 2026] [security2:error] [pid 499751:tid 499902] [client 20.104.50.220:17335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/footer.php"] [unique_id "apPklTmmjdkPfMeJsKOwEgAAA6s"]
[Sun Aug 30 03:06:45.435230 2026] [security2:error] [pid 499145:tid 499383] [client 4.205.62.107:26761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/test1.php"] [unique_id "apPklVJNq1G5uRhTNnstywAAAGw"]
[Sun Aug 30 03:06:45.446201 2026] [security2:error] [pid 499751:tid 499948] [client 158.23.147.79:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/.well-known/content.php"] [unique_id "apPklTmmjdkPfMeJsKOwHAAAA9g"]
[Sun Aug 30 03:06:45.456055 2026] [security2:error] [pid 499751:tid 499993] [client 20.48.251.3:56332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/dialog.php"] [unique_id "apPklTmmjdkPfMeJsKOwIQAABAU"]
[Sun Aug 30 03:06:45.464630 2026] [security2:error] [pid 499751:tid 500021] [client 158.23.147.79:53529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/install.php"] [unique_id "apPklTmmjdkPfMeJsKOwIwAABCE"]
[Sun Aug 30 03:06:45.465482 2026] [security2:error] [pid 499751:tid 500012] [client 20.63.81.20:43329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/c4.php"] [unique_id "apPklTmmjdkPfMeJsKOwJAAABBg"]
[Sun Aug 30 03:06:45.491012 2026] [authz_core:error] [pid 499145:tid 499368] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_GB
[Sun Aug 30 03:06:45.491419 2026] [authz_core:error] [pid 499145:tid 499368] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_GB
[Sun Aug 30 03:06:45.494700 2026] [security2:error] [pid 499145:tid 499398] [client 158.23.147.79:4084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/x.php"] [unique_id "apPklVJNq1G5uRhTNnst5gAAAHs"]
[Sun Aug 30 03:06:45.498795 2026] [security2:error] [pid 499145:tid 499332] [client 20.104.50.220:46187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/tshop.php"] [unique_id "apPklVJNq1G5uRhTNnst7AAAADk"]
[Sun Aug 30 03:06:45.514384 2026] [security2:error] [pid 499145:tid 499342] [client 20.104.18.15:28640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/scxy.php"] [unique_id "apPklVJNq1G5uRhTNnst8QAAAEM"]
[Sun Aug 30 03:06:45.546025 2026] [security2:error] [pid 499145:tid 499319] [client 68.155.159.216:62306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apPklVJNq1G5uRhTNnst_AAAACw"]
[Sun Aug 30 03:06:45.568161 2026] [security2:error] [pid 499145:tid 499353] [client 158.23.147.79:54219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/cong.php"] [unique_id "apPklVJNq1G5uRhTNnsuBQAAAE4"]
[Sun Aug 30 03:06:45.569411 2026] [security2:error] [pid 499145:tid 499356] [client 20.151.200.44:37830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/is.php"] [unique_id "apPklVJNq1G5uRhTNnsuBgAAAFE"]
[Sun Aug 30 03:06:45.587742 2026] [security2:error] [pid 499145:tid 499297] [client 20.104.18.15:23507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/bulet.php"] [unique_id "apPklVJNq1G5uRhTNnsuDAAAABY"]
[Sun Aug 30 03:06:45.592391 2026] [security2:error] [pid 499751:tid 499967] [client 20.63.81.20:43272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp-tymanage.php"] [unique_id "apPklTmmjdkPfMeJsKOwSQAAA-s"]
[Sun Aug 30 03:06:45.601320 2026] [security2:error] [pid 499145:tid 499291] [client 20.104.18.15:13654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/wp-aothait.php"] [unique_id "apPklVJNq1G5uRhTNnsuEAAAABA"]
[Sun Aug 30 03:06:45.611958 2026] [authz_core:error] [pid 499145:tid 499347] [client 216.73.216.128:50607] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:45.612257 2026] [authz_core:error] [pid 499145:tid 499347] [client 216.73.216.128:50607] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:45.621398 2026] [security2:error] [pid 499145:tid 499325] [client 20.104.50.220:33314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/info.php"] [unique_id "apPklVJNq1G5uRhTNnsuFQAAADI"]
[Sun Aug 30 03:06:45.669009 2026] [security2:error] [pid 499751:tid 499934] [client 20.48.251.3:44304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/database.php"] [unique_id "apPklTmmjdkPfMeJsKOwVQAAA8o"]
[Sun Aug 30 03:06:45.672183 2026] [security2:error] [pid 499145:tid 499278] [client 158.23.147.79:53550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-includes/js/index.php"] [unique_id "apPklVJNq1G5uRhTNnsuJQAAAAM"]
[Sun Aug 30 03:06:45.686593 2026] [security2:error] [pid 499145:tid 499358] [client 158.23.147.79:62526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apPklVJNq1G5uRhTNnsuKwAAAFM"]
[Sun Aug 30 03:06:45.689571 2026] [security2:error] [pid 499751:tid 500007] [client 158.23.147.79:42097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-content/x.php"] [unique_id "apPklTmmjdkPfMeJsKOwVwAABBM"]
[Sun Aug 30 03:06:45.705791 2026] [authz_core:error] [pid 499145:tid 499356] [client 216.73.216.128:45526] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:45.706242 2026] [authz_core:error] [pid 499145:tid 499356] [client 216.73.216.128:45526] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:45.719042 2026] [security2:error] [pid 499751:tid 499956] [client 20.63.81.20:43360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/ajfto.php"] [unique_id "apPklTmmjdkPfMeJsKOwbQAAA-A"]
[Sun Aug 30 03:06:45.722900 2026] [authz_core:error] [pid 499145:tid 499361] [client 66.249.66.78:38043] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:45.723256 2026] [authz_core:error] [pid 499145:tid 499361] [client 66.249.66.78:38043] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:45.761338 2026] [security2:error] [pid 499751:tid 499950] [client 158.23.147.79:54596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-content/x/index.php"] [unique_id "apPklTmmjdkPfMeJsKOwewAAA9o"]
[Sun Aug 30 03:06:45.767101 2026] [security2:error] [pid 499751:tid 499984] [client 20.104.50.220:5606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/tanliste.php"] [unique_id "apPklTmmjdkPfMeJsKOwfQAAA_w"]
[Sun Aug 30 03:06:45.795639 2026] [authz_core:error] [pid 499145:tid 499311] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:45.795924 2026] [authz_core:error] [pid 499145:tid 499311] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:45.814246 2026] [authz_core:error] [pid 499145:tid 499357] [client 66.249.66.76:38091] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:45.814527 2026] [authz_core:error] [pid 499145:tid 499357] [client 66.249.66.76:38091] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:45.823280 2026] [security2:error] [pid 499145:tid 499364] [client 4.205.62.107:51765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/wp-info.php"] [unique_id "apPklVJNq1G5uRhTNnsudQAAAFk"]
[Sun Aug 30 03:06:45.824366 2026] [security2:error] [pid 499145:tid 499293] [client 195.178.110.247:63366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ermes-it-it.webnet-hosting4.com"] [uri "/index.php"] [unique_id "apPklVJNq1G5uRhTNnsudgAAABI"]
[Sun Aug 30 03:06:45.847503 2026] [security2:error] [pid 499751:tid 499938] [client 158.23.147.79:4073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPklTmmjdkPfMeJsKOwjwAAA84"]
[Sun Aug 30 03:06:45.858633 2026] [security2:error] [pid 499751:tid 499896] [client 20.63.81.20:43284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp_KwIW0U5F.php"] [unique_id "apPklTmmjdkPfMeJsKOwkAAAA6U"]
[Sun Aug 30 03:06:45.862943 2026] [security2:error] [pid 499751:tid 500008] [client 20.151.200.44:37763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/od.php"] [unique_id "apPklTmmjdkPfMeJsKOwkgAABBQ"]
[Sun Aug 30 03:06:45.885683 2026] [authz_core:error] [pid 499145:tid 499275] [client 216.73.216.128:45526] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:45.885998 2026] [authz_core:error] [pid 499145:tid 499275] [client 216.73.216.128:45526] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:45.899955 2026] [security2:error] [pid 499145:tid 499372] [client 20.151.200.44:47423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/is.php"] [unique_id "apPklVJNq1G5uRhTNnsulwAAAGE"]
[Sun Aug 30 03:06:45.968120 2026] [security2:error] [pid 499751:tid 499913] [client 20.104.18.15:43978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/dk.php"] [unique_id "apPklTmmjdkPfMeJsKOwtgAAA7U"]
[Sun Aug 30 03:06:45.976011 2026] [security2:error] [pid 499145:tid 499387] [client 195.178.110.247:6982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ermes-it-it.webnet-hosting4.com"] [uri "/index.php"] [unique_id "apPklVJNq1G5uRhTNnsusAAAAHA"]
[Sun Aug 30 03:06:45.979401 2026] [security2:error] [pid 499145:tid 499397] [client 158.23.147.79:62560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/nf_tracking.php"] [unique_id "apPklVJNq1G5uRhTNnsutAAAAHo"]
[Sun Aug 30 03:06:45.981271 2026] [authz_core:error] [pid 499751:tid 499988] [client 66.249.66.203:53588] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:45.981719 2026] [authz_core:error] [pid 499751:tid 499988] [client 66.249.66.203:53588] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:45.985031 2026] [security2:error] [pid 499751:tid 499990] [client 158.23.147.79:54242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-content/index.php"] [unique_id "apPklTmmjdkPfMeJsKOwwwAABAI"]
[Sun Aug 30 03:06:45.987574 2026] [security2:error] [pid 499145:tid 499295] [client 20.63.81.20:43347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp_xiPu52Ut.php"] [unique_id "apPklVJNq1G5uRhTNnsuuAAAABQ"]
[Sun Aug 30 03:06:45.990467 2026] [security2:error] [pid 499751:tid 499976] [client 158.23.147.79:42087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/log-mama/function.php"] [unique_id "apPklTmmjdkPfMeJsKOwyAAAA_Q"]
[Sun Aug 30 03:06:46.006430 2026] [security2:error] [pid 499751:tid 499968] [client 20.104.50.220:51629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/klee.php"] [unique_id "apPkljmmjdkPfMeJsKOw1gAAA-w"]
[Sun Aug 30 03:06:46.014084 2026] [authz_core:error] [pid 499145:tid 499352] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZW
[Sun Aug 30 03:06:46.014547 2026] [authz_core:error] [pid 499145:tid 499352] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZW
[Sun Aug 30 03:06:46.016396 2026] [security2:error] [pid 499751:tid 500018] [client 4.205.62.107:58146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/server_info.php"] [unique_id "apPkljmmjdkPfMeJsKOw3AAABB4"]
[Sun Aug 30 03:06:46.038001 2026] [security2:error] [pid 499751:tid 499977] [client 20.48.251.3:64433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/hiquido.com/index.php"] [unique_id "apPkljmmjdkPfMeJsKOw6gAAA_U"]
[Sun Aug 30 03:06:46.055911 2026] [security2:error] [pid 499751:tid 499957] [client 20.104.50.220:29128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/dikne.php"] [unique_id "apPkljmmjdkPfMeJsKOw9wAAA-E"]
[Sun Aug 30 03:06:46.104286 2026] [security2:error] [pid 499751:tid 499994] [client 4.205.62.107:63789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/124.php"] [unique_id "apPkljmmjdkPfMeJsKOxCgAABAY"]
[Sun Aug 30 03:06:46.117185 2026] [security2:error] [pid 499145:tid 499379] [client 20.63.81.20:43333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp_n5VD7XDh.php"] [unique_id "apPkllJNq1G5uRhTNnsu6gAAAGg"]
[Sun Aug 30 03:06:46.118463 2026] [security2:error] [pid 499751:tid 499930] [client 20.151.200.44:47322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/od.php"] [unique_id "apPkljmmjdkPfMeJsKOxDwAAA8Y"]
[Sun Aug 30 03:06:46.134302 2026] [security2:error] [pid 499751:tid 499921] [client 114.119.154.124:58121] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "3226online.com"] [uri "/main/"] [unique_id "apPkljmmjdkPfMeJsKOxGgAAA70"], referer: https://3226online.com/main/
[Sun Aug 30 03:06:46.140316 2026] [security2:error] [pid 499145:tid 499345] [client 20.104.50.220:61632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-0.php"] [unique_id "apPkllJNq1G5uRhTNnsu8gAAAEY"]
[Sun Aug 30 03:06:46.140816 2026] [lsapi:warn] [pid 499145:tid 499169] [remote 34.31.35.56:16384] [host tastylandscape.com] Backend log: PHP Warning: Use of undefined constant user_level - assumed 'user_level' (this will throw an Error in a future version of PHP) in /home4/tommed/public_html/wp-content/plugins/ultimate-google-analytics/ultimate_ga.php on line 524\n
[Sun Aug 30 03:06:46.155500 2026] [security2:error] [pid 499751:tid 499932] [client 158.23.147.79:54232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-includes/Requests/about.php"] [unique_id "apPkljmmjdkPfMeJsKOxIAAAA8g"]
[Sun Aug 30 03:06:46.162989 2026] [security2:error] [pid 499751:tid 499985] [client 20.104.49.130:63248] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.hoslercorp.net"] [uri "/1.php"] [unique_id "apPkljmmjdkPfMeJsKOxIwAAA_0"]
[Sun Aug 30 03:06:46.163098 2026] [security2:error] [pid 499751:tid 499985] [client 20.104.49.130:63248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/1.php"] [unique_id "apPkljmmjdkPfMeJsKOxIwAAA_0"]
[Sun Aug 30 03:06:46.169378 2026] [security2:error] [pid 499751:tid 500007] [client 4.205.62.107:61795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/ammika.php"] [unique_id "apPkljmmjdkPfMeJsKOxKgAABBM"]
[Sun Aug 30 03:06:46.192499 2026] [authz_core:error] [pid 499145:tid 499286] [client 66.249.66.196:40507] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:46.192785 2026] [authz_core:error] [pid 499145:tid 499286] [client 66.249.66.196:40507] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:46.206322 2026] [security2:error] [pid 499751:tid 499972] [client 158.23.147.79:54236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/about/function.php"] [unique_id "apPkljmmjdkPfMeJsKOxNAAAA_A"]
[Sun Aug 30 03:06:46.225111 2026] [security2:error] [pid 499751:tid 499966] [client 68.155.159.216:60864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-content/themes/too.php"] [unique_id "apPkljmmjdkPfMeJsKOxSAAAA-o"]
[Sun Aug 30 03:06:46.247193 2026] [security2:error] [pid 499751:tid 499908] [client 20.63.81.20:43349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp-mini.php"] [unique_id "apPkljmmjdkPfMeJsKOxUwAAA7E"]
[Sun Aug 30 03:06:46.259587 2026] [security2:error] [pid 499751:tid 499997] [client 158.23.147.79:63259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wzy.php"] [unique_id "apPkljmmjdkPfMeJsKOxXAAABAk"]
[Sun Aug 30 03:06:46.264068 2026] [security2:error] [pid 499751:tid 500004] [client 20.104.49.130:52141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkljmmjdkPfMeJsKOxXwAABBA"]
[Sun Aug 30 03:06:46.266674 2026] [security2:error] [pid 499751:tid 499923] [client 20.197.61.180:14763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/upgrade/about.php"] [unique_id "apPkljmmjdkPfMeJsKOxYAAAA78"]
[Sun Aug 30 03:06:46.274447 2026] [security2:error] [pid 499751:tid 499934] [client 68.155.159.216:65520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apPkljmmjdkPfMeJsKOxYQAAA8o"]
[Sun Aug 30 03:06:46.299875 2026] [security2:error] [pid 499751:tid 499982] [client 158.23.147.79:4055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/bk/index.php"] [unique_id "apPkljmmjdkPfMeJsKOxgQAAA_o"]
[Sun Aug 30 03:06:46.301547 2026] [authz_core:error] [pid 499145:tid 499350] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:46.301832 2026] [authz_core:error] [pid 499145:tid 499350] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:46.315065 2026] [security2:error] [pid 499751:tid 499956] [client 158.23.147.79:54261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-includes/customize/index.php"] [unique_id "apPkljmmjdkPfMeJsKOxhQAAA-A"]
[Sun Aug 30 03:06:46.316680 2026] [security2:error] [pid 499751:tid 499908] [client 20.151.200.44:47297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/wp-the.php"] [unique_id "apPkljmmjdkPfMeJsKOxhgAAA7E"]
[Sun Aug 30 03:06:46.333958 2026] [security2:error] [pid 499751:tid 500017] [client 20.104.18.15:34796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkljmmjdkPfMeJsKOxiwAABB0"]
[Sun Aug 30 03:06:46.342590 2026] [authz_core:error] [pid 499145:tid 499402] [client 216.73.216.128:39914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:46.342912 2026] [authz_core:error] [pid 499145:tid 499402] [client 216.73.216.128:39914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:46.350564 2026] [security2:error] [pid 499145:tid 499290] [client 4.205.62.107:31739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/adminfus.php"] [unique_id "apPkllJNq1G5uRhTNnsvQAAAAA8"]
[Sun Aug 30 03:06:46.394333 2026] [security2:error] [pid 499751:tid 500004] [client 20.63.81.20:43355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/xmini4.php"] [unique_id "apPkljmmjdkPfMeJsKOxpwAABBA"]
[Sun Aug 30 03:06:46.423003 2026] [security2:error] [pid 499145:tid 499364] [client 4.205.62.107:63948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/debug.php"] [unique_id "apPkllJNq1G5uRhTNnsvYgAAAFk"]
[Sun Aug 30 03:06:46.438671 2026] [security2:error] [pid 499751:tid 499896] [client 20.104.50.220:27204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/showthread.php"] [unique_id "apPkljmmjdkPfMeJsKOxvAAAA6U"]
[Sun Aug 30 03:06:46.441510 2026] [security2:error] [pid 499751:tid 499928] [client 158.23.147.79:53527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-admin/includes/index.php"] [unique_id "apPkljmmjdkPfMeJsKOxvwAAA8Q"]
[Sun Aug 30 03:06:46.445153 2026] [security2:error] [pid 499751:tid 499943] [client 68.155.159.216:56390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/classwithtostring.php"] [unique_id "apPkljmmjdkPfMeJsKOxxAAAA9M"]
[Sun Aug 30 03:06:46.449053 2026] [security2:error] [pid 499145:tid 499345] [client 158.23.147.79:54220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-admin/index.php"] [unique_id "apPkllJNq1G5uRhTNnsvbAAAAEY"]
[Sun Aug 30 03:06:46.455531 2026] [security2:error] [pid 499751:tid 499961] [client 20.151.200.44:37782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/wp-the.php"] [unique_id "apPkljmmjdkPfMeJsKOxzAAAA-U"]
[Sun Aug 30 03:06:46.476296 2026] [security2:error] [pid 499145:tid 499291] [client 4.205.62.107:2783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/oc460l3x.php"] [unique_id "apPkllJNq1G5uRhTNnsvhAAAABA"]
[Sun Aug 30 03:06:46.504103 2026] [security2:error] [pid 499751:tid 499934] [client 4.205.62.107:18667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/333.php"] [unique_id "apPkljmmjdkPfMeJsKOx5gAAA8o"]
[Sun Aug 30 03:06:46.508378 2026] [authz_core:error] [pid 499145:tid 499277] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_PH%2FLC_MESSAGES
[Sun Aug 30 03:06:46.508881 2026] [authz_core:error] [pid 499145:tid 499277] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_PH%2FLC_MESSAGES
[Sun Aug 30 03:06:46.519304 2026] [security2:error] [pid 499751:tid 499923] [client 20.48.251.3:49942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/otuz1.php"] [unique_id "apPkljmmjdkPfMeJsKOx6wAAA78"]
[Sun Aug 30 03:06:46.519882 2026] [security2:error] [pid 499751:tid 499991] [client 68.155.159.216:54044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/x.php"] [unique_id "apPkljmmjdkPfMeJsKOx7AAABAM"]
[Sun Aug 30 03:06:46.525865 2026] [lsapi:warn] [pid 499751:tid 499776] [remote 34.31.35.56:16385] [host tastylandscape.com] Backend log: PHP Warning: Use of undefined constant user_level - assumed 'user_level' (this will throw an Error in a future version of PHP) in /home4/tommed/public_html/wp-content/plugins/ultimate-google-analytics/ultimate_ga.php on line 524\n
[Sun Aug 30 03:06:46.526262 2026] [security2:error] [pid 499751:tid 499946] [client 20.104.18.15:32990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/pri.php"] [unique_id "apPkljmmjdkPfMeJsKOx7wAAA9Y"]
[Sun Aug 30 03:06:46.527843 2026] [security2:error] [pid 499145:tid 499379] [client 20.63.81.20:43382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/reop3.php"] [unique_id "apPkllJNq1G5uRhTNnsvqQAAAGg"]
[Sun Aug 30 03:06:46.529103 2026] [security2:error] [pid 499145:tid 499345] [client 195.178.110.247:63368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ermes-it.com"] [uri "/index.php"] [unique_id "apPkllJNq1G5uRhTNnsvqgAAAEY"]
[Sun Aug 30 03:06:46.529661 2026] [security2:error] [pid 499145:tid 499354] [client 20.104.50.220:32516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/idx.php"] [unique_id "apPkllJNq1G5uRhTNnsvqwAAAE8"]
[Sun Aug 30 03:06:46.533783 2026] [security2:error] [pid 499751:tid 499894] [client 20.104.50.220:52815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/gaza.php"] [unique_id "apPkljmmjdkPfMeJsKOx8wAAA6M"]
[Sun Aug 30 03:06:46.553323 2026] [security2:error] [pid 499751:tid 499929] [client 4.205.62.107:22926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/mcebraed.php"] [unique_id "apPkljmmjdkPfMeJsKOx_QAAA8U"]
[Sun Aug 30 03:06:46.555454 2026] [security2:error] [pid 499145:tid 499340] [client 158.23.147.79:54641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-login.php"] [unique_id "apPkllJNq1G5uRhTNnsvtgAAAEE"]
[Sun Aug 30 03:06:46.557091 2026] [security2:error] [pid 499751:tid 499932] [client 20.48.251.3:6522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/aws_keys.php"] [unique_id "apPkljmmjdkPfMeJsKOyAQAAA8g"]
[Sun Aug 30 03:06:46.572441 2026] [authz_core:error] [pid 499145:tid 499328] [client 66.249.66.70:41019] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:46.572903 2026] [authz_core:error] [pid 499145:tid 499328] [client 66.249.66.70:41019] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:46.577670 2026] [security2:error] [pid 499751:tid 499989] [client 4.205.62.107:5086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/var/www/wallet/index.php"] [unique_id "apPkljmmjdkPfMeJsKOyCwAABAE"]
[Sun Aug 30 03:06:46.584578 2026] [security2:error] [pid 499751:tid 499988] [client 158.23.147.79:54256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-content/themes/index.php"] [unique_id "apPkljmmjdkPfMeJsKOyEAAABAA"]
[Sun Aug 30 03:06:46.601428 2026] [security2:error] [pid 499751:tid 499982] [client 158.23.147.79:42077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.auscreen.com.au"] [uri "/first.php"] [unique_id "apPkljmmjdkPfMeJsKOyFAAAA_o"]
[Sun Aug 30 03:06:46.616685 2026] [security2:error] [pid 499751:tid 499956] [client 20.48.251.3:56355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/phpinfo01.php"] [unique_id "apPkljmmjdkPfMeJsKOyFwAAA-A"]
[Sun Aug 30 03:06:46.618904 2026] [authz_core:error] [pid 499145:tid 499303] [client 216.73.216.128:45526] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:46.619385 2026] [authz_core:error] [pid 499145:tid 499303] [client 216.73.216.128:45526] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:46.631744 2026] [security2:error] [pid 499751:tid 499903] [client 20.104.50.220:16727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-content/index.php"] [unique_id "apPkljmmjdkPfMeJsKOyGwAAA6w"]
[Sun Aug 30 03:06:46.640063 2026] [security2:error] [pid 499751:tid 499948] [client 158.23.147.79:62479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apPkljmmjdkPfMeJsKOyHwAAA9g"]
[Sun Aug 30 03:06:46.652795 2026] [security2:error] [pid 499751:tid 499926] [client 20.104.50.220:46634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/twin.php"] [unique_id "apPkljmmjdkPfMeJsKOyIwAAA8I"]
[Sun Aug 30 03:06:46.653617 2026] [security2:error] [pid 499751:tid 499965] [client 20.63.81.20:43234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp-mail.php"] [unique_id "apPkljmmjdkPfMeJsKOyJAAAA-k"]
[Sun Aug 30 03:06:46.661764 2026] [security2:error] [pid 499751:tid 499986] [client 20.104.18.15:28660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/ws13.php"] [unique_id "apPkljmmjdkPfMeJsKOyJgAAA_4"]
[Sun Aug 30 03:06:46.667450 2026] [authz_core:error] [pid 499145:tid 499330] [client 66.249.66.78:38043] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:46.667753 2026] [authz_core:error] [pid 499145:tid 499330] [client 66.249.66.78:38043] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:46.694960 2026] [security2:error] [pid 499751:tid 500010] [client 195.178.110.247:6996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ermes-it.com"] [uri "/index.php"] [unique_id "apPkljmmjdkPfMeJsKOyMAAABBY"]
[Sun Aug 30 03:06:46.695118 2026] [security2:error] [pid 499751:tid 499953] [client 20.151.200.44:24583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/wt.php"] [unique_id "apPkljmmjdkPfMeJsKOyMQAAA90"]
[Sun Aug 30 03:06:46.718462 2026] [security2:error] [pid 499751:tid 499896] [client 20.104.18.15:23437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/av.php"] [unique_id "apPkljmmjdkPfMeJsKOyTwAAA6U"]
[Sun Aug 30 03:06:46.758579 2026] [security2:error] [pid 499145:tid 499371] [client 20.104.50.220:33324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/ini.php"] [unique_id "apPkllJNq1G5uRhTNnsv3gAAAGA"]
[Sun Aug 30 03:06:46.780367 2026] [security2:error] [pid 499751:tid 499921] [client 20.63.81.20:43370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp-conffg.php"] [unique_id "apPkljmmjdkPfMeJsKOydAAAA70"]
[Sun Aug 30 03:06:46.785058 2026] [security2:error] [pid 499145:tid 499354] [client 20.151.200.44:37839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/wt.php"] [unique_id "apPkllJNq1G5uRhTNnsv6QAAAE8"]
[Sun Aug 30 03:06:46.812956 2026] [security2:error] [pid 499145:tid 499340] [client 20.104.18.15:13755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/wp-includes/index.php"] [unique_id "apPkllJNq1G5uRhTNnsv8wAAAEE"]
[Sun Aug 30 03:06:46.815523 2026] [lsapi:error] [pid 499751:tid 499777] [remote 209.242.199.74:39994] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n
[Sun Aug 30 03:06:46.815678 2026] [lsapi:error] [pid 499751:tid 499777] [remote 209.242.199.74:39994] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n
[Sun Aug 30 03:06:46.817065 2026] [lsapi:error] [pid 499751:tid 499777] [remote 209.242.199.74:39994] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n
[Sun Aug 30 03:06:46.819345 2026] [security2:error] [pid 499751:tid 499935] [client 20.48.251.3:44388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/atex1.php"] [unique_id "apPkljmmjdkPfMeJsKOyhQAAA8s"]
[Sun Aug 30 03:06:46.823825 2026] [authz_core:error] [pid 499145:tid 499299] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:46.824254 2026] [authz_core:error] [pid 499145:tid 499299] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:46.828054 2026] [security2:error] [pid 499751:tid 499953] [client 68.155.159.216:62278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-content/uploads/about.php"] [unique_id "apPkljmmjdkPfMeJsKOyiwAAA90"]
[Sun Aug 30 03:06:46.853957 2026] [security2:error] [pid 499145:tid 499376] [client 158.23.147.79:54270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apPkllJNq1G5uRhTNnswAgAAAGU"]
[Sun Aug 30 03:06:46.867517 2026] [security2:error] [pid 499145:tid 499366] [client 158.23.147.79:54228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/about.php"] [unique_id "apPkllJNq1G5uRhTNnswAwAAAFs"]
[Sun Aug 30 03:06:46.892751 2026] [authz_core:error] [pid 499145:tid 499275] [client 216.73.216.128:39914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:46.893029 2026] [authz_core:error] [pid 499145:tid 499275] [client 216.73.216.128:39914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:46.909845 2026] [security2:error] [pid 499751:tid 499976] [client 20.104.50.220:5619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/atomlib.php.suspected"] [unique_id "apPkljmmjdkPfMeJsKOynQAAA_Q"]
[Sun Aug 30 03:06:46.919050 2026] [security2:error] [pid 499145:tid 499362] [client 20.63.81.20:43326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/filefuns.php"] [unique_id "apPkllJNq1G5uRhTNnswEwAAAFc"]
[Sun Aug 30 03:06:46.956052 2026] [security2:error] [pid 499145:tid 499200] [remote 97.74.87.194:58568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "southerncruzinmobility.com"] [uri "/wp-login.php"] [unique_id "apPkllJNq1G5uRhTNnswIQAAYzY"]
[Sun Aug 30 03:06:46.958662 2026] [security2:error] [pid 499751:tid 499966] [client 4.205.62.107:51712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/fns.php"] [unique_id "apPkljmmjdkPfMeJsKOytQAAA-o"]
[Sun Aug 30 03:06:46.960324 2026] [authz_core:error] [pid 499145:tid 499318] [client 66.249.66.70:41019] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:46.960640 2026] [authz_core:error] [pid 499145:tid 499318] [client 66.249.66.70:41019] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:46.969149 2026] [security2:error] [pid 499751:tid 499910] [client 20.197.61.180:14039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.cvhcustom.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "apPkljmmjdkPfMeJsKOyuwAAA7M"]
[Sun Aug 30 03:06:47.001711 2026] [security2:error] [pid 499145:tid 499277] [client 4.205.62.107:26518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/bigdump.php"] [unique_id "apPkl1JNq1G5uRhTNnswOwAAAAI"]
[Sun Aug 30 03:06:47.017148 2026] [security2:error] [pid 499751:tid 500004] [client 20.104.49.130:34525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/az.php"] [unique_id "apPklzmmjdkPfMeJsKOy3gAABBA"]
[Sun Aug 30 03:06:47.026406 2026] [security2:error] [pid 499751:tid 499906] [client 158.23.147.79:62472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apPklzmmjdkPfMeJsKOy4wAAA68"]
[Sun Aug 30 03:06:47.030982 2026] [authz_core:error] [pid 499145:tid 499310] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NZ%2FLC_MESSAGES
[Sun Aug 30 03:06:47.031296 2026] [authz_core:error] [pid 499145:tid 499310] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NZ%2FLC_MESSAGES
[Sun Aug 30 03:06:47.042954 2026] [http2:info] [pid 500253:tid 500253] h2_workers: created with min=128 max=192 idle_ms=600000
[Sun Aug 30 03:06:47.047214 2026] [security2:error] [pid 499751:tid 499966] [client 20.63.81.20:43353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp-cron.php"] [unique_id "apPklzmmjdkPfMeJsKOy7wAAA-o"]
[Sun Aug 30 03:06:47.073617 2026] [security2:error] [pid 499751:tid 500019] [client 158.23.147.79:54608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apPklzmmjdkPfMeJsKOy-wAABB8"]
[Sun Aug 30 03:06:47.079150 2026] [authz_core:error] [pid 499145:tid 499374] [client 216.73.216.128:39914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:47.079435 2026] [authz_core:error] [pid 499145:tid 499374] [client 216.73.216.128:39914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:47.080247 2026] [security2:error] [pid 500253:tid 500389] [client 158.23.147.79:54210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-admin/images/about.php"] [unique_id "apPkl1mmXVd4kRvS-FD95wAAAZM"]
[Sun Aug 30 03:06:47.103030 2026] [security2:error] [pid 500253:tid 500410] [client 20.104.18.15:44025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/ta.php"] [unique_id "apPkl1mmXVd4kRvS-FD98AAAAag"]
[Sun Aug 30 03:06:47.141737 2026] [authz_core:error] [pid 499145:tid 499394] [client 66.249.66.77:43085] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:47.142052 2026] [authz_core:error] [pid 499145:tid 499394] [client 66.249.66.77:43085] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:47.165782 2026] [security2:error] [pid 499751:tid 499969] [client 20.104.50.220:63529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/kalokataitusayagatauya.php"] [unique_id "apPklzmmjdkPfMeJsKOzDgAAA-0"]
[Sun Aug 30 03:06:47.171700 2026] [security2:error] [pid 499751:tid 499991] [client 68.155.159.216:61342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/content.php"] [unique_id "apPklzmmjdkPfMeJsKOzEgAABAM"]
[Sun Aug 30 03:06:47.180638 2026] [security2:error] [pid 499751:tid 500013] [client 20.63.81.20:43282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/lock360.php"] [unique_id "apPklzmmjdkPfMeJsKOzFwAABBk"]
[Sun Aug 30 03:06:47.193810 2026] [security2:error] [pid 499751:tid 499896] [client 20.104.50.220:29587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/cPanel.php"] [unique_id "apPklzmmjdkPfMeJsKOzHQAAA6U"]
[Sun Aug 30 03:06:47.228728 2026] [security2:error] [pid 499145:tid 499397] [client 158.23.147.79:54633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPkl1JNq1G5uRhTNnswnAAAAHo"]
[Sun Aug 30 03:06:47.237048 2026] [security2:error] [pid 500253:tid 500487] [client 20.48.251.3:6507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/ws79.php"] [unique_id "apPkl1mmXVd4kRvS-FD-FAAAAfU"]
[Sun Aug 30 03:06:47.239022 2026] [security2:error] [pid 500253:tid 500490] [client 4.205.62.107:63795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/test1.php"] [unique_id "apPkl1mmXVd4kRvS-FD-FgAAAfg"]
[Sun Aug 30 03:06:47.243572 2026] [security2:error] [pid 499145:tid 499367] [client 158.23.147.79:62576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apPkl1JNq1G5uRhTNnswoQAAAFw"]
[Sun Aug 30 03:06:47.245844 2026] [authz_core:error] [pid 500253:tid 500492] [client 66.249.66.193:55974] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:47.246159 2026] [authz_core:error] [pid 500253:tid 500492] [client 66.249.66.193:55974] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:47.260275 2026] [security2:error] [pid 499751:tid 499991] [client 158.23.147.79:53545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/themes.php"] [unique_id "apPklzmmjdkPfMeJsKOzMgAABAM"]
[Sun Aug 30 03:06:47.271340 2026] [security2:error] [pid 500253:tid 500393] [client 20.151.200.44:27285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/wefile.php"] [unique_id "apPkl1mmXVd4kRvS-FD-JQAAAZc"]
[Sun Aug 30 03:06:47.275174 2026] [authz_core:error] [pid 499145:tid 499299] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:47.275525 2026] [authz_core:error] [pid 499145:tid 499299] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:47.302131 2026] [security2:error] [pid 499751:tid 499930] [client 20.104.50.220:61401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-1.php"] [unique_id "apPklzmmjdkPfMeJsKOzPgAAA8Y"]
[Sun Aug 30 03:06:47.306816 2026] [security2:error] [pid 499751:tid 499984] [client 20.151.200.44:37820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/im.php"] [unique_id "apPklzmmjdkPfMeJsKOzPwAAA_w"]
[Sun Aug 30 03:06:47.308968 2026] [security2:error] [pid 499145:tid 499352] [client 20.63.81.20:43206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp-theme.php"] [unique_id "apPkl1JNq1G5uRhTNnswtwAAAE0"]
[Sun Aug 30 03:06:47.339846 2026] [security2:error] [pid 499751:tid 499903] [client 4.205.62.107:61785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/broadcasting.php"] [unique_id "apPklzmmjdkPfMeJsKOzRAAAA6w"]
[Sun Aug 30 03:06:47.347760 2026] [security2:error] [pid 499145:tid 499214] [remote 97.74.87.194:58568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "southerncruzinmobility.com"] [uri "/wp-login.php"] [unique_id "apPkl1JNq1G5uRhTNnswxwAAUkQ"], referer: https://southerncruzinmobility.com/wp-login.php
[Sun Aug 30 03:06:47.348265 2026] [authz_core:error] [pid 499145:tid 499312] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:47.348532 2026] [authz_core:error] [pid 499145:tid 499312] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:47.351034 2026] [security2:error] [pid 499751:tid 500021] [client 4.205.62.107:58166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/hosty.php"] [unique_id "apPklzmmjdkPfMeJsKOzSAAABCE"]
[Sun Aug 30 03:06:47.353871 2026] [security2:error] [pid 500253:tid 500473] [client 158.23.147.79:44242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-admin.php"] [unique_id "apPkl1mmXVd4kRvS-FD-SQAAAec"]
[Sun Aug 30 03:06:47.362930 2026] [security2:error] [pid 500253:tid 500442] [client 158.23.147.79:53552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-mail.php"] [unique_id "apPkl1mmXVd4kRvS-FD-TQAAAcg"]
[Sun Aug 30 03:06:47.389581 2026] [security2:error] [pid 499751:tid 499986] [client 68.155.159.216:12334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/dropdown.php"] [unique_id "apPklzmmjdkPfMeJsKOzVQAAA_4"]
[Sun Aug 30 03:06:47.389925 2026] [security2:error] [pid 499751:tid 499966] [client 158.23.147.79:62519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apPklzmmjdkPfMeJsKOzVgAAA-o"]
[Sun Aug 30 03:06:47.438306 2026] [security2:error] [pid 500253:tid 500389] [client 20.63.81.20:43291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/2d7433/index.php"] [unique_id "apPkl1mmXVd4kRvS-FD-YwAAAZM"]
[Sun Aug 30 03:06:47.446432 2026] [security2:error] [pid 499751:tid 499948] [client 68.155.159.216:60877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/radio.php"] [unique_id "apPklzmmjdkPfMeJsKOzcwAAA9g"]
[Sun Aug 30 03:06:47.481021 2026] [security2:error] [pid 500253:tid 500425] [client 158.23.147.79:54209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/cgi-bin/index.php"] [unique_id "apPkl1mmXVd4kRvS-FD-dAAAAbc"]
[Sun Aug 30 03:06:47.489188 2026] [security2:error] [pid 500253:tid 500438] [client 20.104.18.15:34752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/ap.php"] [unique_id "apPkl1mmXVd4kRvS-FD-egAAAcQ"]
[Sun Aug 30 03:06:47.510443 2026] [authz_core:error] [pid 499145:tid 499352] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_BW
[Sun Aug 30 03:06:47.510494 2026] [security2:error] [pid 500253:tid 500447] [client 158.23.147.79:62571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apPkl1mmXVd4kRvS-FD-hAAAAc0"]
[Sun Aug 30 03:06:47.510918 2026] [authz_core:error] [pid 499145:tid 499352] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_BW
[Sun Aug 30 03:06:47.524606 2026] [security2:error] [pid 499145:tid 499284] [client 216.73.216.128:39914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPkl1JNq1G5uRhTNnsxAgAAAAk"]
[Sun Aug 30 03:06:47.576201 2026] [security2:error] [pid 499145:tid 499281] [client 20.104.50.220:27549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/syndication.php"] [unique_id "apPkl1JNq1G5uRhTNnsxFwAAAAY"]
[Sun Aug 30 03:06:47.577302 2026] [security2:error] [pid 500253:tid 500411] [client 4.205.62.107:64056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/nzv.php"] [unique_id "apPkl1mmXVd4kRvS-FD-oAAAAak"]
[Sun Aug 30 03:06:47.583345 2026] [security2:error] [pid 500253:tid 500414] [client 158.23.147.79:54219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-includes/assets/index.php"] [unique_id "apPkl1mmXVd4kRvS-FD-ogAAAaw"]
[Sun Aug 30 03:06:47.595921 2026] [security2:error] [pid 499145:tid 499292] [client 20.151.200.44:37789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/file.php"] [unique_id "apPkl1JNq1G5uRhTNnsxJAAAABE"]
[Sun Aug 30 03:06:47.598492 2026] [security2:error] [pid 500253:tid 500434] [client 68.155.159.216:56373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/install.php"] [unique_id "apPkl1mmXVd4kRvS-FD-qAAAAcA"]
[Sun Aug 30 03:06:47.610294 2026] [security2:error] [pid 499145:tid 499370] [client 20.63.81.20:43379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp-login.php"] [unique_id "apPkl1JNq1G5uRhTNnsxEQAAAF8"]
[Sun Aug 30 03:06:47.625710 2026] [security2:error] [pid 499145:tid 499301] [client 4.205.62.107:2983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/drykl.php"] [unique_id "apPkl1JNq1G5uRhTNnsxKwAAABo"]
[Sun Aug 30 03:06:47.653758 2026] [security2:error] [pid 499145:tid 499384] [client 20.104.18.15:33668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/wp_blog_footer.php"] [unique_id "apPkl1JNq1G5uRhTNnsxNAAAAG0"]
[Sun Aug 30 03:06:47.660926 2026] [security2:error] [pid 499145:tid 499328] [client 20.48.251.3:55516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/update.php"] [unique_id "apPkl1JNq1G5uRhTNnsxNwAAADU"]
[Sun Aug 30 03:06:47.667824 2026] [security2:error] [pid 500253:tid 500433] [client 20.104.50.220:29615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/injection.php"] [unique_id "apPkl1mmXVd4kRvS-FD-sAAAAb8"]
[Sun Aug 30 03:06:47.678582 2026] [security2:error] [pid 500253:tid 500466] [client 20.104.50.220:32544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/init.php"] [unique_id "apPkl1mmXVd4kRvS-FD-sgAAAeA"]
[Sun Aug 30 03:06:47.705922 2026] [security2:error] [pid 499145:tid 499345] [client 4.205.62.107:62286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/server-info.php"] [unique_id "apPkl1JNq1G5uRhTNnsxVQAAAEY"]
[Sun Aug 30 03:06:47.716096 2026] [authz_core:error] [pid 499145:tid 499292] [client 216.73.216.128:45526] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:47.716447 2026] [authz_core:error] [pid 499145:tid 499292] [client 216.73.216.128:45526] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:47.727503 2026] [security2:error] [pid 499145:tid 499372] [client 20.48.251.3:64439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/umgebung.php"] [unique_id "apPkl1JNq1G5uRhTNnsxYwAAAGE"]
[Sun Aug 30 03:06:47.733878 2026] [security2:error] [pid 499145:tid 499354] [client 158.23.147.79:63294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/packed.php"] [unique_id "apPkl1JNq1G5uRhTNnsxbAAAAE8"]
[Sun Aug 30 03:06:47.736386 2026] [security2:error] [pid 500253:tid 500459] [client 20.63.81.20:43324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/images.php"] [unique_id "apPkl1mmXVd4kRvS-FD-ygAAAdk"]
[Sun Aug 30 03:06:47.746090 2026] [security2:error] [pid 500253:tid 500400] [client 4.205.62.107:18946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/G-in.php"] [unique_id "apPkl1mmXVd4kRvS-FD-zQAAAZ4"]
[Sun Aug 30 03:06:47.756911 2026] [security2:error] [pid 499145:tid 499328] [client 158.23.147.79:53562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPkl1JNq1G5uRhTNnsxcAAAADU"]
[Sun Aug 30 03:06:47.757746 2026] [security2:error] [pid 499751:tid 499986] [client 4.205.62.107:4645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/124.php"] [unique_id "apPklzmmjdkPfMeJsKOzxQAAA_4"]
[Sun Aug 30 03:06:47.762160 2026] [security2:error] [pid 500253:tid 500388] [client 20.48.251.3:56354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/cxc.php"] [unique_id "apPkl1mmXVd4kRvS-FD-zgAAAZI"]
[Sun Aug 30 03:06:47.805110 2026] [security2:error] [pid 500253:tid 500440] [client 20.104.18.15:28643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/btx25.php"] [unique_id "apPkl1mmXVd4kRvS-FD-4QAAAcY"]
[Sun Aug 30 03:06:47.811868 2026] [security2:error] [pid 499145:tid 499388] [client 20.104.50.220:46881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/upload.php"] [unique_id "apPkl1JNq1G5uRhTNnsxjQAAAHE"]
[Sun Aug 30 03:06:47.814037 2026] [authz_core:error] [pid 499145:tid 499353] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdpkg
[Sun Aug 30 03:06:47.814517 2026] [authz_core:error] [pid 499145:tid 499353] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdpkg
[Sun Aug 30 03:06:47.825006 2026] [authz_core:error] [pid 499145:tid 499367] [client 66.249.66.42:42900] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:47.825330 2026] [authz_core:error] [pid 499145:tid 499367] [client 66.249.66.42:42900] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:47.831017 2026] [security2:error] [pid 499145:tid 499398] [client 158.23.147.79:62494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-content/packed.php"] [unique_id "apPkl1JNq1G5uRhTNnsxnQAAAHs"]
[Sun Aug 30 03:06:47.835846 2026] [security2:error] [pid 500253:tid 500428] [client 158.23.147.79:53535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/lock.php"] [unique_id "apPkl1mmXVd4kRvS-FD-5wAAAbo"]
[Sun Aug 30 03:06:47.847460 2026] [security2:error] [pid 500253:tid 500451] [client 20.104.50.220:17288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/zoro.php"] [unique_id "apPkl1mmXVd4kRvS-FD-6AAAAdE"]
[Sun Aug 30 03:06:47.863302 2026] [security2:error] [pid 499145:tid 499386] [client 20.63.81.20:43358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/ops.php"] [unique_id "apPkl1JNq1G5uRhTNnsxrQAAAG8"]
[Sun Aug 30 03:06:47.877929 2026] [security2:error] [pid 499145:tid 499322] [client 20.104.18.15:23456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/images.php"] [unique_id "apPkl1JNq1G5uRhTNnsxtQAAAC8"]
[Sun Aug 30 03:06:47.895119 2026] [authz_core:error] [pid 499145:tid 499396] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:47.895396 2026] [authz_core:error] [pid 499145:tid 499396] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:47.912413 2026] [security2:error] [pid 499145:tid 499340] [client 20.104.50.220:33327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/help.php"] [unique_id "apPkl1JNq1G5uRhTNnsxwwAAAEE"]
[Sun Aug 30 03:06:47.916493 2026] [security2:error] [pid 499145:tid 499337] [client 4.205.62.107:58309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/avim.php"] [unique_id "apPkl1JNq1G5uRhTNnsxxwAAAD4"]
[Sun Aug 30 03:06:47.928833 2026] [security2:error] [pid 499145:tid 499332] [client 158.23.147.79:53553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/index/function.php"] [unique_id "apPkl1JNq1G5uRhTNnsxzAAAADk"]
[Sun Aug 30 03:06:47.935857 2026] [security2:error] [pid 499145:tid 499344] [client 158.23.147.79:54602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-includes/content.php"] [unique_id "apPkl1JNq1G5uRhTNnsx1AAAAEU"]
[Sun Aug 30 03:06:47.958280 2026] [security2:error] [pid 499145:tid 499285] [client 158.23.147.79:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-l0gin.php"] [unique_id "apPkl1JNq1G5uRhTNnsx5AAAAAo"]
[Sun Aug 30 03:06:47.962706 2026] [security2:error] [pid 500253:tid 500496] [client 20.104.18.15:13688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/file31.php"] [unique_id "apPkl1mmXVd4kRvS-FD--wAAAf4"]
[Sun Aug 30 03:06:47.965076 2026] [security2:error] [pid 500253:tid 500498] [client 20.48.251.3:4717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/aws_sdk_settings.php"] [unique_id "apPkl1mmXVd4kRvS-FD-_AAAAgA"]
[Sun Aug 30 03:06:47.970673 2026] [authz_core:error] [pid 499145:tid 499352] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZW
[Sun Aug 30 03:06:47.970919 2026] [authz_core:error] [pid 499145:tid 499352] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZW
[Sun Aug 30 03:06:47.991076 2026] [security2:error] [pid 499145:tid 499375] [client 20.63.81.20:43275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPkl1JNq1G5uRhTNnsx-QAAAGQ"]
[Sun Aug 30 03:06:48.012605 2026] [security2:error] [pid 500253:tid 500404] [client 68.155.159.216:61674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-admin/maint/index.php"] [unique_id "apPkmFmmXVd4kRvS-FD_EQAAAaI"]
[Sun Aug 30 03:06:48.018298 2026] [authz_core:error] [pid 499145:tid 499276] [client 66.249.66.72:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:48.018556 2026] [authz_core:error] [pid 499145:tid 499276] [client 66.249.66.72:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:48.065374 2026] [security2:error] [pid 500253:tid 500467] [client 20.104.50.220:5899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/ehszwsab.php"] [unique_id "apPkmFmmXVd4kRvS-FD_JgAAAeE"]
[Sun Aug 30 03:06:48.065395 2026] [security2:error] [pid 500253:tid 500460] [client 158.23.147.79:62585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apPkmFmmXVd4kRvS-FD_JwAAAdo"]
[Sun Aug 30 03:06:48.120953 2026] [security2:error] [pid 500253:tid 500399] [client 20.63.81.20:43315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPkmFmmXVd4kRvS-FD_PQAAAZ0"]
[Sun Aug 30 03:06:48.142481 2026] [security2:error] [pid 500253:tid 500481] [client 4.205.62.107:51764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/params.php"] [unique_id "apPkmFmmXVd4kRvS-FD_RgAAAe8"]
[Sun Aug 30 03:06:48.145291 2026] [security2:error] [pid 500253:tid 500385] [client 20.151.200.44:37858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/ca.php"] [unique_id "apPkmFmmXVd4kRvS-FD_RwAAAY8"]
[Sun Aug 30 03:06:48.169970 2026] [authz_core:error] [pid 499145:tid 499372] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:48.170299 2026] [authz_core:error] [pid 499145:tid 499372] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:48.208546 2026] [authz_core:error] [pid 499145:tid 499312] [client 66.249.66.203:46614] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:48.209053 2026] [authz_core:error] [pid 499145:tid 499312] [client 66.249.66.203:46614] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:48.210073 2026] [security2:error] [pid 499751:tid 499936] [client 158.23.147.79:54611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/.well-known/content.php"] [unique_id "apPkmDmmjdkPfMeJsKO0JgAAA8w"]
[Sun Aug 30 03:06:48.250002 2026] [security2:error] [pid 499751:tid 500002] [client 20.63.81.20:43372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/about.php"] [unique_id "apPkmDmmjdkPfMeJsKO0MgAABA4"]
[Sun Aug 30 03:06:48.260007 2026] [security2:error] [pid 500253:tid 500471] [client 20.104.18.15:43961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/bo.php"] [unique_id "apPkmFmmXVd4kRvS-FD_cQAAAeU"]
[Sun Aug 30 03:06:48.269477 2026] [authz_core:error] [pid 499145:tid 499400] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:48.269973 2026] [authz_core:error] [pid 499145:tid 499400] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:48.286041 2026] [security2:error] [pid 500253:tid 500417] [client 20.151.200.44:47303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/im.php"] [unique_id "apPkmFmmXVd4kRvS-FD_hAAAAa8"]
[Sun Aug 30 03:06:48.287454 2026] [security2:error] [pid 499751:tid 499978] [client 20.151.200.44:27265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/Contrller.php"] [unique_id "apPkmDmmjdkPfMeJsKO0PwAAA_Y"]
[Sun Aug 30 03:06:48.297303 2026] [security2:error] [pid 500253:tid 500506] [client 158.23.147.79:54652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-admin/css/index.php"] [unique_id "apPkmFmmXVd4kRvS-FD_jwAAAgg"]
[Sun Aug 30 03:06:48.315213 2026] [security2:error] [pid 499751:tid 499985] [client 20.104.50.220:51531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/jpg.php"] [unique_id "apPkmDmmjdkPfMeJsKO0QgAAA_0"]
[Sun Aug 30 03:06:48.326188 2026] [security2:error] [pid 500253:tid 500448] [client 4.205.62.107:27318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/wdf.php"] [unique_id "apPkmFmmXVd4kRvS-FD_mAAAAc4"]
[Sun Aug 30 03:06:48.364254 2026] [security2:error] [pid 500253:tid 500458] [client 20.104.50.220:52843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/cargo.php"] [unique_id "apPkmFmmXVd4kRvS-FD_pwAAAdg"]
[Sun Aug 30 03:06:48.377911 2026] [security2:error] [pid 499751:tid 500016] [client 4.205.62.107:63758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/bigdump.php"] [unique_id "apPkmDmmjdkPfMeJsKO0WAAABBw"]
[Sun Aug 30 03:06:48.382304 2026] [security2:error] [pid 500253:tid 500408] [client 20.63.81.20:43273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/admin.php/admin.php"] [unique_id "apPkmFmmXVd4kRvS-FD_sQAAAaY"]
[Sun Aug 30 03:06:48.405930 2026] [authz_core:error] [pid 500253:tid 500452] [client 216.73.216.128:5993] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:48.406447 2026] [authz_core:error] [pid 500253:tid 500452] [client 216.73.216.128:5993] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:48.444789 2026] [authz_core:error] [pid 499145:tid 499361] [client 216.73.216.128:50607] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:48.445270 2026] [authz_core:error] [pid 499145:tid 499361] [client 216.73.216.128:50607] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:48.447273 2026] [security2:error] [pid 499751:tid 500017] [client 20.104.50.220:61971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/xindex.php"] [unique_id "apPkmDmmjdkPfMeJsKO0ewAABB0"]
[Sun Aug 30 03:06:48.451247 2026] [security2:error] [pid 500253:tid 500471] [client 158.23.147.79:53530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/cong.php"] [unique_id "apPkmFmmXVd4kRvS-FD_0gAAAeU"]
[Sun Aug 30 03:06:48.476206 2026] [security2:error] [pid 500253:tid 500393] [client 4.205.62.107:64500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/aws_config.php"] [unique_id "apPkmFmmXVd4kRvS-FD_4gAAAZc"]
[Sun Aug 30 03:06:48.489159 2026] [security2:error] [pid 500253:tid 500464] [client 68.155.159.216:65491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/sad/about.php"] [unique_id "apPkmFmmXVd4kRvS-FD_6wAAAd4"]
[Sun Aug 30 03:06:48.500207 2026] [security2:error] [pid 499145:tid 499323] [client 20.151.200.44:37837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/pb.php"] [unique_id "apPkmFJNq1G5uRhTNnsyvAAAADA"]
[Sun Aug 30 03:06:48.509161 2026] [authz_core:error] [pid 499145:tid 499335] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZW
[Sun Aug 30 03:06:48.509570 2026] [authz_core:error] [pid 499145:tid 499335] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZW
[Sun Aug 30 03:06:48.518410 2026] [security2:error] [pid 499145:tid 499304] [client 20.63.81.20:43283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/media.php"] [unique_id "apPkmFJNq1G5uRhTNnsywQAAAB0"]
[Sun Aug 30 03:06:48.522002 2026] [security2:error] [pid 499145:tid 499388] [client 20.48.251.3:7094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/public/wp-blog.php"] [unique_id "apPkmFJNq1G5uRhTNnsywwAAAHE"]
[Sun Aug 30 03:06:48.575921 2026] [authz_core:error] [pid 499751:tid 499971] [client 66.249.66.67:48240] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:48.576185 2026] [authz_core:error] [pid 499751:tid 499971] [client 66.249.66.67:48240] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:48.590359 2026] [authz_core:error] [pid 499751:tid 500021] [client 66.249.66.39:49728] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:48.590669 2026] [authz_core:error] [pid 499751:tid 500021] [client 66.249.66.39:49728] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:48.598722 2026] [security2:error] [pid 500253:tid 500438] [client 4.205.62.107:65360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/pass4.php"] [unique_id "apPkmFmmXVd4kRvS-FAADgAAAcQ"]
[Sun Aug 30 03:06:48.602356 2026] [security2:error] [pid 500253:tid 500392] [client 158.23.147.79:62538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPkmFmmXVd4kRvS-FAADwAAAZY"]
[Sun Aug 30 03:06:48.642152 2026] [security2:error] [pid 500253:tid 500464] [client 20.104.18.15:34814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/media.php"] [unique_id "apPkmFmmXVd4kRvS-FAAEwAAAd4"]
[Sun Aug 30 03:06:48.646102 2026] [security2:error] [pid 499145:tid 499281] [client 20.63.81.20:43384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/mac.php"] [unique_id "apPkmFJNq1G5uRhTNnsy7wAAAAY"]
[Sun Aug 30 03:06:48.697373 2026] [security2:error] [pid 500253:tid 500463] [client 20.151.200.44:27313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/file66.php"] [unique_id "apPkmFmmXVd4kRvS-FAAHwAAAd0"]
[Sun Aug 30 03:06:48.709476 2026] [security2:error] [pid 499751:tid 499943] [client 68.155.159.216:56431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-content/x/index.php"] [unique_id "apPkmDmmjdkPfMeJsKO00QAAA9M"]
[Sun Aug 30 03:06:48.710858 2026] [security2:error] [pid 499751:tid 499967] [client 20.104.50.220:27529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/misc.php"] [unique_id "apPkmDmmjdkPfMeJsKO00gAAA-s"]
[Sun Aug 30 03:06:48.714037 2026] [authz_core:error] [pid 499145:tid 499393] [client 216.73.216.128:63106] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:48.714345 2026] [authz_core:error] [pid 499145:tid 499393] [client 216.73.216.128:63106] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:48.723200 2026] [security2:error] [pid 500253:tid 500443] [client 4.205.62.107:64035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/66.php"] [unique_id "apPkmFmmXVd4kRvS-FAAMgAAAck"]
[Sun Aug 30 03:06:48.728306 2026] [security2:error] [pid 499751:tid 499999] [client 158.23.147.79:62475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/ans.php"] [unique_id "apPkmDmmjdkPfMeJsKO01AAABAs"]
[Sun Aug 30 03:06:48.759756 2026] [security2:error] [pid 500253:tid 500414] [client 158.23.147.79:54617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-admin/images/index.php"] [unique_id "apPkmFmmXVd4kRvS-FAAPwAAAaw"]
[Sun Aug 30 03:06:48.766266 2026] [security2:error] [pid 500253:tid 500494] [client 4.205.62.107:2990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/rpk.php"] [unique_id "apPkmFmmXVd4kRvS-FAARQAAAfw"]
[Sun Aug 30 03:06:48.774581 2026] [security2:error] [pid 499751:tid 499949] [client 20.151.200.44:37785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/pk.php"] [unique_id "apPkmDmmjdkPfMeJsKO05QAAA9k"]
[Sun Aug 30 03:06:48.774809 2026] [authz_core:error] [pid 499145:tid 499376] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:48.775267 2026] [authz_core:error] [pid 499145:tid 499376] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:48.780359 2026] [security2:error] [pid 499751:tid 499909] [client 20.63.81.20:43391] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.seaofqi.net"] [uri "/1.php"] [unique_id "apPkmDmmjdkPfMeJsKO06gAAA7I"]
[Sun Aug 30 03:06:48.780435 2026] [security2:error] [pid 499751:tid 499909] [client 20.63.81.20:43391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/1.php"] [unique_id "apPkmDmmjdkPfMeJsKO06gAAA7I"]
[Sun Aug 30 03:06:48.791932 2026] [security2:error] [pid 500253:tid 500465] [client 20.104.18.15:33708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/sushi.php"] [unique_id "apPkmFmmXVd4kRvS-FAAWQAAAd8"]
[Sun Aug 30 03:06:48.795175 2026] [security2:error] [pid 499145:tid 499279] [client 20.48.251.3:49981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/channels.php"] [unique_id "apPkmFJNq1G5uRhTNnszGwAAAAQ"]
[Sun Aug 30 03:06:48.825585 2026] [security2:error] [pid 500253:tid 500437] [client 20.104.50.220:31820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/kepo.php"] [unique_id "apPkmFmmXVd4kRvS-FAAbAAAAcM"]
[Sun Aug 30 03:06:48.826060 2026] [security2:error] [pid 500253:tid 500460] [client 68.155.159.216:61411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPkmFmmXVd4kRvS-FAAbQAAAdo"]
[Sun Aug 30 03:06:48.833707 2026] [security2:error] [pid 500253:tid 500471] [client 20.104.50.220:29365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/bejak.php"] [unique_id "apPkmFmmXVd4kRvS-FAAdAAAAeU"]
[Sun Aug 30 03:06:48.834467 2026] [security2:error] [pid 500253:tid 500471] [client 158.23.147.79:52937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/worksec.php"] [unique_id "apPkmFmmXVd4kRvS-FAAdgAAAeU"]
[Sun Aug 30 03:06:48.843921 2026] [security2:error] [pid 499751:tid 500012] [client 4.205.62.107:22941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/gk.php"] [unique_id "apPkmDmmjdkPfMeJsKO1AgAABBg"]
[Sun Aug 30 03:06:48.877197 2026] [security2:error] [pid 499751:tid 499930] [client 68.155.159.216:54017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-content/x.php"] [unique_id "apPkmDmmjdkPfMeJsKO1BgAAA8Y"]
[Sun Aug 30 03:06:48.889340 2026] [security2:error] [pid 500253:tid 500400] [client 4.205.62.107:18768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/apikeys.php"] [unique_id "apPkmFmmXVd4kRvS-FAAkAAAAZ4"]
[Sun Aug 30 03:06:48.894517 2026] [security2:error] [pid 500253:tid 500396] [client 20.48.251.3:7028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/old_phpinfo.php"] [unique_id "apPkmFmmXVd4kRvS-FAAkQAAAZo"]
[Sun Aug 30 03:06:48.896806 2026] [security2:error] [pid 499145:tid 499353] [client 4.205.62.107:4126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/test1.php"] [unique_id "apPkmFJNq1G5uRhTNnszOwAAAE4"]
[Sun Aug 30 03:06:48.912315 2026] [security2:error] [pid 500253:tid 500434] [client 20.63.81.20:43293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/classwithtostring.php"] [unique_id "apPkmFmmXVd4kRvS-FAAmwAAAcA"]
[Sun Aug 30 03:06:48.915443 2026] [security2:error] [pid 500253:tid 500483] [client 158.23.147.79:44266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-includes/js/index.php"] [unique_id "apPkmFmmXVd4kRvS-FAAnAAAAfE"]
[Sun Aug 30 03:06:48.947088 2026] [security2:error] [pid 500253:tid 500435] [client 20.104.18.15:28505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/SDsadqwrf.php"] [unique_id "apPkmFmmXVd4kRvS-FAAqQAAAcE"]
[Sun Aug 30 03:06:48.947308 2026] [security2:error] [pid 500253:tid 500385] [client 20.48.251.3:56339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/oiko6u.php"] [unique_id "apPkmFmmXVd4kRvS-FAAqgAAAY8"]
[Sun Aug 30 03:06:48.958506 2026] [security2:error] [pid 500253:tid 500401] [client 20.104.50.220:46380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/ups.php"] [unique_id "apPkmFmmXVd4kRvS-FAAtAAAAZ8"]
[Sun Aug 30 03:06:48.972054 2026] [security2:error] [pid 500253:tid 500416] [client 20.104.50.220:17292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wm.php"] [unique_id "apPkmFmmXVd4kRvS-FAAuAAAAa4"]
[Sun Aug 30 03:06:48.981001 2026] [security2:error] [pid 500253:tid 500484] [client 20.151.200.44:37791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/ft.php"] [unique_id "apPkmFmmXVd4kRvS-FAAvgAAAfI"]
[Sun Aug 30 03:06:48.992611 2026] [security2:error] [pid 500253:tid 500410] [client 158.23.147.79:52989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/x.php"] [unique_id "apPkmFmmXVd4kRvS-FAAyAAAAag"]
[Sun Aug 30 03:06:49.019283 2026] [security2:error] [pid 499751:tid 499992] [client 20.104.18.15:23428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/ops.php"] [unique_id "apPkmTmmjdkPfMeJsKO1JAAABAQ"]
[Sun Aug 30 03:06:49.021142 2026] [authz_core:error] [pid 499145:tid 499293] [client 216.73.216.128:50607] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:49.021410 2026] [authz_core:error] [pid 499145:tid 499293] [client 216.73.216.128:50607] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:49.034071 2026] [authz_core:error] [pid 499145:tid 499339] [client 66.249.66.37:38707] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:49.034521 2026] [authz_core:error] [pid 499145:tid 499339] [client 66.249.66.37:38707] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:49.042745 2026] [security2:error] [pid 500253:tid 500400] [client 20.63.81.20:43314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp-ws68.php"] [unique_id "apPkmVmmXVd4kRvS-FAA5gAAAZ4"]
[Sun Aug 30 03:06:49.068961 2026] [authz_core:error] [pid 500253:tid 500451] [client 66.249.66.197:61661] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:49.069458 2026] [authz_core:error] [pid 500253:tid 500451] [client 66.249.66.197:61661] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:49.098295 2026] [security2:error] [pid 500253:tid 500463] [client 158.23.147.79:54600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-includes/index.php"] [unique_id "apPkmVmmXVd4kRvS-FABEAAAAd0"]
[Sun Aug 30 03:06:49.104927 2026] [security2:error] [pid 500253:tid 500416] [client 20.104.18.15:13691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/dk.php"] [unique_id "apPkmVmmXVd4kRvS-FABEgAAAa4"]
[Sun Aug 30 03:06:49.115015 2026] [security2:error] [pid 499751:tid 500004] [client 20.48.251.3:4690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/setup-config.php"] [unique_id "apPkmTmmjdkPfMeJsKO1QwAABBA"]
[Sun Aug 30 03:06:49.129707 2026] [authz_core:error] [pid 499145:tid 499303] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_BW
[Sun Aug 30 03:06:49.130003 2026] [authz_core:error] [pid 499145:tid 499303] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_BW
[Sun Aug 30 03:06:49.165679 2026] [security2:error] [pid 499751:tid 499905] [client 158.23.147.79:62565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-content/x.php"] [unique_id "apPkmTmmjdkPfMeJsKO1VQAAA64"]
[Sun Aug 30 03:06:49.172685 2026] [security2:error] [pid 500253:tid 500510] [client 20.63.81.20:43371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/simple.php"] [unique_id "apPkmVmmXVd4kRvS-FABLgAAAgw"]
[Sun Aug 30 03:06:49.174534 2026] [security2:error] [pid 500253:tid 500409] [client 68.155.159.216:63522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/dropdown.php"] [unique_id "apPkmVmmXVd4kRvS-FABMAAAAac"]
[Sun Aug 30 03:06:49.195988 2026] [security2:error] [pid 499145:tid 499360] [client 216.73.216.128:45526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts2/updateconf"] [unique_id "apPkmVJNq1G5uRhTNnszmAAAAFU"]
[Sun Aug 30 03:06:49.214835 2026] [security2:error] [pid 499751:tid 500006] [client 20.104.50.220:6139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/meta.php"] [unique_id "apPkmTmmjdkPfMeJsKO1YQAABBI"]
[Sun Aug 30 03:06:49.264059 2026] [security2:error] [pid 500253:tid 500463] [client 158.23.147.79:63292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPkmVmmXVd4kRvS-FABYgAAAd0"]
[Sun Aug 30 03:06:49.266776 2026] [authz_core:error] [pid 500253:tid 500393] [client 66.249.66.37:49065] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:49.267026 2026] [authz_core:error] [pid 500253:tid 500393] [client 66.249.66.37:49065] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:49.295720 2026] [security2:error] [pid 499145:tid 499329] [client 4.205.62.107:52151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/gjm.php"] [unique_id "apPkmVJNq1G5uRhTNnszzQAAADY"]
[Sun Aug 30 03:06:49.303196 2026] [security2:error] [pid 499751:tid 499994] [client 20.63.81.20:43320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/aaa.php"] [unique_id "apPkmTmmjdkPfMeJsKO1cQAABAY"]
[Sun Aug 30 03:06:49.318569 2026] [security2:error] [pid 499145:tid 499347] [client 20.151.200.44:37790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/wp-ver.php"] [unique_id "apPkmVJNq1G5uRhTNnsz2wAAAEg"]
[Sun Aug 30 03:06:49.322167 2026] [authz_core:error] [pid 499145:tid 499360] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdpkg
[Sun Aug 30 03:06:49.322582 2026] [authz_core:error] [pid 499145:tid 499360] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdpkg
[Sun Aug 30 03:06:49.401522 2026] [authz_core:error] [pid 500253:tid 500399] [client 66.249.66.197:63139] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:49.401981 2026] [authz_core:error] [pid 500253:tid 500399] [client 66.249.66.197:63139] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:49.417197 2026] [security2:error] [pid 500253:tid 500470] [client 68.155.159.216:63982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPkmVmmXVd4kRvS-FABsAAAAeQ"]
[Sun Aug 30 03:06:49.425504 2026] [security2:error] [pid 499751:tid 499905] [client 20.104.18.15:43922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/44.php"] [unique_id "apPkmTmmjdkPfMeJsKO1kwAAA64"]
[Sun Aug 30 03:06:49.443376 2026] [authz_core:error] [pid 500253:tid 500459] [client 66.249.66.39:49657] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:49.443663 2026] [authz_core:error] [pid 500253:tid 500459] [client 66.249.66.39:49657] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:49.515174 2026] [security2:error] [pid 500253:tid 500476] [client 4.205.62.107:60593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/wdf.php"] [unique_id "apPkmVmmXVd4kRvS-FAB4QAAAeo"]
[Sun Aug 30 03:06:49.531574 2026] [authz_core:error] [pid 499145:tid 499322] [client 216.73.216.128:63106] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:49.532022 2026] [authz_core:error] [pid 499145:tid 499322] [client 216.73.216.128:63106] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:49.536292 2026] [security2:error] [pid 500253:tid 500471] [client 20.104.50.220:51614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/jak.php"] [unique_id "apPkmVmmXVd4kRvS-FAB6AAAAeU"]
[Sun Aug 30 03:06:49.538630 2026] [security2:error] [pid 499751:tid 499906] [client 20.151.200.44:55733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/wk/index.php"] [unique_id "apPkmTmmjdkPfMeJsKO1zAAAA68"]
[Sun Aug 30 03:06:49.545353 2026] [security2:error] [pid 500253:tid 500464] [client 20.104.50.220:29322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/col1.php"] [unique_id "apPkmVmmXVd4kRvS-FAB8AAAAd4"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:06:49.553536 2026] [security2:error] [pid 500253:tid 500451] [client 158.23.147.79:62582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/log-mama/function.php"] [unique_id "apPkmVmmXVd4kRvS-FAB9gAAAdE"]
[Sun Aug 30 03:06:49.585914 2026] [security2:error] [pid 499145:tid 499387] [client 20.104.50.220:61404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wiki-index.php"] [unique_id "apPkmVJNq1G5uRhTNns0UAAAAHA"]
[Sun Aug 30 03:06:49.616089 2026] [authz_core:error] [pid 500253:tid 500421] [client 66.249.66.64:41985] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:49.616493 2026] [authz_core:error] [pid 500253:tid 500421] [client 66.249.66.64:41985] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:49.622164 2026] [security2:error] [pid 500253:tid 500284] [remote 20.237.251.56:9868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.251.237.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myorangedentist.com"] [uri "/wp-login.php"] [unique_id "apPkmVmmXVd4kRvS-FACGwAB9xw"]
[Sun Aug 30 03:06:49.628201 2026] [security2:error] [pid 499145:tid 499351] [client 4.205.62.107:64497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/dialog.php"] [unique_id "apPkmVJNq1G5uRhTNns0XQAAAEw"]
[Sun Aug 30 03:06:49.630790 2026] [authz_core:error] [pid 499145:tid 499289] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_GB
[Sun Aug 30 03:06:49.631042 2026] [authz_core:error] [pid 499145:tid 499289] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_GB
[Sun Aug 30 03:06:49.633945 2026] [security2:error] [pid 500253:tid 500415] [client 68.155.159.216:12333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/admin.php"] [unique_id "apPkmVmmXVd4kRvS-FACIQAAAa0"]
[Sun Aug 30 03:06:49.642611 2026] [authz_core:error] [pid 500253:tid 500394] [client 216.73.216.128:21183] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:49.643055 2026] [authz_core:error] [pid 500253:tid 500394] [client 216.73.216.128:21183] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:49.649137 2026] [security2:error] [pid 500253:tid 500503] [client 84.54.44.204:59221] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "84.54.44.204" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "myediblecravings.com"] [uri "/wp-comments-post.php"] [unique_id "apPkmVmmXVd4kRvS-FACKQAAAgU"], referer: http://myediblecravings.com/menu-list/desserts-baking/cookies/
[Sun Aug 30 03:06:49.649227 2026] [security2:error] [pid 500253:tid 500503] [client 84.54.44.204:59221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "myediblecravings.com"] [uri "/wp-comments-post.php"] [unique_id "apPkmVmmXVd4kRvS-FACKQAAAgU"], referer: http://myediblecravings.com/menu-list/desserts-baking/cookies/
[Sun Aug 30 03:06:49.649740 2026] [security2:error] [pid 500253:tid 500403] [client 4.205.62.107:32063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/nw.php"] [unique_id "apPkmVmmXVd4kRvS-FACKwAAAaE"]
[Sun Aug 30 03:06:49.657377 2026] [authz_core:error] [pid 499751:tid 499946] [client 66.249.66.78:60082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:49.657680 2026] [authz_core:error] [pid 499751:tid 499946] [client 66.249.66.78:60082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:49.659123 2026] [authz_core:error] [pid 499145:tid 499299] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:49.659408 2026] [authz_core:error] [pid 499145:tid 499299] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:49.711507 2026] [security2:error] [pid 500253:tid 500410] [client 158.23.147.79:54269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-content/index.php"] [unique_id "apPkmVmmXVd4kRvS-FACRgAAAag"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:06:49.765146 2026] [security2:error] [pid 500253:tid 500462] [client 4.205.62.107:26771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/bb.php"] [unique_id "apPkmVmmXVd4kRvS-FACZQAAAdw"]
[Sun Aug 30 03:06:49.772873 2026] [security2:error] [pid 499145:tid 499375] [client 20.151.200.44:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/ah24.php"] [unique_id "apPkmVJNq1G5uRhTNns0jgAAAGQ"]
[Sun Aug 30 03:06:49.777565 2026] [security2:error] [pid 499145:tid 499365] [client 20.48.251.3:6470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/php-details.php"] [unique_id "apPkmVJNq1G5uRhTNns0kQAAAFo"]
[Sun Aug 30 03:06:49.786683 2026] [security2:error] [pid 499751:tid 499964] [client 158.23.147.79:52986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/bk/index.php"] [unique_id "apPkmTmmjdkPfMeJsKO2HwAAA-g"]
[Sun Aug 30 03:06:49.788257 2026] [security2:error] [pid 499145:tid 499366] [client 20.104.18.15:34779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/adminfuns.php"] [unique_id "apPkmVJNq1G5uRhTNns0lQAAAFs"]
[Sun Aug 30 03:06:49.799391 2026] [authz_core:error] [pid 500253:tid 500503] [client 216.73.216.128:4988] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:49.799843 2026] [authz_core:error] [pid 500253:tid 500503] [client 216.73.216.128:4988] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:49.803344 2026] [authz_core:error] [pid 499145:tid 499288] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:49.803751 2026] [authz_core:error] [pid 499145:tid 499288] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:49.806866 2026] [security2:error] [pid 499751:tid 499966] [client 20.63.81.20:43342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/shiny.php"] [unique_id "apPkmTmmjdkPfMeJsKO2KQAAA-o"]
[Sun Aug 30 03:06:49.813063 2026] [security2:error] [pid 499751:tid 499905] [client 4.205.62.107:65387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/cu.php"] [unique_id "apPkmTmmjdkPfMeJsKO2LwAAA64"]
[Sun Aug 30 03:06:49.823593 2026] [security2:error] [pid 500253:tid 500288] [remote 20.237.251.56:9868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.251.237.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myorangedentist.com"] [uri "/wp-login.php"] [unique_id "apPkmVmmXVd4kRvS-FACdAABoSA"], referer: https://myorangedentist.com/wp-login.php
[Sun Aug 30 03:06:49.848377 2026] [authz_core:error] [pid 499145:tid 499388] [client 66.249.66.76:38091] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:49.848712 2026] [authz_core:error] [pid 499145:tid 499388] [client 66.249.66.76:38091] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:49.852154 2026] [security2:error] [pid 500253:tid 500395] [client 20.104.50.220:27524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/global.php"] [unique_id "apPkmVmmXVd4kRvS-FACggAAAZk"]
[Sun Aug 30 03:06:49.867105 2026] [security2:error] [pid 500253:tid 500473] [client 68.155.159.216:56403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apPkmVmmXVd4kRvS-FACiAAAAec"]
[Sun Aug 30 03:06:49.868586 2026] [security2:error] [pid 500253:tid 500471] [client 4.205.62.107:62116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/admin.php"] [unique_id "apPkmVmmXVd4kRvS-FACiQAAAeU"]
[Sun Aug 30 03:06:49.877560 2026] [security2:error] [pid 499751:tid 499963] [client 20.151.200.44:46997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/wp-content/admin.php"] [unique_id "apPkmTmmjdkPfMeJsKO2TgAAA-c"]
[Sun Aug 30 03:06:49.887851 2026] [security2:error] [pid 500253:tid 500446] [client 20.151.200.44:24627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/file.php"] [unique_id "apPkmVmmXVd4kRvS-FACkwAAAcw"]
[Sun Aug 30 03:06:49.891520 2026] [security2:error] [pid 500253:tid 500504] [client 158.23.147.79:53520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/mah.php"] [unique_id "apPkmVmmXVd4kRvS-FAClgAAAgY"]
[Sun Aug 30 03:06:49.906197 2026] [security2:error] [pid 499751:tid 499921] [client 4.205.62.107:2755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/saml.php"] [unique_id "apPkmTmmjdkPfMeJsKO2UwAAA70"]
[Sun Aug 30 03:06:49.937034 2026] [security2:error] [pid 499751:tid 499950] [client 20.63.81.20:43351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/goods.php"] [unique_id "apPkmTmmjdkPfMeJsKO2WAAAA9o"]
[Sun Aug 30 03:06:49.942551 2026] [security2:error] [pid 500253:tid 500473] [client 20.48.251.3:12050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/zz.php"] [unique_id "apPkmVmmXVd4kRvS-FACqgAAAec"]
[Sun Aug 30 03:06:49.959391 2026] [security2:error] [pid 500253:tid 500401] [client 68.155.159.216:60883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/makeasmtp.php"] [unique_id "apPkmVmmXVd4kRvS-FACtAAAAZ8"]
[Sun Aug 30 03:06:49.979957 2026] [security2:error] [pid 500253:tid 500454] [client 20.104.50.220:32260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/kk.php"] [unique_id "apPkmVmmXVd4kRvS-FACwgAAAdQ"]
[Sun Aug 30 03:06:49.994161 2026] [security2:error] [pid 499145:tid 499387] [client 20.104.50.220:29158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/idca_shell.php"] [unique_id "apPkmVJNq1G5uRhTNns03wAAAHA"]
[Sun Aug 30 03:06:49.997334 2026] [security2:error] [pid 500253:tid 500486] [client 4.205.62.107:22590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/god.php"] [unique_id "apPkmVmmXVd4kRvS-FACyAAAAfQ"]
[Sun Aug 30 03:06:50.019305 2026] [security2:error] [pid 499751:tid 499894] [client 158.23.147.79:63274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.redlandspawninc.com"] [uri "/first.php"] [unique_id "apPkmjmmjdkPfMeJsKO2cgAAA6M"]
[Sun Aug 30 03:06:50.028890 2026] [security2:error] [pid 500253:tid 500463] [client 20.104.18.15:33715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/manga.php"] [unique_id "apPkmlmmXVd4kRvS-FAC4QAAAd0"]
[Sun Aug 30 03:06:50.032354 2026] [security2:error] [pid 500253:tid 500481] [client 4.205.62.107:18949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/motu.php"] [unique_id "apPkmlmmXVd4kRvS-FAC5AAAAe8"]
[Sun Aug 30 03:06:50.032623 2026] [security2:error] [pid 500253:tid 500411] [client 4.205.62.107:5072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/bigdump.php"] [unique_id "apPkmlmmXVd4kRvS-FAC5QAAAak"]
[Sun Aug 30 03:06:50.034583 2026] [security2:error] [pid 500253:tid 500499] [client 20.48.251.3:7009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.belgradeplace.com"] [uri "/wp-act.php"] [unique_id "apPkmlmmXVd4kRvS-FAC5gAAAgE"]
[Sun Aug 30 03:06:50.064436 2026] [security2:error] [pid 500253:tid 500462] [client 114.119.128.143:30729] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "emetech.com"] [uri "/index.php/component/k2/item/6-riot-gear-how-protesters-around-the-world-suit-up"] [unique_id "apPkmlmmXVd4kRvS-FAC-QAAAdw"], referer: http://emetech.com/index.php/component/k2/item/6-riot-gear-how-protesters-around-the-world-suit-up?start=89780
[Sun Aug 30 03:06:50.067125 2026] [security2:error] [pid 499751:tid 499964] [client 158.23.147.79:53522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/about/function.php"] [unique_id "apPkmjmmjdkPfMeJsKO2hAAAA-g"]
[Sun Aug 30 03:06:50.069275 2026] [security2:error] [pid 499751:tid 499963] [client 20.63.81.20:43327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/000.php/index.php"] [unique_id "apPkmjmmjdkPfMeJsKO2iAAAA-c"]
[Sun Aug 30 03:06:50.085927 2026] [security2:error] [pid 500253:tid 500481] [client 20.48.251.3:56373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/fraro.php"] [unique_id "apPkmlmmXVd4kRvS-FADCAAAAe8"]
[Sun Aug 30 03:06:50.087570 2026] [security2:error] [pid 500253:tid 500447] [client 20.104.18.15:28624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/BDKR28WP.php"] [unique_id "apPkmlmmXVd4kRvS-FADCQAAAc0"]
[Sun Aug 30 03:06:50.089832 2026] [security2:error] [pid 499751:tid 499985] [client 68.155.159.216:54099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPkmjmmjdkPfMeJsKO2lwAAA_0"]
[Sun Aug 30 03:06:50.098076 2026] [security2:error] [pid 500253:tid 500490] [client 20.104.50.220:46641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/usb.php"] [unique_id "apPkmlmmXVd4kRvS-FADDwAAAfg"]
[Sun Aug 30 03:06:50.107957 2026] [security2:error] [pid 500253:tid 500471] [client 20.104.50.220:16708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/bajah.php"] [unique_id "apPkmlmmXVd4kRvS-FADFgAAAeU"]
[Sun Aug 30 03:06:50.155179 2026] [security2:error] [pid 499751:tid 499992] [client 20.104.18.15:23543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/coffexium.php"] [unique_id "apPkmjmmjdkPfMeJsKO2qQAABAQ"]
[Sun Aug 30 03:06:50.198995 2026] [security2:error] [pid 499751:tid 499965] [client 20.63.81.20:43204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/Jcrop.php"] [unique_id "apPkmjmmjdkPfMeJsKO2tAAAA-k"]
[Sun Aug 30 03:06:50.207119 2026] [authz_core:error] [pid 499145:tid 499311] [client 216.73.216.128:63106] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:50.207651 2026] [authz_core:error] [pid 499145:tid 499311] [client 216.73.216.128:63106] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:50.214592 2026] [authz_core:error] [pid 499145:tid 499329] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NZ
[Sun Aug 30 03:06:50.214869 2026] [authz_core:error] [pid 499145:tid 499329] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NZ
[Sun Aug 30 03:06:50.252395 2026] [security2:error] [pid 500253:tid 500419] [client 20.48.251.3:4734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/wp-admin/sc.php"] [unique_id "apPkmlmmXVd4kRvS-FADegAAAbE"]
[Sun Aug 30 03:06:50.279729 2026] [security2:error] [pid 500253:tid 500480] [client 20.151.200.44:37834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPkmlmmXVd4kRvS-FADjAAAAe4"]
[Sun Aug 30 03:06:50.282848 2026] [authz_core:error] [pid 499751:tid 499974] [client 66.249.66.197:35404] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:50.283304 2026] [authz_core:error] [pid 499751:tid 499974] [client 66.249.66.197:35404] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:50.294398 2026] [authz_core:error] [pid 500253:tid 500472] [client 216.73.216.128:5993] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:50.294729 2026] [security2:error] [pid 500253:tid 500444] [client 20.104.18.15:13743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/ta.php"] [unique_id "apPkmlmmXVd4kRvS-FADlwAAAco"]
[Sun Aug 30 03:06:50.294842 2026] [authz_core:error] [pid 500253:tid 500472] [client 216.73.216.128:5993] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:50.328054 2026] [security2:error] [pid 500253:tid 500486] [client 20.63.81.20:43303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/35iDq8NAjLu.php"] [unique_id "apPkmlmmXVd4kRvS-FADsAAAAfQ"]
[Sun Aug 30 03:06:50.331015 2026] [authz_core:error] [pid 499145:tid 499291] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:50.331312 2026] [authz_core:error] [pid 499145:tid 499291] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:50.353193 2026] [security2:error] [pid 499751:tid 499976] [client 158.23.147.79:53566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-blog-header.php"] [unique_id "apPkmjmmjdkPfMeJsKO28QAAA_Q"]
[Sun Aug 30 03:06:50.363994 2026] [security2:error] [pid 500253:tid 500488] [client 20.104.49.130:63282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/wp.php"] [unique_id "apPkmlmmXVd4kRvS-FAD0QAAAfY"]
[Sun Aug 30 03:06:50.366361 2026] [security2:error] [pid 500253:tid 500441] [client 20.104.50.220:6087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/colleen986.php"] [unique_id "apPkmlmmXVd4kRvS-FAD0wAAAcc"]
[Sun Aug 30 03:06:50.386833 2026] [authz_core:error] [pid 499145:tid 499313] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:50.387138 2026] [authz_core:error] [pid 499145:tid 499313] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:50.390630 2026] [security2:error] [pid 500253:tid 500385] [client 158.23.147.79:53517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-includes/customize/index.php"] [unique_id "apPkmlmmXVd4kRvS-FAD5wAAAY8"]
[Sun Aug 30 03:06:50.433965 2026] [security2:error] [pid 500253:tid 500499] [client 20.104.50.220:33282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/high.php"] [unique_id "apPkmlmmXVd4kRvS-FAEEQAAAgE"]
[Sun Aug 30 03:06:50.460324 2026] [security2:error] [pid 499751:tid 499895] [client 20.63.81.20:43294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/btx25.php"] [unique_id "apPkmjmmjdkPfMeJsKO3KwAAA6Q"]
[Sun Aug 30 03:06:50.470198 2026] [security2:error] [pid 500253:tid 500470] [client 4.205.62.107:51761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/configuration.php"] [unique_id "apPkmlmmXVd4kRvS-FAEIQAAAeQ"]
[Sun Aug 30 03:06:50.473115 2026] [authz_core:error] [pid 499751:tid 500002] [client 66.249.66.35:55512] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:50.473433 2026] [authz_core:error] [pid 499751:tid 500002] [client 66.249.66.35:55512] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:50.494516 2026] [authz_core:error] [pid 500253:tid 500471] [client 66.249.66.43:44499] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:50.494845 2026] [authz_core:error] [pid 500253:tid 500471] [client 66.249.66.43:44499] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:50.499728 2026] [security2:error] [pid 500253:tid 500394] [client 68.155.159.216:63509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/sad/about.php"] [unique_id "apPkmlmmXVd4kRvS-FAENgAAAZg"]
[Sun Aug 30 03:06:50.532728 2026] [security2:error] [pid 499751:tid 499980] [client 68.155.159.216:61346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/goat.php"] [unique_id "apPkmjmmjdkPfMeJsKO3XAAAA_g"]
[Sun Aug 30 03:06:50.578707 2026] [authz_core:error] [pid 500253:tid 500437] [client 66.249.66.197:63139] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:50.579147 2026] [authz_core:error] [pid 500253:tid 500437] [client 66.249.66.197:63139] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:50.586728 2026] [security2:error] [pid 499751:tid 500013] [client 20.63.81.20:43305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/radio.php"] [unique_id "apPkmjmmjdkPfMeJsKO3ZwAABBk"]
[Sun Aug 30 03:06:50.600865 2026] [security2:error] [pid 500253:tid 500403] [client 20.104.18.15:44031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/h2.php"] [unique_id "apPkmlmmXVd4kRvS-FAEeAAAAaE"]
[Sun Aug 30 03:06:50.654466 2026] [security2:error] [pid 499751:tid 499999] [client 4.205.62.107:63555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/bb.php"] [unique_id "apPkmjmmjdkPfMeJsKO3cgAABAs"]
[Sun Aug 30 03:06:50.685003 2026] [security2:error] [pid 499751:tid 499987] [client 158.23.147.79:53506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apPkmjmmjdkPfMeJsKO3fwAAA_8"]
[Sun Aug 30 03:06:50.685782 2026] [security2:error] [pid 499751:tid 499964] [client 20.104.50.220:28683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/coli.php"] [unique_id "apPkmjmmjdkPfMeJsKO3gAAAA-g"]
[Sun Aug 30 03:06:50.686797 2026] [security2:error] [pid 499751:tid 499901] [client 20.104.50.220:63525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/image.php"] [unique_id "apPkmjmmjdkPfMeJsKO3ggAAA6o"]
[Sun Aug 30 03:06:50.721777 2026] [security2:error] [pid 499751:tid 499917] [client 20.63.81.20:43380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/dex.php"] [unique_id "apPkmjmmjdkPfMeJsKO3nAAAA7k"]
[Sun Aug 30 03:06:50.730331 2026] [authz_core:error] [pid 499145:tid 499353] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_BW%2FLC_MESSAGES
[Sun Aug 30 03:06:50.730598 2026] [authz_core:error] [pid 499145:tid 499353] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_BW%2FLC_MESSAGES
[Sun Aug 30 03:06:50.745352 2026] [security2:error] [pid 500253:tid 500462] [client 158.23.147.79:44233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-admin/index.php"] [unique_id "apPkmlmmXVd4kRvS-FAEwQAAAdw"]
[Sun Aug 30 03:06:50.751019 2026] [authz_core:error] [pid 500253:tid 500391] [client 216.73.216.128:4988] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:50.751297 2026] [authz_core:error] [pid 500253:tid 500391] [client 216.73.216.128:4988] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:50.764900 2026] [security2:error] [pid 499751:tid 499935] [client 20.104.50.220:61487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/Bulle.php"] [unique_id "apPkmjmmjdkPfMeJsKO3qQAAA8s"]
[Sun Aug 30 03:06:50.771481 2026] [security2:error] [pid 500253:tid 500468] [client 68.155.159.216:12331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-admin/admin.php"] [unique_id "apPkmlmmXVd4kRvS-FAEyAAAAeI"]
[Sun Aug 30 03:06:50.814446 2026] [security2:error] [pid 499751:tid 499988] [client 4.205.62.107:64470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/phpinfo01.php"] [unique_id "apPkmjmmjdkPfMeJsKO3vQAABAA"]
[Sun Aug 30 03:06:50.854559 2026] [security2:error] [pid 499751:tid 499932] [client 20.63.81.20:43312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/giodywky.php"] [unique_id "apPkmjmmjdkPfMeJsKO3yAAAA8g"]
[Sun Aug 30 03:06:50.880413 2026] [authz_core:error] [pid 499145:tid 499392] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp
[Sun Aug 30 03:06:50.880764 2026] [authz_core:error] [pid 499145:tid 499392] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp
[Sun Aug 30 03:06:50.907424 2026] [security2:error] [pid 500253:tid 500388] [client 20.151.200.44:24609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/ca.php"] [unique_id "apPkmlmmXVd4kRvS-FAFDQAAAZI"]
[Sun Aug 30 03:06:50.908490 2026] [authz_core:error] [pid 499751:tid 499949] [client 66.249.66.195:52013] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:50.908783 2026] [authz_core:error] [pid 499751:tid 499949] [client 66.249.66.195:52013] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:50.949357 2026] [security2:error] [pid 500253:tid 500385] [client 158.23.147.79:54635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-content/themes/index.php"] [unique_id "apPkmlmmXVd4kRvS-FAFJgAAAY8"]
[Sun Aug 30 03:06:50.952932 2026] [security2:error] [pid 500253:tid 500413] [client 4.205.62.107:30375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/services.php"] [unique_id "apPkmlmmXVd4kRvS-FAFKgAAAas"]
[Sun Aug 30 03:06:50.955075 2026] [security2:error] [pid 499751:tid 499988] [client 20.104.18.15:34783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/classwithtostring.php"] [unique_id "apPkmjmmjdkPfMeJsKO37AAABAA"]
[Sun Aug 30 03:06:50.969889 2026] [security2:error] [pid 499751:tid 499913] [client 68.155.159.216:56355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apPkmjmmjdkPfMeJsKO39AAAA7U"]
[Sun Aug 30 03:06:50.972811 2026] [authz_core:error] [pid 500253:tid 500395] [client 66.249.66.45:47069] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:50.973271 2026] [authz_core:error] [pid 500253:tid 500395] [client 66.249.66.45:47069] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:50.987380 2026] [security2:error] [pid 499751:tid 500008] [client 20.104.50.220:27396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/inc/class_plugins.php"] [unique_id "apPkmjmmjdkPfMeJsKO3-gAABBQ"]
[Sun Aug 30 03:06:50.988278 2026] [security2:error] [pid 500253:tid 500461] [client 20.63.81.20:43300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp-kz.php"] [unique_id "apPkmlmmXVd4kRvS-FAFQgAAAds"]
[Sun Aug 30 03:06:51.001909 2026] [authz_core:error] [pid 499751:tid 499942] [client 66.249.66.70:62417] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:51.002214 2026] [authz_core:error] [pid 499751:tid 499942] [client 66.249.66.70:62417] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:51.006475 2026] [security2:error] [pid 500253:tid 500502] [client 4.205.62.107:63998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/png.php"] [unique_id "apPkm1mmXVd4kRvS-FAFUwAAAgQ"]
[Sun Aug 30 03:06:51.044493 2026] [security2:error] [pid 500253:tid 500404] [client 4.205.62.107:2776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/aws_settings.php"] [unique_id "apPkm1mmXVd4kRvS-FAFbwAAAaI"]
[Sun Aug 30 03:06:51.079820 2026] [security2:error] [pid 500253:tid 500399] [client 20.48.251.3:7006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/routes.php"] [unique_id "apPkm1mmXVd4kRvS-FAFjgAAAZ0"]
[Sun Aug 30 03:06:51.086608 2026] [security2:error] [pid 500253:tid 500428] [client 20.48.251.3:49927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/test.php"] [unique_id "apPkm1mmXVd4kRvS-FAFlAAAAbo"]
[Sun Aug 30 03:06:51.091846 2026] [security2:error] [pid 500253:tid 500404] [client 68.155.159.216:62026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apPkm1mmXVd4kRvS-FAFmgAAAaI"]
[Sun Aug 30 03:06:51.117836 2026] [security2:error] [pid 499145:tid 499350] [client 20.104.50.220:32312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/kndw1.php"] [unique_id "apPkm1JNq1G5uRhTNns2VAAAAEs"]
[Sun Aug 30 03:06:51.118683 2026] [security2:error] [pid 500253:tid 500511] [client 20.63.81.20:43354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp-includes/ID3/getid.php"] [unique_id "apPkm1mmXVd4kRvS-FAFsQAAAg0"]
[Sun Aug 30 03:06:51.135674 2026] [security2:error] [pid 500253:tid 500462] [client 20.104.50.220:62831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/idca.php"] [unique_id "apPkm1mmXVd4kRvS-FAFuQAAAdw"]
[Sun Aug 30 03:06:51.159774 2026] [security2:error] [pid 500253:tid 500452] [client 4.205.62.107:62421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/fff.php"] [unique_id "apPkm1mmXVd4kRvS-FAFxAAAAdI"]
[Sun Aug 30 03:06:51.161596 2026] [security2:error] [pid 500253:tid 500444] [client 158.23.147.79:54599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-admin/user/index.php"] [unique_id "apPkm1mmXVd4kRvS-FAFxgAAAco"]
[Sun Aug 30 03:06:51.168226 2026] [security2:error] [pid 500253:tid 500483] [client 4.205.62.107:18778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/public/mah.php.php"] [unique_id "apPkm1mmXVd4kRvS-FAFygAAAfE"]
[Sun Aug 30 03:06:51.177766 2026] [security2:error] [pid 500253:tid 500492] [client 4.205.62.107:4125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/wdf.php"] [unique_id "apPkm1mmXVd4kRvS-FAF0AAAAfo"]
[Sun Aug 30 03:06:51.196474 2026] [security2:error] [pid 500253:tid 500472] [client 68.155.159.216:54097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/log-mama/function.php"] [unique_id "apPkm1mmXVd4kRvS-FAF3gAAAeY"]
[Sun Aug 30 03:06:51.207074 2026] [security2:error] [pid 499751:tid 499941] [client 20.151.200.44:37760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.ldhinv.com"] [uri "/waf.php"] [unique_id "apPkmzmmjdkPfMeJsKO4RwAAA9E"]
[Sun Aug 30 03:06:51.209005 2026] [authz_core:error] [pid 499145:tid 499325] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:51.209466 2026] [authz_core:error] [pid 499145:tid 499325] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:51.215425 2026] [security2:error] [pid 500253:tid 500464] [client 4.205.62.107:26498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/file59.php"] [unique_id "apPkm1mmXVd4kRvS-FAF6AAAAd4"]
[Sun Aug 30 03:06:51.224062 2026] [security2:error] [pid 499751:tid 500007] [client 20.48.251.3:56372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/thui.php"] [unique_id "apPkmzmmjdkPfMeJsKO4UgAABBM"]
[Sun Aug 30 03:06:51.226186 2026] [security2:error] [pid 499145:tid 499398] [client 20.104.18.15:28652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/sky.php"] [unique_id "apPkm1JNq1G5uRhTNns2hgAAAHs"]
[Sun Aug 30 03:06:51.233223 2026] [security2:error] [pid 499751:tid 499994] [client 20.104.18.15:33676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/asdfghj.php"] [unique_id "apPkmzmmjdkPfMeJsKO4WwAABAY"]
[Sun Aug 30 03:06:51.236170 2026] [authz_core:error] [pid 499145:tid 499392] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_GB%2FLC_MESSAGES
[Sun Aug 30 03:06:51.236604 2026] [authz_core:error] [pid 499145:tid 499392] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_GB%2FLC_MESSAGES
[Sun Aug 30 03:06:51.246155 2026] [security2:error] [pid 499751:tid 499913] [client 20.63.81.20:43299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/session.php"] [unique_id "apPkmzmmjdkPfMeJsKO4ZAAAA7U"]
[Sun Aug 30 03:06:51.246496 2026] [security2:error] [pid 500253:tid 500463] [client 20.104.50.220:17317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/cream1.php"] [unique_id "apPkm1mmXVd4kRvS-FAF9QAAAd0"]
[Sun Aug 30 03:06:51.252905 2026] [security2:error] [pid 499145:tid 499402] [client 20.104.50.220:46162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/usr.php"] [unique_id "apPkm1JNq1G5uRhTNns2lgAAAH8"]
[Sun Aug 30 03:06:51.297629 2026] [security2:error] [pid 500253:tid 500450] [client 20.104.18.15:23497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/BDKR28WP.php"] [unique_id "apPkm1mmXVd4kRvS-FAGGwAAAdA"]
[Sun Aug 30 03:06:51.317864 2026] [authz_core:error] [pid 499751:tid 499931] [client 66.249.66.64:59259] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:51.318137 2026] [authz_core:error] [pid 499751:tid 499931] [client 66.249.66.64:59259] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:51.344554 2026] [security2:error] [pid 499751:tid 500007] [client 158.23.147.79:54264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/about.php"] [unique_id "apPkmzmmjdkPfMeJsKO4gwAABBM"]
[Sun Aug 30 03:06:51.348081 2026] [security2:error] [pid 499751:tid 499918] [client 20.151.200.44:27306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/blnux.php"] [unique_id "apPkmzmmjdkPfMeJsKO4hQAAA7o"]
[Sun Aug 30 03:06:51.373095 2026] [security2:error] [pid 499751:tid 499976] [client 20.63.81.20:43267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/eagle.php"] [unique_id "apPkmzmmjdkPfMeJsKO4mAAAA_Q"]
[Sun Aug 30 03:06:51.388462 2026] [authz_core:error] [pid 500253:tid 500402] [client 216.73.216.128:5993] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:51.388798 2026] [authz_core:error] [pid 500253:tid 500402] [client 216.73.216.128:5993] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:51.405467 2026] [security2:error] [pid 499145:tid 499276] [client 20.48.251.3:4682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/debug.php"] [unique_id "apPkm1JNq1G5uRhTNns27QAAAAE"]
[Sun Aug 30 03:06:51.428759 2026] [security2:error] [pid 499145:tid 499343] [client 4.205.62.107:32468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/product.php"] [unique_id "apPkm1JNq1G5uRhTNns2-gAAAEQ"]
[Sun Aug 30 03:06:51.441586 2026] [authz_core:error] [pid 499145:tid 499283] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp
[Sun Aug 30 03:06:51.441871 2026] [authz_core:error] [pid 499145:tid 499283] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp
[Sun Aug 30 03:06:51.449270 2026] [lsapi:error] [pid 500253:tid 500393] [client 45.180.130.235:13738] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n
[Sun Aug 30 03:06:51.449435 2026] [lsapi:error] [pid 500253:tid 500393] [client 45.180.130.235:13738] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n
[Sun Aug 30 03:06:51.450814 2026] [lsapi:error] [pid 500253:tid 500393] [client 45.180.130.235:13738] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n
[Sun Aug 30 03:06:51.452927 2026] [security2:error] [pid 499145:tid 499367] [client 20.104.18.15:13737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/bo.php"] [unique_id "apPkm1JNq1G5uRhTNns3DgAAAFw"]
[Sun Aug 30 03:06:51.476782 2026] [security2:error] [pid 500253:tid 500432] [client 114.119.137.193:32643] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.auscreen.com.au"] [uri "/sites/default/files/sunscreen_application1.png"] [unique_id "apPkm1mmXVd4kRvS-FAGiwAAAb4"], referer: https://www.auscreen.com.au/sites/default/files/sunscreen_application1.png
[Sun Aug 30 03:06:51.480839 2026] [authz_core:error] [pid 500253:tid 500442] [client 66.249.66.43:41385] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:51.481107 2026] [authz_core:error] [pid 500253:tid 500510] [client 216.73.216.128:4988] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:51.481310 2026] [authz_core:error] [pid 500253:tid 500442] [client 66.249.66.43:41385] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:51.481522 2026] [authz_core:error] [pid 500253:tid 500510] [client 216.73.216.128:4988] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:51.500528 2026] [security2:error] [pid 500253:tid 500492] [client 158.23.147.79:53507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-includes/plugins.php"] [unique_id "apPkm1mmXVd4kRvS-FAGnwAAAfo"]
[Sun Aug 30 03:06:51.505213 2026] [security2:error] [pid 499145:tid 499286] [client 20.63.81.20:43280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/up-kon.php"] [unique_id "apPkm1JNq1G5uRhTNns3MwAAAAs"]
[Sun Aug 30 03:06:51.517416 2026] [security2:error] [pid 500253:tid 500391] [client 20.104.50.220:6102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/szezaxab.php"] [unique_id "apPkm1mmXVd4kRvS-FAGrwAAAZU"]
[Sun Aug 30 03:06:51.581061 2026] [security2:error] [pid 500253:tid 500390] [client 20.104.50.220:33064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/hehee.php"] [unique_id "apPkm1mmXVd4kRvS-FAGzAAAAZQ"]
[Sun Aug 30 03:06:51.583531 2026] [authz_core:error] [pid 499145:tid 499299] [client 66.249.66.203:46614] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:51.583968 2026] [authz_core:error] [pid 499145:tid 499299] [client 66.249.66.203:46614] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:51.586380 2026] [security2:error] [pid 499145:tid 499293] [client 158.23.147.79:54614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apPkm1JNq1G5uRhTNns3YwAAABI"]
[Sun Aug 30 03:06:51.632518 2026] [security2:error] [pid 500253:tid 500460] [client 20.63.81.20:43226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/tinny.php"] [unique_id "apPkm1mmXVd4kRvS-FAG3AAAAdo"]
[Sun Aug 30 03:06:51.649087 2026] [security2:error] [pid 500253:tid 500399] [client 68.155.159.216:63988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apPkm1mmXVd4kRvS-FAG4wAAAZ0"]
[Sun Aug 30 03:06:51.666882 2026] [security2:error] [pid 500253:tid 500445] [client 158.23.147.79:44239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apPkm1mmXVd4kRvS-FAG6AAAAcs"]
[Sun Aug 30 03:06:51.704027 2026] [security2:error] [pid 500253:tid 500435] [client 158.23.147.79:53526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/themes.php"] [unique_id "apPkm1mmXVd4kRvS-FAG_AAAAcE"]
[Sun Aug 30 03:06:51.722453 2026] [security2:error] [pid 500253:tid 500394] [client 4.205.62.107:52124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/server_info.php"] [unique_id "apPkm1mmXVd4kRvS-FAHDgAAAZg"]
[Sun Aug 30 03:06:51.759395 2026] [security2:error] [pid 499145:tid 499321] [client 20.63.81.20:43212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp-easy.php"] [unique_id "apPkm1JNq1G5uRhTNns3wQAAAC4"]
[Sun Aug 30 03:06:51.761150 2026] [authz_core:error] [pid 499145:tid 499287] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZW%2FLC_MESSAGES
[Sun Aug 30 03:06:51.761247 2026] [security2:error] [pid 499145:tid 499328] [client 68.155.159.216:61633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/admin.php"] [unique_id "apPkm1JNq1G5uRhTNns3xAAAADU"]
[Sun Aug 30 03:06:51.761484 2026] [authz_core:error] [pid 499145:tid 499287] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZW%2FLC_MESSAGES
[Sun Aug 30 03:06:51.762074 2026] [security2:error] [pid 499145:tid 499285] [client 20.104.18.15:43281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apPkm1JNq1G5uRhTNns3xQAAAAo"]
[Sun Aug 30 03:06:51.799477 2026] [security2:error] [pid 500253:tid 500422] [client 4.205.62.107:63595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/file59.php"] [unique_id "apPkm1mmXVd4kRvS-FAHNAAAAbQ"]
[Sun Aug 30 03:06:51.845177 2026] [security2:error] [pid 500253:tid 500478] [client 20.104.50.220:63510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/images.php"] [unique_id "apPkm1mmXVd4kRvS-FAHUwAAAew"]
[Sun Aug 30 03:06:51.866358 2026] [security2:error] [pid 499145:tid 499283] [client 158.23.147.79:53563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-mail.php"] [unique_id "apPkm1JNq1G5uRhTNns36gAAAAg"]
[Sun Aug 30 03:06:51.878587 2026] [authz_core:error] [pid 499145:tid 499337] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:51.879002 2026] [authz_core:error] [pid 499145:tid 499337] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:51.879926 2026] [security2:error] [pid 499751:tid 499920] [client 158.23.147.79:44230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/goat1.php"] [unique_id "apPkmzmmjdkPfMeJsKO5SAAAA7w"]
[Sun Aug 30 03:06:51.887863 2026] [security2:error] [pid 500253:tid 500500] [client 20.63.81.20:43241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/d7.php"] [unique_id "apPkm1mmXVd4kRvS-FAHbAAAAgI"]
[Sun Aug 30 03:06:51.902322 2026] [security2:error] [pid 500253:tid 500468] [client 20.104.50.220:62784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/cylul.php"] [unique_id "apPkm1mmXVd4kRvS-FAHcgAAAeI"]
[Sun Aug 30 03:06:51.916851 2026] [security2:error] [pid 500253:tid 500481] [client 68.155.159.216:12407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apPkm1mmXVd4kRvS-FAHegAAAe8"]
[Sun Aug 30 03:06:51.919335 2026] [security2:error] [pid 500253:tid 500494] [client 20.151.200.44:47298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/pb.php"] [unique_id "apPkm1mmXVd4kRvS-FAHfQAAAfw"]
[Sun Aug 30 03:06:51.934667 2026] [security2:error] [pid 500253:tid 500454] [client 20.104.50.220:61381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/srx.php"] [unique_id "apPkm1mmXVd4kRvS-FAHggAAAdQ"]
[Sun Aug 30 03:06:51.935244 2026] [authz_core:error] [pid 500253:tid 500440] [client 216.73.216.128:5993] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:51.935517 2026] [authz_core:error] [pid 500253:tid 500440] [client 216.73.216.128:5993] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:51.967089 2026] [security2:error] [pid 500253:tid 500502] [client 4.205.62.107:64686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/cxc.php"] [unique_id "apPkm1mmXVd4kRvS-FAHmQAAAgQ"]
[Sun Aug 30 03:06:52.018851 2026] [security2:error] [pid 499751:tid 499997] [client 20.63.81.20:43276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/v5.php"] [unique_id "apPknDmmjdkPfMeJsKO5ewAABAk"]
[Sun Aug 30 03:06:52.019894 2026] [authz_core:error] [pid 499145:tid 499316] [client 66.249.66.203:46614] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:52.020161 2026] [authz_core:error] [pid 499145:tid 499316] [client 66.249.66.203:46614] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:52.088628 2026] [security2:error] [pid 500253:tid 500399] [client 4.205.62.107:58126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/filesystems.php"] [unique_id "apPknFmmXVd4kRvS-FAIBwAAAZ0"]
[Sun Aug 30 03:06:52.097854 2026] [security2:error] [pid 499751:tid 499965] [client 20.104.18.15:34805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPknDmmjdkPfMeJsKO5lgAAA-k"]
[Sun Aug 30 03:06:52.124222 2026] [security2:error] [pid 500253:tid 500511] [client 20.104.50.220:27427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/forumdisplay.php"] [unique_id "apPknFmmXVd4kRvS-FAIGQAAAg0"]
[Sun Aug 30 03:06:52.138215 2026] [security2:error] [pid 500253:tid 500439] [client 158.23.147.79:44259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-includes/certificates/index.php"] [unique_id "apPknFmmXVd4kRvS-FAIJQAAAcU"]
[Sun Aug 30 03:06:52.155225 2026] [security2:error] [pid 500253:tid 500426] [client 4.205.62.107:63993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/chosen.php"] [unique_id "apPknFmmXVd4kRvS-FAINgAAAbg"]
[Sun Aug 30 03:06:52.162011 2026] [security2:error] [pid 500253:tid 500404] [client 20.63.81.20:43332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/az.php"] [unique_id "apPknFmmXVd4kRvS-FAIOwAAAaI"]
[Sun Aug 30 03:06:52.182768 2026] [security2:error] [pid 499751:tid 499972] [client 4.205.62.107:2968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/wp-konfig.backup.php"] [unique_id "apPknDmmjdkPfMeJsKO5sQAAA_A"]
[Sun Aug 30 03:06:52.210800 2026] [security2:error] [pid 499751:tid 499895] [client 68.155.159.216:62066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apPknDmmjdkPfMeJsKO5wAAAA6Q"]
[Sun Aug 30 03:06:52.232141 2026] [authz_core:error] [pid 499145:tid 499291] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZW
[Sun Aug 30 03:06:52.232462 2026] [authz_core:error] [pid 499145:tid 499291] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZW
[Sun Aug 30 03:06:52.255038 2026] [security2:error] [pid 500253:tid 500502] [client 20.48.251.3:50009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/cloud.php"] [unique_id "apPknFmmXVd4kRvS-FAIeQAAAgQ"]
[Sun Aug 30 03:06:52.255782 2026] [authz_core:error] [pid 499751:tid 499939] [client 66.249.66.71:60286] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:52.256169 2026] [authz_core:error] [pid 499751:tid 499939] [client 66.249.66.71:60286] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:52.273406 2026] [security2:error] [pid 500253:tid 500477] [client 20.104.50.220:32302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/la.php"] [unique_id "apPknFmmXVd4kRvS-FAIlgAAAes"]
[Sun Aug 30 03:06:52.279039 2026] [security2:error] [pid 500253:tid 500463] [client 68.155.159.216:56364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-login.php"] [unique_id "apPknFmmXVd4kRvS-FAIiAAAAd0"]
[Sun Aug 30 03:06:52.287675 2026] [security2:error] [pid 500253:tid 500429] [client 158.23.147.79:54267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/cgi-bin/index.php"] [unique_id "apPknFmmXVd4kRvS-FAIpAAAAbs"]
[Sun Aug 30 03:06:52.296333 2026] [security2:error] [pid 500253:tid 500495] [client 20.63.81.20:43274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/js.php"] [unique_id "apPknFmmXVd4kRvS-FAIrgAAAf0"]
[Sun Aug 30 03:06:52.302138 2026] [security2:error] [pid 500253:tid 500466] [client 68.155.159.216:54019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/bk/index.php"] [unique_id "apPknFmmXVd4kRvS-FAIuAAAAeA"]
[Sun Aug 30 03:06:52.305670 2026] [security2:error] [pid 500253:tid 500428] [client 4.205.62.107:62408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/autogooey.php"] [unique_id "apPknFmmXVd4kRvS-FAIvAAAAbo"]
[Sun Aug 30 03:06:52.306958 2026] [security2:error] [pid 500253:tid 500444] [client 4.205.62.107:17793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/zaza.php"] [unique_id "apPknFmmXVd4kRvS-FAIvwAAAco"]
[Sun Aug 30 03:06:52.318116 2026] [security2:error] [pid 499751:tid 499933] [client 4.205.62.107:5081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/bb.php"] [unique_id "apPknDmmjdkPfMeJsKO56AAAA8k"]
[Sun Aug 30 03:06:52.365478 2026] [security2:error] [pid 500253:tid 500426] [client 20.104.18.15:28561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/file5.php"] [unique_id "apPknFmmXVd4kRvS-FAI_AAAAbg"]
[Sun Aug 30 03:06:52.382666 2026] [security2:error] [pid 500253:tid 500413] [client 20.104.50.220:16721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/lim.php"] [unique_id "apPknFmmXVd4kRvS-FAJBwAAAas"]
[Sun Aug 30 03:06:52.382999 2026] [security2:error] [pid 500253:tid 500478] [client 158.23.147.79:44265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-admin/network/index.php"] [unique_id "apPknFmmXVd4kRvS-FAJCQAAAew"]
[Sun Aug 30 03:06:52.395848 2026] [security2:error] [pid 500253:tid 500416] [client 20.48.251.3:56360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/lala.php"] [unique_id "apPknFmmXVd4kRvS-FAJFQAAAa4"]
[Sun Aug 30 03:06:52.417705 2026] [authz_core:error] [pid 499145:tid 499399] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp
[Sun Aug 30 03:06:52.418259 2026] [authz_core:error] [pid 499145:tid 499399] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp
[Sun Aug 30 03:06:52.424219 2026] [security2:error] [pid 500253:tid 500450] [client 20.63.81.20:43308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/hd.php"] [unique_id "apPknFmmXVd4kRvS-FAJMgAAAdA"]
[Sun Aug 30 03:06:52.426063 2026] [security2:error] [pid 499145:tid 499315] [client 20.104.50.220:29312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/indoxploit_shell.php"] [unique_id "apPknFJNq1G5uRhTNns40QAAACg"]
[Sun Aug 30 03:06:52.443814 2026] [security2:error] [pid 499751:tid 499898] [client 20.104.18.15:33010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/dragonshell.php"] [unique_id "apPknDmmjdkPfMeJsKO6MgAAA6c"]
[Sun Aug 30 03:06:52.448929 2026] [security2:error] [pid 500253:tid 500408] [client 20.104.18.15:23511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/sf.php"] [unique_id "apPknFmmXVd4kRvS-FAJRwAAAaY"]
[Sun Aug 30 03:06:52.477550 2026] [security2:error] [pid 500253:tid 500425] [client 20.104.50.220:46454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/v3.php"] [unique_id "apPknFmmXVd4kRvS-FAJYgAAAbc"]
[Sun Aug 30 03:06:52.482365 2026] [security2:error] [pid 500253:tid 500492] [client 68.155.159.216:54250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPknFmmXVd4kRvS-FAJZAAAAfo"]
[Sun Aug 30 03:06:52.487218 2026] [security2:error] [pid 499751:tid 499894] [client 114.119.135.206:61271] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kazuna.com.au"] [uri "/collections/hommes/products/box-weave-ties"] [unique_id "apPknDmmjdkPfMeJsKO6TwAAA6M"], referer: https://kazuna.com.au/collections/all/products/wool-camel-turtle-neck-sweater-by-991japan
[Sun Aug 30 03:06:52.506937 2026] [security2:error] [pid 500253:tid 500512] [client 20.151.200.44:47399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/pk.php"] [unique_id "apPknFmmXVd4kRvS-FAJfQAAAg4"]
[Sun Aug 30 03:06:52.549612 2026] [security2:error] [pid 500253:tid 500466] [client 20.63.81.20:43220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/xl2023.php"] [unique_id "apPknFmmXVd4kRvS-FAJpAAAAeA"]
[Sun Aug 30 03:06:52.559900 2026] [security2:error] [pid 500253:tid 500413] [client 20.48.251.3:6989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/aww.php"] [unique_id "apPknFmmXVd4kRvS-FAJqwAAAas"]
[Sun Aug 30 03:06:52.570780 2026] [authz_core:error] [pid 499145:tid 499306] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:52.571048 2026] [authz_core:error] [pid 499145:tid 499306] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:52.590006 2026] [security2:error] [pid 500253:tid 500500] [client 20.48.251.3:44390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/nzv.php"] [unique_id "apPknFmmXVd4kRvS-FAJwAAAAgI"]
[Sun Aug 30 03:06:52.593398 2026] [security2:error] [pid 499751:tid 500001] [client 20.104.18.15:13620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/44.php"] [unique_id "apPknDmmjdkPfMeJsKO6hgAABA0"]
[Sun Aug 30 03:06:52.637433 2026] [authz_core:error] [pid 499145:tid 499275] [client 66.249.66.38:42629] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:52.637722 2026] [authz_core:error] [pid 499145:tid 499275] [client 66.249.66.38:42629] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:52.659481 2026] [security2:error] [pid 500253:tid 500428] [client 20.104.50.220:5486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/function.php"] [unique_id "apPknFmmXVd4kRvS-FAJ4QAAAbo"]
[Sun Aug 30 03:06:52.672441 2026] [security2:error] [pid 500253:tid 500447] [client 158.23.147.79:53562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPknFmmXVd4kRvS-FAJ5QAAAc0"]
[Sun Aug 30 03:06:52.675850 2026] [security2:error] [pid 500253:tid 500449] [client 20.63.81.20:43321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/V2.php"] [unique_id "apPknFmmXVd4kRvS-FAJ6wAAAc8"]
[Sun Aug 30 03:06:52.718740 2026] [security2:error] [pid 500253:tid 500408] [client 20.104.50.220:33570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/human.php"] [unique_id "apPknFmmXVd4kRvS-FAKDgAAAaY"]
[Sun Aug 30 03:06:52.720186 2026] [security2:error] [pid 500253:tid 500420] [client 158.23.147.79:54271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apPknFmmXVd4kRvS-FAKEQAAAbI"]
[Sun Aug 30 03:06:52.747706 2026] [authz_core:error] [pid 499145:tid 499288] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZW
[Sun Aug 30 03:06:52.747959 2026] [authz_core:error] [pid 499145:tid 499288] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZW
[Sun Aug 30 03:06:52.806075 2026] [security2:error] [pid 499751:tid 499984] [client 68.155.159.216:61335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apPknDmmjdkPfMeJsKO6vAAAA_w"]
[Sun Aug 30 03:06:52.807391 2026] [security2:error] [pid 499751:tid 499979] [client 158.23.147.79:54600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-includes/content.php"] [unique_id "apPknDmmjdkPfMeJsKO6vgAAA_c"]
[Sun Aug 30 03:06:52.820505 2026] [security2:error] [pid 500253:tid 500416] [client 20.63.81.20:43200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/mad.php"] [unique_id "apPknFmmXVd4kRvS-FAKUAAAAa4"]
[Sun Aug 30 03:06:52.856901 2026] [security2:error] [pid 499145:tid 499377] [client 4.205.62.107:26544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/cli_bootstrap.php"] [unique_id "apPknFJNq1G5uRhTNns5jwAAAGY"]
[Sun Aug 30 03:06:52.875273 2026] [authz_core:error] [pid 499145:tid 499330] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp
[Sun Aug 30 03:06:52.875524 2026] [authz_core:error] [pid 499145:tid 499330] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp
[Sun Aug 30 03:06:52.880073 2026] [security2:error] [pid 500253:tid 500500] [client 4.205.62.107:56639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/hosty.php"] [unique_id "apPknFmmXVd4kRvS-FAKbQAAAgI"]
[Sun Aug 30 03:06:52.922109 2026] [security2:error] [pid 500253:tid 500486] [client 158.23.147.79:44248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/.well-knownold/index.php"] [unique_id "apPknFmmXVd4kRvS-FAKjgAAAfQ"]
[Sun Aug 30 03:06:52.923753 2026] [security2:error] [pid 500253:tid 500389] [client 20.104.18.15:43848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/sao.php"] [unique_id "apPknFmmXVd4kRvS-FAKkAAAAZM"]
[Sun Aug 30 03:06:52.928813 2026] [security2:error] [pid 499751:tid 499989] [client 4.205.62.107:60560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/cli_bootstrap.php"] [unique_id "apPknDmmjdkPfMeJsKO68QAABAE"]
[Sun Aug 30 03:06:52.939611 2026] [authz_core:error] [pid 500253:tid 500431] [client 216.73.216.128:4988] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:52.939991 2026] [authz_core:error] [pid 500253:tid 500431] [client 216.73.216.128:4988] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:52.963466 2026] [security2:error] [pid 499751:tid 499974] [client 20.63.81.20:43289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/st.php"] [unique_id "apPknDmmjdkPfMeJsKO7BQAAA_I"]
[Sun Aug 30 03:06:52.977812 2026] [security2:error] [pid 500253:tid 500413] [client 68.155.159.216:63513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-admin/admin.php"] [unique_id "apPknFmmXVd4kRvS-FAKtgAAAas"]
[Sun Aug 30 03:06:53.023770 2026] [security2:error] [pid 500253:tid 500404] [client 20.104.50.220:51585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/htdocs.php"] [unique_id "apPknVmmXVd4kRvS-FAK4QAAAaI"]
[Sun Aug 30 03:06:53.049773 2026] [security2:error] [pid 499751:tid 500010] [client 4.205.62.107:32507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/fun.php"] [unique_id "apPknTmmjdkPfMeJsKO7LAAABBY"]
[Sun Aug 30 03:06:53.051265 2026] [security2:error] [pid 499751:tid 500022] [client 20.151.200.44:47366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/ft.php"] [unique_id "apPknTmmjdkPfMeJsKO7LQAABCI"]
[Sun Aug 30 03:06:53.063408 2026] [authz_core:error] [pid 500253:tid 500429] [client 66.249.66.39:35908] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:53.063753 2026] [authz_core:error] [pid 500253:tid 500429] [client 66.249.66.39:35908] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:53.079440 2026] [security2:error] [pid 500253:tid 500387] [client 20.104.50.220:29125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/Cylul007.php"] [unique_id "apPknVmmXVd4kRvS-FALEAAAAZE"]
[Sun Aug 30 03:06:53.097035 2026] [security2:error] [pid 500253:tid 500406] [client 68.155.159.216:65493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/classwithtostring.php"] [unique_id "apPknVmmXVd4kRvS-FALGAAAAaQ"]
[Sun Aug 30 03:06:53.097172 2026] [authz_core:error] [pid 500253:tid 500440] [client 66.249.66.193:46354] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:53.097470 2026] [authz_core:error] [pid 500253:tid 500440] [client 66.249.66.193:46354] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:53.102825 2026] [security2:error] [pid 499145:tid 499293] [client 20.63.81.20:43304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/alfanew.php"] [unique_id "apPknVJNq1G5uRhTNns51AAAABI"]
[Sun Aug 30 03:06:53.106877 2026] [security2:error] [pid 500253:tid 500456] [client 4.205.62.107:64663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/oiko6u.php"] [unique_id "apPknVmmXVd4kRvS-FALHgAAAdY"]
[Sun Aug 30 03:06:53.112163 2026] [security2:error] [pid 500253:tid 500459] [client 158.23.147.79:54237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apPknVmmXVd4kRvS-FALIQAAAdk"]
[Sun Aug 30 03:06:53.119074 2026] [security2:error] [pid 499751:tid 499897] [client 20.104.50.220:61973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-content/plugins/owfsmac/mar.php"] [unique_id "apPknTmmjdkPfMeJsKO7VAAAA6Y"]
[Sun Aug 30 03:06:53.122585 2026] [authz_core:error] [pid 500253:tid 500397] [client 216.73.216.128:5993] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:53.123009 2026] [authz_core:error] [pid 500253:tid 500397] [client 216.73.216.128:5993] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:53.223276 2026] [security2:error] [pid 499751:tid 500011] [client 158.23.147.79:54240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPknTmmjdkPfMeJsKO7gwAABBc"]
[Sun Aug 30 03:06:53.228199 2026] [security2:error] [pid 499751:tid 499988] [client 158.23.147.79:53542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-admin/css/index.php"] [unique_id "apPknTmmjdkPfMeJsKO7jgAABAA"]
[Sun Aug 30 03:06:53.232582 2026] [security2:error] [pid 499751:tid 500009] [client 20.104.18.15:34765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/5PJcpMFsD8B.php"] [unique_id "apPknTmmjdkPfMeJsKO7kwAABBU"]
[Sun Aug 30 03:06:53.232723 2026] [security2:error] [pid 500253:tid 500391] [client 20.63.81.20:43231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/ioxi.php"] [unique_id "apPknVmmXVd4kRvS-FALbQAAAZU"]
[Sun Aug 30 03:06:53.248065 2026] [security2:error] [pid 499751:tid 499899] [client 114.119.150.29:38631] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "marketinfo.southbaylifestylehomes.com"] [uri "/"] [unique_id "apPknTmmjdkPfMeJsKO7nQAAA6g"], referer: https://marketinfo.southbaylifestylehomes.com/
[Sun Aug 30 03:06:53.261468 2026] [security2:error] [pid 500253:tid 500477] [client 20.104.50.220:27130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/inc/plugins/favcons.php"] [unique_id "apPknVmmXVd4kRvS-FALgAAAAes"]
[Sun Aug 30 03:06:53.271636 2026] [authz_core:error] [pid 499145:tid 499336] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_BW
[Sun Aug 30 03:06:53.272104 2026] [authz_core:error] [pid 499145:tid 499336] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_BW
[Sun Aug 30 03:06:53.298609 2026] [security2:error] [pid 499751:tid 499930] [client 178.20.44.140:51819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.44.20.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.org"] [uri "/index.php/contact-us/"] [unique_id "apPknTmmjdkPfMeJsKO7qAAAA8Y"], referer: http://bridgesofcourage.org/index.php/contact-us/
[Sun Aug 30 03:06:53.304461 2026] [authz_core:error] [pid 499145:tid 499367] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:53.304731 2026] [authz_core:error] [pid 499145:tid 499367] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:53.310270 2026] [security2:error] [pid 500253:tid 500472] [client 4.205.62.107:63982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/admin-ajax.php"] [unique_id "apPknVmmXVd4kRvS-FALugAAAeY"]
[Sun Aug 30 03:06:53.320838 2026] [security2:error] [pid 500253:tid 500408] [client 4.205.62.107:2977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/packed.php"] [unique_id "apPknVmmXVd4kRvS-FALvwAAAaY"]
[Sun Aug 30 03:06:53.341042 2026] [security2:error] [pid 499751:tid 499939] [client 68.155.159.216:62048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-content/languages/about.php"] [unique_id "apPknTmmjdkPfMeJsKO7yQAAA88"]
[Sun Aug 30 03:06:53.352975 2026] [authz_core:error] [pid 500253:tid 500500] [client 66.249.66.66:35810] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:53.353307 2026] [authz_core:error] [pid 500253:tid 500500] [client 66.249.66.66:35810] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:53.364543 2026] [authz_core:error] [pid 499751:tid 499942] [client 66.249.66.192:39777] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:53.364890 2026] [authz_core:error] [pid 499751:tid 499942] [client 66.249.66.192:39777] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:53.385455 2026] [security2:error] [pid 500253:tid 500398] [client 20.63.81.20:43205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/TNT.php"] [unique_id "apPknVmmXVd4kRvS-FAL-gAAAZw"]
[Sun Aug 30 03:06:53.395018 2026] [security2:error] [pid 500253:tid 500445] [client 20.48.251.3:49987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/asdf.php"] [unique_id "apPknVmmXVd4kRvS-FAMCgAAAcs"]
[Sun Aug 30 03:06:53.410548 2026] [authz_core:error] [pid 499145:tid 499399] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:53.411070 2026] [authz_core:error] [pid 499145:tid 499399] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:53.420701 2026] [security2:error] [pid 500253:tid 500398] [client 20.151.200.44:47331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/wp-ver.php"] [unique_id "apPknVmmXVd4kRvS-FAMIAAAAZw"]
[Sun Aug 30 03:06:53.424899 2026] [security2:error] [pid 499751:tid 499998] [client 20.104.50.220:32094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/lnedx.php"] [unique_id "apPknTmmjdkPfMeJsKO8CwAABAo"]
[Sun Aug 30 03:06:53.425512 2026] [security2:error] [pid 500253:tid 500442] [client 158.23.147.79:44272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/images/index.php"] [unique_id "apPknVmmXVd4kRvS-FAMIwAAAcg"]
[Sun Aug 30 03:06:53.434638 2026] [security2:error] [pid 500253:tid 500490] [client 158.23.147.79:53548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-admin/images/index.php"] [unique_id "apPknVmmXVd4kRvS-FAMKwAAAfg"]
[Sun Aug 30 03:06:53.437656 2026] [security2:error] [pid 499145:tid 499381] [client 4.205.62.107:18660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/u88.php"] [unique_id "apPknVJNq1G5uRhTNns6XQAAAGo"]
[Sun Aug 30 03:06:53.441781 2026] [security2:error] [pid 499751:tid 499978] [client 68.155.159.216:59950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.krisestep.com"] [uri "/first.php"] [unique_id "apPknTmmjdkPfMeJsKO8FgAAA_Y"]
[Sun Aug 30 03:06:53.447860 2026] [security2:error] [pid 500253:tid 500401] [client 4.205.62.107:4096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/file59.php"] [unique_id "apPknVmmXVd4kRvS-FAMLgAAAZ8"]
[Sun Aug 30 03:06:53.470482 2026] [security2:error] [pid 499751:tid 499976] [client 4.205.62.107:22557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/sdsa.php"] [unique_id "apPknTmmjdkPfMeJsKO8IwAAA_Q"]
[Sun Aug 30 03:06:53.496045 2026] [security2:error] [pid 499751:tid 499901] [client 20.104.49.130:58081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/tiny2.php"] [unique_id "apPknTmmjdkPfMeJsKO8NQAAA6o"]
[Sun Aug 30 03:06:53.506068 2026] [security2:error] [pid 499751:tid 500022] [client 20.104.18.15:28616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/xyn.php"] [unique_id "apPknTmmjdkPfMeJsKO8PgAABCI"]
[Sun Aug 30 03:06:53.517483 2026] [security2:error] [pid 500253:tid 500430] [client 20.63.81.20:43259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/cd.php"] [unique_id "apPknVmmXVd4kRvS-FAMagAAAbw"]
[Sun Aug 30 03:06:53.524312 2026] [security2:error] [pid 500253:tid 500436] [client 20.104.50.220:17298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/heat3.php"] [unique_id "apPknVmmXVd4kRvS-FAMcAAAAcI"]
[Sun Aug 30 03:06:53.538666 2026] [security2:error] [pid 500253:tid 500459] [client 20.48.251.3:33311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/public/bnn_.php.php"] [unique_id "apPknVmmXVd4kRvS-FAMggAAAdk"]
[Sun Aug 30 03:06:53.550982 2026] [authz_core:error] [pid 499751:tid 499914] [client 66.249.66.44:65347] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:53.551265 2026] [authz_core:error] [pid 499751:tid 499914] [client 66.249.66.44:65347] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:53.565750 2026] [security2:error] [pid 500253:tid 500485] [client 20.104.50.220:29169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/sbh.php"] [unique_id "apPknVmmXVd4kRvS-FAMnQAAAfM"]
[Sun Aug 30 03:06:53.582223 2026] [security2:error] [pid 499751:tid 499982] [client 20.104.18.15:33740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/wp-safe.php"] [unique_id "apPknTmmjdkPfMeJsKO8XAAAA_o"]
[Sun Aug 30 03:06:53.587422 2026] [security2:error] [pid 499145:tid 499391] [client 20.104.18.15:23523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/k.php"] [unique_id "apPknVJNq1G5uRhTNns6oQAAAHQ"]
[Sun Aug 30 03:06:53.604103 2026] [security2:error] [pid 500253:tid 500404] [client 68.155.159.216:55108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPknVmmXVd4kRvS-FAMvwAAAaI"]
[Sun Aug 30 03:06:53.622537 2026] [security2:error] [pid 499145:tid 499398] [client 20.104.50.220:46870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/v4.php"] [unique_id "apPknVJNq1G5uRhTNns6sAAAAHs"]
[Sun Aug 30 03:06:53.644049 2026] [security2:error] [pid 500253:tid 500483] [client 20.63.81.20:43144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/luuf.php"] [unique_id "apPknVmmXVd4kRvS-FAMzQAAAfE"]
[Sun Aug 30 03:06:53.646842 2026] [security2:error] [pid 500253:tid 500429] [client 195.178.110.247:34004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ermes-it.net"] [uri "/index.php"] [unique_id "apPknVmmXVd4kRvS-FAMzwAAAbs"]
[Sun Aug 30 03:06:53.690983 2026] [lsapi:error] [pid 499145:tid 499229] [remote 98.97.106.43:64586] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n
[Sun Aug 30 03:06:53.691090 2026] [lsapi:error] [pid 499145:tid 499229] [remote 98.97.106.43:64586] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n
[Sun Aug 30 03:06:53.692573 2026] [lsapi:error] [pid 499145:tid 499229] [remote 98.97.106.43:64586] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n
[Sun Aug 30 03:06:53.698944 2026] [authz_core:error] [pid 500253:tid 500509] [client 66.249.66.68:63125] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:53.699398 2026] [authz_core:error] [pid 500253:tid 500509] [client 66.249.66.68:63125] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:53.705076 2026] [security2:error] [pid 500253:tid 500499] [client 68.155.159.216:56370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apPknVmmXVd4kRvS-FAM8QAAAgE"]
[Sun Aug 30 03:06:53.714526 2026] [security2:error] [pid 499751:tid 499992] [client 158.23.147.79:53516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-includes/index.php"] [unique_id "apPknTmmjdkPfMeJsKO8jwAABAQ"]
[Sun Aug 30 03:06:53.730522 2026] [security2:error] [pid 500253:tid 500389] [client 20.48.251.3:5056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/66.php"] [unique_id "apPknVmmXVd4kRvS-FANAwAAAZM"]
[Sun Aug 30 03:06:53.737900 2026] [authz_core:error] [pid 499145:tid 499354] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_BW
[Sun Aug 30 03:06:53.738239 2026] [authz_core:error] [pid 499145:tid 499354] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_BW
[Sun Aug 30 03:06:53.764918 2026] [security2:error] [pid 500253:tid 500441] [client 158.23.147.79:44226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-includes/widgets/index.php"] [unique_id "apPknVmmXVd4kRvS-FANDQAAAcc"]
[Sun Aug 30 03:06:53.769013 2026] [security2:error] [pid 500253:tid 500481] [client 20.48.251.3:7101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/maxro.php"] [unique_id "apPknVmmXVd4kRvS-FANDwAAAe8"]
[Sun Aug 30 03:06:53.771052 2026] [authz_core:error] [pid 499751:tid 499958] [client 66.249.66.65:39769] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:53.771510 2026] [authz_core:error] [pid 499751:tid 499958] [client 66.249.66.65:39769] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:53.773192 2026] [security2:error] [pid 499751:tid 500022] [client 20.104.18.15:13662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/h2.php"] [unique_id "apPknTmmjdkPfMeJsKO8qgAABCI"]
[Sun Aug 30 03:06:53.778519 2026] [security2:error] [pid 499751:tid 499903] [client 20.63.81.20:43208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/fex.php"] [unique_id "apPknTmmjdkPfMeJsKO8sAAAA6w"]
[Sun Aug 30 03:06:53.786032 2026] [security2:error] [pid 499751:tid 500012] [client 20.151.200.44:47327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/ah24.php"] [unique_id "apPknTmmjdkPfMeJsKO8sgAABBg"]
[Sun Aug 30 03:06:53.811172 2026] [security2:error] [pid 500253:tid 500458] [client 195.178.110.247:12660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ermes-it.net"] [uri "/index.php"] [unique_id "apPknVmmXVd4kRvS-FANIgAAAdg"]
[Sun Aug 30 03:06:53.811187 2026] [security2:error] [pid 500253:tid 500479] [client 20.104.50.220:5574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/cierra632.php"] [unique_id "apPknVmmXVd4kRvS-FANIwAAAe0"]
[Sun Aug 30 03:06:53.872843 2026] [security2:error] [pid 500253:tid 500437] [client 20.104.50.220:33154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/him.php"] [unique_id "apPknVmmXVd4kRvS-FANQwAAAcM"]
[Sun Aug 30 03:06:53.901382 2026] [security2:error] [pid 499751:tid 500011] [client 158.23.147.79:54268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/mah.php"] [unique_id "apPknTmmjdkPfMeJsKO89gAABBc"]
[Sun Aug 30 03:06:53.908508 2026] [security2:error] [pid 500253:tid 500429] [client 20.63.81.20:43295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/l.php"] [unique_id "apPknVmmXVd4kRvS-FANXQAAAbs"]
[Sun Aug 30 03:06:53.914076 2026] [security2:error] [pid 499751:tid 499925] [client 68.155.159.216:65453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apPknTmmjdkPfMeJsKO9AAAAA8E"]
[Sun Aug 30 03:06:53.916859 2026] [authz_core:error] [pid 499145:tid 499402] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp
[Sun Aug 30 03:06:53.917391 2026] [authz_core:error] [pid 499145:tid 499402] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp
[Sun Aug 30 03:06:53.925898 2026] [authz_core:error] [pid 499751:tid 499979] [client 66.249.66.70:36605] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:53.926344 2026] [authz_core:error] [pid 499751:tid 499979] [client 66.249.66.70:36605] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:53.962490 2026] [security2:error] [pid 499145:tid 499340] [client 114.119.147.42:23381] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtrphotography.net"] [uri "/clients/mobile/login.php"] [unique_id "apPknVJNq1G5uRhTNns7QAAAAEE"], referer: https://mtrphotography.net/clients/mobile/login.php?id=2508
[Sun Aug 30 03:06:54.020103 2026] [security2:error] [pid 499751:tid 499937] [client 4.205.62.107:52157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/pass4.php"] [unique_id "apPknjmmjdkPfMeJsKO9NwAAA80"]
[Sun Aug 30 03:06:54.023897 2026] [authz_core:error] [pid 499751:tid 499950] [client 66.249.66.201:35476] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:54.024368 2026] [authz_core:error] [pid 499751:tid 499950] [client 66.249.66.201:35476] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:54.036572 2026] [security2:error] [pid 500253:tid 500486] [client 20.63.81.20:43281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/xr.php"] [unique_id "apPknlmmXVd4kRvS-FANvwAAAfQ"]
[Sun Aug 30 03:06:54.041305 2026] [security2:error] [pid 499751:tid 499987] [client 158.23.147.79:54225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-blog-header.php"] [unique_id "apPknjmmjdkPfMeJsKO9PwAAA_8"]
[Sun Aug 30 03:06:54.066893 2026] [security2:error] [pid 499751:tid 500003] [client 4.205.62.107:60596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/dd.php"] [unique_id "apPknjmmjdkPfMeJsKO9TgAABA8"]
[Sun Aug 30 03:06:54.091281 2026] [security2:error] [pid 500253:tid 500441] [client 20.104.18.15:43908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/dapa.php"] [unique_id "apPknlmmXVd4kRvS-FAN-QAAAcc"]
[Sun Aug 30 03:06:54.093867 2026] [authz_core:error] [pid 500253:tid 500492] [client 66.249.66.64:41985] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:54.094306 2026] [authz_core:error] [pid 500253:tid 500492] [client 66.249.66.64:41985] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:54.108102 2026] [authz_core:error] [pid 499751:tid 499990] [client 66.249.66.41:59014] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:54.108499 2026] [authz_core:error] [pid 499751:tid 499990] [client 66.249.66.41:59014] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:54.116431 2026] [security2:error] [pid 500253:tid 500474] [client 20.104.18.15:29175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPknlmmXVd4kRvS-FAOBAAAAeg"]
[Sun Aug 30 03:06:54.142912 2026] [security2:error] [pid 500253:tid 500423] [client 20.104.49.130:60656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/samll.php"] [unique_id "apPknlmmXVd4kRvS-FAOEwAAAbU"]
[Sun Aug 30 03:06:54.157240 2026] [security2:error] [pid 500253:tid 500428] [client 68.155.159.216:63518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-includes/IXR/index.php"] [unique_id "apPknlmmXVd4kRvS-FAOJQAAAbo"]
[Sun Aug 30 03:06:54.166497 2026] [security2:error] [pid 500253:tid 500497] [client 20.63.81.20:43302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/Q3.php"] [unique_id "apPknlmmXVd4kRvS-FAOLgAAAf8"]
[Sun Aug 30 03:06:54.181570 2026] [security2:error] [pid 500253:tid 500419] [client 158.23.147.79:54631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apPknlmmXVd4kRvS-FAOOwAAAbE"]
[Sun Aug 30 03:06:54.212563 2026] [security2:error] [pid 499751:tid 500017] [client 68.155.159.216:65525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/install.php"] [unique_id "apPknjmmjdkPfMeJsKO9gwAABB0"]
[Sun Aug 30 03:06:54.215737 2026] [authz_core:error] [pid 500253:tid 500466] [client 216.73.216.128:4988] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:54.215960 2026] [security2:error] [pid 500253:tid 500411] [client 20.104.50.220:42795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/hello.php"] [unique_id "apPknlmmXVd4kRvS-FAOYAAAAak"]
[Sun Aug 30 03:06:54.216201 2026] [authz_core:error] [pid 500253:tid 500466] [client 216.73.216.128:4988] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:54.220890 2026] [security2:error] [pid 499145:tid 499326] [client 158.23.147.79:54251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apPknlJNq1G5uRhTNns7pgAAADM"]
[Sun Aug 30 03:06:54.245470 2026] [security2:error] [pid 499751:tid 499938] [client 4.205.62.107:64700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/fraro.php"] [unique_id "apPknjmmjdkPfMeJsKO9kwAAA84"]
[Sun Aug 30 03:06:54.246033 2026] [security2:error] [pid 500253:tid 500481] [client 20.104.50.220:62817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/cgi-alfa.php"] [unique_id "apPknlmmXVd4kRvS-FAOfQAAAe8"]
[Sun Aug 30 03:06:54.255639 2026] [authz_core:error] [pid 499145:tid 499309] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_PH
[Sun Aug 30 03:06:54.256065 2026] [authz_core:error] [pid 499145:tid 499309] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_PH
[Sun Aug 30 03:06:54.260900 2026] [security2:error] [pid 500253:tid 500474] [client 20.104.50.220:62223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/tersembunyi.php"] [unique_id "apPknlmmXVd4kRvS-FAOiwAAAeg"]
[Sun Aug 30 03:06:54.264816 2026] [security2:error] [pid 500253:tid 500407] [client 4.205.62.107:26528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/dd.php"] [unique_id "apPknlmmXVd4kRvS-FAOkAAAAaU"]
[Sun Aug 30 03:06:54.296084 2026] [security2:error] [pid 499751:tid 499915] [client 20.63.81.20:43278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/Q1.php"] [unique_id "apPknjmmjdkPfMeJsKO9owAAA7c"]
[Sun Aug 30 03:06:54.331932 2026] [security2:error] [pid 500253:tid 500432] [client 180.252.161.46:54092] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "den-enterprises.com"] [uri "/"] [unique_id "apPknlmmXVd4kRvS-FAO0wAAAb4"]
[Sun Aug 30 03:06:54.349694 2026] [security2:error] [pid 500253:tid 500498] [client 158.23.147.79:54601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-admin/user/index.php"] [unique_id "apPknlmmXVd4kRvS-FAO6wAAAgA"]
[Sun Aug 30 03:06:54.350735 2026] [authz_core:error] [pid 499145:tid 499328] [client 66.249.66.38:42629] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:54.351162 2026] [authz_core:error] [pid 499145:tid 499328] [client 66.249.66.38:42629] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:54.373284 2026] [security2:error] [pid 500253:tid 500395] [client 20.104.18.15:34775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPknlmmXVd4kRvS-FAO-wAAAZk"]
[Sun Aug 30 03:06:54.373750 2026] [security2:error] [pid 500253:tid 500471] [client 51.254.132.238:36660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.132.254.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "myediblecravings.com"] [uri "/wp-comments-post.php"] [unique_id "apPknlmmXVd4kRvS-FAO-gAAAeU"], referer: http://myediblecravings.com/menu-list/desserts-baking/cookies/
[Sun Aug 30 03:06:54.373808 2026] [security2:error] [pid 500253:tid 500471] [client 51.254.132.238:36660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "myediblecravings.com"] [uri "/wp-comments-post.php"] [unique_id "apPknlmmXVd4kRvS-FAO-gAAAeU"], referer: http://myediblecravings.com/menu-list/desserts-baking/cookies/
[Sun Aug 30 03:06:54.387358 2026] [authz_core:error] [pid 499145:tid 499320] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:54.387835 2026] [authz_core:error] [pid 499145:tid 499320] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:54.404367 2026] [security2:error] [pid 499751:tid 499970] [client 20.104.49.130:52422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/memberfuns.php"] [unique_id "apPknjmmjdkPfMeJsKO95AAAA-4"]
[Sun Aug 30 03:06:54.413616 2026] [security2:error] [pid 500253:tid 500451] [client 20.104.50.220:27133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/printthread.php"] [unique_id "apPknlmmXVd4kRvS-FAPIwAAAdE"]
[Sun Aug 30 03:06:54.424977 2026] [security2:error] [pid 500253:tid 500386] [client 20.63.81.20:43224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/nz.php"] [unique_id "apPknlmmXVd4kRvS-FAPLgAAAZA"]
[Sun Aug 30 03:06:54.458116 2026] [security2:error] [pid 500253:tid 500456] [client 4.205.62.107:2804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/wp-info.php"] [unique_id "apPknlmmXVd4kRvS-FAPSQAAAdY"]
[Sun Aug 30 03:06:54.462830 2026] [security2:error] [pid 500253:tid 500451] [client 4.205.62.107:63942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/ms.php"] [unique_id "apPknlmmXVd4kRvS-FAPUAAAAdE"]
[Sun Aug 30 03:06:54.480840 2026] [security2:error] [pid 500253:tid 500394] [client 195.178.110.247:34018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marisarettori.it"] [uri "/index.php"] [unique_id "apPknlmmXVd4kRvS-FAPXwAAAZg"]
[Sun Aug 30 03:06:54.484705 2026] [authz_core:error] [pid 499751:tid 499896] [client 66.249.66.71:60286] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:54.485162 2026] [authz_core:error] [pid 499751:tid 499896] [client 66.249.66.71:60286] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:54.515111 2026] [security2:error] [pid 499751:tid 499942] [client 158.23.147.79:54221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-includes/plugins.php"] [unique_id "apPknjmmjdkPfMeJsKO-KgAAA9I"]
[Sun Aug 30 03:06:54.515437 2026] [security2:error] [pid 499751:tid 499967] [client 68.155.159.216:60893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-content/banners/about.php"] [unique_id "apPknjmmjdkPfMeJsKO-KwAAA-s"]
[Sun Aug 30 03:06:54.525203 2026] [security2:error] [pid 500253:tid 500509] [client 4.205.62.107:55256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/kedi.php"] [unique_id "apPknlmmXVd4kRvS-FAPiAAAAgs"]
[Sun Aug 30 03:06:54.531438 2026] [security2:error] [pid 500253:tid 500410] [client 20.48.251.3:49924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apPknlmmXVd4kRvS-FAPkAAAAag"]
[Sun Aug 30 03:06:54.543846 2026] [security2:error] [pid 499751:tid 499947] [client 20.104.49.130:52152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPknjmmjdkPfMeJsKO-QwAAA9c"]
[Sun Aug 30 03:06:54.552689 2026] [security2:error] [pid 499145:tid 499358] [client 20.63.81.20:43140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/sg.php"] [unique_id "apPknlJNq1G5uRhTNns8XgAAAFM"]
[Sun Aug 30 03:06:54.567099 2026] [security2:error] [pid 499751:tid 500022] [client 4.205.62.107:18642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/config/laravolt/css/index.php"] [unique_id "apPknjmmjdkPfMeJsKO-TQAABCI"]
[Sun Aug 30 03:06:54.569244 2026] [security2:error] [pid 500253:tid 500453] [client 158.23.147.79:53533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apPknlmmXVd4kRvS-FAPsAAAAdM"]
[Sun Aug 30 03:06:54.585720 2026] [security2:error] [pid 500253:tid 500457] [client 4.205.62.107:4545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/cli_bootstrap.php"] [unique_id "apPknlmmXVd4kRvS-FAPvAAAAdc"]
[Sun Aug 30 03:06:54.608410 2026] [security2:error] [pid 499145:tid 499384] [client 20.151.200.44:47369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPknlJNq1G5uRhTNns8gQAAAG0"]
[Sun Aug 30 03:06:54.609954 2026] [security2:error] [pid 499751:tid 500007] [client 20.151.200.44:55682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/dehnl.php"] [unique_id "apPknjmmjdkPfMeJsKO-VgAABBM"]
[Sun Aug 30 03:06:54.613283 2026] [security2:error] [pid 499751:tid 499994] [client 4.205.62.107:22968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/sale.php"] [unique_id "apPknjmmjdkPfMeJsKO-WAAABAY"]
[Sun Aug 30 03:06:54.618928 2026] [security2:error] [pid 500253:tid 500397] [client 20.104.50.220:32103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/local.php"] [unique_id "apPknlmmXVd4kRvS-FAPxgAAAZs"]
[Sun Aug 30 03:06:54.641127 2026] [security2:error] [pid 500253:tid 500392] [client 20.104.18.15:28656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/inso.php"] [unique_id "apPknlmmXVd4kRvS-FAP1QAAAZY"]
[Sun Aug 30 03:06:54.645635 2026] [security2:error] [pid 500253:tid 500414] [client 195.178.110.247:12670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marisarettori.it"] [uri "/index.php"] [unique_id "apPknlmmXVd4kRvS-FAP2QAAAaw"]
[Sun Aug 30 03:06:54.671739 2026] [security2:error] [pid 500253:tid 500483] [client 20.48.251.3:56352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/wsws.php"] [unique_id "apPknlmmXVd4kRvS-FAP6QAAAfE"]
[Sun Aug 30 03:06:54.672497 2026] [security2:error] [pid 500253:tid 500450] [client 20.104.50.220:17340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/greap.php"] [unique_id "apPknlmmXVd4kRvS-FAP6wAAAdA"]
[Sun Aug 30 03:06:54.679786 2026] [security2:error] [pid 499145:tid 499306] [client 20.63.81.20:43322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/hypo.php"] [unique_id "apPknlJNq1G5uRhTNns8lwAAAB8"]
[Sun Aug 30 03:06:54.704340 2026] [security2:error] [pid 499751:tid 499991] [client 20.104.50.220:52814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/bh.php"] [unique_id "apPknjmmjdkPfMeJsKO-hQAABAM"]
[Sun Aug 30 03:06:54.732018 2026] [authz_core:error] [pid 499145:tid 499344] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZW
[Sun Aug 30 03:06:54.732451 2026] [authz_core:error] [pid 499145:tid 499344] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZW
[Sun Aug 30 03:06:54.737073 2026] [security2:error] [pid 499751:tid 499968] [client 20.104.18.15:33753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/gjewuagf.php"] [unique_id "apPknjmmjdkPfMeJsKO-ngAAA-w"]
[Sun Aug 30 03:06:54.741900 2026] [security2:error] [pid 499751:tid 499993] [client 20.104.18.15:23427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/82.php"] [unique_id "apPknjmmjdkPfMeJsKO-ogAABAU"]
[Sun Aug 30 03:06:54.763355 2026] [authz_core:error] [pid 500253:tid 500394] [client 216.73.216.128:4988] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:54.763620 2026] [authz_core:error] [pid 500253:tid 500394] [client 216.73.216.128:4988] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:54.771498 2026] [security2:error] [pid 499751:tid 499990] [client 158.23.147.79:53544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apPknjmmjdkPfMeJsKO-sAAABAI"]
[Sun Aug 30 03:06:54.786352 2026] [security2:error] [pid 499145:tid 499360] [client 20.104.50.220:46447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wikindex.php"] [unique_id "apPknlJNq1G5uRhTNns8xwAAAFU"]
[Sun Aug 30 03:06:54.807882 2026] [security2:error] [pid 499751:tid 499989] [client 20.63.81.20:43235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/Hd.php"] [unique_id "apPknjmmjdkPfMeJsKO-ygAABAE"]
[Sun Aug 30 03:06:54.842274 2026] [security2:error] [pid 500253:tid 500396] [client 68.155.159.216:56328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-admin/images/about.php"] [unique_id "apPknlmmXVd4kRvS-FAQUQAAAZo"]
[Sun Aug 30 03:06:54.849656 2026] [security2:error] [pid 500253:tid 500445] [client 68.155.159.216:55117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apPknlmmXVd4kRvS-FAQVwAAAcs"]
[Sun Aug 30 03:06:54.849994 2026] [security2:error] [pid 499751:tid 499939] [client 158.23.147.79:54625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-includes/pomo/index.php"] [unique_id "apPknjmmjdkPfMeJsKO-7QAAA88"]
[Sun Aug 30 03:06:54.895032 2026] [authz_core:error] [pid 499145:tid 499348] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fmemory_hotplug%2Fparameters
[Sun Aug 30 03:06:54.895321 2026] [authz_core:error] [pid 499145:tid 499348] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fmemory_hotplug%2Fparameters
[Sun Aug 30 03:06:54.898916 2026] [security2:error] [pid 499751:tid 499952] [client 20.48.251.3:5115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/admin.php"] [unique_id "apPknjmmjdkPfMeJsKO-_QAAA9w"]
[Sun Aug 30 03:06:54.911434 2026] [security2:error] [pid 499751:tid 499985] [client 20.104.18.15:13569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apPknjmmjdkPfMeJsKO_BQAAA_0"]
[Sun Aug 30 03:06:54.943932 2026] [security2:error] [pid 500253:tid 500440] [client 195.178.110.247:34028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ermes-it.it"] [uri "/index.php"] [unique_id "apPknlmmXVd4kRvS-FAQmQAAAcY"]
[Sun Aug 30 03:06:54.949506 2026] [security2:error] [pid 500253:tid 500385] [client 20.151.200.44:27303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/attack.php"] [unique_id "apPknlmmXVd4kRvS-FAQoAAAAY8"]
[Sun Aug 30 03:06:54.950171 2026] [security2:error] [pid 499751:tid 500007] [client 20.104.50.220:6092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/ciera702.php"] [unique_id "apPknjmmjdkPfMeJsKO_FwAABBM"]
[Sun Aug 30 03:06:54.953935 2026] [security2:error] [pid 500253:tid 500463] [client 20.63.81.20:43374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/im.php"] [unique_id "apPknlmmXVd4kRvS-FAQpgAAAd0"]
[Sun Aug 30 03:06:54.959865 2026] [security2:error] [pid 500253:tid 500435] [client 180.252.161.46:54120] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "den-enterprises.com"] [uri "/wp-json/batch/v1"] [unique_id "apPknlmmXVd4kRvS-FAQnwAAAcE"]
[Sun Aug 30 03:06:54.964057 2026] [security2:error] [pid 499751:tid 499928] [client 20.48.251.3:7410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/brc.php"] [unique_id "apPknjmmjdkPfMeJsKO_JAAAA8Q"]
[Sun Aug 30 03:06:54.967040 2026] [authz_core:error] [pid 500253:tid 500453] [client 66.249.66.42:49028] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:54.967521 2026] [authz_core:error] [pid 500253:tid 500453] [client 66.249.66.42:49028] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:54.975292 2026] [authz_core:error] [pid 500253:tid 500483] [client 66.249.66.36:62598] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:54.975815 2026] [authz_core:error] [pid 500253:tid 500483] [client 66.249.66.36:62598] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:55.010870 2026] [security2:error] [pid 499751:tid 499921] [client 20.104.50.220:33184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/hh.php"] [unique_id "apPknzmmjdkPfMeJsKO_RQAAA70"]
[Sun Aug 30 03:06:55.023058 2026] [security2:error] [pid 500253:tid 500415] [client 158.23.147.79:54262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/nf_tracking.php"] [unique_id "apPkn1mmXVd4kRvS-FAQ0wAAAa0"]
[Sun Aug 30 03:06:55.045762 2026] [security2:error] [pid 499751:tid 499928] [client 68.155.159.216:61325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/dropdown.php"] [unique_id "apPknzmmjdkPfMeJsKO_VwAAA8Q"]
[Sun Aug 30 03:06:55.067761 2026] [security2:error] [pid 500253:tid 500446] [client 20.104.49.130:59576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/222.php"] [unique_id "apPkn1mmXVd4kRvS-FAQ-QAAAcw"]
[Sun Aug 30 03:06:55.077110 2026] [security2:error] [pid 500253:tid 500468] [client 158.23.147.79:54650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/goat1.php"] [unique_id "apPkn1mmXVd4kRvS-FARBQAAAeI"]
[Sun Aug 30 03:06:55.090997 2026] [security2:error] [pid 499751:tid 499932] [client 20.63.81.20:43271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/fc.php"] [unique_id "apPknzmmjdkPfMeJsKO_cgAAA8g"]
[Sun Aug 30 03:06:55.099214 2026] [security2:error] [pid 500253:tid 500386] [client 195.178.110.247:12672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ermes-it.it"] [uri "/index.php"] [unique_id "apPkn1mmXVd4kRvS-FAREAAAAZA"]
[Sun Aug 30 03:06:55.146611 2026] [authz_core:error] [pid 499751:tid 499897] [client 66.249.66.34:44057] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:55.147078 2026] [authz_core:error] [pid 499751:tid 499897] [client 66.249.66.34:44057] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:55.160391 2026] [security2:error] [pid 499145:tid 499377] [client 4.205.62.107:51741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/cu.php"] [unique_id "apPkn1JNq1G5uRhTNns9RgAAAGY"]
[Sun Aug 30 03:06:55.190370 2026] [security2:error] [pid 499145:tid 499296] [client 158.23.147.79:54616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wzy.php"] [unique_id "apPkn1JNq1G5uRhTNns9YQAAABU"]
[Sun Aug 30 03:06:55.206625 2026] [security2:error] [pid 499145:tid 499318] [client 4.205.62.107:60508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/wp-tem.php"] [unique_id "apPkn1JNq1G5uRhTNns9bgAAACs"]
[Sun Aug 30 03:06:55.218000 2026] [security2:error] [pid 500253:tid 500474] [client 20.63.81.20:43202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/ke.php"] [unique_id "apPkn1mmXVd4kRvS-FARWwAAAeg"]
[Sun Aug 30 03:06:55.232738 2026] [authz_core:error] [pid 499145:tid 499342] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_GB
[Sun Aug 30 03:06:55.233097 2026] [authz_core:error] [pid 499145:tid 499342] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_GB
[Sun Aug 30 03:06:55.241503 2026] [security2:error] [pid 499145:tid 499275] [client 20.104.18.15:43906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/wp-content/l.php"] [unique_id "apPkn1JNq1G5uRhTNns9iAAAAAA"]
[Sun Aug 30 03:06:55.250553 2026] [security2:error] [pid 500253:tid 500482] [client 158.23.147.79:54654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-includes/certificates/index.php"] [unique_id "apPkn1mmXVd4kRvS-FARdQAAAfA"]
[Sun Aug 30 03:06:55.251020 2026] [security2:error] [pid 500253:tid 500512] [client 20.104.18.15:29138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkn1mmXVd4kRvS-FARdwAAAg4"]
[Sun Aug 30 03:06:55.276921 2026] [lsapi:error] [pid 499751:tid 499803] [remote 98.97.106.43:38848] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:06:55.277086 2026] [lsapi:error] [pid 499751:tid 499803] [remote 98.97.106.43:38848] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:06:55.278501 2026] [lsapi:error] [pid 499751:tid 499803] [remote 98.97.106.43:38848] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:06:55.290271 2026] [security2:error] [pid 500253:tid 500431] [client 68.155.159.216:62308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/classwithtostring.php"] [unique_id "apPkn1mmXVd4kRvS-FARnQAAAb0"]
[Sun Aug 30 03:06:55.308839 2026] [authz_core:error] [pid 499145:tid 499366] [client 216.73.216.128:63106] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:55.309400 2026] [authz_core:error] [pid 499145:tid 499366] [client 216.73.216.128:63106] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:55.319166 2026] [security2:error] [pid 500253:tid 500483] [client 68.155.159.216:12290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-content/x/index.php"] [unique_id "apPkn1mmXVd4kRvS-FARswAAAfE"]
[Sun Aug 30 03:06:55.346099 2026] [security2:error] [pid 500253:tid 500486] [client 158.23.147.79:48137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-admin/setup-config.php"] [unique_id "apPkn1mmXVd4kRvS-FARzgAAAfQ"]
[Sun Aug 30 03:06:55.346683 2026] [security2:error] [pid 499751:tid 499978] [client 20.63.81.20:43246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/tf.php"] [unique_id "apPknzmmjdkPfMeJsKO_2AAAA_Y"]
[Sun Aug 30 03:06:55.353146 2026] [authz_core:error] [pid 500253:tid 500396] [client 66.249.66.41:39661] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:55.353705 2026] [authz_core:error] [pid 500253:tid 500396] [client 66.249.66.41:39661] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:55.383453 2026] [security2:error] [pid 499751:tid 499906] [client 20.104.50.220:62812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/cok.php"] [unique_id "apPknzmmjdkPfMeJsKO_6AAAA68"]
[Sun Aug 30 03:06:55.388209 2026] [security2:error] [pid 499751:tid 499993] [client 158.23.147.79:54223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-admin/network/index.php"] [unique_id "apPknzmmjdkPfMeJsKO_6wAABAU"]
[Sun Aug 30 03:06:55.395504 2026] [authz_core:error] [pid 499145:tid 499301] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:55.396030 2026] [authz_core:error] [pid 499145:tid 499301] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:55.402440 2026] [security2:error] [pid 500253:tid 500512] [client 4.205.62.107:64508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/thui.php"] [unique_id "apPkn1mmXVd4kRvS-FASBwAAAg4"]
[Sun Aug 30 03:06:55.417032 2026] [security2:error] [pid 499751:tid 500006] [client 20.104.50.220:51608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/info.php"] [unique_id "apPknzmmjdkPfMeJsKPABAAABBI"]
[Sun Aug 30 03:06:55.430288 2026] [security2:error] [pid 500253:tid 500482] [client 20.104.50.220:61966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/lab.php"] [unique_id "apPkn1mmXVd4kRvS-FASGAAAAfA"]
[Sun Aug 30 03:06:55.472369 2026] [security2:error] [pid 499145:tid 499241] [remote 114.119.144.165:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "vangeauxprint.com"] [uri "/"] [unique_id "apPkn1JNq1G5uRhTNns-GwAAHV8"], referer: https://vangeauxprint.com/
[Sun Aug 30 03:06:55.477411 2026] [security2:error] [pid 500253:tid 500389] [client 20.63.81.20:43325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/px.php"] [unique_id "apPkn1mmXVd4kRvS-FASMwAAAZM"]
[Sun Aug 30 03:06:55.518932 2026] [security2:error] [pid 499751:tid 499999] [client 20.104.18.15:34703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/wsd.php"] [unique_id "apPknzmmjdkPfMeJsKPATQAABAs"]
[Sun Aug 30 03:06:55.542196 2026] [authz_core:error] [pid 499751:tid 499894] [client 66.249.66.40:54721] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:55.542609 2026] [authz_core:error] [pid 499751:tid 499894] [client 66.249.66.40:54721] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:55.551036 2026] [security2:error] [pid 500253:tid 500427] [client 20.104.50.220:27581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/newreply.php"] [unique_id "apPkn1mmXVd4kRvS-FASbAAAAbk"]
[Sun Aug 30 03:06:55.574672 2026] [security2:error] [pid 499145:tid 499349] [client 180.252.161.46:29493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.161.252.180.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "den-enterprises.com"] [uri "/index.php"] [unique_id "apPkn1JNq1G5uRhTNns-VAAAAEo"]
[Sun Aug 30 03:06:55.589108 2026] [security2:error] [pid 499145:tid 499370] [client 158.23.147.79:53532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apPkn1JNq1G5uRhTNns-YwAAAF8"]
[Sun Aug 30 03:06:55.604015 2026] [security2:error] [pid 499145:tid 499315] [client 20.63.81.20:43361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/jg.php"] [unique_id "apPkn1JNq1G5uRhTNns-bgAAACg"]
[Sun Aug 30 03:06:55.608740 2026] [security2:error] [pid 499145:tid 499287] [client 4.205.62.107:62095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/fucku.php"] [unique_id "apPkn1JNq1G5uRhTNns-cwAAAAw"]
[Sun Aug 30 03:06:55.615758 2026] [security2:error] [pid 499751:tid 499949] [client 4.205.62.107:2993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/fns.php"] [unique_id "apPknzmmjdkPfMeJsKPAfQAAA9k"]
[Sun Aug 30 03:06:55.669586 2026] [security2:error] [pid 500253:tid 500394] [client 158.23.147.79:54619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apPkn1mmXVd4kRvS-FASowAAAZg"]
[Sun Aug 30 03:06:55.671989 2026] [security2:error] [pid 500253:tid 500447] [client 20.48.251.3:50038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/hochladen.form.php"] [unique_id "apPkn1mmXVd4kRvS-FASpAAAAc0"]
[Sun Aug 30 03:06:55.704745 2026] [security2:error] [pid 499145:tid 499326] [client 4.205.62.107:18686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/87.php"] [unique_id "apPkn1JNq1G5uRhTNns-sAAAADM"]
[Sun Aug 30 03:06:55.706139 2026] [security2:error] [pid 499145:tid 499291] [client 158.23.147.79:53559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apPkn1JNq1G5uRhTNns-sgAAABA"]
[Sun Aug 30 03:06:55.719546 2026] [security2:error] [pid 499751:tid 499971] [client 4.205.62.107:65302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/tax.php"] [unique_id "apPknzmmjdkPfMeJsKPAmQAAA-8"]
[Sun Aug 30 03:06:55.723462 2026] [security2:error] [pid 499751:tid 500003] [client 4.205.62.107:4148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/dd.php"] [unique_id "apPknzmmjdkPfMeJsKPAnQAABA8"]
[Sun Aug 30 03:06:55.730036 2026] [security2:error] [pid 500253:tid 500417] [client 68.155.159.216:60867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apPkn1mmXVd4kRvS-FAS1wAAAa8"]
[Sun Aug 30 03:06:55.732539 2026] [security2:error] [pid 499145:tid 499363] [client 20.63.81.20:43318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/yj.php"] [unique_id "apPkn1JNq1G5uRhTNns-wgAAAFg"]
[Sun Aug 30 03:06:55.752403 2026] [authz_core:error] [pid 499145:tid 499342] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZW
[Sun Aug 30 03:06:55.752777 2026] [authz_core:error] [pid 499145:tid 499342] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZW
[Sun Aug 30 03:06:55.762708 2026] [security2:error] [pid 500253:tid 500490] [client 4.205.62.107:22935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/wp-class.php"] [unique_id "apPkn1mmXVd4kRvS-FAS6QAAAfg"]
[Sun Aug 30 03:06:55.764289 2026] [authz_core:error] [pid 500253:tid 500506] [client 66.249.66.44:43688] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:55.764727 2026] [authz_core:error] [pid 500253:tid 500506] [client 66.249.66.44:43688] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:55.767048 2026] [security2:error] [pid 500253:tid 500451] [client 20.104.50.220:32415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/lolzk.php"] [unique_id "apPkn1mmXVd4kRvS-FAS6gAAAdE"]
[Sun Aug 30 03:06:55.773573 2026] [security2:error] [pid 499145:tid 499310] [client 216.73.216.128:63106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPkn1JNq1G5uRhTNns-3wAAACM"]
[Sun Aug 30 03:06:55.780617 2026] [security2:error] [pid 499145:tid 499389] [client 158.23.147.79:53536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/.well-knownold/index.php"] [unique_id "apPkn1JNq1G5uRhTNns-5QAAAHI"]
[Sun Aug 30 03:06:55.780823 2026] [security2:error] [pid 500253:tid 500399] [client 20.104.18.15:28621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/puc.php"] [unique_id "apPkn1mmXVd4kRvS-FAS9QAAAZ0"]
[Sun Aug 30 03:06:55.798026 2026] [security2:error] [pid 500253:tid 500387] [client 4.205.62.107:27276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/wp-tem.php"] [unique_id "apPkn1mmXVd4kRvS-FAS_wAAAZE"]
[Sun Aug 30 03:06:55.800088 2026] [security2:error] [pid 499145:tid 499344] [client 20.104.50.220:16718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/177.php"] [unique_id "apPkn1JNq1G5uRhTNns-7QAAAEU"]
[Sun Aug 30 03:06:55.809149 2026] [security2:error] [pid 500253:tid 500428] [client 20.48.251.3:33291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/localconf.php"] [unique_id "apPkn1mmXVd4kRvS-FATDQAAAbo"]
[Sun Aug 30 03:06:55.815845 2026] [security2:error] [pid 499751:tid 499958] [client 158.23.147.79:53553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apPknzmmjdkPfMeJsKPAtQAAA-I"]
[Sun Aug 30 03:06:55.845988 2026] [security2:error] [pid 500253:tid 500460] [client 4.205.62.107:32001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/oc460l3x.php"] [unique_id "apPkn1mmXVd4kRvS-FATIwAAAdo"]
[Sun Aug 30 03:06:55.852121 2026] [authz_core:error] [pid 500253:tid 500414] [client 66.249.66.75:62084] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:55.852386 2026] [authz_core:error] [pid 500253:tid 500414] [client 66.249.66.75:62084] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:55.854939 2026] [security2:error] [pid 500253:tid 500421] [client 20.104.50.220:62803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/sh3ll.php"] [unique_id "apPkn1mmXVd4kRvS-FATJwAAAbM"]
[Sun Aug 30 03:06:55.861160 2026] [authz_core:error] [pid 499751:tid 499920] [client 66.249.66.73:57117] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:55.861698 2026] [authz_core:error] [pid 499751:tid 499920] [client 66.249.66.73:57117] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:55.874680 2026] [security2:error] [pid 500253:tid 500467] [client 20.104.18.15:33773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/tnglzqmv.php"] [unique_id "apPkn1mmXVd4kRvS-FATNQAAAeE"]
[Sun Aug 30 03:06:55.877439 2026] [security2:error] [pid 500253:tid 500401] [client 20.104.18.15:23439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/dex.php"] [unique_id "apPkn1mmXVd4kRvS-FATOgAAAZ8"]
[Sun Aug 30 03:06:55.881246 2026] [security2:error] [pid 500253:tid 500450] [client 20.63.81.20:43309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/zi.php"] [unique_id "apPkn1mmXVd4kRvS-FATPQAAAdA"]
[Sun Aug 30 03:06:55.885467 2026] [security2:error] [pid 499145:tid 499317] [client 158.23.147.79:44273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apPkn1JNq1G5uRhTNns_HAAAACo"]
[Sun Aug 30 03:06:55.895974 2026] [authz_core:error] [pid 499145:tid 499303] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp
[Sun Aug 30 03:06:55.896418 2026] [authz_core:error] [pid 499145:tid 499303] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp
[Sun Aug 30 03:06:55.934136 2026] [security2:error] [pid 499751:tid 499970] [client 20.104.50.220:46422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-2019.php"] [unique_id "apPknzmmjdkPfMeJsKPA3wAAA-4"]
[Sun Aug 30 03:06:55.938571 2026] [security2:error] [pid 500253:tid 500432] [client 158.23.147.79:54609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apPkn1mmXVd4kRvS-FATYAAAAb4"]
[Sun Aug 30 03:06:55.949380 2026] [security2:error] [pid 499751:tid 499952] [client 20.151.200.44:47302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powells-e-graphics.com"] [uri "/waf.php"] [unique_id "apPknzmmjdkPfMeJsKPA4gAAA9w"]
[Sun Aug 30 03:06:55.991288 2026] [security2:error] [pid 500253:tid 500397] [client 68.155.159.216:54255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apPkn1mmXVd4kRvS-FATngAAAZs"]
[Sun Aug 30 03:06:55.999681 2026] [security2:error] [pid 499751:tid 499929] [client 158.23.147.79:54244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPknzmmjdkPfMeJsKPA9gAAA8U"]
[Sun Aug 30 03:06:56.009360 2026] [security2:error] [pid 499751:tid 499999] [client 20.63.81.20:43231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/ue.php"] [unique_id "apPkoDmmjdkPfMeJsKPA-wAABAs"]
[Sun Aug 30 03:06:56.012071 2026] [security2:error] [pid 500253:tid 500470] [client 68.155.159.216:56429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPkoFmmXVd4kRvS-FATtgAAAeQ"]
[Sun Aug 30 03:06:56.029127 2026] [security2:error] [pid 499751:tid 499991] [client 104.234.240.212:59520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.240.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "acs-ent.com"] [uri "/wp-login.php"] [unique_id "apPkoDmmjdkPfMeJsKPA-QAABAM"]
[Sun Aug 30 03:06:56.067342 2026] [security2:error] [pid 500253:tid 500388] [client 20.104.18.15:13602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/sao.php"] [unique_id "apPkoFmmXVd4kRvS-FAT5AAAAZI"]
[Sun Aug 30 03:06:56.087110 2026] [security2:error] [pid 499751:tid 499973] [client 20.104.50.220:5605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/chaya986.php"] [unique_id "apPkoDmmjdkPfMeJsKPBKgAAA_E"]
[Sun Aug 30 03:06:56.114122 2026] [security2:error] [pid 500253:tid 500396] [client 20.48.251.3:5080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/png.php"] [unique_id "apPkoFmmXVd4kRvS-FAT_wAAAZo"]
[Sun Aug 30 03:06:56.139601 2026] [security2:error] [pid 499145:tid 499343] [client 20.63.81.20:43340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/nv.php"] [unique_id "apPkoFJNq1G5uRhTNns_mAAAAEQ"]
[Sun Aug 30 03:06:56.148509 2026] [security2:error] [pid 500253:tid 500403] [client 20.104.50.220:33152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/hz.php"] [unique_id "apPkoFmmXVd4kRvS-FAUEwAAAaE"]
[Sun Aug 30 03:06:56.156409 2026] [security2:error] [pid 499751:tid 499981] [client 20.48.251.3:6472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/vx.php"] [unique_id "apPkoDmmjdkPfMeJsKPBOQAAA_k"]
[Sun Aug 30 03:06:56.181040 2026] [security2:error] [pid 500253:tid 500510] [client 158.23.147.79:44231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/packed.php"] [unique_id "apPkoFmmXVd4kRvS-FAUKAAAAgw"]
[Sun Aug 30 03:06:56.221469 2026] [security2:error] [pid 500253:tid 500509] [client 68.155.159.216:65437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/sad/about.php"] [unique_id "apPkoFmmXVd4kRvS-FAUQwAAAgs"]
[Sun Aug 30 03:06:56.240303 2026] [authz_core:error] [pid 500253:tid 500462] [client 216.73.216.128:4988] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:56.240653 2026] [authz_core:error] [pid 500253:tid 500462] [client 216.73.216.128:4988] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:56.249228 2026] [authz_core:error] [pid 499145:tid 499343] [client 66.249.66.41:43962] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:56.249629 2026] [authz_core:error] [pid 499145:tid 499343] [client 66.249.66.41:43962] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:56.255263 2026] [authz_core:error] [pid 499145:tid 499399] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_BW
[Sun Aug 30 03:06:56.255525 2026] [authz_core:error] [pid 499145:tid 499399] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_BW
[Sun Aug 30 03:06:56.276560 2026] [authz_core:error] [pid 499751:tid 499978] [client 66.249.66.41:59014] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:56.276929 2026] [authz_core:error] [pid 499751:tid 499978] [client 66.249.66.41:59014] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:56.280319 2026] [security2:error] [pid 500253:tid 500463] [client 158.23.147.79:54223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-content/packed.php"] [unique_id "apPkoFmmXVd4kRvS-FAUdQAAAd0"]
[Sun Aug 30 03:06:56.284267 2026] [security2:error] [pid 499145:tid 499281] [client 20.63.81.20:43244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/jw.php"] [unique_id "apPkoFJNq1G5uRhTNns_8QAAAAY"]
[Sun Aug 30 03:06:56.290661 2026] [security2:error] [pid 500253:tid 500426] [client 20.104.49.130:63281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/k.php"] [unique_id "apPkoFmmXVd4kRvS-FAUfgAAAbg"]
[Sun Aug 30 03:06:56.298734 2026] [security2:error] [pid 500253:tid 500481] [client 4.205.62.107:56950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/services.php"] [unique_id "apPkoFmmXVd4kRvS-FAUhwAAAe8"]
[Sun Aug 30 03:06:56.343061 2026] [security2:error] [pid 499751:tid 499901] [client 4.205.62.107:63586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/txets.php"] [unique_id "apPkoDmmjdkPfMeJsKPBnAAAA6o"]
[Sun Aug 30 03:06:56.367135 2026] [authz_core:error] [pid 500253:tid 500388] [client 66.249.66.68:63125] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:56.367467 2026] [authz_core:error] [pid 500253:tid 500388] [client 66.249.66.68:63125] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:56.375681 2026] [authz_core:error] [pid 500253:tid 500446] [client 66.249.66.76:57430] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:56.375913 2026] [authz_core:error] [pid 499145:tid 499401] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdpkg
[Sun Aug 30 03:06:56.376084 2026] [authz_core:error] [pid 500253:tid 500446] [client 66.249.66.76:57430] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:56.376321 2026] [authz_core:error] [pid 499145:tid 499401] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdpkg
[Sun Aug 30 03:06:56.390342 2026] [security2:error] [pid 499751:tid 499928] [client 20.104.18.15:29647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/media.php"] [unique_id "apPkoDmmjdkPfMeJsKPBtwAAA8Q"]
[Sun Aug 30 03:06:56.391490 2026] [security2:error] [pid 499751:tid 499929] [client 74.7.175.137:59548] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.popularnotion.beyondmycross.com"] [uri "/robots.txt"] [unique_id "apPkoDmmjdkPfMeJsKPBtgAAA8U"]
[Sun Aug 30 03:06:56.403253 2026] [security2:error] [pid 499751:tid 500003] [client 158.23.147.79:54240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-l0gin.php"] [unique_id "apPkoDmmjdkPfMeJsKPBxAAABA8"]
[Sun Aug 30 03:06:56.416992 2026] [security2:error] [pid 500253:tid 500444] [client 20.63.81.20:43256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/or.php"] [unique_id "apPkoFmmXVd4kRvS-FAVDAAAAco"]
[Sun Aug 30 03:06:56.420806 2026] [security2:error] [pid 499751:tid 500020] [client 20.104.18.15:44009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/wp-admin/w.php"] [unique_id "apPkoDmmjdkPfMeJsKPB1gAABCA"]
[Sun Aug 30 03:06:56.420832 2026] [security2:error] [pid 499751:tid 499963] [client 158.23.147.79:54639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/images/index.php"] [unique_id "apPkoDmmjdkPfMeJsKPB1QAAA-c"]
[Sun Aug 30 03:06:56.439876 2026] [security2:error] [pid 499751:tid 499937] [client 68.155.159.216:12318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apPkoDmmjdkPfMeJsKPB3QAAA80"]
[Sun Aug 30 03:06:56.449794 2026] [security2:error] [pid 499751:tid 499894] [client 68.155.159.216:62326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/install.php"] [unique_id "apPkoDmmjdkPfMeJsKPB5QAAA6M"]
[Sun Aug 30 03:06:56.535919 2026] [security2:error] [pid 499145:tid 499399] [client 20.104.50.220:29132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/cgipro.php"] [unique_id "apPkoFJNq1G5uRhTNntAegAAAHw"]
[Sun Aug 30 03:06:56.538033 2026] [security2:error] [pid 499145:tid 499389] [client 4.205.62.107:64681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/lala.php"] [unique_id "apPkoFJNq1G5uRhTNntAfgAAAHI"]
[Sun Aug 30 03:06:56.546932 2026] [security2:error] [pid 499145:tid 499337] [client 20.63.81.20:43389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/ile56.php"] [unique_id "apPkoFJNq1G5uRhTNntAhwAAAD4"]
[Sun Aug 30 03:06:56.561791 2026] [security2:error] [pid 499145:tid 499343] [client 158.23.147.79:53561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-includes/widgets/index.php"] [unique_id "apPkoFJNq1G5uRhTNntAlQAAAEQ"]
[Sun Aug 30 03:06:56.580047 2026] [security2:error] [pid 499145:tid 499339] [client 20.104.50.220:51592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/ini.php"] [unique_id "apPkoFJNq1G5uRhTNntApQAAAEA"]
[Sun Aug 30 03:06:56.655454 2026] [security2:error] [pid 499145:tid 499297] [client 20.104.18.15:34792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/bulet.php"] [unique_id "apPkoFJNq1G5uRhTNntAxAAAABY"]
[Sun Aug 30 03:06:56.660146 2026] [security2:error] [pid 500253:tid 500474] [client 20.104.49.130:52432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/tiny2.php"] [unique_id "apPkoFmmXVd4kRvS-FAV1AAAAeg"]
[Sun Aug 30 03:06:56.660993 2026] [security2:error] [pid 499751:tid 499991] [client 158.23.147.79:54265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apPkoDmmjdkPfMeJsKPCNgAABAM"]
[Sun Aug 30 03:06:56.675667 2026] [security2:error] [pid 499145:tid 499277] [client 20.63.81.20:43225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/emmh.php"] [unique_id "apPkoFJNq1G5uRhTNntAzwAAAAI"]
[Sun Aug 30 03:06:56.677989 2026] [security2:error] [pid 499145:tid 499283] [client 158.23.147.79:48141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apPkoFJNq1G5uRhTNntA0gAAAAg"]
[Sun Aug 30 03:06:56.689055 2026] [security2:error] [pid 500253:tid 500403] [client 20.104.50.220:27113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/portal.php"] [unique_id "apPkoFmmXVd4kRvS-FAV4QAAAaE"]
[Sun Aug 30 03:06:56.736468 2026] [authz_core:error] [pid 499145:tid 499317] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZW
[Sun Aug 30 03:06:56.736921 2026] [authz_core:error] [pid 499145:tid 499317] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZW
[Sun Aug 30 03:06:56.759674 2026] [security2:error] [pid 499145:tid 499302] [client 158.23.184.117:15957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/new.php"] [unique_id "apPkoFJNq1G5uRhTNntBCgAAABs"]
[Sun Aug 30 03:06:56.762905 2026] [security2:error] [pid 500253:tid 500443] [client 4.205.62.107:2336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/params.php"] [unique_id "apPkoFmmXVd4kRvS-FAWLAAAAck"]
[Sun Aug 30 03:06:56.765629 2026] [security2:error] [pid 499145:tid 499344] [client 4.205.62.107:39142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/error_log.php"] [unique_id "apPkoFJNq1G5uRhTNntBEAAAAEU"]
[Sun Aug 30 03:06:56.783916 2026] [security2:error] [pid 500253:tid 500407] [client 158.23.147.79:53555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apPkoFmmXVd4kRvS-FAWOAAAAaU"]
[Sun Aug 30 03:06:56.786593 2026] [authz_core:error] [pid 500253:tid 500484] [client 66.249.66.73:36537] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:56.786918 2026] [authz_core:error] [pid 500253:tid 500484] [client 66.249.66.73:36537] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:56.804144 2026] [security2:error] [pid 499145:tid 499295] [client 20.63.81.20:43298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/em.php"] [unique_id "apPkoFJNq1G5uRhTNntBKwAAABQ"]
[Sun Aug 30 03:06:56.811075 2026] [security2:error] [pid 499145:tid 499300] [client 20.48.251.3:55483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/debuggen.php"] [unique_id "apPkoFJNq1G5uRhTNntBMAAAABk"]
[Sun Aug 30 03:06:56.832957 2026] [security2:error] [pid 500253:tid 500433] [client 68.155.159.216:60871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/asd.php"] [unique_id "apPkoFmmXVd4kRvS-FAWXAAAAb8"]
[Sun Aug 30 03:06:56.842782 2026] [security2:error] [pid 499145:tid 499384] [client 4.205.62.107:18670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/plss3.php"] [unique_id "apPkoFJNq1G5uRhTNntBRgAAAG0"]
[Sun Aug 30 03:06:56.874677 2026] [security2:error] [pid 500253:tid 500394] [client 4.205.62.107:4131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/wp-tem.php"] [unique_id "apPkoFmmXVd4kRvS-FAWfgAAAZg"]
[Sun Aug 30 03:06:56.897842 2026] [security2:error] [pid 500253:tid 500473] [client 4.205.62.107:22971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/database.php"] [unique_id "apPkoFmmXVd4kRvS-FAWmAAAAec"]
[Sun Aug 30 03:06:56.900896 2026] [authz_core:error] [pid 500253:tid 500443] [client 66.249.66.67:38332] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:56.901370 2026] [authz_core:error] [pid 500253:tid 500443] [client 66.249.66.67:38332] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:56.905621 2026] [security2:error] [pid 499145:tid 499360] [client 20.104.50.220:31912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/marijuana.php"] [unique_id "apPkoFJNq1G5uRhTNntBYAAAAFU"]
[Sun Aug 30 03:06:56.918368 2026] [security2:error] [pid 500253:tid 500503] [client 20.104.18.15:28622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/19.php"] [unique_id "apPkoFmmXVd4kRvS-FAWpQAAAgU"]
[Sun Aug 30 03:06:56.922534 2026] [authz_core:error] [pid 499145:tid 499355] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:56.922994 2026] [authz_core:error] [pid 499145:tid 499355] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:06:56.935984 2026] [security2:error] [pid 499751:tid 499900] [client 20.63.81.20:43339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/dvve.php"] [unique_id "apPkoDmmjdkPfMeJsKPCkwAAA6k"]
[Sun Aug 30 03:06:56.938251 2026] [security2:error] [pid 500253:tid 500394] [client 20.104.50.220:16733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/199.php"] [unique_id "apPkoFmmXVd4kRvS-FAWrwAAAZg"]
[Sun Aug 30 03:06:56.950718 2026] [security2:error] [pid 499751:tid 499934] [client 20.48.251.3:56370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/bengi.php"] [unique_id "apPkoDmmjdkPfMeJsKPClgAAA8o"]
[Sun Aug 30 03:06:56.953542 2026] [security2:error] [pid 499145:tid 499377] [client 158.23.184.117:15996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/bypass.php"] [unique_id "apPkoFJNq1G5uRhTNntBegAAAGY"]
[Sun Aug 30 03:06:56.965902 2026] [security2:error] [pid 500253:tid 500453] [client 158.23.147.79:44250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPkoFmmXVd4kRvS-FAW0AAAAdM"]
[Sun Aug 30 03:06:56.968204 2026] [authz_core:error] [pid 500253:tid 500473] [client 216.73.216.128:21183] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:56.968721 2026] [authz_core:error] [pid 500253:tid 500473] [client 216.73.216.128:21183] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:56.995097 2026] [security2:error] [pid 500253:tid 500506] [client 20.104.50.220:29164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/shell.php"] [unique_id "apPkoFmmXVd4kRvS-FAW6AAAAgg"]
[Sun Aug 30 03:06:57.013352 2026] [security2:error] [pid 500253:tid 500451] [client 20.104.18.15:33709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/wefile.php"] [unique_id "apPkoVmmXVd4kRvS-FAW-wAAAdE"]
[Sun Aug 30 03:06:57.030718 2026] [security2:error] [pid 500253:tid 500500] [client 20.104.18.15:23539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/inso.php"] [unique_id "apPkoVmmXVd4kRvS-FAXDgAAAgI"]
[Sun Aug 30 03:06:57.042702 2026] [security2:error] [pid 500253:tid 500442] [client 158.23.147.79:54616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-includes/pomo/index.php"] [unique_id "apPkoVmmXVd4kRvS-FAXFwAAAcg"]
[Sun Aug 30 03:06:57.062673 2026] [security2:error] [pid 500253:tid 500452] [client 20.63.81.20:43230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/doo.php"] [unique_id "apPkoVmmXVd4kRvS-FAXKwAAAdI"]
[Sun Aug 30 03:06:57.085605 2026] [security2:error] [pid 500253:tid 500478] [client 20.104.50.220:46639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-atom.php"] [unique_id "apPkoVmmXVd4kRvS-FAXQgAAAew"]
[Sun Aug 30 03:06:57.095232 2026] [security2:error] [pid 499751:tid 499900] [client 158.23.184.117:15999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/db/uploader.php"] [unique_id "apPkoTmmjdkPfMeJsKPC6AAAA6k"]
[Sun Aug 30 03:06:57.107521 2026] [security2:error] [pid 499751:tid 499928] [client 46.105.46.43:11309] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "healthonthemenu.com"] [uri "/robots.txt"] [unique_id "apPkoTmmjdkPfMeJsKPC7AAAA8Q"]
[Sun Aug 30 03:06:57.107635 2026] [security2:error] [pid 499751:tid 499928] [client 46.105.46.43:11309] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "healthonthemenu.com"] [uri "/robots.txt"] [unique_id "apPkoTmmjdkPfMeJsKPC7AAAA8Q"]
[Sun Aug 30 03:06:57.107707 2026] [authz_core:error] [pid 499145:tid 499302] [client 66.249.66.206:64460] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:57.108135 2026] [authz_core:error] [pid 499145:tid 499302] [client 66.249.66.206:64460] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:57.119103 2026] [security2:error] [pid 500253:tid 500498] [client 68.155.159.216:56395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-admin.php"] [unique_id "apPkoVmmXVd4kRvS-FAXTwAAAgA"]
[Sun Aug 30 03:06:57.154173 2026] [security2:error] [pid 500253:tid 500417] [client 68.155.159.216:55126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/simple.php"] [unique_id "apPkoVmmXVd4kRvS-FAXZgAAAa8"]
[Sun Aug 30 03:06:57.166411 2026] [security2:error] [pid 500253:tid 500386] [client 4.205.62.107:65350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPkoVmmXVd4kRvS-FAXcQAAAZA"]
[Sun Aug 30 03:06:57.190730 2026] [security2:error] [pid 499751:tid 499894] [client 20.63.81.20:43352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/adminer-4.6.6.php"] [unique_id "apPkoTmmjdkPfMeJsKPDCAAAA6M"]
[Sun Aug 30 03:06:57.196940 2026] [security2:error] [pid 499751:tid 499899] [client 158.23.147.79:54607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/nf_tracking.php"] [unique_id "apPkoTmmjdkPfMeJsKPDCwAAA6g"]
[Sun Aug 30 03:06:57.204391 2026] [security2:error] [pid 499751:tid 500010] [client 20.104.18.15:13600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/dapa.php"] [unique_id "apPkoTmmjdkPfMeJsKPDDgAABBY"]
[Sun Aug 30 03:06:57.210620 2026] [lsapi:error] [pid 500253:tid 500315] [remote 76.182.214.212:60264] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://gracelikestogarden.com/
[Sun Aug 30 03:06:57.210804 2026] [lsapi:error] [pid 500253:tid 500315] [remote 76.182.214.212:60264] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://gracelikestogarden.com/
[Sun Aug 30 03:06:57.212367 2026] [lsapi:error] [pid 500253:tid 500315] [remote 76.182.214.212:60264] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n, referer: https://gracelikestogarden.com/
[Sun Aug 30 03:06:57.225459 2026] [security2:error] [pid 500253:tid 500471] [client 20.104.50.220:5794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/charmaine744.php"] [unique_id "apPkoVmmXVd4kRvS-FAXnwAAAeU"]
[Sun Aug 30 03:06:57.236511 2026] [security2:error] [pid 500253:tid 500418] [client 158.23.184.117:15951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/i.php"] [unique_id "apPkoVmmXVd4kRvS-FAXqwAAAbA"]
[Sun Aug 30 03:06:57.252462 2026] [security2:error] [pid 499751:tid 499958] [client 158.23.147.79:44229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/ans.php"] [unique_id "apPkoTmmjdkPfMeJsKPDMAAAA-I"]
[Sun Aug 30 03:06:57.259603 2026] [authz_core:error] [pid 499145:tid 499296] [client 66.249.66.37:56159] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:57.259918 2026] [authz_core:error] [pid 499145:tid 499296] [client 66.249.66.37:56159] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:57.264274 2026] [authz_core:error] [pid 499145:tid 499364] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZW
[Sun Aug 30 03:06:57.264561 2026] [authz_core:error] [pid 499145:tid 499364] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZW
[Sun Aug 30 03:06:57.282242 2026] [security2:error] [pid 499751:tid 499932] [client 20.48.251.3:4168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/chosen.php"] [unique_id "apPkoTmmjdkPfMeJsKPDQAAAA8g"]
[Sun Aug 30 03:06:57.291465 2026] [security2:error] [pid 499751:tid 499915] [client 4.205.62.107:26529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/txets.php"] [unique_id "apPkoTmmjdkPfMeJsKPDRAAAA7c"]
[Sun Aug 30 03:06:57.307464 2026] [security2:error] [pid 499751:tid 500010] [client 20.104.49.130:45723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/az.php"] [unique_id "apPkoTmmjdkPfMeJsKPDTAAABBY"]
[Sun Aug 30 03:06:57.317313 2026] [security2:error] [pid 499751:tid 499971] [client 47.128.31.20:42490] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cravegoldcoast.com.au"] [uri "/robots.txt"] [unique_id "apPkoTmmjdkPfMeJsKPDTgAAA-8"]
[Sun Aug 30 03:06:57.317720 2026] [security2:error] [pid 499751:tid 499998] [client 20.63.81.20:43367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/gelap1.php"] [unique_id "apPkoTmmjdkPfMeJsKPDTwAABAo"]
[Sun Aug 30 03:06:57.321493 2026] [security2:error] [pid 500253:tid 500446] [client 20.104.50.220:33199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/here.php"] [unique_id "apPkoVmmXVd4kRvS-FAX8QAAAcw"]
[Sun Aug 30 03:06:57.358500 2026] [security2:error] [pid 499751:tid 499944] [client 158.23.147.79:54605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/worksec.php"] [unique_id "apPkoTmmjdkPfMeJsKPDlgAAA9Q"]
[Sun Aug 30 03:06:57.369953 2026] [security2:error] [pid 499751:tid 499919] [client 20.151.200.44:27326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/wk/index.php"] [unique_id "apPkoTmmjdkPfMeJsKPDpwAAA7s"]
[Sun Aug 30 03:06:57.376633 2026] [authz_core:error] [pid 499145:tid 499394] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp
[Sun Aug 30 03:06:57.377102 2026] [authz_core:error] [pid 499145:tid 499394] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp
[Sun Aug 30 03:06:57.423104 2026] [authz_core:error] [pid 500253:tid 500393] [client 66.249.66.65:51682] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:57.423596 2026] [authz_core:error] [pid 500253:tid 500393] [client 66.249.66.65:51682] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:57.426303 2026] [authz_core:error] [pid 500253:tid 500385] [client 216.73.216.128:21183] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:57.426813 2026] [authz_core:error] [pid 500253:tid 500385] [client 216.73.216.128:21183] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:57.428043 2026] [security2:error] [pid 499751:tid 500000] [client 158.23.184.117:15949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/wp-admin/css/index.php"] [unique_id "apPkoTmmjdkPfMeJsKPEAgAABAw"]
[Sun Aug 30 03:06:57.446374 2026] [security2:error] [pid 500253:tid 500452] [client 20.63.81.20:43221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/rsjlrria.php"] [unique_id "apPkoVmmXVd4kRvS-FAYNwAAAdI"]
[Sun Aug 30 03:06:57.454440 2026] [security2:error] [pid 499751:tid 499926] [client 4.205.62.107:56576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/filesystems.php"] [unique_id "apPkoTmmjdkPfMeJsKPEIAAAA8I"]
[Sun Aug 30 03:06:57.464143 2026] [security2:error] [pid 500253:tid 500399] [client 158.23.147.79:53546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/x.php"] [unique_id "apPkoVmmXVd4kRvS-FAYTAAAAZ0"]
[Sun Aug 30 03:06:57.469553 2026] [security2:error] [pid 499751:tid 499968] [client 68.155.159.216:64785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/admin.php"] [unique_id "apPkoTmmjdkPfMeJsKPELgAAA-w"]
[Sun Aug 30 03:06:57.478486 2026] [security2:error] [pid 499751:tid 499976] [client 158.23.147.79:54593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wzy.php"] [unique_id "apPkoTmmjdkPfMeJsKPERgAAA_Q"]
[Sun Aug 30 03:06:57.480746 2026] [security2:error] [pid 499751:tid 499912] [client 4.205.62.107:63760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/time.php"] [unique_id "apPkoTmmjdkPfMeJsKPESgAAA7Q"]
[Sun Aug 30 03:06:57.482292 2026] [security2:error] [pid 499751:tid 499931] [client 20.48.251.3:7385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/adminer-4.7.6-en.php"] [unique_id "apPkoTmmjdkPfMeJsKPETAAAA8c"]
[Sun Aug 30 03:06:57.504997 2026] [security2:error] [pid 499751:tid 499922] [client 4.205.62.107:32489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/drykl.php"] [unique_id "apPkoTmmjdkPfMeJsKPEYQAAA74"]
[Sun Aug 30 03:06:57.507319 2026] [security2:error] [pid 500253:tid 500468] [client 216.73.216.128:57592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/summary.csv"] [unique_id "apPkoVmmXVd4kRvS-FAYZQAAAeI"]
[Sun Aug 30 03:06:57.527984 2026] [security2:error] [pid 499751:tid 500016] [client 20.104.18.15:29173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/adminfuns.php"] [unique_id "apPkoTmmjdkPfMeJsKPEfgAABBw"]
[Sun Aug 30 03:06:57.568990 2026] [security2:error] [pid 499751:tid 499978] [client 158.23.147.79:53557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-content/x.php"] [unique_id "apPkoTmmjdkPfMeJsKPEtAAAA_Y"]
[Sun Aug 30 03:06:57.569168 2026] [security2:error] [pid 499751:tid 499899] [client 68.155.159.216:12319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apPkoTmmjdkPfMeJsKPEtQAAA6g"]
[Sun Aug 30 03:06:57.572489 2026] [security2:error] [pid 500253:tid 500487] [client 20.63.81.20:43231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/AxAo.php"] [unique_id "apPkoVmmXVd4kRvS-FAYgwAAAfU"]
[Sun Aug 30 03:06:57.581620 2026] [security2:error] [pid 499751:tid 499980] [client 158.23.184.117:16023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/wp-content/index.php"] [unique_id "apPkoTmmjdkPfMeJsKPEwwAAA_g"]
[Sun Aug 30 03:06:57.602347 2026] [security2:error] [pid 500253:tid 500504] [client 68.155.159.216:61687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-content/x/index.php"] [unique_id "apPkoVmmXVd4kRvS-FAYkAAAAgY"]
[Sun Aug 30 03:06:57.603782 2026] [security2:error] [pid 499751:tid 499906] [client 20.151.200.44:27145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/dehnl.php"] [unique_id "apPkoTmmjdkPfMeJsKPE1AAAA68"]
[Sun Aug 30 03:06:57.612604 2026] [security2:error] [pid 499751:tid 499968] [client 20.104.18.15:43854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/wp-content/k.php"] [unique_id "apPkoTmmjdkPfMeJsKPE2wAAA-w"]
[Sun Aug 30 03:06:57.615727 2026] [security2:error] [pid 499751:tid 499985] [client 20.104.50.220:61999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-raze.php"] [unique_id "apPkoTmmjdkPfMeJsKPE4QAAA_0"]
[Sun Aug 30 03:06:57.674407 2026] [security2:error] [pid 499751:tid 499937] [client 4.205.62.107:64460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/public/bnn_.php.php"] [unique_id "apPkoTmmjdkPfMeJsKPFCwAAA80"]
[Sun Aug 30 03:06:57.698476 2026] [security2:error] [pid 499145:tid 499282] [client 20.63.81.20:43269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/class17.php"] [unique_id "apPkoVJNq1G5uRhTNntCpwAAAAc"]
[Sun Aug 30 03:06:57.708238 2026] [security2:error] [pid 499751:tid 499959] [client 158.23.147.79:54603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPkoTmmjdkPfMeJsKPFJQAAA-M"]
[Sun Aug 30 03:06:57.725508 2026] [security2:error] [pid 500253:tid 500448] [client 20.104.50.220:41989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/help.php"] [unique_id "apPkoVmmXVd4kRvS-FAYxgAAAc4"]
[Sun Aug 30 03:06:57.727125 2026] [security2:error] [pid 499751:tid 499953] [client 20.104.50.220:62803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/css.php"] [unique_id "apPkoTmmjdkPfMeJsKPFQQAAA90"]
[Sun Aug 30 03:06:57.730710 2026] [security2:error] [pid 499751:tid 499899] [client 158.23.184.117:15950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPkoTmmjdkPfMeJsKPFQgAAA6g"]
[Sun Aug 30 03:06:57.755448 2026] [authz_core:error] [pid 499145:tid 499378] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_PH
[Sun Aug 30 03:06:57.755883 2026] [authz_core:error] [pid 499145:tid 499378] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_PH
[Sun Aug 30 03:06:57.802354 2026] [security2:error] [pid 499751:tid 499988] [client 20.104.18.15:34801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/av.php"] [unique_id "apPkoTmmjdkPfMeJsKPFfAAABAA"]
[Sun Aug 30 03:06:57.802774 2026] [security2:error] [pid 499751:tid 499919] [client 158.23.147.79:54624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-admin/setup-config.php"] [unique_id "apPkoTmmjdkPfMeJsKPFfgAAA7s"]
[Sun Aug 30 03:06:57.823423 2026] [security2:error] [pid 499751:tid 499929] [client 158.23.147.79:44228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/log-mama/function.php"] [unique_id "apPkoTmmjdkPfMeJsKPFjwAAA8U"]
[Sun Aug 30 03:06:57.825048 2026] [security2:error] [pid 499751:tid 499976] [client 20.104.50.220:27123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/bootstrap.php"] [unique_id "apPkoTmmjdkPfMeJsKPFkwAAA_Q"]
[Sun Aug 30 03:06:57.845398 2026] [security2:error] [pid 500253:tid 500511] [client 20.63.81.20:43214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/okxoby.php"] [unique_id "apPkoVmmXVd4kRvS-FAY7QAAAg0"]
[Sun Aug 30 03:06:57.872403 2026] [security2:error] [pid 500253:tid 500403] [client 158.23.184.117:15982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPkoVmmXVd4kRvS-FAZAQAAAaE"]
[Sun Aug 30 03:06:57.876035 2026] [authz_core:error] [pid 499145:tid 499315] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp%2Fholders
[Sun Aug 30 03:06:57.876345 2026] [authz_core:error] [pid 499145:tid 499315] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp%2Fholders
[Sun Aug 30 03:06:57.880217 2026] [authz_core:error] [pid 500253:tid 500467] [client 216.73.216.128:21183] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:57.880665 2026] [authz_core:error] [pid 500253:tid 500467] [client 216.73.216.128:21183] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:57.900827 2026] [security2:error] [pid 500253:tid 500416] [client 4.205.62.107:62101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/phina.php"] [unique_id "apPkoVmmXVd4kRvS-FAZDgAAAa4"]
[Sun Aug 30 03:06:57.907393 2026] [security2:error] [pid 499751:tid 499978] [client 4.205.62.107:2351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/gjm.php"] [unique_id "apPkoTmmjdkPfMeJsKPF4gAAA_Y"]
[Sun Aug 30 03:06:57.923258 2026] [authz_core:error] [pid 500253:tid 500406] [client 66.249.66.42:38582] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:57.923663 2026] [authz_core:error] [pid 500253:tid 500406] [client 66.249.66.42:38582] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:57.927969 2026] [security2:error] [pid 499145:tid 499295] [client 158.23.147.79:54649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/bk/index.php"] [unique_id "apPkoVJNq1G5uRhTNntC_AAAABQ"]
[Sun Aug 30 03:06:57.939504 2026] [security2:error] [pid 499751:tid 500012] [client 68.155.159.216:61427] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.rtsicomply.com"] [uri "/1.php"] [unique_id "apPkoTmmjdkPfMeJsKPF8gAABBg"]
[Sun Aug 30 03:06:57.939578 2026] [security2:error] [pid 499751:tid 500012] [client 68.155.159.216:61427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/1.php"] [unique_id "apPkoTmmjdkPfMeJsKPF8gAABBg"]
[Sun Aug 30 03:06:57.945424 2026] [security2:error] [pid 499751:tid 499936] [client 20.48.251.3:49932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/pouhg.php"] [unique_id "apPkoTmmjdkPfMeJsKPF-AAAA8w"]
[Sun Aug 30 03:06:57.975330 2026] [security2:error] [pid 499751:tid 499947] [client 20.63.81.20:43302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/esuutzzx.php"] [unique_id "apPkoTmmjdkPfMeJsKPGHwAAA9c"]
[Sun Aug 30 03:06:57.980588 2026] [security2:error] [pid 499751:tid 499977] [client 4.205.62.107:18959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/aws.php"] [unique_id "apPkoTmmjdkPfMeJsKPGIgAAA_U"]
[Sun Aug 30 03:06:57.986005 2026] [authz_core:error] [pid 500253:tid 500407] [client 66.249.66.39:40662] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:57.986352 2026] [authz_core:error] [pid 500253:tid 500407] [client 66.249.66.39:40662] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:58.021792 2026] [security2:error] [pid 500253:tid 500442] [client 4.205.62.107:4135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/txets.php"] [unique_id "apPkolmmXVd4kRvS-FAZTQAAAcg"]
[Sun Aug 30 03:06:58.041896 2026] [security2:error] [pid 499751:tid 499915] [client 4.205.62.107:62406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/atex1.php"] [unique_id "apPkojmmjdkPfMeJsKPGWQAAA7c"]
[Sun Aug 30 03:06:58.053939 2026] [security2:error] [pid 500253:tid 500444] [client 20.104.18.15:28571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/133.php"] [unique_id "apPkolmmXVd4kRvS-FAZWwAAAco"]
[Sun Aug 30 03:06:58.061485 2026] [security2:error] [pid 499751:tid 499971] [client 158.23.184.117:15946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/wp-load.php"] [unique_id "apPkojmmjdkPfMeJsKPGawAAA-8"]
[Sun Aug 30 03:06:58.071697 2026] [security2:error] [pid 499751:tid 500018] [client 20.104.50.220:31884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/mas.php"] [unique_id "apPkojmmjdkPfMeJsKPGeAAABB4"]
[Sun Aug 30 03:06:58.075517 2026] [security2:error] [pid 499751:tid 499943] [client 158.23.147.79:44268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.sculpturealley.net"] [uri "/first.php"] [unique_id "apPkojmmjdkPfMeJsKPGfgAAA9M"]
[Sun Aug 30 03:06:58.075798 2026] [security2:error] [pid 500253:tid 500387] [client 20.104.50.220:17342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/file52.php"] [unique_id "apPkolmmXVd4kRvS-FAZcgAAAZE"]
[Sun Aug 30 03:06:58.086085 2026] [security2:error] [pid 500253:tid 500510] [client 20.48.251.3:60492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/i.php"] [unique_id "apPkolmmXVd4kRvS-FAZdQAAAgw"]
[Sun Aug 30 03:06:58.086978 2026] [authz_core:error] [pid 500253:tid 500485] [client 66.249.66.69:41345] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:58.087237 2026] [authz_core:error] [pid 500253:tid 500485] [client 66.249.66.69:41345] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:58.106304 2026] [security2:error] [pid 499751:tid 499996] [client 20.63.81.20:43151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/replace.php"] [unique_id "apPkojmmjdkPfMeJsKPGmQAABAg"]
[Sun Aug 30 03:06:58.133210 2026] [security2:error] [pid 499751:tid 499943] [client 20.104.50.220:29587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/indonesia.php"] [unique_id "apPkojmmjdkPfMeJsKPGswAAA9M"]
[Sun Aug 30 03:06:58.140072 2026] [security2:error] [pid 499751:tid 499940] [client 20.104.49.130:57616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/v2.php"] [unique_id "apPkojmmjdkPfMeJsKPGuAAAA9A"]
[Sun Aug 30 03:06:58.153114 2026] [security2:error] [pid 499751:tid 499950] [client 20.104.18.15:33671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/blog.php"] [unique_id "apPkojmmjdkPfMeJsKPGxAAAA9o"]
[Sun Aug 30 03:06:58.178365 2026] [security2:error] [pid 499751:tid 499923] [client 20.104.18.15:23528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/aa.php"] [unique_id "apPkojmmjdkPfMeJsKPG3gAAA78"]
[Sun Aug 30 03:06:58.200942 2026] [authz_core:error] [pid 499751:tid 499990] [client 66.249.66.34:44057] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:58.201233 2026] [authz_core:error] [pid 499751:tid 499990] [client 66.249.66.34:44057] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:58.203389 2026] [security2:error] [pid 499751:tid 499961] [client 158.23.184.117:16020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/222.php"] [unique_id "apPkojmmjdkPfMeJsKPG-QAAA-U"]
[Sun Aug 30 03:06:58.208054 2026] [security2:error] [pid 499751:tid 499938] [client 20.104.50.220:16733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/122.php"] [unique_id "apPkojmmjdkPfMeJsKPHAwAAA84"]
[Sun Aug 30 03:06:58.238470 2026] [security2:error] [pid 500253:tid 500477] [client 20.104.50.220:47100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-bita.php"] [unique_id "apPkolmmXVd4kRvS-FAZqAAAAes"]
[Sun Aug 30 03:06:58.239333 2026] [security2:error] [pid 499751:tid 499937] [client 20.63.81.20:43148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/gulu.php"] [unique_id "apPkojmmjdkPfMeJsKPHJwAAA80"]
[Sun Aug 30 03:06:58.241948 2026] [security2:error] [pid 499751:tid 499938] [client 20.151.200.44:27276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/png.php"] [unique_id "apPkojmmjdkPfMeJsKPHKwAAA84"]
[Sun Aug 30 03:06:58.269039 2026] [access_compat:error] [pid 499751:tid 499815] [remote 74.7.227.131:57632] AH01797: client denied by server configuration: /home1/joshuapz/public_html/allieandjosh.love/, referer: https://wiki-park.com
[Sun Aug 30 03:06:58.274160 2026] [authz_core:error] [pid 499145:tid 499398] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_PH
[Sun Aug 30 03:06:58.274591 2026] [authz_core:error] [pid 499145:tid 499398] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_PH
[Sun Aug 30 03:06:58.277923 2026] [authz_core:error] [pid 499145:tid 499396] [client 66.249.66.206:64460] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:58.278384 2026] [authz_core:error] [pid 499145:tid 499396] [client 66.249.66.206:64460] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:58.284076 2026] [security2:error] [pid 500253:tid 500426] [client 68.155.159.216:11226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apPkolmmXVd4kRvS-FAZygAAAbg"]
[Sun Aug 30 03:06:58.297821 2026] [security2:error] [pid 500253:tid 500467] [client 68.155.159.216:54251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-admin/about.php"] [unique_id "apPkolmmXVd4kRvS-FAZ0gAAAeE"]
[Sun Aug 30 03:06:58.335403 2026] [authz_core:error] [pid 500253:tid 500491] [client 216.73.216.128:21183] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:58.335857 2026] [authz_core:error] [pid 500253:tid 500491] [client 216.73.216.128:21183] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:58.346486 2026] [security2:error] [pid 499751:tid 499969] [client 158.23.184.117:16007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/aaa.php"] [unique_id "apPkojmmjdkPfMeJsKPHkQAAA-0"]
[Sun Aug 30 03:06:58.363390 2026] [security2:error] [pid 500253:tid 500433] [client 20.104.50.220:5890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/charity744.php"] [unique_id "apPkolmmXVd4kRvS-FAaCAAAAb8"]
[Sun Aug 30 03:06:58.367082 2026] [security2:error] [pid 500253:tid 500470] [client 20.104.18.15:13692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/wp-content/l.php"] [unique_id "apPkolmmXVd4kRvS-FAaFAAAAeQ"]
[Sun Aug 30 03:06:58.367238 2026] [security2:error] [pid 500253:tid 500439] [client 20.63.81.20:43316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/gtghklk.php"] [unique_id "apPkolmmXVd4kRvS-FAaFQAAAcU"]
[Sun Aug 30 03:06:58.391123 2026] [authz_core:error] [pid 499145:tid 499341] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp
[Sun Aug 30 03:06:58.391550 2026] [authz_core:error] [pid 499145:tid 499341] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp
[Sun Aug 30 03:06:58.404979 2026] [security2:error] [pid 499751:tid 499931] [client 158.23.147.79:53537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apPkojmmjdkPfMeJsKPHxAAAA8c"]
[Sun Aug 30 03:06:58.415673 2026] [security2:error] [pid 500253:tid 500488] [client 20.48.251.3:44403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/admin-ajax.php"] [unique_id "apPkolmmXVd4kRvS-FAaOgAAAfY"]
[Sun Aug 30 03:06:58.426033 2026] [authz_core:error] [pid 499145:tid 499282] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:58.426328 2026] [authz_core:error] [pid 499145:tid 499282] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:58.429936 2026] [security2:error] [pid 500253:tid 500425] [client 4.205.62.107:65367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPkolmmXVd4kRvS-FAaSgAAAbc"]
[Sun Aug 30 03:06:58.474666 2026] [security2:error] [pid 499751:tid 499963] [client 20.104.50.220:33031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/hxh.php"] [unique_id "apPkojmmjdkPfMeJsKPICQAAA-c"]
[Sun Aug 30 03:06:58.493799 2026] [security2:error] [pid 500253:tid 500395] [client 158.23.184.117:15972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/admin/function.php"] [unique_id "apPkolmmXVd4kRvS-FAaggAAAZk"]
[Sun Aug 30 03:06:58.495413 2026] [security2:error] [pid 499751:tid 499907] [client 20.63.81.20:43251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/comand.php"] [unique_id "apPkojmmjdkPfMeJsKPIMAAAA7A"]
[Sun Aug 30 03:06:58.516457 2026] [security2:error] [pid 500253:tid 500494] [client 158.23.147.79:54628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apPkolmmXVd4kRvS-FAakAAAAfw"]
[Sun Aug 30 03:06:58.516801 2026] [security2:error] [pid 499751:tid 499942] [client 20.151.200.44:27136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/txets.php"] [unique_id "apPkojmmjdkPfMeJsKPIRQAAA9I"]
[Sun Aug 30 03:06:58.555146 2026] [security2:error] [pid 499751:tid 499901] [client 20.104.49.130:60738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/az.php"] [unique_id "apPkojmmjdkPfMeJsKPIaAAAA6o"]
[Sun Aug 30 03:06:58.619820 2026] [security2:error] [pid 499751:tid 500011] [client 4.205.62.107:63601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/doc.php"] [unique_id "apPkojmmjdkPfMeJsKPIpQAABBc"]
[Sun Aug 30 03:06:58.621732 2026] [security2:error] [pid 499145:tid 499314] [client 20.63.81.20:43317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp_motu_myk3v.php"] [unique_id "apPkolJNq1G5uRhTNntD7QAAACc"]
[Sun Aug 30 03:06:58.630890 2026] [security2:error] [pid 499145:tid 499357] [client 158.23.147.79:54209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apPkolJNq1G5uRhTNntD8wAAAFI"]
[Sun Aug 30 03:06:58.638572 2026] [security2:error] [pid 499751:tid 499967] [client 20.48.251.3:64387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/phpi.php"] [unique_id "apPkojmmjdkPfMeJsKPItQAAA-s"]
[Sun Aug 30 03:06:58.640036 2026] [authz_core:error] [pid 499751:tid 499937] [client 66.249.66.78:45412] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:58.640510 2026] [authz_core:error] [pid 499751:tid 499937] [client 66.249.66.78:45412] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:58.667926 2026] [security2:error] [pid 499145:tid 499398] [client 4.205.62.107:51758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/tax.php"] [unique_id "apPkolJNq1G5uRhTNntEAAAAAHs"]
[Sun Aug 30 03:06:58.674063 2026] [security2:error] [pid 499751:tid 499943] [client 68.155.159.216:63946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-admin/admin.php"] [unique_id "apPkojmmjdkPfMeJsKPI0gAAA9M"]
[Sun Aug 30 03:06:58.679149 2026] [security2:error] [pid 499751:tid 499940] [client 158.23.184.117:16018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/system_log.php"] [unique_id "apPkojmmjdkPfMeJsKPI2AAAA9A"]
[Sun Aug 30 03:06:58.685505 2026] [security2:error] [pid 500253:tid 500435] [client 20.104.18.15:29129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/classwithtostring.php"] [unique_id "apPkolmmXVd4kRvS-FAa6AAAAcE"]
[Sun Aug 30 03:06:58.708025 2026] [security2:error] [pid 499751:tid 500006] [client 20.151.200.44:47080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/log.php"] [unique_id "apPkojmmjdkPfMeJsKPI-wAABBI"]
[Sun Aug 30 03:06:58.742637 2026] [security2:error] [pid 499751:tid 499943] [client 158.23.147.79:54262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apPkojmmjdkPfMeJsKPJIwAAA9M"]
[Sun Aug 30 03:06:58.750959 2026] [authz_core:error] [pid 499145:tid 499341] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_GB
[Sun Aug 30 03:06:58.751287 2026] [authz_core:error] [pid 499145:tid 499341] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_GB
[Sun Aug 30 03:06:58.752349 2026] [lsapi:error] [pid 499751:tid 499814] [remote 76.182.214.212:60276] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:06:58.752520 2026] [lsapi:error] [pid 499751:tid 499814] [remote 76.182.214.212:60276] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:06:58.754000 2026] [lsapi:error] [pid 499751:tid 499814] [remote 76.182.214.212:60276] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:06:58.760852 2026] [security2:error] [pid 499751:tid 499936] [client 20.63.81.20:43266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/wp_motu_ypdat.php"] [unique_id "apPkojmmjdkPfMeJsKPJKwAAA8w"]
[Sun Aug 30 03:06:58.762171 2026] [authz_core:error] [pid 499751:tid 499984] [client 66.249.66.193:39396] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:58.762501 2026] [authz_core:error] [pid 499751:tid 499984] [client 66.249.66.193:39396] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:58.784202 2026] [security2:error] [pid 499751:tid 499948] [client 68.155.159.216:12289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-login.php"] [unique_id "apPkojmmjdkPfMeJsKPJPwAAA9g"]
[Sun Aug 30 03:06:58.814794 2026] [security2:error] [pid 499751:tid 499896] [client 20.104.50.220:61384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-init.php"] [unique_id "apPkojmmjdkPfMeJsKPJXAAAA6U"]
[Sun Aug 30 03:06:58.822920 2026] [security2:error] [pid 499751:tid 499994] [client 68.155.159.216:62333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-includes/Requests/about.php"] [unique_id "apPkojmmjdkPfMeJsKPJZAAABAY"]
[Sun Aug 30 03:06:58.840459 2026] [security2:error] [pid 499751:tid 499923] [client 4.205.62.107:64484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/wsws.php"] [unique_id "apPkojmmjdkPfMeJsKPJegAAA78"]
[Sun Aug 30 03:06:58.875878 2026] [security2:error] [pid 500253:tid 500413] [client 20.104.50.220:62814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/cp.php"] [unique_id "apPkolmmXVd4kRvS-FAbOwAAAas"]
[Sun Aug 30 03:06:58.884781 2026] [authz_core:error] [pid 499145:tid 499292] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fpackages
[Sun Aug 30 03:06:58.885274 2026] [authz_core:error] [pid 499145:tid 499292] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fpackages
[Sun Aug 30 03:06:58.893162 2026] [security2:error] [pid 499751:tid 499989] [client 20.151.200.44:27291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/wp-login.php"] [unique_id "apPkojmmjdkPfMeJsKPJlAAABAE"]
[Sun Aug 30 03:06:58.895198 2026] [security2:error] [pid 499751:tid 499972] [client 20.63.81.20:43368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/edit.php"] [unique_id "apPkojmmjdkPfMeJsKPJnwAAA_A"]
[Sun Aug 30 03:06:58.901041 2026] [security2:error] [pid 499751:tid 499940] [client 20.104.18.15:43298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/os.php"] [unique_id "apPkojmmjdkPfMeJsKPJpgAAA9A"]
[Sun Aug 30 03:06:58.919495 2026] [security2:error] [pid 499145:tid 499279] [client 158.23.184.117:16024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "apPkolJNq1G5uRhTNntEbAAAAAQ"]
[Sun Aug 30 03:06:58.943583 2026] [security2:error] [pid 500253:tid 500434] [client 62.60.130.247:53925] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "921"] [severity "CRITICAL"] [tag "SQLi"] [hostname "sennasound.com"] [uri "/"] [unique_id "apPkolmmXVd4kRvS-FAbXAAAAcA"]
[Sun Aug 30 03:06:58.944897 2026] [security2:error] [pid 499751:tid 500018] [client 20.104.50.220:63501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/high.php"] [unique_id "apPkojmmjdkPfMeJsKPJvgAABB4"]
[Sun Aug 30 03:06:58.957401 2026] [security2:error] [pid 499751:tid 499935] [client 20.104.18.15:34695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/images.php"] [unique_id "apPkojmmjdkPfMeJsKPJzAAAA8s"]
[Sun Aug 30 03:06:58.969512 2026] [security2:error] [pid 499751:tid 499946] [client 4.205.62.107:27277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/time.php"] [unique_id "apPkojmmjdkPfMeJsKPJ3wAAA9Y"]
[Sun Aug 30 03:06:58.977788 2026] [security2:error] [pid 499751:tid 499931] [client 20.104.50.220:27541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/mls.php"] [unique_id "apPkojmmjdkPfMeJsKPJ7QAAA8c"]
[Sun Aug 30 03:06:59.022103 2026] [security2:error] [pid 499751:tid 499921] [client 20.63.81.20:43260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/tqkdqbbv.php"] [unique_id "apPkozmmjdkPfMeJsKPKFwAAA70"]
[Sun Aug 30 03:06:59.045487 2026] [security2:error] [pid 499751:tid 499904] [client 4.205.62.107:63966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/koiy.php"] [unique_id "apPkozmmjdkPfMeJsKPKMgAAA60"]
[Sun Aug 30 03:06:59.046305 2026] [security2:error] [pid 499751:tid 499967] [client 4.205.62.107:2330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/configuration.php"] [unique_id "apPkozmmjdkPfMeJsKPKMwAAA-s"]
[Sun Aug 30 03:06:59.058633 2026] [security2:error] [pid 499751:tid 499937] [client 20.104.18.15:44009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/htio.php"] [unique_id "apPkozmmjdkPfMeJsKPKRAAAA80"]
[Sun Aug 30 03:06:59.060437 2026] [authz_core:error] [pid 500253:tid 500466] [client 216.73.216.128:5993] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:59.060754 2026] [authz_core:error] [pid 500253:tid 500466] [client 216.73.216.128:5993] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:59.084187 2026] [security2:error] [pid 500253:tid 500480] [client 20.48.251.3:49966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/phpversion.php"] [unique_id "apPko1mmXVd4kRvS-FAboAAAAe4"]
[Sun Aug 30 03:06:59.108414 2026] [security2:error] [pid 499751:tid 499921] [client 158.23.184.117:15973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/wp-links-opml.php"] [unique_id "apPkozmmjdkPfMeJsKPKcwAAA70"]
[Sun Aug 30 03:06:59.120616 2026] [security2:error] [pid 499145:tid 499393] [client 4.205.62.107:18754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/app.default.php"] [unique_id "apPko1JNq1G5uRhTNntE1AAAAHY"]
[Sun Aug 30 03:06:59.139528 2026] [security2:error] [pid 500253:tid 500417] [client 68.155.159.216:60900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/ws.php"] [unique_id "apPko1mmXVd4kRvS-FAbtgAAAa8"]
[Sun Aug 30 03:06:59.143887 2026] [security2:error] [pid 499751:tid 499932] [client 158.23.147.79:53547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/packed.php"] [unique_id "apPkozmmjdkPfMeJsKPKiwAAA8g"]
[Sun Aug 30 03:06:59.146829 2026] [security2:error] [pid 500253:tid 500494] [client 216.73.216.128:21183] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPko1mmXVd4kRvS-FAbuAAAAfw"]
[Sun Aug 30 03:06:59.148974 2026] [security2:error] [pid 499751:tid 499904] [client 20.63.81.20:43263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/kjyehoxl.php"] [unique_id "apPkozmmjdkPfMeJsKPKjQAAA60"]
[Sun Aug 30 03:06:59.182169 2026] [security2:error] [pid 500253:tid 500490] [client 114.119.146.16:41263] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cavaleiroveloz.com.br"] [uri "/index.php/fato-ou-fabula"] [unique_id "apPko1mmXVd4kRvS-FAbyQAAAfg"], referer: https://cavaleiroveloz.com.br/index.php/fato-ou-fabula/
[Sun Aug 30 03:06:59.192239 2026] [security2:error] [pid 499751:tid 499965] [client 20.104.18.15:28598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/1xmomo.php"] [unique_id "apPkozmmjdkPfMeJsKPKvwAAA-k"]
[Sun Aug 30 03:06:59.204041 2026] [security2:error] [pid 500253:tid 500434] [client 4.205.62.107:4562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/time.php"] [unique_id "apPko1mmXVd4kRvS-FAb0QAAAcA"]
[Sun Aug 30 03:06:59.209341 2026] [security2:error] [pid 499145:tid 499282] [client 20.104.50.220:32076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/mini.php"] [unique_id "apPko1JNq1G5uRhTNntFCQAAAAc"]
[Sun Aug 30 03:06:59.223597 2026] [authz_core:error] [pid 500253:tid 500430] [client 66.249.66.44:52984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:59.224027 2026] [authz_core:error] [pid 500253:tid 500430] [client 66.249.66.44:52984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:59.229810 2026] [security2:error] [pid 499751:tid 499967] [client 4.205.62.107:62458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/aws_sdk_settings.php"] [unique_id "apPkozmmjdkPfMeJsKPK2QAAA-s"]
[Sun Aug 30 03:06:59.245894 2026] [authz_core:error] [pid 499145:tid 499310] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:59.246164 2026] [authz_core:error] [pid 499145:tid 499310] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:59.248855 2026] [security2:error] [pid 500253:tid 500446] [client 158.23.184.117:16031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/wp.php"] [unique_id "apPko1mmXVd4kRvS-FAb7gAAAcw"]
[Sun Aug 30 03:06:59.258589 2026] [authz_core:error] [pid 499145:tid 499402] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_PH
[Sun Aug 30 03:06:59.258902 2026] [authz_core:error] [pid 499145:tid 499402] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_PH
[Sun Aug 30 03:06:59.270419 2026] [security2:error] [pid 500253:tid 500390] [client 20.104.50.220:63041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/1n73ction.php"] [unique_id "apPko1mmXVd4kRvS-FAb_QAAAZQ"]
[Sun Aug 30 03:06:59.279663 2026] [security2:error] [pid 500253:tid 500462] [client 20.63.81.20:43319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/llyuxaqd.php"] [unique_id "apPko1mmXVd4kRvS-FAcBgAAAdw"]
[Sun Aug 30 03:06:59.287358 2026] [authz_core:error] [pid 499751:tid 499985] [client 66.249.66.38:61710] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:59.287843 2026] [authz_core:error] [pid 499751:tid 499985] [client 66.249.66.38:61710] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:59.295405 2026] [security2:error] [pid 499751:tid 500022] [client 20.48.251.3:33297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/guk.php"] [unique_id "apPkozmmjdkPfMeJsKPLHwAABCI"]
[Sun Aug 30 03:06:59.296729 2026] [authz_core:error] [pid 499751:tid 499922] [client 66.249.66.39:42153] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:59.297088 2026] [authz_core:error] [pid 499145:tid 499298] [client 66.249.66.203:46614] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:59.297185 2026] [authz_core:error] [pid 499751:tid 499922] [client 66.249.66.39:42153] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:59.297577 2026] [authz_core:error] [pid 499145:tid 499298] [client 66.249.66.203:46614] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:59.301200 2026] [authz_core:error] [pid 499751:tid 499996] [client 66.249.66.38:36191] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:59.301598 2026] [authz_core:error] [pid 499751:tid 499996] [client 66.249.66.38:36191] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:59.301806 2026] [security2:error] [pid 499751:tid 499901] [client 20.151.200.44:27289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/wp-access.php"] [unique_id "apPkozmmjdkPfMeJsKPLIwAAA6o"]
[Sun Aug 30 03:06:59.307203 2026] [security2:error] [pid 499751:tid 499913] [client 158.23.147.79:44251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-content/packed.php"] [unique_id "apPkozmmjdkPfMeJsKPLLgAAA7U"]
[Sun Aug 30 03:06:59.312156 2026] [security2:error] [pid 499145:tid 499288] [client 114.119.144.178:33633] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "shreaves.com"] [uri "/FFFLibrary.com/index.php/forum/register"] [unique_id "apPko1JNq1G5uRhTNntFJwAAAA0"], referer: http://shreaves.com/FFFLibrary.com/index.php/forum/register
[Sun Aug 30 03:06:59.320609 2026] [security2:error] [pid 499751:tid 499940] [client 20.104.18.15:32974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/wp-admin/js/wp-load.php"] [unique_id "apPkozmmjdkPfMeJsKPLOAAAA9A"]
[Sun Aug 30 03:06:59.330064 2026] [security2:error] [pid 500253:tid 500505] [client 216.73.216.128:5993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPko1mmXVd4kRvS-FAcKQAAAgc"]
[Sun Aug 30 03:06:59.336737 2026] [security2:error] [pid 499751:tid 499945] [client 20.104.18.15:23425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/img.php"] [unique_id "apPkozmmjdkPfMeJsKPLTAAAA9U"]
[Sun Aug 30 03:06:59.343983 2026] [security2:error] [pid 499751:tid 500001] [client 20.104.50.220:16706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/green1.php"] [unique_id "apPkozmmjdkPfMeJsKPLVQAABA0"]
[Sun Aug 30 03:06:59.352641 2026] [security2:error] [pid 499751:tid 499908] [client 114.119.133.211:49565] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "1superiormachine.com"] [uri "/files/central-park-concert.jpg"] [unique_id "apPkozmmjdkPfMeJsKPLbAAAA7E"], referer: https://1superiormachine.com/files/central-park-concert.jpg
[Sun Aug 30 03:06:59.376492 2026] [security2:error] [pid 500253:tid 500426] [client 20.104.50.220:46358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-conflg.php"] [unique_id "apPko1mmXVd4kRvS-FAcUwAAAbg"]
[Sun Aug 30 03:06:59.391066 2026] [security2:error] [pid 499751:tid 499977] [client 158.23.184.117:15976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/.well-known/hp2.php"] [unique_id "apPkozmmjdkPfMeJsKPLlAAAA_U"]
[Sun Aug 30 03:06:59.408025 2026] [security2:error] [pid 500253:tid 500387] [client 20.63.81.20:43141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/nbwxolou.php"] [unique_id "apPko1mmXVd4kRvS-FAcZwAAAZE"]
[Sun Aug 30 03:06:59.411055 2026] [security2:error] [pid 499751:tid 499909] [client 68.155.159.216:56374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/lock.php"] [unique_id "apPkozmmjdkPfMeJsKPLpgAAA7I"]
[Sun Aug 30 03:06:59.414181 2026] [security2:error] [pid 499751:tid 499904] [client 62.60.130.247:61382] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "sennasound.com"] [uri "/"] [unique_id "apPkozmmjdkPfMeJsKPLpwAAA60"]
[Sun Aug 30 03:06:59.417276 2026] [security2:error] [pid 499751:tid 499917] [client 4.205.62.107:31715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/rpk.php"] [unique_id "apPkozmmjdkPfMeJsKPLrQAAA7k"]
[Sun Aug 30 03:06:59.429844 2026] [authz_core:error] [pid 500253:tid 500399] [client 216.73.216.128:21183] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:59.430179 2026] [authz_core:error] [pid 500253:tid 500399] [client 216.73.216.128:21183] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:59.468018 2026] [security2:error] [pid 499751:tid 499907] [client 114.119.151.171:22049] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "freeourmidwives.org"] [uri "/exciting-news/"] [unique_id "apPkozmmjdkPfMeJsKPL6AAAA7A"], referer: http://freeourmidwives.org/key-vote-happening-today
[Sun Aug 30 03:06:59.486447 2026] [security2:error] [pid 500253:tid 500392] [client 158.23.147.79:54625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-l0gin.php"] [unique_id "apPko1mmXVd4kRvS-FAclgAAAZY"]
[Sun Aug 30 03:06:59.501871 2026] [security2:error] [pid 500253:tid 500424] [client 20.104.18.15:13670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/wp-admin/w.php"] [unique_id "apPko1mmXVd4kRvS-FAcowAAAbY"]
[Sun Aug 30 03:06:59.518404 2026] [security2:error] [pid 500253:tid 500504] [client 20.104.50.220:5618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/camryn118.php"] [unique_id "apPko1mmXVd4kRvS-FAcqgAAAgY"]
[Sun Aug 30 03:06:59.534301 2026] [security2:error] [pid 500253:tid 500450] [client 158.23.184.117:16004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/.well-known/mh.php"] [unique_id "apPko1mmXVd4kRvS-FActgAAAdA"]
[Sun Aug 30 03:06:59.542428 2026] [security2:error] [pid 499751:tid 499925] [client 20.63.81.20:43313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/nsxeubyv.php"] [unique_id "apPkozmmjdkPfMeJsKPMQwAAA8E"]
[Sun Aug 30 03:06:59.567573 2026] [security2:error] [pid 500253:tid 500425] [client 68.155.159.216:54264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apPko1mmXVd4kRvS-FAcwgAAAbc"]
[Sun Aug 30 03:06:59.607804 2026] [authz_core:error] [pid 500253:tid 500505] [client 66.249.66.33:34861] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:59.608271 2026] [authz_core:error] [pid 500253:tid 500505] [client 66.249.66.33:34861] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:59.623584 2026] [security2:error] [pid 499751:tid 500016] [client 20.48.251.3:44330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/ms.php"] [unique_id "apPkozmmjdkPfMeJsKPMdQAABBw"]
[Sun Aug 30 03:06:59.632020 2026] [security2:error] [pid 500253:tid 500493] [client 20.104.50.220:33025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/FX.php"] [unique_id "apPko1mmXVd4kRvS-FAc4wAAAfs"]
[Sun Aug 30 03:06:59.642436 2026] [security2:error] [pid 499751:tid 499969] [client 158.23.147.79:54247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apPkozmmjdkPfMeJsKPMhgAAA-0"]
[Sun Aug 30 03:06:59.660331 2026] [security2:error] [pid 499751:tid 499916] [client 20.151.200.44:27148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/wp-content/admin.php"] [unique_id "apPkozmmjdkPfMeJsKPMkgAAA7g"]
[Sun Aug 30 03:06:59.668422 2026] [security2:error] [pid 499751:tid 499895] [client 20.63.81.20:43346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/zfqipfss.php"] [unique_id "apPkozmmjdkPfMeJsKPMmAAAA6Q"]
[Sun Aug 30 03:06:59.674891 2026] [security2:error] [pid 499145:tid 499319] [client 4.205.62.107:65371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/agg.php"] [unique_id "apPko1JNq1G5uRhTNntF6wAAACw"]
[Sun Aug 30 03:06:59.678563 2026] [security2:error] [pid 499751:tid 499899] [client 158.23.184.117:15541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/about/function.php"] [unique_id "apPkozmmjdkPfMeJsKPMngAAA6g"]
[Sun Aug 30 03:06:59.728085 2026] [authz_core:error] [pid 499751:tid 499985] [client 66.249.66.70:39377] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:59.728552 2026] [authz_core:error] [pid 499751:tid 499985] [client 66.249.66.70:39377] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:59.756633 2026] [security2:error] [pid 499145:tid 499313] [client 4.205.62.107:63552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/classsmtps.php"] [unique_id "apPko1JNq1G5uRhTNntGIAAAACY"]
[Sun Aug 30 03:06:59.760661 2026] [authz_core:error] [pid 499145:tid 499288] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_BW
[Sun Aug 30 03:06:59.761091 2026] [authz_core:error] [pid 499145:tid 499288] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_BW
[Sun Aug 30 03:06:59.794596 2026] [security2:error] [pid 499145:tid 499284] [client 20.63.81.20:43336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.seaofqi.net"] [uri "/zrjuyoos.php"] [unique_id "apPko1JNq1G5uRhTNntGNAAAAAk"]
[Sun Aug 30 03:06:59.819170 2026] [security2:error] [pid 499751:tid 500018] [client 158.23.184.117:16029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/an.php"] [unique_id "apPkozmmjdkPfMeJsKPNHwAABB4"]
[Sun Aug 30 03:06:59.821406 2026] [authz_core:error] [pid 500253:tid 500404] [client 66.249.66.68:63125] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:59.821755 2026] [authz_core:error] [pid 500253:tid 500404] [client 66.249.66.68:63125] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:59.825298 2026] [security2:error] [pid 499751:tid 499999] [client 4.205.62.107:56618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPkozmmjdkPfMeJsKPNLAAABAs"]
[Sun Aug 30 03:06:59.825677 2026] [security2:error] [pid 499751:tid 499898] [client 20.104.18.15:29642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPkozmmjdkPfMeJsKPNLwAAA6c"]
[Sun Aug 30 03:06:59.841991 2026] [authz_core:error] [pid 500253:tid 500454] [client 216.73.216.128:44161] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:06:59.842334 2026] [authz_core:error] [pid 500253:tid 500454] [client 216.73.216.128:44161] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:06:59.862342 2026] [security2:error] [pid 499751:tid 499921] [client 20.48.251.3:7012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "apPkozmmjdkPfMeJsKPNSQAAA70"]
[Sun Aug 30 03:06:59.885375 2026] [security2:error] [pid 499145:tid 499360] [client 68.155.159.216:65468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apPko1JNq1G5uRhTNntGVgAAAFU"]
[Sun Aug 30 03:06:59.907831 2026] [security2:error] [pid 499145:tid 499374] [client 62.60.130.247:61382] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "sennasound.com"] [uri "/"] [unique_id "apPko1JNq1G5uRhTNntGYgAAAGM"]
[Sun Aug 30 03:06:59.922635 2026] [security2:error] [pid 499145:tid 499401] [client 158.23.147.79:54646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPko1JNq1G5uRhTNntGbwAAAH4"]
[Sun Aug 30 03:06:59.925997 2026] [security2:error] [pid 499145:tid 499337] [client 20.151.200.44:27311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/log.php"] [unique_id "apPko1JNq1G5uRhTNntGcQAAAD4"]
[Sun Aug 30 03:06:59.945695 2026] [security2:error] [pid 500253:tid 500392] [client 68.155.159.216:61648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-admin/includes/index.php"] [unique_id "apPko1mmXVd4kRvS-FAdXgAAAZY"]
[Sun Aug 30 03:06:59.951216 2026] [security2:error] [pid 500253:tid 500397] [client 68.155.159.216:65481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apPko1mmXVd4kRvS-FAdYwAAAZs"]
[Sun Aug 30 03:06:59.960061 2026] [security2:error] [pid 499145:tid 499322] [client 158.23.184.117:15989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/buy.php"] [unique_id "apPko1JNq1G5uRhTNntGhwAAAC8"]
[Sun Aug 30 03:06:59.981379 2026] [security2:error] [pid 499751:tid 499960] [client 20.104.50.220:61674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/lyda.php"] [unique_id "apPkozmmjdkPfMeJsKPNnQAAA-Q"]
[Sun Aug 30 03:06:59.996093 2026] [security2:error] [pid 500253:tid 500430] [client 4.205.62.107:64702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/localconf.php"] [unique_id "apPko1mmXVd4kRvS-FAdgAAAAbw"]
[Sun Aug 30 03:07:00.015306 2026] [security2:error] [pid 499145:tid 499275] [client 20.104.50.220:52831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/cyto.php"] [unique_id "apPkpFJNq1G5uRhTNntGowAAAAA"]
[Sun Aug 30 03:07:00.087934 2026] [security2:error] [pid 499751:tid 500022] [client 20.104.50.220:42026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/hehee.php"] [unique_id "apPkpDmmjdkPfMeJsKPN_gAABCI"]
[Sun Aug 30 03:07:00.102086 2026] [security2:error] [pid 499751:tid 499894] [client 158.23.184.117:15966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/config.php"] [unique_id "apPkpDmmjdkPfMeJsKPOBwAAA6M"]
[Sun Aug 30 03:07:00.119284 2026] [security2:error] [pid 500253:tid 500478] [client 20.104.50.220:27435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/clients.php"] [unique_id "apPkpFmmXVd4kRvS-FAdwAAAAew"]
[Sun Aug 30 03:07:00.119561 2026] [security2:error] [pid 499751:tid 499936] [client 20.104.18.15:34762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/ops.php"] [unique_id "apPkpDmmjdkPfMeJsKPOEgAAA8w"]
[Sun Aug 30 03:07:00.190388 2026] [security2:error] [pid 499751:tid 499952] [client 4.205.62.107:62081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/queue.php"] [unique_id "apPkpDmmjdkPfMeJsKPOTQAAA9w"]
[Sun Aug 30 03:07:00.191846 2026] [security2:error] [pid 499751:tid 499940] [client 4.205.62.107:2949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/server_info.php"] [unique_id "apPkpDmmjdkPfMeJsKPOTwAAA9A"]
[Sun Aug 30 03:07:00.222385 2026] [security2:error] [pid 499751:tid 499949] [client 20.48.251.3:55446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/adminfus.php"] [unique_id "apPkpDmmjdkPfMeJsKPObgAAA9k"]
[Sun Aug 30 03:07:00.240407 2026] [security2:error] [pid 499751:tid 500013] [client 158.23.184.117:15947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/inputs.php"] [unique_id "apPkpDmmjdkPfMeJsKPOhAAABBk"]
[Sun Aug 30 03:07:00.250641 2026] [authz_core:error] [pid 499145:tid 499304] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_GB
[Sun Aug 30 03:07:00.251046 2026] [authz_core:error] [pid 499145:tid 499304] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_GB
[Sun Aug 30 03:07:00.271060 2026] [security2:error] [pid 500253:tid 500464] [client 4.205.62.107:18770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/app_local.php"] [unique_id "apPkpFmmXVd4kRvS-FAd-gAAAd4"]
[Sun Aug 30 03:07:00.273687 2026] [security2:error] [pid 500253:tid 500450] [client 20.104.18.15:43909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/dev.php"] [unique_id "apPkpFmmXVd4kRvS-FAeAQAAAdA"]
[Sun Aug 30 03:07:00.342919 2026] [security2:error] [pid 500253:tid 500467] [client 20.104.18.15:28630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/mosty.php"] [unique_id "apPkpFmmXVd4kRvS-FAeMAAAAeE"]
[Sun Aug 30 03:07:00.343844 2026] [security2:error] [pid 500253:tid 500502] [client 4.205.62.107:5091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/doc.php"] [unique_id "apPkpFmmXVd4kRvS-FAeMQAAAgQ"]
[Sun Aug 30 03:07:00.349261 2026] [security2:error] [pid 500253:tid 500455] [client 114.119.136.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "macintoshpro.com"] [uri "/item/starry-night-socks"] [unique_id "apPkpFmmXVd4kRvS-FAePAAAAdU"], referer: http://macintoshpro.com/item/starry-night-socks
[Sun Aug 30 03:07:00.353372 2026] [security2:error] [pid 499751:tid 499968] [client 20.104.50.220:32520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/minik.php"] [unique_id "apPkpDmmjdkPfMeJsKPO-gAAA-w"]
[Sun Aug 30 03:07:00.382656 2026] [security2:error] [pid 499751:tid 499967] [client 158.23.147.79:54602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/ans.php"] [unique_id "apPkpDmmjdkPfMeJsKPPGQAAA-s"]
[Sun Aug 30 03:07:00.385298 2026] [security2:error] [pid 499751:tid 500002] [client 158.23.184.117:15970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/radio.php"] [unique_id "apPkpDmmjdkPfMeJsKPPHAAABA4"]
[Sun Aug 30 03:07:00.387424 2026] [security2:error] [pid 500253:tid 500460] [client 4.205.62.107:22948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/setup-config.php"] [unique_id "apPkpFmmXVd4kRvS-FAeVAAAAdo"]
[Sun Aug 30 03:07:00.391576 2026] [security2:error] [pid 499145:tid 499364] [client 62.60.130.247:59853] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "911"] [severity "CRITICAL"] [tag "SQLi"] [hostname "sennasound.com"] [uri "/"] [unique_id "apPkpFJNq1G5uRhTNntHgAAAAFk"]
[Sun Aug 30 03:07:00.401741 2026] [authz_core:error] [pid 499145:tid 499291] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp%2Fsections
[Sun Aug 30 03:07:00.402129 2026] [authz_core:error] [pid 499145:tid 499291] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp%2Fsections
[Sun Aug 30 03:07:00.425671 2026] [security2:error] [pid 499751:tid 499919] [client 20.104.50.220:62844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/374k.php"] [unique_id "apPkpDmmjdkPfMeJsKPPQgAAA7s"]
[Sun Aug 30 03:07:00.454597 2026] [security2:error] [pid 500253:tid 500476] [client 20.48.251.3:33282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/config_dev.php"] [unique_id "apPkpFmmXVd4kRvS-FAeegAAAeo"]
[Sun Aug 30 03:07:00.456805 2026] [security2:error] [pid 500253:tid 500476] [client 68.155.159.216:60894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-includes/css/index.php"] [unique_id "apPkpFmmXVd4kRvS-FAefQAAAeo"]
[Sun Aug 30 03:07:00.466055 2026] [security2:error] [pid 499751:tid 499969] [client 20.151.200.44:27287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/xwpg.php"] [unique_id "apPkpDmmjdkPfMeJsKPPbAAAA-0"]
[Sun Aug 30 03:07:00.477361 2026] [security2:error] [pid 500253:tid 500500] [client 4.205.62.107:26789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/doc.php"] [unique_id "apPkpFmmXVd4kRvS-FAekwAAAgI"]
[Sun Aug 30 03:07:00.477383 2026] [security2:error] [pid 500253:tid 500467] [client 20.104.50.220:16715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/sukce.php"] [unique_id "apPkpFmmXVd4kRvS-FAelQAAAeE"]
[Sun Aug 30 03:07:00.493102 2026] [security2:error] [pid 499751:tid 500002] [client 20.104.18.15:33634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/robot.php"] [unique_id "apPkpDmmjdkPfMeJsKPPgwAABA4"]
[Sun Aug 30 03:07:00.497459 2026] [security2:error] [pid 500253:tid 500436] [client 20.104.18.15:23547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/222.php"] [unique_id "apPkpFmmXVd4kRvS-FAeqQAAAcI"]
[Sun Aug 30 03:07:00.515903 2026] [security2:error] [pid 500253:tid 500490] [client 20.104.50.220:46859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-ctac.php"] [unique_id "apPkpFmmXVd4kRvS-FAevAAAAfg"]
[Sun Aug 30 03:07:00.524058 2026] [authz_core:error] [pid 500253:tid 500425] [client 216.73.216.128:4988] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:00.524581 2026] [authz_core:error] [pid 500253:tid 500425] [client 216.73.216.128:4988] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:00.527919 2026] [security2:error] [pid 500253:tid 500394] [client 158.23.184.117:15977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/storage/rip.php"] [unique_id "apPkpFmmXVd4kRvS-FAezQAAAZg"]
[Sun Aug 30 03:07:00.541375 2026] [security2:error] [pid 500253:tid 500421] [client 68.155.159.216:11239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/index/function.php"] [unique_id "apPkpFmmXVd4kRvS-FAe2AAAAbM"]
[Sun Aug 30 03:07:00.605002 2026] [security2:error] [pid 500253:tid 500477] [client 216.73.216.128:21183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPkpFmmXVd4kRvS-FAfKgAAAes"]
[Sun Aug 30 03:07:00.669741 2026] [security2:error] [pid 499751:tid 500015] [client 20.104.18.15:13610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/wp-content/k.php"] [unique_id "apPkpDmmjdkPfMeJsKPQAgAABBs"]
[Sun Aug 30 03:07:00.670885 2026] [security2:error] [pid 500253:tid 500446] [client 158.23.184.117:16050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/wp-admin.php"] [unique_id "apPkpFmmXVd4kRvS-FAfTQAAAcw"]
[Sun Aug 30 03:07:00.673533 2026] [security2:error] [pid 499145:tid 499307] [client 20.104.50.220:5931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/byrdie906.php"] [unique_id "apPkpFJNq1G5uRhTNntH8AAAACA"]
[Sun Aug 30 03:07:00.695363 2026] [security2:error] [pid 499751:tid 499969] [client 68.155.159.216:54208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apPkpDmmjdkPfMeJsKPQFQAAA-0"]
[Sun Aug 30 03:07:00.739324 2026] [security2:error] [pid 499751:tid 499949] [client 158.23.147.79:54604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/worksec.php"] [unique_id "apPkpDmmjdkPfMeJsKPQQgAAA9k"]
[Sun Aug 30 03:07:00.766596 2026] [security2:error] [pid 500253:tid 500409] [client 20.48.251.3:44298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/fucku.php"] [unique_id "apPkpFmmXVd4kRvS-FAfdgAAAac"]
[Sun Aug 30 03:07:00.771600 2026] [authz_core:error] [pid 499145:tid 499293] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_GB
[Sun Aug 30 03:07:00.771940 2026] [authz_core:error] [pid 499145:tid 499293] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_GB
[Sun Aug 30 03:07:00.791525 2026] [security2:error] [pid 499751:tid 499933] [client 20.104.50.220:33577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/ga.php"] [unique_id "apPkpDmmjdkPfMeJsKPQYwAAA8k"]
[Sun Aug 30 03:07:00.804952 2026] [lsapi:error] [pid 499751:tid 499824] [remote 96.232.189.185:62292] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.yandex.com/
[Sun Aug 30 03:07:00.805052 2026] [lsapi:error] [pid 499751:tid 499824] [remote 96.232.189.185:62292] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.yandex.com/
[Sun Aug 30 03:07:00.806411 2026] [lsapi:error] [pid 499751:tid 499824] [remote 96.232.189.185:62292] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n, referer: https://www.yandex.com/
[Sun Aug 30 03:07:00.830489 2026] [security2:error] [pid 499751:tid 499996] [client 4.205.62.107:65361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/requirements.php"] [unique_id "apPkpDmmjdkPfMeJsKPQjQAABAg"]
[Sun Aug 30 03:07:00.862367 2026] [authz_core:error] [pid 499145:tid 499364] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fmessage
[Sun Aug 30 03:07:00.862734 2026] [authz_core:error] [pid 499145:tid 499364] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fmessage
[Sun Aug 30 03:07:00.870449 2026] [security2:error] [pid 500253:tid 500442] [client 62.60.130.247:51526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "sennasound.com"] [uri "/"] [unique_id "apPkpFmmXVd4kRvS-FAfmgAAAcg"]
[Sun Aug 30 03:07:00.895151 2026] [security2:error] [pid 499751:tid 499916] [client 4.205.62.107:63582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/cache-compat.php"] [unique_id "apPkpDmmjdkPfMeJsKPQxQAAA7g"]
[Sun Aug 30 03:07:00.959604 2026] [security2:error] [pid 499751:tid 499936] [client 158.23.184.117:16006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/wp-content.php"] [unique_id "apPkpDmmjdkPfMeJsKPRCAAAA8w"]
[Sun Aug 30 03:07:00.968861 2026] [security2:error] [pid 499751:tid 500015] [client 4.205.62.107:52156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPkpDmmjdkPfMeJsKPRDAAABBs"]
[Sun Aug 30 03:07:00.989436 2026] [security2:error] [pid 500253:tid 500490] [client 20.48.251.3:6511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/myfile.php"] [unique_id "apPkpFmmXVd4kRvS-FAf4AAAAfg"]
[Sun Aug 30 03:07:00.990454 2026] [security2:error] [pid 500253:tid 500495] [client 114.119.134.123:40655] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "omconsulting-group.com"] [uri "/fr/%C3%A9tiquette/delta/"] [unique_id "apPkpFmmXVd4kRvS-FAf4wAAAf0"], referer: https://omconsulting-group.com/fr/2022/12/
[Sun Aug 30 03:07:00.993829 2026] [security2:error] [pid 499751:tid 499935] [client 68.155.159.216:61344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/classwithtostring.php"] [unique_id "apPkpDmmjdkPfMeJsKPRGwAAA8s"]
[Sun Aug 30 03:07:01.009544 2026] [security2:error] [pid 499751:tid 499966] [client 20.104.18.15:29132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPkpTmmjdkPfMeJsKPRNQAAA-o"]
[Sun Aug 30 03:07:01.068773 2026] [authz_core:error] [pid 500253:tid 500467] [client 216.73.216.128:4988] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:01.069250 2026] [authz_core:error] [pid 500253:tid 500467] [client 216.73.216.128:4988] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:01.076616 2026] [security2:error] [pid 499751:tid 499993] [client 68.155.159.216:65512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-admin/images/about.php"] [unique_id "apPkpTmmjdkPfMeJsKPRhAAABAU"]
[Sun Aug 30 03:07:01.087529 2026] [security2:error] [pid 499145:tid 499291] [client 20.151.200.44:55634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/png.php"] [unique_id "apPkpVJNq1G5uRhTNntIqAAAABA"]
[Sun Aug 30 03:07:01.101068 2026] [security2:error] [pid 499751:tid 499913] [client 158.23.184.117:15953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/wp-content/about.php"] [unique_id "apPkpTmmjdkPfMeJsKPRmwAAA7U"]
[Sun Aug 30 03:07:01.104247 2026] [security2:error] [pid 499751:tid 499987] [client 158.23.147.79:48131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/x.php"] [unique_id "apPkpTmmjdkPfMeJsKPRngAAA_8"]
[Sun Aug 30 03:07:01.126860 2026] [security2:error] [pid 499751:tid 499967] [client 20.151.200.44:47065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/xwpg.php"] [unique_id "apPkpTmmjdkPfMeJsKPRrQAAA-s"]
[Sun Aug 30 03:07:01.146723 2026] [security2:error] [pid 499751:tid 499932] [client 4.205.62.107:64647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/bengi.php"] [unique_id "apPkpTmmjdkPfMeJsKPRwAAAA8g"]
[Sun Aug 30 03:07:01.181861 2026] [security2:error] [pid 500253:tid 500474] [client 20.104.50.220:59576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/alfashell.php"] [unique_id "apPkpVmmXVd4kRvS-FAgPAAAAeg"]
[Sun Aug 30 03:07:01.183488 2026] [security2:error] [pid 499751:tid 499953] [client 20.104.50.220:29144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/con7.php"] [unique_id "apPkpTmmjdkPfMeJsKPR1AAAA90"]
[Sun Aug 30 03:07:01.225545 2026] [security2:error] [pid 499751:tid 499968] [client 20.104.50.220:42776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/human.php"] [unique_id "apPkpTmmjdkPfMeJsKPSBgAAA-w"]
[Sun Aug 30 03:07:01.241352 2026] [authz_core:error] [pid 499751:tid 499894] [client 66.249.66.68:51400] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:01.241883 2026] [authz_core:error] [pid 499751:tid 499894] [client 66.249.66.68:51400] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:01.243597 2026] [security2:error] [pid 499751:tid 499986] [client 4.205.62.107:31709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/saml.php"] [unique_id "apPkpTmmjdkPfMeJsKPSGQAAA_4"]
[Sun Aug 30 03:07:01.248337 2026] [security2:error] [pid 499751:tid 499899] [client 20.104.18.15:34708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/coffexium.php"] [unique_id "apPkpTmmjdkPfMeJsKPSHQAAA6g"]
[Sun Aug 30 03:07:01.269732 2026] [security2:error] [pid 499751:tid 499981] [client 20.104.50.220:27224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/idx/results.php"] [unique_id "apPkpTmmjdkPfMeJsKPSLQAAA_k"]
[Sun Aug 30 03:07:01.273087 2026] [authz_core:error] [pid 499145:tid 499339] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_PH
[Sun Aug 30 03:07:01.273537 2026] [authz_core:error] [pid 499145:tid 499339] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_PH
[Sun Aug 30 03:07:01.336444 2026] [authz_core:error] [pid 499751:tid 499984] [client 66.249.66.78:45998] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:01.336938 2026] [authz_core:error] [pid 499751:tid 499984] [client 66.249.66.78:45998] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:01.349687 2026] [security2:error] [pid 499751:tid 499953] [client 4.205.62.107:2777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/hosty.php"] [unique_id "apPkpTmmjdkPfMeJsKPSbQAAA90"]
[Sun Aug 30 03:07:01.359235 2026] [security2:error] [pid 500253:tid 500403] [client 62.60.130.247:64108] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "sennasound.com"] [uri "/"] [unique_id "apPkpVmmXVd4kRvS-FAgtAAAAaE"]
[Sun Aug 30 03:07:01.374892 2026] [security2:error] [pid 500253:tid 500404] [client 20.48.251.3:12035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/avim.php"] [unique_id "apPkpVmmXVd4kRvS-FAg0AAAAaI"]
[Sun Aug 30 03:07:01.384659 2026] [security2:error] [pid 499145:tid 499261] [remote 72.167.132.114:51632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "michaelblakemenswear.com"] [uri "/wp-login.php"] [unique_id "apPkpVJNq1G5uRhTNntJFgAAKHM"]
[Sun Aug 30 03:07:01.393735 2026] [security2:error] [pid 500253:tid 500432] [client 68.155.159.216:63498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-login.php"] [unique_id "apPkpVmmXVd4kRvS-FAg6gAAAb4"]
[Sun Aug 30 03:07:01.395605 2026] [security2:error] [pid 500253:tid 500403] [client 20.104.49.130:53581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/images.php"] [unique_id "apPkpVmmXVd4kRvS-FAg8AAAAaE"]
[Sun Aug 30 03:07:01.415557 2026] [security2:error] [pid 499751:tid 499920] [client 4.205.62.107:64025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/doc.php"] [unique_id "apPkpTmmjdkPfMeJsKPSowAAA7w"]
[Sun Aug 30 03:07:01.415891 2026] [authz_core:error] [pid 500253:tid 500501] [client 66.249.66.205:57749] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:01.416198 2026] [security2:error] [pid 500253:tid 500506] [client 4.205.62.107:18780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/ws62.php"] [unique_id "apPkpVmmXVd4kRvS-FAhDgAAAgg"]
[Sun Aug 30 03:07:01.416411 2026] [authz_core:error] [pid 500253:tid 500501] [client 66.249.66.205:57749] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:01.422467 2026] [security2:error] [pid 500253:tid 500406] [client 158.23.184.117:15968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/x.php"] [unique_id "apPkpVmmXVd4kRvS-FAhGwAAAaQ"]
[Sun Aug 30 03:07:01.434253 2026] [authz_core:error] [pid 499145:tid 499307] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:01.434708 2026] [authz_core:error] [pid 499145:tid 499307] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:01.450202 2026] [authz_core:error] [pid 500253:tid 500396] [client 66.249.66.64:35930] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:01.450518 2026] [authz_core:error] [pid 500253:tid 500396] [client 66.249.66.64:35930] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:01.468725 2026] [authz_core:error] [pid 500253:tid 500449] [client 66.249.66.202:46787] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:01.469072 2026] [authz_core:error] [pid 500253:tid 500449] [client 66.249.66.202:46787] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:01.477758 2026] [authz_core:error] [pid 499145:tid 499299] [client 66.249.66.203:46614] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:01.478392 2026] [authz_core:error] [pid 499145:tid 499299] [client 66.249.66.203:46614] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:01.492619 2026] [security2:error] [pid 500253:tid 500460] [client 20.104.50.220:32515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/minishell.php"] [unique_id "apPkpVmmXVd4kRvS-FAhcQAAAdo"]
[Sun Aug 30 03:07:01.494734 2026] [security2:error] [pid 500253:tid 500423] [client 20.104.18.15:28550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/blurbs.php"] [unique_id "apPkpVmmXVd4kRvS-FAhdQAAAbU"]
[Sun Aug 30 03:07:01.502932 2026] [security2:error] [pid 500253:tid 500407] [client 158.23.147.79:53541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-content/x.php"] [unique_id "apPkpVmmXVd4kRvS-FAhggAAAaU"]
[Sun Aug 30 03:07:01.520814 2026] [security2:error] [pid 500253:tid 500505] [client 20.104.18.15:44027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/gos.php"] [unique_id "apPkpVmmXVd4kRvS-FAhnwAAAgc"]
[Sun Aug 30 03:07:01.535304 2026] [security2:error] [pid 500253:tid 500471] [client 4.205.62.107:4152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/classsmtps.php"] [unique_id "apPkpVmmXVd4kRvS-FAhvwAAAeU"]
[Sun Aug 30 03:07:01.540683 2026] [security2:error] [pid 500253:tid 500390] [client 4.205.62.107:62418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/wp-admin/sc.php"] [unique_id "apPkpVmmXVd4kRvS-FAhwgAAAZQ"]
[Sun Aug 30 03:07:01.569289 2026] [security2:error] [pid 499751:tid 499895] [client 20.151.200.44:27138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/sxxb.php"] [unique_id "apPkpTmmjdkPfMeJsKPTEgAAA6Q"]
[Sun Aug 30 03:07:01.571512 2026] [authz_core:error] [pid 499751:tid 499958] [client 66.249.66.199:39015] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:01.572007 2026] [authz_core:error] [pid 499751:tid 499958] [client 66.249.66.199:39015] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:01.579391 2026] [security2:error] [pid 499145:tid 499262] [remote 72.167.132.114:51632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "michaelblakemenswear.com"] [uri "/wp-login.php"] [unique_id "apPkpVJNq1G5uRhTNntJXwAAX3Q"], referer: https://michaelblakemenswear.com/wp-login.php
[Sun Aug 30 03:07:01.579861 2026] [security2:error] [pid 499751:tid 499980] [client 20.104.50.220:29315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/cmd.php"] [unique_id "apPkpTmmjdkPfMeJsKPTGAAAA_g"]
[Sun Aug 30 03:07:01.596018 2026] [security2:error] [pid 500253:tid 500387] [client 20.48.251.3:56358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/aws_credentials.php"] [unique_id "apPkpVmmXVd4kRvS-FAh-AAAAZE"]
[Sun Aug 30 03:07:01.618129 2026] [security2:error] [pid 500253:tid 500416] [client 20.104.50.220:16710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/xb.php"] [unique_id "apPkpVmmXVd4kRvS-FAiCwAAAa4"]
[Sun Aug 30 03:07:01.629350 2026] [security2:error] [pid 500253:tid 500459] [client 20.104.18.15:33013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/revo.php"] [unique_id "apPkpVmmXVd4kRvS-FAiEAAAAdk"]
[Sun Aug 30 03:07:01.633205 2026] [security2:error] [pid 499751:tid 499986] [client 20.104.18.15:23522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/key.php"] [unique_id "apPkpTmmjdkPfMeJsKPTLwAAA_4"]
[Sun Aug 30 03:07:01.653226 2026] [security2:error] [pid 499751:tid 500021] [client 20.104.50.220:46158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-defaul.php"] [unique_id "apPkpTmmjdkPfMeJsKPTNAAABCE"]
[Sun Aug 30 03:07:01.658905 2026] [security2:error] [pid 499751:tid 500001] [client 68.155.159.216:60882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apPkpTmmjdkPfMeJsKPTOAAABA0"]
[Sun Aug 30 03:07:01.662228 2026] [security2:error] [pid 499751:tid 499937] [client 158.23.184.117:15984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/a.php"] [unique_id "apPkpTmmjdkPfMeJsKPTOgAAA80"]
[Sun Aug 30 03:07:01.687440 2026] [security2:error] [pid 500253:tid 500439] [client 68.155.159.216:56418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/.well-known/content.php"] [unique_id "apPkpVmmXVd4kRvS-FAiPwAAAcU"]
[Sun Aug 30 03:07:01.724612 2026] [security2:error] [pid 500253:tid 500413] [client 20.104.49.130:52447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/v2.php"] [unique_id "apPkpVmmXVd4kRvS-FAiaAAAAas"]
[Sun Aug 30 03:07:01.771408 2026] [authz_core:error] [pid 499145:tid 499400] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_PH
[Sun Aug 30 03:07:01.771825 2026] [authz_core:error] [pid 499145:tid 499400] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_PH
[Sun Aug 30 03:07:01.774169 2026] [security2:error] [pid 500253:tid 500426] [client 20.48.250.41:53455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkpVmmXVd4kRvS-FAijQAAAbg"]
[Sun Aug 30 03:07:01.796673 2026] [security2:error] [pid 500253:tid 500387] [client 4.205.62.107:26506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/classsmtps.php"] [unique_id "apPkpVmmXVd4kRvS-FAiogAAAZE"]
[Sun Aug 30 03:07:01.803084 2026] [security2:error] [pid 499145:tid 499349] [client 158.23.184.117:16037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/admin/index.php"] [unique_id "apPkpVJNq1G5uRhTNntJwQAAAEo"]
[Sun Aug 30 03:07:01.807308 2026] [security2:error] [pid 499751:tid 500019] [client 158.23.147.79:54240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPkpTmmjdkPfMeJsKPTgAAABB8"]
[Sun Aug 30 03:07:01.807308 2026] [security2:error] [pid 500253:tid 500410] [client 20.104.50.220:6093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/async-upload.php"] [unique_id "apPkpVmmXVd4kRvS-FAirQAAAag"]
[Sun Aug 30 03:07:01.807464 2026] [security2:error] [pid 499751:tid 500011] [client 68.155.159.216:55133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/chosen.php"] [unique_id "apPkpTmmjdkPfMeJsKPTgQAABBc"]
[Sun Aug 30 03:07:01.832120 2026] [authz_core:error] [pid 500253:tid 500420] [client 66.249.66.39:49081] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:01.832422 2026] [authz_core:error] [pid 500253:tid 500420] [client 66.249.66.39:49081] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:01.849713 2026] [authz_core:error] [pid 499751:tid 499896] [client 66.249.66.197:52562] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:01.850169 2026] [authz_core:error] [pid 499751:tid 499896] [client 66.249.66.197:52562] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:01.851911 2026] [security2:error] [pid 500253:tid 500434] [client 20.104.18.15:13732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/os.php"] [unique_id "apPkpVmmXVd4kRvS-FAi4wAAAcA"]
[Sun Aug 30 03:07:01.896462 2026] [security2:error] [pid 499751:tid 499832] [remote 114.119.155.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thebaumfamily.net"] [uri "/sitemap.xml"] [unique_id "apPkpTmmjdkPfMeJsKPTpwADqUM"], referer: https://www.thebaumfamily.net/sitemap.xml
[Sun Aug 30 03:07:01.908346 2026] [security2:error] [pid 499145:tid 499315] [client 20.48.250.41:53490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkpVJNq1G5uRhTNntJ6gAAACg"]
[Sun Aug 30 03:07:01.932984 2026] [security2:error] [pid 499145:tid 499356] [client 20.104.50.220:33205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/ganz.php"] [unique_id "apPkpVJNq1G5uRhTNntJ9QAAAFE"]
[Sun Aug 30 03:07:01.961510 2026] [security2:error] [pid 499145:tid 499319] [client 158.23.184.117:16005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/ahax.php"] [unique_id "apPkpVJNq1G5uRhTNntKBgAAACw"]
[Sun Aug 30 03:07:01.968315 2026] [security2:error] [pid 500253:tid 500503] [client 158.23.147.79:44224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/log-mama/function.php"] [unique_id "apPkpVmmXVd4kRvS-FAjUgAAAgU"]
[Sun Aug 30 03:07:02.003015 2026] [security2:error] [pid 500253:tid 500497] [client 4.205.62.107:65310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/var/www/wallet/index.php"] [unique_id "apPkplmmXVd4kRvS-FAjbwAAAf8"]
[Sun Aug 30 03:07:02.008257 2026] [core:alert] [pid 500253:tid 500417] [client 103.122.255.16:50286] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:07:02.032919 2026] [security2:error] [pid 500253:tid 500480] [client 4.205.62.107:60559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/aws_keys.php"] [unique_id "apPkplmmXVd4kRvS-FAjlgAAAe4"]
[Sun Aug 30 03:07:02.042245 2026] [security2:error] [pid 500253:tid 500491] [client 20.48.251.3:44392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/error_log.php"] [unique_id "apPkplmmXVd4kRvS-FAjoQAAAfk"]
[Sun Aug 30 03:07:02.051467 2026] [authz_core:error] [pid 500253:tid 500475] [client 66.249.66.64:39431] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:02.051987 2026] [authz_core:error] [pid 500253:tid 500475] [client 66.249.66.64:39431] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:02.058541 2026] [security2:error] [pid 499751:tid 499965] [client 20.48.250.41:53489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/ff1.php"] [unique_id "apPkpjmmjdkPfMeJsKPUAAAAA-k"]
[Sun Aug 30 03:07:02.079128 2026] [authz_core:error] [pid 499751:tid 500006] [client 66.249.66.68:51400] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:02.079534 2026] [authz_core:error] [pid 499751:tid 500006] [client 66.249.66.68:51400] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:02.104049 2026] [security2:error] [pid 499751:tid 500009] [client 158.23.184.117:15969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/alfa.php"] [unique_id "apPkpjmmjdkPfMeJsKPULgAABBU"]
[Sun Aug 30 03:07:02.118071 2026] [security2:error] [pid 499751:tid 499995] [client 68.155.159.216:63937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/install.php"] [unique_id "apPkpjmmjdkPfMeJsKPUOQAABAc"]
[Sun Aug 30 03:07:02.118566 2026] [security2:error] [pid 500253:tid 500489] [client 4.205.62.107:56645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/agg.php"] [unique_id "apPkplmmXVd4kRvS-FAj0QAAAfc"]
[Sun Aug 30 03:07:02.143162 2026] [security2:error] [pid 500253:tid 500446] [client 20.48.251.3:45838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/api.php"] [unique_id "apPkplmmXVd4kRvS-FAj3gAAAcw"]
[Sun Aug 30 03:07:02.153457 2026] [security2:error] [pid 500253:tid 500425] [client 216.73.216.128:44161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPkplmmXVd4kRvS-FAj5wAAAbc"]
[Sun Aug 30 03:07:02.162417 2026] [security2:error] [pid 500253:tid 500395] [client 20.104.18.15:29121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/wsd.php"] [unique_id "apPkplmmXVd4kRvS-FAj6wAAAZk"]
[Sun Aug 30 03:07:02.234295 2026] [security2:error] [pid 499751:tid 500020] [client 20.48.250.41:53378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/t.php"] [unique_id "apPkpjmmjdkPfMeJsKPUrQAABCA"]
[Sun Aug 30 03:07:02.246688 2026] [authz_core:error] [pid 499145:tid 499288] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NZ
[Sun Aug 30 03:07:02.247003 2026] [authz_core:error] [pid 499145:tid 499288] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NZ
[Sun Aug 30 03:07:02.254009 2026] [authz_core:error] [pid 499145:tid 499295] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:02.254477 2026] [authz_core:error] [pid 499145:tid 499295] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:02.260075 2026] [security2:error] [pid 499751:tid 499916] [client 68.155.159.216:12315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPkpjmmjdkPfMeJsKPU0QAAA7g"]
[Sun Aug 30 03:07:02.266406 2026] [security2:error] [pid 499751:tid 499908] [client 20.104.18.15:51591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkpjmmjdkPfMeJsKPU2AAAA7E"]
[Sun Aug 30 03:07:02.274587 2026] [security2:error] [pid 500253:tid 500460] [client 114.119.144.200:55363] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "thedevonshireteaguide.com.au"] [uri "/2018/02/07/stonesthrow-launceston"] [unique_id "apPkplmmXVd4kRvS-FAkOgAAAdo"], referer: https://thedevonshireteaguide.com.au/2018/02/07/stonesthrow-launceston?ak_action=accept_mobile
[Sun Aug 30 03:07:02.291736 2026] [security2:error] [pid 499751:tid 499900] [client 158.23.147.79:54212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/bk/index.php"] [unique_id "apPkpjmmjdkPfMeJsKPU8AAAA6k"]
[Sun Aug 30 03:07:02.307746 2026] [security2:error] [pid 500253:tid 500497] [client 158.23.184.117:15488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/chosen.php"] [unique_id "apPkplmmXVd4kRvS-FAkTQAAAf8"]
[Sun Aug 30 03:07:02.323666 2026] [security2:error] [pid 499751:tid 499999] [client 4.205.62.107:64462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/i.php"] [unique_id "apPkpjmmjdkPfMeJsKPVBgAABAs"]
[Sun Aug 30 03:07:02.338168 2026] [security2:error] [pid 500253:tid 500435] [client 20.104.50.220:52848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/locale.php"] [unique_id "apPkplmmXVd4kRvS-FAkZQAAAcE"]
[Sun Aug 30 03:07:02.345284 2026] [authz_core:error] [pid 500253:tid 500453] [client 216.73.216.128:48105] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:02.345715 2026] [authz_core:error] [pid 500253:tid 500453] [client 216.73.216.128:48105] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:02.364109 2026] [security2:error] [pid 499751:tid 499935] [client 20.104.50.220:42454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/him.php"] [unique_id "apPkpjmmjdkPfMeJsKPVQgAAA8s"]
[Sun Aug 30 03:07:02.368413 2026] [security2:error] [pid 499145:tid 499301] [client 20.104.49.130:60629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/ano.php"] [unique_id "apPkplJNq1G5uRhTNntKrgAAABo"]
[Sun Aug 30 03:07:02.380142 2026] [security2:error] [pid 500253:tid 500503] [client 20.104.50.220:61444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/av.php"] [unique_id "apPkplmmXVd4kRvS-FAkjgAAAgU"]
[Sun Aug 30 03:07:02.387209 2026] [security2:error] [pid 500253:tid 500482] [client 20.104.18.15:34769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/BDKR28WP.php"] [unique_id "apPkplmmXVd4kRvS-FAklgAAAfA"]
[Sun Aug 30 03:07:02.388709 2026] [security2:error] [pid 499751:tid 499971] [client 20.48.250.41:53406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/erty.php"] [unique_id "apPkpjmmjdkPfMeJsKPVVwAAA-8"]
[Sun Aug 30 03:07:02.397440 2026] [security2:error] [pid 499751:tid 499919] [client 20.104.50.220:27235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/2Fedit.php"] [unique_id "apPkpjmmjdkPfMeJsKPVZQAAA7s"]
[Sun Aug 30 03:07:02.404591 2026] [security2:error] [pid 499751:tid 499952] [client 158.23.147.79:54260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.2f6bc6f87abe.smartmoneycompany.com.au"] [uri "/first.php"] [unique_id "apPkpjmmjdkPfMeJsKPVbAAAA9w"]
[Sun Aug 30 03:07:02.423952 2026] [authz_core:error] [pid 499145:tid 499374] [client 66.249.66.195:63106] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:02.424273 2026] [authz_core:error] [pid 499145:tid 499374] [client 66.249.66.195:63106] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:02.437254 2026] [authz_core:error] [pid 499145:tid 499350] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:02.437670 2026] [authz_core:error] [pid 499145:tid 499350] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:02.448764 2026] [security2:error] [pid 499751:tid 499917] [client 158.23.184.117:16027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/hplfuns.php"] [unique_id "apPkpjmmjdkPfMeJsKPVoQAAA7k"]
[Sun Aug 30 03:07:02.479463 2026] [authz_core:error] [pid 499145:tid 499386] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fmessage
[Sun Aug 30 03:07:02.479983 2026] [authz_core:error] [pid 499145:tid 499386] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fmessage
[Sun Aug 30 03:07:02.520720 2026] [security2:error] [pid 499751:tid 499967] [client 4.205.62.107:2353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/pass4.php"] [unique_id "apPkpjmmjdkPfMeJsKPV-wAAA-s"]
[Sun Aug 30 03:07:02.534585 2026] [security2:error] [pid 499751:tid 499971] [client 20.48.250.41:53404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/0x.php"] [unique_id "apPkpjmmjdkPfMeJsKPWBQAAA-8"]
[Sun Aug 30 03:07:02.537079 2026] [security2:error] [pid 499751:tid 499949] [client 20.48.251.3:49930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/nw.php"] [unique_id "apPkpjmmjdkPfMeJsKPWCAAAA9k"]
[Sun Aug 30 03:07:02.546806 2026] [security2:error] [pid 500253:tid 500436] [client 4.205.62.107:62027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/css.php"] [unique_id "apPkplmmXVd4kRvS-FAlAgAAAcI"]
[Sun Aug 30 03:07:02.550687 2026] [security2:error] [pid 500253:tid 500413] [client 4.205.62.107:18659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/grsiuk.php"] [unique_id "apPkplmmXVd4kRvS-FAlBAAAAas"]
[Sun Aug 30 03:07:02.601456 2026] [security2:error] [pid 499751:tid 499949] [client 68.155.159.216:62328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apPkpjmmjdkPfMeJsKPWPAAAA9k"]
[Sun Aug 30 03:07:02.603612 2026] [authz_core:error] [pid 499751:tid 499906] [client 66.249.66.42:44374] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:02.604114 2026] [authz_core:error] [pid 499751:tid 499906] [client 66.249.66.42:44374] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:02.622279 2026] [authz_core:error] [pid 500253:tid 500430] [client 66.249.66.43:43333] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:02.623014 2026] [authz_core:error] [pid 500253:tid 500430] [client 66.249.66.43:43333] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:02.638063 2026] [security2:error] [pid 499751:tid 499966] [client 158.23.184.117:15511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/lite.php"] [unique_id "apPkpjmmjdkPfMeJsKPWYAAAA-o"]
[Sun Aug 30 03:07:02.639553 2026] [security2:error] [pid 499145:tid 499307] [client 20.104.50.220:32093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/mrjn.php"] [unique_id "apPkplJNq1G5uRhTNntLIQAAACA"]
[Sun Aug 30 03:07:02.644113 2026] [security2:error] [pid 499145:tid 499318] [client 20.104.18.15:28564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/h.php"] [unique_id "apPkplJNq1G5uRhTNntLJQAAACs"]
[Sun Aug 30 03:07:02.660374 2026] [autoindex:error] [pid 500253:tid 500450] [client 158.23.184.117:38562] AH01276: Cannot serve directory /home4/smtlabs/nextcloud.smtlabs.co/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:07:02.664622 2026] [security2:error] [pid 499751:tid 500016] [client 4.205.62.107:4139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/cache-compat.php"] [unique_id "apPkpjmmjdkPfMeJsKPWegAABBw"]
[Sun Aug 30 03:07:02.673597 2026] [security2:error] [pid 499145:tid 499289] [client 20.48.250.41:53429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/66.php"] [unique_id "apPkplJNq1G5uRhTNntLMgAAAA4"]
[Sun Aug 30 03:07:02.674791 2026] [security2:error] [pid 499145:tid 499397] [client 4.205.62.107:62457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/debug.php"] [unique_id "apPkplJNq1G5uRhTNntLMwAAAHo"]
[Sun Aug 30 03:07:02.721119 2026] [authz_core:error] [pid 499751:tid 499946] [client 66.249.66.205:44773] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:02.721453 2026] [authz_core:error] [pid 499751:tid 499946] [client 66.249.66.205:44773] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:02.731574 2026] [security2:error] [pid 500253:tid 500455] [client 20.104.18.15:43929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/132.php"] [unique_id "apPkplmmXVd4kRvS-FAlbQAAAdU"]
[Sun Aug 30 03:07:02.733961 2026] [security2:error] [pid 499751:tid 499937] [client 20.104.50.220:62800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/jkt48_1.php"] [unique_id "apPkpjmmjdkPfMeJsKPWvgAAA80"]
[Sun Aug 30 03:07:02.736524 2026] [authz_core:error] [pid 499145:tid 499337] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_GB
[Sun Aug 30 03:07:02.736971 2026] [authz_core:error] [pid 499145:tid 499337] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_GB
[Sun Aug 30 03:07:02.745560 2026] [security2:error] [pid 499145:tid 499306] [client 47.128.54.136:55414] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.fenderrhodes.com"] [uri "/robots.txt"] [unique_id "apPkplJNq1G5uRhTNntLVQAAAB8"]
[Sun Aug 30 03:07:02.754997 2026] [security2:error] [pid 499145:tid 499375] [client 20.48.251.3:56349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/aws-credentials.php"] [unique_id "apPkplJNq1G5uRhTNntLWAAAAGQ"]
[Sun Aug 30 03:07:02.766410 2026] [security2:error] [pid 499751:tid 499899] [client 20.151.200.44:27309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/dx.php"] [unique_id "apPkpjmmjdkPfMeJsKPW0wAAA6g"]
[Sun Aug 30 03:07:02.767943 2026] [security2:error] [pid 499751:tid 500010] [client 20.104.50.220:17324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/biufile.php"] [unique_id "apPkpjmmjdkPfMeJsKPW1AAABBY"]
[Sun Aug 30 03:07:02.779441 2026] [security2:error] [pid 499751:tid 499919] [client 158.23.184.117:16043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/r.php"] [unique_id "apPkpjmmjdkPfMeJsKPW4gAAA7s"]
[Sun Aug 30 03:07:02.781405 2026] [security2:error] [pid 500253:tid 500511] [client 20.104.18.15:33781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/birrs.php"] [unique_id "apPkplmmXVd4kRvS-FAlggAAAg0"]
[Sun Aug 30 03:07:02.782044 2026] [security2:error] [pid 499751:tid 499898] [client 20.104.18.15:23433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/chosen.php"] [unique_id "apPkpjmmjdkPfMeJsKPW6AAAA6c"]
[Sun Aug 30 03:07:02.807123 2026] [security2:error] [pid 499751:tid 499981] [client 20.104.50.220:46437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-hmdra.php"] [unique_id "apPkpjmmjdkPfMeJsKPXAQAAA_k"]
[Sun Aug 30 03:07:02.831622 2026] [security2:error] [pid 499751:tid 499896] [client 20.48.250.41:53419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/f35.php"] [unique_id "apPkpjmmjdkPfMeJsKPXFgAAA6U"]
[Sun Aug 30 03:07:02.855308 2026] [security2:error] [pid 499751:tid 499978] [client 68.155.159.216:56401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/cong.php"] [unique_id "apPkpjmmjdkPfMeJsKPXMAAAA_Y"]
[Sun Aug 30 03:07:02.920912 2026] [security2:error] [pid 499751:tid 499910] [client 68.155.159.216:54261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/goods.php"] [unique_id "apPkpjmmjdkPfMeJsKPXXgAAA7M"]
[Sun Aug 30 03:07:02.920947 2026] [security2:error] [pid 500253:tid 500496] [client 158.23.184.117:15961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/shell.php"] [unique_id "apPkplmmXVd4kRvS-FAl5AAAAf4"]
[Sun Aug 30 03:07:02.930332 2026] [security2:error] [pid 499751:tid 499936] [client 114.119.133.87:48751] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "share.osterhouse.org"] [uri "/_gsdata_/_saved_/HTML/ExpressApp/node_modules/transformers/node_modules/uglify-js/tools"] [unique_id "apPkpjmmjdkPfMeJsKPXZQAAA8w"], referer: http://share.osterhouse.org/_gsdata_/_saved_/HTML/ExpressApp/node_modules/transformers/node_modules/uglify-js/tools?C=N%3BO%3DD
[Sun Aug 30 03:07:02.960747 2026] [security2:error] [pid 499751:tid 500021] [client 20.104.50.220:6122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/br5is.php"] [unique_id "apPkpjmmjdkPfMeJsKPXewAABCE"]
[Sun Aug 30 03:07:02.990057 2026] [security2:error] [pid 500253:tid 500483] [client 20.48.250.41:53396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/wen.php"] [unique_id "apPkplmmXVd4kRvS-FAmFwAAAfE"]
[Sun Aug 30 03:07:02.999817 2026] [security2:error] [pid 499751:tid 499978] [client 20.104.18.15:13652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/htio.php"] [unique_id "apPkpjmmjdkPfMeJsKPXjwAAA_Y"]
[Sun Aug 30 03:07:03.013331 2026] [security2:error] [pid 499751:tid 500003] [client 4.205.62.107:32462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/aws_settings.php"] [unique_id "apPkpzmmjdkPfMeJsKPXngAABA8"]
[Sun Aug 30 03:07:03.035689 2026] [authz_core:error] [pid 499751:tid 499931] [client 216.73.216.128:19732] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:03.038001 2026] [authz_core:error] [pid 499751:tid 499931] [client 216.73.216.128:19732] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:03.063872 2026] [security2:error] [pid 500253:tid 500489] [client 158.23.184.117:16008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lisaariotti.com"] [uri "/themes.php"] [unique_id "apPkp1mmXVd4kRvS-FAmWgAAAfc"]
[Sun Aug 30 03:07:03.072528 2026] [security2:error] [pid 500253:tid 500451] [client 20.104.50.220:32885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/gas.php"] [unique_id "apPkp1mmXVd4kRvS-FAmZgAAAdE"]
[Sun Aug 30 03:07:03.154599 2026] [security2:error] [pid 499145:tid 499378] [client 4.205.62.107:65320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/124.php"] [unique_id "apPkp1JNq1G5uRhTNntMDAAAAGc"]
[Sun Aug 30 03:07:03.166710 2026] [security2:error] [pid 499751:tid 499983] [client 4.205.62.107:63581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/umgebung.php"] [unique_id "apPkpzmmjdkPfMeJsKPYEgAAA_s"]
[Sun Aug 30 03:07:03.182734 2026] [security2:error] [pid 499751:tid 499987] [client 20.48.250.41:53472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/inc.php"] [unique_id "apPkpzmmjdkPfMeJsKPYKAAAA_8"]
[Sun Aug 30 03:07:03.183291 2026] [security2:error] [pid 499751:tid 499947] [client 20.104.49.130:52434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/js.php"] [unique_id "apPkpzmmjdkPfMeJsKPYKQAAA9c"]
[Sun Aug 30 03:07:03.240048 2026] [security2:error] [pid 500253:tid 500396] [client 68.155.159.216:63959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-content/x/index.php"] [unique_id "apPkp1mmXVd4kRvS-FAm4gAAAZo"]
[Sun Aug 30 03:07:03.250022 2026] [authz_core:error] [pid 499751:tid 500010] [client 66.249.66.34:37246] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:03.250498 2026] [authz_core:error] [pid 499751:tid 500010] [client 66.249.66.34:37246] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:03.255412 2026] [authz_core:error] [pid 499751:tid 499905] [client 216.73.216.128:19732] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:03.255901 2026] [authz_core:error] [pid 499751:tid 499905] [client 216.73.216.128:19732] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:03.276120 2026] [authz_core:error] [pid 499145:tid 499339] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NZ
[Sun Aug 30 03:07:03.276682 2026] [authz_core:error] [pid 499145:tid 499339] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NZ
[Sun Aug 30 03:07:03.278320 2026] [security2:error] [pid 500253:tid 500387] [client 4.205.62.107:52149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/requirements.php"] [unique_id "apPkp1mmXVd4kRvS-FAnAwAAAZE"]
[Sun Aug 30 03:07:03.287338 2026] [security2:error] [pid 500253:tid 500477] [client 20.48.251.3:7396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/temp.php"] [unique_id "apPkp1mmXVd4kRvS-FAnDQAAAes"]
[Sun Aug 30 03:07:03.301366 2026] [security2:error] [pid 500253:tid 500453] [client 20.104.18.15:29182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/bulet.php"] [unique_id "apPkp1mmXVd4kRvS-FAnFwAAAdM"]
[Sun Aug 30 03:07:03.330403 2026] [security2:error] [pid 500253:tid 500458] [client 20.48.250.41:53469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/6bcwiqwj.php"] [unique_id "apPkp1mmXVd4kRvS-FAnNAAAAdg"]
[Sun Aug 30 03:07:03.353482 2026] [authz_core:error] [pid 499751:tid 500001] [client 66.249.66.33:43917] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:03.353763 2026] [authz_core:error] [pid 499751:tid 500001] [client 66.249.66.33:43917] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:03.386172 2026] [authz_core:error] [pid 500253:tid 500502] [client 66.249.66.197:57621] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:03.386661 2026] [authz_core:error] [pid 500253:tid 500502] [client 66.249.66.197:57621] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:03.387208 2026] [security2:error] [pid 500253:tid 500427] [client 68.155.159.216:12328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-admin.php"] [unique_id "apPkp1mmXVd4kRvS-FAnjAAAAbk"]
[Sun Aug 30 03:07:03.401071 2026] [authz_core:error] [pid 499751:tid 500020] [client 66.249.66.42:44374] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:03.403617 2026] [authz_core:error] [pid 499751:tid 500020] [client 66.249.66.42:44374] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:03.412415 2026] [security2:error] [pid 500253:tid 500486] [client 68.155.159.216:62033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-content/cong.php"] [unique_id "apPkp1mmXVd4kRvS-FAnrQAAAfQ"]
[Sun Aug 30 03:07:03.467815 2026] [security2:error] [pid 499751:tid 499898] [client 20.48.250.41:53435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/easy.php"] [unique_id "apPkpzmmjdkPfMeJsKPY-wAAA6c"]
[Sun Aug 30 03:07:03.476414 2026] [security2:error] [pid 499751:tid 499936] [client 4.205.62.107:64480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/guk.php"] [unique_id "apPkpzmmjdkPfMeJsKPZBwAAA8w"]
[Sun Aug 30 03:07:03.490806 2026] [security2:error] [pid 499751:tid 499925] [client 20.104.50.220:28731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/enter.php"] [unique_id "apPkpzmmjdkPfMeJsKPZFQAAA8E"]
[Sun Aug 30 03:07:03.509931 2026] [security2:error] [pid 500253:tid 500444] [client 20.104.50.220:63531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/hh.php"] [unique_id "apPkp1mmXVd4kRvS-FAoQAAAAco"]
[Sun Aug 30 03:07:03.513388 2026] [security2:error] [pid 500253:tid 500493] [client 20.104.18.15:51661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkp1mmXVd4kRvS-FAoRAAAAfs"]
[Sun Aug 30 03:07:03.526032 2026] [security2:error] [pid 500253:tid 500404] [client 20.104.18.15:34690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/sf.php"] [unique_id "apPkp1mmXVd4kRvS-FAoWgAAAaI"]
[Sun Aug 30 03:07:03.528953 2026] [authz_core:error] [pid 499751:tid 500006] [client 216.73.216.128:19732] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:03.529390 2026] [authz_core:error] [pid 499751:tid 500006] [client 216.73.216.128:19732] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:03.534748 2026] [security2:error] [pid 500253:tid 500471] [client 216.244.66.238:55316] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arcaneguardians.com"] [uri "/caayjc/what-does-halal-mean-in-muslim"] [unique_id "apPkp1mmXVd4kRvS-FAoYgAAAeU"]
[Sun Aug 30 03:07:03.534838 2026] [security2:error] [pid 500253:tid 500471] [client 216.244.66.238:55316] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "arcaneguardians.com"] [uri "/caayjc/what-does-halal-mean-in-muslim"] [unique_id "apPkp1mmXVd4kRvS-FAoYgAAAeU"]
[Sun Aug 30 03:07:03.535567 2026] [security2:error] [pid 500253:tid 500445] [client 20.104.50.220:27108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/wp-admin/edit.php"] [unique_id "apPkp1mmXVd4kRvS-FAoYwAAAcs"]
[Sun Aug 30 03:07:03.551984 2026] [security2:error] [pid 499751:tid 499897] [client 4.205.62.107:26769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/cache-compat.php"] [unique_id "apPkpzmmjdkPfMeJsKPZLQAAA6Y"]
[Sun Aug 30 03:07:03.586365 2026] [security2:error] [pid 499751:tid 499907] [client 20.104.50.220:61441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/upl.php"] [unique_id "apPkpzmmjdkPfMeJsKPZSAAAA7A"]
[Sun Aug 30 03:07:03.594795 2026] [authz_core:error] [pid 500253:tid 500390] [client 66.249.66.198:57131] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:03.594989 2026] [security2:error] [pid 500253:tid 500448] [client 20.48.250.41:53497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/fresh3.php"] [unique_id "apPkp1mmXVd4kRvS-FAorwAAAc4"]
[Sun Aug 30 03:07:03.595174 2026] [authz_core:error] [pid 500253:tid 500390] [client 66.249.66.198:57131] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:03.606718 2026] [security2:error] [pid 500253:tid 500505] [client 20.196.209.81:10916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/aaa.php"] [unique_id "apPkp1mmXVd4kRvS-FAotQAAAgc"]
[Sun Aug 30 03:07:03.617759 2026] [authz_core:error] [pid 500253:tid 500460] [client 216.73.216.128:48105] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:03.618014 2026] [authz_core:error] [pid 500253:tid 500460] [client 216.73.216.128:48105] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:03.626121 2026] [security2:error] [pid 499145:tid 499285] [client 20.151.200.44:27323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPkp1JNq1G5uRhTNntM3AAAAAo"]
[Sun Aug 30 03:07:03.658371 2026] [security2:error] [pid 499751:tid 500013] [client 4.205.62.107:2979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/cu.php"] [unique_id "apPkpzmmjdkPfMeJsKPZgAAABBk"]
[Sun Aug 30 03:07:03.660738 2026] [security2:error] [pid 499751:tid 499925] [client 20.48.251.3:44373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/phina.php"] [unique_id "apPkpzmmjdkPfMeJsKPZgQAAA8E"]
[Sun Aug 30 03:07:03.677875 2026] [security2:error] [pid 499751:tid 499900] [client 20.48.251.3:50007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/product.php"] [unique_id "apPkpzmmjdkPfMeJsKPZlAAAA6k"]
[Sun Aug 30 03:07:03.688346 2026] [security2:error] [pid 499751:tid 499912] [client 4.205.62.107:18955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/paypal.php"] [unique_id "apPkpzmmjdkPfMeJsKPZnwAAA7Q"]
[Sun Aug 30 03:07:03.700957 2026] [security2:error] [pid 499145:tid 499362] [client 4.205.62.107:62098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/php_info.php"] [unique_id "apPkp1JNq1G5uRhTNntNDwAAAFc"]
[Sun Aug 30 03:07:03.708820 2026] [authz_core:error] [pid 499751:tid 499899] [client 216.73.216.128:19732] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:03.709317 2026] [authz_core:error] [pid 499751:tid 499899] [client 216.73.216.128:19732] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:03.745550 2026] [security2:error] [pid 499145:tid 499377] [client 20.48.250.41:50128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/bgymj.php"] [unique_id "apPkp1JNq1G5uRhTNntNLwAAAGY"]
[Sun Aug 30 03:07:03.750884 2026] [authz_core:error] [pid 499145:tid 499392] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_BW
[Sun Aug 30 03:07:03.751158 2026] [authz_core:error] [pid 499145:tid 499392] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_BW
[Sun Aug 30 03:07:03.765927 2026] [security2:error] [pid 499145:tid 499351] [client 68.155.159.216:62323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-admin/images/about.php"] [unique_id "apPkp1JNq1G5uRhTNntNPAAAAEw"]
[Sun Aug 30 03:07:03.772865 2026] [security2:error] [pid 499751:tid 500002] [client 20.196.209.81:20290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/atomlib.php"] [unique_id "apPkpzmmjdkPfMeJsKPZ1gAABA4"]
[Sun Aug 30 03:07:03.777413 2026] [authz_core:error] [pid 500253:tid 500483] [client 66.249.66.33:56304] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:03.777704 2026] [authz_core:error] [pid 500253:tid 500483] [client 66.249.66.33:56304] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:03.793366 2026] [security2:error] [pid 499751:tid 499949] [client 20.104.50.220:32538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/ninja.php"] [unique_id "apPkpzmmjdkPfMeJsKPZ7AAAA9k"]
[Sun Aug 30 03:07:03.799043 2026] [security2:error] [pid 499145:tid 499353] [client 20.104.18.15:28490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/ano.php"] [unique_id "apPkp1JNq1G5uRhTNntNUAAAAE4"]
[Sun Aug 30 03:07:03.829986 2026] [security2:error] [pid 499751:tid 499942] [client 4.205.62.107:62461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/nzv.php"] [unique_id "apPkpzmmjdkPfMeJsKPaEQAAA9I"]
[Sun Aug 30 03:07:03.834102 2026] [security2:error] [pid 499145:tid 499310] [client 4.205.62.107:4584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/aws_keys.php"] [unique_id "apPkp1JNq1G5uRhTNntNaQAAACM"]
[Sun Aug 30 03:07:03.883811 2026] [security2:error] [pid 499751:tid 500009] [client 20.48.250.41:53380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/ws69.php"] [unique_id "apPkpzmmjdkPfMeJsKPaOQAABBU"]
[Sun Aug 30 03:07:03.889592 2026] [security2:error] [pid 499751:tid 499972] [client 20.48.251.3:33285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/4563.php"] [unique_id "apPkpzmmjdkPfMeJsKPaQAAAA_A"]
[Sun Aug 30 03:07:03.894913 2026] [security2:error] [pid 499751:tid 499971] [client 20.104.18.15:44014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/v22.php"] [unique_id "apPkpzmmjdkPfMeJsKPaRQAAA-8"]
[Sun Aug 30 03:07:03.908886 2026] [security2:error] [pid 499751:tid 499941] [client 20.104.50.220:17286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wpconf.php"] [unique_id "apPkpzmmjdkPfMeJsKPaXAAAA9E"]
[Sun Aug 30 03:07:03.934419 2026] [authz_core:error] [pid 499145:tid 499341] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fmessage
[Sun Aug 30 03:07:03.934862 2026] [authz_core:error] [pid 499145:tid 499341] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fmessage
[Sun Aug 30 03:07:03.951491 2026] [security2:error] [pid 500253:tid 500407] [client 20.104.50.220:62818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/adminer.php"] [unique_id "apPkp1mmXVd4kRvS-FApVQAAAaU"]
[Sun Aug 30 03:07:03.959844 2026] [security2:error] [pid 499751:tid 500013] [client 20.104.18.15:23546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/file1221.php"] [unique_id "apPkpzmmjdkPfMeJsKPafQAABBk"]
[Sun Aug 30 03:07:03.961689 2026] [security2:error] [pid 499751:tid 500001] [client 20.104.50.220:47091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-iav.php"] [unique_id "apPkpzmmjdkPfMeJsKPafwAABA0"]
[Sun Aug 30 03:07:03.963727 2026] [security2:error] [pid 499751:tid 499980] [client 68.155.159.216:56359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-includes/js/index.php"] [unique_id "apPkpzmmjdkPfMeJsKPahAAAA_g"]
[Sun Aug 30 03:07:03.964783 2026] [security2:error] [pid 499751:tid 499915] [client 20.104.18.15:33664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/sss.php"] [unique_id "apPkpzmmjdkPfMeJsKPahwAAA7c"]
[Sun Aug 30 03:07:04.039578 2026] [security2:error] [pid 499145:tid 499393] [client 68.155.159.216:55125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apPkqFJNq1G5uRhTNntNyAAAAHY"]
[Sun Aug 30 03:07:04.041106 2026] [security2:error] [pid 499145:tid 499315] [client 20.48.250.41:53436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/ccs.php"] [unique_id "apPkqFJNq1G5uRhTNntNygAAACg"]
[Sun Aug 30 03:07:04.075374 2026] [authz_core:error] [pid 500253:tid 500481] [client 216.73.216.128:48105] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:04.075828 2026] [authz_core:error] [pid 500253:tid 500481] [client 216.73.216.128:48105] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:04.099036 2026] [security2:error] [pid 499145:tid 499363] [client 20.104.50.220:6127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/bonita76.php"] [unique_id "apPkqFJNq1G5uRhTNntN6AAAAFg"]
[Sun Aug 30 03:07:04.138532 2026] [security2:error] [pid 499751:tid 499894] [client 20.151.200.44:27150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/xda.php"] [unique_id "apPkqDmmjdkPfMeJsKPbCgAAA6M"]
[Sun Aug 30 03:07:04.155843 2026] [authz_core:error] [pid 499145:tid 499390] [client 66.249.66.37:59613] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:04.156108 2026] [authz_core:error] [pid 499145:tid 499390] [client 66.249.66.37:59613] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:04.157728 2026] [security2:error] [pid 499145:tid 499275] [client 216.73.216.128:31508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/usage_202601.html"] [unique_id "apPkqFJNq1G5uRhTNntOAgAAAAA"]
[Sun Aug 30 03:07:04.165159 2026] [security2:error] [pid 500253:tid 500393] [client 20.104.18.15:13709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/dev.php"] [unique_id "apPkqFmmXVd4kRvS-FAp5QAAAZc"]
[Sun Aug 30 03:07:04.207902 2026] [security2:error] [pid 500253:tid 500436] [client 20.48.250.41:53434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/mar.php"] [unique_id "apPkqFmmXVd4kRvS-FAqEQAAAcI"]
[Sun Aug 30 03:07:04.226692 2026] [security2:error] [pid 500253:tid 500399] [client 20.104.50.220:32833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/gg.php"] [unique_id "apPkqFmmXVd4kRvS-FAqNgAAAZ0"]
[Sun Aug 30 03:07:04.230820 2026] [authz_core:error] [pid 499145:tid 499293] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_BW
[Sun Aug 30 03:07:04.231323 2026] [authz_core:error] [pid 499145:tid 499293] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_BW
[Sun Aug 30 03:07:04.255748 2026] [security2:error] [pid 500253:tid 500508] [client 20.196.209.81:10895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/buy.php"] [unique_id "apPkqFmmXVd4kRvS-FAqaAAAAgo"]
[Sun Aug 30 03:07:04.256922 2026] [authz_core:error] [pid 500253:tid 500405] [client 66.249.66.198:57131] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:04.257208 2026] [authz_core:error] [pid 500253:tid 500405] [client 66.249.66.198:57131] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:04.293210 2026] [security2:error] [pid 500253:tid 500425] [client 4.205.62.107:60579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/old_phpinfo.php"] [unique_id "apPkqFmmXVd4kRvS-FAqkAAAAbc"]
[Sun Aug 30 03:07:04.352768 2026] [authz_core:error] [pid 499145:tid 499290] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:04.353208 2026] [authz_core:error] [pid 499145:tid 499290] [client 216.73.216.128:31508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:04.360845 2026] [security2:error] [pid 500253:tid 500504] [client 68.155.159.216:65443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apPkqFmmXVd4kRvS-FAq4AAAAgY"]
[Sun Aug 30 03:07:04.361416 2026] [security2:error] [pid 500253:tid 500386] [client 20.151.200.44:27187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPkqFmmXVd4kRvS-FAq4gAAAZA"]
[Sun Aug 30 03:07:04.361716 2026] [security2:error] [pid 500253:tid 500506] [client 4.205.62.107:65393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/test1.php"] [unique_id "apPkqFmmXVd4kRvS-FAq5AAAAgg"]
[Sun Aug 30 03:07:04.374941 2026] [security2:error] [pid 499751:tid 499846] [remote 191.101.50.240:39936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.50.101.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omconsulting-group.com"] [uri "/wp-login.php"] [unique_id "apPkqDmmjdkPfMeJsKPbnwAEAVE"]
[Sun Aug 30 03:07:04.391072 2026] [security2:error] [pid 500253:tid 500504] [client 20.48.250.41:53499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/ccu.php"] [unique_id "apPkqFmmXVd4kRvS-FArAQAAAgY"]
[Sun Aug 30 03:07:04.414884 2026] [security2:error] [pid 500253:tid 500423] [client 4.205.62.107:58344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/wp-konfig.backup.php"] [unique_id "apPkqFmmXVd4kRvS-FArFAAAAbU"]
[Sun Aug 30 03:07:04.424201 2026] [security2:error] [pid 500253:tid 500421] [client 4.205.62.107:52115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/var/www/wallet/index.php"] [unique_id "apPkqFmmXVd4kRvS-FArJgAAAbM"]
[Sun Aug 30 03:07:04.476058 2026] [security2:error] [pid 499751:tid 499970] [client 20.48.251.3:45848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/tinyfilemanager.php"] [unique_id "apPkqDmmjdkPfMeJsKPcBAAAA-4"]
[Sun Aug 30 03:07:04.489512 2026] [security2:error] [pid 500253:tid 500484] [client 20.104.18.15:29180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/av.php"] [unique_id "apPkqFmmXVd4kRvS-FArcAAAAfI"]
[Sun Aug 30 03:07:04.534093 2026] [security2:error] [pid 500253:tid 500432] [client 68.155.159.216:12327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apPkqFmmXVd4kRvS-FArngAAAb4"]
[Sun Aug 30 03:07:04.534635 2026] [authz_core:error] [pid 500253:tid 500498] [client 216.73.216.128:48105] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:04.534935 2026] [authz_core:error] [pid 500253:tid 500498] [client 216.73.216.128:48105] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:04.536932 2026] [security2:error] [pid 499751:tid 499995] [client 20.48.250.41:53428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/ak.php"] [unique_id "apPkqDmmjdkPfMeJsKPcRwAABAc"]
[Sun Aug 30 03:07:04.553681 2026] [security2:error] [pid 499751:tid 499849] [remote 191.101.50.240:39936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.50.101.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omconsulting-group.com"] [uri "/wp-login.php"] [unique_id "apPkqDmmjdkPfMeJsKPcUAAD1VQ"], referer: https://omconsulting-group.com/wp-login.php
[Sun Aug 30 03:07:04.621324 2026] [security2:error] [pid 499751:tid 500003] [client 4.205.62.107:64691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/config_dev.php"] [unique_id "apPkqDmmjdkPfMeJsKPcewAABA8"]
[Sun Aug 30 03:07:04.653923 2026] [security2:error] [pid 500253:tid 500427] [client 20.48.160.90:37991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkqFmmXVd4kRvS-FAr1wAAAbk"]
[Sun Aug 30 03:07:04.670844 2026] [security2:error] [pid 500253:tid 500493] [client 20.196.209.81:20898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/hello.php"] [unique_id "apPkqFmmXVd4kRvS-FAr4wAAAfs"]
[Sun Aug 30 03:07:04.671058 2026] [security2:error] [pid 499751:tid 499974] [client 20.48.250.41:53402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/lib.php"] [unique_id "apPkqDmmjdkPfMeJsKPcqwAAA_I"]
[Sun Aug 30 03:07:04.671272 2026] [security2:error] [pid 500253:tid 500438] [client 20.104.50.220:51563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/hz.php"] [unique_id "apPkqFmmXVd4kRvS-FAr5AAAAcQ"]
[Sun Aug 30 03:07:04.672458 2026] [security2:error] [pid 499145:tid 499375] [client 20.104.18.15:34725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/k.php"] [unique_id "apPkqFJNq1G5uRhTNntO7QAAAGQ"]
[Sun Aug 30 03:07:04.681168 2026] [security2:error] [pid 499751:tid 499933] [client 20.104.50.220:27208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/fr/wp-login.php"] [unique_id "apPkqDmmjdkPfMeJsKPcpwAAA8k"]
[Sun Aug 30 03:07:04.706990 2026] [security2:error] [pid 500253:tid 500390] [client 216.73.216.128:48105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPkqFmmXVd4kRvS-FAr7gAAAZQ"]
[Sun Aug 30 03:07:04.710533 2026] [security2:error] [pid 500253:tid 500468] [client 20.104.50.220:29595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-enter.php"] [unique_id "apPkqFmmXVd4kRvS-FAr8AAAAeI"]
[Sun Aug 30 03:07:04.738505 2026] [authz_core:error] [pid 499145:tid 499291] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_PH
[Sun Aug 30 03:07:04.738940 2026] [authz_core:error] [pid 499145:tid 499291] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_PH
[Sun Aug 30 03:07:04.754872 2026] [security2:error] [pid 499145:tid 499277] [client 20.104.18.15:51709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/media.php"] [unique_id "apPkqFJNq1G5uRhTNntPKAAAAAI"]
[Sun Aug 30 03:07:04.796732 2026] [security2:error] [pid 499145:tid 499389] [client 216.73.216.128:31508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPkqFJNq1G5uRhTNntPQgAAAHI"]
[Sun Aug 30 03:07:04.800010 2026] [authz_core:error] [pid 499145:tid 499314] [client 66.249.66.203:48744] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:04.800472 2026] [authz_core:error] [pid 499145:tid 499314] [client 66.249.66.203:48744] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:04.801867 2026] [security2:error] [pid 499751:tid 499998] [client 20.48.160.90:37752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkqDmmjdkPfMeJsKPdBgAABAo"]
[Sun Aug 30 03:07:04.808843 2026] [security2:error] [pid 500253:tid 500509] [client 20.48.250.41:53379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/wp-style.php"] [unique_id "apPkqFmmXVd4kRvS-FAsGQAAAgs"]
[Sun Aug 30 03:07:04.809994 2026] [security2:error] [pid 499751:tid 499895] [client 20.104.49.130:52417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/red.php"] [unique_id "apPkqDmmjdkPfMeJsKPdEAAAA6Q"]
[Sun Aug 30 03:07:04.826845 2026] [security2:error] [pid 499751:tid 499933] [client 4.205.62.107:17821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/userfuns.php"] [unique_id "apPkqDmmjdkPfMeJsKPdHwAAA8k"]
[Sun Aug 30 03:07:04.835912 2026] [security2:error] [pid 499751:tid 499951] [client 20.48.251.3:50046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/fun.php"] [unique_id "apPkqDmmjdkPfMeJsKPdJwAAA9s"]
[Sun Aug 30 03:07:04.843416 2026] [security2:error] [pid 499751:tid 499929] [client 4.205.62.107:64014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/session.php"] [unique_id "apPkqDmmjdkPfMeJsKPdMwAAA8U"]
[Sun Aug 30 03:07:04.891327 2026] [authz_core:error] [pid 499751:tid 499917] [client 66.249.66.69:52036] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:04.891588 2026] [authz_core:error] [pid 499751:tid 499917] [client 66.249.66.69:52036] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:05.031691 2026] [qos:error] [pid 499751:tid 499994] [client 103.97.140.127:54676] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.97.140.127, id=apPkqTmmjdkPfMeJsKPdXgAABAY
[Sun Aug 30 03:07:05.052202 2026] [qos:error] [pid 499751:tid 499996] [client 38.19.43.184:35934] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.19.43.184, id=apPkqTmmjdkPfMeJsKPdXwAABAg
[Sun Aug 30 03:07:05.054145 2026] [qos:error] [pid 499145:tid 499393] [client 5.253.196.143:58716] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=5.253.196.143, id=apPkqVJNq1G5uRhTNntPlQAAAHY
[Sun Aug 30 03:07:05.054211 2026] [qos:error] [pid 499145:tid 499338] [client 144.24.171.189:50494] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=109, c=144.24.171.189, id=apPkqVJNq1G5uRhTNntPmAAAAD8
[Sun Aug 30 03:07:05.054151 2026] [qos:error] [pid 499145:tid 499297] [client 185.94.83.249:42444] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=185.94.83.249, id=apPkqVJNq1G5uRhTNntPlAAAABY
[Sun Aug 30 03:07:05.054151 2026] [qos:error] [pid 499145:tid 499327] [client 41.79.233.182:54961] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=41.79.233.182, id=apPkqVJNq1G5uRhTNntPlgAAADQ
[Sun Aug 30 03:07:05.054156 2026] [qos:error] [pid 499145:tid 499323] [client 138.117.14.237:53332] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=138.117.14.237, id=apPkqVJNq1G5uRhTNntPmgAAADA
[Sun Aug 30 03:07:05.054164 2026] [qos:error] [pid 499145:tid 499308] [client 190.112.160.23:56862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=190.112.160.23, id=apPkqVJNq1G5uRhTNntPmQAAACE
[Sun Aug 30 03:07:05.054174 2026] [qos:error] [pid 499145:tid 499391] [client 45.186.106.145:44682] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=107, c=45.186.106.145, id=apPkqVJNq1G5uRhTNntPmwAAAHQ
[Sun Aug 30 03:07:05.054172 2026] [qos:error] [pid 499145:tid 499316] [client 171.226.73.226:41038] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=106, c=171.226.73.226, id=apPkqVJNq1G5uRhTNntPnAAAACk
[Sun Aug 30 03:07:05.054203 2026] [qos:error] [pid 499145:tid 499300] [client 103.126.86.239:51146] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=108, c=103.126.86.239, id=apPkqVJNq1G5uRhTNntPnQAAABk
[Sun Aug 30 03:07:05.054238 2026] [qos:error] [pid 499145:tid 499304] [client 31.130.131.191:37852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=110, c=31.130.131.191, id=apPkqVJNq1G5uRhTNntPlwAAAB0
[Sun Aug 30 03:07:05.054584 2026] [qos:error] [pid 499751:tid 499933] [client 179.225.55.3:36820] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=179.225.55.3, id=apPkqTmmjdkPfMeJsKPdYAAAA8k
[Sun Aug 30 03:07:05.056123 2026] [qos:error] [pid 499751:tid 499957] [client 195.19.49.206:53422] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=195.19.49.206, id=apPkqTmmjdkPfMeJsKPdYQAAA-E
[Sun Aug 30 03:07:05.056358 2026] [qos:error] [pid 499145:tid 499276] [client 157.15.0.167:43062] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=157.15.0.167, id=apPkqVJNq1G5uRhTNntPngAAAAE
[Sun Aug 30 03:07:05.059919 2026] [qos:error] [pid 499751:tid 499968] [client 138.59.190.114:56468] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=138.59.190.114, id=apPkqTmmjdkPfMeJsKPdYgAAA-w
[Sun Aug 30 03:07:05.060501 2026] [qos:error] [pid 499145:tid 499351] [client 103.163.13.36:51868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.163.13.36, id=apPkqVJNq1G5uRhTNntPnwAAAEw
[Sun Aug 30 03:07:05.060808 2026] [qos:error] [pid 499145:tid 499307] [client 185.220.100.255:59666] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=185.220.100.255, id=apPkqVJNq1G5uRhTNntPoAAAACA
[Sun Aug 30 03:07:05.060816 2026] [qos:error] [pid 499751:tid 499949] [client 157.10.105.57:56612] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=157.10.105.57, id=apPkqTmmjdkPfMeJsKPdYwAAA9k
[Sun Aug 30 03:07:05.061468 2026] [qos:error] [pid 499145:tid 499372] [client 42.96.18.62:56616] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=42.96.18.62, id=apPkqVJNq1G5uRhTNntPoQAAAGE
[Sun Aug 30 03:07:05.065598 2026] [qos:error] [pid 499145:tid 499355] [client 139.84.133.240:49024] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=139.84.133.240, id=apPkqVJNq1G5uRhTNntPogAAAFA
[Sun Aug 30 03:07:05.065634 2026] [qos:error] [pid 499145:tid 499350] [client 176.114.125.112:43066] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=176.114.125.112, id=apPkqVJNq1G5uRhTNntPowAAAEs
[Sun Aug 30 03:07:05.066193 2026] [qos:error] [pid 499751:tid 499950] [client 103.169.154.4:54368] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.169.154.4, id=apPkqTmmjdkPfMeJsKPdZQAAA9o
[Sun Aug 30 03:07:05.066290 2026] [qos:error] [pid 499751:tid 499997] [client 147.45.60.136:54212] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=147.45.60.136, id=apPkqTmmjdkPfMeJsKPdZgAABAk
[Sun Aug 30 03:07:05.066873 2026] [qos:error] [pid 499751:tid 499976] [client 43.134.141.85:56692] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=43.134.141.85, id=apPkqTmmjdkPfMeJsKPdZwAAA_Q
[Sun Aug 30 03:07:05.068166 2026] [qos:error] [pid 499751:tid 500009] [client 187.77.24.67:40534] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=187.77.24.67, id=apPkqTmmjdkPfMeJsKPdaAAABBU
[Sun Aug 30 03:07:05.069241 2026] [qos:error] [pid 499145:tid 499358] [client 45.136.115.2:44766] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.136.115.2, id=apPkqVJNq1G5uRhTNntPpAAAAFM
[Sun Aug 30 03:07:05.069894 2026] [qos:error] [pid 499751:tid 499956] [client 91.239.208.190:59116] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=91.239.208.190, id=apPkqTmmjdkPfMeJsKPdaQAAA-A
[Sun Aug 30 03:07:05.070045 2026] [qos:error] [pid 499145:tid 499378] [client 192.255.201.184:46386] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=192.255.201.184, id=apPkqVJNq1G5uRhTNntPpQAAAGc
[Sun Aug 30 03:07:05.074976 2026] [http2:info] [pid 501390:tid 501390] h2_workers: created with min=128 max=192 idle_ms=600000
[Sun Aug 30 03:07:05.075291 2026] [qos:error] [pid 499145:tid 499376] [client 14.241.183.20:34622] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=14.241.183.20, id=apPkqVJNq1G5uRhTNntPpgAAAGU
[Sun Aug 30 03:07:05.076113 2026] [qos:error] [pid 499145:tid 499348] [client 38.58.66.232:55432] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.58.66.232, id=apPkqVJNq1G5uRhTNntPpwAAAEk
[Sun Aug 30 03:07:05.090570 2026] [qos:error] [pid 499751:tid 499925] [client 198.15.30.206:38098] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=198.15.30.206, id=apPkqTmmjdkPfMeJsKPdagAAA8E
[Sun Aug 30 03:07:05.090579 2026] [qos:error] [pid 499145:tid 499295] [client 112.197.57.3:47491] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=112.197.57.3, id=apPkqVJNq1G5uRhTNntPqAAAABQ
[Sun Aug 30 03:07:05.091231 2026] [qos:error] [pid 499751:tid 499941] [client 103.183.69.100:48722] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=103.183.69.100, id=apPkqTmmjdkPfMeJsKPdawAAA9E
[Sun Aug 30 03:07:05.091242 2026] [qos:error] [pid 499145:tid 499373] [client 103.61.18.6:57894] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=103.61.18.6, id=apPkqVJNq1G5uRhTNntPqQAAAGI
[Sun Aug 30 03:07:05.093320 2026] [qos:error] [pid 499751:tid 499982] [client 118.145.141.251:53278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=118.145.141.251, id=apPkqTmmjdkPfMeJsKPdbAAAA_o
[Sun Aug 30 03:07:05.098661 2026] [qos:error] [pid 499751:tid 499904] [client 38.19.43.106:49136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.19.43.106, id=apPkqTmmjdkPfMeJsKPdbQAAA60
[Sun Aug 30 03:07:05.102474 2026] [qos:error] [pid 499145:tid 499279] [client 45.137.12.78:44704] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.137.12.78, id=apPkqVJNq1G5uRhTNntPqgAAAAQ
[Sun Aug 30 03:07:05.104021 2026] [security2:error] [pid 501390:tid 501545] [client 20.104.50.220:32086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/ohayo.php"] [unique_id "apPkqag6skwqJ2NpVh-1BgAAAi0"]
[Sun Aug 30 03:07:05.104078 2026] [security2:error] [pid 501390:tid 501534] [client 20.104.50.220:17217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/ultradybbuks.php"] [unique_id "apPkqag6skwqJ2NpVh-1AQAAAiI"]
[Sun Aug 30 03:07:05.104097 2026] [security2:error] [pid 501390:tid 501525] [client 4.205.62.107:4134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/umgebung.php"] [unique_id "apPkqag6skwqJ2NpVh-0_QAAAhk"]
[Sun Aug 30 03:07:05.104109 2026] [security2:error] [pid 501390:tid 501521] [client 68.155.159.216:62060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPkqag6skwqJ2NpVh-0-gAAAhU"]
[Sun Aug 30 03:07:05.104208 2026] [security2:error] [pid 501390:tid 501523] [client 20.48.251.3:56375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/cp2.php"] [unique_id "apPkqag6skwqJ2NpVh-0_AAAAhc"]
[Sun Aug 30 03:07:05.104253 2026] [security2:error] [pid 501390:tid 501533] [client 20.151.200.44:27166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/t00l.php"] [unique_id "apPkqag6skwqJ2NpVh-0_wAAAiE"]
[Sun Aug 30 03:07:05.104381 2026] [security2:error] [pid 501390:tid 501538] [client 20.48.160.90:61482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/ser.php"] [unique_id "apPkqag6skwqJ2NpVh-1AwAAAiY"]
[Sun Aug 30 03:07:05.104479 2026] [security2:error] [pid 501390:tid 501522] [client 20.48.250.41:53391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/browse.php"] [unique_id "apPkqag6skwqJ2NpVh-0-QAAAhY"]
[Sun Aug 30 03:07:05.104484 2026] [security2:error] [pid 501390:tid 501535] [client 20.48.251.3:44313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/koiy.php"] [unique_id "apPkqag6skwqJ2NpVh-1AgAAAiM"]
[Sun Aug 30 03:07:05.104537 2026] [security2:error] [pid 501390:tid 501542] [client 20.104.18.15:28637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/ai.php"] [unique_id "apPkqag6skwqJ2NpVh-1BQAAAio"]
[Sun Aug 30 03:07:05.104548 2026] [security2:error] [pid 501390:tid 501539] [client 68.155.159.216:56332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-content/index.php"] [unique_id "apPkqag6skwqJ2NpVh-1BAAAAic"]
[Sun Aug 30 03:07:05.104554 2026] [qos:error] [pid 499145:tid 499353] [client 103.124.165.149:35756] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.124.165.149, id=apPkqVJNq1G5uRhTNntPqwAAAE4
[Sun Aug 30 03:07:05.104629 2026] [security2:error] [pid 501390:tid 501520] [client 4.205.62.107:2136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/services.php"] [unique_id "apPkqag6skwqJ2NpVh-0-AAAAhQ"]
[Sun Aug 30 03:07:05.104786 2026] [security2:error] [pid 501390:tid 501532] [client 20.104.18.15:43279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/wp-activate.php"] [unique_id "apPkqag6skwqJ2NpVh-1AAAAAiA"]
[Sun Aug 30 03:07:05.104812 2026] [security2:error] [pid 501390:tid 501524] [client 4.205.62.107:62305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/66.php"] [unique_id "apPkqag6skwqJ2NpVh-0-wAAAhg"]
[Sun Aug 30 03:07:05.107134 2026] [qos:error] [pid 501390:tid 501528] [client 103.184.67.45:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkqag6skwqJ2NpVh-1DwAAAhw
[Sun Aug 30 03:07:05.107656 2026] [qos:error] [pid 499751:tid 500016] [client 45.190.10.22:45520] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=45.190.10.22, id=apPkqTmmjdkPfMeJsKPdbwAABBw
[Sun Aug 30 03:07:05.107655 2026] [qos:error] [pid 499751:tid 499980] [client 212.112.121.130:50516] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=212.112.121.130, id=apPkqTmmjdkPfMeJsKPdbgAAA_g
[Sun Aug 30 03:07:05.108170 2026] [qos:error] [pid 499751:tid 499951] [client 14.179.32.219:51829] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=14.179.32.219, id=apPkqTmmjdkPfMeJsKPdcAAAA9s
[Sun Aug 30 03:07:05.109601 2026] [qos:error] [pid 499751:tid 499916] [client 103.163.80.172:58665] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=103.163.80.172, id=apPkqTmmjdkPfMeJsKPdcQAAA7g
[Sun Aug 30 03:07:05.112591 2026] [qos:error] [pid 499145:tid 499389] [client 59.36.210.211:49875] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=59.36.210.211, id=apPkqVJNq1G5uRhTNntPrAAAAHI
[Sun Aug 30 03:07:05.112795 2026] [qos:error] [pid 499145:tid 499288] [client 212.87.194.103:40946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=212.87.194.103, id=apPkqVJNq1G5uRhTNntPrQAAAA0
[Sun Aug 30 03:07:05.113121 2026] [security2:error] [pid 501390:tid 501563] [client 20.104.18.15:23530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/nox.php"] [unique_id "apPkqag6skwqJ2NpVh-1JwAAAj8"]
[Sun Aug 30 03:07:05.119363 2026] [authz_core:error] [pid 501390:tid 501531] [client 216.73.216.128:50828] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:05.119600 2026] [qos:error] [pid 499145:tid 499363] [client 204.76.203.9:46272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=204.76.203.9, id=apPkqVJNq1G5uRhTNntPrgAAAFg
[Sun Aug 30 03:07:05.119873 2026] [authz_core:error] [pid 501390:tid 501531] [client 216.73.216.128:50828] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:05.120744 2026] [qos:error] [pid 499145:tid 499396] [client 112.198.23.254:41560] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=112.198.23.254, id=apPkqVJNq1G5uRhTNntPrwAAAHk
[Sun Aug 30 03:07:05.120957 2026] [qos:error] [pid 499145:tid 499366] [client 42.114.43.88:59495] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=42.114.43.88, id=apPkqVJNq1G5uRhTNntPsAAAAFs
[Sun Aug 30 03:07:05.121519 2026] [qos:error] [pid 499751:tid 499920] [client 47.238.236.151:40098] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=47.238.236.151, id=apPkqTmmjdkPfMeJsKPdcgAAA7w
[Sun Aug 30 03:07:05.126517 2026] [qos:error] [pid 501390:tid 501551] [client 43.156.228.168:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.44, id=apPkqag6skwqJ2NpVh-1NAAAAjM
[Sun Aug 30 03:07:05.126893 2026] [qos:error] [pid 501390:tid 501546] [client 170.246.144.196:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.44, id=apPkqag6skwqJ2NpVh-1JAAAAi4
[Sun Aug 30 03:07:05.126906 2026] [qos:error] [pid 501390:tid 501548] [client 213.244.95.175:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=50.6.92.44, id=apPkqag6skwqJ2NpVh-1JgAAAjA
[Sun Aug 30 03:07:05.127782 2026] [qos:error] [pid 499751:tid 499897] [client 38.250.229.66:37903] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=38.250.229.66, id=apPkqTmmjdkPfMeJsKPdcwAAA6Y
[Sun Aug 30 03:07:05.128136 2026] [qos:error] [pid 499751:tid 499943] [client 190.97.239.60:43862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=190.97.239.60, id=apPkqTmmjdkPfMeJsKPddAAAA9M
[Sun Aug 30 03:07:05.129273 2026] [security2:error] [pid 501390:tid 501646] [client 20.104.50.220:28696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/rootx.php"] [unique_id "apPkqag6skwqJ2NpVh-1ZQAAApI"]
[Sun Aug 30 03:07:05.130062 2026] [qos:error] [pid 499145:tid 499278] [client 113.45.195.147:46042] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=113.45.195.147, id=apPkqVJNq1G5uRhTNntPsQAAAAM
[Sun Aug 30 03:07:05.130738 2026] [qos:error] [pid 501390:tid 501545] [client 58.69.61.79:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.44, id=apPkqag6skwqJ2NpVh-1ZwAAAi0
[Sun Aug 30 03:07:05.130736 2026] [qos:error] [pid 499751:tid 500020] [client 157.10.156.155:43932] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=157.10.156.155, id=apPkqTmmjdkPfMeJsKPddQAABCA
[Sun Aug 30 03:07:05.131287 2026] [security2:error] [pid 501390:tid 501551] [client 20.104.50.220:47094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-info.php"] [unique_id "apPkqag6skwqJ2NpVh-1agAAAjM"]
[Sun Aug 30 03:07:05.132014 2026] [qos:error] [pid 499751:tid 499932] [client 94.131.92.155:34914] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=94.131.92.155, id=apPkqTmmjdkPfMeJsKPddgAAA8g
[Sun Aug 30 03:07:05.132572 2026] [qos:error] [pid 501390:tid 501563] [client 43.163.112.8:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkqag6skwqJ2NpVh-1bAAAAj8
[Sun Aug 30 03:07:05.132875 2026] [qos:error] [pid 499145:tid 499383] [client 123.20.38.145:44196] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=123.20.38.145, id=apPkqVJNq1G5uRhTNntPswAAAGw
[Sun Aug 30 03:07:05.132891 2026] [qos:error] [pid 499145:tid 499344] [client 38.191.204.22:36540] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=38.191.204.22, id=apPkqVJNq1G5uRhTNntPtAAAAEU
[Sun Aug 30 03:07:05.134071 2026] [qos:error] [pid 501390:tid 501543] [client 150.241.91.238:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkqag6skwqJ2NpVh-1bQAAAis
[Sun Aug 30 03:07:05.134156 2026] [qos:error] [pid 501390:tid 501540] [client 81.70.40.86:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.44, id=apPkqag6skwqJ2NpVh-1bgAAAig
[Sun Aug 30 03:07:05.134370 2026] [qos:error] [pid 501390:tid 501554] [client 36.50.112.174:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkqag6skwqJ2NpVh-1cAAAAjY
[Sun Aug 30 03:07:05.134401 2026] [qos:error] [pid 501390:tid 501558] [client 72.62.59.63:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.44, id=apPkqag6skwqJ2NpVh-1cQAAAjo
[Sun Aug 30 03:07:05.134430 2026] [qos:error] [pid 501390:tid 501569] [client 192.255.201.183:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=50.6.92.44, id=apPkqag6skwqJ2NpVh-1bwAAAkU
[Sun Aug 30 03:07:05.134955 2026] [qos:error] [pid 501390:tid 501532] [client 38.19.239.218:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkqag6skwqJ2NpVh-1cgAAAiA
[Sun Aug 30 03:07:05.136621 2026] [qos:error] [pid 501390:tid 501536] [client 157.85.212.181:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkqag6skwqJ2NpVh-1eQAAAiQ
[Sun Aug 30 03:07:05.138553 2026] [authz_core:error] [pid 501390:tid 501647] [client 216.73.216.128:24601] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:05.139090 2026] [authz_core:error] [pid 501390:tid 501647] [client 216.73.216.128:24601] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:05.144627 2026] [security2:error] [pid 499751:tid 499907] [client 20.104.50.220:62217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/gelay.php"] [unique_id "apPkqTmmjdkPfMeJsKPddwAAA7A"]
[Sun Aug 30 03:07:05.174056 2026] [authz_core:error] [pid 499751:tid 499957] [client 216.73.216.128:19732] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:05.174560 2026] [authz_core:error] [pid 499751:tid 499957] [client 216.73.216.128:19732] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:05.174800 2026] [security2:error] [pid 499751:tid 499913] [client 68.155.159.216:54242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apPkqTmmjdkPfMeJsKPdlAAAA7U"]
[Sun Aug 30 03:07:05.233424 2026] [security2:error] [pid 499751:tid 499969] [client 20.48.160.90:37650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/431.php"] [unique_id "apPkqTmmjdkPfMeJsKPdvQAAA-0"]
[Sun Aug 30 03:07:05.233483 2026] [security2:error] [pid 501390:tid 501530] [client 20.196.209.81:20880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/g.php"] [unique_id "apPkqag6skwqJ2NpVh-2BAAAAh4"]
[Sun Aug 30 03:07:05.240087 2026] [security2:error] [pid 499751:tid 499920] [client 20.48.250.41:53491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/zoo.php"] [unique_id "apPkqTmmjdkPfMeJsKPdwQAAA7w"]
[Sun Aug 30 03:07:05.251281 2026] [security2:error] [pid 499751:tid 499964] [client 20.104.50.220:5187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/angie712.php"] [unique_id "apPkqTmmjdkPfMeJsKPd0gAAA-g"]
[Sun Aug 30 03:07:05.267121 2026] [security2:error] [pid 501390:tid 501593] [client 20.104.18.15:33605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/wp-includes/ID3/moon.php"] [unique_id "apPkqag6skwqJ2NpVh-2DwAAAl0"]
[Sun Aug 30 03:07:05.268925 2026] [authz_core:error] [pid 499145:tid 499305] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_GB
[Sun Aug 30 03:07:05.269379 2026] [authz_core:error] [pid 499145:tid 499305] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_GB
[Sun Aug 30 03:07:05.277047 2026] [security2:error] [pid 499145:tid 499365] [client 68.155.159.216:63504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPkqVJNq1G5uRhTNntP7wAAAFo"]
[Sun Aug 30 03:07:05.282921 2026] [security2:error] [pid 501390:tid 501393] [remote 114.119.137.67:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.concordconsultingbali.com"] [uri "/Details.php"] [unique_id "apPkqag6skwqJ2NpVh-2EgACGwI"], referer: https://www.concordconsultingbali.com/jobs.php?page=8&jobs-page=4
[Sun Aug 30 03:07:05.298709 2026] [security2:error] [pid 499145:tid 499377] [client 20.104.18.15:13637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/gos.php"] [unique_id "apPkqVJNq1G5uRhTNntP-gAAAGY"]
[Sun Aug 30 03:07:05.346140 2026] [security2:error] [pid 501390:tid 501638] [client 4.205.62.107:27288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/aws_keys.php"] [unique_id "apPkqag6skwqJ2NpVh-2JQAAAoo"]
[Sun Aug 30 03:07:05.378300 2026] [security2:error] [pid 499751:tid 499959] [client 20.48.160.90:61523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/rxr.php"] [unique_id "apPkqTmmjdkPfMeJsKPeSQAAA-M"]
[Sun Aug 30 03:07:05.379815 2026] [security2:error] [pid 499751:tid 499898] [client 20.104.50.220:32877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/gelis.php"] [unique_id "apPkqTmmjdkPfMeJsKPeSgAAA6c"]
[Sun Aug 30 03:07:05.384400 2026] [security2:error] [pid 501390:tid 501644] [client 20.48.250.41:50154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/elp.php"] [unique_id "apPkqag6skwqJ2NpVh-2OgAAApA"]
[Sun Aug 30 03:07:05.391470 2026] [security2:error] [pid 499751:tid 499895] [client 20.104.49.130:53599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/mac.php"] [unique_id "apPkqTmmjdkPfMeJsKPeWAAAA6Q"]
[Sun Aug 30 03:07:05.431968 2026] [security2:error] [pid 499145:tid 499377] [client 4.205.62.107:60482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/wp-act.php"] [unique_id "apPkqVJNq1G5uRhTNntQQQAAAGY"]
[Sun Aug 30 03:07:05.458514 2026] [authz_core:error] [pid 501390:tid 501632] [client 216.73.216.128:50828] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:05.458982 2026] [authz_core:error] [pid 501390:tid 501632] [client 216.73.216.128:50828] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:05.466638 2026] [security2:error] [pid 499751:tid 499985] [client 68.155.159.216:61356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apPkqTmmjdkPfMeJsKPenAAAA_0"]
[Sun Aug 30 03:07:05.517570 2026] [security2:error] [pid 499751:tid 499953] [client 114.119.135.215:31317] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arcexploration.com.au"] [uri "/category/food/"] [unique_id "apPkqTmmjdkPfMeJsKPe1QAAA90"], referer: https://arcexploration.com.au/category/food
[Sun Aug 30 03:07:05.519132 2026] [security2:error] [pid 499145:tid 499351] [client 20.48.250.41:53383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/666.php"] [unique_id "apPkqVJNq1G5uRhTNntQegAAAEw"]
[Sun Aug 30 03:07:05.525459 2026] [security2:error] [pid 499751:tid 499925] [client 4.205.62.107:58070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/bigdump.php"] [unique_id "apPkqTmmjdkPfMeJsKPe3AAAA8E"]
[Sun Aug 30 03:07:05.536706 2026] [security2:error] [pid 501390:tid 501582] [client 20.48.160.90:61474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/csst.php"] [unique_id "apPkqag6skwqJ2NpVh-2hgAAAlI"]
[Sun Aug 30 03:07:05.572584 2026] [security2:error] [pid 499145:tid 499317] [client 4.205.62.107:56932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/124.php"] [unique_id "apPkqVJNq1G5uRhTNntQngAAACo"]
[Sun Aug 30 03:07:05.572889 2026] [security2:error] [pid 499751:tid 499919] [client 216.73.216.128:11845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPkqTmmjdkPfMeJsKPe_AAAA7s"]
[Sun Aug 30 03:07:05.599096 2026] [authz_core:error] [pid 499145:tid 499375] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:07:05.599468 2026] [authz_core:error] [pid 499145:tid 499375] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime
[Sun Aug 30 03:07:05.662287 2026] [security2:error] [pid 499751:tid 500005] [client 20.48.250.41:53447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/knmt.php"] [unique_id "apPkqTmmjdkPfMeJsKPfMgAABBE"]
[Sun Aug 30 03:07:05.663444 2026] [security2:error] [pid 499145:tid 499278] [client 20.48.251.3:64495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/05.php"] [unique_id "apPkqVJNq1G5uRhTNntQxwAAAAM"]
[Sun Aug 30 03:07:05.665193 2026] [security2:error] [pid 499751:tid 499991] [client 20.48.160.90:61455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp-includes/blocks/query-title/footer.php"] [unique_id "apPkqTmmjdkPfMeJsKPfNwAABAM"]
[Sun Aug 30 03:07:05.677924 2026] [security2:error] [pid 499751:tid 499989] [client 20.104.49.130:52341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/v2.php"] [unique_id "apPkqTmmjdkPfMeJsKPfPQAABAE"]
[Sun Aug 30 03:07:05.693315 2026] [lsapi:error] [pid 499145:tid 499146] [remote 27.114.174.245:54758] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.google.com/
[Sun Aug 30 03:07:05.693458 2026] [lsapi:error] [pid 499145:tid 499146] [remote 27.114.174.245:54758] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.google.com/
[Sun Aug 30 03:07:05.694564 2026] [security2:error] [pid 501390:tid 501615] [client 68.155.159.216:12340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/lock.php"] [unique_id "apPkqag6skwqJ2NpVh-2owAAAnM"]
[Sun Aug 30 03:07:05.694795 2026] [lsapi:error] [pid 499145:tid 499146] [remote 27.114.174.245:54758] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n, referer: https://www.google.com/
[Sun Aug 30 03:07:05.707639 2026] [security2:error] [pid 501390:tid 501538] [client 20.104.18.15:29161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/images.php"] [unique_id "apPkqag6skwqJ2NpVh-2rgAAAiY"]
[Sun Aug 30 03:07:05.728882 2026] [security2:error] [pid 499751:tid 499928] [client 20.151.200.44:27146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/ls.php"] [unique_id "apPkqTmmjdkPfMeJsKPfYgAAA8Q"]
[Sun Aug 30 03:07:05.731049 2026] [security2:error] [pid 499751:tid 499942] [client 34.125.55.247:17006] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/@fs/root/.env"] [unique_id "apPkqTmmjdkPfMeJsKPfYwAAA9I"]
[Sun Aug 30 03:07:05.735665 2026] [security2:error] [pid 499751:tid 499950] [client 34.125.55.247:17022] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/@fs/app/.env"] [unique_id "apPkqTmmjdkPfMeJsKPfZAAAA9o"]
[Sun Aug 30 03:07:05.735824 2026] [security2:error] [pid 499751:tid 500016] [client 34.125.55.247:17038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/@fs/src/.env"] [unique_id "apPkqTmmjdkPfMeJsKPfZQAABBw"]
[Sun Aug 30 03:07:05.736480 2026] [core:error] [pid 499751:tid 499966] [client 34.125.55.247:17080] AH10244: invalid URI path (/@fs/../../.env?raw??)
[Sun Aug 30 03:07:05.736580 2026] [security2:error] [pid 499751:tid 499896] [client 34.125.55.247:17018] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/@fs/.env"] [unique_id "apPkqTmmjdkPfMeJsKPfZgAAA6U"]
[Sun Aug 30 03:07:05.737025 2026] [security2:error] [pid 499751:tid 499925] [client 34.125.55.247:17062] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/@fs/..%2f..%2f..%2f..%2f..%2fapp/.env"] [unique_id "apPkqTmmjdkPfMeJsKPfZwAAA8E"]
[Sun Aug 30 03:07:05.738146 2026] [security2:error] [pid 501390:tid 501635] [client 34.125.55.247:17082] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "apPkqag6skwqJ2NpVh-2vQAAAoc"]
[Sun Aug 30 03:07:05.739287 2026] [security2:error] [pid 501390:tid 501549] [client 34.125.55.247:17048] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.engaginggoddaily.com"] [uri "/@fs/proc/self/environ"] [unique_id "apPkqag6skwqJ2NpVh-2vgAAAjE"]
[Sun Aug 30 03:07:05.739611 2026] [security2:error] [pid 501390:tid 501604] [client 34.125.55.247:17060] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.engaginggoddaily.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ"] [unique_id "apPkqag6skwqJ2NpVh-2wQAAAmg"]
[Sun Aug 30 03:07:05.740320 2026] [security2:error] [pid 501390:tid 501598] [client 34.125.55.247:17072] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/@fs/..%2f..%2f..%2f..%2f..%2froot/.env"] [unique_id "apPkqag6skwqJ2NpVh-2vwAAAmI"]
[Sun Aug 30 03:07:05.740433 2026] [security2:error] [pid 501390:tid 501598] [client 34.125.55.247:17072] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/@fs/..%2f..%2f..%2f..%2f..%2froot/.env"] [unique_id "apPkqag6skwqJ2NpVh-2vwAAAmI"]
[Sun Aug 30 03:07:05.741322 2026] [security2:error] [pid 501390:tid 501550] [client 34.125.55.247:17140] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/@fs/root/.aws/credentials.bak"] [unique_id "apPkqag6skwqJ2NpVh-2wAAAAjI"]
[Sun Aug 30 03:07:05.744805 2026] [security2:error] [pid 499751:tid 499995] [client 34.125.55.247:17108] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.engaginggoddaily.com"] [uri "/@fs/.env.staging"] [unique_id "apPkqTmmjdkPfMeJsKPfeQAABAc"]
[Sun Aug 30 03:07:05.744945 2026] [proxy_http:error] [pid 499751:tid 499932] (20014)Internal error (specific information not available): [client 34.125.55.247:17124] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:05.744954 2026] [proxy:error] [pid 499751:tid 499932] [client 34.125.55.247:17124] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/.env.local
[Sun Aug 30 03:07:05.745503 2026] [security2:error] [pid 501390:tid 501603] [client 34.125.55.247:17144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/@fs/root/.aws/credentials.backup"] [unique_id "apPkqag6skwqJ2NpVh-2xgAAAmc"]
[Sun Aug 30 03:07:05.752941 2026] [proxy_http:error] [pid 499751:tid 499904] (20014)Internal error (specific information not available): [client 34.125.55.247:17194] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:05.752960 2026] [proxy:error] [pid 499751:tid 499904] [client 34.125.55.247:17194] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/home/node/.aws/credentials
[Sun Aug 30 03:07:05.759515 2026] [proxy_http:error] [pid 499751:tid 499926] (20014)Internal error (specific information not available): [client 34.125.55.247:17090] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:05.759529 2026] [proxy:error] [pid 499751:tid 499926] [client 34.125.55.247:17090] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/.env.production
[Sun Aug 30 03:07:05.767769 2026] [proxy_http:error] [pid 499751:tid 499976] (20014)Internal error (specific information not available): [client 34.125.55.247:17006] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:05.787540 2026] [authz_core:error] [pid 499145:tid 499323] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_GB
[Sun Aug 30 03:07:05.787962 2026] [authz_core:error] [pid 499145:tid 499323] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_GB
[Sun Aug 30 03:07:05.788065 2026] [security2:error] [pid 499145:tid 499402] [client 4.205.62.107:64463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/aws_credentials.php"] [unique_id "apPkqVJNq1G5uRhTNntRAgAAAH8"]
[Sun Aug 30 03:07:05.791718 2026] [security2:error] [pid 499145:tid 499322] [client 216.244.66.238:53738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arcaneguardians.com"] [uri "/joanne-linville/who-guards-the-gates-of-thebes"] [unique_id "apPkqVJNq1G5uRhTNntRBgAAAC8"]
[Sun Aug 30 03:07:05.791837 2026] [security2:error] [pid 499145:tid 499322] [client 216.244.66.238:53738] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "arcaneguardians.com"] [uri "/joanne-linville/who-guards-the-gates-of-thebes"] [unique_id "apPkqVJNq1G5uRhTNntRBgAAAC8"]
[Sun Aug 30 03:07:05.797792 2026] [security2:error] [pid 499751:tid 499944] [client 20.48.250.41:53461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/sbhu.php"] [unique_id "apPkqTmmjdkPfMeJsKPflwAAA9Q"]
[Sun Aug 30 03:07:05.805953 2026] [security2:error] [pid 499145:tid 499378] [client 20.104.50.220:27539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/2Fwp-seo.php"] [unique_id "apPkqVJNq1G5uRhTNntREwAAAGc"]
[Sun Aug 30 03:07:05.807520 2026] [security2:error] [pid 501390:tid 501545] [client 20.48.160.90:37640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp-content/uploads/indoex.php"] [unique_id "apPkqag6skwqJ2NpVh-22wAAAi0"]
[Sun Aug 30 03:07:05.824822 2026] [security2:error] [pid 499145:tid 499383] [client 20.104.50.220:63545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/here.php"] [unique_id "apPkqVJNq1G5uRhTNntRIwAAAGw"]
[Sun Aug 30 03:07:05.834856 2026] [security2:error] [pid 499751:tid 500021] [client 20.104.18.15:34745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/82.php"] [unique_id "apPkqTmmjdkPfMeJsKPfsQAABCE"]
[Sun Aug 30 03:07:05.853446 2026] [security2:error] [pid 499751:tid 499969] [client 20.196.209.81:10880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/cc.php"] [unique_id "apPkqTmmjdkPfMeJsKPfyAAAA-0"]
[Sun Aug 30 03:07:05.865282 2026] [security2:error] [pid 499145:tid 499318] [client 20.104.50.220:29619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/cakt.php"] [unique_id "apPkqVJNq1G5uRhTNntRPQAAACs"]
[Sun Aug 30 03:07:05.884478 2026] [security2:error] [pid 499751:tid 499931] [client 20.104.18.15:51586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/adminfuns.php"] [unique_id "apPkqTmmjdkPfMeJsKPf1wAAA8c"]
[Sun Aug 30 03:07:05.889906 2026] [security2:error] [pid 499751:tid 499981] [client 216.73.216.128:19732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPkqTmmjdkPfMeJsKPf3QAAA_k"]
[Sun Aug 30 03:07:05.942947 2026] [security2:error] [pid 499751:tid 499966] [client 20.48.160.90:37975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPkqTmmjdkPfMeJsKPf8QAAA-o"]
[Sun Aug 30 03:07:05.958927 2026] [security2:error] [pid 501390:tid 501553] [client 34.125.55.247:17084] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/@fs/app/rootkey.csv"] [unique_id "apPkqag6skwqJ2NpVh-2vAAAAjU"]
[Sun Aug 30 03:07:05.959110 2026] [proxy_http:error] [pid 501390:tid 501604] (20014)Internal error (specific information not available): [client 34.125.55.247:17060] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:05.959123 2026] [proxy:error] [pid 501390:tid 501604] [client 34.125.55.247:17060] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/cgi-sys/403.html
[Sun Aug 30 03:07:05.964741 2026] [security2:error] [pid 499751:tid 499904] [client 4.205.62.107:18789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/mamzi.php"] [unique_id "apPkqTmmjdkPfMeJsKPgCAAAA60"]
[Sun Aug 30 03:07:05.966988 2026] [proxy_http:error] [pid 501390:tid 501555] (20014)Internal error (specific information not available): [client 34.125.55.247:17120] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:05.967010 2026] [proxy:error] [pid 501390:tid 501555] [client 34.125.55.247:17120] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/root/.aws/credentials
[Sun Aug 30 03:07:05.975085 2026] [security2:error] [pid 501390:tid 501631] [client 34.125.55.247:17238] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/@fs/var/www/.aws/credentials"] [unique_id "apPkqag6skwqJ2NpVh-2xQAAAoM"]
[Sun Aug 30 03:07:05.975270 2026] [proxy_http:error] [pid 501390:tid 501588] (20014)Internal error (specific information not available): [client 34.125.55.247:17234] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:05.975287 2026] [proxy:error] [pid 501390:tid 501588] [client 34.125.55.247:17234] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/home/www-data/.aws/credentials
[Sun Aug 30 03:07:05.975372 2026] [security2:error] [pid 499751:tid 499974] [client 20.48.251.3:12054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/kedi.php"] [unique_id "apPkqTmmjdkPfMeJsKPgEwAAA_I"]
[Sun Aug 30 03:07:05.975825 2026] [security2:error] [pid 499145:tid 499293] [client 4.205.62.107:64041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/h.php"] [unique_id "apPkqVJNq1G5uRhTNntRggAAABI"]
[Sun Aug 30 03:07:05.979014 2026] [security2:error] [pid 501390:tid 501633] [client 20.48.250.41:53438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/a332.php"] [unique_id "apPkqag6skwqJ2NpVh-2_AAAAoU"]
[Sun Aug 30 03:07:05.983062 2026] [proxy_http:error] [pid 501390:tid 501582] (20014)Internal error (specific information not available): [client 34.125.55.247:17206] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:05.983081 2026] [proxy:error] [pid 501390:tid 501582] [client 34.125.55.247:17206] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/home/debian/.aws/credentials
[Sun Aug 30 03:07:05.990386 2026] [security2:error] [pid 501390:tid 501520] [client 34.125.55.247:17240] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/@fs/home/node/.aws/config"] [unique_id "apPkqag6skwqJ2NpVh-2ywAAAhQ"]
[Sun Aug 30 03:07:05.990505 2026] [proxy_http:error] [pid 501390:tid 501599] (20014)Internal error (specific information not available): [client 34.125.55.247:17180] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:05.990515 2026] [proxy:error] [pid 501390:tid 501599] [client 34.125.55.247:17180] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/home/ec2-user/.aws/credentials
[Sun Aug 30 03:07:05.998039 2026] [proxy_http:error] [pid 501390:tid 501561] (20014)Internal error (specific information not available): [client 34.125.55.247:17214] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:05.998051 2026] [proxy:error] [pid 501390:tid 501561] [client 34.125.55.247:17214] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/app/.aws/credentials
[Sun Aug 30 03:07:06.031711 2026] [security2:error] [pid 499751:tid 500015] [client 4.205.62.107:31695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/packed.php"] [unique_id "apPkqjmmjdkPfMeJsKPgNAAABBs"]
[Sun Aug 30 03:07:06.080054 2026] [authz_core:error] [pid 499145:tid 499283] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdpkg%2Fsh
[Sun Aug 30 03:07:06.080576 2026] [authz_core:error] [pid 499145:tid 499283] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fdpkg%2Fsh
[Sun Aug 30 03:07:06.086761 2026] [security2:error] [pid 499145:tid 499276] [client 20.48.160.90:61488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/haxor.php"] [unique_id "apPkqlJNq1G5uRhTNntRyAAAAAE"]
[Sun Aug 30 03:07:06.128754 2026] [security2:error] [pid 499751:tid 499945] [client 20.48.250.41:53386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/ws66.php"] [unique_id "apPkqjmmjdkPfMeJsKPgfQAAA9U"]
[Sun Aug 30 03:07:06.172501 2026] [authz_core:error] [pid 501390:tid 501616] [client 216.73.216.128:50828] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:06.172899 2026] [authz_core:error] [pid 501390:tid 501616] [client 216.73.216.128:50828] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:06.189941 2026] [security2:error] [pid 499751:tid 499853] [remote 51.89.83.144:62181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.83.89.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ianegenolf.michaelegenolf.com"] [uri "/assets/images/accesson.php"] [unique_id "apPkqjmmjdkPfMeJsKPgnAADxVg"]
[Sun Aug 30 03:07:06.220629 2026] [security2:error] [pid 501390:tid 501556] [client 20.48.160.90:37716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/google.php"] [unique_id "apPkqqg6skwqJ2NpVh-3QgAAAjg"]
[Sun Aug 30 03:07:06.221021 2026] [security2:error] [pid 499145:tid 499340] [client 68.155.159.216:11200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/about/function.php"] [unique_id "apPkqlJNq1G5uRhTNntSGgAAAEE"]
[Sun Aug 30 03:07:06.231412 2026] [security2:error] [pid 501390:tid 501523] [client 20.104.50.220:16716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/novax.php"] [unique_id "apPkqqg6skwqJ2NpVh-3QwAAAhc"]
[Sun Aug 30 03:07:06.234207 2026] [security2:error] [pid 501390:tid 501585] [client 4.205.62.107:2806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/filesystems.php"] [unique_id "apPkqqg6skwqJ2NpVh-3RgAAAlU"]
[Sun Aug 30 03:07:06.237486 2026] [security2:error] [pid 501390:tid 501622] [client 20.48.251.3:56362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/xda.php"] [unique_id "apPkqqg6skwqJ2NpVh-3SwAAAno"]
[Sun Aug 30 03:07:06.238404 2026] [security2:error] [pid 501390:tid 501583] [client 20.104.18.15:28618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/sf.php"] [unique_id "apPkqqg6skwqJ2NpVh-3TAAAAlM"]
[Sun Aug 30 03:07:06.238424 2026] [security2:error] [pid 501390:tid 501529] [client 4.205.62.107:5104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/old_phpinfo.php"] [unique_id "apPkqqg6skwqJ2NpVh-3TQAAAh0"]
[Sun Aug 30 03:07:06.238708 2026] [security2:error] [pid 499145:tid 499328] [client 4.205.62.107:62416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/admin.php"] [unique_id "apPkqlJNq1G5uRhTNntSKAAAADU"]
[Sun Aug 30 03:07:06.243261 2026] [security2:error] [pid 501390:tid 501578] [client 20.104.50.220:32560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/olux.php"] [unique_id "apPkqqg6skwqJ2NpVh-3UAAAAk4"]
[Sun Aug 30 03:07:06.246543 2026] [security2:error] [pid 501390:tid 501608] [client 20.104.18.15:43315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/wp-trackback.php"] [unique_id "apPkqqg6skwqJ2NpVh-3VAAAAmw"]
[Sun Aug 30 03:07:06.249137 2026] [security2:error] [pid 499145:tid 499366] [client 20.104.18.15:23535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/akismet.php"] [unique_id "apPkqlJNq1G5uRhTNntSLgAAAFs"]
[Sun Aug 30 03:07:06.253597 2026] [security2:error] [pid 499145:tid 499297] [client 20.48.251.3:4683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/queue.php"] [unique_id "apPkqlJNq1G5uRhTNntSLwAAABY"]
[Sun Aug 30 03:07:06.260380 2026] [security2:error] [pid 499751:tid 499921] [client 20.196.209.81:20294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/f35.php"] [unique_id "apPkqjmmjdkPfMeJsKPgngAAA70"]
[Sun Aug 30 03:07:06.261409 2026] [security2:error] [pid 499145:tid 499355] [client 20.104.50.220:52812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/ls.php"] [unique_id "apPkqlJNq1G5uRhTNntSOQAAAFA"]
[Sun Aug 30 03:07:06.271229 2026] [authz_core:error] [pid 499145:tid 499338] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NZ
[Sun Aug 30 03:07:06.271502 2026] [authz_core:error] [pid 499145:tid 499338] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NZ
[Sun Aug 30 03:07:06.280343 2026] [security2:error] [pid 499145:tid 499277] [client 68.155.159.216:55120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/file.php"] [unique_id "apPkqlJNq1G5uRhTNntSQgAAAAI"]
[Sun Aug 30 03:07:06.302009 2026] [security2:error] [pid 499145:tid 499323] [client 20.104.50.220:46407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-inlcudes.php"] [unique_id "apPkqlJNq1G5uRhTNntSUAAAADA"]
[Sun Aug 30 03:07:06.328768 2026] [security2:error] [pid 501390:tid 501537] [client 20.104.50.220:62002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/darkshell.php"] [unique_id "apPkqqg6skwqJ2NpVh-3cgAAAiU"]
[Sun Aug 30 03:07:06.338071 2026] [authz_core:error] [pid 501390:tid 501609] [client 66.249.66.197:62326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:06.338562 2026] [authz_core:error] [pid 501390:tid 501609] [client 66.249.66.197:62326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:06.352815 2026] [security2:error] [pid 501390:tid 501534] [client 20.151.200.44:27266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/css/000.php"] [unique_id "apPkqqg6skwqJ2NpVh-3iAAAAiI"]
[Sun Aug 30 03:07:06.359630 2026] [security2:error] [pid 501390:tid 501565] [client 20.48.160.90:37758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "apPkqqg6skwqJ2NpVh-3jAAAAkE"]
[Sun Aug 30 03:07:06.381192 2026] [security2:error] [pid 501390:tid 501633] [client 68.155.159.216:62059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPkqqg6skwqJ2NpVh-3mgAAAoU"]
[Sun Aug 30 03:07:06.405429 2026] [security2:error] [pid 501390:tid 501640] [client 20.104.50.220:5942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/gecko.php"] [unique_id "apPkqqg6skwqJ2NpVh-3swAAAow"]
[Sun Aug 30 03:07:06.429840 2026] [security2:error] [pid 501390:tid 501637] [client 20.104.18.15:13575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/132.php"] [unique_id "apPkqqg6skwqJ2NpVh-3yQAAAok"]
[Sun Aug 30 03:07:06.444442 2026] [security2:error] [pid 501390:tid 501598] [client 20.104.18.15:32976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/xmini4.php"] [unique_id "apPkqqg6skwqJ2NpVh-3zwAAAmI"]
[Sun Aug 30 03:07:06.496759 2026] [security2:error] [pid 501390:tid 501580] [client 20.48.160.90:61534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/robots.php"] [unique_id "apPkqqg6skwqJ2NpVh-38wAAAlA"]
[Sun Aug 30 03:07:06.549258 2026] [authz_core:error] [pid 499145:tid 499292] [client 66.249.66.44:43602] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:06.549541 2026] [authz_core:error] [pid 499145:tid 499292] [client 66.249.66.44:43602] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:06.550097 2026] [security2:error] [pid 499145:tid 499351] [client 20.104.50.220:32840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/FierzaXploit.php"] [unique_id "apPkqlJNq1G5uRhTNntSuAAAAEw"]
[Sun Aug 30 03:07:06.553695 2026] [security2:error] [pid 501390:tid 501542] [client 68.155.159.216:63491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-admin.php"] [unique_id "apPkqqg6skwqJ2NpVh-4GwAAAio"]
[Sun Aug 30 03:07:06.565960 2026] [authz_core:error] [pid 499145:tid 499379] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fmultipart
[Sun Aug 30 03:07:06.566256 2026] [authz_core:error] [pid 499145:tid 499379] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fmultipart
[Sun Aug 30 03:07:06.580148 2026] [security2:error] [pid 501390:tid 501546] [client 20.151.200.44:27167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/cy.php"] [unique_id "apPkqqg6skwqJ2NpVh-4KgAAAi4"]
[Sun Aug 30 03:07:06.597627 2026] [security2:error] [pid 501390:tid 501634] [client 114.119.155.121:36179] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bcwinetrends.com"] [uri "/2023/08/25/ten-bc-pinot-noir-for-under-30/"] [unique_id "apPkqqg6skwqJ2NpVh-4NAAAAoY"], referer: https://bcwinetrends.com/2023/08/25/ten-bc-pinot-noir-for-under-30/
[Sun Aug 30 03:07:06.626667 2026] [authz_core:error] [pid 499145:tid 499283] [client 216.73.216.128:41075] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:06.627104 2026] [authz_core:error] [pid 499145:tid 499283] [client 216.73.216.128:41075] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:06.628430 2026] [security2:error] [pid 501390:tid 501576] [client 20.48.160.90:61497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp-content/plugins/ccx/index.php"] [unique_id "apPkqqg6skwqJ2NpVh-4NwAAAkw"]
[Sun Aug 30 03:07:06.633944 2026] [authz_core:error] [pid 501390:tid 501647] [client 66.249.66.199:38363] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:06.634224 2026] [authz_core:error] [pid 501390:tid 501647] [client 66.249.66.199:38363] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:06.640936 2026] [security2:error] [pid 499145:tid 499401] [client 68.155.159.216:61330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-login.php"] [unique_id "apPkqlJNq1G5uRhTNntS2gAAAH4"]
[Sun Aug 30 03:07:06.658337 2026] [security2:error] [pid 501390:tid 501545] [client 20.196.209.81:20889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/classsmtps.php"] [unique_id "apPkqqg6skwqJ2NpVh-4PQAAAi0"]
[Sun Aug 30 03:07:06.693683 2026] [security2:error] [pid 501390:tid 501534] [client 4.205.62.107:65392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/wdf.php"] [unique_id "apPkqqg6skwqJ2NpVh-4TgAAAiI"]
[Sun Aug 30 03:07:06.716319 2026] [authz_core:error] [pid 501390:tid 501557] [client 216.73.216.128:24601] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:06.716544 2026] [security2:error] [pid 501390:tid 501628] [client 4.205.62.107:56584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/test1.php"] [unique_id "apPkqqg6skwqJ2NpVh-4XgAAAoA"]
[Sun Aug 30 03:07:06.716810 2026] [authz_core:error] [pid 501390:tid 501557] [client 216.73.216.128:24601] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:06.731159 2026] [authz_core:error] [pid 499145:tid 499376] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:07:06.731573 2026] [authz_core:error] [pid 499145:tid 499376] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:07:06.745677 2026] [authz_core:error] [pid 501390:tid 501630] [client 66.249.66.35:46960] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:06.745953 2026] [authz_core:error] [pid 501390:tid 501630] [client 66.249.66.35:46960] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:06.754344 2026] [authz_core:error] [pid 499145:tid 499304] [client 66.249.66.33:43843] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:06.754796 2026] [authz_core:error] [pid 499145:tid 499304] [client 66.249.66.33:43843] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:06.760932 2026] [security2:error] [pid 501390:tid 501534] [client 20.48.250.41:53441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/ws68.php"] [unique_id "apPkqqg6skwqJ2NpVh-4gAAAAiI"]
[Sun Aug 30 03:07:06.791012 2026] [security2:error] [pid 501390:tid 501580] [client 20.48.160.90:61463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp-admin/css/colors/maro.php"] [unique_id "apPkqqg6skwqJ2NpVh-4kAAAAlA"]
[Sun Aug 30 03:07:06.799721 2026] [security2:error] [pid 501390:tid 501561] [client 68.155.159.216:12304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/index/function.php"] [unique_id "apPkqqg6skwqJ2NpVh-4lAAAAj0"]
[Sun Aug 30 03:07:06.819845 2026] [security2:error] [pid 501390:tid 501547] [client 20.48.251.3:7373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/wp-blog.php"] [unique_id "apPkqqg6skwqJ2NpVh-4pAAAAi8"]
[Sun Aug 30 03:07:06.829429 2026] [security2:error] [pid 501390:tid 501602] [client 20.151.200.44:27190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/admin.php/pindex.php"] [unique_id "apPkqqg6skwqJ2NpVh-4qQAAAmY"]
[Sun Aug 30 03:07:06.842587 2026] [security2:error] [pid 501390:tid 501548] [client 20.104.18.15:29139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/ops.php"] [unique_id "apPkqqg6skwqJ2NpVh-4sgAAAjA"]
[Sun Aug 30 03:07:06.844754 2026] [authz_core:error] [pid 501390:tid 501549] [client 66.249.66.73:58783] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:06.845227 2026] [authz_core:error] [pid 501390:tid 501549] [client 66.249.66.73:58783] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:06.902700 2026] [security2:error] [pid 499145:tid 499373] [client 20.48.250.41:53503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/users.php"] [unique_id "apPkqlJNq1G5uRhTNntTLwAAAGI"]
[Sun Aug 30 03:07:06.923982 2026] [security2:error] [pid 499145:tid 499305] [client 4.205.62.107:61753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/aws-credentials.php"] [unique_id "apPkqlJNq1G5uRhTNntTNgAAAB4"]
[Sun Aug 30 03:07:06.934142 2026] [security2:error] [pid 501390:tid 501596] [client 20.48.160.90:37739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp-admin/css/colors/coffee/marijuana.php"] [unique_id "apPkqqg6skwqJ2NpVh-40QAAAmA"]
[Sun Aug 30 03:07:06.941370 2026] [security2:error] [pid 501390:tid 501562] [client 20.104.50.220:27450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/2Fwp-rocket.php"] [unique_id "apPkqqg6skwqJ2NpVh-41wAAAj4"]
[Sun Aug 30 03:07:06.975922 2026] [security2:error] [pid 501390:tid 501527] [client 20.104.18.15:34810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/dex.php"] [unique_id "apPkqqg6skwqJ2NpVh-49AAAAhs"]
[Sun Aug 30 03:07:06.987088 2026] [security2:error] [pid 501390:tid 501637] [client 20.104.50.220:42791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/hxh.php"] [unique_id "apPkqqg6skwqJ2NpVh-4_QAAAok"]
[Sun Aug 30 03:07:07.017795 2026] [security2:error] [pid 499145:tid 499325] [client 20.104.50.220:28677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/CytoXploit.php"] [unique_id "apPkq1JNq1G5uRhTNntTXgAAADI"]
[Sun Aug 30 03:07:07.020003 2026] [security2:error] [pid 501390:tid 501531] [client 20.151.200.44:27587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/admin.php/csv.php"] [unique_id "apPkq6g6skwqJ2NpVh-5DQAAAh8"]
[Sun Aug 30 03:07:07.050546 2026] [security2:error] [pid 501390:tid 501607] [client 20.48.250.41:53464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/bzjdlofz.php"] [unique_id "apPkq6g6skwqJ2NpVh-5IgAAAms"]
[Sun Aug 30 03:07:07.056332 2026] [security2:error] [pid 501390:tid 501646] [client 20.104.18.15:51596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/classwithtostring.php"] [unique_id "apPkq6g6skwqJ2NpVh-5JAAAApI"]
[Sun Aug 30 03:07:07.079425 2026] [security2:error] [pid 501390:tid 501622] [client 20.48.160.90:61532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp-admin/css/colors/coffee/mari.php"] [unique_id "apPkq6g6skwqJ2NpVh-5MgAAAno"]
[Sun Aug 30 03:07:07.079446 2026] [authz_core:error] [pid 501390:tid 501540] [client 216.73.216.128:50828] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:07.079710 2026] [authz_core:error] [pid 501390:tid 501540] [client 216.73.216.128:50828] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:07.116814 2026] [security2:error] [pid 499145:tid 499300] [client 20.48.251.3:34440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/oc460l3x.php"] [unique_id "apPkq1JNq1G5uRhTNntTiAAAABk"]
[Sun Aug 30 03:07:07.117679 2026] [security2:error] [pid 499145:tid 499338] [client 4.205.62.107:64018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/bootstrap.php"] [unique_id "apPkq1JNq1G5uRhTNntTigAAAD8"]
[Sun Aug 30 03:07:07.123102 2026] [security2:error] [pid 501390:tid 501644] [client 20.196.209.81:10927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/install.php"] [unique_id "apPkq6g6skwqJ2NpVh-5RwAAApA"]
[Sun Aug 30 03:07:07.147287 2026] [security2:error] [pid 499145:tid 499388] [client 4.205.62.107:18980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/public/rip.php.php"] [unique_id "apPkq1JNq1G5uRhTNntTmgAAAHE"]
[Sun Aug 30 03:07:07.196126 2026] [security2:error] [pid 501390:tid 501617] [client 20.48.250.41:53398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/selesai.php"] [unique_id "apPkq6g6skwqJ2NpVh-5eQAAAnU"]
[Sun Aug 30 03:07:07.226296 2026] [security2:error] [pid 499145:tid 499366] [client 20.48.160.90:61514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp-includes/images/crystal/option.php"] [unique_id "apPkq1JNq1G5uRhTNntTwQAAAFs"]
[Sun Aug 30 03:07:07.242325 2026] [authz_core:error] [pid 499145:tid 499341] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:07:07.242627 2026] [authz_core:error] [pid 499145:tid 499341] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:07:07.279445 2026] [security2:error] [pid 499145:tid 499337] [client 4.205.62.107:26793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/umgebung.php"] [unique_id "apPkq1JNq1G5uRhTNntT4gAAAD4"]
[Sun Aug 30 03:07:07.308314 2026] [authz_core:error] [pid 501390:tid 501634] [client 66.249.66.195:60350] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:07.308576 2026] [authz_core:error] [pid 501390:tid 501634] [client 66.249.66.195:60350] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:07.360114 2026] [security2:error] [pid 501390:tid 501621] [client 20.48.250.41:53477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/shlo.php"] [unique_id "apPkq6g6skwqJ2NpVh-5zwAAAnk"]
[Sun Aug 30 03:07:07.368059 2026] [security2:error] [pid 501390:tid 501545] [client 20.104.50.220:16731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/mosty.php"] [unique_id "apPkq6g6skwqJ2NpVh-51AAAAi0"]
[Sun Aug 30 03:07:07.368751 2026] [security2:error] [pid 501390:tid 501584] [client 20.104.18.15:28620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/xx.php"] [unique_id "apPkq6g6skwqJ2NpVh-51QAAAlQ"]
[Sun Aug 30 03:07:07.371299 2026] [security2:error] [pid 501390:tid 501532] [client 20.48.251.3:33320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/pinfo.php"] [unique_id "apPkq6g6skwqJ2NpVh-52AAAAiA"]
[Sun Aug 30 03:07:07.374470 2026] [security2:error] [pid 499145:tid 499279] [client 20.48.160.90:37696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp-includes/pomo/xxx.php"] [unique_id "apPkq1JNq1G5uRhTNntUEgAAAAQ"]
[Sun Aug 30 03:07:07.375542 2026] [core:error] [pid 499145:tid 499328] [client 4.205.62.107:2769] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:07:07.375567 2026] [core:error] [pid 499145:tid 499328] [client 4.205.62.107:2769] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:07:07.382450 2026] [security2:error] [pid 501390:tid 501534] [client 4.205.62.107:62324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/png.php"] [unique_id "apPkq6g6skwqJ2NpVh-53gAAAiI"]
[Sun Aug 30 03:07:07.390135 2026] [security2:error] [pid 501390:tid 501597] [client 20.104.50.220:32121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/phpinfo.php"] [unique_id "apPkq6g6skwqJ2NpVh-56gAAAmE"]
[Sun Aug 30 03:07:07.392167 2026] [security2:error] [pid 501390:tid 501569] [client 68.155.159.216:56320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apPkq6g6skwqJ2NpVh-56wAAAkU"]
[Sun Aug 30 03:07:07.396342 2026] [security2:error] [pid 501390:tid 501629] [client 20.104.18.15:23436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/ajax.php"] [unique_id "apPkq6g6skwqJ2NpVh-59QAAAoE"]
[Sun Aug 30 03:07:07.396379 2026] [security2:error] [pid 501390:tid 501554] [client 20.104.18.15:43935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/pri.php"] [unique_id "apPkq6g6skwqJ2NpVh-59gAAAjY"]
[Sun Aug 30 03:07:07.402369 2026] [authz_core:error] [pid 501390:tid 501627] [client 66.249.66.203:58039] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:07.402768 2026] [authz_core:error] [pid 501390:tid 501627] [client 66.249.66.203:58039] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:07.407442 2026] [authz_core:error] [pid 501390:tid 501567] [client 66.249.66.65:38282] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:07.407810 2026] [authz_core:error] [pid 501390:tid 501567] [client 66.249.66.65:38282] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:07.418351 2026] [security2:error] [pid 501390:tid 501521] [client 20.151.200.44:27142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/admin.php/700.php"] [unique_id "apPkq6g6skwqJ2NpVh-6CgAAAhU"]
[Sun Aug 30 03:07:07.423908 2026] [security2:error] [pid 499145:tid 499305] [client 20.48.250.41:46017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkq1JNq1G5uRhTNntUKQAAAB4"]
[Sun Aug 30 03:07:07.425669 2026] [security2:error] [pid 501390:tid 501533] [client 20.104.50.220:52832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/sym2019.php"] [unique_id "apPkq6g6skwqJ2NpVh-6EQAAAiE"]
[Sun Aug 30 03:07:07.439287 2026] [security2:error] [pid 501390:tid 501619] [client 216.73.216.128:24601] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPkq6g6skwqJ2NpVh-6FQAAAnc"]
[Sun Aug 30 03:07:07.452375 2026] [security2:error] [pid 501390:tid 501576] [client 4.205.62.107:5077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.bvacademy.org"] [uri "/wp-act.php"] [unique_id "apPkq6g6skwqJ2NpVh-6GAAAAkw"]
[Sun Aug 30 03:07:07.466727 2026] [security2:error] [pid 501390:tid 501644] [client 20.104.50.220:46207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-installer.php"] [unique_id "apPkq6g6skwqJ2NpVh-6IQAAApA"]
[Sun Aug 30 03:07:07.487601 2026] [security2:error] [pid 501390:tid 501607] [client 20.48.250.41:53446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/asax.php"] [unique_id "apPkq6g6skwqJ2NpVh-6OwAAAms"]
[Sun Aug 30 03:07:07.496488 2026] [security2:error] [pid 501390:tid 501533] [client 68.155.159.216:54269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/file17.php"] [unique_id "apPkq6g6skwqJ2NpVh-6PwAAAiE"]
[Sun Aug 30 03:07:07.506971 2026] [security2:error] [pid 501390:tid 501563] [client 20.104.50.220:61691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/gel4y.php"] [unique_id "apPkq6g6skwqJ2NpVh-6SQAAAj8"]
[Sun Aug 30 03:07:07.517228 2026] [security2:error] [pid 499145:tid 499345] [client 20.48.160.90:61538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/650.php"] [unique_id "apPkq1JNq1G5uRhTNntUUwAAAEY"]
[Sun Aug 30 03:07:07.518894 2026] [security2:error] [pid 501390:tid 501644] [client 68.155.159.216:62017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apPkq6g6skwqJ2NpVh-6TgAAApA"]
[Sun Aug 30 03:07:07.522374 2026] [authz_core:error] [pid 499145:tid 499332] [client 66.249.66.40:34951] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:07.522635 2026] [authz_core:error] [pid 499145:tid 499332] [client 66.249.66.40:34951] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:07.532230 2026] [security2:error] [pid 501390:tid 501589] [client 20.196.209.81:20341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/wp.php"] [unique_id "apPkq6g6skwqJ2NpVh-6VwAAAlk"]
[Sun Aug 30 03:07:07.543017 2026] [security2:error] [pid 501390:tid 501642] [client 20.104.50.220:5572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/andria828.php"] [unique_id "apPkq6g6skwqJ2NpVh-6XwAAAo4"]
[Sun Aug 30 03:07:07.567250 2026] [security2:error] [pid 501390:tid 501533] [client 20.48.250.41:45330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkq6g6skwqJ2NpVh-6agAAAiE"]
[Sun Aug 30 03:07:07.573699 2026] [security2:error] [pid 501390:tid 501608] [client 20.104.18.15:33757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/gulu.php"] [unique_id "apPkq6g6skwqJ2NpVh-6cAAAAmw"]
[Sun Aug 30 03:07:07.581673 2026] [security2:error] [pid 501390:tid 501573] [client 20.104.18.15:13585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/v22.php"] [unique_id "apPkq6g6skwqJ2NpVh-6fAAAAkk"]
[Sun Aug 30 03:07:07.618783 2026] [security2:error] [pid 499145:tid 499372] [client 20.48.250.41:50132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/fetch.php"] [unique_id "apPkq1JNq1G5uRhTNntUhQAAAGE"]
[Sun Aug 30 03:07:07.627432 2026] [security2:error] [pid 501390:tid 501591] [client 20.48.251.3:44333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/doc.php"] [unique_id "apPkq6g6skwqJ2NpVh-6hgAAAls"]
[Sun Aug 30 03:07:07.637968 2026] [security2:error] [pid 501390:tid 501641] [client 114.119.150.209:22433] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "upcorn.agency"] [uri "/wp-content/themes/twentytwenty/assets/images/seo/seo-hero-img.jpg"] [unique_id "apPkq6g6skwqJ2NpVh-6igAAAo0"], referer: https://upcorn.agency/en/ai-poshuk-peremanyuye-vashyh-kliyentiv/
[Sun Aug 30 03:07:07.654697 2026] [security2:error] [pid 499145:tid 499349] [client 20.48.160.90:61540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/nakrip.php"] [unique_id "apPkq1JNq1G5uRhTNntUkAAAAEo"]
[Sun Aug 30 03:07:07.679603 2026] [security2:error] [pid 501390:tid 501405] [remote 66.116.251.167:38492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.251.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "primaryenv.com"] [uri "/wp-login.php"] [unique_id "apPkq6g6skwqJ2NpVh-6jAACSA4"]
[Sun Aug 30 03:07:07.695511 2026] [security2:error] [pid 501390:tid 501523] [client 20.48.250.41:46021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/ff1.php"] [unique_id "apPkq6g6skwqJ2NpVh-6kAAAAhc"]
[Sun Aug 30 03:07:07.698300 2026] [security2:error] [pid 501390:tid 501547] [client 68.155.159.216:63543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-includes/assets/index.php"] [unique_id "apPkq6g6skwqJ2NpVh-6kwAAAi8"]
[Sun Aug 30 03:07:07.710290 2026] [security2:error] [pid 501390:tid 501618] [client 20.104.50.220:33298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/fxshell.php"] [unique_id "apPkq6g6skwqJ2NpVh-6ngAAAnY"]
[Sun Aug 30 03:07:07.723829 2026] [security2:error] [pid 501390:tid 501551] [client 216.244.66.238:53752] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arcaneguardians.com"] [uri "/tdbhc/amy%27s-kitchen-marshmallows"] [unique_id "apPkq6g6skwqJ2NpVh-6sQAAAjM"]
[Sun Aug 30 03:07:07.723893 2026] [security2:error] [pid 501390:tid 501551] [client 216.244.66.238:53752] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "arcaneguardians.com"] [uri "/tdbhc/amy%27s-kitchen-marshmallows"] [unique_id "apPkq6g6skwqJ2NpVh-6sQAAAjM"]
[Sun Aug 30 03:07:07.729682 2026] [security2:error] [pid 501390:tid 501604] [client 4.205.62.107:55249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/wp-info.php"] [unique_id "apPkq6g6skwqJ2NpVh-6tgAAAmg"]
[Sun Aug 30 03:07:07.743849 2026] [authz_core:error] [pid 499145:tid 499387] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fmultipart
[Sun Aug 30 03:07:07.744104 2026] [authz_core:error] [pid 499145:tid 499387] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fmultipart
[Sun Aug 30 03:07:07.744926 2026] [security2:error] [pid 499145:tid 499344] [client 20.48.250.41:53473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/vx.php"] [unique_id "apPkq1JNq1G5uRhTNntUuwAAAEU"]
[Sun Aug 30 03:07:07.757239 2026] [security2:error] [pid 499145:tid 499282] [client 20.104.49.130:57629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/js.php"] [unique_id "apPkq1JNq1G5uRhTNntUwwAAAAc"]
[Sun Aug 30 03:07:07.766157 2026] [security2:error] [pid 501390:tid 501407] [remote 152.53.108.193:58406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.108.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "boblivingstone.com"] [uri "/wp-login.php"] [unique_id "apPkq6g6skwqJ2NpVh-6xgACdxA"]
[Sun Aug 30 03:07:07.782670 2026] [security2:error] [pid 499145:tid 499330] [client 68.155.159.216:65471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apPkq1JNq1G5uRhTNntUzwAAADc"]
[Sun Aug 30 03:07:07.792398 2026] [authz_core:error] [pid 499145:tid 499309] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:07:07.792651 2026] [authz_core:error] [pid 499145:tid 499309] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:07:07.819292 2026] [security2:error] [pid 499145:tid 499303] [client 20.48.160.90:37955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp-includes/interactivity-api/flower.php"] [unique_id "apPkq1JNq1G5uRhTNntU3QAAABw"]
[Sun Aug 30 03:07:07.822273 2026] [authz_core:error] [pid 501390:tid 501526] [client 66.249.66.34:64566] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:07.822542 2026] [authz_core:error] [pid 501390:tid 501526] [client 66.249.66.34:64566] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:07.833955 2026] [security2:error] [pid 499145:tid 499349] [client 87.106.228.102:53530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.228.106.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "betsydunlap.com"] [uri "/wp-login.php"] [unique_id "apPkq1JNq1G5uRhTNntU3wAAAEo"]
[Sun Aug 30 03:07:07.855854 2026] [security2:error] [pid 501390:tid 501527] [client 4.205.62.107:65288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/bb.php"] [unique_id "apPkq6g6skwqJ2NpVh-68AAAAhs"]
[Sun Aug 30 03:07:07.856701 2026] [security2:error] [pid 501390:tid 501554] [client 4.205.62.107:51774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/bigdump.php"] [unique_id "apPkq6g6skwqJ2NpVh-68gAAAjY"]
[Sun Aug 30 03:07:07.868155 2026] [security2:error] [pid 501390:tid 501562] [client 20.48.250.41:45327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/t.php"] [unique_id "apPkq6g6skwqJ2NpVh-69QAAAj4"]
[Sun Aug 30 03:07:07.869640 2026] [security2:error] [pid 501390:tid 501596] [client 20.48.250.41:53460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/global.php"] [unique_id "apPkq6g6skwqJ2NpVh-69gAAAmA"]
[Sun Aug 30 03:07:07.922913 2026] [authz_core:error] [pid 501390:tid 501640] [client 66.249.66.67:45510] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:07.923342 2026] [authz_core:error] [pid 501390:tid 501640] [client 66.249.66.67:45510] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:07.924360 2026] [security2:error] [pid 499145:tid 499334] [client 20.196.209.81:20291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/error.php"] [unique_id "apPkq1JNq1G5uRhTNntU9gAAADs"]
[Sun Aug 30 03:07:07.968103 2026] [security2:error] [pid 501390:tid 501527] [client 20.48.160.90:38010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/xcc.php"] [unique_id "apPkq6g6skwqJ2NpVh-7KwAAAhs"]
[Sun Aug 30 03:07:07.983623 2026] [security2:error] [pid 501390:tid 501409] [remote 152.53.108.193:58406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.108.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "boblivingstone.com"] [uri "/wp-login.php"] [unique_id "apPkq6g6skwqJ2NpVh-7PgACjxI"], referer: https://boblivingstone.com/wp-login.php
[Sun Aug 30 03:07:08.000230 2026] [security2:error] [pid 501390:tid 501583] [client 20.48.251.3:7042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/erty.php"] [unique_id "apPkq6g6skwqJ2NpVh-7SAAAAlM"]
[Sun Aug 30 03:07:08.005856 2026] [security2:error] [pid 501390:tid 501581] [client 20.48.250.41:45317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/erty.php"] [unique_id "apPkrKg6skwqJ2NpVh-7SwAAAlE"]
[Sun Aug 30 03:07:08.006880 2026] [security2:error] [pid 501390:tid 501646] [client 20.48.250.41:53463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/fs.php"] [unique_id "apPkrKg6skwqJ2NpVh-7TAAAApI"]
[Sun Aug 30 03:07:08.013483 2026] [security2:error] [pid 499145:tid 499392] [client 20.104.18.15:29141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/BDKR28WP.php"] [unique_id "apPkrFJNq1G5uRhTNntVFAAAAHU"]
[Sun Aug 30 03:07:08.028990 2026] [security2:error] [pid 501390:tid 501551] [client 68.155.159.216:12380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/.well-known/content.php"] [unique_id "apPkrKg6skwqJ2NpVh-7WQAAAjM"]
[Sun Aug 30 03:07:08.031748 2026] [authz_core:error] [pid 499145:tid 499338] [client 66.249.66.44:43602] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:08.031995 2026] [authz_core:error] [pid 499145:tid 499338] [client 66.249.66.44:43602] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:08.062498 2026] [security2:error] [pid 501390:tid 501634] [client 4.205.62.107:64469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/4563.php"] [unique_id "apPkrKg6skwqJ2NpVh-7cwAAAoY"]
[Sun Aug 30 03:07:08.079623 2026] [security2:error] [pid 501390:tid 501533] [client 20.104.50.220:27227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/wp-admin/plugins.php"] [unique_id "apPkrKg6skwqJ2NpVh-7ewAAAiE"]
[Sun Aug 30 03:07:08.090880 2026] [authz_core:error] [pid 499145:tid 499375] [client 216.73.216.128:41075] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:08.091294 2026] [authz_core:error] [pid 499145:tid 499375] [client 216.73.216.128:41075] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:08.095857 2026] [security2:error] [pid 499145:tid 499373] [client 20.104.49.130:48011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/ccc.php"] [unique_id "apPkrFJNq1G5uRhTNntVMgAAAGI"]
[Sun Aug 30 03:07:08.102093 2026] [security2:error] [pid 501390:tid 501575] [client 20.48.160.90:37709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp-includes/Text/Diff/Engine/aaa.php"] [unique_id "apPkrKg6skwqJ2NpVh-7hgAAAks"]
[Sun Aug 30 03:07:08.126123 2026] [security2:error] [pid 501390:tid 501625] [client 20.104.18.15:34697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/inso.php"] [unique_id "apPkrKg6skwqJ2NpVh-7kQAAAn0"]
[Sun Aug 30 03:07:08.135735 2026] [security2:error] [pid 501390:tid 501557] [client 20.104.50.220:63507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/FX.php"] [unique_id "apPkrKg6skwqJ2NpVh-7lwAAAjk"]
[Sun Aug 30 03:07:08.144168 2026] [security2:error] [pid 501390:tid 501619] [client 20.48.250.41:45369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/0x.php"] [unique_id "apPkrKg6skwqJ2NpVh-7nAAAAnc"]
[Sun Aug 30 03:07:08.169311 2026] [security2:error] [pid 501390:tid 501628] [client 20.104.50.220:29585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/ccc.php"] [unique_id "apPkrKg6skwqJ2NpVh-7sQAAAoA"]
[Sun Aug 30 03:07:08.170045 2026] [security2:error] [pid 501390:tid 501602] [client 20.48.250.41:53471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/ioxi.php"] [unique_id "apPkrKg6skwqJ2NpVh-7sgAAAmY"]
[Sun Aug 30 03:07:08.221986 2026] [security2:error] [pid 501390:tid 501598] [client 20.104.18.15:51656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPkrKg6skwqJ2NpVh-72AAAAmI"]
[Sun Aug 30 03:07:08.232362 2026] [security2:error] [pid 501390:tid 501558] [client 20.48.160.90:38004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp-includes/style-engine/gecko-new.php"] [unique_id "apPkrKg6skwqJ2NpVh-73QAAAjo"]
[Sun Aug 30 03:07:08.252012 2026] [security2:error] [pid 501390:tid 501560] [client 20.48.251.3:34442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/drykl.php"] [unique_id "apPkrKg6skwqJ2NpVh-77gAAAjw"]
[Sun Aug 30 03:07:08.252634 2026] [security2:error] [pid 501390:tid 501560] [client 4.205.62.107:63958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/333.php"] [unique_id "apPkrKg6skwqJ2NpVh-77wAAAjw"]
[Sun Aug 30 03:07:08.269558 2026] [authz_core:error] [pid 499145:tid 499376] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:07:08.269853 2026] [authz_core:error] [pid 499145:tid 499376] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:07:08.270488 2026] [authz_core:error] [pid 501390:tid 501624] [client 216.73.216.128:50828] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:08.271030 2026] [authz_core:error] [pid 501390:tid 501624] [client 216.73.216.128:50828] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:08.271325 2026] [security2:error] [pid 501390:tid 501590] [client 20.48.250.41:45326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/66.php"] [unique_id "apPkrKg6skwqJ2NpVh-7-wAAAlo"]
[Sun Aug 30 03:07:08.274009 2026] [security2:error] [pid 501390:tid 501638] [client 20.151.200.44:27272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/admin.php/007x.php"] [unique_id "apPkrKg6skwqJ2NpVh-7_wAAAoo"]
[Sun Aug 30 03:07:08.286718 2026] [security2:error] [pid 501390:tid 501538] [client 4.205.62.107:18995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/environment.php"] [unique_id "apPkrKg6skwqJ2NpVh-8BgAAAiY"]
[Sun Aug 30 03:07:08.316557 2026] [security2:error] [pid 501390:tid 501582] [client 20.48.250.41:53440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/bootstrap.php"] [unique_id "apPkrKg6skwqJ2NpVh-8GwAAAlI"]
[Sun Aug 30 03:07:08.322686 2026] [security2:error] [pid 501390:tid 501616] [client 34.125.55.247:17252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.engaginggoddaily.com"] [uri "/@fs/root/.aws/sso/cache/"] [unique_id "apPkrKg6skwqJ2NpVh-8IwAAAnQ"]
[Sun Aug 30 03:07:08.323109 2026] [security2:error] [pid 501390:tid 501606] [client 34.125.55.247:17296] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.engaginggoddaily.com"] [uri "/@fs/usr/src/app/.env"] [unique_id "apPkrKg6skwqJ2NpVh-8JAAAAmo"]
[Sun Aug 30 03:07:08.328418 2026] [security2:error] [pid 501390:tid 501599] [client 34.125.55.247:17268] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/@fs/var/www/.env"] [unique_id "apPkrKg6skwqJ2NpVh-8KAAAAmM"]
[Sun Aug 30 03:07:08.328761 2026] [security2:error] [pid 501390:tid 501583] [client 34.125.55.247:17258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/@fs/home/ubuntu/.env"] [unique_id "apPkrKg6skwqJ2NpVh-8KwAAAlM"]
[Sun Aug 30 03:07:08.329361 2026] [security2:error] [pid 501390:tid 501646] [client 34.125.55.247:17284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/@fs/var/www/html/.env"] [unique_id "apPkrKg6skwqJ2NpVh-8LAAAApI"]
[Sun Aug 30 03:07:08.336319 2026] [proxy_http:error] [pid 501390:tid 501618] (20014)Internal error (specific information not available): [client 34.125.55.247:17322] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:08.336333 2026] [proxy:error] [pid 501390:tid 501618] [client 34.125.55.247:17322] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/root/terraform.tfstate
[Sun Aug 30 03:07:08.339422 2026] [security2:error] [pid 501390:tid 501560] [client 34.125.55.247:17334] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.engaginggoddaily.com"] [uri "/@fs/app/.serverless/serverless-state.json"] [unique_id "apPkrKg6skwqJ2NpVh-8OAAAAjw"]
[Sun Aug 30 03:07:08.344482 2026] [proxy_http:error] [pid 501390:tid 501590] (20014)Internal error (specific information not available): [client 34.125.55.247:17248] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:08.351692 2026] [proxy_http:error] [pid 501390:tid 501618] (20014)Internal error (specific information not available): [client 34.125.55.247:17322] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:08.351711 2026] [proxy:error] [pid 501390:tid 501618] [client 34.125.55.247:17322] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml
[Sun Aug 30 03:07:08.359893 2026] [proxy_http:error] [pid 501390:tid 501538] (20014)Internal error (specific information not available): [client 34.125.55.247:17268] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:08.364210 2026] [security2:error] [pid 501390:tid 501606] [client 20.48.160.90:37740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp-settings.php"] [unique_id "apPkrKg6skwqJ2NpVh-8UwAAAmo"]
[Sun Aug 30 03:07:08.367489 2026] [proxy_http:error] [pid 501390:tid 501600] (20014)Internal error (specific information not available): [client 34.125.55.247:17258] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:08.375436 2026] [proxy_http:error] [pid 501390:tid 501637] (20014)Internal error (specific information not available): [client 34.125.55.247:17264] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:08.385186 2026] [proxy_http:error] [pid 501390:tid 501544] (20014)Internal error (specific information not available): [client 34.125.55.247:17284] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:08.389870 2026] [security2:error] [pid 501390:tid 501534] [client 20.196.209.81:10891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/profile.php"] [unique_id "apPkrKg6skwqJ2NpVh-8XwAAAiI"]
[Sun Aug 30 03:07:08.403565 2026] [proxy_http:error] [pid 501390:tid 501581] (20014)Internal error (specific information not available): [client 34.125.55.247:17332] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:08.406276 2026] [security2:error] [pid 501390:tid 501623] [client 20.48.250.41:46021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/f35.php"] [unique_id "apPkrKg6skwqJ2NpVh-8fAAAAns"]
[Sun Aug 30 03:07:08.466072 2026] [security2:error] [pid 499145:tid 499320] [client 20.48.250.41:53414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/export.php"] [unique_id "apPkrFJNq1G5uRhTNntVzQAAAC0"]
[Sun Aug 30 03:07:08.477708 2026] [security2:error] [pid 501390:tid 501631] [client 20.104.18.15:18371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkrKg6skwqJ2NpVh-8twAAAoM"]
[Sun Aug 30 03:07:08.505649 2026] [security2:error] [pid 501390:tid 501591] [client 20.48.160.90:61490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp-signup.php"] [unique_id "apPkrKg6skwqJ2NpVh-8ygAAAls"]
[Sun Aug 30 03:07:08.506514 2026] [security2:error] [pid 499145:tid 499355] [client 20.48.251.3:33318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/X57.php"] [unique_id "apPkrFJNq1G5uRhTNntV4gAAAFA"]
[Sun Aug 30 03:07:08.509259 2026] [security2:error] [pid 499145:tid 499391] [client 20.104.50.220:16765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/dejavu.php"] [unique_id "apPkrFJNq1G5uRhTNntV4wAAAHQ"]
[Sun Aug 30 03:07:08.512141 2026] [security2:error] [pid 499145:tid 499357] [client 4.205.62.107:2985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/tax.php"] [unique_id "apPkrFJNq1G5uRhTNntV5QAAAFI"]
[Sun Aug 30 03:07:08.514878 2026] [security2:error] [pid 499145:tid 499372] [client 68.155.159.216:56377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-admin/index.php"] [unique_id "apPkrFJNq1G5uRhTNntV6QAAAGE"]
[Sun Aug 30 03:07:08.528309 2026] [security2:error] [pid 501390:tid 501623] [client 20.104.18.15:28575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/uwu.php"] [unique_id "apPkrKg6skwqJ2NpVh-80wAAAns"]
[Sun Aug 30 03:07:08.533763 2026] [security2:error] [pid 501390:tid 501600] [client 20.104.50.220:32289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/postfs.php"] [unique_id "apPkrKg6skwqJ2NpVh-82gAAAmQ"]
[Sun Aug 30 03:07:08.536268 2026] [security2:error] [pid 501390:tid 501539] [client 114.119.158.142:23363] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tapcool.com"] [uri "/tag/brand-strategy/"] [unique_id "apPkrKg6skwqJ2NpVh-83AAAAic"], referer: http://tapcool.com/
[Sun Aug 30 03:07:08.537781 2026] [security2:error] [pid 501390:tid 501535] [client 4.205.62.107:22960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/chosen.php"] [unique_id "apPkrKg6skwqJ2NpVh-83QAAAiM"]
[Sun Aug 30 03:07:08.554953 2026] [security2:error] [pid 499145:tid 499275] [client 20.48.250.41:46078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/wen.php"] [unique_id "apPkrFJNq1G5uRhTNntV_wAAAAA"]
[Sun Aug 30 03:07:08.564799 2026] [security2:error] [pid 501390:tid 501559] [client 20.104.18.15:23542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/atomlib.php"] [unique_id "apPkrKg6skwqJ2NpVh-86AAAAjs"]
[Sun Aug 30 03:07:08.566156 2026] [security2:error] [pid 501390:tid 501606] [client 20.104.18.15:43976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/wp_blog_footer.php"] [unique_id "apPkrKg6skwqJ2NpVh-86gAAAmo"]
[Sun Aug 30 03:07:08.584204 2026] [security2:error] [pid 501390:tid 501579] [client 20.104.50.220:28681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/cc.php"] [unique_id "apPkrKg6skwqJ2NpVh-89QAAAk8"]
[Sun Aug 30 03:07:08.605621 2026] [security2:error] [pid 501390:tid 501552] [client 68.155.159.216:55130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/file5.php"] [unique_id "apPkrKg6skwqJ2NpVh-8_QAAAjQ"]
[Sun Aug 30 03:07:08.605782 2026] [security2:error] [pid 501390:tid 501525] [client 20.104.50.220:46440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-js.php"] [unique_id "apPkrKg6skwqJ2NpVh-8_gAAAhk"]
[Sun Aug 30 03:07:08.628152 2026] [authz_core:error] [pid 499145:tid 499279] [client 66.249.66.71:65293] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:08.628490 2026] [authz_core:error] [pid 499145:tid 499279] [client 66.249.66.71:65293] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:08.630984 2026] [security2:error] [pid 501390:tid 501623] [client 20.48.250.41:53431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/gk.php"] [unique_id "apPkrKg6skwqJ2NpVh-9BQAAAns"]
[Sun Aug 30 03:07:08.637072 2026] [security2:error] [pid 501390:tid 501415] [remote 51.89.83.144:17576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.83.89.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ianegenolf.michaelegenolf.com"] [uri "/images/images/cache.php"] [unique_id "apPkrKg6skwqJ2NpVh-9CgACdRg"]
[Sun Aug 30 03:07:08.649748 2026] [security2:error] [pid 501390:tid 501539] [client 20.48.160.90:61549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp-conffg.php"] [unique_id "apPkrKg6skwqJ2NpVh-9DAAAAic"]
[Sun Aug 30 03:07:08.651181 2026] [authz_core:error] [pid 501390:tid 501522] [client 216.73.216.128:24601] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:08.651472 2026] [authz_core:error] [pid 501390:tid 501522] [client 216.73.216.128:24601] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:08.679062 2026] [security2:error] [pid 499145:tid 499352] [client 20.104.50.220:61979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/contacts.php"] [unique_id "apPkrFJNq1G5uRhTNntWMQAAAE0"]
[Sun Aug 30 03:07:08.682415 2026] [security2:error] [pid 501390:tid 501624] [client 20.104.50.220:6112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/botol.php"] [unique_id "apPkrKg6skwqJ2NpVh-9FAAAAnw"]
[Sun Aug 30 03:07:08.690787 2026] [security2:error] [pid 501390:tid 501555] [client 20.48.250.41:45332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/inc.php"] [unique_id "apPkrKg6skwqJ2NpVh-9GAAAAjc"]
[Sun Aug 30 03:07:08.716796 2026] [authz_core:error] [pid 499145:tid 499337] [client 66.249.66.68:62777] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:08.717124 2026] [authz_core:error] [pid 499145:tid 499337] [client 66.249.66.68:62777] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:08.726798 2026] [authz_core:error] [pid 501390:tid 501524] [client 66.249.66.197:48560] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:08.727250 2026] [authz_core:error] [pid 501390:tid 501524] [client 66.249.66.197:48560] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:08.730640 2026] [security2:error] [pid 501390:tid 501630] [client 20.104.18.15:14306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/wp-activate.php"] [unique_id "apPkrKg6skwqJ2NpVh-9PQAAAoI"]
[Sun Aug 30 03:07:08.735298 2026] [security2:error] [pid 501390:tid 501600] [client 20.104.18.15:33783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/replace.php"] [unique_id "apPkrKg6skwqJ2NpVh-9QQAAAmQ"]
[Sun Aug 30 03:07:08.737427 2026] [lsapi:error] [pid 499145:tid 499152] [remote 27.114.174.245:58471] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:07:08.737539 2026] [lsapi:error] [pid 499145:tid 499152] [remote 27.114.174.245:58471] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:07:08.738966 2026] [lsapi:error] [pid 499145:tid 499152] [remote 27.114.174.245:58471] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:07:08.757804 2026] [security2:error] [pid 501390:tid 501638] [client 68.155.159.216:61382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-content/radio.php"] [unique_id "apPkrKg6skwqJ2NpVh-9RgAAAoo"]
[Sun Aug 30 03:07:08.764584 2026] [security2:error] [pid 501390:tid 501616] [client 20.48.251.3:4692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/css.php"] [unique_id "apPkrKg6skwqJ2NpVh-9SQAAAnQ"]
[Sun Aug 30 03:07:08.771331 2026] [authz_core:error] [pid 499145:tid 499314] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:07:08.771590 2026] [authz_core:error] [pid 499145:tid 499314] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:07:08.783459 2026] [security2:error] [pid 501390:tid 501543] [client 20.48.160.90:37969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp-validate.php"] [unique_id "apPkrKg6skwqJ2NpVh-9WAAAAis"]
[Sun Aug 30 03:07:08.795699 2026] [security2:error] [pid 501390:tid 501556] [client 20.48.250.41:50153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/logs1.php"] [unique_id "apPkrKg6skwqJ2NpVh-9XwAAAjg"]
[Sun Aug 30 03:07:08.814084 2026] [security2:error] [pid 501390:tid 501577] [client 20.196.209.81:20896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/sql.php"] [unique_id "apPkrKg6skwqJ2NpVh-9bwAAAk0"]
[Sun Aug 30 03:07:08.827849 2026] [security2:error] [pid 501390:tid 501569] [client 20.48.250.41:45336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/6bcwiqwj.php"] [unique_id "apPkrKg6skwqJ2NpVh-9egAAAkU"]
[Sun Aug 30 03:07:08.847243 2026] [security2:error] [pid 501390:tid 501541] [client 20.104.50.220:32874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/fk.php7"] [unique_id "apPkrKg6skwqJ2NpVh-9hwAAAik"]
[Sun Aug 30 03:07:08.892336 2026] [security2:error] [pid 499145:tid 499370] [client 68.155.159.216:63525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/lock.php"] [unique_id "apPkrFJNq1G5uRhTNntWcAAAAF8"]
[Sun Aug 30 03:07:08.921267 2026] [security2:error] [pid 501390:tid 501588] [client 20.48.160.90:61524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/700.php"] [unique_id "apPkrKg6skwqJ2NpVh-9pgAAAlg"]
[Sun Aug 30 03:07:08.937181 2026] [security2:error] [pid 501390:tid 501638] [client 20.48.250.41:53478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/inege.php"] [unique_id "apPkrKg6skwqJ2NpVh-9qgAAAoo"]
[Sun Aug 30 03:07:08.942770 2026] [security2:error] [pid 501390:tid 501625] [client 4.205.62.107:27303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/old_phpinfo.php"] [unique_id "apPkrKg6skwqJ2NpVh-9qwAAAn0"]
[Sun Aug 30 03:07:08.956632 2026] [security2:error] [pid 501390:tid 501623] [client 20.48.250.41:45354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/easy.php"] [unique_id "apPkrKg6skwqJ2NpVh-9tQAAAns"]
[Sun Aug 30 03:07:08.972787 2026] [security2:error] [pid 501390:tid 501606] [client 68.155.159.216:64810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-admin/images/about.php"] [unique_id "apPkrKg6skwqJ2NpVh-9yQAAAmo"]
[Sun Aug 30 03:07:08.991293 2026] [security2:error] [pid 501390:tid 501560] [client 4.205.62.107:56902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/wdf.php"] [unique_id "apPkrKg6skwqJ2NpVh-91AAAAjw"]
[Sun Aug 30 03:07:08.996346 2026] [security2:error] [pid 501390:tid 501584] [client 47.128.96.11:39690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "michaelegenolf.com"] [uri "/robots.txt"] [unique_id "apPkrKg6skwqJ2NpVh-91gAAAlQ"]
[Sun Aug 30 03:07:09.006358 2026] [security2:error] [pid 501390:tid 501626] [client 4.205.62.107:65321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/file59.php"] [unique_id "apPkrag6skwqJ2NpVh-92gAAAn4"]
[Sun Aug 30 03:07:09.058550 2026] [security2:error] [pid 501390:tid 501543] [client 20.151.200.44:27294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/admin.php/heex.php"] [unique_id "apPkrag6skwqJ2NpVh-9_wAAAis"]
[Sun Aug 30 03:07:09.070066 2026] [security2:error] [pid 499145:tid 499306] [client 20.48.160.90:61495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/c4.php"] [unique_id "apPkrVJNq1G5uRhTNntWtQAAAB8"]
[Sun Aug 30 03:07:09.086620 2026] [security2:error] [pid 501390:tid 501580] [client 20.48.250.41:53452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/wp-link10.php"] [unique_id "apPkrag6skwqJ2NpVh--CgAAAlA"]
[Sun Aug 30 03:07:09.088039 2026] [security2:error] [pid 501390:tid 501643] [client 20.151.200.44:55715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/txets.php"] [unique_id "apPkrag6skwqJ2NpVh--DAAAAo8"]
[Sun Aug 30 03:07:09.112535 2026] [security2:error] [pid 499145:tid 499358] [client 20.48.250.41:45374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/fresh3.php"] [unique_id "apPkrVJNq1G5uRhTNntWwgAAAFM"]
[Sun Aug 30 03:07:09.142758 2026] [authz_core:error] [pid 501390:tid 501638] [client 66.249.66.198:47489] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:09.143030 2026] [authz_core:error] [pid 501390:tid 501638] [client 66.249.66.198:47489] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:09.166062 2026] [security2:error] [pid 501390:tid 501589] [client 20.104.18.15:29124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/k.php"] [unique_id "apPkrag6skwqJ2NpVh--MQAAAlk"]
[Sun Aug 30 03:07:09.184086 2026] [security2:error] [pid 501390:tid 501535] [client 68.155.159.216:12288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/cong.php"] [unique_id "apPkrag6skwqJ2NpVh--PgAAAiM"]
[Sun Aug 30 03:07:09.197278 2026] [authz_core:error] [pid 499145:tid 499336] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fmultipart
[Sun Aug 30 03:07:09.197583 2026] [authz_core:error] [pid 499145:tid 499336] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fmultipart
[Sun Aug 30 03:07:09.200233 2026] [security2:error] [pid 501390:tid 501573] [client 4.205.62.107:64501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/cp2.php"] [unique_id "apPkrag6skwqJ2NpVh--QwAAAkk"]
[Sun Aug 30 03:07:09.205872 2026] [security2:error] [pid 501390:tid 501594] [client 20.48.160.90:61519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp-tymanage.php"] [unique_id "apPkrag6skwqJ2NpVh--RQAAAl4"]
[Sun Aug 30 03:07:09.209387 2026] [security2:error] [pid 501390:tid 501584] [client 20.196.209.81:20327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/index.bak.php"] [unique_id "apPkrag6skwqJ2NpVh--RgAAAlQ"]
[Sun Aug 30 03:07:09.215571 2026] [security2:error] [pid 501390:tid 501586] [client 20.104.50.220:27210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/wp-admin/post.php"] [unique_id "apPkrag6skwqJ2NpVh--SwAAAlY"]
[Sun Aug 30 03:07:09.215956 2026] [security2:error] [pid 501390:tid 501602] [client 20.48.251.3:7022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/wp-config.backup.php"] [unique_id "apPkrag6skwqJ2NpVh--TAAAAmY"]
[Sun Aug 30 03:07:09.219196 2026] [security2:error] [pid 501390:tid 501531] [client 20.48.250.41:53502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/ww.php"] [unique_id "apPkrag6skwqJ2NpVh--TQAAAh8"]
[Sun Aug 30 03:07:09.239085 2026] [security2:error] [pid 501390:tid 501583] [client 20.48.250.41:45349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/bgymj.php"] [unique_id "apPkrag6skwqJ2NpVh--YQAAAlM"]
[Sun Aug 30 03:07:09.254421 2026] [authz_core:error] [pid 499145:tid 499377] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:07:09.254686 2026] [authz_core:error] [pid 499145:tid 499377] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:07:09.270307 2026] [security2:error] [pid 501390:tid 501565] [client 20.104.50.220:42794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/ga.php"] [unique_id "apPkrag6skwqJ2NpVh--ggAAAkE"]
[Sun Aug 30 03:07:09.291538 2026] [security2:error] [pid 501390:tid 501603] [client 20.104.18.15:34785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/aa.php"] [unique_id "apPkrag6skwqJ2NpVh--kgAAAmc"]
[Sun Aug 30 03:07:09.306040 2026] [security2:error] [pid 501390:tid 501598] [client 20.196.209.81:5727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/data.php"] [unique_id "apPkrag6skwqJ2NpVh--pwAAAmI"]
[Sun Aug 30 03:07:09.330590 2026] [security2:error] [pid 501390:tid 501612] [client 20.104.50.220:29335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/cxc.php"] [unique_id "apPkrag6skwqJ2NpVh--vQAAAnA"]
[Sun Aug 30 03:07:09.332942 2026] [security2:error] [pid 501390:tid 501522] [client 20.48.160.90:37974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/ajfto.php"] [unique_id "apPkrag6skwqJ2NpVh--wgAAAhY"]
[Sun Aug 30 03:07:09.359032 2026] [authz_core:error] [pid 501390:tid 501539] [client 66.249.66.35:41227] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:09.359319 2026] [authz_core:error] [pid 501390:tid 501539] [client 66.249.66.35:41227] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:09.362085 2026] [security2:error] [pid 501390:tid 501602] [client 20.48.250.41:50120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/w1px.php"] [unique_id "apPkrag6skwqJ2NpVh--1gAAAmY"]
[Sun Aug 30 03:07:09.373848 2026] [security2:error] [pid 501390:tid 501520] [client 216.73.216.128:24601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPkrag6skwqJ2NpVh--3QAAAhQ"]
[Sun Aug 30 03:07:09.375801 2026] [security2:error] [pid 501390:tid 501631] [client 20.104.18.15:52183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPkrag6skwqJ2NpVh--4QAAAoM"]
[Sun Aug 30 03:07:09.392359 2026] [security2:error] [pid 501390:tid 501642] [client 4.205.62.107:63981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/G-in.php"] [unique_id "apPkrag6skwqJ2NpVh--7wAAAo4"]
[Sun Aug 30 03:07:09.394285 2026] [security2:error] [pid 501390:tid 501593] [client 20.48.250.41:45355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/ws69.php"] [unique_id "apPkrag6skwqJ2NpVh--9AAAAl0"]
[Sun Aug 30 03:07:09.405137 2026] [security2:error] [pid 501390:tid 501624] [client 20.48.251.3:50043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/rpk.php"] [unique_id "apPkrag6skwqJ2NpVh---gAAAnw"]
[Sun Aug 30 03:07:09.427959 2026] [security2:error] [pid 501390:tid 501576] [client 4.205.62.107:18953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/aws_secret_config.php"] [unique_id "apPkrag6skwqJ2NpVh-_GgAAAkw"]
[Sun Aug 30 03:07:09.443719 2026] [security2:error] [pid 501390:tid 501635] [client 20.196.209.81:5751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/dt-the7/css/static-less/plugins/admin.php"] [unique_id "apPkrag6skwqJ2NpVh-_IAAAAoc"]
[Sun Aug 30 03:07:09.467153 2026] [security2:error] [pid 501390:tid 501534] [client 20.48.160.90:61493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp_KwIW0U5F.php"] [unique_id "apPkrag6skwqJ2NpVh-_MQAAAiI"]
[Sun Aug 30 03:07:09.488495 2026] [security2:error] [pid 501390:tid 501592] [client 20.48.250.41:53487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/to.php"] [unique_id "apPkrag6skwqJ2NpVh-_UAAAAlw"]
[Sun Aug 30 03:07:09.505909 2026] [authz_core:error] [pid 501390:tid 501586] [client 66.249.66.43:49722] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:09.506175 2026] [authz_core:error] [pid 501390:tid 501586] [client 66.249.66.43:49722] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:09.520933 2026] [security2:error] [pid 501390:tid 501603] [client 20.151.200.44:27154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/tf.php"] [unique_id "apPkrag6skwqJ2NpVh-_ZgAAAmc"]
[Sun Aug 30 03:07:09.546594 2026] [security2:error] [pid 499145:tid 499376] [client 20.48.250.41:45341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/ccs.php"] [unique_id "apPkrVJNq1G5uRhTNntXdQAAAGU"]
[Sun Aug 30 03:07:09.586042 2026] [security2:error] [pid 501390:tid 501602] [client 4.205.62.107:32508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/fns.php"] [unique_id "apPkrag6skwqJ2NpVh-_jQAAAmY"]
[Sun Aug 30 03:07:09.602033 2026] [security2:error] [pid 501390:tid 501554] [client 20.48.160.90:37755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp_xiPu52Ut.php"] [unique_id "apPkrag6skwqJ2NpVh-_kwAAAjY"]
[Sun Aug 30 03:07:09.606830 2026] [security2:error] [pid 501390:tid 501555] [client 20.196.209.81:20302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/log.php"] [unique_id "apPkrag6skwqJ2NpVh-_lgAAAjc"]
[Sun Aug 30 03:07:09.615291 2026] [authz_core:error] [pid 501390:tid 501596] [client 66.249.66.72:50958] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:09.615738 2026] [authz_core:error] [pid 501390:tid 501596] [client 66.249.66.72:50958] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:09.621904 2026] [security2:error] [pid 501390:tid 501549] [client 20.104.18.15:18411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkrag6skwqJ2NpVh-_nAAAAjE"]
[Sun Aug 30 03:07:09.624196 2026] [security2:error] [pid 499145:tid 499301] [client 68.155.159.216:56336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPkrVJNq1G5uRhTNntXmQAAABo"]
[Sun Aug 30 03:07:09.646482 2026] [security2:error] [pid 501390:tid 501525] [client 20.48.250.41:53470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/thui.php"] [unique_id "apPkrag6skwqJ2NpVh-_nQAAAhk"]
[Sun Aug 30 03:07:09.648388 2026] [security2:error] [pid 499145:tid 499352] [client 20.104.50.220:17257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/aaf.php"] [unique_id "apPkrVJNq1G5uRhTNntXngAAAE0"]
[Sun Aug 30 03:07:09.661743 2026] [security2:error] [pid 499145:tid 499329] [client 20.104.18.15:28642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/signon.php"] [unique_id "apPkrVJNq1G5uRhTNntXpgAAADY"]
[Sun Aug 30 03:07:09.664445 2026] [security2:error] [pid 501390:tid 501640] [client 4.205.62.107:2761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPkrag6skwqJ2NpVh-_oAAAAow"]
[Sun Aug 30 03:07:09.680856 2026] [security2:error] [pid 501390:tid 501583] [client 20.48.250.41:46036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/mar.php"] [unique_id "apPkrag6skwqJ2NpVh-_pgAAAlM"]
[Sun Aug 30 03:07:09.687868 2026] [security2:error] [pid 499145:tid 499400] [client 20.104.50.220:31856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/pref.php"] [unique_id "apPkrVJNq1G5uRhTNntXrgAAAH0"]
[Sun Aug 30 03:07:09.690686 2026] [security2:error] [pid 499145:tid 499283] [client 4.205.62.107:22566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/admin-ajax.php"] [unique_id "apPkrVJNq1G5uRhTNntXsAAAAAg"]
[Sun Aug 30 03:07:09.693408 2026] [security2:error] [pid 501390:tid 501630] [client 20.48.251.3:33287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/register.php"] [unique_id "apPkrag6skwqJ2NpVh-_pQAAAoI"]
[Sun Aug 30 03:07:09.711596 2026] [security2:error] [pid 501390:tid 501593] [client 20.104.18.15:23488] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/1.php"] [unique_id "apPkrag6skwqJ2NpVh-_tgAAAl0"]
[Sun Aug 30 03:07:09.711714 2026] [security2:error] [pid 501390:tid 501593] [client 20.104.18.15:23488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/1.php"] [unique_id "apPkrag6skwqJ2NpVh-_tgAAAl0"]
[Sun Aug 30 03:07:09.711823 2026] [security2:error] [pid 501390:tid 501552] [client 20.104.18.15:43904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/sushi.php"] [unique_id "apPkrag6skwqJ2NpVh-_twAAAjQ"]
[Sun Aug 30 03:07:09.715780 2026] [security2:error] [pid 501390:tid 501634] [client 68.155.159.216:54219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/file88.php"] [unique_id "apPkrag6skwqJ2NpVh-_vAAAAoY"]
[Sun Aug 30 03:07:09.721753 2026] [security2:error] [pid 501390:tid 501628] [client 114.119.153.247:25561] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "markblome.com"] [uri "/"] [unique_id "apPkrag6skwqJ2NpVh-_xwAAAoA"], referer: https://markblome.com/
[Sun Aug 30 03:07:09.737810 2026] [security2:error] [pid 499145:tid 499373] [client 20.48.160.90:61547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp_n5VD7XDh.php"] [unique_id "apPkrVJNq1G5uRhTNntXzgAAAGI"]
[Sun Aug 30 03:07:09.738003 2026] [security2:error] [pid 499145:tid 499398] [client 20.104.50.220:63045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/45.php"] [unique_id "apPkrVJNq1G5uRhTNntXzwAAAHs"]
[Sun Aug 30 03:07:09.748248 2026] [security2:error] [pid 499145:tid 499276] [client 20.104.49.130:52509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/js.php"] [unique_id "apPkrVJNq1G5uRhTNntX0gAAAAE"]
[Sun Aug 30 03:07:09.757914 2026] [security2:error] [pid 499145:tid 499314] [client 20.104.50.220:46883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-mails.php"] [unique_id "apPkrVJNq1G5uRhTNntX1AAAACc"]
[Sun Aug 30 03:07:09.771894 2026] [authz_core:error] [pid 499145:tid 499366] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:07:09.772168 2026] [authz_core:error] [pid 499145:tid 499366] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:07:09.834356 2026] [security2:error] [pid 501390:tid 501535] [client 20.48.250.41:46029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/ccu.php"] [unique_id "apPkrag6skwqJ2NpVh-_-QAAAiM"]
[Sun Aug 30 03:07:09.836913 2026] [security2:error] [pid 501390:tid 501533] [client 20.104.50.220:5460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/amya985.php"] [unique_id "apPkrag6skwqJ2NpVh-__AAAAiE"]
[Sun Aug 30 03:07:09.840309 2026] [security2:error] [pid 499145:tid 499275] [client 20.196.209.81:5697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/hideo/network.php"] [unique_id "apPkrVJNq1G5uRhTNntYAgAAAAA"]
[Sun Aug 30 03:07:09.852076 2026] [security2:error] [pid 499145:tid 499300] [client 20.48.250.41:53479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/Jcrop.php"] [unique_id "apPkrVJNq1G5uRhTNntYCgAAABk"]
[Sun Aug 30 03:07:09.865606 2026] [security2:error] [pid 499145:tid 499311] [client 20.104.18.15:32979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/c4.php"] [unique_id "apPkrVJNq1G5uRhTNntYEAAAACQ"]
[Sun Aug 30 03:07:09.868913 2026] [security2:error] [pid 501390:tid 501549] [client 20.104.50.220:61965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/yo.php"] [unique_id "apPkrag6skwqJ2NpVh_ACAAAAjE"]
[Sun Aug 30 03:07:09.872310 2026] [security2:error] [pid 499145:tid 499399] [client 20.104.18.15:13728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/wp-trackback.php"] [unique_id "apPkrVJNq1G5uRhTNntYFQAAAHw"]
[Sun Aug 30 03:07:09.889082 2026] [rewrite:warn] [pid 501390:tid 501426] AH00665: RewriteCond: NoCase option for non-regex pattern '-d' is not supported and will be ignored. (/home3/keilan/public_html/.htaccess:12)
[Sun Aug 30 03:07:09.889100 2026] [rewrite:warn] [pid 501390:tid 501426] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home3/keilan/public_html/.htaccess:13)
[Sun Aug 30 03:07:09.903941 2026] [security2:error] [pid 499145:tid 499287] [client 20.48.251.3:5088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/php_info.php"] [unique_id "apPkrVJNq1G5uRhTNntYIgAAAAw"]
[Sun Aug 30 03:07:09.912913 2026] [security2:error] [pid 501390:tid 501621] [client 20.48.160.90:30809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp-mini.php"] [unique_id "apPkrag6skwqJ2NpVh_AFwAAAnk"]
[Sun Aug 30 03:07:09.928414 2026] [security2:error] [pid 501390:tid 501619] [client 216.73.216.128:50828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPkrag6skwqJ2NpVh_AGwAAAnc"]
[Sun Aug 30 03:07:09.970114 2026] [security2:error] [pid 501390:tid 501526] [client 20.48.250.41:45313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/ak.php"] [unique_id "apPkrag6skwqJ2NpVh_ALwAAAho"]
[Sun Aug 30 03:07:09.988103 2026] [security2:error] [pid 501390:tid 501580] [client 20.151.200.44:27192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/update/da222.php"] [unique_id "apPkrag6skwqJ2NpVh_AQwAAAlA"]
[Sun Aug 30 03:07:09.991532 2026] [security2:error] [pid 501390:tid 501541] [client 114.119.155.94:22355] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stressfreeaccounts.com"] [uri "/wp-content/uploads/2020/08"] [unique_id "apPkrag6skwqJ2NpVh_ARAAAAik"], referer: http://stressfreeaccounts.com/wp-content/uploads/2020/08?C=S%3BO%3DA
[Sun Aug 30 03:07:09.996774 2026] [security2:error] [pid 499145:tid 499292] [client 20.104.50.220:32975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/eagle.php"] [unique_id "apPkrVJNq1G5uRhTNntYSQAAABE"]
[Sun Aug 30 03:07:10.011221 2026] [security2:error] [pid 501390:tid 501593] [client 20.48.250.41:50117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/ws58.php"] [unique_id "apPkrqg6skwqJ2NpVh_ASgAAAl0"]
[Sun Aug 30 03:07:10.024838 2026] [authz_core:error] [pid 501390:tid 501534] [client 216.73.216.128:49027] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:10.025098 2026] [authz_core:error] [pid 501390:tid 501534] [client 216.73.216.128:49027] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:10.034464 2026] [security2:error] [pid 501390:tid 501645] [client 20.196.209.81:20319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/bak.php"] [unique_id "apPkrqg6skwqJ2NpVh_AUgAAApE"]
[Sun Aug 30 03:07:10.064973 2026] [security2:error] [pid 501390:tid 501591] [client 20.48.160.90:61441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/xmini4.php"] [unique_id "apPkrqg6skwqJ2NpVh_AWwAAAls"]
[Sun Aug 30 03:07:10.085450 2026] [security2:error] [pid 499145:tid 499356] [client 68.155.159.216:62079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apPkrlJNq1G5uRhTNntYhAAAAFE"]
[Sun Aug 30 03:07:10.094715 2026] [security2:error] [pid 499145:tid 499283] [client 68.155.159.216:62279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/index/function.php"] [unique_id "apPkrlJNq1G5uRhTNntYiwAAAAg"]
[Sun Aug 30 03:07:10.134858 2026] [security2:error] [pid 499145:tid 499389] [client 4.205.62.107:56954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/bb.php"] [unique_id "apPkrlJNq1G5uRhTNntYowAAAHI"]
[Sun Aug 30 03:07:10.135621 2026] [security2:error] [pid 501390:tid 501567] [client 192.110.213.58:53596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.213.110.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoinsurancefor.me"] [uri "/wp-comments-post.php"] [unique_id "apPkrqg6skwqJ2NpVh_AagAAAkM"], referer: http://autoinsurancefor.me/auto-insurance-articles/progressive-insurance-phone-number/
[Sun Aug 30 03:07:10.142951 2026] [security2:error] [pid 499145:tid 499291] [client 20.48.250.41:46026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/lib.php"] [unique_id "apPkrlJNq1G5uRhTNntYpgAAABA"]
[Sun Aug 30 03:07:10.147473 2026] [security2:error] [pid 501390:tid 501567] [client 192.110.213.58:53596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "autoinsurancefor.me"] [uri "/wp-comments-post.php"] [unique_id "apPkrqg6skwqJ2NpVh_AagAAAkM"], referer: http://autoinsurancefor.me/auto-insurance-articles/progressive-insurance-phone-number/
[Sun Aug 30 03:07:10.167341 2026] [security2:error] [pid 499145:tid 499340] [client 4.205.62.107:65340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/cli_bootstrap.php"] [unique_id "apPkrlJNq1G5uRhTNntYtAAAAEE"]
[Sun Aug 30 03:07:10.189581 2026] [security2:error] [pid 501390:tid 501646] [client 20.48.250.41:53410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/xs.php"] [unique_id "apPkrqg6skwqJ2NpVh_AnAAAApI"]
[Sun Aug 30 03:07:10.195239 2026] [security2:error] [pid 499145:tid 499308] [client 68.155.159.216:64784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPkrlJNq1G5uRhTNntYxwAAACE"]
[Sun Aug 30 03:07:10.199027 2026] [security2:error] [pid 499145:tid 499316] [client 20.48.160.90:38005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/reop3.php"] [unique_id "apPkrlJNq1G5uRhTNntYygAAACk"]
[Sun Aug 30 03:07:10.228142 2026] [security2:error] [pid 501390:tid 501627] [client 114.119.130.253:40135] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "thelongthread.com"] [uri "/2015/01/24/sewing-with-double-gauze"] [unique_id "apPkrqg6skwqJ2NpVh_ArwAAAn8"], referer: http://thelongthread.com/category/fabric/page/15
[Sun Aug 30 03:07:10.235427 2026] [security2:error] [pid 499145:tid 499391] [client 20.196.209.81:4924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPkrlJNq1G5uRhTNntY4AAAAHQ"]
[Sun Aug 30 03:07:10.269590 2026] [security2:error] [pid 501390:tid 501625] [client 20.48.250.41:46039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/wp-style.php"] [unique_id "apPkrqg6skwqJ2NpVh_A0AAAAn0"]
[Sun Aug 30 03:07:10.286526 2026] [authz_core:error] [pid 499145:tid 499361] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:07:10.286900 2026] [authz_core:error] [pid 499145:tid 499361] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:07:10.289866 2026] [security2:error] [pid 499145:tid 499276] [client 68.155.159.216:12408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-includes/js/index.php"] [unique_id "apPkrlJNq1G5uRhTNntY-AAAAAE"]
[Sun Aug 30 03:07:10.304269 2026] [security2:error] [pid 501390:tid 501583] [client 20.104.18.15:29146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/dex.php"] [unique_id "apPkrqg6skwqJ2NpVh_A5gAAAlM"]
[Sun Aug 30 03:07:10.327252 2026] [security2:error] [pid 501390:tid 501561] [client 20.48.160.90:61445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp-mail.php"] [unique_id "apPkrqg6skwqJ2NpVh_A-QAAAj0"]
[Sun Aug 30 03:07:10.334264 2026] [security2:error] [pid 501390:tid 501588] [client 4.205.62.107:64680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/xda.php"] [unique_id "apPkrqg6skwqJ2NpVh_BAwAAAlg"]
[Sun Aug 30 03:07:10.342895 2026] [security2:error] [pid 501390:tid 501573] [client 20.48.250.41:53405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/zu.php"] [unique_id "apPkrqg6skwqJ2NpVh_BDQAAAkk"]
[Sun Aug 30 03:07:10.344408 2026] [security2:error] [pid 501390:tid 501535] [client 20.220.10.235:20720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkrqg6skwqJ2NpVh_BEQAAAiM"]
[Sun Aug 30 03:07:10.355010 2026] [security2:error] [pid 499145:tid 499344] [client 20.48.251.3:6471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/edit.php"] [unique_id "apPkrlJNq1G5uRhTNntZFwAAAEU"]
[Sun Aug 30 03:07:10.355261 2026] [security2:error] [pid 499145:tid 499308] [client 20.104.50.220:27412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/bdatos.php"] [unique_id "apPkrlJNq1G5uRhTNntZGAAAACE"]
[Sun Aug 30 03:07:10.392171 2026] [authz_core:error] [pid 501390:tid 501625] [client 66.249.66.202:50543] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:10.392449 2026] [authz_core:error] [pid 501390:tid 501625] [client 66.249.66.202:50543] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:10.405888 2026] [security2:error] [pid 501390:tid 501573] [client 20.48.250.41:46050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/browse.php"] [unique_id "apPkrqg6skwqJ2NpVh_BPQAAAkk"]
[Sun Aug 30 03:07:10.420097 2026] [security2:error] [pid 501390:tid 501534] [client 20.104.18.15:34815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/img.php"] [unique_id "apPkrqg6skwqJ2NpVh_BTQAAAiI"]
[Sun Aug 30 03:07:10.425278 2026] [security2:error] [pid 501390:tid 501550] [client 20.104.50.220:42271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/ganz.php"] [unique_id "apPkrqg6skwqJ2NpVh_BUQAAAjI"]
[Sun Aug 30 03:07:10.427140 2026] [security2:error] [pid 501390:tid 501603] [client 20.196.209.81:20343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/pages.php"] [unique_id "apPkrqg6skwqJ2NpVh_BUwAAAmc"]
[Sun Aug 30 03:07:10.479670 2026] [security2:error] [pid 501390:tid 501562] [client 20.48.160.90:61506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp-conffg.php"] [unique_id "apPkrqg6skwqJ2NpVh_BcgAAAj4"]
[Sun Aug 30 03:07:10.480300 2026] [security2:error] [pid 501390:tid 501590] [client 20.48.250.41:50125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/lanka.php"] [unique_id "apPkrqg6skwqJ2NpVh_BdQAAAlo"]
[Sun Aug 30 03:07:10.485280 2026] [security2:error] [pid 501390:tid 501559] [client 20.220.10.235:20928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkrqg6skwqJ2NpVh_BfAAAAjs"]
[Sun Aug 30 03:07:10.487234 2026] [authz_core:error] [pid 501390:tid 501626] [client 216.73.216.128:49027] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:10.487701 2026] [authz_core:error] [pid 501390:tid 501626] [client 216.73.216.128:49027] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:10.496589 2026] [security2:error] [pid 501390:tid 501552] [client 20.104.50.220:29593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/constant.php"] [unique_id "apPkrqg6skwqJ2NpVh_BiQAAAjQ"]
[Sun Aug 30 03:07:10.516573 2026] [security2:error] [pid 501390:tid 501646] [client 20.104.18.15:51594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/wsd.php"] [unique_id "apPkrqg6skwqJ2NpVh_BkAAAApI"]
[Sun Aug 30 03:07:10.526896 2026] [security2:error] [pid 501390:tid 501543] [client 4.205.62.107:62097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/apikeys.php"] [unique_id "apPkrqg6skwqJ2NpVh_BlwAAAis"]
[Sun Aug 30 03:07:10.545549 2026] [security2:error] [pid 501390:tid 501615] [client 20.48.251.3:49984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/saml.php"] [unique_id "apPkrqg6skwqJ2NpVh_BsQAAAnM"]
[Sun Aug 30 03:07:10.546121 2026] [security2:error] [pid 499145:tid 499330] [client 20.48.250.41:46052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/zoo.php"] [unique_id "apPkrlJNq1G5uRhTNntZaQAAADc"]
[Sun Aug 30 03:07:10.575271 2026] [authz_core:error] [pid 501390:tid 501551] [client 216.73.216.128:1374] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:10.575640 2026] [authz_core:error] [pid 501390:tid 501551] [client 216.73.216.128:1374] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:10.591228 2026] [security2:error] [pid 501390:tid 501606] [client 4.205.62.107:18808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/snq.php"] [unique_id "apPkrqg6skwqJ2NpVh_BwwAAAmo"]
[Sun Aug 30 03:07:10.608684 2026] [security2:error] [pid 499145:tid 499378] [client 20.48.160.90:61454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/filefuns.php"] [unique_id "apPkrlJNq1G5uRhTNntZigAAAGc"]
[Sun Aug 30 03:07:10.611764 2026] [authz_core:error] [pid 499145:tid 499400] [client 66.249.66.71:64989] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:10.612233 2026] [authz_core:error] [pid 499145:tid 499400] [client 66.249.66.71:64989] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:10.613413 2026] [security2:error] [pid 499145:tid 499281] [client 20.220.10.235:20685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/h02ugyh.php"] [unique_id "apPkrlJNq1G5uRhTNntZjQAAAAY"]
[Sun Aug 30 03:07:10.626753 2026] [security2:error] [pid 501390:tid 501567] [client 114.119.153.191:44173] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "patrickstaehle.com"] [uri "/index.php/tag/cinematic/"] [unique_id "apPkrqg6skwqJ2NpVh_ByAAAAkM"], referer: https://patrickstaehle.com/index.php/tag/cinematic/
[Sun Aug 30 03:07:10.629049 2026] [authz_core:error] [pid 501390:tid 501584] [client 66.249.66.206:41678] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:10.629332 2026] [authz_core:error] [pid 501390:tid 501584] [client 66.249.66.206:41678] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:10.631927 2026] [security2:error] [pid 501390:tid 501634] [client 20.196.209.81:5736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/intense/block-css.php"] [unique_id "apPkrqg6skwqJ2NpVh_BygAAAoY"]
[Sun Aug 30 03:07:10.650406 2026] [authz_core:error] [pid 499145:tid 499366] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fmultipart
[Sun Aug 30 03:07:10.650688 2026] [authz_core:error] [pid 499145:tid 499366] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fmultipart
[Sun Aug 30 03:07:10.651274 2026] [security2:error] [pid 499145:tid 499398] [client 4.205.62.107:26773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dirkhoag.com"] [uri "/wp-act.php"] [unique_id "apPkrlJNq1G5uRhTNntZmQAAAHs"]
[Sun Aug 30 03:07:10.679998 2026] [security2:error] [pid 499145:tid 499309] [client 20.48.250.41:46031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/elp.php"] [unique_id "apPkrlJNq1G5uRhTNntZowAAACI"]
[Sun Aug 30 03:07:10.711566 2026] [security2:error] [pid 501390:tid 501643] [client 20.48.250.41:50113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/gettest.php"] [unique_id "apPkrqg6skwqJ2NpVh_B7gAAAo8"]
[Sun Aug 30 03:07:10.731072 2026] [authz_core:error] [pid 499145:tid 499370] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm
[Sun Aug 30 03:07:10.731351 2026] [authz_core:error] [pid 499145:tid 499370] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm
[Sun Aug 30 03:07:10.746762 2026] [security2:error] [pid 501390:tid 501596] [client 20.220.10.235:20721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/sf.php"] [unique_id "apPkrqg6skwqJ2NpVh_CEAAAAmA"]
[Sun Aug 30 03:07:10.746860 2026] [security2:error] [pid 501390:tid 501577] [client 68.155.159.216:56363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/about.php"] [unique_id "apPkrqg6skwqJ2NpVh_CEQAAAk0"]
[Sun Aug 30 03:07:10.753157 2026] [security2:error] [pid 501390:tid 501623] [client 20.48.160.90:61475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp-cron.php"] [unique_id "apPkrqg6skwqJ2NpVh_CGwAAAns"]
[Sun Aug 30 03:07:10.781536 2026] [security2:error] [pid 501390:tid 501639] [client 20.104.50.220:16740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/b00869ae6e.php"] [unique_id "apPkrqg6skwqJ2NpVh_CLgAAAos"]
[Sun Aug 30 03:07:10.798556 2026] [security2:error] [pid 501390:tid 501603] [client 20.104.18.15:28647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/file61.php"] [unique_id "apPkrqg6skwqJ2NpVh_CPAAAAmc"]
[Sun Aug 30 03:07:10.799399 2026] [security2:error] [pid 501390:tid 501541] [client 20.104.18.15:18309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/ap.php"] [unique_id "apPkrqg6skwqJ2NpVh_CPQAAAik"]
[Sun Aug 30 03:07:10.807318 2026] [security2:error] [pid 501390:tid 501601] [client 4.205.62.107:2814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPkrqg6skwqJ2NpVh_CRwAAAmU"]
[Sun Aug 30 03:07:10.808802 2026] [authz_core:error] [pid 501390:tid 501574] [client 216.73.216.128:28694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:10.809134 2026] [authz_core:error] [pid 501390:tid 501574] [client 216.73.216.128:28694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:10.820361 2026] [security2:error] [pid 501390:tid 501536] [client 20.196.209.81:10936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/albin.php"] [unique_id "apPkrqg6skwqJ2NpVh_CTwAAAiQ"]
[Sun Aug 30 03:07:10.826867 2026] [security2:error] [pid 501390:tid 501555] [client 20.104.50.220:32552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/priv.php"] [unique_id "apPkrqg6skwqJ2NpVh_CUwAAAjc"]
[Sun Aug 30 03:07:10.831086 2026] [security2:error] [pid 501390:tid 501559] [client 20.48.251.3:33284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/xqq.php"] [unique_id "apPkrqg6skwqJ2NpVh_CVgAAAjs"]
[Sun Aug 30 03:07:10.833246 2026] [security2:error] [pid 501390:tid 501561] [client 68.155.159.216:55075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/NewFile.php/"] [unique_id "apPkrqg6skwqJ2NpVh_CWAAAAj0"]
[Sun Aug 30 03:07:10.836165 2026] [security2:error] [pid 501390:tid 501579] [client 4.205.62.107:62413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/ms.php"] [unique_id "apPkrqg6skwqJ2NpVh_CXQAAAk8"]
[Sun Aug 30 03:07:10.840263 2026] [security2:error] [pid 501390:tid 501619] [client 20.48.250.41:45334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/666.php"] [unique_id "apPkrqg6skwqJ2NpVh_CYgAAAnc"]
[Sun Aug 30 03:07:10.845788 2026] [security2:error] [pid 501390:tid 501560] [client 20.104.18.15:23469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/samll.php"] [unique_id "apPkrqg6skwqJ2NpVh_CawAAAjw"]
[Sun Aug 30 03:07:10.847391 2026] [security2:error] [pid 501390:tid 501633] [client 20.104.18.15:44029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/manga.php"] [unique_id "apPkrqg6skwqJ2NpVh_CbgAAAoU"]
[Sun Aug 30 03:07:10.851881 2026] [authz_core:error] [pid 501390:tid 501617] [client 216.73.216.128:1374] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:10.852204 2026] [authz_core:error] [pid 501390:tid 501617] [client 216.73.216.128:1374] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:10.874519 2026] [security2:error] [pid 501390:tid 501622] [client 20.48.250.41:53421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/35.php"] [unique_id "apPkrqg6skwqJ2NpVh_CfQAAAno"]
[Sun Aug 30 03:07:10.893012 2026] [security2:error] [pid 501390:tid 501546] [client 20.220.10.235:20730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/4e.php"] [unique_id "apPkrqg6skwqJ2NpVh_CigAAAi4"]
[Sun Aug 30 03:07:10.898511 2026] [security2:error] [pid 499145:tid 499300] [client 20.104.50.220:46163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-one.php"] [unique_id "apPkrlJNq1G5uRhTNntZ7AAAABk"]
[Sun Aug 30 03:07:10.906537 2026] [security2:error] [pid 501390:tid 501552] [client 34.125.55.247:47828] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpanel.engaginggoddaily.com"] [uri "/@fs/var/www/html/wp-config.php"] [unique_id "apPkrqg6skwqJ2NpVh_CkgAAAjQ"]
[Sun Aug 30 03:07:10.907110 2026] [security2:error] [pid 501390:tid 501531] [client 34.125.55.247:47846] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.engaginggoddaily.com"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ"] [unique_id "apPkrqg6skwqJ2NpVh_CkwAAAh8"]
[Sun Aug 30 03:07:10.909744 2026] [core:error] [pid 501390:tid 501600] [client 34.125.55.247:47876] AH10244: invalid URI path (/@fs/../../../../../app/.env?raw??)
[Sun Aug 30 03:07:10.913590 2026] [security2:error] [pid 501390:tid 501573] [client 20.48.160.90:61440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/lock360.php"] [unique_id "apPkrqg6skwqJ2NpVh_CnwAAAkk"]
[Sun Aug 30 03:07:10.914258 2026] [security2:error] [pid 499145:tid 499397] [client 34.125.55.247:47796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/@fs/root/.ssh/id_rsa"] [unique_id "apPkrlJNq1G5uRhTNntZ8QAAAHo"]
[Sun Aug 30 03:07:10.914674 2026] [security2:error] [pid 501390:tid 501608] [client 34.125.55.247:47940] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.engaginggoddaily.com"] [uri "/@fs/../../../../../root/.env"] [unique_id "apPkrqg6skwqJ2NpVh_CpQAAAmw"]
[Sun Aug 30 03:07:10.914824 2026] [security2:error] [pid 501390:tid 501529] [client 34.125.55.247:47868] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.engaginggoddaily.com"] [uri "/@fs/../../../../../proc/self/environ"] [unique_id "apPkrqg6skwqJ2NpVh_CpAAAAh0"]
[Sun Aug 30 03:07:10.916423 2026] [security2:error] [pid 501390:tid 501560] [client 34.125.55.247:47884] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.engaginggoddaily.com"] [uri "/@fs/app/credentials.json"] [unique_id "apPkrqg6skwqJ2NpVh_CrAAAAjw"]
[Sun Aug 30 03:07:10.917238 2026] [security2:error] [pid 501390:tid 501567] [client 34.125.55.247:48064] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.engaginggoddaily.com"] [uri "/@fs/home/ubuntu/.oci/config"] [unique_id "apPkrqg6skwqJ2NpVh_CrwAAAkM"]
[Sun Aug 30 03:07:10.921237 2026] [security2:error] [pid 501390:tid 501629] [client 20.104.50.220:29175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/1945.php"] [unique_id "apPkrqg6skwqJ2NpVh_CtgAAAoE"]
[Sun Aug 30 03:07:10.972729 2026] [security2:error] [pid 501390:tid 501537] [client 20.104.50.220:5903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/ui.php"] [unique_id "apPkrqg6skwqJ2NpVh_C2QAAAiU"]
[Sun Aug 30 03:07:10.975068 2026] [security2:error] [pid 501390:tid 501618] [client 20.48.250.41:45363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/knmt.php"] [unique_id "apPkrqg6skwqJ2NpVh_C2wAAAnY"]
[Sun Aug 30 03:07:11.016440 2026] [security2:error] [pid 501390:tid 501590] [client 20.48.250.41:53462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/maraz.php"] [unique_id "apPkr6g6skwqJ2NpVh_C_wAAAlo"]
[Sun Aug 30 03:07:11.020162 2026] [security2:error] [pid 501390:tid 501588] [client 20.104.18.15:33687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/rxr.php"] [unique_id "apPkr6g6skwqJ2NpVh_DBAAAAlg"]
[Sun Aug 30 03:07:11.023458 2026] [security2:error] [pid 501390:tid 501532] [client 34.125.55.247:47838] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/@fs/var/run/secrets/kubernetes.io/serviceaccount/token"] [unique_id "apPkrqg6skwqJ2NpVh_ClAAAAiA"]
[Sun Aug 30 03:07:11.023593 2026] [proxy_http:error] [pid 501390:tid 501568] (20014)Internal error (specific information not available): [client 34.125.55.247:47818] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:11.023602 2026] [proxy:error] [pid 501390:tid 501568] [client 34.125.55.247:47818] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/etc/apache2/apache2.conf
[Sun Aug 30 03:07:11.025692 2026] [security2:error] [pid 501390:tid 501559] [client 20.196.209.81:15108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/login.php"] [unique_id "apPkr6g6skwqJ2NpVh_DBgAAAjs"]
[Sun Aug 30 03:07:11.030033 2026] [proxy_http:error] [pid 501390:tid 501597] (20014)Internal error (specific information not available): [client 34.125.55.247:47930] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:11.030049 2026] [proxy:error] [pid 501390:tid 501597] [client 34.125.55.247:47930] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/home/ubuntu/.config/gcloud/application_default_credentials.json
[Sun Aug 30 03:07:11.034545 2026] [security2:error] [pid 501390:tid 501546] [client 20.104.18.15:13671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/pri.php"] [unique_id "apPkr6g6skwqJ2NpVh_DDgAAAi4"]
[Sun Aug 30 03:07:11.046745 2026] [security2:error] [pid 501390:tid 501623] [client 20.104.50.220:61969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-content/fm.php"] [unique_id "apPkr6g6skwqJ2NpVh_DGgAAAns"]
[Sun Aug 30 03:07:11.046776 2026] [security2:error] [pid 501390:tid 501647] [client 20.48.251.3:5070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/session.php"] [unique_id "apPkr6g6skwqJ2NpVh_DGwAAApM"]
[Sun Aug 30 03:07:11.047007 2026] [security2:error] [pid 501390:tid 501601] [client 20.48.160.90:61503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp-theme.php"] [unique_id "apPkr6g6skwqJ2NpVh_DHAAAAmU"]
[Sun Aug 30 03:07:11.098689 2026] [security2:error] [pid 501390:tid 501574] [client 20.220.10.235:20707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/ssss.php"] [unique_id "apPkr6g6skwqJ2NpVh_DPwAAAko"]
[Sun Aug 30 03:07:11.131233 2026] [security2:error] [pid 499145:tid 499327] [client 20.151.200.44:27293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/qi.php"] [unique_id "apPkr1JNq1G5uRhTNntaQwAAADQ"]
[Sun Aug 30 03:07:11.145684 2026] [security2:error] [pid 501390:tid 501549] [client 20.48.250.41:45338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/sbhu.php"] [unique_id "apPkr6g6skwqJ2NpVh_DTwAAAjE"]
[Sun Aug 30 03:07:11.146845 2026] [proxy_http:error] [pid 501390:tid 501643] (20014)Internal error (specific information not available): [client 34.125.55.247:47988] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:11.146862 2026] [proxy:error] [pid 501390:tid 501643] [client 34.125.55.247:47988] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/home/ec2-user/.aws/config
[Sun Aug 30 03:07:11.150141 2026] [security2:error] [pid 501390:tid 501629] [client 20.104.50.220:33075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/Eagle.php"] [unique_id "apPkr6g6skwqJ2NpVh_DUQAAAoE"]
[Sun Aug 30 03:07:11.154365 2026] [proxy_http:error] [pid 501390:tid 501613] (20014)Internal error (specific information not available): [client 34.125.55.247:47780] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:11.154386 2026] [proxy:error] [pid 501390:tid 501613] [client 34.125.55.247:47780] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/proc/self/cmdline
[Sun Aug 30 03:07:11.162098 2026] [proxy_http:error] [pid 501390:tid 501529] (20014)Internal error (specific information not available): [client 34.125.55.247:47868] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:11.162118 2026] [proxy:error] [pid 501390:tid 501529] [client 34.125.55.247:47868] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/cgi-sys/403.html
[Sun Aug 30 03:07:11.169952 2026] [proxy_http:error] [pid 501390:tid 501589] (20014)Internal error (specific information not available): [client 34.125.55.247:47778] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:11.169971 2026] [proxy:error] [pid 501390:tid 501589] [client 34.125.55.247:47778] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/etc/nginx/nginx.conf
[Sun Aug 30 03:07:11.176787 2026] [proxy_http:error] [pid 501390:tid 501553] (20014)Internal error (specific information not available): [client 34.125.55.247:48042] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:11.176806 2026] [proxy:error] [pid 501390:tid 501553] [client 34.125.55.247:48042] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/root/.config/linode-cli
[Sun Aug 30 03:07:11.184419 2026] [proxy_http:error] [pid 501390:tid 501634] (20014)Internal error (specific information not available): [client 34.125.55.247:47914] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:11.184438 2026] [proxy:error] [pid 501390:tid 501634] [client 34.125.55.247:47914] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/home/ubuntu/.azure/credentials
[Sun Aug 30 03:07:11.186726 2026] [security2:error] [pid 501390:tid 501619] [client 20.48.160.90:37726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/2d7433/index.php"] [unique_id "apPkr6g6skwqJ2NpVh_DdAAAAnc"]
[Sun Aug 30 03:07:11.191245 2026] [proxy_http:error] [pid 501390:tid 501616] (20014)Internal error (specific information not available): [client 34.125.55.247:48018] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:11.191263 2026] [proxy:error] [pid 501390:tid 501616] [client 34.125.55.247:48018] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/root/.config/gcloud/credentials.db
[Sun Aug 30 03:07:11.197491 2026] [security2:error] [pid 501390:tid 501586] [client 34.125.55.247:48026] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/@fs/home/ubuntu/.azure/accessTokens.json"] [unique_id "apPkrqg6skwqJ2NpVh_CrQAAAlY"]
[Sun Aug 30 03:07:11.197661 2026] [proxy_http:error] [pid 501390:tid 501556] (20014)Internal error (specific information not available): [client 34.125.55.247:48032] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:11.197674 2026] [proxy:error] [pid 501390:tid 501556] [client 34.125.55.247:48032] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/root/.config/hcloud/cli.toml
[Sun Aug 30 03:07:11.197770 2026] [security2:error] [pid 501390:tid 501549] [client 20.48.250.41:50135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/kbfr.php"] [unique_id "apPkr6g6skwqJ2NpVh_DewAAAjE"]
[Sun Aug 30 03:07:11.204973 2026] [proxy_http:error] [pid 501390:tid 501633] (20014)Internal error (specific information not available): [client 34.125.55.247:47898] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:11.204993 2026] [proxy:error] [pid 501390:tid 501633] [client 34.125.55.247:47898] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/app/gcp-credentials.json
[Sun Aug 30 03:07:11.213468 2026] [proxy_http:error] [pid 501390:tid 501644] (20014)Internal error (specific information not available): [client 34.125.55.247:48004] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:11.213481 2026] [proxy:error] [pid 501390:tid 501644] [client 34.125.55.247:48004] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/home/node/.config/gcloud/application_default_credentials.json
[Sun Aug 30 03:07:11.227910 2026] [security2:error] [pid 499145:tid 499362] [client 20.220.10.235:20945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/zoz.php"] [unique_id "apPkr1JNq1G5uRhTNntabgAAAFc"]
[Sun Aug 30 03:07:11.259449 2026] [security2:error] [pid 501390:tid 501582] [client 68.155.159.216:61679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/.well-known/content.php"] [unique_id "apPkr6g6skwqJ2NpVh_DqQAAAlI"]
[Sun Aug 30 03:07:11.262277 2026] [authz_core:error] [pid 499145:tid 499371] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:07:11.262643 2026] [authz_core:error] [pid 499145:tid 499371] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:07:11.278859 2026] [security2:error] [pid 501390:tid 501572] [client 20.48.250.41:45361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/a332.php"] [unique_id "apPkr6g6skwqJ2NpVh_DtAAAAkg"]
[Sun Aug 30 03:07:11.285070 2026] [security2:error] [pid 501390:tid 501624] [client 20.196.209.81:20306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/an.php"] [unique_id "apPkr6g6skwqJ2NpVh_DugAAAnw"]
[Sun Aug 30 03:07:11.300421 2026] [security2:error] [pid 501390:tid 501588] [client 4.205.62.107:52139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/file59.php"] [unique_id "apPkr6g6skwqJ2NpVh_DyAAAAlg"]
[Sun Aug 30 03:07:11.312276 2026] [lsapi:error] [pid 501390:tid 501450] [remote 45.143.100.93:55309] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.yahoo.com/
[Sun Aug 30 03:07:11.312385 2026] [lsapi:error] [pid 501390:tid 501450] [remote 45.143.100.93:55309] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.yahoo.com/
[Sun Aug 30 03:07:11.313866 2026] [lsapi:error] [pid 501390:tid 501450] [remote 45.143.100.93:55309] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n, referer: https://www.yahoo.com/
[Sun Aug 30 03:07:11.335374 2026] [security2:error] [pid 501390:tid 501629] [client 20.48.250.41:53459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/wp-act.php"] [unique_id "apPkr6g6skwqJ2NpVh_D4wAAAoE"]
[Sun Aug 30 03:07:11.335612 2026] [security2:error] [pid 501390:tid 501552] [client 20.48.160.90:37661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp-login.php"] [unique_id "apPkr6g6skwqJ2NpVh_D1AAAAjQ"]
[Sun Aug 30 03:07:11.349231 2026] [authz_core:error] [pid 499145:tid 499327] [client 66.249.66.71:65293] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:11.349710 2026] [authz_core:error] [pid 499145:tid 499327] [client 66.249.66.71:65293] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:11.352380 2026] [security2:error] [pid 501390:tid 501531] [client 114.119.138.194:55581] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cravegoldcoast.com.au"] [uri "/xmasrecipes/xmas13recipe_14sml.jpg"] [unique_id "apPkr6g6skwqJ2NpVh_D9wAAAh8"], referer: https://chocolaterecipesyosukei.blogspot.com/2017/10/white-chocolate-xmas-recipes.html?m=0
[Sun Aug 30 03:07:11.373166 2026] [security2:error] [pid 501390:tid 501613] [client 20.220.10.235:20711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/kcs.php"] [unique_id "apPkr6g6skwqJ2NpVh_D_gAAAnE"]
[Sun Aug 30 03:07:11.378299 2026] [security2:error] [pid 501390:tid 501633] [client 68.155.159.216:61355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-admin.php"] [unique_id "apPkr6g6skwqJ2NpVh_EAQAAAoU"]
[Sun Aug 30 03:07:11.392006 2026] [security2:error] [pid 501390:tid 501520] [client 4.205.62.107:65338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/dd.php"] [unique_id "apPkr6g6skwqJ2NpVh_EFQAAAhQ"]
[Sun Aug 30 03:07:11.398747 2026] [authz_core:error] [pid 501390:tid 501615] [client 216.73.216.128:1374] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:11.399204 2026] [authz_core:error] [pid 501390:tid 501615] [client 216.73.216.128:1374] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:11.405721 2026] [security2:error] [pid 501390:tid 501636] [client 68.155.159.216:62021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/login.php"] [unique_id "apPkr6g6skwqJ2NpVh_EKgAAAog"]
[Sun Aug 30 03:07:11.409366 2026] [security2:error] [pid 501390:tid 501545] [client 20.48.250.41:46019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/ws66.php"] [unique_id "apPkr6g6skwqJ2NpVh_EKwAAAi0"]
[Sun Aug 30 03:07:11.416530 2026] [security2:error] [pid 501390:tid 501639] [client 20.196.209.81:13756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/min.php"] [unique_id "apPkr6g6skwqJ2NpVh_EMQAAAos"]
[Sun Aug 30 03:07:11.457710 2026] [security2:error] [pid 501390:tid 501565] [client 20.104.18.15:29166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/img.php"] [unique_id "apPkr6g6skwqJ2NpVh_ESgAAAkE"]
[Sun Aug 30 03:07:11.463538 2026] [security2:error] [pid 501390:tid 501558] [client 20.151.200.44:27137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/px.php"] [unique_id "apPkr6g6skwqJ2NpVh_ETQAAAjo"]
[Sun Aug 30 03:07:11.465650 2026] [security2:error] [pid 501390:tid 501604] [client 20.48.160.90:30795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/images.php"] [unique_id "apPkr6g6skwqJ2NpVh_ETwAAAmg"]
[Sun Aug 30 03:07:11.475248 2026] [security2:error] [pid 501390:tid 501609] [client 4.205.62.107:61768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/pinfo.php"] [unique_id "apPkr6g6skwqJ2NpVh_EVwAAAm0"]
[Sun Aug 30 03:07:11.482343 2026] [security2:error] [pid 501390:tid 501582] [client 4.205.62.107:31716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/params.php"] [unique_id "apPkr6g6skwqJ2NpVh_EXQAAAlI"]
[Sun Aug 30 03:07:11.485940 2026] [security2:error] [pid 501390:tid 501573] [client 20.104.50.220:27551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/public/index.php"] [unique_id "apPkr6g6skwqJ2NpVh_EYgAAAkk"]
[Sun Aug 30 03:07:11.490400 2026] [security2:error] [pid 501390:tid 501636] [client 4.205.62.107:35983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkr6g6skwqJ2NpVh_EaAAAAog"]
[Sun Aug 30 03:07:11.493406 2026] [authz_core:error] [pid 501390:tid 501644] [client 66.249.66.195:60350] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:11.493883 2026] [authz_core:error] [pid 501390:tid 501644] [client 66.249.66.195:60350] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:11.500431 2026] [security2:error] [pid 501390:tid 501545] [client 68.155.159.216:12311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-content/index.php"] [unique_id "apPkr6g6skwqJ2NpVh_EcAAAAi0"]
[Sun Aug 30 03:07:11.500483 2026] [security2:error] [pid 501390:tid 501607] [client 20.48.250.41:53492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/24.php"] [unique_id "apPkr6g6skwqJ2NpVh_EbgAAAms"]
[Sun Aug 30 03:07:11.515276 2026] [security2:error] [pid 501390:tid 501520] [client 20.220.10.235:20938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/tajj.php"] [unique_id "apPkr6g6skwqJ2NpVh_EhwAAAhQ"]
[Sun Aug 30 03:07:11.536659 2026] [security2:error] [pid 501390:tid 501589] [client 20.48.250.41:45348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/ws68.php"] [unique_id "apPkr6g6skwqJ2NpVh_EmAAAAlk"]
[Sun Aug 30 03:07:11.565096 2026] [security2:error] [pid 501390:tid 501602] [client 20.104.50.220:63503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/gas.php"] [unique_id "apPkr6g6skwqJ2NpVh_EqQAAAmY"]
[Sun Aug 30 03:07:11.568530 2026] [security2:error] [pid 501390:tid 501560] [client 20.104.18.15:34630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/222.php"] [unique_id "apPkr6g6skwqJ2NpVh_EqgAAAjw"]
[Sun Aug 30 03:07:11.598998 2026] [security2:error] [pid 501390:tid 501586] [client 20.48.160.90:37670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/ops.php"] [unique_id "apPkr6g6skwqJ2NpVh_EwgAAAlY"]
[Sun Aug 30 03:07:11.633904 2026] [security2:error] [pid 501390:tid 501550] [client 20.104.50.220:62825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/celeng.php"] [unique_id "apPkr6g6skwqJ2NpVh_EzAAAAjI"]
[Sun Aug 30 03:07:11.645372 2026] [security2:error] [pid 501390:tid 501590] [client 20.220.10.235:20675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/bge.php"] [unique_id "apPkr6g6skwqJ2NpVh_EzgAAAlo"]
[Sun Aug 30 03:07:11.652472 2026] [authz_core:error] [pid 499145:tid 499276] [client 66.249.66.78:60410] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:11.652894 2026] [authz_core:error] [pid 499145:tid 499276] [client 66.249.66.78:60410] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:11.667122 2026] [security2:error] [pid 501390:tid 501527] [client 4.205.62.107:63947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/motu.php"] [unique_id "apPkr6g6skwqJ2NpVh_E0wAAAhs"]
[Sun Aug 30 03:07:11.669840 2026] [security2:error] [pid 501390:tid 501601] [client 20.104.18.15:51698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/bulet.php"] [unique_id "apPkr6g6skwqJ2NpVh_E1QAAAmU"]
[Sun Aug 30 03:07:11.673415 2026] [security2:error] [pid 501390:tid 501570] [client 20.48.251.3:7375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/thui.php"] [unique_id "apPkr6g6skwqJ2NpVh_E1wAAAkY"]
[Sun Aug 30 03:07:11.679935 2026] [security2:error] [pid 501390:tid 501592] [client 20.48.251.3:55540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/aws_settings.php"] [unique_id "apPkr6g6skwqJ2NpVh_E2gAAAlw"]
[Sun Aug 30 03:07:11.683260 2026] [security2:error] [pid 499145:tid 499343] [client 20.196.209.81:10920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/mini.php"] [unique_id "apPkr1JNq1G5uRhTNntbIQAAAEQ"]
[Sun Aug 30 03:07:11.688474 2026] [security2:error] [pid 501390:tid 501622] [client 20.48.250.41:45353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/users.php"] [unique_id "apPkr6g6skwqJ2NpVh_E4QAAAno"]
[Sun Aug 30 03:07:11.702128 2026] [security2:error] [pid 499145:tid 499328] [client 20.151.200.44:27184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/is.php"] [unique_id "apPkr1JNq1G5uRhTNntbJwAAADU"]
[Sun Aug 30 03:07:11.705571 2026] [security2:error] [pid 501390:tid 501607] [client 20.48.250.41:53423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/155.php"] [unique_id "apPkr6g6skwqJ2NpVh_E7wAAAms"]
[Sun Aug 30 03:07:11.720539 2026] [security2:error] [pid 501390:tid 501597] [client 4.205.62.107:18669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/wp-access.php"] [unique_id "apPkr6g6skwqJ2NpVh_E_wAAAmE"]
[Sun Aug 30 03:07:11.755759 2026] [security2:error] [pid 499145:tid 499339] [client 20.48.160.90:37749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPkr1JNq1G5uRhTNntbPQAAAEA"]
[Sun Aug 30 03:07:11.774012 2026] [security2:error] [pid 501390:tid 501600] [client 20.220.10.235:20698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/ssh3ll.php"] [unique_id "apPkr6g6skwqJ2NpVh_FJwAAAmQ"]
[Sun Aug 30 03:07:11.775669 2026] [authz_core:error] [pid 499145:tid 499391] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:07:11.776146 2026] [authz_core:error] [pid 499145:tid 499391] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:07:11.812442 2026] [security2:error] [pid 501390:tid 501556] [client 20.196.209.81:5713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/module.php"] [unique_id "apPkr6g6skwqJ2NpVh_FPwAAAjg"]
[Sun Aug 30 03:07:11.818364 2026] [security2:error] [pid 501390:tid 501533] [client 114.119.159.76:61055] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nurturingyourlife.com"] [uri "/category/midlife-women"] [unique_id "apPkr6g6skwqJ2NpVh_FRgAAAiE"], referer: https://nurturingyourlife.com/category/midlife-women
[Sun Aug 30 03:07:11.839361 2026] [security2:error] [pid 501390:tid 501571] [client 20.48.250.41:45953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/bzjdlofz.php"] [unique_id "apPkr6g6skwqJ2NpVh_FWwAAAkc"]
[Sun Aug 30 03:07:11.846233 2026] [security2:error] [pid 501390:tid 501536] [client 20.48.250.41:50055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/file.php"] [unique_id "apPkr6g6skwqJ2NpVh_FXwAAAiQ"]
[Sun Aug 30 03:07:11.884626 2026] [security2:error] [pid 501390:tid 501520] [client 20.151.200.44:27155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/od.php"] [unique_id "apPkr6g6skwqJ2NpVh_FdwAAAhQ"]
[Sun Aug 30 03:07:11.887801 2026] [security2:error] [pid 501390:tid 501533] [client 20.48.160.90:61564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPkr6g6skwqJ2NpVh_FewAAAiE"]
[Sun Aug 30 03:07:11.910009 2026] [authz_core:error] [pid 501390:tid 501607] [client 66.249.66.73:59903] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:11.910145 2026] [security2:error] [pid 501390:tid 501541] [client 20.220.10.235:20701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/motu.php"] [unique_id "apPkr6g6skwqJ2NpVh_FhgAAAik"]
[Sun Aug 30 03:07:11.910372 2026] [authz_core:error] [pid 501390:tid 501607] [client 66.249.66.73:59903] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:11.914837 2026] [security2:error] [pid 501390:tid 501584] [client 68.155.159.216:11166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apPkr6g6skwqJ2NpVh_FiwAAAlQ"]
[Sun Aug 30 03:07:11.925108 2026] [security2:error] [pid 501390:tid 501637] [client 20.104.50.220:16717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/term.php"] [unique_id "apPkr6g6skwqJ2NpVh_FjwAAAok"]
[Sun Aug 30 03:07:11.933925 2026] [security2:error] [pid 501390:tid 501606] [client 20.104.18.15:18401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/media.php"] [unique_id "apPkr6g6skwqJ2NpVh_FkgAAAmo"]
[Sun Aug 30 03:07:11.935603 2026] [security2:error] [pid 501390:tid 501593] [client 20.104.49.130:58055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/red.php"] [unique_id "apPkr6g6skwqJ2NpVh_FlAAAAl0"]
[Sun Aug 30 03:07:11.936172 2026] [security2:error] [pid 499145:tid 499300] [client 20.104.18.15:28496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/copypaths.php"] [unique_id "apPkr1JNq1G5uRhTNntbcAAAABk"]
[Sun Aug 30 03:07:11.948577 2026] [security2:error] [pid 501390:tid 501595] [client 68.155.159.216:55115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/dropdown.php"] [unique_id "apPkr6g6skwqJ2NpVh_FnwAAAl8"]
[Sun Aug 30 03:07:11.979951 2026] [security2:error] [pid 501390:tid 501600] [client 4.205.62.107:2123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/agg.php"] [unique_id "apPkr6g6skwqJ2NpVh_FvwAAAmQ"]
[Sun Aug 30 03:07:11.980087 2026] [security2:error] [pid 501390:tid 501592] [client 20.48.251.3:13399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/a1vx.php"] [unique_id "apPkr6g6skwqJ2NpVh_FwQAAAlw"]
[Sun Aug 30 03:07:11.992037 2026] [security2:error] [pid 501390:tid 501544] [client 20.104.50.220:32266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/priv8.php"] [unique_id "apPkr6g6skwqJ2NpVh_FyAAAAiw"]
[Sun Aug 30 03:07:11.994003 2026] [security2:error] [pid 501390:tid 501548] [client 20.48.250.41:46055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/selesai.php"] [unique_id "apPkr6g6skwqJ2NpVh_FygAAAjA"]
[Sun Aug 30 03:07:11.994981 2026] [security2:error] [pid 501390:tid 501602] [client 4.205.62.107:62285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/fucku.php"] [unique_id "apPkr6g6skwqJ2NpVh_FzAAAAmY"]
[Sun Aug 30 03:07:11.997130 2026] [security2:error] [pid 501390:tid 501645] [client 20.104.18.15:43846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/asdfghj.php"] [unique_id "apPkr6g6skwqJ2NpVh_FzwAAApE"]
[Sun Aug 30 03:07:12.013682 2026] [security2:error] [pid 501390:tid 501520] [client 20.104.18.15:23432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/she11.php"] [unique_id "apPksKg6skwqJ2NpVh_F3gAAAhQ"]
[Sun Aug 30 03:07:12.023373 2026] [security2:error] [pid 501390:tid 501577] [client 20.48.250.41:53443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPksKg6skwqJ2NpVh_F6AAAAk0"]
[Sun Aug 30 03:07:12.036709 2026] [security2:error] [pid 501390:tid 501600] [client 20.104.50.220:46636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-pluging.php"] [unique_id "apPksKg6skwqJ2NpVh_F9QAAAmQ"]
[Sun Aug 30 03:07:12.037515 2026] [security2:error] [pid 501390:tid 501546] [client 20.48.160.90:61480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/about.php"] [unique_id "apPksKg6skwqJ2NpVh_F9gAAAi4"]
[Sun Aug 30 03:07:12.062110 2026] [security2:error] [pid 501390:tid 501630] [client 20.220.10.235:20947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/wefile.php"] [unique_id "apPksKg6skwqJ2NpVh_GCgAAAoI"]
[Sun Aug 30 03:07:12.077023 2026] [security2:error] [pid 501390:tid 501580] [client 20.196.209.81:20913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/robots.php"] [unique_id "apPksKg6skwqJ2NpVh_GFAAAAlA"]
[Sun Aug 30 03:07:12.109486 2026] [security2:error] [pid 501390:tid 501610] [client 20.104.50.220:28721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wos.php"] [unique_id "apPksKg6skwqJ2NpVh_GJAAAAm4"]
[Sun Aug 30 03:07:12.111167 2026] [security2:error] [pid 501390:tid 501637] [client 20.104.50.220:5762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/zz.php"] [unique_id "apPksKg6skwqJ2NpVh_GKAAAAok"]
[Sun Aug 30 03:07:12.115145 2026] [authz_core:error] [pid 499145:tid 499341] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fmultipart
[Sun Aug 30 03:07:12.115439 2026] [authz_core:error] [pid 499145:tid 499341] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fmultipart
[Sun Aug 30 03:07:12.142126 2026] [security2:error] [pid 501390:tid 501620] [client 20.48.250.41:45987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/shlo.php"] [unique_id "apPksKg6skwqJ2NpVh_GNQAAAng"]
[Sun Aug 30 03:07:12.186717 2026] [security2:error] [pid 501390:tid 501606] [client 20.48.160.90:61461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/admin.php/admin.php"] [unique_id "apPksKg6skwqJ2NpVh_GbwAAAmo"]
[Sun Aug 30 03:07:12.187020 2026] [security2:error] [pid 501390:tid 501617] [client 20.104.18.15:13593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/wp_blog_footer.php"] [unique_id "apPksKg6skwqJ2NpVh_GcgAAAnU"]
[Sun Aug 30 03:07:12.190713 2026] [security2:error] [pid 499145:tid 499296] [client 20.48.251.3:44381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/h.php"] [unique_id "apPksFJNq1G5uRhTNntbyQAAABU"]
[Sun Aug 30 03:07:12.202767 2026] [security2:error] [pid 501390:tid 501579] [client 20.196.209.81:5716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/ms-files.php"] [unique_id "apPksKg6skwqJ2NpVh_GfwAAAk8"]
[Sun Aug 30 03:07:12.206319 2026] [security2:error] [pid 501390:tid 501642] [client 20.220.10.235:20943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/Contrller.php"] [unique_id "apPksKg6skwqJ2NpVh_GgAAAAo4"]
[Sun Aug 30 03:07:12.233559 2026] [security2:error] [pid 501390:tid 501535] [client 20.104.18.15:33722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tether-comic.com"] [uri "/reviall.php"] [unique_id "apPksKg6skwqJ2NpVh_GiQAAAiM"]
[Sun Aug 30 03:07:12.236782 2026] [authz_core:error] [pid 499145:tid 499340] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IN
[Sun Aug 30 03:07:12.237175 2026] [authz_core:error] [pid 499145:tid 499340] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IN
[Sun Aug 30 03:07:12.248489 2026] [security2:error] [pid 501390:tid 501600] [client 20.48.250.41:53437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/06.php"] [unique_id "apPksKg6skwqJ2NpVh_GlwAAAmQ"]
[Sun Aug 30 03:07:12.264319 2026] [security2:error] [pid 501390:tid 501568] [client 20.104.50.220:62253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-content/a.php"] [unique_id "apPksKg6skwqJ2NpVh_GpQAAAkQ"]
[Sun Aug 30 03:07:12.281893 2026] [security2:error] [pid 501390:tid 501621] [client 20.48.250.41:45347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/asax.php"] [unique_id "apPksKg6skwqJ2NpVh_GsAAAAnk"]
[Sun Aug 30 03:07:12.306401 2026] [security2:error] [pid 501390:tid 501590] [client 20.104.50.220:33563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/.error_log.php"] [unique_id "apPksKg6skwqJ2NpVh_GxQAAAlo"]
[Sun Aug 30 03:07:12.329540 2026] [security2:error] [pid 501390:tid 501550] [client 20.48.160.90:30748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/media.php"] [unique_id "apPksKg6skwqJ2NpVh_G0QAAAjI"]
[Sun Aug 30 03:07:12.355236 2026] [security2:error] [pid 501390:tid 501531] [client 20.220.10.235:20703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/file66.php"] [unique_id "apPksKg6skwqJ2NpVh_G4wAAAh8"]
[Sun Aug 30 03:07:12.362720 2026] [authz_core:error] [pid 501390:tid 501521] [client 66.249.66.72:50958] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:12.363148 2026] [authz_core:error] [pid 501390:tid 501521] [client 66.249.66.72:50958] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:12.375880 2026] [security2:error] [pid 501390:tid 501554] [client 68.155.159.216:61677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/cong.php"] [unique_id "apPksKg6skwqJ2NpVh_G6AAAAjY"]
[Sun Aug 30 03:07:12.407061 2026] [security2:error] [pid 501390:tid 501605] [client 20.48.250.41:53412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/class.php"] [unique_id "apPksKg6skwqJ2NpVh_HJgAAAmk"]
[Sun Aug 30 03:07:12.415361 2026] [authz_core:error] [pid 501390:tid 501580] [client 216.73.216.128:1374] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:12.415858 2026] [authz_core:error] [pid 501390:tid 501580] [client 216.73.216.128:1374] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:12.454800 2026] [security2:error] [pid 499145:tid 499354] [client 4.205.62.107:51751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/cli_bootstrap.php"] [unique_id "apPksFJNq1G5uRhTNntcMQAAAE8"]
[Sun Aug 30 03:07:12.459897 2026] [security2:error] [pid 501390:tid 501558] [client 20.48.160.90:30826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/mac.php"] [unique_id "apPksKg6skwqJ2NpVh_HWAAAAjo"]
[Sun Aug 30 03:07:12.470786 2026] [security2:error] [pid 501390:tid 501520] [client 20.196.209.81:10899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/cron.php"] [unique_id "apPksKg6skwqJ2NpVh_HYQAAAhQ"]
[Sun Aug 30 03:07:12.484781 2026] [security2:error] [pid 501390:tid 501636] [client 68.155.159.216:65466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apPksKg6skwqJ2NpVh_HcQAAAog"]
[Sun Aug 30 03:07:12.487405 2026] [security2:error] [pid 501390:tid 501621] [client 20.48.250.41:45320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/fetch.php"] [unique_id "apPksKg6skwqJ2NpVh_HdQAAAnk"]
[Sun Aug 30 03:07:12.494310 2026] [security2:error] [pid 501390:tid 501552] [client 20.220.10.235:20700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/blnux.php"] [unique_id "apPksKg6skwqJ2NpVh_HgAAAAjQ"]
[Sun Aug 30 03:07:12.510382 2026] [authz_core:error] [pid 501390:tid 501619] [client 66.249.66.78:65480] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:12.510684 2026] [authz_core:error] [pid 501390:tid 501619] [client 66.249.66.78:65480] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:12.529924 2026] [security2:error] [pid 501390:tid 501642] [client 4.205.62.107:58067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/wp-tem.php"] [unique_id "apPksKg6skwqJ2NpVh_HpAAAAo4"]
[Sun Aug 30 03:07:12.547580 2026] [authz_core:error] [pid 501390:tid 501591] [client 66.249.66.77:49262] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:12.547851 2026] [authz_core:error] [pid 501390:tid 501591] [client 66.249.66.77:49262] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:12.548112 2026] [security2:error] [pid 501390:tid 501561] [client 20.48.250.41:53392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/8.php"] [unique_id "apPksKg6skwqJ2NpVh_HuAAAAj0"]
[Sun Aug 30 03:07:12.596066 2026] [security2:error] [pid 501390:tid 501644] [client 20.196.209.81:5712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/news-portal/error.php"] [unique_id "apPksKg6skwqJ2NpVh_H0wAAApA"]
[Sun Aug 30 03:07:12.597060 2026] [security2:error] [pid 501390:tid 501624] [client 114.119.136.95:35323] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.lordrcane.com"] [uri "/mechwarrior-online-back-to-the-31st-century-the-basics"] [unique_id "apPksKg6skwqJ2NpVh_H1gAAAnw"], referer: http://www.lordrcane.com/tag/mechwarrior/page/2
[Sun Aug 30 03:07:12.598267 2026] [security2:error] [pid 501390:tid 501629] [client 20.104.18.15:29640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/222.php"] [unique_id "apPksKg6skwqJ2NpVh_H2AAAAoE"]
[Sun Aug 30 03:07:12.615261 2026] [security2:error] [pid 499145:tid 499304] [client 4.205.62.107:64468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/X57.php"] [unique_id "apPksFJNq1G5uRhTNntcbAAAAB0"]
[Sun Aug 30 03:07:12.627528 2026] [security2:error] [pid 501390:tid 501587] [client 20.48.160.90:61485] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.arrowlandgroup.com"] [uri "/1.php"] [unique_id "apPksKg6skwqJ2NpVh_H5gAAAlc"]
[Sun Aug 30 03:07:12.627615 2026] [security2:error] [pid 501390:tid 501587] [client 20.48.160.90:61485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/1.php"] [unique_id "apPksKg6skwqJ2NpVh_H5gAAAlc"]
[Sun Aug 30 03:07:12.629037 2026] [security2:error] [pid 499145:tid 499289] [client 20.220.10.235:20697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/attack.php"] [unique_id "apPksFJNq1G5uRhTNntccAAAAA4"]
[Sun Aug 30 03:07:12.630117 2026] [security2:error] [pid 499145:tid 499364] [client 20.104.50.220:27102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/htadmin/login.php"] [unique_id "apPksFJNq1G5uRhTNntccQAAAFk"]
[Sun Aug 30 03:07:12.631067 2026] [security2:error] [pid 501390:tid 501626] [client 68.155.159.216:65524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/about/function.php"] [unique_id "apPksKg6skwqJ2NpVh_H6AAAAn4"]
[Sun Aug 30 03:07:12.631621 2026] [security2:error] [pid 499145:tid 499302] [client 68.155.159.216:62045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/hehehehe.php"] [unique_id "apPksFJNq1G5uRhTNntccgAAABs"]
[Sun Aug 30 03:07:12.641332 2026] [authz_core:error] [pid 501390:tid 501647] [client 66.249.66.75:42669] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:12.641604 2026] [authz_core:error] [pid 501390:tid 501647] [client 66.249.66.75:42669] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:12.654187 2026] [security2:error] [pid 501390:tid 501538] [client 20.48.250.41:45364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/vx.php"] [unique_id "apPksKg6skwqJ2NpVh_H6gAAAiY"]
[Sun Aug 30 03:07:12.719653 2026] [security2:error] [pid 501390:tid 501599] [client 20.48.250.41:53426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/0x0x.php"] [unique_id "apPksKg6skwqJ2NpVh_IFwAAAmM"]
[Sun Aug 30 03:07:12.731916 2026] [security2:error] [pid 501390:tid 501621] [client 20.104.18.15:34811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/key.php"] [unique_id "apPksKg6skwqJ2NpVh_IJgAAAnk"]
[Sun Aug 30 03:07:12.738531 2026] [security2:error] [pid 501390:tid 501603] [client 4.205.62.107:35970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPksKg6skwqJ2NpVh_IMQAAAmc"]
[Sun Aug 30 03:07:12.744046 2026] [security2:error] [pid 501390:tid 501605] [client 20.104.50.220:42755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/gg.php"] [unique_id "apPksKg6skwqJ2NpVh_INAAAAmk"]
[Sun Aug 30 03:07:12.753998 2026] [authz_core:error] [pid 499145:tid 499351] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IN
[Sun Aug 30 03:07:12.754261 2026] [authz_core:error] [pid 499145:tid 499351] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IN
[Sun Aug 30 03:07:12.759897 2026] [security2:error] [pid 501390:tid 501558] [client 20.48.160.90:37697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/classwithtostring.php"] [unique_id "apPksKg6skwqJ2NpVh_IPgAAAjo"]
[Sun Aug 30 03:07:12.764910 2026] [security2:error] [pid 501390:tid 501646] [client 20.220.10.235:20948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/wk/index.php"] [unique_id "apPksKg6skwqJ2NpVh_IQgAAApI"]
[Sun Aug 30 03:07:12.775291 2026] [security2:error] [pid 501390:tid 501539] [client 20.151.200.44:27143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/wp-the.php"] [unique_id "apPksKg6skwqJ2NpVh_ISgAAAic"]
[Sun Aug 30 03:07:12.788265 2026] [security2:error] [pid 501390:tid 501630] [client 20.48.250.41:46034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/global.php"] [unique_id "apPksKg6skwqJ2NpVh_IUAAAAoI"]
[Sun Aug 30 03:07:12.804352 2026] [security2:error] [pid 501390:tid 501538] [client 4.205.62.107:62117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/public/mah.php.php"] [unique_id "apPksKg6skwqJ2NpVh_IWwAAAiY"]
[Sun Aug 30 03:07:12.819978 2026] [security2:error] [pid 501390:tid 501535] [client 20.48.251.3:50002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/wp-konfig.backup.php"] [unique_id "apPksKg6skwqJ2NpVh_IaAAAAiM"]
[Sun Aug 30 03:07:12.827336 2026] [security2:error] [pid 501390:tid 501531] [client 20.104.18.15:51654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/av.php"] [unique_id "apPksKg6skwqJ2NpVh_IbQAAAh8"]
[Sun Aug 30 03:07:12.860321 2026] [security2:error] [pid 501390:tid 501562] [client 4.205.62.107:18766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/otuz1.php"] [unique_id "apPksKg6skwqJ2NpVh_IiQAAAj4"]
[Sun Aug 30 03:07:12.882307 2026] [security2:error] [pid 501390:tid 501544] [client 20.48.250.41:53486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/166.php"] [unique_id "apPksKg6skwqJ2NpVh_IlQAAAiw"]
[Sun Aug 30 03:07:12.895534 2026] [security2:error] [pid 501390:tid 501643] [client 20.220.10.235:20722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/dehnl.php"] [unique_id "apPksKg6skwqJ2NpVh_InAAAAo8"]
[Sun Aug 30 03:07:12.902323 2026] [security2:error] [pid 501390:tid 501625] [client 20.196.209.81:19090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/goat.php"] [unique_id "apPksKg6skwqJ2NpVh_IoAAAAn0"]
[Sun Aug 30 03:07:12.906574 2026] [security2:error] [pid 501390:tid 501533] [client 20.48.160.90:37980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp-ws68.php"] [unique_id "apPksKg6skwqJ2NpVh_IpgAAAiE"]
[Sun Aug 30 03:07:12.911996 2026] [security2:error] [pid 501390:tid 501568] [client 20.104.50.220:62830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/bypassing.php"] [unique_id "apPksKg6skwqJ2NpVh_IqAAAAkQ"]
[Sun Aug 30 03:07:12.914945 2026] [security2:error] [pid 501390:tid 501646] [client 4.205.62.107:32011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/gjm.php"] [unique_id "apPksKg6skwqJ2NpVh_IqQAAApI"]
[Sun Aug 30 03:07:12.938841 2026] [security2:error] [pid 501390:tid 501521] [client 20.48.250.41:45323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/fs.php"] [unique_id "apPksKg6skwqJ2NpVh_IsgAAAhU"]
[Sun Aug 30 03:07:12.952370 2026] [security2:error] [pid 501390:tid 501576] [client 20.48.251.3:45858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/file21.php"] [unique_id "apPksKg6skwqJ2NpVh_IugAAAkw"]
[Sun Aug 30 03:07:12.966722 2026] [authz_core:error] [pid 501390:tid 501608] [client 216.73.216.128:49027] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:12.967193 2026] [authz_core:error] [pid 501390:tid 501608] [client 216.73.216.128:49027] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:12.989600 2026] [security2:error] [pid 501390:tid 501556] [client 20.196.209.81:4884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/nvt/includes/plugins/wp-blog-header.php"] [unique_id "apPksKg6skwqJ2NpVh_I5wAAAjg"]
[Sun Aug 30 03:07:13.022971 2026] [security2:error] [pid 501390:tid 501639] [client 68.155.159.216:56322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/themes.php"] [unique_id "apPksag6skwqJ2NpVh_I-wAAAos"]
[Sun Aug 30 03:07:13.040038 2026] [security2:error] [pid 501390:tid 501532] [client 20.220.10.235:20716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/png.php"] [unique_id "apPksag6skwqJ2NpVh_JBwAAAiA"]
[Sun Aug 30 03:07:13.060943 2026] [security2:error] [pid 501390:tid 501548] [client 20.48.160.90:61539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/simple.php"] [unique_id "apPksag6skwqJ2NpVh_JIQAAAjA"]
[Sun Aug 30 03:07:13.066014 2026] [security2:error] [pid 501390:tid 501643] [client 20.104.50.220:16738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wander.php"] [unique_id "apPksag6skwqJ2NpVh_JJAAAAo8"]
[Sun Aug 30 03:07:13.073799 2026] [security2:error] [pid 501390:tid 501603] [client 20.48.250.41:53475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/h2a2ck.php"] [unique_id "apPksag6skwqJ2NpVh_JKwAAAmc"]
[Sun Aug 30 03:07:13.075430 2026] [security2:error] [pid 501390:tid 501592] [client 20.104.18.15:28625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/bless6.php"] [unique_id "apPksag6skwqJ2NpVh_JLQAAAlw"]
[Sun Aug 30 03:07:13.094110 2026] [security2:error] [pid 501390:tid 501532] [client 68.155.159.216:54235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/.well-known/index.php"] [unique_id "apPksag6skwqJ2NpVh_JOAAAAiA"]
[Sun Aug 30 03:07:13.102186 2026] [security2:error] [pid 499145:tid 499393] [client 20.48.250.41:45365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/ioxi.php"] [unique_id "apPksVJNq1G5uRhTNntc9AAAAHY"]
[Sun Aug 30 03:07:13.106676 2026] [security2:error] [pid 499145:tid 499312] [client 20.48.251.3:13396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/public/vx.php"] [unique_id "apPksVJNq1G5uRhTNntc9wAAACU"]
[Sun Aug 30 03:07:13.117705 2026] [security2:error] [pid 501390:tid 501590] [client 20.104.18.15:18311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/adminfuns.php"] [unique_id "apPksag6skwqJ2NpVh_JQQAAAlo"]
[Sun Aug 30 03:07:13.125161 2026] [lsapi:warn] [pid 501390:tid 501509] [remote 104.197.249.29:32768] [host tastylandscape.com] Backend log: PHP Warning: Use of undefined constant user_level - assumed 'user_level' (this will throw an Error in a future version of PHP) in /home4/tommed/public_html/wp-content/plugins/ultimate-google-analytics/ultimate_ga.php on line 524\n
[Sun Aug 30 03:07:13.139476 2026] [authz_core:error] [pid 501390:tid 501589] [client 66.249.66.73:49344] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:13.139781 2026] [authz_core:error] [pid 501390:tid 501589] [client 66.249.66.73:49344] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:13.142674 2026] [security2:error] [pid 499145:tid 499349] [client 4.205.62.107:2989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/requirements.php"] [unique_id "apPksVJNq1G5uRhTNntdBAAAAEo"]
[Sun Aug 30 03:07:13.150810 2026] [security2:error] [pid 501390:tid 501531] [client 20.104.50.220:32095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/qindex.php"] [unique_id "apPksag6skwqJ2NpVh_JVAAAAh8"]
[Sun Aug 30 03:07:13.156813 2026] [security2:error] [pid 501390:tid 501603] [client 4.205.62.107:22949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/error_log.php"] [unique_id "apPksag6skwqJ2NpVh_JWwAAAmc"]
[Sun Aug 30 03:07:13.157093 2026] [security2:error] [pid 501390:tid 501625] [client 20.104.18.15:44012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/dragonshell.php"] [unique_id "apPksag6skwqJ2NpVh_JXAAAAn0"]
[Sun Aug 30 03:07:13.170930 2026] [security2:error] [pid 501390:tid 501581] [client 20.220.10.235:20946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/txets.php"] [unique_id "apPksag6skwqJ2NpVh_JawAAAlE"]
[Sun Aug 30 03:07:13.174690 2026] [security2:error] [pid 501390:tid 501577] [client 20.104.50.220:46427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-plugins.php"] [unique_id "apPksag6skwqJ2NpVh_JcAAAAk0"]
[Sun Aug 30 03:07:13.177867 2026] [security2:error] [pid 501390:tid 501623] [client 20.104.18.15:23482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/kerang.php"] [unique_id "apPksag6skwqJ2NpVh_JdQAAAns"]
[Sun Aug 30 03:07:13.200831 2026] [security2:error] [pid 501390:tid 501578] [client 20.48.160.90:61555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/aaa.php"] [unique_id "apPksag6skwqJ2NpVh_JjgAAAk4"]
[Sun Aug 30 03:07:13.211918 2026] [security2:error] [pid 501390:tid 501631] [client 20.48.250.41:53390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/error_log.php"] [unique_id "apPksag6skwqJ2NpVh_JkwAAAoM"]
[Sun Aug 30 03:07:13.218002 2026] [authz_core:error] [pid 501390:tid 501577] [client 66.249.66.72:49382] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:13.218273 2026] [authz_core:error] [pid 501390:tid 501577] [client 66.249.66.72:49382] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:13.243708 2026] [authz_core:error] [pid 501390:tid 501630] [client 216.73.216.128:49027] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:13.244180 2026] [authz_core:error] [pid 501390:tid 501630] [client 216.73.216.128:49027] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:13.245737 2026] [authz_core:error] [pid 499145:tid 499388] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AU
[Sun Aug 30 03:07:13.246159 2026] [authz_core:error] [pid 499145:tid 499388] [client 74.7.243.204:51120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AU
[Sun Aug 30 03:07:13.262283 2026] [security2:error] [pid 501390:tid 501608] [client 20.48.250.41:45318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/bootstrap.php"] [unique_id "apPksag6skwqJ2NpVh_JvQAAAmw"]
[Sun Aug 30 03:07:13.265432 2026] [security2:error] [pid 501390:tid 501603] [client 20.104.50.220:5499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/allyson162.php"] [unique_id "apPksag6skwqJ2NpVh_JvgAAAmc"]
[Sun Aug 30 03:07:13.301829 2026] [security2:error] [pid 501390:tid 501530] [client 20.220.10.235:20689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/wp-login.php"] [unique_id "apPksag6skwqJ2NpVh_J3AAAAh4"]
[Sun Aug 30 03:07:13.306537 2026] [security2:error] [pid 501390:tid 501526] [client 46.166.199.190:53265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.199.166.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.betsydunlap.com"] [uri "/wp-comments-post.php"] [unique_id "apPksag6skwqJ2NpVh_J1AAAAho"], referer: http://www.betsydunlap.com/331-2/
[Sun Aug 30 03:07:13.306608 2026] [security2:error] [pid 501390:tid 501526] [client 46.166.199.190:53265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.betsydunlap.com"] [uri "/wp-comments-post.php"] [unique_id "apPksag6skwqJ2NpVh_J1AAAAho"], referer: http://www.betsydunlap.com/331-2/
[Sun Aug 30 03:07:13.330001 2026] [security2:error] [pid 501390:tid 501584] [client 20.104.18.15:13665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/sushi.php"] [unique_id "apPksag6skwqJ2NpVh_J8AAAAlQ"]
[Sun Aug 30 03:07:13.332905 2026] [security2:error] [pid 501390:tid 501579] [client 20.48.251.3:4679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/bootstrap.php"] [unique_id "apPksag6skwqJ2NpVh_J9AAAAk8"]
[Sun Aug 30 03:07:13.336439 2026] [security2:error] [pid 501390:tid 501647] [client 20.104.50.220:62798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/ty.php"] [unique_id "apPksag6skwqJ2NpVh_J-AAAApM"]
[Sun Aug 30 03:07:13.338379 2026] [authz_core:error] [pid 501390:tid 501610] [client 66.249.66.75:61294] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:13.338811 2026] [authz_core:error] [pid 501390:tid 501610] [client 66.249.66.75:61294] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:13.350770 2026] [security2:error] [pid 501390:tid 501644] [client 20.196.209.81:20298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/gg.php"] [unique_id "apPksag6skwqJ2NpVh_KAgAAApA"]
[Sun Aug 30 03:07:13.369924 2026] [security2:error] [pid 501390:tid 501584] [client 20.48.250.41:53493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/403.php"] [unique_id "apPksag6skwqJ2NpVh_KGwAAAlQ"]
[Sun Aug 30 03:07:13.389351 2026] [authz_core:error] [pid 501390:tid 501608] [client 66.249.66.76:52340] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:13.389829 2026] [authz_core:error] [pid 501390:tid 501608] [client 66.249.66.76:52340] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:13.402391 2026] [security2:error] [pid 501390:tid 501624] [client 20.48.250.41:46042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/export.php"] [unique_id "apPksag6skwqJ2NpVh_KQgAAAnw"]
[Sun Aug 30 03:07:13.410558 2026] [security2:error] [pid 501390:tid 501646] [client 20.196.209.81:4907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/oceanwp/sass/components/plugins/panel.php"] [unique_id "apPksag6skwqJ2NpVh_KSgAAApI"]
[Sun Aug 30 03:07:13.418929 2026] [security2:error] [pid 501390:tid 501553] [client 216.73.216.128:28694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPksag6skwqJ2NpVh_KUQAAAjU"]
[Sun Aug 30 03:07:13.428006 2026] [authz_core:error] [pid 501390:tid 501571] [client 66.249.66.74:38401] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:13.428265 2026] [authz_core:error] [pid 501390:tid 501571] [client 66.249.66.74:38401] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:13.430101 2026] [security2:error] [pid 501390:tid 501616] [client 20.104.50.220:61664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/images/sym.php"] [unique_id "apPksag6skwqJ2NpVh_KWgAAAnQ"]
[Sun Aug 30 03:07:13.436982 2026] [security2:error] [pid 501390:tid 501601] [client 20.220.10.235:20936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/wp-access.php"] [unique_id "apPksag6skwqJ2NpVh_KXwAAAmU"]
[Sun Aug 30 03:07:13.458276 2026] [security2:error] [pid 501390:tid 501555] [client 20.104.50.220:33211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/666.php"] [unique_id "apPksag6skwqJ2NpVh_KcwAAAjc"]
[Sun Aug 30 03:07:13.470982 2026] [lsapi:warn] [pid 501390:tid 501516] [remote 104.197.249.29:32769] [host tastylandscape.com] Backend log: PHP Warning: Use of undefined constant user_level - assumed 'user_level' (this will throw an Error in a future version of PHP) in /home4/tommed/public_html/wp-content/plugins/ultimate-google-analytics/ultimate_ga.php on line 524\n
[Sun Aug 30 03:07:13.510460 2026] [security2:error] [pid 501390:tid 501605] [client 20.48.250.41:53500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/cytyr.php"] [unique_id "apPksag6skwqJ2NpVh_KngAAAmk"]
[Sun Aug 30 03:07:13.527081 2026] [security2:error] [pid 501390:tid 501578] [client 20.151.200.44:47059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/sxxb.php"] [unique_id "apPksag6skwqJ2NpVh_KpwAAAk4"]
[Sun Aug 30 03:07:13.543239 2026] [security2:error] [pid 501390:tid 501606] [client 68.155.159.216:63531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-includes/js/index.php"] [unique_id "apPksag6skwqJ2NpVh_KtgAAAmo"]
[Sun Aug 30 03:07:13.558690 2026] [security2:error] [pid 501390:tid 501647] [client 20.48.250.41:45343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/gk.php"] [unique_id "apPksag6skwqJ2NpVh_KvAAAApM"]
[Sun Aug 30 03:07:13.566998 2026] [security2:error] [pid 501390:tid 501564] [client 20.220.10.235:20694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/wp-content/admin.php"] [unique_id "apPksag6skwqJ2NpVh_KwwAAAkA"]
[Sun Aug 30 03:07:13.574748 2026] [proxy_http:error] [pid 499145:tid 499311] (20014)Internal error (specific information not available): [client 34.125.55.247:48096] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:13.574765 2026] [proxy:error] [pid 499145:tid 499311] [client 34.125.55.247:48096] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/root/.anthropic/config.json
[Sun Aug 30 03:07:13.583097 2026] [security2:error] [pid 499145:tid 499311] [client 34.125.55.247:48096] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "502"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/502.shtml"] [unique_id "apPksVJNq1G5uRhTNntdpgAAACQ"]
[Sun Aug 30 03:07:13.591004 2026] [security2:error] [pid 501390:tid 501636] [client 68.155.159.216:61358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/lock.php"] [unique_id "apPksag6skwqJ2NpVh_K1gAAAog"]
[Sun Aug 30 03:07:13.593382 2026] [security2:error] [pid 501390:tid 501547] [client 4.205.62.107:56662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/dd.php"] [unique_id "apPksag6skwqJ2NpVh_K3QAAAi8"]
[Sun Aug 30 03:07:13.601690 2026] [proxy_http:error] [pid 501390:tid 501576] (20014)Internal error (specific information not available): [client 34.125.55.247:48108] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:13.601703 2026] [proxy:error] [pid 501390:tid 501576] [client 34.125.55.247:48108] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/@fs/app/.anthropic/config.json
[Sun Aug 30 03:07:13.607298 2026] [proxy_http:error] [pid 499145:tid 499355] (20014)Internal error (specific information not available): [client 34.125.55.247:48106] AH01102: error reading status line from remote server 127.0.0.1:2082, referer: https://cpanel.engaginggoddaily.com/@fs/root/.claude/settings.json?raw??
[Sun Aug 30 03:07:13.623784 2026] [security2:error] [pid 501390:tid 501647] [client 20.48.160.90:61521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/shiny.php"] [unique_id "apPksag6skwqJ2NpVh_K9gAAApM"]
[Sun Aug 30 03:07:13.624283 2026] [authz_core:error] [pid 499145:tid 499309] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fmultipart
[Sun Aug 30 03:07:13.624549 2026] [authz_core:error] [pid 499145:tid 499309] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fmultipart
[Sun Aug 30 03:07:13.660975 2026] [security2:error] [pid 501390:tid 501599] [client 20.48.250.41:53448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/galer.php"] [unique_id "apPksag6skwqJ2NpVh_LAwAAAmM"]
[Sun Aug 30 03:07:13.664487 2026] [security2:error] [pid 501390:tid 501605] [client 4.205.62.107:65303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/txets.php"] [unique_id "apPksag6skwqJ2NpVh_LBwAAAmk"]
[Sun Aug 30 03:07:13.687269 2026] [security2:error] [pid 501390:tid 501566] [client 20.48.250.41:45362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/logs1.php"] [unique_id "apPksag6skwqJ2NpVh_LDQAAAkI"]
[Sun Aug 30 03:07:13.698488 2026] [security2:error] [pid 501390:tid 501544] [client 20.220.10.235:20704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/log.php"] [unique_id "apPksag6skwqJ2NpVh_LGgAAAiw"]
[Sun Aug 30 03:07:13.738366 2026] [security2:error] [pid 501390:tid 501527] [client 20.104.18.15:29641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/key.php"] [unique_id "apPksag6skwqJ2NpVh_LRQAAAhs"]
[Sun Aug 30 03:07:13.739115 2026] [security2:error] [pid 501390:tid 501634] [client 68.155.159.216:12388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apPksag6skwqJ2NpVh_LRwAAAoY"]
[Sun Aug 30 03:07:13.741818 2026] [security2:error] [pid 501390:tid 501627] [client 20.196.209.81:1565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/defaults.php"] [unique_id "apPksag6skwqJ2NpVh_LSgAAAn8"]
[Sun Aug 30 03:07:13.752575 2026] [security2:error] [pid 501390:tid 501561] [client 20.48.160.90:37717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/goods.php"] [unique_id "apPksag6skwqJ2NpVh_LUAAAAj0"]
[Sun Aug 30 03:07:13.766936 2026] [security2:error] [pid 501390:tid 501542] [client 20.104.50.220:27544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/manage/login.php"] [unique_id "apPksag6skwqJ2NpVh_LVwAAAio"]
[Sun Aug 30 03:07:13.770882 2026] [authz_core:error] [pid 501390:tid 501631] [client 74.7.243.204:34708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_HK
[Sun Aug 30 03:07:13.771194 2026] [authz_core:error] [pid 501390:tid 501631] [client 74.7.243.204:34708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_HK
[Sun Aug 30 03:07:13.773622 2026] [security2:error] [pid 501390:tid 501603] [client 4.205.62.107:64499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/register.php"] [unique_id "apPksag6skwqJ2NpVh_LTwAAAmc"]
[Sun Aug 30 03:07:13.789835 2026] [security2:error] [pid 501390:tid 501609] [client 34.125.55.247:48140] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/@fs/var/task/.env"] [unique_id "apPksag6skwqJ2NpVh_LZgAAAm0"]
[Sun Aug 30 03:07:13.790401 2026] [security2:error] [pid 499145:tid 499400] [client 34.125.55.247:48096] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/@fs/proc/self/cwd/.env"] [unique_id "apPksVJNq1G5uRhTNntd8gAAAH0"]
[Sun Aug 30 03:07:13.790845 2026] [authz_core:error] [pid 501390:tid 501564] [client 216.73.216.128:47669] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:13.791323 2026] [authz_core:error] [pid 501390:tid 501564] [client 216.73.216.128:47669] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:13.801328 2026] [security2:error] [pid 501390:tid 501526] [client 34.125.55.247:48124] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.engaginggoddaily.com"] [uri "/@fs/proc/self/environ"] [unique_id "apPksag6skwqJ2NpVh_LcwAAAho"]
[Sun Aug 30 03:07:13.801784 2026] [security2:error] [pid 501390:tid 501528] [client 20.196.209.81:15108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/options.php"] [unique_id "apPksag6skwqJ2NpVh_LdQAAAhw"]
[Sun Aug 30 03:07:13.801999 2026] [proxy_http:error] [pid 501390:tid 501526] (20014)Internal error (specific information not available): [client 34.125.55.247:48124] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:13.816580 2026] [security2:error] [pid 501390:tid 501611] [client 34.125.55.247:48108] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.engaginggoddaily.com"] [uri "/@fs/proc/self/environ"] [unique_id "apPksag6skwqJ2NpVh_LfAAAAm8"]
[Sun Aug 30 03:07:13.830310 2026] [security2:error] [pid 499145:tid 499401] [client 34.125.55.247:48096] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.engaginggoddaily.com"] [uri "/@fs/proc/self/environ"] [unique_id "apPksVJNq1G5uRhTNntd_wAAAH4"]
[Sun Aug 30 03:07:13.831234 2026] [security2:error] [pid 501390:tid 501587] [client 20.220.10.235:20691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/xwpg.php"] [unique_id "apPksag6skwqJ2NpVh_LjwAAAlc"]
[Sun Aug 30 03:07:13.831857 2026] [security2:error] [pid 501390:tid 501555] [client 20.48.250.41:46040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/inege.php"] [unique_id "apPksag6skwqJ2NpVh_LkQAAAjc"]
[Sun Aug 30 03:07:13.832480 2026] [security2:error] [pid 501390:tid 501637] [client 20.48.250.41:53454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/baixy.php"] [unique_id "apPksag6skwqJ2NpVh_LkgAAAok"]
[Sun Aug 30 03:07:13.844734 2026] [security2:error] [pid 501390:tid 501629] [client 34.125.55.247:48140] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.engaginggoddaily.com"] [uri "/@fs/proc/self/environ"] [unique_id "apPksag6skwqJ2NpVh_LngAAAoE"]
[Sun Aug 30 03:07:13.859297 2026] [security2:error] [pid 501390:tid 501550] [client 34.125.55.247:48160] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.engaginggoddaily.com"] [uri "/@fs/proc/self/environ"] [unique_id "apPksag6skwqJ2NpVh_LqgAAAjI"]
[Sun Aug 30 03:07:13.870119 2026] [security2:error] [pid 499145:tid 499378] [client 20.104.18.15:34755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/chosen.php"] [unique_id "apPksVJNq1G5uRhTNnteCgAAAGc"]
[Sun Aug 30 03:07:13.873790 2026] [security2:error] [pid 501390:tid 501568] [client 34.125.55.247:48154] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.engaginggoddaily.com"] [uri "/@fs/proc/self/environ"] [unique_id "apPksag6skwqJ2NpVh_LrgAAAkQ"]
[Sun Aug 30 03:07:13.874961 2026] [security2:error] [pid 501390:tid 501635] [client 195.178.110.247:14038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ermes-it-org.webnet-hosting4.com"] [uri "/index.php"] [unique_id "apPksag6skwqJ2NpVh_LsQAAAoc"]
[Sun Aug 30 03:07:13.891560 2026] [security2:error] [pid 501390:tid 501552] [client 20.104.50.220:42784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/gelis.php"] [unique_id "apPksag6skwqJ2NpVh_LuAAAAjQ"]
[Sun Aug 30 03:07:13.891783 2026] [security2:error] [pid 501390:tid 501520] [client 4.205.62.107:36021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/cloud.php"] [unique_id "apPksag6skwqJ2NpVh_LuQAAAhQ"]
[Sun Aug 30 03:07:13.901761 2026] [security2:error] [pid 501390:tid 501645] [client 68.155.159.216:62067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apPksag6skwqJ2NpVh_LvwAAApE"]
[Sun Aug 30 03:07:13.911198 2026] [authz_core:error] [pid 501390:tid 501544] [client 66.249.66.33:36421] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:13.911476 2026] [authz_core:error] [pid 501390:tid 501544] [client 66.249.66.33:36421] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:13.919402 2026] [security2:error] [pid 501390:tid 501587] [client 34.125.55.247:48164] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.engaginggoddaily.com"] [uri "/@fs/proc/self/environ"] [unique_id "apPksag6skwqJ2NpVh_LyQAAAlc"]
[Sun Aug 30 03:07:13.937484 2026] [security2:error] [pid 501390:tid 501641] [client 20.48.160.90:38014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/000.php/index.php"] [unique_id "apPksag6skwqJ2NpVh_LzQAAAo0"]
[Sun Aug 30 03:07:13.942194 2026] [security2:error] [pid 501390:tid 501619] [client 4.205.62.107:62033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/zaza.php"] [unique_id "apPksag6skwqJ2NpVh_LzwAAAnc"]
[Sun Aug 30 03:07:13.957545 2026] [security2:error] [pid 501390:tid 501536] [client 20.48.251.3:49979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/packed.php"] [unique_id "apPksag6skwqJ2NpVh_L3wAAAiQ"]
[Sun Aug 30 03:07:13.963863 2026] [security2:error] [pid 501390:tid 501551] [client 20.48.250.41:46062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/wp-link10.php"] [unique_id "apPksag6skwqJ2NpVh_L5wAAAjM"]
[Sun Aug 30 03:07:13.975015 2026] [security2:error] [pid 501390:tid 501574] [client 20.220.10.235:20954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/sxxb.php"] [unique_id "apPksag6skwqJ2NpVh_L-QAAAko"]
[Sun Aug 30 03:07:13.976709 2026] [authz_core:error] [pid 501390:tid 501582] [client 216.73.216.128:47669] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:13.978107 2026] [authz_core:error] [pid 501390:tid 501582] [client 216.73.216.128:47669] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:13.985181 2026] [security2:error] [pid 501390:tid 501619] [client 20.104.18.15:51697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/images.php"] [unique_id "apPksag6skwqJ2NpVh_MBQAAAnc"]
[Sun Aug 30 03:07:13.994019 2026] [security2:error] [pid 501390:tid 501632] [client 20.48.250.41:53401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/ava.php"] [unique_id "apPksag6skwqJ2NpVh_MCwAAAoQ"]
[Sun Aug 30 03:07:13.998283 2026] [authz_core:error] [pid 501390:tid 501642] [client 66.249.66.76:55046] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:13.998697 2026] [authz_core:error] [pid 501390:tid 501642] [client 66.249.66.76:55046] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:14.012526 2026] [security2:error] [pid 501390:tid 501606] [client 4.205.62.107:18985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/update.php"] [unique_id "apPksqg6skwqJ2NpVh_MFgAAAmo"]
[Sun Aug 30 03:07:14.045531 2026] [security2:error] [pid 501390:tid 501596] [client 195.178.110.247:44494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ermes-it-org.webnet-hosting4.com"] [uri "/index.php"] [unique_id "apPksqg6skwqJ2NpVh_MMQAAAmA"]
[Sun Aug 30 03:07:14.046540 2026] [security2:error] [pid 501390:tid 501631] [client 20.104.50.220:52808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/bypshell.php"] [unique_id "apPksqg6skwqJ2NpVh_MNAAAAoM"]
[Sun Aug 30 03:07:14.067584 2026] [authz_core:error] [pid 501390:tid 501597] [client 216.73.216.128:1374] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:14.068075 2026] [authz_core:error] [pid 501390:tid 501597] [client 216.73.216.128:1374] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:14.070457 2026] [security2:error] [pid 501390:tid 501522] [client 20.48.160.90:61500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/Jcrop.php"] [unique_id "apPksqg6skwqJ2NpVh_MSAAAAhY"]
[Sun Aug 30 03:07:14.077975 2026] [authz_core:error] [pid 501390:tid 501577] [client 66.249.66.73:52268] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:14.078403 2026] [authz_core:error] [pid 501390:tid 501577] [client 66.249.66.73:52268] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:14.094950 2026] [security2:error] [pid 501390:tid 501540] [client 20.48.250.41:45375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/ww.php"] [unique_id "apPksqg6skwqJ2NpVh_MXwAAAig"]
[Sun Aug 30 03:07:14.128915 2026] [security2:error] [pid 501390:tid 501563] [client 68.155.159.216:11136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-mail.php"] [unique_id "apPksqg6skwqJ2NpVh_MbgAAAj8"]
[Sun Aug 30 03:07:14.144911 2026] [security2:error] [pid 501390:tid 501524] [client 20.48.250.41:53411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/gdn.php"] [unique_id "apPksqg6skwqJ2NpVh_MeQAAAhg"]
[Sun Aug 30 03:07:14.154062 2026] [security2:error] [pid 501390:tid 501542] [client 20.220.10.235:20732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/dx.php"] [unique_id "apPksqg6skwqJ2NpVh_MggAAAio"]
[Sun Aug 30 03:07:14.182980 2026] [security2:error] [pid 501390:tid 501606] [client 20.48.251.3:7412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/mcebraed.php"] [unique_id "apPksqg6skwqJ2NpVh_MoAAAAmo"]
[Sun Aug 30 03:07:14.187759 2026] [security2:error] [pid 501390:tid 501567] [client 20.196.209.81:19092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/h.php"] [unique_id "apPksqg6skwqJ2NpVh_MowAAAkM"]
[Sun Aug 30 03:07:14.195952 2026] [security2:error] [pid 501390:tid 501538] [client 20.196.209.81:5714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/panel.php"] [unique_id "apPksqg6skwqJ2NpVh_MrAAAAiY"]
[Sun Aug 30 03:07:14.201639 2026] [security2:error] [pid 501390:tid 501639] [client 20.48.160.90:37708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/35iDq8NAjLu.php"] [unique_id "apPksqg6skwqJ2NpVh_MtAAAAos"]
[Sun Aug 30 03:07:14.214936 2026] [security2:error] [pid 501390:tid 501619] [client 20.104.50.220:17308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/ha.php"] [unique_id "apPksqg6skwqJ2NpVh_MugAAAnc"]
[Sun Aug 30 03:07:14.214980 2026] [security2:error] [pid 501390:tid 501546] [client 20.104.18.15:28636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/special.php"] [unique_id "apPksqg6skwqJ2NpVh_MuwAAAi4"]
[Sun Aug 30 03:07:14.216099 2026] [security2:error] [pid 501390:tid 501632] [client 68.155.159.216:55119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-content/themes/too.php"] [unique_id "apPksqg6skwqJ2NpVh_MvQAAAoQ"]
[Sun Aug 30 03:07:14.222607 2026] [security2:error] [pid 499145:tid 499372] [client 20.48.250.41:45331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/w1px.php"] [unique_id "apPkslJNq1G5uRhTNntedAAAAGE"]
[Sun Aug 30 03:07:14.237714 2026] [security2:error] [pid 501390:tid 501589] [client 20.48.251.3:56363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/log.php"] [unique_id "apPksqg6skwqJ2NpVh_MyQAAAlk"]
[Sun Aug 30 03:07:14.262396 2026] [security2:error] [pid 499145:tid 499335] [client 20.104.18.15:18313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/classwithtostring.php"] [unique_id "apPkslJNq1G5uRhTNntehQAAADw"]
[Sun Aug 30 03:07:14.271834 2026] [authz_core:error] [pid 501390:tid 501572] [client 74.7.243.204:34708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NG
[Sun Aug 30 03:07:14.272094 2026] [authz_core:error] [pid 501390:tid 501572] [client 74.7.243.204:34708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NG
[Sun Aug 30 03:07:14.275809 2026] [security2:error] [pid 501390:tid 501613] [client 20.48.250.41:50137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/f2.php"] [unique_id "apPksqg6skwqJ2NpVh_M6gAAAnE"]
[Sun Aug 30 03:07:14.283992 2026] [security2:error] [pid 501390:tid 501593] [client 20.220.10.235:20929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPksqg6skwqJ2NpVh_M8wAAAl0"]
[Sun Aug 30 03:07:14.291949 2026] [security2:error] [pid 501390:tid 501630] [client 4.205.62.107:62284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/phina.php"] [unique_id "apPksqg6skwqJ2NpVh_M9wAAAoI"]
[Sun Aug 30 03:07:14.295503 2026] [security2:error] [pid 501390:tid 501646] [client 4.205.62.107:2813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/var/www/wallet/index.php"] [unique_id "apPksqg6skwqJ2NpVh_M_QAAApI"]
[Sun Aug 30 03:07:14.310615 2026] [security2:error] [pid 499145:tid 499386] [client 20.104.50.220:32110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/radio.php"] [unique_id "apPkslJNq1G5uRhTNntemwAAAG8"]
[Sun Aug 30 03:07:14.313132 2026] [security2:error] [pid 501390:tid 501558] [client 20.104.18.15:23549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/m.php"] [unique_id "apPksqg6skwqJ2NpVh_NBwAAAjo"]
[Sun Aug 30 03:07:14.313439 2026] [security2:error] [pid 501390:tid 501583] [client 20.104.50.220:46184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-rss.php"] [unique_id "apPksqg6skwqJ2NpVh_NCAAAAlM"]
[Sun Aug 30 03:07:14.332418 2026] [security2:error] [pid 501390:tid 501569] [client 20.48.160.90:30834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/btx25.php"] [unique_id "apPksqg6skwqJ2NpVh_NGQAAAkU"]
[Sun Aug 30 03:07:14.340700 2026] [security2:error] [pid 501390:tid 501588] [client 20.104.18.15:43928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/wp-safe.php"] [unique_id "apPksqg6skwqJ2NpVh_NIgAAAlg"]
[Sun Aug 30 03:07:14.341063 2026] [authz_core:error] [pid 501390:tid 501537] [client 66.249.66.77:57278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:14.341519 2026] [authz_core:error] [pid 501390:tid 501537] [client 66.249.66.77:57278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:14.353225 2026] [security2:error] [pid 501390:tid 501551] [client 20.104.49.130:63236] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.killmigraine.com"] [uri "/1.php"] [unique_id "apPksqg6skwqJ2NpVh_NOAAAAjM"]
[Sun Aug 30 03:07:14.353305 2026] [security2:error] [pid 501390:tid 501551] [client 20.104.49.130:63236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/1.php"] [unique_id "apPksqg6skwqJ2NpVh_NOAAAAjM"]
[Sun Aug 30 03:07:14.360442 2026] [security2:error] [pid 501390:tid 501541] [client 20.151.200.44:55704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/wp-login.php"] [unique_id "apPksqg6skwqJ2NpVh_NQAAAAik"]
[Sun Aug 30 03:07:14.372087 2026] [security2:error] [pid 501390:tid 501637] [client 20.48.250.41:46049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/to.php"] [unique_id "apPksqg6skwqJ2NpVh_NRwAAAok"]
[Sun Aug 30 03:07:14.412866 2026] [security2:error] [pid 501390:tid 501532] [client 20.48.250.41:53388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/grsiuk.php"] [unique_id "apPksqg6skwqJ2NpVh_NZwAAAiA"]
[Sun Aug 30 03:07:14.414707 2026] [security2:error] [pid 501390:tid 501619] [client 20.220.10.235:20673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/xda.php"] [unique_id "apPksqg6skwqJ2NpVh_NaQAAAnc"]
[Sun Aug 30 03:07:14.415341 2026] [security2:error] [pid 501390:tid 501543] [client 20.104.50.220:6142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/digiwoll.php"] [unique_id "apPksqg6skwqJ2NpVh_NagAAAis"]
[Sun Aug 30 03:07:14.430639 2026] [authz_core:error] [pid 499145:tid 499330] [client 216.73.216.128:41075] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:14.430927 2026] [authz_core:error] [pid 499145:tid 499330] [client 216.73.216.128:41075] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:14.461428 2026] [security2:error] [pid 501390:tid 501627] [client 20.48.160.90:37972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/radio.php"] [unique_id "apPksqg6skwqJ2NpVh_NgwAAAn8"]
[Sun Aug 30 03:07:14.470566 2026] [security2:error] [pid 501390:tid 501520] [client 20.104.18.15:13607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/manga.php"] [unique_id "apPksqg6skwqJ2NpVh_NiwAAAhQ"]
[Sun Aug 30 03:07:14.470781 2026] [security2:error] [pid 501390:tid 501615] [client 20.48.251.3:5074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/333.php"] [unique_id "apPksqg6skwqJ2NpVh_NjQAAAnM"]
[Sun Aug 30 03:07:14.479919 2026] [security2:error] [pid 501390:tid 501574] [client 20.104.50.220:29178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/1945.php"] [unique_id "apPksqg6skwqJ2NpVh_NmQAAAko"]
[Sun Aug 30 03:07:14.490221 2026] [security2:error] [pid 501390:tid 501634] [client 114.119.140.190:44751] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mimiflores.com"] [uri "/category/family/"] [unique_id "apPksqg6skwqJ2NpVh_NpAAAAoY"], referer: https://mimiflores.com/mommy-and-me-hikingnature-trailing/
[Sun Aug 30 03:07:14.525476 2026] [security2:error] [pid 501390:tid 501616] [client 20.48.250.41:46037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/thui.php"] [unique_id "apPksqg6skwqJ2NpVh_NywAAAnQ"]
[Sun Aug 30 03:07:14.539816 2026] [security2:error] [pid 501390:tid 501526] [client 20.48.250.41:50134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/wp-scr1pts.php"] [unique_id "apPksqg6skwqJ2NpVh_N1gAAAho"]
[Sun Aug 30 03:07:14.546112 2026] [security2:error] [pid 501390:tid 501548] [client 20.220.10.235:20734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPksqg6skwqJ2NpVh_N3QAAAjA"]
[Sun Aug 30 03:07:14.572342 2026] [security2:error] [pid 501390:tid 501567] [client 20.104.50.220:61682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/images/shell.php"] [unique_id "apPksqg6skwqJ2NpVh_N6AAAAkM"]
[Sun Aug 30 03:07:14.584293 2026] [security2:error] [pid 501390:tid 501601] [client 20.196.209.81:2000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/num.php"] [unique_id "apPksqg6skwqJ2NpVh_N7gAAAmU"]
[Sun Aug 30 03:07:14.590498 2026] [security2:error] [pid 501390:tid 501529] [client 20.48.160.90:37652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/dex.php"] [unique_id "apPksqg6skwqJ2NpVh_N7wAAAh0"]
[Sun Aug 30 03:07:14.590682 2026] [security2:error] [pid 501390:tid 501588] [client 20.196.209.81:4876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/reboot/assets/js/plugins/home.php"] [unique_id "apPksqg6skwqJ2NpVh_N8AAAAlg"]
[Sun Aug 30 03:07:14.624996 2026] [security2:error] [pid 501390:tid 501578] [client 20.104.50.220:33034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/Xzd.php"] [unique_id "apPksqg6skwqJ2NpVh_OBQAAAk4"]
[Sun Aug 30 03:07:14.650661 2026] [security2:error] [pid 501390:tid 501534] [client 68.155.159.216:61684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-content/index.php"] [unique_id "apPksqg6skwqJ2NpVh_OFQAAAiI"]
[Sun Aug 30 03:07:14.658493 2026] [security2:error] [pid 501390:tid 501619] [client 20.48.250.41:46048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/Jcrop.php"] [unique_id "apPksqg6skwqJ2NpVh_OGQAAAnc"]
[Sun Aug 30 03:07:14.659876 2026] [security2:error] [pid 501390:tid 501629] [client 4.205.62.107:31700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/configuration.php"] [unique_id "apPksqg6skwqJ2NpVh_OGwAAAoE"]
[Sun Aug 30 03:07:14.666504 2026] [security2:error] [pid 501390:tid 501579] [client 20.48.250.41:53376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/num.php"] [unique_id "apPksqg6skwqJ2NpVh_OHgAAAk8"]
[Sun Aug 30 03:07:14.675220 2026] [security2:error] [pid 501390:tid 501589] [client 20.220.10.235:20705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/t00l.php"] [unique_id "apPksqg6skwqJ2NpVh_OKAAAAlk"]
[Sun Aug 30 03:07:14.690184 2026] [authz_core:error] [pid 501390:tid 501564] [client 66.249.66.68:61211] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:14.690465 2026] [authz_core:error] [pid 501390:tid 501564] [client 66.249.66.68:61211] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:14.702492 2026] [authz_core:error] [pid 501390:tid 501555] [client 216.73.216.128:1374] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:14.702793 2026] [authz_core:error] [pid 501390:tid 501555] [client 216.73.216.128:1374] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:14.720892 2026] [security2:error] [pid 501390:tid 501576] [client 20.48.160.90:37986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/giodywky.php"] [unique_id "apPksqg6skwqJ2NpVh_OWQAAAkw"]
[Sun Aug 30 03:07:14.731108 2026] [security2:error] [pid 501390:tid 501610] [client 4.205.62.107:56604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/wp-tem.php"] [unique_id "apPksqg6skwqJ2NpVh_OZgAAAm4"]
[Sun Aug 30 03:07:14.744127 2026] [security2:error] [pid 501390:tid 501619] [client 68.155.159.216:63974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/index/function.php"] [unique_id "apPksqg6skwqJ2NpVh_OdgAAAnc"]
[Sun Aug 30 03:07:14.758264 2026] [authz_core:error] [pid 501390:tid 501623] [client 66.249.66.68:59138] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:14.758582 2026] [authz_core:error] [pid 501390:tid 501623] [client 66.249.66.68:59138] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:14.787838 2026] [authz_core:error] [pid 501390:tid 501525] [client 74.7.243.204:34708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AG
[Sun Aug 30 03:07:14.788280 2026] [authz_core:error] [pid 501390:tid 501525] [client 74.7.243.204:34708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AG
[Sun Aug 30 03:07:14.808092 2026] [security2:error] [pid 501390:tid 501580] [client 20.220.10.235:20687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/ls.php"] [unique_id "apPksqg6skwqJ2NpVh_OpgAAAlA"]
[Sun Aug 30 03:07:14.808864 2026] [security2:error] [pid 501390:tid 501619] [client 20.151.200.44:27284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/wt.php"] [unique_id "apPksqg6skwqJ2NpVh_OqAAAAnc"]
[Sun Aug 30 03:07:14.824375 2026] [security2:error] [pid 501390:tid 501537] [client 20.48.250.41:45359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/ws58.php"] [unique_id "apPksqg6skwqJ2NpVh_OswAAAiU"]
[Sun Aug 30 03:07:14.840707 2026] [security2:error] [pid 501390:tid 501644] [client 20.48.250.41:53444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/a4.php"] [unique_id "apPksqg6skwqJ2NpVh_OvAAAApA"]
[Sun Aug 30 03:07:14.852539 2026] [security2:error] [pid 501390:tid 501626] [client 20.48.160.90:37712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp-kz.php"] [unique_id "apPksqg6skwqJ2NpVh_OxgAAAn4"]
[Sun Aug 30 03:07:14.854886 2026] [security2:error] [pid 501390:tid 501609] [client 4.205.62.107:65316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/time.php"] [unique_id "apPksqg6skwqJ2NpVh_OygAAAm0"]
[Sun Aug 30 03:07:14.875236 2026] [security2:error] [pid 499145:tid 499349] [client 20.104.18.15:29174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/chosen.php"] [unique_id "apPkslJNq1G5uRhTNntfXAAAAEo"]
[Sun Aug 30 03:07:14.881935 2026] [security2:error] [pid 501390:tid 501633] [client 114.119.135.199:41879] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.concordservices-bali.com"] [uri "/finding_the_right_staff.php"] [unique_id "apPksqg6skwqJ2NpVh_O0QAAAoU"], referer: https://concordservices-bali.com/
[Sun Aug 30 03:07:14.901532 2026] [security2:error] [pid 501390:tid 501646] [client 68.155.159.216:12337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-admin/index.php"] [unique_id "apPksqg6skwqJ2NpVh_O1wAAApI"]
[Sun Aug 30 03:07:14.905257 2026] [security2:error] [pid 501390:tid 501601] [client 94.154.43.180:29900] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.uaeweb3.ae"] [uri "/.env"] [unique_id "apPksqg6skwqJ2NpVh_O2QAAAmU"]
[Sun Aug 30 03:07:14.905327 2026] [security2:error] [pid 501390:tid 501589] [client 20.104.50.220:27579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/TP/index.php"] [unique_id "apPksqg6skwqJ2NpVh_O2gAAAlk"]
[Sun Aug 30 03:07:14.936171 2026] [security2:error] [pid 501390:tid 501531] [client 20.220.10.235:20733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/css/000.php"] [unique_id "apPksqg6skwqJ2NpVh_O7gAAAh8"]
[Sun Aug 30 03:07:14.960418 2026] [security2:error] [pid 501390:tid 501563] [client 4.205.62.107:64666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/xqq.php"] [unique_id "apPksqg6skwqJ2NpVh_PAAAAAj8"]
[Sun Aug 30 03:07:14.968119 2026] [security2:error] [pid 501390:tid 501590] [client 20.48.250.41:53495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/tfm.php"] [unique_id "apPksqg6skwqJ2NpVh_PDgAAAlo"]
[Sun Aug 30 03:07:14.969519 2026] [security2:error] [pid 501390:tid 501526] [client 20.48.250.41:45368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/xs.php"] [unique_id "apPksqg6skwqJ2NpVh_PDwAAAho"]
[Sun Aug 30 03:07:14.980796 2026] [security2:error] [pid 501390:tid 501618] [client 20.196.209.81:19124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/abc.php"] [unique_id "apPksqg6skwqJ2NpVh_PGwAAAnY"]
[Sun Aug 30 03:07:15.002914 2026] [security2:error] [pid 501390:tid 501603] [client 20.48.160.90:37722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp-includes/ID3/getid.php"] [unique_id "apPks6g6skwqJ2NpVh_PKgAAAmc"]
[Sun Aug 30 03:07:15.010794 2026] [security2:error] [pid 501390:tid 501579] [client 20.196.209.81:13744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/salient/css/build/plugins/login.php"] [unique_id "apPks6g6skwqJ2NpVh_PMQAAAk8"]
[Sun Aug 30 03:07:15.030486 2026] [security2:error] [pid 501390:tid 501645] [client 4.205.62.107:36640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/kerang.php"] [unique_id "apPks6g6skwqJ2NpVh_PQQAAApE"]
[Sun Aug 30 03:07:15.036739 2026] [security2:error] [pid 501390:tid 501540] [client 20.104.18.15:34799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/file1221.php"] [unique_id "apPks6g6skwqJ2NpVh_PSAAAAig"]
[Sun Aug 30 03:07:15.039577 2026] [security2:error] [pid 501390:tid 501594] [client 20.104.50.220:42004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/FierzaXploit.php"] [unique_id "apPks6g6skwqJ2NpVh_PTQAAAl4"]
[Sun Aug 30 03:07:15.072887 2026] [authz_core:error] [pid 501390:tid 501613] [client 216.73.216.128:49027] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:15.073358 2026] [authz_core:error] [pid 501390:tid 501613] [client 216.73.216.128:49027] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:15.081540 2026] [security2:error] [pid 501390:tid 501620] [client 4.205.62.107:63940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/u88.php"] [unique_id "apPks6g6skwqJ2NpVh_PbwAAAng"]
[Sun Aug 30 03:07:15.096244 2026] [security2:error] [pid 501390:tid 501594] [client 20.48.251.3:49962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/wp-info.php"] [unique_id "apPks6g6skwqJ2NpVh_PeAAAAl4"]
[Sun Aug 30 03:07:15.118844 2026] [security2:error] [pid 501390:tid 501602] [client 20.220.10.235:20979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/cy.php"] [unique_id "apPks6g6skwqJ2NpVh_PfQAAAmY"]
[Sun Aug 30 03:07:15.121442 2026] [security2:error] [pid 501390:tid 501609] [client 20.48.250.41:53427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/Geforce.php"] [unique_id "apPks6g6skwqJ2NpVh_PfgAAAm0"]
[Sun Aug 30 03:07:15.122339 2026] [authz_core:error] [pid 499145:tid 499389] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fmultipart
[Sun Aug 30 03:07:15.122560 2026] [security2:error] [pid 501390:tid 501539] [client 20.104.49.130:58087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/x1da.php"] [unique_id "apPks6g6skwqJ2NpVh_PgAAAAic"]
[Sun Aug 30 03:07:15.122875 2026] [authz_core:error] [pid 499145:tid 499389] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fmultipart
[Sun Aug 30 03:07:15.136634 2026] [security2:error] [pid 501390:tid 501633] [client 20.104.18.15:51600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/ops.php"] [unique_id "apPks6g6skwqJ2NpVh_PhwAAAoU"]
[Sun Aug 30 03:07:15.144380 2026] [security2:error] [pid 501390:tid 501593] [client 20.48.160.90:30839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/session.php"] [unique_id "apPks6g6skwqJ2NpVh_PkQAAAl0"]
[Sun Aug 30 03:07:15.145029 2026] [security2:error] [pid 501390:tid 501572] [client 20.48.250.41:46022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/zu.php"] [unique_id "apPks6g6skwqJ2NpVh_PkgAAAkg"]
[Sun Aug 30 03:07:15.150811 2026] [security2:error] [pid 501390:tid 501569] [client 4.205.62.107:18665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/channels.php"] [unique_id "apPks6g6skwqJ2NpVh_PlgAAAkU"]
[Sun Aug 30 03:07:15.160606 2026] [authz_core:error] [pid 499145:tid 499369] [client 216.73.216.128:41075] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:15.160890 2026] [authz_core:error] [pid 499145:tid 499369] [client 216.73.216.128:41075] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:15.190765 2026] [security2:error] [pid 501390:tid 501593] [client 20.104.50.220:52835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/bingo.php"] [unique_id "apPks6g6skwqJ2NpVh_PwgAAAl0"]
[Sun Aug 30 03:07:15.235628 2026] [security2:error] [pid 501390:tid 501596] [client 68.155.159.216:56346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/cgi-bin/index.php"] [unique_id "apPks6g6skwqJ2NpVh_P3gAAAmA"]
[Sun Aug 30 03:07:15.249681 2026] [security2:error] [pid 501390:tid 501541] [client 20.220.10.235:20931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/admin.php/pindex.php"] [unique_id "apPks6g6skwqJ2NpVh_P9AAAAik"]
[Sun Aug 30 03:07:15.253571 2026] [security2:error] [pid 501390:tid 501647] [client 68.155.159.216:62072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-content/admin.php"] [unique_id "apPks6g6skwqJ2NpVh_P9wAAApM"]
[Sun Aug 30 03:07:15.274619 2026] [authz_core:error] [pid 501390:tid 501553] [client 74.7.243.204:34708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_DK
[Sun Aug 30 03:07:15.274976 2026] [authz_core:error] [pid 501390:tid 501553] [client 74.7.243.204:34708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_DK
[Sun Aug 30 03:07:15.275400 2026] [security2:error] [pid 501390:tid 501642] [client 20.48.160.90:37729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/eagle.php"] [unique_id "apPks6g6skwqJ2NpVh_QDAAAAo4"]
[Sun Aug 30 03:07:15.305013 2026] [security2:error] [pid 501390:tid 501523] [client 20.48.250.41:53416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/click.php"] [unique_id "apPks6g6skwqJ2NpVh_QJQAAAhc"]
[Sun Aug 30 03:07:15.305653 2026] [security2:error] [pid 501390:tid 501521] [client 20.48.250.41:45954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/lanka.php"] [unique_id "apPks6g6skwqJ2NpVh_QJwAAAhU"]
[Sun Aug 30 03:07:15.322173 2026] [security2:error] [pid 501390:tid 501561] [client 68.155.159.216:54247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/radio.php"] [unique_id "apPks6g6skwqJ2NpVh_QOQAAAj0"]
[Sun Aug 30 03:07:15.355658 2026] [security2:error] [pid 501390:tid 501567] [client 20.104.50.220:17230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/hur.php"] [unique_id "apPks6g6skwqJ2NpVh_QWgAAAkM"]
[Sun Aug 30 03:07:15.356780 2026] [lsapi:error] [pid 501390:tid 501403] [remote 49.204.117.214:42393] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.google.com/
[Sun Aug 30 03:07:15.356900 2026] [lsapi:error] [pid 501390:tid 501403] [remote 49.204.117.214:42393] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.google.com/
[Sun Aug 30 03:07:15.358278 2026] [lsapi:error] [pid 501390:tid 501403] [remote 49.204.117.214:42393] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n, referer: https://www.google.com/
[Sun Aug 30 03:07:15.358897 2026] [security2:error] [pid 501390:tid 501525] [client 20.104.18.15:28578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/fz.php"] [unique_id "apPks6g6skwqJ2NpVh_QXgAAAhk"]
[Sun Aug 30 03:07:15.369574 2026] [security2:error] [pid 501390:tid 501642] [client 20.48.251.3:56368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/ebahvhhh.php"] [unique_id "apPks6g6skwqJ2NpVh_QZgAAAo4"]
[Sun Aug 30 03:07:15.390485 2026] [security2:error] [pid 501390:tid 501617] [client 20.220.10.235:20729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/admin.php/csv.php"] [unique_id "apPks6g6skwqJ2NpVh_QeQAAAnU"]
[Sun Aug 30 03:07:15.401939 2026] [security2:error] [pid 501390:tid 501638] [client 20.196.209.81:4897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/security.php"] [unique_id "apPks6g6skwqJ2NpVh_QigAAAoo"]
[Sun Aug 30 03:07:15.413609 2026] [security2:error] [pid 501390:tid 501588] [client 20.104.18.15:18421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPks6g6skwqJ2NpVh_QkwAAAlg"]
[Sun Aug 30 03:07:15.421932 2026] [security2:error] [pid 501390:tid 501600] [client 20.48.160.90:37959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/up-kon.php"] [unique_id "apPks6g6skwqJ2NpVh_QngAAAmQ"]
[Sun Aug 30 03:07:15.427162 2026] [security2:error] [pid 501390:tid 501646] [client 4.205.62.107:62401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/koiy.php"] [unique_id "apPks6g6skwqJ2NpVh_QoAAAApI"]
[Sun Aug 30 03:07:15.427856 2026] [security2:error] [pid 501390:tid 501571] [client 20.48.251.3:45830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/server-info.php"] [unique_id "apPks6g6skwqJ2NpVh_QoQAAAkc"]
[Sun Aug 30 03:07:15.433560 2026] [security2:error] [pid 501390:tid 501549] [client 4.205.62.107:2305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/124.php"] [unique_id "apPks6g6skwqJ2NpVh_QpAAAAjE"]
[Sun Aug 30 03:07:15.450790 2026] [security2:error] [pid 501390:tid 501567] [client 20.104.50.220:46438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-singupp.php"] [unique_id "apPks6g6skwqJ2NpVh_QuQAAAkM"]
[Sun Aug 30 03:07:15.458905 2026] [security2:error] [pid 501390:tid 501624] [client 20.196.209.81:19924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/default.php"] [unique_id "apPks6g6skwqJ2NpVh_QwgAAAnw"]
[Sun Aug 30 03:07:15.471447 2026] [security2:error] [pid 501390:tid 501609] [client 20.104.18.15:23390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/fling.php"] [unique_id "apPks6g6skwqJ2NpVh_QzQAAAm0"]
[Sun Aug 30 03:07:15.474623 2026] [security2:error] [pid 501390:tid 501562] [client 20.48.250.41:50159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/ms.php"] [unique_id "apPks6g6skwqJ2NpVh_Q0AAAAj4"]
[Sun Aug 30 03:07:15.488101 2026] [security2:error] [pid 501390:tid 501620] [client 20.48.250.41:46074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/gettest.php"] [unique_id "apPks6g6skwqJ2NpVh_Q3AAAAng"]
[Sun Aug 30 03:07:15.489277 2026] [security2:error] [pid 501390:tid 501638] [client 20.104.50.220:31844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/shell20211028.php"] [unique_id "apPks6g6skwqJ2NpVh_Q4AAAAoo"]
[Sun Aug 30 03:07:15.519425 2026] [security2:error] [pid 501390:tid 501549] [client 20.104.18.15:43926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/gjewuagf.php"] [unique_id "apPks6g6skwqJ2NpVh_Q9wAAAjE"]
[Sun Aug 30 03:07:15.521847 2026] [security2:error] [pid 501390:tid 501532] [client 20.220.10.235:20695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/admin.php/700.php"] [unique_id "apPks6g6skwqJ2NpVh_Q-gAAAiA"]
[Sun Aug 30 03:07:15.524798 2026] [authz_core:error] [pid 501390:tid 501556] [client 66.249.66.73:59918] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:15.525199 2026] [authz_core:error] [pid 501390:tid 501556] [client 66.249.66.73:59918] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:15.551337 2026] [security2:error] [pid 501390:tid 501542] [client 20.48.160.90:38003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/tinny.php"] [unique_id "apPks6g6skwqJ2NpVh_RGgAAAio"]
[Sun Aug 30 03:07:15.558411 2026] [security2:error] [pid 501390:tid 501566] [client 20.104.50.220:6111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/tinyfilemanager.php"] [unique_id "apPks6g6skwqJ2NpVh_RHwAAAkI"]
[Sun Aug 30 03:07:15.568858 2026] [lsapi:error] [pid 501390:tid 501404] [remote 57.141.14.78:38198] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n
[Sun Aug 30 03:07:15.569440 2026] [security2:error] [pid 501390:tid 501643] [client 20.151.200.44:46926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/dx.php"] [unique_id "apPks6g6skwqJ2NpVh_RJAAAAo8"]
[Sun Aug 30 03:07:15.570378 2026] [lsapi:error] [pid 501390:tid 501404] [remote 57.141.14.78:38198] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n
[Sun Aug 30 03:07:15.608379 2026] [security2:error] [pid 499145:tid 499305] [client 20.48.251.3:4814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/G-in.php"] [unique_id "apPks1JNq1G5uRhTNntgXgAAAB4"]
[Sun Aug 30 03:07:15.608550 2026] [security2:error] [pid 501390:tid 501620] [client 216.73.216.128:49027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/about.html"] [unique_id "apPks6g6skwqJ2NpVh_RNQAAAng"]
[Sun Aug 30 03:07:15.619391 2026] [security2:error] [pid 501390:tid 501615] [client 20.48.250.41:53484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/zxekqlxb.php"] [unique_id "apPks6g6skwqJ2NpVh_RNgAAAnM"]
[Sun Aug 30 03:07:15.620588 2026] [security2:error] [pid 501390:tid 501569] [client 20.48.250.41:46030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/35.php"] [unique_id "apPks6g6skwqJ2NpVh_ROAAAAkU"]
[Sun Aug 30 03:07:15.630990 2026] [security2:error] [pid 501390:tid 501534] [client 20.104.50.220:29157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wos.php"] [unique_id "apPks6g6skwqJ2NpVh_RPgAAAiI"]
[Sun Aug 30 03:07:15.654993 2026] [security2:error] [pid 499145:tid 499346] [client 20.220.10.235:20937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/admin.php/007x.php"] [unique_id "apPks1JNq1G5uRhTNntgawAAAEc"]
[Sun Aug 30 03:07:15.688880 2026] [security2:error] [pid 501390:tid 501641] [client 20.48.160.90:61525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp-easy.php"] [unique_id "apPks6g6skwqJ2NpVh_RUAAAAo0"]
[Sun Aug 30 03:07:15.706173 2026] [security2:error] [pid 499145:tid 499395] [client 216.73.216.128:41075] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPks1JNq1G5uRhTNntgfQAAAHg"]
[Sun Aug 30 03:07:15.710172 2026] [security2:error] [pid 501390:tid 501594] [client 20.104.50.220:61638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/images/mini.php"] [unique_id "apPks6g6skwqJ2NpVh_RYQAAAl4"]
[Sun Aug 30 03:07:15.748902 2026] [security2:error] [pid 501390:tid 501646] [client 20.48.250.41:46028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/maraz.php"] [unique_id "apPks6g6skwqJ2NpVh_RjQAAApI"]
[Sun Aug 30 03:07:15.751152 2026] [security2:error] [pid 501390:tid 501590] [client 20.48.250.41:50112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/init.php"] [unique_id "apPks6g6skwqJ2NpVh_RkAAAAlo"]
[Sun Aug 30 03:07:15.754003 2026] [authz_core:error] [pid 501390:tid 501642] [client 74.7.243.204:34708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZM
[Sun Aug 30 03:07:15.754285 2026] [authz_core:error] [pid 501390:tid 501642] [client 74.7.243.204:34708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZM
[Sun Aug 30 03:07:15.784881 2026] [security2:error] [pid 501390:tid 501623] [client 20.220.10.235:20972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/admin.php/heex.php"] [unique_id "apPks6g6skwqJ2NpVh_RpwAAAns"]
[Sun Aug 30 03:07:15.794471 2026] [security2:error] [pid 501390:tid 501529] [client 20.196.209.81:5739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "apPks6g6skwqJ2NpVh_RsAAAAh0"]
[Sun Aug 30 03:07:15.796685 2026] [security2:error] [pid 501390:tid 501594] [client 20.104.50.220:33340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/ms-sitess.php"] [unique_id "apPks6g6skwqJ2NpVh_RsQAAAl4"]
[Sun Aug 30 03:07:15.818257 2026] [security2:error] [pid 501390:tid 501552] [client 68.155.159.216:62307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/about/function.php"] [unique_id "apPks6g6skwqJ2NpVh_RzQAAAjQ"]
[Sun Aug 30 03:07:15.821030 2026] [security2:error] [pid 499145:tid 499340] [client 20.48.160.90:37958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/d7.php"] [unique_id "apPks1JNq1G5uRhTNntgqAAAAEE"]
[Sun Aug 30 03:07:15.832060 2026] [security2:error] [pid 499145:tid 499316] [client 114.119.160.248:21585] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "padilakonline.com"] [uri "/es/49-roca"] [unique_id "apPks1JNq1G5uRhTNntgsAAAACk"], referer: https://padilakonline.com/es/inicio/338-tapa-asiento-inodoro-y-bidet-monaco-monocomando-madera-blanco-hc.html
[Sun Aug 30 03:07:15.850946 2026] [security2:error] [pid 501390:tid 501582] [client 20.104.18.15:13604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/asdfghj.php"] [unique_id "apPks6g6skwqJ2NpVh_R4QAAAlI"]
[Sun Aug 30 03:07:15.853228 2026] [security2:error] [pid 501390:tid 501634] [client 20.196.209.81:20865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/cloud.php"] [unique_id "apPks6g6skwqJ2NpVh_R5AAAAoY"]
[Sun Aug 30 03:07:15.866888 2026] [security2:error] [pid 499145:tid 499378] [client 68.155.159.216:61316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/.well-known/content.php"] [unique_id "apPks1JNq1G5uRhTNntgtwAAAGc"]
[Sun Aug 30 03:07:15.885471 2026] [security2:error] [pid 501390:tid 501535] [client 4.205.62.107:51773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/txets.php"] [unique_id "apPks6g6skwqJ2NpVh_R8QAAAiM"]
[Sun Aug 30 03:07:15.886753 2026] [security2:error] [pid 501390:tid 501576] [client 20.48.250.41:46038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/kbfr.php"] [unique_id "apPks6g6skwqJ2NpVh_R8gAAAkw"]
[Sun Aug 30 03:07:15.892842 2026] [authz_core:error] [pid 501390:tid 501576] [client 216.73.216.128:47669] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:15.893102 2026] [authz_core:error] [pid 501390:tid 501576] [client 216.73.216.128:47669] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:15.907700 2026] [security2:error] [pid 501390:tid 501590] [client 20.48.250.41:53377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/term.php"] [unique_id "apPks6g6skwqJ2NpVh_R_AAAAlo"]
[Sun Aug 30 03:07:15.914562 2026] [security2:error] [pid 501390:tid 501569] [client 20.220.10.235:20611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/tf.php"] [unique_id "apPks6g6skwqJ2NpVh_R_wAAAkU"]
[Sun Aug 30 03:07:15.968500 2026] [security2:error] [pid 501390:tid 501579] [client 20.48.160.90:37993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/v5.php"] [unique_id "apPks6g6skwqJ2NpVh_SHAAAAk8"]
[Sun Aug 30 03:07:16.008775 2026] [authz_core:error] [pid 501390:tid 501553] [client 66.249.66.202:52510] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:16.009039 2026] [authz_core:error] [pid 501390:tid 501553] [client 66.249.66.202:52510] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:16.021408 2026] [security2:error] [pid 501390:tid 501548] [client 20.48.250.41:46066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/wp-act.php"] [unique_id "apPktKg6skwqJ2NpVh_SOwAAAjA"]
[Sun Aug 30 03:07:16.025548 2026] [security2:error] [pid 501390:tid 501543] [client 20.104.18.15:29643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/file1221.php"] [unique_id "apPktKg6skwqJ2NpVh_SQAAAAis"]
[Sun Aug 30 03:07:16.053232 2026] [security2:error] [pid 501390:tid 501632] [client 20.220.10.235:20699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/update/da222.php"] [unique_id "apPktKg6skwqJ2NpVh_SUwAAAoQ"]
[Sun Aug 30 03:07:16.054262 2026] [security2:error] [pid 499145:tid 499392] [client 20.104.50.220:27556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/Broker.php"] [unique_id "apPktFJNq1G5uRhTNnthCQAAAHU"]
[Sun Aug 30 03:07:16.102548 2026] [security2:error] [pid 501390:tid 501611] [client 20.48.160.90:37651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/az.php"] [unique_id "apPktKg6skwqJ2NpVh_ScAAAAm8"]
[Sun Aug 30 03:07:16.139964 2026] [security2:error] [pid 501390:tid 501617] [client 4.205.62.107:64641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/a1vx.php"] [unique_id "apPktKg6skwqJ2NpVh_SfwAAAnU"]
[Sun Aug 30 03:07:16.143602 2026] [security2:error] [pid 501390:tid 501574] [client 4.205.62.107:65284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/doc.php"] [unique_id "apPktKg6skwqJ2NpVh_SgQAAAko"]
[Sun Aug 30 03:07:16.176682 2026] [security2:error] [pid 501390:tid 501521] [client 20.104.50.220:51547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/fxshell.php"] [unique_id "apPktKg6skwqJ2NpVh_SnQAAAhU"]
[Sun Aug 30 03:07:16.184394 2026] [security2:error] [pid 501390:tid 501562] [client 20.196.209.81:4894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/system.php"] [unique_id "apPktKg6skwqJ2NpVh_SqQAAAj4"]
[Sun Aug 30 03:07:16.203005 2026] [security2:error] [pid 501390:tid 501632] [client 20.220.10.235:20683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/qi.php"] [unique_id "apPktKg6skwqJ2NpVh_StQAAAoQ"]
[Sun Aug 30 03:07:16.207623 2026] [security2:error] [pid 501390:tid 501535] [client 20.104.18.15:34771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/nox.php"] [unique_id "apPktKg6skwqJ2NpVh_SuQAAAiM"]
[Sun Aug 30 03:07:16.218451 2026] [security2:error] [pid 499145:tid 499313] [client 4.205.62.107:63990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/config/laravolt/css/index.php"] [unique_id "apPktFJNq1G5uRhTNnthUQAAACY"]
[Sun Aug 30 03:07:16.223687 2026] [security2:error] [pid 499145:tid 499350] [client 20.151.200.44:27300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/im.php"] [unique_id "apPktFJNq1G5uRhTNnthUgAAAEs"]
[Sun Aug 30 03:07:16.232819 2026] [security2:error] [pid 501390:tid 501638] [client 20.48.160.90:37728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/js.php"] [unique_id "apPktKg6skwqJ2NpVh_SxwAAAoo"]
[Sun Aug 30 03:07:16.233542 2026] [security2:error] [pid 499145:tid 499287] [client 20.48.251.3:49931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/fns.php"] [unique_id "apPktFJNq1G5uRhTNnthWAAAAAw"]
[Sun Aug 30 03:07:16.235068 2026] [authz_core:error] [pid 501390:tid 501635] [client 74.7.243.204:34708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:16.235561 2026] [authz_core:error] [pid 501390:tid 501635] [client 74.7.243.204:34708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:16.246531 2026] [security2:error] [pid 501390:tid 501537] [client 4.205.62.107:35984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/rem.php"] [unique_id "apPktKg6skwqJ2NpVh_S0gAAAiU"]
[Sun Aug 30 03:07:16.259990 2026] [security2:error] [pid 501390:tid 501526] [client 20.196.209.81:19118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/admin.php"] [unique_id "apPktKg6skwqJ2NpVh_S4QAAAho"]
[Sun Aug 30 03:07:16.264728 2026] [security2:error] [pid 501390:tid 501417] [remote 114.119.144.29:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cagtu.com"] [uri "/data-deletion-policy/"] [unique_id "apPktKg6skwqJ2NpVh_S4wACQRo"], referer: https://cagtu.com/
[Sun Aug 30 03:07:16.283593 2026] [security2:error] [pid 501390:tid 501548] [client 20.104.18.15:51653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/BDKR28WP.php"] [unique_id "apPktKg6skwqJ2NpVh_S6QAAAjA"]
[Sun Aug 30 03:07:16.285347 2026] [security2:error] [pid 501390:tid 501636] [client 4.205.62.107:18962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/zz.php"] [unique_id "apPktKg6skwqJ2NpVh_S6gAAAog"]
[Sun Aug 30 03:07:16.307884 2026] [security2:error] [pid 501390:tid 501566] [client 4.205.62.107:32050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/server_info.php"] [unique_id "apPktKg6skwqJ2NpVh_S_gAAAkI"]
[Sun Aug 30 03:07:16.336803 2026] [security2:error] [pid 501390:tid 501630] [client 20.220.10.235:20693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/px.php"] [unique_id "apPktKg6skwqJ2NpVh_TIgAAAoI"]
[Sun Aug 30 03:07:16.346232 2026] [security2:error] [pid 501390:tid 501586] [client 20.104.50.220:28705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/backd00rshit.php"] [unique_id "apPktKg6skwqJ2NpVh_TLQAAAlY"]
[Sun Aug 30 03:07:16.358933 2026] [security2:error] [pid 501390:tid 501643] [client 68.155.159.216:12355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPktKg6skwqJ2NpVh_TNgAAAo8"]
[Sun Aug 30 03:07:16.381988 2026] [security2:error] [pid 499145:tid 499369] [client 20.48.160.90:37748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/hd.php"] [unique_id "apPktFJNq1G5uRhTNnthqAAAAF4"]
[Sun Aug 30 03:07:16.389804 2026] [security2:error] [pid 501390:tid 501588] [client 68.155.159.216:56350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPktKg6skwqJ2NpVh_TUQAAAlg"]
[Sun Aug 30 03:07:16.462876 2026] [security2:error] [pid 501390:tid 501645] [client 68.155.159.216:54234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPktKg6skwqJ2NpVh_TigAAApE"]
[Sun Aug 30 03:07:16.483901 2026] [security2:error] [pid 501390:tid 501618] [client 20.220.10.235:20955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/is.php"] [unique_id "apPktKg6skwqJ2NpVh_TmAAAAnY"]
[Sun Aug 30 03:07:16.486301 2026] [security2:error] [pid 501390:tid 501646] [client 68.155.159.216:62070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/xmlrpc.php"] [unique_id "apPktKg6skwqJ2NpVh_TmwAAApI"]
[Sun Aug 30 03:07:16.490833 2026] [authz_core:error] [pid 501390:tid 501618] [client 216.73.216.128:47669] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:16.491125 2026] [authz_core:error] [pid 501390:tid 501618] [client 216.73.216.128:47669] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:16.493011 2026] [security2:error] [pid 501390:tid 501606] [client 20.104.50.220:17313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/2222.php"] [unique_id "apPktKg6skwqJ2NpVh_ToQAAAmo"]
[Sun Aug 30 03:07:16.499307 2026] [security2:error] [pid 501390:tid 501600] [client 34.125.55.247:48180] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/img../.env"] [unique_id "apPktKg6skwqJ2NpVh_TpQAAAmQ"]
[Sun Aug 30 03:07:16.500974 2026] [security2:error] [pid 501390:tid 501593] [client 34.125.55.247:48212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/.docker/.env"] [unique_id "apPktKg6skwqJ2NpVh_TqAAAAl0"]
[Sun Aug 30 03:07:16.501051 2026] [security2:error] [pid 501390:tid 501526] [client 34.125.55.247:48220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/v2/.env"] [unique_id "apPktKg6skwqJ2NpVh_TqQAAAho"]
[Sun Aug 30 03:07:16.501900 2026] [security2:error] [pid 501390:tid 501572] [client 34.125.55.247:48166] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.engaginggoddaily.com"] [uri "/_nuxt/../.env"] [unique_id "apPktKg6skwqJ2NpVh_TqgAAAkg"]
[Sun Aug 30 03:07:16.503450 2026] [security2:error] [pid 501390:tid 501537] [client 34.125.55.247:48174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/uploads../.env"] [unique_id "apPktKg6skwqJ2NpVh_TrAAAAiU"]
[Sun Aug 30 03:07:16.504695 2026] [security2:error] [pid 501390:tid 501530] [client 34.125.55.247:48206] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/v1/.env"] [unique_id "apPktKg6skwqJ2NpVh_TrQAAAh4"]
[Sun Aug 30 03:07:16.505002 2026] [security2:error] [pid 501390:tid 501633] [client 34.125.55.247:48184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/assets../.env"] [unique_id "apPktKg6skwqJ2NpVh_TrgAAAoU"]
[Sun Aug 30 03:07:16.505820 2026] [security2:error] [pid 501390:tid 501635] [client 34.125.55.247:48198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/images../.env"] [unique_id "apPktKg6skwqJ2NpVh_TrwAAAoc"]
[Sun Aug 30 03:07:16.505951 2026] [security2:error] [pid 501390:tid 501533] [client 20.48.251.3:33283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/asa.php"] [unique_id "apPktKg6skwqJ2NpVh_TsQAAAiE"]
[Sun Aug 30 03:07:16.506735 2026] [security2:error] [pid 501390:tid 501587] [client 34.125.55.247:48230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "apPktKg6skwqJ2NpVh_TsgAAAlc"]
[Sun Aug 30 03:07:16.512383 2026] [security2:error] [pid 501390:tid 501625] [client 34.125.55.247:48270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/.env.old"] [unique_id "apPktKg6skwqJ2NpVh_TvQAAAn0"]
[Sun Aug 30 03:07:16.512834 2026] [security2:error] [pid 501390:tid 501647] [client 34.125.55.247:48282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/.env.bak"] [unique_id "apPktKg6skwqJ2NpVh_TwQAAApM"]
[Sun Aug 30 03:07:16.513124 2026] [security2:error] [pid 501390:tid 501549] [client 34.125.55.247:48298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/.env.swp"] [unique_id "apPktKg6skwqJ2NpVh_TvAAAAjE"]
[Sun Aug 30 03:07:16.513329 2026] [security2:error] [pid 501390:tid 501596] [client 20.104.18.15:28668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/clque.php"] [unique_id "apPktKg6skwqJ2NpVh_TxQAAAmA"]
[Sun Aug 30 03:07:16.513777 2026] [security2:error] [pid 501390:tid 501643] [client 20.48.160.90:37636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/xl2023.php"] [unique_id "apPktKg6skwqJ2NpVh_TyQAAAo8"]
[Sun Aug 30 03:07:16.514511 2026] [security2:error] [pid 501390:tid 501619] [client 34.125.55.247:48212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "apPktKg6skwqJ2NpVh_TygAAAnc"]
[Sun Aug 30 03:07:16.515156 2026] [security2:error] [pid 501390:tid 501578] [client 34.125.55.247:48180] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/.env.backup"] [unique_id "apPktKg6skwqJ2NpVh_TxAAAAk4"]
[Sun Aug 30 03:07:16.515510 2026] [proxy_http:error] [pid 501390:tid 501528] (20014)Internal error (specific information not available): [client 34.125.55.247:48254] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:16.515520 2026] [proxy:error] [pid 501390:tid 501528] [client 34.125.55.247:48254] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.env.development
[Sun Aug 30 03:07:16.516479 2026] [security2:error] [pid 501390:tid 501539] [client 34.125.55.247:48316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "apPktKg6skwqJ2NpVh_TzwAAAic"]
[Sun Aug 30 03:07:16.521049 2026] [security2:error] [pid 501390:tid 501580] [client 34.125.55.247:48384] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/core/.env"] [unique_id "apPktKg6skwqJ2NpVh_T1QAAAlA"]
[Sun Aug 30 03:07:16.522601 2026] [security2:error] [pid 501390:tid 501630] [client 34.125.55.247:48400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/laravel/.env"] [unique_id "apPktKg6skwqJ2NpVh_T1wAAAoI"]
[Sun Aug 30 03:07:16.522884 2026] [security2:error] [pid 501390:tid 501526] [client 34.125.55.247:48174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/frontend/.env"] [unique_id "apPktKg6skwqJ2NpVh_T2QAAAho"]
[Sun Aug 30 03:07:16.522910 2026] [security2:error] [pid 501390:tid 501527] [client 34.125.55.247:48346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/server/.env"] [unique_id "apPktKg6skwqJ2NpVh_T2AAAAhs"]
[Sun Aug 30 03:07:16.523257 2026] [security2:error] [pid 501390:tid 501544] [client 34.125.55.247:48422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/config/.env"] [unique_id "apPktKg6skwqJ2NpVh_T3AAAAiw"]
[Sun Aug 30 03:07:16.523314 2026] [security2:error] [pid 501390:tid 501541] [client 34.125.55.247:48446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "apPktKg6skwqJ2NpVh_T3QAAAik"]
[Sun Aug 30 03:07:16.523337 2026] [proxy_http:error] [pid 501390:tid 501558] (20014)Internal error (specific information not available): [client 34.125.55.247:48258] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:16.523343 2026] [proxy:error] [pid 501390:tid 501558] [client 34.125.55.247:48258] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.env.staging
[Sun Aug 30 03:07:16.523408 2026] [security2:error] [pid 501390:tid 501541] [client 34.125.55.247:48446] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "apPktKg6skwqJ2NpVh_T3QAAAik"]
[Sun Aug 30 03:07:16.524297 2026] [security2:error] [pid 501390:tid 501569] [client 34.125.55.247:48184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/docker/.env"] [unique_id "apPktKg6skwqJ2NpVh_T2wAAAkU"]
[Sun Aug 30 03:07:16.524499 2026] [security2:error] [pid 501390:tid 501569] [client 34.125.55.247:48184] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/docker/.env"] [unique_id "apPktKg6skwqJ2NpVh_T2wAAAkU"]
[Sun Aug 30 03:07:16.524830 2026] [security2:error] [pid 501390:tid 501593] [client 34.125.55.247:48230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/src/.env"] [unique_id "apPktKg6skwqJ2NpVh_T3wAAAl0"]
[Sun Aug 30 03:07:16.525553 2026] [security2:error] [pid 501390:tid 501559] [client 34.125.55.247:48330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/web/.env"] [unique_id "apPktKg6skwqJ2NpVh_T4AAAAjs"]
[Sun Aug 30 03:07:16.525624 2026] [security2:error] [pid 501390:tid 501559] [client 34.125.55.247:48330] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/web/.env"] [unique_id "apPktKg6skwqJ2NpVh_T4AAAAjs"]
[Sun Aug 30 03:07:16.530560 2026] [proxy_http:error] [pid 501390:tid 501528] (20014)Internal error (specific information not available): [client 34.125.55.247:48254] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:16.530578 2026] [proxy:error] [pid 501390:tid 501528] [client 34.125.55.247:48254] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml
[Sun Aug 30 03:07:16.537598 2026] [proxy_http:error] [pid 501390:tid 501611] (20014)Internal error (specific information not available): [client 34.125.55.247:48274] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:16.537618 2026] [proxy:error] [pid 501390:tid 501611] [client 34.125.55.247:48274] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.env.example
[Sun Aug 30 03:07:16.544275 2026] [proxy_http:error] [pid 501390:tid 501558] (20014)Internal error (specific information not available): [client 34.125.55.247:48258] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:16.544295 2026] [proxy:error] [pid 501390:tid 501558] [client 34.125.55.247:48258] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml
[Sun Aug 30 03:07:16.548516 2026] [authz_core:error] [pid 499145:tid 499385] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fmultipart
[Sun Aug 30 03:07:16.548793 2026] [authz_core:error] [pid 499145:tid 499385] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fmultipart
[Sun Aug 30 03:07:16.566476 2026] [authz_core:error] [pid 501390:tid 501550] [client 66.249.66.201:53506] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:16.566773 2026] [authz_core:error] [pid 501390:tid 501550] [client 66.249.66.201:53506] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:16.572564 2026] [security2:error] [pid 501390:tid 501606] [client 4.205.62.107:2756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/test1.php"] [unique_id "apPktKg6skwqJ2NpVh_UAgAAAmo"]
[Sun Aug 30 03:07:16.578217 2026] [security2:error] [pid 501390:tid 501551] [client 20.196.209.81:4926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/tflow/min.php"] [unique_id "apPktKg6skwqJ2NpVh_UDAAAAjM"]
[Sun Aug 30 03:07:16.579109 2026] [security2:error] [pid 499145:tid 499291] [client 216.73.216.128:41075] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/ourcollection_images/wp-admin/css/install.css"] [unique_id "apPktFJNq1G5uRhTNntiAQAAABA"]
[Sun Aug 30 03:07:16.598031 2026] [security2:error] [pid 501390:tid 501616] [client 4.205.62.107:62448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/queue.php"] [unique_id "apPktKg6skwqJ2NpVh_UHAAAAnQ"]
[Sun Aug 30 03:07:16.610065 2026] [security2:error] [pid 501390:tid 501634] [client 20.104.18.15:18349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/5PJcpMFsD8B.php"] [unique_id "apPktKg6skwqJ2NpVh_UIAAAAoY"]
[Sun Aug 30 03:07:16.619287 2026] [security2:error] [pid 501390:tid 501539] [client 20.104.50.220:47045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-site.php"] [unique_id "apPktKg6skwqJ2NpVh_UJgAAAic"]
[Sun Aug 30 03:07:16.621968 2026] [security2:error] [pid 501390:tid 501580] [client 20.220.10.235:20717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/od.php"] [unique_id "apPktKg6skwqJ2NpVh_UKQAAAlA"]
[Sun Aug 30 03:07:16.621980 2026] [security2:error] [pid 501390:tid 501540] [client 20.104.18.15:23462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/btyuio.php"] [unique_id "apPktKg6skwqJ2NpVh_UKgAAAig"]
[Sun Aug 30 03:07:16.649682 2026] [security2:error] [pid 499145:tid 499297] [client 20.48.160.90:61453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/V2.php"] [unique_id "apPktFJNq1G5uRhTNntiEAAAABY"]
[Sun Aug 30 03:07:16.655032 2026] [security2:error] [pid 501390:tid 501572] [client 20.196.209.81:19107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/index.php"] [unique_id "apPktKg6skwqJ2NpVh_UQgAAAkg"]
[Sun Aug 30 03:07:16.668389 2026] [security2:error] [pid 499145:tid 499346] [client 20.104.18.15:43945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/tnglzqmv.php"] [unique_id "apPktFJNq1G5uRhTNntiHAAAAEc"]
[Sun Aug 30 03:07:16.716089 2026] [security2:error] [pid 501390:tid 501630] [client 20.104.50.220:5629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/70.php"] [unique_id "apPktKg6skwqJ2NpVh_UcQAAAoI"]
[Sun Aug 30 03:07:16.728068 2026] [security2:error] [pid 501390:tid 501600] [client 20.48.251.3:64460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/gk.php"] [unique_id "apPktKg6skwqJ2NpVh_UgAAAAmQ"]
[Sun Aug 30 03:07:16.757539 2026] [security2:error] [pid 499145:tid 499316] [client 216.73.216.128:41075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPktFJNq1G5uRhTNntiVgAAACk"]
[Sun Aug 30 03:07:16.761794 2026] [security2:error] [pid 499145:tid 499344] [client 20.220.10.235:20623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/wp-the.php"] [unique_id "apPktFJNq1G5uRhTNntiWQAAAEU"]
[Sun Aug 30 03:07:16.771755 2026] [authz_core:error] [pid 501390:tid 501523] [client 74.7.243.204:34708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:16.772152 2026] [authz_core:error] [pid 501390:tid 501523] [client 74.7.243.204:34708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:16.785771 2026] [security2:error] [pid 499145:tid 499323] [client 20.104.50.220:62787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wso-2.5.php"] [unique_id "apPktFJNq1G5uRhTNntiaAAAADA"]
[Sun Aug 30 03:07:16.790078 2026] [security2:error] [pid 501390:tid 501529] [client 20.48.160.90:37639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/mad.php"] [unique_id "apPktKg6skwqJ2NpVh_UnwAAAh0"]
[Sun Aug 30 03:07:16.834305 2026] [security2:error] [pid 501390:tid 501534] [client 20.48.251.3:5077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/apikeys.php"] [unique_id "apPktKg6skwqJ2NpVh_UxgAAAiI"]
[Sun Aug 30 03:07:16.834375 2026] [security2:error] [pid 501390:tid 501548] [client 20.104.50.220:31914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/shells.php"] [unique_id "apPktKg6skwqJ2NpVh_UxQAAAjA"]
[Sun Aug 30 03:07:16.859731 2026] [security2:error] [pid 501390:tid 501566] [client 20.151.200.44:27601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/file.php"] [unique_id "apPktKg6skwqJ2NpVh_U2AAAAkI"]
[Sun Aug 30 03:07:16.872069 2026] [security2:error] [pid 499145:tid 499342] [client 20.104.50.220:61394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/images/mar.php"] [unique_id "apPktFJNq1G5uRhTNntilQAAAEM"]
[Sun Aug 30 03:07:16.890223 2026] [security2:error] [pid 501390:tid 501602] [client 20.220.10.235:20731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/wt.php"] [unique_id "apPktKg6skwqJ2NpVh_U5gAAAmY"]
[Sun Aug 30 03:07:16.936390 2026] [security2:error] [pid 501390:tid 501590] [client 20.48.160.90:37672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/st.php"] [unique_id "apPktKg6skwqJ2NpVh_U7wAAAlo"]
[Sun Aug 30 03:07:16.947138 2026] [authz_core:error] [pid 501390:tid 501606] [client 216.73.216.128:47669] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:16.947486 2026] [authz_core:error] [pid 501390:tid 501606] [client 216.73.216.128:47669] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:16.952890 2026] [security2:error] [pid 501390:tid 501556] [client 20.104.50.220:33200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/aku.php"] [unique_id "apPktKg6skwqJ2NpVh_U_AAAAjg"]
[Sun Aug 30 03:07:16.957168 2026] [security2:error] [pid 501390:tid 501529] [client 68.155.159.216:62314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-includes/customize/index.php"] [unique_id "apPktKg6skwqJ2NpVh_VAAAAAh0"]
[Sun Aug 30 03:07:16.961060 2026] [security2:error] [pid 501390:tid 501625] [client 114.119.151.14:58351] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "selectingwinners.com"] [uri "/left-sidebar/"] [unique_id "apPktKg6skwqJ2NpVh_VBgAAAn0"], referer: https://selectingwinners.com/left-sidebar/
[Sun Aug 30 03:07:16.971116 2026] [security2:error] [pid 501390:tid 501539] [client 20.196.209.81:13732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/tflow/pk.php"] [unique_id "apPktKg6skwqJ2NpVh_VEgAAAic"]
[Sun Aug 30 03:07:16.974379 2026] [security2:error] [pid 501390:tid 501548] [client 68.155.159.216:65417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/cong.php"] [unique_id "apPktKg6skwqJ2NpVh_VEwAAAjA"]
[Sun Aug 30 03:07:16.982969 2026] [security2:error] [pid 501390:tid 501618] [client 20.104.18.15:13676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/dragonshell.php"] [unique_id "apPktKg6skwqJ2NpVh_VHAAAAnY"]
[Sun Aug 30 03:07:17.024052 2026] [security2:error] [pid 501390:tid 501533] [client 4.205.62.107:56887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/time.php"] [unique_id "apPktag6skwqJ2NpVh_VMgAAAiE"]
[Sun Aug 30 03:07:17.045476 2026] [security2:error] [pid 501390:tid 501634] [client 20.220.10.235:20735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/im.php"] [unique_id "apPktag6skwqJ2NpVh_VRwAAAoY"]
[Sun Aug 30 03:07:17.065436 2026] [security2:error] [pid 499145:tid 499356] [client 114.119.136.86:37997] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arcaneguardians.com"] [uri "/zgxgbcfh/trident-seafoods-headquarters"] [unique_id "apPktVJNq1G5uRhTNnti5gAAAFE"], referer: https://webhap.co.jp/s2plbc/what-tea-is-good-for-overactive-bladder
[Sun Aug 30 03:07:17.106838 2026] [security2:error] [pid 499145:tid 499361] [client 20.196.209.81:20893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/php8.php"] [unique_id "apPktVJNq1G5uRhTNnti-AAAAFY"]
[Sun Aug 30 03:07:17.109130 2026] [security2:error] [pid 499145:tid 499350] [client 20.48.160.90:61542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/alfanew.php"] [unique_id "apPktVJNq1G5uRhTNnti-wAAAEs"]
[Sun Aug 30 03:07:17.130850 2026] [authz_core:error] [pid 501390:tid 501576] [client 216.73.216.128:47669] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:17.131215 2026] [authz_core:error] [pid 501390:tid 501576] [client 216.73.216.128:47669] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:17.166189 2026] [security2:error] [pid 501390:tid 501628] [client 20.104.18.15:29148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/nox.php"] [unique_id "apPktag6skwqJ2NpVh_VggAAAoA"]
[Sun Aug 30 03:07:17.195482 2026] [security2:error] [pid 501390:tid 501641] [client 20.104.50.220:27436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/Store.php"] [unique_id "apPktag6skwqJ2NpVh_VmAAAAo0"]
[Sun Aug 30 03:07:17.200720 2026] [security2:error] [pid 501390:tid 501602] [client 20.220.10.235:20953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/file.php"] [unique_id "apPktag6skwqJ2NpVh_VnAAAAmY"]
[Sun Aug 30 03:07:17.222725 2026] [authz_core:error] [pid 501390:tid 501635] [client 216.73.216.128:1374] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:17.223008 2026] [authz_core:error] [pid 501390:tid 501635] [client 216.73.216.128:1374] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:17.236165 2026] [security2:error] [pid 501390:tid 501607] [client 20.48.160.90:38012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/ioxi.php"] [unique_id "apPktag6skwqJ2NpVh_VpAAAAms"]
[Sun Aug 30 03:07:17.274270 2026] [authz_core:error] [pid 501390:tid 501621] [client 74.7.243.204:34708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:17.274769 2026] [authz_core:error] [pid 501390:tid 501621] [client 74.7.243.204:34708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:17.286145 2026] [security2:error] [pid 499145:tid 499306] [client 4.205.62.107:61794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/public/vx.php"] [unique_id "apPktVJNq1G5uRhTNntjVQAAAB8"]
[Sun Aug 30 03:07:17.317738 2026] [security2:error] [pid 501390:tid 501600] [client 20.104.50.220:51548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/fk.php7"] [unique_id "apPktag6skwqJ2NpVh_V5wAAAmQ"]
[Sun Aug 30 03:07:17.331810 2026] [security2:error] [pid 501390:tid 501520] [client 114.119.151.64:50671] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.briankornblum.com"] [uri "/category/self-employed/"] [unique_id "apPktag6skwqJ2NpVh_V8AAAAhQ"], referer: http://briankornblum.com/
[Sun Aug 30 03:07:17.333808 2026] [security2:error] [pid 501390:tid 501594] [client 20.220.10.235:20724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/ca.php"] [unique_id "apPktag6skwqJ2NpVh_V9wAAAl4"]
[Sun Aug 30 03:07:17.356796 2026] [security2:error] [pid 501390:tid 501565] [client 4.205.62.107:62121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/87.php"] [unique_id "apPktag6skwqJ2NpVh_WCQAAAkE"]
[Sun Aug 30 03:07:17.361359 2026] [security2:error] [pid 499145:tid 499395] [client 20.196.209.81:5759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/theme-check/theme-check.php"] [unique_id "apPktVJNq1G5uRhTNntjfQAAAHg"]
[Sun Aug 30 03:07:17.370457 2026] [security2:error] [pid 499145:tid 499317] [client 20.104.18.15:34806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/akismet.php"] [unique_id "apPktVJNq1G5uRhTNntjgwAAACo"]
[Sun Aug 30 03:07:17.371354 2026] [security2:error] [pid 499145:tid 499329] [client 20.48.160.90:37963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/TNT.php"] [unique_id "apPktVJNq1G5uRhTNntjhAAAADY"]
[Sun Aug 30 03:07:17.373292 2026] [security2:error] [pid 499145:tid 499369] [client 20.48.251.3:49998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/params.php"] [unique_id "apPktVJNq1G5uRhTNntjhQAAAF4"]
[Sun Aug 30 03:07:17.385601 2026] [security2:error] [pid 501390:tid 501600] [client 20.151.200.44:27597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/ca.php"] [unique_id "apPktag6skwqJ2NpVh_WGQAAAmQ"]
[Sun Aug 30 03:07:17.415091 2026] [security2:error] [pid 501390:tid 501559] [client 4.205.62.107:65388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/classsmtps.php"] [unique_id "apPktag6skwqJ2NpVh_WOwAAAjs"]
[Sun Aug 30 03:07:17.428419 2026] [security2:error] [pid 501390:tid 501630] [client 4.205.62.107:18794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/test.php"] [unique_id "apPktag6skwqJ2NpVh_WRwAAAoI"]
[Sun Aug 30 03:07:17.431994 2026] [security2:error] [pid 501390:tid 501561] [client 20.104.18.15:51659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/k.php"] [unique_id "apPktag6skwqJ2NpVh_WTQAAAj0"]
[Sun Aug 30 03:07:17.468073 2026] [security2:error] [pid 501390:tid 501563] [client 20.220.10.235:20622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/pb.php"] [unique_id "apPktag6skwqJ2NpVh_WWgAAAj8"]
[Sun Aug 30 03:07:17.482424 2026] [security2:error] [pid 501390:tid 501629] [client 4.205.62.107:36015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/min.php"] [unique_id "apPktag6skwqJ2NpVh_WZgAAAoE"]
[Sun Aug 30 03:07:17.498682 2026] [security2:error] [pid 501390:tid 501599] [client 20.48.160.90:37663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/cd.php"] [unique_id "apPktag6skwqJ2NpVh_WdgAAAmM"]
[Sun Aug 30 03:07:17.498849 2026] [security2:error] [pid 499145:tid 499316] [client 20.196.209.81:19958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/function.php"] [unique_id "apPktVJNq1G5uRhTNntjvwAAACk"]
[Sun Aug 30 03:07:17.499419 2026] [security2:error] [pid 501390:tid 501615] [client 20.104.50.220:29176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/ichi.php"] [unique_id "apPktag6skwqJ2NpVh_WeQAAAnM"]
[Sun Aug 30 03:07:17.504717 2026] [security2:error] [pid 501390:tid 501565] [client 114.119.144.51:43675] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.societyofassassins.com"] [uri "/index.php"] [unique_id "apPktag6skwqJ2NpVh_WfgAAAkE"], referer: http://www.societyofassassins.com/index.php?/calendar/1-community-calendar/week-1609029449
[Sun Aug 30 03:07:17.514344 2026] [security2:error] [pid 501390:tid 501620] [client 68.155.159.216:56365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-includes/content.php"] [unique_id "apPktag6skwqJ2NpVh_WgAAAAng"]
[Sun Aug 30 03:07:17.548749 2026] [security2:error] [pid 499145:tid 499363] [client 114.119.140.122:63143] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cruelintentionsnecklace.com"] [uri "/shop"] [unique_id "apPktVJNq1G5uRhTNntj0QAAAFg"], referer: https://cruelintentionsnecklace.com/shop?orderby=menu_order&product_brand=kesa&filter_color=silver
[Sun Aug 30 03:07:17.575556 2026] [security2:error] [pid 499145:tid 499317] [client 68.155.159.216:54238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/makeasmtp.php"] [unique_id "apPktVJNq1G5uRhTNntj3QAAACo"]
[Sun Aug 30 03:07:17.595439 2026] [authz_core:error] [pid 499145:tid 499276] [client 66.249.66.76:45370] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:17.595924 2026] [authz_core:error] [pid 499145:tid 499276] [client 66.249.66.76:45370] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:17.600408 2026] [security2:error] [pid 501390:tid 501525] [client 20.220.10.235:20692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/pk.php"] [unique_id "apPktag6skwqJ2NpVh_W0AAAAhk"]
[Sun Aug 30 03:07:17.630256 2026] [security2:error] [pid 501390:tid 501574] [client 20.104.50.220:16707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/h02ugyh.php"] [unique_id "apPktag6skwqJ2NpVh_W5wAAAko"]
[Sun Aug 30 03:07:17.640307 2026] [security2:error] [pid 501390:tid 501570] [client 20.48.160.90:38006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/luuf.php"] [unique_id "apPktag6skwqJ2NpVh_W6wAAAkY"]
[Sun Aug 30 03:07:17.640870 2026] [lsapi:error] [pid 499145:tid 499195] [remote 45.73.162.106:7398] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n
[Sun Aug 30 03:07:17.641012 2026] [lsapi:error] [pid 499145:tid 499195] [remote 45.73.162.106:7398] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n
[Sun Aug 30 03:07:17.642475 2026] [lsapi:error] [pid 499145:tid 499195] [remote 45.73.162.106:7398] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n
[Sun Aug 30 03:07:17.643172 2026] [security2:error] [pid 501390:tid 501561] [client 68.155.159.216:12412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/about.php"] [unique_id "apPktag6skwqJ2NpVh_W7QAAAj0"]
[Sun Aug 30 03:07:17.645740 2026] [security2:error] [pid 501390:tid 501548] [client 20.48.251.3:33332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/radio.php"] [unique_id "apPktag6skwqJ2NpVh_W7gAAAjA"]
[Sun Aug 30 03:07:17.647198 2026] [security2:error] [pid 501390:tid 501608] [client 20.104.18.15:28667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/nano.php"] [unique_id "apPktag6skwqJ2NpVh_W8AAAAmw"]
[Sun Aug 30 03:07:17.693558 2026] [security2:error] [pid 501390:tid 501606] [client 114.119.159.6:53409] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "shannonkaper.com"] [uri "/the-halfway-point-lodge"] [unique_id "apPktag6skwqJ2NpVh_W_QAAAmo"], referer: http://shannonkaper.com/the-halfway-point-lodge
[Sun Aug 30 03:07:17.701410 2026] [security2:error] [pid 501390:tid 501593] [client 68.155.159.216:62035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/atomlib.php"] [unique_id "apPktag6skwqJ2NpVh_XAwAAAl0"]
[Sun Aug 30 03:07:17.715594 2026] [security2:error] [pid 501390:tid 501567] [client 4.205.62.107:2130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/bigdump.php"] [unique_id "apPktag6skwqJ2NpVh_XEAAAAkM"]
[Sun Aug 30 03:07:17.731806 2026] [authz_core:error] [pid 501390:tid 501636] [client 74.7.243.204:34708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:17.732182 2026] [authz_core:error] [pid 501390:tid 501636] [client 74.7.243.204:34708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:17.733818 2026] [security2:error] [pid 501390:tid 501576] [client 20.220.10.235:20726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/ft.php"] [unique_id "apPktag6skwqJ2NpVh_XKwAAAkw"]
[Sun Aug 30 03:07:17.749014 2026] [security2:error] [pid 501390:tid 501575] [client 20.104.18.15:18417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPktag6skwqJ2NpVh_XOQAAAks"]
[Sun Aug 30 03:07:17.759612 2026] [security2:error] [pid 499145:tid 499375] [client 20.196.209.81:5705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/theme/about.php"] [unique_id "apPktVJNq1G5uRhTNntkKgAAAGQ"]
[Sun Aug 30 03:07:17.772745 2026] [security2:error] [pid 501390:tid 501532] [client 20.48.160.90:61478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/fex.php"] [unique_id "apPktag6skwqJ2NpVh_XRAAAAiA"]
[Sun Aug 30 03:07:17.775078 2026] [security2:error] [pid 501390:tid 501555] [client 20.104.50.220:47084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-system.php"] [unique_id "apPktag6skwqJ2NpVh_XRQAAAjc"]
[Sun Aug 30 03:07:17.785439 2026] [security2:error] [pid 501390:tid 501643] [client 20.104.18.15:23466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/dehnl.php"] [unique_id "apPktag6skwqJ2NpVh_XUAAAAo8"]
[Sun Aug 30 03:07:17.824444 2026] [security2:error] [pid 501390:tid 501600] [client 20.104.18.15:43923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/wefile.php"] [unique_id "apPktag6skwqJ2NpVh_XdQAAAmQ"]
[Sun Aug 30 03:07:17.845167 2026] [security2:error] [pid 501390:tid 501554] [client 4.205.62.107:54401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/doc.php"] [unique_id "apPktag6skwqJ2NpVh_XjgAAAjY"]
[Sun Aug 30 03:07:17.848145 2026] [security2:error] [pid 501390:tid 501624] [client 20.104.50.220:5569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/content.php"] [unique_id "apPktag6skwqJ2NpVh_XkQAAAnw"]
[Sun Aug 30 03:07:17.861786 2026] [authz_core:error] [pid 501390:tid 501557] [client 216.73.216.128:47669] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:17.862128 2026] [authz_core:error] [pid 501390:tid 501557] [client 216.73.216.128:47669] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:17.875470 2026] [security2:error] [pid 499145:tid 499293] [client 20.220.10.235:20934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/wp-ver.php"] [unique_id "apPktVJNq1G5uRhTNntkWAAAABI"]
[Sun Aug 30 03:07:17.876131 2026] [security2:error] [pid 501390:tid 501630] [client 20.48.251.3:6488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/god.php"] [unique_id "apPktag6skwqJ2NpVh_XnQAAAoI"]
[Sun Aug 30 03:07:17.899167 2026] [security2:error] [pid 501390:tid 501587] [client 20.196.209.81:19920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/about.php"] [unique_id "apPktag6skwqJ2NpVh_XrgAAAlc"]
[Sun Aug 30 03:07:17.911278 2026] [security2:error] [pid 499145:tid 499334] [client 20.48.160.90:37637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/l.php"] [unique_id "apPktVJNq1G5uRhTNntkYQAAADs"]
[Sun Aug 30 03:07:17.981057 2026] [authz_core:error] [pid 499145:tid 499317] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fmultipart
[Sun Aug 30 03:07:17.981580 2026] [authz_core:error] [pid 499145:tid 499317] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fmultipart
[Sun Aug 30 03:07:18.017699 2026] [security2:error] [pid 501390:tid 501548] [client 20.104.50.220:29574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/ngacir88.php"] [unique_id "apPktqg6skwqJ2NpVh_X_gAAAjA"]
[Sun Aug 30 03:07:18.018601 2026] [security2:error] [pid 501390:tid 501569] [client 20.220.10.235:20686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/ah24.php"] [unique_id "apPktqg6skwqJ2NpVh_YAQAAAkU"]
[Sun Aug 30 03:07:18.027470 2026] [security2:error] [pid 499145:tid 499299] [client 20.48.251.3:44311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/motu.php"] [unique_id "apPktlJNq1G5uRhTNntkjAAAABg"]
[Sun Aug 30 03:07:18.038362 2026] [security2:error] [pid 501390:tid 501605] [client 20.104.50.220:61405] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/images/1.php"] [unique_id "apPktqg6skwqJ2NpVh_YDAAAAmk"]
[Sun Aug 30 03:07:18.038449 2026] [security2:error] [pid 501390:tid 501605] [client 20.104.50.220:61405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/images/1.php"] [unique_id "apPktqg6skwqJ2NpVh_YDAAAAmk"]
[Sun Aug 30 03:07:18.057929 2026] [security2:error] [pid 501390:tid 501634] [client 20.48.160.90:37654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/xr.php"] [unique_id "apPktqg6skwqJ2NpVh_YIQAAAoY"]
[Sun Aug 30 03:07:18.061991 2026] [authz_core:error] [pid 501390:tid 501539] [client 66.249.66.205:58391] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:18.062464 2026] [authz_core:error] [pid 501390:tid 501539] [client 66.249.66.205:58391] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:18.078872 2026] [security2:error] [pid 501390:tid 501595] [client 68.155.159.216:28608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-admin/index.php"] [unique_id "apPktqg6skwqJ2NpVh_YLAAAAl8"]
[Sun Aug 30 03:07:18.079600 2026] [security2:error] [pid 501390:tid 501522] [client 68.155.159.216:64823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-includes/js/index.php"] [unique_id "apPktqg6skwqJ2NpVh_YLQAAAhY"]
[Sun Aug 30 03:07:18.088444 2026] [security2:error] [pid 501390:tid 501577] [client 20.104.50.220:32863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/syg.php"] [unique_id "apPktqg6skwqJ2NpVh_YNgAAAk0"]
[Sun Aug 30 03:07:18.132412 2026] [security2:error] [pid 501390:tid 501557] [client 20.104.50.220:31913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/stupid.php"] [unique_id "apPktqg6skwqJ2NpVh_YPwAAAjk"]
[Sun Aug 30 03:07:18.154919 2026] [security2:error] [pid 499145:tid 499379] [client 20.196.209.81:5719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/theme/min.php"] [unique_id "apPktlJNq1G5uRhTNntkwgAAAGg"]
[Sun Aug 30 03:07:18.157587 2026] [security2:error] [pid 501390:tid 501643] [client 4.205.62.107:32477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/hosty.php"] [unique_id "apPktqg6skwqJ2NpVh_YUQAAAo8"]
[Sun Aug 30 03:07:18.158322 2026] [security2:error] [pid 501390:tid 501611] [client 20.104.18.15:13614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/wp-safe.php"] [unique_id "apPktqg6skwqJ2NpVh_YUgAAAm8"]
[Sun Aug 30 03:07:18.164438 2026] [security2:error] [pid 501390:tid 501574] [client 4.205.62.107:51726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/doc.php"] [unique_id "apPktqg6skwqJ2NpVh_YWAAAAko"]
[Sun Aug 30 03:07:18.194023 2026] [security2:error] [pid 501390:tid 501616] [client 20.48.160.90:30737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/Q3.php"] [unique_id "apPktqg6skwqJ2NpVh_YcAAAAnQ"]
[Sun Aug 30 03:07:18.197632 2026] [authz_core:error] [pid 499145:tid 499303] [client 66.249.66.67:55851] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:18.197921 2026] [authz_core:error] [pid 499145:tid 499303] [client 66.249.66.67:55851] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:18.201371 2026] [security2:error] [pid 501390:tid 501586] [client 20.220.10.235:20619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPktqg6skwqJ2NpVh_YeAAAAlY"]
[Sun Aug 30 03:07:18.206828 2026] [security2:error] [pid 501390:tid 501638] [client 114.119.130.104:36165] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.fenderrhodes.com"] [uri "/faq/how-many-fender-rhodes-pianos-were-built.html"] [unique_id "apPktqg6skwqJ2NpVh_YegAAAoo"], referer: https://www.fenderrhodes.com/faq/how-many-fender-rhodes-pianos-were-built.html
[Sun Aug 30 03:07:18.271189 2026] [authz_core:error] [pid 501390:tid 501533] [client 74.7.243.204:34708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:18.271462 2026] [authz_core:error] [pid 501390:tid 501533] [client 74.7.243.204:34708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:18.303579 2026] [security2:error] [pid 501390:tid 501577] [client 20.104.49.130:63284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/wp.php"] [unique_id "apPktqg6skwqJ2NpVh_YuwAAAk0"]
[Sun Aug 30 03:07:18.304852 2026] [security2:error] [pid 501390:tid 501603] [client 20.104.18.15:29172] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "arcaneguardians.com"] [uri "/1.php"] [unique_id "apPktqg6skwqJ2NpVh_YvgAAAmc"]
[Sun Aug 30 03:07:18.304947 2026] [security2:error] [pid 501390:tid 501603] [client 20.104.18.15:29172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/1.php"] [unique_id "apPktqg6skwqJ2NpVh_YvgAAAmc"]
[Sun Aug 30 03:07:18.320550 2026] [security2:error] [pid 501390:tid 501590] [client 20.48.160.90:37637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/Q1.php"] [unique_id "apPktqg6skwqJ2NpVh_YzQAAAlo"]
[Sun Aug 30 03:07:18.327558 2026] [security2:error] [pid 501390:tid 501560] [client 20.151.200.44:27170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/pb.php"] [unique_id "apPktqg6skwqJ2NpVh_Y1wAAAjw"]
[Sun Aug 30 03:07:18.333832 2026] [security2:error] [pid 501390:tid 501556] [client 20.104.50.220:27559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/Pdo.php"] [unique_id "apPktqg6skwqJ2NpVh_Y4AAAAjg"]
[Sun Aug 30 03:07:18.349952 2026] [security2:error] [pid 499145:tid 499395] [client 20.220.10.235:20957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.supremeblackcock.com"] [uri "/waf.php"] [unique_id "apPktlJNq1G5uRhTNntlIQAAAHg"]
[Sun Aug 30 03:07:18.358152 2026] [security2:error] [pid 501390:tid 501562] [client 114.119.157.237:45227] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.practicalcreativewriting.com"] [uri "/inspiration"] [unique_id "apPktqg6skwqJ2NpVh_Y8QAAAj4"], referer: https://www.practicalcreativewriting.com/inspiration
[Sun Aug 30 03:07:18.386591 2026] [security2:error] [pid 501390:tid 501599] [client 20.196.209.81:19959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/new.php"] [unique_id "apPktqg6skwqJ2NpVh_Y_gAAAmM"]
[Sun Aug 30 03:07:18.429234 2026] [authz_core:error] [pid 501390:tid 501568] [client 216.73.216.128:1374] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:18.429518 2026] [authz_core:error] [pid 501390:tid 501568] [client 216.73.216.128:1374] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:18.432791 2026] [security2:error] [pid 501390:tid 501578] [client 4.205.62.107:64448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/log.php"] [unique_id "apPktqg6skwqJ2NpVh_ZMAAAAk4"]
[Sun Aug 30 03:07:18.449467 2026] [security2:error] [pid 501390:tid 501606] [client 20.48.160.90:61537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/nz.php"] [unique_id "apPktqg6skwqJ2NpVh_ZOwAAAmo"]
[Sun Aug 30 03:07:18.495076 2026] [security2:error] [pid 501390:tid 501602] [client 4.205.62.107:62092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/plss3.php"] [unique_id "apPktqg6skwqJ2NpVh_ZXwAAAmY"]
[Sun Aug 30 03:07:18.502521 2026] [security2:error] [pid 501390:tid 501533] [client 20.104.18.15:34627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/ajax.php"] [unique_id "apPktqg6skwqJ2NpVh_ZagAAAiE"]
[Sun Aug 30 03:07:18.513012 2026] [security2:error] [pid 499145:tid 499310] [client 20.48.251.3:12042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/gjm.php"] [unique_id "apPktlJNq1G5uRhTNntlcwAAACM"]
[Sun Aug 30 03:07:18.513107 2026] [security2:error] [pid 501390:tid 501551] [client 20.104.50.220:51624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/eagle.php"] [unique_id "apPktqg6skwqJ2NpVh_ZcQAAAjM"]
[Sun Aug 30 03:07:18.532620 2026] [authz_core:error] [pid 501390:tid 501528] [client 66.249.66.71:65175] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:18.532910 2026] [authz_core:error] [pid 501390:tid 501528] [client 66.249.66.71:65175] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:18.572700 2026] [security2:error] [pid 501390:tid 501572] [client 4.205.62.107:18662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/cloud.php"] [unique_id "apPktqg6skwqJ2NpVh_ZngAAAkg"]
[Sun Aug 30 03:07:18.580607 2026] [security2:error] [pid 501390:tid 501536] [client 20.104.18.15:51687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/dex.php"] [unique_id "apPktqg6skwqJ2NpVh_ZpQAAAiQ"]
[Sun Aug 30 03:07:18.585308 2026] [security2:error] [pid 501390:tid 501524] [client 20.196.209.81:5702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/themes/about.php"] [unique_id "apPktqg6skwqJ2NpVh_ZqQAAAhg"]
[Sun Aug 30 03:07:18.600177 2026] [security2:error] [pid 499145:tid 499286] [client 20.48.160.90:61550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/sg.php"] [unique_id "apPktlJNq1G5uRhTNntlnwAAAAs"]
[Sun Aug 30 03:07:18.633081 2026] [security2:error] [pid 499145:tid 499314] [client 68.155.159.216:56392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-admin/css/index.php"] [unique_id "apPktlJNq1G5uRhTNntlrAAAACc"]
[Sun Aug 30 03:07:18.666940 2026] [security2:error] [pid 501390:tid 501520] [client 20.104.50.220:29160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/~.php"] [unique_id "apPktqg6skwqJ2NpVh_ZxwAAAhQ"]
[Sun Aug 30 03:07:18.675098 2026] [security2:error] [pid 501390:tid 501580] [client 68.155.159.216:55145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apPktqg6skwqJ2NpVh_ZyQAAAlA"]
[Sun Aug 30 03:07:18.731001 2026] [security2:error] [pid 501390:tid 501561] [client 20.48.160.90:37746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/hypo.php"] [unique_id "apPktqg6skwqJ2NpVh_aAwAAAj0"]
[Sun Aug 30 03:07:18.752611 2026] [security2:error] [pid 499145:tid 499360] [client 4.205.62.107:36645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/saiga.php"] [unique_id "apPktlJNq1G5uRhTNntl1wAAAFU"]
[Sun Aug 30 03:07:18.762939 2026] [security2:error] [pid 501390:tid 501606] [client 4.205.62.107:65365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/cache-compat.php"] [unique_id "apPktqg6skwqJ2NpVh_aGgAAAmo"]
[Sun Aug 30 03:07:18.770405 2026] [security2:error] [pid 501390:tid 501579] [client 20.104.50.220:17280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/seiso.php"] [unique_id "apPktqg6skwqJ2NpVh_aIAAAAk8"]
[Sun Aug 30 03:07:18.781536 2026] [authz_core:error] [pid 501390:tid 501547] [client 74.7.243.204:34708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_SG
[Sun Aug 30 03:07:18.781858 2026] [authz_core:error] [pid 501390:tid 501547] [client 74.7.243.204:34708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_SG
[Sun Aug 30 03:07:18.781861 2026] [security2:error] [pid 499145:tid 499367] [client 20.196.209.81:19108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/goods.php"] [unique_id "apPktlJNq1G5uRhTNntl4QAAAFw"]
[Sun Aug 30 03:07:18.783239 2026] [security2:error] [pid 501390:tid 501562] [client 20.104.18.15:28544] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/.mopj.php"] [unique_id "apPktqg6skwqJ2NpVh_aKQAAAj4"]
[Sun Aug 30 03:07:18.789055 2026] [security2:error] [pid 501390:tid 501646] [client 20.48.251.3:56344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/xa.php"] [unique_id "apPktqg6skwqJ2NpVh_aLwAAApI"]
[Sun Aug 30 03:07:18.801555 2026] [authz_core:error] [pid 501390:tid 501584] [client 66.249.66.39:56841] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:18.803038 2026] [authz_core:error] [pid 501390:tid 501584] [client 66.249.66.39:56841] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:18.825316 2026] [security2:error] [pid 501390:tid 501611] [client 68.155.159.216:65498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apPktqg6skwqJ2NpVh_aVwAAAm8"]
[Sun Aug 30 03:07:18.861986 2026] [security2:error] [pid 499145:tid 499355] [client 4.205.62.107:2799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/wdf.php"] [unique_id "apPktlJNq1G5uRhTNntl_QAAAFA"]
[Sun Aug 30 03:07:18.868448 2026] [authz_core:error] [pid 501390:tid 501539] [client 66.249.66.201:53506] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:18.868771 2026] [authz_core:error] [pid 501390:tid 501539] [client 66.249.66.201:53506] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:18.878367 2026] [security2:error] [pid 501390:tid 501616] [client 20.48.160.90:61442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/Hd.php"] [unique_id "apPktqg6skwqJ2NpVh_afQAAAnQ"]
[Sun Aug 30 03:07:18.885379 2026] [security2:error] [pid 501390:tid 501598] [client 20.104.18.15:18319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/wsd.php"] [unique_id "apPktqg6skwqJ2NpVh_ahAAAAmI"]
[Sun Aug 30 03:07:18.909356 2026] [security2:error] [pid 501390:tid 501526] [client 20.104.50.220:47095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-title.php"] [unique_id "apPktqg6skwqJ2NpVh_ajAAAAho"]
[Sun Aug 30 03:07:18.925548 2026] [security2:error] [pid 501390:tid 501612] [client 68.155.159.216:12412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/themes.php"] [unique_id "apPktqg6skwqJ2NpVh_algAAAnA"]
[Sun Aug 30 03:07:18.951045 2026] [security2:error] [pid 501390:tid 501624] [client 20.104.18.15:23526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/zoo2.php"] [unique_id "apPktqg6skwqJ2NpVh_aowAAAnw"]
[Sun Aug 30 03:07:18.978346 2026] [security2:error] [pid 501390:tid 501560] [client 20.196.209.81:17197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/themes/panel.php"] [unique_id "apPktqg6skwqJ2NpVh_avQAAAjw"]
[Sun Aug 30 03:07:18.988166 2026] [security2:error] [pid 501390:tid 501567] [client 4.205.62.107:22551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/css.php"] [unique_id "apPktqg6skwqJ2NpVh_axAAAAkM"]
[Sun Aug 30 03:07:18.989912 2026] [security2:error] [pid 499145:tid 499375] [client 20.104.18.15:43267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/blog.php"] [unique_id "apPktlJNq1G5uRhTNntmJAAAAGQ"]
[Sun Aug 30 03:07:19.001681 2026] [security2:error] [pid 501390:tid 501597] [client 20.104.50.220:5588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/lord.php"] [unique_id "apPkt6g6skwqJ2NpVh_azAAAAmE"]
[Sun Aug 30 03:07:19.042064 2026] [security2:error] [pid 501390:tid 501611] [client 20.48.160.90:30786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/im.php"] [unique_id "apPkt6g6skwqJ2NpVh_a7wAAAm8"]
[Sun Aug 30 03:07:19.055104 2026] [security2:error] [pid 501390:tid 501537] [client 34.125.55.247:48500] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.engaginggoddaily.com"] [uri "/.github/.env"] [unique_id "apPkt6g6skwqJ2NpVh_a-wAAAiU"]
[Sun Aug 30 03:07:19.056185 2026] [security2:error] [pid 501390:tid 501550] [client 34.125.55.247:48466] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/public/.env"] [unique_id "apPkt6g6skwqJ2NpVh_a_AAAAjI"]
[Sun Aug 30 03:07:19.061324 2026] [security2:error] [pid 501390:tid 501549] [client 34.125.55.247:48566] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.engaginggoddaily.com"] [uri "/.gcloud/credentials.json"] [unique_id "apPkt6g6skwqJ2NpVh_bCgAAAjE"]
[Sun Aug 30 03:07:19.063591 2026] [proxy_http:error] [pid 501390:tid 501634] (20014)Internal error (specific information not available): [client 34.125.55.247:48514] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:19.063610 2026] [proxy:error] [pid 501390:tid 501634] [client 34.125.55.247:48514] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.aws/credentials
[Sun Aug 30 03:07:19.063829 2026] [security2:error] [pid 501390:tid 501588] [client 20.48.250.41:53494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/aaa.php"] [unique_id "apPkt6g6skwqJ2NpVh_bDwAAAlg"]
[Sun Aug 30 03:07:19.071366 2026] [proxy_http:error] [pid 501390:tid 501560] (20014)Internal error (specific information not available): [client 34.125.55.247:48474] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:19.071381 2026] [proxy:error] [pid 501390:tid 501560] [client 34.125.55.247:48474] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.git/config
[Sun Aug 30 03:07:19.079500 2026] [proxy_http:error] [pid 501390:tid 501576] (20014)Internal error (specific information not available): [client 34.125.55.247:48494] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:19.079513 2026] [proxy:error] [pid 501390:tid 501576] [client 34.125.55.247:48494] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.git-credentials
[Sun Aug 30 03:07:19.086964 2026] [proxy_http:error] [pid 501390:tid 501605] (20014)Internal error (specific information not available): [client 34.125.55.247:48552] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:19.086984 2026] [proxy:error] [pid 501390:tid 501605] [client 34.125.55.247:48552] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/aws.json
[Sun Aug 30 03:07:19.087478 2026] [security2:error] [pid 501390:tid 501587] [client 20.48.251.3:7058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/fff.php"] [unique_id "apPkt6g6skwqJ2NpVh_bIwAAAlc"]
[Sun Aug 30 03:07:19.093882 2026] [proxy_http:error] [pid 501390:tid 501524] (20014)Internal error (specific information not available): [client 34.125.55.247:48536] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:19.093897 2026] [proxy:error] [pid 501390:tid 501524] [client 34.125.55.247:48536] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/root/.aws/credentials
[Sun Aug 30 03:07:19.101094 2026] [proxy_http:error] [pid 501390:tid 501568] (20014)Internal error (specific information not available): [client 34.125.55.247:48574] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:19.101114 2026] [proxy:error] [pid 501390:tid 501568] [client 34.125.55.247:48574] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.azure/credentials
[Sun Aug 30 03:07:19.147339 2026] [lsapi:error] [pid 501390:tid 501440] [remote 45.73.162.106:7404] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:07:19.147484 2026] [lsapi:error] [pid 501390:tid 501440] [remote 45.73.162.106:7404] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:07:19.148873 2026] [lsapi:error] [pid 501390:tid 501440] [remote 45.73.162.106:7404] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:07:19.155877 2026] [authz_core:error] [pid 501390:tid 501644] [client 216.73.216.128:47669] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:19.156264 2026] [authz_core:error] [pid 501390:tid 501644] [client 216.73.216.128:47669] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:19.158082 2026] [security2:error] [pid 501390:tid 501592] [client 20.104.50.220:52855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/&heker!.php"] [unique_id "apPkt6g6skwqJ2NpVh_bUAAAAlw"]
[Sun Aug 30 03:07:19.161939 2026] [security2:error] [pid 501390:tid 501523] [client 20.48.250.41:45315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/24.php"] [unique_id "apPkt6g6skwqJ2NpVh_bUgAAAhc"]
[Sun Aug 30 03:07:19.167117 2026] [security2:error] [pid 501390:tid 501594] [client 20.48.251.3:44353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/public/mah.php.php"] [unique_id "apPkt6g6skwqJ2NpVh_bWgAAAl4"]
[Sun Aug 30 03:07:19.170838 2026] [security2:error] [pid 501390:tid 501530] [client 20.104.50.220:61498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/imageswp-init.php"] [unique_id "apPkt6g6skwqJ2NpVh_bXwAAAh4"]
[Sun Aug 30 03:07:19.176701 2026] [security2:error] [pid 501390:tid 501606] [client 20.196.209.81:20919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/m.php"] [unique_id "apPkt6g6skwqJ2NpVh_bZAAAAmo"]
[Sun Aug 30 03:07:19.185902 2026] [security2:error] [pid 501390:tid 501599] [client 20.48.160.90:61528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/fc.php"] [unique_id "apPkt6g6skwqJ2NpVh_bbwAAAmM"]
[Sun Aug 30 03:07:19.197878 2026] [security2:error] [pid 501390:tid 501642] [client 20.48.250.41:50161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/xsox.php"] [unique_id "apPkt6g6skwqJ2NpVh_beQAAAo4"]
[Sun Aug 30 03:07:19.202066 2026] [security2:error] [pid 501390:tid 501580] [client 68.155.159.216:61320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-content/index.php"] [unique_id "apPkt6g6skwqJ2NpVh_bfgAAAlA"]
[Sun Aug 30 03:07:19.207543 2026] [security2:error] [pid 501390:tid 501541] [client 68.155.159.216:62291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-content/themes/index.php"] [unique_id "apPkt6g6skwqJ2NpVh_bgQAAAik"]
[Sun Aug 30 03:07:19.219957 2026] [security2:error] [pid 501390:tid 501614] [client 20.151.200.44:27322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/pk.php"] [unique_id "apPkt6g6skwqJ2NpVh_biQAAAnI"]
[Sun Aug 30 03:07:19.229219 2026] [security2:error] [pid 501390:tid 501530] [client 20.104.50.220:33318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/contactz.php"] [unique_id "apPkt6g6skwqJ2NpVh_bjwAAAh4"]
[Sun Aug 30 03:07:19.257821 2026] [authz_core:error] [pid 501390:tid 501576] [client 74.7.243.204:34708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:19.258263 2026] [authz_core:error] [pid 501390:tid 501576] [client 74.7.243.204:34708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:19.280075 2026] [security2:error] [pid 501390:tid 501622] [client 68.155.159.216:62032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/lv.php"] [unique_id "apPkt6g6skwqJ2NpVh_bwQAAAno"]
[Sun Aug 30 03:07:19.294012 2026] [security2:error] [pid 501390:tid 501591] [client 20.48.250.41:45337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/155.php"] [unique_id "apPkt6g6skwqJ2NpVh_byQAAAls"]
[Sun Aug 30 03:07:19.299698 2026] [security2:error] [pid 501390:tid 501550] [client 4.205.62.107:51736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/classsmtps.php"] [unique_id "apPkt6g6skwqJ2NpVh_b0QAAAjI"]
[Sun Aug 30 03:07:19.318684 2026] [security2:error] [pid 501390:tid 501536] [client 20.48.160.90:37995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/ke.php"] [unique_id "apPkt6g6skwqJ2NpVh_b5gAAAiQ"]
[Sun Aug 30 03:07:19.327907 2026] [security2:error] [pid 501390:tid 501584] [client 20.104.18.15:13573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/gjewuagf.php"] [unique_id "apPkt6g6skwqJ2NpVh_b8AAAAlQ"]
[Sun Aug 30 03:07:19.331075 2026] [security2:error] [pid 501390:tid 501635] [client 20.48.250.41:53451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/lkui.php"] [unique_id "apPkt6g6skwqJ2NpVh_b9AAAAoc"]
[Sun Aug 30 03:07:19.375075 2026] [security2:error] [pid 501390:tid 501544] [client 20.104.49.130:64082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/chosen.php"] [unique_id "apPkt6g6skwqJ2NpVh_cFgAAAiw"]
[Sun Aug 30 03:07:19.424640 2026] [autoindex:error] [pid 499145:tid 499387] [client 20.196.209.81:13696] AH01276: Cannot serve directory /home4/devstol/public_html/thelakewoodshuttle/wp-content/themes/twentytwentyfive/styles/sections/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:07:19.455337 2026] [security2:error] [pid 501390:tid 501588] [client 20.48.160.90:30728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/tf.php"] [unique_id "apPkt6g6skwqJ2NpVh_cVAAAAlg"]
[Sun Aug 30 03:07:19.458600 2026] [security2:error] [pid 501390:tid 501523] [client 20.48.250.41:53389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apPkt6g6skwqJ2NpVh_cVgAAAhc"]
[Sun Aug 30 03:07:19.462293 2026] [authz_core:error] [pid 499145:tid 499314] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:19.462539 2026] [authz_core:error] [pid 499145:tid 499314] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:19.467031 2026] [security2:error] [pid 501390:tid 501572] [client 20.48.250.41:45955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/file.php"] [unique_id "apPkt6g6skwqJ2NpVh_cXgAAAkg"]
[Sun Aug 30 03:07:19.472183 2026] [security2:error] [pid 501390:tid 501525] [client 20.104.50.220:27072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/core.php"] [unique_id "apPkt6g6skwqJ2NpVh_cZQAAAhk"]
[Sun Aug 30 03:07:19.474471 2026] [security2:error] [pid 501390:tid 501605] [client 20.104.18.15:29057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/m.php"] [unique_id "apPkt6g6skwqJ2NpVh_cZwAAAmk"]
[Sun Aug 30 03:07:19.505405 2026] [security2:error] [pid 501390:tid 501643] [client 94.154.43.125:63348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.one18cleaning.com"] [uri "/.env"] [unique_id "apPkt6g6skwqJ2NpVh_cigAAAo8"]
[Sun Aug 30 03:07:19.512846 2026] [security2:error] [pid 501390:tid 501549] [client 94.154.43.125:63358] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.one18cleaning.com"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "apPkt6g6skwqJ2NpVh_cjgAAAjE"]
[Sun Aug 30 03:07:19.520363 2026] [security2:error] [pid 501390:tid 501573] [client 20.104.50.220:32101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/sys.php"] [unique_id "apPkt6g6skwqJ2NpVh_clwAAAkk"]
[Sun Aug 30 03:07:19.524404 2026] [authz_core:error] [pid 501390:tid 501541] [client 216.73.216.128:1374] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:19.524705 2026] [authz_core:error] [pid 501390:tid 501541] [client 216.73.216.128:1374] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:19.563824 2026] [security2:error] [pid 499145:tid 499279] [client 20.196.209.81:13696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/twentytwentyfive/styles/sections/pk.php"] [unique_id "apPkt1JNq1G5uRhTNntm-QAAAAQ"]
[Sun Aug 30 03:07:19.570691 2026] [security2:error] [pid 501390:tid 501596] [client 4.205.62.107:64476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/ebahvhhh.php"] [unique_id "apPkt6g6skwqJ2NpVh_c1QAAAmA"]
[Sun Aug 30 03:07:19.575572 2026] [security2:error] [pid 501390:tid 501635] [client 20.196.209.81:19115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/doc.php"] [unique_id "apPkt6g6skwqJ2NpVh_c2wAAAoc"]
[Sun Aug 30 03:07:19.584864 2026] [security2:error] [pid 501390:tid 501597] [client 20.48.160.90:37737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/px.php"] [unique_id "apPkt6g6skwqJ2NpVh_c4gAAAmE"]
[Sun Aug 30 03:07:19.584884 2026] [security2:error] [pid 499145:tid 499208] [remote 66.116.251.167:58250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.251.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aheavenlyfootmassage.com"] [uri "/wp-login.php"] [unique_id "apPkt1JNq1G5uRhTNntnAQAAZT4"]
[Sun Aug 30 03:07:19.586833 2026] [security2:error] [pid 501390:tid 501605] [client 20.48.250.41:53382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/motu.php"] [unique_id "apPkt6g6skwqJ2NpVh_c5AAAAmk"]
[Sun Aug 30 03:07:19.595873 2026] [authz_core:error] [pid 501390:tid 501603] [client 66.249.66.72:59896] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:19.596229 2026] [authz_core:error] [pid 501390:tid 501603] [client 66.249.66.72:59896] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:19.613593 2026] [security2:error] [pid 499145:tid 499286] [client 4.205.62.107:32031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/pass4.php"] [unique_id "apPkt1JNq1G5uRhTNntnDQAAAAs"]
[Sun Aug 30 03:07:19.617894 2026] [security2:error] [pid 499145:tid 499313] [client 20.48.250.41:45980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPkt1JNq1G5uRhTNntnEQAAACY"]
[Sun Aug 30 03:07:19.648952 2026] [security2:error] [pid 501390:tid 501624] [client 4.205.62.107:63964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/aws.php"] [unique_id "apPkt6g6skwqJ2NpVh_c8wAAAnw"]
[Sun Aug 30 03:07:19.657700 2026] [security2:error] [pid 501390:tid 501593] [client 152.42.176.114:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.mithosweets.com.au"] [uri "/license.txt"] [unique_id "apPkt6g6skwqJ2NpVh_c9AAAAl0"]
[Sun Aug 30 03:07:19.677835 2026] [security2:error] [pid 499145:tid 499353] [client 20.48.251.3:50005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/configuration.php"] [unique_id "apPkt1JNq1G5uRhTNntnIAAAAE4"]
[Sun Aug 30 03:07:19.683731 2026] [security2:error] [pid 501390:tid 501526] [client 20.104.18.15:34700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/atomlib.php"] [unique_id "apPkt6g6skwqJ2NpVh_dAAAAAho"]
[Sun Aug 30 03:07:19.698667 2026] [security2:error] [pid 499145:tid 499327] [client 20.151.200.44:47052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPkt1JNq1G5uRhTNntnLAAAADQ"]
[Sun Aug 30 03:07:19.713887 2026] [security2:error] [pid 501390:tid 501597] [client 4.205.62.107:18631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/asdf.php"] [unique_id "apPkt6g6skwqJ2NpVh_dGwAAAmE"]
[Sun Aug 30 03:07:19.714860 2026] [security2:error] [pid 501390:tid 501559] [client 20.48.160.90:61533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/jg.php"] [unique_id "apPkt6g6skwqJ2NpVh_dHAAAAjs"]
[Sun Aug 30 03:07:19.730454 2026] [security2:error] [pid 501390:tid 501548] [client 20.48.250.41:53468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/Ov-Simple1.php"] [unique_id "apPkt6g6skwqJ2NpVh_dNQAAAjA"]
[Sun Aug 30 03:07:19.742812 2026] [security2:error] [pid 499145:tid 499382] [client 68.155.159.216:11221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-admin/images/index.php"] [unique_id "apPkt1JNq1G5uRhTNntnRQAAAGs"]
[Sun Aug 30 03:07:19.745160 2026] [security2:error] [pid 499145:tid 499354] [client 20.104.18.15:51706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/img.php"] [unique_id "apPkt1JNq1G5uRhTNntnRgAAAE8"]
[Sun Aug 30 03:07:19.762364 2026] [security2:error] [pid 501390:tid 501588] [client 20.48.250.41:45358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/06.php"] [unique_id "apPkt6g6skwqJ2NpVh_dRgAAAlg"]
[Sun Aug 30 03:07:19.774293 2026] [authz_core:error] [pid 501390:tid 501559] [client 74.7.243.204:34708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:19.774552 2026] [authz_core:error] [pid 501390:tid 501559] [client 74.7.243.204:34708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:19.781400 2026] [security2:error] [pid 499145:tid 499313] [client 68.155.159.216:54240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apPkt1JNq1G5uRhTNntnWwAAACY"]
[Sun Aug 30 03:07:19.850880 2026] [security2:error] [pid 499145:tid 499308] [client 20.104.50.220:52854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/lock360.php"] [unique_id "apPkt1JNq1G5uRhTNntnegAAACE"]
[Sun Aug 30 03:07:19.852776 2026] [security2:error] [pid 499145:tid 499387] [client 20.48.160.90:61487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/yj.php"] [unique_id "apPkt1JNq1G5uRhTNntnewAAAHA"]
[Sun Aug 30 03:07:19.871488 2026] [security2:error] [pid 501390:tid 501625] [client 20.48.250.41:50146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/wp-blogs.php"] [unique_id "apPkt6g6skwqJ2NpVh_dkQAAAn0"]
[Sun Aug 30 03:07:19.884067 2026] [security2:error] [pid 501390:tid 501579] [client 4.205.62.107:36676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/ammika.php"] [unique_id "apPkt6g6skwqJ2NpVh_dngAAAk8"]
[Sun Aug 30 03:07:19.898184 2026] [security2:error] [pid 501390:tid 501584] [client 4.205.62.107:65334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/aws_keys.php"] [unique_id "apPkt6g6skwqJ2NpVh_dpAAAAlQ"]
[Sun Aug 30 03:07:19.908405 2026] [security2:error] [pid 501390:tid 501533] [client 20.104.50.220:17256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/155.php"] [unique_id "apPkt6g6skwqJ2NpVh_dqAAAAiE"]
[Sun Aug 30 03:07:19.916462 2026] [security2:error] [pid 501390:tid 501528] [client 20.48.250.41:45356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/class.php"] [unique_id "apPkt6g6skwqJ2NpVh_dqwAAAhw"]
[Sun Aug 30 03:07:19.919946 2026] [security2:error] [pid 501390:tid 501597] [client 20.48.251.3:56367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/ws61.php"] [unique_id "apPkt6g6skwqJ2NpVh_drQAAAmE"]
[Sun Aug 30 03:07:19.925518 2026] [security2:error] [pid 501390:tid 501544] [client 20.104.18.15:28602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/bengi.php"] [unique_id "apPkt6g6skwqJ2NpVh_dsAAAAiw"]
[Sun Aug 30 03:07:19.966174 2026] [security2:error] [pid 501390:tid 501578] [client 20.196.209.81:19089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/users.php"] [unique_id "apPkt6g6skwqJ2NpVh_dxgAAAk4"]
[Sun Aug 30 03:07:19.976170 2026] [autoindex:error] [pid 501390:tid 501615] [client 20.196.209.81:5703] AH01276: Cannot serve directory /home4/devstol/public_html/thelakewoodshuttle/wp-content/themes/twentytwentythree/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:07:19.986665 2026] [security2:error] [pid 499145:tid 499312] [client 20.48.160.90:30781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/zi.php"] [unique_id "apPkt1JNq1G5uRhTNntntAAAACU"]
[Sun Aug 30 03:07:20.001096 2026] [security2:error] [pid 499145:tid 499400] [client 4.205.62.107:2367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/bb.php"] [unique_id "apPkuFJNq1G5uRhTNntnvAAAAH0"]
[Sun Aug 30 03:07:20.026081 2026] [security2:error] [pid 501390:tid 501646] [client 20.104.49.130:48055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/222.php"] [unique_id "apPkuKg6skwqJ2NpVh_d4wAAApI"]
[Sun Aug 30 03:07:20.034034 2026] [security2:error] [pid 501390:tid 501632] [client 20.104.18.15:18425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/bulet.php"] [unique_id "apPkuKg6skwqJ2NpVh_d6wAAAoQ"]
[Sun Aug 30 03:07:20.034505 2026] [security2:error] [pid 501390:tid 501583] [client 20.104.50.220:42047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/Eagle.php"] [unique_id "apPkuKg6skwqJ2NpVh_d7QAAAlM"]
[Sun Aug 30 03:07:20.049905 2026] [security2:error] [pid 501390:tid 501549] [client 20.104.50.220:46652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-we.php"] [unique_id "apPkuKg6skwqJ2NpVh_d_wAAAjE"]
[Sun Aug 30 03:07:20.050298 2026] [security2:error] [pid 499145:tid 499292] [client 20.48.250.41:50101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/mini.php"] [unique_id "apPkuFJNq1G5uRhTNntn1wAAABE"]
[Sun Aug 30 03:07:20.337742 2026] [qos:error] [pid 499145:tid 499341] [client 200.58.82.209:36599] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=200.58.82.209, id=apPkuFJNq1G5uRhTNntoQAAAAEI
[Sun Aug 30 03:07:20.340708 2026] [qos:error] [pid 499145:tid 499315] [client 95.135.140.104:37235] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=95.135.140.104, id=apPkuFJNq1G5uRhTNntoQQAAACg
[Sun Aug 30 03:07:20.342912 2026] [qos:error] [pid 499145:tid 499335] [client 103.249.18.148:55946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.249.18.148, id=apPkuFJNq1G5uRhTNntoQwAAADw
[Sun Aug 30 03:07:20.343003 2026] [qos:error] [pid 499145:tid 499342] [client 123.25.252.5:45722] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=123.25.252.5, id=apPkuFJNq1G5uRhTNntoQgAAAEM
[Sun Aug 30 03:07:20.351940 2026] [qos:error] [pid 499145:tid 499375] [client 120.232.115.170:13478] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=120.232.115.170, id=apPkuFJNq1G5uRhTNntoRAAAAGQ
[Sun Aug 30 03:07:20.356691 2026] [qos:error] [pid 499145:tid 499295] [client 157.10.184.125:54894] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=157.10.184.125, id=apPkuFJNq1G5uRhTNntoRQAAABQ
[Sun Aug 30 03:07:20.357430 2026] [qos:error] [pid 499145:tid 499286] [client 221.7.239.219:34328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=221.7.239.219, id=apPkuFJNq1G5uRhTNntoRwAAAAs
[Sun Aug 30 03:07:20.360964 2026] [qos:error] [pid 499145:tid 499397] [client 205.209.65.102:34512] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=205.209.65.102, id=apPkuFJNq1G5uRhTNntoSAAAAHo
[Sun Aug 30 03:07:20.363024 2026] [qos:error] [pid 499145:tid 499394] [client 23.129.64.144:57705] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=23.129.64.144, id=apPkuFJNq1G5uRhTNntoSQAAAHc
[Sun Aug 30 03:07:20.377492 2026] [qos:error] [pid 499145:tid 499341] [client 103.157.79.9:48448] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=103.157.79.9, id=apPkuFJNq1G5uRhTNntoSgAAAEI
[Sun Aug 30 03:07:20.377491 2026] [qos:error] [pid 499145:tid 499315] [client 104.28.251.138:15298] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=104.28.251.138, id=apPkuFJNq1G5uRhTNntoSwAAACg
[Sun Aug 30 03:07:20.377739 2026] [qos:error] [pid 499145:tid 499335] [client 180.195.99.168:37194] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=180.195.99.168, id=apPkuFJNq1G5uRhTNntoTAAAADw
[Sun Aug 30 03:07:20.378141 2026] [qos:error] [pid 499145:tid 499342] [client 85.8.47.208:36414] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=85.8.47.208, id=apPkuFJNq1G5uRhTNntoTQAAAEM
[Sun Aug 30 03:07:20.381673 2026] [qos:error] [pid 499145:tid 499375] [client 35.78.66.144:49010] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=35.78.66.144, id=apPkuFJNq1G5uRhTNntoTgAAAGQ
[Sun Aug 30 03:07:20.381873 2026] [qos:error] [pid 499145:tid 499295] [client 203.76.112.107:54080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=203.76.112.107, id=apPkuFJNq1G5uRhTNntoTwAAABQ
[Sun Aug 30 03:07:20.382266 2026] [qos:error] [pid 499145:tid 499286] [client 83.244.77.101:43506] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=83.244.77.101, id=apPkuFJNq1G5uRhTNntoUAAAAAs
[Sun Aug 30 03:07:20.383135 2026] [qos:error] [pid 499145:tid 499394] [client 177.53.154.51:36486] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=177.53.154.51, id=apPkuFJNq1G5uRhTNntoUgAAAHc
[Sun Aug 30 03:07:20.383507 2026] [qos:error] [pid 499145:tid 499397] [client 179.63.6.240:46096] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=179.63.6.240, id=apPkuFJNq1G5uRhTNntoUQAAAHo
[Sun Aug 30 03:07:20.384308 2026] [qos:error] [pid 499145:tid 499341] [client 103.153.62.28:45854] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.153.62.28, id=apPkuFJNq1G5uRhTNntoUwAAAEI
[Sun Aug 30 03:07:20.385275 2026] [qos:error] [pid 499145:tid 499315] [client 82.110.112.36:44950] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=82.110.112.36, id=apPkuFJNq1G5uRhTNntoVAAAACg
[Sun Aug 30 03:07:20.387146 2026] [qos:error] [pid 499145:tid 499335] [client 196.251.222.242:54276] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=196.251.222.242, id=apPkuFJNq1G5uRhTNntoVQAAADw
[Sun Aug 30 03:07:20.388193 2026] [qos:error] [pid 499145:tid 499342] [client 64.112.40.81:33088] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=64.112.40.81, id=apPkuFJNq1G5uRhTNntoVgAAAEM
[Sun Aug 30 03:07:20.391414 2026] [qos:error] [pid 499145:tid 499375] [client 45.127.58.70:43054] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.127.58.70, id=apPkuFJNq1G5uRhTNntoVwAAAGQ
[Sun Aug 30 03:07:20.393536 2026] [qos:error] [pid 499145:tid 499295] [client 38.45.67.95:56684] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.45.67.95, id=apPkuFJNq1G5uRhTNntoWAAAABQ
[Sun Aug 30 03:07:20.397159 2026] [qos:error] [pid 499145:tid 499286] [client 103.80.83.27:56974] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.80.83.27, id=apPkuFJNq1G5uRhTNntoWQAAAAs
[Sun Aug 30 03:07:20.406684 2026] [qos:error] [pid 499145:tid 499394] [client 34.134.26.114:34816] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=34.134.26.114, id=apPkuFJNq1G5uRhTNntoWgAAAHc
[Sun Aug 30 03:07:20.407715 2026] [qos:error] [pid 499145:tid 499341] [client 164.92.148.68:47584] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=164.92.148.68, id=apPkuFJNq1G5uRhTNntoXAAAAEI
[Sun Aug 30 03:07:20.408215 2026] [qos:error] [pid 499145:tid 499397] [client 87.58.216.160:53202] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=87.58.216.160, id=apPkuFJNq1G5uRhTNntoWwAAAHo
[Sun Aug 30 03:07:20.408871 2026] [qos:error] [pid 499145:tid 499315] [client 45.230.170.13:35836] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.230.170.13, id=apPkuFJNq1G5uRhTNntoXQAAACg
[Sun Aug 30 03:07:20.416829 2026] [qos:error] [pid 499145:tid 499335] [client 45.65.137.218:51848] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.65.137.218, id=apPkuFJNq1G5uRhTNntoXgAAADw
[Sun Aug 30 03:07:20.422252 2026] [qos:error] [pid 499145:tid 499342] [client 77.239.106.24:56764] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=77.239.106.24, id=apPkuFJNq1G5uRhTNntoXwAAAEM
[Sun Aug 30 03:07:20.426483 2026] [qos:error] [pid 499145:tid 499375] [client 122.52.169.90:40467] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=122.52.169.90, id=apPkuFJNq1G5uRhTNntoYAAAAGQ
[Sun Aug 30 03:07:20.427563 2026] [qos:error] [pid 499145:tid 499295] [client 206.42.79.243:42704] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=206.42.79.243, id=apPkuFJNq1G5uRhTNntoYQAAABQ
[Sun Aug 30 03:07:20.434386 2026] [qos:error] [pid 499145:tid 499286] [client 203.91.118.6:60870] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=203.91.118.6, id=apPkuFJNq1G5uRhTNntoYgAAAAs
[Sun Aug 30 03:07:20.441789 2026] [qos:error] [pid 499145:tid 499394] [client 177.226.85.7:44790] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=177.226.85.7, id=apPkuFJNq1G5uRhTNntoYwAAAHc
[Sun Aug 30 03:07:20.444654 2026] [qos:error] [pid 501390:tid 501537] [client 213.199.56.121:38084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=213.199.56.121, id=apPkuKg6skwqJ2NpVh_eBAAAAiU
[Sun Aug 30 03:07:20.450529 2026] [qos:error] [pid 499145:tid 499341] [client 103.147.134.33:42431] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.147.134.33, id=apPkuFJNq1G5uRhTNntoZAAAAEI
[Sun Aug 30 03:07:20.455464 2026] [qos:error] [pid 499145:tid 499397] [client 165.101.43.53:39388] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=165.101.43.53, id=apPkuFJNq1G5uRhTNntoZQAAAHo
[Sun Aug 30 03:07:20.455472 2026] [qos:error] [pid 499145:tid 499335] [client 62.201.227.157:34555] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=62.201.227.157, id=apPkuFJNq1G5uRhTNntoZwAAADw
[Sun Aug 30 03:07:20.455478 2026] [qos:error] [pid 499145:tid 499315] [client 46.23.63.34:49541] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=46.23.63.34, id=apPkuFJNq1G5uRhTNntoZgAAACg
[Sun Aug 30 03:07:20.455670 2026] [qos:error] [pid 501390:tid 501529] [client 85.14.247.185:35800] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=85.14.247.185, id=apPkuKg6skwqJ2NpVh_eBQAAAh0
[Sun Aug 30 03:07:20.456726 2026] [qos:error] [pid 499145:tid 499342] [client 190.14.147.19:59264] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=190.14.147.19, id=apPkuFJNq1G5uRhTNntoaAAAAEM
[Sun Aug 30 03:07:20.460462 2026] [qos:error] [pid 499145:tid 499295] [client 103.154.230.73:55172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.154.230.73, id=apPkuFJNq1G5uRhTNntoaQAAABQ
[Sun Aug 30 03:07:20.460577 2026] [qos:error] [pid 499145:tid 499375] [client 203.76.112.234:58030] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=203.76.112.234, id=apPkuFJNq1G5uRhTNntoagAAAGQ
[Sun Aug 30 03:07:20.462385 2026] [qos:error] [pid 499145:tid 499286] [client 161.153.45.81:46404] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=161.153.45.81, id=apPkuFJNq1G5uRhTNntoawAAAAs
[Sun Aug 30 03:07:20.465989 2026] [qos:error] [pid 499145:tid 499394] [client 177.53.154.51:36674] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=177.53.154.51, id=apPkuFJNq1G5uRhTNntobAAAAHc
[Sun Aug 30 03:07:20.467157 2026] [qos:error] [pid 499145:tid 499341] [client 193.233.247.104:60257] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=193.233.247.104, id=apPkuFJNq1G5uRhTNntobQAAAEI
[Sun Aug 30 03:07:20.469612 2026] [qos:error] [pid 499145:tid 499335] [client 103.248.210.28:46436] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.248.210.28, id=apPkuFJNq1G5uRhTNntobgAAADw
[Sun Aug 30 03:07:20.469858 2026] [qos:error] [pid 499145:tid 499315] [client 104.28.194.6:64600] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=104.28.194.6, id=apPkuFJNq1G5uRhTNntobwAAACg
[Sun Aug 30 03:07:20.472086 2026] [qos:error] [pid 499145:tid 499397] [client 14.224.221.42:48188] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=14.224.221.42, id=apPkuFJNq1G5uRhTNntocAAAAHo
[Sun Aug 30 03:07:20.472800 2026] [qos:error] [pid 499145:tid 499342] [client 122.52.35.84:54712] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=122.52.35.84, id=apPkuFJNq1G5uRhTNntocQAAAEM
[Sun Aug 30 03:07:20.474832 2026] [qos:error] [pid 499145:tid 499295] [client 116.196.150.180:59870] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=116.196.150.180, id=apPkuFJNq1G5uRhTNntocgAAABQ
[Sun Aug 30 03:07:20.475586 2026] [qos:error] [pid 499145:tid 499375] [client 103.157.78.190:35006] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.157.78.190, id=apPkuFJNq1G5uRhTNntocwAAAGQ
[Sun Aug 30 03:07:20.484978 2026] [qos:error] [pid 499145:tid 499286] [client 45.230.168.38:56000] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.230.168.38, id=apPkuFJNq1G5uRhTNntodAAAAAs
[Sun Aug 30 03:07:20.485794 2026] [qos:error] [pid 499145:tid 499394] [client 117.4.137.168:57206] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=117.4.137.168, id=apPkuFJNq1G5uRhTNntodQAAAHc
[Sun Aug 30 03:07:20.486478 2026] [qos:error] [pid 499145:tid 499341] [client 103.48.70.27:60084] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.48.70.27, id=apPkuFJNq1G5uRhTNntodgAAAEI
[Sun Aug 30 03:07:20.490851 2026] [qos:error] [pid 499145:tid 499335] [client 201.20.42.46:55058] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=201.20.42.46, id=apPkuFJNq1G5uRhTNntodwAAADw
[Sun Aug 30 03:07:20.495446 2026] [qos:error] [pid 499145:tid 499315] [client 147.45.60.110:39586] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=147.45.60.110, id=apPkuFJNq1G5uRhTNntoeAAAACg
[Sun Aug 30 03:07:20.497030 2026] [qos:error] [pid 499145:tid 499301] [client 192.76.153.253:2232] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=192.76.153.253, id=apPkuFJNq1G5uRhTNntoeQAAABo
[Sun Aug 30 03:07:20.499260 2026] [qos:error] [pid 499145:tid 499397] [client 200.58.214.100:45042] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=200.58.214.100, id=apPkuFJNq1G5uRhTNntoegAAAHo
[Sun Aug 30 03:07:20.499973 2026] [qos:error] [pid 499145:tid 499342] [client 103.180.123.111:40538] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.180.123.111, id=apPkuFJNq1G5uRhTNntoewAAAEM
[Sun Aug 30 03:07:20.506706 2026] [security2:error] [pid 499145:tid 499192] [remote 66.116.251.167:58250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.251.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aheavenlyfootmassage.com"] [uri "/wp-login.php"] [unique_id "apPkuFJNq1G5uRhTNntofAAAFC4"], referer: https://aheavenlyfootmassage.com/wp-login.php
[Sun Aug 30 03:07:20.509867 2026] [qos:error] [pid 499145:tid 499375] [client 181.174.228.175:40234] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=181.174.228.175, id=apPkuFJNq1G5uRhTNntofQAAAGQ
[Sun Aug 30 03:07:20.515396 2026] [qos:error] [pid 499145:tid 499286] [client 200.24.159.131:50304] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=200.24.159.131, id=apPkuFJNq1G5uRhTNntofgAAAAs
[Sun Aug 30 03:07:20.518496 2026] [qos:error] [pid 499145:tid 499394] [client 162.4.44.12:7160] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=162.4.44.12, id=apPkuFJNq1G5uRhTNntofwAAAHc
[Sun Aug 30 03:07:20.519756 2026] [qos:error] [pid 499145:tid 499341] [client 43.164.136.189:51868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=43.164.136.189, id=apPkuFJNq1G5uRhTNntogAAAAEI
[Sun Aug 30 03:07:20.527050 2026] [qos:error] [pid 499145:tid 499335] [client 149.28.251.187:53678] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=149.28.251.187, id=apPkuFJNq1G5uRhTNntogQAAADw
[Sun Aug 30 03:07:20.527055 2026] [qos:error] [pid 499145:tid 499315] [client 176.119.25.107:45714] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=176.119.25.107, id=apPkuFJNq1G5uRhTNntoggAAACg
[Sun Aug 30 03:07:20.528248 2026] [qos:error] [pid 499145:tid 499301] [client 176.111.37.5:20980] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=176.111.37.5, id=apPkuFJNq1G5uRhTNntogwAAABo
[Sun Aug 30 03:07:20.529135 2026] [qos:error] [pid 499145:tid 499397] [client 90.77.122.70:36094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=90.77.122.70, id=apPkuFJNq1G5uRhTNntohAAAAHo
[Sun Aug 30 03:07:20.530626 2026] [qos:error] [pid 499145:tid 499342] [client 38.211.76.201:45588] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.211.76.201, id=apPkuFJNq1G5uRhTNntohQAAAEM
[Sun Aug 30 03:07:20.535631 2026] [qos:error] [pid 499145:tid 499295] [client 117.2.104.13:55386] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=117.2.104.13, id=apPkuFJNq1G5uRhTNntohgAAABQ
[Sun Aug 30 03:07:20.538293 2026] [qos:error] [pid 499145:tid 499375] [client 103.35.171.194:36030] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.35.171.194, id=apPkuFJNq1G5uRhTNntohwAAAGQ
[Sun Aug 30 03:07:20.540903 2026] [qos:error] [pid 499145:tid 499328] [client 104.28.246.49:27357] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=104.28.246.49, id=apPkuFJNq1G5uRhTNntoiAAAADU
[Sun Aug 30 03:07:20.543557 2026] [qos:error] [pid 499145:tid 499286] [client 102.209.76.172:48334] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=102.209.76.172, id=apPkuFJNq1G5uRhTNntoiQAAAAs
[Sun Aug 30 03:07:20.545538 2026] [qos:error] [pid 499145:tid 499394] [client 165.154.20.187:33274] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=165.154.20.187, id=apPkuFJNq1G5uRhTNntoigAAAHc
[Sun Aug 30 03:07:20.552808 2026] [qos:error] [pid 499145:tid 499341] [client 203.76.112.234:58104] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=203.76.112.234, id=apPkuFJNq1G5uRhTNntoiwAAAEI
[Sun Aug 30 03:07:20.560184 2026] [qos:error] [pid 499145:tid 499315] [client 35.235.153.127:16384] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=35.235.153.127, id=apPkuFJNq1G5uRhTNntojAAAACg
[Sun Aug 30 03:07:20.560790 2026] [qos:error] [pid 499145:tid 499335] [client 176.111.37.216:49326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=176.111.37.216, id=apPkuFJNq1G5uRhTNntojQAAADw
[Sun Aug 30 03:07:20.561179 2026] [qos:error] [pid 499145:tid 499301] [client 103.113.116.246:59015] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.113.116.246, id=apPkuFJNq1G5uRhTNntojgAAABo
[Sun Aug 30 03:07:20.561518 2026] [qos:error] [pid 499145:tid 499397] [client 103.147.118.66:33994] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.147.118.66, id=apPkuFJNq1G5uRhTNntojwAAAHo
[Sun Aug 30 03:07:20.563717 2026] [qos:error] [pid 499145:tid 499342] [client 103.162.57.138:48914] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.162.57.138, id=apPkuFJNq1G5uRhTNntokAAAAEM
[Sun Aug 30 03:07:20.564445 2026] [qos:error] [pid 499145:tid 499295] [client 38.76.138.129:51791] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.76.138.129, id=apPkuFJNq1G5uRhTNntokQAAABQ
[Sun Aug 30 03:07:20.569242 2026] [qos:error] [pid 499145:tid 499375] [client 5.255.123.162:60028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=5.255.123.162, id=apPkuFJNq1G5uRhTNntokgAAAGQ
[Sun Aug 30 03:07:20.573816 2026] [qos:error] [pid 499145:tid 499328] [client 88.30.14.94:54568] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=88.30.14.94, id=apPkuFJNq1G5uRhTNntokwAAADU
[Sun Aug 30 03:07:20.575391 2026] [qos:error] [pid 499145:tid 499286] [client 219.148.171.178:4673] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=219.148.171.178, id=apPkuFJNq1G5uRhTNntolAAAAAs
[Sun Aug 30 03:07:20.576240 2026] [qos:error] [pid 501390:tid 501613] [client 202.65.238.122:2495] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=202.65.238.122, id=apPkuKg6skwqJ2NpVh_eBgAAAnE
[Sun Aug 30 03:07:20.578092 2026] [qos:error] [pid 499145:tid 499394] [client 103.81.195.190:40828] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.81.195.190, id=apPkuFJNq1G5uRhTNntolQAAAHc
[Sun Aug 30 03:07:20.578614 2026] [qos:error] [pid 499145:tid 499344] [client 102.213.179.25:54552] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=102.213.179.25, id=apPkuFJNq1G5uRhTNntolgAAAEU
[Sun Aug 30 03:07:20.579868 2026] [qos:error] [pid 499145:tid 499341] [client 103.165.157.247:52474] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.165.157.247, id=apPkuFJNq1G5uRhTNntolwAAAEI
[Sun Aug 30 03:07:20.581693 2026] [qos:error] [pid 499145:tid 499315] [client 160.20.39.93:41217] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=160.20.39.93, id=apPkuFJNq1G5uRhTNntomAAAACg
[Sun Aug 30 03:07:20.586321 2026] [qos:error] [pid 499145:tid 499335] [client 103.112.65.238:50238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.112.65.238, id=apPkuFJNq1G5uRhTNntomQAAADw
[Sun Aug 30 03:07:20.589736 2026] [qos:error] [pid 499145:tid 499301] [client 195.226.213.254:37014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=195.226.213.254, id=apPkuFJNq1G5uRhTNntomgAAABo
[Sun Aug 30 03:07:20.596835 2026] [qos:error] [pid 499145:tid 499397] [client 150.241.91.238:45962] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=150.241.91.238, id=apPkuFJNq1G5uRhTNntomwAAAHo
[Sun Aug 30 03:07:20.596874 2026] [qos:error] [pid 499145:tid 499342] [client 45.180.62.250:45430] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.180.62.250, id=apPkuFJNq1G5uRhTNntonAAAAEM
[Sun Aug 30 03:07:20.611212 2026] [qos:error] [pid 499145:tid 499295] [client 41.217.205.126:35198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=41.217.205.126, id=apPkuFJNq1G5uRhTNntonQAAABQ
[Sun Aug 30 03:07:20.613006 2026] [qos:error] [pid 501390:tid 501585] [client 181.174.231.72:37096] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=181.174.231.72, id=apPkuKg6skwqJ2NpVh_eBwAAAlU
[Sun Aug 30 03:07:20.619258 2026] [qos:error] [pid 499145:tid 499375] [client 78.155.64.122:44820] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=78.155.64.122, id=apPkuFJNq1G5uRhTNntongAAAGQ
[Sun Aug 30 03:07:20.654153 2026] [qos:error] [pid 499145:tid 499328] [client 186.250.147.255:50633] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=186.250.147.255, id=apPkuFJNq1G5uRhTNntonwAAADU
[Sun Aug 30 03:07:20.654231 2026] [qos:error] [pid 499145:tid 499286] [client 165.101.230.77:53925] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=165.101.230.77, id=apPkuFJNq1G5uRhTNntooAAAAAs
[Sun Aug 30 03:07:20.659850 2026] [qos:error] [pid 499145:tid 499394] [client 34.134.26.114:34817] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=34.134.26.114, id=apPkuFJNq1G5uRhTNntooQAAAHc
[Sun Aug 30 03:07:20.665103 2026] [qos:error] [pid 501390:tid 501447] [remote 193.186.4.147:41457] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=193.186.4.147, id=apPkuKg6skwqJ2NpVh_eCAACMzg, referer: https://www.google.com/
[Sun Aug 30 03:07:20.680010 2026] [qos:error] [pid 499145:tid 499341] [client 191.100.23.22:45503] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=191.100.23.22, id=apPkuFJNq1G5uRhTNntoowAAAEI
[Sun Aug 30 03:07:20.680150 2026] [qos:error] [pid 499145:tid 499344] [client 37.221.241.115:49882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=37.221.241.115, id=apPkuFJNq1G5uRhTNntoogAAAEU
[Sun Aug 30 03:07:20.680694 2026] [qos:error] [pid 499145:tid 499341] [client 103.140.207.186:47054] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.140.207.186, id=apPkuFJNq1G5uRhTNntopAAAAEI
[Sun Aug 30 03:07:20.682105 2026] [qos:error] [pid 499145:tid 499335] [client 85.8.47.211:57222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=85.8.47.211, id=apPkuFJNq1G5uRhTNntopQAAADw
[Sun Aug 30 03:07:20.686663 2026] [qos:error] [pid 499145:tid 499301] [client 170.245.132.81:58842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=170.245.132.81, id=apPkuFJNq1G5uRhTNntopgAAABo
[Sun Aug 30 03:07:20.693819 2026] [qos:error] [pid 499145:tid 499397] [client 154.59.111.42:39548] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=154.59.111.42, id=apPkuFJNq1G5uRhTNntopwAAAHo
[Sun Aug 30 03:07:20.695394 2026] [qos:error] [pid 499145:tid 499342] [client 83.148.74.114:52771] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=83.148.74.114, id=apPkuFJNq1G5uRhTNntoqAAAAEM
[Sun Aug 30 03:07:20.699121 2026] [qos:error] [pid 499145:tid 499295] [client 45.144.54.40:60314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.144.54.40, id=apPkuFJNq1G5uRhTNntoqQAAABQ
[Sun Aug 30 03:07:20.702676 2026] [qos:error] [pid 499145:tid 499375] [client 113.174.113.56:40550] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=113.174.113.56, id=apPkuFJNq1G5uRhTNntoqgAAAGQ
[Sun Aug 30 03:07:20.704168 2026] [qos:error] [pid 499145:tid 499328] [client 43.252.107.106:39914] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=43.252.107.106, id=apPkuFJNq1G5uRhTNntoqwAAADU
[Sun Aug 30 03:07:20.705246 2026] [qos:error] [pid 499145:tid 499286] [client 193.202.11.25:37690] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=193.202.11.25, id=apPkuFJNq1G5uRhTNntorAAAAAs
[Sun Aug 30 03:07:20.705620 2026] [qos:error] [pid 499145:tid 499394] [client 94.102.224.138:59434] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=94.102.224.138, id=apPkuFJNq1G5uRhTNntorQAAAHc
[Sun Aug 30 03:07:20.708288 2026] [qos:error] [pid 499145:tid 499315] [client 85.8.47.212:47418] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=85.8.47.212, id=apPkuFJNq1G5uRhTNntorgAAACg
[Sun Aug 30 03:07:20.710166 2026] [qos:error] [pid 499145:tid 499344] [client 203.95.220.114:49572] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=203.95.220.114, id=apPkuFJNq1G5uRhTNntorwAAAEU
[Sun Aug 30 03:07:20.713111 2026] [qos:error] [pid 499145:tid 499341] [client 45.121.216.229:36990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.121.216.229, id=apPkuFJNq1G5uRhTNntosAAAAEI
[Sun Aug 30 03:07:20.713663 2026] [qos:error] [pid 499145:tid 499335] [client 38.65.174.247:49046] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.65.174.247, id=apPkuFJNq1G5uRhTNntosQAAADw
[Sun Aug 30 03:07:20.715119 2026] [qos:error] [pid 499145:tid 499301] [client 85.60.193.47:42382] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=85.60.193.47, id=apPkuFJNq1G5uRhTNntosgAAABo
[Sun Aug 30 03:07:20.718198 2026] [qos:error] [pid 499145:tid 499397] [client 186.1.173.12:38416] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=186.1.173.12, id=apPkuFJNq1G5uRhTNntoswAAAHo
[Sun Aug 30 03:07:20.718719 2026] [qos:error] [pid 499145:tid 499342] [client 146.4.93.102:39080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=146.4.93.102, id=apPkuFJNq1G5uRhTNntotAAAAEM
[Sun Aug 30 03:07:20.719626 2026] [qos:error] [pid 499145:tid 499295] [client 203.175.103.9:56929] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=203.175.103.9, id=apPkuFJNq1G5uRhTNntotQAAABQ
[Sun Aug 30 03:07:20.719879 2026] [qos:error] [pid 499145:tid 499375] [client 202.58.78.30:60526] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=202.58.78.30, id=apPkuFJNq1G5uRhTNntotgAAAGQ
[Sun Aug 30 03:07:20.721983 2026] [qos:error] [pid 499145:tid 499328] [client 147.45.218.2:38902] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=147.45.218.2, id=apPkuFJNq1G5uRhTNntotwAAADU
[Sun Aug 30 03:07:20.723609 2026] [qos:error] [pid 499145:tid 499286] [client 38.172.181.22:46262] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.172.181.22, id=apPkuFJNq1G5uRhTNntouAAAAAs
[Sun Aug 30 03:07:20.732095 2026] [qos:error] [pid 499145:tid 499394] [client 94.28.32.110:56368] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=94.28.32.110, id=apPkuFJNq1G5uRhTNntouQAAAHc
[Sun Aug 30 03:07:20.733370 2026] [qos:error] [pid 499145:tid 499315] [client 103.250.128.23:44884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.250.128.23, id=apPkuFJNq1G5uRhTNntougAAACg
[Sun Aug 30 03:07:20.733847 2026] [qos:error] [pid 499145:tid 499315] [client 95.58.145.162:37429] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=95.58.145.162, id=apPkuFJNq1G5uRhTNntouwAAACg
[Sun Aug 30 03:07:20.734749 2026] [qos:error] [pid 499145:tid 499341] [client 202.21.124.129:46241] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=202.21.124.129, id=apPkuFJNq1G5uRhTNntovAAAAEI
[Sun Aug 30 03:07:20.743017 2026] [qos:error] [pid 501390:tid 501606] [client 45.173.12.103:45238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.173.12.103, id=apPkuKg6skwqJ2NpVh_eCQAAAmo
[Sun Aug 30 03:07:20.756122 2026] [qos:error] [pid 499145:tid 499335] [client 103.210.161.8:54148] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.210.161.8, id=apPkuFJNq1G5uRhTNntovQAAADw
[Sun Aug 30 03:07:20.758528 2026] [qos:error] [pid 499145:tid 499301] [client 38.111.103.17:56761] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.111.103.17, id=apPkuFJNq1G5uRhTNntovgAAABo
[Sun Aug 30 03:07:20.761533 2026] [qos:error] [pid 499145:tid 499397] [client 59.36.210.211:49875] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=59.36.210.211, id=apPkuFJNq1G5uRhTNntovwAAAHo
[Sun Aug 30 03:07:20.761793 2026] [qos:error] [pid 499145:tid 499342] [client 202.59.206.58:49020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=202.59.206.58, id=apPkuFJNq1G5uRhTNntowAAAAEM
[Sun Aug 30 03:07:20.766916 2026] [qos:error] [pid 499145:tid 499295] [client 177.10.59.156:53742] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=177.10.59.156, id=apPkuFJNq1G5uRhTNntowQAAABQ
[Sun Aug 30 03:07:20.772380 2026] [qos:error] [pid 499145:tid 499328] [client 37.150.97.11:41176] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=37.150.97.11, id=apPkuFJNq1G5uRhTNntowwAAADU
[Sun Aug 30 03:07:20.773056 2026] [qos:error] [pid 499145:tid 499286] [client 163.181.207.170:34328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=163.181.207.170, id=apPkuFJNq1G5uRhTNntoxAAAAAs
[Sun Aug 30 03:07:20.773626 2026] [qos:error] [pid 499145:tid 499394] [client 114.9.55.102:43542] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=114.9.55.102, id=apPkuFJNq1G5uRhTNntoxQAAAHc
[Sun Aug 30 03:07:20.780300 2026] [qos:error] [pid 499145:tid 499344] [client 103.166.227.194:39350] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.166.227.194, id=apPkuFJNq1G5uRhTNntoxgAAAEU
[Sun Aug 30 03:07:20.782145 2026] [qos:error] [pid 499145:tid 499315] [client 27.77.96.91:55170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=27.77.96.91, id=apPkuFJNq1G5uRhTNntoxwAAACg
[Sun Aug 30 03:07:20.784588 2026] [qos:error] [pid 499145:tid 499341] [client 103.159.78.237:53371] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.159.78.237, id=apPkuFJNq1G5uRhTNntoyAAAAEI
[Sun Aug 30 03:07:20.786930 2026] [qos:error] [pid 499145:tid 499335] [client 103.58.251.102:36472] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.58.251.102, id=apPkuFJNq1G5uRhTNntoyQAAADw
[Sun Aug 30 03:07:20.797428 2026] [qos:error] [pid 499145:tid 499301] [client 221.121.1.43:41659] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=221.121.1.43, id=apPkuFJNq1G5uRhTNntoygAAABo
[Sun Aug 30 03:07:20.798895 2026] [qos:error] [pid 499145:tid 499397] [client 171.5.130.187:44152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=171.5.130.187, id=apPkuFJNq1G5uRhTNntoywAAAHo
[Sun Aug 30 03:07:20.799845 2026] [qos:error] [pid 499145:tid 499342] [client 58.63.243.11:55326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=58.63.243.11, id=apPkuFJNq1G5uRhTNntozAAAAEM
[Sun Aug 30 03:07:20.802600 2026] [qos:error] [pid 499145:tid 499295] [client 165.0.69.116:51120] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=165.0.69.116, id=apPkuFJNq1G5uRhTNntozQAAABQ
[Sun Aug 30 03:07:20.816754 2026] [qos:error] [pid 499145:tid 499328] [client 177.54.40.12:54800] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=177.54.40.12, id=apPkuFJNq1G5uRhTNntozgAAADU
[Sun Aug 30 03:07:20.821232 2026] [qos:error] [pid 499145:tid 499286] [client 181.115.147.68:46333] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=181.115.147.68, id=apPkuFJNq1G5uRhTNntozwAAAAs
[Sun Aug 30 03:07:20.821230 2026] [qos:error] [pid 499145:tid 499394] [client 102.223.22.130:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=102.223.22.130, id=apPkuFJNq1G5uRhTNnto0AAAAHc
[Sun Aug 30 03:07:20.826111 2026] [qos:error] [pid 499145:tid 499344] [client 105.22.37.218:41296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=105.22.37.218, id=apPkuFJNq1G5uRhTNnto0QAAAEU
[Sun Aug 30 03:07:20.827944 2026] [qos:error] [pid 499145:tid 499315] [client 103.184.67.45:44322] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.184.67.45, id=apPkuFJNq1G5uRhTNnto0gAAACg
[Sun Aug 30 03:07:20.828579 2026] [qos:error] [pid 499145:tid 499341] [client 81.70.40.86:50689] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=81.70.40.86, id=apPkuFJNq1G5uRhTNnto0wAAAEI
[Sun Aug 30 03:07:20.836990 2026] [qos:error] [pid 499145:tid 499335] [client 72.62.59.63:46786] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=72.62.59.63, id=apPkuFJNq1G5uRhTNnto1AAAADw
[Sun Aug 30 03:07:20.845706 2026] [qos:error] [pid 499145:tid 499301] [client 42.118.3.236:55958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=42.118.3.236, id=apPkuFJNq1G5uRhTNnto1QAAABo
[Sun Aug 30 03:07:20.848946 2026] [qos:error] [pid 499145:tid 499397] [client 45.115.41.158:41960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.115.41.158, id=apPkuFJNq1G5uRhTNnto1gAAAHo
[Sun Aug 30 03:07:20.850409 2026] [qos:error] [pid 499145:tid 499342] [client 91.229.151.118:36714] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=91.229.151.118, id=apPkuFJNq1G5uRhTNnto1wAAAEM
[Sun Aug 30 03:07:20.862666 2026] [qos:error] [pid 499145:tid 499295] [client 170.246.144.196:5686] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=170.246.144.196, id=apPkuFJNq1G5uRhTNnto2AAAABQ
[Sun Aug 30 03:07:20.870516 2026] [qos:error] [pid 499145:tid 499328] [client 201.20.42.46:55052] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=201.20.42.46, id=apPkuFJNq1G5uRhTNnto2QAAADU
[Sun Aug 30 03:07:20.871547 2026] [qos:error] [pid 499145:tid 499286] [client 38.19.239.218:59937] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.19.239.218, id=apPkuFJNq1G5uRhTNnto2wAAAAs
[Sun Aug 30 03:07:20.871548 2026] [qos:error] [pid 499145:tid 499394] [client 122.201.27.91:51188] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=122.201.27.91, id=apPkuFJNq1G5uRhTNnto2gAAAHc
[Sun Aug 30 03:07:20.884281 2026] [qos:error] [pid 499145:tid 499344] [client 89.45.220.129:46838] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=89.45.220.129, id=apPkuFJNq1G5uRhTNnto3AAAAEU
[Sun Aug 30 03:07:20.884681 2026] [qos:error] [pid 499145:tid 499315] [client 37.187.109.70:55030] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=37.187.109.70, id=apPkuFJNq1G5uRhTNnto3QAAACg
[Sun Aug 30 03:07:20.898949 2026] [qos:error] [pid 499145:tid 499341] [client 205.209.65.107:53302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=205.209.65.107, id=apPkuFJNq1G5uRhTNnto3gAAAEI
[Sun Aug 30 03:07:20.903023 2026] [qos:error] [pid 499145:tid 499335] [client 139.135.170.23:51964] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=139.135.170.23, id=apPkuFJNq1G5uRhTNnto3wAAADw
[Sun Aug 30 03:07:20.903026 2026] [qos:error] [pid 499145:tid 499301] [client 45.189.36.6:48138] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.189.36.6, id=apPkuFJNq1G5uRhTNnto4AAAABo
[Sun Aug 30 03:07:20.909852 2026] [qos:error] [pid 499145:tid 499397] [client 221.7.239.219:34328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=221.7.239.219, id=apPkuFJNq1G5uRhTNnto4QAAAHo
[Sun Aug 30 03:07:20.921813 2026] [qos:error] [pid 499145:tid 499342] [client 31.76.12.115:37960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=31.76.12.115, id=apPkuFJNq1G5uRhTNnto4gAAAEM
[Sun Aug 30 03:07:20.937301 2026] [qos:error] [pid 501390:tid 501567] [client 85.121.50.25:45522] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=85.121.50.25, id=apPkuKg6skwqJ2NpVh_eCgAAAkM
[Sun Aug 30 03:07:20.937400 2026] [qos:error] [pid 499145:tid 499314] [client 43.163.112.8:50398] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=43.163.112.8, id=apPkuFJNq1G5uRhTNnto5AAAACc
[Sun Aug 30 03:07:20.937746 2026] [qos:error] [pid 499145:tid 499295] [client 31.76.31.221:49894] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=31.76.31.221, id=apPkuFJNq1G5uRhTNnto4wAAABQ
[Sun Aug 30 03:07:20.940128 2026] [qos:error] [pid 499145:tid 499328] [client 181.67.122.157:30555] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=181.67.122.157, id=apPkuFJNq1G5uRhTNnto5QAAADU
[Sun Aug 30 03:07:20.942013 2026] [qos:error] [pid 499145:tid 499394] [client 103.189.97.113:35050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.189.97.113, id=apPkuFJNq1G5uRhTNnto5gAAAHc
[Sun Aug 30 03:07:20.944935 2026] [qos:error] [pid 499145:tid 499286] [client 103.111.116.233:58928] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.111.116.233, id=apPkuFJNq1G5uRhTNnto5wAAAAs
[Sun Aug 30 03:07:20.949135 2026] [qos:error] [pid 501390:tid 501633] [client 103.191.255.111:39126] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.191.255.111, id=apPkuKg6skwqJ2NpVh_eCwAAAoU
[Sun Aug 30 03:07:20.949999 2026] [qos:error] [pid 499145:tid 499344] [client 85.159.94.124:44786] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=85.159.94.124, id=apPkuFJNq1G5uRhTNnto6AAAAEU
[Sun Aug 30 03:07:20.951050 2026] [qos:error] [pid 499145:tid 499341] [client 181.13.210.60:37962] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=181.13.210.60, id=apPkuFJNq1G5uRhTNnto6gAAAEI
[Sun Aug 30 03:07:20.955656 2026] [qos:error] [pid 499145:tid 499335] [client 63.250.52.167:53014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=63.250.52.167, id=apPkuFJNq1G5uRhTNnto6wAAADw
[Sun Aug 30 03:07:20.956722 2026] [authz_core:error] [pid 499145:tid 499315] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:20.956755 2026] [qos:error] [pid 499145:tid 499301] [client 31.25.11.143:42902] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=31.25.11.143, id=apPkuFJNq1G5uRhTNnto7AAAABo
[Sun Aug 30 03:07:20.956973 2026] [authz_core:error] [pid 499145:tid 499315] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:20.957441 2026] [qos:error] [pid 499145:tid 499397] [client 167.250.47.60:40090] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=167.250.47.60, id=apPkuFJNq1G5uRhTNnto7QAAAHo
[Sun Aug 30 03:07:20.957456 2026] [qos:error] [pid 499145:tid 499342] [client 115.79.195.95:39945] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=115.79.195.95, id=apPkuFJNq1G5uRhTNnto7gAAAEM
[Sun Aug 30 03:07:20.957628 2026] [qos:error] [pid 499145:tid 499314] [client 109.72.55.69:46686] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=109.72.55.69, id=apPkuFJNq1G5uRhTNnto7wAAACc
[Sun Aug 30 03:07:20.958379 2026] [qos:error] [pid 499145:tid 499295] [client 185.191.239.248:56782] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=185.191.239.248, id=apPkuFJNq1G5uRhTNnto8AAAABQ
[Sun Aug 30 03:07:20.962841 2026] [qos:error] [pid 499145:tid 499328] [client 103.172.42.221:38340] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.172.42.221, id=apPkuFJNq1G5uRhTNnto8QAAADU
[Sun Aug 30 03:07:20.963226 2026] [qos:error] [pid 499145:tid 499286] [client 43.109.48.180:46368] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=43.109.48.180, id=apPkuFJNq1G5uRhTNnto8wAAAAs
[Sun Aug 30 03:07:20.963459 2026] [qos:error] [pid 499145:tid 499394] [client 110.159.129.213:43878] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=110.159.129.213, id=apPkuFJNq1G5uRhTNnto8gAAAHc
[Sun Aug 30 03:07:20.965321 2026] [qos:error] [pid 499145:tid 499344] [client 42.240.136.180:50780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=42.240.136.180, id=apPkuFJNq1G5uRhTNnto9AAAAEU
[Sun Aug 30 03:07:20.966183 2026] [qos:error] [pid 499145:tid 499375] [client 112.64.135.45:35391] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=112.64.135.45, id=apPkuFJNq1G5uRhTNnto9QAAAGQ
[Sun Aug 30 03:07:20.980103 2026] [qos:error] [pid 499145:tid 499341] [client 103.164.55.81:41040] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.164.55.81, id=apPkuFJNq1G5uRhTNnto9gAAAEI
[Sun Aug 30 03:07:20.981513 2026] [qos:error] [pid 499145:tid 499335] [client 207.248.0.193:60802] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=207.248.0.193, id=apPkuFJNq1G5uRhTNnto9wAAADw
[Sun Aug 30 03:07:20.982994 2026] [qos:error] [pid 499145:tid 499301] [client 41.72.199.106:53940] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=41.72.199.106, id=apPkuFJNq1G5uRhTNnto-AAAABo
[Sun Aug 30 03:07:20.989863 2026] [qos:error] [pid 499145:tid 499397] [client 14.169.77.73:48842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=14.169.77.73, id=apPkuFJNq1G5uRhTNnto-QAAAHo
[Sun Aug 30 03:07:20.996184 2026] [qos:error] [pid 499145:tid 499342] [client 190.100.200.3:55310] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=190.100.200.3, id=apPkuFJNq1G5uRhTNnto-gAAAEM
[Sun Aug 30 03:07:20.997732 2026] [qos:error] [pid 499145:tid 499314] [client 202.21.124.129:46076] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=202.21.124.129, id=apPkuFJNq1G5uRhTNnto-wAAACc
[Sun Aug 30 03:07:20.998297 2026] [qos:error] [pid 499145:tid 499295] [client 58.64.160.132:35828] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=58.64.160.132, id=apPkuFJNq1G5uRhTNnto_AAAABQ
[Sun Aug 30 03:07:20.999425 2026] [qos:error] [pid 499145:tid 499328] [client 181.78.197.196:57959] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=181.78.197.196, id=apPkuFJNq1G5uRhTNnto_QAAADU
[Sun Aug 30 03:07:21.009921 2026] [qos:error] [pid 499145:tid 499286] [client 202.4.127.90:34014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=202.4.127.90, id=apPkuVJNq1G5uRhTNnto_gAAAAs
[Sun Aug 30 03:07:21.015083 2026] [qos:error] [pid 499145:tid 499344] [client 165.99.194.61:47856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=165.99.194.61, id=apPkuVJNq1G5uRhTNntpAAAAAEU
[Sun Aug 30 03:07:21.015240 2026] [qos:error] [pid 499145:tid 499394] [client 124.83.46.180:52650] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=124.83.46.180, id=apPkuVJNq1G5uRhTNnto_wAAAHc
[Sun Aug 30 03:07:21.020388 2026] [qos:error] [pid 499145:tid 499375] [client 2.144.6.22:52264] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=2.144.6.22, id=apPkuVJNq1G5uRhTNntpAQAAAGQ
[Sun Aug 30 03:07:21.023229 2026] [qos:error] [pid 499145:tid 499341] [client 152.32.74.91:41114] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=152.32.74.91, id=apPkuVJNq1G5uRhTNntpAgAAAEI
[Sun Aug 30 03:07:21.023565 2026] [qos:error] [pid 501390:tid 501526] [client 45.95.232.35:54007] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.95.232.35, id=apPkuag6skwqJ2NpVh_eDAAAAho
[Sun Aug 30 03:07:21.025179 2026] [qos:error] [pid 499145:tid 499335] [client 5.253.196.143:58716] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=5.253.196.143, id=apPkuVJNq1G5uRhTNntpAwAAADw
[Sun Aug 30 03:07:21.030079 2026] [qos:error] [pid 499145:tid 499301] [client 172.239.18.67:53210] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=172.239.18.67, id=apPkuVJNq1G5uRhTNntpBAAAABo
[Sun Aug 30 03:07:21.035465 2026] [qos:error] [pid 499145:tid 499397] [client 41.79.233.182:54961] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=41.79.233.182, id=apPkuVJNq1G5uRhTNntpBQAAAHo
[Sun Aug 30 03:07:21.037958 2026] [qos:error] [pid 499145:tid 499342] [client 31.130.131.191:37852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=31.130.131.191, id=apPkuVJNq1G5uRhTNntpBgAAAEM
[Sun Aug 30 03:07:21.041278 2026] [qos:error] [pid 499145:tid 499314] [client 138.117.14.237:53332] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=138.117.14.237, id=apPkuVJNq1G5uRhTNntpBwAAACc
[Sun Aug 30 03:07:21.042102 2026] [qos:error] [pid 499145:tid 499295] [client 144.24.171.189:50494] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=144.24.171.189, id=apPkuVJNq1G5uRhTNntpCAAAABQ
[Sun Aug 30 03:07:21.097109 2026] [http2:info] [pid 502397:tid 502397] h2_workers: created with min=128 max=192 idle_ms=600000
[Sun Aug 30 03:07:21.119120 2026] [security2:error] [pid 502397:tid 502564] [client 20.48.251.3:4728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/zaza.php"] [unique_id "apPkuWuFRxhFZfnD0nIODQAAAS8"]
[Sun Aug 30 03:07:21.119147 2026] [security2:error] [pid 502397:tid 502560] [client 195.178.110.247:26266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.martinvoelund.dk"] [uri "/index.php"] [unique_id "apPkuWuFRxhFZfnD0nIOCQAAASs"]
[Sun Aug 30 03:07:21.119177 2026] [security2:error] [pid 502397:tid 502532] [client 4.205.62.107:64696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/asa.php"] [unique_id "apPkuWuFRxhFZfnD0nIN_QAAAQ8"]
[Sun Aug 30 03:07:21.119263 2026] [security2:error] [pid 502397:tid 502547] [client 20.104.50.220:5525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/cyl.php"] [unique_id "apPkuWuFRxhFZfnD0nIOAgAAAR4"]
[Sun Aug 30 03:07:21.119289 2026] [security2:error] [pid 502397:tid 502530] [client 20.151.200.44:47097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/xda.php"] [unique_id "apPkuWuFRxhFZfnD0nIN-AAAAQ0"]
[Sun Aug 30 03:07:21.119316 2026] [security2:error] [pid 502397:tid 502533] [client 4.205.62.107:62273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/php_info.php"] [unique_id "apPkuWuFRxhFZfnD0nIN-wAAARA"]
[Sun Aug 30 03:07:21.119448 2026] [security2:error] [pid 502397:tid 502550] [client 68.155.159.216:61678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/about.php"] [unique_id "apPkuWuFRxhFZfnD0nIOBQAAASE"]
[Sun Aug 30 03:07:21.119635 2026] [security2:error] [pid 502397:tid 502529] [client 20.104.18.15:43994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/wp-admin/js/wp-load.php"] [unique_id "apPkuWuFRxhFZfnD0nIN-QAAAQw"]
[Sun Aug 30 03:07:21.119794 2026] [security2:error] [pid 502397:tid 502552] [client 20.48.251.3:45827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/autogooey.php"] [unique_id "apPkuWuFRxhFZfnD0nIOBwAAASM"]
[Sun Aug 30 03:07:21.119806 2026] [security2:error] [pid 502397:tid 502534] [client 68.155.159.216:12382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-mail.php"] [unique_id "apPkuWuFRxhFZfnD0nIN_AAAARE"]
[Sun Aug 30 03:07:21.119841 2026] [security2:error] [pid 502397:tid 502551] [client 20.48.251.3:12045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/server_info.php"] [unique_id "apPkuWuFRxhFZfnD0nIOBgAAASI"]
[Sun Aug 30 03:07:21.119892 2026] [security2:error] [pid 502397:tid 502537] [client 20.104.50.220:27127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/www.php"] [unique_id "apPkuWuFRxhFZfnD0nIN_wAAARQ"]
[Sun Aug 30 03:07:21.119925 2026] [security2:error] [pid 502397:tid 502563] [client 4.205.62.107:36029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/broadcasting.php"] [unique_id "apPkuWuFRxhFZfnD0nIODAAAAS4"]
[Sun Aug 30 03:07:21.119962 2026] [security2:error] [pid 502397:tid 502536] [client 4.205.62.107:51718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/cache-compat.php"] [unique_id "apPkuWuFRxhFZfnD0nIN_gAAARM"]
[Sun Aug 30 03:07:21.119974 2026] [security2:error] [pid 502397:tid 502531] [client 20.104.18.15:23536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/zoo1.php"] [unique_id "apPkuWuFRxhFZfnD0nIN-gAAAQ4"]
[Sun Aug 30 03:07:21.119986 2026] [security2:error] [pid 502397:tid 502549] [client 4.205.62.107:64051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/app.default.php"] [unique_id "apPkuWuFRxhFZfnD0nIOBAAAASA"]
[Sun Aug 30 03:07:21.119993 2026] [security2:error] [pid 502397:tid 502546] [client 20.104.49.130:53595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/zoo2.php"] [unique_id "apPkuWuFRxhFZfnD0nIOAQAAAR0"]
[Sun Aug 30 03:07:21.120114 2026] [security2:error] [pid 502397:tid 502562] [client 20.104.50.220:33316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/orange.php"] [unique_id "apPkuWuFRxhFZfnD0nIOCwAAAS0"]
[Sun Aug 30 03:07:21.120225 2026] [security2:error] [pid 502397:tid 502528] [client 20.48.160.90:30785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/ue.php"] [unique_id "apPkuWuFRxhFZfnD0nIN9wAAAQs"]
[Sun Aug 30 03:07:21.120399 2026] [security2:error] [pid 502397:tid 502561] [client 20.48.250.41:45342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/8.php"] [unique_id "apPkuWuFRxhFZfnD0nIOCgAAASw"]
[Sun Aug 30 03:07:21.120435 2026] [security2:error] [pid 502397:tid 502548] [client 20.104.50.220:61983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/images/upload.php"] [unique_id "apPkuWuFRxhFZfnD0nIOAwAAAR8"]
[Sun Aug 30 03:07:21.120482 2026] [security2:error] [pid 502397:tid 502581] [client 20.104.18.15:29646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/fling.php"] [unique_id "apPkuWuFRxhFZfnD0nIODgAAAUA"]
[Sun Aug 30 03:07:21.122169 2026] [security2:error] [pid 502397:tid 502572] [client 4.205.62.107:58174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/umgebung.php"] [unique_id "apPkuWuFRxhFZfnD0nIOEQAAATc"]
[Sun Aug 30 03:07:21.122252 2026] [security2:error] [pid 502397:tid 502573] [client 20.104.50.220:17246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/ppp.php"] [unique_id "apPkuWuFRxhFZfnD0nIOEgAAATg"]
[Sun Aug 30 03:07:21.123389 2026] [qos:error] [pid 499145:tid 499328] [client 82.66.253.58:34188] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=82.66.253.58, id=apPkuVJNq1G5uRhTNntpCQAAADU
[Sun Aug 30 03:07:21.123636 2026] [security2:error] [pid 502397:tid 502582] [client 20.48.251.3:13404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/xza.php"] [unique_id "apPkuWuFRxhFZfnD0nIOGQAAAUE"]
[Sun Aug 30 03:07:21.124151 2026] [security2:error] [pid 502397:tid 502529] [client 20.104.18.15:13710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/tnglzqmv.php"] [unique_id "apPkuWuFRxhFZfnD0nIOGgAAAQw"]
[Sun Aug 30 03:07:21.124386 2026] [qos:error] [pid 499145:tid 499328] [client 82.66.253.58:34188] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=82.66.253.58, id=apPkuVJNq1G5uRhTNntpCgAAADU
[Sun Aug 30 03:07:21.125189 2026] [security2:error] [pid 502397:tid 502588] [client 20.151.200.44:27634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/ft.php"] [unique_id "apPkuWuFRxhFZfnD0nIOHQAAAUc"]
[Sun Aug 30 03:07:21.125220 2026] [security2:error] [pid 502397:tid 502590] [client 20.104.18.15:34802] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "agrokomerc.mobi"] [uri "/1.php"] [unique_id "apPkuWuFRxhFZfnD0nIOHwAAAUg"]
[Sun Aug 30 03:07:21.125234 2026] [qos:error] [pid 499145:tid 499328] [client 82.66.253.58:34188] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=82.66.253.58, id=apPkuVJNq1G5uRhTNntpCwAAADU
[Sun Aug 30 03:07:21.125283 2026] [security2:error] [pid 502397:tid 502590] [client 20.104.18.15:34802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/1.php"] [unique_id "apPkuWuFRxhFZfnD0nIOHwAAAUg"]
[Sun Aug 30 03:07:21.126042 2026] [security2:error] [pid 502397:tid 502551] [client 20.104.50.220:31840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/tes.php"] [unique_id "apPkuWuFRxhFZfnD0nIOJAAAASI"]
[Sun Aug 30 03:07:21.126255 2026] [security2:error] [pid 502397:tid 502595] [client 68.155.159.216:56424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-includes/index.php"] [unique_id "apPkuWuFRxhFZfnD0nIOJgAAAU0"]
[Sun Aug 30 03:07:21.138989 2026] [security2:error] [pid 502397:tid 502599] [client 20.104.50.220:62801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/licensi.php"] [unique_id "apPkuWuFRxhFZfnD0nIOKQAAAVE"]
[Sun Aug 30 03:07:21.139123 2026] [security2:error] [pid 502397:tid 502605] [client 20.104.18.15:51588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/222.php"] [unique_id "apPkuWuFRxhFZfnD0nIOLgAAAVc"]
[Sun Aug 30 03:07:21.139311 2026] [security2:error] [pid 502397:tid 502574] [client 20.104.50.220:64454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/shellv3.php"] [unique_id "apPkuWuFRxhFZfnD0nIOZQAAATk"]
[Sun Aug 30 03:07:21.140173 2026] [security2:error] [pid 502397:tid 502604] [client 20.104.18.15:28572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/file2.php"] [unique_id "apPkuWuFRxhFZfnD0nIOLAAAAVY"]
[Sun Aug 30 03:07:21.141302 2026] [qos:error] [pid 502397:tid 502544] [client 171.226.73.226:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkuWuFRxhFZfnD0nIOIgAAARs
[Sun Aug 30 03:07:21.141672 2026] [qos:error] [pid 502397:tid 502558] [client 45.186.106.145:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.44, id=apPkuWuFRxhFZfnD0nIOJQAAASk
[Sun Aug 30 03:07:21.141964 2026] [qos:error] [pid 502397:tid 502568] [client 157.15.0.167:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=50.6.92.44, id=apPkuWuFRxhFZfnD0nIORgAAATM
[Sun Aug 30 03:07:21.144652 2026] [security2:error] [pid 502397:tid 502571] [client 68.155.159.216:63960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/about/function.php"] [unique_id "apPkuWuFRxhFZfnD0nIOSQAAATY"]
[Sun Aug 30 03:07:21.147733 2026] [qos:error] [pid 499145:tid 499377] [client 171.226.73.226:41038] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=171.226.73.226, id=apPkuVJNq1G5uRhTNntpDAAAAGY
[Sun Aug 30 03:07:21.149141 2026] [authz_core:error] [pid 502397:tid 502598] [client 216.73.216.128:25753] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:21.149661 2026] [authz_core:error] [pid 502397:tid 502570] [client 74.7.243.204:40994] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:21.149819 2026] [authz_core:error] [pid 502397:tid 502587] [client 66.249.66.41:43740] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:21.149997 2026] [authz_core:error] [pid 502397:tid 502570] [client 74.7.243.204:40994] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:21.150308 2026] [authz_core:error] [pid 502397:tid 502587] [client 66.249.66.41:43740] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:21.150415 2026] [authz_core:error] [pid 502397:tid 502561] [client 66.249.66.200:49809] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:21.150749 2026] [authz_core:error] [pid 502397:tid 502626] [client 216.73.216.128:63317] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:21.150882 2026] [authz_core:error] [pid 502397:tid 502561] [client 66.249.66.200:49809] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:21.151113 2026] [authz_core:error] [pid 502397:tid 502626] [client 216.73.216.128:63317] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:21.152745 2026] [security2:error] [pid 502397:tid 502573] [client 68.155.159.216:62058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apPkuWuFRxhFZfnD0nIOawAAATg"]
[Sun Aug 30 03:07:21.153803 2026] [security2:error] [pid 502397:tid 502623] [client 68.155.159.216:55134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-content/languages/about.php"] [unique_id "apPkuWuFRxhFZfnD0nIOOAAAAWk"]
[Sun Aug 30 03:07:21.159559 2026] [authz_core:error] [pid 502397:tid 502598] [client 216.73.216.128:25753] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:21.162783 2026] [qos:error] [pid 499145:tid 499375] [client 179.255.113.74:57158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=179.255.113.74, id=apPkuVJNq1G5uRhTNntpDwAAAGQ
[Sun Aug 30 03:07:21.164096 2026] [security2:error] [pid 502397:tid 502537] [client 4.205.62.107:18680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apPkuWuFRxhFZfnD0nIOLQAAARQ"]
[Sun Aug 30 03:07:21.168079 2026] [qos:error] [pid 501390:tid 501577] [client 187.193.105.19:41612] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=187.193.105.19, id=apPkuag6skwqJ2NpVh_eDQAAAk0
[Sun Aug 30 03:07:21.171083 2026] [authz_core:error] [pid 502397:tid 502580] [client 216.73.216.128:40582] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:21.171549 2026] [authz_core:error] [pid 502397:tid 502580] [client 216.73.216.128:40582] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:21.171980 2026] [qos:error] [pid 502397:tid 502574] [client 139.84.133.240:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkuWuFRxhFZfnD0nIOkQAAATk
[Sun Aug 30 03:07:21.171981 2026] [qos:error] [pid 499145:tid 499279] [client 45.186.106.145:44682] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.186.106.145, id=apPkuVJNq1G5uRhTNntpEAAAAAQ
[Sun Aug 30 03:07:21.173145 2026] [qos:error] [pid 502397:tid 502599] [client 42.96.18.62:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkuWuFRxhFZfnD0nIOkgAAAVE
[Sun Aug 30 03:07:21.180289 2026] [qos:error] [pid 502397:tid 502535] [client 176.114.125.112:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkuWuFRxhFZfnD0nIOlAAAARI
[Sun Aug 30 03:07:21.180780 2026] [qos:error] [pid 502397:tid 502599] [client 51.77.148.27:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkuWuFRxhFZfnD0nIOlQAAAVE
[Sun Aug 30 03:07:21.181045 2026] [qos:error] [pid 502397:tid 502567] [client 123.20.38.145:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkuWuFRxhFZfnD0nIOlwAAATI
[Sun Aug 30 03:07:21.182754 2026] [security2:error] [pid 502397:tid 502567] [client 20.104.18.15:18427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/av.php"] [unique_id "apPkuWuFRxhFZfnD0nIOmAAAATI"]
[Sun Aug 30 03:07:21.184593 2026] [qos:error] [pid 499145:tid 499304] [client 51.77.148.27:45610] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=51.77.148.27, id=apPkuVJNq1G5uRhTNntpEwAAAB0
[Sun Aug 30 03:07:21.188940 2026] [security2:error] [pid 502397:tid 502562] [client 20.104.50.220:46458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wpindex.php"] [unique_id "apPkuWuFRxhFZfnD0nIOnAAAAS0"]
[Sun Aug 30 03:07:21.189902 2026] [qos:error] [pid 502397:tid 502619] [client 178.89.238.40:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkuWuFRxhFZfnD0nIOnwAAAWU
[Sun Aug 30 03:07:21.202737 2026] [security2:error] [pid 502397:tid 502562] [client 4.205.62.107:2322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/file59.php"] [unique_id "apPkuWuFRxhFZfnD0nIOrQAAAS0"]
[Sun Aug 30 03:07:21.213168 2026] [security2:error] [pid 502397:tid 502536] [client 20.48.250.41:53501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/amp.php"] [unique_id "apPkuWuFRxhFZfnD0nIOtQAAARM"]
[Sun Aug 30 03:07:21.252011 2026] [security2:error] [pid 502397:tid 502543] [client 20.196.209.81:19966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/class.php"] [unique_id "apPkuWuFRxhFZfnD0nIO9QAAARo"]
[Sun Aug 30 03:07:21.259427 2026] [security2:error] [pid 502397:tid 502534] [client 20.48.160.90:37669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/nv.php"] [unique_id "apPkuWuFRxhFZfnD0nIO-QAAARE"]
[Sun Aug 30 03:07:21.260746 2026] [security2:error] [pid 502397:tid 502557] [client 20.196.209.81:5635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/twentytwentythree/patterns/index.php"] [unique_id "apPkuWuFRxhFZfnD0nIO-gAAASg"]
[Sun Aug 30 03:07:21.281089 2026] [security2:error] [pid 502397:tid 502631] [client 20.104.49.130:43320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/ops.php"] [unique_id "apPkuWuFRxhFZfnD0nIPDgAAAXE"]
[Sun Aug 30 03:07:21.284183 2026] [security2:error] [pid 502397:tid 502543] [client 20.48.250.41:46018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/0x0x.php"] [unique_id "apPkuWuFRxhFZfnD0nIPEQAAARo"]
[Sun Aug 30 03:07:21.285514 2026] [security2:error] [pid 502397:tid 502538] [client 195.178.110.247:39670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.martinvoelund.dk"] [uri "/index.php"] [unique_id "apPkuWuFRxhFZfnD0nIPEgAAARU"]
[Sun Aug 30 03:07:21.333660 2026] [qos:error] [pid 499145:tid 499281] [client 162.14.109.148:40280] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=162.14.109.148, id=apPkuVJNq1G5uRhTNntpVwAAAAY
[Sun Aug 30 03:07:21.334364 2026] [qos:error] [pid 499145:tid 499379] [client 43.245.131.213:47557] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=43.245.131.213, id=apPkuVJNq1G5uRhTNntpVgAAAGg
[Sun Aug 30 03:07:21.340980 2026] [qos:error] [pid 502397:tid 502615] [client 38.58.66.232:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkuWuFRxhFZfnD0nIPIAAAAWE
[Sun Aug 30 03:07:21.341150 2026] [qos:error] [pid 502397:tid 502557] [client 103.237.102.191:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkuWuFRxhFZfnD0nIPGQAAASg
[Sun Aug 30 03:07:21.356800 2026] [qos:error] [pid 499145:tid 499362] [client 43.160.242.118:38010] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=43.160.242.118, id=apPkuVJNq1G5uRhTNntpaAAAAFc
[Sun Aug 30 03:07:21.361076 2026] [qos:error] [pid 499145:tid 499327] [client 120.232.115.170:13478] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=120.232.115.170, id=apPkuVJNq1G5uRhTNntpaQAAADQ
[Sun Aug 30 03:07:21.361916 2026] [qos:error] [pid 502397:tid 502583] [client 117.184.119.210:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkuWuFRxhFZfnD0nIPMgAAAUI
[Sun Aug 30 03:07:21.361961 2026] [qos:error] [pid 499145:tid 499327] [client 205.209.65.102:34512] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=205.209.65.102, id=apPkuVJNq1G5uRhTNntpagAAADQ
[Sun Aug 30 03:07:21.367446 2026] [qos:error] [pid 502397:tid 502566] [client 27.66.27.114:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkuWuFRxhFZfnD0nIPPAAAATE
[Sun Aug 30 03:07:21.369600 2026] [security2:error] [pid 502397:tid 502573] [client 20.104.50.220:51571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/.error_log.php"] [unique_id "apPkuWuFRxhFZfnD0nIPPgAAATg"]
[Sun Aug 30 03:07:21.373282 2026] [qos:error] [pid 499145:tid 499329] [client 152.32.168.221:33190] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=152.32.168.221, id=apPkuVJNq1G5uRhTNntpbQAAADY
[Sun Aug 30 03:07:21.376382 2026] [qos:error] [pid 499145:tid 499278] [client 180.195.99.168:37194] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=180.195.99.168, id=apPkuVJNq1G5uRhTNntpcQAAAAM
[Sun Aug 30 03:07:21.376917 2026] [qos:error] [pid 502397:tid 502546] [client 43.164.3.124:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkuWuFRxhFZfnD0nIPRgAAAR0
[Sun Aug 30 03:07:21.379380 2026] [qos:error] [pid 499145:tid 499291] [client 85.8.47.208:36414] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=85.8.47.208, id=apPkuVJNq1G5uRhTNntpdAAAABA
[Sun Aug 30 03:07:21.380458 2026] [qos:error] [pid 502397:tid 502604] [client 190.97.35.249:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkuWuFRxhFZfnD0nIPLAAAAVY
[Sun Aug 30 03:07:21.380636 2026] [qos:error] [pid 502397:tid 502631] [client 43.162.115.229:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkuWuFRxhFZfnD0nIPLQAAAXE
[Sun Aug 30 03:07:21.380664 2026] [qos:error] [pid 502397:tid 502531] [client 45.127.58.70:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.44, id=apPkuWuFRxhFZfnD0nIPMAAAAQ4
[Sun Aug 30 03:07:21.380804 2026] [qos:error] [pid 502397:tid 502613] [client 118.173.230.98:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkuWuFRxhFZfnD0nIPMwAAAV8
[Sun Aug 30 03:07:21.381060 2026] [qos:error] [pid 502397:tid 502408] [remote 162.120.184.27:43524] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=162.120.184.27, id=apPkuWuFRxhFZfnD0nIPPQABago, referer: https://www.google.com/
[Sun Aug 30 03:07:21.382212 2026] [qos:error] [pid 499145:tid 499324] [client 203.76.112.107:54080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=203.76.112.107, id=apPkuVJNq1G5uRhTNntpdQAAADE
[Sun Aug 30 03:07:21.382940 2026] [qos:error] [pid 499145:tid 499323] [client 83.244.77.101:43506] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=83.244.77.101, id=apPkuVJNq1G5uRhTNntpeQAAADA
[Sun Aug 30 03:07:21.383099 2026] [qos:error] [pid 502397:tid 502582] [client 139.84.133.240:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkuWuFRxhFZfnD0nIPTgAAAUE
[Sun Aug 30 03:07:21.383148 2026] [qos:error] [pid 499145:tid 499402] [client 45.127.58.70:43682] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=45.127.58.70, id=apPkuVJNq1G5uRhTNntpeAAAAH8
[Sun Aug 30 03:07:21.383212 2026] [qos:error] [pid 499145:tid 499360] [client 179.63.6.240:46096] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=179.63.6.240, id=apPkuVJNq1G5uRhTNntpegAAAFU
[Sun Aug 30 03:07:21.383421 2026] [qos:error] [pid 502397:tid 502628] [client 112.198.23.254:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkuWuFRxhFZfnD0nIPTQAAAW4
[Sun Aug 30 03:07:21.386743 2026] [qos:error] [pid 499145:tid 499365] [client 82.110.112.36:44950] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=82.110.112.36, id=apPkuVJNq1G5uRhTNntpfQAAAFo
[Sun Aug 30 03:07:21.386749 2026] [qos:error] [pid 502397:tid 502645] [client 42.96.18.62:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=50.6.92.44, id=apPkuWuFRxhFZfnD0nIPQwAAAX8
[Sun Aug 30 03:07:21.386753 2026] [qos:error] [pid 499145:tid 499379] [client 103.153.62.28:45854] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=103.153.62.28, id=apPkuVJNq1G5uRhTNntpfwAAAGg
[Sun Aug 30 03:07:21.386767 2026] [qos:error] [pid 499145:tid 499281] [client 35.78.66.144:49010] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=35.78.66.144, id=apPkuVJNq1G5uRhTNntpfgAAAAY
[Sun Aug 30 03:07:21.387898 2026] [qos:error] [pid 502397:tid 502578] [client 23.129.64.160:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPkuWuFRxhFZfnD0nIPUAAAAT0
[Sun Aug 30 03:07:21.390517 2026] [qos:error] [pid 499145:tid 499350] [client 23.129.64.160:10847] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=23.129.64.160, id=apPkuVJNq1G5uRhTNntpgQAAAEs
[Sun Aug 30 03:07:21.392610 2026] [qos:error] [pid 499145:tid 499282] [client 190.112.160.23:56862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=190.112.160.23, id=apPkuVJNq1G5uRhTNntpgwAAAAc
[Sun Aug 30 03:07:21.392732 2026] [qos:error] [pid 499145:tid 499362] [client 45.127.58.70:43054] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.127.58.70, id=apPkuVJNq1G5uRhTNntpggAAAFc
[Sun Aug 30 03:07:21.397272 2026] [qos:error] [pid 499145:tid 499328] [client 103.80.83.27:56974] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.80.83.27, id=apPkuVJNq1G5uRhTNntphQAAADU
[Sun Aug 30 03:07:21.423478 2026] [security2:error] [pid 502397:tid 502527] [client 20.48.160.90:37694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/jw.php"] [unique_id "apPkuWuFRxhFZfnD0nIPiQAAAQo"]
[Sun Aug 30 03:07:21.523795 2026] [authz_core:error] [pid 502397:tid 502648] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:21.524363 2026] [authz_core:error] [pid 502397:tid 502648] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:21.558985 2026] [security2:error] [pid 502397:tid 502628] [client 20.48.160.90:30801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/or.php"] [unique_id "apPkuWuFRxhFZfnD0nIQRgAAAW4"]
[Sun Aug 30 03:07:21.561050 2026] [security2:error] [pid 502397:tid 502566] [client 20.151.200.44:27595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/wp-ver.php"] [unique_id "apPkuWuFRxhFZfnD0nIQRwAAATE"]
[Sun Aug 30 03:07:21.588220 2026] [authz_core:error] [pid 502397:tid 502637] [client 216.73.216.128:46176] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:21.588674 2026] [authz_core:error] [pid 502397:tid 502637] [client 216.73.216.128:46176] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:21.618411 2026] [security2:error] [pid 499145:tid 499320] [client 4.205.62.107:58359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/cu.php"] [unique_id "apPkuVJNq1G5uRhTNntp3AAAAC0"]
[Sun Aug 30 03:07:21.651605 2026] [security2:error] [pid 502397:tid 502546] [client 20.196.209.81:19928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/auth.php"] [unique_id "apPkuWuFRxhFZfnD0nIQaAAAAR0"]
[Sun Aug 30 03:07:21.677232 2026] [authz_core:error] [pid 499145:tid 499345] [client 216.73.216.128:45648] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:21.677509 2026] [authz_core:error] [pid 499145:tid 499345] [client 216.73.216.128:45648] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:21.689712 2026] [autoindex:error] [pid 502397:tid 502552] [client 20.196.209.81:5672] AH01276: Cannot serve directory /home4/devstol/public_html/thelakewoodshuttle/wp-content/themes/twentytwentytwo/parts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:07:21.708934 2026] [security2:error] [pid 502397:tid 502604] [client 20.48.160.90:61551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/ile56.php"] [unique_id "apPkuWuFRxhFZfnD0nIQeQAAAVY"]
[Sun Aug 30 03:07:21.716924 2026] [authz_core:error] [pid 502397:tid 502594] [client 66.249.66.35:42733] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:21.717487 2026] [authz_core:error] [pid 502397:tid 502594] [client 66.249.66.35:42733] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:21.748737 2026] [security2:error] [pid 502397:tid 502643] [client 20.151.200.44:27606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/ah24.php"] [unique_id "apPkuWuFRxhFZfnD0nIQqwAAAX0"]
[Sun Aug 30 03:07:21.755056 2026] [security2:error] [pid 502397:tid 502652] [client 114.119.129.235:47291] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.shiateachings.com"] [uri "/public/ilm/articler/100/21"] [unique_id "apPkuWuFRxhFZfnD0nIQrgAAAYY"], referer: http://www.shiateachings.com/public/ilm/view/21/1
[Sun Aug 30 03:07:21.767837 2026] [authz_core:error] [pid 502397:tid 502588] [client 216.73.216.128:45328] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:21.768196 2026] [authz_core:error] [pid 502397:tid 502588] [client 216.73.216.128:45328] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:21.772600 2026] [security2:error] [pid 502397:tid 502535] [client 114.119.133.182:53737] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "smashedice.com"] [uri "/index.php"] [unique_id "apPkuWuFRxhFZfnD0nIQtQAAARI"], referer: http://smashedice.com/index.php?m=vod-search-pg-48-wd-Carib.html
[Sun Aug 30 03:07:21.781532 2026] [authz_core:error] [pid 502397:tid 502573] [client 66.249.66.70:62247] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:21.781799 2026] [authz_core:error] [pid 502397:tid 502573] [client 66.249.66.70:62247] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:21.810274 2026] [authz_core:error] [pid 502397:tid 502532] [client 216.73.216.128:11425] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:21.810576 2026] [authz_core:error] [pid 502397:tid 502532] [client 216.73.216.128:11425] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:21.822688 2026] [security2:error] [pid 502397:tid 502539] [client 20.196.209.81:5672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/users.php"] [unique_id "apPkuWuFRxhFZfnD0nIQ1AAAARY"]
[Sun Aug 30 03:07:21.853433 2026] [security2:error] [pid 499145:tid 499386] [client 20.48.160.90:61535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/emmh.php"] [unique_id "apPkuVJNq1G5uRhTNntqJwAAAG8"]
[Sun Aug 30 03:07:21.868671 2026] [security2:error] [pid 502397:tid 502570] [client 40.83.93.50:18512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/aaa.php"] [unique_id "apPkuWuFRxhFZfnD0nIQ7wAAATU"]
[Sun Aug 30 03:07:21.893119 2026] [security2:error] [pid 499145:tid 499308] [client 20.151.200.44:27280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPkuVJNq1G5uRhTNntqNgAAACE"]
[Sun Aug 30 03:07:21.963826 2026] [authz_core:error] [pid 502397:tid 502579] [client 66.249.66.71:50452] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:21.964359 2026] [authz_core:error] [pid 502397:tid 502579] [client 66.249.66.71:50452] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:21.980775 2026] [authz_core:error] [pid 502397:tid 502637] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:21.981055 2026] [authz_core:error] [pid 502397:tid 502637] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:21.995010 2026] [security2:error] [pid 502397:tid 502622] [client 20.48.160.90:61512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/em.php"] [unique_id "apPkuWuFRxhFZfnD0nIRHgAAAWg"]
[Sun Aug 30 03:07:21.998328 2026] [security2:error] [pid 502397:tid 502585] [client 20.104.49.130:52484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/1xmomo.php"] [unique_id "apPkuWuFRxhFZfnD0nIRHwAAAUQ"]
[Sun Aug 30 03:07:22.016555 2026] [authz_core:error] [pid 502397:tid 502548] [client 216.73.216.128:45328] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:22.017095 2026] [authz_core:error] [pid 502397:tid 502548] [client 216.73.216.128:45328] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:22.047765 2026] [authz_core:error] [pid 499145:tid 499291] [client 66.249.66.199:58414] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:22.048029 2026] [authz_core:error] [pid 499145:tid 499291] [client 66.249.66.199:58414] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:22.075290 2026] [authz_core:error] [pid 502397:tid 502561] [client 66.249.66.64:60973] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:22.075731 2026] [authz_core:error] [pid 502397:tid 502561] [client 66.249.66.64:60973] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:22.097789 2026] [security2:error] [pid 502397:tid 502626] [client 20.196.209.81:19927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/adminfuns.php"] [unique_id "apPkumuFRxhFZfnD0nIRYAAAAWw"]
[Sun Aug 30 03:07:22.114231 2026] [security2:error] [pid 502397:tid 502612] [client 20.63.81.20:4204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkumuFRxhFZfnD0nIRZAAAAV4"]
[Sun Aug 30 03:07:22.145895 2026] [proxy_http:error] [pid 502397:tid 502583] (20014)Internal error (specific information not available): [client 34.125.55.247:1622] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:22.145916 2026] [proxy:error] [pid 502397:tid 502583] [client 34.125.55.247:1622] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.kube/config
[Sun Aug 30 03:07:22.151116 2026] [authz_core:error] [pid 499145:tid 499324] [client 66.249.66.66:43930] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:22.151453 2026] [authz_core:error] [pid 499145:tid 499324] [client 66.249.66.66:43930] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:22.153686 2026] [proxy_http:error] [pid 502397:tid 502556] (20014)Internal error (specific information not available): [client 34.125.55.247:1612] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:22.153700 2026] [proxy:error] [pid 502397:tid 502556] [client 34.125.55.247:1612] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.docker/config.json
[Sun Aug 30 03:07:22.160328 2026] [proxy_http:error] [pid 502397:tid 502546] (20014)Internal error (specific information not available): [client 34.125.55.247:1678] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:22.160362 2026] [proxy:error] [pid 502397:tid 502546] [client 34.125.55.247:1678] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/app-config.json
[Sun Aug 30 03:07:22.160678 2026] [security2:error] [pid 502397:tid 502529] [client 34.125.55.247:1864] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.engaginggoddaily.com"] [uri "/.ssh/id_dsa"] [unique_id "apPkumuFRxhFZfnD0nIRmwAAAQw"]
[Sun Aug 30 03:07:22.161049 2026] [security2:error] [pid 502397:tid 502648] [client 34.125.55.247:1830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/.ssh/id_rsa"] [unique_id "apPkumuFRxhFZfnD0nIRmAAAAYI"]
[Sun Aug 30 03:07:22.168422 2026] [security2:error] [pid 502397:tid 502638] [client 34.125.55.247:1658] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/config.js"] [unique_id "apPkumuFRxhFZfnD0nIRdwAAAXg"]
[Sun Aug 30 03:07:22.168595 2026] [proxy_http:error] [pid 502397:tid 502538] (20014)Internal error (specific information not available): [client 34.125.55.247:1638] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:22.168605 2026] [proxy:error] [pid 502397:tid 502538] [client 34.125.55.247:1638] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/secrets.json
[Sun Aug 30 03:07:22.175522 2026] [proxy_http:error] [pid 502397:tid 502554] (20014)Internal error (specific information not available): [client 34.125.55.247:1674] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:22.175555 2026] [proxy:error] [pid 502397:tid 502554] [client 34.125.55.247:1674] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/settings.json
[Sun Aug 30 03:07:22.181479 2026] [proxy_http:error] [pid 502397:tid 502583] (20014)Internal error (specific information not available): [client 34.125.55.247:1622] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:22.181498 2026] [proxy:error] [pid 502397:tid 502583] [client 34.125.55.247:1622] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml
[Sun Aug 30 03:07:22.188102 2026] [proxy_http:error] [pid 502397:tid 502642] (20014)Internal error (specific information not available): [client 34.125.55.247:1684] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:22.188118 2026] [proxy:error] [pid 502397:tid 502642] [client 34.125.55.247:1684] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/runtime-config.js
[Sun Aug 30 03:07:22.194624 2026] [proxy_http:error] [pid 502397:tid 502630] (20014)Internal error (specific information not available): [client 34.125.55.247:1686] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:22.194641 2026] [proxy:error] [pid 502397:tid 502630] [client 34.125.55.247:1686] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/api/config
[Sun Aug 30 03:07:22.200822 2026] [security2:error] [pid 502397:tid 502637] [client 20.48.160.90:38002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/dvve.php"] [unique_id "apPkumuFRxhFZfnD0nIRwQAAAXc"]
[Sun Aug 30 03:07:22.201820 2026] [proxy_http:error] [pid 502397:tid 502575] (20014)Internal error (specific information not available): [client 34.125.55.247:1772] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:22.201838 2026] [proxy:error] [pid 502397:tid 502575] [client 34.125.55.247:1772] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/firebase-credentials.json
[Sun Aug 30 03:07:22.208522 2026] [proxy_http:error] [pid 502397:tid 502633] (20014)Internal error (specific information not available): [client 34.125.55.247:1740] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:22.208537 2026] [proxy:error] [pid 502397:tid 502633] [client 34.125.55.247:1740] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/api/v1/env
[Sun Aug 30 03:07:22.212008 2026] [lsapi:error] [pid 502397:tid 502542] [client 98.224.93.242:24375] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://gracelikestogarden.com/
[Sun Aug 30 03:07:22.212187 2026] [lsapi:error] [pid 502397:tid 502542] [client 98.224.93.242:24375] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://gracelikestogarden.com/
[Sun Aug 30 03:07:22.213544 2026] [lsapi:error] [pid 502397:tid 502542] [client 98.224.93.242:24375] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n, referer: https://gracelikestogarden.com/
[Sun Aug 30 03:07:22.215735 2026] [proxy_http:error] [pid 502397:tid 502556] (20014)Internal error (specific information not available): [client 34.125.55.247:1612] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:22.215751 2026] [proxy:error] [pid 502397:tid 502556] [client 34.125.55.247:1612] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml
[Sun Aug 30 03:07:22.222258 2026] [proxy_http:error] [pid 502397:tid 502533] (20014)Internal error (specific information not available): [client 34.125.55.247:1786] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:22.222273 2026] [proxy:error] [pid 502397:tid 502533] [client 34.125.55.247:1786] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/google-credentials.json
[Sun Aug 30 03:07:22.229507 2026] [proxy_http:error] [pid 502397:tid 502647] (20014)Internal error (specific information not available): [client 34.125.55.247:1792] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:22.229517 2026] [proxy:error] [pid 502397:tid 502647] [client 34.125.55.247:1792] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/key.json
[Sun Aug 30 03:07:22.236141 2026] [proxy_http:error] [pid 502397:tid 502634] (20014)Internal error (specific information not available): [client 34.125.55.247:1806] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:22.236160 2026] [proxy:error] [pid 502397:tid 502634] [client 34.125.55.247:1806] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/gcp-key.json
[Sun Aug 30 03:07:22.243455 2026] [proxy_http:error] [pid 502397:tid 502546] (20014)Internal error (specific information not available): [client 34.125.55.247:1678] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:22.243473 2026] [proxy:error] [pid 502397:tid 502546] [client 34.125.55.247:1678] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml
[Sun Aug 30 03:07:22.245250 2026] [security2:error] [pid 499145:tid 499360] [client 20.196.209.81:5649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/wp-cron.php"] [unique_id "apPkulJNq1G5uRhTNntqwQAAAFU"]
[Sun Aug 30 03:07:22.250143 2026] [proxy_http:error] [pid 502397:tid 502541] (20014)Internal error (specific information not available): [client 34.125.55.247:1814] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:22.250162 2026] [proxy:error] [pid 502397:tid 502541] [client 34.125.55.247:1814] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.ssh/id_ed25519
[Sun Aug 30 03:07:22.250191 2026] [security2:error] [pid 502397:tid 502648] [client 20.63.81.20:4178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkumuFRxhFZfnD0nIR4AAAAYI"]
[Sun Aug 30 03:07:22.253809 2026] [security2:error] [pid 502397:tid 502614] [client 20.104.18.15:43269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/robot.php"] [unique_id "apPkumuFRxhFZfnD0nIR4wAAAWA"]
[Sun Aug 30 03:07:22.255713 2026] [security2:error] [pid 502397:tid 502621] [client 20.104.50.220:17314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/201.php"] [unique_id "apPkumuFRxhFZfnD0nIR5AAAAWc"]
[Sun Aug 30 03:07:22.256308 2026] [security2:error] [pid 502397:tid 502581] [client 4.205.62.107:64050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/app_local.php"] [unique_id "apPkumuFRxhFZfnD0nIR5QAAAUA"]
[Sun Aug 30 03:07:22.256398 2026] [security2:error] [pid 502397:tid 502570] [client 4.205.62.107:52148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/aws_keys.php"] [unique_id "apPkumuFRxhFZfnD0nIR5gAAATU"]
[Sun Aug 30 03:07:22.257536 2026] [security2:error] [pid 502397:tid 502547] [client 20.104.18.15:29154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/btyuio.php"] [unique_id "apPkumuFRxhFZfnD0nIR6AAAAR4"]
[Sun Aug 30 03:07:22.257697 2026] [security2:error] [pid 502397:tid 502544] [client 20.104.50.220:6107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/alfav4.1-tesla.php"] [unique_id "apPkumuFRxhFZfnD0nIR5wAAARs"]
[Sun Aug 30 03:07:22.258326 2026] [proxy_http:error] [pid 502397:tid 502538] (20014)Internal error (specific information not available): [client 34.125.55.247:1638] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:22.258336 2026] [proxy:error] [pid 502397:tid 502538] [client 34.125.55.247:1638] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml
[Sun Aug 30 03:07:22.258447 2026] [security2:error] [pid 502397:tid 502538] [client 34.125.55.247:1638] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "502"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/502.shtml"] [unique_id "apPkumuFRxhFZfnD0nIRegAAARU"]
[Sun Aug 30 03:07:22.259033 2026] [security2:error] [pid 502397:tid 502582] [client 4.205.62.107:36612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/aws_config.php"] [unique_id "apPkumuFRxhFZfnD0nIR6QAAAUE"]
[Sun Aug 30 03:07:22.260617 2026] [security2:error] [pid 499145:tid 499358] [client 20.151.200.44:27164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xn--42cfak0ga0aa1bva5e2ccredeh60a0bze2a.com"] [uri "/waf.php"] [unique_id "apPkulJNq1G5uRhTNntqxwAAAFM"]
[Sun Aug 30 03:07:22.262338 2026] [security2:error] [pid 502397:tid 502638] [client 20.48.251.3:33290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/ms-edit.php"] [unique_id "apPkumuFRxhFZfnD0nIR7QAAAXg"]
[Sun Aug 30 03:07:22.262941 2026] [security2:error] [pid 499145:tid 499386] [client 20.104.50.220:27112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/Smarty.php"] [unique_id "apPkulJNq1G5uRhTNntqyQAAAG8"]
[Sun Aug 30 03:07:22.264051 2026] [security2:error] [pid 499145:tid 499297] [client 20.104.50.220:33214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/hcd01.php"] [unique_id "apPkulJNq1G5uRhTNntqywAAABY"]
[Sun Aug 30 03:07:22.264365 2026] [security2:error] [pid 502397:tid 502534] [client 20.104.18.15:23508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/radio.php"] [unique_id "apPkumuFRxhFZfnD0nIR7wAAARE"]
[Sun Aug 30 03:07:22.265741 2026] [security2:error] [pid 499145:tid 499397] [client 20.104.18.15:13729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/wefile.php"] [unique_id "apPkulJNq1G5uRhTNntqzgAAAHo"]
[Sun Aug 30 03:07:22.266159 2026] [security2:error] [pid 502397:tid 502650] [client 20.48.251.3:44407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/u88.php"] [unique_id "apPkumuFRxhFZfnD0nIR8AAAAYQ"]
[Sun Aug 30 03:07:22.266352 2026] [security2:error] [pid 502397:tid 502604] [client 20.104.18.15:34761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/samll.php"] [unique_id "apPkumuFRxhFZfnD0nIR8QAAAVY"]
[Sun Aug 30 03:07:22.267573 2026] [security2:error] [pid 502397:tid 502620] [client 68.155.159.216:54227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-content/banners/about.php"] [unique_id "apPkumuFRxhFZfnD0nIR8wAAAWY"]
[Sun Aug 30 03:07:22.267847 2026] [security2:error] [pid 502397:tid 502612] [client 4.205.62.107:65355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/old_phpinfo.php"] [unique_id "apPkumuFRxhFZfnD0nIR9QAAAV4"]
[Sun Aug 30 03:07:22.269230 2026] [security2:error] [pid 502397:tid 502590] [client 20.104.50.220:61428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/images/fox.php"] [unique_id "apPkumuFRxhFZfnD0nIR-QAAAUg"]
[Sun Aug 30 03:07:22.270624 2026] [security2:error] [pid 502397:tid 502555] [client 20.48.251.3:12046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/hosty.php"] [unique_id "apPkumuFRxhFZfnD0nIR-gAAASY"]
[Sun Aug 30 03:07:22.274893 2026] [security2:error] [pid 502397:tid 502559] [client 4.205.62.107:64688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/radio.php"] [unique_id "apPkumuFRxhFZfnD0nIR_wAAASo"]
[Sun Aug 30 03:07:22.278431 2026] [security2:error] [pid 502397:tid 502583] [client 20.104.18.15:51655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/key.php"] [unique_id "apPkumuFRxhFZfnD0nISBAAAAUI"]
[Sun Aug 30 03:07:22.279680 2026] [security2:error] [pid 502397:tid 502632] [client 20.104.18.15:28631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/gm.php"] [unique_id "apPkumuFRxhFZfnD0nISBwAAAXI"]
[Sun Aug 30 03:07:22.283113 2026] [security2:error] [pid 502397:tid 502541] [client 34.125.55.247:1814] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "502"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/502.shtml"] [unique_id "apPkumuFRxhFZfnD0nIRmgAAARg"]
[Sun Aug 30 03:07:22.286082 2026] [security2:error] [pid 502397:tid 502593] [client 20.104.50.220:31845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/teslav.php"] [unique_id "apPkumuFRxhFZfnD0nISDAAAAUs"]
[Sun Aug 30 03:07:22.289611 2026] [security2:error] [pid 502397:tid 502578] [client 4.205.62.107:62428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/session.php"] [unique_id "apPkumuFRxhFZfnD0nISDwAAAT0"]
[Sun Aug 30 03:07:22.292160 2026] [security2:error] [pid 502397:tid 502626] [client 68.155.159.216:61319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apPkumuFRxhFZfnD0nISEwAAAWw"]
[Sun Aug 30 03:07:22.297763 2026] [security2:error] [pid 502397:tid 502635] [client 4.205.62.107:18763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/hochladen.form.php"] [unique_id "apPkumuFRxhFZfnD0nISFwAAAXU"]
[Sun Aug 30 03:07:22.302220 2026] [security2:error] [pid 502397:tid 502644] [client 68.155.159.216:62288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apPkumuFRxhFZfnD0nISHgAAAX4"]
[Sun Aug 30 03:07:22.309618 2026] [security2:error] [pid 502397:tid 502638] [client 68.155.159.216:11217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/mah.php"] [unique_id "apPkumuFRxhFZfnD0nISJQAAAXg"]
[Sun Aug 30 03:07:22.335271 2026] [security2:error] [pid 502397:tid 502541] [client 20.104.18.15:18418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/images.php"] [unique_id "apPkumuFRxhFZfnD0nISNQAAARg"]
[Sun Aug 30 03:07:22.335988 2026] [security2:error] [pid 502397:tid 502548] [client 20.48.251.3:7027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/sdsa.php"] [unique_id "apPkumuFRxhFZfnD0nISOQAAAR8"]
[Sun Aug 30 03:07:22.341375 2026] [security2:error] [pid 502397:tid 502570] [client 4.205.62.107:2960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/cli_bootstrap.php"] [unique_id "apPkumuFRxhFZfnD0nISPwAAATU"]
[Sun Aug 30 03:07:22.343972 2026] [security2:error] [pid 502397:tid 502621] [client 20.104.50.220:47074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp_wrong_datlib.php"] [unique_id "apPkumuFRxhFZfnD0nISQgAAAWc"]
[Sun Aug 30 03:07:22.346636 2026] [security2:error] [pid 502397:tid 502629] [client 20.48.250.41:64708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/cc13.php"] [unique_id "apPkumuFRxhFZfnD0nISRwAAAW8"]
[Sun Aug 30 03:07:22.351407 2026] [security2:error] [pid 502397:tid 502641] [client 20.48.160.90:61476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/doo.php"] [unique_id "apPkumuFRxhFZfnD0nISSQAAAXs"]
[Sun Aug 30 03:07:22.357885 2026] [security2:error] [pid 502397:tid 502615] [client 40.83.93.50:7991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/atomlib.php"] [unique_id "apPkumuFRxhFZfnD0nISUgAAAWE"]
[Sun Aug 30 03:07:22.384391 2026] [authz_core:error] [pid 499145:tid 499318] [client 216.73.216.128:45648] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:22.384847 2026] [authz_core:error] [pid 499145:tid 499318] [client 216.73.216.128:45648] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:22.389910 2026] [security2:error] [pid 502397:tid 502593] [client 20.63.81.20:4219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/ser.php"] [unique_id "apPkumuFRxhFZfnD0nISZAAAAUs"]
[Sun Aug 30 03:07:22.394637 2026] [authz_core:error] [pid 499145:tid 499300] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:22.395048 2026] [authz_core:error] [pid 499145:tid 499300] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:22.409145 2026] [security2:error] [pid 502397:tid 502646] [client 20.104.50.220:29621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/Marvins.php"] [unique_id "apPkumuFRxhFZfnD0nISewAAAYA"]
[Sun Aug 30 03:07:22.417622 2026] [security2:error] [pid 502397:tid 502604] [client 20.104.50.220:52860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/UnknownSec.php"] [unique_id "apPkumuFRxhFZfnD0nISgQAAAVY"]
[Sun Aug 30 03:07:22.436551 2026] [security2:error] [pid 502397:tid 502625] [client 20.48.250.41:45366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/166.php"] [unique_id "apPkumuFRxhFZfnD0nISiQAAAWs"]
[Sun Aug 30 03:07:22.445407 2026] [security2:error] [pid 502397:tid 502631] [client 157.245.205.168:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "readersusedbooks.com"] [uri "/"] [unique_id "apPkumuFRxhFZfnD0nISjAAAAXE"]
[Sun Aug 30 03:07:22.472369 2026] [security2:error] [pid 502397:tid 502557] [client 52.167.144.161:58220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "concordservices-bali.com"] [uri "/Detail.php"] [unique_id "apPkumuFRxhFZfnD0nISnAAAASg"]
[Sun Aug 30 03:07:22.491934 2026] [security2:error] [pid 502397:tid 502587] [client 20.48.160.90:61509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/adminer-4.6.6.php"] [unique_id "apPkumuFRxhFZfnD0nISvwAAAUY"]
[Sun Aug 30 03:07:22.518627 2026] [security2:error] [pid 502397:tid 502611] [client 20.196.209.81:20906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/rip.php"] [unique_id "apPkumuFRxhFZfnD0nIS0AAAAV0"]
[Sun Aug 30 03:07:22.528009 2026] [authz_core:error] [pid 502397:tid 502569] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:22.528316 2026] [authz_core:error] [pid 502397:tid 502569] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:22.537086 2026] [security2:error] [pid 502397:tid 502627] [client 20.63.81.20:4228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/431.php"] [unique_id "apPkumuFRxhFZfnD0nIS3wAAAW0"]
[Sun Aug 30 03:07:22.546193 2026] [security2:error] [pid 502397:tid 502539] [client 20.104.49.130:60627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/btyuio.php"] [unique_id "apPkumuFRxhFZfnD0nIS6QAAARY"]
[Sun Aug 30 03:07:22.586720 2026] [security2:error] [pid 502397:tid 502619] [client 68.155.159.216:12300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/cgi-bin/index.php"] [unique_id "apPkumuFRxhFZfnD0nIS_QAAAWU"]
[Sun Aug 30 03:07:22.604389 2026] [authz_core:error] [pid 502397:tid 502639] [client 66.249.66.68:51580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:22.604852 2026] [authz_core:error] [pid 502397:tid 502639] [client 66.249.66.68:51580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:22.627736 2026] [security2:error] [pid 499145:tid 499379] [client 20.48.160.90:61508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/gelap1.php"] [unique_id "apPkulJNq1G5uRhTNntrVgAAAGg"]
[Sun Aug 30 03:07:22.639240 2026] [security2:error] [pid 502397:tid 502565] [client 20.196.209.81:13748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/wp-links-opml.php"] [unique_id "apPkumuFRxhFZfnD0nITDwAAATA"]
[Sun Aug 30 03:07:22.671115 2026] [security2:error] [pid 502397:tid 502617] [client 68.155.159.216:62056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/content.php"] [unique_id "apPkumuFRxhFZfnD0nITGQAAAWM"]
[Sun Aug 30 03:07:22.687123 2026] [authz_core:error] [pid 499145:tid 499278] [client 66.249.66.206:43199] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:22.687399 2026] [authz_core:error] [pid 499145:tid 499278] [client 66.249.66.206:43199] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:22.700399 2026] [security2:error] [pid 502397:tid 502615] [client 20.63.81.20:4127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/rxr.php"] [unique_id "apPkumuFRxhFZfnD0nITJwAAAWE"]
[Sun Aug 30 03:07:22.739020 2026] [authz_core:error] [pid 499145:tid 499290] [client 66.249.66.73:43829] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:22.739306 2026] [authz_core:error] [pid 499145:tid 499290] [client 66.249.66.73:43829] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:22.765815 2026] [security2:error] [pid 502397:tid 502629] [client 20.48.160.90:61456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/rsjlrria.php"] [unique_id "apPkumuFRxhFZfnD0nITWgAAAW8"]
[Sun Aug 30 03:07:22.845097 2026] [security2:error] [pid 502397:tid 502651] [client 20.104.49.130:64097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/av.php"] [unique_id "apPkumuFRxhFZfnD0nITjwAAAYU"]
[Sun Aug 30 03:07:22.847585 2026] [authz_core:error] [pid 502397:tid 502645] [client 216.73.216.128:46176] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:22.847889 2026] [authz_core:error] [pid 502397:tid 502645] [client 216.73.216.128:46176] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:22.849249 2026] [security2:error] [pid 502397:tid 502593] [client 40.83.93.50:7986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/buy.php"] [unique_id "apPkumuFRxhFZfnD0nITkQAAAUs"]
[Sun Aug 30 03:07:22.867514 2026] [security2:error] [pid 502397:tid 502588] [client 20.63.81.20:4214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/csst.php"] [unique_id "apPkumuFRxhFZfnD0nITmQAAAUc"]
[Sun Aug 30 03:07:22.895487 2026] [security2:error] [pid 499145:tid 499361] [client 20.48.160.90:37707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/AxAo.php"] [unique_id "apPkulJNq1G5uRhTNntruAAAAFY"]
[Sun Aug 30 03:07:22.900252 2026] [security2:error] [pid 502397:tid 502580] [client 20.104.50.220:51552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/666.php"] [unique_id "apPkumuFRxhFZfnD0nITpQAAAT8"]
[Sun Aug 30 03:07:22.910264 2026] [security2:error] [pid 502397:tid 502646] [client 20.196.209.81:20878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/ws.php"] [unique_id "apPkumuFRxhFZfnD0nITqwAAAYA"]
[Sun Aug 30 03:07:22.937040 2026] [authz_core:error] [pid 502397:tid 502638] [client 66.249.66.70:55103] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:22.937496 2026] [authz_core:error] [pid 502397:tid 502638] [client 66.249.66.70:55103] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:22.960116 2026] [security2:error] [pid 502397:tid 502559] [client 20.104.49.130:60610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/k.php"] [unique_id "apPkumuFRxhFZfnD0nITxQAAASo"]
[Sun Aug 30 03:07:22.965972 2026] [authz_core:error] [pid 502397:tid 502637] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:22.966266 2026] [authz_core:error] [pid 502397:tid 502637] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:22.996444 2026] [security2:error] [pid 502397:tid 502648] [client 20.63.81.20:4192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp-includes/blocks/query-title/footer.php"] [unique_id "apPkumuFRxhFZfnD0nIT4wAAAYI"]
[Sun Aug 30 03:07:23.026858 2026] [authz_core:error] [pid 499145:tid 499354] [client 216.73.216.128:45648] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:23.027232 2026] [authz_core:error] [pid 499145:tid 499354] [client 216.73.216.128:45648] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:23.031125 2026] [security2:error] [pid 502397:tid 502605] [client 20.196.209.81:5660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/wp-load.php"] [unique_id "apPku2uFRxhFZfnD0nIT-wAAAVc"]
[Sun Aug 30 03:07:23.038395 2026] [security2:error] [pid 502397:tid 502628] [client 20.48.160.90:30807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/class17.php"] [unique_id "apPku2uFRxhFZfnD0nIT_gAAAW4"]
[Sun Aug 30 03:07:23.120969 2026] [authz_core:error] [pid 502397:tid 502560] [client 216.73.216.128:45328] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:23.121265 2026] [authz_core:error] [pid 502397:tid 502560] [client 216.73.216.128:45328] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:23.140974 2026] [security2:error] [pid 502397:tid 502621] [client 20.63.81.20:4250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp-content/uploads/indoex.php"] [unique_id "apPku2uFRxhFZfnD0nIUOgAAAWc"]
[Sun Aug 30 03:07:23.196485 2026] [security2:error] [pid 502397:tid 502552] [client 20.48.160.90:37656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/okxoby.php"] [unique_id "apPku2uFRxhFZfnD0nIUZQAAASM"]
[Sun Aug 30 03:07:23.237669 2026] [security2:error] [pid 502397:tid 502651] [client 20.151.200.44:55717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/wp-access.php"] [unique_id "apPku2uFRxhFZfnD0nIUfAAAAYU"]
[Sun Aug 30 03:07:23.264301 2026] [security2:error] [pid 502397:tid 502633] [client 20.104.49.130:53573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/media.php"] [unique_id "apPku2uFRxhFZfnD0nIUkgAAAXM"]
[Sun Aug 30 03:07:23.270601 2026] [security2:error] [pid 499145:tid 499316] [client 20.63.81.20:4241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPku1JNq1G5uRhTNntsQwAAACk"]
[Sun Aug 30 03:07:23.335392 2026] [security2:error] [pid 502397:tid 502533] [client 20.48.160.90:37956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/esuutzzx.php"] [unique_id "apPku2uFRxhFZfnD0nIUwQAAARA"]
[Sun Aug 30 03:07:23.343468 2026] [security2:error] [pid 502397:tid 502549] [client 20.196.209.81:19912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/t.php"] [unique_id "apPku2uFRxhFZfnD0nIUygAAASA"]
[Sun Aug 30 03:07:23.368867 2026] [security2:error] [pid 502397:tid 502604] [client 68.155.159.216:54226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apPku2uFRxhFZfnD0nIU1AAAAVY"]
[Sun Aug 30 03:07:23.371092 2026] [security2:error] [pid 502397:tid 502584] [client 40.83.93.50:18521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/hello.php"] [unique_id "apPku2uFRxhFZfnD0nIU1gAAAUM"]
[Sun Aug 30 03:07:23.386829 2026] [security2:error] [pid 502397:tid 502577] [client 20.104.50.220:16741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/ops.php"] [unique_id "apPku2uFRxhFZfnD0nIU4AAAATw"]
[Sun Aug 30 03:07:23.389575 2026] [security2:error] [pid 502397:tid 502563] [client 20.104.50.220:27554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/Redis.php"] [unique_id "apPku2uFRxhFZfnD0nIU5QAAAS4"]
[Sun Aug 30 03:07:23.390583 2026] [security2:error] [pid 502397:tid 502581] [client 4.205.62.107:63987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/ws62.php"] [unique_id "apPku2uFRxhFZfnD0nIU7AAAAUA"]
[Sun Aug 30 03:07:23.390690 2026] [security2:error] [pid 502397:tid 502546] [client 4.205.62.107:56939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/umgebung.php"] [unique_id "apPku2uFRxhFZfnD0nIU7QAAAR0"]
[Sun Aug 30 03:07:23.395727 2026] [security2:error] [pid 502397:tid 502629] [client 20.104.18.15:29177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/dehnl.php"] [unique_id "apPku2uFRxhFZfnD0nIU8QAAAW8"]
[Sun Aug 30 03:07:23.397592 2026] [security2:error] [pid 502397:tid 502639] [client 20.104.50.220:5949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/-.php"] [unique_id "apPku2uFRxhFZfnD0nIU-gAAAXk"]
[Sun Aug 30 03:07:23.399411 2026] [security2:error] [pid 502397:tid 502608] [client 20.48.251.3:56377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/lmfi2.php"] [unique_id "apPku2uFRxhFZfnD0nIU_AAAAVo"]
[Sun Aug 30 03:07:23.400457 2026] [security2:error] [pid 502397:tid 502550] [client 20.104.18.15:23505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/one.php"] [unique_id "apPku2uFRxhFZfnD0nIU_wAAASE"]
[Sun Aug 30 03:07:23.401401 2026] [security2:error] [pid 502397:tid 502549] [client 20.63.81.20:4215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/haxor.php"] [unique_id "apPku2uFRxhFZfnD0nIVAQAAASA"]
[Sun Aug 30 03:07:23.401641 2026] [security2:error] [pid 502397:tid 502552] [client 20.104.18.15:13645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/blog.php"] [unique_id "apPku2uFRxhFZfnD0nIVAwAAASM"]
[Sun Aug 30 03:07:23.406895 2026] [security2:error] [pid 502397:tid 502566] [client 4.205.62.107:58063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.orthochristiantools.com"] [uri "/wp-act.php"] [unique_id "apPku2uFRxhFZfnD0nIVCAAAATE"]
[Sun Aug 30 03:07:23.407278 2026] [security2:error] [pid 502397:tid 502616] [client 68.155.159.216:65446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-admin/index.php"] [unique_id "apPku2uFRxhFZfnD0nIVCQAAAWI"]
[Sun Aug 30 03:07:23.408515 2026] [security2:error] [pid 502397:tid 502621] [client 68.155.159.216:11146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-blog-header.php"] [unique_id "apPku2uFRxhFZfnD0nIVCgAAAWc"]
[Sun Aug 30 03:07:23.409264 2026] [security2:error] [pid 502397:tid 502631] [client 20.104.18.15:34770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/she11.php"] [unique_id "apPku2uFRxhFZfnD0nIVCwAAAXE"]
[Sun Aug 30 03:07:23.411290 2026] [security2:error] [pid 502397:tid 502604] [client 4.205.62.107:61808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/xa.php"] [unique_id "apPku2uFRxhFZfnD0nIVEQAAAVY"]
[Sun Aug 30 03:07:23.415419 2026] [security2:error] [pid 499145:tid 499352] [client 20.104.18.15:43919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/revo.php"] [unique_id "apPku1JNq1G5uRhTNntsiAAAAE0"]
[Sun Aug 30 03:07:23.416565 2026] [authz_core:error] [pid 502397:tid 502606] [client 66.249.66.34:57230] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:23.416841 2026] [authz_core:error] [pid 502397:tid 502606] [client 66.249.66.34:57230] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:23.419106 2026] [security2:error] [pid 502397:tid 502634] [client 4.205.62.107:35993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/dialog.php"] [unique_id "apPku2uFRxhFZfnD0nIVFgAAAXQ"]
[Sun Aug 30 03:07:23.419153 2026] [security2:error] [pid 502397:tid 502648] [client 20.104.18.15:28670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/ws55.php"] [unique_id "apPku2uFRxhFZfnD0nIVFwAAAYI"]
[Sun Aug 30 03:07:23.426567 2026] [security2:error] [pid 502397:tid 502570] [client 20.196.209.81:5698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/wp-settings.php"] [unique_id "apPku2uFRxhFZfnD0nIVHgAAATU"]
[Sun Aug 30 03:07:23.426680 2026] [security2:error] [pid 499145:tid 499328] [client 20.104.18.15:51603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/chosen.php"] [unique_id "apPku1JNq1G5uRhTNntsjwAAADU"]
[Sun Aug 30 03:07:23.427393 2026] [security2:error] [pid 502397:tid 502614] [client 20.104.50.220:61640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/images/fw.php"] [unique_id "apPku2uFRxhFZfnD0nIVHwAAAWA"]
[Sun Aug 30 03:07:23.427913 2026] [security2:error] [pid 502397:tid 502530] [client 20.48.251.3:50035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/pass4.php"] [unique_id "apPku2uFRxhFZfnD0nIVIAAAAQ0"]
[Sun Aug 30 03:07:23.431746 2026] [security2:error] [pid 499145:tid 499376] [client 20.104.50.220:33302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/prof.php"] [unique_id "apPku1JNq1G5uRhTNntskQAAAGU"]
[Sun Aug 30 03:07:23.439555 2026] [authz_core:error] [pid 499145:tid 499353] [client 66.249.66.66:43930] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:23.439915 2026] [authz_core:error] [pid 499145:tid 499353] [client 66.249.66.66:43930] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:23.440060 2026] [security2:error] [pid 502397:tid 502547] [client 114.119.149.3:46401] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "riverviewknights.org"] [uri "/events-calendar/action~oneday/exact_date~1698375600/request_format~json/tag_ids~7/"] [unique_id "apPku2uFRxhFZfnD0nIVKgAAAR4"], referer: https://riverviewknights.org/events-calendar/action~oneday/exact_date~27-10-2023
[Sun Aug 30 03:07:23.454489 2026] [security2:error] [pid 502397:tid 502650] [client 4.205.62.107:32487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/services.php"] [unique_id "apPku2uFRxhFZfnD0nIVLAAAAYQ"]
[Sun Aug 30 03:07:23.454631 2026] [security2:error] [pid 499145:tid 499375] [client 4.205.62.107:54411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/h.php"] [unique_id "apPku1JNq1G5uRhTNntsnAAAAGQ"]
[Sun Aug 30 03:07:23.468003 2026] [security2:error] [pid 502397:tid 502641] [client 20.48.251.3:4703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/config/laravolt/css/index.php"] [unique_id "apPku2uFRxhFZfnD0nIVNgAAAXs"]
[Sun Aug 30 03:07:23.478005 2026] [security2:error] [pid 502397:tid 502588] [client 4.205.62.107:2981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/dd.php"] [unique_id "apPku2uFRxhFZfnD0nIVQgAAAUc"]
[Sun Aug 30 03:07:23.479145 2026] [security2:error] [pid 502397:tid 502633] [client 20.48.251.3:7013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/sale.php"] [unique_id "apPku2uFRxhFZfnD0nIVQwAAAXM"]
[Sun Aug 30 03:07:23.479241 2026] [security2:error] [pid 502397:tid 502566] [client 20.104.18.15:18343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/ops.php"] [unique_id "apPku2uFRxhFZfnD0nIVRAAAATE"]
[Sun Aug 30 03:07:23.480229 2026] [security2:error] [pid 502397:tid 502631] [client 20.104.50.220:46853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/ws.php"] [unique_id "apPku2uFRxhFZfnD0nIVRgAAAXE"]
[Sun Aug 30 03:07:23.481487 2026] [security2:error] [pid 502397:tid 502626] [client 20.48.160.90:37710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/replace.php"] [unique_id "apPku2uFRxhFZfnD0nIVRwAAAWw"]
[Sun Aug 30 03:07:23.482016 2026] [security2:error] [pid 502397:tid 502542] [client 68.155.159.216:61692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/themes.php"] [unique_id "apPku2uFRxhFZfnD0nIVSgAAARk"]
[Sun Aug 30 03:07:23.485832 2026] [security2:error] [pid 502397:tid 502634] [client 216.73.216.128:46176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPku2uFRxhFZfnD0nIVTwAAAXQ"]
[Sun Aug 30 03:07:23.487234 2026] [authz_core:error] [pid 502397:tid 502583] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:23.487751 2026] [authz_core:error] [pid 502397:tid 502583] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:23.496320 2026] [security2:error] [pid 502397:tid 502547] [client 20.48.250.41:53483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/aa.php"] [unique_id "apPku2uFRxhFZfnD0nIVXQAAAR4"]
[Sun Aug 30 03:07:23.501989 2026] [security2:error] [pid 502397:tid 502607] [client 20.104.50.220:32535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/tshop.php"] [unique_id "apPku2uFRxhFZfnD0nIVYgAAAVk"]
[Sun Aug 30 03:07:23.560125 2026] [security2:error] [pid 502397:tid 502560] [client 20.63.81.20:4146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/google.php"] [unique_id "apPku2uFRxhFZfnD0nIVhAAAASs"]
[Sun Aug 30 03:07:23.561368 2026] [security2:error] [pid 502397:tid 502602] [client 4.205.62.107:18636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/debuggen.php"] [unique_id "apPku2uFRxhFZfnD0nIVhwAAAVQ"]
[Sun Aug 30 03:07:23.582986 2026] [security2:error] [pid 502397:tid 502565] [client 20.48.250.41:45367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/h2a2ck.php"] [unique_id "apPku2uFRxhFZfnD0nIVmgAAATA"]
[Sun Aug 30 03:07:23.638035 2026] [security2:error] [pid 499145:tid 499310] [client 20.48.160.90:30768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/gulu.php"] [unique_id "apPku1JNq1G5uRhTNnts3wAAACM"]
[Sun Aug 30 03:07:23.640902 2026] [security2:error] [pid 502397:tid 502624] [client 20.48.250.41:53439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/s1.php"] [unique_id "apPku2uFRxhFZfnD0nIVsAAAAWo"]
[Sun Aug 30 03:07:23.694406 2026] [security2:error] [pid 502397:tid 502642] [client 20.63.81.20:4101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "apPku2uFRxhFZfnD0nIVuwAAAXw"]
[Sun Aug 30 03:07:23.696962 2026] [security2:error] [pid 502397:tid 502620] [client 20.104.50.220:52859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/lolz.php"] [unique_id "apPku2uFRxhFZfnD0nIVvQAAAWY"]
[Sun Aug 30 03:07:23.720322 2026] [security2:error] [pid 502397:tid 502537] [client 20.48.250.41:45924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/error_log.php"] [unique_id "apPku2uFRxhFZfnD0nIV1QAAARQ"]
[Sun Aug 30 03:07:23.731106 2026] [security2:error] [pid 502397:tid 502621] [client 20.104.50.220:28678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/cilik.php"] [unique_id "apPku2uFRxhFZfnD0nIV4gAAAWc"]
[Sun Aug 30 03:07:23.783628 2026] [security2:error] [pid 502397:tid 502582] [client 20.48.160.90:61494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/gtghklk.php"] [unique_id "apPku2uFRxhFZfnD0nIWCAAAAUE"]
[Sun Aug 30 03:07:23.788385 2026] [security2:error] [pid 502397:tid 502540] [client 20.196.209.81:20864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/fw.php"] [unique_id "apPku2uFRxhFZfnD0nIWCwAAARc"]
[Sun Aug 30 03:07:23.817702 2026] [security2:error] [pid 499145:tid 499338] [client 20.48.250.41:53481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/0byte.php"] [unique_id "apPku1JNq1G5uRhTNnttLwAAAD8"]
[Sun Aug 30 03:07:23.821638 2026] [security2:error] [pid 499145:tid 499364] [client 20.104.49.130:60628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/zoo2.php"] [unique_id "apPku1JNq1G5uRhTNnttMQAAAFk"]
[Sun Aug 30 03:07:23.828196 2026] [security2:error] [pid 499145:tid 499381] [client 20.63.81.20:4215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/robots.php"] [unique_id "apPku1JNq1G5uRhTNnttNgAAAGo"]
[Sun Aug 30 03:07:23.853588 2026] [authz_core:error] [pid 502397:tid 502635] [client 66.249.66.73:54722] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:23.853585 2026] [authz_core:error] [pid 502397:tid 502557] [client 216.73.216.128:45328] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:23.854089 2026] [authz_core:error] [pid 502397:tid 502557] [client 216.73.216.128:45328] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:23.854089 2026] [authz_core:error] [pid 502397:tid 502635] [client 66.249.66.73:54722] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:23.859979 2026] [security2:error] [pid 502397:tid 502542] [client 20.196.209.81:5665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/themes/wp-signup.php"] [unique_id "apPku2uFRxhFZfnD0nIWLgAAARk"]
[Sun Aug 30 03:07:23.861754 2026] [security2:error] [pid 502397:tid 502652] [client 20.48.250.41:45345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/403.php"] [unique_id "apPku2uFRxhFZfnD0nIWLwAAAYY"]
[Sun Aug 30 03:07:23.864960 2026] [authz_core:error] [pid 499145:tid 499394] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:23.865342 2026] [authz_core:error] [pid 499145:tid 499394] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:23.885884 2026] [security2:error] [pid 502397:tid 502585] [client 40.83.93.50:18522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/g.php"] [unique_id "apPku2uFRxhFZfnD0nIWNwAAAUQ"]
[Sun Aug 30 03:07:23.922340 2026] [security2:error] [pid 502397:tid 502575] [client 20.48.160.90:37725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/comand.php"] [unique_id "apPku2uFRxhFZfnD0nIWSAAAATo"]
[Sun Aug 30 03:07:23.954415 2026] [security2:error] [pid 502397:tid 502628] [client 20.48.250.41:53397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/xr.php"] [unique_id "apPku2uFRxhFZfnD0nIWUgAAAW4"]
[Sun Aug 30 03:07:23.959063 2026] [security2:error] [pid 502397:tid 502536] [client 20.63.81.20:4240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp-content/plugins/ccx/index.php"] [unique_id "apPku2uFRxhFZfnD0nIWWgAAARM"]
[Sun Aug 30 03:07:23.997933 2026] [security2:error] [pid 502397:tid 502626] [client 20.48.250.41:46056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/cytyr.php"] [unique_id "apPku2uFRxhFZfnD0nIWdwAAAWw"]
[Sun Aug 30 03:07:24.029523 2026] [authz_core:error] [pid 502397:tid 502651] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:24.029817 2026] [authz_core:error] [pid 502397:tid 502651] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:24.055862 2026] [security2:error] [pid 502397:tid 502588] [client 20.48.160.90:61507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp_motu_myk3v.php"] [unique_id "apPkvGuFRxhFZfnD0nIWogAAAUc"]
[Sun Aug 30 03:07:24.095546 2026] [authz_core:error] [pid 502397:tid 502634] [client 66.249.66.37:57135] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:24.096029 2026] [authz_core:error] [pid 502397:tid 502634] [client 66.249.66.37:57135] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:24.102222 2026] [security2:error] [pid 502397:tid 502547] [client 20.63.81.20:4202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp-admin/css/colors/maro.php"] [unique_id "apPkvGuFRxhFZfnD0nIWwAAAAR4"]
[Sun Aug 30 03:07:24.117421 2026] [security2:error] [pid 502397:tid 502610] [client 20.104.50.220:63547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/Xzd.php"] [unique_id "apPkvGuFRxhFZfnD0nIWxwAAAVw"]
[Sun Aug 30 03:07:24.145383 2026] [security2:error] [pid 502397:tid 502535] [client 20.48.250.41:50071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/h02ugyh.php"] [unique_id "apPkvGuFRxhFZfnD0nIW2AAAARI"]
[Sun Aug 30 03:07:24.148283 2026] [security2:error] [pid 502397:tid 502595] [client 20.48.250.41:45344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/galer.php"] [unique_id "apPkvGuFRxhFZfnD0nIW3QAAAU0"]
[Sun Aug 30 03:07:24.180451 2026] [security2:error] [pid 502397:tid 502551] [client 20.196.209.81:19923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/test.php"] [unique_id "apPkvGuFRxhFZfnD0nIW9QAAASI"]
[Sun Aug 30 03:07:24.218725 2026] [authz_core:error] [pid 502397:tid 502568] [client 216.73.216.128:45328] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:24.219268 2026] [authz_core:error] [pid 502397:tid 502568] [client 216.73.216.128:45328] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:24.228404 2026] [security2:error] [pid 502397:tid 502554] [client 20.48.160.90:61499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/wp_motu_ypdat.php"] [unique_id "apPkvGuFRxhFZfnD0nIXEAAAASU"]
[Sun Aug 30 03:07:24.232354 2026] [security2:error] [pid 502397:tid 502637] [client 20.63.81.20:4117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp-admin/css/colors/coffee/marijuana.php"] [unique_id "apPkvGuFRxhFZfnD0nIXFQAAAXc"]
[Sun Aug 30 03:07:24.264223 2026] [security2:error] [pid 502397:tid 502585] [client 20.196.209.81:5656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/updraft/about.php"] [unique_id "apPkvGuFRxhFZfnD0nIXNAAAAUQ"]
[Sun Aug 30 03:07:24.285982 2026] [security2:error] [pid 502397:tid 502580] [client 20.48.250.41:53403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/xxw.php"] [unique_id "apPkvGuFRxhFZfnD0nIXTQAAAT8"]
[Sun Aug 30 03:07:24.292680 2026] [security2:error] [pid 502397:tid 502530] [client 68.155.159.216:62024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPkvGuFRxhFZfnD0nIXVgAAAQ0"]
[Sun Aug 30 03:07:24.293290 2026] [security2:error] [pid 502397:tid 502579] [client 114.119.135.166:22803] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "letscoolone.org"] [uri "/playlists/lco20140812.htm"] [unique_id "apPkvGuFRxhFZfnD0nIXVwAAAT4"], referer: https://letscoolone.org/playlists/lco20140812.htm
[Sun Aug 30 03:07:24.309620 2026] [authz_core:error] [pid 499145:tid 499309] [client 216.73.216.128:45648] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:24.310079 2026] [authz_core:error] [pid 499145:tid 499309] [client 216.73.216.128:45648] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:24.330996 2026] [security2:error] [pid 502397:tid 502560] [client 20.48.250.41:45314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/baixy.php"] [unique_id "apPkvGuFRxhFZfnD0nIXdAAAASs"]
[Sun Aug 30 03:07:24.357521 2026] [security2:error] [pid 502397:tid 502635] [client 68.155.159.216:65480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPkvGuFRxhFZfnD0nIXkAAAAXU"]
[Sun Aug 30 03:07:24.361806 2026] [security2:error] [pid 502397:tid 502552] [client 20.63.81.20:4097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp-admin/css/colors/coffee/mari.php"] [unique_id "apPkvGuFRxhFZfnD0nIXlAAAASM"]
[Sun Aug 30 03:07:24.384130 2026] [security2:error] [pid 502397:tid 502653] [client 20.48.160.90:30784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/edit.php"] [unique_id "apPkvGuFRxhFZfnD0nIXmwAAAYc"]
[Sun Aug 30 03:07:24.410551 2026] [security2:error] [pid 502397:tid 502558] [client 114.119.145.183:43867] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.tulsadivorceattorney.pro"] [uri "/tulsa-divorce-information/category/oklahoma-divorce-information/family-law/child-custody/"] [unique_id "apPkvGuFRxhFZfnD0nIXvwAAASk"], referer: https://www.tulsadivorceattorney.pro/tulsa-divorce-information/category/oklahoma-divorce-information/family-law/child-custody/
[Sun Aug 30 03:07:24.411917 2026] [security2:error] [pid 502397:tid 502549] [client 20.48.250.41:64731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/bolt.php"] [unique_id "apPkvGuFRxhFZfnD0nIXwQAAASA"]
[Sun Aug 30 03:07:24.442708 2026] [security2:error] [pid 499145:tid 499294] [client 40.83.93.50:18508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/cc.php"] [unique_id "apPkvFJNq1G5uRhTNntuFgAAABM"]
[Sun Aug 30 03:07:24.460488 2026] [security2:error] [pid 502397:tid 502647] [client 40.83.93.50:5962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/data.php"] [unique_id "apPkvGuFRxhFZfnD0nIX2AAAAYE"]
[Sun Aug 30 03:07:24.461216 2026] [authz_core:error] [pid 502397:tid 502573] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:24.461676 2026] [authz_core:error] [pid 502397:tid 502573] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:24.461891 2026] [security2:error] [pid 502397:tid 502636] [client 20.48.250.41:45372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/ava.php"] [unique_id "apPkvGuFRxhFZfnD0nIX2QAAAXY"]
[Sun Aug 30 03:07:24.494082 2026] [security2:error] [pid 502397:tid 502610] [client 20.63.81.20:4143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp-includes/images/crystal/option.php"] [unique_id "apPkvGuFRxhFZfnD0nIYBwAAAVw"]
[Sun Aug 30 03:07:24.514032 2026] [security2:error] [pid 499145:tid 499348] [client 68.155.159.216:54267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/asd.php"] [unique_id "apPkvFJNq1G5uRhTNntuMQAAAEk"]
[Sun Aug 30 03:07:24.523978 2026] [security2:error] [pid 502397:tid 502560] [client 20.104.50.220:17281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/samll.php"] [unique_id "apPkvGuFRxhFZfnD0nIYEwAAASs"]
[Sun Aug 30 03:07:24.532328 2026] [security2:error] [pid 502397:tid 502545] [client 4.205.62.107:51743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/old_phpinfo.php"] [unique_id "apPkvGuFRxhFZfnD0nIYGQAAARw"]
[Sun Aug 30 03:07:24.533711 2026] [security2:error] [pid 502397:tid 502587] [client 20.104.50.220:6124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/fx.php"] [unique_id "apPkvGuFRxhFZfnD0nIYGwAAAUY"]
[Sun Aug 30 03:07:24.534891 2026] [security2:error] [pid 502397:tid 502635] [client 20.48.160.90:61467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/tqkdqbbv.php"] [unique_id "apPkvGuFRxhFZfnD0nIYHgAAAXU"]
[Sun Aug 30 03:07:24.540364 2026] [security2:error] [pid 502397:tid 502533] [client 20.104.18.15:13572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/wp-admin/js/wp-load.php"] [unique_id "apPkvGuFRxhFZfnD0nIYIwAAARA"]
[Sun Aug 30 03:07:24.540582 2026] [security2:error] [pid 502397:tid 502528] [client 68.155.159.216:61361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPkvGuFRxhFZfnD0nIYJAAAAQs"]
[Sun Aug 30 03:07:24.541111 2026] [security2:error] [pid 502397:tid 502641] [client 20.104.50.220:27536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/nginx_error.php"] [unique_id "apPkvGuFRxhFZfnD0nIYJgAAAXs"]
[Sun Aug 30 03:07:24.542037 2026] [security2:error] [pid 502397:tid 502609] [client 20.104.18.15:34804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/kerang.php"] [unique_id "apPkvGuFRxhFZfnD0nIYKAAAAVs"]
[Sun Aug 30 03:07:24.543871 2026] [security2:error] [pid 502397:tid 502529] [client 20.48.251.3:33288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/wpver.php"] [unique_id "apPkvGuFRxhFZfnD0nIYKgAAAQw"]
[Sun Aug 30 03:07:24.544906 2026] [security2:error] [pid 502397:tid 502598] [client 4.205.62.107:39127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/grsiuk.php"] [unique_id "apPkvGuFRxhFZfnD0nIYKwAAAVA"]
[Sun Aug 30 03:07:24.551855 2026] [security2:error] [pid 502397:tid 502642] [client 20.104.18.15:23551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/503.php"] [unique_id "apPkvGuFRxhFZfnD0nIYLgAAAXw"]
[Sun Aug 30 03:07:24.553525 2026] [security2:error] [pid 502397:tid 502614] [client 4.205.62.107:36024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/phpinfo01.php"] [unique_id "apPkvGuFRxhFZfnD0nIYLwAAAWA"]
[Sun Aug 30 03:07:24.556338 2026] [security2:error] [pid 502397:tid 502531] [client 20.48.250.41:53399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/rtx.php"] [unique_id "apPkvGuFRxhFZfnD0nIYMAAAAQ4"]
[Sun Aug 30 03:07:24.558092 2026] [security2:error] [pid 502397:tid 502542] [client 20.104.18.15:28554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/m.php"] [unique_id "apPkvGuFRxhFZfnD0nIYMgAAARk"]
[Sun Aug 30 03:07:24.558120 2026] [security2:error] [pid 502397:tid 502572] [client 20.104.18.15:43324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/birrs.php"] [unique_id "apPkvGuFRxhFZfnD0nIYMwAAATc"]
[Sun Aug 30 03:07:24.559156 2026] [authz_core:error] [pid 502397:tid 502567] [client 66.249.66.202:61853] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:24.559466 2026] [authz_core:error] [pid 502397:tid 502567] [client 66.249.66.202:61853] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:24.562760 2026] [security2:error] [pid 502397:tid 502604] [client 68.155.159.216:56434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apPkvGuFRxhFZfnD0nIYNgAAAVY"]
[Sun Aug 30 03:07:24.565549 2026] [security2:error] [pid 502397:tid 502575] [client 20.48.251.3:50013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/cu.php"] [unique_id "apPkvGuFRxhFZfnD0nIYOQAAATo"]
[Sun Aug 30 03:07:24.573954 2026] [security2:error] [pid 502397:tid 502610] [client 20.104.18.15:29632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/zoo1.php"] [unique_id "apPkvGuFRxhFZfnD0nIYPwAAAVw"]
[Sun Aug 30 03:07:24.575903 2026] [security2:error] [pid 502397:tid 502632] [client 20.104.50.220:33185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/AkuSayangKamu45.php"] [unique_id "apPkvGuFRxhFZfnD0nIYQwAAAXI"]
[Sun Aug 30 03:07:24.582748 2026] [security2:error] [pid 499145:tid 499398] [client 20.196.209.81:1563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/dropdown.php"] [unique_id "apPkvFJNq1G5uRhTNntuTgAAAHs"]
[Sun Aug 30 03:07:24.596360 2026] [security2:error] [pid 499145:tid 499282] [client 4.205.62.107:62312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/bootstrap.php"] [unique_id "apPkvFJNq1G5uRhTNntuUQAAAAc"]
[Sun Aug 30 03:07:24.602524 2026] [security2:error] [pid 499145:tid 499364] [client 4.205.62.107:64697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/ws61.php"] [unique_id "apPkvFJNq1G5uRhTNntuVgAAAFk"]
[Sun Aug 30 03:07:24.612488 2026] [security2:error] [pid 499145:tid 499360] [client 20.104.18.15:18369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/coffexium.php"] [unique_id "apPkvFJNq1G5uRhTNntuWwAAAFU"]
[Sun Aug 30 03:07:24.615538 2026] [security2:error] [pid 502397:tid 502594] [client 20.48.250.41:46068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/gdn.php"] [unique_id "apPkvGuFRxhFZfnD0nIYXQAAAUw"]
[Sun Aug 30 03:07:24.618709 2026] [security2:error] [pid 499145:tid 499278] [client 20.104.18.15:51584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/file1221.php"] [unique_id "apPkvFJNq1G5uRhTNntuXwAAAAM"]
[Sun Aug 30 03:07:24.620846 2026] [security2:error] [pid 499145:tid 499344] [client 20.48.251.3:4732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/87.php"] [unique_id "apPkvFJNq1G5uRhTNntuYQAAAEU"]
[Sun Aug 30 03:07:24.624346 2026] [security2:error] [pid 499145:tid 499358] [client 20.104.50.220:61959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/images/alfa.php"] [unique_id "apPkvFJNq1G5uRhTNntuYwAAAFM"]
[Sun Aug 30 03:07:24.624505 2026] [security2:error] [pid 502397:tid 502613] [client 20.104.50.220:47101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/notfound.php"] [unique_id "apPkvGuFRxhFZfnD0nIYYAAAAV8"]
[Sun Aug 30 03:07:24.630395 2026] [security2:error] [pid 499145:tid 499369] [client 4.205.62.107:2964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/wp-tem.php"] [unique_id "apPkvFJNq1G5uRhTNntuZQAAAF4"]
[Sun Aug 30 03:07:24.637543 2026] [security2:error] [pid 502397:tid 502625] [client 20.63.81.20:4156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp-includes/pomo/xxx.php"] [unique_id "apPkvGuFRxhFZfnD0nIYYgAAAWs"]
[Sun Aug 30 03:07:24.645007 2026] [security2:error] [pid 502397:tid 502648] [client 20.104.50.220:32099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/twin.php"] [unique_id "apPkvGuFRxhFZfnD0nIYYwAAAYI"]
[Sun Aug 30 03:07:24.655355 2026] [security2:error] [pid 502397:tid 502560] [client 20.196.209.81:4919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/upgrade-temp-backup/min.php"] [unique_id "apPkvGuFRxhFZfnD0nIYZQAAASs"]
[Sun Aug 30 03:07:24.675866 2026] [security2:error] [pid 502397:tid 502535] [client 20.48.160.90:37957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/kjyehoxl.php"] [unique_id "apPkvGuFRxhFZfnD0nIYbgAAARI"]
[Sun Aug 30 03:07:24.692402 2026] [security2:error] [pid 502397:tid 502635] [client 20.48.250.41:53465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/ckk.php"] [unique_id "apPkvGuFRxhFZfnD0nIYdAAAAXU"]
[Sun Aug 30 03:07:24.704497 2026] [security2:error] [pid 499145:tid 499337] [client 20.151.200.44:47083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPkvFJNq1G5uRhTNntufQAAAD4"]
[Sun Aug 30 03:07:24.709450 2026] [security2:error] [pid 502397:tid 502586] [client 20.48.251.3:45840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/wp-class.php"] [unique_id "apPkvGuFRxhFZfnD0nIYfAAAAUU"]
[Sun Aug 30 03:07:24.715463 2026] [security2:error] [pid 502397:tid 502644] [client 4.205.62.107:18649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/phpversion.php"] [unique_id "apPkvGuFRxhFZfnD0nIYhAAAAX4"]
[Sun Aug 30 03:07:24.716722 2026] [authz_core:error] [pid 502397:tid 502653] [client 66.249.66.34:57230] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:24.717015 2026] [authz_core:error] [pid 502397:tid 502653] [client 66.249.66.34:57230] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:24.757549 2026] [security2:error] [pid 499145:tid 499338] [client 20.48.250.41:45952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/f2.php"] [unique_id "apPkvFJNq1G5uRhTNntunAAAAD8"]
[Sun Aug 30 03:07:24.769180 2026] [security2:error] [pid 502397:tid 502566] [client 20.63.81.20:4256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/650.php"] [unique_id "apPkvGuFRxhFZfnD0nIYoAAAATE"]
[Sun Aug 30 03:07:24.809530 2026] [security2:error] [pid 502397:tid 502586] [client 20.48.160.90:37988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/llyuxaqd.php"] [unique_id "apPkvGuFRxhFZfnD0nIYsAAAAUU"]
[Sun Aug 30 03:07:24.842246 2026] [security2:error] [pid 502397:tid 502577] [client 20.48.250.41:50151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.littlebousquet.com"] [uri "/R57.php"] [unique_id "apPkvGuFRxhFZfnD0nIYwAAAATw"]
[Sun Aug 30 03:07:24.881776 2026] [security2:error] [pid 502397:tid 502584] [client 20.104.50.220:28732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/libs-func.php"] [unique_id "apPkvGuFRxhFZfnD0nIY0gAAAUM"]
[Sun Aug 30 03:07:24.895332 2026] [security2:error] [pid 502397:tid 502595] [client 20.63.81.20:4231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/nakrip.php"] [unique_id "apPkvGuFRxhFZfnD0nIY2gAAAU0"]
[Sun Aug 30 03:07:24.926022 2026] [security2:error] [pid 502397:tid 502596] [client 20.104.50.220:62846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/zxcok.php"] [unique_id "apPkvGuFRxhFZfnD0nIY6gAAAU4"]
[Sun Aug 30 03:07:24.931548 2026] [security2:error] [pid 502397:tid 502609] [client 20.48.250.41:46058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/grsiuk.php"] [unique_id "apPkvGuFRxhFZfnD0nIY7wAAAVs"]
[Sun Aug 30 03:07:24.943162 2026] [security2:error] [pid 499145:tid 499375] [client 40.83.93.50:9689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/dt-the7/css/static-less/plugins/admin.php"] [unique_id "apPkvFJNq1G5uRhTNntu2wAAAGQ"]
[Sun Aug 30 03:07:24.963445 2026] [security2:error] [pid 502397:tid 502646] [client 20.48.160.90:61516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/nbwxolou.php"] [unique_id "apPkvGuFRxhFZfnD0nIZBAAAAYA"]
[Sun Aug 30 03:07:24.982371 2026] [authz_core:error] [pid 502397:tid 502532] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:24.982810 2026] [authz_core:error] [pid 502397:tid 502532] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:24.991701 2026] [security2:error] [pid 502397:tid 502534] [client 20.196.209.81:19926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/mar.php"] [unique_id "apPkvGuFRxhFZfnD0nIZGwAAARE"]
[Sun Aug 30 03:07:25.006077 2026] [security2:error] [pid 502397:tid 502540] [client 40.83.93.50:7960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/f35.php"] [unique_id "apPkvWuFRxhFZfnD0nIZIgAAARc"]
[Sun Aug 30 03:07:25.027965 2026] [security2:error] [pid 502397:tid 502588] [client 20.63.81.20:4176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp-includes/interactivity-api/flower.php"] [unique_id "apPkvWuFRxhFZfnD0nIZMgAAAUc"]
[Sun Aug 30 03:07:25.046758 2026] [security2:error] [pid 499145:tid 499363] [client 20.196.209.81:4888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/upgrade-temp-backup/pk.php"] [unique_id "apPkvVJNq1G5uRhTNntvAQAAAFg"]
[Sun Aug 30 03:07:25.066633 2026] [security2:error] [pid 502397:tid 502529] [client 68.155.159.216:61640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-mail.php"] [unique_id "apPkvWuFRxhFZfnD0nIZUAAAAQw"]
[Sun Aug 30 03:07:25.070725 2026] [security2:error] [pid 502397:tid 502572] [client 20.48.250.41:45371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/wp-scr1pts.php"] [unique_id "apPkvWuFRxhFZfnD0nIZVgAAATc"]
[Sun Aug 30 03:07:25.132755 2026] [authz_core:error] [pid 499145:tid 499329] [client 66.249.66.36:35404] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:25.133225 2026] [authz_core:error] [pid 499145:tid 499329] [client 66.249.66.36:35404] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:25.137273 2026] [security2:error] [pid 502397:tid 502536] [client 20.48.160.90:37984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/nsxeubyv.php"] [unique_id "apPkvWuFRxhFZfnD0nIZdAAAARM"]
[Sun Aug 30 03:07:25.174713 2026] [security2:error] [pid 502397:tid 502541] [client 20.63.81.20:4196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/xcc.php"] [unique_id "apPkvWuFRxhFZfnD0nIZigAAARg"]
[Sun Aug 30 03:07:25.199453 2026] [security2:error] [pid 502397:tid 502545] [client 20.48.250.41:45346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/num.php"] [unique_id "apPkvWuFRxhFZfnD0nIZngAAARw"]
[Sun Aug 30 03:07:25.220456 2026] [authz_core:error] [pid 502397:tid 502581] [client 216.73.216.128:11425] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:25.220840 2026] [authz_core:error] [pid 502397:tid 502581] [client 216.73.216.128:11425] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:25.251248 2026] [security2:error] [pid 502397:tid 502619] [client 20.104.50.220:51604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/ms-sitess.php"] [unique_id "apPkvWuFRxhFZfnD0nIZuAAAAWU"]
[Sun Aug 30 03:07:25.279993 2026] [security2:error] [pid 502397:tid 502576] [client 34.125.55.247:1880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/id_rsa"] [unique_id "apPkvWuFRxhFZfnD0nIZ2QAAATs"]
[Sun Aug 30 03:07:25.307523 2026] [security2:error] [pid 502397:tid 502583] [client 20.63.81.20:4249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp-includes/Text/Diff/Engine/aaa.php"] [unique_id "apPkvWuFRxhFZfnD0nIZ8AAAAUI"]
[Sun Aug 30 03:07:25.311943 2026] [security2:error] [pid 502397:tid 502599] [client 34.125.55.247:1880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/id_dsa"] [unique_id "apPkvWuFRxhFZfnD0nIZ8wAAAVE"]
[Sun Aug 30 03:07:25.312765 2026] [security2:error] [pid 502397:tid 502577] [client 34.125.55.247:1916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/key.pem"] [unique_id "apPkvWuFRxhFZfnD0nIZ9wAAATw"]
[Sun Aug 30 03:07:25.314133 2026] [security2:error] [pid 502397:tid 502645] [client 20.48.160.90:61515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/zfqipfss.php"] [unique_id "apPkvWuFRxhFZfnD0nIZ-QAAAX8"]
[Sun Aug 30 03:07:25.318614 2026] [security2:error] [pid 502397:tid 502597] [client 34.125.55.247:1928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/privatekey.key"] [unique_id "apPkvWuFRxhFZfnD0nIZ-gAAAU8"]
[Sun Aug 30 03:07:25.326286 2026] [security2:error] [pid 502397:tid 502628] [client 34.125.55.247:1880] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpanel.engaginggoddaily.com"] [uri "/wp-config.php.bak"] [unique_id "apPkvWuFRxhFZfnD0nIaBAAAAW4"]
[Sun Aug 30 03:07:25.328325 2026] [security2:error] [pid 502397:tid 502587] [client 34.125.55.247:1944] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpanel.engaginggoddaily.com"] [uri "/wp-config.php.old"] [unique_id "apPkvWuFRxhFZfnD0nIaBgAAAUY"]
[Sun Aug 30 03:07:25.328482 2026] [security2:error] [pid 502397:tid 502603] [client 4.205.62.107:32453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/filesystems.php"] [unique_id "apPkvWuFRxhFZfnD0nIaBQAAAVU"]
[Sun Aug 30 03:07:25.329526 2026] [security2:error] [pid 502397:tid 502582] [client 34.125.55.247:1884] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/private-key"] [unique_id "apPkvWuFRxhFZfnD0nIZ-wAAAUE"]
[Sun Aug 30 03:07:25.329733 2026] [proxy_http:error] [pid 502397:tid 502567] (20014)Internal error (specific information not available): [client 34.125.55.247:1916] AH01102: error reading status line from remote server 127.0.0.1:2082, referer: https://cpanel.engaginggoddaily.com/id_ed25519
[Sun Aug 30 03:07:25.333621 2026] [security2:error] [pid 502397:tid 502538] [client 34.125.55.247:1938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.55.125.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.engaginggoddaily.com"] [uri "/wp-config.php"] [unique_id "apPkvWuFRxhFZfnD0nIZ_AAAARU"]
[Sun Aug 30 03:07:25.336865 2026] [security2:error] [pid 502397:tid 502622] [client 20.48.250.41:46024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/a4.php"] [unique_id "apPkvWuFRxhFZfnD0nIaDgAAAWg"]
[Sun Aug 30 03:07:25.341349 2026] [security2:error] [pid 502397:tid 502576] [client 34.125.55.247:1988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.55.125.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.engaginggoddaily.com"] [uri "/config.php.bak"] [unique_id "apPkvWuFRxhFZfnD0nIaFgAAATs"]
[Sun Aug 30 03:07:25.346011 2026] [security2:error] [pid 502397:tid 502596] [client 34.125.55.247:1928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.55.125.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.engaginggoddaily.com"] [uri "/config.php"] [unique_id "apPkvWuFRxhFZfnD0nIaDAAAAU4"]
[Sun Aug 30 03:07:25.352504 2026] [authz_core:error] [pid 499145:tid 499312] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:25.352987 2026] [authz_core:error] [pid 499145:tid 499312] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:25.354217 2026] [proxy_http:error] [pid 502397:tid 502560] (20014)Internal error (specific information not available): [client 34.125.55.247:2002] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:25.354231 2026] [proxy:error] [pid 502397:tid 502560] [client 34.125.55.247:2002] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/config/database.yml
[Sun Aug 30 03:07:25.361009 2026] [security2:error] [pid 502397:tid 502637] [client 114.119.155.142:39421] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "direcorgigames.com"] [uri "/community/profile/samuelrobertsonwp"] [unique_id "apPkvWuFRxhFZfnD0nIaKwAAAXc"], referer: https://direcorgigames.com/community/profile/samuelrobertsonwp?foro=allread&foro_n=fcac550fe4
[Sun Aug 30 03:07:25.414253 2026] [security2:error] [pid 502397:tid 502598] [client 40.83.93.50:11516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/hideo/network.php"] [unique_id "apPkvWuFRxhFZfnD0nIaXAAAAVA"]
[Sun Aug 30 03:07:25.415369 2026] [security2:error] [pid 502397:tid 502632] [client 20.196.209.81:20885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/css.php"] [unique_id "apPkvWuFRxhFZfnD0nIaXQAAAXI"]
[Sun Aug 30 03:07:25.416245 2026] [security2:error] [pid 502397:tid 502552] [client 68.155.159.216:62038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/goat.php"] [unique_id "apPkvWuFRxhFZfnD0nIaXgAAASM"]
[Sun Aug 30 03:07:25.442842 2026] [security2:error] [pid 502397:tid 502530] [client 20.63.81.20:4199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp-includes/style-engine/gecko-new.php"] [unique_id "apPkvWuFRxhFZfnD0nIacgAAAQ0"]
[Sun Aug 30 03:07:25.448497 2026] [security2:error] [pid 502397:tid 502535] [client 20.48.160.90:37646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arrowlandgroup.com"] [uri "/zrjuyoos.php"] [unique_id "apPkvWuFRxhFZfnD0nIacwAAARI"]
[Sun Aug 30 03:07:25.460099 2026] [authz_core:error] [pid 502397:tid 502596] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:25.460492 2026] [authz_core:error] [pid 502397:tid 502596] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:25.460916 2026] [security2:error] [pid 502397:tid 502616] [client 20.196.209.81:5855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/upgrade-temp-backup/plugins/security.php"] [unique_id "apPkvWuFRxhFZfnD0nIafgAAAWI"]
[Sun Aug 30 03:07:25.469576 2026] [security2:error] [pid 502397:tid 502562] [client 20.151.200.44:55722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/wp-content/admin.php"] [unique_id "apPkvWuFRxhFZfnD0nIahgAAAS0"]
[Sun Aug 30 03:07:25.487676 2026] [security2:error] [pid 502397:tid 502625] [client 20.48.250.41:46053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/tfm.php"] [unique_id "apPkvWuFRxhFZfnD0nIaoAAAAWs"]
[Sun Aug 30 03:07:25.555000 2026] [security2:error] [pid 502397:tid 502603] [client 40.83.93.50:18507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/classsmtps.php"] [unique_id "apPkvWuFRxhFZfnD0nIa0AAAAVU"]
[Sun Aug 30 03:07:25.584034 2026] [security2:error] [pid 502397:tid 502635] [client 20.63.81.20:4152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp-settings.php"] [unique_id "apPkvWuFRxhFZfnD0nIa6QAAAXU"]
[Sun Aug 30 03:07:25.591333 2026] [security2:error] [pid 502397:tid 502604] [client 68.155.159.216:12354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-includes/content.php"] [unique_id "apPkvWuFRxhFZfnD0nIa8QAAAVY"]
[Sun Aug 30 03:07:25.598266 2026] [authz_core:error] [pid 502397:tid 502641] [client 216.73.216.128:11425] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:25.598766 2026] [authz_core:error] [pid 502397:tid 502641] [client 216.73.216.128:11425] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:25.636343 2026] [security2:error] [pid 499145:tid 499351] [client 20.48.250.41:46035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/Geforce.php"] [unique_id "apPkvVJNq1G5uRhTNntv2QAAAEw"]
[Sun Aug 30 03:07:25.640882 2026] [security2:error] [pid 499145:tid 499386] [client 20.104.49.130:48025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/xa.php"] [unique_id "apPkvVJNq1G5uRhTNntv2wAAAG8"]
[Sun Aug 30 03:07:25.660550 2026] [security2:error] [pid 502397:tid 502646] [client 20.104.50.220:17319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/ingfo.php"] [unique_id "apPkvWuFRxhFZfnD0nIbAwAAAYA"]
[Sun Aug 30 03:07:25.670133 2026] [security2:error] [pid 502397:tid 502536] [client 68.155.159.216:11244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-admin/user/index.php"] [unique_id "apPkvWuFRxhFZfnD0nIbCAAAARM"]
[Sun Aug 30 03:07:25.670904 2026] [security2:error] [pid 502397:tid 502650] [client 20.104.50.220:6108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/p0wny.php"] [unique_id "apPkvWuFRxhFZfnD0nIbCgAAAYQ"]
[Sun Aug 30 03:07:25.674666 2026] [security2:error] [pid 499145:tid 499306] [client 4.205.62.107:56591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psychiatristscottsdale.com"] [uri "/wp-act.php"] [unique_id "apPkvVJNq1G5uRhTNntv4gAAAB8"]
[Sun Aug 30 03:07:25.676306 2026] [security2:error] [pid 499145:tid 499313] [client 68.155.159.216:55137] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.camilaymarco.com"] [uri "/1.php"] [unique_id "apPkvVJNq1G5uRhTNntv4wAAACY"]
[Sun Aug 30 03:07:25.676392 2026] [security2:error] [pid 499145:tid 499313] [client 68.155.159.216:55137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/1.php"] [unique_id "apPkvVJNq1G5uRhTNntv4wAAACY"]
[Sun Aug 30 03:07:25.677831 2026] [security2:error] [pid 499145:tid 499303] [client 20.104.18.15:13656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/robot.php"] [unique_id "apPkvVJNq1G5uRhTNntv5AAAABw"]
[Sun Aug 30 03:07:25.681977 2026] [security2:error] [pid 502397:tid 502653] [client 20.104.50.220:27446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/compat.php"] [unique_id "apPkvWuFRxhFZfnD0nIbDQAAAYc"]
[Sun Aug 30 03:07:25.687147 2026] [security2:error] [pid 502397:tid 502630] [client 4.205.62.107:62068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/paypal.php"] [unique_id "apPkvWuFRxhFZfnD0nIbEQAAAXA"]
[Sun Aug 30 03:07:25.692874 2026] [security2:error] [pid 502397:tid 502569] [client 20.104.18.15:34777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/m.php"] [unique_id "apPkvWuFRxhFZfnD0nIbFwAAATQ"]
[Sun Aug 30 03:07:25.694236 2026] [security2:error] [pid 502397:tid 502569] [client 20.104.18.15:28551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/33.php"] [unique_id "apPkvWuFRxhFZfnD0nIbGAAAATQ"]
[Sun Aug 30 03:07:25.694252 2026] [security2:error] [pid 502397:tid 502546] [client 20.104.18.15:23512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/504.php"] [unique_id "apPkvWuFRxhFZfnD0nIbGQAAAR0"]
[Sun Aug 30 03:07:25.694501 2026] [security2:error] [pid 502397:tid 502637] [client 20.48.251.3:33304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/ah25.php"] [unique_id "apPkvWuFRxhFZfnD0nIbGgAAAXc"]
[Sun Aug 30 03:07:25.694635 2026] [security2:error] [pid 502397:tid 502535] [client 20.104.18.15:43975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/sss.php"] [unique_id "apPkvWuFRxhFZfnD0nIbGwAAARI"]
[Sun Aug 30 03:07:25.696851 2026] [security2:error] [pid 502397:tid 502571] [client 4.205.62.107:35971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/cxc.php"] [unique_id "apPkvWuFRxhFZfnD0nIbHQAAATY"]
[Sun Aug 30 03:07:25.705758 2026] [security2:error] [pid 502397:tid 502626] [client 20.48.251.3:49988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/services.php"] [unique_id "apPkvWuFRxhFZfnD0nIbJwAAAWw"]
[Sun Aug 30 03:07:25.719283 2026] [security2:error] [pid 502397:tid 502629] [client 20.63.81.20:4251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp-signup.php"] [unique_id "apPkvWuFRxhFZfnD0nIbTAAAAW8"]
[Sun Aug 30 03:07:25.728423 2026] [security2:error] [pid 502397:tid 502638] [client 68.155.159.216:65429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/about.php"] [unique_id "apPkvWuFRxhFZfnD0nIbVgAAAXg"]
[Sun Aug 30 03:07:25.733730 2026] [security2:error] [pid 502397:tid 502562] [client 4.205.62.107:22919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/333.php"] [unique_id "apPkvWuFRxhFZfnD0nIbXgAAAS0"]
[Sun Aug 30 03:07:25.735118 2026] [security2:error] [pid 502397:tid 502583] [client 20.104.50.220:33538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/googlebots.php"] [unique_id "apPkvWuFRxhFZfnD0nIbXwAAAUI"]
[Sun Aug 30 03:07:25.740229 2026] [security2:error] [pid 502397:tid 502590] [client 4.205.62.107:61772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/xza.php"] [unique_id "apPkvWuFRxhFZfnD0nIbaAAAAUg"]
[Sun Aug 30 03:07:25.748132 2026] [security2:error] [pid 502397:tid 502593] [client 20.104.18.15:18397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/BDKR28WP.php"] [unique_id "apPkvWuFRxhFZfnD0nIbcAAAAUs"]
[Sun Aug 30 03:07:25.757907 2026] [security2:error] [pid 499145:tid 499281] [client 20.104.50.220:46202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wso1337.php"] [unique_id "apPkvVJNq1G5uRhTNntwBwAAAAY"]
[Sun Aug 30 03:07:25.758927 2026] [security2:error] [pid 499145:tid 499380] [client 20.48.251.3:5109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/plss3.php"] [unique_id "apPkvVJNq1G5uRhTNntwCAAAAGk"]
[Sun Aug 30 03:07:25.768940 2026] [security2:error] [pid 499145:tid 499366] [client 20.48.250.41:45959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/click.php"] [unique_id "apPkvVJNq1G5uRhTNntwDgAAAFs"]
[Sun Aug 30 03:07:25.769815 2026] [security2:error] [pid 499145:tid 499323] [client 20.104.18.15:51679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/nox.php"] [unique_id "apPkvVJNq1G5uRhTNntwDwAAADA"]
[Sun Aug 30 03:07:25.770813 2026] [authz_core:error] [pid 502397:tid 502640] [client 66.249.66.70:55103] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:25.771360 2026] [authz_core:error] [pid 502397:tid 502640] [client 66.249.66.70:55103] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:25.771443 2026] [security2:error] [pid 499145:tid 499322] [client 4.205.62.107:2773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/txets.php"] [unique_id "apPkvVJNq1G5uRhTNntwEAAAAC8"]
[Sun Aug 30 03:07:25.779321 2026] [authz_core:error] [pid 499145:tid 499363] [client 216.73.216.128:45648] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:25.779603 2026] [authz_core:error] [pid 499145:tid 499363] [client 216.73.216.128:45648] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:25.804673 2026] [security2:error] [pid 502397:tid 502595] [client 20.104.18.15:29663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/radio.php"] [unique_id "apPkvWuFRxhFZfnD0nIbjgAAAU0"]
[Sun Aug 30 03:07:25.811212 2026] [security2:error] [pid 502397:tid 502569] [client 20.104.50.220:32547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/upload.php"] [unique_id "apPkvWuFRxhFZfnD0nIbkQAAATQ"]
[Sun Aug 30 03:07:25.811350 2026] [security2:error] [pid 502397:tid 502549] [client 20.104.50.220:61433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/images/alfashell.php"] [unique_id "apPkvWuFRxhFZfnD0nIbkwAAASA"]
[Sun Aug 30 03:07:25.838316 2026] [security2:error] [pid 502397:tid 502633] [client 20.196.209.81:19120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/autoload_classmap.php"] [unique_id "apPkvWuFRxhFZfnD0nIbpgAAAXM"]
[Sun Aug 30 03:07:25.856770 2026] [security2:error] [pid 502397:tid 502586] [client 20.63.81.20:4163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp-conffg.php"] [unique_id "apPkvWuFRxhFZfnD0nIbsQAAAUU"]
[Sun Aug 30 03:07:25.859991 2026] [security2:error] [pid 502397:tid 502605] [client 20.196.209.81:5744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/upgrade-temp-backup/plugins/users.php"] [unique_id "apPkvWuFRxhFZfnD0nIbsgAAAVc"]
[Sun Aug 30 03:07:25.866715 2026] [security2:error] [pid 502397:tid 502608] [client 20.48.251.3:7074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/database.php"] [unique_id "apPkvWuFRxhFZfnD0nIbtAAAAVo"]
[Sun Aug 30 03:07:25.870007 2026] [security2:error] [pid 502397:tid 502575] [client 4.205.62.107:18790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/adminfus.php"] [unique_id "apPkvWuFRxhFZfnD0nIbtQAAATo"]
[Sun Aug 30 03:07:25.882881 2026] [authz_core:error] [pid 502397:tid 502588] [client 66.249.66.67:64553] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:25.883142 2026] [authz_core:error] [pid 502397:tid 502588] [client 66.249.66.67:64553] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:25.898842 2026] [security2:error] [pid 502397:tid 502617] [client 40.83.93.50:9683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPkvWuFRxhFZfnD0nIbwQAAAWM"]
[Sun Aug 30 03:07:25.949947 2026] [security2:error] [pid 502397:tid 502651] [client 20.48.250.41:46032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/ms.php"] [unique_id "apPkvWuFRxhFZfnD0nIb3AAAAYU"]
[Sun Aug 30 03:07:25.997689 2026] [security2:error] [pid 502397:tid 502533] [client 20.63.81.20:4124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp-validate.php"] [unique_id "apPkvWuFRxhFZfnD0nIcAgAAARA"]
[Sun Aug 30 03:07:26.018962 2026] [authz_core:error] [pid 502397:tid 502535] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:26.019261 2026] [authz_core:error] [pid 502397:tid 502535] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:26.106579 2026] [security2:error] [pid 502397:tid 502634] [client 40.83.93.50:7511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/install.php"] [unique_id "apPkvmuFRxhFZfnD0nIcSAAAAXQ"]
[Sun Aug 30 03:07:26.113947 2026] [security2:error] [pid 502397:tid 502646] [client 20.104.50.220:29171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-supports.php"] [unique_id "apPkvmuFRxhFZfnD0nIcSwAAAYA"]
[Sun Aug 30 03:07:26.114098 2026] [security2:error] [pid 499145:tid 499317] [client 20.48.250.41:45340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/zxekqlxb.php"] [unique_id "apPkvlJNq1G5uRhTNntwjQAAACo"]
[Sun Aug 30 03:07:26.129479 2026] [security2:error] [pid 502397:tid 502552] [client 20.63.81.20:4163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/700.php"] [unique_id "apPkvmuFRxhFZfnD0nIcUAAAASM"]
[Sun Aug 30 03:07:26.191089 2026] [authz_core:error] [pid 502397:tid 502647] [client 66.249.66.70:62247] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:26.191531 2026] [authz_core:error] [pid 502397:tid 502647] [client 66.249.66.70:62247] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:26.205369 2026] [security2:error] [pid 502397:tid 502575] [client 68.155.159.216:62283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/cgi-bin/index.php"] [unique_id "apPkvmuFRxhFZfnD0nIclAAAATo"]
[Sun Aug 30 03:07:26.247153 2026] [security2:error] [pid 502397:tid 502593] [client 20.48.250.41:45335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/init.php"] [unique_id "apPkvmuFRxhFZfnD0nIcqwAAAUs"]
[Sun Aug 30 03:07:26.251698 2026] [security2:error] [pid 502397:tid 502561] [client 20.196.209.81:4896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/upgrade-temp-backup/plugins/wp-blog-header.php"] [unique_id "apPkvmuFRxhFZfnD0nIcsgAAASw"]
[Sun Aug 30 03:07:26.262247 2026] [security2:error] [pid 502397:tid 502580] [client 20.63.81.20:4238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/c4.php"] [unique_id "apPkvmuFRxhFZfnD0nIcuwAAAT8"]
[Sun Aug 30 03:07:26.327134 2026] [security2:error] [pid 502397:tid 502622] [client 20.196.209.81:19934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/info.php"] [unique_id "apPkvmuFRxhFZfnD0nIc6QAAAWg"]
[Sun Aug 30 03:07:26.328611 2026] [authz_core:error] [pid 502397:tid 502610] [client 216.73.216.128:63339] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:26.329087 2026] [authz_core:error] [pid 502397:tid 502610] [client 216.73.216.128:63339] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:26.389124 2026] [security2:error] [pid 502397:tid 502606] [client 20.104.50.220:51630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/aku.php"] [unique_id "apPkvmuFRxhFZfnD0nIdGQAAAVg"]
[Sun Aug 30 03:07:26.400421 2026] [security2:error] [pid 502397:tid 502529] [client 20.63.81.20:4270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp-tymanage.php"] [unique_id "apPkvmuFRxhFZfnD0nIdLgAAAQw"]
[Sun Aug 30 03:07:26.403222 2026] [security2:error] [pid 502397:tid 502611] [client 40.83.93.50:9675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/intense/block-css.php"] [unique_id "apPkvmuFRxhFZfnD0nIdMwAAAV0"]
[Sun Aug 30 03:07:26.408848 2026] [authz_core:error] [pid 502397:tid 502651] [client 66.249.66.203:36865] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:26.409183 2026] [authz_core:error] [pid 502397:tid 502651] [client 66.249.66.203:36865] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:26.415395 2026] [security2:error] [pid 502397:tid 502597] [client 20.48.250.41:46064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/term.php"] [unique_id "apPkvmuFRxhFZfnD0nIdPgAAAU8"]
[Sun Aug 30 03:07:26.466264 2026] [authz_core:error] [pid 502397:tid 502565] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:26.466548 2026] [authz_core:error] [pid 502397:tid 502565] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:26.515238 2026] [security2:error] [pid 499145:tid 499281] [client 20.104.49.130:48054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/btyuio.php"] [unique_id "apPkvlJNq1G5uRhTNntxLgAAAAY"]
[Sun Aug 30 03:07:26.529456 2026] [security2:error] [pid 502397:tid 502652] [client 20.63.81.20:4392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/ajfto.php"] [unique_id "apPkvmuFRxhFZfnD0nIdpQAAAYY"]
[Sun Aug 30 03:07:26.590615 2026] [authz_core:error] [pid 499145:tid 499282] [client 66.249.66.197:62735] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:26.591103 2026] [authz_core:error] [pid 499145:tid 499282] [client 66.249.66.197:62735] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:26.594000 2026] [security2:error] [pid 502397:tid 502561] [client 20.48.250.41:45962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/aaa.php"] [unique_id "apPkvmuFRxhFZfnD0nId2gAAASw"]
[Sun Aug 30 03:07:26.609527 2026] [security2:error] [pid 502397:tid 502634] [client 40.83.93.50:7534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/wp.php"] [unique_id "apPkvmuFRxhFZfnD0nId4gAAAXQ"]
[Sun Aug 30 03:07:26.618751 2026] [security2:error] [pid 502397:tid 502585] [client 68.155.159.216:62036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apPkvmuFRxhFZfnD0nId5wAAAUQ"]
[Sun Aug 30 03:07:26.649596 2026] [security2:error] [pid 499145:tid 499323] [client 20.196.209.81:5847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/upgrade-temp-backup/plugins/wp-mail.php"] [unique_id "apPkvlJNq1G5uRhTNntxUQAAADA"]
[Sun Aug 30 03:07:26.677493 2026] [security2:error] [pid 502397:tid 502590] [client 20.63.81.20:4213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp_KwIW0U5F.php"] [unique_id "apPkvmuFRxhFZfnD0nId_QAAAUg"]
[Sun Aug 30 03:07:26.725764 2026] [security2:error] [pid 502397:tid 502639] [client 20.48.250.41:45329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/xsox.php"] [unique_id "apPkvmuFRxhFZfnD0nIeJgAAAXk"]
[Sun Aug 30 03:07:26.739157 2026] [security2:error] [pid 502397:tid 502546] [client 20.196.209.81:19908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/b.php"] [unique_id "apPkvmuFRxhFZfnD0nIeMwAAAR0"]
[Sun Aug 30 03:07:26.778267 2026] [security2:error] [pid 502397:tid 502547] [client 68.155.159.216:56356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-includes/plugins.php"] [unique_id "apPkvmuFRxhFZfnD0nIeTQAAAR4"]
[Sun Aug 30 03:07:26.799052 2026] [security2:error] [pid 502397:tid 502575] [client 20.104.50.220:16714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/error_log.php"] [unique_id "apPkvmuFRxhFZfnD0nIeWAAAATo"]
[Sun Aug 30 03:07:26.805966 2026] [security2:error] [pid 502397:tid 502566] [client 20.63.81.20:4114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp_xiPu52Ut.php"] [unique_id "apPkvmuFRxhFZfnD0nIeaQAAATE"]
[Sun Aug 30 03:07:26.807374 2026] [security2:error] [pid 502397:tid 502619] [client 68.155.159.216:12391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-admin/css/index.php"] [unique_id "apPkvmuFRxhFZfnD0nIeawAAAWU"]
[Sun Aug 30 03:07:26.808818 2026] [security2:error] [pid 502397:tid 502595] [client 20.104.50.220:6085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/69.php"] [unique_id "apPkvmuFRxhFZfnD0nIebQAAAU0"]
[Sun Aug 30 03:07:26.817138 2026] [security2:error] [pid 502397:tid 502560] [client 20.104.18.15:13592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/revo.php"] [unique_id "apPkvmuFRxhFZfnD0nIecgAAASs"]
[Sun Aug 30 03:07:26.820178 2026] [security2:error] [pid 502397:tid 502590] [client 20.104.50.220:27533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/class-wpdb.php"] [unique_id "apPkvmuFRxhFZfnD0nIeeAAAAUg"]
[Sun Aug 30 03:07:26.821470 2026] [security2:error] [pid 502397:tid 502535] [client 68.155.159.216:55089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/ws.php"] [unique_id "apPkvmuFRxhFZfnD0nIeewAAARI"]
[Sun Aug 30 03:07:26.828876 2026] [security2:error] [pid 502397:tid 502556] [client 20.48.251.3:33305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/groceries/index.php"] [unique_id "apPkvmuFRxhFZfnD0nIegQAAASc"]
[Sun Aug 30 03:07:26.833461 2026] [security2:error] [pid 502397:tid 502646] [client 20.104.18.15:28629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/packed.php"] [unique_id "apPkvmuFRxhFZfnD0nIeiAAAAYA"]
[Sun Aug 30 03:07:26.837411 2026] [security2:error] [pid 502397:tid 502568] [client 20.104.18.15:34772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/fling.php"] [unique_id "apPkvmuFRxhFZfnD0nIeiwAAATM"]
[Sun Aug 30 03:07:26.842752 2026] [security2:error] [pid 502397:tid 502532] [client 4.205.62.107:35991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/oiko6u.php"] [unique_id "apPkvmuFRxhFZfnD0nIekQAAAQ8"]
[Sun Aug 30 03:07:26.845150 2026] [security2:error] [pid 502397:tid 502640] [client 4.205.62.107:63974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/userfuns.php"] [unique_id "apPkvmuFRxhFZfnD0nIekwAAAXo"]
[Sun Aug 30 03:07:26.861274 2026] [security2:error] [pid 502397:tid 502619] [client 20.104.18.15:23447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/admin.php"] [unique_id "apPkvmuFRxhFZfnD0nIenAAAAWU"]
[Sun Aug 30 03:07:26.872846 2026] [security2:error] [pid 502397:tid 502564] [client 20.48.250.41:45333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/lkui.php"] [unique_id "apPkvmuFRxhFZfnD0nIenwAAAS8"]
[Sun Aug 30 03:07:26.873721 2026] [security2:error] [pid 502397:tid 502626] [client 4.205.62.107:64674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/ms-edit.php"] [unique_id "apPkvmuFRxhFZfnD0nIeoAAAAWw"]
[Sun Aug 30 03:07:26.874001 2026] [security2:error] [pid 502397:tid 502544] [client 4.205.62.107:22532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/G-in.php"] [unique_id "apPkvmuFRxhFZfnD0nIeoQAAARs"]
[Sun Aug 30 03:07:26.874578 2026] [security2:error] [pid 502397:tid 502558] [client 20.48.251.3:55536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/filesystems.php"] [unique_id "apPkvmuFRxhFZfnD0nIeogAAASk"]
[Sun Aug 30 03:07:26.876134 2026] [authz_core:error] [pid 499145:tid 499275] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:26.876415 2026] [authz_core:error] [pid 499145:tid 499275] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:26.884487 2026] [security2:error] [pid 502397:tid 502569] [client 40.83.93.50:11519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/login.php"] [unique_id "apPkvmuFRxhFZfnD0nIepwAAATQ"]
[Sun Aug 30 03:07:26.887840 2026] [security2:error] [pid 502397:tid 502648] [client 20.104.18.15:18408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/sf.php"] [unique_id "apPkvmuFRxhFZfnD0nIeqgAAAYI"]
[Sun Aug 30 03:07:26.889883 2026] [security2:error] [pid 499145:tid 499334] [client 20.104.50.220:32907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/ben.php"] [unique_id "apPkvlJNq1G5uRhTNntxoQAAADs"]
[Sun Aug 30 03:07:26.894222 2026] [security2:error] [pid 502397:tid 502606] [client 68.155.159.216:61322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apPkvmuFRxhFZfnD0nIerAAAAVg"]
[Sun Aug 30 03:07:26.895207 2026] [security2:error] [pid 502397:tid 502549] [client 20.104.50.220:46432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wso2.php"] [unique_id "apPkvmuFRxhFZfnD0nIerQAAASA"]
[Sun Aug 30 03:07:26.909996 2026] [security2:error] [pid 502397:tid 502582] [client 4.205.62.107:2321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/time.php"] [unique_id "apPkvmuFRxhFZfnD0nIetQAAAUE"]
[Sun Aug 30 03:07:26.910017 2026] [security2:error] [pid 502397:tid 502581] [client 20.104.18.15:51602] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "weaponizedentertainment.com"] [uri "/1.php"] [unique_id "apPkvmuFRxhFZfnD0nIetgAAAUA"]
[Sun Aug 30 03:07:26.910113 2026] [security2:error] [pid 502397:tid 502581] [client 20.104.18.15:51602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/1.php"] [unique_id "apPkvmuFRxhFZfnD0nIetgAAAUA"]
[Sun Aug 30 03:07:26.928113 2026] [security2:error] [pid 499145:tid 499329] [client 20.48.251.3:4684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/aws.php"] [unique_id "apPkvlJNq1G5uRhTNntxrQAAADY"]
[Sun Aug 30 03:07:26.940442 2026] [security2:error] [pid 502397:tid 502599] [client 20.63.81.20:4105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp_n5VD7XDh.php"] [unique_id "apPkvmuFRxhFZfnD0nIevwAAAVE"]
[Sun Aug 30 03:07:26.947145 2026] [security2:error] [pid 502397:tid 502540] [client 20.104.50.220:32551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/ups.php"] [unique_id "apPkvmuFRxhFZfnD0nIexAAAARc"]
[Sun Aug 30 03:07:26.968580 2026] [authz_core:error] [pid 502397:tid 502651] [client 66.249.66.197:39682] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:26.969021 2026] [authz_core:error] [pid 502397:tid 502651] [client 66.249.66.197:39682] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:26.969608 2026] [authz_core:error] [pid 502397:tid 502645] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:26.970071 2026] [authz_core:error] [pid 502397:tid 502645] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:26.977491 2026] [security2:error] [pid 502397:tid 502528] [client 20.104.18.15:29644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/one.php"] [unique_id "apPkvmuFRxhFZfnD0nIe3gAAAQs"]
[Sun Aug 30 03:07:26.998631 2026] [security2:error] [pid 502397:tid 502529] [client 20.104.50.220:61454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/images/gelay.php"] [unique_id "apPkvmuFRxhFZfnD0nIe7wAAAQw"]
[Sun Aug 30 03:07:27.019920 2026] [security2:error] [pid 502397:tid 502644] [client 20.48.250.41:46057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apPkv2uFRxhFZfnD0nIe_gAAAX4"]
[Sun Aug 30 03:07:27.041827 2026] [security2:error] [pid 502397:tid 502567] [client 20.196.209.81:5832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/upgrade-temp-backup/themes/admin.php"] [unique_id "apPkv2uFRxhFZfnD0nIfCwAAATI"]
[Sun Aug 30 03:07:27.071341 2026] [security2:error] [pid 502397:tid 502573] [client 20.63.81.20:4268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp-mini.php"] [unique_id "apPkv2uFRxhFZfnD0nIfHgAAATg"]
[Sun Aug 30 03:07:27.072387 2026] [security2:error] [pid 502397:tid 502527] [client 4.205.62.107:18786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/avim.php"] [unique_id "apPkv2uFRxhFZfnD0nIfHwAAAQo"]
[Sun Aug 30 03:07:27.072578 2026] [security2:error] [pid 502397:tid 502650] [client 103.153.183.69:13722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intentionalrounding.com"] [uri "/wp/index.php"] [unique_id "apPkv2uFRxhFZfnD0nIfIAAAAYQ"]
[Sun Aug 30 03:07:27.103132 2026] [security2:error] [pid 502397:tid 502530] [client 40.83.93.50:7967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/error.php"] [unique_id "apPkv2uFRxhFZfnD0nIfNwAAAQ0"]
[Sun Aug 30 03:07:27.140977 2026] [security2:error] [pid 502397:tid 502566] [client 20.48.251.3:6527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/atex1.php"] [unique_id "apPkv2uFRxhFZfnD0nIfUQAAATE"]
[Sun Aug 30 03:07:27.169851 2026] [security2:error] [pid 502397:tid 502554] [client 20.48.250.41:46023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/motu.php"] [unique_id "apPkv2uFRxhFZfnD0nIfaAAAASU"]
[Sun Aug 30 03:07:27.189855 2026] [security2:error] [pid 502397:tid 502615] [client 20.196.209.81:19084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/wp-login.php"] [unique_id "apPkv2uFRxhFZfnD0nIfSAAAAWE"]
[Sun Aug 30 03:07:27.198382 2026] [security2:error] [pid 502397:tid 502637] [client 20.63.81.20:4246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/xmini4.php"] [unique_id "apPkv2uFRxhFZfnD0nIffgAAAXc"]
[Sun Aug 30 03:07:27.204889 2026] [authz_core:error] [pid 502397:tid 502527] [client 66.249.66.64:35382] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:27.205175 2026] [authz_core:error] [pid 502397:tid 502527] [client 66.249.66.64:35382] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:27.219766 2026] [security2:error] [pid 502397:tid 502627] [client 20.104.49.130:59525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/m.php"] [unique_id "apPkv2uFRxhFZfnD0nIfkQAAAW0"]
[Sun Aug 30 03:07:27.270711 2026] [security2:error] [pid 502397:tid 502533] [client 20.104.50.220:62828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/bkv74.php"] [unique_id "apPkv2uFRxhFZfnD0nIftAAAARA"]
[Sun Aug 30 03:07:27.309748 2026] [security2:error] [pid 502397:tid 502605] [client 20.48.250.41:46071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/Ov-Simple1.php"] [unique_id "apPkv2uFRxhFZfnD0nIf1wAAAVc"]
[Sun Aug 30 03:07:27.337452 2026] [security2:error] [pid 502397:tid 502571] [client 20.63.81.20:4253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/reop3.php"] [unique_id "apPkv2uFRxhFZfnD0nIf7QAAATY"]
[Sun Aug 30 03:07:27.363207 2026] [security2:error] [pid 502397:tid 502593] [client 40.83.93.50:11510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/min.php"] [unique_id "apPkv2uFRxhFZfnD0nIgDQAAAUs"]
[Sun Aug 30 03:07:27.419981 2026] [security2:error] [pid 502397:tid 502638] [client 68.155.159.216:62285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPkv2uFRxhFZfnD0nIgMwAAAXg"]
[Sun Aug 30 03:07:27.443687 2026] [security2:error] [pid 499145:tid 499357] [client 20.48.250.41:45360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/wp-blogs.php"] [unique_id "apPkv1JNq1G5uRhTNntyggAAAFI"]
[Sun Aug 30 03:07:27.467073 2026] [security2:error] [pid 502397:tid 502631] [client 20.63.81.20:4157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp-mail.php"] [unique_id "apPkv2uFRxhFZfnD0nIgTQAAAXE"]
[Sun Aug 30 03:07:27.467761 2026] [security2:error] [pid 502397:tid 502645] [client 20.196.209.81:5873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/upgrade-temp-backup/themes/login.php"] [unique_id "apPkv2uFRxhFZfnD0nIgTgAAAX8"]
[Sun Aug 30 03:07:27.508559 2026] [authz_core:error] [pid 502397:tid 502532] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:27.508859 2026] [authz_core:error] [pid 502397:tid 502532] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:27.523860 2026] [security2:error] [pid 499145:tid 499381] [client 20.104.50.220:63551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/syg.php"] [unique_id "apPkv1JNq1G5uRhTNntyswAAAGo"]
[Sun Aug 30 03:07:27.547475 2026] [security2:error] [pid 502397:tid 502643] [client 20.104.49.130:63279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/xa.php"] [unique_id "apPkv2uFRxhFZfnD0nIghwAAAX0"]
[Sun Aug 30 03:07:27.582757 2026] [security2:error] [pid 502397:tid 502611] [client 40.83.93.50:12314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/profile.php"] [unique_id "apPkv2uFRxhFZfnD0nIgpQAAAV0"]
[Sun Aug 30 03:07:27.592541 2026] [security2:error] [pid 502397:tid 502561] [client 20.63.81.20:4145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp-conffg.php"] [unique_id "apPkv2uFRxhFZfnD0nIgrQAAASw"]
[Sun Aug 30 03:07:27.602014 2026] [security2:error] [pid 499145:tid 499316] [client 20.48.250.41:46027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/mini.php"] [unique_id "apPkv1JNq1G5uRhTNnty2gAAACk"]
[Sun Aug 30 03:07:27.653715 2026] [security2:error] [pid 502397:tid 502570] [client 20.196.209.81:19962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/aa.php"] [unique_id "apPkv2uFRxhFZfnD0nIguAAAATU"]
[Sun Aug 30 03:07:27.656768 2026] [authz_core:error] [pid 502397:tid 502615] [client 66.249.66.65:46979] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:27.657147 2026] [authz_core:error] [pid 502397:tid 502615] [client 66.249.66.65:46979] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:27.680180 2026] [lsapi:error] [pid 502397:tid 502400] [remote 81.153.132.90:47531] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.yandex.com/
[Sun Aug 30 03:07:27.680383 2026] [lsapi:error] [pid 502397:tid 502400] [remote 81.153.132.90:47531] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.yandex.com/
[Sun Aug 30 03:07:27.681802 2026] [lsapi:error] [pid 502397:tid 502400] [remote 81.153.132.90:47531] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n, referer: https://www.yandex.com/
[Sun Aug 30 03:07:27.731630 2026] [security2:error] [pid 502397:tid 502572] [client 20.63.81.20:4243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/filefuns.php"] [unique_id "apPkv2uFRxhFZfnD0nIg5AAAATc"]
[Sun Aug 30 03:07:27.733454 2026] [security2:error] [pid 502397:tid 502547] [client 68.155.159.216:60906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apPkv2uFRxhFZfnD0nIg5wAAAR4"]
[Sun Aug 30 03:07:27.738892 2026] [security2:error] [pid 502397:tid 502595] [client 20.48.250.41:46047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/amp.php"] [unique_id "apPkv2uFRxhFZfnD0nIg8QAAAU0"]
[Sun Aug 30 03:07:27.841903 2026] [security2:error] [pid 499145:tid 499309] [client 40.83.93.50:5969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/module.php"] [unique_id "apPkv1JNq1G5uRhTNntzQwAAACI"]
[Sun Aug 30 03:07:27.860378 2026] [security2:error] [pid 502397:tid 502553] [client 20.196.209.81:5699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/upgrade-temp-backup/themes/test.php"] [unique_id "apPkv2uFRxhFZfnD0nIhIwAAASQ"]
[Sun Aug 30 03:07:27.869351 2026] [security2:error] [pid 499145:tid 499388] [client 20.48.250.41:45352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/cc13.php"] [unique_id "apPkv1JNq1G5uRhTNntzTQAAAHE"]
[Sun Aug 30 03:07:27.873616 2026] [authz_core:error] [pid 499145:tid 499310] [client 216.73.216.128:45648] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:27.873896 2026] [authz_core:error] [pid 499145:tid 499310] [client 216.73.216.128:45648] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:27.880652 2026] [security2:error] [pid 499145:tid 499341] [client 20.63.81.20:4273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp-cron.php"] [unique_id "apPkv1JNq1G5uRhTNntzVAAAAEI"]
[Sun Aug 30 03:07:27.882354 2026] [security2:error] [pid 499145:tid 499301] [client 68.155.159.216:56368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apPkv1JNq1G5uRhTNntzVQAAABo"]
[Sun Aug 30 03:07:27.897898 2026] [security2:error] [pid 502397:tid 502639] [client 20.104.50.220:29596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/anu.php"] [unique_id "apPkv2uFRxhFZfnD0nIhKwAAAXk"]
[Sun Aug 30 03:07:27.934474 2026] [security2:error] [pid 502397:tid 502646] [client 20.104.50.220:17248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/xenon1337.php"] [unique_id "apPkv2uFRxhFZfnD0nIhOQAAAYA"]
[Sun Aug 30 03:07:27.940038 2026] [security2:error] [pid 502397:tid 502536] [client 68.155.159.216:54253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-includes/css/index.php"] [unique_id "apPkv2uFRxhFZfnD0nIhOwAAARM"]
[Sun Aug 30 03:07:27.949547 2026] [security2:error] [pid 502397:tid 502588] [client 20.104.50.220:6106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/67.php"] [unique_id "apPkv2uFRxhFZfnD0nIhQgAAAUc"]
[Sun Aug 30 03:07:27.958826 2026] [security2:error] [pid 502397:tid 502548] [client 20.104.50.220:27564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/base.php"] [unique_id "apPkv2uFRxhFZfnD0nIhTwAAAR8"]
[Sun Aug 30 03:07:27.966825 2026] [authz_core:error] [pid 502397:tid 502585] [client 216.73.216.128:53231] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:27.967199 2026] [authz_core:error] [pid 502397:tid 502585] [client 216.73.216.128:53231] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:27.967587 2026] [security2:error] [pid 502397:tid 502595] [client 20.48.251.3:56364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/konfig.php"] [unique_id "apPkv2uFRxhFZfnD0nIhVgAAAU0"]
[Sun Aug 30 03:07:27.974734 2026] [security2:error] [pid 502397:tid 502617] [client 20.104.18.15:14275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/birrs.php"] [unique_id "apPkv2uFRxhFZfnD0nIhXwAAAWM"]
[Sun Aug 30 03:07:27.975106 2026] [authz_core:error] [pid 502397:tid 502623] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:27.975471 2026] [authz_core:error] [pid 502397:tid 502623] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:27.982277 2026] [security2:error] [pid 502397:tid 502605] [client 4.205.62.107:36623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/fraro.php"] [unique_id "apPkv2uFRxhFZfnD0nIhZAAAAVc"]
[Sun Aug 30 03:07:27.988457 2026] [security2:error] [pid 502397:tid 502533] [client 20.104.18.15:34692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/btyuio.php"] [unique_id "apPkv2uFRxhFZfnD0nIhbAAAARA"]
[Sun Aug 30 03:07:27.994080 2026] [security2:error] [pid 502397:tid 502615] [client 4.205.62.107:64040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/mamzi.php"] [unique_id "apPkv2uFRxhFZfnD0nIhbgAAAWE"]
[Sun Aug 30 03:07:28.005131 2026] [security2:error] [pid 502397:tid 502554] [client 20.104.18.15:23506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/ws85.php"] [unique_id "apPkwGuFRxhFZfnD0nIhfAAAASU"]
[Sun Aug 30 03:07:28.008400 2026] [security2:error] [pid 502397:tid 502633] [client 4.205.62.107:22528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/apikeys.php"] [unique_id "apPkwGuFRxhFZfnD0nIhfwAAAXM"]
[Sun Aug 30 03:07:28.012013 2026] [security2:error] [pid 502397:tid 502558] [client 20.63.81.20:4153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/lock360.php"] [unique_id "apPkwGuFRxhFZfnD0nIhhQAAASk"]
[Sun Aug 30 03:07:28.013957 2026] [security2:error] [pid 502397:tid 502584] [client 20.48.250.41:46051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/aa.php"] [unique_id "apPkwGuFRxhFZfnD0nIhiQAAAUM"]
[Sun Aug 30 03:07:28.020725 2026] [security2:error] [pid 502397:tid 502614] [client 68.155.159.216:12347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-admin/images/index.php"] [unique_id "apPkwGuFRxhFZfnD0nIhiwAAAWA"]
[Sun Aug 30 03:07:28.025418 2026] [security2:error] [pid 502397:tid 502535] [client 4.205.62.107:64479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/lmfi2.php"] [unique_id "apPkwGuFRxhFZfnD0nIhkQAAARI"]
[Sun Aug 30 03:07:28.026618 2026] [security2:error] [pid 502397:tid 502581] [client 20.104.18.15:18382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/k.php"] [unique_id "apPkwGuFRxhFZfnD0nIhkgAAAUA"]
[Sun Aug 30 03:07:28.026923 2026] [security2:error] [pid 499145:tid 499389] [client 20.104.49.130:52104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/sym.php"] [unique_id "apPkwFJNq1G5uRhTNntzhAAAAHI"]
[Sun Aug 30 03:07:28.032431 2026] [security2:error] [pid 502397:tid 502639] [client 20.104.50.220:33322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/9191.php"] [unique_id "apPkwGuFRxhFZfnD0nIhlQAAAXk"]
[Sun Aug 30 03:07:28.040899 2026] [security2:error] [pid 502397:tid 502613] [client 20.104.18.15:28485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/w.php"] [unique_id "apPkwGuFRxhFZfnD0nIhnAAAAV8"]
[Sun Aug 30 03:07:28.041229 2026] [security2:error] [pid 502397:tid 502615] [client 68.155.159.216:64826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/themes.php"] [unique_id "apPkwGuFRxhFZfnD0nIhnQAAAWE"]
[Sun Aug 30 03:07:28.047762 2026] [security2:error] [pid 502397:tid 502561] [client 4.205.62.107:2946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/doc.php"] [unique_id "apPkwGuFRxhFZfnD0nIhpAAAASw"]
[Sun Aug 30 03:07:28.047771 2026] [security2:error] [pid 502397:tid 502621] [client 20.104.50.220:46461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/xcv.php"] [unique_id "apPkwGuFRxhFZfnD0nIhpQAAAWc"]
[Sun Aug 30 03:07:28.056659 2026] [security2:error] [pid 502397:tid 502593] [client 20.104.18.15:51670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/m.php"] [unique_id "apPkwGuFRxhFZfnD0nIhrQAAAUs"]
[Sun Aug 30 03:07:28.058458 2026] [security2:error] [pid 499145:tid 499315] [client 20.196.209.81:19960] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpanel.piako.store"] [uri "/c99.php"] [unique_id "apPkwFJNq1G5uRhTNntzkwAAACg"]
[Sun Aug 30 03:07:28.061636 2026] [security2:error] [pid 502397:tid 502587] [client 20.48.251.3:5079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/app.default.php"] [unique_id "apPkwGuFRxhFZfnD0nIhswAAAUY"]
[Sun Aug 30 03:07:28.092171 2026] [security2:error] [pid 499145:tid 499395] [client 40.83.93.50:18506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/sql.php"] [unique_id "apPkwFJNq1G5uRhTNntzoQAAAHg"]
[Sun Aug 30 03:07:28.093096 2026] [security2:error] [pid 502397:tid 502605] [client 20.48.251.3:55545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/tax.php"] [unique_id "apPkwGuFRxhFZfnD0nIhxgAAAVc"]
[Sun Aug 30 03:07:28.103113 2026] [security2:error] [pid 502397:tid 502569] [client 20.104.50.220:32569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/usb.php"] [unique_id "apPkwGuFRxhFZfnD0nIhzAAAATQ"]
[Sun Aug 30 03:07:28.139636 2026] [security2:error] [pid 502397:tid 502540] [client 20.104.18.15:29637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/504.php"] [unique_id "apPkwGuFRxhFZfnD0nIh5wAAARc"]
[Sun Aug 30 03:07:28.141691 2026] [security2:error] [pid 502397:tid 502644] [client 20.63.81.20:4217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp-theme.php"] [unique_id "apPkwGuFRxhFZfnD0nIh6gAAAX4"]
[Sun Aug 30 03:07:28.148466 2026] [authz_core:error] [pid 502397:tid 502583] [client 216.73.216.128:11425] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:28.148880 2026] [authz_core:error] [pid 502397:tid 502583] [client 216.73.216.128:11425] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:28.152858 2026] [security2:error] [pid 502397:tid 502612] [client 114.119.154.89:41697] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lederhosen4u.com"] [uri "/dirndl/dirndl-heidi.html"] [unique_id "apPkwGuFRxhFZfnD0nIh8wAAAV4"], referer: https://lederhosen4u.com/dirndl/dirndl-heidi.html
[Sun Aug 30 03:07:28.160947 2026] [security2:error] [pid 502397:tid 502549] [client 20.48.250.41:45986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/s1.php"] [unique_id "apPkwGuFRxhFZfnD0nIh-gAAASA"]
[Sun Aug 30 03:07:28.184833 2026] [authz_core:error] [pid 502397:tid 502547] [client 66.249.66.192:43311] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:28.185210 2026] [authz_core:error] [pid 502397:tid 502547] [client 66.249.66.192:43311] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:28.190636 2026] [security2:error] [pid 502397:tid 502648] [client 20.104.50.220:61977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/images/byps.php"] [unique_id "apPkwGuFRxhFZfnD0nIiGAAAAYI"]
[Sun Aug 30 03:07:28.270410 2026] [security2:error] [pid 502397:tid 502617] [client 20.196.209.81:4927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/upgrade-temp-backup/themes/wp-links-opml.php"] [unique_id "apPkwGuFRxhFZfnD0nIiVAAAAWM"]
[Sun Aug 30 03:07:28.278794 2026] [security2:error] [pid 502397:tid 502543] [client 20.63.81.20:4222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/2d7433/index.php"] [unique_id "apPkwGuFRxhFZfnD0nIiXgAAARo"]
[Sun Aug 30 03:07:28.298574 2026] [security2:error] [pid 502397:tid 502654] [client 20.48.250.41:45976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/0byte.php"] [unique_id "apPkwGuFRxhFZfnD0nIiagAAAYg"]
[Sun Aug 30 03:07:28.304385 2026] [security2:error] [pid 502397:tid 502569] [client 4.205.62.107:18944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/nw.php"] [unique_id "apPkwGuFRxhFZfnD0nIibwAAATQ"]
[Sun Aug 30 03:07:28.315865 2026] [security2:error] [pid 502397:tid 502642] [client 40.83.93.50:9720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/ms-files.php"] [unique_id "apPkwGuFRxhFZfnD0nIiewAAAXw"]
[Sun Aug 30 03:07:28.328628 2026] [authz_core:error] [pid 502397:tid 502527] [client 216.73.216.128:11425] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:28.328933 2026] [authz_core:error] [pid 502397:tid 502527] [client 216.73.216.128:11425] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:28.340060 2026] [security2:error] [pid 502397:tid 502625] [client 78.46.190.63:13812] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "catherinevalewines.com.au"] [uri "/index.php"] [unique_id "apPkvWuFRxhFZfnD0nIa_gAAAWs"], referer: https://catherinevalewines.com.au/
[Sun Aug 30 03:07:28.348080 2026] [security2:error] [pid 502397:tid 502532] [client 20.104.49.130:60646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/wsd.php"] [unique_id "apPkwGuFRxhFZfnD0nIilgAAAQ8"]
[Sun Aug 30 03:07:28.351974 2026] [authz_core:error] [pid 499145:tid 499322] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:28.352269 2026] [authz_core:error] [pid 499145:tid 499322] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:28.399334 2026] [security2:error] [pid 502397:tid 502585] [client 20.48.251.3:7360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/aws_sdk_settings.php"] [unique_id "apPkwGuFRxhFZfnD0nIitgAAAUQ"]
[Sun Aug 30 03:07:28.408408 2026] [security2:error] [pid 502397:tid 502638] [client 20.104.50.220:62802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/css/java.php"] [unique_id "apPkwGuFRxhFZfnD0nIiwwAAAXg"]
[Sun Aug 30 03:07:28.408421 2026] [security2:error] [pid 502397:tid 502529] [client 20.63.81.20:4223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp-login.php"] [unique_id "apPkwGuFRxhFZfnD0nIiwgAAAQw"]
[Sun Aug 30 03:07:28.426676 2026] [authz_core:error] [pid 502397:tid 502568] [client 66.249.66.203:36865] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:28.427153 2026] [authz_core:error] [pid 502397:tid 502568] [client 66.249.66.203:36865] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:28.449925 2026] [security2:error] [pid 502397:tid 502595] [client 20.48.250.41:46033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/xr.php"] [unique_id "apPkwGuFRxhFZfnD0nIi4AAAAU0"]
[Sun Aug 30 03:07:28.476136 2026] [authz_core:error] [pid 502397:tid 502546] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:28.476579 2026] [authz_core:error] [pid 502397:tid 502546] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:28.482689 2026] [security2:error] [pid 502397:tid 502594] [client 20.196.209.81:19112] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpanel.piako.store"] [uri "/c99.php"] [unique_id "apPkwGuFRxhFZfnD0nIjAgAAAUw"]
[Sun Aug 30 03:07:28.540616 2026] [security2:error] [pid 502397:tid 502634] [client 20.63.81.20:4280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/images.php"] [unique_id "apPkwGuFRxhFZfnD0nIjLgAAAXQ"]
[Sun Aug 30 03:07:28.581588 2026] [security2:error] [pid 502397:tid 502536] [client 40.83.93.50:7535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/index.bak.php"] [unique_id "apPkwGuFRxhFZfnD0nIjTAAAARM"]
[Sun Aug 30 03:07:28.591114 2026] [core:alert] [pid 499145:tid 499230] [remote 40.77.167.77:0] /home3/lordrcan/public_html/.htaccess: without matching section
[Sun Aug 30 03:07:28.605663 2026] [security2:error] [pid 502397:tid 502554] [client 20.48.250.41:46075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/h02ugyh.php"] [unique_id "apPkwGuFRxhFZfnD0nIjZgAAASU"]
[Sun Aug 30 03:07:28.662344 2026] [security2:error] [pid 502397:tid 502540] [client 20.104.50.220:42813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/contactz.php"] [unique_id "apPkwGuFRxhFZfnD0nIjcAAAARc"]
[Sun Aug 30 03:07:28.668764 2026] [security2:error] [pid 502397:tid 502633] [client 20.63.81.20:4375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/ops.php"] [unique_id "apPkwGuFRxhFZfnD0nIjcwAAAXM"]
[Sun Aug 30 03:07:28.672899 2026] [security2:error] [pid 502397:tid 502572] [client 20.196.209.81:4868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/upgrade-temp-backup/themes/wp-settings.php"] [unique_id "apPkwGuFRxhFZfnD0nIjdAAAATc"]
[Sun Aug 30 03:07:28.748794 2026] [security2:error] [pid 502397:tid 502597] [client 20.48.250.41:46063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/xxw.php"] [unique_id "apPkwGuFRxhFZfnD0nIjsgAAAU8"]
[Sun Aug 30 03:07:28.750272 2026] [security2:error] [pid 502397:tid 502630] [client 68.155.159.216:61685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-includes/content.php"] [unique_id "apPkwGuFRxhFZfnD0nIjtQAAAXA"]
[Sun Aug 30 03:07:28.754724 2026] [proxy_http:error] [pid 502397:tid 502572] (20014)Internal error (specific information not available): [client 34.125.55.247:2014] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:28.754736 2026] [proxy:error] [pid 502397:tid 502572] [client 34.125.55.247:2014] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/docker-compose.yml
[Sun Aug 30 03:07:28.754990 2026] [security2:error] [pid 502397:tid 502624] [client 34.125.55.247:2092] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.engaginggoddaily.com"] [uri "/v1/graphql"] [unique_id "apPkwGuFRxhFZfnD0nIjvQAAAWo"]
[Sun Aug 30 03:07:28.757090 2026] [security2:error] [pid 502397:tid 502603] [client 34.125.55.247:2150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/.hermes/.env"] [unique_id "apPkwGuFRxhFZfnD0nIjwAAAAVU"]
[Sun Aug 30 03:07:28.757172 2026] [security2:error] [pid 502397:tid 502603] [client 34.125.55.247:2150] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/.hermes/.env"] [unique_id "apPkwGuFRxhFZfnD0nIjwAAAAVU"]
[Sun Aug 30 03:07:28.763698 2026] [security2:error] [pid 502397:tid 502598] [client 34.125.55.247:2218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/.openclaw/.env"] [unique_id "apPkwGuFRxhFZfnD0nIj1AAAAVA"]
[Sun Aug 30 03:07:28.790726 2026] [security2:error] [pid 502397:tid 502556] [client 40.83.93.50:9724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/news-portal/error.php"] [unique_id "apPkwGuFRxhFZfnD0nIj5AAAASc"]
[Sun Aug 30 03:07:28.795930 2026] [security2:error] [pid 502397:tid 502542] [client 20.63.81.20:4232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPkwGuFRxhFZfnD0nIj5gAAARk"]
[Sun Aug 30 03:07:28.868063 2026] [security2:error] [pid 502397:tid 502540] [client 216.73.216.128:11425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts2/updateconf"] [unique_id "apPkwGuFRxhFZfnD0nIkCAAAARc"]
[Sun Aug 30 03:07:28.877246 2026] [proxy_http:error] [pid 502397:tid 502606] (20014)Internal error (specific information not available): [client 34.125.55.247:2100] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:28.877277 2026] [proxy:error] [pid 502397:tid 502606] [client 34.125.55.247:2100] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/graphql/console
[Sun Aug 30 03:07:28.883465 2026] [proxy_http:error] [pid 502397:tid 502572] (20014)Internal error (specific information not available): [client 34.125.55.247:2014] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:28.883483 2026] [proxy:error] [pid 502397:tid 502572] [client 34.125.55.247:2014] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml
[Sun Aug 30 03:07:28.889055 2026] [proxy_http:error] [pid 502397:tid 502559] (20014)Internal error (specific information not available): [client 34.125.55.247:2068] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:28.889074 2026] [proxy:error] [pid 502397:tid 502559] [client 34.125.55.247:2068] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/graphql
[Sun Aug 30 03:07:28.892370 2026] [security2:error] [pid 502397:tid 502563] [client 20.48.250.41:46046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/bolt.php"] [unique_id "apPkwGuFRxhFZfnD0nIkEAAAAS4"]
[Sun Aug 30 03:07:28.896322 2026] [proxy_http:error] [pid 502397:tid 502632] (20014)Internal error (specific information not available): [client 34.125.55.247:2144] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:28.896335 2026] [proxy:error] [pid 502397:tid 502632] [client 34.125.55.247:2144] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.cursor/mcp.json
[Sun Aug 30 03:07:28.902440 2026] [security2:error] [pid 502397:tid 502652] [client 68.155.159.216:61376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apPkwGuFRxhFZfnD0nIkEwAAAYY"]
[Sun Aug 30 03:07:28.903243 2026] [proxy_http:error] [pid 502397:tid 502602] (20014)Internal error (specific information not available): [client 34.125.55.247:2084] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:28.903261 2026] [proxy:error] [pid 502397:tid 502602] [client 34.125.55.247:2084] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/api/graphql
[Sun Aug 30 03:07:28.909847 2026] [proxy_http:error] [pid 502397:tid 502550] (20014)Internal error (specific information not available): [client 34.125.55.247:2164] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:28.909862 2026] [proxy:error] [pid 502397:tid 502550] [client 34.125.55.247:2164] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.hermes/config.yaml
[Sun Aug 30 03:07:28.918037 2026] [proxy_http:error] [pid 502397:tid 502641] (20014)Internal error (specific information not available): [client 34.125.55.247:2138] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:28.918053 2026] [proxy:error] [pid 502397:tid 502641] [client 34.125.55.247:2138] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.codex/config.toml
[Sun Aug 30 03:07:28.924854 2026] [proxy_http:error] [pid 502397:tid 502585] (20014)Internal error (specific information not available): [client 34.125.55.247:2268] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:28.924866 2026] [proxy:error] [pid 502397:tid 502585] [client 34.125.55.247:2268] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/assets/env.js
[Sun Aug 30 03:07:28.931446 2026] [proxy_http:error] [pid 502397:tid 502565] (20014)Internal error (specific information not available): [client 34.125.55.247:2180] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:28.931463 2026] [proxy:error] [pid 502397:tid 502565] [client 34.125.55.247:2180] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.config/anthropic/credentials/default.json
[Sun Aug 30 03:07:28.937731 2026] [proxy_http:error] [pid 502397:tid 502642] (20014)Internal error (specific information not available): [client 34.125.55.247:2246] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:28.937733 2026] [security2:error] [pid 499145:tid 499314] [client 20.63.81.20:4119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPkwFJNq1G5uRhTNnt02wAAACc"]
[Sun Aug 30 03:07:28.937748 2026] [proxy:error] [pid 502397:tid 502642] [client 34.125.55.247:2246] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.mcp.json
[Sun Aug 30 03:07:28.944132 2026] [proxy_http:error] [pid 502397:tid 502653] (20014)Internal error (specific information not available): [client 34.125.55.247:2058] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:28.944147 2026] [proxy:error] [pid 502397:tid 502653] [client 34.125.55.247:2058] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/actuator/mappings
[Sun Aug 30 03:07:28.950663 2026] [proxy_http:error] [pid 502397:tid 502639] (20014)Internal error (specific information not available): [client 34.125.55.247:2290] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:28.950685 2026] [proxy:error] [pid 502397:tid 502639] [client 34.125.55.247:2290] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/health
[Sun Aug 30 03:07:28.958255 2026] [proxy_http:error] [pid 502397:tid 502534] (20014)Internal error (specific information not available): [client 34.125.55.247:2322] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:28.958275 2026] [proxy:error] [pid 502397:tid 502534] [client 34.125.55.247:2322] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/awsConfig.js
[Sun Aug 30 03:07:28.969605 2026] [security2:error] [pid 502397:tid 502559] [client 34.125.55.247:2068] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "502"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/502.shtml"] [unique_id "apPkwGuFRxhFZfnD0nIjvwAAASo"]
[Sun Aug 30 03:07:28.981544 2026] [security2:error] [pid 502397:tid 502628] [client 20.196.209.81:20350] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpanel.piako.store"] [uri "/c99.php"] [unique_id "apPkwGuFRxhFZfnD0nIkQQAAAW4"]
[Sun Aug 30 03:07:28.982994 2026] [authz_core:error] [pid 502397:tid 502605] [client 66.249.66.192:43311] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:28.983299 2026] [authz_core:error] [pid 502397:tid 502605] [client 66.249.66.192:43311] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:28.988383 2026] [security2:error] [pid 502397:tid 502568] [client 68.155.159.216:11260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/goat1.php"] [unique_id "apPkwGuFRxhFZfnD0nIkSgAAATM"]
[Sun Aug 30 03:07:28.995960 2026] [authz_core:error] [pid 502397:tid 502573] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fjson-c
[Sun Aug 30 03:07:28.996388 2026] [authz_core:error] [pid 502397:tid 502573] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fjson-c
[Sun Aug 30 03:07:29.038137 2026] [security2:error] [pid 499145:tid 499318] [client 20.48.250.41:45919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/rtx.php"] [unique_id "apPkwVJNq1G5uRhTNnt1BQAAACs"]
[Sun Aug 30 03:07:29.039768 2026] [security2:error] [pid 499145:tid 499302] [client 20.104.50.220:29588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/loip2.php"] [unique_id "apPkwVJNq1G5uRhTNnt1BwAAABs"]
[Sun Aug 30 03:07:29.061252 2026] [security2:error] [pid 502397:tid 502545] [client 68.155.159.216:54214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apPkwWuFRxhFZfnD0nIkggAAARw"]
[Sun Aug 30 03:07:29.066053 2026] [security2:error] [pid 502397:tid 502594] [client 40.83.93.50:7514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/log.php"] [unique_id "apPkwWuFRxhFZfnD0nIkiAAAAUw"]
[Sun Aug 30 03:07:29.069264 2026] [security2:error] [pid 502397:tid 502599] [client 20.63.81.20:4166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/about.php"] [unique_id "apPkwWuFRxhFZfnD0nIkigAAAVE"]
[Sun Aug 30 03:07:29.076884 2026] [security2:error] [pid 502397:tid 502536] [client 20.104.50.220:17326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/test11.php"] [unique_id "apPkwWuFRxhFZfnD0nIkjgAAARM"]
[Sun Aug 30 03:07:29.095577 2026] [security2:error] [pid 502397:tid 502562] [client 20.104.50.220:27248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/Module.php"] [unique_id "apPkwWuFRxhFZfnD0nIkogAAAS0"]
[Sun Aug 30 03:07:29.101034 2026] [security2:error] [pid 502397:tid 502623] [client 20.104.50.220:5924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/68.php"] [unique_id "apPkwWuFRxhFZfnD0nIkpgAAAWk"]
[Sun Aug 30 03:07:29.106232 2026] [security2:error] [pid 502397:tid 502600] [client 20.48.251.3:13378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/paths.php"] [unique_id "apPkwWuFRxhFZfnD0nIkrAAAAVI"]
[Sun Aug 30 03:07:29.112316 2026] [autoindex:error] [pid 502397:tid 502613] [client 20.196.209.81:13727] AH01276: Cannot serve directory /home4/devstol/public_html/thelakewoodshuttle/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:07:29.132573 2026] [security2:error] [pid 502397:tid 502588] [client 68.155.159.216:12326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-includes/index.php"] [unique_id "apPkwWuFRxhFZfnD0nIktgAAAUc"]
[Sun Aug 30 03:07:29.132690 2026] [security2:error] [pid 502397:tid 502604] [client 20.104.18.15:34633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/dehnl.php"] [unique_id "apPkwWuFRxhFZfnD0nIktQAAAVY"]
[Sun Aug 30 03:07:29.134089 2026] [security2:error] [pid 502397:tid 502545] [client 4.205.62.107:39132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/public/rip.php.php"] [unique_id "apPkwWuFRxhFZfnD0nIktwAAARw"]
[Sun Aug 30 03:07:29.149524 2026] [security2:error] [pid 502397:tid 502579] [client 68.155.159.216:63977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-mail.php"] [unique_id "apPkwWuFRxhFZfnD0nIkxAAAAT4"]
[Sun Aug 30 03:07:29.159107 2026] [security2:error] [pid 502397:tid 502555] [client 20.104.18.15:13744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/sss.php"] [unique_id "apPkwWuFRxhFZfnD0nIkzAAAASY"]
[Sun Aug 30 03:07:29.161441 2026] [security2:error] [pid 502397:tid 502531] [client 4.205.62.107:62454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/motu.php"] [unique_id "apPkwWuFRxhFZfnD0nIkzwAAAQ4"]
[Sun Aug 30 03:07:29.166368 2026] [security2:error] [pid 502397:tid 502586] [client 4.205.62.107:64640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/wpver.php"] [unique_id "apPkwWuFRxhFZfnD0nIk0QAAAUU"]
[Sun Aug 30 03:07:29.172931 2026] [security2:error] [pid 502397:tid 502633] [client 20.104.18.15:18424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/82.php"] [unique_id "apPkwWuFRxhFZfnD0nIk1wAAAXM"]
[Sun Aug 30 03:07:29.175388 2026] [security2:error] [pid 502397:tid 502563] [client 20.48.250.41:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/ckk.php"] [unique_id "apPkwWuFRxhFZfnD0nIk2gAAAS4"]
[Sun Aug 30 03:07:29.177044 2026] [security2:error] [pid 502397:tid 502638] [client 20.104.18.15:28499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/ccc.php"] [unique_id "apPkwWuFRxhFZfnD0nIk2wAAAXg"]
[Sun Aug 30 03:07:29.187604 2026] [security2:error] [pid 502397:tid 502626] [client 20.104.18.15:23516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/ffs.php"] [unique_id "apPkwWuFRxhFZfnD0nIk6AAAAWw"]
[Sun Aug 30 03:07:29.188326 2026] [security2:error] [pid 502397:tid 502544] [client 20.104.50.220:46430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/xl.php"] [unique_id "apPkwWuFRxhFZfnD0nIk6gAAARs"]
[Sun Aug 30 03:07:29.188731 2026] [security2:error] [pid 502397:tid 502613] [client 20.104.50.220:32789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/kjtpoad.php"] [unique_id "apPkwWuFRxhFZfnD0nIk6wAAAV8"]
[Sun Aug 30 03:07:29.198517 2026] [security2:error] [pid 502397:tid 502531] [client 20.104.49.130:48000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/133.php"] [unique_id "apPkwWuFRxhFZfnD0nIk_AAAAQ4"]
[Sun Aug 30 03:07:29.198544 2026] [security2:error] [pid 502397:tid 502628] [client 20.63.81.20:4102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/admin.php/admin.php"] [unique_id "apPkwWuFRxhFZfnD0nIk_QAAAW4"]
[Sun Aug 30 03:07:29.202363 2026] [security2:error] [pid 499145:tid 499378] [client 20.104.18.15:51601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/fling.php"] [unique_id "apPkwVJNq1G5uRhTNnt1RAAAAGc"]
[Sun Aug 30 03:07:29.202678 2026] [security2:error] [pid 502397:tid 502607] [client 4.205.62.107:36030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/thui.php"] [unique_id "apPkwWuFRxhFZfnD0nIlAAAAAVk"]
[Sun Aug 30 03:07:29.210204 2026] [security2:error] [pid 502397:tid 502580] [client 20.48.251.3:5082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/app_local.php"] [unique_id "apPkwWuFRxhFZfnD0nIlAwAAAT8"]
[Sun Aug 30 03:07:29.231275 2026] [security2:error] [pid 502397:tid 502578] [client 20.48.251.3:49937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPkwWuFRxhFZfnD0nIlCwAAAT0"]
[Sun Aug 30 03:07:29.239561 2026] [authz_core:error] [pid 499145:tid 499340] [client 216.73.216.128:45648] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:29.240006 2026] [authz_core:error] [pid 499145:tid 499340] [client 216.73.216.128:45648] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:29.251506 2026] [security2:error] [pid 502397:tid 502643] [client 20.196.209.81:13727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/upgrade/about.php"] [unique_id "apPkwWuFRxhFZfnD0nIlHAAAAX0"]
[Sun Aug 30 03:07:29.253315 2026] [security2:error] [pid 502397:tid 502635] [client 40.83.93.50:9714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/nvt/includes/plugins/wp-blog-header.php"] [unique_id "apPkwWuFRxhFZfnD0nIlIAAAAXU"]
[Sun Aug 30 03:07:29.253363 2026] [security2:error] [pid 502397:tid 502556] [client 4.205.62.107:2962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/classsmtps.php"] [unique_id "apPkwWuFRxhFZfnD0nIlIQAAASc"]
[Sun Aug 30 03:07:29.277737 2026] [security2:error] [pid 502397:tid 502529] [client 20.104.18.15:29151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/ano.php"] [unique_id "apPkwWuFRxhFZfnD0nIlMgAAAQw"]
[Sun Aug 30 03:07:29.335126 2026] [security2:error] [pid 502397:tid 502583] [client 20.104.50.220:32264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/usr.php"] [unique_id "apPkwWuFRxhFZfnD0nIlXwAAAUI"]
[Sun Aug 30 03:07:29.335413 2026] [security2:error] [pid 502397:tid 502573] [client 20.63.81.20:4125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/media.php"] [unique_id "apPkwWuFRxhFZfnD0nIlYQAAATg"]
[Sun Aug 30 03:07:29.358601 2026] [security2:error] [pid 502397:tid 502643] [client 20.104.50.220:61411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/images/bypass.php"] [unique_id "apPkwWuFRxhFZfnD0nIlewAAAX0"]
[Sun Aug 30 03:07:29.363593 2026] [security2:error] [pid 499145:tid 499289] [client 20.48.250.41:46010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.forensictoxicology.co.uk"] [uri "/R57.php"] [unique_id "apPkwVJNq1G5uRhTNnt1jwAAAA4"]
[Sun Aug 30 03:07:29.377711 2026] [authz_core:error] [pid 502397:tid 502540] [client 66.249.66.71:56631] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:29.378181 2026] [authz_core:error] [pid 502397:tid 502540] [client 66.249.66.71:56631] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:29.384924 2026] [security2:error] [pid 502397:tid 502651] [client 20.196.209.81:1988] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpanel.piako.store"] [uri "/c99.php"] [unique_id "apPkwWuFRxhFZfnD0nIlggAAAYU"]
[Sun Aug 30 03:07:29.400717 2026] [security2:error] [pid 502397:tid 502616] [client 91.224.92.19:58781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.92.224.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "xn--b3cb4aatcg5ckn7hg1ewed2ivab2inmngh7e.com"] [uri "/wp-login.php"] [unique_id "apPkwWuFRxhFZfnD0nIliAAAAWI"]
[Sun Aug 30 03:07:29.408888 2026] [security2:error] [pid 502397:tid 502542] [client 178.16.55.109:49936] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "neilgclark.com"] [uri "/index.php"] [unique_id "apPkwWuFRxhFZfnD0nIlowAAARk"]
[Sun Aug 30 03:07:29.442002 2026] [lsapi:error] [pid 502397:tid 502423] [remote 81.153.132.90:54747] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:07:29.442135 2026] [security2:error] [pid 502397:tid 502563] [client 4.205.62.107:18779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/product.php"] [unique_id "apPkwWuFRxhFZfnD0nIluwAAAS4"]
[Sun Aug 30 03:07:29.442166 2026] [lsapi:error] [pid 502397:tid 502423] [remote 81.153.132.90:54747] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:07:29.443612 2026] [lsapi:error] [pid 502397:tid 502423] [remote 81.153.132.90:54747] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:07:29.459122 2026] [authz_core:error] [pid 502397:tid 502622] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fjson-c
[Sun Aug 30 03:07:29.459390 2026] [authz_core:error] [pid 502397:tid 502622] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fjson-c
[Sun Aug 30 03:07:29.463295 2026] [security2:error] [pid 502397:tid 502625] [client 20.63.81.20:4234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/mac.php"] [unique_id "apPkwWuFRxhFZfnD0nIlxwAAAWs"]
[Sun Aug 30 03:07:29.477159 2026] [authz_core:error] [pid 502397:tid 502593] [client 66.249.66.35:35040] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:29.477560 2026] [authz_core:error] [pid 502397:tid 502593] [client 66.249.66.35:35040] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:29.533738 2026] [security2:error] [pid 502397:tid 502621] [client 20.48.251.3:7016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/setup-config.php"] [unique_id "apPkwWuFRxhFZfnD0nImBwAAAWc"]
[Sun Aug 30 03:07:29.577977 2026] [security2:error] [pid 502397:tid 502573] [client 20.104.50.220:29181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/edit-video.php"] [unique_id "apPkwWuFRxhFZfnD0nImLAAAATg"]
[Sun Aug 30 03:07:29.589271 2026] [security2:error] [pid 502397:tid 502558] [client 20.63.81.20:4182] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/1.php"] [unique_id "apPkwWuFRxhFZfnD0nImPQAAASk"]
[Sun Aug 30 03:07:29.589353 2026] [security2:error] [pid 502397:tid 502558] [client 20.63.81.20:4182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/1.php"] [unique_id "apPkwWuFRxhFZfnD0nImPQAAASk"]
[Sun Aug 30 03:07:29.595581 2026] [security2:error] [pid 499145:tid 499279] [client 216.73.216.128:45648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/nameserverconfig"] [unique_id "apPkwVJNq1G5uRhTNnt1-gAAAAQ"]
[Sun Aug 30 03:07:29.605111 2026] [security2:error] [pid 499145:tid 499382] [client 40.83.93.50:12300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/bak.php"] [unique_id "apPkwVJNq1G5uRhTNnt2AQAAAGs"]
[Sun Aug 30 03:07:29.644532 2026] [security2:error] [pid 499145:tid 499392] [client 20.196.209.81:5700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.lakewoodshuttle.deevosdesigns.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "apPkwVJNq1G5uRhTNnt2BwAAAHU"]
[Sun Aug 30 03:07:29.692423 2026] [authz_core:error] [pid 502397:tid 502568] [client 216.73.216.128:53231] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:29.692715 2026] [authz_core:error] [pid 502397:tid 502568] [client 216.73.216.128:53231] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:29.739507 2026] [security2:error] [pid 502397:tid 502606] [client 20.63.81.20:4135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/classwithtostring.php"] [unique_id "apPkwWuFRxhFZfnD0nImewAAAVg"]
[Sun Aug 30 03:07:29.751467 2026] [security2:error] [pid 502397:tid 502610] [client 40.83.93.50:5729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/oceanwp/sass/components/plugins/panel.php"] [unique_id "apPkwWuFRxhFZfnD0nImiAAAAVw"]
[Sun Aug 30 03:07:29.762189 2026] [security2:error] [pid 502397:tid 502641] [client 91.224.92.19:58951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.92.224.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "xn--b3cb4aatcg5ckn7hg1ewed2ivab2inmngh7e.com"] [uri "/wp-login.php"] [unique_id "apPkwWuFRxhFZfnD0nImjQAAAXs"]
[Sun Aug 30 03:07:29.779343 2026] [security2:error] [pid 499145:tid 499377] [client 20.196.209.81:19962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/test1.php"] [unique_id "apPkwVJNq1G5uRhTNnt2PgAAAGY"]
[Sun Aug 30 03:07:29.788981 2026] [security2:error] [pid 502397:tid 502582] [client 20.151.200.44:47089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/t00l.php"] [unique_id "apPkwWuFRxhFZfnD0nImmAAAAUE"]
[Sun Aug 30 03:07:29.799763 2026] [security2:error] [pid 502397:tid 502645] [client 20.104.50.220:51568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/orange.php"] [unique_id "apPkwWuFRxhFZfnD0nImnAAAAX8"]
[Sun Aug 30 03:07:29.827021 2026] [authz_core:error] [pid 499145:tid 499374] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:29.827312 2026] [authz_core:error] [pid 499145:tid 499374] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:29.871565 2026] [security2:error] [pid 499145:tid 499298] [client 20.63.81.20:4209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp-ws68.php"] [unique_id "apPkwVJNq1G5uRhTNnt2XwAAABc"]
[Sun Aug 30 03:07:29.874602 2026] [security2:error] [pid 502397:tid 502596] [client 68.155.159.216:62325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-admin/css/index.php"] [unique_id "apPkwWuFRxhFZfnD0nImuwAAAU4"]
[Sun Aug 30 03:07:29.877532 2026] [authz_core:error] [pid 502397:tid 502634] [client 216.73.216.128:30842] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:29.878000 2026] [authz_core:error] [pid 502397:tid 502634] [client 216.73.216.128:30842] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:29.945284 2026] [security2:error] [pid 502397:tid 502635] [client 114.119.148.155:24087] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hopperpsychology.com"] [uri "/psychotherapy"] [unique_id "apPkwWuFRxhFZfnD0nIm1wAAAXU"], referer: https://hopperpsychology.com/psychotherapy
[Sun Aug 30 03:07:29.988865 2026] [authz_core:error] [pid 502397:tid 502550] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:29.989201 2026] [authz_core:error] [pid 502397:tid 502550] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:30.004439 2026] [security2:error] [pid 502397:tid 502597] [client 20.63.81.20:4225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/simple.php"] [unique_id "apPkwmuFRxhFZfnD0nInAAAAAU8"]
[Sun Aug 30 03:07:30.099423 2026] [security2:error] [pid 502397:tid 502433] [remote 94.154.172.8:36300] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "cityliferealestateagent.com"] [uri "/wp-content/plugins/pods/readme.txt"] [unique_id "apPkwmuFRxhFZfnD0nInPAABMiM"]
[Sun Aug 30 03:07:30.099730 2026] [security2:error] [pid 502397:tid 502639] [client 68.155.159.216:56397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apPkwmuFRxhFZfnD0nInOwAAAXk"]
[Sun Aug 30 03:07:30.102427 2026] [security2:error] [pid 499145:tid 499315] [client 68.155.159.216:61380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/dropdown.php"] [unique_id "apPkwlJNq1G5uRhTNnt2qQAAACg"]
[Sun Aug 30 03:07:30.121969 2026] [security2:error] [pid 502397:tid 502598] [client 178.16.55.109:51487] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "neilgclark.com"] [uri "/index.php"] [unique_id "apPkwmuFRxhFZfnD0nInRgAAAVA"]
[Sun Aug 30 03:07:30.150063 2026] [security2:error] [pid 502397:tid 502563] [client 20.63.81.20:4277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/aaa.php"] [unique_id "apPkwmuFRxhFZfnD0nInVQAAAS4"]
[Sun Aug 30 03:07:30.153229 2026] [security2:error] [pid 502397:tid 502650] [client 40.83.93.50:12304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/pages.php"] [unique_id "apPkwmuFRxhFZfnD0nInWwAAAYQ"]
[Sun Aug 30 03:07:30.171252 2026] [security2:error] [pid 502397:tid 502582] [client 20.104.49.130:60696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/one.php"] [unique_id "apPkwmuFRxhFZfnD0nInbwAAAUE"]
[Sun Aug 30 03:07:30.206344 2026] [security2:error] [pid 502397:tid 502561] [client 20.196.209.81:20314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/data.php"] [unique_id "apPkwmuFRxhFZfnD0nInhgAAASw"]
[Sun Aug 30 03:07:30.212408 2026] [security2:error] [pid 499145:tid 499400] [client 68.155.159.216:55132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-content/cong.php"] [unique_id "apPkwlJNq1G5uRhTNnt21gAAAH0"]
[Sun Aug 30 03:07:30.215545 2026] [security2:error] [pid 502397:tid 502643] [client 20.104.50.220:16704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/koala.php"] [unique_id "apPkwmuFRxhFZfnD0nInjAAAAX0"]
[Sun Aug 30 03:07:30.219928 2026] [security2:error] [pid 502397:tid 502527] [client 40.83.93.50:9717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/options.php"] [unique_id "apPkwmuFRxhFZfnD0nInjQAAAQo"]
[Sun Aug 30 03:07:30.219929 2026] [security2:error] [pid 499145:tid 499354] [client 20.104.50.220:62846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/json.php"] [unique_id "apPkwlJNq1G5uRhTNnt21wAAAE8"]
[Sun Aug 30 03:07:30.233763 2026] [security2:error] [pid 502397:tid 502577] [client 20.104.50.220:27109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/Query.php"] [unique_id "apPkwmuFRxhFZfnD0nInlAAAATw"]
[Sun Aug 30 03:07:30.237714 2026] [security2:error] [pid 502397:tid 502608] [client 20.48.251.3:33292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/olfclass.php"] [unique_id "apPkwmuFRxhFZfnD0nInmwAAAVo"]
[Sun Aug 30 03:07:30.254449 2026] [security2:error] [pid 499145:tid 499340] [client 20.104.50.220:5477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/66.php"] [unique_id "apPkwlJNq1G5uRhTNnt27QAAAEE"]
[Sun Aug 30 03:07:30.264713 2026] [security2:error] [pid 502397:tid 502596] [client 68.155.159.216:63939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/cgi-bin/index.php"] [unique_id "apPkwmuFRxhFZfnD0nInvwAAAU4"]
[Sun Aug 30 03:07:30.270141 2026] [security2:error] [pid 502397:tid 502584] [client 4.205.62.107:62042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/environment.php"] [unique_id "apPkwmuFRxhFZfnD0nInxQAAAUM"]
[Sun Aug 30 03:07:30.291286 2026] [security2:error] [pid 502397:tid 502595] [client 20.104.18.15:34787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/zoo2.php"] [unique_id "apPkwmuFRxhFZfnD0nIn1AAAAU0"]
[Sun Aug 30 03:07:30.293149 2026] [authz_core:error] [pid 502397:tid 502652] [client 66.249.66.77:41456] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:30.293594 2026] [authz_core:error] [pid 502397:tid 502652] [client 66.249.66.77:41456] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:30.295660 2026] [security2:error] [pid 502397:tid 502568] [client 68.155.159.216:65513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/mah.php"] [unique_id "apPkwmuFRxhFZfnD0nIn1wAAATM"]
[Sun Aug 30 03:07:30.300275 2026] [security2:error] [pid 502397:tid 502632] [client 4.205.62.107:54418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/public/mah.php.php"] [unique_id "apPkwmuFRxhFZfnD0nIn3QAAAXI"]
[Sun Aug 30 03:07:30.302069 2026] [security2:error] [pid 502397:tid 502553] [client 4.205.62.107:64651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/ah25.php"] [unique_id "apPkwmuFRxhFZfnD0nIn3wAAASQ"]
[Sun Aug 30 03:07:30.317810 2026] [security2:error] [pid 499145:tid 499324] [client 20.104.18.15:28497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/file15.php"] [unique_id "apPkwlJNq1G5uRhTNnt3DwAAADE"]
[Sun Aug 30 03:07:30.323744 2026] [security2:error] [pid 502397:tid 502642] [client 20.104.18.15:18406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/dex.php"] [unique_id "apPkwmuFRxhFZfnD0nIn5gAAAXw"]
[Sun Aug 30 03:07:30.324796 2026] [security2:error] [pid 502397:tid 502598] [client 20.104.18.15:23489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/nano.php"] [unique_id "apPkwmuFRxhFZfnD0nIn6QAAAVA"]
[Sun Aug 30 03:07:30.325857 2026] [security2:error] [pid 502397:tid 502573] [client 20.104.50.220:32856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/blackcat.php"] [unique_id "apPkwmuFRxhFZfnD0nIn6wAAATg"]
[Sun Aug 30 03:07:30.326487 2026] [security2:error] [pid 502397:tid 502531] [client 20.104.50.220:46204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/xleet.php"] [unique_id "apPkwmuFRxhFZfnD0nIn7AAAAQ4"]
[Sun Aug 30 03:07:30.331798 2026] [authz_core:error] [pid 502397:tid 502637] [client 66.249.66.45:63157] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:30.332111 2026] [authz_core:error] [pid 502397:tid 502637] [client 66.249.66.45:63157] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:30.342610 2026] [security2:error] [pid 502397:tid 502624] [client 20.48.251.3:4730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/ws62.php"] [unique_id "apPkwmuFRxhFZfnD0nIn_AAAAWo"]
[Sun Aug 30 03:07:30.342678 2026] [security2:error] [pid 502397:tid 502625] [client 20.104.18.15:51649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/btyuio.php"] [unique_id "apPkwmuFRxhFZfnD0nIn_QAAAWs"]
[Sun Aug 30 03:07:30.357103 2026] [security2:error] [pid 502397:tid 502577] [client 4.205.62.107:36003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/lala.php"] [unique_id "apPkwmuFRxhFZfnD0nIoCQAAATw"]
[Sun Aug 30 03:07:30.382926 2026] [security2:error] [pid 502397:tid 502556] [client 20.48.251.3:50023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPkwmuFRxhFZfnD0nIoFAAAASc"]
[Sun Aug 30 03:07:30.386662 2026] [security2:error] [pid 502397:tid 502550] [client 4.205.62.107:2958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/cache-compat.php"] [unique_id "apPkwmuFRxhFZfnD0nIoFwAAASE"]
[Sun Aug 30 03:07:30.416354 2026] [security2:error] [pid 502397:tid 502561] [client 20.104.18.15:29158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/mac.php"] [unique_id "apPkwmuFRxhFZfnD0nIoNAAAASw"]
[Sun Aug 30 03:07:30.438218 2026] [security2:error] [pid 502397:tid 502622] [client 20.104.18.15:14303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/wp-includes/ID3/moon.php"] [unique_id "apPkwmuFRxhFZfnD0nIoQAAAAWg"]
[Sun Aug 30 03:07:30.438364 2026] [security2:error] [pid 499145:tid 499382] [client 20.63.81.20:4131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/shiny.php"] [unique_id "apPkwlJNq1G5uRhTNnt3VAAAAGs"]
[Sun Aug 30 03:07:30.458059 2026] [authz_core:error] [pid 502397:tid 502617] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:30.458481 2026] [authz_core:error] [pid 502397:tid 502617] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:30.512382 2026] [security2:error] [pid 502397:tid 502591] [client 20.151.200.44:55617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/log.php"] [unique_id "apPkwmuFRxhFZfnD0nIofgAAAUk"]
[Sun Aug 30 03:07:30.523643 2026] [security2:error] [pid 502397:tid 502639] [client 20.104.50.220:61671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/images/x.php"] [unique_id "apPkwmuFRxhFZfnD0nIoiAAAAXk"]
[Sun Aug 30 03:07:30.566698 2026] [security2:error] [pid 502397:tid 502571] [client 20.63.81.20:4388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/goods.php"] [unique_id "apPkwmuFRxhFZfnD0nIorAAAATY"]
[Sun Aug 30 03:07:30.581900 2026] [security2:error] [pid 502397:tid 502645] [client 4.205.62.107:18969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/fun.php"] [unique_id "apPkwmuFRxhFZfnD0nIouAAAAX8"]
[Sun Aug 30 03:07:30.616160 2026] [security2:error] [pid 502397:tid 502568] [client 216.73.216.128:63339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPkwmuFRxhFZfnD0nIoyQAAATM"]
[Sun Aug 30 03:07:30.621441 2026] [security2:error] [pid 502397:tid 502579] [client 114.119.132.207:44209] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jeanbooknerdmedia.com"] [uri "/product-category/merchandise/"] [unique_id "apPkwmuFRxhFZfnD0nIoywAAAT4"], referer: https://jeanbooknerdmedia.com/product/fertility-doll-keychain
[Sun Aug 30 03:07:30.640970 2026] [security2:error] [pid 499145:tid 499394] [client 40.83.93.50:18539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/albin.php"] [unique_id "apPkwlJNq1G5uRhTNnt3qgAAAHc"]
[Sun Aug 30 03:07:30.688221 2026] [security2:error] [pid 499145:tid 499363] [client 20.196.209.81:19940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/classwithtostring.php"] [unique_id "apPkwlJNq1G5uRhTNnt3tQAAAFg"]
[Sun Aug 30 03:07:30.694820 2026] [security2:error] [pid 502397:tid 502549] [client 40.83.93.50:9716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/panel.php"] [unique_id "apPkwmuFRxhFZfnD0nIo2AAAASA"]
[Sun Aug 30 03:07:30.697880 2026] [security2:error] [pid 502397:tid 502596] [client 20.63.81.20:4110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/000.php/index.php"] [unique_id "apPkwmuFRxhFZfnD0nIo2gAAAU4"]
[Sun Aug 30 03:07:30.729368 2026] [security2:error] [pid 502397:tid 502574] [client 20.104.50.220:29272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/.well-known/up.php"] [unique_id "apPkwmuFRxhFZfnD0nIo-AAAATk"]
[Sun Aug 30 03:07:30.777454 2026] [security2:error] [pid 502397:tid 502578] [client 20.104.49.130:59546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/abcd.php"] [unique_id "apPkwmuFRxhFZfnD0nIpCQAAAT0"]
[Sun Aug 30 03:07:30.853801 2026] [security2:error] [pid 502397:tid 502618] [client 20.63.81.20:4351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/Jcrop.php"] [unique_id "apPkwmuFRxhFZfnD0nIpKQAAAWQ"]
[Sun Aug 30 03:07:30.900098 2026] [authz_core:error] [pid 502397:tid 502607] [client 66.249.66.67:53621] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:30.900612 2026] [authz_core:error] [pid 502397:tid 502607] [client 66.249.66.67:53621] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:30.937290 2026] [security2:error] [pid 499145:tid 499364] [client 20.104.50.220:42486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/hcd01.php"] [unique_id "apPkwlJNq1G5uRhTNnt4GwAAAFk"]
[Sun Aug 30 03:07:30.974089 2026] [authz_core:error] [pid 502397:tid 502617] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:30.974419 2026] [authz_core:error] [pid 502397:tid 502617] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:30.988178 2026] [security2:error] [pid 499145:tid 499327] [client 20.63.81.20:4099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/35iDq8NAjLu.php"] [unique_id "apPkwlJNq1G5uRhTNnt4OwAAADQ"]
[Sun Aug 30 03:07:30.990368 2026] [security2:error] [pid 499145:tid 499330] [client 20.48.251.3:7421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/wp-admin/sc.php"] [unique_id "apPkwlJNq1G5uRhTNnt4PQAAADc"]
[Sun Aug 30 03:07:30.991187 2026] [authz_core:error] [pid 499145:tid 499389] [client 66.249.66.74:39199] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:30.991711 2026] [authz_core:error] [pid 499145:tid 499389] [client 66.249.66.74:39199] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:31.012838 2026] [security2:error] [pid 499145:tid 499312] [client 68.155.159.216:63490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-admin/images/index.php"] [unique_id "apPkw1JNq1G5uRhTNnt4SwAAACU"]
[Sun Aug 30 03:07:31.028684 2026] [authz_core:error] [pid 502397:tid 502567] [client 66.249.66.65:37107] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:31.028962 2026] [authz_core:error] [pid 502397:tid 502567] [client 66.249.66.65:37107] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:31.036996 2026] [security2:error] [pid 502397:tid 502622] [client 178.16.55.109:49654] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "neilgclark.com"] [uri "/index.php"] [unique_id "apPkw2uFRxhFZfnD0nIpgAAAAWg"]
[Sun Aug 30 03:07:31.089666 2026] [authz_core:error] [pid 499145:tid 499320] [client 66.249.66.69:38277] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:31.090101 2026] [authz_core:error] [pid 499145:tid 499320] [client 66.249.66.69:38277] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:31.098795 2026] [security2:error] [pid 502397:tid 502623] [client 20.196.209.81:20873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/en.php"] [unique_id "apPkw2uFRxhFZfnD0nIpowAAAWk"]
[Sun Aug 30 03:07:31.122778 2026] [security2:error] [pid 502397:tid 502604] [client 20.104.104.62:37494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkw2uFRxhFZfnD0nIprQAAAVY"]
[Sun Aug 30 03:07:31.127861 2026] [security2:error] [pid 499145:tid 499285] [client 20.63.81.20:4126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/btx25.php"] [unique_id "apPkw1JNq1G5uRhTNnt4fgAAAAo"]
[Sun Aug 30 03:07:31.157594 2026] [security2:error] [pid 502397:tid 502654] [client 40.83.93.50:11499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/reboot/assets/js/plugins/home.php"] [unique_id "apPkw2uFRxhFZfnD0nIpxwAAAYg"]
[Sun Aug 30 03:07:31.171403 2026] [security2:error] [pid 502397:tid 502630] [client 40.83.93.50:13536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/an.php"] [unique_id "apPkw2uFRxhFZfnD0nIp1QAAAXA"]
[Sun Aug 30 03:07:31.218121 2026] [security2:error] [pid 499145:tid 499290] [client 68.155.159.216:56349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-admin/network/index.php"] [unique_id "apPkw1JNq1G5uRhTNnt4qQAAAA8"]
[Sun Aug 30 03:07:31.257691 2026] [security2:error] [pid 502397:tid 502544] [client 20.104.104.62:37451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkw2uFRxhFZfnD0nIqFAAAARs"]
[Sun Aug 30 03:07:31.259586 2026] [security2:error] [pid 502397:tid 502593] [client 20.63.81.20:4259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/radio.php"] [unique_id "apPkw2uFRxhFZfnD0nIqGQAAAUs"]
[Sun Aug 30 03:07:31.319097 2026] [authz_core:error] [pid 499145:tid 499301] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:31.319567 2026] [authz_core:error] [pid 499145:tid 499301] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:31.337362 2026] [security2:error] [pid 502397:tid 502543] [client 20.104.50.220:17238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/mac.php"] [unique_id "apPkw2uFRxhFZfnD0nIqUQAAARo"]
[Sun Aug 30 03:07:31.338871 2026] [security2:error] [pid 502397:tid 502606] [client 68.155.159.216:54212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPkw2uFRxhFZfnD0nIqUgAAAVg"]
[Sun Aug 30 03:07:31.360500 2026] [security2:error] [pid 499145:tid 499276] [client 114.119.144.15:62125] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "holycrossaustin.church"] [uri "/donate"] [unique_id "apPkw1JNq1G5uRhTNnt46wAAAAE"], referer: https://holycrossaustin.church/donate
[Sun Aug 30 03:07:31.361607 2026] [security2:error] [pid 502397:tid 502618] [client 20.104.50.220:29312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/java.php"] [unique_id "apPkw2uFRxhFZfnD0nIqbQAAAWQ"]
[Sun Aug 30 03:07:31.368346 2026] [security2:error] [pid 502397:tid 502632] [client 20.48.251.3:33286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/gnmlc.php"] [unique_id "apPkw2uFRxhFZfnD0nIqcgAAAXI"]
[Sun Aug 30 03:07:31.371546 2026] [security2:error] [pid 499145:tid 499292] [client 20.104.50.220:27215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/DB.php"] [unique_id "apPkw1JNq1G5uRhTNnt47wAAABE"]
[Sun Aug 30 03:07:31.388613 2026] [security2:error] [pid 502397:tid 502533] [client 20.63.81.20:4171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/dex.php"] [unique_id "apPkw2uFRxhFZfnD0nIqgwAAARA"]
[Sun Aug 30 03:07:31.396029 2026] [security2:error] [pid 502397:tid 502570] [client 20.104.50.220:5628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/65.php"] [unique_id "apPkw2uFRxhFZfnD0nIqiwAAATU"]
[Sun Aug 30 03:07:31.408437 2026] [security2:error] [pid 499145:tid 499377] [client 4.205.62.107:62104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/aws_secret_config.php"] [unique_id "apPkw1JNq1G5uRhTNnt5BwAAAGY"]
[Sun Aug 30 03:07:31.410001 2026] [security2:error] [pid 502397:tid 502584] [client 20.104.104.62:37456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/h02ugyh.php"] [unique_id "apPkw2uFRxhFZfnD0nIqnQAAAUM"]
[Sun Aug 30 03:07:31.412739 2026] [security2:error] [pid 502397:tid 502566] [client 68.155.159.216:12385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-blog-header.php"] [unique_id "apPkw2uFRxhFZfnD0nIqoQAAATE"]
[Sun Aug 30 03:07:31.414095 2026] [security2:error] [pid 502397:tid 502562] [client 68.155.159.216:60901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/sad/about.php"] [unique_id "apPkw2uFRxhFZfnD0nIqogAAAS0"]
[Sun Aug 30 03:07:31.422696 2026] [security2:error] [pid 502397:tid 502559] [client 68.155.159.216:61371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPkw2uFRxhFZfnD0nIqqwAAASo"]
[Sun Aug 30 03:07:31.441585 2026] [security2:error] [pid 502397:tid 502623] [client 20.104.18.15:34778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/zoo1.php"] [unique_id "apPkw2uFRxhFZfnD0nIqtwAAAWk"]
[Sun Aug 30 03:07:31.443544 2026] [security2:error] [pid 502397:tid 502612] [client 20.104.50.220:32723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/v3.php"] [unique_id "apPkw2uFRxhFZfnD0nIquAAAAV4"]
[Sun Aug 30 03:07:31.451628 2026] [security2:error] [pid 499145:tid 499364] [client 20.104.18.15:28597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/jp.php"] [unique_id "apPkw1JNq1G5uRhTNnt5FgAAAFk"]
[Sun Aug 30 03:07:31.462206 2026] [security2:error] [pid 502397:tid 502553] [client 20.104.18.15:18381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/inso.php"] [unique_id "apPkw2uFRxhFZfnD0nIqwAAAASQ"]
[Sun Aug 30 03:07:31.465252 2026] [security2:error] [pid 502397:tid 502591] [client 20.104.50.220:33323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/sure.php"] [unique_id "apPkw2uFRxhFZfnD0nIqwwAAAUk"]
[Sun Aug 30 03:07:31.471942 2026] [security2:error] [pid 502397:tid 502598] [client 4.205.62.107:22933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/zaza.php"] [unique_id "apPkw2uFRxhFZfnD0nIqzQAAAVA"]
[Sun Aug 30 03:07:31.474371 2026] [security2:error] [pid 502397:tid 502578] [client 4.205.62.107:64464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/groceries/index.php"] [unique_id "apPkw2uFRxhFZfnD0nIq1QAAAT0"]
[Sun Aug 30 03:07:31.478407 2026] [security2:error] [pid 502397:tid 502555] [client 20.104.50.220:46625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/XxX.php"] [unique_id "apPkw2uFRxhFZfnD0nIq2AAAASY"]
[Sun Aug 30 03:07:31.479556 2026] [authz_core:error] [pid 502397:tid 502595] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:31.479592 2026] [security2:error] [pid 502397:tid 502644] [client 20.48.251.3:44289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/grsiuk.php"] [unique_id "apPkw2uFRxhFZfnD0nIq2QAAAX4"]
[Sun Aug 30 03:07:31.479954 2026] [authz_core:error] [pid 502397:tid 502595] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:31.495675 2026] [security2:error] [pid 502397:tid 502558] [client 20.196.209.81:1995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/13.php"] [unique_id "apPkw2uFRxhFZfnD0nIq5wAAASk"]
[Sun Aug 30 03:07:31.498530 2026] [security2:error] [pid 502397:tid 502557] [client 20.104.18.15:51673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/dehnl.php"] [unique_id "apPkw2uFRxhFZfnD0nIq6gAAASg"]
[Sun Aug 30 03:07:31.509750 2026] [security2:error] [pid 502397:tid 502547] [client 20.104.18.15:23444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/ano.php"] [unique_id "apPkw2uFRxhFZfnD0nIq9wAAAR4"]
[Sun Aug 30 03:07:31.517125 2026] [security2:error] [pid 502397:tid 502609] [client 4.205.62.107:36635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/public/bnn_.php.php"] [unique_id "apPkw2uFRxhFZfnD0nIrAAAAAVs"]
[Sun Aug 30 03:07:31.518783 2026] [security2:error] [pid 499145:tid 499353] [client 20.48.251.3:12056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/agg.php"] [unique_id "apPkw1JNq1G5uRhTNnt5OAAAAE4"]
[Sun Aug 30 03:07:31.519029 2026] [security2:error] [pid 502397:tid 502618] [client 4.205.62.107:2328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/aws_keys.php"] [unique_id "apPkw2uFRxhFZfnD0nIrAQAAAWQ"]
[Sun Aug 30 03:07:31.521139 2026] [security2:error] [pid 499145:tid 499356] [client 20.63.81.20:4365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/giodywky.php"] [unique_id "apPkw1JNq1G5uRhTNnt5OwAAAFE"]
[Sun Aug 30 03:07:31.533017 2026] [authz_core:error] [pid 502397:tid 502653] [client 216.73.216.128:1238] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:31.533297 2026] [authz_core:error] [pid 502397:tid 502653] [client 216.73.216.128:1238] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:31.546769 2026] [security2:error] [pid 502397:tid 502568] [client 20.104.104.62:37488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/sf.php"] [unique_id "apPkw2uFRxhFZfnD0nIrGAAAATM"]
[Sun Aug 30 03:07:31.556455 2026] [authz_core:error] [pid 502397:tid 502593] [client 66.249.66.33:57242] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:31.556801 2026] [authz_core:error] [pid 502397:tid 502593] [client 66.249.66.33:57242] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:31.575903 2026] [security2:error] [pid 502397:tid 502584] [client 20.104.18.15:13611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/xmini4.php"] [unique_id "apPkw2uFRxhFZfnD0nIrNwAAAUM"]
[Sun Aug 30 03:07:31.610715 2026] [security2:error] [pid 499145:tid 499287] [client 20.104.18.15:29143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/simple.php"] [unique_id "apPkw1JNq1G5uRhTNnt5YAAAAAw"]
[Sun Aug 30 03:07:31.622172 2026] [security2:error] [pid 502397:tid 502605] [client 40.83.93.50:11462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/salient/css/build/plugins/login.php"] [unique_id "apPkw2uFRxhFZfnD0nIrSwAAAVc"]
[Sun Aug 30 03:07:31.648275 2026] [security2:error] [pid 499145:tid 499363] [client 20.63.81.20:4104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp-kz.php"] [unique_id "apPkw1JNq1G5uRhTNnt5ZwAAAFg"]
[Sun Aug 30 03:07:31.674525 2026] [security2:error] [pid 502397:tid 502647] [client 20.104.50.220:59561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/images/leaf.php"] [unique_id "apPkw2uFRxhFZfnD0nIrUgAAAYE"]
[Sun Aug 30 03:07:31.687124 2026] [security2:error] [pid 502397:tid 502549] [client 157.7.105.143:55088] ModSecurity: Warning. Matched phrase "LWP::Simple" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "bcwinetrends.com"] [uri "/2017/07/03/rose-gold-at-the-acwc/"] [unique_id "apPkw2uFRxhFZfnD0nIrQQAAASA"]
[Sun Aug 30 03:07:31.697909 2026] [security2:error] [pid 502397:tid 502641] [client 114.119.132.238:41691] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "summer.pplak.org"] [uri "/"] [unique_id "apPkw2uFRxhFZfnD0nIrXAAAAXs"], referer: https://summer.pplak.org/
[Sun Aug 30 03:07:31.701675 2026] [security2:error] [pid 502397:tid 502631] [client 40.83.93.50:18530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/mini.php"] [unique_id "apPkw2uFRxhFZfnD0nIrYgAAAXE"]
[Sun Aug 30 03:07:31.720895 2026] [security2:error] [pid 502397:tid 502565] [client 4.205.62.107:18684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/kedi.php"] [unique_id "apPkw2uFRxhFZfnD0nIrcwAAATA"]
[Sun Aug 30 03:07:31.749132 2026] [authz_core:error] [pid 502397:tid 502582] [client 66.249.66.75:57243] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:31.749547 2026] [authz_core:error] [pid 502397:tid 502582] [client 66.249.66.75:57243] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:31.749637 2026] [security2:error] [pid 499145:tid 499281] [client 20.104.104.62:37478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/4e.php"] [unique_id "apPkw1JNq1G5uRhTNnt5jwAAAAY"]
[Sun Aug 30 03:07:31.807317 2026] [security2:error] [pid 499145:tid 499282] [client 20.63.81.20:4261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp-includes/ID3/getid.php"] [unique_id "apPkw1JNq1G5uRhTNnt5rQAAAAc"]
[Sun Aug 30 03:07:31.858830 2026] [security2:error] [pid 502397:tid 502576] [client 20.151.200.44:55628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/xwpg.php"] [unique_id "apPkw2uFRxhFZfnD0nIrxAAAATs"]
[Sun Aug 30 03:07:31.892011 2026] [security2:error] [pid 502397:tid 502640] [client 20.104.104.62:35358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/ssss.php"] [unique_id "apPkw2uFRxhFZfnD0nIrzgAAAXo"]
[Sun Aug 30 03:07:31.893158 2026] [security2:error] [pid 502397:tid 502602] [client 20.196.209.81:19100] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.piako.store"] [uri "/1.php"] [unique_id "apPkw2uFRxhFZfnD0nIrzwAAAVQ"]
[Sun Aug 30 03:07:31.893310 2026] [security2:error] [pid 502397:tid 502602] [client 20.196.209.81:19100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/1.php"] [unique_id "apPkw2uFRxhFZfnD0nIrzwAAAVQ"]
[Sun Aug 30 03:07:31.898806 2026] [security2:error] [pid 502397:tid 502637] [client 20.104.50.220:28708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/.well-known/shell.php"] [unique_id "apPkw2uFRxhFZfnD0nIr0QAAAXc"]
[Sun Aug 30 03:07:31.914097 2026] [security2:error] [pid 502397:tid 502571] [client 20.104.49.130:58183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/reviall.php"] [unique_id "apPkw2uFRxhFZfnD0nIr2AAAATY"]
[Sun Aug 30 03:07:31.939752 2026] [security2:error] [pid 502397:tid 502603] [client 20.63.81.20:4262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/session.php"] [unique_id "apPkw2uFRxhFZfnD0nIr4wAAAVU"]
[Sun Aug 30 03:07:31.998239 2026] [authz_core:error] [pid 502397:tid 502553] [client 66.249.66.78:50232] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:31.998703 2026] [authz_core:error] [pid 502397:tid 502553] [client 66.249.66.78:50232] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:32.002509 2026] [authz_core:error] [pid 502397:tid 502530] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:32.002968 2026] [authz_core:error] [pid 502397:tid 502530] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:32.057073 2026] [security2:error] [pid 502397:tid 502578] [client 20.104.104.62:35360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/zoz.php"] [unique_id "apPkxGuFRxhFZfnD0nIsKAAAAT0"]
[Sun Aug 30 03:07:32.057924 2026] [security2:error] [pid 499145:tid 499286] [client 91.224.92.19:59602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.92.224.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.xn--b3cb4aatcg5ckn7hg1ewed2ivab2inmngh7e.com"] [uri "/wp-login.php"] [unique_id "apPkxFJNq1G5uRhTNnt6DgAAAAs"], referer: https://twitter.com/
[Sun Aug 30 03:07:32.070023 2026] [security2:error] [pid 502397:tid 502638] [client 20.63.81.20:4158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/eagle.php"] [unique_id "apPkxGuFRxhFZfnD0nIsLgAAAXg"]
[Sun Aug 30 03:07:32.077411 2026] [security2:error] [pid 502397:tid 502647] [client 20.104.50.220:63544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/prof.php"] [unique_id "apPkxGuFRxhFZfnD0nIsMwAAAYE"]
[Sun Aug 30 03:07:32.087908 2026] [security2:error] [pid 502397:tid 502624] [client 40.83.93.50:9684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/security.php"] [unique_id "apPkxGuFRxhFZfnD0nIsOAAAAWo"]
[Sun Aug 30 03:07:32.122712 2026] [security2:error] [pid 499145:tid 499395] [client 34.125.55.247:47556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.55.125.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.engaginggoddaily.com"] [uri "/pi.php"] [unique_id "apPkxFJNq1G5uRhTNnt6MgAAAHg"]
[Sun Aug 30 03:07:32.126082 2026] [security2:error] [pid 502397:tid 502528] [client 34.125.55.247:47542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.55.125.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.engaginggoddaily.com"] [uri "/i.php"] [unique_id "apPkxGuFRxhFZfnD0nIsRAAAAQs"]
[Sun Aug 30 03:07:32.133291 2026] [authz_core:error] [pid 502397:tid 502632] [client 66.249.66.39:36524] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:32.133749 2026] [authz_core:error] [pid 502397:tid 502632] [client 66.249.66.39:36524] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:32.200915 2026] [security2:error] [pid 502397:tid 502648] [client 20.63.81.20:4503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/up-kon.php"] [unique_id "apPkxGuFRxhFZfnD0nIsggAAAYI"]
[Sun Aug 30 03:07:32.203017 2026] [security2:error] [pid 502397:tid 502623] [client 4.205.62.107:58341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/tax.php"] [unique_id "apPkxGuFRxhFZfnD0nIsfAAAAWk"]
[Sun Aug 30 03:07:32.203799 2026] [authz_core:error] [pid 502397:tid 502528] [client 216.73.216.128:53231] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:32.204257 2026] [authz_core:error] [pid 502397:tid 502528] [client 216.73.216.128:53231] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:32.207126 2026] [security2:error] [pid 502397:tid 502542] [client 68.155.159.216:62276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-includes/index.php"] [unique_id "apPkxGuFRxhFZfnD0nIshgAAARk"]
[Sun Aug 30 03:07:32.216261 2026] [security2:error] [pid 502397:tid 502558] [client 20.104.104.62:35341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/kcs.php"] [unique_id "apPkxGuFRxhFZfnD0nIsiAAAASk"]
[Sun Aug 30 03:07:32.241330 2026] [security2:error] [pid 502397:tid 502558] [client 34.125.55.247:47606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "apPkxGuFRxhFZfnD0nIsmQAAASk"]
[Sun Aug 30 03:07:32.241794 2026] [security2:error] [pid 502397:tid 502619] [client 34.125.55.247:47602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/.env~"] [unique_id "apPkxGuFRxhFZfnD0nIslwAAAWU"]
[Sun Aug 30 03:07:32.252824 2026] [security2:error] [pid 502397:tid 502612] [client 34.125.55.247:47560] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.engaginggoddaily.com"] [uri "/.env.prod"] [unique_id "apPkxGuFRxhFZfnD0nIsoQAAAV4"]
[Sun Aug 30 03:07:32.261312 2026] [security2:error] [pid 502397:tid 502537] [client 34.125.55.247:47586] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/_next/.env"] [unique_id "apPkxGuFRxhFZfnD0nIsqgAAARQ"]
[Sun Aug 30 03:07:32.261996 2026] [security2:error] [pid 502397:tid 502562] [client 34.125.55.247:47610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.bash_history"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/.bash_history"] [unique_id "apPkxGuFRxhFZfnD0nIsrQAAAS0"]
[Sun Aug 30 03:07:32.300866 2026] [authz_core:error] [pid 502397:tid 502608] [client 66.249.66.65:64004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:32.301171 2026] [authz_core:error] [pid 502397:tid 502608] [client 66.249.66.65:64004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:32.315314 2026] [security2:error] [pid 502397:tid 502628] [client 20.196.209.81:19072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/as.php"] [unique_id "apPkxGuFRxhFZfnD0nIsyQAAAW4"]
[Sun Aug 30 03:07:32.343894 2026] [security2:error] [pid 502397:tid 502534] [client 20.63.81.20:4200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/tinny.php"] [unique_id "apPkxGuFRxhFZfnD0nIs3AAAARE"]
[Sun Aug 30 03:07:32.345697 2026] [security2:error] [pid 502397:tid 502542] [client 68.155.159.216:56372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apPkxGuFRxhFZfnD0nIs3wAAARk"]
[Sun Aug 30 03:07:32.360328 2026] [security2:error] [pid 502397:tid 502577] [client 40.83.93.50:18509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/robots.php"] [unique_id "apPkxGuFRxhFZfnD0nIs7wAAATw"]
[Sun Aug 30 03:07:32.373035 2026] [security2:error] [pid 499145:tid 499337] [client 20.151.200.44:55622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/sxxb.php"] [unique_id "apPkxFJNq1G5uRhTNnt6xAAAAD4"]
[Sun Aug 30 03:07:32.373639 2026] [security2:error] [pid 499145:tid 499323] [client 20.104.104.62:37467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/tajj.php"] [unique_id "apPkxFJNq1G5uRhTNnt6xQAAADA"]
[Sun Aug 30 03:07:32.375995 2026] [security2:error] [pid 499145:tid 499346] [client 20.48.251.3:64462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/debug.php"] [unique_id "apPkxFJNq1G5uRhTNnt6xwAAAEc"]
[Sun Aug 30 03:07:32.386780 2026] [authz_core:error] [pid 502397:tid 502548] [client 216.73.216.128:53231] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:32.387355 2026] [authz_core:error] [pid 502397:tid 502548] [client 216.73.216.128:53231] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:32.430444 2026] [lsapi:error] [pid 502397:tid 502428] [remote 78.62.187.123:56052] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.yandex.com/
[Sun Aug 30 03:07:32.430676 2026] [lsapi:error] [pid 502397:tid 502428] [remote 78.62.187.123:56052] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.yandex.com/
[Sun Aug 30 03:07:32.432070 2026] [lsapi:error] [pid 502397:tid 502428] [remote 78.62.187.123:56052] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n, referer: https://www.yandex.com/
[Sun Aug 30 03:07:32.442226 2026] [security2:error] [pid 499145:tid 499343] [client 68.155.159.216:54217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPkxFJNq1G5uRhTNnt65AAAAEQ"]
[Sun Aug 30 03:07:32.474973 2026] [security2:error] [pid 502397:tid 502651] [client 20.63.81.20:4186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp-easy.php"] [unique_id "apPkxGuFRxhFZfnD0nItRwAAAYU"]
[Sun Aug 30 03:07:32.475145 2026] [security2:error] [pid 502397:tid 502566] [client 20.104.50.220:17336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/25d653587fdfd1.php"] [unique_id "apPkxGuFRxhFZfnD0nItSAAAATE"]
[Sun Aug 30 03:07:32.500321 2026] [authz_core:error] [pid 502397:tid 502578] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:32.500584 2026] [authz_core:error] [pid 502397:tid 502578] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:32.508750 2026] [security2:error] [pid 502397:tid 502538] [client 20.104.50.220:27540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/OAuth.php"] [unique_id "apPkxGuFRxhFZfnD0nItXAAAARU"]
[Sun Aug 30 03:07:32.516198 2026] [security2:error] [pid 502397:tid 502602] [client 68.155.159.216:60917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/admin.php"] [unique_id "apPkxGuFRxhFZfnD0nItXQAAAVQ"]
[Sun Aug 30 03:07:32.525418 2026] [security2:error] [pid 502397:tid 502576] [client 68.155.159.216:65444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-includes/content.php"] [unique_id "apPkxGuFRxhFZfnD0nItawAAATs"]
[Sun Aug 30 03:07:32.537754 2026] [security2:error] [pid 502397:tid 502593] [client 20.104.50.220:5207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/64.php"] [unique_id "apPkxGuFRxhFZfnD0nItdQAAAUs"]
[Sun Aug 30 03:07:32.538773 2026] [security2:error] [pid 502397:tid 502557] [client 20.104.50.220:29156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/kntl.php"] [unique_id "apPkxGuFRxhFZfnD0nItdgAAASg"]
[Sun Aug 30 03:07:32.540475 2026] [security2:error] [pid 502397:tid 502587] [client 20.48.251.3:13428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/koiy.php"] [unique_id "apPkxGuFRxhFZfnD0nItdwAAAUY"]
[Sun Aug 30 03:07:32.542832 2026] [security2:error] [pid 502397:tid 502604] [client 4.205.62.107:62020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/snq.php"] [unique_id "apPkxGuFRxhFZfnD0nItegAAAVY"]
[Sun Aug 30 03:07:32.545380 2026] [security2:error] [pid 502397:tid 502547] [client 20.104.49.130:53587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/100.php"] [unique_id "apPkxGuFRxhFZfnD0nItewAAAR4"]
[Sun Aug 30 03:07:32.549036 2026] [security2:error] [pid 502397:tid 502648] [client 40.83.93.50:5963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "apPkxGuFRxhFZfnD0nItfQAAAYI"]
[Sun Aug 30 03:07:32.554031 2026] [security2:error] [pid 499145:tid 499250] [remote 114.119.156.126:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "healthyflowblood.com"] [uri "/why-nitric-oxide-foods-are-the-key-to-natural-energy/"] [unique_id "apPkxFJNq1G5uRhTNnt7EAAALWg"], referer: https://bookings.ecocexhibition.com/node/108827
[Sun Aug 30 03:07:32.567051 2026] [security2:error] [pid 502397:tid 502583] [client 20.104.104.62:37486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/bge.php"] [unique_id "apPkxGuFRxhFZfnD0nItiQAAAUI"]
[Sun Aug 30 03:07:32.585358 2026] [security2:error] [pid 502397:tid 502557] [client 20.104.18.15:34754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/radio.php"] [unique_id "apPkxGuFRxhFZfnD0nItlwAAASg"]
[Sun Aug 30 03:07:32.591477 2026] [security2:error] [pid 502397:tid 502540] [client 20.104.50.220:31814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/v4.php"] [unique_id "apPkxGuFRxhFZfnD0nItmwAAARc"]
[Sun Aug 30 03:07:32.591513 2026] [security2:error] [pid 502397:tid 502544] [client 68.155.159.216:12340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apPkxGuFRxhFZfnD0nItnAAAARs"]
[Sun Aug 30 03:07:32.602761 2026] [security2:error] [pid 502397:tid 502595] [client 20.104.18.15:28665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/f35.php"] [unique_id "apPkxGuFRxhFZfnD0nItoQAAAU0"]
[Sun Aug 30 03:07:32.603306 2026] [security2:error] [pid 502397:tid 502640] [client 20.63.81.20:4233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/d7.php"] [unique_id "apPkxGuFRxhFZfnD0nItowAAAXo"]
[Sun Aug 30 03:07:32.605527 2026] [security2:error] [pid 502397:tid 502643] [client 4.205.62.107:61771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/konfig.php"] [unique_id "apPkxGuFRxhFZfnD0nItpgAAAX0"]
[Sun Aug 30 03:07:32.611833 2026] [security2:error] [pid 502397:tid 502608] [client 20.104.18.15:18365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/aa.php"] [unique_id "apPkxGuFRxhFZfnD0nItrAAAAVo"]
[Sun Aug 30 03:07:32.624245 2026] [security2:error] [pid 502397:tid 502531] [client 4.205.62.107:62417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/u88.php"] [unique_id "apPkxGuFRxhFZfnD0nItrwAAAQ4"]
[Sun Aug 30 03:07:32.629061 2026] [security2:error] [pid 502397:tid 502650] [client 20.104.50.220:33301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/dl.php"] [unique_id "apPkxGuFRxhFZfnD0nItsgAAAYQ"]
[Sun Aug 30 03:07:32.632436 2026] [security2:error] [pid 502397:tid 502583] [client 20.104.50.220:46882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/zk.php"] [unique_id "apPkxGuFRxhFZfnD0nItswAAAUI"]
[Sun Aug 30 03:07:32.648198 2026] [security2:error] [pid 502397:tid 502598] [client 4.205.62.107:36614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/wsws.php"] [unique_id "apPkxGuFRxhFZfnD0nItvAAAAVA"]
[Sun Aug 30 03:07:32.650519 2026] [security2:error] [pid 502397:tid 502548] [client 20.48.251.3:4836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/paypal.php"] [unique_id "apPkxGuFRxhFZfnD0nItvwAAAR8"]
[Sun Aug 30 03:07:32.657302 2026] [security2:error] [pid 502397:tid 502565] [client 20.104.18.15:51618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/zoo1.php"] [unique_id "apPkxGuFRxhFZfnD0nItzgAAATA"]
[Sun Aug 30 03:07:32.658678 2026] [security2:error] [pid 502397:tid 502536] [client 20.48.251.3:34465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/requirements.php"] [unique_id "apPkxGuFRxhFZfnD0nIt0QAAARM"]
[Sun Aug 30 03:07:32.660319 2026] [authz_core:error] [pid 502397:tid 502595] [client 216.73.216.128:53231] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:32.660746 2026] [authz_core:error] [pid 502397:tid 502595] [client 216.73.216.128:53231] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:32.663232 2026] [security2:error] [pid 502397:tid 502597] [client 4.205.62.107:2165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/umgebung.php"] [unique_id "apPkxGuFRxhFZfnD0nIt2AAAAU8"]
[Sun Aug 30 03:07:32.665361 2026] [security2:error] [pid 502397:tid 502650] [client 20.104.18.15:23550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/mgrr.php"] [unique_id "apPkxGuFRxhFZfnD0nIt2gAAAYQ"]
[Sun Aug 30 03:07:32.666888 2026] [security2:error] [pid 502397:tid 502610] [client 20.151.200.44:55729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/dx.php"] [unique_id "apPkxGuFRxhFZfnD0nIt2wAAAVw"]
[Sun Aug 30 03:07:32.721718 2026] [security2:error] [pid 502397:tid 502567] [client 20.104.18.15:14281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/gulu.php"] [unique_id "apPkxGuFRxhFZfnD0nIt-QAAATI"]
[Sun Aug 30 03:07:32.723541 2026] [security2:error] [pid 502397:tid 502547] [client 20.196.209.81:19931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/credits.php"] [unique_id "apPkxGuFRxhFZfnD0nIt_AAAAR4"]
[Sun Aug 30 03:07:32.738164 2026] [security2:error] [pid 502397:tid 502617] [client 20.63.81.20:4188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/v5.php"] [unique_id "apPkxGuFRxhFZfnD0nIuCgAAAWM"]
[Sun Aug 30 03:07:32.741596 2026] [authz_core:error] [pid 502397:tid 502596] [client 66.249.66.42:45742] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:32.742025 2026] [authz_core:error] [pid 502397:tid 502596] [client 66.249.66.42:45742] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:32.749113 2026] [authz_core:error] [pid 502397:tid 502594] [client 216.73.216.128:1238] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:32.749532 2026] [authz_core:error] [pid 502397:tid 502594] [client 216.73.216.128:1238] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:32.754900 2026] [security2:error] [pid 502397:tid 502567] [client 158.23.147.79:63913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkxGuFRxhFZfnD0nIuEgAAATI"]
[Sun Aug 30 03:07:32.786691 2026] [security2:error] [pid 502397:tid 502571] [client 20.104.18.15:29128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/sallu.php"] [unique_id "apPkxGuFRxhFZfnD0nIuMAAAATY"]
[Sun Aug 30 03:07:32.788445 2026] [authz_core:error] [pid 499145:tid 499327] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:32.788847 2026] [authz_core:error] [pid 499145:tid 499327] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:32.791753 2026] [security2:error] [pid 502397:tid 502597] [client 20.104.104.62:37472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/ssh3ll.php"] [unique_id "apPkxGuFRxhFZfnD0nIuNwAAAU8"]
[Sun Aug 30 03:07:32.844525 2026] [security2:error] [pid 502397:tid 502559] [client 20.104.50.220:61458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/images/wso.php"] [unique_id "apPkxGuFRxhFZfnD0nIuYgAAASo"]
[Sun Aug 30 03:07:32.854341 2026] [authz_core:error] [pid 502397:tid 502551] [client 66.249.66.70:54128] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:32.854605 2026] [authz_core:error] [pid 502397:tid 502551] [client 66.249.66.70:54128] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:32.866417 2026] [security2:error] [pid 499145:tid 499393] [client 158.23.147.79:63875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkxFJNq1G5uRhTNnt7ZQAAAHY"]
[Sun Aug 30 03:07:32.869900 2026] [security2:error] [pid 502397:tid 502534] [client 40.83.93.50:12321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/cron.php"] [unique_id "apPkxGuFRxhFZfnD0nIucgAAARE"]
[Sun Aug 30 03:07:32.881209 2026] [security2:error] [pid 499145:tid 499355] [client 4.205.62.107:17839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/oc460l3x.php"] [unique_id "apPkxFJNq1G5uRhTNnt7awAAAFA"]
[Sun Aug 30 03:07:32.890899 2026] [security2:error] [pid 499145:tid 499295] [client 20.63.81.20:4257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/az.php"] [unique_id "apPkxFJNq1G5uRhTNnt7cAAAABQ"]
[Sun Aug 30 03:07:32.930714 2026] [security2:error] [pid 499145:tid 499313] [client 20.104.104.62:37501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/motu.php"] [unique_id "apPkxFJNq1G5uRhTNnt7hQAAACY"]
[Sun Aug 30 03:07:32.965553 2026] [security2:error] [pid 502397:tid 502635] [client 65.108.6.34:50416] ModSecurity: Warning. Matched phrase "SEOkicks" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "flashflooring.co.uk"] [uri "/index.php"] [unique_id "apPkxGuFRxhFZfnD0nIs0wAAAXU"], referer: https://flashflooring.co.uk/
[Sun Aug 30 03:07:33.015378 2026] [security2:error] [pid 502397:tid 502543] [client 20.104.49.130:59543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/load.php"] [unique_id "apPkxWuFRxhFZfnD0nIuuwAAARo"]
[Sun Aug 30 03:07:33.021424 2026] [security2:error] [pid 502397:tid 502532] [client 20.63.81.20:4177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/js.php"] [unique_id "apPkxWuFRxhFZfnD0nIuwgAAAQ8"]
[Sun Aug 30 03:07:33.022025 2026] [security2:error] [pid 502397:tid 502561] [client 40.83.93.50:5973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/system.php"] [unique_id "apPkxWuFRxhFZfnD0nIuwwAAASw"]
[Sun Aug 30 03:07:33.034339 2026] [authz_core:error] [pid 502397:tid 502544] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:33.034673 2026] [authz_core:error] [pid 502397:tid 502544] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:33.038633 2026] [security2:error] [pid 502397:tid 502575] [client 20.104.50.220:52843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/.well-known/.dha.php"] [unique_id "apPkxWuFRxhFZfnD0nIu0AAAATo"]
[Sun Aug 30 03:07:33.080201 2026] [security2:error] [pid 502397:tid 502565] [client 20.104.104.62:37496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/wefile.php"] [unique_id "apPkxWuFRxhFZfnD0nIu8wAAATA"]
[Sun Aug 30 03:07:33.114433 2026] [authz_core:error] [pid 502397:tid 502639] [client 216.73.216.128:53231] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:33.114816 2026] [authz_core:error] [pid 502397:tid 502639] [client 216.73.216.128:53231] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:33.138100 2026] [security2:error] [pid 499145:tid 499276] [client 114.119.136.103:54169] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aheavenlyfootmassage.com"] [uri "/miscellaneous/"] [unique_id "apPkxVJNq1G5uRhTNnt70QAAAAE"], referer: https://aheavenlyfootmassage.com/miscellaneous/
[Sun Aug 30 03:07:33.155092 2026] [security2:error] [pid 502397:tid 502540] [client 20.63.81.20:4106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/hd.php"] [unique_id "apPkxWuFRxhFZfnD0nIvIAAAARc"]
[Sun Aug 30 03:07:33.163984 2026] [security2:error] [pid 502397:tid 502581] [client 20.196.209.81:19117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/cache.php"] [unique_id "apPkxWuFRxhFZfnD0nIvKAAAAUA"]
[Sun Aug 30 03:07:33.175610 2026] [security2:error] [pid 502397:tid 502562] [client 20.151.200.44:55698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPkxWuFRxhFZfnD0nIvNgAAAS0"]
[Sun Aug 30 03:07:33.229304 2026] [security2:error] [pid 499145:tid 499378] [client 20.104.50.220:51603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/AkuSayangKamu45.php"] [unique_id "apPkxVJNq1G5uRhTNnt79QAAAGc"]
[Sun Aug 30 03:07:33.269123 2026] [security2:error] [pid 502397:tid 502602] [client 20.104.104.62:37455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/Contrller.php"] [unique_id "apPkxWuFRxhFZfnD0nIvfQAAAVQ"]
[Sun Aug 30 03:07:33.283232 2026] [security2:error] [pid 502397:tid 502540] [client 20.104.104.62:14358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkxWuFRxhFZfnD0nIvjQAAARc"]
[Sun Aug 30 03:07:33.284291 2026] [security2:error] [pid 499145:tid 499348] [client 20.63.81.20:4260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/xl2023.php"] [unique_id "apPkxVJNq1G5uRhTNnt8EAAAAEk"]
[Sun Aug 30 03:07:33.386448 2026] [security2:error] [pid 502397:tid 502578] [client 40.83.93.50:18533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/goat.php"] [unique_id "apPkxWuFRxhFZfnD0nIvxQAAAT0"]
[Sun Aug 30 03:07:33.399248 2026] [security2:error] [pid 502397:tid 502595] [client 68.155.159.216:61674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/mah.php"] [unique_id "apPkxWuFRxhFZfnD0nIv1AAAAU0"]
[Sun Aug 30 03:07:33.412575 2026] [security2:error] [pid 499145:tid 499289] [client 20.63.81.20:4405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/V2.php"] [unique_id "apPkxVJNq1G5uRhTNnt8YwAAAA4"]
[Sun Aug 30 03:07:33.413265 2026] [security2:error] [pid 499145:tid 499278] [client 20.104.104.62:14343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkxVJNq1G5uRhTNnt8ZQAAAAM"]
[Sun Aug 30 03:07:33.421476 2026] [security2:error] [pid 502397:tid 502626] [client 20.104.18.15:43947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/wp-includes/ID3/moon.php"] [unique_id "apPkxWuFRxhFZfnD0nIv4gAAAWw"]
[Sun Aug 30 03:07:33.423772 2026] [security2:error] [pid 499145:tid 499339] [client 20.104.104.62:37491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/file66.php"] [unique_id "apPkxVJNq1G5uRhTNnt8awAAAEA"]
[Sun Aug 30 03:07:33.474888 2026] [security2:error] [pid 502397:tid 502549] [client 20.104.49.130:59523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/82.php"] [unique_id "apPkxWuFRxhFZfnD0nIwAAAAASA"]
[Sun Aug 30 03:07:33.497900 2026] [security2:error] [pid 502397:tid 502637] [client 40.83.93.50:11470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/tflow/min.php"] [unique_id "apPkxWuFRxhFZfnD0nIwFwAAAXc"]
[Sun Aug 30 03:07:33.513944 2026] [security2:error] [pid 502397:tid 502608] [client 68.155.159.216:56353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/.well-knownold/index.php"] [unique_id "apPkxWuFRxhFZfnD0nIwHwAAAVo"]
[Sun Aug 30 03:07:33.527809 2026] [authz_core:error] [pid 502397:tid 502561] [client 66.249.66.69:64720] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:33.528256 2026] [authz_core:error] [pid 502397:tid 502561] [client 66.249.66.69:64720] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:33.547227 2026] [security2:error] [pid 502397:tid 502583] [client 20.63.81.20:4274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/mad.php"] [unique_id "apPkxWuFRxhFZfnD0nIwTAAAAUI"]
[Sun Aug 30 03:07:33.549669 2026] [security2:error] [pid 499145:tid 499317] [client 20.104.104.62:14847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/h02ugyh.php"] [unique_id "apPkxVJNq1G5uRhTNnt8oAAAACo"]
[Sun Aug 30 03:07:33.562390 2026] [security2:error] [pid 502397:tid 502548] [client 20.196.209.81:19102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/fix.php"] [unique_id "apPkxWuFRxhFZfnD0nIwWAAAAR8"]
[Sun Aug 30 03:07:33.573640 2026] [security2:error] [pid 499145:tid 499303] [client 20.104.104.62:37499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/blnux.php"] [unique_id "apPkxVJNq1G5uRhTNnt8sgAAABw"]
[Sun Aug 30 03:07:33.624116 2026] [security2:error] [pid 499145:tid 499353] [client 68.155.159.216:55147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apPkxVJNq1G5uRhTNnt8xAAAAE4"]
[Sun Aug 30 03:07:33.627114 2026] [security2:error] [pid 499145:tid 499319] [client 20.104.50.220:16747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wefile.php"] [unique_id "apPkxVJNq1G5uRhTNnt8xgAAACw"]
[Sun Aug 30 03:07:33.648812 2026] [security2:error] [pid 502397:tid 502591] [client 20.104.50.220:27520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/Nonce.php"] [unique_id "apPkxWuFRxhFZfnD0nIwfwAAAUk"]
[Sun Aug 30 03:07:33.654304 2026] [security2:error] [pid 502397:tid 502573] [client 114.119.136.164:59731] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "wagwoo.com"] [uri "/blog/"] [unique_id "apPkxWuFRxhFZfnD0nIwggAAATg"], referer: https://wagwoo.com/blog/
[Sun Aug 30 03:07:33.658844 2026] [security2:error] [pid 502397:tid 502565] [client 68.155.159.216:61347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-admin/css/index.php"] [unique_id "apPkxWuFRxhFZfnD0nIwhAAAATA"]
[Sun Aug 30 03:07:33.664405 2026] [security2:error] [pid 502397:tid 502581] [client 68.155.159.216:61400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-admin/admin.php"] [unique_id "apPkxWuFRxhFZfnD0nIwiAAAAUA"]
[Sun Aug 30 03:07:33.668899 2026] [security2:error] [pid 502397:tid 502579] [client 20.104.50.220:5612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/63.php"] [unique_id "apPkxWuFRxhFZfnD0nIwigAAAT4"]
[Sun Aug 30 03:07:33.669566 2026] [security2:error] [pid 502397:tid 502534] [client 4.205.62.107:32480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPkxWuFRxhFZfnD0nIwiwAAARE"]
[Sun Aug 30 03:07:33.672370 2026] [security2:error] [pid 502397:tid 502600] [client 20.63.81.20:4193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/st.php"] [unique_id "apPkxWuFRxhFZfnD0nIwjQAAAVI"]
[Sun Aug 30 03:07:33.675664 2026] [security2:error] [pid 502397:tid 502540] [client 20.48.251.3:33330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/w.php"] [unique_id "apPkxWuFRxhFZfnD0nIwjwAAARc"]
[Sun Aug 30 03:07:33.677895 2026] [security2:error] [pid 502397:tid 502599] [client 20.104.104.62:14812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/sf.php"] [unique_id "apPkxWuFRxhFZfnD0nIwkAAAAVE"]
[Sun Aug 30 03:07:33.684775 2026] [security2:error] [pid 502397:tid 502617] [client 4.205.62.107:63969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/wp-access.php"] [unique_id "apPkxWuFRxhFZfnD0nIwkwAAAWM"]
[Sun Aug 30 03:07:33.694599 2026] [security2:error] [pid 502397:tid 502577] [client 20.104.50.220:29181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/klee.php"] [unique_id "apPkxWuFRxhFZfnD0nIwmwAAATw"]
[Sun Aug 30 03:07:33.708426 2026] [security2:error] [pid 502397:tid 502642] [client 20.104.104.62:37485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/attack.php"] [unique_id "apPkxWuFRxhFZfnD0nIwpwAAAXw"]
[Sun Aug 30 03:07:33.717563 2026] [security2:error] [pid 502397:tid 502610] [client 68.155.159.216:12360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-admin/user/index.php"] [unique_id "apPkxWuFRxhFZfnD0nIwtgAAAVw"]
[Sun Aug 30 03:07:33.727348 2026] [security2:error] [pid 502397:tid 502599] [client 20.104.50.220:31842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wikindex.php"] [unique_id "apPkxWuFRxhFZfnD0nIwxAAAAVE"]
[Sun Aug 30 03:07:33.742397 2026] [authz_core:error] [pid 502397:tid 502555] [client 66.249.66.70:36030] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:33.742761 2026] [authz_core:error] [pid 502397:tid 502555] [client 66.249.66.70:36030] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:33.748235 2026] [security2:error] [pid 502397:tid 502644] [client 20.104.18.15:28658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/shiny.php"] [unique_id "apPkxWuFRxhFZfnD0nIw0wAAAX4"]
[Sun Aug 30 03:07:33.748245 2026] [security2:error] [pid 499145:tid 499380] [client 20.104.18.15:18412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/img.php"] [unique_id "apPkxVJNq1G5uRhTNnt89AAAAGk"]
[Sun Aug 30 03:07:33.749628 2026] [security2:error] [pid 502397:tid 502578] [client 4.205.62.107:64465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/paths.php"] [unique_id "apPkxWuFRxhFZfnD0nIw1AAAAT0"]
[Sun Aug 30 03:07:33.751860 2026] [security2:error] [pid 502397:tid 502593] [client 20.104.18.15:34794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/one.php"] [unique_id "apPkxWuFRxhFZfnD0nIw2AAAAUs"]
[Sun Aug 30 03:07:33.756267 2026] [authz_core:error] [pid 502397:tid 502603] [client 216.73.216.128:53231] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:33.756541 2026] [authz_core:error] [pid 502397:tid 502603] [client 216.73.216.128:53231] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:33.770868 2026] [security2:error] [pid 502397:tid 502626] [client 20.104.50.220:33176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/donate.php"] [unique_id "apPkxWuFRxhFZfnD0nIw3QAAAWw"]
[Sun Aug 30 03:07:33.775911 2026] [security2:error] [pid 502397:tid 502650] [client 4.205.62.107:22916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/config/laravolt/css/index.php"] [unique_id "apPkxWuFRxhFZfnD0nIw4AAAAYQ"]
[Sun Aug 30 03:07:33.785620 2026] [security2:error] [pid 499145:tid 499385] [client 4.205.62.107:35969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/localconf.php"] [unique_id "apPkxVJNq1G5uRhTNnt9BAAAAG4"]
[Sun Aug 30 03:07:33.786630 2026] [security2:error] [pid 502397:tid 502581] [client 20.104.50.220:47057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/zone.php"] [unique_id "apPkxWuFRxhFZfnD0nIw5gAAAUA"]
[Sun Aug 30 03:07:33.787096 2026] [security2:error] [pid 502397:tid 502586] [client 20.48.251.3:4720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/userfuns.php"] [unique_id "apPkxWuFRxhFZfnD0nIw5wAAAUU"]
[Sun Aug 30 03:07:33.796494 2026] [security2:error] [pid 499145:tid 499363] [client 20.48.251.3:49961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/var/www/wallet/index.php"] [unique_id "apPkxVJNq1G5uRhTNnt9CQAAAFg"]
[Sun Aug 30 03:07:33.801946 2026] [security2:error] [pid 499145:tid 499364] [client 20.104.18.15:51663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/radio.php"] [unique_id "apPkxVJNq1G5uRhTNnt9DgAAAFk"]
[Sun Aug 30 03:07:33.803678 2026] [security2:error] [pid 499145:tid 499298] [client 20.104.104.62:14336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/4e.php"] [unique_id "apPkxVJNq1G5uRhTNnt9EAAAABc"]
[Sun Aug 30 03:07:33.806445 2026] [security2:error] [pid 499145:tid 499306] [client 20.63.81.20:4239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/alfanew.php"] [unique_id "apPkxVJNq1G5uRhTNnt9FAAAAB8"]
[Sun Aug 30 03:07:33.811433 2026] [security2:error] [pid 502397:tid 502543] [client 20.104.18.15:23467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/mac.php"] [unique_id "apPkxWuFRxhFZfnD0nIw7wAAARo"]
[Sun Aug 30 03:07:33.814152 2026] [security2:error] [pid 499145:tid 499373] [client 4.205.62.107:2125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/old_phpinfo.php"] [unique_id "apPkxVJNq1G5uRhTNnt9FgAAAGI"]
[Sun Aug 30 03:07:33.879320 2026] [security2:error] [pid 502397:tid 502626] [client 20.104.104.62:37463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/wk/index.php"] [unique_id "apPkxWuFRxhFZfnD0nIxCgAAAWw"]
[Sun Aug 30 03:07:33.901072 2026] [security2:error] [pid 502397:tid 502556] [client 40.83.93.50:13540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/gg.php"] [unique_id "apPkxWuFRxhFZfnD0nIxEAAAASc"]
[Sun Aug 30 03:07:33.902141 2026] [security2:error] [pid 502397:tid 502586] [client 20.104.18.15:13571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/replace.php"] [unique_id "apPkxWuFRxhFZfnD0nIxEgAAAUU"]
[Sun Aug 30 03:07:33.905608 2026] [core:error] [pid 502397:tid 502448] [remote 57.141.14.14:20008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:07:33.905623 2026] [core:error] [pid 502397:tid 502448] [remote 57.141.14.14:20008] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:07:33.920961 2026] [security2:error] [pid 499145:tid 499294] [client 20.104.49.130:48002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/m.php"] [unique_id "apPkxVJNq1G5uRhTNnt9PwAAABM"]
[Sun Aug 30 03:07:33.931816 2026] [security2:error] [pid 502397:tid 502579] [client 216.73.216.128:53231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/classes.html"] [unique_id "apPkxWuFRxhFZfnD0nIxGAAAAT4"]
[Sun Aug 30 03:07:33.933443 2026] [security2:error] [pid 499145:tid 499344] [client 20.63.81.20:4108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/ioxi.php"] [unique_id "apPkxVJNq1G5uRhTNnt9QwAAAEU"]
[Sun Aug 30 03:07:33.934801 2026] [security2:error] [pid 499145:tid 499296] [client 20.104.104.62:14804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/ssss.php"] [unique_id "apPkxVJNq1G5uRhTNnt9RAAAABU"]
[Sun Aug 30 03:07:33.954079 2026] [security2:error] [pid 502397:tid 502617] [client 20.196.209.81:19073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/alfa.php"] [unique_id "apPkxWuFRxhFZfnD0nIxHgAAAWM"]
[Sun Aug 30 03:07:33.954858 2026] [security2:error] [pid 499145:tid 499364] [client 20.104.18.15:29652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/biufile.php"] [unique_id "apPkxVJNq1G5uRhTNnt9UQAAAFk"]
[Sun Aug 30 03:07:33.975703 2026] [security2:error] [pid 502397:tid 502547] [client 40.83.93.50:9701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/tflow/pk.php"] [unique_id "apPkxWuFRxhFZfnD0nIxMwAAAR4"]
[Sun Aug 30 03:07:33.999912 2026] [security2:error] [pid 499145:tid 499308] [client 20.104.49.130:53575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/read.php"] [unique_id "apPkxVJNq1G5uRhTNnt9agAAACE"]
[Sun Aug 30 03:07:34.019080 2026] [security2:error] [pid 502397:tid 502530] [client 20.104.50.220:61987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/images/sym403.php"] [unique_id "apPkxmuFRxhFZfnD0nIxRgAAAQ0"]
[Sun Aug 30 03:07:34.026395 2026] [security2:error] [pid 502397:tid 502591] [client 20.104.104.62:37469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/dehnl.php"] [unique_id "apPkxmuFRxhFZfnD0nIxTAAAAUk"]
[Sun Aug 30 03:07:34.026885 2026] [security2:error] [pid 502397:tid 502600] [client 4.205.62.107:17840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/drykl.php"] [unique_id "apPkxmuFRxhFZfnD0nIxTQAAAVI"]
[Sun Aug 30 03:07:34.061415 2026] [security2:error] [pid 499145:tid 499293] [client 20.63.81.20:4226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/TNT.php"] [unique_id "apPkxlJNq1G5uRhTNnt9jQAAABI"]
[Sun Aug 30 03:07:34.061561 2026] [security2:error] [pid 502397:tid 502557] [client 20.104.104.62:14828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/zoz.php"] [unique_id "apPkxmuFRxhFZfnD0nIxZwAAASg"]
[Sun Aug 30 03:07:34.121174 2026] [authz_core:error] [pid 502397:tid 502597] [client 216.73.216.128:30842] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:34.121478 2026] [authz_core:error] [pid 502397:tid 502597] [client 216.73.216.128:30842] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:34.158615 2026] [security2:error] [pid 502397:tid 502591] [client 20.104.104.62:35366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/png.php"] [unique_id "apPkxmuFRxhFZfnD0nIxqwAAAUk"]
[Sun Aug 30 03:07:34.189714 2026] [security2:error] [pid 502397:tid 502648] [client 20.63.81.20:4307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/cd.php"] [unique_id "apPkxmuFRxhFZfnD0nIxvwAAAYI"]
[Sun Aug 30 03:07:34.195879 2026] [security2:error] [pid 502397:tid 502572] [client 20.104.50.220:52850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/.well-known/403.php"] [unique_id "apPkxmuFRxhFZfnD0nIxwgAAATc"]
[Sun Aug 30 03:07:34.198113 2026] [security2:error] [pid 502397:tid 502530] [client 20.104.104.62:14833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/kcs.php"] [unique_id "apPkxmuFRxhFZfnD0nIxxQAAAQ0"]
[Sun Aug 30 03:07:34.243091 2026] [security2:error] [pid 502397:tid 502630] [client 20.48.251.3:64427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/nzv.php"] [unique_id "apPkxmuFRxhFZfnD0nIx1AAAAXA"]
[Sun Aug 30 03:07:34.247747 2026] [authz_core:error] [pid 499145:tid 499336] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:34.248050 2026] [authz_core:error] [pid 499145:tid 499336] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:34.254926 2026] [authz_core:error] [pid 502397:tid 502635] [client 66.249.66.68:60824] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:34.255230 2026] [authz_core:error] [pid 502397:tid 502635] [client 66.249.66.68:60824] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:34.297586 2026] [security2:error] [pid 502397:tid 502549] [client 20.104.104.62:37457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/txets.php"] [unique_id "apPkxmuFRxhFZfnD0nIyHQAAASA"]
[Sun Aug 30 03:07:34.310547 2026] [security2:error] [pid 502397:tid 502547] [client 20.104.49.130:60669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/gecko-new.php"] [unique_id "apPkxmuFRxhFZfnD0nIyLAAAAR4"]
[Sun Aug 30 03:07:34.317384 2026] [security2:error] [pid 499145:tid 499294] [client 20.63.81.20:4096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/luuf.php"] [unique_id "apPkxlJNq1G5uRhTNnt96wAAABM"]
[Sun Aug 30 03:07:34.339405 2026] [authz_core:error] [pid 502397:tid 502551] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:34.339698 2026] [authz_core:error] [pid 502397:tid 502551] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:34.350281 2026] [security2:error] [pid 502397:tid 502633] [client 20.196.209.81:19132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/wp-blog-header.php"] [unique_id "apPkxmuFRxhFZfnD0nIyUQAAAXM"]
[Sun Aug 30 03:07:34.366313 2026] [security2:error] [pid 502397:tid 502642] [client 20.104.50.220:63493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/googlebots.php"] [unique_id "apPkxmuFRxhFZfnD0nIyXAAAAXw"]
[Sun Aug 30 03:07:34.390273 2026] [security2:error] [pid 502397:tid 502566] [client 20.104.104.62:14820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/tajj.php"] [unique_id "apPkxmuFRxhFZfnD0nIyZQAAATE"]
[Sun Aug 30 03:07:34.420601 2026] [security2:error] [pid 502397:tid 502626] [client 40.83.93.50:13520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/defaults.php"] [unique_id "apPkxmuFRxhFZfnD0nIygwAAAWw"]
[Sun Aug 30 03:07:34.425522 2026] [security2:error] [pid 502397:tid 502653] [client 20.104.104.62:37470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/wp-login.php"] [unique_id "apPkxmuFRxhFZfnD0nIyhAAAAYc"]
[Sun Aug 30 03:07:34.450662 2026] [security2:error] [pid 502397:tid 502637] [client 40.83.93.50:5958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/theme-check/theme-check.php"] [unique_id "apPkxmuFRxhFZfnD0nIyiwAAAXc"]
[Sun Aug 30 03:07:34.451780 2026] [security2:error] [pid 502397:tid 502565] [client 20.63.81.20:4477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/fex.php"] [unique_id "apPkxmuFRxhFZfnD0nIyjgAAATA"]
[Sun Aug 30 03:07:34.515662 2026] [security2:error] [pid 499145:tid 499363] [client 68.155.159.216:63519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-blog-header.php"] [unique_id "apPkxlJNq1G5uRhTNnt-UAAAAFg"]
[Sun Aug 30 03:07:34.519764 2026] [security2:error] [pid 499145:tid 499303] [client 20.104.104.62:14802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/bge.php"] [unique_id "apPkxlJNq1G5uRhTNnt-VgAAABw"]
[Sun Aug 30 03:07:34.534895 2026] [authz_core:error] [pid 502397:tid 502629] [client 216.73.216.128:14113] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:34.535162 2026] [authz_core:error] [pid 502397:tid 502629] [client 216.73.216.128:14113] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:34.563349 2026] [security2:error] [pid 499145:tid 499324] [client 20.104.104.62:37464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/wp-access.php"] [unique_id "apPkxlJNq1G5uRhTNnt-bQAAADE"]
[Sun Aug 30 03:07:34.578789 2026] [security2:error] [pid 502397:tid 502583] [client 20.63.81.20:4150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/l.php"] [unique_id "apPkxmuFRxhFZfnD0nIy_QAAAUI"]
[Sun Aug 30 03:07:34.594356 2026] [security2:error] [pid 502397:tid 502545] [client 20.104.18.15:43963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/xmini4.php"] [unique_id "apPkxmuFRxhFZfnD0nIzDAAAARw"]
[Sun Aug 30 03:07:34.617182 2026] [security2:error] [pid 502397:tid 502535] [client 68.155.159.216:11227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apPkxmuFRxhFZfnD0nIzEgAAARI"]
[Sun Aug 30 03:07:34.654012 2026] [security2:error] [pid 502397:tid 502587] [client 20.104.104.62:14821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/ssh3ll.php"] [unique_id "apPkxmuFRxhFZfnD0nIzFAAAAUY"]
[Sun Aug 30 03:07:34.704716 2026] [security2:error] [pid 502397:tid 502595] [client 20.63.81.20:4136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/xr.php"] [unique_id "apPkxmuFRxhFZfnD0nIzJAAAAU0"]
[Sun Aug 30 03:07:34.735489 2026] [security2:error] [pid 502397:tid 502543] [client 20.104.104.62:41090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/wp-content/admin.php"] [unique_id "apPkxmuFRxhFZfnD0nIzQwAAARo"]
[Sun Aug 30 03:07:34.739428 2026] [security2:error] [pid 502397:tid 502633] [client 114.119.158.216:65129] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "southerncruzinmobility.com"] [uri "/index.php/product/cruzin-cooler-cz-hb-sport-x"] [unique_id "apPkxmuFRxhFZfnD0nIzRQAAAXM"], referer: https://southerncruzinmobility.com/index.php/product/duelly-kit
[Sun Aug 30 03:07:34.740817 2026] [authz_core:error] [pid 502397:tid 502593] [client 66.249.66.201:40473] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:34.741262 2026] [authz_core:error] [pid 502397:tid 502593] [client 66.249.66.201:40473] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:34.749470 2026] [security2:error] [pid 502397:tid 502585] [client 68.155.159.216:54259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-content/radio.php"] [unique_id "apPkxmuFRxhFZfnD0nIzTwAAAUQ"]
[Sun Aug 30 03:07:34.767487 2026] [security2:error] [pid 499145:tid 499373] [client 20.104.50.220:17295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "apPkxlJNq1G5uRhTNnt-tAAAAGI"]
[Sun Aug 30 03:07:34.768395 2026] [security2:error] [pid 502397:tid 502613] [client 20.196.209.81:1989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/s.php"] [unique_id "apPkxmuFRxhFZfnD0nIzVQAAAV8"]
[Sun Aug 30 03:07:34.781281 2026] [security2:error] [pid 502397:tid 502649] [client 20.104.50.220:27527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/common.php"] [unique_id "apPkxmuFRxhFZfnD0nIzXgAAAYM"]
[Sun Aug 30 03:07:34.781639 2026] [security2:error] [pid 502397:tid 502527] [client 20.104.104.62:14338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/motu.php"] [unique_id "apPkxmuFRxhFZfnD0nIzXwAAAQo"]
[Sun Aug 30 03:07:34.806037 2026] [security2:error] [pid 502397:tid 502535] [client 20.104.50.220:5587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/62.php"] [unique_id "apPkxmuFRxhFZfnD0nIzbAAAARI"]
[Sun Aug 30 03:07:34.812867 2026] [authz_core:error] [pid 502397:tid 502630] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:34.813185 2026] [authz_core:error] [pid 502397:tid 502630] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:34.824062 2026] [security2:error] [pid 502397:tid 502572] [client 68.155.159.216:12292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-includes/plugins.php"] [unique_id "apPkxmuFRxhFZfnD0nIzegAAATc"]
[Sun Aug 30 03:07:34.834081 2026] [security2:error] [pid 502397:tid 502582] [client 4.205.62.107:63963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/otuz1.php"] [unique_id "apPkxmuFRxhFZfnD0nIzggAAAUE"]
[Sun Aug 30 03:07:34.838806 2026] [security2:error] [pid 502397:tid 502592] [client 68.155.159.216:63955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-admin/images/index.php"] [unique_id "apPkxmuFRxhFZfnD0nIzhwAAAUo"]
[Sun Aug 30 03:07:34.839961 2026] [security2:error] [pid 502397:tid 502595] [client 20.48.251.3:33331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/btx25.php"] [unique_id "apPkxmuFRxhFZfnD0nIzigAAAU0"]
[Sun Aug 30 03:07:34.850067 2026] [security2:error] [pid 502397:tid 502527] [client 20.63.81.20:4154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/Q3.php"] [unique_id "apPkxmuFRxhFZfnD0nIzkwAAAQo"]
[Sun Aug 30 03:07:34.850194 2026] [security2:error] [pid 502397:tid 502603] [client 20.104.50.220:62836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/kalokataitusayagatauya.php"] [unique_id "apPkxmuFRxhFZfnD0nIzlAAAAVU"]
[Sun Aug 30 03:07:34.858766 2026] [security2:error] [pid 502397:tid 502648] [client 20.104.49.130:57472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/x1da.php"] [unique_id "apPkxmuFRxhFZfnD0nIzmwAAAYI"]
[Sun Aug 30 03:07:34.881722 2026] [security2:error] [pid 502397:tid 502560] [client 20.104.50.220:32267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-2019.php"] [unique_id "apPkxmuFRxhFZfnD0nIzowAAASs"]
[Sun Aug 30 03:07:34.885800 2026] [security2:error] [pid 502397:tid 502637] [client 20.104.104.62:37441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/log.php"] [unique_id "apPkxmuFRxhFZfnD0nIzpwAAAXc"]
[Sun Aug 30 03:07:34.891866 2026] [security2:error] [pid 499145:tid 499389] [client 20.104.18.15:18385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/222.php"] [unique_id "apPkxlJNq1G5uRhTNnt-2gAAAHI"]
[Sun Aug 30 03:07:34.893191 2026] [security2:error] [pid 499145:tid 499285] [client 20.104.18.15:28548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/images.php"] [unique_id "apPkxlJNq1G5uRhTNnt-2wAAAAo"]
[Sun Aug 30 03:07:34.896114 2026] [security2:error] [pid 502397:tid 502590] [client 4.205.62.107:64477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/olfclass.php"] [unique_id "apPkxmuFRxhFZfnD0nIzrAAAAUg"]
[Sun Aug 30 03:07:34.915999 2026] [security2:error] [pid 502397:tid 502613] [client 68.155.159.216:60923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apPkxmuFRxhFZfnD0nIztgAAAV8"]
[Sun Aug 30 03:07:34.917396 2026] [security2:error] [pid 502397:tid 502635] [client 20.104.104.62:14842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/wefile.php"] [unique_id "apPkxmuFRxhFZfnD0nIzuAAAAXU"]
[Sun Aug 30 03:07:34.921368 2026] [security2:error] [pid 502397:tid 502629] [client 20.104.18.15:34776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/503.php"] [unique_id "apPkxmuFRxhFZfnD0nIzuwAAAW8"]
[Sun Aug 30 03:07:34.923529 2026] [security2:error] [pid 502397:tid 502583] [client 20.104.50.220:33342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/tntmar.php"] [unique_id "apPkxmuFRxhFZfnD0nIzvAAAAUI"]
[Sun Aug 30 03:07:34.927998 2026] [security2:error] [pid 502397:tid 502573] [client 20.48.251.3:4687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/mamzi.php"] [unique_id "apPkxmuFRxhFZfnD0nIzvgAAATg"]
[Sun Aug 30 03:07:34.929862 2026] [security2:error] [pid 502397:tid 502532] [client 4.205.62.107:62415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/87.php"] [unique_id "apPkxmuFRxhFZfnD0nIzvwAAAQ8"]
[Sun Aug 30 03:07:34.932174 2026] [security2:error] [pid 499145:tid 499345] [client 40.83.93.50:11471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/theme/about.php"] [unique_id "apPkxlJNq1G5uRhTNnt-5AAAAEY"]
[Sun Aug 30 03:07:34.932233 2026] [security2:error] [pid 502397:tid 502618] [client 20.48.250.41:60798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkxmuFRxhFZfnD0nIzwAAAAWQ"]
[Sun Aug 30 03:07:34.934821 2026] [security2:error] [pid 502397:tid 502546] [client 40.83.93.50:12310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/h.php"] [unique_id "apPkxmuFRxhFZfnD0nIzwgAAAR0"]
[Sun Aug 30 03:07:34.935110 2026] [security2:error] [pid 502397:tid 502568] [client 20.48.251.3:34450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/124.php"] [unique_id "apPkxmuFRxhFZfnD0nIzwwAAATM"]
[Sun Aug 30 03:07:34.941894 2026] [security2:error] [pid 502397:tid 502600] [client 20.104.18.15:23515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/simple.php"] [unique_id "apPkxmuFRxhFZfnD0nIzxAAAAVI"]
[Sun Aug 30 03:07:34.942081 2026] [lsapi:error] [pid 502397:tid 502446] [remote 41.251.30.247:57448] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.google.com/
[Sun Aug 30 03:07:34.942095 2026] [lsapi:error] [pid 502397:tid 502446] [remote 41.251.30.247:57448] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.google.com/
[Sun Aug 30 03:07:34.943062 2026] [security2:error] [pid 499145:tid 499384] [client 4.205.62.107:35994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/bengi.php"] [unique_id "apPkxlJNq1G5uRhTNnt-6QAAAG0"]
[Sun Aug 30 03:07:34.943511 2026] [lsapi:error] [pid 502397:tid 502446] [remote 41.251.30.247:57448] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n, referer: https://www.google.com/
[Sun Aug 30 03:07:34.955812 2026] [security2:error] [pid 502397:tid 502614] [client 20.104.50.220:46619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/zx.php"] [unique_id "apPkxmuFRxhFZfnD0nIzzQAAAWA"]
[Sun Aug 30 03:07:34.968487 2026] [security2:error] [pid 502397:tid 502535] [client 20.104.18.15:51689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/one.php"] [unique_id "apPkxmuFRxhFZfnD0nIz4gAAARI"]
[Sun Aug 30 03:07:34.977465 2026] [security2:error] [pid 502397:tid 502540] [client 20.63.81.20:4111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/Q1.php"] [unique_id "apPkxmuFRxhFZfnD0nIz6QAAARc"]
[Sun Aug 30 03:07:34.983833 2026] [security2:error] [pid 499145:tid 499344] [client 4.205.62.107:2363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-8b8d40e1.ilmyst.com"] [uri "/wp-act.php"] [unique_id "apPkxlJNq1G5uRhTNnt--wAAAEU"]
[Sun Aug 30 03:07:35.005221 2026] [security2:error] [pid 502397:tid 502642] [client 20.151.200.44:55646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/xda.php"] [unique_id "apPkx2uFRxhFZfnD0nIz-AAAAXw"]
[Sun Aug 30 03:07:35.024241 2026] [security2:error] [pid 502397:tid 502585] [client 20.104.104.62:35342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/xwpg.php"] [unique_id "apPkx2uFRxhFZfnD0nI0BgAAAUQ"]
[Sun Aug 30 03:07:35.044952 2026] [security2:error] [pid 499145:tid 499375] [client 20.104.104.62:14345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/Contrller.php"] [unique_id "apPkx1JNq1G5uRhTNnt_FwAAAGQ"]
[Sun Aug 30 03:07:35.050587 2026] [security2:error] [pid 499145:tid 499349] [client 20.104.18.15:14280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/c4.php"] [unique_id "apPkx1JNq1G5uRhTNnt_GwAAAEo"]
[Sun Aug 30 03:07:35.064144 2026] [security2:error] [pid 502397:tid 502642] [client 20.197.61.180:7869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/aaa.php"] [unique_id "apPkx2uFRxhFZfnD0nI0JwAAAXw"]
[Sun Aug 30 03:07:35.065221 2026] [security2:error] [pid 502397:tid 502551] [client 20.104.49.130:60692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/wsd.php"] [unique_id "apPkx2uFRxhFZfnD0nI0KQAAASI"]
[Sun Aug 30 03:07:35.105830 2026] [security2:error] [pid 499145:tid 499384] [client 20.63.81.20:4170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/nz.php"] [unique_id "apPkx1JNq1G5uRhTNnt_OAAAAG0"]
[Sun Aug 30 03:07:35.108160 2026] [security2:error] [pid 499145:tid 499325] [client 20.104.18.15:29164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/blacks.php"] [unique_id "apPkx1JNq1G5uRhTNnt_OgAAADI"]
[Sun Aug 30 03:07:35.120458 2026] [security2:error] [pid 499145:tid 499342] [client 20.48.250.41:60776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkx1JNq1G5uRhTNnt_QQAAAEM"]
[Sun Aug 30 03:07:35.166100 2026] [security2:error] [pid 502397:tid 502624] [client 20.104.104.62:37462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/sxxb.php"] [unique_id "apPkx2uFRxhFZfnD0nI0WAAAAWo"]
[Sun Aug 30 03:07:35.182481 2026] [security2:error] [pid 502397:tid 502606] [client 20.196.209.81:1122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/php.php"] [unique_id "apPkx2uFRxhFZfnD0nI0YwAAAVg"]
[Sun Aug 30 03:07:35.190985 2026] [security2:error] [pid 502397:tid 502604] [client 20.104.104.62:14341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/file66.php"] [unique_id "apPkx2uFRxhFZfnD0nI0awAAAVY"]
[Sun Aug 30 03:07:35.197812 2026] [security2:error] [pid 502397:tid 502587] [client 20.104.49.130:60735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/dehnl.php"] [unique_id "apPkx2uFRxhFZfnD0nI0cAAAAUY"]
[Sun Aug 30 03:07:35.201256 2026] [security2:error] [pid 502397:tid 502603] [client 20.104.50.220:59545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/images/leafmailer2.8.php"] [unique_id "apPkx2uFRxhFZfnD0nI0dAAAAVU"]
[Sun Aug 30 03:07:35.202641 2026] [authz_core:error] [pid 502397:tid 502568] [client 66.249.66.35:52656] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:35.203122 2026] [authz_core:error] [pid 502397:tid 502568] [client 66.249.66.35:52656] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:35.209058 2026] [security2:error] [pid 502397:tid 502645] [client 4.205.62.107:17834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/rpk.php"] [unique_id "apPkx2uFRxhFZfnD0nI0gQAAAX8"]
[Sun Aug 30 03:07:35.233935 2026] [security2:error] [pid 502397:tid 502612] [client 20.63.81.20:4320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/sg.php"] [unique_id "apPkx2uFRxhFZfnD0nI0lQAAAV4"]
[Sun Aug 30 03:07:35.269444 2026] [authz_core:error] [pid 502397:tid 502576] [client 216.73.216.128:11694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:35.269929 2026] [authz_core:error] [pid 502397:tid 502576] [client 216.73.216.128:11694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:35.270900 2026] [security2:error] [pid 502397:tid 502632] [client 20.48.250.41:62494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/ff1.php"] [unique_id "apPkx2uFRxhFZfnD0nI0rwAAAXI"]
[Sun Aug 30 03:07:35.298620 2026] [security2:error] [pid 502397:tid 502640] [client 20.104.104.62:35340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/dx.php"] [unique_id "apPkx2uFRxhFZfnD0nI0wAAAAXo"]
[Sun Aug 30 03:07:35.318227 2026] [authz_core:error] [pid 502397:tid 502614] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_DK%2FLC_MESSAGES
[Sun Aug 30 03:07:35.318569 2026] [authz_core:error] [pid 502397:tid 502614] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_DK%2FLC_MESSAGES
[Sun Aug 30 03:07:35.324986 2026] [security2:error] [pid 502397:tid 502629] [client 20.151.200.44:55618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPkx2uFRxhFZfnD0nI05gAAAW8"]
[Sun Aug 30 03:07:35.329155 2026] [security2:error] [pid 502397:tid 502612] [client 20.104.50.220:29629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/.well-known/fox.php"] [unique_id "apPkx2uFRxhFZfnD0nI06gAAAV4"]
[Sun Aug 30 03:07:35.330288 2026] [security2:error] [pid 502397:tid 502537] [client 20.104.104.62:14793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/blnux.php"] [unique_id "apPkx2uFRxhFZfnD0nI06wAAARQ"]
[Sun Aug 30 03:07:35.375935 2026] [security2:error] [pid 502397:tid 502631] [client 20.63.81.20:4139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/hypo.php"] [unique_id "apPkx2uFRxhFZfnD0nI1GAAAAXE"]
[Sun Aug 30 03:07:35.400713 2026] [security2:error] [pid 502397:tid 502582] [client 40.83.93.50:5999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/theme/min.php"] [unique_id "apPkx2uFRxhFZfnD0nI1MgAAAUE"]
[Sun Aug 30 03:07:35.402527 2026] [security2:error] [pid 502397:tid 502551] [client 20.48.250.41:62466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/t.php"] [unique_id "apPkx2uFRxhFZfnD0nI1NAAAASI"]
[Sun Aug 30 03:07:35.410663 2026] [security2:error] [pid 502397:tid 502586] [client 103.153.183.69:10812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intentionalrounding.com"] [uri "/wp/index.php"] [unique_id "apPkx2uFRxhFZfnD0nI1OgAAAUU"]
[Sun Aug 30 03:07:35.415286 2026] [security2:error] [pid 502397:tid 502587] [client 40.83.93.50:13543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/num.php"] [unique_id "apPkx2uFRxhFZfnD0nI1QwAAAUY"]
[Sun Aug 30 03:07:35.438961 2026] [security2:error] [pid 502397:tid 502632] [client 20.104.104.62:37476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPkx2uFRxhFZfnD0nI1UwAAAXI"]
[Sun Aug 30 03:07:35.467327 2026] [security2:error] [pid 502397:tid 502546] [client 20.104.104.62:15302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/attack.php"] [unique_id "apPkx2uFRxhFZfnD0nI1ZAAAAR0"]
[Sun Aug 30 03:07:35.469897 2026] [authz_core:error] [pid 502397:tid 502566] [client 66.249.66.77:56402] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:35.470297 2026] [authz_core:error] [pid 502397:tid 502566] [client 66.249.66.77:56402] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:35.505889 2026] [security2:error] [pid 502397:tid 502595] [client 20.104.50.220:51549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/ben.php"] [unique_id "apPkx2uFRxhFZfnD0nI1iAAAAU0"]
[Sun Aug 30 03:07:35.516603 2026] [security2:error] [pid 502397:tid 502560] [client 20.48.251.3:7071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/66.php"] [unique_id "apPkx2uFRxhFZfnD0nI1lwAAASs"]
[Sun Aug 30 03:07:35.527068 2026] [security2:error] [pid 502397:tid 502565] [client 20.63.81.20:4291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/Hd.php"] [unique_id "apPkx2uFRxhFZfnD0nI1ogAAATA"]
[Sun Aug 30 03:07:35.533566 2026] [security2:error] [pid 502397:tid 502570] [client 20.48.250.41:62565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/erty.php"] [unique_id "apPkx2uFRxhFZfnD0nI1pgAAATU"]
[Sun Aug 30 03:07:35.584083 2026] [security2:error] [pid 502397:tid 502558] [client 20.196.209.81:1115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/system_log.php"] [unique_id "apPkx2uFRxhFZfnD0nI14gAAASk"]
[Sun Aug 30 03:07:35.585369 2026] [authz_core:error] [pid 502397:tid 502645] [client 216.73.216.128:11694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:35.585675 2026] [authz_core:error] [pid 502397:tid 502645] [client 216.73.216.128:11694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:35.588483 2026] [security2:error] [pid 499145:tid 499284] [client 20.104.104.62:35359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/xda.php"] [unique_id "apPkx1JNq1G5uRhTNnt_9wAAAAk"]
[Sun Aug 30 03:07:35.601837 2026] [security2:error] [pid 502397:tid 502599] [client 20.104.104.62:14349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/wk/index.php"] [unique_id "apPkx2uFRxhFZfnD0nI16AAAAVE"]
[Sun Aug 30 03:07:35.603817 2026] [security2:error] [pid 499145:tid 499379] [client 4.205.62.107:32463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPkx1JNq1G5uRhTNnuAAQAAAGg"]
[Sun Aug 30 03:07:35.605760 2026] [authz_core:error] [pid 499145:tid 499322] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:35.606035 2026] [authz_core:error] [pid 499145:tid 499322] [client 74.7.227.8:40984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:35.656920 2026] [security2:error] [pid 499145:tid 499282] [client 20.63.81.20:4181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/im.php"] [unique_id "apPkx1JNq1G5uRhTNnuAFAAAAAc"]
[Sun Aug 30 03:07:35.675221 2026] [security2:error] [pid 502397:tid 502544] [client 20.48.250.41:62572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/0x.php"] [unique_id "apPkx2uFRxhFZfnD0nI18wAAARs"]
[Sun Aug 30 03:07:35.725282 2026] [security2:error] [pid 502397:tid 502538] [client 68.155.159.216:11215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPkx2uFRxhFZfnD0nI2HQAAARU"]
[Sun Aug 30 03:07:35.732468 2026] [proxy_http:error] [pid 502397:tid 502593] (20014)Internal error (specific information not available): [client 34.125.55.247:47686] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:35.732491 2026] [proxy:error] [pid 502397:tid 502593] [client 34.125.55.247:47686] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.gcp/credentials.json
[Sun Aug 30 03:07:35.736562 2026] [security2:error] [pid 502397:tid 502641] [client 20.104.104.62:35328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/wp-admin/js/index.php"] [unique_id "apPkx2uFRxhFZfnD0nI2KAAAAXs"]
[Sun Aug 30 03:07:35.744615 2026] [security2:error] [pid 502397:tid 502632] [client 34.125.55.247:47816] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.engaginggoddaily.com"] [uri "/config.env"] [unique_id "apPkx2uFRxhFZfnD0nI2NgAAAXI"]
[Sun Aug 30 03:07:35.746064 2026] [security2:error] [pid 502397:tid 502543] [client 34.125.55.247:47916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/staging/.env"] [unique_id "apPkx2uFRxhFZfnD0nI2OAAAARo"]
[Sun Aug 30 03:07:35.746155 2026] [security2:error] [pid 502397:tid 502543] [client 34.125.55.247:47916] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/staging/.env"] [unique_id "apPkx2uFRxhFZfnD0nI2OAAAARo"]
[Sun Aug 30 03:07:35.749103 2026] [security2:error] [pid 502397:tid 502563] [client 20.104.104.62:14356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/dehnl.php"] [unique_id "apPkx2uFRxhFZfnD0nI2QAAAAS4"]
[Sun Aug 30 03:07:35.751878 2026] [security2:error] [pid 502397:tid 502555] [client 34.125.55.247:47930] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.engaginggoddaily.com"] [uri "/.azure/accessTokens.json"] [unique_id "apPkx2uFRxhFZfnD0nI2RwAAASY"]
[Sun Aug 30 03:07:35.753353 2026] [security2:error] [pid 502397:tid 502619] [client 34.125.55.247:47884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/dev/.env"] [unique_id "apPkx2uFRxhFZfnD0nI2SAAAAWU"]
[Sun Aug 30 03:07:35.753985 2026] [proxy_http:error] [pid 502397:tid 502578] (20014)Internal error (specific information not available): [client 34.125.55.247:47824] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:35.753999 2026] [proxy:error] [pid 502397:tid 502578] [client 34.125.55.247:47824] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/config/anthropic.json
[Sun Aug 30 03:07:35.757205 2026] [security2:error] [pid 502397:tid 502633] [client 20.104.18.15:44004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/gulu.php"] [unique_id "apPkx2uFRxhFZfnD0nI2TgAAAXM"]
[Sun Aug 30 03:07:35.762146 2026] [security2:error] [pid 502397:tid 502592] [client 34.125.55.247:47800] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/config/openai.json"] [unique_id "apPkx2uFRxhFZfnD0nI2OQAAAUo"]
[Sun Aug 30 03:07:35.767703 2026] [authz_core:error] [pid 502397:tid 502643] [client 66.249.66.74:59598] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:35.768169 2026] [authz_core:error] [pid 502397:tid 502643] [client 66.249.66.74:59598] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:35.769881 2026] [security2:error] [pid 502397:tid 502624] [client 34.125.55.247:47780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/client/.env"] [unique_id "apPkx2uFRxhFZfnD0nI2WwAAAWo"]
[Sun Aug 30 03:07:35.770267 2026] [proxy_http:error] [pid 502397:tid 502549] (20014)Internal error (specific information not available): [client 34.125.55.247:47902] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:35.770278 2026] [proxy:error] [pid 502397:tid 502549] [client 34.125.55.247:47902] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.env.docker
[Sun Aug 30 03:07:35.770506 2026] [authz_core:error] [pid 502397:tid 502540] [client 66.249.66.66:59881] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:35.771018 2026] [authz_core:error] [pid 502397:tid 502540] [client 66.249.66.66:59881] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:35.772085 2026] [security2:error] [pid 502397:tid 502565] [client 34.125.55.247:47758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/production/.env"] [unique_id "apPkx2uFRxhFZfnD0nI2XgAAATA"]
[Sun Aug 30 03:07:35.774132 2026] [security2:error] [pid 502397:tid 502553] [client 34.125.55.247:47878] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/backup/.env"] [unique_id "apPkx2uFRxhFZfnD0nI2YQAAASQ"]
[Sun Aug 30 03:07:35.774286 2026] [security2:error] [pid 502397:tid 502553] [client 34.125.55.247:47878] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/backup/.env"] [unique_id "apPkx2uFRxhFZfnD0nI2YQAAASQ"]
[Sun Aug 30 03:07:35.776913 2026] [security2:error] [pid 502397:tid 502593] [client 68.155.159.216:63511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apPkx2uFRxhFZfnD0nI2ZAAAAUs"]
[Sun Aug 30 03:07:35.777963 2026] [security2:error] [pid 502397:tid 502648] [client 34.125.55.247:47694] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/.gcp/service-account.json"] [unique_id "apPkx2uFRxhFZfnD0nI2PQAAAYI"]
[Sun Aug 30 03:07:35.778111 2026] [proxy_http:error] [pid 502397:tid 502610] (20014)Internal error (specific information not available): [client 34.125.55.247:47784] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:35.778124 2026] [proxy:error] [pid 502397:tid 502610] [client 34.125.55.247:47784] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/openai.json
[Sun Aug 30 03:07:35.783060 2026] [security2:error] [pid 502397:tid 502622] [client 20.104.49.130:60628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/dex.php"] [unique_id "apPkx2uFRxhFZfnD0nI2bAAAAWg"]
[Sun Aug 30 03:07:35.786060 2026] [proxy_http:error] [pid 502397:tid 502530] (20014)Internal error (specific information not available): [client 34.125.55.247:47926] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:35.786077 2026] [proxy:error] [pid 502397:tid 502530] [client 34.125.55.247:47926] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.github/workflows/deploy.yml
[Sun Aug 30 03:07:35.789906 2026] [security2:error] [pid 502397:tid 502614] [client 20.197.61.180:7837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/atomlib.php"] [unique_id "apPkx2uFRxhFZfnD0nI2cgAAAWA"]
[Sun Aug 30 03:07:35.793435 2026] [proxy_http:error] [pid 502397:tid 502578] (20014)Internal error (specific information not available): [client 34.125.55.247:47824] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:35.793454 2026] [proxy:error] [pid 502397:tid 502578] [client 34.125.55.247:47824] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml
[Sun Aug 30 03:07:35.796095 2026] [security2:error] [pid 499145:tid 499379] [client 20.63.81.20:4211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/fc.php"] [unique_id "apPkx1JNq1G5uRhTNnuASwAAAGg"]
[Sun Aug 30 03:07:35.800217 2026] [security2:error] [pid 502397:tid 502576] [client 34.125.55.247:47786] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/anthropic.json"] [unique_id "apPkx2uFRxhFZfnD0nI2SQAAATs"]
[Sun Aug 30 03:07:35.800361 2026] [proxy_http:error] [pid 502397:tid 502590] (20014)Internal error (specific information not available): [client 34.125.55.247:47798] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:35.800374 2026] [proxy:error] [pid 502397:tid 502590] [client 34.125.55.247:47798] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.env.anthropic
[Sun Aug 30 03:07:35.803931 2026] [security2:error] [pid 502397:tid 502559] [client 20.48.250.41:62489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/66.php"] [unique_id "apPkx2uFRxhFZfnD0nI2dwAAASo"]
[Sun Aug 30 03:07:35.807729 2026] [proxy_http:error] [pid 502397:tid 502550] (20014)Internal error (specific information not available): [client 34.125.55.247:47794] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:35.807757 2026] [proxy:error] [pid 502397:tid 502550] [client 34.125.55.247:47794] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/service-principal.json
[Sun Aug 30 03:07:35.815731 2026] [security2:error] [pid 502397:tid 502594] [client 34.125.55.247:47768] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/azure-credentials.json"] [unique_id "apPkx2uFRxhFZfnD0nI2UQAAAUw"]
[Sun Aug 30 03:07:35.822794 2026] [proxy_http:error] [pid 502397:tid 502597] (20014)Internal error (specific information not available): [client 34.125.55.247:47714] AH01102: error reading status line from remote server 127.0.0.1:2082, referer: https://cpanel.engaginggoddaily.com/gcp-service-account.json
[Sun Aug 30 03:07:35.830318 2026] [proxy_http:error] [pid 502397:tid 502549] (20014)Internal error (specific information not available): [client 34.125.55.247:47902] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:35.830332 2026] [proxy:error] [pid 502397:tid 502549] [client 34.125.55.247:47902] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml
[Sun Aug 30 03:07:35.837425 2026] [proxy_http:error] [pid 502397:tid 502637] (20014)Internal error (specific information not available): [client 34.125.55.247:47698] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:35.844871 2026] [proxy_http:error] [pid 502397:tid 502610] (20014)Internal error (specific information not available): [client 34.125.55.247:47784] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:35.844890 2026] [proxy:error] [pid 502397:tid 502610] [client 34.125.55.247:47784] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml
[Sun Aug 30 03:07:35.845032 2026] [security2:error] [pid 502397:tid 502610] [client 34.125.55.247:47784] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "502"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/502.shtml"] [unique_id "apPkx2uFRxhFZfnD0nI2PwAAAVw"]
[Sun Aug 30 03:07:35.851532 2026] [proxy_http:error] [pid 502397:tid 502620] (20014)Internal error (specific information not available): [client 34.125.55.247:47916] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:35.855211 2026] [authz_core:error] [pid 502397:tid 502653] [client 66.249.66.36:40170] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:35.855596 2026] [authz_core:error] [pid 502397:tid 502653] [client 66.249.66.36:40170] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:35.865051 2026] [authz_core:error] [pid 502397:tid 502619] [client 216.73.216.128:33889] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:35.865399 2026] [authz_core:error] [pid 502397:tid 502571] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AG%2FLC_MESSAGES
[Sun Aug 30 03:07:35.865512 2026] [authz_core:error] [pid 502397:tid 502619] [client 216.73.216.128:33889] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:35.865864 2026] [authz_core:error] [pid 502397:tid 502571] [client 74.7.243.204:41004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AG%2FLC_MESSAGES
[Sun Aug 30 03:07:35.866681 2026] [security2:error] [pid 502397:tid 502614] [client 20.104.104.62:37459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/t00l.php"] [unique_id "apPkx2uFRxhFZfnD0nI2lQAAAWA"]
[Sun Aug 30 03:07:35.879890 2026] [security2:error] [pid 502397:tid 502588] [client 20.104.104.62:14801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/png.php"] [unique_id "apPkx2uFRxhFZfnD0nI2ogAAAUc"]
[Sun Aug 30 03:07:35.883538 2026] [security2:error] [pid 502397:tid 502647] [client 114.119.145.151:41799] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "piako.ca"] [uri "/cdn/shop/products/PiaKoPPEDisposableGlovesBlue_09747250-60cb-4961-8e93-9e6e984f3f12_1024x1024.jpg"] [unique_id "apPkx2uFRxhFZfnD0nI2pAAAAYE"], referer: https://piako.ca/collections/protection-package/products/real-estate-industry-package
[Sun Aug 30 03:07:35.883587 2026] [proxy_http:error] [pid 502397:tid 502600] (20014)Internal error (specific information not available): [client 34.125.55.247:47842] AH01102: error reading status line from remote server 127.0.0.1:2082, referer: https://cpanel.engaginggoddaily.com/.flaskenv
[Sun Aug 30 03:07:35.887446 2026] [security2:error] [pid 502397:tid 502544] [client 40.83.93.50:5970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/themes/about.php"] [unique_id "apPkx2uFRxhFZfnD0nI2pgAAARs"]
[Sun Aug 30 03:07:35.887470 2026] [security2:error] [pid 502397:tid 502611] [client 68.155.159.216:55151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apPkx2uFRxhFZfnD0nI2pwAAAV0"]
[Sun Aug 30 03:07:35.892582 2026] [authz_core:error] [pid 499145:tid 499397] [client 66.249.66.67:47986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:35.892859 2026] [authz_core:error] [pid 499145:tid 499397] [client 66.249.66.67:47986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:35.925159 2026] [security2:error] [pid 502397:tid 502559] [client 20.63.81.20:4155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/ke.php"] [unique_id "apPkx2uFRxhFZfnD0nI2vwAAASo"]
[Sun Aug 30 03:07:35.926220 2026] [security2:error] [pid 502397:tid 502529] [client 20.104.50.220:27567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/Block.php"] [unique_id "apPkx2uFRxhFZfnD0nI2wQAAAQw"]
[Sun Aug 30 03:07:35.939827 2026] [security2:error] [pid 502397:tid 502546] [client 40.83.93.50:12289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/abc.php"] [unique_id "apPkx2uFRxhFZfnD0nI2xwAAAR0"]
[Sun Aug 30 03:07:35.940022 2026] [security2:error] [pid 499145:tid 499382] [client 68.155.159.216:12299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apPkx1JNq1G5uRhTNnuAdwAAAGs"]
[Sun Aug 30 03:07:35.943767 2026] [security2:error] [pid 502397:tid 502528] [client 20.104.50.220:6120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/61.php"] [unique_id "apPkx2uFRxhFZfnD0nI2yAAAAQs"]
[Sun Aug 30 03:07:35.960137 2026] [security2:error] [pid 502397:tid 502588] [client 68.155.159.216:65441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-includes/index.php"] [unique_id "apPkx2uFRxhFZfnD0nI21QAAAUc"]
[Sun Aug 30 03:07:35.977175 2026] [security2:error] [pid 502397:tid 502561] [client 4.205.62.107:64031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/update.php"] [unique_id "apPkx2uFRxhFZfnD0nI25gAAASw"]
[Sun Aug 30 03:07:35.983560 2026] [security2:error] [pid 502397:tid 502629] [client 20.48.251.3:33301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/app_dev.php"] [unique_id "apPkx2uFRxhFZfnD0nI28AAAAW8"]
[Sun Aug 30 03:07:35.993854 2026] [security2:error] [pid 502397:tid 502608] [client 20.104.50.220:63044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/jpg.php"] [unique_id "apPkx2uFRxhFZfnD0nI2-gAAAVo"]
[Sun Aug 30 03:07:36.002848 2026] [security2:error] [pid 499145:tid 499334] [client 20.48.250.41:62571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/f35.php"] [unique_id "apPkyFJNq1G5uRhTNnuAkwAAADs"]
[Sun Aug 30 03:07:36.038865 2026] [security2:error] [pid 502397:tid 502553] [client 20.196.209.81:5117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/w.php"] [unique_id "apPkyGuFRxhFZfnD0nI2_AAAASQ"]
[Sun Aug 30 03:07:36.140110 2026] [http2:info] [pid 503470:tid 503470] h2_workers: created with min=128 max=192 idle_ms=600000
[Sun Aug 30 03:07:36.159107 2026] [security2:error] [pid 503470:tid 503600] [client 20.104.18.15:18429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/key.php"] [unique_id "apPkyD8EKFABaii6jtPujAAAAIU"]
[Sun Aug 30 03:07:36.161669 2026] [security2:error] [pid 503470:tid 503601] [client 20.104.18.15:28567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/82.php"] [unique_id "apPkyD8EKFABaii6jtPujQAAAIY"]
[Sun Aug 30 03:07:36.162440 2026] [security2:error] [pid 503470:tid 503603] [client 20.104.18.15:23502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/xty.php"] [unique_id "apPkyD8EKFABaii6jtPujgAAAIg"]
[Sun Aug 30 03:07:36.162997 2026] [security2:error] [pid 503470:tid 503604] [client 20.104.104.62:41134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/ls.php"] [unique_id "apPkyD8EKFABaii6jtPukAAAAIk"]
[Sun Aug 30 03:07:36.163042 2026] [security2:error] [pid 503470:tid 503602] [client 20.104.50.220:32832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/dd.php"] [unique_id "apPkyD8EKFABaii6jtPujwAAAIc"]
[Sun Aug 30 03:07:36.163200 2026] [security2:error] [pid 503470:tid 503605] [client 4.205.62.107:61698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/gnmlc.php"] [unique_id "apPkyD8EKFABaii6jtPukQAAAIo"]
[Sun Aug 30 03:07:36.163961 2026] [security2:error] [pid 503470:tid 503606] [client 20.104.104.62:14360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/txets.php"] [unique_id "apPkyD8EKFABaii6jtPukgAAAIs"]
[Sun Aug 30 03:07:36.164122 2026] [security2:error] [pid 503470:tid 503607] [client 20.63.81.20:4148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/tf.php"] [unique_id "apPkyD8EKFABaii6jtPukwAAAIw"]
[Sun Aug 30 03:07:36.164761 2026] [security2:error] [pid 503470:tid 503611] [client 20.104.50.220:32277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-atom.php"] [unique_id "apPkyD8EKFABaii6jtPulQAAAJA"]
[Sun Aug 30 03:07:36.165042 2026] [security2:error] [pid 503470:tid 503614] [client 4.205.62.107:22555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/plss3.php"] [unique_id "apPkyD8EKFABaii6jtPulgAAAJM"]
[Sun Aug 30 03:07:36.165398 2026] [security2:error] [pid 503470:tid 503615] [client 4.205.62.107:35990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/i.php"] [unique_id "apPkyD8EKFABaii6jtPulwAAAJQ"]
[Sun Aug 30 03:07:36.165433 2026] [security2:error] [pid 503470:tid 503616] [client 20.48.251.3:5118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/public/rip.php.php"] [unique_id "apPkyD8EKFABaii6jtPumAAAAJU"]
[Sun Aug 30 03:07:36.165880 2026] [security2:error] [pid 503470:tid 503620] [client 20.104.50.220:46415] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "cpanel.ianegenolf.com"] [uri "/.conf.php"] [unique_id "apPkyD8EKFABaii6jtPumgAAAJk"]
[Sun Aug 30 03:07:36.166117 2026] [security2:error] [pid 503470:tid 503621] [client 20.48.251.3:12076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/test1.php"] [unique_id "apPkyD8EKFABaii6jtPumwAAAJo"]
[Sun Aug 30 03:07:36.166169 2026] [security2:error] [pid 503470:tid 503622] [client 20.104.18.15:34706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/504.php"] [unique_id "apPkyD8EKFABaii6jtPunAAAAJs"]
[Sun Aug 30 03:07:36.166569 2026] [security2:error] [pid 503470:tid 503624] [client 20.104.18.15:51620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/504.php"] [unique_id "apPkyD8EKFABaii6jtPunQAAAJ0"]
[Sun Aug 30 03:07:36.179439 2026] [security2:error] [pid 503470:tid 503682] [client 20.48.250.41:60756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/wen.php"] [unique_id "apPkyD8EKFABaii6jtPutQAAANc"]
[Sun Aug 30 03:07:36.190938 2026] [security2:error] [pid 503470:tid 503684] [client 20.104.49.130:57636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/1xmomo.php"] [unique_id "apPkyD8EKFABaii6jtPu0QAAANk"]
[Sun Aug 30 03:07:36.208874 2026] [security2:error] [pid 503470:tid 503697] [client 68.155.159.216:60903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/classwithtostring.php"] [unique_id "apPkyD8EKFABaii6jtPu2QAAAOY"]
[Sun Aug 30 03:07:36.217281 2026] [security2:error] [pid 503470:tid 503601] [client 20.104.18.15:13587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/rxr.php"] [unique_id "apPkyD8EKFABaii6jtPu_gAAAIY"]
[Sun Aug 30 03:07:36.222944 2026] [authz_core:error] [pid 503470:tid 503613] [client 216.73.216.128:44299] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:36.223470 2026] [authz_core:error] [pid 503470:tid 503613] [client 216.73.216.128:44299] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:36.253778 2026] [security2:error] [pid 503470:tid 503656] [client 20.104.18.15:29657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/wp.php"] [unique_id "apPkyD8EKFABaii6jtPvOwAAAL0"]
[Sun Aug 30 03:07:36.299788 2026] [security2:error] [pid 503470:tid 503690] [client 20.63.81.20:4184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/px.php"] [unique_id "apPkyD8EKFABaii6jtPvawAAAN8"]
[Sun Aug 30 03:07:36.303701 2026] [security2:error] [pid 503470:tid 503630] [client 20.104.104.62:35337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/css/000.php"] [unique_id "apPkyD8EKFABaii6jtPvcAAAAKM"]
[Sun Aug 30 03:07:36.309568 2026] [security2:error] [pid 503470:tid 503679] [client 20.104.104.62:14795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/wp-login.php"] [unique_id "apPkyD8EKFABaii6jtPvdwAAANQ"]
[Sun Aug 30 03:07:36.322054 2026] [security2:error] [pid 499145:tid 499361] [client 114.119.150.215:33721] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.djsevenevents.com"] [uri "/wp-content/uploads/2020/01"] [unique_id "apPkyFJNq1G5uRhTNnuBAAAAAFY"], referer: http://www.djsevenevents.com/wp-content/uploads/2020/01?C=M%3BO%3DA
[Sun Aug 30 03:07:36.351624 2026] [security2:error] [pid 503470:tid 503671] [client 4.205.62.107:18677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/saml.php"] [unique_id "apPkyD8EKFABaii6jtPvnAAAAMw"]
[Sun Aug 30 03:07:36.359177 2026] [authz_core:error] [pid 503470:tid 503634] [client 66.249.66.192:47904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:36.359692 2026] [authz_core:error] [pid 503470:tid 503634] [client 66.249.66.192:47904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:36.373707 2026] [security2:error] [pid 503470:tid 503656] [client 20.104.50.220:61678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/images/lux.php"] [unique_id "apPkyD8EKFABaii6jtPvqAAAAL0"]
[Sun Aug 30 03:07:36.374198 2026] [security2:error] [pid 503470:tid 503725] [client 40.83.93.50:11469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/themes/panel.php"] [unique_id "apPkyD8EKFABaii6jtPvpwAAAQI"]
[Sun Aug 30 03:07:36.408072 2026] [security2:error] [pid 503470:tid 503691] [client 20.48.250.41:60796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/inc.php"] [unique_id "apPkyD8EKFABaii6jtPvxgAAAOA"]
[Sun Aug 30 03:07:36.416583 2026] [authz_core:error] [pid 503470:tid 503685] [client 66.249.66.78:42469] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:36.416990 2026] [authz_core:error] [pid 503470:tid 503685] [client 66.249.66.78:42469] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:36.428885 2026] [security2:error] [pid 503470:tid 503668] [client 20.63.81.20:4141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/jg.php"] [unique_id "apPkyD8EKFABaii6jtPv1gAAAMk"]
[Sun Aug 30 03:07:36.432787 2026] [security2:error] [pid 503470:tid 503686] [client 20.104.104.62:35368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/cy.php"] [unique_id "apPkyD8EKFABaii6jtPv3AAAANs"]
[Sun Aug 30 03:07:36.432975 2026] [security2:error] [pid 503470:tid 503695] [client 40.83.93.50:13567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/default.php"] [unique_id "apPkyD8EKFABaii6jtPv3QAAAOQ"]
[Sun Aug 30 03:07:36.438094 2026] [security2:error] [pid 503470:tid 503663] [client 20.104.104.62:14831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/wp-access.php"] [unique_id "apPkyD8EKFABaii6jtPv4gAAAMQ"]
[Sun Aug 30 03:07:36.461147 2026] [security2:error] [pid 503470:tid 503676] [client 20.196.209.81:20306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/wp.php"] [unique_id "apPkyD8EKFABaii6jtPv6QAAANE"]
[Sun Aug 30 03:07:36.467326 2026] [security2:error] [pid 503470:tid 503675] [client 20.104.50.220:29148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/.well-known/alfa.php"] [unique_id "apPkyD8EKFABaii6jtPv7wAAANA"]
[Sun Aug 30 03:07:36.491667 2026] [authz_core:error] [pid 503470:tid 503600] [client 66.249.66.198:51111] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:36.492061 2026] [authz_core:error] [pid 503470:tid 503600] [client 66.249.66.198:51111] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:36.524145 2026] [authz_core:error] [pid 499145:tid 499375] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AU%2FLC_MESSAGES
[Sun Aug 30 03:07:36.524528 2026] [authz_core:error] [pid 499145:tid 499375] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AU%2FLC_MESSAGES
[Sun Aug 30 03:07:36.537711 2026] [security2:error] [pid 503470:tid 503697] [client 20.197.61.180:7820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/buy.php"] [unique_id "apPkyD8EKFABaii6jtPwIwAAAOY"]
[Sun Aug 30 03:07:36.556146 2026] [security2:error] [pid 503470:tid 503650] [client 20.63.81.20:4134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/yj.php"] [unique_id "apPkyD8EKFABaii6jtPwMAAAALc"]
[Sun Aug 30 03:07:36.567206 2026] [security2:error] [pid 503470:tid 503655] [client 20.48.250.41:60684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/6bcwiqwj.php"] [unique_id "apPkyD8EKFABaii6jtPwOQAAALw"]
[Sun Aug 30 03:07:36.569928 2026] [security2:error] [pid 503470:tid 503701] [client 20.104.104.62:14817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/wp-content/admin.php"] [unique_id "apPkyD8EKFABaii6jtPwPAAAAOo"]
[Sun Aug 30 03:07:36.587122 2026] [security2:error] [pid 503470:tid 503637] [client 20.104.104.62:41089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/admin.php/pindex.php"] [unique_id "apPkyD8EKFABaii6jtPwTAAAAKo"]
[Sun Aug 30 03:07:36.659469 2026] [security2:error] [pid 499145:tid 499325] [client 20.104.50.220:51540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/9191.php"] [unique_id "apPkyFJNq1G5uRhTNnuBgQAAADI"]
[Sun Aug 30 03:07:36.677769 2026] [security2:error] [pid 502397:tid 502541] [client 65.108.6.34:50430] ModSecurity: Warning. Matched phrase "SEOkicks" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "flashflooring.co.uk"] [uri "/index.php"] [unique_id "apPkx2uFRxhFZfnD0nI1vQAAARg"], referer: https://flashflooring.co.uk/
[Sun Aug 30 03:07:36.687137 2026] [authz_core:error] [pid 503470:tid 503609] [client 216.73.216.128:44299] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:36.687565 2026] [authz_core:error] [pid 503470:tid 503609] [client 216.73.216.128:44299] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:36.700657 2026] [security2:error] [pid 503470:tid 503718] [client 20.63.81.20:4137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/zi.php"] [unique_id "apPkyD8EKFABaii6jtPwYQAAAPs"]
[Sun Aug 30 03:07:36.709793 2026] [security2:error] [pid 503470:tid 503616] [client 20.104.104.62:14832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/log.php"] [unique_id "apPkyD8EKFABaii6jtPwawAAAJU"]
[Sun Aug 30 03:07:36.732909 2026] [security2:error] [pid 503470:tid 503663] [client 20.48.250.41:62472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/easy.php"] [unique_id "apPkyD8EKFABaii6jtPwhwAAAMQ"]
[Sun Aug 30 03:07:36.776072 2026] [security2:error] [pid 503470:tid 503638] [client 20.104.104.62:41100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/admin.php/csv.php"] [unique_id "apPkyD8EKFABaii6jtPwngAAAKs"]
[Sun Aug 30 03:07:36.837976 2026] [security2:error] [pid 503470:tid 503630] [client 20.63.81.20:4109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/ue.php"] [unique_id "apPkyD8EKFABaii6jtPwwAAAAKM"]
[Sun Aug 30 03:07:36.844452 2026] [security2:error] [pid 503470:tid 503601] [client 20.104.104.62:14794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/xwpg.php"] [unique_id "apPkyD8EKFABaii6jtPwxQAAAIY"]
[Sun Aug 30 03:07:36.845466 2026] [security2:error] [pid 503470:tid 503705] [client 68.155.159.216:56362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/images/index.php"] [unique_id "apPkyD8EKFABaii6jtPwyAAAAO4"]
[Sun Aug 30 03:07:36.861363 2026] [security2:error] [pid 503470:tid 503647] [client 20.196.209.81:1987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/composer.php"] [unique_id "apPkyD8EKFABaii6jtPw0wAAALQ"]
[Sun Aug 30 03:07:36.871320 2026] [security2:error] [pid 499145:tid 499283] [client 20.48.250.41:62549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/fresh3.php"] [unique_id "apPkyFJNq1G5uRhTNnuBwwAAAAg"]
[Sun Aug 30 03:07:36.886011 2026] [security2:error] [pid 503470:tid 503680] [client 20.48.251.3:6514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/admin.php"] [unique_id "apPkyD8EKFABaii6jtPw2gAAANU"]
[Sun Aug 30 03:07:36.911720 2026] [security2:error] [pid 503470:tid 503711] [client 40.83.93.50:18537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/cloud.php"] [unique_id "apPkyD8EKFABaii6jtPw5AAAAPQ"]
[Sun Aug 30 03:07:36.916602 2026] [security2:error] [pid 503470:tid 503654] [client 20.104.104.62:35329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/admin.php/700.php"] [unique_id "apPkyD8EKFABaii6jtPw5wAAALs"]
[Sun Aug 30 03:07:36.959448 2026] [security2:error] [pid 503470:tid 503601] [client 20.104.18.15:43995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/replace.php"] [unique_id "apPkyD8EKFABaii6jtPw-QAAAIY"]
[Sun Aug 30 03:07:36.974108 2026] [security2:error] [pid 503470:tid 503656] [client 20.104.104.62:14815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/sxxb.php"] [unique_id "apPkyD8EKFABaii6jtPxCAAAAL0"]
[Sun Aug 30 03:07:36.975053 2026] [security2:error] [pid 503470:tid 503646] [client 114.119.159.236:30177] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kamiaiibeauty.com"] [uri "/%E0%B8%AA%E0%B8%B4%E0%B8%99%E0%B8%84%E0%B9%89%E0%B8%B2%E0%B8%97%E0%B8%B1%E0%B9%89%E0%B8%87%E0%B8%AB%E0%B8%A1%E0%B8%94/%E0%B8%9A%E0%B8%B3%E0%B8%A3%E0%B8%B8%E0%B8%87%E0%B8%9C%E0%B8%B4%E0%B8%A7%E0%B8%9E%E0%B8%A3%E0%B8%A3%E0%B8%93/%E0%B8%AA%E0%B8%B1%E0%B9%88%E0%B8%87%E0%B9%80%E0%B8%8B%E0%B8%97%E0%B8%95%E0%B8%B2%E0%B8%A1%E0%B8%A3%E0%B8%B5%E0%B8%A7%E0%B8%B4%E0%B8%A7-%E0%B9%80%E0%B8%8B%E0%B8%97%E0%B8%A2%E0%B8%B2%E0%B9%81%E0%B8%A3%E0%B8%87%E0%B9%80%E0%B8%99%E0%B9%89%E0%B8%99%E0%B8%82%E0%B8%B2%E0%B8%A7%E0%B9%84%E0%B8%A7-%E0%B9%80%E0%B8%9B%E0%B8%A5%E0%B8%B5%E0%B9%88%E0%B8%A2%E0%B8%99%E0%B8%9C%E0%B8%B4%E0%B8%A7%E0%B8%84%E0%B8%A5%E0%B9%89%E0%B8%B3%E0%B9%80%E0%B8%AA%E0%B8%B5%E0%B8%A2%E0%B8%AA%E0%B8%B0%E0%B8%AA%E0%B8%A1%E0%B9%83%E0%B8%AB%E0%B9%89%E0%B8%82%E0%B8%B2%E0%B8%A7%E0%B9%83%E0%B8%AA%E0%B9%80%E0%B8%A3%E0%B9%88%E0%B8%87%E0%B8%94%E0%B9%88%E0%B8%A7%E0%B8%99/"] [unique_id "apPkyD8EKFABaii6jtPxCQAAALM"], referer: https://www.kamiaiibeauty.com/%E0%B8%AA%E0%B8%B4%E0%B8%99%E0%B8%84%E0%B9%89%E0%B8%B2%E0%B8%97%E0%B8%B1%E0%B9%89%E0%B8%87%E0%B8%AB%E0%B8%A1%E0%B8%94/%E0%B8%9A%E0%B8%B3%E0%B8%A3%E0%B8%B8%E0%B8%87%E0%B8%9C%E0%B8%B4%E0%B8%A7%E0%B8%9E%E0%B8%A3%E0%B8%A3%E0%B8%93/%E0%B8%AA%E0%B8%B1%E0%B9%88%E0%B8%87%E0%B9%80%E0%B8%8B%E0%B8%97%E0%B8%95%E0%B8%B2%E0%B8%A1%E0%B8%A3%E0%B8%B5%E0%B8%A7%E0%B8%B4%E0%B8%A7-%E0%B9%80%E0%B8%8B%E0%B8%97%E0%B8%A2%E0%B8%B2%E0%B9%81%E0%B8%A3%E0%B8%87%E0%B9%80%E0%B8%99%E0%B9%89%E0%B8%99%E0%B8%82%E0%B8%B2%E0%B8%A7%E0%B9%84%E0%B8%A7-%E0%B9%80%E0%B8%9B%E0%B8%A5%E0%B8%B5%E0%B9%88%E0%B8%A2%E0%B8%99%E0%B8%9C%E0%B8%B4%E0%B8%A7%E0%B8%84%E0%B8%A5%E0%B9%89%E0%B8%B3%E0%B9%80%E0%B8%AA%E0%B8%B5%E0%B8%A2%E0%B8%AA%E0%B8%B0%E0%B8%AA%E0%B8%A1%E0%B9%83%E0%B8%AB%E0%B9%89%E0%B8%82%E0%B8%B2%E0%B8%A7%E0%B9%83%E0%B8%AA%E0%B9%80%E0%B8%A3%E0%B9%88%E0%B8%87%E0%B8%94%E0%B9%88%E0%B8%A7%E0%B8%99/
[Sun Aug 30 03:07:36.982237 2026] [security2:error] [pid 503470:tid 503693] [client 20.63.81.20:4279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/nv.php"] [unique_id "apPkyD8EKFABaii6jtPxEwAAAOI"]
[Sun Aug 30 03:07:36.995557 2026] [security2:error] [pid 499145:tid 499364] [client 40.83.93.50:5325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/twentytwentyfive/styles/sections/pk.php"] [unique_id "apPkyFJNq1G5uRhTNnuB6gAAAFk"]
[Sun Aug 30 03:07:36.998532 2026] [security2:error] [pid 503470:tid 503631] [client 68.155.159.216:55095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/login.php"] [unique_id "apPkyD8EKFABaii6jtPxHgAAAKQ"]
[Sun Aug 30 03:07:37.012255 2026] [security2:error] [pid 503470:tid 503695] [client 20.48.250.41:60766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/bgymj.php"] [unique_id "apPkyT8EKFABaii6jtPxJwAAAOQ"]
[Sun Aug 30 03:07:37.032842 2026] [security2:error] [pid 499145:tid 499376] [client 68.155.159.216:63549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-admin/user/index.php"] [unique_id "apPkyVJNq1G5uRhTNnuB-gAAAGU"]
[Sun Aug 30 03:07:37.046081 2026] [security2:error] [pid 503470:tid 503608] [client 20.104.104.62:37460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/admin.php/007x.php"] [unique_id "apPkyT8EKFABaii6jtPxOgAAAI0"]
[Sun Aug 30 03:07:37.058597 2026] [security2:error] [pid 502397:tid 502628] [client 178.16.55.109:50114] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "neilgclark.com"] [uri "/index.php"] [unique_id "apPkyWuFRxhFZfnD0nI3AQAAAW4"]
[Sun Aug 30 03:07:37.059909 2026] [authz_core:error] [pid 503470:tid 503694] [client 74.7.227.8:38186] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:37.060369 2026] [authz_core:error] [pid 503470:tid 503694] [client 74.7.227.8:38186] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:37.063358 2026] [authz_core:error] [pid 499145:tid 499355] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:37.063823 2026] [authz_core:error] [pid 499145:tid 499355] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:37.067297 2026] [security2:error] [pid 503470:tid 503674] [client 20.104.50.220:27578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/wp-Block.php"] [unique_id "apPkyT8EKFABaii6jtPxSQAAAM8"]
[Sun Aug 30 03:07:37.080427 2026] [security2:error] [pid 503470:tid 503685] [client 68.155.159.216:12416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/goat1.php"] [unique_id "apPkyT8EKFABaii6jtPxTwAAANo"]
[Sun Aug 30 03:07:37.087796 2026] [security2:error] [pid 503470:tid 503620] [client 20.104.50.220:5898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/60.php"] [unique_id "apPkyT8EKFABaii6jtPxUQAAAJk"]
[Sun Aug 30 03:07:37.100906 2026] [security2:error] [pid 503470:tid 503714] [client 20.104.104.62:14840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/dx.php"] [unique_id "apPkyT8EKFABaii6jtPxXgAAAPc"]
[Sun Aug 30 03:07:37.100965 2026] [authz_core:error] [pid 499145:tid 499316] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_HK%2FLC_MESSAGES
[Sun Aug 30 03:07:37.101406 2026] [authz_core:error] [pid 499145:tid 499316] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_HK%2FLC_MESSAGES
[Sun Aug 30 03:07:37.115702 2026] [security2:error] [pid 503470:tid 503664] [client 20.63.81.20:4287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/jw.php"] [unique_id "apPkyT8EKFABaii6jtPxaAAAAMU"]
[Sun Aug 30 03:07:37.128857 2026] [security2:error] [pid 499145:tid 499388] [client 4.205.62.107:64058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/channels.php"] [unique_id "apPkyVJNq1G5uRhTNnuCGAAAAHE"]
[Sun Aug 30 03:07:37.132352 2026] [security2:error] [pid 503470:tid 503722] [client 20.104.50.220:52861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/jak.php"] [unique_id "apPkyT8EKFABaii6jtPxcQAAAP8"]
[Sun Aug 30 03:07:37.138060 2026] [security2:error] [pid 503470:tid 503629] [client 20.104.50.220:17307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-admin/css/colour.php"] [unique_id "apPkyT8EKFABaii6jtPxdwAAAKI"]
[Sun Aug 30 03:07:37.157798 2026] [security2:error] [pid 503470:tid 503672] [client 20.48.251.3:56333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/php-info.php"] [unique_id "apPkyT8EKFABaii6jtPxggAAAM0"]
[Sun Aug 30 03:07:37.182782 2026] [security2:error] [pid 503470:tid 503700] [client 68.155.159.216:63972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/mah.php"] [unique_id "apPkyT8EKFABaii6jtPxkwAAAOk"]
[Sun Aug 30 03:07:37.187822 2026] [security2:error] [pid 503470:tid 503705] [client 20.104.104.62:37495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/admin.php/heex.php"] [unique_id "apPkyT8EKFABaii6jtPxmAAAAO4"]
[Sun Aug 30 03:07:37.189117 2026] [security2:error] [pid 503470:tid 503601] [client 20.48.250.41:60741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/ws69.php"] [unique_id "apPkyT8EKFABaii6jtPxnQAAAIY"]
[Sun Aug 30 03:07:37.230166 2026] [security2:error] [pid 503470:tid 503662] [client 20.104.104.62:15316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPkyT8EKFABaii6jtPxsQAAAMM"]
[Sun Aug 30 03:07:37.245065 2026] [security2:error] [pid 503470:tid 503649] [client 20.63.81.20:4115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/or.php"] [unique_id "apPkyT8EKFABaii6jtPxugAAALY"]
[Sun Aug 30 03:07:37.270612 2026] [security2:error] [pid 503470:tid 503485] [remote 40.77.167.38:47570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "concordservices-bali.com"] [uri "/Detail.php"] [unique_id "apPkyT8EKFABaii6jtPxxwABAQ4"]
[Sun Aug 30 03:07:37.275722 2026] [security2:error] [pid 499145:tid 499288] [client 20.197.61.180:9369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/hello.php"] [unique_id "apPkyVJNq1G5uRhTNnuCXgAAAA0"]
[Sun Aug 30 03:07:37.284175 2026] [security2:error] [pid 503470:tid 503648] [client 20.196.209.81:1148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/abcd.php"] [unique_id "apPkyT8EKFABaii6jtPx2QAAALU"]
[Sun Aug 30 03:07:37.295109 2026] [authz_core:error] [pid 499145:tid 499282] [client 66.249.66.33:57699] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:37.295558 2026] [authz_core:error] [pid 499145:tid 499282] [client 66.249.66.33:57699] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:37.297838 2026] [security2:error] [pid 503470:tid 503644] [client 4.205.62.107:36002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/guk.php"] [unique_id "apPkyT8EKFABaii6jtPx3wAAALE"]
[Sun Aug 30 03:07:37.302739 2026] [security2:error] [pid 503470:tid 503722] [client 20.104.18.15:34813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/admin.php"] [unique_id "apPkyT8EKFABaii6jtPx5QAAAP8"]
[Sun Aug 30 03:07:37.305031 2026] [security2:error] [pid 499145:tid 499394] [client 20.104.18.15:28654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/files.php/new.php"] [unique_id "apPkyVJNq1G5uRhTNnuCcAAAAHc"]
[Sun Aug 30 03:07:37.305619 2026] [security2:error] [pid 503470:tid 503663] [client 20.104.18.15:18372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/chosen.php"] [unique_id "apPkyT8EKFABaii6jtPx5wAAAMQ"]
[Sun Aug 30 03:07:37.307117 2026] [security2:error] [pid 503470:tid 503600] [client 4.205.62.107:64486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/koiy.php"] [unique_id "apPkyT8EKFABaii6jtPx6AAAAIU"]
[Sun Aug 30 03:07:37.313661 2026] [security2:error] [pid 503470:tid 503710] [client 20.104.50.220:46852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/decer.php"] [unique_id "apPkyT8EKFABaii6jtPx8AAAAPM"]
[Sun Aug 30 03:07:37.317307 2026] [security2:error] [pid 503470:tid 503671] [client 20.104.18.15:51696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/ano.php"] [unique_id "apPkyT8EKFABaii6jtPx8QAAAMw"]
[Sun Aug 30 03:07:37.318728 2026] [security2:error] [pid 503470:tid 503691] [client 20.104.104.62:35361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/tf.php"] [unique_id "apPkyT8EKFABaii6jtPx8gAAAOA"]
[Sun Aug 30 03:07:37.319419 2026] [security2:error] [pid 503470:tid 503666] [client 20.104.18.15:23455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/sallu.php"] [unique_id "apPkyT8EKFABaii6jtPx8wAAAMc"]
[Sun Aug 30 03:07:37.320198 2026] [authz_core:error] [pid 503470:tid 503674] [client 216.73.216.128:41450] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:37.320679 2026] [authz_core:error] [pid 503470:tid 503674] [client 216.73.216.128:41450] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:37.321368 2026] [security2:error] [pid 503470:tid 503634] [client 20.48.251.3:34471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/wdf.php"] [unique_id "apPkyT8EKFABaii6jtPx9AAAAKc"]
[Sun Aug 30 03:07:37.328611 2026] [security2:error] [pid 503470:tid 503665] [client 20.48.251.3:4806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/environment.php"] [unique_id "apPkyT8EKFABaii6jtPx-wAAAMY"]
[Sun Aug 30 03:07:37.329683 2026] [security2:error] [pid 503470:tid 503657] [client 20.151.200.44:55694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/t00l.php"] [unique_id "apPkyT8EKFABaii6jtPx_AAAAL4"]
[Sun Aug 30 03:07:37.334701 2026] [security2:error] [pid 503470:tid 503716] [client 20.104.50.220:32720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-bita.php"] [unique_id "apPkyT8EKFABaii6jtPx_wAAAPk"]
[Sun Aug 30 03:07:37.335517 2026] [security2:error] [pid 503470:tid 503673] [client 20.48.250.41:62503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/ccs.php"] [unique_id "apPkyT8EKFABaii6jtPyAQAAAM4"]
[Sun Aug 30 03:07:37.336747 2026] [security2:error] [pid 503470:tid 503659] [client 4.205.62.107:62407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/aws.php"] [unique_id "apPkyT8EKFABaii6jtPyBAAAAMA"]
[Sun Aug 30 03:07:37.364998 2026] [security2:error] [pid 503470:tid 503640] [client 20.104.18.15:13651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.quieroestudiarmedicina.es"] [uri "/reviall.php"] [unique_id "apPkyT8EKFABaii6jtPyFgAAAK0"]
[Sun Aug 30 03:07:37.382895 2026] [security2:error] [pid 503470:tid 503680] [client 20.63.81.20:4133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/ile56.php"] [unique_id "apPkyT8EKFABaii6jtPyHQAAANU"]
[Sun Aug 30 03:07:37.395024 2026] [security2:error] [pid 503470:tid 503656] [client 20.104.18.15:29651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/wander.php"] [unique_id "apPkyT8EKFABaii6jtPyKgAAAL0"]
[Sun Aug 30 03:07:37.400013 2026] [security2:error] [pid 503470:tid 503626] [client 20.104.104.62:14366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/xda.php"] [unique_id "apPkyT8EKFABaii6jtPyLgAAAJ8"]
[Sun Aug 30 03:07:37.413385 2026] [authz_core:error] [pid 503470:tid 503611] [client 216.73.216.128:37437] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:37.413827 2026] [authz_core:error] [pid 503470:tid 503611] [client 216.73.216.128:37437] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:37.419747 2026] [security2:error] [pid 503470:tid 503698] [client 4.205.62.107:32046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/agg.php"] [unique_id "apPkyT8EKFABaii6jtPyPwAAAOc"]
[Sun Aug 30 03:07:37.433692 2026] [security2:error] [pid 503470:tid 503722] [client 20.151.200.44:57876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkyT8EKFABaii6jtPyUwAAAP8"]
[Sun Aug 30 03:07:37.450474 2026] [security2:error] [pid 503470:tid 503700] [client 20.104.104.62:35348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/update/da222.php"] [unique_id "apPkyT8EKFABaii6jtPyYQAAAOk"]
[Sun Aug 30 03:07:37.503864 2026] [security2:error] [pid 503470:tid 503650] [client 20.48.250.41:62582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/mar.php"] [unique_id "apPkyT8EKFABaii6jtPymAAAALc"]
[Sun Aug 30 03:07:37.504285 2026] [security2:error] [pid 503470:tid 503660] [client 40.83.93.50:12347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/admin.php"] [unique_id "apPkyT8EKFABaii6jtPymgAAAME"]
[Sun Aug 30 03:07:37.515598 2026] [security2:error] [pid 503470:tid 503630] [client 20.63.81.20:4354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/emmh.php"] [unique_id "apPkyT8EKFABaii6jtPyowAAAKM"]
[Sun Aug 30 03:07:37.529754 2026] [security2:error] [pid 503470:tid 503685] [client 20.104.104.62:14377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPkyT8EKFABaii6jtPyqgAAANo"]
[Sun Aug 30 03:07:37.530851 2026] [security2:error] [pid 503470:tid 503665] [client 68.155.159.216:60889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/install.php"] [unique_id "apPkyT8EKFABaii6jtPyrgAAAMY"]
[Sun Aug 30 03:07:37.534057 2026] [security2:error] [pid 503470:tid 503686] [client 4.205.62.107:18989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/aws_settings.php"] [unique_id "apPkyT8EKFABaii6jtPysAAAANs"]
[Sun Aug 30 03:07:37.539786 2026] [authz_core:error] [pid 499145:tid 499387] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IN%2FLC_MESSAGES
[Sun Aug 30 03:07:37.540255 2026] [authz_core:error] [pid 499145:tid 499387] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IN%2FLC_MESSAGES
[Sun Aug 30 03:07:37.555014 2026] [security2:error] [pid 499145:tid 499394] [client 20.104.50.220:59569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/w3llstore.php"] [unique_id "apPkyVJNq1G5uRhTNnuC1AAAAHc"]
[Sun Aug 30 03:07:37.586246 2026] [security2:error] [pid 503470:tid 503727] [client 20.104.104.62:35355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/qi.php"] [unique_id "apPkyT8EKFABaii6jtPy2QAAAQQ"]
[Sun Aug 30 03:07:37.593575 2026] [authz_core:error] [pid 503470:tid 503697] [client 216.73.216.128:29153] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:37.593951 2026] [authz_core:error] [pid 503470:tid 503697] [client 216.73.216.128:29153] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:37.633520 2026] [security2:error] [pid 499145:tid 499322] [client 40.83.93.50:5968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/twentytwentythree/patterns/index.php"] [unique_id "apPkyVJNq1G5uRhTNnuC5wAAAC8"]
[Sun Aug 30 03:07:37.645126 2026] [security2:error] [pid 503470:tid 503677] [client 20.63.81.20:4201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/em.php"] [unique_id "apPkyT8EKFABaii6jtPy6gAAANI"]
[Sun Aug 30 03:07:37.660413 2026] [security2:error] [pid 499145:tid 499397] [client 20.104.104.62:14803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/t00l.php"] [unique_id "apPkyVJNq1G5uRhTNnuC7AAAAHo"]
[Sun Aug 30 03:07:37.662578 2026] [security2:error] [pid 503470:tid 503620] [client 20.104.50.220:52828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/.well-known/wso.php"] [unique_id "apPkyT8EKFABaii6jtPy6wAAAJk"]
[Sun Aug 30 03:07:37.675087 2026] [security2:error] [pid 499145:tid 499277] [client 20.48.250.41:62534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/ccu.php"] [unique_id "apPkyVJNq1G5uRhTNnuC8AAAAAI"]
[Sun Aug 30 03:07:37.685736 2026] [authz_core:error] [pid 503470:tid 503629] [client 216.73.216.128:41450] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:37.686038 2026] [authz_core:error] [pid 503470:tid 503629] [client 216.73.216.128:41450] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:37.710368 2026] [security2:error] [pid 503470:tid 503645] [client 20.196.209.81:19938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/sf.php"] [unique_id "apPkyT8EKFABaii6jtPzAAAAALI"]
[Sun Aug 30 03:07:37.750083 2026] [security2:error] [pid 503470:tid 503648] [client 20.104.104.62:41107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/px.php"] [unique_id "apPkyT8EKFABaii6jtPzKwAAALU"]
[Sun Aug 30 03:07:37.773270 2026] [security2:error] [pid 499145:tid 499360] [client 20.63.81.20:4317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/dvve.php"] [unique_id "apPkyVJNq1G5uRhTNnuDGwAAAFU"]
[Sun Aug 30 03:07:37.774954 2026] [authz_core:error] [pid 503470:tid 503662] [client 216.73.216.128:37437] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:37.775473 2026] [authz_core:error] [pid 503470:tid 503662] [client 216.73.216.128:37437] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:37.800309 2026] [security2:error] [pid 503470:tid 503637] [client 20.104.104.62:14348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/ls.php"] [unique_id "apPkyT8EKFABaii6jtPzRQAAAKo"]
[Sun Aug 30 03:07:37.815118 2026] [security2:error] [pid 503470:tid 503687] [client 20.104.50.220:63528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/kjtpoad.php"] [unique_id "apPkyT8EKFABaii6jtPzUgAAANw"]
[Sun Aug 30 03:07:37.818451 2026] [security2:error] [pid 503470:tid 503654] [client 20.151.200.44:57118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkyT8EKFABaii6jtPzVQAAALs"]
[Sun Aug 30 03:07:37.821149 2026] [security2:error] [pid 503470:tid 503717] [client 20.48.250.41:62590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/ak.php"] [unique_id "apPkyT8EKFABaii6jtPzWQAAAPo"]
[Sun Aug 30 03:07:37.874237 2026] [authz_core:error] [pid 503470:tid 503702] [client 66.249.66.194:56977] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:37.874540 2026] [authz_core:error] [pid 503470:tid 503702] [client 66.249.66.194:56977] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:37.882093 2026] [security2:error] [pid 503470:tid 503613] [client 20.104.104.62:35340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/is.php"] [unique_id "apPkyT8EKFABaii6jtPzbQAAAJI"]
[Sun Aug 30 03:07:37.912275 2026] [security2:error] [pid 503470:tid 503703] [client 20.63.81.20:4267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/doo.php"] [unique_id "apPkyT8EKFABaii6jtPzegAAAOw"]
[Sun Aug 30 03:07:37.933148 2026] [security2:error] [pid 499145:tid 499317] [client 20.104.104.62:14357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/css/000.php"] [unique_id "apPkyVJNq1G5uRhTNnuDUQAAACo"]
[Sun Aug 30 03:07:37.946695 2026] [security2:error] [pid 503470:tid 503612] [client 114.119.159.233:49345] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kingcakeman.com"] [uri "/wp-activate.php"] [unique_id "apPkyT8EKFABaii6jtPzgQAAAJE"], referer: http://kingcakeman.com/wp-activate.php?3aqafl94wd6c8c48twa1anhq46n
[Sun Aug 30 03:07:37.948123 2026] [security2:error] [pid 503470:tid 503700] [client 20.48.250.41:62516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/lib.php"] [unique_id "apPkyT8EKFABaii6jtPzhAAAAOk"]
[Sun Aug 30 03:07:37.953775 2026] [security2:error] [pid 503470:tid 503672] [client 68.155.159.216:56380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apPkyT8EKFABaii6jtPziQAAAM0"]
[Sun Aug 30 03:07:37.991740 2026] [authz_core:error] [pid 503470:tid 503663] [client 66.249.66.70:65045] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:37.992195 2026] [authz_core:error] [pid 503470:tid 503663] [client 66.249.66.70:65045] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:38.011284 2026] [security2:error] [pid 503470:tid 503707] [client 20.104.104.62:41093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/od.php"] [unique_id "apPkyj8EKFABaii6jtPzrAAAAPA"]
[Sun Aug 30 03:07:38.028206 2026] [security2:error] [pid 503470:tid 503604] [client 40.83.93.50:18523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/index.php"] [unique_id "apPkyj8EKFABaii6jtPzuQAAAIk"]
[Sun Aug 30 03:07:38.041930 2026] [security2:error] [pid 503470:tid 503630] [client 20.63.81.20:4185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/adminer-4.6.6.php"] [unique_id "apPkyj8EKFABaii6jtPzyQAAAKM"]
[Sun Aug 30 03:07:38.065670 2026] [security2:error] [pid 503470:tid 503600] [client 20.104.104.62:14355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/cy.php"] [unique_id "apPkyj8EKFABaii6jtPz5gAAAIU"]
[Sun Aug 30 03:07:38.100125 2026] [security2:error] [pid 499145:tid 499384] [client 20.104.49.130:57666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/reviall.php"] [unique_id "apPkylJNq1G5uRhTNnuDkQAAAG0"]
[Sun Aug 30 03:07:38.111987 2026] [security2:error] [pid 503470:tid 503620] [client 20.196.209.81:1999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/gel4y.php"] [unique_id "apPkyj8EKFABaii6jtP0AQAAAJk"]
[Sun Aug 30 03:07:38.116894 2026] [security2:error] [pid 503470:tid 503667] [client 68.155.159.216:55109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/hehehehe.php"] [unique_id "apPkyj8EKFABaii6jtP0AwAAAMg"]
[Sun Aug 30 03:07:38.126861 2026] [security2:error] [pid 503470:tid 503658] [client 20.48.250.41:60751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/wp-style.php"] [unique_id "apPkyj8EKFABaii6jtP0CwAAAL8"]
[Sun Aug 30 03:07:38.133568 2026] [security2:error] [pid 503470:tid 503665] [client 20.197.61.180:19059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/g.php"] [unique_id "apPkyj8EKFABaii6jtP0DwAAAMY"]
[Sun Aug 30 03:07:38.139625 2026] [authz_core:error] [pid 503470:tid 503703] [client 216.73.216.128:41450] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:38.139961 2026] [authz_core:error] [pid 503470:tid 503703] [client 216.73.216.128:41450] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:38.151999 2026] [security2:error] [pid 503470:tid 503696] [client 20.104.18.15:43270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/c4.php"] [unique_id "apPkyj8EKFABaii6jtP0GAAAAOU"]
[Sun Aug 30 03:07:38.152182 2026] [security2:error] [pid 503470:tid 503692] [client 20.104.104.62:37447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/wp-the.php"] [unique_id "apPkyj8EKFABaii6jtP0GQAAAOE"]
[Sun Aug 30 03:07:38.162024 2026] [security2:error] [pid 503470:tid 503678] [client 20.48.251.3:6504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/png.php"] [unique_id "apPkyj8EKFABaii6jtP0IQAAANM"]
[Sun Aug 30 03:07:38.170021 2026] [authz_core:error] [pid 499145:tid 499352] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NG%2FLC_MESSAGES
[Sun Aug 30 03:07:38.170457 2026] [authz_core:error] [pid 499145:tid 499352] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NG%2FLC_MESSAGES
[Sun Aug 30 03:07:38.174097 2026] [security2:error] [pid 503470:tid 503633] [client 20.63.81.20:4258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/gelap1.php"] [unique_id "apPkyj8EKFABaii6jtP0LgAAAKY"]
[Sun Aug 30 03:07:38.194380 2026] [security2:error] [pid 503470:tid 503643] [client 20.104.104.62:15317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/admin.php/pindex.php"] [unique_id "apPkyj8EKFABaii6jtP0QgAAALA"]
[Sun Aug 30 03:07:38.198959 2026] [security2:error] [pid 503470:tid 503702] [client 20.104.50.220:27428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/yes.php"] [unique_id "apPkyj8EKFABaii6jtP0RQAAAOs"]
[Sun Aug 30 03:07:38.235893 2026] [security2:error] [pid 503470:tid 503641] [client 20.104.50.220:6101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/59.php"] [unique_id "apPkyj8EKFABaii6jtP0YQAAAK4"]
[Sun Aug 30 03:07:38.244223 2026] [security2:error] [pid 503470:tid 503607] [client 20.104.49.130:59568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/css.php"] [unique_id "apPkyj8EKFABaii6jtP0ZgAAAIw"]
[Sun Aug 30 03:07:38.249442 2026] [security2:error] [pid 503470:tid 503642] [client 68.155.159.216:12389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apPkyj8EKFABaii6jtP0bgAAAK8"]
[Sun Aug 30 03:07:38.269897 2026] [security2:error] [pid 503470:tid 503657] [client 4.205.62.107:62036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/zz.php"] [unique_id "apPkyj8EKFABaii6jtP0gQAAAL4"]
[Sun Aug 30 03:07:38.277521 2026] [security2:error] [pid 503470:tid 503613] [client 20.104.50.220:17328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/2P.php"] [unique_id "apPkyj8EKFABaii6jtP0hQAAAJI"]
[Sun Aug 30 03:07:38.280531 2026] [security2:error] [pid 503470:tid 503706] [client 20.104.104.62:35331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/wt.php"] [unique_id "apPkyj8EKFABaii6jtP0iQAAAO8"]
[Sun Aug 30 03:07:38.283738 2026] [security2:error] [pid 503470:tid 503629] [client 68.155.159.216:61340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-blog-header.php"] [unique_id "apPkyj8EKFABaii6jtP0iwAAAKI"]
[Sun Aug 30 03:07:38.289370 2026] [security2:error] [pid 503470:tid 503718] [client 68.155.159.216:61643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-includes/plugins.php"] [unique_id "apPkyj8EKFABaii6jtP0jgAAAPs"]
[Sun Aug 30 03:07:38.293268 2026] [security2:error] [pid 503470:tid 503660] [client 20.48.251.3:33317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/infos.php"] [unique_id "apPkyj8EKFABaii6jtP0kQAAAME"]
[Sun Aug 30 03:07:38.293726 2026] [security2:error] [pid 499145:tid 499338] [client 114.119.137.193:50239] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rampd.co"] [uri "/free-assesment"] [unique_id "apPkylJNq1G5uRhTNnuD1gAAAD8"], referer: https://rampd.co/free-assesment
[Sun Aug 30 03:07:38.297914 2026] [security2:error] [pid 503470:tid 503635] [client 40.83.93.50:5980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/users.php"] [unique_id "apPkyj8EKFABaii6jtP0lQAAAKg"]
[Sun Aug 30 03:07:38.300699 2026] [security2:error] [pid 503470:tid 503628] [client 20.63.81.20:4187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/rsjlrria.php"] [unique_id "apPkyj8EKFABaii6jtP0mQAAAKE"]
[Sun Aug 30 03:07:38.339888 2026] [security2:error] [pid 503470:tid 503632] [client 20.104.104.62:14369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/admin.php/csv.php"] [unique_id "apPkyj8EKFABaii6jtP0sAAAAKU"]
[Sun Aug 30 03:07:38.367159 2026] [security2:error] [pid 499145:tid 499324] [client 20.48.250.41:60791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/browse.php"] [unique_id "apPkylJNq1G5uRhTNnuD8wAAADE"]
[Sun Aug 30 03:07:38.375800 2026] [authz_core:error] [pid 503470:tid 503708] [client 66.249.66.32:58033] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:38.376266 2026] [authz_core:error] [pid 503470:tid 503708] [client 66.249.66.32:58033] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:38.376309 2026] [security2:error] [pid 503470:tid 503609] [client 114.119.144.85:45927] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.stellarmigration.com"] [uri "/index.php/visas/migrating-to-australia"] [unique_id "apPkyj8EKFABaii6jtP0pwAAAI4"], referer: http://www.stellarmigration.com/index.php/visas/migrating-to-australia?share=email
[Sun Aug 30 03:07:38.382948 2026] [security2:error] [pid 503470:tid 503638] [client 20.104.50.220:29319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/image.php"] [unique_id "apPkyj8EKFABaii6jtP0yQAAAKs"]
[Sun Aug 30 03:07:38.410772 2026] [security2:error] [pid 503470:tid 503693] [client 20.104.104.62:37500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/im.php"] [unique_id "apPkyj8EKFABaii6jtP06AAAAOI"]
[Sun Aug 30 03:07:38.411627 2026] [authz_core:error] [pid 499145:tid 499312] [client 216.73.216.128:47617] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:38.411992 2026] [authz_core:error] [pid 499145:tid 499312] [client 216.73.216.128:47617] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:38.428789 2026] [security2:error] [pid 503470:tid 503635] [client 20.63.81.20:4258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/AxAo.php"] [unique_id "apPkyj8EKFABaii6jtP09wAAAKg"]
[Sun Aug 30 03:07:38.433688 2026] [security2:error] [pid 499145:tid 499375] [client 20.151.200.44:59510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/h02ugyh.php"] [unique_id "apPkylJNq1G5uRhTNnuEDwAAAGQ"]
[Sun Aug 30 03:07:38.444328 2026] [security2:error] [pid 503470:tid 503647] [client 20.104.18.15:18392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/file1221.php"] [unique_id "apPkyj8EKFABaii6jtP0_QAAALQ"]
[Sun Aug 30 03:07:38.444588 2026] [security2:error] [pid 503470:tid 503622] [client 20.104.18.15:34705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/ws85.php"] [unique_id "apPkyj8EKFABaii6jtP0_gAAAJs"]
[Sun Aug 30 03:07:38.450049 2026] [security2:error] [pid 503470:tid 503642] [client 20.104.18.15:28549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/mghnhykio.php/new.php"] [unique_id "apPkyj8EKFABaii6jtP1AQAAAK8"]
[Sun Aug 30 03:07:38.450422 2026] [security2:error] [pid 503470:tid 503618] [client 20.104.50.220:46183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/auto_seo.php"] [unique_id "apPkyj8EKFABaii6jtP1AgAAAJc"]
[Sun Aug 30 03:07:38.459840 2026] [security2:error] [pid 503470:tid 503644] [client 20.48.251.3:12040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/bb.php"] [unique_id "apPkyj8EKFABaii6jtP1BQAAALE"]
[Sun Aug 30 03:07:38.462297 2026] [security2:error] [pid 503470:tid 503690] [client 4.205.62.107:61763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/w.php"] [unique_id "apPkyj8EKFABaii6jtP1CQAAAN8"]
[Sun Aug 30 03:07:38.466103 2026] [security2:error] [pid 503470:tid 503645] [client 20.104.18.15:23440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/codex.php"] [unique_id "apPkyj8EKFABaii6jtP1DAAAALI"]
[Sun Aug 30 03:07:38.471019 2026] [security2:error] [pid 503470:tid 503627] [client 20.104.50.220:32068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-conflg.php"] [unique_id "apPkyj8EKFABaii6jtP1EwAAAKA"]
[Sun Aug 30 03:07:38.473349 2026] [security2:error] [pid 503470:tid 503700] [client 20.104.18.15:51613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/mac.php"] [unique_id "apPkyj8EKFABaii6jtP1FQAAAOk"]
[Sun Aug 30 03:07:38.478164 2026] [security2:error] [pid 503470:tid 503669] [client 20.48.251.3:44307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/aws_secret_config.php"] [unique_id "apPkyj8EKFABaii6jtP1HQAAAMo"]
[Sun Aug 30 03:07:38.482439 2026] [security2:error] [pid 503470:tid 503615] [client 20.104.104.62:14806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/admin.php/700.php"] [unique_id "apPkyj8EKFABaii6jtP1IAAAAJQ"]
[Sun Aug 30 03:07:38.486954 2026] [authz_core:error] [pid 503470:tid 503671] [client 74.7.227.8:38186] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:38.487419 2026] [authz_core:error] [pid 503470:tid 503671] [client 74.7.227.8:38186] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:38.489483 2026] [security2:error] [pid 503470:tid 503640] [client 4.205.62.107:51402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/app.default.php"] [unique_id "apPkyj8EKFABaii6jtP1JQAAAK0"]
[Sun Aug 30 03:07:38.507457 2026] [security2:error] [pid 503470:tid 503695] [client 20.48.250.41:60745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/zoo.php"] [unique_id "apPkyj8EKFABaii6jtP1MgAAAOQ"]
[Sun Aug 30 03:07:38.508426 2026] [security2:error] [pid 503470:tid 503670] [client 20.196.209.81:5119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/leaf.php"] [unique_id "apPkyj8EKFABaii6jtP1NAAAAMs"]
[Sun Aug 30 03:07:38.515235 2026] [security2:error] [pid 503470:tid 503614] [client 158.23.147.79:63987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apPkyj8EKFABaii6jtP1PAAAAJM"]
[Sun Aug 30 03:07:38.522405 2026] [security2:error] [pid 503470:tid 503645] [client 4.205.62.107:36613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/config_dev.php"] [unique_id "apPkyj8EKFABaii6jtP1RAAAALI"]
[Sun Aug 30 03:07:38.526240 2026] [security2:error] [pid 503470:tid 503707] [client 20.104.18.15:29181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/abcd.php"] [unique_id "apPkyj8EKFABaii6jtP1RwAAAPA"]
[Sun Aug 30 03:07:38.539759 2026] [security2:error] [pid 503470:tid 503600] [client 20.104.104.62:37475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/file.php"] [unique_id "apPkyj8EKFABaii6jtP1UgAAAIU"]
[Sun Aug 30 03:07:38.557820 2026] [security2:error] [pid 503470:tid 503693] [client 20.63.81.20:4235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/class17.php"] [unique_id "apPkyj8EKFABaii6jtP1YAAAAOI"]
[Sun Aug 30 03:07:38.570341 2026] [security2:error] [pid 503470:tid 503699] [client 40.83.93.50:18540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/php8.php"] [unique_id "apPkyj8EKFABaii6jtP1agAAAOg"]
[Sun Aug 30 03:07:38.614433 2026] [security2:error] [pid 499145:tid 499367] [client 20.104.104.62:14796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/admin.php/007x.php"] [unique_id "apPkylJNq1G5uRhTNnuEUAAAAFw"]
[Sun Aug 30 03:07:38.633889 2026] [security2:error] [pid 499145:tid 499389] [client 158.23.147.79:63903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-content/plugins/index.php"] [unique_id "apPkylJNq1G5uRhTNnuEVQAAAHI"]
[Sun Aug 30 03:07:38.659729 2026] [security2:error] [pid 499145:tid 499287] [client 68.155.159.216:61398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-content/x/index.php"] [unique_id "apPkylJNq1G5uRhTNnuEWQAAAAw"]
[Sun Aug 30 03:07:38.662265 2026] [security2:error] [pid 503470:tid 503722] [client 20.48.250.41:60759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/elp.php"] [unique_id "apPkyj8EKFABaii6jtP1igAAAP8"]
[Sun Aug 30 03:07:38.677416 2026] [security2:error] [pid 503470:tid 503695] [client 4.205.62.107:18761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/wp-konfig.backup.php"] [unique_id "apPkyj8EKFABaii6jtP1kAAAAOQ"]
[Sun Aug 30 03:07:38.685224 2026] [security2:error] [pid 503470:tid 503709] [client 20.63.81.20:4318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/okxoby.php"] [unique_id "apPkyj8EKFABaii6jtP1kQAAAPI"]
[Sun Aug 30 03:07:38.692455 2026] [security2:error] [pid 503470:tid 503622] [client 20.104.104.62:35334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/ca.php"] [unique_id "apPkyj8EKFABaii6jtP1lgAAAJs"]
[Sun Aug 30 03:07:38.707726 2026] [security2:error] [pid 503470:tid 503642] [client 20.104.50.220:61690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/alfi.php"] [unique_id "apPkyj8EKFABaii6jtP1oAAAAK8"]
[Sun Aug 30 03:07:38.714268 2026] [authz_core:error] [pid 499145:tid 499316] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_SG%2FLC_MESSAGES
[Sun Aug 30 03:07:38.714583 2026] [authz_core:error] [pid 499145:tid 499316] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_SG%2FLC_MESSAGES
[Sun Aug 30 03:07:38.714780 2026] [security2:error] [pid 499145:tid 499329] [client 20.104.50.220:32861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/lf.php"] [unique_id "apPkylJNq1G5uRhTNnuEbQAAADY"]
[Sun Aug 30 03:07:38.718998 2026] [authz_core:error] [pid 503470:tid 503637] [client 66.249.66.193:44586] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:38.719472 2026] [authz_core:error] [pid 503470:tid 503637] [client 66.249.66.193:44586] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:38.746196 2026] [security2:error] [pid 503470:tid 503643] [client 20.104.104.62:14800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/admin.php/heex.php"] [unique_id "apPkyj8EKFABaii6jtP1ygAAALA"]
[Sun Aug 30 03:07:38.765588 2026] [security2:error] [pid 499145:tid 499324] [client 40.83.93.50:11483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/wp-cron.php"] [unique_id "apPkylJNq1G5uRhTNnuEgQAAADE"]
[Sun Aug 30 03:07:38.768413 2026] [security2:error] [pid 503470:tid 503710] [client 158.23.147.79:63889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/simple.php"] [unique_id "apPkyj8EKFABaii6jtP13AAAAPM"]
[Sun Aug 30 03:07:38.807946 2026] [security2:error] [pid 503470:tid 503722] [client 20.104.50.220:63046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/.well-known/java.php"] [unique_id "apPkyj8EKFABaii6jtP19wAAAP8"]
[Sun Aug 30 03:07:38.825358 2026] [security2:error] [pid 499145:tid 499313] [client 20.63.81.20:4326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/esuutzzx.php"] [unique_id "apPkylJNq1G5uRhTNnuElgAAACY"]
[Sun Aug 30 03:07:38.827402 2026] [security2:error] [pid 499145:tid 499364] [client 20.104.104.62:37468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/pb.php"] [unique_id "apPkylJNq1G5uRhTNnuEmAAAAFk"]
[Sun Aug 30 03:07:38.834430 2026] [security2:error] [pid 503470:tid 503699] [client 20.48.250.41:62545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/666.php"] [unique_id "apPkyj8EKFABaii6jtP2CAAAAOg"]
[Sun Aug 30 03:07:38.867974 2026] [authz_core:error] [pid 503470:tid 503646] [client 216.73.216.128:41450] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:38.868258 2026] [authz_core:error] [pid 503470:tid 503646] [client 216.73.216.128:41450] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:38.875501 2026] [security2:error] [pid 503470:tid 503660] [client 20.104.104.62:14361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/tf.php"] [unique_id "apPkyj8EKFABaii6jtP2GQAAAME"]
[Sun Aug 30 03:07:38.880225 2026] [security2:error] [pid 499145:tid 499311] [client 20.197.61.180:19015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/cc.php"] [unique_id "apPkylJNq1G5uRhTNnuEpwAAACQ"]
[Sun Aug 30 03:07:38.882457 2026] [security2:error] [pid 499145:tid 499382] [client 158.23.147.79:63877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-admin/about.php"] [unique_id "apPkylJNq1G5uRhTNnuEqAAAAGs"]
[Sun Aug 30 03:07:38.909720 2026] [security2:error] [pid 503470:tid 503707] [client 20.196.209.81:5115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/k.php"] [unique_id "apPkyj8EKFABaii6jtP2IwAAAPA"]
[Sun Aug 30 03:07:38.953961 2026] [security2:error] [pid 503470:tid 503681] [client 20.104.50.220:42015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/blackcat.php"] [unique_id "apPkyj8EKFABaii6jtP2MAAAANY"]
[Sun Aug 30 03:07:38.958876 2026] [authz_core:error] [pid 499145:tid 499342] [client 216.73.216.128:47617] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:38.959130 2026] [authz_core:error] [pid 499145:tid 499342] [client 216.73.216.128:47617] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:38.960055 2026] [security2:error] [pid 503470:tid 503601] [client 20.48.250.41:62573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/knmt.php"] [unique_id "apPkyj8EKFABaii6jtP2NwAAAIY"]
[Sun Aug 30 03:07:38.962515 2026] [security2:error] [pid 503470:tid 503659] [client 20.63.81.20:4478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/replace.php"] [unique_id "apPkyj8EKFABaii6jtP2OQAAAMA"]
[Sun Aug 30 03:07:38.967069 2026] [security2:error] [pid 503470:tid 503622] [client 20.104.104.62:41141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/pk.php"] [unique_id "apPkyj8EKFABaii6jtP2PgAAAJs"]
[Sun Aug 30 03:07:38.980040 2026] [security2:error] [pid 503470:tid 503689] [client 114.119.165.226:64911] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "calchampsoccer.org"] [uri "/event/guerrero/"] [unique_id "apPkyj8EKFABaii6jtP2SgAAAN4"], referer: https://calchampsoccer.org/event/guerrero/
[Sun Aug 30 03:07:38.992096 2026] [security2:error] [pid 503470:tid 503697] [client 46.166.199.190:59081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.199.166.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ballyyahoo.com"] [uri "/wp-comments-post.php"] [unique_id "apPkyj8EKFABaii6jtP2VAAAAOY"], referer: https://ballyyahoo.com/
[Sun Aug 30 03:07:38.992196 2026] [security2:error] [pid 503470:tid 503697] [client 46.166.199.190:59081] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "ballyyahoo.com"] [uri "/wp-comments-post.php"] [unique_id "apPkyj8EKFABaii6jtP2VAAAAOY"], referer: https://ballyyahoo.com/
[Sun Aug 30 03:07:39.004292 2026] [security2:error] [pid 503470:tid 503692] [client 158.23.147.79:63961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-content/uploads/index.php"] [unique_id "apPkyz8EKFABaii6jtP2WgAAAOE"]
[Sun Aug 30 03:07:39.009735 2026] [security2:error] [pid 503470:tid 503715] [client 20.104.104.62:14347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/update/da222.php"] [unique_id "apPkyz8EKFABaii6jtP2XQAAAPg"]
[Sun Aug 30 03:07:39.055350 2026] [authz_core:error] [pid 503470:tid 503668] [client 216.73.216.128:41450] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:39.055806 2026] [authz_core:error] [pid 503470:tid 503668] [client 216.73.216.128:41450] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:39.060622 2026] [security2:error] [pid 503470:tid 503674] [client 68.155.159.216:56330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apPkyz8EKFABaii6jtP2iAAAAM8"]
[Sun Aug 30 03:07:39.067890 2026] [security2:error] [pid 503470:tid 503654] [client 114.119.147.152:29487] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "topglossdetail.com"] [uri "/wp-content/uploads/2020/12/Cmaro-ZL1-3-360x240.jpg"] [unique_id "apPkyz8EKFABaii6jtP2jgAAALs"], referer: https://topglossdetail.com/wp-content/uploads/2020/12/Cmaro-ZL1-3-360x240.jpg
[Sun Aug 30 03:07:39.072549 2026] [security2:error] [pid 503470:tid 503620] [client 40.83.93.50:13516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/function.php"] [unique_id "apPkyz8EKFABaii6jtP2kQAAAJk"]
[Sun Aug 30 03:07:39.095129 2026] [security2:error] [pid 503470:tid 503635] [client 20.104.104.62:35367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/ft.php"] [unique_id "apPkyz8EKFABaii6jtP2ngAAAKg"]
[Sun Aug 30 03:07:39.101416 2026] [security2:error] [pid 499145:tid 499350] [client 20.63.81.20:4293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/gulu.php"] [unique_id "apPky1JNq1G5uRhTNnuE_AAAAEs"]
[Sun Aug 30 03:07:39.102714 2026] [security2:error] [pid 503470:tid 503710] [client 20.48.250.41:60682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/sbhu.php"] [unique_id "apPkyz8EKFABaii6jtP2oAAAAPM"]
[Sun Aug 30 03:07:39.117321 2026] [security2:error] [pid 503470:tid 503725] [client 158.23.147.79:63966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apPkyz8EKFABaii6jtP2ogAAAQI"]
[Sun Aug 30 03:07:39.149009 2026] [security2:error] [pid 503470:tid 503611] [client 20.104.104.62:14379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/qi.php"] [unique_id "apPkyz8EKFABaii6jtP2qwAAAJA"]
[Sun Aug 30 03:07:39.200066 2026] [authz_core:error] [pid 499145:tid 499380] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_US
[Sun Aug 30 03:07:39.200344 2026] [authz_core:error] [pid 499145:tid 499380] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_US
[Sun Aug 30 03:07:39.206461 2026] [security2:error] [pid 503470:tid 503632] [client 20.104.49.130:63293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/133.php"] [unique_id "apPkyz8EKFABaii6jtP22QAAAKU"]
[Sun Aug 30 03:07:39.226282 2026] [security2:error] [pid 503470:tid 503602] [client 158.23.147.79:63885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/chosen.php"] [unique_id "apPkyz8EKFABaii6jtP25gAAAIc"]
[Sun Aug 30 03:07:39.230410 2026] [security2:error] [pid 503470:tid 503696] [client 20.63.81.20:4175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/gtghklk.php"] [unique_id "apPkyz8EKFABaii6jtP26gAAAOU"]
[Sun Aug 30 03:07:39.234368 2026] [security2:error] [pid 503470:tid 503648] [client 20.104.104.62:37489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/wp-ver.php"] [unique_id "apPkyz8EKFABaii6jtP27QAAALU"]
[Sun Aug 30 03:07:39.245070 2026] [security2:error] [pid 503470:tid 503674] [client 68.155.159.216:55142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apPkyz8EKFABaii6jtP2-AAAAM8"]
[Sun Aug 30 03:07:39.258149 2026] [security2:error] [pid 503470:tid 503645] [client 20.48.250.41:60773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/a332.php"] [unique_id "apPkyz8EKFABaii6jtP3AgAAALI"]
[Sun Aug 30 03:07:39.264067 2026] [security2:error] [pid 499145:tid 499288] [client 40.83.93.50:11492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/wp-links-opml.php"] [unique_id "apPky1JNq1G5uRhTNnuFPgAAAA0"]
[Sun Aug 30 03:07:39.275119 2026] [proxy_http:error] [pid 503470:tid 503694] (20014)Internal error (specific information not available): [client 34.125.55.247:47956] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:39.275141 2026] [proxy:error] [pid 503470:tid 503694] [client 34.125.55.247:47956] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/creds.json
[Sun Aug 30 03:07:39.276391 2026] [security2:error] [pid 503470:tid 503612] [client 20.104.104.62:14837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/px.php"] [unique_id "apPkyz8EKFABaii6jtP3FwAAAJE"]
[Sun Aug 30 03:07:39.281373 2026] [security2:error] [pid 503470:tid 503693] [client 34.125.55.247:48000] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.engaginggoddaily.com"] [uri "/appsettings.Development.json"] [unique_id "apPkyz8EKFABaii6jtP3IgAAAOI"]
[Sun Aug 30 03:07:39.282007 2026] [security2:error] [pid 499145:tid 499310] [client 4.205.62.107:32003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/requirements.php"] [unique_id "apPky1JNq1G5uRhTNnuFRQAAACM"]
[Sun Aug 30 03:07:39.287906 2026] [security2:error] [pid 499145:tid 499308] [client 20.151.200.44:55680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/ls.php"] [unique_id "apPky1JNq1G5uRhTNnuFSAAAACE"]
[Sun Aug 30 03:07:39.293295 2026] [security2:error] [pid 503470:tid 503702] [client 20.104.104.62:57022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkyz8EKFABaii6jtP3KAAAAOs"]
[Sun Aug 30 03:07:39.293311 2026] [proxy_http:error] [pid 503470:tid 503719] (20014)Internal error (specific information not available): [client 34.125.55.247:48008] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:39.293327 2026] [proxy:error] [pid 503470:tid 503719] [client 34.125.55.247:48008] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/appsettings.Production.json
[Sun Aug 30 03:07:39.301605 2026] [proxy_http:error] [pid 503470:tid 503719] (20014)Internal error (specific information not available): [client 34.125.55.247:48008] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:39.301621 2026] [proxy:error] [pid 503470:tid 503719] [client 34.125.55.247:48008] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml
[Sun Aug 30 03:07:39.301776 2026] [security2:error] [pid 503470:tid 503691] [client 20.196.209.81:5094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/chosen.php"] [unique_id "apPkyz8EKFABaii6jtP3MgAAAOA"]
[Sun Aug 30 03:07:39.301791 2026] [security2:error] [pid 503470:tid 503719] [client 34.125.55.247:48008] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "502"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/502.shtml"] [unique_id "apPkyz8EKFABaii6jtP3IwAAAPw"]
[Sun Aug 30 03:07:39.312691 2026] [proxy_http:error] [pid 503470:tid 503607] (20014)Internal error (specific information not available): [client 34.125.55.247:47956] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:39.312931 2026] [security2:error] [pid 503470:tid 503607] [client 34.125.55.247:47956] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "502"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/client_secret.json"] [unique_id "apPkyz8EKFABaii6jtP3LwAAAIw"]
[Sun Aug 30 03:07:39.318274 2026] [security2:error] [pid 503470:tid 503724] [client 20.104.18.15:43920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/rxr.php"] [unique_id "apPkyz8EKFABaii6jtP3PwAAAQE"]
[Sun Aug 30 03:07:39.321067 2026] [proxy_http:error] [pid 503470:tid 503601] (20014)Internal error (specific information not available): [client 34.125.55.247:47976] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:39.327359 2026] [authz_core:error] [pid 499145:tid 499398] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:39.327815 2026] [authz_core:error] [pid 499145:tid 499398] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:39.338157 2026] [security2:error] [pid 503470:tid 503696] [client 20.104.50.220:27095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/2008.php"] [unique_id "apPkyz8EKFABaii6jtP3TwAAAOU"]
[Sun Aug 30 03:07:39.339440 2026] [proxy_http:error] [pid 503470:tid 503665] (20014)Internal error (specific information not available): [client 34.125.55.247:48040] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:39.339456 2026] [proxy:error] [pid 503470:tid 503665] [client 34.125.55.247:48040] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/firebase-admin.json
[Sun Aug 30 03:07:39.347897 2026] [security2:error] [pid 503470:tid 503604] [client 34.125.55.247:47986] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/client_secret.json"] [unique_id "apPkyz8EKFABaii6jtP3RQAAAIk"]
[Sun Aug 30 03:07:39.348018 2026] [proxy_http:error] [pid 503470:tid 503647] (20014)Internal error (specific information not available): [client 34.125.55.247:48020] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:39.360680 2026] [security2:error] [pid 503470:tid 503644] [client 20.104.104.62:37487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/ah24.php"] [unique_id "apPkyz8EKFABaii6jtP3ZQAAALE"]
[Sun Aug 30 03:07:39.367277 2026] [proxy_http:error] [pid 503470:tid 503674] (20014)Internal error (specific information not available): [client 34.125.55.247:48026] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:39.374450 2026] [security2:error] [pid 503470:tid 503680] [client 20.104.50.220:6109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/58.php"] [unique_id "apPkyz8EKFABaii6jtP3bAAAANU"]
[Sun Aug 30 03:07:39.376414 2026] [security2:error] [pid 499145:tid 499381] [client 20.63.81.20:4479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/comand.php"] [unique_id "apPky1JNq1G5uRhTNnuFagAAAGo"]
[Sun Aug 30 03:07:39.380086 2026] [security2:error] [pid 503470:tid 503609] [client 158.23.147.79:63941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/goods.php"] [unique_id "apPkyz8EKFABaii6jtP3bgAAAI4"]
[Sun Aug 30 03:07:39.408777 2026] [security2:error] [pid 503470:tid 503663] [client 20.48.250.41:62479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/ws66.php"] [unique_id "apPkyz8EKFABaii6jtP3kAAAAMQ"]
[Sun Aug 30 03:07:39.409830 2026] [security2:error] [pid 503470:tid 503640] [client 20.104.104.62:14352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/is.php"] [unique_id "apPkyz8EKFABaii6jtP3kQAAAK0"]
[Sun Aug 30 03:07:39.414460 2026] [security2:error] [pid 503470:tid 503677] [client 20.104.50.220:16760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/tires.php"] [unique_id "apPkyz8EKFABaii6jtP3lwAAANI"]
[Sun Aug 30 03:07:39.414512 2026] [security2:error] [pid 503470:tid 503712] [client 68.155.159.216:12394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-admin/network/index.php"] [unique_id "apPkyz8EKFABaii6jtP3mAAAAPU"]
[Sun Aug 30 03:07:39.418098 2026] [security2:error] [pid 499145:tid 499348] [client 68.155.159.216:63969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apPky1JNq1G5uRhTNnuFhAAAAEk"]
[Sun Aug 30 03:07:39.421305 2026] [security2:error] [pid 503470:tid 503709] [client 20.104.104.62:56999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkyz8EKFABaii6jtP3nAAAAPI"]
[Sun Aug 30 03:07:39.422751 2026] [security2:error] [pid 503470:tid 503725] [client 4.205.62.107:62034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/test.php"] [unique_id "apPkyz8EKFABaii6jtP3ngAAAQI"]
[Sun Aug 30 03:07:39.446727 2026] [security2:error] [pid 503470:tid 503609] [client 20.48.251.3:33308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/env.php"] [unique_id "apPkyz8EKFABaii6jtP3pgAAAI4"]
[Sun Aug 30 03:07:39.457271 2026] [security2:error] [pid 503470:tid 503655] [client 20.48.251.3:45867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/chosen.php"] [unique_id "apPkyz8EKFABaii6jtP3qAAAALw"]
[Sun Aug 30 03:07:39.504196 2026] [security2:error] [pid 503470:tid 503649] [client 20.63.81.20:4227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp_motu_myk3v.php"] [unique_id "apPkyz8EKFABaii6jtP3zgAAALY"]
[Sun Aug 30 03:07:39.504261 2026] [security2:error] [pid 503470:tid 503617] [client 68.155.159.216:28622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apPkyz8EKFABaii6jtP3zwAAAJY"]
[Sun Aug 30 03:07:39.505774 2026] [authz_core:error] [pid 499145:tid 499339] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:39.506050 2026] [authz_core:error] [pid 499145:tid 499339] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:39.510598 2026] [security2:error] [pid 503470:tid 503645] [client 158.23.147.79:63995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apPkyz8EKFABaii6jtP30AAAALI"]
[Sun Aug 30 03:07:39.529730 2026] [authz_core:error] [pid 503470:tid 503684] [client 66.249.66.74:61329] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:39.530012 2026] [authz_core:error] [pid 503470:tid 503684] [client 66.249.66.74:61329] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:39.532545 2026] [security2:error] [pid 503470:tid 503703] [client 20.104.104.62:35376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/wp-admin/zwso.php"] [unique_id "apPkyz8EKFABaii6jtP34gAAAOw"]
[Sun Aug 30 03:07:39.539151 2026] [security2:error] [pid 503470:tid 503710] [client 20.48.250.41:60683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/ws68.php"] [unique_id "apPkyz8EKFABaii6jtP35gAAAPM"]
[Sun Aug 30 03:07:39.546102 2026] [security2:error] [pid 503470:tid 503616] [client 20.104.104.62:14351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/od.php"] [unique_id "apPkyz8EKFABaii6jtP37wAAAJU"]
[Sun Aug 30 03:07:39.549530 2026] [security2:error] [pid 499145:tid 499335] [client 20.104.104.62:57023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/h02ugyh.php"] [unique_id "apPky1JNq1G5uRhTNnuFvAAAADw"]
[Sun Aug 30 03:07:39.574117 2026] [security2:error] [pid 503470:tid 503649] [client 20.104.50.220:29171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/images.php"] [unique_id "apPkyz8EKFABaii6jtP3-wAAALY"]
[Sun Aug 30 03:07:39.578486 2026] [security2:error] [pid 503470:tid 503645] [client 20.104.18.15:28503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/admin.php/nope.php"] [unique_id "apPkyz8EKFABaii6jtP4AQAAALI"]
[Sun Aug 30 03:07:39.581780 2026] [security2:error] [pid 499145:tid 499354] [client 20.104.18.15:34702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/ffs.php"] [unique_id "apPky1JNq1G5uRhTNnuFzQAAAE8"]
[Sun Aug 30 03:07:39.582976 2026] [security2:error] [pid 499145:tid 499321] [client 20.104.50.220:46200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/alone.php"] [unique_id "apPky1JNq1G5uRhTNnuFzwAAAC4"]
[Sun Aug 30 03:07:39.583382 2026] [security2:error] [pid 503470:tid 503600] [client 20.104.18.15:18320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/nox.php"] [unique_id "apPkyz8EKFABaii6jtP4BgAAAIU"]
[Sun Aug 30 03:07:39.598129 2026] [security2:error] [pid 503470:tid 503683] [client 20.48.251.3:50012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/file59.php"] [unique_id "apPkyz8EKFABaii6jtP4DgAAANg"]
[Sun Aug 30 03:07:39.612148 2026] [security2:error] [pid 503470:tid 503612] [client 4.205.62.107:61804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/btx25.php"] [unique_id "apPkyz8EKFABaii6jtP4EwAAAJE"]
[Sun Aug 30 03:07:39.621030 2026] [security2:error] [pid 503470:tid 503726] [client 20.104.18.15:23378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/5656.php"] [unique_id "apPkyz8EKFABaii6jtP4FQAAAQM"]
[Sun Aug 30 03:07:39.624326 2026] [security2:error] [pid 503470:tid 503601] [client 40.83.93.50:18502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/about.php"] [unique_id "apPkyz8EKFABaii6jtP4FgAAAIY"]
[Sun Aug 30 03:07:39.625220 2026] [security2:error] [pid 503470:tid 503601] [client 4.205.62.107:62287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/app_local.php"] [unique_id "apPkyz8EKFABaii6jtP4GAAAAIY"]
[Sun Aug 30 03:07:39.629952 2026] [security2:error] [pid 499145:tid 499283] [client 158.23.147.79:62306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-admin/includes/nav.php"] [unique_id "apPky1JNq1G5uRhTNnuF3AAAAAg"]
[Sun Aug 30 03:07:39.632791 2026] [security2:error] [pid 503470:tid 503670] [client 20.63.81.20:4254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/wp_motu_ypdat.php"] [unique_id "apPkyz8EKFABaii6jtP4GQAAAMs"]
[Sun Aug 30 03:07:39.646926 2026] [security2:error] [pid 503470:tid 503697] [client 20.197.61.180:9357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/f35.php"] [unique_id "apPkyz8EKFABaii6jtP4HAAAAOY"]
[Sun Aug 30 03:07:39.654576 2026] [security2:error] [pid 499145:tid 499323] [client 4.205.62.107:36626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/aws_credentials.php"] [unique_id "apPky1JNq1G5uRhTNnuF3QAAADA"]
[Sun Aug 30 03:07:39.657981 2026] [security2:error] [pid 503470:tid 503624] [client 20.48.251.3:44315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/snq.php"] [unique_id "apPkyz8EKFABaii6jtP4HgAAAJ0"]
[Sun Aug 30 03:07:39.663346 2026] [security2:error] [pid 503470:tid 503672] [client 20.104.18.15:51703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/simple.php"] [unique_id "apPkyz8EKFABaii6jtP4IQAAAM0"]
[Sun Aug 30 03:07:39.673577 2026] [authz_core:error] [pid 499145:tid 499351] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZM
[Sun Aug 30 03:07:39.674003 2026] [authz_core:error] [pid 499145:tid 499351] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZM
[Sun Aug 30 03:07:39.687250 2026] [security2:error] [pid 503470:tid 503651] [client 20.104.104.62:41128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.dottfanciullacci.it"] [uri "/waf.php"] [unique_id "apPkyz8EKFABaii6jtP4LgAAALg"]
[Sun Aug 30 03:07:39.687804 2026] [security2:error] [pid 503470:tid 503646] [client 20.104.104.62:14353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/wp-the.php"] [unique_id "apPkyz8EKFABaii6jtP4LwAAALM"]
[Sun Aug 30 03:07:39.688437 2026] [security2:error] [pid 503470:tid 503640] [client 20.104.104.62:57013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/sf.php"] [unique_id "apPkyz8EKFABaii6jtP4MAAAAK0"]
[Sun Aug 30 03:07:39.690375 2026] [security2:error] [pid 503470:tid 503617] [client 20.48.250.41:60764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/users.php"] [unique_id "apPkyz8EKFABaii6jtP4MwAAAJY"]
[Sun Aug 30 03:07:39.694796 2026] [security2:error] [pid 503470:tid 503667] [client 20.196.209.81:5085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/radio.php"] [unique_id "apPkyz8EKFABaii6jtP4NgAAAMg"]
[Sun Aug 30 03:07:39.695717 2026] [security2:error] [pid 503470:tid 503721] [client 20.104.18.15:29673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/nofile.php"] [unique_id "apPkyz8EKFABaii6jtP4NwAAAP4"]
[Sun Aug 30 03:07:39.700588 2026] [security2:error] [pid 503470:tid 503644] [client 20.104.50.220:32527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-ctac.php"] [unique_id "apPkyz8EKFABaii6jtP4OgAAALE"]
[Sun Aug 30 03:07:39.728213 2026] [security2:error] [pid 503470:tid 503677] [client 158.23.147.79:63938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/file.php"] [unique_id "apPkyz8EKFABaii6jtP4UQAAANI"]
[Sun Aug 30 03:07:39.743033 2026] [security2:error] [pid 499145:tid 499356] [client 40.83.93.50:9676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/wp-load.php"] [unique_id "apPky1JNq1G5uRhTNnuGAwAAAFE"]
[Sun Aug 30 03:07:39.760417 2026] [security2:error] [pid 503470:tid 503640] [client 20.63.81.20:4327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/edit.php"] [unique_id "apPkyz8EKFABaii6jtP4ZwAAAK0"]
[Sun Aug 30 03:07:39.793391 2026] [security2:error] [pid 503470:tid 503668] [client 68.155.159.216:61419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apPkyz8EKFABaii6jtP4gwAAAMk"]
[Sun Aug 30 03:07:39.818940 2026] [security2:error] [pid 499145:tid 499395] [client 20.104.104.62:56985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/4e.php"] [unique_id "apPky1JNq1G5uRhTNnuGFwAAAHg"]
[Sun Aug 30 03:07:39.823638 2026] [security2:error] [pid 503470:tid 503637] [client 20.48.250.41:60739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/bzjdlofz.php"] [unique_id "apPkyz8EKFABaii6jtP4jgAAAKo"]
[Sun Aug 30 03:07:39.832660 2026] [security2:error] [pid 503470:tid 503644] [client 20.104.104.62:14843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/wt.php"] [unique_id "apPkyz8EKFABaii6jtP4kgAAALE"]
[Sun Aug 30 03:07:39.871925 2026] [security2:error] [pid 503470:tid 503709] [client 20.104.50.220:33337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/saya.php"] [unique_id "apPkyz8EKFABaii6jtP4nQAAAPI"]
[Sun Aug 30 03:07:39.885112 2026] [security2:error] [pid 499145:tid 499375] [client 4.205.62.107:17792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/packed.php"] [unique_id "apPky1JNq1G5uRhTNnuGMgAAAGQ"]
[Sun Aug 30 03:07:39.893850 2026] [security2:error] [pid 499145:tid 499296] [client 158.23.147.79:63937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/file17.php"] [unique_id "apPky1JNq1G5uRhTNnuGMwAAABU"]
[Sun Aug 30 03:07:39.897339 2026] [security2:error] [pid 503470:tid 503631] [client 20.63.81.20:4313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/tqkdqbbv.php"] [unique_id "apPkyz8EKFABaii6jtP4pQAAAKQ"]
[Sun Aug 30 03:07:39.907556 2026] [security2:error] [pid 503470:tid 503678] [client 20.104.50.220:61449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/DC.php"] [unique_id "apPkyz8EKFABaii6jtP4qAAAANM"]
[Sun Aug 30 03:07:39.925387 2026] [authz_core:error] [pid 503470:tid 503698] [client 74.7.227.8:38186] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:39.925719 2026] [authz_core:error] [pid 503470:tid 503698] [client 74.7.227.8:38186] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:39.960841 2026] [security2:error] [pid 503470:tid 503723] [client 20.48.250.41:62579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/selesai.php"] [unique_id "apPkyz8EKFABaii6jtP4wAAAAQA"]
[Sun Aug 30 03:07:39.961884 2026] [security2:error] [pid 503470:tid 503620] [client 20.104.104.62:14846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/im.php"] [unique_id "apPkyz8EKFABaii6jtP4wwAAAJk"]
[Sun Aug 30 03:07:39.962219 2026] [authz_core:error] [pid 499145:tid 499391] [client 216.73.216.128:47617] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:39.962542 2026] [authz_core:error] [pid 499145:tid 499391] [client 216.73.216.128:47617] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:39.965788 2026] [security2:error] [pid 503470:tid 503690] [client 20.104.104.62:55814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/ssss.php"] [unique_id "apPkyz8EKFABaii6jtP4ywAAAN8"]
[Sun Aug 30 03:07:40.025880 2026] [security2:error] [pid 503470:tid 503662] [client 20.63.81.20:4322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/kjyehoxl.php"] [unique_id "apPkzD8EKFABaii6jtP48QAAAMM"]
[Sun Aug 30 03:07:40.044304 2026] [security2:error] [pid 503470:tid 503718] [client 20.151.200.44:59474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/sf.php"] [unique_id "apPkzD8EKFABaii6jtP4-wAAAPs"]
[Sun Aug 30 03:07:40.087573 2026] [security2:error] [pid 503470:tid 503630] [client 20.48.250.41:60736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/shlo.php"] [unique_id "apPkzD8EKFABaii6jtP5GwAAAKM"]
[Sun Aug 30 03:07:40.088956 2026] [security2:error] [pid 503470:tid 503691] [client 20.104.104.62:14807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/file.php"] [unique_id "apPkzD8EKFABaii6jtP5HQAAAOA"]
[Sun Aug 30 03:07:40.094376 2026] [security2:error] [pid 503470:tid 503654] [client 20.104.104.62:57010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/zoz.php"] [unique_id "apPkzD8EKFABaii6jtP5JQAAALs"]
[Sun Aug 30 03:07:40.097215 2026] [autoindex:error] [pid 503470:tid 503685] [client 20.104.50.220:28700] AH01276: Cannot serve directory /var/www/html/.well-known/: No matching DirectoryIndex (index.cgi,index.php,index.html,index.htm) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:07:40.102136 2026] [security2:error] [pid 503470:tid 503696] [client 20.104.50.220:63548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/sure.php"] [unique_id "apPkzD8EKFABaii6jtP5KwAAAOU"]
[Sun Aug 30 03:07:40.103811 2026] [security2:error] [pid 503470:tid 503639] [client 158.23.147.79:63897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/file5.php"] [unique_id "apPkzD8EKFABaii6jtP5LAAAAKw"]
[Sun Aug 30 03:07:40.105359 2026] [security2:error] [pid 503470:tid 503684] [client 20.196.209.81:1143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/functions.php"] [unique_id "apPkzD8EKFABaii6jtP5LQAAANk"]
[Sun Aug 30 03:07:40.125999 2026] [authz_core:error] [pid 503470:tid 503638] [client 66.249.66.198:52434] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:40.126302 2026] [authz_core:error] [pid 503470:tid 503638] [client 66.249.66.198:52434] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:40.138608 2026] [security2:error] [pid 499145:tid 499308] [client 40.83.93.50:18541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/new.php"] [unique_id "apPkzFJNq1G5uRhTNnuGigAAACE"]
[Sun Aug 30 03:07:40.159074 2026] [security2:error] [pid 503470:tid 503655] [client 20.63.81.20:4237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/llyuxaqd.php"] [unique_id "apPkzD8EKFABaii6jtP5RwAAALw"]
[Sun Aug 30 03:07:40.163737 2026] [security2:error] [pid 503470:tid 503695] [client 20.104.50.220:28700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/images/java.php"] [unique_id "apPkzD8EKFABaii6jtP5SQAAAOQ"]
[Sun Aug 30 03:07:40.192516 2026] [authz_core:error] [pid 499145:tid 499304] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:40.192793 2026] [authz_core:error] [pid 499145:tid 499304] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:40.207794 2026] [security2:error] [pid 503470:tid 503634] [client 40.83.93.50:11518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/wp-settings.php"] [unique_id "apPkzD8EKFABaii6jtP5ZQAAAKc"]
[Sun Aug 30 03:07:40.230057 2026] [security2:error] [pid 503470:tid 503716] [client 20.104.104.62:55861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/kcs.php"] [unique_id "apPkzD8EKFABaii6jtP5bgAAAPk"]
[Sun Aug 30 03:07:40.238112 2026] [security2:error] [pid 503470:tid 503657] [client 20.104.104.62:14823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/ca.php"] [unique_id "apPkzD8EKFABaii6jtP5dAAAAL4"]
[Sun Aug 30 03:07:40.241308 2026] [security2:error] [pid 503470:tid 503633] [client 65.108.6.34:34654] ModSecurity: Warning. Matched phrase "SEOkicks" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "flashflooring.co.uk"] [uri "/index.php"] [unique_id "apPkyz8EKFABaii6jtP30gAAAKY"], referer: https://flashflooring.co.uk/my-account/lost-password/
[Sun Aug 30 03:07:40.244970 2026] [security2:error] [pid 503470:tid 503646] [client 68.155.159.216:11237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apPkzD8EKFABaii6jtP5egAAALM"]
[Sun Aug 30 03:07:40.260386 2026] [security2:error] [pid 503470:tid 503710] [client 20.48.250.41:60742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/asax.php"] [unique_id "apPkzD8EKFABaii6jtP5igAAAPM"]
[Sun Aug 30 03:07:40.288538 2026] [security2:error] [pid 503470:tid 503684] [client 20.63.81.20:4263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/nbwxolou.php"] [unique_id "apPkzD8EKFABaii6jtP5mwAAANk"]
[Sun Aug 30 03:07:40.372921 2026] [security2:error] [pid 503470:tid 503629] [client 20.104.104.62:14829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/pb.php"] [unique_id "apPkzD8EKFABaii6jtP5zQAAAKI"]
[Sun Aug 30 03:07:40.376263 2026] [security2:error] [pid 503470:tid 503640] [client 20.104.104.62:57009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/tajj.php"] [unique_id "apPkzD8EKFABaii6jtP5zgAAAK0"]
[Sun Aug 30 03:07:40.377149 2026] [security2:error] [pid 503470:tid 503712] [client 158.23.147.79:63965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/file88.php"] [unique_id "apPkzD8EKFABaii6jtP5zwAAAPU"]
[Sun Aug 30 03:07:40.384324 2026] [security2:error] [pid 499145:tid 499295] [client 68.155.159.216:55110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-content/admin.php"] [unique_id "apPkzFJNq1G5uRhTNnuHCAAAABQ"]
[Sun Aug 30 03:07:40.395744 2026] [security2:error] [pid 503470:tid 503689] [client 20.197.61.180:19032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/classsmtps.php"] [unique_id "apPkzD8EKFABaii6jtP54AAAAN4"]
[Sun Aug 30 03:07:40.403757 2026] [security2:error] [pid 503470:tid 503657] [client 20.48.250.41:62493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/fetch.php"] [unique_id "apPkzD8EKFABaii6jtP56gAAAL4"]
[Sun Aug 30 03:07:40.423149 2026] [security2:error] [pid 503470:tid 503603] [client 20.63.81.20:4142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/nsxeubyv.php"] [unique_id "apPkzD8EKFABaii6jtP59wAAAIg"]
[Sun Aug 30 03:07:40.470967 2026] [security2:error] [pid 503470:tid 503606] [client 20.104.18.15:43956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "garypia.co"] [uri "/reviall.php"] [unique_id "apPkzD8EKFABaii6jtP6DgAAAIs"]
[Sun Aug 30 03:07:40.472971 2026] [security2:error] [pid 503470:tid 503666] [client 20.104.50.220:27568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/wp-cli.php"] [unique_id "apPkzD8EKFABaii6jtP6EQAAAMc"]
[Sun Aug 30 03:07:40.482608 2026] [authz_core:error] [pid 503470:tid 503668] [client 66.249.66.74:61329] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:40.483039 2026] [authz_core:error] [pid 503470:tid 503668] [client 66.249.66.74:61329] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:40.513988 2026] [security2:error] [pid 503470:tid 503655] [client 20.104.104.62:56994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/bge.php"] [unique_id "apPkzD8EKFABaii6jtP6MQAAALw"]
[Sun Aug 30 03:07:40.515357 2026] [security2:error] [pid 503470:tid 503723] [client 158.23.147.79:63882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/NewFile.php/"] [unique_id "apPkzD8EKFABaii6jtP6MwAAAQA"]
[Sun Aug 30 03:07:40.523700 2026] [security2:error] [pid 499145:tid 499356] [client 20.196.209.81:19937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/elp.php"] [unique_id "apPkzFJNq1G5uRhTNnuHPwAAAFE"]
[Sun Aug 30 03:07:40.525497 2026] [security2:error] [pid 503470:tid 503619] [client 20.104.104.62:14798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/pk.php"] [unique_id "apPkzD8EKFABaii6jtP6NgAAAJg"]
[Sun Aug 30 03:07:40.527746 2026] [security2:error] [pid 503470:tid 503705] [client 20.104.50.220:6115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/57.php"] [unique_id "apPkzD8EKFABaii6jtP6OAAAAO4"]
[Sun Aug 30 03:07:40.536568 2026] [security2:error] [pid 499145:tid 499353] [client 20.48.250.41:60675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/vx.php"] [unique_id "apPkzFJNq1G5uRhTNnuHRwAAAE4"]
[Sun Aug 30 03:07:40.555724 2026] [security2:error] [pid 499145:tid 499296] [client 20.63.81.20:4098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/zfqipfss.php"] [unique_id "apPkzFJNq1G5uRhTNnuHTwAAABU"]
[Sun Aug 30 03:07:40.572006 2026] [security2:error] [pid 503470:tid 503718] [client 68.155.159.216:53203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-admin/user/index.php"] [unique_id "apPkzD8EKFABaii6jtP6UQAAAPs"]
[Sun Aug 30 03:07:40.579700 2026] [security2:error] [pid 503470:tid 503643] [client 158.23.184.117:2314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "apPkzD8EKFABaii6jtP6WwAAALA"]
[Sun Aug 30 03:07:40.582283 2026] [security2:error] [pid 503470:tid 503670] [client 114.119.153.211:46163] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jacobs-treasures.com"] [uri "/shop"] [unique_id "apPkzD8EKFABaii6jtP6XgAAAMs"], referer: https://jacobs-treasures.com/shop
[Sun Aug 30 03:07:40.593774 2026] [security2:error] [pid 503470:tid 503715] [client 4.205.62.107:62088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/cloud.php"] [unique_id "apPkzD8EKFABaii6jtP6ZwAAAPg"]
[Sun Aug 30 03:07:40.598953 2026] [authz_core:error] [pid 503470:tid 503645] [client 216.73.216.128:41450] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:40.599296 2026] [authz_core:error] [pid 503470:tid 503645] [client 216.73.216.128:41450] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:40.606299 2026] [security2:error] [pid 499145:tid 499354] [client 20.48.251.3:60512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/xve22.php"] [unique_id "apPkzFJNq1G5uRhTNnuHagAAAE8"]
[Sun Aug 30 03:07:40.610020 2026] [security2:error] [pid 499145:tid 499330] [client 20.48.251.3:6496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/admin-ajax.php"] [unique_id "apPkzFJNq1G5uRhTNnuHbQAAADc"]
[Sun Aug 30 03:07:40.616638 2026] [security2:error] [pid 499145:tid 499377] [client 158.23.147.79:63910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/dropdown.php"] [unique_id "apPkzFJNq1G5uRhTNnuHbwAAAGY"]
[Sun Aug 30 03:07:40.619410 2026] [security2:error] [pid 503470:tid 503625] [client 20.104.50.220:17337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/.well-known/about.php"] [unique_id "apPkzD8EKFABaii6jtP6cAAAAJ4"]
[Sun Aug 30 03:07:40.620795 2026] [security2:error] [pid 499145:tid 499348] [client 68.155.159.216:12317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apPkzFJNq1G5uRhTNnuHcQAAAEk"]
[Sun Aug 30 03:07:40.653728 2026] [security2:error] [pid 503470:tid 503630] [client 20.104.104.62:55867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/ssh3ll.php"] [unique_id "apPkzD8EKFABaii6jtP6cgAAAKM"]
[Sun Aug 30 03:07:40.658605 2026] [security2:error] [pid 503470:tid 503600] [client 40.83.93.50:12302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/goods.php"] [unique_id "apPkzD8EKFABaii6jtP6dAAAAIU"]
[Sun Aug 30 03:07:40.667112 2026] [security2:error] [pid 499145:tid 499289] [client 20.104.104.62:14339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/ft.php"] [unique_id "apPkzFJNq1G5uRhTNnuHgAAAAA4"]
[Sun Aug 30 03:07:40.669503 2026] [authz_core:error] [pid 499145:tid 499290] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:40.669892 2026] [authz_core:error] [pid 499145:tid 499290] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:40.672876 2026] [security2:error] [pid 503470:tid 503683] [client 40.83.93.50:11465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/themes/wp-signup.php"] [unique_id "apPkzD8EKFABaii6jtP6eQAAANg"]
[Sun Aug 30 03:07:40.683516 2026] [security2:error] [pid 503470:tid 503671] [client 20.48.250.41:62523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/global.php"] [unique_id "apPkzD8EKFABaii6jtP6ewAAAMw"]
[Sun Aug 30 03:07:40.684756 2026] [security2:error] [pid 499145:tid 499279] [client 20.63.81.20:4149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.needlifeinsuranceuk.com"] [uri "/zrjuyoos.php"] [unique_id "apPkzFJNq1G5uRhTNnuHgwAAAAQ"]
[Sun Aug 30 03:07:40.691343 2026] [authz_core:error] [pid 499145:tid 499351] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:40.691601 2026] [authz_core:error] [pid 499145:tid 499351] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:40.692117 2026] [security2:error] [pid 503470:tid 503680] [client 20.220.10.235:29081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPkzD8EKFABaii6jtP6fQAAANU"]
[Sun Aug 30 03:07:40.717589 2026] [security2:error] [pid 503470:tid 503676] [client 20.104.18.15:28492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/lib.php/new.php"] [unique_id "apPkzD8EKFABaii6jtP6lQAAANE"]
[Sun Aug 30 03:07:40.719831 2026] [security2:error] [pid 503470:tid 503637] [client 158.23.184.117:2337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/light.php"] [unique_id "apPkzD8EKFABaii6jtP6mgAAAKo"]
[Sun Aug 30 03:07:40.722639 2026] [security2:error] [pid 503470:tid 503672] [client 20.104.18.15:34795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/nano.php"] [unique_id "apPkzD8EKFABaii6jtP6ogAAAM0"]
[Sun Aug 30 03:07:40.724569 2026] [security2:error] [pid 503470:tid 503697] [client 20.104.50.220:46856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/error.php"] [unique_id "apPkzD8EKFABaii6jtP6pAAAAOY"]
[Sun Aug 30 03:07:40.733723 2026] [security2:error] [pid 503470:tid 503723] [client 20.48.251.3:55502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/cli_bootstrap.php"] [unique_id "apPkzD8EKFABaii6jtP6rAAAAQA"]
[Sun Aug 30 03:07:40.739824 2026] [security2:error] [pid 503470:tid 503725] [client 158.23.147.79:63881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/.well-known/index.php"] [unique_id "apPkzD8EKFABaii6jtP6sAAAAQI"]
[Sun Aug 30 03:07:40.753040 2026] [security2:error] [pid 503470:tid 503627] [client 4.205.62.107:64650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/app_dev.php"] [unique_id "apPkzD8EKFABaii6jtP6vgAAAKA"]
[Sun Aug 30 03:07:40.761989 2026] [security2:error] [pid 499145:tid 499341] [client 20.104.18.15:18310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/akismet.php"] [unique_id "apPkzFJNq1G5uRhTNnuHpgAAAEI"]
[Sun Aug 30 03:07:40.772057 2026] [security2:error] [pid 503470:tid 503651] [client 20.104.50.220:28729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/htdocs.php"] [unique_id "apPkzD8EKFABaii6jtP6wAAAALg"]
[Sun Aug 30 03:07:40.779062 2026] [security2:error] [pid 503470:tid 503663] [client 4.205.62.107:22531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/ws62.php"] [unique_id "apPkzD8EKFABaii6jtP6xQAAAMQ"]
[Sun Aug 30 03:07:40.784992 2026] [authz_core:error] [pid 499145:tid 499310] [client 216.73.216.128:47617] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:40.785438 2026] [authz_core:error] [pid 499145:tid 499310] [client 216.73.216.128:47617] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:40.786023 2026] [security2:error] [pid 503470:tid 503674] [client 20.104.104.62:56987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/motu.php"] [unique_id "apPkzD8EKFABaii6jtP6xgAAAM8"]
[Sun Aug 30 03:07:40.790080 2026] [security2:error] [pid 503470:tid 503690] [client 20.104.18.15:23477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/w3lls.php"] [unique_id "apPkzD8EKFABaii6jtP6ywAAAN8"]
[Sun Aug 30 03:07:40.797413 2026] [security2:error] [pid 503470:tid 503672] [client 4.205.62.107:36632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/aws-credentials.php"] [unique_id "apPkzD8EKFABaii6jtP60AAAAM0"]
[Sun Aug 30 03:07:40.809989 2026] [security2:error] [pid 503470:tid 503639] [client 20.48.250.41:62482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/fs.php"] [unique_id "apPkzD8EKFABaii6jtP62gAAAKw"]
[Sun Aug 30 03:07:40.813553 2026] [security2:error] [pid 503470:tid 503709] [client 20.104.104.62:15305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/wp-ver.php"] [unique_id "apPkzD8EKFABaii6jtP63QAAAPI"]
[Sun Aug 30 03:07:40.823578 2026] [security2:error] [pid 503470:tid 503669] [client 20.220.10.235:29106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPkzD8EKFABaii6jtP64QAAAMo"]
[Sun Aug 30 03:07:40.826268 2026] [security2:error] [pid 503470:tid 503619] [client 20.104.18.15:51585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/sallu.php"] [unique_id "apPkzD8EKFABaii6jtP64wAAAJg"]
[Sun Aug 30 03:07:40.835202 2026] [security2:error] [pid 503470:tid 503638] [client 158.23.147.79:63920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-content/themes/too.php"] [unique_id "apPkzD8EKFABaii6jtP65wAAAKs"]
[Sun Aug 30 03:07:40.836491 2026] [security2:error] [pid 503470:tid 503720] [client 20.48.251.3:4715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/wp-access.php"] [unique_id "apPkzD8EKFABaii6jtP66QAAAP0"]
[Sun Aug 30 03:07:40.844352 2026] [security2:error] [pid 503470:tid 503685] [client 20.104.50.220:32719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-defaul.php"] [unique_id "apPkzD8EKFABaii6jtP68wAAANo"]
[Sun Aug 30 03:07:40.851854 2026] [security2:error] [pid 503470:tid 503694] [client 20.104.18.15:29160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/run.php"] [unique_id "apPkzD8EKFABaii6jtP69wAAAOM"]
[Sun Aug 30 03:07:40.862227 2026] [security2:error] [pid 503470:tid 503681] [client 158.23.184.117:2331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/wp-admin/css/about.php7"] [unique_id "apPkzD8EKFABaii6jtP6_gAAANY"]
[Sun Aug 30 03:07:40.916510 2026] [security2:error] [pid 499145:tid 499399] [client 20.104.104.62:55815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/wefile.php"] [unique_id "apPkzFJNq1G5uRhTNnuH2AAAAHw"]
[Sun Aug 30 03:07:40.942727 2026] [security2:error] [pid 503470:tid 503616] [client 20.196.209.81:5102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/options-reading.php"] [unique_id "apPkzD8EKFABaii6jtP7HQAAAJU"]
[Sun Aug 30 03:07:40.943098 2026] [security2:error] [pid 499145:tid 499320] [client 20.104.104.62:14839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/ah24.php"] [unique_id "apPkzFJNq1G5uRhTNnuH4QAAAC0"]
[Sun Aug 30 03:07:40.949309 2026] [security2:error] [pid 503470:tid 503626] [client 158.23.147.79:63962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/radio.php"] [unique_id "apPkzD8EKFABaii6jtP7IQAAAJ8"]
[Sun Aug 30 03:07:40.953714 2026] [security2:error] [pid 503470:tid 503707] [client 20.220.10.235:29086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/h02ugyh.php"] [unique_id "apPkzD8EKFABaii6jtP7JgAAAPA"]
[Sun Aug 30 03:07:40.960683 2026] [security2:error] [pid 503470:tid 503699] [client 20.48.250.41:62591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/ioxi.php"] [unique_id "apPkzD8EKFABaii6jtP7LgAAAOg"]
[Sun Aug 30 03:07:40.965136 2026] [authz_core:error] [pid 503470:tid 503605] [client 66.249.66.206:58904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:40.965576 2026] [authz_core:error] [pid 503470:tid 503605] [client 66.249.66.206:58904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:40.965847 2026] [authz_core:error] [pid 503470:tid 503623] [client 216.73.216.128:29153] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:40.966283 2026] [authz_core:error] [pid 503470:tid 503623] [client 216.73.216.128:29153] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:40.998240 2026] [security2:error] [pid 503470:tid 503709] [client 68.155.159.216:61681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/goat1.php"] [unique_id "apPkzD8EKFABaii6jtP7RQAAAPI"]
[Sun Aug 30 03:07:41.002769 2026] [security2:error] [pid 503470:tid 503693] [client 158.23.184.117:2348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/alf.php"] [unique_id "apPkzT8EKFABaii6jtP7SQAAAOI"]
[Sun Aug 30 03:07:41.006066 2026] [security2:error] [pid 503470:tid 503642] [client 68.155.159.216:60884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apPkzT8EKFABaii6jtP7SgAAAK8"]
[Sun Aug 30 03:07:41.009861 2026] [security2:error] [pid 499145:tid 499341] [client 20.104.50.220:32846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/do.php"] [unique_id "apPkzVJNq1G5uRhTNnuH_QAAAEI"]
[Sun Aug 30 03:07:41.048454 2026] [security2:error] [pid 499145:tid 499377] [client 158.23.147.79:63974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPkzVJNq1G5uRhTNnuIFwAAAGY"]
[Sun Aug 30 03:07:41.054462 2026] [security2:error] [pid 503470:tid 503712] [client 20.104.104.62:55823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/Contrller.php"] [unique_id "apPkzT8EKFABaii6jtP7WQAAAPU"]
[Sun Aug 30 03:07:41.056589 2026] [authz_core:error] [pid 499145:tid 499372] [client 216.73.216.128:47617] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:41.056633 2026] [security2:error] [pid 503470:tid 503612] [client 4.205.62.107:31721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/var/www/wallet/index.php"] [unique_id "apPkzT8EKFABaii6jtP7WwAAAJE"]
[Sun Aug 30 03:07:41.056863 2026] [authz_core:error] [pid 499145:tid 499372] [client 216.73.216.128:47617] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:41.061698 2026] [security2:error] [pid 503470:tid 503711] [client 4.205.62.107:18797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/wp-info.php"] [unique_id "apPkzT8EKFABaii6jtP7XQAAAPQ"]
[Sun Aug 30 03:07:41.062118 2026] [security2:error] [pid 503470:tid 503674] [client 20.104.50.220:59550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-content/uploads/simple-file-list/DC.php"] [unique_id "apPkzT8EKFABaii6jtP7XwAAAM8"]
[Sun Aug 30 03:07:41.069167 2026] [security2:error] [pid 499145:tid 499325] [client 20.104.104.62:14826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPkzVJNq1G5uRhTNnuIIQAAADI"]
[Sun Aug 30 03:07:41.088880 2026] [security2:error] [pid 503470:tid 503658] [client 20.220.10.235:29105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/sf.php"] [unique_id "apPkzT8EKFABaii6jtP7bgAAAL8"]
[Sun Aug 30 03:07:41.108093 2026] [security2:error] [pid 499145:tid 499278] [client 20.197.61.180:19050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/install.php"] [unique_id "apPkzVJNq1G5uRhTNnuIMQAAAAM"]
[Sun Aug 30 03:07:41.146862 2026] [security2:error] [pid 503470:tid 503719] [client 40.83.93.50:11474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/updraft/about.php"] [unique_id "apPkzT8EKFABaii6jtP7jQAAAPw"]
[Sun Aug 30 03:07:41.171141 2026] [security2:error] [pid 503470:tid 503623] [client 20.48.250.41:62542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/bootstrap.php"] [unique_id "apPkzT8EKFABaii6jtP7nQAAAJw"]
[Sun Aug 30 03:07:41.173507 2026] [authz_core:error] [pid 503470:tid 503688] [client 66.249.66.70:45075] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:41.173946 2026] [authz_core:error] [pid 503470:tid 503688] [client 66.249.66.70:45075] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:41.192942 2026] [security2:error] [pid 499145:tid 499401] [client 158.23.184.117:2326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/wp-admin/import.php"] [unique_id "apPkzVJNq1G5uRhTNnuIVwAAAH4"]
[Sun Aug 30 03:07:41.194315 2026] [security2:error] [pid 503470:tid 503602] [client 20.104.104.62:57020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/file66.php"] [unique_id "apPkzT8EKFABaii6jtP7sAAAAIc"]
[Sun Aug 30 03:07:41.195272 2026] [authz_core:error] [pid 499145:tid 499386] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZM
[Sun Aug 30 03:07:41.195753 2026] [authz_core:error] [pid 499145:tid 499386] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZM
[Sun Aug 30 03:07:41.201947 2026] [security2:error] [pid 503470:tid 503614] [client 40.83.93.50:13565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/m.php"] [unique_id "apPkzT8EKFABaii6jtP7tgAAAJM"]
[Sun Aug 30 03:07:41.223628 2026] [security2:error] [pid 503470:tid 503692] [client 158.23.147.79:63993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/makeasmtp.php"] [unique_id "apPkzT8EKFABaii6jtP7wwAAAOE"]
[Sun Aug 30 03:07:41.225729 2026] [security2:error] [pid 503470:tid 503684] [client 20.220.10.235:29090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/4e.php"] [unique_id "apPkzT8EKFABaii6jtP7xAAAANk"]
[Sun Aug 30 03:07:41.236687 2026] [security2:error] [pid 503470:tid 503607] [client 20.104.104.62:14344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/waf.php"] [unique_id "apPkzT8EKFABaii6jtP7zQAAAIw"]
[Sun Aug 30 03:07:41.238438 2026] [authz_core:error] [pid 499145:tid 499315] [client 216.73.216.128:47617] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:41.238718 2026] [authz_core:error] [pid 499145:tid 499315] [client 216.73.216.128:47617] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:41.240008 2026] [security2:error] [pid 503470:tid 503631] [client 20.104.50.220:63538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/dl.php"] [unique_id "apPkzT8EKFABaii6jtP70QAAAKQ"]
[Sun Aug 30 03:07:41.279367 2026] [security2:error] [pid 503470:tid 503680] [client 20.151.200.44:59514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/4e.php"] [unique_id "apPkzT8EKFABaii6jtP79wAAANU"]
[Sun Aug 30 03:07:41.307480 2026] [security2:error] [pid 503470:tid 503698] [client 20.48.250.41:62552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/export.php"] [unique_id "apPkzT8EKFABaii6jtP8DAAAAOc"]
[Sun Aug 30 03:07:41.320696 2026] [security2:error] [pid 503470:tid 503602] [client 158.23.147.79:63963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apPkzT8EKFABaii6jtP8EQAAAIc"]
[Sun Aug 30 03:07:41.334260 2026] [security2:error] [pid 503470:tid 503671] [client 158.23.184.117:2374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "apPkzT8EKFABaii6jtP8HwAAAMw"]
[Sun Aug 30 03:07:41.341699 2026] [security2:error] [pid 503470:tid 503685] [client 20.104.104.62:46677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/blnux.php"] [unique_id "apPkzT8EKFABaii6jtP8JgAAANo"]
[Sun Aug 30 03:07:41.351380 2026] [security2:error] [pid 503470:tid 503704] [client 68.155.159.216:56329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apPkzT8EKFABaii6jtP8LwAAAO0"]
[Sun Aug 30 03:07:41.357581 2026] [security2:error] [pid 503470:tid 503607] [client 20.104.50.220:64454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/js/java.php"] [unique_id "apPkzT8EKFABaii6jtP8NAAAAIw"]
[Sun Aug 30 03:07:41.368565 2026] [security2:error] [pid 503470:tid 503718] [client 20.220.10.235:29097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/ssss.php"] [unique_id "apPkzT8EKFABaii6jtP8OwAAAPs"]
[Sun Aug 30 03:07:41.371693 2026] [authz_core:error] [pid 503470:tid 503664] [client 74.7.227.8:38186] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:41.372026 2026] [authz_core:error] [pid 503470:tid 503664] [client 74.7.227.8:38186] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:41.428808 2026] [security2:error] [pid 503470:tid 503620] [client 158.23.147.79:63948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apPkzT8EKFABaii6jtP8XwAAAJk"]
[Sun Aug 30 03:07:41.454765 2026] [security2:error] [pid 503470:tid 503668] [client 20.48.250.41:60740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/gk.php"] [unique_id "apPkzT8EKFABaii6jtP8dQAAAMk"]
[Sun Aug 30 03:07:41.469903 2026] [security2:error] [pid 503470:tid 503710] [client 20.104.104.62:46719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/attack.php"] [unique_id "apPkzT8EKFABaii6jtP8fgAAAPM"]
[Sun Aug 30 03:07:41.470483 2026] [security2:error] [pid 499145:tid 499306] [client 20.196.209.81:5089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/db.php"] [unique_id "apPkzVJNq1G5uRhTNnuIwAAAAB8"]
[Sun Aug 30 03:07:41.476937 2026] [cgid:error] [pid 503470:tid 503712] [client 158.23.184.117:2348] AH01264: stderr from /home1/greaskit/public_html/willysmartpersonal/cgi-bin: script not found or unable to stat
[Sun Aug 30 03:07:41.515671 2026] [security2:error] [pid 503470:tid 503606] [client 68.155.159.216:55135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/xmlrpc.php"] [unique_id "apPkzT8EKFABaii6jtP8lAAAAIs"]
[Sun Aug 30 03:07:41.532334 2026] [authz_core:error] [pid 503470:tid 503640] [client 66.249.66.45:54690] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:41.532584 2026] [authz_core:error] [pid 503470:tid 503640] [client 66.249.66.45:54690] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:41.579787 2026] [security2:error] [pid 503470:tid 503700] [client 158.23.184.117:2348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/wp-admin/admin-post.php"] [unique_id "apPkzT8EKFABaii6jtP8xAAAAOk"]
[Sun Aug 30 03:07:41.591978 2026] [security2:error] [pid 503470:tid 503611] [client 158.23.147.79:63971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-content/languages/about.php"] [unique_id "apPkzT8EKFABaii6jtP8zQAAAJA"]
[Sun Aug 30 03:07:41.607004 2026] [security2:error] [pid 503470:tid 503693] [client 20.104.104.62:57011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/wk/index.php"] [unique_id "apPkzT8EKFABaii6jtP84AAAAOI"]
[Sun Aug 30 03:07:41.611295 2026] [security2:error] [pid 503470:tid 503654] [client 20.104.50.220:27111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/cong.php"] [unique_id "apPkzT8EKFABaii6jtP85AAAALs"]
[Sun Aug 30 03:07:41.611845 2026] [security2:error] [pid 503470:tid 503645] [client 20.48.250.41:60763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/logs1.php"] [unique_id "apPkzT8EKFABaii6jtP86AAAALI"]
[Sun Aug 30 03:07:41.626468 2026] [security2:error] [pid 503470:tid 503688] [client 40.83.93.50:5976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/upgrade-temp-backup/min.php"] [unique_id "apPkzT8EKFABaii6jtP8-wAAAN0"]
[Sun Aug 30 03:07:41.628667 2026] [security2:error] [pid 503470:tid 503686] [client 20.220.10.235:28739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/zoz.php"] [unique_id "apPkzT8EKFABaii6jtP8_QAAANs"]
[Sun Aug 30 03:07:41.652730 2026] [autoindex:error] [pid 503470:tid 503631] [client 100.61.245.67:60022] AH01276: Cannot serve directory /home1/imasicampo/tplax.masicampo.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:07:41.676003 2026] [security2:error] [pid 499145:tid 499308] [client 20.151.200.44:57796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/ssss.php"] [unique_id "apPkzVJNq1G5uRhTNnuJAwAAACE"]
[Sun Aug 30 03:07:41.680964 2026] [security2:error] [pid 503470:tid 503670] [client 20.104.50.220:6137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/56.php"] [unique_id "apPkzT8EKFABaii6jtP9CQAAAMs"]
[Sun Aug 30 03:07:41.690431 2026] [authz_core:error] [pid 499145:tid 499402] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AU
[Sun Aug 30 03:07:41.690858 2026] [authz_core:error] [pid 499145:tid 499402] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AU
[Sun Aug 30 03:07:41.718276 2026] [security2:error] [pid 503470:tid 503614] [client 158.23.184.117:2305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/favicon.php"] [unique_id "apPkzT8EKFABaii6jtP9HAAAAJM"]
[Sun Aug 30 03:07:41.734179 2026] [security2:error] [pid 503470:tid 503606] [client 68.155.159.216:12368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/.well-knownold/index.php"] [unique_id "apPkzT8EKFABaii6jtP9MAAAAIs"]
[Sun Aug 30 03:07:41.734832 2026] [security2:error] [pid 503470:tid 503693] [client 68.155.159.216:64814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-includes/plugins.php"] [unique_id "apPkzT8EKFABaii6jtP9MgAAAOI"]
[Sun Aug 30 03:07:41.739746 2026] [security2:error] [pid 503470:tid 503638] [client 20.48.251.3:56361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/06.php"] [unique_id "apPkzT8EKFABaii6jtP9NwAAAKs"]
[Sun Aug 30 03:07:41.741349 2026] [security2:error] [pid 499145:tid 499374] [client 20.48.250.41:59328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/inege.php"] [unique_id "apPkzVJNq1G5uRhTNnuJKQAAAGM"]
[Sun Aug 30 03:07:41.746822 2026] [security2:error] [pid 499145:tid 499289] [client 4.205.62.107:62067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/asdf.php"] [unique_id "apPkzVJNq1G5uRhTNnuJLQAAAA4"]
[Sun Aug 30 03:07:41.752532 2026] [security2:error] [pid 499145:tid 499328] [client 20.104.50.220:17231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "apPkzVJNq1G5uRhTNnuJMAAAADU"]
[Sun Aug 30 03:07:41.752660 2026] [security2:error] [pid 503470:tid 503641] [client 40.83.93.50:7913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/doc.php"] [unique_id "apPkzT8EKFABaii6jtP9OgAAAK4"]
[Sun Aug 30 03:07:41.756757 2026] [security2:error] [pid 499145:tid 499354] [client 20.104.104.62:55829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/dehnl.php"] [unique_id "apPkzVJNq1G5uRhTNnuJMQAAAE8"]
[Sun Aug 30 03:07:41.764727 2026] [security2:error] [pid 503470:tid 503617] [client 158.23.147.79:63896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-content/banners/about.php"] [unique_id "apPkzT8EKFABaii6jtP9PgAAAJY"]
[Sun Aug 30 03:07:41.776309 2026] [security2:error] [pid 503470:tid 503645] [client 20.48.251.3:64502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/error_log.php"] [unique_id "apPkzT8EKFABaii6jtP9RQAAALI"]
[Sun Aug 30 03:07:41.778312 2026] [security2:error] [pid 503470:tid 503699] [client 20.220.10.235:29108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/kcs.php"] [unique_id "apPkzT8EKFABaii6jtP9SQAAAOg"]
[Sun Aug 30 03:07:41.795325 2026] [security2:error] [pid 499145:tid 499398] [client 20.104.49.130:34529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/pfm.php"] [unique_id "apPkzVJNq1G5uRhTNnuJQgAAAHs"]
[Sun Aug 30 03:07:41.829373 2026] [security2:error] [pid 503470:tid 503676] [client 20.197.61.180:19048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/wp.php"] [unique_id "apPkzT8EKFABaii6jtP9UwAAANE"]
[Sun Aug 30 03:07:41.839915 2026] [authz_core:error] [pid 503470:tid 503609] [client 66.249.66.193:44586] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:41.840366 2026] [authz_core:error] [pid 503470:tid 503609] [client 66.249.66.193:44586] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:41.858318 2026] [security2:error] [pid 503470:tid 503667] [client 20.104.18.15:28534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/info.php/new.php"] [unique_id "apPkzT8EKFABaii6jtP9XAAAAMg"]
[Sun Aug 30 03:07:41.858344 2026] [security2:error] [pid 503470:tid 503652] [client 20.104.18.15:34632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/ano.php"] [unique_id "apPkzT8EKFABaii6jtP9XgAAALk"]
[Sun Aug 30 03:07:41.858361 2026] [security2:error] [pid 503470:tid 503678] [client 158.23.184.117:2403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/wp-admin/css/my.php"] [unique_id "apPkzT8EKFABaii6jtP9XQAAANM"]
[Sun Aug 30 03:07:41.862252 2026] [security2:error] [pid 503470:tid 503690] [client 20.104.50.220:46596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/x.php"] [unique_id "apPkzT8EKFABaii6jtP9YAAAAN8"]
[Sun Aug 30 03:07:41.867971 2026] [security2:error] [pid 503470:tid 503668] [client 20.48.250.41:62535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/wp-link10.php"] [unique_id "apPkzT8EKFABaii6jtP9YwAAAMk"]
[Sun Aug 30 03:07:41.869495 2026] [security2:error] [pid 503470:tid 503723] [client 20.196.209.81:10885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/server.php"] [unique_id "apPkzT8EKFABaii6jtP9ZgAAAQA"]
[Sun Aug 30 03:07:41.875832 2026] [security2:error] [pid 503470:tid 503686] [client 158.23.147.79:63884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-includes/Text/about.php"] [unique_id "apPkzT8EKFABaii6jtP9cAAAANs"]
[Sun Aug 30 03:07:41.887324 2026] [security2:error] [pid 503470:tid 503627] [client 20.104.104.62:55862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/png.php"] [unique_id "apPkzT8EKFABaii6jtP9dAAAAKA"]
[Sun Aug 30 03:07:41.896692 2026] [security2:error] [pid 503470:tid 503721] [client 4.205.62.107:64471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/php-info.php"] [unique_id "apPkzT8EKFABaii6jtP9fAAAAP4"]
[Sun Aug 30 03:07:41.899960 2026] [security2:error] [pid 503470:tid 503620] [client 20.48.251.3:55471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/dd.php"] [unique_id "apPkzT8EKFABaii6jtP9fQAAAJk"]
[Sun Aug 30 03:07:41.907683 2026] [security2:error] [pid 503470:tid 503670] [client 20.104.18.15:18375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/ajax.php"] [unique_id "apPkzT8EKFABaii6jtP9gQAAAMs"]
[Sun Aug 30 03:07:41.925831 2026] [security2:error] [pid 499145:tid 499290] [client 20.220.10.235:28754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/tajj.php"] [unique_id "apPkzVJNq1G5uRhTNnuJaQAAAA8"]
[Sun Aug 30 03:07:41.927686 2026] [authz_core:error] [pid 503470:tid 503615] [client 66.249.66.71:61391] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:41.927845 2026] [security2:error] [pid 499145:tid 499287] [client 20.104.18.15:23492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/fpwch.php"] [unique_id "apPkzVJNq1G5uRhTNnuJawAAAAw"]
[Sun Aug 30 03:07:41.928083 2026] [authz_core:error] [pid 503470:tid 503615] [client 66.249.66.71:61391] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:41.930332 2026] [security2:error] [pid 499145:tid 499296] [client 4.205.62.107:22945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/grsiuk.php"] [unique_id "apPkzVJNq1G5uRhTNnuJbAAAABU"]
[Sun Aug 30 03:07:41.931215 2026] [security2:error] [pid 499145:tid 499277] [client 4.205.62.107:36637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/4563.php"] [unique_id "apPkzVJNq1G5uRhTNnuJbgAAAAI"]
[Sun Aug 30 03:07:41.939674 2026] [authz_core:error] [pid 499145:tid 499323] [client 66.249.66.40:45742] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:41.940075 2026] [authz_core:error] [pid 499145:tid 499323] [client 66.249.66.40:45742] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:41.972399 2026] [security2:error] [pid 503470:tid 503659] [client 20.104.18.15:51680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/biufile.php"] [unique_id "apPkzT8EKFABaii6jtP9oQAAAMA"]
[Sun Aug 30 03:07:41.975299 2026] [security2:error] [pid 503470:tid 503705] [client 20.104.50.220:52814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/hello.php"] [unique_id "apPkzT8EKFABaii6jtP9pAAAAO4"]
[Sun Aug 30 03:07:41.979307 2026] [security2:error] [pid 503470:tid 503662] [client 158.23.147.79:63874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/asd.php"] [unique_id "apPkzT8EKFABaii6jtP9qQAAAMM"]
[Sun Aug 30 03:07:41.995598 2026] [security2:error] [pid 503470:tid 503604] [client 20.104.18.15:29648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/new.php"] [unique_id "apPkzT8EKFABaii6jtP9tgAAAIk"]
[Sun Aug 30 03:07:41.998490 2026] [security2:error] [pid 503470:tid 503673] [client 158.23.184.117:2392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/wp-content/images/doc.php"] [unique_id "apPkzT8EKFABaii6jtP9uQAAAM4"]
[Sun Aug 30 03:07:42.011311 2026] [security2:error] [pid 503470:tid 503636] [client 20.104.50.220:31866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-hmdra.php"] [unique_id "apPkzj8EKFABaii6jtP9wwAAAKk"]
[Sun Aug 30 03:07:42.048403 2026] [security2:error] [pid 503470:tid 503686] [client 20.48.250.41:60761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/ww.php"] [unique_id "apPkzj8EKFABaii6jtP92wAAANs"]
[Sun Aug 30 03:07:42.058858 2026] [security2:error] [pid 503470:tid 503716] [client 20.220.10.235:28746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/bge.php"] [unique_id "apPkzj8EKFABaii6jtP94wAAAPk"]
[Sun Aug 30 03:07:42.061529 2026] [security2:error] [pid 503470:tid 503674] [client 20.48.251.3:5081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/otuz1.php"] [unique_id "apPkzj8EKFABaii6jtP95gAAAM8"]
[Sun Aug 30 03:07:42.069971 2026] [security2:error] [pid 503470:tid 503725] [client 20.104.104.62:55809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/txets.php"] [unique_id "apPkzj8EKFABaii6jtP97gAAAQI"]
[Sun Aug 30 03:07:42.086166 2026] [security2:error] [pid 499145:tid 499369] [client 158.23.147.79:63959] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "tgifa.org"] [uri "/1.php"] [unique_id "apPkzlJNq1G5uRhTNnuJqwAAAF4"]
[Sun Aug 30 03:07:42.086273 2026] [security2:error] [pid 499145:tid 499369] [client 158.23.147.79:63959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/1.php"] [unique_id "apPkzlJNq1G5uRhTNnuJqwAAAF4"]
[Sun Aug 30 03:07:42.102026 2026] [security2:error] [pid 503470:tid 503710] [client 40.83.93.50:11488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/upgrade-temp-backup/pk.php"] [unique_id "apPkzj8EKFABaii6jtP-AwAAAPM"]
[Sun Aug 30 03:07:42.113559 2026] [security2:error] [pid 499145:tid 499348] [client 68.155.159.216:60896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-login.php"] [unique_id "apPkzlJNq1G5uRhTNnuJugAAAEk"]
[Sun Aug 30 03:07:42.150310 2026] [authz_core:error] [pid 499145:tid 499373] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:42.150715 2026] [authz_core:error] [pid 499145:tid 499373] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:42.162812 2026] [security2:error] [pid 503470:tid 503605] [client 20.104.50.220:33198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/funtion.php"] [unique_id "apPkzj8EKFABaii6jtP-HgAAAIo"]
[Sun Aug 30 03:07:42.179879 2026] [security2:error] [pid 503470:tid 503620] [client 158.23.184.117:2315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/wp-comments.php"] [unique_id "apPkzj8EKFABaii6jtP-DgAAAJk"]
[Sun Aug 30 03:07:42.191342 2026] [security2:error] [pid 503470:tid 503672] [client 20.220.10.235:29064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/ssh3ll.php"] [unique_id "apPkzj8EKFABaii6jtP-NwAAAM0"]
[Sun Aug 30 03:07:42.194086 2026] [authz_core:error] [pid 499145:tid 499302] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NG
[Sun Aug 30 03:07:42.194385 2026] [authz_core:error] [pid 499145:tid 499302] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NG
[Sun Aug 30 03:07:42.197236 2026] [security2:error] [pid 503470:tid 503677] [client 20.48.250.41:60738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/w1px.php"] [unique_id "apPkzj8EKFABaii6jtP-PQAAANI"]
[Sun Aug 30 03:07:42.202480 2026] [security2:error] [pid 503470:tid 503601] [client 4.205.62.107:17822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/fns.php"] [unique_id "apPkzj8EKFABaii6jtP-QwAAAIY"]
[Sun Aug 30 03:07:42.205191 2026] [security2:error] [pid 503470:tid 503716] [client 158.23.147.79:62208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/ws.php"] [unique_id "apPkzj8EKFABaii6jtP-RwAAAPk"]
[Sun Aug 30 03:07:42.208281 2026] [security2:error] [pid 503470:tid 503708] [client 20.104.104.62:56961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/wp-login.php"] [unique_id "apPkzj8EKFABaii6jtP-SQAAAPE"]
[Sun Aug 30 03:07:42.237116 2026] [security2:error] [pid 503470:tid 503670] [client 68.155.159.216:61686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-includes/certificates/index.php"] [unique_id "apPkzj8EKFABaii6jtP-WwAAAMs"]
[Sun Aug 30 03:07:42.260785 2026] [security2:error] [pid 503470:tid 503632] [client 20.151.200.44:59538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/zoz.php"] [unique_id "apPkzj8EKFABaii6jtP-bQAAAKU"]
[Sun Aug 30 03:07:42.271787 2026] [security2:error] [pid 503470:tid 503638] [client 20.196.209.81:20299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/favicon.php"] [unique_id "apPkzj8EKFABaii6jtP-eAAAAKs"]
[Sun Aug 30 03:07:42.274637 2026] [security2:error] [pid 503470:tid 503663] [client 20.104.50.220:61480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-content/uploads/simple-file-list/shell.php"] [unique_id "apPkzj8EKFABaii6jtP-ewAAAMQ"]
[Sun Aug 30 03:07:42.310275 2026] [authz_core:error] [pid 503470:tid 503658] [client 66.249.66.67:42536] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:42.310514 2026] [authz_core:error] [pid 503470:tid 503658] [client 66.249.66.67:42536] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:42.317417 2026] [security2:error] [pid 503470:tid 503637] [client 158.23.147.79:63973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-includes/css/index.php"] [unique_id "apPkzj8EKFABaii6jtP-lQAAAKo"]
[Sun Aug 30 03:07:42.321035 2026] [security2:error] [pid 503470:tid 503665] [client 158.23.184.117:2333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/wp-includes/panel.php"] [unique_id "apPkzj8EKFABaii6jtP-mgAAAMY"]
[Sun Aug 30 03:07:42.334583 2026] [security2:error] [pid 503470:tid 503614] [client 20.220.10.235:29058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/motu.php"] [unique_id "apPkzj8EKFABaii6jtP-pwAAAJM"]
[Sun Aug 30 03:07:42.337578 2026] [security2:error] [pid 503470:tid 503724] [client 20.104.104.62:55820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/wp-access.php"] [unique_id "apPkzj8EKFABaii6jtP-qAAAAQE"]
[Sun Aug 30 03:07:42.342949 2026] [security2:error] [pid 503470:tid 503716] [client 20.48.250.41:60678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/to.php"] [unique_id "apPkzj8EKFABaii6jtP-sAAAAPk"]
[Sun Aug 30 03:07:42.365880 2026] [security2:error] [pid 503470:tid 503655] [client 40.83.93.50:12340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/users.php"] [unique_id "apPkzj8EKFABaii6jtP-xAAAALw"]
[Sun Aug 30 03:07:42.368589 2026] [security2:error] [pid 503470:tid 503641] [client 114.119.150.28:28833] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.tulsacriminalattorney.pro"] [uri "/defense-lawyer-blog/2016/01/vehicle-burglary-in-tulsa/"] [unique_id "apPkzj8EKFABaii6jtP-xgAAAK4"], referer: https://www.tulsacriminalattorney.pro/defense-lawyer-blog/2016/01/vehicle-burglary-in-tulsa/
[Sun Aug 30 03:07:42.424400 2026] [security2:error] [pid 503470:tid 503617] [client 114.119.156.126:33687] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bayouking.com"] [uri "/shopping_cart.php/products_id/51/action/remove_product/osCsid/1ac720598ce6d42aafd9231eb748bab1"] [unique_id "apPkzj8EKFABaii6jtP-9QAAAJY"], referer: http://bayouking.com/shopping_cart.php/products_id/51/action/remove_product/osCsid/1ac720598ce6d42aafd9231eb748bab1
[Sun Aug 30 03:07:42.425675 2026] [security2:error] [pid 503470:tid 503643] [client 20.104.50.220:63511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/donate.php"] [unique_id "apPkzj8EKFABaii6jtP-9wAAALA"]
[Sun Aug 30 03:07:42.433705 2026] [security2:error] [pid 503470:tid 503706] [client 158.23.147.79:63969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/cgi-bin/wp-login.php"] [unique_id "apPkzj8EKFABaii6jtP-5gAAAO8"]
[Sun Aug 30 03:07:42.458055 2026] [security2:error] [pid 503470:tid 503642] [client 68.155.159.216:11224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/nf_tracking.php"] [unique_id "apPkzj8EKFABaii6jtP_AQAAAK8"]
[Sun Aug 30 03:07:42.468680 2026] [security2:error] [pid 503470:tid 503631] [client 20.220.10.235:29072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/wefile.php"] [unique_id "apPkzj8EKFABaii6jtP_DAAAAKQ"]
[Sun Aug 30 03:07:42.471406 2026] [security2:error] [pid 503470:tid 503695] [client 20.104.104.62:56976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/wp-content/admin.php"] [unique_id "apPkzj8EKFABaii6jtP_EAAAAOQ"]
[Sun Aug 30 03:07:42.493776 2026] [security2:error] [pid 503470:tid 503679] [client 20.48.250.41:62485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/thui.php"] [unique_id "apPkzj8EKFABaii6jtP_KgAAANQ"]
[Sun Aug 30 03:07:42.509329 2026] [security2:error] [pid 503470:tid 503644] [client 158.23.184.117:2347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/www.php"] [unique_id "apPkzj8EKFABaii6jtP_MAAAALE"]
[Sun Aug 30 03:07:42.556744 2026] [security2:error] [pid 499145:tid 499399] [client 20.197.61.180:7808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/error.php"] [unique_id "apPkzlJNq1G5uRhTNnuKcQAAAHw"]
[Sun Aug 30 03:07:42.567953 2026] [security2:error] [pid 503470:tid 503661] [client 40.83.93.50:11503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/upgrade-temp-backup/plugins/security.php"] [unique_id "apPkzj8EKFABaii6jtP_TQAAAMI"]
[Sun Aug 30 03:07:42.577966 2026] [security2:error] [pid 503470:tid 503638] [client 158.23.147.79:63999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-content/cong.php"] [unique_id "apPkzj8EKFABaii6jtP_VgAAAKs"]
[Sun Aug 30 03:07:42.606523 2026] [security2:error] [pid 499145:tid 499360] [client 20.104.104.62:56988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/log.php"] [unique_id "apPkzlJNq1G5uRhTNnuKggAAAFU"]
[Sun Aug 30 03:07:42.623443 2026] [security2:error] [pid 503470:tid 503628] [client 20.220.10.235:29074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/Contrller.php"] [unique_id "apPkzj8EKFABaii6jtP_dwAAAKE"]
[Sun Aug 30 03:07:42.623816 2026] [security2:error] [pid 499145:tid 499296] [client 68.155.159.216:55118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/atomlib.php"] [unique_id "apPkzlJNq1G5uRhTNnuKhQAAABU"]
[Sun Aug 30 03:07:42.629229 2026] [security2:error] [pid 499145:tid 499299] [client 20.48.250.41:62469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/Jcrop.php"] [unique_id "apPkzlJNq1G5uRhTNnuKiQAAABg"]
[Sun Aug 30 03:07:42.650302 2026] [security2:error] [pid 499145:tid 499377] [client 158.23.184.117:2399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/.well-known/core.php"] [unique_id "apPkzlJNq1G5uRhTNnuKjAAAAGY"]
[Sun Aug 30 03:07:42.651057 2026] [security2:error] [pid 503470:tid 503726] [client 4.205.62.107:32014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/124.php"] [unique_id "apPkzj8EKFABaii6jtP_eQAAAQM"]
[Sun Aug 30 03:07:42.664494 2026] [security2:error] [pid 503470:tid 503669] [client 20.196.209.81:5089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/gecko.php"] [unique_id "apPkzj8EKFABaii6jtP_fAAAAMo"]
[Sun Aug 30 03:07:42.686082 2026] [security2:error] [pid 499145:tid 499281] [client 158.23.147.79:63944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPkzlJNq1G5uRhTNnuKmgAAAAY"]
[Sun Aug 30 03:07:42.689811 2026] [authz_core:error] [pid 499145:tid 499304] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IN
[Sun Aug 30 03:07:42.690129 2026] [authz_core:error] [pid 499145:tid 499304] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IN
[Sun Aug 30 03:07:42.702010 2026] [security2:error] [pid 503470:tid 503679] [client 20.104.50.220:29121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-content/f0x.php"] [unique_id "apPkzj8EKFABaii6jtP_hAAAANQ"]
[Sun Aug 30 03:07:42.733246 2026] [security2:error] [pid 503470:tid 503612] [client 114.119.144.176:26443] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "acs-ent.com"] [uri "/contact/"] [unique_id "apPkzj8EKFABaii6jtP_nAAAAJE"], referer: https://acs-ent.com/contact/
[Sun Aug 30 03:07:42.746914 2026] [security2:error] [pid 503470:tid 503600] [client 20.104.50.220:27569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/getid3s.php"] [unique_id "apPkzj8EKFABaii6jtP_qAAAAIU"]
[Sun Aug 30 03:07:42.754978 2026] [security2:error] [pid 503470:tid 503634] [client 20.104.104.62:55812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/xwpg.php"] [unique_id "apPkzj8EKFABaii6jtP_sAAAAKc"]
[Sun Aug 30 03:07:42.763541 2026] [security2:error] [pid 499145:tid 499321] [client 20.48.250.41:60793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/ws58.php"] [unique_id "apPkzlJNq1G5uRhTNnuKvwAAAC4"]
[Sun Aug 30 03:07:42.764424 2026] [authz_core:error] [pid 503470:tid 503676] [client 66.249.66.43:64508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:42.764820 2026] [authz_core:error] [pid 503470:tid 503676] [client 66.249.66.43:64508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:42.771352 2026] [security2:error] [pid 503470:tid 503648] [client 20.220.10.235:29066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/file66.php"] [unique_id "apPkzj8EKFABaii6jtP_xAAAALU"]
[Sun Aug 30 03:07:42.791325 2026] [security2:error] [pid 503470:tid 503698] [client 158.23.184.117:2338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/akcc.php"] [unique_id "apPkzj8EKFABaii6jtP_0QAAAOc"]
[Sun Aug 30 03:07:42.818595 2026] [security2:error] [pid 499145:tid 499294] [client 20.104.50.220:5559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/55.php"] [unique_id "apPkzlJNq1G5uRhTNnuK3wAAABM"]
[Sun Aug 30 03:07:42.824017 2026] [security2:error] [pid 503470:tid 503619] [client 20.151.200.44:55708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/css/000.php"] [unique_id "apPkzj8EKFABaii6jtP_3QAAAJg"]
[Sun Aug 30 03:07:42.835039 2026] [authz_core:error] [pid 503470:tid 503718] [client 74.7.227.8:38186] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:42.835452 2026] [authz_core:error] [pid 503470:tid 503718] [client 74.7.227.8:38186] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:42.853785 2026] [security2:error] [pid 503470:tid 503709] [client 34.125.55.247:31962] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.engaginggoddaily.com"] [uri "/api/config.json"] [unique_id "apPkzj8EKFABaii6jtP_-AAAAPI"]
[Sun Aug 30 03:07:42.857082 2026] [proxy_http:error] [pid 503470:tid 503682] (20014)Internal error (specific information not available): [client 34.125.55.247:32000] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:42.857103 2026] [proxy:error] [pid 503470:tid 503682] [client 34.125.55.247:32000] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/backend/aws.json
[Sun Aug 30 03:07:42.858875 2026] [proxy_http:error] [pid 499145:tid 499328] (20014)Internal error (specific information not available): [client 34.125.55.247:32078] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:42.858890 2026] [proxy:error] [pid 499145:tid 499328] [client 34.125.55.247:32078] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/config/application.properties
[Sun Aug 30 03:07:42.864481 2026] [proxy_http:error] [pid 503470:tid 503604] (20014)Internal error (specific information not available): [client 34.125.55.247:32126] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:42.864498 2026] [proxy:error] [pid 503470:tid 503604] [client 34.125.55.247:32126] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/config.yaml
[Sun Aug 30 03:07:42.865034 2026] [security2:error] [pid 499145:tid 499337] [client 34.125.55.247:31984] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/app/config.json"] [unique_id "apPkzlJNq1G5uRhTNnuK8AAAAD4"]
[Sun Aug 30 03:07:42.865171 2026] [proxy_http:error] [pid 499145:tid 499328] (20014)Internal error (specific information not available): [client 34.125.55.247:32078] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:42.865189 2026] [proxy:error] [pid 499145:tid 499328] [client 34.125.55.247:32078] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml
[Sun Aug 30 03:07:42.865318 2026] [security2:error] [pid 499145:tid 499328] [client 34.125.55.247:32078] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "502"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/502.shtml"] [unique_id "apPkzlJNq1G5uRhTNnuK7wAAADU"]
[Sun Aug 30 03:07:42.869249 2026] [security2:error] [pid 499145:tid 499395] [client 158.23.147.79:62313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPkzlJNq1G5uRhTNnuK9gAAAHg"]
[Sun Aug 30 03:07:42.871002 2026] [proxy_http:error] [pid 503470:tid 503611] (20014)Internal error (specific information not available): [client 34.125.55.247:32140] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:42.871031 2026] [proxy:error] [pid 503470:tid 503611] [client 34.125.55.247:32140] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/config.toml
[Sun Aug 30 03:07:42.872505 2026] [security2:error] [pid 503470:tid 503640] [client 40.83.93.50:13564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/class.php"] [unique_id "apPkzj8EKFABaii6jtMADAAAAK0"]
[Sun Aug 30 03:07:42.877657 2026] [proxy_http:error] [pid 503470:tid 503638] (20014)Internal error (specific information not available): [client 34.125.55.247:32168] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:42.877676 2026] [proxy:error] [pid 503470:tid 503638] [client 34.125.55.247:32168] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/secrets.yaml
[Sun Aug 30 03:07:42.883498 2026] [proxy_http:error] [pid 503470:tid 503726] (20014)Internal error (specific information not available): [client 34.125.55.247:31968] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:42.883515 2026] [proxy:error] [pid 503470:tid 503726] [client 34.125.55.247:31968] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/api/openapi.json
[Sun Aug 30 03:07:42.883780 2026] [security2:error] [pid 503470:tid 503624] [client 4.205.62.107:62103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apPkzj8EKFABaii6jtMADgAAAJ0"]
[Sun Aug 30 03:07:42.883802 2026] [security2:error] [pid 503470:tid 503685] [client 20.104.104.62:55838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/sxxb.php"] [unique_id "apPkzj8EKFABaii6jtMADwAAANo"]
[Sun Aug 30 03:07:42.887453 2026] [security2:error] [pid 503470:tid 503622] [client 68.155.159.216:65505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apPkzj8EKFABaii6jtMAEAAAAJs"]
[Sun Aug 30 03:07:42.889002 2026] [security2:error] [pid 503470:tid 503691] [client 20.104.50.220:17325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/bob.php"] [unique_id "apPkzj8EKFABaii6jtMAEwAAAOA"]
[Sun Aug 30 03:07:42.890759 2026] [proxy_http:error] [pid 503470:tid 503662] (20014)Internal error (specific information not available): [client 34.125.55.247:32040] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:42.890773 2026] [proxy:error] [pid 503470:tid 503662] [client 34.125.55.247:32040] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/deploy/service-account.json
[Sun Aug 30 03:07:42.896399 2026] [security2:error] [pid 503470:tid 503702] [client 34.125.55.247:32082] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/config/settings.py"] [unique_id "apPkzj8EKFABaii6jtP_-gAAAOs"]
[Sun Aug 30 03:07:42.896499 2026] [proxy_http:error] [pid 503470:tid 503635] (20014)Internal error (specific information not available): [client 34.125.55.247:32192] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:42.896506 2026] [proxy:error] [pid 503470:tid 503635] [client 34.125.55.247:32192] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/app/settings.py
[Sun Aug 30 03:07:42.902600 2026] [proxy_http:error] [pid 503470:tid 503626] (20014)Internal error (specific information not available): [client 34.125.55.247:32166] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:42.902614 2026] [proxy:error] [pid 503470:tid 503626] [client 34.125.55.247:32166] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/secrets.yml
[Sun Aug 30 03:07:42.905449 2026] [security2:error] [pid 503470:tid 503698] [client 68.155.159.216:65463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apPkzj8EKFABaii6jtMAFQAAAOc"]
[Sun Aug 30 03:07:42.908023 2026] [security2:error] [pid 503470:tid 503637] [client 20.151.200.44:57799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/kcs.php"] [unique_id "apPkzj8EKFABaii6jtMAGAAAAKo"]
[Sun Aug 30 03:07:42.909086 2026] [proxy_http:error] [pid 503470:tid 503669] (20014)Internal error (specific information not available): [client 34.125.55.247:32104] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:42.909101 2026] [proxy:error] [pid 503470:tid 503669] [client 34.125.55.247:32104] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/config/prod.exs
[Sun Aug 30 03:07:42.911414 2026] [security2:error] [pid 503470:tid 503642] [client 20.220.10.235:29065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/blnux.php"] [unique_id "apPkzj8EKFABaii6jtMAGQAAAK8"]
[Sun Aug 30 03:07:42.915474 2026] [proxy_http:error] [pid 503470:tid 503636] (20014)Internal error (specific information not available): [client 34.125.55.247:32016] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:42.915492 2026] [proxy:error] [pid 503470:tid 503636] [client 34.125.55.247:32016] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/config/service-account.json
[Sun Aug 30 03:07:42.921503 2026] [security2:error] [pid 503470:tid 503600] [client 20.48.251.3:45870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/phina.php"] [unique_id "apPkzj8EKFABaii6jtMAHAAAAIU"]
[Sun Aug 30 03:07:42.921559 2026] [proxy_http:error] [pid 503470:tid 503630] (20014)Internal error (specific information not available): [client 34.125.55.247:32172] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:42.921570 2026] [proxy:error] [pid 503470:tid 503630] [client 34.125.55.247:32172] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/application.properties
[Sun Aug 30 03:07:42.926330 2026] [security2:error] [pid 499145:tid 499321] [client 20.48.251.3:13382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/xin1.php"] [unique_id "apPkzlJNq1G5uRhTNnuLCAAAAC4"]
[Sun Aug 30 03:07:42.932213 2026] [security2:error] [pid 503470:tid 503658] [client 158.23.184.117:2355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/themes7.php"] [unique_id "apPkzj8EKFABaii6jtMAHQAAAL8"]
[Sun Aug 30 03:07:42.935397 2026] [proxy_http:error] [pid 503470:tid 503683] (20014)Internal error (specific information not available): [client 34.125.55.247:32184] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:42.935411 2026] [proxy:error] [pid 503470:tid 503683] [client 34.125.55.247:32184] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/settings.py
[Sun Aug 30 03:07:42.941028 2026] [proxy_http:error] [pid 503470:tid 503665] (20014)Internal error (specific information not available): [client 34.125.55.247:32196] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:42.941045 2026] [proxy:error] [pid 503470:tid 503665] [client 34.125.55.247:32196] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/backend/settings.py
[Sun Aug 30 03:07:42.943889 2026] [security2:error] [pid 503470:tid 503631] [client 20.48.250.41:60750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/xs.php"] [unique_id "apPkzj8EKFABaii6jtMAIwAAAKQ"]
[Sun Aug 30 03:07:42.947620 2026] [proxy_http:error] [pid 503470:tid 503604] (20014)Internal error (specific information not available): [client 34.125.55.247:32126] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:42.947637 2026] [proxy:error] [pid 503470:tid 503604] [client 34.125.55.247:32126] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml
[Sun Aug 30 03:07:42.958384 2026] [security2:error] [pid 503470:tid 503638] [client 34.125.55.247:32168] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "502"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/502.shtml"] [unique_id "apPkzj8EKFABaii6jtP_9AAAAKs"]
[Sun Aug 30 03:07:42.962264 2026] [security2:error] [pid 503470:tid 503662] [client 34.125.55.247:32040] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "502"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/502.shtml"] [unique_id "apPkzj8EKFABaii6jtP_-QAAAMM"]
[Sun Aug 30 03:07:42.963799 2026] [security2:error] [pid 503470:tid 503709] [client 216.73.216.128:29153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts2/updateconf"] [unique_id "apPkzj8EKFABaii6jtMANgAAAPI"]
[Sun Aug 30 03:07:42.967927 2026] [security2:error] [pid 503470:tid 503669] [client 34.125.55.247:32104] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "502"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/502.shtml"] [unique_id "apPkzj8EKFABaii6jtMAAAAAAMo"]
[Sun Aug 30 03:07:42.995394 2026] [security2:error] [pid 503470:tid 503700] [client 20.104.18.15:28657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/db.php/new.php"] [unique_id "apPkzj8EKFABaii6jtMATQAAAOk"]
[Sun Aug 30 03:07:43.001828 2026] [security2:error] [pid 503470:tid 503675] [client 20.104.50.220:46877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/xx.php"] [unique_id "apPkzz8EKFABaii6jtMAUwAAANA"]
[Sun Aug 30 03:07:43.010460 2026] [security2:error] [pid 503470:tid 503656] [client 20.104.104.62:55855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/dx.php"] [unique_id "apPkzz8EKFABaii6jtMAWAAAAL0"]
[Sun Aug 30 03:07:43.011001 2026] [security2:error] [pid 503470:tid 503711] [client 20.104.18.15:34766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/mgrr.php"] [unique_id "apPkzz8EKFABaii6jtMAWgAAAPQ"]
[Sun Aug 30 03:07:43.034953 2026] [security2:error] [pid 499145:tid 499349] [client 40.83.93.50:11466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/upgrade-temp-backup/plugins/users.php"] [unique_id "apPkz1JNq1G5uRhTNnuLOAAAAEo"]
[Sun Aug 30 03:07:43.042589 2026] [security2:error] [pid 503470:tid 503669] [client 20.220.10.235:29088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/attack.php"] [unique_id "apPkzz8EKFABaii6jtMAbAAAAMo"]
[Sun Aug 30 03:07:43.050675 2026] [security2:error] [pid 503470:tid 503679] [client 158.23.147.79:63898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-includes/Requests/network.php"] [unique_id "apPkzz8EKFABaii6jtMAcwAAANQ"]
[Sun Aug 30 03:07:43.060530 2026] [authz_core:error] [pid 499145:tid 499375] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:43.060827 2026] [authz_core:error] [pid 499145:tid 499375] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:43.062744 2026] [security2:error] [pid 499145:tid 499352] [client 20.196.209.81:5095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/ioxi-o.php"] [unique_id "apPkz1JNq1G5uRhTNnuLRQAAAE0"]
[Sun Aug 30 03:07:43.063987 2026] [security2:error] [pid 499145:tid 499352] [client 4.205.62.107:64474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/infos.php"] [unique_id "apPkz1JNq1G5uRhTNnuLRwAAAE0"]
[Sun Aug 30 03:07:43.065836 2026] [security2:error] [pid 499145:tid 499385] [client 20.104.18.15:23361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/domvf.php"] [unique_id "apPkz1JNq1G5uRhTNnuLSgAAAG4"]
[Sun Aug 30 03:07:43.070503 2026] [security2:error] [pid 499145:tid 499328] [client 20.104.18.15:18402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/atomlib.php"] [unique_id "apPkz1JNq1G5uRhTNnuLTQAAADU"]
[Sun Aug 30 03:07:43.071422 2026] [security2:error] [pid 499145:tid 499304] [client 4.205.62.107:36020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/cp2.php"] [unique_id "apPkz1JNq1G5uRhTNnuLTgAAAB0"]
[Sun Aug 30 03:07:43.072211 2026] [security2:error] [pid 503470:tid 503662] [client 158.23.184.117:2367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/wp-admin/images.php"] [unique_id "apPkzz8EKFABaii6jtMAhQAAAMM"]
[Sun Aug 30 03:07:43.086953 2026] [security2:error] [pid 503470:tid 503696] [client 4.205.62.107:22937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/paypal.php"] [unique_id "apPkzz8EKFABaii6jtMAiwAAAOU"]
[Sun Aug 30 03:07:43.090741 2026] [security2:error] [pid 503470:tid 503616] [client 20.48.251.3:12048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/wp-tem.php"] [unique_id "apPkzz8EKFABaii6jtMAjwAAAJU"]
[Sun Aug 30 03:07:43.125825 2026] [security2:error] [pid 503470:tid 503703] [client 20.104.18.15:29150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/vpn.php"] [unique_id "apPkzz8EKFABaii6jtMAlgAAAOw"]
[Sun Aug 30 03:07:43.128536 2026] [security2:error] [pid 499145:tid 499310] [client 20.104.18.15:51702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/blacks.php"] [unique_id "apPkz1JNq1G5uRhTNnuLawAAACM"]
[Sun Aug 30 03:07:43.140359 2026] [authz_core:error] [pid 503470:tid 503727] [client 66.249.66.70:42357] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:43.140615 2026] [authz_core:error] [pid 503470:tid 503727] [client 66.249.66.70:42357] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:43.151417 2026] [security2:error] [pid 499145:tid 499398] [client 20.48.250.41:62515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/zu.php"] [unique_id "apPkz1JNq1G5uRhTNnuLeAAAAHs"]
[Sun Aug 30 03:07:43.153861 2026] [authz_core:error] [pid 499145:tid 499291] [client 216.73.216.128:47617] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:43.154117 2026] [authz_core:error] [pid 499145:tid 499291] [client 216.73.216.128:47617] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:43.163416 2026] [security2:error] [pid 503470:tid 503705] [client 20.104.104.62:55868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPkzz8EKFABaii6jtMAqwAAAO4"]
[Sun Aug 30 03:07:43.176283 2026] [authz_core:error] [pid 499145:tid 499308] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZM
[Sun Aug 30 03:07:43.176717 2026] [authz_core:error] [pid 499145:tid 499308] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZM
[Sun Aug 30 03:07:43.178996 2026] [security2:error] [pid 503470:tid 503712] [client 20.220.10.235:29087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/wk/index.php"] [unique_id "apPkzz8EKFABaii6jtMAtgAAAPU"]
[Sun Aug 30 03:07:43.194790 2026] [security2:error] [pid 503470:tid 503684] [client 20.104.50.220:32105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-iav.php"] [unique_id "apPkzz8EKFABaii6jtMAwwAAANk"]
[Sun Aug 30 03:07:43.197459 2026] [security2:error] [pid 503470:tid 503634] [client 158.23.147.79:63997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-content/radio.php"] [unique_id "apPkzz8EKFABaii6jtMAyAAAAKc"]
[Sun Aug 30 03:07:43.207290 2026] [security2:error] [pid 503470:tid 503635] [client 20.104.50.220:62838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/info.php"] [unique_id "apPkzz8EKFABaii6jtMAzgAAAKg"]
[Sun Aug 30 03:07:43.212170 2026] [security2:error] [pid 499145:tid 499296] [client 158.23.184.117:2393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/wp-content/themes/haha.php"] [unique_id "apPkz1JNq1G5uRhTNnuLlgAAABU"]
[Sun Aug 30 03:07:43.215109 2026] [authz_core:error] [pid 503470:tid 503656] [client 66.249.66.69:52443] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:43.215504 2026] [authz_core:error] [pid 503470:tid 503656] [client 66.249.66.69:52443] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:43.247508 2026] [security2:error] [pid 503470:tid 503707] [client 20.48.251.3:5119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/update.php"] [unique_id "apPkzz8EKFABaii6jtMA4wAAAPA"]
[Sun Aug 30 03:07:43.274595 2026] [security2:error] [pid 503470:tid 503715] [client 20.197.61.180:7811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/profile.php"] [unique_id "apPkzz8EKFABaii6jtMA-AAAAPg"]
[Sun Aug 30 03:07:43.283171 2026] [security2:error] [pid 503470:tid 503663] [client 20.48.250.41:60690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/lanka.php"] [unique_id "apPkzz8EKFABaii6jtMA-QAAAMQ"]
[Sun Aug 30 03:07:43.293339 2026] [security2:error] [pid 503470:tid 503722] [client 20.104.104.62:46713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/xda.php"] [unique_id "apPkzz8EKFABaii6jtMBAgAAAP8"]
[Sun Aug 30 03:07:43.308963 2026] [security2:error] [pid 503470:tid 503719] [client 20.220.10.235:28758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/dehnl.php"] [unique_id "apPkzz8EKFABaii6jtMBDgAAAPw"]
[Sun Aug 30 03:07:43.317584 2026] [security2:error] [pid 503470:tid 503706] [client 20.104.50.220:33188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/xixi.php"] [unique_id "apPkzz8EKFABaii6jtMBFwAAAO8"]
[Sun Aug 30 03:07:43.347717 2026] [security2:error] [pid 503470:tid 503639] [client 20.151.200.44:59562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/tajj.php"] [unique_id "apPkzz8EKFABaii6jtMBMwAAAKw"]
[Sun Aug 30 03:07:43.348409 2026] [security2:error] [pid 503470:tid 503711] [client 158.23.147.79:63988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-admin/dropdown.php"] [unique_id "apPkzz8EKFABaii6jtMBNgAAAPQ"]
[Sun Aug 30 03:07:43.353553 2026] [security2:error] [pid 503470:tid 503628] [client 158.23.184.117:2380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/wp-mail.php"] [unique_id "apPkzz8EKFABaii6jtMBPAAAAKE"]
[Sun Aug 30 03:07:43.404996 2026] [security2:error] [pid 503470:tid 503645] [client 40.83.93.50:13542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/auth.php"] [unique_id "apPkzz8EKFABaii6jtMBXQAAALI"]
[Sun Aug 30 03:07:43.415347 2026] [security2:error] [pid 503470:tid 503716] [client 68.155.159.216:60873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apPkzz8EKFABaii6jtMBZgAAAPk"]
[Sun Aug 30 03:07:43.419213 2026] [security2:error] [pid 503470:tid 503679] [client 4.205.62.107:18640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/params.php"] [unique_id "apPkzz8EKFABaii6jtMBbQAAANQ"]
[Sun Aug 30 03:07:43.428723 2026] [security2:error] [pid 503470:tid 503641] [client 20.104.104.62:55842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/wp-admin/js/index.php"] [unique_id "apPkzz8EKFABaii6jtMBdgAAAK4"]
[Sun Aug 30 03:07:43.431954 2026] [security2:error] [pid 503470:tid 503705] [client 20.48.250.41:62583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/gettest.php"] [unique_id "apPkzz8EKFABaii6jtMBeAAAAO4"]
[Sun Aug 30 03:07:43.445496 2026] [security2:error] [pid 503470:tid 503600] [client 20.220.10.235:28751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/png.php"] [unique_id "apPkzz8EKFABaii6jtMBewAAAIU"]
[Sun Aug 30 03:07:43.459737 2026] [security2:error] [pid 503470:tid 503640] [client 20.196.209.81:5077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.piako.store"] [uri "/lock.php"] [unique_id "apPkzz8EKFABaii6jtMBgwAAAK0"]
[Sun Aug 30 03:07:43.478295 2026] [security2:error] [pid 503470:tid 503687] [client 68.155.159.216:61645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-admin/network/index.php"] [unique_id "apPkzz8EKFABaii6jtMBmQAAANw"]
[Sun Aug 30 03:07:43.494575 2026] [security2:error] [pid 503470:tid 503642] [client 158.23.184.117:2379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/root.php"] [unique_id "apPkzz8EKFABaii6jtMBrQAAAK8"]
[Sun Aug 30 03:07:43.501961 2026] [security2:error] [pid 503470:tid 503603] [client 40.83.93.50:5953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/upgrade-temp-backup/plugins/wp-blog-header.php"] [unique_id "apPkzz8EKFABaii6jtMBswAAAIg"]
[Sun Aug 30 03:07:43.508870 2026] [security2:error] [pid 503470:tid 503636] [client 20.104.50.220:59582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-content/uploads/simple-file-list/fox.php"] [unique_id "apPkzz8EKFABaii6jtMBuQAAAKk"]
[Sun Aug 30 03:07:43.547728 2026] [security2:error] [pid 499145:tid 499350] [client 158.23.147.79:63976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/login.php"] [unique_id "apPkz1JNq1G5uRhTNnuMLQAAAEs"]
[Sun Aug 30 03:07:43.558539 2026] [security2:error] [pid 503470:tid 503697] [client 20.104.104.62:56997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/t00l.php"] [unique_id "apPkzz8EKFABaii6jtMB0QAAAOY"]
[Sun Aug 30 03:07:43.564157 2026] [security2:error] [pid 503470:tid 503618] [client 20.104.50.220:51555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/tntmar.php"] [unique_id "apPkzz8EKFABaii6jtMB1AAAAJc"]
[Sun Aug 30 03:07:43.564254 2026] [security2:error] [pid 503470:tid 503630] [client 68.155.159.216:11262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wzy.php"] [unique_id "apPkzz8EKFABaii6jtMB1QAAAKM"]
[Sun Aug 30 03:07:43.584024 2026] [security2:error] [pid 503470:tid 503711] [client 52.139.37.240:52198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apPkzz8EKFABaii6jtMB3wAAAPQ"]
[Sun Aug 30 03:07:43.598221 2026] [security2:error] [pid 503470:tid 503671] [client 20.220.10.235:28740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/txets.php"] [unique_id "apPkzz8EKFABaii6jtMB6AAAAMw"]
[Sun Aug 30 03:07:43.610136 2026] [security2:error] [pid 503470:tid 503647] [client 20.48.250.41:62477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/35.php"] [unique_id "apPkzz8EKFABaii6jtMB7gAAALQ"]
[Sun Aug 30 03:07:43.634583 2026] [security2:error] [pid 503470:tid 503619] [client 158.23.184.117:2344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/ae.php"] [unique_id "apPkzz8EKFABaii6jtMB_QAAAJg"]
[Sun Aug 30 03:07:43.644280 2026] [security2:error] [pid 499145:tid 499384] [client 158.23.147.79:62314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/hehehehe.php"] [unique_id "apPkz1JNq1G5uRhTNnuMSAAAAG0"]
[Sun Aug 30 03:07:43.668343 2026] [authz_core:error] [pid 503470:tid 503670] [client 66.249.66.64:39706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:43.668620 2026] [authz_core:error] [pid 503470:tid 503670] [client 66.249.66.64:39706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:43.687086 2026] [security2:error] [pid 499145:tid 499304] [client 20.104.104.62:56982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/ls.php"] [unique_id "apPkz1JNq1G5uRhTNnuMWQAAAB0"]
[Sun Aug 30 03:07:43.710930 2026] [authz_core:error] [pid 499145:tid 499392] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AG
[Sun Aug 30 03:07:43.711222 2026] [authz_core:error] [pid 499145:tid 499392] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AG
[Sun Aug 30 03:07:43.725251 2026] [security2:error] [pid 503470:tid 503724] [client 68.155.159.216:55127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/lv.php"] [unique_id "apPkzz8EKFABaii6jtMCHwAAAQE"]
[Sun Aug 30 03:07:43.760103 2026] [authz_core:error] [pid 503470:tid 503626] [client 66.249.66.41:44200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:43.760472 2026] [authz_core:error] [pid 503470:tid 503626] [client 66.249.66.41:44200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:43.762603 2026] [security2:error] [pid 503470:tid 503644] [client 65.108.6.34:34656] ModSecurity: Warning. Matched phrase "SEOkicks" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "flashflooring.co.uk"] [uri "/index.php"] [unique_id "apPkzz8EKFABaii6jtMAggAAALE"], referer: https://flashflooring.co.uk/
[Sun Aug 30 03:07:43.764673 2026] [security2:error] [pid 503470:tid 503681] [client 20.48.250.41:62473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/maraz.php"] [unique_id "apPkzz8EKFABaii6jtMCRgAAANY"]
[Sun Aug 30 03:07:43.767607 2026] [security2:error] [pid 503470:tid 503621] [client 20.220.10.235:29071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/wp-login.php"] [unique_id "apPkzz8EKFABaii6jtMCPQAAAJo"]
[Sun Aug 30 03:07:43.774957 2026] [security2:error] [pid 503470:tid 503700] [client 158.23.184.117:2317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/admin/controller/extension/ultra.php"] [unique_id "apPkzz8EKFABaii6jtMCRwAAAOk"]
[Sun Aug 30 03:07:43.787684 2026] [security2:error] [pid 503470:tid 503609] [client 52.139.37.240:31862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/wp-content/uploads/min.php"] [unique_id "apPkzz8EKFABaii6jtMCTQAAAI4"]
[Sun Aug 30 03:07:43.802740 2026] [security2:error] [pid 499145:tid 499377] [client 20.151.200.44:57916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/bge.php"] [unique_id "apPkz1JNq1G5uRhTNnuMigAAAGY"]
[Sun Aug 30 03:07:43.814481 2026] [security2:error] [pid 503470:tid 503633] [client 158.23.147.79:63901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-includes/fonts/about.php"] [unique_id "apPkzz8EKFABaii6jtMCXgAAAKY"]
[Sun Aug 30 03:07:43.885436 2026] [security2:error] [pid 503470:tid 503704] [client 20.104.50.220:27219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/row.php"] [unique_id "apPkzz8EKFABaii6jtMCdwAAAO0"]
[Sun Aug 30 03:07:43.894859 2026] [security2:error] [pid 503470:tid 503677] [client 40.83.93.50:7895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/adminfuns.php"] [unique_id "apPkzz8EKFABaii6jtMCfAAAANI"]
[Sun Aug 30 03:07:43.905996 2026] [security2:error] [pid 503470:tid 503682] [client 20.220.10.235:28783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/wp-access.php"] [unique_id "apPkzz8EKFABaii6jtMCgAAAANc"]
[Sun Aug 30 03:07:43.909169 2026] [security2:error] [pid 503470:tid 503713] [client 158.23.147.79:63956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-content/admin.php"] [unique_id "apPkzz8EKFABaii6jtMCggAAAPY"]
[Sun Aug 30 03:07:43.913769 2026] [security2:error] [pid 503470:tid 503727] [client 158.23.184.117:2325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/wp-content/import.php"] [unique_id "apPkzz8EKFABaii6jtMChQAAAQQ"]
[Sun Aug 30 03:07:43.957500 2026] [security2:error] [pid 503470:tid 503709] [client 20.104.50.220:6123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/51.php"] [unique_id "apPkzz8EKFABaii6jtMCmAAAAPI"]
[Sun Aug 30 03:07:43.965579 2026] [security2:error] [pid 503470:tid 503666] [client 114.119.150.65:22149] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.boblivingstone.com"] [uri "/2015/04/24/how-to-forgive-your-ex-partner-in-order-to-transform-a-high-conflict-relationship/"] [unique_id "apPkzz8EKFABaii6jtMCoAAAAMc"], referer: https://www.boblivingstone.com/2015/04/24/how-to-forgive-your-ex-partner-in-order-to-transform-a-high-conflict-relationship/
[Sun Aug 30 03:07:43.967046 2026] [security2:error] [pid 503470:tid 503612] [client 20.48.250.41:62550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/kbfr.php"] [unique_id "apPkzz8EKFABaii6jtMCogAAAJE"]
[Sun Aug 30 03:07:43.981557 2026] [security2:error] [pid 503470:tid 503725] [client 52.139.37.240:31827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/zoom1.php"] [unique_id "apPkzz8EKFABaii6jtMCqgAAAQI"]
[Sun Aug 30 03:07:43.982081 2026] [security2:error] [pid 503470:tid 503726] [client 40.83.93.50:11509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/upgrade-temp-backup/plugins/wp-mail.php"] [unique_id "apPkzz8EKFABaii6jtMCqwAAAQM"]
[Sun Aug 30 03:07:43.997546 2026] [security2:error] [pid 503470:tid 503611] [client 20.197.61.180:19044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/sql.php"] [unique_id "apPkzz8EKFABaii6jtMCtQAAAJA"]
[Sun Aug 30 03:07:44.004100 2026] [security2:error] [pid 503470:tid 503675] [client 158.23.147.79:63946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/xmlrpc.php"] [unique_id "apPk0D8EKFABaii6jtMCuQAAANA"]
[Sun Aug 30 03:07:44.016447 2026] [security2:error] [pid 503470:tid 503707] [client 68.155.159.216:12296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPk0D8EKFABaii6jtMCwwAAAPA"]
[Sun Aug 30 03:07:44.021773 2026] [security2:error] [pid 503470:tid 503708] [client 4.205.62.107:64015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/hochladen.form.php"] [unique_id "apPk0D8EKFABaii6jtMCyAAAAPE"]
[Sun Aug 30 03:07:44.022517 2026] [security2:error] [pid 503470:tid 503681] [client 20.104.49.130:59559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/wp-css.php"] [unique_id "apPk0D8EKFABaii6jtMCyQAAANY"]
[Sun Aug 30 03:07:44.025918 2026] [security2:error] [pid 503470:tid 503652] [client 20.104.50.220:17322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/t3s.php"] [unique_id "apPk0D8EKFABaii6jtMCygAAALk"]
[Sun Aug 30 03:07:44.043316 2026] [security2:error] [pid 503470:tid 503611] [client 20.220.10.235:29118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/wp-content/admin.php"] [unique_id "apPk0D8EKFABaii6jtMC3AAAAJA"]
[Sun Aug 30 03:07:44.049120 2026] [security2:error] [pid 503470:tid 503607] [client 68.155.159.216:63998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/goat1.php"] [unique_id "apPk0D8EKFABaii6jtMC3wAAAIw"]
[Sun Aug 30 03:07:44.052400 2026] [security2:error] [pid 503470:tid 503721] [client 158.23.184.117:2246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/wp-includes/fonts/admin.php"] [unique_id "apPk0D8EKFABaii6jtMC4wAAAP4"]
[Sun Aug 30 03:07:44.061145 2026] [security2:error] [pid 503470:tid 503623] [client 20.48.251.3:56380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/sadd.php"] [unique_id "apPk0D8EKFABaii6jtMC7gAAAJw"]
[Sun Aug 30 03:07:44.062069 2026] [authz_core:error] [pid 499145:tid 499290] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:44.062338 2026] [authz_core:error] [pid 499145:tid 499290] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:44.069808 2026] [security2:error] [pid 503470:tid 503722] [client 20.151.200.44:59495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/ssh3ll.php"] [unique_id "apPk0D8EKFABaii6jtMC9gAAAP8"]
[Sun Aug 30 03:07:44.092418 2026] [security2:error] [pid 503470:tid 503619] [client 20.104.50.220:29132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-admin/f0x.php"] [unique_id "apPk0D8EKFABaii6jtMDFQAAAJg"]
[Sun Aug 30 03:07:44.106516 2026] [authz_core:error] [pid 499145:tid 499294] [client 66.249.66.68:45378] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:44.106775 2026] [authz_core:error] [pid 499145:tid 499294] [client 66.249.66.68:45378] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:44.125342 2026] [security2:error] [pid 503470:tid 503722] [client 20.104.18.15:28609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/kuda.php"] [unique_id "apPk0D8EKFABaii6jtMDHQAAAP8"]
[Sun Aug 30 03:07:44.154368 2026] [security2:error] [pid 503470:tid 503674] [client 20.104.50.220:46631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/222.php"] [unique_id "apPk0D8EKFABaii6jtMDLQAAAM8"]
[Sun Aug 30 03:07:44.155305 2026] [security2:error] [pid 503470:tid 503669] [client 20.48.250.41:59336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/wp-act.php"] [unique_id "apPk0D8EKFABaii6jtMDMAAAAMo"]
[Sun Aug 30 03:07:44.174100 2026] [security2:error] [pid 499145:tid 499381] [client 52.139.37.240:31849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/lock360.php"] [unique_id "apPk0FJNq1G5uRhTNnuNBQAAAGo"]
[Sun Aug 30 03:07:44.179230 2026] [security2:error] [pid 503470:tid 503705] [client 20.104.18.15:34652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/mac.php"] [unique_id "apPk0D8EKFABaii6jtMDQwAAAO4"]
[Sun Aug 30 03:07:44.183718 2026] [security2:error] [pid 503470:tid 503614] [client 20.48.251.3:64470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/koiy.php"] [unique_id "apPk0D8EKFABaii6jtMDSAAAAJM"]
[Sun Aug 30 03:07:44.188234 2026] [security2:error] [pid 503470:tid 503721] [client 20.220.10.235:28755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/log.php"] [unique_id "apPk0D8EKFABaii6jtMDTwAAAP4"]
[Sun Aug 30 03:07:44.192373 2026] [security2:error] [pid 503470:tid 503720] [client 158.23.184.117:2341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/222.php"] [unique_id "apPk0D8EKFABaii6jtMDUQAAAP0"]
[Sun Aug 30 03:07:44.204908 2026] [security2:error] [pid 503470:tid 503665] [client 158.23.147.79:63982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/atomlib.php"] [unique_id "apPk0D8EKFABaii6jtMDWQAAAMY"]
[Sun Aug 30 03:07:44.205488 2026] [security2:error] [pid 503470:tid 503699] [client 20.104.18.15:23544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/biufile.php"] [unique_id "apPk0D8EKFABaii6jtMDWgAAAOg"]
[Sun Aug 30 03:07:44.215896 2026] [security2:error] [pid 503470:tid 503604] [client 20.104.18.15:18318] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/1.php"] [unique_id "apPk0D8EKFABaii6jtMDYQAAAIk"]
[Sun Aug 30 03:07:44.215990 2026] [security2:error] [pid 503470:tid 503604] [client 20.104.18.15:18318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/1.php"] [unique_id "apPk0D8EKFABaii6jtMDYQAAAIk"]
[Sun Aug 30 03:07:44.229279 2026] [authz_core:error] [pid 499145:tid 499340] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IN
[Sun Aug 30 03:07:44.229623 2026] [authz_core:error] [pid 499145:tid 499340] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IN
[Sun Aug 30 03:07:44.230052 2026] [security2:error] [pid 499145:tid 499364] [client 4.205.62.107:64656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/env.php"] [unique_id "apPk0FJNq1G5uRhTNnuNGwAAAFk"]
[Sun Aug 30 03:07:44.230597 2026] [security2:error] [pid 503470:tid 503628] [client 20.48.251.3:50031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/txets.php"] [unique_id "apPk0D8EKFABaii6jtMDawAAAKE"]
[Sun Aug 30 03:07:44.234324 2026] [security2:error] [pid 503470:tid 503602] [client 20.104.49.130:58075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/pfm.php"] [unique_id "apPk0D8EKFABaii6jtMDbwAAAIc"]
[Sun Aug 30 03:07:44.239384 2026] [security2:error] [pid 503470:tid 503698] [client 4.205.62.107:62307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/userfuns.php"] [unique_id "apPk0D8EKFABaii6jtMDdgAAAOc"]
[Sun Aug 30 03:07:44.244065 2026] [security2:error] [pid 503470:tid 503655] [client 114.119.128.14:36965] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bearfootcreative.net"] [uri "/wp-content/uploads/2020/09/Capital-DSC_0155-scaled.jpg"] [unique_id "apPk0D8EKFABaii6jtMDegAAALw"], referer: https://bearfootcreative.net/wp-content/uploads/2020/09/Capital-DSC_0155-scaled.jpg
[Sun Aug 30 03:07:44.244677 2026] [authz_core:error] [pid 503470:tid 503724] [client 74.7.227.8:38186] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:44.244999 2026] [authz_core:error] [pid 503470:tid 503724] [client 74.7.227.8:38186] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:44.271049 2026] [security2:error] [pid 503470:tid 503675] [client 20.104.18.15:52189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/wp.php"] [unique_id "apPk0D8EKFABaii6jtMDjgAAANA"]
[Sun Aug 30 03:07:44.279583 2026] [security2:error] [pid 499145:tid 499350] [client 114.119.129.4:40741] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "africadayfestival.com"] [uri "/wp-content/uploads/2020/02/africadayfestivalslider1.jpg"] [unique_id "apPk0FJNq1G5uRhTNnuNMwAAAEs"], referer: https://africadayfestival.com/wp-content/uploads/2020/02/africadayfestivalslider1.jpg?gid=1
[Sun Aug 30 03:07:44.294504 2026] [security2:error] [pid 503470:tid 503661] [client 4.205.62.107:35988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/xda.php"] [unique_id "apPk0D8EKFABaii6jtMDmwAAAMI"]
[Sun Aug 30 03:07:44.311657 2026] [security2:error] [pid 503470:tid 503706] [client 20.104.18.15:29667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/goods.php"] [unique_id "apPk0D8EKFABaii6jtMDpgAAAO8"]
[Sun Aug 30 03:07:44.323110 2026] [security2:error] [pid 503470:tid 503613] [client 20.220.10.235:28752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/xwpg.php"] [unique_id "apPk0D8EKFABaii6jtMDrAAAAJI"]
[Sun Aug 30 03:07:44.327343 2026] [security2:error] [pid 503470:tid 503627] [client 20.151.200.44:57853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/motu.php"] [unique_id "apPk0D8EKFABaii6jtMDsAAAAKA"]
[Sun Aug 30 03:07:44.334683 2026] [security2:error] [pid 499145:tid 499335] [client 158.23.184.117:2396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/wp-content/languages.php"] [unique_id "apPk0FJNq1G5uRhTNnuNUQAAADw"]
[Sun Aug 30 03:07:44.337875 2026] [authz_core:error] [pid 499145:tid 499330] [client 216.73.216.128:47617] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:44.337942 2026] [security2:error] [pid 503470:tid 503607] [client 20.48.250.41:62562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/24.php"] [unique_id "apPk0D8EKFABaii6jtMDvQAAAIw"]
[Sun Aug 30 03:07:44.338171 2026] [authz_core:error] [pid 499145:tid 499330] [client 216.73.216.128:47617] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:44.357257 2026] [security2:error] [pid 503470:tid 503620] [client 20.104.50.220:32081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-info.php"] [unique_id "apPk0D8EKFABaii6jtMD0gAAAJk"]
[Sun Aug 30 03:07:44.365504 2026] [security2:error] [pid 499145:tid 499345] [client 158.23.147.79:63981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/lv.php"] [unique_id "apPk0FJNq1G5uRhTNnuNXAAAAEY"]
[Sun Aug 30 03:07:44.368399 2026] [security2:error] [pid 503470:tid 503653] [client 52.139.37.240:52193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/r.php"] [unique_id "apPk0D8EKFABaii6jtMD2AAAALo"]
[Sun Aug 30 03:07:44.375649 2026] [security2:error] [pid 503470:tid 503631] [client 40.83.93.50:7904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/rip.php"] [unique_id "apPk0D8EKFABaii6jtMD2QAAAKQ"]
[Sun Aug 30 03:07:44.412526 2026] [security2:error] [pid 503470:tid 503707] [client 20.48.251.3:5067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/channels.php"] [unique_id "apPk0D8EKFABaii6jtMD8gAAAPA"]
[Sun Aug 30 03:07:44.433546 2026] [security2:error] [pid 503470:tid 503719] [client 36.255.97.72:53989] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "198.57.247.130"] [uri "/.env"] [unique_id "apPk0D8EKFABaii6jtMEAwAAAPw"]
[Sun Aug 30 03:07:44.444832 2026] [authz_core:error] [pid 503470:tid 503711] [client 66.249.66.206:51626] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:44.445109 2026] [authz_core:error] [pid 503470:tid 503711] [client 66.249.66.206:51626] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:44.447970 2026] [security2:error] [pid 503470:tid 503717] [client 40.83.93.50:9685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/upgrade-temp-backup/themes/admin.php"] [unique_id "apPk0D8EKFABaii6jtMECgAAAPo"]
[Sun Aug 30 03:07:44.454987 2026] [security2:error] [pid 503470:tid 503666] [client 20.104.50.220:32886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-cli.php"] [unique_id "apPk0D8EKFABaii6jtMECwAAAMc"]
[Sun Aug 30 03:07:44.473307 2026] [security2:error] [pid 503470:tid 503694] [client 4.205.62.107:58337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/test1.php"] [unique_id "apPk0D8EKFABaii6jtMEFgAAAOM"]
[Sun Aug 30 03:07:44.474575 2026] [security2:error] [pid 503470:tid 503720] [client 158.23.184.117:2406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/wp-config-sample.php"] [unique_id "apPk0D8EKFABaii6jtMEGAAAAP0"]
[Sun Aug 30 03:07:44.482984 2026] [authz_core:error] [pid 499145:tid 499309] [client 66.249.66.33:63306] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:44.483261 2026] [authz_core:error] [pid 499145:tid 499309] [client 66.249.66.33:63306] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:44.486350 2026] [security2:error] [pid 503470:tid 503674] [client 20.220.10.235:29116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/sxxb.php"] [unique_id "apPk0D8EKFABaii6jtMEJQAAAM8"]
[Sun Aug 30 03:07:44.490943 2026] [security2:error] [pid 503470:tid 503681] [client 158.23.147.79:63955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-includes/Text/index.php"] [unique_id "apPk0D8EKFABaii6jtMEMAAAANY"]
[Sun Aug 30 03:07:44.493676 2026] [security2:error] [pid 499145:tid 499353] [client 20.48.250.41:60748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/155.php"] [unique_id "apPk0FJNq1G5uRhTNnuNmgAAAE4"]
[Sun Aug 30 03:07:44.553619 2026] [security2:error] [pid 499145:tid 499351] [client 68.155.159.216:62037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-admin/images/about.php"] [unique_id "apPk0FJNq1G5uRhTNnuNvAAAAEw"]
[Sun Aug 30 03:07:44.560078 2026] [security2:error] [pid 499145:tid 499376] [client 52.139.37.240:52183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/sf.php"] [unique_id "apPk0FJNq1G5uRhTNnuNwwAAAGU"]
[Sun Aug 30 03:07:44.620343 2026] [security2:error] [pid 503470:tid 503655] [client 158.23.184.117:2398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/wp-admin/install-helper.php"] [unique_id "apPk0D8EKFABaii6jtMEYAAAALw"]
[Sun Aug 30 03:07:44.627760 2026] [security2:error] [pid 499145:tid 499363] [client 20.48.250.41:62521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/file.php"] [unique_id "apPk0FJNq1G5uRhTNnuN3wAAAFg"]
[Sun Aug 30 03:07:44.642949 2026] [security2:error] [pid 499145:tid 499399] [client 158.23.147.79:62302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/content.php"] [unique_id "apPk0FJNq1G5uRhTNnuN4gAAAHw"]
[Sun Aug 30 03:07:44.660664 2026] [authz_core:error] [pid 499145:tid 499329] [client 66.249.66.77:54346] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:44.660950 2026] [authz_core:error] [pid 499145:tid 499329] [client 66.249.66.77:54346] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:44.661576 2026] [security2:error] [pid 499145:tid 499356] [client 20.104.50.220:61684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-content/uploads/simple-file-list/fw.php"] [unique_id "apPk0FJNq1G5uRhTNnuN6AAAAFE"]
[Sun Aug 30 03:07:44.668007 2026] [security2:error] [pid 499145:tid 499303] [client 20.220.10.235:29076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/dx.php"] [unique_id "apPk0FJNq1G5uRhTNnuN6gAAABw"]
[Sun Aug 30 03:07:44.683292 2026] [security2:error] [pid 503470:tid 503682] [client 68.155.159.216:63532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apPk0D8EKFABaii6jtMEawAAANc"]
[Sun Aug 30 03:07:44.685615 2026] [security2:error] [pid 503470:tid 503677] [client 4.205.62.107:18996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/gjm.php"] [unique_id "apPk0D8EKFABaii6jtMEbQAAANI"]
[Sun Aug 30 03:07:44.701996 2026] [security2:error] [pid 503470:tid 503612] [client 68.155.159.216:56358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apPk0D8EKFABaii6jtMEeAAAAJE"]
[Sun Aug 30 03:07:44.709991 2026] [security2:error] [pid 503470:tid 503661] [client 20.104.50.220:42759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/dd.php"] [unique_id "apPk0D8EKFABaii6jtMEfgAAAMI"]
[Sun Aug 30 03:07:44.718355 2026] [authz_core:error] [pid 499145:tid 499361] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_US%2FLC_MESSAGES
[Sun Aug 30 03:07:44.718808 2026] [authz_core:error] [pid 499145:tid 499361] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_US%2FLC_MESSAGES
[Sun Aug 30 03:07:44.723221 2026] [security2:error] [pid 503470:tid 503638] [client 20.197.61.180:9381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/index.bak.php"] [unique_id "apPk0D8EKFABaii6jtMEjAAAAKs"]
[Sun Aug 30 03:07:44.761962 2026] [security2:error] [pid 503470:tid 503701] [client 158.23.184.117:2353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/wp-includes/fonts/classmap.php"] [unique_id "apPk0D8EKFABaii6jtMEpQAAAOo"]
[Sun Aug 30 03:07:44.769927 2026] [security2:error] [pid 503470:tid 503620] [client 52.139.37.240:52196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/7.php"] [unique_id "apPk0D8EKFABaii6jtMEpwAAAJk"]
[Sun Aug 30 03:07:44.791955 2026] [authz_core:error] [pid 499145:tid 499323] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:44.792320 2026] [authz_core:error] [pid 499145:tid 499323] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:44.796460 2026] [security2:error] [pid 503470:tid 503707] [client 20.220.10.235:28756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPk0D8EKFABaii6jtMEtQAAAPA"]
[Sun Aug 30 03:07:44.801249 2026] [security2:error] [pid 503470:tid 503626] [client 20.48.250.41:60752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPk0D8EKFABaii6jtMEtgAAAJ8"]
[Sun Aug 30 03:07:44.816828 2026] [security2:error] [pid 503470:tid 503665] [client 20.104.50.220:29122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/ini.php"] [unique_id "apPk0D8EKFABaii6jtMEvwAAAMY"]
[Sun Aug 30 03:07:44.849329 2026] [security2:error] [pid 503470:tid 503663] [client 68.155.159.216:55149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apPk0D8EKFABaii6jtME1gAAAMQ"]
[Sun Aug 30 03:07:44.897787 2026] [security2:error] [pid 503470:tid 503646] [client 158.23.147.79:63968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPk0D8EKFABaii6jtME5wAAALM"]
[Sun Aug 30 03:07:44.901171 2026] [security2:error] [pid 499145:tid 499363] [client 158.23.184.117:2390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/adminfuns.php/.well-known/acme-challenge/file.php"] [unique_id "apPk0FJNq1G5uRhTNnuOPgAAAFg"]
[Sun Aug 30 03:07:44.919278 2026] [security2:error] [pid 503470:tid 503699] [client 40.83.93.50:6003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/upgrade-temp-backup/themes/login.php"] [unique_id "apPk0D8EKFABaii6jtME8wAAAOg"]
[Sun Aug 30 03:07:44.925700 2026] [security2:error] [pid 499145:tid 499337] [client 20.220.10.235:28793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/xda.php"] [unique_id "apPk0FJNq1G5uRhTNnuORgAAAD4"]
[Sun Aug 30 03:07:44.941022 2026] [core:alert] [pid 499145:tid 499362] [client 190.105.35.174:56008] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:07:44.943356 2026] [security2:error] [pid 503470:tid 503604] [client 20.48.250.41:62507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/06.php"] [unique_id "apPk0D8EKFABaii6jtME9wAAAIk"]
[Sun Aug 30 03:07:44.981890 2026] [security2:error] [pid 503470:tid 503694] [client 52.139.37.240:52204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/b.php"] [unique_id "apPk0D8EKFABaii6jtMFFQAAAOM"]
[Sun Aug 30 03:07:44.994061 2026] [security2:error] [pid 503470:tid 503646] [client 158.23.147.79:63923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/goat.php"] [unique_id "apPk0D8EKFABaii6jtMFHgAAALM"]
[Sun Aug 30 03:07:45.021496 2026] [security2:error] [pid 499145:tid 499341] [client 20.104.50.220:27205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/export.php"] [unique_id "apPk0VJNq1G5uRhTNnuOcAAAAEI"]
[Sun Aug 30 03:07:45.042033 2026] [security2:error] [pid 503470:tid 503707] [client 158.23.184.117:2411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/wp-content/themes/aa.php"] [unique_id "apPk0T8EKFABaii6jtMFOQAAAPA"]
[Sun Aug 30 03:07:45.058152 2026] [security2:error] [pid 503470:tid 503658] [client 20.151.200.44:55743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/cy.php"] [unique_id "apPk0T8EKFABaii6jtMFRwAAAL8"]
[Sun Aug 30 03:07:45.067771 2026] [security2:error] [pid 503470:tid 503643] [client 20.220.10.235:29104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPk0T8EKFABaii6jtMFSgAAALA"]
[Sun Aug 30 03:07:45.089640 2026] [security2:error] [pid 503470:tid 503631] [client 20.48.250.41:60797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/class.php"] [unique_id "apPk0T8EKFABaii6jtMFUwAAAKQ"]
[Sun Aug 30 03:07:45.111540 2026] [security2:error] [pid 503470:tid 503653] [client 158.23.147.79:62333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apPk0T8EKFABaii6jtMFWAAAALo"]
[Sun Aug 30 03:07:45.117883 2026] [security2:error] [pid 503470:tid 503703] [client 20.104.50.220:5592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/54.php"] [unique_id "apPk0T8EKFABaii6jtMFXAAAAOw"]
[Sun Aug 30 03:07:45.130116 2026] [security2:error] [pid 503470:tid 503602] [client 40.83.93.50:13538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/ws.php"] [unique_id "apPk0T8EKFABaii6jtMFYQAAAIc"]
[Sun Aug 30 03:07:45.142416 2026] [security2:error] [pid 503470:tid 503605] [client 156.59.198.135:20744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.arcexploration.com.au"] [uri "/2001Announcements/Sep01app5b.pdf"] [unique_id "apPk0T8EKFABaii6jtMFawAAAIo"]
[Sun Aug 30 03:07:45.145942 2026] [security2:error] [pid 499145:tid 499164] [remote 216.73.217.178:16448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "ltr7.com"] [uri "/_runtime"] [unique_id "apPk0VJNq1G5uRhTNnuOpwAAEBI"]
[Sun Aug 30 03:07:45.161438 2026] [security2:error] [pid 503470:tid 503611] [client 4.205.62.107:64052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/debuggen.php"] [unique_id "apPk0T8EKFABaii6jtMFeAAAAJA"]
[Sun Aug 30 03:07:45.163098 2026] [authz_core:error] [pid 503470:tid 503696] [client 66.249.66.41:44200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:45.163439 2026] [authz_core:error] [pid 503470:tid 503696] [client 66.249.66.41:44200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:45.165654 2026] [security2:error] [pid 503470:tid 503699] [client 68.155.159.216:61350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apPk0T8EKFABaii6jtMFegAAAOg"]
[Sun Aug 30 03:07:45.173641 2026] [security2:error] [pid 499145:tid 499344] [client 52.139.37.240:31852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/buy.php"] [unique_id "apPk0VJNq1G5uRhTNnuOuAAAAEU"]
[Sun Aug 30 03:07:45.181375 2026] [security2:error] [pid 503470:tid 503711] [client 158.23.184.117:2342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/chosen.php"] [unique_id "apPk0T8EKFABaii6jtMFiQAAAPQ"]
[Sun Aug 30 03:07:45.198554 2026] [authz_core:error] [pid 499145:tid 499352] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZM%2FLC_MESSAGES
[Sun Aug 30 03:07:45.198925 2026] [authz_core:error] [pid 499145:tid 499352] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZM%2FLC_MESSAGES
[Sun Aug 30 03:07:45.201409 2026] [security2:error] [pid 503470:tid 503703] [client 20.220.10.235:28741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/t00l.php"] [unique_id "apPk0T8EKFABaii6jtMFlwAAAOw"]
[Sun Aug 30 03:07:45.202616 2026] [security2:error] [pid 503470:tid 503630] [client 20.48.251.3:56338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/application.config.php"] [unique_id "apPk0T8EKFABaii6jtMFmAAAAKM"]
[Sun Aug 30 03:07:45.229799 2026] [security2:error] [pid 503470:tid 503689] [client 20.48.250.41:60784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/8.php"] [unique_id "apPk0T8EKFABaii6jtMFowAAAN4"]
[Sun Aug 30 03:07:45.241319 2026] [security2:error] [pid 503470:tid 503617] [client 20.104.49.130:57719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/albin.php"] [unique_id "apPk0T8EKFABaii6jtMFqwAAAJY"]
[Sun Aug 30 03:07:45.244495 2026] [security2:error] [pid 503470:tid 503660] [client 20.104.50.220:28720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-content/uploads/meiwei.php"] [unique_id "apPk0T8EKFABaii6jtMFsQAAAME"]
[Sun Aug 30 03:07:45.261174 2026] [security2:error] [pid 503470:tid 503640] [client 20.104.18.15:28661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/sure.php"] [unique_id "apPk0T8EKFABaii6jtMFvwAAAK0"]
[Sun Aug 30 03:07:45.270205 2026] [security2:error] [pid 503470:tid 503627] [client 158.23.147.79:63957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-content/uploads/about.php"] [unique_id "apPk0T8EKFABaii6jtMFygAAAKA"]
[Sun Aug 30 03:07:45.293113 2026] [security2:error] [pid 503470:tid 503612] [client 20.104.50.220:46195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/444.php"] [unique_id "apPk0T8EKFABaii6jtMF2QAAAJE"]
[Sun Aug 30 03:07:45.320855 2026] [security2:error] [pid 503470:tid 503616] [client 158.23.184.117:2308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/admin/function.php"] [unique_id "apPk0T8EKFABaii6jtMF6QAAAJU"]
[Sun Aug 30 03:07:45.322295 2026] [security2:error] [pid 503470:tid 503613] [client 20.104.50.220:17341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/uwu.php"] [unique_id "apPk0T8EKFABaii6jtMF6gAAAJI"]
[Sun Aug 30 03:07:45.325027 2026] [authz_core:error] [pid 503470:tid 503614] [client 66.249.66.66:46302] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:45.325315 2026] [authz_core:error] [pid 503470:tid 503614] [client 66.249.66.66:46302] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:45.330345 2026] [security2:error] [pid 503470:tid 503658] [client 20.104.18.15:34809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/simple.php"] [unique_id "apPk0T8EKFABaii6jtMF8QAAAL8"]
[Sun Aug 30 03:07:45.337671 2026] [security2:error] [pid 503470:tid 503701] [client 68.155.159.216:12378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/images/index.php"] [unique_id "apPk0T8EKFABaii6jtMF_AAAAOo"]
[Sun Aug 30 03:07:45.342590 2026] [security2:error] [pid 503470:tid 503627] [client 20.104.18.15:23540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/blacks.php"] [unique_id "apPk0T8EKFABaii6jtMGBQAAAKA"]
[Sun Aug 30 03:07:45.351123 2026] [security2:error] [pid 503470:tid 503719] [client 20.220.10.235:28738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/ls.php"] [unique_id "apPk0T8EKFABaii6jtMGDAAAAPw"]
[Sun Aug 30 03:07:45.361774 2026] [security2:error] [pid 499145:tid 499329] [client 178.16.55.109:57824] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "neilgclark.com"] [uri "/index.php"] [unique_id "apPk0VJNq1G5uRhTNnuPDgAAADY"]
[Sun Aug 30 03:07:45.364908 2026] [security2:error] [pid 503470:tid 503661] [client 52.139.37.240:52203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/config.php"] [unique_id "apPk0T8EKFABaii6jtMGFwAAAMI"]
[Sun Aug 30 03:07:45.368435 2026] [security2:error] [pid 499145:tid 499365] [client 20.104.18.15:18404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/samll.php"] [unique_id "apPk0VJNq1G5uRhTNnuPEQAAAFo"]
[Sun Aug 30 03:07:45.369753 2026] [security2:error] [pid 499145:tid 499374] [client 4.205.62.107:64654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/xve22.php"] [unique_id "apPk0VJNq1G5uRhTNnuPEgAAAGM"]
[Sun Aug 30 03:07:45.370525 2026] [security2:error] [pid 499145:tid 499325] [client 20.48.250.41:60672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/0x0x.php"] [unique_id "apPk0VJNq1G5uRhTNnuPEwAAADI"]
[Sun Aug 30 03:07:45.384851 2026] [security2:error] [pid 499145:tid 499343] [client 40.83.93.50:11459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/upgrade-temp-backup/themes/test.php"] [unique_id "apPk0VJNq1G5uRhTNnuPIQAAAEQ"]
[Sun Aug 30 03:07:45.385529 2026] [security2:error] [pid 503470:tid 503639] [client 20.48.251.3:34434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/time.php"] [unique_id "apPk0T8EKFABaii6jtMGGgAAAKw"]
[Sun Aug 30 03:07:45.404977 2026] [security2:error] [pid 499145:tid 499350] [client 4.205.62.107:22568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/mamzi.php"] [unique_id "apPk0VJNq1G5uRhTNnuPKwAAAEs"]
[Sun Aug 30 03:07:45.422992 2026] [security2:error] [pid 503470:tid 503602] [client 20.104.18.15:51695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/wander.php"] [unique_id "apPk0T8EKFABaii6jtMGPgAAAIc"]
[Sun Aug 30 03:07:45.427295 2026] [security2:error] [pid 503470:tid 503624] [client 4.205.62.107:36641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/pinfo.php"] [unique_id "apPk0T8EKFABaii6jtMGRQAAAJ0"]
[Sun Aug 30 03:07:45.430477 2026] [authz_core:error] [pid 499145:tid 499296] [client 216.73.216.128:47617] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:45.430748 2026] [authz_core:error] [pid 499145:tid 499296] [client 216.73.216.128:47617] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:45.443973 2026] [security2:error] [pid 503470:tid 503661] [client 20.48.251.3:7380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/queue.php"] [unique_id "apPk0T8EKFABaii6jtMGSgAAAMI"]
[Sun Aug 30 03:07:45.455417 2026] [security2:error] [pid 503470:tid 503610] [client 20.151.200.44:59460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/wefile.php"] [unique_id "apPk0T8EKFABaii6jtMGTQAAAI8"]
[Sun Aug 30 03:07:45.462613 2026] [security2:error] [pid 499145:tid 499372] [client 158.23.184.117:2312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/wxo.php"] [unique_id "apPk0VJNq1G5uRhTNnuPSQAAAGE"]
[Sun Aug 30 03:07:45.470426 2026] [security2:error] [pid 503470:tid 503608] [client 20.104.18.15:29151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/alfa.php"] [unique_id "apPk0T8EKFABaii6jtMGWwAAAI0"]
[Sun Aug 30 03:07:45.503451 2026] [security2:error] [pid 503470:tid 503695] [client 36.255.97.72:54053] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "198.57.247.130"] [uri "/.env"] [unique_id "apPk0T8EKFABaii6jtMGegAAAOQ"]
[Sun Aug 30 03:07:45.503603 2026] [security2:error] [pid 503470:tid 503605] [client 20.220.10.235:29110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/css/000.php"] [unique_id "apPk0T8EKFABaii6jtMGfQAAAIo"]
[Sun Aug 30 03:07:45.518746 2026] [security2:error] [pid 503470:tid 503702] [client 158.23.147.79:62276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-admin/maint/index.php"] [unique_id "apPk0T8EKFABaii6jtMGhAAAAOs"]
[Sun Aug 30 03:07:45.518918 2026] [security2:error] [pid 499145:tid 499383] [client 20.104.50.220:32078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-inlcudes.php"] [unique_id "apPk0VJNq1G5uRhTNnuPYgAAAGw"]
[Sun Aug 30 03:07:45.546201 2026] [security2:error] [pid 503470:tid 503668] [client 20.197.61.180:7843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/log.php"] [unique_id "apPk0T8EKFABaii6jtMGmAAAAMk"]
[Sun Aug 30 03:07:45.558546 2026] [security2:error] [pid 499145:tid 499378] [client 52.139.37.240:31864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/num.php"] [unique_id "apPk0VJNq1G5uRhTNnuPdQAAAGc"]
[Sun Aug 30 03:07:45.573945 2026] [security2:error] [pid 503470:tid 503694] [client 20.48.250.41:62530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/166.php"] [unique_id "apPk0T8EKFABaii6jtMGowAAAOM"]
[Sun Aug 30 03:07:45.592389 2026] [security2:error] [pid 499145:tid 499276] [client 20.104.50.220:33283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/IP.php"] [unique_id "apPk0VJNq1G5uRhTNnuPiQAAAAE"]
[Sun Aug 30 03:07:45.603809 2026] [security2:error] [pid 499145:tid 499395] [client 158.23.184.117:2386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/wp-admin/theme-editor.php"] [unique_id "apPk0VJNq1G5uRhTNnuPjQAAAHg"]
[Sun Aug 30 03:07:45.605675 2026] [security2:error] [pid 499145:tid 499275] [client 20.48.251.3:5060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/zz.php"] [unique_id "apPk0VJNq1G5uRhTNnuPjwAAAAA"]
[Sun Aug 30 03:07:45.631209 2026] [security2:error] [pid 499145:tid 499358] [client 158.23.147.79:63975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/dropdown.php"] [unique_id "apPk0VJNq1G5uRhTNnuPkwAAAFM"]
[Sun Aug 30 03:07:45.637557 2026] [security2:error] [pid 503470:tid 503651] [client 40.83.93.50:19408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/t.php"] [unique_id "apPk0T8EKFABaii6jtMGsgAAALg"]
[Sun Aug 30 03:07:45.662168 2026] [security2:error] [pid 499145:tid 499391] [client 68.155.159.216:61395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPk0VJNq1G5uRhTNnuPoAAAAHQ"]
[Sun Aug 30 03:07:45.670837 2026] [authz_core:error] [pid 503470:tid 503643] [client 74.7.227.8:38186] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:45.671155 2026] [authz_core:error] [pid 503470:tid 503643] [client 74.7.227.8:38186] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:45.674055 2026] [security2:error] [pid 499145:tid 499277] [client 20.220.10.235:28743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/cy.php"] [unique_id "apPk0VJNq1G5uRhTNnuPowAAAAI"]
[Sun Aug 30 03:07:45.703016 2026] [security2:error] [pid 499145:tid 499360] [client 20.48.250.41:59337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/h2a2ck.php"] [unique_id "apPk0VJNq1G5uRhTNnuPrQAAAFU"]
[Sun Aug 30 03:07:45.705977 2026] [authz_core:error] [pid 503470:tid 503670] [client 216.73.216.128:41450] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:45.706433 2026] [authz_core:error] [pid 503470:tid 503670] [client 216.73.216.128:41450] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:45.721350 2026] [authz_core:error] [pid 503470:tid 503665] [client 66.249.66.45:54690] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:45.721818 2026] [authz_core:error] [pid 503470:tid 503665] [client 66.249.66.45:54690] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:45.751749 2026] [security2:error] [pid 503470:tid 503702] [client 52.139.37.240:31841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/areak1.php"] [unique_id "apPk0T8EKFABaii6jtMG-QAAAOs"]
[Sun Aug 30 03:07:45.772169 2026] [authz_core:error] [pid 499145:tid 499292] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_US%2FLC_MESSAGES
[Sun Aug 30 03:07:45.772609 2026] [authz_core:error] [pid 499145:tid 499292] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_US%2FLC_MESSAGES
[Sun Aug 30 03:07:45.775370 2026] [security2:error] [pid 503470:tid 503705] [client 158.23.147.79:62299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/sad/about.php"] [unique_id "apPk0T8EKFABaii6jtMG_wAAAO4"]
[Sun Aug 30 03:07:45.792164 2026] [security2:error] [pid 503470:tid 503616] [client 158.23.184.117:2384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/termps.php"] [unique_id "apPk0T8EKFABaii6jtMHDAAAAJU"]
[Sun Aug 30 03:07:45.794941 2026] [authz_core:error] [pid 499145:tid 499276] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:45.795209 2026] [authz_core:error] [pid 499145:tid 499276] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:45.803196 2026] [security2:error] [pid 503470:tid 503602] [client 20.220.10.235:29100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/admin.php/pindex.php"] [unique_id "apPk0T8EKFABaii6jtMHDgAAAIc"]
[Sun Aug 30 03:07:45.809281 2026] [security2:error] [pid 503470:tid 503691] [client 68.155.159.216:11157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apPk0T8EKFABaii6jtMHEQAAAOA"]
[Sun Aug 30 03:07:45.842323 2026] [security2:error] [pid 503470:tid 503694] [client 20.48.250.41:60707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/error_log.php"] [unique_id "apPk0T8EKFABaii6jtMHJAAAAOM"]
[Sun Aug 30 03:07:45.853792 2026] [security2:error] [pid 503470:tid 503671] [client 40.83.93.50:9690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/upgrade-temp-backup/themes/wp-links-opml.php"] [unique_id "apPk0T8EKFABaii6jtMHLwAAAMw"]
[Sun Aug 30 03:07:45.867970 2026] [security2:error] [pid 503470:tid 503614] [client 4.205.62.107:18965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/configuration.php"] [unique_id "apPk0T8EKFABaii6jtMHNQAAAJM"]
[Sun Aug 30 03:07:45.889285 2026] [security2:error] [pid 503470:tid 503658] [client 20.104.50.220:62238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-content/uploads/simple-file-list/alfa.php"] [unique_id "apPk0T8EKFABaii6jtMHOgAAAL8"]
[Sun Aug 30 03:07:45.907724 2026] [security2:error] [pid 503470:tid 503699] [client 20.104.50.220:51557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/lf.php"] [unique_id "apPk0T8EKFABaii6jtMHQwAAAOg"]
[Sun Aug 30 03:07:45.911058 2026] [security2:error] [pid 503470:tid 503628] [client 4.205.62.107:32043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/bigdump.php"] [unique_id "apPk0T8EKFABaii6jtMHSAAAAKE"]
[Sun Aug 30 03:07:45.932795 2026] [security2:error] [pid 503470:tid 503640] [client 158.23.184.117:2330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/fix.php"] [unique_id "apPk0T8EKFABaii6jtMHUAAAAK0"]
[Sun Aug 30 03:07:45.938587 2026] [security2:error] [pid 503470:tid 503703] [client 68.155.159.216:61655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/.well-knownold/index.php"] [unique_id "apPk0T8EKFABaii6jtMHUQAAAOw"]
[Sun Aug 30 03:07:45.956359 2026] [security2:error] [pid 503470:tid 503641] [client 68.155.159.216:54257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/content.php"] [unique_id "apPk0T8EKFABaii6jtMHXAAAAK4"]
[Sun Aug 30 03:07:45.958311 2026] [security2:error] [pid 503470:tid 503689] [client 158.23.147.79:63949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/admin.php"] [unique_id "apPk0T8EKFABaii6jtMHYAAAAN4"]
[Sun Aug 30 03:07:45.964908 2026] [security2:error] [pid 503470:tid 503679] [client 20.220.10.235:28742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/admin.php/csv.php"] [unique_id "apPk0T8EKFABaii6jtMHaQAAANQ"]
[Sun Aug 30 03:07:45.978117 2026] [security2:error] [pid 503470:tid 503672] [client 52.139.37.240:52217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/vc.php"] [unique_id "apPk0T8EKFABaii6jtMHeAAAAM0"]
[Sun Aug 30 03:07:46.022903 2026] [authz_core:error] [pid 503470:tid 503617] [client 66.249.66.70:57280] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:46.023262 2026] [authz_core:error] [pid 503470:tid 503617] [client 66.249.66.70:57280] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:46.027394 2026] [security2:error] [pid 503470:tid 503641] [client 20.48.250.41:62563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/403.php"] [unique_id "apPk0j8EKFABaii6jtMHjAAAAK4"]
[Sun Aug 30 03:07:46.044929 2026] [security2:error] [pid 503470:tid 503666] [client 20.104.50.220:29133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/help.php"] [unique_id "apPk0j8EKFABaii6jtMHmAAAAMc"]
[Sun Aug 30 03:07:46.073071 2026] [security2:error] [pid 503470:tid 503631] [client 158.23.184.117:2304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/wp-includes/ID3/admin.php"] [unique_id "apPk0j8EKFABaii6jtMHsgAAAKQ"]
[Sun Aug 30 03:07:46.104353 2026] [security2:error] [pid 503470:tid 503637] [client 20.220.10.235:29082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/admin.php/700.php"] [unique_id "apPk0j8EKFABaii6jtMHyAAAAKo"]
[Sun Aug 30 03:07:46.136802 2026] [security2:error] [pid 503470:tid 503726] [client 158.23.147.79:63925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-admin/admin.php"] [unique_id "apPk0j8EKFABaii6jtMH1QAAAQM"]
[Sun Aug 30 03:07:46.172901 2026] [security2:error] [pid 503470:tid 503720] [client 20.104.50.220:27550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/boot-fs.php"] [unique_id "apPk0j8EKFABaii6jtMH8wAAAP0"]
[Sun Aug 30 03:07:46.177392 2026] [security2:error] [pid 503470:tid 503635] [client 52.139.37.240:31857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPk0j8EKFABaii6jtMH9wAAAKg"]
[Sun Aug 30 03:07:46.179028 2026] [security2:error] [pid 503470:tid 503697] [client 40.83.93.50:19394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/fw.php"] [unique_id "apPk0j8EKFABaii6jtMH-AAAAOY"]
[Sun Aug 30 03:07:46.188142 2026] [authz_core:error] [pid 499145:tid 499353] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fjson-c
[Sun Aug 30 03:07:46.188416 2026] [authz_core:error] [pid 499145:tid 499353] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fjson-c
[Sun Aug 30 03:07:46.213679 2026] [security2:error] [pid 503470:tid 503681] [client 158.23.184.117:2310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/tiny.php"] [unique_id "apPk0j8EKFABaii6jtMIEAAAANY"]
[Sun Aug 30 03:07:46.229459 2026] [security2:error] [pid 503470:tid 503669] [client 34.125.55.247:32252] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/web.config"] [unique_id "apPk0j8EKFABaii6jtMIGgAAAMo"]
[Sun Aug 30 03:07:46.234932 2026] [security2:error] [pid 503470:tid 503602] [client 20.220.10.235:29057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/admin.php/007x.php"] [unique_id "apPk0j8EKFABaii6jtMIJAAAAIc"]
[Sun Aug 30 03:07:46.236230 2026] [security2:error] [pid 499145:tid 499357] [client 34.125.55.247:32338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.55.125.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.engaginggoddaily.com"] [uri "/configuration.php.bak"] [unique_id "apPk0lJNq1G5uRhTNnuQZgAAAFI"]
[Sun Aug 30 03:07:46.238959 2026] [proxy_http:error] [pid 503470:tid 503670] (20014)Internal error (specific information not available): [client 34.125.55.247:32282] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:46.238978 2026] [proxy:error] [pid 503470:tid 503670] [client 34.125.55.247:32282] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.s3cfg
[Sun Aug 30 03:07:46.242998 2026] [security2:error] [pid 503470:tid 503635] [client 20.48.250.41:62555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/cytyr.php"] [unique_id "apPk0j8EKFABaii6jtMILwAAAKg"]
[Sun Aug 30 03:07:46.244216 2026] [proxy_http:error] [pid 499145:tid 499387] (20014)Internal error (specific information not available): [client 34.125.55.247:32302] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:46.244235 2026] [proxy:error] [pid 499145:tid 499387] [client 34.125.55.247:32302] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/ssl/localhost.key
[Sun Aug 30 03:07:46.247215 2026] [proxy_http:error] [pid 503470:tid 503667] (20014)Internal error (specific information not available): [client 34.125.55.247:32266] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:46.247242 2026] [proxy:error] [pid 503470:tid 503667] [client 34.125.55.247:32266] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/rclone.conf
[Sun Aug 30 03:07:46.252866 2026] [security2:error] [pid 499145:tid 499387] [client 34.125.55.247:32302] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "502"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/502.shtml"] [unique_id "apPk0lJNq1G5uRhTNnuQaAAAAHA"]
[Sun Aug 30 03:07:46.253448 2026] [authz_core:error] [pid 499145:tid 499400] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:46.253555 2026] [proxy_http:error] [pid 503470:tid 503670] (20014)Internal error (specific information not available): [client 34.125.55.247:32282] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:46.253567 2026] [proxy:error] [pid 503470:tid 503670] [client 34.125.55.247:32282] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml
[Sun Aug 30 03:07:46.253719 2026] [security2:error] [pid 503470:tid 503670] [client 34.125.55.247:32282] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "502"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/502.shtml"] [unique_id "apPk0j8EKFABaii6jtMIHQAAAMs"]
[Sun Aug 30 03:07:46.253726 2026] [authz_core:error] [pid 499145:tid 499400] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:46.260580 2026] [proxy_http:error] [pid 503470:tid 503717] (20014)Internal error (specific information not available): [client 34.125.55.247:32252] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:46.268937 2026] [proxy_http:error] [pid 503470:tid 503608] (20014)Internal error (specific information not available): [client 34.125.55.247:32334] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:46.268969 2026] [proxy:error] [pid 503470:tid 503608] [client 34.125.55.247:32334] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/configuration.js
[Sun Aug 30 03:07:46.284783 2026] [security2:error] [pid 503470:tid 503630] [client 20.197.61.180:19069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/bak.php"] [unique_id "apPk0j8EKFABaii6jtMIVQAAAKM"]
[Sun Aug 30 03:07:46.285434 2026] [proxy_http:error] [pid 503470:tid 503660] (20014)Internal error (specific information not available): [client 34.125.55.247:32242] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:46.294359 2026] [security2:error] [pid 503470:tid 503697] [client 68.155.159.216:61367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-admin/network/index.php"] [unique_id "apPk0j8EKFABaii6jtMIWwAAAOY"]
[Sun Aug 30 03:07:46.296194 2026] [security2:error] [pid 503470:tid 503700] [client 20.104.50.220:6100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/53.php"] [unique_id "apPk0j8EKFABaii6jtMIXAAAAOk"]
[Sun Aug 30 03:07:46.297455 2026] [security2:error] [pid 503470:tid 503718] [client 4.205.62.107:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/pouhg.php"] [unique_id "apPk0j8EKFABaii6jtMIXgAAAPs"]
[Sun Aug 30 03:07:46.302792 2026] [proxy_http:error] [pid 503470:tid 503673] (20014)Internal error (specific information not available): [client 34.125.55.247:32340] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:46.310529 2026] [security2:error] [pid 503470:tid 503647] [client 114.119.148.138:58437] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.scholtek.com"] [uri "/md/wiki/index.php"] [unique_id "apPk0j8EKFABaii6jtMIaAAAALQ"], referer: https://amp.reddit.com/r/MineDefense/comments/3kgqwx/how_is_the_exchange_market_calculated
[Sun Aug 30 03:07:46.316700 2026] [proxy_http:error] [pid 503470:tid 503703] (20014)Internal error (specific information not available): [client 34.125.55.247:32288] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:46.324063 2026] [security2:error] [pid 503470:tid 503612] [client 158.23.147.79:63980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-includes/IXR/index.php"] [unique_id "apPk0j8EKFABaii6jtMIcwAAAJE"]
[Sun Aug 30 03:07:46.340114 2026] [security2:error] [pid 503470:tid 503619] [client 20.48.251.3:33293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/xp.php"] [unique_id "apPk0j8EKFABaii6jtMIhAAAAJg"]
[Sun Aug 30 03:07:46.344080 2026] [authz_core:error] [pid 499145:tid 499365] [client 66.249.66.65:46193] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:46.344382 2026] [authz_core:error] [pid 499145:tid 499365] [client 66.249.66.65:46193] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:46.353630 2026] [security2:error] [pid 503470:tid 503655] [client 40.83.93.50:6001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/upgrade-temp-backup/themes/wp-settings.php"] [unique_id "apPk0j8EKFABaii6jtMIlQAAALw"]
[Sun Aug 30 03:07:46.353977 2026] [security2:error] [pid 503470:tid 503646] [client 158.23.184.117:2320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/css/classwithtostring.php"] [unique_id "apPk0j8EKFABaii6jtMIlgAAALM"]
[Sun Aug 30 03:07:46.361764 2026] [security2:error] [pid 503470:tid 503645] [client 20.220.10.235:29059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/admin.php/heex.php"] [unique_id "apPk0j8EKFABaii6jtMInQAAALI"]
[Sun Aug 30 03:07:46.380104 2026] [security2:error] [pid 503470:tid 503703] [client 20.104.50.220:62790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/f0x.php"] [unique_id "apPk0j8EKFABaii6jtMIqgAAAOw"]
[Sun Aug 30 03:07:46.386687 2026] [security2:error] [pid 503470:tid 503638] [client 52.139.37.240:31866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/core.php"] [unique_id "apPk0j8EKFABaii6jtMIsQAAAKs"]
[Sun Aug 30 03:07:46.394003 2026] [security2:error] [pid 503470:tid 503698] [client 20.104.18.15:28641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/gray.php"] [unique_id "apPk0j8EKFABaii6jtMIvAAAAOc"]
[Sun Aug 30 03:07:46.429820 2026] [security2:error] [pid 503470:tid 503669] [client 20.104.50.220:46855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/file9.php"] [unique_id "apPk0j8EKFABaii6jtMI3AAAAMo"]
[Sun Aug 30 03:07:46.430395 2026] [security2:error] [pid 503470:tid 503717] [client 158.23.147.79:63914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/classwithtostring.php"] [unique_id "apPk0j8EKFABaii6jtMI3QAAAPo"]
[Sun Aug 30 03:07:46.457594 2026] [security2:error] [pid 503470:tid 503601] [client 20.104.50.220:17250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/uwa.php"] [unique_id "apPk0j8EKFABaii6jtMI5AAAAIY"]
[Sun Aug 30 03:07:46.458205 2026] [security2:error] [pid 503470:tid 503606] [client 20.48.250.41:60790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/galer.php"] [unique_id "apPk0j8EKFABaii6jtMI5QAAAIs"]
[Sun Aug 30 03:07:46.465218 2026] [security2:error] [pid 503470:tid 503692] [client 68.155.159.216:12308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apPk0j8EKFABaii6jtMI6QAAAOE"]
[Sun Aug 30 03:07:46.481897 2026] [security2:error] [pid 503470:tid 503658] [client 20.104.18.15:23525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/beck.php"] [unique_id "apPk0j8EKFABaii6jtMI_wAAAL8"]
[Sun Aug 30 03:07:46.484610 2026] [security2:error] [pid 503470:tid 503674] [client 20.104.18.15:34646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/xty.php"] [unique_id "apPk0j8EKFABaii6jtMJAwAAAM8"]
[Sun Aug 30 03:07:46.494290 2026] [security2:error] [pid 499145:tid 499311] [client 158.23.184.117:2417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/buy.php"] [unique_id "apPk0lJNq1G5uRhTNnuQzgAAACQ"]
[Sun Aug 30 03:07:46.503530 2026] [security2:error] [pid 503470:tid 503616] [client 20.220.10.235:29089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/tf.php"] [unique_id "apPk0j8EKFABaii6jtMJFwAAAJU"]
[Sun Aug 30 03:07:46.512034 2026] [security2:error] [pid 503470:tid 503692] [client 4.205.62.107:64452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/06.php"] [unique_id "apPk0j8EKFABaii6jtMJHQAAAOE"]
[Sun Aug 30 03:07:46.523261 2026] [security2:error] [pid 503470:tid 503682] [client 20.48.251.3:55484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/doc.php"] [unique_id "apPk0j8EKFABaii6jtMJIgAAANc"]
[Sun Aug 30 03:07:46.523476 2026] [security2:error] [pid 503470:tid 503727] [client 20.104.18.15:18306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/she11.php"] [unique_id "apPk0j8EKFABaii6jtMJJAAAAQQ"]
[Sun Aug 30 03:07:46.540351 2026] [core:error] [pid 503470:tid 503658] [client 158.23.184.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:07:46.540374 2026] [core:error] [pid 503470:tid 503658] [client 158.23.184.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:07:46.553148 2026] [security2:error] [pid 503470:tid 503709] [client 4.205.62.107:62439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/public/rip.php.php"] [unique_id "apPk0j8EKFABaii6jtMJPAAAAPI"]
[Sun Aug 30 03:07:46.555324 2026] [security2:error] [pid 503470:tid 503650] [client 158.23.147.79:63935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/install.php"] [unique_id "apPk0j8EKFABaii6jtMJPQAAALc"]
[Sun Aug 30 03:07:46.565455 2026] [security2:error] [pid 503470:tid 503721] [client 4.205.62.107:36624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/X57.php"] [unique_id "apPk0j8EKFABaii6jtMJQgAAAP4"]
[Sun Aug 30 03:07:46.579891 2026] [security2:error] [pid 499145:tid 499364] [client 52.139.37.240:31832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/wp-content/min.php"] [unique_id "apPk0lJNq1G5uRhTNnuQ6wAAAFk"]
[Sun Aug 30 03:07:46.595869 2026] [security2:error] [pid 503470:tid 503674] [client 20.104.18.15:51708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/abcd.php"] [unique_id "apPk0j8EKFABaii6jtMJXAAAAM8"]
[Sun Aug 30 03:07:46.629888 2026] [security2:error] [pid 503470:tid 503671] [client 20.48.250.41:62566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/baixy.php"] [unique_id "apPk0j8EKFABaii6jtMJZwAAAMw"]
[Sun Aug 30 03:07:46.632671 2026] [authz_core:error] [pid 499145:tid 499389] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:46.632938 2026] [authz_core:error] [pid 499145:tid 499389] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:46.633328 2026] [security2:error] [pid 503470:tid 503647] [client 158.23.184.117:2332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/bk.php"] [unique_id "apPk0j8EKFABaii6jtMJaAAAALQ"]
[Sun Aug 30 03:07:46.634036 2026] [security2:error] [pid 503470:tid 503604] [client 20.220.10.235:29078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/update/da222.php"] [unique_id "apPk0j8EKFABaii6jtMJaQAAAIk"]
[Sun Aug 30 03:07:46.644780 2026] [security2:error] [pid 499145:tid 499317] [client 20.104.18.15:29171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/133.php"] [unique_id "apPk0lJNq1G5uRhTNnuQ9wAAACo"]
[Sun Aug 30 03:07:46.663494 2026] [security2:error] [pid 499145:tid 499353] [client 20.151.200.44:57801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/Contrller.php"] [unique_id "apPk0lJNq1G5uRhTNnuQ-gAAAE4"]
[Sun Aug 30 03:07:46.680019 2026] [authz_core:error] [pid 499145:tid 499342] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:46.680489 2026] [authz_core:error] [pid 499145:tid 499342] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:46.712721 2026] [security2:error] [pid 503470:tid 503649] [client 20.104.50.220:31887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-installer.php"] [unique_id "apPk0j8EKFABaii6jtMJiAAAALY"]
[Sun Aug 30 03:07:46.714264 2026] [security2:error] [pid 503470:tid 503608] [client 4.205.62.107:22568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/environment.php"] [unique_id "apPk0j8EKFABaii6jtMJiQAAAI0"]
[Sun Aug 30 03:07:46.746379 2026] [security2:error] [pid 503470:tid 503699] [client 20.104.50.220:33310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/XiXi.php"] [unique_id "apPk0j8EKFABaii6jtMJqgAAAOg"]
[Sun Aug 30 03:07:46.748019 2026] [security2:error] [pid 503470:tid 503660] [client 158.23.147.79:63926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-content/x/index.php"] [unique_id "apPk0j8EKFABaii6jtMJqwAAAME"]
[Sun Aug 30 03:07:46.771149 2026] [security2:error] [pid 503470:tid 503614] [client 52.139.37.240:32129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "apPk0j8EKFABaii6jtMJuQAAAJM"]
[Sun Aug 30 03:07:46.773175 2026] [security2:error] [pid 503470:tid 503698] [client 158.23.184.117:2395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/.trash7309/index.php"] [unique_id "apPk0j8EKFABaii6jtMJvQAAAOc"]
[Sun Aug 30 03:07:46.779849 2026] [security2:error] [pid 503470:tid 503720] [client 20.48.251.3:44370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/test.php"] [unique_id "apPk0j8EKFABaii6jtMJxAAAAP0"]
[Sun Aug 30 03:07:46.780911 2026] [security2:error] [pid 503470:tid 503641] [client 20.220.10.235:29119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/qi.php"] [unique_id "apPk0j8EKFABaii6jtMJyAAAAK4"]
[Sun Aug 30 03:07:46.817115 2026] [authz_core:error] [pid 499145:tid 499339] [client 216.73.216.128:47617] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:46.817593 2026] [authz_core:error] [pid 499145:tid 499339] [client 216.73.216.128:47617] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:46.831230 2026] [security2:error] [pid 503470:tid 503715] [client 20.48.250.41:62481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/ava.php"] [unique_id "apPk0j8EKFABaii6jtMJ3wAAAPg"]
[Sun Aug 30 03:07:46.860816 2026] [security2:error] [pid 503470:tid 503699] [client 158.23.147.79:63979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-includes/Requests/about.php"] [unique_id "apPk0j8EKFABaii6jtMJ-QAAAOg"]
[Sun Aug 30 03:07:46.861595 2026] [security2:error] [pid 503470:tid 503718] [client 20.104.104.62:55865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/css/000.php"] [unique_id "apPk0j8EKFABaii6jtMJ-gAAAPs"]
[Sun Aug 30 03:07:46.879587 2026] [security2:error] [pid 503470:tid 503685] [client 40.83.93.50:7884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/test.php"] [unique_id "apPk0j8EKFABaii6jtMKAQAAANo"]
[Sun Aug 30 03:07:46.901949 2026] [security2:error] [pid 503470:tid 503649] [client 68.155.159.216:61422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-admin.php"] [unique_id "apPk0j8EKFABaii6jtMKDQAAALY"]
[Sun Aug 30 03:07:46.914549 2026] [security2:error] [pid 503470:tid 503677] [client 20.220.10.235:29124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/px.php"] [unique_id "apPk0j8EKFABaii6jtMKFQAAANI"]
[Sun Aug 30 03:07:46.914626 2026] [security2:error] [pid 503470:tid 503727] [client 68.155.159.216:56357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apPk0j8EKFABaii6jtMKFAAAAQQ"]
[Sun Aug 30 03:07:46.919875 2026] [security2:error] [pid 503470:tid 503648] [client 20.104.49.130:34527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/ohct.php"] [unique_id "apPk0j8EKFABaii6jtMKFgAAALU"]
[Sun Aug 30 03:07:46.920033 2026] [security2:error] [pid 499145:tid 499373] [client 158.23.184.117:2352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/jp.php"] [unique_id "apPk0lJNq1G5uRhTNnuRSgAAAGI"]
[Sun Aug 30 03:07:46.962496 2026] [security2:error] [pid 503470:tid 503690] [client 158.23.147.79:63888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-admin/includes/index.php"] [unique_id "apPk0j8EKFABaii6jtMKJgAAAN8"]
[Sun Aug 30 03:07:46.963576 2026] [security2:error] [pid 503470:tid 503626] [client 20.48.251.3:7066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/doc.php"] [unique_id "apPk0j8EKFABaii6jtMKKgAAAJ8"]
[Sun Aug 30 03:07:46.986478 2026] [security2:error] [pid 499145:tid 499363] [client 20.48.250.41:60716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/gdn.php"] [unique_id "apPk0lJNq1G5uRhTNnuRYwAAAFg"]
[Sun Aug 30 03:07:46.994529 2026] [security2:error] [pid 503470:tid 503611] [client 20.104.104.62:57017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/cy.php"] [unique_id "apPk0j8EKFABaii6jtMKRQAAAJA"]
[Sun Aug 30 03:07:47.005067 2026] [security2:error] [pid 503470:tid 503653] [client 52.139.37.240:52223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/ws37.php"] [unique_id "apPk0z8EKFABaii6jtMKTgAAALo"]
[Sun Aug 30 03:07:47.006199 2026] [authz_core:error] [pid 503470:tid 503712] [client 66.249.66.196:48641] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:47.006384 2026] [security2:error] [pid 503470:tid 503676] [client 40.83.93.50:5991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/upgrade/about.php"] [unique_id "apPk0z8EKFABaii6jtMKTwAAANE"]
[Sun Aug 30 03:07:47.006685 2026] [authz_core:error] [pid 503470:tid 503712] [client 66.249.66.196:48641] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:47.016802 2026] [authz_core:error] [pid 499145:tid 499289] [client 216.73.216.128:47617] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:47.017088 2026] [authz_core:error] [pid 499145:tid 499289] [client 216.73.216.128:47617] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:47.036674 2026] [security2:error] [pid 503470:tid 503685] [client 4.205.62.107:18627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/server_info.php"] [unique_id "apPk0z8EKFABaii6jtMKZgAAANo"]
[Sun Aug 30 03:07:47.050358 2026] [security2:error] [pid 503470:tid 503652] [client 20.220.10.235:28747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/is.php"] [unique_id "apPk0z8EKFABaii6jtMKcgAAALk"]
[Sun Aug 30 03:07:47.062968 2026] [security2:error] [pid 503470:tid 503687] [client 158.23.184.117:2377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/item.php"] [unique_id "apPk0z8EKFABaii6jtMKegAAANw"]
[Sun Aug 30 03:07:47.064690 2026] [security2:error] [pid 503470:tid 503662] [client 158.23.147.79:63983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-login.php"] [unique_id "apPk0z8EKFABaii6jtMKewAAAMM"]
[Sun Aug 30 03:07:47.070418 2026] [security2:error] [pid 503470:tid 503708] [client 20.104.50.220:56715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/saya.php"] [unique_id "apPk0z8EKFABaii6jtMKhAAAAPE"]
[Sun Aug 30 03:07:47.081000 2026] [security2:error] [pid 503470:tid 503690] [client 20.104.50.220:61680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/Ninja.php"] [unique_id "apPk0z8EKFABaii6jtMKiQAAAN8"]
[Sun Aug 30 03:07:47.090875 2026] [security2:error] [pid 503470:tid 503667] [client 68.155.159.216:55159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPk0z8EKFABaii6jtMKlAAAAMg"]
[Sun Aug 30 03:07:47.097828 2026] [security2:error] [pid 503470:tid 503616] [client 68.155.159.216:61672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apPk0z8EKFABaii6jtMKmgAAAJU"]
[Sun Aug 30 03:07:47.124272 2026] [security2:error] [pid 503470:tid 503601] [client 20.104.104.62:56998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/admin.php/pindex.php"] [unique_id "apPk0z8EKFABaii6jtMKoQAAAIY"]
[Sun Aug 30 03:07:47.127469 2026] [security2:error] [pid 503470:tid 503683] [client 20.197.61.180:9360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/pages.php"] [unique_id "apPk0z8EKFABaii6jtMKpQAAANg"]
[Sun Aug 30 03:07:47.133998 2026] [authz_core:error] [pid 503470:tid 503645] [client 74.7.227.8:38186] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:47.134312 2026] [authz_core:error] [pid 503470:tid 503645] [client 74.7.227.8:38186] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:47.171949 2026] [security2:error] [pid 503470:tid 503717] [client 20.48.250.41:62567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/f2.php"] [unique_id "apPk0z8EKFABaii6jtMKxAAAAPo"]
[Sun Aug 30 03:07:47.174959 2026] [authz_core:error] [pid 499145:tid 499346] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fjson-c
[Sun Aug 30 03:07:47.175223 2026] [authz_core:error] [pid 499145:tid 499346] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fjson-c
[Sun Aug 30 03:07:47.176437 2026] [security2:error] [pid 503470:tid 503681] [client 158.23.147.79:62274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apPk0z8EKFABaii6jtMKyQAAANY"]
[Sun Aug 30 03:07:47.183526 2026] [security2:error] [pid 499145:tid 499343] [client 20.220.10.235:29075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/od.php"] [unique_id "apPk01JNq1G5uRhTNnuRrwAAAEQ"]
[Sun Aug 30 03:07:47.201535 2026] [security2:error] [pid 503470:tid 503633] [client 158.23.184.117:2357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/wp-admin/controller.php"] [unique_id "apPk0z8EKFABaii6jtMK2wAAAKY"]
[Sun Aug 30 03:07:47.204276 2026] [security2:error] [pid 503470:tid 503635] [client 52.139.37.240:52226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/new.php"] [unique_id "apPk0z8EKFABaii6jtMK4AAAAKg"]
[Sun Aug 30 03:07:47.245623 2026] [security2:error] [pid 503470:tid 503663] [client 141.94.139.14:33470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.139.94.141.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "riverglenhoa.com"] [uri "/wp-login.php"] [unique_id "apPk0z8EKFABaii6jtMK5wAAAMQ"]
[Sun Aug 30 03:07:47.270552 2026] [security2:error] [pid 503470:tid 503622] [client 178.16.55.109:57824] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "neilgclark.com"] [uri "/index.php"] [unique_id "apPk0z8EKFABaii6jtMLCQAAAJs"]
[Sun Aug 30 03:07:47.279570 2026] [security2:error] [pid 503470:tid 503643] [client 158.23.147.79:63994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-admin/images/about.php"] [unique_id "apPk0z8EKFABaii6jtMLEQAAALA"]
[Sun Aug 30 03:07:47.290982 2026] [authz_core:error] [pid 499145:tid 499369] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:47.291264 2026] [authz_core:error] [pid 499145:tid 499369] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:47.303205 2026] [security2:error] [pid 503470:tid 503676] [client 20.48.250.41:60711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/grsiuk.php"] [unique_id "apPk0z8EKFABaii6jtMLIwAAANE"]
[Sun Aug 30 03:07:47.315460 2026] [security2:error] [pid 503470:tid 503679] [client 20.104.50.220:27538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/taxonomy.php"] [unique_id "apPk0z8EKFABaii6jtMLKgAAANQ"]
[Sun Aug 30 03:07:47.315838 2026] [security2:error] [pid 503470:tid 503681] [client 20.104.104.62:55864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/admin.php/csv.php"] [unique_id "apPk0z8EKFABaii6jtMLKwAAANY"]
[Sun Aug 30 03:07:47.317022 2026] [security2:error] [pid 503470:tid 503665] [client 20.220.10.235:29068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/wp-the.php"] [unique_id "apPk0z8EKFABaii6jtMLLAAAAMY"]
[Sun Aug 30 03:07:47.356329 2026] [security2:error] [pid 499145:tid 499293] [client 65.108.6.34:34660] ModSecurity: Warning. Matched phrase "SEOkicks" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "flashflooring.co.uk"] [uri "/index.php"] [unique_id "apPk0lJNq1G5uRhTNnuQ8QAAABI"], referer: https://flashflooring.co.uk/
[Sun Aug 30 03:07:47.373473 2026] [security2:error] [pid 499145:tid 499353] [client 40.83.93.50:7919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/dropdown.php"] [unique_id "apPk01JNq1G5uRhTNnuR-AAAAE4"]
[Sun Aug 30 03:07:47.383292 2026] [security2:error] [pid 503470:tid 503662] [client 216.73.216.128:41450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPk0z8EKFABaii6jtMLXgAAAMM"]
[Sun Aug 30 03:07:47.389947 2026] [security2:error] [pid 503470:tid 503678] [client 4.205.62.107:32048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/wdf.php"] [unique_id "apPk0z8EKFABaii6jtMLZwAAANM"]
[Sun Aug 30 03:07:47.391403 2026] [security2:error] [pid 503470:tid 503666] [client 158.23.184.117:2354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/wp-configs.php"] [unique_id "apPk0z8EKFABaii6jtMLagAAAMc"]
[Sun Aug 30 03:07:47.397051 2026] [security2:error] [pid 503470:tid 503713] [client 68.155.159.216:63967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apPk0z8EKFABaii6jtMLcQAAAPY"]
[Sun Aug 30 03:07:47.434914 2026] [security2:error] [pid 499145:tid 499305] [client 20.104.50.220:5631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/52.php"] [unique_id "apPk01JNq1G5uRhTNnuSHQAAAB4"]
[Sun Aug 30 03:07:47.435695 2026] [security2:error] [pid 499145:tid 499362] [client 4.205.62.107:62035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/phpversion.php"] [unique_id "apPk01JNq1G5uRhTNnuSHgAAAFc"]
[Sun Aug 30 03:07:47.450881 2026] [security2:error] [pid 499145:tid 499318] [client 158.23.147.79:62280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPk01JNq1G5uRhTNnuSJQAAACs"]
[Sun Aug 30 03:07:47.459204 2026] [security2:error] [pid 503470:tid 503625] [client 20.220.10.235:28737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/wt.php"] [unique_id "apPk0z8EKFABaii6jtMLkgAAAJ4"]
[Sun Aug 30 03:07:47.463296 2026] [security2:error] [pid 503470:tid 503726] [client 52.139.37.240:31842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/il.php"] [unique_id "apPk0z8EKFABaii6jtMLlwAAAQM"]
[Sun Aug 30 03:07:47.472638 2026] [security2:error] [pid 503470:tid 503605] [client 40.83.93.50:11505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bluegrassatthelake.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "apPk0z8EKFABaii6jtMLoAAAAIo"]
[Sun Aug 30 03:07:47.478964 2026] [security2:error] [pid 503470:tid 503697] [client 20.104.104.62:56993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/admin.php/700.php"] [unique_id "apPk0z8EKFABaii6jtMLqQAAAOY"]
[Sun Aug 30 03:07:47.481815 2026] [security2:error] [pid 503470:tid 503696] [client 20.48.251.3:13427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/g3.php"] [unique_id "apPk0z8EKFABaii6jtMLrQAAAOU"]
[Sun Aug 30 03:07:47.504849 2026] [security2:error] [pid 503470:tid 503641] [client 47.128.29.18:51426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.lordrcane.com"] [uri "/tag/rift-rogue-build/"] [unique_id "apPk0z8EKFABaii6jtMLwwAAAK4"]
[Sun Aug 30 03:07:47.516374 2026] [authz_core:error] [pid 499145:tid 499313] [client 66.249.66.68:45378] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:47.516631 2026] [authz_core:error] [pid 499145:tid 499313] [client 66.249.66.68:45378] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:47.520071 2026] [security2:error] [pid 503470:tid 503719] [client 20.104.50.220:52848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-includes/fw.php"] [unique_id "apPk0z8EKFABaii6jtMLyQAAAPw"]
[Sun Aug 30 03:07:47.534694 2026] [security2:error] [pid 503470:tid 503701] [client 20.48.250.41:62491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/wp-scr1pts.php"] [unique_id "apPk0z8EKFABaii6jtML2AAAAOo"]
[Sun Aug 30 03:07:47.535432 2026] [security2:error] [pid 503470:tid 503604] [client 20.104.18.15:28444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/puki.php"] [unique_id "apPk0z8EKFABaii6jtML2QAAAIk"]
[Sun Aug 30 03:07:47.551174 2026] [security2:error] [pid 499145:tid 499391] [client 158.23.184.117:2307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/wp-admin/user/credits.php"] [unique_id "apPk01JNq1G5uRhTNnuSXAAAAHQ"]
[Sun Aug 30 03:07:47.568945 2026] [security2:error] [pid 503470:tid 503687] [client 20.104.50.220:46463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/filesss.php"] [unique_id "apPk0z8EKFABaii6jtML7AAAANw"]
[Sun Aug 30 03:07:47.597038 2026] [security2:error] [pid 503470:tid 503617] [client 20.104.50.220:17327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/crgio.php"] [unique_id "apPk0z8EKFABaii6jtML_gAAAJY"]
[Sun Aug 30 03:07:47.607524 2026] [security2:error] [pid 503470:tid 503653] [client 20.220.10.235:29070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/im.php"] [unique_id "apPk0z8EKFABaii6jtMMAwAAALo"]
[Sun Aug 30 03:07:47.619119 2026] [security2:error] [pid 503470:tid 503669] [client 20.104.18.15:23471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/t3.php"] [unique_id "apPk0z8EKFABaii6jtMMBwAAAMo"]
[Sun Aug 30 03:07:47.628573 2026] [security2:error] [pid 503470:tid 503688] [client 20.104.18.15:34768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/sallu.php"] [unique_id "apPk0z8EKFABaii6jtMMCAAAAN0"]
[Sun Aug 30 03:07:47.637525 2026] [security2:error] [pid 503470:tid 503626] [client 68.155.159.216:12376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apPk0z8EKFABaii6jtMMCgAAAJ8"]
[Sun Aug 30 03:07:47.638771 2026] [security2:error] [pid 499145:tid 499397] [client 20.104.104.62:56974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/admin.php/007x.php"] [unique_id "apPk01JNq1G5uRhTNnuScwAAAHo"]
[Sun Aug 30 03:07:47.647090 2026] [security2:error] [pid 499145:tid 499365] [client 4.205.62.107:61764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/xin1.php"] [unique_id "apPk01JNq1G5uRhTNnuSdgAAAFo"]
[Sun Aug 30 03:07:47.659541 2026] [security2:error] [pid 503470:tid 503665] [client 20.48.251.3:49958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/classsmtps.php"] [unique_id "apPk0z8EKFABaii6jtMMEAAAAMY"]
[Sun Aug 30 03:07:47.661045 2026] [security2:error] [pid 503470:tid 503651] [client 20.104.18.15:18340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/kerang.php"] [unique_id "apPk0z8EKFABaii6jtMMEQAAALg"]
[Sun Aug 30 03:07:47.671425 2026] [security2:error] [pid 503470:tid 503717] [client 52.139.37.240:31870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/images/index.php"] [unique_id "apPk0z8EKFABaii6jtMMFgAAAPo"]
[Sun Aug 30 03:07:47.673556 2026] [authz_core:error] [pid 499145:tid 499402] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:47.673841 2026] [authz_core:error] [pid 499145:tid 499402] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:07:47.684217 2026] [security2:error] [pid 499145:tid 499334] [client 158.23.147.79:63950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-admin.php"] [unique_id "apPk01JNq1G5uRhTNnuSfgAAADs"]
[Sun Aug 30 03:07:47.691943 2026] [security2:error] [pid 503470:tid 503643] [client 158.23.184.117:2401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "apPk0z8EKFABaii6jtMMHQAAALA"]
[Sun Aug 30 03:07:47.717300 2026] [security2:error] [pid 503470:tid 503715] [client 4.205.62.107:36691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/register.php"] [unique_id "apPk0z8EKFABaii6jtMMNAAAAPg"]
[Sun Aug 30 03:07:47.733521 2026] [authz_core:error] [pid 503470:tid 503638] [client 66.249.66.35:55448] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:47.733834 2026] [authz_core:error] [pid 503470:tid 503638] [client 66.249.66.35:55448] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:47.765355 2026] [security2:error] [pid 503470:tid 503693] [client 20.104.18.15:51630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/nofile.php"] [unique_id "apPk0z8EKFABaii6jtMMXQAAAOI"]
[Sun Aug 30 03:07:47.772172 2026] [security2:error] [pid 503470:tid 503716] [client 20.48.250.41:62488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/num.php"] [unique_id "apPk0z8EKFABaii6jtMMXgAAAPk"]
[Sun Aug 30 03:07:47.803631 2026] [security2:error] [pid 503470:tid 503620] [client 20.220.10.235:28763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/file.php"] [unique_id "apPk0z8EKFABaii6jtMMbwAAAJk"]
[Sun Aug 30 03:07:47.805371 2026] [security2:error] [pid 503470:tid 503633] [client 20.104.18.15:29666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/sym.php"] [unique_id "apPk0z8EKFABaii6jtMMcQAAAKY"]
[Sun Aug 30 03:07:47.832066 2026] [security2:error] [pid 503470:tid 503671] [client 158.23.184.117:2260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/.well-known/about/function.php"] [unique_id "apPk0z8EKFABaii6jtMMgAAAAMw"]
[Sun Aug 30 03:07:47.844757 2026] [security2:error] [pid 503470:tid 503622] [client 40.83.93.50:19419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/mar.php"] [unique_id "apPk0z8EKFABaii6jtMMiwAAAJs"]
[Sun Aug 30 03:07:47.861740 2026] [security2:error] [pid 499145:tid 499363] [client 4.205.62.107:62304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/aws_secret_config.php"] [unique_id "apPk01JNq1G5uRhTNnuSvAAAAFg"]
[Sun Aug 30 03:07:47.864757 2026] [security2:error] [pid 499145:tid 499401] [client 158.23.147.79:63918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-includes/assets/index.php"] [unique_id "apPk01JNq1G5uRhTNnuSvgAAAH4"]
[Sun Aug 30 03:07:47.866424 2026] [security2:error] [pid 503470:tid 503652] [client 52.139.37.240:32142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/lite.php"] [unique_id "apPk0z8EKFABaii6jtMMlwAAALk"]
[Sun Aug 30 03:07:47.884354 2026] [security2:error] [pid 499145:tid 499384] [client 20.104.50.220:33299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/.piongroup.php"] [unique_id "apPk01JNq1G5uRhTNnuSxAAAAG0"]
[Sun Aug 30 03:07:47.886824 2026] [security2:error] [pid 499145:tid 499310] [client 20.197.61.180:9352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/albin.php"] [unique_id "apPk01JNq1G5uRhTNnuSxgAAACM"]
[Sun Aug 30 03:07:47.892708 2026] [security2:error] [pid 503470:tid 503620] [client 20.104.49.130:45739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/albin.php"] [unique_id "apPk0z8EKFABaii6jtMMowAAAJk"]
[Sun Aug 30 03:07:47.927549 2026] [security2:error] [pid 499145:tid 499386] [client 20.104.50.220:31857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-js.php"] [unique_id "apPk01JNq1G5uRhTNnuS0wAAAG8"]
[Sun Aug 30 03:07:47.947914 2026] [authz_core:error] [pid 499145:tid 499308] [client 216.73.216.128:47617] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:47.948362 2026] [authz_core:error] [pid 499145:tid 499308] [client 216.73.216.128:47617] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:47.958115 2026] [security2:error] [pid 503470:tid 503669] [client 20.220.10.235:29115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/ca.php"] [unique_id "apPk0z8EKFABaii6jtMMuwAAAMo"]
[Sun Aug 30 03:07:47.974250 2026] [security2:error] [pid 503470:tid 503706] [client 158.23.184.117:2278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPk0z8EKFABaii6jtMM0AAAAO8"]
[Sun Aug 30 03:07:47.977172 2026] [security2:error] [pid 503470:tid 503608] [client 20.48.250.41:62537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/a4.php"] [unique_id "apPk0z8EKFABaii6jtMM0wAAAI0"]
[Sun Aug 30 03:07:47.983288 2026] [security2:error] [pid 503470:tid 503620] [client 20.48.251.3:44320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/cloud.php"] [unique_id "apPk0z8EKFABaii6jtMM2AAAAJk"]
[Sun Aug 30 03:07:47.995758 2026] [security2:error] [pid 503470:tid 503717] [client 158.23.147.79:63947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/lock.php"] [unique_id "apPk0z8EKFABaii6jtMM4gAAAPo"]
[Sun Aug 30 03:07:48.038650 2026] [security2:error] [pid 503470:tid 503663] [client 68.155.159.216:11241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apPk1D8EKFABaii6jtMM-gAAAMQ"]
[Sun Aug 30 03:07:48.060333 2026] [security2:error] [pid 503470:tid 503713] [client 52.139.37.240:31810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/xda.php"] [unique_id "apPk1D8EKFABaii6jtMNBQAAAPY"]
[Sun Aug 30 03:07:48.101700 2026] [security2:error] [pid 503470:tid 503643] [client 20.220.10.235:29093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/pb.php"] [unique_id "apPk1D8EKFABaii6jtMNJAAAALA"]
[Sun Aug 30 03:07:48.113459 2026] [security2:error] [pid 503470:tid 503720] [client 158.23.184.117:2251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/gg.php"] [unique_id "apPk1D8EKFABaii6jtMNJwAAAP0"]
[Sun Aug 30 03:07:48.121814 2026] [security2:error] [pid 503470:tid 503705] [client 68.155.159.216:60885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apPk1D8EKFABaii6jtMNKQAAAO4"]
[Sun Aug 30 03:07:48.124041 2026] [security2:error] [pid 499145:tid 499397] [client 216.73.216.128:47617] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPk1FJNq1G5uRhTNnuTHAAAAHo"]
[Sun Aug 30 03:07:48.133486 2026] [security2:error] [pid 503470:tid 503646] [client 20.48.250.41:62508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/tfm.php"] [unique_id "apPk1D8EKFABaii6jtMNLQAAALM"]
[Sun Aug 30 03:07:48.165761 2026] [authz_core:error] [pid 499145:tid 499282] [client 66.249.66.78:41602] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:48.166041 2026] [authz_core:error] [pid 499145:tid 499282] [client 66.249.66.78:41602] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:48.189865 2026] [security2:error] [pid 503470:tid 503713] [client 158.23.147.79:63933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/index/function.php"] [unique_id "apPk1D8EKFABaii6jtMNbQAAAPY"]
[Sun Aug 30 03:07:48.200860 2026] [security2:error] [pid 499145:tid 499357] [client 114.119.151.103:59101] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bohemianmode.com"] [uri "/collections/winter"] [unique_id "apPk1FJNq1G5uRhTNnuTQQAAAFI"], referer: https://bohemianmode.com/collections/winter?page=3
[Sun Aug 30 03:07:48.204053 2026] [security2:error] [pid 503470:tid 503605] [client 4.205.62.107:18638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/hosty.php"] [unique_id "apPk1D8EKFABaii6jtMNfgAAAIo"]
[Sun Aug 30 03:07:48.209218 2026] [security2:error] [pid 503470:tid 503641] [client 20.104.50.220:63498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/do.php"] [unique_id "apPk1D8EKFABaii6jtMNggAAAK4"]
[Sun Aug 30 03:07:48.229456 2026] [security2:error] [pid 503470:tid 503683] [client 68.155.159.216:61644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPk1D8EKFABaii6jtMNiQAAANg"]
[Sun Aug 30 03:07:48.236355 2026] [security2:error] [pid 503470:tid 503720] [client 68.155.159.216:55047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/goat.php"] [unique_id "apPk1D8EKFABaii6jtMNjgAAAP0"]
[Sun Aug 30 03:07:48.244893 2026] [security2:error] [pid 503470:tid 503617] [client 20.220.10.235:28749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/pk.php"] [unique_id "apPk1D8EKFABaii6jtMNlQAAAJY"]
[Sun Aug 30 03:07:48.252355 2026] [security2:error] [pid 503470:tid 503689] [client 52.139.37.240:32158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/.trash7206/index.php"] [unique_id "apPk1D8EKFABaii6jtMNoAAAAN4"]
[Sun Aug 30 03:07:48.254848 2026] [authz_core:error] [pid 499145:tid 499354] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AU
[Sun Aug 30 03:07:48.255168 2026] [authz_core:error] [pid 499145:tid 499354] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AU
[Sun Aug 30 03:07:48.257266 2026] [security2:error] [pid 503470:tid 503704] [client 158.23.184.117:2424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/wp-admin/includes/post.php"] [unique_id "apPk1D8EKFABaii6jtMNpAAAAO0"]
[Sun Aug 30 03:07:48.271871 2026] [security2:error] [pid 503470:tid 503655] [client 20.48.251.3:7402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/css.php"] [unique_id "apPk1D8EKFABaii6jtMNsAAAALw"]
[Sun Aug 30 03:07:48.296588 2026] [security2:error] [pid 503470:tid 503683] [client 20.104.50.220:62006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-incleude.php"] [unique_id "apPk1D8EKFABaii6jtMNvwAAANg"]
[Sun Aug 30 03:07:48.320181 2026] [security2:error] [pid 503470:tid 503677] [client 20.48.250.41:60749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/Geforce.php"] [unique_id "apPk1D8EKFABaii6jtMNzQAAANI"]
[Sun Aug 30 03:07:48.326204 2026] [security2:error] [pid 503470:tid 503624] [client 40.83.93.50:7930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/css.php"] [unique_id "apPk1D8EKFABaii6jtMN0AAAAJ0"]
[Sun Aug 30 03:07:48.357077 2026] [security2:error] [pid 503470:tid 503603] [client 114.119.150.86:28331] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "duckobxphotographer.com"] [uri "/r062vei/c7d5bd-sweet-adjeley-goat-soup"] [unique_id "apPk1D8EKFABaii6jtMN8wAAAIg"], referer: https://duckobxphotographer.com/r062vei/c7d5bd-a-friend-in-need-is-a-friend-indeed-adjective-phrase
[Sun Aug 30 03:07:48.389238 2026] [security2:error] [pid 503470:tid 503680] [client 20.220.10.235:29151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/ft.php"] [unique_id "apPk1D8EKFABaii6jtMOCQAAANU"]
[Sun Aug 30 03:07:48.431748 2026] [security2:error] [pid 503470:tid 503680] [client 158.23.147.79:62272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/.well-known/content.php"] [unique_id "apPk1D8EKFABaii6jtMONQAAANU"]
[Sun Aug 30 03:07:48.443196 2026] [security2:error] [pid 503470:tid 503626] [client 52.139.37.240:52186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/storage/index.php"] [unique_id "apPk1D8EKFABaii6jtMOOwAAAJ8"]
[Sun Aug 30 03:07:48.448035 2026] [security2:error] [pid 503470:tid 503677] [client 158.23.184.117:2358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willysmart.com"] [uri "/wp-act.php"] [unique_id "apPk1D8EKFABaii6jtMOPQAAANI"]
[Sun Aug 30 03:07:48.451221 2026] [security2:error] [pid 503470:tid 503651] [client 20.104.50.220:27561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/g3.php"] [unique_id "apPk1D8EKFABaii6jtMOPgAAALg"]
[Sun Aug 30 03:07:48.457879 2026] [security2:error] [pid 503470:tid 503688] [client 20.104.18.15:35467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPk1D8EKFABaii6jtMOQQAAAN0"]
[Sun Aug 30 03:07:48.487413 2026] [security2:error] [pid 503470:tid 503632] [client 20.48.250.41:62495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/click.php"] [unique_id "apPk1D8EKFABaii6jtMOXwAAAKU"]
[Sun Aug 30 03:07:48.496488 2026] [authz_core:error] [pid 499145:tid 499387] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:48.496948 2026] [authz_core:error] [pid 499145:tid 499387] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:48.499400 2026] [authz_core:error] [pid 499145:tid 499392] [client 66.249.66.77:54346] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:48.499690 2026] [authz_core:error] [pid 499145:tid 499392] [client 66.249.66.77:54346] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:48.512661 2026] [security2:error] [pid 499145:tid 499394] [client 68.155.159.216:65427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/.well-knownold/index.php"] [unique_id "apPk1FJNq1G5uRhTNnuTvQAAAHc"]
[Sun Aug 30 03:07:48.524742 2026] [security2:error] [pid 503470:tid 503665] [client 20.220.10.235:28760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/wp-ver.php"] [unique_id "apPk1D8EKFABaii6jtMOewAAAMY"]
[Sun Aug 30 03:07:48.561228 2026] [security2:error] [pid 503470:tid 503726] [client 20.104.49.130:36768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPk1D8EKFABaii6jtMOlAAAAQM"]
[Sun Aug 30 03:07:48.573853 2026] [security2:error] [pid 503470:tid 503608] [client 4.205.62.107:62083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/adminfus.php"] [unique_id "apPk1D8EKFABaii6jtMOmgAAAI0"]
[Sun Aug 30 03:07:48.587685 2026] [security2:error] [pid 503470:tid 503681] [client 20.104.50.220:5511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/50.php"] [unique_id "apPk1D8EKFABaii6jtMOpgAAANY"]
[Sun Aug 30 03:07:48.589430 2026] [authz_core:error] [pid 503470:tid 503709] [client 66.249.66.198:65216] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:48.589717 2026] [authz_core:error] [pid 503470:tid 503709] [client 66.249.66.198:65216] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:48.592715 2026] [security2:error] [pid 503470:tid 503607] [client 20.48.250.41:18381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPk1D8EKFABaii6jtMOqQAAAIw"]
[Sun Aug 30 03:07:48.608316 2026] [security2:error] [pid 503470:tid 503640] [client 36.255.97.72:54319] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "198.57.247.130"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPk1D8EKFABaii6jtMOtgAAAK0"]
[Sun Aug 30 03:07:48.613267 2026] [authz_core:error] [pid 503470:tid 503679] [client 74.7.227.8:38186] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:48.613540 2026] [authz_core:error] [pid 503470:tid 503679] [client 74.7.227.8:38186] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:48.631856 2026] [security2:error] [pid 499145:tid 499314] [client 20.104.49.130:64103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/samll.php"] [unique_id "apPk1FJNq1G5uRhTNnuT5wAAACc"]
[Sun Aug 30 03:07:48.632263 2026] [security2:error] [pid 503470:tid 503684] [client 20.197.61.180:7956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/an.php"] [unique_id "apPk1D8EKFABaii6jtMOugAAANk"]
[Sun Aug 30 03:07:48.634223 2026] [security2:error] [pid 503470:tid 503668] [client 52.139.37.240:32128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPk1D8EKFABaii6jtMOuwAAAMk"]
[Sun Aug 30 03:07:48.637198 2026] [security2:error] [pid 499145:tid 499310] [client 20.48.250.41:60788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/ms.php"] [unique_id "apPk1FJNq1G5uRhTNnuT6gAAACM"]
[Sun Aug 30 03:07:48.669972 2026] [security2:error] [pid 503470:tid 503624] [client 20.104.50.220:63040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-includes/wp_wrong_datlib.php"] [unique_id "apPk1D8EKFABaii6jtMOygAAAJ0"]
[Sun Aug 30 03:07:48.671151 2026] [security2:error] [pid 503470:tid 503689] [client 20.104.18.15:28502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/sonic.php"] [unique_id "apPk1D8EKFABaii6jtMOzAAAAN4"]
[Sun Aug 30 03:07:48.674630 2026] [security2:error] [pid 503470:tid 503649] [client 20.220.10.235:28798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/ah24.php"] [unique_id "apPk1D8EKFABaii6jtMOzwAAALY"]
[Sun Aug 30 03:07:48.680340 2026] [security2:error] [pid 503470:tid 503697] [client 20.48.251.3:13405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/wp-konfig.php"] [unique_id "apPk1D8EKFABaii6jtMO0wAAAOY"]
[Sun Aug 30 03:07:48.683285 2026] [authz_core:error] [pid 499145:tid 499348] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:48.683792 2026] [authz_core:error] [pid 499145:tid 499348] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:48.712007 2026] [authz_core:error] [pid 499145:tid 499357] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AG
[Sun Aug 30 03:07:48.712273 2026] [authz_core:error] [pid 499145:tid 499357] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AG
[Sun Aug 30 03:07:48.722812 2026] [security2:error] [pid 503470:tid 503715] [client 20.104.50.220:47063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/file88.php"] [unique_id "apPk1D8EKFABaii6jtMO-wAAAPg"]
[Sun Aug 30 03:07:48.723914 2026] [security2:error] [pid 503470:tid 503666] [client 20.104.50.220:62834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/high.php"] [unique_id "apPk1D8EKFABaii6jtMO_wAAAMc"]
[Sun Aug 30 03:07:48.733077 2026] [security2:error] [pid 503470:tid 503688] [client 20.104.50.220:16763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/geforce.php"] [unique_id "apPk1D8EKFABaii6jtMPCgAAAN0"]
[Sun Aug 30 03:07:48.746390 2026] [security2:error] [pid 503470:tid 503606] [client 20.151.200.44:55626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/admin.php/pindex.php"] [unique_id "apPk1D8EKFABaii6jtMPIwAAAIs"]
[Sun Aug 30 03:07:48.750834 2026] [security2:error] [pid 503470:tid 503695] [client 20.48.250.41:18377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPk1D8EKFABaii6jtMPJAAAAOQ"]
[Sun Aug 30 03:07:48.751452 2026] [security2:error] [pid 503470:tid 503673] [client 158.23.147.79:63906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/cong.php"] [unique_id "apPk1D8EKFABaii6jtMPJQAAAM4"]
[Sun Aug 30 03:07:48.757305 2026] [security2:error] [pid 503470:tid 503660] [client 20.104.18.15:23483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/wp.php"] [unique_id "apPk1D8EKFABaii6jtMPKAAAAME"]
[Sun Aug 30 03:07:48.769271 2026] [security2:error] [pid 503470:tid 503620] [client 20.48.250.41:62497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/zxekqlxb.php"] [unique_id "apPk1D8EKFABaii6jtMPLwAAAJk"]
[Sun Aug 30 03:07:48.772971 2026] [security2:error] [pid 503470:tid 503686] [client 20.104.104.62:57019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/admin.php/heex.php"] [unique_id "apPk1D8EKFABaii6jtMPMQAAANs"]
[Sun Aug 30 03:07:48.775797 2026] [security2:error] [pid 503470:tid 503724] [client 20.104.18.15:34688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/codex.php"] [unique_id "apPk1D8EKFABaii6jtMPMgAAAQE"]
[Sun Aug 30 03:07:48.783145 2026] [security2:error] [pid 503470:tid 503676] [client 4.205.62.107:61735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/sadd.php"] [unique_id "apPk1D8EKFABaii6jtMPOgAAANE"]
[Sun Aug 30 03:07:48.801094 2026] [security2:error] [pid 503470:tid 503672] [client 178.16.55.109:49899] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "onestoptestshop.com"] [uri "/index.php"] [unique_id "apPk1D8EKFABaii6jtMPQQAAAM0"]
[Sun Aug 30 03:07:48.806231 2026] [security2:error] [pid 503470:tid 503668] [client 20.48.251.3:50040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/cache-compat.php"] [unique_id "apPk1D8EKFABaii6jtMPRgAAAMk"]
[Sun Aug 30 03:07:48.815562 2026] [security2:error] [pid 503470:tid 503693] [client 20.104.18.15:18394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/m.php"] [unique_id "apPk1D8EKFABaii6jtMPSgAAAOI"]
[Sun Aug 30 03:07:48.826533 2026] [security2:error] [pid 503470:tid 503604] [client 40.83.93.50:19424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/autoload_classmap.php"] [unique_id "apPk1D8EKFABaii6jtMPWgAAAIk"]
[Sun Aug 30 03:07:48.826726 2026] [security2:error] [pid 503470:tid 503638] [client 52.139.37.240:52182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/wp-blog.php"] [unique_id "apPk1D8EKFABaii6jtMPWwAAAKs"]
[Sun Aug 30 03:07:48.845267 2026] [security2:error] [pid 503470:tid 503686] [client 68.155.159.216:12382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apPk1D8EKFABaii6jtMPaAAAANs"]
[Sun Aug 30 03:07:48.851229 2026] [security2:error] [pid 503470:tid 503674] [client 20.220.10.235:29107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPk1D8EKFABaii6jtMPbwAAAM8"]
[Sun Aug 30 03:07:48.858731 2026] [security2:error] [pid 503470:tid 503663] [client 4.205.62.107:36697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/xqq.php"] [unique_id "apPk1D8EKFABaii6jtMPdwAAAMQ"]
[Sun Aug 30 03:07:48.880793 2026] [security2:error] [pid 503470:tid 503643] [client 20.48.250.41:18376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/ff1.php"] [unique_id "apPk1D8EKFABaii6jtMPgAAAALA"]
[Sun Aug 30 03:07:48.881394 2026] [security2:error] [pid 503470:tid 503631] [client 158.23.147.79:63934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-includes/js/index.php"] [unique_id "apPk1D8EKFABaii6jtMPgQAAAKQ"]
[Sun Aug 30 03:07:48.902271 2026] [security2:error] [pid 503470:tid 503617] [client 20.104.18.15:51674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/run.php"] [unique_id "apPk1D8EKFABaii6jtMPjAAAAJY"]
[Sun Aug 30 03:07:48.908817 2026] [security2:error] [pid 503470:tid 503709] [client 20.104.104.62:55839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/tf.php"] [unique_id "apPk1D8EKFABaii6jtMPkQAAAPI"]
[Sun Aug 30 03:07:48.910241 2026] [security2:error] [pid 503470:tid 503603] [client 20.48.250.41:62505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/init.php"] [unique_id "apPk1D8EKFABaii6jtMPkgAAAIg"]
[Sun Aug 30 03:07:48.940343 2026] [authz_core:error] [pid 503470:tid 503618] [client 66.249.66.32:35956] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:48.940635 2026] [authz_core:error] [pid 503470:tid 503618] [client 66.249.66.32:35956] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:48.986540 2026] [security2:error] [pid 503470:tid 503673] [client 4.205.62.107:32019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/bb.php"] [unique_id "apPk1D8EKFABaii6jtMPxwAAAM4"]
[Sun Aug 30 03:07:48.993930 2026] [security2:error] [pid 503470:tid 503619] [client 20.220.10.235:28773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shellmediagroup.mikeshell.com"] [uri "/waf.php"] [unique_id "apPk1D8EKFABaii6jtMPygAAAJg"]
[Sun Aug 30 03:07:48.997994 2026] [security2:error] [pid 503470:tid 503682] [client 158.23.147.79:63954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-content/index.php"] [unique_id "apPk1D8EKFABaii6jtMPzQAAANc"]
[Sun Aug 30 03:07:48.999403 2026] [security2:error] [pid 503470:tid 503724] [client 20.104.18.15:29676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/8.php"] [unique_id "apPk1D8EKFABaii6jtMPzwAAAQE"]
[Sun Aug 30 03:07:49.004426 2026] [security2:error] [pid 503470:tid 503684] [client 4.205.62.107:54402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/snq.php"] [unique_id "apPk1T8EKFABaii6jtMP0wAAANk"]
[Sun Aug 30 03:07:49.042791 2026] [security2:error] [pid 503470:tid 503659] [client 20.104.50.220:32890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/oke.php"] [unique_id "apPk1T8EKFABaii6jtMP9wAAAMA"]
[Sun Aug 30 03:07:49.050283 2026] [security2:error] [pid 503470:tid 503606] [client 20.104.104.62:55828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/update/da222.php"] [unique_id "apPk1T8EKFABaii6jtMQCAAAAIs"]
[Sun Aug 30 03:07:49.053323 2026] [security2:error] [pid 503470:tid 503624] [client 20.48.250.41:18428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/t.php"] [unique_id "apPk1T8EKFABaii6jtMQDQAAAJ0"]
[Sun Aug 30 03:07:49.055044 2026] [security2:error] [pid 503470:tid 503681] [client 52.139.37.240:31851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/xmlrpc.php"] [unique_id "apPk1T8EKFABaii6jtMP4AAAANY"]
[Sun Aug 30 03:07:49.082636 2026] [security2:error] [pid 503470:tid 503639] [client 20.104.50.220:31838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-mails.php"] [unique_id "apPk1T8EKFABaii6jtMQIwAAAKw"]
[Sun Aug 30 03:07:49.087360 2026] [security2:error] [pid 503470:tid 503699] [client 20.48.250.41:62518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/term.php"] [unique_id "apPk1T8EKFABaii6jtMQJQAAAOg"]
[Sun Aug 30 03:07:49.107761 2026] [security2:error] [pid 503470:tid 503716] [client 158.23.147.79:63873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/about/function.php"] [unique_id "apPk1T8EKFABaii6jtMQLgAAAPk"]
[Sun Aug 30 03:07:49.117441 2026] [security2:error] [pid 503470:tid 503617] [client 20.48.251.3:4709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/asdf.php"] [unique_id "apPk1T8EKFABaii6jtMQMgAAAJY"]
[Sun Aug 30 03:07:49.131829 2026] [authz_core:error] [pid 499145:tid 499344] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:49.132171 2026] [authz_core:error] [pid 499145:tid 499344] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:49.194550 2026] [security2:error] [pid 503470:tid 503682] [client 20.104.104.62:55852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/qi.php"] [unique_id "apPk1T8EKFABaii6jtMQfAAAANc"]
[Sun Aug 30 03:07:49.199771 2026] [security2:error] [pid 503470:tid 503600] [client 20.48.250.41:18304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/erty.php"] [unique_id "apPk1T8EKFABaii6jtMQhgAAAIU"]
[Sun Aug 30 03:07:49.212158 2026] [authz_core:error] [pid 499145:tid 499292] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IN
[Sun Aug 30 03:07:49.212501 2026] [authz_core:error] [pid 499145:tid 499292] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IN
[Sun Aug 30 03:07:49.215241 2026] [security2:error] [pid 503470:tid 503609] [client 158.23.147.79:63879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-includes/customize/index.php"] [unique_id "apPk1T8EKFABaii6jtMQkwAAAI4"]
[Sun Aug 30 03:07:49.225398 2026] [security2:error] [pid 503470:tid 503692] [client 68.155.159.216:11247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apPk1T8EKFABaii6jtMQmgAAAOE"]
[Sun Aug 30 03:07:49.252123 2026] [security2:error] [pid 503470:tid 503656] [client 52.139.37.240:31822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/lu4.php"] [unique_id "apPk1T8EKFABaii6jtMQrwAAAL0"]
[Sun Aug 30 03:07:49.263574 2026] [security2:error] [pid 503470:tid 503713] [client 68.155.159.216:61402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/lock.php"] [unique_id "apPk1T8EKFABaii6jtMQuAAAAPY"]
[Sun Aug 30 03:07:49.289095 2026] [security2:error] [pid 503470:tid 503659] [client 20.48.250.41:59369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/aaa.php"] [unique_id "apPk1T8EKFABaii6jtMQyQAAAMA"]
[Sun Aug 30 03:07:49.294670 2026] [security2:error] [pid 503470:tid 503726] [client 40.83.93.50:19418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/info.php"] [unique_id "apPk1T8EKFABaii6jtMQzAAAAQM"]
[Sun Aug 30 03:07:49.334757 2026] [security2:error] [pid 503470:tid 503681] [client 158.23.147.79:63998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-admin/index.php"] [unique_id "apPk1T8EKFABaii6jtMQ5wAAANY"]
[Sun Aug 30 03:07:49.342905 2026] [security2:error] [pid 503470:tid 503648] [client 20.104.104.62:46659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/px.php"] [unique_id "apPk1T8EKFABaii6jtMQ8AAAALU"]
[Sun Aug 30 03:07:49.347986 2026] [security2:error] [pid 503470:tid 503683] [client 20.104.50.220:51545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/funtion.php"] [unique_id "apPk1T8EKFABaii6jtMQ-wAAANg"]
[Sun Aug 30 03:07:49.363577 2026] [security2:error] [pid 503470:tid 503727] [client 4.205.62.107:18650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/pass4.php"] [unique_id "apPk1T8EKFABaii6jtMRCgAAAQQ"]
[Sun Aug 30 03:07:49.364016 2026] [security2:error] [pid 503470:tid 503704] [client 20.197.61.180:9346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/mini.php"] [unique_id "apPk1T8EKFABaii6jtMRCwAAAO0"]
[Sun Aug 30 03:07:49.371154 2026] [security2:error] [pid 503470:tid 503722] [client 68.155.159.216:54248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apPk1T8EKFABaii6jtMREQAAAP8"]
[Sun Aug 30 03:07:49.423873 2026] [security2:error] [pid 503470:tid 503637] [client 20.48.250.41:18387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/0x.php"] [unique_id "apPk1T8EKFABaii6jtMRRQAAAKo"]
[Sun Aug 30 03:07:49.426199 2026] [security2:error] [pid 503470:tid 503668] [client 20.104.50.220:59581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/fpebr.php"] [unique_id "apPk1T8EKFABaii6jtMRRgAAAMk"]
[Sun Aug 30 03:07:49.447022 2026] [security2:error] [pid 503470:tid 503601] [client 52.139.37.240:32130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "apPk1T8EKFABaii6jtMRVQAAAIY"]
[Sun Aug 30 03:07:49.468272 2026] [security2:error] [pid 503470:tid 503644] [client 20.48.250.41:62498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/xsox.php"] [unique_id "apPk1T8EKFABaii6jtMRYgAAALE"]
[Sun Aug 30 03:07:49.492102 2026] [security2:error] [pid 503470:tid 503699] [client 20.104.104.62:55863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/is.php"] [unique_id "apPk1T8EKFABaii6jtMRfQAAAOg"]
[Sun Aug 30 03:07:49.546243 2026] [security2:error] [pid 503470:tid 503647] [client 68.155.159.216:62289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/images/index.php"] [unique_id "apPk1T8EKFABaii6jtMRpQAAALQ"]
[Sun Aug 30 03:07:49.547758 2026] [security2:error] [pid 503470:tid 503658] [client 158.23.147.79:62289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-content/themes/index.php"] [unique_id "apPk1T8EKFABaii6jtMRqAAAAL8"]
[Sun Aug 30 03:07:49.554312 2026] [security2:error] [pid 503470:tid 503608] [client 178.16.55.109:60971] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "onestoptestshop.com"] [uri "/index.php"] [unique_id "apPk1T8EKFABaii6jtMRrgAAAI0"]
[Sun Aug 30 03:07:49.557656 2026] [security2:error] [pid 503470:tid 503653] [client 20.48.250.41:18380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/66.php"] [unique_id "apPk1T8EKFABaii6jtMRsgAAALo"]
[Sun Aug 30 03:07:49.570724 2026] [security2:error] [pid 503470:tid 503697] [client 74.7.241.175:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "cpcontacts.pbg.lkt.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "apPk1T8EKFABaii6jtMRtQAAAOY"]
[Sun Aug 30 03:07:49.572849 2026] [security2:error] [pid 499145:tid 499395] [client 74.7.241.175:53392] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "cpcontacts.pbg.lkt.temporary.site"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "apPk1VJNq1G5uRhTNnuVKAAAeBE"]
[Sun Aug 30 03:07:49.589239 2026] [security2:error] [pid 503470:tid 503602] [client 20.104.50.220:27583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/Yamarket.php"] [unique_id "apPk1T8EKFABaii6jtMRxAAAAIc"]
[Sun Aug 30 03:07:49.596066 2026] [security2:error] [pid 503470:tid 503724] [client 20.48.251.3:64503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/php_info.php"] [unique_id "apPk1T8EKFABaii6jtMRygAAAQE"]
[Sun Aug 30 03:07:49.598856 2026] [security2:error] [pid 503470:tid 503642] [client 20.104.18.15:35466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPk1T8EKFABaii6jtMRzAAAAK8"]
[Sun Aug 30 03:07:49.605621 2026] [security2:error] [pid 503470:tid 503722] [client 34.125.55.247:32566] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.engaginggoddaily.com"] [uri "/backend/.aws/credentials"] [unique_id "apPk1T8EKFABaii6jtMR1gAAAP8"]
[Sun Aug 30 03:07:49.606664 2026] [security2:error] [pid 503470:tid 503644] [client 34.125.55.247:32552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.55.125.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.engaginggoddaily.com"] [uri "/config/aws.php"] [unique_id "apPk1T8EKFABaii6jtMR3AAAALE"]
[Sun Aug 30 03:07:49.608150 2026] [security2:error] [pid 503470:tid 503665] [client 34.125.55.247:32434] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.engaginggoddaily.com"] [uri "/.vscode/launch.json"] [unique_id "apPk1T8EKFABaii6jtMR4QAAAMY"]
[Sun Aug 30 03:07:49.608698 2026] [security2:error] [pid 503470:tid 503708] [client 34.125.55.247:32580] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.engaginggoddaily.com"] [uri "/config/aws.json"] [unique_id "apPk1T8EKFABaii6jtMR4gAAAPE"]
[Sun Aug 30 03:07:49.610287 2026] [proxy_http:error] [pid 503470:tid 503672] (20014)Internal error (specific information not available): [client 34.125.55.247:32428] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:49.610303 2026] [proxy:error] [pid 503470:tid 503672] [client 34.125.55.247:32428] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/dist/.vite/manifest.json
[Sun Aug 30 03:07:49.611851 2026] [security2:error] [pid 503470:tid 503723] [client 34.125.55.247:32592] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.engaginggoddaily.com"] [uri "/aws/.env"] [unique_id "apPk1T8EKFABaii6jtMR6wAAAQA"]
[Sun Aug 30 03:07:49.612968 2026] [security2:error] [pid 503470:tid 503607] [client 34.125.55.247:32618] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/.aws/credentials.old"] [unique_id "apPk1T8EKFABaii6jtMR6AAAAIw"]
[Sun Aug 30 03:07:49.613256 2026] [security2:error] [pid 503470:tid 503704] [client 34.125.55.247:32610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/.aws/credentials.bak"] [unique_id "apPk1T8EKFABaii6jtMR7AAAAO0"]
[Sun Aug 30 03:07:49.616459 2026] [security2:error] [pid 503470:tid 503718] [client 20.48.250.41:60768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/lkui.php"] [unique_id "apPk1T8EKFABaii6jtMR8gAAAPs"]
[Sun Aug 30 03:07:49.617775 2026] [proxy_http:error] [pid 503470:tid 503725] (20014)Internal error (specific information not available): [client 34.125.55.247:32450] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:49.617788 2026] [proxy:error] [pid 503470:tid 503725] [client 34.125.55.247:32450] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/api/v2/settings
[Sun Aug 30 03:07:49.620181 2026] [proxy_http:error] [pid 499145:tid 499346] (20014)Internal error (specific information not available): [client 34.125.55.247:32404] AH01102: error reading status line from remote server 127.0.0.1:2082, referer: https://cpanel.engaginggoddaily.com/build/manifest.json
[Sun Aug 30 03:07:49.624692 2026] [proxy_http:error] [pid 503470:tid 503703] (20014)Internal error (specific information not available): [client 34.125.55.247:32542] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:49.624709 2026] [proxy:error] [pid 503470:tid 503703] [client 34.125.55.247:32542] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/app/.aws/credentials
[Sun Aug 30 03:07:49.630618 2026] [security2:error] [pid 503470:tid 503668] [client 34.125.55.247:32446] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/api/v2/config"] [unique_id "apPk1T8EKFABaii6jtMR2wAAAMk"]
[Sun Aug 30 03:07:49.630770 2026] [proxy_http:error] [pid 503470:tid 503727] (20014)Internal error (specific information not available): [client 34.125.55.247:32444] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:49.630782 2026] [proxy:error] [pid 503470:tid 503727] [client 34.125.55.247:32444] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/dist/manifest.json
[Sun Aug 30 03:07:49.637416 2026] [proxy_http:error] [pid 503470:tid 503606] (20014)Internal error (specific information not available): [client 34.125.55.247:32464] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:49.637435 2026] [proxy:error] [pid 503470:tid 503606] [client 34.125.55.247:32464] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/telescope/requests
[Sun Aug 30 03:07:49.637760 2026] [security2:error] [pid 503470:tid 503681] [client 20.104.104.62:55849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/od.php"] [unique_id "apPk1T8EKFABaii6jtMR-AAAANY"]
[Sun Aug 30 03:07:49.640433 2026] [security2:error] [pid 503470:tid 503669] [client 52.139.37.240:32191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "apPk1T8EKFABaii6jtMR-gAAAMo"]
[Sun Aug 30 03:07:49.643637 2026] [security2:error] [pid 499145:tid 499332] [client 68.155.159.216:64798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apPk1VJNq1G5uRhTNnuVRAAAADk"]
[Sun Aug 30 03:07:49.645030 2026] [proxy_http:error] [pid 503470:tid 503706] (20014)Internal error (specific information not available): [client 34.125.55.247:32500] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:49.645046 2026] [proxy:error] [pid 503470:tid 503706] [client 34.125.55.247:32500] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/openapi.json
[Sun Aug 30 03:07:49.652197 2026] [proxy_http:error] [pid 503470:tid 503635] (20014)Internal error (specific information not available): [client 34.125.55.247:32368] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:49.652217 2026] [proxy:error] [pid 503470:tid 503635] [client 34.125.55.247:32368] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/credentials.js
[Sun Aug 30 03:07:49.658823 2026] [proxy_http:error] [pid 503470:tid 503619] (20014)Internal error (specific information not available): [client 34.125.55.247:32528] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:49.658843 2026] [proxy:error] [pid 503470:tid 503619] [client 34.125.55.247:32528] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.svn/entries
[Sun Aug 30 03:07:49.665854 2026] [proxy_http:error] [pid 503470:tid 503709] (20014)Internal error (specific information not available): [client 34.125.55.247:32448] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:49.665870 2026] [proxy:error] [pid 503470:tid 503709] [client 34.125.55.247:32448] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/values.yaml
[Sun Aug 30 03:07:49.681706 2026] [proxy_http:error] [pid 503470:tid 503633] (20014)Internal error (specific information not available): [client 34.125.55.247:32524] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:49.681728 2026] [proxy:error] [pid 503470:tid 503633] [client 34.125.55.247:32524] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/config/aws.yml
[Sun Aug 30 03:07:49.687486 2026] [security2:error] [pid 499145:tid 499290] [client 20.151.200.44:59542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/file66.php"] [unique_id "apPk1VJNq1G5uRhTNnuVTgAAAA8"]
[Sun Aug 30 03:07:49.688431 2026] [proxy_http:error] [pid 503470:tid 503721] (20014)Internal error (specific information not available): [client 34.125.55.247:32598] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:49.688454 2026] [proxy:error] [pid 503470:tid 503721] [client 34.125.55.247:32598] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/aws/.env.production
[Sun Aug 30 03:07:49.709322 2026] [authz_core:error] [pid 499145:tid 499378] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_HK
[Sun Aug 30 03:07:49.709755 2026] [authz_core:error] [pid 499145:tid 499378] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_HK
[Sun Aug 30 03:07:49.714102 2026] [security2:error] [pid 503470:tid 503668] [client 4.205.62.107:64001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/avim.php"] [unique_id "apPk1T8EKFABaii6jtMSGwAAAMk"]
[Sun Aug 30 03:07:49.714498 2026] [security2:error] [pid 503470:tid 503628] [client 158.23.147.79:63992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/about.php"] [unique_id "apPk1T8EKFABaii6jtMSHAAAAKE"]
[Sun Aug 30 03:07:49.716792 2026] [security2:error] [pid 503470:tid 503683] [client 20.48.250.41:18411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/f35.php"] [unique_id "apPk1T8EKFABaii6jtMSHwAAANg"]
[Sun Aug 30 03:07:49.717006 2026] [security2:error] [pid 503470:tid 503635] [client 34.125.55.247:32368] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "502"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/502.shtml"] [unique_id "apPk1T8EKFABaii6jtMR3wAAAKg"]
[Sun Aug 30 03:07:49.725657 2026] [security2:error] [pid 503470:tid 503684] [client 114.119.142.72:27981] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.duathlon.com"] [uri "/"] [unique_id "apPk1T8EKFABaii6jtMSLwAAANk"], referer: http://www.duathlon.com/
[Sun Aug 30 03:07:49.731335 2026] [security2:error] [pid 503470:tid 503650] [client 178.16.55.109:64503] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "neilgclark.com"] [uri "/index.php"] [unique_id "apPk1T8EKFABaii6jtMSOQAAALc"]
[Sun Aug 30 03:07:49.740577 2026] [security2:error] [pid 503470:tid 503673] [client 20.104.50.220:5556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/49.php"] [unique_id "apPk1T8EKFABaii6jtMSQwAAAM4"]
[Sun Aug 30 03:07:49.763237 2026] [security2:error] [pid 503470:tid 503722] [client 40.83.93.50:8103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/b.php"] [unique_id "apPk1T8EKFABaii6jtMSUwAAAP8"]
[Sun Aug 30 03:07:49.772267 2026] [security2:error] [pid 503470:tid 503716] [client 20.104.104.62:55870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/wp-the.php"] [unique_id "apPk1T8EKFABaii6jtMSWQAAAPk"]
[Sun Aug 30 03:07:49.803539 2026] [security2:error] [pid 503470:tid 503631] [client 20.48.250.41:60712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apPk1T8EKFABaii6jtMSbQAAAKQ"]
[Sun Aug 30 03:07:49.812040 2026] [security2:error] [pid 503470:tid 503660] [client 20.104.18.15:28626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/pop.php"] [unique_id "apPk1T8EKFABaii6jtMSdQAAAME"]
[Sun Aug 30 03:07:49.817903 2026] [security2:error] [pid 503470:tid 503668] [client 20.48.251.3:56337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/25.php"] [unique_id "apPk1T8EKFABaii6jtMSeQAAAMk"]
[Sun Aug 30 03:07:49.834046 2026] [security2:error] [pid 503470:tid 503605] [client 52.139.37.240:52216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "apPk1T8EKFABaii6jtMSgAAAAIo"]
[Sun Aug 30 03:07:49.841838 2026] [security2:error] [pid 503470:tid 503694] [client 20.104.49.130:36749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPk1T8EKFABaii6jtMShgAAAOM"]
[Sun Aug 30 03:07:49.844389 2026] [security2:error] [pid 503470:tid 503652] [client 20.48.250.41:18319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/wen.php"] [unique_id "apPk1T8EKFABaii6jtMSiAAAALk"]
[Sun Aug 30 03:07:49.853022 2026] [security2:error] [pid 499145:tid 499282] [client 216.73.216.128:47617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPk1VJNq1G5uRhTNnuVmgAAAAc"]
[Sun Aug 30 03:07:49.854312 2026] [authz_core:error] [pid 503470:tid 503686] [client 66.249.66.64:58674] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:49.854566 2026] [authz_core:error] [pid 503470:tid 503686] [client 66.249.66.64:58674] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:49.856488 2026] [security2:error] [pid 503470:tid 503656] [client 20.104.50.220:16711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/pucci.php"] [unique_id "apPk1T8EKFABaii6jtMSlAAAAL0"]
[Sun Aug 30 03:07:49.857053 2026] [security2:error] [pid 503470:tid 503653] [client 20.104.50.220:62792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-admin/wp_wrong_datlib.php"] [unique_id "apPk1T8EKFABaii6jtMSlQAAALo"]
[Sun Aug 30 03:07:49.860907 2026] [security2:error] [pid 499145:tid 499346] [client 20.104.50.220:46627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/gifclass4.php"] [unique_id "apPk1VJNq1G5uRhTNnuVmwAAAEc"]
[Sun Aug 30 03:07:49.896429 2026] [security2:error] [pid 503470:tid 503608] [client 20.104.18.15:23431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/abcd.php"] [unique_id "apPk1T8EKFABaii6jtMSpQAAAI0"]
[Sun Aug 30 03:07:49.904097 2026] [security2:error] [pid 499145:tid 499277] [client 20.104.104.62:55816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/wt.php"] [unique_id "apPk1VJNq1G5uRhTNnuVqgAAAAI"]
[Sun Aug 30 03:07:49.922384 2026] [security2:error] [pid 503470:tid 503667] [client 4.205.62.107:64695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/application.config.php"] [unique_id "apPk1T8EKFABaii6jtMStAAAAMg"]
[Sun Aug 30 03:07:49.926071 2026] [security2:error] [pid 503470:tid 503694] [client 20.104.50.220:29315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/hehee.php"] [unique_id "apPk1T8EKFABaii6jtMStgAAAOM"]
[Sun Aug 30 03:07:49.938286 2026] [security2:error] [pid 503470:tid 503690] [client 20.104.18.15:34693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/5656.php"] [unique_id "apPk1T8EKFABaii6jtMSuAAAAN8"]
[Sun Aug 30 03:07:49.944313 2026] [security2:error] [pid 503470:tid 503713] [client 158.23.147.79:63940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apPk1T8EKFABaii6jtMSuwAAAPY"]
[Sun Aug 30 03:07:49.950602 2026] [authz_core:error] [pid 499145:tid 499380] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:49.950887 2026] [authz_core:error] [pid 499145:tid 499380] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:49.950929 2026] [security2:error] [pid 503470:tid 503678] [client 20.48.251.3:12064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/aws_keys.php"] [unique_id "apPk1T8EKFABaii6jtMSwQAAANM"]
[Sun Aug 30 03:07:49.950965 2026] [security2:error] [pid 503470:tid 503699] [client 20.48.250.41:60679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/motu.php"] [unique_id "apPk1T8EKFABaii6jtMSwAAAAOg"]
[Sun Aug 30 03:07:49.983155 2026] [security2:error] [pid 503470:tid 503685] [client 20.104.18.15:18426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/fling.php"] [unique_id "apPk1T8EKFABaii6jtMS3wAAANo"]
[Sun Aug 30 03:07:49.985638 2026] [security2:error] [pid 499145:tid 499387] [client 68.155.159.216:12435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apPk1VJNq1G5uRhTNnuVzQAAAHA"]
[Sun Aug 30 03:07:50.009754 2026] [security2:error] [pid 503470:tid 503722] [client 4.205.62.107:36648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/a1vx.php"] [unique_id "apPk1j8EKFABaii6jtMS7gAAAP8"]
[Sun Aug 30 03:07:50.028937 2026] [security2:error] [pid 503470:tid 503617] [client 20.48.250.41:18426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/inc.php"] [unique_id "apPk1j8EKFABaii6jtMS_gAAAJY"]
[Sun Aug 30 03:07:50.032333 2026] [security2:error] [pid 503470:tid 503673] [client 52.139.37.240:52208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/ant.php"] [unique_id "apPk1j8EKFABaii6jtMTAAAAAM4"]
[Sun Aug 30 03:07:50.037062 2026] [security2:error] [pid 499145:tid 499324] [client 20.104.18.15:51684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/new.php"] [unique_id "apPk1lJNq1G5uRhTNnuV4gAAADE"]
[Sun Aug 30 03:07:50.048069 2026] [security2:error] [pid 503470:tid 503618] [client 20.104.104.62:46676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/im.php"] [unique_id "apPk1j8EKFABaii6jtMTCgAAAJc"]
[Sun Aug 30 03:07:50.084826 2026] [authz_core:error] [pid 503470:tid 503667] [client 74.7.227.8:38186] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:50.085296 2026] [authz_core:error] [pid 503470:tid 503667] [client 74.7.227.8:38186] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:50.091941 2026] [security2:error] [pid 503470:tid 503636] [client 216.244.66.238:48894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arcaneguardians.com"] [uri "/caayjc/juicy-blueberry-cobbler"] [unique_id "apPk1j8EKFABaii6jtMTIgAAAKk"]
[Sun Aug 30 03:07:50.092032 2026] [security2:error] [pid 503470:tid 503636] [client 216.244.66.238:48894] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "arcaneguardians.com"] [uri "/caayjc/juicy-blueberry-cobbler"] [unique_id "apPk1j8EKFABaii6jtMTIgAAAKk"]
[Sun Aug 30 03:07:50.098205 2026] [security2:error] [pid 503470:tid 503639] [client 20.48.250.41:62581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/Ov-Simple1.php"] [unique_id "apPk1j8EKFABaii6jtMTJgAAAKw"]
[Sun Aug 30 03:07:50.113408 2026] [security2:error] [pid 503470:tid 503604] [client 185.191.171.17:33532] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arcaneguardians.com"] [uri "/caayjc/gold-beach-salmon-derby-2022"] [unique_id "apPk1j8EKFABaii6jtMTMQAAAIk"]
[Sun Aug 30 03:07:50.113498 2026] [security2:error] [pid 503470:tid 503604] [client 185.191.171.17:33532] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "arcaneguardians.com"] [uri "/caayjc/gold-beach-salmon-derby-2022"] [unique_id "apPk1j8EKFABaii6jtMTMQAAAIk"]
[Sun Aug 30 03:07:50.117397 2026] [authz_core:error] [pid 499145:tid 499283] [client 66.249.66.37:45123] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:50.117657 2026] [authz_core:error] [pid 499145:tid 499283] [client 66.249.66.37:45123] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:50.132549 2026] [authz_core:error] [pid 499145:tid 499348] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:50.132945 2026] [authz_core:error] [pid 499145:tid 499348] [client 216.73.216.128:2786] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:50.153089 2026] [security2:error] [pid 503470:tid 503627] [client 20.104.18.15:29635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/ws55.php"] [unique_id "apPk1j8EKFABaii6jtMTUAAAAKA"]
[Sun Aug 30 03:07:50.185300 2026] [security2:error] [pid 503470:tid 503707] [client 158.23.147.79:63907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/themes.php"] [unique_id "apPk1j8EKFABaii6jtMTeAAAAPA"]
[Sun Aug 30 03:07:50.196023 2026] [security2:error] [pid 503470:tid 503653] [client 20.48.250.41:18424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/6bcwiqwj.php"] [unique_id "apPk1j8EKFABaii6jtMTggAAALo"]
[Sun Aug 30 03:07:50.197549 2026] [security2:error] [pid 503470:tid 503636] [client 20.104.104.62:55848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/file.php"] [unique_id "apPk1j8EKFABaii6jtMTgwAAAKk"]
[Sun Aug 30 03:07:50.200795 2026] [authz_core:error] [pid 499145:tid 499297] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_HK
[Sun Aug 30 03:07:50.201305 2026] [authz_core:error] [pid 499145:tid 499297] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_HK
[Sun Aug 30 03:07:50.204092 2026] [security2:error] [pid 503470:tid 503601] [client 20.104.50.220:33564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/MKY.php"] [unique_id "apPk1j8EKFABaii6jtMTigAAAIY"]
[Sun Aug 30 03:07:50.216254 2026] [security2:error] [pid 503470:tid 503669] [client 4.205.62.107:22529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/wp-access.php"] [unique_id "apPk1j8EKFABaii6jtMTkAAAAMo"]
[Sun Aug 30 03:07:50.224945 2026] [security2:error] [pid 503470:tid 503678] [client 52.139.37.240:31831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/autoload_classmap.php"] [unique_id "apPk1j8EKFABaii6jtMTlAAAANM"]
[Sun Aug 30 03:07:50.228789 2026] [security2:error] [pid 503470:tid 503711] [client 20.48.250.41:62575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/wp-blogs.php"] [unique_id "apPk1j8EKFABaii6jtMTmgAAAPQ"]
[Sun Aug 30 03:07:50.233266 2026] [security2:error] [pid 503470:tid 503702] [client 20.104.50.220:32523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-one.php"] [unique_id "apPk1j8EKFABaii6jtMTnwAAAOs"]
[Sun Aug 30 03:07:50.254426 2026] [security2:error] [pid 503470:tid 503622] [client 20.197.61.180:9372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/robots.php"] [unique_id "apPk1j8EKFABaii6jtMTtQAAAJs"]
[Sun Aug 30 03:07:50.262795 2026] [security2:error] [pid 503470:tid 503693] [client 20.48.251.3:44339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apPk1j8EKFABaii6jtMTuwAAAOI"]
[Sun Aug 30 03:07:50.272488 2026] [security2:error] [pid 503470:tid 503672] [client 40.83.93.50:13559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/wp-login.php"] [unique_id "apPk1j8EKFABaii6jtMTrwAAAM0"]
[Sun Aug 30 03:07:50.287720 2026] [security2:error] [pid 503470:tid 503680] [client 178.16.55.109:62284] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "onestoptestshop.com"] [uri "/index.php"] [unique_id "apPk1j8EKFABaii6jtMTyQAAANU"]
[Sun Aug 30 03:07:50.321977 2026] [security2:error] [pid 503470:tid 503605] [client 158.23.147.79:63984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-mail.php"] [unique_id "apPk1j8EKFABaii6jtMT4AAAAIo"]
[Sun Aug 30 03:07:50.359149 2026] [security2:error] [pid 503470:tid 503610] [client 20.48.250.41:18375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/easy.php"] [unique_id "apPk1j8EKFABaii6jtMUAwAAAI8"]
[Sun Aug 30 03:07:50.376265 2026] [security2:error] [pid 499145:tid 499313] [client 20.104.104.62:56986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/ca.php"] [unique_id "apPk1lJNq1G5uRhTNnuWYQAAACY"]
[Sun Aug 30 03:07:50.407846 2026] [authz_core:error] [pid 503470:tid 503715] [client 216.73.216.128:63560] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:50.408281 2026] [authz_core:error] [pid 503470:tid 503715] [client 216.73.216.128:63560] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:50.416071 2026] [security2:error] [pid 503470:tid 503678] [client 52.139.37.240:31820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/storage/rip.php"] [unique_id "apPk1j8EKFABaii6jtMUOgAAANM"]
[Sun Aug 30 03:07:50.418251 2026] [security2:error] [pid 503470:tid 503707] [client 20.48.250.41:59331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/mini.php"] [unique_id "apPk1j8EKFABaii6jtMUPwAAAPA"]
[Sun Aug 30 03:07:50.465888 2026] [security2:error] [pid 503470:tid 503724] [client 20.151.200.44:55718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/admin.php/csv.php"] [unique_id "apPk1j8EKFABaii6jtMUXAAAAQE"]
[Sun Aug 30 03:07:50.478606 2026] [security2:error] [pid 503470:tid 503660] [client 158.23.147.79:63945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/cgi-bin/index.php"] [unique_id "apPk1j8EKFABaii6jtMUaAAAAME"]
[Sun Aug 30 03:07:50.502361 2026] [security2:error] [pid 503470:tid 503627] [client 4.205.62.107:17817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/cu.php"] [unique_id "apPk1j8EKFABaii6jtMUfwAAAKA"]
[Sun Aug 30 03:07:50.504475 2026] [security2:error] [pid 503470:tid 503674] [client 20.104.50.220:51632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/xixi.php"] [unique_id "apPk1j8EKFABaii6jtMUggAAAM8"]
[Sun Aug 30 03:07:50.515058 2026] [security2:error] [pid 503470:tid 503697] [client 20.104.49.130:63276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/ab.php"] [unique_id "apPk1j8EKFABaii6jtMUiAAAAOY"]
[Sun Aug 30 03:07:50.519064 2026] [security2:error] [pid 503470:tid 503655] [client 20.104.104.62:56972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/pb.php"] [unique_id "apPk1j8EKFABaii6jtMUigAAALw"]
[Sun Aug 30 03:07:50.543030 2026] [security2:error] [pid 503470:tid 503617] [client 20.48.250.41:18321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/fresh3.php"] [unique_id "apPk1j8EKFABaii6jtMUmAAAAJY"]
[Sun Aug 30 03:07:50.554090 2026] [security2:error] [pid 503470:tid 503657] [client 20.48.250.41:59375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/amp.php"] [unique_id "apPk1j8EKFABaii6jtMUngAAAL4"]
[Sun Aug 30 03:07:50.554979 2026] [security2:error] [pid 503470:tid 503634] [client 68.155.159.216:55105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apPk1j8EKFABaii6jtMUnwAAAKc"]
[Sun Aug 30 03:07:50.569881 2026] [security2:error] [pid 503470:tid 503702] [client 68.155.159.216:11209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/packed.php"] [unique_id "apPk1j8EKFABaii6jtMUqgAAAOs"]
[Sun Aug 30 03:07:50.577949 2026] [security2:error] [pid 503470:tid 503619] [client 158.23.147.79:63872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPk1j8EKFABaii6jtMUrwAAAJg"]
[Sun Aug 30 03:07:50.582429 2026] [security2:error] [pid 499145:tid 499398] [client 216.73.216.128:2786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/classes.html"] [unique_id "apPk1lJNq1G5uRhTNnuWuAAAAHs"]
[Sun Aug 30 03:07:50.590085 2026] [security2:error] [pid 503470:tid 503672] [client 20.104.50.220:63025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/snd21.php"] [unique_id "apPk1j8EKFABaii6jtMUuwAAAM0"]
[Sun Aug 30 03:07:50.615481 2026] [security2:error] [pid 503470:tid 503612] [client 52.139.37.240:31843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/tinyfilemanager.php"] [unique_id "apPk1j8EKFABaii6jtMUygAAAJE"]
[Sun Aug 30 03:07:50.673151 2026] [authz_core:error] [pid 499145:tid 499289] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NG
[Sun Aug 30 03:07:50.673459 2026] [authz_core:error] [pid 499145:tid 499289] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NG
[Sun Aug 30 03:07:50.679552 2026] [security2:error] [pid 503470:tid 503639] [client 20.104.104.62:55869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/pk.php"] [unique_id "apPk1j8EKFABaii6jtMU5gAAAKw"]
[Sun Aug 30 03:07:50.679966 2026] [authz_core:error] [pid 503470:tid 503602] [client 216.73.216.128:63560] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:50.680254 2026] [authz_core:error] [pid 503470:tid 503602] [client 216.73.216.128:63560] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:50.685052 2026] [security2:error] [pid 503470:tid 503697] [client 158.23.147.79:63929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-includes/content.php"] [unique_id "apPk1j8EKFABaii6jtMU6AAAAOY"]
[Sun Aug 30 03:07:50.687353 2026] [security2:error] [pid 503470:tid 503624] [client 20.48.250.41:18310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/bgymj.php"] [unique_id "apPk1j8EKFABaii6jtMU6gAAAJ0"]
[Sun Aug 30 03:07:50.706315 2026] [security2:error] [pid 503470:tid 503693] [client 68.155.159.216:63501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-includes/widgets/index.php"] [unique_id "apPk1j8EKFABaii6jtMU-AAAAOI"]
[Sun Aug 30 03:07:50.714567 2026] [security2:error] [pid 499145:tid 499330] [client 65.108.6.34:36340] ModSecurity: Warning. Matched phrase "SEOkicks" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "flashflooring.co.uk"] [uri "/index.php"] [unique_id "apPk1lJNq1G5uRhTNnuWEwAAADc"], referer: https://flashflooring.co.uk/
[Sun Aug 30 03:07:50.718775 2026] [security2:error] [pid 503470:tid 503678] [client 20.104.50.220:27103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/globales.php"] [unique_id "apPk1j8EKFABaii6jtMVBQAAANM"]
[Sun Aug 30 03:07:50.721305 2026] [security2:error] [pid 503470:tid 503634] [client 20.48.250.41:58446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/cc13.php"] [unique_id "apPk1j8EKFABaii6jtMVDQAAAKc"]
[Sun Aug 30 03:07:50.732329 2026] [security2:error] [pid 503470:tid 503611] [client 20.104.18.15:35154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/ap.php"] [unique_id "apPk1j8EKFABaii6jtMVHwAAAJA"]
[Sun Aug 30 03:07:50.764093 2026] [security2:error] [pid 499145:tid 499390] [client 68.155.159.216:61334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPk1lJNq1G5uRhTNnuW8gAAAHM"]
[Sun Aug 30 03:07:50.778308 2026] [security2:error] [pid 503470:tid 503622] [client 158.23.147.79:62294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-admin/css/index.php"] [unique_id "apPk1j8EKFABaii6jtMVNgAAAJs"]
[Sun Aug 30 03:07:50.794491 2026] [security2:error] [pid 503470:tid 503688] [client 195.178.110.247:59438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.matercell.com.ve"] [uri "/index.php"] [unique_id "apPk1j8EKFABaii6jtMVPgAAAN0"]
[Sun Aug 30 03:07:50.816729 2026] [security2:error] [pid 503470:tid 503637] [client 20.48.250.41:18322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/ws69.php"] [unique_id "apPk1j8EKFABaii6jtMVRwAAAKo"]
[Sun Aug 30 03:07:50.819556 2026] [security2:error] [pid 503470:tid 503680] [client 20.104.104.62:55857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/ft.php"] [unique_id "apPk1j8EKFABaii6jtMVSQAAANU"]
[Sun Aug 30 03:07:50.860030 2026] [security2:error] [pid 503470:tid 503607] [client 20.48.250.41:60799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/aa.php"] [unique_id "apPk1j8EKFABaii6jtMVbAAAAIw"]
[Sun Aug 30 03:07:50.860738 2026] [security2:error] [pid 503470:tid 503647] [client 4.205.62.107:39117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/nw.php"] [unique_id "apPk1j8EKFABaii6jtMVbQAAALQ"]
[Sun Aug 30 03:07:50.872276 2026] [security2:error] [pid 499145:tid 499298] [client 4.205.62.107:58365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/file59.php"] [unique_id "apPk1lJNq1G5uRhTNnuXFgAAABc"]
[Sun Aug 30 03:07:50.872963 2026] [security2:error] [pid 503470:tid 503610] [client 52.139.37.240:52219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/403.php"] [unique_id "apPk1j8EKFABaii6jtMVcgAAAI8"]
[Sun Aug 30 03:07:50.879154 2026] [security2:error] [pid 503470:tid 503635] [client 20.104.50.220:5452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/48.php"] [unique_id "apPk1j8EKFABaii6jtMVdAAAAKg"]
[Sun Aug 30 03:07:50.882218 2026] [security2:error] [pid 503470:tid 503629] [client 68.155.159.216:62052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/index/function.php"] [unique_id "apPk1j8EKFABaii6jtMVdgAAAKI"]
[Sun Aug 30 03:07:50.929247 2026] [security2:error] [pid 503470:tid 503654] [client 158.23.147.79:63894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-admin/images/index.php"] [unique_id "apPk1j8EKFABaii6jtMVigAAALs"]
[Sun Aug 30 03:07:50.952890 2026] [security2:error] [pid 503470:tid 503660] [client 20.104.104.62:57000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/wp-ver.php"] [unique_id "apPk1j8EKFABaii6jtMVlAAAAME"]
[Sun Aug 30 03:07:50.953224 2026] [security2:error] [pid 503470:tid 503652] [client 20.104.18.15:28589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/503.php"] [unique_id "apPk1j8EKFABaii6jtMVlQAAALk"]
[Sun Aug 30 03:07:50.956421 2026] [security2:error] [pid 503470:tid 503721] [client 195.178.110.247:37320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.matercell.com.ve"] [uri "/index.php"] [unique_id "apPk1j8EKFABaii6jtMVmwAAAP4"]
[Sun Aug 30 03:07:50.957095 2026] [security2:error] [pid 503470:tid 503623] [client 20.48.251.3:13958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/nlnub.php"] [unique_id "apPk1j8EKFABaii6jtMVnAAAAJw"]
[Sun Aug 30 03:07:50.960255 2026] [security2:error] [pid 503470:tid 503662] [client 20.48.250.41:18254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/ccs.php"] [unique_id "apPk1j8EKFABaii6jtMVnwAAAMM"]
[Sun Aug 30 03:07:50.966071 2026] [security2:error] [pid 503470:tid 503627] [client 40.83.93.50:7876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/aa.php"] [unique_id "apPk1j8EKFABaii6jtMVpwAAAKA"]
[Sun Aug 30 03:07:50.967658 2026] [security2:error] [pid 503470:tid 503606] [client 114.119.145.79:39805] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gracelikestogarden.com"] [uri "/how-to-get-rid-of-slugs"] [unique_id "apPk1j8EKFABaii6jtMVqQAAAIs"], referer: https://gracelikestogarden.com/blog/page/5
[Sun Aug 30 03:07:50.995086 2026] [security2:error] [pid 503470:tid 503686] [client 178.16.55.109:55922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "onestoptestshop.com"] [uri "/index.php"] [unique_id "apPk1j8EKFABaii6jtMVwAAAANs"]
[Sun Aug 30 03:07:50.995296 2026] [security2:error] [pid 503470:tid 503661] [client 20.197.61.180:9345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/goat.php"] [unique_id "apPk1j8EKFABaii6jtMVwQAAAMI"]
[Sun Aug 30 03:07:50.998468 2026] [security2:error] [pid 503470:tid 503619] [client 20.104.50.220:46175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/class19.php"] [unique_id "apPk1j8EKFABaii6jtMVxQAAAJg"]
[Sun Aug 30 03:07:51.011906 2026] [security2:error] [pid 503470:tid 503700] [client 20.48.250.41:62475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/s1.php"] [unique_id "apPk1z8EKFABaii6jtMVzgAAAOk"]
[Sun Aug 30 03:07:51.012487 2026] [security2:error] [pid 503470:tid 503643] [client 20.104.50.220:62827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-content/wp_wrong_datlib.php"] [unique_id "apPk1z8EKFABaii6jtMVzwAAALA"]
[Sun Aug 30 03:07:51.034605 2026] [security2:error] [pid 503470:tid 503615] [client 20.104.18.15:23368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/nofile.php"] [unique_id "apPk1z8EKFABaii6jtMV5wAAAJQ"]
[Sun Aug 30 03:07:51.060797 2026] [security2:error] [pid 499145:tid 499401] [client 4.205.62.107:64662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/xp.php"] [unique_id "apPk11JNq1G5uRhTNnuXUwAAAH4"]
[Sun Aug 30 03:07:51.075458 2026] [security2:error] [pid 503470:tid 503721] [client 20.104.50.220:63041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/human.php"] [unique_id "apPk1z8EKFABaii6jtMWAwAAAP4"]
[Sun Aug 30 03:07:51.078428 2026] [security2:error] [pid 503470:tid 503641] [client 52.139.37.240:31856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/av.php"] [unique_id "apPk1z8EKFABaii6jtMWBAAAAK4"]
[Sun Aug 30 03:07:51.082348 2026] [security2:error] [pid 503470:tid 503622] [client 20.104.18.15:34763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/w3lls.php"] [unique_id "apPk1z8EKFABaii6jtMWCQAAAJs"]
[Sun Aug 30 03:07:51.084591 2026] [security2:error] [pid 503470:tid 503707] [client 20.104.104.62:55854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/ah24.php"] [unique_id "apPk1z8EKFABaii6jtMWDAAAAPA"]
[Sun Aug 30 03:07:51.096944 2026] [security2:error] [pid 503470:tid 503660] [client 20.48.251.3:34489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/umgebung.php"] [unique_id "apPk1z8EKFABaii6jtMWFQAAAME"]
[Sun Aug 30 03:07:51.117334 2026] [security2:error] [pid 499145:tid 499365] [client 20.48.250.41:18391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/mar.php"] [unique_id "apPk11JNq1G5uRhTNnuXaAAAAFo"]
[Sun Aug 30 03:07:51.124320 2026] [security2:error] [pid 503470:tid 503631] [client 20.104.18.15:18378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/btyuio.php"] [unique_id "apPk1z8EKFABaii6jtMWIgAAAKQ"]
[Sun Aug 30 03:07:51.151236 2026] [security2:error] [pid 503470:tid 503651] [client 20.104.50.220:17323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-temp.php"] [unique_id "apPk1z8EKFABaii6jtMWNwAAALg"]
[Sun Aug 30 03:07:51.164105 2026] [security2:error] [pid 503470:tid 503629] [client 68.155.159.216:12329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/nf_tracking.php"] [unique_id "apPk1z8EKFABaii6jtMWRgAAAKI"]
[Sun Aug 30 03:07:51.170283 2026] [security2:error] [pid 503470:tid 503643] [client 158.23.147.79:63958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-includes/index.php"] [unique_id "apPk1z8EKFABaii6jtMWUAAAALA"]
[Sun Aug 30 03:07:51.170412 2026] [security2:error] [pid 503470:tid 503670] [client 4.205.62.107:36639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/public/vx.php"] [unique_id "apPk1z8EKFABaii6jtMWUQAAAMs"]
[Sun Aug 30 03:07:51.179148 2026] [security2:error] [pid 503470:tid 503611] [client 20.48.250.41:60706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/0byte.php"] [unique_id "apPk1z8EKFABaii6jtMWWwAAAJA"]
[Sun Aug 30 03:07:51.181223 2026] [security2:error] [pid 503470:tid 503699] [client 20.104.18.15:51662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/vpn.php"] [unique_id "apPk1z8EKFABaii6jtMWXgAAAOg"]
[Sun Aug 30 03:07:51.186546 2026] [authz_core:error] [pid 499145:tid 499334] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZM
[Sun Aug 30 03:07:51.187003 2026] [authz_core:error] [pid 499145:tid 499334] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZM
[Sun Aug 30 03:07:51.211733 2026] [security2:error] [pid 503470:tid 503626] [client 20.48.251.3:64506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/h.php"] [unique_id "apPk1z8EKFABaii6jtMWdQAAAJ8"]
[Sun Aug 30 03:07:51.220211 2026] [security2:error] [pid 503470:tid 503668] [client 20.104.104.62:56977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/wp-admin/zwso.php"] [unique_id "apPk1z8EKFABaii6jtMWfwAAAMk"]
[Sun Aug 30 03:07:51.275710 2026] [security2:error] [pid 503470:tid 503642] [client 52.139.37.240:52185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/wp-admin/index.php"] [unique_id "apPk1z8EKFABaii6jtMWnAAAAK8"]
[Sun Aug 30 03:07:51.275777 2026] [authz_core:error] [pid 503470:tid 503618] [client 66.249.66.43:54268] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:51.276215 2026] [authz_core:error] [pid 503470:tid 503618] [client 66.249.66.43:54268] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:51.527726 2026] [qos:error] [pid 499145:tid 499308] [client 149.28.251.187:53678] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=149.28.251.187, id=apPk11JNq1G5uRhTNnuX_gAAACE
[Sun Aug 30 03:07:51.527815 2026] [qos:error] [pid 499145:tid 499278] [client 176.119.25.107:45714] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=176.119.25.107, id=apPk11JNq1G5uRhTNnuX_wAAAAM
[Sun Aug 30 03:07:51.528915 2026] [qos:error] [pid 499145:tid 499381] [client 176.111.37.5:20980] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=176.111.37.5, id=apPk11JNq1G5uRhTNnuYAQAAAGo
[Sun Aug 30 03:07:51.529056 2026] [qos:error] [pid 499145:tid 499376] [client 103.35.171.194:36030] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.35.171.194, id=apPk11JNq1G5uRhTNnuYAAAAAGU
[Sun Aug 30 03:07:51.532979 2026] [qos:error] [pid 499145:tid 499355] [client 38.211.76.201:45588] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.211.76.201, id=apPk11JNq1G5uRhTNnuYAgAAAFA
[Sun Aug 30 03:07:51.535566 2026] [qos:error] [pid 499145:tid 499367] [client 117.2.104.13:55386] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=117.2.104.13, id=apPk11JNq1G5uRhTNnuYAwAAAFw
[Sun Aug 30 03:07:51.539384 2026] [qos:error] [pid 499145:tid 499334] [client 104.28.246.49:27357] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=104.28.246.49, id=apPk11JNq1G5uRhTNnuYBAAAADs
[Sun Aug 30 03:07:51.543984 2026] [qos:error] [pid 499145:tid 499383] [client 102.209.76.172:48334] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=102.209.76.172, id=apPk11JNq1G5uRhTNnuYBQAAAGw
[Sun Aug 30 03:07:51.546285 2026] [qos:error] [pid 499145:tid 499283] [client 23.129.64.160:10847] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=23.129.64.160, id=apPk11JNq1G5uRhTNnuYBgAAAAg
[Sun Aug 30 03:07:51.561241 2026] [qos:error] [pid 499145:tid 499335] [client 103.113.116.246:59015] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.113.116.246, id=apPk11JNq1G5uRhTNnuYBwAAADw
[Sun Aug 30 03:07:51.561441 2026] [qos:error] [pid 499145:tid 499366] [client 203.76.112.234:58104] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=203.76.112.234, id=apPk11JNq1G5uRhTNnuYCAAAAFs
[Sun Aug 30 03:07:51.561995 2026] [qos:error] [pid 499145:tid 499378] [client 176.111.37.216:49326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=176.111.37.216, id=apPk11JNq1G5uRhTNnuYCQAAAGc
[Sun Aug 30 03:07:51.563551 2026] [qos:error] [pid 499145:tid 499348] [client 103.147.118.66:33994] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.147.118.66, id=apPk11JNq1G5uRhTNnuYCgAAAEk
[Sun Aug 30 03:07:51.565254 2026] [qos:error] [pid 499145:tid 499308] [client 103.162.57.138:48914] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.162.57.138, id=apPk11JNq1G5uRhTNnuYCwAAACE
[Sun Aug 30 03:07:51.565674 2026] [qos:error] [pid 499145:tid 499278] [client 38.76.138.129:51791] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.76.138.129, id=apPk11JNq1G5uRhTNnuYDAAAAAM
[Sun Aug 30 03:07:51.574421 2026] [qos:error] [pid 499145:tid 499381] [client 103.81.195.190:40828] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.81.195.190, id=apPk11JNq1G5uRhTNnuYDQAAAGo
[Sun Aug 30 03:07:51.574890 2026] [qos:error] [pid 499145:tid 499376] [client 160.20.39.93:41217] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=160.20.39.93, id=apPk11JNq1G5uRhTNnuYDgAAAGU
[Sun Aug 30 03:07:51.575757 2026] [qos:error] [pid 499145:tid 499355] [client 219.148.171.178:4673] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=219.148.171.178, id=apPk11JNq1G5uRhTNnuYDwAAAFA
[Sun Aug 30 03:07:51.575918 2026] [qos:error] [pid 499145:tid 499367] [client 88.30.14.94:54568] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=88.30.14.94, id=apPk11JNq1G5uRhTNnuYEAAAAFw
[Sun Aug 30 03:07:51.579027 2026] [qos:error] [pid 499145:tid 499334] [client 102.213.179.25:54552] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=102.213.179.25, id=apPk11JNq1G5uRhTNnuYEQAAADs
[Sun Aug 30 03:07:51.579989 2026] [qos:error] [pid 499145:tid 499383] [client 5.255.123.162:60028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=5.255.123.162, id=apPk11JNq1G5uRhTNnuYEgAAAGw
[Sun Aug 30 03:07:51.592121 2026] [qos:error] [pid 499145:tid 499366] [client 195.226.213.254:37014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=195.226.213.254, id=apPk11JNq1G5uRhTNnuYFAAAAFs
[Sun Aug 30 03:07:51.593918 2026] [qos:error] [pid 499145:tid 499335] [client 35.235.153.127:16384] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=35.235.153.127, id=apPk11JNq1G5uRhTNnuYFQAAADw
[Sun Aug 30 03:07:51.596076 2026] [qos:error] [pid 499145:tid 499378] [client 150.241.91.238:45962] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=150.241.91.238, id=apPk11JNq1G5uRhTNnuYFgAAAGc
[Sun Aug 30 03:07:51.598162 2026] [qos:error] [pid 499145:tid 499348] [client 45.180.62.250:45430] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.180.62.250, id=apPk11JNq1G5uRhTNnuYFwAAAEk
[Sun Aug 30 03:07:51.598729 2026] [qos:error] [pid 499145:tid 499308] [client 31.25.11.143:42902] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=31.25.11.143, id=apPk11JNq1G5uRhTNnuYGAAAACE
[Sun Aug 30 03:07:51.606940 2026] [qos:error] [pid 499145:tid 499278] [client 103.112.65.238:50238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.112.65.238, id=apPk11JNq1G5uRhTNnuYGQAAAAM
[Sun Aug 30 03:07:51.619200 2026] [qos:error] [pid 502397:tid 502636] [client 31.187.64.243:42082] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=31.187.64.243, id=apPk12uFRxhFZfnD0nI3BAAAAXY
[Sun Aug 30 03:07:51.619802 2026] [qos:error] [pid 499145:tid 499381] [client 78.155.64.122:44820] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=78.155.64.122, id=apPk11JNq1G5uRhTNnuYGgAAAGo
[Sun Aug 30 03:07:51.652364 2026] [qos:error] [pid 499145:tid 499376] [client 186.250.147.255:50633] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=186.250.147.255, id=apPk11JNq1G5uRhTNnuYGwAAAGU
[Sun Aug 30 03:07:51.655406 2026] [qos:error] [pid 499145:tid 499355] [client 165.101.230.77:53925] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=165.101.230.77, id=apPk11JNq1G5uRhTNnuYHAAAAFA
[Sun Aug 30 03:07:51.663667 2026] [qos:error] [pid 499145:tid 499334] [client 34.134.26.114:34817] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=34.134.26.114, id=apPk11JNq1G5uRhTNnuYHgAAADs
[Sun Aug 30 03:07:51.669382 2026] [authz_core:error] [pid 499145:tid 499367] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IN
[Sun Aug 30 03:07:51.669662 2026] [authz_core:error] [pid 499145:tid 499367] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IN
[Sun Aug 30 03:07:51.683130 2026] [qos:error] [pid 499145:tid 499383] [client 103.140.207.186:47054] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.140.207.186, id=apPk11JNq1G5uRhTNnuYHwAAAGw
[Sun Aug 30 03:07:51.685400 2026] [qos:error] [pid 499145:tid 499366] [client 191.100.23.22:45503] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=191.100.23.22, id=apPk11JNq1G5uRhTNnuYIAAAAFs
[Sun Aug 30 03:07:51.686407 2026] [qos:error] [pid 499145:tid 499378] [client 85.8.47.211:57222] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=85.8.47.211, id=apPk11JNq1G5uRhTNnuYIgAAAGc
[Sun Aug 30 03:07:51.686565 2026] [qos:error] [pid 499145:tid 499335] [client 37.221.241.115:49882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=37.221.241.115, id=apPk11JNq1G5uRhTNnuYIQAAADw
[Sun Aug 30 03:07:51.687985 2026] [qos:error] [pid 499145:tid 499348] [client 170.245.132.81:58842] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=170.245.132.81, id=apPk11JNq1G5uRhTNnuYIwAAAEk
[Sun Aug 30 03:07:51.694627 2026] [qos:error] [pid 499145:tid 499308] [client 154.59.111.42:39548] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=154.59.111.42, id=apPk11JNq1G5uRhTNnuYJAAAACE
[Sun Aug 30 03:07:51.699026 2026] [qos:error] [pid 499145:tid 499278] [client 83.148.74.114:52771] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=83.148.74.114, id=apPk11JNq1G5uRhTNnuYJQAAAAM
[Sun Aug 30 03:07:51.702613 2026] [qos:error] [pid 499145:tid 499381] [client 113.174.113.56:40550] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=113.174.113.56, id=apPk11JNq1G5uRhTNnuYJgAAAGo
[Sun Aug 30 03:07:51.706166 2026] [qos:error] [pid 499145:tid 499376] [client 193.202.11.25:37690] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=193.202.11.25, id=apPk11JNq1G5uRhTNnuYJwAAAGU
[Sun Aug 30 03:07:51.706180 2026] [qos:error] [pid 499145:tid 499355] [client 43.252.107.106:39914] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=43.252.107.106, id=apPk11JNq1G5uRhTNnuYKAAAAFA
[Sun Aug 30 03:07:51.707665 2026] [qos:error] [pid 499145:tid 499334] [client 94.102.224.138:59434] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=94.102.224.138, id=apPk11JNq1G5uRhTNnuYKQAAADs
[Sun Aug 30 03:07:51.707973 2026] [qos:error] [pid 499145:tid 499383] [client 203.95.220.114:49572] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=203.95.220.114, id=apPk11JNq1G5uRhTNnuYKgAAAGw
[Sun Aug 30 03:07:51.709897 2026] [qos:error] [pid 499145:tid 499366] [client 85.8.47.212:47418] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=85.8.47.212, id=apPk11JNq1G5uRhTNnuYKwAAAFs
[Sun Aug 30 03:07:51.715616 2026] [qos:error] [pid 499145:tid 499378] [client 146.4.93.102:39080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=146.4.93.102, id=apPk11JNq1G5uRhTNnuYLAAAAGc
[Sun Aug 30 03:07:51.715656 2026] [qos:error] [pid 499145:tid 499335] [client 38.65.174.247:49046] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=38.65.174.247, id=apPk11JNq1G5uRhTNnuYLQAAADw
[Sun Aug 30 03:07:51.716441 2026] [qos:error] [pid 499145:tid 499348] [client 45.121.216.229:36990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.121.216.229, id=apPk11JNq1G5uRhTNnuYLgAAAEk
[Sun Aug 30 03:07:51.718057 2026] [qos:error] [pid 499145:tid 499308] [client 85.60.193.47:42382] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=85.60.193.47, id=apPk11JNq1G5uRhTNnuYLwAAACE
[Sun Aug 30 03:07:51.719564 2026] [qos:error] [pid 499145:tid 499278] [client 202.58.78.30:60526] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=202.58.78.30, id=apPk11JNq1G5uRhTNnuYMAAAAAM
[Sun Aug 30 03:07:51.719638 2026] [qos:error] [pid 499145:tid 499283] [client 186.1.173.12:38416] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=186.1.173.12, id=apPk11JNq1G5uRhTNnuYMQAAAAg
[Sun Aug 30 03:07:51.725685 2026] [qos:error] [pid 499145:tid 499381] [client 38.172.181.22:46262] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.172.181.22, id=apPk11JNq1G5uRhTNnuYMgAAAGo
[Sun Aug 30 03:07:51.726117 2026] [qos:error] [pid 499145:tid 499376] [client 147.45.218.2:38902] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=147.45.218.2, id=apPk11JNq1G5uRhTNnuYMwAAAGU
[Sun Aug 30 03:07:51.726461 2026] [qos:error] [pid 499145:tid 499355] [client 104.28.228.110:40824] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=104.28.228.110, id=apPk11JNq1G5uRhTNnuYNAAAAFA
[Sun Aug 30 03:07:51.727035 2026] [qos:error] [pid 499145:tid 499334] [client 94.28.32.110:56368] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=94.28.32.110, id=apPk11JNq1G5uRhTNnuYNQAAADs
[Sun Aug 30 03:07:51.734545 2026] [qos:error] [pid 499145:tid 499383] [client 203.175.103.9:56929] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=203.175.103.9, id=apPk11JNq1G5uRhTNnuYNgAAAGw
[Sun Aug 30 03:07:51.735966 2026] [qos:error] [pid 499145:tid 499366] [client 95.58.145.162:37429] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=95.58.145.162, id=apPk11JNq1G5uRhTNnuYNwAAAFs
[Sun Aug 30 03:07:51.737479 2026] [qos:error] [pid 499145:tid 499378] [client 202.21.124.129:46241] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=202.21.124.129, id=apPk11JNq1G5uRhTNnuYOAAAAGc
[Sun Aug 30 03:07:51.737773 2026] [qos:error] [pid 499145:tid 499335] [client 103.250.128.23:44884] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.250.128.23, id=apPk11JNq1G5uRhTNnuYOQAAADw
[Sun Aug 30 03:07:51.740060 2026] [qos:error] [pid 499145:tid 499348] [client 103.75.118.84:43989] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.75.118.84, id=apPk11JNq1G5uRhTNnuYOgAAAEk
[Sun Aug 30 03:07:51.756496 2026] [qos:error] [pid 499145:tid 499311] [client 124.107.173.219:55502] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=124.107.173.219, id=apPk11JNq1G5uRhTNnuYOwAAACQ
[Sun Aug 30 03:07:51.760570 2026] [qos:error] [pid 499145:tid 499308] [client 103.210.161.8:54148] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.210.161.8, id=apPk11JNq1G5uRhTNnuYPAAAACE
[Sun Aug 30 03:07:51.762104 2026] [qos:error] [pid 499145:tid 499278] [client 202.59.206.58:49020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=202.59.206.58, id=apPk11JNq1G5uRhTNnuYPQAAAAM
[Sun Aug 30 03:07:51.762801 2026] [qos:error] [pid 499145:tid 499283] [client 38.111.103.17:56761] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.111.103.17, id=apPk11JNq1G5uRhTNnuYPgAAAAg
[Sun Aug 30 03:07:51.764153 2026] [qos:error] [pid 499145:tid 499381] [client 177.10.59.156:53742] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=177.10.59.156, id=apPk11JNq1G5uRhTNnuYPwAAAGo
[Sun Aug 30 03:07:51.773611 2026] [qos:error] [pid 499145:tid 499355] [client 37.150.97.11:41176] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=37.150.97.11, id=apPk11JNq1G5uRhTNnuYQQAAAFA
[Sun Aug 30 03:07:51.774089 2026] [authz_core:error] [pid 499145:tid 499376] [client 216.73.216.128:49300] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:51.774494 2026] [authz_core:error] [pid 499145:tid 499376] [client 216.73.216.128:49300] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:51.776027 2026] [qos:error] [pid 499145:tid 499334] [client 103.159.78.237:53371] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.159.78.237, id=apPk11JNq1G5uRhTNnuYQgAAADs
[Sun Aug 30 03:07:51.779064 2026] [qos:error] [pid 499145:tid 499383] [client 114.9.55.102:43542] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=114.9.55.102, id=apPk11JNq1G5uRhTNnuYQwAAAGw
[Sun Aug 30 03:07:51.782227 2026] [qos:error] [pid 499145:tid 499366] [client 103.166.227.194:39350] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.166.227.194, id=apPk11JNq1G5uRhTNnuYRAAAAFs
[Sun Aug 30 03:07:51.783596 2026] [qos:error] [pid 503470:tid 503630] [client 170.78.208.54:37316] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=170.78.208.54, id=apPk1z8EKFABaii6jtMWnwAAAKM
[Sun Aug 30 03:07:51.788239 2026] [qos:error] [pid 499145:tid 499335] [client 27.77.96.91:55170] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=27.77.96.91, id=apPk11JNq1G5uRhTNnuYRgAAADw
[Sun Aug 30 03:07:51.788314 2026] [qos:error] [pid 499145:tid 499378] [client 103.58.251.102:36472] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.58.251.102, id=apPk11JNq1G5uRhTNnuYRQAAAGc
[Sun Aug 30 03:07:51.796779 2026] [qos:error] [pid 499145:tid 499348] [client 181.115.147.68:46333] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=181.115.147.68, id=apPk11JNq1G5uRhTNnuYRwAAAEk
[Sun Aug 30 03:07:51.800719 2026] [qos:error] [pid 499145:tid 499311] [client 221.121.1.43:41659] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=221.121.1.43, id=apPk11JNq1G5uRhTNnuYSAAAACQ
[Sun Aug 30 03:07:51.801322 2026] [qos:error] [pid 499145:tid 499308] [client 171.5.130.187:44152] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=171.5.130.187, id=apPk11JNq1G5uRhTNnuYSQAAACE
[Sun Aug 30 03:07:51.803583 2026] [qos:error] [pid 499145:tid 499278] [client 165.0.69.116:51120] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=165.0.69.116, id=apPk11JNq1G5uRhTNnuYSgAAAAM
[Sun Aug 30 03:07:51.808388 2026] [qos:error] [pid 503470:tid 503666] [client 38.183.146.5:45950] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.183.146.5, id=apPk1z8EKFABaii6jtMWoAAAAMc
[Sun Aug 30 03:07:51.809738 2026] [qos:error] [pid 499145:tid 499283] [client 58.63.243.11:55326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=58.63.243.11, id=apPk11JNq1G5uRhTNnuYSwAAAAg
[Sun Aug 30 03:07:51.815141 2026] [qos:error] [pid 499145:tid 499381] [client 102.223.22.130:35252] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=102.223.22.130, id=apPk11JNq1G5uRhTNnuYTAAAAGo
[Sun Aug 30 03:07:51.815212 2026] [qos:error] [pid 499145:tid 499355] [client 177.54.40.12:54800] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=177.54.40.12, id=apPk11JNq1G5uRhTNnuYTQAAAFA
[Sun Aug 30 03:07:51.827479 2026] [qos:error] [pid 499145:tid 499383] [client 105.22.37.218:41296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=105.22.37.218, id=apPk11JNq1G5uRhTNnuYTwAAAGw
[Sun Aug 30 03:07:51.828763 2026] [qos:error] [pid 499145:tid 499366] [client 103.184.67.45:44322] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.184.67.45, id=apPk11JNq1G5uRhTNnuYUAAAAFs
[Sun Aug 30 03:07:51.831074 2026] [qos:error] [pid 499145:tid 499335] [client 81.70.40.86:50689] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=81.70.40.86, id=apPk11JNq1G5uRhTNnuYUQAAADw
[Sun Aug 30 03:07:51.833046 2026] [qos:error] [pid 499145:tid 499378] [client 111.229.126.163:56305] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=111.229.126.163, id=apPk11JNq1G5uRhTNnuYUgAAAGc
[Sun Aug 30 03:07:51.835430 2026] [qos:error] [pid 499145:tid 499348] [client 170.246.144.196:5686] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=170.246.144.196, id=apPk11JNq1G5uRhTNnuYUwAAAEk
[Sun Aug 30 03:07:51.841996 2026] [qos:error] [pid 499145:tid 499311] [client 72.62.59.63:46786] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=72.62.59.63, id=apPk11JNq1G5uRhTNnuYVAAAACQ
[Sun Aug 30 03:07:51.844535 2026] [qos:error] [pid 499145:tid 499308] [client 91.229.151.118:36714] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=91.229.151.118, id=apPk11JNq1G5uRhTNnuYVQAAACE
[Sun Aug 30 03:07:51.844866 2026] [qos:error] [pid 499145:tid 499278] [client 185.238.236.99:59693] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=185.238.236.99, id=apPk11JNq1G5uRhTNnuYVgAAAAM
[Sun Aug 30 03:07:51.848104 2026] [qos:error] [pid 499145:tid 499283] [client 42.118.3.236:55958] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=42.118.3.236, id=apPk11JNq1G5uRhTNnuYVwAAAAg
[Sun Aug 30 03:07:51.849894 2026] [qos:error] [pid 499145:tid 499381] [client 45.115.41.158:41960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.115.41.158, id=apPk11JNq1G5uRhTNnuYWAAAAGo
[Sun Aug 30 03:07:51.871159 2026] [qos:error] [pid 499145:tid 499355] [client 201.20.42.46:55052] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=201.20.42.46, id=apPk11JNq1G5uRhTNnuYWQAAAFA
[Sun Aug 30 03:07:51.873238 2026] [qos:error] [pid 499145:tid 499383] [client 122.201.27.91:51188] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=122.201.27.91, id=apPk11JNq1G5uRhTNnuYWgAAAGw
[Sun Aug 30 03:07:51.876612 2026] [qos:error] [pid 499145:tid 499366] [client 38.19.239.218:59937] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.19.239.218, id=apPk11JNq1G5uRhTNnuYWwAAAFs
[Sun Aug 30 03:07:51.885481 2026] [qos:error] [pid 499145:tid 499335] [client 89.45.220.129:46838] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=89.45.220.129, id=apPk11JNq1G5uRhTNnuYXAAAADw
[Sun Aug 30 03:07:51.887040 2026] [qos:error] [pid 499145:tid 499378] [client 179.255.113.74:57158] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=179.255.113.74, id=apPk11JNq1G5uRhTNnuYXQAAAGc
[Sun Aug 30 03:07:51.892235 2026] [qos:error] [pid 499145:tid 499348] [client 45.189.36.6:48138] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.189.36.6, id=apPk11JNq1G5uRhTNnuYXgAAAEk
[Sun Aug 30 03:07:51.895146 2026] [qos:error] [pid 503470:tid 503664] [client 202.169.51.45:47721] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=202.169.51.45, id=apPk1z8EKFABaii6jtMWoQAAAMU
[Sun Aug 30 03:07:51.897268 2026] [qos:error] [pid 499145:tid 499311] [client 37.195.116.105:58462] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=37.195.116.105, id=apPk11JNq1G5uRhTNnuYXwAAACQ
[Sun Aug 30 03:07:51.903223 2026] [qos:error] [pid 499145:tid 499308] [client 205.209.65.107:53302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=205.209.65.107, id=apPk11JNq1G5uRhTNnuYYAAAACE
[Sun Aug 30 03:07:51.903865 2026] [qos:error] [pid 499145:tid 499278] [client 139.135.170.23:51964] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=139.135.170.23, id=apPk11JNq1G5uRhTNnuYYQAAAAM
[Sun Aug 30 03:07:51.907696 2026] [qos:error] [pid 499145:tid 499367] [client 221.7.239.219:34328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=221.7.239.219, id=apPk11JNq1G5uRhTNnuYYgAAAFw
[Sun Aug 30 03:07:51.917383 2026] [qos:error] [pid 499145:tid 499283] [client 82.66.253.58:34188] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=82.66.253.58, id=apPk11JNq1G5uRhTNnuYYwAAAAg
[Sun Aug 30 03:07:51.925861 2026] [qos:error] [pid 499145:tid 499381] [client 31.76.12.115:37960] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=31.76.12.115, id=apPk11JNq1G5uRhTNnuYZAAAAGo
[Sun Aug 30 03:07:51.941039 2026] [qos:error] [pid 499145:tid 499355] [client 181.67.122.157:30555] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=181.67.122.157, id=apPk11JNq1G5uRhTNnuYZQAAAFA
[Sun Aug 30 03:07:51.942350 2026] [qos:error] [pid 499145:tid 499383] [client 103.189.97.113:35050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.189.97.113, id=apPk11JNq1G5uRhTNnuYZgAAAGw
[Sun Aug 30 03:07:51.942564 2026] [qos:error] [pid 499145:tid 499366] [client 43.163.112.8:50398] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=43.163.112.8, id=apPk11JNq1G5uRhTNnuYZwAAAFs
[Sun Aug 30 03:07:51.943202 2026] [qos:error] [pid 499145:tid 499376] [client 89.43.132.231:51821] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=89.43.132.231, id=apPk11JNq1G5uRhTNnuYaAAAAGU
[Sun Aug 30 03:07:51.947769 2026] [qos:error] [pid 499145:tid 499335] [client 103.111.116.233:58928] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.111.116.233, id=apPk11JNq1G5uRhTNnuYaQAAADw
[Sun Aug 30 03:07:51.952582 2026] [qos:error] [pid 499145:tid 499348] [client 181.13.210.60:37962] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=181.13.210.60, id=apPk11JNq1G5uRhTNnuYawAAAEk
[Sun Aug 30 03:07:51.952676 2026] [qos:error] [pid 499145:tid 499311] [client 85.159.94.124:44786] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=85.159.94.124, id=apPk11JNq1G5uRhTNnuYbAAAACQ
[Sun Aug 30 03:07:51.954271 2026] [qos:error] [pid 499145:tid 499308] [client 63.250.52.167:53014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=63.250.52.167, id=apPk11JNq1G5uRhTNnuYbQAAACE
[Sun Aug 30 03:07:51.955088 2026] [authz_core:error] [pid 499145:tid 499378] [client 216.73.216.128:49300] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:51.955352 2026] [authz_core:error] [pid 499145:tid 499378] [client 216.73.216.128:49300] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:51.959196 2026] [qos:error] [pid 499145:tid 499278] [client 109.72.55.69:46686] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=109.72.55.69, id=apPk11JNq1G5uRhTNnuYbgAAAAM
[Sun Aug 30 03:07:51.960300 2026] [qos:error] [pid 499145:tid 499367] [client 115.79.195.95:39945] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=115.79.195.95, id=apPk11JNq1G5uRhTNnuYbwAAAFw
[Sun Aug 30 03:07:51.961074 2026] [qos:error] [pid 499145:tid 499283] [client 167.250.47.60:40090] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=167.250.47.60, id=apPk11JNq1G5uRhTNnuYcAAAAAg
[Sun Aug 30 03:07:51.962154 2026] [qos:error] [pid 499145:tid 499381] [client 41.72.199.106:53940] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=41.72.199.106, id=apPk11JNq1G5uRhTNnuYcQAAAGo
[Sun Aug 30 03:07:51.962717 2026] [qos:error] [pid 499145:tid 499355] [client 103.172.42.221:38340] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.172.42.221, id=apPk11JNq1G5uRhTNnuYcgAAAFA
[Sun Aug 30 03:07:51.963824 2026] [qos:error] [pid 499145:tid 499383] [client 43.109.48.180:46368] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=43.109.48.180, id=apPk11JNq1G5uRhTNnuYcwAAAGw
[Sun Aug 30 03:07:51.967002 2026] [qos:error] [pid 499145:tid 499366] [client 110.159.129.213:43878] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=110.159.129.213, id=apPk11JNq1G5uRhTNnuYdAAAAFs
[Sun Aug 30 03:07:51.969371 2026] [qos:error] [pid 499145:tid 499376] [client 112.64.135.45:35391] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=112.64.135.45, id=apPk11JNq1G5uRhTNnuYdQAAAGU
[Sun Aug 30 03:07:51.979221 2026] [qos:error] [pid 499145:tid 499335] [client 42.240.136.180:50780] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=42.240.136.180, id=apPk11JNq1G5uRhTNnuYdgAAADw
[Sun Aug 30 03:07:51.982881 2026] [qos:error] [pid 499145:tid 499348] [client 207.248.0.193:60802] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=207.248.0.193, id=apPk11JNq1G5uRhTNnuYdwAAAEk
[Sun Aug 30 03:07:51.991140 2026] [qos:error] [pid 499145:tid 499311] [client 103.164.55.81:41040] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.164.55.81, id=apPk11JNq1G5uRhTNnuYeAAAACQ
[Sun Aug 30 03:07:51.993999 2026] [qos:error] [pid 499145:tid 499308] [client 24.152.37.60:51619] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=24.152.37.60, id=apPk11JNq1G5uRhTNnuYeQAAACE
[Sun Aug 30 03:07:51.997393 2026] [qos:error] [pid 499145:tid 499278] [client 58.64.160.132:35828] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=58.64.160.132, id=apPk11JNq1G5uRhTNnuYegAAAAM
[Sun Aug 30 03:07:51.998157 2026] [qos:error] [pid 499145:tid 499367] [client 190.100.200.3:55310] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=190.100.200.3, id=apPk11JNq1G5uRhTNnuYewAAAFw
[Sun Aug 30 03:07:52.004552 2026] [qos:error] [pid 499145:tid 499355] [client 202.21.124.129:46076] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=202.21.124.129, id=apPk2FJNq1G5uRhTNnuYfAAAAFA
[Sun Aug 30 03:07:52.005844 2026] [qos:error] [pid 499145:tid 499383] [client 181.78.197.196:57959] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=181.78.197.196, id=apPk2FJNq1G5uRhTNnuYfQAAAGw
[Sun Aug 30 03:07:52.012091 2026] [qos:error] [pid 499145:tid 499366] [client 202.4.127.90:34014] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=202.4.127.90, id=apPk2FJNq1G5uRhTNnuYfgAAAFs
[Sun Aug 30 03:07:52.017022 2026] [qos:error] [pid 499145:tid 499376] [client 2.144.6.22:52264] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=2.144.6.22, id=apPk2FJNq1G5uRhTNnuYfwAAAGU
[Sun Aug 30 03:07:52.018606 2026] [qos:error] [pid 499145:tid 499335] [client 124.83.46.180:52650] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=124.83.46.180, id=apPk2FJNq1G5uRhTNnuYgAAAADw
[Sun Aug 30 03:07:52.027251 2026] [qos:error] [pid 499145:tid 499348] [client 165.99.194.61:47856] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=165.99.194.61, id=apPk2FJNq1G5uRhTNnuYgQAAAEk
[Sun Aug 30 03:07:52.032662 2026] [qos:error] [pid 499145:tid 499311] [client 152.32.74.91:41114] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=152.32.74.91, id=apPk2FJNq1G5uRhTNnuYggAAACQ
[Sun Aug 30 03:07:52.034061 2026] [qos:error] [pid 499145:tid 499308] [client 5.253.196.143:58716] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=5.253.196.143, id=apPk2FJNq1G5uRhTNnuYgwAAACE
[Sun Aug 30 03:07:52.034149 2026] [qos:error] [pid 499145:tid 499278] [client 172.239.18.67:53210] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=172.239.18.67, id=apPk2FJNq1G5uRhTNnuYhAAAAAM
[Sun Aug 30 03:07:52.037945 2026] [qos:error] [pid 499145:tid 499283] [client 31.130.131.191:37852] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=31.130.131.191, id=apPk2FJNq1G5uRhTNnuYhQAAAAg
[Sun Aug 30 03:07:52.038010 2026] [qos:error] [pid 499145:tid 499367] [client 190.112.160.23:56862] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=190.112.160.23, id=apPk2FJNq1G5uRhTNnuYhgAAAFw
[Sun Aug 30 03:07:52.038422 2026] [qos:error] [pid 499145:tid 499381] [client 41.79.233.182:54961] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=41.79.233.182, id=apPk2FJNq1G5uRhTNnuYhwAAAGo
[Sun Aug 30 03:07:52.042538 2026] [qos:error] [pid 499145:tid 499334] [client 138.117.14.237:53332] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=138.117.14.237, id=apPk2FJNq1G5uRhTNnuYiAAAADs
[Sun Aug 30 03:07:52.044847 2026] [qos:error] [pid 499145:tid 499355] [client 144.24.171.189:50494] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=144.24.171.189, id=apPk2FJNq1G5uRhTNnuYiQAAAFA
[Sun Aug 30 03:07:52.047427 2026] [qos:error] [pid 499751:tid 500004] [client 118.145.141.251:58442] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=118.145.141.251, id=apPk2DmmjdkPfMeJsKPgpwAABBA
[Sun Aug 30 03:07:52.047612 2026] [qos:error] [pid 499145:tid 499383] [client 45.186.106.145:44682] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.186.106.145, id=apPk2FJNq1G5uRhTNnuYigAAAGw
[Sun Aug 30 03:07:52.050745 2026] [qos:error] [pid 499145:tid 499376] [client 171.226.73.226:41038] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=171.226.73.226, id=apPk2FJNq1G5uRhTNnuYiwAAAGU
[Sun Aug 30 03:07:52.053061 2026] [qos:error] [pid 499145:tid 499335] [client 103.126.86.239:51146] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.126.86.239, id=apPk2FJNq1G5uRhTNnuYjAAAADw
[Sun Aug 30 03:07:52.061895 2026] [qos:error] [pid 499145:tid 499348] [client 157.15.0.167:43062] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=157.15.0.167, id=apPk2FJNq1G5uRhTNnuYjQAAAEk
[Sun Aug 30 03:07:52.063712 2026] [qos:error] [pid 499145:tid 499311] [client 103.163.13.36:51868] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.163.13.36, id=apPk2FJNq1G5uRhTNnuYjgAAACQ
[Sun Aug 30 03:07:52.069708 2026] [qos:error] [pid 499145:tid 499308] [client 42.96.18.62:56616] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=42.96.18.62, id=apPk2FJNq1G5uRhTNnuYjwAAACE
[Sun Aug 30 03:07:52.073578 2026] [qos:error] [pid 499145:tid 499278] [client 192.255.201.184:46386] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=192.255.201.184, id=apPk2FJNq1G5uRhTNnuYkAAAAAM
[Sun Aug 30 03:07:52.076233 2026] [qos:error] [pid 499145:tid 499283] [client 139.84.133.240:49024] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=139.84.133.240, id=apPk2FJNq1G5uRhTNnuYkQAAAAg
[Sun Aug 30 03:07:52.076699 2026] [qos:error] [pid 499145:tid 499367] [client 45.136.115.2:44766] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.136.115.2, id=apPk2FJNq1G5uRhTNnuYkgAAAFw
[Sun Aug 30 03:07:52.077755 2026] [qos:error] [pid 499145:tid 499381] [client 14.241.183.20:34622] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=14.241.183.20, id=apPk2FJNq1G5uRhTNnuYkwAAAGo
[Sun Aug 30 03:07:52.079978 2026] [qos:error] [pid 499145:tid 499334] [client 38.58.66.232:55432] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.58.66.232, id=apPk2FJNq1G5uRhTNnuYlAAAADs
[Sun Aug 30 03:07:52.086315 2026] [qos:error] [pid 499145:tid 499355] [client 112.197.57.3:47491] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=112.197.57.3, id=apPk2FJNq1G5uRhTNnuYlQAAAFA
[Sun Aug 30 03:07:52.090957 2026] [qos:error] [pid 499145:tid 499366] [client 51.77.148.27:45610] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=51.77.148.27, id=apPk2FJNq1G5uRhTNnuYlgAAAFs
[Sun Aug 30 03:07:52.092832 2026] [qos:error] [pid 499145:tid 499376] [client 45.144.54.40:60314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.144.54.40, id=apPk2FJNq1G5uRhTNnuYmAAAAGU
[Sun Aug 30 03:07:52.093032 2026] [qos:error] [pid 499145:tid 499383] [client 103.61.18.6:57894] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.61.18.6, id=apPk2FJNq1G5uRhTNnuYlwAAAGw
[Sun Aug 30 03:07:52.105397 2026] [qos:error] [pid 499145:tid 499335] [client 103.124.165.149:35756] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.124.165.149, id=apPk2FJNq1G5uRhTNnuYmQAAADw
[Sun Aug 30 03:07:52.110031 2026] [qos:error] [pid 499145:tid 499348] [client 45.137.12.78:44704] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.137.12.78, id=apPk2FJNq1G5uRhTNnuYmgAAAEk
[Sun Aug 30 03:07:52.122391 2026] [qos:error] [pid 499145:tid 499378] [client 204.76.203.9:46272] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=204.76.203.9, id=apPk2FJNq1G5uRhTNnuYmwAAAGc
[Sun Aug 30 03:07:52.123704 2026] [qos:error] [pid 499145:tid 499308] [client 112.198.23.254:41560] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=112.198.23.254, id=apPk2FJNq1G5uRhTNnuYnAAAACE
[Sun Aug 30 03:07:52.131996 2026] [qos:error] [pid 499145:tid 499283] [client 113.45.195.147:46042] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=113.45.195.147, id=apPk2FJNq1G5uRhTNnuYngAAAAg
[Sun Aug 30 03:07:52.133870 2026] [qos:error] [pid 499145:tid 499367] [client 38.191.204.22:36540] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.191.204.22, id=apPk2FJNq1G5uRhTNnuYnwAAAFw
[Sun Aug 30 03:07:52.134704 2026] [qos:error] [pid 499145:tid 499381] [client 123.20.38.145:44196] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=123.20.38.145, id=apPk2FJNq1G5uRhTNnuYoAAAAGo
[Sun Aug 30 03:07:52.142805 2026] [qos:error] [pid 499145:tid 499334] [client 45.43.60.220:46606] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.43.60.220, id=apPk2FJNq1G5uRhTNnuYoQAAADs
[Sun Aug 30 03:07:52.145075 2026] [qos:error] [pid 499145:tid 499355] [client 122.43.226.106:64370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=122.43.226.106, id=apPk2FJNq1G5uRhTNnuYogAAAFA
[Sun Aug 30 03:07:52.146385 2026] [qos:error] [pid 499145:tid 499366] [client 180.148.24.170:52669] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=180.148.24.170, id=apPk2FJNq1G5uRhTNnuYowAAAFs
[Sun Aug 30 03:07:52.148641 2026] [qos:error] [pid 499145:tid 499376] [client 160.19.17.43:35110] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=160.19.17.43, id=apPk2FJNq1G5uRhTNnuYpAAAAGU
[Sun Aug 30 03:07:52.150262 2026] [qos:error] [pid 499145:tid 499383] [client 179.136.111.46:52562] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=179.136.111.46, id=apPk2FJNq1G5uRhTNnuYpQAAAGw
[Sun Aug 30 03:07:52.152718 2026] [qos:error] [pid 499145:tid 499335] [client 45.127.58.70:43682] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.127.58.70, id=apPk2FJNq1G5uRhTNnuYpgAAADw
[Sun Aug 30 03:07:52.153669 2026] [qos:error] [pid 499145:tid 499348] [client 85.1.75.2:45910] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=85.1.75.2, id=apPk2FJNq1G5uRhTNnuYpwAAAEk
[Sun Aug 30 03:07:52.154123 2026] [qos:error] [pid 499145:tid 499378] [client 205.209.65.105:56314] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=205.209.65.105, id=apPk2FJNq1G5uRhTNnuYqAAAAGc
[Sun Aug 30 03:07:52.156983 2026] [http2:info] [pid 504660:tid 504660] h2_workers: created with min=128 max=192 idle_ms=600000
[Sun Aug 30 03:07:52.157157 2026] [qos:error] [pid 499145:tid 499308] [client 170.79.157.58:37320] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=170.79.157.58, id=apPk2FJNq1G5uRhTNnuYqQAAACE
[Sun Aug 30 03:07:52.173678 2026] [qos:error] [pid 499145:tid 499367] [client 165.154.20.187:33274] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=165.154.20.187, id=apPk2FJNq1G5uRhTNnuYqgAAAFw
[Sun Aug 30 03:07:52.174178 2026] [qos:error] [pid 499145:tid 499283] [client 103.153.135.2:48746] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=103.153.135.2, id=apPk2FJNq1G5uRhTNnuYqwAAAAg
[Sun Aug 30 03:07:52.174674 2026] [qos:error] [pid 499145:tid 499381] [client 103.237.102.191:54342] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=103.237.102.191, id=apPk2FJNq1G5uRhTNnuYrAAAAGo
[Sun Aug 30 03:07:52.174871 2026] [qos:error] [pid 499145:tid 499334] [client 196.1.187.146:34443] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=196.1.187.146, id=apPk2FJNq1G5uRhTNnuYrQAAADs
[Sun Aug 30 03:07:52.174880 2026] [qos:error] [pid 499145:tid 499355] [client 38.194.246.34:37670] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=38.194.246.34, id=apPk2FJNq1G5uRhTNnuYrgAAAFA
[Sun Aug 30 03:07:52.175212 2026] [qos:error] [pid 499145:tid 499366] [client 27.66.27.114:59090] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=27.66.27.114, id=apPk2FJNq1G5uRhTNnuYrwAAAFs
[Sun Aug 30 03:07:52.175702 2026] [qos:error] [pid 499145:tid 499376] [client 200.10.31.45:46123] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=200.10.31.45, id=apPk2FJNq1G5uRhTNnuYsAAAAGU
[Sun Aug 30 03:07:52.177627 2026] [qos:error] [pid 499145:tid 499383] [client 203.175.103.45:56628] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=203.175.103.45, id=apPk2FJNq1G5uRhTNnuYsQAAAGw
[Sun Aug 30 03:07:52.178031 2026] [security2:error] [pid 504660:tid 504868] [client 20.104.50.220:27573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/init.php"] [unique_id "apPk2AgfiZclygrb6nn5ZAAAAzo"]
[Sun Aug 30 03:07:52.178074 2026] [security2:error] [pid 504660:tid 504861] [client 158.23.147.79:62301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/mah.php"] [unique_id "apPk2AgfiZclygrb6nn5XQAAAzM"]
[Sun Aug 30 03:07:52.178091 2026] [security2:error] [pid 504660:tid 504863] [client 20.104.50.220:33043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/xl33t.php"] [unique_id "apPk2AgfiZclygrb6nn5XwAAAzU"]
[Sun Aug 30 03:07:52.178158 2026] [security2:error] [pid 504660:tid 504864] [client 20.104.50.220:51590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-cli.php"] [unique_id "apPk2AgfiZclygrb6nn5YAAAAzY"]
[Sun Aug 30 03:07:52.178182 2026] [security2:error] [pid 504660:tid 504866] [client 20.48.251.3:33289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/mga.php"] [unique_id "apPk2AgfiZclygrb6nn5YgAAAzg"]
[Sun Aug 30 03:07:52.178238 2026] [security2:error] [pid 504660:tid 504867] [client 4.205.62.107:18643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/services.php"] [unique_id "apPk2AgfiZclygrb6nn5YwAAAzk"]
[Sun Aug 30 03:07:52.178271 2026] [security2:error] [pid 504660:tid 504865] [client 68.155.159.216:62327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apPk2AgfiZclygrb6nn5YQAAAzc"]
[Sun Aug 30 03:07:52.178346 2026] [security2:error] [pid 504660:tid 504843] [client 20.48.250.41:60696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/xr.php"] [unique_id "apPk2AgfiZclygrb6nn5VwAAAyE"]
[Sun Aug 30 03:07:52.178356 2026] [security2:error] [pid 504660:tid 504862] [client 20.104.50.220:31911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-pluging.php"] [unique_id "apPk2AgfiZclygrb6nn5XgAAAzQ"]
[Sun Aug 30 03:07:52.178382 2026] [security2:error] [pid 504660:tid 504848] [client 20.48.251.3:5105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/hochladen.form.php"] [unique_id "apPk2AgfiZclygrb6nn5WwAAAyY"]
[Sun Aug 30 03:07:52.178421 2026] [security2:error] [pid 504660:tid 504846] [client 20.104.104.62:55841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expresso.social"] [uri "/waf.php"] [unique_id "apPk2AgfiZclygrb6nn5WgAAAyQ"]
[Sun Aug 30 03:07:52.178502 2026] [security2:error] [pid 504660:tid 504844] [client 4.205.62.107:62460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/otuz1.php"] [unique_id "apPk2AgfiZclygrb6nn5WAAAAyI"]
[Sun Aug 30 03:07:52.178554 2026] [security2:error] [pid 504660:tid 504842] [client 20.48.250.41:18404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/ccu.php"] [unique_id "apPk2AgfiZclygrb6nn5VQAAAyA"]
[Sun Aug 30 03:07:52.178582 2026] [security2:error] [pid 504660:tid 504841] [client 20.104.18.15:29165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/indo.php"] [unique_id "apPk2AgfiZclygrb6nn5VgAAAx8"]
[Sun Aug 30 03:07:52.179312 2026] [security2:error] [pid 504660:tid 504878] [client 68.155.159.216:64791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/images/index.php"] [unique_id "apPk2AgfiZclygrb6nn5ZQAAA0Q"]
[Sun Aug 30 03:07:52.179518 2026] [security2:error] [pid 504660:tid 504880] [client 4.205.62.107:64027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/product.php"] [unique_id "apPk2AgfiZclygrb6nn5ZgAAA0Y"]
[Sun Aug 30 03:07:52.181350 2026] [qos:error] [pid 499145:tid 499348] [client 200.39.139.65:33281] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=200.39.139.65, id=apPk2FJNq1G5uRhTNnuYswAAAEk
[Sun Aug 30 03:07:52.181694 2026] [security2:error] [pid 504660:tid 504879] [client 20.104.50.220:61985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/olu.php"] [unique_id "apPk2AgfiZclygrb6nn5aAAAA0U"]
[Sun Aug 30 03:07:52.182037 2026] [qos:error] [pid 499145:tid 499378] [client 43.162.115.229:57322] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=43.162.115.229, id=apPk2FJNq1G5uRhTNnuYtAAAAGc
[Sun Aug 30 03:07:52.182100 2026] [security2:error] [pid 504660:tid 504841] [client 68.155.159.216:56422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-content/packed.php"] [unique_id "apPk2AgfiZclygrb6nn5aQAAAx8"]
[Sun Aug 30 03:07:52.182262 2026] [qos:error] [pid 499145:tid 499308] [client 165.154.7.156:37740] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=165.154.7.156, id=apPk2FJNq1G5uRhTNnuYtQAAACE
[Sun Aug 30 03:07:52.183429 2026] [security2:error] [pid 504660:tid 504888] [client 20.104.49.130:39425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/well.php"] [unique_id "apPk2AgfiZclygrb6nn5cAAAA04"]
[Sun Aug 30 03:07:52.183460 2026] [security2:error] [pid 504660:tid 504889] [client 20.104.50.220:5575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/47.php"] [unique_id "apPk2AgfiZclygrb6nn5cQAAA08"]
[Sun Aug 30 03:07:52.183585 2026] [security2:error] [pid 504660:tid 504890] [client 114.119.137.122:47583] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "corollaobxphotographer.com"] [uri "/blog/where-to-buy-sugar-cane-nyc-5fcba0"] [unique_id "apPk2AgfiZclygrb6nn5cgAAA1A"], referer: http://corollaobxphotographer.com/blog/blank-canvas-with-wood-frame-5fcba0
[Sun Aug 30 03:07:52.184692 2026] [security2:error] [pid 504660:tid 504895] [client 20.104.18.15:28638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/fxp.php"] [unique_id "apPk2AgfiZclygrb6nn5dQAAA1U"]
[Sun Aug 30 03:07:52.186012 2026] [security2:error] [pid 504660:tid 504901] [client 114.119.155.2:23441] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "1800rlawyer.com"] [uri "/family-law"] [unique_id "apPk2AgfiZclygrb6nn5fgAAA1s"], referer: http://1800rlawyer.com/family-law
[Sun Aug 30 03:07:52.186022 2026] [security2:error] [pid 504660:tid 504902] [client 20.104.50.220:46154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/2clas.php"] [unique_id "apPk2AgfiZclygrb6nn5fQAAA1w"]
[Sun Aug 30 03:07:52.186846 2026] [authz_core:error] [pid 499145:tid 499335] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_SG
[Sun Aug 30 03:07:52.187133 2026] [qos:error] [pid 499145:tid 499367] [client 82.157.11.124:54578] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=82.157.11.124, id=apPk2FJNq1G5uRhTNnuYtgAAAFw
[Sun Aug 30 03:07:52.187159 2026] [authz_core:error] [pid 499145:tid 499335] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_SG
[Sun Aug 30 03:07:52.187821 2026] [security2:error] [pid 504660:tid 504913] [client 68.155.159.216:54233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apPk2AgfiZclygrb6nn5gwAAA2c"]
[Sun Aug 30 03:07:52.189756 2026] [qos:error] [pid 499145:tid 499283] [client 103.156.17.161:53638] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.156.17.161, id=apPk2FJNq1G5uRhTNnuYtwAAAAg
[Sun Aug 30 03:07:52.190422 2026] [qos:error] [pid 499145:tid 499381] [client 103.165.157.247:52474] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.165.157.247, id=apPk2FJNq1G5uRhTNnuYuAAAAGo
[Sun Aug 30 03:07:52.195407 2026] [authz_core:error] [pid 504660:tid 504875] [client 66.249.66.38:45220] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:52.195862 2026] [authz_core:error] [pid 504660:tid 504875] [client 66.249.66.38:45220] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:52.196407 2026] [qos:error] [pid 499145:tid 499334] [client 42.83.84.87:52798] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=42.83.84.87, id=apPk2FJNq1G5uRhTNnuYuQAAADs
[Sun Aug 30 03:07:52.200788 2026] [qos:error] [pid 499145:tid 499366] [client 145.63.139.234:60854] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=145.63.139.234, id=apPk2FJNq1G5uRhTNnuYugAAAFs
[Sun Aug 30 03:07:52.202286 2026] [qos:error] [pid 504660:tid 504859] [client 124.105.110.243:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPk2AgfiZclygrb6nn5eQAAAzE
[Sun Aug 30 03:07:52.202294 2026] [qos:error] [pid 504660:tid 504886] [client 103.145.34.112:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.44, id=apPk2AgfiZclygrb6nn5eAAAA0w
[Sun Aug 30 03:07:52.202309 2026] [qos:error] [pid 504660:tid 504874] [client 45.7.64.8:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=50.6.92.44, id=apPk2AgfiZclygrb6nn5ewAAA0A
[Sun Aug 30 03:07:52.202335 2026] [security2:error] [pid 504660:tid 504919] [client 20.104.18.15:35498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/media.php"] [unique_id "apPk2AgfiZclygrb6nn5hwAAA20"]
[Sun Aug 30 03:07:52.203460 2026] [security2:error] [pid 504660:tid 504919] [client 4.205.62.107:64646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/g3.php"] [unique_id "apPk2AgfiZclygrb6nn5vgAAA20"]
[Sun Aug 30 03:07:52.203839 2026] [qos:error] [pid 499145:tid 499355] [client 104.28.244.150:63144] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=104.28.244.150, id=apPk2FJNq1G5uRhTNnuYuwAAAFA
[Sun Aug 30 03:07:52.204064 2026] [qos:error] [pid 504660:tid 504898] [client 139.208.232.207:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=50.6.92.44, id=apPk2AgfiZclygrb6nn5ngAAA1g
[Sun Aug 30 03:07:52.205059 2026] [security2:error] [pid 504660:tid 504908] [client 20.104.50.220:52854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-content/fw.php"] [unique_id "apPk2AgfiZclygrb6nn5wgAAA2I"]
[Sun Aug 30 03:07:52.206150 2026] [security2:error] [pid 504660:tid 504948] [client 20.104.18.15:23527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/run.php"] [unique_id "apPk2AgfiZclygrb6nn5wwAAA4o"]
[Sun Aug 30 03:07:52.207250 2026] [qos:error] [pid 504660:tid 504904] [client 95.3.69.222:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.44, id=apPk2AgfiZclygrb6nn5xAAAA14
[Sun Aug 30 03:07:52.208120 2026] [qos:error] [pid 499145:tid 499376] [client 14.241.37.80:40846] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=14.241.37.80, id=apPk2FJNq1G5uRhTNnuYvAAAAGU
[Sun Aug 30 03:07:52.209237 2026] [qos:error] [pid 504660:tid 504914] [client 77.239.106.24:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.44, id=apPk2AgfiZclygrb6nn5xgAAA2g
[Sun Aug 30 03:07:52.211200 2026] [authz_core:error] [pid 504660:tid 504916] [client 66.249.66.71:40698] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:52.211216 2026] [authz_core:error] [pid 504660:tid 504910] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:52.211470 2026] [authz_core:error] [pid 504660:tid 504910] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:52.211488 2026] [authz_core:error] [pid 504660:tid 504916] [client 66.249.66.71:40698] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:52.214228 2026] [qos:error] [pid 499145:tid 499383] [client 58.56.0.234:59056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=58.56.0.234, id=apPk2FJNq1G5uRhTNnuYvQAAAGw
[Sun Aug 30 03:07:52.215547 2026] [qos:error] [pid 499145:tid 499348] [client 118.173.230.98:44356] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=118.173.230.98, id=apPk2FJNq1G5uRhTNnuYvgAAAEk
[Sun Aug 30 03:07:52.221773 2026] [qos:error] [pid 504660:tid 504943] [client 206.42.79.243:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPk2AgfiZclygrb6nn5zwAAA4U
[Sun Aug 30 03:07:52.224876 2026] [qos:error] [pid 504660:tid 504886] [client 38.76.232.195:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPk2AgfiZclygrb6nn51AAAA0w
[Sun Aug 30 03:07:52.226239 2026] [qos:error] [pid 499145:tid 499378] [client 190.97.35.249:40854] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=190.97.35.249, id=apPk2FJNq1G5uRhTNnuYvwAAAGc
[Sun Aug 30 03:07:52.227124 2026] [security2:error] [pid 504660:tid 504914] [client 20.104.50.220:62792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/him.php"] [unique_id "apPk2AgfiZclygrb6nn51wAAA2g"]
[Sun Aug 30 03:07:52.232144 2026] [qos:error] [pid 504660:tid 504898] [client 43.159.37.201:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPk2AgfiZclygrb6nn53gAAA1g
[Sun Aug 30 03:07:52.246606 2026] [security2:error] [pid 504660:tid 504904] [client 20.104.18.15:34730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/fpwch.php"] [unique_id "apPk2AgfiZclygrb6nn57wAAA14"]
[Sun Aug 30 03:07:52.252269 2026] [security2:error] [pid 504660:tid 504851] [client 52.139.37.240:49886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apPk2AgfiZclygrb6nn58wAAAyk"]
[Sun Aug 30 03:07:52.264243 2026] [security2:error] [pid 504660:tid 504872] [client 52.139.37.240:31861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "apPk2AgfiZclygrb6nn5-wAAAz4"]
[Sun Aug 30 03:07:52.276146 2026] [security2:error] [pid 504660:tid 504965] [client 20.104.18.15:18399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/dehnl.php"] [unique_id "apPk2AgfiZclygrb6nn6BgAAA5s"]
[Sun Aug 30 03:07:52.277936 2026] [security2:error] [pid 504660:tid 504891] [client 20.48.251.3:34485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/old_phpinfo.php"] [unique_id "apPk2AgfiZclygrb6nn6CAAAA1E"]
[Sun Aug 30 03:07:52.283975 2026] [security2:error] [pid 504660:tid 504915] [client 158.23.147.79:62297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-blog-header.php"] [unique_id "apPk2AgfiZclygrb6nn6DQAAA2k"]
[Sun Aug 30 03:07:52.298116 2026] [authz_core:error] [pid 504660:tid 504902] [client 216.73.216.128:40000] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:52.298610 2026] [authz_core:error] [pid 504660:tid 504902] [client 216.73.216.128:40000] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:52.309064 2026] [security2:error] [pid 504660:tid 504885] [client 20.151.200.44:59580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/blnux.php"] [unique_id "apPk2AgfiZclygrb6nn6HwAAA0s"]
[Sun Aug 30 03:07:52.312620 2026] [security2:error] [pid 504660:tid 504950] [client 68.155.159.216:65478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wzy.php"] [unique_id "apPk2AgfiZclygrb6nn6IQAAA4w"]
[Sun Aug 30 03:07:52.314522 2026] [security2:error] [pid 504660:tid 504885] [client 20.104.18.15:51676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/goods.php"] [unique_id "apPk2AgfiZclygrb6nn6IgAAA0s"]
[Sun Aug 30 03:07:52.333332 2026] [security2:error] [pid 504660:tid 504897] [client 20.48.250.41:62519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/h02ugyh.php"] [unique_id "apPk2AgfiZclygrb6nn6MQAAA1c"]
[Sun Aug 30 03:07:52.334776 2026] [security2:error] [pid 504660:tid 504964] [client 20.48.250.41:18307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/ak.php"] [unique_id "apPk2AgfiZclygrb6nn6MgAAA5o"]
[Sun Aug 30 03:07:52.351857 2026] [security2:error] [pid 504660:tid 504911] [client 4.205.62.107:36715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/log.php"] [unique_id "apPk2AgfiZclygrb6nn6SQAAA2U"]
[Sun Aug 30 03:07:52.366947 2026] [security2:error] [pid 504660:tid 504856] [client 40.83.93.50:19416] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "lydialovegrave.com"] [uri "/c99.php"] [unique_id "apPk2AgfiZclygrb6nn6ZQAAAy4"]
[Sun Aug 30 03:07:52.380731 2026] [security2:error] [pid 504660:tid 504850] [client 114.119.140.47:37839] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.africamachineryforsale.com"] [uri "/french/searchresultque.php"] [unique_id "apPk2AgfiZclygrb6nn6ggAAAyg"], referer: https://www.africamachineryforsale.com/french/searchresultque.php?tgtcountry=19&cat=258
[Sun Aug 30 03:07:52.380975 2026] [security2:error] [pid 504660:tid 504857] [client 74.248.24.12:6239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/96i.php"] [unique_id "apPk2AgfiZclygrb6nn6ZwAAAy8"]
[Sun Aug 30 03:07:52.409819 2026] [security2:error] [pid 504660:tid 504966] [client 68.155.159.216:61407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/.well-known/content.php"] [unique_id "apPk2AgfiZclygrb6nn6vQAAA5w"]
[Sun Aug 30 03:07:52.444569 2026] [security2:error] [pid 504660:tid 504884] [client 20.197.61.180:19018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/gg.php"] [unique_id "apPk2AgfiZclygrb6nn7DQAAA0o"]
[Sun Aug 30 03:07:52.447289 2026] [security2:error] [pid 504660:tid 504961] [client 52.139.37.240:48721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/wp-content/uploads/min.php"] [unique_id "apPk2AgfiZclygrb6nn7EwAAA5c"]
[Sun Aug 30 03:07:52.467597 2026] [security2:error] [pid 504660:tid 504876] [client 20.48.250.41:18400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/lib.php"] [unique_id "apPk2AgfiZclygrb6nn7KgAAA0I"]
[Sun Aug 30 03:07:52.474051 2026] [security2:error] [pid 504660:tid 504915] [client 20.48.251.3:7368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/G-in.php"] [unique_id "apPk2AgfiZclygrb6nn7LwAAA2k"]
[Sun Aug 30 03:07:52.475816 2026] [security2:error] [pid 504660:tid 504887] [client 52.139.37.240:32150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/wp-content/themes/pridmag/b.php"] [unique_id "apPk2AgfiZclygrb6nn7MwAAA00"]
[Sun Aug 30 03:07:52.497685 2026] [security2:error] [pid 504660:tid 504904] [client 158.23.147.79:63972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apPk2AgfiZclygrb6nn7TQAAA14"]
[Sun Aug 30 03:07:52.525873 2026] [security2:error] [pid 504660:tid 504943] [client 20.48.250.41:59391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/xxw.php"] [unique_id "apPk2AgfiZclygrb6nn7ZAAAA4U"]
[Sun Aug 30 03:07:52.540418 2026] [security2:error] [pid 504660:tid 504865] [client 178.128.110.190:50586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.110.128.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-bb4abda1.vrprovideo.com"] [uri "/wp-admin/install.php"] [unique_id "apPk2AgfiZclygrb6nn7bQAAAzc"]
[Sun Aug 30 03:07:52.600196 2026] [security2:error] [pid 504660:tid 504851] [client 158.23.147.79:62332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-admin/user/index.php"] [unique_id "apPk2AgfiZclygrb6nn7kwAAAyk"]
[Sun Aug 30 03:07:52.604550 2026] [authz_core:error] [pid 504660:tid 504955] [client 216.73.216.128:7140] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:52.604996 2026] [authz_core:error] [pid 504660:tid 504955] [client 216.73.216.128:7140] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:52.618754 2026] [security2:error] [pid 499145:tid 499292] [client 20.48.250.41:18399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/wp-style.php"] [unique_id "apPk2FJNq1G5uRhTNnuZWQAAABE"]
[Sun Aug 30 03:07:52.649321 2026] [security2:error] [pid 504660:tid 504940] [client 52.139.37.240:48723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/zoom1.php"] [unique_id "apPk2AgfiZclygrb6nn7pQAAA4I"]
[Sun Aug 30 03:07:52.657875 2026] [security2:error] [pid 504660:tid 504846] [client 20.48.250.41:62574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/bolt.php"] [unique_id "apPk2AgfiZclygrb6nn7pgAAAyQ"]
[Sun Aug 30 03:07:52.699094 2026] [authz_core:error] [pid 499145:tid 499361] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AU
[Sun Aug 30 03:07:52.699606 2026] [authz_core:error] [pid 499145:tid 499361] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AU
[Sun Aug 30 03:07:52.709814 2026] [security2:error] [pid 504660:tid 504840] [client 158.23.147.79:63951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-includes/plugins.php"] [unique_id "apPk2AgfiZclygrb6nn7tQAAAx4"]
[Sun Aug 30 03:07:52.736266 2026] [security2:error] [pid 504660:tid 504867] [client 52.139.37.240:32147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/0.php"] [unique_id "apPk2AgfiZclygrb6nn70wAAAzk"]
[Sun Aug 30 03:07:52.749084 2026] [security2:error] [pid 504660:tid 504884] [client 20.104.49.130:36793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/coffexium.php"] [unique_id "apPk2AgfiZclygrb6nn73gAAA0o"]
[Sun Aug 30 03:07:52.777497 2026] [security2:error] [pid 504660:tid 504893] [client 20.104.49.130:52298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/wp-login.php"] [unique_id "apPk2AgfiZclygrb6nn7zQAAA1M"]
[Sun Aug 30 03:07:52.779301 2026] [security2:error] [pid 504660:tid 504931] [client 216.73.216.128:28622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPk2AgfiZclygrb6nn7-AAAA3k"]
[Sun Aug 30 03:07:52.783049 2026] [security2:error] [pid 504660:tid 504949] [client 20.48.250.41:18318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/browse.php"] [unique_id "apPk2AgfiZclygrb6nn7-wAAA4s"]
[Sun Aug 30 03:07:52.802195 2026] [security2:error] [pid 499145:tid 499327] [client 20.48.250.41:62504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/rtx.php"] [unique_id "apPk2FJNq1G5uRhTNnuZlAAAADQ"]
[Sun Aug 30 03:07:52.820016 2026] [security2:error] [pid 504660:tid 504957] [client 158.23.147.79:63880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apPk2AgfiZclygrb6nn8DgAAA5M"]
[Sun Aug 30 03:07:52.840611 2026] [security2:error] [pid 504660:tid 504862] [client 52.139.37.240:25756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/lock360.php"] [unique_id "apPk2AgfiZclygrb6nn8FgAAAzQ"]
[Sun Aug 30 03:07:52.846841 2026] [security2:error] [pid 504660:tid 504880] [client 4.205.62.107:32006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/cli_bootstrap.php"] [unique_id "apPk2AgfiZclygrb6nn8HgAAA0Y"]
[Sun Aug 30 03:07:52.855534 2026] [authz_core:error] [pid 504660:tid 504869] [client 66.249.66.75:38381] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:52.855873 2026] [authz_core:error] [pid 504660:tid 504869] [client 66.249.66.75:38381] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:52.870715 2026] [security2:error] [pid 504660:tid 504890] [client 216.73.216.128:7140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPk2AgfiZclygrb6nn8JgAAA1A"]
[Sun Aug 30 03:07:52.920262 2026] [security2:error] [pid 504660:tid 504855] [client 74.248.24.12:2193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/min.php"] [unique_id "apPk2AgfiZclygrb6nn8OQAAAy0"]
[Sun Aug 30 03:07:52.930422 2026] [security2:error] [pid 499145:tid 499364] [client 52.139.37.240:52178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/autoload_classmap/function.php"] [unique_id "apPk2FJNq1G5uRhTNnuZsQAAAFk"]
[Sun Aug 30 03:07:52.940007 2026] [security2:error] [pid 499145:tid 499390] [client 20.48.250.41:18356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/zoo.php"] [unique_id "apPk2FJNq1G5uRhTNnuZsgAAAHM"]
[Sun Aug 30 03:07:52.944916 2026] [security2:error] [pid 504660:tid 504885] [client 158.23.147.79:63891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/goat1.php"] [unique_id "apPk2AgfiZclygrb6nn8QwAAA0s"]
[Sun Aug 30 03:07:52.953231 2026] [security2:error] [pid 504660:tid 504956] [client 20.104.49.130:48005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/forum.php"] [unique_id "apPk2AgfiZclygrb6nn8TAAAA5I"]
[Sun Aug 30 03:07:52.956242 2026] [security2:error] [pid 504660:tid 504872] [client 20.48.250.41:60762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/ckk.php"] [unique_id "apPk2AgfiZclygrb6nn8UAAAAz4"]
[Sun Aug 30 03:07:52.970917 2026] [authz_core:error] [pid 504660:tid 504911] [client 216.73.216.128:52542] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:52.971370 2026] [authz_core:error] [pid 504660:tid 504911] [client 216.73.216.128:52542] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:52.971808 2026] [authz_core:error] [pid 504660:tid 504925] [client 66.249.66.192:41969] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:52.972062 2026] [authz_core:error] [pid 504660:tid 504925] [client 66.249.66.192:41969] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:52.974343 2026] [security2:error] [pid 504660:tid 504962] [client 68.155.159.216:45968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPk2AgfiZclygrb6nn8YQAAA5g"]
[Sun Aug 30 03:07:53.023327 2026] [security2:error] [pid 504660:tid 504851] [client 40.83.93.50:7694] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "lydialovegrave.com"] [uri "/c99.php"] [unique_id "apPk2QgfiZclygrb6nn8ggAAAyk"]
[Sun Aug 30 03:07:53.032292 2026] [security2:error] [pid 504660:tid 504909] [client 52.139.37.240:48775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/r.php"] [unique_id "apPk2QgfiZclygrb6nn8iQAAA2M"]
[Sun Aug 30 03:07:53.042437 2026] [security2:error] [pid 504660:tid 504958] [client 20.151.200.44:55731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/admin.php/700.php"] [unique_id "apPk2QgfiZclygrb6nn8jgAAA5Q"]
[Sun Aug 30 03:07:53.082383 2026] [security2:error] [pid 504660:tid 504916] [client 20.48.250.41:62511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parents.pplak.org"] [uri "/R57.php"] [unique_id "apPk2QgfiZclygrb6nn8qQAAA2o"]
[Sun Aug 30 03:07:53.084288 2026] [security2:error] [pid 504660:tid 504851] [client 20.48.250.41:18305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/elp.php"] [unique_id "apPk2QgfiZclygrb6nn8rAAAAyk"]
[Sun Aug 30 03:07:53.101583 2026] [security2:error] [pid 504660:tid 504895] [client 158.23.147.79:62303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-includes/certificates/index.php"] [unique_id "apPk2QgfiZclygrb6nn8tQAAA1U"]
[Sun Aug 30 03:07:53.122331 2026] [security2:error] [pid 504660:tid 504889] [client 52.139.37.240:31838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/dvve.php"] [unique_id "apPk2QgfiZclygrb6nn8uQAAA08"]
[Sun Aug 30 03:07:53.177197 2026] [security2:error] [pid 499145:tid 499325] [client 20.197.61.180:7867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/defaults.php"] [unique_id "apPk2VJNq1G5uRhTNnuaCgAAADI"]
[Sun Aug 30 03:07:53.211068 2026] [authz_core:error] [pid 499145:tid 499310] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_HK
[Sun Aug 30 03:07:53.211441 2026] [authz_core:error] [pid 499145:tid 499310] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_HK
[Sun Aug 30 03:07:53.217548 2026] [security2:error] [pid 499145:tid 499328] [client 20.48.250.41:18320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/666.php"] [unique_id "apPk2VJNq1G5uRhTNnuaIgAAADU"]
[Sun Aug 30 03:07:53.223530 2026] [security2:error] [pid 504660:tid 504847] [client 52.139.37.240:48730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/sf.php"] [unique_id "apPk2QgfiZclygrb6nn89gAAAyU"]
[Sun Aug 30 03:07:53.224388 2026] [security2:error] [pid 504660:tid 504896] [client 158.23.147.79:63986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-admin/network/index.php"] [unique_id "apPk2QgfiZclygrb6nn89wAAA1Y"]
[Sun Aug 30 03:07:53.241481 2026] [security2:error] [pid 504660:tid 504905] [client 34.125.55.247:46186] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/var/www/html/.env"] [unique_id "apPk2QgfiZclygrb6nn8_wAAA18"]
[Sun Aug 30 03:07:53.248497 2026] [security2:error] [pid 504660:tid 504852] [client 34.125.55.247:46170] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/var/www/.env"] [unique_id "apPk2QgfiZclygrb6nn9CgAAAyo"]
[Sun Aug 30 03:07:53.248603 2026] [security2:error] [pid 504660:tid 504852] [client 34.125.55.247:46170] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/var/www/.env"] [unique_id "apPk2QgfiZclygrb6nn9CgAAAyo"]
[Sun Aug 30 03:07:53.248706 2026] [security2:error] [pid 499145:tid 499369] [client 34.125.55.247:46126] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/terraform.tfvars"] [unique_id "apPk2VJNq1G5uRhTNnuaMQAAAF4"]
[Sun Aug 30 03:07:53.248917 2026] [proxy_http:error] [pid 499145:tid 499305] (20014)Internal error (specific information not available): [client 34.125.55.247:46110] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:53.248931 2026] [proxy:error] [pid 499145:tid 499305] [client 34.125.55.247:46110] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/s3/credentials
[Sun Aug 30 03:07:53.250579 2026] [proxy_http:error] [pid 504660:tid 504962] (20014)Internal error (specific information not available): [client 34.125.55.247:46154] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:53.250595 2026] [proxy:error] [pid 504660:tid 504962] [client 34.125.55.247:46154] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/serverless.yaml
[Sun Aug 30 03:07:53.257284 2026] [security2:error] [pid 504660:tid 504967] [client 34.125.55.247:46136] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/terraform.tfstate"] [unique_id "apPk2QgfiZclygrb6nn9AgAAA50"]
[Sun Aug 30 03:07:53.257409 2026] [proxy_http:error] [pid 504660:tid 504940] (20014)Internal error (specific information not available): [client 34.125.55.247:46122] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:53.257419 2026] [proxy:error] [pid 504660:tid 504940] [client 34.125.55.247:46122] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/s3/.aws/config
[Sun Aug 30 03:07:53.263470 2026] [security2:error] [pid 504660:tid 504868] [client 34.125.55.247:46170] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.engaginggoddaily.com"] [uri "/sendgrid/.env"] [unique_id "apPk2QgfiZclygrb6nn9FQAAAzo"]
[Sun Aug 30 03:07:53.274027 2026] [security2:error] [pid 504660:tid 504914] [client 34.125.55.247:46136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/mail/.env"] [unique_id "apPk2QgfiZclygrb6nn9HQAAA2g"]
[Sun Aug 30 03:07:53.279860 2026] [security2:error] [pid 504660:tid 504900] [client 34.125.55.247:46154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/email/.env"] [unique_id "apPk2QgfiZclygrb6nn9IQAAA1o"]
[Sun Aug 30 03:07:53.286826 2026] [security2:error] [pid 499145:tid 499316] [client 68.155.159.216:56334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-l0gin.php"] [unique_id "apPk2VJNq1G5uRhTNnuaQQAAACk"]
[Sun Aug 30 03:07:53.288030 2026] [security2:error] [pid 504660:tid 504905] [client 68.155.159.216:61639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apPk2QgfiZclygrb6nn9KwAAA18"]
[Sun Aug 30 03:07:53.292941 2026] [security2:error] [pid 504660:tid 504932] [client 34.125.55.247:46208] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/stripe.env"] [unique_id "apPk2QgfiZclygrb6nn9JgAAA3o"]
[Sun Aug 30 03:07:53.293093 2026] [proxy_http:error] [pid 504660:tid 504866] (20014)Internal error (specific information not available): [client 34.125.55.247:46200] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:53.293106 2026] [proxy:error] [pid 504660:tid 504866] [client 34.125.55.247:46200] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/stripe.json
[Sun Aug 30 03:07:53.293506 2026] [security2:error] [pid 504660:tid 504938] [client 34.125.55.247:46122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/stripe/.env"] [unique_id "apPk2QgfiZclygrb6nn9LwAAA4A"]
[Sun Aug 30 03:07:53.300114 2026] [security2:error] [pid 504660:tid 504897] [client 68.155.159.216:55128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/dropdown.php"] [unique_id "apPk2QgfiZclygrb6nn9NQAAA1c"]
[Sun Aug 30 03:07:53.316378 2026] [security2:error] [pid 504660:tid 504883] [client 20.104.50.220:27124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/inicio.php"] [unique_id "apPk2QgfiZclygrb6nn9RgAAA0k"]
[Sun Aug 30 03:07:53.316378 2026] [security2:error] [pid 499145:tid 499345] [client 4.205.62.107:62026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/fun.php"] [unique_id "apPk2VJNq1G5uRhTNnuaUAAAAEY"]
[Sun Aug 30 03:07:53.324213 2026] [security2:error] [pid 504660:tid 504884] [client 20.104.50.220:33343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/1n73ct10n.php"] [unique_id "apPk2QgfiZclygrb6nn9TAAAA0o"]
[Sun Aug 30 03:07:53.324486 2026] [security2:error] [pid 504660:tid 504898] [client 20.104.50.220:46451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/bless5.php"] [unique_id "apPk2QgfiZclygrb6nn9TgAAA1g"]
[Sun Aug 30 03:07:53.328184 2026] [security2:error] [pid 504660:tid 504841] [client 20.104.50.220:5598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/46.php"] [unique_id "apPk2QgfiZclygrb6nn9UgAAAx8"]
[Sun Aug 30 03:07:53.334269 2026] [security2:error] [pid 504660:tid 504873] [client 20.104.50.220:32537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-plugins.php"] [unique_id "apPk2QgfiZclygrb6nn9WQAAAz8"]
[Sun Aug 30 03:07:53.336150 2026] [authz_core:error] [pid 504660:tid 504858] [client 216.73.216.128:52542] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:53.336639 2026] [authz_core:error] [pid 504660:tid 504858] [client 216.73.216.128:52542] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:53.339011 2026] [security2:error] [pid 504660:tid 504905] [client 20.104.18.15:28635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/vv.php"] [unique_id "apPk2QgfiZclygrb6nn9XwAAA18"]
[Sun Aug 30 03:07:53.340402 2026] [security2:error] [pid 504660:tid 504965] [client 20.104.18.15:29672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/wnnjpsby.php"] [unique_id "apPk2QgfiZclygrb6nn9YgAAA5s"]
[Sun Aug 30 03:07:53.342344 2026] [security2:error] [pid 504660:tid 504897] [client 4.205.62.107:18947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/filesystems.php"] [unique_id "apPk2QgfiZclygrb6nn9YwAAA1c"]
[Sun Aug 30 03:07:53.343157 2026] [security2:error] [pid 504660:tid 504888] [client 4.205.62.107:61797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/wp-konfig.php"] [unique_id "apPk2QgfiZclygrb6nn9ZgAAA04"]
[Sun Aug 30 03:07:53.343551 2026] [security2:error] [pid 504660:tid 504932] [client 20.48.251.3:56326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/ccou.php"] [unique_id "apPk2QgfiZclygrb6nn9aQAAA3o"]
[Sun Aug 30 03:07:53.343671 2026] [security2:error] [pid 504660:tid 504922] [client 4.205.62.107:22970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/update.php"] [unique_id "apPk2QgfiZclygrb6nn9awAAA3A"]
[Sun Aug 30 03:07:53.344219 2026] [security2:error] [pid 504660:tid 504879] [client 20.104.50.220:42440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/IP.php"] [unique_id "apPk2QgfiZclygrb6nn9bQAAA0U"]
[Sun Aug 30 03:07:53.347754 2026] [security2:error] [pid 504660:tid 504869] [client 20.48.250.41:18418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/knmt.php"] [unique_id "apPk2QgfiZclygrb6nn9cwAAAzs"]
[Sun Aug 30 03:07:53.351051 2026] [security2:error] [pid 504660:tid 504851] [client 20.104.50.220:29122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-admin/fw.php"] [unique_id "apPk2QgfiZclygrb6nn9dgAAAyk"]
[Sun Aug 30 03:07:53.355054 2026] [security2:error] [pid 504660:tid 504960] [client 20.104.18.15:23454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/new.php"] [unique_id "apPk2QgfiZclygrb6nn9ewAAA5Y"]
[Sun Aug 30 03:07:53.382377 2026] [security2:error] [pid 504660:tid 504864] [client 20.104.50.220:29154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/hh.php"] [unique_id "apPk2QgfiZclygrb6nn9hwAAAzY"]
[Sun Aug 30 03:07:53.385310 2026] [security2:error] [pid 499145:tid 499324] [client 52.139.37.240:52222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/ws77.php"] [unique_id "apPk2VJNq1G5uRhTNnuadQAAADE"]
[Sun Aug 30 03:07:53.387246 2026] [security2:error] [pid 504660:tid 504944] [client 20.104.18.15:34807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/domvf.php"] [unique_id "apPk2QgfiZclygrb6nn9jwAAA4Y"]
[Sun Aug 30 03:07:53.389628 2026] [security2:error] [pid 504660:tid 504876] [client 20.104.18.15:35476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/adminfuns.php"] [unique_id "apPk2QgfiZclygrb6nn9kgAAA0I"]
[Sun Aug 30 03:07:53.415024 2026] [security2:error] [pid 504660:tid 504903] [client 52.139.37.240:25782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/7.php"] [unique_id "apPk2QgfiZclygrb6nn9pgAAA10"]
[Sun Aug 30 03:07:53.415752 2026] [security2:error] [pid 504660:tid 504896] [client 20.104.18.15:18393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/zoo2.php"] [unique_id "apPk2QgfiZclygrb6nn9qAAAA1Y"]
[Sun Aug 30 03:07:53.429368 2026] [security2:error] [pid 504660:tid 504860] [client 74.248.24.12:12014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/chosen.php"] [unique_id "apPk2QgfiZclygrb6nn9tgAAAzI"]
[Sun Aug 30 03:07:53.431974 2026] [security2:error] [pid 499145:tid 499384] [client 68.155.159.216:12330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apPk2VJNq1G5uRhTNnuaiAAAAG0"]
[Sun Aug 30 03:07:53.434090 2026] [security2:error] [pid 499145:tid 499386] [client 20.48.251.3:49956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.krisestep.com"] [uri "/wp-act.php"] [unique_id "apPk2VJNq1G5uRhTNnuaiQAAAG8"]
[Sun Aug 30 03:07:53.457792 2026] [security2:error] [pid 504660:tid 504852] [client 20.104.50.220:16724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/mode.php"] [unique_id "apPk2QgfiZclygrb6nn9uwAAAyo"]
[Sun Aug 30 03:07:53.458254 2026] [security2:error] [pid 504660:tid 504921] [client 20.48.251.3:4851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/debuggen.php"] [unique_id "apPk2QgfiZclygrb6nn9vAAAA28"]
[Sun Aug 30 03:07:53.461892 2026] [security2:error] [pid 504660:tid 504853] [client 20.104.18.15:52181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/alfa.php"] [unique_id "apPk2QgfiZclygrb6nn9wQAAAys"]
[Sun Aug 30 03:07:53.481792 2026] [security2:error] [pid 504660:tid 504870] [client 20.48.250.41:18320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/sbhu.php"] [unique_id "apPk2QgfiZclygrb6nn91AAAAzw"]
[Sun Aug 30 03:07:53.488340 2026] [security2:error] [pid 499145:tid 499389] [client 20.104.50.220:62015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/tuco.php"] [unique_id "apPk2VJNq1G5uRhTNnuaogAAAHI"]
[Sun Aug 30 03:07:53.492889 2026] [security2:error] [pid 504660:tid 504897] [client 4.205.62.107:36627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/ebahvhhh.php"] [unique_id "apPk2QgfiZclygrb6nn92wAAA1c"]
[Sun Aug 30 03:07:53.514124 2026] [authz_core:error] [pid 504660:tid 504876] [client 216.73.216.128:40000] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:53.514380 2026] [authz_core:error] [pid 504660:tid 504876] [client 216.73.216.128:40000] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:53.516051 2026] [security2:error] [pid 504660:tid 504893] [client 158.23.147.79:63890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apPk2QgfiZclygrb6nn96AAAA1M"]
[Sun Aug 30 03:07:53.539809 2026] [security2:error] [pid 504660:tid 504885] [client 68.155.159.216:63957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apPk2QgfiZclygrb6nn99gAAA0s"]
[Sun Aug 30 03:07:53.558623 2026] [authz_core:error] [pid 504660:tid 504898] [client 66.249.66.192:35354] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:53.558984 2026] [authz_core:error] [pid 504660:tid 504898] [client 66.249.66.192:35354] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:53.599268 2026] [security2:error] [pid 499145:tid 499354] [client 52.139.37.240:31833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/admin/function.php"] [unique_id "apPk2VJNq1G5uRhTNnuazQAAAE8"]
[Sun Aug 30 03:07:53.606934 2026] [security2:error] [pid 504660:tid 504949] [client 52.139.37.240:48747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/b.php"] [unique_id "apPk2QgfiZclygrb6nn-MAAAA4s"]
[Sun Aug 30 03:07:53.620228 2026] [security2:error] [pid 504660:tid 504877] [client 20.48.250.41:18412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/a332.php"] [unique_id "apPk2QgfiZclygrb6nn-NQAAA0M"]
[Sun Aug 30 03:07:53.671609 2026] [security2:error] [pid 504660:tid 504954] [client 40.83.93.50:7699] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "lydialovegrave.com"] [uri "/c99.php"] [unique_id "apPk2QgfiZclygrb6nn-RAAAA5A"]
[Sun Aug 30 03:07:53.685074 2026] [security2:error] [pid 504660:tid 504870] [client 20.104.49.130:53612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/sxxb.php"] [unique_id "apPk2QgfiZclygrb6nn-SwAAAzw"]
[Sun Aug 30 03:07:53.696381 2026] [authz_core:error] [pid 504660:tid 504896] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:53.696659 2026] [authz_core:error] [pid 504660:tid 504896] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:53.713425 2026] [security2:error] [pid 504660:tid 504901] [client 158.23.147.79:63899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/.well-knownold/index.php"] [unique_id "apPk2QgfiZclygrb6nn-ZgAAA1s"]
[Sun Aug 30 03:07:53.713782 2026] [authz_core:error] [pid 499145:tid 499395] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AG
[Sun Aug 30 03:07:53.714205 2026] [authz_core:error] [pid 499145:tid 499395] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AG
[Sun Aug 30 03:07:53.737489 2026] [security2:error] [pid 504660:tid 504956] [client 20.48.251.3:64467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/apikeys.php"] [unique_id "apPk2QgfiZclygrb6nn-fQAAA5I"]
[Sun Aug 30 03:07:53.768866 2026] [security2:error] [pid 504660:tid 504943] [client 20.48.250.41:18423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/ws66.php"] [unique_id "apPk2QgfiZclygrb6nn-lAAAA4U"]
[Sun Aug 30 03:07:53.793277 2026] [security2:error] [pid 504660:tid 504908] [client 52.139.37.240:31869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/xx.php"] [unique_id "apPk2QgfiZclygrb6nn-pgAAA2I"]
[Sun Aug 30 03:07:53.801860 2026] [security2:error] [pid 504660:tid 504958] [client 52.139.37.240:25768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/buy.php"] [unique_id "apPk2QgfiZclygrb6nn-rAAAA5Q"]
[Sun Aug 30 03:07:53.809999 2026] [security2:error] [pid 504660:tid 504901] [client 68.155.159.216:60922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/cong.php"] [unique_id "apPk2QgfiZclygrb6nn-uAAAA1s"]
[Sun Aug 30 03:07:53.860816 2026] [security2:error] [pid 504660:tid 504880] [client 158.23.147.79:63921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apPk2QgfiZclygrb6nn-3QAAA0Y"]
[Sun Aug 30 03:07:53.896639 2026] [security2:error] [pid 504660:tid 504871] [client 20.48.250.41:18328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/ws68.php"] [unique_id "apPk2QgfiZclygrb6nn-7wAAAz0"]
[Sun Aug 30 03:07:53.900081 2026] [security2:error] [pid 499145:tid 499288] [client 20.197.61.180:9370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/h.php"] [unique_id "apPk2VJNq1G5uRhTNnubKgAAAA0"]
[Sun Aug 30 03:07:53.947114 2026] [security2:error] [pid 504660:tid 504960] [client 74.248.24.12:2184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/vx.php"] [unique_id "apPk2QgfiZclygrb6nn_AwAAA5Y"]
[Sun Aug 30 03:07:53.954026 2026] [security2:error] [pid 499145:tid 499375] [client 114.119.135.152:36479] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jackasssawhorse.com"] [uri "/product-category/kits/"] [unique_id "apPk2VJNq1G5uRhTNnubOgAAAGQ"], referer: https://jackasssawhorse.com/product-category/kits/?product_order=desc&product_orderby=date
[Sun Aug 30 03:07:53.982936 2026] [authz_core:error] [pid 504660:tid 504912] [client 216.73.216.128:41735] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:53.983266 2026] [authz_core:error] [pid 504660:tid 504912] [client 216.73.216.128:41735] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:53.985094 2026] [security2:error] [pid 499145:tid 499397] [client 52.139.37.240:31859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/wp-content/about.php"] [unique_id "apPk2VJNq1G5uRhTNnubSgAAAHo"]
[Sun Aug 30 03:07:54.008251 2026] [security2:error] [pid 504660:tid 504917] [client 114.119.147.81:54051] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "smartmenu.do"] [uri "/2sir/specialized-tarmac-sl5.html"] [unique_id "apPk2ggfiZclygrb6nn_OwAAA2s"], referer: http://suzannatran.com/bh8qhh/lincoln-sa-200-problems.html
[Sun Aug 30 03:07:54.013329 2026] [security2:error] [pid 504660:tid 504847] [client 52.139.37.240:49881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/config.php"] [unique_id "apPk2ggfiZclygrb6nn_QQAAAyU"]
[Sun Aug 30 03:07:54.037412 2026] [security2:error] [pid 504660:tid 504848] [client 114.119.132.34:36283] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.benchcreative.com.au"] [uri "/submit-project-brief"] [unique_id "apPk2ggfiZclygrb6nn_UgAAAyY"], referer: https://www.benchcreative.com.au/submit-project-brief
[Sun Aug 30 03:07:54.055429 2026] [security2:error] [pid 504660:tid 504925] [client 20.48.250.41:18313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/users.php"] [unique_id "apPk2ggfiZclygrb6nn_WwAAA3M"]
[Sun Aug 30 03:07:54.059583 2026] [security2:error] [pid 504660:tid 504849] [client 65.108.6.34:36356] ModSecurity: Warning. Matched phrase "SEOkicks" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "flashflooring.co.uk"] [uri "/index.php"] [unique_id "apPk2QgfiZclygrb6nn9SAAAAyc"], referer: https://flashflooring.co.uk/sitemap_index.xml
[Sun Aug 30 03:07:54.104876 2026] [security2:error] [pid 504660:tid 504901] [client 158.23.147.79:63927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPk2ggfiZclygrb6nn_fQAAA1s"]
[Sun Aug 30 03:07:54.157100 2026] [security2:error] [pid 504660:tid 504930] [client 40.83.93.50:8107] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "lydialovegrave.com"] [uri "/c99.php"] [unique_id "apPk2ggfiZclygrb6nn_kwAAA3g"]
[Sun Aug 30 03:07:54.169145 2026] [authz_core:error] [pid 504660:tid 504938] [client 66.249.66.35:51249] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:54.169412 2026] [authz_core:error] [pid 504660:tid 504938] [client 66.249.66.35:51249] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:54.177507 2026] [security2:error] [pid 499145:tid 499357] [client 52.139.37.240:32132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/wp-the.php"] [unique_id "apPk2lJNq1G5uRhTNnubmQAAAFI"]
[Sun Aug 30 03:07:54.189869 2026] [security2:error] [pid 504660:tid 504872] [client 20.48.250.41:18309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/bzjdlofz.php"] [unique_id "apPk2ggfiZclygrb6nn_qwAAAz4"]
[Sun Aug 30 03:07:54.199319 2026] [security2:error] [pid 499145:tid 499283] [client 20.104.49.130:48513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/log.php"] [unique_id "apPk2lJNq1G5uRhTNnubqQAAAAg"]
[Sun Aug 30 03:07:54.210423 2026] [security2:error] [pid 504660:tid 504891] [client 52.139.37.240:25791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/num.php"] [unique_id "apPk2ggfiZclygrb6nn_uAAAA1E"]
[Sun Aug 30 03:07:54.215024 2026] [authz_core:error] [pid 499145:tid 499295] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IN
[Sun Aug 30 03:07:54.215464 2026] [authz_core:error] [pid 499145:tid 499295] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IN
[Sun Aug 30 03:07:54.217818 2026] [authz_core:error] [pid 504660:tid 504944] [client 66.249.66.192:48354] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:54.218183 2026] [authz_core:error] [pid 504660:tid 504944] [client 66.249.66.192:48354] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:54.231442 2026] [security2:error] [pid 499145:tid 499308] [client 68.155.159.216:46043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPk2lJNq1G5uRhTNnubvgAAACE"]
[Sun Aug 30 03:07:54.251349 2026] [security2:error] [pid 504660:tid 504850] [client 158.23.147.79:62293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/images/index.php"] [unique_id "apPk2ggfiZclygrb6nn_0AAAAyg"]
[Sun Aug 30 03:07:54.288255 2026] [authz_core:error] [pid 504660:tid 504852] [client 66.249.66.204:48288] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:54.288605 2026] [authz_core:error] [pid 504660:tid 504852] [client 66.249.66.204:48288] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:54.364859 2026] [security2:error] [pid 499145:tid 499317] [client 20.48.250.41:18317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/selesai.php"] [unique_id "apPk2lJNq1G5uRhTNnub_QAAACo"]
[Sun Aug 30 03:07:54.369562 2026] [security2:error] [pid 504660:tid 504923] [client 52.139.37.240:32167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/ws81.php"] [unique_id "apPk2ggfiZclygrb6nkAIAAAA3E"]
[Sun Aug 30 03:07:54.369704 2026] [security2:error] [pid 504660:tid 504880] [client 20.104.49.130:48019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/3.php"] [unique_id "apPk2ggfiZclygrb6nkAIQAAA0Y"]
[Sun Aug 30 03:07:54.390693 2026] [security2:error] [pid 504660:tid 504910] [client 158.23.147.79:62286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-includes/widgets/index.php"] [unique_id "apPk2ggfiZclygrb6nkAKgAAA2Q"]
[Sun Aug 30 03:07:54.396120 2026] [security2:error] [pid 504660:tid 504842] [client 68.155.159.216:61693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-includes/pomo/index.php"] [unique_id "apPk2ggfiZclygrb6nkALwAAAyA"]
[Sun Aug 30 03:07:54.405635 2026] [security2:error] [pid 504660:tid 504900] [client 52.139.37.240:49888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/areak1.php"] [unique_id "apPk2ggfiZclygrb6nkAOwAAA1o"]
[Sun Aug 30 03:07:54.425485 2026] [security2:error] [pid 504660:tid 504963] [client 68.155.159.216:11158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apPk2ggfiZclygrb6nkAQwAAA5k"]
[Sun Aug 30 03:07:54.427988 2026] [security2:error] [pid 504660:tid 504946] [client 68.155.159.216:54244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/sad/about.php"] [unique_id "apPk2ggfiZclygrb6nkASAAAA4g"]
[Sun Aug 30 03:07:54.429214 2026] [security2:error] [pid 504660:tid 504863] [client 4.205.62.107:32496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/dd.php"] [unique_id "apPk2ggfiZclygrb6nkASgAAAzU"]
[Sun Aug 30 03:07:54.452976 2026] [security2:error] [pid 504660:tid 504861] [client 4.205.62.107:62045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/kedi.php"] [unique_id "apPk2ggfiZclygrb6nkAWwAAAzM"]
[Sun Aug 30 03:07:54.455013 2026] [security2:error] [pid 504660:tid 504840] [client 20.104.50.220:27078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/Model.php"] [unique_id "apPk2ggfiZclygrb6nkAXgAAAx4"]
[Sun Aug 30 03:07:54.465793 2026] [security2:error] [pid 504660:tid 504894] [client 20.104.50.220:5912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/44.php"] [unique_id "apPk2ggfiZclygrb6nkAZAAAA1Q"]
[Sun Aug 30 03:07:54.476364 2026] [security2:error] [pid 504660:tid 504904] [client 20.104.50.220:47053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/file15.php"] [unique_id "apPk2ggfiZclygrb6nkAbAAAA14"]
[Sun Aug 30 03:07:54.476595 2026] [security2:error] [pid 504660:tid 504932] [client 20.104.50.220:32839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/not_acceptable.php"] [unique_id "apPk2ggfiZclygrb6nkAbQAAA3o"]
[Sun Aug 30 03:07:54.482718 2026] [security2:error] [pid 504660:tid 504886] [client 20.104.18.15:28418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/bossu.php"] [unique_id "apPk2ggfiZclygrb6nkAcQAAA0w"]
[Sun Aug 30 03:07:54.483225 2026] [security2:error] [pid 504660:tid 504872] [client 20.48.251.3:33296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/rum.or.php"] [unique_id "apPk2ggfiZclygrb6nkAcgAAAz4"]
[Sun Aug 30 03:07:54.484183 2026] [security2:error] [pid 504660:tid 504938] [client 20.104.50.220:51579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/XiXi.php"] [unique_id "apPk2ggfiZclygrb6nkAdAAAA4A"]
[Sun Aug 30 03:07:54.489254 2026] [security2:error] [pid 504660:tid 504963] [client 20.104.50.220:52824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wordpress/fw.php"] [unique_id "apPk2ggfiZclygrb6nkAeAAAA5k"]
[Sun Aug 30 03:07:54.499922 2026] [security2:error] [pid 504660:tid 504859] [client 20.104.50.220:31889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-rss.php"] [unique_id "apPk2ggfiZclygrb6nkAgAAAAzE"]
[Sun Aug 30 03:07:54.500124 2026] [security2:error] [pid 504660:tid 504891] [client 20.104.18.15:23453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/inx.php"] [unique_id "apPk2ggfiZclygrb6nkAggAAA1E"]
[Sun Aug 30 03:07:54.504259 2026] [security2:error] [pid 504660:tid 504939] [client 20.48.250.41:18372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/shlo.php"] [unique_id "apPk2ggfiZclygrb6nkAhAAAA4E"]
[Sun Aug 30 03:07:54.509041 2026] [security2:error] [pid 504660:tid 504880] [client 20.104.18.15:29069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/info.php/new.php"] [unique_id "apPk2ggfiZclygrb6nkAhQAAA0Y"]
[Sun Aug 30 03:07:54.519948 2026] [security2:error] [pid 504660:tid 504925] [client 4.205.62.107:9537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.themelodybymtr.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPk2ggfiZclygrb6nkAjwAAA3M"]
[Sun Aug 30 03:07:54.520214 2026] [security2:error] [pid 504660:tid 504851] [client 20.104.50.220:52860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/hz.php"] [unique_id "apPk2ggfiZclygrb6nkAkAAAAyk"]
[Sun Aug 30 03:07:54.529743 2026] [security2:error] [pid 504660:tid 504850] [client 20.104.18.15:34759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/biufile.php"] [unique_id "apPk2ggfiZclygrb6nkAmgAAAyg"]
[Sun Aug 30 03:07:54.530926 2026] [security2:error] [pid 504660:tid 504932] [client 4.205.62.107:64657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/25.php"] [unique_id "apPk2ggfiZclygrb6nkAnAAAA3o"]
[Sun Aug 30 03:07:54.537800 2026] [security2:error] [pid 504660:tid 504881] [client 20.104.18.15:35479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/classwithtostring.php"] [unique_id "apPk2ggfiZclygrb6nkAogAAA0c"]
[Sun Aug 30 03:07:54.554193 2026] [security2:error] [pid 504660:tid 504959] [client 4.205.62.107:22955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/channels.php"] [unique_id "apPk2ggfiZclygrb6nkAqAAAA5U"]
[Sun Aug 30 03:07:54.557862 2026] [security2:error] [pid 504660:tid 504935] [client 158.23.184.117:18720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/bgymj.php"] [unique_id "apPk2ggfiZclygrb6nkAqgAAA30"]
[Sun Aug 30 03:07:54.562564 2026] [security2:error] [pid 504660:tid 504879] [client 52.139.37.240:52200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/a1.php"] [unique_id "apPk2ggfiZclygrb6nkAsQAAA0U"]
[Sun Aug 30 03:07:54.570361 2026] [security2:error] [pid 504660:tid 504874] [client 20.104.18.15:18355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/zoo1.php"] [unique_id "apPk2ggfiZclygrb6nkAvQAAA0A"]
[Sun Aug 30 03:07:54.579345 2026] [security2:error] [pid 504660:tid 504947] [client 4.205.62.107:18657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/tax.php"] [unique_id "apPk2ggfiZclygrb6nkAywAAA4k"]
[Sun Aug 30 03:07:54.591374 2026] [security2:error] [pid 504660:tid 504904] [client 20.48.251.3:44334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/pouhg.php"] [unique_id "apPk2ggfiZclygrb6nkA1QAAA14"]
[Sun Aug 30 03:07:54.596120 2026] [security2:error] [pid 504660:tid 504871] [client 20.104.50.220:17235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPk2ggfiZclygrb6nkA2QAAAz0"]
[Sun Aug 30 03:07:54.597555 2026] [security2:error] [pid 504660:tid 504938] [client 52.139.37.240:48771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/vc.php"] [unique_id "apPk2ggfiZclygrb6nkA2wAAA4A"]
[Sun Aug 30 03:07:54.603901 2026] [security2:error] [pid 504660:tid 504860] [client 158.23.184.117:18719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/bk/index.php"] [unique_id "apPk2ggfiZclygrb6nkA4AAAAzI"]
[Sun Aug 30 03:07:54.609125 2026] [security2:error] [pid 504660:tid 504911] [client 158.23.147.79:62311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apPk2ggfiZclygrb6nkA5AAAA2U"]
[Sun Aug 30 03:07:54.625830 2026] [security2:error] [pid 499145:tid 499329] [client 20.104.18.15:51592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/133.php"] [unique_id "apPk2lJNq1G5uRhTNnucWAAAADY"]
[Sun Aug 30 03:07:54.632727 2026] [security2:error] [pid 504660:tid 504916] [client 68.155.159.216:65510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apPk2ggfiZclygrb6nkA8AAAA2o"]
[Sun Aug 30 03:07:54.649821 2026] [security2:error] [pid 499145:tid 499349] [client 4.205.62.107:35989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/asa.php"] [unique_id "apPk2lJNq1G5uRhTNnucXQAAAEo"]
[Sun Aug 30 03:07:54.656307 2026] [security2:error] [pid 499145:tid 499391] [client 68.155.159.216:64807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apPk2lJNq1G5uRhTNnucXwAAAHQ"]
[Sun Aug 30 03:07:54.656955 2026] [security2:error] [pid 499145:tid 499281] [client 20.104.50.220:61489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/ice.php"] [unique_id "apPk2lJNq1G5uRhTNnucYwAAAAY"]
[Sun Aug 30 03:07:54.661637 2026] [authz_core:error] [pid 499145:tid 499374] [client 66.249.66.205:38854] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:54.661905 2026] [authz_core:error] [pid 499145:tid 499374] [client 66.249.66.205:38854] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:54.664855 2026] [security2:error] [pid 499145:tid 499303] [client 74.248.24.12:10766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/wap.php"] [unique_id "apPk2lJNq1G5uRhTNnucZwAAABw"]
[Sun Aug 30 03:07:54.679466 2026] [security2:error] [pid 504660:tid 504882] [client 40.83.93.50:8073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/test1.php"] [unique_id "apPk2ggfiZclygrb6nkA_AAAA0g"]
[Sun Aug 30 03:07:54.679545 2026] [security2:error] [pid 504660:tid 504960] [client 20.104.49.130:48059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/one.php"] [unique_id "apPk2ggfiZclygrb6nkA_QAAA5Y"]
[Sun Aug 30 03:07:54.702720 2026] [security2:error] [pid 504660:tid 504925] [client 158.23.147.79:63887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apPk2ggfiZclygrb6nkBCAAAA3M"]
[Sun Aug 30 03:07:54.743057 2026] [security2:error] [pid 504660:tid 504895] [client 158.23.184.117:18726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/bootstrap.php"] [unique_id "apPk2ggfiZclygrb6nkBNAAAA1U"]
[Sun Aug 30 03:07:54.756409 2026] [security2:error] [pid 504660:tid 504878] [client 52.139.37.240:52179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/ca5.php"] [unique_id "apPk2ggfiZclygrb6nkBOgAAA0Q"]
[Sun Aug 30 03:07:54.792345 2026] [security2:error] [pid 504660:tid 504880] [client 20.197.61.180:7970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/num.php"] [unique_id "apPk2ggfiZclygrb6nkBTgAAA0Y"]
[Sun Aug 30 03:07:54.802501 2026] [security2:error] [pid 504660:tid 504906] [client 52.139.37.240:48726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPk2ggfiZclygrb6nkBUQAAA2A"]
[Sun Aug 30 03:07:54.804479 2026] [security2:error] [pid 499145:tid 499284] [client 158.23.147.79:62328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-includes/pomo/index.php"] [unique_id "apPk2lJNq1G5uRhTNnucqAAAAAk"]
[Sun Aug 30 03:07:54.806086 2026] [security2:error] [pid 504660:tid 504944] [client 216.73.216.128:41735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/'+this.controller.state().get("] [unique_id "apPk2ggfiZclygrb6nkBUgAAA4Y"]
[Sun Aug 30 03:07:54.860442 2026] [security2:error] [pid 504660:tid 504851] [client 20.104.49.130:60715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/df.php"] [unique_id "apPk2ggfiZclygrb6nkBdQAAAyk"]
[Sun Aug 30 03:07:54.883958 2026] [security2:error] [pid 504660:tid 504934] [client 158.23.184.117:18729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/bs1.php"] [unique_id "apPk2ggfiZclygrb6nkBeAAAA3w"]
[Sun Aug 30 03:07:54.916468 2026] [security2:error] [pid 499145:tid 499364] [client 158.23.147.79:63876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/nf_tracking.php"] [unique_id "apPk2lJNq1G5uRhTNnuc1QAAAFk"]
[Sun Aug 30 03:07:54.952790 2026] [security2:error] [pid 499145:tid 499292] [client 52.139.37.240:52207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/install.php"] [unique_id "apPk2lJNq1G5uRhTNnuc5wAAABE"]
[Sun Aug 30 03:07:54.992859 2026] [security2:error] [pid 504660:tid 504941] [client 52.139.37.240:25785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/core.php"] [unique_id "apPk2ggfiZclygrb6nkBsgAAA4M"]
[Sun Aug 30 03:07:55.020660 2026] [security2:error] [pid 504660:tid 504913] [client 158.23.147.79:63960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wzy.php"] [unique_id "apPk2wgfiZclygrb6nkBwQAAA2c"]
[Sun Aug 30 03:07:55.023988 2026] [security2:error] [pid 504660:tid 504894] [client 158.23.184.117:18724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/bthil.php"] [unique_id "apPk2wgfiZclygrb6nkBwwAAA1Q"]
[Sun Aug 30 03:07:55.027846 2026] [security2:error] [pid 499145:tid 499283] [client 20.48.251.3:6935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/motu.php"] [unique_id "apPk21JNq1G5uRhTNnudEwAAAAg"]
[Sun Aug 30 03:07:55.080442 2026] [authz_core:error] [pid 499145:tid 499329] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_US
[Sun Aug 30 03:07:55.080719 2026] [authz_core:error] [pid 499145:tid 499329] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_US
[Sun Aug 30 03:07:55.098410 2026] [security2:error] [pid 499145:tid 499293] [client 20.48.250.41:18401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/asax.php"] [unique_id "apPk21JNq1G5uRhTNnudOgAAABI"]
[Sun Aug 30 03:07:55.114960 2026] [security2:error] [pid 499145:tid 499376] [client 68.155.159.216:60866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-includes/js/index.php"] [unique_id "apPk21JNq1G5uRhTNnudRAAAAGU"]
[Sun Aug 30 03:07:55.159641 2026] [authz_core:error] [pid 504660:tid 504852] [client 66.249.66.40:62505] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:55.160021 2026] [authz_core:error] [pid 504660:tid 504852] [client 66.249.66.40:62505] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:55.165035 2026] [security2:error] [pid 499145:tid 499373] [client 158.23.184.117:18580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/buy.php"] [unique_id "apPk21JNq1G5uRhTNnudWQAAAGI"]
[Sun Aug 30 03:07:55.171982 2026] [authz_core:error] [pid 504660:tid 504877] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:55.172448 2026] [authz_core:error] [pid 504660:tid 504877] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:55.177424 2026] [security2:error] [pid 504660:tid 504932] [client 74.248.24.12:5936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/wp-admin/wp.php"] [unique_id "apPk2wgfiZclygrb6nkCAwAAA3o"]
[Sun Aug 30 03:07:55.185117 2026] [security2:error] [pid 499145:tid 499349] [client 52.139.37.240:48735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/wp-content/min.php"] [unique_id "apPk21JNq1G5uRhTNnudZAAAAEo"]
[Sun Aug 30 03:07:55.199204 2026] [security2:error] [pid 499145:tid 499388] [client 158.23.147.79:62211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-admin/setup-config.php"] [unique_id "apPk21JNq1G5uRhTNnudbgAAAHE"]
[Sun Aug 30 03:07:55.215982 2026] [security2:error] [pid 504660:tid 504910] [client 52.139.37.240:32169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/wp-signin.php"] [unique_id "apPk2wgfiZclygrb6nkCGgAAA2Q"]
[Sun Aug 30 03:07:55.237906 2026] [security2:error] [pid 499145:tid 499363] [client 40.83.93.50:17558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/data.php"] [unique_id "apPk21JNq1G5uRhTNnudiQAAAFg"]
[Sun Aug 30 03:07:55.293426 2026] [authz_core:error] [pid 499145:tid 499287] [client 66.249.66.45:52679] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:55.293721 2026] [authz_core:error] [pid 499145:tid 499287] [client 66.249.66.45:52679] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:55.303724 2026] [security2:error] [pid 499145:tid 499390] [client 158.23.184.117:18590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/byp.php"] [unique_id "apPk21JNq1G5uRhTNnudrQAAAHM"]
[Sun Aug 30 03:07:55.321065 2026] [security2:error] [pid 499145:tid 499276] [client 20.48.250.41:18355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/fetch.php"] [unique_id "apPk21JNq1G5uRhTNnudtAAAAAE"]
[Sun Aug 30 03:07:55.360315 2026] [authz_core:error] [pid 504660:tid 504866] [client 216.73.216.128:40000] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:55.360776 2026] [authz_core:error] [pid 504660:tid 504866] [client 216.73.216.128:40000] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:55.376868 2026] [security2:error] [pid 504660:tid 504912] [client 52.139.37.240:25730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "apPk2wgfiZclygrb6nkCdQAAA2Y"]
[Sun Aug 30 03:07:55.410695 2026] [security2:error] [pid 504660:tid 504868] [client 52.139.37.240:32190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/Ov-Simple1.php"] [unique_id "apPk2wgfiZclygrb6nkCiQAAAzo"]
[Sun Aug 30 03:07:55.444593 2026] [security2:error] [pid 504660:tid 504959] [client 158.23.184.117:18691] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpanel.fakemusic.org"] [uri "/c99.php"] [unique_id "apPk2wgfiZclygrb6nkCngAAA5U"]
[Sun Aug 30 03:07:55.453793 2026] [security2:error] [pid 504660:tid 504884] [client 20.48.250.41:18416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/vx.php"] [unique_id "apPk2wgfiZclygrb6nkCoQAAA0o"]
[Sun Aug 30 03:07:55.459850 2026] [security2:error] [pid 499145:tid 499301] [client 68.155.159.216:46036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apPk21JNq1G5uRhTNnud_QAAABo"]
[Sun Aug 30 03:07:55.472495 2026] [security2:error] [pid 504660:tid 504934] [client 20.151.200.44:47082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/css/000.php"] [unique_id "apPk2wgfiZclygrb6nkCqgAAA3w"]
[Sun Aug 30 03:07:55.492107 2026] [security2:error] [pid 504660:tid 504910] [client 158.23.147.79:62300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apPk2wgfiZclygrb6nkCtwAAA2Q"]
[Sun Aug 30 03:07:55.521795 2026] [security2:error] [pid 499145:tid 499309] [client 68.155.159.216:61637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/nf_tracking.php"] [unique_id "apPk21JNq1G5uRhTNnueJgAAACI"]
[Sun Aug 30 03:07:55.524552 2026] [security2:error] [pid 499145:tid 499344] [client 20.197.61.180:19037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/abc.php"] [unique_id "apPk21JNq1G5uRhTNnueKQAAAEU"]
[Sun Aug 30 03:07:55.535039 2026] [security2:error] [pid 504660:tid 504935] [client 68.155.159.216:54490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/admin.php"] [unique_id "apPk2wgfiZclygrb6nkC0wAAA30"]
[Sun Aug 30 03:07:55.570309 2026] [security2:error] [pid 504660:tid 504856] [client 52.139.37.240:25775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/ws37.php"] [unique_id "apPk2wgfiZclygrb6nkC6AAAAy4"]
[Sun Aug 30 03:07:55.570466 2026] [authz_core:error] [pid 499145:tid 499357] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_HK
[Sun Aug 30 03:07:55.570769 2026] [authz_core:error] [pid 499145:tid 499357] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_HK
[Sun Aug 30 03:07:55.588795 2026] [security2:error] [pid 504660:tid 504891] [client 158.23.184.117:18563] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpanel.fakemusic.org"] [uri "/c99.php"] [unique_id "apPk2wgfiZclygrb6nkC9AAAA1E"]
[Sun Aug 30 03:07:55.592151 2026] [security2:error] [pid 504660:tid 504858] [client 4.205.62.107:62130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/oc460l3x.php"] [unique_id "apPk2wgfiZclygrb6nkC9QAAAzA"]
[Sun Aug 30 03:07:55.592911 2026] [security2:error] [pid 504660:tid 504872] [client 20.104.50.220:27128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/Kernel.php"] [unique_id "apPk2wgfiZclygrb6nkC9gAAAz4"]
[Sun Aug 30 03:07:55.608629 2026] [security2:error] [pid 499145:tid 499386] [client 52.139.37.240:31808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/ftde.php"] [unique_id "apPk21JNq1G5uRhTNnueUQAAAG8"]
[Sun Aug 30 03:07:55.614961 2026] [security2:error] [pid 499145:tid 499385] [client 20.104.50.220:32866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/dada.php"] [unique_id "apPk21JNq1G5uRhTNnueUwAAAG4"]
[Sun Aug 30 03:07:55.615186 2026] [security2:error] [pid 499145:tid 499370] [client 20.104.50.220:46418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/333.php"] [unique_id "apPk21JNq1G5uRhTNnueUgAAAF8"]
[Sun Aug 30 03:07:55.615717 2026] [security2:error] [pid 499145:tid 499314] [client 20.48.250.41:18389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/global.php"] [unique_id "apPk21JNq1G5uRhTNnueVAAAACc"]
[Sun Aug 30 03:07:55.617380 2026] [security2:error] [pid 499145:tid 499350] [client 20.104.18.15:28577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/504.php"] [unique_id "apPk21JNq1G5uRhTNnueVQAAAEs"]
[Sun Aug 30 03:07:55.618960 2026] [security2:error] [pid 504660:tid 504939] [client 20.151.200.44:55735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/admin.php/007x.php"] [unique_id "apPk2wgfiZclygrb6nkDCgAAA4E"]
[Sun Aug 30 03:07:55.619327 2026] [security2:error] [pid 504660:tid 504850] [client 20.104.50.220:5889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/43.php"] [unique_id "apPk2wgfiZclygrb6nkDCwAAAyg"]
[Sun Aug 30 03:07:55.620957 2026] [security2:error] [pid 499145:tid 499399] [client 20.48.251.3:56335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/xmy.php"] [unique_id "apPk21JNq1G5uRhTNnueWAAAAHw"]
[Sun Aug 30 03:07:55.623926 2026] [security2:error] [pid 504660:tid 504846] [client 20.104.50.220:63515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/.piongroup.php"] [unique_id "apPk2wgfiZclygrb6nkDDQAAAyQ"]
[Sun Aug 30 03:07:55.633966 2026] [security2:error] [pid 499145:tid 499323] [client 20.104.18.15:23393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/vpn.php"] [unique_id "apPk21JNq1G5uRhTNnueXwAAADA"]
[Sun Aug 30 03:07:55.645886 2026] [security2:error] [pid 499145:tid 499279] [client 20.104.50.220:52819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-content/dg.php"] [unique_id "apPk21JNq1G5uRhTNnueYwAAAAQ"]
[Sun Aug 30 03:07:55.651849 2026] [security2:error] [pid 499145:tid 499361] [client 20.104.50.220:32748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-singupp.php"] [unique_id "apPk21JNq1G5uRhTNnueZAAAAFY"]
[Sun Aug 30 03:07:55.658424 2026] [security2:error] [pid 499145:tid 499283] [client 20.104.50.220:28709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/here.php"] [unique_id "apPk21JNq1G5uRhTNnueZwAAAAg"]
[Sun Aug 30 03:07:55.660215 2026] [security2:error] [pid 499145:tid 499285] [client 4.205.62.107:64487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/nlnub.php"] [unique_id "apPk21JNq1G5uRhTNnueaAAAAAo"]
[Sun Aug 30 03:07:55.663335 2026] [security2:error] [pid 499145:tid 499295] [client 20.104.18.15:34739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/blacks.php"] [unique_id "apPk21JNq1G5uRhTNnueawAAABQ"]
[Sun Aug 30 03:07:55.684308 2026] [security2:error] [pid 499145:tid 499392] [client 68.155.159.216:56423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPk21JNq1G5uRhTNnuedQAAAHU"]
[Sun Aug 30 03:07:55.691934 2026] [security2:error] [pid 499145:tid 499394] [client 74.248.24.12:7060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/bolt.php"] [unique_id "apPk21JNq1G5uRhTNnueewAAAHc"]
[Sun Aug 30 03:07:55.693031 2026] [security2:error] [pid 504660:tid 504862] [client 20.104.18.15:35506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPk2wgfiZclygrb6nkDGgAAAzQ"]
[Sun Aug 30 03:07:55.695255 2026] [core:alert] [pid 504660:tid 504954] [client 20.104.18.15:29134] /home3/lordrcan/public_html/.htaccess: without matching section
[Sun Aug 30 03:07:55.727846 2026] [security2:error] [pid 504660:tid 504966] [client 158.23.184.117:18438] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpanel.fakemusic.org"] [uri "/c99.php"] [unique_id "apPk2wgfiZclygrb6nkDLwAAA5w"]
[Sun Aug 30 03:07:55.732201 2026] [security2:error] [pid 504660:tid 504843] [client 4.205.62.107:22565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/zz.php"] [unique_id "apPk2wgfiZclygrb6nkDNgAAAyE"]
[Sun Aug 30 03:07:55.736245 2026] [security2:error] [pid 504660:tid 504851] [client 4.205.62.107:18629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPk2wgfiZclygrb6nkDOwAAAyk"]
[Sun Aug 30 03:07:55.737608 2026] [security2:error] [pid 504660:tid 504921] [client 20.104.50.220:16580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/dx.php"] [unique_id "apPk2wgfiZclygrb6nkDPAAAA28"]
[Sun Aug 30 03:07:55.740051 2026] [security2:error] [pid 504660:tid 504888] [client 20.104.18.15:18244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/radio.php"] [unique_id "apPk2wgfiZclygrb6nkDPgAAA04"]
[Sun Aug 30 03:07:55.740926 2026] [security2:error] [pid 504660:tid 504842] [client 68.155.159.216:12374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apPk2wgfiZclygrb6nkDQAAAAyA"]
[Sun Aug 30 03:07:55.749564 2026] [security2:error] [pid 504660:tid 504935] [client 40.83.93.50:13796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/classwithtostring.php"] [unique_id "apPk2wgfiZclygrb6nkDRwAAA30"]
[Sun Aug 30 03:07:55.755598 2026] [security2:error] [pid 504660:tid 504901] [client 20.48.250.41:18327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/fs.php"] [unique_id "apPk2wgfiZclygrb6nkDSQAAA1s"]
[Sun Aug 30 03:07:55.756367 2026] [security2:error] [pid 504660:tid 504919] [client 20.48.251.3:5081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/phpversion.php"] [unique_id "apPk2wgfiZclygrb6nkDSgAAA20"]
[Sun Aug 30 03:07:55.762232 2026] [security2:error] [pid 499145:tid 499341] [client 52.139.37.240:48743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/new.php"] [unique_id "apPk21JNq1G5uRhTNnuenwAAAEI"]
[Sun Aug 30 03:07:55.765947 2026] [security2:error] [pid 504660:tid 504863] [client 20.104.18.15:52187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/sym.php"] [unique_id "apPk2wgfiZclygrb6nkDTwAAAzU"]
[Sun Aug 30 03:07:55.775823 2026] [security2:error] [pid 504660:tid 504867] [client 68.155.159.216:63993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apPk2wgfiZclygrb6nkDVgAAAzk"]
[Sun Aug 30 03:07:55.801935 2026] [security2:error] [pid 499145:tid 499344] [client 4.205.62.107:36017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/radio.php"] [unique_id "apPk21JNq1G5uRhTNnuerAAAAEU"]
[Sun Aug 30 03:07:55.805827 2026] [security2:error] [pid 504660:tid 504942] [client 52.139.37.240:52231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/hplfuns.php"] [unique_id "apPk2wgfiZclygrb6nkDcwAAA4Q"]
[Sun Aug 30 03:07:55.854211 2026] [security2:error] [pid 504660:tid 504860] [client 20.104.50.220:61685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/codeboy1877x.php"] [unique_id "apPk2wgfiZclygrb6nkDigAAAzI"]
[Sun Aug 30 03:07:55.885636 2026] [security2:error] [pid 499145:tid 499330] [client 20.48.250.41:18338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/ioxi.php"] [unique_id "apPk21JNq1G5uRhTNnue2AAAADc"]
[Sun Aug 30 03:07:55.899300 2026] [security2:error] [pid 499145:tid 499354] [client 4.205.62.107:58352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/wp-tem.php"] [unique_id "apPk21JNq1G5uRhTNnue4gAAAE8"]
[Sun Aug 30 03:07:55.906691 2026] [authz_core:error] [pid 504660:tid 504960] [client 216.73.216.128:40000] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:55.907129 2026] [authz_core:error] [pid 504660:tid 504960] [client 216.73.216.128:40000] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:55.937144 2026] [security2:error] [pid 499145:tid 499284] [client 158.23.184.117:18585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/cache/cache/min.php"] [unique_id "apPk21JNq1G5uRhTNnue9gAAAAk"]
[Sun Aug 30 03:07:55.967482 2026] [security2:error] [pid 504660:tid 504853] [client 158.23.147.79:63978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apPk2wgfiZclygrb6nkDtgAAAys"]
[Sun Aug 30 03:07:55.997768 2026] [security2:error] [pid 499145:tid 499294] [client 52.139.37.240:32485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/log.php"] [unique_id "apPk21JNq1G5uRhTNnufDAAAABM"]
[Sun Aug 30 03:07:56.000881 2026] [security2:error] [pid 504660:tid 504951] [client 20.151.200.44:57888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/attack.php"] [unique_id "apPk3AgfiZclygrb6nkD1QAAA40"]
[Sun Aug 30 03:07:56.015216 2026] [security2:error] [pid 504660:tid 504889] [client 20.48.250.41:18386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/bootstrap.php"] [unique_id "apPk3AgfiZclygrb6nkD2QAAA08"]
[Sun Aug 30 03:07:56.047798 2026] [authz_core:error] [pid 504660:tid 504885] [client 66.249.66.40:40865] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:56.048248 2026] [authz_core:error] [pid 504660:tid 504885] [client 66.249.66.40:40865] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:56.054330 2026] [autoindex:error] [pid 499145:tid 499311] [client 52.139.37.240:48748] AH01276: Cannot serve directory /home1/nattdesign/public_html/xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:07:56.074015 2026] [authz_core:error] [pid 499145:tid 499386] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NG
[Sun Aug 30 03:07:56.075747 2026] [authz_core:error] [pid 499145:tid 499386] [client 74.7.243.204:38984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NG
[Sun Aug 30 03:07:56.078445 2026] [security2:error] [pid 504660:tid 504901] [client 158.23.184.117:18471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/catalogbypass.php"] [unique_id "apPk3AgfiZclygrb6nkD_AAAA1s"]
[Sun Aug 30 03:07:56.118224 2026] [security2:error] [pid 499145:tid 499314] [client 52.139.37.240:48748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/il.php"] [unique_id "apPk3FJNq1G5uRhTNnufQAAAACc"]
[Sun Aug 30 03:07:56.145430 2026] [security2:error] [pid 499145:tid 499290] [client 158.23.147.79:62283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apPk3FJNq1G5uRhTNnufSwAAAA8"]
[Sun Aug 30 03:07:56.150668 2026] [security2:error] [pid 504660:tid 504962] [client 20.48.250.41:18408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/export.php"] [unique_id "apPk3AgfiZclygrb6nkEEAAAA5g"]
[Sun Aug 30 03:07:56.171361 2026] [security2:error] [pid 504660:tid 504860] [client 216.73.216.128:40000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPk3AgfiZclygrb6nkEIgAAAzI"]
[Sun Aug 30 03:07:56.189713 2026] [security2:error] [pid 504660:tid 504963] [client 52.139.37.240:32505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/txets.php"] [unique_id "apPk3AgfiZclygrb6nkEKgAAA5k"]
[Sun Aug 30 03:07:56.217852 2026] [security2:error] [pid 499145:tid 499341] [client 158.23.184.117:18567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/cc.php"] [unique_id "apPk3FJNq1G5uRhTNnufdwAAAEI"]
[Sun Aug 30 03:07:56.218139 2026] [cgid:error] [pid 504660:tid 504965] [client 74.248.24.12:5230] AH01265: stderr from /home4/a220training/public_html/b6standards.com/cgi-bin/: attempt to invoke directory as script
[Sun Aug 30 03:07:56.238607 2026] [security2:error] [pid 504660:tid 504881] [client 40.83.93.50:17560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/en.php"] [unique_id "apPk3AgfiZclygrb6nkEPgAAA0c"]
[Sun Aug 30 03:07:56.238906 2026] [security2:error] [pid 499145:tid 499282] [client 20.197.61.180:7856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/default.php"] [unique_id "apPk3FJNq1G5uRhTNnufhQAAAAc"]
[Sun Aug 30 03:07:56.264998 2026] [security2:error] [pid 499145:tid 499402] [client 20.48.251.3:64457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/public/mah.php.php"] [unique_id "apPk3FJNq1G5uRhTNnuflAAAAH8"]
[Sun Aug 30 03:07:56.298908 2026] [security2:error] [pid 504660:tid 504848] [client 20.48.250.41:18409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/gk.php"] [unique_id "apPk3AgfiZclygrb6nkEZwAAAyY"]
[Sun Aug 30 03:07:56.315309 2026] [security2:error] [pid 504660:tid 504844] [client 52.139.37.240:48744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/images/index.php"] [unique_id "apPk3AgfiZclygrb6nkEagAAAyI"]
[Sun Aug 30 03:07:56.336631 2026] [security2:error] [pid 504660:tid 504967] [client 158.23.147.79:63905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apPk3AgfiZclygrb6nkEbAAAA50"]
[Sun Aug 30 03:07:56.358035 2026] [security2:error] [pid 504660:tid 504896] [client 158.23.184.117:18566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/cgi-bin/admin.php"] [unique_id "apPk3AgfiZclygrb6nkEdgAAA1Y"]
[Sun Aug 30 03:07:56.380691 2026] [security2:error] [pid 504660:tid 504907] [client 52.139.37.240:52224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/wp-admin.php"] [unique_id "apPk3AgfiZclygrb6nkEegAAA2E"]
[Sun Aug 30 03:07:56.387373 2026] [security2:error] [pid 504660:tid 504875] [client 74.248.24.12:5230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/edit-tags.php"] [unique_id "apPk3AgfiZclygrb6nkEfAAAA0E"]
[Sun Aug 30 03:07:56.454579 2026] [security2:error] [pid 504660:tid 504920] [client 20.48.250.41:18323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/logs1.php"] [unique_id "apPk3AgfiZclygrb6nkEggAAA24"]
[Sun Aug 30 03:07:56.458655 2026] [security2:error] [pid 499145:tid 499200] [remote 157.230.98.178:37630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.98.230.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirewithangela.com"] [uri "/wp-login.php"] [unique_id "apPk3FJNq1G5uRhTNnufngAAJDY"]
[Sun Aug 30 03:07:56.480973 2026] [security2:error] [pid 504660:tid 504900] [client 158.23.147.79:62238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/packed.php"] [unique_id "apPk3AgfiZclygrb6nkEhgAAA1o"]
[Sun Aug 30 03:07:56.482809 2026] [security2:error] [pid 504660:tid 504862] [client 20.104.49.130:52324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/ohct.php"] [unique_id "apPk3AgfiZclygrb6nkEhwAAAzQ"]
[Sun Aug 30 03:07:56.507719 2026] [security2:error] [pid 504660:tid 504914] [client 52.139.37.240:25749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/lite.php"] [unique_id "apPk3AgfiZclygrb6nkEjQAAA2g"]
[Sun Aug 30 03:07:56.523196 2026] [authz_core:error] [pid 504660:tid 504929] [client 66.249.66.195:62576] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:56.523606 2026] [authz_core:error] [pid 504660:tid 504929] [client 66.249.66.195:62576] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:56.542117 2026] [security2:error] [pid 504660:tid 504941] [client 20.151.200.44:46991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/cy.php"] [unique_id "apPk3AgfiZclygrb6nkEmAAAA4M"]
[Sun Aug 30 03:07:56.554989 2026] [security2:error] [pid 504660:tid 504840] [client 158.23.184.117:18617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/config.php"] [unique_id "apPk3AgfiZclygrb6nkEmwAAAx4"]
[Sun Aug 30 03:07:56.564450 2026] [security2:error] [pid 504660:tid 504844] [client 68.155.159.216:45961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-content/plugins/index.php"] [unique_id "apPk3AgfiZclygrb6nkEngAAAyI"]
[Sun Aug 30 03:07:56.573448 2026] [security2:error] [pid 504660:tid 504945] [client 68.155.159.216:62040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-content/index.php"] [unique_id "apPk3AgfiZclygrb6nkEnwAAA4c"]
[Sun Aug 30 03:07:56.577803 2026] [security2:error] [pid 504660:tid 504960] [client 158.23.147.79:62226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-content/packed.php"] [unique_id "apPk3AgfiZclygrb6nkEogAAA5Y"]
[Sun Aug 30 03:07:56.582301 2026] [security2:error] [pid 504660:tid 504857] [client 20.48.250.41:18373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/inege.php"] [unique_id "apPk3AgfiZclygrb6nkEowAAAy8"]
[Sun Aug 30 03:07:56.590303 2026] [security2:error] [pid 504660:tid 504878] [client 20.104.49.130:48006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/xmini4.php"] [unique_id "apPk3AgfiZclygrb6nkEpAAAA0Q"]
[Sun Aug 30 03:07:56.608166 2026] [security2:error] [pid 504660:tid 504922] [client 20.104.49.130:60980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/pfm.php"] [unique_id "apPk3AgfiZclygrb6nkEqgAAA3A"]
[Sun Aug 30 03:07:56.613050 2026] [authz_core:error] [pid 504660:tid 504886] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZM
[Sun Aug 30 03:07:56.613370 2026] [authz_core:error] [pid 504660:tid 504886] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZM
[Sun Aug 30 03:07:56.661133 2026] [security2:error] [pid 504660:tid 504963] [client 68.155.159.216:54270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-admin/admin.php"] [unique_id "apPk3AgfiZclygrb6nkEtAAAA5k"]
[Sun Aug 30 03:07:56.687046 2026] [authz_core:error] [pid 504660:tid 504947] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:56.687337 2026] [authz_core:error] [pid 504660:tid 504947] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:56.694593 2026] [security2:error] [pid 504660:tid 504867] [client 158.23.184.117:18572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/login.php"] [unique_id "apPk3AgfiZclygrb6nkExAAAAzk"]
[Sun Aug 30 03:07:56.702941 2026] [security2:error] [pid 504660:tid 504954] [client 52.139.37.240:25736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/xda.php"] [unique_id "apPk3AgfiZclygrb6nkExQAAA5A"]
[Sun Aug 30 03:07:56.704067 2026] [security2:error] [pid 504660:tid 504901] [client 158.23.147.79:63991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-l0gin.php"] [unique_id "apPk3AgfiZclygrb6nkExgAAA1s"]
[Sun Aug 30 03:07:56.708638 2026] [security2:error] [pid 504660:tid 504883] [client 20.151.200.44:59533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/wk/index.php"] [unique_id "apPk3AgfiZclygrb6nkExwAAA0k"]
[Sun Aug 30 03:07:56.709252 2026] [security2:error] [pid 504660:tid 504941] [client 52.139.37.240:31867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/wp-config-sample.php"] [unique_id "apPk3AgfiZclygrb6nkEyAAAA4M"]
[Sun Aug 30 03:07:56.714484 2026] [security2:error] [pid 504660:tid 504848] [client 68.155.159.216:61638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wzy.php"] [unique_id "apPk3AgfiZclygrb6nkEywAAAyY"]
[Sun Aug 30 03:07:56.730444 2026] [security2:error] [pid 504660:tid 504945] [client 20.104.50.220:27582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/Builder.php"] [unique_id "apPk3AgfiZclygrb6nkE0AAAA4c"]
[Sun Aug 30 03:07:56.730578 2026] [security2:error] [pid 504660:tid 504881] [client 4.205.62.107:62139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/drykl.php"] [unique_id "apPk3AgfiZclygrb6nkE0QAAA0c"]
[Sun Aug 30 03:07:56.748021 2026] [security2:error] [pid 504660:tid 504857] [client 20.48.250.41:18337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/wp-link10.php"] [unique_id "apPk3AgfiZclygrb6nkE1gAAAy8"]
[Sun Aug 30 03:07:56.758990 2026] [security2:error] [pid 504660:tid 504876] [client 20.104.50.220:5528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/37.php"] [unique_id "apPk3AgfiZclygrb6nkE2QAAA0I"]
[Sun Aug 30 03:07:56.759713 2026] [security2:error] [pid 504660:tid 504964] [client 20.48.251.3:56347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/ms-edit.php"] [unique_id "apPk3AgfiZclygrb6nkE2gAAA5o"]
[Sun Aug 30 03:07:56.765030 2026] [security2:error] [pid 504660:tid 504923] [client 20.104.50.220:46606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/alpa.php"] [unique_id "apPk3AgfiZclygrb6nkE3AAAA3E"]
[Sun Aug 30 03:07:56.767722 2026] [security2:error] [pid 504660:tid 504926] [client 20.104.50.220:32870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/0x1337.php"] [unique_id "apPk3AgfiZclygrb6nkE3QAAA3Q"]
[Sun Aug 30 03:07:56.772734 2026] [security2:error] [pid 504660:tid 504868] [client 20.104.18.15:28659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/nice.php"] [unique_id "apPk3AgfiZclygrb6nkE3wAAAzo"]
[Sun Aug 30 03:07:56.772971 2026] [security2:error] [pid 504660:tid 504955] [client 20.104.18.15:23463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/shiny.php"] [unique_id "apPk3AgfiZclygrb6nkE3gAAA5E"]
[Sun Aug 30 03:07:56.774823 2026] [security2:error] [pid 504660:tid 504894] [client 40.83.93.50:17571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/13.php"] [unique_id "apPk3AgfiZclygrb6nkE4AAAA1Q"]
[Sun Aug 30 03:07:56.794798 2026] [security2:error] [pid 504660:tid 504882] [client 20.104.50.220:28675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-content/mek.php"] [unique_id "apPk3AgfiZclygrb6nkE4wAAA0g"]
[Sun Aug 30 03:07:56.799564 2026] [security2:error] [pid 504660:tid 504893] [client 20.104.50.220:29252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/hxh.php"] [unique_id "apPk3AgfiZclygrb6nkE5gAAA1M"]
[Sun Aug 30 03:07:56.805213 2026] [security2:error] [pid 504660:tid 504919] [client 20.104.50.220:51583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/oke.php"] [unique_id "apPk3AgfiZclygrb6nkE6AAAA20"]
[Sun Aug 30 03:07:56.810201 2026] [security2:error] [pid 504660:tid 504925] [client 20.104.50.220:31872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-site.php"] [unique_id "apPk3AgfiZclygrb6nkE7AAAA3M"]
[Sun Aug 30 03:07:56.811840 2026] [security2:error] [pid 504660:tid 504895] [client 68.155.159.216:56417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/ans.php"] [unique_id "apPk3AgfiZclygrb6nkE7gAAA1U"]
[Sun Aug 30 03:07:56.829202 2026] [security2:error] [pid 504660:tid 504861] [client 4.205.62.107:64678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/mga.php"] [unique_id "apPk3AgfiZclygrb6nkE9QAAAzM"]
[Sun Aug 30 03:07:56.836498 2026] [security2:error] [pid 504660:tid 504871] [client 158.23.184.117:18597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/index.php"] [unique_id "apPk3AgfiZclygrb6nkE9wAAAz0"]
[Sun Aug 30 03:07:56.837162 2026] [security2:error] [pid 504660:tid 504956] [client 20.104.18.15:34648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/beck.php"] [unique_id "apPk3AgfiZclygrb6nkE-AAAA5I"]
[Sun Aug 30 03:07:56.841985 2026] [security2:error] [pid 504660:tid 504840] [client 158.23.147.79:62237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apPk3AgfiZclygrb6nkE-wAAAx4"]
[Sun Aug 30 03:07:56.849216 2026] [security2:error] [pid 504660:tid 504945] [client 68.155.159.216:12410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apPk3AgfiZclygrb6nkE_gAAA4c"]
[Sun Aug 30 03:07:56.856979 2026] [security2:error] [pid 504660:tid 504933] [client 20.104.18.15:35146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/5PJcpMFsD8B.php"] [unique_id "apPk3AgfiZclygrb6nkFAQAAA3s"]
[Sun Aug 30 03:07:56.857688 2026] [authz_core:error] [pid 504660:tid 504897] [client 66.249.66.78:48308] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:56.858086 2026] [authz_core:error] [pid 504660:tid 504897] [client 66.249.66.78:48308] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:56.861990 2026] [security2:error] [pid 504660:tid 504959] [client 4.205.62.107:62283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/test.php"] [unique_id "apPk3AgfiZclygrb6nkFAgAAA5U"]
[Sun Aug 30 03:07:56.877214 2026] [security2:error] [pid 504660:tid 504907] [client 20.104.50.220:17302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/puc.php"] [unique_id "apPk3AgfiZclygrb6nkFBAAAA2E"]
[Sun Aug 30 03:07:56.881567 2026] [security2:error] [pid 504660:tid 504931] [client 20.48.250.41:18326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/ww.php"] [unique_id "apPk3AgfiZclygrb6nkFCAAAA3k"]
[Sun Aug 30 03:07:56.882533 2026] [security2:error] [pid 504660:tid 504938] [client 68.155.159.216:61335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apPk3AgfiZclygrb6nkFCQAAA4A"]
[Sun Aug 30 03:07:56.886549 2026] [security2:error] [pid 504660:tid 504905] [client 20.104.18.15:18367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/one.php"] [unique_id "apPk3AgfiZclygrb6nkFDgAAA18"]
[Sun Aug 30 03:07:56.887330 2026] [security2:error] [pid 504660:tid 504936] [client 4.205.62.107:18978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPk3AgfiZclygrb6nkFDwAAA34"]
[Sun Aug 30 03:07:56.893678 2026] [security2:error] [pid 504660:tid 504875] [client 34.125.55.247:46276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/test/.env"] [unique_id "apPk3AgfiZclygrb6nkFEwAAA0E"]
[Sun Aug 30 03:07:56.893739 2026] [security2:error] [pid 504660:tid 504917] [client 34.125.55.247:46290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/stage/.env"] [unique_id "apPk3AgfiZclygrb6nkFEgAAA2s"]
[Sun Aug 30 03:07:56.895855 2026] [security2:error] [pid 504660:tid 504955] [client 34.125.55.247:46258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/development/.env"] [unique_id "apPk3AgfiZclygrb6nkFFwAAA5E"]
[Sun Aug 30 03:07:56.896310 2026] [security2:error] [pid 504660:tid 504935] [client 34.125.55.247:46232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/back/.env"] [unique_id "apPk3AgfiZclygrb6nkFGQAAA30"]
[Sun Aug 30 03:07:56.896363 2026] [security2:error] [pid 504660:tid 504868] [client 34.125.55.247:46246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/backend-api/.env"] [unique_id "apPk3AgfiZclygrb6nkFGAAAAzo"]
[Sun Aug 30 03:07:56.896752 2026] [security2:error] [pid 504660:tid 504894] [client 34.125.55.247:46260] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/prod/.env"] [unique_id "apPk3AgfiZclygrb6nkFGwAAA1Q"]
[Sun Aug 30 03:07:56.897303 2026] [security2:error] [pid 504660:tid 504952] [client 34.125.55.247:46302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/services/.env"] [unique_id "apPk3AgfiZclygrb6nkFHQAAA44"]
[Sun Aug 30 03:07:56.897436 2026] [security2:error] [pid 504660:tid 504946] [client 34.125.55.247:46292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/node/.env"] [unique_id "apPk3AgfiZclygrb6nkFIQAAA4g"]
[Sun Aug 30 03:07:56.897799 2026] [security2:error] [pid 504660:tid 504851] [client 34.125.55.247:46308] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/private/.env"] [unique_id "apPk3AgfiZclygrb6nkFIwAAAyk"]
[Sun Aug 30 03:07:56.897935 2026] [security2:error] [pid 504660:tid 504918] [client 34.125.55.247:46406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/src/api/.env"] [unique_id "apPk3AgfiZclygrb6nkFJAAAA2w"]
[Sun Aug 30 03:07:56.898246 2026] [security2:error] [pid 504660:tid 504893] [client 34.125.55.247:46316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/internal/.env"] [unique_id "apPk3AgfiZclygrb6nkFJQAAA1M"]
[Sun Aug 30 03:07:56.898350 2026] [security2:error] [pid 504660:tid 504893] [client 34.125.55.247:46316] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/internal/.env"] [unique_id "apPk3AgfiZclygrb6nkFJQAAA1M"]
[Sun Aug 30 03:07:56.898952 2026] [security2:error] [pid 504660:tid 504925] [client 34.125.55.247:46468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.55.125.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.engaginggoddaily.com"] [uri "/config/env.php"] [unique_id "apPk3AgfiZclygrb6nkFKAAAA3M"]
[Sun Aug 30 03:07:56.899246 2026] [security2:error] [pid 504660:tid 504920] [client 34.125.55.247:46508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/apps/backend/.env"] [unique_id "apPk3AgfiZclygrb6nkFJwAAA24"]
[Sun Aug 30 03:07:56.899382 2026] [security2:error] [pid 504660:tid 504940] [client 34.125.55.247:46336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/app/backend/.env"] [unique_id "apPk3AgfiZclygrb6nkFJgAAA4I"]
[Sun Aug 30 03:07:56.899397 2026] [security2:error] [pid 504660:tid 504867] [client 52.139.37.240:25779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/.trash7206/index.php"] [unique_id "apPk3AgfiZclygrb6nkFKQAAAzk"]
[Sun Aug 30 03:07:56.899423 2026] [security2:error] [pid 504660:tid 504847] [client 20.104.18.15:51611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/8.php"] [unique_id "apPk3AgfiZclygrb6nkFKgAAAyU"]
[Sun Aug 30 03:07:56.899602 2026] [security2:error] [pid 504660:tid 504914] [client 34.125.55.247:46492] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.engaginggoddaily.com"] [uri "/config/credentials.json"] [unique_id "apPk3AgfiZclygrb6nkFKwAAA2g"]
[Sun Aug 30 03:07:56.901143 2026] [security2:error] [pid 504660:tid 504850] [client 34.125.55.247:46386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/backend/api/.env"] [unique_id "apPk3AgfiZclygrb6nkFLwAAAyg"]
[Sun Aug 30 03:07:56.901302 2026] [security2:error] [pid 504660:tid 504842] [client 34.125.55.247:46452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/database/.env"] [unique_id "apPk3AgfiZclygrb6nkFMAAAAyA"]
[Sun Aug 30 03:07:56.902533 2026] [security2:error] [pid 504660:tid 504902] [client 20.48.251.3:44358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/adminfus.php"] [unique_id "apPk3AgfiZclygrb6nkFNAAAA1w"]
[Sun Aug 30 03:07:56.902810 2026] [security2:error] [pid 504660:tid 504895] [client 34.125.55.247:46330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/app/api/.env"] [unique_id "apPk3AgfiZclygrb6nkFMwAAA1U"]
[Sun Aug 30 03:07:56.903433 2026] [proxy_http:error] [pid 504660:tid 504926] (20014)Internal error (specific information not available): [client 34.125.55.247:46218] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:56.903443 2026] [proxy:error] [pid 504660:tid 504926] [client 34.125.55.247:46218] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/config/stripe.json
[Sun Aug 30 03:07:56.905430 2026] [security2:error] [pid 504660:tid 504956] [client 34.125.55.247:46432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.engaginggoddaily.com"] [uri "/apps/api/.env"] [unique_id "apPk3AgfiZclygrb6nkFOwAAA5I"]
[Sun Aug 30 03:07:56.906033 2026] [security2:error] [pid 504660:tid 504848] [client 52.139.37.240:32145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webio7.com"] [uri "/wp-content/packed.php"] [unique_id "apPk3AgfiZclygrb6nkFPAAAAyY"]
[Sun Aug 30 03:07:56.907431 2026] [authz_core:error] [pid 504660:tid 504900] [client 216.73.216.128:52542] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:56.907720 2026] [authz_core:error] [pid 504660:tid 504900] [client 216.73.216.128:52542] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:56.911068 2026] [proxy_http:error] [pid 504660:tid 504919] (20014)Internal error (specific information not available): [client 34.125.55.247:46382] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:56.911082 2026] [proxy:error] [pid 504660:tid 504919] [client 34.125.55.247:46382] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/src/.env.production
[Sun Aug 30 03:07:56.917783 2026] [proxy_http:error] [pid 504660:tid 504872] (20014)Internal error (specific information not available): [client 34.125.55.247:46368] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:56.917800 2026] [proxy:error] [pid 504660:tid 504872] [client 34.125.55.247:46368] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/frontend/.env.local
[Sun Aug 30 03:07:56.920211 2026] [authz_core:error] [pid 504660:tid 504896] [client 66.249.66.194:36737] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:56.920563 2026] [authz_core:error] [pid 504660:tid 504896] [client 66.249.66.194:36737] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:56.924368 2026] [proxy_http:error] [pid 504660:tid 504926] (20014)Internal error (specific information not available): [client 34.125.55.247:46218] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:56.924385 2026] [proxy:error] [pid 504660:tid 504926] [client 34.125.55.247:46218] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml
[Sun Aug 30 03:07:56.927148 2026] [security2:error] [pid 504660:tid 504856] [client 20.104.18.15:29073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/w.php"] [unique_id "apPk3AgfiZclygrb6nkFRQAAAy4"]
[Sun Aug 30 03:07:56.930589 2026] [proxy_http:error] [pid 504660:tid 504861] (20014)Internal error (specific information not available): [client 34.125.55.247:46402] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:56.930602 2026] [proxy:error] [pid 504660:tid 504861] [client 34.125.55.247:46402] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/src/.env.local
[Sun Aug 30 03:07:56.936529 2026] [security2:error] [pid 504660:tid 504928] [client 34.125.55.247:46416] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/server/.env.production"] [unique_id "apPk3AgfiZclygrb6nkFOQAAA3Y"]
[Sun Aug 30 03:07:56.936598 2026] [proxy_http:error] [pid 504660:tid 504871] (20014)Internal error (specific information not available): [client 34.125.55.247:46420] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:56.936614 2026] [proxy:error] [pid 504660:tid 504871] [client 34.125.55.247:46420] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/server/.env.local
[Sun Aug 30 03:07:56.940969 2026] [security2:error] [pid 504660:tid 504875] [client 4.205.62.107:36610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/xa.php"] [unique_id "apPk3AgfiZclygrb6nkFSQAAA0E"]
[Sun Aug 30 03:07:56.941454 2026] [security2:error] [pid 504660:tid 504844] [client 74.248.24.12:5225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/h.php"] [unique_id "apPk3AgfiZclygrb6nkFSgAAAyI"]
[Sun Aug 30 03:07:56.942208 2026] [proxy_http:error] [pid 504660:tid 504883] (20014)Internal error (specific information not available): [client 34.125.55.247:46512] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:07:56.942218 2026] [proxy:error] [pid 504660:tid 504883] [client 34.125.55.247:46512] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/config/env.json
[Sun Aug 30 03:07:56.966350 2026] [security2:error] [pid 504660:tid 504943] [client 20.197.61.180:19064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/cloud.php"] [unique_id "apPk3AgfiZclygrb6nkFTwAAA4U"]
[Sun Aug 30 03:07:56.979091 2026] [security2:error] [pid 504660:tid 504931] [client 158.23.184.117:18569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/min.php"] [unique_id "apPk3AgfiZclygrb6nkFUwAAA3k"]
[Sun Aug 30 03:07:57.028110 2026] [security2:error] [pid 504660:tid 504903] [client 20.104.50.220:61992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wsanon.php"] [unique_id "apPk3QgfiZclygrb6nkFXwAAA10"]
[Sun Aug 30 03:07:57.059210 2026] [security2:error] [pid 504660:tid 504904] [client 20.48.250.41:18383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/w1px.php"] [unique_id "apPk3QgfiZclygrb6nkFZAAAA14"]
[Sun Aug 30 03:07:57.074331 2026] [authz_core:error] [pid 504660:tid 504881] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AU
[Sun Aug 30 03:07:57.074722 2026] [authz_core:error] [pid 504660:tid 504881] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AU
[Sun Aug 30 03:07:57.117415 2026] [security2:error] [pid 504660:tid 504841] [client 52.139.37.240:49884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/storage/index.php"] [unique_id "apPk3QgfiZclygrb6nkFbQAAAx8"]
[Sun Aug 30 03:07:57.119096 2026] [security2:error] [pid 504660:tid 504951] [client 158.23.184.117:18456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/options.php"] [unique_id "apPk3QgfiZclygrb6nkFcAAAA40"]
[Sun Aug 30 03:07:57.123603 2026] [authz_core:error] [pid 504660:tid 504928] [client 66.249.66.41:48514] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:57.123933 2026] [authz_core:error] [pid 504660:tid 504928] [client 66.249.66.41:48514] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:57.167762 2026] [security2:error] [pid 504660:tid 504967] [client 65.108.6.34:36362] ModSecurity: Warning. Matched phrase "SEOkicks" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "flashflooring.co.uk"] [uri "/index.php"] [unique_id "apPk3AgfiZclygrb6nkE0gAAA50"], referer: https://flashflooring.co.uk/sitemap_index.xml
[Sun Aug 30 03:07:57.177026 2026] [security2:error] [pid 504660:tid 504852] [client 20.104.49.130:48571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/sta.php"] [unique_id "apPk3QgfiZclygrb6nkFeQAAAyo"]
[Sun Aug 30 03:07:57.193574 2026] [security2:error] [pid 504660:tid 504939] [client 20.48.250.41:18332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/to.php"] [unique_id "apPk3QgfiZclygrb6nkFfQAAA4E"]
[Sun Aug 30 03:07:57.226241 2026] [security2:error] [pid 504660:tid 504902] [client 20.151.200.44:57907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/dehnl.php"] [unique_id "apPk3QgfiZclygrb6nkFiwAAA1w"]
[Sun Aug 30 03:07:57.258766 2026] [security2:error] [pid 504660:tid 504890] [client 158.23.184.117:18737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/pk.php"] [unique_id "apPk3QgfiZclygrb6nkFkAAAA1A"]
[Sun Aug 30 03:07:57.284685 2026] [security2:error] [pid 504660:tid 504950] [client 4.205.62.107:32497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/txets.php"] [unique_id "apPk3QgfiZclygrb6nkFmgAAA4w"]
[Sun Aug 30 03:07:57.309559 2026] [security2:error] [pid 504660:tid 504848] [client 52.139.37.240:25733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPk3QgfiZclygrb6nkFoAAAAyY"]
[Sun Aug 30 03:07:57.356485 2026] [security2:error] [pid 504660:tid 504853] [client 40.83.93.50:17585] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "lydialovegrave.com"] [uri "/1.php"] [unique_id "apPk3QgfiZclygrb6nkFsAAAAys"]
[Sun Aug 30 03:07:57.356612 2026] [security2:error] [pid 504660:tid 504853] [client 40.83.93.50:17585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/1.php"] [unique_id "apPk3QgfiZclygrb6nkFsAAAAys"]
[Sun Aug 30 03:07:57.368802 2026] [security2:error] [pid 504660:tid 504946] [client 20.48.250.41:18362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/thui.php"] [unique_id "apPk3QgfiZclygrb6nkFswAAA4g"]
[Sun Aug 30 03:07:57.400691 2026] [security2:error] [pid 504660:tid 504912] [client 158.23.184.117:18598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/cgi-bin/cgi-bin/cgi-bin/index.php"] [unique_id "apPk3QgfiZclygrb6nkFtwAAA2Y"]
[Sun Aug 30 03:07:57.452590 2026] [security2:error] [pid 504660:tid 504904] [client 74.248.24.12:10295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/ms-edit.php"] [unique_id "apPk3QgfiZclygrb6nkFuwAAA14"]
[Sun Aug 30 03:07:57.501291 2026] [security2:error] [pid 504660:tid 504881] [client 52.139.37.240:48736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/wp-blog.php"] [unique_id "apPk3QgfiZclygrb6nkFwwAAA0c"]
[Sun Aug 30 03:07:57.505771 2026] [security2:error] [pid 504660:tid 504883] [client 20.104.49.130:65217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/albin.php"] [unique_id "apPk3QgfiZclygrb6nkFxgAAA0k"]
[Sun Aug 30 03:07:57.545037 2026] [security2:error] [pid 504660:tid 504845] [client 158.23.184.117:18586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/cgi-bin/index.php"] [unique_id "apPk3QgfiZclygrb6nkF1gAAAyM"]
[Sun Aug 30 03:07:57.575756 2026] [security2:error] [pid 504660:tid 504902] [client 20.104.49.130:52519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/log.php"] [unique_id "apPk3QgfiZclygrb6nkF3QAAA1w"]
[Sun Aug 30 03:07:57.586015 2026] [authz_core:error] [pid 504660:tid 504920] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NG
[Sun Aug 30 03:07:57.586431 2026] [authz_core:error] [pid 504660:tid 504920] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NG
[Sun Aug 30 03:07:57.625573 2026] [security2:error] [pid 504660:tid 504961] [client 20.48.251.3:6474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/zaza.php"] [unique_id "apPk3QgfiZclygrb6nkF6QAAA5c"]
[Sun Aug 30 03:07:57.635539 2026] [security2:error] [pid 504660:tid 504951] [client 20.48.250.41:18430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/Jcrop.php"] [unique_id "apPk3QgfiZclygrb6nkF7wAAA40"]
[Sun Aug 30 03:07:57.671345 2026] [security2:error] [pid 504660:tid 504849] [client 68.155.159.216:45972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/simple.php"] [unique_id "apPk3QgfiZclygrb6nkF9AAAAyc"]
[Sun Aug 30 03:07:57.684708 2026] [security2:error] [pid 504660:tid 504856] [client 158.23.184.117:18575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/cgi-bin/load.php"] [unique_id "apPk3QgfiZclygrb6nkF_AAAAy4"]
[Sun Aug 30 03:07:57.689310 2026] [security2:error] [pid 504660:tid 504959] [client 20.197.61.180:19021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/admin.php"] [unique_id "apPk3QgfiZclygrb6nkGAQAAA5U"]
[Sun Aug 30 03:07:57.693923 2026] [security2:error] [pid 504660:tid 504901] [client 52.139.37.240:48741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/xmlrpc.php"] [unique_id "apPk3QgfiZclygrb6nkGAgAAA1s"]
[Sun Aug 30 03:07:57.698810 2026] [security2:error] [pid 504660:tid 504928] [client 20.151.200.44:47012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/admin.php/pindex.php"] [unique_id "apPk3QgfiZclygrb6nkGAwAAA3Y"]
[Sun Aug 30 03:07:57.731816 2026] [authz_core:error] [pid 504660:tid 504957] [client 216.73.216.128:20684] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:57.732201 2026] [authz_core:error] [pid 504660:tid 504957] [client 216.73.216.128:20684] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:57.753450 2026] [security2:error] [pid 504660:tid 504949] [client 68.155.159.216:60879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/about/function.php"] [unique_id "apPk3QgfiZclygrb6nkGDwAAA4s"]
[Sun Aug 30 03:07:57.803441 2026] [security2:error] [pid 504660:tid 504908] [client 20.48.250.41:18354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/ws58.php"] [unique_id "apPk3QgfiZclygrb6nkGHQAAA2I"]
[Sun Aug 30 03:07:57.811315 2026] [security2:error] [pid 504660:tid 504870] [client 216.73.216.128:52542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/'+this.controller.state().get("] [unique_id "apPk3QgfiZclygrb6nkGIwAAAzw"]
[Sun Aug 30 03:07:57.823115 2026] [security2:error] [pid 504660:tid 504862] [client 158.23.184.117:18460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/cgi-bin/ms-files.php"] [unique_id "apPk3QgfiZclygrb6nkGJwAAAzQ"]
[Sun Aug 30 03:07:57.827685 2026] [security2:error] [pid 504660:tid 504853] [client 68.155.159.216:55060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apPk3QgfiZclygrb6nkGLQAAAys"]
[Sun Aug 30 03:07:57.841765 2026] [security2:error] [pid 504660:tid 504893] [client 68.155.159.216:63508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-admin/setup-config.php"] [unique_id "apPk3QgfiZclygrb6nkGMwAAA1M"]
[Sun Aug 30 03:07:57.867800 2026] [security2:error] [pid 504660:tid 504949] [client 4.205.62.107:62093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/rpk.php"] [unique_id "apPk3QgfiZclygrb6nkGNgAAA4s"]
[Sun Aug 30 03:07:57.869955 2026] [security2:error] [pid 504660:tid 504933] [client 20.104.50.220:27251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getanswer-rb.socalhomessouthbay.com"] [uri "/View.php"] [unique_id "apPk3QgfiZclygrb6nkGNwAAA3s"]
[Sun Aug 30 03:07:57.885324 2026] [security2:error] [pid 504660:tid 504881] [client 52.139.37.240:25751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/lu4.php"] [unique_id "apPk3QgfiZclygrb6nkGPgAAA0c"]
[Sun Aug 30 03:07:57.890899 2026] [authz_core:error] [pid 504660:tid 504900] [client 66.249.66.204:44442] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:57.891042 2026] [security2:error] [pid 504660:tid 504892] [client 40.83.93.50:17596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/as.php"] [unique_id "apPk3QgfiZclygrb6nkGPwAAA1I"]
[Sun Aug 30 03:07:57.891217 2026] [authz_core:error] [pid 504660:tid 504900] [client 66.249.66.204:44442] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:57.897665 2026] [security2:error] [pid 504660:tid 504929] [client 20.48.251.3:56376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/sys.php"] [unique_id "apPk3QgfiZclygrb6nkGRAAAA3c"]
[Sun Aug 30 03:07:57.908761 2026] [security2:error] [pid 504660:tid 504844] [client 20.104.18.15:28662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/beence.php"] [unique_id "apPk3QgfiZclygrb6nkGTgAAAyI"]
[Sun Aug 30 03:07:57.914414 2026] [security2:error] [pid 504660:tid 504959] [client 20.104.50.220:5915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/42.php"] [unique_id "apPk3QgfiZclygrb6nkGUwAAA5U"]
[Sun Aug 30 03:07:57.917449 2026] [security2:error] [pid 504660:tid 504853] [client 68.155.159.216:56352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/worksec.php"] [unique_id "apPk3QgfiZclygrb6nkGVwAAAys"]
[Sun Aug 30 03:07:57.922036 2026] [security2:error] [pid 504660:tid 504958] [client 20.104.50.220:46148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/file21.php"] [unique_id "apPk3QgfiZclygrb6nkGWQAAA5Q"]
[Sun Aug 30 03:07:57.922602 2026] [security2:error] [pid 504660:tid 504880] [client 20.104.50.220:33037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/xltavrat.php"] [unique_id "apPk3QgfiZclygrb6nkGWgAAA0Y"]
[Sun Aug 30 03:07:57.925923 2026] [security2:error] [pid 504660:tid 504847] [client 20.104.18.15:23362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/goods.php"] [unique_id "apPk3QgfiZclygrb6nkGXAAAAyU"]
[Sun Aug 30 03:07:57.935376 2026] [security2:error] [pid 504660:tid 504957] [client 20.104.50.220:28686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/FX.php"] [unique_id "apPk3QgfiZclygrb6nkGXwAAA5M"]
[Sun Aug 30 03:07:57.935435 2026] [security2:error] [pid 504660:tid 504890] [client 20.48.250.41:18252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/xs.php"] [unique_id "apPk3QgfiZclygrb6nkGYAAAA1A"]
[Sun Aug 30 03:07:57.935738 2026] [security2:error] [pid 504660:tid 504913] [client 20.104.50.220:52851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/bypass.php"] [unique_id "apPk3QgfiZclygrb6nkGYgAAA2c"]
[Sun Aug 30 03:07:57.949505 2026] [security2:error] [pid 504660:tid 504938] [client 20.104.50.220:31925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-system.php"] [unique_id "apPk3QgfiZclygrb6nkGZgAAA4A"]
[Sun Aug 30 03:07:57.963290 2026] [security2:error] [pid 504660:tid 504876] [client 20.104.50.220:42442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/MKY.php"] [unique_id "apPk3QgfiZclygrb6nkGaQAAA0I"]
[Sun Aug 30 03:07:57.963321 2026] [security2:error] [pid 504660:tid 504852] [client 158.23.184.117:18449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/cgi-bin/wp-activate.php"] [unique_id "apPk3QgfiZclygrb6nkGaAAAAyo"]
[Sun Aug 30 03:07:57.983812 2026] [security2:error] [pid 504660:tid 504848] [client 4.205.62.107:64683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/ccou.php"] [unique_id "apPk3QgfiZclygrb6nkGcQAAAyY"]
[Sun Aug 30 03:07:57.987635 2026] [security2:error] [pid 504660:tid 504960] [client 68.155.159.216:12365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apPk3QgfiZclygrb6nkGdAAAA5Y"]
[Sun Aug 30 03:07:57.989135 2026] [security2:error] [pid 504660:tid 504943] [client 20.104.18.15:34701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/t3.php"] [unique_id "apPk3QgfiZclygrb6nkGdgAAA4U"]
[Sun Aug 30 03:07:57.989608 2026] [security2:error] [pid 504660:tid 504844] [client 68.155.159.216:64773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/nf_tracking.php"] [unique_id "apPk3QgfiZclygrb6nkGdQAAAyI"]
[Sun Aug 30 03:07:58.011142 2026] [security2:error] [pid 504660:tid 504880] [client 20.104.18.15:35462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPk3ggfiZclygrb6nkGfwAAA0Y"]
[Sun Aug 30 03:07:58.013841 2026] [security2:error] [pid 504660:tid 504850] [client 20.104.50.220:16709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/themes.php"] [unique_id "apPk3ggfiZclygrb6nkGggAAAyg"]
[Sun Aug 30 03:07:58.016822 2026] [security2:error] [pid 504660:tid 504903] [client 4.205.62.107:62425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/cloud.php"] [unique_id "apPk3ggfiZclygrb6nkGgwAAA10"]
[Sun Aug 30 03:07:58.022244 2026] [security2:error] [pid 504660:tid 504914] [client 74.248.24.12:11726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/a7.php"] [unique_id "apPk3ggfiZclygrb6nkGhQAAA2g"]
[Sun Aug 30 03:07:58.024101 2026] [security2:error] [pid 504660:tid 504890] [client 20.104.18.15:18315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/503.php"] [unique_id "apPk3ggfiZclygrb6nkGhwAAA1A"]
[Sun Aug 30 03:07:58.053326 2026] [security2:error] [pid 504660:tid 504852] [client 20.104.18.15:51677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/ws55.php"] [unique_id "apPk3ggfiZclygrb6nkGjwAAAyo"]
[Sun Aug 30 03:07:58.055893 2026] [security2:error] [pid 504660:tid 504926] [client 4.205.62.107:18652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/agg.php"] [unique_id "apPk3ggfiZclygrb6nkGkQAAA3Q"]
[Sun Aug 30 03:07:58.073633 2026] [authz_core:error] [pid 504660:tid 504848] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_SG
[Sun Aug 30 03:07:58.074105 2026] [authz_core:error] [pid 504660:tid 504848] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_SG
[Sun Aug 30 03:07:58.078081 2026] [security2:error] [pid 504660:tid 504963] [client 52.139.37.240:25764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "apPk3ggfiZclygrb6nkGlwAAA5k"]
[Sun Aug 30 03:07:58.083144 2026] [security2:error] [pid 504660:tid 504873] [client 4.205.62.107:36675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/ws61.php"] [unique_id "apPk3ggfiZclygrb6nkGmAAAAz8"]
[Sun Aug 30 03:07:58.099185 2026] [security2:error] [pid 504660:tid 504915] [client 20.104.18.15:29649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/x.php"] [unique_id "apPk3ggfiZclygrb6nkGnQAAA2k"]
[Sun Aug 30 03:07:58.104141 2026] [security2:error] [pid 504660:tid 504840] [client 158.23.184.117:18453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/cgi-bin/wp-load.php"] [unique_id "apPk3ggfiZclygrb6nkGnwAAAx4"]
[Sun Aug 30 03:07:58.143510 2026] [authz_core:error] [pid 504660:tid 504850] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:58.143839 2026] [authz_core:error] [pid 504660:tid 504850] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:58.148610 2026] [security2:error] [pid 504660:tid 504950] [client 114.119.139.251:36393] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "paulgarrigan.com"] [uri "/is-neuroscience-wrong-about-addiction/"] [unique_id "apPk3ggfiZclygrb6nkGpgAAA4w"], referer: https://paulgarrigan.com/are-12-step-recovery-programs-best-for-addicts/
[Sun Aug 30 03:07:58.157574 2026] [security2:error] [pid 504660:tid 504903] [client 20.48.250.41:18359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/zu.php"] [unique_id "apPk3ggfiZclygrb6nkGpwAAA10"]
[Sun Aug 30 03:07:58.173615 2026] [security2:error] [pid 504660:tid 504864] [client 178.16.55.109:59291] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "neilgclark.com"] [uri "/index.php"] [unique_id "apPk3ggfiZclygrb6nkGrAAAAzY"]
[Sun Aug 30 03:07:58.183850 2026] [security2:error] [pid 504660:tid 504863] [client 20.104.50.220:59568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/Alfa.php"] [unique_id "apPk3ggfiZclygrb6nkGsgAAAzU"]
[Sun Aug 30 03:07:58.243908 2026] [security2:error] [pid 504660:tid 504954] [client 158.23.184.117:18436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/cgi-bin/wp-mail.php"] [unique_id "apPk3ggfiZclygrb6nkG4QAAA5A"]
[Sun Aug 30 03:07:58.271636 2026] [security2:error] [pid 504660:tid 504875] [client 52.139.37.240:49897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "apPk3ggfiZclygrb6nkG8wAAA0E"]
[Sun Aug 30 03:07:58.276237 2026] [authz_core:error] [pid 504660:tid 504935] [client 216.73.216.128:29681] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:58.276548 2026] [authz_core:error] [pid 504660:tid 504935] [client 216.73.216.128:29681] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:58.287629 2026] [security2:error] [pid 504660:tid 504842] [client 20.48.251.3:5112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/avim.php"] [unique_id "apPk3ggfiZclygrb6nkG-AAAAyA"]
[Sun Aug 30 03:07:58.297563 2026] [security2:error] [pid 504660:tid 504964] [client 20.151.200.44:57820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/png.php"] [unique_id "apPk3ggfiZclygrb6nkG_wAAA5o"]
[Sun Aug 30 03:07:58.326995 2026] [security2:error] [pid 504660:tid 504922] [client 20.48.250.41:18413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/lanka.php"] [unique_id "apPk3ggfiZclygrb6nkHBwAAA3A"]
[Sun Aug 30 03:07:58.349305 2026] [security2:error] [pid 504660:tid 504950] [client 20.151.200.44:46921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/admin.php/csv.php"] [unique_id "apPk3ggfiZclygrb6nkHGAAAA4w"]
[Sun Aug 30 03:07:58.385535 2026] [security2:error] [pid 504660:tid 504866] [client 158.23.184.117:18588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "apPk3ggfiZclygrb6nkHKwAAAzg"]
[Sun Aug 30 03:07:58.387213 2026] [security2:error] [pid 504660:tid 504903] [client 40.83.93.50:17590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/credits.php"] [unique_id "apPk3ggfiZclygrb6nkHLAAAA10"]
[Sun Aug 30 03:07:58.414490 2026] [authz_core:error] [pid 504660:tid 504853] [client 66.249.66.44:43360] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:58.414944 2026] [authz_core:error] [pid 504660:tid 504853] [client 66.249.66.44:43360] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:58.463956 2026] [security2:error] [pid 504660:tid 504958] [client 20.197.61.180:19019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/index.php"] [unique_id "apPk3ggfiZclygrb6nkHdAAAA5Q"]
[Sun Aug 30 03:07:58.464927 2026] [security2:error] [pid 504660:tid 504889] [client 52.139.37.240:48753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "apPk3ggfiZclygrb6nkHdQAAA08"]
[Sun Aug 30 03:07:58.484998 2026] [security2:error] [pid 504660:tid 504875] [client 20.48.250.41:18342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/gettest.php"] [unique_id "apPk3ggfiZclygrb6nkHfgAAA0E"]
[Sun Aug 30 03:07:58.533514 2026] [security2:error] [pid 504660:tid 504957] [client 158.23.184.117:18444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/chosen.php"] [unique_id "apPk3ggfiZclygrb6nkHoQAAA5M"]
[Sun Aug 30 03:07:58.543029 2026] [security2:error] [pid 504660:tid 504871] [client 74.248.24.12:14447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/manager.php"] [unique_id "apPk3ggfiZclygrb6nkHpwAAAz0"]
[Sun Aug 30 03:07:58.579037 2026] [authz_core:error] [pid 504660:tid 504883] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AU
[Sun Aug 30 03:07:58.579522 2026] [authz_core:error] [pid 504660:tid 504883] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AU
[Sun Aug 30 03:07:58.642850 2026] [security2:error] [pid 504660:tid 504852] [client 20.48.250.41:18361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/35.php"] [unique_id "apPk3ggfiZclygrb6nkH3AAAAyo"]
[Sun Aug 30 03:07:58.661197 2026] [security2:error] [pid 504660:tid 504885] [client 52.139.37.240:48739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/ant.php"] [unique_id "apPk3ggfiZclygrb6nkH4QAAA0s"]
[Sun Aug 30 03:07:58.696389 2026] [security2:error] [pid 504660:tid 504967] [client 20.104.49.130:59544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/xwpg.php"] [unique_id "apPk3ggfiZclygrb6nkH8wAAA50"]
[Sun Aug 30 03:07:58.728279 2026] [security2:error] [pid 504660:tid 504853] [client 158.23.184.117:18576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/class-wp-logo-new.php"] [unique_id "apPk3ggfiZclygrb6nkIFQAAAys"]
[Sun Aug 30 03:07:58.737796 2026] [security2:error] [pid 504660:tid 504933] [client 20.104.49.130:45698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/sta.php"] [unique_id "apPk3ggfiZclygrb6nkIIQAAA3s"]
[Sun Aug 30 03:07:58.792204 2026] [authz_core:error] [pid 504660:tid 504894] [client 216.73.216.128:28110] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:58.792510 2026] [authz_core:error] [pid 504660:tid 504894] [client 216.73.216.128:28110] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:58.798364 2026] [security2:error] [pid 504660:tid 504938] [client 20.48.250.41:18371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/maraz.php"] [unique_id "apPk3ggfiZclygrb6nkIPAAAA4A"]
[Sun Aug 30 03:07:58.808843 2026] [security2:error] [pid 504660:tid 504967] [client 20.48.251.3:7387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/u88.php"] [unique_id "apPk3ggfiZclygrb6nkIQQAAA50"]
[Sun Aug 30 03:07:58.836273 2026] [authz_core:error] [pid 504660:tid 504872] [client 216.73.216.128:65420] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:58.836759 2026] [authz_core:error] [pid 504660:tid 504872] [client 216.73.216.128:65420] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:58.848746 2026] [security2:error] [pid 504660:tid 504927] [client 68.155.159.216:45964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-admin/about.php"] [unique_id "apPk3ggfiZclygrb6nkITgAAA3U"]
[Sun Aug 30 03:07:58.869072 2026] [security2:error] [pid 504660:tid 504843] [client 20.151.200.44:46942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/admin.php/700.php"] [unique_id "apPk3ggfiZclygrb6nkIUQAAAyE"]
[Sun Aug 30 03:07:58.869073 2026] [security2:error] [pid 504660:tid 504860] [client 178.16.55.109:62032] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "neilgclark.com"] [uri "/index.php"] [unique_id "apPk3ggfiZclygrb6nkIUgAAAzI"]
[Sun Aug 30 03:07:58.870352 2026] [security2:error] [pid 504660:tid 504903] [client 158.23.184.117:18579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/classwithtostring.php"] [unique_id "apPk3ggfiZclygrb6nkIUwAAA10"]
[Sun Aug 30 03:07:58.870992 2026] [security2:error] [pid 504660:tid 504928] [client 52.139.37.240:48768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/autoload_classmap.php"] [unique_id "apPk3ggfiZclygrb6nkIVAAAA3Y"]
[Sun Aug 30 03:07:58.898536 2026] [security2:error] [pid 504660:tid 504905] [client 40.83.93.50:13777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/cache.php"] [unique_id "apPk3ggfiZclygrb6nkIWwAAA18"]
[Sun Aug 30 03:07:58.935060 2026] [security2:error] [pid 504660:tid 504939] [client 20.48.250.41:18278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/kbfr.php"] [unique_id "apPk3ggfiZclygrb6nkIaAAAA4E"]
[Sun Aug 30 03:07:58.966811 2026] [security2:error] [pid 504660:tid 504863] [client 68.155.159.216:61650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apPk3ggfiZclygrb6nkIcQAAAzU"]
[Sun Aug 30 03:07:58.968727 2026] [security2:error] [pid 504660:tid 504964] [client 158.23.147.79:58384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPk3ggfiZclygrb6nkIcgAAA5o"]
[Sun Aug 30 03:07:58.985655 2026] [security2:error] [pid 504660:tid 504888] [client 4.205.62.107:32052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/time.php"] [unique_id "apPk3ggfiZclygrb6nkIegAAA04"]
[Sun Aug 30 03:07:59.000473 2026] [security2:error] [pid 504660:tid 504844] [client 68.155.159.216:55167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/classwithtostring.php"] [unique_id "apPk3ggfiZclygrb6nkIfQAAAyI"]
[Sun Aug 30 03:07:59.011087 2026] [security2:error] [pid 504660:tid 504933] [client 158.23.184.117:18463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/cms.php"] [unique_id "apPk3wgfiZclygrb6nkIggAAA3s"]
[Sun Aug 30 03:07:59.011575 2026] [security2:error] [pid 504660:tid 504915] [client 4.205.62.107:62047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/saml.php"] [unique_id "apPk3wgfiZclygrb6nkIgwAAA2k"]
[Sun Aug 30 03:07:59.025237 2026] [security2:error] [pid 504660:tid 504955] [client 68.155.159.216:11176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/x.php"] [unique_id "apPk3wgfiZclygrb6nkIigAAA5E"]
[Sun Aug 30 03:07:59.038135 2026] [security2:error] [pid 504660:tid 504906] [client 20.48.251.3:33328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/phpsysinfo.php"] [unique_id "apPk3wgfiZclygrb6nkIjwAAA2A"]
[Sun Aug 30 03:07:59.044921 2026] [security2:error] [pid 504660:tid 504923] [client 20.104.18.15:28644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/222.php"] [unique_id "apPk3wgfiZclygrb6nkIkQAAA3E"]
[Sun Aug 30 03:07:59.059986 2026] [security2:error] [pid 504660:tid 504913] [client 20.104.50.220:32902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/12j.php"] [unique_id "apPk3wgfiZclygrb6nkIlgAAA2c"]
[Sun Aug 30 03:07:59.065553 2026] [security2:error] [pid 504660:tid 504842] [client 20.104.18.15:23529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/alfa.php"] [unique_id "apPk3wgfiZclygrb6nkIlwAAAyA"]
[Sun Aug 30 03:07:59.065582 2026] [security2:error] [pid 504660:tid 504914] [client 52.139.37.240:25752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/storage/rip.php"] [unique_id "apPk3wgfiZclygrb6nkImAAAA2g"]
[Sun Aug 30 03:07:59.066115 2026] [security2:error] [pid 504660:tid 504909] [client 20.104.50.220:5891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/41.php"] [unique_id "apPk3wgfiZclygrb6nkImQAAA2M"]
[Sun Aug 30 03:07:59.076825 2026] [security2:error] [pid 504660:tid 504856] [client 20.104.50.220:46177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/ut.php"] [unique_id "apPk3wgfiZclygrb6nkImgAAAy4"]
[Sun Aug 30 03:07:59.081931 2026] [security2:error] [pid 504660:tid 504924] [client 68.155.159.216:60918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apPk3wgfiZclygrb6nkImwAAA3I"]
[Sun Aug 30 03:07:59.082003 2026] [security2:error] [pid 504660:tid 504840] [client 74.248.24.12:2228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/w1.php"] [unique_id "apPk3wgfiZclygrb6nkInAAAAx4"]
[Sun Aug 30 03:07:59.084411 2026] [security2:error] [pid 504660:tid 504848] [client 20.48.250.41:18259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/wp-act.php"] [unique_id "apPk3wgfiZclygrb6nkInQAAAyY"]
[Sun Aug 30 03:07:59.092776 2026] [security2:error] [pid 504660:tid 504893] [client 68.155.159.216:12431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/packed.php"] [unique_id "apPk3wgfiZclygrb6nkIngAAA1M"]
[Sun Aug 30 03:07:59.099269 2026] [security2:error] [pid 504660:tid 504922] [client 114.119.129.22:60175] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.maarifado.com"] [uri "/shop/"] [unique_id "apPk3wgfiZclygrb6nkIowAAA3A"], referer: https://www.maarifado.com/shop/
[Sun Aug 30 03:07:59.102162 2026] [security2:error] [pid 504660:tid 504907] [client 20.104.50.220:32562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-title.php"] [unique_id "apPk3wgfiZclygrb6nkIpQAAA2E"]
[Sun Aug 30 03:07:59.109131 2026] [security2:error] [pid 504660:tid 504910] [client 158.23.147.79:60172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPk3wgfiZclygrb6nkIqAAAA2Q"]
[Sun Aug 30 03:07:59.137322 2026] [security2:error] [pid 504660:tid 504864] [client 68.155.159.216:64802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wzy.php"] [unique_id "apPk3wgfiZclygrb6nkIsAAAAzY"]
[Sun Aug 30 03:07:59.139390 2026] [security2:error] [pid 504660:tid 504928] [client 4.205.62.107:64490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/rum.or.php"] [unique_id "apPk3wgfiZclygrb6nkIsQAAA3Y"]
[Sun Aug 30 03:07:59.141487 2026] [security2:error] [pid 504660:tid 504923] [client 20.104.18.15:34660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/wp.php"] [unique_id "apPk3wgfiZclygrb6nkItAAAA3E"]
[Sun Aug 30 03:07:59.148538 2026] [security2:error] [pid 504660:tid 504901] [client 20.104.50.220:62794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/w50.php"] [unique_id "apPk3wgfiZclygrb6nkItQAAA1s"]
[Sun Aug 30 03:07:59.151899 2026] [security2:error] [pid 504660:tid 504859] [client 158.23.184.117:18565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/config.php"] [unique_id "apPk3wgfiZclygrb6nkItgAAAzE"]
[Sun Aug 30 03:07:59.153369 2026] [security2:error] [pid 504660:tid 504944] [client 20.104.18.15:35510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/wsd.php"] [unique_id "apPk3wgfiZclygrb6nkItwAAA4Y"]
[Sun Aug 30 03:07:59.162682 2026] [security2:error] [pid 504660:tid 504845] [client 20.104.50.220:42441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/xl33t.php"] [unique_id "apPk3wgfiZclygrb6nkIugAAAyM"]
[Sun Aug 30 03:07:59.163097 2026] [security2:error] [pid 504660:tid 504921] [client 20.104.50.220:29147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/ga.php"] [unique_id "apPk3wgfiZclygrb6nkIvAAAA28"]
[Sun Aug 30 03:07:59.163130 2026] [security2:error] [pid 504660:tid 504945] [client 4.205.62.107:62310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/asdf.php"] [unique_id "apPk3wgfiZclygrb6nkIuwAAA4c"]
[Sun Aug 30 03:07:59.163747 2026] [security2:error] [pid 504660:tid 504913] [client 20.104.50.220:17220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/dx.php"] [unique_id "apPk3wgfiZclygrb6nkIvQAAA2c"]
[Sun Aug 30 03:07:59.188309 2026] [security2:error] [pid 504660:tid 504874] [client 20.104.18.15:18331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/504.php"] [unique_id "apPk3wgfiZclygrb6nkIzAAAA0A"]
[Sun Aug 30 03:07:59.192634 2026] [security2:error] [pid 504660:tid 504892] [client 20.104.18.15:51590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/indo.php"] [unique_id "apPk3wgfiZclygrb6nkIzgAAA1I"]
[Sun Aug 30 03:07:59.200591 2026] [authz_core:error] [pid 504660:tid 504868] [client 216.73.216.128:40000] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:59.201087 2026] [authz_core:error] [pid 504660:tid 504868] [client 216.73.216.128:40000] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:59.207264 2026] [security2:error] [pid 504660:tid 504879] [client 20.197.61.180:10447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/php8.php"] [unique_id "apPk3wgfiZclygrb6nkI0QAAA0U"]
[Sun Aug 30 03:07:59.222411 2026] [authz_core:error] [pid 504660:tid 504955] [client 66.249.66.44:43360] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:59.222864 2026] [authz_core:error] [pid 504660:tid 504955] [client 66.249.66.44:43360] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:59.224082 2026] [authz_core:error] [pid 504660:tid 504958] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AG
[Sun Aug 30 03:07:59.224569 2026] [authz_core:error] [pid 504660:tid 504958] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AG
[Sun Aug 30 03:07:59.236892 2026] [security2:error] [pid 504660:tid 504859] [client 20.104.18.15:29133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apPk3wgfiZclygrb6nkI5AAAAzE"]
[Sun Aug 30 03:07:59.277146 2026] [security2:error] [pid 504660:tid 504967] [client 20.48.250.41:18260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/24.php"] [unique_id "apPk3wgfiZclygrb6nkI7gAAA50"]
[Sun Aug 30 03:07:59.283831 2026] [security2:error] [pid 504660:tid 504875] [client 52.139.37.240:49890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/tinyfilemanager.php"] [unique_id "apPk3wgfiZclygrb6nkI8wAAA0E"]
[Sun Aug 30 03:07:59.293657 2026] [security2:error] [pid 504660:tid 504939] [client 158.23.184.117:18493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/configs.php"] [unique_id "apPk3wgfiZclygrb6nkI-AAAA4E"]
[Sun Aug 30 03:07:59.309230 2026] [security2:error] [pid 504660:tid 504892] [client 4.205.62.107:36026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/xza.php"] [unique_id "apPk3wgfiZclygrb6nkI_QAAA1I"]
[Sun Aug 30 03:07:59.323564 2026] [security2:error] [pid 504660:tid 504904] [client 158.23.147.79:58396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apPk3wgfiZclygrb6nkJAQAAA14"]
[Sun Aug 30 03:07:59.424262 2026] [security2:error] [pid 504660:tid 504882] [client 20.48.251.3:4710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/nw.php"] [unique_id "apPk3wgfiZclygrb6nkJJAAAA0g"]
[Sun Aug 30 03:07:59.436104 2026] [security2:error] [pid 504660:tid 504890] [client 158.23.184.117:18706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/configuration.php"] [unique_id "apPk3wgfiZclygrb6nkJJQAAA1A"]
[Sun Aug 30 03:07:59.440410 2026] [security2:error] [pid 504660:tid 504957] [client 4.205.62.107:18679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/requirements.php"] [unique_id "apPk3wgfiZclygrb6nkJJwAAA5M"]
[Sun Aug 30 03:07:59.442267 2026] [security2:error] [pid 504660:tid 504862] [client 40.83.93.50:7844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/fix.php"] [unique_id "apPk3wgfiZclygrb6nkJKQAAAzQ"]
[Sun Aug 30 03:07:59.464682 2026] [security2:error] [pid 504660:tid 504908] [client 20.104.50.220:61658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-admin/includes/mailer.php.php"] [unique_id "apPk3wgfiZclygrb6nkJMgAAA2I"]
[Sun Aug 30 03:07:59.469409 2026] [security2:error] [pid 504660:tid 504943] [client 20.48.250.41:18287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/155.php"] [unique_id "apPk3wgfiZclygrb6nkJNAAAA4U"]
[Sun Aug 30 03:07:59.522934 2026] [security2:error] [pid 504660:tid 504870] [client 158.23.147.79:58373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apPk3wgfiZclygrb6nkJQAAAAzw"]
[Sun Aug 30 03:07:59.545297 2026] [security2:error] [pid 504660:tid 504929] [client 20.104.49.130:34546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/bdroot.php"] [unique_id "apPk3wgfiZclygrb6nkJSgAAA3c"]
[Sun Aug 30 03:07:59.556352 2026] [security2:error] [pid 504660:tid 504872] [client 216.73.216.128:20684] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPk3wgfiZclygrb6nkJUgAAAz4"]
[Sun Aug 30 03:07:59.572722 2026] [authz_core:error] [pid 504660:tid 504907] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:59.573185 2026] [authz_core:error] [pid 504660:tid 504907] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:07:59.577203 2026] [security2:error] [pid 504660:tid 504928] [client 158.23.184.117:18488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/content.php"] [unique_id "apPk3wgfiZclygrb6nkJWAAAA3Y"]
[Sun Aug 30 03:07:59.651343 2026] [security2:error] [pid 504660:tid 504844] [client 209.87.169.16:55325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.169.87.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jazzdreamz.com"] [uri "/wp-login.php"] [unique_id "apPk3wgfiZclygrb6nkJeAAAAyI"]
[Sun Aug 30 03:07:59.662770 2026] [security2:error] [pid 504660:tid 504951] [client 20.48.250.41:18429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/file.php"] [unique_id "apPk3wgfiZclygrb6nkJfAAAA40"]
[Sun Aug 30 03:07:59.674811 2026] [security2:error] [pid 504660:tid 504952] [client 74.248.24.12:21831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/wp-login.php"] [unique_id "apPk3wgfiZclygrb6nkJcgAAA44"]
[Sun Aug 30 03:07:59.676523 2026] [authz_core:error] [pid 504660:tid 504890] [client 66.249.66.194:36737] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:59.676997 2026] [authz_core:error] [pid 504660:tid 504890] [client 66.249.66.194:36737] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:59.717577 2026] [security2:error] [pid 504660:tid 504936] [client 158.23.184.117:18499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/core.php"] [unique_id "apPk3wgfiZclygrb6nkJkAAAA34"]
[Sun Aug 30 03:07:59.728784 2026] [authz_core:error] [pid 504660:tid 504860] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AU
[Sun Aug 30 03:07:59.729062 2026] [authz_core:error] [pid 504660:tid 504860] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AU
[Sun Aug 30 03:07:59.763721 2026] [security2:error] [pid 504660:tid 504849] [client 20.151.200.44:47051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/admin.php/007x.php"] [unique_id "apPk3wgfiZclygrb6nkJqAAAAyc"]
[Sun Aug 30 03:07:59.795100 2026] [security2:error] [pid 504660:tid 504939] [client 20.48.250.41:18330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPk3wgfiZclygrb6nkJsAAAA4E"]
[Sun Aug 30 03:07:59.802633 2026] [authz_core:error] [pid 504660:tid 504868] [client 66.249.66.78:47930] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:59.802948 2026] [authz_core:error] [pid 504660:tid 504868] [client 66.249.66.78:47930] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:59.843051 2026] [authz_core:error] [pid 504660:tid 504902] [client 216.73.216.128:40000] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:59.843502 2026] [authz_core:error] [pid 504660:tid 504902] [client 216.73.216.128:40000] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:59.858152 2026] [security2:error] [pid 504660:tid 504933] [client 158.23.184.117:18443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/data.php"] [unique_id "apPk3wgfiZclygrb6nkJzQAAA3s"]
[Sun Aug 30 03:07:59.863671 2026] [security2:error] [pid 504660:tid 504876] [client 158.23.147.79:60197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/simple.php"] [unique_id "apPk3wgfiZclygrb6nkJzgAAA0I"]
[Sun Aug 30 03:07:59.924514 2026] [security2:error] [pid 504660:tid 504915] [client 40.83.93.50:13761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/alfa.php"] [unique_id "apPk3wgfiZclygrb6nkJ4QAAA2k"]
[Sun Aug 30 03:07:59.924561 2026] [security2:error] [pid 504660:tid 504847] [client 20.48.250.41:18275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/06.php"] [unique_id "apPk3wgfiZclygrb6nkJ4gAAAyU"]
[Sun Aug 30 03:07:59.925906 2026] [security2:error] [pid 504660:tid 504911] [client 20.197.61.180:19054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/function.php"] [unique_id "apPk3wgfiZclygrb6nkJ4wAAA2U"]
[Sun Aug 30 03:07:59.935061 2026] [authz_core:error] [pid 504660:tid 504930] [client 216.73.216.128:28110] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:59.935347 2026] [authz_core:error] [pid 504660:tid 504930] [client 216.73.216.128:28110] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:59.938202 2026] [authz_core:error] [pid 504660:tid 504882] [client 66.249.66.67:41188] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:07:59.938478 2026] [authz_core:error] [pid 504660:tid 504882] [client 66.249.66.67:41188] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:07:59.992398 2026] [security2:error] [pid 504660:tid 504950] [client 68.155.159.216:46017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-content/uploads/index.php"] [unique_id "apPk3wgfiZclygrb6nkJ9wAAA4w"]
[Sun Aug 30 03:08:00.001185 2026] [security2:error] [pid 504660:tid 504872] [client 158.23.184.117:18522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/database.php"] [unique_id "apPk4AgfiZclygrb6nkJ-wAAAz4"]
[Sun Aug 30 03:08:00.016626 2026] [security2:error] [pid 504660:tid 504843] [client 20.104.49.130:60929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-login.php"] [unique_id "apPk4AgfiZclygrb6nkKAQAAAyE"]
[Sun Aug 30 03:08:00.019241 2026] [security2:error] [pid 504660:tid 504959] [client 20.48.251.3:45836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/87.php"] [unique_id "apPk4AgfiZclygrb6nkKBQAAA5U"]
[Sun Aug 30 03:08:00.038811 2026] [authz_core:error] [pid 504660:tid 504936] [client 66.249.66.66:46180] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:00.039258 2026] [authz_core:error] [pid 504660:tid 504936] [client 66.249.66.66:46180] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:00.039348 2026] [security2:error] [pid 504660:tid 504953] [client 74.7.230.12:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.one18cleaning.com"] [uri "/index.php"] [unique_id "apPk3QgfiZclygrb6nkFzgAAA48"]
[Sun Aug 30 03:08:00.040406 2026] [security2:error] [pid 504660:tid 504896] [client 74.7.230.12:34344] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.one18cleaning.com"] [uri "/robots.txt"] [unique_id "apPk3QgfiZclygrb6nkFxwADVkM"]
[Sun Aug 30 03:08:00.059583 2026] [security2:error] [pid 504660:tid 504863] [client 20.48.250.41:18270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/class.php"] [unique_id "apPk4AgfiZclygrb6nkKFgAAAzU"]
[Sun Aug 30 03:08:00.065331 2026] [security2:error] [pid 504660:tid 504885] [client 158.23.147.79:58391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-admin/about.php"] [unique_id "apPk4AgfiZclygrb6nkKGQAAA0s"]
[Sun Aug 30 03:08:00.071476 2026] [security2:error] [pid 504660:tid 504944] [client 68.155.159.216:62330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apPk4AgfiZclygrb6nkKGgAAA4Y"]
[Sun Aug 30 03:08:00.100748 2026] [security2:error] [pid 504660:tid 504908] [client 20.151.200.44:55736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/admin.php/heex.php"] [unique_id "apPk4AgfiZclygrb6nkKHQAAA2I"]
[Sun Aug 30 03:08:00.145112 2026] [security2:error] [pid 504660:tid 504881] [client 158.23.184.117:18550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/db.php"] [unique_id "apPk4AgfiZclygrb6nkKIgAAA0c"]
[Sun Aug 30 03:08:00.147851 2026] [security2:error] [pid 504660:tid 504951] [client 68.155.159.216:11202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-content/x.php"] [unique_id "apPk4AgfiZclygrb6nkKIwAAA40"]
[Sun Aug 30 03:08:00.160295 2026] [security2:error] [pid 504660:tid 504862] [client 4.205.62.107:39124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/aws_settings.php"] [unique_id "apPk4AgfiZclygrb6nkKJgAAAzQ"]
[Sun Aug 30 03:08:00.168413 2026] [security2:error] [pid 504660:tid 504938] [client 68.155.159.216:54236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/install.php"] [unique_id "apPk4AgfiZclygrb6nkKKQAAA4A"]
[Sun Aug 30 03:08:00.169707 2026] [security2:error] [pid 504660:tid 504945] [client 158.23.147.79:60174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apPk4AgfiZclygrb6nkKLQAAA4c"]
[Sun Aug 30 03:08:00.174587 2026] [security2:error] [pid 504660:tid 504898] [client 20.48.251.3:13377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/sgd.php"] [unique_id "apPk4AgfiZclygrb6nkKMgAAA1g"]
[Sun Aug 30 03:08:00.182659 2026] [security2:error] [pid 504660:tid 504855] [client 20.104.18.15:28482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/ops.php"] [unique_id "apPk4AgfiZclygrb6nkKNQAAAy0"]
[Sun Aug 30 03:08:00.187701 2026] [security2:error] [pid 504660:tid 504894] [client 20.48.250.41:18421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/8.php"] [unique_id "apPk4AgfiZclygrb6nkKOQAAA1Q"]
[Sun Aug 30 03:08:00.192181 2026] [security2:error] [pid 504660:tid 504844] [client 20.104.50.220:33562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/danon.php"] [unique_id "apPk4AgfiZclygrb6nkKOwAAAyI"]
[Sun Aug 30 03:08:00.214617 2026] [security2:error] [pid 504660:tid 504853] [client 68.155.159.216:12363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-content/packed.php"] [unique_id "apPk4AgfiZclygrb6nkKRgAAAys"]
[Sun Aug 30 03:08:00.214960 2026] [security2:error] [pid 504660:tid 504897] [client 20.104.18.15:23478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/33.php"] [unique_id "apPk4AgfiZclygrb6nkKRwAAA1c"]
[Sun Aug 30 03:08:00.228615 2026] [security2:error] [pid 504660:tid 504961] [client 74.248.24.12:5232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/gecko-new.php"] [unique_id "apPk4AgfiZclygrb6nkKTgAAA5c"]
[Sun Aug 30 03:08:00.230029 2026] [security2:error] [pid 504660:tid 504871] [client 20.104.50.220:46147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/inde.php"] [unique_id "apPk4AgfiZclygrb6nkKUAAAAz0"]
[Sun Aug 30 03:08:00.238187 2026] [security2:error] [pid 504660:tid 504881] [client 20.104.50.220:6099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/40.php"] [unique_id "apPk4AgfiZclygrb6nkKUwAAA0c"]
[Sun Aug 30 03:08:00.250486 2026] [security2:error] [pid 504660:tid 504938] [client 20.104.50.220:32084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-we.php"] [unique_id "apPk4AgfiZclygrb6nkKVwAAA4A"]
[Sun Aug 30 03:08:00.260452 2026] [security2:error] [pid 504660:tid 504931] [client 4.205.62.107:55276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/doc.php"] [unique_id "apPk4AgfiZclygrb6nkKWwAAA3k"]
[Sun Aug 30 03:08:00.262718 2026] [security2:error] [pid 504660:tid 504923] [client 20.48.160.90:50603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPk4AgfiZclygrb6nkKXQAAA3E"]
[Sun Aug 30 03:08:00.266319 2026] [security2:error] [pid 504660:tid 504933] [client 68.155.159.216:63968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apPk4AgfiZclygrb6nkKYAAAA3s"]
[Sun Aug 30 03:08:00.282584 2026] [security2:error] [pid 504660:tid 504906] [client 158.23.147.79:60198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apPk4AgfiZclygrb6nkKZQAAA2A"]
[Sun Aug 30 03:08:00.284306 2026] [security2:error] [pid 504660:tid 504943] [client 20.104.18.15:34791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/abcd.php"] [unique_id "apPk4AgfiZclygrb6nkKZwAAA4U"]
[Sun Aug 30 03:08:00.290658 2026] [security2:error] [pid 504660:tid 504872] [client 158.23.184.117:18511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/default.php"] [unique_id "apPk4AgfiZclygrb6nkKaQAAAz4"]
[Sun Aug 30 03:08:00.290667 2026] [security2:error] [pid 504660:tid 504965] [client 20.104.50.220:29167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/xccc.php"] [unique_id "apPk4AgfiZclygrb6nkKagAAA5s"]
[Sun Aug 30 03:08:00.292214 2026] [security2:error] [pid 504660:tid 504849] [client 20.104.18.15:35493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/bulet.php"] [unique_id "apPk4AgfiZclygrb6nkKawAAAyc"]
[Sun Aug 30 03:08:00.300878 2026] [security2:error] [pid 504660:tid 504911] [client 20.104.50.220:16578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/11.php"] [unique_id "apPk4AgfiZclygrb6nkKbgAAA2U"]
[Sun Aug 30 03:08:00.303462 2026] [security2:error] [pid 504660:tid 504840] [client 4.205.62.107:64694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/xmy.php"] [unique_id "apPk4AgfiZclygrb6nkKcAAAAx4"]
[Sun Aug 30 03:08:00.303499 2026] [security2:error] [pid 504660:tid 504904] [client 4.205.62.107:62449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apPk4AgfiZclygrb6nkKbwAAA14"]
[Sun Aug 30 03:08:00.306192 2026] [security2:error] [pid 504660:tid 504861] [client 20.104.50.220:29360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/ganz.php"] [unique_id "apPk4AgfiZclygrb6nkKcgAAAzM"]
[Sun Aug 30 03:08:00.314960 2026] [security2:error] [pid 504660:tid 504910] [client 65.108.6.34:59720] ModSecurity: Warning. Matched phrase "SEOkicks" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "flashflooring.co.uk"] [uri "/index.php"] [unique_id "apPk3wgfiZclygrb6nkJaQAAA2Q"], referer: https://flashflooring.co.uk/sitemap_index.xml
[Sun Aug 30 03:08:00.315319 2026] [security2:error] [pid 504660:tid 504847] [client 20.104.50.220:41990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/1n73ct10n.php"] [unique_id "apPk4AgfiZclygrb6nkKdwAAAyU"]
[Sun Aug 30 03:08:00.337316 2026] [security2:error] [pid 504660:tid 504862] [client 20.104.18.15:52165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/wnnjpsby.php"] [unique_id "apPk4AgfiZclygrb6nkKfgAAAzQ"]
[Sun Aug 30 03:08:00.344466 2026] [security2:error] [pid 504660:tid 504902] [client 20.48.250.41:18360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/0x0x.php"] [unique_id "apPk4AgfiZclygrb6nkKhQAAA1w"]
[Sun Aug 30 03:08:00.349137 2026] [security2:error] [pid 504660:tid 504855] [client 20.104.18.15:18416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/admin.php"] [unique_id "apPk4AgfiZclygrb6nkKiQAAAy0"]
[Sun Aug 30 03:08:00.350389 2026] [authz_core:error] [pid 504660:tid 504959] [client 216.73.216.128:59390] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:00.350670 2026] [authz_core:error] [pid 504660:tid 504959] [client 216.73.216.128:59390] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:00.355525 2026] [security2:error] [pid 504660:tid 504963] [client 20.104.49.130:57475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/talkxkej.php"] [unique_id "apPk4AgfiZclygrb6nkKjAAAA5k"]
[Sun Aug 30 03:08:00.388066 2026] [security2:error] [pid 504660:tid 504921] [client 20.104.18.15:29653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/wp-includes/index.php"] [unique_id "apPk4AgfiZclygrb6nkKmAAAA28"]
[Sun Aug 30 03:08:00.420745 2026] [security2:error] [pid 504660:tid 504892] [client 20.48.160.90:50590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPk4AgfiZclygrb6nkKmwAAA1I"]
[Sun Aug 30 03:08:00.432727 2026] [security2:error] [pid 504660:tid 504730] [remote 40.77.167.77:31003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "decielockers.com"] [uri "/index.php/grocery/"] [unique_id "apPk4AgfiZclygrb6nkKngADJUQ"]
[Sun Aug 30 03:08:00.435303 2026] [security2:error] [pid 504660:tid 504844] [client 158.23.184.117:18432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/dev1s.php"] [unique_id "apPk4AgfiZclygrb6nkKoAAAAyI"]
[Sun Aug 30 03:08:00.442710 2026] [security2:error] [pid 504660:tid 504858] [client 40.83.93.50:17577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/wp-blog-header.php"] [unique_id "apPk4AgfiZclygrb6nkKowAAAzA"]
[Sun Aug 30 03:08:00.443160 2026] [security2:error] [pid 504660:tid 504845] [client 4.205.62.107:36702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/ms-edit.php"] [unique_id "apPk4AgfiZclygrb6nkKpAAAAyM"]
[Sun Aug 30 03:08:00.461081 2026] [security2:error] [pid 504660:tid 504890] [client 34.125.55.247:46578] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/terraform.tfstate.backup"] [unique_id "apPk4AgfiZclygrb6nkKqwAAA1A"]
[Sun Aug 30 03:08:00.464954 2026] [proxy_http:error] [pid 504660:tid 504867] (20014)Internal error (specific information not available): [client 34.125.55.247:46538] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:00.464968 2026] [proxy:error] [pid 504660:tid 504867] [client 34.125.55.247:46538] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/kubernetes.yml
[Sun Aug 30 03:08:00.466132 2026] [security2:error] [pid 504660:tid 504843] [client 34.125.55.247:46596] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/dump.sql"] [unique_id "apPk4AgfiZclygrb6nkKrgAAAyE"]
[Sun Aug 30 03:08:00.467142 2026] [security2:error] [pid 504660:tid 504862] [client 34.125.55.247:46594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/backup.sql"] [unique_id "apPk4AgfiZclygrb6nkKrwAAAzQ"]
[Sun Aug 30 03:08:00.469912 2026] [security2:error] [pid 504660:tid 504931] [client 34.125.55.247:46672] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.engaginggoddaily.com"] [uri "/proc/self/environ"] [unique_id "apPk4AgfiZclygrb6nkKtAAAA3k"]
[Sun Aug 30 03:08:00.470325 2026] [security2:error] [pid 504660:tid 504944] [client 34.125.55.247:46638] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/files../.env"] [unique_id "apPk4AgfiZclygrb6nkKsgAAA4Y"]
[Sun Aug 30 03:08:00.470585 2026] [security2:error] [pid 504660:tid 504927] [client 34.125.55.247:46662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/media../.env"] [unique_id "apPk4AgfiZclygrb6nkKswAAA3U"]
[Sun Aug 30 03:08:00.471289 2026] [proxy_http:error] [pid 504660:tid 504867] (20014)Internal error (specific information not available): [client 34.125.55.247:46538] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:00.471300 2026] [proxy:error] [pid 504660:tid 504867] [client 34.125.55.247:46538] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml
[Sun Aug 30 03:08:00.471980 2026] [security2:error] [pid 504660:tid 504868] [client 34.125.55.247:46532] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.engaginggoddaily.com"] [uri "/static../.aws/credentials"] [unique_id "apPk4AgfiZclygrb6nkKtgAAAzo"]
[Sun Aug 30 03:08:00.472090 2026] [core:error] [pid 504660:tid 504933] [client 34.125.55.247:46654] AH10244: invalid URI path (/assets../../../.env)
[Sun Aug 30 03:08:00.473718 2026] [security2:error] [pid 504660:tid 504928] [client 34.125.55.247:46626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/static../.env"] [unique_id "apPk4AgfiZclygrb6nkKuQAAA3Y"]
[Sun Aug 30 03:08:00.477516 2026] [proxy_http:error] [pid 504660:tid 504931] (20014)Internal error (specific information not available): [client 34.125.55.247:46672] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:00.477531 2026] [proxy:error] [pid 504660:tid 504931] [client 34.125.55.247:46672] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/cgi-sys/403.html
[Sun Aug 30 03:08:00.483053 2026] [proxy_http:error] [pid 504660:tid 504933] (20014)Internal error (specific information not available): [client 34.125.55.247:46654] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:00.483066 2026] [proxy:error] [pid 504660:tid 504933] [client 34.125.55.247:46654] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/400.shtml
[Sun Aug 30 03:08:00.484052 2026] [authz_core:error] [pid 504660:tid 504913] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_SG
[Sun Aug 30 03:08:00.484152 2026] [security2:error] [pid 504660:tid 504934] [client 20.48.250.41:18329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/166.php"] [unique_id "apPk4AgfiZclygrb6nkKvgAAA3w"]
[Sun Aug 30 03:08:00.484345 2026] [authz_core:error] [pid 504660:tid 504913] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_SG
[Sun Aug 30 03:08:00.489091 2026] [proxy_http:error] [pid 504660:tid 504947] (20014)Internal error (specific information not available): [client 34.125.55.247:46628] AH01102: error reading status line from remote server 127.0.0.1:2082, referer: https://cpanel.engaginggoddaily.com/.env.testing
[Sun Aug 30 03:08:00.489105 2026] [proxy:error] [pid 504660:tid 504947] [client 34.125.55.247:46628] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.env.testing, referer: https://cpanel.engaginggoddaily.com/.env.testing
[Sun Aug 30 03:08:00.547187 2026] [security2:error] [pid 504660:tid 504847] [client 158.23.147.79:58404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/chosen.php"] [unique_id "apPk4AgfiZclygrb6nkK1gAAAyU"]
[Sun Aug 30 03:08:00.552467 2026] [security2:error] [pid 504660:tid 504845] [client 20.104.18.15:2018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPk4AgfiZclygrb6nkK2AAAAyM"]
[Sun Aug 30 03:08:00.565481 2026] [security2:error] [pid 504660:tid 504950] [client 20.48.251.3:5072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/product.php"] [unique_id "apPk4AgfiZclygrb6nkK3QAAA4w"]
[Sun Aug 30 03:08:00.577023 2026] [security2:error] [pid 504660:tid 504897] [client 158.23.184.117:18454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/dex.php"] [unique_id "apPk4AgfiZclygrb6nkK3wAAA1c"]
[Sun Aug 30 03:08:00.578964 2026] [security2:error] [pid 504660:tid 504944] [client 20.48.160.90:50651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/ap.php"] [unique_id "apPk4AgfiZclygrb6nkK4QAAA4Y"]
[Sun Aug 30 03:08:00.610825 2026] [security2:error] [pid 504660:tid 504884] [client 20.104.50.220:62013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-admin/maint/mailer.php.php"] [unique_id "apPk4AgfiZclygrb6nkK6QAAA0o"]
[Sun Aug 30 03:08:00.658248 2026] [security2:error] [pid 504660:tid 504965] [client 20.48.250.41:18346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/h2a2ck.php"] [unique_id "apPk4AgfiZclygrb6nkK-wAAA5s"]
[Sun Aug 30 03:08:00.671583 2026] [security2:error] [pid 504660:tid 504844] [client 114.119.142.156:30783] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.betsydunlap.com"] [uri "/tag/calligraphy/"] [unique_id "apPk4AgfiZclygrb6nkLAQAAAyI"], referer: http://www.betsydunlap.com/tag/calligraphy/
[Sun Aug 30 03:08:00.677906 2026] [security2:error] [pid 504660:tid 504930] [client 20.197.61.180:10461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/about.php"] [unique_id "apPk4AgfiZclygrb6nkLBQAAA3g"]
[Sun Aug 30 03:08:00.693927 2026] [security2:error] [pid 504660:tid 504856] [client 158.23.147.79:63902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPk4AgfiZclygrb6nkLCgAAAy4"]
[Sun Aug 30 03:08:00.705337 2026] [security2:error] [pid 504660:tid 504928] [client 158.23.147.79:60171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/goods.php"] [unique_id "apPk4AgfiZclygrb6nkLDgAAA3Y"]
[Sun Aug 30 03:08:00.717334 2026] [security2:error] [pid 504660:tid 504887] [client 158.23.184.117:18731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/disagrsxr.php"] [unique_id "apPk4AgfiZclygrb6nkLEgAAA00"]
[Sun Aug 30 03:08:00.732090 2026] [security2:error] [pid 504660:tid 504890] [client 74.248.24.12:5201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/NewFile.php"] [unique_id "apPk4AgfiZclygrb6nkLGQAAA1A"]
[Sun Aug 30 03:08:00.748052 2026] [security2:error] [pid 504660:tid 504899] [client 216.73.216.128:17701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPk4AgfiZclygrb6nkLIgAAA1k"]
[Sun Aug 30 03:08:00.764117 2026] [security2:error] [pid 504660:tid 504737] [remote 114.119.129.218:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "registerencio.com"] [uri "/wp-content/uploads/2016/04/gem-photo-3.jpg"] [unique_id "apPk4AgfiZclygrb6nkLIwADNEs"], referer: https://registerencio.com/wp-content/uploads/2016/04/gem-photo-3.jpg
[Sun Aug 30 03:08:00.775060 2026] [security2:error] [pid 504660:tid 504873] [client 178.16.55.109:49437] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "neilgclark.com"] [uri "/index.php"] [unique_id "apPk4AgfiZclygrb6nkLJQAAAz8"]
[Sun Aug 30 03:08:00.789275 2026] [security2:error] [pid 504660:tid 504917] [client 158.23.147.79:63904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/ans.php"] [unique_id "apPk4AgfiZclygrb6nkLKQAAA2s"]
[Sun Aug 30 03:08:00.790315 2026] [security2:error] [pid 504660:tid 504872] [client 20.48.250.41:18314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/error_log.php"] [unique_id "apPk4AgfiZclygrb6nkLKwAAAz4"]
[Sun Aug 30 03:08:00.802382 2026] [security2:error] [pid 504660:tid 504910] [client 20.48.160.90:50655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/media.php"] [unique_id "apPk4AgfiZclygrb6nkLMAAAA2Q"]
[Sun Aug 30 03:08:00.816113 2026] [security2:error] [pid 504660:tid 504858] [client 158.23.147.79:16320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apPk4AgfiZclygrb6nkLPAAAAzA"]
[Sun Aug 30 03:08:00.825567 2026] [autoindex:error] [pid 504660:tid 504921] [client 32.197.93.224:46330] AH01276: Cannot serve directory /home2/nova/public_html/tomanddaves.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:08:00.841548 2026] [security2:error] [pid 504660:tid 504933] [client 4.205.62.107:18795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/var/www/wallet/index.php"] [unique_id "apPk4AgfiZclygrb6nkLUAAAA3s"]
[Sun Aug 30 03:08:00.845712 2026] [authz_core:error] [pid 504660:tid 504938] [client 216.73.216.128:29681] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:00.846003 2026] [authz_core:error] [pid 504660:tid 504938] [client 216.73.216.128:29681] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:00.863499 2026] [security2:error] [pid 504660:tid 504894] [client 158.23.184.117:18589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/domvf.php"] [unique_id "apPk4AgfiZclygrb6nkLVAAAA1Q"]
[Sun Aug 30 03:08:00.888853 2026] [security2:error] [pid 504660:tid 504873] [client 158.23.147.79:63967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/worksec.php"] [unique_id "apPk4AgfiZclygrb6nkLWQAAAz8"]
[Sun Aug 30 03:08:00.933425 2026] [security2:error] [pid 504660:tid 504855] [client 20.48.250.41:18331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/403.php"] [unique_id "apPk4AgfiZclygrb6nkLcgAAAy0"]
[Sun Aug 30 03:08:00.970135 2026] [authz_core:error] [pid 504660:tid 504914] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AG
[Sun Aug 30 03:08:00.970622 2026] [authz_core:error] [pid 504660:tid 504914] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AG
[Sun Aug 30 03:08:00.989867 2026] [security2:error] [pid 504660:tid 504894] [client 158.23.147.79:58372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apPk4AgfiZclygrb6nkLgAAAA1Q"]
[Sun Aug 30 03:08:00.991342 2026] [security2:error] [pid 504660:tid 504874] [client 20.48.160.90:50586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/adminfuns.php"] [unique_id "apPk4AgfiZclygrb6nkLgQAAA0A"]
[Sun Aug 30 03:08:01.019929 2026] [security2:error] [pid 504660:tid 504902] [client 158.23.147.79:62310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/x.php"] [unique_id "apPk4QgfiZclygrb6nkLjQAAA1w"]
[Sun Aug 30 03:08:01.023564 2026] [security2:error] [pid 504660:tid 504923] [client 158.23.184.117:18581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/donate.php"] [unique_id "apPk4QgfiZclygrb6nkLkQAAA3E"]
[Sun Aug 30 03:08:01.061237 2026] [security2:error] [pid 504660:tid 504926] [client 20.48.250.41:18390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/cytyr.php"] [unique_id "apPk4QgfiZclygrb6nkLnwAAA3Q"]
[Sun Aug 30 03:08:01.064022 2026] [authz_core:error] [pid 504660:tid 504853] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:01.064474 2026] [authz_core:error] [pid 504660:tid 504853] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:01.068955 2026] [security2:error] [pid 504660:tid 504849] [client 40.83.93.50:7830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/s.php"] [unique_id "apPk4QgfiZclygrb6nkLoAAAAyc"]
[Sun Aug 30 03:08:01.113900 2026] [security2:error] [pid 504660:tid 504953] [client 216.73.216.128:12390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPk4QgfiZclygrb6nkLqwAAA48"]
[Sun Aug 30 03:08:01.131035 2026] [security2:error] [pid 504660:tid 504890] [client 20.48.160.90:50610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/classwithtostring.php"] [unique_id "apPk4QgfiZclygrb6nkLsAAAA1A"]
[Sun Aug 30 03:08:01.149497 2026] [security2:error] [pid 504660:tid 504962] [client 158.23.147.79:63878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-content/x.php"] [unique_id "apPk4QgfiZclygrb6nkLsgAAA5g"]
[Sun Aug 30 03:08:01.149914 2026] [security2:error] [pid 504660:tid 504894] [client 68.155.159.216:45911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apPk4QgfiZclygrb6nkLswAAA1Q"]
[Sun Aug 30 03:08:01.161042 2026] [security2:error] [pid 504660:tid 504919] [client 158.23.184.117:18552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/dropdown.php"] [unique_id "apPk4QgfiZclygrb6nkLtQAAA20"]
[Sun Aug 30 03:08:01.163617 2026] [security2:error] [pid 504660:tid 504865] [client 158.23.147.79:60177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/file.php"] [unique_id "apPk4QgfiZclygrb6nkLtgAAAzc"]
[Sun Aug 30 03:08:01.194224 2026] [security2:error] [pid 504660:tid 504961] [client 114.119.134.51:34355] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "allsaintsbowie.org"] [uri "/images/pdf/Pastors%20Corner%20-%20What%20ifs%20Nov%202019.pdf"] [unique_id "apPk4QgfiZclygrb6nkLxQAAA5c"]
[Sun Aug 30 03:08:01.196301 2026] [security2:error] [pid 504660:tid 504876] [client 20.48.250.41:18363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/galer.php"] [unique_id "apPk4QgfiZclygrb6nkLxwAAA0I"]
[Sun Aug 30 03:08:01.246581 2026] [security2:error] [pid 504660:tid 504941] [client 74.248.24.12:5218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/wp-Blogs.php"] [unique_id "apPk4QgfiZclygrb6nkL3wAAA4M"]
[Sun Aug 30 03:08:01.264995 2026] [security2:error] [pid 504660:tid 504894] [client 158.23.147.79:62290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPk4QgfiZclygrb6nkL6AAAA1Q"]
[Sun Aug 30 03:08:01.286462 2026] [security2:error] [pid 504660:tid 504859] [client 20.48.160.90:50630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPk4QgfiZclygrb6nkL7AAAAzE"]
[Sun Aug 30 03:08:01.306787 2026] [security2:error] [pid 504660:tid 504895] [client 158.23.184.117:18596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/edit.php"] [unique_id "apPk4QgfiZclygrb6nkL9AAAA1U"]
[Sun Aug 30 03:08:01.312933 2026] [security2:error] [pid 504660:tid 504896] [client 20.48.251.3:33307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/fleen.php"] [unique_id "apPk4QgfiZclygrb6nkL-AAAA1Y"]
[Sun Aug 30 03:08:01.318963 2026] [security2:error] [pid 504660:tid 504856] [client 68.155.159.216:56382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPk4QgfiZclygrb6nkL-wAAAy4"]
[Sun Aug 30 03:08:01.323287 2026] [security2:error] [pid 504660:tid 504898] [client 20.48.250.41:18211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/baixy.php"] [unique_id "apPk4QgfiZclygrb6nkL_QAAA1g"]
[Sun Aug 30 03:08:01.328401 2026] [security2:error] [pid 504660:tid 504909] [client 20.104.18.15:28655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPk4QgfiZclygrb6nkMAAAAA2M"]
[Sun Aug 30 03:08:01.332872 2026] [security2:error] [pid 504660:tid 504940] [client 4.205.62.107:62131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/wp-konfig.backup.php"] [unique_id "apPk4QgfiZclygrb6nkMAQAAA4I"]
[Sun Aug 30 03:08:01.337679 2026] [security2:error] [pid 504660:tid 504927] [client 20.104.50.220:33158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/xd.php"] [unique_id "apPk4QgfiZclygrb6nkMBgAAA3U"]
[Sun Aug 30 03:08:01.372272 2026] [security2:error] [pid 504660:tid 504840] [client 68.155.159.216:63958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apPk4QgfiZclygrb6nkMEQAAAx4"]
[Sun Aug 30 03:08:01.373297 2026] [security2:error] [pid 504660:tid 504862] [client 20.104.18.15:23495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/133.php"] [unique_id "apPk4QgfiZclygrb6nkMEwAAAzQ"]
[Sun Aug 30 03:08:01.373911 2026] [security2:error] [pid 504660:tid 504930] [client 20.104.50.220:5907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/39.php"] [unique_id "apPk4QgfiZclygrb6nkMFAAAA3g"]
[Sun Aug 30 03:08:01.374725 2026] [security2:error] [pid 504660:tid 504953] [client 158.23.147.79:62322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/log-mama/function.php"] [unique_id "apPk4QgfiZclygrb6nkMFQAAA48"]
[Sun Aug 30 03:08:01.383059 2026] [security2:error] [pid 504660:tid 504899] [client 20.104.50.220:46626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/classgoto24.php"] [unique_id "apPk4QgfiZclygrb6nkMGQAAA1k"]
[Sun Aug 30 03:08:01.384290 2026] [security2:error] [pid 504660:tid 504957] [client 68.155.159.216:12369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-l0gin.php"] [unique_id "apPk4QgfiZclygrb6nkMGgAAA5M"]
[Sun Aug 30 03:08:01.395563 2026] [authz_core:error] [pid 504660:tid 504851] [client 66.249.66.37:36351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:01.396055 2026] [authz_core:error] [pid 504660:tid 504851] [client 66.249.66.37:36351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:01.396262 2026] [authz_core:error] [pid 504660:tid 504846] [client 216.73.216.128:6999] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:01.396705 2026] [authz_core:error] [pid 504660:tid 504846] [client 216.73.216.128:6999] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:01.406838 2026] [security2:error] [pid 504660:tid 504893] [client 20.197.61.180:10433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/new.php"] [unique_id "apPk4QgfiZclygrb6nkMIQAAA1M"]
[Sun Aug 30 03:08:01.408767 2026] [security2:error] [pid 504660:tid 504893] [client 20.104.50.220:31894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wpindex.php"] [unique_id "apPk4QgfiZclygrb6nkMIgAAA1M"]
[Sun Aug 30 03:08:01.419669 2026] [security2:error] [pid 504660:tid 504881] [client 20.104.18.15:34698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/nofile.php"] [unique_id "apPk4QgfiZclygrb6nkMJgAAA0c"]
[Sun Aug 30 03:08:01.428867 2026] [security2:error] [pid 504660:tid 504845] [client 20.104.50.220:29626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/moon.php"] [unique_id "apPk4QgfiZclygrb6nkMKgAAAyM"]
[Sun Aug 30 03:08:01.437461 2026] [security2:error] [pid 504660:tid 504892] [client 20.104.50.220:16736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/p.php"] [unique_id "apPk4QgfiZclygrb6nkMLAAAA1I"]
[Sun Aug 30 03:08:01.445213 2026] [security2:error] [pid 504660:tid 504876] [client 4.205.62.107:64690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/ms-edit.php"] [unique_id "apPk4QgfiZclygrb6nkMMQAAA0I"]
[Sun Aug 30 03:08:01.446420 2026] [security2:error] [pid 504660:tid 504874] [client 20.104.50.220:52850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/gas.php"] [unique_id "apPk4QgfiZclygrb6nkMMgAAA0A"]
[Sun Aug 30 03:08:01.446459 2026] [security2:error] [pid 504660:tid 504907] [client 158.23.184.117:18469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/ee.php"] [unique_id "apPk4QgfiZclygrb6nkMMwAAA2E"]
[Sun Aug 30 03:08:01.447756 2026] [security2:error] [pid 504660:tid 504959] [client 20.48.160.90:50597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/5PJcpMFsD8B.php"] [unique_id "apPk4QgfiZclygrb6nkMNAAAA5U"]
[Sun Aug 30 03:08:01.447977 2026] [security2:error] [pid 504660:tid 504952] [client 20.104.18.15:35482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/av.php"] [unique_id "apPk4QgfiZclygrb6nkMNgAAA44"]
[Sun Aug 30 03:08:01.450655 2026] [security2:error] [pid 504660:tid 504880] [client 20.48.250.41:18405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/ava.php"] [unique_id "apPk4QgfiZclygrb6nkMNwAAA0Y"]
[Sun Aug 30 03:08:01.452022 2026] [security2:error] [pid 504660:tid 504950] [client 20.104.50.220:63509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/not_acceptable.php"] [unique_id "apPk4QgfiZclygrb6nkMOAAAA4w"]
[Sun Aug 30 03:08:01.453172 2026] [security2:error] [pid 504660:tid 504913] [client 4.205.62.107:62433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/hochladen.form.php"] [unique_id "apPk4QgfiZclygrb6nkMOQAAA2c"]
[Sun Aug 30 03:08:01.464003 2026] [security2:error] [pid 504660:tid 504906] [client 68.155.159.216:61649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apPk4QgfiZclygrb6nkMPgAAA2A"]
[Sun Aug 30 03:08:01.464193 2026] [authz_core:error] [pid 504660:tid 504918] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_DK
[Sun Aug 30 03:08:01.464495 2026] [authz_core:error] [pid 504660:tid 504918] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_DK
[Sun Aug 30 03:08:01.481312 2026] [security2:error] [pid 504660:tid 504925] [client 158.23.147.79:60220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/file17.php"] [unique_id "apPk4QgfiZclygrb6nkMQwAAA3M"]
[Sun Aug 30 03:08:01.491600 2026] [security2:error] [pid 504660:tid 504840] [client 20.104.18.15:51688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/info.php/new.php"] [unique_id "apPk4QgfiZclygrb6nkMSQAAAx4"]
[Sun Aug 30 03:08:01.500405 2026] [security2:error] [pid 504660:tid 504887] [client 20.104.18.15:18415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/ws85.php"] [unique_id "apPk4QgfiZclygrb6nkMSgAAA00"]
[Sun Aug 30 03:08:01.538989 2026] [security2:error] [pid 504660:tid 504945] [client 158.23.147.79:62227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/bk/index.php"] [unique_id "apPk4QgfiZclygrb6nkMVwAAA4c"]
[Sun Aug 30 03:08:01.539654 2026] [security2:error] [pid 504660:tid 504881] [client 20.104.18.15:29665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/dk.php"] [unique_id "apPk4QgfiZclygrb6nkMWAAAA0c"]
[Sun Aug 30 03:08:01.553530 2026] [authz_core:error] [pid 504660:tid 504937] [client 66.249.66.73:54785] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:01.554234 2026] [authz_core:error] [pid 504660:tid 504937] [client 66.249.66.73:54785] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:01.578724 2026] [security2:error] [pid 504660:tid 504920] [client 20.48.250.41:18316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/gdn.php"] [unique_id "apPk4QgfiZclygrb6nkMcAAAA24"]
[Sun Aug 30 03:08:01.585006 2026] [authz_core:error] [pid 504660:tid 504952] [client 216.73.216.128:40000] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:01.585502 2026] [authz_core:error] [pid 504660:tid 504952] [client 216.73.216.128:40000] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:01.592514 2026] [security2:error] [pid 504660:tid 504965] [client 158.23.184.117:18556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/elp.php"] [unique_id "apPk4QgfiZclygrb6nkMcwAAA5s"]
[Sun Aug 30 03:08:01.593433 2026] [security2:error] [pid 504660:tid 504925] [client 20.48.160.90:50574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPk4QgfiZclygrb6nkMdAAAA3M"]
[Sun Aug 30 03:08:01.595760 2026] [security2:error] [pid 504660:tid 504902] [client 40.83.93.50:17553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/php.php"] [unique_id "apPk4QgfiZclygrb6nkMdgAAA1w"]
[Sun Aug 30 03:08:01.643021 2026] [security2:error] [pid 504660:tid 504890] [client 68.155.159.216:60887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-admin/index.php"] [unique_id "apPk4QgfiZclygrb6nkMjQAAA1A"]
[Sun Aug 30 03:08:01.652197 2026] [security2:error] [pid 504660:tid 504950] [client 158.23.147.79:63977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tgifa.org"] [uri "/first.php"] [unique_id "apPk4QgfiZclygrb6nkMkQAAA4w"]
[Sun Aug 30 03:08:01.652223 2026] [security2:error] [pid 504660:tid 504959] [client 4.205.62.107:32450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/classsmtps.php"] [unique_id "apPk4QgfiZclygrb6nkMkgAAA5U"]
[Sun Aug 30 03:08:01.657304 2026] [security2:error] [pid 504660:tid 504908] [client 4.205.62.107:36008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/lmfi2.php"] [unique_id "apPk4QgfiZclygrb6nkMkwAAA2I"]
[Sun Aug 30 03:08:01.678213 2026] [security2:error] [pid 504660:tid 504897] [client 158.23.147.79:60192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/file5.php"] [unique_id "apPk4QgfiZclygrb6nkMnwAAA1c"]
[Sun Aug 30 03:08:01.690818 2026] [security2:error] [pid 504660:tid 504862] [client 20.104.18.15:1996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPk4QgfiZclygrb6nkMowAAAzQ"]
[Sun Aug 30 03:08:01.703007 2026] [security2:error] [pid 504660:tid 504755] [remote 67.205.0.102:46824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.0.205.67.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "watertownchessclub.com"] [uri "/wp-login.php"] [unique_id "apPk4QgfiZclygrb6nkMqgADRF0"]
[Sun Aug 30 03:08:01.707688 2026] [security2:error] [pid 504660:tid 504865] [client 68.155.159.216:55165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-content/x/index.php"] [unique_id "apPk4QgfiZclygrb6nkMrQAAAzc"]
[Sun Aug 30 03:08:01.730607 2026] [security2:error] [pid 504660:tid 504855] [client 158.23.184.117:18507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/en.php"] [unique_id "apPk4QgfiZclygrb6nkMugAAAy0"]
[Sun Aug 30 03:08:01.730925 2026] [security2:error] [pid 504660:tid 504846] [client 20.48.160.90:50563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/wsd.php"] [unique_id "apPk4QgfiZclygrb6nkMuwAAAyQ"]
[Sun Aug 30 03:08:01.740585 2026] [security2:error] [pid 504660:tid 504879] [client 20.48.251.3:5058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/fun.php"] [unique_id "apPk4QgfiZclygrb6nkMwQAAA0U"]
[Sun Aug 30 03:08:01.743397 2026] [security2:error] [pid 504660:tid 504871] [client 20.48.250.41:18324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/f2.php"] [unique_id "apPk4QgfiZclygrb6nkMwgAAAz0"]
[Sun Aug 30 03:08:01.767292 2026] [security2:error] [pid 504660:tid 504965] [client 74.248.24.12:14812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apPk4QgfiZclygrb6nkMyAAAA5s"]
[Sun Aug 30 03:08:01.787786 2026] [security2:error] [pid 504660:tid 504863] [client 20.104.50.220:61415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-admin/css/mailer.php.php"] [unique_id "apPk4QgfiZclygrb6nkMzwAAAzU"]
[Sun Aug 30 03:08:01.798964 2026] [security2:error] [pid 504660:tid 504936] [client 158.23.147.79:58393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/file88.php"] [unique_id "apPk4QgfiZclygrb6nkM0wAAA34"]
[Sun Aug 30 03:08:01.872828 2026] [security2:error] [pid 504660:tid 504913] [client 158.23.184.117:18711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.fakemusic.org"] [uri "/error.php"] [unique_id "apPk4QgfiZclygrb6nkM7wAAA2c"]
[Sun Aug 30 03:08:01.892850 2026] [security2:error] [pid 504660:tid 504934] [client 20.48.160.90:33223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/bulet.php"] [unique_id "apPk4QgfiZclygrb6nkM-AAAA3w"]
[Sun Aug 30 03:08:01.899025 2026] [security2:error] [pid 504660:tid 504918] [client 20.48.250.41:18271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/grsiuk.php"] [unique_id "apPk4QgfiZclygrb6nkM_wAAA2w"]
[Sun Aug 30 03:08:01.901156 2026] [authz_core:error] [pid 504660:tid 504842] [client 66.249.66.194:42972] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:01.901517 2026] [authz_core:error] [pid 504660:tid 504842] [client 66.249.66.194:42972] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:01.926989 2026] [security2:error] [pid 504660:tid 504896] [client 158.23.147.79:58397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/NewFile.php/"] [unique_id "apPk4QgfiZclygrb6nkNDwAAA1Y"]
[Sun Aug 30 03:08:01.975822 2026] [authz_core:error] [pid 504660:tid 504943] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NG
[Sun Aug 30 03:08:01.976175 2026] [authz_core:error] [pid 504660:tid 504943] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NG
[Sun Aug 30 03:08:01.981840 2026] [security2:error] [pid 504660:tid 504879] [client 4.205.62.107:18992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/124.php"] [unique_id "apPk4QgfiZclygrb6nkNIgAAA0U"]
[Sun Aug 30 03:08:02.058713 2026] [security2:error] [pid 504660:tid 504896] [client 216.73.216.128:40000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/ourcollection_images/wp-admin/css/install.css"] [unique_id "apPk4ggfiZclygrb6nkNPQAAA1Y"]
[Sun Aug 30 03:08:02.061561 2026] [security2:error] [pid 504660:tid 504962] [client 20.48.250.41:18336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/wp-scr1pts.php"] [unique_id "apPk4ggfiZclygrb6nkNQQAAA5g"]
[Sun Aug 30 03:08:02.083115 2026] [security2:error] [pid 504660:tid 504893] [client 158.23.147.79:16346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/dropdown.php"] [unique_id "apPk4ggfiZclygrb6nkNRwAAA1M"]
[Sun Aug 30 03:08:02.084900 2026] [security2:error] [pid 504660:tid 504904] [client 40.83.93.50:17574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/system_log.php"] [unique_id "apPk4ggfiZclygrb6nkNSQAAA14"]
[Sun Aug 30 03:08:02.106802 2026] [security2:error] [pid 504660:tid 504887] [client 20.48.160.90:50614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/av.php"] [unique_id "apPk4ggfiZclygrb6nkNTgAAA00"]
[Sun Aug 30 03:08:02.116434 2026] [security2:error] [pid 504660:tid 504898] [client 20.197.61.180:19014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/goods.php"] [unique_id "apPk4ggfiZclygrb6nkNUAAAA1g"]
[Sun Aug 30 03:08:02.178388 2026] [security2:error] [pid 504660:tid 504874] [client 158.23.147.79:60207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/.well-known/index.php"] [unique_id "apPk4ggfiZclygrb6nkNZAAAA0A"]
[Sun Aug 30 03:08:02.185045 2026] [authz_core:error] [pid 504660:tid 504932] [client 66.249.66.194:52981] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:02.185541 2026] [authz_core:error] [pid 504660:tid 504932] [client 66.249.66.194:52981] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:02.191556 2026] [security2:error] [pid 504660:tid 504851] [client 20.48.250.41:18370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/num.php"] [unique_id "apPk4ggfiZclygrb6nkNagAAAyk"]
[Sun Aug 30 03:08:02.240963 2026] [security2:error] [pid 504660:tid 504898] [client 20.48.160.90:50629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/images.php"] [unique_id "apPk4ggfiZclygrb6nkNhgAAA1g"]
[Sun Aug 30 03:08:02.263791 2026] [security2:error] [pid 504660:tid 504892] [client 68.155.159.216:45906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/chosen.php"] [unique_id "apPk4ggfiZclygrb6nkNjwAAA1I"]
[Sun Aug 30 03:08:02.316540 2026] [security2:error] [pid 504660:tid 504878] [client 74.248.24.12:10795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/ws83.php"] [unique_id "apPk4ggfiZclygrb6nkNngAAA0Q"]
[Sun Aug 30 03:08:02.323150 2026] [security2:error] [pid 504660:tid 504841] [client 20.151.200.44:47036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/admin.php/heex.php"] [unique_id "apPk4ggfiZclygrb6nkNnwAAAx8"]
[Sun Aug 30 03:08:02.347518 2026] [security2:error] [pid 504660:tid 504856] [client 20.48.250.41:18190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/a4.php"] [unique_id "apPk4ggfiZclygrb6nkNqwAAAy4"]
[Sun Aug 30 03:08:02.357535 2026] [security2:error] [pid 504660:tid 504929] [client 20.48.251.3:6999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/plss3.php"] [unique_id "apPk4ggfiZclygrb6nkNrAAAA3c"]
[Sun Aug 30 03:08:02.424092 2026] [security2:error] [pid 504660:tid 504857] [client 68.155.159.216:56412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/log-mama/function.php"] [unique_id "apPk4ggfiZclygrb6nkNuwAAAy8"]
[Sun Aug 30 03:08:02.451508 2026] [security2:error] [pid 504660:tid 504954] [client 20.48.251.3:33325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/upload.form.php"] [unique_id "apPk4ggfiZclygrb6nkNwAAAA5A"]
[Sun Aug 30 03:08:02.455305 2026] [security2:error] [pid 504660:tid 504917] [client 20.48.160.90:50647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/ops.php"] [unique_id "apPk4ggfiZclygrb6nkNwQAAA2s"]
[Sun Aug 30 03:08:02.460705 2026] [security2:error] [pid 504660:tid 504903] [client 20.104.18.15:28568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPk4ggfiZclygrb6nkNxAAAA10"]
[Sun Aug 30 03:08:02.468448 2026] [security2:error] [pid 504660:tid 504943] [client 158.23.147.79:60221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-content/themes/too.php"] [unique_id "apPk4ggfiZclygrb6nkNxQAAA4U"]
[Sun Aug 30 03:08:02.468918 2026] [security2:error] [pid 504660:tid 504885] [client 4.205.62.107:63946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/packed.php"] [unique_id "apPk4ggfiZclygrb6nkNxgAAA0s"]
[Sun Aug 30 03:08:02.478217 2026] [security2:error] [pid 504660:tid 504897] [client 68.155.159.216:61370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apPk4ggfiZclygrb6nkNyQAAA1c"]
[Sun Aug 30 03:08:02.493221 2026] [security2:error] [pid 504660:tid 504913] [client 20.104.50.220:32933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/dada.php"] [unique_id "apPk4ggfiZclygrb6nkN0QAAA2c"]
[Sun Aug 30 03:08:02.496669 2026] [authz_core:error] [pid 504660:tid 504871] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZM
[Sun Aug 30 03:08:02.497060 2026] [authz_core:error] [pid 504660:tid 504871] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZM
[Sun Aug 30 03:08:02.506330 2026] [security2:error] [pid 504660:tid 504951] [client 68.155.159.216:12397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apPk4ggfiZclygrb6nkN1AAAA40"]
[Sun Aug 30 03:08:02.513194 2026] [security2:error] [pid 504660:tid 504860] [client 20.104.50.220:5888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/38.php"] [unique_id "apPk4ggfiZclygrb6nkN1wAAAzI"]
[Sun Aug 30 03:08:02.529016 2026] [security2:error] [pid 504660:tid 504947] [client 20.48.250.41:18398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/tfm.php"] [unique_id "apPk4ggfiZclygrb6nkN4QAAA4k"]
[Sun Aug 30 03:08:02.529690 2026] [security2:error] [pid 504660:tid 504869] [client 20.104.18.15:23314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/sym.php"] [unique_id "apPk4ggfiZclygrb6nkN4gAAAzs"]
[Sun Aug 30 03:08:02.545656 2026] [security2:error] [pid 504660:tid 504938] [client 20.104.50.220:32568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp_wrong_datlib.php"] [unique_id "apPk4ggfiZclygrb6nkN7gAAA4A"]
[Sun Aug 30 03:08:02.547831 2026] [security2:error] [pid 504660:tid 504810] [remote 67.205.0.102:46824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.0.205.67.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "watertownchessclub.com"] [uri "/wp-login.php"] [unique_id "apPk4ggfiZclygrb6nkN7QADVmM"], referer: https://watertownchessclub.com/wp-login.php
[Sun Aug 30 03:08:02.553703 2026] [security2:error] [pid 504660:tid 504850] [client 20.104.50.220:46605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/thh.php"] [unique_id "apPk4ggfiZclygrb6nkN8gAAAyg"]
[Sun Aug 30 03:08:02.555183 2026] [authz_core:error] [pid 504660:tid 504936] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:02.555549 2026] [authz_core:error] [pid 504660:tid 504936] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:02.556686 2026] [security2:error] [pid 504660:tid 504890] [client 20.104.18.15:34723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/run.php"] [unique_id "apPk4ggfiZclygrb6nkN8wAAA1A"]
[Sun Aug 30 03:08:02.565620 2026] [security2:error] [pid 504660:tid 504892] [client 20.104.50.220:29149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wkwk.php"] [unique_id "apPk4ggfiZclygrb6nkN-wAAA1I"]
[Sun Aug 30 03:08:02.574908 2026] [security2:error] [pid 504660:tid 504937] [client 68.155.159.216:28615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apPk4ggfiZclygrb6nkN_wAAA38"]
[Sun Aug 30 03:08:02.583022 2026] [security2:error] [pid 504660:tid 504913] [client 20.104.50.220:29164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/gg.php"] [unique_id "apPk4ggfiZclygrb6nkOAgAAA2c"]
[Sun Aug 30 03:08:02.588548 2026] [security2:error] [pid 504660:tid 504891] [client 20.48.160.90:50594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/coffexium.php"] [unique_id "apPk4ggfiZclygrb6nkOAwAAA1E"]
[Sun Aug 30 03:08:02.591280 2026] [security2:error] [pid 504660:tid 504967] [client 20.104.50.220:63530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/dada.php"] [unique_id "apPk4ggfiZclygrb6nkOBgAAA50"]
[Sun Aug 30 03:08:02.595059 2026] [security2:error] [pid 504660:tid 504868] [client 114.119.150.158:58009] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "holacleaning.com.au"] [uri "/wp-content/uploads/2023/06/house.png"] [unique_id "apPk4ggfiZclygrb6nkOCQAAAzo"], referer: https://sur.ly/o/holacleaning.com.au/AA000014?pageviewId=mobile-302e313933393436303020313635363235303735372031313333343833353037
[Sun Aug 30 03:08:02.595457 2026] [security2:error] [pid 504660:tid 504882] [client 40.83.93.50:7810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/w.php"] [unique_id "apPk4ggfiZclygrb6nkOCgAAA0g"]
[Sun Aug 30 03:08:02.596068 2026] [authz_core:error] [pid 504660:tid 504891] [client 66.249.66.40:64628] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:02.596200 2026] [security2:error] [pid 504660:tid 504907] [client 20.104.18.15:35464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/images.php"] [unique_id "apPk4ggfiZclygrb6nkODAAAA2E"]
[Sun Aug 30 03:08:02.596356 2026] [authz_core:error] [pid 504660:tid 504891] [client 66.249.66.40:64628] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:02.605458 2026] [security2:error] [pid 504660:tid 504959] [client 4.205.62.107:22554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/debuggen.php"] [unique_id "apPk4ggfiZclygrb6nkOEAAAA5U"]
[Sun Aug 30 03:08:02.621465 2026] [security2:error] [pid 504660:tid 504950] [client 4.205.62.107:64684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/sys.php"] [unique_id "apPk4ggfiZclygrb6nkOGwAAA4w"]
[Sun Aug 30 03:08:02.634728 2026] [security2:error] [pid 504660:tid 504926] [client 20.104.18.15:18322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/ffs.php"] [unique_id "apPk4ggfiZclygrb6nkOHwAAA3Q"]
[Sun Aug 30 03:08:02.648634 2026] [security2:error] [pid 504660:tid 504853] [client 20.104.50.220:17301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/bthil.php"] [unique_id "apPk4ggfiZclygrb6nkOJAAAAys"]
[Sun Aug 30 03:08:02.661830 2026] [security2:error] [pid 504660:tid 504844] [client 20.48.250.41:18285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/Geforce.php"] [unique_id "apPk4ggfiZclygrb6nkOKQAAAyI"]
[Sun Aug 30 03:08:02.671134 2026] [security2:error] [pid 504660:tid 504953] [client 20.104.18.15:29136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apPk4ggfiZclygrb6nkOMQAAA48"]
[Sun Aug 30 03:08:02.685413 2026] [security2:error] [pid 504660:tid 504865] [client 114.119.128.237:30877] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "drainzit.com"] [uri "/"] [unique_id "apPk4ggfiZclygrb6nkOOAAAAzc"], referer: http://drainzit.com/
[Sun Aug 30 03:08:02.740857 2026] [security2:error] [pid 504660:tid 504946] [client 20.48.160.90:50685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/BDKR28WP.php"] [unique_id "apPk4ggfiZclygrb6nkOSwAAA4g"]
[Sun Aug 30 03:08:02.762761 2026] [security2:error] [pid 504660:tid 504965] [client 20.104.49.130:52329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/talkxkej.php"] [unique_id "apPk4ggfiZclygrb6nkOUAAAA5s"]
[Sun Aug 30 03:08:02.766549 2026] [authz_core:error] [pid 504660:tid 504921] [client 66.249.66.77:57669] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:02.766869 2026] [authz_core:error] [pid 504660:tid 504921] [client 66.249.66.77:57669] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:02.769151 2026] [security2:error] [pid 504660:tid 504856] [client 158.23.147.79:60199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/radio.php"] [unique_id "apPk4ggfiZclygrb6nkOUwAAAy4"]
[Sun Aug 30 03:08:02.781622 2026] [security2:error] [pid 504660:tid 504952] [client 20.104.18.15:51616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/w.php"] [unique_id "apPk4ggfiZclygrb6nkOVwAAA44"]
[Sun Aug 30 03:08:02.790852 2026] [security2:error] [pid 504660:tid 504884] [client 20.48.250.41:18132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/click.php"] [unique_id "apPk4ggfiZclygrb6nkOWwAAA0o"]
[Sun Aug 30 03:08:02.815709 2026] [security2:error] [pid 504660:tid 504937] [client 4.205.62.107:36009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/wpver.php"] [unique_id "apPk4ggfiZclygrb6nkOYwAAA38"]
[Sun Aug 30 03:08:02.824314 2026] [security2:error] [pid 504660:tid 504939] [client 20.197.61.180:8790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/m.php"] [unique_id "apPk4ggfiZclygrb6nkOaQAAA4E"]
[Sun Aug 30 03:08:02.829578 2026] [security2:error] [pid 504660:tid 504887] [client 20.104.18.15:1988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/media.php"] [unique_id "apPk4ggfiZclygrb6nkObQAAA00"]
[Sun Aug 30 03:08:02.834452 2026] [security2:error] [pid 504660:tid 504876] [client 74.248.24.12:11850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/atex1.php"] [unique_id "apPk4ggfiZclygrb6nkOdAAAA0I"]
[Sun Aug 30 03:08:02.881242 2026] [security2:error] [pid 504660:tid 504938] [client 20.48.251.3:44318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/kedi.php"] [unique_id "apPk4ggfiZclygrb6nkOjgAAA4A"]
[Sun Aug 30 03:08:02.882130 2026] [authz_core:error] [pid 504660:tid 504965] [client 216.73.216.128:40000] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:02.882443 2026] [authz_core:error] [pid 504660:tid 504965] [client 216.73.216.128:40000] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:02.919487 2026] [security2:error] [pid 504660:tid 504900] [client 20.48.250.41:18251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/ms.php"] [unique_id "apPk4ggfiZclygrb6nkOpwAAA1o"]
[Sun Aug 30 03:08:02.939873 2026] [security2:error] [pid 504660:tid 504925] [client 20.104.50.220:61975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-includes/css/mailer.php.php"] [unique_id "apPk4ggfiZclygrb6nkOsAAAA3M"]
[Sun Aug 30 03:08:02.941691 2026] [security2:error] [pid 504660:tid 504941] [client 20.48.160.90:50644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/sf.php"] [unique_id "apPk4ggfiZclygrb6nkOsQAAA4M"]
[Sun Aug 30 03:08:02.990639 2026] [authz_core:error] [pid 504660:tid 504869] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AG
[Sun Aug 30 03:08:02.990940 2026] [authz_core:error] [pid 504660:tid 504869] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AG
[Sun Aug 30 03:08:03.006444 2026] [security2:error] [pid 504660:tid 504902] [client 158.23.147.79:16328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPk4wgfiZclygrb6nkOxwAAA1w"]
[Sun Aug 30 03:08:03.062532 2026] [security2:error] [pid 504660:tid 504959] [client 20.48.250.41:18394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/zxekqlxb.php"] [unique_id "apPk4wgfiZclygrb6nkO5QAAA5U"]
[Sun Aug 30 03:08:03.076394 2026] [security2:error] [pid 504660:tid 504943] [client 20.48.160.90:50686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/k.php"] [unique_id "apPk4wgfiZclygrb6nkO5wAAA4U"]
[Sun Aug 30 03:08:03.110543 2026] [security2:error] [pid 504660:tid 504894] [client 40.83.93.50:13794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/wp.php"] [unique_id "apPk4wgfiZclygrb6nkO9gAAA1Q"]
[Sun Aug 30 03:08:03.119338 2026] [security2:error] [pid 504660:tid 504952] [client 4.205.62.107:17799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/test1.php"] [unique_id "apPk4wgfiZclygrb6nkO-AAAA44"]
[Sun Aug 30 03:08:03.154621 2026] [core:error] [pid 504660:tid 504823] [remote 216.73.216.82:40548] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:08:03.154661 2026] [core:error] [pid 504660:tid 504823] [remote 216.73.216.82:40548] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:08:03.197628 2026] [security2:error] [pid 504660:tid 504959] [client 20.48.250.41:18340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/init.php"] [unique_id "apPk4wgfiZclygrb6nkPDgAAA5U"]
[Sun Aug 30 03:08:03.203468 2026] [security2:error] [pid 504660:tid 504950] [client 4.205.62.107:32021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/cache-compat.php"] [unique_id "apPk4wgfiZclygrb6nkPDwAAA4w"]
[Sun Aug 30 03:08:03.235123 2026] [security2:error] [pid 504660:tid 504893] [client 20.48.160.90:50596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/82.php"] [unique_id "apPk4wgfiZclygrb6nkPJwAAA1M"]
[Sun Aug 30 03:08:03.248139 2026] [security2:error] [pid 504660:tid 504871] [client 68.155.159.216:60904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPk4wgfiZclygrb6nkPKwAAAz0"]
[Sun Aug 30 03:08:03.321439 2026] [security2:error] [pid 504660:tid 504861] [client 65.108.6.34:59736] ModSecurity: Warning. Matched phrase "SEOkicks" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "flashflooring.co.uk"] [uri "/index.php"] [unique_id "apPk4ggfiZclygrb6nkOfwAAAzM"], referer: https://flashflooring.co.uk/sitemap_index.xml
[Sun Aug 30 03:08:03.374738 2026] [security2:error] [pid 504660:tid 504935] [client 68.155.159.216:46040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/goods.php"] [unique_id "apPk4wgfiZclygrb6nkPXAAAA30"]
[Sun Aug 30 03:08:03.375383 2026] [security2:error] [pid 504660:tid 504907] [client 20.48.160.90:50687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/dex.php"] [unique_id "apPk4wgfiZclygrb6nkPXgAAA2E"]
[Sun Aug 30 03:08:03.377781 2026] [security2:error] [pid 504660:tid 504927] [client 52.139.37.240:25789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/403.php"] [unique_id "apPk4wgfiZclygrb6nkPYAAAA3U"]
[Sun Aug 30 03:08:03.414434 2026] [security2:error] [pid 504660:tid 504840] [client 74.248.24.12:11863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/class-t.api.php"] [unique_id "apPk4wgfiZclygrb6nkPZwAAAx4"]
[Sun Aug 30 03:08:03.438220 2026] [security2:error] [pid 504660:tid 504888] [client 20.48.250.41:18388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/term.php"] [unique_id "apPk4wgfiZclygrb6nkPbQAAA04"]
[Sun Aug 30 03:08:03.465679 2026] [authz_core:error] [pid 504660:tid 504924] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AG
[Sun Aug 30 03:08:03.466034 2026] [authz_core:error] [pid 504660:tid 504924] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AG
[Sun Aug 30 03:08:03.484261 2026] [authz_core:error] [pid 504660:tid 504910] [client 66.249.66.75:53713] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:03.484535 2026] [authz_core:error] [pid 504660:tid 504910] [client 66.249.66.75:53713] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:03.521546 2026] [authz_core:error] [pid 504660:tid 504946] [client 216.73.216.128:40000] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:03.521866 2026] [authz_core:error] [pid 504660:tid 504946] [client 216.73.216.128:40000] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:03.528587 2026] [security2:error] [pid 504660:tid 504863] [client 68.155.159.216:11143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/bk/index.php"] [unique_id "apPk4wgfiZclygrb6nkPjQAAAzU"]
[Sun Aug 30 03:08:03.537927 2026] [security2:error] [pid 504660:tid 504927] [client 20.104.49.130:34552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/run.php"] [unique_id "apPk4wgfiZclygrb6nkPlAAAA3U"]
[Sun Aug 30 03:08:03.542846 2026] [security2:error] [pid 504660:tid 504869] [client 20.48.160.90:50680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/inso.php"] [unique_id "apPk4wgfiZclygrb6nkPmgAAAzs"]
[Sun Aug 30 03:08:03.555650 2026] [security2:error] [pid 504660:tid 504933] [client 158.23.147.79:58413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/makeasmtp.php"] [unique_id "apPk4wgfiZclygrb6nkPngAAA3s"]
[Sun Aug 30 03:08:03.558845 2026] [security2:error] [pid 504660:tid 504899] [client 20.197.61.180:7857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/doc.php"] [unique_id "apPk4wgfiZclygrb6nkPoAAAA1k"]
[Sun Aug 30 03:08:03.570460 2026] [security2:error] [pid 504660:tid 504868] [client 52.139.37.240:48755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/av.php"] [unique_id "apPk4wgfiZclygrb6nkPpgAAAzo"]
[Sun Aug 30 03:08:03.585429 2026] [security2:error] [pid 504660:tid 504879] [client 20.48.251.3:56356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/aws_auth.php"] [unique_id "apPk4wgfiZclygrb6nkPsAAAA0U"]
[Sun Aug 30 03:08:03.589364 2026] [security2:error] [pid 504660:tid 504864] [client 20.196.209.81:11360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/aaa.php"] [unique_id "apPk4wgfiZclygrb6nkPsgAAAzY"]
[Sun Aug 30 03:08:03.599107 2026] [security2:error] [pid 504660:tid 504918] [client 20.104.18.15:28445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/f.php"] [unique_id "apPk4wgfiZclygrb6nkPtwAAA2w"]
[Sun Aug 30 03:08:03.610786 2026] [security2:error] [pid 504660:tid 504865] [client 4.205.62.107:39106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/wp-info.php"] [unique_id "apPk4wgfiZclygrb6nkPuwAAAzc"]
[Sun Aug 30 03:08:03.616748 2026] [authz_core:error] [pid 504660:tid 504860] [client 216.73.216.128:12390] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:03.618624 2026] [security2:error] [pid 504660:tid 504927] [client 68.155.159.216:64778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apPk4wgfiZclygrb6nkPwgAAA3U"]
[Sun Aug 30 03:08:03.617074 2026] [authz_core:error] [pid 504660:tid 504860] [client 216.73.216.128:12390] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:03.633761 2026] [security2:error] [pid 504660:tid 504847] [client 40.83.93.50:13764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/composer.php"] [unique_id "apPk4wgfiZclygrb6nkPygAAAyU"]
[Sun Aug 30 03:08:03.645718 2026] [security2:error] [pid 504660:tid 504852] [client 20.104.50.220:33024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/xml.php"] [unique_id "apPk4wgfiZclygrb6nkPzQAAAyo"]
[Sun Aug 30 03:08:03.648700 2026] [security2:error] [pid 504660:tid 504892] [client 20.48.250.41:18414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/aaa.php"] [unique_id "apPk4wgfiZclygrb6nkPzwAAA1I"]
[Sun Aug 30 03:08:03.666232 2026] [security2:error] [pid 504660:tid 504898] [client 20.104.50.220:5922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/36.php"] [unique_id "apPk4wgfiZclygrb6nkP1QAAA1g"]
[Sun Aug 30 03:08:03.680077 2026] [security2:error] [pid 504660:tid 504895] [client 20.104.18.15:23531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/8.php"] [unique_id "apPk4wgfiZclygrb6nkP2wAAA1U"]
[Sun Aug 30 03:08:03.682011 2026] [security2:error] [pid 504660:tid 504861] [client 68.155.159.216:61688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/packed.php"] [unique_id "apPk4wgfiZclygrb6nkP3AAAAzM"]
[Sun Aug 30 03:08:03.685547 2026] [security2:error] [pid 504660:tid 504848] [client 20.104.50.220:31896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/ws.php"] [unique_id "apPk4wgfiZclygrb6nkP3wAAAyY"]
[Sun Aug 30 03:08:03.690384 2026] [security2:error] [pid 504660:tid 504900] [client 20.104.50.220:46435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/fffff.php"] [unique_id "apPk4wgfiZclygrb6nkP4QAAA1o"]
[Sun Aug 30 03:08:03.690409 2026] [security2:error] [pid 504660:tid 504879] [client 20.48.160.90:50602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/aa.php"] [unique_id "apPk4wgfiZclygrb6nkP4AAAA0U"]
[Sun Aug 30 03:08:03.695572 2026] [security2:error] [pid 504660:tid 504875] [client 20.104.18.15:34711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/new.php"] [unique_id "apPk4wgfiZclygrb6nkP4gAAA0E"]
[Sun Aug 30 03:08:03.710633 2026] [security2:error] [pid 504660:tid 504966] [client 20.104.50.220:52826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wpvitamins.php"] [unique_id "apPk4wgfiZclygrb6nkP6QAAA5w"]
[Sun Aug 30 03:08:03.735713 2026] [security2:error] [pid 504660:tid 504883] [client 20.104.50.220:29123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/gelis.php"] [unique_id "apPk4wgfiZclygrb6nkP8gAAA0k"]
[Sun Aug 30 03:08:03.744927 2026] [security2:error] [pid 504660:tid 504932] [client 20.104.50.220:51644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/0x1337.php"] [unique_id "apPk4wgfiZclygrb6nkP9QAAA3o"]
[Sun Aug 30 03:08:03.747821 2026] [security2:error] [pid 504660:tid 504843] [client 4.205.62.107:62296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/pouhg.php"] [unique_id "apPk4wgfiZclygrb6nkP9wAAAyE"]
[Sun Aug 30 03:08:03.748930 2026] [security2:error] [pid 504660:tid 504937] [client 20.104.18.15:35148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/ops.php"] [unique_id "apPk4wgfiZclygrb6nkP-QAAA38"]
[Sun Aug 30 03:08:03.762463 2026] [security2:error] [pid 504660:tid 504892] [client 68.155.159.216:12351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPk4wgfiZclygrb6nkQAQAAA1I"]
[Sun Aug 30 03:08:03.769188 2026] [security2:error] [pid 504660:tid 504953] [client 4.205.62.107:64664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/phpsysinfo.php"] [unique_id "apPk4wgfiZclygrb6nkQBAAAA48"]
[Sun Aug 30 03:08:03.774756 2026] [security2:error] [pid 504660:tid 504940] [client 34.125.55.247:29410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/.env.orig"] [unique_id "apPk4wgfiZclygrb6nkQCQAAA4I"]
[Sun Aug 30 03:08:03.774791 2026] [security2:error] [pid 504660:tid 504966] [client 20.104.18.15:18281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/nano.php"] [unique_id "apPk4wgfiZclygrb6nkQCgAAA5w"]
[Sun Aug 30 03:08:03.775596 2026] [security2:error] [pid 504660:tid 504864] [client 52.139.37.240:49135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/wp-admin/index.php"] [unique_id "apPk4wgfiZclygrb6nkQDAAAAzY"]
[Sun Aug 30 03:08:03.776276 2026] [security2:error] [pid 504660:tid 504959] [client 34.125.55.247:29434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.55.125.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.engaginggoddaily.com"] [uri "/.env.php"] [unique_id "apPk4wgfiZclygrb6nkQDwAAA5U"]
[Sun Aug 30 03:08:03.776615 2026] [security2:error] [pid 504660:tid 504924] [client 34.125.55.247:29528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/services/api/.env"] [unique_id "apPk4wgfiZclygrb6nkQDgAAA3I"]
[Sun Aug 30 03:08:03.776737 2026] [security2:error] [pid 504660:tid 504924] [client 34.125.55.247:29528] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/services/api/.env"] [unique_id "apPk4wgfiZclygrb6nkQDgAAA3I"]
[Sun Aug 30 03:08:03.778316 2026] [security2:error] [pid 504660:tid 504898] [client 34.125.55.247:29612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/backend/.env.backup"] [unique_id "apPk4wgfiZclygrb6nkQFAAAA1g"]
[Sun Aug 30 03:08:03.778924 2026] [security2:error] [pid 504660:tid 504915] [client 34.125.55.247:29466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.55.125.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.engaginggoddaily.com"] [uri "/config/.env.php"] [unique_id "apPk4wgfiZclygrb6nkQGgAAA2k"]
[Sun Aug 30 03:08:03.778941 2026] [security2:error] [pid 504660:tid 504868] [client 34.125.55.247:29480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/deploy/.env"] [unique_id "apPk4wgfiZclygrb6nkQFwAAAzo"]
[Sun Aug 30 03:08:03.779755 2026] [security2:error] [pid 504660:tid 504965] [client 34.125.55.247:29392] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/.env.production.bak"] [unique_id "apPk4wgfiZclygrb6nkQGQAAA5s"]
[Sun Aug 30 03:08:03.780987 2026] [security2:error] [pid 504660:tid 504905] [client 34.125.55.247:29388] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/service/.env"] [unique_id "apPk4wgfiZclygrb6nkQHgAAA18"]
[Sun Aug 30 03:08:03.781341 2026] [security2:error] [pid 504660:tid 504895] [client 34.125.55.247:29552] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "cpanel.engaginggoddaily.com"] [uri "/wp-config.php.save"] [unique_id "apPk4wgfiZclygrb6nkQIQAAA1U"]
[Sun Aug 30 03:08:03.782773 2026] [security2:error] [pid 504660:tid 504945] [client 34.125.55.247:29556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.55.125.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.engaginggoddaily.com"] [uri "/config/config.php"] [unique_id "apPk4wgfiZclygrb6nkQJgAAA4c"]
[Sun Aug 30 03:08:03.784358 2026] [security2:error] [pid 504660:tid 504842] [client 34.125.55.247:29576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/config/credentials.json.bak"] [unique_id "apPk4wgfiZclygrb6nkQKAAAAyA"]
[Sun Aug 30 03:08:03.784613 2026] [proxy_http:error] [pid 504660:tid 504914] (20014)Internal error (specific information not available): [client 34.125.55.247:29372] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:03.784628 2026] [proxy:error] [pid 504660:tid 504914] [client 34.125.55.247:29372] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/log-viewer
[Sun Aug 30 03:08:03.785666 2026] [security2:error] [pid 504660:tid 504907] [client 34.125.55.247:29510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/app/.env.backup"] [unique_id "apPk4wgfiZclygrb6nkQLAAAA2E"]
[Sun Aug 30 03:08:03.785692 2026] [security2:error] [pid 504660:tid 504926] [client 34.125.55.247:29534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/env.old"] [unique_id "apPk4wgfiZclygrb6nkQLQAAA3Q"]
[Sun Aug 30 03:08:03.785778 2026] [security2:error] [pid 504660:tid 504900] [client 34.125.55.247:29570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.55.125.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.engaginggoddaily.com"] [uri "/database.php"] [unique_id "apPk4wgfiZclygrb6nkQMAAAA1o"]
[Sun Aug 30 03:08:03.786044 2026] [security2:error] [pid 504660:tid 504858] [client 34.125.55.247:29536] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/env.bak"] [unique_id "apPk4wgfiZclygrb6nkQLgAAAzA"]
[Sun Aug 30 03:08:03.786148 2026] [security2:error] [pid 504660:tid 504858] [client 34.125.55.247:29536] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/env.bak"] [unique_id "apPk4wgfiZclygrb6nkQLgAAAzA"]
[Sun Aug 30 03:08:03.789050 2026] [security2:error] [pid 504660:tid 504843] [client 20.104.50.220:17240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/7.php"] [unique_id "apPk4wgfiZclygrb6nkQMQAAAyE"]
[Sun Aug 30 03:08:03.791711 2026] [proxy_http:error] [pid 504660:tid 504950] (20014)Internal error (specific information not available): [client 34.125.55.247:29406] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:03.791727 2026] [proxy:error] [pid 504660:tid 504950] [client 34.125.55.247:29406] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.env.production.local
[Sun Aug 30 03:08:03.795684 2026] [security2:error] [pid 504660:tid 504891] [client 20.48.250.41:18427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/xsox.php"] [unique_id "apPk4wgfiZclygrb6nkQOAAAA1E"]
[Sun Aug 30 03:08:03.800120 2026] [proxy_http:error] [pid 504660:tid 504880] (20014)Internal error (specific information not available): [client 34.125.55.247:29460] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:03.800135 2026] [proxy:error] [pid 504660:tid 504880] [client 34.125.55.247:29460] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/config/.env.production
[Sun Aug 30 03:08:03.806695 2026] [proxy_http:error] [pid 504660:tid 504919] (20014)Internal error (specific information not available): [client 34.125.55.247:29474] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:03.806708 2026] [proxy:error] [pid 504660:tid 504919] [client 34.125.55.247:29474] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/private/.env.production
[Sun Aug 30 03:08:03.807372 2026] [security2:error] [pid 504660:tid 504847] [client 20.104.18.15:29574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/xc.php"] [unique_id "apPk4wgfiZclygrb6nkQPgAAAyU"]
[Sun Aug 30 03:08:03.813303 2026] [proxy_http:error] [pid 504660:tid 504901] (20014)Internal error (specific information not available): [client 34.125.55.247:29448] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:03.813322 2026] [proxy:error] [pid 504660:tid 504901] [client 34.125.55.247:29448] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/config/.env.local
[Sun Aug 30 03:08:03.819850 2026] [proxy_http:error] [pid 504660:tid 504960] (20014)Internal error (specific information not available): [client 34.125.55.247:29438] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:03.819869 2026] [proxy:error] [pid 504660:tid 504960] [client 34.125.55.247:29438] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.env.prod.local
[Sun Aug 30 03:08:03.822702 2026] [security2:error] [pid 504660:tid 504841] [client 20.48.160.90:50584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/img.php"] [unique_id "apPk4wgfiZclygrb6nkQQwAAAx8"]
[Sun Aug 30 03:08:03.825363 2026] [security2:error] [pid 504660:tid 504908] [client 158.23.147.79:60223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apPk4wgfiZclygrb6nkQRgAAA2I"]
[Sun Aug 30 03:08:03.827612 2026] [proxy_http:error] [pid 504660:tid 504938] (20014)Internal error (specific information not available): [client 34.125.55.247:29616] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:03.827633 2026] [proxy:error] [pid 504660:tid 504938] [client 34.125.55.247:29616] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/storage/logs/laravel.log
[Sun Aug 30 03:08:03.835134 2026] [proxy_http:error] [pid 504660:tid 504914] (20014)Internal error (specific information not available): [client 34.125.55.247:29372] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:03.835150 2026] [proxy:error] [pid 504660:tid 504914] [client 34.125.55.247:29372] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml
[Sun Aug 30 03:08:03.843047 2026] [security2:error] [pid 504660:tid 504844] [client 34.125.55.247:29516] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/backend/.env.prod"] [unique_id "apPk4wgfiZclygrb6nkQLwAAAyI"]
[Sun Aug 30 03:08:03.843283 2026] [proxy_http:error] [pid 504660:tid 504859] (20014)Internal error (specific information not available): [client 34.125.55.247:29402] AH01102: error reading status line from remote server 127.0.0.1:2082, referer: https://cpanel.engaginggoddaily.com/.env.dev
[Sun Aug 30 03:08:03.926620 2026] [security2:error] [pid 504660:tid 504955] [client 74.248.24.12:10294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/archive.php"] [unique_id "apPk4wgfiZclygrb6nkQhgAAA5E"]
[Sun Aug 30 03:08:03.926758 2026] [security2:error] [pid 504660:tid 504895] [client 20.48.250.41:18378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/lkui.php"] [unique_id "apPk4wgfiZclygrb6nkQhwAAA1U"]
[Sun Aug 30 03:08:03.940400 2026] [security2:error] [pid 504660:tid 504911] [client 20.48.251.3:7415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/aws.php"] [unique_id "apPk4wgfiZclygrb6nkQjQAAA2U"]
[Sun Aug 30 03:08:03.951493 2026] [security2:error] [pid 504660:tid 504905] [client 4.205.62.107:36001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/ah25.php"] [unique_id "apPk4wgfiZclygrb6nkQkQAAA18"]
[Sun Aug 30 03:08:03.953690 2026] [security2:error] [pid 504660:tid 504965] [client 20.104.104.62:48009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPk4wgfiZclygrb6nkQkgAAA5s"]
[Sun Aug 30 03:08:03.959847 2026] [security2:error] [pid 504660:tid 504870] [client 20.104.18.15:51682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/x.php"] [unique_id "apPk4wgfiZclygrb6nkQlgAAAzw"]
[Sun Aug 30 03:08:03.966019 2026] [security2:error] [pid 504660:tid 504869] [client 20.104.18.15:1925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/adminfuns.php"] [unique_id "apPk4wgfiZclygrb6nkQmQAAAzs"]
[Sun Aug 30 03:08:03.971523 2026] [security2:error] [pid 504660:tid 504914] [client 52.139.37.240:25784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "apPk4wgfiZclygrb6nkQmwAAA2g"]
[Sun Aug 30 03:08:03.993461 2026] [security2:error] [pid 504660:tid 504840] [client 20.48.160.90:50626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/222.php"] [unique_id "apPk4wgfiZclygrb6nkQogAAAx4"]
[Sun Aug 30 03:08:04.020619 2026] [security2:error] [pid 504660:tid 504897] [client 20.48.251.3:4735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/oc460l3x.php"] [unique_id "apPk5AgfiZclygrb6nkQsgAAA1c"]
[Sun Aug 30 03:08:04.027893 2026] [authz_core:error] [pid 504660:tid 504859] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:04.028332 2026] [authz_core:error] [pid 504660:tid 504859] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:04.033088 2026] [security2:error] [pid 504660:tid 504885] [client 20.196.209.81:12675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/atomlib.php"] [unique_id "apPk5AgfiZclygrb6nkQuAAAA0s"]
[Sun Aug 30 03:08:04.058126 2026] [authz_core:error] [pid 504660:tid 504866] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IN
[Sun Aug 30 03:08:04.058426 2026] [authz_core:error] [pid 504660:tid 504866] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IN
[Sun Aug 30 03:08:04.066708 2026] [security2:error] [pid 504660:tid 504913] [client 20.48.250.41:18369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apPk5AgfiZclygrb6nkQzAAAA2c"]
[Sun Aug 30 03:08:04.081414 2026] [security2:error] [pid 504660:tid 504919] [client 20.104.50.220:61639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-admin/mailer.php"] [unique_id "apPk5AgfiZclygrb6nkQzwAAA20"]
[Sun Aug 30 03:08:04.085119 2026] [security2:error] [pid 504660:tid 504842] [client 20.104.104.62:37574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPk5AgfiZclygrb6nkQ0QAAAyA"]
[Sun Aug 30 03:08:04.137792 2026] [security2:error] [pid 504660:tid 504891] [client 40.83.93.50:13808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/abcd.php"] [unique_id "apPk5AgfiZclygrb6nkQ3gAAA1E"]
[Sun Aug 30 03:08:04.173279 2026] [security2:error] [pid 504660:tid 504892] [client 52.139.37.240:49116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/wp-content/themes/pridmag/b.php"] [unique_id "apPk5AgfiZclygrb6nkQ7wAAA1I"]
[Sun Aug 30 03:08:04.181967 2026] [authz_core:error] [pid 504660:tid 504841] [client 66.249.66.41:55800] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:04.182397 2026] [authz_core:error] [pid 504660:tid 504841] [client 66.249.66.41:55800] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:04.187974 2026] [security2:error] [pid 504660:tid 504909] [client 20.48.160.90:50575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/key.php"] [unique_id "apPk5AgfiZclygrb6nkQ-gAAA2M"]
[Sun Aug 30 03:08:04.198151 2026] [security2:error] [pid 504660:tid 504902] [client 114.119.158.50:51275] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.khanwadeabutalib.com"] [uri "/public/ilm/view/94/1"] [unique_id "apPk5AgfiZclygrb6nkQ_AAAA1w"], referer: http://www.khanwadeabutalib.com/public/ilm/article/Imam-Ali-(as)-sayings-from-Nahjul-Balagh/658/1
[Sun Aug 30 03:08:04.213836 2026] [security2:error] [pid 504660:tid 504914] [client 20.104.104.62:37575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/h02ugyh.php"] [unique_id "apPk5AgfiZclygrb6nkRAwAAA2g"]
[Sun Aug 30 03:08:04.220460 2026] [security2:error] [pid 504660:tid 504905] [client 20.48.250.41:18325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/motu.php"] [unique_id "apPk5AgfiZclygrb6nkRCgAAA18"]
[Sun Aug 30 03:08:04.257659 2026] [security2:error] [pid 504660:tid 504887] [client 4.205.62.107:18809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/bigdump.php"] [unique_id "apPk5AgfiZclygrb6nkRGQAAA00"]
[Sun Aug 30 03:08:04.311040 2026] [security2:error] [pid 504660:tid 504952] [client 20.197.61.180:10434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/users.php"] [unique_id "apPk5AgfiZclygrb6nkROAAAA44"]
[Sun Aug 30 03:08:04.330399 2026] [security2:error] [pid 504660:tid 504899] [client 20.151.200.44:55734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/tf.php"] [unique_id "apPk5AgfiZclygrb6nkRPwAAA1k"]
[Sun Aug 30 03:08:04.342682 2026] [security2:error] [pid 504660:tid 504926] [client 20.104.104.62:48060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/sf.php"] [unique_id "apPk5AgfiZclygrb6nkRRwAAA3Q"]
[Sun Aug 30 03:08:04.362040 2026] [security2:error] [pid 504660:tid 504853] [client 20.48.160.90:50572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/chosen.php"] [unique_id "apPk5AgfiZclygrb6nkRTwAAAys"]
[Sun Aug 30 03:08:04.369397 2026] [security2:error] [pid 504660:tid 504953] [client 68.155.159.216:54210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apPk5AgfiZclygrb6nkRUgAAA48"]
[Sun Aug 30 03:08:04.403542 2026] [security2:error] [pid 504660:tid 504944] [client 20.48.250.41:18417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/Ov-Simple1.php"] [unique_id "apPk5AgfiZclygrb6nkRWgAAA4Y"]
[Sun Aug 30 03:08:04.435099 2026] [security2:error] [pid 504660:tid 504959] [client 74.248.24.12:10272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/bless.php"] [unique_id "apPk5AgfiZclygrb6nkRZAAAA5U"]
[Sun Aug 30 03:08:04.438539 2026] [authz_core:error] [pid 504660:tid 504856] [client 216.73.216.128:12390] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:04.438836 2026] [authz_core:error] [pid 504660:tid 504856] [client 216.73.216.128:12390] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:04.440151 2026] [security2:error] [pid 504660:tid 504937] [client 20.220.10.235:36814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPk5AgfiZclygrb6nkRZQAAA38"]
[Sun Aug 30 03:08:04.450962 2026] [security2:error] [pid 504660:tid 504942] [client 68.155.159.216:62064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/about.php"] [unique_id "apPk5AgfiZclygrb6nkRaQAAA4Q"]
[Sun Aug 30 03:08:04.464701 2026] [security2:error] [pid 504660:tid 504891] [client 20.196.209.81:12681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/buy.php"] [unique_id "apPk5AgfiZclygrb6nkRbQAAA1E"]
[Sun Aug 30 03:08:04.472415 2026] [security2:error] [pid 504660:tid 504927] [client 20.104.104.62:48055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/4e.php"] [unique_id "apPk5AgfiZclygrb6nkRcAAAA3U"]
[Sun Aug 30 03:08:04.475866 2026] [security2:error] [pid 504660:tid 504913] [client 20.104.49.130:63584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/ohct.php"] [unique_id "apPk5AgfiZclygrb6nkRcQAAA2c"]
[Sun Aug 30 03:08:04.479075 2026] [authz_core:error] [pid 504660:tid 504861] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_US
[Sun Aug 30 03:08:04.479354 2026] [authz_core:error] [pid 504660:tid 504861] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_US
[Sun Aug 30 03:08:04.496201 2026] [security2:error] [pid 504660:tid 504908] [client 20.48.160.90:50587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/file1221.php"] [unique_id "apPk5AgfiZclygrb6nkRdgAAA2I"]
[Sun Aug 30 03:08:04.508613 2026] [security2:error] [pid 504660:tid 504852] [client 68.155.159.216:45903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apPk5AgfiZclygrb6nkRegAAAyo"]
[Sun Aug 30 03:08:04.530920 2026] [security2:error] [pid 504660:tid 504853] [client 20.48.250.41:18348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/wp-blogs.php"] [unique_id "apPk5AgfiZclygrb6nkRhwAAAys"]
[Sun Aug 30 03:08:04.534738 2026] [security2:error] [pid 504660:tid 504858] [client 20.151.200.44:57862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/txets.php"] [unique_id "apPk5AgfiZclygrb6nkRigAAAzA"]
[Sun Aug 30 03:08:04.560997 2026] [security2:error] [pid 504660:tid 504935] [client 158.23.147.79:58398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apPk5AgfiZclygrb6nkRmgAAA30"]
[Sun Aug 30 03:08:04.569903 2026] [security2:error] [pid 504660:tid 504942] [client 20.220.10.235:36843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPk5AgfiZclygrb6nkRoQAAA4Q"]
[Sun Aug 30 03:08:04.622184 2026] [security2:error] [pid 504660:tid 504880] [client 20.104.104.62:48016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/ssss.php"] [unique_id "apPk5AgfiZclygrb6nkRtgAAA0Y"]
[Sun Aug 30 03:08:04.657347 2026] [security2:error] [pid 504660:tid 504846] [client 20.48.160.90:50564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/nox.php"] [unique_id "apPk5AgfiZclygrb6nkRxQAAAyQ"]
[Sun Aug 30 03:08:04.659365 2026] [security2:error] [pid 504660:tid 504928] [client 68.155.159.216:11223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.orbainsurance.com"] [uri "/first.php"] [unique_id "apPk5AgfiZclygrb6nkRyAAAA3Y"]
[Sun Aug 30 03:08:04.700194 2026] [security2:error] [pid 504660:tid 504897] [client 20.48.250.41:18422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/mini.php"] [unique_id "apPk5AgfiZclygrb6nkR1gAAA1c"]
[Sun Aug 30 03:08:04.701913 2026] [security2:error] [pid 504660:tid 504863] [client 40.83.93.50:13798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/sf.php"] [unique_id "apPk5AgfiZclygrb6nkR1wAAAzU"]
[Sun Aug 30 03:08:04.710208 2026] [security2:error] [pid 504660:tid 504883] [client 20.220.10.235:36827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/h02ugyh.php"] [unique_id "apPk5AgfiZclygrb6nkR3AAAA0k"]
[Sun Aug 30 03:08:04.718039 2026] [security2:error] [pid 504660:tid 504881] [client 68.155.159.216:65432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apPk5AgfiZclygrb6nkR4QAAA0c"]
[Sun Aug 30 03:08:04.734031 2026] [security2:error] [pid 504660:tid 504843] [client 20.48.251.3:33299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/hiquido.com/index.php"] [unique_id "apPk5AgfiZclygrb6nkR6gAAAyE"]
[Sun Aug 30 03:08:04.735921 2026] [security2:error] [pid 504660:tid 504856] [client 20.104.18.15:28504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sandiegoinsight.tastylandscape.com"] [uri "/1dfcd2d08f.php"] [unique_id "apPk5AgfiZclygrb6nkR7gAAAy4"]
[Sun Aug 30 03:08:04.742842 2026] [security2:error] [pid 504660:tid 504853] [client 4.205.62.107:63983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/fns.php"] [unique_id "apPk5AgfiZclygrb6nkR8wAAAys"]
[Sun Aug 30 03:08:04.797021 2026] [security2:error] [pid 504660:tid 504890] [client 20.104.50.220:5613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/35.php"] [unique_id "apPk5AgfiZclygrb6nkSDgAAA1A"]
[Sun Aug 30 03:08:04.797207 2026] [security2:error] [pid 504660:tid 504867] [client 20.104.50.220:33040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/xm.php"] [unique_id "apPk5AgfiZclygrb6nkSDwAAAzk"]
[Sun Aug 30 03:08:04.798637 2026] [security2:error] [pid 504660:tid 504932] [client 20.48.160.90:50608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/akismet.php"] [unique_id "apPk5AgfiZclygrb6nkSEAAAA3o"]
[Sun Aug 30 03:08:04.821369 2026] [security2:error] [pid 504660:tid 504881] [client 20.104.104.62:48054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/zoz.php"] [unique_id "apPk5AgfiZclygrb6nkSGQAAA0c"]
[Sun Aug 30 03:08:04.821431 2026] [security2:error] [pid 504660:tid 504952] [client 20.104.50.220:32071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/notfound.php"] [unique_id "apPk5AgfiZclygrb6nkSGgAAA44"]
[Sun Aug 30 03:08:04.832508 2026] [security2:error] [pid 504660:tid 504958] [client 20.104.18.15:34625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/inx.php"] [unique_id "apPk5AgfiZclygrb6nkSIAAAA5Q"]
[Sun Aug 30 03:08:04.834255 2026] [security2:error] [pid 504660:tid 504939] [client 20.104.18.15:23503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/goods.php"] [unique_id "apPk5AgfiZclygrb6nkSJAAAA4E"]
[Sun Aug 30 03:08:04.841193 2026] [security2:error] [pid 504660:tid 504908] [client 20.48.250.41:18385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/amp.php"] [unique_id "apPk5AgfiZclygrb6nkSKwAAA2I"]
[Sun Aug 30 03:08:04.845221 2026] [security2:error] [pid 504660:tid 504852] [client 20.104.50.220:46600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/indo.php"] [unique_id "apPk5AgfiZclygrb6nkSLwAAAyo"]
[Sun Aug 30 03:08:04.860717 2026] [security2:error] [pid 504660:tid 504877] [client 68.155.159.216:65482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/ans.php"] [unique_id "apPk5AgfiZclygrb6nkSOgAAA0M"]
[Sun Aug 30 03:08:04.872865 2026] [security2:error] [pid 504660:tid 504959] [client 20.104.50.220:62840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-content/pluginswp-freeform/black2llleaf.php"] [unique_id "apPk5AgfiZclygrb6nkSPwAAA5U"]
[Sun Aug 30 03:08:04.880204 2026] [security2:error] [pid 504660:tid 504842] [client 4.205.62.107:22574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/phpversion.php"] [unique_id "apPk5AgfiZclygrb6nkSQgAAAyA"]
[Sun Aug 30 03:08:04.881729 2026] [security2:error] [pid 504660:tid 504946] [client 20.196.209.81:13243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/hello.php"] [unique_id "apPk5AgfiZclygrb6nkSRgAAA4g"]
[Sun Aug 30 03:08:04.881862 2026] [security2:error] [pid 504660:tid 504938] [client 20.104.50.220:51622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/xltavrat.php"] [unique_id "apPk5AgfiZclygrb6nkSSAAAA4A"]
[Sun Aug 30 03:08:04.889392 2026] [security2:error] [pid 504660:tid 504917] [client 20.104.50.220:52815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/FierzaXploit.php"] [unique_id "apPk5AgfiZclygrb6nkSTgAAA2s"]
[Sun Aug 30 03:08:04.895827 2026] [security2:error] [pid 504660:tid 504920] [client 216.73.216.128:40000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPk5AgfiZclygrb6nkSVQAAA24"]
[Sun Aug 30 03:08:04.902084 2026] [security2:error] [pid 504660:tid 504941] [client 20.220.10.235:36822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/sf.php"] [unique_id "apPk5AgfiZclygrb6nkSXgAAA4M"]
[Sun Aug 30 03:08:04.909983 2026] [security2:error] [pid 504660:tid 504840] [client 20.104.18.15:18405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/ano.php"] [unique_id "apPk5AgfiZclygrb6nkSYwAAAx4"]
[Sun Aug 30 03:08:04.910142 2026] [security2:error] [pid 504660:tid 504853] [client 52.139.37.240:25745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/0.php"] [unique_id "apPk5AgfiZclygrb6nkSZQAAAys"]
[Sun Aug 30 03:08:04.925949 2026] [security2:error] [pid 504660:tid 504870] [client 20.104.50.220:17318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/8.php"] [unique_id "apPk5AgfiZclygrb6nkScQAAAzw"]
[Sun Aug 30 03:08:04.926255 2026] [security2:error] [pid 504660:tid 504931] [client 20.104.18.15:35502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/coffexium.php"] [unique_id "apPk5AgfiZclygrb6nkScgAAA3k"]
[Sun Aug 30 03:08:04.944525 2026] [security2:error] [pid 504660:tid 504966] [client 74.248.24.12:5231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/sagax1.php"] [unique_id "apPk5AgfiZclygrb6nkSeAAAA5w"]
[Sun Aug 30 03:08:04.952825 2026] [security2:error] [pid 504660:tid 504861] [client 20.48.160.90:50639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/ajax.php"] [unique_id "apPk5AgfiZclygrb6nkSfQAAAzM"]
[Sun Aug 30 03:08:04.958262 2026] [security2:error] [pid 504660:tid 504842] [client 20.104.104.62:37585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/kcs.php"] [unique_id "apPk5AgfiZclygrb6nkSgQAAAyA"]
[Sun Aug 30 03:08:04.963757 2026] [authz_core:error] [pid 504660:tid 504959] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZM
[Sun Aug 30 03:08:04.964116 2026] [authz_core:error] [pid 504660:tid 504959] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZM
[Sun Aug 30 03:08:04.966021 2026] [security2:error] [pid 504660:tid 504903] [client 68.155.159.216:62312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-content/packed.php"] [unique_id "apPk5AgfiZclygrb6nkShgAAA10"]
[Sun Aug 30 03:08:04.973127 2026] [security2:error] [pid 504660:tid 504928] [client 20.104.18.15:29137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/wp-content/l.php"] [unique_id "apPk5AgfiZclygrb6nkSigAAA3Y"]
[Sun Aug 30 03:08:04.980822 2026] [security2:error] [pid 504660:tid 504963] [client 20.48.250.41:18268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/cc13.php"] [unique_id "apPk5AgfiZclygrb6nkSkAAAA5k"]
[Sun Aug 30 03:08:04.989006 2026] [security2:error] [pid 504660:tid 504927] [client 4.205.62.107:61816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/sgd.php"] [unique_id "apPk5AgfiZclygrb6nkSlQAAA3U"]
[Sun Aug 30 03:08:04.993008 2026] [authz_core:error] [pid 504660:tid 504952] [client 216.73.216.128:12390] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:04.993338 2026] [authz_core:error] [pid 504660:tid 504952] [client 216.73.216.128:12390] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:05.034797 2026] [security2:error] [pid 504660:tid 504845] [client 20.220.10.235:36847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/4e.php"] [unique_id "apPk5QgfiZclygrb6nkSrAAAAyM"]
[Sun Aug 30 03:08:05.086118 2026] [authz_core:error] [pid 504660:tid 504902] [client 216.73.216.128:6999] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:05.086390 2026] [authz_core:error] [pid 504660:tid 504902] [client 216.73.216.128:6999] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:05.096264 2026] [security2:error] [pid 504660:tid 504881] [client 20.104.18.15:51672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apPk5QgfiZclygrb6nkSxwAAA0c"]
[Sun Aug 30 03:08:05.097786 2026] [security2:error] [pid 504660:tid 504917] [client 20.104.104.62:37581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/tajj.php"] [unique_id "apPk5QgfiZclygrb6nkSyQAAA2s"]
[Sun Aug 30 03:08:05.105102 2026] [security2:error] [pid 504660:tid 504887] [client 52.139.37.240:48756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/autoload_classmap/function.php"] [unique_id "apPk5QgfiZclygrb6nkSzgAAA00"]
[Sun Aug 30 03:08:05.105174 2026] [security2:error] [pid 504660:tid 504913] [client 20.104.18.15:2008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/classwithtostring.php"] [unique_id "apPk5QgfiZclygrb6nkSzQAAA2c"]
[Sun Aug 30 03:08:05.120218 2026] [security2:error] [pid 504660:tid 504865] [client 20.48.160.90:50679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/atomlib.php"] [unique_id "apPk5QgfiZclygrb6nkS0QAAAzc"]
[Sun Aug 30 03:08:05.143052 2026] [security2:error] [pid 504660:tid 504911] [client 20.48.250.41:18244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/aa.php"] [unique_id "apPk5QgfiZclygrb6nkS1wAAA2U"]
[Sun Aug 30 03:08:05.149295 2026] [security2:error] [pid 504660:tid 504864] [client 158.23.147.79:60210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-content/languages/about.php"] [unique_id "apPk5QgfiZclygrb6nkS2QAAAzY"]
[Sun Aug 30 03:08:05.150585 2026] [security2:error] [pid 504660:tid 504935] [client 20.197.61.180:19027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/class.php"] [unique_id "apPk5QgfiZclygrb6nkS2gAAA30"]
[Sun Aug 30 03:08:05.162636 2026] [security2:error] [pid 504660:tid 504937] [client 4.205.62.107:36608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/groceries/index.php"] [unique_id "apPk5QgfiZclygrb6nkS3QAAA38"]
[Sun Aug 30 03:08:05.162677 2026] [security2:error] [pid 504660:tid 504945] [client 4.205.62.107:32054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/aws_keys.php"] [unique_id "apPk5QgfiZclygrb6nkS3AAAA4c"]
[Sun Aug 30 03:08:05.167886 2026] [security2:error] [pid 504660:tid 504918] [client 20.220.10.235:36855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/ssss.php"] [unique_id "apPk5QgfiZclygrb6nkS4gAAA2w"]
[Sun Aug 30 03:08:05.173380 2026] [authz_core:error] [pid 504660:tid 504845] [client 216.73.216.128:40000] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:05.173652 2026] [authz_core:error] [pid 504660:tid 504845] [client 216.73.216.128:40000] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:05.188476 2026] [security2:error] [pid 504660:tid 504960] [client 20.48.251.3:4706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/drykl.php"] [unique_id "apPk5QgfiZclygrb6nkS6wAAA5Y"]
[Sun Aug 30 03:08:05.230347 2026] [security2:error] [pid 504660:tid 504891] [client 20.104.104.62:48051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/bge.php"] [unique_id "apPk5QgfiZclygrb6nkTAQAAA1E"]
[Sun Aug 30 03:08:05.234512 2026] [security2:error] [pid 504660:tid 504860] [client 20.104.50.220:59558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-content/mailer.php"] [unique_id "apPk5QgfiZclygrb6nkTAgAAAzI"]
[Sun Aug 30 03:08:05.248237 2026] [security2:error] [pid 504660:tid 504957] [client 40.83.93.50:17586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/gel4y.php"] [unique_id "apPk5QgfiZclygrb6nkTBAAAA5M"]
[Sun Aug 30 03:08:05.265789 2026] [authz_core:error] [pid 504660:tid 504966] [client 66.249.66.64:46863] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:05.266341 2026] [authz_core:error] [pid 504660:tid 504966] [client 66.249.66.64:46863] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:05.268736 2026] [authz_core:error] [pid 504660:tid 504954] [client 216.73.216.128:12390] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:05.268997 2026] [authz_core:error] [pid 504660:tid 504954] [client 216.73.216.128:12390] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:05.286431 2026] [security2:error] [pid 504660:tid 504896] [client 20.196.209.81:13197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/g.php"] [unique_id "apPk5QgfiZclygrb6nkTHgAAA1Y"]
[Sun Aug 30 03:08:05.292202 2026] [security2:error] [pid 504660:tid 504938] [client 20.48.250.41:18351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/s1.php"] [unique_id "apPk5QgfiZclygrb6nkTJgAAA4A"]
[Sun Aug 30 03:08:05.298979 2026] [security2:error] [pid 504660:tid 504932] [client 52.139.37.240:25737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/dvve.php"] [unique_id "apPk5QgfiZclygrb6nkTKAAAA3o"]
[Sun Aug 30 03:08:05.307216 2026] [security2:error] [pid 504660:tid 504858] [client 20.220.10.235:36931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/zoz.php"] [unique_id "apPk5QgfiZclygrb6nkTKwAAAzA"]
[Sun Aug 30 03:08:05.313942 2026] [security2:error] [pid 504660:tid 504900] [client 20.48.160.90:33277] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "celestialcreative.com"] [uri "/1.php"] [unique_id "apPk5QgfiZclygrb6nkTMAAAA1o"]
[Sun Aug 30 03:08:05.314049 2026] [security2:error] [pid 504660:tid 504900] [client 20.48.160.90:33277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/1.php"] [unique_id "apPk5QgfiZclygrb6nkTMAAAA1o"]
[Sun Aug 30 03:08:05.355891 2026] [authz_core:error] [pid 504660:tid 504911] [client 216.73.216.128:40000] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:05.356158 2026] [authz_core:error] [pid 504660:tid 504911] [client 216.73.216.128:40000] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:05.366972 2026] [security2:error] [pid 504660:tid 504953] [client 20.104.104.62:48005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/ssh3ll.php"] [unique_id "apPk5QgfiZclygrb6nkTQgAAA48"]
[Sun Aug 30 03:08:05.395242 2026] [security2:error] [pid 504660:tid 504841] [client 4.205.62.107:19031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/wdf.php"] [unique_id "apPk5QgfiZclygrb6nkTTQAAAx8"]
[Sun Aug 30 03:08:05.425264 2026] [security2:error] [pid 504660:tid 504967] [client 158.23.147.79:60191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-content/banners/about.php"] [unique_id "apPk5QgfiZclygrb6nkTVwAAA50"]
[Sun Aug 30 03:08:05.429195 2026] [security2:error] [pid 504660:tid 504907] [client 20.48.250.41:18384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/0byte.php"] [unique_id "apPk5QgfiZclygrb6nkTWAAAA2E"]
[Sun Aug 30 03:08:05.435243 2026] [security2:error] [pid 504660:tid 504882] [client 20.220.10.235:36829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/kcs.php"] [unique_id "apPk5QgfiZclygrb6nkTWgAAA0g"]
[Sun Aug 30 03:08:05.442008 2026] [security2:error] [pid 504660:tid 504903] [client 20.48.251.3:6469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/app.default.php"] [unique_id "apPk5QgfiZclygrb6nkTXwAAA10"]
[Sun Aug 30 03:08:05.445057 2026] [security2:error] [pid 504660:tid 504873] [client 20.48.160.90:33240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/samll.php"] [unique_id "apPk5QgfiZclygrb6nkTYQAAAz8"]
[Sun Aug 30 03:08:05.460702 2026] [security2:error] [pid 504660:tid 504961] [client 74.248.24.12:5220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/wpc.php"] [unique_id "apPk5QgfiZclygrb6nkTZgAAA5c"]
[Sun Aug 30 03:08:05.472323 2026] [authz_core:error] [pid 504660:tid 504958] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:05.472605 2026] [authz_core:error] [pid 504660:tid 504958] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:05.501801 2026] [autoindex:error] [pid 504660:tid 504967] [client 52.139.37.240:48745] AH01276: Cannot serve directory /home1/nattdesign/public_html/xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:08:05.507326 2026] [security2:error] [pid 504660:tid 504925] [client 20.104.104.62:48022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/motu.php"] [unique_id "apPk5QgfiZclygrb6nkTdQAAA3M"]
[Sun Aug 30 03:08:05.556071 2026] [security2:error] [pid 504660:tid 504924] [client 20.48.250.41:18253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/xr.php"] [unique_id "apPk5QgfiZclygrb6nkTjgAAA3I"]
[Sun Aug 30 03:08:05.564810 2026] [security2:error] [pid 504660:tid 504882] [client 52.139.37.240:48745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/ws77.php"] [unique_id "apPk5QgfiZclygrb6nkTmAAAA0g"]
[Sun Aug 30 03:08:05.565399 2026] [security2:error] [pid 504660:tid 504901] [client 20.220.10.235:36805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/tajj.php"] [unique_id "apPk5QgfiZclygrb6nkTmQAAA1s"]
[Sun Aug 30 03:08:05.567176 2026] [authz_core:error] [pid 504660:tid 504885] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NG
[Sun Aug 30 03:08:05.567607 2026] [authz_core:error] [pid 504660:tid 504885] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NG
[Sun Aug 30 03:08:05.590805 2026] [security2:error] [pid 504660:tid 504867] [client 20.48.160.90:50569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/she11.php"] [unique_id "apPk5QgfiZclygrb6nkTpgAAAzk"]
[Sun Aug 30 03:08:05.597983 2026] [authz_core:error] [pid 504660:tid 504897] [client 66.249.66.43:40867] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:05.598276 2026] [authz_core:error] [pid 504660:tid 504897] [client 66.249.66.43:40867] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:05.643471 2026] [security2:error] [pid 504660:tid 504845] [client 20.104.104.62:48038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/wefile.php"] [unique_id "apPk5QgfiZclygrb6nkTwgAAAyM"]
[Sun Aug 30 03:08:05.646412 2026] [security2:error] [pid 504660:tid 504864] [client 158.23.147.79:60205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apPk5QgfiZclygrb6nkTxAAAAzY"]
[Sun Aug 30 03:08:05.687213 2026] [security2:error] [pid 504660:tid 504846] [client 20.196.209.81:10060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/cc.php"] [unique_id "apPk5QgfiZclygrb6nkT1AAAAyQ"]
[Sun Aug 30 03:08:05.695707 2026] [security2:error] [pid 504660:tid 504872] [client 20.220.10.235:36970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/bge.php"] [unique_id "apPk5QgfiZclygrb6nkT1gAAAz4"]
[Sun Aug 30 03:08:05.716982 2026] [security2:error] [pid 504660:tid 504678] [remote 47.128.49.133:49836] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.chaosjelly.com"] [uri "/robots.txt"] [unique_id "apPk5QgfiZclygrb6nkT3wADexA"]
[Sun Aug 30 03:08:05.717238 2026] [security2:error] [pid 504660:tid 504877] [client 68.155.159.216:61416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apPk5QgfiZclygrb6nkT4AAAA0M"]
[Sun Aug 30 03:08:05.729261 2026] [security2:error] [pid 504660:tid 504941] [client 20.48.250.41:18334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/h02ugyh.php"] [unique_id "apPk5QgfiZclygrb6nkT6QAAA4M"]
[Sun Aug 30 03:08:05.746374 2026] [security2:error] [pid 504660:tid 504952] [client 20.48.160.90:50682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/kerang.php"] [unique_id "apPk5QgfiZclygrb6nkT9AAAA44"]
[Sun Aug 30 03:08:05.755369 2026] [security2:error] [pid 504660:tid 504950] [client 68.155.159.216:46026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-admin/includes/nav.php"] [unique_id "apPk5QgfiZclygrb6nkT-gAAA4w"]
[Sun Aug 30 03:08:05.759950 2026] [security2:error] [pid 504660:tid 504847] [client 52.139.37.240:25735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/admin/function.php"] [unique_id "apPk5QgfiZclygrb6nkT-wAAAyU"]
[Sun Aug 30 03:08:05.770176 2026] [security2:error] [pid 504660:tid 504927] [client 40.83.93.50:17546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/leaf.php"] [unique_id "apPk5QgfiZclygrb6nkT_wAAA3U"]
[Sun Aug 30 03:08:05.785220 2026] [authz_core:error] [pid 504660:tid 504937] [client 66.249.66.77:35208] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:05.785500 2026] [authz_core:error] [pid 504660:tid 504937] [client 66.249.66.77:35208] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:05.827261 2026] [security2:error] [pid 504660:tid 504967] [client 20.220.10.235:36816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/ssh3ll.php"] [unique_id "apPk5QgfiZclygrb6nkUHgAAA50"]
[Sun Aug 30 03:08:05.832355 2026] [security2:error] [pid 504660:tid 504944] [client 68.155.159.216:61363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/packed.php"] [unique_id "apPk5QgfiZclygrb6nkUJQAAA4Y"]
[Sun Aug 30 03:08:05.833097 2026] [core:alert] [pid 504660:tid 504935] [client 35.186.144.56:0] /home3/fremant1/thedevonshireteaguide.com.au/.htaccess: without matching section
[Sun Aug 30 03:08:05.857680 2026] [security2:error] [pid 504660:tid 504889] [client 20.48.250.41:18350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/xxw.php"] [unique_id "apPk5QgfiZclygrb6nkUQAAAA08"]
[Sun Aug 30 03:08:05.869237 2026] [security2:error] [pid 504660:tid 504869] [client 20.197.61.180:19025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/auth.php"] [unique_id "apPk5QgfiZclygrb6nkURgAAAzs"]
[Sun Aug 30 03:08:05.877343 2026] [security2:error] [pid 504660:tid 504872] [client 20.48.160.90:50561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/m.php"] [unique_id "apPk5QgfiZclygrb6nkUSAAAAz4"]
[Sun Aug 30 03:08:05.881580 2026] [security2:error] [pid 504660:tid 504905] [client 4.205.62.107:63960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/params.php"] [unique_id "apPk5QgfiZclygrb6nkUTQAAA18"]
[Sun Aug 30 03:08:05.882276 2026] [security2:error] [pid 504660:tid 504925] [client 20.48.251.3:56330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/ws79.php"] [unique_id "apPk5QgfiZclygrb6nkUTgAAA3M"]
[Sun Aug 30 03:08:05.888089 2026] [security2:error] [pid 504660:tid 504963] [client 20.104.104.62:37576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/Contrller.php"] [unique_id "apPk5QgfiZclygrb6nkUUgAAA5k"]
[Sun Aug 30 03:08:05.938012 2026] [security2:error] [pid 504660:tid 504961] [client 20.104.50.220:32843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/xamp.php"] [unique_id "apPk5QgfiZclygrb6nkUdgAAA5c"]
[Sun Aug 30 03:08:05.940719 2026] [security2:error] [pid 504660:tid 504867] [client 20.104.50.220:5599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/34.php"] [unique_id "apPk5QgfiZclygrb6nkUdwAAAzk"]
[Sun Aug 30 03:08:05.954371 2026] [security2:error] [pid 504660:tid 504863] [client 52.139.37.240:25748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/xx.php"] [unique_id "apPk5QgfiZclygrb6nkUgAAAAzU"]
[Sun Aug 30 03:08:05.964520 2026] [authz_core:error] [pid 504660:tid 504908] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_HK
[Sun Aug 30 03:08:05.964804 2026] [authz_core:error] [pid 504660:tid 504908] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_HK
[Sun Aug 30 03:08:05.967940 2026] [security2:error] [pid 504660:tid 504960] [client 20.104.50.220:31934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wso1337.php"] [unique_id "apPk5QgfiZclygrb6nkUhQAAA5Y"]
[Sun Aug 30 03:08:05.968592 2026] [security2:error] [pid 504660:tid 504913] [client 68.155.159.216:12370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/worksec.php"] [unique_id "apPk5QgfiZclygrb6nkUhgAAA2c"]
[Sun Aug 30 03:08:05.970937 2026] [security2:error] [pid 504660:tid 504926] [client 74.248.24.12:14405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/fone1.php"] [unique_id "apPk5QgfiZclygrb6nkUhwAAA3Q"]
[Sun Aug 30 03:08:05.973524 2026] [security2:error] [pid 504660:tid 504935] [client 20.220.10.235:36804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/motu.php"] [unique_id "apPk5QgfiZclygrb6nkUiQAAA30"]
[Sun Aug 30 03:08:05.974404 2026] [authz_core:error] [pid 504660:tid 504902] [client 66.249.66.75:47345] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:05.974846 2026] [authz_core:error] [pid 504660:tid 504902] [client 66.249.66.75:47345] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:05.980275 2026] [security2:error] [pid 504660:tid 504860] [client 20.104.18.15:23491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/ah.php"] [unique_id "apPk5QgfiZclygrb6nkUjAAAAzI"]
[Sun Aug 30 03:08:05.986957 2026] [security2:error] [pid 504660:tid 504850] [client 20.104.50.220:46373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/fileas.php"] [unique_id "apPk5QgfiZclygrb6nkUjwAAAyg"]
[Sun Aug 30 03:08:05.996270 2026] [security2:error] [pid 504660:tid 504959] [client 20.48.250.41:18250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/bolt.php"] [unique_id "apPk5QgfiZclygrb6nkUlAAAA5U"]
[Sun Aug 30 03:08:06.000657 2026] [authz_core:error] [pid 504660:tid 504898] [client 216.73.216.128:40000] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:06.000978 2026] [authz_core:error] [pid 504660:tid 504898] [client 216.73.216.128:40000] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:06.008556 2026] [security2:error] [pid 504660:tid 504931] [client 20.104.18.15:34756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/vpn.php"] [unique_id "apPk5ggfiZclygrb6nkUnAAAA3k"]
[Sun Aug 30 03:08:06.015020 2026] [security2:error] [pid 504660:tid 504904] [client 20.48.160.90:50667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/fling.php"] [unique_id "apPk5ggfiZclygrb6nkUoAAAA14"]
[Sun Aug 30 03:08:06.015498 2026] [security2:error] [pid 504660:tid 504852] [client 20.104.50.220:29151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/meiwei.php"] [unique_id "apPk5ggfiZclygrb6nkUoQAAAyo"]
[Sun Aug 30 03:08:06.020959 2026] [security2:error] [pid 504660:tid 504853] [client 20.104.104.62:48008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/file66.php"] [unique_id "apPk5ggfiZclygrb6nkUqAAAAys"]
[Sun Aug 30 03:08:06.034278 2026] [security2:error] [pid 504660:tid 504846] [client 4.205.62.107:62404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/adminfus.php"] [unique_id "apPk5ggfiZclygrb6nkUswAAAyQ"]
[Sun Aug 30 03:08:06.035566 2026] [security2:error] [pid 504660:tid 504868] [client 20.104.50.220:51588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/12j.php"] [unique_id "apPk5ggfiZclygrb6nkUtQAAAzo"]
[Sun Aug 30 03:08:06.059501 2026] [security2:error] [pid 504660:tid 504965] [client 20.104.50.220:28710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/fxshell.php"] [unique_id "apPk5ggfiZclygrb6nkUxAAAA5s"]
[Sun Aug 30 03:08:06.063397 2026] [security2:error] [pid 504660:tid 504955] [client 20.104.50.220:17296] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/1.php"] [unique_id "apPk5ggfiZclygrb6nkUxgAAA5E"]
[Sun Aug 30 03:08:06.063508 2026] [security2:error] [pid 504660:tid 504955] [client 20.104.50.220:17296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/1.php"] [unique_id "apPk5ggfiZclygrb6nkUxgAAA5E"]
[Sun Aug 30 03:08:06.071195 2026] [security2:error] [pid 504660:tid 504852] [client 20.104.18.15:18409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/mgrr.php"] [unique_id "apPk5ggfiZclygrb6nkUyQAAAyo"]
[Sun Aug 30 03:08:06.085828 2026] [authz_core:error] [pid 504660:tid 504866] [client 66.249.66.72:45655] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:06.086310 2026] [authz_core:error] [pid 504660:tid 504866] [client 66.249.66.72:45655] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:06.088331 2026] [security2:error] [pid 504660:tid 504883] [client 20.196.209.81:11365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/f35.php"] [unique_id "apPk5ggfiZclygrb6nkUzgAAA0k"]
[Sun Aug 30 03:08:06.103861 2026] [security2:error] [pid 504660:tid 504917] [client 20.104.18.15:35035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/BDKR28WP.php"] [unique_id "apPk5ggfiZclygrb6nkU1QAAA2s"]
[Sun Aug 30 03:08:06.104308 2026] [security2:error] [pid 504660:tid 504961] [client 20.220.10.235:36821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/wefile.php"] [unique_id "apPk5ggfiZclygrb6nkU1wAAA5c"]
[Sun Aug 30 03:08:06.114831 2026] [security2:error] [pid 504660:tid 504843] [client 20.104.18.15:29178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/wp-admin/w.php"] [unique_id "apPk5ggfiZclygrb6nkU2QAAAyE"]
[Sun Aug 30 03:08:06.115195 2026] [authz_core:error] [pid 504660:tid 504952] [client 66.249.66.72:57110] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:06.115599 2026] [authz_core:error] [pid 504660:tid 504952] [client 66.249.66.72:57110] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:06.126978 2026] [security2:error] [pid 504660:tid 504935] [client 20.48.250.41:18396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/rtx.php"] [unique_id "apPk5ggfiZclygrb6nkU3QAAA30"]
[Sun Aug 30 03:08:06.138542 2026] [security2:error] [pid 504660:tid 504869] [client 20.48.250.41:47428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPk5ggfiZclygrb6nkU3wAAAzs"]
[Sun Aug 30 03:08:06.147025 2026] [security2:error] [pid 504660:tid 504963] [client 20.48.160.90:50684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/btyuio.php"] [unique_id "apPk5ggfiZclygrb6nkU4wAAA5k"]
[Sun Aug 30 03:08:06.150678 2026] [security2:error] [pid 504660:tid 504875] [client 52.139.37.240:25742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/wp-content/about.php"] [unique_id "apPk5ggfiZclygrb6nkU5QAAA0E"]
[Sun Aug 30 03:08:06.153240 2026] [security2:error] [pid 504660:tid 504930] [client 20.104.104.62:48043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/blnux.php"] [unique_id "apPk5ggfiZclygrb6nkU5gAAA3g"]
[Sun Aug 30 03:08:06.176450 2026] [security2:error] [pid 504660:tid 504850] [client 216.73.216.128:40000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPk5ggfiZclygrb6nkU8QAAAyg"]
[Sun Aug 30 03:08:06.182333 2026] [security2:error] [pid 504660:tid 504864] [client 158.23.147.79:60195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/asd.php"] [unique_id "apPk5ggfiZclygrb6nkU9gAAAzY"]
[Sun Aug 30 03:08:06.193836 2026] [security2:error] [pid 504660:tid 504856] [client 4.205.62.107:64473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/fleen.php"] [unique_id "apPk5ggfiZclygrb6nkU-gAAAy4"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:06.236970 2026] [security2:error] [pid 504660:tid 504891] [client 20.220.10.235:36846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/Contrller.php"] [unique_id "apPk5ggfiZclygrb6nkVEAAAA1E"]
[Sun Aug 30 03:08:06.245844 2026] [security2:error] [pid 504660:tid 504875] [client 68.155.159.216:54479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apPk5ggfiZclygrb6nkVEgAAA0E"]
[Sun Aug 30 03:08:06.256576 2026] [security2:error] [pid 504660:tid 504886] [client 20.104.18.15:51605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/wp-includes/index.php"] [unique_id "apPk5ggfiZclygrb6nkVGAAAA0w"]
[Sun Aug 30 03:08:06.262601 2026] [security2:error] [pid 504660:tid 504915] [client 20.104.18.15:1927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPk5ggfiZclygrb6nkVHQAAA2k"]
[Sun Aug 30 03:08:06.281329 2026] [security2:error] [pid 504660:tid 504944] [client 20.48.250.41:18247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/ckk.php"] [unique_id "apPk5ggfiZclygrb6nkVLAAAA4Y"]
[Sun Aug 30 03:08:06.291742 2026] [security2:error] [pid 504660:tid 504863] [client 20.104.104.62:48059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/attack.php"] [unique_id "apPk5ggfiZclygrb6nkVLwAAAzU"]
[Sun Aug 30 03:08:06.297749 2026] [security2:error] [pid 504660:tid 504953] [client 20.48.250.41:48082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPk5ggfiZclygrb6nkVMwAAA48"]
[Sun Aug 30 03:08:06.314903 2026] [security2:error] [pid 504660:tid 504894] [client 40.83.93.50:17589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/k.php"] [unique_id "apPk5ggfiZclygrb6nkVOwAAA1Q"]
[Sun Aug 30 03:08:06.320319 2026] [security2:error] [pid 504660:tid 504908] [client 4.205.62.107:36712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/konfig.php"] [unique_id "apPk5ggfiZclygrb6nkVPAAAA2I"]
[Sun Aug 30 03:08:06.324197 2026] [security2:error] [pid 504660:tid 504860] [client 20.48.251.3:44389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/rpk.php"] [unique_id "apPk5ggfiZclygrb6nkVPwAAAzI"]
[Sun Aug 30 03:08:06.326537 2026] [security2:error] [pid 504660:tid 504891] [client 20.151.200.44:47055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/tf.php"] [unique_id "apPk5ggfiZclygrb6nkVQAAAA1E"]
[Sun Aug 30 03:08:06.327214 2026] [security2:error] [pid 504660:tid 504899] [client 103.215.74.185:36350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.144.1.153"] [uri "/index.php"] [unique_id "apPk5ggfiZclygrb6nkVOQAAA1k"]
[Sun Aug 30 03:08:06.340319 2026] [security2:error] [pid 504660:tid 504918] [client 20.48.160.90:50658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/dehnl.php"] [unique_id "apPk5ggfiZclygrb6nkVSgAAA2w"]
[Sun Aug 30 03:08:06.352212 2026] [core:alert] [pid 504660:tid 504850] [client 35.186.144.56:0] /home3/fremant1/thedevonshireteaguide.com.au/.htaccess: without matching section
[Sun Aug 30 03:08:06.352580 2026] [security2:error] [pid 504660:tid 504881] [client 68.155.159.216:28646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-l0gin.php"] [unique_id "apPk5ggfiZclygrb6nkVTwAAA0c"]
[Sun Aug 30 03:08:06.359402 2026] [security2:error] [pid 504660:tid 504846] [client 52.139.37.240:49885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/wp-the.php"] [unique_id "apPk5ggfiZclygrb6nkVVAAAAyQ"]
[Sun Aug 30 03:08:06.369723 2026] [security2:error] [pid 504660:tid 504927] [client 20.220.10.235:36806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/file66.php"] [unique_id "apPk5ggfiZclygrb6nkVWAAAA3U"]
[Sun Aug 30 03:08:06.376516 2026] [security2:error] [pid 504660:tid 504907] [client 20.104.49.130:60670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/kerang.php"] [unique_id "apPk5ggfiZclygrb6nkVXQAAA2E"]
[Sun Aug 30 03:08:06.377719 2026] [security2:error] [pid 504660:tid 504848] [client 65.108.6.34:59742] ModSecurity: Warning. Matched phrase "SEOkicks" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "flashflooring.co.uk"] [uri "/index.php"] [unique_id "apPk5QgfiZclygrb6nkUbwAAAyY"], referer: https://flashflooring.co.uk/sitemap_index.xml
[Sun Aug 30 03:08:06.422282 2026] [security2:error] [pid 504660:tid 504861] [client 20.104.104.62:48006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/wk/index.php"] [unique_id "apPk5ggfiZclygrb6nkVawAAAzM"]
[Sun Aug 30 03:08:06.424204 2026] [security2:error] [pid 504660:tid 504859] [client 20.48.250.41:18431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.artsandcollectibles.com"] [uri "/R57.php"] [unique_id "apPk5ggfiZclygrb6nkVbQAAAzE"]
[Sun Aug 30 03:08:06.456013 2026] [authz_core:error] [pid 504660:tid 504942] [client 216.73.216.128:28110] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:06.456451 2026] [authz_core:error] [pid 504660:tid 504942] [client 216.73.216.128:28110] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:06.458882 2026] [authz_core:error] [pid 504660:tid 504945] [client 66.249.66.64:50757] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:06.459351 2026] [authz_core:error] [pid 504660:tid 504945] [client 66.249.66.64:50757] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:06.472992 2026] [security2:error] [pid 504660:tid 504850] [client 20.48.250.41:47432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/ff1.php"] [unique_id "apPk5ggfiZclygrb6nkVeQAAAyg"]
[Sun Aug 30 03:08:06.485794 2026] [security2:error] [pid 504660:tid 504912] [client 74.248.24.12:7424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/ncx.php"] [unique_id "apPk5ggfiZclygrb6nkVfgAAA2Y"]
[Sun Aug 30 03:08:06.494178 2026] [authz_core:error] [pid 504660:tid 504910] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IN
[Sun Aug 30 03:08:06.494545 2026] [authz_core:error] [pid 504660:tid 504910] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IN
[Sun Aug 30 03:08:06.503140 2026] [security2:error] [pid 504660:tid 504915] [client 20.220.10.235:36802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/blnux.php"] [unique_id "apPk5ggfiZclygrb6nkVhQAAA2k"]
[Sun Aug 30 03:08:06.508349 2026] [security2:error] [pid 504660:tid 504946] [client 20.48.160.90:33156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/zoo2.php"] [unique_id "apPk5ggfiZclygrb6nkVhwAAA4g"]
[Sun Aug 30 03:08:06.543550 2026] [security2:error] [pid 504660:tid 504919] [client 20.196.209.81:12695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/classsmtps.php"] [unique_id "apPk5ggfiZclygrb6nkVngAAA20"]
[Sun Aug 30 03:08:06.549513 2026] [security2:error] [pid 504660:tid 504918] [client 4.205.62.107:18772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/bb.php"] [unique_id "apPk5ggfiZclygrb6nkVpQAAA2w"]
[Sun Aug 30 03:08:06.550855 2026] [security2:error] [pid 504660:tid 504966] [client 52.139.37.240:48729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/ws81.php"] [unique_id "apPk5ggfiZclygrb6nkVpgAAA5w"]
[Sun Aug 30 03:08:06.571947 2026] [security2:error] [pid 504660:tid 504893] [client 20.104.104.62:37610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/dehnl.php"] [unique_id "apPk5ggfiZclygrb6nkVswAAA1M"]
[Sun Aug 30 03:08:06.608130 2026] [security2:error] [pid 504660:tid 504906] [client 103.215.74.185:16680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.144.1.153"] [uri "/index.php"] [unique_id "apPk5ggfiZclygrb6nkVwQAAA2A"]
[Sun Aug 30 03:08:06.621855 2026] [security2:error] [pid 504660:tid 504891] [client 20.48.250.41:47449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/t.php"] [unique_id "apPk5ggfiZclygrb6nkVygAAA1E"]
[Sun Aug 30 03:08:06.634226 2026] [security2:error] [pid 504660:tid 504933] [client 20.220.10.235:36820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/attack.php"] [unique_id "apPk5ggfiZclygrb6nkV0AAAA3s"]
[Sun Aug 30 03:08:06.640465 2026] [security2:error] [pid 504660:tid 504902] [client 20.48.160.90:50585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/zoo1.php"] [unique_id "apPk5ggfiZclygrb6nkV0wAAA1w"]
[Sun Aug 30 03:08:06.652658 2026] [security2:error] [pid 504660:tid 504953] [client 20.197.61.180:7822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/adminfuns.php"] [unique_id "apPk5ggfiZclygrb6nkV2AAAA48"]
[Sun Aug 30 03:08:06.708085 2026] [security2:error] [pid 504660:tid 504843] [client 158.23.147.79:58394] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.cherylvalk.com"] [uri "/1.php"] [unique_id "apPk5ggfiZclygrb6nkV8wAAAyE"]
[Sun Aug 30 03:08:06.708201 2026] [security2:error] [pid 504660:tid 504843] [client 158.23.147.79:58394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/1.php"] [unique_id "apPk5ggfiZclygrb6nkV8wAAAyE"]
[Sun Aug 30 03:08:06.729386 2026] [security2:error] [pid 504660:tid 504898] [client 20.104.104.62:37525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/png.php"] [unique_id "apPk5ggfiZclygrb6nkV_wAAA1g"]
[Sun Aug 30 03:08:06.736045 2026] [authz_core:error] [pid 504660:tid 504967] [client 66.249.66.64:46863] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:06.736501 2026] [authz_core:error] [pid 504660:tid 504967] [client 66.249.66.64:46863] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:06.752870 2026] [security2:error] [pid 504660:tid 504847] [client 52.139.37.240:48717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/a1.php"] [unique_id "apPk5ggfiZclygrb6nkWDAAAAyU"]
[Sun Aug 30 03:08:06.767273 2026] [security2:error] [pid 504660:tid 504930] [client 20.220.10.235:36858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/wk/index.php"] [unique_id "apPk5ggfiZclygrb6nkWEQAAA3g"]
[Sun Aug 30 03:08:06.806041 2026] [authz_core:error] [pid 504660:tid 504925] [client 66.249.66.40:64628] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:06.806351 2026] [authz_core:error] [pid 504660:tid 504925] [client 66.249.66.40:64628] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:06.811399 2026] [security2:error] [pid 504660:tid 504898] [client 20.48.250.41:47424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/erty.php"] [unique_id "apPk5ggfiZclygrb6nkWKwAAA1g"]
[Sun Aug 30 03:08:06.812869 2026] [security2:error] [pid 504660:tid 504941] [client 20.48.160.90:50620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/radio.php"] [unique_id "apPk5ggfiZclygrb6nkWLAAAA4M"]
[Sun Aug 30 03:08:06.813892 2026] [security2:error] [pid 504660:tid 504874] [client 40.83.93.50:13775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/chosen.php"] [unique_id "apPk5ggfiZclygrb6nkWLQAAA0A"]
[Sun Aug 30 03:08:06.875746 2026] [authz_core:error] [pid 504660:tid 504914] [client 66.249.66.77:56800] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:06.876042 2026] [authz_core:error] [pid 504660:tid 504914] [client 66.249.66.77:56800] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:06.890924 2026] [authz_core:error] [pid 504660:tid 504915] [client 66.249.66.67:36858] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:06.891235 2026] [authz_core:error] [pid 504660:tid 504915] [client 66.249.66.67:36858] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:06.899188 2026] [authz_core:error] [pid 504660:tid 504928] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:06.899458 2026] [authz_core:error] [pid 504660:tid 504928] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:06.960764 2026] [security2:error] [pid 504660:tid 504917] [client 20.196.209.81:11389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/install.php"] [unique_id "apPk5ggfiZclygrb6nkWYgAAA2s"]
[Sun Aug 30 03:08:07.002771 2026] [security2:error] [pid 504660:tid 504932] [client 74.248.24.12:6817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/zup.php73"] [unique_id "apPk5wgfiZclygrb6nkWaAAAA3o"]
[Sun Aug 30 03:08:07.014785 2026] [authz_core:error] [pid 504660:tid 504955] [client 216.73.216.128:28110] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:07.015246 2026] [authz_core:error] [pid 504660:tid 504955] [client 216.73.216.128:28110] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:07.053310 2026] [authz_core:error] [pid 504660:tid 504877] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZM
[Sun Aug 30 03:08:07.053571 2026] [authz_core:error] [pid 504660:tid 504877] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZM
[Sun Aug 30 03:08:07.188139 2026] [http2:info] [pid 507246:tid 507246] h2_workers: created with min=128 max=192 idle_ms=600000
[Sun Aug 30 03:08:07.217090 2026] [security2:error] [pid 507246:tid 507377] [client 4.205.62.107:32029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/umgebung.php"] [unique_id "apPk5-8CsCvw81e_I2osGQAAApo"]
[Sun Aug 30 03:08:07.217096 2026] [security2:error] [pid 507246:tid 507380] [client 20.48.250.41:47433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/0x.php"] [unique_id "apPk5-8CsCvw81e_I2osHQAAAp0"]
[Sun Aug 30 03:08:07.217137 2026] [security2:error] [pid 507246:tid 507379] [client 4.205.62.107:64003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/gjm.php"] [unique_id "apPk5-8CsCvw81e_I2osGgAAApw"]
[Sun Aug 30 03:08:07.217145 2026] [security2:error] [pid 507246:tid 507381] [client 20.48.251.3:56342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/public/wp-blog.php"] [unique_id "apPk5-8CsCvw81e_I2osHAAAAp4"]
[Sun Aug 30 03:08:07.217518 2026] [security2:error] [pid 507246:tid 507395] [client 4.205.62.107:62281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/avim.php"] [unique_id "apPk5-8CsCvw81e_I2osIgAAAqw"]
[Sun Aug 30 03:08:07.217539 2026] [security2:error] [pid 507246:tid 507392] [client 20.104.50.220:5914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/123456.php"] [unique_id "apPk5-8CsCvw81e_I2osIAAAAqk"]
[Sun Aug 30 03:08:07.217672 2026] [security2:error] [pid 507246:tid 507382] [client 20.104.104.62:48015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/txets.php"] [unique_id "apPk5-8CsCvw81e_I2osHgAAAp8"]
[Sun Aug 30 03:08:07.217720 2026] [security2:error] [pid 507246:tid 507396] [client 68.155.159.216:45962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/file.php"] [unique_id "apPk5-8CsCvw81e_I2osIwAAAq0"]
[Sun Aug 30 03:08:07.217819 2026] [security2:error] [pid 507246:tid 507378] [client 20.104.18.15:23392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/ws55.php"] [unique_id "apPk5-8CsCvw81e_I2osGwAAAps"]
[Sun Aug 30 03:08:07.217822 2026] [security2:error] [pid 507246:tid 507406] [client 20.48.160.90:50634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/one.php"] [unique_id "apPk5-8CsCvw81e_I2osJwAAArc"]
[Sun Aug 30 03:08:07.217829 2026] [security2:error] [pid 507246:tid 507404] [client 20.104.50.220:46453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/yellow.php"] [unique_id "apPk5-8CsCvw81e_I2osJgAAArU"]
[Sun Aug 30 03:08:07.217827 2026] [security2:error] [pid 507246:tid 507393] [client 20.104.50.220:33192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/ya.php"] [unique_id "apPk5-8CsCvw81e_I2osHwAAAqo"]
[Sun Aug 30 03:08:07.217862 2026] [security2:error] [pid 507246:tid 507411] [client 68.155.159.216:12399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/x.php"] [unique_id "apPk5-8CsCvw81e_I2osKQAAArw"]
[Sun Aug 30 03:08:07.217867 2026] [security2:error] [pid 507246:tid 507376] [client 68.155.159.216:63983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-content/packed.php"] [unique_id "apPk5-8CsCvw81e_I2osGAAAApk"]
[Sun Aug 30 03:08:07.217895 2026] [security2:error] [pid 507246:tid 507394] [client 20.104.50.220:63540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/danon.php"] [unique_id "apPk5-8CsCvw81e_I2osIQAAAqs"]
[Sun Aug 30 03:08:07.218062 2026] [security2:error] [pid 507246:tid 507401] [client 20.220.10.235:36844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/dehnl.php"] [unique_id "apPk5-8CsCvw81e_I2osJQAAArI"]
[Sun Aug 30 03:08:07.218096 2026] [security2:error] [pid 507246:tid 507400] [client 20.104.50.220:32573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wso2.php"] [unique_id "apPk5-8CsCvw81e_I2osJAAAArE"]
[Sun Aug 30 03:08:07.219023 2026] [security2:error] [pid 507246:tid 507414] [client 20.104.18.15:34741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/shiny.php"] [unique_id "apPk5-8CsCvw81e_I2osNwAAAr8"]
[Sun Aug 30 03:08:07.219775 2026] [security2:error] [pid 507246:tid 507417] [client 20.104.50.220:29138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/fonts/priv8.php"] [unique_id "apPk5-8CsCvw81e_I2osOQAAAsI"]
[Sun Aug 30 03:08:07.220498 2026] [security2:error] [pid 507246:tid 507423] [client 20.104.50.220:16588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/100.php"] [unique_id "apPk5-8CsCvw81e_I2osOgAAAsg"]
[Sun Aug 30 03:08:07.221579 2026] [security2:error] [pid 507246:tid 507432] [client 68.155.159.216:61408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/themes.php"] [unique_id "apPk5-8CsCvw81e_I2osOwAAAtE"]
[Sun Aug 30 03:08:07.228172 2026] [security2:error] [pid 507246:tid 507425] [client 20.104.50.220:63047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/fk.php7"] [unique_id "apPk5-8CsCvw81e_I2osTgAAAso"]
[Sun Aug 30 03:08:07.232271 2026] [security2:error] [pid 507246:tid 507426] [client 20.48.251.3:64469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/app_local.php"] [unique_id "apPk5-8CsCvw81e_I2osWgAAAss"]
[Sun Aug 30 03:08:07.240652 2026] [authz_core:error] [pid 507246:tid 507401] [client 66.249.66.68:56566] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:07.241097 2026] [authz_core:error] [pid 507246:tid 507401] [client 66.249.66.68:56566] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:07.243619 2026] [security2:error] [pid 507246:tid 507394] [client 20.104.18.15:18316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/mac.php"] [unique_id "apPk5-8CsCvw81e_I2osiAAAAqs"]
[Sun Aug 30 03:08:07.253964 2026] [proxy_http:error] [pid 507246:tid 507463] (20014)Internal error (specific information not available): [client 34.125.55.247:29692] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:07.253987 2026] [proxy:error] [pid 507246:tid 507463] [client 34.125.55.247:29692] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/gcloud-service-account.json
[Sun Aug 30 03:08:07.256873 2026] [security2:error] [pid 507246:tid 507396] [client 20.104.18.15:29063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/wp-content/k.php"] [unique_id "apPk5-8CsCvw81e_I2osowAAAq0"]
[Sun Aug 30 03:08:07.265713 2026] [proxy_http:error] [pid 507246:tid 507441] (20014)Internal error (specific information not available): [client 34.125.55.247:29620] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:07.265738 2026] [proxy:error] [pid 507246:tid 507441] [client 34.125.55.247:29620] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/settings.local.py
[Sun Aug 30 03:08:07.272714 2026] [security2:error] [pid 504660:tid 504965] [client 20.104.18.15:35457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/sf.php"] [unique_id "apPk5wgfiZclygrb6nkWnwAAA5s"]
[Sun Aug 30 03:08:07.273689 2026] [authz_core:error] [pid 507246:tid 507383] [client 66.249.66.71:61628] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:07.273872 2026] [security2:error] [pid 507246:tid 507452] [client 34.125.55.247:29760] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/home/node/.config/gcloud/application_default_credentials.json"] [unique_id "apPk5-8CsCvw81e_I2oscwAAAuU"]
[Sun Aug 30 03:08:07.275357 2026] [authz_core:error] [pid 507246:tid 507383] [client 66.249.66.71:61628] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:07.277131 2026] [authz_core:error] [pid 507246:tid 507397] [client 66.249.66.70:60100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:07.277577 2026] [authz_core:error] [pid 507246:tid 507397] [client 66.249.66.70:60100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:07.282878 2026] [proxy_http:error] [pid 507246:tid 507446] (20014)Internal error (specific information not available): [client 34.125.55.247:29676] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:07.282899 2026] [proxy:error] [pid 507246:tid 507446] [client 34.125.55.247:29676] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/home/node/.aws/credentials
[Sun Aug 30 03:08:07.291309 2026] [proxy_http:error] [pid 507246:tid 507470] (20014)Internal error (specific information not available): [client 34.125.55.247:29732] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:07.291326 2026] [proxy:error] [pid 507246:tid 507470] [client 34.125.55.247:29732] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/config/gcp.json
[Sun Aug 30 03:08:07.298930 2026] [security2:error] [pid 507246:tid 507496] [client 20.151.200.44:57797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/wp-login.php"] [unique_id "apPk5-8CsCvw81e_I2osjQAAAxE"]
[Sun Aug 30 03:08:07.300797 2026] [security2:error] [pid 507246:tid 507479] [client 34.125.55.247:29724] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "308"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/keys/gcp.json"] [unique_id "apPk5-8CsCvw81e_I2osjwAAAwA"]
[Sun Aug 30 03:08:07.307528 2026] [proxy_http:error] [pid 507246:tid 507414] (20014)Internal error (specific information not available): [client 34.125.55.247:29782] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:07.307542 2026] [proxy:error] [pid 507246:tid 507414] [client 34.125.55.247:29782] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/openai_key.json
[Sun Aug 30 03:08:07.314923 2026] [proxy_http:error] [pid 507246:tid 507380] (20014)Internal error (specific information not available): [client 34.125.55.247:29786] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:07.314943 2026] [proxy:error] [pid 507246:tid 507380] [client 34.125.55.247:29786] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.env.save
[Sun Aug 30 03:08:07.321455 2026] [proxy_http:error] [pid 507246:tid 507476] (20014)Internal error (specific information not available): [client 34.125.55.247:29708] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:07.321476 2026] [proxy:error] [pid 507246:tid 507476] [client 34.125.55.247:29708] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/serviceAccount.json
[Sun Aug 30 03:08:07.322286 2026] [security2:error] [pid 507246:tid 507384] [client 52.139.37.240:25743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/ca5.php"] [unique_id "apPk5-8CsCvw81e_I2osxwAAAqE"]
[Sun Aug 30 03:08:07.329778 2026] [security2:error] [pid 507246:tid 507441] [client 34.125.55.247:29620] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "502"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/502.shtml"] [unique_id "apPk5-8CsCvw81e_I2osYgAAAto"]
[Sun Aug 30 03:08:07.336382 2026] [security2:error] [pid 507246:tid 507493] [client 34.125.55.247:29724] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "308"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/keys/gcp.json"] [unique_id "apPk5-8CsCvw81e_I2osxQAAAw4"], referer: https://cpanel.engaginggoddaily.com/keys/gcp.json
[Sun Aug 30 03:08:07.352831 2026] [security2:error] [pid 504660:tid 504965] [client 20.48.250.41:48081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/66.php"] [unique_id "apPk5wgfiZclygrb6nkWwgAAA5s"]
[Sun Aug 30 03:08:07.353586 2026] [security2:error] [pid 507246:tid 507486] [client 34.125.55.247:29724] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "308"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/keys/gcp.json"] [unique_id "apPk5-8CsCvw81e_I2oszAAAAwc"], referer: https://cpanel.engaginggoddaily.com/keys/gcp.json
[Sun Aug 30 03:08:07.355897 2026] [security2:error] [pid 504660:tid 504913] [client 20.220.10.235:36850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/png.php"] [unique_id "apPk5wgfiZclygrb6nkWwwAAA2c"]
[Sun Aug 30 03:08:07.360574 2026] [security2:error] [pid 504660:tid 504881] [client 20.48.160.90:50660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/503.php"] [unique_id "apPk5wgfiZclygrb6nkWxgAAA0c"]
[Sun Aug 30 03:08:07.360766 2026] [security2:error] [pid 504660:tid 504840] [client 4.205.62.107:61719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/upload.form.php"] [unique_id "apPk5wgfiZclygrb6nkWxQAAAx4"]
[Sun Aug 30 03:08:07.361781 2026] [security2:error] [pid 507246:tid 507484] [client 68.155.159.216:55050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-login.php"] [unique_id "apPk5-8CsCvw81e_I2osyAAAAwU"]
[Sun Aug 30 03:08:07.368806 2026] [security2:error] [pid 507246:tid 507499] [client 20.196.209.81:11383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/wp.php"] [unique_id "apPk5-8CsCvw81e_I2oszwAAAxQ"]
[Sun Aug 30 03:08:07.377197 2026] [security2:error] [pid 504660:tid 504894] [client 158.23.147.79:60165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/ws.php"] [unique_id "apPk5wgfiZclygrb6nkWzwAAA1Q"]
[Sun Aug 30 03:08:07.390602 2026] [security2:error] [pid 507246:tid 507444] [client 20.104.104.62:37597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/wp-login.php"] [unique_id "apPk5-8CsCvw81e_I2osywAAAt0"]
[Sun Aug 30 03:08:07.395996 2026] [security2:error] [pid 504660:tid 504966] [client 20.104.18.15:1940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPk5wgfiZclygrb6nkW0wAAA5w"]
[Sun Aug 30 03:08:07.397605 2026] [security2:error] [pid 504660:tid 504953] [client 20.104.18.15:52185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/dk.php"] [unique_id "apPk5wgfiZclygrb6nkW1AAAA48"]
[Sun Aug 30 03:08:07.402073 2026] [security2:error] [pid 504660:tid 504923] [client 114.119.138.48:20305] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "myorangedentist.com"] [uri "/cosmetic-dentistry/"] [unique_id "apPk5wgfiZclygrb6nkW1QAAA3E"], referer: http://myorangedentist.com/cosmetic-dentistry/
[Sun Aug 30 03:08:07.402398 2026] [security2:error] [pid 507246:tid 507469] [client 158.69.119.14:63044] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "158.69.119.14" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPk5-8CsCvw81e_I2os0AAAAvY"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:08:07.402491 2026] [security2:error] [pid 507246:tid 507469] [client 158.69.119.14:63044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPk5-8CsCvw81e_I2os0AAAAvY"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:08:07.402847 2026] [security2:error] [pid 504660:tid 504962] [client 20.104.49.130:36796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/simple.php"] [unique_id "apPk5wgfiZclygrb6nkW1gAAA5g"]
[Sun Aug 30 03:08:07.406772 2026] [security2:error] [pid 507246:tid 507495] [client 213.209.159.223:33639] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transitionthemovie.com"] [uri "/.env"] [unique_id "apPk5-8CsCvw81e_I2os0QAAAxA"]
[Sun Aug 30 03:08:07.414097 2026] [security2:error] [pid 507246:tid 507421] [client 40.83.93.50:13806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/radio.php"] [unique_id "apPk5-8CsCvw81e_I2os0wAAAsY"]
[Sun Aug 30 03:08:07.444731 2026] [security2:error] [pid 507246:tid 507387] [client 20.197.61.180:10484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/rip.php"] [unique_id "apPk5-8CsCvw81e_I2os1AAAAqQ"]
[Sun Aug 30 03:08:07.471979 2026] [security2:error] [pid 504660:tid 504933] [client 20.48.251.3:4701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/saml.php"] [unique_id "apPk5wgfiZclygrb6nkW5wAAA3s"]
[Sun Aug 30 03:08:07.473547 2026] [authz_core:error] [pid 504660:tid 504904] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IN
[Sun Aug 30 03:08:07.473933 2026] [authz_core:error] [pid 504660:tid 504904] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IN
[Sun Aug 30 03:08:07.475380 2026] [security2:error] [pid 507246:tid 507412] [client 4.205.62.107:36011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/paths.php"] [unique_id "apPk5-8CsCvw81e_I2os2AAAAr0"]
[Sun Aug 30 03:08:07.482792 2026] [security2:error] [pid 507246:tid 507402] [client 20.220.10.235:36830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/txets.php"] [unique_id "apPk5-8CsCvw81e_I2os2QAAArM"]
[Sun Aug 30 03:08:07.484497 2026] [security2:error] [pid 504660:tid 504957] [client 20.104.50.220:61501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-includes/mailer.php"] [unique_id "apPk5wgfiZclygrb6nkW7gAAA5M"]
[Sun Aug 30 03:08:07.509633 2026] [security2:error] [pid 504660:tid 504842] [client 20.48.250.41:48065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/f35.php"] [unique_id "apPk5wgfiZclygrb6nkW8wAAAyA"]
[Sun Aug 30 03:08:07.519258 2026] [security2:error] [pid 504660:tid 504906] [client 20.48.160.90:50619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/504.php"] [unique_id "apPk5wgfiZclygrb6nkW-QAAA2A"]
[Sun Aug 30 03:08:07.530678 2026] [security2:error] [pid 504660:tid 504881] [client 20.104.104.62:37598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/wp-access.php"] [unique_id "apPk5wgfiZclygrb6nkXAQAAA0c"]
[Sun Aug 30 03:08:07.533188 2026] [security2:error] [pid 504660:tid 504886] [client 114.119.153.186:41695] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "geotravel.am"] [uri "/"] [unique_id "apPk5wgfiZclygrb6nkXAwAAA0w"], referer: http://geotravel.am/
[Sun Aug 30 03:08:07.533413 2026] [security2:error] [pid 507246:tid 507381] [client 74.248.24.12:7047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/wp-blink.php"] [unique_id "apPk5-8CsCvw81e_I2os3QAAAp4"]
[Sun Aug 30 03:08:07.534328 2026] [security2:error] [pid 504660:tid 504872] [client 52.139.37.240:25771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/install.php"] [unique_id "apPk5wgfiZclygrb6nkXBAAAAz4"]
[Sun Aug 30 03:08:07.540770 2026] [security2:error] [pid 507246:tid 507426] [client 213.209.159.223:33639] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transitionthemovie.com"] [uri "/api/.env"] [unique_id "apPk5-8CsCvw81e_I2os3wAAAss"]
[Sun Aug 30 03:08:07.542077 2026] [authz_core:error] [pid 504660:tid 504910] [client 66.249.66.78:44404] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:07.542533 2026] [authz_core:error] [pid 504660:tid 504910] [client 66.249.66.78:44404] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:07.611765 2026] [security2:error] [pid 507246:tid 507382] [client 20.220.10.235:36803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/wp-login.php"] [unique_id "apPk5-8CsCvw81e_I2os8QAAAp8"]
[Sun Aug 30 03:08:07.672146 2026] [security2:error] [pid 504660:tid 504897] [client 20.104.104.62:37588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/wp-content/admin.php"] [unique_id "apPk5wgfiZclygrb6nkXSQAAA1c"]
[Sun Aug 30 03:08:07.679249 2026] [security2:error] [pid 507246:tid 507411] [client 213.209.159.223:33639] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transitionthemovie.com"] [uri "/backend/.env"] [unique_id "apPk5-8CsCvw81e_I2os9QAAArw"]
[Sun Aug 30 03:08:07.680390 2026] [security2:error] [pid 504660:tid 504930] [client 20.48.250.41:48079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/wen.php"] [unique_id "apPk5wgfiZclygrb6nkXTgAAA3g"]
[Sun Aug 30 03:08:07.688415 2026] [security2:error] [pid 507246:tid 507379] [client 20.48.160.90:50599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/admin.php"] [unique_id "apPk5-8CsCvw81e_I2os9gAAApw"]
[Sun Aug 30 03:08:07.704912 2026] [security2:error] [pid 504660:tid 504945] [client 4.205.62.107:18646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/file59.php"] [unique_id "apPk5wgfiZclygrb6nkXVgAAA4c"]
[Sun Aug 30 03:08:07.736759 2026] [security2:error] [pid 507246:tid 507410] [client 158.69.119.14:63064] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "158.69.119.14" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPk5-8CsCvw81e_I2os_gAAArs"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:08:07.736871 2026] [security2:error] [pid 507246:tid 507410] [client 158.69.119.14:63064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPk5-8CsCvw81e_I2os_gAAArs"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:08:07.742693 2026] [security2:error] [pid 507246:tid 507472] [client 20.220.10.235:36852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/wp-access.php"] [unique_id "apPk5-8CsCvw81e_I2otAAAAAvk"]
[Sun Aug 30 03:08:07.762061 2026] [security2:error] [pid 507246:tid 507475] [client 20.104.49.130:58191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/run.php"] [unique_id "apPk5-8CsCvw81e_I2otAwAAAvw"]
[Sun Aug 30 03:08:07.807079 2026] [security2:error] [pid 504660:tid 504907] [client 158.23.147.79:60208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-includes/css/index.php"] [unique_id "apPk5wgfiZclygrb6nkXhgAAA2E"]
[Sun Aug 30 03:08:07.810625 2026] [security2:error] [pid 504660:tid 504920] [client 20.48.250.41:47473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/inc.php"] [unique_id "apPk5wgfiZclygrb6nkXiAAAA24"]
[Sun Aug 30 03:08:07.812350 2026] [security2:error] [pid 507246:tid 507501] [client 213.209.159.223:33639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transitionthemovie.com"] [uri "/phpinfo.php"] [unique_id "apPk5-8CsCvw81e_I2otBQAAAxY"]
[Sun Aug 30 03:08:07.823330 2026] [security2:error] [pid 504660:tid 504840] [client 20.48.160.90:50571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/ws85.php"] [unique_id "apPk5wgfiZclygrb6nkXjgAAAx4"]
[Sun Aug 30 03:08:07.846335 2026] [security2:error] [pid 504660:tid 504847] [client 20.196.209.81:13218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/error.php"] [unique_id "apPk5wgfiZclygrb6nkXnAAAAyU"]
[Sun Aug 30 03:08:07.851703 2026] [security2:error] [pid 504660:tid 504894] [client 20.104.104.62:37599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/log.php"] [unique_id "apPk5wgfiZclygrb6nkXoAAAA1Q"]
[Sun Aug 30 03:08:07.854544 2026] [autoindex:error] [pid 507246:tid 507403] [client 52.139.37.240:25765] AH01276: Cannot serve directory /home1/nattdesign/public_html/xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:08:07.919151 2026] [security2:error] [pid 507246:tid 507432] [client 52.139.37.240:25765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/wp-signin.php"] [unique_id "apPk5-8CsCvw81e_I2otEgAAAtE"]
[Sun Aug 30 03:08:07.921546 2026] [security2:error] [pid 504660:tid 504911] [client 216.73.216.128:6999] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPk5wgfiZclygrb6nkXzwAAA2U"]
[Sun Aug 30 03:08:07.926751 2026] [security2:error] [pid 504660:tid 504960] [client 20.220.10.235:36859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/wp-content/admin.php"] [unique_id "apPk5wgfiZclygrb6nkX0AAAA5Y"]
[Sun Aug 30 03:08:07.947516 2026] [security2:error] [pid 504660:tid 504967] [client 20.48.250.41:47445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/6bcwiqwj.php"] [unique_id "apPk5wgfiZclygrb6nkX2wAAA50"]
[Sun Aug 30 03:08:07.972617 2026] [authz_core:error] [pid 507246:tid 507412] [client 66.249.66.65:63067] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:07.973022 2026] [authz_core:error] [pid 507246:tid 507412] [client 66.249.66.65:63067] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:07.985348 2026] [security2:error] [pid 504660:tid 504906] [client 20.48.160.90:50652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/ffs.php"] [unique_id "apPk5wgfiZclygrb6nkX7gAAA2A"]
[Sun Aug 30 03:08:08.002265 2026] [security2:error] [pid 504660:tid 504905] [client 20.104.104.62:37603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/xwpg.php"] [unique_id "apPk6AgfiZclygrb6nkX8wAAA18"]
[Sun Aug 30 03:08:08.006071 2026] [authz_core:error] [pid 504660:tid 504901] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_US
[Sun Aug 30 03:08:08.006343 2026] [authz_core:error] [pid 504660:tid 504901] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_US
[Sun Aug 30 03:08:08.019495 2026] [authz_core:error] [pid 504660:tid 504960] [client 216.73.216.128:12390] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:08.019846 2026] [authz_core:error] [pid 504660:tid 504960] [client 216.73.216.128:12390] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:08.062571 2026] [security2:error] [pid 504660:tid 504950] [client 74.248.24.12:14827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/ww5.php"] [unique_id "apPk6AgfiZclygrb6nkYEAAAA4w"]
[Sun Aug 30 03:08:08.068579 2026] [security2:error] [pid 504660:tid 504847] [client 20.220.10.235:36934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/log.php"] [unique_id "apPk6AgfiZclygrb6nkYEwAAAyU"]
[Sun Aug 30 03:08:08.068625 2026] [security2:error] [pid 504660:tid 504962] [client 40.83.93.50:7854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/functions.php"] [unique_id "apPk6AgfiZclygrb6nkYEgAAA5g"]
[Sun Aug 30 03:08:08.112102 2026] [security2:error] [pid 504660:tid 504842] [client 52.139.37.240:49904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/Ov-Simple1.php"] [unique_id "apPk6AgfiZclygrb6nkYJAAAAyA"]
[Sun Aug 30 03:08:08.126064 2026] [security2:error] [pid 504660:tid 504926] [client 20.48.250.41:47476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/easy.php"] [unique_id "apPk6AgfiZclygrb6nkYJwAAA3Q"]
[Sun Aug 30 03:08:08.141593 2026] [security2:error] [pid 507246:tid 507428] [client 158.23.147.79:16333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apPk6O8CsCvw81e_I2otHAAAAs0"]
[Sun Aug 30 03:08:08.163810 2026] [security2:error] [pid 504660:tid 504860] [client 20.48.160.90:33220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/nano.php"] [unique_id "apPk6AgfiZclygrb6nkYLgAAAzI"]
[Sun Aug 30 03:08:08.167056 2026] [security2:error] [pid 504660:tid 504878] [client 20.197.61.180:19017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/ws.php"] [unique_id "apPk6AgfiZclygrb6nkYMAAAA0Q"]
[Sun Aug 30 03:08:08.198908 2026] [security2:error] [pid 504660:tid 504898] [client 20.220.10.235:36863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/xwpg.php"] [unique_id "apPk6AgfiZclygrb6nkYPwAAA1g"]
[Sun Aug 30 03:08:08.240336 2026] [security2:error] [pid 504660:tid 504931] [client 114.119.151.128:23693] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "homessencegroup.com"] [uri "/copyright-and-ip-rights/"] [unique_id "apPk6AgfiZclygrb6nkYTgAAA3k"], referer: https://homessencegroup.com/medium/clay/
[Sun Aug 30 03:08:08.260136 2026] [security2:error] [pid 504660:tid 504915] [client 20.104.104.62:48027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/sxxb.php"] [unique_id "apPk6AgfiZclygrb6nkYXAAAA2k"]
[Sun Aug 30 03:08:08.262538 2026] [security2:error] [pid 504660:tid 504956] [client 178.16.55.109:56436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "youtubesteak.com"] [uri "/index.php"] [unique_id "apPk6AgfiZclygrb6nkYXwAAA5I"]
[Sun Aug 30 03:08:08.274044 2026] [authz_core:error] [pid 504660:tid 504873] [client 66.249.66.36:44489] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:08.274339 2026] [authz_core:error] [pid 504660:tid 504873] [client 66.249.66.36:44489] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:08.280560 2026] [security2:error] [pid 507246:tid 507437] [client 20.104.49.130:60962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/log.php"] [unique_id "apPk6O8CsCvw81e_I2otJgAAAtY"]
[Sun Aug 30 03:08:08.280608 2026] [security2:error] [pid 504660:tid 504918] [client 68.155.159.216:63509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apPk6AgfiZclygrb6nkYbAAAA2w"]
[Sun Aug 30 03:08:08.285054 2026] [security2:error] [pid 504660:tid 504903] [client 20.48.250.41:47480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/fresh3.php"] [unique_id "apPk6AgfiZclygrb6nkYbgAAA10"]
[Sun Aug 30 03:08:08.297398 2026] [security2:error] [pid 504660:tid 504896] [client 20.196.209.81:10057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/profile.php"] [unique_id "apPk6AgfiZclygrb6nkYcgAAA1Y"]
[Sun Aug 30 03:08:08.305775 2026] [security2:error] [pid 504660:tid 504840] [client 52.139.37.240:25754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/ftde.php"] [unique_id "apPk6AgfiZclygrb6nkYdAAAAx4"]
[Sun Aug 30 03:08:08.324906 2026] [security2:error] [pid 504660:tid 504900] [client 68.155.159.216:12377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-content/x.php"] [unique_id "apPk6AgfiZclygrb6nkYeQAAA1o"]
[Sun Aug 30 03:08:08.336159 2026] [security2:error] [pid 504660:tid 504845] [client 20.220.10.235:36936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/sxxb.php"] [unique_id "apPk6AgfiZclygrb6nkYfwAAAyM"]
[Sun Aug 30 03:08:08.353131 2026] [security2:error] [pid 504660:tid 504846] [client 20.104.50.220:16767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/about.php"] [unique_id "apPk6AgfiZclygrb6nkYigAAAyQ"]
[Sun Aug 30 03:08:08.355918 2026] [security2:error] [pid 504660:tid 504945] [client 20.104.50.220:32894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/zer0.php"] [unique_id "apPk6AgfiZclygrb6nkYiwAAA4c"]
[Sun Aug 30 03:08:08.359261 2026] [security2:error] [pid 504660:tid 504847] [client 20.104.50.220:51643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/xd.php"] [unique_id "apPk6AgfiZclygrb6nkYjQAAAyU"]
[Sun Aug 30 03:08:08.359892 2026] [security2:error] [pid 507246:tid 507463] [client 20.104.50.220:5589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/33.php"] [unique_id "apPk6O8CsCvw81e_I2otLAAAAvA"]
[Sun Aug 30 03:08:08.360035 2026] [security2:error] [pid 504660:tid 504899] [client 4.205.62.107:54412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/nw.php"] [unique_id "apPk6AgfiZclygrb6nkYjwAAA1k"]
[Sun Aug 30 03:08:08.362313 2026] [security2:error] [pid 504660:tid 504871] [client 4.205.62.107:64045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/configuration.php"] [unique_id "apPk6AgfiZclygrb6nkYkQAAAz0"]
[Sun Aug 30 03:08:08.362826 2026] [security2:error] [pid 504660:tid 504912] [client 20.104.50.220:31907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/xcv.php"] [unique_id "apPk6AgfiZclygrb6nkYkwAAA2Y"]
[Sun Aug 30 03:08:08.363759 2026] [security2:error] [pid 504660:tid 504939] [client 20.104.18.15:34742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/goods.php"] [unique_id "apPk6AgfiZclygrb6nkYlAAAA4E"]
[Sun Aug 30 03:08:08.368048 2026] [authz_core:error] [pid 504660:tid 504953] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:08.368339 2026] [authz_core:error] [pid 504660:tid 504953] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:08.371988 2026] [security2:error] [pid 504660:tid 504956] [client 20.104.50.220:46405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wfile.php"] [unique_id "apPk6AgfiZclygrb6nkYlQAAA5I"]
[Sun Aug 30 03:08:08.372540 2026] [security2:error] [pid 504660:tid 504961] [client 68.155.159.216:61327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-l0gin.php"] [unique_id "apPk6AgfiZclygrb6nkYlwAAA5c"]
[Sun Aug 30 03:08:08.372785 2026] [security2:error] [pid 504660:tid 504842] [client 20.104.18.15:23442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/drykl.php"] [unique_id "apPk6AgfiZclygrb6nkYmAAAAyA"]
[Sun Aug 30 03:08:08.374446 2026] [security2:error] [pid 504660:tid 504936] [client 20.104.18.15:18398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/simple.php"] [unique_id "apPk6AgfiZclygrb6nkYmgAAA34"]
[Sun Aug 30 03:08:08.382095 2026] [security2:error] [pid 507246:tid 507479] [client 20.104.50.220:29161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/eagle.php"] [unique_id "apPk6O8CsCvw81e_I2otLQAAAwA"]
[Sun Aug 30 03:08:08.384116 2026] [authz_core:error] [pid 504660:tid 504841] [client 216.73.216.128:28110] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:08.384433 2026] [authz_core:error] [pid 504660:tid 504841] [client 216.73.216.128:28110] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:08.393117 2026] [security2:error] [pid 504660:tid 504885] [client 20.104.18.15:29183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/dev.php"] [unique_id "apPk6AgfiZclygrb6nkYoQAAA0s"]
[Sun Aug 30 03:08:08.395623 2026] [security2:error] [pid 504660:tid 504855] [client 20.48.251.3:56369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/php-details.php"] [unique_id "apPk6AgfiZclygrb6nkYpQAAAy0"]
[Sun Aug 30 03:08:08.401741 2026] [security2:error] [pid 504660:tid 504914] [client 20.104.18.15:35507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/k.php"] [unique_id "apPk6AgfiZclygrb6nkYpwAAA2g"]
[Sun Aug 30 03:08:08.406541 2026] [security2:error] [pid 507246:tid 507410] [client 20.48.160.90:50577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/ano.php"] [unique_id "apPk6O8CsCvw81e_I2otLgAAArs"]
[Sun Aug 30 03:08:08.409019 2026] [security2:error] [pid 504660:tid 504928] [client 68.155.159.216:45975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/file17.php"] [unique_id "apPk6AgfiZclygrb6nkYqwAAA3Y"]
[Sun Aug 30 03:08:08.409399 2026] [security2:error] [pid 507246:tid 507393] [client 20.104.104.62:48031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/dx.php"] [unique_id "apPk6O8CsCvw81e_I2otLwAAAqo"]
[Sun Aug 30 03:08:08.428990 2026] [security2:error] [pid 504660:tid 504910] [client 20.48.250.41:47465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/bgymj.php"] [unique_id "apPk6AgfiZclygrb6nkYsgAAA2Q"]
[Sun Aug 30 03:08:08.447266 2026] [security2:error] [pid 504660:tid 504845] [client 20.104.50.220:62819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/vendor/priv8.php"] [unique_id "apPk6AgfiZclygrb6nkYtgAAAyM"]
[Sun Aug 30 03:08:08.454524 2026] [security2:error] [pid 504660:tid 504920] [client 213.209.159.223:48377] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transitionthemovie.com"] [uri "/laravel/.env"] [unique_id "apPk6AgfiZclygrb6nkYuAAAA24"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:08.472362 2026] [security2:error] [pid 504660:tid 504966] [client 20.220.10.235:36848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/dx.php"] [unique_id "apPk6AgfiZclygrb6nkYvgAAA5w"]
[Sun Aug 30 03:08:08.475718 2026] [security2:error] [pid 507246:tid 507392] [client 68.155.159.216:55164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apPk6O8CsCvw81e_I2otMgAAAqk"]
[Sun Aug 30 03:08:08.480198 2026] [authz_core:error] [pid 504660:tid 504946] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZM
[Sun Aug 30 03:08:08.480458 2026] [authz_core:error] [pid 504660:tid 504946] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZM
[Sun Aug 30 03:08:08.496282 2026] [security2:error] [pid 504660:tid 504886] [client 4.205.62.107:64692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/aws_auth.php"] [unique_id "apPk6AgfiZclygrb6nkYyAAAA0w"]
[Sun Aug 30 03:08:08.509415 2026] [security2:error] [pid 507246:tid 507438] [client 52.139.37.240:48738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/hplfuns.php"] [unique_id "apPk6O8CsCvw81e_I2otNQAAAtc"]
[Sun Aug 30 03:08:08.509853 2026] [security2:error] [pid 504660:tid 504853] [client 158.23.147.79:60185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-content/cong.php"] [unique_id "apPk6AgfiZclygrb6nkYygAAAys"]
[Sun Aug 30 03:08:08.517677 2026] [security2:error] [pid 504660:tid 504891] [client 20.104.50.220:63047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/Eagle.php"] [unique_id "apPk6AgfiZclygrb6nkYzgAAA1E"]
[Sun Aug 30 03:08:08.535131 2026] [security2:error] [pid 504660:tid 504926] [client 20.104.18.15:2010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/wsd.php"] [unique_id "apPk6AgfiZclygrb6nkY3QAAA3Q"]
[Sun Aug 30 03:08:08.546230 2026] [security2:error] [pid 504660:tid 504856] [client 20.104.104.62:37601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPk6AgfiZclygrb6nkY5AAAAy4"]
[Sun Aug 30 03:08:08.548223 2026] [security2:error] [pid 504660:tid 504957] [client 20.104.18.15:51693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apPk6AgfiZclygrb6nkY5wAAA5M"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:08.569340 2026] [security2:error] [pid 504660:tid 504966] [client 20.48.251.3:45825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/ws62.php"] [unique_id "apPk6AgfiZclygrb6nkY8QAAA5w"]
[Sun Aug 30 03:08:08.588951 2026] [security2:error] [pid 504660:tid 504955] [client 213.209.159.223:48377] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transitionthemovie.com"] [uri "/core/.env"] [unique_id "apPk6AgfiZclygrb6nkY-QAAA5E"]
[Sun Aug 30 03:08:08.607290 2026] [security2:error] [pid 504660:tid 504842] [client 20.220.10.235:36841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPk6AgfiZclygrb6nkZAgAAAyA"]
[Sun Aug 30 03:08:08.611430 2026] [security2:error] [pid 504660:tid 504936] [client 20.48.251.3:4813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/aws_settings.php"] [unique_id "apPk6AgfiZclygrb6nkZBgAAA34"]
[Sun Aug 30 03:08:08.613609 2026] [security2:error] [pid 504660:tid 504877] [client 4.205.62.107:36616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/olfclass.php"] [unique_id "apPk6AgfiZclygrb6nkZCgAAA0M"]
[Sun Aug 30 03:08:08.627903 2026] [security2:error] [pid 504660:tid 504849] [client 40.83.93.50:7846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/elp.php"] [unique_id "apPk6AgfiZclygrb6nkZEAAAAyc"]
[Sun Aug 30 03:08:08.635037 2026] [security2:error] [pid 504660:tid 504944] [client 74.248.24.12:5184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/rip.php"] [unique_id "apPk6AgfiZclygrb6nkZEgAAA4Y"]
[Sun Aug 30 03:08:08.649579 2026] [security2:error] [pid 504660:tid 504859] [client 20.48.250.41:48076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/ws69.php"] [unique_id "apPk6AgfiZclygrb6nkZFwAAAzE"]
[Sun Aug 30 03:08:08.655248 2026] [security2:error] [pid 504660:tid 504840] [client 20.48.160.90:50653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/mgrr.php"] [unique_id "apPk6AgfiZclygrb6nkZGgAAAx4"]
[Sun Aug 30 03:08:08.660355 2026] [security2:error] [pid 504660:tid 504964] [client 4.205.62.107:58354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/old_phpinfo.php"] [unique_id "apPk6AgfiZclygrb6nkZHQAAA5o"]
[Sun Aug 30 03:08:08.674392 2026] [security2:error] [pid 504660:tid 504913] [client 20.104.104.62:48024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/xda.php"] [unique_id "apPk6AgfiZclygrb6nkZJQAAA2c"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:08.704029 2026] [security2:error] [pid 507246:tid 507501] [client 20.196.209.81:11336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/sql.php"] [unique_id "apPk6O8CsCvw81e_I2otQQAAAxY"]
[Sun Aug 30 03:08:08.711393 2026] [security2:error] [pid 504660:tid 504866] [client 52.139.37.240:25763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/log.php"] [unique_id "apPk6AgfiZclygrb6nkZOQAAAzg"]
[Sun Aug 30 03:08:08.742907 2026] [security2:error] [pid 504660:tid 504871] [client 20.220.10.235:36813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/xda.php"] [unique_id "apPk6AgfiZclygrb6nkZSwAAAz0"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:08.794599 2026] [security2:error] [pid 504660:tid 504872] [client 20.104.50.220:59551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/ym.php"] [unique_id "apPk6AgfiZclygrb6nkZZAAAAz4"]
[Sun Aug 30 03:08:08.799684 2026] [security2:error] [pid 504660:tid 504962] [client 20.48.250.41:47474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/ccs.php"] [unique_id "apPk6AgfiZclygrb6nkZZwAAA5g"]
[Sun Aug 30 03:08:08.836125 2026] [security2:error] [pid 507246:tid 507387] [client 20.48.160.90:50669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/mac.php"] [unique_id "apPk6O8CsCvw81e_I2otSQAAAqQ"]
[Sun Aug 30 03:08:08.841891 2026] [security2:error] [pid 507246:tid 507474] [client 4.205.62.107:18675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/cli_bootstrap.php"] [unique_id "apPk6O8CsCvw81e_I2otSwAAAvs"]
[Sun Aug 30 03:08:08.844489 2026] [security2:error] [pid 507246:tid 507434] [client 20.104.104.62:48011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPk6O8CsCvw81e_I2otTQAAAtM"]
[Sun Aug 30 03:08:08.881862 2026] [authz_core:error] [pid 507246:tid 507381] [client 66.249.66.71:61628] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:08.882141 2026] [authz_core:error] [pid 507246:tid 507381] [client 66.249.66.71:61628] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:08.886174 2026] [security2:error] [pid 504660:tid 504920] [client 20.104.49.130:36766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/chosen.php"] [unique_id "apPk6AgfiZclygrb6nkZmAAAA24"]
[Sun Aug 30 03:08:08.888337 2026] [security2:error] [pid 504660:tid 504851] [client 20.197.61.180:7823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/t.php"] [unique_id "apPk6AgfiZclygrb6nkZmQAAAyk"]
[Sun Aug 30 03:08:08.890980 2026] [security2:error] [pid 507246:tid 507390] [client 20.220.10.235:36969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPk6O8CsCvw81e_I2otVAAAAqc"]
[Sun Aug 30 03:08:08.903560 2026] [security2:error] [pid 504660:tid 504902] [client 52.139.37.240:49151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/txets.php"] [unique_id "apPk6AgfiZclygrb6nkZpgAAA1w"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:08.928070 2026] [security2:error] [pid 504660:tid 504921] [client 216.73.216.128:28110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPk6AgfiZclygrb6nkZuAAAA28"]
[Sun Aug 30 03:08:08.942731 2026] [security2:error] [pid 507246:tid 507466] [client 20.48.250.41:47483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/mar.php"] [unique_id "apPk6O8CsCvw81e_I2otWAAAAvM"]
[Sun Aug 30 03:08:08.971407 2026] [security2:error] [pid 507246:tid 507394] [client 158.23.147.79:60169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPk6O8CsCvw81e_I2otYAAAAqs"]
[Sun Aug 30 03:08:08.986138 2026] [authz_core:error] [pid 504660:tid 504930] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AU
[Sun Aug 30 03:08:08.986410 2026] [authz_core:error] [pid 504660:tid 504930] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AU
[Sun Aug 30 03:08:08.995896 2026] [security2:error] [pid 504660:tid 504840] [client 178.16.55.109:61721] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "youtubesteak.com"] [uri "/index.php"] [unique_id "apPk6AgfiZclygrb6nkZ0AAAAx4"]
[Sun Aug 30 03:08:09.007866 2026] [security2:error] [pid 507246:tid 507379] [client 20.48.160.90:50648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/simple.php"] [unique_id "apPk6e8CsCvw81e_I2otZQAAApw"]
[Sun Aug 30 03:08:09.009983 2026] [security2:error] [pid 504660:tid 504932] [client 20.104.104.62:37572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/t00l.php"] [unique_id "apPk6QgfiZclygrb6nkZ1wAAA3o"]
[Sun Aug 30 03:08:09.020496 2026] [security2:error] [pid 507246:tid 507492] [client 20.220.10.235:36932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/t00l.php"] [unique_id "apPk6e8CsCvw81e_I2otagAAAw0"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:09.074920 2026] [authz_core:error] [pid 507246:tid 507427] [client 66.249.66.43:60081] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:09.075216 2026] [authz_core:error] [pid 507246:tid 507427] [client 66.249.66.43:60081] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:09.087767 2026] [security2:error] [pid 507246:tid 507441] [client 20.48.250.41:47469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/ccu.php"] [unique_id "apPk6e8CsCvw81e_I2otdAAAAto"]
[Sun Aug 30 03:08:09.095797 2026] [security2:error] [pid 507246:tid 507393] [client 52.139.37.240:25777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/wp-admin.php"] [unique_id "apPk6e8CsCvw81e_I2otdQAAAqo"]
[Sun Aug 30 03:08:09.105743 2026] [security2:error] [pid 504660:tid 504947] [client 213.209.159.223:48377] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transitionthemovie.com"] [uri "/app/.env"] [unique_id "apPk6QgfiZclygrb6nkZ-wAAA4k"]
[Sun Aug 30 03:08:09.142278 2026] [security2:error] [pid 507246:tid 507470] [client 20.104.104.62:48019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/ls.php"] [unique_id "apPk6e8CsCvw81e_I2oteAAAAvc"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:09.147637 2026] [security2:error] [pid 507246:tid 507399] [client 20.196.209.81:13224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/index.bak.php"] [unique_id "apPk6e8CsCvw81e_I2oteQAAArA"]
[Sun Aug 30 03:08:09.150055 2026] [security2:error] [pid 504660:tid 504845] [client 20.220.10.235:36839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/ls.php"] [unique_id "apPk6QgfiZclygrb6nkaAwAAAyM"]
[Sun Aug 30 03:08:09.189335 2026] [security2:error] [pid 504660:tid 504863] [client 20.48.160.90:50621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/xty.php"] [unique_id "apPk6QgfiZclygrb6nkaFwAAAzU"]
[Sun Aug 30 03:08:09.236569 2026] [security2:error] [pid 507246:tid 507418] [client 20.48.250.41:48113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/ak.php"] [unique_id "apPk6e8CsCvw81e_I2otfQAAAsM"]
[Sun Aug 30 03:08:09.240229 2026] [security2:error] [pid 504660:tid 504903] [client 213.209.159.223:48377] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transitionthemovie.com"] [uri "/dev/.env"] [unique_id "apPk6QgfiZclygrb6nkaLwAAA10"]
[Sun Aug 30 03:08:09.263472 2026] [security2:error] [pid 504660:tid 504870] [client 40.83.93.50:13814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/options-reading.php"] [unique_id "apPk6QgfiZclygrb6nkaOgAAAzw"]
[Sun Aug 30 03:08:09.267704 2026] [security2:error] [pid 507246:tid 507444] [client 20.151.200.44:55742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/update/da222.php"] [unique_id "apPk6e8CsCvw81e_I2otgQAAAt0"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:09.279054 2026] [security2:error] [pid 504660:tid 504932] [client 20.220.10.235:36971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/css/000.php"] [unique_id "apPk6QgfiZclygrb6nkaRAAAA3o"]
[Sun Aug 30 03:08:09.283499 2026] [authz_core:error] [pid 504660:tid 504859] [client 66.249.66.194:46452] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:09.283943 2026] [authz_core:error] [pid 504660:tid 504859] [client 66.249.66.194:46452] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:09.284325 2026] [security2:error] [pid 504660:tid 504966] [client 20.104.104.62:37583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/css/000.php"] [unique_id "apPk6QgfiZclygrb6nkaRwAAA5w"]
[Sun Aug 30 03:08:09.293602 2026] [security2:error] [pid 504660:tid 504919] [client 216.73.216.128:6999] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPk6QgfiZclygrb6nkaTQAAA20"]
[Sun Aug 30 03:08:09.323510 2026] [security2:error] [pid 507246:tid 507434] [client 20.48.160.90:50604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/sallu.php"] [unique_id "apPk6e8CsCvw81e_I2otiQAAAtM"]
[Sun Aug 30 03:08:09.361199 2026] [security2:error] [pid 504660:tid 504916] [client 158.23.147.79:60203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPk6QgfiZclygrb6nkaYwAAA2o"]
[Sun Aug 30 03:08:09.367725 2026] [autoindex:error] [pid 504660:tid 504864] [client 52.139.37.240:25760] AH01276: Cannot serve directory /home1/nattdesign/public_html/xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:09.388433 2026] [security2:error] [pid 504660:tid 504903] [client 20.151.200.44:57856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/wp-access.php"] [unique_id "apPk6QgfiZclygrb6nkaaQAAA10"]
[Sun Aug 30 03:08:09.406499 2026] [security2:error] [pid 504660:tid 504923] [client 20.220.10.235:36828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/cy.php"] [unique_id "apPk6QgfiZclygrb6nkacAAAA3E"]
[Sun Aug 30 03:08:09.411145 2026] [security2:error] [pid 504660:tid 504842] [client 20.48.250.41:48071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/lib.php"] [unique_id "apPk6QgfiZclygrb6nkadAAAAyA"]
[Sun Aug 30 03:08:09.416217 2026] [security2:error] [pid 504660:tid 504877] [client 20.104.49.130:43270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/ano.php"] [unique_id "apPk6QgfiZclygrb6nkaeAAAA0M"]
[Sun Aug 30 03:08:09.416240 2026] [security2:error] [pid 504660:tid 504843] [client 68.155.159.216:53501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-mail.php"] [unique_id "apPk6QgfiZclygrb6nkadwAAAyE"]
[Sun Aug 30 03:08:09.420035 2026] [security2:error] [pid 504660:tid 504865] [client 20.104.104.62:37595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/cy.php"] [unique_id "apPk6QgfiZclygrb6nkaegAAAzc"]
[Sun Aug 30 03:08:09.459184 2026] [security2:error] [pid 507246:tid 507397] [client 20.48.160.90:50615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/codex.php"] [unique_id "apPk6e8CsCvw81e_I2otkQAAAq4"]
[Sun Aug 30 03:08:09.463160 2026] [authz_core:error] [pid 504660:tid 504920] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_DK
[Sun Aug 30 03:08:09.463438 2026] [authz_core:error] [pid 504660:tid 504920] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_DK
[Sun Aug 30 03:08:09.481438 2026] [authz_core:error] [pid 504660:tid 504847] [client 216.73.216.128:28110] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:09.481734 2026] [authz_core:error] [pid 504660:tid 504847] [client 216.73.216.128:28110] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:09.484984 2026] [security2:error] [pid 504660:tid 504863] [client 74.248.24.12:14808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/wp-the.php"] [unique_id "apPk6QgfiZclygrb6nkaiAAAAzU"]
[Sun Aug 30 03:08:09.485806 2026] [security2:error] [pid 504660:tid 504946] [client 114.119.152.149:29547] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "b2c-egypt.com"] [uri "/projects/"] [unique_id "apPk6QgfiZclygrb6nkaiQAAA4g"], referer: https://b2c-egypt.com/projects/
[Sun Aug 30 03:08:09.486059 2026] [security2:error] [pid 504660:tid 504965] [client 103.215.74.185:16682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.144.1.153"] [uri "/index.php"] [unique_id "apPk6QgfiZclygrb6nkaigAAA5s"], referer: https://162.144.1.153/wp-admin/
[Sun Aug 30 03:08:09.490379 2026] [security2:error] [pid 507246:tid 507448] [client 20.104.50.220:16726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/admin.php"] [unique_id "apPk6e8CsCvw81e_I2otkgAAAuE"]
[Sun Aug 30 03:08:09.493266 2026] [security2:error] [pid 507246:tid 507489] [client 68.155.159.216:12371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPk6e8CsCvw81e_I2otlAAAAwo"]
[Sun Aug 30 03:08:09.495037 2026] [security2:error] [pid 504660:tid 504898] [client 68.155.159.216:64797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apPk6QgfiZclygrb6nkajQAAA1g"]
[Sun Aug 30 03:08:09.496429 2026] [security2:error] [pid 504660:tid 504899] [client 20.104.50.220:5507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/25.php"] [unique_id "apPk6QgfiZclygrb6nkajgAAA1k"]
[Sun Aug 30 03:08:09.496593 2026] [security2:error] [pid 507246:tid 507480] [client 20.104.50.220:51554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/dada.php"] [unique_id "apPk6e8CsCvw81e_I2otlQAAAwE"]
[Sun Aug 30 03:08:09.502482 2026] [security2:error] [pid 507246:tid 507436] [client 20.104.18.15:34748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/alfa.php"] [unique_id "apPk6e8CsCvw81e_I2otlwAAAtU"]
[Sun Aug 30 03:08:09.507629 2026] [security2:error] [pid 507246:tid 507471] [client 20.104.50.220:46153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/class20.php"] [unique_id "apPk6e8CsCvw81e_I2otmQAAAvg"]
[Sun Aug 30 03:08:09.517032 2026] [security2:error] [pid 507246:tid 507394] [client 20.104.50.220:32114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/xl.php"] [unique_id "apPk6e8CsCvw81e_I2otnAAAAqs"]
[Sun Aug 30 03:08:09.517971 2026] [security2:error] [pid 504660:tid 504900] [client 20.104.18.15:18345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/xty.php"] [unique_id "apPk6QgfiZclygrb6nkakgAAA1o"]
[Sun Aug 30 03:08:09.519132 2026] [security2:error] [pid 504660:tid 504900] [client 4.205.62.107:64044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/server_info.php"] [unique_id "apPk6QgfiZclygrb6nkakwAAA1o"]
[Sun Aug 30 03:08:09.527963 2026] [security2:error] [pid 504660:tid 504941] [client 4.205.62.107:22943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/product.php"] [unique_id "apPk6QgfiZclygrb6nkamgAAA4M"]
[Sun Aug 30 03:08:09.528900 2026] [security2:error] [pid 504660:tid 504893] [client 20.104.18.15:29075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/wp-activate.php"] [unique_id "apPk6QgfiZclygrb6nkanAAAA1M"]
[Sun Aug 30 03:08:09.530777 2026] [security2:error] [pid 504660:tid 504943] [client 20.104.50.220:33197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/63dor.php"] [unique_id "apPk6QgfiZclygrb6nkangAAA4U"]
[Sun Aug 30 03:08:09.532830 2026] [security2:error] [pid 504660:tid 504912] [client 20.104.18.15:35488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/82.php"] [unique_id "apPk6QgfiZclygrb6nkaoAAAA2Y"]
[Sun Aug 30 03:08:09.535761 2026] [security2:error] [pid 507246:tid 507451] [client 20.220.10.235:36801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/admin.php/pindex.php"] [unique_id "apPk6e8CsCvw81e_I2otngAAAuQ"]
[Sun Aug 30 03:08:09.541659 2026] [security2:error] [pid 507246:tid 507416] [client 20.48.251.3:13426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/routes.php"] [unique_id "apPk6e8CsCvw81e_I2otoAAAAsE"]
[Sun Aug 30 03:08:09.546453 2026] [security2:error] [pid 504660:tid 504858] [client 195.178.110.247:58116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.maxout360.com"] [uri "/index.php"] [unique_id "apPk6QgfiZclygrb6nkaqwAAAzA"]
[Sun Aug 30 03:08:09.550779 2026] [security2:error] [pid 504660:tid 504930] [client 20.196.209.81:13214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/log.php"] [unique_id "apPk6QgfiZclygrb6nkarwAAA3g"]
[Sun Aug 30 03:08:09.556026 2026] [security2:error] [pid 504660:tid 504947] [client 213.209.159.223:48377] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transitionthemovie.com"] [uri "/server/.env"] [unique_id "apPk6QgfiZclygrb6nkasgAAA4k"]
[Sun Aug 30 03:08:09.561189 2026] [security2:error] [pid 504660:tid 504872] [client 20.104.18.15:23499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/backup.php"] [unique_id "apPk6QgfiZclygrb6nkauQAAAz4"]
[Sun Aug 30 03:08:09.563983 2026] [security2:error] [pid 504660:tid 504963] [client 20.104.104.62:37618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/admin.php/pindex.php"] [unique_id "apPk6QgfiZclygrb6nkavAAAA5k"]
[Sun Aug 30 03:08:09.572799 2026] [security2:error] [pid 504660:tid 504894] [client 68.155.159.216:46049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/file5.php"] [unique_id "apPk6QgfiZclygrb6nkawQAAA1Q"]
[Sun Aug 30 03:08:09.600397 2026] [security2:error] [pid 504660:tid 504935] [client 20.48.250.41:47437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/wp-style.php"] [unique_id "apPk6QgfiZclygrb6nkazQAAA30"]
[Sun Aug 30 03:08:09.603408 2026] [security2:error] [pid 507246:tid 507463] [client 20.48.160.90:50566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/5656.php"] [unique_id "apPk6e8CsCvw81e_I2otpQAAAvA"]
[Sun Aug 30 03:08:09.610357 2026] [authz_core:error] [pid 504660:tid 504893] [client 66.249.66.197:38848] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:09.610627 2026] [authz_core:error] [pid 504660:tid 504893] [client 66.249.66.197:38848] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:09.614835 2026] [security2:error] [pid 507246:tid 507423] [client 20.197.61.180:8812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/fw.php"] [unique_id "apPk6e8CsCvw81e_I2otpwAAAsg"]
[Sun Aug 30 03:08:09.620227 2026] [security2:error] [pid 504660:tid 504904] [client 68.155.159.216:55155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-admin/images/about.php"] [unique_id "apPk6QgfiZclygrb6nka2QAAA14"]
[Sun Aug 30 03:08:09.643569 2026] [security2:error] [pid 504660:tid 504902] [client 4.205.62.107:64498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/hiquido.com/index.php"] [unique_id "apPk6QgfiZclygrb6nka4QAAA1w"]
[Sun Aug 30 03:08:09.669132 2026] [security2:error] [pid 504660:tid 504870] [client 20.220.10.235:36861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/admin.php/csv.php"] [unique_id "apPk6QgfiZclygrb6nka7AAAAzw"]
[Sun Aug 30 03:08:09.672473 2026] [security2:error] [pid 504660:tid 504939] [client 20.104.18.15:2039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/bulet.php"] [unique_id "apPk6QgfiZclygrb6nka8AAAA4E"]
[Sun Aug 30 03:08:09.684258 2026] [security2:error] [pid 504660:tid 504866] [client 20.104.50.220:28693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/.error_log.php"] [unique_id "apPk6QgfiZclygrb6nka9gAAAzg"]
[Sun Aug 30 03:08:09.691704 2026] [security2:error] [pid 504660:tid 504899] [client 20.104.18.15:51692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/xc.php"] [unique_id "apPk6QgfiZclygrb6nka-gAAA1k"]
[Sun Aug 30 03:08:09.706503 2026] [security2:error] [pid 507246:tid 507466] [client 178.16.55.109:53172] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "youtubesteak.com"] [uri "/index.php"] [unique_id "apPk6e8CsCvw81e_I2otqgAAAvM"]
[Sun Aug 30 03:08:09.709187 2026] [security2:error] [pid 507246:tid 507433] [client 20.104.104.62:37579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/admin.php/csv.php"] [unique_id "apPk6e8CsCvw81e_I2otrAAAAtI"]
[Sun Aug 30 03:08:09.720049 2026] [security2:error] [pid 507246:tid 507435] [client 195.178.110.247:54726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.maxout360.com"] [uri "/index.php"] [unique_id "apPk6e8CsCvw81e_I2otrgAAAtQ"]
[Sun Aug 30 03:08:09.725636 2026] [security2:error] [pid 504660:tid 504851] [client 20.104.50.220:29135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/css/priv8.php"] [unique_id "apPk6QgfiZclygrb6nkbCgAAAyk"]
[Sun Aug 30 03:08:09.748785 2026] [security2:error] [pid 504660:tid 504954] [client 68.155.159.216:62290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPk6QgfiZclygrb6nkbFgAAA5A"]
[Sun Aug 30 03:08:09.750874 2026] [security2:error] [pid 504660:tid 504949] [client 20.48.251.3:4716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/wp-konfig.backup.php"] [unique_id "apPk6QgfiZclygrb6nkbGQAAA4s"]
[Sun Aug 30 03:08:09.753943 2026] [security2:error] [pid 507246:tid 507380] [client 4.205.62.107:36636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/gnmlc.php"] [unique_id "apPk6e8CsCvw81e_I2otsgAAAp0"]
[Sun Aug 30 03:08:09.760184 2026] [security2:error] [pid 504660:tid 504947] [client 20.48.160.90:50609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/w3lls.php"] [unique_id "apPk6QgfiZclygrb6nkbHQAAA4k"]
[Sun Aug 30 03:08:09.768616 2026] [authz_core:error] [pid 504660:tid 504875] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:09.768961 2026] [authz_core:error] [pid 504660:tid 504875] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:09.794702 2026] [security2:error] [pid 504660:tid 504901] [client 20.48.250.41:47451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/browse.php"] [unique_id "apPk6QgfiZclygrb6nkbKwAAA1s"]
[Sun Aug 30 03:08:09.796686 2026] [security2:error] [pid 504660:tid 504860] [client 40.83.93.50:7834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/db.php"] [unique_id "apPk6QgfiZclygrb6nkbLwAAAzI"]
[Sun Aug 30 03:08:09.798852 2026] [security2:error] [pid 507246:tid 507404] [client 20.220.10.235:37086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/admin.php/700.php"] [unique_id "apPk6e8CsCvw81e_I2ottgAAArU"]
[Sun Aug 30 03:08:09.844303 2026] [security2:error] [pid 504660:tid 504853] [client 20.48.251.3:6513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/grsiuk.php"] [unique_id "apPk6QgfiZclygrb6nkbSgAAAys"]
[Sun Aug 30 03:08:09.850767 2026] [authz_core:error] [pid 504660:tid 504845] [client 216.73.216.128:12390] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:09.851242 2026] [authz_core:error] [pid 504660:tid 504845] [client 216.73.216.128:12390] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:09.858356 2026] [security2:error] [pid 504660:tid 504906] [client 103.215.74.185:16690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.144.1.153"] [uri "/index.php"] [unique_id "apPk6QgfiZclygrb6nkbVAAAA2A"], referer: https://162.144.1.153/wp-admin/
[Sun Aug 30 03:08:09.876069 2026] [security2:error] [pid 504660:tid 504944] [client 20.104.104.62:37580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/admin.php/700.php"] [unique_id "apPk6QgfiZclygrb6nkbWAAAA4Y"]
[Sun Aug 30 03:08:09.911520 2026] [security2:error] [pid 504660:tid 504855] [client 158.23.147.79:58385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apPk6QgfiZclygrb6nkbdAAAAy0"]
[Sun Aug 30 03:08:09.942485 2026] [rewrite:warn] [pid 504660:tid 504695] AH00665: RewriteCond: NoCase option for non-regex pattern '-d' is not supported and will be ignored. (/home3/keilan/public_html/.htaccess:12)
[Sun Aug 30 03:08:09.942501 2026] [rewrite:warn] [pid 504660:tid 504695] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home3/keilan/public_html/.htaccess:13)
[Sun Aug 30 03:08:09.943368 2026] [security2:error] [pid 507246:tid 507409] [client 20.48.250.41:47426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/zoo.php"] [unique_id "apPk6e8CsCvw81e_I2ot0wAAAro"]
[Sun Aug 30 03:08:09.951108 2026] [security2:error] [pid 507246:tid 507480] [client 20.220.10.235:36941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/admin.php/007x.php"] [unique_id "apPk6e8CsCvw81e_I2ot1AAAAwE"]
[Sun Aug 30 03:08:09.959098 2026] [security2:error] [pid 507246:tid 507444] [client 20.196.209.81:13228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/bak.php"] [unique_id "apPk6e8CsCvw81e_I2ot1QAAAt0"]
[Sun Aug 30 03:08:09.988710 2026] [authz_core:error] [pid 504660:tid 504953] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_HK
[Sun Aug 30 03:08:09.989198 2026] [authz_core:error] [pid 504660:tid 504953] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_HK
[Sun Aug 30 03:08:09.992990 2026] [security2:error] [pid 504660:tid 504936] [client 4.205.62.107:18678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/dd.php"] [unique_id "apPk6QgfiZclygrb6nkboAAAA34"]
[Sun Aug 30 03:08:10.003475 2026] [security2:error] [pid 504660:tid 504842] [client 20.48.160.90:50613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/fpwch.php"] [unique_id "apPk6ggfiZclygrb6nkbqAAAAyA"]
[Sun Aug 30 03:08:10.004011 2026] [security2:error] [pid 504660:tid 504956] [client 74.248.24.12:20194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/f35.php"] [unique_id "apPk6ggfiZclygrb6nkbqQAAA5I"]
[Sun Aug 30 03:08:10.009423 2026] [security2:error] [pid 504660:tid 504889] [client 20.104.49.130:63602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/sta.php"] [unique_id "apPk6ggfiZclygrb6nkbrwAAA08"]
[Sun Aug 30 03:08:10.032340 2026] [security2:error] [pid 504660:tid 504840] [client 20.104.104.62:48007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/admin.php/007x.php"] [unique_id "apPk6ggfiZclygrb6nkbwAAAAx4"]
[Sun Aug 30 03:08:10.051511 2026] [security2:error] [pid 504660:tid 504919] [client 20.104.50.220:61681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/alfa1.php"] [unique_id "apPk6ggfiZclygrb6nkbywAAA20"]
[Sun Aug 30 03:08:10.072040 2026] [security2:error] [pid 504660:tid 504932] [client 213.209.159.223:48377] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transitionthemovie.com"] [uri "/staging/.env"] [unique_id "apPk6ggfiZclygrb6nkb1QAAA3o"]
[Sun Aug 30 03:08:10.081689 2026] [security2:error] [pid 504660:tid 504936] [client 20.220.10.235:36823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/admin.php/heex.php"] [unique_id "apPk6ggfiZclygrb6nkb1wAAA34"]
[Sun Aug 30 03:08:10.095892 2026] [security2:error] [pid 504660:tid 504865] [client 20.104.49.130:36741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/ops.php"] [unique_id "apPk6ggfiZclygrb6nkb3AAAAzc"]
[Sun Aug 30 03:08:10.134030 2026] [security2:error] [pid 504660:tid 504967] [client 20.48.250.41:48093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/elp.php"] [unique_id "apPk6ggfiZclygrb6nkb4QAAA50"]
[Sun Aug 30 03:08:10.169814 2026] [security2:error] [pid 507246:tid 507396] [client 20.104.104.62:37625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/admin.php/heex.php"] [unique_id "apPk6u8CsCvw81e_I2ot4gAAAq0"]
[Sun Aug 30 03:08:10.172192 2026] [security2:error] [pid 504660:tid 504874] [client 20.48.160.90:50664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/domvf.php"] [unique_id "apPk6ggfiZclygrb6nkb6AAAA0A"]
[Sun Aug 30 03:08:10.189386 2026] [security2:error] [pid 504660:tid 504870] [client 4.205.62.107:32475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.recoverymarine.com"] [uri "/wp-act.php"] [unique_id "apPk6ggfiZclygrb6nkb8gAAAzw"]
[Sun Aug 30 03:08:10.212289 2026] [authz_core:error] [pid 504660:tid 504873] [client 216.73.216.128:28110] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:10.212562 2026] [authz_core:error] [pid 504660:tid 504873] [client 216.73.216.128:28110] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:10.222100 2026] [security2:error] [pid 504660:tid 504954] [client 20.220.10.235:36955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/tf.php"] [unique_id "apPk6ggfiZclygrb6nkb_gAAA5A"]
[Sun Aug 30 03:08:10.243335 2026] [security2:error] [pid 504660:tid 504955] [client 4.205.62.107:25733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPk6ggfiZclygrb6nkcBwAAA5E"]
[Sun Aug 30 03:08:10.256107 2026] [security2:error] [pid 504660:tid 504939] [client 20.104.49.130:52135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/mac.php"] [unique_id "apPk6ggfiZclygrb6nkcEQAAA4E"]
[Sun Aug 30 03:08:10.267730 2026] [security2:error] [pid 507246:tid 507388] [client 40.83.93.50:10032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/server.php"] [unique_id "apPk6u8CsCvw81e_I2ot6gAAAqU"]
[Sun Aug 30 03:08:10.279919 2026] [security2:error] [pid 504660:tid 504880] [client 20.48.250.41:47470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/666.php"] [unique_id "apPk6ggfiZclygrb6nkcJgAAA0Y"]
[Sun Aug 30 03:08:10.289628 2026] [security2:error] [pid 504660:tid 504962] [client 20.104.49.130:45748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/srontol.php"] [unique_id "apPk6ggfiZclygrb6nkcKwAAA5g"]
[Sun Aug 30 03:08:10.313809 2026] [security2:error] [pid 507246:tid 507470] [client 20.48.160.90:33228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/biufile.php"] [unique_id "apPk6u8CsCvw81e_I2ot7gAAAvc"]
[Sun Aug 30 03:08:10.314449 2026] [security2:error] [pid 504660:tid 504848] [client 20.104.104.62:37578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/tf.php"] [unique_id "apPk6ggfiZclygrb6nkcNwAAAyY"]
[Sun Aug 30 03:08:10.345486 2026] [security2:error] [pid 504660:tid 504844] [client 20.197.61.180:7842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/test.php"] [unique_id "apPk6ggfiZclygrb6nkcQgAAAyI"]
[Sun Aug 30 03:08:10.352700 2026] [security2:error] [pid 504660:tid 504909] [client 20.220.10.235:36956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/update/da222.php"] [unique_id "apPk6ggfiZclygrb6nkcRgAAA2M"]
[Sun Aug 30 03:08:10.356536 2026] [security2:error] [pid 504660:tid 504849] [client 20.196.209.81:12708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/pages.php"] [unique_id "apPk6ggfiZclygrb6nkcSQAAAyc"]
[Sun Aug 30 03:08:10.374723 2026] [security2:error] [pid 504660:tid 504871] [client 34.125.55.247:29832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/htdocs/.env"] [unique_id "apPk6ggfiZclygrb6nkcTQAAAz0"]
[Sun Aug 30 03:08:10.374726 2026] [security2:error] [pid 504660:tid 504942] [client 34.125.55.247:29810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/front/.env"] [unique_id "apPk6ggfiZclygrb6nkcTgAAA4Q"]
[Sun Aug 30 03:08:10.374742 2026] [security2:error] [pid 504660:tid 504924] [client 34.125.55.247:29822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/public_html/.env"] [unique_id "apPk6ggfiZclygrb6nkcTwAAA3I"]
[Sun Aug 30 03:08:10.376290 2026] [security2:error] [pid 504660:tid 504858] [client 34.125.55.247:29796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.55.125.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.engaginggoddaily.com"] [uri "/.env.php.bak"] [unique_id "apPk6ggfiZclygrb6nkcUgAAAzA"]
[Sun Aug 30 03:08:10.376352 2026] [security2:error] [pid 504660:tid 504858] [client 34.125.55.247:29796] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "cpanel.engaginggoddaily.com"] [uri "/.env.php.bak"] [unique_id "apPk6ggfiZclygrb6nkcUgAAAzA"]
[Sun Aug 30 03:08:10.376380 2026] [security2:error] [pid 507246:tid 507476] [client 34.125.55.247:29856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/packages/api/.env"] [unique_id "apPk6u8CsCvw81e_I2ot9gAAAv0"]
[Sun Aug 30 03:08:10.376532 2026] [security2:error] [pid 507246:tid 507476] [client 34.125.55.247:29856] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/packages/api/.env"] [unique_id "apPk6u8CsCvw81e_I2ot9gAAAv0"]
[Sun Aug 30 03:08:10.376974 2026] [security2:error] [pid 504660:tid 504952] [client 34.125.55.247:29882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/back-end/.env"] [unique_id "apPk6ggfiZclygrb6nkcUwAAA44"]
[Sun Aug 30 03:08:10.377127 2026] [security2:error] [pid 504660:tid 504964] [client 34.125.55.247:29804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/.env.prod.bak"] [unique_id "apPk6ggfiZclygrb6nkcUQAAA5o"]
[Sun Aug 30 03:08:10.377552 2026] [security2:error] [pid 504660:tid 504931] [client 34.125.55.247:29924] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/shared/.env"] [unique_id "apPk6ggfiZclygrb6nkcVAAAA3k"]
[Sun Aug 30 03:08:10.377937 2026] [security2:error] [pid 507246:tid 507484] [client 34.125.55.247:29828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/html/.env"] [unique_id "apPk6u8CsCvw81e_I2ot-AAAAwU"]
[Sun Aug 30 03:08:10.379062 2026] [security2:error] [pid 507246:tid 507389] [client 34.125.55.247:29920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/wp/.env"] [unique_id "apPk6u8CsCvw81e_I2ot-gAAAqY"]
[Sun Aug 30 03:08:10.379115 2026] [security2:error] [pid 504660:tid 504937] [client 34.125.55.247:29944] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.engaginggoddaily.com"] [uri "/env"] [unique_id "apPk6ggfiZclygrb6nkcWQAAA38"]
[Sun Aug 30 03:08:10.379903 2026] [security2:error] [pid 507246:tid 507452] [client 34.125.55.247:30018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.55.125.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.engaginggoddaily.com"] [uri "/phpinfo.php"] [unique_id "apPk6u8CsCvw81e_I2ot-wAAAuU"]
[Sun Aug 30 03:08:10.379957 2026] [security2:error] [pid 504660:tid 504879] [client 34.125.55.247:29914] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/www/.env"] [unique_id "apPk6ggfiZclygrb6nkcWAAAA0U"]
[Sun Aug 30 03:08:10.380737 2026] [security2:error] [pid 507246:tid 507418] [client 34.125.55.247:29980] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "cpanel.engaginggoddaily.com"] [uri "/static../proc/self/environ"] [unique_id "apPk6u8CsCvw81e_I2ot_QAAAsM"]
[Sun Aug 30 03:08:10.381414 2026] [security2:error] [pid 507246:tid 507447] [client 34.125.55.247:29970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/apps/.env"] [unique_id "apPk6u8CsCvw81e_I2ot_AAAAuA"]
[Sun Aug 30 03:08:10.381523 2026] [security2:error] [pid 504660:tid 504866] [client 34.125.55.247:29890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/cms/.env"] [unique_id "apPk6ggfiZclygrb6nkcWgAAAzg"]
[Sun Aug 30 03:08:10.382055 2026] [security2:error] [pid 507246:tid 507488] [client 34.125.55.247:29854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/apps/frontend/.env"] [unique_id "apPk6u8CsCvw81e_I2ot_gAAAwk"]
[Sun Aug 30 03:08:10.382521 2026] [security2:error] [pid 507246:tid 507485] [client 34.125.55.247:29996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/static/.env"] [unique_id "apPk6u8CsCvw81e_I2ot_wAAAwY"]
[Sun Aug 30 03:08:10.385269 2026] [proxy_http:error] [pid 504660:tid 504867] (20014)Internal error (specific information not available): [client 34.125.55.247:29866] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:10.385287 2026] [proxy:error] [pid 504660:tid 504867] [client 34.125.55.247:29866] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/config/environment.json
[Sun Aug 30 03:08:10.385795 2026] [proxy_http:error] [pid 507246:tid 507493] (20014)Internal error (specific information not available): [client 34.125.55.247:30014] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:10.385812 2026] [proxy:error] [pid 507246:tid 507493] [client 34.125.55.247:30014] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.npmrc
[Sun Aug 30 03:08:10.385830 2026] [security2:error] [pid 507246:tid 507399] [client 34.125.55.247:29840] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/backend/.env.staging"] [unique_id "apPk6u8CsCvw81e_I2ot9wAAArA"]
[Sun Aug 30 03:08:10.386863 2026] [security2:error] [pid 504660:tid 504874] [client 34.125.55.247:30036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/symfony/.env"] [unique_id "apPk6ggfiZclygrb6nkcYQAAA0A"]
[Sun Aug 30 03:08:10.387202 2026] [security2:error] [pid 504660:tid 504853] [client 216.73.216.128:12390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPk6ggfiZclygrb6nkcYgAAAys"]
[Sun Aug 30 03:08:10.387880 2026] [security2:error] [pid 507246:tid 507501] [client 34.125.55.247:29994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/api/.env.bak"] [unique_id "apPk6u8CsCvw81e_I2ouAQAAAxY"]
[Sun Aug 30 03:08:10.388012 2026] [security2:error] [pid 507246:tid 507501] [client 34.125.55.247:29994] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/api/.env.bak"] [unique_id "apPk6u8CsCvw81e_I2ouAQAAAxY"]
[Sun Aug 30 03:08:10.388587 2026] [security2:error] [pid 504660:tid 504908] [client 34.125.55.247:30022] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/wordpress/.env"] [unique_id "apPk6ggfiZclygrb6nkcYwAAA2I"]
[Sun Aug 30 03:08:10.392286 2026] [proxy_http:error] [pid 504660:tid 504936] (20014)Internal error (specific information not available): [client 34.125.55.247:29998] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:10.392298 2026] [proxy:error] [pid 504660:tid 504936] [client 34.125.55.247:29998] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/.continue/config.json
[Sun Aug 30 03:08:10.398547 2026] [proxy_http:error] [pid 504660:tid 504867] (20014)Internal error (specific information not available): [client 34.125.55.247:29866] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:10.398563 2026] [proxy:error] [pid 504660:tid 504867] [client 34.125.55.247:29866] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml
[Sun Aug 30 03:08:10.404190 2026] [proxy_http:error] [pid 504660:tid 504936] (20014)Internal error (specific information not available): [client 34.125.55.247:29998] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:10.404207 2026] [proxy:error] [pid 504660:tid 504936] [client 34.125.55.247:29998] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml
[Sun Aug 30 03:08:10.409225 2026] [security2:error] [pid 504660:tid 504872] [client 178.16.55.109:49426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "youtubesteak.com"] [uri "/index.php"] [unique_id "apPk6ggfiZclygrb6nkcZwAAAz4"]
[Sun Aug 30 03:08:10.451515 2026] [security2:error] [pid 504660:tid 504955] [client 20.48.250.41:47436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/knmt.php"] [unique_id "apPk6ggfiZclygrb6nkcdQAAA5E"]
[Sun Aug 30 03:08:10.454534 2026] [security2:error] [pid 504660:tid 504902] [client 20.104.104.62:48029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/update/da222.php"] [unique_id "apPk6ggfiZclygrb6nkceAAAA1w"]
[Sun Aug 30 03:08:10.464783 2026] [authz_core:error] [pid 504660:tid 504921] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_DK
[Sun Aug 30 03:08:10.465182 2026] [authz_core:error] [pid 504660:tid 504921] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_DK
[Sun Aug 30 03:08:10.474106 2026] [security2:error] [pid 507246:tid 507486] [client 20.48.160.90:33232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/blacks.php"] [unique_id "apPk6u8CsCvw81e_I2ouBQAAAwc"]
[Sun Aug 30 03:08:10.477969 2026] [security2:error] [pid 504660:tid 504840] [client 52.139.37.240:25760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/wp-config-sample.php"] [unique_id "apPk6ggfiZclygrb6nkcfQAAAx4"]
[Sun Aug 30 03:08:10.483852 2026] [security2:error] [pid 504660:tid 504947] [client 20.220.10.235:36960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/qi.php"] [unique_id "apPk6ggfiZclygrb6nkcfgAAA4k"]
[Sun Aug 30 03:08:10.585187 2026] [security2:error] [pid 504660:tid 504912] [client 20.151.200.44:46996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/update/da222.php"] [unique_id "apPk6ggfiZclygrb6nkcsQAAA2Y"]
[Sun Aug 30 03:08:10.586220 2026] [security2:error] [pid 507246:tid 507480] [client 20.104.104.62:48041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/qi.php"] [unique_id "apPk6u8CsCvw81e_I2ouFgAAAwE"]
[Sun Aug 30 03:08:10.591968 2026] [security2:error] [pid 504660:tid 504843] [client 20.48.250.41:47431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/sbhu.php"] [unique_id "apPk6ggfiZclygrb6nkctQAAAyE"]
[Sun Aug 30 03:08:10.600114 2026] [security2:error] [pid 507246:tid 507384] [client 68.155.159.216:12383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/log-mama/function.php"] [unique_id "apPk6u8CsCvw81e_I2ouGQAAAqE"]
[Sun Aug 30 03:08:10.604769 2026] [security2:error] [pid 504660:tid 504891] [client 158.23.184.117:51808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/t.php"] [unique_id "apPk6ggfiZclygrb6nkcuQAAA1E"]
[Sun Aug 30 03:08:10.613330 2026] [security2:error] [pid 504660:tid 504939] [client 20.220.10.235:36972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/px.php"] [unique_id "apPk6ggfiZclygrb6nkcwQAAA4E"]
[Sun Aug 30 03:08:10.636212 2026] [security2:error] [pid 507246:tid 507453] [client 20.104.50.220:42040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/xml.php"] [unique_id "apPk6u8CsCvw81e_I2ouIAAAAuY"]
[Sun Aug 30 03:08:10.637295 2026] [security2:error] [pid 504660:tid 504933] [client 20.104.50.220:17285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/edit.php"] [unique_id "apPk6ggfiZclygrb6nkcyAAAA3s"]
[Sun Aug 30 03:08:10.638009 2026] [security2:error] [pid 507246:tid 507394] [client 20.104.18.15:34712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/33.php"] [unique_id "apPk6u8CsCvw81e_I2ouIQAAAqs"]
[Sun Aug 30 03:08:10.650278 2026] [security2:error] [pid 504660:tid 504866] [client 20.104.18.15:18360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/sallu.php"] [unique_id "apPk6ggfiZclygrb6nkcygAAAzg"]
[Sun Aug 30 03:08:10.651226 2026] [security2:error] [pid 504660:tid 504900] [client 20.104.50.220:5625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/24.php"] [unique_id "apPk6ggfiZclygrb6nkcywAAA1o"]
[Sun Aug 30 03:08:10.660712 2026] [security2:error] [pid 504660:tid 504858] [client 20.104.50.220:47068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/build.php"] [unique_id "apPk6ggfiZclygrb6nkc1gAAAzA"]
[Sun Aug 30 03:08:10.664327 2026] [security2:error] [pid 507246:tid 507419] [client 20.104.18.15:35485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/dex.php"] [unique_id "apPk6u8CsCvw81e_I2ouIwAAAsQ"]
[Sun Aug 30 03:08:10.669537 2026] [security2:error] [pid 504660:tid 504913] [client 20.104.50.220:32272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/xleet.php"] [unique_id "apPk6ggfiZclygrb6nkc3AAAA2c"]
[Sun Aug 30 03:08:10.674100 2026] [security2:error] [pid 507246:tid 507451] [client 4.205.62.107:62114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/hosty.php"] [unique_id "apPk6u8CsCvw81e_I2ouJAAAAuQ"]
[Sun Aug 30 03:08:10.681030 2026] [security2:error] [pid 504660:tid 504944] [client 20.104.50.220:32851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/dh.php"] [unique_id "apPk6ggfiZclygrb6nkc3wAAA4Y"]
[Sun Aug 30 03:08:10.683322 2026] [security2:error] [pid 504660:tid 504885] [client 52.139.37.240:25732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/wp-content/packed.php"] [unique_id "apPk6ggfiZclygrb6nkc4AAAA0s"]
[Sun Aug 30 03:08:10.683953 2026] [security2:error] [pid 504660:tid 504966] [client 20.104.18.15:29060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/wp_blog_footer.php"] [unique_id "apPk6ggfiZclygrb6nkc4QAAA5w"]
[Sun Aug 30 03:08:10.686727 2026] [security2:error] [pid 507246:tid 507442] [client 20.48.160.90:33218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/beck.php"] [unique_id "apPk6u8CsCvw81e_I2ouJwAAAts"]
[Sun Aug 30 03:08:10.700324 2026] [security2:error] [pid 504660:tid 504916] [client 20.104.18.15:23484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/indo.php"] [unique_id "apPk6ggfiZclygrb6nkc6AAAA2o"]
[Sun Aug 30 03:08:10.704983 2026] [security2:error] [pid 504660:tid 504963] [client 74.248.24.12:11846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/fm.php"] [unique_id "apPk6ggfiZclygrb6nkc6wAAA5k"]
[Sun Aug 30 03:08:10.729962 2026] [security2:error] [pid 504660:tid 504967] [client 20.104.104.62:48061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/px.php"] [unique_id "apPk6ggfiZclygrb6nkc-QAAA50"]
[Sun Aug 30 03:08:10.733103 2026] [security2:error] [pid 504660:tid 504940] [client 20.48.250.41:47439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/a332.php"] [unique_id "apPk6ggfiZclygrb6nkc_AAAA4I"]
[Sun Aug 30 03:08:10.743127 2026] [security2:error] [pid 507246:tid 507430] [client 20.220.10.235:36951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/is.php"] [unique_id "apPk6u8CsCvw81e_I2ouLQAAAs8"]
[Sun Aug 30 03:08:10.743440 2026] [security2:error] [pid 504660:tid 504962] [client 68.155.159.216:55123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPk6ggfiZclygrb6nkdBQAAA5g"]
[Sun Aug 30 03:08:10.748460 2026] [security2:error] [pid 504660:tid 504893] [client 40.83.93.50:13762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/favicon.php"] [unique_id "apPk6ggfiZclygrb6nkdCgAAA1M"]
[Sun Aug 30 03:08:10.754873 2026] [security2:error] [pid 507246:tid 507477] [client 158.23.184.117:56377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/table/int/tmpl/index.php"] [unique_id "apPk6u8CsCvw81e_I2ouLgAAAv4"]
[Sun Aug 30 03:08:10.754968 2026] [security2:error] [pid 504660:tid 504855] [client 68.155.159.216:46056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/file88.php"] [unique_id "apPk6ggfiZclygrb6nkdDgAAAy0"]
[Sun Aug 30 03:08:10.758559 2026] [security2:error] [pid 504660:tid 504942] [client 20.196.209.81:10056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/albin.php"] [unique_id "apPk6ggfiZclygrb6nkdEAAAA4Q"]
[Sun Aug 30 03:08:10.767134 2026] [security2:error] [pid 504660:tid 504888] [client 20.104.50.220:16726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-content/admin.php"] [unique_id "apPk6ggfiZclygrb6nkdEgAAA04"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:10.784592 2026] [security2:error] [pid 504660:tid 504946] [client 158.23.147.79:58395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-content/radio.php"] [unique_id "apPk6ggfiZclygrb6nkdHQAAA4g"]
[Sun Aug 30 03:08:10.789038 2026] [security2:error] [pid 504660:tid 504881] [client 4.205.62.107:64672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/ws79.php"] [unique_id "apPk6ggfiZclygrb6nkdHwAAA0c"]
[Sun Aug 30 03:08:10.814008 2026] [security2:error] [pid 504660:tid 504895] [client 20.104.18.15:1936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/av.php"] [unique_id "apPk6ggfiZclygrb6nkdLAAAA1U"]
[Sun Aug 30 03:08:10.856315 2026] [security2:error] [pid 504660:tid 504939] [client 20.48.251.3:13398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/aww.php"] [unique_id "apPk6ggfiZclygrb6nkdTQAAA4E"]
[Sun Aug 30 03:08:10.856982 2026] [security2:error] [pid 504660:tid 504877] [client 20.48.160.90:50678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/t3.php"] [unique_id "apPk6ggfiZclygrb6nkdTwAAA0M"]
[Sun Aug 30 03:08:10.858681 2026] [security2:error] [pid 507246:tid 507422] [client 20.104.18.15:51595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/wp-content/l.php"] [unique_id "apPk6u8CsCvw81e_I2ouPwAAAsc"]
[Sun Aug 30 03:08:10.859244 2026] [security2:error] [pid 507246:tid 507486] [client 20.48.250.41:47471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/ws66.php"] [unique_id "apPk6u8CsCvw81e_I2ouQAAAAwc"]
[Sun Aug 30 03:08:10.869571 2026] [security2:error] [pid 507246:tid 507418] [client 20.220.10.235:36933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/od.php"] [unique_id "apPk6u8CsCvw81e_I2ouQwAAAsM"]
[Sun Aug 30 03:08:10.879013 2026] [security2:error] [pid 504660:tid 504872] [client 20.104.49.130:34510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/srontol.php"] [unique_id "apPk6ggfiZclygrb6nkdWgAAAz4"]
[Sun Aug 30 03:08:10.890881 2026] [autoindex:error] [pid 504660:tid 504927] [client 52.139.37.240:48757] AH01276: Cannot serve directory /home1/nattdesign/public_html/xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:08:10.892217 2026] [security2:error] [pid 507246:tid 507483] [client 4.205.62.107:36707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/koiy.php"] [unique_id "apPk6u8CsCvw81e_I2ouRQAAAwQ"]
[Sun Aug 30 03:08:10.894364 2026] [security2:error] [pid 504660:tid 504941] [client 158.23.184.117:56332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/taxonomy.php"] [unique_id "apPk6ggfiZclygrb6nkdZgAAA4M"]
[Sun Aug 30 03:08:10.894391 2026] [security2:error] [pid 504660:tid 504947] [client 20.104.104.62:37596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/is.php"] [unique_id "apPk6ggfiZclygrb6nkdaAAAA4k"]
[Sun Aug 30 03:08:10.897903 2026] [security2:error] [pid 504660:tid 504898] [client 20.104.50.220:62820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/assets/priv8.php"] [unique_id "apPk6ggfiZclygrb6nkdawAAA1g"]
[Sun Aug 30 03:08:10.952693 2026] [security2:error] [pid 504660:tid 504966] [client 68.155.159.216:61657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/ans.php"] [unique_id "apPk6ggfiZclygrb6nkdmQAAA5w"]
[Sun Aug 30 03:08:10.984549 2026] [authz_core:error] [pid 504660:tid 504891] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_SG
[Sun Aug 30 03:08:10.984828 2026] [authz_core:error] [pid 504660:tid 504891] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_SG
[Sun Aug 30 03:08:10.994057 2026] [security2:error] [pid 507246:tid 507414] [client 20.48.250.41:47446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/ws68.php"] [unique_id "apPk6u8CsCvw81e_I2ouTwAAAr8"]
[Sun Aug 30 03:08:11.011771 2026] [security2:error] [pid 507246:tid 507409] [client 20.104.50.220:62819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/666.php"] [unique_id "apPk6-8CsCvw81e_I2ouUgAAAro"]
[Sun Aug 30 03:08:11.013407 2026] [security2:error] [pid 507246:tid 507384] [client 20.220.10.235:36964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/wp-the.php"] [unique_id "apPk6-8CsCvw81e_I2ouUwAAAqE"]
[Sun Aug 30 03:08:11.019610 2026] [security2:error] [pid 504660:tid 504945] [client 20.48.160.90:33231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/wp.php"] [unique_id "apPk6wgfiZclygrb6nkdtgAAA4c"]
[Sun Aug 30 03:08:11.036987 2026] [security2:error] [pid 504660:tid 504906] [client 158.23.184.117:56372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/tcp.php"] [unique_id "apPk6wgfiZclygrb6nkdvwAAA2A"]
[Sun Aug 30 03:08:11.044624 2026] [security2:error] [pid 507246:tid 507462] [client 20.197.61.180:7838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/dropdown.php"] [unique_id "apPk6-8CsCvw81e_I2ouVQAAAu8"]
[Sun Aug 30 03:08:11.045697 2026] [security2:error] [pid 507246:tid 507471] [client 20.104.104.62:37528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/od.php"] [unique_id "apPk6-8CsCvw81e_I2ouVwAAAvg"]
[Sun Aug 30 03:08:11.046485 2026] [security2:error] [pid 504660:tid 504842] [client 20.48.251.3:4722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/packed.php"] [unique_id "apPk6wgfiZclygrb6nkdxQAAAyA"]
[Sun Aug 30 03:08:11.066109 2026] [security2:error] [pid 504660:tid 504858] [client 4.205.62.107:54434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/fun.php"] [unique_id "apPk6wgfiZclygrb6nkd0QAAAzA"]
[Sun Aug 30 03:08:11.081981 2026] [security2:error] [pid 504660:tid 504947] [client 68.155.159.216:61383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/cgi-bin/index.php"] [unique_id "apPk6wgfiZclygrb6nkd2gAAA4k"]
[Sun Aug 30 03:08:11.092749 2026] [security2:error] [pid 504660:tid 504923] [client 213.209.159.223:48377] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transitionthemovie.com"] [uri "/source/.env"] [unique_id "apPk6wgfiZclygrb6nkd3AAAA3E"]
[Sun Aug 30 03:08:11.131627 2026] [security2:error] [pid 507246:tid 507491] [client 20.151.200.44:57880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/wp-content/admin.php"] [unique_id "apPk6-8CsCvw81e_I2ouXAAAAww"]
[Sun Aug 30 03:08:11.134376 2026] [security2:error] [pid 504660:tid 504884] [client 4.205.62.107:18807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/wp-tem.php"] [unique_id "apPk6wgfiZclygrb6nkd5AAAA0o"]
[Sun Aug 30 03:08:11.142233 2026] [security2:error] [pid 504660:tid 504952] [client 114.119.134.127:49405] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "filtagreen.com"] [uri "/wp-content/uploads/2017/03/separ4.png"] [unique_id "apPk6wgfiZclygrb6nkd5wAAA44"], referer: https://filtagreen.com/productssepar-filter/
[Sun Aug 30 03:08:11.145325 2026] [security2:error] [pid 504660:tid 504865] [client 20.220.10.235:36966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/wt.php"] [unique_id "apPk6wgfiZclygrb6nkd6AAAAzc"]
[Sun Aug 30 03:08:11.176878 2026] [security2:error] [pid 504660:tid 504939] [client 20.48.250.41:47486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/users.php"] [unique_id "apPk6wgfiZclygrb6nkd9AAAA4E"]
[Sun Aug 30 03:08:11.177574 2026] [security2:error] [pid 507246:tid 507457] [client 158.23.184.117:51790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/teamadmin.php"] [unique_id "apPk6-8CsCvw81e_I2ouXgAAAuo"]
[Sun Aug 30 03:08:11.183956 2026] [security2:error] [pid 504660:tid 504911] [client 20.104.104.62:37563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/wp-the.php"] [unique_id "apPk6wgfiZclygrb6nkd9wAAA2U"]
[Sun Aug 30 03:08:11.194043 2026] [security2:error] [pid 504660:tid 504941] [client 20.196.209.81:13234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/an.php"] [unique_id "apPk6wgfiZclygrb6nkd-QAAA4M"]
[Sun Aug 30 03:08:11.207754 2026] [security2:error] [pid 507246:tid 507437] [client 20.48.160.90:50641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/abcd.php"] [unique_id "apPk6-8CsCvw81e_I2ouYAAAAtY"]
[Sun Aug 30 03:08:11.210913 2026] [authz_core:error] [pid 504660:tid 504840] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:11.211231 2026] [authz_core:error] [pid 504660:tid 504840] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:11.240855 2026] [security2:error] [pid 504660:tid 504950] [client 74.248.24.12:20176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/3.php"] [unique_id "apPk6wgfiZclygrb6nkeEgAAA4w"]
[Sun Aug 30 03:08:11.243600 2026] [autoindex:error] [pid 504660:tid 504934] [client 40.83.93.50:10902] AH01276: Cannot serve directory /home1/tommy99/public_html/d/davinciart_it/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:08:11.271655 2026] [security2:error] [pid 504660:tid 504853] [client 158.23.184.117:27521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/bgymj.php"] [unique_id "apPk6wgfiZclygrb6nkeIQAAAys"]
[Sun Aug 30 03:08:11.279752 2026] [security2:error] [pid 504660:tid 504883] [client 20.220.10.235:36937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/im.php"] [unique_id "apPk6wgfiZclygrb6nkeKQAAA0k"]
[Sun Aug 30 03:08:11.294526 2026] [security2:error] [pid 504660:tid 504867] [client 40.83.93.50:7819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/gecko.php"] [unique_id "apPk6wgfiZclygrb6nkeLgAAAzk"]
[Sun Aug 30 03:08:11.317001 2026] [security2:error] [pid 504660:tid 504848] [client 158.23.184.117:56328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/teamx.php"] [unique_id "apPk6wgfiZclygrb6nkeNgAAAyY"]
[Sun Aug 30 03:08:11.317880 2026] [security2:error] [pid 507246:tid 507494] [client 158.23.184.117:27533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/bk/index.php"] [unique_id "apPk6-8CsCvw81e_I2oubwAAAw8"]
[Sun Aug 30 03:08:11.320975 2026] [security2:error] [pid 504660:tid 504953] [client 20.104.104.62:48042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/wt.php"] [unique_id "apPk6wgfiZclygrb6nkeNwAAA48"]
[Sun Aug 30 03:08:11.375781 2026] [security2:error] [pid 504660:tid 504951] [client 20.48.160.90:50612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/nofile.php"] [unique_id "apPk6wgfiZclygrb6nkeSQAAA40"]
[Sun Aug 30 03:08:11.410363 2026] [security2:error] [pid 504660:tid 504934] [client 20.220.10.235:36853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/file.php"] [unique_id "apPk6wgfiZclygrb6nkeVAAAA3w"]
[Sun Aug 30 03:08:11.423629 2026] [security2:error] [pid 507246:tid 507378] [client 20.104.50.220:61679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/159.php"] [unique_id "apPk6-8CsCvw81e_I2oufQAAAps"]
[Sun Aug 30 03:08:11.430786 2026] [security2:error] [pid 507246:tid 507418] [client 20.48.250.41:47461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/bzjdlofz.php"] [unique_id "apPk6-8CsCvw81e_I2oufwAAAsM"]
[Sun Aug 30 03:08:11.436323 2026] [security2:error] [pid 504660:tid 504949] [client 213.209.159.223:48377] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transitionthemovie.com"] [uri "/framework/.env"] [unique_id "apPk6wgfiZclygrb6nkeWQAAA4s"]
[Sun Aug 30 03:08:11.457003 2026] [security2:error] [pid 504660:tid 504893] [client 158.23.184.117:56382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/techl.php"] [unique_id "apPk6wgfiZclygrb6nkeXQAAA1M"]
[Sun Aug 30 03:08:11.457768 2026] [security2:error] [pid 507246:tid 507456] [client 20.104.104.62:37602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/im.php"] [unique_id "apPk6-8CsCvw81e_I2ouggAAAuk"]
[Sun Aug 30 03:08:11.458054 2026] [security2:error] [pid 504660:tid 504902] [client 158.23.184.117:27018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/bootstrap.php"] [unique_id "apPk6wgfiZclygrb6nkeXwAAA1w"]
[Sun Aug 30 03:08:11.462882 2026] [authz_core:error] [pid 504660:tid 504913] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AU
[Sun Aug 30 03:08:11.463156 2026] [authz_core:error] [pid 504660:tid 504913] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AU
[Sun Aug 30 03:08:11.508102 2026] [security2:error] [pid 504660:tid 504904] [client 20.48.160.90:50607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/run.php"] [unique_id "apPk6wgfiZclygrb6nkeawAAA14"]
[Sun Aug 30 03:08:11.517028 2026] [authz_core:error] [pid 504660:tid 504860] [client 66.249.66.41:61192] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:11.517462 2026] [authz_core:error] [pid 504660:tid 504860] [client 66.249.66.41:61192] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:11.534514 2026] [security2:error] [pid 504660:tid 504958] [client 4.205.62.107:25787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPk6wgfiZclygrb6nkefgAAA5Q"]
[Sun Aug 30 03:08:11.556073 2026] [security2:error] [pid 504660:tid 504889] [client 20.220.10.235:36817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/ca.php"] [unique_id "apPk6wgfiZclygrb6nkekgAAA08"]
[Sun Aug 30 03:08:11.574547 2026] [security2:error] [pid 504660:tid 504903] [client 213.209.159.223:48377] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transitionthemovie.com"] [uri "/ikiwiki/.env"] [unique_id "apPk6wgfiZclygrb6nkenwAAA10"]
[Sun Aug 30 03:08:11.593768 2026] [security2:error] [pid 507246:tid 507480] [client 20.104.104.62:37582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/file.php"] [unique_id "apPk6-8CsCvw81e_I2oujwAAAwE"]
[Sun Aug 30 03:08:11.599579 2026] [security2:error] [pid 504660:tid 504868] [client 158.23.184.117:27026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/bs1.php"] [unique_id "apPk6wgfiZclygrb6nkeqAAAAzo"]
[Sun Aug 30 03:08:11.601158 2026] [security2:error] [pid 504660:tid 504926] [client 158.23.184.117:56360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/temp.php"] [unique_id "apPk6wgfiZclygrb6nkeqQAAA3Q"]
[Sun Aug 30 03:08:11.605368 2026] [security2:error] [pid 504660:tid 504898] [client 20.48.250.41:47440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/selesai.php"] [unique_id "apPk6wgfiZclygrb6nkerAAAA1g"]
[Sun Aug 30 03:08:11.673872 2026] [security2:error] [pid 504660:tid 504872] [client 20.196.209.81:12721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/mini.php"] [unique_id "apPk6wgfiZclygrb6nke0AAAAz4"]
[Sun Aug 30 03:08:11.684627 2026] [security2:error] [pid 504660:tid 504850] [client 20.48.160.90:33265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/new.php"] [unique_id "apPk6wgfiZclygrb6nke0QAAAyg"]
[Sun Aug 30 03:08:11.688130 2026] [security2:error] [pid 507246:tid 507431] [client 20.220.10.235:36840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/pb.php"] [unique_id "apPk6-8CsCvw81e_I2ounQAAAtA"]
[Sun Aug 30 03:08:11.714191 2026] [security2:error] [pid 504660:tid 504861] [client 213.209.159.223:48377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transitionthemovie.com"] [uri "/config.inc.php"] [unique_id "apPk6wgfiZclygrb6nke3AAAAzM"]
[Sun Aug 30 03:08:11.723729 2026] [security2:error] [pid 507246:tid 507502] [client 20.104.104.62:37506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/ca.php"] [unique_id "apPk6-8CsCvw81e_I2ouowAAAxc"]
[Sun Aug 30 03:08:11.739210 2026] [security2:error] [pid 507246:tid 507437] [client 158.23.184.117:56366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/tempfuns.php"] [unique_id "apPk6-8CsCvw81e_I2ouqAAAAtY"]
[Sun Aug 30 03:08:11.739611 2026] [security2:error] [pid 507246:tid 507424] [client 158.23.184.117:27522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/bthil.php"] [unique_id "apPk6-8CsCvw81e_I2ouqQAAAsk"]
[Sun Aug 30 03:08:11.751003 2026] [security2:error] [pid 504660:tid 504955] [client 68.155.159.216:12366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/bk/index.php"] [unique_id "apPk6wgfiZclygrb6nke8QAAA5E"]
[Sun Aug 30 03:08:11.757315 2026] [security2:error] [pid 504660:tid 504937] [client 20.48.250.41:47459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/shlo.php"] [unique_id "apPk6wgfiZclygrb6nke9QAAA38"]
[Sun Aug 30 03:08:11.757679 2026] [security2:error] [pid 504660:tid 504848] [client 216.73.216.128:28110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPk6wgfiZclygrb6nke9gAAAyY"]
[Sun Aug 30 03:08:11.772102 2026] [security2:error] [pid 504660:tid 504925] [client 40.83.93.50:13781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/ioxi-o.php"] [unique_id "apPk6wgfiZclygrb6nke-wAAA3M"]
[Sun Aug 30 03:08:11.777594 2026] [security2:error] [pid 504660:tid 504919] [client 20.104.18.15:34793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/133.php"] [unique_id "apPk6wgfiZclygrb6nke_gAAA20"]
[Sun Aug 30 03:08:11.787922 2026] [security2:error] [pid 507246:tid 507454] [client 20.104.50.220:5925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/12345.php"] [unique_id "apPk6-8CsCvw81e_I2ourQAAAuc"]
[Sun Aug 30 03:08:11.791799 2026] [security2:error] [pid 504660:tid 504921] [client 20.104.18.15:18422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/codex.php"] [unique_id "apPk6wgfiZclygrb6nkfAwAAA28"]
[Sun Aug 30 03:08:11.797252 2026] [security2:error] [pid 504660:tid 504917] [client 20.104.49.130:54144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/av.php"] [unique_id "apPk6wgfiZclygrb6nkfCgAAA2s"]
[Sun Aug 30 03:08:11.800401 2026] [security2:error] [pid 504660:tid 504933] [client 20.104.50.220:46176] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.ianegenolf.com"] [uri "/1.php"] [unique_id "apPk6wgfiZclygrb6nkfDAAAA3s"]
[Sun Aug 30 03:08:11.800472 2026] [security2:error] [pid 504660:tid 504933] [client 20.104.50.220:46176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/1.php"] [unique_id "apPk6wgfiZclygrb6nkfDAAAA3s"]
[Sun Aug 30 03:08:11.803523 2026] [security2:error] [pid 504660:tid 504890] [client 20.104.50.220:51530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/xm.php"] [unique_id "apPk6wgfiZclygrb6nkfDgAAA1A"]
[Sun Aug 30 03:08:11.808670 2026] [security2:error] [pid 504660:tid 504941] [client 20.104.50.220:31906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/XxX.php"] [unique_id "apPk6wgfiZclygrb6nkfEwAAA4M"]
[Sun Aug 30 03:08:11.810002 2026] [security2:error] [pid 504660:tid 504902] [client 20.104.18.15:35456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/inso.php"] [unique_id "apPk6wgfiZclygrb6nkfFQAAA1w"]
[Sun Aug 30 03:08:11.812096 2026] [security2:error] [pid 507246:tid 507481] [client 74.248.24.12:11890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/meta.php"] [unique_id "apPk6-8CsCvw81e_I2ourwAAAwI"]
[Sun Aug 30 03:08:11.820927 2026] [security2:error] [pid 504660:tid 504962] [client 20.104.18.15:29169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/wefile.php"] [unique_id "apPk6wgfiZclygrb6nkfGgAAA5g"]
[Sun Aug 30 03:08:11.827698 2026] [security2:error] [pid 504660:tid 504867] [client 20.197.61.180:10463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/mar.php"] [unique_id "apPk6wgfiZclygrb6nkfHwAAAzk"]
[Sun Aug 30 03:08:11.837840 2026] [security2:error] [pid 504660:tid 504900] [client 20.104.18.15:23549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/sign.php"] [unique_id "apPk6wgfiZclygrb6nkfKgAAA1o"]
[Sun Aug 30 03:08:11.847500 2026] [security2:error] [pid 504660:tid 504956] [client 20.220.10.235:36943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/pk.php"] [unique_id "apPk6wgfiZclygrb6nkfMQAAA5I"]
[Sun Aug 30 03:08:11.850538 2026] [security2:error] [pid 504660:tid 504919] [client 20.104.50.220:33166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/%E5%B9%B3%E4%BB%AE%E5%90%8Ds.php"] [unique_id "apPk6wgfiZclygrb6nkfNgAAA20"]
[Sun Aug 30 03:08:11.862336 2026] [authz_core:error] [pid 504660:tid 504918] [client 66.249.66.70:39166] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:11.862629 2026] [authz_core:error] [pid 504660:tid 504918] [client 66.249.66.70:39166] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:11.865106 2026] [security2:error] [pid 504660:tid 504947] [client 20.104.104.62:37622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/pb.php"] [unique_id "apPk6wgfiZclygrb6nkfQwAAA4k"]
[Sun Aug 30 03:08:11.874256 2026] [security2:error] [pid 507246:tid 507395] [client 198.44.116.203:33752] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.boblivingstone.com"] [uri "/wp-content/plugins/pods/readme.txt"] [unique_id "apPk6-8CsCvw81e_I2outgAAAqw"]
[Sun Aug 30 03:08:11.879842 2026] [security2:error] [pid 504660:tid 504930] [client 158.23.184.117:56330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/template-wploader.php"] [unique_id "apPk6wgfiZclygrb6nkfSAAAA3g"]
[Sun Aug 30 03:08:11.881326 2026] [security2:error] [pid 504660:tid 504875] [client 20.48.160.90:50567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/inx.php"] [unique_id "apPk6wgfiZclygrb6nkfTAAAA0E"]
[Sun Aug 30 03:08:11.881538 2026] [security2:error] [pid 504660:tid 504851] [client 158.23.184.117:27545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/buy.php"] [unique_id "apPk6wgfiZclygrb6nkfTgAAAyk"]
[Sun Aug 30 03:08:11.884216 2026] [security2:error] [pid 507246:tid 507452] [client 20.48.250.41:47458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/asax.php"] [unique_id "apPk6-8CsCvw81e_I2outwAAAuU"]
[Sun Aug 30 03:08:11.894767 2026] [security2:error] [pid 504660:tid 504965] [client 68.155.159.216:55067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-admin.php"] [unique_id "apPk6wgfiZclygrb6nkfVwAAA5s"]
[Sun Aug 30 03:08:11.908549 2026] [security2:error] [pid 504660:tid 504955] [client 20.104.50.220:17338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/f6.php"] [unique_id "apPk6wgfiZclygrb6nkfYgAAA5E"]
[Sun Aug 30 03:08:11.951208 2026] [security2:error] [pid 504660:tid 504846] [client 68.155.159.216:63987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPk6wgfiZclygrb6nkfeQAAAyQ"]
[Sun Aug 30 03:08:11.962630 2026] [authz_core:error] [pid 504660:tid 504852] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_US
[Sun Aug 30 03:08:11.962910 2026] [authz_core:error] [pid 504660:tid 504852] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_US
[Sun Aug 30 03:08:11.964139 2026] [security2:error] [pid 504660:tid 504906] [client 20.104.18.15:1933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/images.php"] [unique_id "apPk6wgfiZclygrb6nkfgAAAA2A"]
[Sun Aug 30 03:08:11.999008 2026] [security2:error] [pid 507246:tid 507432] [client 20.220.10.235:36826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/ft.php"] [unique_id "apPk6-8CsCvw81e_I2ouxgAAAtE"]
[Sun Aug 30 03:08:12.009940 2026] [security2:error] [pid 504660:tid 504950] [client 20.104.18.15:51641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/wp-admin/w.php"] [unique_id "apPk7AgfiZclygrb6nkflgAAA4w"]
[Sun Aug 30 03:08:12.015352 2026] [security2:error] [pid 504660:tid 504908] [client 20.104.104.62:37584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/pk.php"] [unique_id "apPk7AgfiZclygrb6nkfmQAAA2I"]
[Sun Aug 30 03:08:12.021597 2026] [security2:error] [pid 504660:tid 504875] [client 158.23.184.117:56336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/template.php.INFECTED.php"] [unique_id "apPk7AgfiZclygrb6nkfoAAAA0E"]
[Sun Aug 30 03:08:12.023482 2026] [security2:error] [pid 504660:tid 504886] [client 20.48.160.90:50582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/vpn.php"] [unique_id "apPk7AgfiZclygrb6nkfoQAAA0w"]
[Sun Aug 30 03:08:12.026950 2026] [security2:error] [pid 504660:tid 504954] [client 158.23.184.117:27042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/byp.php"] [unique_id "apPk7AgfiZclygrb6nkfogAAA5A"]
[Sun Aug 30 03:08:12.040463 2026] [security2:error] [pid 504660:tid 504960] [client 20.48.250.41:47430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/fetch.php"] [unique_id "apPk7AgfiZclygrb6nkfrQAAA5Y"]
[Sun Aug 30 03:08:12.048875 2026] [security2:error] [pid 504660:tid 504858] [client 68.155.159.216:45955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/NewFile.php/"] [unique_id "apPk7AgfiZclygrb6nkfswAAAzA"]
[Sun Aug 30 03:08:12.051305 2026] [security2:error] [pid 504660:tid 504888] [client 4.205.62.107:64503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/public/wp-blog.php"] [unique_id "apPk7AgfiZclygrb6nkftQAAA04"]
[Sun Aug 30 03:08:12.060523 2026] [security2:error] [pid 504660:tid 504863] [client 4.205.62.107:36650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/w.php"] [unique_id "apPk7AgfiZclygrb6nkfuQAAAzU"]
[Sun Aug 30 03:08:12.062970 2026] [security2:error] [pid 504660:tid 504868] [client 20.104.50.220:62813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/js/priv8.php"] [unique_id "apPk7AgfiZclygrb6nkfvAAAAzo"]
[Sun Aug 30 03:08:12.092186 2026] [security2:error] [pid 504660:tid 504842] [client 20.48.251.3:33294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/maxro.php"] [unique_id "apPk7AgfiZclygrb6nkfxwAAAyA"]
[Sun Aug 30 03:08:12.102834 2026] [security2:error] [pid 504660:tid 504845] [client 20.196.209.81:12702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/robots.php"] [unique_id "apPk7AgfiZclygrb6nkfygAAAyM"]
[Sun Aug 30 03:08:12.113668 2026] [security2:error] [pid 504660:tid 504910] [client 47.128.47.11:52900] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "creativelyfree.com"] [uri "/robots.txt"] [unique_id "apPk7AgfiZclygrb6nkfzAAAA2Q"]
[Sun Aug 30 03:08:12.145713 2026] [security2:error] [pid 504660:tid 504871] [client 20.104.104.62:48036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/ft.php"] [unique_id "apPk7AgfiZclygrb6nkf2AAAAz0"]
[Sun Aug 30 03:08:12.151393 2026] [security2:error] [pid 504660:tid 504954] [client 68.155.159.216:62322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/worksec.php"] [unique_id "apPk7AgfiZclygrb6nkf2QAAA5A"]
[Sun Aug 30 03:08:12.154503 2026] [security2:error] [pid 504660:tid 504913] [client 20.220.10.235:36962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/wp-ver.php"] [unique_id "apPk7AgfiZclygrb6nkf3AAAA2c"]
[Sun Aug 30 03:08:12.159139 2026] [security2:error] [pid 504660:tid 504891] [client 20.48.160.90:33266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/shiny.php"] [unique_id "apPk7AgfiZclygrb6nkf3gAAA1E"]
[Sun Aug 30 03:08:12.162273 2026] [security2:error] [pid 504660:tid 504885] [client 158.23.184.117:56381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/templates.php"] [unique_id "apPk7AgfiZclygrb6nkf4AAAA0s"]
[Sun Aug 30 03:08:12.165772 2026] [security2:error] [pid 504660:tid 504908] [client 158.23.184.117:26969] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "www.utensiltecnica.it"] [uri "/c99.php"] [unique_id "apPk7AgfiZclygrb6nkf4wAAA2I"]
[Sun Aug 30 03:08:12.169223 2026] [security2:error] [pid 504660:tid 504944] [client 20.48.250.41:47456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/vx.php"] [unique_id "apPk7AgfiZclygrb6nkf5QAAA4Y"]
[Sun Aug 30 03:08:12.177997 2026] [security2:error] [pid 504660:tid 504896] [client 20.104.50.220:28675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/Xzd.php"] [unique_id "apPk7AgfiZclygrb6nkf7wAAA1Y"]
[Sun Aug 30 03:08:12.213366 2026] [security2:error] [pid 504660:tid 504939] [client 4.205.62.107:62426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/kedi.php"] [unique_id "apPk7AgfiZclygrb6nkgAAAAA4E"]
[Sun Aug 30 03:08:12.272080 2026] [security2:error] [pid 504660:tid 504863] [client 4.205.62.107:19054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/txets.php"] [unique_id "apPk7AgfiZclygrb6nkgIgAAAzU"]
[Sun Aug 30 03:08:12.282712 2026] [security2:error] [pid 504660:tid 504940] [client 40.83.93.50:13799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lydialovegrave.com"] [uri "/lock.php"] [unique_id "apPk7AgfiZclygrb6nkgKwAAA4I"]
[Sun Aug 30 03:08:12.283394 2026] [security2:error] [pid 504660:tid 504878] [client 20.220.10.235:36938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/ah24.php"] [unique_id "apPk7AgfiZclygrb6nkgLAAAA0Q"]
[Sun Aug 30 03:08:12.302090 2026] [security2:error] [pid 504660:tid 504935] [client 158.23.184.117:51800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/templatesdex.php"] [unique_id "apPk7AgfiZclygrb6nkgMwAAA30"]
[Sun Aug 30 03:08:12.306977 2026] [security2:error] [pid 507246:tid 507503] [client 158.23.184.117:27524] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "www.utensiltecnica.it"] [uri "/c99.php"] [unique_id "apPk7O8CsCvw81e_I2ouywAAAxg"]
[Sun Aug 30 03:08:12.307320 2026] [security2:error] [pid 507246:tid 507474] [client 216.73.216.128:42924] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPk7O8CsCvw81e_I2ouygAAAvs"]
[Sun Aug 30 03:08:12.307360 2026] [security2:error] [pid 504660:tid 504915] [client 20.48.251.3:44350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/wp-info.php"] [unique_id "apPk7AgfiZclygrb6nkgNAAAA2k"]
[Sun Aug 30 03:08:12.312008 2026] [security2:error] [pid 504660:tid 504850] [client 20.48.250.41:47457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/global.php"] [unique_id "apPk7AgfiZclygrb6nkgOAAAAyg"]
[Sun Aug 30 03:08:12.313810 2026] [security2:error] [pid 507246:tid 507440] [client 20.104.104.62:48023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/wp-ver.php"] [unique_id "apPk7O8CsCvw81e_I2ouzAAAAtk"]
[Sun Aug 30 03:08:12.315073 2026] [authz_core:error] [pid 504660:tid 504924] [client 66.249.66.77:60482] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:12.315338 2026] [authz_core:error] [pid 504660:tid 504924] [client 66.249.66.77:60482] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:12.317022 2026] [security2:error] [pid 504660:tid 504946] [client 20.48.160.90:50611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/goods.php"] [unique_id "apPk7AgfiZclygrb6nkgOgAAA4g"]
[Sun Aug 30 03:08:12.376158 2026] [security2:error] [pid 507246:tid 507405] [client 74.248.24.12:8215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/yindu.php"] [unique_id "apPk7O8CsCvw81e_I2ou0QAAArY"]
[Sun Aug 30 03:08:12.429101 2026] [security2:error] [pid 504660:tid 504927] [client 20.220.10.235:36825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPk7AgfiZclygrb6nkgYQAAA3U"]
[Sun Aug 30 03:08:12.442936 2026] [security2:error] [pid 504660:tid 504944] [client 158.23.184.117:56334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/term.php"] [unique_id "apPk7AgfiZclygrb6nkgYwAAA4Y"]
[Sun Aug 30 03:08:12.445989 2026] [security2:error] [pid 504660:tid 504905] [client 158.23.184.117:27532] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "www.utensiltecnica.it"] [uri "/c99.php"] [unique_id "apPk7AgfiZclygrb6nkgZQAAA18"]
[Sun Aug 30 03:08:12.448264 2026] [security2:error] [pid 507246:tid 507471] [client 20.104.104.62:48039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/ah24.php"] [unique_id "apPk7O8CsCvw81e_I2ou1AAAAvg"]
[Sun Aug 30 03:08:12.458271 2026] [security2:error] [pid 504660:tid 504958] [client 20.48.250.41:47484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/fs.php"] [unique_id "apPk7AgfiZclygrb6nkgaAAAA5Q"]
[Sun Aug 30 03:08:12.477081 2026] [security2:error] [pid 504660:tid 504861] [client 68.155.159.216:61388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPk7AgfiZclygrb6nkgbAAAAzM"]
[Sun Aug 30 03:08:12.495529 2026] [authz_core:error] [pid 504660:tid 504898] [client 216.73.216.128:31036] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:12.495808 2026] [authz_core:error] [pid 504660:tid 504898] [client 216.73.216.128:31036] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:12.504864 2026] [authz_core:error] [pid 504660:tid 504859] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_DK
[Sun Aug 30 03:08:12.505124 2026] [authz_core:error] [pid 504660:tid 504859] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_DK
[Sun Aug 30 03:08:12.561709 2026] [security2:error] [pid 504660:tid 504909] [client 20.196.209.81:11358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/cron.php"] [unique_id "apPk7AgfiZclygrb6nkgmQAAA2M"]
[Sun Aug 30 03:08:12.563344 2026] [security2:error] [pid 504660:tid 504894] [client 20.104.49.130:64078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/ccc.php"] [unique_id "apPk7AgfiZclygrb6nkgnAAAA1Q"]
[Sun Aug 30 03:08:12.584193 2026] [security2:error] [pid 504660:tid 504856] [client 158.23.184.117:27054] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "www.utensiltecnica.it"] [uri "/c99.php"] [unique_id "apPk7AgfiZclygrb6nkgpgAAAy4"]
[Sun Aug 30 03:08:12.584325 2026] [security2:error] [pid 504660:tid 504919] [client 158.23.184.117:51817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/tes.php"] [unique_id "apPk7AgfiZclygrb6nkgpwAAA20"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:12.589722 2026] [authz_core:error] [pid 504660:tid 504874] [client 216.73.216.128:6999] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:12.590159 2026] [authz_core:error] [pid 504660:tid 504874] [client 216.73.216.128:6999] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:12.591201 2026] [security2:error] [pid 504660:tid 504963] [client 20.48.160.90:50683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/alfa.php"] [unique_id "apPk7AgfiZclygrb6nkgqgAAA5k"]
[Sun Aug 30 03:08:12.599302 2026] [security2:error] [pid 504660:tid 504965] [client 20.104.104.62:48049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPk7AgfiZclygrb6nkgrwAAA5s"]
[Sun Aug 30 03:08:12.602149 2026] [security2:error] [pid 504660:tid 504934] [client 20.220.10.235:36961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getcrewcard.com"] [uri "/waf.php"] [unique_id "apPk7AgfiZclygrb6nkgsAAAA3w"]
[Sun Aug 30 03:08:12.605267 2026] [security2:error] [pid 504660:tid 504915] [client 20.48.250.41:48078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/ioxi.php"] [unique_id "apPk7AgfiZclygrb6nkgswAAA2k"]
[Sun Aug 30 03:08:12.625709 2026] [security2:error] [pid 504660:tid 504872] [client 20.104.50.220:61675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/tesla1.php"] [unique_id "apPk7AgfiZclygrb6nkgwQAAAz4"]
[Sun Aug 30 03:08:12.655072 2026] [authz_core:error] [pid 504660:tid 504899] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:12.655351 2026] [authz_core:error] [pid 504660:tid 504899] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:12.688410 2026] [security2:error] [pid 504660:tid 504877] [client 20.48.251.3:7093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/paypal.php"] [unique_id "apPk7AgfiZclygrb6nkg1QAAA0M"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:12.720270 2026] [security2:error] [pid 504660:tid 504926] [client 20.48.160.90:50628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/33.php"] [unique_id "apPk7AgfiZclygrb6nkg5AAAA3Q"]
[Sun Aug 30 03:08:12.726234 2026] [security2:error] [pid 504660:tid 504868] [client 158.23.184.117:51776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/tesla.php"] [unique_id "apPk7AgfiZclygrb6nkg6gAAAzo"]
[Sun Aug 30 03:08:12.739266 2026] [security2:error] [pid 507246:tid 507454] [client 20.104.104.62:37509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ryanmichaelnorton.com"] [uri "/waf.php"] [unique_id "apPk7O8CsCvw81e_I2ou7QAAAuc"]
[Sun Aug 30 03:08:12.741234 2026] [security2:error] [pid 504660:tid 504871] [client 158.23.147.79:58377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apPk7AgfiZclygrb6nkg9wAAAz0"]
[Sun Aug 30 03:08:12.742216 2026] [security2:error] [pid 504660:tid 504947] [client 20.48.250.41:48122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/bootstrap.php"] [unique_id "apPk7AgfiZclygrb6nkg-QAAA4k"]
[Sun Aug 30 03:08:12.754745 2026] [security2:error] [pid 504660:tid 504841] [client 4.205.62.107:25779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/cloud.php"] [unique_id "apPk7AgfiZclygrb6nkhAgAAAx8"]
[Sun Aug 30 03:08:12.763513 2026] [security2:error] [pid 504660:tid 504900] [client 216.73.216.128:31036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/about.html"] [unique_id "apPk7AgfiZclygrb6nkhAwAAA1o"]
[Sun Aug 30 03:08:12.771715 2026] [security2:error] [pid 504660:tid 504955] [client 158.23.184.117:27016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/cache/cache/min.php"] [unique_id "apPk7AgfiZclygrb6nkhBgAAA5E"]
[Sun Aug 30 03:08:12.789450 2026] [security2:error] [pid 504660:tid 504883] [client 20.197.61.180:7870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/css.php"] [unique_id "apPk7AgfiZclygrb6nkhEgAAA0k"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:12.848658 2026] [security2:error] [pid 507246:tid 507485] [client 20.48.160.90:50654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/133.php"] [unique_id "apPk7O8CsCvw81e_I2ou9wAAAwY"]
[Sun Aug 30 03:08:12.859228 2026] [security2:error] [pid 504660:tid 504897] [client 68.155.159.216:65476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wildcard.fenderhordes.com"] [uri "/first.php"] [unique_id "apPk7AgfiZclygrb6nkhQgAAA1c"]
[Sun Aug 30 03:08:12.862332 2026] [security2:error] [pid 507246:tid 507469] [client 4.205.62.107:64007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/pass4.php"] [unique_id "apPk7O8CsCvw81e_I2ou_gAAAvY"]
[Sun Aug 30 03:08:12.866715 2026] [security2:error] [pid 504660:tid 504920] [client 158.23.184.117:56353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/teslav.php"] [unique_id "apPk7AgfiZclygrb6nkhRwAAA24"]
[Sun Aug 30 03:08:12.873603 2026] [security2:error] [pid 504660:tid 504918] [client 20.48.250.41:48083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/export.php"] [unique_id "apPk7AgfiZclygrb6nkhSAAAA2w"]
[Sun Aug 30 03:08:12.912626 2026] [security2:error] [pid 504660:tid 504954] [client 20.104.18.15:34689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/sym.php"] [unique_id "apPk7AgfiZclygrb6nkhZwAAA5A"]
[Sun Aug 30 03:08:12.919984 2026] [security2:error] [pid 504660:tid 504937] [client 158.23.184.117:27060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/catalogbypass.php"] [unique_id "apPk7AgfiZclygrb6nkhbQAAA38"]
[Sun Aug 30 03:08:12.926090 2026] [security2:error] [pid 504660:tid 504841] [client 20.104.50.220:5913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/1234.php"] [unique_id "apPk7AgfiZclygrb6nkhbwAAAx8"]
[Sun Aug 30 03:08:12.942538 2026] [security2:error] [pid 504660:tid 504939] [client 20.104.50.220:42473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/xamp.php"] [unique_id "apPk7AgfiZclygrb6nkhdwAAA4E"]
[Sun Aug 30 03:08:12.944931 2026] [security2:error] [pid 507246:tid 507482] [client 216.73.216.128:42924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/about.html"] [unique_id "apPk7O8CsCvw81e_I2ovBwAAAwM"]
[Sun Aug 30 03:08:12.951222 2026] [security2:error] [pid 507246:tid 507499] [client 74.248.24.12:14410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/randkeyword.php"] [unique_id "apPk7O8CsCvw81e_I2ovCAAAAxQ"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:12.953179 2026] [security2:error] [pid 504660:tid 504931] [client 20.104.50.220:46595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/usep.php"] [unique_id "apPk7AgfiZclygrb6nkhggAAA3k"]
[Sun Aug 30 03:08:12.955413 2026] [security2:error] [pid 504660:tid 504920] [client 20.104.18.15:35138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/aa.php"] [unique_id "apPk7AgfiZclygrb6nkhhAAAA24"]
[Sun Aug 30 03:08:12.960536 2026] [security2:error] [pid 507246:tid 507498] [client 20.104.18.15:29575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/wp-load.php"] [unique_id "apPk7O8CsCvw81e_I2ovCgAAAxM"]
[Sun Aug 30 03:08:12.961998 2026] [authz_core:error] [pid 504660:tid 504947] [client 66.249.66.200:53918] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:12.962345 2026] [authz_core:error] [pid 504660:tid 504947] [client 66.249.66.200:53918] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:12.963213 2026] [security2:error] [pid 504660:tid 504889] [client 20.196.209.81:10083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/goat.php"] [unique_id "apPk7AgfiZclygrb6nkhjQAAA08"]
[Sun Aug 30 03:08:12.966630 2026] [security2:error] [pid 507246:tid 507390] [client 20.104.18.15:18348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/5656.php"] [unique_id "apPk7O8CsCvw81e_I2ovCwAAAqc"]
[Sun Aug 30 03:08:12.967267 2026] [authz_core:error] [pid 504660:tid 504952] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_US
[Sun Aug 30 03:08:12.967543 2026] [authz_core:error] [pid 504660:tid 504952] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_US
[Sun Aug 30 03:08:12.978582 2026] [security2:error] [pid 504660:tid 504936] [client 20.104.50.220:32565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/zk.php"] [unique_id "apPk7AgfiZclygrb6nkhlQAAA34"]
[Sun Aug 30 03:08:12.989445 2026] [security2:error] [pid 504660:tid 504890] [client 20.104.18.15:23494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/wnnjpsby.php"] [unique_id "apPk7AgfiZclygrb6nkhngAAA1A"]
[Sun Aug 30 03:08:13.002064 2026] [security2:error] [pid 504660:tid 504885] [client 20.48.160.90:33188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/sym.php"] [unique_id "apPk7QgfiZclygrb6nkhpgAAA0s"]
[Sun Aug 30 03:08:13.004425 2026] [security2:error] [pid 504660:tid 504937] [client 20.48.250.41:48110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/gk.php"] [unique_id "apPk7QgfiZclygrb6nkhqAAAA38"]
[Sun Aug 30 03:08:13.007273 2026] [security2:error] [pid 507246:tid 507487] [client 158.23.184.117:56364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/test.php"] [unique_id "apPk7e8CsCvw81e_I2ovDwAAAwg"]
[Sun Aug 30 03:08:13.015414 2026] [security2:error] [pid 504660:tid 504841] [client 213.209.159.223:31617] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transitionthemovie.com"] [uri "/system/.env"] [unique_id "apPk7QgfiZclygrb6nkhrwAAAx8"]
[Sun Aug 30 03:08:13.032376 2026] [security2:error] [pid 504660:tid 504897] [client 68.155.159.216:55072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apPk7QgfiZclygrb6nkhtwAAA1c"]
[Sun Aug 30 03:08:13.034211 2026] [security2:error] [pid 504660:tid 504914] [client 20.104.49.130:43324] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.biospherecampus.com"] [uri "/1.php"] [unique_id "apPk7QgfiZclygrb6nkhuQAAA2g"]
[Sun Aug 30 03:08:13.034308 2026] [security2:error] [pid 504660:tid 504914] [client 20.104.49.130:43324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/1.php"] [unique_id "apPk7QgfiZclygrb6nkhuQAAA2g"]
[Sun Aug 30 03:08:13.038921 2026] [security2:error] [pid 504660:tid 504953] [client 20.104.50.220:33083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-includes/rest-api/fields/anbu.php"] [unique_id "apPk7QgfiZclygrb6nkhvgAAA48"]
[Sun Aug 30 03:08:13.046022 2026] [security2:error] [pid 507246:tid 507414] [client 20.104.50.220:17309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/inputs.php"] [unique_id "apPk7e8CsCvw81e_I2ovFAAAAr8"]
[Sun Aug 30 03:08:13.059148 2026] [security2:error] [pid 504660:tid 504880] [client 158.23.184.117:27530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/cc.php"] [unique_id "apPk7QgfiZclygrb6nkhzQAAA0Y"]
[Sun Aug 30 03:08:13.064983 2026] [security2:error] [pid 504660:tid 504961] [client 68.155.159.216:64817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/ans.php"] [unique_id "apPk7QgfiZclygrb6nkh0AAAA5c"]
[Sun Aug 30 03:08:13.101155 2026] [security2:error] [pid 504660:tid 504937] [client 20.104.18.15:1990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/ops.php"] [unique_id "apPk7QgfiZclygrb6nkh2gAAA38"]
[Sun Aug 30 03:08:13.133876 2026] [security2:error] [pid 507246:tid 507438] [client 34.125.55.247:3002] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.engaginggoddaily.com"] [uri "/"] [unique_id "apPk7e8CsCvw81e_I2ovFwAAAtc"]
[Sun Aug 30 03:08:13.147109 2026] [security2:error] [pid 507246:tid 507450] [client 20.48.250.41:47438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/logs1.php"] [unique_id "apPk7e8CsCvw81e_I2ovGQAAAuM"]
[Sun Aug 30 03:08:13.150479 2026] [security2:error] [pid 504660:tid 504946] [client 158.23.184.117:51788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/test1.php"] [unique_id "apPk7QgfiZclygrb6nkh5gAAA4g"]
[Sun Aug 30 03:08:13.151599 2026] [security2:error] [pid 504660:tid 504849] [client 20.104.18.15:51664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/wp-content/k.php"] [unique_id "apPk7QgfiZclygrb6nkh5wAAAyc"]
[Sun Aug 30 03:08:13.153489 2026] [security2:error] [pid 504660:tid 504897] [client 213.209.159.223:31617] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "transitionthemovie.com"] [uri "/wp-config.php.backup"] [unique_id "apPk7QgfiZclygrb6nkh6AAAA1c"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:13.199544 2026] [security2:error] [pid 507246:tid 507379] [client 158.23.184.117:27026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/cgi-bin/admin.php"] [unique_id "apPk7e8CsCvw81e_I2ovHQAAApw"]
[Sun Aug 30 03:08:13.212187 2026] [security2:error] [pid 507246:tid 507442] [client 20.48.160.90:50622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/8.php"] [unique_id "apPk7e8CsCvw81e_I2ovHwAAAts"]
[Sun Aug 30 03:08:13.226116 2026] [security2:error] [pid 504660:tid 504934] [client 4.205.62.107:64676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/php-details.php"] [unique_id "apPk7QgfiZclygrb6nkiEgAAA3w"]
[Sun Aug 30 03:08:13.247942 2026] [security2:error] [pid 504660:tid 504960] [client 4.205.62.107:36619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/btx25.php"] [unique_id "apPk7QgfiZclygrb6nkiGwAAA5Y"]
[Sun Aug 30 03:08:13.276286 2026] [security2:error] [pid 507246:tid 507467] [client 20.48.250.41:48095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/inege.php"] [unique_id "apPk7e8CsCvw81e_I2ovKgAAAvQ"]
[Sun Aug 30 03:08:13.283478 2026] [security2:error] [pid 504660:tid 504858] [client 20.48.251.3:60513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/brc.php"] [unique_id "apPk7QgfiZclygrb6nkiKAAAAzA"]
[Sun Aug 30 03:08:13.292077 2026] [security2:error] [pid 504660:tid 504902] [client 158.23.184.117:45736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/testsend.php"] [unique_id "apPk7QgfiZclygrb6nkiKgAAA1w"]
[Sun Aug 30 03:08:13.309728 2026] [security2:error] [pid 507246:tid 507452] [client 20.104.50.220:29130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/images/priv8.php"] [unique_id "apPk7e8CsCvw81e_I2ovMwAAAuU"]
[Sun Aug 30 03:08:13.318453 2026] [authz_core:error] [pid 504660:tid 504950] [client 216.73.216.128:7918] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:13.318810 2026] [authz_core:error] [pid 504660:tid 504950] [client 216.73.216.128:7918] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:13.341195 2026] [security2:error] [pid 504660:tid 504894] [client 20.48.160.90:33224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/goods.php"] [unique_id "apPk7QgfiZclygrb6nkiOQAAA1Q"]
[Sun Aug 30 03:08:13.343568 2026] [cgid:error] [pid 504660:tid 504967] [client 158.23.184.117:27070] AH01264: stderr from /home1/tommy99/public_html/u/utensiltecnica_it/cgi-bin/cgi-bin: script not found or unable to stat
[Sun Aug 30 03:08:13.359682 2026] [security2:error] [pid 504660:tid 504937] [client 20.196.209.81:10071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/gg.php"] [unique_id "apPk7QgfiZclygrb6nkiQwAAA38"]
[Sun Aug 30 03:08:13.366510 2026] [security2:error] [pid 504660:tid 504928] [client 20.151.200.44:57914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/log.php"] [unique_id "apPk7QgfiZclygrb6nkiRgAAA3Y"]
[Sun Aug 30 03:08:13.367629 2026] [security2:error] [pid 504660:tid 504893] [client 68.155.159.216:61680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/x.php"] [unique_id "apPk7QgfiZclygrb6nkiRwAAA1M"]
[Sun Aug 30 03:08:13.368693 2026] [security2:error] [pid 504660:tid 504867] [client 4.205.62.107:62453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/oc460l3x.php"] [unique_id "apPk7QgfiZclygrb6nkiSQAAAzk"]
[Sun Aug 30 03:08:13.389432 2026] [security2:error] [pid 504660:tid 504952] [client 158.23.184.117:27070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/config.php"] [unique_id "apPk7QgfiZclygrb6nkiUAAAA44"]
[Sun Aug 30 03:08:13.402394 2026] [security2:error] [pid 504660:tid 504946] [client 20.48.250.41:11146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPk7QgfiZclygrb6nkiUwAAA4g"]
[Sun Aug 30 03:08:13.407693 2026] [security2:error] [pid 504660:tid 504951] [client 20.48.250.41:47427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/wp-link10.php"] [unique_id "apPk7QgfiZclygrb6nkiVwAAA40"]
[Sun Aug 30 03:08:13.410351 2026] [security2:error] [pid 504660:tid 504888] [client 68.155.159.216:46044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/dropdown.php"] [unique_id "apPk7QgfiZclygrb6nkiWQAAA04"]
[Sun Aug 30 03:08:13.411504 2026] [security2:error] [pid 504660:tid 504915] [client 20.104.50.220:64455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/ms-sitess.php"] [unique_id "apPk7QgfiZclygrb6nkiWgAAA2k"]
[Sun Aug 30 03:08:13.412096 2026] [security2:error] [pid 507246:tid 507447] [client 20.104.49.130:53625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/berlin.php"] [unique_id "apPk7e8CsCvw81e_I2ovNQAAAuA"]
[Sun Aug 30 03:08:13.413201 2026] [security2:error] [pid 504660:tid 504910] [client 4.205.62.107:17795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/time.php"] [unique_id "apPk7QgfiZclygrb6nkiXQAAA2Q"]
[Sun Aug 30 03:08:13.430947 2026] [security2:error] [pid 504660:tid 504863] [client 158.23.184.117:51826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/testwp.php"] [unique_id "apPk7QgfiZclygrb6nkiZwAAAzU"]
[Sun Aug 30 03:08:13.434242 2026] [authz_core:error] [pid 507246:tid 507422] [client 66.249.66.70:62529] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:13.434618 2026] [authz_core:error] [pid 507246:tid 507422] [client 66.249.66.70:62529] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:13.492067 2026] [authz_core:error] [pid 504660:tid 504958] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IN
[Sun Aug 30 03:08:13.492508 2026] [authz_core:error] [pid 504660:tid 504958] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IN
[Sun Aug 30 03:08:13.500946 2026] [security2:error] [pid 507246:tid 507465] [client 20.197.61.180:10480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/autoload_classmap.php"] [unique_id "apPk7e8CsCvw81e_I2ovOgAAAvI"]
[Sun Aug 30 03:08:13.508766 2026] [security2:error] [pid 504660:tid 504847] [client 20.48.160.90:33198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/ah.php"] [unique_id "apPk7QgfiZclygrb6nkiegAAAyU"]
[Sun Aug 30 03:08:13.523507 2026] [security2:error] [pid 507246:tid 507393] [client 20.48.251.3:4677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/fns.php"] [unique_id "apPk7e8CsCvw81e_I2ovQAAAAqo"]
[Sun Aug 30 03:08:13.530464 2026] [security2:error] [pid 504660:tid 504900] [client 158.23.184.117:26954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/login.php"] [unique_id "apPk7QgfiZclygrb6nkihwAAA1o"]
[Sun Aug 30 03:08:13.539390 2026] [security2:error] [pid 507246:tid 507432] [client 20.48.250.41:11246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPk7e8CsCvw81e_I2ovRAAAAtE"]
[Sun Aug 30 03:08:13.560170 2026] [security2:error] [pid 504660:tid 504895] [client 20.48.250.41:48009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/ww.php"] [unique_id "apPk7QgfiZclygrb6nkimAAAA1U"]
[Sun Aug 30 03:08:13.571225 2026] [security2:error] [pid 504660:tid 504925] [client 158.23.184.117:56327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/text.php"] [unique_id "apPk7QgfiZclygrb6nkioAAAA3M"]
[Sun Aug 30 03:08:13.582315 2026] [security2:error] [pid 504660:tid 504846] [client 74.248.24.12:14404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/hehe.php"] [unique_id "apPk7QgfiZclygrb6nkipwAAAyQ"]
[Sun Aug 30 03:08:13.608944 2026] [security2:error] [pid 504660:tid 504867] [client 158.23.184.117:24446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxielectronics.com"] [uri "/bgymj.php"] [unique_id "apPk7QgfiZclygrb6nkiugAAAzk"]
[Sun Aug 30 03:08:13.630311 2026] [security2:error] [pid 507246:tid 507444] [client 158.23.147.79:60213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/login.php"] [unique_id "apPk7e8CsCvw81e_I2ovUQAAAt0"]
[Sun Aug 30 03:08:13.634956 2026] [security2:error] [pid 507246:tid 507414] [client 20.151.200.44:55714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/qi.php"] [unique_id "apPk7e8CsCvw81e_I2ovVAAAAr8"]
[Sun Aug 30 03:08:13.639917 2026] [security2:error] [pid 504660:tid 504917] [client 20.48.160.90:50646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/ws55.php"] [unique_id "apPk7QgfiZclygrb6nkixQAAA2s"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:13.660867 2026] [security2:error] [pid 504660:tid 504955] [client 158.23.184.117:24403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxielectronics.com"] [uri "/bk/index.php"] [unique_id "apPk7QgfiZclygrb6nki0AAAA5E"]
[Sun Aug 30 03:08:13.674516 2026] [security2:error] [pid 507246:tid 507459] [client 158.23.184.117:27035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/index.php"] [unique_id "apPk7e8CsCvw81e_I2ovXAAAAuw"]
[Sun Aug 30 03:08:13.705652 2026] [security2:error] [pid 504660:tid 504891] [client 20.48.250.41:48086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/w1px.php"] [unique_id "apPk7QgfiZclygrb6nki8AAAA1E"]
[Sun Aug 30 03:08:13.710783 2026] [security2:error] [pid 507246:tid 507491] [client 158.23.184.117:56341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/tflow/goat.php"] [unique_id "apPk7e8CsCvw81e_I2ovZQAAAww"]
[Sun Aug 30 03:08:13.713288 2026] [security2:error] [pid 504660:tid 504890] [client 20.48.250.41:11219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/ff1.php"] [unique_id "apPk7QgfiZclygrb6nki9AAAA1A"]
[Sun Aug 30 03:08:13.716278 2026] [autoindex:error] [pid 504660:tid 504941] [client 158.23.184.117:61917] AH01276: Cannot serve directory /home1/tommy99/public_html/c/castellani1943_it/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:08:13.763732 2026] [security2:error] [pid 507246:tid 507405] [client 20.196.209.81:11367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/defaults.php"] [unique_id "apPk7e8CsCvw81e_I2ovZgAAArY"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:13.777522 2026] [security2:error] [pid 504660:tid 504907] [client 20.48.160.90:50623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/drykl.php"] [unique_id "apPk7QgfiZclygrb6nkjHAAAA2E"]
[Sun Aug 30 03:08:13.778448 2026] [security2:error] [pid 504660:tid 504856] [client 20.104.50.220:61376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/shadowx.php"] [unique_id "apPk7QgfiZclygrb6nkjHwAAAy4"]
[Sun Aug 30 03:08:13.802089 2026] [security2:error] [pid 504660:tid 504965] [client 158.23.184.117:24415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxielectronics.com"] [uri "/bootstrap.php"] [unique_id "apPk7QgfiZclygrb6nkjKQAAA5s"]
[Sun Aug 30 03:08:13.805221 2026] [security2:error] [pid 504660:tid 504941] [client 103.215.74.185:16696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.144.1.153"] [uri "/index.php"] [unique_id "apPk7QgfiZclygrb6nkjKwAAA4M"], referer: https://162.144.1.153/wp-admin/
[Sun Aug 30 03:08:13.816471 2026] [security2:error] [pid 504660:tid 504905] [client 158.23.184.117:27031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/min.php"] [unique_id "apPk7QgfiZclygrb6nkjMAAAA18"]
[Sun Aug 30 03:08:13.840174 2026] [security2:error] [pid 507246:tid 507478] [client 20.48.250.41:47453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/to.php"] [unique_id "apPk7e8CsCvw81e_I2ovdAAAAv8"]
[Sun Aug 30 03:08:13.847767 2026] [security2:error] [pid 504660:tid 504926] [client 158.23.184.117:51796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/tflow/up.php"] [unique_id "apPk7QgfiZclygrb6nkjRAAAA3Q"]
[Sun Aug 30 03:08:13.873227 2026] [security2:error] [pid 504660:tid 504874] [client 20.48.250.41:11220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/t.php"] [unique_id "apPk7QgfiZclygrb6nkjVQAAA0A"]
[Sun Aug 30 03:08:13.896662 2026] [security2:error] [pid 507246:tid 507393] [client 4.205.62.107:25875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/kerang.php"] [unique_id "apPk7e8CsCvw81e_I2ovfgAAAqo"]
[Sun Aug 30 03:08:13.943703 2026] [security2:error] [pid 507246:tid 507445] [client 158.23.184.117:24425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxielectronics.com"] [uri "/bs1.php"] [unique_id "apPk7e8CsCvw81e_I2ovhQAAAt4"]
[Sun Aug 30 03:08:13.956040 2026] [security2:error] [pid 504660:tid 504874] [client 20.48.160.90:50631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/backup.php"] [unique_id "apPk7QgfiZclygrb6nkjkQAAA0A"]
[Sun Aug 30 03:08:13.962602 2026] [security2:error] [pid 504660:tid 504853] [client 158.23.184.117:27045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/options.php"] [unique_id "apPk7QgfiZclygrb6nkjlwAAAys"]
[Sun Aug 30 03:08:13.966267 2026] [authz_core:error] [pid 504660:tid 504875] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_US
[Sun Aug 30 03:08:13.966592 2026] [authz_core:error] [pid 504660:tid 504875] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_US
[Sun Aug 30 03:08:13.968749 2026] [security2:error] [pid 504660:tid 504932] [client 20.48.250.41:47450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/thui.php"] [unique_id "apPk7QgfiZclygrb6nkjmAAAA3o"]
[Sun Aug 30 03:08:13.990757 2026] [security2:error] [pid 504660:tid 504925] [client 158.23.184.117:51778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/theme-configurator/mini.php"] [unique_id "apPk7QgfiZclygrb6nkjpgAAA3M"]
[Sun Aug 30 03:08:13.992201 2026] [security2:error] [pid 507246:tid 507495] [client 103.215.74.185:16710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.144.1.153"] [uri "/index.php"] [unique_id "apPk7e8CsCvw81e_I2ovjgAAAxA"], referer: https://162.144.1.153/wp-admin/
[Sun Aug 30 03:08:14.004971 2026] [security2:error] [pid 507246:tid 507453] [client 4.205.62.107:62105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/cu.php"] [unique_id "apPk7u8CsCvw81e_I2ovkgAAAuY"]
[Sun Aug 30 03:08:14.014803 2026] [security2:error] [pid 504660:tid 504893] [client 20.48.250.41:11248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/erty.php"] [unique_id "apPk7ggfiZclygrb6nkjsQAAA1M"]
[Sun Aug 30 03:08:14.029175 2026] [security2:error] [pid 504660:tid 504848] [client 158.23.147.79:58369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/hehehehe.php"] [unique_id "apPk7ggfiZclygrb6nkjtQAAAyY"]
[Sun Aug 30 03:08:14.039331 2026] [security2:error] [pid 504660:tid 504841] [client 20.220.10.235:46866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPk7ggfiZclygrb6nkjvAAAAx8"]
[Sun Aug 30 03:08:14.055094 2026] [security2:error] [pid 504660:tid 504951] [client 20.104.18.15:34641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/8.php"] [unique_id "apPk7ggfiZclygrb6nkjxQAAA40"]
[Sun Aug 30 03:08:14.059825 2026] [authz_core:error] [pid 507246:tid 507450] [client 216.73.216.128:9123] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:14.060099 2026] [authz_core:error] [pid 507246:tid 507450] [client 216.73.216.128:9123] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:14.063905 2026] [security2:error] [pid 504660:tid 504867] [client 20.104.50.220:5192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/10.php"] [unique_id "apPk7ggfiZclygrb6nkjzAAAAzk"]
[Sun Aug 30 03:08:14.084175 2026] [security2:error] [pid 504660:tid 504901] [client 158.23.184.117:23699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxielectronics.com"] [uri "/bthil.php"] [unique_id "apPk7ggfiZclygrb6nkj1QAAA1s"]
[Sun Aug 30 03:08:14.085971 2026] [security2:error] [pid 504660:tid 504916] [client 20.48.160.90:50642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/indo.php"] [unique_id "apPk7ggfiZclygrb6nkj1gAAA2o"]
[Sun Aug 30 03:08:14.092462 2026] [security2:error] [pid 504660:tid 504906] [client 20.104.50.220:47040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wa.php"] [unique_id "apPk7ggfiZclygrb6nkj2AAAA2A"]
[Sun Aug 30 03:08:14.096025 2026] [security2:error] [pid 504660:tid 504949] [client 20.104.50.220:42038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/ya.php"] [unique_id "apPk7ggfiZclygrb6nkj2gAAA4s"]
[Sun Aug 30 03:08:14.098530 2026] [security2:error] [pid 507246:tid 507457] [client 20.48.250.41:48103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/Jcrop.php"] [unique_id "apPk7u8CsCvw81e_I2ovlgAAAuo"]
[Sun Aug 30 03:08:14.105824 2026] [security2:error] [pid 504660:tid 504853] [client 158.23.184.117:27556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/pk.php"] [unique_id "apPk7ggfiZclygrb6nkj2wAAAys"]
[Sun Aug 30 03:08:14.110014 2026] [security2:error] [pid 507246:tid 507431] [client 20.104.18.15:35491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/img.php"] [unique_id "apPk7u8CsCvw81e_I2ovmQAAAtA"]
[Sun Aug 30 03:08:14.113569 2026] [security2:error] [pid 504660:tid 504959] [client 20.104.18.15:18389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/w3lls.php"] [unique_id "apPk7ggfiZclygrb6nkj3gAAA5U"]
[Sun Aug 30 03:08:14.115187 2026] [authz_core:error] [pid 504660:tid 504868] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:14.115662 2026] [authz_core:error] [pid 504660:tid 504868] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:14.132141 2026] [security2:error] [pid 504660:tid 504891] [client 158.23.184.117:51839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/theme-editor.php"] [unique_id "apPk7ggfiZclygrb6nkj4wAAA1E"]
[Sun Aug 30 03:08:14.139153 2026] [security2:error] [pid 507246:tid 507487] [client 74.248.24.12:8229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/user.php"] [unique_id "apPk7u8CsCvw81e_I2ovnQAAAwg"]
[Sun Aug 30 03:08:14.141978 2026] [security2:error] [pid 507246:tid 507427] [client 20.104.50.220:31882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/zone.php"] [unique_id "apPk7u8CsCvw81e_I2ovngAAAsw"]
[Sun Aug 30 03:08:14.142325 2026] [security2:error] [pid 504660:tid 504879] [client 20.104.18.15:23538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/gigi.php"] [unique_id "apPk7ggfiZclygrb6nkj5gAAA0U"]
[Sun Aug 30 03:08:14.146104 2026] [security2:error] [pid 507246:tid 507477] [client 68.155.159.216:55143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/lock.php"] [unique_id "apPk7u8CsCvw81e_I2ovoQAAAv4"]
[Sun Aug 30 03:08:14.169037 2026] [security2:error] [pid 504660:tid 504865] [client 20.220.10.235:46914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPk7ggfiZclygrb6nkj6QAAAzc"]
[Sun Aug 30 03:08:14.174911 2026] [security2:error] [pid 507246:tid 507433] [client 68.155.159.216:53243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/worksec.php"] [unique_id "apPk7u8CsCvw81e_I2ovogAAAtI"]
[Sun Aug 30 03:08:14.187785 2026] [security2:error] [pid 504660:tid 504944] [client 20.104.50.220:33293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/anbu.php"] [unique_id "apPk7ggfiZclygrb6nkj-AAAA4Y"]
[Sun Aug 30 03:08:14.188793 2026] [security2:error] [pid 504660:tid 504845] [client 20.104.50.220:16722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/av.php"] [unique_id "apPk7ggfiZclygrb6nkj-gAAAyM"]
[Sun Aug 30 03:08:14.188949 2026] [security2:error] [pid 507246:tid 507415] [client 20.48.250.41:11158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/0x.php"] [unique_id "apPk7u8CsCvw81e_I2ovowAAAsA"]
[Sun Aug 30 03:08:14.194795 2026] [security2:error] [pid 504660:tid 504904] [client 20.104.49.130:36770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/sym.php"] [unique_id "apPk7ggfiZclygrb6nkj_AAAA14"]
[Sun Aug 30 03:08:14.194909 2026] [security2:error] [pid 507246:tid 507458] [client 52.139.37.240:17364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/wp-admin/maint/index.php"] [unique_id "apPk7u8CsCvw81e_I2ovpAAAAus"]
[Sun Aug 30 03:08:14.212865 2026] [security2:error] [pid 504660:tid 504961] [client 158.23.147.79:16354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apPk7ggfiZclygrb6nkkCAAAA5c"]
[Sun Aug 30 03:08:14.215443 2026] [security2:error] [pid 504660:tid 504949] [client 20.104.18.15:29101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/robot.php"] [unique_id "apPk7ggfiZclygrb6nkkDgAAA4s"]
[Sun Aug 30 03:08:14.221393 2026] [security2:error] [pid 504660:tid 504863] [client 158.23.184.117:24388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxielectronics.com"] [uri "/buy.php"] [unique_id "apPk7ggfiZclygrb6nkkFQAAAzU"]
[Sun Aug 30 03:08:14.225252 2026] [security2:error] [pid 507246:tid 507490] [client 20.48.160.90:50645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/sign.php"] [unique_id "apPk7u8CsCvw81e_I2ovqAAAAws"]
[Sun Aug 30 03:08:14.239311 2026] [security2:error] [pid 504660:tid 504902] [client 20.104.18.15:2036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/BDKR28WP.php"] [unique_id "apPk7ggfiZclygrb6nkkHgAAA1w"]
[Sun Aug 30 03:08:14.247874 2026] [security2:error] [pid 504660:tid 504847] [client 158.23.184.117:27066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/cgi-bin/cgi-bin/cgi-bin/index.php"] [unique_id "apPk7ggfiZclygrb6nkkIAAAAyU"]
[Sun Aug 30 03:08:14.257173 2026] [security2:error] [pid 504660:tid 504896] [client 20.197.61.180:10488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/info.php"] [unique_id "apPk7ggfiZclygrb6nkkJAAAA1Y"]
[Sun Aug 30 03:08:14.274559 2026] [security2:error] [pid 507246:tid 507381] [client 158.23.184.117:51786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/theme-insbgqw.php"] [unique_id "apPk7u8CsCvw81e_I2ovrwAAAp4"]
[Sun Aug 30 03:08:14.288001 2026] [security2:error] [pid 507246:tid 507378] [client 20.104.18.15:52180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/dev.php"] [unique_id "apPk7u8CsCvw81e_I2ovsgAAAps"]
[Sun Aug 30 03:08:14.303345 2026] [security2:error] [pid 507246:tid 507464] [client 20.220.10.235:46913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/h02ugyh.php"] [unique_id "apPk7u8CsCvw81e_I2ovtQAAAvE"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:14.329562 2026] [security2:error] [pid 507246:tid 507461] [client 20.48.250.41:11215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/66.php"] [unique_id "apPk7u8CsCvw81e_I2ovuwAAAu4"]
[Sun Aug 30 03:08:14.329874 2026] [security2:error] [pid 507246:tid 507393] [client 20.48.250.41:48115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/ws58.php"] [unique_id "apPk7u8CsCvw81e_I2ovvAAAAqo"]
[Sun Aug 30 03:08:14.363931 2026] [security2:error] [pid 504660:tid 504883] [client 4.205.62.107:61823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/routes.php"] [unique_id "apPk7ggfiZclygrb6nkkTQAAA0k"]
[Sun Aug 30 03:08:14.365764 2026] [security2:error] [pid 504660:tid 504961] [client 158.23.184.117:23700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxielectronics.com"] [uri "/byp.php"] [unique_id "apPk7ggfiZclygrb6nkkTwAAA5c"]
[Sun Aug 30 03:08:14.369967 2026] [security2:error] [pid 504660:tid 504872] [client 20.196.209.81:12693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/h.php"] [unique_id "apPk7ggfiZclygrb6nkkVAAAAz4"]
[Sun Aug 30 03:08:14.371128 2026] [authz_core:error] [pid 504660:tid 504898] [client 66.249.66.199:60473] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:14.371602 2026] [authz_core:error] [pid 504660:tid 504898] [client 66.249.66.199:60473] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:14.388378 2026] [security2:error] [pid 504660:tid 504952] [client 52.139.37.240:17348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/wp-content/uploads/min.php"] [unique_id "apPk7ggfiZclygrb6nkkXQAAA44"]
[Sun Aug 30 03:08:14.389948 2026] [security2:error] [pid 507246:tid 507439] [client 158.23.184.117:27043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/cgi-bin/index.php"] [unique_id "apPk7u8CsCvw81e_I2ovwQAAAtg"]
[Sun Aug 30 03:08:14.403619 2026] [security2:error] [pid 504660:tid 504845] [client 4.205.62.107:36609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/app_dev.php"] [unique_id "apPk7ggfiZclygrb6nkkYwAAAyM"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:14.410945 2026] [security2:error] [pid 507246:tid 507420] [client 158.23.147.79:60173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-content/admin.php"] [unique_id "apPk7u8CsCvw81e_I2ovwgAAAsU"]
[Sun Aug 30 03:08:14.414348 2026] [security2:error] [pid 504660:tid 504900] [client 158.23.184.117:45712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/theme-insbitn.php"] [unique_id "apPk7ggfiZclygrb6nkkaAAAA1o"]
[Sun Aug 30 03:08:14.419922 2026] [security2:error] [pid 504660:tid 504944] [client 20.48.160.90:50593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/wnnjpsby.php"] [unique_id "apPk7ggfiZclygrb6nkkbQAAA4Y"]
[Sun Aug 30 03:08:14.420097 2026] [security2:error] [pid 507246:tid 507465] [client 20.48.251.3:13975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/vx.php"] [unique_id "apPk7u8CsCvw81e_I2ovxQAAAvI"]
[Sun Aug 30 03:08:14.430067 2026] [security2:error] [pid 504660:tid 504849] [client 20.220.10.235:46864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/sf.php"] [unique_id "apPk7ggfiZclygrb6nkkcAAAAyc"]
[Sun Aug 30 03:08:14.455383 2026] [security2:error] [pid 504660:tid 504897] [client 20.48.251.3:64448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/userfuns.php"] [unique_id "apPk7ggfiZclygrb6nkkeQAAA1c"]
[Sun Aug 30 03:08:14.456281 2026] [security2:error] [pid 504660:tid 504924] [client 20.104.49.130:52137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/wp.php"] [unique_id "apPk7ggfiZclygrb6nkkegAAA3I"]
[Sun Aug 30 03:08:14.457349 2026] [security2:error] [pid 507246:tid 507455] [client 20.104.50.220:52859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/Xploit.php"] [unique_id "apPk7u8CsCvw81e_I2ovygAAAug"]
[Sun Aug 30 03:08:14.463583 2026] [authz_core:error] [pid 504660:tid 504870] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_SG
[Sun Aug 30 03:08:14.463883 2026] [authz_core:error] [pid 504660:tid 504870] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_SG
[Sun Aug 30 03:08:14.476037 2026] [security2:error] [pid 504660:tid 504909] [client 20.48.251.3:59314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPk7ggfiZclygrb6nkkfwAAA2M"]
[Sun Aug 30 03:08:14.483654 2026] [security2:error] [pid 507246:tid 507462] [client 213.209.159.223:11765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transitionthemovie.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPk7u8CsCvw81e_I2ovzgAAAu8"]
[Sun Aug 30 03:08:14.484049 2026] [security2:error] [pid 504660:tid 504901] [client 20.48.250.41:47434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/xs.php"] [unique_id "apPk7ggfiZclygrb6nkkgQAAA1s"]
[Sun Aug 30 03:08:14.495573 2026] [security2:error] [pid 504660:tid 504843] [client 20.48.250.41:11247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/f35.php"] [unique_id "apPk7ggfiZclygrb6nkkhgAAAyE"]
[Sun Aug 30 03:08:14.505067 2026] [security2:error] [pid 507246:tid 507384] [client 4.205.62.107:22939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/drykl.php"] [unique_id "apPk7u8CsCvw81e_I2ov0AAAAqE"]
[Sun Aug 30 03:08:14.505785 2026] [security2:error] [pid 504660:tid 504932] [client 158.23.184.117:24390] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "luxielectronics.com"] [uri "/c99.php"] [unique_id "apPk7ggfiZclygrb6nkkiAAAA3o"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:14.531703 2026] [security2:error] [pid 504660:tid 504925] [client 158.23.184.117:27527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/cgi-bin/load.php"] [unique_id "apPk7ggfiZclygrb6nkklQAAA3M"]
[Sun Aug 30 03:08:14.532024 2026] [authz_core:error] [pid 504660:tid 504869] [client 216.73.216.128:6999] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:14.532306 2026] [authz_core:error] [pid 504660:tid 504869] [client 216.73.216.128:6999] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:14.547248 2026] [security2:error] [pid 504660:tid 504874] [client 20.48.160.90:33257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/gigi.php"] [unique_id "apPk7ggfiZclygrb6nkknQAAA0A"]
[Sun Aug 30 03:08:14.554896 2026] [security2:error] [pid 507246:tid 507411] [client 158.23.184.117:51777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/theme-insynwr.php"] [unique_id "apPk7u8CsCvw81e_I2ov0wAAArw"]
[Sun Aug 30 03:08:14.558615 2026] [security2:error] [pid 504660:tid 504866] [client 20.220.10.235:46850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/4e.php"] [unique_id "apPk7ggfiZclygrb6nkkpAAAAzg"]
[Sun Aug 30 03:08:14.559267 2026] [security2:error] [pid 504660:tid 504900] [client 4.205.62.107:18755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/doc.php"] [unique_id "apPk7ggfiZclygrb6nkkpwAAA1o"]
[Sun Aug 30 03:08:14.566669 2026] [security2:error] [pid 504660:tid 504882] [client 20.104.50.220:29625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/aku.php"] [unique_id "apPk7ggfiZclygrb6nkkrgAAA0g"]
[Sun Aug 30 03:08:14.572567 2026] [security2:error] [pid 504660:tid 504943] [client 68.155.159.216:45959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/.well-known/index.php"] [unique_id "apPk7ggfiZclygrb6nkkrwAAA4U"]
[Sun Aug 30 03:08:14.581230 2026] [security2:error] [pid 504660:tid 504911] [client 52.139.37.240:16656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/zoom1.php"] [unique_id "apPk7ggfiZclygrb6nkktwAAA2U"]
[Sun Aug 30 03:08:14.598800 2026] [authz_core:error] [pid 504660:tid 504889] [client 66.249.66.69:36481] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:14.599063 2026] [authz_core:error] [pid 504660:tid 504889] [client 66.249.66.69:36481] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:14.617564 2026] [security2:error] [pid 504660:tid 504886] [client 20.48.250.41:47482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/zu.php"] [unique_id "apPk7ggfiZclygrb6nkkzQAAA0w"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:14.643440 2026] [security2:error] [pid 504660:tid 504882] [client 20.48.250.41:11231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/wen.php"] [unique_id "apPk7ggfiZclygrb6nkk2wAAA0g"]
[Sun Aug 30 03:08:14.646050 2026] [security2:error] [pid 504660:tid 504873] [client 158.23.184.117:24433] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "luxielectronics.com"] [uri "/c99.php"] [unique_id "apPk7ggfiZclygrb6nkk3QAAAz8"]
[Sun Aug 30 03:08:14.652860 2026] [authz_core:error] [pid 504660:tid 504912] [client 66.249.66.206:41006] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:14.653146 2026] [authz_core:error] [pid 504660:tid 504912] [client 66.249.66.206:41006] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:14.654750 2026] [security2:error] [pid 504660:tid 504860] [client 68.155.159.216:63541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-content/x.php"] [unique_id "apPk7ggfiZclygrb6nkk5QAAAzI"]
[Sun Aug 30 03:08:14.672731 2026] [security2:error] [pid 504660:tid 504845] [client 158.23.184.117:27055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/cgi-bin/ms-files.php"] [unique_id "apPk7ggfiZclygrb6nkk8AAAAyM"]
[Sun Aug 30 03:08:14.697755 2026] [security2:error] [pid 507246:tid 507496] [client 158.23.184.117:56344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/theme-single.php"] [unique_id "apPk7u8CsCvw81e_I2ov4wAAAxE"]
[Sun Aug 30 03:08:14.703516 2026] [security2:error] [pid 504660:tid 504933] [client 20.220.10.235:46920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/ssss.php"] [unique_id "apPk7ggfiZclygrb6nklBwAAA3s"]
[Sun Aug 30 03:08:14.719541 2026] [security2:error] [pid 504660:tid 504941] [client 20.48.160.90:33158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/info.php/new.php"] [unique_id "apPk7ggfiZclygrb6nklEAAAA4M"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:14.736576 2026] [security2:error] [pid 504660:tid 504923] [client 68.155.159.216:53489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-includes/content.php"] [unique_id "apPk7ggfiZclygrb6nklGgAAA3E"]
[Sun Aug 30 03:08:14.750305 2026] [security2:error] [pid 504660:tid 504930] [client 213.209.159.223:15871] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "transitionthemovie.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPk7ggfiZclygrb6nklJgAAA3g"]
[Sun Aug 30 03:08:14.750809 2026] [security2:error] [pid 504660:tid 504942] [client 158.23.147.79:58414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/xmlrpc.php"] [unique_id "apPk7ggfiZclygrb6nklKAAAA4Q"]
[Sun Aug 30 03:08:14.752869 2026] [security2:error] [pid 504660:tid 504893] [client 20.48.250.41:48099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/lanka.php"] [unique_id "apPk7ggfiZclygrb6nklKQAAA1M"]
[Sun Aug 30 03:08:14.763287 2026] [security2:error] [pid 507246:tid 507422] [client 20.196.209.81:11343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/num.php"] [unique_id "apPk7u8CsCvw81e_I2ov7AAAAsc"]
[Sun Aug 30 03:08:14.773590 2026] [security2:error] [pid 504660:tid 504947] [client 52.139.37.240:16642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/lock360.php"] [unique_id "apPk7ggfiZclygrb6nklMAAAA4k"]
[Sun Aug 30 03:08:14.789532 2026] [security2:error] [pid 504660:tid 504966] [client 158.23.184.117:24200] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "luxielectronics.com"] [uri "/c99.php"] [unique_id "apPk7ggfiZclygrb6nklOAAAA5w"]
[Sun Aug 30 03:08:14.792971 2026] [security2:error] [pid 504660:tid 504864] [client 74.248.24.12:14820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/functions.php"] [unique_id "apPk7ggfiZclygrb6nklOQAAAzY"]
[Sun Aug 30 03:08:14.810566 2026] [security2:error] [pid 504660:tid 504915] [client 158.23.184.117:27008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/cgi-bin/wp-activate.php"] [unique_id "apPk7ggfiZclygrb6nklSQAAA2k"]
[Sun Aug 30 03:08:14.816500 2026] [security2:error] [pid 504660:tid 504851] [client 20.48.250.41:11254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/inc.php"] [unique_id "apPk7ggfiZclygrb6nklTgAAAyk"]
[Sun Aug 30 03:08:14.834692 2026] [security2:error] [pid 504660:tid 504928] [client 20.48.251.3:4718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/params.php"] [unique_id "apPk7ggfiZclygrb6nklXAAAA3Y"]
[Sun Aug 30 03:08:14.838791 2026] [security2:error] [pid 504660:tid 504852] [client 158.23.184.117:51801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/theme.php"] [unique_id "apPk7ggfiZclygrb6nklYgAAAyo"]
[Sun Aug 30 03:08:14.845391 2026] [security2:error] [pid 504660:tid 504904] [client 20.220.10.235:46955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/zoz.php"] [unique_id "apPk7ggfiZclygrb6nklagAAA14"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:14.894328 2026] [security2:error] [pid 507246:tid 507399] [client 20.48.250.41:48012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/gettest.php"] [unique_id "apPk7u8CsCvw81e_I2ov-QAAArA"]
[Sun Aug 30 03:08:14.923155 2026] [authz_core:error] [pid 507246:tid 507393] [client 216.73.216.128:13571] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:14.923437 2026] [authz_core:error] [pid 507246:tid 507393] [client 216.73.216.128:13571] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:14.943550 2026] [security2:error] [pid 504660:tid 504937] [client 20.48.250.41:11260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/6bcwiqwj.php"] [unique_id "apPk7ggfiZclygrb6nklsQAAA38"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:14.970446 2026] [security2:error] [pid 504660:tid 504898] [client 20.104.50.220:61438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/hexor.php"] [unique_id "apPk7ggfiZclygrb6nklwgAAA1g"]
[Sun Aug 30 03:08:14.970469 2026] [security2:error] [pid 504660:tid 504852] [client 158.23.184.117:27063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/cgi-bin/wp-load.php"] [unique_id "apPk7ggfiZclygrb6nklwwAAAyo"]
[Sun Aug 30 03:08:14.974912 2026] [security2:error] [pid 504660:tid 504939] [client 20.220.10.235:46854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/kcs.php"] [unique_id "apPk7ggfiZclygrb6nklxgAAA4E"]
[Sun Aug 30 03:08:14.978816 2026] [security2:error] [pid 504660:tid 504856] [client 158.23.184.117:51806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/theme/gr.php"] [unique_id "apPk7ggfiZclygrb6nklygAAAy4"]
[Sun Aug 30 03:08:14.983233 2026] [security2:error] [pid 507246:tid 507493] [client 52.139.37.240:17346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/r.php"] [unique_id "apPk7u8CsCvw81e_I2owCAAAAw4"]
[Sun Aug 30 03:08:14.991058 2026] [authz_core:error] [pid 504660:tid 504904] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_US
[Sun Aug 30 03:08:14.991382 2026] [authz_core:error] [pid 504660:tid 504904] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_US
[Sun Aug 30 03:08:15.002048 2026] [authz_core:error] [pid 504660:tid 504918] [client 66.249.66.67:62123] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:15.002335 2026] [authz_core:error] [pid 504660:tid 504918] [client 66.249.66.67:62123] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:15.021216 2026] [security2:error] [pid 504660:tid 504925] [client 20.197.61.180:7845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/b.php"] [unique_id "apPk7wgfiZclygrb6nkl4wAAA3M"]
[Sun Aug 30 03:08:15.035363 2026] [security2:error] [pid 504660:tid 504855] [client 158.23.147.79:60190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/atomlib.php"] [unique_id "apPk7wgfiZclygrb6nkl7QAAAy0"]
[Sun Aug 30 03:08:15.036870 2026] [security2:error] [pid 504660:tid 504858] [client 20.48.160.90:50672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/w.php"] [unique_id "apPk7wgfiZclygrb6nkl7gAAAzA"]
[Sun Aug 30 03:08:15.042111 2026] [security2:error] [pid 507246:tid 507391] [client 20.48.250.41:48064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/35.php"] [unique_id "apPk7-8CsCvw81e_I2owCgAAAqg"]
[Sun Aug 30 03:08:15.065629 2026] [security2:error] [pid 504660:tid 504856] [client 213.209.159.223:15871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transitionthemovie.com"] [uri "/php-info.php"] [unique_id "apPk7wgfiZclygrb6nkmBAAAAy4"]
[Sun Aug 30 03:08:15.070527 2026] [security2:error] [pid 504660:tid 504936] [client 20.48.250.41:11138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/easy.php"] [unique_id "apPk7wgfiZclygrb6nkmBQAAA34"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:15.109133 2026] [security2:error] [pid 504660:tid 504919] [client 20.220.10.235:46940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/tajj.php"] [unique_id "apPk7wgfiZclygrb6nkmDQAAA20"]
[Sun Aug 30 03:08:15.119981 2026] [security2:error] [pid 504660:tid 504851] [client 158.23.184.117:51814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/themes-install.php"] [unique_id "apPk7wgfiZclygrb6nkmEAAAAyk"]
[Sun Aug 30 03:08:15.123175 2026] [security2:error] [pid 504660:tid 504963] [client 158.23.184.117:24437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxielectronics.com"] [uri "/cache/cache/min.php"] [unique_id "apPk7wgfiZclygrb6nkmEgAAA5k"]
[Sun Aug 30 03:08:15.141231 2026] [security2:error] [pid 504660:tid 504940] [client 158.23.184.117:27558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/cgi-bin/wp-mail.php"] [unique_id "apPk7wgfiZclygrb6nkmGgAAA4I"]
[Sun Aug 30 03:08:15.143365 2026] [security2:error] [pid 504660:tid 504914] [client 4.205.62.107:62106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/services.php"] [unique_id "apPk7wgfiZclygrb6nkmHAAAA2g"]
[Sun Aug 30 03:08:15.159176 2026] [security2:error] [pid 504660:tid 504953] [client 20.196.209.81:12691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/abc.php"] [unique_id "apPk7wgfiZclygrb6nkmHwAAA48"]
[Sun Aug 30 03:08:15.175091 2026] [security2:error] [pid 504660:tid 504872] [client 52.139.37.240:16650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/sf.php"] [unique_id "apPk7wgfiZclygrb6nkmLQAAAz4"]
[Sun Aug 30 03:08:15.184544 2026] [security2:error] [pid 504660:tid 504887] [client 20.48.250.41:48043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/maraz.php"] [unique_id "apPk7wgfiZclygrb6nkmNAAAA00"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:15.194377 2026] [security2:error] [pid 507246:tid 507453] [client 216.73.216.128:13571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPk7-8CsCvw81e_I2owDgAAAuY"]
[Sun Aug 30 03:08:15.195743 2026] [security2:error] [pid 504660:tid 504917] [client 20.104.18.15:34758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/goods.php"] [unique_id "apPk7wgfiZclygrb6nkmOgAAA2s"]
[Sun Aug 30 03:08:15.201333 2026] [security2:error] [pid 504660:tid 504919] [client 20.104.50.220:5518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/9.php"] [unique_id "apPk7wgfiZclygrb6nkmPQAAA20"]
[Sun Aug 30 03:08:15.206484 2026] [security2:error] [pid 504660:tid 504951] [client 20.151.200.44:57798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/xwpg.php"] [unique_id "apPk7wgfiZclygrb6nkmQQAAA40"]
[Sun Aug 30 03:08:15.229902 2026] [security2:error] [pid 504660:tid 504950] [client 20.104.50.220:42434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/zer0.php"] [unique_id "apPk7wgfiZclygrb6nkmXgAAA4w"]
[Sun Aug 30 03:08:15.230576 2026] [security2:error] [pid 507246:tid 507384] [client 20.104.50.220:47102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wb.php"] [unique_id "apPk7-8CsCvw81e_I2owFgAAAqE"]
[Sun Aug 30 03:08:15.237135 2026] [security2:error] [pid 504660:tid 504841] [client 20.220.10.235:46974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/bge.php"] [unique_id "apPk7wgfiZclygrb6nkmYQAAAx8"]
[Sun Aug 30 03:08:15.248106 2026] [security2:error] [pid 504660:tid 504887] [client 20.104.18.15:35144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/222.php"] [unique_id "apPk7wgfiZclygrb6nkmaAAAA00"]
[Sun Aug 30 03:08:15.251263 2026] [security2:error] [pid 504660:tid 504842] [client 20.104.18.15:18386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/fpwch.php"] [unique_id "apPk7wgfiZclygrb6nkmagAAAyA"]
[Sun Aug 30 03:08:15.252365 2026] [authz_core:error] [pid 504660:tid 504866] [client 66.249.66.66:56121] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:15.252911 2026] [authz_core:error] [pid 504660:tid 504866] [client 66.249.66.66:56121] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:15.253859 2026] [security2:error] [pid 504660:tid 504967] [client 20.48.250.41:11136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/fresh3.php"] [unique_id "apPk7wgfiZclygrb6nkmbAAAA50"]
[Sun Aug 30 03:08:15.257222 2026] [security2:error] [pid 504660:tid 504964] [client 4.205.62.107:25750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/rem.php"] [unique_id "apPk7wgfiZclygrb6nkmbgAAA5o"]
[Sun Aug 30 03:08:15.258366 2026] [security2:error] [pid 504660:tid 504883] [client 158.23.184.117:56340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/themes.php"] [unique_id "apPk7wgfiZclygrb6nkmbwAAA0k"]
[Sun Aug 30 03:08:15.259158 2026] [security2:error] [pid 504660:tid 504891] [client 20.104.49.130:63526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/fling.php"] [unique_id "apPk7wgfiZclygrb6nkmcgAAA1E"]
[Sun Aug 30 03:08:15.266181 2026] [security2:error] [pid 507246:tid 507419] [client 158.23.184.117:24424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxielectronics.com"] [uri "/catalogbypass.php"] [unique_id "apPk7-8CsCvw81e_I2owHAAAAsQ"]
[Sun Aug 30 03:08:15.266309 2026] [security2:error] [pid 504660:tid 504961] [client 20.48.160.90:33241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/x.php"] [unique_id "apPk7wgfiZclygrb6nkmegAAA5c"]
[Sun Aug 30 03:08:15.283010 2026] [security2:error] [pid 504660:tid 504904] [client 158.23.184.117:27531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "apPk7wgfiZclygrb6nkmhQAAA14"]
[Sun Aug 30 03:08:15.284786 2026] [security2:error] [pid 504660:tid 504930] [client 20.104.50.220:32104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/zx.php"] [unique_id "apPk7wgfiZclygrb6nkmhgAAA3g"]
[Sun Aug 30 03:08:15.291198 2026] [security2:error] [pid 504660:tid 504958] [client 68.155.159.216:64812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/x.php"] [unique_id "apPk7wgfiZclygrb6nkmiwAAA5Q"]
[Sun Aug 30 03:08:15.294153 2026] [security2:error] [pid 504660:tid 504875] [client 20.104.18.15:23429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/info.php/new.php"] [unique_id "apPk7wgfiZclygrb6nkmjwAAA0E"]
[Sun Aug 30 03:08:15.294325 2026] [security2:error] [pid 504660:tid 504965] [client 68.155.159.216:54237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/index/function.php"] [unique_id "apPk7wgfiZclygrb6nkmkAAAA5s"]
[Sun Aug 30 03:08:15.308732 2026] [security2:error] [pid 504660:tid 504874] [client 74.248.24.12:11889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/cron.php"] [unique_id "apPk7wgfiZclygrb6nkmlAAAA0A"]
[Sun Aug 30 03:08:15.325792 2026] [security2:error] [pid 507246:tid 507392] [client 20.48.250.41:47464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/kbfr.php"] [unique_id "apPk7-8CsCvw81e_I2owHgAAAqk"]
[Sun Aug 30 03:08:15.325809 2026] [security2:error] [pid 504660:tid 504858] [client 20.104.50.220:33056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-content/%E5%B9%B3%E4%BB%AE%E5%90%8Ds.php"] [unique_id "apPk7wgfiZclygrb6nkmmwAAAzA"]
[Sun Aug 30 03:08:15.330848 2026] [security2:error] [pid 504660:tid 504967] [client 20.104.50.220:16641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/classwithtostring.php"] [unique_id "apPk7wgfiZclygrb6nkmnAAAA50"]
[Sun Aug 30 03:08:15.364930 2026] [security2:error] [pid 504660:tid 504913] [client 20.220.10.235:46940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/ssh3ll.php"] [unique_id "apPk7wgfiZclygrb6nkmsAAAA2c"]
[Sun Aug 30 03:08:15.372135 2026] [security2:error] [pid 507246:tid 507409] [client 20.104.18.15:29093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/sss.php"] [unique_id "apPk7-8CsCvw81e_I2owIgAAAro"]
[Sun Aug 30 03:08:15.378801 2026] [security2:error] [pid 504660:tid 504860] [client 20.104.18.15:2013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/k.php"] [unique_id "apPk7wgfiZclygrb6nkmtgAAAzI"]
[Sun Aug 30 03:08:15.385033 2026] [security2:error] [pid 504660:tid 504886] [client 52.139.37.240:16679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/7.php"] [unique_id "apPk7wgfiZclygrb6nkmuQAAA0w"]
[Sun Aug 30 03:08:15.395263 2026] [security2:error] [pid 504660:tid 504889] [client 158.23.184.117:56338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/themes/index.php"] [unique_id "apPk7wgfiZclygrb6nkmvgAAA08"]
[Sun Aug 30 03:08:15.405787 2026] [security2:error] [pid 504660:tid 504892] [client 158.23.184.117:23701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxielectronics.com"] [uri "/cc.php"] [unique_id "apPk7wgfiZclygrb6nkmwwAAA1I"]
[Sun Aug 30 03:08:15.420785 2026] [security2:error] [pid 504660:tid 504898] [client 158.23.184.117:27539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/chosen.php"] [unique_id "apPk7wgfiZclygrb6nkmzQAAA1g"]
[Sun Aug 30 03:08:15.428672 2026] [security2:error] [pid 504660:tid 504887] [client 20.48.250.41:11156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/bgymj.php"] [unique_id "apPk7wgfiZclygrb6nkm0QAAA00"]
[Sun Aug 30 03:08:15.430865 2026] [security2:error] [pid 504660:tid 504927] [client 20.104.18.15:51599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/wp-activate.php"] [unique_id "apPk7wgfiZclygrb6nkm0gAAA3U"]
[Sun Aug 30 03:08:15.449919 2026] [security2:error] [pid 504660:tid 504967] [client 20.48.160.90:33248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/ssla.php"] [unique_id "apPk7wgfiZclygrb6nkm1gAAA50"]
[Sun Aug 30 03:08:15.458474 2026] [security2:error] [pid 504660:tid 504897] [client 20.48.250.41:48094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/wp-act.php"] [unique_id "apPk7wgfiZclygrb6nkm2gAAA1c"]
[Sun Aug 30 03:08:15.464497 2026] [authz_core:error] [pid 504660:tid 504855] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NG
[Sun Aug 30 03:08:15.464815 2026] [authz_core:error] [pid 504660:tid 504855] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NG
[Sun Aug 30 03:08:15.480493 2026] [security2:error] [pid 504660:tid 504901] [client 103.215.74.185:16718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.144.1.153"] [uri "/index.php"] [unique_id "apPk7wgfiZclygrb6nkm5AAAA1s"], referer: https://162.144.1.153/wp-admin/
[Sun Aug 30 03:08:15.493767 2026] [security2:error] [pid 504660:tid 504952] [client 20.220.10.235:46962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/motu.php"] [unique_id "apPk7wgfiZclygrb6nkm7QAAA44"]
[Sun Aug 30 03:08:15.511329 2026] [authz_core:error] [pid 504660:tid 504923] [client 66.249.66.76:56999] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:15.511603 2026] [authz_core:error] [pid 504660:tid 504923] [client 66.249.66.76:56999] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:15.518898 2026] [security2:error] [pid 504660:tid 504863] [client 4.205.62.107:64687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/aww.php"] [unique_id "apPk7wgfiZclygrb6nkm8wAAAzU"]
[Sun Aug 30 03:08:15.538534 2026] [security2:error] [pid 504660:tid 504915] [client 158.23.184.117:56374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/themes/wp-login.php"] [unique_id "apPk7wgfiZclygrb6nknAQAAA2k"]
[Sun Aug 30 03:08:15.549410 2026] [security2:error] [pid 504660:tid 504845] [client 20.48.251.3:56381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/ty.php"] [unique_id "apPk7wgfiZclygrb6nknCgAAAyM"]
[Sun Aug 30 03:08:15.549906 2026] [security2:error] [pid 507246:tid 507380] [client 158.23.184.117:24435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxielectronics.com"] [uri "/cgi-bin/admin.php"] [unique_id "apPk7-8CsCvw81e_I2owKgAAAp0"]
[Sun Aug 30 03:08:15.563729 2026] [security2:error] [pid 507246:tid 507389] [client 20.48.250.41:11152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/ws69.php"] [unique_id "apPk7-8CsCvw81e_I2owLAAAAqY"]
[Sun Aug 30 03:08:15.579840 2026] [security2:error] [pid 507246:tid 507424] [client 52.139.37.240:16653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/b.php"] [unique_id "apPk7-8CsCvw81e_I2owMgAAAsk"]
[Sun Aug 30 03:08:15.592254 2026] [security2:error] [pid 504660:tid 504913] [client 158.23.147.79:16366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/lv.php"] [unique_id "apPk7wgfiZclygrb6nknIgAAA2c"]
[Sun Aug 30 03:08:15.596301 2026] [security2:error] [pid 504660:tid 504861] [client 103.215.74.185:16774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.144.1.153"] [uri "/index.php"] [unique_id "apPk7wgfiZclygrb6nknJQAAAzM"], referer: https://162.144.1.153/wp-admin/
[Sun Aug 30 03:08:15.606175 2026] [security2:error] [pid 504660:tid 504863] [client 20.104.50.220:28674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wso2.5.1.php"] [unique_id "apPk7wgfiZclygrb6nknKAAAAzU"]
[Sun Aug 30 03:08:15.610715 2026] [security2:error] [pid 507246:tid 507475] [client 158.23.184.117:27034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/class-wp-logo-new.php"] [unique_id "apPk7-8CsCvw81e_I2owNAAAAvw"]
[Sun Aug 30 03:08:15.613215 2026] [security2:error] [pid 504660:tid 504844] [client 20.196.209.81:11364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/default.php"] [unique_id "apPk7wgfiZclygrb6nknLgAAAyI"]
[Sun Aug 30 03:08:15.615741 2026] [security2:error] [pid 504660:tid 504916] [client 4.205.62.107:36723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/php-info.php"] [unique_id "apPk7wgfiZclygrb6nknMgAAA2o"]
[Sun Aug 30 03:08:15.623109 2026] [security2:error] [pid 504660:tid 504850] [client 20.220.10.235:46967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/wefile.php"] [unique_id "apPk7wgfiZclygrb6nknNQAAAyg"]
[Sun Aug 30 03:08:15.623214 2026] [security2:error] [pid 504660:tid 504956] [client 20.48.160.90:50668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apPk7wgfiZclygrb6nknNgAAA5I"]
[Sun Aug 30 03:08:15.628671 2026] [security2:error] [pid 504660:tid 504953] [client 20.48.251.3:59340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPk7wgfiZclygrb6nknPQAAA48"]
[Sun Aug 30 03:08:15.629717 2026] [security2:error] [pid 504660:tid 504858] [client 20.48.250.41:48072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/24.php"] [unique_id "apPk7wgfiZclygrb6nknPwAAAzA"]
[Sun Aug 30 03:08:15.645350 2026] [security2:error] [pid 507246:tid 507447] [client 4.205.62.107:62291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/rpk.php"] [unique_id "apPk7-8CsCvw81e_I2owNgAAAuA"]
[Sun Aug 30 03:08:15.646105 2026] [authz_core:error] [pid 504660:tid 504885] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:15.646550 2026] [authz_core:error] [pid 504660:tid 504885] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:15.680964 2026] [security2:error] [pid 507246:tid 507460] [client 158.23.184.117:56322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/think.php"] [unique_id "apPk7-8CsCvw81e_I2owOQAAAu0"]
[Sun Aug 30 03:08:15.683417 2026] [security2:error] [pid 504660:tid 504900] [client 114.119.136.96:61845] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.rosacollier.com"] [uri "/wp-content/plugins/jetpack/languages/json/jetpack-ckb-1bac79e646a8bf4081a5011ab72d5807.json"] [unique_id "apPk7wgfiZclygrb6nknWwAAA1o"], referer: https://www.rosacollier.com/wp-content/plugins/jetpack/languages/json/jetpack-ckb-1bac79e646a8bf4081a5011ab72d5807.json
[Sun Aug 30 03:08:15.700497 2026] [security2:error] [pid 504660:tid 504850] [client 20.104.50.220:52836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/syg.php"] [unique_id "apPk7wgfiZclygrb6nknaAAAAyg"]
[Sun Aug 30 03:08:15.701798 2026] [security2:error] [pid 504660:tid 504956] [client 213.209.159.223:7518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transitionthemovie.com"] [uri "/info.php.bak"] [unique_id "apPk7wgfiZclygrb6nknaQAAA5I"]
[Sun Aug 30 03:08:15.702936 2026] [security2:error] [pid 504660:tid 504925] [client 4.205.62.107:18973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/classsmtps.php"] [unique_id "apPk7wgfiZclygrb6nknagAAA3M"]
[Sun Aug 30 03:08:15.708404 2026] [core:crit] [pid 504660:tid 504918] (13)Permission denied: [client 158.23.184.117:0] AH00529: /home1/luxi0616/public_html/cgi-bin/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/luxi0616/public_html/cgi-bin/' is executable
[Sun Aug 30 03:08:15.746787 2026] [security2:error] [pid 504660:tid 504950] [client 68.155.159.216:46047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-content/themes/too.php"] [unique_id "apPk7wgfiZclygrb6nkniQAAA4w"]
[Sun Aug 30 03:08:15.752019 2026] [security2:error] [pid 504660:tid 504900] [client 20.220.10.235:46915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/Contrller.php"] [unique_id "apPk7wgfiZclygrb6nkniwAAA1o"]
[Sun Aug 30 03:08:15.755032 2026] [security2:error] [pid 504660:tid 504953] [client 158.23.184.117:27069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/classwithtostring.php"] [unique_id "apPk7wgfiZclygrb6nknjAAAA48"]
[Sun Aug 30 03:08:15.756257 2026] [security2:error] [pid 504660:tid 504842] [client 158.23.184.117:23698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxielectronics.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/config.php"] [unique_id "apPk7wgfiZclygrb6nknjgAAAyA"]
[Sun Aug 30 03:08:15.756281 2026] [security2:error] [pid 504660:tid 504905] [client 20.48.251.3:7400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/mamzi.php"] [unique_id "apPk7wgfiZclygrb6nknjQAAA18"]
[Sun Aug 30 03:08:15.759726 2026] [security2:error] [pid 504660:tid 504939] [client 20.151.200.44:59511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/sxxb.php"] [unique_id "apPk7wgfiZclygrb6nknkAAAA4E"]
[Sun Aug 30 03:08:15.767925 2026] [security2:error] [pid 507246:tid 507385] [client 20.48.250.41:11137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/ccs.php"] [unique_id "apPk7-8CsCvw81e_I2owQwAAAqI"]
[Sun Aug 30 03:08:15.769618 2026] [security2:error] [pid 507246:tid 507449] [client 20.48.160.90:33262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/wp-aothait.php"] [unique_id "apPk7-8CsCvw81e_I2owRAAAAuI"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:15.790582 2026] [security2:error] [pid 504660:tid 504907] [client 52.139.37.240:17385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/buy.php"] [unique_id "apPk7wgfiZclygrb6nknngAAA2E"]
[Sun Aug 30 03:08:15.801362 2026] [authz_core:error] [pid 504660:tid 504849] [client 66.249.66.74:60580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:15.801817 2026] [authz_core:error] [pid 504660:tid 504849] [client 66.249.66.74:60580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:15.806240 2026] [security2:error] [pid 504660:tid 504860] [client 20.48.250.41:48087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/155.php"] [unique_id "apPk7wgfiZclygrb6nknqAAAAzI"]
[Sun Aug 30 03:08:15.817463 2026] [security2:error] [pid 507246:tid 507386] [client 158.23.184.117:51804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/thoms.php"] [unique_id "apPk7-8CsCvw81e_I2owTAAAAqM"]
[Sun Aug 30 03:08:15.824526 2026] [security2:error] [pid 504660:tid 504843] [client 74.248.24.12:8219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/cookie.php"] [unique_id "apPk7wgfiZclygrb6nknrgAAAyE"]
[Sun Aug 30 03:08:15.845793 2026] [security2:error] [pid 504660:tid 504939] [client 158.23.147.79:58392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apPk7wgfiZclygrb6nknxQAAA4E"]
[Sun Aug 30 03:08:15.858490 2026] [security2:error] [pid 504660:tid 504880] [client 20.197.61.180:9353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/wp-login.php"] [unique_id "apPk7wgfiZclygrb6nknwgAAA0Y"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:15.893071 2026] [authz_core:error] [pid 504660:tid 504903] [client 66.249.66.72:54942] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:15.893385 2026] [authz_core:error] [pid 504660:tid 504903] [client 66.249.66.72:54942] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:15.897221 2026] [security2:error] [pid 504660:tid 504952] [client 158.23.184.117:23687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxielectronics.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/login.php"] [unique_id "apPk7wgfiZclygrb6nkn4wAAA44"]
[Sun Aug 30 03:08:15.898090 2026] [security2:error] [pid 507246:tid 507446] [client 158.23.184.117:27543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/cms.php"] [unique_id "apPk7-8CsCvw81e_I2owVgAAAt8"]
[Sun Aug 30 03:08:15.899656 2026] [security2:error] [pid 504660:tid 504846] [client 20.48.160.90:50606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/wp-includes/index.php"] [unique_id "apPk7wgfiZclygrb6nkn6AAAAyQ"]
[Sun Aug 30 03:08:15.905831 2026] [security2:error] [pid 504660:tid 504872] [client 20.220.10.235:46917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/file66.php"] [unique_id "apPk7wgfiZclygrb6nkn7QAAAz4"]
[Sun Aug 30 03:08:15.936509 2026] [security2:error] [pid 507246:tid 507398] [client 20.48.250.41:47941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/file.php"] [unique_id "apPk7-8CsCvw81e_I2owZAAAAq8"]
[Sun Aug 30 03:08:15.951524 2026] [security2:error] [pid 507246:tid 507418] [client 20.48.250.41:11262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/mar.php"] [unique_id "apPk7-8CsCvw81e_I2owawAAAsM"]
[Sun Aug 30 03:08:15.954717 2026] [security2:error] [pid 507246:tid 507377] [client 158.23.147.79:58423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/content.php"] [unique_id "apPk7-8CsCvw81e_I2owbQAAApo"]
[Sun Aug 30 03:08:15.957945 2026] [security2:error] [pid 507246:tid 507442] [client 158.23.184.117:56380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/three-column-screen-layout/db.php"] [unique_id "apPk7-8CsCvw81e_I2owbwAAAts"]
[Sun Aug 30 03:08:15.969326 2026] [security2:error] [pid 507246:tid 507496] [client 213.209.159.223:15206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transitionthemovie.com"] [uri "/phpinfo.php.bak"] [unique_id "apPk7-8CsCvw81e_I2owcgAAAxE"]
[Sun Aug 30 03:08:15.982826 2026] [security2:error] [pid 507246:tid 507443] [client 52.139.37.240:16684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/config.php"] [unique_id "apPk7-8CsCvw81e_I2oweAAAAtw"]
[Sun Aug 30 03:08:15.987985 2026] [security2:error] [pid 504660:tid 504961] [client 20.48.251.3:5083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/gjm.php"] [unique_id "apPk7wgfiZclygrb6nkoEgAAA5c"]
[Sun Aug 30 03:08:15.993325 2026] [authz_core:error] [pid 504660:tid 504846] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_DK
[Sun Aug 30 03:08:15.993689 2026] [authz_core:error] [pid 504660:tid 504846] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_DK
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:16.020339 2026] [security2:error] [pid 504660:tid 504867] [client 20.196.209.81:13196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/cloud.php"] [unique_id "apPk8AgfiZclygrb6nkoIgAAAzk"]
[Sun Aug 30 03:08:16.032640 2026] [security2:error] [pid 504660:tid 504860] [client 20.220.10.235:46797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/blnux.php"] [unique_id "apPk8AgfiZclygrb6nkoLAAAAzI"]
[Sun Aug 30 03:08:16.038386 2026] [security2:error] [pid 504660:tid 504931] [client 158.23.184.117:23697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxielectronics.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/index.php"] [unique_id "apPk8AgfiZclygrb6nkoMwAAA3k"]
[Sun Aug 30 03:08:16.040786 2026] [security2:error] [pid 504660:tid 504927] [client 158.23.184.117:27040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/config.php"] [unique_id "apPk8AgfiZclygrb6nkoNQAAA3U"]
[Sun Aug 30 03:08:16.043436 2026] [security2:error] [pid 504660:tid 504966] [client 20.151.200.44:57813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/dx.php"] [unique_id "apPk8AgfiZclygrb6nkoOAAAA5w"]
[Sun Aug 30 03:08:16.064032 2026] [authz_core:error] [pid 507246:tid 507474] [client 66.249.66.68:41726] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:16.064311 2026] [authz_core:error] [pid 507246:tid 507474] [client 66.249.66.68:41726] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:16.074664 2026] [security2:error] [pid 504660:tid 504937] [client 20.48.250.41:48120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPk8AgfiZclygrb6nkoRwAAA38"]
[Sun Aug 30 03:08:16.078532 2026] [security2:error] [pid 504660:tid 504947] [client 158.23.147.79:60186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPk8AgfiZclygrb6nkoTAAAA4k"]
[Sun Aug 30 03:08:16.083141 2026] [security2:error] [pid 504660:tid 504953] [client 20.48.250.41:11253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/ccu.php"] [unique_id "apPk8AgfiZclygrb6nkoTQAAA48"]
[Sun Aug 30 03:08:16.083226 2026] [security2:error] [pid 504660:tid 504936] [client 20.48.160.90:33168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/file31.php"] [unique_id "apPk8AgfiZclygrb6nkoTgAAA34"]
[Sun Aug 30 03:08:16.098102 2026] [security2:error] [pid 504660:tid 504841] [client 158.23.184.117:51816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/thumbs.php"] [unique_id "apPk8AgfiZclygrb6nkoUgAAAx8"]
[Sun Aug 30 03:08:16.107972 2026] [security2:error] [pid 504660:tid 504951] [client 20.104.49.130:43299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/222.php"] [unique_id "apPk8AgfiZclygrb6nkoVAAAA40"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:16.125750 2026] [security2:error] [pid 507246:tid 507391] [client 20.104.50.220:59564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/leaf.php"] [unique_id "apPk8O8CsCvw81e_I2owiQAAAqg"]
[Sun Aug 30 03:08:16.167039 2026] [security2:error] [pid 504660:tid 504880] [client 20.220.10.235:46927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/attack.php"] [unique_id "apPk8AgfiZclygrb6nkoaAAAA0Y"]
[Sun Aug 30 03:08:16.177384 2026] [security2:error] [pid 504660:tid 504867] [client 52.139.37.240:17355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/num.php"] [unique_id "apPk8AgfiZclygrb6nkocQAAAzk"]
[Sun Aug 30 03:08:16.188209 2026] [security2:error] [pid 504660:tid 504943] [client 158.23.184.117:27049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/configs.php"] [unique_id "apPk8AgfiZclygrb6nkoeAAAA4U"]
[Sun Aug 30 03:08:16.199036 2026] [security2:error] [pid 504660:tid 504909] [client 158.23.184.117:23682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxielectronics.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/min.php"] [unique_id "apPk8AgfiZclygrb6nkoewAAA2M"]
[Sun Aug 30 03:08:16.214964 2026] [security2:error] [pid 507246:tid 507416] [client 20.48.160.90:50616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/dk.php"] [unique_id "apPk8O8CsCvw81e_I2owjQAAAsE"]
[Sun Aug 30 03:08:16.221059 2026] [security2:error] [pid 507246:tid 507382] [client 20.48.250.41:47467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/06.php"] [unique_id "apPk8O8CsCvw81e_I2owjgAAAp8"]
[Sun Aug 30 03:08:16.225784 2026] [security2:error] [pid 504660:tid 504901] [client 216.73.216.128:6999] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPk8AgfiZclygrb6nkojQAAA1s"]
[Sun Aug 30 03:08:16.254976 2026] [security2:error] [pid 504660:tid 504935] [client 20.48.250.41:11213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/ak.php"] [unique_id "apPk8AgfiZclygrb6nkomwAAA30"]
[Sun Aug 30 03:08:16.258693 2026] [security2:error] [pid 504660:tid 504870] [client 158.23.184.117:51794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/ticket.php"] [unique_id "apPk8AgfiZclygrb6nkooAAAAzw"]
[Sun Aug 30 03:08:16.284542 2026] [security2:error] [pid 504660:tid 504875] [client 4.205.62.107:62122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/filesystems.php"] [unique_id "apPk8AgfiZclygrb6nkotAAAA0E"]
[Sun Aug 30 03:08:16.294580 2026] [security2:error] [pid 504660:tid 504891] [client 20.151.200.44:57104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPk8AgfiZclygrb6nkovQAAA1E"]
[Sun Aug 30 03:08:16.295048 2026] [security2:error] [pid 504660:tid 504951] [client 158.23.147.79:60201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/goat.php"] [unique_id "apPk8AgfiZclygrb6nkovgAAA40"]
[Sun Aug 30 03:08:16.298441 2026] [security2:error] [pid 507246:tid 507452] [client 20.220.10.235:46939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/wk/index.php"] [unique_id "apPk8O8CsCvw81e_I2owlQAAAuU"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:16.328587 2026] [security2:error] [pid 504660:tid 504909] [client 158.23.184.117:27534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/configuration.php"] [unique_id "apPk8AgfiZclygrb6nkoygAAA2M"]
[Sun Aug 30 03:08:16.340133 2026] [security2:error] [pid 504660:tid 504864] [client 158.23.184.117:24400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxielectronics.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/options.php"] [unique_id "apPk8AgfiZclygrb6nko0AAAAzY"]
[Sun Aug 30 03:08:16.347820 2026] [security2:error] [pid 504660:tid 504960] [client 20.104.18.15:34639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/ah.php"] [unique_id "apPk8AgfiZclygrb6nko1QAAA5Y"]
[Sun Aug 30 03:08:16.348856 2026] [security2:error] [pid 504660:tid 504933] [client 20.104.50.220:5484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/8.php"] [unique_id "apPk8AgfiZclygrb6nko1wAAA3s"]
[Sun Aug 30 03:08:16.350914 2026] [security2:error] [pid 504660:tid 504880] [client 68.155.159.216:63539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPk8AgfiZclygrb6nko2QAAA0Y"]
[Sun Aug 30 03:08:16.366481 2026] [security2:error] [pid 507246:tid 507405] [client 20.48.250.41:48097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/class.php"] [unique_id "apPk8O8CsCvw81e_I2owngAAArY"]
[Sun Aug 30 03:08:16.367331 2026] [security2:error] [pid 504660:tid 504927] [client 20.104.50.220:47081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/file1.php"] [unique_id "apPk8AgfiZclygrb6nko4gAAA3U"]
[Sun Aug 30 03:08:16.370560 2026] [security2:error] [pid 504660:tid 504878] [client 20.104.50.220:56716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/63dor.php"] [unique_id "apPk8AgfiZclygrb6nko5QAAA0Q"]
[Sun Aug 30 03:08:16.371252 2026] [security2:error] [pid 507246:tid 507409] [client 52.139.37.240:16662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/areak1.php"] [unique_id "apPk8O8CsCvw81e_I2owoAAAAro"]
[Sun Aug 30 03:08:16.388396 2026] [security2:error] [pid 504660:tid 504866] [client 20.104.18.15:18431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/domvf.php"] [unique_id "apPk8AgfiZclygrb6nko7QAAAzg"]
[Sun Aug 30 03:08:16.400435 2026] [security2:error] [pid 504660:tid 504951] [client 20.48.160.90:50637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/ta.php"] [unique_id "apPk8AgfiZclygrb6nko8QAAA40"]
[Sun Aug 30 03:08:16.402427 2026] [security2:error] [pid 504660:tid 504907] [client 68.155.159.216:54512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/.well-known/content.php"] [unique_id "apPk8AgfiZclygrb6nko8wAAA2E"]
[Sun Aug 30 03:08:16.407810 2026] [security2:error] [pid 504660:tid 504928] [client 158.23.184.117:51818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/time.php"] [unique_id "apPk8AgfiZclygrb6nko9QAAA3Y"]
[Sun Aug 30 03:08:16.408771 2026] [security2:error] [pid 504660:tid 504913] [client 74.248.24.12:17678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/spip.php"] [unique_id "apPk8AgfiZclygrb6nko9wAAA2c"]
[Sun Aug 30 03:08:16.411584 2026] [security2:error] [pid 507246:tid 507383] [client 20.104.18.15:35471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/key.php"] [unique_id "apPk8O8CsCvw81e_I2owoQAAAqA"]
[Sun Aug 30 03:08:16.414106 2026] [security2:error] [pid 504660:tid 504872] [client 20.196.209.81:12696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/admin.php"] [unique_id "apPk8AgfiZclygrb6nko_wAAAz4"]
[Sun Aug 30 03:08:16.420740 2026] [security2:error] [pid 507246:tid 507421] [client 68.155.159.216:61315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-content/x.php"] [unique_id "apPk8O8CsCvw81e_I2owogAAAsY"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:16.428366 2026] [security2:error] [pid 504660:tid 504863] [client 158.23.147.79:16376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apPk8AgfiZclygrb6nkpCQAAAzU"]
[Sun Aug 30 03:08:16.435620 2026] [security2:error] [pid 504660:tid 504925] [client 20.48.250.41:11141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/lib.php"] [unique_id "apPk8AgfiZclygrb6nkpDQAAA3M"]
[Sun Aug 30 03:08:16.436739 2026] [security2:error] [pid 504660:tid 504917] [client 20.104.50.220:31846] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "www.38cupscreen.cover789.com"] [uri "/.conf.php"] [unique_id "apPk8AgfiZclygrb6nkpDgAAA2s"]
[Sun Aug 30 03:08:16.437056 2026] [autoindex:error] [pid 504660:tid 504912] [client 20.104.18.15:23445] AH01276: Cannot serve directory /home2/mtrstacy/public_html/bridges/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:08:16.439335 2026] [security2:error] [pid 504660:tid 504914] [client 20.220.10.235:46868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/dehnl.php"] [unique_id "apPk8AgfiZclygrb6nkpDwAAA2g"]
[Sun Aug 30 03:08:16.467411 2026] [security2:error] [pid 504660:tid 504893] [client 20.104.50.220:16742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPk8AgfiZclygrb6nkpFAAAA1M"]
[Sun Aug 30 03:08:16.470549 2026] [security2:error] [pid 504660:tid 504935] [client 158.23.184.117:27013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/content.php"] [unique_id "apPk8AgfiZclygrb6nkpFQAAA30"]
[Sun Aug 30 03:08:16.478528 2026] [security2:error] [pid 504660:tid 504883] [client 20.104.50.220:33336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-admin/%E5%B9%B3%E4%BB%AE%E5%90%8Ds.php"] [unique_id "apPk8AgfiZclygrb6nkpGQAAA0k"]
[Sun Aug 30 03:08:16.481477 2026] [security2:error] [pid 504660:tid 504892] [client 158.23.184.117:24393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxielectronics.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/pk.php"] [unique_id "apPk8AgfiZclygrb6nkpGgAAA1I"]
[Sun Aug 30 03:08:16.481890 2026] [security2:error] [pid 507246:tid 507435] [client 20.104.49.130:63490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/samll.php"] [unique_id "apPk8O8CsCvw81e_I2owqAAAAtQ"]
[Sun Aug 30 03:08:16.491825 2026] [authz_core:error] [pid 504660:tid 504901] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NG
[Sun Aug 30 03:08:16.492111 2026] [authz_core:error] [pid 504660:tid 504901] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NG
[Sun Aug 30 03:08:16.500115 2026] [security2:error] [pid 504660:tid 504905] [client 20.104.18.15:23445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/w.php"] [unique_id "apPk8AgfiZclygrb6nkpIgAAA18"]
[Sun Aug 30 03:08:16.516759 2026] [authz_core:error] [pid 507246:tid 507395] [client 216.73.216.128:9123] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:16.517190 2026] [authz_core:error] [pid 507246:tid 507395] [client 216.73.216.128:9123] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:16.527057 2026] [security2:error] [pid 504660:tid 504886] [client 20.104.49.130:63293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/makeasmtp.php"] [unique_id "apPk8AgfiZclygrb6nkpLQAAA0w"]
[Sun Aug 30 03:08:16.531412 2026] [security2:error] [pid 504660:tid 504942] [client 20.104.18.15:2002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/dex.php"] [unique_id "apPk8AgfiZclygrb6nkpMQAAA4Q"]
[Sun Aug 30 03:08:16.532101 2026] [security2:error] [pid 507246:tid 507447] [client 20.48.160.90:33213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/bo.php"] [unique_id "apPk8O8CsCvw81e_I2owrQAAAuA"]
[Sun Aug 30 03:08:16.535597 2026] [security2:error] [pid 504660:tid 504921] [client 20.151.200.44:57812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/xda.php"] [unique_id "apPk8AgfiZclygrb6nkpNgAAA28"]
[Sun Aug 30 03:08:16.536924 2026] [security2:error] [pid 507246:tid 507458] [client 20.104.18.15:29669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/xmini4.php"] [unique_id "apPk8O8CsCvw81e_I2owrgAAAus"]
[Sun Aug 30 03:08:16.551181 2026] [security2:error] [pid 504660:tid 504899] [client 158.23.184.117:56370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/tiny.php"] [unique_id "apPk8AgfiZclygrb6nkpPwAAA1k"]
[Sun Aug 30 03:08:16.568851 2026] [security2:error] [pid 504660:tid 504935] [client 20.48.250.41:11079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/wp-style.php"] [unique_id "apPk8AgfiZclygrb6nkpUAAAA30"]
[Sun Aug 30 03:08:16.574863 2026] [security2:error] [pid 507246:tid 507472] [client 20.104.18.15:51700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/wp_blog_footer.php"] [unique_id "apPk8O8CsCvw81e_I2owtAAAAvk"]
[Sun Aug 30 03:08:16.579153 2026] [security2:error] [pid 504660:tid 504873] [client 20.220.10.235:46954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/png.php"] [unique_id "apPk8AgfiZclygrb6nkpWAAAAz8"]
[Sun Aug 30 03:08:16.580837 2026] [security2:error] [pid 507246:tid 507478] [client 52.139.37.240:17376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/vc.php"] [unique_id "apPk8O8CsCvw81e_I2owtwAAAv8"]
[Sun Aug 30 03:08:16.592919 2026] [security2:error] [pid 504660:tid 504942] [client 20.48.250.41:48073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/8.php"] [unique_id "apPk8AgfiZclygrb6nkpYgAAA4Q"]
[Sun Aug 30 03:08:16.598627 2026] [security2:error] [pid 504660:tid 504868] [client 4.205.62.107:25760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/min.php"] [unique_id "apPk8AgfiZclygrb6nkpYwAAAzo"]
[Sun Aug 30 03:08:16.599026 2026] [security2:error] [pid 504660:tid 504904] [client 20.197.61.180:10452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/aa.php"] [unique_id "apPk8AgfiZclygrb6nkpZAAAA14"]
[Sun Aug 30 03:08:16.604142 2026] [security2:error] [pid 504660:tid 504921] [client 213.209.159.223:23928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transitionthemovie.com"] [uri "/env/.env"] [unique_id "apPk8AgfiZclygrb6nkpZQAAA28"]
[Sun Aug 30 03:08:16.615701 2026] [security2:error] [pid 504660:tid 504953] [client 158.23.184.117:12895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jdmpruning.com"] [uri "/wp-includes/ID3/config.php"] [unique_id "apPk8AgfiZclygrb6nkpbQAAA48"]
[Sun Aug 30 03:08:16.627106 2026] [security2:error] [pid 504660:tid 504840] [client 158.23.147.79:58381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apPk8AgfiZclygrb6nkpdgAAAx4"]
[Sun Aug 30 03:08:16.629192 2026] [security2:error] [pid 504660:tid 504850] [client 158.23.184.117:27542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/core.php"] [unique_id "apPk8AgfiZclygrb6nkpdwAAAyg"]
[Sun Aug 30 03:08:16.640281 2026] [security2:error] [pid 504660:tid 504871] [client 158.23.184.117:24401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxielectronics.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/index.php"] [unique_id "apPk8AgfiZclygrb6nkpfQAAAz0"]
[Sun Aug 30 03:08:16.654097 2026] [security2:error] [pid 504660:tid 504892] [client 4.205.62.107:61789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/maxro.php"] [unique_id "apPk8AgfiZclygrb6nkphQAAA1I"]
[Sun Aug 30 03:08:16.668407 2026] [security2:error] [pid 504660:tid 504918] [client 158.23.184.117:12916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jdmpruning.com"] [uri "/test1.php"] [unique_id "apPk8AgfiZclygrb6nkpjQAAA2w"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:16.689898 2026] [security2:error] [pid 504660:tid 504907] [client 20.48.251.3:33342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/adminer-4.7.6-en.php"] [unique_id "apPk8AgfiZclygrb6nkplwAAA2E"]
[Sun Aug 30 03:08:16.693829 2026] [security2:error] [pid 504660:tid 504920] [client 158.23.184.117:56355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/tinyfilemanager.php"] [unique_id "apPk8AgfiZclygrb6nkpmgAAA24"]
[Sun Aug 30 03:08:16.696970 2026] [security2:error] [pid 504660:tid 504960] [client 20.48.250.41:11214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/browse.php"] [unique_id "apPk8AgfiZclygrb6nkpmwAAA5Y"]
[Sun Aug 30 03:08:16.705002 2026] [security2:error] [pid 504660:tid 504898] [client 20.48.160.90:33264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/44.php"] [unique_id "apPk8AgfiZclygrb6nkpoQAAA1g"]
[Sun Aug 30 03:08:16.720889 2026] [security2:error] [pid 504660:tid 504840] [client 20.220.10.235:46919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/txets.php"] [unique_id "apPk8AgfiZclygrb6nkprQAAAx4"]
[Sun Aug 30 03:08:16.728853 2026] [security2:error] [pid 504660:tid 504874] [client 20.48.250.41:48102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/0x0x.php"] [unique_id "apPk8AgfiZclygrb6nkpsAAAA0A"]
[Sun Aug 30 03:08:16.730266 2026] [authz_core:error] [pid 504660:tid 504966] [client 66.249.66.71:46260] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:16.730706 2026] [authz_core:error] [pid 504660:tid 504966] [client 66.249.66.71:46260] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:16.735274 2026] [security2:error] [pid 504660:tid 504847] [client 158.23.147.79:60212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apPk8AgfiZclygrb6nkpswAAAyU"]
[Sun Aug 30 03:08:16.744924 2026] [security2:error] [pid 504660:tid 504935] [client 20.104.50.220:52818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wibu.php"] [unique_id "apPk8AgfiZclygrb6nkpvwAAA30"]
[Sun Aug 30 03:08:16.767217 2026] [security2:error] [pid 507246:tid 507462] [client 20.48.251.3:59359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/cloud.php"] [unique_id "apPk8O8CsCvw81e_I2ow0AAAAu8"]
[Sun Aug 30 03:08:16.770444 2026] [security2:error] [pid 504660:tid 504872] [client 158.23.184.117:27576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/data.php"] [unique_id "apPk8AgfiZclygrb6nkpyAAAAz4"]
[Sun Aug 30 03:08:16.772938 2026] [security2:error] [pid 504660:tid 504887] [client 52.139.37.240:17362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPk8AgfiZclygrb6nkpywAAA00"]
[Sun Aug 30 03:08:16.777795 2026] [security2:error] [pid 504660:tid 504902] [client 4.205.62.107:36729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/infos.php"] [unique_id "apPk8AgfiZclygrb6nkpzwAAA1w"]
[Sun Aug 30 03:08:16.778509 2026] [security2:error] [pid 507246:tid 507457] [client 20.151.200.44:57904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPk8O8CsCvw81e_I2ow0gAAAuo"]
[Sun Aug 30 03:08:16.780456 2026] [security2:error] [pid 504660:tid 504842] [client 158.23.184.117:24414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxielectronics.com"] [uri "/cgi-bin/index.php"] [unique_id "apPk8AgfiZclygrb6nkp0wAAAyA"]
[Sun Aug 30 03:08:16.802058 2026] [security2:error] [pid 504660:tid 504931] [client 4.205.62.107:22974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/saml.php"] [unique_id "apPk8AgfiZclygrb6nkp4wAAA3k"]
[Sun Aug 30 03:08:16.809941 2026] [security2:error] [pid 504660:tid 504925] [client 158.23.184.117:12903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jdmpruning.com"] [uri "/wp-admin/edit-tags.php"] [unique_id "apPk8AgfiZclygrb6nkp5wAAA3M"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:16.835786 2026] [security2:error] [pid 504660:tid 504959] [client 158.23.184.117:51782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/tinymce/langs/about.php"] [unique_id "apPk8AgfiZclygrb6nkp9QAAA5U"]
[Sun Aug 30 03:08:16.841040 2026] [security2:error] [pid 504660:tid 504908] [client 4.205.62.107:18663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/cache-compat.php"] [unique_id "apPk8AgfiZclygrb6nkp-wAAA2I"]
[Sun Aug 30 03:08:16.841422 2026] [security2:error] [pid 504660:tid 504918] [client 20.48.160.90:33249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/h2.php"] [unique_id "apPk8AgfiZclygrb6nkp_AAAA2w"]
[Sun Aug 30 03:08:16.842335 2026] [security2:error] [pid 504660:tid 504895] [client 20.196.209.81:13198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/index.php"] [unique_id "apPk8AgfiZclygrb6nkp_QAAA1U"]
[Sun Aug 30 03:08:16.864594 2026] [security2:error] [pid 507246:tid 507409] [client 20.48.250.41:11204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/zoo.php"] [unique_id "apPk8O8CsCvw81e_I2ow4gAAAro"]
[Sun Aug 30 03:08:16.868620 2026] [security2:error] [pid 504660:tid 504901] [client 20.48.250.41:48048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/166.php"] [unique_id "apPk8AgfiZclygrb6nkqDgAAA1s"]
[Sun Aug 30 03:08:16.878957 2026] [security2:error] [pid 507246:tid 507400] [client 20.220.10.235:46972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/wp-login.php"] [unique_id "apPk8O8CsCvw81e_I2ow5gAAArE"]
[Sun Aug 30 03:08:16.890996 2026] [security2:error] [pid 504660:tid 504933] [client 103.215.74.185:16788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.144.1.153"] [uri "/index.php"] [unique_id "apPk8AgfiZclygrb6nkqIQAAA3s"], referer: https://162.144.1.153/wp-admin/
[Sun Aug 30 03:08:16.891986 2026] [security2:error] [pid 504660:tid 504927] [client 158.23.147.79:58374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/dropdown.php"] [unique_id "apPk8AgfiZclygrb6nkqIgAAA3U"]
[Sun Aug 30 03:08:16.895155 2026] [security2:error] [pid 504660:tid 504896] [client 68.155.159.216:62042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-admin/css/index.php"] [unique_id "apPk8AgfiZclygrb6nkqKAAAA1Y"]
[Sun Aug 30 03:08:16.903932 2026] [security2:error] [pid 504660:tid 504913] [client 20.104.50.220:62797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/contactz.php"] [unique_id "apPk8AgfiZclygrb6nkqMAAAA2c"]
[Sun Aug 30 03:08:16.911622 2026] [security2:error] [pid 504660:tid 504851] [client 158.23.184.117:27033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/database.php"] [unique_id "apPk8AgfiZclygrb6nkqNwAAAyk"]
[Sun Aug 30 03:08:16.916887 2026] [authz_core:error] [pid 507246:tid 507470] [client 66.249.66.65:59870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:16.917320 2026] [authz_core:error] [pid 507246:tid 507470] [client 66.249.66.65:59870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:16.918364 2026] [security2:error] [pid 504660:tid 504840] [client 158.23.184.117:24432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxielectronics.com"] [uri "/cgi-bin/load.php"] [unique_id "apPk8AgfiZclygrb6nkqOwAAAx4"]
[Sun Aug 30 03:08:16.920766 2026] [security2:error] [pid 504660:tid 504861] [client 213.209.159.223:23928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transitionthemovie.com"] [uri "/src/.env"] [unique_id "apPk8AgfiZclygrb6nkqPAAAAzM"]
[Sun Aug 30 03:08:16.923070 2026] [security2:error] [pid 504660:tid 504879] [client 74.248.24.12:20202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/22.php"] [unique_id "apPk8AgfiZclygrb6nkqPwAAA0U"]
[Sun Aug 30 03:08:16.953004 2026] [security2:error] [pid 504660:tid 504961] [client 158.23.184.117:12886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jdmpruning.com"] [uri "/xmlrpc.php"] [unique_id "apPk8AgfiZclygrb6nkqUQAAA5c"]
[Sun Aug 30 03:08:16.967489 2026] [authz_core:error] [pid 504660:tid 504896] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_US
[Sun Aug 30 03:08:16.967849 2026] [authz_core:error] [pid 504660:tid 504896] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_US
[Sun Aug 30 03:08:16.976231 2026] [security2:error] [pid 504660:tid 504859] [client 158.23.184.117:51835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/tinymce/plugins/compat3x/css/index.php"] [unique_id "apPk8AgfiZclygrb6nkqYwAAAzE"]
[Sun Aug 30 03:08:16.997772 2026] [security2:error] [pid 504660:tid 504947] [client 52.139.37.240:16640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/core.php"] [unique_id "apPk8AgfiZclygrb6nkqcgAAA4k"]
[Sun Aug 30 03:08:17.000803 2026] [security2:error] [pid 507246:tid 507487] [client 20.48.250.41:48085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/h2a2ck.php"] [unique_id "apPk8e8CsCvw81e_I2ow-wAAAwg"]
[Sun Aug 30 03:08:17.002566 2026] [security2:error] [pid 504660:tid 504886] [client 103.215.74.185:40018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.144.1.153"] [uri "/index.php"] [unique_id "apPk8QgfiZclygrb6nkqdQAAA0w"], referer: https://162.144.1.153/wp-admin/
[Sun Aug 30 03:08:17.003418 2026] [security2:error] [pid 507246:tid 507500] [client 20.48.250.41:11257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/elp.php"] [unique_id "apPk8e8CsCvw81e_I2ow_AAAAxU"]
[Sun Aug 30 03:08:17.007890 2026] [security2:error] [pid 504660:tid 504931] [client 158.23.147.79:58390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/sad/about.php"] [unique_id "apPk8QgfiZclygrb6nkqeQAAA3k"]
[Sun Aug 30 03:08:17.019303 2026] [security2:error] [pid 504660:tid 504860] [client 20.220.10.235:46857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/wp-access.php"] [unique_id "apPk8QgfiZclygrb6nkqggAAAzI"]
[Sun Aug 30 03:08:17.027876 2026] [security2:error] [pid 504660:tid 504918] [client 20.48.160.90:50600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apPk8QgfiZclygrb6nkqhQAAA2w"]
[Sun Aug 30 03:08:17.053181 2026] [security2:error] [pid 507246:tid 507485] [client 158.23.184.117:27555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/db.php"] [unique_id "apPk8e8CsCvw81e_I2oxAAAAAwY"]
[Sun Aug 30 03:08:17.054459 2026] [security2:error] [pid 507246:tid 507456] [client 158.158.54.35:18147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/96i.php"] [unique_id "apPk8e8CsCvw81e_I2oxAgAAAuk"]
[Sun Aug 30 03:08:17.059413 2026] [security2:error] [pid 504660:tid 504902] [client 158.23.184.117:23736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxielectronics.com"] [uri "/cgi-bin/ms-files.php"] [unique_id "apPk8QgfiZclygrb6nkqmwAAA1w"]
[Sun Aug 30 03:08:17.116013 2026] [security2:error] [pid 504660:tid 504910] [client 158.23.184.117:56359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/tinymce/plugins/fullscreen/about.php"] [unique_id "apPk8QgfiZclygrb6nkqqAAAA2Q"]
[Sun Aug 30 03:08:17.133565 2026] [security2:error] [pid 504660:tid 504967] [client 20.48.250.41:47452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/error_log.php"] [unique_id "apPk8QgfiZclygrb6nkqsAAAA50"]
[Sun Aug 30 03:08:17.135091 2026] [security2:error] [pid 504660:tid 504906] [client 20.48.251.3:6473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/public/rip.php.php"] [unique_id "apPk8QgfiZclygrb6nkqsgAAA2A"]
[Sun Aug 30 03:08:17.148485 2026] [security2:error] [pid 507246:tid 507414] [client 20.220.10.235:46861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/wp-content/admin.php"] [unique_id "apPk8e8CsCvw81e_I2oxDAAAAr8"]
[Sun Aug 30 03:08:17.150853 2026] [security2:error] [pid 507246:tid 507495] [client 158.23.184.117:12876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jdmpruning.com"] [uri "/wp-admin/.cfg_aae.php"] [unique_id "apPk8e8CsCvw81e_I2oxDQAAAxA"]
[Sun Aug 30 03:08:17.152593 2026] [authz_core:error] [pid 504660:tid 504958] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:17.152888 2026] [authz_core:error] [pid 504660:tid 504958] [client 74.7.227.8:46706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:17.158911 2026] [security2:error] [pid 504660:tid 504949] [client 20.48.160.90:50562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/sao.php"] [unique_id "apPk8QgfiZclygrb6nkqtgAAA4s"]
[Sun Aug 30 03:08:17.161796 2026] [lsapi:error] [pid 504660:tid 504826] [remote 57.141.14.28:59978] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n
[Sun Aug 30 03:08:17.163216 2026] [lsapi:error] [pid 504660:tid 504826] [remote 57.141.14.28:59978] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n
[Sun Aug 30 03:08:17.186304 2026] [security2:error] [pid 507246:tid 507416] [client 158.23.147.79:58389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/admin.php"] [unique_id "apPk8e8CsCvw81e_I2oxEQAAAsE"]
[Sun Aug 30 03:08:17.188432 2026] [security2:error] [pid 504660:tid 504928] [client 52.139.37.240:16669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/wp-content/min.php"] [unique_id "apPk8QgfiZclygrb6nkqwwAAA3Y"]
[Sun Aug 30 03:08:17.194710 2026] [security2:error] [pid 504660:tid 504909] [client 20.48.251.3:4833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/configuration.php"] [unique_id "apPk8QgfiZclygrb6nkqyQAAA2M"]
[Sun Aug 30 03:08:17.199590 2026] [security2:error] [pid 504660:tid 504840] [client 20.48.250.41:11148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/666.php"] [unique_id "apPk8QgfiZclygrb6nkqzAAAAx4"]
[Sun Aug 30 03:08:17.200339 2026] [security2:error] [pid 504660:tid 504957] [client 158.23.184.117:24405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxielectronics.com"] [uri "/cgi-bin/wp-activate.php"] [unique_id "apPk8QgfiZclygrb6nkqzgAAA5M"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:17.209138 2026] [core:error] [pid 504660:tid 504851] [client 20.196.209.81:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:08:17.209158 2026] [core:error] [pid 504660:tid 504851] [client 20.196.209.81:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:08:17.215430 2026] [security2:error] [pid 504660:tid 504884] [client 158.23.184.117:26948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/default.php"] [unique_id "apPk8QgfiZclygrb6nkq3wAAA0o"]
[Sun Aug 30 03:08:17.236020 2026] [security2:error] [pid 504660:tid 504870] [client 213.209.159.223:23928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transitionthemovie.com"] [uri "/config/app.php"] [unique_id "apPk8QgfiZclygrb6nkq6gAAAzw"]
[Sun Aug 30 03:08:17.240009 2026] [security2:error] [pid 507246:tid 507438] [client 68.155.159.216:46058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/radio.php"] [unique_id "apPk8e8CsCvw81e_I2oxFQAAAtc"]
[Sun Aug 30 03:08:17.257193 2026] [security2:error] [pid 504660:tid 504912] [client 158.23.184.117:56369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/tinymce/skins/lightgray/fonts/index.php"] [unique_id "apPk8QgfiZclygrb6nkq9QAAA2Y"]
[Sun Aug 30 03:08:17.260512 2026] [authz_core:error] [pid 507246:tid 507396] [client 66.249.66.68:41726] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:17.260840 2026] [authz_core:error] [pid 507246:tid 507396] [client 66.249.66.68:41726] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:17.269358 2026] [security2:error] [pid 504660:tid 504903] [client 20.48.250.41:48069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/403.php"] [unique_id "apPk8QgfiZclygrb6nkq_QAAA10"]
[Sun Aug 30 03:08:17.271630 2026] [security2:error] [pid 504660:tid 504849] [client 20.196.209.81:10054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/php8.php"] [unique_id "apPk8QgfiZclygrb6nkq_wAAAyc"]
[Sun Aug 30 03:08:17.278964 2026] [security2:error] [pid 504660:tid 504946] [client 20.220.10.235:46916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/log.php"] [unique_id "apPk8QgfiZclygrb6nkrBgAAA4g"]
[Sun Aug 30 03:08:17.293089 2026] [security2:error] [pid 504660:tid 504913] [client 158.23.184.117:12865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jdmpruning.com"] [uri "/wp-content/.wp_a1f.php"] [unique_id "apPk8QgfiZclygrb6nkrDAAAA2c"]
[Sun Aug 30 03:08:17.294338 2026] [security2:error] [pid 504660:tid 504863] [client 158.23.147.79:60168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-admin/admin.php"] [unique_id "apPk8QgfiZclygrb6nkrDgAAAzU"]
[Sun Aug 30 03:08:17.295855 2026] [security2:error] [pid 504660:tid 504842] [client 20.197.61.180:9365] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "www.indieoffroad.webio7.com"] [uri "/c99.php"] [unique_id "apPk8QgfiZclygrb6nkrDwAAAyA"]
[Sun Aug 30 03:08:17.316888 2026] [security2:error] [pid 504660:tid 504886] [client 20.48.160.90:33234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/dapa.php"] [unique_id "apPk8QgfiZclygrb6nkrGAAAA0w"]
[Sun Aug 30 03:08:17.320408 2026] [security2:error] [pid 504660:tid 504875] [client 20.104.50.220:61386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/FoxWSOv1.php"] [unique_id "apPk8QgfiZclygrb6nkrGQAAA0E"]
[Sun Aug 30 03:08:17.341440 2026] [security2:error] [pid 504660:tid 504964] [client 158.23.184.117:23685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxielectronics.com"] [uri "/cgi-bin/wp-load.php"] [unique_id "apPk8QgfiZclygrb6nkrIQAAA5o"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:17.357513 2026] [security2:error] [pid 507246:tid 507431] [client 158.23.184.117:27569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/dev1s.php"] [unique_id "apPk8e8CsCvw81e_I2oxHgAAAtA"]
[Sun Aug 30 03:08:17.381263 2026] [security2:error] [pid 504660:tid 504900] [client 20.48.250.41:11256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/knmt.php"] [unique_id "apPk8QgfiZclygrb6nkrNwAAA1o"]
[Sun Aug 30 03:08:17.381293 2026] [security2:error] [pid 504660:tid 504890] [client 52.139.37.240:17366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "apPk8QgfiZclygrb6nkrNgAAA1A"]
[Sun Aug 30 03:08:17.405778 2026] [security2:error] [pid 504660:tid 504937] [client 158.23.184.117:56333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/tinymce/skins/lightgray/fonts/sx.php"] [unique_id "apPk8QgfiZclygrb6nkrPgAAA38"]
[Sun Aug 30 03:08:17.406717 2026] [security2:error] [pid 507246:tid 507502] [client 158.23.147.79:16349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apPk8e8CsCvw81e_I2oxJQAAAxc"]
[Sun Aug 30 03:08:17.406863 2026] [security2:error] [pid 507246:tid 507405] [client 20.220.10.235:46861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/xwpg.php"] [unique_id "apPk8e8CsCvw81e_I2oxJgAAArY"]
[Sun Aug 30 03:08:17.418477 2026] [security2:error] [pid 504660:tid 504874] [client 20.48.250.41:48007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/cytyr.php"] [unique_id "apPk8QgfiZclygrb6nkrSAAAA0A"]
[Sun Aug 30 03:08:17.431679 2026] [security2:error] [pid 504660:tid 504915] [client 158.23.184.117:12890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jdmpruning.com"] [uri "/12.php"] [unique_id "apPk8QgfiZclygrb6nkrTAAAA2k"]
[Sun Aug 30 03:08:17.441619 2026] [authz_core:error] [pid 504660:tid 504887] [client 66.249.66.196:47649] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:17.441896 2026] [authz_core:error] [pid 504660:tid 504887] [client 66.249.66.196:47649] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:17.449355 2026] [security2:error] [pid 504660:tid 504920] [client 20.48.160.90:50659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/wp-content/l.php"] [unique_id "apPk8QgfiZclygrb6nkrUQAAA24"]
[Sun Aug 30 03:08:17.481179 2026] [security2:error] [pid 504660:tid 504931] [client 158.23.184.117:23690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxielectronics.com"] [uri "/cgi-bin/wp-mail.php"] [unique_id "apPk8QgfiZclygrb6nkrWQAAA3k"]
[Sun Aug 30 03:08:17.491791 2026] [security2:error] [pid 504660:tid 504947] [client 4.205.62.107:63967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/tax.php"] [unique_id "apPk8QgfiZclygrb6nkrYwAAA4k"]
[Sun Aug 30 03:08:17.492556 2026] [security2:error] [pid 504660:tid 504859] [client 20.104.50.220:6098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/7.php"] [unique_id "apPk8QgfiZclygrb6nkrZQAAAzE"]
[Sun Aug 30 03:08:17.493709 2026] [authz_core:error] [pid 504660:tid 504897] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AU
[Sun Aug 30 03:08:17.493998 2026] [authz_core:error] [pid 504660:tid 504897] [client 74.7.243.204:37636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AU
[Sun Aug 30 03:08:17.500593 2026] [security2:error] [pid 504660:tid 504910] [client 74.248.24.12:7818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/room.php"] [unique_id "apPk8QgfiZclygrb6nkrZgAAA2Q"]
[Sun Aug 30 03:08:17.500593 2026] [security2:error] [pid 507246:tid 507378] [client 158.23.184.117:27029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/dex.php"] [unique_id "apPk8e8CsCvw81e_I2oxKwAAAps"]
[Sun Aug 30 03:08:17.502449 2026] [security2:error] [pid 507246:tid 507499] [client 213.209.159.223:56147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transitionthemovie.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPk8e8CsCvw81e_I2oxLAAAAxQ"]
[Sun Aug 30 03:08:17.504152 2026] [security2:error] [pid 504660:tid 504891] [client 158.23.147.79:60215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/classwithtostring.php"] [unique_id "apPk8QgfiZclygrb6nkrZwAAA1E"]
[Sun Aug 30 03:08:17.505233 2026] [security2:error] [pid 507246:tid 507392] [client 20.104.50.220:46889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/gmo.php"] [unique_id "apPk8e8CsCvw81e_I2oxLgAAAqk"]
[Sun Aug 30 03:08:17.505501 2026] [security2:error] [pid 504660:tid 504935] [client 158.158.54.35:7503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/min.php"] [unique_id "apPk8QgfiZclygrb6nkraQAAA30"]
[Sun Aug 30 03:08:17.508249 2026] [security2:error] [pid 504660:tid 504845] [client 68.155.159.216:55166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/cong.php"] [unique_id "apPk8QgfiZclygrb6nkragAAAyM"]
[Sun Aug 30 03:08:17.522080 2026] [security2:error] [pid 504660:tid 504961] [client 68.155.159.216:64781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPk8QgfiZclygrb6nkrcgAAA5c"]
[Sun Aug 30 03:08:17.524530 2026] [security2:error] [pid 504660:tid 504944] [client 20.104.18.15:34773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/ws55.php"] [unique_id "apPk8QgfiZclygrb6nkrcwAAA4Y"]
[Sun Aug 30 03:08:17.525041 2026] [security2:error] [pid 504660:tid 504937] [client 20.104.50.220:51570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/dh.php"] [unique_id "apPk8QgfiZclygrb6nkrdQAAA38"]
[Sun Aug 30 03:08:17.533870 2026] [security2:error] [pid 504660:tid 504853] [client 20.104.18.15:18387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/biufile.php"] [unique_id "apPk8QgfiZclygrb6nkrgAAAAys"]
[Sun Aug 30 03:08:17.534520 2026] [security2:error] [pid 504660:tid 504889] [client 20.220.10.235:46957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/sxxb.php"] [unique_id "apPk8QgfiZclygrb6nkrgQAAA08"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:17.535678 2026] [security2:error] [pid 504660:tid 504893] [client 168.119.53.160:35004] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rantica.it"] [uri "/index.html"] [unique_id "apPk8QgfiZclygrb6nkrewAAA1M"], referer: https://rantica.it
[Sun Aug 30 03:08:17.545641 2026] [security2:error] [pid 504660:tid 504900] [client 158.23.184.117:56379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/tinymce/skins/lightgray/img/about.php"] [unique_id "apPk8QgfiZclygrb6nkriAAAA1o"]
[Sun Aug 30 03:08:17.561081 2026] [security2:error] [pid 507246:tid 507419] [client 20.48.250.41:47425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/galer.php"] [unique_id "apPk8e8CsCvw81e_I2oxMwAAAsQ"]
[Sun Aug 30 03:08:17.571554 2026] [security2:error] [pid 504660:tid 504934] [client 52.139.37.240:16674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/ws37.php"] [unique_id "apPk8QgfiZclygrb6nkrnAAAA3w"]
[Sun Aug 30 03:08:17.575665 2026] [security2:error] [pid 504660:tid 504860] [client 20.48.160.90:50588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/wp-admin/w.php"] [unique_id "apPk8QgfiZclygrb6nkrnwAAAzI"]
[Sun Aug 30 03:08:17.577887 2026] [security2:error] [pid 504660:tid 504961] [client 20.104.18.15:35139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/chosen.php"] [unique_id "apPk8QgfiZclygrb6nkrogAAA5c"]
[Sun Aug 30 03:08:17.583673 2026] [security2:error] [pid 504660:tid 504918] [client 20.104.50.220:31848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/decer.php"] [unique_id "apPk8QgfiZclygrb6nkrqQAAA2w"]
[Sun Aug 30 03:08:17.597749 2026] [security2:error] [pid 504660:tid 504915] [client 20.104.50.220:16712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-blog.php"] [unique_id "apPk8QgfiZclygrb6nkrsgAAA2k"]
[Sun Aug 30 03:08:17.620255 2026] [security2:error] [pid 504660:tid 504878] [client 158.23.184.117:12689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jdmpruning.com"] [uri "/colour.php"] [unique_id "apPk8QgfiZclygrb6nkrvQAAA0Q"]
[Sun Aug 30 03:08:17.620976 2026] [security2:error] [pid 504660:tid 504909] [client 158.23.184.117:24438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxielectronics.com"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "apPk8QgfiZclygrb6nkrvgAAA2M"]
[Sun Aug 30 03:08:17.621028 2026] [authz_core:error] [pid 507246:tid 507491] [client 66.249.66.73:44894] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:17.621332 2026] [authz_core:error] [pid 507246:tid 507491] [client 66.249.66.73:44894] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:17.631734 2026] [security2:error] [pid 504660:tid 504850] [client 20.48.250.41:11143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/sbhu.php"] [unique_id "apPk8QgfiZclygrb6nkrxAAAAyg"]
[Sun Aug 30 03:08:17.635056 2026] [security2:error] [pid 504660:tid 504859] [client 20.104.50.220:32935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/plugins.php"] [unique_id "apPk8QgfiZclygrb6nkrxQAAAzE"]
[Sun Aug 30 03:08:17.645733 2026] [security2:error] [pid 504660:tid 504926] [client 20.104.18.15:23406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/x.php"] [unique_id "apPk8QgfiZclygrb6nkrzQAAA3Q"]
[Sun Aug 30 03:08:17.662284 2026] [security2:error] [pid 504660:tid 504894] [client 20.104.18.15:2001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/img.php"] [unique_id "apPk8QgfiZclygrb6nkr1QAAA1Q"]
[Sun Aug 30 03:08:17.662388 2026] [security2:error] [pid 504660:tid 504843] [client 158.23.184.117:27525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/disagrsxr.php"] [unique_id "apPk8QgfiZclygrb6nkr1gAAAyE"]
[Sun Aug 30 03:08:17.663650 2026] [security2:error] [pid 504660:tid 504901] [client 20.196.209.81:13187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/function.php"] [unique_id "apPk8QgfiZclygrb6nkr2AAAA1s"]
[Sun Aug 30 03:08:17.668235 2026] [security2:error] [pid 504660:tid 504928] [client 20.104.49.130:54192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/images.php"] [unique_id "apPk8QgfiZclygrb6nkr3QAAA3Y"]
[Sun Aug 30 03:08:17.670559 2026] [security2:error] [pid 504660:tid 504899] [client 20.220.10.235:46926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/dx.php"] [unique_id "apPk8QgfiZclygrb6nkr4QAAA1k"]
[Sun Aug 30 03:08:17.684117 2026] [security2:error] [pid 507246:tid 507382] [client 20.104.49.130:48627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/bdroot.php"] [unique_id "apPk8e8CsCvw81e_I2oxRQAAAp8"]
[Sun Aug 30 03:08:17.697767 2026] [security2:error] [pid 504660:tid 504923] [client 158.23.184.117:56346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/tinymce/skins/lightgray/img/index.php"] [unique_id "apPk8QgfiZclygrb6nkr7QAAA3E"]
[Sun Aug 30 03:08:17.704892 2026] [security2:error] [pid 504660:tid 504906] [client 20.48.250.41:47460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/baixy.php"] [unique_id "apPk8QgfiZclygrb6nkr9AAAA2A"]
[Sun Aug 30 03:08:17.717177 2026] [security2:error] [pid 504660:tid 504849] [client 158.23.147.79:58388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/install.php"] [unique_id "apPk8QgfiZclygrb6nkr_QAAAyc"]
[Sun Aug 30 03:08:17.719246 2026] [security2:error] [pid 504660:tid 504843] [client 20.104.18.15:29082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/gulu.php"] [unique_id "apPk8QgfiZclygrb6nkr_gAAAyE"]
[Sun Aug 30 03:08:17.723368 2026] [authz_core:error] [pid 507246:tid 507444] [client 216.73.216.128:9123] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:17.723698 2026] [authz_core:error] [pid 507246:tid 507444] [client 216.73.216.128:9123] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:17.742460 2026] [security2:error] [pid 504660:tid 504898] [client 20.48.160.90:50663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/wp-content/k.php"] [unique_id "apPk8QgfiZclygrb6nksDQAAA1g"]
[Sun Aug 30 03:08:17.747795 2026] [security2:error] [pid 507246:tid 507497] [client 20.104.18.15:51640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/wefile.php"] [unique_id "apPk8e8CsCvw81e_I2oxTgAAAxI"]
[Sun Aug 30 03:08:17.761731 2026] [security2:error] [pid 504660:tid 504879] [client 158.23.184.117:23724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luxielectronics.com"] [uri "/chosen.php"] [unique_id "apPk8QgfiZclygrb6nksFQAAA0U"]
[Sun Aug 30 03:08:17.765407 2026] [security2:error] [pid 507246:tid 507391] [client 52.139.37.240:17373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/new.php"] [unique_id "apPk8e8CsCvw81e_I2oxUAAAAqg"]
[Sun Aug 30 03:08:17.767285 2026] [security2:error] [pid 504660:tid 504845] [client 4.205.62.107:25874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/saiga.php"] [unique_id "apPk8QgfiZclygrb6nksGAAAAyM"]
[Sun Aug 30 03:08:17.774114 2026] [security2:error] [pid 504660:tid 504863] [client 158.23.184.117:12695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jdmpruning.com"] [uri "/wp-admin/network/themes.php"] [unique_id "apPk8QgfiZclygrb6nksHQAAAzU"]
[Sun Aug 30 03:08:17.798129 2026] [security2:error] [pid 507246:tid 507427] [client 20.220.10.235:46885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPk8e8CsCvw81e_I2oxWQAAAsw"]
[Sun Aug 30 03:08:17.805765 2026] [security2:error] [pid 504660:tid 504910] [client 158.23.184.117:27528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/domvf.php"] [unique_id "apPk8QgfiZclygrb6nksLwAAA2Q"]
[Sun Aug 30 03:08:17.805880 2026] [security2:error] [pid 507246:tid 507415] [client 4.205.62.107:64653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/brc.php"] [unique_id "apPk8e8CsCvw81e_I2oxXAAAAsA"]
[Sun Aug 30 03:08:17.822682 2026] [security2:error] [pid 504660:tid 504913] [client 20.48.251.3:33322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/phpi.php"] [unique_id "apPk8QgfiZclygrb6nksOAAAA2c"]
[Sun Aug 30 03:08:17.831693 2026] [security2:error] [pid 504660:tid 504957] [client 20.48.250.41:48011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/ava.php"] [unique_id "apPk8QgfiZclygrb6nksPgAAA5M"]
[Sun Aug 30 03:08:17.833396 2026] [authz_core:error] [pid 507246:tid 507389] [client 66.249.66.65:59870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:17.833844 2026] [authz_core:error] [pid 507246:tid 507389] [client 66.249.66.65:59870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:17.845053 2026] [security2:error] [pid 504660:tid 504906] [client 20.151.200.44:47101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/qi.php"] [unique_id "apPk8QgfiZclygrb6nksSwAAA2A"]
[Sun Aug 30 03:08:17.857584 2026] [security2:error] [pid 504660:tid 504880] [client 158.23.184.117:45711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/tinymce/skins/lightgray/img/wp-login.php"] [unique_id "apPk8QgfiZclygrb6nksUgAAA0Y"]
[Sun Aug 30 03:08:17.869864 2026] [security2:error] [pid 507246:tid 507405] [client 20.151.200.44:57881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/t00l.php"] [unique_id "apPk8e8CsCvw81e_I2oxaQAAArY"]
[Sun Aug 30 03:08:17.875801 2026] [security2:error] [pid 504660:tid 504949] [client 20.48.250.41:11229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/a332.php"] [unique_id "apPk8QgfiZclygrb6nksXAAAA4s"]
[Sun Aug 30 03:08:17.883540 2026] [authz_core:error] [pid 504660:tid 504918] [client 66.249.66.199:60473] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:17.883868 2026] [authz_core:error] [pid 504660:tid 504918] [client 66.249.66.199:60473] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:17.905753 2026] [security2:error] [pid 504660:tid 504864] [client 20.48.251.3:59354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/kerang.php"] [unique_id "apPk8QgfiZclygrb6nksfAAAAzY"]
[Sun Aug 30 03:08:17.911367 2026] [security2:error] [pid 507246:tid 507454] [client 20.104.50.220:29126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/Wop.php"] [unique_id "apPk8e8CsCvw81e_I2oxcQAAAuc"]
[Sun Aug 30 03:08:17.914316 2026] [security2:error] [pid 507246:tid 507472] [client 158.23.147.79:60202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-content/x/index.php"] [unique_id "apPk8e8CsCvw81e_I2oxdQAAAvk"]
[Sun Aug 30 03:08:17.916365 2026] [security2:error] [pid 504660:tid 504894] [client 158.23.184.117:12894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jdmpruning.com"] [uri "/wp-admin/post.php"] [unique_id "apPk8QgfiZclygrb6nkshAAAA1Q"]
[Sun Aug 30 03:08:17.919009 2026] [security2:error] [pid 507246:tid 507464] [client 4.205.62.107:35974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/env.php"] [unique_id "apPk8e8CsCvw81e_I2oxeAAAAvE"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:17.932951 2026] [security2:error] [pid 507246:tid 507385] [client 20.48.160.90:50665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/os.php"] [unique_id "apPk8e8CsCvw81e_I2oxgQAAAqI"]
[Sun Aug 30 03:08:17.948669 2026] [security2:error] [pid 504660:tid 504846] [client 158.23.184.117:27025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/donate.php"] [unique_id "apPk8QgfiZclygrb6nkshQAAAyQ"]
[Sun Aug 30 03:08:17.953611 2026] [security2:error] [pid 504660:tid 504941] [client 158.158.54.35:7531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/chosen.php"] [unique_id "apPk8QgfiZclygrb6nkshgAAA4M"]
[Sun Aug 30 03:08:17.954663 2026] [security2:error] [pid 507246:tid 507503] [client 4.205.62.107:54428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/aws_settings.php"] [unique_id "apPk8e8CsCvw81e_I2oxhgAAAxg"]
[Sun Aug 30 03:08:17.956890 2026] [security2:error] [pid 507246:tid 507379] [client 20.220.10.235:46912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/xda.php"] [unique_id "apPk8e8CsCvw81e_I2oxiAAAApw"]
[Sun Aug 30 03:08:17.959329 2026] [security2:error] [pid 507246:tid 507386] [client 20.48.250.41:47479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/gdn.php"] [unique_id "apPk8e8CsCvw81e_I2oxiQAAAqM"]
[Sun Aug 30 03:08:17.998575 2026] [security2:error] [pid 507246:tid 507416] [client 4.205.62.107:18954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/aws_keys.php"] [unique_id "apPk8e8CsCvw81e_I2oxjgAAAsE"]
[Sun Aug 30 03:08:17.998988 2026] [security2:error] [pid 507246:tid 507382] [client 158.23.184.117:56365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/tinymce/skins/wordpress/images/about.php"] [unique_id "apPk8e8CsCvw81e_I2oxjwAAAp8"]
[Sun Aug 30 03:08:18.008321 2026] [security2:error] [pid 504660:tid 504935] [client 20.197.61.180:19026] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "www.indieoffroad.webio7.com"] [uri "/c99.php"] [unique_id "apPk8ggfiZclygrb6nkshwAAA30"]
[Sun Aug 30 03:08:18.018552 2026] [authz_core:error] [pid 507246:tid 507471] [client 66.249.66.68:41726] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:18.018849 2026] [authz_core:error] [pid 507246:tid 507471] [client 66.249.66.68:41726] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:18.024005 2026] [security2:error] [pid 507246:tid 507470] [client 158.23.147.79:16347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apPk8u8CsCvw81e_I2oxkwAAAvc"]
[Sun Aug 30 03:08:18.041366 2026] [security2:error] [pid 507246:tid 507438] [client 52.139.37.240:50116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/il.php"] [unique_id "apPk8u8CsCvw81e_I2oxlwAAAtc"]
[Sun Aug 30 03:08:18.058522 2026] [security2:error] [pid 507246:tid 507492] [client 158.23.184.117:12893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jdmpruning.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPk8u8CsCvw81e_I2oxmAAAAw0"]
[Sun Aug 30 03:08:18.063736 2026] [security2:error] [pid 507246:tid 507457] [client 20.48.250.41:11147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/ws66.php"] [unique_id "apPk8u8CsCvw81e_I2oxmQAAAuo"]
[Sun Aug 30 03:08:18.068928 2026] [security2:error] [pid 507246:tid 507486] [client 20.196.209.81:11362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/about.php"] [unique_id "apPk8u8CsCvw81e_I2oxmwAAAwc"]
[Sun Aug 30 03:08:18.069931 2026] [security2:error] [pid 507246:tid 507446] [client 68.155.159.216:60880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-admin/images/index.php"] [unique_id "apPk8u8CsCvw81e_I2oxnAAAAt8"]
[Sun Aug 30 03:08:18.070271 2026] [security2:error] [pid 507246:tid 507384] [client 20.104.49.130:53589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/100.php"] [unique_id "apPk8u8CsCvw81e_I2oxnQAAAqE"]
[Sun Aug 30 03:08:18.085543 2026] [security2:error] [pid 507246:tid 507452] [client 20.48.160.90:50591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/htio.php"] [unique_id "apPk8u8CsCvw81e_I2oxngAAAuU"]
[Sun Aug 30 03:08:18.087695 2026] [security2:error] [pid 507246:tid 507479] [client 20.48.250.41:48023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/f2.php"] [unique_id "apPk8u8CsCvw81e_I2oxnwAAAwA"]
[Sun Aug 30 03:08:18.088679 2026] [security2:error] [pid 507246:tid 507427] [client 158.23.184.117:27529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/dropdown.php"] [unique_id "apPk8u8CsCvw81e_I2oxoAAAAsw"]
[Sun Aug 30 03:08:18.102747 2026] [security2:error] [pid 507246:tid 507441] [client 20.220.10.235:46859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPk8u8CsCvw81e_I2oxogAAAto"]
[Sun Aug 30 03:08:18.103488 2026] [security2:error] [pid 507246:tid 507411] [client 20.104.50.220:62789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/orange.php"] [unique_id "apPk8u8CsCvw81e_I2oxowAAArw"]
[Sun Aug 30 03:08:18.129088 2026] [security2:error] [pid 504660:tid 504849] [client 74.248.24.12:7836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/disagreed.php"] [unique_id "apPk8ggfiZclygrb6nksiAAAAyc"]
[Sun Aug 30 03:08:18.142547 2026] [security2:error] [pid 507246:tid 507418] [client 158.23.184.117:56321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/tinymce/skins/wordpress/images/index.php"] [unique_id "apPk8u8CsCvw81e_I2oxpQAAAsM"]
[Sun Aug 30 03:08:18.168785 2026] [security2:error] [pid 507246:tid 507405] [client 158.23.147.79:60200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apPk8u8CsCvw81e_I2oxpwAAArY"]
[Sun Aug 30 03:08:18.183112 2026] [security2:error] [pid 507246:tid 507407] [client 213.209.159.223:61665] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "transitionthemovie.com"] [uri "/web/.env"] [unique_id "apPk8u8CsCvw81e_I2oxqAAAArg"]
[Sun Aug 30 03:08:18.215114 2026] [security2:error] [pid 507246:tid 507387] [client 20.48.250.41:48026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/grsiuk.php"] [unique_id "apPk8u8CsCvw81e_I2oxqwAAAqQ"]
[Sun Aug 30 03:08:18.224130 2026] [security2:error] [pid 507246:tid 507388] [client 20.48.160.90:33230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/dev.php"] [unique_id "apPk8u8CsCvw81e_I2oxrgAAAqU"]
[Sun Aug 30 03:08:18.226942 2026] [security2:error] [pid 507246:tid 507463] [client 158.23.184.117:27011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/edit.php"] [unique_id "apPk8u8CsCvw81e_I2oxrwAAAvA"]
[Sun Aug 30 03:08:18.233553 2026] [security2:error] [pid 507246:tid 507502] [client 52.139.37.240:17390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/images/index.php"] [unique_id "apPk8u8CsCvw81e_I2oxsAAAAxc"]
[Sun Aug 30 03:08:18.234999 2026] [security2:error] [pid 507246:tid 507465] [client 20.220.10.235:46867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/t00l.php"] [unique_id "apPk8u8CsCvw81e_I2oxsQAAAvI"]
[Sun Aug 30 03:08:18.243813 2026] [security2:error] [pid 507246:tid 507472] [client 20.151.200.44:59456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/ls.php"] [unique_id "apPk8u8CsCvw81e_I2oxsgAAAvk"]
[Sun Aug 30 03:08:18.251833 2026] [security2:error] [pid 507246:tid 507475] [client 158.23.184.117:12879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jdmpruning.com"] [uri "/wp-content/post.php"] [unique_id "apPk8u8CsCvw81e_I2oxswAAAvw"]
[Sun Aug 30 03:08:18.285860 2026] [security2:error] [pid 507246:tid 507392] [client 158.23.184.117:51799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/tinymce/utils/license.php"] [unique_id "apPk8u8CsCvw81e_I2oxtQAAAqk"]
[Sun Aug 30 03:08:18.317037 2026] [security2:error] [pid 507246:tid 507433] [client 213.209.159.223:61665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transitionthemovie.com"] [uri "/phpinfo.php3"] [unique_id "apPk8u8CsCvw81e_I2oxtgAAAtI"]
[Sun Aug 30 03:08:18.318310 2026] [security2:error] [pid 507246:tid 507483] [client 20.48.250.41:11258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/ws68.php"] [unique_id "apPk8u8CsCvw81e_I2oxtwAAAwQ"]
[Sun Aug 30 03:08:18.321575 2026] [security2:error] [pid 507246:tid 507456] [client 158.23.147.79:58383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-login.php"] [unique_id "apPk8u8CsCvw81e_I2oxuAAAAuk"]
[Sun Aug 30 03:08:18.326895 2026] [security2:error] [pid 507246:tid 507460] [client 20.48.251.3:44141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/environment.php"] [unique_id "apPk8u8CsCvw81e_I2oxugAAAu0"]
[Sun Aug 30 03:08:18.342096 2026] [security2:error] [pid 507246:tid 507385] [client 20.48.250.41:48066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/wp-scr1pts.php"] [unique_id "apPk8u8CsCvw81e_I2oxuwAAAqI"]
[Sun Aug 30 03:08:18.364158 2026] [security2:error] [pid 507246:tid 507434] [client 20.220.10.235:46932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/ls.php"] [unique_id "apPk8u8CsCvw81e_I2oxvAAAAtM"]
[Sun Aug 30 03:08:18.367972 2026] [security2:error] [pid 507246:tid 507449] [client 158.23.184.117:27065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.utensiltecnica.it"] [uri "/ee.php"] [unique_id "apPk8u8CsCvw81e_I2oxvgAAAuI"]
[Sun Aug 30 03:08:18.383684 2026] [security2:error] [pid 507246:tid 507481] [client 20.48.251.3:4702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/server_info.php"] [unique_id "apPk8u8CsCvw81e_I2oxvwAAAwI"]
[Sun Aug 30 03:08:18.419050 2026] [security2:error] [pid 507246:tid 507404] [client 158.158.54.35:6172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/vx.php"] [unique_id "apPk8u8CsCvw81e_I2oxxAAAArU"]
[Sun Aug 30 03:08:18.426073 2026] [security2:error] [pid 507246:tid 507478] [client 52.139.37.240:16678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/lite.php"] [unique_id "apPk8u8CsCvw81e_I2oxxgAAAv8"]
[Sun Aug 30 03:08:18.428107 2026] [security2:error] [pid 507246:tid 507503] [client 158.23.184.117:51836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wholebeingportland.com"] [uri "/tinymce/wp-tinymce.php"] [unique_id "apPk8u8CsCvw81e_I2oxyAAAAxg"]
[Sun Aug 30 03:08:18.447957 2026] [security2:error] [pid 507246:tid 507393] [client 158.23.184.117:12887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.jdmpruning.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "apPk8u8CsCvw81e_I2oxyQAAAqo"]
[Sun Aug 30 03:08:18.461465 2026] [security2:error] [pid 507246:tid 507439] [client 158.23.147.79:16357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apPk8u8CsCvw81e_I2oxygAAAtg"]
[Sun Aug 30 03:08:18.470175 2026] [security2:error] [pid 507246:tid 507453] [client 20.104.50.220:61656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/foxwsov1.php"] [unique_id "apPk8u8CsCvw81e_I2oxzAAAAuY"]
[Sun Aug 30 03:08:18.477618 2026] [security2:error] [pid 507246:tid 507492] [client 20.104.49.130:64087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/k.php"] [unique_id "apPk8u8CsCvw81e_I2oxzgAAAw0"]
[Sun Aug 30 03:08:18.487808 2026] [security2:error] [pid 507246:tid 507457] [client 20.48.250.41:11171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/users.php"] [unique_id "apPk8u8CsCvw81e_I2oxzwAAAuo"]
[Sun Aug 30 03:08:18.490191 2026] [security2:error] [pid 504660:tid 504692] [remote 34.14.60.202:33600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.60.14.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "maarifado.com"] [uri "/wp-login.php"] [unique_id "apPk8ggfiZclygrb6nksiwADSB4"]
[Sun Aug 30 03:08:18.497064 2026] [security2:error] [pid 507246:tid 507441] [client 20.48.250.41:47960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/num.php"] [unique_id "apPk8u8CsCvw81e_I2ox0gAAAto"]
[Sun Aug 30 03:08:18.497608 2026] [security2:error] [pid 507246:tid 507442] [client 20.220.10.235:46975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/css/000.php"] [unique_id "apPk8u8CsCvw81e_I2ox0wAAAts"]
[Sun Aug 30 03:08:18.534852 2026] [security2:error] [pid 507246:tid 507445] [client 20.196.209.81:12689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/new.php"] [unique_id "apPk8u8CsCvw81e_I2ox1AAAAt4"]
[Sun Aug 30 03:08:18.595622 2026] [authz_core:error] [pid 507246:tid 507378] [client 216.73.216.128:31509] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:18.596093 2026] [authz_core:error] [pid 507246:tid 507378] [client 216.73.216.128:31509] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:18.611985 2026] [authz_core:error] [pid 507246:tid 507476] [client 66.249.66.68:50554] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:18.612414 2026] [authz_core:error] [pid 507246:tid 507476] [client 66.249.66.68:50554] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:18.620433 2026] [security2:error] [pid 507246:tid 507490] [client 52.139.37.240:16644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/xda.php"] [unique_id "apPk8u8CsCvw81e_I2ox5wAAAws"]
[Sun Aug 30 03:08:18.620746 2026] [security2:error] [pid 507246:tid 507447] [client 158.23.147.79:58387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-admin/images/about.php"] [unique_id "apPk8u8CsCvw81e_I2ox6gAAAuA"]
[Sun Aug 30 03:08:18.621066 2026] [security2:error] [pid 507246:tid 507501] [client 4.205.62.107:62107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPk8u8CsCvw81e_I2ox6QAAAxY"]
[Sun Aug 30 03:08:18.631638 2026] [security2:error] [pid 507246:tid 507433] [client 20.104.50.220:5521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/6.php"] [unique_id "apPk8u8CsCvw81e_I2ox7gAAAtI"]
[Sun Aug 30 03:08:18.634548 2026] [security2:error] [pid 507246:tid 507483] [client 20.220.10.235:46930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/cy.php"] [unique_id "apPk8u8CsCvw81e_I2ox8AAAAwQ"]
[Sun Aug 30 03:08:18.635893 2026] [security2:error] [pid 507246:tid 507456] [client 68.155.159.216:65465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/log-mama/function.php"] [unique_id "apPk8u8CsCvw81e_I2ox8QAAAuk"]
[Sun Aug 30 03:08:18.643711 2026] [security2:error] [pid 507246:tid 507434] [client 20.104.50.220:46617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/info.php"] [unique_id "apPk8u8CsCvw81e_I2ox8wAAAtM"]
[Sun Aug 30 03:08:18.651170 2026] [authz_core:error] [pid 507246:tid 507440] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:18.651472 2026] [authz_core:error] [pid 507246:tid 507440] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:18.653890 2026] [security2:error] [pid 507246:tid 507449] [client 68.155.159.216:46045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPk8u8CsCvw81e_I2ox9QAAAuI"]
[Sun Aug 30 03:08:18.656854 2026] [security2:error] [pid 507246:tid 507500] [client 20.48.250.41:48067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/a4.php"] [unique_id "apPk8u8CsCvw81e_I2ox9wAAAxU"]
[Sun Aug 30 03:08:18.660278 2026] [security2:error] [pid 507246:tid 507420] [client 20.48.250.41:11150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/bzjdlofz.php"] [unique_id "apPk8u8CsCvw81e_I2ox-AAAAsU"]
[Sun Aug 30 03:08:18.662928 2026] [security2:error] [pid 507246:tid 507481] [client 20.104.50.220:42005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/%E5%B9%B3%E4%BB%AE%E5%90%8Ds.php"] [unique_id "apPk8u8CsCvw81e_I2ox-QAAAwI"]
[Sun Aug 30 03:08:18.669960 2026] [security2:error] [pid 507246:tid 507416] [client 20.104.18.15:34707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/drykl.php"] [unique_id "apPk8u8CsCvw81e_I2ox_AAAAsE"]
[Sun Aug 30 03:08:18.672356 2026] [security2:error] [pid 507246:tid 507478] [client 20.104.18.15:18191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/blacks.php"] [unique_id "apPk8u8CsCvw81e_I2ox_QAAAv8"]
[Sun Aug 30 03:08:18.707623 2026] [authz_core:error] [pid 507246:tid 507384] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AG
[Sun Aug 30 03:08:18.708062 2026] [authz_core:error] [pid 507246:tid 507384] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AG
[Sun Aug 30 03:08:18.708894 2026] [authz_core:error] [pid 507246:tid 507390] [client 66.249.66.75:40481] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:18.709322 2026] [authz_core:error] [pid 507246:tid 507390] [client 66.249.66.75:40481] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:18.716973 2026] [security2:error] [pid 507246:tid 507491] [client 20.104.50.220:32307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/auto_seo.php"] [unique_id "apPk8u8CsCvw81e_I2oyDAAAAww"]
[Sun Aug 30 03:08:18.717483 2026] [security2:error] [pid 507246:tid 507484] [client 20.104.18.15:35153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/file1221.php"] [unique_id "apPk8u8CsCvw81e_I2oyDgAAAwU"]
[Sun Aug 30 03:08:18.727731 2026] [security2:error] [pid 507246:tid 507383] [client 68.155.159.216:62273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/log-mama/function.php"] [unique_id "apPk8u8CsCvw81e_I2oyEAAAAqA"]
[Sun Aug 30 03:08:18.730202 2026] [security2:error] [pid 507246:tid 507423] [client 68.155.159.216:54229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-includes/js/index.php"] [unique_id "apPk8u8CsCvw81e_I2oyEQAAAsg"]
[Sun Aug 30 03:08:18.752190 2026] [security2:error] [pid 507246:tid 507411] [client 20.197.61.180:8825] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "www.indieoffroad.webio7.com"] [uri "/c99.php"] [unique_id "apPk8u8CsCvw81e_I2oyGAAAArw"]
[Sun Aug 30 03:08:18.755170 2026] [security2:error] [pid 507246:tid 507464] [client 20.48.160.90:33163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/gos.php"] [unique_id "apPk8u8CsCvw81e_I2oyGQAAAvE"]
[Sun Aug 30 03:08:18.778288 2026] [security2:error] [pid 507246:tid 507381] [client 20.220.10.235:46951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/admin.php/pindex.php"] [unique_id "apPk8u8CsCvw81e_I2oyHgAAAp4"]
[Sun Aug 30 03:08:18.788675 2026] [security2:error] [pid 507246:tid 507410] [client 20.104.50.220:33167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-content/priv8.php"] [unique_id "apPk8u8CsCvw81e_I2oyHwAAArs"]
[Sun Aug 30 03:08:18.790864 2026] [security2:error] [pid 507246:tid 507403] [client 158.23.147.79:60175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPk8u8CsCvw81e_I2oyIQAAArQ"]
[Sun Aug 30 03:08:18.793735 2026] [security2:error] [pid 507246:tid 507436] [client 20.104.18.15:2009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/222.php"] [unique_id "apPk8u8CsCvw81e_I2oyIgAAAtU"]
[Sun Aug 30 03:08:18.794551 2026] [security2:error] [pid 507246:tid 507428] [client 20.104.18.15:23383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/ssla.php"] [unique_id "apPk8u8CsCvw81e_I2oyIwAAAs0"]
[Sun Aug 30 03:08:18.795035 2026] [security2:error] [pid 507246:tid 507483] [client 20.48.250.41:11217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/selesai.php"] [unique_id "apPk8u8CsCvw81e_I2oyJAAAAwQ"]
[Sun Aug 30 03:08:18.802525 2026] [security2:error] [pid 507246:tid 507406] [client 20.104.50.220:16693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-content/admin.php"] [unique_id "apPk8u8CsCvw81e_I2oyJwAAArc"]
[Sun Aug 30 03:08:18.811913 2026] [security2:error] [pid 507246:tid 507455] [client 20.48.250.41:47455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/tfm.php"] [unique_id "apPk8u8CsCvw81e_I2oyKgAAAug"]
[Sun Aug 30 03:08:18.818544 2026] [security2:error] [pid 507246:tid 507397] [client 52.139.37.240:16657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/.trash7206/index.php"] [unique_id "apPk8u8CsCvw81e_I2oyKwAAAq4"]
[Sun Aug 30 03:08:18.895145 2026] [security2:error] [pid 507246:tid 507430] [client 20.104.18.15:52162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/wp-load.php"] [unique_id "apPk8u8CsCvw81e_I2oyQgAAAs8"]
[Sun Aug 30 03:08:18.906748 2026] [security2:error] [pid 507246:tid 507400] [client 158.23.147.79:16356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-admin.php"] [unique_id "apPk8u8CsCvw81e_I2oyRAAAArE"]
[Sun Aug 30 03:08:18.910079 2026] [security2:error] [pid 507246:tid 507473] [client 20.104.18.15:29149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/replace.php"] [unique_id "apPk8u8CsCvw81e_I2oyRQAAAvo"]
[Sun Aug 30 03:08:18.932603 2026] [security2:error] [pid 507246:tid 507426] [client 4.205.62.107:25870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/ammika.php"] [unique_id "apPk8u8CsCvw81e_I2oySwAAAss"]
[Sun Aug 30 03:08:18.938983 2026] [security2:error] [pid 507246:tid 507495] [client 20.220.10.235:46949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/admin.php/csv.php"] [unique_id "apPk8u8CsCvw81e_I2oyTAAAAxA"]
[Sun Aug 30 03:08:18.941546 2026] [security2:error] [pid 507246:tid 507407] [client 20.48.160.90:50649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/132.php"] [unique_id "apPk8u8CsCvw81e_I2oyTwAAArg"]
[Sun Aug 30 03:08:18.957671 2026] [security2:error] [pid 507246:tid 507425] [client 20.48.251.3:13386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/wp-admin/css/bolt.php"] [unique_id "apPk8u8CsCvw81e_I2oyUwAAAso"]
[Sun Aug 30 03:08:18.980044 2026] [security2:error] [pid 507246:tid 507436] [client 4.205.62.107:61821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/vx.php"] [unique_id "apPk8u8CsCvw81e_I2oyVQAAAtU"]
[Sun Aug 30 03:08:18.984148 2026] [security2:error] [pid 507246:tid 507483] [client 20.48.250.41:48121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/Geforce.php"] [unique_id "apPk8u8CsCvw81e_I2oyVgAAAwQ"]
[Sun Aug 30 03:08:19.030070 2026] [security2:error] [pid 507246:tid 507419] [client 20.48.250.41:11225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/shlo.php"] [unique_id "apPk8-8CsCvw81e_I2oyXAAAAsQ"]
[Sun Aug 30 03:08:19.048201 2026] [security2:error] [pid 507246:tid 507428] [client 52.139.37.240:16667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/storage/index.php"] [unique_id "apPk8-8CsCvw81e_I2oyXgAAAs0"]
[Sun Aug 30 03:08:19.049734 2026] [security2:error] [pid 507246:tid 507431] [client 74.248.24.12:7824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/text.php"] [unique_id "apPk8-8CsCvw81e_I2oyXwAAAtA"]
[Sun Aug 30 03:08:19.051988 2026] [security2:error] [pid 507246:tid 507439] [client 158.23.147.79:58376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apPk8-8CsCvw81e_I2oyYgAAAtg"]
[Sun Aug 30 03:08:19.056051 2026] [security2:error] [pid 507246:tid 507503] [client 4.205.62.107:36025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/xve22.php"] [unique_id "apPk8-8CsCvw81e_I2oyZAAAAxg"]
[Sun Aug 30 03:08:19.057024 2026] [security2:error] [pid 507246:tid 507492] [client 20.104.49.130:52505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/static.php"] [unique_id "apPk8-8CsCvw81e_I2oyZQAAAw0"]
[Sun Aug 30 03:08:19.070060 2026] [security2:error] [pid 507246:tid 507386] [client 20.220.10.235:46851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/admin.php/700.php"] [unique_id "apPk8-8CsCvw81e_I2oyZgAAAqM"]
[Sun Aug 30 03:08:19.071522 2026] [security2:error] [pid 507246:tid 507442] [client 20.104.50.220:52857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/pah.php"] [unique_id "apPk8-8CsCvw81e_I2oyaAAAAts"]
[Sun Aug 30 03:08:19.077907 2026] [security2:error] [pid 507246:tid 507424] [client 20.48.251.3:55746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/rem.php"] [unique_id "apPk8-8CsCvw81e_I2oyaQAAAsk"]
[Sun Aug 30 03:08:19.081706 2026] [security2:error] [pid 507246:tid 507304] [remote 51.89.83.144:54202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.83.89.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familycruisesguide.dirkhoag.com"] [uri "/assets/images/accesson.php"] [unique_id "apPk8-8CsCvw81e_I2oyawACoDk"]
[Sun Aug 30 03:08:19.091593 2026] [security2:error] [pid 507246:tid 507497] [client 20.48.160.90:33222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/v22.php"] [unique_id "apPk8-8CsCvw81e_I2oybQAAAxI"]
[Sun Aug 30 03:08:19.095141 2026] [security2:error] [pid 507246:tid 507381] [client 20.196.209.81:10085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/goods.php"] [unique_id "apPk8-8CsCvw81e_I2oybwAAAp4"]
[Sun Aug 30 03:08:19.098729 2026] [security2:error] [pid 507246:tid 507491] [client 20.151.200.44:59508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/css/000.php"] [unique_id "apPk8-8CsCvw81e_I2oycAAAAww"]
[Sun Aug 30 03:08:19.102048 2026] [security2:error] [pid 507246:tid 507422] [client 20.104.49.130:52145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/media.php"] [unique_id "apPk8-8CsCvw81e_I2oycQAAAsc"]
[Sun Aug 30 03:08:19.104957 2026] [security2:error] [pid 507246:tid 507441] [client 4.205.62.107:54458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/wp-konfig.backup.php"] [unique_id "apPk8-8CsCvw81e_I2oycgAAAto"]
[Sun Aug 30 03:08:19.120053 2026] [security2:error] [pid 507246:tid 507444] [client 20.48.250.41:48044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/click.php"] [unique_id "apPk8-8CsCvw81e_I2oydQAAAt0"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:19.134639 2026] [security2:error] [pid 507246:tid 507476] [client 4.205.62.107:18771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/umgebung.php"] [unique_id "apPk8-8CsCvw81e_I2oydwAAAv0"]
[Sun Aug 30 03:08:19.139104 2026] [security2:error] [pid 507246:tid 507438] [client 37.220.132.13:55600] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "lorenzosnowcones.com"] [uri "/.env.example"] [unique_id "apPk8-8CsCvw81e_I2oyegAAAtc"]
[Sun Aug 30 03:08:19.177302 2026] [security2:error] [pid 507246:tid 507401] [client 158.23.147.79:16327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/lock.php"] [unique_id "apPk8-8CsCvw81e_I2oyfAAAArI"]
[Sun Aug 30 03:08:19.202512 2026] [security2:error] [pid 507246:tid 507490] [client 20.220.10.235:46923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/admin.php/007x.php"] [unique_id "apPk8-8CsCvw81e_I2oygAAAAws"]
[Sun Aug 30 03:08:19.241243 2026] [security2:error] [pid 507246:tid 507465] [client 52.139.37.240:16651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPk8-8CsCvw81e_I2oyhgAAAvI"]
[Sun Aug 30 03:08:19.247505 2026] [security2:error] [pid 507246:tid 507488] [client 34.125.55.247:3064] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "apPk8-8CsCvw81e_I2oydgAAAwk"]
[Sun Aug 30 03:08:19.279000 2026] [authz_core:error] [pid 507246:tid 507419] [client 66.249.66.75:55749] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:19.279324 2026] [authz_core:error] [pid 507246:tid 507419] [client 66.249.66.75:55749] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:19.286977 2026] [security2:error] [pid 507246:tid 507428] [client 20.48.160.90:50573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/wp-activate.php"] [unique_id "apPk8-8CsCvw81e_I2oykgAAAs0"]
[Sun Aug 30 03:08:19.289463 2026] [security2:error] [pid 507246:tid 507431] [client 20.48.250.41:48003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/ms.php"] [unique_id "apPk8-8CsCvw81e_I2oykwAAAtA"]
[Sun Aug 30 03:08:19.323088 2026] [security2:error] [pid 507246:tid 507502] [client 158.23.147.79:60189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/index/function.php"] [unique_id "apPk8-8CsCvw81e_I2oylAAAAxc"]
[Sun Aug 30 03:08:19.333913 2026] [authz_core:error] [pid 507246:tid 507404] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AG
[Sun Aug 30 03:08:19.334184 2026] [authz_core:error] [pid 507246:tid 507404] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AG
[Sun Aug 30 03:08:19.336354 2026] [security2:error] [pid 507246:tid 507424] [client 20.220.10.235:46889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/admin.php/heex.php"] [unique_id "apPk8-8CsCvw81e_I2oylgAAAsk"]
[Sun Aug 30 03:08:19.339260 2026] [security2:error] [pid 507246:tid 507383] [client 20.48.250.41:11186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/asax.php"] [unique_id "apPk8-8CsCvw81e_I2oylwAAAqA"]
[Sun Aug 30 03:08:19.352631 2026] [security2:error] [pid 507246:tid 507497] [client 20.104.50.220:28684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/hcd01.php"] [unique_id "apPk8-8CsCvw81e_I2oymAAAAxI"]
[Sun Aug 30 03:08:19.363723 2026] [proxy_http:error] [pid 507246:tid 507380] (20014)Internal error (specific information not available): [client 34.125.55.247:3064] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:19.430696 2026] [security2:error] [pid 507246:tid 507458] [client 20.48.250.41:48084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/zxekqlxb.php"] [unique_id "apPk8-8CsCvw81e_I2oyoAAAAus"]
[Sun Aug 30 03:08:19.439481 2026] [authz_core:error] [pid 507246:tid 507458] [client 66.249.66.75:40481] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:19.439778 2026] [authz_core:error] [pid 507246:tid 507458] [client 66.249.66.75:40481] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:19.443935 2026] [authz_core:error] [pid 507246:tid 507400] [client 66.249.66.77:56450] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:19.444286 2026] [authz_core:error] [pid 507246:tid 507400] [client 66.249.66.77:56450] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:19.445629 2026] [security2:error] [pid 507246:tid 507422] [client 52.139.37.240:16673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/wp-blog.php"] [unique_id "apPk8-8CsCvw81e_I2oyowAAAsc"]
[Sun Aug 30 03:08:19.449397 2026] [security2:error] [pid 507246:tid 507423] [client 158.23.147.79:60167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/.well-known/content.php"] [unique_id "apPk8-8CsCvw81e_I2oypQAAAsg"]
[Sun Aug 30 03:08:19.462193 2026] [security2:error] [pid 507246:tid 507417] [client 20.48.160.90:19916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/wp-trackback.php"] [unique_id "apPk8-8CsCvw81e_I2oypgAAAsI"]
[Sun Aug 30 03:08:19.467344 2026] [security2:error] [pid 507246:tid 507445] [client 20.220.10.235:46960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/tf.php"] [unique_id "apPk8-8CsCvw81e_I2oypwAAAt4"]
[Sun Aug 30 03:08:19.478241 2026] [security2:error] [pid 507246:tid 507421] [client 20.48.251.3:7046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/aws_secret_config.php"] [unique_id "apPk8-8CsCvw81e_I2oyqgAAAsY"]
[Sun Aug 30 03:08:19.499856 2026] [security2:error] [pid 507246:tid 507481] [client 20.151.200.44:59464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/cy.php"] [unique_id "apPk8-8CsCvw81e_I2oysAAAAwI"]
[Sun Aug 30 03:08:19.499926 2026] [security2:error] [pid 507246:tid 507446] [client 20.196.209.81:11333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/m.php"] [unique_id "apPk8-8CsCvw81e_I2oysQAAAt8"]
[Sun Aug 30 03:08:19.507511 2026] [security2:error] [pid 507246:tid 507385] [client 68.155.159.216:53446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-includes/index.php"] [unique_id "apPk8-8CsCvw81e_I2oysgAAAqI"]
[Sun Aug 30 03:08:19.527103 2026] [security2:error] [pid 507246:tid 507451] [client 20.48.250.41:11105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/fetch.php"] [unique_id "apPk8-8CsCvw81e_I2oytQAAAuQ"]
[Sun Aug 30 03:08:19.531709 2026] [security2:error] [pid 507246:tid 507483] [client 158.158.54.35:22387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/wap.php"] [unique_id "apPk8-8CsCvw81e_I2oytwAAAwQ"]
[Sun Aug 30 03:08:19.531789 2026] [authz_core:error] [pid 507246:tid 507501] [client 66.249.66.198:45771] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:19.532249 2026] [authz_core:error] [pid 507246:tid 507501] [client 66.249.66.198:45771] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:19.556252 2026] [security2:error] [pid 507246:tid 507429] [client 20.197.61.180:10459] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "www.indieoffroad.webio7.com"] [uri "/c99.php"] [unique_id "apPk8-8CsCvw81e_I2oyvAAAAs4"]
[Sun Aug 30 03:08:19.563870 2026] [security2:error] [pid 507246:tid 507435] [client 20.48.250.41:47485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/init.php"] [unique_id "apPk8-8CsCvw81e_I2oyvgAAAtQ"]
[Sun Aug 30 03:08:19.578688 2026] [authz_core:error] [pid 507246:tid 507379] [client 66.249.66.198:41839] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:19.578952 2026] [authz_core:error] [pid 507246:tid 507379] [client 66.249.66.198:41839] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:19.579887 2026] [security2:error] [pid 507246:tid 507414] [client 20.48.251.3:5059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/hosty.php"] [unique_id "apPk8-8CsCvw81e_I2oywgAAAr8"]
[Sun Aug 30 03:08:19.607944 2026] [security2:error] [pid 507246:tid 507492] [client 20.220.10.235:46870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/update/da222.php"] [unique_id "apPk8-8CsCvw81e_I2oyxwAAAw0"]
[Sun Aug 30 03:08:19.615087 2026] [authz_core:error] [pid 507246:tid 507485] [client 66.249.66.72:35010] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:19.615444 2026] [authz_core:error] [pid 507246:tid 507485] [client 66.249.66.72:35010] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:19.640224 2026] [security2:error] [pid 507246:tid 507431] [client 52.139.37.240:16682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/xmlrpc.php"] [unique_id "apPk8-8CsCvw81e_I2oy0QAAAtA"]
[Sun Aug 30 03:08:19.650342 2026] [security2:error] [pid 507246:tid 507416] [client 20.48.160.90:50578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/pri.php"] [unique_id "apPk8-8CsCvw81e_I2oy1AAAAsE"]
[Sun Aug 30 03:08:19.682673 2026] [security2:error] [pid 507246:tid 507421] [client 158.23.147.79:58378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/cong.php"] [unique_id "apPk8-8CsCvw81e_I2oy2gAAAsY"]
[Sun Aug 30 03:08:19.695130 2026] [security2:error] [pid 507246:tid 507418] [client 20.48.250.41:48041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/term.php"] [unique_id "apPk8-8CsCvw81e_I2oy3AAAAsM"]
[Sun Aug 30 03:08:19.695181 2026] [security2:error] [pid 507246:tid 507464] [client 20.104.50.220:61653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/FoxWSOv2.php"] [unique_id "apPk8-8CsCvw81e_I2oy2wAAAvE"]
[Sun Aug 30 03:08:19.708243 2026] [security2:error] [pid 507246:tid 507382] [client 20.104.49.130:53601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/load.php"] [unique_id "apPk8-8CsCvw81e_I2oy3wAAAp8"]
[Sun Aug 30 03:08:19.732144 2026] [security2:error] [pid 507246:tid 507397] [client 20.48.250.41:11244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/vx.php"] [unique_id "apPk8-8CsCvw81e_I2oy4gAAAq4"]
[Sun Aug 30 03:08:19.747329 2026] [security2:error] [pid 507246:tid 507483] [client 20.220.10.235:46856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/qi.php"] [unique_id "apPk8-8CsCvw81e_I2oy4wAAAwQ"]
[Sun Aug 30 03:08:19.749239 2026] [security2:error] [pid 507246:tid 507390] [client 74.248.24.12:14830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/alfa-rex.php"] [unique_id "apPk8-8CsCvw81e_I2oy5AAAAqc"]
[Sun Aug 30 03:08:19.753434 2026] [security2:error] [pid 507246:tid 507392] [client 34.74.242.206:1585] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.happynerdcompany.com"] [uri "/robots.txt"] [unique_id "apPk8-8CsCvw81e_I2oy5QAAAqk"]
[Sun Aug 30 03:08:19.753518 2026] [security2:error] [pid 507246:tid 507392] [client 34.74.242.206:1585] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.happynerdcompany.com"] [uri "/robots.txt"] [unique_id "apPk8-8CsCvw81e_I2oy5QAAAqk"]
[Sun Aug 30 03:08:19.770199 2026] [security2:error] [pid 507246:tid 507394] [client 20.104.50.220:5509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/5.php"] [unique_id "apPk8-8CsCvw81e_I2oy6wAAAqs"]
[Sun Aug 30 03:08:19.771995 2026] [security2:error] [pid 507246:tid 507429] [client 20.151.200.44:59573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/admin.php/pindex.php"] [unique_id "apPk8-8CsCvw81e_I2oy7AAAAs4"]
[Sun Aug 30 03:08:19.774813 2026] [security2:error] [pid 507246:tid 507475] [client 4.205.62.107:64061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPk8-8CsCvw81e_I2oy7QAAAvw"]
[Sun Aug 30 03:08:19.786210 2026] [security2:error] [pid 507246:tid 507493] [client 68.155.159.216:61360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/bk/index.php"] [unique_id "apPk8-8CsCvw81e_I2oy8AAAAw4"]
[Sun Aug 30 03:08:19.787769 2026] [security2:error] [pid 507246:tid 507492] [client 20.48.160.90:19935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/wp_blog_footer.php"] [unique_id "apPk8-8CsCvw81e_I2oy8QAAAw0"]
[Sun Aug 30 03:08:19.800157 2026] [security2:error] [pid 507246:tid 507434] [client 20.104.50.220:42762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-includes/rest-api/fields/anbu.php"] [unique_id "apPk8-8CsCvw81e_I2oy9AAAAtM"]
[Sun Aug 30 03:08:19.808294 2026] [security2:error] [pid 507246:tid 507470] [client 20.104.18.15:34788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/backup.php"] [unique_id "apPk8-8CsCvw81e_I2oy9wAAAvc"]
[Sun Aug 30 03:08:19.813884 2026] [security2:error] [pid 507246:tid 507477] [client 20.104.50.220:46197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/file2.php"] [unique_id "apPk8-8CsCvw81e_I2oy-AAAAv4"]
[Sun Aug 30 03:08:19.814918 2026] [security2:error] [pid 507246:tid 507409] [client 20.104.18.15:18383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/beck.php"] [unique_id "apPk8-8CsCvw81e_I2oy-gAAAro"]
[Sun Aug 30 03:08:19.833260 2026] [security2:error] [pid 507246:tid 507500] [client 52.139.37.240:16671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/lu4.php"] [unique_id "apPk8-8CsCvw81e_I2oy-wAAAxU"]
[Sun Aug 30 03:08:19.841435 2026] [security2:error] [pid 507246:tid 507380] [client 20.48.250.41:47442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/aaa.php"] [unique_id "apPk8-8CsCvw81e_I2ozAAAAAp0"]
[Sun Aug 30 03:08:19.854606 2026] [security2:error] [pid 507246:tid 507444] [client 34.74.242.206:1569] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.happynerdcompany.com"] [uri "/"] [unique_id "apPk8-8CsCvw81e_I2ozBAAAAt0"]
[Sun Aug 30 03:08:19.854739 2026] [security2:error] [pid 507246:tid 507444] [client 34.74.242.206:1569] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.happynerdcompany.com"] [uri "/"] [unique_id "apPk8-8CsCvw81e_I2ozBAAAAt0"]
[Sun Aug 30 03:08:19.859704 2026] [security2:error] [pid 507246:tid 507499] [client 158.23.147.79:58401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-includes/js/index.php"] [unique_id "apPk8-8CsCvw81e_I2ozBgAAAxQ"]
[Sun Aug 30 03:08:19.866785 2026] [security2:error] [pid 507246:tid 507418] [client 20.104.18.15:35495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/nox.php"] [unique_id "apPk8-8CsCvw81e_I2ozCQAAAsM"]
[Sun Aug 30 03:08:19.882438 2026] [security2:error] [pid 507246:tid 507466] [client 20.220.10.235:46853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/px.php"] [unique_id "apPk8-8CsCvw81e_I2ozCwAAAvM"]
[Sun Aug 30 03:08:19.896641 2026] [security2:error] [pid 507246:tid 507451] [client 20.104.50.220:31812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/alone.php"] [unique_id "apPk8-8CsCvw81e_I2ozDQAAAuQ"]
[Sun Aug 30 03:08:19.900758 2026] [security2:error] [pid 507246:tid 507377] [client 68.155.159.216:46068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/makeasmtp.php"] [unique_id "apPk8-8CsCvw81e_I2ozDgAAApo"]
[Sun Aug 30 03:08:19.903212 2026] [security2:error] [pid 507246:tid 507390] [client 216.73.216.128:53242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPk8-8CsCvw81e_I2ozDwAAAqc"]
[Sun Aug 30 03:08:19.908706 2026] [security2:error] [pid 507246:tid 507474] [client 34.100.204.203:59118] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "bitcoinforum.it"] [uri "/"] [unique_id "apPk8-8CsCvw81e_I2ozEgAAAvs"]
[Sun Aug 30 03:08:19.925733 2026] [security2:error] [pid 507246:tid 507402] [client 20.104.50.220:33590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-admin/priv8.php"] [unique_id "apPk8-8CsCvw81e_I2ozFgAAArM"]
[Sun Aug 30 03:08:19.930393 2026] [security2:error] [pid 507246:tid 507489] [client 20.196.209.81:11342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/doc.php"] [unique_id "apPk8-8CsCvw81e_I2ozGQAAAwo"]
[Sun Aug 30 03:08:19.933593 2026] [security2:error] [pid 507246:tid 507435] [client 20.48.250.41:11240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/global.php"] [unique_id "apPk8-8CsCvw81e_I2ozGwAAAtQ"]
[Sun Aug 30 03:08:19.939557 2026] [authz_core:error] [pid 507246:tid 507420] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_DK
[Sun Aug 30 03:08:19.940025 2026] [authz_core:error] [pid 507246:tid 507420] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_DK
[Sun Aug 30 03:08:19.944013 2026] [security2:error] [pid 507246:tid 507395] [client 20.104.50.220:17261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/adminfuns.php"] [unique_id "apPk8-8CsCvw81e_I2ozHgAAAqw"]
[Sun Aug 30 03:08:19.945932 2026] [security2:error] [pid 507246:tid 507447] [client 20.104.18.15:2023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/key.php"] [unique_id "apPk8-8CsCvw81e_I2ozHwAAAuA"]
[Sun Aug 30 03:08:19.958132 2026] [authz_core:error] [pid 507246:tid 507437] [client 66.249.66.192:55401] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:19.958592 2026] [authz_core:error] [pid 507246:tid 507437] [client 66.249.66.192:55401] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:19.973971 2026] [security2:error] [pid 507246:tid 507500] [client 20.104.18.15:23504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apPk8-8CsCvw81e_I2ozKAAAAxU"]
[Sun Aug 30 03:08:19.974732 2026] [security2:error] [pid 507246:tid 507430] [client 20.48.160.90:33159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/sushi.php"] [unique_id "apPk8-8CsCvw81e_I2ozKQAAAs8"]
[Sun Aug 30 03:08:19.990034 2026] [security2:error] [pid 507246:tid 507497] [client 20.48.250.41:48002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/xsox.php"] [unique_id "apPk8-8CsCvw81e_I2ozLQAAAxI"]
[Sun Aug 30 03:08:19.990271 2026] [security2:error] [pid 507246:tid 507473] [client 68.155.159.216:55088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-content/index.php"] [unique_id "apPk8-8CsCvw81e_I2ozLgAAAvo"]
[Sun Aug 30 03:08:19.996607 2026] [security2:error] [pid 507246:tid 507455] [client 20.151.200.44:59498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/admin.php/csv.php"] [unique_id "apPk8-8CsCvw81e_I2ozMAAAAug"]
[Sun Aug 30 03:08:19.999778 2026] [security2:error] [pid 507246:tid 507407] [client 158.158.54.35:27879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/wp-admin/wp.php"] [unique_id "apPk8-8CsCvw81e_I2ozMQAAArg"]
[Sun Aug 30 03:08:20.003388 2026] [security2:error] [pid 507246:tid 507380] [client 158.23.147.79:16337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-content/index.php"] [unique_id "apPk9O8CsCvw81e_I2ozMgAAAp0"]
[Sun Aug 30 03:08:20.021108 2026] [security2:error] [pid 507246:tid 507444] [client 20.220.10.235:46973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/is.php"] [unique_id "apPk9O8CsCvw81e_I2ozNAAAAt0"]
[Sun Aug 30 03:08:20.031910 2026] [security2:error] [pid 507246:tid 507463] [client 20.104.18.15:52163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/robot.php"] [unique_id "apPk9O8CsCvw81e_I2ozNQAAAvA"]
[Sun Aug 30 03:08:20.048744 2026] [security2:error] [pid 507246:tid 507490] [client 52.139.37.240:17351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "apPk9O8CsCvw81e_I2ozNwAAAws"]
[Sun Aug 30 03:08:20.069027 2026] [authz_core:error] [pid 507246:tid 507388] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:20.069311 2026] [authz_core:error] [pid 507246:tid 507388] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:20.069512 2026] [security2:error] [pid 507246:tid 507436] [client 20.104.18.15:29674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/c4.php"] [unique_id "apPk9O8CsCvw81e_I2ozOQAAAtU"]
[Sun Aug 30 03:08:20.076333 2026] [security2:error] [pid 507246:tid 507479] [client 4.205.62.107:25758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/broadcasting.php"] [unique_id "apPk9O8CsCvw81e_I2ozOgAAAwA"]
[Sun Aug 30 03:08:20.094456 2026] [authz_core:error] [pid 507246:tid 507491] [client 216.73.216.128:31509] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:20.094858 2026] [authz_core:error] [pid 507246:tid 507491] [client 216.73.216.128:31509] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:20.095834 2026] [security2:error] [pid 507246:tid 507481] [client 20.48.251.3:33298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/myfile.php"] [unique_id "apPk9O8CsCvw81e_I2ozPAAAAwI"]
[Sun Aug 30 03:08:20.109288 2026] [security2:error] [pid 507246:tid 507399] [client 158.23.147.79:58375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/about/function.php"] [unique_id "apPk9O8CsCvw81e_I2ozPgAAArA"]
[Sun Aug 30 03:08:20.117569 2026] [security2:error] [pid 507246:tid 507397] [client 4.205.62.107:61754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/ty.php"] [unique_id "apPk9O8CsCvw81e_I2ozQAAAAq4"]
[Sun Aug 30 03:08:20.121870 2026] [security2:error] [pid 507246:tid 507451] [client 20.48.250.41:48080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/lkui.php"] [unique_id "apPk9O8CsCvw81e_I2ozQQAAAuQ"]
[Sun Aug 30 03:08:20.161368 2026] [security2:error] [pid 507246:tid 507488] [client 20.48.160.90:33194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/manga.php"] [unique_id "apPk9O8CsCvw81e_I2ozRAAAAwk"]
[Sun Aug 30 03:08:20.165287 2026] [security2:error] [pid 507246:tid 507468] [client 20.220.10.235:46943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/od.php"] [unique_id "apPk9O8CsCvw81e_I2ozRQAAAvU"]
[Sun Aug 30 03:08:20.169166 2026] [security2:error] [pid 507246:tid 507394] [client 20.48.250.41:11241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/fs.php"] [unique_id "apPk9O8CsCvw81e_I2ozRgAAAqs"]
[Sun Aug 30 03:08:20.210711 2026] [security2:error] [pid 507246:tid 507447] [client 158.23.147.79:58429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apPk9O8CsCvw81e_I2ozSwAAAuA"]
[Sun Aug 30 03:08:20.211952 2026] [security2:error] [pid 507246:tid 507386] [client 4.205.62.107:36615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/06.php"] [unique_id "apPk9O8CsCvw81e_I2ozTAAAAqM"]
[Sun Aug 30 03:08:20.214569 2026] [security2:error] [pid 507246:tid 507424] [client 20.48.251.3:59300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/min.php"] [unique_id "apPk9O8CsCvw81e_I2ozTgAAAsk"]
[Sun Aug 30 03:08:20.216134 2026] [security2:error] [pid 507246:tid 507434] [client 20.104.49.130:43839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/crgio.php"] [unique_id "apPk9O8CsCvw81e_I2ozTwAAAtM"]
[Sun Aug 30 03:08:20.241882 2026] [security2:error] [pid 507246:tid 507475] [client 52.139.37.240:17406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/wp-content/upgrade/index.php"] [unique_id "apPk9O8CsCvw81e_I2ozUwAAAvw"]
[Sun Aug 30 03:08:20.251196 2026] [security2:error] [pid 507246:tid 507387] [client 20.48.250.41:48096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apPk9O8CsCvw81e_I2ozWAAAAqQ"]
[Sun Aug 30 03:08:20.259526 2026] [security2:error] [pid 507246:tid 507497] [client 4.205.62.107:22562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/packed.php"] [unique_id "apPk9O8CsCvw81e_I2ozWgAAAxI"]
[Sun Aug 30 03:08:20.272440 2026] [security2:error] [pid 507246:tid 507411] [client 4.205.62.107:18951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/old_phpinfo.php"] [unique_id "apPk9O8CsCvw81e_I2ozXAAAArw"]
[Sun Aug 30 03:08:20.273796 2026] [security2:error] [pid 507246:tid 507450] [client 20.197.61.180:8775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/test1.php"] [unique_id "apPk9O8CsCvw81e_I2ozXQAAAuM"]
[Sun Aug 30 03:08:20.279279 2026] [authz_core:error] [pid 507246:tid 507396] [client 216.73.216.128:31509] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:20.279652 2026] [authz_core:error] [pid 507246:tid 507396] [client 216.73.216.128:31509] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:20.285565 2026] [security2:error] [pid 507246:tid 507464] [client 74.248.24.12:7595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/feeds.php"] [unique_id "apPk9O8CsCvw81e_I2ozXwAAAvE"]
[Sun Aug 30 03:08:20.303336 2026] [security2:error] [pid 507246:tid 507380] [client 20.220.10.235:46853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/wp-the.php"] [unique_id "apPk9O8CsCvw81e_I2ozYQAAAp0"]
[Sun Aug 30 03:08:20.304047 2026] [authz_core:error] [pid 507246:tid 507487] [client 66.249.66.70:43862] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:20.304328 2026] [authz_core:error] [pid 507246:tid 507487] [client 66.249.66.70:43862] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:20.316460 2026] [security2:error] [pid 507246:tid 507444] [client 158.23.147.79:16322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-admin/index.php"] [unique_id "apPk9O8CsCvw81e_I2ozYgAAAt0"]
[Sun Aug 30 03:08:20.319199 2026] [security2:error] [pid 507246:tid 507422] [client 20.48.160.90:33221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/asdfghj.php"] [unique_id "apPk9O8CsCvw81e_I2ozYwAAAsc"]
[Sun Aug 30 03:08:20.368650 2026] [authz_core:error] [pid 507246:tid 507389] [client 66.249.66.41:48036] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:20.368918 2026] [authz_core:error] [pid 507246:tid 507389] [client 66.249.66.41:48036] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:20.372540 2026] [security2:error] [pid 507246:tid 507485] [client 20.104.50.220:52849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/webshell.php"] [unique_id "apPk9O8CsCvw81e_I2ozZwAAAwY"]
[Sun Aug 30 03:08:20.373193 2026] [security2:error] [pid 507246:tid 507429] [client 20.196.209.81:11339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/users.php"] [unique_id "apPk9O8CsCvw81e_I2ozaAAAAs4"]
[Sun Aug 30 03:08:20.396000 2026] [security2:error] [pid 507246:tid 507462] [client 20.48.250.41:48024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/motu.php"] [unique_id "apPk9O8CsCvw81e_I2ozagAAAu8"]
[Sun Aug 30 03:08:20.412089 2026] [security2:error] [pid 507246:tid 507385] [client 158.23.147.79:16363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPk9O8CsCvw81e_I2ozawAAAqI"]
[Sun Aug 30 03:08:20.434101 2026] [security2:error] [pid 507246:tid 507490] [client 52.139.37.240:17363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "apPk9O8CsCvw81e_I2ozbAAAAws"]
[Sun Aug 30 03:08:20.434672 2026] [security2:error] [pid 507246:tid 507466] [client 20.220.10.235:46963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/wt.php"] [unique_id "apPk9O8CsCvw81e_I2ozbQAAAvM"]
[Sun Aug 30 03:08:20.440489 2026] [authz_core:error] [pid 507246:tid 507321] [remote 216.73.217.178:29035] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:20.440756 2026] [authz_core:error] [pid 507246:tid 507321] [remote 216.73.217.178:29035] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:20.450876 2026] [authz_core:error] [pid 507246:tid 507476] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZM
[Sun Aug 30 03:08:20.451132 2026] [authz_core:error] [pid 507246:tid 507476] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZM
[Sun Aug 30 03:08:20.453929 2026] [authz_core:error] [pid 507246:tid 507451] [client 66.249.66.38:50120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:20.454189 2026] [authz_core:error] [pid 507246:tid 507451] [client 66.249.66.38:50120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:20.461009 2026] [security2:error] [pid 507246:tid 507503] [client 158.158.54.35:18126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/bolt.php"] [unique_id "apPk9O8CsCvw81e_I2ozcwAAAxg"]
[Sun Aug 30 03:08:20.499071 2026] [security2:error] [pid 507246:tid 507488] [client 20.48.250.41:11233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/ioxi.php"] [unique_id "apPk9O8CsCvw81e_I2ozewAAAwk"]
[Sun Aug 30 03:08:20.517721 2026] [security2:error] [pid 507246:tid 507498] [client 20.104.49.130:53712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/xa.php"] [unique_id "apPk9O8CsCvw81e_I2ozfQAAAxM"]
[Sun Aug 30 03:08:20.523431 2026] [security2:error] [pid 507246:tid 507437] [client 20.104.50.220:62807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/prof.php"] [unique_id "apPk9O8CsCvw81e_I2ozgAAAAtY"]
[Sun Aug 30 03:08:20.523451 2026] [security2:error] [pid 507246:tid 507439] [client 20.48.160.90:50560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/dragonshell.php"] [unique_id "apPk9O8CsCvw81e_I2ozfwAAAtg"]
[Sun Aug 30 03:08:20.524431 2026] [security2:error] [pid 507246:tid 507491] [client 20.151.200.44:59502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/admin.php/700.php"] [unique_id "apPk9O8CsCvw81e_I2ozgQAAAww"]
[Sun Aug 30 03:08:20.569503 2026] [security2:error] [pid 507246:tid 507477] [client 20.220.10.235:46933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/im.php"] [unique_id "apPk9O8CsCvw81e_I2oziQAAAv4"]
[Sun Aug 30 03:08:20.601262 2026] [security2:error] [pid 507246:tid 507486] [client 20.48.250.41:47462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/Ov-Simple1.php"] [unique_id "apPk9O8CsCvw81e_I2ozkQAAAwc"]
[Sun Aug 30 03:08:20.602956 2026] [security2:error] [pid 507246:tid 507440] [client 158.23.147.79:60209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/about.php"] [unique_id "apPk9O8CsCvw81e_I2ozkwAAAtk"]
[Sun Aug 30 03:08:20.627316 2026] [security2:error] [pid 507246:tid 507436] [client 20.48.251.3:45842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/snq.php"] [unique_id "apPk9O8CsCvw81e_I2oznQAAAtU"]
[Sun Aug 30 03:08:20.641944 2026] [authz_core:error] [pid 507246:tid 507396] [client 216.73.216.128:33767] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:20.642368 2026] [authz_core:error] [pid 507246:tid 507396] [client 216.73.216.128:33767] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:20.646996 2026] [security2:error] [pid 507246:tid 507492] [client 52.139.37.240:17380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/ant.php"] [unique_id "apPk9O8CsCvw81e_I2ozoQAAAw0"]
[Sun Aug 30 03:08:20.662294 2026] [security2:error] [pid 507246:tid 507420] [client 20.48.250.41:11226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/bootstrap.php"] [unique_id "apPk9O8CsCvw81e_I2ozpAAAAsU"]
[Sun Aug 30 03:08:20.696577 2026] [security2:error] [pid 507246:tid 507397] [client 34.100.204.203:59134] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "bitcoinforum.it"] [uri "/"] [unique_id "apPk9O8CsCvw81e_I2ozpwAAAq4"]
[Sun Aug 30 03:08:20.708665 2026] [security2:error] [pid 507246:tid 507378] [client 20.220.10.235:46848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/file.php"] [unique_id "apPk9O8CsCvw81e_I2ozqQAAAps"]
[Sun Aug 30 03:08:20.722093 2026] [security2:error] [pid 507246:tid 507453] [client 20.48.251.3:4698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/pass4.php"] [unique_id "apPk9O8CsCvw81e_I2ozqwAAAuY"]
[Sun Aug 30 03:08:20.726869 2026] [security2:error] [pid 507246:tid 507437] [client 20.48.160.90:33174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/wp-safe.php"] [unique_id "apPk9O8CsCvw81e_I2ozrQAAAtY"]
[Sun Aug 30 03:08:20.740634 2026] [security2:error] [pid 507246:tid 507395] [client 158.23.147.79:60182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apPk9O8CsCvw81e_I2ozrgAAAqw"]
[Sun Aug 30 03:08:20.743596 2026] [security2:error] [pid 507246:tid 507386] [client 20.48.250.41:48004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/wp-blogs.php"] [unique_id "apPk9O8CsCvw81e_I2ozrwAAAqM"]
[Sun Aug 30 03:08:20.765991 2026] [security2:error] [pid 507246:tid 507448] [client 20.196.209.81:13194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/class.php"] [unique_id "apPk9O8CsCvw81e_I2oztQAAAuE"]
[Sun Aug 30 03:08:20.776263 2026] [authz_core:error] [pid 507246:tid 507494] [client 66.249.66.71:45000] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:20.776557 2026] [authz_core:error] [pid 507246:tid 507494] [client 66.249.66.71:45000] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:20.807262 2026] [security2:error] [pid 507246:tid 507427] [client 74.248.24.12:7587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/defaults.php"] [unique_id "apPk9O8CsCvw81e_I2ozwgAAAsw"]
[Sun Aug 30 03:08:20.822891 2026] [authz_core:error] [pid 507246:tid 507486] [client 216.73.216.128:31509] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:20.823166 2026] [authz_core:error] [pid 507246:tid 507486] [client 216.73.216.128:31509] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:20.845581 2026] [security2:error] [pid 507246:tid 507408] [client 20.104.50.220:59570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/foxwsov2.php"] [unique_id "apPk9O8CsCvw81e_I2ozyQAAArk"]
[Sun Aug 30 03:08:20.848232 2026] [security2:error] [pid 507246:tid 507404] [client 20.220.10.235:46849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/ca.php"] [unique_id "apPk9O8CsCvw81e_I2ozywAAArU"]
[Sun Aug 30 03:08:20.849194 2026] [security2:error] [pid 507246:tid 507447] [client 52.139.37.240:17379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/autoload_classmap.php"] [unique_id "apPk9O8CsCvw81e_I2ozzAAAAuA"]
[Sun Aug 30 03:08:20.854518 2026] [security2:error] [pid 507246:tid 507464] [client 20.48.160.90:33155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/gjewuagf.php"] [unique_id "apPk9O8CsCvw81e_I2ozzgAAAvE"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:20.870877 2026] [security2:error] [pid 507246:tid 507423] [client 20.48.250.41:48088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/mini.php"] [unique_id "apPk9O8CsCvw81e_I2oz0wAAAsg"]
[Sun Aug 30 03:08:20.871208 2026] [security2:error] [pid 507246:tid 507385] [client 158.23.147.79:60222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/themes.php"] [unique_id "apPk9O8CsCvw81e_I2oz1AAAAqI"]
[Sun Aug 30 03:08:20.900192 2026] [security2:error] [pid 507246:tid 507483] [client 20.48.250.41:11226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/export.php"] [unique_id "apPk9O8CsCvw81e_I2oz2AAAAwQ"]
[Sun Aug 30 03:08:20.908691 2026] [security2:error] [pid 507246:tid 507401] [client 20.104.50.220:5451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/4.php"] [unique_id "apPk9O8CsCvw81e_I2oz2QAAArI"]
[Sun Aug 30 03:08:20.913282 2026] [security2:error] [pid 507246:tid 507425] [client 68.155.159.216:61368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "djsevenevents.com"] [uri "/first.php"] [unique_id "apPk9O8CsCvw81e_I2oz2gAAAso"]
[Sun Aug 30 03:08:20.913300 2026] [security2:error] [pid 507246:tid 507492] [client 4.205.62.107:63970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/agg.php"] [unique_id "apPk9O8CsCvw81e_I2oz2wAAAw0"]
[Sun Aug 30 03:08:20.935812 2026] [security2:error] [pid 507246:tid 507397] [client 20.151.200.44:47068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/px.php"] [unique_id "apPk9O8CsCvw81e_I2oz5AAAAq4"]
[Sun Aug 30 03:08:20.942453 2026] [security2:error] [pid 507246:tid 507456] [client 20.104.18.15:18241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/t3.php"] [unique_id "apPk9O8CsCvw81e_I2oz5wAAAuk"]
[Sun Aug 30 03:08:20.950581 2026] [security2:error] [pid 507246:tid 507395] [client 20.104.50.220:46189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/lv.php"] [unique_id "apPk9O8CsCvw81e_I2oz7QAAAqw"]
[Sun Aug 30 03:08:20.953933 2026] [security2:error] [pid 507246:tid 507386] [client 20.104.50.220:42773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/anbu.php"] [unique_id "apPk9O8CsCvw81e_I2oz7gAAAqM"]
[Sun Aug 30 03:08:20.956858 2026] [security2:error] [pid 507246:tid 507410] [client 20.104.18.15:34568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/indo.php"] [unique_id "apPk9O8CsCvw81e_I2oz7wAAArs"]
[Sun Aug 30 03:08:20.956967 2026] [authz_core:error] [pid 507246:tid 507471] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NG
[Sun Aug 30 03:08:20.957361 2026] [authz_core:error] [pid 507246:tid 507471] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_NG
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:20.988489 2026] [security2:error] [pid 507246:tid 507387] [client 158.23.147.79:16361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-mail.php"] [unique_id "apPk9O8CsCvw81e_I2oz9QAAAqQ"]
[Sun Aug 30 03:08:20.996350 2026] [security2:error] [pid 507246:tid 507493] [client 20.48.160.90:50627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/tnglzqmv.php"] [unique_id "apPk9O8CsCvw81e_I2oz-AAAAw4"]
[Sun Aug 30 03:08:20.997631 2026] [security2:error] [pid 507246:tid 507450] [client 20.220.10.235:46911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/pb.php"] [unique_id "apPk9O8CsCvw81e_I2oz-QAAAuM"]
[Sun Aug 30 03:08:20.998919 2026] [security2:error] [pid 507246:tid 507467] [client 20.48.250.41:47478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/amp.php"] [unique_id "apPk9O8CsCvw81e_I2oz-gAAAvQ"]
[Sun Aug 30 03:08:21.008215 2026] [security2:error] [pid 507246:tid 507416] [client 20.104.18.15:35151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/akismet.php"] [unique_id "apPk9e8CsCvw81e_I2oz_QAAAsE"]
[Sun Aug 30 03:08:21.013942 2026] [security2:error] [pid 507246:tid 507475] [client 20.197.61.180:8794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/data.php"] [unique_id "apPk9e8CsCvw81e_I2o0AAAAAvw"]
[Sun Aug 30 03:08:21.018947 2026] [authz_core:error] [pid 507246:tid 507396] [client 66.249.66.34:40357] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:21.019292 2026] [authz_core:error] [pid 507246:tid 507396] [client 66.249.66.34:40357] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:21.043556 2026] [security2:error] [pid 507246:tid 507477] [client 52.139.37.240:17391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/storage/rip.php"] [unique_id "apPk9e8CsCvw81e_I2o0AwAAAv4"]
[Sun Aug 30 03:08:21.047112 2026] [security2:error] [pid 507246:tid 507489] [client 20.104.50.220:32517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/error.php"] [unique_id "apPk9e8CsCvw81e_I2o0BAAAAwo"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:21.067263 2026] [security2:error] [pid 507246:tid 507454] [client 20.104.50.220:32867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/403.php"] [unique_id "apPk9e8CsCvw81e_I2o0BQAAAuc"]
[Sun Aug 30 03:08:21.084550 2026] [security2:error] [pid 507246:tid 507462] [client 20.104.50.220:16744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/goods.php"] [unique_id "apPk9e8CsCvw81e_I2o0CAAAAu8"]
[Sun Aug 30 03:08:21.084590 2026] [security2:error] [pid 507246:tid 507379] [client 20.104.18.15:1991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/chosen.php"] [unique_id "apPk9e8CsCvw81e_I2o0CQAAApw"]
[Sun Aug 30 03:08:21.101797 2026] [security2:error] [pid 507246:tid 507385] [client 68.155.159.216:46025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apPk9e8CsCvw81e_I2o0DAAAAqI"]
[Sun Aug 30 03:08:21.108755 2026] [security2:error] [pid 507246:tid 507382] [client 158.158.54.35:8498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/edit-tags.php"] [unique_id "apPk9e8CsCvw81e_I2o0EAAAAp8"]
[Sun Aug 30 03:08:21.117721 2026] [security2:error] [pid 507246:tid 507483] [client 20.104.18.15:23363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/wp-aothait.php"] [unique_id "apPk9e8CsCvw81e_I2o0EQAAAwQ"]
[Sun Aug 30 03:08:21.125326 2026] [security2:error] [pid 507246:tid 507501] [client 20.48.160.90:19941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/wefile.php"] [unique_id "apPk9e8CsCvw81e_I2o0FAAAAxY"]
[Sun Aug 30 03:08:21.130200 2026] [security2:error] [pid 507246:tid 507446] [client 20.220.10.235:46882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/pk.php"] [unique_id "apPk9e8CsCvw81e_I2o0FQAAAt8"]
[Sun Aug 30 03:08:21.131984 2026] [security2:error] [pid 507246:tid 507420] [client 158.23.147.79:60180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/cgi-bin/index.php"] [unique_id "apPk9e8CsCvw81e_I2o0FgAAAsU"]
[Sun Aug 30 03:08:21.158718 2026] [security2:error] [pid 507246:tid 507404] [client 20.196.209.81:11476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/auth.php"] [unique_id "apPk9e8CsCvw81e_I2o0GAAAArU"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:21.166565 2026] [security2:error] [pid 507246:tid 507478] [client 20.104.18.15:51593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/sss.php"] [unique_id "apPk9e8CsCvw81e_I2o0GgAAAv8"]
[Sun Aug 30 03:08:21.174606 2026] [security2:error] [pid 507246:tid 507392] [client 20.48.250.41:47463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/cc13.php"] [unique_id "apPk9e8CsCvw81e_I2o0HAAAAqk"]
[Sun Aug 30 03:08:21.192127 2026] [security2:error] [pid 507246:tid 507395] [client 103.215.74.185:40042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.144.1.153"] [uri "/index.php"] [unique_id "apPk9e8CsCvw81e_I2o0HQAAAqw"], referer: https://162.144.1.153/wp-admin/
[Sun Aug 30 03:08:21.213630 2026] [security2:error] [pid 507246:tid 507413] [client 20.104.18.15:29636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/rxr.php"] [unique_id "apPk9e8CsCvw81e_I2o0IAAAAr4"]
[Sun Aug 30 03:08:21.220475 2026] [security2:error] [pid 507246:tid 507461] [client 20.104.49.130:53718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/m.php"] [unique_id "apPk9e8CsCvw81e_I2o0IgAAAu4"]
[Sun Aug 30 03:08:21.223406 2026] [security2:error] [pid 507246:tid 507391] [client 4.205.62.107:25856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/aws_config.php"] [unique_id "apPk9e8CsCvw81e_I2o0JAAAAqg"]
[Sun Aug 30 03:08:21.232446 2026] [authz_core:error] [pid 507246:tid 507378] [client 66.249.66.68:54128] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:21.232729 2026] [authz_core:error] [pid 507246:tid 507378] [client 66.249.66.68:54128] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:21.237073 2026] [security2:error] [pid 507246:tid 507503] [client 52.139.37.240:16697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/tinyfilemanager.php"] [unique_id "apPk9e8CsCvw81e_I2o0KAAAAxg"]
[Sun Aug 30 03:08:21.247326 2026] [security2:error] [pid 507246:tid 507433] [client 4.205.62.107:64494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/adminer-4.7.6-en.php"] [unique_id "apPk9e8CsCvw81e_I2o0KgAAAtI"]
[Sun Aug 30 03:08:21.253685 2026] [security2:error] [pid 507246:tid 507448] [client 20.104.18.15:43317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPk9e8CsCvw81e_I2o0KwAAAuE"]
[Sun Aug 30 03:08:21.257535 2026] [security2:error] [pid 507246:tid 507500] [client 20.48.251.3:56357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/lm15.php"] [unique_id "apPk9e8CsCvw81e_I2o0LAAAAxU"]
[Sun Aug 30 03:08:21.262827 2026] [security2:error] [pid 507246:tid 507426] [client 20.220.10.235:46931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/ft.php"] [unique_id "apPk9e8CsCvw81e_I2o0LQAAAss"]
[Sun Aug 30 03:08:21.269767 2026] [security2:error] [pid 507246:tid 507431] [client 20.48.160.90:50674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/blog.php"] [unique_id "apPk9e8CsCvw81e_I2o0LgAAAtA"]
[Sun Aug 30 03:08:21.270897 2026] [security2:error] [pid 507246:tid 507493] [client 158.23.147.79:58422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPk9e8CsCvw81e_I2o0LwAAAw4"]
[Sun Aug 30 03:08:21.273776 2026] [security2:error] [pid 507246:tid 507405] [client 103.215.74.185:40050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.144.1.153"] [uri "/index.php"] [unique_id "apPk9e8CsCvw81e_I2o0MAAAArY"], referer: https://162.144.1.153/wp-admin/
[Sun Aug 30 03:08:21.306763 2026] [security2:error] [pid 507246:tid 507411] [client 20.48.250.41:11149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/gk.php"] [unique_id "apPk9e8CsCvw81e_I2o0NAAAArw"]
[Sun Aug 30 03:08:21.306815 2026] [security2:error] [pid 507246:tid 507383] [client 68.155.159.216:28545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/bk/index.php"] [unique_id "apPk9e8CsCvw81e_I2o0NQAAAqA"]
[Sun Aug 30 03:08:21.308315 2026] [security2:error] [pid 507246:tid 507473] [client 20.48.250.41:48098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/aa.php"] [unique_id "apPk9e8CsCvw81e_I2o0NgAAAvo"]
[Sun Aug 30 03:08:21.351151 2026] [security2:error] [pid 507246:tid 507469] [client 74.248.24.12:6804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/system.php"] [unique_id "apPk9e8CsCvw81e_I2o0OAAAAvY"]
[Sun Aug 30 03:08:21.369101 2026] [security2:error] [pid 507246:tid 507382] [client 20.48.251.3:59266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/saiga.php"] [unique_id "apPk9e8CsCvw81e_I2o0OwAAAp8"]
[Sun Aug 30 03:08:21.393537 2026] [security2:error] [pid 507246:tid 507472] [client 20.220.10.235:46893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/wp-ver.php"] [unique_id "apPk9e8CsCvw81e_I2o0QQAAAvk"]
[Sun Aug 30 03:08:21.397031 2026] [security2:error] [pid 507246:tid 507471] [client 4.205.62.107:62288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/wp-info.php"] [unique_id "apPk9e8CsCvw81e_I2o0QwAAAvg"]
[Sun Aug 30 03:08:21.400201 2026] [security2:error] [pid 507246:tid 507420] [client 4.205.62.107:36620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/xin1.php"] [unique_id "apPk9e8CsCvw81e_I2o0RQAAAsU"]
[Sun Aug 30 03:08:21.411056 2026] [security2:error] [pid 507246:tid 507478] [client 4.205.62.107:18792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.piako.ca"] [uri "/wp-act.php"] [unique_id "apPk9e8CsCvw81e_I2o0RwAAAv8"]
[Sun Aug 30 03:08:21.417312 2026] [security2:error] [pid 507246:tid 507476] [client 158.23.147.79:60219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-includes/content.php"] [unique_id "apPk9e8CsCvw81e_I2o0SAAAAv0"]
[Sun Aug 30 03:08:21.435578 2026] [authz_core:error] [pid 507246:tid 507498] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_SG
[Sun Aug 30 03:08:21.435854 2026] [authz_core:error] [pid 507246:tid 507498] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_SG
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:21.460560 2026] [security2:error] [pid 507246:tid 507384] [client 20.104.49.130:57627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/static.php"] [unique_id "apPk9e8CsCvw81e_I2o0SwAAAqE"]
[Sun Aug 30 03:08:21.474526 2026] [security2:error] [pid 507246:tid 507470] [client 20.48.160.90:33227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/wp-admin/js/wp-load.php"] [unique_id "apPk9e8CsCvw81e_I2o0UAAAAvc"]
[Sun Aug 30 03:08:21.477535 2026] [security2:error] [pid 507246:tid 507391] [client 20.48.250.41:48017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/s1.php"] [unique_id "apPk9e8CsCvw81e_I2o0UgAAAqg"]
[Sun Aug 30 03:08:21.487695 2026] [authz_core:error] [pid 507246:tid 507461] [client 216.73.216.128:18339] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:21.488135 2026] [authz_core:error] [pid 507246:tid 507461] [client 216.73.216.128:18339] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:21.493623 2026] [security2:error] [pid 507246:tid 507487] [client 34.100.204.203:59148] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "bitcoinforum.it"] [uri "/"] [unique_id "apPk9e8CsCvw81e_I2o0VgAAAwg"]
[Sun Aug 30 03:08:21.509267 2026] [security2:error] [pid 507246:tid 507424] [client 52.139.37.240:17405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/403.php"] [unique_id "apPk9e8CsCvw81e_I2o0WgAAAsk"]
[Sun Aug 30 03:08:21.518405 2026] [security2:error] [pid 507246:tid 507387] [client 158.23.147.79:60162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-admin/css/index.php"] [unique_id "apPk9e8CsCvw81e_I2o0XQAAAqQ"]
[Sun Aug 30 03:08:21.524385 2026] [security2:error] [pid 507246:tid 507493] [client 20.104.50.220:62786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wso25.php"] [unique_id "apPk9e8CsCvw81e_I2o0XgAAAw4"]
[Sun Aug 30 03:08:21.528016 2026] [security2:error] [pid 507246:tid 507427] [client 20.220.10.235:46860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/ah24.php"] [unique_id "apPk9e8CsCvw81e_I2o0YAAAAsw"]
[Sun Aug 30 03:08:21.539417 2026] [security2:error] [pid 507246:tid 507411] [client 20.48.250.41:11237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/logs1.php"] [unique_id "apPk9e8CsCvw81e_I2o0ZAAAArw"]
[Sun Aug 30 03:08:21.547176 2026] [authz_core:error] [pid 507246:tid 507486] [client 66.249.66.44:59356] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:21.547589 2026] [authz_core:error] [pid 507246:tid 507486] [client 66.249.66.44:59356] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:21.547852 2026] [security2:error] [pid 507246:tid 507402] [client 158.158.54.35:16069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/h.php"] [unique_id "apPk9e8CsCvw81e_I2o0ZQAAArM"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:21.573472 2026] [authz_core:error] [pid 507246:tid 507477] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:21.573761 2026] [authz_core:error] [pid 507246:tid 507477] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:21.612421 2026] [security2:error] [pid 507246:tid 507460] [client 20.48.160.90:50595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/robot.php"] [unique_id "apPk9e8CsCvw81e_I2o0dQAAAu0"]
[Sun Aug 30 03:08:21.626593 2026] [security2:error] [pid 507246:tid 507492] [client 68.155.159.216:55074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/about/function.php"] [unique_id "apPk9e8CsCvw81e_I2o0ewAAAw0"]
[Sun Aug 30 03:08:21.636420 2026] [security2:error] [pid 507246:tid 507451] [client 20.48.250.41:47481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/0byte.php"] [unique_id "apPk9e8CsCvw81e_I2o0gAAAAuQ"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:21.663363 2026] [security2:error] [pid 507246:tid 507456] [client 20.220.10.235:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPk9e8CsCvw81e_I2o0hwAAAuk"]
[Sun Aug 30 03:08:21.677331 2026] [security2:error] [pid 507246:tid 507391] [client 20.104.50.220:52824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/AkuSayangKamu45.php"] [unique_id "apPk9e8CsCvw81e_I2o0iwAAAqg"]
[Sun Aug 30 03:08:21.700204 2026] [security2:error] [pid 507246:tid 507500] [client 20.196.209.81:10089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/adminfuns.php"] [unique_id "apPk9e8CsCvw81e_I2o0jgAAAxU"]
[Sun Aug 30 03:08:21.707220 2026] [security2:error] [pid 507246:tid 507404] [client 52.139.37.240:16648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/av.php"] [unique_id "apPk9e8CsCvw81e_I2o0kAAAArU"]
[Sun Aug 30 03:08:21.742566 2026] [security2:error] [pid 507246:tid 507503] [client 20.197.61.180:7848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/classwithtostring.php"] [unique_id "apPk9e8CsCvw81e_I2o0kwAAAxg"]
[Sun Aug 30 03:08:21.743730 2026] [security2:error] [pid 507246:tid 507405] [client 20.48.160.90:33226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/revo.php"] [unique_id "apPk9e8CsCvw81e_I2o0lAAAArY"]
[Sun Aug 30 03:08:21.751500 2026] [security2:error] [pid 507246:tid 507453] [client 158.23.147.79:60216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-admin/images/index.php"] [unique_id "apPk9e8CsCvw81e_I2o0lwAAAuY"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:21.758825 2026] [security2:error] [pid 507246:tid 507427] [client 20.48.250.41:11186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/inege.php"] [unique_id "apPk9e8CsCvw81e_I2o0mgAAAsw"]
[Sun Aug 30 03:08:21.776870 2026] [security2:error] [pid 507246:tid 507408] [client 20.48.251.3:7417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/wp-access.php"] [unique_id "apPk9e8CsCvw81e_I2o0nwAAArk"]
[Sun Aug 30 03:08:21.787015 2026] [security2:error] [pid 507246:tid 507422] [client 20.48.250.41:48006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/xr.php"] [unique_id "apPk9e8CsCvw81e_I2o0oQAAAsc"]
[Sun Aug 30 03:08:21.794811 2026] [security2:error] [pid 507246:tid 507400] [client 20.220.10.235:46865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/waf.php"] [unique_id "apPk9e8CsCvw81e_I2o0qAAAArE"]
[Sun Aug 30 03:08:21.828614 2026] [security2:error] [pid 507246:tid 507410] [client 20.104.49.130:59551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/82.php"] [unique_id "apPk9e8CsCvw81e_I2o0sAAAArs"]
[Sun Aug 30 03:08:21.845228 2026] [authz_core:error] [pid 507246:tid 507447] [client 66.249.66.65:35624] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:21.845729 2026] [authz_core:error] [pid 507246:tid 507447] [client 66.249.66.65:35624] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:21.859317 2026] [security2:error] [pid 507246:tid 507446] [client 20.48.251.3:5113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/cu.php"] [unique_id "apPk9e8CsCvw81e_I2o0vAAAAt8"]
[Sun Aug 30 03:08:21.895814 2026] [security2:error] [pid 507246:tid 507483] [client 74.248.24.12:14806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/xmlrpc.php0"] [unique_id "apPk9e8CsCvw81e_I2o0wgAAAwQ"]
[Sun Aug 30 03:08:21.904284 2026] [security2:error] [pid 507246:tid 507484] [client 20.48.160.90:33205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/birrs.php"] [unique_id "apPk9e8CsCvw81e_I2o0wwAAAwU"]
[Sun Aug 30 03:08:21.911142 2026] [authz_core:error] [pid 507246:tid 507448] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_DK
[Sun Aug 30 03:08:21.911425 2026] [authz_core:error] [pid 507246:tid 507448] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_DK
[Sun Aug 30 03:08:21.914438 2026] [security2:error] [pid 507246:tid 507392] [client 52.139.37.240:17368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/wp-admin/index.php"] [unique_id "apPk9e8CsCvw81e_I2o0xgAAAqk"]
[Sun Aug 30 03:08:21.935791 2026] [security2:error] [pid 507246:tid 507424] [client 20.48.250.41:48025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/h02ugyh.php"] [unique_id "apPk9e8CsCvw81e_I2o0zAAAAsk"]
[Sun Aug 30 03:08:21.942348 2026] [authz_core:error] [pid 507246:tid 507474] [client 216.73.216.128:18339] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:21.942597 2026] [authz_core:error] [pid 507246:tid 507474] [client 216.73.216.128:18339] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:21.962905 2026] [security2:error] [pid 507246:tid 507427] [client 20.48.250.41:11261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/wp-link10.php"] [unique_id "apPk9e8CsCvw81e_I2o00wAAAsw"]
[Sun Aug 30 03:08:21.967830 2026] [security2:error] [pid 507246:tid 507378] [client 20.151.200.44:57878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/admin.php/007x.php"] [unique_id "apPk9e8CsCvw81e_I2o01gAAAps"]
[Sun Aug 30 03:08:22.004222 2026] [security2:error] [pid 507246:tid 507444] [client 20.104.50.220:59577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/shellx.php"] [unique_id "apPk9u8CsCvw81e_I2o03QAAAt0"]
[Sun Aug 30 03:08:22.036418 2026] [security2:error] [pid 507246:tid 507460] [client 158.23.147.79:16330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-includes/index.php"] [unique_id "apPk9u8CsCvw81e_I2o04gAAAu0"]
[Sun Aug 30 03:08:22.043521 2026] [security2:error] [pid 507246:tid 507467] [client 20.48.160.90:50581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/sss.php"] [unique_id "apPk9u8CsCvw81e_I2o04wAAAvQ"]
[Sun Aug 30 03:08:22.052815 2026] [security2:error] [pid 507246:tid 507454] [client 4.205.62.107:62102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/requirements.php"] [unique_id "apPk9u8CsCvw81e_I2o05AAAAuc"]
[Sun Aug 30 03:08:22.057888 2026] [security2:error] [pid 507246:tid 507421] [client 20.104.50.220:5504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/3.php"] [unique_id "apPk9u8CsCvw81e_I2o05QAAAsY"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:22.064124 2026] [security2:error] [pid 507246:tid 507431] [client 20.48.250.41:47475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/xxw.php"] [unique_id "apPk9u8CsCvw81e_I2o05gAAAtA"]
[Sun Aug 30 03:08:22.078075 2026] [security2:error] [pid 507246:tid 507482] [client 20.104.18.15:18390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/wp.php"] [unique_id "apPk9u8CsCvw81e_I2o06QAAAwM"]
[Sun Aug 30 03:08:22.084310 2026] [security2:error] [pid 507246:tid 507401] [client 158.158.54.35:6152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/ms-edit.php"] [unique_id "apPk9u8CsCvw81e_I2o06gAAArI"]
[Sun Aug 30 03:08:22.088290 2026] [security2:error] [pid 507246:tid 507398] [client 20.104.18.15:34774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/sign.php"] [unique_id "apPk9u8CsCvw81e_I2o06wAAAq8"]
[Sun Aug 30 03:08:22.089944 2026] [security2:error] [pid 507246:tid 507459] [client 20.104.50.220:46193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/about.php"] [unique_id "apPk9u8CsCvw81e_I2o07AAAAuw"]
[Sun Aug 30 03:08:22.091451 2026] [security2:error] [pid 507246:tid 507388] [client 20.104.50.220:42756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-content/%E5%B9%B3%E4%BB%AE%E5%90%8Ds.php"] [unique_id "apPk9u8CsCvw81e_I2o07QAAAqU"]
[Sun Aug 30 03:08:22.092389 2026] [security2:error] [pid 507246:tid 507465] [client 20.48.250.41:11177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/ww.php"] [unique_id "apPk9u8CsCvw81e_I2o07gAAAvI"]
[Sun Aug 30 03:08:22.117595 2026] [security2:error] [pid 507246:tid 507420] [client 216.73.216.128:42925] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPk9u8CsCvw81e_I2o08gAAAsU"]
[Sun Aug 30 03:08:22.119856 2026] [security2:error] [pid 507246:tid 507472] [client 52.139.37.240:16706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "apPk9u8CsCvw81e_I2o08wAAAvk"]
[Sun Aug 30 03:08:22.120342 2026] [security2:error] [pid 507246:tid 507422] [client 20.196.209.81:9837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/rip.php"] [unique_id "apPk9u8CsCvw81e_I2o09QAAAsc"]
[Sun Aug 30 03:08:22.153083 2026] [authz_core:error] [pid 507246:tid 507481] [client 66.249.66.37:63783] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:22.153358 2026] [authz_core:error] [pid 507246:tid 507481] [client 66.249.66.37:63783] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:22.160823 2026] [security2:error] [pid 507246:tid 507392] [client 20.104.18.15:35486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/ajax.php"] [unique_id "apPk9u8CsCvw81e_I2o0_QAAAqk"]
[Sun Aug 30 03:08:22.161611 2026] [security2:error] [pid 507246:tid 507463] [client 158.23.147.79:16351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/mah.php"] [unique_id "apPk9u8CsCvw81e_I2o0_gAAAvA"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:22.193630 2026] [security2:error] [pid 507246:tid 507493] [client 20.104.50.220:32545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/x.php"] [unique_id "apPk9u8CsCvw81e_I2o1AAAAAw4"]
[Sun Aug 30 03:08:22.198392 2026] [security2:error] [pid 507246:tid 507376] [client 20.48.250.41:48070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/bolt.php"] [unique_id "apPk9u8CsCvw81e_I2o1AQAAApk"]
[Sun Aug 30 03:08:22.203767 2026] [security2:error] [pid 507246:tid 507433] [client 20.104.50.220:32834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-includes/priv8.php"] [unique_id "apPk9u8CsCvw81e_I2o1AwAAAtI"]
[Sun Aug 30 03:08:22.222857 2026] [security2:error] [pid 507246:tid 507453] [client 20.104.50.220:16748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/ms-edit.php"] [unique_id "apPk9u8CsCvw81e_I2o1CQAAAuY"]
[Sun Aug 30 03:08:22.234089 2026] [security2:error] [pid 507246:tid 507380] [client 20.48.250.41:11239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/w1px.php"] [unique_id "apPk9u8CsCvw81e_I2o1CwAAAp0"]
[Sun Aug 30 03:08:22.242224 2026] [security2:error] [pid 507246:tid 507377] [client 68.155.159.216:45979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apPk9u8CsCvw81e_I2o1DQAAApo"]
[Sun Aug 30 03:08:22.257185 2026] [security2:error] [pid 507246:tid 507461] [client 20.104.18.15:23450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/wp-includes/index.php"] [unique_id "apPk9u8CsCvw81e_I2o1DgAAAu4"]
[Sun Aug 30 03:08:22.259829 2026] [security2:error] [pid 507246:tid 507458] [client 20.104.18.15:2024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/file1221.php"] [unique_id "apPk9u8CsCvw81e_I2o1DwAAAus"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:22.302253 2026] [security2:error] [pid 507246:tid 507485] [client 103.215.74.185:40064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.144.1.153"] [uri "/index.php"] [unique_id "apPk9u8CsCvw81e_I2o1EAAAAwY"], referer: https://162.144.1.153/wp-admin/
[Sun Aug 30 03:08:22.309535 2026] [security2:error] [pid 507246:tid 507421] [client 20.104.18.15:51668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/xmini4.php"] [unique_id "apPk9u8CsCvw81e_I2o1EgAAAsY"]
[Sun Aug 30 03:08:22.311134 2026] [security2:error] [pid 507246:tid 507399] [client 52.139.37.240:17352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/wp-content/themes/pridmag/b.php"] [unique_id "apPk9u8CsCvw81e_I2o1FAAAArA"]
[Sun Aug 30 03:08:22.321508 2026] [security2:error] [pid 507246:tid 507431] [client 20.48.160.90:50671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/wp-includes/ID3/moon.php"] [unique_id "apPk9u8CsCvw81e_I2o1FQAAAtA"]
[Sun Aug 30 03:08:22.330522 2026] [security2:error] [pid 507246:tid 507410] [client 20.48.250.41:48077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/rtx.php"] [unique_id "apPk9u8CsCvw81e_I2o1FwAAArs"]
[Sun Aug 30 03:08:22.365229 2026] [security2:error] [pid 507246:tid 507482] [client 20.48.250.41:11249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/to.php"] [unique_id "apPk9u8CsCvw81e_I2o1GgAAAwM"]
[Sun Aug 30 03:08:22.368218 2026] [authz_core:error] [pid 507246:tid 507426] [client 66.249.66.72:35010] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:22.368866 2026] [authz_core:error] [pid 507246:tid 507426] [client 66.249.66.72:35010] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:22.375696 2026] [security2:error] [pid 507246:tid 507403] [client 20.104.18.15:29179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/reviall.php"] [unique_id "apPk9u8CsCvw81e_I2o1HAAAArQ"]
[Sun Aug 30 03:08:22.391191 2026] [security2:error] [pid 507246:tid 507436] [client 4.205.62.107:61760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/phpi.php"] [unique_id "apPk9u8CsCvw81e_I2o1HwAAAtU"]
[Sun Aug 30 03:08:22.392665 2026] [security2:error] [pid 507246:tid 507492] [client 103.215.74.185:40078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.144.1.153"] [uri "/index.php"] [unique_id "apPk9u8CsCvw81e_I2o1IQAAAw0"], referer: https://162.144.1.153/wp-admin/
[Sun Aug 30 03:08:22.398724 2026] [security2:error] [pid 507246:tid 507394] [client 20.48.251.3:33329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/test.config.php"] [unique_id "apPk9u8CsCvw81e_I2o1JQAAAqs"]
[Sun Aug 30 03:08:22.410322 2026] [proxy_http:error] [pid 507246:tid 507398] (20014)Internal error (specific information not available): [client 34.125.55.247:63664] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:22.410339 2026] [proxy:error] [pid 507246:tid 507398] [client 34.125.55.247:63664] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/
[Sun Aug 30 03:08:22.428195 2026] [security2:error] [pid 507246:tid 507489] [client 4.205.62.107:25862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/dialog.php"] [unique_id "apPk9u8CsCvw81e_I2o1KgAAAwo"]
[Sun Aug 30 03:08:22.433041 2026] [security2:error] [pid 507246:tid 507411] [client 74.248.24.12:7463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/colors.php"] [unique_id "apPk9u8CsCvw81e_I2o1KwAAArw"]
[Sun Aug 30 03:08:22.448844 2026] [security2:error] [pid 507246:tid 507395] [client 20.104.18.15:43311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPk9u8CsCvw81e_I2o1MQAAAqw"]
[Sun Aug 30 03:08:22.456687 2026] [authz_core:error] [pid 507246:tid 507413] [client 66.249.66.76:56130] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:22.457045 2026] [authz_core:error] [pid 507246:tid 507413] [client 66.249.66.76:56130] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:22.460300 2026] [security2:error] [pid 507246:tid 507468] [client 20.48.160.90:33250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/xmini4.php"] [unique_id "apPk9u8CsCvw81e_I2o1NQAAAvU"]
[Sun Aug 30 03:08:22.467320 2026] [security2:error] [pid 507246:tid 507450] [client 20.48.250.41:47454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/ckk.php"] [unique_id "apPk9u8CsCvw81e_I2o1NwAAAuM"]
[Sun Aug 30 03:08:22.469570 2026] [authz_core:error] [pid 507246:tid 507405] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AU
[Sun Aug 30 03:08:22.470158 2026] [authz_core:error] [pid 507246:tid 507405] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_AU
[Sun Aug 30 03:08:22.470707 2026] [security2:error] [pid 507246:tid 507497] [client 20.197.61.180:7855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/en.php"] [unique_id "apPk9u8CsCvw81e_I2o1OAAAAxI"]
[Sun Aug 30 03:08:22.479979 2026] [security2:error] [pid 507246:tid 507475] [client 158.23.147.79:58419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-blog-header.php"] [unique_id "apPk9u8CsCvw81e_I2o1OgAAAvw"]
[Sun Aug 30 03:08:22.507790 2026] [security2:error] [pid 507246:tid 507498] [client 20.48.251.3:59386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/ammika.php"] [unique_id "apPk9u8CsCvw81e_I2o1RQAAAxM"]
[Sun Aug 30 03:08:22.519713 2026] [security2:error] [pid 507246:tid 507465] [client 20.196.209.81:17687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/ws.php"] [unique_id "apPk9u8CsCvw81e_I2o1SAAAAvI"]
[Sun Aug 30 03:08:22.535909 2026] [security2:error] [pid 507246:tid 507431] [client 4.205.62.107:36656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/sadd.php"] [unique_id "apPk9u8CsCvw81e_I2o1TgAAAtA"]
[Sun Aug 30 03:08:22.536168 2026] [security2:error] [pid 507246:tid 507462] [client 4.205.62.107:22533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/fns.php"] [unique_id "apPk9u8CsCvw81e_I2o1TQAAAu8"]
[Sun Aug 30 03:08:22.570174 2026] [security2:error] [pid 507246:tid 507401] [client 52.139.37.240:17402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/0.php"] [unique_id "apPk9u8CsCvw81e_I2o1VAAAArI"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:22.594227 2026] [authz_core:error] [pid 507246:tid 507466] [client 66.249.66.36:63896] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:22.594838 2026] [authz_core:error] [pid 507246:tid 507466] [client 66.249.66.36:63896] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:22.598368 2026] [security2:error] [pid 507246:tid 507398] [client 20.48.160.90:33185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/gulu.php"] [unique_id "apPk9u8CsCvw81e_I2o1XwAAAq8"]
[Sun Aug 30 03:08:22.619256 2026] [security2:error] [pid 507246:tid 507501] [client 158.158.54.35:5185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/a7.php"] [unique_id "apPk9u8CsCvw81e_I2o1ZwAAAxY"]
[Sun Aug 30 03:08:22.651938 2026] [authz_core:error] [pid 507246:tid 507440] [client 66.249.66.76:56597] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:22.652266 2026] [authz_core:error] [pid 507246:tid 507440] [client 66.249.66.76:56597] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:22.712322 2026] [security2:error] [pid 507246:tid 507499] [client 20.220.10.235:46871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPk9u8CsCvw81e_I2o1fgAAAxQ"]
[Sun Aug 30 03:08:22.724223 2026] [authz_core:error] [pid 507246:tid 507465] [client 66.249.66.201:49708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:22.724657 2026] [authz_core:error] [pid 507246:tid 507465] [client 66.249.66.201:49708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:22.734780 2026] [security2:error] [pid 507246:tid 507454] [client 20.104.50.220:29331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wso2022_shell.php"] [unique_id "apPk9u8CsCvw81e_I2o1ggAAAuc"]
[Sun Aug 30 03:08:22.760595 2026] [security2:error] [pid 507246:tid 507397] [client 68.155.159.216:61439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/mah.php"] [unique_id "apPk9u8CsCvw81e_I2o1iQAAAq4"]
[Sun Aug 30 03:08:22.764238 2026] [security2:error] [pid 507246:tid 507430] [client 52.139.37.240:56086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/autoload_classmap/function.php"] [unique_id "apPk9u8CsCvw81e_I2o1igAAAs8"]
[Sun Aug 30 03:08:22.765702 2026] [security2:error] [pid 507246:tid 507399] [client 20.48.160.90:33269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/replace.php"] [unique_id "apPk9u8CsCvw81e_I2o1jAAAArA"]
[Sun Aug 30 03:08:22.767039 2026] [security2:error] [pid 507246:tid 507401] [client 34.100.204.203:59156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "bitcoinforum.it"] [uri "/"] [unique_id "apPk9u8CsCvw81e_I2o1jQAAArI"]
[Sun Aug 30 03:08:22.782636 2026] [security2:error] [pid 507246:tid 507406] [client 158.23.147.79:58405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apPk9u8CsCvw81e_I2o1kAAAArc"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:22.793142 2026] [security2:error] [pid 507246:tid 507409] [client 20.151.200.44:57053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/admin.php/heex.php"] [unique_id "apPk9u8CsCvw81e_I2o1mAAAAro"]
[Sun Aug 30 03:08:22.815292 2026] [security2:error] [pid 507246:tid 507376] [client 20.104.50.220:28702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/googlebots.php"] [unique_id "apPk9u8CsCvw81e_I2o1oQAAApk"]
[Sun Aug 30 03:08:22.846801 2026] [security2:error] [pid 507246:tid 507491] [client 20.220.10.235:46899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPk9u8CsCvw81e_I2o1pwAAAww"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:22.935066 2026] [security2:error] [pid 507246:tid 507454] [client 20.48.160.90:33190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/c4.php"] [unique_id "apPk9u8CsCvw81e_I2o1tQAAAuc"]
[Sun Aug 30 03:08:22.943614 2026] [security2:error] [pid 507246:tid 507483] [client 20.196.209.81:13184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/t.php"] [unique_id "apPk9u8CsCvw81e_I2o1uQAAAwQ"]
[Sun Aug 30 03:08:22.945498 2026] [security2:error] [pid 507246:tid 507379] [client 158.23.147.79:16288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-admin/user/index.php"] [unique_id "apPk9u8CsCvw81e_I2o1uwAAApw"]
[Sun Aug 30 03:08:22.955287 2026] [authz_core:error] [pid 507246:tid 507401] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_HK
[Sun Aug 30 03:08:22.955552 2026] [authz_core:error] [pid 507246:tid 507401] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_HK
[Sun Aug 30 03:08:22.960413 2026] [security2:error] [pid 507246:tid 507500] [client 52.139.37.240:56094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/dvve.php"] [unique_id "apPk9u8CsCvw81e_I2o1vwAAAxU"]
[Sun Aug 30 03:08:22.974966 2026] [security2:error] [pid 507246:tid 507470] [client 74.248.24.12:7438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/alfa-rex1.php"] [unique_id "apPk9u8CsCvw81e_I2o1xQAAAvc"]
[Sun Aug 30 03:08:22.998174 2026] [security2:error] [pid 507246:tid 507406] [client 20.48.251.3:4849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/services.php"] [unique_id "apPk9u8CsCvw81e_I2o1yAAAArc"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:23.006385 2026] [authz_core:error] [pid 507246:tid 507409] [client 66.249.66.76:56130] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:23.006675 2026] [authz_core:error] [pid 507246:tid 507409] [client 66.249.66.76:56130] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:23.015013 2026] [security2:error] [pid 507246:tid 507446] [client 20.220.10.235:46872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/h02ugyh.php"] [unique_id "apPk9-8CsCvw81e_I2o1ywAAAt8"]
[Sun Aug 30 03:08:23.047303 2026] [security2:error] [pid 507246:tid 507386] [client 68.155.159.216:28637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bigbuba.it"] [uri "/first.php"] [unique_id "apPk9-8CsCvw81e_I2o10QAAAqM"]
[Sun Aug 30 03:08:23.072999 2026] [authz_core:error] [pid 507246:tid 507387] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:23.073468 2026] [authz_core:error] [pid 507246:tid 507387] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:23.073779 2026] [security2:error] [pid 507246:tid 507493] [client 20.48.160.90:33160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/rxr.php"] [unique_id "apPk9-8CsCvw81e_I2o11QAAAw4"]
[Sun Aug 30 03:08:23.094709 2026] [security2:error] [pid 507246:tid 507430] [client 158.158.54.35:24778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/manager.php"] [unique_id "apPk9-8CsCvw81e_I2o11gAAAs8"]
[Sun Aug 30 03:08:23.106773 2026] [security2:error] [pid 507246:tid 507433] [client 20.48.251.3:64474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/otuz1.php"] [unique_id "apPk9-8CsCvw81e_I2o11wAAAtI"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:23.147494 2026] [security2:error] [pid 507246:tid 507444] [client 20.220.10.235:46809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/sf.php"] [unique_id "apPk9-8CsCvw81e_I2o13QAAAt0"]
[Sun Aug 30 03:08:23.151568 2026] [security2:error] [pid 507246:tid 507427] [client 158.23.147.79:16324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-includes/plugins.php"] [unique_id "apPk9-8CsCvw81e_I2o13gAAAsw"]
[Sun Aug 30 03:08:23.157535 2026] [security2:error] [pid 507246:tid 507452] [client 20.104.50.220:61392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/1index.php"] [unique_id "apPk9-8CsCvw81e_I2o14QAAAuU"]
[Sun Aug 30 03:08:23.189220 2026] [security2:error] [pid 507246:tid 507396] [client 4.205.62.107:62024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/var/www/wallet/index.php"] [unique_id "apPk9-8CsCvw81e_I2o15QAAAq0"]
[Sun Aug 30 03:08:23.196284 2026] [security2:error] [pid 507246:tid 507378] [client 20.197.61.180:10465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/13.php"] [unique_id "apPk9-8CsCvw81e_I2o16QAAAps"]
[Sun Aug 30 03:08:23.199490 2026] [security2:error] [pid 507246:tid 507413] [client 20.104.50.220:5543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/2.php"] [unique_id "apPk9-8CsCvw81e_I2o16gAAAr4"]
[Sun Aug 30 03:08:23.199716 2026] [authz_core:error] [pid 507246:tid 507426] [client 66.249.66.74:56025] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:23.200013 2026] [authz_core:error] [pid 507246:tid 507426] [client 66.249.66.74:56025] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:23.205852 2026] [security2:error] [pid 507246:tid 507376] [client 103.153.183.69:39146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intentionalrounding.com"] [uri "/wp/index.php"] [unique_id "apPk9-8CsCvw81e_I2o17AAAApk"], referer: https://intentionalrounding.com/wp/wp-admin/
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:23.218717 2026] [security2:error] [pid 507246:tid 507473] [client 52.139.37.240:16649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/ws77.php"] [unique_id "apPk9-8CsCvw81e_I2o17wAAAvo"]
[Sun Aug 30 03:08:23.219288 2026] [security2:error] [pid 507246:tid 507458] [client 20.104.18.15:18326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/abcd.php"] [unique_id "apPk9-8CsCvw81e_I2o18AAAAus"]
[Sun Aug 30 03:08:23.223300 2026] [security2:error] [pid 507246:tid 507379] [client 20.104.18.15:34659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/wnnjpsby.php"] [unique_id "apPk9-8CsCvw81e_I2o18gAAApw"]
[Sun Aug 30 03:08:23.239450 2026] [security2:error] [pid 507246:tid 507482] [client 20.48.160.90:33153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "celestialcreative.com"] [uri "/reviall.php"] [unique_id "apPk9-8CsCvw81e_I2o19wAAAwM"]
[Sun Aug 30 03:08:23.243669 2026] [security2:error] [pid 507246:tid 507489] [client 20.104.50.220:46439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/abcd.php"] [unique_id "apPk9-8CsCvw81e_I2o1-AAAAwo"]
[Sun Aug 30 03:08:23.246635 2026] [security2:error] [pid 507246:tid 507432] [client 20.104.50.220:51533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-admin/%E5%B9%B3%E4%BB%AE%E5%90%8Ds.php"] [unique_id "apPk9-8CsCvw81e_I2o1-gAAAtE"]
[Sun Aug 30 03:08:23.284902 2026] [security2:error] [pid 507246:tid 507393] [client 20.220.10.235:46858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/4e.php"] [unique_id "apPk9-8CsCvw81e_I2o1_AAAAqo"]
[Sun Aug 30 03:08:23.290593 2026] [security2:error] [pid 507246:tid 507398] [client 158.23.147.79:58426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apPk9-8CsCvw81e_I2o1_wAAAq8"]
[Sun Aug 30 03:08:23.293829 2026] [security2:error] [pid 507246:tid 507449] [client 20.104.18.15:35152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/atomlib.php"] [unique_id "apPk9-8CsCvw81e_I2o2AAAAAuI"]
[Sun Aug 30 03:08:23.301151 2026] [authz_core:error] [pid 507246:tid 507388] [client 66.249.66.66:38283] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:23.301437 2026] [authz_core:error] [pid 507246:tid 507388] [client 66.249.66.66:38283] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:23.346720 2026] [security2:error] [pid 507246:tid 507417] [client 20.104.50.220:32550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/xx.php"] [unique_id "apPk9-8CsCvw81e_I2o2BAAAAsI"]
[Sun Aug 30 03:08:23.357076 2026] [security2:error] [pid 507246:tid 507377] [client 20.104.50.220:33588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/00.php"] [unique_id "apPk9-8CsCvw81e_I2o2BgAAApo"]
[Sun Aug 30 03:08:23.358599 2026] [security2:error] [pid 507246:tid 507442] [client 20.104.50.220:17303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/222.php"] [unique_id "apPk9-8CsCvw81e_I2o2CAAAAts"]
[Sun Aug 30 03:08:23.358635 2026] [security2:error] [pid 507246:tid 507392] [client 68.155.159.216:46050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-content/languages/about.php"] [unique_id "apPk9-8CsCvw81e_I2o2BwAAAqk"]
[Sun Aug 30 03:08:23.393624 2026] [security2:error] [pid 507246:tid 507380] [client 20.104.18.15:1930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/nox.php"] [unique_id "apPk9-8CsCvw81e_I2o2DwAAAp0"]
[Sun Aug 30 03:08:23.395133 2026] [security2:error] [pid 507246:tid 507455] [client 20.104.18.15:23434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/file31.php"] [unique_id "apPk9-8CsCvw81e_I2o2EAAAAug"]
[Sun Aug 30 03:08:23.410300 2026] [security2:error] [pid 507246:tid 507484] [client 52.139.37.240:16643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/admin/function.php"] [unique_id "apPk9-8CsCvw81e_I2o2FwAAAwU"]
[Sun Aug 30 03:08:23.411739 2026] [authz_core:error] [pid 507246:tid 507450] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_US
[Sun Aug 30 03:08:23.412065 2026] [authz_core:error] [pid 507246:tid 507450] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_US
[Sun Aug 30 03:08:23.412540 2026] [security2:error] [pid 507246:tid 507474] [client 20.196.209.81:11347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/fw.php"] [unique_id "apPk9-8CsCvw81e_I2o2GAAAAvs"]
[Sun Aug 30 03:08:23.414492 2026] [security2:error] [pid 507246:tid 507439] [client 20.220.10.235:46887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/ssss.php"] [unique_id "apPk9-8CsCvw81e_I2o2GgAAAtg"]
[Sun Aug 30 03:08:23.428075 2026] [authz_core:error] [pid 507246:tid 507405] [client 66.249.66.32:44662] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:23.428497 2026] [authz_core:error] [pid 507246:tid 507405] [client 66.249.66.32:44662] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:23.437884 2026] [security2:error] [pid 507246:tid 507440] [client 158.23.147.79:58428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/goat1.php"] [unique_id "apPk9-8CsCvw81e_I2o2HwAAAtk"]
[Sun Aug 30 03:08:23.441287 2026] [security2:error] [pid 507246:tid 507391] [client 20.104.18.15:51619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/gulu.php"] [unique_id "apPk9-8CsCvw81e_I2o2IAAAAqg"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:23.494727 2026] [security2:error] [pid 507246:tid 507400] [client 101.78.141.110:33154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.141.78.101.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avondesignservices.co.uk"] [uri "/wp-login.php"] [unique_id "apPk9-8CsCvw81e_I2o2JwAAArE"]
[Sun Aug 30 03:08:23.531076 2026] [security2:error] [pid 507246:tid 507492] [client 4.205.62.107:61762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "apPk9-8CsCvw81e_I2o2MAAAAw0"]
[Sun Aug 30 03:08:23.531089 2026] [security2:error] [pid 507246:tid 507459] [client 20.48.250.41:11091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/thui.php"] [unique_id "apPk9-8CsCvw81e_I2o2MQAAAuw"]
[Sun Aug 30 03:08:23.542385 2026] [security2:error] [pid 507246:tid 507446] [client 20.48.251.3:60484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/gecko-litespeed.php"] [unique_id "apPk9-8CsCvw81e_I2o2NAAAAt8"]
[Sun Aug 30 03:08:23.543039 2026] [security2:error] [pid 507246:tid 507393] [client 20.220.10.235:46952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/zoz.php"] [unique_id "apPk9-8CsCvw81e_I2o2NQAAAqo"]
[Sun Aug 30 03:08:23.549122 2026] [security2:error] [pid 507246:tid 507466] [client 74.248.24.12:11883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/Njima.php"] [unique_id "apPk9-8CsCvw81e_I2o2OQAAAvM"]
[Sun Aug 30 03:08:23.581424 2026] [security2:error] [pid 507246:tid 507380] [client 158.23.147.79:16284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apPk9-8CsCvw81e_I2o2PgAAAp0"]
[Sun Aug 30 03:08:23.593040 2026] [authz_core:error] [pid 507246:tid 507401] [client 216.73.216.128:18339] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:23.593366 2026] [authz_core:error] [pid 507246:tid 507401] [client 216.73.216.128:18339] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:23.595926 2026] [security2:error] [pid 507246:tid 507427] [client 20.104.18.15:43292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/ap.php"] [unique_id "apPk9-8CsCvw81e_I2o2QwAAAsw"]
[Sun Aug 30 03:08:23.600902 2026] [security2:error] [pid 507246:tid 507474] [client 20.104.49.130:63238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/read.php"] [unique_id "apPk9-8CsCvw81e_I2o2SAAAAvs"]
[Sun Aug 30 03:08:23.601658 2026] [security2:error] [pid 507246:tid 507503] [client 4.205.62.107:25781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/phpinfo01.php"] [unique_id "apPk9-8CsCvw81e_I2o2SQAAAxg"]
[Sun Aug 30 03:08:23.602378 2026] [security2:error] [pid 507246:tid 507498] [client 20.48.250.41:48112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.juuvana.com"] [uri "/R57.php"] [unique_id "apPk9-8CsCvw81e_I2o2SwAAAxM"]
[Sun Aug 30 03:08:23.604065 2026] [security2:error] [pid 507246:tid 507403] [client 52.139.37.240:16681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/xx.php"] [unique_id "apPk9-8CsCvw81e_I2o2TAAAArQ"]
[Sun Aug 30 03:08:23.645060 2026] [security2:error] [pid 507246:tid 507400] [client 20.48.251.3:59293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/broadcasting.php"] [unique_id "apPk9-8CsCvw81e_I2o2WwAAArE"]
[Sun Aug 30 03:08:23.653085 2026] [security2:error] [pid 507246:tid 507472] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/.env"] [unique_id "apPk9-8CsCvw81e_I2o2XAAAAvk"]
[Sun Aug 30 03:08:23.664859 2026] [security2:error] [pid 507246:tid 507458] [client 103.153.183.69:39160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intentionalrounding.com"] [uri "/wp/index.php"] [unique_id "apPk9-8CsCvw81e_I2o2YgAAAus"], referer: https://intentionalrounding.com/wp/wp-admin/
[Sun Aug 30 03:08:23.675335 2026] [security2:error] [pid 507246:tid 507393] [client 20.48.250.41:11209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/Jcrop.php"] [unique_id "apPk9-8CsCvw81e_I2o2ZAAAAqo"]
[Sun Aug 30 03:08:23.677537 2026] [security2:error] [pid 507246:tid 507446] [client 20.220.10.235:46833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/kcs.php"] [unique_id "apPk9-8CsCvw81e_I2o2ZgAAAt8"]
[Sun Aug 30 03:08:23.683540 2026] [authz_core:error] [pid 507246:tid 507390] [client 216.73.216.128:42925] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:23.683828 2026] [authz_core:error] [pid 507246:tid 507390] [client 216.73.216.128:42925] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:23.690480 2026] [security2:error] [pid 507246:tid 507489] [client 4.205.62.107:62272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/params.php"] [unique_id "apPk9-8CsCvw81e_I2o2aAAAAwo"]
[Sun Aug 30 03:08:23.692718 2026] [security2:error] [pid 507246:tid 507417] [client 4.205.62.107:36630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/application.config.php"] [unique_id "apPk9-8CsCvw81e_I2o2agAAAsI"]
[Sun Aug 30 03:08:23.705387 2026] [security2:error] [pid 507246:tid 507491] [client 158.158.54.35:22336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/w1.php"] [unique_id "apPk9-8CsCvw81e_I2o2bwAAAww"]
[Sun Aug 30 03:08:23.781319 2026] [security2:error] [pid 507246:tid 507396] [client 20.151.200.44:46987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/is.php"] [unique_id "apPk9-8CsCvw81e_I2o2eAAAAq0"]
[Sun Aug 30 03:08:23.795825 2026] [security2:error] [pid 507246:tid 507397] [client 52.139.37.240:56098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/wp-content/about.php"] [unique_id "apPk9-8CsCvw81e_I2o2fgAAAq4"]
[Sun Aug 30 03:08:23.804412 2026] [authz_core:error] [pid 507246:tid 507429] [client 66.249.66.67:35041] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:23.804719 2026] [authz_core:error] [pid 507246:tid 507429] [client 66.249.66.67:35041] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:23.805324 2026] [authz_core:error] [pid 507246:tid 507484] [client 66.249.66.71:49519] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:23.805614 2026] [authz_core:error] [pid 507246:tid 507484] [client 66.249.66.71:49519] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:23.807515 2026] [authz_core:error] [pid 507246:tid 507444] [client 66.249.66.66:58977] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:23.807733 2026] [security2:error] [pid 507246:tid 507448] [client 20.196.209.81:10073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/test.php"] [unique_id "apPk9-8CsCvw81e_I2o2iAAAAuE"]
[Sun Aug 30 03:08:23.808065 2026] [authz_core:error] [pid 507246:tid 507444] [client 66.249.66.66:58977] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:23.811688 2026] [security2:error] [pid 507246:tid 507436] [client 20.220.10.235:46811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/tajj.php"] [unique_id "apPk9-8CsCvw81e_I2o2iQAAAtU"]
[Sun Aug 30 03:08:23.818122 2026] [security2:error] [pid 507246:tid 507409] [client 158.23.147.79:58430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-admin/network/index.php"] [unique_id "apPk9-8CsCvw81e_I2o2igAAAro"]
[Sun Aug 30 03:08:23.820661 2026] [security2:error] [pid 507246:tid 507468] [client 20.48.250.41:11245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/ws58.php"] [unique_id "apPk9-8CsCvw81e_I2o2jAAAAvU"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:23.896394 2026] [security2:error] [pid 507246:tid 507493] [client 68.155.159.216:62044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-blog-header.php"] [unique_id "apPk9-8CsCvw81e_I2o2ngAAAw4"]
[Sun Aug 30 03:08:23.902637 2026] [authz_core:error] [pid 507246:tid 507421] [client 66.249.66.71:56762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:23.902972 2026] [authz_core:error] [pid 507246:tid 507421] [client 66.249.66.71:56762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:23.915317 2026] [security2:error] [pid 507246:tid 507430] [client 20.104.50.220:28733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wpxadmin.php"] [unique_id "apPk9-8CsCvw81e_I2o2pgAAAs8"]
[Sun Aug 30 03:08:23.925270 2026] [security2:error] [pid 507246:tid 507407] [client 20.197.61.180:7854] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.indieoffroad.webio7.com"] [uri "/1.php"] [unique_id "apPk9-8CsCvw81e_I2o2qQAAArg"]
[Sun Aug 30 03:08:23.925388 2026] [security2:error] [pid 507246:tid 507407] [client 20.197.61.180:7854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/1.php"] [unique_id "apPk9-8CsCvw81e_I2o2qQAAArg"]
[Sun Aug 30 03:08:23.945455 2026] [security2:error] [pid 507246:tid 507396] [client 20.220.10.235:46952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/bge.php"] [unique_id "apPk9-8CsCvw81e_I2o2swAAAq0"]
[Sun Aug 30 03:08:23.947523 2026] [security2:error] [pid 507246:tid 507397] [client 20.48.250.41:11230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/xs.php"] [unique_id "apPk9-8CsCvw81e_I2o2tAAAAq4"]
[Sun Aug 30 03:08:23.952451 2026] [authz_core:error] [pid 507246:tid 507498] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_DK
[Sun Aug 30 03:08:23.952906 2026] [authz_core:error] [pid 507246:tid 507498] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_DK
[Sun Aug 30 03:08:23.969078 2026] [security2:error] [pid 507246:tid 507409] [client 20.104.50.220:52819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/ben.php"] [unique_id "apPk9-8CsCvw81e_I2o2vwAAAro"]
[Sun Aug 30 03:08:23.987507 2026] [security2:error] [pid 507246:tid 507422] [client 52.139.37.240:17383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/wp-the.php"] [unique_id "apPk9-8CsCvw81e_I2o2xgAAAsc"]
[Sun Aug 30 03:08:23.990583 2026] [security2:error] [pid 507246:tid 507485] [client 20.104.49.130:48018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/gecko-new.php"] [unique_id "apPk9-8CsCvw81e_I2o2yAAAAwY"]
[Sun Aug 30 03:08:23.996778 2026] [authz_core:error] [pid 507246:tid 507453] [client 66.249.66.78:44443] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:23.997107 2026] [authz_core:error] [pid 507246:tid 507453] [client 66.249.66.78:44443] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:24.003403 2026] [security2:error] [pid 507246:tid 507414] [client 20.220.10.235:39868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPk-O8CsCvw81e_I2o2zQAAAr8"]
[Sun Aug 30 03:08:24.032818 2026] [security2:error] [pid 507246:tid 507480] [client 158.23.147.79:58425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apPk-O8CsCvw81e_I2o2zwAAAwE"]
[Sun Aug 30 03:08:24.046980 2026] [ssl:error] [pid 507246:tid 507460] [client 18.235.110.182:36641] AH02032: Hostname gator3166.hostgator.com (default host as no SNI was provided) and hostname mail.heopworks.edu provided via HTTP have no compatible SSL setup for policy 'secure'
[Sun Aug 30 03:08:24.049489 2026] [security2:error] [pid 507246:tid 507493] [client 20.151.200.44:47064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/od.php"] [unique_id "apPk-O8CsCvw81e_I2o21gAAAw4"]
[Sun Aug 30 03:08:24.082103 2026] [security2:error] [pid 507246:tid 507475] [client 20.48.250.41:11198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/zu.php"] [unique_id "apPk-O8CsCvw81e_I2o22gAAAvw"]
[Sun Aug 30 03:08:24.086880 2026] [security2:error] [pid 507246:tid 507410] [client 20.220.10.235:46791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/ssh3ll.php"] [unique_id "apPk-O8CsCvw81e_I2o22wAAArs"]
[Sun Aug 30 03:08:24.135715 2026] [security2:error] [pid 507246:tid 507486] [client 20.220.10.235:40805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPk-O8CsCvw81e_I2o24QAAAwc"]
[Sun Aug 30 03:08:24.149936 2026] [security2:error] [pid 507246:tid 507383] [client 20.48.251.3:5107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/filesystems.php"] [unique_id "apPk-O8CsCvw81e_I2o25AAAAqA"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:24.158504 2026] [security2:error] [pid 507246:tid 507358] [remote 51.89.83.144:20630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.83.89.51.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "familycruisesguide.dirkhoag.com"] [uri "/images/images/cache.php"] [unique_id "apPk-O8CsCvw81e_I2o26QADDW8"]
[Sun Aug 30 03:08:24.181414 2026] [security2:error] [pid 507246:tid 507431] [client 52.139.37.240:16646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/ws81.php"] [unique_id "apPk-O8CsCvw81e_I2o27AAAAtA"]
[Sun Aug 30 03:08:24.185368 2026] [security2:error] [pid 507246:tid 507477] [client 158.23.147.79:16335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/.well-knownold/index.php"] [unique_id "apPk-O8CsCvw81e_I2o27QAAAv4"]
[Sun Aug 30 03:08:24.205376 2026] [security2:error] [pid 507246:tid 507400] [client 158.158.54.35:5223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/wp-login.php"] [unique_id "apPk-O8CsCvw81e_I2o25gAAArE"]
[Sun Aug 30 03:08:24.206115 2026] [security2:error] [pid 507246:tid 507478] [client 74.248.24.12:7480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/BIBIL0DAY.php"] [unique_id "apPk-O8CsCvw81e_I2o28QAAAv8"]
[Sun Aug 30 03:08:24.207961 2026] [security2:error] [pid 507246:tid 507404] [client 20.196.209.81:13231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/dropdown.php"] [unique_id "apPk-O8CsCvw81e_I2o28gAAArU"]
[Sun Aug 30 03:08:24.228284 2026] [security2:error] [pid 507246:tid 507393] [client 20.220.10.235:46942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/motu.php"] [unique_id "apPk-O8CsCvw81e_I2o2-gAAAqo"]
[Sun Aug 30 03:08:24.240311 2026] [security2:error] [pid 507246:tid 507399] [client 20.48.251.3:64400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/update.php"] [unique_id "apPk-O8CsCvw81e_I2o2_AAAArA"]
[Sun Aug 30 03:08:24.275675 2026] [security2:error] [pid 507246:tid 507493] [client 20.220.10.235:40788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/h02ugyh.php"] [unique_id "apPk-O8CsCvw81e_I2o3AAAAAw4"]
[Sun Aug 30 03:08:24.285550 2026] [security2:error] [pid 507246:tid 507405] [client 20.48.250.41:11163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/lanka.php"] [unique_id "apPk-O8CsCvw81e_I2o3AQAAArY"]
[Sun Aug 30 03:08:24.290778 2026] [security2:error] [pid 507246:tid 507395] [client 20.104.50.220:61645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/2index.php"] [unique_id "apPk-O8CsCvw81e_I2o3AgAAAqw"]
[Sun Aug 30 03:08:24.314079 2026] [security2:error] [pid 507246:tid 507377] [client 158.23.147.79:16262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apPk-O8CsCvw81e_I2o3BAAAApo"]
[Sun Aug 30 03:08:24.325726 2026] [authz_core:error] [pid 507246:tid 507376] [client 216.73.216.128:31509] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:24.326171 2026] [authz_core:error] [pid 507246:tid 507376] [client 216.73.216.128:31509] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:24.339290 2026] [security2:error] [pid 507246:tid 507475] [client 4.205.62.107:63943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/124.php"] [unique_id "apPk-O8CsCvw81e_I2o3BgAAAvw"]
[Sun Aug 30 03:08:24.352956 2026] [security2:error] [pid 507246:tid 507447] [client 20.104.50.220:5514] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/1.php"] [unique_id "apPk-O8CsCvw81e_I2o3CAAAAuA"]
[Sun Aug 30 03:08:24.353069 2026] [security2:error] [pid 507246:tid 507447] [client 20.104.50.220:5514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/1.php"] [unique_id "apPk-O8CsCvw81e_I2o3CAAAAuA"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:24.359242 2026] [security2:error] [pid 507246:tid 507450] [client 20.104.18.15:18328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/nofile.php"] [unique_id "apPk-O8CsCvw81e_I2o3CQAAAuM"]
[Sun Aug 30 03:08:24.359493 2026] [security2:error] [pid 507246:tid 507494] [client 20.220.10.235:46938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/wefile.php"] [unique_id "apPk-O8CsCvw81e_I2o3CgAAAw8"]
[Sun Aug 30 03:08:24.362252 2026] [security2:error] [pid 507246:tid 507474] [client 20.104.18.15:34781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/gigi.php"] [unique_id "apPk-O8CsCvw81e_I2o3CwAAAvs"]
[Sun Aug 30 03:08:24.381555 2026] [security2:error] [pid 507246:tid 507498] [client 20.104.50.220:51641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/plugins.php"] [unique_id "apPk-O8CsCvw81e_I2o3DQAAAxM"]
[Sun Aug 30 03:08:24.381704 2026] [security2:error] [pid 507246:tid 507397] [client 20.104.50.220:46342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/lock360.php"] [unique_id "apPk-O8CsCvw81e_I2o3DgAAAq4"]
[Sun Aug 30 03:08:24.394103 2026] [security2:error] [pid 507246:tid 507380] [client 52.139.37.240:17377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/a1.php"] [unique_id "apPk-O8CsCvw81e_I2o3EgAAAp0"]
[Sun Aug 30 03:08:24.411413 2026] [authz_core:error] [pid 507246:tid 507412] [client 216.73.216.128:18339] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:24.411700 2026] [authz_core:error] [pid 507246:tid 507412] [client 216.73.216.128:18339] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:24.417314 2026] [authz_core:error] [pid 507246:tid 507473] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_SG
[Sun Aug 30 03:08:24.417762 2026] [authz_core:error] [pid 507246:tid 507473] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_SG
[Sun Aug 30 03:08:24.436256 2026] [security2:error] [pid 507246:tid 507441] [client 20.220.10.235:39862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/sf.php"] [unique_id "apPk-O8CsCvw81e_I2o3HQAAAto"]
[Sun Aug 30 03:08:24.451135 2026] [security2:error] [pid 507246:tid 507404] [client 20.48.250.41:11205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/gettest.php"] [unique_id "apPk-O8CsCvw81e_I2o3IgAAArU"]
[Sun Aug 30 03:08:24.454461 2026] [security2:error] [pid 507246:tid 507433] [client 158.23.147.79:60196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPk-O8CsCvw81e_I2o3JwAAAtI"]
[Sun Aug 30 03:08:24.466555 2026] [security2:error] [pid 507246:tid 507417] [client 20.104.18.15:35167] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "firesouq.com"] [uri "/1.php"] [unique_id "apPk-O8CsCvw81e_I2o3KQAAAsI"]
[Sun Aug 30 03:08:24.466658 2026] [security2:error] [pid 507246:tid 507417] [client 20.104.18.15:35167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/1.php"] [unique_id "apPk-O8CsCvw81e_I2o3KQAAAsI"]
[Sun Aug 30 03:08:24.484512 2026] [security2:error] [pid 507246:tid 507444] [client 20.104.50.220:31876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/222.php"] [unique_id "apPk-O8CsCvw81e_I2o3LQAAAt0"]
[Sun Aug 30 03:08:24.489326 2026] [security2:error] [pid 507246:tid 507502] [client 20.220.10.235:46937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/Contrller.php"] [unique_id "apPk-O8CsCvw81e_I2o3MQAAAxc"]
[Sun Aug 30 03:08:24.496899 2026] [authz_core:error] [pid 507246:tid 507436] [client 66.249.66.65:59870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:24.497317 2026] [authz_core:error] [pid 507246:tid 507436] [client 66.249.66.65:59870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:24.497926 2026] [security2:error] [pid 507246:tid 507405] [client 20.104.50.220:16577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/cgi-bin/index.php"] [unique_id "apPk-O8CsCvw81e_I2o3NgAAArY"]
[Sun Aug 30 03:08:24.531520 2026] [security2:error] [pid 507246:tid 507450] [client 20.104.18.15:2046] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "brandscape.qa"] [uri "/1.php"] [unique_id "apPk-O8CsCvw81e_I2o3PgAAAuM"]
[Sun Aug 30 03:08:24.531632 2026] [security2:error] [pid 507246:tid 507450] [client 20.104.18.15:2046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/1.php"] [unique_id "apPk-O8CsCvw81e_I2o3PgAAAuM"]
[Sun Aug 30 03:08:24.532706 2026] [security2:error] [pid 507246:tid 507479] [client 20.104.18.15:23384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/dk.php"] [unique_id "apPk-O8CsCvw81e_I2o3QAAAAwA"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:24.549068 2026] [authz_core:error] [pid 507246:tid 507396] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:24.549542 2026] [authz_core:error] [pid 507246:tid 507396] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:24.555565 2026] [security2:error] [pid 507246:tid 507442] [client 20.104.50.220:33172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/000.php"] [unique_id "apPk-O8CsCvw81e_I2o3RgAAAts"]
[Sun Aug 30 03:08:24.559124 2026] [security2:error] [pid 507246:tid 507497] [client 158.23.147.79:16258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/images/index.php"] [unique_id "apPk-O8CsCvw81e_I2o3RwAAAxI"]
[Sun Aug 30 03:08:24.582952 2026] [security2:error] [pid 507246:tid 507409] [client 20.104.18.15:51681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/replace.php"] [unique_id "apPk-O8CsCvw81e_I2o3SwAAAro"]
[Sun Aug 30 03:08:24.588185 2026] [authz_core:error] [pid 507246:tid 507494] [client 66.249.66.38:47223] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:24.588587 2026] [authz_core:error] [pid 507246:tid 507494] [client 66.249.66.38:47223] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:24.591294 2026] [security2:error] [pid 507246:tid 507420] [client 52.139.37.240:16694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/ca5.php"] [unique_id "apPk-O8CsCvw81e_I2o3TwAAAsU"]
[Sun Aug 30 03:08:24.606011 2026] [security2:error] [pid 507246:tid 507404] [client 20.220.10.235:40789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/4e.php"] [unique_id "apPk-O8CsCvw81e_I2o3VQAAArU"]
[Sun Aug 30 03:08:24.618050 2026] [security2:error] [pid 507246:tid 507428] [client 20.196.209.81:11387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/mar.php"] [unique_id "apPk-O8CsCvw81e_I2o3XQAAAs0"]
[Sun Aug 30 03:08:24.619343 2026] [security2:error] [pid 507246:tid 507485] [client 20.220.10.235:46805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/file66.php"] [unique_id "apPk-O8CsCvw81e_I2o3XwAAAwY"]
[Sun Aug 30 03:08:24.630676 2026] [security2:error] [pid 507246:tid 507454] [client 20.197.61.180:7810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/as.php"] [unique_id "apPk-O8CsCvw81e_I2o3ZwAAAuc"]
[Sun Aug 30 03:08:24.648949 2026] [security2:error] [pid 507246:tid 507446] [client 20.48.250.41:11144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/35.php"] [unique_id "apPk-O8CsCvw81e_I2o3awAAAt8"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:24.657114 2026] [security2:error] [pid 507246:tid 507398] [client 158.158.54.35:27129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/gecko-new.php"] [unique_id "apPk-O8CsCvw81e_I2o3bgAAAq8"]
[Sun Aug 30 03:08:24.673172 2026] [security2:error] [pid 507246:tid 507489] [client 68.155.159.216:54216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apPk-O8CsCvw81e_I2o3cQAAAwo"]
[Sun Aug 30 03:08:24.676209 2026] [security2:error] [pid 507246:tid 507380] [client 4.205.62.107:64655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/myfile.php"] [unique_id "apPk-O8CsCvw81e_I2o3cwAAAp0"]
[Sun Aug 30 03:08:24.681229 2026] [security2:error] [pid 507246:tid 507474] [client 20.48.251.3:33303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/goods.php"] [unique_id "apPk-O8CsCvw81e_I2o3dQAAAvs"]
[Sun Aug 30 03:08:24.689794 2026] [security2:error] [pid 507246:tid 507364] [remote 97.74.87.194:52318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "esselwebdesign.com"] [uri "/wp-login.php"] [unique_id "apPk-O8CsCvw81e_I2o3dAACvHU"]
[Sun Aug 30 03:08:24.726372 2026] [security2:error] [pid 507246:tid 507397] [client 74.248.24.12:11881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/contentloader1.php"] [unique_id "apPk-O8CsCvw81e_I2o3ggAAAq4"]
[Sun Aug 30 03:08:24.740623 2026] [security2:error] [pid 507246:tid 507378] [client 20.220.10.235:39835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/ssss.php"] [unique_id "apPk-O8CsCvw81e_I2o3gwAAAps"]
[Sun Aug 30 03:08:24.747943 2026] [security2:error] [pid 507246:tid 507431] [client 20.220.10.235:46790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/blnux.php"] [unique_id "apPk-O8CsCvw81e_I2o3hQAAAtA"]
[Sun Aug 30 03:08:24.752536 2026] [security2:error] [pid 507246:tid 507428] [client 20.104.18.15:43326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/media.php"] [unique_id "apPk-O8CsCvw81e_I2o3iQAAAs0"]
[Sun Aug 30 03:08:24.756903 2026] [security2:error] [pid 507246:tid 507485] [client 4.205.62.107:25887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/cxc.php"] [unique_id "apPk-O8CsCvw81e_I2o3jAAAAwY"]
[Sun Aug 30 03:08:24.758103 2026] [authz_core:error] [pid 507246:tid 507412] [client 66.249.66.66:53659] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:24.758578 2026] [authz_core:error] [pid 507246:tid 507412] [client 66.249.66.66:53659] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:24.770576 2026] [fcgid:warn] [pid 507246:tid 507471] (70014)End of file found: [client 143.110.213.72:48472] mod_fcgid: can't get data from http client
[Sun Aug 30 03:08:24.790321 2026] [security2:error] [pid 507246:tid 507377] [client 20.48.251.3:59352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/aws_config.php"] [unique_id "apPk-O8CsCvw81e_I2o3mQAAApo"]
[Sun Aug 30 03:08:24.795240 2026] [security2:error] [pid 507246:tid 507478] [client 52.139.37.240:17349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/install.php"] [unique_id "apPk-O8CsCvw81e_I2o3nAAAAv8"]
[Sun Aug 30 03:08:24.811520 2026] [security2:error] [pid 507246:tid 507479] [client 158.23.147.79:58379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apPk-O8CsCvw81e_I2o3oQAAAwA"]
[Sun Aug 30 03:08:24.827814 2026] [security2:error] [pid 507246:tid 507440] [client 4.205.62.107:54419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/gjm.php"] [unique_id "apPk-O8CsCvw81e_I2o3pQAAAtk"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:24.870432 2026] [security2:error] [pid 507246:tid 507452] [client 20.48.250.41:11078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/maraz.php"] [unique_id "apPk-O8CsCvw81e_I2o3sgAAAuU"]
[Sun Aug 30 03:08:24.873226 2026] [security2:error] [pid 507246:tid 507385] [client 20.220.10.235:40727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/zoz.php"] [unique_id "apPk-O8CsCvw81e_I2o3swAAAqI"]
[Sun Aug 30 03:08:24.874070 2026] [security2:error] [pid 507246:tid 507393] [client 20.151.200.44:47058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/wp-the.php"] [unique_id "apPk-O8CsCvw81e_I2o3tAAAAqo"]
[Sun Aug 30 03:08:24.878423 2026] [security2:error] [pid 507246:tid 507428] [client 20.220.10.235:46881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/attack.php"] [unique_id "apPk-O8CsCvw81e_I2o3tQAAAs0"]
[Sun Aug 30 03:08:24.911452 2026] [fcgid:warn] [pid 507246:tid 507444] (70014)End of file found: [client 143.110.213.72:48486] mod_fcgid: can't get data from http client
[Sun Aug 30 03:08:24.917528 2026] [authz_core:error] [pid 507246:tid 507471] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_HK
[Sun Aug 30 03:08:24.917992 2026] [authz_core:error] [pid 507246:tid 507471] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_HK
[Sun Aug 30 03:08:25.002571 2026] [security2:error] [pid 507246:tid 507500] [client 20.220.10.235:40770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/kcs.php"] [unique_id "apPk-e8CsCvw81e_I2o33QAAAxU"]
[Sun Aug 30 03:08:25.008954 2026] [security2:error] [pid 507246:tid 507433] [client 158.23.147.79:58403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apPk-e8CsCvw81e_I2o34AAAAtI"]
[Sun Aug 30 03:08:25.016439 2026] [security2:error] [pid 507246:tid 507485] [client 20.220.10.235:46925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/wk/index.php"] [unique_id "apPk-e8CsCvw81e_I2o35QAAAwY"]
[Sun Aug 30 03:08:25.046990 2026] [security2:error] [pid 507246:tid 507376] [client 68.155.159.216:46031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-content/banners/about.php"] [unique_id "apPk-e8CsCvw81e_I2o38gAAApk"]
[Sun Aug 30 03:08:25.054136 2026] [security2:error] [pid 507246:tid 507398] [client 52.139.37.240:16660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/wp-signin.php"] [unique_id "apPk-e8CsCvw81e_I2o39wAAAq8"]
[Sun Aug 30 03:08:25.054939 2026] [authz_core:error] [pid 507246:tid 507405] [client 216.73.216.128:42925] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:25.055383 2026] [authz_core:error] [pid 507246:tid 507405] [client 216.73.216.128:42925] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:25.057432 2026] [security2:error] [pid 507246:tid 507495] [client 68.155.159.216:61409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apPk-e8CsCvw81e_I2o3-AAAAxA"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:25.067144 2026] [security2:error] [pid 507246:tid 507415] [client 20.48.250.41:11093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/kbfr.php"] [unique_id "apPk-e8CsCvw81e_I2o3-wAAAsA"]
[Sun Aug 30 03:08:25.072272 2026] [security2:error] [pid 507246:tid 507493] [client 20.196.209.81:11328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/css.php"] [unique_id "apPk-e8CsCvw81e_I2o3_AAAAw4"]
[Sun Aug 30 03:08:25.081780 2026] [security2:error] [pid 507246:tid 507480] [client 20.104.49.130:63597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/talkxkej.php"] [unique_id "apPk-e8CsCvw81e_I2o3_QAAAwE"]
[Sun Aug 30 03:08:25.110376 2026] [security2:error] [pid 507246:tid 507456] [client 158.23.147.79:16378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apPk-e8CsCvw81e_I2o4AQAAAuk"]
[Sun Aug 30 03:08:25.124183 2026] [security2:error] [pid 507246:tid 507497] [client 158.158.54.35:24959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/NewFile.php"] [unique_id "apPk-e8CsCvw81e_I2o4BgAAAxI"]
[Sun Aug 30 03:08:25.134240 2026] [security2:error] [pid 507246:tid 507482] [client 20.220.10.235:40720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/tajj.php"] [unique_id "apPk-e8CsCvw81e_I2o4CQAAAwM"]
[Sun Aug 30 03:08:25.141797 2026] [security2:error] [pid 507246:tid 507466] [client 20.104.50.220:29145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/9191.php"] [unique_id "apPk-e8CsCvw81e_I2o4DAAAAvM"]
[Sun Aug 30 03:08:25.144381 2026] [authz_core:error] [pid 507246:tid 507473] [client 216.73.216.128:31509] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:25.144649 2026] [authz_core:error] [pid 507246:tid 507473] [client 216.73.216.128:31509] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:25.152594 2026] [security2:error] [pid 507246:tid 507490] [client 20.220.10.235:46832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/dehnl.php"] [unique_id "apPk-e8CsCvw81e_I2o4EQAAAws"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:25.182187 2026] [security2:error] [pid 507246:tid 507378] [client 20.104.50.220:63042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wso2.5.php"] [unique_id "apPk-e8CsCvw81e_I2o4FAAAAps"]
[Sun Aug 30 03:08:25.229154 2026] [security2:error] [pid 507246:tid 507439] [client 20.48.250.41:11210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/wp-act.php"] [unique_id "apPk-e8CsCvw81e_I2o4HgAAAtg"]
[Sun Aug 30 03:08:25.253183 2026] [authz_core:error] [pid 507246:tid 507413] [client 66.249.66.69:55919] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:25.253463 2026] [authz_core:error] [pid 507246:tid 507413] [client 66.249.66.69:55919] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:25.259743 2026] [security2:error] [pid 507246:tid 507399] [client 52.139.37.240:56083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/Ov-Simple1.php"] [unique_id "apPk-e8CsCvw81e_I2o4IAAAArA"]
[Sun Aug 30 03:08:25.264706 2026] [security2:error] [pid 507246:tid 507444] [client 20.220.10.235:40708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/bge.php"] [unique_id "apPk-e8CsCvw81e_I2o4IgAAAt0"]
[Sun Aug 30 03:08:25.265984 2026] [security2:error] [pid 507246:tid 507486] [client 158.23.147.79:58418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apPk-e8CsCvw81e_I2o4JAAAAwc"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:25.287363 2026] [security2:error] [pid 507246:tid 507489] [client 20.220.10.235:46798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/png.php"] [unique_id "apPk-e8CsCvw81e_I2o4JwAAAwo"]
[Sun Aug 30 03:08:25.297754 2026] [proxy_http:error] [pid 507246:tid 507492] (20014)Internal error (specific information not available): [client 34.125.55.247:63710] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:25.297781 2026] [proxy:error] [pid 507246:tid 507492] [client 34.125.55.247:63710] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/admin
[Sun Aug 30 03:08:25.299091 2026] [authz_core:error] [pid 507246:tid 507371] [remote 216.73.217.178:29035] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:25.299371 2026] [authz_core:error] [pid 507246:tid 507371] [remote 216.73.217.178:29035] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:25.305581 2026] [proxy_http:error] [pid 507246:tid 507492] (20014)Internal error (specific information not available): [client 34.125.55.247:63710] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:25.305595 2026] [proxy:error] [pid 507246:tid 507492] [client 34.125.55.247:63710] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml
[Sun Aug 30 03:08:25.347268 2026] [security2:error] [pid 507246:tid 507494] [client 20.197.61.180:9379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/credits.php"] [unique_id "apPk-e8CsCvw81e_I2o4NAAAAw8"]
[Sun Aug 30 03:08:25.350107 2026] [security2:error] [pid 507246:tid 507464] [client 20.104.49.130:53611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/wpxml.php"] [unique_id "apPk-e8CsCvw81e_I2o4NQAAAvE"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:25.377436 2026] [security2:error] [pid 507246:tid 507443] [client 74.248.24.12:7855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/sim.php"] [unique_id "apPk-e8CsCvw81e_I2o4OQAAAtw"]
[Sun Aug 30 03:08:25.393864 2026] [security2:error] [pid 507246:tid 507474] [client 20.220.10.235:40820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/ssh3ll.php"] [unique_id "apPk-e8CsCvw81e_I2o4QwAAAvs"]
[Sun Aug 30 03:08:25.414632 2026] [security2:error] [pid 507246:tid 507451] [client 20.48.250.41:11168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/24.php"] [unique_id "apPk-e8CsCvw81e_I2o4SQAAAuQ"]
[Sun Aug 30 03:08:25.417599 2026] [security2:error] [pid 507246:tid 507465] [client 20.220.10.235:46793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/txets.php"] [unique_id "apPk-e8CsCvw81e_I2o4SwAAAvI"]
[Sun Aug 30 03:08:25.429061 2026] [security2:error] [pid 507246:tid 507425] [client 20.104.50.220:59559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/3index.php"] [unique_id "apPk-e8CsCvw81e_I2o4TgAAAso"]
[Sun Aug 30 03:08:25.433297 2026] [authz_core:error] [pid 507246:tid 507409] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_SG
[Sun Aug 30 03:08:25.433664 2026] [authz_core:error] [pid 507246:tid 507409] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_SG
[Sun Aug 30 03:08:25.433902 2026] [security2:error] [pid 507246:tid 507385] [client 20.48.251.3:4708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/tax.php"] [unique_id "apPk-e8CsCvw81e_I2o4UAAAAqI"]
[Sun Aug 30 03:08:25.438976 2026] [security2:error] [pid 507246:tid 507502] [client 158.23.147.79:16352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/nf_tracking.php"] [unique_id "apPk-e8CsCvw81e_I2o4VQAAAxc"]
[Sun Aug 30 03:08:25.452857 2026] [security2:error] [pid 507246:tid 507389] [client 52.139.37.240:56120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/ftde.php"] [unique_id "apPk-e8CsCvw81e_I2o4WgAAAqY"]
[Sun Aug 30 03:08:25.468516 2026] [security2:error] [pid 507246:tid 507453] [client 20.151.200.44:55632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/px.php"] [unique_id "apPk-e8CsCvw81e_I2o4XwAAAuY"]
[Sun Aug 30 03:08:25.470837 2026] [security2:error] [pid 507246:tid 507414] [client 4.205.62.107:62136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/test1.php"] [unique_id "apPk-e8CsCvw81e_I2o4YAAAAr8"]
[Sun Aug 30 03:08:25.483858 2026] [security2:error] [pid 507246:tid 507429] [client 20.196.209.81:12688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/autoload_classmap.php"] [unique_id "apPk-e8CsCvw81e_I2o4YgAAAs4"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:25.487187 2026] [security2:error] [pid 507246:tid 507493] [client 158.69.119.16:58716] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "158.69.119.16" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPk-e8CsCvw81e_I2o4YwAAAw4"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:08:25.487301 2026] [security2:error] [pid 507246:tid 507493] [client 158.69.119.16:58716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPk-e8CsCvw81e_I2o4YwAAAw4"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:08:25.499274 2026] [security2:error] [pid 507246:tid 507479] [client 20.104.18.15:18307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/run.php"] [unique_id "apPk-e8CsCvw81e_I2o4aAAAAwA"]
[Sun Aug 30 03:08:25.500872 2026] [security2:error] [pid 507246:tid 507487] [client 20.104.18.15:34651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/info.php/new.php"] [unique_id "apPk-e8CsCvw81e_I2o4aQAAAwg"]
[Sun Aug 30 03:08:25.522369 2026] [security2:error] [pid 507246:tid 507467] [client 20.104.50.220:51605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-content/priv8.php"] [unique_id "apPk-e8CsCvw81e_I2o4bwAAAvQ"]
[Sun Aug 30 03:08:25.529113 2026] [security2:error] [pid 507246:tid 507420] [client 20.220.10.235:39859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/motu.php"] [unique_id "apPk-e8CsCvw81e_I2o4cAAAAsU"]
[Sun Aug 30 03:08:25.534188 2026] [security2:error] [pid 507246:tid 507466] [client 20.48.251.3:7077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/channels.php"] [unique_id "apPk-e8CsCvw81e_I2o4cgAAAvM"]
[Sun Aug 30 03:08:25.534952 2026] [security2:error] [pid 507246:tid 507470] [client 20.104.50.220:46886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/pp.php"] [unique_id "apPk-e8CsCvw81e_I2o4cwAAAvc"]
[Sun Aug 30 03:08:25.540606 2026] [security2:error] [pid 507246:tid 507490] [client 20.104.50.220:5583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/0.php"] [unique_id "apPk-e8CsCvw81e_I2o4dQAAAws"]
[Sun Aug 30 03:08:25.549434 2026] [security2:error] [pid 507246:tid 507496] [client 20.220.10.235:46941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/wp-login.php"] [unique_id "apPk-e8CsCvw81e_I2o4eAAAAxE"]
[Sun Aug 30 03:08:25.559523 2026] [security2:error] [pid 507246:tid 507499] [client 20.48.250.41:11170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/155.php"] [unique_id "apPk-e8CsCvw81e_I2o4egAAAxQ"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:25.612740 2026] [security2:error] [pid 507246:tid 507453] [client 20.104.18.15:35512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/samll.php"] [unique_id "apPk-e8CsCvw81e_I2o4hwAAAuY"]
[Sun Aug 30 03:08:25.620688 2026] [security2:error] [pid 507246:tid 507486] [client 158.23.147.79:16325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wzy.php"] [unique_id "apPk-e8CsCvw81e_I2o4kAAAAwc"]
[Sun Aug 30 03:08:25.645147 2026] [security2:error] [pid 507246:tid 507431] [client 52.139.37.240:16680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/hplfuns.php"] [unique_id "apPk-e8CsCvw81e_I2o4nAAAAtA"]
[Sun Aug 30 03:08:25.653952 2026] [security2:error] [pid 507246:tid 507467] [client 20.104.50.220:32286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/444.php"] [unique_id "apPk-e8CsCvw81e_I2o4ngAAAvQ"]
[Sun Aug 30 03:08:25.655016 2026] [security2:error] [pid 507246:tid 507450] [client 158.158.54.35:24933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/wp-Blogs.php"] [unique_id "apPk-e8CsCvw81e_I2o4nwAAAuM"]
[Sun Aug 30 03:08:25.660654 2026] [security2:error] [pid 507246:tid 507460] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/.env.bak"] [unique_id "apPk-e8CsCvw81e_I2o4oQAAAu0"]
[Sun Aug 30 03:08:25.666518 2026] [security2:error] [pid 507246:tid 507416] [client 20.104.18.15:2045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/m.php"] [unique_id "apPk-e8CsCvw81e_I2o4pAAAAsE"]
[Sun Aug 30 03:08:25.678883 2026] [security2:error] [pid 507246:tid 507451] [client 20.220.10.235:46863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/wp-access.php"] [unique_id "apPk-e8CsCvw81e_I2o4pwAAAuQ"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:25.695177 2026] [security2:error] [pid 507246:tid 507403] [client 20.104.18.15:23435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/ta.php"] [unique_id "apPk-e8CsCvw81e_I2o4qgAAArQ"]
[Sun Aug 30 03:08:25.712200 2026] [security2:error] [pid 507246:tid 507448] [client 20.104.50.220:17315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/BDKR28WP.php"] [unique_id "apPk-e8CsCvw81e_I2o4sQAAAuE"]
[Sun Aug 30 03:08:25.712312 2026] [security2:error] [pid 507246:tid 507433] [client 20.104.50.220:33294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/okkk.php"] [unique_id "apPk-e8CsCvw81e_I2o4sAAAAtI"]
[Sun Aug 30 03:08:25.717879 2026] [security2:error] [pid 507246:tid 507409] [client 20.48.250.41:11232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/file.php"] [unique_id "apPk-e8CsCvw81e_I2o4sgAAAro"]
[Sun Aug 30 03:08:25.723011 2026] [security2:error] [pid 507246:tid 507434] [client 20.220.10.235:40826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/wefile.php"] [unique_id "apPk-e8CsCvw81e_I2o4swAAAtM"]
[Sun Aug 30 03:08:25.743418 2026] [security2:error] [pid 507246:tid 507495] [client 20.104.18.15:51587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/c4.php"] [unique_id "apPk-e8CsCvw81e_I2o4uQAAAxA"]
[Sun Aug 30 03:08:25.746726 2026] [security2:error] [pid 507246:tid 507383] [client 158.23.147.79:58402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apPk-e8CsCvw81e_I2o4ugAAAqA"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:25.812151 2026] [security2:error] [pid 507246:tid 507387] [client 20.220.10.235:46901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/wp-content/admin.php"] [unique_id "apPk-e8CsCvw81e_I2o41wAAAqQ"]
[Sun Aug 30 03:08:25.821127 2026] [security2:error] [pid 507246:tid 507465] [client 216.73.216.128:31509] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPk-e8CsCvw81e_I2o42AAAAvI"]
[Sun Aug 30 03:08:25.825773 2026] [security2:error] [pid 507246:tid 507482] [client 158.69.119.16:58731] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "158.69.119.16" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPk-e8CsCvw81e_I2o42QAAAwM"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:08:25.825866 2026] [security2:error] [pid 507246:tid 507482] [client 158.69.119.16:58731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPk-e8CsCvw81e_I2o42QAAAwM"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:08:25.837994 2026] [security2:error] [pid 507246:tid 507479] [client 52.139.37.240:17354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/log.php"] [unique_id "apPk-e8CsCvw81e_I2o43AAAAwA"]
[Sun Aug 30 03:08:25.862803 2026] [security2:error] [pid 507246:tid 507495] [client 20.48.251.3:33326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/loxi-o.php"] [unique_id "apPk-e8CsCvw81e_I2o47AAAAxA"]
[Sun Aug 30 03:08:25.863540 2026] [security2:error] [pid 507246:tid 507399] [client 20.220.10.235:39846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/Contrller.php"] [unique_id "apPk-e8CsCvw81e_I2o47QAAArA"]
[Sun Aug 30 03:08:25.874796 2026] [security2:error] [pid 507246:tid 507503] [client 20.104.49.130:36753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPk-e8CsCvw81e_I2o47wAAAxg"]
[Sun Aug 30 03:08:25.879723 2026] [security2:error] [pid 507246:tid 507439] [client 20.48.250.41:11255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPk-e8CsCvw81e_I2o48gAAAtg"]
[Sun Aug 30 03:08:25.879750 2026] [security2:error] [pid 507246:tid 507405] [client 158.23.147.79:58399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apPk-e8CsCvw81e_I2o48AAAArY"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:25.894002 2026] [security2:error] [pid 507246:tid 507428] [client 74.248.24.12:7450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/83064.php"] [unique_id "apPk-e8CsCvw81e_I2o49AAAAs0"]
[Sun Aug 30 03:08:25.921438 2026] [security2:error] [pid 507246:tid 507429] [client 4.205.62.107:25883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/oiko6u.php"] [unique_id "apPk-e8CsCvw81e_I2o4-wAAAs4"]
[Sun Aug 30 03:08:25.921466 2026] [security2:error] [pid 507246:tid 507411] [client 20.48.251.3:59332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/dialog.php"] [unique_id "apPk-e8CsCvw81e_I2o4_AAAArw"]
[Sun Aug 30 03:08:25.926283 2026] [security2:error] [pid 507246:tid 507250] [remote 97.74.87.194:52318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "esselwebdesign.com"] [uri "/wp-login.php"] [unique_id "apPk-e8CsCvw81e_I2o4_gAC9gM"], referer: https://esselwebdesign.com/wp-login.php
[Sun Aug 30 03:08:25.927705 2026] [authz_core:error] [pid 507246:tid 507417] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:08:25.927968 2026] [authz_core:error] [pid 507246:tid 507417] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Frpm%2Fmacros.d
[Sun Aug 30 03:08:25.957936 2026] [security2:error] [pid 507246:tid 507454] [client 20.220.10.235:46884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/log.php"] [unique_id "apPk-e8CsCvw81e_I2o5DgAAAuc"]
[Sun Aug 30 03:08:25.961197 2026] [security2:error] [pid 507246:tid 507376] [client 20.196.209.81:11378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/info.php"] [unique_id "apPk-e8CsCvw81e_I2o5EQAAApk"]
[Sun Aug 30 03:08:25.967064 2026] [authz_core:error] [pid 507246:tid 507440] [client 66.249.66.69:38025] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:25.967369 2026] [authz_core:error] [pid 507246:tid 507440] [client 66.249.66.69:38025] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:25.975493 2026] [security2:error] [pid 507246:tid 507482] [client 4.205.62.107:36023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/xp.php"] [unique_id "apPk-e8CsCvw81e_I2o5GAAAAwM"]
[Sun Aug 30 03:08:25.980762 2026] [security2:error] [pid 507246:tid 507500] [client 4.205.62.107:62442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/configuration.php"] [unique_id "apPk-e8CsCvw81e_I2o5GwAAAxU"]
[Sun Aug 30 03:08:25.983658 2026] [security2:error] [pid 507246:tid 507437] [client 20.104.18.15:43324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/adminfuns.php"] [unique_id "apPk-e8CsCvw81e_I2o5HAAAAtY"]
[Sun Aug 30 03:08:25.988381 2026] [security2:error] [pid 507246:tid 507421] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/.env.backup"] [unique_id "apPk-e8CsCvw81e_I2o5HQAAAsY"]
[Sun Aug 30 03:08:26.004136 2026] [security2:error] [pid 507246:tid 507458] [client 20.220.10.235:40769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/file66.php"] [unique_id "apPk-u8CsCvw81e_I2o5IgAAAus"]
[Sun Aug 30 03:08:26.007389 2026] [security2:error] [pid 507246:tid 507495] [client 20.48.250.41:11165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/06.php"] [unique_id "apPk-u8CsCvw81e_I2o5IwAAAxA"]
[Sun Aug 30 03:08:26.009587 2026] [authz_core:error] [pid 507246:tid 507472] [client 216.73.216.128:22035] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:26.009948 2026] [authz_core:error] [pid 507246:tid 507472] [client 216.73.216.128:22035] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:26.029795 2026] [security2:error] [pid 507246:tid 507459] [client 4.205.62.107:64685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/lm15.php"] [unique_id "apPk-u8CsCvw81e_I2o5KwAAAuw"]
[Sun Aug 30 03:08:26.037007 2026] [security2:error] [pid 507246:tid 507423] [client 52.139.37.240:17358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/txets.php"] [unique_id "apPk-u8CsCvw81e_I2o5LgAAAsg"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:26.065292 2026] [security2:error] [pid 507246:tid 507461] [client 68.155.159.216:54256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-admin/index.php"] [unique_id "apPk-u8CsCvw81e_I2o5NgAAAu4"]
[Sun Aug 30 03:08:26.067282 2026] [authz_core:error] [pid 507246:tid 507456] [client 66.249.66.68:48233] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:26.067635 2026] [authz_core:error] [pid 507246:tid 507456] [client 66.249.66.68:48233] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:26.073195 2026] [security2:error] [pid 507246:tid 507412] [client 20.197.61.180:19049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/cache.php"] [unique_id "apPk-u8CsCvw81e_I2o5OAAAAr0"]
[Sun Aug 30 03:08:26.076125 2026] [security2:error] [pid 507246:tid 507475] [client 158.23.147.79:60161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apPk-u8CsCvw81e_I2o5OQAAAvw"]
[Sun Aug 30 03:08:26.098129 2026] [security2:error] [pid 507246:tid 507427] [client 20.220.10.235:46909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/xwpg.php"] [unique_id "apPk-u8CsCvw81e_I2o5PQAAAsw"]
[Sun Aug 30 03:08:26.139195 2026] [security2:error] [pid 507246:tid 507500] [client 20.220.10.235:40709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/blnux.php"] [unique_id "apPk-u8CsCvw81e_I2o5SAAAAxU"]
[Sun Aug 30 03:08:26.157355 2026] [security2:error] [pid 507246:tid 507413] [client 20.48.250.41:11197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/class.php"] [unique_id "apPk-u8CsCvw81e_I2o5UAAAAr4"]
[Sun Aug 30 03:08:26.167656 2026] [security2:error] [pid 507246:tid 507398] [client 20.104.49.130:64081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/33.php"] [unique_id "apPk-u8CsCvw81e_I2o5UQAAAq8"]
[Sun Aug 30 03:08:26.174004 2026] [security2:error] [pid 507246:tid 507428] [client 158.158.54.35:24807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apPk-u8CsCvw81e_I2o5UwAAAs0"]
[Sun Aug 30 03:08:26.190411 2026] [authz_core:error] [pid 507246:tid 507414] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:26.190685 2026] [authz_core:error] [pid 507246:tid 507414] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:26.208491 2026] [security2:error] [pid 507246:tid 507436] [client 68.155.159.216:61396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-admin/user/index.php"] [unique_id "apPk-u8CsCvw81e_I2o5WQAAAtU"]
[Sun Aug 30 03:08:26.223885 2026] [security2:error] [pid 507246:tid 507464] [client 158.23.147.79:58400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apPk-u8CsCvw81e_I2o5XQAAAvE"]
[Sun Aug 30 03:08:26.230103 2026] [security2:error] [pid 507246:tid 507483] [client 20.220.10.235:46891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/sxxb.php"] [unique_id "apPk-u8CsCvw81e_I2o5XgAAAwQ"]
[Sun Aug 30 03:08:26.231544 2026] [security2:error] [pid 507246:tid 507458] [client 52.139.37.240:17365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/wp-admin.php"] [unique_id "apPk-u8CsCvw81e_I2o5YAAAAus"]
[Sun Aug 30 03:08:26.257135 2026] [authz_core:error] [pid 507246:tid 507486] [client 66.249.66.64:62438] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:26.257430 2026] [authz_core:error] [pid 507246:tid 507486] [client 66.249.66.64:62438] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:26.257795 2026] [security2:error] [pid 507246:tid 507491] [client 20.104.49.130:63273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/dehnl.php"] [unique_id "apPk-u8CsCvw81e_I2o5ZQAAAww"]
[Sun Aug 30 03:08:26.284636 2026] [security2:error] [pid 507246:tid 507475] [client 20.220.10.235:40765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/attack.php"] [unique_id "apPk-u8CsCvw81e_I2o5aAAAAvw"]
[Sun Aug 30 03:08:26.298875 2026] [security2:error] [pid 507246:tid 507457] [client 20.104.50.220:28728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/kjtpoad.php"] [unique_id "apPk-u8CsCvw81e_I2o5aQAAAuo"]
[Sun Aug 30 03:08:26.310954 2026] [security2:error] [pid 507246:tid 507427] [client 20.48.250.41:11097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/8.php"] [unique_id "apPk-u8CsCvw81e_I2o5agAAAsw"]
[Sun Aug 30 03:08:26.338238 2026] [security2:error] [pid 507246:tid 507462] [client 158.23.147.79:60183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apPk-u8CsCvw81e_I2o5awAAAu8"]
[Sun Aug 30 03:08:26.356869 2026] [authz_core:error] [pid 507246:tid 507424] [client 66.249.66.66:38283] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:26.357166 2026] [authz_core:error] [pid 507246:tid 507424] [client 66.249.66.66:38283] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:26.364286 2026] [security2:error] [pid 507246:tid 507467] [client 20.220.10.235:46722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/dx.php"] [unique_id "apPk-u8CsCvw81e_I2o5bwAAAvQ"]
[Sun Aug 30 03:08:26.388365 2026] [security2:error] [pid 507246:tid 507403] [client 20.104.50.220:62797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-mode.php"] [unique_id "apPk-u8CsCvw81e_I2o5dwAAArQ"]
[Sun Aug 30 03:08:26.409867 2026] [security2:error] [pid 507246:tid 507461] [client 74.248.24.12:7491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/cnzcsfwm.php"] [unique_id "apPk-u8CsCvw81e_I2o5fwAAAu4"]
[Sun Aug 30 03:08:26.421797 2026] [authz_core:error] [pid 507246:tid 507379] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:08:26.422066 2026] [authz_core:error] [pid 507246:tid 507379] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:08:26.425993 2026] [security2:error] [pid 507246:tid 507412] [client 20.196.209.81:10098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/b.php"] [unique_id "apPk-u8CsCvw81e_I2o5hgAAAr0"]
[Sun Aug 30 03:08:26.440682 2026] [security2:error] [pid 507246:tid 507434] [client 20.220.10.235:39820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/wk/index.php"] [unique_id "apPk-u8CsCvw81e_I2o5jQAAAtM"]
[Sun Aug 30 03:08:26.450358 2026] [authz_core:error] [pid 507246:tid 507394] [client 66.249.66.75:40481] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:26.450635 2026] [authz_core:error] [pid 507246:tid 507394] [client 66.249.66.75:40481] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:26.453640 2026] [security2:error] [pid 507246:tid 507389] [client 20.48.250.41:11153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/0x0x.php"] [unique_id "apPk-u8CsCvw81e_I2o5kQAAAqY"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:26.488803 2026] [security2:error] [pid 507246:tid 507383] [client 158.23.147.79:16365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/packed.php"] [unique_id "apPk-u8CsCvw81e_I2o5lwAAAqA"]
[Sun Aug 30 03:08:26.492761 2026] [security2:error] [pid 507246:tid 507473] [client 20.220.10.235:46918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPk-u8CsCvw81e_I2o5mgAAAvo"]
[Sun Aug 30 03:08:26.498967 2026] [security2:error] [pid 507246:tid 507491] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/.env.old"] [unique_id "apPk-u8CsCvw81e_I2o5nAAAAww"]
[Sun Aug 30 03:08:26.510569 2026] [security2:error] [pid 507246:tid 507457] [client 20.151.200.44:57863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/tf.php"] [unique_id "apPk-u8CsCvw81e_I2o5ogAAAuo"]
[Sun Aug 30 03:08:26.563343 2026] [security2:error] [pid 507246:tid 507492] [client 52.139.37.240:16666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/wp-config-sample.php"] [unique_id "apPk-u8CsCvw81e_I2o5qgAAAw0"]
[Sun Aug 30 03:08:26.569542 2026] [security2:error] [pid 507246:tid 507413] [client 20.104.50.220:61395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/4index.php"] [unique_id "apPk-u8CsCvw81e_I2o5qwAAAr4"]
[Sun Aug 30 03:08:26.582446 2026] [security2:error] [pid 507246:tid 507445] [client 20.48.250.41:11181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/166.php"] [unique_id "apPk-u8CsCvw81e_I2o5rgAAAt4"]
[Sun Aug 30 03:08:26.597282 2026] [security2:error] [pid 507246:tid 507425] [client 20.220.10.235:40710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/dehnl.php"] [unique_id "apPk-u8CsCvw81e_I2o5tAAAAso"]
[Sun Aug 30 03:08:26.617671 2026] [security2:error] [pid 507246:tid 507485] [client 158.158.54.35:9148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/ws83.php"] [unique_id "apPk-u8CsCvw81e_I2o5wgAAAwY"]
[Sun Aug 30 03:08:26.621755 2026] [security2:error] [pid 507246:tid 507406] [client 4.205.62.107:62100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/bigdump.php"] [unique_id "apPk-u8CsCvw81e_I2o5xQAAArc"]
[Sun Aug 30 03:08:26.626993 2026] [security2:error] [pid 507246:tid 507383] [client 20.220.10.235:46794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/xda.php"] [unique_id "apPk-u8CsCvw81e_I2o5ywAAAqA"]
[Sun Aug 30 03:08:26.636897 2026] [security2:error] [pid 507246:tid 507391] [client 20.104.18.15:18304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/new.php"] [unique_id "apPk-u8CsCvw81e_I2o50AAAAqg"]
[Sun Aug 30 03:08:26.642555 2026] [authz_core:error] [pid 507246:tid 507382] [client 66.249.66.64:56409] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:26.642914 2026] [authz_core:error] [pid 507246:tid 507382] [client 66.249.66.64:56409] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:26.642956 2026] [security2:error] [pid 507246:tid 507475] [client 158.23.147.79:60188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-content/packed.php"] [unique_id "apPk-u8CsCvw81e_I2o51AAAAvw"]
[Sun Aug 30 03:08:26.659762 2026] [security2:error] [pid 507246:tid 507376] [client 20.104.50.220:42278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-admin/priv8.php"] [unique_id "apPk-u8CsCvw81e_I2o52wAAApk"]
[Sun Aug 30 03:08:26.660549 2026] [authz_core:error] [pid 507246:tid 507499] [client 66.249.66.201:49708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:26.660904 2026] [authz_core:error] [pid 507246:tid 507499] [client 66.249.66.201:49708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:26.673535 2026] [security2:error] [pid 507246:tid 507384] [client 20.104.50.220:47070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/geck.php"] [unique_id "apPk-u8CsCvw81e_I2o54gAAAqE"]
[Sun Aug 30 03:08:26.682276 2026] [security2:error] [pid 507246:tid 507448] [client 20.48.251.3:4816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPk-u8CsCvw81e_I2o55AAAAuE"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:26.721265 2026] [security2:error] [pid 507246:tid 507442] [client 20.48.251.3:7040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/zz.php"] [unique_id "apPk-u8CsCvw81e_I2o57wAAAts"]
[Sun Aug 30 03:08:26.724058 2026] [security2:error] [pid 507246:tid 507450] [client 20.104.50.220:5479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/z.php"] [unique_id "apPk-u8CsCvw81e_I2o58QAAAuM"]
[Sun Aug 30 03:08:26.730137 2026] [security2:error] [pid 507246:tid 507481] [client 20.220.10.235:39813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/png.php"] [unique_id "apPk-u8CsCvw81e_I2o58wAAAwI"]
[Sun Aug 30 03:08:26.754992 2026] [security2:error] [pid 507246:tid 507494] [client 20.104.18.15:34718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/w.php"] [unique_id "apPk-u8CsCvw81e_I2o5-wAAAw8"]
[Sun Aug 30 03:08:26.755668 2026] [security2:error] [pid 507246:tid 507389] [client 103.215.74.185:40092] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "162.144.1.153"] [uri "/"] [unique_id "apPk-u8CsCvw81e_I2o59wAAAqY"]
[Sun Aug 30 03:08:26.758176 2026] [security2:error] [pid 507246:tid 507415] [client 20.104.18.15:35169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/she11.php"] [unique_id "apPk-u8CsCvw81e_I2o5_QAAAsA"]
[Sun Aug 30 03:08:26.759159 2026] [security2:error] [pid 507246:tid 507439] [client 20.220.10.235:46890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPk-u8CsCvw81e_I2o5_gAAAtg"]
[Sun Aug 30 03:08:26.760555 2026] [security2:error] [pid 507246:tid 507483] [client 20.48.250.41:11200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/h2a2ck.php"] [unique_id "apPk-u8CsCvw81e_I2o5_wAAAwQ"]
[Sun Aug 30 03:08:26.773020 2026] [security2:error] [pid 507246:tid 507491] [client 68.155.159.216:46075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-includes/Text/about.php"] [unique_id "apPk-u8CsCvw81e_I2o6BAAAAww"]
[Sun Aug 30 03:08:26.774043 2026] [security2:error] [pid 507246:tid 507412] [client 52.139.37.240:17400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gentlefuture.nl"] [uri "/wp-content/packed.php"] [unique_id "apPk-u8CsCvw81e_I2o6BQAAAr0"]
[Sun Aug 30 03:08:26.805968 2026] [security2:error] [pid 507246:tid 507479] [client 20.104.18.15:2014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/fling.php"] [unique_id "apPk-u8CsCvw81e_I2o6GwAAAwA"]
[Sun Aug 30 03:08:26.807621 2026] [security2:error] [pid 507246:tid 507482] [client 20.104.50.220:32563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/file9.php"] [unique_id "apPk-u8CsCvw81e_I2o6HAAAAwM"]
[Sun Aug 30 03:08:26.818503 2026] [security2:error] [pid 507246:tid 507390] [client 158.23.147.79:58406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-l0gin.php"] [unique_id "apPk-u8CsCvw81e_I2o6HwAAAqc"]
[Sun Aug 30 03:08:26.843486 2026] [security2:error] [pid 507246:tid 507442] [client 20.104.18.15:23375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/bo.php"] [unique_id "apPk-u8CsCvw81e_I2o6JgAAAts"]
[Sun Aug 30 03:08:26.852781 2026] [security2:error] [pid 507246:tid 507497] [client 20.196.209.81:11334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/wp-login.php"] [unique_id "apPk-u8CsCvw81e_I2o6KQAAAxI"]
[Sun Aug 30 03:08:26.873048 2026] [security2:error] [pid 507246:tid 507490] [client 20.220.10.235:39816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/txets.php"] [unique_id "apPk-u8CsCvw81e_I2o6MAAAAws"]
[Sun Aug 30 03:08:26.874316 2026] [security2:error] [pid 507246:tid 507415] [client 20.104.18.15:51633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/rxr.php"] [unique_id "apPk-u8CsCvw81e_I2o6MQAAAsA"]
[Sun Aug 30 03:08:26.897057 2026] [security2:error] [pid 507246:tid 507458] [client 20.220.10.235:46953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/t00l.php"] [unique_id "apPk-u8CsCvw81e_I2o6NgAAAus"]
[Sun Aug 30 03:08:26.909210 2026] [security2:error] [pid 507246:tid 507492] [client 103.215.74.185:40092] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "162.144.1.153"] [uri "/"] [unique_id "apPk-u8CsCvw81e_I2o6OAAAAw0"]
[Sun Aug 30 03:08:26.909589 2026] [security2:error] [pid 507246:tid 507462] [client 20.197.61.180:19056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/fix.php"] [unique_id "apPk-u8CsCvw81e_I2o6OgAAAu8"]
[Sun Aug 30 03:08:26.913039 2026] [security2:error] [pid 507246:tid 507474] [client 20.104.50.220:33292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/yamate.php"] [unique_id "apPk-u8CsCvw81e_I2o6PAAAAvs"]
[Sun Aug 30 03:08:26.928731 2026] [security2:error] [pid 507246:tid 507378] [client 74.248.24.12:7477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/word.php"] [unique_id "apPk-u8CsCvw81e_I2o6QAAAAps"]
[Sun Aug 30 03:08:26.936763 2026] [authz_core:error] [pid 507246:tid 507429] [client 66.249.66.71:48179] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:26.937049 2026] [authz_core:error] [pid 507246:tid 507429] [client 66.249.66.71:48179] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:26.937406 2026] [authz_core:error] [pid 507246:tid 507402] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:08:26.937861 2026] [authz_core:error] [pid 507246:tid 507402] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:08:26.953622 2026] [security2:error] [pid 507246:tid 507390] [client 158.23.147.79:58420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apPk-u8CsCvw81e_I2o6UAAAAqc"]
[Sun Aug 30 03:08:26.956706 2026] [security2:error] [pid 507246:tid 507421] [client 20.48.250.41:11173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/error_log.php"] [unique_id "apPk-u8CsCvw81e_I2o6UQAAAsY"]
[Sun Aug 30 03:08:26.992155 2026] [security2:error] [pid 507246:tid 507459] [client 20.104.50.220:16594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp.php"] [unique_id "apPk-u8CsCvw81e_I2o6XgAAAuw"]
[Sun Aug 30 03:08:27.007297 2026] [security2:error] [pid 507246:tid 507496] [client 20.220.10.235:39843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/wp-login.php"] [unique_id "apPk--8CsCvw81e_I2o6ZAAAAxE"]
[Sun Aug 30 03:08:27.009636 2026] [security2:error] [pid 507246:tid 507415] [client 20.104.49.130:52158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/wsd.php"] [unique_id "apPk--8CsCvw81e_I2o6ZwAAAsA"]
[Sun Aug 30 03:08:27.019751 2026] [security2:error] [pid 507246:tid 507423] [client 103.215.74.185:40092] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "162.144.1.153"] [uri "/wp-json/batch/v1"] [unique_id "apPk--8CsCvw81e_I2o6agAAAsg"]
[Sun Aug 30 03:08:27.019993 2026] [security2:error] [pid 507246:tid 507491] [client 20.48.251.3:56340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/f35.php"] [unique_id "apPk--8CsCvw81e_I2o6bQAAAww"]
[Sun Aug 30 03:08:27.030011 2026] [security2:error] [pid 507246:tid 507449] [client 20.220.10.235:46802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/ls.php"] [unique_id "apPk--8CsCvw81e_I2o6cQAAAuI"]
[Sun Aug 30 03:08:27.059744 2026] [security2:error] [pid 507246:tid 507404] [client 20.48.251.3:59275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/phpinfo01.php"] [unique_id "apPk--8CsCvw81e_I2o6egAAArU"]
[Sun Aug 30 03:08:27.110155 2026] [security2:error] [pid 507246:tid 507479] [client 4.205.62.107:25740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/fraro.php"] [unique_id "apPk--8CsCvw81e_I2o6hAAAAwA"]
[Sun Aug 30 03:08:27.117726 2026] [security2:error] [pid 507246:tid 507489] [client 4.205.62.107:22563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/server_info.php"] [unique_id "apPk--8CsCvw81e_I2o6iQAAAwo"]
[Sun Aug 30 03:08:27.121858 2026] [security2:error] [pid 507246:tid 507379] [client 20.151.200.44:55637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/is.php"] [unique_id "apPk--8CsCvw81e_I2o6igAAApw"]
[Sun Aug 30 03:08:27.125038 2026] [security2:error] [pid 507246:tid 507405] [client 103.215.74.185:40092] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "162.144.1.153"] [uri "/wp-json/batch/v1"] [unique_id "apPk--8CsCvw81e_I2o6iwAAArY"]
[Sun Aug 30 03:08:27.128397 2026] [security2:error] [pid 507246:tid 507428] [client 20.48.250.41:11161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/403.php"] [unique_id "apPk--8CsCvw81e_I2o6jwAAAs0"]
[Sun Aug 30 03:08:27.140807 2026] [security2:error] [pid 507246:tid 507415] [client 20.220.10.235:39809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/wp-access.php"] [unique_id "apPk--8CsCvw81e_I2o6kQAAAsA"]
[Sun Aug 30 03:08:27.159152 2026] [security2:error] [pid 507246:tid 507443] [client 20.220.10.235:46792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/css/000.php"] [unique_id "apPk--8CsCvw81e_I2o6mAAAAtw"]
[Sun Aug 30 03:08:27.168338 2026] [security2:error] [pid 507246:tid 507477] [client 68.155.159.216:54231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPk--8CsCvw81e_I2o6mQAAAv4"]
[Sun Aug 30 03:08:27.199089 2026] [security2:error] [pid 507246:tid 507492] [client 4.205.62.107:61793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/test.config.php"] [unique_id "apPk--8CsCvw81e_I2o6oQAAAw0"]
[Sun Aug 30 03:08:27.243941 2026] [security2:error] [pid 507246:tid 507470] [client 158.23.147.79:58431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPk--8CsCvw81e_I2o6qAAAAvc"]
[Sun Aug 30 03:08:27.244828 2026] [security2:error] [pid 507246:tid 507501] [client 20.104.18.15:43312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/classwithtostring.php"] [unique_id "apPk--8CsCvw81e_I2o6qQAAAxY"]
[Sun Aug 30 03:08:27.245705 2026] [security2:error] [pid 507246:tid 507422] [client 20.196.209.81:12676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/aa.php"] [unique_id "apPk--8CsCvw81e_I2o6qgAAAsc"]
[Sun Aug 30 03:08:27.263539 2026] [authz_core:error] [pid 507246:tid 507384] [client 66.249.66.70:50660] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:27.263847 2026] [authz_core:error] [pid 507246:tid 507384] [client 66.249.66.70:50660] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:27.271887 2026] [security2:error] [pid 507246:tid 507425] [client 20.220.10.235:40782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/wp-content/admin.php"] [unique_id "apPk--8CsCvw81e_I2o6rQAAAso"]
[Sun Aug 30 03:08:27.291037 2026] [security2:error] [pid 507246:tid 507398] [client 20.220.10.235:46804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/cy.php"] [unique_id "apPk--8CsCvw81e_I2o6sAAAAq8"]
[Sun Aug 30 03:08:27.298008 2026] [security2:error] [pid 507246:tid 507434] [client 20.48.250.41:11176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/cytyr.php"] [unique_id "apPk--8CsCvw81e_I2o6sgAAAtM"]
[Sun Aug 30 03:08:27.331855 2026] [security2:error] [pid 507246:tid 507454] [client 158.158.54.35:27874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/atex1.php"] [unique_id "apPk--8CsCvw81e_I2o6twAAAuc"]
[Sun Aug 30 03:08:27.352589 2026] [security2:error] [pid 507246:tid 507442] [client 68.155.159.216:61397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-includes/plugins.php"] [unique_id "apPk--8CsCvw81e_I2o6uAAAAts"]
[Sun Aug 30 03:08:27.353054 2026] [security2:error] [pid 507246:tid 507426] [client 158.23.147.79:58411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/ans.php"] [unique_id "apPk--8CsCvw81e_I2o6uQAAAss"]
[Sun Aug 30 03:08:27.373916 2026] [security2:error] [pid 507246:tid 507406] [client 4.205.62.107:35982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/g3.php"] [unique_id "apPk--8CsCvw81e_I2o6uwAAArc"]
[Sun Aug 30 03:08:27.405017 2026] [security2:error] [pid 507246:tid 507392] [client 20.220.10.235:40716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/log.php"] [unique_id "apPk--8CsCvw81e_I2o6xQAAAqk"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:27.422631 2026] [security2:error] [pid 507246:tid 507496] [client 20.220.10.235:46899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/admin.php/pindex.php"] [unique_id "apPk--8CsCvw81e_I2o6ywAAAxE"]
[Sun Aug 30 03:08:27.449673 2026] [security2:error] [pid 507246:tid 507378] [client 158.23.147.79:16341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/worksec.php"] [unique_id "apPk--8CsCvw81e_I2o62AAAAps"]
[Sun Aug 30 03:08:27.455516 2026] [security2:error] [pid 507246:tid 507382] [client 20.104.50.220:52855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/blackcat.php"] [unique_id "apPk--8CsCvw81e_I2o62gAAAp8"]
[Sun Aug 30 03:08:27.459242 2026] [authz_core:error] [pid 507246:tid 507485] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:08:27.459565 2026] [authz_core:error] [pid 507246:tid 507485] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:08:27.477542 2026] [security2:error] [pid 507246:tid 507486] [client 20.48.250.41:11095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/galer.php"] [unique_id "apPk--8CsCvw81e_I2o64QAAAwc"]
[Sun Aug 30 03:08:27.484520 2026] [authz_core:error] [pid 507246:tid 507439] [client 66.249.66.71:49219] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:27.484845 2026] [authz_core:error] [pid 507246:tid 507439] [client 66.249.66.71:49219] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:27.491886 2026] [security2:error] [pid 507246:tid 507437] [client 74.248.24.12:7537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/headerg.php"] [unique_id "apPk--8CsCvw81e_I2o65QAAAtY"]
[Sun Aug 30 03:08:27.540509 2026] [security2:error] [pid 507246:tid 507478] [client 20.220.10.235:40707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/xwpg.php"] [unique_id "apPk--8CsCvw81e_I2o68wAAAv8"]
[Sun Aug 30 03:08:27.554101 2026] [security2:error] [pid 507246:tid 507392] [client 20.220.10.235:46966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/admin.php/csv.php"] [unique_id "apPk--8CsCvw81e_I2o69wAAAqk"]
[Sun Aug 30 03:08:27.572844 2026] [security2:error] [pid 507246:tid 507467] [client 20.104.50.220:62812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-mailcek.php"] [unique_id "apPk--8CsCvw81e_I2o6-wAAAvQ"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:27.640686 2026] [security2:error] [pid 507246:tid 507385] [client 20.196.209.81:13229] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "mail.michaeldanzerphoto.com"] [uri "/c99.php"] [unique_id "apPk--8CsCvw81e_I2o7JAAAAqI"]
[Sun Aug 30 03:08:27.656285 2026] [authz_core:error] [pid 507246:tid 507440] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:27.656733 2026] [authz_core:error] [pid 507246:tid 507440] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:27.657701 2026] [security2:error] [pid 507246:tid 507447] [client 158.23.147.79:16274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/x.php"] [unique_id "apPk--8CsCvw81e_I2o7LAAAAuA"]
[Sun Aug 30 03:08:27.683306 2026] [security2:error] [pid 507246:tid 507384] [client 20.48.250.41:11044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/baixy.php"] [unique_id "apPk--8CsCvw81e_I2o7NgAAAqE"]
[Sun Aug 30 03:08:27.686252 2026] [security2:error] [pid 507246:tid 507464] [client 20.197.61.180:19016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/alfa.php"] [unique_id "apPk--8CsCvw81e_I2o7NwAAAvE"]
[Sun Aug 30 03:08:27.689721 2026] [security2:error] [pid 507246:tid 507488] [client 103.215.74.185:13830] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "162.144.1.153"] [uri "/livewire/update"] [unique_id "apPk--8CsCvw81e_I2o7OAAAAwk"]
[Sun Aug 30 03:08:27.689751 2026] [security2:error] [pid 507246:tid 507481] [client 20.220.10.235:46746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/admin.php/700.php"] [unique_id "apPk--8CsCvw81e_I2o7OgAAAwI"]
[Sun Aug 30 03:08:27.695699 2026] [security2:error] [pid 507246:tid 507443] [client 20.220.10.235:40794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/sxxb.php"] [unique_id "apPk--8CsCvw81e_I2o7PQAAAtw"]
[Sun Aug 30 03:08:27.713008 2026] [security2:error] [pid 507246:tid 507483] [client 20.104.50.220:61408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/5index.php"] [unique_id "apPk--8CsCvw81e_I2o7QgAAAwQ"]
[Sun Aug 30 03:08:27.724008 2026] [security2:error] [pid 507246:tid 507401] [client 20.104.49.130:36754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/ano.php"] [unique_id "apPk--8CsCvw81e_I2o7RAAAArI"]
[Sun Aug 30 03:08:27.756234 2026] [security2:error] [pid 507246:tid 507445] [client 4.205.62.107:62129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/wdf.php"] [unique_id "apPk--8CsCvw81e_I2o7UgAAAt4"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:27.790310 2026] [security2:error] [pid 507246:tid 507489] [client 158.158.54.35:9098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/class-t.api.php"] [unique_id "apPk--8CsCvw81e_I2o7XwAAAwo"]
[Sun Aug 30 03:08:27.798588 2026] [security2:error] [pid 507246:tid 507444] [client 20.104.18.15:18312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/inx.php"] [unique_id "apPk--8CsCvw81e_I2o7ZwAAAt0"]
[Sun Aug 30 03:08:27.808164 2026] [authz_core:error] [pid 507246:tid 507404] [client 66.249.66.69:55919] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:27.808430 2026] [authz_core:error] [pid 507246:tid 507404] [client 66.249.66.69:55919] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:27.812937 2026] [security2:error] [pid 507246:tid 507459] [client 20.104.50.220:63516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/403.php"] [unique_id "apPk--8CsCvw81e_I2o7bwAAAuw"]
[Sun Aug 30 03:08:27.818400 2026] [security2:error] [pid 507246:tid 507384] [client 20.48.251.3:5062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPk--8CsCvw81e_I2o7cQAAAqE"]
[Sun Aug 30 03:08:27.824289 2026] [security2:error] [pid 507246:tid 507491] [client 20.220.10.235:46928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/admin.php/007x.php"] [unique_id "apPk--8CsCvw81e_I2o7cgAAAww"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:27.825118 2026] [security2:error] [pid 507246:tid 507443] [client 20.220.10.235:40685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/dx.php"] [unique_id "apPk--8CsCvw81e_I2o7dQAAAtw"]
[Sun Aug 30 03:08:27.825456 2026] [security2:error] [pid 507246:tid 507488] [client 216.73.216.128:42925] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPk--8CsCvw81e_I2o7cwAAAwk"]
[Sun Aug 30 03:08:27.826674 2026] [security2:error] [pid 507246:tid 507487] [client 20.104.50.220:46408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/gm.php"] [unique_id "apPk--8CsCvw81e_I2o7dgAAAwg"]
[Sun Aug 30 03:08:27.843626 2026] [security2:error] [pid 507246:tid 507456] [client 20.48.250.41:11199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/ava.php"] [unique_id "apPk--8CsCvw81e_I2o7ewAAAuk"]
[Sun Aug 30 03:08:27.855315 2026] [security2:error] [pid 507246:tid 507451] [client 158.23.147.79:60218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-content/x.php"] [unique_id "apPk--8CsCvw81e_I2o7gAAAAuQ"]
[Sun Aug 30 03:08:27.861909 2026] [security2:error] [pid 507246:tid 507430] [client 20.104.50.220:5516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/new/wp-admin/install.php"] [unique_id "apPk--8CsCvw81e_I2o7gQAAAs8"]
[Sun Aug 30 03:08:27.903715 2026] [security2:error] [pid 507246:tid 507502] [client 20.104.18.15:34662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/x.php"] [unique_id "apPk--8CsCvw81e_I2o7iAAAAxc"]
[Sun Aug 30 03:08:27.911576 2026] [authz_core:error] [pid 507246:tid 507425] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:08:27.911895 2026] [authz_core:error] [pid 507246:tid 507425] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc
[Sun Aug 30 03:08:27.914492 2026] [security2:error] [pid 507246:tid 507436] [client 20.104.18.15:35463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/kerang.php"] [unique_id "apPk--8CsCvw81e_I2o7jAAAAtU"]
[Sun Aug 30 03:08:27.944336 2026] [security2:error] [pid 507246:tid 507498] [client 20.104.18.15:2042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/btyuio.php"] [unique_id "apPk--8CsCvw81e_I2o7mgAAAxM"]
[Sun Aug 30 03:08:27.945881 2026] [security2:error] [pid 507246:tid 507385] [client 20.48.251.3:64453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/test.php"] [unique_id "apPk--8CsCvw81e_I2o7nQAAAqI"]
[Sun Aug 30 03:08:27.956132 2026] [security2:error] [pid 507246:tid 507387] [client 20.220.10.235:40795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPk--8CsCvw81e_I2o7oQAAAqQ"]
[Sun Aug 30 03:08:27.958393 2026] [security2:error] [pid 507246:tid 507388] [client 20.220.10.235:46869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/admin.php/heex.php"] [unique_id "apPk--8CsCvw81e_I2o7ogAAAqU"]
[Sun Aug 30 03:08:27.973472 2026] [security2:error] [pid 507246:tid 507460] [client 68.155.159.216:45971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/asd.php"] [unique_id "apPk--8CsCvw81e_I2o7rAAAAu0"]
[Sun Aug 30 03:08:27.975964 2026] [security2:error] [pid 507246:tid 507487] [client 20.104.50.220:31869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/filesss.php"] [unique_id "apPk--8CsCvw81e_I2o7rgAAAwg"]
[Sun Aug 30 03:08:27.982095 2026] [security2:error] [pid 507246:tid 507401] [client 20.104.18.15:23448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/44.php"] [unique_id "apPk--8CsCvw81e_I2o7sAAAArI"]
[Sun Aug 30 03:08:27.991951 2026] [security2:error] [pid 507246:tid 507499] [client 20.48.250.41:11259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/gdn.php"] [unique_id "apPk--8CsCvw81e_I2o7tQAAAxQ"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:28.007600 2026] [security2:error] [pid 507246:tid 507494] [client 74.248.24.12:11886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/admin-header.php"] [unique_id "apPk_O8CsCvw81e_I2o7vAAAAw8"]
[Sun Aug 30 03:08:28.028981 2026] [security2:error] [pid 507246:tid 507457] [client 20.104.18.15:51589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weaponizedentertainment.com"] [uri "/reviall.php"] [unique_id "apPk_O8CsCvw81e_I2o7xwAAAuo"]
[Sun Aug 30 03:08:28.048892 2026] [security2:error] [pid 507246:tid 507489] [client 20.196.209.81:12715] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "mail.michaeldanzerphoto.com"] [uri "/c99.php"] [unique_id "apPk_O8CsCvw81e_I2o70AAAAwo"]
[Sun Aug 30 03:08:28.050035 2026] [security2:error] [pid 507246:tid 507423] [client 20.104.50.220:32862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/upppp.php"] [unique_id "apPk_O8CsCvw81e_I2o70QAAAsg"]
[Sun Aug 30 03:08:28.060336 2026] [security2:error] [pid 507246:tid 507459] [client 103.215.74.185:40092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.144.1.153"] [uri "/index.php"] [unique_id "apPk_O8CsCvw81e_I2o71AAAAuw"]
[Sun Aug 30 03:08:28.074073 2026] [security2:error] [pid 507246:tid 507422] [client 20.104.49.130:48048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/ty.php"] [unique_id "apPk_O8CsCvw81e_I2o71wAAAsc"]
[Sun Aug 30 03:08:28.095587 2026] [security2:error] [pid 507246:tid 507380] [client 20.220.10.235:40813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/xda.php"] [unique_id "apPk_O8CsCvw81e_I2o72AAAAp0"]
[Sun Aug 30 03:08:28.114787 2026] [security2:error] [pid 507246:tid 507488] [client 20.220.10.235:46900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/tf.php"] [unique_id "apPk_O8CsCvw81e_I2o73wAAAwk"]
[Sun Aug 30 03:08:28.134320 2026] [security2:error] [pid 507246:tid 507378] [client 20.104.50.220:17304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/abcd.php"] [unique_id "apPk_O8CsCvw81e_I2o75QAAAps"]
[Sun Aug 30 03:08:28.134697 2026] [authz_core:error] [pid 507246:tid 507414] [client 66.249.66.32:39770] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:28.134980 2026] [authz_core:error] [pid 507246:tid 507414] [client 66.249.66.32:39770] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:28.135911 2026] [security2:error] [pid 507246:tid 507424] [client 20.104.49.130:52476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/run.php"] [unique_id "apPk_O8CsCvw81e_I2o75gAAAsk"]
[Sun Aug 30 03:08:28.152671 2026] [security2:error] [pid 507246:tid 507451] [client 20.48.250.41:11160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/f2.php"] [unique_id "apPk_O8CsCvw81e_I2o76gAAAuQ"]
[Sun Aug 30 03:08:28.154072 2026] [security2:error] [pid 507246:tid 507395] [client 20.151.200.44:59549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/update/da222.php"] [unique_id "apPk_O8CsCvw81e_I2o76wAAAqw"]
[Sun Aug 30 03:08:28.160224 2026] [security2:error] [pid 507246:tid 507449] [client 20.48.251.3:60515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/api.php"] [unique_id "apPk_O8CsCvw81e_I2o77gAAAuI"]
[Sun Aug 30 03:08:28.177146 2026] [security2:error] [pid 507246:tid 507429] [client 158.23.147.79:60160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPk_O8CsCvw81e_I2o78AAAAs4"]
[Sun Aug 30 03:08:28.201630 2026] [security2:error] [pid 507246:tid 507430] [client 20.48.251.3:59376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/cxc.php"] [unique_id "apPk_O8CsCvw81e_I2o79QAAAs8"]
[Sun Aug 30 03:08:28.231139 2026] [security2:error] [pid 507246:tid 507462] [client 20.220.10.235:40745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPk_O8CsCvw81e_I2o7_wAAAu8"]
[Sun Aug 30 03:08:28.239841 2026] [proxy_http:error] [pid 507246:tid 507457] (20014)Internal error (specific information not available): [client 34.125.55.247:63758] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:28.239857 2026] [proxy:error] [pid 507246:tid 507457] [client 34.125.55.247:63758] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/cgi-bin/test
[Sun Aug 30 03:08:28.246730 2026] [proxy_http:error] [pid 507246:tid 507457] (20014)Internal error (specific information not available): [client 34.125.55.247:63758] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:28.246753 2026] [proxy:error] [pid 507246:tid 507457] [client 34.125.55.247:63758] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml
[Sun Aug 30 03:08:28.246908 2026] [security2:error] [pid 507246:tid 507457] [client 34.125.55.247:63758] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "502"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/502.shtml"] [unique_id "apPk_O8CsCvw81e_I2o7_AAAAuo"]
[Sun Aug 30 03:08:28.248858 2026] [authz_core:error] [pid 507246:tid 507411] [client 66.249.66.67:41095] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:28.249126 2026] [authz_core:error] [pid 507246:tid 507411] [client 66.249.66.67:41095] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:28.250704 2026] [security2:error] [pid 507246:tid 507467] [client 158.158.54.35:9627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/archive.php"] [unique_id "apPk_O8CsCvw81e_I2o8BAAAAvQ"]
[Sun Aug 30 03:08:28.257523 2026] [security2:error] [pid 507246:tid 507388] [client 20.220.10.235:46883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/update/da222.php"] [unique_id "apPk_O8CsCvw81e_I2o8BQAAAqU"]
[Sun Aug 30 03:08:28.265999 2026] [security2:error] [pid 507246:tid 507380] [client 20.104.49.130:45731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/reop3.php"] [unique_id "apPk_O8CsCvw81e_I2o8BwAAAp0"]
[Sun Aug 30 03:08:28.277328 2026] [security2:error] [pid 507246:tid 507384] [client 4.205.62.107:62441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/hosty.php"] [unique_id "apPk_O8CsCvw81e_I2o8CAAAAqE"]
[Sun Aug 30 03:08:28.287285 2026] [security2:error] [pid 507246:tid 507489] [client 4.205.62.107:25861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/thui.php"] [unique_id "apPk_O8CsCvw81e_I2o8CwAAAwo"]
[Sun Aug 30 03:08:28.310495 2026] [security2:error] [pid 507246:tid 507427] [client 20.48.250.41:11221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/grsiuk.php"] [unique_id "apPk_O8CsCvw81e_I2o8DAAAAsw"]
[Sun Aug 30 03:08:28.321315 2026] [security2:error] [pid 507246:tid 507378] [client 68.155.159.216:54266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/about.php"] [unique_id "apPk_O8CsCvw81e_I2o8DgAAAps"]
[Sun Aug 30 03:08:28.336021 2026] [security2:error] [pid 507246:tid 507491] [client 4.205.62.107:58433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/gecko-litespeed.php"] [unique_id "apPk_O8CsCvw81e_I2o8EQAAAww"]
[Sun Aug 30 03:08:28.336343 2026] [security2:error] [pid 507246:tid 507383] [client 158.23.147.79:16329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/log-mama/function.php"] [unique_id "apPk_O8CsCvw81e_I2o8EgAAAqA"]
[Sun Aug 30 03:08:28.361088 2026] [security2:error] [pid 507246:tid 507405] [client 20.220.10.235:39834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/t00l.php"] [unique_id "apPk_O8CsCvw81e_I2o8FAAAArY"]
[Sun Aug 30 03:08:28.386080 2026] [security2:error] [pid 507246:tid 507377] [client 20.220.10.235:46862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/qi.php"] [unique_id "apPk_O8CsCvw81e_I2o8GgAAApo"]
[Sun Aug 30 03:08:28.414941 2026] [security2:error] [pid 507246:tid 507417] [client 20.197.61.180:9375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/wp-blog-header.php"] [unique_id "apPk_O8CsCvw81e_I2o8IQAAAsI"]
[Sun Aug 30 03:08:28.447014 2026] [security2:error] [pid 507246:tid 507401] [client 20.196.209.81:12672] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "mail.michaeldanzerphoto.com"] [uri "/c99.php"] [unique_id "apPk_O8CsCvw81e_I2o8NAAAArI"]
[Sun Aug 30 03:08:28.450802 2026] [authz_core:error] [pid 507246:tid 507502] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:08:28.451089 2026] [authz_core:error] [pid 507246:tid 507502] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:08:28.488286 2026] [security2:error] [pid 507246:tid 507427] [client 20.48.250.41:11075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/wp-scr1pts.php"] [unique_id "apPk_O8CsCvw81e_I2o8QAAAAsw"]
[Sun Aug 30 03:08:28.492467 2026] [security2:error] [pid 507246:tid 507448] [client 20.220.10.235:40785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/ls.php"] [unique_id "apPk_O8CsCvw81e_I2o8QwAAAuE"]
[Sun Aug 30 03:08:28.521585 2026] [security2:error] [pid 507246:tid 507466] [client 20.220.10.235:46924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/px.php"] [unique_id "apPk_O8CsCvw81e_I2o8SwAAAvM"]
[Sun Aug 30 03:08:28.527572 2026] [security2:error] [pid 507246:tid 507445] [client 4.205.62.107:36018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/wp-konfig.php"] [unique_id "apPk_O8CsCvw81e_I2o8TgAAAt4"]
[Sun Aug 30 03:08:28.530797 2026] [security2:error] [pid 507246:tid 507494] [client 158.23.147.79:16277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/bk/index.php"] [unique_id "apPk_O8CsCvw81e_I2o8TwAAAw8"]
[Sun Aug 30 03:08:28.590111 2026] [security2:error] [pid 507246:tid 507495] [client 74.248.24.12:14831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/disagraep.php"] [unique_id "apPk_O8CsCvw81e_I2o8ZAAAAxA"]
[Sun Aug 30 03:08:28.599911 2026] [security2:error] [pid 507246:tid 507412] [client 20.104.50.220:28710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/sure.php"] [unique_id "apPk_O8CsCvw81e_I2o8bAAAAr0"]
[Sun Aug 30 03:08:28.600637 2026] [security2:error] [pid 507246:tid 507484] [client 68.155.159.216:62057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apPk_O8CsCvw81e_I2o8bQAAAwU"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:28.621601 2026] [security2:error] [pid 507246:tid 507478] [client 20.151.200.44:55662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/od.php"] [unique_id "apPk_O8CsCvw81e_I2o8fQAAAv8"]
[Sun Aug 30 03:08:28.630453 2026] [security2:error] [pid 507246:tid 507469] [client 20.220.10.235:40730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/css/000.php"] [unique_id "apPk_O8CsCvw81e_I2o8ggAAAvY"]
[Sun Aug 30 03:08:28.635775 2026] [security2:error] [pid 507246:tid 507395] [client 158.23.147.79:16379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cherylvalk.com"] [uri "/first.php"] [unique_id "apPk_O8CsCvw81e_I2o8hAAAAqw"]
[Sun Aug 30 03:08:28.639572 2026] [security2:error] [pid 507246:tid 507494] [client 20.104.18.15:43986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPk_O8CsCvw81e_I2o8hgAAAw8"]
[Sun Aug 30 03:08:28.655626 2026] [security2:error] [pid 507246:tid 507475] [client 20.220.10.235:46852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/is.php"] [unique_id "apPk_O8CsCvw81e_I2o8jQAAAvw"]
[Sun Aug 30 03:08:28.662294 2026] [authz_core:error] [pid 507246:tid 507415] [client 66.249.66.200:64829] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:28.662595 2026] [authz_core:error] [pid 507246:tid 507415] [client 66.249.66.200:64829] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:28.686936 2026] [security2:error] [pid 507246:tid 507423] [client 20.48.250.41:11212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/num.php"] [unique_id "apPk_O8CsCvw81e_I2o8lgAAAsg"]
[Sun Aug 30 03:08:28.714770 2026] [security2:error] [pid 507246:tid 507402] [client 158.158.54.35:5191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/bless.php"] [unique_id "apPk_O8CsCvw81e_I2o8ngAAArM"]
[Sun Aug 30 03:08:28.727129 2026] [security2:error] [pid 507246:tid 507380] [client 20.104.50.220:62799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-config-blog.php"] [unique_id "apPk_O8CsCvw81e_I2o8oQAAAp0"]
[Sun Aug 30 03:08:28.758480 2026] [security2:error] [pid 507246:tid 507458] [client 20.220.10.235:40828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/cy.php"] [unique_id "apPk_O8CsCvw81e_I2o8qAAAAus"]
[Sun Aug 30 03:08:28.788466 2026] [access_compat:error] [pid 507246:tid 507425] [client 143.110.213.72:39470] AH01797: client denied by server configuration: proxy:http://127.0.0.1:8080/server-status
[Sun Aug 30 03:08:28.793773 2026] [security2:error] [pid 507246:tid 507411] [client 20.220.10.235:46878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/od.php"] [unique_id "apPk_O8CsCvw81e_I2o8uwAAArw"]
[Sun Aug 30 03:08:28.800894 2026] [security2:error] [pid 507246:tid 507430] [client 20.104.49.130:63502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/mac.php"] [unique_id "apPk_O8CsCvw81e_I2o8wwAAAs8"]
[Sun Aug 30 03:08:28.834099 2026] [security2:error] [pid 507246:tid 507376] [client 216.73.216.128:18339] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPk_O8CsCvw81e_I2o8yQAAApk"]
[Sun Aug 30 03:08:28.841417 2026] [security2:error] [pid 507246:tid 507414] [client 20.48.250.41:11073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/a4.php"] [unique_id "apPk_O8CsCvw81e_I2o8ywAAAr8"]
[Sun Aug 30 03:08:28.859583 2026] [security2:error] [pid 507246:tid 507438] [client 20.196.209.81:11355] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "mail.michaeldanzerphoto.com"] [uri "/c99.php"] [unique_id "apPk_O8CsCvw81e_I2o80wAAAtc"]
[Sun Aug 30 03:08:28.890611 2026] [security2:error] [pid 507246:tid 507392] [client 20.220.10.235:40822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/admin.php/pindex.php"] [unique_id "apPk_O8CsCvw81e_I2o83AAAAqk"]
[Sun Aug 30 03:08:28.893861 2026] [security2:error] [pid 507246:tid 507479] [client 4.205.62.107:62030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/bb.php"] [unique_id "apPk_O8CsCvw81e_I2o83QAAAwA"]
[Sun Aug 30 03:08:28.894474 2026] [security2:error] [pid 507246:tid 507458] [client 20.104.50.220:61398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/6index.php"] [unique_id "apPk_O8CsCvw81e_I2o83gAAAus"]
[Sun Aug 30 03:08:28.922133 2026] [security2:error] [pid 507246:tid 507448] [client 20.220.10.235:46834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/wp-the.php"] [unique_id "apPk_O8CsCvw81e_I2o85wAAAuE"]
[Sun Aug 30 03:08:28.929416 2026] [authz_core:error] [pid 507246:tid 507395] [client 216.73.216.128:22035] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:28.929693 2026] [authz_core:error] [pid 507246:tid 507395] [client 216.73.216.128:22035] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:28.933032 2026] [security2:error] [pid 507246:tid 507450] [client 20.104.18.15:18324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/vpn.php"] [unique_id "apPk_O8CsCvw81e_I2o87gAAAuM"]
[Sun Aug 30 03:08:28.964463 2026] [security2:error] [pid 507246:tid 507449] [client 20.48.251.3:4840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/agg.php"] [unique_id "apPk_O8CsCvw81e_I2o8_gAAAuI"]
[Sun Aug 30 03:08:28.965245 2026] [security2:error] [pid 507246:tid 507468] [client 20.104.50.220:46164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/file4.php"] [unique_id "apPk_O8CsCvw81e_I2o8_wAAAvU"]
[Sun Aug 30 03:08:28.965882 2026] [security2:error] [pid 507246:tid 507388] [client 20.104.50.220:42805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-includes/priv8.php"] [unique_id "apPk_O8CsCvw81e_I2o9AAAAAqU"]
[Sun Aug 30 03:08:28.967774 2026] [security2:error] [pid 507246:tid 507503] [client 20.48.250.41:11250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/tfm.php"] [unique_id "apPk_O8CsCvw81e_I2o9BAAAAxg"]
[Sun Aug 30 03:08:28.972387 2026] [authz_core:error] [pid 507246:tid 507441] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:08:28.972709 2026] [authz_core:error] [pid 507246:tid 507441] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale
[Sun Aug 30 03:08:29.015302 2026] [security2:error] [pid 507246:tid 507497] [client 20.104.50.220:5607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/y.php"] [unique_id "apPk_e8CsCvw81e_I2o9EwAAAxI"]
[Sun Aug 30 03:08:29.023939 2026] [security2:error] [pid 507246:tid 507495] [client 20.220.10.235:40793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/admin.php/csv.php"] [unique_id "apPk_e8CsCvw81e_I2o9FgAAAxA"]
[Sun Aug 30 03:08:29.045028 2026] [security2:error] [pid 507246:tid 507392] [client 20.104.18.15:34733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/ssla.php"] [unique_id "apPk_e8CsCvw81e_I2o9HAAAAqk"]
[Sun Aug 30 03:08:29.053147 2026] [security2:error] [pid 507246:tid 507491] [client 20.104.18.15:35461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/m.php"] [unique_id "apPk_e8CsCvw81e_I2o9IAAAAww"]
[Sun Aug 30 03:08:29.058209 2026] [security2:error] [pid 507246:tid 507427] [client 20.220.10.235:46921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/wt.php"] [unique_id "apPk_e8CsCvw81e_I2o9IgAAAsw"]
[Sun Aug 30 03:08:29.070981 2026] [authz_core:error] [pid 507246:tid 507416] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:29.071263 2026] [authz_core:error] [pid 507246:tid 507416] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:29.081721 2026] [security2:error] [pid 507246:tid 507387] [client 20.104.18.15:2040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/dehnl.php"] [unique_id "apPk_e8CsCvw81e_I2o9JgAAAqQ"]
[Sun Aug 30 03:08:29.098226 2026] [security2:error] [pid 507246:tid 507478] [client 74.248.24.12:6809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/v4.php"] [unique_id "apPk_e8CsCvw81e_I2o9JwAAAv8"]
[Sun Aug 30 03:08:29.123278 2026] [security2:error] [pid 507246:tid 507476] [client 20.48.250.41:11234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/Geforce.php"] [unique_id "apPk_e8CsCvw81e_I2o9NAAAAv0"]
[Sun Aug 30 03:08:29.130285 2026] [security2:error] [pid 507246:tid 507503] [client 20.104.50.220:32067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/file88.php"] [unique_id "apPk_e8CsCvw81e_I2o9NgAAAxg"]
[Sun Aug 30 03:08:29.131394 2026] [security2:error] [pid 507246:tid 507452] [client 20.104.18.15:23474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/h2.php"] [unique_id "apPk_e8CsCvw81e_I2o9NwAAAuU"]
[Sun Aug 30 03:08:29.154966 2026] [security2:error] [pid 507246:tid 507487] [client 20.220.10.235:40738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/admin.php/700.php"] [unique_id "apPk_e8CsCvw81e_I2o9PAAAAwg"]
[Sun Aug 30 03:08:29.154994 2026] [security2:error] [pid 507246:tid 507391] [client 20.197.61.180:8777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/s.php"] [unique_id "apPk_e8CsCvw81e_I2o9PQAAAqg"]
[Sun Aug 30 03:08:29.183619 2026] [security2:error] [pid 507246:tid 507432] [client 20.104.50.220:33084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/up.php"] [unique_id "apPk_e8CsCvw81e_I2o9QgAAAtE"]
[Sun Aug 30 03:08:29.199091 2026] [security2:error] [pid 507246:tid 507397] [client 20.220.10.235:46945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/im.php"] [unique_id "apPk_e8CsCvw81e_I2o9RQAAAq4"]
[Sun Aug 30 03:08:29.235780 2026] [security2:error] [pid 507246:tid 507467] [client 20.48.251.3:64412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/cloud.php"] [unique_id "apPk_e8CsCvw81e_I2o9TAAAAvQ"]
[Sun Aug 30 03:08:29.254764 2026] [security2:error] [pid 507246:tid 507430] [client 158.158.54.35:5243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/sagax1.php"] [unique_id "apPk_e8CsCvw81e_I2o9TQAAAs8"]
[Sun Aug 30 03:08:29.256896 2026] [security2:error] [pid 507246:tid 507477] [client 20.48.250.41:11032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/click.php"] [unique_id "apPk_e8CsCvw81e_I2o9TgAAAv4"]
[Sun Aug 30 03:08:29.273454 2026] [security2:error] [pid 507246:tid 507482] [client 20.104.50.220:17283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/a1.php"] [unique_id "apPk_e8CsCvw81e_I2o9UQAAAwM"]
[Sun Aug 30 03:08:29.288176 2026] [security2:error] [pid 507246:tid 507406] [client 20.220.10.235:40774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/admin.php/007x.php"] [unique_id "apPk_e8CsCvw81e_I2o9UwAAArc"]
[Sun Aug 30 03:08:29.292503 2026] [security2:error] [pid 507246:tid 507436] [client 20.196.209.81:12690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/test1.php"] [unique_id "apPk_e8CsCvw81e_I2o9VgAAAtU"]
[Sun Aug 30 03:08:29.296386 2026] [security2:error] [pid 507246:tid 507437] [client 20.48.251.3:13383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/temp.php"] [unique_id "apPk_e8CsCvw81e_I2o9VwAAAtY"]
[Sun Aug 30 03:08:29.329889 2026] [security2:error] [pid 507246:tid 507448] [client 68.155.159.216:45901] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.localconnections.info"] [uri "/1.php"] [unique_id "apPk_e8CsCvw81e_I2o9WQAAAuE"]
[Sun Aug 30 03:08:29.329893 2026] [security2:error] [pid 507246:tid 507450] [client 20.220.10.235:46740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/file.php"] [unique_id "apPk_e8CsCvw81e_I2o9WgAAAuM"]
[Sun Aug 30 03:08:29.329964 2026] [security2:error] [pid 507246:tid 507448] [client 68.155.159.216:45901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/1.php"] [unique_id "apPk_e8CsCvw81e_I2o9WQAAAuE"]
[Sun Aug 30 03:08:29.352035 2026] [security2:error] [pid 507246:tid 507387] [client 20.48.251.3:59297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/oiko6u.php"] [unique_id "apPk_e8CsCvw81e_I2o9XAAAAqQ"]
[Sun Aug 30 03:08:29.380690 2026] [security2:error] [pid 507246:tid 507395] [client 216.73.216.128:31509] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPk_e8CsCvw81e_I2o9XwAAAqw"]
[Sun Aug 30 03:08:29.414711 2026] [security2:error] [pid 507246:tid 507494] [client 20.220.10.235:40810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/admin.php/heex.php"] [unique_id "apPk_e8CsCvw81e_I2o9aAAAAw8"]
[Sun Aug 30 03:08:29.425552 2026] [security2:error] [pid 507246:tid 507454] [client 4.205.62.107:54433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/pass4.php"] [unique_id "apPk_e8CsCvw81e_I2o9bgAAAuc"]
[Sun Aug 30 03:08:29.438915 2026] [security2:error] [pid 507246:tid 507385] [client 4.205.62.107:25858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/lala.php"] [unique_id "apPk_e8CsCvw81e_I2o9fAAAAqI"]
[Sun Aug 30 03:08:29.442240 2026] [security2:error] [pid 507246:tid 507474] [client 68.155.159.216:55094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apPk_e8CsCvw81e_I2o9fgAAAvs"]
[Sun Aug 30 03:08:29.442934 2026] [authz_core:error] [pid 507246:tid 507397] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2F%2Fopt
[Sun Aug 30 03:08:29.443228 2026] [authz_core:error] [pid 507246:tid 507397] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2F%2Fopt
[Sun Aug 30 03:08:29.461080 2026] [security2:error] [pid 507246:tid 507405] [client 20.48.250.41:11099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/ms.php"] [unique_id "apPk_e8CsCvw81e_I2o9ggAAArY"]
[Sun Aug 30 03:08:29.467067 2026] [security2:error] [pid 507246:tid 507402] [client 20.220.10.235:46826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/ca.php"] [unique_id "apPk_e8CsCvw81e_I2o9gwAAArM"]
[Sun Aug 30 03:08:29.478976 2026] [security2:error] [pid 507246:tid 507444] [client 4.205.62.107:61749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/goods.php"] [unique_id "apPk_e8CsCvw81e_I2o9hwAAAt0"]
[Sun Aug 30 03:08:29.498568 2026] [authz_core:error] [pid 507246:tid 507448] [client 66.249.66.70:40871] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:29.498854 2026] [authz_core:error] [pid 507246:tid 507448] [client 66.249.66.70:40871] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:29.551082 2026] [security2:error] [pid 507246:tid 507396] [client 20.220.10.235:40724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/tf.php"] [unique_id "apPk_e8CsCvw81e_I2o9pQAAAq0"]
[Sun Aug 30 03:08:29.599184 2026] [security2:error] [pid 507246:tid 507475] [client 74.248.24.12:23953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/1index.php"] [unique_id "apPk_e8CsCvw81e_I2o9uAAAAvw"]
[Sun Aug 30 03:08:29.599862 2026] [security2:error] [pid 507246:tid 507430] [client 20.220.10.235:46968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/pb.php"] [unique_id "apPk_e8CsCvw81e_I2o9uwAAAs8"]
[Sun Aug 30 03:08:29.601156 2026] [security2:error] [pid 507246:tid 507467] [client 20.48.250.41:11184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/zxekqlxb.php"] [unique_id "apPk_e8CsCvw81e_I2o9vgAAAvQ"]
[Sun Aug 30 03:08:29.664551 2026] [security2:error] [pid 507246:tid 507454] [client 94.154.43.164:58508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.calvarycrosssa.com"] [uri "/.env"] [unique_id "apPk_e8CsCvw81e_I2o92gAAAuc"]
[Sun Aug 30 03:08:29.667514 2026] [security2:error] [pid 507246:tid 507446] [client 4.205.62.107:36000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/25.php"] [unique_id "apPk_e8CsCvw81e_I2o93QAAAt8"]
[Sun Aug 30 03:08:29.668404 2026] [authz_core:error] [pid 507246:tid 507445] [client 66.249.66.78:44443] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:29.668681 2026] [authz_core:error] [pid 507246:tid 507445] [client 66.249.66.78:44443] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:29.681924 2026] [security2:error] [pid 507246:tid 507412] [client 20.220.10.235:39842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/update/da222.php"] [unique_id "apPk_e8CsCvw81e_I2o94gAAAr0"]
[Sun Aug 30 03:08:29.682185 2026] [security2:error] [pid 507246:tid 507470] [client 20.104.49.130:57701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/crgio.php"] [unique_id "apPk_e8CsCvw81e_I2o94AAAAvc"]
[Sun Aug 30 03:08:29.700956 2026] [security2:error] [pid 507246:tid 507490] [client 20.196.209.81:10069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/data.php"] [unique_id "apPk_e8CsCvw81e_I2o95wAAAws"]
[Sun Aug 30 03:08:29.733081 2026] [security2:error] [pid 507246:tid 507420] [client 20.220.10.235:46929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/pk.php"] [unique_id "apPk_e8CsCvw81e_I2o97gAAAsU"]
[Sun Aug 30 03:08:29.753987 2026] [security2:error] [pid 507246:tid 507384] [client 20.104.50.220:52812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/dl.php"] [unique_id "apPk_e8CsCvw81e_I2o98gAAAqE"]
[Sun Aug 30 03:08:29.758943 2026] [security2:error] [pid 507246:tid 507458] [client 20.48.250.41:11187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/init.php"] [unique_id "apPk_e8CsCvw81e_I2o99QAAAus"]
[Sun Aug 30 03:08:29.773907 2026] [authz_core:error] [pid 507246:tid 507378] [client 66.249.66.64:56409] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:29.774208 2026] [authz_core:error] [pid 507246:tid 507378] [client 66.249.66.64:56409] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:29.775462 2026] [security2:error] [pid 507246:tid 507405] [client 158.158.54.35:24810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/wpc.php"] [unique_id "apPk_e8CsCvw81e_I2o9_AAAArY"]
[Sun Aug 30 03:08:29.794748 2026] [security2:error] [pid 507246:tid 507476] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/.env.swp"] [unique_id "apPk_e8CsCvw81e_I2o-CQAAAv0"]
[Sun Aug 30 03:08:29.812043 2026] [security2:error] [pid 507246:tid 507464] [client 20.220.10.235:40819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/qi.php"] [unique_id "apPk_e8CsCvw81e_I2o-EwAAAvE"]
[Sun Aug 30 03:08:29.862615 2026] [security2:error] [pid 507246:tid 507484] [client 68.155.159.216:60912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/goat1.php"] [unique_id "apPk_e8CsCvw81e_I2o-JQAAAwU"]
[Sun Aug 30 03:08:29.863931 2026] [security2:error] [pid 507246:tid 507503] [client 20.220.10.235:46956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/ft.php"] [unique_id "apPk_e8CsCvw81e_I2o-JwAAAxg"]
[Sun Aug 30 03:08:29.881098 2026] [security2:error] [pid 507246:tid 507481] [client 20.197.61.180:19052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/php.php"] [unique_id "apPk_e8CsCvw81e_I2o-KgAAAwI"]
[Sun Aug 30 03:08:29.905364 2026] [security2:error] [pid 507246:tid 507426] [client 20.104.50.220:29146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-thumbs.php"] [unique_id "apPk_e8CsCvw81e_I2o-LAAAAss"]
[Sun Aug 30 03:08:29.916662 2026] [authz_core:error] [pid 507246:tid 507383] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2F%2Fproc
[Sun Aug 30 03:08:29.916936 2026] [authz_core:error] [pid 507246:tid 507383] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2F%2Fproc
[Sun Aug 30 03:08:29.921449 2026] [security2:error] [pid 507246:tid 507401] [client 20.48.250.41:11151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/term.php"] [unique_id "apPk_e8CsCvw81e_I2o-NwAAArI"]
[Sun Aug 30 03:08:29.924148 2026] [security2:error] [pid 507246:tid 507447] [client 20.104.18.15:43968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/5PJcpMFsD8B.php"] [unique_id "apPk_e8CsCvw81e_I2o-OgAAAuA"]
[Sun Aug 30 03:08:29.944615 2026] [security2:error] [pid 507246:tid 507387] [client 20.220.10.235:39831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/px.php"] [unique_id "apPk_e8CsCvw81e_I2o-SAAAAqQ"]
[Sun Aug 30 03:08:29.966071 2026] [security2:error] [pid 507246:tid 507462] [client 20.104.49.130:59523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/yawa.php"] [unique_id "apPk_e8CsCvw81e_I2o-UQAAAu8"]
[Sun Aug 30 03:08:29.991194 2026] [security2:error] [pid 507246:tid 507477] [client 20.220.10.235:46958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/wp-ver.php"] [unique_id "apPk_e8CsCvw81e_I2o-WgAAAv4"]
[Sun Aug 30 03:08:29.998494 2026] [authz_core:error] [pid 507246:tid 507396] [client 66.249.66.78:61567] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:29.998841 2026] [authz_core:error] [pid 507246:tid 507396] [client 66.249.66.78:61567] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:30.033027 2026] [security2:error] [pid 507246:tid 507436] [client 4.205.62.107:62140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/file59.php"] [unique_id "apPk_u8CsCvw81e_I2o-agAAAtU"]
[Sun Aug 30 03:08:30.052897 2026] [security2:error] [pid 507246:tid 507437] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/.env~"] [unique_id "apPk_u8CsCvw81e_I2o-dAAAAtY"]
[Sun Aug 30 03:08:30.068277 2026] [authz_core:error] [pid 507246:tid 507461] [client 66.249.66.73:64646] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:30.068573 2026] [authz_core:error] [pid 507246:tid 507461] [client 66.249.66.73:64646] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:30.077492 2026] [security2:error] [pid 507246:tid 507385] [client 20.104.50.220:61494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/7index.php"] [unique_id "apPk_u8CsCvw81e_I2o-ewAAAqI"]
[Sun Aug 30 03:08:30.077714 2026] [security2:error] [pid 507246:tid 507446] [client 20.104.18.15:18257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/shiny.php"] [unique_id "apPk_u8CsCvw81e_I2o-fAAAAt8"]
[Sun Aug 30 03:08:30.083336 2026] [security2:error] [pid 507246:tid 507474] [client 20.151.200.44:46958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/wt.php"] [unique_id "apPk_u8CsCvw81e_I2o-fQAAAvs"]
[Sun Aug 30 03:08:30.083963 2026] [security2:error] [pid 507246:tid 507499] [client 20.220.10.235:39819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/is.php"] [unique_id "apPk_u8CsCvw81e_I2o-fgAAAxQ"]
[Sun Aug 30 03:08:30.096471 2026] [security2:error] [pid 507246:tid 507442] [client 20.104.49.130:43323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/133.php"] [unique_id "apPk_u8CsCvw81e_I2o-fwAAAts"]
[Sun Aug 30 03:08:30.104456 2026] [security2:error] [pid 507246:tid 507397] [client 20.104.50.220:42787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/00.php"] [unique_id "apPk_u8CsCvw81e_I2o-ggAAAq4"]
[Sun Aug 30 03:08:30.104573 2026] [security2:error] [pid 507246:tid 507432] [client 20.104.50.220:46644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/520.php"] [unique_id "apPk_u8CsCvw81e_I2o-gQAAAtE"]
[Sun Aug 30 03:08:30.110632 2026] [security2:error] [pid 507246:tid 507429] [client 20.48.251.3:5108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/requirements.php"] [unique_id "apPk_u8CsCvw81e_I2o-hgAAAs4"]
[Sun Aug 30 03:08:30.119609 2026] [security2:error] [pid 507246:tid 507496] [client 20.220.10.235:46894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/ah24.php"] [unique_id "apPk_u8CsCvw81e_I2o-iwAAAxE"]
[Sun Aug 30 03:08:30.121723 2026] [security2:error] [pid 507246:tid 507486] [client 216.73.216.128:31509] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPk_u8CsCvw81e_I2o-jAAAAwc"]
[Sun Aug 30 03:08:30.122615 2026] [security2:error] [pid 507246:tid 507475] [client 20.196.209.81:13200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/classwithtostring.php"] [unique_id "apPk_u8CsCvw81e_I2o-jQAAAvw"]
[Sun Aug 30 03:08:30.131123 2026] [security2:error] [pid 507246:tid 507479] [client 74.248.24.12:8207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/exif.php"] [unique_id "apPk_u8CsCvw81e_I2o-jwAAAwA"]
[Sun Aug 30 03:08:30.145412 2026] [security2:error] [pid 507246:tid 507477] [client 20.48.250.41:11235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/aaa.php"] [unique_id "apPk_u8CsCvw81e_I2o-lQAAAv4"]
[Sun Aug 30 03:08:30.152570 2026] [security2:error] [pid 507246:tid 507484] [client 20.151.200.44:55664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/wp-the.php"] [unique_id "apPk_u8CsCvw81e_I2o-mAAAAwU"]
[Sun Aug 30 03:08:30.153045 2026] [security2:error] [pid 507246:tid 507483] [client 20.104.50.220:5617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/x.php"] [unique_id "apPk_u8CsCvw81e_I2o-mQAAAwQ"]
[Sun Aug 30 03:08:30.166948 2026] [authz_core:error] [pid 507246:tid 507444] [client 66.249.66.68:48233] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:30.167240 2026] [authz_core:error] [pid 507246:tid 507444] [client 66.249.66.68:48233] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:30.189142 2026] [security2:error] [pid 507246:tid 507426] [client 20.104.18.15:35468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/fling.php"] [unique_id "apPk_u8CsCvw81e_I2o-nAAAAss"]
[Sun Aug 30 03:08:30.209967 2026] [security2:error] [pid 507246:tid 507495] [client 20.104.18.15:34626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apPk_u8CsCvw81e_I2o-oQAAAxA"]
[Sun Aug 30 03:08:30.226724 2026] [security2:error] [pid 507246:tid 507393] [client 158.158.54.35:14916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/fone1.php"] [unique_id "apPk_u8CsCvw81e_I2o-qAAAAqo"]
[Sun Aug 30 03:08:30.234289 2026] [security2:error] [pid 507246:tid 507392] [client 20.104.18.15:1929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/zoo1.php"] [unique_id "apPk_u8CsCvw81e_I2o-qgAAAqk"]
[Sun Aug 30 03:08:30.261229 2026] [authz_core:error] [pid 507246:tid 507395] [client 66.249.66.66:38283] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:30.261508 2026] [authz_core:error] [pid 507246:tid 507395] [client 66.249.66.66:38283] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:30.270078 2026] [security2:error] [pid 507246:tid 507428] [client 20.104.50.220:31908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/gifclass4.php"] [unique_id "apPk_u8CsCvw81e_I2o-rAAAAs0"]
[Sun Aug 30 03:08:30.271522 2026] [security2:error] [pid 507246:tid 507433] [client 20.48.250.41:11128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/xsox.php"] [unique_id "apPk_u8CsCvw81e_I2o-rgAAAtI"]
[Sun Aug 30 03:08:30.277593 2026] [authz_core:error] [pid 507246:tid 507501] [client 66.249.66.76:35407] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:30.277883 2026] [authz_core:error] [pid 507246:tid 507501] [client 66.249.66.76:35407] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:30.281053 2026] [security2:error] [pid 507246:tid 507440] [client 20.104.18.15:23376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apPk_u8CsCvw81e_I2o-rwAAAtk"]
[Sun Aug 30 03:08:30.328485 2026] [security2:error] [pid 507246:tid 507432] [client 20.104.50.220:32847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/l3.php"] [unique_id "apPk_u8CsCvw81e_I2o-twAAAtE"]
[Sun Aug 30 03:08:30.410026 2026] [security2:error] [pid 507246:tid 507489] [client 20.104.50.220:17224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "apPk_u8CsCvw81e_I2o-wwAAAwo"]
[Sun Aug 30 03:08:30.417326 2026] [security2:error] [pid 507246:tid 507420] [client 20.48.250.41:11228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/lkui.php"] [unique_id "apPk_u8CsCvw81e_I2o-xQAAAsU"]
[Sun Aug 30 03:08:30.428898 2026] [authz_core:error] [pid 507246:tid 507457] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fman%2Fman8
[Sun Aug 30 03:08:30.429215 2026] [authz_core:error] [pid 507246:tid 507457] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fman%2Fman8
[Sun Aug 30 03:08:30.436475 2026] [security2:error] [pid 507246:tid 507503] [client 20.48.251.3:13419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/fm.php"] [unique_id "apPk_u8CsCvw81e_I2o-1AAAAxg"]
[Sun Aug 30 03:08:30.465409 2026] [security2:error] [pid 507246:tid 507437] [client 20.104.49.130:54145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/ccc.php"] [unique_id "apPk_u8CsCvw81e_I2o-4AAAAtY"]
[Sun Aug 30 03:08:30.483758 2026] [security2:error] [pid 507246:tid 507389] [client 20.104.49.130:60984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/srontol.php"] [unique_id "apPk_u8CsCvw81e_I2o-5AAAAqY"]
[Sun Aug 30 03:08:30.492104 2026] [security2:error] [pid 507246:tid 507405] [client 20.48.251.3:59385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/fraro.php"] [unique_id "apPk_u8CsCvw81e_I2o-5wAAArY"]
[Sun Aug 30 03:08:30.547923 2026] [authz_core:error] [pid 507246:tid 507464] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:30.548353 2026] [authz_core:error] [pid 507246:tid 507464] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:30.559031 2026] [security2:error] [pid 507246:tid 507477] [client 20.151.200.44:55713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/wt.php"] [unique_id "apPk_u8CsCvw81e_I2o-_AAAAv4"]
[Sun Aug 30 03:08:30.563746 2026] [security2:error] [pid 507246:tid 507483] [client 4.205.62.107:22938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/cu.php"] [unique_id "apPk_u8CsCvw81e_I2o-_gAAAwQ"]
[Sun Aug 30 03:08:30.573891 2026] [security2:error] [pid 507246:tid 507397] [client 4.205.62.107:25734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/public/bnn_.php.php"] [unique_id "apPk_u8CsCvw81e_I2o_BAAAAq4"]
[Sun Aug 30 03:08:30.581725 2026] [security2:error] [pid 507246:tid 507421] [client 20.48.251.3:7087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/asdf.php"] [unique_id "apPk_u8CsCvw81e_I2o_CQAAAsY"]
[Sun Aug 30 03:08:30.596698 2026] [security2:error] [pid 507246:tid 507482] [client 20.48.250.41:11139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apPk_u8CsCvw81e_I2o_EQAAAwM"]
[Sun Aug 30 03:08:30.609173 2026] [security2:error] [pid 507246:tid 507475] [client 20.197.61.180:9388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/system_log.php"] [unique_id "apPk_u8CsCvw81e_I2o_GQAAAvw"]
[Sun Aug 30 03:08:30.622048 2026] [security2:error] [pid 507246:tid 507385] [client 68.155.159.216:55053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/themes.php"] [unique_id "apPk_u8CsCvw81e_I2o_IwAAAqI"]
[Sun Aug 30 03:08:30.626364 2026] [security2:error] [pid 507246:tid 507486] [client 216.73.216.128:30567] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPk_u8CsCvw81e_I2o_JgAAAwc"]
[Sun Aug 30 03:08:30.642589 2026] [security2:error] [pid 507246:tid 507401] [client 74.248.24.12:8252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/OthioNDwMEK.php"] [unique_id "apPk_u8CsCvw81e_I2o_LQAAArI"]
[Sun Aug 30 03:08:30.662415 2026] [security2:error] [pid 507246:tid 507429] [client 20.196.209.81:13216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/en.php"] [unique_id "apPk_u8CsCvw81e_I2o_NgAAAs4"]
[Sun Aug 30 03:08:30.691253 2026] [authz_core:error] [pid 507246:tid 507398] [client 66.249.66.70:50660] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:30.691651 2026] [authz_core:error] [pid 507246:tid 507398] [client 66.249.66.70:50660] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:30.710691 2026] [security2:error] [pid 507246:tid 507416] [client 158.158.54.35:5245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/ncx.php"] [unique_id "apPk_u8CsCvw81e_I2o_RwAAAsE"]
[Sun Aug 30 03:08:30.724994 2026] [security2:error] [pid 507246:tid 507377] [client 20.48.250.41:11080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/motu.php"] [unique_id "apPk_u8CsCvw81e_I2o_SwAAApo"]
[Sun Aug 30 03:08:30.743805 2026] [security2:error] [pid 507246:tid 507495] [client 4.205.62.107:64457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/loxi-o.php"] [unique_id "apPk_u8CsCvw81e_I2o_UAAAAxA"]
[Sun Aug 30 03:08:30.832407 2026] [authz_core:error] [pid 507246:tid 507477] [client 66.249.66.40:56198] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:30.832855 2026] [authz_core:error] [pid 507246:tid 507477] [client 66.249.66.40:56198] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:30.833850 2026] [authz_core:error] [pid 507246:tid 507442] [client 66.249.66.71:49219] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:30.834340 2026] [authz_core:error] [pid 507246:tid 507442] [client 66.249.66.71:49219] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:30.936094 2026] [security2:error] [pid 507246:tid 507428] [client 4.205.62.107:36022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/nlnub.php"] [unique_id "apPk_u8CsCvw81e_I2o_ngAAAs0"]
[Sun Aug 30 03:08:30.966281 2026] [security2:error] [pid 507246:tid 507487] [client 20.48.250.41:11011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/Ov-Simple1.php"] [unique_id "apPk_u8CsCvw81e_I2o_qgAAAwg"]
[Sun Aug 30 03:08:30.974226 2026] [security2:error] [pid 507246:tid 507409] [client 20.104.50.220:62808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/donate.php"] [unique_id "apPk_u8CsCvw81e_I2o_sAAAAro"]
[Sun Aug 30 03:08:31.030937 2026] [security2:error] [pid 507246:tid 507383] [client 68.155.159.216:53465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apPk_-8CsCvw81e_I2o_wAAAAqA"]
[Sun Aug 30 03:08:31.054781 2026] [security2:error] [pid 507246:tid 507393] [client 20.104.18.15:43303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPk_-8CsCvw81e_I2o_yAAAAqo"]
[Sun Aug 30 03:08:31.059076 2026] [security2:error] [pid 507246:tid 507402] [client 20.196.209.81:11346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/13.php"] [unique_id "apPk_-8CsCvw81e_I2o_ywAAArM"]
[Sun Aug 30 03:08:31.097184 2026] [security2:error] [pid 507246:tid 507456] [client 20.48.250.41:11076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/wp-blogs.php"] [unique_id "apPk_-8CsCvw81e_I2o_zwAAAuk"]
[Sun Aug 30 03:08:31.127235 2026] [security2:error] [pid 507246:tid 507410] [client 20.104.50.220:52810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-mobfi.php"] [unique_id "apPk_-8CsCvw81e_I2o_4wAAArs"]
[Sun Aug 30 03:08:31.129094 2026] [authz_core:error] [pid 507246:tid 507474] [client 216.73.216.128:31509] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:31.129534 2026] [authz_core:error] [pid 507246:tid 507474] [client 216.73.216.128:31509] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:31.159186 2026] [security2:error] [pid 507246:tid 507443] [client 114.119.144.143:36681] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cvhcustom.com"] [uri "/"] [unique_id "apPk_-8CsCvw81e_I2o_7AAAAtw"], referer: http://cvhcustom.com/
[Sun Aug 30 03:08:31.178352 2026] [security2:error] [pid 507246:tid 507382] [client 158.158.54.35:27858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/zup.php73"] [unique_id "apPk_-8CsCvw81e_I2o_7wAAAp8"]
[Sun Aug 30 03:08:31.190853 2026] [security2:error] [pid 507246:tid 507430] [client 4.205.62.107:63999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/cli_bootstrap.php"] [unique_id "apPk_-8CsCvw81e_I2o_8AAAAs8"]
[Sun Aug 30 03:08:31.210562 2026] [security2:error] [pid 507246:tid 507481] [client 74.248.24.12:6795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/favicon.php"] [unique_id "apPk_-8CsCvw81e_I2o_9gAAAwI"]
[Sun Aug 30 03:08:31.221263 2026] [authz_core:error] [pid 507246:tid 507486] [client 216.73.216.128:42925] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:31.221539 2026] [authz_core:error] [pid 507246:tid 507486] [client 216.73.216.128:42925] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:31.230506 2026] [security2:error] [pid 507246:tid 507449] [client 20.220.10.235:40772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/od.php"] [unique_id "apPk_-8CsCvw81e_I2o_-gAAAuI"]
[Sun Aug 30 03:08:31.231053 2026] [security2:error] [pid 507246:tid 507494] [client 20.104.18.15:18314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/goods.php"] [unique_id "apPk_-8CsCvw81e_I2o_-wAAAw8"]
[Sun Aug 30 03:08:31.241183 2026] [security2:error] [pid 507246:tid 507484] [client 20.104.50.220:41988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/000.php"] [unique_id "apPk_-8CsCvw81e_I2o__AAAAwU"]
[Sun Aug 30 03:08:31.248128 2026] [security2:error] [pid 507246:tid 507427] [client 20.104.50.220:61669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/8index.php"] [unique_id "apPk_-8CsCvw81e_I2o__gAAAsw"]
[Sun Aug 30 03:08:31.251410 2026] [security2:error] [pid 507246:tid 507497] [client 20.151.200.44:59496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/qi.php"] [unique_id "apPk_-8CsCvw81e_I2o__wAAAxI"]
[Sun Aug 30 03:08:31.255369 2026] [authz_core:error] [pid 507246:tid 507458] [client 66.249.66.70:43835] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:31.255719 2026] [authz_core:error] [pid 507246:tid 507458] [client 66.249.66.70:43835] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:31.258221 2026] [security2:error] [pid 507246:tid 507485] [client 20.48.251.3:4218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/var/www/wallet/index.php"] [unique_id "apPk_-8CsCvw81e_I2pAAAAAAwY"]
[Sun Aug 30 03:08:31.262170 2026] [security2:error] [pid 507246:tid 507402] [client 20.104.50.220:46450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/file18.php"] [unique_id "apPk_-8CsCvw81e_I2pAAQAAArM"]
[Sun Aug 30 03:08:31.262671 2026] [security2:error] [pid 507246:tid 507403] [client 20.48.250.41:11018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/mini.php"] [unique_id "apPk_-8CsCvw81e_I2pAAgAAArQ"]
[Sun Aug 30 03:08:31.283281 2026] [security2:error] [pid 507246:tid 507385] [client 20.104.49.130:53585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/dk.php"] [unique_id "apPk_-8CsCvw81e_I2pABQAAAqI"]
[Sun Aug 30 03:08:31.283691 2026] [security2:error] [pid 507246:tid 507439] [client 20.220.10.235:46808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPk_-8CsCvw81e_I2pABgAAAtg"]
[Sun Aug 30 03:08:31.324957 2026] [security2:error] [pid 507246:tid 507446] [client 20.104.50.220:5573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/w.php"] [unique_id "apPk_-8CsCvw81e_I2pACQAAAt8"]
[Sun Aug 30 03:08:31.327583 2026] [security2:error] [pid 507246:tid 507408] [client 20.197.61.180:8799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/w.php"] [unique_id "apPk_-8CsCvw81e_I2pACgAAArk"]
[Sun Aug 30 03:08:31.330922 2026] [security2:error] [pid 507246:tid 507377] [client 34.125.55.247:18976] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.engaginggoddaily.com"] [uri "/"] [unique_id "apPk_-8CsCvw81e_I2pADgAAApo"]
[Sun Aug 30 03:08:31.332769 2026] [security2:error] [pid 507246:tid 507396] [client 20.104.18.15:35474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/btyuio.php"] [unique_id "apPk_-8CsCvw81e_I2pADwAAAq0"]
[Sun Aug 30 03:08:31.334900 2026] [security2:error] [pid 507246:tid 507391] [client 68.155.159.216:45952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/ws.php"] [unique_id "apPk_-8CsCvw81e_I2pAEAAAAqg"]
[Sun Aug 30 03:08:31.337886 2026] [proxy_http:error] [pid 507246:tid 507469] (20014)Internal error (specific information not available): [client 34.125.55.247:18962] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:31.337906 2026] [proxy:error] [pid 507246:tid 507469] [client 34.125.55.247:18962] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/system
[Sun Aug 30 03:08:31.345839 2026] [proxy_http:error] [pid 507246:tid 507469] (20014)Internal error (specific information not available): [client 34.125.55.247:18962] AH01102: error reading status line from remote server 127.0.0.1:2082
[Sun Aug 30 03:08:31.345856 2026] [proxy:error] [pid 507246:tid 507469] [client 34.125.55.247:18962] AH00898: Error reading from remote server returned by /___proxy_subdomain_cpanel/502.shtml
[Sun Aug 30 03:08:31.346031 2026] [security2:error] [pid 507246:tid 507469] [client 34.125.55.247:18962] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "502"] [hostname "cpanel.engaginggoddaily.com"] [uri "/___proxy_subdomain_cpanel/502.shtml"] [unique_id "apPk_-8CsCvw81e_I2pADAAAAvY"]
[Sun Aug 30 03:08:31.346527 2026] [security2:error] [pid 507246:tid 507472] [client 20.104.18.15:34764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/wp-aothait.php"] [unique_id "apPk_-8CsCvw81e_I2pAEgAAAvk"]
[Sun Aug 30 03:08:31.366760 2026] [security2:error] [pid 507246:tid 507479] [client 20.220.10.235:40790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/wp-the.php"] [unique_id "apPk_-8CsCvw81e_I2pAEwAAAwA"]
[Sun Aug 30 03:08:31.374709 2026] [security2:error] [pid 507246:tid 507411] [client 20.104.18.15:2016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/radio.php"] [unique_id "apPk_-8CsCvw81e_I2pAFQAAArw"]
[Sun Aug 30 03:08:31.408799 2026] [authz_core:error] [pid 507246:tid 507440] [client 66.249.66.32:45284] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:31.409241 2026] [authz_core:error] [pid 507246:tid 507440] [client 66.249.66.32:45284] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:31.413152 2026] [security2:error] [pid 507246:tid 507478] [client 20.48.250.41:11117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/amp.php"] [unique_id "apPk_-8CsCvw81e_I2pAIwAAAv8"]
[Sun Aug 30 03:08:31.422678 2026] [security2:error] [pid 507246:tid 507489] [client 20.104.18.15:23475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/sao.php"] [unique_id "apPk_-8CsCvw81e_I2pAJwAAAwo"]
[Sun Aug 30 03:08:31.425537 2026] [security2:error] [pid 507246:tid 507388] [client 20.104.50.220:32706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/class19.php"] [unique_id "apPk_-8CsCvw81e_I2pAKAAAAqU"]
[Sun Aug 30 03:08:31.428940 2026] [security2:error] [pid 507246:tid 507466] [client 20.220.10.235:46739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theunknownpatriot.com"] [uri "/waf.php"] [unique_id "apPk_-8CsCvw81e_I2pAKwAAAvM"]
[Sun Aug 30 03:08:31.453467 2026] [authz_core:error] [pid 507246:tid 507423] [client 66.249.66.199:43414] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:31.453825 2026] [authz_core:error] [pid 507246:tid 507423] [client 66.249.66.199:43414] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:31.465913 2026] [security2:error] [pid 507246:tid 507376] [client 20.104.50.220:33558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/fellganteng.php"] [unique_id "apPk_-8CsCvw81e_I2pAPQAAApk"]
[Sun Aug 30 03:08:31.488694 2026] [security2:error] [pid 507246:tid 507486] [client 216.73.216.128:31509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPk_-8CsCvw81e_I2pARAAAAwc"]
[Sun Aug 30 03:08:31.511241 2026] [security2:error] [pid 507246:tid 507429] [client 20.220.10.235:39817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/wt.php"] [unique_id "apPk_-8CsCvw81e_I2pATQAAAs4"]
[Sun Aug 30 03:08:31.548364 2026] [security2:error] [pid 507246:tid 507388] [client 20.104.50.220:17329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/bal.php"] [unique_id "apPk_-8CsCvw81e_I2pAWQAAAqU"]
[Sun Aug 30 03:08:31.566464 2026] [security2:error] [pid 507246:tid 507452] [client 20.196.209.81:17411] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.michaeldanzerphoto.com"] [uri "/1.php"] [unique_id "apPk_-8CsCvw81e_I2pAXwAAAuU"]
[Sun Aug 30 03:08:31.566569 2026] [security2:error] [pid 507246:tid 507452] [client 20.196.209.81:17411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/1.php"] [unique_id "apPk_-8CsCvw81e_I2pAXwAAAuU"]
[Sun Aug 30 03:08:31.578696 2026] [security2:error] [pid 507246:tid 507485] [client 20.48.251.3:56348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/tinyfilemanager.php"] [unique_id "apPk_-8CsCvw81e_I2pAZgAAAwY"]
[Sun Aug 30 03:08:31.598872 2026] [security2:error] [pid 507246:tid 507446] [client 20.48.250.41:11251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/cc13.php"] [unique_id "apPk_-8CsCvw81e_I2pAdAAAAt8"]
[Sun Aug 30 03:08:31.602462 2026] [authz_core:error] [pid 507246:tid 507376] [client 66.249.66.71:49219] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:31.602776 2026] [authz_core:error] [pid 507246:tid 507376] [client 66.249.66.71:49219] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:31.610977 2026] [authz_core:error] [pid 507246:tid 507392] [client 66.249.66.65:36180] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:31.611269 2026] [authz_core:error] [pid 507246:tid 507392] [client 66.249.66.65:36180] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:31.628102 2026] [security2:error] [pid 507246:tid 507431] [client 20.48.251.3:59391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/thui.php"] [unique_id "apPk_-8CsCvw81e_I2pAjQAAAtA"]
[Sun Aug 30 03:08:31.644127 2026] [security2:error] [pid 507246:tid 507466] [client 20.220.10.235:39814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/im.php"] [unique_id "apPk_-8CsCvw81e_I2pAkgAAAvM"]
[Sun Aug 30 03:08:31.708115 2026] [security2:error] [pid 507246:tid 507467] [client 158.158.54.35:5378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/wp-blink.php"] [unique_id "apPk_-8CsCvw81e_I2pAqQAAAvQ"]
[Sun Aug 30 03:08:31.713236 2026] [security2:error] [pid 507246:tid 507489] [client 74.248.24.12:7847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/help.php"] [unique_id "apPk_-8CsCvw81e_I2pAqwAAAwo"]
[Sun Aug 30 03:08:31.725734 2026] [security2:error] [pid 507246:tid 507384] [client 4.205.62.107:22969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/services.php"] [unique_id "apPk_-8CsCvw81e_I2pArwAAAqE"]
[Sun Aug 30 03:08:31.731392 2026] [security2:error] [pid 507246:tid 507391] [client 4.205.62.107:25762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/wsws.php"] [unique_id "apPk_-8CsCvw81e_I2pAsgAAAqg"]
[Sun Aug 30 03:08:31.745204 2026] [security2:error] [pid 507246:tid 507411] [client 20.48.251.3:6481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apPk_-8CsCvw81e_I2pAtAAAArw"]
[Sun Aug 30 03:08:31.766147 2026] [security2:error] [pid 507246:tid 507401] [client 20.48.250.41:11162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/aa.php"] [unique_id "apPk_-8CsCvw81e_I2pAvQAAArI"]
[Sun Aug 30 03:08:31.779965 2026] [security2:error] [pid 507246:tid 507424] [client 20.104.49.130:63558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/static.php"] [unique_id "apPk_-8CsCvw81e_I2pAwAAAAsk"]
[Sun Aug 30 03:08:31.786387 2026] [security2:error] [pid 507246:tid 507438] [client 20.220.10.235:40798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/file.php"] [unique_id "apPk_-8CsCvw81e_I2pAxQAAAtc"]
[Sun Aug 30 03:08:31.816406 2026] [security2:error] [pid 507246:tid 507481] [client 68.155.159.216:55138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-mail.php"] [unique_id "apPk_-8CsCvw81e_I2pA1QAAAwI"]
[Sun Aug 30 03:08:31.890994 2026] [authz_core:error] [pid 507246:tid 507383] [client 66.249.66.77:40259] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:31.891312 2026] [authz_core:error] [pid 507246:tid 507383] [client 66.249.66.77:40259] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:31.912923 2026] [authz_core:error] [pid 507246:tid 507456] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZA
[Sun Aug 30 03:08:31.913354 2026] [authz_core:error] [pid 507246:tid 507456] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZA
[Sun Aug 30 03:08:31.914893 2026] [security2:error] [pid 507246:tid 507433] [client 20.220.10.235:40735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/ca.php"] [unique_id "apPk_-8CsCvw81e_I2pA7QAAAtI"]
[Sun Aug 30 03:08:31.933694 2026] [security2:error] [pid 507246:tid 507420] [client 4.205.62.107:61773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/f35.php"] [unique_id "apPk_-8CsCvw81e_I2pA-AAAAsU"]
[Sun Aug 30 03:08:31.983221 2026] [security2:error] [pid 507246:tid 507391] [client 20.48.250.41:11159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/s1.php"] [unique_id "apPk_-8CsCvw81e_I2pBEgAAAqg"]
[Sun Aug 30 03:08:32.008800 2026] [security2:error] [pid 507246:tid 507411] [client 20.196.209.81:9793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/as.php"] [unique_id "apPlAO8CsCvw81e_I2pBGgAAArw"]
[Sun Aug 30 03:08:32.018652 2026] [authz_core:error] [pid 507246:tid 507451] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:32.019083 2026] [authz_core:error] [pid 507246:tid 507451] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:32.039282 2026] [security2:error] [pid 507246:tid 507444] [client 20.104.49.130:53697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/one.php"] [unique_id "apPlAO8CsCvw81e_I2pBJAAAAt0"]
[Sun Aug 30 03:08:32.048821 2026] [security2:error] [pid 507246:tid 507461] [client 20.220.10.235:40753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/pb.php"] [unique_id "apPlAO8CsCvw81e_I2pBJgAAAu4"]
[Sun Aug 30 03:08:32.072457 2026] [security2:error] [pid 507246:tid 507484] [client 4.205.62.107:36678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/mga.php"] [unique_id "apPlAO8CsCvw81e_I2pBLwAAAwU"]
[Sun Aug 30 03:08:32.106856 2026] [authz_core:error] [pid 507246:tid 507408] [client 66.249.66.68:42509] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:32.107345 2026] [authz_core:error] [pid 507246:tid 507408] [client 66.249.66.68:42509] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:32.125672 2026] [security2:error] [pid 507246:tid 507437] [client 20.104.50.220:29183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/tntmar.php"] [unique_id "apPlAO8CsCvw81e_I2pBPgAAAtY"]
[Sun Aug 30 03:08:32.134769 2026] [authz_core:error] [pid 507246:tid 507426] [client 216.73.216.128:22035] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:32.135240 2026] [authz_core:error] [pid 507246:tid 507426] [client 216.73.216.128:22035] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:32.158225 2026] [security2:error] [pid 507246:tid 507439] [client 20.48.250.41:11116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/0byte.php"] [unique_id "apPlAO8CsCvw81e_I2pBRgAAAtg"]
[Sun Aug 30 03:08:32.164605 2026] [security2:error] [pid 507246:tid 507403] [client 68.155.159.216:62075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-admin/network/index.php"] [unique_id "apPlAO8CsCvw81e_I2pBRwAAArQ"]
[Sun Aug 30 03:08:32.180847 2026] [security2:error] [pid 507246:tid 507477] [client 158.158.54.35:14975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/ww5.php"] [unique_id "apPlAO8CsCvw81e_I2pBSgAAAv4"]
[Sun Aug 30 03:08:32.185817 2026] [security2:error] [pid 507246:tid 507389] [client 20.220.10.235:40814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/pk.php"] [unique_id "apPlAO8CsCvw81e_I2pBSwAAAqY"]
[Sun Aug 30 03:08:32.206221 2026] [security2:error] [pid 507246:tid 507402] [client 20.104.18.15:43316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/wsd.php"] [unique_id "apPlAO8CsCvw81e_I2pBTwAAArM"]
[Sun Aug 30 03:08:32.223832 2026] [security2:error] [pid 507246:tid 507401] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/app/.env"] [unique_id "apPlAO8CsCvw81e_I2pBVwAAArI"]
[Sun Aug 30 03:08:32.224811 2026] [security2:error] [pid 507246:tid 507399] [client 20.197.61.180:7959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/wp.php"] [unique_id "apPlAO8CsCvw81e_I2pBWQAAArA"]
[Sun Aug 30 03:08:32.267850 2026] [security2:error] [pid 507246:tid 507380] [client 20.104.50.220:62814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-comments-post.php"] [unique_id "apPlAO8CsCvw81e_I2pBXQAAAp0"]
[Sun Aug 30 03:08:32.276983 2026] [authz_core:error] [pid 507246:tid 507483] [client 66.249.66.65:46043] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:32.277281 2026] [authz_core:error] [pid 507246:tid 507483] [client 66.249.66.65:46043] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:32.281384 2026] [security2:error] [pid 507246:tid 507424] [client 74.248.24.12:7495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/gebase.php69"] [unique_id "apPlAO8CsCvw81e_I2pBXwAAAsk"]
[Sun Aug 30 03:08:32.321934 2026] [security2:error] [pid 507246:tid 507459] [client 20.220.10.235:40732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/ft.php"] [unique_id "apPlAO8CsCvw81e_I2pBYgAAAuw"]
[Sun Aug 30 03:08:32.323950 2026] [security2:error] [pid 507246:tid 507421] [client 4.205.62.107:64017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/dd.php"] [unique_id "apPlAO8CsCvw81e_I2pBYwAAAsY"]
[Sun Aug 30 03:08:32.345100 2026] [security2:error] [pid 507246:tid 507376] [client 20.48.250.41:11046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/xr.php"] [unique_id "apPlAO8CsCvw81e_I2pBZAAAApk"]
[Sun Aug 30 03:08:32.375051 2026] [security2:error] [pid 507246:tid 507464] [client 20.104.18.15:18391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/alfa.php"] [unique_id "apPlAO8CsCvw81e_I2pBZwAAAvE"]
[Sun Aug 30 03:08:32.383248 2026] [security2:error] [pid 507246:tid 507378] [client 20.104.50.220:51628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/okkk.php"] [unique_id "apPlAO8CsCvw81e_I2pBaQAAAps"]
[Sun Aug 30 03:08:32.404075 2026] [security2:error] [pid 507246:tid 507395] [client 20.48.251.3:4196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/124.php"] [unique_id "apPlAO8CsCvw81e_I2pBcAAAAqw"]
[Sun Aug 30 03:08:32.411509 2026] [security2:error] [pid 507246:tid 507432] [client 20.104.50.220:46431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/ffile.php"] [unique_id "apPlAO8CsCvw81e_I2pBdAAAAtE"]
[Sun Aug 30 03:08:32.414092 2026] [authz_core:error] [pid 507246:tid 507478] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZA
[Sun Aug 30 03:08:32.414570 2026] [authz_core:error] [pid 507246:tid 507478] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZA
[Sun Aug 30 03:08:32.416931 2026] [security2:error] [pid 507246:tid 507498] [client 20.104.50.220:61385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/9index.php"] [unique_id "apPlAO8CsCvw81e_I2pBdQAAAxM"]
[Sun Aug 30 03:08:32.451830 2026] [security2:error] [pid 507246:tid 507402] [client 20.220.10.235:40675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/wp-ver.php"] [unique_id "apPlAO8CsCvw81e_I2pBigAAArM"]
[Sun Aug 30 03:08:32.466206 2026] [security2:error] [pid 507246:tid 507494] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/apps/.env"] [unique_id "apPlAO8CsCvw81e_I2pBkAAAAw8"]
[Sun Aug 30 03:08:32.470352 2026] [security2:error] [pid 507246:tid 507383] [client 20.104.18.15:35143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/dehnl.php"] [unique_id "apPlAO8CsCvw81e_I2pBlAAAAqA"]
[Sun Aug 30 03:08:32.473986 2026] [security2:error] [pid 507246:tid 507475] [client 20.104.18.15:34637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/wp-includes/index.php"] [unique_id "apPlAO8CsCvw81e_I2pBlgAAAvw"]
[Sun Aug 30 03:08:32.474971 2026] [security2:error] [pid 507246:tid 507459] [client 20.104.50.220:5895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/v.php"] [unique_id "apPlAO8CsCvw81e_I2pBlwAAAuw"]
[Sun Aug 30 03:08:32.481003 2026] [security2:error] [pid 507246:tid 507485] [client 20.48.250.41:11201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/h02ugyh.php"] [unique_id "apPlAO8CsCvw81e_I2pBmgAAAwY"]
[Sun Aug 30 03:08:32.483737 2026] [security2:error] [pid 507246:tid 507464] [client 20.104.49.130:63252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/dex.php"] [unique_id "apPlAO8CsCvw81e_I2pBmwAAAvE"]
[Sun Aug 30 03:08:32.486781 2026] [authz_core:error] [pid 507246:tid 507413] [client 66.249.66.65:36180] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:32.487252 2026] [authz_core:error] [pid 507246:tid 507413] [client 66.249.66.65:36180] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:32.507274 2026] [security2:error] [pid 507246:tid 507409] [client 20.104.49.130:36753] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.perfectsalesperson.com"] [uri "/1.php"] [unique_id "apPlAO8CsCvw81e_I2pBqAAAAro"]
[Sun Aug 30 03:08:32.507404 2026] [security2:error] [pid 507246:tid 507409] [client 20.104.49.130:36753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/1.php"] [unique_id "apPlAO8CsCvw81e_I2pBqAAAAro"]
[Sun Aug 30 03:08:32.510589 2026] [security2:error] [pid 507246:tid 507412] [client 20.104.18.15:1921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/one.php"] [unique_id "apPlAO8CsCvw81e_I2pBqwAAAr0"]
[Sun Aug 30 03:08:32.562292 2026] [security2:error] [pid 507246:tid 507461] [client 20.104.50.220:32572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/2clas.php"] [unique_id "apPlAO8CsCvw81e_I2pBuwAAAu4"]
[Sun Aug 30 03:08:32.563568 2026] [security2:error] [pid 507246:tid 507384] [client 20.104.18.15:23476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/dapa.php"] [unique_id "apPlAO8CsCvw81e_I2pBvAAAAqE"]
[Sun Aug 30 03:08:32.569338 2026] [security2:error] [pid 507246:tid 507408] [client 52.139.37.240:37199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apPlAO8CsCvw81e_I2pBwAAAArk"]
[Sun Aug 30 03:08:32.575499 2026] [security2:error] [pid 507246:tid 507493] [client 20.196.209.81:10098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/credits.php"] [unique_id "apPlAO8CsCvw81e_I2pBxQAAAw4"]
[Sun Aug 30 03:08:32.576618 2026] [authz_core:error] [pid 507246:tid 507420] [client 66.249.66.70:43835] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:32.576947 2026] [authz_core:error] [pid 507246:tid 507420] [client 66.249.66.70:43835] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:32.591052 2026] [security2:error] [pid 507246:tid 507491] [client 20.220.10.235:40829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/ah24.php"] [unique_id "apPlAO8CsCvw81e_I2pBzAAAAww"]
[Sun Aug 30 03:08:32.611825 2026] [security2:error] [pid 507246:tid 507397] [client 158.158.54.35:10180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/rip.php"] [unique_id "apPlAO8CsCvw81e_I2pB2gAAAq4"]
[Sun Aug 30 03:08:32.618957 2026] [security2:error] [pid 507246:tid 507380] [client 20.104.50.220:32875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/fell.php"] [unique_id "apPlAO8CsCvw81e_I2pB5QAAAp0"]
[Sun Aug 30 03:08:32.670189 2026] [security2:error] [pid 507246:tid 507466] [client 20.48.250.41:11084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/xxw.php"] [unique_id "apPlAO8CsCvw81e_I2pB_gAAAvM"]
[Sun Aug 30 03:08:32.686522 2026] [security2:error] [pid 507246:tid 507445] [client 20.104.50.220:16754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/cgi-bin/admin.php"] [unique_id "apPlAO8CsCvw81e_I2pCAQAAAt4"]
[Sun Aug 30 03:08:32.712061 2026] [security2:error] [pid 507246:tid 507443] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/api/.env"] [unique_id "apPlAO8CsCvw81e_I2pCCgAAAtw"]
[Sun Aug 30 03:08:32.741346 2026] [security2:error] [pid 507246:tid 507441] [client 20.220.10.235:40726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPlAO8CsCvw81e_I2pCEwAAAto"]
[Sun Aug 30 03:08:32.763497 2026] [security2:error] [pid 507246:tid 507456] [client 20.48.251.3:13413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/05.php"] [unique_id "apPlAO8CsCvw81e_I2pCGQAAAuk"]
[Sun Aug 30 03:08:32.764240 2026] [security2:error] [pid 507246:tid 507403] [client 52.139.37.240:37213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/wp-content/uploads/min.php"] [unique_id "apPlAO8CsCvw81e_I2pCGgAAArQ"]
[Sun Aug 30 03:08:32.766487 2026] [security2:error] [pid 507246:tid 507452] [client 20.48.251.3:59334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/lala.php"] [unique_id "apPlAO8CsCvw81e_I2pCGwAAAuU"]
[Sun Aug 30 03:08:32.798131 2026] [security2:error] [pid 507246:tid 507399] [client 74.248.24.12:14911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/MYK4TJEfFvO.php"] [unique_id "apPlAO8CsCvw81e_I2pCKwAAArA"]
[Sun Aug 30 03:08:32.811535 2026] [security2:error] [pid 507246:tid 507458] [client 20.48.250.41:11179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/bolt.php"] [unique_id "apPlAO8CsCvw81e_I2pCNQAAAus"]
[Sun Aug 30 03:08:32.850854 2026] [security2:error] [pid 507246:tid 507388] [client 20.151.200.44:55566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/im.php"] [unique_id "apPlAO8CsCvw81e_I2pCPwAAAqU"]
[Sun Aug 30 03:08:32.855807 2026] [security2:error] [pid 507246:tid 507446] [client 4.205.62.107:22951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/filesystems.php"] [unique_id "apPlAO8CsCvw81e_I2pCQgAAAt8"]
[Sun Aug 30 03:08:32.880241 2026] [security2:error] [pid 507246:tid 507461] [client 20.220.10.235:39837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.krisestep.com"] [uri "/waf.php"] [unique_id "apPlAO8CsCvw81e_I2pCSgAAAu4"]
[Sun Aug 30 03:08:32.880471 2026] [security2:error] [pid 507246:tid 507462] [client 4.205.62.107:25744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/localconf.php"] [unique_id "apPlAO8CsCvw81e_I2pCSwAAAu8"]
[Sun Aug 30 03:08:32.919528 2026] [authz_core:error] [pid 507246:tid 507399] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IL
[Sun Aug 30 03:08:32.920006 2026] [authz_core:error] [pid 507246:tid 507399] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IL
[Sun Aug 30 03:08:32.937356 2026] [security2:error] [pid 507246:tid 507472] [client 20.197.61.180:10183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/composer.php"] [unique_id "apPlAO8CsCvw81e_I2pCZgAAAvk"]
[Sun Aug 30 03:08:32.937962 2026] [security2:error] [pid 507246:tid 507491] [client 68.155.159.216:54223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/cgi-bin/index.php"] [unique_id "apPlAO8CsCvw81e_I2pCZwAAAww"]
[Sun Aug 30 03:08:32.938802 2026] [security2:error] [pid 507246:tid 507479] [client 20.48.251.3:6501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/hochladen.form.php"] [unique_id "apPlAO8CsCvw81e_I2pCaAAAAwA"]
[Sun Aug 30 03:08:32.947621 2026] [security2:error] [pid 507246:tid 507449] [client 20.48.250.41:11236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/rtx.php"] [unique_id "apPlAO8CsCvw81e_I2pCcAAAAuI"]
[Sun Aug 30 03:08:32.960941 2026] [security2:error] [pid 507246:tid 507432] [client 52.139.37.240:37010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/zoom1.php"] [unique_id "apPlAO8CsCvw81e_I2pCdgAAAtE"]
[Sun Aug 30 03:08:32.971812 2026] [security2:error] [pid 507246:tid 507436] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/web/.env"] [unique_id "apPlAO8CsCvw81e_I2pCfQAAAtU"]
[Sun Aug 30 03:08:32.987513 2026] [security2:error] [pid 507246:tid 507389] [client 20.196.209.81:12732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/cache.php"] [unique_id "apPlAO8CsCvw81e_I2pCgQAAAqY"]
[Sun Aug 30 03:08:33.050434 2026] [authz_core:error] [pid 507246:tid 507498] [client 216.73.216.128:44807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:33.050900 2026] [authz_core:error] [pid 507246:tid 507498] [client 216.73.216.128:44807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:33.058368 2026] [authz_core:error] [pid 507246:tid 507422] [client 66.249.66.196:39396] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:33.058952 2026] [authz_core:error] [pid 507246:tid 507422] [client 66.249.66.196:39396] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:33.086919 2026] [security2:error] [pid 507246:tid 507446] [client 4.205.62.107:64703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/api.php"] [unique_id "apPlAe8CsCvw81e_I2pCpwAAAt8"]
[Sun Aug 30 03:08:33.090123 2026] [authz_core:error] [pid 507246:tid 507444] [client 66.249.66.73:64646] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:33.090597 2026] [authz_core:error] [pid 507246:tid 507444] [client 66.249.66.73:64646] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:33.097960 2026] [autoindex:error] [pid 507246:tid 507445] [client 158.158.54.35:0] AH01276: Cannot serve directory /home3/lordrcan/direcorgigames.com/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:08:33.099711 2026] [security2:error] [pid 507246:tid 507423] [client 20.48.250.41:11094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/ckk.php"] [unique_id "apPlAe8CsCvw81e_I2pCqQAAAsg"]
[Sun Aug 30 03:08:33.161197 2026] [security2:error] [pid 507246:tid 507412] [client 52.139.37.240:37193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/lock360.php"] [unique_id "apPlAe8CsCvw81e_I2pCvgAAAr0"]
[Sun Aug 30 03:08:33.215726 2026] [security2:error] [pid 507246:tid 507480] [client 4.205.62.107:35997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/ccou.php"] [unique_id "apPlAe8CsCvw81e_I2pCxwAAAwE"]
[Sun Aug 30 03:08:33.218697 2026] [security2:error] [pid 507246:tid 507409] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/site/.env"] [unique_id "apPlAe8CsCvw81e_I2pCyAAAAro"]
[Sun Aug 30 03:08:33.223255 2026] [security2:error] [pid 507246:tid 507380] [client 216.73.216.128:18339] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPlAe8CsCvw81e_I2pCygAAAp0"]
[Sun Aug 30 03:08:33.227940 2026] [security2:error] [pid 507246:tid 507454] [client 20.48.250.41:11242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.496cebada52a.fcconveyancing.com.au"] [uri "/R57.php"] [unique_id "apPlAe8CsCvw81e_I2pCywAAAuc"]
[Sun Aug 30 03:08:33.246441 2026] [security2:error] [pid 507246:tid 507500] [client 158.158.54.35:24896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/wp-the.php"] [unique_id "apPlAe8CsCvw81e_I2pCzQAAAxU"]
[Sun Aug 30 03:08:33.265919 2026] [security2:error] [pid 507246:tid 507434] [client 20.104.50.220:62835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/dd.php"] [unique_id "apPlAe8CsCvw81e_I2pCzgAAAtM"]
[Sun Aug 30 03:08:33.316406 2026] [security2:error] [pid 507246:tid 507395] [client 74.248.24.12:5196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/Casper.php"] [unique_id "apPlAe8CsCvw81e_I2pC0gAAAqw"]
[Sun Aug 30 03:08:33.327790 2026] [security2:error] [pid 507246:tid 507430] [client 68.155.159.216:60914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apPlAe8CsCvw81e_I2pC1AAAAs8"]
[Sun Aug 30 03:08:33.354857 2026] [security2:error] [pid 507246:tid 507398] [client 20.104.18.15:43278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/bulet.php"] [unique_id "apPlAe8CsCvw81e_I2pC1gAAAq8"]
[Sun Aug 30 03:08:33.357198 2026] [security2:error] [pid 507246:tid 507487] [client 52.139.37.240:37208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/r.php"] [unique_id "apPlAe8CsCvw81e_I2pC1wAAAwg"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:33.389477 2026] [security2:error] [pid 507246:tid 507439] [client 68.155.159.216:46018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-includes/css/index.php"] [unique_id "apPlAe8CsCvw81e_I2pC3AAAAtg"]
[Sun Aug 30 03:08:33.408961 2026] [authz_core:error] [pid 507246:tid 507416] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:33.409440 2026] [authz_core:error] [pid 507246:tid 507416] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:33.410243 2026] [authz_core:error] [pid 507246:tid 507456] [client 216.73.216.128:22035] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:33.410505 2026] [authz_core:error] [pid 507246:tid 507456] [client 216.73.216.128:22035] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:33.444984 2026] [security2:error] [pid 507246:tid 507411] [client 20.104.50.220:29141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-config-style.php"] [unique_id "apPlAe8CsCvw81e_I2pC9wAAArw"]
[Sun Aug 30 03:08:33.455184 2026] [authz_core:error] [pid 507246:tid 507479] [client 66.249.66.196:46455] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:33.455452 2026] [authz_core:error] [pid 507246:tid 507479] [client 66.249.66.196:46455] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:33.462176 2026] [security2:error] [pid 507246:tid 507380] [client 4.205.62.107:39115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/wp-tem.php"] [unique_id "apPlAe8CsCvw81e_I2pDAAAAAp0"]
[Sun Aug 30 03:08:33.466250 2026] [security2:error] [pid 507246:tid 507392] [client 20.196.209.81:10053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/fix.php"] [unique_id "apPlAe8CsCvw81e_I2pDAgAAAqk"]
[Sun Aug 30 03:08:33.467590 2026] [security2:error] [pid 507246:tid 507490] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/public/.env"] [unique_id "apPlAe8CsCvw81e_I2pDAwAAAws"]
[Sun Aug 30 03:08:33.513126 2026] [security2:error] [pid 507246:tid 507398] [client 20.104.18.15:18176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/33.php"] [unique_id "apPlAe8CsCvw81e_I2pDEAAAAq8"]
[Sun Aug 30 03:08:33.514580 2026] [authz_core:error] [pid 507246:tid 507430] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fman-db
[Sun Aug 30 03:08:33.514849 2026] [authz_core:error] [pid 507246:tid 507430] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fman-db
[Sun Aug 30 03:08:33.518020 2026] [security2:error] [pid 507246:tid 507453] [client 20.104.50.220:42761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/yamate.php"] [unique_id "apPlAe8CsCvw81e_I2pDEgAAAuY"]
[Sun Aug 30 03:08:33.540738 2026] [security2:error] [pid 507246:tid 507424] [client 20.48.251.3:4817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/test1.php"] [unique_id "apPlAe8CsCvw81e_I2pDGgAAAsk"]
[Sun Aug 30 03:08:33.554107 2026] [security2:error] [pid 507246:tid 507438] [client 20.104.50.220:46387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/file7.php"] [unique_id "apPlAe8CsCvw81e_I2pDIgAAAtc"]
[Sun Aug 30 03:08:33.554632 2026] [security2:error] [pid 507246:tid 507393] [client 20.104.50.220:61420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/index4.php"] [unique_id "apPlAe8CsCvw81e_I2pDIwAAAqo"]
[Sun Aug 30 03:08:33.562880 2026] [security2:error] [pid 507246:tid 507498] [client 52.139.37.240:37215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/sf.php"] [unique_id "apPlAe8CsCvw81e_I2pDJgAAAxM"]
[Sun Aug 30 03:08:33.586967 2026] [security2:error] [pid 507246:tid 507382] [client 216.73.216.128:30567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPlAe8CsCvw81e_I2pDMQAAAp8"]
[Sun Aug 30 03:08:33.614715 2026] [authz_core:error] [pid 507246:tid 507488] [client 66.249.66.206:36773] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:33.615052 2026] [security2:error] [pid 507246:tid 507500] [client 20.104.18.15:34744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/file31.php"] [unique_id "apPlAe8CsCvw81e_I2pDQgAAAxU"]
[Sun Aug 30 03:08:33.615133 2026] [authz_core:error] [pid 507246:tid 507488] [client 66.249.66.206:36773] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:33.616476 2026] [security2:error] [pid 507246:tid 507482] [client 20.104.18.15:35149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/zoo2.php"] [unique_id "apPlAe8CsCvw81e_I2pDSAAAAwM"]
[Sun Aug 30 03:08:33.618109 2026] [security2:error] [pid 507246:tid 507414] [client 20.104.50.220:5447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/u.php"] [unique_id "apPlAe8CsCvw81e_I2pDSQAAAr8"]
[Sun Aug 30 03:08:33.650116 2026] [security2:error] [pid 507246:tid 507388] [client 20.104.18.15:1926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/504.php"] [unique_id "apPlAe8CsCvw81e_I2pDVQAAAqU"]
[Sun Aug 30 03:08:33.698684 2026] [security2:error] [pid 507246:tid 507437] [client 20.104.50.220:31835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/bless5.php"] [unique_id "apPlAe8CsCvw81e_I2pDaAAAAtY"]
[Sun Aug 30 03:08:33.699775 2026] [security2:error] [pid 507246:tid 507409] [client 20.197.61.180:8779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/abcd.php"] [unique_id "apPlAe8CsCvw81e_I2pDaQAAAro"]
[Sun Aug 30 03:08:33.707244 2026] [authz_core:error] [pid 507246:tid 507452] [client 66.249.66.205:38911] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:33.707661 2026] [authz_core:error] [pid 507246:tid 507452] [client 66.249.66.205:38911] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:33.727863 2026] [authz_core:error] [pid 507246:tid 507432] [client 66.249.66.203:64897] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:33.728154 2026] [authz_core:error] [pid 507246:tid 507432] [client 66.249.66.203:64897] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:33.730317 2026] [security2:error] [pid 507246:tid 507429] [client 158.158.54.35:6563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/f35.php"] [unique_id "apPlAe8CsCvw81e_I2pDcgAAAs4"]
[Sun Aug 30 03:08:33.748313 2026] [security2:error] [pid 507246:tid 507414] [client 20.104.18.15:23369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/wp-content/l.php"] [unique_id "apPlAe8CsCvw81e_I2pDdQAAAr8"]
[Sun Aug 30 03:08:33.761368 2026] [security2:error] [pid 507246:tid 507458] [client 20.104.50.220:33087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/ok.php"] [unique_id "apPlAe8CsCvw81e_I2pDewAAAus"]
[Sun Aug 30 03:08:33.771210 2026] [security2:error] [pid 507246:tid 507454] [client 52.139.37.240:36995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/7.php"] [unique_id "apPlAe8CsCvw81e_I2pDfgAAAuc"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:33.825286 2026] [security2:error] [pid 507246:tid 507476] [client 20.104.50.220:16597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/gettest.php"] [unique_id "apPlAe8CsCvw81e_I2pDmgAAAv0"]
[Sun Aug 30 03:08:33.837795 2026] [security2:error] [pid 507246:tid 507495] [client 74.248.24.12:5247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/wander.php"] [unique_id "apPlAe8CsCvw81e_I2pDmwAAAxA"]
[Sun Aug 30 03:08:33.866815 2026] [security2:error] [pid 507246:tid 507491] [client 20.104.49.130:54161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/wp.php"] [unique_id "apPlAe8CsCvw81e_I2pDqgAAAww"]
[Sun Aug 30 03:08:33.869086 2026] [security2:error] [pid 507246:tid 507494] [client 20.196.209.81:10086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/alfa.php"] [unique_id "apPlAe8CsCvw81e_I2pDqwAAAw8"]
[Sun Aug 30 03:08:33.893477 2026] [authz_core:error] [pid 507246:tid 507492] [client 66.249.66.43:39934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:33.893846 2026] [authz_core:error] [pid 507246:tid 507492] [client 66.249.66.43:39934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:33.897538 2026] [security2:error] [pid 507246:tid 507390] [client 20.48.251.3:13394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/wp-blog.php"] [unique_id "apPlAe8CsCvw81e_I2pDsAAAAqc"]
[Sun Aug 30 03:08:33.904599 2026] [security2:error] [pid 507246:tid 507408] [client 20.48.251.3:59384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/public/bnn_.php.php"] [unique_id "apPlAe8CsCvw81e_I2pDsgAAArk"]
[Sun Aug 30 03:08:33.965824 2026] [security2:error] [pid 507246:tid 507414] [client 52.139.37.240:37245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/b.php"] [unique_id "apPlAe8CsCvw81e_I2pD1AAAAr8"]
[Sun Aug 30 03:08:33.981817 2026] [env:warn] [pid 507246:tid 507484] AH01506: PassEnv variable MODSEC_ENABLE was undefined
[Sun Aug 30 03:08:33.989282 2026] [authz_core:error] [pid 507246:tid 507485] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_CA
[Sun Aug 30 03:08:33.989701 2026] [authz_core:error] [pid 507246:tid 507485] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_CA
[Sun Aug 30 03:08:34.019117 2026] [security2:error] [pid 507246:tid 507499] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/backend/.env"] [unique_id "apPlAu8CsCvw81e_I2pD7AAAAxQ"]
[Sun Aug 30 03:08:34.035818 2026] [security2:error] [pid 507246:tid 507441] [client 4.205.62.107:25729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/bengi.php"] [unique_id "apPlAu8CsCvw81e_I2pD9AAAAto"]
[Sun Aug 30 03:08:34.053024 2026] [authz_core:error] [pid 507246:tid 507412] [client 66.249.66.39:58370] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:34.053279 2026] [authz_core:error] [pid 507246:tid 507412] [client 66.249.66.39:58370] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:34.075427 2026] [security2:error] [pid 507246:tid 507397] [client 4.205.62.107:62452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/tax.php"] [unique_id "apPlAu8CsCvw81e_I2pEAQAAAq4"]
[Sun Aug 30 03:08:34.126822 2026] [security2:error] [pid 507246:tid 507444] [client 20.48.251.3:7381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/debuggen.php"] [unique_id "apPlAu8CsCvw81e_I2pEDgAAAt0"]
[Sun Aug 30 03:08:34.132839 2026] [security2:error] [pid 507246:tid 507473] [client 20.104.49.130:52350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/f35.update.php"] [unique_id "apPlAu8CsCvw81e_I2pEEAAAAvo"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:34.175681 2026] [security2:error] [pid 507246:tid 507476] [client 68.155.159.216:54472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPlAu8CsCvw81e_I2pEGQAAAv0"]
[Sun Aug 30 03:08:34.175962 2026] [security2:error] [pid 507246:tid 507467] [client 52.139.37.240:37205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/buy.php"] [unique_id "apPlAu8CsCvw81e_I2pEGgAAAvQ"]
[Sun Aug 30 03:08:34.230879 2026] [security2:error] [pid 507246:tid 507502] [client 4.205.62.107:61818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/temp.php"] [unique_id "apPlAu8CsCvw81e_I2pELQAAAxc"]
[Sun Aug 30 03:08:34.237799 2026] [autoindex:error] [pid 507246:tid 507454] [client 158.158.54.35:0] AH01276: Cannot serve directory /home3/lordrcan/direcorgigames.com/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:08:34.273662 2026] [security2:error] [pid 507246:tid 507457] [client 20.196.209.81:11359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/wp-blog-header.php"] [unique_id "apPlAu8CsCvw81e_I2pELgAAAuo"]
[Sun Aug 30 03:08:34.283222 2026] [security2:error] [pid 507246:tid 507438] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/server/.env"] [unique_id "apPlAu8CsCvw81e_I2pEMAAAAtc"]
[Sun Aug 30 03:08:34.283365 2026] [authz_core:error] [pid 507246:tid 507445] [client 66.249.66.45:39941] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:34.283818 2026] [authz_core:error] [pid 507246:tid 507445] [client 66.249.66.45:39941] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:34.329588 2026] [authz_core:error] [pid 507246:tid 507493] [client 216.73.216.128:22035] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:34.329896 2026] [authz_core:error] [pid 507246:tid 507493] [client 216.73.216.128:22035] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:34.351010 2026] [authz_core:error] [pid 507246:tid 507378] [client 66.249.66.42:42042] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:34.351282 2026] [authz_core:error] [pid 507246:tid 507378] [client 66.249.66.42:42042] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:34.356747 2026] [security2:error] [pid 507246:tid 507380] [client 74.248.24.12:2950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/config.php7"] [unique_id "apPlAu8CsCvw81e_I2pENwAAAp0"]
[Sun Aug 30 03:08:34.370215 2026] [security2:error] [pid 507246:tid 507376] [client 52.139.37.240:37191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/config.php"] [unique_id "apPlAu8CsCvw81e_I2pEOAAAApk"]
[Sun Aug 30 03:08:34.384715 2026] [security2:error] [pid 507246:tid 507389] [client 158.158.54.35:5226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/fm.php"] [unique_id "apPlAu8CsCvw81e_I2pEPAAAAqY"]
[Sun Aug 30 03:08:34.414786 2026] [security2:error] [pid 507246:tid 507437] [client 20.197.61.180:10214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/sf.php"] [unique_id "apPlAu8CsCvw81e_I2pERwAAAtY"]
[Sun Aug 30 03:08:34.420582 2026] [security2:error] [pid 507246:tid 507391] [client 4.205.62.107:36014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/rum.or.php"] [unique_id "apPlAu8CsCvw81e_I2pESwAAAqg"]
[Sun Aug 30 03:08:34.437860 2026] [authz_core:error] [pid 507246:tid 507462] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IE
[Sun Aug 30 03:08:34.438307 2026] [authz_core:error] [pid 507246:tid 507462] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IE
[Sun Aug 30 03:08:34.455606 2026] [security2:error] [pid 507246:tid 507483] [client 68.155.159.216:61418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/.well-knownold/index.php"] [unique_id "apPlAu8CsCvw81e_I2pEZwAAAwQ"]
[Sun Aug 30 03:08:34.494182 2026] [security2:error] [pid 507246:tid 507461] [client 20.104.18.15:43969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/av.php"] [unique_id "apPlAu8CsCvw81e_I2pEdQAAAu4"]
[Sun Aug 30 03:08:34.505605 2026] [security2:error] [pid 507246:tid 507449] [client 20.151.200.44:55647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/file.php"] [unique_id "apPlAu8CsCvw81e_I2pEfQAAAuI"]
[Sun Aug 30 03:08:34.533460 2026] [security2:error] [pid 507246:tid 507463] [client 68.155.159.216:45993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/cgi-bin/wp-login.php"] [unique_id "apPlAu8CsCvw81e_I2pEgwAAAvA"]
[Sun Aug 30 03:08:34.566359 2026] [security2:error] [pid 507246:tid 507376] [client 52.139.37.240:37827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/num.php"] [unique_id "apPlAu8CsCvw81e_I2pEkAAAApk"]
[Sun Aug 30 03:08:34.600014 2026] [authz_core:error] [pid 507246:tid 507385] [client 216.73.216.128:22035] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:34.600429 2026] [authz_core:error] [pid 507246:tid 507385] [client 216.73.216.128:22035] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:34.604606 2026] [security2:error] [pid 507246:tid 507384] [client 20.104.49.130:57654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/reop3.php"] [unique_id "apPlAu8CsCvw81e_I2pEpAAAAqE"]
[Sun Aug 30 03:08:34.620079 2026] [security2:error] [pid 507246:tid 507444] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/frontend/.env"] [unique_id "apPlAu8CsCvw81e_I2pErwAAAt0"]
[Sun Aug 30 03:08:34.637249 2026] [security2:error] [pid 507246:tid 507466] [client 20.104.50.220:52811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-logo.php"] [unique_id "apPlAu8CsCvw81e_I2pEtgAAAvM"]
[Sun Aug 30 03:08:34.646333 2026] [security2:error] [pid 507246:tid 507499] [client 4.205.62.107:62118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/txets.php"] [unique_id "apPlAu8CsCvw81e_I2pEugAAAxQ"]
[Sun Aug 30 03:08:34.653427 2026] [security2:error] [pid 507246:tid 507491] [client 20.104.18.15:18325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/133.php"] [unique_id "apPlAu8CsCvw81e_I2pEvQAAAww"]
[Sun Aug 30 03:08:34.656920 2026] [authz_core:error] [pid 507246:tid 507403] [client 66.249.66.45:41850] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:34.657380 2026] [authz_core:error] [pid 507246:tid 507403] [client 66.249.66.45:41850] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:34.670772 2026] [security2:error] [pid 507246:tid 507453] [client 20.104.50.220:63534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/upppp.php"] [unique_id "apPlAu8CsCvw81e_I2pEzAAAAuY"]
[Sun Aug 30 03:08:34.671864 2026] [security2:error] [pid 507246:tid 507465] [client 20.196.209.81:12713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/s.php"] [unique_id "apPlAu8CsCvw81e_I2pEygAAAvI"]
[Sun Aug 30 03:08:34.680072 2026] [security2:error] [pid 507246:tid 507447] [client 20.48.251.3:44297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/bigdump.php"] [unique_id "apPlAu8CsCvw81e_I2pE0AAAAuA"]
[Sun Aug 30 03:08:34.702663 2026] [security2:error] [pid 507246:tid 507477] [client 20.104.50.220:47089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/aaa.php"] [unique_id "apPlAu8CsCvw81e_I2pE2AAAAv4"]
[Sun Aug 30 03:08:34.707736 2026] [security2:error] [pid 507246:tid 507486] [client 20.104.50.220:61429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/index5.php"] [unique_id "apPlAu8CsCvw81e_I2pE2gAAAwc"]
[Sun Aug 30 03:08:34.749631 2026] [security2:error] [pid 507246:tid 507450] [client 20.104.18.15:34649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/dk.php"] [unique_id "apPlAu8CsCvw81e_I2pE5AAAAuM"]
[Sun Aug 30 03:08:34.760292 2026] [security2:error] [pid 507246:tid 507405] [client 52.139.37.240:37223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/areak1.php"] [unique_id "apPlAu8CsCvw81e_I2pE6QAAArY"]
[Sun Aug 30 03:08:34.766112 2026] [security2:error] [pid 507246:tid 507484] [client 20.104.18.15:35189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/zoo1.php"] [unique_id "apPlAu8CsCvw81e_I2pE7AAAAwU"]
[Sun Aug 30 03:08:34.770761 2026] [authz_core:error] [pid 507246:tid 507384] [client 66.249.66.67:39937] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:34.771221 2026] [authz_core:error] [pid 507246:tid 507384] [client 66.249.66.67:39937] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:34.782619 2026] [authz_core:error] [pid 507246:tid 507382] [client 66.249.66.204:55453] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:34.782929 2026] [authz_core:error] [pid 507246:tid 507382] [client 66.249.66.204:55453] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:34.784096 2026] [security2:error] [pid 507246:tid 507442] [client 20.104.50.220:6080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/t.php"] [unique_id "apPlAu8CsCvw81e_I2pE9AAAAts"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:34.787932 2026] [security2:error] [pid 507246:tid 507424] [client 20.104.18.15:1994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/ano.php"] [unique_id "apPlAu8CsCvw81e_I2pE-AAAAsk"]
[Sun Aug 30 03:08:34.813170 2026] [security2:error] [pid 507246:tid 507477] [client 143.110.213.72:39512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.anantiapolytechnic.ng"] [uri "/.env"] [unique_id "apPlAu8CsCvw81e_I2pFCgAAAv4"]
[Sun Aug 30 03:08:34.825980 2026] [security2:error] [pid 507246:tid 507401] [client 158.158.54.35:6558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/3.php"] [unique_id "apPlAu8CsCvw81e_I2pFDAAAArI"]
[Sun Aug 30 03:08:34.850613 2026] [security2:error] [pid 507246:tid 507427] [client 20.104.50.220:31853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/file15.php"] [unique_id "apPlAu8CsCvw81e_I2pFFAAAAsw"]
[Sun Aug 30 03:08:34.880902 2026] [security2:error] [pid 507246:tid 507377] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/src/.env"] [unique_id "apPlAu8CsCvw81e_I2pFIQAAApo"]
[Sun Aug 30 03:08:34.901530 2026] [security2:error] [pid 507246:tid 507449] [client 20.104.18.15:23451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/wp-admin/w.php"] [unique_id "apPlAu8CsCvw81e_I2pFIgAAAuI"]
[Sun Aug 30 03:08:34.911259 2026] [security2:error] [pid 507246:tid 507453] [client 20.104.50.220:33186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/herp.php"] [unique_id "apPlAu8CsCvw81e_I2pFJwAAAuY"]
[Sun Aug 30 03:08:34.917590 2026] [security2:error] [pid 507246:tid 507462] [client 74.248.24.12:14909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/eq2hbpgs.php"] [unique_id "apPlAu8CsCvw81e_I2pFKQAAAu8"]
[Sun Aug 30 03:08:34.951346 2026] [authz_core:error] [pid 507246:tid 507440] [client 66.249.66.44:39571] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:34.951622 2026] [authz_core:error] [pid 507246:tid 507440] [client 66.249.66.44:39571] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:34.963449 2026] [security2:error] [pid 507246:tid 507461] [client 52.139.37.240:37240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/vc.php"] [unique_id "apPlAu8CsCvw81e_I2pFRwAAAu4"]
[Sun Aug 30 03:08:34.964246 2026] [security2:error] [pid 507246:tid 507410] [client 20.104.50.220:17260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-content/BypassBest.php"] [unique_id "apPlAu8CsCvw81e_I2pFSAAAArs"]
[Sun Aug 30 03:08:34.965065 2026] [authz_core:error] [pid 507246:tid 507444] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fman-db
[Sun Aug 30 03:08:34.965342 2026] [authz_core:error] [pid 507246:tid 507444] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fman-db
[Sun Aug 30 03:08:35.040580 2026] [security2:error] [pid 507246:tid 507456] [client 20.48.251.3:33316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/erty.php"] [unique_id "apPlA-8CsCvw81e_I2pFZAAAAuk"]
[Sun Aug 30 03:08:35.045952 2026] [authz_core:error] [pid 507246:tid 507448] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:35.046224 2026] [authz_core:error] [pid 507246:tid 507448] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:35.052662 2026] [security2:error] [pid 507246:tid 507502] [client 20.48.251.3:55747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/wsws.php"] [unique_id "apPlA-8CsCvw81e_I2pFbAAAAxc"]
[Sun Aug 30 03:08:35.055416 2026] [security2:error] [pid 507246:tid 507357] [remote 162.144.3.250:57206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.3.144.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "orthochristiantools.com"] [uri "/wp-login.php"] [unique_id "apPlA-8CsCvw81e_I2pFZQACtm4"]
[Sun Aug 30 03:08:35.061863 2026] [security2:error] [pid 507246:tid 507457] [client 20.151.200.44:57817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/px.php"] [unique_id "apPlA-8CsCvw81e_I2pFcAAAAuo"]
[Sun Aug 30 03:08:35.125053 2026] [security2:error] [pid 507246:tid 507459] [client 20.196.209.81:11379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/php.php"] [unique_id "apPlA-8CsCvw81e_I2pFfgAAAuw"]
[Sun Aug 30 03:08:35.131921 2026] [security2:error] [pid 507246:tid 507500] [client 20.197.61.180:10199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/gel4y.php"] [unique_id "apPlA-8CsCvw81e_I2pFgwAAAxU"]
[Sun Aug 30 03:08:35.152000 2026] [security2:error] [pid 507246:tid 507377] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/core/.env"] [unique_id "apPlA-8CsCvw81e_I2pFhgAAApo"]
[Sun Aug 30 03:08:35.161454 2026] [security2:error] [pid 507246:tid 507491] [client 52.139.37.240:37209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPlA-8CsCvw81e_I2pFjQAAAww"]
[Sun Aug 30 03:08:35.211860 2026] [security2:error] [pid 507246:tid 507495] [client 4.205.62.107:25492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/i.php"] [unique_id "apPlA-8CsCvw81e_I2pFlgAAAxA"]
[Sun Aug 30 03:08:35.215905 2026] [security2:error] [pid 507246:tid 507446] [client 4.205.62.107:22581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPlA-8CsCvw81e_I2pFmAAAAt8"]
[Sun Aug 30 03:08:35.276866 2026] [security2:error] [pid 507246:tid 507359] [remote 162.144.3.250:57206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.3.144.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "orthochristiantools.com"] [uri "/wp-login.php"] [unique_id "apPlA-8CsCvw81e_I2pFnwAC-3A"], referer: https://orthochristiantools.com/wp-login.php
[Sun Aug 30 03:08:35.280937 2026] [security2:error] [pid 507246:tid 507405] [client 20.48.251.3:64480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/pouhg.php"] [unique_id "apPlA-8CsCvw81e_I2pFoAAAArY"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:35.303784 2026] [security2:error] [pid 507246:tid 507481] [client 158.158.54.35:27118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/meta.php"] [unique_id "apPlA-8CsCvw81e_I2pFogAAAwI"]
[Sun Aug 30 03:08:35.354032 2026] [security2:error] [pid 507246:tid 507483] [client 68.155.159.216:55086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-includes/content.php"] [unique_id "apPlA-8CsCvw81e_I2pFpgAAAwQ"]
[Sun Aug 30 03:08:35.354525 2026] [security2:error] [pid 507246:tid 507457] [client 52.139.37.240:37234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/core.php"] [unique_id "apPlA-8CsCvw81e_I2pFpwAAAuo"]
[Sun Aug 30 03:08:35.372631 2026] [security2:error] [pid 507246:tid 507479] [client 4.205.62.107:64667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/fm.php"] [unique_id "apPlA-8CsCvw81e_I2pFrQAAAwA"]
[Sun Aug 30 03:08:35.394716 2026] [security2:error] [pid 507246:tid 507410] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/core/app/.env"] [unique_id "apPlA-8CsCvw81e_I2pFuQAAArs"]
[Sun Aug 30 03:08:35.401328 2026] [security2:error] [pid 507246:tid 507492] [client 98.66.162.46:51804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.162.66.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bgindustry.com.au"] [uri "/wp-login.php"] [unique_id "apPlA-8CsCvw81e_I2pFswAAAw0"]
[Sun Aug 30 03:08:35.412055 2026] [authz_core:error] [pid 507246:tid 507390] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:35.412333 2026] [authz_core:error] [pid 507246:tid 507390] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:35.416154 2026] [security2:error] [pid 507246:tid 507451] [client 74.248.24.12:7448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/GOD.php"] [unique_id "apPlA-8CsCvw81e_I2pFwAAAAuQ"]
[Sun Aug 30 03:08:35.439185 2026] [authz_core:error] [pid 507246:tid 507429] [client 66.249.66.205:38911] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:35.439623 2026] [authz_core:error] [pid 507246:tid 507429] [client 66.249.66.205:38911] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:35.443723 2026] [authz_core:error] [pid 507246:tid 507426] [client 66.249.66.32:54379] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:35.444187 2026] [authz_core:error] [pid 507246:tid 507426] [client 66.249.66.32:54379] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:35.471706 2026] [security2:error] [pid 507246:tid 507423] [client 20.104.49.130:36789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/222.php"] [unique_id "apPlA-8CsCvw81e_I2pF4AAAAsg"]
[Sun Aug 30 03:08:35.492605 2026] [security2:error] [pid 507246:tid 507382] [client 62.60.130.227:55723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.130.60.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.iwd.chg.temporary.site"] [uri "/wp-admin/admin-ajax.php"] [unique_id "apPlA-8CsCvw81e_I2pF6gAAAp8"]
[Sun Aug 30 03:08:35.542591 2026] [authz_core:error] [pid 507246:tid 507452] [client 66.249.66.67:39937] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:35.543085 2026] [authz_core:error] [pid 507246:tid 507452] [client 66.249.66.67:39937] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:35.552321 2026] [security2:error] [pid 507246:tid 507424] [client 20.196.209.81:9819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/system_log.php"] [unique_id "apPlA-8CsCvw81e_I2pF_wAAAsk"]
[Sun Aug 30 03:08:35.558961 2026] [security2:error] [pid 507246:tid 507484] [client 52.139.37.240:37225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/wp-content/min.php"] [unique_id "apPlA-8CsCvw81e_I2pGBAAAAwU"]
[Sun Aug 30 03:08:35.583800 2026] [security2:error] [pid 507246:tid 507487] [client 20.104.49.130:52138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/100.php"] [unique_id "apPlA-8CsCvw81e_I2pGDAAAAwg"]
[Sun Aug 30 03:08:35.615517 2026] [security2:error] [pid 507246:tid 507416] [client 68.155.159.216:62074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apPlA-8CsCvw81e_I2pGJAAAAsE"]
[Sun Aug 30 03:08:35.652138 2026] [security2:error] [pid 507246:tid 507403] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/config/.env"] [unique_id "apPlA-8CsCvw81e_I2pGNgAAArQ"]
[Sun Aug 30 03:08:35.652666 2026] [authz_core:error] [pid 507246:tid 507402] [client 66.249.66.32:37908] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:35.653007 2026] [authz_core:error] [pid 507246:tid 507402] [client 66.249.66.32:37908] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:35.655391 2026] [authz_core:error] [pid 507246:tid 507393] [client 216.73.216.128:22035] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:35.655764 2026] [authz_core:error] [pid 507246:tid 507393] [client 216.73.216.128:22035] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:35.677141 2026] [security2:error] [pid 507246:tid 507441] [client 20.104.18.15:43319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/images.php"] [unique_id "apPlA-8CsCvw81e_I2pGQgAAAto"]
[Sun Aug 30 03:08:35.687608 2026] [security2:error] [pid 507246:tid 507391] [client 68.155.159.216:45960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-content/cong.php"] [unique_id "apPlA-8CsCvw81e_I2pGRQAAAqg"]
[Sun Aug 30 03:08:35.743195 2026] [core:error] [pid 507246:tid 507473] [client 158.158.54.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:08:35.743221 2026] [core:error] [pid 507246:tid 507473] [client 158.158.54.35:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:08:35.748888 2026] [authz_core:error] [pid 507246:tid 507493] [client 216.73.216.128:44807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:35.749327 2026] [security2:error] [pid 507246:tid 507502] [client 158.158.54.35:10203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/yindu.php"] [unique_id "apPlA-8CsCvw81e_I2pGYwAAAxc"]
[Sun Aug 30 03:08:35.749334 2026] [authz_core:error] [pid 507246:tid 507493] [client 216.73.216.128:44807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:35.761761 2026] [security2:error] [pid 507246:tid 507411] [client 52.139.37.240:36998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "apPlA-8CsCvw81e_I2pGZwAAArw"]
[Sun Aug 30 03:08:35.773685 2026] [security2:error] [pid 507246:tid 507484] [client 4.205.62.107:64005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/time.php"] [unique_id "apPlA-8CsCvw81e_I2pGagAAAwU"]
[Sun Aug 30 03:08:35.791822 2026] [security2:error] [pid 507246:tid 507488] [client 20.104.50.220:28687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-config-sample.php"] [unique_id "apPlA-8CsCvw81e_I2pGeQAAAwk"]
[Sun Aug 30 03:08:35.808216 2026] [security2:error] [pid 507246:tid 507391] [client 20.104.50.220:42455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/up.php"] [unique_id "apPlA-8CsCvw81e_I2pGhAAAAqg"]
[Sun Aug 30 03:08:35.809962 2026] [security2:error] [pid 507246:tid 507420] [client 20.104.18.15:18370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/sym.php"] [unique_id "apPlA-8CsCvw81e_I2pGhwAAAsU"]
[Sun Aug 30 03:08:35.819021 2026] [authz_core:error] [pid 507246:tid 507499] [client 66.249.66.201:64892] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:35.819480 2026] [authz_core:error] [pid 507246:tid 507499] [client 66.249.66.201:64892] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:35.831633 2026] [security2:error] [pid 507246:tid 507404] [client 20.48.251.3:44295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/wdf.php"] [unique_id "apPlA-8CsCvw81e_I2pGjQAAArU"]
[Sun Aug 30 03:08:35.838028 2026] [security2:error] [pid 507246:tid 507454] [client 20.104.50.220:46406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/vee.php"] [unique_id "apPlA-8CsCvw81e_I2pGjwAAAuc"]
[Sun Aug 30 03:08:35.874107 2026] [security2:error] [pid 507246:tid 507379] [client 20.104.50.220:59572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/index6.php"] [unique_id "apPlA-8CsCvw81e_I2pGngAAApw"]
[Sun Aug 30 03:08:35.890868 2026] [security2:error] [pid 507246:tid 507488] [client 20.104.18.15:34734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/ta.php"] [unique_id "apPlA-8CsCvw81e_I2pGpAAAAwk"]
[Sun Aug 30 03:08:35.921866 2026] [security2:error] [pid 507246:tid 507420] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/private/.env"] [unique_id "apPlA-8CsCvw81e_I2pGrAAAAsU"]
[Sun Aug 30 03:08:35.922385 2026] [security2:error] [pid 507246:tid 507443] [client 216.73.216.128:22035] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/_runtime"] [unique_id "apPlA-8CsCvw81e_I2pGrQAAAtw"]
[Sun Aug 30 03:08:35.922882 2026] [security2:error] [pid 507246:tid 507392] [client 20.104.50.220:5920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/s.php"] [unique_id "apPlA-8CsCvw81e_I2pGrgAAAqk"]
[Sun Aug 30 03:08:35.925964 2026] [security2:error] [pid 507246:tid 507398] [client 20.104.18.15:1957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/mac.php"] [unique_id "apPlA-8CsCvw81e_I2pGsAAAAq8"]
[Sun Aug 30 03:08:35.937735 2026] [security2:error] [pid 507246:tid 507413] [client 20.104.18.15:35505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/radio.php"] [unique_id "apPlA-8CsCvw81e_I2pGuQAAAr4"]
[Sun Aug 30 03:08:35.951005 2026] [authz_core:error] [pid 507246:tid 507393] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:35.951352 2026] [authz_core:error] [pid 507246:tid 507393] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:35.955343 2026] [security2:error] [pid 507246:tid 507492] [client 20.197.61.180:8779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/leaf.php"] [unique_id "apPlA-8CsCvw81e_I2pGxQAAAw0"]
[Sun Aug 30 03:08:35.956120 2026] [security2:error] [pid 507246:tid 507397] [client 52.139.37.240:37017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/ws37.php"] [unique_id "apPlA-8CsCvw81e_I2pGxgAAAq4"]
[Sun Aug 30 03:08:35.985012 2026] [security2:error] [pid 507246:tid 507494] [client 20.196.209.81:13215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/w.php"] [unique_id "apPlA-8CsCvw81e_I2pG2gAAAw8"]
[Sun Aug 30 03:08:35.985077 2026] [security2:error] [pid 507246:tid 507476] [client 74.248.24.12:7837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/depotcv.php"] [unique_id "apPlA-8CsCvw81e_I2pG2wAAAv0"]
[Sun Aug 30 03:08:36.000225 2026] [security2:error] [pid 507246:tid 507477] [client 20.104.50.220:62794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/lf.php"] [unique_id "apPlA-8CsCvw81e_I2pG4AAAAv4"]
[Sun Aug 30 03:08:36.006169 2026] [authz_core:error] [pid 507246:tid 507449] [client 66.249.66.38:36879] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:36.006603 2026] [authz_core:error] [pid 507246:tid 507449] [client 66.249.66.38:36879] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:36.012464 2026] [security2:error] [pid 507246:tid 507414] [client 216.73.216.128:44807] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPlBO8CsCvw81e_I2pG5wAAAr8"]
[Sun Aug 30 03:08:36.020415 2026] [security2:error] [pid 507246:tid 507392] [client 20.104.50.220:31830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/333.php"] [unique_id "apPlBO8CsCvw81e_I2pG7gAAAqk"]
[Sun Aug 30 03:08:36.020896 2026] [authz_core:error] [pid 507246:tid 507388] [client 66.249.66.194:64564] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:36.021170 2026] [authz_core:error] [pid 507246:tid 507388] [client 66.249.66.194:64564] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:36.029389 2026] [authz_core:error] [pid 507246:tid 507411] [client 66.249.66.36:60250] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:36.029697 2026] [authz_core:error] [pid 507246:tid 507411] [client 66.249.66.36:60250] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:36.048588 2026] [security2:error] [pid 507246:tid 507481] [client 20.104.50.220:33541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/nptice.php"] [unique_id "apPlBO8CsCvw81e_I2pG_AAAAwI"]
[Sun Aug 30 03:08:36.072497 2026] [security2:error] [pid 507246:tid 507423] [client 20.104.18.15:23364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/wp-content/k.php"] [unique_id "apPlBO8CsCvw81e_I2pHBQAAAsg"]
[Sun Aug 30 03:08:36.151759 2026] [security2:error] [pid 507246:tid 507405] [client 52.139.37.240:37233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/new.php"] [unique_id "apPlBO8CsCvw81e_I2pHIgAAArY"]
[Sun Aug 30 03:08:36.177779 2026] [security2:error] [pid 507246:tid 507453] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/application/.env"] [unique_id "apPlBO8CsCvw81e_I2pHLQAAAuY"]
[Sun Aug 30 03:08:36.179507 2026] [security2:error] [pid 507246:tid 507481] [client 20.104.50.220:16720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/simple.php"] [unique_id "apPlBO8CsCvw81e_I2pHLgAAAwI"]
[Sun Aug 30 03:08:36.189926 2026] [security2:error] [pid 507246:tid 507454] [client 20.48.251.3:60519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/wp-config.backup.php"] [unique_id "apPlBO8CsCvw81e_I2pHMgAAAuc"]
[Sun Aug 30 03:08:36.189968 2026] [authz_core:error] [pid 507246:tid 507480] [client 66.249.66.67:51157] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:36.190226 2026] [authz_core:error] [pid 507246:tid 507480] [client 66.249.66.67:51157] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:36.195623 2026] [security2:error] [pid 507246:tid 507495] [client 158.158.54.35:27073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/randkeyword.php"] [unique_id "apPlBO8CsCvw81e_I2pHNQAAAxA"]
[Sun Aug 30 03:08:36.202181 2026] [security2:error] [pid 507246:tid 507486] [client 20.48.251.3:59279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/localconf.php"] [unique_id "apPlBO8CsCvw81e_I2pHNwAAAwc"]
[Sun Aug 30 03:08:36.366289 2026] [security2:error] [pid 507246:tid 507405] [client 4.205.62.107:54445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPlBO8CsCvw81e_I2pHSQAAArY"]
[Sun Aug 30 03:08:36.376507 2026] [security2:error] [pid 507246:tid 507392] [client 4.205.62.107:25901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/guk.php"] [unique_id "apPlBO8CsCvw81e_I2pHSwAAAqk"]
[Sun Aug 30 03:08:36.393235 2026] [security2:error] [pid 507246:tid 507477] [client 20.196.209.81:12678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/wp.php"] [unique_id "apPlBO8CsCvw81e_I2pHTQAAAv4"]
[Sun Aug 30 03:08:36.412376 2026] [autoindex:error] [pid 507246:tid 507496] [client 52.139.37.240:37001] AH01276: Cannot serve directory /home3/matthew/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:08:36.422280 2026] [authz_core:error] [pid 507246:tid 507484] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:36.422552 2026] [authz_core:error] [pid 507246:tid 507484] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:36.430256 2026] [security2:error] [pid 507246:tid 507387] [client 20.48.251.3:6506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/phpversion.php"] [unique_id "apPlBO8CsCvw81e_I2pHTwAAAqQ"]
[Sun Aug 30 03:08:36.446912 2026] [security2:error] [pid 507246:tid 507413] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/bootstrap/.env"] [unique_id "apPlBO8CsCvw81e_I2pHUQAAAr4"]
[Sun Aug 30 03:08:36.448202 2026] [authz_core:error] [pid 507246:tid 507443] [client 66.249.66.69:36268] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:36.448466 2026] [authz_core:error] [pid 507246:tid 507443] [client 66.249.66.69:36268] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:36.475234 2026] [security2:error] [pid 507246:tid 507457] [client 52.139.37.240:37001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/il.php"] [unique_id "apPlBO8CsCvw81e_I2pHXAAAAuo"]
[Sun Aug 30 03:08:36.483138 2026] [authz_core:error] [pid 507246:tid 507398] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:36.483410 2026] [authz_core:error] [pid 507246:tid 507398] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:36.506321 2026] [security2:error] [pid 507246:tid 507421] [client 74.248.24.12:7456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/amaxx.php"] [unique_id "apPlBO8CsCvw81e_I2pHXwAAAsY"]
[Sun Aug 30 03:08:36.507683 2026] [security2:error] [pid 507246:tid 507489] [client 4.205.62.107:61703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/tinyfilemanager.php"] [unique_id "apPlBO8CsCvw81e_I2pHYAAAAwo"]
[Sun Aug 30 03:08:36.602838 2026] [security2:error] [pid 507246:tid 507389] [client 68.155.159.216:54470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-admin/css/index.php"] [unique_id "apPlBO8CsCvw81e_I2pHaAAAAqY"]
[Sun Aug 30 03:08:36.609797 2026] [authz_core:error] [pid 507246:tid 507427] [client 66.249.66.41:51240] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:36.610061 2026] [authz_core:error] [pid 507246:tid 507427] [client 66.249.66.41:51240] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:36.625170 2026] [authz_core:error] [pid 507246:tid 507486] [client 66.249.66.199:55032] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:36.625618 2026] [authz_core:error] [pid 507246:tid 507486] [client 66.249.66.199:55032] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:36.647698 2026] [security2:error] [pid 507246:tid 507481] [client 158.158.54.35:9657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/hehe.php"] [unique_id "apPlBO8CsCvw81e_I2pHcAAAAwI"]
[Sun Aug 30 03:08:36.675086 2026] [security2:error] [pid 507246:tid 507440] [client 52.139.37.240:37220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/images/index.php"] [unique_id "apPlBO8CsCvw81e_I2pHcgAAAtk"]
[Sun Aug 30 03:08:36.681810 2026] [security2:error] [pid 507246:tid 507433] [client 20.197.61.180:10194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/k.php"] [unique_id "apPlBO8CsCvw81e_I2pHcwAAAtI"]
[Sun Aug 30 03:08:36.729752 2026] [security2:error] [pid 507246:tid 507378] [client 68.155.159.216:60907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPlBO8CsCvw81e_I2pHdAAAAps"]
[Sun Aug 30 03:08:36.730701 2026] [security2:error] [pid 507246:tid 507432] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/database/.env"] [unique_id "apPlBO8CsCvw81e_I2pHdQAAAtE"]
[Sun Aug 30 03:08:36.742216 2026] [security2:error] [pid 507246:tid 507399] [client 216.73.216.128:22035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/',b,'"] [unique_id "apPlBO8CsCvw81e_I2pHdgAAArA"]
[Sun Aug 30 03:08:36.815099 2026] [security2:error] [pid 507246:tid 507461] [client 20.196.209.81:17665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/composer.php"] [unique_id "apPlBO8CsCvw81e_I2pHhgAAAu4"]
[Sun Aug 30 03:08:36.822074 2026] [authz_core:error] [pid 507246:tid 507435] [client 66.249.66.74:53782] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:36.822533 2026] [authz_core:error] [pid 507246:tid 507435] [client 66.249.66.74:53782] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:36.867110 2026] [security2:error] [pid 507246:tid 507479] [client 52.139.37.240:37188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/lite.php"] [unique_id "apPlBO8CsCvw81e_I2pHjAAAAwA"]
[Sun Aug 30 03:08:36.894155 2026] [security2:error] [pid 507246:tid 507466] [client 20.104.18.15:43296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/ops.php"] [unique_id "apPlBO8CsCvw81e_I2pHjQAAAvM"]
[Sun Aug 30 03:08:36.908725 2026] [security2:error] [pid 507246:tid 507392] [client 68.155.159.216:45909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPlBO8CsCvw81e_I2pHjgAAAqk"]
[Sun Aug 30 03:08:36.920115 2026] [authz_core:error] [pid 507246:tid 507452] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:36.920574 2026] [authz_core:error] [pid 507246:tid 507452] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:36.923924 2026] [security2:error] [pid 507246:tid 507402] [client 20.151.200.44:57902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/is.php"] [unique_id "apPlBO8CsCvw81e_I2pHkQAAArM"]
[Sun Aug 30 03:08:36.924002 2026] [security2:error] [pid 507246:tid 507450] [client 4.205.62.107:62126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/doc.php"] [unique_id "apPlBO8CsCvw81e_I2pHkAAAAuM"]
[Sun Aug 30 03:08:36.926352 2026] [security2:error] [pid 507246:tid 507431] [client 20.104.50.220:29579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/blog/fw.php"] [unique_id "apPlBO8CsCvw81e_I2pHkwAAAtA"]
[Sun Aug 30 03:08:36.944564 2026] [security2:error] [pid 507246:tid 507430] [client 20.104.18.15:18362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/8.php"] [unique_id "apPlBO8CsCvw81e_I2pHlAAAAs8"]
[Sun Aug 30 03:08:36.961765 2026] [security2:error] [pid 507246:tid 507457] [client 20.104.50.220:42767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/l3.php"] [unique_id "apPlBO8CsCvw81e_I2pHlQAAAuo"]
[Sun Aug 30 03:08:36.971671 2026] [security2:error] [pid 507246:tid 507453] [client 20.48.251.3:4721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/bb.php"] [unique_id "apPlBO8CsCvw81e_I2pHlwAAAuY"]
[Sun Aug 30 03:08:36.976824 2026] [security2:error] [pid 507246:tid 507421] [client 20.104.49.130:63527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/k.php"] [unique_id "apPlBO8CsCvw81e_I2pHmAAAAsY"]
[Sun Aug 30 03:08:36.978322 2026] [authz_core:error] [pid 507246:tid 507448] [client 66.249.66.35:38662] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:36.978779 2026] [authz_core:error] [pid 507246:tid 507448] [client 66.249.66.35:38662] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:36.979354 2026] [security2:error] [pid 507246:tid 507493] [client 20.104.50.220:46441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/efile.php"] [unique_id "apPlBO8CsCvw81e_I2pHmgAAAw4"]
[Sun Aug 30 03:08:37.016338 2026] [security2:error] [pid 507246:tid 507437] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/storage/.env"] [unique_id "apPlBe8CsCvw81e_I2pHngAAAtY"]
[Sun Aug 30 03:08:37.019129 2026] [security2:error] [pid 507246:tid 507406] [client 74.248.24.12:6842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/02.php"] [unique_id "apPlBe8CsCvw81e_I2pHoQAAArc"]
[Sun Aug 30 03:08:37.020861 2026] [security2:error] [pid 507246:tid 507481] [client 20.104.50.220:61466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/index7.php"] [unique_id "apPlBe8CsCvw81e_I2pHogAAAwI"]
[Sun Aug 30 03:08:37.036721 2026] [security2:error] [pid 507246:tid 507433] [client 20.104.18.15:34582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/bo.php"] [unique_id "apPlBe8CsCvw81e_I2pHpAAAAtI"]
[Sun Aug 30 03:08:37.058872 2026] [security2:error] [pid 507246:tid 507380] [client 114.119.150.15:39535] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "smithfieldicecreamplace.com"] [uri "/photo-gallery"] [unique_id "apPlBe8CsCvw81e_I2pHqQAAAp0"], referer: https://smithfieldicecreamplace.com/photo-gallery
[Sun Aug 30 03:08:37.060679 2026] [security2:error] [pid 507246:tid 507490] [client 52.139.37.240:36996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/xda.php"] [unique_id "apPlBe8CsCvw81e_I2pHqgAAAws"]
[Sun Aug 30 03:08:37.071165 2026] [authz_core:error] [pid 507246:tid 507399] [client 66.249.66.45:41850] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:37.071442 2026] [authz_core:error] [pid 507246:tid 507399] [client 66.249.66.45:41850] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:37.075759 2026] [security2:error] [pid 507246:tid 507383] [client 20.104.50.220:5904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/r.php"] [unique_id "apPlBe8CsCvw81e_I2pHrQAAAqA"]
[Sun Aug 30 03:08:37.080770 2026] [security2:error] [pid 507246:tid 507423] [client 20.104.18.15:2005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/simple.php"] [unique_id "apPlBe8CsCvw81e_I2pHrgAAAsg"]
[Sun Aug 30 03:08:37.102611 2026] [security2:error] [pid 507246:tid 507413] [client 158.158.54.35:10294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/user.php"] [unique_id "apPlBe8CsCvw81e_I2pHrwAAAr4"]
[Sun Aug 30 03:08:37.128831 2026] [security2:error] [pid 507246:tid 507393] [client 20.151.200.44:45967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlBe8CsCvw81e_I2pHsgAAAqo"]
[Sun Aug 30 03:08:37.140718 2026] [security2:error] [pid 507246:tid 507464] [client 20.104.18.15:35499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/one.php"] [unique_id "apPlBe8CsCvw81e_I2pHswAAAvE"]
[Sun Aug 30 03:08:37.178561 2026] [security2:error] [pid 507246:tid 507388] [client 20.104.50.220:32256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/alpa.php"] [unique_id "apPlBe8CsCvw81e_I2pHtAAAAqU"]
[Sun Aug 30 03:08:37.182675 2026] [security2:error] [pid 507246:tid 507491] [client 20.104.50.220:52838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/saya.php"] [unique_id "apPlBe8CsCvw81e_I2pHtQAAAww"]
[Sun Aug 30 03:08:37.203538 2026] [security2:error] [pid 507246:tid 507467] [client 20.104.50.220:33288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/tuyul.php"] [unique_id "apPlBe8CsCvw81e_I2pHuAAAAvQ"]
[Sun Aug 30 03:08:37.210638 2026] [security2:error] [pid 507246:tid 507382] [client 20.196.209.81:13233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/abcd.php"] [unique_id "apPlBe8CsCvw81e_I2pHuQAAAp8"]
[Sun Aug 30 03:08:37.236823 2026] [security2:error] [pid 507246:tid 507500] [client 20.104.18.15:23385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/os.php"] [unique_id "apPlBe8CsCvw81e_I2pHugAAAxU"]
[Sun Aug 30 03:08:37.249757 2026] [security2:error] [pid 507246:tid 507384] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/var/www/.env"] [unique_id "apPlBe8CsCvw81e_I2pHuwAAAqE"]
[Sun Aug 30 03:08:37.255299 2026] [security2:error] [pid 507246:tid 507473] [client 52.139.37.240:37186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/.trash7206/index.php"] [unique_id "apPlBe8CsCvw81e_I2pHvQAAAvo"]
[Sun Aug 30 03:08:37.268871 2026] [authz_core:error] [pid 507246:tid 507405] [client 66.249.66.201:64892] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:37.269170 2026] [authz_core:error] [pid 507246:tid 507405] [client 66.249.66.201:64892] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:37.296602 2026] [authz_core:error] [pid 507246:tid 507477] [client 216.73.216.128:44807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:37.296872 2026] [authz_core:error] [pid 507246:tid 507477] [client 216.73.216.128:44807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:37.307428 2026] [authz_core:error] [pid 507246:tid 507496] [client 66.249.66.200:47750] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:37.307708 2026] [authz_core:error] [pid 507246:tid 507496] [client 66.249.66.200:47750] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:37.310152 2026] [security2:error] [pid 507246:tid 507431] [client 20.104.50.220:17265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/kj.php"] [unique_id "apPlBe8CsCvw81e_I2pHwQAAAtA"]
[Sun Aug 30 03:08:37.327825 2026] [security2:error] [pid 507246:tid 507411] [client 20.104.49.130:52463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/crgio.php"] [unique_id "apPlBe8CsCvw81e_I2pHwwAAArw"]
[Sun Aug 30 03:08:37.345780 2026] [security2:error] [pid 507246:tid 507426] [client 20.48.251.3:59294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/bengi.php"] [unique_id "apPlBe8CsCvw81e_I2pHxQAAAss"]
[Sun Aug 30 03:08:37.371065 2026] [security2:error] [pid 507246:tid 507421] [client 20.48.251.3:13438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/edit.php"] [unique_id "apPlBe8CsCvw81e_I2pHxwAAAsY"]
[Sun Aug 30 03:08:37.395268 2026] [security2:error] [pid 507246:tid 507498] [client 20.104.49.130:57714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/f35.update.php"] [unique_id "apPlBe8CsCvw81e_I2pHywAAAxM"]
[Sun Aug 30 03:08:37.410411 2026] [security2:error] [pid 507246:tid 507439] [client 20.197.61.180:8824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/chosen.php"] [unique_id "apPlBe8CsCvw81e_I2pHzAAAAtg"]
[Sun Aug 30 03:08:37.427524 2026] [authz_core:error] [pid 507246:tid 507503] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:37.427801 2026] [authz_core:error] [pid 507246:tid 507503] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:37.446537 2026] [security2:error] [pid 507246:tid 507445] [client 52.139.37.240:37002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/storage/index.php"] [unique_id "apPlBe8CsCvw81e_I2pHzgAAAt4"]
[Sun Aug 30 03:08:37.504653 2026] [security2:error] [pid 507246:tid 507441] [client 4.205.62.107:22546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/agg.php"] [unique_id "apPlBe8CsCvw81e_I2pH0QAAAto"]
[Sun Aug 30 03:08:37.508173 2026] [security2:error] [pid 507246:tid 507502] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/var/www/html/.env"] [unique_id "apPlBe8CsCvw81e_I2pH0gAAAxc"]
[Sun Aug 30 03:08:37.515888 2026] [security2:error] [pid 507246:tid 507452] [client 4.205.62.107:25780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/config_dev.php"] [unique_id "apPlBe8CsCvw81e_I2pH0wAAAuU"]
[Sun Aug 30 03:08:37.533119 2026] [security2:error] [pid 507246:tid 507453] [client 74.248.24.12:23950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/csv.php"] [unique_id "apPlBe8CsCvw81e_I2pH1AAAAuY"]
[Sun Aug 30 03:08:37.554509 2026] [security2:error] [pid 507246:tid 507390] [client 20.104.49.130:63264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/css.php"] [unique_id "apPlBe8CsCvw81e_I2pH1gAAAqc"]
[Sun Aug 30 03:08:37.560546 2026] [authz_core:error] [pid 507246:tid 507423] [client 66.249.66.71:46541] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:37.560975 2026] [authz_core:error] [pid 507246:tid 507423] [client 66.249.66.71:46541] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:37.570490 2026] [authz_core:error] [pid 507246:tid 507394] [client 216.73.216.128:18339] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:37.570908 2026] [authz_core:error] [pid 507246:tid 507394] [client 216.73.216.128:18339] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:37.571556 2026] [security2:error] [pid 507246:tid 507472] [client 158.158.54.35:27089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/functions.php"] [unique_id "apPlBe8CsCvw81e_I2pH2AAAAvk"]
[Sun Aug 30 03:08:37.617317 2026] [security2:error] [pid 507246:tid 507380] [client 20.196.209.81:10102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/sf.php"] [unique_id "apPlBe8CsCvw81e_I2pH2gAAAp0"]
[Sun Aug 30 03:08:37.647224 2026] [security2:error] [pid 507246:tid 507444] [client 4.205.62.107:64488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/05.php"] [unique_id "apPlBe8CsCvw81e_I2pH2wAAAt0"]
[Sun Aug 30 03:08:37.653008 2026] [security2:error] [pid 507246:tid 507376] [client 52.139.37.240:37031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPlBe8CsCvw81e_I2pH3AAAApk"]
[Sun Aug 30 03:08:37.669013 2026] [security2:error] [pid 507246:tid 507410] [client 20.48.251.3:6489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/adminfus.php"] [unique_id "apPlBe8CsCvw81e_I2pH3wAAArs"]
[Sun Aug 30 03:08:37.678746 2026] [security2:error] [pid 507246:tid 507388] [client 20.104.49.130:51565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlBe8CsCvw81e_I2pH4AAAAqU"]
[Sun Aug 30 03:08:37.725392 2026] [security2:error] [pid 507246:tid 507409] [client 68.155.159.216:55103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-admin/images/index.php"] [unique_id "apPlBe8CsCvw81e_I2pH4gAAAro"]
[Sun Aug 30 03:08:37.770480 2026] [security2:error] [pid 507246:tid 507446] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/current/.env"] [unique_id "apPlBe8CsCvw81e_I2pH5AAAAt8"]
[Sun Aug 30 03:08:37.816567 2026] [security2:error] [pid 507246:tid 507387] [client 20.104.49.130:58203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/term.php"] [unique_id "apPlBe8CsCvw81e_I2pH5gAAAqQ"]
[Sun Aug 30 03:08:37.858362 2026] [security2:error] [pid 507246:tid 507431] [client 52.139.37.240:37239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/wp-blog.php"] [unique_id "apPlBe8CsCvw81e_I2pH7wAAAtA"]
[Sun Aug 30 03:08:37.937057 2026] [authz_core:error] [pid 507246:tid 507443] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:37.937522 2026] [authz_core:error] [pid 507246:tid 507443] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:37.948671 2026] [authz_core:error] [pid 507246:tid 507437] [client 66.249.66.35:35914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:37.949106 2026] [authz_core:error] [pid 507246:tid 507437] [client 66.249.66.35:35914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:37.956915 2026] [security2:error] [pid 507246:tid 507399] [client 4.205.62.107:36665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/xmy.php"] [unique_id "apPlBe8CsCvw81e_I2pH-wAAArA"]
[Sun Aug 30 03:08:37.982674 2026] [authz_core:error] [pid 507246:tid 507453] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:37.982959 2026] [authz_core:error] [pid 507246:tid 507453] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:37.998054 2026] [authz_core:error] [pid 507246:tid 507441] [client 66.249.66.197:42036] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:37.998351 2026] [authz_core:error] [pid 507246:tid 507441] [client 66.249.66.197:42036] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:38.012154 2026] [security2:error] [pid 507246:tid 507472] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/release/.env"] [unique_id "apPlBu8CsCvw81e_I2pH_wAAAvk"]
[Sun Aug 30 03:08:38.019632 2026] [security2:error] [pid 507246:tid 507498] [client 158.158.54.35:26805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/cron.php"] [unique_id "apPlBu8CsCvw81e_I2pIAQAAAxM"]
[Sun Aug 30 03:08:38.040072 2026] [security2:error] [pid 507246:tid 507416] [client 20.196.209.81:12955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/gel4y.php"] [unique_id "apPlBu8CsCvw81e_I2pIAgAAAsE"]
[Sun Aug 30 03:08:38.041300 2026] [security2:error] [pid 507246:tid 507474] [client 74.248.24.12:7835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/curl.php"] [unique_id "apPlBu8CsCvw81e_I2pIAwAAAvs"]
[Sun Aug 30 03:08:38.044831 2026] [security2:error] [pid 507246:tid 507462] [client 68.155.159.216:61434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/images/index.php"] [unique_id "apPlBu8CsCvw81e_I2pIBAAAAu8"]
[Sun Aug 30 03:08:38.051925 2026] [security2:error] [pid 507246:tid 507424] [client 52.139.37.240:37217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/xmlrpc.php"] [unique_id "apPlBu8CsCvw81e_I2pIBwAAAsk"]
[Sun Aug 30 03:08:38.061590 2026] [security2:error] [pid 507246:tid 507376] [client 4.205.62.107:63953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/classsmtps.php"] [unique_id "apPlBu8CsCvw81e_I2pICwAAApk"]
[Sun Aug 30 03:08:38.073331 2026] [security2:error] [pid 507246:tid 507397] [client 20.104.50.220:28716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-optionss.php"] [unique_id "apPlBu8CsCvw81e_I2pIDgAAAq4"]
[Sun Aug 30 03:08:38.087040 2026] [security2:error] [pid 507246:tid 507487] [client 20.104.18.15:18388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/goods.php"] [unique_id "apPlBu8CsCvw81e_I2pIDwAAAwg"]
[Sun Aug 30 03:08:38.092351 2026] [security2:error] [pid 507246:tid 507394] [client 20.104.18.15:43264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/coffexium.php"] [unique_id "apPlBu8CsCvw81e_I2pIEAAAAqs"]
[Sun Aug 30 03:08:38.116915 2026] [security2:error] [pid 507246:tid 507384] [client 20.104.50.220:51567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/fellganteng.php"] [unique_id "apPlBu8CsCvw81e_I2pIFAAAAqE"]
[Sun Aug 30 03:08:38.119308 2026] [security2:error] [pid 507246:tid 507473] [client 20.48.251.3:44354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/file59.php"] [unique_id "apPlBu8CsCvw81e_I2pIFQAAAvo"]
[Sun Aug 30 03:08:38.133675 2026] [security2:error] [pid 507246:tid 507409] [client 20.104.50.220:47069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/afile.php"] [unique_id "apPlBu8CsCvw81e_I2pIFwAAAro"]
[Sun Aug 30 03:08:38.146726 2026] [security2:error] [pid 507246:tid 507481] [client 20.197.61.180:10220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/radio.php"] [unique_id "apPlBu8CsCvw81e_I2pIGAAAAwI"]
[Sun Aug 30 03:08:38.170089 2026] [security2:error] [pid 507246:tid 507391] [client 20.151.200.44:45971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlBu8CsCvw81e_I2pIGwAAAqg"]
[Sun Aug 30 03:08:38.174104 2026] [security2:error] [pid 507246:tid 507459] [client 68.155.159.216:45957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPlBu8CsCvw81e_I2pIHAAAAuw"]
[Sun Aug 30 03:08:38.186413 2026] [security2:error] [pid 507246:tid 507432] [client 20.104.18.15:34751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/44.php"] [unique_id "apPlBu8CsCvw81e_I2pIHwAAAtE"]
[Sun Aug 30 03:08:38.212619 2026] [security2:error] [pid 507246:tid 507445] [client 20.104.50.220:61668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/index8.php"] [unique_id "apPlBu8CsCvw81e_I2pIIwAAAt4"]
[Sun Aug 30 03:08:38.212792 2026] [security2:error] [pid 507246:tid 507413] [client 20.104.50.220:6118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/q.php"] [unique_id "apPlBu8CsCvw81e_I2pIIgAAAr4"]
[Sun Aug 30 03:08:38.215967 2026] [authz_core:error] [pid 507246:tid 507461] [client 66.249.66.66:47389] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:38.216400 2026] [authz_core:error] [pid 507246:tid 507461] [client 66.249.66.66:47389] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:38.234141 2026] [security2:error] [pid 507246:tid 507420] [client 20.104.18.15:1959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/sallu.php"] [unique_id "apPlBu8CsCvw81e_I2pIJQAAAsU"]
[Sun Aug 30 03:08:38.244702 2026] [security2:error] [pid 507246:tid 507423] [client 52.139.37.240:37224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/lu4.php"] [unique_id "apPlBu8CsCvw81e_I2pIJgAAAsg"]
[Sun Aug 30 03:08:38.244732 2026] [security2:error] [pid 507246:tid 507494] [client 20.104.49.130:62299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/txets.php"] [unique_id "apPlBu8CsCvw81e_I2pIJwAAAw8"]
[Sun Aug 30 03:08:38.248176 2026] [security2:error] [pid 507246:tid 507404] [client 20.104.49.130:43269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/load.php"] [unique_id "apPlBu8CsCvw81e_I2pIKAAAArU"]
[Sun Aug 30 03:08:38.295723 2026] [security2:error] [pid 507246:tid 507448] [client 20.104.18.15:35197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/503.php"] [unique_id "apPlBu8CsCvw81e_I2pIKgAAAuE"]
[Sun Aug 30 03:08:38.297424 2026] [authz_core:error] [pid 507246:tid 507399] [client 216.73.216.128:18339] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:38.297692 2026] [authz_core:error] [pid 507246:tid 507399] [client 216.73.216.128:18339] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:38.313337 2026] [security2:error] [pid 507246:tid 507503] [client 20.104.50.220:31932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/file21.php"] [unique_id "apPlBu8CsCvw81e_I2pILgAAAxg"]
[Sun Aug 30 03:08:38.321451 2026] [security2:error] [pid 507246:tid 507462] [client 20.104.50.220:29179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/do.php"] [unique_id "apPlBu8CsCvw81e_I2pIMAAAAu8"]
[Sun Aug 30 03:08:38.349923 2026] [security2:error] [pid 507246:tid 507410] [client 20.151.200.44:46045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/h02ugyh.php"] [unique_id "apPlBu8CsCvw81e_I2pIMQAAArs"]
[Sun Aug 30 03:08:38.351425 2026] [security2:error] [pid 507246:tid 507380] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/releases/.env"] [unique_id "apPlBu8CsCvw81e_I2pIMgAAAp0"]
[Sun Aug 30 03:08:38.358564 2026] [security2:error] [pid 507246:tid 507388] [client 20.104.50.220:33048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/nikung.php"] [unique_id "apPlBu8CsCvw81e_I2pIMwAAAqU"]
[Sun Aug 30 03:08:38.380177 2026] [security2:error] [pid 507246:tid 507460] [client 20.104.18.15:23548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/htio.php"] [unique_id "apPlBu8CsCvw81e_I2pINwAAAu0"]
[Sun Aug 30 03:08:38.388450 2026] [authz_core:error] [pid 507246:tid 507464] [client 216.73.216.128:42925] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:38.388757 2026] [authz_core:error] [pid 507246:tid 507464] [client 216.73.216.128:42925] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:38.435672 2026] [security2:error] [pid 507246:tid 507472] [client 20.196.209.81:10049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/leaf.php"] [unique_id "apPlBu8CsCvw81e_I2pIPQAAAvk"]
[Sun Aug 30 03:08:38.440151 2026] [security2:error] [pid 507246:tid 507484] [client 52.139.37.240:37200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "apPlBu8CsCvw81e_I2pIQQAAAwU"]
[Sun Aug 30 03:08:38.440401 2026] [security2:error] [pid 507246:tid 507392] [client 20.151.200.44:47076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/im.php"] [unique_id "apPlBu8CsCvw81e_I2pIPwAAAqk"]
[Sun Aug 30 03:08:38.440510 2026] [security2:error] [pid 507246:tid 507430] [client 20.104.50.220:17237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/xxx.php"] [unique_id "apPlBu8CsCvw81e_I2pIQAAAAs8"]
[Sun Aug 30 03:08:38.451044 2026] [authz_core:error] [pid 507246:tid 507453] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:38.451501 2026] [authz_core:error] [pid 507246:tid 507453] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:38.479044 2026] [authz_core:error] [pid 507246:tid 507426] [client 216.73.216.128:44807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:38.479309 2026] [authz_core:error] [pid 507246:tid 507426] [client 216.73.216.128:44807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:38.481982 2026] [security2:error] [pid 507246:tid 507442] [client 158.158.54.35:20308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/cookie.php"] [unique_id "apPlBu8CsCvw81e_I2pIRgAAAts"]
[Sun Aug 30 03:08:38.489298 2026] [security2:error] [pid 507246:tid 507436] [client 20.48.251.3:59357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/i.php"] [unique_id "apPlBu8CsCvw81e_I2pISAAAAtU"]
[Sun Aug 30 03:08:38.527472 2026] [security2:error] [pid 507246:tid 507423] [client 20.48.251.3:56366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/8.php"] [unique_id "apPlBu8CsCvw81e_I2pISQAAAsg"]
[Sun Aug 30 03:08:38.554075 2026] [security2:error] [pid 507246:tid 507487] [client 74.248.24.12:6801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/cloud.php"] [unique_id "apPlBu8CsCvw81e_I2pISwAAAwg"]
[Sun Aug 30 03:08:38.594810 2026] [security2:error] [pid 507246:tid 507462] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/shared/.env"] [unique_id "apPlBu8CsCvw81e_I2pIUAAAAu8"]
[Sun Aug 30 03:08:38.641145 2026] [security2:error] [pid 507246:tid 507448] [client 52.139.37.240:37201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "apPlBu8CsCvw81e_I2pIVQAAAuE"]
[Sun Aug 30 03:08:38.651682 2026] [security2:error] [pid 507246:tid 507397] [client 4.205.62.107:25736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/aws_credentials.php"] [unique_id "apPlBu8CsCvw81e_I2pIVgAAAq4"]
[Sun Aug 30 03:08:38.655365 2026] [security2:error] [pid 507246:tid 507460] [client 4.205.62.107:62402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/requirements.php"] [unique_id "apPlBu8CsCvw81e_I2pIWAAAAu0"]
[Sun Aug 30 03:08:38.664925 2026] [authz_core:error] [pid 507246:tid 507447] [client 66.249.66.34:48890] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:38.665197 2026] [authz_core:error] [pid 507246:tid 507447] [client 66.249.66.34:48890] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:38.747133 2026] [authz_core:error] [pid 507246:tid 507384] [client 66.249.66.38:57173] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:38.747405 2026] [authz_core:error] [pid 507246:tid 507384] [client 66.249.66.38:57173] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:38.833264 2026] [security2:error] [pid 507246:tid 507391] [client 52.139.37.240:37185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "apPlBu8CsCvw81e_I2pIcgAAAqg"]
[Sun Aug 30 03:08:38.836073 2026] [security2:error] [pid 507246:tid 507463] [client 20.196.209.81:13185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/k.php"] [unique_id "apPlBu8CsCvw81e_I2pIcwAAAvA"]
[Sun Aug 30 03:08:38.839677 2026] [security2:error] [pid 507246:tid 507408] [client 20.48.251.3:7082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/avim.php"] [unique_id "apPlBu8CsCvw81e_I2pIdwAAArk"]
[Sun Aug 30 03:08:38.848209 2026] [security2:error] [pid 507246:tid 507390] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/deploy/.env"] [unique_id "apPlBu8CsCvw81e_I2pIfQAAAqc"]
[Sun Aug 30 03:08:38.851235 2026] [security2:error] [pid 507246:tid 507416] [client 4.205.62.107:58440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/wp-blog.php"] [unique_id "apPlBu8CsCvw81e_I2pIfwAAAsE"]
[Sun Aug 30 03:08:38.853177 2026] [authz_core:error] [pid 507246:tid 507440] [client 66.249.66.198:50541] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:38.853624 2026] [authz_core:error] [pid 507246:tid 507440] [client 66.249.66.198:50541] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:38.862450 2026] [security2:error] [pid 507246:tid 507468] [client 68.155.159.216:54492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-includes/index.php"] [unique_id "apPlBu8CsCvw81e_I2pIgAAAAvU"]
[Sun Aug 30 03:08:38.883854 2026] [security2:error] [pid 507246:tid 507454] [client 20.151.200.44:59512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/od.php"] [unique_id "apPlBu8CsCvw81e_I2pIgwAAAuc"]
[Sun Aug 30 03:08:38.926884 2026] [authz_core:error] [pid 507246:tid 507432] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:38.927224 2026] [authz_core:error] [pid 507246:tid 507432] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:38.939059 2026] [security2:error] [pid 507246:tid 507497] [client 20.197.61.180:10215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/functions.php"] [unique_id "apPlBu8CsCvw81e_I2pIjAAAAxI"]
[Sun Aug 30 03:08:38.944065 2026] [security2:error] [pid 507246:tid 507459] [client 158.158.54.35:5387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/spip.php"] [unique_id "apPlBu8CsCvw81e_I2pIjwAAAuw"]
[Sun Aug 30 03:08:38.946737 2026] [authz_core:error] [pid 507246:tid 507410] [client 66.249.66.37:51352] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:38.946999 2026] [authz_core:error] [pid 507246:tid 507410] [client 66.249.66.37:51352] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:38.951077 2026] [security2:error] [pid 507246:tid 507500] [client 20.104.49.130:26942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlBu8CsCvw81e_I2pIkAAAAxU"]
[Sun Aug 30 03:08:39.027977 2026] [security2:error] [pid 507246:tid 507481] [client 52.139.37.240:37187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/ant.php"] [unique_id "apPlB-8CsCvw81e_I2pIlwAAAwI"]
[Sun Aug 30 03:08:39.069318 2026] [security2:error] [pid 507246:tid 507448] [client 74.248.24.12:7861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/add_actualites.php"] [unique_id "apPlB-8CsCvw81e_I2pIoAAAAuE"]
[Sun Aug 30 03:08:39.092377 2026] [authz_core:error] [pid 507246:tid 507442] [client 66.249.66.202:47441] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:39.092659 2026] [authz_core:error] [pid 507246:tid 507442] [client 66.249.66.202:47441] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:39.100320 2026] [security2:error] [pid 507246:tid 507380] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/build/.env"] [unique_id "apPlB-8CsCvw81e_I2pIpgAAAp0"]
[Sun Aug 30 03:08:39.122090 2026] [authz_core:error] [pid 507246:tid 507459] [client 216.73.216.128:42925] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:39.122420 2026] [authz_core:error] [pid 507246:tid 507459] [client 216.73.216.128:42925] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:39.167558 2026] [security2:error] [pid 507246:tid 507491] [client 68.155.159.216:53442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apPlB-8CsCvw81e_I2pIsAAAAww"]
[Sun Aug 30 03:08:39.186143 2026] [security2:error] [pid 507246:tid 507437] [client 20.151.200.44:46077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/sf.php"] [unique_id "apPlB-8CsCvw81e_I2pItAAAAtY"]
[Sun Aug 30 03:08:39.207369 2026] [security2:error] [pid 507246:tid 507384] [client 4.205.62.107:62113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/cache-compat.php"] [unique_id "apPlB-8CsCvw81e_I2pIuQAAAqE"]
[Sun Aug 30 03:08:39.221465 2026] [security2:error] [pid 507246:tid 507436] [client 20.104.50.220:28693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/work.php"] [unique_id "apPlB-8CsCvw81e_I2pIvAAAAtU"]
[Sun Aug 30 03:08:39.221955 2026] [security2:error] [pid 507246:tid 507423] [client 52.139.37.240:37034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/autoload_classmap.php"] [unique_id "apPlB-8CsCvw81e_I2pIvQAAAsg"]
[Sun Aug 30 03:08:39.224791 2026] [security2:error] [pid 507246:tid 507378] [client 20.104.18.15:18364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/ah.php"] [unique_id "apPlB-8CsCvw81e_I2pIvgAAAps"]
[Sun Aug 30 03:08:39.234103 2026] [security2:error] [pid 507246:tid 507492] [client 20.196.209.81:12978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/chosen.php"] [unique_id "apPlB-8CsCvw81e_I2pIvwAAAw0"]
[Sun Aug 30 03:08:39.250048 2026] [security2:error] [pid 507246:tid 507498] [client 20.104.18.15:44027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/BDKR28WP.php"] [unique_id "apPlB-8CsCvw81e_I2pIwQAAAxM"]
[Sun Aug 30 03:08:39.250062 2026] [authz_core:error] [pid 507246:tid 507408] [client 66.249.66.192:61555] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:39.250342 2026] [authz_core:error] [pid 507246:tid 507408] [client 66.249.66.192:61555] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:39.261123 2026] [security2:error] [pid 507246:tid 507448] [client 20.48.251.3:4696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/cli_bootstrap.php"] [unique_id "apPlB-8CsCvw81e_I2pIwwAAAuE"]
[Sun Aug 30 03:08:39.269591 2026] [security2:error] [pid 507246:tid 507406] [client 20.104.50.220:42468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/fell.php"] [unique_id "apPlB-8CsCvw81e_I2pIxwAAArc"]
[Sun Aug 30 03:08:39.271313 2026] [security2:error] [pid 507246:tid 507398] [client 20.104.50.220:46410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/f35.php"] [unique_id "apPlB-8CsCvw81e_I2pIyAAAAq8"]
[Sun Aug 30 03:08:39.324898 2026] [core:alert] [pid 507246:tid 507338] [remote 52.167.144.204:38112] /home3/lordrcan/public_html/.htaccess: without matching section
[Sun Aug 30 03:08:39.332336 2026] [security2:error] [pid 507246:tid 507451] [client 20.104.18.15:34720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/h2.php"] [unique_id "apPlB-8CsCvw81e_I2pI1gAAAuQ"]
[Sun Aug 30 03:08:39.351053 2026] [security2:error] [pid 507246:tid 507392] [client 20.104.50.220:5626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/p.php"] [unique_id "apPlB-8CsCvw81e_I2pI2QAAAqk"]
[Sun Aug 30 03:08:39.355571 2026] [security2:error] [pid 507246:tid 507483] [client 20.104.50.220:61397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/index9.php"] [unique_id "apPlB-8CsCvw81e_I2pI2gAAAwQ"]
[Sun Aug 30 03:08:39.372306 2026] [security2:error] [pid 507246:tid 507467] [client 20.104.18.15:1934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/biufile.php"] [unique_id "apPlB-8CsCvw81e_I2pI2wAAAvQ"]
[Sun Aug 30 03:08:39.377495 2026] [security2:error] [pid 507246:tid 507490] [client 158.158.54.35:27111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/22.php"] [unique_id "apPlB-8CsCvw81e_I2pI3QAAAws"]
[Sun Aug 30 03:08:39.398069 2026] [security2:error] [pid 507246:tid 507501] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/dist/.env"] [unique_id "apPlB-8CsCvw81e_I2pI4AAAAxY"]
[Sun Aug 30 03:08:39.420848 2026] [authz_core:error] [pid 507246:tid 507378] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:39.421322 2026] [authz_core:error] [pid 507246:tid 507378] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:39.422808 2026] [security2:error] [pid 507246:tid 507376] [client 52.139.37.240:37211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/storage/rip.php"] [unique_id "apPlB-8CsCvw81e_I2pI5gAAApk"]
[Sun Aug 30 03:08:39.425664 2026] [security2:error] [pid 507246:tid 507406] [client 68.155.159.216:46074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-includes/Requests/network.php"] [unique_id "apPlB-8CsCvw81e_I2pI6AAAArc"]
[Sun Aug 30 03:08:39.439002 2026] [security2:error] [pid 507246:tid 507454] [client 20.104.18.15:35480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/504.php"] [unique_id "apPlB-8CsCvw81e_I2pI6wAAAuc"]
[Sun Aug 30 03:08:39.464523 2026] [security2:error] [pid 507246:tid 507380] [client 20.104.50.220:52809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/funtion.php"] [unique_id "apPlB-8CsCvw81e_I2pI7AAAAp0"]
[Sun Aug 30 03:08:39.487433 2026] [security2:error] [pid 507246:tid 507426] [client 20.104.50.220:32111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/ut.php"] [unique_id "apPlB-8CsCvw81e_I2pI7gAAAss"]
[Sun Aug 30 03:08:39.490150 2026] [authz_core:error] [pid 507246:tid 507470] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:39.490427 2026] [authz_core:error] [pid 507246:tid 507470] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:39.512249 2026] [authz_core:error] [pid 507246:tid 507460] [client 216.73.216.128:42925] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:39.512530 2026] [authz_core:error] [pid 507246:tid 507460] [client 216.73.216.128:42925] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:39.514024 2026] [security2:error] [pid 507246:tid 507464] [client 20.104.50.220:33190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/tertykung.php"] [unique_id "apPlB-8CsCvw81e_I2pI8wAAAvE"]
[Sun Aug 30 03:08:39.578617 2026] [security2:error] [pid 507246:tid 507392] [client 20.104.50.220:17311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/hypo.php"] [unique_id "apPlB-8CsCvw81e_I2pI-wAAAqk"]
[Sun Aug 30 03:08:39.588621 2026] [authz_core:error] [pid 507246:tid 507451] [client 66.249.66.38:35472] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:39.588929 2026] [authz_core:error] [pid 507246:tid 507451] [client 66.249.66.38:35472] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:39.591353 2026] [security2:error] [pid 507246:tid 507498] [client 74.248.24.12:14846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/contact_tpl.php"] [unique_id "apPlB-8CsCvw81e_I2pI_gAAAxM"]
[Sun Aug 30 03:08:39.598106 2026] [authz_core:error] [pid 507246:tid 507389] [client 66.249.66.36:60250] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:39.598382 2026] [authz_core:error] [pid 507246:tid 507389] [client 66.249.66.36:60250] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:39.614602 2026] [security2:error] [pid 507246:tid 507437] [client 52.139.37.240:37219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/tinyfilemanager.php"] [unique_id "apPlB-8CsCvw81e_I2pJAAAAAtY"]
[Sun Aug 30 03:08:39.625811 2026] [security2:error] [pid 507246:tid 507430] [client 20.48.251.3:59391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/guk.php"] [unique_id "apPlB-8CsCvw81e_I2pJAwAAAs8"]
[Sun Aug 30 03:08:39.633862 2026] [security2:error] [pid 507246:tid 507449] [client 20.196.209.81:13244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/radio.php"] [unique_id "apPlB-8CsCvw81e_I2pJBAAAAuI"]
[Sun Aug 30 03:08:39.651064 2026] [security2:error] [pid 507246:tid 507499] [client 4.205.62.107:35999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/ms-edit.php"] [unique_id "apPlB-8CsCvw81e_I2pJBwAAAxQ"]
[Sun Aug 30 03:08:39.655323 2026] [security2:error] [pid 507246:tid 507459] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/public_html/.env"] [unique_id "apPlB-8CsCvw81e_I2pJCAAAAuw"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:39.672752 2026] [security2:error] [pid 507246:tid 507462] [client 20.48.251.3:33315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/thui.php"] [unique_id "apPlB-8CsCvw81e_I2pJDQAAAu8"]
[Sun Aug 30 03:08:39.695944 2026] [security2:error] [pid 507246:tid 507340] [remote 118.99.73.30:29477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.73.99.118.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelongthread.com"] [uri "/wp-login.php"] [unique_id "apPlB-8CsCvw81e_I2pJFAAC610"]
[Sun Aug 30 03:08:39.697836 2026] [security2:error] [pid 507246:tid 507433] [client 20.197.61.180:7957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/elp.php"] [unique_id "apPlB-8CsCvw81e_I2pJFgAAAtI"]
[Sun Aug 30 03:08:39.702226 2026] [authz_core:error] [pid 507246:tid 507473] [client 66.249.66.38:51680] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:39.702672 2026] [authz_core:error] [pid 507246:tid 507473] [client 66.249.66.38:51680] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:39.812374 2026] [security2:error] [pid 507246:tid 507491] [client 4.205.62.107:25737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/aws-credentials.php"] [unique_id "apPlB-8CsCvw81e_I2pJHAAAAww"]
[Sun Aug 30 03:08:39.814267 2026] [security2:error] [pid 507246:tid 507452] [client 4.205.62.107:22954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/var/www/wallet/index.php"] [unique_id "apPlB-8CsCvw81e_I2pJHgAAAuU"]
[Sun Aug 30 03:08:39.818711 2026] [security2:error] [pid 507246:tid 507475] [client 20.151.200.44:55652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/ca.php"] [unique_id "apPlB-8CsCvw81e_I2pJIQAAAvw"]
[Sun Aug 30 03:08:39.821678 2026] [security2:error] [pid 507246:tid 507492] [client 158.158.54.35:10261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/room.php"] [unique_id "apPlB-8CsCvw81e_I2pJIwAAAw0"]
[Sun Aug 30 03:08:39.826592 2026] [security2:error] [pid 507246:tid 507498] [client 20.104.49.130:52301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/sd.php"] [unique_id "apPlB-8CsCvw81e_I2pJJAAAAxM"]
[Sun Aug 30 03:08:39.864455 2026] [authz_core:error] [pid 507246:tid 507490] [client 66.249.66.35:38674] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:39.864748 2026] [authz_core:error] [pid 507246:tid 507490] [client 66.249.66.35:38674] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:39.876745 2026] [authz_core:error] [pid 507246:tid 507487] [client 66.249.66.65:48761] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:39.877281 2026] [authz_core:error] [pid 507246:tid 507487] [client 66.249.66.65:48761] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:39.892224 2026] [security2:error] [pid 507246:tid 507417] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/htdocs/.env"] [unique_id "apPlB-8CsCvw81e_I2pJOAAAAsI"]
[Sun Aug 30 03:08:39.932326 2026] [authz_core:error] [pid 507246:tid 507403] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:39.932632 2026] [authz_core:error] [pid 507246:tid 507403] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:39.941955 2026] [security2:error] [pid 507246:tid 507435] [client 4.205.62.107:25901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/4563.php"] [unique_id "apPlB-8CsCvw81e_I2pJQAAAAtQ"]
[Sun Aug 30 03:08:39.971837 2026] [security2:error] [pid 507246:tid 507452] [client 68.155.159.216:54220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/mah.php"] [unique_id "apPlB-8CsCvw81e_I2pJRAAAAuU"]
[Sun Aug 30 03:08:39.986883 2026] [security2:error] [pid 507246:tid 507502] [client 4.205.62.107:58245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/erty.php"] [unique_id "apPlB-8CsCvw81e_I2pJRgAAAxc"]
[Sun Aug 30 03:08:40.015194 2026] [security2:error] [pid 507246:tid 507436] [client 20.48.251.3:6466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/nw.php"] [unique_id "apPlCO8CsCvw81e_I2pJTAAAAtU"]
[Sun Aug 30 03:08:40.022020 2026] [security2:error] [pid 507246:tid 507398] [client 20.151.200.44:46017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/4e.php"] [unique_id "apPlCO8CsCvw81e_I2pJTQAAAq8"]
[Sun Aug 30 03:08:40.022846 2026] [security2:error] [pid 507246:tid 507395] [client 20.104.49.130:57673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/term.php"] [unique_id "apPlCO8CsCvw81e_I2pJTgAAAqw"]
[Sun Aug 30 03:08:40.029016 2026] [security2:error] [pid 507246:tid 507390] [client 20.104.49.130:63588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/reop3.php"] [unique_id "apPlCO8CsCvw81e_I2pJUAAAAqc"]
[Sun Aug 30 03:08:40.036662 2026] [security2:error] [pid 507246:tid 507503] [client 20.196.209.81:13202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/functions.php"] [unique_id "apPlCO8CsCvw81e_I2pJUwAAAxg"]
[Sun Aug 30 03:08:40.045106 2026] [security2:error] [pid 507246:tid 507426] [client 68.155.159.216:45957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-content/radio.php"] [unique_id "apPlCO8CsCvw81e_I2pJVAAAAss"]
[Sun Aug 30 03:08:40.115062 2026] [security2:error] [pid 507246:tid 507347] [remote 118.99.73.30:29477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.73.99.118.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelongthread.com"] [uri "/wp-login.php"] [unique_id "apPlCO8CsCvw81e_I2pJZwACz2Q"], referer: https://thelongthread.com/wp-login.php
[Sun Aug 30 03:08:40.118198 2026] [security2:error] [pid 507246:tid 507446] [client 74.248.24.12:6812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/OK.php"] [unique_id "apPlCO8CsCvw81e_I2pJbAAAAt8"]
[Sun Aug 30 03:08:40.154042 2026] [security2:error] [pid 507246:tid 507393] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/www/.env"] [unique_id "apPlCO8CsCvw81e_I2pJcgAAAqo"]
[Sun Aug 30 03:08:40.231737 2026] [http2:info] [pid 509172:tid 509172] h2_workers: created with min=128 max=192 idle_ms=600000
[Sun Aug 30 03:08:40.274923 2026] [authz_core:error] [pid 507246:tid 507446] [client 66.249.66.68:52961] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:40.275283 2026] [authz_core:error] [pid 507246:tid 507446] [client 66.249.66.68:52961] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:40.279316 2026] [security2:error] [pid 507246:tid 507388] [client 20.104.49.130:63243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/wp-css.php"] [unique_id "apPlCO8CsCvw81e_I2pJhwAAAqU"]
[Sun Aug 30 03:08:40.281834 2026] [security2:error] [pid 509172:tid 509313] [client 68.155.159.216:53459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apPlCJwMiz5K1he2FnnsCgAAAZg"]
[Sun Aug 30 03:08:40.316100 2026] [security2:error] [pid 507246:tid 507452] [client 158.158.54.35:10264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/disagreed.php"] [unique_id "apPlCO8CsCvw81e_I2pJkQAAAuU"]
[Sun Aug 30 03:08:40.354446 2026] [security2:error] [pid 509172:tid 509334] [client 4.205.62.107:63951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/aws_keys.php"] [unique_id "apPlCJwMiz5K1he2FnnsEwAAAa0"]
[Sun Aug 30 03:08:40.359567 2026] [security2:error] [pid 507246:tid 507473] [client 20.104.18.15:18248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/ws55.php"] [unique_id "apPlCO8CsCvw81e_I2pJlgAAAvo"]
[Sun Aug 30 03:08:40.363652 2026] [security2:error] [pid 507246:tid 507440] [client 20.104.50.220:28689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-config-pantheon.php"] [unique_id "apPlCO8CsCvw81e_I2pJlwAAAtk"]
[Sun Aug 30 03:08:40.395721 2026] [security2:error] [pid 509172:tid 509335] [client 20.104.49.130:57607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/sd.php"] [unique_id "apPlCJwMiz5K1he2FnnsFAAAAa4"]
[Sun Aug 30 03:08:40.400177 2026] [security2:error] [pid 509172:tid 509338] [client 20.48.251.3:4726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/dd.php"] [unique_id "apPlCJwMiz5K1he2FnnsFgAAAbE"]
[Sun Aug 30 03:08:40.407824 2026] [security2:error] [pid 509172:tid 509341] [client 20.104.50.220:42760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/ok.php"] [unique_id "apPlCJwMiz5K1he2FnnsGAAAAbQ"]
[Sun Aug 30 03:08:40.408787 2026] [security2:error] [pid 509172:tid 509342] [client 20.104.50.220:46186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/goods.php"] [unique_id "apPlCJwMiz5K1he2FnnsGQAAAbU"]
[Sun Aug 30 03:08:40.417236 2026] [authz_core:error] [pid 509172:tid 509340] [client 66.249.66.44:65301] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:40.417702 2026] [authz_core:error] [pid 509172:tid 509340] [client 66.249.66.44:65301] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:40.419359 2026] [security2:error] [pid 507246:tid 507460] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/html/.env"] [unique_id "apPlCO8CsCvw81e_I2pJowAAAu0"]
[Sun Aug 30 03:08:40.425180 2026] [security2:error] [pid 509172:tid 509344] [client 20.104.49.130:48028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/kj.php"] [unique_id "apPlCJwMiz5K1he2FnnsGgAAAbc"]
[Sun Aug 30 03:08:40.435896 2026] [authz_core:error] [pid 507246:tid 507415] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:40.436257 2026] [authz_core:error] [pid 507246:tid 507415] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:40.447180 2026] [security2:error] [pid 509172:tid 509349] [client 20.104.18.15:43300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/sf.php"] [unique_id "apPlCJwMiz5K1he2FnnsHQAAAbw"]
[Sun Aug 30 03:08:40.473486 2026] [security2:error] [pid 509172:tid 509330] [client 20.196.209.81:10070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/elp.php"] [unique_id "apPlCJwMiz5K1he2FnnsHwAAAak"]
[Sun Aug 30 03:08:40.474368 2026] [security2:error] [pid 507246:tid 507463] [client 20.104.18.15:34647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apPlCO8CsCvw81e_I2pJqAAAAvA"]
[Sun Aug 30 03:08:40.489191 2026] [security2:error] [pid 509172:tid 509361] [client 20.104.50.220:5226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/o.php"] [unique_id "apPlCJwMiz5K1he2FnnsIQAAAcg"]
[Sun Aug 30 03:08:40.509279 2026] [security2:error] [pid 507246:tid 507400] [client 20.104.50.220:61479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/indeex.php"] [unique_id "apPlCO8CsCvw81e_I2pJrwAAArE"]
[Sun Aug 30 03:08:40.512019 2026] [authz_core:error] [pid 507246:tid 507464] [client 66.249.66.202:47441] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:40.512356 2026] [authz_core:error] [pid 507246:tid 507464] [client 66.249.66.202:47441] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:40.581236 2026] [security2:error] [pid 509172:tid 509380] [client 20.104.18.15:23337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/dev.php"] [unique_id "apPlCJwMiz5K1he2FnnsJwAAAds"]
[Sun Aug 30 03:08:40.608422 2026] [authz_core:error] [pid 507246:tid 507426] [client 66.249.66.35:35914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:40.608690 2026] [authz_core:error] [pid 507246:tid 507426] [client 66.249.66.35:35914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:40.609351 2026] [core:error] [pid 507246:tid 507305] [remote 57.141.14.19:26106] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:08:40.609363 2026] [core:error] [pid 507246:tid 507305] [remote 57.141.14.19:26106] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:08:40.612381 2026] [security2:error] [pid 507246:tid 507492] [client 20.197.61.180:8820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/options-reading.php"] [unique_id "apPlCO8CsCvw81e_I2pJtwAAAw0"]
[Sun Aug 30 03:08:40.623736 2026] [security2:error] [pid 509172:tid 509384] [client 20.104.50.220:62813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/xixi.php"] [unique_id "apPlCJwMiz5K1he2FnnsKAAAAd8"]
[Sun Aug 30 03:08:40.632134 2026] [security2:error] [pid 509172:tid 509351] [client 74.248.24.12:7856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/eNtnKM.php"] [unique_id "apPlCJwMiz5K1he2FnnsKQAAAb4"]
[Sun Aug 30 03:08:40.640100 2026] [security2:error] [pid 509172:tid 509387] [client 20.104.50.220:31810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/inde.php"] [unique_id "apPlCJwMiz5K1he2FnnsKgAAAeI"]
[Sun Aug 30 03:08:40.661930 2026] [security2:error] [pid 507246:tid 507501] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/live/.env"] [unique_id "apPlCO8CsCvw81e_I2pJuwAAAxY"]
[Sun Aug 30 03:08:40.680211 2026] [security2:error] [pid 509172:tid 509396] [client 20.104.50.220:33169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/goods.php"] [unique_id "apPlCJwMiz5K1he2FnnsLgAAAes"]
[Sun Aug 30 03:08:40.713450 2026] [security2:error] [pid 507246:tid 507413] [client 216.244.66.238:41062] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arcaneguardians.com"] [uri "/caayjc/highland-elementary-school-st-paul"] [unique_id "apPlCO8CsCvw81e_I2pJygAAAr4"]
[Sun Aug 30 03:08:40.713540 2026] [security2:error] [pid 507246:tid 507413] [client 216.244.66.238:41062] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "arcaneguardians.com"] [uri "/caayjc/highland-elementary-school-st-paul"] [unique_id "apPlCO8CsCvw81e_I2pJygAAAr4"]
[Sun Aug 30 03:08:40.763938 2026] [security2:error] [pid 509172:tid 509307] [client 20.48.251.3:55753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/config_dev.php"] [unique_id "apPlCJwMiz5K1he2FnnsPwAAAZI"]
[Sun Aug 30 03:08:40.770387 2026] [security2:error] [pid 507246:tid 507487] [client 158.158.54.35:9734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/text.php"] [unique_id "apPlCO8CsCvw81e_I2pJ0AAAAwg"]
[Sun Aug 30 03:08:40.793201 2026] [security2:error] [pid 507246:tid 507452] [client 20.104.50.220:17251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/chosen.php"] [unique_id "apPlCO8CsCvw81e_I2pJ1AAAAuU"]
[Sun Aug 30 03:08:40.798891 2026] [security2:error] [pid 507246:tid 507391] [client 20.151.200.44:46051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/ssss.php"] [unique_id "apPlCO8CsCvw81e_I2pJ1gAAAqg"]
[Sun Aug 30 03:08:40.803543 2026] [authz_core:error] [pid 507246:tid 507503] [client 66.249.66.193:55682] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:40.804005 2026] [authz_core:error] [pid 507246:tid 507503] [client 66.249.66.193:55682] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:40.810428 2026] [security2:error] [pid 509172:tid 509316] [client 20.48.251.3:13400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/file21.php"] [unique_id "apPlCJwMiz5K1he2FnnsQwAAAZs"]
[Sun Aug 30 03:08:40.904612 2026] [security2:error] [pid 507246:tid 507401] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/prod/.env"] [unique_id "apPlCO8CsCvw81e_I2pJ7AAAArI"]
[Sun Aug 30 03:08:40.910509 2026] [security2:error] [pid 507246:tid 507449] [client 4.205.62.107:36720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/sys.php"] [unique_id "apPlCO8CsCvw81e_I2pJ7QAAAuI"]
[Sun Aug 30 03:08:40.911400 2026] [security2:error] [pid 507246:tid 507400] [client 20.196.209.81:13235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/options-reading.php"] [unique_id "apPlCO8CsCvw81e_I2pJ7gAAArE"]
[Sun Aug 30 03:08:40.941504 2026] [authz_core:error] [pid 507246:tid 507448] [client 66.249.66.34:48890] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:40.941963 2026] [authz_core:error] [pid 507246:tid 507448] [client 66.249.66.34:48890] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:40.946285 2026] [authz_core:error] [pid 507246:tid 507436] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:40.946550 2026] [authz_core:error] [pid 507246:tid 507436] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:40.962170 2026] [security2:error] [pid 507246:tid 507384] [client 4.205.62.107:22550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/124.php"] [unique_id "apPlCO8CsCvw81e_I2pJ-AAAAqE"]
[Sun Aug 30 03:08:41.025981 2026] [authz_core:error] [pid 509172:tid 509353] [client 66.249.66.32:57022] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:41.026427 2026] [authz_core:error] [pid 509172:tid 509353] [client 66.249.66.32:57022] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:41.081064 2026] [security2:error] [pid 509172:tid 509374] [client 20.151.200.44:57909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/wp-the.php"] [unique_id "apPlCZwMiz5K1he2FnnsXgAAAdU"]
[Sun Aug 30 03:08:41.081195 2026] [security2:error] [pid 507246:tid 507475] [client 20.104.49.130:36796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlCe8CsCvw81e_I2pKCQAAAvw"]
[Sun Aug 30 03:08:41.099051 2026] [security2:error] [pid 509172:tid 509382] [client 68.155.159.216:54228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-blog-header.php"] [unique_id "apPlCZwMiz5K1he2FnnsYQAAAd0"]
[Sun Aug 30 03:08:41.125351 2026] [security2:error] [pid 509172:tid 509401] [client 4.205.62.107:64451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/wp-config.backup.php"] [unique_id "apPlCZwMiz5K1he2FnnsZwAAAfA"]
[Sun Aug 30 03:08:41.126474 2026] [authz_core:error] [pid 509172:tid 509398] [client 66.249.66.70:51237] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:41.126949 2026] [authz_core:error] [pid 509172:tid 509398] [client 66.249.66.70:51237] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:41.128556 2026] [security2:error] [pid 507246:tid 507409] [client 20.104.18.15:35509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/admin.php"] [unique_id "apPlCe8CsCvw81e_I2pKFQAAAro"]
[Sun Aug 30 03:08:41.132543 2026] [authz_core:error] [pid 507246:tid 507494] [client 216.73.216.128:44807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:41.132855 2026] [authz_core:error] [pid 507246:tid 507494] [client 216.73.216.128:44807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:41.134195 2026] [security2:error] [pid 507246:tid 507476] [client 74.248.24.12:7820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/nf.php"] [unique_id "apPlCe8CsCvw81e_I2pKFwAAAv0"]
[Sun Aug 30 03:08:41.134544 2026] [authz_core:error] [pid 507246:tid 507471] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:41.134997 2026] [authz_core:error] [pid 507246:tid 507471] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:41.155189 2026] [security2:error] [pid 509172:tid 509414] [client 4.205.62.107:25731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/cp2.php"] [unique_id "apPlCZwMiz5K1he2FnnsawAAAf0"]
[Sun Aug 30 03:08:41.178423 2026] [security2:error] [pid 507246:tid 507378] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/dev/.env"] [unique_id "apPlCe8CsCvw81e_I2pKGwAAAps"]
[Sun Aug 30 03:08:41.188510 2026] [security2:error] [pid 507246:tid 507446] [client 20.104.49.130:52348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/wp-blog-header.php"] [unique_id "apPlCe8CsCvw81e_I2pKHgAAAt8"]
[Sun Aug 30 03:08:41.196640 2026] [security2:error] [pid 509172:tid 509423] [client 20.151.200.44:46055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/zoz.php"] [unique_id "apPlCZwMiz5K1he2FnnscgAAAgY"]
[Sun Aug 30 03:08:41.204441 2026] [security2:error] [pid 509172:tid 509307] [client 20.48.251.3:7392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/product.php"] [unique_id "apPlCZwMiz5K1he2FnnsdAAAAZI"]
[Sun Aug 30 03:08:41.227249 2026] [authz_core:error] [pid 509172:tid 509415] [client 66.249.66.75:40930] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:41.227525 2026] [authz_core:error] [pid 509172:tid 509415] [client 66.249.66.75:40930] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:41.267509 2026] [security2:error] [pid 509172:tid 509399] [client 158.158.54.35:26764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/alfa-rex.php"] [unique_id "apPlCZwMiz5K1he2FnnsewAAAe4"]
[Sun Aug 30 03:08:41.307255 2026] [security2:error] [pid 507246:tid 507411] [client 20.196.209.81:12936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/db.php"] [unique_id "apPlCe8CsCvw81e_I2pKLgAAArw"]
[Sun Aug 30 03:08:41.345341 2026] [security2:error] [pid 507246:tid 507477] [client 20.197.61.180:10197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/db.php"] [unique_id "apPlCe8CsCvw81e_I2pKNwAAAv4"]
[Sun Aug 30 03:08:41.388535 2026] [security2:error] [pid 509172:tid 509365] [client 68.155.159.216:62078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apPlCZwMiz5K1he2FnnsjQAAAcw"]
[Sun Aug 30 03:08:41.424108 2026] [security2:error] [pid 507246:tid 507449] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/staging/.env"] [unique_id "apPlCe8CsCvw81e_I2pKQgAAAuI"]
[Sun Aug 30 03:08:41.460841 2026] [authz_core:error] [pid 507246:tid 507431] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:41.461136 2026] [authz_core:error] [pid 507246:tid 507431] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:41.465348 2026] [authz_core:error] [pid 509172:tid 509374] [client 66.249.66.70:45487] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:41.465853 2026] [authz_core:error] [pid 509172:tid 509374] [client 66.249.66.70:45487] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:41.493350 2026] [security2:error] [pid 509172:tid 509421] [client 4.205.62.107:64037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/umgebung.php"] [unique_id "apPlCZwMiz5K1he2FnnsogAAAgQ"]
[Sun Aug 30 03:08:41.498937 2026] [security2:error] [pid 509172:tid 509428] [client 20.104.18.15:18308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/drykl.php"] [unique_id "apPlCZwMiz5K1he2FnnspQAAAgs"]
[Sun Aug 30 03:08:41.498960 2026] [security2:error] [pid 509172:tid 509408] [client 20.104.50.220:62835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-xmlx.php"] [unique_id "apPlCZwMiz5K1he2FnnspgAAAfc"]
[Sun Aug 30 03:08:41.499373 2026] [authz_core:error] [pid 507246:tid 507490] [client 216.73.216.128:44807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:41.499825 2026] [authz_core:error] [pid 507246:tid 507490] [client 216.73.216.128:44807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:41.533931 2026] [security2:error] [pid 509172:tid 509313] [client 20.104.18.15:1939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/blacks.php"] [unique_id "apPlCZwMiz5K1he2FnnsqwAAAZg"]
[Sun Aug 30 03:08:41.548545 2026] [security2:error] [pid 507246:tid 507432] [client 20.104.50.220:47046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/enclas.php"] [unique_id "apPlCe8CsCvw81e_I2pKXgAAAtE"]
[Sun Aug 30 03:08:41.550092 2026] [security2:error] [pid 507246:tid 507391] [client 20.104.50.220:42459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/herp.php"] [unique_id "apPlCe8CsCvw81e_I2pKXwAAAqg"]
[Sun Aug 30 03:08:41.552740 2026] [security2:error] [pid 507246:tid 507468] [client 20.48.251.3:44340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/wp-tem.php"] [unique_id "apPlCe8CsCvw81e_I2pKYAAAAvU"]
[Sun Aug 30 03:08:41.590698 2026] [security2:error] [pid 507246:tid 507425] [client 20.104.18.15:44020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/k.php"] [unique_id "apPlCe8CsCvw81e_I2pKZgAAAso"]
[Sun Aug 30 03:08:41.613402 2026] [security2:error] [pid 509172:tid 509348] [client 20.151.200.44:45972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/kcs.php"] [unique_id "apPlCZwMiz5K1he2FnnstQAAAbs"]
[Sun Aug 30 03:08:41.614889 2026] [security2:error] [pid 509172:tid 509350] [client 20.104.18.15:34731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/sao.php"] [unique_id "apPlCZwMiz5K1he2FnnstwAAAb0"]
[Sun Aug 30 03:08:41.630385 2026] [security2:error] [pid 509172:tid 509412] [client 20.104.50.220:5899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/n.php"] [unique_id "apPlCZwMiz5K1he2FnnsuQAAAfs"]
[Sun Aug 30 03:08:41.645111 2026] [security2:error] [pid 507246:tid 507480] [client 74.248.24.12:6785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/alumni_reg.php"] [unique_id "apPlCe8CsCvw81e_I2pKawAAAwE"]
[Sun Aug 30 03:08:41.661069 2026] [security2:error] [pid 507246:tid 507422] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/opt/.env"] [unique_id "apPlCe8CsCvw81e_I2pKcgAAAsc"]
[Sun Aug 30 03:08:41.666122 2026] [security2:error] [pid 509172:tid 509330] [client 20.104.49.130:60948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/f35.update.php"] [unique_id "apPlCZwMiz5K1he2FnnsvAAAAak"]
[Sun Aug 30 03:08:41.698339 2026] [security2:error] [pid 507246:tid 507492] [client 20.104.50.220:61970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/jindex.php"] [unique_id "apPlCe8CsCvw81e_I2pKhAAAAw0"]
[Sun Aug 30 03:08:41.702403 2026] [security2:error] [pid 507246:tid 507430] [client 20.196.209.81:10102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/server.php"] [unique_id "apPlCe8CsCvw81e_I2pKhgAAAs8"]
[Sun Aug 30 03:08:41.705180 2026] [authz_core:error] [pid 507246:tid 507395] [client 66.249.66.37:51352] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:41.705662 2026] [authz_core:error] [pid 507246:tid 507395] [client 66.249.66.37:51352] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:41.714921 2026] [security2:error] [pid 509172:tid 509388] [client 20.104.18.15:23500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/gos.php"] [unique_id "apPlCZwMiz5K1he2FnnsyQAAAeM"]
[Sun Aug 30 03:08:41.729055 2026] [security2:error] [pid 509172:tid 509345] [client 158.158.54.35:27133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/feeds.php"] [unique_id "apPlCZwMiz5K1he2FnnszQAAAbg"]
[Sun Aug 30 03:08:41.767806 2026] [security2:error] [pid 509172:tid 509313] [client 20.104.50.220:52828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-cli.php"] [unique_id "apPlCZwMiz5K1he2Fnns1wAAAZg"]
[Sun Aug 30 03:08:41.792749 2026] [security2:error] [pid 507246:tid 507411] [client 20.104.50.220:31890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/classgoto24.php"] [unique_id "apPlCe8CsCvw81e_I2pKlAAAArw"]
[Sun Aug 30 03:08:41.824499 2026] [security2:error] [pid 509172:tid 509325] [client 20.104.50.220:33160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/codrs.php"] [unique_id "apPlCZwMiz5K1he2Fnns3wAAAaQ"]
[Sun Aug 30 03:08:41.870722 2026] [security2:error] [pid 509172:tid 509358] [client 20.104.49.130:45172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/coffexium.php"] [unique_id "apPlCZwMiz5K1he2Fnns5gAAAcU"]
[Sun Aug 30 03:08:41.873556 2026] [security2:error] [pid 507246:tid 507420] [client 216.244.66.238:41072] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arcaneguardians.com"] [uri "/sblx/raw-salmon-3-days-in-fridge"] [unique_id "apPlCe8CsCvw81e_I2pKqAAAAsU"]
[Sun Aug 30 03:08:41.873653 2026] [security2:error] [pid 507246:tid 507420] [client 216.244.66.238:41072] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "arcaneguardians.com"] [uri "/sblx/raw-salmon-3-days-in-fridge"] [unique_id "apPlCe8CsCvw81e_I2pKqAAAAsU"]
[Sun Aug 30 03:08:41.899083 2026] [authz_core:error] [pid 507246:tid 507476] [client 66.249.66.199:56279] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:41.899729 2026] [authz_core:error] [pid 507246:tid 507476] [client 66.249.66.199:56279] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:41.901362 2026] [security2:error] [pid 509172:tid 509364] [client 20.48.251.3:59344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/aws_credentials.php"] [unique_id "apPlCZwMiz5K1he2Fnns7AAAAcs"]
[Sun Aug 30 03:08:41.905966 2026] [security2:error] [pid 507246:tid 507430] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/laravel/.env"] [unique_id "apPlCe8CsCvw81e_I2pKtAAAAs8"]
[Sun Aug 30 03:08:41.943949 2026] [security2:error] [pid 509172:tid 509387] [client 20.48.251.3:60493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/mcebraed.php"] [unique_id "apPlCZwMiz5K1he2Fnns8gAAAeI"]
[Sun Aug 30 03:08:41.951943 2026] [authz_core:error] [pid 507246:tid 507489] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:41.952353 2026] [authz_core:error] [pid 507246:tid 507489] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:41.963808 2026] [authz_core:error] [pid 507246:tid 507488] [client 66.249.66.71:46541] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:41.964074 2026] [authz_core:error] [pid 507246:tid 507488] [client 66.249.66.71:46541] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:42.028771 2026] [security2:error] [pid 509172:tid 509399] [client 20.104.50.220:16643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/gg.php"] [unique_id "apPlCpwMiz5K1he2Fnns_wAAAe4"]
[Sun Aug 30 03:08:42.044449 2026] [authz_core:error] [pid 507246:tid 507436] [client 216.73.216.128:44807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:42.044857 2026] [authz_core:error] [pid 507246:tid 507436] [client 216.73.216.128:44807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:42.085344 2026] [security2:error] [pid 507246:tid 507473] [client 20.197.61.180:8778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/server.php"] [unique_id "apPlCu8CsCvw81e_I2pK1gAAAvo"]
[Sun Aug 30 03:08:42.093240 2026] [security2:error] [pid 507246:tid 507401] [client 68.155.159.216:46073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-admin/dropdown.php"] [unique_id "apPlCu8CsCvw81e_I2pK1wAAArI"]
[Sun Aug 30 03:08:42.112074 2026] [security2:error] [pid 509172:tid 509419] [client 4.205.62.107:22585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/test1.php"] [unique_id "apPlCpwMiz5K1he2FnntDQAAAgI"]
[Sun Aug 30 03:08:42.112900 2026] [security2:error] [pid 509172:tid 509344] [client 4.205.62.107:36634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/phpsysinfo.php"] [unique_id "apPlCpwMiz5K1he2FnntDgAAAbc"]
[Sun Aug 30 03:08:42.115225 2026] [security2:error] [pid 509172:tid 509429] [client 20.196.209.81:13204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/favicon.php"] [unique_id "apPlCpwMiz5K1he2FnntDwAAAgw"]
[Sun Aug 30 03:08:42.135751 2026] [authz_core:error] [pid 507246:tid 507464] [client 216.73.216.128:42925] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:42.136037 2026] [authz_core:error] [pid 507246:tid 507464] [client 216.73.216.128:42925] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:42.146146 2026] [security2:error] [pid 507246:tid 507499] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/symfony/.env"] [unique_id "apPlCu8CsCvw81e_I2pK4QAAAxQ"]
[Sun Aug 30 03:08:42.160575 2026] [security2:error] [pid 507246:tid 507378] [client 20.151.200.44:45953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/tajj.php"] [unique_id "apPlCu8CsCvw81e_I2pK6AAAAps"]
[Sun Aug 30 03:08:42.188924 2026] [security2:error] [pid 509172:tid 509425] [client 74.248.24.12:6834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/admin.php7"] [unique_id "apPlCpwMiz5K1he2FnntGgAAAgg"]
[Sun Aug 30 03:08:42.198360 2026] [authz_core:error] [pid 509172:tid 509352] [client 66.249.66.69:49269] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:42.198848 2026] [authz_core:error] [pid 509172:tid 509352] [client 66.249.66.69:49269] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:42.202932 2026] [security2:error] [pid 509172:tid 509313] [client 158.158.54.35:20340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/defaults.php"] [unique_id "apPlCpwMiz5K1he2FnntHgAAAZg"]
[Sun Aug 30 03:08:42.261929 2026] [security2:error] [pid 507246:tid 507489] [client 4.205.62.107:61730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/edit.php"] [unique_id "apPlCu8CsCvw81e_I2pK-gAAAwo"]
[Sun Aug 30 03:08:42.278610 2026] [security2:error] [pid 507246:tid 507473] [client 20.104.18.15:35168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/ws85.php"] [unique_id "apPlCu8CsCvw81e_I2pLAAAAAvo"]
[Sun Aug 30 03:08:42.317069 2026] [authz_core:error] [pid 507246:tid 507490] [client 216.73.216.128:18339] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:42.317638 2026] [authz_core:error] [pid 507246:tid 507490] [client 216.73.216.128:18339] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:42.340630 2026] [security2:error] [pid 507246:tid 507379] [client 68.155.159.216:55104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apPlCu8CsCvw81e_I2pLFwAAApw"]
[Sun Aug 30 03:08:42.346231 2026] [security2:error] [pid 507246:tid 507494] [client 20.48.251.3:7103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/fun.php"] [unique_id "apPlCu8CsCvw81e_I2pLGgAAAw8"]
[Sun Aug 30 03:08:42.375360 2026] [security2:error] [pid 509172:tid 509325] [client 4.205.62.107:25859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/xda.php"] [unique_id "apPlCpwMiz5K1he2FnntNgAAAaQ"]
[Sun Aug 30 03:08:42.382861 2026] [security2:error] [pid 507246:tid 507397] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/wordpress/.env"] [unique_id "apPlCu8CsCvw81e_I2pLJQAAAq4"]
[Sun Aug 30 03:08:42.431857 2026] [authz_core:error] [pid 509172:tid 509349] [client 66.249.66.70:51237] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:42.432323 2026] [authz_core:error] [pid 509172:tid 509349] [client 66.249.66.70:51237] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:42.472302 2026] [authz_core:error] [pid 507246:tid 507501] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:42.472717 2026] [authz_core:error] [pid 507246:tid 507501] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:42.493884 2026] [security2:error] [pid 509172:tid 509381] [client 68.155.159.216:60925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apPlCpwMiz5K1he2FnntTgAAAdw"]
[Sun Aug 30 03:08:42.515250 2026] [security2:error] [pid 509172:tid 509333] [client 20.196.209.81:10077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/gecko.php"] [unique_id "apPlCpwMiz5K1he2FnntVQAAAaw"]
[Sun Aug 30 03:08:42.583486 2026] [authz_core:error] [pid 507246:tid 507396] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:42.583845 2026] [authz_core:error] [pid 507246:tid 507396] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:42.622762 2026] [security2:error] [pid 507246:tid 507395] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/wp/.env"] [unique_id "apPlCu8CsCvw81e_I2pLSQAAAqw"]
[Sun Aug 30 03:08:42.629866 2026] [security2:error] [pid 507246:tid 507439] [client 4.205.62.107:63944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/old_phpinfo.php"] [unique_id "apPlCu8CsCvw81e_I2pLSgAAAtg"]
[Sun Aug 30 03:08:42.670195 2026] [security2:error] [pid 509172:tid 509419] [client 20.104.18.15:18361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/backup.php"] [unique_id "apPlCpwMiz5K1he2FnntaQAAAgI"]
[Sun Aug 30 03:08:42.673283 2026] [security2:error] [pid 507246:tid 507380] [client 216.73.216.128:42925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/'+e.href+'"] [unique_id "apPlCu8CsCvw81e_I2pLUQAAAp0"]
[Sun Aug 30 03:08:42.674653 2026] [security2:error] [pid 509172:tid 509342] [client 20.104.18.15:1997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/wp.php"] [unique_id "apPlCpwMiz5K1he2FnntbAAAAbU"]
[Sun Aug 30 03:08:42.675719 2026] [security2:error] [pid 509172:tid 509408] [client 158.158.54.35:29466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/system.php"] [unique_id "apPlCpwMiz5K1he2FnntbQAAAfc"]
[Sun Aug 30 03:08:42.685525 2026] [security2:error] [pid 509172:tid 509323] [client 20.104.50.220:46614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/ioxi-o.php"] [unique_id "apPlCpwMiz5K1he2FnntcAAAAaI"]
[Sun Aug 30 03:08:42.686374 2026] [security2:error] [pid 509172:tid 509425] [client 20.48.251.3:44384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/txets.php"] [unique_id "apPlCpwMiz5K1he2FnntcQAAAgg"]
[Sun Aug 30 03:08:42.689766 2026] [authz_core:error] [pid 509172:tid 509370] [client 66.249.66.198:55573] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:42.690043 2026] [authz_core:error] [pid 509172:tid 509370] [client 66.249.66.198:55573] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:42.714632 2026] [security2:error] [pid 509172:tid 509306] [client 20.104.50.220:42008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/nptice.php"] [unique_id "apPlCpwMiz5K1he2FnntdgAAAZE"]
[Sun Aug 30 03:08:42.723994 2026] [authz_core:error] [pid 507246:tid 507402] [client 66.249.66.37:51352] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:42.724167 2026] [security2:error] [pid 509172:tid 509417] [client 74.248.24.12:11854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/jquery.php"] [unique_id "apPlCpwMiz5K1he2FnnteAAAAgA"]
[Sun Aug 30 03:08:42.724334 2026] [authz_core:error] [pid 507246:tid 507402] [client 66.249.66.37:51352] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:42.725331 2026] [authz_core:error] [pid 507246:tid 507442] [client 66.249.66.199:51757] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:42.725753 2026] [authz_core:error] [pid 507246:tid 507442] [client 66.249.66.199:51757] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:42.750471 2026] [security2:error] [pid 509172:tid 509313] [client 20.104.18.15:34746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/dapa.php"] [unique_id "apPlCpwMiz5K1he2FnntfAAAAZg"]
[Sun Aug 30 03:08:42.765022 2026] [security2:error] [pid 509172:tid 509357] [client 20.104.50.220:5918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/m.php"] [unique_id "apPlCpwMiz5K1he2FnntfgAAAcQ"]
[Sun Aug 30 03:08:42.765059 2026] [security2:error] [pid 507246:tid 507412] [client 216.73.216.128:18339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mysqlupgrade"] [unique_id "apPlCu8CsCvw81e_I2pLYgAAAr0"]
[Sun Aug 30 03:08:42.769210 2026] [security2:error] [pid 509172:tid 509391] [client 20.104.50.220:29152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/pwp-.myluv.php"] [unique_id "apPlCpwMiz5K1he2FnntfwAAAeY"]
[Sun Aug 30 03:08:42.807461 2026] [security2:error] [pid 509172:tid 509360] [client 20.104.18.15:43267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/82.php"] [unique_id "apPlCpwMiz5K1he2FnntiwAAAcc"]
[Sun Aug 30 03:08:42.817681 2026] [security2:error] [pid 507246:tid 507477] [client 20.197.61.180:14225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/favicon.php"] [unique_id "apPlCu8CsCvw81e_I2pLcgAAAv4"]
[Sun Aug 30 03:08:42.836032 2026] [security2:error] [pid 507246:tid 507385] [client 20.104.50.220:61984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/p0wny-shell.php"] [unique_id "apPlCu8CsCvw81e_I2pLewAAAqI"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:42.863250 2026] [security2:error] [pid 507246:tid 507439] [client 20.104.18.15:23525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/132.php"] [unique_id "apPlCu8CsCvw81e_I2pLiQAAAtg"]
[Sun Aug 30 03:08:42.877342 2026] [security2:error] [pid 507246:tid 507481] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/cms/.env"] [unique_id "apPlCu8CsCvw81e_I2pLkwAAAwI"]
[Sun Aug 30 03:08:42.919466 2026] [security2:error] [pid 507246:tid 507460] [client 20.196.209.81:17670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/ioxi-o.php"] [unique_id "apPlCu8CsCvw81e_I2pLpwAAAu0"]
[Sun Aug 30 03:08:42.928476 2026] [security2:error] [pid 507246:tid 507425] [client 20.104.50.220:31886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/thh.php"] [unique_id "apPlCu8CsCvw81e_I2pLrAAAAso"]
[Sun Aug 30 03:08:42.933199 2026] [security2:error] [pid 507246:tid 507428] [client 20.104.50.220:52843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/IP.php"] [unique_id "apPlCu8CsCvw81e_I2pLrQAAAs0"]
[Sun Aug 30 03:08:42.953640 2026] [authz_core:error] [pid 507246:tid 507409] [client 216.73.216.128:44300] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:42.953954 2026] [authz_core:error] [pid 507246:tid 507409] [client 216.73.216.128:44300] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:42.968322 2026] [authz_core:error] [pid 507246:tid 507440] [client 66.249.66.40:46241] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:42.968603 2026] [authz_core:error] [pid 507246:tid 507440] [client 66.249.66.40:46241] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:42.972198 2026] [security2:error] [pid 509172:tid 509362] [client 20.104.50.220:32844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/jingan.php"] [unique_id "apPlCpwMiz5K1he2FnnttQAAAck"]
[Sun Aug 30 03:08:42.972840 2026] [authz_core:error] [pid 507246:tid 507439] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:42.973189 2026] [authz_core:error] [pid 507246:tid 507439] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:43.021339 2026] [security2:error] [pid 509172:tid 509321] [client 20.151.200.44:46072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/bge.php"] [unique_id "apPlC5wMiz5K1he2FnntwwAAAaA"]
[Sun Aug 30 03:08:43.024540 2026] [security2:error] [pid 509172:tid 509191] [remote 190.92.174.81:34268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "artistsallianceagency.com"] [uri "/wp-login.php"] [unique_id "apPlC5wMiz5K1he2FnntwgAB9BA"]
[Sun Aug 30 03:08:43.033473 2026] [security2:error] [pid 509172:tid 509394] [client 216.244.66.238:41076] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arcaneguardians.com"] [uri "/zgxgbcfh/maclocks-universal-tablet-lock"] [unique_id "apPlC5wMiz5K1he2FnntywAAAek"]
[Sun Aug 30 03:08:43.033582 2026] [security2:error] [pid 509172:tid 509394] [client 216.244.66.238:41076] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "arcaneguardians.com"] [uri "/zgxgbcfh/maclocks-universal-tablet-lock"] [unique_id "apPlC5wMiz5K1he2FnntywAAAek"]
[Sun Aug 30 03:08:43.099136 2026] [security2:error] [pid 507246:tid 507394] [client 20.48.251.3:33341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/server-info.php"] [unique_id "apPlC-8CsCvw81e_I2pL3AAAAqs"]
[Sun Aug 30 03:08:43.111803 2026] [security2:error] [pid 507246:tid 507433] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/drupal/.env"] [unique_id "apPlC-8CsCvw81e_I2pL3gAAAtI"]
[Sun Aug 30 03:08:43.119300 2026] [security2:error] [pid 507246:tid 507425] [client 20.48.251.3:59368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/aws-credentials.php"] [unique_id "apPlC-8CsCvw81e_I2pL4QAAAso"]
[Sun Aug 30 03:08:43.128629 2026] [security2:error] [pid 507246:tid 507386] [client 158.158.54.35:26799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/xmlrpc.php0"] [unique_id "apPlC-8CsCvw81e_I2pL5AAAAqM"]
[Sun Aug 30 03:08:43.146511 2026] [security2:error] [pid 507246:tid 507467] [client 52.139.37.240:36997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/403.php"] [unique_id "apPlC-8CsCvw81e_I2pL6QAAAvQ"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:43.163059 2026] [security2:error] [pid 507246:tid 507403] [client 20.104.50.220:17226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/als.php"] [unique_id "apPlC-8CsCvw81e_I2pL7wAAArQ"]
[Sun Aug 30 03:08:43.229704 2026] [authz_core:error] [pid 507246:tid 507469] [client 216.73.216.128:44300] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:43.230148 2026] [authz_core:error] [pid 507246:tid 507469] [client 216.73.216.128:44300] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:43.238703 2026] [security2:error] [pid 507246:tid 507400] [client 74.248.24.12:7610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/cd.php"] [unique_id "apPlC-8CsCvw81e_I2pMBgAAArE"]
[Sun Aug 30 03:08:43.271524 2026] [security2:error] [pid 509172:tid 509316] [client 4.205.62.107:22928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/bigdump.php"] [unique_id "apPlC5wMiz5K1he2Fnnt-QAAAZs"]
[Sun Aug 30 03:08:43.300865 2026] [security2:error] [pid 509172:tid 509418] [client 144.124.244.26:53695] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "144.124.244.26" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1093"] [id "999023"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "planbtourism.com"] [uri "/user/register"] [unique_id "apPlC5wMiz5K1he2Fnnt9QAAAgE"], referer: https://planbtourism.com/user/register
[Sun Aug 30 03:08:43.311451 2026] [security2:error] [pid 509172:tid 509323] [client 4.205.62.107:36710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/sgd.php"] [unique_id "apPlC5wMiz5K1he2FnnuBAAAAaI"]
[Sun Aug 30 03:08:43.348576 2026] [security2:error] [pid 507246:tid 507382] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/joomla/.env"] [unique_id "apPlC-8CsCvw81e_I2pMJAAAAp8"]
[Sun Aug 30 03:08:43.348778 2026] [authz_core:error] [pid 509172:tid 509366] [client 66.249.66.197:64947] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:43.348869 2026] [security2:error] [pid 507246:tid 507444] [client 52.139.37.240:37241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/av.php"] [unique_id "apPlC-8CsCvw81e_I2pMJQAAAt0"]
[Sun Aug 30 03:08:43.349051 2026] [authz_core:error] [pid 509172:tid 509366] [client 66.249.66.197:64947] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:43.355916 2026] [security2:error] [pid 509172:tid 509377] [client 20.196.209.81:11337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.michaeldanzerphoto.com"] [uri "/lock.php"] [unique_id "apPlC5wMiz5K1he2FnnuDgAAAdg"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:43.366196 2026] [security2:error] [pid 509172:tid 509423] [client 20.151.200.44:46967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/file.php"] [unique_id "apPlC5wMiz5K1he2FnnuEQAAAgY"]
[Sun Aug 30 03:08:43.405367 2026] [security2:error] [pid 509172:tid 509359] [client 4.205.62.107:61701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/8.php"] [unique_id "apPlC5wMiz5K1he2FnnuFwAAAcY"]
[Sun Aug 30 03:08:43.426239 2026] [authz_core:error] [pid 509172:tid 509324] [client 66.249.66.43:46029] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:43.426506 2026] [authz_core:error] [pid 509172:tid 509324] [client 66.249.66.43:46029] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:43.436963 2026] [security2:error] [pid 509172:tid 509322] [client 20.104.18.15:35010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/ffs.php"] [unique_id "apPlC5wMiz5K1he2FnnuIgAAAaE"]
[Sun Aug 30 03:08:43.439116 2026] [authz_core:error] [pid 507246:tid 507464] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:43.439521 2026] [authz_core:error] [pid 507246:tid 507464] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:43.442766 2026] [security2:error] [pid 509172:tid 509194] [remote 190.92.174.81:34268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "artistsallianceagency.com"] [uri "/wp-login.php"] [unique_id "apPlC5wMiz5K1he2FnnuJAAB-hM"], referer: https://artistsallianceagency.com/wp-login.php
[Sun Aug 30 03:08:43.505035 2026] [security2:error] [pid 509172:tid 509344] [client 4.205.62.107:25773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/pinfo.php"] [unique_id "apPlC5wMiz5K1he2FnnuMAAAAbc"]
[Sun Aug 30 03:08:43.507091 2026] [security2:error] [pid 509172:tid 509338] [client 68.155.159.216:46028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/login.php"] [unique_id "apPlC5wMiz5K1he2FnnuMgAAAbE"]
[Sun Aug 30 03:08:43.511781 2026] [security2:error] [pid 509172:tid 509372] [client 68.155.159.216:55112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-admin/user/index.php"] [unique_id "apPlC5wMiz5K1he2FnnuMwAAAdM"]
[Sun Aug 30 03:08:43.538108 2026] [security2:error] [pid 509172:tid 509429] [client 20.197.61.180:14231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/gecko.php"] [unique_id "apPlC5wMiz5K1he2FnnuPAAAAgw"]
[Sun Aug 30 03:08:43.540505 2026] [security2:error] [pid 507246:tid 507476] [client 52.139.37.240:37184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/wp-admin/index.php"] [unique_id "apPlC-8CsCvw81e_I2pMWQAAAv0"]
[Sun Aug 30 03:08:43.542785 2026] [authz_core:error] [pid 509172:tid 509404] [client 66.249.66.38:46113] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:43.543108 2026] [authz_core:error] [pid 509172:tid 509404] [client 66.249.66.38:46113] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:43.546424 2026] [authz_core:error] [pid 507246:tid 507490] [client 66.249.66.45:38768] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:43.546706 2026] [authz_core:error] [pid 507246:tid 507490] [client 66.249.66.45:38768] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:43.570749 2026] [security2:error] [pid 509172:tid 509334] [client 20.48.251.3:64504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/kedi.php"] [unique_id "apPlC5wMiz5K1he2FnnuQwAAAa0"]
[Sun Aug 30 03:08:43.576018 2026] [security2:error] [pid 509172:tid 509325] [client 158.158.54.35:9550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/colors.php"] [unique_id "apPlC5wMiz5K1he2FnnuRQAAAaQ"]
[Sun Aug 30 03:08:43.594198 2026] [security2:error] [pid 507246:tid 507407] [client 20.104.49.130:57534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/wp-blog-header.php"] [unique_id "apPlC-8CsCvw81e_I2pMYwAAArg"]
[Sun Aug 30 03:08:43.600822 2026] [security2:error] [pid 509172:tid 509370] [client 68.155.159.216:53461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/nf_tracking.php"] [unique_id "apPlC5wMiz5K1he2FnnuSgAAAdE"]
[Sun Aug 30 03:08:43.622548 2026] [security2:error] [pid 507246:tid 507499] [client 34.100.204.203:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/magento/.env"] [unique_id "apPlC-8CsCvw81e_I2pMaAAAAxQ"]
[Sun Aug 30 03:08:43.642566 2026] [authz_core:error] [pid 507246:tid 507402] [client 66.249.66.198:50541] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:43.642950 2026] [authz_core:error] [pid 507246:tid 507402] [client 66.249.66.198:50541] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:43.736850 2026] [security2:error] [pid 509172:tid 509311] [client 52.139.37.240:37235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "apPlC5wMiz5K1he2FnnuXAAAAZY"]
[Sun Aug 30 03:08:43.737330 2026] [security2:error] [pid 509172:tid 509313] [client 74.248.24.12:11895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/5173e.php"] [unique_id "apPlC5wMiz5K1he2FnnuXQAAAZg"]
[Sun Aug 30 03:08:43.771794 2026] [security2:error] [pid 507246:tid 507427] [client 4.205.62.107:64033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.avondesignservices.co.uk"] [uri "/wp-act.php"] [unique_id "apPlC-8CsCvw81e_I2pMgAAAAsw"]
[Sun Aug 30 03:08:43.782208 2026] [authz_core:error] [pid 507246:tid 507466] [client 216.73.216.128:44807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:43.782480 2026] [authz_core:error] [pid 507246:tid 507466] [client 216.73.216.128:44807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:43.807306 2026] [security2:error] [pid 509172:tid 509357] [client 20.104.18.15:18354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/indo.php"] [unique_id "apPlC5wMiz5K1he2FnnubgAAAcQ"]
[Sun Aug 30 03:08:43.818080 2026] [security2:error] [pid 509172:tid 509347] [client 20.104.18.15:1884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/wander.php"] [unique_id "apPlC5wMiz5K1he2FnnucgAAAbo"]
[Sun Aug 30 03:08:43.823843 2026] [security2:error] [pid 507246:tid 507464] [client 20.104.50.220:46411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-admin/js/wp-conflg.php"] [unique_id "apPlC-8CsCvw81e_I2pMlQAAAvE"]
[Sun Aug 30 03:08:43.884761 2026] [security2:error] [pid 509172:tid 509340] [client 20.104.50.220:41993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/tuyul.php"] [unique_id "apPlC5wMiz5K1he2FnnukQAAAbM"]
[Sun Aug 30 03:08:43.897481 2026] [security2:error] [pid 509172:tid 509390] [client 20.104.18.15:34678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/wp-content/l.php"] [unique_id "apPlC5wMiz5K1he2FnnulgAAAeU"]
[Sun Aug 30 03:08:43.902046 2026] [security2:error] [pid 509172:tid 509417] [client 20.104.50.220:5900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/l.php"] [unique_id "apPlC5wMiz5K1he2FnnumgAAAgA"]
[Sun Aug 30 03:08:43.945071 2026] [authz_core:error] [pid 507246:tid 507386] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:43.945348 2026] [authz_core:error] [pid 507246:tid 507386] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:43.955772 2026] [security2:error] [pid 509172:tid 509412] [client 52.139.37.240:37455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/wp-content/themes/pridmag/b.php"] [unique_id "apPlC5wMiz5K1he2FnnurAAAAfs"]
[Sun Aug 30 03:08:43.970555 2026] [security2:error] [pid 509172:tid 509389] [client 20.48.251.3:44409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/time.php"] [unique_id "apPlC5wMiz5K1he2FnnutgAAAeQ"]
[Sun Aug 30 03:08:43.970584 2026] [security2:error] [pid 509172:tid 509410] [client 20.104.18.15:43970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/dex.php"] [unique_id "apPlC5wMiz5K1he2FnnutQAAAfk"]
[Sun Aug 30 03:08:43.974710 2026] [security2:error] [pid 509172:tid 509342] [client 20.104.49.130:36743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/coffexium.php"] [unique_id "apPlC5wMiz5K1he2FnnuuAAAAbU"]
[Sun Aug 30 03:08:43.984653 2026] [security2:error] [pid 509172:tid 509380] [client 20.104.50.220:61387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/ex0shell.php"] [unique_id "apPlC5wMiz5K1he2FnnuuwAAAds"]
[Sun Aug 30 03:08:44.023340 2026] [security2:error] [pid 509172:tid 509333] [client 20.104.18.15:23386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/v22.php"] [unique_id "apPlDJwMiz5K1he2FnnuygAAAaw"]
[Sun Aug 30 03:08:44.023949 2026] [authz_core:error] [pid 509172:tid 509347] [client 66.249.66.192:57751] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:44.024246 2026] [authz_core:error] [pid 509172:tid 509347] [client 66.249.66.192:57751] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:44.028433 2026] [security2:error] [pid 507246:tid 507377] [client 20.104.50.220:29168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wihp1.php"] [unique_id "apPlDO8CsCvw81e_I2pM1wAAApo"]
[Sun Aug 30 03:08:44.043919 2026] [security2:error] [pid 509172:tid 509364] [client 158.158.54.35:6496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/alfa-rex1.php"] [unique_id "apPlDJwMiz5K1he2Fnnu0QAAAcs"]
[Sun Aug 30 03:08:44.074826 2026] [security2:error] [pid 507246:tid 507495] [client 20.104.50.220:64452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/XiXi.php"] [unique_id "apPlDO8CsCvw81e_I2pM8gAAAxA"]
[Sun Aug 30 03:08:44.111201 2026] [security2:error] [pid 509172:tid 509326] [client 20.104.50.220:33326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/chan.php"] [unique_id "apPlDJwMiz5K1he2Fnnu5AAAAaU"]
[Sun Aug 30 03:08:44.111845 2026] [security2:error] [pid 507246:tid 507403] [client 20.104.50.220:31826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/fffff.php"] [unique_id "apPlDO8CsCvw81e_I2pM_wAAArQ"]
[Sun Aug 30 03:08:44.159755 2026] [authz_core:error] [pid 509172:tid 509330] [client 66.249.66.72:49014] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:44.160078 2026] [authz_core:error] [pid 509172:tid 509330] [client 66.249.66.72:49014] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:44.211699 2026] [security2:error] [pid 507246:tid 507437] [client 20.151.200.44:46053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/ssh3ll.php"] [unique_id "apPlDO8CsCvw81e_I2pNGQAAAtY"]
[Sun Aug 30 03:08:44.226049 2026] [security2:error] [pid 509172:tid 509365] [client 20.151.200.44:55557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/pb.php"] [unique_id "apPlDJwMiz5K1he2FnnvAwAAAcw"]
[Sun Aug 30 03:08:44.234328 2026] [authz_core:error] [pid 507246:tid 507430] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:44.234765 2026] [authz_core:error] [pid 507246:tid 507430] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:44.240944 2026] [security2:error] [pid 509172:tid 509321] [client 20.48.251.3:60522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/gk.php"] [unique_id "apPlDJwMiz5K1he2FnnvCAAAAaA"]
[Sun Aug 30 03:08:44.245055 2026] [security2:error] [pid 509172:tid 509386] [client 74.248.24.12:20217] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "b6standards.com"] [uri "/c99.php"] [unique_id "apPlDJwMiz5K1he2FnnvCgAAAeE"]
[Sun Aug 30 03:08:44.284209 2026] [security2:error] [pid 509172:tid 509380] [client 20.48.251.3:59390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/4563.php"] [unique_id "apPlDJwMiz5K1he2FnnvFQAAAds"]
[Sun Aug 30 03:08:44.308907 2026] [security2:error] [pid 509172:tid 509344] [client 20.104.50.220:16751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/pol.php"] [unique_id "apPlDJwMiz5K1he2FnnvHQAAAbc"]
[Sun Aug 30 03:08:44.309573 2026] [security2:error] [pid 509172:tid 509429] [client 20.197.61.180:14270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/ioxi-o.php"] [unique_id "apPlDJwMiz5K1he2FnnvIAAAAgw"]
[Sun Aug 30 03:08:44.407247 2026] [security2:error] [pid 509172:tid 509334] [client 216.73.216.128:24431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlDJwMiz5K1he2FnnvNQAAAa0"]
[Sun Aug 30 03:08:44.408839 2026] [security2:error] [pid 507246:tid 507398] [client 4.205.62.107:22580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/wdf.php"] [unique_id "apPlDO8CsCvw81e_I2pNUQAAAq8"]
[Sun Aug 30 03:08:44.409164 2026] [authz_core:error] [pid 507246:tid 507423] [client 66.249.66.39:58207] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:44.409591 2026] [authz_core:error] [pid 507246:tid 507423] [client 66.249.66.39:58207] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:44.443227 2026] [security2:error] [pid 507246:tid 507435] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/shopify/.env"] [unique_id "apPlDO8CsCvw81e_I2pNWwAAAtQ"]
[Sun Aug 30 03:08:44.445214 2026] [authz_core:error] [pid 507246:tid 507395] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:44.445548 2026] [authz_core:error] [pid 507246:tid 507395] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:44.475127 2026] [authz_core:error] [pid 509172:tid 509351] [client 66.249.66.73:48474] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:44.475453 2026] [authz_core:error] [pid 509172:tid 509351] [client 66.249.66.73:48474] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:44.497838 2026] [security2:error] [pid 509172:tid 509312] [client 4.205.62.107:35979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/fleen.php"] [unique_id "apPlDJwMiz5K1he2FnnvTAAAAZc"]
[Sun Aug 30 03:08:44.507313 2026] [authz_core:error] [pid 507246:tid 507431] [client 216.73.216.128:44807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:44.507694 2026] [authz_core:error] [pid 507246:tid 507431] [client 216.73.216.128:44807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:44.519775 2026] [security2:error] [pid 509172:tid 509370] [client 158.158.54.35:27224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/Njima.php"] [unique_id "apPlDJwMiz5K1he2FnnvUQAAAdE"]
[Sun Aug 30 03:08:44.537824 2026] [security2:error] [pid 507246:tid 507458] [client 4.205.62.107:64492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/thui.php"] [unique_id "apPlDO8CsCvw81e_I2pNdwAAAus"]
[Sun Aug 30 03:08:44.596358 2026] [security2:error] [pid 509172:tid 509341] [client 20.104.18.15:35481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/nano.php"] [unique_id "apPlDJwMiz5K1he2FnnvbgAAAbQ"]
[Sun Aug 30 03:08:44.628417 2026] [security2:error] [pid 507246:tid 507439] [client 52.139.37.240:37242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/0.php"] [unique_id "apPlDO8CsCvw81e_I2pNiAAAAtg"]
[Sun Aug 30 03:08:44.633291 2026] [security2:error] [pid 509172:tid 509371] [client 143.110.213.72:33544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.213.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.anantiapolytechnic.ng"] [uri "/info.php"] [unique_id "apPlDJwMiz5K1he2FnnvcQAAAdI"]
[Sun Aug 30 03:08:44.649330 2026] [authz_core:error] [pid 509172:tid 509417] [client 66.249.66.74:42381] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:44.649596 2026] [authz_core:error] [pid 509172:tid 509417] [client 66.249.66.74:42381] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:44.687468 2026] [authz_core:error] [pid 507246:tid 507405] [client 216.73.216.128:44807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:44.687780 2026] [authz_core:error] [pid 507246:tid 507405] [client 216.73.216.128:44807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:44.699924 2026] [security2:error] [pid 507246:tid 507440] [client 68.155.159.216:54243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-includes/plugins.php"] [unique_id "apPlDO8CsCvw81e_I2pNmQAAAtk"]
[Sun Aug 30 03:08:44.712846 2026] [security2:error] [pid 507246:tid 507442] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/prestashop/.env"] [unique_id "apPlDO8CsCvw81e_I2pNngAAAts"]
[Sun Aug 30 03:08:44.749341 2026] [security2:error] [pid 507246:tid 507458] [client 20.48.251.3:64497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/oc460l3x.php"] [unique_id "apPlDO8CsCvw81e_I2pNpAAAAus"]
[Sun Aug 30 03:08:44.795199 2026] [security2:error] [pid 509172:tid 509415] [client 74.248.24.12:6803] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "b6standards.com"] [uri "/c99.php"] [unique_id "apPlDJwMiz5K1he2FnnvnAAAAf4"]
[Sun Aug 30 03:08:44.820930 2026] [security2:error] [pid 507246:tid 507411] [client 52.139.37.240:37828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/autoload_classmap/function.php"] [unique_id "apPlDO8CsCvw81e_I2pNwQAAArw"]
[Sun Aug 30 03:08:44.834742 2026] [security2:error] [pid 509172:tid 509395] [client 68.155.159.216:61399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wzy.php"] [unique_id "apPlDJwMiz5K1he2FnnvsgAAAeo"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:44.917802 2026] [security2:error] [pid 509172:tid 509371] [client 4.205.62.107:25881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/X57.php"] [unique_id "apPlDJwMiz5K1he2Fnnv1QAAAdI"]
[Sun Aug 30 03:08:44.927765 2026] [security2:error] [pid 509172:tid 509363] [client 20.104.49.130:48059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/new.php"] [unique_id "apPlDJwMiz5K1he2Fnnv2AAAAco"]
[Sun Aug 30 03:08:44.943053 2026] [security2:error] [pid 507246:tid 507438] [client 20.104.18.15:18266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/sign.php"] [unique_id "apPlDO8CsCvw81e_I2pOBAAAAtc"]
[Sun Aug 30 03:08:44.950814 2026] [security2:error] [pid 507246:tid 507423] [client 20.104.18.15:1932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/abcd.php"] [unique_id "apPlDO8CsCvw81e_I2pOCQAAAsg"]
[Sun Aug 30 03:08:44.959539 2026] [security2:error] [pid 507246:tid 507442] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/codeigniter/.env"] [unique_id "apPlDO8CsCvw81e_I2pODAAAAts"]
[Sun Aug 30 03:08:44.972769 2026] [authz_core:error] [pid 509172:tid 509408] [client 66.249.66.38:65106] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:44.973089 2026] [authz_core:error] [pid 509172:tid 509408] [client 66.249.66.38:65106] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:44.973819 2026] [security2:error] [pid 509172:tid 509382] [client 20.104.50.220:46421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/classwithtostring.php"] [unique_id "apPlDJwMiz5K1he2Fnnv6wAAAd0"]
[Sun Aug 30 03:08:44.979291 2026] [authz_core:error] [pid 507246:tid 507465] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:44.979559 2026] [authz_core:error] [pid 507246:tid 507465] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:44.983281 2026] [security2:error] [pid 507246:tid 507439] [client 158.158.54.35:34930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/BIBIL0DAY.php"] [unique_id "apPlDO8CsCvw81e_I2pOEwAAAtg"]
[Sun Aug 30 03:08:45.004031 2026] [authz_core:error] [pid 507246:tid 507460] [client 66.249.66.32:46784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:45.004482 2026] [authz_core:error] [pid 507246:tid 507460] [client 66.249.66.32:46784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:45.010955 2026] [authz_core:error] [pid 507246:tid 507378] [client 216.73.216.128:1805] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:45.011444 2026] [authz_core:error] [pid 507246:tid 507378] [client 216.73.216.128:1805] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:45.016053 2026] [security2:error] [pid 509172:tid 509334] [client 52.139.37.240:37829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/dvve.php"] [unique_id "apPlDZwMiz5K1he2Fnnv-gAAAa0"]
[Sun Aug 30 03:08:45.032016 2026] [security2:error] [pid 507246:tid 507483] [client 20.104.50.220:63539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/nikung.php"] [unique_id "apPlDe8CsCvw81e_I2pOKwAAAwQ"]
[Sun Aug 30 03:08:45.036526 2026] [security2:error] [pid 507246:tid 507426] [client 20.104.18.15:34654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/wp-admin/w.php"] [unique_id "apPlDe8CsCvw81e_I2pOMQAAAss"]
[Sun Aug 30 03:08:45.038315 2026] [security2:error] [pid 509172:tid 509341] [client 20.197.61.180:7940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.indieoffroad.webio7.com"] [uri "/lock.php"] [unique_id "apPlDZwMiz5K1he2FnnwBgAAAbQ"]
[Sun Aug 30 03:08:45.039874 2026] [security2:error] [pid 507246:tid 507377] [client 20.104.50.220:5529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/k.php"] [unique_id "apPlDe8CsCvw81e_I2pOMwAAApo"]
[Sun Aug 30 03:08:45.049568 2026] [authz_core:error] [pid 509172:tid 509381] [client 216.73.216.128:28214] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:45.049849 2026] [authz_core:error] [pid 509172:tid 509381] [client 216.73.216.128:28214] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:45.109663 2026] [security2:error] [pid 509172:tid 509335] [client 20.48.251.3:44314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/doc.php"] [unique_id "apPlDZwMiz5K1he2FnnwJwAAAa4"]
[Sun Aug 30 03:08:45.132854 2026] [security2:error] [pid 509172:tid 509384] [client 20.104.18.15:43306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/inso.php"] [unique_id "apPlDZwMiz5K1he2FnnwLwAAAd8"]
[Sun Aug 30 03:08:45.139827 2026] [security2:error] [pid 509172:tid 509341] [client 20.104.50.220:61383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/exp.php"] [unique_id "apPlDZwMiz5K1he2FnnwNAAAAbQ"]
[Sun Aug 30 03:08:45.166028 2026] [security2:error] [pid 507246:tid 507496] [client 20.104.18.15:23510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/wp-activate.php"] [unique_id "apPlDe8CsCvw81e_I2pOVwAAAxE"]
[Sun Aug 30 03:08:45.184769 2026] [security2:error] [pid 507246:tid 507383] [client 20.104.50.220:62834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-blog.php"] [unique_id "apPlDe8CsCvw81e_I2pOXgAAAqA"]
[Sun Aug 30 03:08:45.201804 2026] [security2:error] [pid 509172:tid 509319] [client 68.155.159.216:46048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/hehehehe.php"] [unique_id "apPlDZwMiz5K1he2FnnwRgAAAZ4"]
[Sun Aug 30 03:08:45.216857 2026] [security2:error] [pid 507246:tid 507450] [client 114.119.133.119:43309] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lodestarcollaboration.com"] [uri "/2012/06/19/how-foursquare-worked-for-a-mall"] [unique_id "apPlDe8CsCvw81e_I2pOZAAAAuM"], referer: https://lodestarcollaboration.com/2012/06/19/how-foursquare-worked-for-a-mall
[Sun Aug 30 03:08:45.231389 2026] [security2:error] [pid 507246:tid 507394] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/cakephp/.env"] [unique_id "apPlDe8CsCvw81e_I2pOagAAAqs"]
[Sun Aug 30 03:08:45.236809 2026] [security2:error] [pid 509172:tid 509376] [client 20.151.200.44:59509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/wt.php"] [unique_id "apPlDZwMiz5K1he2FnnwVwAAAdc"]
[Sun Aug 30 03:08:45.245947 2026] [security2:error] [pid 507246:tid 507390] [client 20.104.50.220:63046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/.piongroup.php"] [unique_id "apPlDe8CsCvw81e_I2pObAAAAqc"]
[Sun Aug 30 03:08:45.248761 2026] [security2:error] [pid 507246:tid 507479] [client 20.104.50.220:33308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/losX.php"] [unique_id "apPlDe8CsCvw81e_I2pObQAAAwA"]
[Sun Aug 30 03:08:45.250261 2026] [autoindex:error] [pid 509172:tid 509367] [client 52.139.37.240:0] AH01276: Cannot serve directory /home3/matthew/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:08:45.267893 2026] [security2:error] [pid 509172:tid 509310] [client 20.104.50.220:32074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/indo.php"] [unique_id "apPlDZwMiz5K1he2FnnwYAAAAZU"]
[Sun Aug 30 03:08:45.278438 2026] [security2:error] [pid 509172:tid 509330] [client 20.151.200.44:46940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/ca.php"] [unique_id "apPlDZwMiz5K1he2FnnwbAAAAak"]
[Sun Aug 30 03:08:45.308065 2026] [security2:error] [pid 509172:tid 509398] [client 74.248.24.12:7545] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "b6standards.com"] [uri "/c99.php"] [unique_id "apPlDZwMiz5K1he2FnnwewAAAe0"]
[Sun Aug 30 03:08:45.315616 2026] [security2:error] [pid 509172:tid 509325] [client 52.139.37.240:37238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/ws77.php"] [unique_id "apPlDZwMiz5K1he2FnnwfgAAAaQ"]
[Sun Aug 30 03:08:45.350690 2026] [authz_core:error] [pid 509172:tid 509367] [client 66.249.66.71:46486] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:45.351099 2026] [authz_core:error] [pid 509172:tid 509367] [client 66.249.66.71:46486] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:45.373912 2026] [authz_core:error] [pid 509172:tid 509326] [client 66.249.66.202:40224] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:45.374347 2026] [authz_core:error] [pid 509172:tid 509326] [client 66.249.66.202:40224] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:45.386784 2026] [security2:error] [pid 507246:tid 507493] [client 20.48.251.3:13425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/god.php"] [unique_id "apPlDe8CsCvw81e_I2pOjAAAAw4"]
[Sun Aug 30 03:08:45.434223 2026] [security2:error] [pid 509172:tid 509383] [client 20.63.81.20:52405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlDZwMiz5K1he2FnnwlwAAAd4"]
[Sun Aug 30 03:08:45.438067 2026] [security2:error] [pid 509172:tid 509355] [client 20.104.50.220:16728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/006.php"] [unique_id "apPlDZwMiz5K1he2FnnwmwAAAcI"]
[Sun Aug 30 03:08:45.459875 2026] [security2:error] [pid 507246:tid 507445] [client 20.104.49.130:51547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/simple.php"] [unique_id "apPlDe8CsCvw81e_I2pOoAAAAt4"]
[Sun Aug 30 03:08:45.461538 2026] [security2:error] [pid 509172:tid 509430] [client 20.48.251.3:59311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/cp2.php"] [unique_id "apPlDZwMiz5K1he2FnnwpQAAAg0"]
[Sun Aug 30 03:08:45.470751 2026] [authz_core:error] [pid 507246:tid 507501] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:45.471028 2026] [authz_core:error] [pid 507246:tid 507501] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:45.471175 2026] [authz_core:error] [pid 509172:tid 509428] [client 66.249.66.74:52102] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:45.471562 2026] [authz_core:error] [pid 509172:tid 509428] [client 66.249.66.74:52102] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:45.490008 2026] [security2:error] [pid 509172:tid 509414] [client 158.158.54.35:6535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/contentloader1.php"] [unique_id "apPlDZwMiz5K1he2FnnwsAAAAf0"]
[Sun Aug 30 03:08:45.507331 2026] [security2:error] [pid 507246:tid 507437] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/zend/.env"] [unique_id "apPlDe8CsCvw81e_I2pOrwAAAtY"]
[Sun Aug 30 03:08:45.509873 2026] [security2:error] [pid 509172:tid 509412] [client 52.139.37.240:37229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/admin/function.php"] [unique_id "apPlDZwMiz5K1he2FnnwuwAAAfs"]
[Sun Aug 30 03:08:45.555229 2026] [security2:error] [pid 509172:tid 509376] [client 4.205.62.107:22912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/bb.php"] [unique_id "apPlDZwMiz5K1he2Fnnw0QAAAdc"]
[Sun Aug 30 03:08:45.576794 2026] [security2:error] [pid 509172:tid 509420] [client 20.63.81.20:52685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlDZwMiz5K1he2Fnnw2AAAAgM"]
[Sun Aug 30 03:08:45.595239 2026] [authz_core:error] [pid 507246:tid 507435] [client 216.73.216.128:44807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:45.595561 2026] [authz_core:error] [pid 507246:tid 507435] [client 216.73.216.128:44807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:45.643285 2026] [authz_core:error] [pid 507246:tid 507377] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:45.643733 2026] [authz_core:error] [pid 507246:tid 507377] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:45.677751 2026] [security2:error] [pid 509172:tid 509333] [client 4.205.62.107:64481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/file21.php"] [unique_id "apPlDZwMiz5K1he2Fnnw9AAAAaw"]
[Sun Aug 30 03:08:45.701246 2026] [security2:error] [pid 509172:tid 509355] [client 52.139.37.240:37230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/xx.php"] [unique_id "apPlDZwMiz5K1he2FnnxAgAAAcI"]
[Sun Aug 30 03:08:45.702526 2026] [security2:error] [pid 509172:tid 509387] [client 20.63.81.20:52411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/ser.php"] [unique_id "apPlDZwMiz5K1he2FnnxAwAAAeI"]
[Sun Aug 30 03:08:45.708802 2026] [authz_core:error] [pid 509172:tid 509420] [client 66.249.66.34:62064] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:45.709061 2026] [authz_core:error] [pid 509172:tid 509420] [client 66.249.66.34:62064] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:45.741965 2026] [security2:error] [pid 507246:tid 507401] [client 4.205.62.107:36660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/upload.form.php"] [unique_id "apPlDe8CsCvw81e_I2pO4QAAArI"]
[Sun Aug 30 03:08:45.742958 2026] [security2:error] [pid 509172:tid 509354] [client 20.104.18.15:35019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/ano.php"] [unique_id "apPlDZwMiz5K1he2FnnxEAAAAcE"]
[Sun Aug 30 03:08:45.762933 2026] [security2:error] [pid 509172:tid 509389] [client 20.104.49.130:63497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/simple.php"] [unique_id "apPlDZwMiz5K1he2FnnxGAAAAeQ"]
[Sun Aug 30 03:08:45.778622 2026] [security2:error] [pid 507246:tid 507465] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/yii/.env"] [unique_id "apPlDe8CsCvw81e_I2pO6gAAAvI"]
[Sun Aug 30 03:08:45.803630 2026] [security2:error] [pid 509172:tid 509422] [client 68.155.159.216:55129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apPlDZwMiz5K1he2FnnxLAAAAgU"]
[Sun Aug 30 03:08:45.828480 2026] [authz_core:error] [pid 509172:tid 509425] [client 66.249.66.42:59977] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:45.828900 2026] [authz_core:error] [pid 509172:tid 509425] [client 66.249.66.42:59977] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:45.833046 2026] [authz_core:error] [pid 509172:tid 509347] [client 66.249.66.198:47754] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:45.833327 2026] [authz_core:error] [pid 509172:tid 509347] [client 66.249.66.198:47754] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:45.833480 2026] [security2:error] [pid 507246:tid 507417] [client 20.63.81.20:52679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/431.php"] [unique_id "apPlDe8CsCvw81e_I2pPBwAAAsI"]
[Sun Aug 30 03:08:45.852311 2026] [security2:error] [pid 509172:tid 509399] [client 74.248.24.12:11297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/404.php123123"] [unique_id "apPlDZwMiz5K1he2FnnxPAAAAe4"]
[Sun Aug 30 03:08:45.893740 2026] [security2:error] [pid 509172:tid 509416] [client 52.139.37.240:37228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/wp-content/about.php"] [unique_id "apPlDZwMiz5K1he2FnnxWgAAAf8"]
[Sun Aug 30 03:08:45.932433 2026] [security2:error] [pid 509172:tid 509393] [client 158.158.54.35:34883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/sim.php"] [unique_id "apPlDZwMiz5K1he2FnnxbAAAAeg"]
[Sun Aug 30 03:08:45.939436 2026] [security2:error] [pid 507246:tid 507442] [client 68.155.159.216:62063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apPlDe8CsCvw81e_I2pPWAAAAts"]
[Sun Aug 30 03:08:45.965236 2026] [security2:error] [pid 507246:tid 507467] [client 20.63.81.20:52691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/rxr.php"] [unique_id "apPlDe8CsCvw81e_I2pPagAAAvQ"]
[Sun Aug 30 03:08:45.990883 2026] [authz_core:error] [pid 507246:tid 507456] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:45.991281 2026] [authz_core:error] [pid 507246:tid 507456] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:45.994398 2026] [security2:error] [pid 507246:tid 507482] [client 20.48.251.3:6500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/drykl.php"] [unique_id "apPlDe8CsCvw81e_I2pPegAAAwM"]
[Sun Aug 30 03:08:46.014670 2026] [security2:error] [pid 507246:tid 507469] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/laravel5/.env"] [unique_id "apPlDu8CsCvw81e_I2pPhgAAAvY"]
[Sun Aug 30 03:08:46.051922 2026] [authz_core:error] [pid 507246:tid 507468] [client 216.73.216.128:1805] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:46.052236 2026] [authz_core:error] [pid 507246:tid 507468] [client 216.73.216.128:1805] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:46.085466 2026] [security2:error] [pid 507246:tid 507407] [client 52.139.37.240:37019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/wp-the.php"] [unique_id "apPlDu8CsCvw81e_I2pPvwAAArg"]
[Sun Aug 30 03:08:46.088633 2026] [security2:error] [pid 507246:tid 507450] [client 20.104.18.15:1987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/nofile.php"] [unique_id "apPlDu8CsCvw81e_I2pPwwAAAuM"]
[Sun Aug 30 03:08:46.090422 2026] [security2:error] [pid 507246:tid 507464] [client 20.63.81.20:52383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/csst.php"] [unique_id "apPlDu8CsCvw81e_I2pPxQAAAvE"]
[Sun Aug 30 03:08:46.096013 2026] [security2:error] [pid 507246:tid 507483] [client 20.104.18.15:18335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/wnnjpsby.php"] [unique_id "apPlDu8CsCvw81e_I2pPyAAAAwQ"]
[Sun Aug 30 03:08:46.109695 2026] [security2:error] [pid 507246:tid 507475] [client 4.205.62.107:25474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/register.php"] [unique_id "apPlDu8CsCvw81e_I2pPsAAAAvw"]
[Sun Aug 30 03:08:46.127476 2026] [security2:error] [pid 507246:tid 507435] [client 20.104.50.220:47090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/image.php"] [unique_id "apPlDu8CsCvw81e_I2pP1AAAAtQ"]
[Sun Aug 30 03:08:46.146035 2026] [security2:error] [pid 507246:tid 507432] [client 20.151.200.44:46079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/motu.php"] [unique_id "apPlDu8CsCvw81e_I2pP3QAAAtE"]
[Sun Aug 30 03:08:46.175576 2026] [security2:error] [pid 509172:tid 509370] [client 20.104.18.15:34642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/wp-content/k.php"] [unique_id "apPlDpwMiz5K1he2FnnxnwAAAdE"]
[Sun Aug 30 03:08:46.177515 2026] [security2:error] [pid 509172:tid 509345] [client 20.104.50.220:41995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/tertykung.php"] [unique_id "apPlDpwMiz5K1he2FnnxoQAAAbg"]
[Sun Aug 30 03:08:46.178184 2026] [security2:error] [pid 509172:tid 509389] [client 20.104.50.220:6121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/i.php"] [unique_id "apPlDpwMiz5K1he2FnnxowAAAeQ"]
[Sun Aug 30 03:08:46.216830 2026] [security2:error] [pid 509172:tid 509421] [client 20.63.81.20:52717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp-includes/blocks/query-title/footer.php"] [unique_id "apPlDpwMiz5K1he2FnnxrwAAAgQ"]
[Sun Aug 30 03:08:46.246967 2026] [security2:error] [pid 509172:tid 509410] [client 20.48.251.3:5071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/classsmtps.php"] [unique_id "apPlDpwMiz5K1he2FnnxsgAAAfk"]
[Sun Aug 30 03:08:46.251183 2026] [security2:error] [pid 507246:tid 507467] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/v1/.env"] [unique_id "apPlDu8CsCvw81e_I2pQBgAAAvQ"]
[Sun Aug 30 03:08:46.273231 2026] [security2:error] [pid 507246:tid 507388] [client 20.104.18.15:43272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/aa.php"] [unique_id "apPlDu8CsCvw81e_I2pQEwAAAqU"]
[Sun Aug 30 03:08:46.277465 2026] [security2:error] [pid 507246:tid 507469] [client 52.139.37.240:37053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/ws81.php"] [unique_id "apPlDu8CsCvw81e_I2pQFQAAAvY"]
[Sun Aug 30 03:08:46.311787 2026] [security2:error] [pid 507246:tid 507491] [client 20.104.50.220:61958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/robot.php"] [unique_id "apPlDu8CsCvw81e_I2pQKgAAAww"]
[Sun Aug 30 03:08:46.313156 2026] [security2:error] [pid 507246:tid 507498] [client 20.104.18.15:23302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/wp-trackback.php"] [unique_id "apPlDu8CsCvw81e_I2pQLAAAAxM"]
[Sun Aug 30 03:08:46.332570 2026] [security2:error] [pid 507246:tid 507395] [client 20.104.50.220:28705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-utchershill.php"] [unique_id "apPlDu8CsCvw81e_I2pQMgAAAqw"]
[Sun Aug 30 03:08:46.363630 2026] [security2:error] [pid 509172:tid 509415] [client 20.63.81.20:52402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp-content/uploads/indoex.php"] [unique_id "apPlDpwMiz5K1he2Fnnx2wAAAf4"]
[Sun Aug 30 03:08:46.383135 2026] [security2:error] [pid 509172:tid 509307] [client 20.104.49.130:34512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/dragonshell.php"] [unique_id "apPlDpwMiz5K1he2Fnnx4gAAAZI"]
[Sun Aug 30 03:08:46.385541 2026] [authz_core:error] [pid 507246:tid 507411] [client 66.249.66.198:50541] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:46.385907 2026] [authz_core:error] [pid 507246:tid 507411] [client 66.249.66.198:50541] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:46.386333 2026] [security2:error] [pid 509172:tid 509391] [client 20.104.50.220:33042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/mom.php"] [unique_id "apPlDpwMiz5K1he2Fnnx5gAAAeY"]
[Sun Aug 30 03:08:46.387560 2026] [security2:error] [pid 507246:tid 507501] [client 74.248.24.12:7507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/error.php"] [unique_id "apPlDu8CsCvw81e_I2pQQAAAAxY"]
[Sun Aug 30 03:08:46.387794 2026] [authz_core:error] [pid 509172:tid 509353] [client 66.249.66.77:41757] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:46.387888 2026] [security2:error] [pid 509172:tid 509313] [client 158.158.54.35:34892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/83064.php"] [unique_id "apPlDpwMiz5K1he2Fnnx6AAAAZg"]
[Sun Aug 30 03:08:46.388237 2026] [authz_core:error] [pid 509172:tid 509353] [client 66.249.66.77:41757] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:46.397390 2026] [security2:error] [pid 509172:tid 509392] [client 20.104.50.220:62796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/oke.php"] [unique_id "apPlDpwMiz5K1he2Fnnx6wAAAec"]
[Sun Aug 30 03:08:46.406818 2026] [security2:error] [pid 507246:tid 507444] [client 20.104.50.220:32536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/fileas.php"] [unique_id "apPlDu8CsCvw81e_I2pQQgAAAt0"]
[Sun Aug 30 03:08:46.470350 2026] [authz_core:error] [pid 507246:tid 507479] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:46.470886 2026] [authz_core:error] [pid 507246:tid 507479] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:46.471761 2026] [security2:error] [pid 507246:tid 507496] [client 52.139.37.240:37243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/a1.php"] [unique_id "apPlDu8CsCvw81e_I2pQUgAAAxE"]
[Sun Aug 30 03:08:46.484207 2026] [authz_core:error] [pid 509172:tid 509313] [client 66.249.66.73:48474] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:46.484473 2026] [authz_core:error] [pid 509172:tid 509313] [client 66.249.66.73:48474] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:46.492296 2026] [security2:error] [pid 507246:tid 507502] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/v2/.env"] [unique_id "apPlDu8CsCvw81e_I2pQVAAAAxc"]
[Sun Aug 30 03:08:46.497571 2026] [security2:error] [pid 509172:tid 509348] [client 20.63.81.20:52410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPlDpwMiz5K1he2FnnyGQAAAbs"]
[Sun Aug 30 03:08:46.538705 2026] [authz_core:error] [pid 509172:tid 509321] [client 66.249.66.195:57406] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:46.539128 2026] [authz_core:error] [pid 509172:tid 509321] [client 66.249.66.195:57406] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:46.544497 2026] [security2:error] [pid 509172:tid 509399] [client 20.48.251.3:60499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/fff.php"] [unique_id "apPlDpwMiz5K1he2FnnyNgAAAe4"]
[Sun Aug 30 03:08:46.554424 2026] [security2:error] [pid 509172:tid 509400] [client 20.104.49.130:63614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/term.php"] [unique_id "apPlDpwMiz5K1he2FnnyQAAAAe8"]
[Sun Aug 30 03:08:46.559385 2026] [security2:error] [pid 509172:tid 509398] [client 68.155.159.216:45977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-includes/fonts/about.php"] [unique_id "apPlDpwMiz5K1he2FnnyRAAAAe0"]
[Sun Aug 30 03:08:46.561739 2026] [security2:error] [pid 509172:tid 509391] [client 20.151.200.44:47096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/pb.php"] [unique_id "apPlDpwMiz5K1he2FnnyRgAAAeY"]
[Sun Aug 30 03:08:46.576386 2026] [security2:error] [pid 509172:tid 509395] [client 20.104.50.220:16633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/file5.php"] [unique_id "apPlDpwMiz5K1he2FnnyTwAAAeo"]
[Sun Aug 30 03:08:46.595442 2026] [security2:error] [pid 507246:tid 507461] [client 20.48.251.3:59340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/xda.php"] [unique_id "apPlDu8CsCvw81e_I2pQawAAAu4"]
[Sun Aug 30 03:08:46.596914 2026] [authz_core:error] [pid 507246:tid 507388] [client 216.73.216.128:44807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:46.597212 2026] [authz_core:error] [pid 507246:tid 507388] [client 216.73.216.128:44807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:46.631638 2026] [security2:error] [pid 507246:tid 507382] [client 20.63.81.20:52352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/haxor.php"] [unique_id "apPlDu8CsCvw81e_I2pQdwAAAp8"]
[Sun Aug 30 03:08:46.671235 2026] [security2:error] [pid 507246:tid 507490] [client 52.139.37.240:37247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/ca5.php"] [unique_id "apPlDu8CsCvw81e_I2pQhAAAAws"]
[Sun Aug 30 03:08:46.690764 2026] [authz_core:error] [pid 509172:tid 509314] [client 216.73.216.128:34637] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:46.690864 2026] [authz_core:error] [pid 509172:tid 509351] [client 66.249.66.74:52102] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:46.691199 2026] [authz_core:error] [pid 509172:tid 509314] [client 216.73.216.128:34637] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:46.691274 2026] [authz_core:error] [pid 509172:tid 509351] [client 66.249.66.74:52102] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:46.700339 2026] [security2:error] [pid 507246:tid 507415] [client 4.205.62.107:62290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/file59.php"] [unique_id "apPlDu8CsCvw81e_I2pQlAAAAsA"]
[Sun Aug 30 03:08:46.736035 2026] [security2:error] [pid 507246:tid 507397] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/v3/.env"] [unique_id "apPlDu8CsCvw81e_I2pQoAAAAq4"]
[Sun Aug 30 03:08:46.758710 2026] [security2:error] [pid 507246:tid 507437] [client 20.63.81.20:52395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/google.php"] [unique_id "apPlDu8CsCvw81e_I2pQpQAAAtY"]
[Sun Aug 30 03:08:46.814405 2026] [security2:error] [pid 509172:tid 509389] [client 4.205.62.107:64644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/mcebraed.php"] [unique_id "apPlDpwMiz5K1he2FnnyowAAAeQ"]
[Sun Aug 30 03:08:46.829198 2026] [security2:error] [pid 509172:tid 509370] [client 20.151.200.44:46990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/pk.php"] [unique_id "apPlDpwMiz5K1he2FnnysgAAAdE"]
[Sun Aug 30 03:08:46.834096 2026] [security2:error] [pid 507246:tid 507427] [client 158.158.54.35:27230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/cnzcsfwm.php"] [unique_id "apPlDu8CsCvw81e_I2pQwgAAAsw"]
[Sun Aug 30 03:08:46.864836 2026] [security2:error] [pid 509172:tid 509309] [client 52.139.37.240:37194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/install.php"] [unique_id "apPlDpwMiz5K1he2FnnyyQAAAZQ"]
[Sun Aug 30 03:08:46.881700 2026] [security2:error] [pid 507246:tid 507446] [client 20.104.18.15:35517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/mgrr.php"] [unique_id "apPlDu8CsCvw81e_I2pQ2QAAAt8"]
[Sun Aug 30 03:08:46.889579 2026] [security2:error] [pid 509172:tid 509393] [client 20.63.81.20:52709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "apPlDpwMiz5K1he2Fnny4QAAAeg"]
[Sun Aug 30 03:08:46.898373 2026] [security2:error] [pid 509172:tid 509395] [client 74.248.24.12:12218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/raf.php"] [unique_id "apPlDpwMiz5K1he2Fnny6gAAAeo"]
[Sun Aug 30 03:08:46.899456 2026] [authz_core:error] [pid 509172:tid 509369] [client 66.249.66.78:44273] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:46.899926 2026] [authz_core:error] [pid 509172:tid 509369] [client 66.249.66.78:44273] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:46.923249 2026] [security2:error] [pid 509172:tid 509412] [client 4.205.62.107:36672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/aws_auth.php"] [unique_id "apPlDpwMiz5K1he2Fnny8wAAAfs"]
[Sun Aug 30 03:08:46.936088 2026] [authz_core:error] [pid 507246:tid 507456] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:46.936496 2026] [authz_core:error] [pid 507246:tid 507456] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:46.940189 2026] [security2:error] [pid 507246:tid 507388] [client 68.155.159.216:55161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/goat1.php"] [unique_id "apPlDu8CsCvw81e_I2pQ-AAAAqU"]
[Sun Aug 30 03:08:46.987273 2026] [authz_core:error] [pid 507246:tid 507422] [client 66.249.66.32:46784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:46.987711 2026] [authz_core:error] [pid 507246:tid 507422] [client 66.249.66.32:46784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:46.997176 2026] [security2:error] [pid 507246:tid 507490] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/api/v1/.env"] [unique_id "apPlDu8CsCvw81e_I2pRFQAAAws"]
[Sun Aug 30 03:08:47.015784 2026] [security2:error] [pid 507246:tid 507432] [client 20.63.81.20:52674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/robots.php"] [unique_id "apPlD-8CsCvw81e_I2pRHQAAAtE"]
[Sun Aug 30 03:08:47.076709 2026] [authz_core:error] [pid 509172:tid 509397] [client 66.249.66.73:48474] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:47.077196 2026] [authz_core:error] [pid 509172:tid 509397] [client 66.249.66.73:48474] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:47.080872 2026] [authz_core:error] [pid 507246:tid 507377] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:47.081133 2026] [authz_core:error] [pid 507246:tid 507377] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:47.091526 2026] [security2:error] [pid 507246:tid 507427] [client 68.155.159.216:61437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apPlD-8CsCvw81e_I2pRUQAAAsw"]
[Sun Aug 30 03:08:47.109519 2026] [security2:error] [pid 509172:tid 509317] [client 20.151.200.44:46993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/ft.php"] [unique_id "apPlD5wMiz5K1he2FnnzUQAAAZw"]
[Sun Aug 30 03:08:47.141665 2026] [security2:error] [pid 509172:tid 509393] [client 20.63.81.20:52688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp-content/plugins/ccx/index.php"] [unique_id "apPlD5wMiz5K1he2FnnzXwAAAeg"]
[Sun Aug 30 03:08:47.168066 2026] [autoindex:error] [pid 507246:tid 507406] [client 52.139.37.240:37457] AH01276: Cannot serve directory /home3/matthew/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:08:47.227039 2026] [security2:error] [pid 509172:tid 509412] [client 20.104.18.15:1931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/run.php"] [unique_id "apPlD5wMiz5K1he2FnnzeAAAAfs"]
[Sun Aug 30 03:08:47.231938 2026] [security2:error] [pid 507246:tid 507465] [client 52.139.37.240:37457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/wp-signin.php"] [unique_id "apPlD-8CsCvw81e_I2pRhAAAAvI"]
[Sun Aug 30 03:08:47.241144 2026] [security2:error] [pid 507246:tid 507495] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/api/v2/.env"] [unique_id "apPlD-8CsCvw81e_I2pRhQAAAxA"]
[Sun Aug 30 03:08:47.253433 2026] [security2:error] [pid 509172:tid 509351] [client 20.104.18.15:18410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/gigi.php"] [unique_id "apPlD5wMiz5K1he2FnnzgAAAAb4"]
[Sun Aug 30 03:08:47.265423 2026] [security2:error] [pid 507246:tid 507415] [client 20.151.200.44:46074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/wefile.php"] [unique_id "apPlD-8CsCvw81e_I2pRkgAAAsA"]
[Sun Aug 30 03:08:47.269745 2026] [security2:error] [pid 509172:tid 509418] [client 20.48.251.3:64473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/rpk.php"] [unique_id "apPlD5wMiz5K1he2FnnziwAAAgE"]
[Sun Aug 30 03:08:47.269768 2026] [security2:error] [pid 509172:tid 509380] [client 20.104.50.220:46887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-admin/wp-conflg.php"] [unique_id "apPlD5wMiz5K1he2FnnzigAAAds"]
[Sun Aug 30 03:08:47.280572 2026] [security2:error] [pid 509172:tid 509354] [client 20.63.81.20:52681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp-admin/css/colors/maro.php"] [unique_id "apPlD5wMiz5K1he2FnnzlgAAAcE"]
[Sun Aug 30 03:08:47.309290 2026] [security2:error] [pid 509172:tid 509331] [client 20.104.18.15:34798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/os.php"] [unique_id "apPlD5wMiz5K1he2FnnzqgAAAao"]
[Sun Aug 30 03:08:47.313897 2026] [security2:error] [pid 509172:tid 509419] [client 20.104.50.220:51566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/goods.php"] [unique_id "apPlD5wMiz5K1he2FnnzrwAAAgI"]
[Sun Aug 30 03:08:47.331865 2026] [security2:error] [pid 507246:tid 507403] [client 20.104.50.220:5622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/j.php"] [unique_id "apPlD-8CsCvw81e_I2pRqwAAArQ"]
[Sun Aug 30 03:08:47.334665 2026] [security2:error] [pid 509172:tid 509375] [client 4.205.62.107:25749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/xqq.php"] [unique_id "apPlD5wMiz5K1he2FnnzuwAAAdY"]
[Sun Aug 30 03:08:47.339036 2026] [security2:error] [pid 509172:tid 509338] [client 20.151.200.44:47069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/wp-ver.php"] [unique_id "apPlD5wMiz5K1he2FnnzvQAAAbE"]
[Sun Aug 30 03:08:47.385573 2026] [security2:error] [pid 509172:tid 509353] [client 20.48.251.3:44378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/cache-compat.php"] [unique_id "apPlD5wMiz5K1he2FnnzyQAAAcA"]
[Sun Aug 30 03:08:47.388230 2026] [security2:error] [pid 507246:tid 507460] [client 158.158.54.35:6519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/word.php"] [unique_id "apPlD-8CsCvw81e_I2pRtgAAAu0"]
[Sun Aug 30 03:08:47.406817 2026] [security2:error] [pid 509172:tid 509348] [client 20.63.81.20:52408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp-admin/css/colors/coffee/marijuana.php"] [unique_id "apPlD5wMiz5K1he2Fnnz1AAAAbs"]
[Sun Aug 30 03:08:47.423239 2026] [security2:error] [pid 509172:tid 509349] [client 52.139.37.240:37862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/Ov-Simple1.php"] [unique_id "apPlD5wMiz5K1he2Fnnz4wAAAbw"]
[Sun Aug 30 03:08:47.436939 2026] [security2:error] [pid 507246:tid 507423] [client 20.104.18.15:43985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/img.php"] [unique_id "apPlD-8CsCvw81e_I2pRvgAAAsg"]
[Sun Aug 30 03:08:47.438635 2026] [security2:error] [pid 509172:tid 509405] [client 74.248.24.12:6020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/about.php525"] [unique_id "apPlD5wMiz5K1he2Fnnz7AAAAfQ"]
[Sun Aug 30 03:08:47.451487 2026] [security2:error] [pid 509172:tid 509350] [client 20.104.50.220:61968] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "523"] [id "900207"] [msg "Sys[0-9]+ Mailer"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/sys32.php"] [unique_id "apPlD5wMiz5K1he2Fnnz8wAAAb0"]
[Sun Aug 30 03:08:47.455252 2026] [authz_core:error] [pid 509172:tid 509311] [client 66.249.66.45:63624] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:47.455712 2026] [authz_core:error] [pid 509172:tid 509311] [client 66.249.66.45:63624] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:47.472397 2026] [security2:error] [pid 509172:tid 509378] [client 20.104.50.220:62784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-log.php"] [unique_id "apPlD5wMiz5K1he2Fnn0AAAAAdk"]
[Sun Aug 30 03:08:47.480558 2026] [authz_core:error] [pid 507246:tid 507432] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:47.480883 2026] [authz_core:error] [pid 507246:tid 507432] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:47.481324 2026] [security2:error] [pid 507246:tid 507458] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/rest/.env"] [unique_id "apPlD-8CsCvw81e_I2pRyQAAAus"]
[Sun Aug 30 03:08:47.497629 2026] [security2:error] [pid 509172:tid 509383] [client 20.104.49.130:45177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/chosen.php"] [unique_id "apPlD5wMiz5K1he2Fnn0CwAAAd4"]
[Sun Aug 30 03:08:47.501096 2026] [security2:error] [pid 509172:tid 509417] [client 20.104.18.15:23422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/pri.php"] [unique_id "apPlD5wMiz5K1he2Fnn0DQAAAgA"]
[Sun Aug 30 03:08:47.501526 2026] [authz_core:error] [pid 509172:tid 509305] [client 66.249.66.43:46127] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:47.501971 2026] [authz_core:error] [pid 509172:tid 509305] [client 66.249.66.43:46127] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:47.539820 2026] [security2:error] [pid 509172:tid 509344] [client 20.63.81.20:52388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp-admin/css/colors/coffee/mari.php"] [unique_id "apPlD5wMiz5K1he2Fnn0KwAAAbc"]
[Sun Aug 30 03:08:47.540808 2026] [security2:error] [pid 509172:tid 509428] [client 20.104.50.220:52842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/MKY.php"] [unique_id "apPlD5wMiz5K1he2Fnn0LQAAAgs"]
[Sun Aug 30 03:08:47.558466 2026] [security2:error] [pid 509172:tid 509320] [client 20.104.50.220:33164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/killer.php"] [unique_id "apPlD5wMiz5K1he2Fnn0QQAAAZ8"]
[Sun Aug 30 03:08:47.584229 2026] [security2:error] [pid 509172:tid 509415] [client 20.104.50.220:32531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/yellow.php"] [unique_id "apPlD5wMiz5K1he2Fnn0TAAAAf4"]
[Sun Aug 30 03:08:47.600563 2026] [authz_core:error] [pid 509172:tid 509339] [client 66.249.66.40:41708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:47.601018 2026] [authz_core:error] [pid 509172:tid 509339] [client 66.249.66.40:41708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:47.618982 2026] [security2:error] [pid 509172:tid 509404] [client 52.139.37.240:36994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/ftde.php"] [unique_id "apPlD5wMiz5K1he2Fnn0WAAAAfM"]
[Sun Aug 30 03:08:47.663267 2026] [authz_core:error] [pid 507246:tid 507437] [client 66.249.66.44:51124] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:47.663735 2026] [authz_core:error] [pid 507246:tid 507437] [client 66.249.66.44:51124] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:47.674208 2026] [security2:error] [pid 509172:tid 509310] [client 20.63.81.20:52697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp-includes/images/crystal/option.php"] [unique_id "apPlD5wMiz5K1he2Fnn0aAAAAZU"]
[Sun Aug 30 03:08:47.691902 2026] [authz_core:error] [pid 509172:tid 509353] [client 216.73.216.128:28214] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:47.692269 2026] [authz_core:error] [pid 509172:tid 509353] [client 216.73.216.128:28214] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:47.692531 2026] [security2:error] [pid 507246:tid 507382] [client 20.48.251.3:33335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/autogooey.php"] [unique_id "apPlD-8CsCvw81e_I2pSCgAAAp8"]
[Sun Aug 30 03:08:47.715915 2026] [security2:error] [pid 509172:tid 509417] [client 20.104.50.220:16596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPlD5wMiz5K1he2Fnn0gQAAAgA"]
[Sun Aug 30 03:08:47.727002 2026] [security2:error] [pid 507246:tid 507448] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/graphql/.env"] [unique_id "apPlD-8CsCvw81e_I2pSEQAAAuE"]
[Sun Aug 30 03:08:47.733851 2026] [security2:error] [pid 507246:tid 507403] [client 20.48.251.3:55751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/pinfo.php"] [unique_id "apPlD-8CsCvw81e_I2pSFgAAArQ"]
[Sun Aug 30 03:08:47.760602 2026] [authz_core:error] [pid 509172:tid 509361] [client 66.249.66.197:64947] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:47.760914 2026] [authz_core:error] [pid 509172:tid 509361] [client 66.249.66.197:64947] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:47.780918 2026] [authz_core:error] [pid 507246:tid 507465] [client 216.73.216.128:44807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:47.781195 2026] [authz_core:error] [pid 507246:tid 507465] [client 216.73.216.128:44807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:47.800400 2026] [security2:error] [pid 509172:tid 509413] [client 20.63.81.20:52683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp-includes/pomo/xxx.php"] [unique_id "apPlD5wMiz5K1he2Fnn0tgAAAfw"]
[Sun Aug 30 03:08:47.809851 2026] [security2:error] [pid 509172:tid 509369] [client 52.139.37.240:37004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/hplfuns.php"] [unique_id "apPlD5wMiz5K1he2Fnn0vgAAAdA"]
[Sun Aug 30 03:08:47.836447 2026] [security2:error] [pid 509172:tid 509380] [client 158.158.54.35:6581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/headerg.php"] [unique_id "apPlD5wMiz5K1he2Fnn00gAAAds"]
[Sun Aug 30 03:08:47.838283 2026] [security2:error] [pid 509172:tid 509338] [client 4.205.62.107:22538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/cli_bootstrap.php"] [unique_id "apPlD5wMiz5K1he2Fnn01wAAAbE"]
[Sun Aug 30 03:08:47.932571 2026] [security2:error] [pid 509172:tid 509363] [client 20.104.49.130:63244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/memberfuns.php"] [unique_id "apPlD5wMiz5K1he2Fnn1FQAAAco"]
[Sun Aug 30 03:08:47.937568 2026] [security2:error] [pid 509172:tid 509424] [client 20.63.81.20:52398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/650.php"] [unique_id "apPlD5wMiz5K1he2Fnn1GQAAAgc"]
[Sun Aug 30 03:08:47.947006 2026] [security2:error] [pid 507246:tid 507411] [client 74.248.24.12:12162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/embed.php"] [unique_id "apPlD-8CsCvw81e_I2pSbwAAArw"]
[Sun Aug 30 03:08:47.953296 2026] [authz_core:error] [pid 507246:tid 507429] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:47.953561 2026] [authz_core:error] [pid 507246:tid 507429] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:47.961456 2026] [security2:error] [pid 507246:tid 507439] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/gateway/.env"] [unique_id "apPlD-8CsCvw81e_I2pSdAAAAtg"]
[Sun Aug 30 03:08:48.007674 2026] [security2:error] [pid 509172:tid 509347] [client 52.139.37.240:37237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/log.php"] [unique_id "apPlEJwMiz5K1he2Fnn1KgAAAbo"]
[Sun Aug 30 03:08:48.054287 2026] [authz_core:error] [pid 507246:tid 507471] [client 216.73.216.128:44807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:48.054671 2026] [authz_core:error] [pid 507246:tid 507471] [client 216.73.216.128:44807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:48.153981 2026] [authz_core:error] [pid 507246:tid 507445] [client 66.249.66.205:54363] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:48.154302 2026] [authz_core:error] [pid 507246:tid 507445] [client 66.249.66.205:54363] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:48.186458 2026] [qos:error] [pid 509172:tid 509399] [client 103.188.173.37:35879] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.188.173.37, id=apPlEJwMiz5K1he2Fnn1RQAAAe4
[Sun Aug 30 03:08:48.196950 2026] [qos:error] [pid 509172:tid 509412] [client 117.2.104.13:36930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=117.2.104.13, id=apPlEJwMiz5K1he2Fnn1RgAAAfs
[Sun Aug 30 03:08:48.199225 2026] [qos:error] [pid 507246:tid 507448] [client 103.159.78.237:58263] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.159.78.237, id=apPlEO8CsCvw81e_I2pSpAAAAuE
[Sun Aug 30 03:08:48.199230 2026] [qos:error] [pid 507246:tid 507492] [client 199.7.149.90:58534] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=199.7.149.90, id=apPlEO8CsCvw81e_I2pSpQAAAw0
[Sun Aug 30 03:08:48.199446 2026] [qos:error] [pid 507246:tid 507428] [client 103.138.185.2:58887] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.138.185.2, id=apPlEO8CsCvw81e_I2pSowAAAs0
[Sun Aug 30 03:08:48.200155 2026] [qos:error] [pid 507246:tid 507391] [client 154.59.111.42:45818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=154.59.111.42, id=apPlEO8CsCvw81e_I2pSpgAAAqg
[Sun Aug 30 03:08:48.202833 2026] [qos:error] [pid 507246:tid 507484] [client 45.127.58.70:49334] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.127.58.70, id=apPlEO8CsCvw81e_I2pSpwAAAwU
[Sun Aug 30 03:08:48.203610 2026] [qos:error] [pid 509172:tid 509353] [client 37.193.101.148:52945] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=37.193.101.148, id=apPlEJwMiz5K1he2Fnn1RwAAAcA
[Sun Aug 30 03:08:48.205441 2026] [qos:error] [pid 507246:tid 507440] [client 121.169.46.116:59613] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=121.169.46.116, id=apPlEO8CsCvw81e_I2pSqAAAAtk
[Sun Aug 30 03:08:48.208205 2026] [security2:error] [pid 507246:tid 507489] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/microservice/.env"] [unique_id "apPlEO8CsCvw81e_I2pSqQAAAwo"]
[Sun Aug 30 03:08:48.220558 2026] [qos:error] [pid 509172:tid 509407] [client 37.29.12.198:36874] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=37.29.12.198, id=apPlEJwMiz5K1he2Fnn1SAAAAfY
[Sun Aug 30 03:08:48.222063 2026] [qos:error] [pid 507246:tid 507401] [client 87.251.77.29:59088] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=87.251.77.29, id=apPlEO8CsCvw81e_I2pSqgAAArI
[Sun Aug 30 03:08:48.222944 2026] [qos:error] [pid 509172:tid 509384] [client 124.106.119.83:55496] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=124.106.119.83, id=apPlEJwMiz5K1he2Fnn1SQAAAd8
[Sun Aug 30 03:08:48.230590 2026] [qos:error] [pid 507246:tid 507491] [client 108.165.173.211:58494] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=108.165.173.211, id=apPlEO8CsCvw81e_I2pSrAAAAww
[Sun Aug 30 03:08:48.231231 2026] [qos:error] [pid 507246:tid 507463] [client 195.190.121.154:50062] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=195.190.121.154, id=apPlEO8CsCvw81e_I2pSrgAAAvA
[Sun Aug 30 03:08:48.231238 2026] [qos:error] [pid 507246:tid 507410] [client 43.249.227.186:50094] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=43.249.227.186, id=apPlEO8CsCvw81e_I2pSrQAAArs
[Sun Aug 30 03:08:48.245525 2026] [qos:error] [pid 509172:tid 509381] [client 78.40.199.121:38686] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=78.40.199.121, id=apPlEJwMiz5K1he2Fnn1SgAAAdw
[Sun Aug 30 03:08:48.248124 2026] [qos:error] [pid 507246:tid 507496] [client 177.159.113.232:33841] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=177.159.113.232, id=apPlEO8CsCvw81e_I2pSrwAAAxE
[Sun Aug 30 03:08:48.250944 2026] [http2:info] [pid 509915:tid 509915] h2_workers: created with min=128 max=192 idle_ms=600000
[Sun Aug 30 03:08:48.252988 2026] [qos:error] [pid 509172:tid 509323] [client 103.150.64.71:60281] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.150.64.71, id=apPlEJwMiz5K1he2Fnn1SwAAAaI
[Sun Aug 30 03:08:48.252993 2026] [qos:error] [pid 509172:tid 509365] [client 157.10.184.125:58798] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=157.10.184.125, id=apPlEJwMiz5K1he2Fnn1TAAAAcw
[Sun Aug 30 03:08:48.253619 2026] [qos:error] [pid 509172:tid 509425] [client 31.7.86.35:33642] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=31.7.86.35, id=apPlEJwMiz5K1he2Fnn1TQAAAgg
[Sun Aug 30 03:08:48.255902 2026] [qos:error] [pid 507246:tid 507497] [client 186.5.94.206:36968] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=186.5.94.206, id=apPlEO8CsCvw81e_I2pSsAAAAxI
[Sun Aug 30 03:08:48.268399 2026] [qos:error] [pid 507246:tid 507390] [client 85.8.47.207:58974] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=85.8.47.207, id=apPlEO8CsCvw81e_I2pSsQAAAqc
[Sun Aug 30 03:08:48.269021 2026] [qos:error] [pid 507246:tid 507387] [client 160.187.174.186:55688] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=160.187.174.186, id=apPlEO8CsCvw81e_I2pSsgAAAqQ
[Sun Aug 30 03:08:48.269025 2026] [qos:error] [pid 509172:tid 509390] [client 123.139.125.120:44264] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=123.139.125.120, id=apPlEJwMiz5K1he2Fnn1TgAAAeU
[Sun Aug 30 03:08:48.269424 2026] [qos:error] [pid 507246:tid 507443] [client 163.181.207.170:36720] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=163.181.207.170, id=apPlEO8CsCvw81e_I2pSswAAAtw
[Sun Aug 30 03:08:48.269600 2026] [security2:error] [pid 509915:tid 510048] [client 20.151.200.44:55620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/pk.php"] [unique_id "apPlEM2gn1q0xw8Wp-TJewAABTQ"]
[Sun Aug 30 03:08:48.269711 2026] [qos:error] [pid 507246:tid 507485] [client 212.34.233.150:43200] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=212.34.233.150, id=apPlEO8CsCvw81e_I2pStAAAAwY
[Sun Aug 30 03:08:48.269885 2026] [qos:error] [pid 507246:tid 507388] [client 124.70.144.96:48983] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=124.70.144.96, id=apPlEO8CsCvw81e_I2pStQAAAqU
[Sun Aug 30 03:08:48.270314 2026] [security2:error] [pid 509915:tid 510049] [client 20.151.200.44:46933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/ah24.php"] [unique_id "apPlEM2gn1q0xw8Wp-TJfAAABTU"]
[Sun Aug 30 03:08:48.270452 2026] [security2:error] [pid 509915:tid 510050] [client 4.205.62.107:61729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/server-info.php"] [unique_id "apPlEM2gn1q0xw8Wp-TJfQAABTY"]
[Sun Aug 30 03:08:48.270559 2026] [security2:error] [pid 509915:tid 510052] [client 68.155.159.216:46022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-content/admin.php"] [unique_id "apPlEM2gn1q0xw8Wp-TJfgAABTg"]
[Sun Aug 30 03:08:48.271669 2026] [security2:error] [pid 509915:tid 510051] [client 20.48.251.3:59471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlEM2gn1q0xw8Wp-TJfwAABTc"]
[Sun Aug 30 03:08:48.271738 2026] [security2:error] [pid 509915:tid 510060] [client 68.155.159.216:55068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apPlEM2gn1q0xw8Wp-TJgAAABUA"]
[Sun Aug 30 03:08:48.271792 2026] [security2:error] [pid 509915:tid 510061] [client 4.205.62.107:36617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/hiquido.com/index.php"] [unique_id "apPlEM2gn1q0xw8Wp-TJgQAABUE"]
[Sun Aug 30 03:08:48.271795 2026] [security2:error] [pid 509915:tid 510062] [client 20.63.81.20:52677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/nakrip.php"] [unique_id "apPlEM2gn1q0xw8Wp-TJggAABUI"]
[Sun Aug 30 03:08:48.273827 2026] [qos:error] [pid 509172:tid 509402] [client 27.185.218.213:34117] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=27.185.218.213, id=apPlEJwMiz5K1he2Fnn1TwAAAfE
[Sun Aug 30 03:08:48.275148 2026] [qos:error] [pid 509172:tid 509369] [client 193.32.176.109:58149] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=193.32.176.109, id=apPlEJwMiz5K1he2Fnn1UAAAAdA
[Sun Aug 30 03:08:48.276148 2026] [qos:error] [pid 509915:tid 510058] [client 203.76.112.234:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlEM2gn1q0xw8Wp-TJiQAABT4
[Sun Aug 30 03:08:48.276904 2026] [qos:error] [pid 509172:tid 509344] [client 58.64.160.132:41793] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=58.64.160.132, id=apPlEJwMiz5K1he2Fnn1UQAAAbc
[Sun Aug 30 03:08:48.279201 2026] [qos:error] [pid 509915:tid 510080] [client 38.76.232.195:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlEM2gn1q0xw8Wp-TJkgAABVQ
[Sun Aug 30 03:08:48.279320 2026] [qos:error] [pid 509915:tid 510070] [client 123.25.252.5:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlEM2gn1q0xw8Wp-TJkwAABUo
[Sun Aug 30 03:08:48.279671 2026] [qos:error] [pid 507246:tid 507423] [client 45.172.19.171:44107] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.172.19.171, id=apPlEO8CsCvw81e_I2pStgAAAsg
[Sun Aug 30 03:08:48.280529 2026] [qos:error] [pid 509915:tid 510076] [client 200.30.130.50:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlEM2gn1q0xw8Wp-TJlwAABVA
[Sun Aug 30 03:08:48.280706 2026] [qos:error] [pid 507246:tid 507411] [client 190.60.39.226:47136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=190.60.39.226, id=apPlEO8CsCvw81e_I2pStwAAArw
[Sun Aug 30 03:08:48.282214 2026] [qos:error] [pid 509172:tid 509347] [client 113.161.62.230:42772] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=113.161.62.230, id=apPlEJwMiz5K1he2Fnn1UwAAAbo
[Sun Aug 30 03:08:48.295597 2026] [qos:error] [pid 507246:tid 507384] [client 213.21.53.243:39050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=213.21.53.243, id=apPlEO8CsCvw81e_I2pSugAAAqE
[Sun Aug 30 03:08:48.295632 2026] [qos:error] [pid 509915:tid 510053] [client 43.156.236.238:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.44, id=apPlEM2gn1q0xw8Wp-TJrAAABTk
[Sun Aug 30 03:08:48.296895 2026] [qos:error] [pid 507246:tid 507404] [client 42.118.3.236:60186] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=42.118.3.236, id=apPlEO8CsCvw81e_I2pSuwAAArU
[Sun Aug 30 03:08:48.298583 2026] [qos:error] [pid 509172:tid 509372] [client 38.183.150.10:41822] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.183.150.10, id=apPlEJwMiz5K1he2Fnn1VAAAAdM
[Sun Aug 30 03:08:48.301666 2026] [security2:error] [pid 509915:tid 510046] [client 20.104.18.15:35501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/mac.php"] [unique_id "apPlEM2gn1q0xw8Wp-TJ2AAABTI"]
[Sun Aug 30 03:08:48.304449 2026] [qos:error] [pid 509172:tid 509352] [client 45.95.232.35:43685] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.95.232.35, id=apPlEJwMiz5K1he2Fnn1VQAAAb8
[Sun Aug 30 03:08:48.304453 2026] [qos:error] [pid 507246:tid 507437] [client 109.72.55.69:51486] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=109.72.55.69, id=apPlEO8CsCvw81e_I2pSvAAAAtY
[Sun Aug 30 03:08:48.305059 2026] [qos:error] [pid 509172:tid 509358] [client 165.0.69.116:60677] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=165.0.69.116, id=apPlEJwMiz5K1he2Fnn1VgAAAcU
[Sun Aug 30 03:08:48.306885 2026] [qos:error] [pid 509915:tid 510074] [client 43.109.48.179:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlEM2gn1q0xw8Wp-TJiwAABU4
[Sun Aug 30 03:08:48.306896 2026] [qos:error] [pid 509915:tid 510068] [client 82.157.11.124:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.44, id=apPlEM2gn1q0xw8Wp-TJkAAABUg
[Sun Aug 30 03:08:48.307199 2026] [authz_core:error] [pid 509915:tid 510160] [client 66.249.66.37:47194] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:48.307661 2026] [authz_core:error] [pid 509915:tid 510160] [client 66.249.66.37:47194] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:48.307672 2026] [qos:error] [pid 509915:tid 510064] [client 192.255.201.184:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.44, id=apPlEM2gn1q0xw8Wp-TJmAAABUQ
[Sun Aug 30 03:08:48.307699 2026] [qos:error] [pid 509915:tid 510082] [client 185.42.192.218:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=50.6.92.44, id=apPlEM2gn1q0xw8Wp-TJlgAABVY
[Sun Aug 30 03:08:48.307859 2026] [qos:error] [pid 509915:tid 510072] [client 45.173.12.103:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.44, id=apPlEM2gn1q0xw8Wp-TJmwAABUw
[Sun Aug 30 03:08:48.309637 2026] [security2:error] [pid 509915:tid 510058] [client 68.155.159.216:62039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apPlEM2gn1q0xw8Wp-TJ8AAABT4"]
[Sun Aug 30 03:08:48.316232 2026] [authz_core:error] [pid 509915:tid 510066] [client 66.249.66.204:56803] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:48.316749 2026] [authz_core:error] [pid 509915:tid 510066] [client 66.249.66.204:56803] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:48.317018 2026] [qos:error] [pid 509172:tid 509399] [client 46.23.63.34:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlEJwMiz5K1he2Fnn1WAAAAe4
[Sun Aug 30 03:08:48.317037 2026] [qos:error] [pid 507246:tid 507444] [client 182.48.71.10:60056] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=182.48.71.10, id=apPlEO8CsCvw81e_I2pSvwAAAt0
[Sun Aug 30 03:08:48.335775 2026] [authz_core:error] [pid 509172:tid 509365] [client 216.73.216.128:28214] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:48.336233 2026] [authz_core:error] [pid 509172:tid 509365] [client 216.73.216.128:28214] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:48.339342 2026] [security2:error] [pid 509915:tid 510057] [client 52.139.37.240:37040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/txets.php"] [unique_id "apPlEM2gn1q0xw8Wp-TKDAAABT0"]
[Sun Aug 30 03:08:48.365932 2026] [security2:error] [pid 509915:tid 510073] [client 20.104.18.15:1859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/new.php"] [unique_id "apPlEM2gn1q0xw8Wp-TKFQAABU0"]
[Sun Aug 30 03:08:48.394630 2026] [security2:error] [pid 509172:tid 509393] [client 20.104.18.15:18373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/info.php/new.php"] [unique_id "apPlEJwMiz5K1he2Fnn1bgAAAeg"]
[Sun Aug 30 03:08:48.406489 2026] [security2:error] [pid 509915:tid 510131] [client 20.63.81.20:52723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp-includes/interactivity-api/flower.php"] [unique_id "apPlEM2gn1q0xw8Wp-TKQQAABYc"]
[Sun Aug 30 03:08:48.416026 2026] [security2:error] [pid 509915:tid 510172] [client 20.104.50.220:47096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-freya.php"] [unique_id "apPlEM2gn1q0xw8Wp-TKSAAABbA"]
[Sun Aug 30 03:08:48.424777 2026] [security2:error] [pid 509915:tid 510054] [client 158.158.54.35:6521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/admin-header.php"] [unique_id "apPlEM2gn1q0xw8Wp-TKTQAABTo"]
[Sun Aug 30 03:08:48.435089 2026] [security2:error] [pid 509915:tid 510056] [client 216.252.238.225:45522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.238.252.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "flashflooring.co.uk"] [uri "/wp-login.php"] [unique_id "apPlEM2gn1q0xw8Wp-TKQwAABTw"]
[Sun Aug 30 03:08:48.438714 2026] [authz_core:error] [pid 507246:tid 507401] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:48.439013 2026] [authz_core:error] [pid 507246:tid 507401] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:48.446046 2026] [security2:error] [pid 507246:tid 507471] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/service/.env"] [unique_id "apPlEO8CsCvw81e_I2pSzgAAAvg"]
[Sun Aug 30 03:08:48.447483 2026] [security2:error] [pid 509172:tid 509387] [client 20.104.18.15:34563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/htio.php"] [unique_id "apPlEJwMiz5K1he2Fnn1gwAAAeI"]
[Sun Aug 30 03:08:48.449214 2026] [security2:error] [pid 509172:tid 509418] [client 20.48.250.41:61309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlEJwMiz5K1he2Fnn1hwAAAgE"]
[Sun Aug 30 03:08:48.455769 2026] [security2:error] [pid 507246:tid 507463] [client 20.104.50.220:56714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/codrs.php"] [unique_id "apPlEO8CsCvw81e_I2pS0gAAAvA"]
[Sun Aug 30 03:08:48.481175 2026] [security2:error] [pid 509172:tid 509319] [client 20.104.50.220:5570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/backup/wp-admin/install.php"] [unique_id "apPlEJwMiz5K1he2Fnn1mAAAAZ4"]
[Sun Aug 30 03:08:48.481370 2026] [security2:error] [pid 507246:tid 507432] [client 4.205.62.107:25877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/a1vx.php"] [unique_id "apPlEO8CsCvw81e_I2pS4AAAAtE"]
[Sun Aug 30 03:08:48.500711 2026] [authz_core:error] [pid 507246:tid 507498] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:48.501009 2026] [authz_core:error] [pid 507246:tid 507498] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:48.509677 2026] [security2:error] [pid 507246:tid 507426] [client 20.151.200.44:45970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/Contrller.php"] [unique_id "apPlEO8CsCvw81e_I2pS8wAAAss"]
[Sun Aug 30 03:08:48.510317 2026] [authz_core:error] [pid 507246:tid 507400] [client 216.73.216.128:1805] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:48.510683 2026] [authz_core:error] [pid 507246:tid 507400] [client 216.73.216.128:1805] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:48.517140 2026] [security2:error] [pid 509915:tid 510077] [client 74.248.24.12:7565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/essexec.php"] [unique_id "apPlEM2gn1q0xw8Wp-TKdAAABVE"]
[Sun Aug 30 03:08:48.523709 2026] [security2:error] [pid 509915:tid 510069] [client 20.48.251.3:44399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/aws_keys.php"] [unique_id "apPlEM2gn1q0xw8Wp-TKdwAABUk"]
[Sun Aug 30 03:08:48.531749 2026] [security2:error] [pid 507246:tid 507494] [client 20.63.81.20:52361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/xcc.php"] [unique_id "apPlEO8CsCvw81e_I2pS-gAAAw8"]
[Sun Aug 30 03:08:48.545444 2026] [security2:error] [pid 507246:tid 507430] [client 52.139.37.240:37831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/wp-admin.php"] [unique_id "apPlEO8CsCvw81e_I2pTBgAAAs8"]
[Sun Aug 30 03:08:48.575174 2026] [security2:error] [pid 509915:tid 510156] [client 20.104.18.15:43975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/222.php"] [unique_id "apPlEM2gn1q0xw8Wp-TKjQAABaA"]
[Sun Aug 30 03:08:48.586179 2026] [security2:error] [pid 509915:tid 510151] [client 20.48.250.41:61271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlEM2gn1q0xw8Wp-TKjwAABZs"]
[Sun Aug 30 03:08:48.617728 2026] [security2:error] [pid 507246:tid 507397] [client 20.151.200.44:59467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/im.php"] [unique_id "apPlEO8CsCvw81e_I2pTJgAAAq4"]
[Sun Aug 30 03:08:48.619360 2026] [security2:error] [pid 507246:tid 507467] [client 20.104.50.220:62003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/simple_cmd.php"] [unique_id "apPlEO8CsCvw81e_I2pTJwAAAvQ"]
[Sun Aug 30 03:08:48.626842 2026] [security2:error] [pid 507246:tid 507450] [client 20.48.251.3:64471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/saml.php"] [unique_id "apPlEO8CsCvw81e_I2pTLAAAAuM"]
[Sun Aug 30 03:08:48.637704 2026] [security2:error] [pid 509915:tid 510114] [client 20.104.18.15:23389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/wp_blog_footer.php"] [unique_id "apPlEM2gn1q0xw8Wp-TKmQAABXY"]
[Sun Aug 30 03:08:48.663066 2026] [security2:error] [pid 509172:tid 509414] [client 20.63.81.20:52715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp-includes/Text/Diff/Engine/aaa.php"] [unique_id "apPlEJwMiz5K1he2Fnn1yQAAAf0"]
[Sun Aug 30 03:08:48.676020 2026] [security2:error] [pid 507246:tid 507402] [client 20.104.50.220:29130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/xl33t.php"] [unique_id "apPlEO8CsCvw81e_I2pTRAAAArM"]
[Sun Aug 30 03:08:48.679314 2026] [security2:error] [pid 507246:tid 507390] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/api/v3/.env"] [unique_id "apPlEO8CsCvw81e_I2pTRwAAAqc"]
[Sun Aug 30 03:08:48.713929 2026] [security2:error] [pid 507246:tid 507498] [client 20.48.250.41:61217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/ff1.php"] [unique_id "apPlEO8CsCvw81e_I2pTVwAAAxM"]
[Sun Aug 30 03:08:48.714253 2026] [security2:error] [pid 509172:tid 509429] [client 20.104.50.220:31928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wfile.php"] [unique_id "apPlEJwMiz5K1he2Fnn10wAAAgw"]
[Sun Aug 30 03:08:48.724739 2026] [security2:error] [pid 507246:tid 507450] [client 20.104.50.220:33030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/Sh3ll.php"] [unique_id "apPlEO8CsCvw81e_I2pTXQAAAuM"]
[Sun Aug 30 03:08:48.728748 2026] [authz_core:error] [pid 507246:tid 507422] [client 66.249.66.198:50541] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:48.729447 2026] [authz_core:error] [pid 507246:tid 507422] [client 66.249.66.198:50541] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:48.729616 2026] [security2:error] [pid 509915:tid 510136] [client 20.104.50.220:64455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/web-setting.php"] [unique_id "apPlEM2gn1q0xw8Wp-TKuQAABYw"]
[Sun Aug 30 03:08:48.745128 2026] [security2:error] [pid 509172:tid 509382] [client 20.104.49.130:63544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/chosen.php"] [unique_id "apPlEJwMiz5K1he2Fnn14gAAAd0"]
[Sun Aug 30 03:08:48.769385 2026] [security2:error] [pid 509915:tid 510059] [client 20.151.200.44:47062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPlEM2gn1q0xw8Wp-TKwgAABT8"]
[Sun Aug 30 03:08:48.806595 2026] [security2:error] [pid 509172:tid 509373] [client 20.63.81.20:52373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp-includes/style-engine/gecko-new.php"] [unique_id "apPlEJwMiz5K1he2Fnn1-AAAAdQ"]
[Sun Aug 30 03:08:48.821748 2026] [authz_core:error] [pid 509172:tid 509410] [client 66.249.66.192:62585] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:48.822274 2026] [authz_core:error] [pid 509172:tid 509410] [client 66.249.66.192:62585] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:48.822436 2026] [authz_core:error] [pid 507246:tid 507378] [client 66.249.66.200:48685] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:48.822705 2026] [authz_core:error] [pid 507246:tid 507378] [client 66.249.66.200:48685] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:48.836741 2026] [security2:error] [pid 509172:tid 509378] [client 20.48.251.3:14012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/sdsa.php"] [unique_id "apPlEJwMiz5K1he2Fnn2EQAAAdk"]
[Sun Aug 30 03:08:48.846475 2026] [security2:error] [pid 509915:tid 510160] [client 20.48.250.41:61209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/t.php"] [unique_id "apPlEM2gn1q0xw8Wp-TK5wAABaQ"]
[Sun Aug 30 03:08:48.860726 2026] [security2:error] [pid 509915:tid 510097] [client 20.104.50.220:17255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/file.php"] [unique_id "apPlEM2gn1q0xw8Wp-TK8wAABWU"]
[Sun Aug 30 03:08:48.876370 2026] [autoindex:error] [pid 509915:tid 510111] [client 52.139.37.240:37014] AH01276: Cannot serve directory /home3/matthew/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:08:48.878332 2026] [security2:error] [pid 509915:tid 510140] [client 20.48.251.3:59312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/X57.php"] [unique_id "apPlEM2gn1q0xw8Wp-TLAwAABZA"]
[Sun Aug 30 03:08:48.883353 2026] [authz_core:error] [pid 509172:tid 509305] [client 216.73.216.128:28214] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:48.883862 2026] [authz_core:error] [pid 509172:tid 509305] [client 216.73.216.128:28214] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:48.916606 2026] [security2:error] [pid 507246:tid 507478] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/api/dev/.env"] [unique_id "apPlEO8CsCvw81e_I2pToQAAAv8"]
[Sun Aug 30 03:08:48.925183 2026] [security2:error] [pid 509915:tid 510079] [client 158.158.54.35:23036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/disagraep.php"] [unique_id "apPlEM2gn1q0xw8Wp-TLFwAABVM"]
[Sun Aug 30 03:08:48.938016 2026] [security2:error] [pid 509915:tid 510140] [client 20.63.81.20:52384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp-settings.php"] [unique_id "apPlEM2gn1q0xw8Wp-TLHgAABZA"]
[Sun Aug 30 03:08:48.938783 2026] [authz_core:error] [pid 507246:tid 507469] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:48.939231 2026] [authz_core:error] [pid 507246:tid 507469] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:48.939460 2026] [authz_core:error] [pid 509915:tid 510101] [client 66.249.66.69:35001] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:48.939796 2026] [authz_core:error] [pid 509915:tid 510101] [client 66.249.66.69:35001] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:48.967132 2026] [authz_core:error] [pid 507246:tid 507485] [client 216.73.216.128:1805] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:48.967565 2026] [authz_core:error] [pid 507246:tid 507485] [client 216.73.216.128:1805] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:48.983640 2026] [security2:error] [pid 507246:tid 507498] [client 20.48.250.41:61304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/erty.php"] [unique_id "apPlEO8CsCvw81e_I2pTxwAAAxM"]
[Sun Aug 30 03:08:48.991407 2026] [security2:error] [pid 507246:tid 507389] [client 4.205.62.107:22961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/dd.php"] [unique_id "apPlEO8CsCvw81e_I2pTzAAAAqY"]
[Sun Aug 30 03:08:49.044040 2026] [security2:error] [pid 509915:tid 510072] [client 74.248.24.12:7519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/gecko-new.php.1"] [unique_id "apPlEc2gn1q0xw8Wp-TLQwAABUw"]
[Sun Aug 30 03:08:49.069179 2026] [security2:error] [pid 509172:tid 509386] [client 20.63.81.20:52401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp-signup.php"] [unique_id "apPlEZwMiz5K1he2Fnn2ggAAAeE"]
[Sun Aug 30 03:08:49.114924 2026] [security2:error] [pid 507246:tid 507426] [client 20.48.250.41:60492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/0x.php"] [unique_id "apPlEe8CsCvw81e_I2pUEgAAAss"]
[Sun Aug 30 03:08:49.127774 2026] [authz_core:error] [pid 509172:tid 509402] [client 66.249.66.76:56696] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:49.128198 2026] [authz_core:error] [pid 509172:tid 509402] [client 66.249.66.76:56696] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:49.165206 2026] [security2:error] [pid 507246:tid 507477] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/api/staging/.env"] [unique_id "apPlEe8CsCvw81e_I2pUHQAAAv4"]
[Sun Aug 30 03:08:49.196765 2026] [security2:error] [pid 507246:tid 507413] [client 20.63.81.20:52379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp-conffg.php"] [unique_id "apPlEe8CsCvw81e_I2pUMgAAAr4"]
[Sun Aug 30 03:08:49.238310 2026] [authz_core:error] [pid 509172:tid 509366] [client 216.73.216.128:28214] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:49.238605 2026] [authz_core:error] [pid 509172:tid 509366] [client 216.73.216.128:28214] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:49.260215 2026] [security2:error] [pid 509915:tid 510088] [client 20.48.250.41:60500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/66.php"] [unique_id "apPlEc2gn1q0xw8Wp-TLcQAABVw"]
[Sun Aug 30 03:08:49.322263 2026] [security2:error] [pid 507246:tid 507477] [client 216.73.216.128:44807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlEe8CsCvw81e_I2pUYAAAAv4"]
[Sun Aug 30 03:08:49.334924 2026] [security2:error] [pid 509915:tid 510062] [client 20.63.81.20:52355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp-validate.php"] [unique_id "apPlEc2gn1q0xw8Wp-TLlgAABUI"]
[Sun Aug 30 03:08:49.374915 2026] [security2:error] [pid 509172:tid 509419] [client 68.155.159.216:55062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-admin/network/index.php"] [unique_id "apPlEZwMiz5K1he2Fnn23AAAAgI"]
[Sun Aug 30 03:08:49.394062 2026] [security2:error] [pid 509915:tid 510122] [client 20.151.200.44:47072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.blackfounderssummit.com"] [uri "/waf.php"] [unique_id "apPlEc2gn1q0xw8Wp-TLqQAABX4"]
[Sun Aug 30 03:08:49.406829 2026] [security2:error] [pid 509915:tid 510156] [client 4.205.62.107:64502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/gk.php"] [unique_id "apPlEc2gn1q0xw8Wp-TLqwAABaA"]
[Sun Aug 30 03:08:49.407132 2026] [security2:error] [pid 509915:tid 510109] [client 20.48.251.3:59849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlEc2gn1q0xw8Wp-TLrAAABXE"]
[Sun Aug 30 03:08:49.407886 2026] [security2:error] [pid 507246:tid 507407] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/vendor/.env"] [unique_id "apPlEe8CsCvw81e_I2pUbAAAArg"]
[Sun Aug 30 03:08:49.413363 2026] [security2:error] [pid 509915:tid 510152] [client 20.48.250.41:61272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/f35.php"] [unique_id "apPlEc2gn1q0xw8Wp-TLsAAABZw"]
[Sun Aug 30 03:08:49.419809 2026] [authz_core:error] [pid 507246:tid 507403] [client 216.73.216.128:1805] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:49.420100 2026] [authz_core:error] [pid 507246:tid 507403] [client 216.73.216.128:1805] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:49.421518 2026] [security2:error] [pid 509915:tid 510047] [client 68.155.159.216:61415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apPlEc2gn1q0xw8Wp-TLswAABTM"]
[Sun Aug 30 03:08:49.437764 2026] [authz_core:error] [pid 507246:tid 507468] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:49.438119 2026] [authz_core:error] [pid 507246:tid 507468] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:49.445536 2026] [security2:error] [pid 509172:tid 509377] [client 20.104.49.130:60612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/tiny2.php"] [unique_id "apPlEZwMiz5K1he2Fnn2-gAAAdg"]
[Sun Aug 30 03:08:49.449219 2026] [security2:error] [pid 509172:tid 509359] [client 20.104.18.15:35171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/simple.php"] [unique_id "apPlEZwMiz5K1he2Fnn2_wAAAcY"]
[Sun Aug 30 03:08:49.458448 2026] [core:alert] [pid 509172:tid 509222] [remote 52.167.144.204:38093] /home3/lordrcan/public_html/.htaccess: without matching section
[Sun Aug 30 03:08:49.460798 2026] [authz_core:error] [pid 509172:tid 509398] [client 66.249.66.42:52349] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:49.461266 2026] [authz_core:error] [pid 509172:tid 509398] [client 66.249.66.42:52349] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:49.462413 2026] [security2:error] [pid 509915:tid 510077] [client 20.63.81.20:52389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/700.php"] [unique_id "apPlEc2gn1q0xw8Wp-TLzQAABVE"]
[Sun Aug 30 03:08:49.462861 2026] [security2:error] [pid 509915:tid 510104] [client 158.158.54.35:20334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/v4.php"] [unique_id "apPlEc2gn1q0xw8Wp-TLzgAABWw"]
[Sun Aug 30 03:08:49.465862 2026] [security2:error] [pid 509172:tid 509311] [client 20.151.200.44:46025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/file66.php"] [unique_id "apPlEZwMiz5K1he2Fnn3DAAAAZY"]
[Sun Aug 30 03:08:49.497507 2026] [security2:error] [pid 509172:tid 509309] [client 4.205.62.107:36654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/ws79.php"] [unique_id "apPlEZwMiz5K1he2Fnn3JAAAAZQ"]
[Sun Aug 30 03:08:49.502559 2026] [security2:error] [pid 509172:tid 509355] [client 20.104.18.15:1923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/vpn.php"] [unique_id "apPlEZwMiz5K1he2Fnn3KgAAAcI"]
[Sun Aug 30 03:08:49.548109 2026] [security2:error] [pid 509915:tid 510075] [client 20.48.250.41:61303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/wen.php"] [unique_id "apPlEc2gn1q0xw8Wp-TL4QAABU8"]
[Sun Aug 30 03:08:49.548933 2026] [security2:error] [pid 507246:tid 507485] [client 20.104.50.220:46863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/X7x.php"] [unique_id "apPlEe8CsCvw81e_I2pUsQAAAwY"]
[Sun Aug 30 03:08:49.554298 2026] [autoindex:error] [pid 509915:tid 510085] [client 20.104.18.15:18423] AH01276: Cannot serve directory /home4/jung39/public_html/platinumsnowremoval.com/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:08:49.563183 2026] [security2:error] [pid 509172:tid 509365] [client 74.248.24.12:6850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/disagraeed.php"] [unique_id "apPlEZwMiz5K1he2Fnn3TgAAAcw"]
[Sun Aug 30 03:08:49.594436 2026] [security2:error] [pid 507246:tid 507417] [client 20.63.81.20:52414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/c4.php"] [unique_id "apPlEe8CsCvw81e_I2pUwAAAAsI"]
[Sun Aug 30 03:08:49.602594 2026] [security2:error] [pid 507246:tid 507409] [client 20.104.50.220:42471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/jingan.php"] [unique_id "apPlEe8CsCvw81e_I2pUxgAAAro"]
[Sun Aug 30 03:08:49.605283 2026] [security2:error] [pid 507246:tid 507402] [client 20.104.18.15:34661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/dev.php"] [unique_id "apPlEe8CsCvw81e_I2pUxwAAArM"]
[Sun Aug 30 03:08:49.622877 2026] [security2:error] [pid 507246:tid 507449] [client 195.178.110.247:10634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mediacoalitionfoundation.org"] [uri "/index.php"] [unique_id "apPlEe8CsCvw81e_I2pUzgAAAuI"]
[Sun Aug 30 03:08:49.627554 2026] [security2:error] [pid 509915:tid 510119] [client 20.104.50.220:5234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/h.php"] [unique_id "apPlEc2gn1q0xw8Wp-TL6wAABXs"]
[Sun Aug 30 03:08:49.636242 2026] [security2:error] [pid 507246:tid 507477] [client 4.205.62.107:25765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/public/vx.php"] [unique_id "apPlEe8CsCvw81e_I2pU1AAAAv4"]
[Sun Aug 30 03:08:49.645703 2026] [security2:error] [pid 509915:tid 510079] [client 20.104.18.15:18423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/w.php"] [unique_id "apPlEc2gn1q0xw8Wp-TL7QAABVM"]
[Sun Aug 30 03:08:49.649779 2026] [authz_core:error] [pid 509172:tid 509373] [client 66.249.66.76:50257] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:49.650252 2026] [authz_core:error] [pid 509172:tid 509373] [client 66.249.66.76:50257] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:49.660764 2026] [security2:error] [pid 509172:tid 509412] [client 20.48.251.3:44348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/umgebung.php"] [unique_id "apPlEZwMiz5K1he2Fnn3aAAAAfs"]
[Sun Aug 30 03:08:49.667021 2026] [security2:error] [pid 507246:tid 507378] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/lib/.env"] [unique_id "apPlEe8CsCvw81e_I2pU3gAAAps"]
[Sun Aug 30 03:08:49.674099 2026] [security2:error] [pid 509172:tid 509372] [client 68.155.159.216:45975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/xmlrpc.php"] [unique_id "apPlEZwMiz5K1he2Fnn3bgAAAdM"]
[Sun Aug 30 03:08:49.676674 2026] [security2:error] [pid 507246:tid 507480] [client 20.48.250.41:61253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/inc.php"] [unique_id "apPlEe8CsCvw81e_I2pU5AAAAwE"]
[Sun Aug 30 03:08:49.695119 2026] [authz_core:error] [pid 507246:tid 507426] [client 216.73.216.128:1805] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:49.695498 2026] [authz_core:error] [pid 507246:tid 507426] [client 216.73.216.128:1805] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:49.704074 2026] [authz_core:error] [pid 507246:tid 507471] [client 66.249.66.44:51124] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:49.704577 2026] [authz_core:error] [pid 507246:tid 507471] [client 66.249.66.44:51124] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:49.728044 2026] [security2:error] [pid 507246:tid 507450] [client 20.63.81.20:52381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp-tymanage.php"] [unique_id "apPlEe8CsCvw81e_I2pU-gAAAuM"]
[Sun Aug 30 03:08:49.766003 2026] [security2:error] [pid 509915:tid 510154] [client 20.104.18.15:43327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/key.php"] [unique_id "apPlEc2gn1q0xw8Wp-TL_QAABZ4"]
[Sun Aug 30 03:08:49.782124 2026] [security2:error] [pid 507246:tid 507460] [client 195.178.110.247:58334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mediacoalitionfoundation.org"] [uri "/index.php"] [unique_id "apPlEe8CsCvw81e_I2pVFQAAAu0"]
[Sun Aug 30 03:08:49.786903 2026] [security2:error] [pid 509172:tid 509381] [client 20.104.50.220:61666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/alpa.php"] [unique_id "apPlEZwMiz5K1he2Fnn3pQAAAdw"]
[Sun Aug 30 03:08:49.793784 2026] [security2:error] [pid 509172:tid 509308] [client 20.104.18.15:23418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/sushi.php"] [unique_id "apPlEZwMiz5K1he2Fnn3qQAAAZM"]
[Sun Aug 30 03:08:49.800483 2026] [security2:error] [pid 509172:tid 509321] [client 20.151.200.44:57090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/file.php"] [unique_id "apPlEZwMiz5K1he2Fnn3sgAAAaA"]
[Sun Aug 30 03:08:49.805231 2026] [security2:error] [pid 509172:tid 509425] [client 20.48.250.41:61260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/6bcwiqwj.php"] [unique_id "apPlEZwMiz5K1he2Fnn3tAAAAgg"]
[Sun Aug 30 03:08:49.827967 2026] [security2:error] [pid 509915:tid 510122] [client 20.104.50.220:29180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/1n73ct10n.php"] [unique_id "apPlEc2gn1q0xw8Wp-TMCQAABX4"]
[Sun Aug 30 03:08:49.851566 2026] [security2:error] [pid 509172:tid 509391] [client 20.104.50.220:32124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/class20.php"] [unique_id "apPlEZwMiz5K1he2Fnn31gAAAeY"]
[Sun Aug 30 03:08:49.853809 2026] [security2:error] [pid 509172:tid 509381] [client 20.63.81.20:52407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/ajfto.php"] [unique_id "apPlEZwMiz5K1he2Fnn32AAAAdw"]
[Sun Aug 30 03:08:49.865033 2026] [security2:error] [pid 509172:tid 509340] [client 20.104.50.220:33036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/new.php"] [unique_id "apPlEZwMiz5K1he2Fnn35QAAAbM"]
[Sun Aug 30 03:08:49.880128 2026] [security2:error] [pid 509915:tid 510052] [client 20.104.50.220:29597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-ettoyag.php"] [unique_id "apPlEc2gn1q0xw8Wp-TMGgAABTg"]
[Sun Aug 30 03:08:49.889289 2026] [authz_core:error] [pid 507246:tid 507500] [client 66.249.66.194:34780] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:49.889815 2026] [authz_core:error] [pid 507246:tid 507500] [client 66.249.66.194:34780] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:49.928429 2026] [security2:error] [pid 507246:tid 507486] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/resources/.env"] [unique_id "apPlEe8CsCvw81e_I2pVWAAAAwc"]
[Sun Aug 30 03:08:49.929446 2026] [security2:error] [pid 509172:tid 509314] [client 158.158.54.35:27219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/1index.php"] [unique_id "apPlEZwMiz5K1he2Fnn4DQAAAZk"]
[Sun Aug 30 03:08:49.931492 2026] [authz_core:error] [pid 507246:tid 507422] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:49.933440 2026] [authz_core:error] [pid 507246:tid 507422] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:49.951622 2026] [security2:error] [pid 509172:tid 509332] [client 20.48.250.41:61206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/easy.php"] [unique_id "apPlEZwMiz5K1he2Fnn4FQAAAas"]
[Sun Aug 30 03:08:49.980871 2026] [security2:error] [pid 509172:tid 509359] [client 20.63.81.20:52675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp_KwIW0U5F.php"] [unique_id "apPlEZwMiz5K1he2Fnn4JQAAAcY"]
[Sun Aug 30 03:08:49.983181 2026] [security2:error] [pid 509172:tid 509317] [client 20.48.251.3:60518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/sale.php"] [unique_id "apPlEZwMiz5K1he2Fnn4JwAAAZw"]
[Sun Aug 30 03:08:49.989235 2026] [authz_core:error] [pid 507246:tid 507436] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:49.989723 2026] [authz_core:error] [pid 507246:tid 507436] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:49.993297 2026] [security2:error] [pid 509172:tid 509349] [client 20.104.50.220:16758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/cfile.php"] [unique_id "apPlEZwMiz5K1he2Fnn4MQAAAbw"]
[Sun Aug 30 03:08:50.005513 2026] [authz_core:error] [pid 509172:tid 509366] [client 66.249.66.77:41757] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:50.006001 2026] [authz_core:error] [pid 509172:tid 509366] [client 66.249.66.77:41757] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:50.012226 2026] [security2:error] [pid 509172:tid 509390] [client 20.151.200.44:46042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/blnux.php"] [unique_id "apPlEpwMiz5K1he2Fnn4OQAAAeU"]
[Sun Aug 30 03:08:50.015359 2026] [security2:error] [pid 509915:tid 510103] [client 20.48.251.3:64485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/aws_settings.php"] [unique_id "apPlEs2gn1q0xw8Wp-TMXQAABWs"]
[Sun Aug 30 03:08:50.052615 2026] [security2:error] [pid 509915:tid 510123] [client 20.48.251.3:59309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/register.php"] [unique_id "apPlEs2gn1q0xw8Wp-TMcQAABX8"]
[Sun Aug 30 03:08:50.052905 2026] [security2:error] [pid 509915:tid 510168] [client 52.139.37.240:37014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/wp-config-sample.php"] [unique_id "apPlEs2gn1q0xw8Wp-TMewAABaw"]
[Sun Aug 30 03:08:50.074931 2026] [authz_core:error] [pid 509915:tid 510114] [client 66.249.66.70:46070] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:50.075409 2026] [authz_core:error] [pid 509915:tid 510114] [client 66.249.66.70:46070] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:50.077055 2026] [security2:error] [pid 509915:tid 510130] [client 74.248.24.12:12189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/class-IXR-encryption.php"] [unique_id "apPlEs2gn1q0xw8Wp-TMjwAABYY"]
[Sun Aug 30 03:08:50.098722 2026] [security2:error] [pid 509915:tid 510141] [client 20.48.250.41:61301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/fresh3.php"] [unique_id "apPlEs2gn1q0xw8Wp-TMqQAABZE"]
[Sun Aug 30 03:08:50.107512 2026] [security2:error] [pid 509915:tid 510165] [client 20.63.81.20:52733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp_xiPu52Ut.php"] [unique_id "apPlEs2gn1q0xw8Wp-TMtgAABak"]
[Sun Aug 30 03:08:50.146953 2026] [security2:error] [pid 509915:tid 510170] [client 4.205.62.107:22534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/wp-tem.php"] [unique_id "apPlEs2gn1q0xw8Wp-TMwAAABa4"]
[Sun Aug 30 03:08:50.175082 2026] [security2:error] [pid 507246:tid 507491] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/assets/.env"] [unique_id "apPlEu8CsCvw81e_I2pVkwAAAww"]
[Sun Aug 30 03:08:50.225803 2026] [security2:error] [pid 509915:tid 510089] [client 20.48.250.41:61310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/bgymj.php"] [unique_id "apPlEs2gn1q0xw8Wp-TM7QAABV0"]
[Sun Aug 30 03:08:50.234357 2026] [security2:error] [pid 509915:tid 510092] [client 20.63.81.20:52692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp_n5VD7XDh.php"] [unique_id "apPlEs2gn1q0xw8Wp-TM9AAABWA"]
[Sun Aug 30 03:08:50.250495 2026] [security2:error] [pid 509915:tid 510081] [client 52.139.37.240:37882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onesprayaway.com"] [uri "/wp-content/packed.php"] [unique_id "apPlEs2gn1q0xw8Wp-TM_QAABVU"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:50.305189 2026] [authz_core:error] [pid 507246:tid 507471] [client 66.249.66.32:46784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:50.305677 2026] [authz_core:error] [pid 507246:tid 507471] [client 66.249.66.32:46784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:50.310279 2026] [authz_core:error] [pid 509915:tid 510147] [client 66.249.66.43:64008] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:50.310760 2026] [authz_core:error] [pid 509915:tid 510147] [client 66.249.66.43:64008] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:50.362708 2026] [security2:error] [pid 509915:tid 510153] [client 20.63.81.20:52365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp-mini.php"] [unique_id "apPlEs2gn1q0xw8Wp-TNLQAABZ0"]
[Sun Aug 30 03:08:50.370880 2026] [security2:error] [pid 509915:tid 510090] [client 158.158.54.35:9599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/exif.php"] [unique_id "apPlEs2gn1q0xw8Wp-TNMgAABV4"]
[Sun Aug 30 03:08:50.373891 2026] [security2:error] [pid 509915:tid 510152] [client 20.48.250.41:61258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/ws69.php"] [unique_id "apPlEs2gn1q0xw8Wp-TNNwAABZw"]
[Sun Aug 30 03:08:50.422587 2026] [security2:error] [pid 507246:tid 507410] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/uploads/.env"] [unique_id "apPlEu8CsCvw81e_I2pVzAAAArs"]
[Sun Aug 30 03:08:50.484084 2026] [authz_core:error] [pid 507246:tid 507466] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:50.484571 2026] [authz_core:error] [pid 507246:tid 507466] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:08:50.492939 2026] [security2:error] [pid 509172:tid 509341] [client 20.63.81.20:52412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/xmini4.php"] [unique_id "apPlEpwMiz5K1he2Fnn48wAAAbQ"]
[Sun Aug 30 03:08:50.501927 2026] [autoindex:error] [pid 509915:tid 510099] [client 52.139.37.240:0] AH01276: Cannot serve directory /home3/matthew/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:08:50.515320 2026] [security2:error] [pid 509915:tid 510106] [client 68.155.159.216:54465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apPlEs2gn1q0xw8Wp-TNwQAABW4"]
[Sun Aug 30 03:08:50.521403 2026] [security2:error] [pid 509915:tid 510054] [client 20.48.250.41:61267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/ccs.php"] [unique_id "apPlEs2gn1q0xw8Wp-TNxwAABTo"]
[Sun Aug 30 03:08:50.530778 2026] [authz_core:error] [pid 507246:tid 507395] [client 66.249.66.75:47025] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:50.531230 2026] [authz_core:error] [pid 507246:tid 507395] [client 66.249.66.75:47025] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:50.536355 2026] [security2:error] [pid 509915:tid 510118] [client 4.205.62.107:17286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlEs2gn1q0xw8Wp-TN0QAABXo"]
[Sun Aug 30 03:08:50.552896 2026] [security2:error] [pid 509915:tid 510161] [client 68.155.159.216:61430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apPlEs2gn1q0xw8Wp-TN4wAABaU"]
[Sun Aug 30 03:08:50.559115 2026] [security2:error] [pid 509915:tid 510122] [client 20.48.251.3:59473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/cloud.php"] [unique_id "apPlEs2gn1q0xw8Wp-TN6gAABX4"]
[Sun Aug 30 03:08:50.560076 2026] [security2:error] [pid 509915:tid 510122] [client 4.205.62.107:61761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/god.php"] [unique_id "apPlEs2gn1q0xw8Wp-TN6wAABX4"]
[Sun Aug 30 03:08:50.591118 2026] [security2:error] [pid 509915:tid 510132] [client 74.248.24.12:5775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/cache-base.php"] [unique_id "apPlEs2gn1q0xw8Wp-TN-gAABYg"]
[Sun Aug 30 03:08:50.601374 2026] [security2:error] [pid 509915:tid 510166] [client 20.104.18.15:35160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/xty.php"] [unique_id "apPlEs2gn1q0xw8Wp-TN_AAABao"]
[Sun Aug 30 03:08:50.621679 2026] [security2:error] [pid 507246:tid 507499] [client 20.63.81.20:52710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/reop3.php"] [unique_id "apPlEu8CsCvw81e_I2pWBgAAAxQ"]
[Sun Aug 30 03:08:50.640313 2026] [security2:error] [pid 507246:tid 507415] [client 20.104.18.15:1989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/goods.php"] [unique_id "apPlEu8CsCvw81e_I2pWEQAAAsA"]
[Sun Aug 30 03:08:50.652148 2026] [security2:error] [pid 509172:tid 509422] [client 20.48.250.41:61192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/mar.php"] [unique_id "apPlEpwMiz5K1he2Fnn5NQAAAgU"]
[Sun Aug 30 03:08:50.667615 2026] [security2:error] [pid 507246:tid 507418] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/internal/.env"] [unique_id "apPlEu8CsCvw81e_I2pWHAAAAsM"]
[Sun Aug 30 03:08:50.671804 2026] [authz_core:error] [pid 509172:tid 509413] [client 66.249.66.195:57406] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:50.672276 2026] [authz_core:error] [pid 509172:tid 509413] [client 66.249.66.195:57406] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:50.686767 2026] [security2:error] [pid 509172:tid 509351] [client 20.104.50.220:46630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/admir.php"] [unique_id "apPlEpwMiz5K1he2Fnn5QwAAAb4"]
[Sun Aug 30 03:08:50.745596 2026] [security2:error] [pid 507246:tid 507384] [client 20.104.18.15:34736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/gos.php"] [unique_id "apPlEu8CsCvw81e_I2pWQgAAAqE"]
[Sun Aug 30 03:08:50.749237 2026] [security2:error] [pid 509172:tid 509350] [client 20.104.50.220:42804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/chan.php"] [unique_id "apPlEpwMiz5K1he2Fnn5bAAAAb0"]
[Sun Aug 30 03:08:50.752837 2026] [security2:error] [pid 507246:tid 507396] [client 20.63.81.20:52724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp-mail.php"] [unique_id "apPlEu8CsCvw81e_I2pWSQAAAq0"]
[Sun Aug 30 03:08:50.795175 2026] [security2:error] [pid 509915:tid 510064] [client 20.104.50.220:5893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/old/wp-admin/install.php"] [unique_id "apPlEs2gn1q0xw8Wp-TOHQAABUQ"]
[Sun Aug 30 03:08:50.796775 2026] [security2:error] [pid 509915:tid 510166] [client 20.48.250.41:61199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/ccu.php"] [unique_id "apPlEs2gn1q0xw8Wp-TOHgAABao"]
[Sun Aug 30 03:08:50.801302 2026] [security2:error] [pid 509172:tid 509388] [client 20.104.18.15:18358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/x.php"] [unique_id "apPlEpwMiz5K1he2Fnn5gwAAAeM"]
[Sun Aug 30 03:08:50.802154 2026] [security2:error] [pid 509915:tid 510102] [client 20.48.251.3:44407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/old_phpinfo.php"] [unique_id "apPlEs2gn1q0xw8Wp-TOIwAABWo"]
[Sun Aug 30 03:08:50.830417 2026] [security2:error] [pid 509915:tid 510048] [client 4.205.62.107:35975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/public/wp-blog.php"] [unique_id "apPlEs2gn1q0xw8Wp-TOPQAABTQ"]
[Sun Aug 30 03:08:50.843981 2026] [security2:error] [pid 509172:tid 509425] [client 158.158.54.35:6475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/OthioNDwMEK.php"] [unique_id "apPlEpwMiz5K1he2Fnn5ogAAAgg"]
[Sun Aug 30 03:08:50.873430 2026] [authz_core:error] [pid 507246:tid 507456] [client 66.249.66.205:54363] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:50.873867 2026] [authz_core:error] [pid 507246:tid 507456] [client 66.249.66.205:54363] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:50.881916 2026] [authz_core:error] [pid 509915:tid 510147] [client 66.249.66.41:55938] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:50.882408 2026] [authz_core:error] [pid 509915:tid 510147] [client 66.249.66.41:55938] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:50.891841 2026] [security2:error] [pid 509915:tid 510049] [client 20.63.81.20:52672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp-conffg.php"] [unique_id "apPlEs2gn1q0xw8Wp-TOaQAABTU"]
[Sun Aug 30 03:08:50.915484 2026] [security2:error] [pid 507246:tid 507394] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/tools/.env"] [unique_id "apPlEu8CsCvw81e_I2pWiAAAAqs"]
[Sun Aug 30 03:08:50.934053 2026] [security2:error] [pid 509915:tid 510107] [client 20.48.250.41:61281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/ak.php"] [unique_id "apPlEs2gn1q0xw8Wp-TOhwAABW8"]
[Sun Aug 30 03:08:50.939596 2026] [security2:error] [pid 509172:tid 509393] [client 20.104.50.220:61414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/themes/antioch/acces.php"] [unique_id "apPlEpwMiz5K1he2Fnn50AAAAeg"]
[Sun Aug 30 03:08:50.940231 2026] [security2:error] [pid 507246:tid 507440] [client 20.104.18.15:23304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/manga.php"] [unique_id "apPlEu8CsCvw81e_I2pWmQAAAtk"]
[Sun Aug 30 03:08:50.945941 2026] [security2:error] [pid 509172:tid 509312] [client 20.104.49.130:43295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/82.php"] [unique_id "apPlEpwMiz5K1he2Fnn51AAAAZc"]
[Sun Aug 30 03:08:50.961250 2026] [authz_core:error] [pid 507246:tid 507390] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:50.961545 2026] [authz_core:error] [pid 507246:tid 507390] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:50.968517 2026] [security2:error] [pid 509172:tid 509408] [client 20.104.18.15:43977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/chosen.php"] [unique_id "apPlEpwMiz5K1he2Fnn54AAAAfc"]
[Sun Aug 30 03:08:50.986829 2026] [security2:error] [pid 509172:tid 509311] [client 20.104.50.220:28690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/not_acceptable.php"] [unique_id "apPlEpwMiz5K1he2Fnn57wAAAZY"]
[Sun Aug 30 03:08:51.002957 2026] [security2:error] [pid 509172:tid 509351] [client 20.104.50.220:33046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/Sym.php"] [unique_id "apPlE5wMiz5K1he2Fnn6AgAAAb4"]
[Sun Aug 30 03:08:51.005220 2026] [security2:error] [pid 509915:tid 510087] [client 20.104.50.220:32539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/build.php"] [unique_id "apPlE82gn1q0xw8Wp-TOlgAABVs"]
[Sun Aug 30 03:08:51.018577 2026] [security2:error] [pid 509172:tid 509331] [client 20.63.81.20:52375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/filefuns.php"] [unique_id "apPlE5wMiz5K1he2Fnn6DwAAAao"]
[Sun Aug 30 03:08:51.028883 2026] [security2:error] [pid 509172:tid 509322] [client 20.104.50.220:28729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/venom.php"] [unique_id "apPlE5wMiz5K1he2Fnn6IgAAAaE"]
[Sun Aug 30 03:08:51.064837 2026] [security2:error] [pid 509915:tid 510082] [client 20.48.250.41:61278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/lib.php"] [unique_id "apPlE82gn1q0xw8Wp-TOtwAABVY"]
[Sun Aug 30 03:08:51.076109 2026] [security2:error] [pid 509915:tid 510057] [client 68.155.159.216:46064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/atomlib.php"] [unique_id "apPlE82gn1q0xw8Wp-TOwAAABT0"]
[Sun Aug 30 03:08:51.104247 2026] [security2:error] [pid 507246:tid 507450] [client 74.248.24.12:2950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/Js.php"] [unique_id "apPlE-8CsCvw81e_I2pW1AAAAuM"]
[Sun Aug 30 03:08:51.112722 2026] [security2:error] [pid 509915:tid 510116] [client 20.151.200.44:46038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/attack.php"] [unique_id "apPlE82gn1q0xw8Wp-TO1gAABXg"]
[Sun Aug 30 03:08:51.113436 2026] [security2:error] [pid 509915:tid 510161] [client 20.48.251.3:60511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/wp-class.php"] [unique_id "apPlE82gn1q0xw8Wp-TO1wAABaU"]
[Sun Aug 30 03:08:51.126938 2026] [security2:error] [pid 509915:tid 510117] [client 20.104.50.220:17216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/class-wp.php"] [unique_id "apPlE82gn1q0xw8Wp-TO3AAABXk"]
[Sun Aug 30 03:08:51.143869 2026] [security2:error] [pid 509915:tid 510137] [client 20.63.81.20:52374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp-cron.php"] [unique_id "apPlE82gn1q0xw8Wp-TO4QAABY0"]
[Sun Aug 30 03:08:51.154430 2026] [security2:error] [pid 507246:tid 507454] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/scripts/.env"] [unique_id "apPlE-8CsCvw81e_I2pW2AAAAuc"]
[Sun Aug 30 03:08:51.185384 2026] [security2:error] [pid 509915:tid 510057] [client 20.104.49.130:57696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/wp-blogs.php"] [unique_id "apPlE82gn1q0xw8Wp-TO7wAABT0"]
[Sun Aug 30 03:08:51.199048 2026] [security2:error] [pid 509915:tid 510074] [client 20.48.251.3:64487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/wp-konfig.backup.php"] [unique_id "apPlE82gn1q0xw8Wp-TO9QAABU4"]
[Sun Aug 30 03:08:51.199668 2026] [security2:error] [pid 509915:tid 510046] [client 20.48.251.3:59316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/xqq.php"] [unique_id "apPlE82gn1q0xw8Wp-TO9gAABTI"]
[Sun Aug 30 03:08:51.199961 2026] [security2:error] [pid 509915:tid 510067] [client 20.48.250.41:61211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/wp-style.php"] [unique_id "apPlE82gn1q0xw8Wp-TO9wAABUc"]
[Sun Aug 30 03:08:51.228305 2026] [security2:error] [pid 509915:tid 510106] [client 20.104.49.130:59561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/az.php"] [unique_id "apPlE82gn1q0xw8Wp-TPAQAABW4"]
[Sun Aug 30 03:08:51.229727 2026] [authz_core:error] [pid 509915:tid 510152] [client 66.249.66.204:56803] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:51.230145 2026] [authz_core:error] [pid 509915:tid 510152] [client 66.249.66.204:56803] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:51.246533 2026] [authz_core:error] [pid 509172:tid 509393] [client 66.249.66.199:45166] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:51.247027 2026] [authz_core:error] [pid 509172:tid 509393] [client 66.249.66.199:45166] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:51.272294 2026] [http2:info] [pid 510357:tid 510357] h2_workers: created with min=128 max=192 idle_ms=600000
[Sun Aug 30 03:08:51.275151 2026] [qos:error] [pid 509915:tid 510083] [client 103.157.79.9:51634] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.157.79.9, id=apPlE82gn1q0xw8Wp-TPCAAABVc
[Sun Aug 30 03:08:51.275315 2026] [qos:error] [pid 509172:tid 509405] [client 193.32.176.109:58149] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=193.32.176.109, id=apPlE5wMiz5K1he2Fnn6YQAAAfQ
[Sun Aug 30 03:08:51.276372 2026] [qos:error] [pid 509915:tid 510057] [client 190.14.147.19:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlE82gn1q0xw8Wp-TPCQAABT0
[Sun Aug 30 03:08:51.276626 2026] [security2:error] [pid 509915:tid 510072] [client 20.104.49.130:63237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/ab.php"] [unique_id "apPlE82gn1q0xw8Wp-TPCgAABUw"]
[Sun Aug 30 03:08:51.276800 2026] [security2:error] [pid 509915:tid 510106] [client 20.63.81.20:52403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/lock360.php"] [unique_id "apPlE82gn1q0xw8Wp-TPCwAABW4"]
[Sun Aug 30 03:08:51.276994 2026] [qos:error] [pid 509172:tid 509381] [client 43.156.236.238:56710] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=43.156.236.238, id=apPlE5wMiz5K1he2Fnn6YgAAAdw
[Sun Aug 30 03:08:51.277413 2026] [qos:error] [pid 509172:tid 509391] [client 58.64.160.132:41793] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=58.64.160.132, id=apPlE5wMiz5K1he2Fnn6YwAAAeY
[Sun Aug 30 03:08:51.289122 2026] [qos:error] [pid 507246:tid 507446] [client 160.187.174.186:55688] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=160.187.174.186, id=apPlE-8CsCvw81e_I2pW9gAAAt8
[Sun Aug 30 03:08:51.289168 2026] [qos:error] [pid 509172:tid 509394] [client 148.230.166.137:37240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=148.230.166.137, id=apPlE5wMiz5K1he2Fnn6ZAAAAek
[Sun Aug 30 03:08:51.289595 2026] [qos:error] [pid 509915:tid 510081] [client 159.223.52.199:47558] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=159.223.52.199, id=apPlE82gn1q0xw8Wp-TPDQAABVU
[Sun Aug 30 03:08:51.289607 2026] [qos:error] [pid 509172:tid 509368] [client 161.153.45.81:49480] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=161.153.45.81, id=apPlE5wMiz5K1he2Fnn6ZQAAAc8
[Sun Aug 30 03:08:51.290009 2026] [qos:error] [pid 509915:tid 510067] [client 45.7.64.8:37296] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=45.7.64.8, id=apPlE82gn1q0xw8Wp-TPDgAABUc
[Sun Aug 30 03:08:51.290017 2026] [qos:error] [pid 509172:tid 509359] [client 103.20.191.118:58388] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=103.20.191.118, id=apPlE5wMiz5K1he2Fnn6ZgAAAcY
[Sun Aug 30 03:08:51.290033 2026] [qos:error] [pid 507246:tid 507376] [client 190.60.39.226:47136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=106, c=190.60.39.226, id=apPlE-8CsCvw81e_I2pW9wAAApk
[Sun Aug 30 03:08:51.290041 2026] [qos:error] [pid 507246:tid 507485] [client 45.172.19.171:44107] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=107, c=45.172.19.171, id=apPlE-8CsCvw81e_I2pW-AAAAwY
[Sun Aug 30 03:08:51.290051 2026] [qos:error] [pid 507246:tid 507411] [client 154.90.70.238:32796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=108, c=154.90.70.238, id=apPlE-8CsCvw81e_I2pW-QAAArw
[Sun Aug 30 03:08:51.292741 2026] [qos:error] [pid 507246:tid 507444] [client 213.21.53.243:39050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=213.21.53.243, id=apPlE-8CsCvw81e_I2pW-wAAAt0
[Sun Aug 30 03:08:51.292765 2026] [qos:error] [pid 509915:tid 510094] [client 45.136.115.2:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.44, id=apPlE82gn1q0xw8Wp-TPEAAABWI
[Sun Aug 30 03:08:51.292777 2026] [qos:error] [pid 509915:tid 510128] [client 181.119.238.58:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=50.6.92.44, id=apPlE82gn1q0xw8Wp-TPEQAABYQ
[Sun Aug 30 03:08:51.298711 2026] [qos:error] [pid 509172:tid 509428] [client 38.183.150.10:41822] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.183.150.10, id=apPlE5wMiz5K1he2Fnn6ZwAAAgs
[Sun Aug 30 03:08:51.298815 2026] [qos:error] [pid 507246:tid 507380] [client 163.181.207.170:36720] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=163.181.207.170, id=apPlE-8CsCvw81e_I2pW_QAAAp0
[Sun Aug 30 03:08:51.302378 2026] [qos:error] [pid 509915:tid 510143] [client 203.217.169.26:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlE82gn1q0xw8Wp-TPFQAABZM
[Sun Aug 30 03:08:51.302389 2026] [qos:error] [pid 509172:tid 509307] [client 14.19.58.242:47947] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=14.19.58.242, id=apPlE5wMiz5K1he2Fnn6aQAAAZI
[Sun Aug 30 03:08:51.303502 2026] [qos:error] [pid 509172:tid 509330] [client 27.74.254.228:46066] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=27.74.254.228, id=apPlE5wMiz5K1he2Fnn6agAAAak
[Sun Aug 30 03:08:51.305330 2026] [qos:error] [pid 509172:tid 509342] [client 45.95.232.35:43685] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.95.232.35, id=apPlE5wMiz5K1he2Fnn6awAAAbU
[Sun Aug 30 03:08:51.305516 2026] [qos:error] [pid 507246:tid 507487] [client 177.159.113.232:33841] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=177.159.113.232, id=apPlE-8CsCvw81e_I2pW_gAAAwg
[Sun Aug 30 03:08:51.308703 2026] [security2:error] [pid 509915:tid 510049] [client 4.205.62.107:22947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/txets.php"] [unique_id "apPlE82gn1q0xw8Wp-TPGQAABTU"]
[Sun Aug 30 03:08:51.310552 2026] [qos:error] [pid 507246:tid 507404] [client 109.72.55.69:51486] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=109.72.55.69, id=apPlE-8CsCvw81e_I2pXAgAAArU
[Sun Aug 30 03:08:51.310553 2026] [qos:error] [pid 509915:tid 510067] [client 103.157.78.190:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlE82gn1q0xw8Wp-TPGAAABUc
[Sun Aug 30 03:08:51.310763 2026] [qos:error] [pid 509915:tid 510064] [client 38.188.63.115:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlE82gn1q0xw8Wp-TPGgAABUQ
[Sun Aug 30 03:08:51.313000 2026] [qos:error] [pid 507246:tid 507481] [client 45.127.58.70:49334] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.127.58.70, id=apPlE-8CsCvw81e_I2pXAwAAAwI
[Sun Aug 30 03:08:51.313712 2026] [qos:error] [pid 507246:tid 507393] [client 186.250.147.255:40282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=186.250.147.255, id=apPlE-8CsCvw81e_I2pXBAAAAqo
[Sun Aug 30 03:08:51.314710 2026] [qos:error] [pid 509915:tid 510163] [client 204.76.203.9:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlE82gn1q0xw8Wp-TPHQAABac
[Sun Aug 30 03:08:51.315661 2026] [qos:error] [pid 510357:tid 510497] [client 65.20.160.87:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlE35YTqJxoOZUSXs_vQAABb0
[Sun Aug 30 03:08:51.318890 2026] [authz_core:error] [pid 507246:tid 507419] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:51.319203 2026] [authz_core:error] [pid 507246:tid 507419] [client 74.7.227.8:48100] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:51.320143 2026] [qos:error] [pid 509172:tid 509362] [client 192.232.48.18:46738] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=192.232.48.18, id=apPlE5wMiz5K1he2Fnn6bgAAAck
[Sun Aug 30 03:08:51.320971 2026] [qos:error] [pid 510357:tid 510527] [client 82.110.112.36:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlE35YTqJxoOZUSXs_4gAABds
[Sun Aug 30 03:08:51.321067 2026] [qos:error] [pid 510357:tid 510505] [client 103.179.252.225:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.44, id=apPlE35YTqJxoOZUSXs_4AAABcU
[Sun Aug 30 03:08:51.326249 2026] [qos:error] [pid 510357:tid 510513] [client 103.153.62.162:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlE35YTqJxoOZUSXs_vwAABc0
[Sun Aug 30 03:08:51.326607 2026] [qos:error] [pid 509172:tid 509346] [client 123.139.125.120:44264] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=123.139.125.120, id=apPlE5wMiz5K1he2Fnn6cAAAAbk
[Sun Aug 30 03:08:51.326617 2026] [qos:error] [pid 510357:tid 510493] [client 103.60.175.39:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=50.6.92.44, id=apPlE35YTqJxoOZUSXs_wQAABbk
[Sun Aug 30 03:08:51.326836 2026] [qos:error] [pid 510357:tid 510498] [client 113.163.53.182:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=50.6.92.44, id=apPlE35YTqJxoOZUSXs_wwAABb4
[Sun Aug 30 03:08:51.327795 2026] [qos:error] [pid 510357:tid 510565] [client 85.159.94.124:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=50.6.92.44, id=apPlE35YTqJxoOZUSXs_xQAABgE
[Sun Aug 30 03:08:51.328052 2026] [qos:error] [pid 510357:tid 510491] [client 72.62.59.63:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=50.6.92.44, id=apPlE35YTqJxoOZUSXs_xwAABbc
[Sun Aug 30 03:08:51.328247 2026] [qos:error] [pid 510357:tid 510517] [client 95.3.69.222:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=50.6.92.44, id=apPlE35YTqJxoOZUSXs_ygAABdE
[Sun Aug 30 03:08:51.328767 2026] [qos:error] [pid 507246:tid 507421] [client 120.232.115.170:20714] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=120.232.115.170, id=apPlE-8CsCvw81e_I2pXBgAAAsY
[Sun Aug 30 03:08:51.328772 2026] [qos:error] [pid 510357:tid 510522] [client 103.237.102.191:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=106, c=50.6.92.44, id=apPlE35YTqJxoOZUSXs_zQAABdY
[Sun Aug 30 03:08:51.328932 2026] [qos:error] [pid 510357:tid 510518] [client 31.58.57.82:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=50.6.92.44, id=apPlE35YTqJxoOZUSXs_zAAABdI
[Sun Aug 30 03:08:51.328940 2026] [qos:error] [pid 510357:tid 510574] [client 38.194.250.66:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=106, c=50.6.92.44, id=apPlE35YTqJxoOZUSXs_zgAABgo
[Sun Aug 30 03:08:51.330121 2026] [qos:error] [pid 509172:tid 509384] [client 2.56.108.184:50024] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=106, c=2.56.108.184, id=apPlE5wMiz5K1he2Fnn6cQAAAd8
[Sun Aug 30 03:08:51.330572 2026] [qos:error] [pid 510357:tid 510504] [client 115.127.44.14:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=106, c=50.6.92.44, id=apPlE35YTqJxoOZUSXs_1AAABcQ
[Sun Aug 30 03:08:51.330679 2026] [qos:error] [pid 510357:tid 510511] [client 197.248.16.109:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=106, c=50.6.92.44, id=apPlE35YTqJxoOZUSXs_1gAABcs
[Sun Aug 30 03:08:51.330690 2026] [qos:error] [pid 510357:tid 510526] [client 217.171.94.166:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=107, c=50.6.92.44, id=apPlE35YTqJxoOZUSXs_1wAABdo
[Sun Aug 30 03:08:51.330827 2026] [qos:error] [pid 510357:tid 510508] [client 189.4.65.74:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=106, c=50.6.92.44, id=apPlE35YTqJxoOZUSXs__QAABcg
[Sun Aug 30 03:08:51.330899 2026] [qos:error] [pid 510357:tid 510529] [client 185.95.152.38:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=50.6.92.44, id=apPlE35YTqJxoOZUSXs_2QAABd0
[Sun Aug 30 03:08:51.330925 2026] [qos:error] [pid 510357:tid 510509] [client 85.112.80.98:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=106, c=50.6.92.44, id=apPlE35YTqJxoOZUSXs_7wAABck
[Sun Aug 30 03:08:51.331235 2026] [qos:error] [pid 510357:tid 510535] [client 45.151.106.226:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=50.6.92.44, id=apPlE35YTqJxoOZUSXs_8gAABeM
[Sun Aug 30 03:08:51.331258 2026] [qos:error] [pid 510357:tid 510540] [client 14.169.77.73:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=105, c=50.6.92.44, id=apPlE35YTqJxoOZUSXs_9QAABeg
[Sun Aug 30 03:08:51.331422 2026] [qos:error] [pid 510357:tid 510537] [client 181.13.210.60:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.44, id=apPlE35YTqJxoOZUSXs_-gAABeU
[Sun Aug 30 03:08:51.331834 2026] [security2:error] [pid 509915:tid 510051] [client 158.158.54.35:22987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/favicon.php"] [unique_id "apPlE82gn1q0xw8Wp-TPIQAABTc"]
[Sun Aug 30 03:08:51.348937 2026] [security2:error] [pid 510357:tid 510493] [client 20.48.250.41:61308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/browse.php"] [unique_id "apPlE35YTqJxoOZUSXtAFgAABbk"]
[Sun Aug 30 03:08:51.413355 2026] [security2:error] [pid 507246:tid 507411] [client 20.63.81.20:52680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp-theme.php"] [unique_id "apPlE-8CsCvw81e_I2pXIgAAArw"]
[Sun Aug 30 03:08:51.426808 2026] [security2:error] [pid 507246:tid 507443] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/bin/.env"] [unique_id "apPlE-8CsCvw81e_I2pXMAAAAtw"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:51.443025 2026] [authz_core:error] [pid 507246:tid 507431] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:51.443348 2026] [authz_core:error] [pid 507246:tid 507431] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:51.459443 2026] [authz_core:error] [pid 507246:tid 507439] [client 66.249.66.66:58184] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:51.459802 2026] [authz_core:error] [pid 507246:tid 507439] [client 66.249.66.66:58184] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:51.490806 2026] [security2:error] [pid 509915:tid 510049] [client 20.151.200.44:55567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/ft.php"] [unique_id "apPlE82gn1q0xw8Wp-TPWwAABTU"]
[Sun Aug 30 03:08:51.492414 2026] [security2:error] [pid 509915:tid 510125] [client 20.48.250.41:61216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/zoo.php"] [unique_id "apPlE82gn1q0xw8Wp-TPXAAABYE"]
[Sun Aug 30 03:08:51.500484 2026] [security2:error] [pid 507246:tid 507450] [client 20.48.160.90:45878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlE-8CsCvw81e_I2pXXAAAAuM"]
[Sun Aug 30 03:08:51.515624 2026] [authz_core:error] [pid 507246:tid 507383] [client 216.73.216.128:1805] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:51.516014 2026] [authz_core:error] [pid 507246:tid 507383] [client 216.73.216.128:1805] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:51.553463 2026] [security2:error] [pid 509172:tid 509353] [client 20.63.81.20:52684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/2d7433/index.php"] [unique_id "apPlE5wMiz5K1he2Fnn62wAAAcA"]
[Sun Aug 30 03:08:51.573789 2026] [authz_core:error] [pid 509172:tid 509382] [client 66.249.66.75:58596] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:51.574311 2026] [authz_core:error] [pid 509172:tid 509382] [client 66.249.66.75:58596] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:51.617600 2026] [security2:error] [pid 507246:tid 507471] [client 74.248.24.12:7517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/about.php7"] [unique_id "apPlE-8CsCvw81e_I2pXkAAAAvg"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:51.626400 2026] [security2:error] [pid 507246:tid 507490] [client 20.48.250.41:61298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/elp.php"] [unique_id "apPlE-8CsCvw81e_I2pXkgAAAws"]
[Sun Aug 30 03:08:51.634599 2026] [security2:error] [pid 507246:tid 507452] [client 68.155.159.216:55081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/.well-knownold/index.php"] [unique_id "apPlE-8CsCvw81e_I2pXmQAAAuU"]
[Sun Aug 30 03:08:51.635203 2026] [security2:error] [pid 509915:tid 510087] [client 20.151.200.44:57919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/ca.php"] [unique_id "apPlE82gn1q0xw8Wp-TPkAAABVs"]
[Sun Aug 30 03:08:51.657398 2026] [security2:error] [pid 509915:tid 510063] [client 20.48.160.90:40011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlE82gn1q0xw8Wp-TPkQAABUM"]
[Sun Aug 30 03:08:51.664709 2026] [lsapi:warn] [pid 509915:tid 509937] [remote 35.184.52.239:32768] [host tastylandscape.com] Backend log: PHP Warning: Use of undefined constant user_level - assumed 'user_level' (this will throw an Error in a future version of PHP) in /home4/tommed/public_html/wp-content/plugins/ultimate-google-analytics/ultimate_ga.php on line 524\n
[Sun Aug 30 03:08:51.671488 2026] [authz_core:error] [pid 509172:tid 509343] [client 66.249.66.36:54095] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:51.671922 2026] [authz_core:error] [pid 509172:tid 509343] [client 66.249.66.36:54095] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:51.680748 2026] [security2:error] [pid 509915:tid 510156] [client 4.205.62.107:17285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlE82gn1q0xw8Wp-TPlwAABaA"]
[Sun Aug 30 03:08:51.686707 2026] [security2:error] [pid 507246:tid 507393] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/sbin/.env"] [unique_id "apPlE-8CsCvw81e_I2pXuAAAAqo"]
[Sun Aug 30 03:08:51.698998 2026] [security2:error] [pid 509172:tid 509310] [client 4.205.62.107:61806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/fff.php"] [unique_id "apPlE5wMiz5K1he2Fnn7GAAAAZU"]
[Sun Aug 30 03:08:51.705008 2026] [security2:error] [pid 509172:tid 509320] [client 20.63.81.20:52391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp-login.php"] [unique_id "apPlE5wMiz5K1he2Fnn7FAAAAZ8"]
[Sun Aug 30 03:08:51.710224 2026] [security2:error] [pid 507246:tid 507413] [client 20.48.251.3:59869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/kerang.php"] [unique_id "apPlE-8CsCvw81e_I2pXxwAAAr4"]
[Sun Aug 30 03:08:51.723641 2026] [security2:error] [pid 507246:tid 507404] [client 68.155.159.216:60920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/packed.php"] [unique_id "apPlE-8CsCvw81e_I2pX0wAAArU"]
[Sun Aug 30 03:08:51.749056 2026] [security2:error] [pid 507246:tid 507443] [client 20.104.18.15:35011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/sallu.php"] [unique_id "apPlE-8CsCvw81e_I2pX3wAAAtw"]
[Sun Aug 30 03:08:51.756832 2026] [security2:error] [pid 507246:tid 507380] [client 20.48.250.41:61200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/666.php"] [unique_id "apPlE-8CsCvw81e_I2pX4wAAAp0"]
[Sun Aug 30 03:08:51.768128 2026] [authz_core:error] [pid 509172:tid 509394] [client 66.249.66.74:44113] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:51.768467 2026] [authz_core:error] [pid 509172:tid 509394] [client 66.249.66.74:44113] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:51.786529 2026] [authz_core:error] [pid 509172:tid 509351] [client 216.73.216.128:35630] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:51.786898 2026] [authz_core:error] [pid 509172:tid 509351] [client 216.73.216.128:35630] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:51.797462 2026] [security2:error] [pid 507246:tid 507441] [client 158.158.54.35:20292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/help.php"] [unique_id "apPlE-8CsCvw81e_I2pYAgAAAto"]
[Sun Aug 30 03:08:51.803741 2026] [security2:error] [pid 507246:tid 507488] [client 20.48.160.90:45876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/ser.php"] [unique_id "apPlE-8CsCvw81e_I2pYCgAAAwk"]
[Sun Aug 30 03:08:51.811688 2026] [security2:error] [pid 509172:tid 509418] [client 20.104.18.15:1875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/alfa.php"] [unique_id "apPlE5wMiz5K1he2Fnn7UwAAAgE"]
[Sun Aug 30 03:08:51.833272 2026] [security2:error] [pid 507246:tid 507496] [client 20.63.81.20:52694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/images.php"] [unique_id "apPlE-8CsCvw81e_I2pYJgAAAxE"]
[Sun Aug 30 03:08:51.839342 2026] [security2:error] [pid 507246:tid 507409] [client 20.104.50.220:46171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/file52.php"] [unique_id "apPlE-8CsCvw81e_I2pYLgAAAro"]
[Sun Aug 30 03:08:51.880776 2026] [security2:error] [pid 509172:tid 509319] [client 20.104.18.15:34638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/132.php"] [unique_id "apPlE5wMiz5K1he2Fnn7jQAAAZ4"]
[Sun Aug 30 03:08:51.884249 2026] [security2:error] [pid 509172:tid 509331] [client 20.48.250.41:61188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/knmt.php"] [unique_id "apPlE5wMiz5K1he2Fnn7lwAAAao"]
[Sun Aug 30 03:08:51.901548 2026] [security2:error] [pid 509172:tid 509378] [client 20.104.50.220:42490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/losX.php"] [unique_id "apPlE5wMiz5K1he2Fnn7nwAAAdk"]
[Sun Aug 30 03:08:51.929725 2026] [security2:error] [pid 507246:tid 507498] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/local/.env"] [unique_id "apPlE-8CsCvw81e_I2pYZAAAAxM"]
[Sun Aug 30 03:08:51.932500 2026] [security2:error] [pid 509172:tid 509374] [client 20.104.18.15:18275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/ssla.php"] [unique_id "apPlE5wMiz5K1he2Fnn7tgAAAdU"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:51.952571 2026] [authz_core:error] [pid 507246:tid 507435] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:51.953179 2026] [authz_core:error] [pid 507246:tid 507435] [client 74.7.243.204:60606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:51.955072 2026] [security2:error] [pid 507246:tid 507378] [client 20.104.50.220:5571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/g.php"] [unique_id "apPlE-8CsCvw81e_I2pYbgAAAps"]
[Sun Aug 30 03:08:51.968472 2026] [security2:error] [pid 509172:tid 509337] [client 20.48.251.3:5103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/wp-act.php"] [unique_id "apPlE5wMiz5K1he2Fnn7zQAAAbA"]
[Sun Aug 30 03:08:51.972370 2026] [security2:error] [pid 509915:tid 510082] [client 20.63.81.20:52392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/ops.php"] [unique_id "apPlE82gn1q0xw8Wp-TP8gAABVY"]
[Sun Aug 30 03:08:51.985280 2026] [security2:error] [pid 509172:tid 509398] [client 20.48.160.90:45927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/431.php"] [unique_id "apPlE5wMiz5K1he2Fnn71gAAAe0"]
[Sun Aug 30 03:08:52.001055 2026] [security2:error] [pid 509915:tid 510153] [client 4.205.62.107:36013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/php-details.php"] [unique_id "apPlFM2gn1q0xw8Wp-TP-gAABZ0"]
[Sun Aug 30 03:08:52.016190 2026] [security2:error] [pid 509915:tid 510047] [client 20.48.250.41:61276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/sbhu.php"] [unique_id "apPlFM2gn1q0xw8Wp-TQBAAABTM"]
[Sun Aug 30 03:08:52.062495 2026] [lsapi:warn] [pid 507246:tid 507280] [remote 35.184.52.239:32769] [host tastylandscape.com] Backend log: PHP Warning: Use of undefined constant user_level - assumed 'user_level' (this will throw an Error in a future version of PHP) in /home4/tommed/public_html/wp-content/plugins/ultimate-google-analytics/ultimate_ga.php on line 524\n
[Sun Aug 30 03:08:52.101324 2026] [security2:error] [pid 510357:tid 510559] [client 20.63.81.20:52632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPlFH5YTqJxoOZUSXtAigAABfs"]
[Sun Aug 30 03:08:52.104813 2026] [authz_core:error] [pid 509172:tid 509350] [client 66.249.66.201:63904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:52.105251 2026] [authz_core:error] [pid 509172:tid 509350] [client 66.249.66.201:63904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:52.115381 2026] [security2:error] [pid 509172:tid 509338] [client 20.104.18.15:23380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/asdfghj.php"] [unique_id "apPlFJwMiz5K1he2Fnn8EQAAAbE"]
[Sun Aug 30 03:08:52.118902 2026] [security2:error] [pid 507246:tid 507409] [client 74.248.24.12:2983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/dxc.php"] [unique_id "apPlFO8CsCvw81e_I2pYoAAAAro"]
[Sun Aug 30 03:08:52.121804 2026] [security2:error] [pid 509172:tid 509379] [client 20.104.50.220:52826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/dada.php"] [unique_id "apPlFJwMiz5K1he2Fnn8EgAAAdo"]
[Sun Aug 30 03:08:52.132533 2026] [authz_core:error] [pid 510357:tid 510537] [client 66.249.66.65:44067] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:52.132870 2026] [authz_core:error] [pid 510357:tid 510537] [client 66.249.66.65:44067] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:52.136820 2026] [security2:error] [pid 509172:tid 509370] [client 20.48.160.90:45893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/rxr.php"] [unique_id "apPlFJwMiz5K1he2Fnn8GAAAAdE"]
[Sun Aug 30 03:08:52.136820 2026] [security2:error] [pid 510357:tid 510611] [client 20.104.50.220:61993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/su.php"] [unique_id "apPlFH5YTqJxoOZUSXtAlgAABi8"]
[Sun Aug 30 03:08:52.141319 2026] [security2:error] [pid 507246:tid 507498] [client 20.104.50.220:32842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/dom.php"] [unique_id "apPlFO8CsCvw81e_I2pYpgAAAxM"]
[Sun Aug 30 03:08:52.143030 2026] [security2:error] [pid 507246:tid 507498] [client 20.104.50.220:31850] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.38cupscreen.cover789.com"] [uri "/1.php"] [unique_id "apPlFO8CsCvw81e_I2pYpwAAAxM"]
[Sun Aug 30 03:08:52.143184 2026] [security2:error] [pid 507246:tid 507498] [client 20.104.50.220:31850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/1.php"] [unique_id "apPlFO8CsCvw81e_I2pYpwAAAxM"]
[Sun Aug 30 03:08:52.154270 2026] [security2:error] [pid 509915:tid 510083] [client 20.104.18.15:43290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/file1221.php"] [unique_id "apPlFM2gn1q0xw8Wp-TQUAAABVc"]
[Sun Aug 30 03:08:52.155737 2026] [security2:error] [pid 509172:tid 509421] [client 20.48.250.41:60481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/a332.php"] [unique_id "apPlFJwMiz5K1he2Fnn8IgAAAgQ"]
[Sun Aug 30 03:08:52.168762 2026] [security2:error] [pid 507246:tid 507381] [client 34.100.204.203:34790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/portal/.env"] [unique_id "apPlFO8CsCvw81e_I2pYsgAAAp4"]
[Sun Aug 30 03:08:52.229984 2026] [security2:error] [pid 509915:tid 510156] [client 20.63.81.20:52400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPlFM2gn1q0xw8Wp-TQbQAABaA"]
[Sun Aug 30 03:08:52.259052 2026] [security2:error] [pid 510357:tid 510536] [client 20.48.251.3:13387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/database.php"] [unique_id "apPlFH5YTqJxoOZUSXtAqAAABeQ"]
[Sun Aug 30 03:08:52.265721 2026] [security2:error] [pid 509172:tid 509369] [client 20.104.50.220:17225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/admin.php"] [unique_id "apPlFJwMiz5K1he2Fnn8ZAAAAdA"]
[Sun Aug 30 03:08:52.268070 2026] [security2:error] [pid 509172:tid 509417] [client 20.48.160.90:45899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/csst.php"] [unique_id "apPlFJwMiz5K1he2Fnn8ZwAAAgA"]
[Sun Aug 30 03:08:52.284468 2026] [security2:error] [pid 509172:tid 509374] [client 20.48.250.41:61203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/ws66.php"] [unique_id "apPlFJwMiz5K1he2Fnn8dAAAAdU"]
[Sun Aug 30 03:08:52.297185 2026] [security2:error] [pid 509172:tid 509320] [client 20.104.49.130:63535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/ops.php"] [unique_id "apPlFJwMiz5K1he2Fnn8fQAAAZ8"]
[Sun Aug 30 03:08:52.339632 2026] [authz_core:error] [pid 509172:tid 509405] [client 216.73.216.128:28214] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:52.340139 2026] [authz_core:error] [pid 509172:tid 509405] [client 216.73.216.128:28214] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:52.342491 2026] [security2:error] [pid 509172:tid 509323] [client 20.48.251.3:59307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/a1vx.php"] [unique_id "apPlFJwMiz5K1he2Fnn8ngAAAaI"]
[Sun Aug 30 03:08:52.361735 2026] [security2:error] [pid 509915:tid 510117] [client 20.63.81.20:52687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/about.php"] [unique_id "apPlFM2gn1q0xw8Wp-TQkwAABXk"]
[Sun Aug 30 03:08:52.364250 2026] [security2:error] [pid 509172:tid 509416] [client 20.48.251.3:7419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/packed.php"] [unique_id "apPlFJwMiz5K1he2Fnn8qgAAAf8"]
[Sun Aug 30 03:08:52.395448 2026] [security2:error] [pid 509172:tid 509322] [client 20.48.160.90:45918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp-includes/blocks/query-title/footer.php"] [unique_id "apPlFJwMiz5K1he2Fnn8tgAAAaE"]
[Sun Aug 30 03:08:52.402510 2026] [security2:error] [pid 510357:tid 510567] [client 20.151.200.44:46061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/wk/index.php"] [unique_id "apPlFH5YTqJxoOZUSXtAtgAABgM"]
[Sun Aug 30 03:08:52.408324 2026] [security2:error] [pid 509172:tid 509421] [client 68.155.159.216:45891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/lv.php"] [unique_id "apPlFJwMiz5K1he2Fnn8vQAAAgQ"]
[Sun Aug 30 03:08:52.409145 2026] [authz_core:error] [pid 509172:tid 509386] [client 66.249.66.203:47159] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:52.409557 2026] [authz_core:error] [pid 509172:tid 509386] [client 66.249.66.203:47159] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:52.427742 2026] [security2:error] [pid 509172:tid 509309] [client 158.158.54.35:9542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/gebase.php69"] [unique_id "apPlFJwMiz5K1he2Fnn8zAAAAZQ"]
[Sun Aug 30 03:08:52.431104 2026] [security2:error] [pid 509172:tid 509398] [client 20.104.49.130:45735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/dragonshell.php"] [unique_id "apPlFJwMiz5K1he2Fnn80QAAAe0"]
[Sun Aug 30 03:08:52.436627 2026] [security2:error] [pid 509915:tid 510163] [client 20.48.250.41:61307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/ws68.php"] [unique_id "apPlFM2gn1q0xw8Wp-TQpAAABac"]
[Sun Aug 30 03:08:52.454409 2026] [security2:error] [pid 509915:tid 510072] [client 4.205.62.107:22548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/time.php"] [unique_id "apPlFM2gn1q0xw8Wp-TQpgAABUw"]
[Sun Aug 30 03:08:52.460182 2026] [security2:error] [pid 509172:tid 509384] [client 20.104.49.130:52469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/sd.php"] [unique_id "apPlFJwMiz5K1he2Fnn83gAAAd8"]
[Sun Aug 30 03:08:52.495015 2026] [security2:error] [pid 509172:tid 509419] [client 20.63.81.20:52705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/admin.php/admin.php"] [unique_id "apPlFJwMiz5K1he2Fnn8_wAAAgI"]
[Sun Aug 30 03:08:52.511089 2026] [authz_core:error] [pid 509915:tid 510171] [client 66.249.66.65:54301] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:52.511543 2026] [authz_core:error] [pid 509915:tid 510171] [client 66.249.66.65:54301] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:52.516866 2026] [authz_core:error] [pid 509172:tid 509364] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:52.517143 2026] [authz_core:error] [pid 509172:tid 509364] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:52.518124 2026] [authz_core:error] [pid 510357:tid 510552] [client 216.73.216.128:6795] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:52.518421 2026] [authz_core:error] [pid 510357:tid 510552] [client 216.73.216.128:6795] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:52.524657 2026] [security2:error] [pid 509172:tid 509335] [client 20.48.160.90:40038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp-content/uploads/indoex.php"] [unique_id "apPlFJwMiz5K1he2Fnn9GQAAAa4"]
[Sun Aug 30 03:08:52.572517 2026] [security2:error] [pid 509915:tid 510154] [client 20.48.250.41:61270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/users.php"] [unique_id "apPlFM2gn1q0xw8Wp-TQwgAABZ4"]
[Sun Aug 30 03:08:52.579428 2026] [authz_core:error] [pid 509172:tid 509331] [client 66.249.66.40:55168] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:52.579757 2026] [authz_core:error] [pid 509172:tid 509331] [client 66.249.66.40:55168] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:52.620214 2026] [security2:error] [pid 509172:tid 509375] [client 87.223.236.195:42076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.236.223.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pritchardislandhoa.com"] [uri "/wp-login.php"] [unique_id "apPlFJwMiz5K1he2Fnn9RwAAAdY"]
[Sun Aug 30 03:08:52.622379 2026] [security2:error] [pid 509172:tid 509426] [client 20.63.81.20:52362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/media.php"] [unique_id "apPlFJwMiz5K1he2Fnn9TAAAAgk"]
[Sun Aug 30 03:08:52.631382 2026] [security2:error] [pid 510357:tid 510545] [client 74.248.24.12:2086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/bihnmimh.php"] [unique_id "apPlFH5YTqJxoOZUSXtAxQAABe0"]
[Sun Aug 30 03:08:52.654314 2026] [security2:error] [pid 509915:tid 510149] [client 20.48.160.90:40040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPlFM2gn1q0xw8Wp-TQzgAABZk"]
[Sun Aug 30 03:08:52.682985 2026] [security2:error] [pid 509172:tid 509377] [client 143.110.213.72:43904] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "mail.anantiapolytechnic.ng"] [uri "/"] [unique_id "apPlFJwMiz5K1he2Fnn9VwAAAdg"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:52.701680 2026] [security2:error] [pid 509172:tid 509314] [client 20.48.250.41:61226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/bzjdlofz.php"] [unique_id "apPlFJwMiz5K1he2Fnn9YwAAAZk"]
[Sun Aug 30 03:08:52.705735 2026] [authz_core:error] [pid 509172:tid 509350] [client 216.73.216.128:34637] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:52.706184 2026] [authz_core:error] [pid 509172:tid 509350] [client 216.73.216.128:34637] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:52.747587 2026] [security2:error] [pid 510357:tid 510526] [client 68.155.159.216:55150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apPlFH5YTqJxoOZUSXtAywAABdo"]
[Sun Aug 30 03:08:52.750109 2026] [security2:error] [pid 509915:tid 510141] [client 20.63.81.20:52731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/mac.php"] [unique_id "apPlFM2gn1q0xw8Wp-TQ6QAABZE"]
[Sun Aug 30 03:08:52.793998 2026] [security2:error] [pid 509915:tid 510081] [client 20.48.160.90:45871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/haxor.php"] [unique_id "apPlFM2gn1q0xw8Wp-TQ_QAABVU"]
[Sun Aug 30 03:08:52.809380 2026] [security2:error] [pid 509915:tid 510159] [client 20.104.49.130:59536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/v2.php"] [unique_id "apPlFM2gn1q0xw8Wp-TRAgAABaM"]
[Sun Aug 30 03:08:52.813133 2026] [security2:error] [pid 509915:tid 510073] [client 4.205.62.107:17144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/cloud.php"] [unique_id "apPlFM2gn1q0xw8Wp-TRBAAABU0"]
[Sun Aug 30 03:08:52.833140 2026] [security2:error] [pid 509915:tid 510108] [client 68.155.159.216:61425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-content/packed.php"] [unique_id "apPlFM2gn1q0xw8Wp-TREwAABXA"]
[Sun Aug 30 03:08:52.834046 2026] [security2:error] [pid 509915:tid 510134] [client 20.48.250.41:61213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/selesai.php"] [unique_id "apPlFM2gn1q0xw8Wp-TRFAAABYo"]
[Sun Aug 30 03:08:52.837385 2026] [security2:error] [pid 510357:tid 510519] [client 4.205.62.107:61738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/autogooey.php"] [unique_id "apPlFH5YTqJxoOZUSXtA2wAABdM"]
[Sun Aug 30 03:08:52.845893 2026] [authz_core:error] [pid 509915:tid 510132] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:52.846237 2026] [authz_core:error] [pid 509915:tid 510132] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:52.868781 2026] [security2:error] [pid 509172:tid 509358] [client 158.158.54.35:5393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/MYK4TJEfFvO.php"] [unique_id "apPlFJwMiz5K1he2Fnn9igAAAcU"]
[Sun Aug 30 03:08:52.882995 2026] [security2:error] [pid 509915:tid 510139] [client 20.63.81.20:52408] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.st20.org"] [uri "/1.php"] [unique_id "apPlFM2gn1q0xw8Wp-TRKgAABY8"]
[Sun Aug 30 03:08:52.883106 2026] [security2:error] [pid 509915:tid 510139] [client 20.63.81.20:52408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/1.php"] [unique_id "apPlFM2gn1q0xw8Wp-TRKgAABY8"]
[Sun Aug 30 03:08:52.888040 2026] [security2:error] [pid 510357:tid 510602] [client 20.104.18.15:35136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/codex.php"] [unique_id "apPlFH5YTqJxoOZUSXtA5wAABiY"]
[Sun Aug 30 03:08:52.900209 2026] [security2:error] [pid 510357:tid 510607] [client 20.48.251.3:59875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/rem.php"] [unique_id "apPlFH5YTqJxoOZUSXtA6AAABis"]
[Sun Aug 30 03:08:52.929248 2026] [security2:error] [pid 509915:tid 510108] [client 20.48.160.90:40008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/google.php"] [unique_id "apPlFM2gn1q0xw8Wp-TRQgAABXA"]
[Sun Aug 30 03:08:52.939735 2026] [security2:error] [pid 509915:tid 509943] [remote 168.63.79.147:60216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lodestarcollaboration.com"] [uri "/wp-login.php"] [unique_id "apPlFM2gn1q0xw8Wp-TRPwAFPRo"]
[Sun Aug 30 03:08:52.950067 2026] [security2:error] [pid 509915:tid 510068] [client 20.104.18.15:2015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/133.php"] [unique_id "apPlFM2gn1q0xw8Wp-TRUQAABUg"]
[Sun Aug 30 03:08:52.987854 2026] [security2:error] [pid 509915:tid 510099] [client 20.48.250.41:61254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/shlo.php"] [unique_id "apPlFM2gn1q0xw8Wp-TRdgAABWc"]
[Sun Aug 30 03:08:52.988977 2026] [security2:error] [pid 509915:tid 510144] [client 20.104.50.220:46857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/zde.php"] [unique_id "apPlFM2gn1q0xw8Wp-TReAAABZQ"]
[Sun Aug 30 03:08:53.012237 2026] [security2:error] [pid 509915:tid 510110] [client 20.63.81.20:52706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/classwithtostring.php"] [unique_id "apPlFc2gn1q0xw8Wp-TRgQAABXI"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:53.025667 2026] [security2:error] [pid 510357:tid 510612] [client 20.104.18.15:34666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/v22.php"] [unique_id "apPlFX5YTqJxoOZUSXtBBAAABjA"]
[Sun Aug 30 03:08:53.046702 2026] [security2:error] [pid 509172:tid 509391] [client 20.151.200.44:45962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/dehnl.php"] [unique_id "apPlFZwMiz5K1he2Fnn93QAAAeY"]
[Sun Aug 30 03:08:53.049789 2026] [security2:error] [pid 509172:tid 509378] [client 20.104.50.220:42035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/mom.php"] [unique_id "apPlFZwMiz5K1he2Fnn94QAAAdk"]
[Sun Aug 30 03:08:53.082951 2026] [authz_core:error] [pid 509172:tid 509413] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:53.083256 2026] [authz_core:error] [pid 509172:tid 509413] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:53.085975 2026] [security2:error] [pid 509172:tid 509414] [client 20.104.50.220:6117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/test/wp-admin/install.php"] [unique_id "apPlFZwMiz5K1he2Fnn98gAAAf0"]
[Sun Aug 30 03:08:53.090609 2026] [security2:error] [pid 509172:tid 509346] [client 20.48.160.90:45874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "apPlFZwMiz5K1he2Fnn99AAAAbk"]
[Sun Aug 30 03:08:53.108154 2026] [security2:error] [pid 509915:tid 509946] [remote 168.63.79.147:60216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lodestarcollaboration.com"] [uri "/wp-login.php"] [unique_id "apPlFc2gn1q0xw8Wp-TRqgAFrR0"], referer: https://lodestarcollaboration.com/wp-login.php
[Sun Aug 30 03:08:53.114541 2026] [security2:error] [pid 509172:tid 509314] [client 20.48.250.41:61256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/asax.php"] [unique_id "apPlFZwMiz5K1he2Fnn-AwAAAZk"]
[Sun Aug 30 03:08:53.119372 2026] [security2:error] [pid 509172:tid 509370] [client 20.104.18.15:18428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apPlFZwMiz5K1he2Fnn-BQAAAdE"]
[Sun Aug 30 03:08:53.143048 2026] [security2:error] [pid 509172:tid 509337] [client 20.63.81.20:52377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp-ws68.php"] [unique_id "apPlFZwMiz5K1he2Fnn-CgAAAbA"]
[Sun Aug 30 03:08:53.145389 2026] [security2:error] [pid 509915:tid 510103] [client 74.248.24.12:12214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/ewywe1dg.php"] [unique_id "apPlFc2gn1q0xw8Wp-TRsAAABWs"]
[Sun Aug 30 03:08:53.157237 2026] [authz_core:error] [pid 509172:tid 509387] [client 216.73.216.128:28214] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:53.157696 2026] [authz_core:error] [pid 509172:tid 509387] [client 216.73.216.128:28214] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:53.174432 2026] [authz_core:error] [pid 509172:tid 509365] [client 66.249.66.42:52349] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:53.174873 2026] [authz_core:error] [pid 509172:tid 509365] [client 66.249.66.42:52349] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:53.188592 2026] [security2:error] [pid 509915:tid 510166] [client 4.205.62.107:36714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/routes.php"] [unique_id "apPlFc2gn1q0xw8Wp-TRvAAABao"]
[Sun Aug 30 03:08:53.220216 2026] [security2:error] [pid 509172:tid 509426] [client 20.48.160.90:40017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/robots.php"] [unique_id "apPlFZwMiz5K1he2Fnn-MgAAAgk"]
[Sun Aug 30 03:08:53.245676 2026] [security2:error] [pid 509172:tid 509339] [client 20.104.18.15:23411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/dragonshell.php"] [unique_id "apPlFZwMiz5K1he2Fnn-SgAAAbI"]
[Sun Aug 30 03:08:53.246007 2026] [security2:error] [pid 509915:tid 510067] [client 20.48.250.41:60486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/fetch.php"] [unique_id "apPlFc2gn1q0xw8Wp-TRzAAABUc"]
[Sun Aug 30 03:08:53.265759 2026] [core:error] [pid 509172:tid 509318] [client 20.63.219.114:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:08:53.265780 2026] [core:error] [pid 509172:tid 509318] [client 20.63.219.114:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:08:53.270401 2026] [security2:error] [pid 509172:tid 509425] [client 20.63.81.20:52690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/simple.php"] [unique_id "apPlFZwMiz5K1he2Fnn-XAAAAgg"]
[Sun Aug 30 03:08:53.271026 2026] [security2:error] [pid 509172:tid 509414] [client 20.104.50.220:52837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/0x1337.php"] [unique_id "apPlFZwMiz5K1he2Fnn-XQAAAf0"]
[Sun Aug 30 03:08:53.279049 2026] [security2:error] [pid 509172:tid 509323] [client 20.104.50.220:33585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/v4ga.php"] [unique_id "apPlFZwMiz5K1he2Fnn-aAAAAaI"]
[Sun Aug 30 03:08:53.296257 2026] [security2:error] [pid 509172:tid 509311] [client 20.104.50.220:32513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/usep.php"] [unique_id "apPlFZwMiz5K1he2Fnn-dQAAAZY"]
[Sun Aug 30 03:08:53.303063 2026] [security2:error] [pid 509915:tid 510151] [client 20.104.50.220:62002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/xx.php"] [unique_id "apPlFc2gn1q0xw8Wp-TR4QAABZs"]
[Sun Aug 30 03:08:53.308391 2026] [security2:error] [pid 510357:tid 510532] [client 20.104.18.15:43304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/nox.php"] [unique_id "apPlFX5YTqJxoOZUSXtBEAAABeA"]
[Sun Aug 30 03:08:53.311283 2026] [security2:error] [pid 509172:tid 509400] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/panel/.env"] [unique_id "apPlFZwMiz5K1he2Fnn-hgAAAe8"]
[Sun Aug 30 03:08:53.329882 2026] [security2:error] [pid 509172:tid 509343] [client 158.158.54.35:18595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/Casper.php"] [unique_id "apPlFZwMiz5K1he2Fnn-jQAAAbY"]
[Sun Aug 30 03:08:53.350328 2026] [security2:error] [pid 509172:tid 509385] [client 20.48.160.90:45845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp-content/plugins/ccx/index.php"] [unique_id "apPlFZwMiz5K1he2Fnn-nQAAAeA"]
[Sun Aug 30 03:08:53.376989 2026] [security2:error] [pid 509915:tid 510076] [client 20.48.250.41:61283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/vx.php"] [unique_id "apPlFc2gn1q0xw8Wp-TR-wAABVA"]
[Sun Aug 30 03:08:53.381267 2026] [security2:error] [pid 510357:tid 510615] [client 20.104.50.220:28707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/vuln.php"] [unique_id "apPlFX5YTqJxoOZUSXtBFQAABjM"]
[Sun Aug 30 03:08:53.399313 2026] [security2:error] [pid 509915:tid 510099] [client 20.63.81.20:52727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/aaa.php"] [unique_id "apPlFc2gn1q0xw8Wp-TR_wAABWc"]
[Sun Aug 30 03:08:53.403483 2026] [security2:error] [pid 509915:tid 510122] [client 20.104.50.220:16595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/aa2.php"] [unique_id "apPlFc2gn1q0xw8Wp-TSAAAABX4"]
[Sun Aug 30 03:08:53.449463 2026] [security2:error] [pid 509172:tid 509343] [client 20.151.200.44:46043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/png.php"] [unique_id "apPlFZwMiz5K1he2Fnn-6AAAAbY"]
[Sun Aug 30 03:08:53.479490 2026] [security2:error] [pid 509915:tid 510138] [client 20.48.160.90:40012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp-admin/css/colors/maro.php"] [unique_id "apPlFc2gn1q0xw8Wp-TSFAAABY4"]
[Sun Aug 30 03:08:53.481556 2026] [security2:error] [pid 509172:tid 509379] [client 20.48.251.3:13409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/atex1.php"] [unique_id "apPlFZwMiz5K1he2Fnn-_AAAAdo"]
[Sun Aug 30 03:08:53.505359 2026] [security2:error] [pid 509172:tid 509402] [client 20.48.250.41:61302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/global.php"] [unique_id "apPlFZwMiz5K1he2Fnn_EQAAAfE"]
[Sun Aug 30 03:08:53.521807 2026] [authz_core:error] [pid 509172:tid 509426] [client 216.73.216.128:34637] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:53.522134 2026] [authz_core:error] [pid 509172:tid 509426] [client 216.73.216.128:34637] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:53.532748 2026] [security2:error] [pid 509172:tid 509421] [client 20.48.251.3:59320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/public/vx.php"] [unique_id "apPlFZwMiz5K1he2Fnn_JAAAAgQ"]
[Sun Aug 30 03:08:53.538027 2026] [security2:error] [pid 509172:tid 509311] [client 20.48.251.3:44113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/wp-info.php"] [unique_id "apPlFZwMiz5K1he2Fnn_KQAAAZY"]
[Sun Aug 30 03:08:53.549724 2026] [security2:error] [pid 509172:tid 509390] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/crm/.env"] [unique_id "apPlFZwMiz5K1he2Fnn_MwAAAeU"]
[Sun Aug 30 03:08:53.550444 2026] [authz_core:error] [pid 509172:tid 509310] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:53.550814 2026] [authz_core:error] [pid 509172:tid 509310] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:53.592981 2026] [security2:error] [pid 509172:tid 509364] [client 4.205.62.107:54407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/doc.php"] [unique_id "apPlFZwMiz5K1he2Fnn_TQAAAcs"]
[Sun Aug 30 03:08:53.609720 2026] [security2:error] [pid 509172:tid 509380] [client 20.48.160.90:40027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp-admin/css/colors/coffee/marijuana.php"] [unique_id "apPlFZwMiz5K1he2Fnn_UgAAAds"]
[Sun Aug 30 03:08:53.628883 2026] [security2:error] [pid 509915:tid 510094] [client 143.110.213.72:43914] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "mail.anantiapolytechnic.ng"] [uri "/"] [unique_id "apPlFc2gn1q0xw8Wp-TSSAAABWI"]
[Sun Aug 30 03:08:53.633177 2026] [security2:error] [pid 509915:tid 510145] [client 20.48.250.41:61233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/fs.php"] [unique_id "apPlFc2gn1q0xw8Wp-TSSQAABZU"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:53.746339 2026] [security2:error] [pid 509915:tid 510116] [client 20.48.160.90:45858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp-admin/css/colors/coffee/mari.php"] [unique_id "apPlFc2gn1q0xw8Wp-TSdQAABXg"]
[Sun Aug 30 03:08:53.756928 2026] [security2:error] [pid 509915:tid 510143] [client 74.248.24.12:6018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/haiterus.php"] [unique_id "apPlFc2gn1q0xw8Wp-TSfAAABZM"]
[Sun Aug 30 03:08:53.761600 2026] [security2:error] [pid 509915:tid 510073] [client 20.63.81.20:52730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/shiny.php"] [unique_id "apPlFc2gn1q0xw8Wp-TSfwAABU0"]
[Sun Aug 30 03:08:53.763745 2026] [security2:error] [pid 509915:tid 510119] [client 68.155.159.216:46053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-includes/Text/index.php"] [unique_id "apPlFc2gn1q0xw8Wp-TSgQAABXs"]
[Sun Aug 30 03:08:53.766346 2026] [security2:error] [pid 509915:tid 510053] [client 20.48.250.41:61234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/ioxi.php"] [unique_id "apPlFc2gn1q0xw8Wp-TShAAABTk"]
[Sun Aug 30 03:08:53.794350 2026] [security2:error] [pid 509915:tid 510067] [client 158.158.54.35:6564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/wander.php"] [unique_id "apPlFc2gn1q0xw8Wp-TSmwAABUc"]
[Sun Aug 30 03:08:53.803937 2026] [authz_core:error] [pid 509172:tid 509364] [client 216.73.216.128:28214] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:53.804415 2026] [authz_core:error] [pid 509172:tid 509364] [client 216.73.216.128:28214] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:53.805438 2026] [security2:error] [pid 509172:tid 509385] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/erp/.env"] [unique_id "apPlFZwMiz5K1he2Fnn_hwAAAeA"]
[Sun Aug 30 03:08:53.844949 2026] [authz_core:error] [pid 509915:tid 510094] [client 66.249.66.71:50080] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:53.845294 2026] [authz_core:error] [pid 509915:tid 510094] [client 66.249.66.71:50080] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:53.850338 2026] [security2:error] [pid 509915:tid 510114] [client 68.155.159.216:55048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPlFc2gn1q0xw8Wp-TStAAABXY"]
[Sun Aug 30 03:08:53.878355 2026] [security2:error] [pid 510357:tid 510566] [client 20.151.200.44:46047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/txets.php"] [unique_id "apPlFX5YTqJxoOZUSXtBUAAABgI"]
[Sun Aug 30 03:08:53.888909 2026] [security2:error] [pid 509915:tid 510086] [client 20.63.81.20:52699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/goods.php"] [unique_id "apPlFc2gn1q0xw8Wp-TSzAAABVo"]
[Sun Aug 30 03:08:53.898539 2026] [security2:error] [pid 509915:tid 510114] [client 20.48.160.90:45852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp-includes/images/crystal/option.php"] [unique_id "apPlFc2gn1q0xw8Wp-TS1gAABXY"]
[Sun Aug 30 03:08:53.935475 2026] [security2:error] [pid 509172:tid 509310] [client 20.48.250.41:61300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/bootstrap.php"] [unique_id "apPlFZwMiz5K1he2Fnn_qgAAAZU"]
[Sun Aug 30 03:08:53.950923 2026] [security2:error] [pid 509915:tid 510093] [client 4.205.62.107:17093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/kerang.php"] [unique_id "apPlFc2gn1q0xw8Wp-TS8gAABWE"]
[Sun Aug 30 03:08:53.974057 2026] [security2:error] [pid 509172:tid 509429] [client 4.205.62.107:61732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/sdsa.php"] [unique_id "apPlFZwMiz5K1he2Fnn_wAAAAgw"]
[Sun Aug 30 03:08:53.976542 2026] [security2:error] [pid 509915:tid 510155] [client 68.155.159.216:60891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-l0gin.php"] [unique_id "apPlFc2gn1q0xw8Wp-TTCQAABZ8"]
[Sun Aug 30 03:08:54.015639 2026] [security2:error] [pid 509915:tid 510065] [client 20.63.81.20:52613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/000.php/index.php"] [unique_id "apPlFs2gn1q0xw8Wp-TTEAAABUU"]
[Sun Aug 30 03:08:54.038868 2026] [security2:error] [pid 509172:tid 509343] [client 20.48.251.3:59510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/min.php"] [unique_id "apPlFpwMiz5K1he2Fnn_-QAAAbY"]
[Sun Aug 30 03:08:54.043257 2026] [security2:error] [pid 509172:tid 509344] [client 20.104.18.15:35500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/5656.php"] [unique_id "apPlFpwMiz5K1he2Fnn__QAAAbc"]
[Sun Aug 30 03:08:54.043523 2026] [security2:error] [pid 509172:tid 509342] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/shop/.env"] [unique_id "apPlFpwMiz5K1he2Fnn__AAAAbU"]
[Sun Aug 30 03:08:54.054247 2026] [security2:error] [pid 509172:tid 509321] [client 20.48.160.90:45935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp-includes/pomo/xxx.php"] [unique_id "apPlFpwMiz5K1he2FnkADAAAAaA"]
[Sun Aug 30 03:08:54.072387 2026] [security2:error] [pid 509172:tid 509310] [client 20.48.250.41:61215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/export.php"] [unique_id "apPlFpwMiz5K1he2FnkAGAAAAZU"]
[Sun Aug 30 03:08:54.094803 2026] [authz_core:error] [pid 509172:tid 509373] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:54.095209 2026] [authz_core:error] [pid 509172:tid 509373] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:54.103672 2026] [security2:error] [pid 509172:tid 509344] [client 20.104.18.15:1866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/sym.php"] [unique_id "apPlFpwMiz5K1he2FnkAMgAAAbc"]
[Sun Aug 30 03:08:54.131771 2026] [security2:error] [pid 509172:tid 509332] [client 20.104.50.220:47080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wpo.php"] [unique_id "apPlFpwMiz5K1he2FnkAOQAAAas"]
[Sun Aug 30 03:08:54.141837 2026] [security2:error] [pid 510357:tid 510575] [client 20.63.81.20:52703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/Jcrop.php"] [unique_id "apPlFn5YTqJxoOZUSXtBegAABgs"]
[Sun Aug 30 03:08:54.154661 2026] [security2:error] [pid 509915:tid 510047] [client 20.104.49.130:60609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/js.php"] [unique_id "apPlFs2gn1q0xw8Wp-TTLgAABTM"]
[Sun Aug 30 03:08:54.171754 2026] [security2:error] [pid 509915:tid 510139] [client 20.104.18.15:34726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/wp-activate.php"] [unique_id "apPlFs2gn1q0xw8Wp-TTNwAABY8"]
[Sun Aug 30 03:08:54.185986 2026] [security2:error] [pid 509172:tid 509418] [client 20.48.160.90:45915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/650.php"] [unique_id "apPlFpwMiz5K1he2FnkASgAAAgE"]
[Sun Aug 30 03:08:54.212722 2026] [security2:error] [pid 509172:tid 509331] [client 20.104.50.220:42482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/killer.php"] [unique_id "apPlFpwMiz5K1he2FnkAWQAAAao"]
[Sun Aug 30 03:08:54.221837 2026] [security2:error] [pid 509172:tid 509404] [client 20.48.250.41:61264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/gk.php"] [unique_id "apPlFpwMiz5K1he2FnkAYgAAAfM"]
[Sun Aug 30 03:08:54.234453 2026] [security2:error] [pid 509172:tid 509357] [client 20.104.50.220:5547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/f.php"] [unique_id "apPlFpwMiz5K1he2FnkAZgAAAcQ"]
[Sun Aug 30 03:08:54.253911 2026] [authz_core:error] [pid 509172:tid 509368] [client 66.249.66.42:52349] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:54.254206 2026] [authz_core:error] [pid 509172:tid 509368] [client 66.249.66.42:52349] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:54.261721 2026] [security2:error] [pid 510357:tid 510492] [client 158.158.54.35:7383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/config.php7"] [unique_id "apPlFn5YTqJxoOZUSXtBgQAABbg"]
[Sun Aug 30 03:08:54.269806 2026] [security2:error] [pid 509172:tid 509346] [client 20.104.18.15:18242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/wp-aothait.php"] [unique_id "apPlFpwMiz5K1he2FnkAjQAAAbk"]
[Sun Aug 30 03:08:54.271927 2026] [security2:error] [pid 509172:tid 509306] [client 20.63.81.20:52708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/35iDq8NAjLu.php"] [unique_id "apPlFpwMiz5K1he2FnkAjgAAAZE"]
[Sun Aug 30 03:08:54.274425 2026] [security2:error] [pid 509172:tid 509409] [client 74.248.24.12:6035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/beence.php"] [unique_id "apPlFpwMiz5K1he2FnkAkgAAAfg"]
[Sun Aug 30 03:08:54.280612 2026] [security2:error] [pid 509172:tid 509397] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/store/.env"] [unique_id "apPlFpwMiz5K1he2FnkAmwAAAew"]
[Sun Aug 30 03:08:54.295370 2026] [security2:error] [pid 509172:tid 509399] [client 20.104.49.130:52456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-blog-header.php"] [unique_id "apPlFpwMiz5K1he2FnkArgAAAe4"]
[Sun Aug 30 03:08:54.312272 2026] [authz_core:error] [pid 509915:tid 510057] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:54.312739 2026] [authz_core:error] [pid 509915:tid 510057] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:54.321241 2026] [security2:error] [pid 509915:tid 510166] [client 20.48.160.90:45940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/nakrip.php"] [unique_id "apPlFs2gn1q0xw8Wp-TTYgAABao"]
[Sun Aug 30 03:08:54.337947 2026] [security2:error] [pid 509915:tid 510060] [client 4.205.62.107:36611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/aww.php"] [unique_id "apPlFs2gn1q0xw8Wp-TTYwAABUA"]
[Sun Aug 30 03:08:54.389815 2026] [security2:error] [pid 509172:tid 509327] [client 20.48.250.41:61185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/logs1.php"] [unique_id "apPlFpwMiz5K1he2FnkA8gAAAaY"]
[Sun Aug 30 03:08:54.405921 2026] [security2:error] [pid 509915:tid 510162] [client 20.63.81.20:52700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/btx25.php"] [unique_id "apPlFs2gn1q0xw8Wp-TTdwAABaY"]
[Sun Aug 30 03:08:54.415912 2026] [security2:error] [pid 509915:tid 510163] [client 20.104.50.220:32880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/s3c.php"] [unique_id "apPlFs2gn1q0xw8Wp-TTfQAABac"]
[Sun Aug 30 03:08:54.434769 2026] [security2:error] [pid 509915:tid 510107] [client 20.104.50.220:32282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wa.php"] [unique_id "apPlFs2gn1q0xw8Wp-TThwAABW8"]
[Sun Aug 30 03:08:54.439475 2026] [security2:error] [pid 509915:tid 510132] [client 20.104.50.220:61436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/byps.php"] [unique_id "apPlFs2gn1q0xw8Wp-TTiQAABYg"]
[Sun Aug 30 03:08:54.440832 2026] [security2:error] [pid 509172:tid 509307] [client 20.104.18.15:23237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/wp-safe.php"] [unique_id "apPlFpwMiz5K1he2FnkBCAAAAZI"]
[Sun Aug 30 03:08:54.451368 2026] [security2:error] [pid 509172:tid 509312] [client 20.48.160.90:40001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp-includes/interactivity-api/flower.php"] [unique_id "apPlFpwMiz5K1he2FnkBEgAAAZc"]
[Sun Aug 30 03:08:54.453355 2026] [security2:error] [pid 509172:tid 509390] [client 20.104.50.220:64454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/xltavrat.php"] [unique_id "apPlFpwMiz5K1he2FnkBFQAAAeU"]
[Sun Aug 30 03:08:54.457780 2026] [security2:error] [pid 509915:tid 510122] [client 20.104.18.15:43283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/akismet.php"] [unique_id "apPlFs2gn1q0xw8Wp-TTkAAABX4"]
[Sun Aug 30 03:08:54.522225 2026] [security2:error] [pid 509172:tid 509423] [client 20.104.50.220:29172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/V5.php"] [unique_id "apPlFpwMiz5K1he2FnkBRwAAAgY"]
[Sun Aug 30 03:08:54.524029 2026] [security2:error] [pid 509172:tid 509367] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/saas/.env"] [unique_id "apPlFpwMiz5K1he2FnkBSQAAAc4"]
[Sun Aug 30 03:08:54.539083 2026] [security2:error] [pid 510357:tid 510597] [client 20.48.250.41:60442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/inege.php"] [unique_id "apPlFn5YTqJxoOZUSXtBjgAABiE"]
[Sun Aug 30 03:08:54.540227 2026] [security2:error] [pid 509172:tid 509320] [client 20.104.50.220:17331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/ccou.php"] [unique_id "apPlFpwMiz5K1he2FnkBXQAAAZ8"]
[Sun Aug 30 03:08:54.547757 2026] [security2:error] [pid 509172:tid 509347] [client 20.63.81.20:52372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/radio.php"] [unique_id "apPlFpwMiz5K1he2FnkBYgAAAbo"]
[Sun Aug 30 03:08:54.565942 2026] [authz_core:error] [pid 509172:tid 509397] [client 66.249.66.40:54672] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:54.566225 2026] [authz_core:error] [pid 509172:tid 509397] [client 66.249.66.40:54672] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:54.583232 2026] [authz_core:error] [pid 509172:tid 509317] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:54.583538 2026] [authz_core:error] [pid 509172:tid 509317] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:54.598580 2026] [security2:error] [pid 509915:tid 510075] [client 20.48.160.90:45849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/xcc.php"] [unique_id "apPlFs2gn1q0xw8Wp-TTswAABU8"]
[Sun Aug 30 03:08:54.608461 2026] [security2:error] [pid 509172:tid 509393] [client 216.73.216.128:34637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlFpwMiz5K1he2FnkBhwAAAeg"]
[Sun Aug 30 03:08:54.629408 2026] [security2:error] [pid 509172:tid 509348] [client 20.48.251.3:56359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/aws_sdk_settings.php"] [unique_id "apPlFpwMiz5K1he2FnkBkAAAAbs"]
[Sun Aug 30 03:08:54.653329 2026] [security2:error] [pid 509915:tid 510089] [client 20.104.49.130:63536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/zoo2.php"] [unique_id "apPlFs2gn1q0xw8Wp-TTvwAABV0"]
[Sun Aug 30 03:08:54.656460 2026] [security2:error] [pid 509172:tid 509333] [client 143.110.213.72:43918] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "mail.anantiapolytechnic.ng"] [uri "/wp-json/batch/v1"] [unique_id "apPlFpwMiz5K1he2FnkBnAAAAaw"]
[Sun Aug 30 03:08:54.669621 2026] [security2:error] [pid 509915:tid 510132] [client 20.48.250.41:61224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/wp-link10.php"] [unique_id "apPlFs2gn1q0xw8Wp-TTwwAABYg"]
[Sun Aug 30 03:08:54.679068 2026] [security2:error] [pid 509172:tid 509364] [client 20.63.81.20:52609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/dex.php"] [unique_id "apPlFpwMiz5K1he2FnkBqQAAAcs"]
[Sun Aug 30 03:08:54.688955 2026] [security2:error] [pid 509172:tid 509365] [client 20.48.251.3:59284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/log.php"] [unique_id "apPlFpwMiz5K1he2FnkBsQAAAcw"]
[Sun Aug 30 03:08:54.694182 2026] [security2:error] [pid 509172:tid 509314] [client 158.158.54.35:22976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/eq2hbpgs.php"] [unique_id "apPlFpwMiz5K1he2FnkBtAAAAZk"]
[Sun Aug 30 03:08:54.714901 2026] [security2:error] [pid 509915:tid 510065] [client 20.48.251.3:64468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/fns.php"] [unique_id "apPlFs2gn1q0xw8Wp-TT1QAABUU"]
[Sun Aug 30 03:08:54.738491 2026] [security2:error] [pid 509172:tid 509415] [client 4.205.62.107:22930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/classsmtps.php"] [unique_id "apPlFpwMiz5K1he2FnkB1AAAAf4"]
[Sun Aug 30 03:08:54.740748 2026] [security2:error] [pid 509172:tid 509362] [client 20.48.160.90:45828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp-includes/Text/Diff/Engine/aaa.php"] [unique_id "apPlFpwMiz5K1he2FnkB1wAAAck"]
[Sun Aug 30 03:08:54.783424 2026] [security2:error] [pid 509172:tid 509382] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/client/.env"] [unique_id "apPlFpwMiz5K1he2FnkB7gAAAd0"]
[Sun Aug 30 03:08:54.797613 2026] [authz_core:error] [pid 509172:tid 509305] [client 216.73.216.128:28214] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:54.797907 2026] [authz_core:error] [pid 509172:tid 509305] [client 216.73.216.128:28214] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:54.799357 2026] [security2:error] [pid 509915:tid 510103] [client 20.48.250.41:61195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/ww.php"] [unique_id "apPlFs2gn1q0xw8Wp-TT8gAABWs"]
[Sun Aug 30 03:08:54.811335 2026] [security2:error] [pid 509172:tid 509359] [client 74.248.24.12:2103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/e69ovfsr.php"] [unique_id "apPlFpwMiz5K1he2FnkB-AAAAcY"]
[Sun Aug 30 03:08:54.814238 2026] [security2:error] [pid 509915:tid 510092] [client 20.63.81.20:52382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/giodywky.php"] [unique_id "apPlFs2gn1q0xw8Wp-TT-AAABWA"]
[Sun Aug 30 03:08:54.854087 2026] [authz_core:error] [pid 509172:tid 509375] [client 66.249.66.199:45166] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:54.854364 2026] [authz_core:error] [pid 509172:tid 509375] [client 66.249.66.199:45166] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:54.874961 2026] [security2:error] [pid 509915:tid 510151] [client 20.48.160.90:40024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp-includes/style-engine/gecko-new.php"] [unique_id "apPlFs2gn1q0xw8Wp-TUEAAABZs"]
[Sun Aug 30 03:08:54.941904 2026] [security2:error] [pid 509172:tid 509390] [client 20.63.81.20:52360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp-kz.php"] [unique_id "apPlFpwMiz5K1he2FnkCKQAAAeU"]
[Sun Aug 30 03:08:54.947447 2026] [security2:error] [pid 509172:tid 509366] [client 20.48.250.41:61235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/w1px.php"] [unique_id "apPlFpwMiz5K1he2FnkCKwAAAc0"]
[Sun Aug 30 03:08:54.979466 2026] [security2:error] [pid 509172:tid 509373] [client 68.155.159.216:54400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/images/index.php"] [unique_id "apPlFpwMiz5K1he2FnkCSQAAAdQ"]
[Sun Aug 30 03:08:54.988309 2026] [security2:error] [pid 509172:tid 509385] [client 68.155.159.216:45980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/content.php"] [unique_id "apPlFpwMiz5K1he2FnkCTwAAAeA"]
[Sun Aug 30 03:08:55.016470 2026] [security2:error] [pid 509172:tid 509386] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/project/.env"] [unique_id "apPlF5wMiz5K1he2FnkCZgAAAeE"]
[Sun Aug 30 03:08:55.027317 2026] [security2:error] [pid 509172:tid 509358] [client 20.48.160.90:39950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp-settings.php"] [unique_id "apPlF5wMiz5K1he2FnkCdwAAAcU"]
[Sun Aug 30 03:08:55.041205 2026] [authz_core:error] [pid 509172:tid 509326] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:55.041516 2026] [authz_core:error] [pid 509172:tid 509326] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:55.064490 2026] [authz_core:error] [pid 509172:tid 509422] [client 66.249.66.205:47582] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:55.064849 2026] [authz_core:error] [pid 509172:tid 509422] [client 66.249.66.205:47582] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:55.073232 2026] [security2:error] [pid 510357:tid 510554] [client 20.63.81.20:52720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp-includes/ID3/getid.php"] [unique_id "apPlF35YTqJxoOZUSXtBugAABfY"]
[Sun Aug 30 03:08:55.087605 2026] [security2:error] [pid 509172:tid 509405] [client 4.205.62.107:17288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/rem.php"] [unique_id "apPlF5wMiz5K1he2FnkCpgAAAfQ"]
[Sun Aug 30 03:08:55.089665 2026] [security2:error] [pid 509915:tid 510104] [client 20.48.250.41:61189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/to.php"] [unique_id "apPlF82gn1q0xw8Wp-TUbQAABWw"]
[Sun Aug 30 03:08:55.113886 2026] [security2:error] [pid 509172:tid 509307] [client 4.205.62.107:61777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/sale.php"] [unique_id "apPlF5wMiz5K1he2FnkCtgAAAZI"]
[Sun Aug 30 03:08:55.117882 2026] [security2:error] [pid 509172:tid 509384] [client 68.155.159.216:62068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apPlF5wMiz5K1he2FnkCtwAAAd8"]
[Sun Aug 30 03:08:55.141509 2026] [security2:error] [pid 509172:tid 509371] [client 158.158.54.35:34899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/GOD.php"] [unique_id "apPlF5wMiz5K1he2FnkCxQAAAdI"]
[Sun Aug 30 03:08:55.182829 2026] [security2:error] [pid 509172:tid 509410] [client 20.48.160.90:45944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp-signup.php"] [unique_id "apPlF5wMiz5K1he2FnkC2AAAAfk"]
[Sun Aug 30 03:08:55.197184 2026] [security2:error] [pid 509172:tid 509425] [client 20.48.251.3:59480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/saiga.php"] [unique_id "apPlF5wMiz5K1he2FnkC5gAAAgg"]
[Sun Aug 30 03:08:55.198757 2026] [security2:error] [pid 509172:tid 509350] [client 20.63.81.20:52608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/session.php"] [unique_id "apPlF5wMiz5K1he2FnkC6AAAAb0"]
[Sun Aug 30 03:08:55.199905 2026] [security2:error] [pid 509915:tid 510107] [client 20.104.49.130:26635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/ops.php"] [unique_id "apPlF82gn1q0xw8Wp-TUhwAABW8"]
[Sun Aug 30 03:08:55.204485 2026] [security2:error] [pid 509915:tid 510073] [client 20.104.18.15:35166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/w3lls.php"] [unique_id "apPlF82gn1q0xw8Wp-TUiQAABU0"]
[Sun Aug 30 03:08:55.223193 2026] [security2:error] [pid 510357:tid 510525] [client 20.48.250.41:61266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/thui.php"] [unique_id "apPlF35YTqJxoOZUSXtBxQAABdk"]
[Sun Aug 30 03:08:55.240204 2026] [security2:error] [pid 509172:tid 509379] [client 20.104.18.15:1950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/8.php"] [unique_id "apPlF5wMiz5K1he2FnkDAgAAAdo"]
[Sun Aug 30 03:08:55.268043 2026] [security2:error] [pid 509172:tid 509319] [client 20.104.50.220:47055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/aj.php"] [unique_id "apPlF5wMiz5K1he2FnkDFAAAAZ4"]
[Sun Aug 30 03:08:55.276612 2026] [security2:error] [pid 509172:tid 509384] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/admin-panel/.env"] [unique_id "apPlF5wMiz5K1he2FnkDGwAAAd8"]
[Sun Aug 30 03:08:55.307841 2026] [authz_core:error] [pid 509172:tid 509349] [client 66.249.66.199:63267] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:55.308385 2026] [authz_core:error] [pid 509172:tid 509349] [client 66.249.66.199:63267] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:55.314675 2026] [security2:error] [pid 509915:tid 510092] [client 20.48.160.90:45832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp-conffg.php"] [unique_id "apPlF82gn1q0xw8Wp-TUwQAABWA"]
[Sun Aug 30 03:08:55.316289 2026] [security2:error] [pid 510357:tid 510534] [client 20.104.18.15:34634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/wp-trackback.php"] [unique_id "apPlF35YTqJxoOZUSXtBzQAABeI"]
[Sun Aug 30 03:08:55.324357 2026] [security2:error] [pid 509172:tid 509310] [client 74.248.24.12:15247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/bypass.php7"] [unique_id "apPlF5wMiz5K1he2FnkDQgAAAZU"]
[Sun Aug 30 03:08:55.327466 2026] [security2:error] [pid 509172:tid 509337] [client 20.104.49.130:60668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/red.php"] [unique_id "apPlF5wMiz5K1he2FnkDRQAAAbA"]
[Sun Aug 30 03:08:55.329017 2026] [security2:error] [pid 509172:tid 509395] [client 20.63.81.20:52368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/eagle.php"] [unique_id "apPlF5wMiz5K1he2FnkDRgAAAeo"]
[Sun Aug 30 03:08:55.352165 2026] [security2:error] [pid 509915:tid 510128] [client 20.48.250.41:60519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/Jcrop.php"] [unique_id "apPlF82gn1q0xw8Wp-TUxwAABYQ"]
[Sun Aug 30 03:08:55.359367 2026] [security2:error] [pid 509915:tid 510151] [client 20.104.50.220:63508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/Sh3ll.php"] [unique_id "apPlF82gn1q0xw8Wp-TUygAABZs"]
[Sun Aug 30 03:08:55.388186 2026] [security2:error] [pid 509172:tid 509335] [client 20.104.50.220:5624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/blog/wp-admin/install.php"] [unique_id "apPlF5wMiz5K1he2FnkDXwAAAa4"]
[Sun Aug 30 03:08:55.448085 2026] [security2:error] [pid 509172:tid 509332] [client 20.48.160.90:40035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp-validate.php"] [unique_id "apPlF5wMiz5K1he2FnkDjgAAAas"]
[Sun Aug 30 03:08:55.455764 2026] [security2:error] [pid 509915:tid 510081] [client 20.63.81.20:52686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/up-kon.php"] [unique_id "apPlF82gn1q0xw8Wp-TU9AAABVU"]
[Sun Aug 30 03:08:55.457067 2026] [security2:error] [pid 509172:tid 509418] [client 20.104.18.15:18379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/wp-includes/index.php"] [unique_id "apPlF5wMiz5K1he2FnkDkgAAAgE"]
[Sun Aug 30 03:08:55.467102 2026] [security2:error] [pid 509172:tid 509322] [client 20.151.200.44:46028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/wp-login.php"] [unique_id "apPlF5wMiz5K1he2FnkDlgAAAaE"]
[Sun Aug 30 03:08:55.480286 2026] [security2:error] [pid 509915:tid 510130] [client 4.205.62.107:35992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/maxro.php"] [unique_id "apPlF82gn1q0xw8Wp-TU_QAABYY"]
[Sun Aug 30 03:08:55.482696 2026] [security2:error] [pid 509172:tid 509404] [client 20.48.250.41:61248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/ws58.php"] [unique_id "apPlF5wMiz5K1he2FnkDogAAAfM"]
[Sun Aug 30 03:08:55.495419 2026] [authz_core:error] [pid 509172:tid 509339] [client 66.249.66.78:47793] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:55.495917 2026] [authz_core:error] [pid 509172:tid 509339] [client 66.249.66.78:47793] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:55.518556 2026] [security2:error] [pid 509172:tid 509391] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/control-panel/.env"] [unique_id "apPlF5wMiz5K1he2FnkDtgAAAeY"]
[Sun Aug 30 03:08:55.566076 2026] [authz_core:error] [pid 509172:tid 509373] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:55.566375 2026] [authz_core:error] [pid 509172:tid 509373] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:55.570525 2026] [security2:error] [pid 509172:tid 509408] [client 20.104.50.220:33567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/madspotshell.php"] [unique_id "apPlF5wMiz5K1he2FnkD1QAAAfc"]
[Sun Aug 30 03:08:55.581563 2026] [security2:error] [pid 509915:tid 510098] [client 20.48.160.90:45933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/700.php"] [unique_id "apPlF82gn1q0xw8Wp-TVMQAABWY"]
[Sun Aug 30 03:08:55.590601 2026] [security2:error] [pid 509172:tid 509421] [client 20.104.50.220:31877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wb.php"] [unique_id "apPlF5wMiz5K1he2FnkD2wAAAgQ"]
[Sun Aug 30 03:08:55.595576 2026] [security2:error] [pid 509915:tid 510103] [client 20.63.81.20:52376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/tinny.php"] [unique_id "apPlF82gn1q0xw8Wp-TVNgAABWs"]
[Sun Aug 30 03:08:55.596068 2026] [security2:error] [pid 509172:tid 509327] [client 158.158.54.35:34918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/depotcv.php"] [unique_id "apPlF5wMiz5K1he2FnkD3wAAAaY"]
[Sun Aug 30 03:08:55.604077 2026] [security2:error] [pid 509915:tid 510056] [client 20.104.18.15:43980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/ajax.php"] [unique_id "apPlF82gn1q0xw8Wp-TVOAAABTw"]
[Sun Aug 30 03:08:55.606585 2026] [security2:error] [pid 509172:tid 509341] [client 20.104.18.15:23460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/gjewuagf.php"] [unique_id "apPlF5wMiz5K1he2FnkD6QAAAbQ"]
[Sun Aug 30 03:08:55.613571 2026] [security2:error] [pid 509172:tid 509353] [client 20.104.50.220:61646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/themes/authentic/gud.php/themes/antioch/shell.php"] [unique_id "apPlF5wMiz5K1he2FnkD7QAAAcA"]
[Sun Aug 30 03:08:55.615870 2026] [security2:error] [pid 509915:tid 510141] [client 20.104.50.220:28727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/12j.php"] [unique_id "apPlF82gn1q0xw8Wp-TVPgAABZE"]
[Sun Aug 30 03:08:55.636917 2026] [security2:error] [pid 509172:tid 509330] [client 20.48.250.41:61197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/xs.php"] [unique_id "apPlF5wMiz5K1he2FnkD-wAAAak"]
[Sun Aug 30 03:08:55.671109 2026] [security2:error] [pid 510357:tid 510555] [client 143.110.213.72:43924] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "mail.anantiapolytechnic.ng"] [uri "/wp-json/batch/v1"] [unique_id "apPlF35YTqJxoOZUSXtB7gAABfc"]
[Sun Aug 30 03:08:55.679045 2026] [security2:error] [pid 509172:tid 509317] [client 20.104.50.220:17217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/dr.php"] [unique_id "apPlF5wMiz5K1he2FnkEAwAAAZw"]
[Sun Aug 30 03:08:55.691457 2026] [security2:error] [pid 509172:tid 509392] [client 20.104.50.220:64450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/v5.php"] [unique_id "apPlF5wMiz5K1he2FnkEDwAAAec"]
[Sun Aug 30 03:08:55.709713 2026] [security2:error] [pid 509915:tid 510152] [client 20.48.160.90:45913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/c4.php"] [unique_id "apPlF82gn1q0xw8Wp-TVXgAABZw"]
[Sun Aug 30 03:08:55.721598 2026] [security2:error] [pid 509915:tid 510092] [client 20.63.81.20:52617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp-easy.php"] [unique_id "apPlF82gn1q0xw8Wp-TVaQAABWA"]
[Sun Aug 30 03:08:55.721948 2026] [security2:error] [pid 509172:tid 509365] [client 20.104.50.220:32880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/sa.php"] [unique_id "apPlF5wMiz5K1he2FnkEIgAAAcw"]
[Sun Aug 30 03:08:55.737619 2026] [authz_core:error] [pid 509915:tid 510082] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:55.737970 2026] [authz_core:error] [pid 509915:tid 510082] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:55.738086 2026] [security2:error] [pid 510357:tid 510496] [client 20.151.200.44:55740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/wp-ver.php"] [unique_id "apPlF35YTqJxoOZUSXtB9QAABbw"]
[Sun Aug 30 03:08:55.760282 2026] [security2:error] [pid 509172:tid 509372] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/user-panel/.env"] [unique_id "apPlF5wMiz5K1he2FnkEOwAAAdM"]
[Sun Aug 30 03:08:55.780212 2026] [security2:error] [pid 509172:tid 509323] [client 20.48.250.41:61269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/zu.php"] [unique_id "apPlF5wMiz5K1he2FnkERQAAAaI"]
[Sun Aug 30 03:08:55.782689 2026] [security2:error] [pid 510357:tid 510598] [client 20.48.251.3:60516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/setup-config.php"] [unique_id "apPlF35YTqJxoOZUSXtB-wAABiI"]
[Sun Aug 30 03:08:55.827900 2026] [security2:error] [pid 510357:tid 510568] [client 20.48.251.3:59278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/ebahvhhh.php"] [unique_id "apPlF35YTqJxoOZUSXtCAAAABgQ"]
[Sun Aug 30 03:08:55.838013 2026] [security2:error] [pid 510357:tid 510493] [client 74.248.24.12:5826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/colour.php"] [unique_id "apPlF35YTqJxoOZUSXtCBAAABbk"]
[Sun Aug 30 03:08:55.845342 2026] [security2:error] [pid 509915:tid 510144] [client 20.48.160.90:45847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp-tymanage.php"] [unique_id "apPlF82gn1q0xw8Wp-TVpwAABZQ"]
[Sun Aug 30 03:08:55.862916 2026] [security2:error] [pid 510357:tid 510551] [client 20.63.81.20:52615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/d7.php"] [unique_id "apPlF35YTqJxoOZUSXtCBwAABfM"]
[Sun Aug 30 03:08:55.868887 2026] [security2:error] [pid 509172:tid 509427] [client 4.205.62.107:62459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/cache-compat.php"] [unique_id "apPlF5wMiz5K1he2FnkEYQAAAgo"]
[Sun Aug 30 03:08:55.869925 2026] [security2:error] [pid 510357:tid 510525] [client 20.48.251.3:64496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/params.php"] [unique_id "apPlF35YTqJxoOZUSXtCCwAABdk"]
[Sun Aug 30 03:08:55.883551 2026] [security2:error] [pid 509172:tid 509335] [client 216.73.216.128:28214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/topics.html"] [unique_id "apPlF5wMiz5K1he2FnkEZgAAAa4"]
[Sun Aug 30 03:08:55.915687 2026] [authz_core:error] [pid 509915:tid 510078] [client 66.249.66.72:54009] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:55.915963 2026] [authz_core:error] [pid 509915:tid 510078] [client 66.249.66.72:54009] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:55.924135 2026] [security2:error] [pid 509915:tid 510126] [client 20.48.250.41:61282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/lanka.php"] [unique_id "apPlF82gn1q0xw8Wp-TV0QAABYI"]
[Sun Aug 30 03:08:55.976070 2026] [security2:error] [pid 509172:tid 509323] [client 216.73.216.128:57762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/ourcollection_images/wp-admin/css/install.css"] [unique_id "apPlF5wMiz5K1he2FnkEfQAAAaI"]
[Sun Aug 30 03:08:55.990953 2026] [security2:error] [pid 509915:tid 510119] [client 20.63.81.20:52367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/v5.php"] [unique_id "apPlF82gn1q0xw8Wp-TV9wAABXs"]
[Sun Aug 30 03:08:55.997871 2026] [security2:error] [pid 509172:tid 509311] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/node/.env"] [unique_id "apPlF5wMiz5K1he2FnkEhAAAAZY"]
[Sun Aug 30 03:08:56.001991 2026] [security2:error] [pid 509915:tid 510104] [client 20.48.160.90:45859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/ajfto.php"] [unique_id "apPlGM2gn1q0xw8Wp-TWAAAABWw"]
[Sun Aug 30 03:08:56.044997 2026] [security2:error] [pid 510357:tid 510542] [client 158.158.54.35:9572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/amaxx.php"] [unique_id "apPlGH5YTqJxoOZUSXtCNAAABeo"]
[Sun Aug 30 03:08:56.052737 2026] [security2:error] [pid 509915:tid 510171] [client 20.48.250.41:61219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/gettest.php"] [unique_id "apPlGM2gn1q0xw8Wp-TWDQAABa8"]
[Sun Aug 30 03:08:56.068293 2026] [authz_core:error] [pid 510357:tid 510527] [client 66.249.66.193:35492] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:56.068558 2026] [authz_core:error] [pid 510357:tid 510527] [client 66.249.66.193:35492] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:56.078651 2026] [security2:error] [pid 509915:tid 509960] [remote 165.227.105.233:46462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.227.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "onestoptestshop.com"] [uri "/wp-login.php"] [unique_id "apPlGM2gn1q0xw8Wp-TWIwAFhSs"]
[Sun Aug 30 03:08:56.080745 2026] [authz_core:error] [pid 509172:tid 509365] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:56.081192 2026] [authz_core:error] [pid 509172:tid 509365] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:08:56.111361 2026] [security2:error] [pid 509915:tid 510140] [client 68.155.159.216:45890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPlGM2gn1q0xw8Wp-TWQQAABZA"]
[Sun Aug 30 03:08:56.113093 2026] [authz_core:error] [pid 510357:tid 510578] [client 66.249.66.41:35278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:56.113376 2026] [authz_core:error] [pid 510357:tid 510578] [client 66.249.66.41:35278] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:56.116074 2026] [security2:error] [pid 509915:tid 510103] [client 20.63.81.20:52397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/az.php"] [unique_id "apPlGM2gn1q0xw8Wp-TWQwAABWs"]
[Sun Aug 30 03:08:56.158374 2026] [security2:error] [pid 509172:tid 509322] [client 20.48.160.90:45827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp_KwIW0U5F.php"] [unique_id "apPlGJwMiz5K1he2FnkEwAAAAaE"]
[Sun Aug 30 03:08:56.194876 2026] [security2:error] [pid 509915:tid 510133] [client 20.48.250.41:60449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/35.php"] [unique_id "apPlGM2gn1q0xw8Wp-TWbQAABYk"]
[Sun Aug 30 03:08:56.194977 2026] [security2:error] [pid 509915:tid 510099] [client 68.155.159.216:54224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apPlGM2gn1q0xw8Wp-TWbgAABWc"]
[Sun Aug 30 03:08:56.222366 2026] [security2:error] [pid 509915:tid 510111] [client 20.104.49.130:59569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/well.php"] [unique_id "apPlGM2gn1q0xw8Wp-TWewAABXM"]
[Sun Aug 30 03:08:56.226519 2026] [security2:error] [pid 509172:tid 509337] [client 4.205.62.107:17296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/min.php"] [unique_id "apPlGJwMiz5K1he2FnkE6AAAAbA"]
[Sun Aug 30 03:08:56.234916 2026] [security2:error] [pid 509172:tid 509415] [client 20.104.49.130:53717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/read.php"] [unique_id "apPlGJwMiz5K1he2FnkE7AAAAf4"]
[Sun Aug 30 03:08:56.241126 2026] [security2:error] [pid 509172:tid 509386] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/express/.env"] [unique_id "apPlGJwMiz5K1he2FnkE7wAAAeE"]
[Sun Aug 30 03:08:56.247664 2026] [security2:error] [pid 509915:tid 510092] [client 20.63.81.20:52704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/js.php"] [unique_id "apPlGM2gn1q0xw8Wp-TWgwAABWA"]
[Sun Aug 30 03:08:56.253326 2026] [security2:error] [pid 509915:tid 509961] [remote 165.227.105.233:46462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.105.227.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "onestoptestshop.com"] [uri "/wp-login.php"] [unique_id "apPlGM2gn1q0xw8Wp-TWhwAFOSw"], referer: https://onestoptestshop.com/wp-login.php
[Sun Aug 30 03:08:56.262308 2026] [security2:error] [pid 509915:tid 510135] [client 4.205.62.107:64643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/wp-class.php"] [unique_id "apPlGM2gn1q0xw8Wp-TWiQAABYs"]
[Sun Aug 30 03:08:56.271312 2026] [security2:error] [pid 509172:tid 509376] [client 20.220.204.93:59075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlGJwMiz5K1he2FnkFBwAAAdc"]
[Sun Aug 30 03:08:56.287347 2026] [security2:error] [pid 509172:tid 509403] [client 20.48.160.90:26701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp_xiPu52Ut.php"] [unique_id "apPlGJwMiz5K1he2FnkFGgAAAfI"]
[Sun Aug 30 03:08:56.338658 2026] [security2:error] [pid 509915:tid 510131] [client 20.104.18.15:35478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/fpwch.php"] [unique_id "apPlGM2gn1q0xw8Wp-TWtAAABYc"]
[Sun Aug 30 03:08:56.338878 2026] [security2:error] [pid 509915:tid 510102] [client 74.248.24.12:2057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/fm2.php"] [unique_id "apPlGM2gn1q0xw8Wp-TWtQAABWo"]
[Sun Aug 30 03:08:56.347691 2026] [authz_core:error] [pid 510357:tid 510573] [client 216.73.216.128:6795] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:56.348165 2026] [authz_core:error] [pid 510357:tid 510573] [client 216.73.216.128:6795] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:56.348358 2026] [security2:error] [pid 509172:tid 509416] [client 20.48.250.41:60527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/maraz.php"] [unique_id "apPlGJwMiz5K1he2FnkFSgAAAf8"]
[Sun Aug 30 03:08:56.380089 2026] [security2:error] [pid 509915:tid 510070] [client 20.63.81.20:52390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/hd.php"] [unique_id "apPlGM2gn1q0xw8Wp-TWvQAABUo"]
[Sun Aug 30 03:08:56.394760 2026] [security2:error] [pid 509172:tid 509415] [client 20.104.18.15:1999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/ws55.php"] [unique_id "apPlGJwMiz5K1he2FnkFZQAAAf4"]
[Sun Aug 30 03:08:56.402970 2026] [security2:error] [pid 509172:tid 509398] [client 20.220.204.93:59062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlGJwMiz5K1he2FnkFbAAAAe0"]
[Sun Aug 30 03:08:56.418920 2026] [security2:error] [pid 509172:tid 509429] [client 20.48.160.90:39951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp_n5VD7XDh.php"] [unique_id "apPlGJwMiz5K1he2FnkFdwAAAgw"]
[Sun Aug 30 03:08:56.419351 2026] [security2:error] [pid 509172:tid 509338] [client 20.104.49.130:53519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/xa.php"] [unique_id "apPlGJwMiz5K1he2FnkFeAAAAbE"]
[Sun Aug 30 03:08:56.428468 2026] [security2:error] [pid 510357:tid 510615] [client 20.104.50.220:46875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/opts.php"] [unique_id "apPlGH5YTqJxoOZUSXtCfwAABjM"]
[Sun Aug 30 03:08:56.440091 2026] [security2:error] [pid 509915:tid 510048] [client 20.48.251.3:59472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/ammika.php"] [unique_id "apPlGM2gn1q0xw8Wp-TW1AAABTQ"]
[Sun Aug 30 03:08:56.464212 2026] [security2:error] [pid 509172:tid 509363] [client 20.104.18.15:34704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/pri.php"] [unique_id "apPlGJwMiz5K1he2FnkFmAAAAco"]
[Sun Aug 30 03:08:56.477215 2026] [security2:error] [pid 509172:tid 509367] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/next/.env"] [unique_id "apPlGJwMiz5K1he2FnkFqgAAAc4"]
[Sun Aug 30 03:08:56.488079 2026] [security2:error] [pid 509915:tid 510096] [client 158.158.54.35:34891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/02.php"] [unique_id "apPlGM2gn1q0xw8Wp-TW6QAABWQ"]
[Sun Aug 30 03:08:56.509294 2026] [security2:error] [pid 509172:tid 509346] [client 20.104.50.220:42025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/new.php"] [unique_id "apPlGJwMiz5K1he2FnkFygAAAbk"]
[Sun Aug 30 03:08:56.509466 2026] [security2:error] [pid 509915:tid 510052] [client 20.63.81.20:52394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/xl2023.php"] [unique_id "apPlGM2gn1q0xw8Wp-TW9AAABTg"]
[Sun Aug 30 03:08:56.521703 2026] [security2:error] [pid 509172:tid 509382] [client 20.48.250.41:61212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/kbfr.php"] [unique_id "apPlGJwMiz5K1he2FnkF0QAAAd0"]
[Sun Aug 30 03:08:56.529751 2026] [security2:error] [pid 509915:tid 510155] [client 20.104.50.220:5537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/e.php"] [unique_id "apPlGM2gn1q0xw8Wp-TW-wAABZ8"]
[Sun Aug 30 03:08:56.567845 2026] [security2:error] [pid 509172:tid 509308] [client 20.48.160.90:40018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp-mini.php"] [unique_id "apPlGJwMiz5K1he2FnkF9AAAAZM"]
[Sun Aug 30 03:08:56.570268 2026] [security2:error] [pid 509172:tid 509407] [client 20.220.204.93:59099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/ff1.php"] [unique_id "apPlGJwMiz5K1he2FnkF9QAAAfY"]
[Sun Aug 30 03:08:56.596843 2026] [authz_core:error] [pid 509172:tid 509340] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:08:56.597132 2026] [authz_core:error] [pid 509172:tid 509340] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:08:56.612248 2026] [security2:error] [pid 509172:tid 509320] [client 20.104.18.15:18344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/file31.php"] [unique_id "apPlGJwMiz5K1he2FnkGBwAAAZ8"]
[Sun Aug 30 03:08:56.630890 2026] [security2:error] [pid 509172:tid 509363] [client 4.205.62.107:36006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/brc.php"] [unique_id "apPlGJwMiz5K1he2FnkGEQAAAco"]
[Sun Aug 30 03:08:56.635667 2026] [security2:error] [pid 509915:tid 510091] [client 20.63.81.20:52734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/V2.php"] [unique_id "apPlGM2gn1q0xw8Wp-TXGwAABV8"]
[Sun Aug 30 03:08:56.652026 2026] [authz_core:error] [pid 509172:tid 509376] [client 66.249.66.199:45166] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:56.652321 2026] [authz_core:error] [pid 509172:tid 509376] [client 66.249.66.199:45166] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:56.658699 2026] [security2:error] [pid 509915:tid 510112] [client 20.48.250.41:60427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/wp-act.php"] [unique_id "apPlGM2gn1q0xw8Wp-TXIAAABXQ"]
[Sun Aug 30 03:08:56.709801 2026] [security2:error] [pid 509915:tid 510062] [client 20.48.160.90:45837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/xmini4.php"] [unique_id "apPlGM2gn1q0xw8Wp-TXOAAABUI"]
[Sun Aug 30 03:08:56.713985 2026] [authz_core:error] [pid 509172:tid 509426] [client 216.73.216.128:57762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:56.714532 2026] [authz_core:error] [pid 509172:tid 509426] [client 216.73.216.128:57762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:56.719227 2026] [security2:error] [pid 509172:tid 509310] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/nuxt/.env"] [unique_id "apPlGJwMiz5K1he2FnkGQQAAAZU"]
[Sun Aug 30 03:08:56.733079 2026] [security2:error] [pid 509172:tid 509304] [client 20.104.50.220:32066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/file1.php"] [unique_id "apPlGJwMiz5K1he2FnkGUAAAAY8"]
[Sun Aug 30 03:08:56.738426 2026] [security2:error] [pid 509172:tid 509377] [client 68.155.159.216:53478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPlGJwMiz5K1he2FnkGVQAAAdg"]
[Sun Aug 30 03:08:56.758288 2026] [security2:error] [pid 510357:tid 510617] [client 20.151.200.44:57913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/pb.php"] [unique_id "apPlGH5YTqJxoOZUSXtCmQAABjU"]
[Sun Aug 30 03:08:56.760067 2026] [security2:error] [pid 509915:tid 510119] [client 20.104.18.15:23472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/tnglzqmv.php"] [unique_id "apPlGM2gn1q0xw8Wp-TXRwAABXs"]
[Sun Aug 30 03:08:56.765214 2026] [security2:error] [pid 509172:tid 509395] [client 20.104.50.220:62790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/danon.php"] [unique_id "apPlGJwMiz5K1he2FnkGcgAAAeo"]
[Sun Aug 30 03:08:56.766441 2026] [security2:error] [pid 510357:tid 510552] [client 20.104.18.15:43983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/atomlib.php"] [unique_id "apPlGH5YTqJxoOZUSXtCmgAABfQ"]
[Sun Aug 30 03:08:56.767718 2026] [security2:error] [pid 509172:tid 509356] [client 20.63.81.20:52711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/mad.php"] [unique_id "apPlGJwMiz5K1he2FnkGdAAAAcM"]
[Sun Aug 30 03:08:56.772670 2026] [security2:error] [pid 509915:tid 510056] [client 20.220.204.93:59107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/t.php"] [unique_id "apPlGM2gn1q0xw8Wp-TXSQAABTw"]
[Sun Aug 30 03:08:56.775808 2026] [security2:error] [pid 509915:tid 510168] [client 20.104.50.220:61412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/and.php"] [unique_id "apPlGM2gn1q0xw8Wp-TXSwAABaw"]
[Sun Aug 30 03:08:56.785033 2026] [security2:error] [pid 509172:tid 509381] [client 20.48.250.41:60496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/24.php"] [unique_id "apPlGJwMiz5K1he2FnkGigAAAdw"]
[Sun Aug 30 03:08:56.818944 2026] [security2:error] [pid 509172:tid 509390] [client 20.104.50.220:16732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/xamp.php"] [unique_id "apPlGJwMiz5K1he2FnkGoAAAAeU"]
[Sun Aug 30 03:08:56.820484 2026] [authz_core:error] [pid 509172:tid 509360] [client 66.249.66.33:41723] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:56.820768 2026] [authz_core:error] [pid 509172:tid 509360] [client 66.249.66.33:41723] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:56.852975 2026] [security2:error] [pid 509915:tid 510114] [client 20.104.50.220:62785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/Unknown45.php"] [unique_id "apPlGM2gn1q0xw8Wp-TXcwAABXY"]
[Sun Aug 30 03:08:56.853304 2026] [security2:error] [pid 509172:tid 509418] [client 20.48.160.90:45926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/reop3.php"] [unique_id "apPlGJwMiz5K1he2FnkGrgAAAgE"]
[Sun Aug 30 03:08:56.862436 2026] [security2:error] [pid 510357:tid 510543] [client 20.104.49.130:43310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/gecko-new.php"] [unique_id "apPlGH5YTqJxoOZUSXtCpAAABes"]
[Sun Aug 30 03:08:56.868005 2026] [security2:error] [pid 510357:tid 510568] [client 20.104.50.220:33290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/noname.php"] [unique_id "apPlGH5YTqJxoOZUSXtCpQAABgQ"]
[Sun Aug 30 03:08:56.884721 2026] [security2:error] [pid 509172:tid 509391] [client 216.73.216.128:28214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPlGJwMiz5K1he2FnkGuQAAAeY"]
[Sun Aug 30 03:08:56.899131 2026] [security2:error] [pid 509915:tid 510054] [client 20.63.81.20:52621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/st.php"] [unique_id "apPlGM2gn1q0xw8Wp-TXgwAABTo"]
[Sun Aug 30 03:08:56.915321 2026] [security2:error] [pid 509915:tid 510150] [client 20.48.251.3:13437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/wp-admin/sc.php"] [unique_id "apPlGM2gn1q0xw8Wp-TXjQAABZo"]
[Sun Aug 30 03:08:56.920888 2026] [security2:error] [pid 510357:tid 510517] [client 20.220.204.93:59017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/erty.php"] [unique_id "apPlGH5YTqJxoOZUSXtCuAAABdE"]
[Sun Aug 30 03:08:56.925684 2026] [security2:error] [pid 509915:tid 510047] [client 20.48.250.41:61295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/155.php"] [unique_id "apPlGM2gn1q0xw8Wp-TXlwAABTM"]
[Sun Aug 30 03:08:56.935619 2026] [security2:error] [pid 509172:tid 509359] [client 158.158.54.35:6512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/csv.php"] [unique_id "apPlGJwMiz5K1he2FnkGzwAAAcY"]
[Sun Aug 30 03:08:56.936920 2026] [security2:error] [pid 509915:tid 510161] [client 74.248.24.12:7575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/4price.php"] [unique_id "apPlGM2gn1q0xw8Wp-TXngAABaU"]
[Sun Aug 30 03:08:56.968187 2026] [security2:error] [pid 509172:tid 509418] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/nest/.env"] [unique_id "apPlGJwMiz5K1he2FnkG3wAAAgE"]
[Sun Aug 30 03:08:56.977445 2026] [authz_core:error] [pid 509915:tid 510100] [client 66.249.66.69:64064] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:56.977909 2026] [authz_core:error] [pid 509915:tid 510100] [client 66.249.66.69:64064] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:56.980765 2026] [security2:error] [pid 509172:tid 509343] [client 20.48.251.3:55758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/asa.php"] [unique_id "apPlGJwMiz5K1he2FnkG7AAAAbY"]
[Sun Aug 30 03:08:56.984950 2026] [authz_core:error] [pid 509172:tid 509340] [client 216.73.216.128:35630] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:56.985413 2026] [authz_core:error] [pid 509172:tid 509340] [client 216.73.216.128:35630] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:56.987575 2026] [security2:error] [pid 509172:tid 509370] [client 20.48.160.90:45846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp-mail.php"] [unique_id "apPlGJwMiz5K1he2FnkG8QAAAdE"]
[Sun Aug 30 03:08:57.031871 2026] [security2:error] [pid 509915:tid 510155] [client 20.63.81.20:52722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/alfanew.php"] [unique_id "apPlGc2gn1q0xw8Wp-TX2wAABZ8"]
[Sun Aug 30 03:08:57.036996 2026] [security2:error] [pid 509915:tid 510081] [client 4.205.62.107:22944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/aws_keys.php"] [unique_id "apPlGc2gn1q0xw8Wp-TX4QAABVU"]
[Sun Aug 30 03:08:57.044059 2026] [authz_core:error] [pid 509172:tid 509321] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:08:57.044334 2026] [authz_core:error] [pid 509172:tid 509321] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:08:57.053569 2026] [security2:error] [pid 509172:tid 509363] [client 20.220.204.93:59097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/0x.php"] [unique_id "apPlGZwMiz5K1he2FnkHPAAAAco"]
[Sun Aug 30 03:08:57.061020 2026] [security2:error] [pid 509172:tid 509407] [client 20.48.251.3:64466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/gjm.php"] [unique_id "apPlGZwMiz5K1he2FnkHQQAAAfY"]
[Sun Aug 30 03:08:57.091823 2026] [security2:error] [pid 509172:tid 509323] [client 20.48.250.41:61201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/file.php"] [unique_id "apPlGZwMiz5K1he2FnkHXQAAAaI"]
[Sun Aug 30 03:08:57.126293 2026] [security2:error] [pid 509172:tid 509399] [client 20.48.160.90:45872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp-conffg.php"] [unique_id "apPlGZwMiz5K1he2FnkHbwAAAe4"]
[Sun Aug 30 03:08:57.133016 2026] [authz_core:error] [pid 509915:tid 510122] [client 66.249.66.192:37331] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:57.133457 2026] [authz_core:error] [pid 509915:tid 510122] [client 66.249.66.192:37331] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:57.157856 2026] [security2:error] [pid 509172:tid 509428] [client 20.63.81.20:52406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/ioxi.php"] [unique_id "apPlGZwMiz5K1he2FnkHfQAAAgs"]
[Sun Aug 30 03:08:57.165476 2026] [authz_core:error] [pid 509915:tid 510047] [client 216.73.216.128:55539] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:57.165763 2026] [authz_core:error] [pid 509915:tid 510047] [client 216.73.216.128:55539] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:57.178555 2026] [authz_core:error] [pid 509915:tid 510117] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:57.178983 2026] [authz_core:error] [pid 509915:tid 510117] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:57.191607 2026] [authz_core:error] [pid 509172:tid 509422] [client 66.249.66.70:36129] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:57.191914 2026] [authz_core:error] [pid 509172:tid 509422] [client 66.249.66.70:36129] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:57.213333 2026] [security2:error] [pid 509172:tid 509326] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/react/.env"] [unique_id "apPlGZwMiz5K1he2FnkHnQAAAaU"]
[Sun Aug 30 03:08:57.216794 2026] [security2:error] [pid 509172:tid 509415] [client 20.220.204.93:59038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/66.php"] [unique_id "apPlGZwMiz5K1he2FnkHnwAAAf4"]
[Sun Aug 30 03:08:57.235447 2026] [security2:error] [pid 509172:tid 509418] [client 20.48.250.41:61262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPlGZwMiz5K1he2FnkHqAAAAgE"]
[Sun Aug 30 03:08:57.245294 2026] [authz_core:error] [pid 509172:tid 509322] [client 66.249.66.36:59562] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:57.245773 2026] [authz_core:error] [pid 509172:tid 509322] [client 66.249.66.36:59562] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:57.266743 2026] [security2:error] [pid 509915:tid 510137] [client 20.48.160.90:40013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/filefuns.php"] [unique_id "apPlGc2gn1q0xw8Wp-TYKAAABY0"]
[Sun Aug 30 03:08:57.285583 2026] [security2:error] [pid 509915:tid 510083] [client 20.63.81.20:52707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/TNT.php"] [unique_id "apPlGc2gn1q0xw8Wp-TYNgAABVc"]
[Sun Aug 30 03:08:57.362184 2026] [security2:error] [pid 509915:tid 510129] [client 20.48.250.41:61294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/06.php"] [unique_id "apPlGc2gn1q0xw8Wp-TYVgAABYU"]
[Sun Aug 30 03:08:57.363405 2026] [security2:error] [pid 509915:tid 510065] [client 20.220.204.93:59056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/f35.php"] [unique_id "apPlGc2gn1q0xw8Wp-TYWAAABUU"]
[Sun Aug 30 03:08:57.366170 2026] [security2:error] [pid 509172:tid 509360] [client 4.205.62.107:17114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/saiga.php"] [unique_id "apPlGZwMiz5K1he2FnkIFgAAAcc"]
[Sun Aug 30 03:08:57.396145 2026] [security2:error] [pid 509172:tid 509313] [client 20.48.160.90:45929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp-cron.php"] [unique_id "apPlGZwMiz5K1he2FnkIJAAAAZg"]
[Sun Aug 30 03:08:57.414845 2026] [security2:error] [pid 509172:tid 509408] [client 158.158.54.35:28044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/curl.php"] [unique_id "apPlGZwMiz5K1he2FnkILQAAAfc"]
[Sun Aug 30 03:08:57.416194 2026] [security2:error] [pid 509915:tid 510057] [client 20.63.81.20:52714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/cd.php"] [unique_id "apPlGc2gn1q0xw8Wp-TYZgAABT0"]
[Sun Aug 30 03:08:57.418111 2026] [security2:error] [pid 509915:tid 510054] [client 4.205.62.107:64677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/database.php"] [unique_id "apPlGc2gn1q0xw8Wp-TYagAABTo"]
[Sun Aug 30 03:08:57.426694 2026] [authz_core:error] [pid 509172:tid 509341] [client 66.249.66.42:47928] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:57.426975 2026] [authz_core:error] [pid 509172:tid 509341] [client 66.249.66.42:47928] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:57.431706 2026] [security2:error] [pid 510357:tid 510568] [client 216.73.216.128:6795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPlGX5YTqJxoOZUSXtC3gAABgQ"]
[Sun Aug 30 03:08:57.470851 2026] [security2:error] [pid 509172:tid 509321] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/vue/.env"] [unique_id "apPlGZwMiz5K1he2FnkIPAAAAaA"]
[Sun Aug 30 03:08:57.484522 2026] [authz_core:error] [pid 509915:tid 510158] [client 66.249.66.196:64554] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:57.484811 2026] [authz_core:error] [pid 509915:tid 510158] [client 66.249.66.196:64554] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:57.486045 2026] [security2:error] [pid 509915:tid 510046] [client 68.155.159.216:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apPlGc2gn1q0xw8Wp-TYmAAABTI"]
[Sun Aug 30 03:08:57.491713 2026] [security2:error] [pid 509915:tid 510067] [client 20.104.18.15:35157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/domvf.php"] [unique_id "apPlGc2gn1q0xw8Wp-TYnQAABUc"]
[Sun Aug 30 03:08:57.492495 2026] [security2:error] [pid 509915:tid 510063] [client 20.48.250.41:61280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/class.php"] [unique_id "apPlGc2gn1q0xw8Wp-TYngAABUM"]
[Sun Aug 30 03:08:57.493673 2026] [security2:error] [pid 509915:tid 510146] [client 68.155.159.216:46059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/goat.php"] [unique_id "apPlGc2gn1q0xw8Wp-TYoQAABZY"]
[Sun Aug 30 03:08:57.525113 2026] [security2:error] [pid 509172:tid 509394] [client 20.220.204.93:59008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/wen.php"] [unique_id "apPlGZwMiz5K1he2FnkIVgAAAek"]
[Sun Aug 30 03:08:57.532146 2026] [security2:error] [pid 509915:tid 510130] [client 20.48.160.90:45950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/lock360.php"] [unique_id "apPlGc2gn1q0xw8Wp-TYwgAABYY"]
[Sun Aug 30 03:08:57.543221 2026] [authz_core:error] [pid 510357:tid 510512] [client 66.249.66.38:41354] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:57.543697 2026] [authz_core:error] [pid 510357:tid 510512] [client 66.249.66.38:41354] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:57.553625 2026] [security2:error] [pid 509172:tid 509418] [client 20.104.18.15:1955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/indo.php"] [unique_id "apPlGZwMiz5K1he2FnkIbQAAAgE"]
[Sun Aug 30 03:08:57.554928 2026] [security2:error] [pid 509172:tid 509417] [client 20.63.81.20:52718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/luuf.php"] [unique_id "apPlGZwMiz5K1he2FnkIbgAAAgA"]
[Sun Aug 30 03:08:57.578406 2026] [security2:error] [pid 509915:tid 510147] [client 20.104.50.220:46167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/filer.php"] [unique_id "apPlGc2gn1q0xw8Wp-TY1AAABZc"]
[Sun Aug 30 03:08:57.586860 2026] [security2:error] [pid 509172:tid 509403] [client 20.48.251.3:59845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/broadcasting.php"] [unique_id "apPlGZwMiz5K1he2FnkIfwAAAfI"]
[Sun Aug 30 03:08:57.594515 2026] [security2:error] [pid 509172:tid 509425] [client 74.248.24.12:6860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/zwso.php"] [unique_id "apPlGZwMiz5K1he2FnkIgQAAAgg"]
[Sun Aug 30 03:08:57.598277 2026] [security2:error] [pid 509915:tid 510160] [client 20.104.18.15:34719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/wp_blog_footer.php"] [unique_id "apPlGc2gn1q0xw8Wp-TY3gAABaQ"]
[Sun Aug 30 03:08:57.619001 2026] [authz_core:error] [pid 509172:tid 509398] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:08:57.619477 2026] [authz_core:error] [pid 509172:tid 509398] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:08:57.620603 2026] [security2:error] [pid 510357:tid 510565] [client 20.48.250.41:61255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/8.php"] [unique_id "apPlGX5YTqJxoOZUSXtDBgAABgE"]
[Sun Aug 30 03:08:57.649899 2026] [security2:error] [pid 509172:tid 509376] [client 20.104.50.220:42778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/Sym.php"] [unique_id "apPlGZwMiz5K1he2FnkImgAAAdc"]
[Sun Aug 30 03:08:57.656142 2026] [security2:error] [pid 509172:tid 509417] [client 20.220.204.93:59082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/inc.php"] [unique_id "apPlGZwMiz5K1he2FnkInAAAAgA"]
[Sun Aug 30 03:08:57.663137 2026] [security2:error] [pid 509172:tid 509354] [client 20.48.160.90:39982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp-theme.php"] [unique_id "apPlGZwMiz5K1he2FnkInwAAAcE"]
[Sun Aug 30 03:08:57.673074 2026] [authz_core:error] [pid 509172:tid 509310] [client 216.73.216.128:28951] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:57.673465 2026] [authz_core:error] [pid 509172:tid 509310] [client 216.73.216.128:28951] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:57.682900 2026] [security2:error] [pid 509172:tid 509412] [client 20.104.50.220:5615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wordpress/wp-admin/install.php"] [unique_id "apPlGZwMiz5K1he2FnkIrQAAAfs"]
[Sun Aug 30 03:08:57.689110 2026] [security2:error] [pid 509915:tid 510148] [client 20.63.81.20:52701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/fex.php"] [unique_id "apPlGc2gn1q0xw8Wp-TY-QAABZg"]
[Sun Aug 30 03:08:57.711229 2026] [security2:error] [pid 509172:tid 509391] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/angular/.env"] [unique_id "apPlGZwMiz5K1he2FnkIwgAAAeY"]
[Sun Aug 30 03:08:57.747505 2026] [security2:error] [pid 509172:tid 509410] [client 20.48.250.41:61275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/0x0x.php"] [unique_id "apPlGZwMiz5K1he2FnkI5AAAAfk"]
[Sun Aug 30 03:08:57.750389 2026] [security2:error] [pid 509172:tid 509383] [client 20.104.18.15:18253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/dk.php"] [unique_id "apPlGZwMiz5K1he2FnkI5wAAAd4"]
[Sun Aug 30 03:08:57.767737 2026] [security2:error] [pid 510357:tid 510550] [client 4.205.62.107:36644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/vx.php"] [unique_id "apPlGX5YTqJxoOZUSXtDCQAABfI"]
[Sun Aug 30 03:08:57.806765 2026] [security2:error] [pid 509172:tid 509338] [client 20.48.160.90:45882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/2d7433/index.php"] [unique_id "apPlGZwMiz5K1he2FnkJGQAAAbE"]
[Sun Aug 30 03:08:57.815459 2026] [security2:error] [pid 509915:tid 509967] [remote 97.74.87.194:43238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "readyerpsolutions.com"] [uri "/wp-login.php"] [unique_id "apPlGc2gn1q0xw8Wp-TZHgAFgTI"]
[Sun Aug 30 03:08:57.823380 2026] [security2:error] [pid 509172:tid 509386] [client 20.63.81.20:52385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/l.php"] [unique_id "apPlGZwMiz5K1he2FnkJJQAAAeE"]
[Sun Aug 30 03:08:57.867035 2026] [authz_core:error] [pid 509172:tid 509373] [client 66.249.66.42:45124] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:57.867298 2026] [authz_core:error] [pid 509172:tid 509373] [client 66.249.66.42:45124] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:57.880736 2026] [security2:error] [pid 509172:tid 509397] [client 20.104.50.220:32112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/gmo.php"] [unique_id "apPlGZwMiz5K1he2FnkJTQAAAew"]
[Sun Aug 30 03:08:57.883163 2026] [security2:error] [pid 509172:tid 509347] [client 158.158.54.35:7531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/cloud.php"] [unique_id "apPlGZwMiz5K1he2FnkJTwAAAbo"]
[Sun Aug 30 03:08:57.887203 2026] [security2:error] [pid 509172:tid 509345] [client 20.220.204.93:59037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/6bcwiqwj.php"] [unique_id "apPlGZwMiz5K1he2FnkJUgAAAbg"]
[Sun Aug 30 03:08:57.889987 2026] [security2:error] [pid 509915:tid 510101] [client 20.48.250.41:61285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/166.php"] [unique_id "apPlGc2gn1q0xw8Wp-TZMwAABWk"]
[Sun Aug 30 03:08:57.903172 2026] [security2:error] [pid 509172:tid 509355] [client 20.104.18.15:23443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/wefile.php"] [unique_id "apPlGZwMiz5K1he2FnkJXAAAAcI"]
[Sun Aug 30 03:08:57.919398 2026] [security2:error] [pid 509915:tid 510128] [client 20.104.18.15:43274] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.robertpitti.it"] [uri "/1.php"] [unique_id "apPlGc2gn1q0xw8Wp-TZQAAABYQ"]
[Sun Aug 30 03:08:57.919507 2026] [security2:error] [pid 509915:tid 510128] [client 20.104.18.15:43274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/1.php"] [unique_id "apPlGc2gn1q0xw8Wp-TZQAAABYQ"]
[Sun Aug 30 03:08:57.933277 2026] [authz_core:error] [pid 510357:tid 510507] [client 66.249.66.65:53577] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:57.933715 2026] [authz_core:error] [pid 510357:tid 510507] [client 66.249.66.65:53577] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:57.939494 2026] [security2:error] [pid 509915:tid 510139] [client 20.104.50.220:29589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/xd.php"] [unique_id "apPlGc2gn1q0xw8Wp-TZSgAABY8"]
[Sun Aug 30 03:08:57.953930 2026] [security2:error] [pid 509915:tid 510089] [client 20.63.81.20:52371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/xr.php"] [unique_id "apPlGc2gn1q0xw8Wp-TZUAAABV0"]
[Sun Aug 30 03:08:57.956008 2026] [security2:error] [pid 509172:tid 509314] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/svelte/.env"] [unique_id "apPlGZwMiz5K1he2FnkJfAAAAZk"]
[Sun Aug 30 03:08:57.956268 2026] [security2:error] [pid 509915:tid 510154] [client 20.104.50.220:17263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/bless.php"] [unique_id "apPlGc2gn1q0xw8Wp-TZUwAABZ4"]
[Sun Aug 30 03:08:57.960449 2026] [security2:error] [pid 509172:tid 509343] [client 20.48.160.90:45941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp-login.php"] [unique_id "apPlGZwMiz5K1he2FnkJegAAAbY"]
[Sun Aug 30 03:08:57.991928 2026] [security2:error] [pid 509915:tid 510063] [client 20.104.50.220:62214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/skizoo.php"] [unique_id "apPlGc2gn1q0xw8Wp-TZaAAABUM"]
[Sun Aug 30 03:08:58.009760 2026] [security2:error] [pid 509172:tid 509368] [client 20.104.50.220:29160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/vinus.php"] [unique_id "apPlGpwMiz5K1he2FnkJnwAAAc8"]
[Sun Aug 30 03:08:58.020871 2026] [security2:error] [pid 509172:tid 509330] [client 20.104.50.220:33202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/kntol.php"] [unique_id "apPlGpwMiz5K1he2FnkJqAAAAak"]
[Sun Aug 30 03:08:58.034062 2026] [security2:error] [pid 509172:tid 509350] [client 20.48.250.41:61196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/h2a2ck.php"] [unique_id "apPlGpwMiz5K1he2FnkJuQAAAb0"]
[Sun Aug 30 03:08:58.034270 2026] [security2:error] [pid 509172:tid 509382] [client 20.220.204.93:59059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/easy.php"] [unique_id "apPlGpwMiz5K1he2FnkJugAAAd0"]
[Sun Aug 30 03:08:58.042594 2026] [authz_core:error] [pid 509172:tid 509407] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:08:58.042980 2026] [authz_core:error] [pid 509172:tid 509407] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:08:58.070104 2026] [security2:error] [pid 509172:tid 509421] [client 20.48.251.3:56320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/debug.php"] [unique_id "apPlGpwMiz5K1he2FnkJ1wAAAgQ"]
[Sun Aug 30 03:08:58.081422 2026] [security2:error] [pid 509915:tid 510169] [client 20.63.81.20:52624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/Q3.php"] [unique_id "apPlGs2gn1q0xw8Wp-TZmwAABa0"]
[Sun Aug 30 03:08:58.110109 2026] [security2:error] [pid 509172:tid 509387] [client 20.48.160.90:45865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/images.php"] [unique_id "apPlGpwMiz5K1he2FnkJ8wAAAeI"]
[Sun Aug 30 03:08:58.120015 2026] [security2:error] [pid 509915:tid 510104] [client 20.48.251.3:55757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/radio.php"] [unique_id "apPlGs2gn1q0xw8Wp-TZrgAABWw"]
[Sun Aug 30 03:08:58.162660 2026] [security2:error] [pid 509915:tid 510083] [client 4.205.62.107:25751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/log.php"] [unique_id "apPlGs2gn1q0xw8Wp-TZvQAABVc"]
[Sun Aug 30 03:08:58.174932 2026] [security2:error] [pid 509915:tid 510123] [client 20.104.49.130:63607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/dragonshell.php"] [unique_id "apPlGs2gn1q0xw8Wp-TZxgAABX8"]
[Sun Aug 30 03:08:58.175606 2026] [security2:error] [pid 510357:tid 510499] [client 20.48.250.41:61249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/error_log.php"] [unique_id "apPlGn5YTqJxoOZUSXtDPAAABb8"]
[Sun Aug 30 03:08:58.186787 2026] [security2:error] [pid 509172:tid 509367] [client 20.220.204.93:59034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/fresh3.php"] [unique_id "apPlGpwMiz5K1he2FnkKFgAAAc4"]
[Sun Aug 30 03:08:58.191397 2026] [security2:error] [pid 509172:tid 509385] [client 4.205.62.107:22586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/umgebung.php"] [unique_id "apPlGpwMiz5K1he2FnkKGgAAAeA"]
[Sun Aug 30 03:08:58.194143 2026] [security2:error] [pid 509172:tid 509418] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/vite/.env"] [unique_id "apPlGpwMiz5K1he2FnkKGwAAAgE"]
[Sun Aug 30 03:08:58.198026 2026] [authz_core:error] [pid 509915:tid 510124] [client 66.249.66.72:54009] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:58.198303 2026] [authz_core:error] [pid 509915:tid 510124] [client 66.249.66.72:54009] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:58.199948 2026] [security2:error] [pid 509915:tid 509969] [remote 97.74.87.194:43238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "readyerpsolutions.com"] [uri "/wp-login.php"] [unique_id "apPlGs2gn1q0xw8Wp-TZzgAFfDQ"], referer: https://readyerpsolutions.com/wp-login.php
[Sun Aug 30 03:08:58.209453 2026] [security2:error] [pid 509172:tid 509376] [client 20.63.81.20:52702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/Q1.php"] [unique_id "apPlGpwMiz5K1he2FnkKKQAAAdc"]
[Sun Aug 30 03:08:58.241609 2026] [security2:error] [pid 509172:tid 509344] [client 20.48.160.90:45830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/ops.php"] [unique_id "apPlGpwMiz5K1he2FnkKQgAAAbc"]
[Sun Aug 30 03:08:58.303398 2026] [security2:error] [pid 510357:tid 510596] [client 20.48.251.3:64491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/configuration.php"] [unique_id "apPlGn5YTqJxoOZUSXtDRgAABiA"]
[Sun Aug 30 03:08:58.316180 2026] [security2:error] [pid 509172:tid 509339] [client 20.48.250.41:61244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/403.php"] [unique_id "apPlGpwMiz5K1he2FnkKjQAAAbI"]
[Sun Aug 30 03:08:58.324199 2026] [security2:error] [pid 509172:tid 509328] [client 20.104.49.130:58103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/wp-blogs.php"] [unique_id "apPlGpwMiz5K1he2FnkKlAAAAac"]
[Sun Aug 30 03:08:58.337015 2026] [security2:error] [pid 509172:tid 509313] [client 20.63.81.20:52635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/nz.php"] [unique_id "apPlGpwMiz5K1he2FnkKmQAAAZg"]
[Sun Aug 30 03:08:58.342656 2026] [security2:error] [pid 509915:tid 510120] [client 20.220.204.93:59009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/bgymj.php"] [unique_id "apPlGs2gn1q0xw8Wp-TaDAAABXw"]
[Sun Aug 30 03:08:58.359737 2026] [authz_core:error] [pid 509915:tid 510119] [client 216.73.216.128:55539] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:58.360017 2026] [authz_core:error] [pid 509915:tid 510119] [client 216.73.216.128:55539] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:58.362170 2026] [security2:error] [pid 509915:tid 510094] [client 158.158.54.35:27206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/add_actualites.php"] [unique_id "apPlGs2gn1q0xw8Wp-TaFQAABWI"]
[Sun Aug 30 03:08:58.370489 2026] [security2:error] [pid 509172:tid 509346] [client 20.48.160.90:40039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPlGpwMiz5K1he2FnkKsAAAAbk"]
[Sun Aug 30 03:08:58.432290 2026] [security2:error] [pid 509172:tid 509403] [client 74.248.24.12:17709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/backup.php"] [unique_id "apPlGpwMiz5K1he2FnkK5AAAAfI"]
[Sun Aug 30 03:08:58.440065 2026] [authz_core:error] [pid 509915:tid 510122] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:58.440336 2026] [authz_core:error] [pid 509915:tid 510122] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:58.441398 2026] [security2:error] [pid 509172:tid 509408] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/backup/.env"] [unique_id "apPlGpwMiz5K1he2FnkK6wAAAfc"]
[Sun Aug 30 03:08:58.451631 2026] [security2:error] [pid 509915:tid 510083] [client 20.48.250.41:61198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/cytyr.php"] [unique_id "apPlGs2gn1q0xw8Wp-TaOgAABVc"]
[Sun Aug 30 03:08:58.467518 2026] [security2:error] [pid 509915:tid 510056] [client 20.63.81.20:52719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/sg.php"] [unique_id "apPlGs2gn1q0xw8Wp-TaPgAABTw"]
[Sun Aug 30 03:08:58.482836 2026] [security2:error] [pid 509172:tid 509347] [client 20.220.204.93:59093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/ws69.php"] [unique_id "apPlGpwMiz5K1he2FnkLBQAAAbo"]
[Sun Aug 30 03:08:58.510603 2026] [security2:error] [pid 510357:tid 510540] [client 20.48.160.90:40004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPlGn5YTqJxoOZUSXtDVwAABeg"]
[Sun Aug 30 03:08:58.517986 2026] [security2:error] [pid 509172:tid 509391] [client 4.205.62.107:17297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/ammika.php"] [unique_id "apPlGpwMiz5K1he2FnkLMQAAAeY"]
[Sun Aug 30 03:08:58.545238 2026] [authz_core:error] [pid 509172:tid 509320] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:08:58.545686 2026] [authz_core:error] [pid 509172:tid 509320] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:08:58.559247 2026] [security2:error] [pid 509172:tid 509343] [client 4.205.62.107:64682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/atex1.php"] [unique_id "apPlGpwMiz5K1he2FnkLUwAAAbY"]
[Sun Aug 30 03:08:58.590485 2026] [security2:error] [pid 509172:tid 509372] [client 20.48.250.41:61286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/galer.php"] [unique_id "apPlGpwMiz5K1he2FnkLYwAAAdM"]
[Sun Aug 30 03:08:58.596924 2026] [security2:error] [pid 509172:tid 509398] [client 20.63.81.20:52358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/hypo.php"] [unique_id "apPlGpwMiz5K1he2FnkLagAAAe0"]
[Sun Aug 30 03:08:58.619025 2026] [security2:error] [pid 509172:tid 509317] [client 20.220.204.93:59070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/ccs.php"] [unique_id "apPlGpwMiz5K1he2FnkLdwAAAZw"]
[Sun Aug 30 03:08:58.626835 2026] [security2:error] [pid 509915:tid 510055] [client 20.104.18.15:35515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/biufile.php"] [unique_id "apPlGs2gn1q0xw8Wp-TaegAABTs"]
[Sun Aug 30 03:08:58.652835 2026] [security2:error] [pid 509172:tid 509371] [client 20.48.160.90:39979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/about.php"] [unique_id "apPlGpwMiz5K1he2FnkLiAAAAdI"]
[Sun Aug 30 03:08:58.679329 2026] [security2:error] [pid 509172:tid 509410] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/backups/.env"] [unique_id "apPlGpwMiz5K1he2FnkLlwAAAfk"]
[Sun Aug 30 03:08:58.702770 2026] [security2:error] [pid 509172:tid 509310] [client 20.104.18.15:2038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/wnnjpsby.php"] [unique_id "apPlGpwMiz5K1he2FnkLqgAAAZU"]
[Sun Aug 30 03:08:58.712898 2026] [security2:error] [pid 509915:tid 510086] [client 20.104.50.220:47086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/lites.php"] [unique_id "apPlGs2gn1q0xw8Wp-TamgAABVo"]
[Sun Aug 30 03:08:58.722297 2026] [security2:error] [pid 509915:tid 510168] [client 68.155.159.216:55144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apPlGs2gn1q0xw8Wp-TaoAAABaw"]
[Sun Aug 30 03:08:58.722616 2026] [security2:error] [pid 509172:tid 509371] [client 20.48.250.41:61225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/baixy.php"] [unique_id "apPlGpwMiz5K1he2FnkLvQAAAdI"]
[Sun Aug 30 03:08:58.724809 2026] [security2:error] [pid 509915:tid 510109] [client 20.63.81.20:52643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/Hd.php"] [unique_id "apPlGs2gn1q0xw8Wp-TaoQAABXE"]
[Sun Aug 30 03:08:58.728374 2026] [security2:error] [pid 509172:tid 509343] [client 20.104.18.15:34710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/sushi.php"] [unique_id "apPlGpwMiz5K1he2FnkLwAAAAbY"]
[Sun Aug 30 03:08:58.733579 2026] [security2:error] [pid 509172:tid 509358] [client 20.48.251.3:59877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/aws_config.php"] [unique_id "apPlGpwMiz5K1he2FnkLxQAAAcU"]
[Sun Aug 30 03:08:58.762747 2026] [security2:error] [pid 509172:tid 509425] [client 20.220.204.93:59015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/mar.php"] [unique_id "apPlGpwMiz5K1he2FnkL2QAAAgg"]
[Sun Aug 30 03:08:58.798289 2026] [security2:error] [pid 510357:tid 510528] [client 20.104.50.220:42774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/dom.php"] [unique_id "apPlGn5YTqJxoOZUSXtDdgAABdw"]
[Sun Aug 30 03:08:58.798795 2026] [security2:error] [pid 509915:tid 510146] [client 20.48.160.90:40056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/admin.php/admin.php"] [unique_id "apPlGs2gn1q0xw8Wp-Ta0wAABZY"]
[Sun Aug 30 03:08:58.807837 2026] [security2:error] [pid 509172:tid 509308] [client 158.158.54.35:27218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/contact_tpl.php"] [unique_id "apPlGpwMiz5K1he2FnkL8QAAAZM"]
[Sun Aug 30 03:08:58.836564 2026] [security2:error] [pid 509172:tid 509373] [client 20.104.50.220:5614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/d.php"] [unique_id "apPlGpwMiz5K1he2FnkMCQAAAdQ"]
[Sun Aug 30 03:08:58.851945 2026] [security2:error] [pid 509172:tid 509323] [client 20.48.250.41:60535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/ava.php"] [unique_id "apPlGpwMiz5K1he2FnkMEAAAAaI"]
[Sun Aug 30 03:08:58.860368 2026] [security2:error] [pid 509915:tid 510159] [client 20.63.81.20:52386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/im.php"] [unique_id "apPlGs2gn1q0xw8Wp-Ta8QAABaM"]
[Sun Aug 30 03:08:58.893049 2026] [security2:error] [pid 509915:tid 510066] [client 20.104.18.15:18395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/ta.php"] [unique_id "apPlGs2gn1q0xw8Wp-Ta_QAABUY"]
[Sun Aug 30 03:08:58.906897 2026] [security2:error] [pid 509172:tid 509333] [client 20.220.204.93:59016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/ccu.php"] [unique_id "apPlGpwMiz5K1he2FnkMMQAAAaw"]
[Sun Aug 30 03:08:58.922269 2026] [security2:error] [pid 509172:tid 509397] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/old/.env"] [unique_id "apPlGpwMiz5K1he2FnkMPgAAAew"]
[Sun Aug 30 03:08:58.927553 2026] [security2:error] [pid 509915:tid 510053] [client 68.155.159.216:45982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apPlGs2gn1q0xw8Wp-TbCgAABTk"]
[Sun Aug 30 03:08:58.932678 2026] [security2:error] [pid 509915:tid 510099] [client 20.48.160.90:45901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/media.php"] [unique_id "apPlGs2gn1q0xw8Wp-TbCwAABWc"]
[Sun Aug 30 03:08:58.947413 2026] [security2:error] [pid 509172:tid 509347] [client 4.205.62.107:36580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/ty.php"] [unique_id "apPlGpwMiz5K1he2FnkMTgAAAbo"]
[Sun Aug 30 03:08:58.978786 2026] [security2:error] [pid 509172:tid 509314] [client 20.48.250.41:61279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/gdn.php"] [unique_id "apPlGpwMiz5K1he2FnkMbQAAAZk"]
[Sun Aug 30 03:08:58.989863 2026] [security2:error] [pid 509172:tid 509356] [client 20.63.81.20:52354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/fc.php"] [unique_id "apPlGpwMiz5K1he2FnkMewAAAcM"]
[Sun Aug 30 03:08:58.999874 2026] [authz_core:error] [pid 509172:tid 509335] [client 216.73.216.128:57762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:59.000293 2026] [authz_core:error] [pid 509172:tid 509335] [client 216.73.216.128:57762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:59.038702 2026] [security2:error] [pid 509172:tid 509360] [client 20.220.204.93:59041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/ak.php"] [unique_id "apPlG5wMiz5K1he2FnkMrgAAAcc"]
[Sun Aug 30 03:08:59.043384 2026] [security2:error] [pid 509172:tid 509313] [client 20.104.18.15:23409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/blog.php"] [unique_id "apPlG5wMiz5K1he2FnkMsgAAAZg"]
[Sun Aug 30 03:08:59.047991 2026] [security2:error] [pid 509915:tid 510060] [client 20.104.18.15:43276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/samll.php"] [unique_id "apPlG82gn1q0xw8Wp-TbNwAABUA"]
[Sun Aug 30 03:08:59.060965 2026] [security2:error] [pid 509172:tid 509330] [client 74.248.24.12:17677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/disagrsod.php"] [unique_id "apPlG5wMiz5K1he2FnkMvgAAAak"]
[Sun Aug 30 03:08:59.062533 2026] [security2:error] [pid 509172:tid 509388] [client 20.48.160.90:39949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/mac.php"] [unique_id "apPlG5wMiz5K1he2FnkMwQAAAeM"]
[Sun Aug 30 03:08:59.065598 2026] [security2:error] [pid 509172:tid 509423] [client 20.104.50.220:31902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/info.php"] [unique_id "apPlG5wMiz5K1he2FnkMxgAAAgY"]
[Sun Aug 30 03:08:59.084599 2026] [authz_core:error] [pid 509172:tid 509429] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:08:59.084900 2026] [authz_core:error] [pid 509172:tid 509429] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:08:59.091019 2026] [security2:error] [pid 509915:tid 510053] [client 20.104.49.130:58215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/worksec.php"] [unique_id "apPlG82gn1q0xw8Wp-TbSwAABTk"]
[Sun Aug 30 03:08:59.091201 2026] [security2:error] [pid 509915:tid 510155] [client 20.104.50.220:17284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/file46.php"] [unique_id "apPlG82gn1q0xw8Wp-TbTAAABZ8"]
[Sun Aug 30 03:08:59.114745 2026] [security2:error] [pid 509172:tid 509375] [client 20.63.81.20:52644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/ke.php"] [unique_id "apPlG5wMiz5K1he2FnkM5QAAAdY"]
[Sun Aug 30 03:08:59.118777 2026] [security2:error] [pid 509172:tid 509313] [client 20.48.250.41:61230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/f2.php"] [unique_id "apPlG5wMiz5K1he2FnkM6QAAAZg"]
[Sun Aug 30 03:08:59.124355 2026] [authz_core:error] [pid 509172:tid 509310] [client 66.249.66.39:58690] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:59.124750 2026] [authz_core:error] [pid 509172:tid 509310] [client 66.249.66.39:58690] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:59.125443 2026] [security2:error] [pid 510357:tid 510617] [client 20.104.50.220:28718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/dada.php"] [unique_id "apPlG35YTqJxoOZUSXtDnwAABjU"]
[Sun Aug 30 03:08:59.150477 2026] [security2:error] [pid 509172:tid 509397] [client 20.104.50.220:61455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wsmini.php"] [unique_id "apPlG5wMiz5K1he2FnkM9gAAAew"]
[Sun Aug 30 03:08:59.162132 2026] [security2:error] [pid 509172:tid 509417] [client 20.104.50.220:28735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/store.php"] [unique_id "apPlG5wMiz5K1he2FnkM-wAAAgA"]
[Sun Aug 30 03:08:59.162441 2026] [security2:error] [pid 509172:tid 509306] [client 20.104.50.220:32857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/WSO.php"] [unique_id "apPlG5wMiz5K1he2FnkM_AAAAZE"]
[Sun Aug 30 03:08:59.169697 2026] [security2:error] [pid 509172:tid 509350] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/tmp/.env"] [unique_id "apPlG5wMiz5K1he2FnkNAAAAAb0"]
[Sun Aug 30 03:08:59.181955 2026] [security2:error] [pid 509172:tid 509386] [client 68.155.159.216:62022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/ans.php"] [unique_id "apPlG5wMiz5K1he2FnkNCAAAAeE"]
[Sun Aug 30 03:08:59.182989 2026] [security2:error] [pid 509172:tid 509318] [client 20.220.204.93:59049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/lib.php"] [unique_id "apPlG5wMiz5K1he2FnkNCwAAAZ0"]
[Sun Aug 30 03:08:59.203966 2026] [security2:error] [pid 509915:tid 510050] [client 20.48.160.90:45951] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.website-e725365c.a220training.com"] [uri "/1.php"] [unique_id "apPlG82gn1q0xw8Wp-TbcwAABTY"]
[Sun Aug 30 03:08:59.204075 2026] [security2:error] [pid 509915:tid 510050] [client 20.48.160.90:45951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/1.php"] [unique_id "apPlG82gn1q0xw8Wp-TbcwAABTY"]
[Sun Aug 30 03:08:59.223120 2026] [security2:error] [pid 509172:tid 509334] [client 20.48.251.3:60489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/nzv.php"] [unique_id "apPlG5wMiz5K1he2FnkNLQAAAa0"]
[Sun Aug 30 03:08:59.241072 2026] [security2:error] [pid 509172:tid 509347] [client 20.63.81.20:52676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/tf.php"] [unique_id "apPlG5wMiz5K1he2FnkNOQAAAbo"]
[Sun Aug 30 03:08:59.247296 2026] [security2:error] [pid 509915:tid 510113] [client 20.48.250.41:61246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/grsiuk.php"] [unique_id "apPlG82gn1q0xw8Wp-TbiQAABXU"]
[Sun Aug 30 03:08:59.258314 2026] [security2:error] [pid 510357:tid 510595] [client 20.48.251.3:59280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/xa.php"] [unique_id "apPlG35YTqJxoOZUSXtDqAAABh8"]
[Sun Aug 30 03:08:59.288276 2026] [security2:error] [pid 509915:tid 510046] [client 158.158.54.35:5398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/OK.php"] [unique_id "apPlG82gn1q0xw8Wp-TbqQAABTI"]
[Sun Aug 30 03:08:59.296192 2026] [security2:error] [pid 509915:tid 510148] [client 4.205.62.107:25908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/ebahvhhh.php"] [unique_id "apPlG82gn1q0xw8Wp-TbswAABZg"]
[Sun Aug 30 03:08:59.309131 2026] [security2:error] [pid 509915:tid 510079] [client 114.119.141.217:58499] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.whatwouldderriawear.com"] [uri "/shop/"] [unique_id "apPlG82gn1q0xw8Wp-TbwAAABVM"], referer: https://www.whatwouldderriawear.com/shop/
[Sun Aug 30 03:08:59.330788 2026] [security2:error] [pid 509172:tid 509339] [client 20.220.204.93:59074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/wp-style.php"] [unique_id "apPlG5wMiz5K1he2FnkNcwAAAbI"]
[Sun Aug 30 03:08:59.331937 2026] [security2:error] [pid 509172:tid 509407] [client 20.48.160.90:45917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/classwithtostring.php"] [unique_id "apPlG5wMiz5K1he2FnkNdgAAAfY"]
[Sun Aug 30 03:08:59.332853 2026] [authz_core:error] [pid 509915:tid 510091] [client 66.249.66.32:63751] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:59.333214 2026] [authz_core:error] [pid 509915:tid 510091] [client 66.249.66.32:63751] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:59.348582 2026] [security2:error] [pid 509172:tid 509387] [client 4.205.62.107:54362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/old_phpinfo.php"] [unique_id "apPlG5wMiz5K1he2FnkNfgAAAeI"]
[Sun Aug 30 03:08:59.372827 2026] [security2:error] [pid 509172:tid 509346] [client 20.63.81.20:52627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/px.php"] [unique_id "apPlG5wMiz5K1he2FnkNiwAAAbk"]
[Sun Aug 30 03:08:59.373904 2026] [security2:error] [pid 510357:tid 510371] [remote 52.142.35.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.35.142.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "registerencio.com"] [uri "/wp-login.php"] [unique_id "apPlG35YTqJxoOZUSXtDtAAF8wk"]
[Sun Aug 30 03:08:59.386631 2026] [security2:error] [pid 509915:tid 510067] [client 20.48.250.41:60424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/wp-scr1pts.php"] [unique_id "apPlG82gn1q0xw8Wp-Tb1wAABUc"]
[Sun Aug 30 03:08:59.396670 2026] [authz_core:error] [pid 510357:tid 510561] [client 66.249.66.78:36058] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:59.396955 2026] [authz_core:error] [pid 510357:tid 510561] [client 66.249.66.78:36058] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:59.408316 2026] [security2:error] [pid 509172:tid 509395] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/temp/.env"] [unique_id "apPlG5wMiz5K1he2FnkNlgAAAeo"]
[Sun Aug 30 03:08:59.454829 2026] [security2:error] [pid 509172:tid 509379] [client 20.48.251.3:6503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/server_info.php"] [unique_id "apPlG5wMiz5K1he2FnkNvAAAAdo"]
[Sun Aug 30 03:08:59.464988 2026] [security2:error] [pid 509172:tid 509352] [client 20.48.160.90:45838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp-ws68.php"] [unique_id "apPlG5wMiz5K1he2FnkNwwAAAb8"]
[Sun Aug 30 03:08:59.475803 2026] [security2:error] [pid 509172:tid 509365] [client 20.220.204.93:52243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/browse.php"] [unique_id "apPlG5wMiz5K1he2FnkNzAAAAcw"]
[Sun Aug 30 03:08:59.506712 2026] [security2:error] [pid 510357:tid 510616] [client 20.63.81.20:52614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/jg.php"] [unique_id "apPlG35YTqJxoOZUSXtDzgAABjQ"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:08:59.534515 2026] [security2:error] [pid 509172:tid 509315] [client 20.48.250.41:60480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/num.php"] [unique_id "apPlG5wMiz5K1he2FnkN-AAAAZo"]
[Sun Aug 30 03:08:59.553669 2026] [authz_core:error] [pid 509172:tid 509332] [client 216.73.216.128:57762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:59.554139 2026] [authz_core:error] [pid 509172:tid 509332] [client 216.73.216.128:57762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:59.566063 2026] [authz_core:error] [pid 509915:tid 510072] [client 66.249.66.197:56206] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:59.566402 2026] [authz_core:error] [pid 509915:tid 510072] [client 66.249.66.197:56206] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:59.575947 2026] [authz_core:error] [pid 509172:tid 509407] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:08:59.576273 2026] [authz_core:error] [pid 509172:tid 509407] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:08:59.592827 2026] [security2:error] [pid 509172:tid 509419] [client 20.48.160.90:45875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/simple.php"] [unique_id "apPlG5wMiz5K1he2FnkOFQAAAgI"]
[Sun Aug 30 03:08:59.614345 2026] [security2:error] [pid 509915:tid 510155] [client 20.220.204.93:52331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/zoo.php"] [unique_id "apPlG82gn1q0xw8Wp-TcTAAABZ8"]
[Sun Aug 30 03:08:59.616399 2026] [lsapi:warn] [pid 509172:tid 509177] [remote 34.121.33.92:16384] [host tastylandscape.com] Backend log: PHP Warning: Use of undefined constant user_level - assumed 'user_level' (this will throw an Error in a future version of PHP) in /home4/tommed/public_html/wp-content/plugins/ultimate-google-analytics/ultimate_ga.php on line 524\n
[Sun Aug 30 03:08:59.643869 2026] [security2:error] [pid 509172:tid 509418] [client 20.151.200.44:55589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/ah24.php"] [unique_id "apPlG5wMiz5K1he2FnkOMQAAAgE"]
[Sun Aug 30 03:08:59.644077 2026] [authz_core:error] [pid 509172:tid 509359] [client 216.73.216.128:35630] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:59.644330 2026] [authz_core:error] [pid 509172:tid 509359] [client 216.73.216.128:35630] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:59.646730 2026] [security2:error] [pid 510357:tid 510533] [client 20.63.81.20:52413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/yj.php"] [unique_id "apPlG35YTqJxoOZUSXtD5gAABeE"]
[Sun Aug 30 03:08:59.655606 2026] [security2:error] [pid 509172:tid 509404] [client 4.205.62.107:17104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/broadcasting.php"] [unique_id "apPlG5wMiz5K1he2FnkONgAAAfM"]
[Sun Aug 30 03:08:59.656916 2026] [security2:error] [pid 509172:tid 509404] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/lab/.env"] [unique_id "apPlG5wMiz5K1he2FnkONwAAAfM"]
[Sun Aug 30 03:08:59.671977 2026] [security2:error] [pid 509915:tid 510070] [client 20.48.250.41:60419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/a4.php"] [unique_id "apPlG82gn1q0xw8Wp-TcWQAABUo"]
[Sun Aug 30 03:08:59.689326 2026] [authz_core:error] [pid 509172:tid 509340] [client 66.249.66.76:49793] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:59.689693 2026] [authz_core:error] [pid 509172:tid 509340] [client 66.249.66.76:49793] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:59.695466 2026] [security2:error] [pid 509172:tid 509180] [remote 52.142.35.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.35.142.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "registerencio.com"] [uri "/wp-login.php"] [unique_id "apPlG5wMiz5K1he2FnkOTAAB4gU"], referer: https://registerencio.com/wp-login.php
[Sun Aug 30 03:08:59.695903 2026] [security2:error] [pid 509172:tid 509306] [client 4.205.62.107:64504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/aws_sdk_settings.php"] [unique_id "apPlG5wMiz5K1he2FnkOTgAAAZE"]
[Sun Aug 30 03:08:59.697583 2026] [security2:error] [pid 509172:tid 509409] [client 74.248.24.12:11326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/1p.php"] [unique_id "apPlG5wMiz5K1he2FnkOUAAAAfg"]
[Sun Aug 30 03:08:59.717089 2026] [security2:error] [pid 510357:tid 510512] [client 158.158.54.35:9584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/eNtnKM.php"] [unique_id "apPlG35YTqJxoOZUSXtD8wAABcw"]
[Sun Aug 30 03:08:59.721286 2026] [security2:error] [pid 509172:tid 509378] [client 20.48.160.90:45907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/aaa.php"] [unique_id "apPlG5wMiz5K1he2FnkOaQAAAdk"]
[Sun Aug 30 03:08:59.747624 2026] [security2:error] [pid 509172:tid 509365] [client 20.151.200.44:46018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/wp-access.php"] [unique_id "apPlG5wMiz5K1he2FnkOgAAAAcw"]
[Sun Aug 30 03:08:59.771955 2026] [security2:error] [pid 509915:tid 510111] [client 20.63.81.20:52378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/zi.php"] [unique_id "apPlG82gn1q0xw8Wp-TchAAABXM"]
[Sun Aug 30 03:08:59.778426 2026] [security2:error] [pid 509915:tid 510145] [client 20.104.18.15:35150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/blacks.php"] [unique_id "apPlG82gn1q0xw8Wp-TcigAABZU"]
[Sun Aug 30 03:08:59.780296 2026] [security2:error] [pid 509915:tid 510109] [client 20.220.204.93:59104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/elp.php"] [unique_id "apPlG82gn1q0xw8Wp-TciwAABXE"]
[Sun Aug 30 03:08:59.818030 2026] [security2:error] [pid 509172:tid 509331] [client 20.48.250.41:61247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/tfm.php"] [unique_id "apPlG5wMiz5K1he2FnkOqwAAAao"]
[Sun Aug 30 03:08:59.819639 2026] [authz_core:error] [pid 509915:tid 510123] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:59.819935 2026] [authz_core:error] [pid 509915:tid 510123] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:08:59.828492 2026] [authz_core:error] [pid 509915:tid 510094] [client 216.73.216.128:55539] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:08:59.828773 2026] [authz_core:error] [pid 509915:tid 510094] [client 216.73.216.128:55539] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:08:59.838216 2026] [security2:error] [pid 510357:tid 510556] [client 20.104.18.15:2012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/info.php/new.php"] [unique_id "apPlG35YTqJxoOZUSXtD_gAABfg"]
[Sun Aug 30 03:08:59.838503 2026] [security2:error] [pid 509915:tid 510076] [client 68.155.159.216:55136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apPlG82gn1q0xw8Wp-TcsgAABVA"]
[Sun Aug 30 03:08:59.872337 2026] [security2:error] [pid 509172:tid 509415] [client 20.48.251.3:59482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/dialog.php"] [unique_id "apPlG5wMiz5K1he2FnkOzwAAAf4"]
[Sun Aug 30 03:08:59.877569 2026] [security2:error] [pid 509915:tid 510155] [client 20.104.50.220:46604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/0x.php"] [unique_id "apPlG82gn1q0xw8Wp-TcvgAABZ8"]
[Sun Aug 30 03:08:59.878349 2026] [security2:error] [pid 509172:tid 509370] [client 20.104.18.15:34738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/manga.php"] [unique_id "apPlG5wMiz5K1he2FnkO0gAAAdE"]
[Sun Aug 30 03:08:59.903878 2026] [security2:error] [pid 509915:tid 510079] [client 20.63.81.20:52364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/ue.php"] [unique_id "apPlG82gn1q0xw8Wp-Tc0AAABVM"]
[Sun Aug 30 03:08:59.911092 2026] [security2:error] [pid 509915:tid 510169] [client 20.220.204.93:59013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/666.php"] [unique_id "apPlG82gn1q0xw8Wp-Tc0wAABa0"]
[Sun Aug 30 03:08:59.932760 2026] [security2:error] [pid 509172:tid 509377] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/cronlab/.env"] [unique_id "apPlG5wMiz5K1he2FnkO9gAAAdg"]
[Sun Aug 30 03:08:59.957177 2026] [security2:error] [pid 509915:tid 510148] [client 20.48.250.41:61186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/Geforce.php"] [unique_id "apPlG82gn1q0xw8Wp-Tc6QAABZg"]
[Sun Aug 30 03:08:59.975514 2026] [security2:error] [pid 509172:tid 509381] [client 20.104.50.220:5609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/c.php"] [unique_id "apPlG5wMiz5K1he2FnkPGgAAAdw"]
[Sun Aug 30 03:08:59.977328 2026] [security2:error] [pid 510357:tid 510544] [client 20.104.50.220:63494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/v4ga.php"] [unique_id "apPlG35YTqJxoOZUSXtEEwAABew"]
[Sun Aug 30 03:08:59.980378 2026] [lsapi:warn] [pid 509915:tid 509977] [remote 34.121.33.92:16385] [host tastylandscape.com] Backend log: PHP Warning: Use of undefined constant user_level - assumed 'user_level' (this will throw an Error in a future version of PHP) in /home4/tommed/public_html/wp-content/plugins/ultimate-google-analytics/ultimate_ga.php on line 524\n
[Sun Aug 30 03:09:00.009531 2026] [authz_core:error] [pid 509915:tid 510111] [client 216.73.216.128:55539] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:00.009910 2026] [authz_core:error] [pid 509915:tid 510111] [client 216.73.216.128:55539] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:00.038100 2026] [security2:error] [pid 509915:tid 510089] [client 20.63.81.20:52653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/nv.php"] [unique_id "apPlHM2gn1q0xw8Wp-TdEAAABV0"]
[Sun Aug 30 03:09:00.064178 2026] [security2:error] [pid 509915:tid 510074] [client 20.104.18.15:18183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/bo.php"] [unique_id "apPlHM2gn1q0xw8Wp-TdGQAABU4"]
[Sun Aug 30 03:09:00.082868 2026] [authz_core:error] [pid 509172:tid 509370] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:00.083141 2026] [authz_core:error] [pid 509172:tid 509370] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:00.106888 2026] [security2:error] [pid 509172:tid 509427] [client 20.48.250.41:61305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/click.php"] [unique_id "apPlHJwMiz5K1he2FnkPgwAAAgo"]
[Sun Aug 30 03:09:00.107955 2026] [security2:error] [pid 509172:tid 509427] [client 20.220.204.93:59011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/knmt.php"] [unique_id "apPlHJwMiz5K1he2FnkPhQAAAgo"]
[Sun Aug 30 03:09:00.121303 2026] [security2:error] [pid 509172:tid 509372] [client 68.155.159.216:46027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-content/uploads/about.php"] [unique_id "apPlHJwMiz5K1he2FnkPjQAAAdM"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:00.160076 2026] [security2:error] [pid 509915:tid 510173] [client 158.158.54.35:22985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/nf.php"] [unique_id "apPlHM2gn1q0xw8Wp-TdQAAABbE"]
[Sun Aug 30 03:09:00.164677 2026] [security2:error] [pid 509172:tid 509306] [client 20.63.81.20:52612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/jw.php"] [unique_id "apPlHJwMiz5K1he2FnkPpQAAAZE"]
[Sun Aug 30 03:09:00.186564 2026] [security2:error] [pid 509172:tid 509388] [client 20.104.18.15:44013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/she11.php"] [unique_id "apPlHJwMiz5K1he2FnkPrQAAAeM"]
[Sun Aug 30 03:09:00.187606 2026] [security2:error] [pid 509172:tid 509319] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/cron/.env"] [unique_id "apPlHJwMiz5K1he2FnkPrgAAAZ4"]
[Sun Aug 30 03:09:00.221866 2026] [security2:error] [pid 509172:tid 509330] [client 20.104.50.220:16617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/eee.php"] [unique_id "apPlHJwMiz5K1he2FnkPwwAAAak"]
[Sun Aug 30 03:09:00.232478 2026] [security2:error] [pid 509915:tid 510060] [client 20.104.18.15:23446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/wp-admin/js/wp-load.php"] [unique_id "apPlHM2gn1q0xw8Wp-TdeAAABUA"]
[Sun Aug 30 03:09:00.233272 2026] [security2:error] [pid 509915:tid 510116] [client 20.48.250.41:60498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/ms.php"] [unique_id "apPlHM2gn1q0xw8Wp-TdeQAABXg"]
[Sun Aug 30 03:09:00.259576 2026] [security2:error] [pid 509915:tid 510102] [client 20.104.50.220:29143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/xml.php"] [unique_id "apPlHM2gn1q0xw8Wp-TdigAABWo"]
[Sun Aug 30 03:09:00.266481 2026] [security2:error] [pid 509172:tid 509407] [client 20.104.50.220:32257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/file2.php"] [unique_id "apPlHJwMiz5K1he2FnkP3gAAAfY"]
[Sun Aug 30 03:09:00.271111 2026] [security2:error] [pid 509915:tid 510130] [client 20.48.160.90:45892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/shiny.php"] [unique_id "apPlHM2gn1q0xw8Wp-TdlQAABYY"]
[Sun Aug 30 03:09:00.274695 2026] [security2:error] [pid 509172:tid 509331] [client 20.220.204.93:59067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/sbhu.php"] [unique_id "apPlHJwMiz5K1he2FnkP5QAAAao"]
[Sun Aug 30 03:09:00.302604 2026] [security2:error] [pid 509172:tid 509426] [client 20.63.81.20:52353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/or.php"] [unique_id "apPlHJwMiz5K1he2FnkP-AAAAgk"]
[Sun Aug 30 03:09:00.309860 2026] [security2:error] [pid 509915:tid 510144] [client 20.104.50.220:52862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/unzip.php"] [unique_id "apPlHM2gn1q0xw8Wp-TdrwAABZQ"]
[Sun Aug 30 03:09:00.311097 2026] [security2:error] [pid 509915:tid 510101] [client 20.104.50.220:33213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/IndoXploit.php"] [unique_id "apPlHM2gn1q0xw8Wp-TdsQAABWk"]
[Sun Aug 30 03:09:00.355198 2026] [security2:error] [pid 509915:tid 510158] [client 4.205.62.107:36556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/adminer-4.7.6-en.php"] [unique_id "apPlHM2gn1q0xw8Wp-TdxwAABaI"]
[Sun Aug 30 03:09:00.357974 2026] [security2:error] [pid 509172:tid 509323] [client 20.104.50.220:63031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/86.php"] [unique_id "apPlHJwMiz5K1he2FnkQHwAAAaI"]
[Sun Aug 30 03:09:00.361533 2026] [security2:error] [pid 509172:tid 509377] [client 216.73.216.128:57762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPlHJwMiz5K1he2FnkQJAAAAdg"]
[Sun Aug 30 03:09:00.361719 2026] [security2:error] [pid 509172:tid 509431] [client 20.48.250.41:61261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/zxekqlxb.php"] [unique_id "apPlHJwMiz5K1he2FnkQJQAAAg4"]
[Sun Aug 30 03:09:00.378473 2026] [security2:error] [pid 509172:tid 509308] [client 20.48.251.3:33339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/66.php"] [unique_id "apPlHJwMiz5K1he2FnkQLwAAAZM"]
[Sun Aug 30 03:09:00.396336 2026] [security2:error] [pid 509172:tid 509330] [client 20.48.251.3:59287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/ws61.php"] [unique_id "apPlHJwMiz5K1he2FnkQNwAAAak"]
[Sun Aug 30 03:09:00.402626 2026] [security2:error] [pid 510357:tid 510592] [client 20.48.160.90:40034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/goods.php"] [unique_id "apPlHH5YTqJxoOZUSXtEPgAABhw"]
[Sun Aug 30 03:09:00.431641 2026] [security2:error] [pid 509172:tid 509315] [client 20.151.200.44:46036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/wp-content/admin.php"] [unique_id "apPlHJwMiz5K1he2FnkQSQAAAZo"]
[Sun Aug 30 03:09:00.432607 2026] [security2:error] [pid 509172:tid 509370] [client 20.63.81.20:52641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/ile56.php"] [unique_id "apPlHJwMiz5K1he2FnkQSwAAAdE"]
[Sun Aug 30 03:09:00.433154 2026] [security2:error] [pid 509172:tid 509386] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/en/.env"] [unique_id "apPlHJwMiz5K1he2FnkQTQAAAeE"]
[Sun Aug 30 03:09:00.437174 2026] [security2:error] [pid 509172:tid 509419] [client 20.220.204.93:59039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/a332.php"] [unique_id "apPlHJwMiz5K1he2FnkQUAAAAgI"]
[Sun Aug 30 03:09:00.445448 2026] [security2:error] [pid 509172:tid 509378] [client 74.248.24.12:11296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/Auth.php"] [unique_id "apPlHJwMiz5K1he2FnkQVQAAAdk"]
[Sun Aug 30 03:09:00.503015 2026] [security2:error] [pid 509915:tid 510065] [client 20.48.250.41:61228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/init.php"] [unique_id "apPlHM2gn1q0xw8Wp-TeBAAABUU"]
[Sun Aug 30 03:09:00.519516 2026] [security2:error] [pid 510357:tid 510508] [client 4.205.62.107:22530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.rosscosmetics.com"] [uri "/wp-act.php"] [unique_id "apPlHH5YTqJxoOZUSXtEagAABcg"]
[Sun Aug 30 03:09:00.542149 2026] [security2:error] [pid 510357:tid 510598] [client 20.48.160.90:45946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/000.php/index.php"] [unique_id "apPlHH5YTqJxoOZUSXtEdQAABiI"]
[Sun Aug 30 03:09:00.542917 2026] [security2:error] [pid 509915:tid 510135] [client 216.73.216.128:55539] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/usage_202601.html"] [unique_id "apPlHM2gn1q0xw8Wp-TeIwAABYs"]
[Sun Aug 30 03:09:00.562223 2026] [security2:error] [pid 509915:tid 510139] [client 20.63.81.20:52645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/emmh.php"] [unique_id "apPlHM2gn1q0xw8Wp-TeLgAABY8"]
[Sun Aug 30 03:09:00.562594 2026] [security2:error] [pid 509915:tid 510080] [client 4.205.62.107:25782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/asa.php"] [unique_id "apPlHM2gn1q0xw8Wp-TeLwAABVQ"]
[Sun Aug 30 03:09:00.574752 2026] [authz_core:error] [pid 509172:tid 509384] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:00.575042 2026] [authz_core:error] [pid 509172:tid 509384] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:00.592906 2026] [security2:error] [pid 509172:tid 509364] [client 20.220.204.93:59095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/ws66.php"] [unique_id "apPlHJwMiz5K1he2FnkQhQAAAcs"]
[Sun Aug 30 03:09:00.603758 2026] [security2:error] [pid 509915:tid 510075] [client 158.158.54.35:23010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/alumni_reg.php"] [unique_id "apPlHM2gn1q0xw8Wp-TeVAAABU8"]
[Sun Aug 30 03:09:00.629309 2026] [security2:error] [pid 509172:tid 509374] [client 20.48.250.41:60417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/term.php"] [unique_id "apPlHJwMiz5K1he2FnkQmAAAAdU"]
[Sun Aug 30 03:09:00.670888 2026] [security2:error] [pid 509915:tid 510081] [client 20.151.200.44:46054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/log.php"] [unique_id "apPlHM2gn1q0xw8Wp-TebQAABVU"]
[Sun Aug 30 03:09:00.683389 2026] [security2:error] [pid 509172:tid 509323] [client 20.48.160.90:40060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/Jcrop.php"] [unique_id "apPlHJwMiz5K1he2FnkQwQAAAaI"]
[Sun Aug 30 03:09:00.706556 2026] [security2:error] [pid 509172:tid 509327] [client 20.63.81.20:52610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/em.php"] [unique_id "apPlHJwMiz5K1he2FnkQ1QAAAaY"]
[Sun Aug 30 03:09:00.729397 2026] [security2:error] [pid 509915:tid 510161] [client 20.220.204.93:59028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/ws68.php"] [unique_id "apPlHM2gn1q0xw8Wp-TejAAABaU"]
[Sun Aug 30 03:09:00.748941 2026] [security2:error] [pid 509172:tid 509372] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/administrator/.env"] [unique_id "apPlHJwMiz5K1he2FnkQywAAAdM"]
[Sun Aug 30 03:09:00.755626 2026] [security2:error] [pid 509172:tid 509394] [client 20.48.250.41:59986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/aaa.php"] [unique_id "apPlHJwMiz5K1he2FnkQ7wAAAek"]
[Sun Aug 30 03:09:00.784071 2026] [security2:error] [pid 509172:tid 509345] [client 20.104.49.130:63277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/forum.php"] [unique_id "apPlHJwMiz5K1he2FnkRDgAAAbg"]
[Sun Aug 30 03:09:00.796770 2026] [security2:error] [pid 509915:tid 510081] [client 4.205.62.107:17147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/aws_config.php"] [unique_id "apPlHM2gn1q0xw8Wp-TesAAABVU"]
[Sun Aug 30 03:09:00.817064 2026] [security2:error] [pid 510357:tid 510579] [client 20.48.251.3:7064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/hosty.php"] [unique_id "apPlHH5YTqJxoOZUSXtElgAABg8"]
[Sun Aug 30 03:09:00.822828 2026] [security2:error] [pid 509915:tid 510110] [client 20.48.160.90:39936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/35iDq8NAjLu.php"] [unique_id "apPlHM2gn1q0xw8Wp-TexAAABXI"]
[Sun Aug 30 03:09:00.835749 2026] [security2:error] [pid 509172:tid 509412] [client 4.205.62.107:61781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/setup-config.php"] [unique_id "apPlHJwMiz5K1he2FnkRNQAAAfs"]
[Sun Aug 30 03:09:00.839425 2026] [security2:error] [pid 509172:tid 509397] [client 20.63.81.20:52716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/dvve.php"] [unique_id "apPlHJwMiz5K1he2FnkROgAAAew"]
[Sun Aug 30 03:09:00.885988 2026] [security2:error] [pid 509172:tid 509350] [client 20.48.250.41:60487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/xsox.php"] [unique_id "apPlHJwMiz5K1he2FnkRWwAAAb0"]
[Sun Aug 30 03:09:00.896849 2026] [security2:error] [pid 509915:tid 510113] [client 68.155.159.216:53498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/worksec.php"] [unique_id "apPlHM2gn1q0xw8Wp-Te5wAABXU"]
[Sun Aug 30 03:09:00.917715 2026] [security2:error] [pid 509172:tid 509324] [client 20.220.204.93:59102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/users.php"] [unique_id "apPlHJwMiz5K1he2FnkRcwAAAaM"]
[Sun Aug 30 03:09:00.920127 2026] [security2:error] [pid 509172:tid 509397] [client 20.104.18.15:35469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/beck.php"] [unique_id "apPlHJwMiz5K1he2FnkRdgAAAew"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:00.956996 2026] [security2:error] [pid 509915:tid 510104] [client 20.48.160.90:40002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/btx25.php"] [unique_id "apPlHM2gn1q0xw8Wp-TfAwAABWw"]
[Sun Aug 30 03:09:00.975993 2026] [security2:error] [pid 509172:tid 509325] [client 20.63.81.20:52664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/doo.php"] [unique_id "apPlHJwMiz5K1he2FnkRpAAAAaQ"]
[Sun Aug 30 03:09:01.005240 2026] [security2:error] [pid 509172:tid 509384] [client 20.104.50.220:46400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/bless3.php"] [unique_id "apPlHZwMiz5K1he2FnkRvwAAAd8"]
[Sun Aug 30 03:09:01.007863 2026] [security2:error] [pid 509172:tid 509319] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/psnlink/.env"] [unique_id "apPlHZwMiz5K1he2FnkRwQAAAZ4"]
[Sun Aug 30 03:09:01.017002 2026] [security2:error] [pid 509172:tid 509390] [client 20.48.250.41:61293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/lkui.php"] [unique_id "apPlHZwMiz5K1he2FnkRzAAAAeU"]
[Sun Aug 30 03:09:01.024454 2026] [security2:error] [pid 509915:tid 510124] [client 68.155.159.216:55077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/nf_tracking.php"] [unique_id "apPlHc2gn1q0xw8Wp-TfOwAABYA"]
[Sun Aug 30 03:09:01.043383 2026] [security2:error] [pid 510357:tid 510516] [client 20.104.18.15:34679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/asdfghj.php"] [unique_id "apPlHX5YTqJxoOZUSXtErAAABdA"]
[Sun Aug 30 03:09:01.043947 2026] [authz_core:error] [pid 509172:tid 509334] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:01.044396 2026] [authz_core:error] [pid 509172:tid 509334] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:01.059234 2026] [security2:error] [pid 509172:tid 509429] [client 74.248.24.12:2062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/special.php"] [unique_id "apPlHZwMiz5K1he2FnkR6QAAAgw"]
[Sun Aug 30 03:09:01.061120 2026] [security2:error] [pid 509915:tid 510097] [client 158.158.54.35:6095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/admin.php7"] [unique_id "apPlHc2gn1q0xw8Wp-TfVwAABWU"]
[Sun Aug 30 03:09:01.063744 2026] [security2:error] [pid 509915:tid 510071] [client 20.104.18.15:2019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/w.php"] [unique_id "apPlHc2gn1q0xw8Wp-TfWQAABUs"]
[Sun Aug 30 03:09:01.069540 2026] [security2:error] [pid 509915:tid 510086] [client 20.220.204.93:59101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/bzjdlofz.php"] [unique_id "apPlHc2gn1q0xw8Wp-TfXQAABVo"]
[Sun Aug 30 03:09:01.084032 2026] [security2:error] [pid 509915:tid 510151] [client 20.48.251.3:59490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/phpinfo01.php"] [unique_id "apPlHc2gn1q0xw8Wp-TfYQAABZs"]
[Sun Aug 30 03:09:01.105216 2026] [security2:error] [pid 509172:tid 509426] [client 20.63.81.20:52558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/adminer-4.6.6.php"] [unique_id "apPlHZwMiz5K1he2FnkSCgAAAgk"]
[Sun Aug 30 03:09:01.118713 2026] [security2:error] [pid 509172:tid 509379] [client 20.48.160.90:40036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/radio.php"] [unique_id "apPlHZwMiz5K1he2FnkSFAAAAdo"]
[Sun Aug 30 03:09:01.120586 2026] [security2:error] [pid 509172:tid 509386] [client 20.104.50.220:63499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/s3c.php"] [unique_id "apPlHZwMiz5K1he2FnkSFgAAAeE"]
[Sun Aug 30 03:09:01.129234 2026] [security2:error] [pid 509172:tid 509407] [client 20.104.50.220:5557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/b.php"] [unique_id "apPlHZwMiz5K1he2FnkSGgAAAfY"]
[Sun Aug 30 03:09:01.195239 2026] [security2:error] [pid 509172:tid 509387] [client 216.73.216.128:17556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlHZwMiz5K1he2FnkSSAAAAeI"]
[Sun Aug 30 03:09:01.201026 2026] [security2:error] [pid 510357:tid 510515] [client 20.48.250.41:61207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apPlHX5YTqJxoOZUSXtEvQAABc8"]
[Sun Aug 30 03:09:01.214905 2026] [authz_core:error] [pid 510357:tid 510601] [client 66.249.66.38:41354] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:01.215395 2026] [authz_core:error] [pid 510357:tid 510601] [client 66.249.66.38:41354] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:01.216317 2026] [security2:error] [pid 509915:tid 510139] [client 20.220.204.93:52246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/selesai.php"] [unique_id "apPlHc2gn1q0xw8Wp-TfjgAABY8"]
[Sun Aug 30 03:09:01.219470 2026] [security2:error] [pid 509915:tid 510057] [client 20.104.18.15:18400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/44.php"] [unique_id "apPlHc2gn1q0xw8Wp-TfkAAABT0"]
[Sun Aug 30 03:09:01.234812 2026] [security2:error] [pid 509915:tid 510156] [client 20.63.81.20:52693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/gelap1.php"] [unique_id "apPlHc2gn1q0xw8Wp-TflQAABaA"]
[Sun Aug 30 03:09:01.255893 2026] [security2:error] [pid 509172:tid 509388] [client 20.48.160.90:45870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/dex.php"] [unique_id "apPlHZwMiz5K1he2FnkScwAAAeM"]
[Sun Aug 30 03:09:01.259638 2026] [authz_core:error] [pid 509915:tid 510112] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:01.259996 2026] [authz_core:error] [pid 509915:tid 510112] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:01.277502 2026] [security2:error] [pid 509172:tid 509355] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/exapi/.env"] [unique_id "apPlHZwMiz5K1he2FnkShQAAAcI"]
[Sun Aug 30 03:09:01.284940 2026] [authz_core:error] [pid 509172:tid 509373] [client 216.73.216.128:26821] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:01.285404 2026] [authz_core:error] [pid 509172:tid 509373] [client 216.73.216.128:26821] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:01.310364 2026] [security2:error] [pid 509172:tid 509358] [client 20.151.200.44:45955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/xwpg.php"] [unique_id "apPlHZwMiz5K1he2FnkSnAAAAcU"]
[Sun Aug 30 03:09:01.314153 2026] [authz_core:error] [pid 509172:tid 509384] [client 66.249.66.33:40347] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:01.314674 2026] [authz_core:error] [pid 509172:tid 509384] [client 66.249.66.33:40347] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:01.326615 2026] [security2:error] [pid 509172:tid 509350] [client 20.104.18.15:43268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/kerang.php"] [unique_id "apPlHZwMiz5K1he2FnkSpgAAAb0"]
[Sun Aug 30 03:09:01.348344 2026] [authz_core:error] [pid 509915:tid 510162] [client 66.249.66.40:49258] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:01.348674 2026] [authz_core:error] [pid 509915:tid 510162] [client 66.249.66.40:49258] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:01.349893 2026] [security2:error] [pid 509915:tid 510142] [client 20.104.50.220:17294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/file25.php"] [unique_id "apPlHc2gn1q0xw8Wp-Tf7gAABZI"]
[Sun Aug 30 03:09:01.354099 2026] [security2:error] [pid 509915:tid 510079] [client 20.48.250.41:61277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/motu.php"] [unique_id "apPlHc2gn1q0xw8Wp-Tf8QAABVM"]
[Sun Aug 30 03:09:01.362188 2026] [security2:error] [pid 509915:tid 510080] [client 20.63.81.20:52626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/rsjlrria.php"] [unique_id "apPlHc2gn1q0xw8Wp-Tf9gAABVQ"]
[Sun Aug 30 03:09:01.362221 2026] [security2:error] [pid 509915:tid 510132] [client 20.220.204.93:59027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/shlo.php"] [unique_id "apPlHc2gn1q0xw8Wp-Tf9wAABYg"]
[Sun Aug 30 03:09:01.384113 2026] [security2:error] [pid 510357:tid 510610] [client 20.48.160.90:45931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/giodywky.php"] [unique_id "apPlHX5YTqJxoOZUSXtEzQAABi4"]
[Sun Aug 30 03:09:01.394337 2026] [security2:error] [pid 509172:tid 509326] [client 74.7.227.150:55848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ltr7.com"] [uri "/3D%22https:/email-vam.org.uk/3D%22http:/www.SoulLeap.za.com/unsubs3.jpg%22"] [unique_id "apPlHZwMiz5K1he2FnkSzQAAAaU"], referer: http://ltr7.com/3D%22https:/email-vam.org.uk/3D%22http:/www.SoulLeap.za.com/unsubs3.jpg%22?p=%2Fusr%2Fshare%2Fdoc%2Fcpanel-php84-net-url%2Fdocs
[Sun Aug 30 03:09:01.418223 2026] [authz_core:error] [pid 509915:tid 510064] [client 66.249.66.71:59383] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:01.418494 2026] [authz_core:error] [pid 509915:tid 510064] [client 66.249.66.71:59383] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:01.433869 2026] [security2:error] [pid 509915:tid 510077] [client 20.104.50.220:29167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/xm.php"] [unique_id "apPlHc2gn1q0xw8Wp-TgHgAABVE"]
[Sun Aug 30 03:09:01.443457 2026] [security2:error] [pid 509172:tid 509318] [client 20.104.18.15:23374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/robot.php"] [unique_id "apPlHZwMiz5K1he2FnkS7gAAAZ0"]
[Sun Aug 30 03:09:01.450219 2026] [security2:error] [pid 509172:tid 509321] [client 20.104.50.220:33032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/bajingan.php"] [unique_id "apPlHZwMiz5K1he2FnkS9wAAAaA"]
[Sun Aug 30 03:09:01.459390 2026] [security2:error] [pid 509172:tid 509427] [client 20.104.50.220:32279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/lv.php"] [unique_id "apPlHZwMiz5K1he2FnkS_wAAAgo"]
[Sun Aug 30 03:09:01.460514 2026] [security2:error] [pid 509915:tid 510080] [client 20.104.50.220:52852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/think.php"] [unique_id "apPlHc2gn1q0xw8Wp-TgLQAABVQ"]
[Sun Aug 30 03:09:01.463948 2026] [security2:error] [pid 509172:tid 509311] [client 68.155.159.216:45976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-admin/maint/index.php"] [unique_id "apPlHZwMiz5K1he2FnkTAgAAAZY"]
[Sun Aug 30 03:09:01.480610 2026] [security2:error] [pid 509172:tid 509323] [client 20.48.250.41:61204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/Ov-Simple1.php"] [unique_id "apPlHZwMiz5K1he2FnkTEQAAAaI"]
[Sun Aug 30 03:09:01.492944 2026] [security2:error] [pid 509915:tid 510057] [client 20.220.204.93:59050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/asax.php"] [unique_id "apPlHc2gn1q0xw8Wp-TgQAAABT0"]
[Sun Aug 30 03:09:01.493133 2026] [security2:error] [pid 509915:tid 510076] [client 20.63.81.20:52655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/AxAo.php"] [unique_id "apPlHc2gn1q0xw8Wp-TgQQAABVA"]
[Sun Aug 30 03:09:01.504591 2026] [security2:error] [pid 509915:tid 510094] [client 158.158.54.35:7360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/jquery.php"] [unique_id "apPlHc2gn1q0xw8Wp-TgUgAABWI"]
[Sun Aug 30 03:09:01.515060 2026] [security2:error] [pid 510357:tid 510501] [client 20.48.251.3:60495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/admin.php"] [unique_id "apPlHX5YTqJxoOZUSXtE5AAABcE"]
[Sun Aug 30 03:09:01.517592 2026] [security2:error] [pid 509172:tid 509375] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/sitemaps/.env"] [unique_id "apPlHZwMiz5K1he2FnkTKQAAAdY"]
[Sun Aug 30 03:09:01.522778 2026] [security2:error] [pid 509172:tid 509318] [client 4.205.62.107:36621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/phpi.php"] [unique_id "apPlHZwMiz5K1he2FnkTLwAAAZ0"]
[Sun Aug 30 03:09:01.538430 2026] [authz_core:error] [pid 510357:tid 510604] [client 66.249.66.204:60362] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:01.538592 2026] [security2:error] [pid 509172:tid 509413] [client 20.48.160.90:45873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp-kz.php"] [unique_id "apPlHZwMiz5K1he2FnkTPAAAAfw"]
[Sun Aug 30 03:09:01.538842 2026] [authz_core:error] [pid 510357:tid 510604] [client 66.249.66.204:60362] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:01.555484 2026] [security2:error] [pid 509915:tid 510160] [client 20.48.251.3:55708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/xza.php"] [unique_id "apPlHc2gn1q0xw8Wp-TgcQAABaQ"]
[Sun Aug 30 03:09:01.568291 2026] [security2:error] [pid 509915:tid 510114] [client 20.104.50.220:61475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/min.php"] [unique_id "apPlHc2gn1q0xw8Wp-TgdgAABXY"]
[Sun Aug 30 03:09:01.581400 2026] [security2:error] [pid 510357:tid 510584] [client 20.104.49.130:63550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/m.php"] [unique_id "apPlHX5YTqJxoOZUSXtE-gAABhQ"]
[Sun Aug 30 03:09:01.585980 2026] [authz_core:error] [pid 509172:tid 509373] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:01.586417 2026] [authz_core:error] [pid 509172:tid 509373] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:01.624152 2026] [security2:error] [pid 509915:tid 510053] [client 20.63.81.20:52695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/class17.php"] [unique_id "apPlHc2gn1q0xw8Wp-TgkQAABTk"]
[Sun Aug 30 03:09:01.634827 2026] [security2:error] [pid 509172:tid 509413] [client 20.48.250.41:61193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/wp-blogs.php"] [unique_id "apPlHZwMiz5K1he2FnkTcwAAAfw"]
[Sun Aug 30 03:09:01.662977 2026] [security2:error] [pid 509172:tid 509391] [client 74.248.24.12:17705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/wp_wol.php"] [unique_id "apPlHZwMiz5K1he2FnkTiwAAAeY"]
[Sun Aug 30 03:09:01.671909 2026] [security2:error] [pid 509172:tid 509346] [client 20.48.160.90:45910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp-includes/ID3/getid.php"] [unique_id "apPlHZwMiz5K1he2FnkTjwAAAbk"]
[Sun Aug 30 03:09:01.688513 2026] [security2:error] [pid 509172:tid 509375] [client 20.220.204.93:52312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/fetch.php"] [unique_id "apPlHZwMiz5K1he2FnkTnwAAAdY"]
[Sun Aug 30 03:09:01.757220 2026] [security2:error] [pid 509172:tid 509345] [client 20.63.81.20:52673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/okxoby.php"] [unique_id "apPlHZwMiz5K1he2FnkTwQAAAbg"]
[Sun Aug 30 03:09:01.761686 2026] [authz_core:error] [pid 509172:tid 509422] [client 66.249.66.64:64175] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:01.762120 2026] [authz_core:error] [pid 509172:tid 509422] [client 66.249.66.64:64175] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:01.768117 2026] [security2:error] [pid 509915:tid 510053] [client 20.48.250.41:60538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/mini.php"] [unique_id "apPlHc2gn1q0xw8Wp-Tg2AAABTk"]
[Sun Aug 30 03:09:01.806982 2026] [security2:error] [pid 509172:tid 509342] [client 20.48.160.90:45851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/session.php"] [unique_id "apPlHZwMiz5K1he2FnkT2AAAAbU"]
[Sun Aug 30 03:09:01.818713 2026] [security2:error] [pid 509172:tid 509306] [client 20.151.200.44:45954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/sxxb.php"] [unique_id "apPlHZwMiz5K1he2FnkT4AAAAZE"]
[Sun Aug 30 03:09:01.847796 2026] [security2:error] [pid 509915:tid 510062] [client 20.220.204.93:59132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/vx.php"] [unique_id "apPlHc2gn1q0xw8Wp-ThBwAABUI"]
[Sun Aug 30 03:09:01.885811 2026] [security2:error] [pid 509172:tid 509344] [client 20.63.81.20:52656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/esuutzzx.php"] [unique_id "apPlHZwMiz5K1he2FnkUEAAAAbc"]
[Sun Aug 30 03:09:01.898100 2026] [security2:error] [pid 509172:tid 509376] [client 20.48.250.41:61220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/amp.php"] [unique_id "apPlHZwMiz5K1he2FnkUFwAAAdc"]
[Sun Aug 30 03:09:01.906041 2026] [authz_core:error] [pid 509172:tid 509405] [client 66.249.66.74:54535] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:01.906311 2026] [authz_core:error] [pid 509172:tid 509405] [client 66.249.66.74:54535] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:01.936674 2026] [security2:error] [pid 509915:tid 510155] [client 4.205.62.107:17150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/dialog.php"] [unique_id "apPlHc2gn1q0xw8Wp-ThMgAABZ8"]
[Sun Aug 30 03:09:01.939121 2026] [security2:error] [pid 510357:tid 510508] [client 158.158.54.35:27215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/cd.php"] [unique_id "apPlHX5YTqJxoOZUSXtFRQAABcg"]
[Sun Aug 30 03:09:01.942336 2026] [security2:error] [pid 509172:tid 509420] [client 20.48.160.90:40006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/eagle.php"] [unique_id "apPlHZwMiz5K1he2FnkUOgAAAgM"]
[Sun Aug 30 03:09:01.980876 2026] [security2:error] [pid 509915:tid 510137] [client 20.220.204.93:52302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/global.php"] [unique_id "apPlHc2gn1q0xw8Wp-ThUAAABY0"]
[Sun Aug 30 03:09:01.994110 2026] [security2:error] [pid 509172:tid 509364] [client 20.48.251.3:7365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/pass4.php"] [unique_id "apPlHZwMiz5K1he2FnkUWgAAAcs"]
[Sun Aug 30 03:09:02.014036 2026] [security2:error] [pid 509915:tid 510154] [client 20.63.81.20:52593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/replace.php"] [unique_id "apPlHs2gn1q0xw8Wp-ThZAAABZ4"]
[Sun Aug 30 03:09:02.024412 2026] [authz_core:error] [pid 509915:tid 510073] [client 66.249.66.69:34901] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:02.024773 2026] [authz_core:error] [pid 509915:tid 510073] [client 66.249.66.69:34901] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:02.027182 2026] [security2:error] [pid 510357:tid 510579] [client 20.48.250.41:61208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/cc13.php"] [unique_id "apPlHn5YTqJxoOZUSXtFWgAABg8"]
[Sun Aug 30 03:09:02.061592 2026] [security2:error] [pid 510357:tid 510615] [client 20.151.200.44:59461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/pk.php"] [unique_id "apPlHn5YTqJxoOZUSXtFZgAABjM"]
[Sun Aug 30 03:09:02.078056 2026] [security2:error] [pid 509915:tid 510056] [client 20.104.18.15:35490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/t3.php"] [unique_id "apPlHs2gn1q0xw8Wp-ThiwAABTw"]
[Sun Aug 30 03:09:02.079246 2026] [security2:error] [pid 509172:tid 509344] [client 4.205.62.107:61722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/wp-admin/sc.php"] [unique_id "apPlHpwMiz5K1he2FnkUgwAAAbc"]
[Sun Aug 30 03:09:02.086813 2026] [authz_core:error] [pid 509172:tid 509358] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:02.087586 2026] [authz_core:error] [pid 509172:tid 509358] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:02.087771 2026] [security2:error] [pid 509172:tid 509305] [client 20.48.160.90:45836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/up-kon.php"] [unique_id "apPlHpwMiz5K1he2FnkUiwAAAZA"]
[Sun Aug 30 03:09:02.091676 2026] [security2:error] [pid 509915:tid 510141] [client 68.155.159.216:61436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/x.php"] [unique_id "apPlHs2gn1q0xw8Wp-ThkAAABZE"]
[Sun Aug 30 03:09:02.138219 2026] [security2:error] [pid 509172:tid 509376] [client 20.220.204.93:59063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/fs.php"] [unique_id "apPlHpwMiz5K1he2FnkUowAAAdc"]
[Sun Aug 30 03:09:02.139196 2026] [security2:error] [pid 509915:tid 510155] [client 20.63.81.20:52619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/gulu.php"] [unique_id "apPlHs2gn1q0xw8Wp-ThogAABZ8"]
[Sun Aug 30 03:09:02.142589 2026] [security2:error] [pid 509172:tid 509379] [client 20.104.50.220:46609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wsd.php"] [unique_id "apPlHpwMiz5K1he2FnkUpgAAAdo"]
[Sun Aug 30 03:09:02.162477 2026] [security2:error] [pid 509172:tid 509417] [client 68.155.159.216:54254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wzy.php"] [unique_id "apPlHpwMiz5K1he2FnkUrQAAAgA"]
[Sun Aug 30 03:09:02.170567 2026] [security2:error] [pid 509172:tid 509423] [client 74.248.24.12:3004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/class-wp-cmd.php/fied.php"] [unique_id "apPlHpwMiz5K1he2FnkUtQAAAgY"]
[Sun Aug 30 03:09:02.173321 2026] [security2:error] [pid 509172:tid 509335] [client 4.205.62.107:25763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/radio.php"] [unique_id "apPlHpwMiz5K1he2FnkUtgAAAa4"]
[Sun Aug 30 03:09:02.192413 2026] [security2:error] [pid 509172:tid 509390] [client 20.104.18.15:34565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/dragonshell.php"] [unique_id "apPlHpwMiz5K1he2FnkUxwAAAeU"]
[Sun Aug 30 03:09:02.195852 2026] [security2:error] [pid 509915:tid 510138] [client 20.104.18.15:1862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/x.php"] [unique_id "apPlHs2gn1q0xw8Wp-ThtAAABY4"]
[Sun Aug 30 03:09:02.207210 2026] [security2:error] [pid 510357:tid 510595] [client 158.69.118.188:54823] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "158.69.118.188" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPlHn5YTqJxoOZUSXtFjQAABh8"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:09:02.207298 2026] [security2:error] [pid 510357:tid 510595] [client 158.69.118.188:54823] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPlHn5YTqJxoOZUSXtFjQAABh8"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:09:02.226308 2026] [security2:error] [pid 509172:tid 509375] [client 20.48.251.3:59858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/cxc.php"] [unique_id "apPlHpwMiz5K1he2FnkU3QAAAdY"]
[Sun Aug 30 03:09:02.229097 2026] [security2:error] [pid 509172:tid 509355] [client 20.48.160.90:45883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/tinny.php"] [unique_id "apPlHpwMiz5K1he2FnkU4AAAAcI"]
[Sun Aug 30 03:09:02.231825 2026] [security2:error] [pid 509172:tid 509347] [client 20.104.49.130:63582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-blogs.php"] [unique_id "apPlHpwMiz5K1he2FnkU4gAAAbo"]
[Sun Aug 30 03:09:02.253104 2026] [security2:error] [pid 509172:tid 509316] [client 20.48.250.41:61289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/aa.php"] [unique_id "apPlHpwMiz5K1he2FnkU9QAAAZs"]
[Sun Aug 30 03:09:02.264286 2026] [security2:error] [pid 509915:tid 510122] [client 20.104.50.220:63550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/madspotshell.php"] [unique_id "apPlHs2gn1q0xw8Wp-Th0AAABX4"]
[Sun Aug 30 03:09:02.267588 2026] [security2:error] [pid 510357:tid 510603] [client 20.104.50.220:6136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/.well-known/a.php"] [unique_id "apPlHn5YTqJxoOZUSXtFoAAABic"]
[Sun Aug 30 03:09:02.271332 2026] [security2:error] [pid 509172:tid 509342] [client 20.63.81.20:52553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/gtghklk.php"] [unique_id "apPlHpwMiz5K1he2FnkVBQAAAbU"]
[Sun Aug 30 03:09:02.277514 2026] [security2:error] [pid 509915:tid 510100] [client 20.220.204.93:59122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/ioxi.php"] [unique_id "apPlHs2gn1q0xw8Wp-Th2AAABWg"]
[Sun Aug 30 03:09:02.281706 2026] [security2:error] [pid 509172:tid 509306] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/logs/.env"] [unique_id "apPlHpwMiz5K1he2FnkVEAAAAZE"]
[Sun Aug 30 03:09:02.283522 2026] [authz_core:error] [pid 509172:tid 509370] [client 66.249.66.203:44434] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:02.283812 2026] [authz_core:error] [pid 509172:tid 509370] [client 66.249.66.203:44434] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:02.310961 2026] [security2:error] [pid 509172:tid 509314] [client 20.151.200.44:46066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/dx.php"] [unique_id "apPlHpwMiz5K1he2FnkVMwAAAZk"]
[Sun Aug 30 03:09:02.350730 2026] [security2:error] [pid 509172:tid 509365] [client 20.104.18.15:18321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/h2.php"] [unique_id "apPlHpwMiz5K1he2FnkVVgAAAcw"]
[Sun Aug 30 03:09:02.363062 2026] [security2:error] [pid 509172:tid 509420] [client 20.48.160.90:45943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp-easy.php"] [unique_id "apPlHpwMiz5K1he2FnkVXwAAAgM"]
[Sun Aug 30 03:09:02.375042 2026] [security2:error] [pid 509172:tid 509402] [client 20.104.49.130:59558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/x1da.php"] [unique_id "apPlHpwMiz5K1he2FnkVZQAAAfE"]
[Sun Aug 30 03:09:02.384433 2026] [security2:error] [pid 509915:tid 510104] [client 158.158.54.35:34896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/5173e.php"] [unique_id "apPlHs2gn1q0xw8Wp-Th_wAABWw"]
[Sun Aug 30 03:09:02.401945 2026] [security2:error] [pid 509172:tid 509312] [client 20.63.81.20:52698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/comand.php"] [unique_id "apPlHpwMiz5K1he2FnkVdgAAAZc"]
[Sun Aug 30 03:09:02.423589 2026] [security2:error] [pid 510357:tid 510562] [client 20.48.250.41:60509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/s1.php"] [unique_id "apPlHn5YTqJxoOZUSXtFrAAABf4"]
[Sun Aug 30 03:09:02.445448 2026] [security2:error] [pid 509172:tid 509321] [client 20.220.204.93:59088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/bootstrap.php"] [unique_id "apPlHpwMiz5K1he2FnkVjwAAAaA"]
[Sun Aug 30 03:09:02.471399 2026] [security2:error] [pid 509172:tid 509344] [client 20.104.18.15:43988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/m.php"] [unique_id "apPlHpwMiz5K1he2FnkVqAAAAbc"]
[Sun Aug 30 03:09:02.487952 2026] [security2:error] [pid 509915:tid 510136] [client 20.104.50.220:16713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/hg.php"] [unique_id "apPlHs2gn1q0xw8Wp-TiKwAABYw"]
[Sun Aug 30 03:09:02.497359 2026] [security2:error] [pid 509915:tid 510166] [client 20.48.160.90:40003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/d7.php"] [unique_id "apPlHs2gn1q0xw8Wp-TiLgAABao"]
[Sun Aug 30 03:09:02.517552 2026] [security2:error] [pid 509172:tid 509313] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/cache/.env"] [unique_id "apPlHpwMiz5K1he2FnkV2AAAAZg"]
[Sun Aug 30 03:09:02.540127 2026] [security2:error] [pid 509915:tid 510088] [client 20.63.81.20:52623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp_motu_myk3v.php"] [unique_id "apPlHs2gn1q0xw8Wp-TiSQAABVw"]
[Sun Aug 30 03:09:02.548517 2026] [security2:error] [pid 509915:tid 509992] [remote 152.53.108.193:48806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.108.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "impend.com"] [uri "/wp-login.php"] [unique_id "apPlHs2gn1q0xw8Wp-TiTQAFlUs"]
[Sun Aug 30 03:09:02.556689 2026] [security2:error] [pid 509915:tid 510103] [client 20.48.250.41:60515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/0byte.php"] [unique_id "apPlHs2gn1q0xw8Wp-TiWgAABWs"]
[Sun Aug 30 03:09:02.576573 2026] [security2:error] [pid 509172:tid 509381] [client 158.69.118.188:54837] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "158.69.118.188" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPlHpwMiz5K1he2FnkWAQAAAdw"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:09:02.576662 2026] [security2:error] [pid 509172:tid 509381] [client 158.69.118.188:54837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPlHpwMiz5K1he2FnkWAQAAAdw"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:09:02.582963 2026] [authz_core:error] [pid 509172:tid 509339] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:02.583319 2026] [authz_core:error] [pid 509172:tid 509339] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:02.587278 2026] [security2:error] [pid 509915:tid 510064] [client 20.104.50.220:52817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/xamp.php"] [unique_id "apPlHs2gn1q0xw8Wp-TiaAAABUQ"]
[Sun Aug 30 03:09:02.597602 2026] [security2:error] [pid 509172:tid 509359] [client 20.104.50.220:62838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/tod.php"] [unique_id "apPlHpwMiz5K1he2FnkWEAAAAcY"]
[Sun Aug 30 03:09:02.598020 2026] [security2:error] [pid 509172:tid 509371] [client 20.104.18.15:23379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/revo.php"] [unique_id "apPlHpwMiz5K1he2FnkWEQAAAdI"]
[Sun Aug 30 03:09:02.604034 2026] [security2:error] [pid 509172:tid 509393] [client 20.104.50.220:32854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/Good.php"] [unique_id "apPlHpwMiz5K1he2FnkWFgAAAeg"]
[Sun Aug 30 03:09:02.621691 2026] [authz_core:error] [pid 509915:tid 510161] [client 66.249.66.195:53027] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:02.622087 2026] [authz_core:error] [pid 509915:tid 510161] [client 66.249.66.195:53027] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:02.629950 2026] [security2:error] [pid 509172:tid 509429] [client 20.48.160.90:26700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/v5.php"] [unique_id "apPlHpwMiz5K1he2FnkWJQAAAgw"]
[Sun Aug 30 03:09:02.641391 2026] [security2:error] [pid 509172:tid 509358] [client 20.220.204.93:59125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/export.php"] [unique_id "apPlHpwMiz5K1he2FnkWKAAAAcU"]
[Sun Aug 30 03:09:02.655784 2026] [security2:error] [pid 509172:tid 509425] [client 20.48.251.3:60485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/png.php"] [unique_id "apPlHpwMiz5K1he2FnkWLQAAAgg"]
[Sun Aug 30 03:09:02.671751 2026] [security2:error] [pid 510357:tid 510533] [client 20.63.81.20:52579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/wp_motu_ypdat.php"] [unique_id "apPlHn5YTqJxoOZUSXtF0gAABeE"]
[Sun Aug 30 03:09:02.672138 2026] [security2:error] [pid 509172:tid 509365] [client 74.248.24.12:6864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/M1.php"] [unique_id "apPlHpwMiz5K1he2FnkWMgAAAcw"]
[Sun Aug 30 03:09:02.675402 2026] [security2:error] [pid 509915:tid 510096] [client 20.104.50.220:32070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/about.php"] [unique_id "apPlHs2gn1q0xw8Wp-TikAAABWQ"]
[Sun Aug 30 03:09:02.687379 2026] [security2:error] [pid 510357:tid 510553] [client 20.48.251.3:59327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/ms-edit.php"] [unique_id "apPlHn5YTqJxoOZUSXtF1wAABfU"]
[Sun Aug 30 03:09:02.687758 2026] [security2:error] [pid 510357:tid 510586] [client 20.104.49.130:36783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/33.php"] [unique_id "apPlHn5YTqJxoOZUSXtF2AAABhY"]
[Sun Aug 30 03:09:02.712228 2026] [security2:error] [pid 510357:tid 510588] [client 20.48.250.41:60420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/xr.php"] [unique_id "apPlHn5YTqJxoOZUSXtF4AAABhg"]
[Sun Aug 30 03:09:02.719914 2026] [security2:error] [pid 509915:tid 510157] [client 20.104.50.220:61448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-backup-sql-302.php"] [unique_id "apPlHs2gn1q0xw8Wp-TitAAABaE"]
[Sun Aug 30 03:09:02.726358 2026] [authz_core:error] [pid 509915:tid 510107] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:02.726790 2026] [authz_core:error] [pid 509915:tid 510107] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:02.759412 2026] [security2:error] [pid 509172:tid 509313] [client 20.48.160.90:39942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/az.php"] [unique_id "apPlHpwMiz5K1he2FnkWVQAAAZg"]
[Sun Aug 30 03:09:02.768994 2026] [security2:error] [pid 509915:tid 509994] [remote 152.53.108.193:48806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.108.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "impend.com"] [uri "/wp-login.php"] [unique_id "apPlHs2gn1q0xw8Wp-Ti2QAFNk0"], referer: https://impend.com/wp-login.php
[Sun Aug 30 03:09:02.770181 2026] [security2:error] [pid 509172:tid 509346] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/mailer/.env"] [unique_id "apPlHpwMiz5K1he2FnkWXgAAAbk"]
[Sun Aug 30 03:09:02.790807 2026] [authz_core:error] [pid 509915:tid 510145] [client 66.249.66.193:59033] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:02.791297 2026] [authz_core:error] [pid 509915:tid 510145] [client 66.249.66.193:59033] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:02.815688 2026] [security2:error] [pid 510357:tid 510615] [client 158.158.54.35:28091] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "direcorgigames.com"] [uri "/c99.php"] [unique_id "apPlHn5YTqJxoOZUSXtF-wAABjM"]
[Sun Aug 30 03:09:02.822928 2026] [security2:error] [pid 509915:tid 510047] [client 20.63.81.20:52639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/edit.php"] [unique_id "apPlHs2gn1q0xw8Wp-Ti-wAABTM"]
[Sun Aug 30 03:09:02.824990 2026] [security2:error] [pid 509915:tid 510138] [client 20.220.204.93:59126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/gk.php"] [unique_id "apPlHs2gn1q0xw8Wp-Ti_gAABY4"]
[Sun Aug 30 03:09:02.831063 2026] [security2:error] [pid 509915:tid 510167] [client 20.104.49.130:47970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/worksec.php"] [unique_id "apPlHs2gn1q0xw8Wp-TjAAAABas"]
[Sun Aug 30 03:09:02.837615 2026] [security2:error] [pid 509172:tid 509327] [client 20.48.250.41:60445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/h02ugyh.php"] [unique_id "apPlHpwMiz5K1he2FnkWkgAAAaY"]
[Sun Aug 30 03:09:02.848629 2026] [security2:error] [pid 509915:tid 510130] [client 68.155.159.216:45969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/dropdown.php"] [unique_id "apPlHs2gn1q0xw8Wp-TjDQAABYY"]
[Sun Aug 30 03:09:02.889206 2026] [security2:error] [pid 509172:tid 509323] [client 20.48.160.90:45937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/js.php"] [unique_id "apPlHpwMiz5K1he2FnkWwAAAAaI"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:02.926837 2026] [security2:error] [pid 509915:tid 510135] [client 137.184.201.15:49913] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "wondertanks.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "apPlHs2gn1q0xw8Wp-TjKgAABYs"]
[Sun Aug 30 03:09:02.953543 2026] [security2:error] [pid 509172:tid 509371] [client 20.63.81.20:52562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/tqkdqbbv.php"] [unique_id "apPlHpwMiz5K1he2FnkW8gAAAdI"]
[Sun Aug 30 03:09:02.978749 2026] [security2:error] [pid 509915:tid 510148] [client 20.48.250.41:60434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/xxw.php"] [unique_id "apPlHs2gn1q0xw8Wp-TjQQAABZg"]
[Sun Aug 30 03:09:02.988560 2026] [security2:error] [pid 509172:tid 509317] [client 20.220.204.93:59092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/logs1.php"] [unique_id "apPlHpwMiz5K1he2FnkXEwAAAZw"]
[Sun Aug 30 03:09:03.015140 2026] [security2:error] [pid 509172:tid 509352] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/mail/.env"] [unique_id "apPlH5wMiz5K1he2FnkXKQAAAb8"]
[Sun Aug 30 03:09:03.028144 2026] [authz_core:error] [pid 509172:tid 509358] [client 66.249.66.76:49793] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:03.028573 2026] [authz_core:error] [pid 509172:tid 509358] [client 66.249.66.76:49793] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:03.030357 2026] [security2:error] [pid 509915:tid 510101] [client 20.48.160.90:45916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/hd.php"] [unique_id "apPlH82gn1q0xw8Wp-TjYwAABWk"]
[Sun Aug 30 03:09:03.051309 2026] [authz_core:error] [pid 509172:tid 509399] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:03.051799 2026] [authz_core:error] [pid 509172:tid 509399] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:03.074714 2026] [security2:error] [pid 510357:tid 510569] [client 4.205.62.107:17103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/phpinfo01.php"] [unique_id "apPlH35YTqJxoOZUSXtGHQAABgU"]
[Sun Aug 30 03:09:03.083025 2026] [security2:error] [pid 509915:tid 510134] [client 20.63.81.20:52545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/kjyehoxl.php"] [unique_id "apPlH82gn1q0xw8Wp-TjhwAABYo"]
[Sun Aug 30 03:09:03.104987 2026] [security2:error] [pid 509172:tid 509384] [client 20.48.250.41:60510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/bolt.php"] [unique_id "apPlH5wMiz5K1he2FnkXZwAAAd8"]
[Sun Aug 30 03:09:03.138267 2026] [security2:error] [pid 509172:tid 509342] [client 20.48.251.3:7403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/cu.php"] [unique_id "apPlH5wMiz5K1he2FnkXfwAAAbU"]
[Sun Aug 30 03:09:03.168469 2026] [security2:error] [pid 509172:tid 509317] [client 20.220.204.93:59078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/inege.php"] [unique_id "apPlH5wMiz5K1he2FnkXkQAAAZw"]
[Sun Aug 30 03:09:03.185111 2026] [security2:error] [pid 510357:tid 510554] [client 20.48.160.90:40010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/xl2023.php"] [unique_id "apPlH35YTqJxoOZUSXtGJgAABfY"]
[Sun Aug 30 03:09:03.192786 2026] [security2:error] [pid 509172:tid 509324] [client 74.248.24.12:6876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/DxHhVcy2bmJ.php"] [unique_id "apPlH5wMiz5K1he2FnkXngAAAaM"]
[Sun Aug 30 03:09:03.213120 2026] [security2:error] [pid 509915:tid 510121] [client 20.63.81.20:52654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/llyuxaqd.php"] [unique_id "apPlH82gn1q0xw8Wp-TjyAAABX0"]
[Sun Aug 30 03:09:03.224573 2026] [security2:error] [pid 509915:tid 510123] [client 4.205.62.107:61796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/debug.php"] [unique_id "apPlH82gn1q0xw8Wp-TjzQAABX8"]
[Sun Aug 30 03:09:03.235139 2026] [security2:error] [pid 509915:tid 510166] [client 20.104.18.15:35513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/wp.php"] [unique_id "apPlH82gn1q0xw8Wp-Tj1QAABao"]
[Sun Aug 30 03:09:03.235415 2026] [security2:error] [pid 509915:tid 510052] [client 20.48.250.41:60495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/rtx.php"] [unique_id "apPlH82gn1q0xw8Wp-Tj2AAABTg"]
[Sun Aug 30 03:09:03.250443 2026] [security2:error] [pid 509172:tid 509431] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/email/.env"] [unique_id "apPlH5wMiz5K1he2FnkXqwAAAg4"]
[Sun Aug 30 03:09:03.274776 2026] [security2:error] [pid 509172:tid 509316] [client 68.155.159.216:54455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apPlH5wMiz5K1he2FnkXvAAAAZs"]
[Sun Aug 30 03:09:03.278958 2026] [security2:error] [pid 509172:tid 509344] [client 158.158.54.35:20289] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "direcorgigames.com"] [uri "/c99.php"] [unique_id "apPlH5wMiz5K1he2FnkXxAAAAbc"]
[Sun Aug 30 03:09:03.293446 2026] [security2:error] [pid 510357:tid 510516] [client 20.104.50.220:46190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/f6.php"] [unique_id "apPlH35YTqJxoOZUSXtGNAAABdA"]
[Sun Aug 30 03:09:03.301320 2026] [authz_core:error] [pid 509172:tid 509399] [client 216.73.216.128:28951] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:03.301695 2026] [authz_core:error] [pid 509172:tid 509399] [client 216.73.216.128:28951] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:03.312449 2026] [security2:error] [pid 509915:tid 510146] [client 20.48.160.90:45912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/V2.php"] [unique_id "apPlH82gn1q0xw8Wp-TkHAAABZY"]
[Sun Aug 30 03:09:03.314853 2026] [security2:error] [pid 509172:tid 509413] [client 20.220.204.93:52238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/wp-link10.php"] [unique_id "apPlH5wMiz5K1he2FnkX5gAAAfw"]
[Sun Aug 30 03:09:03.328553 2026] [security2:error] [pid 509915:tid 510150] [client 4.205.62.107:36668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "apPlH82gn1q0xw8Wp-TkJQAABZo"]
[Sun Aug 30 03:09:03.333015 2026] [security2:error] [pid 509172:tid 509422] [client 20.104.18.15:1944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apPlH5wMiz5K1he2FnkX9gAAAgU"]
[Sun Aug 30 03:09:03.339398 2026] [security2:error] [pid 509172:tid 509338] [client 20.63.81.20:52399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/nbwxolou.php"] [unique_id "apPlH5wMiz5K1he2FnkX-wAAAbE"]
[Sun Aug 30 03:09:03.341196 2026] [security2:error] [pid 509915:tid 510093] [client 20.104.49.130:36760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/wsd.php"] [unique_id "apPlH82gn1q0xw8Wp-TkKgAABWE"]
[Sun Aug 30 03:09:03.342081 2026] [security2:error] [pid 509915:tid 510077] [client 20.104.18.15:34699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/wp-safe.php"] [unique_id "apPlH82gn1q0xw8Wp-TkLAAABVE"]
[Sun Aug 30 03:09:03.356008 2026] [security2:error] [pid 509172:tid 509330] [client 20.151.200.44:59558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/ft.php"] [unique_id "apPlH5wMiz5K1he2FnkYBAAAAak"]
[Sun Aug 30 03:09:03.357950 2026] [security2:error] [pid 509915:tid 510172] [client 4.205.62.107:25754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/xa.php"] [unique_id "apPlH82gn1q0xw8Wp-TkNAAABbA"]
[Sun Aug 30 03:09:03.374099 2026] [security2:error] [pid 509915:tid 510171] [client 20.48.251.3:52257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/oiko6u.php"] [unique_id "apPlH82gn1q0xw8Wp-TkOwAABa8"]
[Sun Aug 30 03:09:03.379194 2026] [security2:error] [pid 509915:tid 510059] [client 20.48.250.41:60514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/ckk.php"] [unique_id "apPlH82gn1q0xw8Wp-TkQAAABT8"]
[Sun Aug 30 03:09:03.421356 2026] [security2:error] [pid 509915:tid 510116] [client 20.104.50.220:5600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/js.php"] [unique_id "apPlH82gn1q0xw8Wp-TkUwAABXg"]
[Sun Aug 30 03:09:03.432934 2026] [security2:error] [pid 510357:tid 510585] [client 20.104.50.220:51615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/sa.php"] [unique_id "apPlH35YTqJxoOZUSXtGSgAABhU"]
[Sun Aug 30 03:09:03.444099 2026] [security2:error] [pid 509172:tid 509332] [client 20.48.160.90:26732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/mad.php"] [unique_id "apPlH5wMiz5K1he2FnkYMgAAAas"]
[Sun Aug 30 03:09:03.461569 2026] [security2:error] [pid 509915:tid 510062] [client 68.155.159.216:62055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-content/x.php"] [unique_id "apPlH82gn1q0xw8Wp-TkbgAABUI"]
[Sun Aug 30 03:09:03.468888 2026] [security2:error] [pid 510357:tid 510529] [client 20.63.81.20:52630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/nsxeubyv.php"] [unique_id "apPlH35YTqJxoOZUSXtGWAAABd0"]
[Sun Aug 30 03:09:03.484346 2026] [security2:error] [pid 509172:tid 509409] [client 20.220.204.93:59077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/ww.php"] [unique_id "apPlH5wMiz5K1he2FnkYUgAAAfg"]
[Sun Aug 30 03:09:03.489877 2026] [security2:error] [pid 509172:tid 509355] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/smtp/.env"] [unique_id "apPlH5wMiz5K1he2FnkYWwAAAcI"]
[Sun Aug 30 03:09:03.518755 2026] [security2:error] [pid 510357:tid 510592] [client 20.48.250.41:61214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app-crafter.com"] [uri "/R57.php"] [unique_id "apPlH35YTqJxoOZUSXtGYgAABhw"]
[Sun Aug 30 03:09:03.522236 2026] [security2:error] [pid 509915:tid 510152] [client 20.104.18.15:18341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apPlH82gn1q0xw8Wp-TklAAABZw"]
[Sun Aug 30 03:09:03.537634 2026] [authz_core:error] [pid 509915:tid 510058] [client 66.249.66.38:52202] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:03.538194 2026] [authz_core:error] [pid 509915:tid 510058] [client 66.249.66.38:52202] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:03.586392 2026] [authz_core:error] [pid 509172:tid 509415] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:03.586841 2026] [authz_core:error] [pid 509172:tid 509415] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:03.594998 2026] [security2:error] [pid 509172:tid 509428] [client 20.48.160.90:45891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/st.php"] [unique_id "apPlH5wMiz5K1he2FnkYpwAAAgs"]
[Sun Aug 30 03:09:03.600411 2026] [security2:error] [pid 509915:tid 510116] [client 20.63.81.20:52732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/zfqipfss.php"] [unique_id "apPlH82gn1q0xw8Wp-TkugAABXg"]
[Sun Aug 30 03:09:03.613348 2026] [security2:error] [pid 509915:tid 510167] [client 20.104.50.220:17228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/file48.php"] [unique_id "apPlH82gn1q0xw8Wp-TkwQAABas"]
[Sun Aug 30 03:09:03.630943 2026] [security2:error] [pid 509172:tid 509386] [client 20.104.18.15:43288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/fling.php"] [unique_id "apPlH5wMiz5K1he2FnkYvgAAAeE"]
[Sun Aug 30 03:09:03.636967 2026] [security2:error] [pid 510357:tid 510584] [client 20.220.204.93:52330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/w1px.php"] [unique_id "apPlH35YTqJxoOZUSXtGcAAABhQ"]
[Sun Aug 30 03:09:03.657804 2026] [security2:error] [pid 510357:tid 510528] [client 20.104.49.130:63528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/133.php"] [unique_id "apPlH35YTqJxoOZUSXtGcwAABdw"]
[Sun Aug 30 03:09:03.700294 2026] [security2:error] [pid 509172:tid 509349] [client 20.104.49.130:60611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/1xmomo.php"] [unique_id "apPlH5wMiz5K1he2FnkY8AAAAbw"]
[Sun Aug 30 03:09:03.703988 2026] [security2:error] [pid 509172:tid 509404] [client 74.248.24.12:12220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/browse.php"] [unique_id "apPlH5wMiz5K1he2FnkY8wAAAfM"]
[Sun Aug 30 03:09:03.721004 2026] [security2:error] [pid 509172:tid 509379] [client 20.104.50.220:28674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/ya.php"] [unique_id "apPlH5wMiz5K1he2FnkZBAAAAdo"]
[Sun Aug 30 03:09:03.727153 2026] [security2:error] [pid 509172:tid 509423] [client 20.48.160.90:45948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/alfanew.php"] [unique_id "apPlH5wMiz5K1he2FnkZBwAAAgY"]
[Sun Aug 30 03:09:03.728751 2026] [security2:error] [pid 510357:tid 510568] [client 158.158.54.35:5392] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "direcorgigames.com"] [uri "/c99.php"] [unique_id "apPlH35YTqJxoOZUSXtGgAAABgQ"]
[Sun Aug 30 03:09:03.731816 2026] [security2:error] [pid 509172:tid 509371] [client 20.63.81.20:52556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.st20.org"] [uri "/zrjuyoos.php"] [unique_id "apPlH5wMiz5K1he2FnkZDAAAAdI"]
[Sun Aug 30 03:09:03.733413 2026] [security2:error] [pid 509172:tid 509409] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/mailing/.env"] [unique_id "apPlH5wMiz5K1he2FnkZDgAAAfg"]
[Sun Aug 30 03:09:03.736447 2026] [security2:error] [pid 509915:tid 510141] [client 20.104.18.15:23439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/birrs.php"] [unique_id "apPlH82gn1q0xw8Wp-Tk_gAABZE"]
[Sun Aug 30 03:09:03.761423 2026] [security2:error] [pid 509172:tid 509417] [client 20.104.50.220:29170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/setor.php"] [unique_id "apPlH5wMiz5K1he2FnkZHwAAAgA"]
[Sun Aug 30 03:09:03.809427 2026] [security2:error] [pid 509915:tid 510069] [client 20.104.49.130:53616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/sxxb.php"] [unique_id "apPlH82gn1q0xw8Wp-TlRAAABUk"]
[Sun Aug 30 03:09:03.823023 2026] [security2:error] [pid 509172:tid 509409] [client 20.104.50.220:31813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/abcd.php"] [unique_id "apPlH5wMiz5K1he2FnkZTwAAAfg"]
[Sun Aug 30 03:09:03.843566 2026] [security2:error] [pid 509172:tid 509427] [client 20.48.251.3:59337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/lmfi2.php"] [unique_id "apPlH5wMiz5K1he2FnkZXgAAAgo"]
[Sun Aug 30 03:09:03.844289 2026] [authz_core:error] [pid 509172:tid 509414] [client 216.73.216.128:26821] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:03.844553 2026] [authz_core:error] [pid 509172:tid 509414] [client 216.73.216.128:26821] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:03.856568 2026] [security2:error] [pid 509915:tid 510086] [client 20.48.160.90:45909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/ioxi.php"] [unique_id "apPlH82gn1q0xw8Wp-TlVwAABVo"]
[Sun Aug 30 03:09:03.864476 2026] [security2:error] [pid 509172:tid 509327] [client 20.104.50.220:61476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/json-php.php"] [unique_id "apPlH5wMiz5K1he2FnkZaQAAAaY"]
[Sun Aug 30 03:09:03.883726 2026] [security2:error] [pid 509915:tid 510154] [client 20.104.49.130:43308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/dehnl.php"] [unique_id "apPlH82gn1q0xw8Wp-TlZwAABZ4"]
[Sun Aug 30 03:09:03.918023 2026] [security2:error] [pid 509915:tid 510083] [client 20.48.251.3:13384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/chosen.php"] [unique_id "apPlH82gn1q0xw8Wp-TlegAABVc"]
[Sun Aug 30 03:09:03.926929 2026] [security2:error] [pid 510357:tid 510500] [client 20.220.204.93:59036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/to.php"] [unique_id "apPlH35YTqJxoOZUSXtGogAABcA"]
[Sun Aug 30 03:09:03.953082 2026] [security2:error] [pid 509172:tid 509311] [client 20.151.200.44:45985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPlH5wMiz5K1he2FnkZqwAAAZY"]
[Sun Aug 30 03:09:03.964449 2026] [authz_core:error] [pid 509172:tid 509334] [client 66.249.66.67:55279] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:03.964731 2026] [authz_core:error] [pid 509172:tid 509334] [client 66.249.66.67:55279] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:03.981692 2026] [security2:error] [pid 509172:tid 509352] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/notifications/.env"] [unique_id "apPlH5wMiz5K1he2FnkZxQAAAb8"]
[Sun Aug 30 03:09:03.991595 2026] [security2:error] [pid 509172:tid 509361] [client 20.48.160.90:40016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/TNT.php"] [unique_id "apPlH5wMiz5K1he2FnkZzAAAAcg"]
[Sun Aug 30 03:09:04.044664 2026] [authz_core:error] [pid 509172:tid 509347] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:04.045165 2026] [authz_core:error] [pid 509172:tid 509347] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:04.053851 2026] [security2:error] [pid 509172:tid 509346] [client 20.220.204.93:59113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/thui.php"] [unique_id "apPlIJwMiz5K1he2FnkaAgAAAbk"]
[Sun Aug 30 03:09:04.090098 2026] [authz_core:error] [pid 509172:tid 509403] [client 66.249.66.70:52509] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:04.090486 2026] [authz_core:error] [pid 509172:tid 509403] [client 66.249.66.70:52509] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:04.118314 2026] [authz_core:error] [pid 509915:tid 510159] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:04.118744 2026] [authz_core:error] [pid 509915:tid 510159] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:04.148343 2026] [security2:error] [pid 509915:tid 510050] [client 20.48.160.90:45867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/cd.php"] [unique_id "apPlIM2gn1q0xw8Wp-Tl_gAABTY"]
[Sun Aug 30 03:09:04.174993 2026] [security2:error] [pid 509915:tid 510091] [client 158.158.54.35:28076] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "direcorgigames.com"] [uri "/c99.php"] [unique_id "apPlIM2gn1q0xw8Wp-TmDgAABV8"]
[Sun Aug 30 03:09:04.200584 2026] [security2:error] [pid 509915:tid 510003] [remote 156.59.198.136:41944] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.khanwadeabutalib.com"] [uri "/public/upload/media/20240822aZdownload%20____p%2033%20%20translated.pdf"] [unique_id "apPlIM2gn1q0xw8Wp-TmGQAFhlY"]
[Sun Aug 30 03:09:04.209108 2026] [security2:error] [pid 510357:tid 510536] [client 4.205.62.107:17284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/cxc.php"] [unique_id "apPlIH5YTqJxoOZUSXtGygAABeQ"]
[Sun Aug 30 03:09:04.218035 2026] [security2:error] [pid 509172:tid 509356] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/notify/.env"] [unique_id "apPlIJwMiz5K1he2FnkaXwAAAcM"]
[Sun Aug 30 03:09:04.224849 2026] [security2:error] [pid 509172:tid 509362] [client 3.79.134.69:42790] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "benchcreative.com.au"] [uri "/wp-content/endurance-page-cache/_index.html"] [unique_id "apPlIJwMiz5K1he2FnkaXgAAAck"], referer: https://benchcreative.com.au/
[Sun Aug 30 03:09:04.229495 2026] [security2:error] [pid 509915:tid 510146] [client 74.248.24.12:15293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/cljntmcz.php"] [unique_id "apPlIM2gn1q0xw8Wp-TmNgAABZY"]
[Sun Aug 30 03:09:04.276030 2026] [security2:error] [pid 509172:tid 509354] [client 20.48.160.90:40020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/luuf.php"] [unique_id "apPlIJwMiz5K1he2FnkagQAAAcE"]
[Sun Aug 30 03:09:04.293335 2026] [security2:error] [pid 509915:tid 510129] [client 216.73.216.128:55539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlIM2gn1q0xw8Wp-TmYAAABYU"]
[Sun Aug 30 03:09:04.307467 2026] [security2:error] [pid 509172:tid 509427] [client 20.220.204.93:59116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/Jcrop.php"] [unique_id "apPlIJwMiz5K1he2FnkaoQAAAgo"]
[Sun Aug 30 03:09:04.358568 2026] [security2:error] [pid 509172:tid 509349] [client 4.205.62.107:64509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/nzv.php"] [unique_id "apPlIJwMiz5K1he2FnkaxQAAAbw"]
[Sun Aug 30 03:09:04.374985 2026] [authz_core:error] [pid 509915:tid 510166] [client 66.249.66.45:36655] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:04.375291 2026] [authz_core:error] [pid 509915:tid 510166] [client 66.249.66.45:36655] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:04.383270 2026] [security2:error] [pid 509915:tid 510153] [client 68.155.159.216:55051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apPlIM2gn1q0xw8Wp-TmgwAABZ0"]
[Sun Aug 30 03:09:04.385997 2026] [security2:error] [pid 510357:tid 510539] [client 20.48.251.3:44142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/services.php"] [unique_id "apPlIH5YTqJxoOZUSXtG7AAABec"]
[Sun Aug 30 03:09:04.410290 2026] [security2:error] [pid 510357:tid 510524] [client 20.48.160.90:40042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/fex.php"] [unique_id "apPlIH5YTqJxoOZUSXtG8gAABdg"]
[Sun Aug 30 03:09:04.419253 2026] [security2:error] [pid 509915:tid 510126] [client 20.104.18.15:35185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/abcd.php"] [unique_id "apPlIM2gn1q0xw8Wp-TmngAABYI"]
[Sun Aug 30 03:09:04.435020 2026] [security2:error] [pid 509915:tid 510150] [client 20.104.50.220:46610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/he.php"] [unique_id "apPlIM2gn1q0xw8Wp-TmpgAABZo"]
[Sun Aug 30 03:09:04.436377 2026] [authz_core:error] [pid 509915:tid 510129] [client 66.249.66.33:59703] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:04.436859 2026] [authz_core:error] [pid 509915:tid 510129] [client 66.249.66.33:59703] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:04.459903 2026] [security2:error] [pid 509172:tid 509328] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/sender/.env"] [unique_id "apPlIJwMiz5K1he2Fnka7gAAAac"]
[Sun Aug 30 03:09:04.471848 2026] [security2:error] [pid 510357:tid 510611] [client 20.104.18.15:1810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/wp-includes/index.php"] [unique_id "apPlIH5YTqJxoOZUSXtHCgAABi8"]
[Sun Aug 30 03:09:04.475446 2026] [security2:error] [pid 509915:tid 510100] [client 20.220.204.93:59035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/ws58.php"] [unique_id "apPlIM2gn1q0xw8Wp-TmzAAABWg"]
[Sun Aug 30 03:09:04.483024 2026] [security2:error] [pid 509915:tid 510141] [client 20.104.18.15:34800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/gjewuagf.php"] [unique_id "apPlIM2gn1q0xw8Wp-Tm1AAABZE"]
[Sun Aug 30 03:09:04.509845 2026] [security2:error] [pid 509915:tid 510101] [client 20.48.251.3:59867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/fraro.php"] [unique_id "apPlIM2gn1q0xw8Wp-Tm8QAABWk"]
[Sun Aug 30 03:09:04.546053 2026] [security2:error] [pid 509915:tid 510088] [client 4.205.62.107:25755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/ws61.php"] [unique_id "apPlIM2gn1q0xw8Wp-TnDQAABVw"]
[Sun Aug 30 03:09:04.547097 2026] [security2:error] [pid 509915:tid 510059] [client 20.48.160.90:45914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/l.php"] [unique_id "apPlIM2gn1q0xw8Wp-TnDwAABT8"]
[Sun Aug 30 03:09:04.549500 2026] [security2:error] [pid 510357:tid 510618] [client 68.155.159.216:46033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/sad/about.php"] [unique_id "apPlIH5YTqJxoOZUSXtHIAAABjY"]
[Sun Aug 30 03:09:04.565993 2026] [authz_core:error] [pid 509172:tid 509351] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:04.566277 2026] [authz_core:error] [pid 509172:tid 509351] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:04.573821 2026] [security2:error] [pid 509915:tid 510149] [client 20.104.50.220:5902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-admin/install.php"] [unique_id "apPlIM2gn1q0xw8Wp-TnHgAABZk"]
[Sun Aug 30 03:09:04.592447 2026] [security2:error] [pid 509172:tid 509362] [client 20.104.50.220:51616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/noname.php"] [unique_id "apPlIJwMiz5K1he2FnkbOAAAAck"]
[Sun Aug 30 03:09:04.595845 2026] [security2:error] [pid 509172:tid 509421] [client 68.155.159.216:53486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPlIJwMiz5K1he2FnkbPAAAAgQ"]
[Sun Aug 30 03:09:04.625632 2026] [security2:error] [pid 509915:tid 510060] [client 158.158.54.35:27213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/404.php123123"] [unique_id "apPlIM2gn1q0xw8Wp-TnMgAABUA"]
[Sun Aug 30 03:09:04.660307 2026] [security2:error] [pid 509915:tid 510145] [client 20.104.18.15:18269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/sao.php"] [unique_id "apPlIM2gn1q0xw8Wp-TnQwAABZU"]
[Sun Aug 30 03:09:04.671129 2026] [security2:error] [pid 509172:tid 509364] [client 20.220.204.93:59025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/xs.php"] [unique_id "apPlIJwMiz5K1he2FnkbYAAAAcs"]
[Sun Aug 30 03:09:04.674892 2026] [security2:error] [pid 509915:tid 510075] [client 20.48.160.90:45841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/xr.php"] [unique_id "apPlIM2gn1q0xw8Wp-TnSgAABU8"]
[Sun Aug 30 03:09:04.692747 2026] [authz_core:error] [pid 509172:tid 509414] [client 66.249.66.193:64251] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:04.693235 2026] [authz_core:error] [pid 509172:tid 509414] [client 66.249.66.193:64251] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:04.694476 2026] [security2:error] [pid 509172:tid 509328] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/campaign/.env"] [unique_id "apPlIJwMiz5K1he2FnkbcQAAAac"]
[Sun Aug 30 03:09:04.746701 2026] [security2:error] [pid 509172:tid 509311] [client 74.248.24.12:2099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/fox.php"] [unique_id "apPlIJwMiz5K1he2FnkblQAAAZY"]
[Sun Aug 30 03:09:04.749023 2026] [security2:error] [pid 509172:tid 509326] [client 20.104.50.220:17276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/ff.php"] [unique_id "apPlIJwMiz5K1he2FnkbmAAAAaU"]
[Sun Aug 30 03:09:04.753394 2026] [authz_core:error] [pid 509172:tid 509382] [client 216.73.216.128:26821] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:04.753680 2026] [authz_core:error] [pid 509172:tid 509382] [client 216.73.216.128:26821] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:04.769235 2026] [security2:error] [pid 510357:tid 510556] [client 20.151.200.44:46049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/xda.php"] [unique_id "apPlIH5YTqJxoOZUSXtHRwAABfg"]
[Sun Aug 30 03:09:04.795335 2026] [security2:error] [pid 510357:tid 510588] [client 20.104.49.130:52433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/worksec.php"] [unique_id "apPlIH5YTqJxoOZUSXtHTgAABhg"]
[Sun Aug 30 03:09:04.811574 2026] [security2:error] [pid 509172:tid 509380] [client 20.151.200.44:57802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/wp-ver.php"] [unique_id "apPlIJwMiz5K1he2FnkbxAAAAds"]
[Sun Aug 30 03:09:04.825604 2026] [security2:error] [pid 509915:tid 510105] [client 20.220.204.93:52311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/zu.php"] [unique_id "apPlIM2gn1q0xw8Wp-TnrwAABW0"]
[Sun Aug 30 03:09:04.833823 2026] [security2:error] [pid 509172:tid 509333] [client 20.48.160.90:45861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/Q3.php"] [unique_id "apPlIJwMiz5K1he2Fnkb1wAAAaw"]
[Sun Aug 30 03:09:04.844898 2026] [security2:error] [pid 509915:tid 510167] [client 216.73.216.128:15962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mysqlupgrade"] [unique_id "apPlIM2gn1q0xw8Wp-TnvQAABas"]
[Sun Aug 30 03:09:04.866901 2026] [authz_core:error] [pid 509915:tid 510082] [client 66.249.66.200:64460] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:04.867397 2026] [authz_core:error] [pid 509915:tid 510082] [client 66.249.66.200:64460] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:04.868457 2026] [security2:error] [pid 509915:tid 510079] [client 20.104.18.15:43277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/btyuio.php"] [unique_id "apPlIM2gn1q0xw8Wp-TnxQAABVM"]
[Sun Aug 30 03:09:04.872970 2026] [security2:error] [pid 510357:tid 510501] [client 20.104.50.220:52823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/zer0.php"] [unique_id "apPlIH5YTqJxoOZUSXtHWAAABcE"]
[Sun Aug 30 03:09:04.895621 2026] [security2:error] [pid 509172:tid 509404] [client 20.104.18.15:23319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/sss.php"] [unique_id "apPlIJwMiz5K1he2FnkcAwAAAfM"]
[Sun Aug 30 03:09:04.906143 2026] [security2:error] [pid 509172:tid 509403] [client 20.104.50.220:28695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/thr.php"] [unique_id "apPlIJwMiz5K1he2FnkcDAAAAfI"]
[Sun Aug 30 03:09:04.940901 2026] [security2:error] [pid 509172:tid 509400] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/newsletter/.env"] [unique_id "apPlIJwMiz5K1he2FnkcJwAAAe8"]
[Sun Aug 30 03:09:04.954680 2026] [security2:error] [pid 509172:tid 509388] [client 20.220.204.93:52232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/lanka.php"] [unique_id "apPlIJwMiz5K1he2FnkcNAAAAeM"]
[Sun Aug 30 03:09:04.975416 2026] [security2:error] [pid 509172:tid 509355] [client 20.48.160.90:26734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/Q1.php"] [unique_id "apPlIJwMiz5K1he2FnkcRQAAAcI"]
[Sun Aug 30 03:09:04.979611 2026] [security2:error] [pid 509172:tid 509402] [client 20.48.251.3:55750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/wpver.php"] [unique_id "apPlIJwMiz5K1he2FnkcRwAAAfE"]
[Sun Aug 30 03:09:04.994504 2026] [authz_core:error] [pid 509915:tid 510086] [client 66.249.66.71:54692] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:04.994796 2026] [authz_core:error] [pid 509915:tid 510086] [client 66.249.66.71:54692] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:05.005457 2026] [security2:error] [pid 509915:tid 510115] [client 20.104.50.220:31920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/lock360.php"] [unique_id "apPlIc2gn1q0xw8Wp-ToGQAABXc"]
[Sun Aug 30 03:09:05.022750 2026] [security2:error] [pid 509915:tid 510087] [client 20.104.50.220:61972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/0x0.php"] [unique_id "apPlIc2gn1q0xw8Wp-ToIwAABVs"]
[Sun Aug 30 03:09:05.050342 2026] [authz_core:error] [pid 509172:tid 509353] [client 66.249.66.197:46264] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:05.050797 2026] [authz_core:error] [pid 509172:tid 509353] [client 66.249.66.197:46264] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:05.056406 2026] [security2:error] [pid 509915:tid 510105] [client 20.48.251.3:13395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/admin-ajax.php"] [unique_id "apPlIc2gn1q0xw8Wp-ToNgAABW0"]
[Sun Aug 30 03:09:05.061254 2026] [security2:error] [pid 509172:tid 509358] [client 20.151.200.44:45992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/wp-admin/js/index.php"] [unique_id "apPlIZwMiz5K1he2FnkcfgAAAcU"]
[Sun Aug 30 03:09:05.084080 2026] [authz_core:error] [pid 509172:tid 509331] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:05.084447 2026] [authz_core:error] [pid 509172:tid 509331] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:05.098990 2026] [authz_core:error] [pid 510357:tid 510600] [client 66.249.66.76:46422] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:05.099369 2026] [authz_core:error] [pid 510357:tid 510600] [client 66.249.66.76:46422] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:05.101184 2026] [security2:error] [pid 509915:tid 510166] [client 158.158.54.35:23031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/error.php"] [unique_id "apPlIc2gn1q0xw8Wp-ToWAAABao"]
[Sun Aug 30 03:09:05.112291 2026] [security2:error] [pid 509915:tid 510138] [client 20.48.160.90:40048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/nz.php"] [unique_id "apPlIc2gn1q0xw8Wp-ToXwAABY4"]
[Sun Aug 30 03:09:05.135452 2026] [security2:error] [pid 509915:tid 510145] [client 20.220.204.93:59135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/gettest.php"] [unique_id "apPlIc2gn1q0xw8Wp-ToagAABZU"]
[Sun Aug 30 03:09:05.193627 2026] [security2:error] [pid 509915:tid 510087] [client 20.104.50.220:33315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/pas.php"] [unique_id "apPlIc2gn1q0xw8Wp-TokgAABVs"]
[Sun Aug 30 03:09:05.194697 2026] [security2:error] [pid 509172:tid 509319] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/ses/.env"] [unique_id "apPlIZwMiz5K1he2FnkczwAAAZ4"]
[Sun Aug 30 03:09:05.218087 2026] [authz_core:error] [pid 509172:tid 509335] [client 216.73.216.128:43770] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:05.218555 2026] [authz_core:error] [pid 509172:tid 509335] [client 216.73.216.128:43770] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:05.250695 2026] [security2:error] [pid 509915:tid 510052] [client 20.151.200.44:45963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/t00l.php"] [unique_id "apPlIc2gn1q0xw8Wp-TorAAABTg"]
[Sun Aug 30 03:09:05.252236 2026] [security2:error] [pid 510357:tid 510503] [client 20.48.160.90:45834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/sg.php"] [unique_id "apPlIX5YTqJxoOZUSXtHmgAABcM"]
[Sun Aug 30 03:09:05.256869 2026] [security2:error] [pid 509915:tid 510085] [client 74.248.24.12:6908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/hello.php"] [unique_id "apPlIc2gn1q0xw8Wp-TotAAABVk"]
[Sun Aug 30 03:09:05.266509 2026] [authz_core:error] [pid 509172:tid 509383] [client 66.249.66.36:36477] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:05.266632 2026] [security2:error] [pid 509915:tid 510119] [client 20.220.204.93:59053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/35.php"] [unique_id "apPlIc2gn1q0xw8Wp-TovQAABXs"]
[Sun Aug 30 03:09:05.267046 2026] [authz_core:error] [pid 509172:tid 509383] [client 66.249.66.36:36477] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:05.353876 2026] [security2:error] [pid 509915:tid 510076] [client 4.205.62.107:35978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/myfile.php"] [unique_id "apPlIc2gn1q0xw8Wp-TpBQAABVA"]
[Sun Aug 30 03:09:05.367680 2026] [authz_core:error] [pid 510357:tid 510572] [client 66.249.66.41:52266] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:05.367965 2026] [authz_core:error] [pid 510357:tid 510572] [client 66.249.66.41:52266] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:05.370240 2026] [security2:error] [pid 509172:tid 509357] [client 4.205.62.107:17146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/oiko6u.php"] [unique_id "apPlIZwMiz5K1he2FnkdNgAAAcQ"]
[Sun Aug 30 03:09:05.378048 2026] [authz_core:error] [pid 509172:tid 509380] [client 66.249.66.33:59092] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:05.378381 2026] [authz_core:error] [pid 509172:tid 509380] [client 66.249.66.33:59092] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:05.398406 2026] [authz_core:error] [pid 509172:tid 509414] [client 216.73.216.128:28951] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:05.398813 2026] [authz_core:error] [pid 509172:tid 509414] [client 216.73.216.128:28951] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:05.408995 2026] [security2:error] [pid 510357:tid 510507] [client 20.48.160.90:45855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/hypo.php"] [unique_id "apPlIX5YTqJxoOZUSXtHtgAABcc"]
[Sun Aug 30 03:09:05.411094 2026] [security2:error] [pid 509172:tid 509315] [client 20.220.204.93:59061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/maraz.php"] [unique_id "apPlIZwMiz5K1he2FnkdTAAAAZo"]
[Sun Aug 30 03:09:05.434232 2026] [security2:error] [pid 509172:tid 509316] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/sendgrid/.env"] [unique_id "apPlIZwMiz5K1he2FnkdXQAAAZs"]
[Sun Aug 30 03:09:05.497396 2026] [security2:error] [pid 510357:tid 510525] [client 4.205.62.107:64461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/66.php"] [unique_id "apPlIX5YTqJxoOZUSXtH0gAABdk"]
[Sun Aug 30 03:09:05.513236 2026] [security2:error] [pid 509915:tid 510120] [client 68.155.159.216:55146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apPlIc2gn1q0xw8Wp-TpbgAABXw"]
[Sun Aug 30 03:09:05.522739 2026] [security2:error] [pid 509915:tid 510012] [remote 68.155.159.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ibrgroup.in"] [uri "/.well-known/index.php"] [unique_id "apPlIc2gn1q0xw8Wp-TpeQAFh18"]
[Sun Aug 30 03:09:05.541597 2026] [authz_core:error] [pid 509915:tid 510169] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:05.541933 2026] [authz_core:error] [pid 509915:tid 510169] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:05.542512 2026] [security2:error] [pid 509915:tid 510156] [client 20.220.204.93:59131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/kbfr.php"] [unique_id "apPlIc2gn1q0xw8Wp-TpjAAABaA"]
[Sun Aug 30 03:09:05.551838 2026] [core:alert] [pid 509915:tid 510102] [client 141.98.11.224:0] /home3/fremant1/thedevonshireteaguide.com.au/.htaccess: without matching section, referer: http://thedevonshireteaguide.com.au/
[Sun Aug 30 03:09:05.564498 2026] [security2:error] [pid 509915:tid 510129] [client 20.48.160.90:45921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/Hd.php"] [unique_id "apPlIc2gn1q0xw8Wp-TpmgAABYU"]
[Sun Aug 30 03:09:05.567441 2026] [security2:error] [pid 510357:tid 510562] [client 158.158.54.35:21197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/raf.php"] [unique_id "apPlIX5YTqJxoOZUSXtH5gAABf4"]
[Sun Aug 30 03:09:05.568535 2026] [security2:error] [pid 509915:tid 510123] [client 20.104.18.15:35176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/nofile.php"] [unique_id "apPlIc2gn1q0xw8Wp-TpngAABX8"]
[Sun Aug 30 03:09:05.569561 2026] [security2:error] [pid 510357:tid 510609] [client 20.104.49.130:52333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/browse.php"] [unique_id "apPlIX5YTqJxoOZUSXtH5wAABi0"]
[Sun Aug 30 03:09:05.572865 2026] [security2:error] [pid 509172:tid 509332] [client 216.73.216.128:28951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPlIZwMiz5K1he2FnkdvAAAAas"]
[Sun Aug 30 03:09:05.573901 2026] [security2:error] [pid 509172:tid 509394] [client 20.104.50.220:47073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/aves.php"] [unique_id "apPlIZwMiz5K1he2FnkdvQAAAek"]
[Sun Aug 30 03:09:05.601065 2026] [authz_core:error] [pid 509172:tid 509366] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:05.601355 2026] [authz_core:error] [pid 509172:tid 509366] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:05.619059 2026] [security2:error] [pid 509915:tid 510166] [client 20.104.18.15:34722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/tnglzqmv.php"] [unique_id "apPlIc2gn1q0xw8Wp-TpsQAABao"]
[Sun Aug 30 03:09:05.619906 2026] [security2:error] [pid 509172:tid 509371] [client 20.104.18.15:1970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/dk.php"] [unique_id "apPlIZwMiz5K1he2Fnkd1wAAAdI"]
[Sun Aug 30 03:09:05.648379 2026] [security2:error] [pid 509172:tid 509349] [client 20.48.251.3:59841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/thui.php"] [unique_id "apPlIZwMiz5K1he2Fnkd6QAAAbw"]
[Sun Aug 30 03:09:05.670799 2026] [security2:error] [pid 509172:tid 509394] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/sparkpost/.env"] [unique_id "apPlIZwMiz5K1he2Fnkd-gAAAek"]
[Sun Aug 30 03:09:05.671407 2026] [authz_core:error] [pid 509172:tid 509381] [client 216.73.216.128:43770] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:05.671682 2026] [authz_core:error] [pid 509172:tid 509381] [client 216.73.216.128:43770] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:05.681995 2026] [security2:error] [pid 509172:tid 509387] [client 20.220.204.93:59127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/wp-act.php"] [unique_id "apPlIZwMiz5K1he2FnkeBQAAAeI"]
[Sun Aug 30 03:09:05.684631 2026] [security2:error] [pid 509172:tid 509335] [client 20.104.49.130:57637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/browse.php"] [unique_id "apPlIZwMiz5K1he2FnkeBwAAAa4"]
[Sun Aug 30 03:09:05.713764 2026] [security2:error] [pid 509915:tid 510099] [client 20.48.160.90:45853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/im.php"] [unique_id "apPlIc2gn1q0xw8Wp-Tp0gAABWc"]
[Sun Aug 30 03:09:05.720605 2026] [security2:error] [pid 509915:tid 510172] [client 68.155.159.216:53463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/log-mama/function.php"] [unique_id "apPlIc2gn1q0xw8Wp-Tp1gAABbA"]
[Sun Aug 30 03:09:05.725526 2026] [security2:error] [pid 509172:tid 509428] [client 20.104.50.220:5621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/jembut.php"] [unique_id "apPlIZwMiz5K1he2FnkeJgAAAgs"]
[Sun Aug 30 03:09:05.742485 2026] [security2:error] [pid 509172:tid 509421] [client 20.104.50.220:51617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/kntol.php"] [unique_id "apPlIZwMiz5K1he2FnkeNQAAAgQ"]
[Sun Aug 30 03:09:05.755868 2026] [security2:error] [pid 509915:tid 510097] [client 20.151.200.44:46070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/ls.php"] [unique_id "apPlIc2gn1q0xw8Wp-Tp6QAABWU"]
[Sun Aug 30 03:09:05.758464 2026] [security2:error] [pid 509915:tid 510057] [client 68.155.159.216:46012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/admin.php"] [unique_id "apPlIc2gn1q0xw8Wp-Tp6wAABT0"]
[Sun Aug 30 03:09:05.775751 2026] [security2:error] [pid 509172:tid 509423] [client 74.248.24.12:7604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/IDhrIlrLb.php"] [unique_id "apPlIZwMiz5K1he2FnkeSwAAAgY"]
[Sun Aug 30 03:09:05.796971 2026] [security2:error] [pid 509915:tid 510173] [client 20.151.8.82:16726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlIc2gn1q0xw8Wp-TqCgAABbE"]
[Sun Aug 30 03:09:05.797443 2026] [security2:error] [pid 509172:tid 509348] [client 20.104.18.15:18419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/dapa.php"] [unique_id "apPlIZwMiz5K1he2FnkeXAAAAbs"]
[Sun Aug 30 03:09:05.814359 2026] [authz_core:error] [pid 509172:tid 509312] [client 66.249.66.41:57554] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:05.814627 2026] [authz_core:error] [pid 509172:tid 509312] [client 66.249.66.41:57554] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:05.817194 2026] [security2:error] [pid 509172:tid 509415] [client 20.220.204.93:59081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/24.php"] [unique_id "apPlIZwMiz5K1he2FnkeagAAAf4"]
[Sun Aug 30 03:09:05.843291 2026] [security2:error] [pid 509172:tid 509407] [client 20.48.160.90:40049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/fc.php"] [unique_id "apPlIZwMiz5K1he2FnkegAAAAfY"]
[Sun Aug 30 03:09:05.873687 2026] [security2:error] [pid 509172:tid 509376] [client 20.104.50.220:16685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/file31.php"] [unique_id "apPlIZwMiz5K1he2FnkemAAAAdc"]
[Sun Aug 30 03:09:05.912618 2026] [security2:error] [pid 509172:tid 509345] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/postmark/.env"] [unique_id "apPlIZwMiz5K1he2FnkeuQAAAbg"]
[Sun Aug 30 03:09:05.926706 2026] [security2:error] [pid 509915:tid 510059] [client 20.151.8.82:16736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlIc2gn1q0xw8Wp-TqRQAABT8"]
[Sun Aug 30 03:09:05.938520 2026] [security2:error] [pid 509172:tid 509331] [client 216.73.216.128:43770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlIZwMiz5K1he2FnkezwAAAao"]
[Sun Aug 30 03:09:05.972528 2026] [security2:error] [pid 509172:tid 509425] [client 20.220.204.93:59043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/155.php"] [unique_id "apPlIZwMiz5K1he2Fnke6wAAAgg"]
[Sun Aug 30 03:09:05.975507 2026] [security2:error] [pid 509172:tid 509399] [client 20.48.160.90:45824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/ke.php"] [unique_id "apPlIZwMiz5K1he2Fnke7gAAAe4"]
[Sun Aug 30 03:09:06.010287 2026] [security2:error] [pid 509915:tid 510130] [client 158.158.54.35:23037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/about.php525"] [unique_id "apPlIs2gn1q0xw8Wp-TqhAAABYY"]
[Sun Aug 30 03:09:06.013549 2026] [security2:error] [pid 509915:tid 510100] [client 20.104.18.15:43270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/dehnl.php"] [unique_id "apPlIs2gn1q0xw8Wp-TqiwAABWg"]
[Sun Aug 30 03:09:06.016904 2026] [security2:error] [pid 509915:tid 510088] [client 20.104.50.220:62816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/63dor.php"] [unique_id "apPlIs2gn1q0xw8Wp-TqjAAABVw"]
[Sun Aug 30 03:09:06.043560 2026] [security2:error] [pid 509172:tid 509394] [client 20.104.50.220:52833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/tmv.php"] [unique_id "apPlIpwMiz5K1he2FnkfKwAAAek"]
[Sun Aug 30 03:09:06.061142 2026] [security2:error] [pid 509172:tid 509354] [client 20.151.8.82:16650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/nail.php"] [unique_id "apPlIpwMiz5K1he2FnkfPAAAAcE"]
[Sun Aug 30 03:09:06.082379 2026] [authz_core:error] [pid 509915:tid 510058] [client 66.249.66.32:63348] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:06.082839 2026] [authz_core:error] [pid 509915:tid 510058] [client 66.249.66.32:63348] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:06.085613 2026] [authz_core:error] [pid 509172:tid 509310] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:06.086042 2026] [authz_core:error] [pid 509172:tid 509310] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:06.104482 2026] [security2:error] [pid 509172:tid 509420] [client 4.205.62.107:25869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/xza.php"] [unique_id "apPlIpwMiz5K1he2FnkfYQAAAgM"]
[Sun Aug 30 03:09:06.108133 2026] [security2:error] [pid 509915:tid 510098] [client 20.220.204.93:52309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/file.php"] [unique_id "apPlIs2gn1q0xw8Wp-TquAAABWY"]
[Sun Aug 30 03:09:06.118210 2026] [security2:error] [pid 509915:tid 510120] [client 20.48.251.3:59331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/ah25.php"] [unique_id "apPlIs2gn1q0xw8Wp-TqvAAABXw"]
[Sun Aug 30 03:09:06.119921 2026] [security2:error] [pid 509172:tid 509305] [client 20.48.160.90:40032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/tf.php"] [unique_id "apPlIpwMiz5K1he2FnkfbAAAAZA"]
[Sun Aug 30 03:09:06.145748 2026] [security2:error] [pid 509172:tid 509381] [client 20.104.49.130:63519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/one.php"] [unique_id "apPlIpwMiz5K1he2FnkffAAAAdw"]
[Sun Aug 30 03:09:06.152313 2026] [security2:error] [pid 509172:tid 509429] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/mailgun/.env"] [unique_id "apPlIpwMiz5K1he2FnkfggAAAgw"]
[Sun Aug 30 03:09:06.157805 2026] [security2:error] [pid 509172:tid 509355] [client 94.154.43.122:50820] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-bc2bae47.khj.vju.temporary.site"] [uri "/.env"] [unique_id "apPlIpwMiz5K1he2FnkfhQAAAcI"]
[Sun Aug 30 03:09:06.159850 2026] [security2:error] [pid 509172:tid 509385] [client 94.154.43.180:19984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-492e4e63.khj.vju.temporary.site"] [uri "/.env"] [unique_id "apPlIpwMiz5K1he2FnkfiQAAAeA"]
[Sun Aug 30 03:09:06.186580 2026] [security2:error] [pid 509172:tid 509317] [client 20.104.50.220:61960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/0z.php"] [unique_id "apPlIpwMiz5K1he2FnkflwAAAZw"]
[Sun Aug 30 03:09:06.189171 2026] [security2:error] [pid 509172:tid 509382] [client 20.151.8.82:16651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/or.php"] [unique_id "apPlIpwMiz5K1he2FnkfmgAAAd0"]
[Sun Aug 30 03:09:06.197630 2026] [security2:error] [pid 509172:tid 509378] [client 20.48.251.3:13412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/ms.php"] [unique_id "apPlIpwMiz5K1he2FnkfogAAAdk"]
[Sun Aug 30 03:09:06.208859 2026] [authz_core:error] [pid 509915:tid 510083] [client 66.249.66.73:45966] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:06.209144 2026] [authz_core:error] [pid 509915:tid 510083] [client 66.249.66.73:45966] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:06.241238 2026] [security2:error] [pid 509915:tid 510135] [client 20.151.200.44:55738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPlIs2gn1q0xw8Wp-Tq8gAABYs"]
[Sun Aug 30 03:09:06.255399 2026] [security2:error] [pid 509172:tid 509357] [client 20.104.50.220:32543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/pp.php"] [unique_id "apPlIpwMiz5K1he2FnkfywAAAcQ"]
[Sun Aug 30 03:09:06.269493 2026] [security2:error] [pid 509915:tid 510097] [client 20.220.204.93:59010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPlIs2gn1q0xw8Wp-Tq-AAABWU"]
[Sun Aug 30 03:09:06.280475 2026] [security2:error] [pid 509172:tid 509420] [client 20.151.200.44:46026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/css/000.php"] [unique_id "apPlIpwMiz5K1he2Fnkf4wAAAgM"]
[Sun Aug 30 03:09:06.290924 2026] [security2:error] [pid 509915:tid 510112] [client 74.248.24.12:12738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/fi2.php"] [unique_id "apPlIs2gn1q0xw8Wp-TrBQAABXQ"]
[Sun Aug 30 03:09:06.297450 2026] [security2:error] [pid 509172:tid 509356] [client 20.48.160.90:45824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/px.php"] [unique_id "apPlIpwMiz5K1he2Fnkf9QAAAcM"]
[Sun Aug 30 03:09:06.323933 2026] [security2:error] [pid 510357:tid 510533] [client 20.151.8.82:16641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/verox.php"] [unique_id "apPlIn5YTqJxoOZUSXtIVwAABeE"]
[Sun Aug 30 03:09:06.334661 2026] [security2:error] [pid 509172:tid 509318] [client 20.104.50.220:33153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/abc.php"] [unique_id "apPlIpwMiz5K1he2FnkgGgAAAZ0"]
[Sun Aug 30 03:09:06.339991 2026] [security2:error] [pid 509915:tid 510064] [client 20.104.18.15:23464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/wp-includes/ID3/moon.php"] [unique_id "apPlIs2gn1q0xw8Wp-TrIAAABUQ"]
[Sun Aug 30 03:09:06.403791 2026] [security2:error] [pid 509915:tid 510095] [client 20.220.204.93:52290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/06.php"] [unique_id "apPlIs2gn1q0xw8Wp-TrNAAABWM"]
[Sun Aug 30 03:09:06.412627 2026] [security2:error] [pid 509172:tid 509343] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/mandrill/.env"] [unique_id "apPlIpwMiz5K1he2FnkgSQAAAbY"]
[Sun Aug 30 03:09:06.437479 2026] [security2:error] [pid 509172:tid 509420] [client 20.48.160.90:26705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/jg.php"] [unique_id "apPlIpwMiz5K1he2FnkgXgAAAgM"]
[Sun Aug 30 03:09:06.459457 2026] [security2:error] [pid 509915:tid 510150] [client 158.158.54.35:28079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/embed.php"] [unique_id "apPlIs2gn1q0xw8Wp-TrUQAABZo"]
[Sun Aug 30 03:09:06.463224 2026] [security2:error] [pid 509172:tid 509342] [client 20.151.8.82:16742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/ba.php"] [unique_id "apPlIpwMiz5K1he2FnkgdQAAAbU"]
[Sun Aug 30 03:09:06.503298 2026] [security2:error] [pid 509172:tid 509320] [client 4.205.62.107:17121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/fraro.php"] [unique_id "apPlIpwMiz5K1he2FnkgmwAAAZ8"]
[Sun Aug 30 03:09:06.542108 2026] [authz_core:error] [pid 509172:tid 509403] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:06.542384 2026] [authz_core:error] [pid 509172:tid 509403] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:06.555955 2026] [security2:error] [pid 509915:tid 510100] [client 20.104.49.130:60958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/browse.php"] [unique_id "apPlIs2gn1q0xw8Wp-TrlwAABWg"]
[Sun Aug 30 03:09:06.568414 2026] [security2:error] [pid 509915:tid 510155] [client 20.48.160.90:26710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/yj.php"] [unique_id "apPlIs2gn1q0xw8Wp-TrnQAABZ8"]
[Sun Aug 30 03:09:06.572866 2026] [security2:error] [pid 509172:tid 509312] [client 20.220.204.93:52296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/class.php"] [unique_id "apPlIpwMiz5K1he2Fnkg0wAAAZc"]
[Sun Aug 30 03:09:06.596687 2026] [security2:error] [pid 509172:tid 509314] [client 20.151.8.82:16668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/G.php"] [unique_id "apPlIpwMiz5K1he2Fnkg5wAAAZk"]
[Sun Aug 30 03:09:06.631517 2026] [security2:error] [pid 509172:tid 509369] [client 68.155.159.216:55082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apPlIpwMiz5K1he2Fnkg-QAAAdA"]
[Sun Aug 30 03:09:06.635235 2026] [security2:error] [pid 509915:tid 510118] [client 4.205.62.107:58486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/admin.php"] [unique_id "apPlIs2gn1q0xw8Wp-TrugAABXo"]
[Sun Aug 30 03:09:06.651439 2026] [security2:error] [pid 509172:tid 509414] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/mailjet/.env"] [unique_id "apPlIpwMiz5K1he2FnkhBQAAAf0"]
[Sun Aug 30 03:09:06.657372 2026] [authz_core:error] [pid 509172:tid 509341] [client 66.249.66.39:63194] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:06.657857 2026] [authz_core:error] [pid 509172:tid 509341] [client 66.249.66.39:63194] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:06.668427 2026] [security2:error] [pid 510357:tid 510614] [client 20.104.49.130:60643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/3.php"] [unique_id "apPlIn5YTqJxoOZUSXtIlgAABjI"]
[Sun Aug 30 03:09:06.704796 2026] [security2:error] [pid 509915:tid 510070] [client 20.48.160.90:45854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/zi.php"] [unique_id "apPlIs2gn1q0xw8Wp-Tr2gAABUo"]
[Sun Aug 30 03:09:06.715667 2026] [security2:error] [pid 509915:tid 510155] [client 20.104.18.15:35174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/run.php"] [unique_id "apPlIs2gn1q0xw8Wp-Tr4wAABZ8"]
[Sun Aug 30 03:09:06.727170 2026] [security2:error] [pid 509915:tid 510158] [client 20.104.50.220:46201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPlIs2gn1q0xw8Wp-Tr7gAABaI"]
[Sun Aug 30 03:09:06.729414 2026] [security2:error] [pid 509915:tid 510173] [client 20.151.8.82:16740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/great.php"] [unique_id "apPlIs2gn1q0xw8Wp-Tr8AAABbE"]
[Sun Aug 30 03:09:06.778987 2026] [security2:error] [pid 510357:tid 510577] [client 20.104.18.15:34663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/wefile.php"] [unique_id "apPlIn5YTqJxoOZUSXtIugAABg0"]
[Sun Aug 30 03:09:06.779893 2026] [security2:error] [pid 510357:tid 510561] [client 20.104.18.15:2011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apPlIn5YTqJxoOZUSXtIuwAABf0"]
[Sun Aug 30 03:09:06.780454 2026] [security2:error] [pid 510357:tid 510565] [client 20.220.204.93:52257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/8.php"] [unique_id "apPlIn5YTqJxoOZUSXtIvAAABgE"]
[Sun Aug 30 03:09:06.811894 2026] [security2:error] [pid 509915:tid 510089] [client 20.48.251.3:59866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/lala.php"] [unique_id "apPlIs2gn1q0xw8Wp-TsNQAABV0"]
[Sun Aug 30 03:09:06.812139 2026] [security2:error] [pid 509172:tid 509420] [client 74.248.24.12:15284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/admin.php1"] [unique_id "apPlIpwMiz5K1he2FnkhXQAAAgM"]
[Sun Aug 30 03:09:06.815706 2026] [security2:error] [pid 509915:tid 510157] [client 4.205.62.107:36618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/lm15.php"] [unique_id "apPlIs2gn1q0xw8Wp-TsOgAABaE"]
[Sun Aug 30 03:09:06.842783 2026] [security2:error] [pid 509172:tid 509399] [client 20.48.160.90:26690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/ue.php"] [unique_id "apPlIpwMiz5K1he2FnkhcAAAAe4"]
[Sun Aug 30 03:09:06.862009 2026] [security2:error] [pid 509172:tid 509428] [client 20.151.8.82:16724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "apPlIpwMiz5K1he2FnkhfgAAAgs"]
[Sun Aug 30 03:09:06.871178 2026] [security2:error] [pid 510357:tid 510525] [client 20.104.50.220:6103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/class.php"] [unique_id "apPlIn5YTqJxoOZUSXtI0AAABdk"]
[Sun Aug 30 03:09:06.873244 2026] [authz_core:error] [pid 509172:tid 509311] [client 216.73.216.128:26821] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:06.873693 2026] [authz_core:error] [pid 509172:tid 509311] [client 216.73.216.128:26821] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:06.893495 2026] [security2:error] [pid 510357:tid 510559] [client 68.155.159.216:64854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/bk/index.php"] [unique_id "apPlIn5YTqJxoOZUSXtI2wAABfs"]
[Sun Aug 30 03:09:06.897179 2026] [security2:error] [pid 509172:tid 509328] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/brevo/.env"] [unique_id "apPlIpwMiz5K1he2FnkhmwAAAac"]
[Sun Aug 30 03:09:06.911450 2026] [security2:error] [pid 510357:tid 510512] [client 20.104.50.220:51573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/WSO.php"] [unique_id "apPlIn5YTqJxoOZUSXtI3gAABcw"]
[Sun Aug 30 03:09:06.933847 2026] [security2:error] [pid 509915:tid 510058] [client 158.158.54.35:22983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/essexec.php"] [unique_id "apPlIs2gn1q0xw8Wp-TshwAABT4"]
[Sun Aug 30 03:09:06.954895 2026] [security2:error] [pid 509915:tid 510165] [client 20.220.204.93:59115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/0x0x.php"] [unique_id "apPlIs2gn1q0xw8Wp-TslgAABak"]
[Sun Aug 30 03:09:06.959243 2026] [security2:error] [pid 509172:tid 509420] [client 20.104.18.15:18287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/wp-content/l.php"] [unique_id "apPlIpwMiz5K1he2FnkhzwAAAgM"]
[Sun Aug 30 03:09:06.971146 2026] [authz_core:error] [pid 509915:tid 510084] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:06.971615 2026] [authz_core:error] [pid 509915:tid 510084] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:06.980529 2026] [security2:error] [pid 509915:tid 510128] [client 20.48.160.90:26726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/nv.php"] [unique_id "apPlIs2gn1q0xw8Wp-TspAAABYQ"]
[Sun Aug 30 03:09:06.994988 2026] [security2:error] [pid 509172:tid 509425] [client 20.151.8.82:16646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/robots.php"] [unique_id "apPlIpwMiz5K1he2Fnkh7wAAAgg"]
[Sun Aug 30 03:09:07.000871 2026] [security2:error] [pid 509915:tid 510143] [client 20.104.49.130:64003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/reviall.php"] [unique_id "apPlI82gn1q0xw8Wp-TsuAAABZM"]
[Sun Aug 30 03:09:07.006524 2026] [security2:error] [pid 509915:tid 510079] [client 20.104.50.220:16759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/file6.php"] [unique_id "apPlI82gn1q0xw8Wp-TsvQAABVM"]
[Sun Aug 30 03:09:07.045769 2026] [authz_core:error] [pid 509915:tid 510106] [client 66.249.66.74:42884] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:07.046035 2026] [authz_core:error] [pid 509915:tid 510106] [client 66.249.66.74:42884] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:07.052477 2026] [security2:error] [pid 509172:tid 509377] [client 20.151.200.44:46040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/cy.php"] [unique_id "apPlI5wMiz5K1he2FnkiIQAAAdg"]
[Sun Aug 30 03:09:07.094449 2026] [security2:error] [pid 509915:tid 510133] [client 20.220.204.93:59109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/166.php"] [unique_id "apPlI82gn1q0xw8Wp-Ts9QAABYk"]
[Sun Aug 30 03:09:07.095384 2026] [authz_core:error] [pid 509172:tid 509367] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:07.095716 2026] [authz_core:error] [pid 509172:tid 509367] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:07.116584 2026] [security2:error] [pid 509915:tid 510085] [client 20.48.160.90:26741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/jw.php"] [unique_id "apPlI82gn1q0xw8Wp-TtBgAABVk"]
[Sun Aug 30 03:09:07.132573 2026] [security2:error] [pid 509915:tid 510101] [client 20.151.8.82:16729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/sky.php"] [unique_id "apPlI82gn1q0xw8Wp-TtFQAABWk"]
[Sun Aug 30 03:09:07.140417 2026] [security2:error] [pid 509172:tid 509392] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/transactional/.env"] [unique_id "apPlI5wMiz5K1he2FnkiRgAAAec"]
[Sun Aug 30 03:09:07.144128 2026] [security2:error] [pid 509172:tid 509394] [client 195.178.110.247:2996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mediacoalition.org"] [uri "/index.php"] [unique_id "apPlI5wMiz5K1he2FnkiSgAAAek"]
[Sun Aug 30 03:09:07.159698 2026] [security2:error] [pid 509172:tid 509322] [client 20.104.18.15:44025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/zoo2.php"] [unique_id "apPlI5wMiz5K1he2FnkiUwAAAaE"]
[Sun Aug 30 03:09:07.171419 2026] [security2:error] [pid 509172:tid 509351] [client 20.104.50.220:29139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/dh.php"] [unique_id "apPlI5wMiz5K1he2FnkiWwAAAb4"]
[Sun Aug 30 03:09:07.189897 2026] [authz_core:error] [pid 509915:tid 510157] [client 66.249.66.39:49851] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:07.190190 2026] [authz_core:error] [pid 509915:tid 510157] [client 66.249.66.39:49851] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:07.197936 2026] [security2:error] [pid 509915:tid 510110] [client 20.104.50.220:28692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/terminal.php"] [unique_id "apPlI82gn1q0xw8Wp-TtNgAABXI"]
[Sun Aug 30 03:09:07.224292 2026] [security2:error] [pid 510357:tid 510540] [client 20.220.204.93:59087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/h2a2ck.php"] [unique_id "apPlI35YTqJxoOZUSXtJDwAABeg"]
[Sun Aug 30 03:09:07.255928 2026] [security2:error] [pid 509915:tid 510171] [client 20.48.251.3:59270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/groceries/index.php"] [unique_id "apPlI82gn1q0xw8Wp-TtXwAABa8"]
[Sun Aug 30 03:09:07.260955 2026] [security2:error] [pid 510357:tid 510534] [client 20.151.8.82:16676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/sixxis.php"] [unique_id "apPlI35YTqJxoOZUSXtJFwAABeI"]
[Sun Aug 30 03:09:07.265373 2026] [security2:error] [pid 509915:tid 510122] [client 20.151.200.44:57805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/ah24.php"] [unique_id "apPlI82gn1q0xw8Wp-TtagAABX4"]
[Sun Aug 30 03:09:07.281070 2026] [security2:error] [pid 510357:tid 510593] [client 4.205.62.107:25888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/ms-edit.php"] [unique_id "apPlI35YTqJxoOZUSXtJGQAABh0"]
[Sun Aug 30 03:09:07.283391 2026] [security2:error] [pid 509172:tid 509415] [client 20.48.160.90:45884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/or.php"] [unique_id "apPlI5wMiz5K1he2FnkilQAAAf4"]
[Sun Aug 30 03:09:07.308492 2026] [security2:error] [pid 509172:tid 509418] [client 195.178.110.247:46188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mediacoalition.org"] [uri "/index.php"] [unique_id "apPlI5wMiz5K1he2FnkiqwAAAgE"]
[Sun Aug 30 03:09:07.328092 2026] [security2:error] [pid 509172:tid 509370] [client 74.248.24.12:6873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/hyIPpxWDQ.php"] [unique_id "apPlI5wMiz5K1he2FnkitQAAAdE"]
[Sun Aug 30 03:09:07.334877 2026] [security2:error] [pid 509172:tid 509325] [client 20.104.50.220:62225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/13.php"] [unique_id "apPlI5wMiz5K1he2FnkitwAAAaQ"]
[Sun Aug 30 03:09:07.337016 2026] [security2:error] [pid 509172:tid 509406] [client 20.48.251.3:13401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/fucku.php"] [unique_id "apPlI5wMiz5K1he2FnkiuQAAAfU"]
[Sun Aug 30 03:09:07.358373 2026] [security2:error] [pid 509915:tid 510049] [client 20.220.204.93:59031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/error_log.php"] [unique_id "apPlI82gn1q0xw8Wp-TtsgAABTU"]
[Sun Aug 30 03:09:07.370115 2026] [security2:error] [pid 509915:tid 510121] [client 20.151.200.44:45957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/admin.php/pindex.php"] [unique_id "apPlI82gn1q0xw8Wp-TtuAAABX0"]
[Sun Aug 30 03:09:07.380302 2026] [security2:error] [pid 509172:tid 509404] [client 158.158.54.35:28057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/gecko-new.php.1"] [unique_id "apPlI5wMiz5K1he2FnkizQAAAfM"]
[Sun Aug 30 03:09:07.387359 2026] [security2:error] [pid 509172:tid 509308] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/bulk/.env"] [unique_id "apPlI5wMiz5K1he2Fnki0AAAAZM"]
[Sun Aug 30 03:09:07.409309 2026] [security2:error] [pid 509915:tid 510077] [client 20.151.8.82:16671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/yj09.php"] [unique_id "apPlI82gn1q0xw8Wp-TtzAAABVE"]
[Sun Aug 30 03:09:07.418886 2026] [security2:error] [pid 509915:tid 510076] [client 216.73.216.128:31159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/about:blank"] [unique_id "apPlI82gn1q0xw8Wp-Tt0QAABVA"]
[Sun Aug 30 03:09:07.424293 2026] [security2:error] [pid 509172:tid 509379] [client 20.48.160.90:23243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/ile56.php"] [unique_id "apPlI5wMiz5K1he2Fnki9QAAAdo"]
[Sun Aug 30 03:09:07.427145 2026] [security2:error] [pid 509172:tid 509306] [client 20.104.50.220:32285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/geck.php"] [unique_id "apPlI5wMiz5K1he2Fnki9wAAAZE"]
[Sun Aug 30 03:09:07.472237 2026] [security2:error] [pid 509915:tid 510049] [client 20.104.50.220:33179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/indexx.php"] [unique_id "apPlI82gn1q0xw8Wp-Tt6wAABTU"]
[Sun Aug 30 03:09:07.491354 2026] [security2:error] [pid 510357:tid 510563] [client 20.220.204.93:52317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/403.php"] [unique_id "apPlI35YTqJxoOZUSXtJRwAABf8"]
[Sun Aug 30 03:09:07.495257 2026] [security2:error] [pid 509172:tid 509372] [client 20.104.18.15:23382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/xmini4.php"] [unique_id "apPlI5wMiz5K1he2FnkjNgAAAdM"]
[Sun Aug 30 03:09:07.518287 2026] [authz_core:error] [pid 509172:tid 509378] [client 216.73.216.128:31080] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:07.518736 2026] [authz_core:error] [pid 509172:tid 509378] [client 216.73.216.128:31080] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:07.545203 2026] [security2:error] [pid 509915:tid 510098] [client 20.151.8.82:16715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/k.php"] [unique_id "apPlI82gn1q0xw8Wp-TuFAAABWY"]
[Sun Aug 30 03:09:07.563000 2026] [authz_core:error] [pid 509172:tid 509317] [client 66.249.66.197:48467] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:07.563358 2026] [security2:error] [pid 509172:tid 509425] [client 20.48.160.90:45936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/emmh.php"] [unique_id "apPlI5wMiz5K1he2FnkjeAAAAgg"]
[Sun Aug 30 03:09:07.563450 2026] [authz_core:error] [pid 509172:tid 509317] [client 66.249.66.197:48467] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:07.585466 2026] [authz_core:error] [pid 509172:tid 509315] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:07.585928 2026] [authz_core:error] [pid 509172:tid 509315] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:07.628794 2026] [security2:error] [pid 509172:tid 509420] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/aws/.env"] [unique_id "apPlI5wMiz5K1he2FnkjnwAAAgM"]
[Sun Aug 30 03:09:07.635315 2026] [security2:error] [pid 509172:tid 509354] [client 20.220.204.93:59019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/cytyr.php"] [unique_id "apPlI5wMiz5K1he2FnkjpAAAAcE"]
[Sun Aug 30 03:09:07.639352 2026] [security2:error] [pid 509172:tid 509340] [client 4.205.62.107:17320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/thui.php"] [unique_id "apPlI5wMiz5K1he2FnkjpQAAAbM"]
[Sun Aug 30 03:09:07.674229 2026] [security2:error] [pid 509915:tid 510141] [client 20.151.8.82:16642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/w.php"] [unique_id "apPlI82gn1q0xw8Wp-TuPAAABZE"]
[Sun Aug 30 03:09:07.695946 2026] [security2:error] [pid 509172:tid 509305] [client 20.48.160.90:45880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/em.php"] [unique_id "apPlI5wMiz5K1he2Fnkj0wAAAZA"]
[Sun Aug 30 03:09:07.777038 2026] [security2:error] [pid 510357:tid 510609] [client 4.205.62.107:64469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/png.php"] [unique_id "apPlI35YTqJxoOZUSXtJcQAABi0"]
[Sun Aug 30 03:09:07.780607 2026] [security2:error] [pid 510357:tid 510578] [client 68.155.159.216:55078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apPlI35YTqJxoOZUSXtJcgAABg4"]
[Sun Aug 30 03:09:07.803658 2026] [security2:error] [pid 509915:tid 510119] [client 20.151.8.82:16665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/FWAZ.php"] [unique_id "apPlI82gn1q0xw8Wp-TukgAABXs"]
[Sun Aug 30 03:09:07.826567 2026] [security2:error] [pid 509915:tid 510164] [client 158.158.54.35:35213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/disagraeed.php"] [unique_id "apPlI82gn1q0xw8Wp-TumQAABag"]
[Sun Aug 30 03:09:07.827196 2026] [security2:error] [pid 509172:tid 509395] [client 20.48.160.90:26744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/dvve.php"] [unique_id "apPlI5wMiz5K1he2FnkkRQAAAeo"]
[Sun Aug 30 03:09:07.830139 2026] [security2:error] [pid 510357:tid 510491] [client 20.220.204.93:59130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/galer.php"] [unique_id "apPlI35YTqJxoOZUSXtJggAABbc"]
[Sun Aug 30 03:09:07.854582 2026] [security2:error] [pid 509172:tid 509314] [client 20.104.18.15:35181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/new.php"] [unique_id "apPlI5wMiz5K1he2FnkkVwAAAZk"]
[Sun Aug 30 03:09:07.864489 2026] [security2:error] [pid 509172:tid 509328] [client 20.104.50.220:46448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/gorila.php"] [unique_id "apPlI5wMiz5K1he2FnkkXgAAAac"]
[Sun Aug 30 03:09:07.878466 2026] [security2:error] [pid 509172:tid 509386] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/azure/.env"] [unique_id "apPlI5wMiz5K1he2FnkkZwAAAeE"]
[Sun Aug 30 03:09:07.912369 2026] [security2:error] [pid 509915:tid 510129] [client 20.104.18.15:34684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/blog.php"] [unique_id "apPlI82gn1q0xw8Wp-TuwAAABYU"]
[Sun Aug 30 03:09:07.933461 2026] [security2:error] [pid 509172:tid 509304] [client 20.104.18.15:2028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/xc.php"] [unique_id "apPlI5wMiz5K1he2FnkklAAAAY8"]
[Sun Aug 30 03:09:07.934802 2026] [security2:error] [pid 510357:tid 510573] [client 20.151.8.82:16666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/blurbs.php"] [unique_id "apPlI35YTqJxoOZUSXtJjAAABgk"]
[Sun Aug 30 03:09:07.940573 2026] [security2:error] [pid 509915:tid 510168] [client 74.248.24.12:7653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/BIBIL_0DAY.php/global.php"] [unique_id "apPlI82gn1q0xw8Wp-Tu0gAABaw"]
[Sun Aug 30 03:09:07.953072 2026] [security2:error] [pid 509172:tid 509311] [client 20.48.251.3:59512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/public/bnn_.php.php"] [unique_id "apPlI5wMiz5K1he2FnkkpwAAAZY"]
[Sun Aug 30 03:09:07.961263 2026] [security2:error] [pid 509915:tid 510093] [client 20.48.160.90:39937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/doo.php"] [unique_id "apPlI82gn1q0xw8Wp-Tu6AAABWE"]
[Sun Aug 30 03:09:07.974416 2026] [security2:error] [pid 509172:tid 509410] [client 20.220.204.93:59064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/baixy.php"] [unique_id "apPlI5wMiz5K1he2FnkkuQAAAfk"]
[Sun Aug 30 03:09:08.031317 2026] [security2:error] [pid 509915:tid 510172] [client 20.104.50.220:5938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/seo.php"] [unique_id "apPlJM2gn1q0xw8Wp-TvIgAABbA"]
[Sun Aug 30 03:09:08.033389 2026] [authz_core:error] [pid 509172:tid 509414] [client 66.249.66.74:38395] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:08.033794 2026] [authz_core:error] [pid 509172:tid 509414] [client 66.249.66.74:38395] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:08.062284 2026] [security2:error] [pid 509172:tid 509326] [client 20.151.8.82:16708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/100.php"] [unique_id "apPlJJwMiz5K1he2FnklBgAAAaU"]
[Sun Aug 30 03:09:08.069700 2026] [security2:error] [pid 509915:tid 510064] [client 20.104.50.220:51612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/IndoXploit.php"] [unique_id "apPlJM2gn1q0xw8Wp-TvLgAABUQ"]
[Sun Aug 30 03:09:08.076498 2026] [authz_core:error] [pid 509172:tid 509404] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:08.076572 2026] [security2:error] [pid 509915:tid 510027] [remote 68.155.159.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ibrgroup.in"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPlJM2gn1q0xw8Wp-TvNgAFlG4"]
[Sun Aug 30 03:09:08.076908 2026] [authz_core:error] [pid 509172:tid 509404] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:08.089960 2026] [security2:error] [pid 509915:tid 510099] [client 20.104.18.15:18323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/wp-admin/w.php"] [unique_id "apPlJM2gn1q0xw8Wp-TvQQAABWc"]
[Sun Aug 30 03:09:08.114389 2026] [security2:error] [pid 510357:tid 510614] [client 20.48.160.90:40005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/adminer-4.6.6.php"] [unique_id "apPlJH5YTqJxoOZUSXtJqgAABjI"]
[Sun Aug 30 03:09:08.116145 2026] [security2:error] [pid 509915:tid 510155] [client 20.220.204.93:59022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/ava.php"] [unique_id "apPlJM2gn1q0xw8Wp-TvVgAABZ8"]
[Sun Aug 30 03:09:08.126561 2026] [security2:error] [pid 509172:tid 509363] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/gcp/.env"] [unique_id "apPlJJwMiz5K1he2FnklNAAAAco"]
[Sun Aug 30 03:09:08.146283 2026] [security2:error] [pid 509172:tid 509326] [client 20.104.50.220:17271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/a2.php"] [unique_id "apPlJJwMiz5K1he2FnklQQAAAaU"]
[Sun Aug 30 03:09:08.180393 2026] [security2:error] [pid 509172:tid 509374] [client 68.155.159.216:53464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.rtsicomply.com"] [uri "/first.php"] [unique_id "apPlJJwMiz5K1he2FnklVwAAAdU"]
[Sun Aug 30 03:09:08.201467 2026] [security2:error] [pid 509915:tid 510111] [client 20.151.8.82:16752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/ccc.php"] [unique_id "apPlJM2gn1q0xw8Wp-TviAAABXM"]
[Sun Aug 30 03:09:08.246612 2026] [security2:error] [pid 509915:tid 510158] [client 20.48.160.90:39990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/gelap1.php"] [unique_id "apPlJM2gn1q0xw8Wp-TvoQAABaI"]
[Sun Aug 30 03:09:08.249796 2026] [security2:error] [pid 509915:tid 510056] [client 20.220.204.93:59134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/gdn.php"] [unique_id "apPlJM2gn1q0xw8Wp-TvpAAABTw"]
[Sun Aug 30 03:09:08.255338 2026] [security2:error] [pid 509915:tid 510059] [client 118.27.125.83:41510] ModSecurity: Warning. Matched phrase "LWP::Simple" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "bcwinetrends.com"] [uri "/2017/07/03/rose-gold-at-the-acwc/"] [unique_id "apPlJM2gn1q0xw8Wp-TvgQAABT8"]
[Sun Aug 30 03:09:08.295699 2026] [security2:error] [pid 509172:tid 509353] [client 158.158.54.35:7410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/class-IXR-encryption.php"] [unique_id "apPlJJwMiz5K1he2FnklmQAAAcA"]
[Sun Aug 30 03:09:08.310060 2026] [security2:error] [pid 509172:tid 509362] [client 20.104.50.220:28673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/%E5%B9%B3%E4%BB%AE%E5%90%8Ds.php"] [unique_id "apPlJJwMiz5K1he2FnklpwAAAck"]
[Sun Aug 30 03:09:08.319348 2026] [security2:error] [pid 509915:tid 510119] [client 20.104.49.130:53696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/yawa.php"] [unique_id "apPlJM2gn1q0xw8Wp-Tv4gAABXs"]
[Sun Aug 30 03:09:08.319679 2026] [security2:error] [pid 509915:tid 510116] [client 20.104.18.15:44021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/zoo1.php"] [unique_id "apPlJM2gn1q0xw8Wp-Tv4wAABXg"]
[Sun Aug 30 03:09:08.340016 2026] [security2:error] [pid 509915:tid 510165] [client 20.151.8.82:16655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/images.php"] [unique_id "apPlJM2gn1q0xw8Wp-Tv7wAABak"]
[Sun Aug 30 03:09:08.341931 2026] [security2:error] [pid 509915:tid 510147] [client 20.104.50.220:28725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/titid.php"] [unique_id "apPlJM2gn1q0xw8Wp-Tv8AAABZc"]
[Sun Aug 30 03:09:08.355556 2026] [security2:error] [pid 509915:tid 510115] [client 20.151.200.44:45932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/admin.php/csv.php"] [unique_id "apPlJM2gn1q0xw8Wp-Tv-AAABXc"]
[Sun Aug 30 03:09:08.389391 2026] [security2:error] [pid 509172:tid 509354] [client 20.220.204.93:52249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/f2.php"] [unique_id "apPlJJwMiz5K1he2Fnkl2AAAAcE"]
[Sun Aug 30 03:09:08.391844 2026] [security2:error] [pid 509172:tid 509403] [client 20.48.160.90:26737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/rsjlrria.php"] [unique_id "apPlJJwMiz5K1he2Fnkl3AAAAfI"]
[Sun Aug 30 03:09:08.393552 2026] [security2:error] [pid 509172:tid 509375] [client 20.48.251.3:59273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/konfig.php"] [unique_id "apPlJJwMiz5K1he2Fnkl3gAAAdY"]
[Sun Aug 30 03:09:08.409049 2026] [security2:error] [pid 509172:tid 509420] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/cloud/.env"] [unique_id "apPlJJwMiz5K1he2Fnkl5wAAAgM"]
[Sun Aug 30 03:09:08.420445 2026] [authz_core:error] [pid 509915:tid 510051] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:08.420907 2026] [authz_core:error] [pid 509915:tid 510051] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:08.424855 2026] [security2:error] [pid 509915:tid 510028] [remote 51.81.111.9:42994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/robots.txt"] [unique_id "apPlJM2gn1q0xw8Wp-TwGQAFXG8"]
[Sun Aug 30 03:09:08.425028 2026] [security2:error] [pid 509915:tid 510088] [client 51.81.111.9:42994] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/robots.txt"] [unique_id "apPlJM2gn1q0xw8Wp-TwGQAFXG8"]
[Sun Aug 30 03:09:08.438888 2026] [security2:error] [pid 509172:tid 509408] [client 20.104.49.130:48035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/df.php"] [unique_id "apPlJJwMiz5K1he2Fnkl_QAAAfc"]
[Sun Aug 30 03:09:08.460660 2026] [authz_core:error] [pid 509172:tid 509315] [client 66.249.66.69:51925] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:08.460935 2026] [authz_core:error] [pid 509172:tid 509315] [client 66.249.66.69:51925] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:08.471194 2026] [security2:error] [pid 509915:tid 510163] [client 20.48.251.3:33343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/error_log.php"] [unique_id "apPlJM2gn1q0xw8Wp-TwMgAABac"]
[Sun Aug 30 03:09:08.475701 2026] [security2:error] [pid 509915:tid 510106] [client 20.151.8.82:16765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/alls.php"] [unique_id "apPlJM2gn1q0xw8Wp-TwOAAABW4"]
[Sun Aug 30 03:09:08.487366 2026] [security2:error] [pid 510357:tid 510542] [client 74.248.24.12:12217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/fxcexgle.php"] [unique_id "apPlJH5YTqJxoOZUSXtKAAAABeo"]
[Sun Aug 30 03:09:08.507229 2026] [security2:error] [pid 509172:tid 509377] [client 4.205.62.107:25915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/lmfi2.php"] [unique_id "apPlJJwMiz5K1he2FnkmMgAAAdg"]
[Sun Aug 30 03:09:08.524458 2026] [security2:error] [pid 509915:tid 510084] [client 20.104.50.220:61437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/1index.php"] [unique_id "apPlJM2gn1q0xw8Wp-TwXwAABVg"]
[Sun Aug 30 03:09:08.526101 2026] [security2:error] [pid 509915:tid 510083] [client 20.48.160.90:26707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/AxAo.php"] [unique_id "apPlJM2gn1q0xw8Wp-TwYwAABVc"]
[Sun Aug 30 03:09:08.548841 2026] [security2:error] [pid 509915:tid 510112] [client 20.220.204.93:52226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/grsiuk.php"] [unique_id "apPlJM2gn1q0xw8Wp-TwdwAABXQ"]
[Sun Aug 30 03:09:08.566871 2026] [authz_core:error] [pid 509172:tid 509372] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:08.567305 2026] [authz_core:error] [pid 509172:tid 509372] [client 74.7.243.204:56700] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:08.597124 2026] [security2:error] [pid 509915:tid 510070] [client 20.104.50.220:31897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/gm.php"] [unique_id "apPlJM2gn1q0xw8Wp-TwmQAABUo"]
[Sun Aug 30 03:09:08.605502 2026] [security2:error] [pid 509172:tid 509399] [client 20.104.50.220:32860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/browse.php"] [unique_id "apPlJJwMiz5K1he2FnkmYAAAAe4"]
[Sun Aug 30 03:09:08.623235 2026] [security2:error] [pid 509915:tid 510113] [client 20.151.8.82:16707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/coffexium.php"] [unique_id "apPlJM2gn1q0xw8Wp-TwqQAABXU"]
[Sun Aug 30 03:09:08.655877 2026] [security2:error] [pid 509172:tid 509419] [client 34.100.204.203:34792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/infrastructure/.env"] [unique_id "apPlJJwMiz5K1he2FnkmfgAAAgI"]
[Sun Aug 30 03:09:08.659148 2026] [security2:error] [pid 510357:tid 510614] [client 20.48.160.90:45850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/class17.php"] [unique_id "apPlJH5YTqJxoOZUSXtKKAAABjI"]
[Sun Aug 30 03:09:08.659939 2026] [security2:error] [pid 509915:tid 510048] [client 4.205.62.107:36716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/test.config.php"] [unique_id "apPlJM2gn1q0xw8Wp-TwtAAABTQ"]
[Sun Aug 30 03:09:08.663430 2026] [security2:error] [pid 509172:tid 509387] [client 20.104.18.15:23372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/gulu.php"] [unique_id "apPlJJwMiz5K1he2FnkmhgAAAeI"]
[Sun Aug 30 03:09:08.669362 2026] [security2:error] [pid 509172:tid 509314] [client 20.104.50.220:63212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlJJwMiz5K1he2FnkmigAAAZk"]
[Sun Aug 30 03:09:08.679948 2026] [security2:error] [pid 509915:tid 510138] [client 20.220.204.93:52233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/wp-scr1pts.php"] [unique_id "apPlJM2gn1q0xw8Wp-TwvQAABY4"]
[Sun Aug 30 03:09:08.691666 2026] [autoindex:error] [pid 509172:tid 509340] [client 34.237.50.25:21187] AH01276: Cannot serve directory /home1/lehugh/public_html/torrance/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:09:08.751110 2026] [authz_core:error] [pid 509915:tid 510046] [client 66.249.66.69:57984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:08.751583 2026] [authz_core:error] [pid 509915:tid 510046] [client 66.249.66.69:57984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:08.763886 2026] [security2:error] [pid 510357:tid 510584] [client 20.151.8.82:16644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/red.php"] [unique_id "apPlJH5YTqJxoOZUSXtKRgAABhQ"]
[Sun Aug 30 03:09:08.785914 2026] [security2:error] [pid 509172:tid 509388] [client 20.48.160.90:45903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/okxoby.php"] [unique_id "apPlJJwMiz5K1he2FnkmwwAAAeM"]
[Sun Aug 30 03:09:08.790678 2026] [security2:error] [pid 509915:tid 510107] [client 4.205.62.107:17142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/lala.php"] [unique_id "apPlJM2gn1q0xw8Wp-TxGgAABW8"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:08.830718 2026] [security2:error] [pid 509915:tid 510139] [client 20.220.204.93:59045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/num.php"] [unique_id "apPlJM2gn1q0xw8Wp-TxNgAABY8"]
[Sun Aug 30 03:09:08.847883 2026] [security2:error] [pid 509915:tid 510149] [client 158.158.54.35:6645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/cache-base.php"] [unique_id "apPlJM2gn1q0xw8Wp-TxPQAABZk"]
[Sun Aug 30 03:09:08.898655 2026] [security2:error] [pid 509915:tid 510085] [client 20.151.8.82:16754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/admin.php"] [unique_id "apPlJM2gn1q0xw8Wp-TxUwAABVk"]
[Sun Aug 30 03:09:08.911430 2026] [security2:error] [pid 510357:tid 510542] [client 68.155.159.216:55087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/packed.php"] [unique_id "apPlJH5YTqJxoOZUSXtKdAAABeo"]
[Sun Aug 30 03:09:08.911709 2026] [security2:error] [pid 510357:tid 510530] [client 4.205.62.107:61798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/chosen.php"] [unique_id "apPlJH5YTqJxoOZUSXtKdQAABd4"]
[Sun Aug 30 03:09:08.914680 2026] [security2:error] [pid 509915:tid 510155] [client 20.48.160.90:26714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/esuutzzx.php"] [unique_id "apPlJM2gn1q0xw8Wp-TxXAAABZ8"]
[Sun Aug 30 03:09:09.000010 2026] [security2:error] [pid 510357:tid 510594] [client 74.248.24.12:6883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/NFXxUAA.php"] [unique_id "apPlJH5YTqJxoOZUSXtKhAAABh4"]
[Sun Aug 30 03:09:09.003345 2026] [security2:error] [pid 509915:tid 510168] [client 20.104.50.220:47076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/vanta.php"] [unique_id "apPlJc2gn1q0xw8Wp-TxlQAABaw"]
[Sun Aug 30 03:09:09.004119 2026] [security2:error] [pid 509915:tid 510068] [client 20.220.204.93:59064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/a4.php"] [unique_id "apPlJc2gn1q0xw8Wp-TxlgAABUg"]
[Sun Aug 30 03:09:09.007671 2026] [security2:error] [pid 509915:tid 510132] [client 20.104.18.15:35459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/inx.php"] [unique_id "apPlJc2gn1q0xw8Wp-TxmQAABYg"]
[Sun Aug 30 03:09:09.023231 2026] [security2:error] [pid 509915:tid 510157] [client 20.104.49.130:63500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/sym.php"] [unique_id "apPlJc2gn1q0xw8Wp-TxogAABaE"]
[Sun Aug 30 03:09:09.028275 2026] [security2:error] [pid 509915:tid 510171] [client 20.151.8.82:16599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/file52.php"] [unique_id "apPlJc2gn1q0xw8Wp-TxpgAABa8"]
[Sun Aug 30 03:09:09.048957 2026] [security2:error] [pid 509915:tid 510099] [client 20.48.160.90:45919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/replace.php"] [unique_id "apPlJc2gn1q0xw8Wp-TxswAABWc"]
[Sun Aug 30 03:09:09.052787 2026] [security2:error] [pid 509915:tid 510072] [client 20.104.18.15:34808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/wp-admin/js/wp-load.php"] [unique_id "apPlJc2gn1q0xw8Wp-TxtQAABUw"]
[Sun Aug 30 03:09:09.069804 2026] [security2:error] [pid 510357:tid 510508] [client 20.104.18.15:2034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/wp-content/l.php"] [unique_id "apPlJX5YTqJxoOZUSXtKkAAABcg"]
[Sun Aug 30 03:09:09.094794 2026] [authz_core:error] [pid 509915:tid 510080] [client 74.7.243.204:54682] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:09.095440 2026] [authz_core:error] [pid 509915:tid 510080] [client 74.7.243.204:54682] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:09.101681 2026] [authz_core:error] [pid 509915:tid 510121] [client 66.249.66.68:45190] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:09.102105 2026] [authz_core:error] [pid 509915:tid 510121] [client 66.249.66.68:45190] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:09.150182 2026] [security2:error] [pid 509915:tid 510079] [client 20.48.251.3:59861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wsws.php"] [unique_id "apPlJc2gn1q0xw8Wp-Tx5QAABVM"]
[Sun Aug 30 03:09:09.154710 2026] [security2:error] [pid 509915:tid 510137] [client 20.151.8.82:16744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/geck.php"] [unique_id "apPlJc2gn1q0xw8Wp-Tx6QAABY0"]
[Sun Aug 30 03:09:09.159102 2026] [security2:error] [pid 509915:tid 510160] [client 20.220.204.93:59030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/tfm.php"] [unique_id "apPlJc2gn1q0xw8Wp-Tx7AAABaQ"]
[Sun Aug 30 03:09:09.172717 2026] [security2:error] [pid 509915:tid 510093] [client 20.104.50.220:5945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/cannonical.php"] [unique_id "apPlJc2gn1q0xw8Wp-Tx9wAABWE"]
[Sun Aug 30 03:09:09.178093 2026] [security2:error] [pid 510357:tid 510524] [client 20.48.160.90:39988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/gulu.php"] [unique_id "apPlJX5YTqJxoOZUSXtKpgAABdg"]
[Sun Aug 30 03:09:09.217183 2026] [security2:error] [pid 509915:tid 510136] [client 20.104.50.220:51561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/bajingan.php"] [unique_id "apPlJc2gn1q0xw8Wp-TyDgAABYw"]
[Sun Aug 30 03:09:09.227851 2026] [security2:error] [pid 509915:tid 510096] [client 20.104.18.15:18282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/wp-content/k.php"] [unique_id "apPlJc2gn1q0xw8Wp-TyEwAABWQ"]
[Sun Aug 30 03:09:09.228941 2026] [security2:error] [pid 509915:tid 510153] [client 216.73.216.128:41659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlJc2gn1q0xw8Wp-TyFAAABZ0"]
[Sun Aug 30 03:09:09.281995 2026] [security2:error] [pid 510357:tid 510527] [client 20.104.50.220:17218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/file15.php"] [unique_id "apPlJX5YTqJxoOZUSXtKrgAABds"]
[Sun Aug 30 03:09:09.287579 2026] [security2:error] [pid 510357:tid 510609] [client 20.151.8.82:16696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/biufile.php"] [unique_id "apPlJX5YTqJxoOZUSXtKsQAABi0"]
[Sun Aug 30 03:09:09.318823 2026] [security2:error] [pid 509915:tid 510096] [client 20.48.160.90:39968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/gtghklk.php"] [unique_id "apPlJc2gn1q0xw8Wp-TyUgAABWQ"]
[Sun Aug 30 03:09:09.343627 2026] [security2:error] [pid 510357:tid 510514] [client 20.220.204.93:52307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/Geforce.php"] [unique_id "apPlJX5YTqJxoOZUSXtKtwAABc4"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:09.359500 2026] [security2:error] [pid 509915:tid 510082] [client 158.158.54.35:27206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/Js.php"] [unique_id "apPlJc2gn1q0xw8Wp-TyZAAABVY"]
[Sun Aug 30 03:09:09.390247 2026] [security2:error] [pid 510357:tid 510387] [remote 97.74.87.194:35642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/wp-login.php"] [unique_id "apPlJX5YTqJxoOZUSXtKuwAGABk"]
[Sun Aug 30 03:09:09.399306 2026] [authz_core:error] [pid 510357:tid 510541] [client 66.249.66.201:39085] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:09.399796 2026] [authz_core:error] [pid 510357:tid 510541] [client 66.249.66.201:39085] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:09.425378 2026] [security2:error] [pid 510357:tid 510529] [client 20.151.8.82:16645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/dejavu.php"] [unique_id "apPlJX5YTqJxoOZUSXtKwQAABd0"]
[Sun Aug 30 03:09:09.447589 2026] [security2:error] [pid 509915:tid 510144] [client 20.48.160.90:39955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/comand.php"] [unique_id "apPlJc2gn1q0xw8Wp-TyjAAABZQ"]
[Sun Aug 30 03:09:09.449190 2026] [security2:error] [pid 509915:tid 510135] [client 20.104.49.130:60744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/002.php"] [unique_id "apPlJc2gn1q0xw8Wp-TyjQAABYs"]
[Sun Aug 30 03:09:09.453593 2026] [security2:error] [pid 509915:tid 510118] [client 216.73.216.128:58719] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/ourcollection_images/wp-admin/css/install.css"] [unique_id "apPlJc2gn1q0xw8Wp-TykAAABXo"]
[Sun Aug 30 03:09:09.466686 2026] [security2:error] [pid 509915:tid 510062] [client 20.104.18.15:43318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/radio.php"] [unique_id "apPlJc2gn1q0xw8Wp-TynAAABUI"]
[Sun Aug 30 03:09:09.469108 2026] [security2:error] [pid 509915:tid 510107] [client 20.104.50.220:52857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-includes/rest-api/fields/anbu.php"] [unique_id "apPlJc2gn1q0xw8Wp-TyngAABW8"]
[Sun Aug 30 03:09:09.499814 2026] [security2:error] [pid 509915:tid 510071] [client 20.220.204.93:59124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/click.php"] [unique_id "apPlJc2gn1q0xw8Wp-TytwAABUs"]
[Sun Aug 30 03:09:09.503697 2026] [security2:error] [pid 509915:tid 510097] [client 20.104.50.220:29159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/sllolx.php"] [unique_id "apPlJc2gn1q0xw8Wp-TyvgAABWU"]
[Sun Aug 30 03:09:09.504743 2026] [security2:error] [pid 510357:tid 510518] [client 74.248.24.12:2992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/blog.php7"] [unique_id "apPlJX5YTqJxoOZUSXtKzQAABdI"]
[Sun Aug 30 03:09:09.533221 2026] [security2:error] [pid 509915:tid 510068] [client 20.48.251.3:59292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/paths.php"] [unique_id "apPlJc2gn1q0xw8Wp-TyzQAABUg"]
[Sun Aug 30 03:09:09.548976 2026] [security2:error] [pid 509915:tid 510151] [client 20.151.200.44:45965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/admin.php/700.php"] [unique_id "apPlJc2gn1q0xw8Wp-Ty3AAABZs"]
[Sun Aug 30 03:09:09.550999 2026] [authz_core:error] [pid 509915:tid 510073] [client 216.73.216.128:58719] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:09.551476 2026] [authz_core:error] [pid 509915:tid 510073] [client 216.73.216.128:58719] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:09.552232 2026] [security2:error] [pid 509915:tid 510148] [client 20.151.8.82:16712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/aaf.php"] [unique_id "apPlJc2gn1q0xw8Wp-Ty3wAABZg"]
[Sun Aug 30 03:09:09.555430 2026] [security2:error] [pid 509915:tid 510070] [client 34.100.204.203:60656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/k8s/.env"] [unique_id "apPlJc2gn1q0xw8Wp-Ty4AAABUo"]
[Sun Aug 30 03:09:09.591006 2026] [security2:error] [pid 509915:tid 510140] [client 20.48.160.90:45856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp_motu_myk3v.php"] [unique_id "apPlJc2gn1q0xw8Wp-Ty8QAABZA"]
[Sun Aug 30 03:09:09.604134 2026] [authz_core:error] [pid 509915:tid 510136] [client 74.7.243.204:54682] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:09.604425 2026] [authz_core:error] [pid 509915:tid 510136] [client 74.7.243.204:54682] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:09.610558 2026] [security2:error] [pid 509915:tid 510072] [client 20.48.251.3:13414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/phina.php"] [unique_id "apPlJc2gn1q0xw8Wp-Ty_QAABUw"]
[Sun Aug 30 03:09:09.667864 2026] [security2:error] [pid 509915:tid 510165] [client 20.104.49.130:52510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/002.php"] [unique_id "apPlJc2gn1q0xw8Wp-TzFgAABak"]
[Sun Aug 30 03:09:09.675484 2026] [security2:error] [pid 509915:tid 510141] [client 20.104.50.220:61981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/22xc.php"] [unique_id "apPlJc2gn1q0xw8Wp-TzGwAABZE"]
[Sun Aug 30 03:09:09.682722 2026] [security2:error] [pid 510357:tid 510543] [client 20.220.204.93:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/ms.php"] [unique_id "apPlJX5YTqJxoOZUSXtK4AAABes"]
[Sun Aug 30 03:09:09.684409 2026] [security2:error] [pid 509915:tid 510122] [client 20.151.8.82:16660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/h02ugyh.php"] [unique_id "apPlJc2gn1q0xw8Wp-TzIgAABX4"]
[Sun Aug 30 03:09:09.720720 2026] [security2:error] [pid 510357:tid 510608] [client 20.48.160.90:39998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/wp_motu_ypdat.php"] [unique_id "apPlJX5YTqJxoOZUSXtK7gAABiw"]
[Sun Aug 30 03:09:09.747704 2026] [security2:error] [pid 509915:tid 510077] [client 20.104.50.220:31822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/file4.php"] [unique_id "apPlJc2gn1q0xw8Wp-TzSgAABVE"]
[Sun Aug 30 03:09:09.749120 2026] [security2:error] [pid 509915:tid 510116] [client 20.104.50.220:32873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/up1.php"] [unique_id "apPlJc2gn1q0xw8Wp-TzSwAABXg"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:09.809107 2026] [security2:error] [pid 509915:tid 510148] [client 20.104.50.220:59381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlJc2gn1q0xw8Wp-TzdwAABZg"]
[Sun Aug 30 03:09:09.817178 2026] [security2:error] [pid 510357:tid 510388] [remote 97.74.87.194:35642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/wp-login.php"] [unique_id "apPlJX5YTqJxoOZUSXtLBwAF4Ro"], referer: https://bridgesofcourage.mtrphotography.net/wp-login.php
[Sun Aug 30 03:09:09.819180 2026] [authz_core:error] [pid 509915:tid 510112] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:09.819563 2026] [authz_core:error] [pid 509915:tid 510112] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:09.819984 2026] [security2:error] [pid 510357:tid 510552] [client 20.151.8.82:16716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/155.php"] [unique_id "apPlJX5YTqJxoOZUSXtLCAAABfQ"]
[Sun Aug 30 03:09:09.830636 2026] [security2:error] [pid 509915:tid 510137] [client 34.100.204.203:60656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/kubernetes/.env"] [unique_id "apPlJc2gn1q0xw8Wp-TzggAABY0"]
[Sun Aug 30 03:09:09.832973 2026] [security2:error] [pid 509915:tid 510059] [client 158.158.54.35:21194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/about.php7"] [unique_id "apPlJc2gn1q0xw8Wp-TzhgAABT8"]
[Sun Aug 30 03:09:09.835487 2026] [security2:error] [pid 509915:tid 510042] [remote 51.81.111.78:16068] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/"] [unique_id "apPlJc2gn1q0xw8Wp-TziQAFO30"]
[Sun Aug 30 03:09:09.835992 2026] [security2:error] [pid 509915:tid 510055] [client 51.81.111.78:16068] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.xn--c3cxftacreiie2czb1bm9b6bo6fvgna5b6ireh.com"] [uri "/"] [unique_id "apPlJc2gn1q0xw8Wp-TziQAFO30"]
[Sun Aug 30 03:09:09.846197 2026] [security2:error] [pid 509915:tid 510086] [client 20.220.204.93:59091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/zxekqlxb.php"] [unique_id "apPlJc2gn1q0xw8Wp-TzjgAABVo"]
[Sun Aug 30 03:09:09.850516 2026] [security2:error] [pid 509915:tid 510078] [client 20.48.160.90:26721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/edit.php"] [unique_id "apPlJc2gn1q0xw8Wp-TzkAAABVI"]
[Sun Aug 30 03:09:09.870191 2026] [security2:error] [pid 509915:tid 510067] [client 20.104.18.15:23308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/replace.php"] [unique_id "apPlJc2gn1q0xw8Wp-TznQAABUc"]
[Sun Aug 30 03:09:09.909531 2026] [rewrite:warn] [pid 509915:tid 509918] AH00665: RewriteCond: NoCase option for non-regex pattern '-d' is not supported and will be ignored. (/home3/keilan/public_html/.htaccess:12)
[Sun Aug 30 03:09:09.909547 2026] [rewrite:warn] [pid 509915:tid 509918] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home3/keilan/public_html/.htaccess:13)
[Sun Aug 30 03:09:09.924905 2026] [security2:error] [pid 509915:tid 510137] [client 20.151.200.44:59544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPlJc2gn1q0xw8Wp-TzugAABY0"]
[Sun Aug 30 03:09:09.931253 2026] [security2:error] [pid 509915:tid 510129] [client 4.205.62.107:17127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/public/bnn_.php.php"] [unique_id "apPlJc2gn1q0xw8Wp-TzvAAABYU"]
[Sun Aug 30 03:09:09.959594 2026] [security2:error] [pid 510357:tid 510591] [client 20.151.8.82:16713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/ops.php"] [unique_id "apPlJX5YTqJxoOZUSXtLGwAABhs"]
[Sun Aug 30 03:09:10.001075 2026] [security2:error] [pid 509915:tid 510137] [client 20.48.160.90:45840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/tqkdqbbv.php"] [unique_id "apPlJs2gn1q0xw8Wp-Tz8AAABY0"]
[Sun Aug 30 03:09:10.032089 2026] [security2:error] [pid 509915:tid 510065] [client 68.155.159.216:55045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-content/packed.php"] [unique_id "apPlJs2gn1q0xw8Wp-T0AgAABUU"]
[Sun Aug 30 03:09:10.043428 2026] [security2:error] [pid 509915:tid 510087] [client 20.220.204.93:52337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/init.php"] [unique_id "apPlJs2gn1q0xw8Wp-T0BQAABVs"]
[Sun Aug 30 03:09:10.061899 2026] [security2:error] [pid 509915:tid 510164] [client 4.205.62.107:61775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/admin-ajax.php"] [unique_id "apPlJs2gn1q0xw8Wp-T0DAAABag"]
[Sun Aug 30 03:09:10.081371 2026] [security2:error] [pid 509915:tid 510073] [client 34.100.204.203:60656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/terraform/.env"] [unique_id "apPlJs2gn1q0xw8Wp-T0FQAABU0"]
[Sun Aug 30 03:09:10.088758 2026] [security2:error] [pid 509915:tid 510142] [client 20.151.8.82:16647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/mac.php"] [unique_id "apPlJs2gn1q0xw8Wp-T0GAAABZI"]
[Sun Aug 30 03:09:10.104738 2026] [security2:error] [pid 509915:tid 510119] [client 74.248.24.12:13915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/aQzODIgoBr.php"] [unique_id "apPlJs2gn1q0xw8Wp-T0IgAABXs"]
[Sun Aug 30 03:09:10.126871 2026] [authz_core:error] [pid 509915:tid 510137] [client 74.7.243.204:54682] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:10.127312 2026] [authz_core:error] [pid 509915:tid 510137] [client 74.7.243.204:54682] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:10.132638 2026] [security2:error] [pid 510357:tid 510547] [client 20.48.160.90:39977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/kjyehoxl.php"] [unique_id "apPlJn5YTqJxoOZUSXtLOQAABe8"]
[Sun Aug 30 03:09:10.141387 2026] [security2:error] [pid 509915:tid 510126] [client 20.104.50.220:47050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/sh3ll.php"] [unique_id "apPlJs2gn1q0xw8Wp-T0OQAABYI"]
[Sun Aug 30 03:09:10.148360 2026] [security2:error] [pid 509915:tid 510057] [client 20.104.18.15:35489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/vpn.php"] [unique_id "apPlJs2gn1q0xw8Wp-T0OwAABT0"]
[Sun Aug 30 03:09:10.185948 2026] [security2:error] [pid 509915:tid 510091] [client 20.220.204.93:59133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/term.php"] [unique_id "apPlJs2gn1q0xw8Wp-T0WgAABV8"]
[Sun Aug 30 03:09:10.192513 2026] [security2:error] [pid 510357:tid 510577] [client 20.104.18.15:34784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/robot.php"] [unique_id "apPlJn5YTqJxoOZUSXtLQgAABg0"]
[Sun Aug 30 03:09:10.212625 2026] [security2:error] [pid 509915:tid 510052] [client 20.104.18.15:1937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/wp-admin/w.php"] [unique_id "apPlJs2gn1q0xw8Wp-T0ZgAABTg"]
[Sun Aug 30 03:09:10.236545 2026] [security2:error] [pid 510357:tid 510574] [client 20.151.8.82:16592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/makeasmtp.php"] [unique_id "apPlJn5YTqJxoOZUSXtLSwAABgo"]
[Sun Aug 30 03:09:10.272848 2026] [security2:error] [pid 509915:tid 510118] [client 216.73.216.128:58719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts2/updateconf"] [unique_id "apPlJs2gn1q0xw8Wp-T0ggAABXo"]
[Sun Aug 30 03:09:10.277059 2026] [security2:error] [pid 509915:tid 510132] [client 20.48.160.90:40033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/llyuxaqd.php"] [unique_id "apPlJs2gn1q0xw8Wp-T0hgAABYg"]
[Sun Aug 30 03:09:10.292125 2026] [authz_core:error] [pid 510357:tid 510596] [client 66.249.66.33:62793] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:10.292621 2026] [authz_core:error] [pid 510357:tid 510596] [client 66.249.66.33:62793] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:10.310986 2026] [security2:error] [pid 509915:tid 510149] [client 20.104.50.220:5894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/format.php"] [unique_id "apPlJs2gn1q0xw8Wp-T0lQAABZk"]
[Sun Aug 30 03:09:10.314559 2026] [security2:error] [pid 510357:tid 510550] [client 158.158.54.35:10046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/dxc.php"] [unique_id "apPlJn5YTqJxoOZUSXtLWwAABfI"]
[Sun Aug 30 03:09:10.325927 2026] [security2:error] [pid 509915:tid 510101] [client 34.100.204.203:60656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/ansible/.env"] [unique_id "apPlJs2gn1q0xw8Wp-T0mAAABWk"]
[Sun Aug 30 03:09:10.351254 2026] [security2:error] [pid 509915:tid 510064] [client 20.48.251.3:59852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/localconf.php"] [unique_id "apPlJs2gn1q0xw8Wp-T0pgAABUQ"]
[Sun Aug 30 03:09:10.358037 2026] [security2:error] [pid 510357:tid 510532] [client 20.104.50.220:51591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/Good.php"] [unique_id "apPlJn5YTqJxoOZUSXtLYAAABeA"]
[Sun Aug 30 03:09:10.365767 2026] [security2:error] [pid 509915:tid 510148] [client 20.151.8.82:16733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/pucci.php"] [unique_id "apPlJs2gn1q0xw8Wp-T0qQAABZg"]
[Sun Aug 30 03:09:10.369186 2026] [security2:error] [pid 509915:tid 510066] [client 20.220.204.93:52334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/aaa.php"] [unique_id "apPlJs2gn1q0xw8Wp-T0rQAABUY"]
[Sun Aug 30 03:09:10.371723 2026] [security2:error] [pid 510357:tid 510524] [client 20.104.18.15:18283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/os.php"] [unique_id "apPlJn5YTqJxoOZUSXtLZAAABdg"]
[Sun Aug 30 03:09:10.417688 2026] [security2:error] [pid 509915:tid 510071] [client 20.104.50.220:16735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/no1.php"] [unique_id "apPlJs2gn1q0xw8Wp-T0wwAABUs"]
[Sun Aug 30 03:09:10.427271 2026] [security2:error] [pid 509915:tid 510113] [client 20.48.160.90:45833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/nbwxolou.php"] [unique_id "apPlJs2gn1q0xw8Wp-T0yQAABXU"]
[Sun Aug 30 03:09:10.497208 2026] [security2:error] [pid 509915:tid 510143] [client 20.151.8.82:16731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/puc.php"] [unique_id "apPlJs2gn1q0xw8Wp-T08wAABZM"]
[Sun Aug 30 03:09:10.517553 2026] [security2:error] [pid 509915:tid 510062] [client 4.205.62.107:25752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/wpver.php"] [unique_id "apPlJs2gn1q0xw8Wp-T0_QAABUI"]
[Sun Aug 30 03:09:10.522297 2026] [security2:error] [pid 509915:tid 510160] [client 20.220.204.93:52241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/lkui.php"] [unique_id "apPlJs2gn1q0xw8Wp-T0_wAABaQ"]
[Sun Aug 30 03:09:10.540185 2026] [authz_core:error] [pid 509915:tid 510053] [client 66.249.66.66:45898] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:10.540505 2026] [authz_core:error] [pid 509915:tid 510053] [client 66.249.66.66:45898] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:10.542078 2026] [security2:error] [pid 509915:tid 510168] [client 20.151.200.44:55625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.icanto.com"] [uri "/waf.php"] [unique_id "apPlJs2gn1q0xw8Wp-T1DAAABaw"]
[Sun Aug 30 03:09:10.555490 2026] [security2:error] [pid 509915:tid 510137] [client 20.48.160.90:40058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/nsxeubyv.php"] [unique_id "apPlJs2gn1q0xw8Wp-T1FQAABY0"]
[Sun Aug 30 03:09:10.578824 2026] [security2:error] [pid 509915:tid 510162] [client 34.100.204.203:60656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/.git/.env"] [unique_id "apPlJs2gn1q0xw8Wp-T1GwAABaY"]
[Sun Aug 30 03:09:10.606082 2026] [security2:error] [pid 509915:tid 510089] [client 68.155.159.216:46041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-admin/admin.php"] [unique_id "apPlJs2gn1q0xw8Wp-T1KgAABV0"]
[Sun Aug 30 03:09:10.608678 2026] [security2:error] [pid 509915:tid 510050] [client 20.104.18.15:43266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/one.php"] [unique_id "apPlJs2gn1q0xw8Wp-T1LgAABTY"]
[Sun Aug 30 03:09:10.615142 2026] [authz_core:error] [pid 509915:tid 510106] [client 74.7.243.204:54682] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:10.615401 2026] [authz_core:error] [pid 509915:tid 510106] [client 74.7.243.204:54682] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:10.626754 2026] [security2:error] [pid 509915:tid 510088] [client 20.151.8.82:16706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/8.php"] [unique_id "apPlJs2gn1q0xw8Wp-T1OQAABVw"]
[Sun Aug 30 03:09:10.643615 2026] [security2:error] [pid 509915:tid 510164] [client 20.104.50.220:52845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/anbu.php"] [unique_id "apPlJs2gn1q0xw8Wp-T1RwAABag"]
[Sun Aug 30 03:09:10.656273 2026] [security2:error] [pid 509915:tid 510151] [client 20.104.50.220:52841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/small.php"] [unique_id "apPlJs2gn1q0xw8Wp-T1TAAABZs"]
[Sun Aug 30 03:09:10.660723 2026] [security2:error] [pid 509915:tid 510086] [client 20.220.204.93:52340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apPlJs2gn1q0xw8Wp-T1UAAABVo"]
[Sun Aug 30 03:09:10.674713 2026] [security2:error] [pid 509915:tid 510070] [client 20.48.251.3:59323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/olfclass.php"] [unique_id "apPlJs2gn1q0xw8Wp-T1VgAABUo"]
[Sun Aug 30 03:09:10.686235 2026] [authz_core:error] [pid 509915:tid 510101] [client 66.249.66.194:62200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:10.686500 2026] [authz_core:error] [pid 509915:tid 510101] [client 66.249.66.194:62200] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:10.688804 2026] [security2:error] [pid 510357:tid 510590] [client 20.48.160.90:40061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/zfqipfss.php"] [unique_id "apPlJn5YTqJxoOZUSXtLjAAABho"]
[Sun Aug 30 03:09:10.722100 2026] [security2:error] [pid 509915:tid 510100] [client 74.248.24.12:15253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/fucixwya.php"] [unique_id "apPlJs2gn1q0xw8Wp-T1fQAABWg"]
[Sun Aug 30 03:09:10.754780 2026] [security2:error] [pid 510357:tid 510531] [client 20.151.8.82:16640] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.societyofassassins.com"] [uri "/1.php"] [unique_id "apPlJn5YTqJxoOZUSXtLnQAABd8"]
[Sun Aug 30 03:09:10.754872 2026] [security2:error] [pid 510357:tid 510531] [client 20.151.8.82:16640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/1.php"] [unique_id "apPlJn5YTqJxoOZUSXtLnQAABd8"]
[Sun Aug 30 03:09:10.763306 2026] [security2:error] [pid 509915:tid 510095] [client 20.151.200.44:59551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.captainrummy.com"] [uri "/waf.php"] [unique_id "apPlJs2gn1q0xw8Wp-T1jwAABWM"]
[Sun Aug 30 03:09:10.763398 2026] [security2:error] [pid 509915:tid 510117] [client 20.48.251.3:13424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/koiy.php"] [unique_id "apPlJs2gn1q0xw8Wp-T1kAAABXk"]
[Sun Aug 30 03:09:10.791870 2026] [security2:error] [pid 509915:tid 510126] [client 20.220.204.93:52348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/motu.php"] [unique_id "apPlJs2gn1q0xw8Wp-T1pQAABYI"]
[Sun Aug 30 03:09:10.816485 2026] [security2:error] [pid 509915:tid 510078] [client 34.100.204.203:60656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/ci/.env"] [unique_id "apPlJs2gn1q0xw8Wp-T1uAAABVI"]
[Sun Aug 30 03:09:10.818920 2026] [security2:error] [pid 509915:tid 510099] [client 20.48.160.90:39952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-e725365c.a220training.com"] [uri "/zrjuyoos.php"] [unique_id "apPlJs2gn1q0xw8Wp-T1uQAABWc"]
[Sun Aug 30 03:09:10.828766 2026] [security2:error] [pid 510357:tid 510558] [client 20.104.50.220:61954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/26.php"] [unique_id "apPlJn5YTqJxoOZUSXtLrwAABfo"]
[Sun Aug 30 03:09:10.875815 2026] [security2:error] [pid 509915:tid 510054] [client 158.158.54.35:5372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/bihnmimh.php"] [unique_id "apPlJs2gn1q0xw8Wp-T10gAABTo"]
[Sun Aug 30 03:09:10.888784 2026] [security2:error] [pid 510357:tid 510542] [client 20.151.8.82:16709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/admin.php"] [unique_id "apPlJn5YTqJxoOZUSXtLuQAABeo"]
[Sun Aug 30 03:09:10.889211 2026] [security2:error] [pid 510357:tid 510527] [client 20.104.50.220:31824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/520.php"] [unique_id "apPlJn5YTqJxoOZUSXtLugAABds"]
[Sun Aug 30 03:09:10.897313 2026] [security2:error] [pid 509915:tid 510136] [client 20.104.50.220:33295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/haha.php"] [unique_id "apPlJs2gn1q0xw8Wp-T12wAABYw"]
[Sun Aug 30 03:09:10.950687 2026] [security2:error] [pid 509915:tid 510094] [client 20.220.204.93:59080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/Ov-Simple1.php"] [unique_id "apPlJs2gn1q0xw8Wp-T2BAAABWI"]
[Sun Aug 30 03:09:10.960684 2026] [security2:error] [pid 509915:tid 510168] [client 20.104.50.220:63207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/x.php"] [unique_id "apPlJs2gn1q0xw8Wp-T2DAAABaw"]
[Sun Aug 30 03:09:11.004772 2026] [security2:error] [pid 510357:tid 510498] [client 20.104.49.130:53734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/dex.php"] [unique_id "apPlJ35YTqJxoOZUSXtLzwAABb4"]
[Sun Aug 30 03:09:11.006688 2026] [authz_core:error] [pid 509915:tid 510047] [client 216.73.216.128:36128] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:11.006951 2026] [authz_core:error] [pid 509915:tid 510047] [client 216.73.216.128:36128] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:11.017436 2026] [security2:error] [pid 510357:tid 510517] [client 20.151.8.82:16616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/edit.php"] [unique_id "apPlJ35YTqJxoOZUSXtL0QAABdE"]
[Sun Aug 30 03:09:11.038850 2026] [security2:error] [pid 510357:tid 510610] [client 20.104.18.15:23323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/c4.php"] [unique_id "apPlJ35YTqJxoOZUSXtL1gAABi4"]
[Sun Aug 30 03:09:11.060428 2026] [security2:error] [pid 509915:tid 510075] [client 34.100.204.203:60656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/cd/.env"] [unique_id "apPlJ82gn1q0xw8Wp-T2OAAABU8"]
[Sun Aug 30 03:09:11.071350 2026] [security2:error] [pid 509915:tid 510156] [client 4.205.62.107:17326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/wsws.php"] [unique_id "apPlJ82gn1q0xw8Wp-T2QAAABaA"]
[Sun Aug 30 03:09:11.098257 2026] [authz_core:error] [pid 510357:tid 510575] [client 216.73.216.128:13634] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:11.098530 2026] [authz_core:error] [pid 510357:tid 510575] [client 216.73.216.128:13634] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:11.099539 2026] [authz_core:error] [pid 509915:tid 510117] [client 74.7.243.204:54682] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:11.099916 2026] [authz_core:error] [pid 509915:tid 510117] [client 74.7.243.204:54682] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:11.109110 2026] [security2:error] [pid 509915:tid 510077] [client 20.220.204.93:52327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/wp-blogs.php"] [unique_id "apPlJ82gn1q0xw8Wp-T2WQAABVE"]
[Sun Aug 30 03:09:11.144527 2026] [security2:error] [pid 509915:tid 510094] [client 20.151.8.82:16717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/inputs.php"] [unique_id "apPlJ82gn1q0xw8Wp-T2cQAABWI"]
[Sun Aug 30 03:09:11.153291 2026] [security2:error] [pid 509915:tid 510105] [client 20.104.49.130:53510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/abcd.php"] [unique_id "apPlJ82gn1q0xw8Wp-T2dAAABW0"]
[Sun Aug 30 03:09:11.186021 2026] [authz_core:error] [pid 509915:tid 510161] [client 66.249.66.65:36265] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:11.186311 2026] [authz_core:error] [pid 509915:tid 510161] [client 66.249.66.65:36265] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:11.207850 2026] [security2:error] [pid 510357:tid 510607] [client 68.155.159.216:54222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-l0gin.php"] [unique_id "apPlJ35YTqJxoOZUSXtL8gAABis"]
[Sun Aug 30 03:09:11.207938 2026] [security2:error] [pid 510357:tid 510558] [client 4.205.62.107:61801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/ms.php"] [unique_id "apPlJ35YTqJxoOZUSXtL8QAABfo"]
[Sun Aug 30 03:09:11.239905 2026] [security2:error] [pid 509915:tid 510048] [client 74.248.24.12:3054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/al.php"] [unique_id "apPlJ82gn1q0xw8Wp-T2oAAABTQ"]
[Sun Aug 30 03:09:11.242285 2026] [security2:error] [pid 509915:tid 510124] [client 20.220.204.93:59071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/mini.php"] [unique_id "apPlJ82gn1q0xw8Wp-T2ogAABYA"]
[Sun Aug 30 03:09:11.262334 2026] [authz_core:error] [pid 509915:tid 510066] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:11.262781 2026] [authz_core:error] [pid 509915:tid 510066] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:11.268223 2026] [security2:error] [pid 509915:tid 510142] [client 20.104.49.130:43778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/jp.php"] [unique_id "apPlJ82gn1q0xw8Wp-T2rQAABZI"]
[Sun Aug 30 03:09:11.269570 2026] [security2:error] [pid 509915:tid 510046] [client 4.205.62.107:36671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/gecko-litespeed.php"] [unique_id "apPlJ82gn1q0xw8Wp-T2sAAABTI"]
[Sun Aug 30 03:09:11.279554 2026] [security2:error] [pid 509915:tid 510093] [client 20.104.50.220:46607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/cabs.php"] [unique_id "apPlJ82gn1q0xw8Wp-T2vQAABWE"]
[Sun Aug 30 03:09:11.280211 2026] [security2:error] [pid 509915:tid 510057] [client 20.151.8.82:16649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/av.php"] [unique_id "apPlJ82gn1q0xw8Wp-T2vwAABT0"]
[Sun Aug 30 03:09:11.292129 2026] [security2:error] [pid 510357:tid 510529] [client 20.104.18.15:35487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/shiny.php"] [unique_id "apPlJ35YTqJxoOZUSXtMBQAABd0"]
[Sun Aug 30 03:09:11.300573 2026] [security2:error] [pid 509915:tid 510168] [client 34.100.204.203:60656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/jenkins/.env"] [unique_id "apPlJ82gn1q0xw8Wp-T2xwAABaw"]
[Sun Aug 30 03:09:11.321927 2026] [security2:error] [pid 509915:tid 510077] [client 20.104.49.130:47945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/002.php"] [unique_id "apPlJ82gn1q0xw8Wp-T2zwAABVE"]
[Sun Aug 30 03:09:11.328433 2026] [security2:error] [pid 510357:tid 510545] [client 20.104.18.15:34510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/revo.php"] [unique_id "apPlJ35YTqJxoOZUSXtMEAAABe0"]
[Sun Aug 30 03:09:11.336889 2026] [security2:error] [pid 510357:tid 510548] [client 158.158.54.35:23010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/ewywe1dg.php"] [unique_id "apPlJ35YTqJxoOZUSXtMFwAABfA"]
[Sun Aug 30 03:09:11.351582 2026] [security2:error] [pid 510357:tid 510492] [client 20.104.18.15:2041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/wp-content/k.php"] [unique_id "apPlJ35YTqJxoOZUSXtMHAAABbg"]
[Sun Aug 30 03:09:11.386132 2026] [security2:error] [pid 509915:tid 510160] [client 20.220.204.93:50782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/amp.php"] [unique_id "apPlJ82gn1q0xw8Wp-T24gAABaQ"]
[Sun Aug 30 03:09:11.432003 2026] [security2:error] [pid 509915:tid 510173] [client 20.151.8.82:16583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/classwithtostring.php"] [unique_id "apPlJ82gn1q0xw8Wp-T3AAAABbE"]
[Sun Aug 30 03:09:11.460731 2026] [security2:error] [pid 509915:tid 510112] [client 20.104.50.220:5620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/loader.php"] [unique_id "apPlJ82gn1q0xw8Wp-T3EgAABXQ"]
[Sun Aug 30 03:09:11.485868 2026] [security2:error] [pid 509915:tid 510094] [client 20.48.251.3:59501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/bengi.php"] [unique_id "apPlJ82gn1q0xw8Wp-T3IgAABWI"]
[Sun Aug 30 03:09:11.504989 2026] [security2:error] [pid 509915:tid 510095] [client 20.104.18.15:18262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/htio.php"] [unique_id "apPlJ82gn1q0xw8Wp-T3MQAABWM"]
[Sun Aug 30 03:09:11.530350 2026] [security2:error] [pid 510357:tid 510501] [client 20.220.204.93:50791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/cc13.php"] [unique_id "apPlJ35YTqJxoOZUSXtMOAAABcE"]
[Sun Aug 30 03:09:11.538921 2026] [security2:error] [pid 509915:tid 510141] [client 34.100.204.203:60656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/gitlab/.env"] [unique_id "apPlJ82gn1q0xw8Wp-T3OQAABZE"]
[Sun Aug 30 03:09:11.541860 2026] [security2:error] [pid 509915:tid 510133] [client 68.155.159.216:54307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlJ82gn1q0xw8Wp-T3PAAABYk"]
[Sun Aug 30 03:09:11.564273 2026] [security2:error] [pid 509915:tid 510172] [client 20.151.8.82:16745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/adminfuns.php"] [unique_id "apPlJ82gn1q0xw8Wp-T3RgAABbA"]
[Sun Aug 30 03:09:11.574757 2026] [security2:error] [pid 509915:tid 510067] [client 20.104.50.220:16746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/jp.php"] [unique_id "apPlJ82gn1q0xw8Wp-T3SQAABUc"]
[Sun Aug 30 03:09:11.589511 2026] [authz_core:error] [pid 509915:tid 510157] [client 66.249.66.77:53518] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:11.589794 2026] [authz_core:error] [pid 509915:tid 510157] [client 66.249.66.77:53518] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:11.602970 2026] [authz_core:error] [pid 509915:tid 510117] [client 74.7.243.204:54682] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:11.603499 2026] [authz_core:error] [pid 509915:tid 510117] [client 74.7.243.204:54682] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:11.670709 2026] [security2:error] [pid 509915:tid 510116] [client 20.104.50.220:51626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/pas.php"] [unique_id "apPlJ82gn1q0xw8Wp-T3eQAABXg"]
[Sun Aug 30 03:09:11.696422 2026] [security2:error] [pid 509915:tid 510131] [client 20.220.204.93:52339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/aa.php"] [unique_id "apPlJ82gn1q0xw8Wp-T3iwAABYc"]
[Sun Aug 30 03:09:11.699210 2026] [security2:error] [pid 509915:tid 510124] [client 20.151.8.82:16667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/ms-edit.php"] [unique_id "apPlJ82gn1q0xw8Wp-T3jgAABYA"]
[Sun Aug 30 03:09:11.700558 2026] [security2:error] [pid 509915:tid 510054] [client 20.104.49.130:54168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/100.php"] [unique_id "apPlJ82gn1q0xw8Wp-T3kgAABTo"]
[Sun Aug 30 03:09:11.726341 2026] [security2:error] [pid 509915:tid 510133] [client 20.104.49.130:52132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/css.php"] [unique_id "apPlJ82gn1q0xw8Wp-T3qgAABYk"]
[Sun Aug 30 03:09:11.781700 2026] [security2:error] [pid 509915:tid 510078] [client 20.104.18.15:43265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/503.php"] [unique_id "apPlJ82gn1q0xw8Wp-T3yAAABVI"]
[Sun Aug 30 03:09:11.796960 2026] [security2:error] [pid 509915:tid 510052] [client 20.104.50.220:62791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/style-js.php"] [unique_id "apPlJ82gn1q0xw8Wp-T32QAABTg"]
[Sun Aug 30 03:09:11.797124 2026] [security2:error] [pid 509915:tid 510117] [client 20.104.50.220:29615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-content/%E5%B9%B3%E4%BB%AE%E5%90%8Ds.php"] [unique_id "apPlJ82gn1q0xw8Wp-T32wAABXk"]
[Sun Aug 30 03:09:11.812232 2026] [security2:error] [pid 509915:tid 510065] [client 20.48.251.3:55760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/gnmlc.php"] [unique_id "apPlJ82gn1q0xw8Wp-T35wAABUU"]
[Sun Aug 30 03:09:11.820695 2026] [security2:error] [pid 509915:tid 510072] [client 74.248.24.12:2958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/cadastro-2.php"] [unique_id "apPlJ82gn1q0xw8Wp-T37AAABUw"]
[Sun Aug 30 03:09:11.827359 2026] [security2:error] [pid 509915:tid 510155] [client 158.158.54.35:5380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/haiterus.php"] [unique_id "apPlJ82gn1q0xw8Wp-T38AAABZ8"]
[Sun Aug 30 03:09:11.841098 2026] [security2:error] [pid 509915:tid 510078] [client 20.220.204.93:52342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/s1.php"] [unique_id "apPlJ82gn1q0xw8Wp-T3-wAABVI"]
[Sun Aug 30 03:09:11.849507 2026] [security2:error] [pid 509915:tid 510128] [client 20.104.49.130:48034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/xmini4.php"] [unique_id "apPlJ82gn1q0xw8Wp-T3_gAABYQ"]
[Sun Aug 30 03:09:11.851818 2026] [security2:error] [pid 509915:tid 510135] [client 20.151.8.82:16705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/222.php"] [unique_id "apPlJ82gn1q0xw8Wp-T4AQAABYs"]
[Sun Aug 30 03:09:11.864987 2026] [lsapi:warn] [pid 509915:tid 509936] [remote 136.114.86.244:16384] [host tastylandscape.com] Backend log: PHP Warning: Use of undefined constant user_level - assumed 'user_level' (this will throw an Error in a future version of PHP) in /home4/tommed/public_html/wp-content/plugins/ultimate-google-analytics/ultimate_ga.php on line 524\n
[Sun Aug 30 03:09:11.873216 2026] [security2:error] [pid 509915:tid 510129] [client 34.100.204.203:60656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/github/.env"] [unique_id "apPlJ82gn1q0xw8Wp-T4CwAABYU"]
[Sun Aug 30 03:09:11.911504 2026] [security2:error] [pid 510357:tid 510544] [client 216.73.216.128:13634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/about.html"] [unique_id "apPlJ35YTqJxoOZUSXtMdwAABew"]
[Sun Aug 30 03:09:11.917199 2026] [security2:error] [pid 509915:tid 510124] [client 20.48.251.3:13421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/queue.php"] [unique_id "apPlJ82gn1q0xw8Wp-T4FgAABYA"]
[Sun Aug 30 03:09:11.980370 2026] [security2:error] [pid 509915:tid 510129] [client 20.151.8.82:16648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/BDKR28WP.php"] [unique_id "apPlJ82gn1q0xw8Wp-T4RQAABYU"]
[Sun Aug 30 03:09:11.990972 2026] [security2:error] [pid 509915:tid 510145] [client 20.220.204.93:59033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/0byte.php"] [unique_id "apPlJ82gn1q0xw8Wp-T4UQAABZU"]
[Sun Aug 30 03:09:11.991209 2026] [security2:error] [pid 509915:tid 510050] [client 20.104.50.220:61470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/2index.php"] [unique_id "apPlJ82gn1q0xw8Wp-T4UgAABTY"]
[Sun Aug 30 03:09:12.026667 2026] [security2:error] [pid 509915:tid 510126] [client 4.205.62.107:25865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/ah25.php"] [unique_id "apPlKM2gn1q0xw8Wp-T4awAABYI"]
[Sun Aug 30 03:09:12.032334 2026] [authz_core:error] [pid 509915:tid 510084] [client 66.249.66.195:64173] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:12.032603 2026] [authz_core:error] [pid 509915:tid 510084] [client 66.249.66.195:64173] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:12.041426 2026] [security2:error] [pid 509915:tid 510111] [client 20.104.50.220:33061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/sc.php"] [unique_id "apPlKM2gn1q0xw8Wp-T4cwAABXM"]
[Sun Aug 30 03:09:12.042566 2026] [security2:error] [pid 509915:tid 510100] [client 20.104.50.220:32737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/file18.php"] [unique_id "apPlKM2gn1q0xw8Wp-T4dAAABWg"]
[Sun Aug 30 03:09:12.044143 2026] [security2:error] [pid 509915:tid 510153] [client 20.104.49.130:57667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/jp.php"] [unique_id "apPlKM2gn1q0xw8Wp-T4dgAABZ0"]
[Sun Aug 30 03:09:12.102324 2026] [security2:error] [pid 510357:tid 510595] [client 20.104.50.220:59350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/by.php"] [unique_id "apPlKH5YTqJxoOZUSXtMkgAABh8"]
[Sun Aug 30 03:09:12.109803 2026] [security2:error] [pid 509915:tid 510165] [client 34.100.204.203:60656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/actions/.env"] [unique_id "apPlKM2gn1q0xw8Wp-T4pAAABak"]
[Sun Aug 30 03:09:12.109901 2026] [security2:error] [pid 509915:tid 510070] [client 20.151.8.82:16653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/wp.php"] [unique_id "apPlKM2gn1q0xw8Wp-T4pQAABUo"]
[Sun Aug 30 03:09:12.118987 2026] [lsapi:warn] [pid 509915:tid 509937] [remote 136.114.86.244:16384] [host tastylandscape.com] Backend log: PHP Warning: Use of undefined constant user_level - assumed 'user_level' (this will throw an Error in a future version of PHP) in /home4/tommed/public_html/wp-content/plugins/ultimate-google-analytics/ultimate_ga.php on line 524\n
[Sun Aug 30 03:09:12.123307 2026] [security2:error] [pid 509915:tid 510139] [client 20.220.204.93:52230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/xr.php"] [unique_id "apPlKM2gn1q0xw8Wp-T4rgAABY8"]
[Sun Aug 30 03:09:12.133820 2026] [authz_core:error] [pid 509915:tid 510135] [client 74.7.243.204:54682] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:12.134193 2026] [authz_core:error] [pid 509915:tid 510135] [client 74.7.243.204:54682] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:12.182257 2026] [core:alert] [pid 509915:tid 510070] [client 116.179.32.166:0] /home3/fremant1/thedevonshireteaguide.com.au/.htaccess: without matching section
[Sun Aug 30 03:09:12.202567 2026] [security2:error] [pid 509915:tid 510094] [client 20.104.18.15:23367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/rxr.php"] [unique_id "apPlKM2gn1q0xw8Wp-T46gAABWI"]
[Sun Aug 30 03:09:12.202699 2026] [security2:error] [pid 509915:tid 510166] [client 20.104.49.130:54162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/fling.php"] [unique_id "apPlKM2gn1q0xw8Wp-T46wAABao"]
[Sun Aug 30 03:09:12.207380 2026] [security2:error] [pid 510357:tid 510518] [client 4.205.62.107:17134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/localconf.php"] [unique_id "apPlKH5YTqJxoOZUSXtMmgAABdI"]
[Sun Aug 30 03:09:12.241982 2026] [authz_core:error] [pid 509915:tid 510109] [client 216.73.216.128:36798] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:12.242215 2026] [security2:error] [pid 509915:tid 510120] [client 20.104.49.130:51371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/jp.php"] [unique_id "apPlKM2gn1q0xw8Wp-T4_wAABXw"]
[Sun Aug 30 03:09:12.242330 2026] [authz_core:error] [pid 509915:tid 510109] [client 216.73.216.128:36798] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:12.243598 2026] [security2:error] [pid 509915:tid 510060] [client 20.151.8.82:16725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/abcd.php"] [unique_id "apPlKM2gn1q0xw8Wp-T5AQAABUA"]
[Sun Aug 30 03:09:12.266250 2026] [security2:error] [pid 509915:tid 510171] [client 20.220.204.93:59069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/h02ugyh.php"] [unique_id "apPlKM2gn1q0xw8Wp-T5DQAABa8"]
[Sun Aug 30 03:09:12.312435 2026] [security2:error] [pid 509915:tid 510074] [client 158.158.54.35:2454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/beence.php"] [unique_id "apPlKM2gn1q0xw8Wp-T5LgAABU4"]
[Sun Aug 30 03:09:12.323971 2026] [security2:error] [pid 509915:tid 510048] [client 68.155.159.216:55116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apPlKM2gn1q0xw8Wp-T5MAAABTQ"]
[Sun Aug 30 03:09:12.342443 2026] [security2:error] [pid 509915:tid 510125] [client 4.205.62.107:61822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/fucku.php"] [unique_id "apPlKM2gn1q0xw8Wp-T5OQAABYE"]
[Sun Aug 30 03:09:12.349144 2026] [security2:error] [pid 509915:tid 510169] [client 34.100.204.203:60656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/circleci/.env"] [unique_id "apPlKM2gn1q0xw8Wp-T5PQAABa0"]
[Sun Aug 30 03:09:12.372350 2026] [security2:error] [pid 509915:tid 510106] [client 20.151.8.82:16721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/simple.php"] [unique_id "apPlKM2gn1q0xw8Wp-T5SAAABW4"]
[Sun Aug 30 03:09:12.417563 2026] [security2:error] [pid 509915:tid 510046] [client 20.104.50.220:46628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/filesss.php"] [unique_id "apPlKM2gn1q0xw8Wp-T5XAAABTI"]
[Sun Aug 30 03:09:12.425442 2026] [security2:error] [pid 509915:tid 510146] [client 74.248.24.12:15291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/addslashes.php"] [unique_id "apPlKM2gn1q0xw8Wp-T5YAAABZY"]
[Sun Aug 30 03:09:12.433995 2026] [security2:error] [pid 509915:tid 510051] [client 20.220.204.93:59083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/xxw.php"] [unique_id "apPlKM2gn1q0xw8Wp-T5ZAAABTc"]
[Sun Aug 30 03:09:12.439137 2026] [security2:error] [pid 509915:tid 510074] [client 20.104.18.15:35196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/goods.php"] [unique_id "apPlKM2gn1q0xw8Wp-T5agAABU4"]
[Sun Aug 30 03:09:12.485077 2026] [security2:error] [pid 510357:tid 510594] [client 20.104.18.15:1935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/dev.php"] [unique_id "apPlKH5YTqJxoOZUSXtMywAABh4"]
[Sun Aug 30 03:09:12.493940 2026] [security2:error] [pid 510357:tid 510555] [client 20.104.18.15:34682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/birrs.php"] [unique_id "apPlKH5YTqJxoOZUSXtMzgAABfc"]
[Sun Aug 30 03:09:12.508098 2026] [security2:error] [pid 509915:tid 510117] [client 20.151.8.82:16727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/chosen.php"] [unique_id "apPlKM2gn1q0xw8Wp-T5lgAABXk"]
[Sun Aug 30 03:09:12.583768 2026] [security2:error] [pid 509915:tid 510156] [client 34.100.204.203:60656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/travis/.env"] [unique_id "apPlKM2gn1q0xw8Wp-T5sAAABaA"]
[Sun Aug 30 03:09:12.617434 2026] [security2:error] [pid 509915:tid 510119] [client 20.220.204.93:59026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/bolt.php"] [unique_id "apPlKM2gn1q0xw8Wp-T5xgAABXs"]
[Sun Aug 30 03:09:12.618621 2026] [security2:error] [pid 510357:tid 510508] [client 20.104.50.220:5905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/log.php"] [unique_id "apPlKH5YTqJxoOZUSXtM5gAABcg"]
[Sun Aug 30 03:09:12.621561 2026] [authz_core:error] [pid 509915:tid 510165] [client 66.249.66.43:43454] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:12.621831 2026] [authz_core:error] [pid 509915:tid 510165] [client 66.249.66.43:43454] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:12.627873 2026] [authz_core:error] [pid 509915:tid 510166] [client 74.7.243.204:54682] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:12.628133 2026] [authz_core:error] [pid 509915:tid 510166] [client 74.7.243.204:54682] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:12.633272 2026] [security2:error] [pid 509915:tid 510085] [client 20.48.251.3:59903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/i.php"] [unique_id "apPlKM2gn1q0xw8Wp-T5zgAABVk"]
[Sun Aug 30 03:09:12.642081 2026] [core:alert] [pid 510357:tid 510550] [client 119.249.100.43:0] /home3/fremant1/thedevonshireteaguide.com.au/.htaccess: without matching section
[Sun Aug 30 03:09:12.644293 2026] [security2:error] [pid 509915:tid 510153] [client 20.104.18.15:18359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/dev.php"] [unique_id "apPlKM2gn1q0xw8Wp-T52QAABZ0"]
[Sun Aug 30 03:09:12.653461 2026] [security2:error] [pid 509915:tid 510141] [client 20.151.8.82:16720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/als.php"] [unique_id "apPlKM2gn1q0xw8Wp-T53QAABZE"]
[Sun Aug 30 03:09:12.712437 2026] [security2:error] [pid 509915:tid 510173] [client 20.104.50.220:17239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/f35.php"] [unique_id "apPlKM2gn1q0xw8Wp-T6CwAABbE"]
[Sun Aug 30 03:09:12.742680 2026] [authz_core:error] [pid 509915:tid 510112] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:12.742941 2026] [authz_core:error] [pid 509915:tid 510112] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:12.769482 2026] [security2:error] [pid 509915:tid 510123] [client 20.220.204.93:59123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/rtx.php"] [unique_id "apPlKM2gn1q0xw8Wp-T6LAAABX8"]
[Sun Aug 30 03:09:12.785002 2026] [security2:error] [pid 509915:tid 510145] [client 20.151.8.82:16728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/nox.php"] [unique_id "apPlKM2gn1q0xw8Wp-T6PwAABZU"]
[Sun Aug 30 03:09:12.787918 2026] [security2:error] [pid 509915:tid 510158] [client 158.158.54.35:2468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/e69ovfsr.php"] [unique_id "apPlKM2gn1q0xw8Wp-T6QwAABaI"]
[Sun Aug 30 03:09:12.821249 2026] [security2:error] [pid 509915:tid 510162] [client 20.104.50.220:42766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/abc.php"] [unique_id "apPlKM2gn1q0xw8Wp-T6YAAABaY"]
[Sun Aug 30 03:09:12.831773 2026] [security2:error] [pid 509915:tid 510171] [client 34.100.204.203:60656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/buildkite/.env"] [unique_id "apPlKM2gn1q0xw8Wp-T6agAABa8"]
[Sun Aug 30 03:09:12.923234 2026] [security2:error] [pid 509915:tid 510095] [client 20.220.204.93:52347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/ckk.php"] [unique_id "apPlKM2gn1q0xw8Wp-T6ngAABWM"]
[Sun Aug 30 03:09:12.924916 2026] [security2:error] [pid 509915:tid 510134] [client 20.151.8.82:16714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/file59.php"] [unique_id "apPlKM2gn1q0xw8Wp-T6oQAABYo"]
[Sun Aug 30 03:09:12.933817 2026] [security2:error] [pid 509915:tid 510145] [client 20.104.18.15:43315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/504.php"] [unique_id "apPlKM2gn1q0xw8Wp-T6pgAABZU"]
[Sun Aug 30 03:09:12.945233 2026] [security2:error] [pid 509915:tid 510171] [client 146.190.213.223:40872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.213.190.146.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "demandthetruth.org"] [uri "/wp-login.php"] [unique_id "apPlKM2gn1q0xw8Wp-T6pQAABa8"]
[Sun Aug 30 03:09:12.954175 2026] [security2:error] [pid 510357:tid 510502] [client 20.104.50.220:28695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-admin/%E5%B9%B3%E4%BB%AE%E5%90%8Ds.php"] [unique_id "apPlKH5YTqJxoOZUSXtNBwAABcI"]
[Sun Aug 30 03:09:12.961136 2026] [security2:error] [pid 509915:tid 510169] [client 20.48.251.3:55696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/koiy.php"] [unique_id "apPlKM2gn1q0xw8Wp-T6uAAABa0"]
[Sun Aug 30 03:09:12.991111 2026] [security2:error] [pid 510357:tid 510499] [client 20.104.50.220:62832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/style.php"] [unique_id "apPlKH5YTqJxoOZUSXtNFAAABb8"]
[Sun Aug 30 03:09:13.024348 2026] [security2:error] [pid 509915:tid 510137] [client 68.155.159.216:54291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlKc2gn1q0xw8Wp-T64AAABY0"]
[Sun Aug 30 03:09:13.054442 2026] [security2:error] [pid 509915:tid 510147] [client 20.220.204.93:59098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.204.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcaneguardians.com"] [uri "/R57.php"] [unique_id "apPlKc2gn1q0xw8Wp-T67gAABZc"]
[Sun Aug 30 03:09:13.063420 2026] [security2:error] [pid 509915:tid 510170] [client 20.151.8.82:16604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/admin.php"] [unique_id "apPlKc2gn1q0xw8Wp-T68gAABa4"]
[Sun Aug 30 03:09:13.072607 2026] [security2:error] [pid 509915:tid 510094] [client 34.100.204.203:60656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/mysql/.env"] [unique_id "apPlKc2gn1q0xw8Wp-T6-AAABWI"]
[Sun Aug 30 03:09:13.084991 2026] [security2:error] [pid 510357:tid 510578] [client 20.151.200.44:45956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/admin.php/007x.php"] [unique_id "apPlKX5YTqJxoOZUSXtNJQAABg4"]
[Sun Aug 30 03:09:13.093917 2026] [core:alert] [pid 510357:tid 510508] [client 111.225.214.188:0] /home3/fremant1/thedevonshireteaguide.com.au/.htaccess: without matching section
[Sun Aug 30 03:09:13.094969 2026] [security2:error] [pid 509915:tid 510101] [client 74.248.24.12:11378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/content.php888"] [unique_id "apPlKc2gn1q0xw8Wp-T7CQAABWk"]
[Sun Aug 30 03:09:13.100667 2026] [authz_core:error] [pid 509915:tid 510048] [client 74.7.243.204:54682] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:13.100972 2026] [authz_core:error] [pid 509915:tid 510048] [client 74.7.243.204:54682] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:13.104360 2026] [authz_core:error] [pid 509915:tid 510111] [client 216.73.216.128:36128] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:13.104637 2026] [authz_core:error] [pid 509915:tid 510111] [client 216.73.216.128:36128] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:13.131107 2026] [security2:error] [pid 509915:tid 510053] [client 20.48.251.3:56371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/doc.php"] [unique_id "apPlKc2gn1q0xw8Wp-T7JQAABTk"]
[Sun Aug 30 03:09:13.149902 2026] [security2:error] [pid 509915:tid 510058] [client 20.104.50.220:59566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/32.php"] [unique_id "apPlKc2gn1q0xw8Wp-T7LwAABT4"]
[Sun Aug 30 03:09:13.176800 2026] [security2:error] [pid 509915:tid 510090] [client 217.160.22.146:39232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.22.160.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "patrickstaehle.com"] [uri "/wp-login.php"] [unique_id "apPlKc2gn1q0xw8Wp-T7OQAABV4"]
[Sun Aug 30 03:09:13.195767 2026] [security2:error] [pid 509915:tid 510160] [client 20.104.50.220:33539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/fvck.php"] [unique_id "apPlKc2gn1q0xw8Wp-T7SwAABaQ"]
[Sun Aug 30 03:09:13.202746 2026] [security2:error] [pid 509915:tid 510096] [client 20.151.8.82:16760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/aa2.php"] [unique_id "apPlKc2gn1q0xw8Wp-T7TgAABWQ"]
[Sun Aug 30 03:09:13.209578 2026] [security2:error] [pid 510357:tid 510505] [client 20.104.50.220:32090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/ffile.php"] [unique_id "apPlKX5YTqJxoOZUSXtNPQAABcU"]
[Sun Aug 30 03:09:13.259990 2026] [security2:error] [pid 510357:tid 510509] [client 20.104.50.220:31537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/cxs.php"] [unique_id "apPlKX5YTqJxoOZUSXtNQAAABck"]
[Sun Aug 30 03:09:13.272021 2026] [security2:error] [pid 509915:tid 510145] [client 4.205.62.107:25784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/groceries/index.php"] [unique_id "apPlKc2gn1q0xw8Wp-T7aAAABZU"]
[Sun Aug 30 03:09:13.273694 2026] [security2:error] [pid 510357:tid 510573] [client 158.158.54.35:5356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/bypass.php7"] [unique_id "apPlKX5YTqJxoOZUSXtNQwAABgk"]
[Sun Aug 30 03:09:13.280514 2026] [security2:error] [pid 510357:tid 510547] [client 216.73.216.128:2010] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/topics.html"] [unique_id "apPlKX5YTqJxoOZUSXtNRgAABe8"]
[Sun Aug 30 03:09:13.324995 2026] [security2:error] [pid 509915:tid 510104] [client 34.100.204.203:60656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/postgres/.env"] [unique_id "apPlKc2gn1q0xw8Wp-T7ewAABWw"]
[Sun Aug 30 03:09:13.333588 2026] [security2:error] [pid 510357:tid 510511] [client 20.151.8.82:16764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/xamp.php"] [unique_id "apPlKX5YTqJxoOZUSXtNWwAABcs"]
[Sun Aug 30 03:09:13.341250 2026] [security2:error] [pid 509915:tid 510089] [client 4.205.62.107:17329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/bengi.php"] [unique_id "apPlKc2gn1q0xw8Wp-T7gAAABV0"]
[Sun Aug 30 03:09:13.380064 2026] [authz_core:error] [pid 510357:tid 510508] [client 216.73.216.128:2010] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:13.380342 2026] [authz_core:error] [pid 510357:tid 510508] [client 216.73.216.128:2010] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:13.380933 2026] [security2:error] [pid 510357:tid 510574] [client 20.104.18.15:23513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bridgesofcourage.mtrphotography.net"] [uri "/reviall.php"] [unique_id "apPlKX5YTqJxoOZUSXtNbgAABgo"]
[Sun Aug 30 03:09:13.422709 2026] [security2:error] [pid 509915:tid 510161] [client 20.104.49.130:53793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlKc2gn1q0xw8Wp-T7ogAABaU"]
[Sun Aug 30 03:09:13.466210 2026] [security2:error] [pid 509915:tid 510101] [client 20.151.8.82:16766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/bless.php"] [unique_id "apPlKc2gn1q0xw8Wp-T7vAAABWk"]
[Sun Aug 30 03:09:13.479209 2026] [security2:error] [pid 509915:tid 510073] [client 4.205.62.107:58451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/error_log.php"] [unique_id "apPlKc2gn1q0xw8Wp-T7xAAABU0"]
[Sun Aug 30 03:09:13.514193 2026] [security2:error] [pid 509915:tid 510067] [client 68.155.159.216:54225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPlKc2gn1q0xw8Wp-T72AAABUc"]
[Sun Aug 30 03:09:13.548806 2026] [core:alert] [pid 509915:tid 510077] [client 119.249.100.112:0] /home3/fremant1/thedevonshireteaguide.com.au/.htaccess: without matching section
[Sun Aug 30 03:09:13.554216 2026] [security2:error] [pid 510357:tid 510565] [client 20.104.50.220:46872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/wp-aaa.php"] [unique_id "apPlKX5YTqJxoOZUSXtNnQAABgE"]
[Sun Aug 30 03:09:13.558019 2026] [security2:error] [pid 509915:tid 510156] [client 34.100.204.203:60656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/mongodb/.env"] [unique_id "apPlKc2gn1q0xw8Wp-T79AAABaA"]
[Sun Aug 30 03:09:13.572556 2026] [authz_core:error] [pid 509915:tid 510126] [client 66.249.66.40:57544] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:13.572856 2026] [authz_core:error] [pid 509915:tid 510126] [client 66.249.66.40:57544] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:13.574271 2026] [security2:error] [pid 509915:tid 510135] [client 20.104.18.15:35519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/alfa.php"] [unique_id "apPlKc2gn1q0xw8Wp-T7-QAABYs"]
[Sun Aug 30 03:09:13.585200 2026] [security2:error] [pid 510357:tid 510513] [client 168.107.94.195:61779] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "infoceptsinc.com"] [uri "/"] [unique_id "apPlKX5YTqJxoOZUSXtNoAAABc0"]
[Sun Aug 30 03:09:13.599709 2026] [security2:error] [pid 510357:tid 510587] [client 20.151.8.82:16657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/f35.php"] [unique_id "apPlKX5YTqJxoOZUSXtNpAAABhc"]
[Sun Aug 30 03:09:13.621727 2026] [security2:error] [pid 509915:tid 510104] [client 20.104.18.15:1980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/wp-activate.php"] [unique_id "apPlKc2gn1q0xw8Wp-T8DgAABWw"]
[Sun Aug 30 03:09:13.627753 2026] [security2:error] [pid 509915:tid 510154] [client 74.248.24.12:6033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/access.php"] [unique_id "apPlKc2gn1q0xw8Wp-T8EAAABZ4"]
[Sun Aug 30 03:09:13.639649 2026] [authz_core:error] [pid 509915:tid 510057] [client 74.7.243.204:54682] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:13.640175 2026] [authz_core:error] [pid 509915:tid 510057] [client 74.7.243.204:54682] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:13.644813 2026] [security2:error] [pid 509915:tid 510149] [client 216.73.216.128:36128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/_runtime"] [unique_id "apPlKc2gn1q0xw8Wp-T8HwAABZk"]
[Sun Aug 30 03:09:13.655503 2026] [security2:error] [pid 509915:tid 510089] [client 195.178.110.247:2546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.megansday.com"] [uri "/index.php"] [unique_id "apPlKc2gn1q0xw8Wp-T8IQAABV0"]
[Sun Aug 30 03:09:13.664770 2026] [security2:error] [pid 509915:tid 510122] [client 20.104.18.15:34757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/sss.php"] [unique_id "apPlKc2gn1q0xw8Wp-T8JQAABX4"]
[Sun Aug 30 03:09:13.731752 2026] [security2:error] [pid 509915:tid 510128] [client 20.151.8.82:16749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/aaa.php"] [unique_id "apPlKc2gn1q0xw8Wp-T8WgAABYQ"]
[Sun Aug 30 03:09:13.752839 2026] [security2:error] [pid 510357:tid 510601] [client 4.205.62.107:36617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/goods.php"] [unique_id "apPlKX5YTqJxoOZUSXtNvgAABiU"]
[Sun Aug 30 03:09:13.765909 2026] [security2:error] [pid 509915:tid 510106] [client 20.48.251.3:59471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/guk.php"] [unique_id "apPlKc2gn1q0xw8Wp-T8bwAABW4"]
[Sun Aug 30 03:09:13.773552 2026] [security2:error] [pid 510357:tid 510572] [client 20.104.50.220:5930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/functions.php"] [unique_id "apPlKX5YTqJxoOZUSXtNwgAABgg"]
[Sun Aug 30 03:09:13.781874 2026] [security2:error] [pid 510357:tid 510594] [client 20.104.18.15:18380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/gos.php"] [unique_id "apPlKX5YTqJxoOZUSXtNxQAABh4"]
[Sun Aug 30 03:09:13.798091 2026] [security2:error] [pid 509915:tid 510094] [client 34.100.204.203:60656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/redis/.env"] [unique_id "apPlKc2gn1q0xw8Wp-T8iQAABWI"]
[Sun Aug 30 03:09:13.815527 2026] [security2:error] [pid 510357:tid 510600] [client 158.158.54.35:4723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/colour.php"] [unique_id "apPlKX5YTqJxoOZUSXtN1QAABiQ"]
[Sun Aug 30 03:09:13.816378 2026] [security2:error] [pid 509915:tid 510133] [client 195.178.110.247:62404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.megansday.com"] [uri "/index.php"] [unique_id "apPlKc2gn1q0xw8Wp-T8lAAABYk"]
[Sun Aug 30 03:09:13.832500 2026] [authz_core:error] [pid 510357:tid 510506] [client 216.73.216.128:2010] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:13.832808 2026] [authz_core:error] [pid 510357:tid 510506] [client 216.73.216.128:2010] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:13.850783 2026] [security2:error] [pid 509915:tid 510083] [client 20.104.50.220:17244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-load.php"] [unique_id "apPlKc2gn1q0xw8Wp-T8qwAABVc"]
[Sun Aug 30 03:09:13.860907 2026] [security2:error] [pid 509915:tid 510113] [client 20.151.8.82:16608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/gecko.php"] [unique_id "apPlKc2gn1q0xw8Wp-T8rwAABXU"]
[Sun Aug 30 03:09:13.916289 2026] [security2:error] [pid 509915:tid 510060] [client 20.104.49.130:57710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/about.php"] [unique_id "apPlKc2gn1q0xw8Wp-T80AAABUA"]
[Sun Aug 30 03:09:13.968120 2026] [security2:error] [pid 510357:tid 510606] [client 68.155.159.216:45967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-includes/IXR/index.php"] [unique_id "apPlKX5YTqJxoOZUSXtN7gAABio"]
[Sun Aug 30 03:09:13.990446 2026] [security2:error] [pid 510357:tid 510500] [client 20.151.8.82:16751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/xiugai.php"] [unique_id "apPlKX5YTqJxoOZUSXtN-AAABcA"]
[Sun Aug 30 03:09:14.008592 2026] [security2:error] [pid 509915:tid 510171] [client 20.104.50.220:51642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/indexx.php"] [unique_id "apPlKs2gn1q0xw8Wp-T9BwAABa8"]
[Sun Aug 30 03:09:14.038506 2026] [security2:error] [pid 509915:tid 510117] [client 34.100.204.203:60656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/elasticsearch/.env"] [unique_id "apPlKs2gn1q0xw8Wp-T9FAAABXk"]
[Sun Aug 30 03:09:14.066400 2026] [security2:error] [pid 509915:tid 510097] [client 20.104.49.130:63489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/samll.php"] [unique_id "apPlKs2gn1q0xw8Wp-T9HgAABWU"]
[Sun Aug 30 03:09:14.076391 2026] [security2:error] [pid 510357:tid 510537] [client 20.104.18.15:43914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/admin.php"] [unique_id "apPlKn5YTqJxoOZUSXtOCAAABeU"]
[Sun Aug 30 03:09:14.091782 2026] [security2:error] [pid 510357:tid 510543] [client 20.104.50.220:52847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/plugins.php"] [unique_id "apPlKn5YTqJxoOZUSXtOCwAABes"]
[Sun Aug 30 03:09:14.099107 2026] [authz_core:error] [pid 509915:tid 510138] [client 74.7.243.204:54682] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:14.099378 2026] [authz_core:error] [pid 509915:tid 510138] [client 74.7.243.204:54682] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:14.100984 2026] [security2:error] [pid 509915:tid 510147] [client 20.48.251.3:59347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/w.php"] [unique_id "apPlKs2gn1q0xw8Wp-T9NgAABZc"]
[Sun Aug 30 03:09:14.107086 2026] [authz_core:error] [pid 509915:tid 510051] [client 216.73.216.128:36798] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:14.107371 2026] [authz_core:error] [pid 509915:tid 510051] [client 216.73.216.128:36798] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:14.121530 2026] [security2:error] [pid 509915:tid 510154] [client 20.151.8.82:16664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/adminner.php"] [unique_id "apPlKs2gn1q0xw8Wp-T9RAAABZ4"]
[Sun Aug 30 03:09:14.122701 2026] [authz_core:error] [pid 510357:tid 510561] [client 66.249.66.66:64708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:14.123135 2026] [authz_core:error] [pid 510357:tid 510561] [client 66.249.66.66:64708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:14.136661 2026] [security2:error] [pid 509915:tid 510156] [client 20.104.50.220:28695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/Success.php"] [unique_id "apPlKs2gn1q0xw8Wp-T9SwAABaA"]
[Sun Aug 30 03:09:14.157288 2026] [security2:error] [pid 509915:tid 510113] [client 74.248.24.12:2296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/aksinet.php"] [unique_id "apPlKs2gn1q0xw8Wp-T9VgAABXU"]
[Sun Aug 30 03:09:14.167355 2026] [authz_core:error] [pid 509915:tid 510064] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:14.167601 2026] [authz_core:error] [pid 509915:tid 510064] [client 74.7.227.8:54762] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:14.250113 2026] [security2:error] [pid 509915:tid 510081] [client 20.151.8.82:16699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/file1221.php"] [unique_id "apPlKs2gn1q0xw8Wp-T9lwAABVU"]
[Sun Aug 30 03:09:14.268394 2026] [security2:error] [pid 509915:tid 510128] [client 158.158.54.35:5374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/fm2.php"] [unique_id "apPlKs2gn1q0xw8Wp-T9ogAABYQ"]
[Sun Aug 30 03:09:14.277211 2026] [security2:error] [pid 509915:tid 510098] [client 34.100.204.203:60656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/rabbitmq/.env"] [unique_id "apPlKs2gn1q0xw8Wp-T9qwAABWY"]
[Sun Aug 30 03:09:14.289738 2026] [security2:error] [pid 510357:tid 510551] [client 20.104.50.220:61396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/404.php"] [unique_id "apPlKn5YTqJxoOZUSXtOLQAABfM"]
[Sun Aug 30 03:09:14.291631 2026] [security2:error] [pid 509915:tid 510144] [client 20.48.251.3:60525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/css.php"] [unique_id "apPlKs2gn1q0xw8Wp-T9tQAABZQ"]
[Sun Aug 30 03:09:14.322235 2026] [authz_core:error] [pid 509915:tid 510154] [client 66.249.66.198:47624] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:14.322688 2026] [authz_core:error] [pid 509915:tid 510154] [client 66.249.66.198:47624] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:14.364550 2026] [security2:error] [pid 509915:tid 510116] [client 20.104.50.220:32883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/0x.php"] [unique_id "apPlKs2gn1q0xw8Wp-T90QAABXg"]
[Sun Aug 30 03:09:14.380427 2026] [authz_core:error] [pid 509915:tid 510169] [client 216.73.216.128:55886] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:14.380741 2026] [authz_core:error] [pid 509915:tid 510169] [client 216.73.216.128:55886] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:14.392880 2026] [security2:error] [pid 510357:tid 510558] [client 20.151.8.82:16719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/inx.php"] [unique_id "apPlKn5YTqJxoOZUSXtOQAAABfo"]
[Sun Aug 30 03:09:14.395931 2026] [security2:error] [pid 509915:tid 510148] [client 20.104.50.220:63224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/coffexium.php"] [unique_id "apPlKs2gn1q0xw8Wp-T93AAABZg"]
[Sun Aug 30 03:09:14.401192 2026] [security2:error] [pid 510357:tid 510502] [client 20.104.49.130:48038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/pfm.php"] [unique_id "apPlKn5YTqJxoOZUSXtORQAABcI"]
[Sun Aug 30 03:09:14.402411 2026] [security2:error] [pid 509915:tid 510164] [client 20.104.50.220:32526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/file7.php"] [unique_id "apPlKs2gn1q0xw8Wp-T93gAABag"]
[Sun Aug 30 03:09:14.430311 2026] [security2:error] [pid 509915:tid 510131] [client 4.205.62.107:25767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/konfig.php"] [unique_id "apPlKs2gn1q0xw8Wp-T98gAABYc"]
[Sun Aug 30 03:09:14.486407 2026] [security2:error] [pid 509915:tid 510124] [client 4.205.62.107:17306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/i.php"] [unique_id "apPlKs2gn1q0xw8Wp-T-FQAABYA"]
[Sun Aug 30 03:09:14.538716 2026] [security2:error] [pid 510357:tid 510596] [client 20.151.8.82:16682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/reviall.php"] [unique_id "apPlKn5YTqJxoOZUSXtOZwAABiA"]
[Sun Aug 30 03:09:14.565342 2026] [security2:error] [pid 510357:tid 510598] [client 20.104.49.130:64127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/wp-css.php"] [unique_id "apPlKn5YTqJxoOZUSXtObgAABiI"]
[Sun Aug 30 03:09:14.646805 2026] [security2:error] [pid 510357:tid 510608] [client 4.205.62.107:61767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/phina.php"] [unique_id "apPlKn5YTqJxoOZUSXtOdgAABiw"]
[Sun Aug 30 03:09:14.649529 2026] [security2:error] [pid 510357:tid 510602] [client 68.155.159.216:55042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/ans.php"] [unique_id "apPlKn5YTqJxoOZUSXtOeAAABiY"]
[Sun Aug 30 03:09:14.663247 2026] [security2:error] [pid 510357:tid 510515] [client 74.248.24.12:12752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/ab1ux1ft.php"] [unique_id "apPlKn5YTqJxoOZUSXtOfQAABc8"]
[Sun Aug 30 03:09:14.675249 2026] [authz_core:error] [pid 510357:tid 510601] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:14.675517 2026] [authz_core:error] [pid 510357:tid 510601] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:14.683722 2026] [security2:error] [pid 510357:tid 510547] [client 20.151.8.82:16761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/11.php"] [unique_id "apPlKn5YTqJxoOZUSXtOgwAABe8"]
[Sun Aug 30 03:09:14.684255 2026] [security2:error] [pid 510357:tid 510569] [client 20.151.200.44:41860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlKn5YTqJxoOZUSXtOhAAABgU"]
[Sun Aug 30 03:09:14.693566 2026] [security2:error] [pid 510357:tid 510558] [client 20.104.50.220:46613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/css.php"] [unique_id "apPlKn5YTqJxoOZUSXtOhwAABfo"]
[Sun Aug 30 03:09:14.722124 2026] [security2:error] [pid 510357:tid 510604] [client 158.158.54.35:26332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/4price.php"] [unique_id "apPlKn5YTqJxoOZUSXtOkAAABig"]
[Sun Aug 30 03:09:14.736737 2026] [security2:error] [pid 510357:tid 510597] [client 20.104.18.15:35187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/33.php"] [unique_id "apPlKn5YTqJxoOZUSXtOkwAABiE"]
[Sun Aug 30 03:09:14.761422 2026] [security2:error] [pid 510357:tid 510526] [client 20.104.18.15:1902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/wp_blog_footer.php"] [unique_id "apPlKn5YTqJxoOZUSXtOlAAABdo"]
[Sun Aug 30 03:09:14.822757 2026] [authz_core:error] [pid 510357:tid 510548] [client 66.249.66.40:53687] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:14.823211 2026] [authz_core:error] [pid 510357:tid 510548] [client 66.249.66.40:53687] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:14.831079 2026] [security2:error] [pid 510357:tid 510541] [client 20.151.8.82:16656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/File.php"] [unique_id "apPlKn5YTqJxoOZUSXtOpQAABek"]
[Sun Aug 30 03:09:14.887351 2026] [authz_core:error] [pid 510357:tid 510605] [client 216.73.216.128:41351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:14.887624 2026] [authz_core:error] [pid 510357:tid 510605] [client 216.73.216.128:41351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:14.897698 2026] [autoindex:error] [pid 510357:tid 510554] [client 158.23.184.117:15007] AH01276: Cannot serve directory /home1/mudassar/public_html/mail/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:09:14.903415 2026] [security2:error] [pid 510357:tid 510560] [client 20.48.251.3:59863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/config_dev.php"] [unique_id "apPlKn5YTqJxoOZUSXtOrAAABfw"]
[Sun Aug 30 03:09:14.912012 2026] [security2:error] [pid 510357:tid 510561] [client 20.104.50.220:5540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/taxonomy.php"] [unique_id "apPlKn5YTqJxoOZUSXtOrwAABf0"]
[Sun Aug 30 03:09:14.948821 2026] [security2:error] [pid 510357:tid 510539] [client 20.104.18.15:34643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/wp-includes/ID3/moon.php"] [unique_id "apPlKn5YTqJxoOZUSXtOtwAABec"]
[Sun Aug 30 03:09:14.963341 2026] [security2:error] [pid 510357:tid 510594] [client 20.151.8.82:16767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/fi22.php"] [unique_id "apPlKn5YTqJxoOZUSXtOuwAABh4"]
[Sun Aug 30 03:09:14.988041 2026] [security2:error] [pid 510357:tid 510564] [client 20.104.50.220:16737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/xwpg.php"] [unique_id "apPlKn5YTqJxoOZUSXtOwAAABgA"]
[Sun Aug 30 03:09:14.989794 2026] [security2:error] [pid 510357:tid 510505] [client 20.104.18.15:18245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/132.php"] [unique_id "apPlKn5YTqJxoOZUSXtOwwAABcU"]
[Sun Aug 30 03:09:15.008847 2026] [security2:error] [pid 510357:tid 510508] [client 20.104.49.130:53880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/coffexium.php"] [unique_id "apPlK35YTqJxoOZUSXtOywAABcg"]
[Sun Aug 30 03:09:15.093275 2026] [security2:error] [pid 510357:tid 510517] [client 20.151.8.82:16654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPlK35YTqJxoOZUSXtO2AAABdE"]
[Sun Aug 30 03:09:15.108256 2026] [authz_core:error] [pid 510357:tid 510563] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:15.108519 2026] [authz_core:error] [pid 510357:tid 510563] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:15.174840 2026] [security2:error] [pid 510357:tid 510502] [client 74.248.24.12:15276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/block-bindings.php"] [unique_id "apPlK35YTqJxoOZUSXtO3gAABcI"]
[Sun Aug 30 03:09:15.193042 2026] [security2:error] [pid 510357:tid 510551] [client 20.104.50.220:63491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/browse.php"] [unique_id "apPlK35YTqJxoOZUSXtO4AAABfM"]
[Sun Aug 30 03:09:15.210944 2026] [security2:error] [pid 510357:tid 510598] [client 20.104.18.15:43995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/ws85.php"] [unique_id "apPlK35YTqJxoOZUSXtO5gAABiI"]
[Sun Aug 30 03:09:15.227114 2026] [security2:error] [pid 510357:tid 510592] [client 20.104.50.220:28707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-content/priv8.php"] [unique_id "apPlK35YTqJxoOZUSXtO6QAABhw"]
[Sun Aug 30 03:09:15.228250 2026] [security2:error] [pid 510357:tid 510531] [client 20.151.8.82:16587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "apPlK35YTqJxoOZUSXtO6gAABd8"]
[Sun Aug 30 03:09:15.243022 2026] [security2:error] [pid 510357:tid 510515] [client 20.48.251.3:59364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/btx25.php"] [unique_id "apPlK35YTqJxoOZUSXtO7QAABc8"]
[Sun Aug 30 03:09:15.250458 2026] [security2:error] [pid 510357:tid 510539] [client 20.104.49.130:53588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/xwpg.php"] [unique_id "apPlK35YTqJxoOZUSXtO8AAABec"]
[Sun Aug 30 03:09:15.256951 2026] [security2:error] [pid 510357:tid 510569] [client 68.155.159.216:54301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apPlK35YTqJxoOZUSXtO8gAABgU"]
[Sun Aug 30 03:09:15.258753 2026] [security2:error] [pid 510357:tid 510523] [client 34.100.204.203:52686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/queue/.env"] [unique_id "apPlK35YTqJxoOZUSXtO8wAABdc"]
[Sun Aug 30 03:09:15.270036 2026] [security2:error] [pid 510357:tid 510571] [client 20.104.49.130:36769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/images.php"] [unique_id "apPlK35YTqJxoOZUSXtO9gAABgc"]
[Sun Aug 30 03:09:15.278999 2026] [security2:error] [pid 510357:tid 510491] [client 20.104.50.220:52853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/syad.php"] [unique_id "apPlK35YTqJxoOZUSXtO9wAABbc"]
[Sun Aug 30 03:09:15.361969 2026] [security2:error] [pid 510357:tid 510500] [client 20.151.8.82:16703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPlK35YTqJxoOZUSXtPBAAABcA"]
[Sun Aug 30 03:09:15.431573 2026] [security2:error] [pid 510357:tid 510605] [client 20.104.50.220:63027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/4x4.php"] [unique_id "apPlK35YTqJxoOZUSXtPDAAABik"]
[Sun Aug 30 03:09:15.434263 2026] [security2:error] [pid 510357:tid 510540] [client 20.48.251.3:33319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/php_info.php"] [unique_id "apPlK35YTqJxoOZUSXtPDQAABeg"]
[Sun Aug 30 03:09:15.436891 2026] [security2:error] [pid 510357:tid 510568] [client 20.151.200.44:45966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/admin.php/heex.php"] [unique_id "apPlK35YTqJxoOZUSXtPEAAABgQ"]
[Sun Aug 30 03:09:15.454022 2026] [security2:error] [pid 510357:tid 510603] [client 158.158.54.35:24678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/zwso.php"] [unique_id "apPlK35YTqJxoOZUSXtPGgAABic"]
[Sun Aug 30 03:09:15.491273 2026] [security2:error] [pid 510357:tid 510535] [client 20.151.8.82:16711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "apPlK35YTqJxoOZUSXtPKgAABeM"]
[Sun Aug 30 03:09:15.498278 2026] [security2:error] [pid 510357:tid 510539] [client 20.151.8.82:27593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlK35YTqJxoOZUSXtPKwAABec"]
[Sun Aug 30 03:09:15.499571 2026] [security2:error] [pid 510357:tid 510549] [client 34.100.204.203:52686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/worker/.env"] [unique_id "apPlK35YTqJxoOZUSXtPLAAABfE"]
[Sun Aug 30 03:09:15.502635 2026] [security2:error] [pid 510357:tid 510523] [client 20.104.50.220:32850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/up.php5"] [unique_id "apPlK35YTqJxoOZUSXtPLgAABdc"]
[Sun Aug 30 03:09:15.514915 2026] [authz_core:error] [pid 510357:tid 510594] [client 66.249.66.75:62431] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:15.515195 2026] [authz_core:error] [pid 510357:tid 510594] [client 66.249.66.75:62431] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:15.533565 2026] [security2:error] [pid 510357:tid 510533] [client 20.104.49.130:63277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/albin.php"] [unique_id "apPlK35YTqJxoOZUSXtPNwAABeE"]
[Sun Aug 30 03:09:15.544675 2026] [security2:error] [pid 510357:tid 510537] [client 20.104.50.220:59387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/asdf.php"] [unique_id "apPlK35YTqJxoOZUSXtPOgAABeU"]
[Sun Aug 30 03:09:15.549472 2026] [security2:error] [pid 510357:tid 510585] [client 20.104.49.130:60647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/kerang.php"] [unique_id "apPlK35YTqJxoOZUSXtPPgAABhU"]
[Sun Aug 30 03:09:15.553244 2026] [security2:error] [pid 510357:tid 510516] [client 20.104.50.220:32419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/aaa.php"] [unique_id "apPlK35YTqJxoOZUSXtPPwAABdA"]
[Sun Aug 30 03:09:15.593361 2026] [security2:error] [pid 510357:tid 510504] [client 4.205.62.107:25739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/paths.php"] [unique_id "apPlK35YTqJxoOZUSXtPRQAABcQ"]
[Sun Aug 30 03:09:15.621182 2026] [security2:error] [pid 510357:tid 510550] [client 4.205.62.107:17298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/guk.php"] [unique_id "apPlK35YTqJxoOZUSXtPSwAABfI"]
[Sun Aug 30 03:09:15.629888 2026] [authz_core:error] [pid 510357:tid 510600] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:15.629908 2026] [security2:error] [pid 510357:tid 510611] [client 20.151.8.82:27591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlK35YTqJxoOZUSXtPTwAABi8"]
[Sun Aug 30 03:09:15.630165 2026] [authz_core:error] [pid 510357:tid 510600] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:15.643123 2026] [security2:error] [pid 510357:tid 510577] [client 20.151.8.82:16659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "apPlK35YTqJxoOZUSXtPUQAABg0"]
[Sun Aug 30 03:09:15.673814 2026] [security2:error] [pid 510357:tid 510528] [client 20.104.49.130:47979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/classwithtostring.php"] [unique_id "apPlK35YTqJxoOZUSXtPVgAABdw"]
[Sun Aug 30 03:09:15.741168 2026] [security2:error] [pid 510357:tid 510532] [client 34.100.204.203:52686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/job/.env"] [unique_id "apPlK35YTqJxoOZUSXtPYwAABeA"]
[Sun Aug 30 03:09:15.746631 2026] [security2:error] [pid 510357:tid 510525] [client 74.248.24.12:2085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/aleXus.php"] [unique_id "apPlK35YTqJxoOZUSXtPZAAABdk"]
[Sun Aug 30 03:09:15.753790 2026] [authz_core:error] [pid 510357:tid 510593] [client 66.249.66.69:40947] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:15.754064 2026] [authz_core:error] [pid 510357:tid 510593] [client 66.249.66.69:40947] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:15.762112 2026] [security2:error] [pid 510357:tid 510503] [client 20.151.8.82:27630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/nail.php"] [unique_id "apPlK35YTqJxoOZUSXtPZgAABcM"]
[Sun Aug 30 03:09:15.766352 2026] [security2:error] [pid 510357:tid 510592] [client 68.155.159.216:54485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/worksec.php"] [unique_id "apPlK35YTqJxoOZUSXtPZwAABhw"]
[Sun Aug 30 03:09:15.773571 2026] [security2:error] [pid 510357:tid 510542] [client 20.151.8.82:16580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "apPlK35YTqJxoOZUSXtPaQAABeo"]
[Sun Aug 30 03:09:15.786000 2026] [security2:error] [pid 510357:tid 510588] [client 4.205.62.107:58262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/koiy.php"] [unique_id "apPlK35YTqJxoOZUSXtPawAABhg"]
[Sun Aug 30 03:09:15.838635 2026] [security2:error] [pid 510357:tid 510537] [client 20.104.50.220:47088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/ioxi-o.php"] [unique_id "apPlK35YTqJxoOZUSXtPeQAABeU"]
[Sun Aug 30 03:09:15.878861 2026] [security2:error] [pid 510357:tid 510499] [client 20.104.18.15:35045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/133.php"] [unique_id "apPlK35YTqJxoOZUSXtPewAABb8"]
[Sun Aug 30 03:09:15.885754 2026] [authz_core:error] [pid 510357:tid 510508] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:15.886032 2026] [authz_core:error] [pid 510357:tid 510508] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:15.899068 2026] [security2:error] [pid 510357:tid 510543] [client 20.104.18.15:1880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/wefile.php"] [unique_id "apPlK35YTqJxoOZUSXtPgwAABes"]
[Sun Aug 30 03:09:15.903687 2026] [security2:error] [pid 510357:tid 510504] [client 20.151.8.82:27625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/or.php"] [unique_id "apPlK35YTqJxoOZUSXtPhgAABcQ"]
[Sun Aug 30 03:09:15.908315 2026] [security2:error] [pid 510357:tid 510604] [client 20.151.8.82:16684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/media.php"] [unique_id "apPlK35YTqJxoOZUSXtPhwAABig"]
[Sun Aug 30 03:09:15.955058 2026] [security2:error] [pid 510357:tid 510492] [client 20.151.200.44:46071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/tf.php"] [unique_id "apPlK35YTqJxoOZUSXtPjwAABbg"]
[Sun Aug 30 03:09:16.003076 2026] [security2:error] [pid 510357:tid 510512] [client 158.158.54.35:21232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/backup.php"] [unique_id "apPlLH5YTqJxoOZUSXtPngAABcw"]
[Sun Aug 30 03:09:16.033086 2026] [security2:error] [pid 510357:tid 510598] [client 20.151.8.82:27626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/verox.php"] [unique_id "apPlLH5YTqJxoOZUSXtPpAAABiI"]
[Sun Aug 30 03:09:16.035732 2026] [security2:error] [pid 510357:tid 510547] [client 34.100.204.203:52686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/test/.env"] [unique_id "apPlLH5YTqJxoOZUSXtPpQAABe8"]
[Sun Aug 30 03:09:16.039766 2026] [security2:error] [pid 510357:tid 510532] [client 20.151.8.82:16757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/inso.php"] [unique_id "apPlLH5YTqJxoOZUSXtPpwAABeA"]
[Sun Aug 30 03:09:16.043863 2026] [security2:error] [pid 510357:tid 510556] [client 20.48.251.3:59880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/aws_credentials.php"] [unique_id "apPlLH5YTqJxoOZUSXtPqQAABfg"]
[Sun Aug 30 03:09:16.059319 2026] [security2:error] [pid 510357:tid 510515] [client 20.104.49.130:54166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/ano.php"] [unique_id "apPlLH5YTqJxoOZUSXtPrAAABc8"]
[Sun Aug 30 03:09:16.063689 2026] [security2:error] [pid 510357:tid 510563] [client 20.104.50.220:5597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/footer.php"] [unique_id "apPlLH5YTqJxoOZUSXtPrgAABf8"]
[Sun Aug 30 03:09:16.069379 2026] [authz_core:error] [pid 510357:tid 510406] [remote 216.73.217.178:59557] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:16.069826 2026] [authz_core:error] [pid 510357:tid 510406] [remote 216.73.217.178:59557] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:16.093060 2026] [security2:error] [pid 510357:tid 510569] [client 20.104.18.15:34608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/xmini4.php"] [unique_id "apPlLH5YTqJxoOZUSXtPtQAABgU"]
[Sun Aug 30 03:09:16.137467 2026] [authz_core:error] [pid 510357:tid 510538] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:16.137749 2026] [authz_core:error] [pid 510357:tid 510538] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:16.158272 2026] [security2:error] [pid 510357:tid 510604] [client 20.104.18.15:18263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/v22.php"] [unique_id "apPlLH5YTqJxoOZUSXtPwgAABig"]
[Sun Aug 30 03:09:16.166551 2026] [security2:error] [pid 510357:tid 510550] [client 68.155.159.216:46038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/classwithtostring.php"] [unique_id "apPlLH5YTqJxoOZUSXtPxAAABfI"]
[Sun Aug 30 03:09:16.166817 2026] [security2:error] [pid 510357:tid 510506] [client 20.151.8.82:27552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/ba.php"] [unique_id "apPlLH5YTqJxoOZUSXtPwwAABcY"]
[Sun Aug 30 03:09:16.167343 2026] [security2:error] [pid 510357:tid 510597] [client 20.151.8.82:16691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/shiny.php"] [unique_id "apPlLH5YTqJxoOZUSXtPxQAABiE"]
[Sun Aug 30 03:09:16.212687 2026] [security2:error] [pid 510357:tid 510495] [client 20.104.50.220:16734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/ddd.php"] [unique_id "apPlLH5YTqJxoOZUSXtPyAAABbs"]
[Sun Aug 30 03:09:16.261183 2026] [security2:error] [pid 510357:tid 510583] [client 74.248.24.12:22422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/cJLGqzB.php"] [unique_id "apPlLH5YTqJxoOZUSXtPzwAABhM"]
[Sun Aug 30 03:09:16.297115 2026] [security2:error] [pid 510357:tid 510570] [client 20.151.8.82:27539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/G.php"] [unique_id "apPlLH5YTqJxoOZUSXtP1AAABgY"]
[Sun Aug 30 03:09:16.312999 2026] [security2:error] [pid 510357:tid 510574] [client 20.151.8.82:16618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/403dd.php"] [unique_id "apPlLH5YTqJxoOZUSXtP2wAABgo"]
[Sun Aug 30 03:09:16.327297 2026] [security2:error] [pid 510357:tid 510578] [client 34.100.204.203:52686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/qa/.env"] [unique_id "apPlLH5YTqJxoOZUSXtP3QAABg4"]
[Sun Aug 30 03:09:16.350167 2026] [security2:error] [pid 510357:tid 510613] [client 20.104.50.220:51546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/up1.php"] [unique_id "apPlLH5YTqJxoOZUSXtP4gAABjE"]
[Sun Aug 30 03:09:16.351146 2026] [security2:error] [pid 510357:tid 510515] [client 20.104.18.15:43850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/ffs.php"] [unique_id "apPlLH5YTqJxoOZUSXtP4wAABc8"]
[Sun Aug 30 03:09:16.366635 2026] [security2:error] [pid 510357:tid 510544] [client 20.104.50.220:63045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-admin/priv8.php"] [unique_id "apPlLH5YTqJxoOZUSXtP5AAABew"]
[Sun Aug 30 03:09:16.377080 2026] [security2:error] [pid 510357:tid 510559] [client 20.48.251.3:59290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/app_dev.php"] [unique_id "apPlLH5YTqJxoOZUSXtP5QAABfs"]
[Sun Aug 30 03:09:16.424176 2026] [security2:error] [pid 510357:tid 510533] [client 20.151.8.82:27600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/great.php"] [unique_id "apPlLH5YTqJxoOZUSXtP8AAABeE"]
[Sun Aug 30 03:09:16.432587 2026] [security2:error] [pid 510357:tid 510541] [client 20.104.50.220:29166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/success.php"] [unique_id "apPlLH5YTqJxoOZUSXtP8QAABek"]
[Sun Aug 30 03:09:16.457988 2026] [security2:error] [pid 510357:tid 510615] [client 20.151.8.82:16762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/baba.php"] [unique_id "apPlLH5YTqJxoOZUSXtP_QAABjM"]
[Sun Aug 30 03:09:16.514583 2026] [authz_core:error] [pid 510357:tid 510504] [client 66.249.66.192:40565] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:16.514860 2026] [authz_core:error] [pid 510357:tid 510504] [client 66.249.66.192:40565] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:16.560737 2026] [security2:error] [pid 510357:tid 510611] [client 20.151.8.82:27637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/dyt8mjxc3yofbkoriukvgjaCdefault.php"] [unique_id "apPlLH5YTqJxoOZUSXtQHAAABi8"]
[Sun Aug 30 03:09:16.567052 2026] [security2:error] [pid 510357:tid 510588] [client 20.104.50.220:61380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/73.php"] [unique_id "apPlLH5YTqJxoOZUSXtQHgAABhg"]
[Sun Aug 30 03:09:16.572029 2026] [security2:error] [pid 510357:tid 510569] [client 20.48.251.3:13416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/session.php"] [unique_id "apPlLH5YTqJxoOZUSXtQIQAABgU"]
[Sun Aug 30 03:09:16.576834 2026] [authz_core:error] [pid 510357:tid 510589] [client 216.73.216.128:62586] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:16.577356 2026] [authz_core:error] [pid 510357:tid 510589] [client 216.73.216.128:62586] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:16.584001 2026] [security2:error] [pid 510357:tid 510581] [client 34.100.204.203:52686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/preview/.env"] [unique_id "apPlLH5YTqJxoOZUSXtQIwAABhE"]
[Sun Aug 30 03:09:16.593614 2026] [security2:error] [pid 510357:tid 510565] [client 20.151.8.82:16674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/site.php"] [unique_id "apPlLH5YTqJxoOZUSXtQJAAABgE"]
[Sun Aug 30 03:09:16.613376 2026] [security2:error] [pid 510357:tid 510604] [client 158.158.54.35:4699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/disagrsod.php"] [unique_id "apPlLH5YTqJxoOZUSXtQKAAABig"]
[Sun Aug 30 03:09:16.613775 2026] [authz_core:error] [pid 510357:tid 510543] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:16.614041 2026] [authz_core:error] [pid 510357:tid 510543] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:16.625046 2026] [security2:error] [pid 510357:tid 510534] [client 20.104.49.130:36755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/mac.php"] [unique_id "apPlLH5YTqJxoOZUSXtQLgAABeI"]
[Sun Aug 30 03:09:16.645493 2026] [security2:error] [pid 510357:tid 510502] [client 20.104.50.220:33182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/shell.php5"] [unique_id "apPlLH5YTqJxoOZUSXtQMgAABcI"]
[Sun Aug 30 03:09:16.661402 2026] [security2:error] [pid 510357:tid 510610] [client 216.73.216.128:2010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mysqlupgrade"] [unique_id "apPlLH5YTqJxoOZUSXtQNQAABi4"]
[Sun Aug 30 03:09:16.684055 2026] [security2:error] [pid 510357:tid 510499] [client 20.104.50.220:59373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/red.php"] [unique_id "apPlLH5YTqJxoOZUSXtQOQAABb8"]
[Sun Aug 30 03:09:16.693981 2026] [security2:error] [pid 510357:tid 510521] [client 20.151.8.82:27554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/robots.php"] [unique_id "apPlLH5YTqJxoOZUSXtQOgAABdU"]
[Sun Aug 30 03:09:16.713616 2026] [security2:error] [pid 510357:tid 510593] [client 20.151.200.44:41981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlLH5YTqJxoOZUSXtQQgAABh0"]
[Sun Aug 30 03:09:16.717665 2026] [security2:error] [pid 510357:tid 510540] [client 20.104.50.220:32564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/vee.php"] [unique_id "apPlLH5YTqJxoOZUSXtQQwAABeg"]
[Sun Aug 30 03:09:16.732962 2026] [security2:error] [pid 510357:tid 510612] [client 4.205.62.107:25764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/olfclass.php"] [unique_id "apPlLH5YTqJxoOZUSXtQRQAABjA"]
[Sun Aug 30 03:09:16.738117 2026] [security2:error] [pid 510357:tid 510531] [client 20.151.8.82:16693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/cabs.php"] [unique_id "apPlLH5YTqJxoOZUSXtQRgAABd8"]
[Sun Aug 30 03:09:16.759530 2026] [security2:error] [pid 510357:tid 510551] [client 4.205.62.107:17095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/config_dev.php"] [unique_id "apPlLH5YTqJxoOZUSXtQSwAABfM"]
[Sun Aug 30 03:09:16.795013 2026] [security2:error] [pid 510357:tid 510527] [client 20.151.200.44:46021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/update/da222.php"] [unique_id "apPlLH5YTqJxoOZUSXtQTgAABds"]
[Sun Aug 30 03:09:16.812279 2026] [security2:error] [pid 510357:tid 510597] [client 74.248.24.12:11344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/inc.php"] [unique_id "apPlLH5YTqJxoOZUSXtQVQAABiE"]
[Sun Aug 30 03:09:16.825657 2026] [security2:error] [pid 510357:tid 510602] [client 20.151.8.82:27520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/sky.php"] [unique_id "apPlLH5YTqJxoOZUSXtQWAAABiY"]
[Sun Aug 30 03:09:16.853404 2026] [security2:error] [pid 510357:tid 510584] [client 195.178.110.247:2562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.megmoseley.com"] [uri "/index.php"] [unique_id "apPlLH5YTqJxoOZUSXtQWgAABhQ"]
[Sun Aug 30 03:09:16.869880 2026] [security2:error] [pid 510357:tid 510565] [client 20.151.8.82:16673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/insc.php"] [unique_id "apPlLH5YTqJxoOZUSXtQWwAABgE"]
[Sun Aug 30 03:09:16.882073 2026] [security2:error] [pid 510357:tid 510607] [client 34.100.204.203:52686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/beta/.env"] [unique_id "apPlLH5YTqJxoOZUSXtQXQAABis"]
[Sun Aug 30 03:09:16.882550 2026] [security2:error] [pid 510357:tid 510533] [client 68.155.159.216:54464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/x.php"] [unique_id "apPlLH5YTqJxoOZUSXtQXwAABeE"]
[Sun Aug 30 03:09:16.927083 2026] [security2:error] [pid 510357:tid 510610] [client 4.205.62.107:64668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/queue.php"] [unique_id "apPlLH5YTqJxoOZUSXtQaQAABi4"]
[Sun Aug 30 03:09:16.939719 2026] [authz_core:error] [pid 510357:tid 510492] [client 216.73.216.128:41351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:16.939998 2026] [authz_core:error] [pid 510357:tid 510492] [client 216.73.216.128:41351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:16.956995 2026] [security2:error] [pid 510357:tid 510599] [client 20.151.8.82:27615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/sixxis.php"] [unique_id "apPlLH5YTqJxoOZUSXtQbAAABiM"]
[Sun Aug 30 03:09:16.969104 2026] [security2:error] [pid 510357:tid 510528] [client 20.104.50.220:47083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/classwithtostring.php"] [unique_id "apPlLH5YTqJxoOZUSXtQcQAABdw"]
[Sun Aug 30 03:09:16.969250 2026] [authz_core:error] [pid 510357:tid 510575] [client 66.249.66.45:60463] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:16.969561 2026] [authz_core:error] [pid 510357:tid 510575] [client 66.249.66.45:60463] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:16.985888 2026] [security2:error] [pid 510357:tid 510582] [client 20.48.250.41:45045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlLH5YTqJxoOZUSXtQeAAABhI"]
[Sun Aug 30 03:09:17.011982 2026] [security2:error] [pid 510357:tid 510551] [client 20.151.8.82:16596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/file.php"] [unique_id "apPlLX5YTqJxoOZUSXtQgQAABfM"]
[Sun Aug 30 03:09:17.017872 2026] [security2:error] [pid 510357:tid 510581] [client 195.178.110.247:62482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.megmoseley.com"] [uri "/index.php"] [unique_id "apPlLX5YTqJxoOZUSXtQgwAABhE"]
[Sun Aug 30 03:09:17.023356 2026] [security2:error] [pid 510357:tid 510525] [client 20.104.18.15:35504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/sym.php"] [unique_id "apPlLX5YTqJxoOZUSXtQhQAABdk"]
[Sun Aug 30 03:09:17.029828 2026] [security2:error] [pid 510357:tid 510559] [client 20.104.49.130:43277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlLX5YTqJxoOZUSXtQhwAABfs"]
[Sun Aug 30 03:09:17.037935 2026] [security2:error] [pid 510357:tid 510494] [client 20.104.18.15:1869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/blog.php"] [unique_id "apPlLX5YTqJxoOZUSXtQiQAABbo"]
[Sun Aug 30 03:09:17.054024 2026] [security2:error] [pid 510357:tid 510617] [client 20.104.49.130:43272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/ab.php"] [unique_id "apPlLX5YTqJxoOZUSXtQiwAABjU"]
[Sun Aug 30 03:09:17.089502 2026] [security2:error] [pid 510357:tid 510560] [client 20.151.8.82:27587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/yj09.php"] [unique_id "apPlLX5YTqJxoOZUSXtQkwAABfw"]
[Sun Aug 30 03:09:17.104696 2026] [authz_core:error] [pid 510357:tid 510555] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:17.104965 2026] [authz_core:error] [pid 510357:tid 510555] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:17.121451 2026] [authz_core:error] [pid 510357:tid 510496] [client 216.73.216.128:41351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:17.121755 2026] [authz_core:error] [pid 510357:tid 510496] [client 216.73.216.128:41351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:17.144362 2026] [security2:error] [pid 510357:tid 510576] [client 20.48.250.41:45033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlLX5YTqJxoOZUSXtQnQAABgw"]
[Sun Aug 30 03:09:17.146982 2026] [security2:error] [pid 510357:tid 510558] [client 20.151.8.82:16586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/dex.php"] [unique_id "apPlLX5YTqJxoOZUSXtQngAABfo"]
[Sun Aug 30 03:09:17.148519 2026] [authz_core:error] [pid 510357:tid 510587] [client 66.249.66.45:42227] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:17.148784 2026] [authz_core:error] [pid 510357:tid 510587] [client 66.249.66.45:42227] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:17.152742 2026] [security2:error] [pid 510357:tid 510612] [client 158.158.54.35:24680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/1p.php"] [unique_id "apPlLX5YTqJxoOZUSXtQoQAABjA"]
[Sun Aug 30 03:09:17.173309 2026] [security2:error] [pid 510357:tid 510493] [client 20.104.49.130:53846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/simple.php"] [unique_id "apPlLX5YTqJxoOZUSXtQogAABbk"]
[Sun Aug 30 03:09:17.184972 2026] [security2:error] [pid 510357:tid 510545] [client 34.100.204.203:52686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/uat/.env"] [unique_id "apPlLX5YTqJxoOZUSXtQowAABe0"]
[Sun Aug 30 03:09:17.202122 2026] [security2:error] [pid 510357:tid 510608] [client 20.104.50.220:5495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/mouse.php"] [unique_id "apPlLX5YTqJxoOZUSXtQqQAABiw"]
[Sun Aug 30 03:09:17.220865 2026] [security2:error] [pid 510357:tid 510520] [client 20.151.8.82:27532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/k.php"] [unique_id "apPlLX5YTqJxoOZUSXtQrQAABdQ"]
[Sun Aug 30 03:09:17.225959 2026] [security2:error] [pid 510357:tid 510614] [client 20.48.251.3:59464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/aws-credentials.php"] [unique_id "apPlLX5YTqJxoOZUSXtQrwAABjI"]
[Sun Aug 30 03:09:17.233511 2026] [security2:error] [pid 510357:tid 510501] [client 20.104.18.15:34790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/gulu.php"] [unique_id "apPlLX5YTqJxoOZUSXtQsAAABcE"]
[Sun Aug 30 03:09:17.284793 2026] [security2:error] [pid 510357:tid 510503] [client 20.48.250.41:45028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/ff1.php"] [unique_id "apPlLX5YTqJxoOZUSXtQugAABcM"]
[Sun Aug 30 03:09:17.289068 2026] [security2:error] [pid 510357:tid 510559] [client 20.151.8.82:16652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/key.php"] [unique_id "apPlLX5YTqJxoOZUSXtQvAAABfs"]
[Sun Aug 30 03:09:17.296727 2026] [authz_core:error] [pid 510357:tid 510597] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:17.297000 2026] [authz_core:error] [pid 510357:tid 510597] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:17.306573 2026] [security2:error] [pid 510357:tid 510563] [client 20.104.18.15:18430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/wp-activate.php"] [unique_id "apPlLX5YTqJxoOZUSXtQxQAABf8"]
[Sun Aug 30 03:09:17.364464 2026] [security2:error] [pid 510357:tid 510615] [client 20.104.49.130:57695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/666.php"] [unique_id "apPlLX5YTqJxoOZUSXtQ0AAABjM"]
[Sun Aug 30 03:09:17.364512 2026] [security2:error] [pid 510357:tid 510584] [client 4.205.62.107:35992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/loxi-o.php"] [unique_id "apPlLX5YTqJxoOZUSXtQ0QAABhQ"]
[Sun Aug 30 03:09:17.366755 2026] [security2:error] [pid 510357:tid 510601] [client 20.151.8.82:27525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/w.php"] [unique_id "apPlLX5YTqJxoOZUSXtQ0gAABiU"]
[Sun Aug 30 03:09:17.422320 2026] [security2:error] [pid 510357:tid 510516] [client 20.151.8.82:16582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/kir.php"] [unique_id "apPlLX5YTqJxoOZUSXtQ2gAABdA"]
[Sun Aug 30 03:09:17.425114 2026] [security2:error] [pid 510357:tid 510548] [client 20.104.50.220:16745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/waf.php"] [unique_id "apPlLX5YTqJxoOZUSXtQ2wAABfA"]
[Sun Aug 30 03:09:17.427245 2026] [security2:error] [pid 510357:tid 510610] [client 34.100.204.203:52686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/stage/.env"] [unique_id "apPlLX5YTqJxoOZUSXtQ3AAABi4"]
[Sun Aug 30 03:09:17.429826 2026] [security2:error] [pid 510357:tid 510517] [client 20.48.250.41:44947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/t.php"] [unique_id "apPlLX5YTqJxoOZUSXtQ3QAABdE"]
[Sun Aug 30 03:09:17.445895 2026] [security2:error] [pid 510357:tid 510543] [client 74.248.24.12:11390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/aged.php"] [unique_id "apPlLX5YTqJxoOZUSXtQ5AAABes"]
[Sun Aug 30 03:09:17.483096 2026] [security2:error] [pid 510357:tid 510596] [client 20.104.50.220:42765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/haha.php"] [unique_id "apPlLX5YTqJxoOZUSXtQ8wAABiA"]
[Sun Aug 30 03:09:17.507455 2026] [security2:error] [pid 510357:tid 510494] [client 20.104.50.220:62809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/403.php"] [unique_id "apPlLX5YTqJxoOZUSXtQ-wAABbo"]
[Sun Aug 30 03:09:17.516013 2026] [security2:error] [pid 510357:tid 510525] [client 20.48.251.3:59381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/php-info.php"] [unique_id "apPlLX5YTqJxoOZUSXtQ_wAABdk"]
[Sun Aug 30 03:09:17.520092 2026] [security2:error] [pid 510357:tid 510617] [client 20.151.8.82:27639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/FWAZ.php"] [unique_id "apPlLX5YTqJxoOZUSXtRAgAABjU"]
[Sun Aug 30 03:09:17.521928 2026] [security2:error] [pid 510357:tid 510618] [client 20.104.18.15:43981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/nano.php"] [unique_id "apPlLX5YTqJxoOZUSXtRBAAABjY"]
[Sun Aug 30 03:09:17.523892 2026] [security2:error] [pid 510357:tid 510505] [client 194.126.252.241:56362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.252.126.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "belloinsights.com"] [uri "/wp-login.php"] [unique_id "apPlLX5YTqJxoOZUSXtQ_AAABcU"]
[Sun Aug 30 03:09:17.555287 2026] [security2:error] [pid 510357:tid 510565] [client 20.151.8.82:16741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/nofile.php"] [unique_id "apPlLX5YTqJxoOZUSXtRDQAABgE"]
[Sun Aug 30 03:09:17.582597 2026] [security2:error] [pid 510357:tid 510526] [client 20.104.50.220:29183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/swm@asd365.php"] [unique_id "apPlLX5YTqJxoOZUSXtREQAABdo"]
[Sun Aug 30 03:09:17.583576 2026] [security2:error] [pid 510357:tid 510514] [client 20.48.250.41:45041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/erty.php"] [unique_id "apPlLX5YTqJxoOZUSXtREgAABc4"]
[Sun Aug 30 03:09:17.587597 2026] [authz_core:error] [pid 510357:tid 510572] [client 66.249.66.65:54764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:17.587892 2026] [authz_core:error] [pid 510357:tid 510572] [client 66.249.66.65:54764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:17.600760 2026] [authz_core:error] [pid 510357:tid 510497] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:17.601042 2026] [authz_core:error] [pid 510357:tid 510497] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:17.652581 2026] [security2:error] [pid 510357:tid 510493] [client 20.151.8.82:27597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/blurbs.php"] [unique_id "apPlLX5YTqJxoOZUSXtRHAAABbk"]
[Sun Aug 30 03:09:17.669082 2026] [security2:error] [pid 510357:tid 510557] [client 34.100.204.203:52686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/development/.env"] [unique_id "apPlLX5YTqJxoOZUSXtRIAAABfk"]
[Sun Aug 30 03:09:17.701490 2026] [security2:error] [pid 510357:tid 510606] [client 43.153.96.233:34542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.96.153.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ltr7.com"] [uri "/"] [unique_id "apPlLX5YTqJxoOZUSXtRJAAABio"]
[Sun Aug 30 03:09:17.702022 2026] [security2:error] [pid 510357:tid 510603] [client 20.151.8.82:16704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/fling.php"] [unique_id "apPlLX5YTqJxoOZUSXtRKAAABic"]
[Sun Aug 30 03:09:17.702969 2026] [security2:error] [pid 510357:tid 510508] [client 20.104.50.220:61688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/al.php"] [unique_id "apPlLX5YTqJxoOZUSXtRKQAABcg"]
[Sun Aug 30 03:09:17.708848 2026] [security2:error] [pid 510357:tid 510561] [client 20.48.250.41:26563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlLX5YTqJxoOZUSXtRLAAABf0"]
[Sun Aug 30 03:09:17.720837 2026] [security2:error] [pid 510357:tid 510595] [client 20.48.251.3:13380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/h.php"] [unique_id "apPlLX5YTqJxoOZUSXtRLwAABh8"]
[Sun Aug 30 03:09:17.735717 2026] [security2:error] [pid 510357:tid 510575] [client 20.48.250.41:45010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/0x.php"] [unique_id "apPlLX5YTqJxoOZUSXtRMAAABgs"]
[Sun Aug 30 03:09:17.753823 2026] [security2:error] [pid 510357:tid 510535] [client 158.158.54.35:35250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/Auth.php"] [unique_id "apPlLX5YTqJxoOZUSXtRMgAABeM"]
[Sun Aug 30 03:09:17.768062 2026] [security2:error] [pid 510357:tid 510509] [client 20.151.200.44:46073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/qi.php"] [unique_id "apPlLX5YTqJxoOZUSXtRMwAABck"]
[Sun Aug 30 03:09:17.775635 2026] [security2:error] [pid 510357:tid 510553] [client 68.155.159.216:54276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apPlLX5YTqJxoOZUSXtRNAAABfU"]
[Sun Aug 30 03:09:17.786496 2026] [security2:error] [pid 510357:tid 510525] [client 20.151.8.82:27526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/100.php"] [unique_id "apPlLX5YTqJxoOZUSXtRNQAABdk"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:17.794866 2026] [security2:error] [pid 510357:tid 510539] [client 20.104.50.220:32872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/inc/config.php"] [unique_id "apPlLX5YTqJxoOZUSXtROQAABec"]
[Sun Aug 30 03:09:17.804257 2026] [security2:error] [pid 510357:tid 510564] [client 216.73.216.128:35702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlLX5YTqJxoOZUSXtRQAAABgA"]
[Sun Aug 30 03:09:17.834284 2026] [security2:error] [pid 510357:tid 510526] [client 20.151.8.82:16584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/zoo1.php"] [unique_id "apPlLX5YTqJxoOZUSXtRRwAABdo"]
[Sun Aug 30 03:09:17.851781 2026] [authz_core:error] [pid 510357:tid 510587] [client 66.249.66.73:61247] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:17.852075 2026] [authz_core:error] [pid 510357:tid 510587] [client 66.249.66.73:61247] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:17.863067 2026] [security2:error] [pid 510357:tid 510607] [client 20.48.250.41:45034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/66.php"] [unique_id "apPlLX5YTqJxoOZUSXtRSwAABis"]
[Sun Aug 30 03:09:17.870431 2026] [security2:error] [pid 510357:tid 510534] [client 4.205.62.107:25860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/gnmlc.php"] [unique_id "apPlLX5YTqJxoOZUSXtRTAAABeI"]
[Sun Aug 30 03:09:17.898620 2026] [security2:error] [pid 510357:tid 510516] [client 4.205.62.107:17137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/aws_credentials.php"] [unique_id "apPlLX5YTqJxoOZUSXtRUgAABdA"]
[Sun Aug 30 03:09:17.915973 2026] [security2:error] [pid 510357:tid 510608] [client 34.100.204.203:52686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/production/.env"] [unique_id "apPlLX5YTqJxoOZUSXtRVQAABiw"]
[Sun Aug 30 03:09:17.921042 2026] [security2:error] [pid 510357:tid 510591] [client 20.151.8.82:27606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/ccc.php"] [unique_id "apPlLX5YTqJxoOZUSXtRWAAABhs"]
[Sun Aug 30 03:09:17.926902 2026] [security2:error] [pid 510357:tid 510555] [client 20.104.50.220:32522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/efile.php"] [unique_id "apPlLX5YTqJxoOZUSXtRWQAABfc"]
[Sun Aug 30 03:09:17.950849 2026] [security2:error] [pid 510357:tid 510508] [client 20.104.50.220:63230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "apPlLX5YTqJxoOZUSXtRXwAABcg"]
[Sun Aug 30 03:09:17.965127 2026] [security2:error] [pid 510357:tid 510548] [client 20.104.49.130:60673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/wp-login.php"] [unique_id "apPlLX5YTqJxoOZUSXtRVgAABfA"]
[Sun Aug 30 03:09:17.969347 2026] [security2:error] [pid 510357:tid 510520] [client 20.151.8.82:16610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/btyuio.php"] [unique_id "apPlLX5YTqJxoOZUSXtRZQAABdQ"]
[Sun Aug 30 03:09:17.976531 2026] [security2:error] [pid 510357:tid 510570] [client 20.104.49.130:63535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/load.php"] [unique_id "apPlLX5YTqJxoOZUSXtRaAAABgY"]
[Sun Aug 30 03:09:17.991591 2026] [security2:error] [pid 510357:tid 510615] [client 20.48.250.41:44997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/f35.php"] [unique_id "apPlLX5YTqJxoOZUSXtRbAAABjM"]
[Sun Aug 30 03:09:18.002337 2026] [security2:error] [pid 510357:tid 510504] [client 74.248.24.12:38121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/y.php"] [unique_id "apPlLn5YTqJxoOZUSXtRbwAABcQ"]
[Sun Aug 30 03:09:18.033496 2026] [security2:error] [pid 510357:tid 510569] [client 68.155.159.216:54245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-content/x.php"] [unique_id "apPlLn5YTqJxoOZUSXtRdQAABgU"]
[Sun Aug 30 03:09:18.040283 2026] [security2:error] [pid 510357:tid 510584] [client 20.48.250.41:26574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlLn5YTqJxoOZUSXtReAAABhQ"]
[Sun Aug 30 03:09:18.052934 2026] [security2:error] [pid 510357:tid 510616] [client 20.151.8.82:27528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/images.php"] [unique_id "apPlLn5YTqJxoOZUSXtRfgAABjQ"]
[Sun Aug 30 03:09:18.078148 2026] [security2:error] [pid 510357:tid 510604] [client 4.205.62.107:64660] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/wp-includes/js/tinymce/themes/inlite"] [unique_id "apPlLn5YTqJxoOZUSXtRggAABig"]
[Sun Aug 30 03:09:18.080375 2026] [security2:error] [pid 510357:tid 510607] [client 68.155.159.216:62601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlLn5YTqJxoOZUSXtRgwAABis"]
[Sun Aug 30 03:09:18.112162 2026] [security2:error] [pid 510357:tid 510543] [client 20.104.50.220:46862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "apPlLn5YTqJxoOZUSXtRhwAABes"]
[Sun Aug 30 03:09:18.114172 2026] [security2:error] [pid 510357:tid 510516] [client 20.151.8.82:16750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/00zip.php"] [unique_id "apPlLn5YTqJxoOZUSXtRiAAABdA"]
[Sun Aug 30 03:09:18.123216 2026] [security2:error] [pid 510357:tid 510513] [client 20.48.250.41:44940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/wen.php"] [unique_id "apPlLn5YTqJxoOZUSXtRiwAABc0"]
[Sun Aug 30 03:09:18.131037 2026] [security2:error] [pid 510357:tid 510608] [client 20.151.200.44:46078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/px.php"] [unique_id "apPlLn5YTqJxoOZUSXtRjAAABiw"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:18.165654 2026] [authz_core:error] [pid 510357:tid 510548] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:18.166100 2026] [authz_core:error] [pid 510357:tid 510548] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:18.171792 2026] [security2:error] [pid 510357:tid 510589] [client 68.155.159.216:46016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/install.php"] [unique_id "apPlLn5YTqJxoOZUSXtRlAAABhk"]
[Sun Aug 30 03:09:18.176223 2026] [security2:error] [pid 510357:tid 510570] [client 20.104.18.15:35503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/8.php"] [unique_id "apPlLn5YTqJxoOZUSXtRlQAABgY"]
[Sun Aug 30 03:09:18.179596 2026] [security2:error] [pid 510357:tid 510535] [client 34.100.204.203:52686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bitcoinforum.it"] [uri "/config/app/.env"] [unique_id "apPlLn5YTqJxoOZUSXtRlgAABeM"]
[Sun Aug 30 03:09:18.181590 2026] [security2:error] [pid 510357:tid 510615] [client 20.151.8.82:27610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/alls.php"] [unique_id "apPlLn5YTqJxoOZUSXtRlwAABjM"]
[Sun Aug 30 03:09:18.190001 2026] [security2:error] [pid 510357:tid 510556] [client 20.104.18.15:1860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/wp-load.php"] [unique_id "apPlLn5YTqJxoOZUSXtRmQAABfg"]
[Sun Aug 30 03:09:18.222713 2026] [security2:error] [pid 510357:tid 510494] [client 20.48.250.41:26575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/ff1.php"] [unique_id "apPlLn5YTqJxoOZUSXtRngAABbo"]
[Sun Aug 30 03:09:18.258784 2026] [security2:error] [pid 510357:tid 510569] [client 20.151.8.82:16735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/silver.php"] [unique_id "apPlLn5YTqJxoOZUSXtRpwAABgU"]
[Sun Aug 30 03:09:18.266280 2026] [security2:error] [pid 510357:tid 510584] [client 20.48.250.41:45016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/inc.php"] [unique_id "apPlLn5YTqJxoOZUSXtRqgAABhQ"]
[Sun Aug 30 03:09:18.305173 2026] [authz_core:error] [pid 510357:tid 510547] [client 66.249.66.39:53896] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:18.305440 2026] [authz_core:error] [pid 510357:tid 510547] [client 66.249.66.39:53896] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:18.306139 2026] [security2:error] [pid 510357:tid 510536] [client 158.158.54.35:29087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/special.php"] [unique_id "apPlLn5YTqJxoOZUSXtRtwAABeQ"]
[Sun Aug 30 03:09:18.309693 2026] [security2:error] [pid 510357:tid 510572] [client 20.151.8.82:27550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/coffexium.php"] [unique_id "apPlLn5YTqJxoOZUSXtRuQAABgg"]
[Sun Aug 30 03:09:18.347800 2026] [security2:error] [pid 510357:tid 510495] [client 20.104.50.220:5549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/hp.php"] [unique_id "apPlLn5YTqJxoOZUSXtRwQAABbs"]
[Sun Aug 30 03:09:18.370662 2026] [security2:error] [pid 510357:tid 510589] [client 20.48.250.41:26594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/t.php"] [unique_id "apPlLn5YTqJxoOZUSXtRxAAABhk"]
[Sun Aug 30 03:09:18.390627 2026] [security2:error] [pid 510357:tid 510615] [client 20.104.18.15:34686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/replace.php"] [unique_id "apPlLn5YTqJxoOZUSXtRxQAABjM"]
[Sun Aug 30 03:09:18.391793 2026] [security2:error] [pid 510357:tid 510503] [client 20.151.8.82:16635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/wp-mails.php"] [unique_id "apPlLn5YTqJxoOZUSXtRxwAABcM"]
[Sun Aug 30 03:09:18.398312 2026] [security2:error] [pid 510357:tid 510549] [client 20.48.250.41:45036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/6bcwiqwj.php"] [unique_id "apPlLn5YTqJxoOZUSXtRygAABfE"]
[Sun Aug 30 03:09:18.421683 2026] [security2:error] [pid 510357:tid 510554] [client 20.48.251.3:59475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/4563.php"] [unique_id "apPlLn5YTqJxoOZUSXtRzgAABfY"]
[Sun Aug 30 03:09:18.446014 2026] [security2:error] [pid 510357:tid 510606] [client 20.104.18.15:18272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/wp-trackback.php"] [unique_id "apPlLn5YTqJxoOZUSXtR2AAABio"]
[Sun Aug 30 03:09:18.448242 2026] [security2:error] [pid 510357:tid 510599] [client 20.151.8.82:27604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/red.php"] [unique_id "apPlLn5YTqJxoOZUSXtR2wAABiM"]
[Sun Aug 30 03:09:18.452939 2026] [security2:error] [pid 510357:tid 510539] [client 34.100.204.203:52686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/phpinfo.php"] [unique_id "apPlLn5YTqJxoOZUSXtR1gAABec"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:18.502890 2026] [security2:error] [pid 510357:tid 510540] [client 4.205.62.107:35972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/f35.php"] [unique_id "apPlLn5YTqJxoOZUSXtR7AAABeg"]
[Sun Aug 30 03:09:18.513047 2026] [security2:error] [pid 510357:tid 510610] [client 20.48.250.41:26620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/erty.php"] [unique_id "apPlLn5YTqJxoOZUSXtR8AAABi4"]
[Sun Aug 30 03:09:18.519991 2026] [security2:error] [pid 510357:tid 510526] [client 20.151.8.82:16588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/new.php"] [unique_id "apPlLn5YTqJxoOZUSXtR8gAABdo"]
[Sun Aug 30 03:09:18.528338 2026] [security2:error] [pid 510357:tid 510501] [client 74.248.24.12:15280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/delpaths.php"] [unique_id "apPlLn5YTqJxoOZUSXtR9QAABcE"]
[Sun Aug 30 03:09:18.535638 2026] [security2:error] [pid 510357:tid 510589] [client 20.48.250.41:44955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/easy.php"] [unique_id "apPlLn5YTqJxoOZUSXtR-AAABhk"]
[Sun Aug 30 03:09:18.553325 2026] [security2:error] [pid 510357:tid 510615] [client 20.104.49.130:63491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/82.php"] [unique_id "apPlLn5YTqJxoOZUSXtR_QAABjM"]
[Sun Aug 30 03:09:18.559964 2026] [security2:error] [pid 510357:tid 510504] [client 20.104.49.130:60935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/about.php"] [unique_id "apPlLn5YTqJxoOZUSXtSAQAABcQ"]
[Sun Aug 30 03:09:18.573368 2026] [security2:error] [pid 510357:tid 510603] [client 20.104.50.220:17291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/xstelth.php"] [unique_id "apPlLn5YTqJxoOZUSXtSAgAABic"]
[Sun Aug 30 03:09:18.578744 2026] [security2:error] [pid 510357:tid 510520] [client 20.151.8.82:27586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/admin.php"] [unique_id "apPlLn5YTqJxoOZUSXtSBQAABdQ"]
[Sun Aug 30 03:09:18.608241 2026] [authz_core:error] [pid 510357:tid 510611] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:18.608563 2026] [authz_core:error] [pid 510357:tid 510611] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:18.612564 2026] [security2:error] [pid 510357:tid 510601] [client 20.151.200.44:45977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/is.php"] [unique_id "apPlLn5YTqJxoOZUSXtSCAAABiU"]
[Sun Aug 30 03:09:18.621008 2026] [security2:error] [pid 510357:tid 510514] [client 20.104.50.220:51597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/sc.php"] [unique_id "apPlLn5YTqJxoOZUSXtSCwAABc4"]
[Sun Aug 30 03:09:18.647460 2026] [security2:error] [pid 510357:tid 510491] [client 20.104.50.220:28699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-includes/priv8.php"] [unique_id "apPlLn5YTqJxoOZUSXtSEQAABbc"]
[Sun Aug 30 03:09:18.652345 2026] [security2:error] [pid 510357:tid 510512] [client 20.48.251.3:55785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/infos.php"] [unique_id "apPlLn5YTqJxoOZUSXtSFAAABcw"]
[Sun Aug 30 03:09:18.657588 2026] [security2:error] [pid 510357:tid 510506] [client 20.48.250.41:26500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/0x.php"] [unique_id "apPlLn5YTqJxoOZUSXtSFQAABcY"]
[Sun Aug 30 03:09:18.661594 2026] [security2:error] [pid 510357:tid 510588] [client 20.48.250.41:45055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/fresh3.php"] [unique_id "apPlLn5YTqJxoOZUSXtSGAAABhg"]
[Sun Aug 30 03:09:18.666249 2026] [security2:error] [pid 510357:tid 510550] [client 20.151.8.82:16748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/run.php"] [unique_id "apPlLn5YTqJxoOZUSXtSGgAABfI"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:18.686558 2026] [authz_core:error] [pid 510357:tid 510513] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:18.686855 2026] [authz_core:error] [pid 510357:tid 510513] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:18.691409 2026] [security2:error] [pid 510357:tid 510614] [client 20.104.18.15:43285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/ano.php"] [unique_id "apPlLn5YTqJxoOZUSXtSIwAABjI"]
[Sun Aug 30 03:09:18.711937 2026] [security2:error] [pid 510357:tid 510612] [client 20.151.8.82:27608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/file52.php"] [unique_id "apPlLn5YTqJxoOZUSXtSKgAABjA"]
[Sun Aug 30 03:09:18.736383 2026] [security2:error] [pid 510357:tid 510615] [client 20.104.50.220:28704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/smtphec.php"] [unique_id "apPlLn5YTqJxoOZUSXtSLAAABjM"]
[Sun Aug 30 03:09:18.754447 2026] [authz_core:error] [pid 510357:tid 510565] [client 66.249.66.193:42796] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:18.754753 2026] [authz_core:error] [pid 510357:tid 510565] [client 66.249.66.193:42796] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:18.798283 2026] [security2:error] [pid 510357:tid 510520] [client 20.48.250.41:26601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/66.php"] [unique_id "apPlLn5YTqJxoOZUSXtSNAAABdQ"]
[Sun Aug 30 03:09:18.799938 2026] [security2:error] [pid 510357:tid 510505] [client 20.151.8.82:16600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/sm.php"] [unique_id "apPlLn5YTqJxoOZUSXtSOAAABcU"]
[Sun Aug 30 03:09:18.841969 2026] [security2:error] [pid 510357:tid 510510] [client 20.151.8.82:27634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/geck.php"] [unique_id "apPlLn5YTqJxoOZUSXtSQQAABco"]
[Sun Aug 30 03:09:18.852990 2026] [security2:error] [pid 510357:tid 510571] [client 20.104.50.220:61644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/alf.php"] [unique_id "apPlLn5YTqJxoOZUSXtSQgAABgc"]
[Sun Aug 30 03:09:18.854571 2026] [security2:error] [pid 510357:tid 510496] [client 158.158.54.35:30501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/wp_wol.php"] [unique_id "apPlLn5YTqJxoOZUSXtSQwAABbw"]
[Sun Aug 30 03:09:18.861160 2026] [security2:error] [pid 510357:tid 510609] [client 20.48.251.3:13407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/bootstrap.php"] [unique_id "apPlLn5YTqJxoOZUSXtSRQAABi0"]
[Sun Aug 30 03:09:18.862148 2026] [security2:error] [pid 510357:tid 510618] [client 20.48.250.41:44928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/bgymj.php"] [unique_id "apPlLn5YTqJxoOZUSXtSRgAABjY"]
[Sun Aug 30 03:09:18.864992 2026] [authz_core:error] [pid 510357:tid 510576] [client 216.73.216.128:41351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:18.865302 2026] [authz_core:error] [pid 510357:tid 510576] [client 216.73.216.128:41351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:18.885855 2026] [security2:error] [pid 510357:tid 510588] [client 20.151.200.44:46035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/od.php"] [unique_id "apPlLn5YTqJxoOZUSXtSSgAABhg"]
[Sun Aug 30 03:09:18.929329 2026] [security2:error] [pid 510357:tid 510562] [client 20.151.8.82:16687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/araso.php"] [unique_id "apPlLn5YTqJxoOZUSXtSVgAABf4"]
[Sun Aug 30 03:09:18.932754 2026] [security2:error] [pid 510357:tid 510526] [client 20.104.50.220:33156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/ix.php"] [unique_id "apPlLn5YTqJxoOZUSXtSVwAABdo"]
[Sun Aug 30 03:09:18.950427 2026] [security2:error] [pid 510357:tid 510578] [client 20.48.250.41:26496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/f35.php"] [unique_id "apPlLn5YTqJxoOZUSXtSXAAABg4"]
[Sun Aug 30 03:09:18.959560 2026] [authz_core:error] [pid 510357:tid 510523] [client 216.73.216.128:48844] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:18.960010 2026] [authz_core:error] [pid 510357:tid 510523] [client 216.73.216.128:48844] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:18.988554 2026] [security2:error] [pid 510357:tid 510508] [client 20.151.8.82:27523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/biufile.php"] [unique_id "apPlLn5YTqJxoOZUSXtSZAAABcg"]
[Sun Aug 30 03:09:19.015975 2026] [security2:error] [pid 510357:tid 510535] [client 20.48.250.41:45044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/ws69.php"] [unique_id "apPlL35YTqJxoOZUSXtSbQAABeM"]
[Sun Aug 30 03:09:19.036899 2026] [security2:error] [pid 510357:tid 510539] [client 4.205.62.107:17293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/aws-credentials.php"] [unique_id "apPlL35YTqJxoOZUSXtScgAABec"]
[Sun Aug 30 03:09:19.037261 2026] [security2:error] [pid 510357:tid 510583] [client 4.205.62.107:25907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/koiy.php"] [unique_id "apPlL35YTqJxoOZUSXtSdAAABhM"]
[Sun Aug 30 03:09:19.044661 2026] [security2:error] [pid 510357:tid 510587] [client 74.248.24.12:12782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/alfanew.php7"] [unique_id "apPlL35YTqJxoOZUSXtSeQAABhc"]
[Sun Aug 30 03:09:19.051486 2026] [authz_core:error] [pid 510357:tid 510566] [client 66.249.66.205:62747] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:19.051895 2026] [authz_core:error] [pid 510357:tid 510566] [client 66.249.66.205:62747] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:19.062782 2026] [security2:error] [pid 510357:tid 510510] [client 20.151.8.82:16700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/a.php"] [unique_id "apPlL35YTqJxoOZUSXtSegAABco"]
[Sun Aug 30 03:09:19.067679 2026] [security2:error] [pid 510357:tid 510609] [client 20.104.18.15:16728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlL35YTqJxoOZUSXtSfAAABi0"]
[Sun Aug 30 03:09:19.096993 2026] [security2:error] [pid 510357:tid 510608] [client 20.48.250.41:26567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/wen.php"] [unique_id "apPlL35YTqJxoOZUSXtSjQAABiw"]
[Sun Aug 30 03:09:19.100250 2026] [authz_core:error] [pid 510357:tid 510517] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:19.100567 2026] [authz_core:error] [pid 510357:tid 510517] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:19.123665 2026] [security2:error] [pid 510357:tid 510564] [client 20.151.8.82:27644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/dejavu.php"] [unique_id "apPlL35YTqJxoOZUSXtSmAAABgA"]
[Sun Aug 30 03:09:19.123745 2026] [security2:error] [pid 510357:tid 510529] [client 20.104.50.220:32072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/afile.php"] [unique_id "apPlL35YTqJxoOZUSXtSmgAABd0"]
[Sun Aug 30 03:09:19.139612 2026] [security2:error] [pid 510357:tid 510596] [client 68.155.159.216:55163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPlL35YTqJxoOZUSXtSnwAABiA"]
[Sun Aug 30 03:09:19.170748 2026] [security2:error] [pid 510357:tid 510547] [client 20.48.250.41:45050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/ccs.php"] [unique_id "apPlL35YTqJxoOZUSXtSowAABe8"]
[Sun Aug 30 03:09:19.191542 2026] [security2:error] [pid 510357:tid 510600] [client 20.151.8.82:16694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/ass.php"] [unique_id "apPlL35YTqJxoOZUSXtSpQAABiQ"]
[Sun Aug 30 03:09:19.201837 2026] [security2:error] [pid 510357:tid 510511] [client 68.155.159.216:62608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlL35YTqJxoOZUSXtSqAAABcs"]
[Sun Aug 30 03:09:19.204901 2026] [security2:error] [pid 510357:tid 510556] [client 20.104.50.220:59713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/footer.php"] [unique_id "apPlL35YTqJxoOZUSXtSqQAABfg"]
[Sun Aug 30 03:09:19.227175 2026] [security2:error] [pid 510357:tid 510579] [client 34.100.204.203:52696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/info.php"] [unique_id "apPlL35YTqJxoOZUSXtSrgAABg8"]
[Sun Aug 30 03:09:19.230948 2026] [authz_core:error] [pid 510357:tid 510510] [client 216.73.216.128:41351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:19.231434 2026] [authz_core:error] [pid 510357:tid 510510] [client 216.73.216.128:41351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:19.231693 2026] [security2:error] [pid 510357:tid 510618] [client 4.205.62.107:64511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/doc.php"] [unique_id "apPlL35YTqJxoOZUSXtSsAAABjY"]
[Sun Aug 30 03:09:19.242631 2026] [security2:error] [pid 510357:tid 510520] [client 20.48.250.41:26512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/inc.php"] [unique_id "apPlL35YTqJxoOZUSXtStAAABdQ"]
[Sun Aug 30 03:09:19.253768 2026] [security2:error] [pid 510357:tid 510491] [client 20.151.8.82:27534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/aaf.php"] [unique_id "apPlL35YTqJxoOZUSXtSuAAABbc"]
[Sun Aug 30 03:09:19.255625 2026] [security2:error] [pid 510357:tid 510586] [client 20.104.50.220:47054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/fm.php"] [unique_id "apPlL35YTqJxoOZUSXtSugAABhY"]
[Sun Aug 30 03:09:19.321558 2026] [security2:error] [pid 510357:tid 510533] [client 20.48.250.41:45002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/mar.php"] [unique_id "apPlL35YTqJxoOZUSXtS0QAABeE"]
[Sun Aug 30 03:09:19.325450 2026] [security2:error] [pid 510357:tid 510551] [client 20.104.18.15:35033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/goods.php"] [unique_id "apPlL35YTqJxoOZUSXtS1AAABfM"]
[Sun Aug 30 03:09:19.327062 2026] [security2:error] [pid 510357:tid 510600] [client 20.151.8.82:16585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/sb.php"] [unique_id "apPlL35YTqJxoOZUSXtS1QAABiQ"]
[Sun Aug 30 03:09:19.329278 2026] [security2:error] [pid 510357:tid 510497] [client 20.104.18.15:1809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/robot.php"] [unique_id "apPlL35YTqJxoOZUSXtS1wAABb0"]
[Sun Aug 30 03:09:19.388580 2026] [security2:error] [pid 510357:tid 510618] [client 20.151.8.82:27647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/h02ugyh.php"] [unique_id "apPlL35YTqJxoOZUSXtS3AAABjY"]
[Sun Aug 30 03:09:19.404443 2026] [security2:error] [pid 510357:tid 510562] [client 68.155.159.216:46071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-content/x/index.php"] [unique_id "apPlL35YTqJxoOZUSXtS4QAABf4"]
[Sun Aug 30 03:09:19.448302 2026] [security2:error] [pid 510357:tid 510509] [client 158.158.54.35:26324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/class-wp-cmd.php/fied.php"] [unique_id "apPlL35YTqJxoOZUSXtS7wAABck"]
[Sun Aug 30 03:09:19.448697 2026] [security2:error] [pid 510357:tid 510570] [client 20.48.250.41:45031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/ccu.php"] [unique_id "apPlL35YTqJxoOZUSXtS8AAABgY"]
[Sun Aug 30 03:09:19.458981 2026] [security2:error] [pid 510357:tid 510589] [client 20.151.8.82:16732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/in.php"] [unique_id "apPlL35YTqJxoOZUSXtS9AAABhk"]
[Sun Aug 30 03:09:19.484859 2026] [security2:error] [pid 510357:tid 510508] [client 20.48.250.41:26578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/6bcwiqwj.php"] [unique_id "apPlL35YTqJxoOZUSXtS_gAABcg"]
[Sun Aug 30 03:09:19.498820 2026] [security2:error] [pid 510357:tid 510497] [client 20.104.50.220:5551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/asu.php"] [unique_id "apPlL35YTqJxoOZUSXtTAwAABb0"]
[Sun Aug 30 03:09:19.508144 2026] [authz_core:error] [pid 510357:tid 510500] [client 66.249.66.195:42424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:19.508625 2026] [authz_core:error] [pid 510357:tid 510500] [client 66.249.66.195:42424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:19.528107 2026] [security2:error] [pid 510357:tid 510502] [client 20.151.8.82:27623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/155.php"] [unique_id "apPlL35YTqJxoOZUSXtTDAAABcI"]
[Sun Aug 30 03:09:19.554826 2026] [security2:error] [pid 510357:tid 510604] [client 20.104.18.15:34650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/c4.php"] [unique_id "apPlL35YTqJxoOZUSXtTFAAABig"]
[Sun Aug 30 03:09:19.557077 2026] [security2:error] [pid 510357:tid 510553] [client 74.248.24.12:22426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/dav.php"] [unique_id "apPlL35YTqJxoOZUSXtTFQAABfU"]
[Sun Aug 30 03:09:19.578623 2026] [security2:error] [pid 510357:tid 510495] [client 20.48.250.41:45040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/ak.php"] [unique_id "apPlL35YTqJxoOZUSXtTGQAABbs"]
[Sun Aug 30 03:09:19.584864 2026] [security2:error] [pid 510357:tid 510595] [client 20.48.251.3:59470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/cp2.php"] [unique_id "apPlL35YTqJxoOZUSXtTGgAABh8"]
[Sun Aug 30 03:09:19.592060 2026] [security2:error] [pid 510357:tid 510538] [client 20.151.8.82:16698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/ssg.php"] [unique_id "apPlL35YTqJxoOZUSXtTHwAABeY"]
[Sun Aug 30 03:09:19.600093 2026] [security2:error] [pid 510357:tid 510534] [client 20.104.18.15:18254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/pri.php"] [unique_id "apPlL35YTqJxoOZUSXtTIgAABeI"]
[Sun Aug 30 03:09:19.601663 2026] [authz_core:error] [pid 510357:tid 510541] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:19.602129 2026] [authz_core:error] [pid 510357:tid 510541] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:19.628905 2026] [security2:error] [pid 510357:tid 510515] [client 20.151.200.44:41923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/h02ugyh.php"] [unique_id "apPlL35YTqJxoOZUSXtTKwAABc8"]
[Sun Aug 30 03:09:19.630761 2026] [security2:error] [pid 510357:tid 510533] [client 20.104.49.130:63512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/read.php"] [unique_id "apPlL35YTqJxoOZUSXtTLAAABeE"]
[Sun Aug 30 03:09:19.631149 2026] [authz_core:error] [pid 510357:tid 510509] [client 66.249.66.197:40439] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:19.631639 2026] [authz_core:error] [pid 510357:tid 510509] [client 66.249.66.197:40439] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:19.633954 2026] [security2:error] [pid 510357:tid 510547] [client 20.48.250.41:26621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/easy.php"] [unique_id "apPlL35YTqJxoOZUSXtTMAAABe8"]
[Sun Aug 30 03:09:19.658043 2026] [security2:error] [pid 510357:tid 510598] [client 4.205.62.107:35977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/api.php"] [unique_id "apPlL35YTqJxoOZUSXtTNgAABiI"]
[Sun Aug 30 03:09:19.658262 2026] [security2:error] [pid 510357:tid 510497] [client 20.151.8.82:27646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/ops.php"] [unique_id "apPlL35YTqJxoOZUSXtTNwAABb0"]
[Sun Aug 30 03:09:19.680502 2026] [security2:error] [pid 510357:tid 510535] [client 216.73.216.128:58251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/%22"] [unique_id "apPlL35YTqJxoOZUSXtTPgAABeM"]
[Sun Aug 30 03:09:19.712919 2026] [security2:error] [pid 510357:tid 510611] [client 20.104.50.220:17316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "apPlL35YTqJxoOZUSXtTTAAABi8"]
[Sun Aug 30 03:09:19.718212 2026] [security2:error] [pid 510357:tid 510578] [client 20.48.250.41:45020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/lib.php"] [unique_id "apPlL35YTqJxoOZUSXtTUgAABg4"]
[Sun Aug 30 03:09:19.722928 2026] [security2:error] [pid 510357:tid 510592] [client 20.151.8.82:16590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/gigi.php"] [unique_id "apPlL35YTqJxoOZUSXtTUwAABhw"]
[Sun Aug 30 03:09:19.780594 2026] [security2:error] [pid 510357:tid 510615] [client 20.104.50.220:51596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/fvck.php"] [unique_id "apPlL35YTqJxoOZUSXtTXgAABjM"]
[Sun Aug 30 03:09:19.790936 2026] [security2:error] [pid 510357:tid 510542] [client 20.48.251.3:59276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/env.php"] [unique_id "apPlL35YTqJxoOZUSXtTXwAABeo"]
[Sun Aug 30 03:09:19.796933 2026] [security2:error] [pid 510357:tid 510492] [client 20.104.50.220:62837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/00.php"] [unique_id "apPlL35YTqJxoOZUSXtTYgAABbg"]
[Sun Aug 30 03:09:19.799425 2026] [security2:error] [pid 510357:tid 510497] [client 20.151.8.82:27631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/mac.php"] [unique_id "apPlL35YTqJxoOZUSXtTZQAABb0"]
[Sun Aug 30 03:09:19.842981 2026] [security2:error] [pid 510357:tid 510548] [client 20.48.250.41:26582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/fresh3.php"] [unique_id "apPlL35YTqJxoOZUSXtTbgAABfA"]
[Sun Aug 30 03:09:19.846884 2026] [security2:error] [pid 510357:tid 510567] [client 20.104.18.15:43321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/mgrr.php"] [unique_id "apPlL35YTqJxoOZUSXtTbwAABgM"]
[Sun Aug 30 03:09:19.848424 2026] [security2:error] [pid 510357:tid 510537] [client 20.48.250.41:44938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/wp-style.php"] [unique_id "apPlL35YTqJxoOZUSXtTcAAABeU"]
[Sun Aug 30 03:09:19.864449 2026] [security2:error] [pid 510357:tid 510614] [client 20.151.8.82:17357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/xnm-apc.php"] [unique_id "apPlL35YTqJxoOZUSXtTcQAABjI"]
[Sun Aug 30 03:09:19.870779 2026] [security2:error] [pid 510357:tid 510552] [client 68.155.159.216:54313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/simple.php"] [unique_id "apPlL35YTqJxoOZUSXtTcwAABfQ"]
[Sun Aug 30 03:09:19.898616 2026] [security2:error] [pid 510357:tid 510576] [client 20.104.50.220:63043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/s_on.php"] [unique_id "apPlL35YTqJxoOZUSXtTeQAABgw"]
[Sun Aug 30 03:09:19.936948 2026] [security2:error] [pid 510357:tid 510525] [client 20.151.8.82:27633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/makeasmtp.php"] [unique_id "apPlL35YTqJxoOZUSXtTgAAABdk"]
[Sun Aug 30 03:09:19.940754 2026] [security2:error] [pid 510357:tid 510554] [client 20.151.200.44:46031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/wp-the.php"] [unique_id "apPlL35YTqJxoOZUSXtTgwAABfY"]
[Sun Aug 30 03:09:19.976907 2026] [security2:error] [pid 510357:tid 510533] [client 20.63.81.20:60274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlL35YTqJxoOZUSXtTjQAABeE"]
[Sun Aug 30 03:09:19.989914 2026] [security2:error] [pid 510357:tid 510586] [client 20.48.250.41:45039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/browse.php"] [unique_id "apPlL35YTqJxoOZUSXtTkQAABhY"]
[Sun Aug 30 03:09:19.997200 2026] [security2:error] [pid 510357:tid 510517] [client 20.48.251.3:56345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/333.php"] [unique_id "apPlL35YTqJxoOZUSXtTlgAABdE"]
[Sun Aug 30 03:09:19.998847 2026] [security2:error] [pid 510357:tid 510573] [client 20.151.8.82:16702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/adminimagess.php"] [unique_id "apPlL35YTqJxoOZUSXtTmAAABgk"]
[Sun Aug 30 03:09:20.000872 2026] [security2:error] [pid 510357:tid 510610] [client 34.100.204.203:52698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/php.php"] [unique_id "apPlMH5YTqJxoOZUSXtTmgAABi4"]
[Sun Aug 30 03:09:20.036018 2026] [security2:error] [pid 510357:tid 510555] [client 158.158.54.35:10014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/M1.php"] [unique_id "apPlMH5YTqJxoOZUSXtTowAABfc"]
[Sun Aug 30 03:09:20.060657 2026] [security2:error] [pid 510357:tid 510499] [client 20.104.50.220:59567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/alf4.php"] [unique_id "apPlMH5YTqJxoOZUSXtTpwAABb8"]
[Sun Aug 30 03:09:20.065920 2026] [security2:error] [pid 510357:tid 510570] [client 20.151.8.82:27531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/pucci.php"] [unique_id "apPlMH5YTqJxoOZUSXtTqAAABgY"]
[Sun Aug 30 03:09:20.071433 2026] [security2:error] [pid 510357:tid 510611] [client 20.104.50.220:33162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/r0x.php"] [unique_id "apPlMH5YTqJxoOZUSXtTqgAABi8"]
[Sun Aug 30 03:09:20.080867 2026] [security2:error] [pid 510357:tid 510594] [client 20.48.250.41:26561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/bgymj.php"] [unique_id "apPlMH5YTqJxoOZUSXtTrAAABh4"]
[Sun Aug 30 03:09:20.123701 2026] [authz_core:error] [pid 510357:tid 510609] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:20.123997 2026] [authz_core:error] [pid 510357:tid 510609] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:20.124269 2026] [security2:error] [pid 510357:tid 510612] [client 20.48.250.41:45019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/zoo.php"] [unique_id "apPlMH5YTqJxoOZUSXtTswAABjA"]
[Sun Aug 30 03:09:20.145111 2026] [security2:error] [pid 510357:tid 510493] [client 20.151.8.82:16606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/wp-content/index.php"] [unique_id "apPlMH5YTqJxoOZUSXtTuAAABbk"]
[Sun Aug 30 03:09:20.148753 2026] [security2:error] [pid 510357:tid 510596] [client 74.248.24.12:11352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/hkvkjguw.php"] [unique_id "apPlMH5YTqJxoOZUSXtTuQAABiA"]
[Sun Aug 30 03:09:20.149638 2026] [security2:error] [pid 510357:tid 510547] [client 20.63.81.20:60250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlMH5YTqJxoOZUSXtTugAABe8"]
[Sun Aug 30 03:09:20.154925 2026] [authz_core:error] [pid 510357:tid 510604] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:20.155394 2026] [authz_core:error] [pid 510357:tid 510604] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:20.174193 2026] [security2:error] [pid 510357:tid 510564] [client 4.205.62.107:17124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/4563.php"] [unique_id "apPlMH5YTqJxoOZUSXtTvgAABgA"]
[Sun Aug 30 03:09:20.181094 2026] [security2:error] [pid 510357:tid 510586] [client 4.205.62.107:25785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/w.php"] [unique_id "apPlMH5YTqJxoOZUSXtTwAAABhY"]
[Sun Aug 30 03:09:20.193874 2026] [security2:error] [pid 510357:tid 510600] [client 20.151.8.82:27628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/puc.php"] [unique_id "apPlMH5YTqJxoOZUSXtTwwAABiQ"]
[Sun Aug 30 03:09:20.207840 2026] [authz_core:error] [pid 510357:tid 510573] [client 66.249.66.203:52199] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:20.208134 2026] [authz_core:error] [pid 510357:tid 510573] [client 66.249.66.203:52199] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:20.208543 2026] [security2:error] [pid 510357:tid 510571] [client 20.104.18.15:16700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlMH5YTqJxoOZUSXtTxwAABgc"]
[Sun Aug 30 03:09:20.225532 2026] [security2:error] [pid 510357:tid 510545] [client 20.48.250.41:26599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/ws69.php"] [unique_id "apPlMH5YTqJxoOZUSXtTyAAABe0"]
[Sun Aug 30 03:09:20.258660 2026] [security2:error] [pid 510357:tid 510531] [client 20.48.250.41:45026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/elp.php"] [unique_id "apPlMH5YTqJxoOZUSXtT0AAABd8"]
[Sun Aug 30 03:09:20.262750 2026] [security2:error] [pid 510357:tid 510555] [client 68.155.159.216:55121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/log-mama/function.php"] [unique_id "apPlMH5YTqJxoOZUSXtT1gAABfc"]
[Sun Aug 30 03:09:20.274888 2026] [security2:error] [pid 510357:tid 510543] [client 20.151.8.82:16755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "apPlMH5YTqJxoOZUSXtT3QAABes"]
[Sun Aug 30 03:09:20.301717 2026] [security2:error] [pid 510357:tid 510576] [client 20.104.50.220:31926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/f35.php"] [unique_id "apPlMH5YTqJxoOZUSXtT5AAABgw"]
[Sun Aug 30 03:09:20.307837 2026] [autoindex:error] [pid 510357:tid 510553] [client 20.196.209.81:13943] AH01276: Cannot serve directory /home2/njert/public_html/www/index.php/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:09:20.323803 2026] [security2:error] [pid 510357:tid 510617] [client 20.151.8.82:27599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/8.php"] [unique_id "apPlMH5YTqJxoOZUSXtT6QAABjU"]
[Sun Aug 30 03:09:20.330907 2026] [authz_core:error] [pid 510357:tid 510589] [client 216.73.216.128:41351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:20.331235 2026] [authz_core:error] [pid 510357:tid 510589] [client 216.73.216.128:41351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:20.333532 2026] [security2:error] [pid 510357:tid 510518] [client 20.104.49.130:54166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/gecko-new.php"] [unique_id "apPlMH5YTqJxoOZUSXtT7AAABdI"]
[Sun Aug 30 03:09:20.359131 2026] [security2:error] [pid 510357:tid 510568] [client 20.63.81.20:60167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/adminfuns.php"] [unique_id "apPlMH5YTqJxoOZUSXtT9AAABgQ"]
[Sun Aug 30 03:09:20.370890 2026] [security2:error] [pid 510357:tid 510542] [client 4.205.62.107:64459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/css.php"] [unique_id "apPlMH5YTqJxoOZUSXtT9QAABeo"]
[Sun Aug 30 03:09:20.380814 2026] [security2:error] [pid 510357:tid 510512] [client 68.155.159.216:62648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apPlMH5YTqJxoOZUSXtT-AAABcw"]
[Sun Aug 30 03:09:20.392012 2026] [security2:error] [pid 510357:tid 510571] [client 20.48.250.41:45046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/666.php"] [unique_id "apPlMH5YTqJxoOZUSXtT-wAABgc"]
[Sun Aug 30 03:09:20.398526 2026] [security2:error] [pid 510357:tid 510545] [client 20.104.50.220:47056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/403.php"] [unique_id "apPlMH5YTqJxoOZUSXtT_gAABe0"]
[Sun Aug 30 03:09:20.447772 2026] [security2:error] [pid 510357:tid 510611] [client 20.48.250.41:26456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/ccs.php"] [unique_id "apPlMH5YTqJxoOZUSXtUDAAABi8"]
[Sun Aug 30 03:09:20.456287 2026] [security2:error] [pid 510357:tid 510604] [client 20.104.50.220:59388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-content/index.php"] [unique_id "apPlMH5YTqJxoOZUSXtUEgAABig"]
[Sun Aug 30 03:09:20.471690 2026] [security2:error] [pid 510357:tid 510503] [client 20.104.18.15:1973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/sss.php"] [unique_id "apPlMH5YTqJxoOZUSXtUGQAABcM"]
[Sun Aug 30 03:09:20.482032 2026] [security2:error] [pid 510357:tid 510526] [client 20.151.8.82:27545] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/1.php"] [unique_id "apPlMH5YTqJxoOZUSXtUHAAABdo"]
[Sun Aug 30 03:09:20.482114 2026] [security2:error] [pid 510357:tid 510526] [client 20.151.8.82:27545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/1.php"] [unique_id "apPlMH5YTqJxoOZUSXtUHAAABdo"]
[Sun Aug 30 03:09:20.484298 2026] [security2:error] [pid 510357:tid 510538] [client 20.104.18.15:35028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/ah.php"] [unique_id "apPlMH5YTqJxoOZUSXtUHgAABeY"]
[Sun Aug 30 03:09:20.490657 2026] [security2:error] [pid 510357:tid 510493] [client 20.63.81.20:60260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/goods.php"] [unique_id "apPlMH5YTqJxoOZUSXtUIAAABbk"]
[Sun Aug 30 03:09:20.499290 2026] [security2:error] [pid 510357:tid 510586] [client 158.158.54.35:4704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/DxHhVcy2bmJ.php"] [unique_id "apPlMH5YTqJxoOZUSXtUIgAABhY"]
[Sun Aug 30 03:09:20.521794 2026] [security2:error] [pid 510357:tid 510496] [client 20.48.250.41:45012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/knmt.php"] [unique_id "apPlMH5YTqJxoOZUSXtUJgAABbw"]
[Sun Aug 30 03:09:20.574219 2026] [security2:error] [pid 510357:tid 510499] [client 20.104.49.130:52111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlMH5YTqJxoOZUSXtUPQAABb8"]
[Sun Aug 30 03:09:20.578002 2026] [security2:error] [pid 510357:tid 510523] [client 20.48.250.41:26603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/mar.php"] [unique_id "apPlMH5YTqJxoOZUSXtUPgAABdc"]
[Sun Aug 30 03:09:20.578217 2026] [authz_core:error] [pid 510357:tid 510560] [client 66.249.66.200:58083] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:20.578667 2026] [authz_core:error] [pid 510357:tid 510560] [client 66.249.66.200:58083] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:20.601766 2026] [authz_core:error] [pid 510357:tid 510604] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:20.602083 2026] [authz_core:error] [pid 510357:tid 510604] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:20.623531 2026] [security2:error] [pid 510357:tid 510553] [client 20.151.8.82:27562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/admin.php"] [unique_id "apPlMH5YTqJxoOZUSXtUTwAABfU"]
[Sun Aug 30 03:09:20.629368 2026] [security2:error] [pid 510357:tid 510583] [client 20.63.81.20:60207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/100.php"] [unique_id "apPlMH5YTqJxoOZUSXtUUQAABhM"]
[Sun Aug 30 03:09:20.648384 2026] [security2:error] [pid 510357:tid 510515] [client 20.104.50.220:5943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/sql.php"] [unique_id "apPlMH5YTqJxoOZUSXtUXgAABc8"]
[Sun Aug 30 03:09:20.648959 2026] [security2:error] [pid 510357:tid 510502] [client 20.48.250.41:44931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/sbhu.php"] [unique_id "apPlMH5YTqJxoOZUSXtUYAAABcI"]
[Sun Aug 30 03:09:20.662429 2026] [security2:error] [pid 510357:tid 510596] [client 74.248.24.12:13920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/conf_upload.php"] [unique_id "apPlMH5YTqJxoOZUSXtUZwAABiA"]
[Sun Aug 30 03:09:20.702128 2026] [security2:error] [pid 510357:tid 510583] [client 20.104.18.15:34561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/rxr.php"] [unique_id "apPlMH5YTqJxoOZUSXtUegAABhM"]
[Sun Aug 30 03:09:20.718814 2026] [security2:error] [pid 510357:tid 510615] [client 20.48.250.41:26465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/ccu.php"] [unique_id "apPlMH5YTqJxoOZUSXtUgwAABjM"]
[Sun Aug 30 03:09:20.723674 2026] [security2:error] [pid 510357:tid 510516] [client 20.151.8.82:16662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/wp-temp.php"] [unique_id "apPlMH5YTqJxoOZUSXtUhgAABdA"]
[Sun Aug 30 03:09:20.744262 2026] [security2:error] [pid 510357:tid 510561] [client 20.104.18.15:18352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/wp_blog_footer.php"] [unique_id "apPlMH5YTqJxoOZUSXtUhwAABf0"]
[Sun Aug 30 03:09:20.751146 2026] [security2:error] [pid 510357:tid 510496] [client 20.48.251.3:59894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/xda.php"] [unique_id "apPlMH5YTqJxoOZUSXtUiQAABbw"]
[Sun Aug 30 03:09:20.758585 2026] [security2:error] [pid 510357:tid 510600] [client 20.151.8.82:27607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/edit.php"] [unique_id "apPlMH5YTqJxoOZUSXtUigAABiQ"]
[Sun Aug 30 03:09:20.765985 2026] [security2:error] [pid 510357:tid 510568] [client 20.63.81.20:60253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/about.php"] [unique_id "apPlMH5YTqJxoOZUSXtUiwAABgQ"]
[Sun Aug 30 03:09:20.775628 2026] [security2:error] [pid 510357:tid 510525] [client 20.48.250.41:44999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/a332.php"] [unique_id "apPlMH5YTqJxoOZUSXtUjgAABdk"]
[Sun Aug 30 03:09:20.795823 2026] [security2:error] [pid 510357:tid 510501] [client 20.104.49.130:36787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/ccc.php"] [unique_id "apPlMH5YTqJxoOZUSXtUkwAABcE"]
[Sun Aug 30 03:09:20.801173 2026] [security2:error] [pid 510357:tid 510592] [client 34.100.204.203:52704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/i.php"] [unique_id "apPlMH5YTqJxoOZUSXtUlwAABhw"]
[Sun Aug 30 03:09:20.805494 2026] [authz_core:error] [pid 510357:tid 510545] [client 66.249.66.37:51704] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:20.805823 2026] [authz_core:error] [pid 510357:tid 510545] [client 66.249.66.37:51704] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:20.837614 2026] [security2:error] [pid 510357:tid 510506] [client 167.235.143.113:23496] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "lenoreashwood.com"] [uri "/index.php"] [unique_id "apPlL35YTqJxoOZUSXtSbwAABcY"], referer: https://lenoreashwood.com
[Sun Aug 30 03:09:20.840610 2026] [security2:error] [pid 510357:tid 510562] [client 4.205.62.107:36726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/temp.php"] [unique_id "apPlMH5YTqJxoOZUSXtUoAAABf4"]
[Sun Aug 30 03:09:20.850939 2026] [security2:error] [pid 510357:tid 510547] [client 20.104.50.220:16620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-links.php"] [unique_id "apPlMH5YTqJxoOZUSXtUogAABe8"]
[Sun Aug 30 03:09:20.852077 2026] [security2:error] [pid 510357:tid 510605] [client 20.151.8.82:17389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPlMH5YTqJxoOZUSXtUowAABik"]
[Sun Aug 30 03:09:20.855223 2026] [security2:error] [pid 510357:tid 510603] [client 18.192.166.72:33104] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "lenoreashwood.com"] [uri "/index.php"] [unique_id "apPlLn5YTqJxoOZUSXtSWAAABic"], referer: https://lenoreashwood.com
[Sun Aug 30 03:09:20.863715 2026] [security2:error] [pid 510357:tid 510520] [client 20.104.49.130:43268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/well.php"] [unique_id "apPlMH5YTqJxoOZUSXtUpAAABdQ"]
[Sun Aug 30 03:09:20.904812 2026] [security2:error] [pid 510357:tid 510493] [client 103.153.183.69:44798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intentionalrounding.com"] [uri "/wp/index.php"] [unique_id "apPlMH5YTqJxoOZUSXtUtQAABbk"], referer: https://intentionalrounding.com/wp/wp-admin/
[Sun Aug 30 03:09:20.911467 2026] [security2:error] [pid 510357:tid 510618] [client 20.63.81.20:60252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/about.php"] [unique_id "apPlMH5YTqJxoOZUSXtUuwAABjY"]
[Sun Aug 30 03:09:20.915080 2026] [security2:error] [pid 510357:tid 510568] [client 20.48.250.41:26617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/ak.php"] [unique_id "apPlMH5YTqJxoOZUSXtUvQAABgQ"]
[Sun Aug 30 03:09:20.922675 2026] [security2:error] [pid 510357:tid 510552] [client 20.48.250.41:45003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/ws66.php"] [unique_id "apPlMH5YTqJxoOZUSXtUwAAABfQ"]
[Sun Aug 30 03:09:20.928850 2026] [security2:error] [pid 510357:tid 510592] [client 20.48.251.3:59355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/xve22.php"] [unique_id "apPlMH5YTqJxoOZUSXtUwgAABhw"]
[Sun Aug 30 03:09:20.932795 2026] [security2:error] [pid 510357:tid 510582] [client 20.104.50.220:62787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/000.php"] [unique_id "apPlMH5YTqJxoOZUSXtUwwAABhI"]
[Sun Aug 30 03:09:20.949006 2026] [authz_core:error] [pid 510357:tid 510450] [remote 216.73.217.178:59557] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:20.949485 2026] [authz_core:error] [pid 510357:tid 510450] [remote 216.73.217.178:59557] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:20.957714 2026] [authz_core:error] [pid 510357:tid 510531] [client 66.249.66.68:44044] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:20.957989 2026] [authz_core:error] [pid 510357:tid 510531] [client 66.249.66.68:44044] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:20.972288 2026] [authz_core:error] [pid 510357:tid 510565] [client 216.73.216.128:41351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:20.972579 2026] [authz_core:error] [pid 510357:tid 510565] [client 216.73.216.128:41351] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:20.990140 2026] [security2:error] [pid 510357:tid 510566] [client 34.96.44.100:13053] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "bloombayroberts.com"] [uri "/nltulipfest/"] [unique_id "apPlMH5YTqJxoOZUSXtU2wAABgI"]
[Sun Aug 30 03:09:20.991380 2026] [security2:error] [pid 510357:tid 510590] [client 20.104.50.220:51619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/0x.php"] [unique_id "apPlMH5YTqJxoOZUSXtU3QAABho"]
[Sun Aug 30 03:09:20.997184 2026] [security2:error] [pid 510357:tid 510598] [client 158.158.54.35:29090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/browse.php"] [unique_id "apPlMH5YTqJxoOZUSXtU3gAABiI"]
[Sun Aug 30 03:09:20.998880 2026] [security2:error] [pid 510357:tid 510518] [client 20.104.18.15:43271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/mac.php"] [unique_id "apPlMH5YTqJxoOZUSXtU3wAABdI"]
[Sun Aug 30 03:09:21.043662 2026] [security2:error] [pid 510357:tid 510568] [client 20.63.81.20:60277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/admin.php"] [unique_id "apPlMX5YTqJxoOZUSXtU7AAABgQ"]
[Sun Aug 30 03:09:21.045370 2026] [security2:error] [pid 510357:tid 510552] [client 20.104.50.220:28685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/selaras.php"] [unique_id "apPlMX5YTqJxoOZUSXtU7QAABfQ"]
[Sun Aug 30 03:09:21.065551 2026] [security2:error] [pid 510357:tid 510591] [client 20.48.250.41:44993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/ws68.php"] [unique_id "apPlMX5YTqJxoOZUSXtU8QAABhs"]
[Sun Aug 30 03:09:21.066315 2026] [security2:error] [pid 510357:tid 510504] [client 3.77.67.4:33300] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "nalahenkelaislinn.com"] [uri "/index.php"] [unique_id "apPlL35YTqJxoOZUSXtS7QAABcQ"], referer: https://nalahenkelaislinn.com/
[Sun Aug 30 03:09:21.111903 2026] [security2:error] [pid 510357:tid 510509] [client 20.48.250.41:26528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/lib.php"] [unique_id "apPlMX5YTqJxoOZUSXtU-QAABck"]
[Sun Aug 30 03:09:21.119073 2026] [authz_core:error] [pid 510357:tid 510530] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:21.119456 2026] [authz_core:error] [pid 510357:tid 510530] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:21.135233 2026] [security2:error] [pid 510357:tid 510567] [client 20.48.251.3:56342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/G-in.php"] [unique_id "apPlMX5YTqJxoOZUSXtU_AAABgM"]
[Sun Aug 30 03:09:21.138968 2026] [security2:error] [pid 510357:tid 510551] [client 68.155.159.216:54302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-admin/about.php"] [unique_id "apPlMX5YTqJxoOZUSXtU_gAABfM"]
[Sun Aug 30 03:09:21.162523 2026] [security2:error] [pid 510357:tid 510507] [client 20.104.49.130:53507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/dehnl.php"] [unique_id "apPlMX5YTqJxoOZUSXtVBAAABcc"]
[Sun Aug 30 03:09:21.191551 2026] [security2:error] [pid 510357:tid 510578] [client 74.248.24.12:15244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/catuploadcsv.php"] [unique_id "apPlMX5YTqJxoOZUSXtVCgAABg4"]
[Sun Aug 30 03:09:21.202364 2026] [security2:error] [pid 510357:tid 510512] [client 20.48.250.41:45018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/users.php"] [unique_id "apPlMX5YTqJxoOZUSXtVDAAABcw"]
[Sun Aug 30 03:09:21.205913 2026] [security2:error] [pid 510357:tid 510533] [client 20.63.81.20:60120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/admin.php"] [unique_id "apPlMX5YTqJxoOZUSXtVDQAABeE"]
[Sun Aug 30 03:09:21.209405 2026] [security2:error] [pid 510357:tid 510517] [client 20.104.50.220:33281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/bn.php"] [unique_id "apPlMX5YTqJxoOZUSXtVDwAABdE"]
[Sun Aug 30 03:09:21.214623 2026] [security2:error] [pid 510357:tid 510502] [client 20.104.50.220:59553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/alfa-shell-v4.php"] [unique_id "apPlMX5YTqJxoOZUSXtVEAAABcI"]
[Sun Aug 30 03:09:21.242085 2026] [security2:error] [pid 510357:tid 510575] [client 20.48.250.41:26616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/wp-style.php"] [unique_id "apPlMX5YTqJxoOZUSXtVFAAABgs"]
[Sun Aug 30 03:09:21.292770 2026] [authz_core:error] [pid 510357:tid 510493] [client 66.249.66.77:41581] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:21.293069 2026] [authz_core:error] [pid 510357:tid 510493] [client 66.249.66.77:41581] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:21.318691 2026] [security2:error] [pid 510357:tid 510544] [client 4.205.62.107:25741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/btx25.php"] [unique_id "apPlMX5YTqJxoOZUSXtVMQAABew"]
[Sun Aug 30 03:09:21.318716 2026] [security2:error] [pid 510357:tid 510551] [client 4.205.62.107:17133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/cp2.php"] [unique_id "apPlMX5YTqJxoOZUSXtVMAAABfM"]
[Sun Aug 30 03:09:21.318866 2026] [authz_core:error] [pid 510357:tid 510563] [client 66.249.66.73:58464] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:21.319178 2026] [authz_core:error] [pid 510357:tid 510563] [client 66.249.66.73:58464] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:21.328090 2026] [security2:error] [pid 510357:tid 510521] [client 216.73.216.128:41351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts2/updateconf"] [unique_id "apPlMX5YTqJxoOZUSXtVNQAABdU"]
[Sun Aug 30 03:09:21.331029 2026] [security2:error] [pid 510357:tid 510571] [client 20.48.250.41:45009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/bzjdlofz.php"] [unique_id "apPlMX5YTqJxoOZUSXtVNwAABgc"]
[Sun Aug 30 03:09:21.343437 2026] [security2:error] [pid 510357:tid 510503] [client 20.104.18.15:64851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/adminfuns.php"] [unique_id "apPlMX5YTqJxoOZUSXtVOgAABcM"]
[Sun Aug 30 03:09:21.356663 2026] [security2:error] [pid 510357:tid 510603] [client 20.104.49.130:60642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/ohct.php"] [unique_id "apPlMX5YTqJxoOZUSXtVPAAABic"]
[Sun Aug 30 03:09:21.362946 2026] [security2:error] [pid 510357:tid 510555] [client 20.63.81.20:60230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/themes.php"] [unique_id "apPlMX5YTqJxoOZUSXtVPgAABfc"]
[Sun Aug 30 03:09:21.388865 2026] [security2:error] [pid 510357:tid 510543] [client 20.48.250.41:26589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/browse.php"] [unique_id "apPlMX5YTqJxoOZUSXtVQAAABes"]
[Sun Aug 30 03:09:21.397090 2026] [authz_core:error] [pid 510357:tid 510523] [client 66.249.66.70:42982] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:21.397529 2026] [authz_core:error] [pid 510357:tid 510523] [client 66.249.66.70:42982] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:21.400025 2026] [security2:error] [pid 510357:tid 510615] [client 68.155.159.216:55141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/bk/index.php"] [unique_id "apPlMX5YTqJxoOZUSXtVQwAABjM"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:21.464937 2026] [security2:error] [pid 510357:tid 510501] [client 20.104.50.220:31861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/goods.php"] [unique_id "apPlMX5YTqJxoOZUSXtVXAAABcE"]
[Sun Aug 30 03:09:21.471850 2026] [security2:error] [pid 510357:tid 510495] [client 20.48.250.41:45015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/selesai.php"] [unique_id "apPlMX5YTqJxoOZUSXtVYwAABbs"]
[Sun Aug 30 03:09:21.487673 2026] [security2:error] [pid 510357:tid 510581] [client 68.155.159.216:62619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apPlMX5YTqJxoOZUSXtVaAAABhE"]
[Sun Aug 30 03:09:21.489933 2026] [security2:error] [pid 510357:tid 510571] [client 20.151.200.44:41974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/sf.php"] [unique_id "apPlMX5YTqJxoOZUSXtVaQAABgc"]
[Sun Aug 30 03:09:21.502612 2026] [security2:error] [pid 510357:tid 510558] [client 20.151.200.44:46015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/wt.php"] [unique_id "apPlMX5YTqJxoOZUSXtVbgAABfo"]
[Sun Aug 30 03:09:21.509248 2026] [security2:error] [pid 510357:tid 510557] [client 4.205.62.107:64661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/php_info.php"] [unique_id "apPlMX5YTqJxoOZUSXtVbwAABfk"]
[Sun Aug 30 03:09:21.521511 2026] [security2:error] [pid 510357:tid 510578] [client 20.63.81.20:60175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/biufile.php"] [unique_id "apPlMX5YTqJxoOZUSXtVdgAABg4"]
[Sun Aug 30 03:09:21.529744 2026] [security2:error] [pid 510357:tid 510610] [client 158.158.54.35:2732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/cljntmcz.php"] [unique_id "apPlMX5YTqJxoOZUSXtVewAABi4"]
[Sun Aug 30 03:09:21.569143 2026] [security2:error] [pid 510357:tid 510505] [client 20.104.50.220:46445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/admin.php"] [unique_id "apPlMX5YTqJxoOZUSXtViQAABcU"]
[Sun Aug 30 03:09:21.584774 2026] [security2:error] [pid 510357:tid 510494] [client 34.100.204.203:52712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/pi.php"] [unique_id "apPlMX5YTqJxoOZUSXtViwAABbo"]
[Sun Aug 30 03:09:21.598292 2026] [security2:error] [pid 510357:tid 510541] [client 20.104.18.15:1998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/xmini4.php"] [unique_id "apPlMX5YTqJxoOZUSXtVkQAABek"]
[Sun Aug 30 03:09:21.601862 2026] [security2:error] [pid 510357:tid 510564] [client 20.48.250.41:44932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/shlo.php"] [unique_id "apPlMX5YTqJxoOZUSXtVkgAABgA"]
[Sun Aug 30 03:09:21.622105 2026] [security2:error] [pid 510357:tid 510515] [client 20.48.250.41:26504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/zoo.php"] [unique_id "apPlMX5YTqJxoOZUSXtVnwAABc8"]
[Sun Aug 30 03:09:21.630078 2026] [authz_core:error] [pid 510357:tid 510571] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:21.630531 2026] [authz_core:error] [pid 510357:tid 510571] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:21.635114 2026] [autoindex:error] [pid 510357:tid 510576] [client 20.104.50.220:59383] AH01276: Cannot serve directory /var/www/html/images/: No matching DirectoryIndex (index.cgi,index.php,index.html,index.htm) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:09:21.643352 2026] [security2:error] [pid 510357:tid 510554] [client 20.104.18.15:35170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/ws55.php"] [unique_id "apPlMX5YTqJxoOZUSXtVrgAABfY"]
[Sun Aug 30 03:09:21.664855 2026] [security2:error] [pid 510357:tid 510601] [client 20.63.81.20:60236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/coffexium.php"] [unique_id "apPlMX5YTqJxoOZUSXtVwQAABiU"]
[Sun Aug 30 03:09:21.666085 2026] [authz_core:error] [pid 510357:tid 510597] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:21.666357 2026] [authz_core:error] [pid 510357:tid 510597] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:21.700202 2026] [authz_core:error] [pid 510357:tid 510548] [client 216.73.216.128:34642] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:21.700479 2026] [authz_core:error] [pid 510357:tid 510548] [client 216.73.216.128:34642] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:21.724884 2026] [security2:error] [pid 510357:tid 510576] [client 20.104.50.220:59383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/zoro.php"] [unique_id "apPlMX5YTqJxoOZUSXtV1gAABgw"]
[Sun Aug 30 03:09:21.740622 2026] [security2:error] [pid 510357:tid 510565] [client 20.48.250.41:44946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/asax.php"] [unique_id "apPlMX5YTqJxoOZUSXtV2AAABgE"]
[Sun Aug 30 03:09:21.790941 2026] [security2:error] [pid 510357:tid 510617] [client 20.104.50.220:5565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/tol.php"] [unique_id "apPlMX5YTqJxoOZUSXtV3wAABjU"]
[Sun Aug 30 03:09:21.806877 2026] [security2:error] [pid 510357:tid 510503] [client 74.248.24.12:13939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/Alfa.php"] [unique_id "apPlMX5YTqJxoOZUSXtV5wAABcM"]
[Sun Aug 30 03:09:21.836504 2026] [security2:error] [pid 510357:tid 510575] [client 68.155.159.216:45983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-includes/Requests/about.php"] [unique_id "apPlMX5YTqJxoOZUSXtV7wAABgs"]
[Sun Aug 30 03:09:21.836511 2026] [security2:error] [pid 510357:tid 510537] [client 20.63.81.20:60161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/coffee.php"] [unique_id "apPlMX5YTqJxoOZUSXtV7gAABeU"]
[Sun Aug 30 03:09:21.845946 2026] [security2:error] [pid 510357:tid 510564] [client 20.104.18.15:34740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agrokomerc.mobi"] [uri "/reviall.php"] [unique_id "apPlMX5YTqJxoOZUSXtV8gAABgA"]
[Sun Aug 30 03:09:21.874345 2026] [security2:error] [pid 510357:tid 510600] [client 20.48.250.41:26613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/elp.php"] [unique_id "apPlMX5YTqJxoOZUSXtV9AAABiQ"]
[Sun Aug 30 03:09:21.886198 2026] [authz_core:error] [pid 510357:tid 510582] [client 66.249.66.204:36020] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:21.886652 2026] [authz_core:error] [pid 510357:tid 510582] [client 66.249.66.204:36020] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:21.889799 2026] [security2:error] [pid 510357:tid 510513] [client 20.48.251.3:59892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/pinfo.php"] [unique_id "apPlMX5YTqJxoOZUSXtV-wAABc0"]
[Sun Aug 30 03:09:21.894072 2026] [security2:error] [pid 510357:tid 510541] [client 20.104.18.15:18357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/sushi.php"] [unique_id "apPlMX5YTqJxoOZUSXtV_AAABek"]
[Sun Aug 30 03:09:21.907137 2026] [security2:error] [pid 510357:tid 510547] [client 20.48.250.41:45038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/fetch.php"] [unique_id "apPlMX5YTqJxoOZUSXtWAQAABe8"]
[Sun Aug 30 03:09:21.907661 2026] [security2:error] [pid 510357:tid 510595] [client 20.151.8.82:27560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/inputs.php"] [unique_id "apPlMX5YTqJxoOZUSXtWAgAABh8"]
[Sun Aug 30 03:09:21.983255 2026] [security2:error] [pid 510357:tid 510550] [client 20.104.50.220:17296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "apPlMX5YTqJxoOZUSXtWHgAABfI"]
[Sun Aug 30 03:09:21.992972 2026] [security2:error] [pid 510357:tid 510586] [client 20.63.81.20:60251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/classwithtostring.php"] [unique_id "apPlMX5YTqJxoOZUSXtWJAAABhY"]
[Sun Aug 30 03:09:22.007443 2026] [authz_core:error] [pid 510357:tid 510537] [client 66.249.66.42:47743] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:22.007759 2026] [authz_core:error] [pid 510357:tid 510537] [client 66.249.66.42:47743] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:22.015880 2026] [security2:error] [pid 510357:tid 510526] [client 103.153.183.69:44808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intentionalrounding.com"] [uri "/wp/index.php"] [unique_id "apPlMn5YTqJxoOZUSXtWKwAABdo"], referer: https://intentionalrounding.com/wp/wp-admin/
[Sun Aug 30 03:09:22.026084 2026] [security2:error] [pid 510357:tid 510541] [client 20.48.250.41:26562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/666.php"] [unique_id "apPlMn5YTqJxoOZUSXtWLQAABek"]
[Sun Aug 30 03:09:22.028742 2026] [security2:error] [pid 510357:tid 510588] [client 158.158.54.35:5364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/fox.php"] [unique_id "apPlMn5YTqJxoOZUSXtWLgAABhg"]
[Sun Aug 30 03:09:22.039472 2026] [security2:error] [pid 510357:tid 510544] [client 20.151.8.82:27594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/av.php"] [unique_id "apPlMn5YTqJxoOZUSXtWMAAABew"]
[Sun Aug 30 03:09:22.052733 2026] [security2:error] [pid 510357:tid 510495] [client 20.48.250.41:44994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/vx.php"] [unique_id "apPlMn5YTqJxoOZUSXtWMgAABbs"]
[Sun Aug 30 03:09:22.061954 2026] [security2:error] [pid 510357:tid 510542] [client 20.151.8.82:16612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/wp-content/admin.php"] [unique_id "apPlMn5YTqJxoOZUSXtWNQAABeo"]
[Sun Aug 30 03:09:22.066114 2026] [security2:error] [pid 510357:tid 510521] [client 20.48.251.3:59304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/06.php"] [unique_id "apPlMn5YTqJxoOZUSXtWNgAABdU"]
[Sun Aug 30 03:09:22.072042 2026] [security2:error] [pid 510357:tid 510514] [client 20.104.50.220:62804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/okkk.php"] [unique_id "apPlMn5YTqJxoOZUSXtWNwAABc4"]
[Sun Aug 30 03:09:22.092688 2026] [security2:error] [pid 510357:tid 510583] [client 4.205.62.107:36561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/fm.php"] [unique_id "apPlMn5YTqJxoOZUSXtWPgAABhM"]
[Sun Aug 30 03:09:22.128668 2026] [security2:error] [pid 510357:tid 510606] [client 20.104.49.130:45697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/about.php"] [unique_id "apPlMn5YTqJxoOZUSXtWQwAABio"]
[Sun Aug 30 03:09:22.135253 2026] [security2:error] [pid 510357:tid 510592] [client 20.63.81.20:60239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/wp-ws68.php"] [unique_id "apPlMn5YTqJxoOZUSXtWRwAABhw"]
[Sun Aug 30 03:09:22.139019 2026] [authz_core:error] [pid 510357:tid 510587] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:22.139298 2026] [authz_core:error] [pid 510357:tid 510587] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:22.146857 2026] [security2:error] [pid 510357:tid 510579] [client 20.104.50.220:42024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/up.php5"] [unique_id "apPlMn5YTqJxoOZUSXtWSgAABg8"]
[Sun Aug 30 03:09:22.153736 2026] [security2:error] [pid 510357:tid 510610] [client 20.104.18.15:43305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/simple.php"] [unique_id "apPlMn5YTqJxoOZUSXtWTwAABi4"]
[Sun Aug 30 03:09:22.168306 2026] [security2:error] [pid 510357:tid 510615] [client 20.151.8.82:27619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/classwithtostring.php"] [unique_id "apPlMn5YTqJxoOZUSXtWVAAABjM"]
[Sun Aug 30 03:09:22.182852 2026] [security2:error] [pid 510357:tid 510501] [client 20.104.50.220:52845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/ssh.php"] [unique_id "apPlMn5YTqJxoOZUSXtWVQAABcE"]
[Sun Aug 30 03:09:22.191141 2026] [security2:error] [pid 510357:tid 510552] [client 20.48.250.41:45007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/global.php"] [unique_id "apPlMn5YTqJxoOZUSXtWWAAABfQ"]
[Sun Aug 30 03:09:22.192979 2026] [security2:error] [pid 510357:tid 510600] [client 20.151.8.82:16683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPlMn5YTqJxoOZUSXtWWgAABiQ"]
[Sun Aug 30 03:09:22.241803 2026] [authz_core:error] [pid 510357:tid 510617] [client 66.249.66.65:42003] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:22.242098 2026] [authz_core:error] [pid 510357:tid 510617] [client 66.249.66.65:42003] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:22.294463 2026] [security2:error] [pid 510357:tid 510608] [client 20.48.251.3:33337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/apikeys.php"] [unique_id "apPlMn5YTqJxoOZUSXtWcgAABiw"]
[Sun Aug 30 03:09:22.304085 2026] [authz_core:error] [pid 510357:tid 510509] [client 66.249.66.64:36441] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:22.304351 2026] [authz_core:error] [pid 510357:tid 510509] [client 66.249.66.64:36441] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:22.305749 2026] [security2:error] [pid 510357:tid 510578] [client 20.151.8.82:27643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/adminfuns.php"] [unique_id "apPlMn5YTqJxoOZUSXtWdAAABg4"]
[Sun Aug 30 03:09:22.306629 2026] [security2:error] [pid 510357:tid 510563] [client 20.63.81.20:60255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/mgrr.php"] [unique_id "apPlMn5YTqJxoOZUSXtWdgAABf8"]
[Sun Aug 30 03:09:22.308467 2026] [security2:error] [pid 510357:tid 510606] [client 20.48.250.41:26591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/knmt.php"] [unique_id "apPlMn5YTqJxoOZUSXtWdwAABio"]
[Sun Aug 30 03:09:22.317023 2026] [security2:error] [pid 510357:tid 510507] [client 20.48.250.41:44872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/fs.php"] [unique_id "apPlMn5YTqJxoOZUSXtWegAABcc"]
[Sun Aug 30 03:09:22.325048 2026] [security2:error] [pid 510357:tid 510505] [client 74.248.24.12:11376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/wp-index.php"] [unique_id "apPlMn5YTqJxoOZUSXtWgAAABcU"]
[Sun Aug 30 03:09:22.340308 2026] [security2:error] [pid 510357:tid 510501] [client 20.151.8.82:16697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/av.php"] [unique_id "apPlMn5YTqJxoOZUSXtWigAABcE"]
[Sun Aug 30 03:09:22.343855 2026] [security2:error] [pid 510357:tid 510520] [client 34.100.204.203:52726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/pinfo.php"] [unique_id "apPlMn5YTqJxoOZUSXtWiwAABdQ"]
[Sun Aug 30 03:09:22.352291 2026] [security2:error] [pid 510357:tid 510609] [client 20.104.50.220:33335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/dm.php"] [unique_id "apPlMn5YTqJxoOZUSXtWjAAABi0"]
[Sun Aug 30 03:09:22.366038 2026] [security2:error] [pid 510357:tid 510572] [client 20.104.50.220:61655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/alfakun.php"] [unique_id "apPlMn5YTqJxoOZUSXtWjgAABgg"]
[Sun Aug 30 03:09:22.366076 2026] [security2:error] [pid 510357:tid 510525] [client 68.155.159.216:54322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apPlMn5YTqJxoOZUSXtWjwAABdk"]
[Sun Aug 30 03:09:22.438776 2026] [security2:error] [pid 510357:tid 510592] [client 20.63.81.20:60286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/55.php"] [unique_id "apPlMn5YTqJxoOZUSXtWngAABhw"]
[Sun Aug 30 03:09:22.440110 2026] [security2:error] [pid 510357:tid 510601] [client 20.151.8.82:27541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/ms-edit.php"] [unique_id "apPlMn5YTqJxoOZUSXtWogAABiU"]
[Sun Aug 30 03:09:22.451940 2026] [security2:error] [pid 510357:tid 510607] [client 20.48.250.41:44945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/ioxi.php"] [unique_id "apPlMn5YTqJxoOZUSXtWqQAABis"]
[Sun Aug 30 03:09:22.475380 2026] [security2:error] [pid 510357:tid 510515] [client 4.205.62.107:25778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/app_dev.php"] [unique_id "apPlMn5YTqJxoOZUSXtWvAAABc8"]
[Sun Aug 30 03:09:22.481212 2026] [security2:error] [pid 510357:tid 510598] [client 4.205.62.107:17145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/xda.php"] [unique_id "apPlMn5YTqJxoOZUSXtWvwAABiI"]
[Sun Aug 30 03:09:22.482746 2026] [security2:error] [pid 510357:tid 510550] [client 20.104.18.15:16652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/goods.php"] [unique_id "apPlMn5YTqJxoOZUSXtWwgAABfI"]
[Sun Aug 30 03:09:22.486199 2026] [security2:error] [pid 510357:tid 510615] [client 137.184.201.15:53350] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "swmpainters.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "apPlMn5YTqJxoOZUSXtWwwAABjM"]
[Sun Aug 30 03:09:22.504630 2026] [security2:error] [pid 510357:tid 510513] [client 20.48.250.41:26498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/sbhu.php"] [unique_id "apPlMn5YTqJxoOZUSXtWxgAABc0"]
[Sun Aug 30 03:09:22.524287 2026] [security2:error] [pid 510357:tid 510554] [client 68.155.159.216:54262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.camilaymarco.com"] [uri "/first.php"] [unique_id "apPlMn5YTqJxoOZUSXtWzQAABfY"]
[Sun Aug 30 03:09:22.580806 2026] [security2:error] [pid 510357:tid 510516] [client 20.63.81.20:60226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/yj09.php"] [unique_id "apPlMn5YTqJxoOZUSXtW3gAABdA"]
[Sun Aug 30 03:09:22.604977 2026] [security2:error] [pid 510357:tid 510530] [client 20.48.250.41:44937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/bootstrap.php"] [unique_id "apPlMn5YTqJxoOZUSXtW5gAABd4"]
[Sun Aug 30 03:09:22.606129 2026] [security2:error] [pid 510357:tid 510494] [client 158.158.54.35:5334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/hello.php"] [unique_id "apPlMn5YTqJxoOZUSXtW6AAABbo"]
[Sun Aug 30 03:09:22.610067 2026] [security2:error] [pid 510357:tid 510609] [client 68.155.159.216:63243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/simple.php"] [unique_id "apPlMn5YTqJxoOZUSXtW6wAABi0"]
[Sun Aug 30 03:09:22.611977 2026] [authz_core:error] [pid 510357:tid 510500] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:22.612408 2026] [authz_core:error] [pid 510357:tid 510500] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:22.622942 2026] [security2:error] [pid 510357:tid 510589] [client 20.104.50.220:31873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/enclas.php"] [unique_id "apPlMn5YTqJxoOZUSXtW9AAABhk"]
[Sun Aug 30 03:09:22.651224 2026] [security2:error] [pid 510357:tid 510569] [client 4.205.62.107:64495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/session.php"] [unique_id "apPlMn5YTqJxoOZUSXtXCgAABgU"]
[Sun Aug 30 03:09:22.708941 2026] [security2:error] [pid 510357:tid 510538] [client 20.104.50.220:47078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ianegenolf.com"] [uri "/lv.php"] [unique_id "apPlMn5YTqJxoOZUSXtXKAAABeY"]
[Sun Aug 30 03:09:22.721524 2026] [security2:error] [pid 510357:tid 510572] [client 20.63.81.20:60247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/scxy.php"] [unique_id "apPlMn5YTqJxoOZUSXtXLQAABgg"]
[Sun Aug 30 03:09:22.735945 2026] [security2:error] [pid 510357:tid 510568] [client 20.48.250.41:45029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/export.php"] [unique_id "apPlMn5YTqJxoOZUSXtXMAAABgQ"]
[Sun Aug 30 03:09:22.736167 2026] [security2:error] [pid 510357:tid 510529] [client 20.48.250.41:26515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/a332.php"] [unique_id "apPlMn5YTqJxoOZUSXtXMQAABd0"]
[Sun Aug 30 03:09:22.742827 2026] [security2:error] [pid 510357:tid 510513] [client 20.104.18.15:1946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/gulu.php"] [unique_id "apPlMn5YTqJxoOZUSXtXMwAABc0"]
[Sun Aug 30 03:09:22.819917 2026] [security2:error] [pid 510357:tid 510516] [client 20.104.18.15:35155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/drykl.php"] [unique_id "apPlMn5YTqJxoOZUSXtXSgAABdA"]
[Sun Aug 30 03:09:22.836879 2026] [security2:error] [pid 510357:tid 510512] [client 74.248.24.12:18897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/locale.php"] [unique_id "apPlMn5YTqJxoOZUSXtXUQAABcw"]
[Sun Aug 30 03:09:22.872106 2026] [security2:error] [pid 510357:tid 510608] [client 20.63.81.20:60211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/ws13.php"] [unique_id "apPlMn5YTqJxoOZUSXtXXAAABiw"]
[Sun Aug 30 03:09:22.878025 2026] [security2:error] [pid 510357:tid 510566] [client 20.104.50.220:59391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wm.php"] [unique_id "apPlMn5YTqJxoOZUSXtXXwAABgI"]
[Sun Aug 30 03:09:22.888341 2026] [security2:error] [pid 510357:tid 510509] [client 20.48.250.41:44929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/gk.php"] [unique_id "apPlMn5YTqJxoOZUSXtXYgAABck"]
[Sun Aug 30 03:09:22.895025 2026] [security2:error] [pid 510357:tid 510570] [client 20.48.250.41:26609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/ws66.php"] [unique_id "apPlMn5YTqJxoOZUSXtXZQAABgY"]
[Sun Aug 30 03:09:22.922894 2026] [security2:error] [pid 510357:tid 510543] [client 20.104.50.220:6128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/lol.php"] [unique_id "apPlMn5YTqJxoOZUSXtXbgAABes"]
[Sun Aug 30 03:09:22.968297 2026] [security2:error] [pid 510357:tid 510508] [client 216.73.216.128:58456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts2/updateconf"] [unique_id "apPlMn5YTqJxoOZUSXtXgQAABcg"]
[Sun Aug 30 03:09:22.971660 2026] [authz_core:error] [pid 510357:tid 510530] [client 66.249.66.70:53107] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:22.971984 2026] [authz_core:error] [pid 510357:tid 510530] [client 66.249.66.70:53107] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:23.010953 2026] [security2:error] [pid 510357:tid 510501] [client 20.63.81.20:60225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/btx25.php"] [unique_id "apPlM35YTqJxoOZUSXtXlQAABcE"]
[Sun Aug 30 03:09:23.023243 2026] [security2:error] [pid 510357:tid 510617] [client 20.48.250.41:26571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/ws68.php"] [unique_id "apPlM35YTqJxoOZUSXtXmAAABjU"]
[Sun Aug 30 03:09:23.028917 2026] [security2:error] [pid 510357:tid 510568] [client 20.48.250.41:44942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/logs1.php"] [unique_id "apPlM35YTqJxoOZUSXtXmQAABgQ"]
[Sun Aug 30 03:09:23.033185 2026] [security2:error] [pid 510357:tid 510611] [client 20.151.200.44:45981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/im.php"] [unique_id "apPlM35YTqJxoOZUSXtXmgAABi8"]
[Sun Aug 30 03:09:23.034702 2026] [security2:error] [pid 510357:tid 510529] [client 20.104.18.15:18271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/manga.php"] [unique_id "apPlM35YTqJxoOZUSXtXmwAABd0"]
[Sun Aug 30 03:09:23.052229 2026] [security2:error] [pid 510357:tid 510569] [client 20.48.251.3:52236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/X57.php"] [unique_id "apPlM35YTqJxoOZUSXtXnwAABgU"]
[Sun Aug 30 03:09:23.062163 2026] [security2:error] [pid 510357:tid 510510] [client 20.104.49.130:54177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/yawa.php"] [unique_id "apPlM35YTqJxoOZUSXtXoQAABco"]
[Sun Aug 30 03:09:23.085384 2026] [security2:error] [pid 510357:tid 510567] [client 158.158.54.35:2479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/IDhrIlrLb.php"] [unique_id "apPlM35YTqJxoOZUSXtXqAAABgM"]
[Sun Aug 30 03:09:23.091322 2026] [authz_core:error] [pid 510357:tid 510531] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:23.091772 2026] [authz_core:error] [pid 510357:tid 510531] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:23.098312 2026] [security2:error] [pid 510357:tid 510500] [client 173.212.237.185:33922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.237.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cmoranphotography.com"] [uri "/wp-login.php"] [unique_id "apPlM35YTqJxoOZUSXtXpAAABcA"]
[Sun Aug 30 03:09:23.107695 2026] [security2:error] [pid 510357:tid 510504] [client 20.104.50.220:16591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/class-t.api.php"] [unique_id "apPlM35YTqJxoOZUSXtXrwAABcQ"]
[Sun Aug 30 03:09:23.135192 2026] [authz_core:error] [pid 510357:tid 510550] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:23.135664 2026] [authz_core:error] [pid 510357:tid 510550] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:23.153976 2026] [security2:error] [pid 510357:tid 510575] [client 20.63.81.20:60172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/SDsadqwrf.php"] [unique_id "apPlM35YTqJxoOZUSXtXxwAABgs"]
[Sun Aug 30 03:09:23.187670 2026] [security2:error] [pid 510357:tid 510595] [client 20.48.250.41:44934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/inege.php"] [unique_id "apPlM35YTqJxoOZUSXtXzgAABh8"]
[Sun Aug 30 03:09:23.204934 2026] [security2:error] [pid 510357:tid 510574] [client 20.48.251.3:59374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/xin1.php"] [unique_id "apPlM35YTqJxoOZUSXtX0wAABgo"]
[Sun Aug 30 03:09:23.218044 2026] [security2:error] [pid 510357:tid 510568] [client 20.48.250.41:26513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/users.php"] [unique_id "apPlM35YTqJxoOZUSXtX1AAABgQ"]
[Sun Aug 30 03:09:23.226162 2026] [security2:error] [pid 510357:tid 510611] [client 20.104.50.220:62785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/yamate.php"] [unique_id "apPlM35YTqJxoOZUSXtX1QAABi8"]
[Sun Aug 30 03:09:23.284127 2026] [security2:error] [pid 510357:tid 510518] [client 20.104.50.220:51627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/shell.php5"] [unique_id "apPlM35YTqJxoOZUSXtX6wAABdI"]
[Sun Aug 30 03:09:23.296750 2026] [security2:error] [pid 510357:tid 510612] [client 20.104.18.15:43309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/xty.php"] [unique_id "apPlM35YTqJxoOZUSXtX7gAABjA"]
[Sun Aug 30 03:09:23.300128 2026] [security2:error] [pid 510357:tid 510553] [client 20.63.81.20:60162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/BDKR28WP.php"] [unique_id "apPlM35YTqJxoOZUSXtX7wAABfU"]
[Sun Aug 30 03:09:23.313803 2026] [security2:error] [pid 510357:tid 510605] [client 20.48.250.41:44998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/wp-link10.php"] [unique_id "apPlM35YTqJxoOZUSXtX8wAABik"]
[Sun Aug 30 03:09:23.318676 2026] [security2:error] [pid 510357:tid 510604] [client 20.104.50.220:29156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/s4d.php"] [unique_id "apPlM35YTqJxoOZUSXtX9QAABig"]
[Sun Aug 30 03:09:23.323448 2026] [security2:error] [pid 510357:tid 510539] [client 4.205.62.107:35981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/tinyfilemanager.php"] [unique_id "apPlM35YTqJxoOZUSXtX9wAABec"]
[Sun Aug 30 03:09:23.344850 2026] [security2:error] [pid 510357:tid 510525] [client 20.48.250.41:26587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/bzjdlofz.php"] [unique_id "apPlM35YTqJxoOZUSXtX_gAABdk"]
[Sun Aug 30 03:09:23.348875 2026] [security2:error] [pid 510357:tid 510521] [client 34.100.204.203:52736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/test.php"] [unique_id "apPlM35YTqJxoOZUSXtX_wAABdU"]
[Sun Aug 30 03:09:23.370737 2026] [security2:error] [pid 510357:tid 510570] [client 74.248.24.12:13900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/wxo.php"] [unique_id "apPlM35YTqJxoOZUSXtYAAAABgY"]
[Sun Aug 30 03:09:23.421338 2026] [security2:error] [pid 510357:tid 510496] [client 20.104.49.130:53701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/forum.php"] [unique_id "apPlM35YTqJxoOZUSXtYCwAABbw"]
[Sun Aug 30 03:09:23.433144 2026] [security2:error] [pid 510357:tid 510510] [client 20.48.251.3:33310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/motu.php"] [unique_id "apPlM35YTqJxoOZUSXtYDgAABco"]
[Sun Aug 30 03:09:23.447747 2026] [security2:error] [pid 510357:tid 510562] [client 20.63.81.20:60205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/sky.php"] [unique_id "apPlM35YTqJxoOZUSXtYHAAABf4"]
[Sun Aug 30 03:09:23.456589 2026] [security2:error] [pid 510357:tid 510518] [client 20.48.250.41:45025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/ww.php"] [unique_id "apPlM35YTqJxoOZUSXtYIgAABdI"]
[Sun Aug 30 03:09:23.489936 2026] [security2:error] [pid 510357:tid 510614] [client 20.151.8.82:16633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPlM35YTqJxoOZUSXtYMQAABjI"]
[Sun Aug 30 03:09:23.504791 2026] [security2:error] [pid 510357:tid 510613] [client 20.104.50.220:61424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/alfatesla.php"] [unique_id "apPlM35YTqJxoOZUSXtYNQAABjE"]
[Sun Aug 30 03:09:23.505998 2026] [security2:error] [pid 510357:tid 510570] [client 20.104.50.220:33334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/gator.php"] [unique_id "apPlM35YTqJxoOZUSXtYNgAABgY"]
[Sun Aug 30 03:09:23.516738 2026] [security2:error] [pid 510357:tid 510501] [client 158.23.184.117:13247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/wp-includes/ID3/config.php"] [unique_id "apPlM35YTqJxoOZUSXtYOAAABcE"]
[Sun Aug 30 03:09:23.531661 2026] [security2:error] [pid 510357:tid 510617] [client 20.48.250.41:26510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/selesai.php"] [unique_id "apPlM35YTqJxoOZUSXtYPgAABjU"]
[Sun Aug 30 03:09:23.539448 2026] [security2:error] [pid 510357:tid 510497] [client 158.158.54.35:26305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/fi2.php"] [unique_id "apPlM35YTqJxoOZUSXtYQQAABb0"]
[Sun Aug 30 03:09:23.568666 2026] [security2:error] [pid 510357:tid 510574] [client 158.23.184.117:12897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/test1.php"] [unique_id "apPlM35YTqJxoOZUSXtYTAAABgo"]
[Sun Aug 30 03:09:23.587614 2026] [security2:error] [pid 510357:tid 510558] [client 20.48.250.41:45006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/w1px.php"] [unique_id "apPlM35YTqJxoOZUSXtYTwAABfo"]
[Sun Aug 30 03:09:23.589614 2026] [security2:error] [pid 510357:tid 510504] [client 20.151.8.82:27572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/222.php"] [unique_id "apPlM35YTqJxoOZUSXtYUQAABcQ"]
[Sun Aug 30 03:09:23.590525 2026] [security2:error] [pid 510357:tid 510540] [client 20.63.81.20:60281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/file5.php"] [unique_id "apPlM35YTqJxoOZUSXtYUgAABeg"]
[Sun Aug 30 03:09:23.610588 2026] [security2:error] [pid 510357:tid 510575] [client 216.73.216.128:62586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlM35YTqJxoOZUSXtYXAAABgs"]
[Sun Aug 30 03:09:23.619706 2026] [security2:error] [pid 510357:tid 510532] [client 4.205.62.107:17300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/pinfo.php"] [unique_id "apPlM35YTqJxoOZUSXtYYgAABeA"]
[Sun Aug 30 03:09:23.624572 2026] [security2:error] [pid 510357:tid 510538] [client 20.151.8.82:16722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/wp-blog.php"] [unique_id "apPlM35YTqJxoOZUSXtYaQAABeY"]
[Sun Aug 30 03:09:23.626423 2026] [security2:error] [pid 510357:tid 510566] [client 4.205.62.107:25746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/php-info.php"] [unique_id "apPlM35YTqJxoOZUSXtYawAABgI"]
[Sun Aug 30 03:09:23.628222 2026] [security2:error] [pid 510357:tid 510521] [client 20.104.18.15:16755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/100.php"] [unique_id "apPlM35YTqJxoOZUSXtYbAAABdU"]
[Sun Aug 30 03:09:23.645519 2026] [authz_core:error] [pid 510357:tid 510595] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:23.645941 2026] [authz_core:error] [pid 510357:tid 510595] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:23.671523 2026] [security2:error] [pid 510357:tid 510540] [client 20.48.250.41:26610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/shlo.php"] [unique_id "apPlM35YTqJxoOZUSXtYjQAABeg"]
[Sun Aug 30 03:09:23.672128 2026] [authz_core:error] [pid 510357:tid 510580] [client 66.249.66.72:35847] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:23.672404 2026] [authz_core:error] [pid 510357:tid 510580] [client 66.249.66.72:35847] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:23.708720 2026] [security2:error] [pid 510357:tid 510583] [client 158.23.184.117:13188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/wp-admin/edit-tags.php"] [unique_id "apPlM35YTqJxoOZUSXtYogAABhM"]
[Sun Aug 30 03:09:23.721266 2026] [security2:error] [pid 510357:tid 510525] [client 68.155.159.216:62655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-admin/about.php"] [unique_id "apPlM35YTqJxoOZUSXtYpQAABdk"]
[Sun Aug 30 03:09:23.721406 2026] [security2:error] [pid 510357:tid 510608] [client 20.48.250.41:44987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/to.php"] [unique_id "apPlM35YTqJxoOZUSXtYpgAABiw"]
[Sun Aug 30 03:09:23.724733 2026] [security2:error] [pid 510357:tid 510590] [client 20.151.8.82:27627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/BDKR28WP.php"] [unique_id "apPlM35YTqJxoOZUSXtYqAAABho"]
[Sun Aug 30 03:09:23.741120 2026] [security2:error] [pid 510357:tid 510613] [client 20.63.81.20:60170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/xyn.php"] [unique_id "apPlM35YTqJxoOZUSXtYrQAABjE"]
[Sun Aug 30 03:09:23.744213 2026] [authz_core:error] [pid 510357:tid 510548] [client 66.249.66.195:36109] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:23.744468 2026] [authz_core:error] [pid 510357:tid 510548] [client 66.249.66.195:36109] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:23.750804 2026] [security2:error] [pid 510357:tid 510562] [client 20.104.49.130:36775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/dex.php"] [unique_id "apPlM35YTqJxoOZUSXtYrwAABf4"]
[Sun Aug 30 03:09:23.773746 2026] [security2:error] [pid 510357:tid 510520] [client 20.104.50.220:32073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/ioxi-o.php"] [unique_id "apPlM35YTqJxoOZUSXtYtAAABdQ"]
[Sun Aug 30 03:09:23.788510 2026] [security2:error] [pid 510357:tid 510597] [client 4.205.62.107:61728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/h.php"] [unique_id "apPlM35YTqJxoOZUSXtYtgAABiE"]
[Sun Aug 30 03:09:23.838465 2026] [security2:error] [pid 510357:tid 510605] [client 20.48.250.41:26623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/asax.php"] [unique_id "apPlM35YTqJxoOZUSXtYxAAABik"]
[Sun Aug 30 03:09:23.840198 2026] [security2:error] [pid 510357:tid 510541] [client 20.151.8.82:16593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/cgi-bin/index.php"] [unique_id "apPlM35YTqJxoOZUSXtYxQAABek"]
[Sun Aug 30 03:09:23.851879 2026] [security2:error] [pid 510357:tid 510569] [client 20.151.8.82:27568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/wp.php"] [unique_id "apPlM35YTqJxoOZUSXtYyAAABgU"]
[Sun Aug 30 03:09:23.863193 2026] [security2:error] [pid 510357:tid 510495] [client 20.48.250.41:44965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/thui.php"] [unique_id "apPlM35YTqJxoOZUSXtYyQAABbs"]
[Sun Aug 30 03:09:23.868476 2026] [security2:error] [pid 510357:tid 510493] [client 158.23.184.117:13220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/xmlrpc.php"] [unique_id "apPlM35YTqJxoOZUSXtYxwAABbk"]
[Sun Aug 30 03:09:23.880423 2026] [security2:error] [pid 510357:tid 510491] [client 20.104.18.15:2027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/replace.php"] [unique_id "apPlM35YTqJxoOZUSXtYzAAABbc"]
[Sun Aug 30 03:09:23.891407 2026] [security2:error] [pid 510357:tid 510539] [client 20.63.81.20:60243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/inso.php"] [unique_id "apPlM35YTqJxoOZUSXtY0AAABec"]
[Sun Aug 30 03:09:23.925242 2026] [security2:error] [pid 510357:tid 510611] [client 74.248.24.12:18910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/wp-contentt.php"] [unique_id "apPlM35YTqJxoOZUSXtY2gAABi8"]
[Sun Aug 30 03:09:23.955810 2026] [security2:error] [pid 510357:tid 510562] [client 20.104.18.15:35470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/backup.php"] [unique_id "apPlM35YTqJxoOZUSXtY4wAABf4"]
[Sun Aug 30 03:09:23.967122 2026] [security2:error] [pid 510357:tid 510526] [client 20.48.250.41:26606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/fetch.php"] [unique_id "apPlM35YTqJxoOZUSXtY5wAABdo"]
[Sun Aug 30 03:09:23.980585 2026] [security2:error] [pid 510357:tid 510515] [client 158.158.54.35:29077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/admin.php1"] [unique_id "apPlM35YTqJxoOZUSXtY8AAABc8"]
[Sun Aug 30 03:09:23.987729 2026] [security2:error] [pid 510357:tid 510598] [client 20.151.8.82:27592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/abcd.php"] [unique_id "apPlM35YTqJxoOZUSXtY8wAABiI"]
[Sun Aug 30 03:09:24.002962 2026] [security2:error] [pid 510357:tid 510593] [client 20.48.250.41:44819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/Jcrop.php"] [unique_id "apPlNH5YTqJxoOZUSXtY-AAABh0"]
[Sun Aug 30 03:09:24.021192 2026] [security2:error] [pid 510357:tid 510581] [client 20.104.50.220:63215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/bajah.php"] [unique_id "apPlNH5YTqJxoOZUSXtY_QAABhE"]
[Sun Aug 30 03:09:24.030443 2026] [security2:error] [pid 510357:tid 510540] [client 20.63.81.20:60233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/puc.php"] [unique_id "apPlNH5YTqJxoOZUSXtY_gAABeg"]
[Sun Aug 30 03:09:24.040621 2026] [security2:error] [pid 510357:tid 510576] [client 216.73.216.128:19315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/'+this.controller.state().get("] [unique_id "apPlNH5YTqJxoOZUSXtZAAAABgw"]
[Sun Aug 30 03:09:24.062095 2026] [security2:error] [pid 510357:tid 510607] [client 20.104.50.220:5910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/dor.php"] [unique_id "apPlNH5YTqJxoOZUSXtZBgAABis"]
[Sun Aug 30 03:09:24.107700 2026] [authz_core:error] [pid 510357:tid 510604] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:24.107975 2026] [authz_core:error] [pid 510357:tid 510604] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:24.128194 2026] [security2:error] [pid 510357:tid 510570] [client 158.23.184.117:12886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/wp-admin/.cfg_aae.php"] [unique_id "apPlNH5YTqJxoOZUSXtZGQAABgY"]
[Sun Aug 30 03:09:24.133573 2026] [security2:error] [pid 510357:tid 510494] [client 20.48.250.41:44983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/ws58.php"] [unique_id "apPlNH5YTqJxoOZUSXtZHAAABbo"]
[Sun Aug 30 03:09:24.156860 2026] [security2:error] [pid 510357:tid 510486] [remote 209.42.21.221:51470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.21.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "getabikini.com"] [uri "/wp-login.php"] [unique_id "apPlNH5YTqJxoOZUSXtZHwAFvXw"]
[Sun Aug 30 03:09:24.187097 2026] [security2:error] [pid 510357:tid 510581] [client 20.104.18.15:18240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/asdfghj.php"] [unique_id "apPlNH5YTqJxoOZUSXtZJQAABhE"]
[Sun Aug 30 03:09:24.191382 2026] [security2:error] [pid 510357:tid 510579] [client 20.63.81.20:60187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/19.php"] [unique_id "apPlNH5YTqJxoOZUSXtZKQAABg8"]
[Sun Aug 30 03:09:24.196677 2026] [security2:error] [pid 510357:tid 510572] [client 20.48.251.3:59840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/register.php"] [unique_id "apPlNH5YTqJxoOZUSXtZKwAABgg"]
[Sun Aug 30 03:09:24.203395 2026] [security2:error] [pid 510357:tid 510575] [client 20.104.49.130:63505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/css.php"] [unique_id "apPlNH5YTqJxoOZUSXtZMwAABgs"]
[Sun Aug 30 03:09:24.229046 2026] [security2:error] [pid 510357:tid 510611] [client 20.48.250.41:26547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/vx.php"] [unique_id "apPlNH5YTqJxoOZUSXtZPAAABi8"]
[Sun Aug 30 03:09:24.245548 2026] [security2:error] [pid 510357:tid 510508] [client 20.104.50.220:16601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/zwso.php"] [unique_id "apPlNH5YTqJxoOZUSXtZRAAABcg"]
[Sun Aug 30 03:09:24.247213 2026] [authz_core:error] [pid 510357:tid 510529] [client 66.249.66.194:55406] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:24.247661 2026] [authz_core:error] [pid 510357:tid 510529] [client 66.249.66.194:55406] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:24.269229 2026] [security2:error] [pid 510357:tid 510525] [client 158.23.184.117:13197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/wp-content/.wp_a1f.php"] [unique_id "apPlNH5YTqJxoOZUSXtZUgAABdk"]
[Sun Aug 30 03:09:24.279339 2026] [security2:error] [pid 510357:tid 510537] [client 20.48.250.41:45014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/xs.php"] [unique_id "apPlNH5YTqJxoOZUSXtZVgAABeU"]
[Sun Aug 30 03:09:24.292565 2026] [security2:error] [pid 510357:tid 510515] [client 195.178.110.247:29060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.meilianfuinc.com"] [uri "/index.php"] [unique_id "apPlNH5YTqJxoOZUSXtZWwAABc8"]
[Sun Aug 30 03:09:24.330128 2026] [security2:error] [pid 510357:tid 510570] [client 68.155.159.216:54331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apPlNH5YTqJxoOZUSXtZYgAABgY"]
[Sun Aug 30 03:09:24.335494 2026] [security2:error] [pid 510357:tid 510591] [client 20.63.81.20:60269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/133.php"] [unique_id "apPlNH5YTqJxoOZUSXtZZQAABhs"]
[Sun Aug 30 03:09:24.341784 2026] [security2:error] [pid 510357:tid 510594] [client 20.48.251.3:52808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/sadd.php"] [unique_id "apPlNH5YTqJxoOZUSXtZZwAABh4"]
[Sun Aug 30 03:09:24.365853 2026] [security2:error] [pid 510357:tid 510494] [client 34.100.204.203:52750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/p.php"] [unique_id "apPlNH5YTqJxoOZUSXtZbQAABbo"]
[Sun Aug 30 03:09:24.375012 2026] [security2:error] [pid 510357:tid 510516] [client 20.104.50.220:52856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/upppp.php"] [unique_id "apPlNH5YTqJxoOZUSXtZcQAABdA"]
[Sun Aug 30 03:09:24.414529 2026] [security2:error] [pid 510357:tid 510526] [client 20.48.250.41:45053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/zu.php"] [unique_id "apPlNH5YTqJxoOZUSXtZewAABdo"]
[Sun Aug 30 03:09:24.415691 2026] [security2:error] [pid 510357:tid 510572] [client 20.104.50.220:63517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/inc/config.php"] [unique_id "apPlNH5YTqJxoOZUSXtZfAAABgg"]
[Sun Aug 30 03:09:24.428376 2026] [security2:error] [pid 510357:tid 510508] [client 158.23.184.117:12890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/12.php"] [unique_id "apPlNH5YTqJxoOZUSXtZfgAABcg"]
[Sun Aug 30 03:09:24.446213 2026] [security2:error] [pid 510357:tid 510547] [client 20.104.49.130:36787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/wp-css.php"] [unique_id "apPlNH5YTqJxoOZUSXtZhwAABe8"]
[Sun Aug 30 03:09:24.456747 2026] [security2:error] [pid 510357:tid 510593] [client 20.104.18.15:43917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/sallu.php"] [unique_id "apPlNH5YTqJxoOZUSXtZjwAABh0"]
[Sun Aug 30 03:09:24.463042 2026] [security2:error] [pid 510357:tid 510586] [client 195.178.110.247:27766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.meilianfuinc.com"] [uri "/index.php"] [unique_id "apPlNH5YTqJxoOZUSXtZkwAABhY"]
[Sun Aug 30 03:09:24.474005 2026] [security2:error] [pid 510357:tid 510611] [client 158.158.54.35:2733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/hyIPpxWDQ.php"] [unique_id "apPlNH5YTqJxoOZUSXtZlwAABi8"]
[Sun Aug 30 03:09:24.477427 2026] [security2:error] [pid 510357:tid 510501] [client 20.104.50.220:29136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/slot.php"] [unique_id "apPlNH5YTqJxoOZUSXtZmgAABcE"]
[Sun Aug 30 03:09:24.479893 2026] [security2:error] [pid 510357:tid 510570] [client 20.63.81.20:60147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/1xmomo.php"] [unique_id "apPlNH5YTqJxoOZUSXtZmwAABgY"]
[Sun Aug 30 03:09:24.484082 2026] [security2:error] [pid 510357:tid 510563] [client 20.104.49.130:26649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/sym.php"] [unique_id "apPlNH5YTqJxoOZUSXtZnQAABf8"]
[Sun Aug 30 03:09:24.485795 2026] [security2:error] [pid 510357:tid 510596] [client 74.248.24.12:11694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/class_api.php"] [unique_id "apPlNH5YTqJxoOZUSXtZnwAABiA"]
[Sun Aug 30 03:09:24.488971 2026] [security2:error] [pid 510357:tid 510601] [client 20.48.250.41:26540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/global.php"] [unique_id "apPlNH5YTqJxoOZUSXtZogAABiU"]
[Sun Aug 30 03:09:24.500871 2026] [security2:error] [pid 510357:tid 510362] [remote 209.42.21.221:51470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.21.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "getabikini.com"] [uri "/wp-login.php"] [unique_id "apPlNH5YTqJxoOZUSXtZpQAGAgA"], referer: https://getabikini.com/wp-login.php
[Sun Aug 30 03:09:24.515114 2026] [authz_core:error] [pid 510357:tid 510589] [client 66.249.66.42:39798] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:24.515409 2026] [authz_core:error] [pid 510357:tid 510589] [client 66.249.66.42:39798] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:24.539493 2026] [authz_core:error] [pid 510357:tid 510595] [client 216.73.216.128:34642] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:24.539919 2026] [authz_core:error] [pid 510357:tid 510595] [client 216.73.216.128:34642] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:24.546813 2026] [security2:error] [pid 510357:tid 510532] [client 20.48.250.41:44950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/lanka.php"] [unique_id "apPlNH5YTqJxoOZUSXtZwQAABeA"]
[Sun Aug 30 03:09:24.547073 2026] [security2:error] [pid 510357:tid 510578] [client 219.94.128.161:0] ModSecurity: Warning. Matched phrase "LWP::Simple" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "bcwinetrends.com"] [uri "/2017/07/03/rose-gold-at-the-acwc/"] [unique_id "apPlNH5YTqJxoOZUSXtZvwAABg4"]
[Sun Aug 30 03:09:24.548603 2026] [authz_core:error] [pid 510357:tid 510547] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:24.548762 2026] [security2:error] [pid 510357:tid 510521] [client 219.94.128.161:62252] ModSecurity: Warning. Matched phrase "LWP::Simple" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "bcwinetrends.com"] [uri "/2017/07/03/rose-gold-at-the-acwc/"] [unique_id "apPlNH5YTqJxoOZUSXtZtQAABdU"]
[Sun Aug 30 03:09:24.549045 2026] [authz_core:error] [pid 510357:tid 510547] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:24.550300 2026] [security2:error] [pid 510357:tid 510505] [client 4.205.62.107:36570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/05.php"] [unique_id "apPlNH5YTqJxoOZUSXtZxAAABcU"]
[Sun Aug 30 03:09:24.589285 2026] [security2:error] [pid 510357:tid 510570] [client 20.48.251.3:13379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/public/mah.php.php"] [unique_id "apPlNH5YTqJxoOZUSXtZyQAABgY"]
[Sun Aug 30 03:09:24.599256 2026] [security2:error] [pid 510357:tid 510503] [client 158.23.184.117:13194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/colour.php"] [unique_id "apPlNH5YTqJxoOZUSXtZzQAABcM"]
[Sun Aug 30 03:09:24.614882 2026] [security2:error] [pid 510357:tid 510499] [client 20.63.81.20:60249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/mosty.php"] [unique_id "apPlNH5YTqJxoOZUSXtZ1AAABb8"]
[Sun Aug 30 03:09:24.618913 2026] [authz_core:error] [pid 510357:tid 510590] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:24.619325 2026] [authz_core:error] [pid 510357:tid 510590] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:24.623867 2026] [security2:error] [pid 510357:tid 510544] [client 20.48.250.41:26612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/fs.php"] [unique_id "apPlNH5YTqJxoOZUSXtZ2wAABew"]
[Sun Aug 30 03:09:24.642827 2026] [security2:error] [pid 510357:tid 510577] [client 20.104.50.220:59549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/alfateslav4.php"] [unique_id "apPlNH5YTqJxoOZUSXtZ6gAABg0"]
[Sun Aug 30 03:09:24.667478 2026] [security2:error] [pid 510357:tid 510495] [client 20.48.251.3:54797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlNH5YTqJxoOZUSXtZ-gAABbs"]
[Sun Aug 30 03:09:24.669554 2026] [security2:error] [pid 510357:tid 510537] [client 216.73.216.128:13315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlNH5YTqJxoOZUSXtZ_AAABeU"]
[Sun Aug 30 03:09:24.677966 2026] [security2:error] [pid 510357:tid 510570] [client 20.104.49.130:53711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/sxxb.php"] [unique_id "apPlNH5YTqJxoOZUSXtZ_wAABgY"]
[Sun Aug 30 03:09:24.701820 2026] [security2:error] [pid 510357:tid 510514] [client 20.48.250.41:45000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/gettest.php"] [unique_id "apPlNH5YTqJxoOZUSXtaCwAABc4"]
[Sun Aug 30 03:09:24.740364 2026] [security2:error] [pid 510357:tid 510563] [client 158.23.184.117:12708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/wp-admin/network/themes.php"] [unique_id "apPlNH5YTqJxoOZUSXtaFAAABf8"]
[Sun Aug 30 03:09:24.758438 2026] [security2:error] [pid 510357:tid 510523] [client 4.205.62.107:17315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/X57.php"] [unique_id "apPlNH5YTqJxoOZUSXtaGQAABdc"]
[Sun Aug 30 03:09:24.758577 2026] [security2:error] [pid 510357:tid 510555] [client 20.63.81.20:60190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/blurbs.php"] [unique_id "apPlNH5YTqJxoOZUSXtaGgAABfc"]
[Sun Aug 30 03:09:24.769772 2026] [security2:error] [pid 510357:tid 510521] [client 20.104.18.15:16760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/about.php"] [unique_id "apPlNH5YTqJxoOZUSXtaHwAABdU"]
[Sun Aug 30 03:09:24.775945 2026] [security2:error] [pid 510357:tid 510565] [client 4.205.62.107:25899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/infos.php"] [unique_id "apPlNH5YTqJxoOZUSXtaIgAABgE"]
[Sun Aug 30 03:09:24.787253 2026] [security2:error] [pid 510357:tid 510600] [client 20.48.250.41:26524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/ioxi.php"] [unique_id "apPlNH5YTqJxoOZUSXtaJgAABiQ"]
[Sun Aug 30 03:09:24.804684 2026] [security2:error] [pid 510357:tid 510596] [client 216.73.216.128:34642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlNH5YTqJxoOZUSXtaLQAABiA"]
[Sun Aug 30 03:09:24.830443 2026] [security2:error] [pid 510357:tid 510606] [client 68.155.159.216:63238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apPlNH5YTqJxoOZUSXtaNgAABio"]
[Sun Aug 30 03:09:24.832341 2026] [security2:error] [pid 510357:tid 510496] [client 20.48.250.41:44978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/35.php"] [unique_id "apPlNH5YTqJxoOZUSXtaNwAABbw"]
[Sun Aug 30 03:09:24.881966 2026] [security2:error] [pid 510357:tid 510576] [client 158.23.184.117:13232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/wp-admin/post.php"] [unique_id "apPlNH5YTqJxoOZUSXtaPQAABgw"]
[Sun Aug 30 03:09:24.896046 2026] [security2:error] [pid 510357:tid 510516] [client 216.73.216.128:24924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/about.html"] [unique_id "apPlNH5YTqJxoOZUSXtaQQAABdA"]
[Sun Aug 30 03:09:24.900404 2026] [security2:error] [pid 510357:tid 510531] [client 20.63.81.20:60273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/h.php"] [unique_id "apPlNH5YTqJxoOZUSXtaQwAABd8"]
[Sun Aug 30 03:09:24.925421 2026] [security2:error] [pid 510357:tid 510587] [client 4.205.62.107:64506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/bootstrap.php"] [unique_id "apPlNH5YTqJxoOZUSXtaRwAABhc"]
[Sun Aug 30 03:09:24.926322 2026] [security2:error] [pid 510357:tid 510609] [client 20.104.50.220:32296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-admin/js/wp-conflg.php"] [unique_id "apPlNH5YTqJxoOZUSXtaSAAABi0"]
[Sun Aug 30 03:09:24.943794 2026] [security2:error] [pid 510357:tid 510567] [client 20.151.200.44:41949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/4e.php"] [unique_id "apPlNH5YTqJxoOZUSXtaTwAABgM"]
[Sun Aug 30 03:09:24.952484 2026] [security2:error] [pid 510357:tid 510493] [client 20.48.250.41:26467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/bootstrap.php"] [unique_id "apPlNH5YTqJxoOZUSXtaUQAABbk"]
[Sun Aug 30 03:09:24.958525 2026] [security2:error] [pid 510357:tid 510605] [client 20.48.250.41:44894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/maraz.php"] [unique_id "apPlNH5YTqJxoOZUSXtaVQAABik"]
[Sun Aug 30 03:09:24.980490 2026] [security2:error] [pid 510357:tid 510558] [client 158.158.54.35:29372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/BIBIL_0DAY.php/global.php"] [unique_id "apPlNH5YTqJxoOZUSXtaZQAABfo"]
[Sun Aug 30 03:09:25.025047 2026] [security2:error] [pid 510357:tid 510607] [client 74.248.24.12:13890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/configs.php"] [unique_id "apPlNX5YTqJxoOZUSXtaeAAABis"]
[Sun Aug 30 03:09:25.025672 2026] [security2:error] [pid 510357:tid 510529] [client 20.104.18.15:2037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/c4.php"] [unique_id "apPlNX5YTqJxoOZUSXtaeQAABd0"]
[Sun Aug 30 03:09:25.026329 2026] [security2:error] [pid 510357:tid 510523] [client 158.23.184.117:13246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPlNX5YTqJxoOZUSXtaegAABdc"]
[Sun Aug 30 03:09:25.036813 2026] [security2:error] [pid 510357:tid 510559] [client 216.73.216.128:35992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlNX5YTqJxoOZUSXtafAAABfs"]
[Sun Aug 30 03:09:25.058892 2026] [security2:error] [pid 510357:tid 510508] [client 20.63.81.20:60172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/ano.php"] [unique_id "apPlNX5YTqJxoOZUSXtafwAABcg"]
[Sun Aug 30 03:09:25.071799 2026] [security2:error] [pid 510357:tid 510538] [client 20.151.8.82:16686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/wp-manager.php"] [unique_id "apPlNX5YTqJxoOZUSXtagAAABeY"]
[Sun Aug 30 03:09:25.079180 2026] [security2:error] [pid 510357:tid 510596] [client 20.104.49.130:48031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/log.php"] [unique_id "apPlNX5YTqJxoOZUSXtaggAABiA"]
[Sun Aug 30 03:09:25.087440 2026] [security2:error] [pid 510357:tid 510578] [client 20.48.250.41:44933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/kbfr.php"] [unique_id "apPlNX5YTqJxoOZUSXtahAAABg4"]
[Sun Aug 30 03:09:25.108272 2026] [authz_core:error] [pid 510357:tid 510494] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:25.108685 2026] [authz_core:error] [pid 510357:tid 510494] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:25.121523 2026] [security2:error] [pid 510357:tid 510512] [client 20.104.18.15:35158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/indo.php"] [unique_id "apPlNX5YTqJxoOZUSXtakgAABcw"]
[Sun Aug 30 03:09:25.122164 2026] [authz_core:error] [pid 510357:tid 510565] [client 66.249.66.40:63814] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:25.122611 2026] [authz_core:error] [pid 510357:tid 510565] [client 66.249.66.40:63814] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:25.129897 2026] [security2:error] [pid 510357:tid 510540] [client 20.48.250.41:26607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/export.php"] [unique_id "apPlNX5YTqJxoOZUSXtalwAABeg"]
[Sun Aug 30 03:09:25.134420 2026] [security2:error] [pid 510357:tid 510580] [client 20.151.8.82:27624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/simple.php"] [unique_id "apPlNX5YTqJxoOZUSXtamgAABhA"]
[Sun Aug 30 03:09:25.158273 2026] [security2:error] [pid 510357:tid 510511] [client 20.104.50.220:63210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/cream1.php"] [unique_id "apPlNX5YTqJxoOZUSXtangAABcs"]
[Sun Aug 30 03:09:25.170020 2026] [security2:error] [pid 510357:tid 510599] [client 34.100.204.203:50442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/debug.php"] [unique_id "apPlNX5YTqJxoOZUSXtapAAABiM"]
[Sun Aug 30 03:09:25.193821 2026] [security2:error] [pid 510357:tid 510504] [client 20.63.81.20:60280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/ai.php"] [unique_id "apPlNX5YTqJxoOZUSXtatAAABcQ"]
[Sun Aug 30 03:09:25.201373 2026] [security2:error] [pid 510357:tid 510548] [client 20.151.8.82:16638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "apPlNX5YTqJxoOZUSXtatwAABfA"]
[Sun Aug 30 03:09:25.212184 2026] [security2:error] [pid 510357:tid 510526] [client 158.23.184.117:13243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/wp-content/post.php"] [unique_id "apPlNX5YTqJxoOZUSXtavgAABdo"]
[Sun Aug 30 03:09:25.214806 2026] [security2:error] [pid 510357:tid 510554] [client 20.104.50.220:5562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/coy.php"] [unique_id "apPlNX5YTqJxoOZUSXtawAAABfY"]
[Sun Aug 30 03:09:25.219976 2026] [security2:error] [pid 510357:tid 510615] [client 216.73.216.128:1674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_config_quote_replace_string"] [unique_id "apPlNX5YTqJxoOZUSXtawgAABjM"]
[Sun Aug 30 03:09:25.231808 2026] [security2:error] [pid 510357:tid 510563] [client 20.48.250.41:44936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/wp-act.php"] [unique_id "apPlNX5YTqJxoOZUSXtaxwAABf8"]
[Sun Aug 30 03:09:25.260442 2026] [security2:error] [pid 510357:tid 510613] [client 20.48.250.41:26615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/gk.php"] [unique_id "apPlNX5YTqJxoOZUSXta1gAABjE"]
[Sun Aug 30 03:09:25.262749 2026] [security2:error] [pid 510357:tid 510608] [client 20.151.8.82:27601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/chosen.php"] [unique_id "apPlNX5YTqJxoOZUSXta2AAABiw"]
[Sun Aug 30 03:09:25.277852 2026] [authz_core:error] [pid 510357:tid 510512] [client 66.249.66.70:36603] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:25.278131 2026] [authz_core:error] [pid 510357:tid 510512] [client 66.249.66.70:36603] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:25.327492 2026] [security2:error] [pid 510357:tid 510533] [client 20.63.81.20:60212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/sf.php"] [unique_id "apPlNX5YTqJxoOZUSXta6gAABeE"]
[Sun Aug 30 03:09:25.333302 2026] [security2:error] [pid 510357:tid 510611] [client 20.151.200.44:46019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/file.php"] [unique_id "apPlNX5YTqJxoOZUSXta7QAABi8"]
[Sun Aug 30 03:09:25.334051 2026] [security2:error] [pid 510357:tid 510528] [client 20.151.8.82:16737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/cgi-bin/admin.php"] [unique_id "apPlNX5YTqJxoOZUSXta7gAABdw"]
[Sun Aug 30 03:09:25.347286 2026] [security2:error] [pid 510357:tid 510562] [client 20.104.18.15:18342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/dragonshell.php"] [unique_id "apPlNX5YTqJxoOZUSXta9QAABf4"]
[Sun Aug 30 03:09:25.353305 2026] [security2:error] [pid 510357:tid 510510] [client 20.48.251.3:52278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/xqq.php"] [unique_id "apPlNX5YTqJxoOZUSXta-AAABco"]
[Sun Aug 30 03:09:25.375289 2026] [security2:error] [pid 510357:tid 510597] [client 20.104.50.220:16664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "apPlNX5YTqJxoOZUSXta-gAABiE"]
[Sun Aug 30 03:09:25.393931 2026] [security2:error] [pid 510357:tid 510515] [client 20.48.250.41:26608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/logs1.php"] [unique_id "apPlNX5YTqJxoOZUSXta_AAABc8"]
[Sun Aug 30 03:09:25.394589 2026] [security2:error] [pid 510357:tid 510561] [client 20.151.8.82:27529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/als.php"] [unique_id "apPlNX5YTqJxoOZUSXta_QAABf0"]
[Sun Aug 30 03:09:25.403158 2026] [security2:error] [pid 510357:tid 510577] [client 20.48.250.41:44915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/24.php"] [unique_id "apPlNX5YTqJxoOZUSXtbAQAABg0"]
[Sun Aug 30 03:09:25.404302 2026] [security2:error] [pid 510357:tid 510494] [client 158.23.184.117:13228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "apPlNX5YTqJxoOZUSXtbAgAABbo"]
[Sun Aug 30 03:09:25.424551 2026] [security2:error] [pid 510357:tid 510507] [client 158.158.54.35:29369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/fxcexgle.php"] [unique_id "apPlNX5YTqJxoOZUSXtbBgAABcc"]
[Sun Aug 30 03:09:25.483057 2026] [security2:error] [pid 510357:tid 510572] [client 20.48.251.3:59317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/application.config.php"] [unique_id "apPlNX5YTqJxoOZUSXtbLAAABgg"]
[Sun Aug 30 03:09:25.513325 2026] [security2:error] [pid 510357:tid 510497] [client 20.63.81.20:60177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/xx.php"] [unique_id "apPlNX5YTqJxoOZUSXtbPwAABb0"]
[Sun Aug 30 03:09:25.523265 2026] [security2:error] [pid 510357:tid 510507] [client 20.151.8.82:27522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/nox.php"] [unique_id "apPlNX5YTqJxoOZUSXtbQgAABcc"]
[Sun Aug 30 03:09:25.533058 2026] [security2:error] [pid 510357:tid 510531] [client 20.104.50.220:29177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/up.php"] [unique_id "apPlNX5YTqJxoOZUSXtbSAAABd8"]
[Sun Aug 30 03:09:25.539815 2026] [security2:error] [pid 510357:tid 510612] [client 74.248.24.12:13918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/update.php"] [unique_id "apPlNX5YTqJxoOZUSXtbTQAABjA"]
[Sun Aug 30 03:09:25.553786 2026] [security2:error] [pid 510357:tid 510529] [client 20.48.250.41:44943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/155.php"] [unique_id "apPlNX5YTqJxoOZUSXtbVQAABd0"]
[Sun Aug 30 03:09:25.557324 2026] [security2:error] [pid 510357:tid 510591] [client 103.215.74.185:6980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.74.215.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "162.144.1.153"] [uri "/register"] [unique_id "apPlNX5YTqJxoOZUSXtbSwAABhs"]
[Sun Aug 30 03:09:25.557403 2026] [security2:error] [pid 510357:tid 510591] [client 103.215.74.185:6980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "160"] [id "900408"] [msg "register POST logging"] [data "409"] [hostname "162.144.1.153"] [uri "/register"] [unique_id "apPlNX5YTqJxoOZUSXtbSwAABhs"]
[Sun Aug 30 03:09:25.558059 2026] [security2:error] [pid 510357:tid 510568] [client 20.104.50.220:42781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/ix.php"] [unique_id "apPlNX5YTqJxoOZUSXtbVwAABgQ"]
[Sun Aug 30 03:09:25.591247 2026] [security2:error] [pid 510357:tid 510492] [client 158.23.184.117:13200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/ma.php"] [unique_id "apPlNX5YTqJxoOZUSXtbZAAABbg"]
[Sun Aug 30 03:09:25.602656 2026] [authz_core:error] [pid 510357:tid 510505] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:25.603095 2026] [authz_core:error] [pid 510357:tid 510505] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:25.605527 2026] [security2:error] [pid 510357:tid 510510] [client 20.48.250.41:26437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/inege.php"] [unique_id "apPlNX5YTqJxoOZUSXtbbwAABco"]
[Sun Aug 30 03:09:25.621655 2026] [security2:error] [pid 510357:tid 510497] [client 20.104.18.15:43280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/codex.php"] [unique_id "apPlNX5YTqJxoOZUSXtbegAABb0"]
[Sun Aug 30 03:09:25.634850 2026] [security2:error] [pid 510357:tid 510549] [client 20.104.50.220:28697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/sad.php"] [unique_id "apPlNX5YTqJxoOZUSXtbgwAABfE"]
[Sun Aug 30 03:09:25.654082 2026] [security2:error] [pid 510357:tid 510513] [client 103.215.74.185:6990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.74.215.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "162.144.1.153"] [uri "/register"] [unique_id "apPlNX5YTqJxoOZUSXtblQAABc0"]
[Sun Aug 30 03:09:25.654196 2026] [security2:error] [pid 510357:tid 510513] [client 103.215.74.185:6990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "160"] [id "900408"] [msg "register POST logging"] [data "409"] [hostname "162.144.1.153"] [uri "/register"] [unique_id "apPlNX5YTqJxoOZUSXtblQAABc0"]
[Sun Aug 30 03:09:25.659841 2026] [security2:error] [pid 510357:tid 510492] [client 20.151.8.82:27542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/file59.php"] [unique_id "apPlNX5YTqJxoOZUSXtblgAABbg"]
[Sun Aug 30 03:09:25.672102 2026] [security2:error] [pid 510357:tid 510596] [client 20.63.81.20:60271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/uwu.php"] [unique_id "apPlNX5YTqJxoOZUSXtbngAABiA"]
[Sun Aug 30 03:09:25.685456 2026] [security2:error] [pid 510357:tid 510593] [client 20.48.250.41:45035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/file.php"] [unique_id "apPlNX5YTqJxoOZUSXtbpwAABh0"]
[Sun Aug 30 03:09:25.723853 2026] [security2:error] [pid 510357:tid 510501] [client 20.48.251.3:60487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/zaza.php"] [unique_id "apPlNX5YTqJxoOZUSXtbuwAABcE"]
[Sun Aug 30 03:09:25.739284 2026] [security2:error] [pid 510357:tid 510583] [client 20.48.250.41:26497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/wp-link10.php"] [unique_id "apPlNX5YTqJxoOZUSXtbvQAABhM"]
[Sun Aug 30 03:09:25.767125 2026] [security2:error] [pid 510357:tid 510540] [client 4.205.62.107:36010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/wp-blog.php"] [unique_id "apPlNX5YTqJxoOZUSXtbwAAABeg"]
[Sun Aug 30 03:09:25.797881 2026] [security2:error] [pid 510357:tid 510551] [client 20.104.50.220:61418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/alwso.php"] [unique_id "apPlNX5YTqJxoOZUSXtbywAABfM"]
[Sun Aug 30 03:09:25.800522 2026] [authz_core:error] [pid 510357:tid 510544] [client 66.249.66.70:49812] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:25.800842 2026] [authz_core:error] [pid 510357:tid 510544] [client 66.249.66.70:49812] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:25.801216 2026] [security2:error] [pid 510357:tid 510558] [client 20.151.8.82:27629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/admin.php"] [unique_id "apPlNX5YTqJxoOZUSXtbzgAABfo"]
[Sun Aug 30 03:09:25.806290 2026] [security2:error] [pid 510357:tid 510590] [client 20.48.251.3:65490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlNX5YTqJxoOZUSXtb0gAABho"]
[Sun Aug 30 03:09:25.809426 2026] [security2:error] [pid 510357:tid 510510] [client 20.63.81.20:60275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/signon.php"] [unique_id "apPlNX5YTqJxoOZUSXtb1AAABco"]
[Sun Aug 30 03:09:25.822098 2026] [security2:error] [pid 510357:tid 510506] [client 20.48.250.41:45022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPlNX5YTqJxoOZUSXtb2gAABcY"]
[Sun Aug 30 03:09:25.854506 2026] [security2:error] [pid 510357:tid 510562] [client 158.23.184.117:13196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/xleet.php"] [unique_id "apPlNX5YTqJxoOZUSXtb2wAABf4"]
[Sun Aug 30 03:09:25.854528 2026] [security2:error] [pid 510357:tid 510617] [client 20.151.8.82:16601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "apPlNX5YTqJxoOZUSXtb3AAABjU"]
[Sun Aug 30 03:09:25.882661 2026] [security2:error] [pid 510357:tid 510581] [client 20.48.250.41:26592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/ww.php"] [unique_id "apPlNX5YTqJxoOZUSXtb3wAABhE"]
[Sun Aug 30 03:09:25.886525 2026] [security2:error] [pid 510357:tid 510603] [client 158.158.54.35:30465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/NFXxUAA.php"] [unique_id "apPlNX5YTqJxoOZUSXtb4QAABic"]
[Sun Aug 30 03:09:25.887488 2026] [security2:error] [pid 510357:tid 510612] [client 4.205.62.107:17151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/register.php"] [unique_id "apPlNX5YTqJxoOZUSXtb4gAABjA"]
[Sun Aug 30 03:09:25.931848 2026] [security2:error] [pid 510357:tid 510545] [client 20.151.8.82:27588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/aa2.php"] [unique_id "apPlNX5YTqJxoOZUSXtb7wAABe0"]
[Sun Aug 30 03:09:25.939250 2026] [security2:error] [pid 510357:tid 510532] [client 4.205.62.107:25916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/env.php"] [unique_id "apPlNX5YTqJxoOZUSXtb8wAABeA"]
[Sun Aug 30 03:09:25.958597 2026] [security2:error] [pid 510357:tid 510492] [client 68.155.159.216:62604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apPlNX5YTqJxoOZUSXtb-QAABbg"]
[Sun Aug 30 03:09:25.960817 2026] [security2:error] [pid 510357:tid 510528] [client 20.63.81.20:60267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/file61.php"] [unique_id "apPlNX5YTqJxoOZUSXtb_gAABdw"]
[Sun Aug 30 03:09:25.975580 2026] [security2:error] [pid 510357:tid 510596] [client 20.48.250.41:44957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/06.php"] [unique_id "apPlNX5YTqJxoOZUSXtcBwAABiA"]
[Sun Aug 30 03:09:25.982896 2026] [security2:error] [pid 510357:tid 510525] [client 20.104.49.130:63552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/classwithtostring.php"] [unique_id "apPlNX5YTqJxoOZUSXtcDQAABdk"]
[Sun Aug 30 03:09:25.992751 2026] [security2:error] [pid 510357:tid 510566] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlNX5YTqJxoOZUSXtcFgAABgI"]
[Sun Aug 30 03:09:25.994407 2026] [security2:error] [pid 510357:tid 510540] [client 158.23.184.117:13217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/.well-known/pki-validation/fm.php"] [unique_id "apPlNX5YTqJxoOZUSXtcGAAABeg"]
[Sun Aug 30 03:09:26.005712 2026] [security2:error] [pid 510357:tid 510606] [client 34.100.204.203:50454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/admin/phpinfo.php"] [unique_id "apPlNn5YTqJxoOZUSXtcHAAABio"]
[Sun Aug 30 03:09:26.017514 2026] [authz_core:error] [pid 510357:tid 510608] [client 66.249.66.192:65080] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:26.017828 2026] [security2:error] [pid 510357:tid 510497] [client 20.48.250.41:26463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/w1px.php"] [unique_id "apPlNn5YTqJxoOZUSXtcIwAABb0"]
[Sun Aug 30 03:09:26.017864 2026] [authz_core:error] [pid 510357:tid 510608] [client 66.249.66.192:65080] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:26.035106 2026] [security2:error] [pid 510357:tid 510586] [client 20.104.50.220:32849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/mail.php"] [unique_id "apPlNn5YTqJxoOZUSXtcKAAABhY"]
[Sun Aug 30 03:09:26.052989 2026] [authz_core:error] [pid 510357:tid 510604] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:26.053415 2026] [authz_core:error] [pid 510357:tid 510604] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:26.058967 2026] [security2:error] [pid 510357:tid 510503] [client 74.248.24.12:38143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.24.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "b6standards.com"] [uri "/input.php"] [unique_id "apPlNn5YTqJxoOZUSXtcLQAABcM"]
[Sun Aug 30 03:09:26.096832 2026] [security2:error] [pid 510357:tid 510563] [client 20.104.50.220:32566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/classwithtostring.php"] [unique_id "apPlNn5YTqJxoOZUSXtcNAAABf8"]
[Sun Aug 30 03:09:26.116174 2026] [authz_core:error] [pid 510357:tid 510504] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:26.116478 2026] [authz_core:error] [pid 510357:tid 510504] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:26.132364 2026] [security2:error] [pid 510357:tid 510540] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlNn5YTqJxoOZUSXtcQgAABeg"]
[Sun Aug 30 03:09:26.136224 2026] [security2:error] [pid 510357:tid 510590] [client 158.23.184.117:13211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/wp-admin/user.php"] [unique_id "apPlNn5YTqJxoOZUSXtcRQAABho"]
[Sun Aug 30 03:09:26.141398 2026] [security2:error] [pid 510357:tid 510609] [client 20.63.81.20:60234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/copypaths.php"] [unique_id "apPlNn5YTqJxoOZUSXtcSAAABi0"]
[Sun Aug 30 03:09:26.165197 2026] [security2:error] [pid 510357:tid 510617] [client 20.48.250.41:44877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/class.php"] [unique_id "apPlNn5YTqJxoOZUSXtcSwAABjU"]
[Sun Aug 30 03:09:26.172765 2026] [security2:error] [pid 510357:tid 510557] [client 20.104.18.15:2003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/rxr.php"] [unique_id "apPlNn5YTqJxoOZUSXtcTQAABfk"]
[Sun Aug 30 03:09:26.179992 2026] [security2:error] [pid 510357:tid 510554] [client 103.215.74.185:63020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.74.215.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "162.144.1.153"] [uri "/register"] [unique_id "apPlNn5YTqJxoOZUSXtcUAAABfY"]
[Sun Aug 30 03:09:26.180084 2026] [security2:error] [pid 510357:tid 510554] [client 103.215.74.185:63020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "160"] [id "900408"] [msg "register POST logging"] [data "409"] [hostname "162.144.1.153"] [uri "/register"] [unique_id "apPlNn5YTqJxoOZUSXtcUAAABfY"]
[Sun Aug 30 03:09:26.181753 2026] [security2:error] [pid 510357:tid 510613] [client 20.48.250.41:26584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/to.php"] [unique_id "apPlNn5YTqJxoOZUSXtcUQAABjE"]
[Sun Aug 30 03:09:26.211419 2026] [security2:error] [pid 510357:tid 510536] [client 20.104.49.130:60636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/sta.php"] [unique_id "apPlNn5YTqJxoOZUSXtcWgAABeQ"]
[Sun Aug 30 03:09:26.256840 2026] [security2:error] [pid 510357:tid 510495] [client 4.205.62.107:61744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/333.php"] [unique_id "apPlNn5YTqJxoOZUSXtcbAAABbs"]
[Sun Aug 30 03:09:26.276388 2026] [security2:error] [pid 510357:tid 510540] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/media.php"] [unique_id "apPlNn5YTqJxoOZUSXtcewAABeg"]
[Sun Aug 30 03:09:26.279523 2026] [security2:error] [pid 510357:tid 510577] [client 158.23.184.117:13231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/wp-admin/radio.php"] [unique_id "apPlNn5YTqJxoOZUSXtcfAAABg0"]
[Sun Aug 30 03:09:26.294119 2026] [security2:error] [pid 510357:tid 510550] [client 20.63.81.20:60214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/bless6.php"] [unique_id "apPlNn5YTqJxoOZUSXtcggAABfI"]
[Sun Aug 30 03:09:26.297606 2026] [security2:error] [pid 510357:tid 510561] [client 20.104.18.15:35516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/sign.php"] [unique_id "apPlNn5YTqJxoOZUSXtchAAABf0"]
[Sun Aug 30 03:09:26.302111 2026] [security2:error] [pid 510357:tid 510558] [client 20.48.250.41:44953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/8.php"] [unique_id "apPlNn5YTqJxoOZUSXtchgAABfo"]
[Sun Aug 30 03:09:26.322532 2026] [security2:error] [pid 510357:tid 510497] [client 20.104.50.220:63203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/lim.php"] [unique_id "apPlNn5YTqJxoOZUSXtciQAABb0"]
[Sun Aug 30 03:09:26.341212 2026] [security2:error] [pid 510357:tid 510529] [client 20.48.250.41:26586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/thui.php"] [unique_id "apPlNn5YTqJxoOZUSXtcjwAABd0"]
[Sun Aug 30 03:09:26.352954 2026] [security2:error] [pid 510357:tid 510605] [client 20.104.50.220:5917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/hehe.php"] [unique_id "apPlNn5YTqJxoOZUSXtckAAABik"]
[Sun Aug 30 03:09:26.369953 2026] [security2:error] [pid 510357:tid 510505] [client 158.158.54.35:8266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/blog.php7"] [unique_id "apPlNn5YTqJxoOZUSXtckwAABcU"]
[Sun Aug 30 03:09:26.401330 2026] [security2:error] [pid 510357:tid 510600] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/adminfuns.php"] [unique_id "apPlNn5YTqJxoOZUSXtcmQAABiQ"]
[Sun Aug 30 03:09:26.439932 2026] [security2:error] [pid 510357:tid 510562] [client 20.63.81.20:60237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/special.php"] [unique_id "apPlNn5YTqJxoOZUSXtcpAAABf4"]
[Sun Aug 30 03:09:26.446206 2026] [security2:error] [pid 510357:tid 510569] [client 216.73.216.128:44752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_config_quote_replace_string"] [unique_id "apPlNn5YTqJxoOZUSXtcqQAABgU"]
[Sun Aug 30 03:09:26.446725 2026] [security2:error] [pid 510357:tid 510581] [client 20.48.250.41:45017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/0x0x.php"] [unique_id "apPlNn5YTqJxoOZUSXtcqgAABhE"]
[Sun Aug 30 03:09:26.465937 2026] [security2:error] [pid 510357:tid 510556] [client 68.155.159.216:54334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/chosen.php"] [unique_id "apPlNn5YTqJxoOZUSXtcugAABfg"]
[Sun Aug 30 03:09:26.488726 2026] [security2:error] [pid 510357:tid 510605] [client 20.48.251.3:59460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/a1vx.php"] [unique_id "apPlNn5YTqJxoOZUSXtcxAAABik"]
[Sun Aug 30 03:09:26.497300 2026] [security2:error] [pid 510357:tid 510552] [client 20.104.18.15:18291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/wp-safe.php"] [unique_id "apPlNn5YTqJxoOZUSXtcyAAABfQ"]
[Sun Aug 30 03:09:26.504423 2026] [security2:error] [pid 510357:tid 510505] [client 20.104.50.220:16593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/class19.php"] [unique_id "apPlNn5YTqJxoOZUSXtcyQAABcU"]
[Sun Aug 30 03:09:26.512713 2026] [security2:error] [pid 510357:tid 510572] [client 20.48.250.41:26503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/Jcrop.php"] [unique_id "apPlNn5YTqJxoOZUSXtczwAABgg"]
[Sun Aug 30 03:09:26.522795 2026] [security2:error] [pid 510357:tid 510504] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/classwithtostring.php"] [unique_id "apPlNn5YTqJxoOZUSXtc0gAABcQ"]
[Sun Aug 30 03:09:26.536264 2026] [security2:error] [pid 510357:tid 510543] [client 20.104.49.130:60124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/ab.php"] [unique_id "apPlNn5YTqJxoOZUSXtc1wAABes"]
[Sun Aug 30 03:09:26.557270 2026] [security2:error] [pid 510357:tid 510506] [client 158.23.184.117:13224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/bypass.php7"] [unique_id "apPlNn5YTqJxoOZUSXtc5wAABcY"]
[Sun Aug 30 03:09:26.573069 2026] [security2:error] [pid 510357:tid 510500] [client 20.104.49.130:63283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/berlin.php"] [unique_id "apPlNn5YTqJxoOZUSXtc6wAABcA"]
[Sun Aug 30 03:09:26.581991 2026] [security2:error] [pid 510357:tid 510548] [client 20.48.250.41:44886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/166.php"] [unique_id "apPlNn5YTqJxoOZUSXtc7AAABfA"]
[Sun Aug 30 03:09:26.585663 2026] [security2:error] [pid 510357:tid 510606] [client 20.104.49.130:63522] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.thepiako.com"] [uri "/1.php"] [unique_id "apPlNn5YTqJxoOZUSXtc7QAABio"]
[Sun Aug 30 03:09:26.585745 2026] [security2:error] [pid 510357:tid 510606] [client 20.104.49.130:63522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/1.php"] [unique_id "apPlNn5YTqJxoOZUSXtc7QAABio"]
[Sun Aug 30 03:09:26.597714 2026] [security2:error] [pid 510357:tid 510521] [client 20.63.81.20:60185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/fz.php"] [unique_id "apPlNn5YTqJxoOZUSXtc9QAABdU"]
[Sun Aug 30 03:09:26.610007 2026] [security2:error] [pid 510357:tid 510529] [client 20.151.200.44:46000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/ca.php"] [unique_id "apPlNn5YTqJxoOZUSXtc-wAABd0"]
[Sun Aug 30 03:09:26.618419 2026] [security2:error] [pid 510357:tid 510572] [client 20.48.251.3:55695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/xp.php"] [unique_id "apPlNn5YTqJxoOZUSXtdAgAABgg"]
[Sun Aug 30 03:09:26.621122 2026] [authz_core:error] [pid 510357:tid 510552] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:26.621558 2026] [authz_core:error] [pid 510357:tid 510552] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:26.643435 2026] [security2:error] [pid 510357:tid 510581] [client 20.48.250.41:26519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/ws58.php"] [unique_id "apPlNn5YTqJxoOZUSXtdFQAABhE"]
[Sun Aug 30 03:09:26.644873 2026] [security2:error] [pid 510357:tid 510577] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPlNn5YTqJxoOZUSXtdFwAABg0"]
[Sun Aug 30 03:09:26.684369 2026] [security2:error] [pid 510357:tid 510493] [client 20.104.50.220:63040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/l3.php"] [unique_id "apPlNn5YTqJxoOZUSXtdMAAABbk"]
[Sun Aug 30 03:09:26.693590 2026] [security2:error] [pid 510357:tid 510572] [client 20.104.104.62:3458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-b8b870f5.filtagreen.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlNn5YTqJxoOZUSXtdNAAABgg"]
[Sun Aug 30 03:09:26.697196 2026] [security2:error] [pid 510357:tid 510607] [client 158.23.184.117:12887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/wp-admin/css/colors/midnight/wp-login.php"] [unique_id "apPlNn5YTqJxoOZUSXtdNwAABis"]
[Sun Aug 30 03:09:26.697225 2026] [security2:error] [pid 510357:tid 510539] [client 20.104.50.220:51560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/r0x.php"] [unique_id "apPlNn5YTqJxoOZUSXtdOAAABec"]
[Sun Aug 30 03:09:26.730855 2026] [security2:error] [pid 510357:tid 510553] [client 20.48.250.41:45030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/h2a2ck.php"] [unique_id "apPlNn5YTqJxoOZUSXtdTgAABfU"]
[Sun Aug 30 03:09:26.736238 2026] [security2:error] [pid 510357:tid 510511] [client 34.100.204.203:50464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/test/phpinfo.php"] [unique_id "apPlNn5YTqJxoOZUSXtdUAAABcs"]
[Sun Aug 30 03:09:26.740794 2026] [security2:error] [pid 510357:tid 510496] [client 20.63.81.20:60283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/clque.php"] [unique_id "apPlNn5YTqJxoOZUSXtdUgAABbw"]
[Sun Aug 30 03:09:26.757986 2026] [security2:error] [pid 510357:tid 510502] [client 20.104.18.15:43281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/5656.php"] [unique_id "apPlNn5YTqJxoOZUSXtdUwAABcI"]
[Sun Aug 30 03:09:26.769659 2026] [security2:error] [pid 510357:tid 510557] [client 103.215.74.185:63022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.74.215.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "162.144.1.153"] [uri "/register"] [unique_id "apPlNn5YTqJxoOZUSXtdVQAABfk"]
[Sun Aug 30 03:09:26.769756 2026] [security2:error] [pid 510357:tid 510557] [client 103.215.74.185:63022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "160"] [id "900408"] [msg "register POST logging"] [data "409"] [hostname "162.144.1.153"] [uri "/register"] [unique_id "apPlNn5YTqJxoOZUSXtdVQAABfk"]
[Sun Aug 30 03:09:26.771610 2026] [security2:error] [pid 510357:tid 510614] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPlNn5YTqJxoOZUSXtdVgAABjI"]
[Sun Aug 30 03:09:26.779845 2026] [security2:error] [pid 510357:tid 510570] [client 20.104.50.220:64448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/sec.php"] [unique_id "apPlNn5YTqJxoOZUSXtdWAAABgY"]
[Sun Aug 30 03:09:26.793911 2026] [security2:error] [pid 510357:tid 510587] [client 20.48.250.41:26590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/xs.php"] [unique_id "apPlNn5YTqJxoOZUSXtdXAAABhc"]
[Sun Aug 30 03:09:26.825882 2026] [security2:error] [pid 510357:tid 510576] [client 158.23.147.79:57671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlNn5YTqJxoOZUSXtdaQAABgw"]
[Sun Aug 30 03:09:26.871216 2026] [security2:error] [pid 510357:tid 510532] [client 20.48.251.3:13385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/u88.php"] [unique_id "apPlNn5YTqJxoOZUSXtdbgAABeA"]
[Sun Aug 30 03:09:26.874853 2026] [security2:error] [pid 510357:tid 510577] [client 20.48.250.41:44944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/error_log.php"] [unique_id "apPlNn5YTqJxoOZUSXtdcAAABg0"]
[Sun Aug 30 03:09:26.875195 2026] [security2:error] [pid 510357:tid 510586] [client 20.63.81.20:60176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/nano.php"] [unique_id "apPlNn5YTqJxoOZUSXtdcgAABhY"]
[Sun Aug 30 03:09:26.898904 2026] [security2:error] [pid 510357:tid 510538] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wsd.php"] [unique_id "apPlNn5YTqJxoOZUSXtdewAABeY"]
[Sun Aug 30 03:09:26.903728 2026] [security2:error] [pid 510357:tid 510508] [client 158.23.184.117:12877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/leafmailer.php"] [unique_id "apPlNn5YTqJxoOZUSXtdfgAABcg"]
[Sun Aug 30 03:09:26.911203 2026] [security2:error] [pid 510357:tid 510603] [client 4.205.62.107:36631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/erty.php"] [unique_id "apPlNn5YTqJxoOZUSXtdggAABic"]
[Sun Aug 30 03:09:26.918540 2026] [authz_core:error] [pid 510357:tid 510591] [client 66.249.66.32:44477] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:26.919058 2026] [authz_core:error] [pid 510357:tid 510591] [client 66.249.66.32:44477] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:26.920585 2026] [security2:error] [pid 510357:tid 510594] [client 20.104.18.15:64867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/about.php"] [unique_id "apPlNn5YTqJxoOZUSXtdhQAABh4"]
[Sun Aug 30 03:09:26.931119 2026] [security2:error] [pid 510357:tid 510579] [client 158.158.54.35:24696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/aQzODIgoBr.php"] [unique_id "apPlNn5YTqJxoOZUSXtdiQAABg8"]
[Sun Aug 30 03:09:26.944215 2026] [security2:error] [pid 510357:tid 510578] [client 20.48.251.3:65480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/cloud.php"] [unique_id "apPlNn5YTqJxoOZUSXtdiwAABg4"]
[Sun Aug 30 03:09:26.946548 2026] [security2:error] [pid 510357:tid 510570] [client 20.104.50.220:59557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/anjay.php"] [unique_id "apPlNn5YTqJxoOZUSXtdjAAABgY"]
[Sun Aug 30 03:09:26.955332 2026] [security2:error] [pid 510357:tid 510606] [client 20.48.250.41:26455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/zu.php"] [unique_id "apPlNn5YTqJxoOZUSXtdjgAABio"]
[Sun Aug 30 03:09:26.998041 2026] [security2:error] [pid 510357:tid 510505] [client 20.151.8.82:16629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apPlNn5YTqJxoOZUSXtdpAAABcU"]
[Sun Aug 30 03:09:27.003706 2026] [security2:error] [pid 510357:tid 510520] [client 20.104.18.15:22471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlN35YTqJxoOZUSXtdqQAABdQ"]
[Sun Aug 30 03:09:27.012070 2026] [security2:error] [pid 510357:tid 510543] [client 20.48.250.41:45037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/403.php"] [unique_id "apPlN35YTqJxoOZUSXtdrgAABes"]
[Sun Aug 30 03:09:27.014515 2026] [security2:error] [pid 510357:tid 510567] [client 20.104.49.130:36782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/well.php"] [unique_id "apPlN35YTqJxoOZUSXtdsAAABgM"]
[Sun Aug 30 03:09:27.016044 2026] [security2:error] [pid 510357:tid 510516] [client 20.63.81.20:60224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "ourcalmchrysalis.com"] [uri "/.mopj.php"] [unique_id "apPlN35YTqJxoOZUSXtdswAABdA"]
[Sun Aug 30 03:09:27.043777 2026] [security2:error] [pid 510357:tid 510504] [client 158.23.184.117:13225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/hplfuns.php"] [unique_id "apPlN35YTqJxoOZUSXtdtwAABcQ"]
[Sun Aug 30 03:09:27.054466 2026] [security2:error] [pid 510357:tid 510603] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/bulet.php"] [unique_id "apPlN35YTqJxoOZUSXtduQAABic"]
[Sun Aug 30 03:09:27.070148 2026] [security2:error] [pid 510357:tid 510594] [client 4.205.62.107:25911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/xve22.php"] [unique_id "apPlN35YTqJxoOZUSXtdugAABh4"]
[Sun Aug 30 03:09:27.073500 2026] [security2:error] [pid 510357:tid 510571] [client 20.151.8.82:27565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/xamp.php"] [unique_id "apPlN35YTqJxoOZUSXtdvAAABgc"]
[Sun Aug 30 03:09:27.091347 2026] [security2:error] [pid 510357:tid 510559] [client 216.73.216.128:48844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlN35YTqJxoOZUSXtdwQAABfs"]
[Sun Aug 30 03:09:27.095500 2026] [security2:error] [pid 510357:tid 510589] [client 68.155.159.216:63235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/chosen.php"] [unique_id "apPlN35YTqJxoOZUSXtdwgAABhk"]
[Sun Aug 30 03:09:27.103721 2026] [authz_core:error] [pid 510357:tid 510548] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:27.104001 2026] [authz_core:error] [pid 510357:tid 510548] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:27.135222 2026] [security2:error] [pid 510357:tid 510507] [client 4.205.62.107:17309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/xqq.php"] [unique_id "apPlN35YTqJxoOZUSXtd0QAABcc"]
[Sun Aug 30 03:09:27.141292 2026] [security2:error] [pid 510357:tid 510576] [client 20.48.250.41:26506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/lanka.php"] [unique_id "apPlN35YTqJxoOZUSXtd0wAABgw"]
[Sun Aug 30 03:09:27.162022 2026] [security2:error] [pid 510357:tid 510520] [client 20.48.250.41:44949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/cytyr.php"] [unique_id "apPlN35YTqJxoOZUSXtd1QAABdQ"]
[Sun Aug 30 03:09:27.164677 2026] [security2:error] [pid 510357:tid 510583] [client 20.63.81.20:60163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/bengi.php"] [unique_id "apPlN35YTqJxoOZUSXtd1gAABhM"]
[Sun Aug 30 03:09:27.183750 2026] [security2:error] [pid 510357:tid 510540] [client 20.104.50.220:33191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/mailer.php"] [unique_id "apPlN35YTqJxoOZUSXtd3gAABeg"]
[Sun Aug 30 03:09:27.184747 2026] [security2:error] [pid 510357:tid 510612] [client 216.73.216.128:30307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_config_quote_replace_string"] [unique_id "apPlN35YTqJxoOZUSXtd3wAABjA"]
[Sun Aug 30 03:09:27.191267 2026] [autoindex:error] [pid 510357:tid 510529] [client 158.23.184.117:13245] AH01276: Cannot serve directory /home3/kendeall/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.php) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:09:27.204796 2026] [security2:error] [pid 510357:tid 510599] [client 20.151.8.82:16578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/qazwsx.php"] [unique_id "apPlN35YTqJxoOZUSXtd5wAABiM"]
[Sun Aug 30 03:09:27.205580 2026] [security2:error] [pid 510357:tid 510492] [client 20.151.8.82:27498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/bless.php"] [unique_id "apPlN35YTqJxoOZUSXtd6AAABbg"]
[Sun Aug 30 03:09:27.253174 2026] [security2:error] [pid 510357:tid 510593] [client 20.104.50.220:31931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/image.php"] [unique_id "apPlN35YTqJxoOZUSXteAAAABh0"]
[Sun Aug 30 03:09:27.282679 2026] [security2:error] [pid 510357:tid 510618] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/av.php"] [unique_id "apPlN35YTqJxoOZUSXteFQAABjY"]
[Sun Aug 30 03:09:27.286826 2026] [security2:error] [pid 510357:tid 510539] [client 158.23.184.117:13245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/autoload_classmap/function.php"] [unique_id "apPlN35YTqJxoOZUSXteFwAABec"]
[Sun Aug 30 03:09:27.290834 2026] [security2:error] [pid 510357:tid 510575] [client 103.215.74.185:63038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.74.215.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "162.144.1.153"] [uri "/register"] [unique_id "apPlN35YTqJxoOZUSXteGwAABgs"]
[Sun Aug 30 03:09:27.290939 2026] [security2:error] [pid 510357:tid 510575] [client 103.215.74.185:63038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "160"] [id "900408"] [msg "register POST logging"] [data "409"] [hostname "162.144.1.153"] [uri "/register"] [unique_id "apPlN35YTqJxoOZUSXteGwAABgs"]
[Sun Aug 30 03:09:27.305024 2026] [authz_core:error] [pid 510357:tid 510556] [client 66.249.66.67:61538] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:27.305294 2026] [authz_core:error] [pid 510357:tid 510556] [client 66.249.66.67:61538] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:27.313916 2026] [security2:error] [pid 510357:tid 510610] [client 20.104.18.15:1870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brandscape.qa"] [uri "/reviall.php"] [unique_id "apPlN35YTqJxoOZUSXteIQAABi4"]
[Sun Aug 30 03:09:27.316812 2026] [security2:error] [pid 510357:tid 510516] [client 20.48.250.41:45024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/galer.php"] [unique_id "apPlN35YTqJxoOZUSXteIwAABdA"]
[Sun Aug 30 03:09:27.319981 2026] [security2:error] [pid 510357:tid 510582] [client 20.63.81.20:60254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/file2.php"] [unique_id "apPlN35YTqJxoOZUSXteJAAABhI"]
[Sun Aug 30 03:09:27.327565 2026] [security2:error] [pid 510357:tid 510517] [client 20.104.49.130:63489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/forum.php"] [unique_id "apPlN35YTqJxoOZUSXteKAAABdE"]
[Sun Aug 30 03:09:27.336232 2026] [security2:error] [pid 510357:tid 510611] [client 20.151.8.82:16758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/elp.php"] [unique_id "apPlN35YTqJxoOZUSXteKwAABi8"]
[Sun Aug 30 03:09:27.347039 2026] [security2:error] [pid 510357:tid 510600] [client 20.151.8.82:27602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/f35.php"] [unique_id "apPlN35YTqJxoOZUSXteLQAABiQ"]
[Sun Aug 30 03:09:27.366289 2026] [security2:error] [pid 510357:tid 510512] [client 20.104.49.130:64117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/3.php"] [unique_id "apPlN35YTqJxoOZUSXteLwAABcw"]
[Sun Aug 30 03:09:27.402955 2026] [security2:error] [pid 510357:tid 510592] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/images.php"] [unique_id "apPlN35YTqJxoOZUSXteNQAABhw"]
[Sun Aug 30 03:09:27.410266 2026] [security2:error] [pid 510357:tid 510557] [client 4.205.62.107:61800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/G-in.php"] [unique_id "apPlN35YTqJxoOZUSXteOQAABfk"]
[Sun Aug 30 03:09:27.416389 2026] [security2:error] [pid 510357:tid 510515] [client 216.73.216.128:19895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/$%7Be%7D"] [unique_id "apPlN35YTqJxoOZUSXteOgAABc8"]
[Sun Aug 30 03:09:27.417104 2026] [security2:error] [pid 510357:tid 510576] [client 20.48.250.41:26519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/gettest.php"] [unique_id "apPlN35YTqJxoOZUSXteOwAABgw"]
[Sun Aug 30 03:09:27.440393 2026] [security2:error] [pid 510357:tid 510588] [client 20.104.18.15:35472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/wnnjpsby.php"] [unique_id "apPlN35YTqJxoOZUSXteRAAABhg"]
[Sun Aug 30 03:09:27.453389 2026] [security2:error] [pid 510357:tid 510605] [client 20.63.81.20:60241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/gm.php"] [unique_id "apPlN35YTqJxoOZUSXteSwAABik"]
[Sun Aug 30 03:09:27.482440 2026] [security2:error] [pid 510357:tid 510544] [client 20.104.50.220:59720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/heat3.php"] [unique_id "apPlN35YTqJxoOZUSXteXQAABew"]
[Sun Aug 30 03:09:27.490966 2026] [security2:error] [pid 510357:tid 510517] [client 20.104.50.220:5489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/php.php"] [unique_id "apPlN35YTqJxoOZUSXteXwAABdE"]
[Sun Aug 30 03:09:27.492106 2026] [security2:error] [pid 510357:tid 510594] [client 34.100.204.203:50478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/dev/phpinfo.php"] [unique_id "apPlN35YTqJxoOZUSXteYAAABh4"]
[Sun Aug 30 03:09:27.499217 2026] [security2:error] [pid 510357:tid 510571] [client 20.48.250.41:44867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/baixy.php"] [unique_id "apPlN35YTqJxoOZUSXteZQAABgc"]
[Sun Aug 30 03:09:27.525953 2026] [security2:error] [pid 510357:tid 510552] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/ops.php"] [unique_id "apPlN35YTqJxoOZUSXtebwAABfQ"]
[Sun Aug 30 03:09:27.534771 2026] [authz_core:error] [pid 510357:tid 510515] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:27.535196 2026] [authz_core:error] [pid 510357:tid 510515] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:27.538745 2026] [security2:error] [pid 510357:tid 510614] [client 158.158.54.35:29363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/fucixwya.php"] [unique_id "apPlN35YTqJxoOZUSXtecwAABjI"]
[Sun Aug 30 03:09:27.540918 2026] [security2:error] [pid 510357:tid 510558] [client 20.151.8.82:16681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/dorps.php"] [unique_id "apPlN35YTqJxoOZUSXtedAAABfo"]
[Sun Aug 30 03:09:27.597770 2026] [security2:error] [pid 510357:tid 510609] [client 20.63.81.20:60197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/ws55.php"] [unique_id "apPlN35YTqJxoOZUSXtejAAABi0"]
[Sun Aug 30 03:09:27.597790 2026] [security2:error] [pid 510357:tid 510603] [client 158.23.184.117:12874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/wp-includes/wp-includes/box.php"] [unique_id "apPlN35YTqJxoOZUSXteiwAABic"]
[Sun Aug 30 03:09:27.599055 2026] [security2:error] [pid 510357:tid 510568] [client 94.154.43.74:39864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autoconfig.blackfounderssummit.com"] [uri "/.env"] [unique_id "apPlN35YTqJxoOZUSXtejgAABgQ"]
[Sun Aug 30 03:09:27.619383 2026] [security2:error] [pid 510357:tid 510592] [client 20.48.250.41:26516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/35.php"] [unique_id "apPlN35YTqJxoOZUSXtelwAABhw"]
[Sun Aug 30 03:09:27.625294 2026] [security2:error] [pid 510357:tid 510538] [client 20.48.250.41:44995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/ava.php"] [unique_id "apPlN35YTqJxoOZUSXteoAAABeY"]
[Sun Aug 30 03:09:27.626769 2026] [security2:error] [pid 510357:tid 510598] [client 20.48.251.3:52224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/public/vx.php"] [unique_id "apPlN35YTqJxoOZUSXteoQAABiI"]
[Sun Aug 30 03:09:27.640480 2026] [security2:error] [pid 510357:tid 510499] [client 20.104.50.220:16752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/class20.php"] [unique_id "apPlN35YTqJxoOZUSXteqwAABb8"]
[Sun Aug 30 03:09:27.641076 2026] [authz_core:error] [pid 510357:tid 510567] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:27.641357 2026] [authz_core:error] [pid 510357:tid 510567] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:27.660406 2026] [security2:error] [pid 510357:tid 510529] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/BDKR28WP.php"] [unique_id "apPlN35YTqJxoOZUSXteuQAABd0"]
[Sun Aug 30 03:09:27.663737 2026] [security2:error] [pid 510357:tid 510603] [client 20.104.18.15:18298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/gjewuagf.php"] [unique_id "apPlN35YTqJxoOZUSXtevgAABic"]
[Sun Aug 30 03:09:27.669298 2026] [security2:error] [pid 510357:tid 510509] [client 20.151.200.44:45969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/pb.php"] [unique_id "apPlN35YTqJxoOZUSXtewwAABck"]
[Sun Aug 30 03:09:27.673819 2026] [authz_core:error] [pid 510357:tid 510511] [client 66.249.66.77:61091] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:27.674200 2026] [authz_core:error] [pid 510357:tid 510511] [client 66.249.66.77:61091] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:27.728142 2026] [security2:error] [pid 510357:tid 510506] [client 20.63.81.20:60168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/m.php"] [unique_id "apPlN35YTqJxoOZUSXte3AAABcY"]
[Sun Aug 30 03:09:27.743360 2026] [security2:error] [pid 510357:tid 510528] [client 158.23.184.117:13202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/wp-content/uploads/wp.php"] [unique_id "apPlN35YTqJxoOZUSXte3wAABdw"]
[Sun Aug 30 03:09:27.755347 2026] [security2:error] [pid 510357:tid 510576] [client 20.48.250.41:45051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/gdn.php"] [unique_id "apPlN35YTqJxoOZUSXte4QAABgw"]
[Sun Aug 30 03:09:27.757588 2026] [security2:error] [pid 510357:tid 510559] [client 20.48.251.3:59288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/g3.php"] [unique_id "apPlN35YTqJxoOZUSXte4gAABfs"]
[Sun Aug 30 03:09:27.773522 2026] [security2:error] [pid 510357:tid 510553] [client 20.48.250.41:26454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/maraz.php"] [unique_id "apPlN35YTqJxoOZUSXte5wAABfU"]
[Sun Aug 30 03:09:27.793128 2026] [security2:error] [pid 510357:tid 510529] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/k.php"] [unique_id "apPlN35YTqJxoOZUSXte6wAABd0"]
[Sun Aug 30 03:09:27.833113 2026] [authz_core:error] [pid 510357:tid 510579] [client 216.73.216.128:33641] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:27.833395 2026] [authz_core:error] [pid 510357:tid 510579] [client 216.73.216.128:33641] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:27.843847 2026] [security2:error] [pid 510357:tid 510545] [client 20.104.50.220:28689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/fellganteng.php"] [unique_id "apPlN35YTqJxoOZUSXte-AAABe0"]
[Sun Aug 30 03:09:27.851176 2026] [security2:error] [pid 510357:tid 510596] [client 20.104.50.220:41996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/bn.php"] [unique_id "apPlN35YTqJxoOZUSXte-gAABiA"]
[Sun Aug 30 03:09:27.882056 2026] [security2:error] [pid 510357:tid 510512] [client 20.104.49.130:63541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/sxxb.php"] [unique_id "apPlN35YTqJxoOZUSXtfAAAABcw"]
[Sun Aug 30 03:09:27.882545 2026] [security2:error] [pid 510357:tid 510615] [client 20.48.250.41:44885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/f2.php"] [unique_id "apPlN35YTqJxoOZUSXtfAQAABjM"]
[Sun Aug 30 03:09:27.883993 2026] [security2:error] [pid 510357:tid 510580] [client 20.63.81.20:60266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/33.php"] [unique_id "apPlN35YTqJxoOZUSXtfAgAABhA"]
[Sun Aug 30 03:09:27.888744 2026] [security2:error] [pid 510357:tid 510496] [client 152.89.64.52:56926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.64.89.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upcorn.agency"] [uri "/wp-login.php"] [unique_id "apPlN35YTqJxoOZUSXte_QAABbw"]
[Sun Aug 30 03:09:27.909771 2026] [security2:error] [pid 510357:tid 510497] [client 158.23.184.117:12892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/wp-includes/css//index.php"] [unique_id "apPlN35YTqJxoOZUSXtfCwAABb0"]
[Sun Aug 30 03:09:27.919850 2026] [security2:error] [pid 510357:tid 510572] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/dex.php"] [unique_id "apPlN35YTqJxoOZUSXtfEQAABgg"]
[Sun Aug 30 03:09:27.920381 2026] [security2:error] [pid 510357:tid 510614] [client 20.104.18.15:44031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/w3lls.php"] [unique_id "apPlN35YTqJxoOZUSXtfEgAABjI"]
[Sun Aug 30 03:09:27.923387 2026] [security2:error] [pid 510357:tid 510499] [client 20.104.50.220:62842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/shapes.php"] [unique_id "apPlN35YTqJxoOZUSXtfEwAABb8"]
[Sun Aug 30 03:09:27.924674 2026] [security2:error] [pid 510357:tid 510558] [client 20.48.250.41:26501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/kbfr.php"] [unique_id "apPlN35YTqJxoOZUSXtfFAAABfo"]
[Sun Aug 30 03:09:27.941621 2026] [authz_core:error] [pid 510357:tid 510595] [client 66.249.66.77:48464] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:27.941903 2026] [authz_core:error] [pid 510357:tid 510595] [client 66.249.66.77:48464] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:27.986568 2026] [security2:error] [pid 510357:tid 510549] [client 20.151.200.44:28556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlN35YTqJxoOZUSXtfKQAABfE"]
[Sun Aug 30 03:09:28.031521 2026] [security2:error] [pid 510357:tid 510571] [client 20.48.250.41:44960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/grsiuk.php"] [unique_id "apPlOH5YTqJxoOZUSXtfOwAABgc"]
[Sun Aug 30 03:09:28.034343 2026] [security2:error] [pid 510357:tid 510504] [client 20.63.81.20:60114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/packed.php"] [unique_id "apPlOH5YTqJxoOZUSXtfPAAABcQ"]
[Sun Aug 30 03:09:28.035421 2026] [security2:error] [pid 510357:tid 510538] [client 158.158.54.35:2688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/al.php"] [unique_id "apPlOH5YTqJxoOZUSXtfPQAABeY"]
[Sun Aug 30 03:09:28.035901 2026] [security2:error] [pid 510357:tid 510508] [client 20.104.49.130:36797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/wp.php"] [unique_id "apPlOH5YTqJxoOZUSXtfPgAABcg"]
[Sun Aug 30 03:09:28.044433 2026] [security2:error] [pid 510357:tid 510582] [client 20.48.251.3:60537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/config/laravolt/css/index.php"] [unique_id "apPlOH5YTqJxoOZUSXtfRgAABhI"]
[Sun Aug 30 03:09:28.064272 2026] [security2:error] [pid 510357:tid 510611] [client 20.104.18.15:16703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/admin.php"] [unique_id "apPlOH5YTqJxoOZUSXtfSwAABi8"]
[Sun Aug 30 03:09:28.068327 2026] [security2:error] [pid 510357:tid 510612] [client 20.48.250.41:26505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/wp-act.php"] [unique_id "apPlOH5YTqJxoOZUSXtfTQAABjA"]
[Sun Aug 30 03:09:28.108804 2026] [security2:error] [pid 510357:tid 510579] [client 20.48.251.3:64294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/kerang.php"] [unique_id "apPlOH5YTqJxoOZUSXtfVgAABg8"]
[Sun Aug 30 03:09:28.112866 2026] [security2:error] [pid 510357:tid 510570] [client 158.23.184.117:12894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/index2.php"] [unique_id "apPlOH5YTqJxoOZUSXtfVwAABgY"]
[Sun Aug 30 03:09:28.134115 2026] [authz_core:error] [pid 510357:tid 510568] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:28.134405 2026] [authz_core:error] [pid 510357:tid 510568] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:28.144398 2026] [security2:error] [pid 510357:tid 510516] [client 20.104.18.15:22412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlOH5YTqJxoOZUSXtfYAAABdA"]
[Sun Aug 30 03:09:28.150780 2026] [security2:error] [pid 510357:tid 510566] [client 20.104.50.220:61463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/anons79.php"] [unique_id "apPlOH5YTqJxoOZUSXtfZAAABgI"]
[Sun Aug 30 03:09:28.159257 2026] [security2:error] [pid 510357:tid 510538] [client 4.205.62.107:36687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/wp-config.backup.php"] [unique_id "apPlOH5YTqJxoOZUSXtfaAAABeY"]
[Sun Aug 30 03:09:28.187303 2026] [security2:error] [pid 510357:tid 510536] [client 20.48.250.41:44969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/wp-scr1pts.php"] [unique_id "apPlOH5YTqJxoOZUSXtfbgAABeQ"]
[Sun Aug 30 03:09:28.191604 2026] [security2:error] [pid 510357:tid 510561] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/img.php"] [unique_id "apPlOH5YTqJxoOZUSXtfcQAABf0"]
[Sun Aug 30 03:09:28.194606 2026] [security2:error] [pid 510357:tid 510603] [client 20.48.250.41:26516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/24.php"] [unique_id "apPlOH5YTqJxoOZUSXtfcwAABic"]
[Sun Aug 30 03:09:28.196966 2026] [security2:error] [pid 510357:tid 510509] [client 68.155.159.216:63246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/goods.php"] [unique_id "apPlOH5YTqJxoOZUSXtfdQAABck"]
[Sun Aug 30 03:09:28.209297 2026] [security2:error] [pid 510357:tid 510573] [client 4.205.62.107:25772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/06.php"] [unique_id "apPlOH5YTqJxoOZUSXtfeQAABgk"]
[Sun Aug 30 03:09:28.214281 2026] [authz_core:error] [pid 510357:tid 510588] [client 216.73.216.128:60985] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:28.214659 2026] [authz_core:error] [pid 510357:tid 510588] [client 216.73.216.128:60985] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:28.268981 2026] [security2:error] [pid 510357:tid 510607] [client 4.205.62.107:17307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/a1vx.php"] [unique_id "apPlOH5YTqJxoOZUSXtfkAAABis"]
[Sun Aug 30 03:09:28.275469 2026] [security2:error] [pid 510357:tid 510514] [client 20.151.200.44:45924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/pk.php"] [unique_id "apPlOH5YTqJxoOZUSXtflgAABc4"]
[Sun Aug 30 03:09:28.301281 2026] [security2:error] [pid 510357:tid 510615] [client 158.23.184.117:13241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/wp-admin/images/about.php"] [unique_id "apPlOH5YTqJxoOZUSXtfmgAABjM"]
[Sun Aug 30 03:09:28.307118 2026] [security2:error] [pid 510357:tid 510600] [client 20.104.49.130:39060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/chosen.php"] [unique_id "apPlOH5YTqJxoOZUSXtfnAAABiQ"]
[Sun Aug 30 03:09:28.316942 2026] [security2:error] [pid 510357:tid 510530] [client 20.48.250.41:44874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/num.php"] [unique_id "apPlOH5YTqJxoOZUSXtfnwAABd4"]
[Sun Aug 30 03:09:28.318733 2026] [authz_core:error] [pid 510357:tid 510589] [client 20.104.50.220:33170] AH01630: client denied by server configuration: /home4/suite103/public_html/icanto.com/php.ini
[Sun Aug 30 03:09:28.325778 2026] [security2:error] [pid 510357:tid 510536] [client 20.63.81.20:60242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/w.php"] [unique_id "apPlOH5YTqJxoOZUSXtfowAABeQ"]
[Sun Aug 30 03:09:28.335500 2026] [security2:error] [pid 510357:tid 510613] [client 34.100.204.203:50486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/old/phpinfo.php"] [unique_id "apPlOH5YTqJxoOZUSXtfqAAABjE"]
[Sun Aug 30 03:09:28.363961 2026] [security2:error] [pid 510357:tid 510567] [client 20.48.250.41:26453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/155.php"] [unique_id "apPlOH5YTqJxoOZUSXtfrAAABgM"]
[Sun Aug 30 03:09:28.382702 2026] [security2:error] [pid 510357:tid 510599] [client 20.104.50.220:33170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/modul.php"] [unique_id "apPlOH5YTqJxoOZUSXtfrgAABiM"]
[Sun Aug 30 03:09:28.394224 2026] [security2:error] [pid 510357:tid 510551] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/222.php"] [unique_id "apPlOH5YTqJxoOZUSXtfsQAABfM"]
[Sun Aug 30 03:09:28.446692 2026] [autoindex:error] [pid 510357:tid 510566] [client 158.23.184.117:12674] AH01276: Cannot serve directory /home3/kendeall/public_html/wp-includes/rest-api/endpoints/: No matching DirectoryIndex (index.php) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:09:28.481297 2026] [security2:error] [pid 510357:tid 510520] [client 20.63.81.20:60106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/ccc.php"] [unique_id "apPlOH5YTqJxoOZUSXtf3QAABdQ"]
[Sun Aug 30 03:09:28.492086 2026] [security2:error] [pid 510357:tid 510569] [client 20.48.250.41:44925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/a4.php"] [unique_id "apPlOH5YTqJxoOZUSXtf4gAABgU"]
[Sun Aug 30 03:09:28.493030 2026] [security2:error] [pid 510357:tid 510618] [client 158.23.184.117:12674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/wp-includes/theme-compat.php"] [unique_id "apPlOH5YTqJxoOZUSXtf5AAABjY"]
[Sun Aug 30 03:09:28.499895 2026] [security2:error] [pid 510357:tid 510610] [client 20.151.8.82:27609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/aaa.php"] [unique_id "apPlOH5YTqJxoOZUSXtf5gAABi4"]
[Sun Aug 30 03:09:28.515783 2026] [security2:error] [pid 510357:tid 510526] [client 20.104.50.220:32314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-admin/wp-conflg.php"] [unique_id "apPlOH5YTqJxoOZUSXtf6gAABdo"]
[Sun Aug 30 03:09:28.516708 2026] [security2:error] [pid 510357:tid 510553] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/key.php"] [unique_id "apPlOH5YTqJxoOZUSXtf6wAABfU"]
[Sun Aug 30 03:09:28.543789 2026] [security2:error] [pid 510357:tid 510506] [client 4.205.62.107:64698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/apikeys.php"] [unique_id "apPlOH5YTqJxoOZUSXtf9AAABcY"]
[Sun Aug 30 03:09:28.564193 2026] [security2:error] [pid 510357:tid 510502] [client 158.158.54.35:4724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/cadastro-2.php"] [unique_id "apPlOH5YTqJxoOZUSXtgAgAABcI"]
[Sun Aug 30 03:09:28.572923 2026] [security2:error] [pid 510357:tid 510572] [client 20.48.250.41:26565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/file.php"] [unique_id "apPlOH5YTqJxoOZUSXtgBAAABgg"]
[Sun Aug 30 03:09:28.585425 2026] [security2:error] [pid 510357:tid 510525] [client 20.104.18.15:35137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/gigi.php"] [unique_id "apPlOH5YTqJxoOZUSXtgCQAABdk"]
[Sun Aug 30 03:09:28.620562 2026] [security2:error] [pid 510357:tid 510537] [client 20.104.50.220:59712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/greap.php"] [unique_id "apPlOH5YTqJxoOZUSXtgGgAABeU"]
[Sun Aug 30 03:09:28.625753 2026] [security2:error] [pid 510357:tid 510551] [client 20.63.81.20:60276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/file15.php"] [unique_id "apPlOH5YTqJxoOZUSXtgJAAABfM"]
[Sun Aug 30 03:09:28.629979 2026] [security2:error] [pid 510357:tid 510584] [client 20.104.50.220:6135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/for.php"] [unique_id "apPlOH5YTqJxoOZUSXtgJgAABhQ"]
[Sun Aug 30 03:09:28.633302 2026] [authz_core:error] [pid 510357:tid 510617] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:28.633757 2026] [authz_core:error] [pid 510357:tid 510617] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:28.636166 2026] [security2:error] [pid 510357:tid 510570] [client 20.48.250.41:44958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/tfm.php"] [unique_id "apPlOH5YTqJxoOZUSXtgLAAABgY"]
[Sun Aug 30 03:09:28.638736 2026] [security2:error] [pid 510357:tid 510573] [client 158.23.184.117:13222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/NewFile.php"] [unique_id "apPlOH5YTqJxoOZUSXtgMQAABgk"]
[Sun Aug 30 03:09:28.643110 2026] [security2:error] [pid 510357:tid 510615] [client 20.104.49.130:52137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/coffexium.php"] [unique_id "apPlOH5YTqJxoOZUSXtgMwAABjM"]
[Sun Aug 30 03:09:28.672892 2026] [security2:error] [pid 510357:tid 510568] [client 20.151.8.82:27612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/gecko.php"] [unique_id "apPlOH5YTqJxoOZUSXtgTQAABgQ"]
[Sun Aug 30 03:09:28.679290 2026] [authz_core:error] [pid 510357:tid 510521] [client 66.249.66.192:65080] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:28.679745 2026] [authz_core:error] [pid 510357:tid 510521] [client 66.249.66.192:65080] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:28.684799 2026] [authz_core:error] [pid 510357:tid 510499] [client 216.73.216.128:60985] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:28.685252 2026] [authz_core:error] [pid 510357:tid 510499] [client 216.73.216.128:60985] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:28.689480 2026] [security2:error] [pid 510357:tid 510612] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/chosen.php"] [unique_id "apPlOH5YTqJxoOZUSXtgWQAABjA"]
[Sun Aug 30 03:09:28.690148 2026] [security2:error] [pid 510357:tid 510543] [client 20.151.8.82:16598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/cagor.php"] [unique_id "apPlOH5YTqJxoOZUSXtgWgAABes"]
[Sun Aug 30 03:09:28.699246 2026] [authz_core:error] [pid 510357:tid 510549] [client 66.249.66.67:64001] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:28.699556 2026] [authz_core:error] [pid 510357:tid 510549] [client 66.249.66.67:64001] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:28.706134 2026] [security2:error] [pid 510357:tid 510605] [client 20.48.250.41:26502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPlOH5YTqJxoOZUSXtgYgAABik"]
[Sun Aug 30 03:09:28.758953 2026] [security2:error] [pid 510357:tid 510520] [client 20.63.81.20:60228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/jp.php"] [unique_id "apPlOH5YTqJxoOZUSXtgdQAABdQ"]
[Sun Aug 30 03:09:28.766010 2026] [security2:error] [pid 510357:tid 510537] [client 20.48.251.3:59854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/log.php"] [unique_id "apPlOH5YTqJxoOZUSXtgdgAABeU"]
[Sun Aug 30 03:09:28.779292 2026] [security2:error] [pid 510357:tid 510500] [client 68.155.159.216:54305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/goods.php"] [unique_id "apPlOH5YTqJxoOZUSXtgfAAABcA"]
[Sun Aug 30 03:09:28.779303 2026] [security2:error] [pid 510357:tid 510571] [client 20.104.50.220:16585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/admin.php"] [unique_id "apPlOH5YTqJxoOZUSXtgegAABgc"]
[Sun Aug 30 03:09:28.779513 2026] [security2:error] [pid 510357:tid 510550] [client 158.23.184.117:13212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/wp-admin/css/colors/sunrise.php"] [unique_id "apPlOH5YTqJxoOZUSXtgewAABfI"]
[Sun Aug 30 03:09:28.785430 2026] [security2:error] [pid 510357:tid 510574] [client 20.48.250.41:49795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlOH5YTqJxoOZUSXtgfgAABgo"]
[Sun Aug 30 03:09:28.793512 2026] [security2:error] [pid 510357:tid 510516] [client 20.48.250.41:44959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/Geforce.php"] [unique_id "apPlOH5YTqJxoOZUSXtggAAABdA"]
[Sun Aug 30 03:09:28.797046 2026] [security2:error] [pid 510357:tid 510560] [client 20.48.251.3:64511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/tax.php"] [unique_id "apPlOH5YTqJxoOZUSXtggwAABfw"]
[Sun Aug 30 03:09:28.801917 2026] [security2:error] [pid 510357:tid 510491] [client 20.151.8.82:27535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/xiugai.php"] [unique_id "apPlOH5YTqJxoOZUSXtghwAABbc"]
[Sun Aug 30 03:09:28.809691 2026] [security2:error] [pid 510357:tid 510580] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/file1221.php"] [unique_id "apPlOH5YTqJxoOZUSXtgjQAABhA"]
[Sun Aug 30 03:09:28.818302 2026] [security2:error] [pid 510357:tid 510556] [client 20.151.8.82:17373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/billzgs.php"] [unique_id "apPlOH5YTqJxoOZUSXtgkAAABfg"]
[Sun Aug 30 03:09:28.830531 2026] [security2:error] [pid 510357:tid 510514] [client 20.104.18.15:18300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/tnglzqmv.php"] [unique_id "apPlOH5YTqJxoOZUSXtgkgAABc4"]
[Sun Aug 30 03:09:28.863503 2026] [security2:error] [pid 510357:tid 510566] [client 20.48.250.41:26433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/06.php"] [unique_id "apPlOH5YTqJxoOZUSXtglAAABgI"]
[Sun Aug 30 03:09:28.866395 2026] [security2:error] [pid 510357:tid 510598] [client 216.73.216.128:60985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/about:blank"] [unique_id "apPlOH5YTqJxoOZUSXtglQAABiI"]
[Sun Aug 30 03:09:28.872626 2026] [security2:error] [pid 510357:tid 510507] [client 20.104.49.130:34532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/users.php"] [unique_id "apPlOH5YTqJxoOZUSXtglwAABcc"]
[Sun Aug 30 03:09:28.892335 2026] [security2:error] [pid 510357:tid 510541] [client 20.63.81.20:60262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/f35.php"] [unique_id "apPlOH5YTqJxoOZUSXtgnwAABek"]
[Sun Aug 30 03:09:28.896061 2026] [security2:error] [pid 510357:tid 510561] [client 20.48.251.3:59298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/wp-konfig.php"] [unique_id "apPlOH5YTqJxoOZUSXtgoAAABf0"]
[Sun Aug 30 03:09:28.914588 2026] [authz_core:error] [pid 510357:tid 510562] [client 66.249.66.75:42549] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:28.915080 2026] [authz_core:error] [pid 510357:tid 510562] [client 66.249.66.75:42549] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:28.918851 2026] [security2:error] [pid 510357:tid 510533] [client 158.23.184.117:13186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/ova.php"] [unique_id "apPlOH5YTqJxoOZUSXtgqQAABeE"]
[Sun Aug 30 03:09:28.932187 2026] [security2:error] [pid 510357:tid 510608] [client 20.151.8.82:27567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/adminner.php"] [unique_id "apPlOH5YTqJxoOZUSXtgrAAABiw"]
[Sun Aug 30 03:09:28.932574 2026] [security2:error] [pid 510357:tid 510607] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/nox.php"] [unique_id "apPlOH5YTqJxoOZUSXtgrQAABis"]
[Sun Aug 30 03:09:28.954087 2026] [security2:error] [pid 510357:tid 510494] [client 20.151.8.82:17407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/BDKR28_u7cn8y3b.php"] [unique_id "apPlOH5YTqJxoOZUSXtgrwAABbo"]
[Sun Aug 30 03:09:28.992684 2026] [security2:error] [pid 510357:tid 510589] [client 20.104.50.220:62795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/fell.php"] [unique_id "apPlOH5YTqJxoOZUSXtgvwAABhk"]
[Sun Aug 30 03:09:29.010105 2026] [authz_core:error] [pid 510357:tid 510560] [client 66.249.66.43:51469] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:29.010558 2026] [authz_core:error] [pid 510357:tid 510560] [client 66.249.66.43:51469] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:29.021942 2026] [security2:error] [pid 510357:tid 510509] [client 20.104.50.220:63514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/dm.php"] [unique_id "apPlOX5YTqJxoOZUSXtg0QAABck"]
[Sun Aug 30 03:09:29.041348 2026] [security2:error] [pid 510357:tid 510550] [client 20.63.81.20:60246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/shiny.php"] [unique_id "apPlOX5YTqJxoOZUSXtg2gAABfI"]
[Sun Aug 30 03:09:29.058949 2026] [authz_core:error] [pid 510357:tid 510537] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:29.059245 2026] [authz_core:error] [pid 510357:tid 510537] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:29.063016 2026] [security2:error] [pid 510357:tid 510521] [client 20.104.18.15:43982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/fpwch.php"] [unique_id "apPlOX5YTqJxoOZUSXtg4AAABdU"]
[Sun Aug 30 03:09:29.064088 2026] [security2:error] [pid 510357:tid 510577] [client 34.100.204.203:50494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/tmp/phpinfo.php"] [unique_id "apPlOX5YTqJxoOZUSXtg4QAABg0"]
[Sun Aug 30 03:09:29.064666 2026] [security2:error] [pid 510357:tid 510491] [client 20.151.8.82:27557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/file1221.php"] [unique_id "apPlOX5YTqJxoOZUSXtg4gAABbc"]
[Sun Aug 30 03:09:29.069247 2026] [security2:error] [pid 510357:tid 510493] [client 158.158.54.35:29325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/addslashes.php"] [unique_id "apPlOX5YTqJxoOZUSXtg5AAABbk"]
[Sun Aug 30 03:09:29.071730 2026] [security2:error] [pid 510357:tid 510499] [client 20.104.50.220:29127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/sos.php"] [unique_id "apPlOX5YTqJxoOZUSXtg5QAABb8"]
[Sun Aug 30 03:09:29.083924 2026] [security2:error] [pid 510357:tid 510541] [client 158.23.184.117:13242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/wp-admin/network/about.php"] [unique_id "apPlOX5YTqJxoOZUSXtg5wAABek"]
[Sun Aug 30 03:09:29.096526 2026] [security2:error] [pid 510357:tid 510565] [client 158.23.147.79:56453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlOX5YTqJxoOZUSXtg7gAABgE"]
[Sun Aug 30 03:09:29.102675 2026] [security2:error] [pid 510357:tid 510497] [client 20.48.160.90:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cagtu.com"] [uri "/1.php"] [unique_id "apPlOX5YTqJxoOZUSXtg8QAABb0"]
[Sun Aug 30 03:09:29.102758 2026] [security2:error] [pid 510357:tid 510497] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/1.php"] [unique_id "apPlOX5YTqJxoOZUSXtg8QAABb0"]
[Sun Aug 30 03:09:29.128407 2026] [authz_core:error] [pid 510357:tid 510511] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:29.128683 2026] [authz_core:error] [pid 510357:tid 510511] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:29.168100 2026] [security2:error] [pid 510357:tid 510604] [client 20.63.81.20:60231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/images.php"] [unique_id "apPlOX5YTqJxoOZUSXthDAAABig"]
[Sun Aug 30 03:09:29.190947 2026] [security2:error] [pid 510357:tid 510493] [client 20.48.251.3:60488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/87.php"] [unique_id "apPlOX5YTqJxoOZUSXthFQAABbk"]
[Sun Aug 30 03:09:29.207975 2026] [security2:error] [pid 510357:tid 510583] [client 20.104.18.15:16646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/admin.php"] [unique_id "apPlOX5YTqJxoOZUSXthGQAABhM"]
[Sun Aug 30 03:09:29.252380 2026] [security2:error] [pid 510357:tid 510561] [client 20.48.251.3:65493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/rem.php"] [unique_id "apPlOX5YTqJxoOZUSXthJwAABf0"]
[Sun Aug 30 03:09:29.262779 2026] [authz_core:error] [pid 510357:tid 510597] [client 66.249.66.75:55452] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:29.263120 2026] [authz_core:error] [pid 510357:tid 510597] [client 66.249.66.75:55452] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:29.264799 2026] [security2:error] [pid 510357:tid 510594] [client 158.23.184.117:12677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/dashboard.php"] [unique_id "apPlOX5YTqJxoOZUSXthLQAABh4"]
[Sun Aug 30 03:09:29.284672 2026] [security2:error] [pid 510357:tid 510618] [client 20.104.49.130:63551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/222.php"] [unique_id "apPlOX5YTqJxoOZUSXthOQAABjY"]
[Sun Aug 30 03:09:29.288591 2026] [security2:error] [pid 510357:tid 510529] [client 20.104.50.220:61486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/base.php"] [unique_id "apPlOX5YTqJxoOZUSXthOwAABd0"]
[Sun Aug 30 03:09:29.294967 2026] [security2:error] [pid 510357:tid 510582] [client 20.104.18.15:22505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/ap.php"] [unique_id "apPlOX5YTqJxoOZUSXthPgAABhI"]
[Sun Aug 30 03:09:29.303712 2026] [security2:error] [pid 510357:tid 510540] [client 68.155.159.216:63260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apPlOX5YTqJxoOZUSXthQQAABeg"]
[Sun Aug 30 03:09:29.307964 2026] [security2:error] [pid 510357:tid 510609] [client 4.205.62.107:35987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/edit.php"] [unique_id "apPlOX5YTqJxoOZUSXthQwAABi0"]
[Sun Aug 30 03:09:29.319733 2026] [security2:error] [pid 510357:tid 510588] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/m.php"] [unique_id "apPlOX5YTqJxoOZUSXthRgAABhg"]
[Sun Aug 30 03:09:29.333038 2026] [security2:error] [pid 510357:tid 510491] [client 20.63.81.20:60178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/82.php"] [unique_id "apPlOX5YTqJxoOZUSXthSgAABbc"]
[Sun Aug 30 03:09:29.336817 2026] [security2:error] [pid 510357:tid 510565] [client 20.151.200.44:45892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/ft.php"] [unique_id "apPlOX5YTqJxoOZUSXthTQAABgE"]
[Sun Aug 30 03:09:29.363329 2026] [security2:error] [pid 510357:tid 510563] [client 4.205.62.107:25783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/xin1.php"] [unique_id "apPlOX5YTqJxoOZUSXthUQAABf8"]
[Sun Aug 30 03:09:29.365029 2026] [authz_core:error] [pid 510357:tid 510533] [client 66.249.66.67:51043] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:29.365399 2026] [authz_core:error] [pid 510357:tid 510533] [client 66.249.66.67:51043] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:29.405345 2026] [security2:error] [pid 510357:tid 510580] [client 158.23.184.117:13191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/wp-content/plugins/sid/sidwso.php"] [unique_id "apPlOX5YTqJxoOZUSXthWQAABhA"]
[Sun Aug 30 03:09:29.405366 2026] [security2:error] [pid 510357:tid 510515] [client 4.205.62.107:17677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/public/vx.php"] [unique_id "apPlOX5YTqJxoOZUSXthWwAABc8"]
[Sun Aug 30 03:09:29.419218 2026] [security2:error] [pid 510357:tid 510613] [client 20.104.49.130:54151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/3.php"] [unique_id "apPlOX5YTqJxoOZUSXthYwAABjE"]
[Sun Aug 30 03:09:29.422831 2026] [authz_core:error] [pid 510357:tid 510543] [client 216.73.216.128:26257] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:29.423283 2026] [authz_core:error] [pid 510357:tid 510543] [client 216.73.216.128:26257] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:29.478558 2026] [security2:error] [pid 510357:tid 510538] [client 20.63.81.20:60245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/files.php/new.php"] [unique_id "apPlOX5YTqJxoOZUSXthggAABeY"]
[Sun Aug 30 03:09:29.479000 2026] [authz_core:error] [pid 510357:tid 510549] [client 66.249.66.34:60858] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:29.479454 2026] [authz_core:error] [pid 510357:tid 510549] [client 66.249.66.34:60858] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:29.493533 2026] [security2:error] [pid 510357:tid 510530] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/fling.php"] [unique_id "apPlOX5YTqJxoOZUSXthiAAABd4"]
[Sun Aug 30 03:09:29.523576 2026] [security2:error] [pid 510357:tid 510575] [client 20.104.50.220:33027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/configuration.php"] [unique_id "apPlOX5YTqJxoOZUSXthmAAABgs"]
[Sun Aug 30 03:09:29.599991 2026] [security2:error] [pid 510357:tid 510529] [client 20.104.49.130:60745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/666.php"] [unique_id "apPlOX5YTqJxoOZUSXthswAABd0"]
[Sun Aug 30 03:09:29.601077 2026] [authz_core:error] [pid 510357:tid 510543] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:29.601527 2026] [authz_core:error] [pid 510357:tid 510543] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:29.626753 2026] [security2:error] [pid 510357:tid 510614] [client 20.63.81.20:60171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/mghnhykio.php/new.php"] [unique_id "apPlOX5YTqJxoOZUSXthxwAABjI"]
[Sun Aug 30 03:09:29.662554 2026] [security2:error] [pid 510357:tid 510540] [client 158.23.184.117:12893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/admin/index.php"] [unique_id "apPlOX5YTqJxoOZUSXth4QAABeg"]
[Sun Aug 30 03:09:29.689450 2026] [security2:error] [pid 510357:tid 510603] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/btyuio.php"] [unique_id "apPlOX5YTqJxoOZUSXth8gAABic"]
[Sun Aug 30 03:09:29.697378 2026] [security2:error] [pid 510357:tid 510504] [client 20.104.50.220:31809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-freya.php"] [unique_id "apPlOX5YTqJxoOZUSXth9gAABcQ"]
[Sun Aug 30 03:09:29.697635 2026] [security2:error] [pid 510357:tid 510596] [client 4.205.62.107:61815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/motu.php"] [unique_id "apPlOX5YTqJxoOZUSXth-AAABiA"]
[Sun Aug 30 03:09:29.715500 2026] [security2:error] [pid 510357:tid 510578] [client 158.23.147.79:57667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apPlOX5YTqJxoOZUSXth_AAABg4"]
[Sun Aug 30 03:09:29.735781 2026] [security2:error] [pid 510357:tid 510561] [client 20.104.18.15:35014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/info.php/new.php"] [unique_id "apPlOX5YTqJxoOZUSXtiAQAABf0"]
[Sun Aug 30 03:09:29.771663 2026] [security2:error] [pid 510357:tid 510542] [client 20.63.81.20:60128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/admin.php/nope.php"] [unique_id "apPlOX5YTqJxoOZUSXtiBQAABeo"]
[Sun Aug 30 03:09:29.773340 2026] [security2:error] [pid 510357:tid 510595] [client 20.104.50.220:31517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/177.php"] [unique_id "apPlOX5YTqJxoOZUSXtiBgAABh8"]
[Sun Aug 30 03:09:29.782090 2026] [security2:error] [pid 510357:tid 510516] [client 20.104.50.220:5218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/perl.php"] [unique_id "apPlOX5YTqJxoOZUSXtiDAAABdA"]
[Sun Aug 30 03:09:29.806530 2026] [autoindex:error] [pid 510357:tid 510611] [client 158.23.184.117:13236] AH01276: Cannot serve directory /home3/kendeall/public_html/wp-includes/images/smilies/: No matching DirectoryIndex (index.php) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:09:29.810227 2026] [authz_core:error] [pid 510357:tid 510575] [client 66.249.66.193:47918] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:29.810496 2026] [authz_core:error] [pid 510357:tid 510575] [client 66.249.66.193:47918] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:29.828358 2026] [authz_core:error] [pid 510357:tid 510545] [client 66.249.66.68:47893] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:29.828656 2026] [authz_core:error] [pid 510357:tid 510545] [client 66.249.66.68:47893] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:29.835210 2026] [security2:error] [pid 510357:tid 510617] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/dehnl.php"] [unique_id "apPlOX5YTqJxoOZUSXtiIQAABjU"]
[Sun Aug 30 03:09:29.853100 2026] [security2:error] [pid 510357:tid 510560] [client 158.23.184.117:13236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/wp-includes/blocks/block/index.php"] [unique_id "apPlOX5YTqJxoOZUSXtiJQAABfw"]
[Sun Aug 30 03:09:29.854883 2026] [security2:error] [pid 510357:tid 510517] [client 34.100.204.203:50496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/public/phpinfo.php"] [unique_id "apPlOX5YTqJxoOZUSXtiJgAABdE"]
[Sun Aug 30 03:09:29.901223 2026] [security2:error] [pid 510357:tid 510581] [client 20.63.81.20:60268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/lib.php/new.php"] [unique_id "apPlOX5YTqJxoOZUSXtiNgAABhE"]
[Sun Aug 30 03:09:29.917029 2026] [security2:error] [pid 510357:tid 510570] [client 20.104.50.220:16583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/randkeyword.php"] [unique_id "apPlOX5YTqJxoOZUSXtiPAAABgY"]
[Sun Aug 30 03:09:29.934580 2026] [security2:error] [pid 510357:tid 510520] [client 20.48.251.3:59884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/ebahvhhh.php"] [unique_id "apPlOX5YTqJxoOZUSXtiQAAABdQ"]
[Sun Aug 30 03:09:29.955030 2026] [security2:error] [pid 510357:tid 510515] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/zoo1.php"] [unique_id "apPlOX5YTqJxoOZUSXtiQgAABc8"]
[Sun Aug 30 03:09:29.987014 2026] [security2:error] [pid 510357:tid 510606] [client 20.104.49.130:45175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/fling.php"] [unique_id "apPlOX5YTqJxoOZUSXtiUgAABio"]
[Sun Aug 30 03:09:29.987972 2026] [security2:error] [pid 510357:tid 510610] [client 20.104.18.15:18330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/wefile.php"] [unique_id "apPlOX5YTqJxoOZUSXtiVQAABi4"]
[Sun Aug 30 03:09:29.995094 2026] [security2:error] [pid 510357:tid 510535] [client 158.23.184.117:12883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bodaciousbooze.com"] [uri "/bolt.php"] [unique_id "apPlOX5YTqJxoOZUSXtiWQAABeM"]
[Sun Aug 30 03:09:30.033492 2026] [security2:error] [pid 510357:tid 510597] [client 20.48.251.3:55756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/25.php"] [unique_id "apPlOn5YTqJxoOZUSXtiaQAABiE"]
[Sun Aug 30 03:09:30.054101 2026] [security2:error] [pid 510357:tid 510497] [client 20.63.81.20:60221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/info.php/new.php"] [unique_id "apPlOn5YTqJxoOZUSXtibgAABb0"]
[Sun Aug 30 03:09:30.074531 2026] [security2:error] [pid 510357:tid 510576] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/radio.php"] [unique_id "apPlOn5YTqJxoOZUSXticQAABgw"]
[Sun Aug 30 03:09:30.096763 2026] [security2:error] [pid 510357:tid 510569] [client 20.151.8.82:16623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.societyofassassins.com"] [uri "/dftwg.php"] [unique_id "apPlOn5YTqJxoOZUSXtieQAABgU"]
[Sun Aug 30 03:09:30.105801 2026] [authz_core:error] [pid 510357:tid 510598] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:30.106070 2026] [authz_core:error] [pid 510357:tid 510598] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:30.130453 2026] [security2:error] [pid 510357:tid 510604] [client 20.104.49.130:36752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/k.php"] [unique_id "apPlOn5YTqJxoOZUSXtigwAABig"]
[Sun Aug 30 03:09:30.154971 2026] [security2:error] [pid 510357:tid 510603] [client 20.104.50.220:52849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/ok.php"] [unique_id "apPlOn5YTqJxoOZUSXtijQAABic"]
[Sun Aug 30 03:09:30.172635 2026] [security2:error] [pid 510357:tid 510539] [client 20.104.50.220:51634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/gator.php"] [unique_id "apPlOn5YTqJxoOZUSXtikQAABec"]
[Sun Aug 30 03:09:30.185848 2026] [security2:error] [pid 510357:tid 510508] [client 20.63.81.20:60204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/db.php/new.php"] [unique_id "apPlOn5YTqJxoOZUSXtilgAABcg"]
[Sun Aug 30 03:09:30.204042 2026] [security2:error] [pid 510357:tid 510614] [client 20.151.8.82:27614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/inx.php"] [unique_id "apPlOn5YTqJxoOZUSXtinAAABjI"]
[Sun Aug 30 03:09:30.206062 2026] [security2:error] [pid 510357:tid 510504] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/one.php"] [unique_id "apPlOn5YTqJxoOZUSXtinQAABcQ"]
[Sun Aug 30 03:09:30.214698 2026] [security2:error] [pid 510357:tid 510497] [client 20.104.18.15:43973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/domvf.php"] [unique_id "apPlOn5YTqJxoOZUSXtiogAABb0"]
[Sun Aug 30 03:09:30.216766 2026] [authz_core:error] [pid 510357:tid 510499] [client 66.249.66.206:37777] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:30.217093 2026] [authz_core:error] [pid 510357:tid 510499] [client 66.249.66.206:37777] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:30.224084 2026] [security2:error] [pid 510357:tid 510561] [client 20.104.50.220:29123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/print.php"] [unique_id "apPlOn5YTqJxoOZUSXtipAAABf0"]
[Sun Aug 30 03:09:30.238736 2026] [security2:error] [pid 510357:tid 510552] [client 158.23.147.79:57710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apPlOn5YTqJxoOZUSXtipgAABfQ"]
[Sun Aug 30 03:09:30.267672 2026] [security2:error] [pid 510357:tid 510601] [client 158.158.54.35:4725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/content.php888"] [unique_id "apPlOn5YTqJxoOZUSXtitwAABiU"]
[Sun Aug 30 03:09:30.321574 2026] [security2:error] [pid 510357:tid 510540] [client 20.48.251.3:60527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/plss3.php"] [unique_id "apPlOn5YTqJxoOZUSXtixQAABeg"]
[Sun Aug 30 03:09:30.336486 2026] [security2:error] [pid 510357:tid 510568] [client 20.63.81.20:60196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/kuda.php"] [unique_id "apPlOn5YTqJxoOZUSXtizQAABgQ"]
[Sun Aug 30 03:09:30.338885 2026] [security2:error] [pid 510357:tid 510587] [client 20.151.8.82:27595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/reviall.php"] [unique_id "apPlOn5YTqJxoOZUSXti0AAABhc"]
[Sun Aug 30 03:09:30.339554 2026] [security2:error] [pid 510357:tid 510594] [client 20.151.200.44:28559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlOn5YTqJxoOZUSXti0QAABh4"]
[Sun Aug 30 03:09:30.340581 2026] [security2:error] [pid 510357:tid 510592] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/504.php"] [unique_id "apPlOn5YTqJxoOZUSXti0gAABhw"]
[Sun Aug 30 03:09:30.341824 2026] [security2:error] [pid 510357:tid 510502] [client 20.104.18.15:64789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/themes.php"] [unique_id "apPlOn5YTqJxoOZUSXti1AAABcI"]
[Sun Aug 30 03:09:30.358554 2026] [autoindex:error] [pid 510357:tid 510614] [client 43.165.65.117:60118] AH01276: Cannot serve directory /home2/fong0421/unitedaxis.com.my/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:09:30.363752 2026] [authz_core:error] [pid 510357:tid 510504] [client 66.249.66.40:60283] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:30.364217 2026] [authz_core:error] [pid 510357:tid 510504] [client 66.249.66.40:60283] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:30.407423 2026] [security2:error] [pid 510357:tid 510572] [client 20.48.251.3:64261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/min.php"] [unique_id "apPlOn5YTqJxoOZUSXti6gAABgg"]
[Sun Aug 30 03:09:30.408859 2026] [security2:error] [pid 510357:tid 510572] [client 68.155.159.216:62594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apPlOn5YTqJxoOZUSXti6wAABgg"]
[Sun Aug 30 03:09:30.429569 2026] [security2:error] [pid 510357:tid 510583] [client 20.104.50.220:62251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/batm.php"] [unique_id "apPlOn5YTqJxoOZUSXti8gAABhM"]
[Sun Aug 30 03:09:30.435961 2026] [security2:error] [pid 510357:tid 510535] [client 20.104.18.15:22474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/media.php"] [unique_id "apPlOn5YTqJxoOZUSXti9QAABeM"]
[Sun Aug 30 03:09:30.448554 2026] [security2:error] [pid 510357:tid 510565] [client 4.205.62.107:36719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/8.php"] [unique_id "apPlOn5YTqJxoOZUSXti_QAABgE"]
[Sun Aug 30 03:09:30.465458 2026] [security2:error] [pid 510357:tid 510568] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/ano.php"] [unique_id "apPlOn5YTqJxoOZUSXtjBgAABgQ"]
[Sun Aug 30 03:09:30.469314 2026] [security2:error] [pid 510357:tid 510526] [client 20.151.8.82:27548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/11.php"] [unique_id "apPlOn5YTqJxoOZUSXtjCQAABdo"]
[Sun Aug 30 03:09:30.486971 2026] [security2:error] [pid 510357:tid 510518] [client 20.63.81.20:60164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/sure.php"] [unique_id "apPlOn5YTqJxoOZUSXtjFAAABdI"]
[Sun Aug 30 03:09:30.502378 2026] [security2:error] [pid 510357:tid 510530] [client 4.205.62.107:25906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/sadd.php"] [unique_id "apPlOn5YTqJxoOZUSXtjGwAABd4"]
[Sun Aug 30 03:09:30.549307 2026] [security2:error] [pid 510357:tid 510543] [client 4.205.62.107:17318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/log.php"] [unique_id "apPlOn5YTqJxoOZUSXtjLgAABes"]
[Sun Aug 30 03:09:30.564248 2026] [authz_core:error] [pid 510357:tid 510537] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:30.564518 2026] [authz_core:error] [pid 510357:tid 510537] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:30.596310 2026] [security2:error] [pid 510357:tid 510510] [client 216.244.66.238:55540] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arcaneguardians.com"] [uri "/joanne-linville/laravel-toggle-boolean"] [unique_id "apPlOn5YTqJxoOZUSXtjQAAABco"]
[Sun Aug 30 03:09:30.596379 2026] [security2:error] [pid 510357:tid 510510] [client 216.244.66.238:55540] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "arcaneguardians.com"] [uri "/joanne-linville/laravel-toggle-boolean"] [unique_id "apPlOn5YTqJxoOZUSXtjQAAABco"]
[Sun Aug 30 03:09:30.597447 2026] [security2:error] [pid 510357:tid 510548] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/mac.php"] [unique_id "apPlOn5YTqJxoOZUSXtjQQAABfA"]
[Sun Aug 30 03:09:30.598212 2026] [security2:error] [pid 510357:tid 510599] [client 20.151.8.82:27500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/File.php"] [unique_id "apPlOn5YTqJxoOZUSXtjQgAABiM"]
[Sun Aug 30 03:09:30.627007 2026] [security2:error] [pid 510357:tid 510513] [client 20.63.81.20:60166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/gray.php"] [unique_id "apPlOn5YTqJxoOZUSXtjVwAABc0"]
[Sun Aug 30 03:09:30.643599 2026] [authz_core:error] [pid 510357:tid 510576] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:30.643922 2026] [authz_core:error] [pid 510357:tid 510576] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:30.675550 2026] [security2:error] [pid 510357:tid 510568] [client 20.151.200.44:46057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/wp-ver.php"] [unique_id "apPlOn5YTqJxoOZUSXtjfAAABgQ"]
[Sun Aug 30 03:09:30.676623 2026] [security2:error] [pid 510357:tid 510579] [client 20.104.50.220:33578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/tai.php"] [unique_id "apPlOn5YTqJxoOZUSXtjfgAABg8"]
[Sun Aug 30 03:09:30.728620 2026] [security2:error] [pid 510357:tid 510509] [client 20.48.251.3:64476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPlOn5YTqJxoOZUSXtjlAAABck"]
[Sun Aug 30 03:09:30.739543 2026] [security2:error] [pid 510357:tid 510544] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/simple.php"] [unique_id "apPlOn5YTqJxoOZUSXtjlwAABew"]
[Sun Aug 30 03:09:30.747818 2026] [security2:error] [pid 510357:tid 510572] [client 20.151.8.82:27464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/fi22.php"] [unique_id "apPlOn5YTqJxoOZUSXtjmQAABgg"]
[Sun Aug 30 03:09:30.767328 2026] [security2:error] [pid 510357:tid 510573] [client 158.158.54.35:8312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/access.php"] [unique_id "apPlOn5YTqJxoOZUSXtjmwAABgk"]
[Sun Aug 30 03:09:30.793575 2026] [security2:error] [pid 510357:tid 510535] [client 20.63.81.20:60287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/puki.php"] [unique_id "apPlOn5YTqJxoOZUSXtjpwAABeM"]
[Sun Aug 30 03:09:30.837916 2026] [security2:error] [pid 510357:tid 510586] [client 4.205.62.107:64482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/public/mah.php.php"] [unique_id "apPlOn5YTqJxoOZUSXtjtAAABhY"]
[Sun Aug 30 03:09:30.837946 2026] [security2:error] [pid 510357:tid 510526] [client 216.73.216.128:7466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_config_quote_replace_string"] [unique_id "apPlOn5YTqJxoOZUSXtjtQAABdo"]
[Sun Aug 30 03:09:30.856029 2026] [authz_core:error] [pid 510357:tid 510504] [client 66.249.66.194:50199] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:30.856470 2026] [authz_core:error] [pid 510357:tid 510504] [client 66.249.66.194:50199] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:30.863093 2026] [security2:error] [pid 510357:tid 510511] [client 34.100.204.203:50508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/php-info.php"] [unique_id "apPlOn5YTqJxoOZUSXtjtwAABcs"]
[Sun Aug 30 03:09:30.863245 2026] [security2:error] [pid 510357:tid 510567] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/sallu.php"] [unique_id "apPlOn5YTqJxoOZUSXtjuAAABgM"]
[Sun Aug 30 03:09:30.878170 2026] [security2:error] [pid 510357:tid 510562] [client 20.151.8.82:27571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPlOn5YTqJxoOZUSXtjugAABf4"]
[Sun Aug 30 03:09:30.895829 2026] [security2:error] [pid 510357:tid 510547] [client 20.104.50.220:31916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/X7x.php"] [unique_id "apPlOn5YTqJxoOZUSXtjwQAABe8"]
[Sun Aug 30 03:09:30.915124 2026] [autoindex:error] [pid 510357:tid 510596] [client 20.104.18.15:35186] AH01276: Cannot serve directory /home3/ucdsscom/firesouq.com/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:09:30.921243 2026] [security2:error] [pid 510357:tid 510549] [client 20.104.50.220:5581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/cgi.php"] [unique_id "apPlOn5YTqJxoOZUSXtjygAABfE"]
[Sun Aug 30 03:09:30.922816 2026] [security2:error] [pid 510357:tid 510509] [client 20.63.81.20:60264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/sonic.php"] [unique_id "apPlOn5YTqJxoOZUSXtjzAAABck"]
[Sun Aug 30 03:09:30.929820 2026] [security2:error] [pid 510357:tid 510541] [client 20.104.50.220:63208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/199.php"] [unique_id "apPlOn5YTqJxoOZUSXtj0QAABek"]
[Sun Aug 30 03:09:30.980545 2026] [security2:error] [pid 510357:tid 510568] [client 20.104.18.15:35186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/w.php"] [unique_id "apPlOn5YTqJxoOZUSXtj4wAABgQ"]
[Sun Aug 30 03:09:31.017333 2026] [security2:error] [pid 510357:tid 510590] [client 20.151.8.82:27618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/a3ampzmbipnkpxeqhqpsanCdefault.php"] [unique_id "apPlO35YTqJxoOZUSXtj_QAABho"]
[Sun Aug 30 03:09:31.052999 2026] [security2:error] [pid 510357:tid 510566] [client 20.104.50.220:16762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/fwe.php"] [unique_id "apPlO35YTqJxoOZUSXtkBQAABgI"]
[Sun Aug 30 03:09:31.061450 2026] [security2:error] [pid 510357:tid 510541] [client 20.63.81.20:60033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/pop.php"] [unique_id "apPlO35YTqJxoOZUSXtkBgAABek"]
[Sun Aug 30 03:09:31.064173 2026] [security2:error] [pid 510357:tid 510581] [client 68.155.159.216:54325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apPlO35YTqJxoOZUSXtkBwAABhE"]
[Sun Aug 30 03:09:31.067209 2026] [security2:error] [pid 510357:tid 510592] [client 20.104.49.130:63490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/media.php"] [unique_id "apPlO35YTqJxoOZUSXtkCAAABhw"]
[Sun Aug 30 03:09:31.095636 2026] [security2:error] [pid 510357:tid 510491] [client 20.48.251.3:59476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/asa.php"] [unique_id "apPlO35YTqJxoOZUSXtkEgAABbc"]
[Sun Aug 30 03:09:31.101848 2026] [authz_core:error] [pid 510357:tid 510506] [client 66.249.66.75:55452] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:31.102133 2026] [authz_core:error] [pid 510357:tid 510506] [client 66.249.66.75:55452] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:31.111180 2026] [security2:error] [pid 510357:tid 510492] [client 216.73.216.128:26257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts2/updateconf"] [unique_id "apPlO35YTqJxoOZUSXtkFgAABbg"]
[Sun Aug 30 03:09:31.117633 2026] [security2:error] [pid 510357:tid 510531] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/fpwch.php"] [unique_id "apPlO35YTqJxoOZUSXtkGAAABd8"]
[Sun Aug 30 03:09:31.129627 2026] [security2:error] [pid 510357:tid 510604] [client 20.104.18.15:18205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/blog.php"] [unique_id "apPlO35YTqJxoOZUSXtkHgAABig"]
[Sun Aug 30 03:09:31.136877 2026] [authz_core:error] [pid 510357:tid 510533] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:31.137168 2026] [authz_core:error] [pid 510357:tid 510533] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:31.149012 2026] [security2:error] [pid 510357:tid 510595] [client 20.151.8.82:27462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPlO35YTqJxoOZUSXtkJAAABh8"]
[Sun Aug 30 03:09:31.169267 2026] [security2:error] [pid 510357:tid 510605] [client 20.48.251.3:55755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/nlnub.php"] [unique_id "apPlO35YTqJxoOZUSXtkKgAABik"]
[Sun Aug 30 03:09:31.175720 2026] [security2:error] [pid 510357:tid 510603] [client 20.104.49.130:52123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/simple.php"] [unique_id "apPlO35YTqJxoOZUSXtkLQAABic"]
[Sun Aug 30 03:09:31.189316 2026] [security2:error] [pid 510357:tid 510550] [client 20.63.81.20:60200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/503.php"] [unique_id "apPlO35YTqJxoOZUSXtkMwAABfI"]
[Sun Aug 30 03:09:31.202472 2026] [security2:error] [pid 510357:tid 510615] [client 103.215.74.185:63042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.74.215.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "162.144.1.153"] [uri "/register"] [unique_id "apPlO35YTqJxoOZUSXtkNwAABjM"]
[Sun Aug 30 03:09:31.202623 2026] [security2:error] [pid 510357:tid 510615] [client 103.215.74.185:63042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "160"] [id "900408"] [msg "register POST logging"] [data "409"] [hostname "162.144.1.153"] [uri "/register"] [unique_id "apPlO35YTqJxoOZUSXtkNwAABjM"]
[Sun Aug 30 03:09:31.245452 2026] [security2:error] [pid 510357:tid 510569] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/domvf.php"] [unique_id "apPlO35YTqJxoOZUSXtkQQAABgU"]
[Sun Aug 30 03:09:31.282909 2026] [security2:error] [pid 510357:tid 510508] [client 20.151.8.82:27590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/i99z7zzbwtpteujvv6s8hiCdefault.php"] [unique_id "apPlO35YTqJxoOZUSXtkWQAABcg"]
[Sun Aug 30 03:09:31.294495 2026] [security2:error] [pid 510357:tid 510587] [client 20.104.50.220:62820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/herp.php"] [unique_id "apPlO35YTqJxoOZUSXtkXAAABhc"]
[Sun Aug 30 03:09:31.295955 2026] [security2:error] [pid 510357:tid 510565] [client 20.104.49.130:59580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/bdroot.php"] [unique_id "apPlO35YTqJxoOZUSXtkXQAABgE"]
[Sun Aug 30 03:09:31.335290 2026] [security2:error] [pid 510357:tid 510574] [client 20.63.81.20:60160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/fxp.php"] [unique_id "apPlO35YTqJxoOZUSXtkZwAABgo"]
[Sun Aug 30 03:09:31.378515 2026] [security2:error] [pid 510357:tid 510615] [client 20.104.50.220:29129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/pdi.php"] [unique_id "apPlO35YTqJxoOZUSXtkbgAABjM"]
[Sun Aug 30 03:09:31.381779 2026] [security2:error] [pid 510357:tid 510570] [client 20.104.50.220:42010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/mail.php"] [unique_id "apPlO35YTqJxoOZUSXtkcAAABgY"]
[Sun Aug 30 03:09:31.381976 2026] [security2:error] [pid 510357:tid 510554] [client 20.104.18.15:43932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/biufile.php"] [unique_id "apPlO35YTqJxoOZUSXtkcQAABfY"]
[Sun Aug 30 03:09:31.394451 2026] [security2:error] [pid 510357:tid 510520] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/biufile.php"] [unique_id "apPlO35YTqJxoOZUSXtkdQAABdQ"]
[Sun Aug 30 03:09:31.413586 2026] [security2:error] [pid 510357:tid 510584] [client 20.151.8.82:27546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/gwaih1gfzp5vuwr04Cdefault.php"] [unique_id "apPlO35YTqJxoOZUSXtkegAABhQ"]
[Sun Aug 30 03:09:31.440409 2026] [security2:error] [pid 510357:tid 510509] [client 158.158.54.35:5073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/aksinet.php"] [unique_id "apPlO35YTqJxoOZUSXtkhwAABck"]
[Sun Aug 30 03:09:31.455587 2026] [security2:error] [pid 510357:tid 510508] [client 20.48.251.3:14003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/aws.php"] [unique_id "apPlO35YTqJxoOZUSXtkkgAABcg"]
[Sun Aug 30 03:09:31.481107 2026] [security2:error] [pid 510357:tid 510574] [client 20.104.18.15:64857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/biufile.php"] [unique_id "apPlO35YTqJxoOZUSXtkoAAABgo"]
[Sun Aug 30 03:09:31.483228 2026] [security2:error] [pid 510357:tid 510603] [client 20.63.81.20:60181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/vv.php"] [unique_id "apPlO35YTqJxoOZUSXtkowAABic"]
[Sun Aug 30 03:09:31.528629 2026] [security2:error] [pid 510357:tid 510589] [client 52.139.37.240:43098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apPlO35YTqJxoOZUSXtktQAABhk"]
[Sun Aug 30 03:09:31.531880 2026] [security2:error] [pid 510357:tid 510598] [client 68.155.159.216:63249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/file.php"] [unique_id "apPlO35YTqJxoOZUSXtktwAABiI"]
[Sun Aug 30 03:09:31.538495 2026] [security2:error] [pid 510357:tid 510581] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/blacks.php"] [unique_id "apPlO35YTqJxoOZUSXtkuQAABhE"]
[Sun Aug 30 03:09:31.544427 2026] [security2:error] [pid 510357:tid 510579] [client 20.48.251.3:65476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/saiga.php"] [unique_id "apPlO35YTqJxoOZUSXtkwAAABg8"]
[Sun Aug 30 03:09:31.548833 2026] [security2:error] [pid 510357:tid 510531] [client 20.151.8.82:27488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/1wvekeybd9it2di2vyipgr6Cdefault.php"] [unique_id "apPlO35YTqJxoOZUSXtkwwAABd8"]
[Sun Aug 30 03:09:31.565295 2026] [security2:error] [pid 510357:tid 510510] [client 20.104.49.130:36745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/df.php"] [unique_id "apPlO35YTqJxoOZUSXtkxwAABco"]
[Sun Aug 30 03:09:31.576530 2026] [security2:error] [pid 510357:tid 510538] [client 20.104.18.15:22482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/adminfuns.php"] [unique_id "apPlO35YTqJxoOZUSXtkywAABeY"]
[Sun Aug 30 03:09:31.582797 2026] [security2:error] [pid 510357:tid 510595] [client 4.205.62.107:36708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/thui.php"] [unique_id "apPlO35YTqJxoOZUSXtkzgAABh8"]
[Sun Aug 30 03:09:31.589474 2026] [security2:error] [pid 510357:tid 510606] [client 20.104.50.220:61643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/bj.php"] [unique_id "apPlO35YTqJxoOZUSXtk0QAABio"]
[Sun Aug 30 03:09:31.609925 2026] [security2:error] [pid 510357:tid 510577] [client 34.100.204.203:50514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/phpversion.php"] [unique_id "apPlO35YTqJxoOZUSXtk4AAABg0"]
[Sun Aug 30 03:09:31.618109 2026] [authz_core:error] [pid 510357:tid 510558] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:31.618403 2026] [authz_core:error] [pid 510357:tid 510558] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:31.624186 2026] [security2:error] [pid 510357:tid 510615] [client 20.63.81.20:60222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/bossu.php"] [unique_id "apPlO35YTqJxoOZUSXtk7gAABjM"]
[Sun Aug 30 03:09:31.624697 2026] [security2:error] [pid 510357:tid 510499] [client 216.244.66.238:55554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arcaneguardians.com"] [uri "/tdbhc/cloud-contact-center-gartner"] [unique_id "apPlO35YTqJxoOZUSXtk7wAABb8"]
[Sun Aug 30 03:09:31.624767 2026] [security2:error] [pid 510357:tid 510499] [client 216.244.66.238:55554] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "arcaneguardians.com"] [uri "/tdbhc/cloud-contact-center-gartner"] [unique_id "apPlO35YTqJxoOZUSXtk7wAABb8"]
[Sun Aug 30 03:09:31.627329 2026] [authz_core:error] [pid 510357:tid 510587] [client 66.249.66.65:62843] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:31.627581 2026] [authz_core:error] [pid 510357:tid 510587] [client 66.249.66.65:62843] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:31.642020 2026] [security2:error] [pid 510357:tid 510599] [client 4.205.62.107:25742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/application.config.php"] [unique_id "apPlO35YTqJxoOZUSXtk_gAABiM"]
[Sun Aug 30 03:09:31.658294 2026] [security2:error] [pid 510357:tid 510539] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp.php"] [unique_id "apPlO35YTqJxoOZUSXtlCAAABec"]
[Sun Aug 30 03:09:31.698490 2026] [security2:error] [pid 510357:tid 510592] [client 20.151.8.82:27481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/media.php"] [unique_id "apPlO35YTqJxoOZUSXtlJwAABhw"]
[Sun Aug 30 03:09:31.710063 2026] [security2:error] [pid 510357:tid 510599] [client 4.205.62.107:17113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/ebahvhhh.php"] [unique_id "apPlO35YTqJxoOZUSXtlLAAABiM"]
[Sun Aug 30 03:09:31.739336 2026] [security2:error] [pid 510357:tid 510618] [client 52.139.37.240:44557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/wp-content/uploads/min.php"] [unique_id "apPlO35YTqJxoOZUSXtlNAAABjY"]
[Sun Aug 30 03:09:31.770059 2026] [security2:error] [pid 510357:tid 510510] [client 20.63.81.20:60129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/504.php"] [unique_id "apPlO35YTqJxoOZUSXtlOAAABco"]
[Sun Aug 30 03:09:31.797713 2026] [authz_core:error] [pid 510357:tid 510573] [client 66.249.66.70:36766] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:31.797999 2026] [authz_core:error] [pid 510357:tid 510573] [client 66.249.66.70:36766] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:31.806910 2026] [security2:error] [pid 510357:tid 510534] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wander.php"] [unique_id "apPlO35YTqJxoOZUSXtlRgAABeI"]
[Sun Aug 30 03:09:31.821525 2026] [security2:error] [pid 510357:tid 510535] [client 20.151.200.44:28619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/h02ugyh.php"] [unique_id "apPlO35YTqJxoOZUSXtlTAAABeM"]
[Sun Aug 30 03:09:31.831118 2026] [security2:error] [pid 510357:tid 510612] [client 20.104.50.220:33550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/www.php"] [unique_id "apPlO35YTqJxoOZUSXtlTQAABjA"]
[Sun Aug 30 03:09:31.855397 2026] [security2:error] [pid 510357:tid 510530] [client 20.151.200.44:45998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/ah24.php"] [unique_id "apPlO35YTqJxoOZUSXtlUAAABd4"]
[Sun Aug 30 03:09:31.866016 2026] [security2:error] [pid 510357:tid 510549] [client 20.151.8.82:27613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/inso.php"] [unique_id "apPlO35YTqJxoOZUSXtlUQAABfE"]
[Sun Aug 30 03:09:31.900413 2026] [security2:error] [pid 510357:tid 510513] [client 20.63.81.20:60102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/nice.php"] [unique_id "apPlO35YTqJxoOZUSXtlWgAABc0"]
[Sun Aug 30 03:09:31.915597 2026] [security2:error] [pid 510357:tid 510513] [client 162.55.6.244:46650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.6.55.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "letsalcook.com"] [uri "/wp-login.php"] [unique_id "apPlO35YTqJxoOZUSXtlWwAABc0"]
[Sun Aug 30 03:09:31.940540 2026] [security2:error] [pid 510357:tid 510577] [client 52.139.37.240:44609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/zoom1.php"] [unique_id "apPlO35YTqJxoOZUSXtlaAAABg0"]
[Sun Aug 30 03:09:31.965061 2026] [security2:error] [pid 510357:tid 510510] [client 20.48.251.3:6467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPlO35YTqJxoOZUSXtlbAAABco"]
[Sun Aug 30 03:09:31.966587 2026] [security2:error] [pid 510357:tid 510491] [client 4.205.62.107:61766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/zaza.php"] [unique_id "apPlO35YTqJxoOZUSXtlbwAABbc"]
[Sun Aug 30 03:09:31.999316 2026] [security2:error] [pid 510357:tid 510535] [client 74.7.227.8:36082] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:< ?i?frame ?src ?= ?(?:ogg|tls|ssl|gopher|file|data|php|zlib|zip|glob|s3|phar|rar|s(?:sh2?|cp)|dict|expect|(?:ht|f)tps?):/|(?:\\\\.add|\\\\@)import |asfunction\\\\:|background-image\\\\:|\\\\be(?:cma|xec)script\\\\b|\\\\.fromcharcode|get(?:parentfolder|specialfol ..." at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1083"] [id "340149"] [rev "157"] [msg "Atomicorp.com WAF Rules: Potential Cross Site Scripting Attack"] [data "ecmascript"] [severity "CRITICAL"] [hostname "www.ltr7.com"] [uri "/"] [unique_id "apPlO35YTqJxoOZUSXtlgAAABeM"], referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:32.002907 2026] [security2:error] [pid 510357:tid 510583] [client 20.151.8.82:27598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/shiny.php"] [unique_id "apPlPH5YTqJxoOZUSXtlhQAABhM"]
[Sun Aug 30 03:09:32.026943 2026] [security2:error] [pid 510357:tid 510550] [client 158.158.54.35:24689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/ab1ux1ft.php"] [unique_id "apPlPH5YTqJxoOZUSXtljwAABfI"]
[Sun Aug 30 03:09:32.040562 2026] [security2:error] [pid 510357:tid 510520] [client 20.63.81.20:60112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/beence.php"] [unique_id "apPlPH5YTqJxoOZUSXtlkwAABdQ"]
[Sun Aug 30 03:09:32.078766 2026] [security2:error] [pid 510357:tid 510596] [client 20.104.50.220:5578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/tmp.php"] [unique_id "apPlPH5YTqJxoOZUSXtlmgAABiA"]
[Sun Aug 30 03:09:32.099712 2026] [security2:error] [pid 510357:tid 510568] [client 20.104.50.220:59375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/file52.php"] [unique_id "apPlPH5YTqJxoOZUSXtloQAABgQ"]
[Sun Aug 30 03:09:32.100832 2026] [security2:error] [pid 510357:tid 510531] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/abcd.php"] [unique_id "apPlPH5YTqJxoOZUSXtlogAABd8"]
[Sun Aug 30 03:09:32.109424 2026] [security2:error] [pid 510357:tid 510494] [client 20.104.50.220:31893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/admir.php"] [unique_id "apPlPH5YTqJxoOZUSXtlpQAABbo"]
[Sun Aug 30 03:09:32.118538 2026] [authz_core:error] [pid 510357:tid 510539] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:09:32.118822 2026] [authz_core:error] [pid 510357:tid 510539] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:09:32.131639 2026] [security2:error] [pid 510357:tid 510497] [client 20.104.18.15:35023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/x.php"] [unique_id "apPlPH5YTqJxoOZUSXtlrQAABb0"]
[Sun Aug 30 03:09:32.137889 2026] [security2:error] [pid 510357:tid 510542] [client 20.151.8.82:27465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/403dd.php"] [unique_id "apPlPH5YTqJxoOZUSXtlrwAABeo"]
[Sun Aug 30 03:09:32.140870 2026] [security2:error] [pid 510357:tid 510507] [client 52.139.37.240:44574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/lock360.php"] [unique_id "apPlPH5YTqJxoOZUSXtlsAAABcc"]
[Sun Aug 30 03:09:32.154580 2026] [security2:error] [pid 510357:tid 510582] [client 158.23.147.79:56473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/simple.php"] [unique_id "apPlPH5YTqJxoOZUSXtlsgAABhI"]
[Sun Aug 30 03:09:32.157334 2026] [security2:error] [pid 510357:tid 510576] [client 20.151.200.44:45987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/wp-admin/zwso.php"] [unique_id "apPlPH5YTqJxoOZUSXtltAAABgw"]
[Sun Aug 30 03:09:32.179824 2026] [security2:error] [pid 510357:tid 510547] [client 20.63.81.20:60165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/222.php"] [unique_id "apPlPH5YTqJxoOZUSXtlvAAABe8"]
[Sun Aug 30 03:09:32.191518 2026] [security2:error] [pid 510357:tid 510600] [client 20.104.50.220:16603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/images/m.php"] [unique_id "apPlPH5YTqJxoOZUSXtlxAAABiQ"]
[Sun Aug 30 03:09:32.226531 2026] [security2:error] [pid 510357:tid 510592] [client 20.48.251.3:52225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/radio.php"] [unique_id "apPlPH5YTqJxoOZUSXtlywAABhw"]
[Sun Aug 30 03:09:32.260442 2026] [security2:error] [pid 510357:tid 510518] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/nofile.php"] [unique_id "apPlPH5YTqJxoOZUSXtl1QAABdI"]
[Sun Aug 30 03:09:32.269763 2026] [security2:error] [pid 510357:tid 510568] [client 20.151.8.82:27611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/baba.php"] [unique_id "apPlPH5YTqJxoOZUSXtl2wAABgQ"]
[Sun Aug 30 03:09:32.270048 2026] [security2:error] [pid 510357:tid 510491] [client 20.104.18.15:18189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/wp-admin/js/wp-load.php"] [unique_id "apPlPH5YTqJxoOZUSXtl3AAABbc"]
[Sun Aug 30 03:09:32.311104 2026] [security2:error] [pid 510357:tid 510526] [client 20.48.251.3:55790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/mga.php"] [unique_id "apPlPH5YTqJxoOZUSXtl5wAABdo"]
[Sun Aug 30 03:09:32.322142 2026] [security2:error] [pid 510357:tid 510508] [client 20.63.81.20:60216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/ops.php"] [unique_id "apPlPH5YTqJxoOZUSXtl7QAABcg"]
[Sun Aug 30 03:09:32.325257 2026] [authz_core:error] [pid 510357:tid 510505] [client 66.249.66.39:35819] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:32.325517 2026] [authz_core:error] [pid 510357:tid 510505] [client 66.249.66.39:35819] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:32.332546 2026] [security2:error] [pid 510357:tid 510601] [client 52.139.37.240:44607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/r.php"] [unique_id "apPlPH5YTqJxoOZUSXtl8QAABiU"]
[Sun Aug 30 03:09:32.355977 2026] [security2:error] [pid 510357:tid 510600] [client 68.155.159.216:54311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apPlPH5YTqJxoOZUSXtl9gAABiQ"]
[Sun Aug 30 03:09:32.383220 2026] [security2:error] [pid 510357:tid 510566] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/run.php"] [unique_id "apPlPH5YTqJxoOZUSXtl-gAABgI"]
[Sun Aug 30 03:09:32.402385 2026] [security2:error] [pid 510357:tid 510617] [client 20.151.200.44:45980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.filtakleen.org"] [uri "/waf.php"] [unique_id "apPlPH5YTqJxoOZUSXtl_wAABjU"]
[Sun Aug 30 03:09:32.419893 2026] [security2:error] [pid 510357:tid 510563] [client 20.151.8.82:27551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/site.php"] [unique_id "apPlPH5YTqJxoOZUSXtmBAAABf8"]
[Sun Aug 30 03:09:32.439233 2026] [security2:error] [pid 510357:tid 510518] [client 20.104.50.220:52834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/nptice.php"] [unique_id "apPlPH5YTqJxoOZUSXtmDAAABdI"]
[Sun Aug 30 03:09:32.446292 2026] [authz_core:error] [pid 510357:tid 510573] [client 66.249.66.197:58177] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:32.446760 2026] [authz_core:error] [pid 510357:tid 510573] [client 66.249.66.197:58177] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:32.462949 2026] [security2:error] [pid 510357:tid 510497] [client 20.63.81.20:60131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPlPH5YTqJxoOZUSXtmGQAABb0"]
[Sun Aug 30 03:09:32.473280 2026] [authz_core:error] [pid 510357:tid 510553] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp
[Sun Aug 30 03:09:32.473736 2026] [authz_core:error] [pid 510357:tid 510553] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp
[Sun Aug 30 03:09:32.493031 2026] [security2:error] [pid 510357:tid 510499] [client 34.100.204.203:50528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/_phpinfo.php"] [unique_id "apPlPH5YTqJxoOZUSXtmJwAABb8"]
[Sun Aug 30 03:09:32.503657 2026] [security2:error] [pid 510357:tid 510603] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/new.php"] [unique_id "apPlPH5YTqJxoOZUSXtmLQAABic"]
[Sun Aug 30 03:09:32.505709 2026] [security2:error] [pid 510357:tid 510584] [client 158.158.54.35:8270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/block-bindings.php"] [unique_id "apPlPH5YTqJxoOZUSXtmMQAABhQ"]
[Sun Aug 30 03:09:32.523833 2026] [security2:error] [pid 510357:tid 510551] [client 52.139.37.240:43088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/sf.php"] [unique_id "apPlPH5YTqJxoOZUSXtmPAAABfM"]
[Sun Aug 30 03:09:32.526895 2026] [security2:error] [pid 510357:tid 510502] [client 20.104.18.15:43979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/blacks.php"] [unique_id "apPlPH5YTqJxoOZUSXtmQAAABcI"]
[Sun Aug 30 03:09:32.527571 2026] [security2:error] [pid 510357:tid 510567] [client 20.104.50.220:51591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/mailer.php"] [unique_id "apPlPH5YTqJxoOZUSXtmQQAABgM"]
[Sun Aug 30 03:09:32.529388 2026] [security2:error] [pid 510357:tid 510520] [client 20.104.50.220:28684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/rayzky.php"] [unique_id "apPlPH5YTqJxoOZUSXtmQwAABdQ"]
[Sun Aug 30 03:09:32.551871 2026] [security2:error] [pid 510357:tid 510583] [client 20.151.8.82:27570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/cabs.php"] [unique_id "apPlPH5YTqJxoOZUSXtmWQAABhM"]
[Sun Aug 30 03:09:32.601753 2026] [security2:error] [pid 510357:tid 510561] [client 20.48.251.3:33323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/app.default.php"] [unique_id "apPlPH5YTqJxoOZUSXtmdgAABf0"]
[Sun Aug 30 03:09:32.606225 2026] [security2:error] [pid 510357:tid 510500] [client 20.63.81.20:60127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPlPH5YTqJxoOZUSXtmegAABcA"]
[Sun Aug 30 03:09:32.611623 2026] [authz_core:error] [pid 510357:tid 510610] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:09:32.612093 2026] [authz_core:error] [pid 510357:tid 510610] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:09:32.623331 2026] [security2:error] [pid 510357:tid 510503] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/vpn.php"] [unique_id "apPlPH5YTqJxoOZUSXtmgwAABcM"]
[Sun Aug 30 03:09:32.624228 2026] [security2:error] [pid 510357:tid 510510] [client 20.104.18.15:16651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/coffexium.php"] [unique_id "apPlPH5YTqJxoOZUSXtmhAAABco"]
[Sun Aug 30 03:09:32.638977 2026] [security2:error] [pid 510357:tid 510514] [client 20.104.49.130:57496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/echkm.php"] [unique_id "apPlPH5YTqJxoOZUSXtmkAAABc4"]
[Sun Aug 30 03:09:32.644723 2026] [security2:error] [pid 510357:tid 510541] [client 68.155.159.216:62640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/file17.php"] [unique_id "apPlPH5YTqJxoOZUSXtmlwAABek"]
[Sun Aug 30 03:09:32.688081 2026] [security2:error] [pid 510357:tid 510535] [client 20.48.251.3:64270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/ammika.php"] [unique_id "apPlPH5YTqJxoOZUSXtmrwAABeM"]
[Sun Aug 30 03:09:32.697295 2026] [security2:error] [pid 510357:tid 510569] [client 20.151.8.82:27473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/insc.php"] [unique_id "apPlPH5YTqJxoOZUSXtmtgAABgU"]
[Sun Aug 30 03:09:32.716815 2026] [security2:error] [pid 510357:tid 510594] [client 52.139.37.240:44562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/7.php"] [unique_id "apPlPH5YTqJxoOZUSXtmyAAABh4"]
[Sun Aug 30 03:09:32.720167 2026] [security2:error] [pid 510357:tid 510532] [client 20.104.18.15:22485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/classwithtostring.php"] [unique_id "apPlPH5YTqJxoOZUSXtmygAABeA"]
[Sun Aug 30 03:09:32.733450 2026] [security2:error] [pid 510357:tid 510576] [client 20.63.81.20:60278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/f.php"] [unique_id "apPlPH5YTqJxoOZUSXtm0QAABgw"]
[Sun Aug 30 03:09:32.734844 2026] [security2:error] [pid 510357:tid 510515] [client 20.104.50.220:59563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/black.php"] [unique_id "apPlPH5YTqJxoOZUSXtm0gAABc8"]
[Sun Aug 30 03:09:32.738655 2026] [security2:error] [pid 510357:tid 510550] [client 158.23.147.79:56478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-admin/about.php"] [unique_id "apPlPH5YTqJxoOZUSXtm0wAABfI"]
[Sun Aug 30 03:09:32.772537 2026] [security2:error] [pid 510357:tid 510530] [client 4.205.62.107:36651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/file21.php"] [unique_id "apPlPH5YTqJxoOZUSXtm3QAABd4"]
[Sun Aug 30 03:09:32.775799 2026] [security2:error] [pid 510357:tid 510577] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/goods.php"] [unique_id "apPlPH5YTqJxoOZUSXtm3gAABg0"]
[Sun Aug 30 03:09:32.794570 2026] [security2:error] [pid 510357:tid 510583] [client 4.205.62.107:25756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/xp.php"] [unique_id "apPlPH5YTqJxoOZUSXtm5QAABhM"]
[Sun Aug 30 03:09:32.805980 2026] [security2:error] [pid 510357:tid 510507] [client 20.151.200.44:28642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/sf.php"] [unique_id "apPlPH5YTqJxoOZUSXtm6gAABcc"]
[Sun Aug 30 03:09:32.840037 2026] [security2:error] [pid 510357:tid 510531] [client 4.205.62.107:17099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/asa.php"] [unique_id "apPlPH5YTqJxoOZUSXtm8QAABd8"]
[Sun Aug 30 03:09:32.869035 2026] [security2:error] [pid 510357:tid 510562] [client 20.63.81.20:60121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ourcalmchrysalis.com"] [uri "/1dfcd2d08f.php"] [unique_id "apPlPH5YTqJxoOZUSXtm9AAABf4"]
[Sun Aug 30 03:09:32.886969 2026] [security2:error] [pid 510357:tid 510532] [client 20.151.200.44:41920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/ssss.php"] [unique_id "apPlPH5YTqJxoOZUSXtm-QAABeA"]
[Sun Aug 30 03:09:32.897920 2026] [security2:error] [pid 510357:tid 510610] [client 20.151.8.82:27533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/file.php"] [unique_id "apPlPH5YTqJxoOZUSXtm_wAABi4"]
[Sun Aug 30 03:09:32.915972 2026] [security2:error] [pid 510357:tid 510561] [client 20.104.49.130:43589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/ops.php"] [unique_id "apPlPH5YTqJxoOZUSXtnBgAABf0"]
[Sun Aug 30 03:09:32.930996 2026] [security2:error] [pid 510357:tid 510578] [client 52.139.37.240:44605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/b.php"] [unique_id "apPlPH5YTqJxoOZUSXtnCgAABg4"]
[Sun Aug 30 03:09:32.970336 2026] [security2:error] [pid 510357:tid 510513] [client 20.104.50.220:33280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/x13.php"] [unique_id "apPlPH5YTqJxoOZUSXtnFgAABc0"]
[Sun Aug 30 03:09:32.982659 2026] [security2:error] [pid 510357:tid 510592] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/alfa.php"] [unique_id "apPlPH5YTqJxoOZUSXtnHgAABhw"]
[Sun Aug 30 03:09:32.995655 2026] [security2:error] [pid 510357:tid 510614] [client 158.158.54.35:2709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/aleXus.php"] [unique_id "apPlPH5YTqJxoOZUSXtnJwAABjI"]
[Sun Aug 30 03:09:33.004430 2026] [authz_core:error] [pid 510357:tid 510491] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp
[Sun Aug 30 03:09:33.004700 2026] [authz_core:error] [pid 510357:tid 510491] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp
[Sun Aug 30 03:09:33.034046 2026] [authz_core:error] [pid 510357:tid 510515] [client 66.249.66.198:51331] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:33.034327 2026] [authz_core:error] [pid 510357:tid 510515] [client 66.249.66.198:51331] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:33.112572 2026] [security2:error] [pid 510357:tid 510592] [client 4.205.62.107:61710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/u88.php"] [unique_id "apPlPX5YTqJxoOZUSXtnSQAABhw"]
[Sun Aug 30 03:09:33.127214 2026] [security2:error] [pid 510357:tid 510525] [client 52.139.37.240:44617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/buy.php"] [unique_id "apPlPX5YTqJxoOZUSXtnUAAABdk"]
[Sun Aug 30 03:09:33.127413 2026] [security2:error] [pid 510357:tid 510549] [client 20.151.8.82:27558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/dex.php"] [unique_id "apPlPX5YTqJxoOZUSXtnUQAABfE"]
[Sun Aug 30 03:09:33.132069 2026] [authz_core:error] [pid 510357:tid 510567] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:33.132361 2026] [authz_core:error] [pid 510357:tid 510567] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:33.139836 2026] [security2:error] [pid 510357:tid 510598] [client 20.48.251.3:64456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/agg.php"] [unique_id "apPlPX5YTqJxoOZUSXtnVAAABiI"]
[Sun Aug 30 03:09:33.177512 2026] [security2:error] [pid 510357:tid 510579] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/133.php"] [unique_id "apPlPX5YTqJxoOZUSXtnXgAABg8"]
[Sun Aug 30 03:09:33.200913 2026] [authz_core:error] [pid 510357:tid 510581] [client 66.249.66.77:40914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:33.201167 2026] [authz_core:error] [pid 510357:tid 510581] [client 66.249.66.77:40914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:33.212898 2026] [security2:error] [pid 510357:tid 510606] [client 20.104.50.220:5919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/login.php"] [unique_id "apPlPX5YTqJxoOZUSXtnaQAABio"]
[Sun Aug 30 03:09:33.223088 2026] [authz_core:error] [pid 510357:tid 510536] [client 216.73.216.128:65399] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:33.223364 2026] [authz_core:error] [pid 510357:tid 510536] [client 216.73.216.128:65399] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:33.251094 2026] [security2:error] [pid 510357:tid 510535] [client 20.104.50.220:63231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/122.php"] [unique_id "apPlPX5YTqJxoOZUSXtncQAABeM"]
[Sun Aug 30 03:09:33.259800 2026] [security2:error] [pid 510357:tid 510558] [client 20.151.8.82:27585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/key.php"] [unique_id "apPlPX5YTqJxoOZUSXtndwAABfo"]
[Sun Aug 30 03:09:33.276248 2026] [security2:error] [pid 510357:tid 510583] [client 158.23.147.79:56448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apPlPX5YTqJxoOZUSXtnhAAABhM"]
[Sun Aug 30 03:09:33.278155 2026] [security2:error] [pid 510357:tid 510518] [client 34.100.204.203:50532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/old_phpinfo.php"] [unique_id "apPlPX5YTqJxoOZUSXtnhQAABdI"]
[Sun Aug 30 03:09:33.288843 2026] [security2:error] [pid 510357:tid 510584] [client 20.104.18.15:35043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/ssla.php"] [unique_id "apPlPX5YTqJxoOZUSXtnigAABhQ"]
[Sun Aug 30 03:09:33.314340 2026] [authz_core:error] [pid 510357:tid 510542] [client 216.73.216.128:43208] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:33.314613 2026] [authz_core:error] [pid 510357:tid 510542] [client 216.73.216.128:43208] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:33.321107 2026] [security2:error] [pid 510357:tid 510537] [client 52.139.37.240:44552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/config.php"] [unique_id "apPlPX5YTqJxoOZUSXtnkAAABeU"]
[Sun Aug 30 03:09:33.331062 2026] [security2:error] [pid 510357:tid 510509] [client 20.104.50.220:16586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/g.php"] [unique_id "apPlPX5YTqJxoOZUSXtnlAAABck"]
[Sun Aug 30 03:09:33.338949 2026] [security2:error] [pid 510357:tid 510587] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/sym.php"] [unique_id "apPlPX5YTqJxoOZUSXtnmQAABhc"]
[Sun Aug 30 03:09:33.365311 2026] [security2:error] [pid 510357:tid 510540] [client 20.48.251.3:59883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/xa.php"] [unique_id "apPlPX5YTqJxoOZUSXtnmwAABeg"]
[Sun Aug 30 03:09:33.382673 2026] [security2:error] [pid 510357:tid 510526] [client 20.104.50.220:32556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/file52.php"] [unique_id "apPlPX5YTqJxoOZUSXtnnQAABdo"]
[Sun Aug 30 03:09:33.392996 2026] [security2:error] [pid 510357:tid 510559] [client 20.151.8.82:27645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/kir.php"] [unique_id "apPlPX5YTqJxoOZUSXtnoAAABfs"]
[Sun Aug 30 03:09:33.423876 2026] [security2:error] [pid 510357:tid 510544] [client 20.104.18.15:18363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/robot.php"] [unique_id "apPlPX5YTqJxoOZUSXtnqQAABew"]
[Sun Aug 30 03:09:33.426735 2026] [security2:error] [pid 510357:tid 510554] [client 20.104.49.130:53531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/zoo2.php"] [unique_id "apPlPX5YTqJxoOZUSXtnqgAABfY"]
[Sun Aug 30 03:09:33.446411 2026] [security2:error] [pid 510357:tid 510560] [client 20.48.251.3:59305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/ccou.php"] [unique_id "apPlPX5YTqJxoOZUSXtntQAABfw"]
[Sun Aug 30 03:09:33.457565 2026] [security2:error] [pid 510357:tid 510575] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/8.php"] [unique_id "apPlPX5YTqJxoOZUSXtnwQAABgs"]
[Sun Aug 30 03:09:33.468511 2026] [authz_core:error] [pid 510357:tid 510598] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:33.468789 2026] [authz_core:error] [pid 510357:tid 510598] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:33.475105 2026] [security2:error] [pid 510357:tid 510608] [client 158.158.54.35:5397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/cJLGqzB.php"] [unique_id "apPlPX5YTqJxoOZUSXtnzgAABiw"]
[Sun Aug 30 03:09:33.521484 2026] [security2:error] [pid 510357:tid 510596] [client 52.139.37.240:44602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/num.php"] [unique_id "apPlPX5YTqJxoOZUSXtn4AAABiA"]
[Sun Aug 30 03:09:33.530062 2026] [security2:error] [pid 510357:tid 510556] [client 20.151.8.82:27470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/nofile.php"] [unique_id "apPlPX5YTqJxoOZUSXtn4wAABfg"]
[Sun Aug 30 03:09:33.554809 2026] [security2:error] [pid 510357:tid 510494] [client 158.23.147.79:57722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apPlPX5YTqJxoOZUSXtn8AAABbo"]
[Sun Aug 30 03:09:33.555469 2026] [security2:error] [pid 510357:tid 510578] [client 68.155.159.216:52544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/file.php"] [unique_id "apPlPX5YTqJxoOZUSXtn8gAABg4"]
[Sun Aug 30 03:09:33.579591 2026] [security2:error] [pid 510357:tid 510572] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/ws55.php"] [unique_id "apPlPX5YTqJxoOZUSXtn9QAABgg"]
[Sun Aug 30 03:09:33.591784 2026] [authz_core:error] [pid 510357:tid 510495] [client 216.73.216.128:43208] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:33.592072 2026] [authz_core:error] [pid 510357:tid 510495] [client 216.73.216.128:43208] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:33.592887 2026] [security2:error] [pid 510357:tid 510551] [client 20.104.50.220:62805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/tuyul.php"] [unique_id "apPlPX5YTqJxoOZUSXtn_QAABfM"]
[Sun Aug 30 03:09:33.669612 2026] [security2:error] [pid 510357:tid 510615] [client 20.104.49.130:32768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/av.php"] [unique_id "apPlPX5YTqJxoOZUSXtoLwAABjM"]
[Sun Aug 30 03:09:33.674584 2026] [security2:error] [pid 510357:tid 510572] [client 216.73.216.128:65399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_config_quote_replace_string"] [unique_id "apPlPX5YTqJxoOZUSXtoNQAABgg"]
[Sun Aug 30 03:09:33.675507 2026] [security2:error] [pid 510357:tid 510595] [client 20.104.50.220:29598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/repair.php"] [unique_id "apPlPX5YTqJxoOZUSXtoNgAABh8"]
[Sun Aug 30 03:09:33.679402 2026] [security2:error] [pid 510357:tid 510533] [client 20.104.18.15:43302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/beck.php"] [unique_id "apPlPX5YTqJxoOZUSXtoNwAABeE"]
[Sun Aug 30 03:09:33.698956 2026] [security2:error] [pid 510357:tid 510492] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/indo.php"] [unique_id "apPlPX5YTqJxoOZUSXtoQAAABbg"]
[Sun Aug 30 03:09:33.713821 2026] [security2:error] [pid 510357:tid 510544] [client 52.139.37.240:44582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/areak1.php"] [unique_id "apPlPX5YTqJxoOZUSXtoRgAABew"]
[Sun Aug 30 03:09:33.718276 2026] [security2:error] [pid 510357:tid 510520] [client 20.104.49.130:52119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/df.php"] [unique_id "apPlPX5YTqJxoOZUSXtoSQAABdQ"]
[Sun Aug 30 03:09:33.721904 2026] [authz_core:error] [pid 510357:tid 510562] [client 66.249.66.193:47918] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:33.722272 2026] [authz_core:error] [pid 510357:tid 510562] [client 66.249.66.193:47918] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:33.735591 2026] [security2:error] [pid 510357:tid 510510] [client 20.48.251.3:33333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/app_local.php"] [unique_id "apPlPX5YTqJxoOZUSXtoTQAABco"]
[Sun Aug 30 03:09:33.739745 2026] [security2:error] [pid 510357:tid 510574] [client 20.104.50.220:51584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/modul.php"] [unique_id "apPlPX5YTqJxoOZUSXtoTgAABgo"]
[Sun Aug 30 03:09:33.744665 2026] [security2:error] [pid 510357:tid 510587] [client 20.151.8.82:27487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/fling.php"] [unique_id "apPlPX5YTqJxoOZUSXtoUAAABhc"]
[Sun Aug 30 03:09:33.774271 2026] [security2:error] [pid 510357:tid 510568] [client 20.104.18.15:64785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/coffee.php"] [unique_id "apPlPX5YTqJxoOZUSXtoUwAABgQ"]
[Sun Aug 30 03:09:33.777630 2026] [authz_core:error] [pid 510357:tid 510565] [client 216.73.216.128:33641] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:33.778086 2026] [authz_core:error] [pid 510357:tid 510565] [client 216.73.216.128:33641] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:33.805067 2026] [core:alert] [pid 510357:tid 510572] [client 96.237.158.242:0] /home3/lordrcan/public_html/.htaccess: without matching section, referer: http://www.lordrcane.com/
[Sun Aug 30 03:09:33.806879 2026] [security2:error] [pid 510357:tid 510583] [client 68.155.159.216:62630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/file5.php"] [unique_id "apPlPX5YTqJxoOZUSXtoZQAABhM"]
[Sun Aug 30 03:09:33.818992 2026] [security2:error] [pid 510357:tid 510491] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wnnjpsby.php"] [unique_id "apPlPX5YTqJxoOZUSXtoawAABbc"]
[Sun Aug 30 03:09:33.820243 2026] [security2:error] [pid 510357:tid 510613] [client 20.48.251.3:64297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/broadcasting.php"] [unique_id "apPlPX5YTqJxoOZUSXtobAAABjE"]
[Sun Aug 30 03:09:33.833810 2026] [security2:error] [pid 510357:tid 510589] [client 20.151.200.44:28648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/4e.php"] [unique_id "apPlPX5YTqJxoOZUSXtobgAABhk"]
[Sun Aug 30 03:09:33.861774 2026] [security2:error] [pid 510357:tid 510563] [client 20.104.18.15:22478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPlPX5YTqJxoOZUSXtocQAABf8"]
[Sun Aug 30 03:09:33.902114 2026] [security2:error] [pid 510357:tid 510516] [client 20.151.8.82:27530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/zoo1.php"] [unique_id "apPlPX5YTqJxoOZUSXtofgAABdA"]
[Sun Aug 30 03:09:33.905766 2026] [security2:error] [pid 510357:tid 510532] [client 20.104.18.15:16651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/classwithtostring.php"] [unique_id "apPlPX5YTqJxoOZUSXtogAAABeA"]
[Sun Aug 30 03:09:33.905800 2026] [security2:error] [pid 510357:tid 510511] [client 20.104.50.220:61654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/by.php"] [unique_id "apPlPX5YTqJxoOZUSXtogQAABcs"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:33.930024 2026] [security2:error] [pid 510357:tid 510513] [client 158.23.147.79:57683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/chosen.php"] [unique_id "apPlPX5YTqJxoOZUSXtoiAAABc0"]
[Sun Aug 30 03:09:33.934986 2026] [authz_core:error] [pid 510357:tid 510530] [client 66.249.66.73:60554] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:33.935392 2026] [authz_core:error] [pid 510357:tid 510530] [client 66.249.66.73:60554] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:33.935738 2026] [security2:error] [pid 510357:tid 510568] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/info.php/new.php"] [unique_id "apPlPX5YTqJxoOZUSXtoigAABgQ"]
[Sun Aug 30 03:09:33.937159 2026] [security2:error] [pid 510357:tid 510577] [client 4.205.62.107:26948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/g3.php"] [unique_id "apPlPX5YTqJxoOZUSXtojAAABg0"]
[Sun Aug 30 03:09:33.960704 2026] [security2:error] [pid 510357:tid 510508] [client 52.139.37.240:44587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/vc.php"] [unique_id "apPlPX5YTqJxoOZUSXtolQAABcg"]
[Sun Aug 30 03:09:33.969921 2026] [security2:error] [pid 510357:tid 510503] [client 158.158.54.35:5066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/inc.php"] [unique_id "apPlPX5YTqJxoOZUSXtomAAABcM"]
[Sun Aug 30 03:09:33.975148 2026] [security2:error] [pid 510357:tid 510617] [client 4.205.62.107:36681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/mcebraed.php"] [unique_id "apPlPX5YTqJxoOZUSXtonAAABjU"]
[Sun Aug 30 03:09:33.978395 2026] [security2:error] [pid 510357:tid 510552] [client 4.205.62.107:17149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/radio.php"] [unique_id "apPlPX5YTqJxoOZUSXtonQAABfQ"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:34.036666 2026] [security2:error] [pid 510357:tid 510511] [client 20.151.8.82:27603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/btyuio.php"] [unique_id "apPlPn5YTqJxoOZUSXtotwAABcs"]
[Sun Aug 30 03:09:34.041519 2026] [security2:error] [pid 510357:tid 510559] [client 20.104.49.130:59539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/talkxkej.php"] [unique_id "apPlPn5YTqJxoOZUSXtougAABfs"]
[Sun Aug 30 03:09:34.070638 2026] [authz_core:error] [pid 510357:tid 510560] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:34.070915 2026] [authz_core:error] [pid 510357:tid 510560] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:34.074091 2026] [security2:error] [pid 510357:tid 510504] [client 34.100.204.203:50544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/server-info.php"] [unique_id "apPlPn5YTqJxoOZUSXtowgAABcQ"]
[Sun Aug 30 03:09:34.123180 2026] [security2:error] [pid 510357:tid 510561] [client 20.104.50.220:32911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/ntaps.php"] [unique_id "apPlPn5YTqJxoOZUSXto3wAABf0"]
[Sun Aug 30 03:09:34.129822 2026] [security2:error] [pid 510357:tid 510576] [client 216.73.216.128:54507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/files.html"] [unique_id "apPlPn5YTqJxoOZUSXto4wAABgw"]
[Sun Aug 30 03:09:34.153926 2026] [security2:error] [pid 510357:tid 510586] [client 52.139.37.240:43096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPlPn5YTqJxoOZUSXto7QAABhY"]
[Sun Aug 30 03:09:34.185580 2026] [security2:error] [pid 510357:tid 510618] [client 20.151.8.82:27476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/00zip.php"] [unique_id "apPlPn5YTqJxoOZUSXto9AAABjY"]
[Sun Aug 30 03:09:34.250742 2026] [security2:error] [pid 510357:tid 510549] [client 4.205.62.107:61784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/config/laravolt/css/index.php"] [unique_id "apPlPn5YTqJxoOZUSXtpBAAABfE"]
[Sun Aug 30 03:09:34.264374 2026] [security2:error] [pid 510357:tid 510572] [client 20.104.49.130:63516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/xmini4.php"] [unique_id "apPlPn5YTqJxoOZUSXtpDQAABgg"]
[Sun Aug 30 03:09:34.265292 2026] [security2:error] [pid 510357:tid 510596] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/w.php"] [unique_id "apPlPn5YTqJxoOZUSXtpDwAABiA"]
[Sun Aug 30 03:09:34.316658 2026] [security2:error] [pid 510357:tid 510539] [client 20.151.8.82:27635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/silver.php"] [unique_id "apPlPn5YTqJxoOZUSXtpIgAABec"]
[Sun Aug 30 03:09:34.347901 2026] [security2:error] [pid 510357:tid 510595] [client 52.139.37.240:43099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/core.php"] [unique_id "apPlPn5YTqJxoOZUSXtpKgAABh8"]
[Sun Aug 30 03:09:34.365618 2026] [security2:error] [pid 510357:tid 510618] [client 20.104.50.220:5927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/logout.php"] [unique_id "apPlPn5YTqJxoOZUSXtpLwAABjY"]
[Sun Aug 30 03:09:34.379988 2026] [security2:error] [pid 510357:tid 510554] [client 20.48.250.41:38801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlPn5YTqJxoOZUSXtpMAAABfY"]
[Sun Aug 30 03:09:34.384762 2026] [security2:error] [pid 510357:tid 510542] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/x.php"] [unique_id "apPlPn5YTqJxoOZUSXtpMwAABeo"]
[Sun Aug 30 03:09:34.398448 2026] [security2:error] [pid 510357:tid 510573] [client 20.104.50.220:59389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/green1.php"] [unique_id "apPlPn5YTqJxoOZUSXtpNwAABgk"]
[Sun Aug 30 03:09:34.406309 2026] [security2:error] [pid 510357:tid 510497] [client 209.141.32.143:43748] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "lordrcane.com"] [uri "/wp-content/plugins/tutor/readme.txt"] [unique_id "apPlPn5YTqJxoOZUSXtpPQAABb0"]
[Sun Aug 30 03:09:34.434025 2026] [security2:error] [pid 510357:tid 510491] [client 20.104.18.15:35012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apPlPn5YTqJxoOZUSXtpRwAABbc"]
[Sun Aug 30 03:09:34.439904 2026] [security2:error] [pid 510357:tid 510617] [client 158.23.147.79:57719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/goods.php"] [unique_id "apPlPn5YTqJxoOZUSXtpTwAABjU"]
[Sun Aug 30 03:09:34.447179 2026] [security2:error] [pid 510357:tid 510562] [client 20.48.251.3:64508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/requirements.php"] [unique_id "apPlPn5YTqJxoOZUSXtpUwAABf4"]
[Sun Aug 30 03:09:34.461201 2026] [security2:error] [pid 510357:tid 510538] [client 20.104.50.220:17274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/tx1.php"] [unique_id "apPlPn5YTqJxoOZUSXtpXgAABeY"]
[Sun Aug 30 03:09:34.480978 2026] [authz_core:error] [pid 510357:tid 510500] [client 66.249.66.66:51789] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:34.481429 2026] [authz_core:error] [pid 510357:tid 510500] [client 66.249.66.66:51789] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:34.498599 2026] [security2:error] [pid 510357:tid 510543] [client 158.158.54.35:29317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/aged.php"] [unique_id "apPlPn5YTqJxoOZUSXtpbgAABes"]
[Sun Aug 30 03:09:34.502378 2026] [security2:error] [pid 510357:tid 510521] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apPlPn5YTqJxoOZUSXtpcAAABdU"]
[Sun Aug 30 03:09:34.508539 2026] [authz_core:error] [pid 510357:tid 510604] [client 216.73.216.128:33641] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:34.509057 2026] [authz_core:error] [pid 510357:tid 510604] [client 216.73.216.128:33641] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:34.518455 2026] [authz_core:error] [pid 510357:tid 510588] [client 66.249.66.67:46840] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:34.518787 2026] [authz_core:error] [pid 510357:tid 510588] [client 66.249.66.67:46840] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:34.530364 2026] [security2:error] [pid 510357:tid 510584] [client 20.48.251.3:59495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/ws61.php"] [unique_id "apPlPn5YTqJxoOZUSXtpegAABhQ"]
[Sun Aug 30 03:09:34.554053 2026] [security2:error] [pid 510357:tid 510512] [client 52.139.37.240:43135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/wp-content/min.php"] [unique_id "apPlPn5YTqJxoOZUSXtpjQAABcw"]
[Sun Aug 30 03:09:34.556217 2026] [authz_core:error] [pid 510357:tid 510592] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:34.556763 2026] [authz_core:error] [pid 510357:tid 510592] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:34.560695 2026] [security2:error] [pid 510357:tid 510599] [client 20.151.8.82:27512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/wp-mails.php"] [unique_id "apPlPn5YTqJxoOZUSXtpkgAABiM"]
[Sun Aug 30 03:09:34.565244 2026] [security2:error] [pid 510357:tid 510535] [client 20.104.18.15:18336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/revo.php"] [unique_id "apPlPn5YTqJxoOZUSXtplAAABeM"]
[Sun Aug 30 03:09:34.575559 2026] [authz_core:error] [pid 510357:tid 510509] [client 66.249.66.68:47893] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:34.576244 2026] [authz_core:error] [pid 510357:tid 510509] [client 66.249.66.68:47893] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:34.599048 2026] [security2:error] [pid 510357:tid 510547] [client 20.48.251.3:59339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/rum.or.php"] [unique_id "apPlPn5YTqJxoOZUSXtpnQAABe8"]
[Sun Aug 30 03:09:34.621304 2026] [security2:error] [pid 510357:tid 510515] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp-includes/index.php"] [unique_id "apPlPn5YTqJxoOZUSXtppwAABc8"]
[Sun Aug 30 03:09:34.643488 2026] [security2:error] [pid 510357:tid 510569] [client 20.104.50.220:32087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/zde.php"] [unique_id "apPlPn5YTqJxoOZUSXtpvQAABgU"]
[Sun Aug 30 03:09:34.665096 2026] [security2:error] [pid 510357:tid 510593] [client 20.48.250.41:38786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlPn5YTqJxoOZUSXtpzwAABh0"]
[Sun Aug 30 03:09:34.687082 2026] [authz_core:error] [pid 510357:tid 510504] [client 216.73.216.128:60637] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:34.687508 2026] [authz_core:error] [pid 510357:tid 510504] [client 216.73.216.128:60637] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:34.731230 2026] [security2:error] [pid 510357:tid 510562] [client 158.23.147.79:57679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apPlPn5YTqJxoOZUSXtp6wAABf4"]
[Sun Aug 30 03:09:34.746867 2026] [security2:error] [pid 510357:tid 510578] [client 52.139.37.240:44581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "apPlPn5YTqJxoOZUSXtp9AAABg4"]
[Sun Aug 30 03:09:34.760267 2026] [security2:error] [pid 510357:tid 510613] [client 20.104.50.220:52821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/nikung.php"] [unique_id "apPlPn5YTqJxoOZUSXtp9gAABjE"]
[Sun Aug 30 03:09:34.767123 2026] [security2:error] [pid 510357:tid 510491] [client 20.151.8.82:27563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/new.php"] [unique_id "apPlPn5YTqJxoOZUSXtp-QAABbc"]
[Sun Aug 30 03:09:34.772063 2026] [security2:error] [pid 510357:tid 510600] [client 216.73.216.128:43208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPlPn5YTqJxoOZUSXtp_AAABiQ"]
[Sun Aug 30 03:09:34.773810 2026] [security2:error] [pid 510357:tid 510539] [client 68.155.159.216:52607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/file17.php"] [unique_id "apPlPn5YTqJxoOZUSXtp_gAABec"]
[Sun Aug 30 03:09:34.789389 2026] [security2:error] [pid 510357:tid 510508] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/dk.php"] [unique_id "apPlPn5YTqJxoOZUSXtqAwAABcg"]
[Sun Aug 30 03:09:34.796516 2026] [security2:error] [pid 510357:tid 510581] [client 40.83.93.50:5157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/data.php"] [unique_id "apPlPn5YTqJxoOZUSXtqCAAABhE"]
[Sun Aug 30 03:09:34.804986 2026] [security2:error] [pid 510357:tid 510531] [client 20.48.250.41:38797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/ff1.php"] [unique_id "apPlPn5YTqJxoOZUSXtqDAAABd8"]
[Sun Aug 30 03:09:34.818351 2026] [security2:error] [pid 510357:tid 510557] [client 20.104.18.15:43915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/t3.php"] [unique_id "apPlPn5YTqJxoOZUSXtqEgAABfk"]
[Sun Aug 30 03:09:34.823844 2026] [security2:error] [pid 510357:tid 510554] [client 20.104.50.220:52831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/raw.php"] [unique_id "apPlPn5YTqJxoOZUSXtqFAAABfY"]
[Sun Aug 30 03:09:34.838809 2026] [security2:error] [pid 510357:tid 510560] [client 34.100.204.203:37830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/server-status.php"] [unique_id "apPlPn5YTqJxoOZUSXtqFwAABfw"]
[Sun Aug 30 03:09:34.885389 2026] [authz_core:error] [pid 510357:tid 510563] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:34.885652 2026] [authz_core:error] [pid 510357:tid 510563] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:34.891110 2026] [security2:error] [pid 510357:tid 510562] [client 20.48.251.3:33335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/ws62.php"] [unique_id "apPlPn5YTqJxoOZUSXtqIwAABf4"]
[Sun Aug 30 03:09:34.898220 2026] [security2:error] [pid 510357:tid 510518] [client 20.104.50.220:51611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/configuration.php"] [unique_id "apPlPn5YTqJxoOZUSXtqJQAABdI"]
[Sun Aug 30 03:09:34.909467 2026] [security2:error] [pid 510357:tid 510568] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apPlPn5YTqJxoOZUSXtqKQAABgQ"]
[Sun Aug 30 03:09:34.911678 2026] [autoindex:error] [pid 510357:tid 510565] [client 34.230.146.223:30617] AH01276: Cannot serve directory /home1/ajaisingh93/public_html/.website_770d4ac7/: No matching DirectoryIndex (index.html,index.php) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:09:34.912521 2026] [core:error] [pid 510357:tid 510565] [client 34.230.146.223:30617] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:09:34.925171 2026] [security2:error] [pid 510357:tid 510567] [client 20.151.8.82:27580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/run.php"] [unique_id "apPlPn5YTqJxoOZUSXtqLQAABgM"]
[Sun Aug 30 03:09:34.950173 2026] [security2:error] [pid 510357:tid 510577] [client 20.48.250.41:38784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/t.php"] [unique_id "apPlPn5YTqJxoOZUSXtqNAAABg0"]
[Sun Aug 30 03:09:34.950366 2026] [security2:error] [pid 510357:tid 510615] [client 52.139.37.240:44576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/ws37.php"] [unique_id "apPlPn5YTqJxoOZUSXtqNQAABjM"]
[Sun Aug 30 03:09:34.954857 2026] [security2:error] [pid 510357:tid 510576] [client 216.73.216.128:25721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts2/updateconf"] [unique_id "apPlPn5YTqJxoOZUSXtqNwAABgw"]
[Sun Aug 30 03:09:34.957650 2026] [security2:error] [pid 510357:tid 510508] [client 68.155.159.216:62598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/file88.php"] [unique_id "apPlPn5YTqJxoOZUSXtqOgAABcg"]
[Sun Aug 30 03:09:34.962872 2026] [security2:error] [pid 510357:tid 510514] [client 20.48.251.3:65492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/aws_config.php"] [unique_id "apPlPn5YTqJxoOZUSXtqPQAABc4"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:35.014372 2026] [security2:error] [pid 510357:tid 510580] [client 20.104.18.15:22503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/5PJcpMFsD8B.php"] [unique_id "apPlP35YTqJxoOZUSXtqXAAABhA"]
[Sun Aug 30 03:09:35.030372 2026] [security2:error] [pid 510357:tid 510495] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/xc.php"] [unique_id "apPlP35YTqJxoOZUSXtqYgAABbs"]
[Sun Aug 30 03:09:35.038102 2026] [security2:error] [pid 510357:tid 510573] [client 20.104.18.15:16694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/wp-ws68.php"] [unique_id "apPlP35YTqJxoOZUSXtqZgAABgk"]
[Sun Aug 30 03:09:35.044287 2026] [authz_core:error] [pid 510357:tid 510515] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:35.044721 2026] [authz_core:error] [pid 510357:tid 510515] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:35.054579 2026] [security2:error] [pid 510357:tid 510595] [client 20.151.200.44:28647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/ssss.php"] [unique_id "apPlP35YTqJxoOZUSXtqawAABh8"]
[Sun Aug 30 03:09:35.058836 2026] [security2:error] [pid 510357:tid 510512] [client 158.158.54.35:25876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/y.php"] [unique_id "apPlP35YTqJxoOZUSXtqbAAABcw"]
[Sun Aug 30 03:09:35.061065 2026] [security2:error] [pid 510357:tid 510596] [client 20.151.8.82:27458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/sm.php"] [unique_id "apPlP35YTqJxoOZUSXtqbgAABiA"]
[Sun Aug 30 03:09:35.061229 2026] [security2:error] [pid 510357:tid 510601] [client 158.23.147.79:57698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apPlP35YTqJxoOZUSXtqbwAABiU"]
[Sun Aug 30 03:09:35.070311 2026] [security2:error] [pid 510357:tid 510577] [client 4.205.62.107:25884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/wp-konfig.php"] [unique_id "apPlP35YTqJxoOZUSXtqcAAABg0"]
[Sun Aug 30 03:09:35.116080 2026] [security2:error] [pid 510357:tid 510535] [client 20.48.250.41:38790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/erty.php"] [unique_id "apPlP35YTqJxoOZUSXtqewAABeM"]
[Sun Aug 30 03:09:35.116932 2026] [security2:error] [pid 510357:tid 510504] [client 4.205.62.107:17102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/xa.php"] [unique_id "apPlP35YTqJxoOZUSXtqfAAABcQ"]
[Sun Aug 30 03:09:35.131254 2026] [security2:error] [pid 510357:tid 510550] [client 4.205.62.107:36722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/server-info.php"] [unique_id "apPlP35YTqJxoOZUSXtqfwAABfI"]
[Sun Aug 30 03:09:35.156494 2026] [security2:error] [pid 510357:tid 510517] [client 20.104.50.220:61978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/byp.php"] [unique_id "apPlP35YTqJxoOZUSXtqhgAABdE"]
[Sun Aug 30 03:09:35.158333 2026] [security2:error] [pid 510357:tid 510586] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp-content/l.php"] [unique_id "apPlP35YTqJxoOZUSXtqhwAABhY"]
[Sun Aug 30 03:09:35.173366 2026] [security2:error] [pid 510357:tid 510506] [client 52.139.37.240:44571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/new.php"] [unique_id "apPlP35YTqJxoOZUSXtqjQAABcY"]
[Sun Aug 30 03:09:35.187975 2026] [security2:error] [pid 510357:tid 510552] [client 216.73.216.128:35938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlP35YTqJxoOZUSXtqkAAABfQ"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:35.209383 2026] [security2:error] [pid 510357:tid 510605] [client 20.151.8.82:27564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/araso.php"] [unique_id "apPlP35YTqJxoOZUSXtqlwAABik"]
[Sun Aug 30 03:09:35.238353 2026] [security2:error] [pid 510357:tid 510508] [client 20.104.49.130:51540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/samll.php"] [unique_id "apPlP35YTqJxoOZUSXtqpQAABcg"]
[Sun Aug 30 03:09:35.243958 2026] [authz_core:error] [pid 510357:tid 510491] [client 216.73.216.128:33641] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:35.244370 2026] [authz_core:error] [pid 510357:tid 510491] [client 216.73.216.128:33641] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:35.262807 2026] [security2:error] [pid 510357:tid 510535] [client 20.104.50.220:33047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/zip.php"] [unique_id "apPlP35YTqJxoOZUSXtqtAAABeM"]
[Sun Aug 30 03:09:35.275321 2026] [security2:error] [pid 510357:tid 510547] [client 40.83.93.50:5831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/dt-the7/css/static-less/plugins/admin.php"] [unique_id "apPlP35YTqJxoOZUSXtquwAABe8"]
[Sun Aug 30 03:09:35.319320 2026] [security2:error] [pid 510357:tid 510552] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp-admin/w.php"] [unique_id "apPlP35YTqJxoOZUSXtqxwAABfQ"]
[Sun Aug 30 03:09:35.353268 2026] [security2:error] [pid 510357:tid 510579] [client 20.151.8.82:27486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/a.php"] [unique_id "apPlP35YTqJxoOZUSXtq1AAABg8"]
[Sun Aug 30 03:09:35.377553 2026] [security2:error] [pid 510357:tid 510512] [client 216.73.216.128:3120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/usage_202601.html"] [unique_id "apPlP35YTqJxoOZUSXtq1gAABcw"]
[Sun Aug 30 03:09:35.391317 2026] [security2:error] [pid 510357:tid 510493] [client 4.205.62.107:61716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/87.php"] [unique_id "apPlP35YTqJxoOZUSXtq2gAABbk"]
[Sun Aug 30 03:09:35.446980 2026] [autoindex:error] [pid 510357:tid 510501] [client 52.139.37.240:44612] AH01276: Cannot serve directory /home2/callahan/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:09:35.447109 2026] [security2:error] [pid 510357:tid 510517] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp-content/k.php"] [unique_id "apPlP35YTqJxoOZUSXtq8QAABdE"]
[Sun Aug 30 03:09:35.461318 2026] [security2:error] [pid 510357:tid 510591] [client 20.48.250.41:38889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/0x.php"] [unique_id "apPlP35YTqJxoOZUSXtq_QAABhs"]
[Sun Aug 30 03:09:35.491518 2026] [security2:error] [pid 510357:tid 510605] [client 20.151.8.82:27459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/ass.php"] [unique_id "apPlP35YTqJxoOZUSXtrDgAABik"]
[Sun Aug 30 03:09:35.510560 2026] [authz_core:error] [pid 510357:tid 510567] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:35.510606 2026] [security2:error] [pid 510357:tid 510592] [client 52.139.37.240:44612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/il.php"] [unique_id "apPlP35YTqJxoOZUSXtrFAAABhw"]
[Sun Aug 30 03:09:35.510888 2026] [authz_core:error] [pid 510357:tid 510567] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:35.524461 2026] [security2:error] [pid 510357:tid 510508] [client 20.104.50.220:5527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/fuck.php"] [unique_id "apPlP35YTqJxoOZUSXtrGgAABcg"]
[Sun Aug 30 03:09:35.529638 2026] [security2:error] [pid 510357:tid 510556] [client 158.23.147.79:57706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/file.php"] [unique_id "apPlP35YTqJxoOZUSXtrHQAABfg"]
[Sun Aug 30 03:09:35.554176 2026] [security2:error] [pid 510357:tid 510520] [client 20.104.50.220:59355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/sukce.php"] [unique_id "apPlP35YTqJxoOZUSXtrJwAABdQ"]
[Sun Aug 30 03:09:35.566222 2026] [security2:error] [pid 510357:tid 510590] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/dev.php"] [unique_id "apPlP35YTqJxoOZUSXtrLAAABho"]
[Sun Aug 30 03:09:35.589411 2026] [authz_core:error] [pid 510357:tid 510551] [client 66.249.66.72:52664] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:35.589886 2026] [authz_core:error] [pid 510357:tid 510551] [client 66.249.66.72:52664] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:35.589909 2026] [security2:error] [pid 510357:tid 510566] [client 20.104.50.220:17241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/xv.php"] [unique_id "apPlP35YTqJxoOZUSXtrMgAABgI"]
[Sun Aug 30 03:09:35.591839 2026] [security2:error] [pid 510357:tid 510606] [client 20.104.18.15:35511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/wp-aothait.php"] [unique_id "apPlP35YTqJxoOZUSXtrNAAABio"]
[Sun Aug 30 03:09:35.610314 2026] [security2:error] [pid 510357:tid 510589] [client 20.48.250.41:38857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/66.php"] [unique_id "apPlP35YTqJxoOZUSXtrQwAABhk"]
[Sun Aug 30 03:09:35.617583 2026] [authz_core:error] [pid 510357:tid 510549] [client 216.73.216.128:33641] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:35.618017 2026] [authz_core:error] [pid 510357:tid 510549] [client 216.73.216.128:33641] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:35.640686 2026] [security2:error] [pid 510357:tid 510560] [client 20.151.8.82:27582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/sb.php"] [unique_id "apPlP35YTqJxoOZUSXtrXQAABfw"]
[Sun Aug 30 03:09:35.641792 2026] [security2:error] [pid 510357:tid 510572] [client 20.48.251.3:6464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/var/www/wallet/index.php"] [unique_id "apPlP35YTqJxoOZUSXtrXwAABgg"]
[Sun Aug 30 03:09:35.662547 2026] [security2:error] [pid 510357:tid 510591] [client 213.209.159.223:15243] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/.env"] [unique_id "apPlP35YTqJxoOZUSXtrawAABhs"]
[Sun Aug 30 03:09:35.670629 2026] [authz_core:error] [pid 510357:tid 510611] [client 66.249.66.71:47584] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:35.671065 2026] [authz_core:error] [pid 510357:tid 510611] [client 66.249.66.71:47584] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:35.678270 2026] [security2:error] [pid 510357:tid 510570] [client 20.104.49.130:63267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/run.php"] [unique_id "apPlP35YTqJxoOZUSXtrdwAABgY"]
[Sun Aug 30 03:09:35.693404 2026] [security2:error] [pid 510357:tid 510613] [client 20.48.251.3:59488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/xza.php"] [unique_id "apPlP35YTqJxoOZUSXtrhQAABjE"]
[Sun Aug 30 03:09:35.702688 2026] [security2:error] [pid 510357:tid 510576] [client 52.139.37.240:44601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/images/index.php"] [unique_id "apPlP35YTqJxoOZUSXtriwAABgw"]
[Sun Aug 30 03:09:35.713253 2026] [security2:error] [pid 510357:tid 510531] [client 20.104.18.15:18396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/birrs.php"] [unique_id "apPlP35YTqJxoOZUSXtrkAAABd8"]
[Sun Aug 30 03:09:35.718488 2026] [security2:error] [pid 510357:tid 510566] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp-activate.php"] [unique_id "apPlP35YTqJxoOZUSXtrlAAABgI"]
[Sun Aug 30 03:09:35.740174 2026] [security2:error] [pid 510357:tid 510506] [client 20.48.251.3:55791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/xmy.php"] [unique_id "apPlP35YTqJxoOZUSXtrmwAABcY"]
[Sun Aug 30 03:09:35.751870 2026] [security2:error] [pid 510357:tid 510552] [client 40.83.93.50:5878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/hideo/network.php"] [unique_id "apPlP35YTqJxoOZUSXtrngAABfQ"]
[Sun Aug 30 03:09:35.775718 2026] [security2:error] [pid 510357:tid 510494] [client 158.23.147.79:57680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/file17.php"] [unique_id "apPlP35YTqJxoOZUSXtroQAABbo"]
[Sun Aug 30 03:09:35.796574 2026] [security2:error] [pid 510357:tid 510565] [client 213.209.159.223:15243] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/api/.env"] [unique_id "apPlP35YTqJxoOZUSXtrqwAABgE"]
[Sun Aug 30 03:09:35.818849 2026] [security2:error] [pid 510357:tid 510604] [client 20.151.8.82:27622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/in.php"] [unique_id "apPlP35YTqJxoOZUSXtrtgAABig"]
[Sun Aug 30 03:09:35.823131 2026] [authz_core:error] [pid 510357:tid 510499] [client 66.249.66.76:60204] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:35.823504 2026] [authz_core:error] [pid 510357:tid 510499] [client 66.249.66.76:60204] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:35.828743 2026] [security2:error] [pid 510357:tid 510572] [client 20.48.250.41:38891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/f35.php"] [unique_id "apPlP35YTqJxoOZUSXtruQAABgg"]
[Sun Aug 30 03:09:35.831086 2026] [security2:error] [pid 510357:tid 510523] [client 158.158.54.35:4718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/delpaths.php"] [unique_id "apPlP35YTqJxoOZUSXtrugAABdc"]
[Sun Aug 30 03:09:35.839580 2026] [security2:error] [pid 510357:tid 510562] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp_blog_footer.php"] [unique_id "apPlP35YTqJxoOZUSXtrvAAABf4"]
[Sun Aug 30 03:09:35.868418 2026] [security2:error] [pid 510357:tid 510598] [client 20.104.50.220:32718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wpo.php"] [unique_id "apPlP35YTqJxoOZUSXtrvgAABiI"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:35.917995 2026] [security2:error] [pid 510357:tid 510515] [client 20.104.50.220:52840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/tertykung.php"] [unique_id "apPlP35YTqJxoOZUSXtrzgAABc8"]
[Sun Aug 30 03:09:35.930481 2026] [security2:error] [pid 510357:tid 510600] [client 213.209.159.223:15243] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/backend/.env"] [unique_id "apPlP35YTqJxoOZUSXtr0gAABiQ"]
[Sun Aug 30 03:09:35.940334 2026] [security2:error] [pid 510357:tid 510570] [client 20.48.250.41:44902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/click.php"] [unique_id "apPlP35YTqJxoOZUSXtr1AAABgY"]
[Sun Aug 30 03:09:35.958724 2026] [security2:error] [pid 510357:tid 510493] [client 20.104.18.15:44011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/wp.php"] [unique_id "apPlP35YTqJxoOZUSXtr2QAABbk"]
[Sun Aug 30 03:09:35.960139 2026] [security2:error] [pid 510357:tid 510597] [client 20.48.250.41:49914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlP35YTqJxoOZUSXtr2wAABiE"]
[Sun Aug 30 03:09:35.961668 2026] [security2:error] [pid 510357:tid 510521] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wefile.php"] [unique_id "apPlP35YTqJxoOZUSXtr3QAABdU"]
[Sun Aug 30 03:09:35.982560 2026] [security2:error] [pid 510357:tid 510599] [client 20.104.50.220:52834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/py.php"] [unique_id "apPlP35YTqJxoOZUSXtr6AAABiM"]
[Sun Aug 30 03:09:36.008983 2026] [authz_core:error] [pid 510357:tid 510568] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:09:36.009258 2026] [authz_core:error] [pid 510357:tid 510568] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:09:36.028497 2026] [security2:error] [pid 510357:tid 510590] [client 20.48.251.3:33340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/grsiuk.php"] [unique_id "apPlQH5YTqJxoOZUSXtr_QAABho"]
[Sun Aug 30 03:09:36.035567 2026] [security2:error] [pid 510357:tid 510558] [client 20.104.50.220:42285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/tai.php"] [unique_id "apPlQH5YTqJxoOZUSXtr_wAABfo"]
[Sun Aug 30 03:09:36.063916 2026] [security2:error] [pid 510357:tid 510492] [client 213.209.159.223:15243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themayorcoffee.com"] [uri "/phpinfo.php"] [unique_id "apPlQH5YTqJxoOZUSXtsBwAABbg"]
[Sun Aug 30 03:09:36.073354 2026] [security2:error] [pid 510357:tid 510561] [client 20.104.49.130:52452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlQH5YTqJxoOZUSXtsCQAABf0"]
[Sun Aug 30 03:09:36.078367 2026] [security2:error] [pid 510357:tid 510609] [client 20.48.250.41:26543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/class.php"] [unique_id "apPlQH5YTqJxoOZUSXtsCwAABi0"]
[Sun Aug 30 03:09:36.083203 2026] [security2:error] [pid 510357:tid 510570] [client 216.73.216.128:39905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts2/updateconf"] [unique_id "apPlQH5YTqJxoOZUSXtsDQAABgY"]
[Sun Aug 30 03:09:36.089760 2026] [security2:error] [pid 510357:tid 510584] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/blog.php"] [unique_id "apPlQH5YTqJxoOZUSXtsEgAABhQ"]
[Sun Aug 30 03:09:36.091077 2026] [security2:error] [pid 510357:tid 510603] [client 68.155.159.216:62631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/NewFile.php/"] [unique_id "apPlQH5YTqJxoOZUSXtsFAAABic"]
[Sun Aug 30 03:09:36.099601 2026] [security2:error] [pid 510357:tid 510586] [client 158.23.147.79:1984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/file5.php"] [unique_id "apPlQH5YTqJxoOZUSXtsFgAABhY"]
[Sun Aug 30 03:09:36.108850 2026] [security2:error] [pid 510357:tid 510601] [client 20.48.251.3:64319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/dialog.php"] [unique_id "apPlQH5YTqJxoOZUSXtsGQAABiU"]
[Sun Aug 30 03:09:36.114186 2026] [security2:error] [pid 510357:tid 510548] [client 20.48.250.41:49803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/ff1.php"] [unique_id "apPlQH5YTqJxoOZUSXtsGwAABfA"]
[Sun Aug 30 03:09:36.142609 2026] [security2:error] [pid 510357:tid 510607] [client 34.100.204.203:37840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/webroot/index.php/_environment"] [unique_id "apPlQH5YTqJxoOZUSXtsJQAABis"]
[Sun Aug 30 03:09:36.152760 2026] [security2:error] [pid 510357:tid 510567] [client 20.48.250.41:44918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/ms.php"] [unique_id "apPlQH5YTqJxoOZUSXtsKQAABgM"]
[Sun Aug 30 03:09:36.172663 2026] [security2:error] [pid 510357:tid 510575] [client 20.104.18.15:22419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPlQH5YTqJxoOZUSXtsLwAABgs"]
[Sun Aug 30 03:09:36.178886 2026] [security2:error] [pid 510357:tid 510566] [client 20.104.49.130:36773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/xwpg.php"] [unique_id "apPlQH5YTqJxoOZUSXtsMgAABgI"]
[Sun Aug 30 03:09:36.183496 2026] [security2:error] [pid 510357:tid 510512] [client 20.104.18.15:64770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/mgrr.php"] [unique_id "apPlQH5YTqJxoOZUSXtsMwAABcw"]
[Sun Aug 30 03:09:36.209027 2026] [security2:error] [pid 510357:tid 510506] [client 4.205.62.107:25510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/25.php"] [unique_id "apPlQH5YTqJxoOZUSXtsOwAABcY"]
[Sun Aug 30 03:09:36.216625 2026] [security2:error] [pid 510357:tid 510600] [client 40.83.93.50:5159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPlQH5YTqJxoOZUSXtsPgAABiQ"]
[Sun Aug 30 03:09:36.243682 2026] [security2:error] [pid 510357:tid 510596] [client 114.119.156.71:30515] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.brandscape.qa"] [uri "/images/background/bg-11.jpg"] [unique_id "apPlQH5YTqJxoOZUSXtsQQAABiA"], referer: https://www.brandscape.qa/
[Sun Aug 30 03:09:36.245263 2026] [security2:error] [pid 510357:tid 510570] [client 20.48.250.41:26460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/8.php"] [unique_id "apPlQH5YTqJxoOZUSXtsQgAABgY"]
[Sun Aug 30 03:09:36.248859 2026] [security2:error] [pid 510357:tid 510493] [client 20.48.250.41:49916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/t.php"] [unique_id "apPlQH5YTqJxoOZUSXtsRAAABbk"]
[Sun Aug 30 03:09:36.250359 2026] [security2:error] [pid 510357:tid 510586] [client 4.205.62.107:17139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/ws61.php"] [unique_id "apPlQH5YTqJxoOZUSXtsRwAABhY"]
[Sun Aug 30 03:09:36.273432 2026] [authz_core:error] [pid 510357:tid 510589] [client 216.73.216.128:60637] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:36.273739 2026] [authz_core:error] [pid 510357:tid 510589] [client 216.73.216.128:60637] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:36.288404 2026] [security2:error] [pid 510357:tid 510599] [client 4.205.62.107:36642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/gk.php"] [unique_id "apPlQH5YTqJxoOZUSXtsWgAABiM"]
[Sun Aug 30 03:09:36.289187 2026] [security2:error] [pid 510357:tid 510607] [client 20.48.250.41:44901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/zxekqlxb.php"] [unique_id "apPlQH5YTqJxoOZUSXtsWwAABis"]
[Sun Aug 30 03:09:36.321752 2026] [authz_core:error] [pid 510357:tid 510536] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:36.322215 2026] [authz_core:error] [pid 510357:tid 510536] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:36.329178 2026] [security2:error] [pid 510357:tid 510550] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp-admin/js/wp-load.php"] [unique_id "apPlQH5YTqJxoOZUSXtsZgAABfI"]
[Sun Aug 30 03:09:36.341136 2026] [security2:error] [pid 510357:tid 510512] [client 20.104.50.220:63026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/con.php"] [unique_id "apPlQH5YTqJxoOZUSXtsawAABcw"]
[Sun Aug 30 03:09:36.380023 2026] [security2:error] [pid 510357:tid 510584] [client 20.48.250.41:49805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/erty.php"] [unique_id "apPlQH5YTqJxoOZUSXtsdwAABhQ"]
[Sun Aug 30 03:09:36.381517 2026] [core:alert] [pid 510357:tid 510493] [client 38.191.38.107:0] /home3/lordrcan/public_html/.htaccess: without matching section, referer: http://www.lordrcane.com/
[Sun Aug 30 03:09:36.388746 2026] [security2:error] [pid 510357:tid 510601] [client 20.104.49.130:53878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/fling.php"] [unique_id "apPlQH5YTqJxoOZUSXtsfQAABiU"]
[Sun Aug 30 03:09:36.399821 2026] [security2:error] [pid 510357:tid 510604] [client 20.104.50.220:33085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/@.php"] [unique_id "apPlQH5YTqJxoOZUSXtsgwAABig"]
[Sun Aug 30 03:09:36.413603 2026] [security2:error] [pid 510357:tid 510503] [client 158.158.54.35:2818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/alfanew.php7"] [unique_id "apPlQH5YTqJxoOZUSXtsiAAABcM"]
[Sun Aug 30 03:09:36.415125 2026] [security2:error] [pid 510357:tid 510607] [client 20.48.250.41:45049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/init.php"] [unique_id "apPlQH5YTqJxoOZUSXtsigAABis"]
[Sun Aug 30 03:09:36.423026 2026] [security2:error] [pid 510357:tid 510508] [client 158.23.147.79:56464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/file88.php"] [unique_id "apPlQH5YTqJxoOZUSXtsjQAABcg"]
[Sun Aug 30 03:09:36.440180 2026] [security2:error] [pid 510357:tid 510538] [client 52.139.37.240:44559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/lite.php"] [unique_id "apPlQH5YTqJxoOZUSXtslAAABeY"]
[Sun Aug 30 03:09:36.441659 2026] [security2:error] [pid 510357:tid 510549] [client 20.48.250.41:26499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/0x0x.php"] [unique_id "apPlQH5YTqJxoOZUSXtslQAABfE"]
[Sun Aug 30 03:09:36.453683 2026] [security2:error] [pid 510357:tid 510611] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/robot.php"] [unique_id "apPlQH5YTqJxoOZUSXtsnwAABi8"]
[Sun Aug 30 03:09:36.456119 2026] [authz_core:error] [pid 510357:tid 510562] [client 66.249.66.39:43435] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:36.456379 2026] [authz_core:error] [pid 510357:tid 510562] [client 66.249.66.39:43435] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:36.477337 2026] [security2:error] [pid 510357:tid 510506] [client 20.104.49.130:60950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/users.php"] [unique_id "apPlQH5YTqJxoOZUSXtsqQAABcY"]
[Sun Aug 30 03:09:36.500490 2026] [authz_core:error] [pid 510357:tid 510547] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:36.500762 2026] [authz_core:error] [pid 510357:tid 510547] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:36.511954 2026] [security2:error] [pid 510357:tid 510548] [client 20.104.49.130:63292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/makeasmtp.php"] [unique_id "apPlQH5YTqJxoOZUSXtstwAABfA"]
[Sun Aug 30 03:09:36.513467 2026] [security2:error] [pid 510357:tid 510507] [client 20.48.250.41:49804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/0x.php"] [unique_id "apPlQH5YTqJxoOZUSXtsuAAABcc"]
[Sun Aug 30 03:09:36.542223 2026] [security2:error] [pid 510357:tid 510508] [client 4.205.62.107:58443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/plss3.php"] [unique_id "apPlQH5YTqJxoOZUSXtsxgAABcg"]
[Sun Aug 30 03:09:36.581222 2026] [security2:error] [pid 510357:tid 510512] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/sss.php"] [unique_id "apPlQH5YTqJxoOZUSXts0gAABcw"]
[Sun Aug 30 03:09:36.598906 2026] [security2:error] [pid 510357:tid 510571] [client 20.48.250.41:44968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/term.php"] [unique_id "apPlQH5YTqJxoOZUSXts2gAABgc"]
[Sun Aug 30 03:09:36.633614 2026] [security2:error] [pid 510357:tid 510615] [client 52.139.37.240:44610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/xda.php"] [unique_id "apPlQH5YTqJxoOZUSXts6wAABjM"]
[Sun Aug 30 03:09:36.636267 2026] [security2:error] [pid 510357:tid 510528] [client 20.48.250.41:26580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/166.php"] [unique_id "apPlQH5YTqJxoOZUSXts7wAABdw"]
[Sun Aug 30 03:09:36.638504 2026] [security2:error] [pid 510357:tid 510518] [client 20.48.250.41:49828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/66.php"] [unique_id "apPlQH5YTqJxoOZUSXts8wAABdI"]
[Sun Aug 30 03:09:36.643531 2026] [authz_core:error] [pid 510357:tid 510601] [client 66.249.66.78:41189] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:36.643965 2026] [authz_core:error] [pid 510357:tid 510601] [client 66.249.66.78:41189] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:36.673878 2026] [security2:error] [pid 510357:tid 510503] [client 20.104.50.220:6141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/outside.php"] [unique_id "apPlQH5YTqJxoOZUSXttCQAABcM"]
[Sun Aug 30 03:09:36.691051 2026] [authz_core:error] [pid 510357:tid 510580] [client 216.73.216.128:60637] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:36.691355 2026] [authz_core:error] [pid 510357:tid 510580] [client 216.73.216.128:60637] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:36.696220 2026] [security2:error] [pid 510357:tid 510604] [client 20.104.50.220:63206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/xb.php"] [unique_id "apPlQH5YTqJxoOZUSXttIgAABig"]
[Sun Aug 30 03:09:36.696774 2026] [security2:error] [pid 510357:tid 510499] [client 213.209.159.223:8531] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/laravel/.env"] [unique_id "apPlQH5YTqJxoOZUSXttIAAABb8"]
[Sun Aug 30 03:09:36.700431 2026] [security2:error] [pid 510357:tid 510505] [client 40.83.93.50:23518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/intense/block-css.php"] [unique_id "apPlQH5YTqJxoOZUSXttJAAABcU"]
[Sun Aug 30 03:09:36.703620 2026] [security2:error] [pid 510357:tid 510578] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp-includes/ID3/moon.php"] [unique_id "apPlQH5YTqJxoOZUSXttKAAABg4"]
[Sun Aug 30 03:09:36.728084 2026] [security2:error] [pid 510357:tid 510568] [client 20.104.50.220:16605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/x56.php"] [unique_id "apPlQH5YTqJxoOZUSXttNwAABgQ"]
[Sun Aug 30 03:09:36.751843 2026] [security2:error] [pid 510357:tid 510542] [client 20.48.250.41:44982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/aaa.php"] [unique_id "apPlQH5YTqJxoOZUSXttOwAABeo"]
[Sun Aug 30 03:09:36.768263 2026] [security2:error] [pid 510357:tid 510543] [client 20.104.18.15:35199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/wp-includes/index.php"] [unique_id "apPlQH5YTqJxoOZUSXttPAAABes"]
[Sun Aug 30 03:09:36.769107 2026] [security2:error] [pid 510357:tid 510500] [client 20.48.250.41:49872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/f35.php"] [unique_id "apPlQH5YTqJxoOZUSXttPgAABcA"]
[Sun Aug 30 03:09:36.774883 2026] [security2:error] [pid 510357:tid 510615] [client 20.104.49.130:45178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/images.php"] [unique_id "apPlQH5YTqJxoOZUSXttQQAABjM"]
[Sun Aug 30 03:09:36.816070 2026] [security2:error] [pid 510357:tid 510494] [client 20.48.250.41:26560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/h2a2ck.php"] [unique_id "apPlQH5YTqJxoOZUSXttVAAABbo"]
[Sun Aug 30 03:09:36.827725 2026] [security2:error] [pid 510357:tid 510506] [client 52.139.37.240:43114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/.trash7206/index.php"] [unique_id "apPlQH5YTqJxoOZUSXttVgAABcY"]
[Sun Aug 30 03:09:36.828474 2026] [security2:error] [pid 510357:tid 510617] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/xmini4.php"] [unique_id "apPlQH5YTqJxoOZUSXttVwAABjU"]
[Sun Aug 30 03:09:36.829704 2026] [security2:error] [pid 510357:tid 510570] [client 20.48.251.3:59876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/ms-edit.php"] [unique_id "apPlQH5YTqJxoOZUSXttWQAABgY"]
[Sun Aug 30 03:09:36.831769 2026] [security2:error] [pid 510357:tid 510569] [client 213.209.159.223:8531] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/core/.env"] [unique_id "apPlQH5YTqJxoOZUSXttWAAABgU"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:36.872286 2026] [security2:error] [pid 510357:tid 510533] [client 20.48.251.3:64392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/124.php"] [unique_id "apPlQH5YTqJxoOZUSXttXQAABeE"]
[Sun Aug 30 03:09:36.877086 2026] [security2:error] [pid 510357:tid 510516] [client 20.48.251.3:55731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/ms-edit.php"] [unique_id "apPlQH5YTqJxoOZUSXttYQAABdA"]
[Sun Aug 30 03:09:36.883405 2026] [security2:error] [pid 510357:tid 510513] [client 20.48.251.3:43979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.correllfarms.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlQH5YTqJxoOZUSXttZgAABc0"]
[Sun Aug 30 03:09:36.883864 2026] [security2:error] [pid 510357:tid 510603] [client 34.100.204.203:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/mail/phpinfo.php"] [unique_id "apPlQH5YTqJxoOZUSXttZQAABic"]
[Sun Aug 30 03:09:36.886726 2026] [security2:error] [pid 510357:tid 510492] [client 20.104.18.15:18333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/sss.php"] [unique_id "apPlQH5YTqJxoOZUSXttaAAABbg"]
[Sun Aug 30 03:09:36.924492 2026] [security2:error] [pid 510357:tid 510542] [client 20.48.250.41:49910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/wen.php"] [unique_id "apPlQH5YTqJxoOZUSXttcwAABeo"]
[Sun Aug 30 03:09:36.926104 2026] [security2:error] [pid 510357:tid 510539] [client 20.48.250.41:44903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/xsox.php"] [unique_id "apPlQH5YTqJxoOZUSXttdAAABec"]
[Sun Aug 30 03:09:36.953497 2026] [security2:error] [pid 510357:tid 510556] [client 20.48.250.41:26532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/error_log.php"] [unique_id "apPlQH5YTqJxoOZUSXtteAAABfg"]
[Sun Aug 30 03:09:36.955005 2026] [security2:error] [pid 510357:tid 510541] [client 158.158.54.35:30482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/dav.php"] [unique_id "apPlQH5YTqJxoOZUSXtteQAABek"]
[Sun Aug 30 03:09:36.963754 2026] [authz_core:error] [pid 510357:tid 510493] [client 216.73.216.128:33641] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:36.964020 2026] [authz_core:error] [pid 510357:tid 510493] [client 216.73.216.128:33641] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:36.990297 2026] [security2:error] [pid 510357:tid 510608] [client 20.151.8.82:27521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/ssg.php"] [unique_id "apPlQH5YTqJxoOZUSXttiwAABiw"]
[Sun Aug 30 03:09:37.002389 2026] [authz_core:error] [pid 510357:tid 510590] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:37.002784 2026] [authz_core:error] [pid 510357:tid 510590] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:37.008734 2026] [security2:error] [pid 510357:tid 510567] [client 20.48.250.41:38791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/wen.php"] [unique_id "apPlQX5YTqJxoOZUSXttlwAABgM"]
[Sun Aug 30 03:09:37.018951 2026] [security2:error] [pid 510357:tid 510535] [client 52.139.37.240:13837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/storage/index.php"] [unique_id "apPlQX5YTqJxoOZUSXttnQAABeM"]
[Sun Aug 30 03:09:37.023502 2026] [security2:error] [pid 510357:tid 510526] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/gulu.php"] [unique_id "apPlQX5YTqJxoOZUSXttnwAABdo"]
[Sun Aug 30 03:09:37.052499 2026] [security2:error] [pid 510357:tid 510592] [client 20.104.50.220:29173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/goods.php"] [unique_id "apPlQX5YTqJxoOZUSXttpQAABhw"]
[Sun Aug 30 03:09:37.054804 2026] [security2:error] [pid 510357:tid 510560] [client 216.73.216.128:3120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/files.html"] [unique_id "apPlQX5YTqJxoOZUSXttpgAABfw"]
[Sun Aug 30 03:09:37.068709 2026] [security2:error] [pid 510357:tid 510512] [client 20.48.250.41:49802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/inc.php"] [unique_id "apPlQX5YTqJxoOZUSXttqAAABcw"]
[Sun Aug 30 03:09:37.089975 2026] [security2:error] [pid 510357:tid 510556] [client 20.104.18.15:43299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/abcd.php"] [unique_id "apPlQX5YTqJxoOZUSXttrgAABfg"]
[Sun Aug 30 03:09:37.111015 2026] [security2:error] [pid 510357:tid 510520] [client 20.48.250.41:45043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/lkui.php"] [unique_id "apPlQX5YTqJxoOZUSXttsAAABdQ"]
[Sun Aug 30 03:09:37.126802 2026] [security2:error] [pid 510357:tid 510528] [client 20.104.50.220:31854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/aj.php"] [unique_id "apPlQX5YTqJxoOZUSXtttwAABdw"]
[Sun Aug 30 03:09:37.132973 2026] [security2:error] [pid 510357:tid 510506] [client 20.104.50.220:29154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/ray.php"] [unique_id "apPlQX5YTqJxoOZUSXttugAABcY"]
[Sun Aug 30 03:09:37.140324 2026] [security2:error] [pid 510357:tid 510548] [client 20.48.250.41:26585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/403.php"] [unique_id "apPlQX5YTqJxoOZUSXttwQAABfA"]
[Sun Aug 30 03:09:37.144462 2026] [security2:error] [pid 510357:tid 510516] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/replace.php"] [unique_id "apPlQX5YTqJxoOZUSXttwgAABdA"]
[Sun Aug 30 03:09:37.150143 2026] [security2:error] [pid 510357:tid 510563] [client 20.151.8.82:27492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/gigi.php"] [unique_id "apPlQX5YTqJxoOZUSXttxgAABf8"]
[Sun Aug 30 03:09:37.153926 2026] [authz_core:error] [pid 510357:tid 510505] [client 216.73.216.128:33641] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:37.154368 2026] [authz_core:error] [pid 510357:tid 510505] [client 216.73.216.128:33641] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:37.170244 2026] [security2:error] [pid 510357:tid 510554] [client 20.48.250.41:38793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/inc.php"] [unique_id "apPlQX5YTqJxoOZUSXttygAABfY"]
[Sun Aug 30 03:09:37.177004 2026] [security2:error] [pid 510357:tid 510593] [client 40.83.93.50:5601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/login.php"] [unique_id "apPlQX5YTqJxoOZUSXttzQAABh0"]
[Sun Aug 30 03:09:37.179450 2026] [security2:error] [pid 510357:tid 510562] [client 20.104.50.220:42020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/www.php"] [unique_id "apPlQX5YTqJxoOZUSXttzgAABf4"]
[Sun Aug 30 03:09:37.181370 2026] [security2:error] [pid 510357:tid 510535] [client 20.104.49.130:34513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/amax.php"] [unique_id "apPlQX5YTqJxoOZUSXttzwAABeM"]
[Sun Aug 30 03:09:37.188904 2026] [security2:error] [pid 510357:tid 510549] [client 20.48.251.3:13391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/paypal.php"] [unique_id "apPlQX5YTqJxoOZUSXtt0gAABfE"]
[Sun Aug 30 03:09:37.196592 2026] [security2:error] [pid 510357:tid 510560] [client 158.23.147.79:57714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/NewFile.php/"] [unique_id "apPlQX5YTqJxoOZUSXtt1gAABfw"]
[Sun Aug 30 03:09:37.204138 2026] [security2:error] [pid 510357:tid 510589] [client 20.48.250.41:49917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/6bcwiqwj.php"] [unique_id "apPlQX5YTqJxoOZUSXtt2QAABhk"]
[Sun Aug 30 03:09:37.206635 2026] [security2:error] [pid 510357:tid 510512] [client 68.155.159.216:63242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/dropdown.php"] [unique_id "apPlQX5YTqJxoOZUSXtt2gAABcw"]
[Sun Aug 30 03:09:37.210636 2026] [security2:error] [pid 510357:tid 510494] [client 52.139.37.240:44573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPlQX5YTqJxoOZUSXtt3AAABbo"]
[Sun Aug 30 03:09:37.244096 2026] [security2:error] [pid 510357:tid 510520] [client 20.48.250.41:44961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apPlQX5YTqJxoOZUSXtt4wAABdQ"]
[Sun Aug 30 03:09:37.265277 2026] [security2:error] [pid 510357:tid 510552] [client 20.48.250.41:26569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/cytyr.php"] [unique_id "apPlQX5YTqJxoOZUSXtt8QAABfQ"]
[Sun Aug 30 03:09:37.267282 2026] [security2:error] [pid 510357:tid 510569] [client 20.48.251.3:54806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/phpinfo01.php"] [unique_id "apPlQX5YTqJxoOZUSXtt8wAABgU"]
[Sun Aug 30 03:09:37.279466 2026] [security2:error] [pid 510357:tid 510501] [client 20.151.8.82:27549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/xnm-apc.php"] [unique_id "apPlQX5YTqJxoOZUSXtt-wAABcE"]
[Sun Aug 30 03:09:37.283109 2026] [security2:error] [pid 510357:tid 510554] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/c4.php"] [unique_id "apPlQX5YTqJxoOZUSXtt_QAABfY"]
[Sun Aug 30 03:09:37.309693 2026] [security2:error] [pid 510357:tid 510561] [client 20.104.18.15:22526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/wsd.php"] [unique_id "apPlQX5YTqJxoOZUSXtuAwAABf0"]
[Sun Aug 30 03:09:37.328293 2026] [security2:error] [pid 510357:tid 510592] [client 213.209.159.223:8531] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/app/.env"] [unique_id "apPlQX5YTqJxoOZUSXtuBwAABhw"]
[Sun Aug 30 03:09:37.328563 2026] [security2:error] [pid 510357:tid 510515] [client 20.104.18.15:64881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/55.php"] [unique_id "apPlQX5YTqJxoOZUSXtuCQAABc8"]
[Sun Aug 30 03:09:37.329975 2026] [security2:error] [pid 510357:tid 510521] [client 20.48.250.41:49874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/easy.php"] [unique_id "apPlQX5YTqJxoOZUSXtuDAAABdU"]
[Sun Aug 30 03:09:37.352854 2026] [security2:error] [pid 510357:tid 510618] [client 20.48.250.41:38890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/6bcwiqwj.php"] [unique_id "apPlQX5YTqJxoOZUSXtuEwAABjY"]
[Sun Aug 30 03:09:37.376436 2026] [security2:error] [pid 510357:tid 510581] [client 20.48.250.41:44973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/motu.php"] [unique_id "apPlQX5YTqJxoOZUSXtuHgAABhE"]
[Sun Aug 30 03:09:37.388378 2026] [security2:error] [pid 510357:tid 510528] [client 4.205.62.107:17304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/xza.php"] [unique_id "apPlQX5YTqJxoOZUSXtuIgAABdw"]
[Sun Aug 30 03:09:37.405254 2026] [security2:error] [pid 510357:tid 510504] [client 52.139.37.240:43107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/wp-blog.php"] [unique_id "apPlQX5YTqJxoOZUSXtuKQAABcQ"]
[Sun Aug 30 03:09:37.407379 2026] [security2:error] [pid 510357:tid 510599] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/rxr.php"] [unique_id "apPlQX5YTqJxoOZUSXtuKwAABiM"]
[Sun Aug 30 03:09:37.409377 2026] [authz_core:error] [pid 510357:tid 510500] [client 66.249.66.64:41104] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:37.409673 2026] [authz_core:error] [pid 510357:tid 510500] [client 66.249.66.64:41104] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:37.416213 2026] [security2:error] [pid 510357:tid 510590] [client 20.151.200.44:28544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/zoz.php"] [unique_id "apPlQX5YTqJxoOZUSXtuLQAABho"]
[Sun Aug 30 03:09:37.419352 2026] [security2:error] [pid 510357:tid 510548] [client 20.151.8.82:27576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/adminimagess.php"] [unique_id "apPlQX5YTqJxoOZUSXtuLwAABfA"]
[Sun Aug 30 03:09:37.432242 2026] [security2:error] [pid 510357:tid 510563] [client 4.205.62.107:36674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/god.php"] [unique_id "apPlQX5YTqJxoOZUSXtuMgAABf8"]
[Sun Aug 30 03:09:37.446395 2026] [security2:error] [pid 510357:tid 510583] [client 4.205.62.107:25789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/nlnub.php"] [unique_id "apPlQX5YTqJxoOZUSXtuOwAABhM"]
[Sun Aug 30 03:09:37.459251 2026] [security2:error] [pid 510357:tid 510603] [client 68.155.159.216:52547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/file5.php"] [unique_id "apPlQX5YTqJxoOZUSXtuPwAABic"]
[Sun Aug 30 03:09:37.461319 2026] [security2:error] [pid 510357:tid 510560] [client 213.209.159.223:8531] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/dev/.env"] [unique_id "apPlQX5YTqJxoOZUSXtuQAAABfw"]
[Sun Aug 30 03:09:37.476489 2026] [authz_core:error] [pid 510357:tid 510530] [client 216.73.216.128:20605] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:37.476777 2026] [authz_core:error] [pid 510357:tid 510530] [client 216.73.216.128:20605] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:37.480005 2026] [core:alert] [pid 510357:tid 510542] [client 38.191.38.107:0] /home3/lordrcan/public_html/.htaccess: without matching section, referer: http://www.lordrcane.com/
[Sun Aug 30 03:09:37.481254 2026] [security2:error] [pid 510357:tid 510609] [client 20.48.250.41:38802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/easy.php"] [unique_id "apPlQX5YTqJxoOZUSXtuUQAABi0"]
[Sun Aug 30 03:09:37.492873 2026] [security2:error] [pid 510357:tid 510509] [client 20.104.50.220:61995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/con7ext.php"] [unique_id "apPlQX5YTqJxoOZUSXtuVgAABck"]
[Sun Aug 30 03:09:37.502123 2026] [security2:error] [pid 510357:tid 510529] [client 20.48.250.41:26595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/galer.php"] [unique_id "apPlQX5YTqJxoOZUSXtuXgAABd0"]
[Sun Aug 30 03:09:37.503352 2026] [security2:error] [pid 510357:tid 510590] [client 20.48.250.41:49897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/fresh3.php"] [unique_id "apPlQX5YTqJxoOZUSXtuYAAABho"]
[Sun Aug 30 03:09:37.507912 2026] [security2:error] [pid 510357:tid 510492] [client 158.158.54.35:17279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/hkvkjguw.php"] [unique_id "apPlQX5YTqJxoOZUSXtuYwAABbg"]
[Sun Aug 30 03:09:37.519997 2026] [authz_core:error] [pid 510357:tid 510514] [client 216.73.216.128:60637] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:37.520315 2026] [authz_core:error] [pid 510357:tid 510514] [client 216.73.216.128:60637] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:37.533219 2026] [security2:error] [pid 510357:tid 510583] [client 20.48.160.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/reviall.php"] [unique_id "apPlQX5YTqJxoOZUSXtuagAABhM"]
[Sun Aug 30 03:09:37.538008 2026] [security2:error] [pid 510357:tid 510561] [client 20.104.50.220:33212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/ea.php"] [unique_id "apPlQX5YTqJxoOZUSXtubQAABf0"]
[Sun Aug 30 03:09:37.542033 2026] [authz_core:error] [pid 510357:tid 510537] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:37.542349 2026] [authz_core:error] [pid 510357:tid 510537] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:37.552180 2026] [security2:error] [pid 510357:tid 510512] [client 20.151.8.82:27632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/wp-content/index.php"] [unique_id "apPlQX5YTqJxoOZUSXtudQAABcw"]
[Sun Aug 30 03:09:37.559371 2026] [security2:error] [pid 510357:tid 510502] [client 158.23.147.79:57704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/dropdown.php"] [unique_id "apPlQX5YTqJxoOZUSXtuegAABcI"]
[Sun Aug 30 03:09:37.593486 2026] [security2:error] [pid 510357:tid 510589] [client 20.48.250.41:44992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/Ov-Simple1.php"] [unique_id "apPlQX5YTqJxoOZUSXtuggAABhk"]
[Sun Aug 30 03:09:37.612126 2026] [security2:error] [pid 510357:tid 510571] [client 52.139.37.240:44572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/xmlrpc.php"] [unique_id "apPlQX5YTqJxoOZUSXtuhwAABgc"]
[Sun Aug 30 03:09:37.624534 2026] [security2:error] [pid 510357:tid 510580] [client 20.104.49.130:36786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/kerang.php"] [unique_id "apPlQX5YTqJxoOZUSXtunwAABhA"]
[Sun Aug 30 03:09:37.631147 2026] [security2:error] [pid 510357:tid 510561] [client 20.48.250.41:49906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/bgymj.php"] [unique_id "apPlQX5YTqJxoOZUSXtuogAABf0"]
[Sun Aug 30 03:09:37.636271 2026] [security2:error] [pid 510357:tid 510526] [client 20.48.250.41:38893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/fresh3.php"] [unique_id "apPlQX5YTqJxoOZUSXtuqAAABdo"]
[Sun Aug 30 03:09:37.645759 2026] [security2:error] [pid 510357:tid 510547] [client 34.100.204.203:37856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/cpanel/phpinfo.php"] [unique_id "apPlQX5YTqJxoOZUSXturQAABe8"]
[Sun Aug 30 03:09:37.671685 2026] [security2:error] [pid 510357:tid 510501] [client 40.83.93.50:5617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/min.php"] [unique_id "apPlQX5YTqJxoOZUSXtuvgAABcE"]
[Sun Aug 30 03:09:37.678753 2026] [security2:error] [pid 510357:tid 510618] [client 4.205.62.107:64485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/aws.php"] [unique_id "apPlQX5YTqJxoOZUSXtuwgAABjY"]
[Sun Aug 30 03:09:37.683227 2026] [security2:error] [pid 510357:tid 510568] [client 20.151.8.82:27621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "apPlQX5YTqJxoOZUSXtuxwAABgQ"]
[Sun Aug 30 03:09:37.694102 2026] [authz_core:error] [pid 510357:tid 510529] [client 66.249.66.65:48004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:37.694536 2026] [authz_core:error] [pid 510357:tid 510529] [client 66.249.66.65:48004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:37.775829 2026] [security2:error] [pid 510357:tid 510572] [client 213.209.159.223:8531] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/server/.env"] [unique_id "apPlQX5YTqJxoOZUSXtu5wAABgg"]
[Sun Aug 30 03:09:37.810574 2026] [security2:error] [pid 510357:tid 510618] [client 20.104.50.220:5567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/exists.php"] [unique_id "apPlQX5YTqJxoOZUSXtu-AAABjY"]
[Sun Aug 30 03:09:37.816423 2026] [security2:error] [pid 510357:tid 510589] [client 20.151.8.82:27583] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/wp-admin/css/"] [unique_id "apPlQX5YTqJxoOZUSXtu_AAABhk"]
[Sun Aug 30 03:09:37.821827 2026] [security2:error] [pid 510357:tid 510560] [client 52.139.37.240:43094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/lu4.php"] [unique_id "apPlQX5YTqJxoOZUSXtvAwAABfw"]
[Sun Aug 30 03:09:37.859266 2026] [security2:error] [pid 510357:tid 510573] [client 20.104.50.220:59366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/biufile.php"] [unique_id "apPlQX5YTqJxoOZUSXtvCgAABgk"]
[Sun Aug 30 03:09:37.877548 2026] [security2:error] [pid 510357:tid 510570] [client 20.104.50.220:16582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/htaccess.php"] [unique_id "apPlQX5YTqJxoOZUSXtvEAAABgY"]
[Sun Aug 30 03:09:37.883052 2026] [authz_core:error] [pid 510357:tid 510520] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:37.883307 2026] [authz_core:error] [pid 510357:tid 510520] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:37.922801 2026] [security2:error] [pid 510357:tid 510599] [client 20.104.49.130:60929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlQX5YTqJxoOZUSXtvJwAABiM"]
[Sun Aug 30 03:09:37.922833 2026] [security2:error] [pid 510357:tid 510593] [client 20.104.18.15:35051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/file31.php"] [unique_id "apPlQX5YTqJxoOZUSXtvJgAABh0"]
[Sun Aug 30 03:09:37.923263 2026] [security2:error] [pid 510357:tid 510615] [client 20.104.49.130:63615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/echkm.php"] [unique_id "apPlQX5YTqJxoOZUSXtvKAAABjM"]
[Sun Aug 30 03:09:37.969075 2026] [security2:error] [pid 510357:tid 510492] [client 20.48.251.3:59855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/lmfi2.php"] [unique_id "apPlQX5YTqJxoOZUSXtvOAAABbg"]
[Sun Aug 30 03:09:37.994612 2026] [security2:error] [pid 510357:tid 510493] [client 20.151.8.82:27463] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/wp-admin/css/colors/modern/"] [unique_id "apPlQX5YTqJxoOZUSXtvQwAABbk"]
[Sun Aug 30 03:09:37.995040 2026] [security2:error] [pid 510357:tid 510570] [client 216.73.216.128:60637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts2/updateconf"] [unique_id "apPlQX5YTqJxoOZUSXtvRAAABgY"]
[Sun Aug 30 03:09:38.017090 2026] [security2:error] [pid 510357:tid 510578] [client 20.48.251.3:55711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/sys.php"] [unique_id "apPlQn5YTqJxoOZUSXtvUAAABg4"]
[Sun Aug 30 03:09:38.018429 2026] [security2:error] [pid 510357:tid 510539] [client 52.139.37.240:43091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "apPlQn5YTqJxoOZUSXtvUgAABec"]
[Sun Aug 30 03:09:38.019720 2026] [authz_core:error] [pid 510357:tid 510494] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:38.019976 2026] [authz_core:error] [pid 510357:tid 510494] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:38.086474 2026] [security2:error] [pid 510357:tid 510590] [client 158.23.147.79:57721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/.well-known/index.php"] [unique_id "apPlQn5YTqJxoOZUSXtvYgAABho"]
[Sun Aug 30 03:09:38.091205 2026] [security2:error] [pid 510357:tid 510600] [client 20.48.251.3:6517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/test1.php"] [unique_id "apPlQn5YTqJxoOZUSXtvZQAABiQ"]
[Sun Aug 30 03:09:38.135227 2026] [security2:error] [pid 510357:tid 510515] [client 20.151.8.82:27517] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/wp-includes/blocks/details/"] [unique_id "apPlQn5YTqJxoOZUSXtvcAAABc8"]
[Sun Aug 30 03:09:38.147929 2026] [authz_core:error] [pid 510357:tid 510595] [client 66.249.66.68:36813] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:38.148188 2026] [authz_core:error] [pid 510357:tid 510595] [client 66.249.66.68:36813] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:38.170467 2026] [security2:error] [pid 510357:tid 510499] [client 40.83.93.50:5602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/module.php"] [unique_id "apPlQn5YTqJxoOZUSXtvfAAABb8"]
[Sun Aug 30 03:09:38.190551 2026] [security2:error] [pid 510357:tid 510597] [client 20.104.50.220:62828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/codrs.php"] [unique_id "apPlQn5YTqJxoOZUSXtvhQAABiE"]
[Sun Aug 30 03:09:38.208632 2026] [security2:error] [pid 510357:tid 510618] [client 158.158.54.35:8305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/conf_upload.php"] [unique_id "apPlQn5YTqJxoOZUSXtviQAABjY"]
[Sun Aug 30 03:09:38.211737 2026] [security2:error] [pid 510357:tid 510550] [client 52.139.37.240:44599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "apPlQn5YTqJxoOZUSXtvigAABfI"]
[Sun Aug 30 03:09:38.252155 2026] [security2:error] [pid 510357:tid 510590] [client 20.104.18.15:44001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/nofile.php"] [unique_id "apPlQn5YTqJxoOZUSXtvmgAABho"]
[Sun Aug 30 03:09:38.262035 2026] [security2:error] [pid 510357:tid 510611] [client 20.151.8.82:27547] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/wp-includes/blocks/audio/"] [unique_id "apPlQn5YTqJxoOZUSXtvpAAABi8"]
[Sun Aug 30 03:09:38.272795 2026] [security2:error] [pid 510357:tid 510556] [client 213.209.159.223:8531] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/staging/.env"] [unique_id "apPlQn5YTqJxoOZUSXtvqwAABfg"]
[Sun Aug 30 03:09:38.285494 2026] [security2:error] [pid 510357:tid 510541] [client 20.104.50.220:52822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/Q2-.php"] [unique_id "apPlQn5YTqJxoOZUSXtvsAAABek"]
[Sun Aug 30 03:09:38.314418 2026] [security2:error] [pid 510357:tid 510573] [client 68.155.159.216:62627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/.well-known/index.php"] [unique_id "apPlQn5YTqJxoOZUSXtvtQAABgk"]
[Sun Aug 30 03:09:38.322226 2026] [security2:error] [pid 510357:tid 510552] [client 20.220.10.235:36811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlQn5YTqJxoOZUSXtvuAAABfQ"]
[Sun Aug 30 03:09:38.328167 2026] [security2:error] [pid 510357:tid 510504] [client 20.104.50.220:51593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/x13.php"] [unique_id "apPlQn5YTqJxoOZUSXtvuwAABcQ"]
[Sun Aug 30 03:09:38.336137 2026] [security2:error] [pid 510357:tid 510554] [client 20.48.251.3:56346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/userfuns.php"] [unique_id "apPlQn5YTqJxoOZUSXtvvgAABfY"]
[Sun Aug 30 03:09:38.376197 2026] [security2:error] [pid 510357:tid 510583] [client 34.100.204.203:37868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/hosting/phpinfo.php"] [unique_id "apPlQn5YTqJxoOZUSXtvwwAABhM"]
[Sun Aug 30 03:09:38.395217 2026] [security2:error] [pid 510357:tid 510576] [client 20.151.8.82:27457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/wp-temp.php"] [unique_id "apPlQn5YTqJxoOZUSXtvxwAABgw"]
[Sun Aug 30 03:09:38.404870 2026] [security2:error] [pid 510357:tid 510539] [client 52.139.37.240:13824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "apPlQn5YTqJxoOZUSXtvywAABec"]
[Sun Aug 30 03:09:38.437690 2026] [security2:error] [pid 510357:tid 510517] [client 20.48.251.3:65512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/cxc.php"] [unique_id "apPlQn5YTqJxoOZUSXtv2wAABdE"]
[Sun Aug 30 03:09:38.458826 2026] [security2:error] [pid 510357:tid 510591] [client 20.220.10.235:36982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlQn5YTqJxoOZUSXtv6wAABhs"]
[Sun Aug 30 03:09:38.464692 2026] [security2:error] [pid 510357:tid 510509] [client 20.104.18.15:22473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/bulet.php"] [unique_id "apPlQn5YTqJxoOZUSXtv8QAABck"]
[Sun Aug 30 03:09:38.470602 2026] [security2:error] [pid 510357:tid 510577] [client 20.104.50.220:32305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/opts.php"] [unique_id "apPlQn5YTqJxoOZUSXtv9gAABg0"]
[Sun Aug 30 03:09:38.474017 2026] [security2:error] [pid 510357:tid 510610] [client 20.104.49.130:26882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/ano.php"] [unique_id "apPlQn5YTqJxoOZUSXtv-QAABi4"]
[Sun Aug 30 03:09:38.476687 2026] [security2:error] [pid 510357:tid 510507] [client 20.104.18.15:64828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/yj09.php"] [unique_id "apPlQn5YTqJxoOZUSXtv-wAABcc"]
[Sun Aug 30 03:09:38.512448 2026] [authz_core:error] [pid 510357:tid 510517] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:38.512927 2026] [authz_core:error] [pid 510357:tid 510517] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:38.526827 2026] [security2:error] [pid 510357:tid 510603] [client 4.205.62.107:17322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/ms-edit.php"] [unique_id "apPlQn5YTqJxoOZUSXtwEwAABic"]
[Sun Aug 30 03:09:38.535897 2026] [security2:error] [pid 510357:tid 510567] [client 20.151.8.82:27469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPlQn5YTqJxoOZUSXtwFwAABgM"]
[Sun Aug 30 03:09:38.591790 2026] [security2:error] [pid 510357:tid 510545] [client 20.220.10.235:37063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/h02ugyh.php"] [unique_id "apPlQn5YTqJxoOZUSXtwKwAABe0"]
[Sun Aug 30 03:09:38.594999 2026] [security2:error] [pid 510357:tid 510529] [client 4.205.62.107:25903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/mga.php"] [unique_id "apPlQn5YTqJxoOZUSXtwLwAABd0"]
[Sun Aug 30 03:09:38.595841 2026] [security2:error] [pid 510357:tid 510531] [client 4.205.62.107:36666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/fff.php"] [unique_id "apPlQn5YTqJxoOZUSXtwMAAABd8"]
[Sun Aug 30 03:09:38.597056 2026] [security2:error] [pid 510357:tid 510513] [client 52.139.37.240:43103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/ant.php"] [unique_id "apPlQn5YTqJxoOZUSXtwMQAABc0"]
[Sun Aug 30 03:09:38.613904 2026] [security2:error] [pid 510357:tid 510579] [client 216.73.216.128:51913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mysqlupgrade"] [unique_id "apPlQn5YTqJxoOZUSXtwNwAABg8"]
[Sun Aug 30 03:09:38.643516 2026] [security2:error] [pid 510357:tid 510534] [client 20.104.50.220:62213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/loader/ff.php"] [unique_id "apPlQn5YTqJxoOZUSXtwUAAABeI"]
[Sun Aug 30 03:09:38.646523 2026] [security2:error] [pid 510357:tid 510607] [client 40.83.93.50:5604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/ms-files.php"] [unique_id "apPlQn5YTqJxoOZUSXtwUgAABis"]
[Sun Aug 30 03:09:38.661822 2026] [security2:error] [pid 510357:tid 510494] [client 20.48.250.41:26583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/baixy.php"] [unique_id "apPlQn5YTqJxoOZUSXtwYwAABbo"]
[Sun Aug 30 03:09:38.671546 2026] [security2:error] [pid 510357:tid 510559] [client 20.151.8.82:27578] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/wp-includes/Requests/"] [unique_id "apPlQn5YTqJxoOZUSXtwbQAABfs"]
[Sun Aug 30 03:09:38.682406 2026] [security2:error] [pid 510357:tid 510567] [client 20.104.50.220:32845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/aaaa.php"] [unique_id "apPlQn5YTqJxoOZUSXtwdQAABgM"]
[Sun Aug 30 03:09:38.723718 2026] [security2:error] [pid 510357:tid 510572] [client 158.158.54.35:30500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/catuploadcsv.php"] [unique_id "apPlQn5YTqJxoOZUSXtwigAABgg"]
[Sun Aug 30 03:09:38.739590 2026] [security2:error] [pid 510357:tid 510526] [client 20.48.250.41:44878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/wp-blogs.php"] [unique_id "apPlQn5YTqJxoOZUSXtwjQAABdo"]
[Sun Aug 30 03:09:38.753839 2026] [security2:error] [pid 510357:tid 510609] [client 20.220.10.235:36947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/sf.php"] [unique_id "apPlQn5YTqJxoOZUSXtwkQAABi0"]
[Sun Aug 30 03:09:38.773616 2026] [authz_core:error] [pid 510357:tid 510576] [client 216.73.216.128:33641] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:38.773955 2026] [authz_core:error] [pid 510357:tid 510576] [client 216.73.216.128:33641] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:38.777450 2026] [security2:error] [pid 510357:tid 510540] [client 20.48.250.41:49813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/ws69.php"] [unique_id "apPlQn5YTqJxoOZUSXtwlgAABeg"]
[Sun Aug 30 03:09:38.789775 2026] [security2:error] [pid 510357:tid 510544] [client 52.139.37.240:43115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/autoload_classmap.php"] [unique_id "apPlQn5YTqJxoOZUSXtwmgAABew"]
[Sun Aug 30 03:09:38.801760 2026] [security2:error] [pid 510357:tid 510605] [client 20.151.8.82:27493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/wp-content/admin.php"] [unique_id "apPlQn5YTqJxoOZUSXtwoQAABik"]
[Sun Aug 30 03:09:38.813140 2026] [security2:error] [pid 510357:tid 510597] [client 158.23.147.79:56468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-content/themes/too.php"] [unique_id "apPlQn5YTqJxoOZUSXtwpwAABiE"]
[Sun Aug 30 03:09:38.815258 2026] [security2:error] [pid 510357:tid 510551] [client 4.205.62.107:61770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/app.default.php"] [unique_id "apPlQn5YTqJxoOZUSXtwqAAABfM"]
[Sun Aug 30 03:09:38.835461 2026] [security2:error] [pid 510357:tid 510592] [client 20.48.250.41:26520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/ava.php"] [unique_id "apPlQn5YTqJxoOZUSXtwrgAABhw"]
[Sun Aug 30 03:09:38.865083 2026] [authz_core:error] [pid 510357:tid 510589] [client 66.249.66.69:61393] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:38.865361 2026] [authz_core:error] [pid 510357:tid 510589] [client 66.249.66.69:61393] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:38.870583 2026] [security2:error] [pid 510357:tid 510615] [client 20.48.250.41:38848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/bgymj.php"] [unique_id "apPlQn5YTqJxoOZUSXtwsQAABjM"]
[Sun Aug 30 03:09:38.877792 2026] [security2:error] [pid 510357:tid 510528] [client 20.151.200.44:41945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/zoz.php"] [unique_id "apPlQn5YTqJxoOZUSXtwtQAABdw"]
[Sun Aug 30 03:09:38.884381 2026] [authz_core:error] [pid 510357:tid 510542] [client 66.249.66.66:58871] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:38.884631 2026] [authz_core:error] [pid 510357:tid 510542] [client 66.249.66.66:58871] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:38.888353 2026] [security2:error] [pid 510357:tid 510538] [client 20.220.10.235:37069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/4e.php"] [unique_id "apPlQn5YTqJxoOZUSXtwuQAABeY"]
[Sun Aug 30 03:09:38.916558 2026] [security2:error] [pid 510357:tid 510544] [client 20.48.250.41:49830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/ccs.php"] [unique_id "apPlQn5YTqJxoOZUSXtwwwAABew"]
[Sun Aug 30 03:09:38.918863 2026] [security2:error] [pid 510357:tid 510580] [client 20.48.250.41:44954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/mini.php"] [unique_id "apPlQn5YTqJxoOZUSXtwxQAABhA"]
[Sun Aug 30 03:09:38.929021 2026] [security2:error] [pid 510357:tid 510558] [client 20.104.49.130:52453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/amax.php"] [unique_id "apPlQn5YTqJxoOZUSXtwyQAABfo"]
[Sun Aug 30 03:09:38.939761 2026] [security2:error] [pid 510357:tid 510570] [client 20.151.8.82:27536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPlQn5YTqJxoOZUSXtwzQAABgY"]
[Sun Aug 30 03:09:38.965211 2026] [security2:error] [pid 510357:tid 510552] [client 20.104.50.220:5474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/exit.php"] [unique_id "apPlQn5YTqJxoOZUSXtw1QAABfQ"]
[Sun Aug 30 03:09:38.978831 2026] [security2:error] [pid 510357:tid 510539] [client 20.151.200.44:28625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/kcs.php"] [unique_id "apPlQn5YTqJxoOZUSXtw4QAABec"]
[Sun Aug 30 03:09:38.985274 2026] [security2:error] [pid 510357:tid 510549] [client 52.139.37.240:43129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/storage/rip.php"] [unique_id "apPlQn5YTqJxoOZUSXtw5QAABfE"]
[Sun Aug 30 03:09:39.010325 2026] [security2:error] [pid 510357:tid 510544] [client 20.48.250.41:26618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/gdn.php"] [unique_id "apPlQ35YTqJxoOZUSXtw8wAABew"]
[Sun Aug 30 03:09:39.017067 2026] [security2:error] [pid 510357:tid 510611] [client 20.104.50.220:17320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/readme.php"] [unique_id "apPlQ35YTqJxoOZUSXtw-QAABi8"]
[Sun Aug 30 03:09:39.023242 2026] [authz_core:error] [pid 510357:tid 510514] [client 66.249.66.69:42442] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:39.023682 2026] [authz_core:error] [pid 510357:tid 510514] [client 66.249.66.69:42442] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:39.027516 2026] [security2:error] [pid 510357:tid 510515] [client 20.220.10.235:36808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/ssss.php"] [unique_id "apPlQ35YTqJxoOZUSXtw_AAABc8"]
[Sun Aug 30 03:09:39.033756 2026] [security2:error] [pid 510357:tid 510534] [client 20.104.49.130:63543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/berlin.php"] [unique_id "apPlQ35YTqJxoOZUSXtw_gAABeI"]
[Sun Aug 30 03:09:39.038286 2026] [security2:error] [pid 510357:tid 510579] [client 20.104.50.220:59377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wpconf.php"] [unique_id "apPlQ35YTqJxoOZUSXtxAQAABg8"]
[Sun Aug 30 03:09:39.042924 2026] [security2:error] [pid 510357:tid 510529] [client 20.48.250.41:49915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/mar.php"] [unique_id "apPlQ35YTqJxoOZUSXtxBAAABd0"]
[Sun Aug 30 03:09:39.061681 2026] [authz_core:error] [pid 510357:tid 510573] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:39.061986 2026] [authz_core:error] [pid 510357:tid 510573] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:39.064131 2026] [security2:error] [pid 510357:tid 510545] [client 20.104.18.15:35060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/dk.php"] [unique_id "apPlQ35YTqJxoOZUSXtxCQAABe0"]
[Sun Aug 30 03:09:39.076899 2026] [security2:error] [pid 510357:tid 510617] [client 20.104.49.130:52132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/chosen.php"] [unique_id "apPlQ35YTqJxoOZUSXtxDQAABjU"]
[Sun Aug 30 03:09:39.082876 2026] [security2:error] [pid 510357:tid 510506] [client 20.151.8.82:27513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/av.php"] [unique_id "apPlQ35YTqJxoOZUSXtxDwAABcY"]
[Sun Aug 30 03:09:39.084835 2026] [security2:error] [pid 510357:tid 510533] [client 34.100.204.203:37884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/webmail/phpinfo.php"] [unique_id "apPlQ35YTqJxoOZUSXtxEAAABeE"]
[Sun Aug 30 03:09:39.098767 2026] [security2:error] [pid 510357:tid 510394] [remote 68.155.159.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ibrgroup.in"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPlQ35YTqJxoOZUSXtxFAAFuiA"]
[Sun Aug 30 03:09:39.102113 2026] [security2:error] [pid 510357:tid 510553] [client 20.48.251.3:59493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wpver.php"] [unique_id "apPlQ35YTqJxoOZUSXtxFQAABfU"]
[Sun Aug 30 03:09:39.112250 2026] [security2:error] [pid 510357:tid 510518] [client 20.48.250.41:38861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/ws69.php"] [unique_id "apPlQ35YTqJxoOZUSXtxGAAABdI"]
[Sun Aug 30 03:09:39.135112 2026] [security2:error] [pid 510357:tid 510598] [client 216.73.216.128:15299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/classes.html"] [unique_id "apPlQ35YTqJxoOZUSXtxHgAABiI"]
[Sun Aug 30 03:09:39.139042 2026] [security2:error] [pid 510357:tid 510516] [client 213.209.159.223:8531] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/source/.env"] [unique_id "apPlQ35YTqJxoOZUSXtxIAAABdA"]
[Sun Aug 30 03:09:39.143383 2026] [security2:error] [pid 510357:tid 510531] [client 40.83.93.50:5579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/news-portal/error.php"] [unique_id "apPlQ35YTqJxoOZUSXtxJAAABd8"]
[Sun Aug 30 03:09:39.152343 2026] [security2:error] [pid 510357:tid 510609] [client 20.48.251.3:55687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/phpsysinfo.php"] [unique_id "apPlQ35YTqJxoOZUSXtxJwAABi0"]
[Sun Aug 30 03:09:39.182080 2026] [security2:error] [pid 510357:tid 510504] [client 158.158.54.35:17273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/Alfa.php"] [unique_id "apPlQ35YTqJxoOZUSXtxKwAABcQ"]
[Sun Aug 30 03:09:39.186386 2026] [security2:error] [pid 510357:tid 510588] [client 52.139.37.240:44595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/tinyfilemanager.php"] [unique_id "apPlQ35YTqJxoOZUSXtxLQAABhg"]
[Sun Aug 30 03:09:39.188517 2026] [security2:error] [pid 510357:tid 510580] [client 20.220.10.235:36985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/zoz.php"] [unique_id "apPlQ35YTqJxoOZUSXtxLwAABhA"]
[Sun Aug 30 03:09:39.195900 2026] [security2:error] [pid 510357:tid 510534] [client 20.48.250.41:26533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/f2.php"] [unique_id "apPlQ35YTqJxoOZUSXtxMwAABeI"]
[Sun Aug 30 03:09:39.212166 2026] [security2:error] [pid 510357:tid 510584] [client 20.151.8.82:27507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPlQ35YTqJxoOZUSXtxNQAABhQ"]
[Sun Aug 30 03:09:39.221911 2026] [security2:error] [pid 510357:tid 510615] [client 20.48.250.41:44817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/amp.php"] [unique_id "apPlQ35YTqJxoOZUSXtxOQAABjM"]
[Sun Aug 30 03:09:39.293497 2026] [authz_core:error] [pid 510357:tid 510544] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:39.293777 2026] [authz_core:error] [pid 510357:tid 510544] [client 74.7.227.8:36082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:39.308449 2026] [security2:error] [pid 510357:tid 510560] [client 20.48.251.3:6502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/bigdump.php"] [unique_id "apPlQ35YTqJxoOZUSXtxWwAABfw"]
[Sun Aug 30 03:09:39.350470 2026] [security2:error] [pid 510357:tid 510492] [client 20.151.8.82:27569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/wp-blog.php"] [unique_id "apPlQ35YTqJxoOZUSXtxYwAABbg"]
[Sun Aug 30 03:09:39.368233 2026] [security2:error] [pid 510357:tid 510615] [client 158.23.147.79:56452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/radio.php"] [unique_id "apPlQ35YTqJxoOZUSXtxZQAABjM"]
[Sun Aug 30 03:09:39.370389 2026] [security2:error] [pid 510357:tid 510597] [client 20.220.10.235:36849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/kcs.php"] [unique_id "apPlQ35YTqJxoOZUSXtxZgAABiE"]
[Sun Aug 30 03:09:39.380110 2026] [security2:error] [pid 510357:tid 510579] [client 20.104.50.220:52830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/jingan.php"] [unique_id "apPlQ35YTqJxoOZUSXtxZwAABg8"]
[Sun Aug 30 03:09:39.411014 2026] [security2:error] [pid 510357:tid 510586] [client 20.104.18.15:44023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/run.php"] [unique_id "apPlQ35YTqJxoOZUSXtxdQAABhY"]
[Sun Aug 30 03:09:39.437973 2026] [security2:error] [pid 510357:tid 510491] [client 20.104.50.220:29609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/python.php"] [unique_id "apPlQ35YTqJxoOZUSXtxfwAABbc"]
[Sun Aug 30 03:09:39.454954 2026] [security2:error] [pid 510357:tid 510526] [client 213.209.159.223:8531] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/framework/.env"] [unique_id "apPlQ35YTqJxoOZUSXtxiQAABdo"]
[Sun Aug 30 03:09:39.464181 2026] [security2:error] [pid 510357:tid 510611] [client 68.155.159.216:63263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-content/themes/too.php"] [unique_id "apPlQ35YTqJxoOZUSXtxiwAABi8"]
[Sun Aug 30 03:09:39.464391 2026] [security2:error] [pid 510357:tid 510521] [client 20.104.50.220:51556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/ntaps.php"] [unique_id "apPlQ35YTqJxoOZUSXtxjAAABdU"]
[Sun Aug 30 03:09:39.484666 2026] [security2:error] [pid 510357:tid 510591] [client 20.151.8.82:27408] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/wp-includes/js/jquery/"] [unique_id "apPlQ35YTqJxoOZUSXtxmAAABhs"]
[Sun Aug 30 03:09:39.485985 2026] [security2:error] [pid 510357:tid 510568] [client 20.48.251.3:33327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/mamzi.php"] [unique_id "apPlQ35YTqJxoOZUSXtxmQAABgQ"]
[Sun Aug 30 03:09:39.494002 2026] [security2:error] [pid 510357:tid 510617] [client 68.155.159.216:52556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/file88.php"] [unique_id "apPlQ35YTqJxoOZUSXtxoAAABjU"]
[Sun Aug 30 03:09:39.510668 2026] [security2:error] [pid 510357:tid 510586] [client 20.220.10.235:36845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/tajj.php"] [unique_id "apPlQ35YTqJxoOZUSXtxpwAABhY"]
[Sun Aug 30 03:09:39.529462 2026] [authz_core:error] [pid 510357:tid 510561] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:39.529759 2026] [authz_core:error] [pid 510357:tid 510561] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:39.580334 2026] [security2:error] [pid 510357:tid 510549] [client 20.48.251.3:54794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/oiko6u.php"] [unique_id "apPlQ35YTqJxoOZUSXtxvQAABfE"]
[Sun Aug 30 03:09:39.588369 2026] [security2:error] [pid 510357:tid 510591] [client 213.209.159.223:8531] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/ikiwiki/.env"] [unique_id "apPlQ35YTqJxoOZUSXtxwAAABhs"]
[Sun Aug 30 03:09:39.595467 2026] [authz_core:error] [pid 510357:tid 510545] [client 66.249.66.71:60841] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:39.595873 2026] [authz_core:error] [pid 510357:tid 510545] [client 66.249.66.71:60841] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:39.604336 2026] [security2:error] [pid 510357:tid 510604] [client 20.104.18.15:22504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/av.php"] [unique_id "apPlQ35YTqJxoOZUSXtxywAABig"]
[Sun Aug 30 03:09:39.608028 2026] [security2:error] [pid 510357:tid 510606] [client 20.104.50.220:32528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/filer.php"] [unique_id "apPlQ35YTqJxoOZUSXtxzwAABio"]
[Sun Aug 30 03:09:39.608481 2026] [security2:error] [pid 510357:tid 510609] [client 20.104.18.15:64771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/scxy.php"] [unique_id "apPlQ35YTqJxoOZUSXtx0QAABi0"]
[Sun Aug 30 03:09:39.619539 2026] [security2:error] [pid 510357:tid 510579] [client 20.151.8.82:27460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/cgi-bin/index.php"] [unique_id "apPlQ35YTqJxoOZUSXtx2AAABg8"]
[Sun Aug 30 03:09:39.624761 2026] [security2:error] [pid 510357:tid 510595] [client 40.83.93.50:23532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/nvt/includes/plugins/wp-blog-header.php"] [unique_id "apPlQ35YTqJxoOZUSXtx3QAABh8"]
[Sun Aug 30 03:09:39.625555 2026] [security2:error] [pid 510357:tid 510499] [client 158.158.54.35:8296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/wp-index.php"] [unique_id "apPlQ35YTqJxoOZUSXtx3wAABb8"]
[Sun Aug 30 03:09:39.651902 2026] [security2:error] [pid 510357:tid 510608] [client 20.220.10.235:36807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/bge.php"] [unique_id "apPlQ35YTqJxoOZUSXtx7QAABiw"]
[Sun Aug 30 03:09:39.668813 2026] [security2:error] [pid 510357:tid 510504] [client 4.205.62.107:17138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/lmfi2.php"] [unique_id "apPlQ35YTqJxoOZUSXtx9QAABcQ"]
[Sun Aug 30 03:09:39.721342 2026] [security2:error] [pid 510357:tid 510528] [client 213.209.159.223:8531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themayorcoffee.com"] [uri "/config.inc.php"] [unique_id "apPlQ35YTqJxoOZUSXtyFwAABdw"]
[Sun Aug 30 03:09:39.749685 2026] [security2:error] [pid 510357:tid 510531] [client 20.151.8.82:27544] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/wp-includes/l10n/"] [unique_id "apPlQ35YTqJxoOZUSXtyHQAABd8"]
[Sun Aug 30 03:09:39.762929 2026] [security2:error] [pid 510357:tid 510574] [client 4.205.62.107:25864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/ccou.php"] [unique_id "apPlQ35YTqJxoOZUSXtyIQAABgo"]
[Sun Aug 30 03:09:39.774516 2026] [security2:error] [pid 510357:tid 510576] [client 4.205.62.107:36677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/autogooey.php"] [unique_id "apPlQ35YTqJxoOZUSXtyJAAABgw"]
[Sun Aug 30 03:09:39.786635 2026] [security2:error] [pid 510357:tid 510600] [client 20.104.50.220:61651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/dbx.php"] [unique_id "apPlQ35YTqJxoOZUSXtyKgAABiQ"]
[Sun Aug 30 03:09:39.804217 2026] [security2:error] [pid 510357:tid 510540] [client 20.104.49.130:60978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/coffexium.php"] [unique_id "apPlQ35YTqJxoOZUSXtyMQAABeg"]
[Sun Aug 30 03:09:39.804329 2026] [security2:error] [pid 510357:tid 510568] [client 20.220.10.235:37058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/ssh3ll.php"] [unique_id "apPlQ35YTqJxoOZUSXtyNAAABgQ"]
[Sun Aug 30 03:09:39.820278 2026] [core:alert] [pid 510357:tid 510617] [client 172.59.242.231:0] /home3/lordrcan/public_html/.htaccess: without matching section, referer: http://www.baidu.com/
[Sun Aug 30 03:09:39.834379 2026] [security2:error] [pid 510357:tid 510571] [client 20.104.50.220:33303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/cinfo.php"] [unique_id "apPlQ35YTqJxoOZUSXtyQQAABgc"]
[Sun Aug 30 03:09:39.846026 2026] [security2:error] [pid 510357:tid 510603] [client 216.73.216.128:32866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlQ35YTqJxoOZUSXtyQgAABic"]
[Sun Aug 30 03:09:39.922164 2026] [security2:error] [pid 510357:tid 510590] [client 34.100.204.203:37896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/smtp/phpinfo.php"] [unique_id "apPlQ35YTqJxoOZUSXtyUQAABho"]
[Sun Aug 30 03:09:39.940876 2026] [security2:error] [pid 510357:tid 510496] [client 20.151.8.82:27605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/wp-manager.php"] [unique_id "apPlQ35YTqJxoOZUSXtyWgAABbw"]
[Sun Aug 30 03:09:39.972925 2026] [security2:error] [pid 510357:tid 510604] [client 20.220.10.235:36946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/motu.php"] [unique_id "apPlQ35YTqJxoOZUSXtycAAABig"]
[Sun Aug 30 03:09:39.985203 2026] [authz_core:error] [pid 510357:tid 510513] [client 216.73.216.128:20605] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:39.985499 2026] [authz_core:error] [pid 510357:tid 510513] [client 216.73.216.128:20605] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:39.987571 2026] [security2:error] [pid 510357:tid 510579] [client 213.209.159.223:51945] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/system/.env"] [unique_id "apPlQ35YTqJxoOZUSXtyegAABg8"]
[Sun Aug 30 03:09:39.987768 2026] [security2:error] [pid 510357:tid 510506] [client 4.205.62.107:61812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/app_local.php"] [unique_id "apPlQ35YTqJxoOZUSXtyewAABcY"]
[Sun Aug 30 03:09:39.998975 2026] [authz_core:error] [pid 510357:tid 510615] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:39.999256 2026] [authz_core:error] [pid 510357:tid 510615] [client 74.7.243.204:55248] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:40.064326 2026] [security2:error] [pid 510357:tid 510530] [client 158.23.147.79:57688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPlRH5YTqJxoOZUSXtykwAABd4"]
[Sun Aug 30 03:09:40.081227 2026] [security2:error] [pid 510357:tid 510611] [client 20.151.8.82:27577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "apPlRH5YTqJxoOZUSXtylQAABi8"]
[Sun Aug 30 03:09:40.103714 2026] [security2:error] [pid 510357:tid 510505] [client 20.104.50.220:5194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/b374k.php"] [unique_id "apPlRH5YTqJxoOZUSXtymwAABcU"]
[Sun Aug 30 03:09:40.120565 2026] [security2:error] [pid 510357:tid 510559] [client 213.209.159.223:51945] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "themayorcoffee.com"] [uri "/wp-config.php.backup"] [unique_id "apPlRH5YTqJxoOZUSXtyowAABfs"]
[Sun Aug 30 03:09:40.122431 2026] [security2:error] [pid 510357:tid 510521] [client 40.83.93.50:23543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/oceanwp/sass/components/plugins/panel.php"] [unique_id "apPlRH5YTqJxoOZUSXtypQAABdU"]
[Sun Aug 30 03:09:40.132738 2026] [security2:error] [pid 510357:tid 510499] [client 20.220.10.235:36942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/wefile.php"] [unique_id "apPlRH5YTqJxoOZUSXtypwAABb8"]
[Sun Aug 30 03:09:40.158757 2026] [security2:error] [pid 510357:tid 510517] [client 158.158.54.35:2691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/locale.php"] [unique_id "apPlRH5YTqJxoOZUSXtyqQAABdE"]
[Sun Aug 30 03:09:40.330472 2026] [http2:info] [pid 512881:tid 512881] h2_workers: created with min=128 max=192 idle_ms=600000
[Sun Aug 30 03:09:40.348392 2026] [security2:error] [pid 512881:tid 513013] [client 20.48.251.3:59325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/sgd.php"] [unique_id "apPlRAi65Hcg2zUJjxBOEgAAAhY"]
[Sun Aug 30 03:09:40.349186 2026] [security2:error] [pid 512881:tid 513011] [client 20.104.18.15:35147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/ta.php"] [unique_id "apPlRAi65Hcg2zUJjxBOFAAAAhQ"]
[Sun Aug 30 03:09:40.349260 2026] [security2:error] [pid 512881:tid 513014] [client 20.48.250.41:49900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/ccu.php"] [unique_id "apPlRAi65Hcg2zUJjxBOFQAAAhc"]
[Sun Aug 30 03:09:40.349432 2026] [security2:error] [pid 512881:tid 513016] [client 20.151.8.82:27511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/cgi-bin/admin.php"] [unique_id "apPlRAi65Hcg2zUJjxBOFgAAAhk"]
[Sun Aug 30 03:09:40.349835 2026] [security2:error] [pid 512881:tid 513015] [client 20.104.50.220:16611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/x50.php"] [unique_id "apPlRAi65Hcg2zUJjxBOFwAAAhg"]
[Sun Aug 30 03:09:40.349946 2026] [security2:error] [pid 512881:tid 513017] [client 20.104.50.220:63192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/ultradybbuks.php"] [unique_id "apPlRAi65Hcg2zUJjxBOGAAAAho"]
[Sun Aug 30 03:09:40.350401 2026] [security2:error] [pid 512881:tid 513018] [client 20.48.251.3:59891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/ah25.php"] [unique_id "apPlRAi65Hcg2zUJjxBOGQAAAhs"]
[Sun Aug 30 03:09:40.350917 2026] [security2:error] [pid 512881:tid 513025] [client 20.48.250.41:38846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/ccs.php"] [unique_id "apPlRAi65Hcg2zUJjxBOGwAAAiI"]
[Sun Aug 30 03:09:40.358716 2026] [security2:error] [pid 512881:tid 513032] [client 20.48.250.41:26508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/grsiuk.php"] [unique_id "apPlRAi65Hcg2zUJjxBOIgAAAik"]
[Sun Aug 30 03:09:40.365057 2026] [security2:error] [pid 512881:tid 513033] [client 20.220.10.235:36819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/Contrller.php"] [unique_id "apPlRAi65Hcg2zUJjxBOJQAAAio"]
[Sun Aug 30 03:09:40.413709 2026] [authz_core:error] [pid 512881:tid 513019] [client 66.249.66.70:52794] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:40.414193 2026] [authz_core:error] [pid 512881:tid 513019] [client 66.249.66.70:52794] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:40.432397 2026] [security2:error] [pid 512881:tid 513057] [client 20.48.250.41:44976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/cc13.php"] [unique_id "apPlRAi65Hcg2zUJjxBOLQAAAkI"]
[Sun Aug 30 03:09:40.455391 2026] [authz_core:error] [pid 512881:tid 513064] [client 66.249.66.40:62048] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:40.455677 2026] [authz_core:error] [pid 512881:tid 513064] [client 66.249.66.40:62048] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:40.467101 2026] [security2:error] [pid 512881:tid 513068] [client 20.48.251.3:7404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/wdf.php"] [unique_id "apPlRAi65Hcg2zUJjxBOMQAAAk0"]
[Sun Aug 30 03:09:40.476544 2026] [security2:error] [pid 512881:tid 513069] [client 20.48.250.41:49808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/ak.php"] [unique_id "apPlRAi65Hcg2zUJjxBOMgAAAk4"]
[Sun Aug 30 03:09:40.485771 2026] [security2:error] [pid 512881:tid 513070] [client 20.151.8.82:27636] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/wp-content/"] [unique_id "apPlRAi65Hcg2zUJjxBOMwAAAk8"]
[Sun Aug 30 03:09:40.494756 2026] [security2:error] [pid 512881:tid 513073] [client 20.48.250.41:26440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/wp-scr1pts.php"] [unique_id "apPlRAi65Hcg2zUJjxBONAAAAlI"]
[Sun Aug 30 03:09:40.531752 2026] [security2:error] [pid 512881:tid 513077] [client 20.220.10.235:36815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/file66.php"] [unique_id "apPlRAi65Hcg2zUJjxBONgAAAlY"]
[Sun Aug 30 03:09:40.532444 2026] [security2:error] [pid 512881:tid 513078] [client 20.104.50.220:64448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/chan.php"] [unique_id "apPlRAi65Hcg2zUJjxBONwAAAlc"]
[Sun Aug 30 03:09:40.549830 2026] [security2:error] [pid 512881:tid 512883] [remote 68.155.159.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ibrgroup.in"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apPlRAi65Hcg2zUJjxBOOQACVAE"]
[Sun Aug 30 03:09:40.551270 2026] [security2:error] [pid 512881:tid 513083] [client 20.104.18.15:43965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/new.php"] [unique_id "apPlRAi65Hcg2zUJjxBOOgAAAlw"]
[Sun Aug 30 03:09:40.552804 2026] [authz_core:error] [pid 512881:tid 513081] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:40.553070 2026] [authz_core:error] [pid 512881:tid 513081] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:40.565436 2026] [security2:error] [pid 512881:tid 513088] [client 68.155.159.216:63275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/radio.php"] [unique_id "apPlRAi65Hcg2zUJjxBOPAAAAmE"]
[Sun Aug 30 03:09:40.566518 2026] [security2:error] [pid 512881:tid 513089] [client 20.48.250.41:44813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/aa.php"] [unique_id "apPlRAi65Hcg2zUJjxBOPQAAAmI"]
[Sun Aug 30 03:09:40.575471 2026] [security2:error] [pid 512881:tid 513090] [client 20.104.50.220:28706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-pop.php"] [unique_id "apPlRAi65Hcg2zUJjxBOPgAAAmM"]
[Sun Aug 30 03:09:40.586122 2026] [core:alert] [pid 512881:tid 513094] [client 172.59.242.231:0] /home3/lordrcan/public_html/.htaccess: without matching section, referer: http://www.lordrcane.com/
[Sun Aug 30 03:09:40.596865 2026] [security2:error] [pid 512881:tid 513060] [client 40.83.93.50:23499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/options.php"] [unique_id "apPlRAi65Hcg2zUJjxBOQwAAAkU"]
[Sun Aug 30 03:09:40.600183 2026] [security2:error] [pid 512881:tid 513100] [client 20.48.250.41:38855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/mar.php"] [unique_id "apPlRAi65Hcg2zUJjxBORAAAAm0"]
[Sun Aug 30 03:09:40.602689 2026] [security2:error] [pid 512881:tid 513101] [client 20.104.50.220:42799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/zip.php"] [unique_id "apPlRAi65Hcg2zUJjxBORQAAAm4"]
[Sun Aug 30 03:09:40.612924 2026] [security2:error] [pid 512881:tid 513103] [client 20.48.250.41:49801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/lib.php"] [unique_id "apPlRAi65Hcg2zUJjxBORgAAAnA"]
[Sun Aug 30 03:09:40.615256 2026] [security2:error] [pid 512881:tid 513104] [client 20.151.8.82:27472] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/wp-admin/css/colors/blue/"] [unique_id "apPlRAi65Hcg2zUJjxBORwAAAnE"]
[Sun Aug 30 03:09:40.629074 2026] [security2:error] [pid 512881:tid 513105] [client 20.48.251.3:60517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/public/rip.php.php"] [unique_id "apPlRAi65Hcg2zUJjxBOSAAAAnI"]
[Sun Aug 30 03:09:40.657222 2026] [security2:error] [pid 512881:tid 513111] [client 20.48.250.41:26439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/num.php"] [unique_id "apPlRAi65Hcg2zUJjxBOSgAAAng"]
[Sun Aug 30 03:09:40.672837 2026] [security2:error] [pid 512881:tid 513116] [client 20.104.49.130:43284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/ops.php"] [unique_id "apPlRAi65Hcg2zUJjxBOSwAAAn0"]
[Sun Aug 30 03:09:40.676373 2026] [security2:error] [pid 512881:tid 513118] [client 20.220.10.235:36838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/blnux.php"] [unique_id "apPlRAi65Hcg2zUJjxBOTQAAAn8"]
[Sun Aug 30 03:09:40.680410 2026] [security2:error] [pid 512881:tid 513054] [client 34.100.204.203:37900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/phpinfo.php.bak"] [unique_id "apPlRAi65Hcg2zUJjxBOTwAAAj8"]
[Sun Aug 30 03:09:40.712995 2026] [security2:error] [pid 512881:tid 513126] [client 20.104.49.130:64730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/mac.php"] [unique_id "apPlRAi65Hcg2zUJjxBOUQAAAoc"]
[Sun Aug 30 03:09:40.728044 2026] [security2:error] [pid 512881:tid 513132] [client 20.48.250.41:45021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/s1.php"] [unique_id "apPlRAi65Hcg2zUJjxBOUwAAAo0"]
[Sun Aug 30 03:09:40.733506 2026] [security2:error] [pid 512881:tid 513133] [client 20.48.251.3:65477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/fraro.php"] [unique_id "apPlRAi65Hcg2zUJjxBOVAAAAo4"]
[Sun Aug 30 03:09:40.736936 2026] [security2:error] [pid 512881:tid 513138] [client 158.23.147.79:57682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/makeasmtp.php"] [unique_id "apPlRAi65Hcg2zUJjxBOVwAAApM"]
[Sun Aug 30 03:09:40.742131 2026] [security2:error] [pid 512881:tid 513013] [client 20.48.250.41:38792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/ccu.php"] [unique_id "apPlRAi65Hcg2zUJjxBOWAAAAhY"]
[Sun Aug 30 03:09:40.743146 2026] [security2:error] [pid 512881:tid 513011] [client 20.104.18.15:22464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/images.php"] [unique_id "apPlRAi65Hcg2zUJjxBOWQAAAhQ"]
[Sun Aug 30 03:09:40.749180 2026] [security2:error] [pid 512881:tid 513016] [client 20.104.18.15:63585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/ws13.php"] [unique_id "apPlRAi65Hcg2zUJjxBOWgAAAhk"]
[Sun Aug 30 03:09:40.751201 2026] [security2:error] [pid 512881:tid 513086] [client 158.158.54.35:2740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/wxo.php"] [unique_id "apPlRAi65Hcg2zUJjxBOWwAAAl8"]
[Sun Aug 30 03:09:40.753670 2026] [security2:error] [pid 512881:tid 513025] [client 20.151.8.82:27396] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/wp-includes/block-bindings/"] [unique_id "apPlRAi65Hcg2zUJjxBOXAAAAiI"]
[Sun Aug 30 03:09:40.759472 2026] [security2:error] [pid 512881:tid 513032] [client 20.48.250.41:49854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/wp-style.php"] [unique_id "apPlRAi65Hcg2zUJjxBOXwAAAik"]
[Sun Aug 30 03:09:40.761627 2026] [security2:error] [pid 512881:tid 513033] [client 68.155.159.216:52585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/NewFile.php/"] [unique_id "apPlRAi65Hcg2zUJjxBOYAAAAio"]
[Sun Aug 30 03:09:40.762510 2026] [security2:error] [pid 512881:tid 513035] [client 20.104.50.220:31875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/lites.php"] [unique_id "apPlRAi65Hcg2zUJjxBOYQAAAiw"]
[Sun Aug 30 03:09:40.778743 2026] [authz_core:error] [pid 512881:tid 513040] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:40.779078 2026] [authz_core:error] [pid 512881:tid 513040] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:40.801475 2026] [security2:error] [pid 512881:tid 513050] [client 4.205.62.107:17130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/wpver.php"] [unique_id "apPlRAi65Hcg2zUJjxBOaAAAAjs"]
[Sun Aug 30 03:09:40.802548 2026] [security2:error] [pid 512881:tid 513053] [client 20.104.49.130:60944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/simple.php"] [unique_id "apPlRAi65Hcg2zUJjxBOaQAAAj4"]
[Sun Aug 30 03:09:40.819394 2026] [security2:error] [pid 512881:tid 513061] [client 20.220.10.235:36928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/attack.php"] [unique_id "apPlRAi65Hcg2zUJjxBOagAAAkY"]
[Sun Aug 30 03:09:40.849684 2026] [security2:error] [pid 512881:tid 513065] [client 20.104.49.130:36761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/makeasmtp.php"] [unique_id "apPlRAi65Hcg2zUJjxBObQAAAko"]
[Sun Aug 30 03:09:40.919989 2026] [security2:error] [pid 512881:tid 513071] [client 4.205.62.107:25890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/rum.or.php"] [unique_id "apPlRAi65Hcg2zUJjxBObgAAAlA"]
[Sun Aug 30 03:09:40.921216 2026] [security2:error] [pid 512881:tid 513070] [client 20.151.8.82:27537] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/wp-includes/assets/"] [unique_id "apPlRAi65Hcg2zUJjxBObwAAAk8"]
[Sun Aug 30 03:09:40.929100 2026] [security2:error] [pid 512881:tid 513074] [client 4.205.62.107:35986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/sdsa.php"] [unique_id "apPlRAi65Hcg2zUJjxBOcgAAAlM"]
[Sun Aug 30 03:09:40.937524 2026] [security2:error] [pid 512881:tid 513077] [client 20.104.50.220:61642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/degeselih.php"] [unique_id "apPlRAi65Hcg2zUJjxBOcwAAAlY"]
[Sun Aug 30 03:09:40.949610 2026] [security2:error] [pid 512881:tid 513078] [client 20.104.49.130:32801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/samll.php"] [unique_id "apPlRAi65Hcg2zUJjxBOdQAAAlc"]
[Sun Aug 30 03:09:40.953072 2026] [security2:error] [pid 512881:tid 513080] [client 213.209.159.223:24892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themayorcoffee.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlRAi65Hcg2zUJjxBOdgAAAlk"]
[Sun Aug 30 03:09:40.973598 2026] [security2:error] [pid 512881:tid 513024] [client 20.220.10.235:37073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/wk/index.php"] [unique_id "apPlRAi65Hcg2zUJjxBOeAAAAiE"]
[Sun Aug 30 03:09:40.983535 2026] [security2:error] [pid 512881:tid 513082] [client 20.104.50.220:33189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/newfile.php"] [unique_id "apPlRAi65Hcg2zUJjxBOeQAAAls"]
[Sun Aug 30 03:09:41.013947 2026] [authz_core:error] [pid 512881:tid 513090] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:41.014234 2026] [authz_core:error] [pid 512881:tid 513090] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:41.024141 2026] [security2:error] [pid 512881:tid 513096] [client 216.73.216.128:32466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts2/updateconf"] [unique_id "apPlRQi65Hcg2zUJjxBOfAAAAmk"]
[Sun Aug 30 03:09:41.061018 2026] [security2:error] [pid 512881:tid 513060] [client 20.151.8.82:27494] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "apPlRQi65Hcg2zUJjxBOfQAAAkU"]
[Sun Aug 30 03:09:41.092565 2026] [security2:error] [pid 512881:tid 513073] [client 40.83.93.50:5568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/panel.php"] [unique_id "apPlRQi65Hcg2zUJjxBOgAAAAlI"]
[Sun Aug 30 03:09:41.121056 2026] [security2:error] [pid 512881:tid 513105] [client 20.151.200.44:28608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/tajj.php"] [unique_id "apPlRQi65Hcg2zUJjxBOggAAAnI"]
[Sun Aug 30 03:09:41.137902 2026] [security2:error] [pid 512881:tid 513012] [client 158.23.147.79:56461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apPlRQi65Hcg2zUJjxBOgwAAAhU"]
[Sun Aug 30 03:09:41.174769 2026] [security2:error] [pid 512881:tid 513112] [client 4.205.62.107:61799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/ws62.php"] [unique_id "apPlRQi65Hcg2zUJjxBOhQAAAnk"]
[Sun Aug 30 03:09:41.181041 2026] [security2:error] [pid 512881:tid 513114] [client 20.220.10.235:37081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/dehnl.php"] [unique_id "apPlRQi65Hcg2zUJjxBOiAAAAns"]
[Sun Aug 30 03:09:41.207069 2026] [security2:error] [pid 512881:tid 513076] [client 20.151.8.82:27556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "apPlRQi65Hcg2zUJjxBOiwAAAlU"]
[Sun Aug 30 03:09:41.236700 2026] [security2:error] [pid 512881:tid 513124] [client 213.209.159.223:8948] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlRQi65Hcg2zUJjxBOjQAAAoU"]
[Sun Aug 30 03:09:41.240984 2026] [security2:error] [pid 512881:tid 513126] [client 20.104.50.220:5196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/assets.php"] [unique_id "apPlRQi65Hcg2zUJjxBOjgAAAoc"]
[Sun Aug 30 03:09:41.268198 2026] [authz_core:error] [pid 512881:tid 513122] [client 66.249.66.72:35511] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:41.268500 2026] [authz_core:error] [pid 512881:tid 513122] [client 66.249.66.72:35511] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:41.300860 2026] [security2:error] [pid 512881:tid 513013] [client 20.104.49.130:36784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/btyuio.php"] [unique_id "apPlRQi65Hcg2zUJjxBOkwAAAhY"]
[Sun Aug 30 03:09:41.339416 2026] [security2:error] [pid 512881:tid 513011] [client 20.151.8.82:27399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apPlRQi65Hcg2zUJjxBOlAAAAhQ"]
[Sun Aug 30 03:09:41.390392 2026] [security2:error] [pid 512881:tid 513022] [client 20.220.10.235:36952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/png.php"] [unique_id "apPlRQi65Hcg2zUJjxBOlwAAAh8"]
[Sun Aug 30 03:09:41.397411 2026] [security2:error] [pid 512881:tid 513116] [client 158.158.54.35:16896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/wp-contentt.php"] [unique_id "apPlRQi65Hcg2zUJjxBOmQAAAn0"]
[Sun Aug 30 03:09:41.449843 2026] [security2:error] [pid 512881:tid 513050] [client 20.151.200.44:41933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/kcs.php"] [unique_id "apPlRQi65Hcg2zUJjxBOnQAAAjs"]
[Sun Aug 30 03:09:41.468691 2026] [security2:error] [pid 512881:tid 513057] [client 20.151.8.82:27472] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "apPlRQi65Hcg2zUJjxBOoAAAAkI"]
[Sun Aug 30 03:09:41.477403 2026] [security2:error] [pid 512881:tid 513056] [client 20.48.251.3:55795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/fleen.php"] [unique_id "apPlRQi65Hcg2zUJjxBOogAAAkE"]
[Sun Aug 30 03:09:41.486113 2026] [security2:error] [pid 512881:tid 513061] [client 20.104.50.220:17243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/fv.php"] [unique_id "apPlRQi65Hcg2zUJjxBOowAAAkY"]
[Sun Aug 30 03:09:41.489033 2026] [security2:error] [pid 512881:tid 513023] [client 20.48.251.3:59498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/groceries/index.php"] [unique_id "apPlRQi65Hcg2zUJjxBOpAAAAiA"]
[Sun Aug 30 03:09:41.500093 2026] [security2:error] [pid 512881:tid 513063] [client 20.104.50.220:59364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/novax.php"] [unique_id "apPlRQi65Hcg2zUJjxBOpQAAAkg"]
[Sun Aug 30 03:09:41.501002 2026] [security2:error] [pid 512881:tid 513133] [client 34.100.204.203:37916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/phpinfo.php.old"] [unique_id "apPlRQi65Hcg2zUJjxBOpgAAAo4"]
[Sun Aug 30 03:09:41.503675 2026] [security2:error] [pid 512881:tid 513049] [client 20.104.18.15:35195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/bo.php"] [unique_id "apPlRQi65Hcg2zUJjxBOqAAAAjo"]
[Sun Aug 30 03:09:41.531823 2026] [security2:error] [pid 512881:tid 513110] [client 20.220.10.235:37068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/txets.php"] [unique_id "apPlRQi65Hcg2zUJjxBOqgAAAnc"]
[Sun Aug 30 03:09:41.547337 2026] [authz_core:error] [pid 512881:tid 513066] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:41.547792 2026] [authz_core:error] [pid 512881:tid 513066] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:41.560740 2026] [security2:error] [pid 512881:tid 513033] [client 40.83.93.50:5628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/reboot/assets/js/plugins/home.php"] [unique_id "apPlRQi65Hcg2zUJjxBOrAAAAio"]
[Sun Aug 30 03:09:41.567673 2026] [security2:error] [pid 512881:tid 513074] [client 213.209.159.223:8948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themayorcoffee.com"] [uri "/php-info.php"] [unique_id "apPlRQi65Hcg2zUJjxBOrgAAAlM"]
[Sun Aug 30 03:09:41.607951 2026] [security2:error] [pid 512881:tid 513024] [client 20.151.8.82:27478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/qazwsx.php"] [unique_id "apPlRQi65Hcg2zUJjxBOsQAAAiE"]
[Sun Aug 30 03:09:41.623190 2026] [authz_core:error] [pid 512881:tid 513029] [client 66.249.66.71:43878] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:41.623656 2026] [authz_core:error] [pid 512881:tid 513029] [client 66.249.66.71:43878] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:41.666035 2026] [security2:error] [pid 512881:tid 513098] [client 68.155.159.216:62647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPlRQi65Hcg2zUJjxBOuAAAAms"]
[Sun Aug 30 03:09:41.666172 2026] [security2:error] [pid 512881:tid 513099] [client 20.104.50.220:52811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/losX.php"] [unique_id "apPlRQi65Hcg2zUJjxBOuQAAAmw"]
[Sun Aug 30 03:09:41.668804 2026] [security2:error] [pid 512881:tid 513060] [client 158.23.147.79:57670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apPlRQi65Hcg2zUJjxBOugAAAkU"]
[Sun Aug 30 03:09:41.703420 2026] [security2:error] [pid 512881:tid 513103] [client 20.220.10.235:37070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/wp-login.php"] [unique_id "apPlRQi65Hcg2zUJjxBOuwAAAnA"]
[Sun Aug 30 03:09:41.715356 2026] [security2:error] [pid 512881:tid 513044] [client 20.104.50.220:29586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/marjan.php"] [unique_id "apPlRQi65Hcg2zUJjxBOvgAAAjU"]
[Sun Aug 30 03:09:41.725280 2026] [security2:error] [pid 512881:tid 513012] [client 20.104.18.15:43297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/inx.php"] [unique_id "apPlRQi65Hcg2zUJjxBOwAAAAhU"]
[Sun Aug 30 03:09:41.726222 2026] [authz_core:error] [pid 512881:tid 513090] [client 66.249.66.69:35799] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:41.726495 2026] [authz_core:error] [pid 512881:tid 513090] [client 66.249.66.69:35799] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:41.740480 2026] [security2:error] [pid 512881:tid 513115] [client 20.104.50.220:42444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/@.php"] [unique_id "apPlRQi65Hcg2zUJjxBOwgAAAnw"]
[Sun Aug 30 03:09:41.740507 2026] [security2:error] [pid 512881:tid 513114] [client 20.151.8.82:27435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/elp.php"] [unique_id "apPlRQi65Hcg2zUJjxBOwQAAAns"]
[Sun Aug 30 03:09:41.744796 2026] [security2:error] [pid 512881:tid 513117] [client 216.73.216.128:1201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlRQi65Hcg2zUJjxBOwwAAAn4"]
[Sun Aug 30 03:09:41.766864 2026] [security2:error] [pid 512881:tid 513076] [client 20.48.251.3:13403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/environment.php"] [unique_id "apPlRQi65Hcg2zUJjxBOxAAAAlU"]
[Sun Aug 30 03:09:41.777974 2026] [security2:error] [pid 512881:tid 513128] [client 20.48.251.3:64454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/bb.php"] [unique_id "apPlRQi65Hcg2zUJjxBOxQAAAok"]
[Sun Aug 30 03:09:41.798099 2026] [security2:error] [pid 512881:tid 513026] [client 20.48.250.41:26469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/a4.php"] [unique_id "apPlRQi65Hcg2zUJjxBOxgAAAiM"]
[Sun Aug 30 03:09:41.842740 2026] [security2:error] [pid 512881:tid 513022] [client 20.220.10.235:36957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/wp-access.php"] [unique_id "apPlRQi65Hcg2zUJjxBOyQAAAh8"]
[Sun Aug 30 03:09:41.869356 2026] [security2:error] [pid 512881:tid 513054] [client 20.48.251.3:64262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/thui.php"] [unique_id "apPlRQi65Hcg2zUJjxBOzAAAAj8"]
[Sun Aug 30 03:09:41.878844 2026] [security2:error] [pid 512881:tid 513015] [client 20.104.18.15:22435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/ops.php"] [unique_id "apPlRQi65Hcg2zUJjxBOzgAAAhg"]
[Sun Aug 30 03:09:41.885094 2026] [security2:error] [pid 512881:tid 513018] [client 20.104.18.15:64774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/btx25.php"] [unique_id "apPlRQi65Hcg2zUJjxBOzwAAAhs"]
[Sun Aug 30 03:09:41.896982 2026] [security2:error] [pid 512881:tid 513041] [client 20.48.250.41:49843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/browse.php"] [unique_id "apPlRQi65Hcg2zUJjxBO0AAAAjI"]
[Sun Aug 30 03:09:41.898247 2026] [security2:error] [pid 512881:tid 513045] [client 20.48.250.41:44891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/0byte.php"] [unique_id "apPlRQi65Hcg2zUJjxBO0QAAAjY"]
[Sun Aug 30 03:09:41.909077 2026] [security2:error] [pid 512881:tid 513050] [client 20.151.8.82:27485] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/wp-content/uploads/"] [unique_id "apPlRQi65Hcg2zUJjxBO0gAAAjs"]
[Sun Aug 30 03:09:41.941721 2026] [security2:error] [pid 512881:tid 513056] [client 4.205.62.107:17312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/ah25.php"] [unique_id "apPlRQi65Hcg2zUJjxBO0wAAAkE"]
[Sun Aug 30 03:09:41.975883 2026] [security2:error] [pid 512881:tid 513110] [client 20.104.50.220:31935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/0x.php"] [unique_id "apPlRQi65Hcg2zUJjxBO1gAAAnc"]
[Sun Aug 30 03:09:41.979332 2026] [security2:error] [pid 512881:tid 513081] [client 158.23.147.79:57707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-content/languages/about.php"] [unique_id "apPlRQi65Hcg2zUJjxBO2AAAAlo"]
[Sun Aug 30 03:09:41.984639 2026] [security2:error] [pid 512881:tid 513019] [client 20.104.49.130:63580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/init.php"] [unique_id "apPlRQi65Hcg2zUJjxBO2QAAAhw"]
[Sun Aug 30 03:09:41.990764 2026] [security2:error] [pid 512881:tid 513037] [client 20.220.10.235:37065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/wp-content/admin.php"] [unique_id "apPlRQi65Hcg2zUJjxBO2gAAAi4"]
[Sun Aug 30 03:09:42.010543 2026] [security2:error] [pid 512881:tid 513033] [client 20.48.250.41:26511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/tfm.php"] [unique_id "apPlRgi65Hcg2zUJjxBO2wAAAio"]
[Sun Aug 30 03:09:42.014062 2026] [security2:error] [pid 512881:tid 513070] [client 20.48.250.41:38849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/ak.php"] [unique_id "apPlRgi65Hcg2zUJjxBO3AAAAk8"]
[Sun Aug 30 03:09:42.036960 2026] [security2:error] [pid 512881:tid 513027] [client 40.83.93.50:5631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/salient/css/build/plugins/login.php"] [unique_id "apPlRgi65Hcg2zUJjxBO3wAAAiQ"]
[Sun Aug 30 03:09:42.037520 2026] [security2:error] [pid 512881:tid 513062] [client 20.48.250.41:49912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/zoo.php"] [unique_id "apPlRgi65Hcg2zUJjxBO4QAAAkc"]
[Sun Aug 30 03:09:42.037612 2026] [security2:error] [pid 512881:tid 513069] [client 68.155.159.216:54317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/dropdown.php"] [unique_id "apPlRgi65Hcg2zUJjxBO4AAAAk4"]
[Sun Aug 30 03:09:42.046442 2026] [authz_core:error] [pid 512881:tid 513080] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:42.046736 2026] [authz_core:error] [pid 512881:tid 513080] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:42.069308 2026] [security2:error] [pid 512881:tid 513088] [client 4.205.62.107:36653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/sale.php"] [unique_id "apPlRgi65Hcg2zUJjxBO5wAAAmE"]
[Sun Aug 30 03:09:42.073205 2026] [security2:error] [pid 512881:tid 513129] [client 20.151.8.82:27480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/dorps.php"] [unique_id "apPlRgi65Hcg2zUJjxBO6AAAAoo"]
[Sun Aug 30 03:09:42.078836 2026] [authz_core:error] [pid 512881:tid 513087] [client 216.73.216.128:53111] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:42.079299 2026] [authz_core:error] [pid 512881:tid 513087] [client 216.73.216.128:53111] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:42.090081 2026] [security2:error] [pid 512881:tid 513113] [client 20.48.250.41:45054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/xr.php"] [unique_id "apPlRgi65Hcg2zUJjxBO6QAAAno"]
[Sun Aug 30 03:09:42.121395 2026] [security2:error] [pid 512881:tid 513089] [client 20.104.50.220:33313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/pro.php"] [unique_id "apPlRgi65Hcg2zUJjxBO6wAAAmI"]
[Sun Aug 30 03:09:42.124078 2026] [security2:error] [pid 512881:tid 513091] [client 4.205.62.107:27002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/xmy.php"] [unique_id "apPlRgi65Hcg2zUJjxBO7AAAAmQ"]
[Sun Aug 30 03:09:42.136252 2026] [security2:error] [pid 512881:tid 513058] [client 20.220.10.235:36929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/log.php"] [unique_id "apPlRgi65Hcg2zUJjxBO7QAAAkM"]
[Sun Aug 30 03:09:42.148936 2026] [security2:error] [pid 512881:tid 513060] [client 20.48.250.41:26614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/Geforce.php"] [unique_id "apPlRgi65Hcg2zUJjxBO7gAAAkU"]
[Sun Aug 30 03:09:42.160830 2026] [security2:error] [pid 512881:tid 513092] [client 52.139.37.240:44594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/403.php"] [unique_id "apPlRgi65Hcg2zUJjxBO7wAAAmU"]
[Sun Aug 30 03:09:42.164661 2026] [security2:error] [pid 512881:tid 513068] [client 158.158.54.35:2835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/class_api.php"] [unique_id "apPlRgi65Hcg2zUJjxBO8AAAAk0"]
[Sun Aug 30 03:09:42.172269 2026] [security2:error] [pid 512881:tid 513102] [client 20.104.50.220:61442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/doc.php"] [unique_id "apPlRgi65Hcg2zUJjxBO8QAAAm8"]
[Sun Aug 30 03:09:42.176129 2026] [security2:error] [pid 512881:tid 513066] [client 20.48.250.41:38872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/lib.php"] [unique_id "apPlRgi65Hcg2zUJjxBO8gAAAks"]
[Sun Aug 30 03:09:42.177910 2026] [security2:error] [pid 512881:tid 513071] [client 20.48.250.41:49873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/elp.php"] [unique_id "apPlRgi65Hcg2zUJjxBO8wAAAlA"]
[Sun Aug 30 03:09:42.180916 2026] [security2:error] [pid 512881:tid 513103] [client 20.104.49.130:57645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/init.php"] [unique_id "apPlRgi65Hcg2zUJjxBO9AAAAnA"]
[Sun Aug 30 03:09:42.200967 2026] [security2:error] [pid 512881:tid 513093] [client 213.209.159.223:26417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themayorcoffee.com"] [uri "/info.php.bak"] [unique_id "apPlRgi65Hcg2zUJjxBO9gAAAmY"]
[Sun Aug 30 03:09:42.205680 2026] [security2:error] [pid 512881:tid 513012] [client 20.151.8.82:27477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/wp_blog_footer.php"] [unique_id "apPlRgi65Hcg2zUJjxBO-QAAAhU"]
[Sun Aug 30 03:09:42.246912 2026] [security2:error] [pid 512881:tid 513125] [client 20.48.250.41:44979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/h02ugyh.php"] [unique_id "apPlRgi65Hcg2zUJjxBO-wAAAoY"]
[Sun Aug 30 03:09:42.262524 2026] [security2:error] [pid 512881:tid 513051] [client 34.100.204.203:37920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/phpinfo.php~"] [unique_id "apPlRgi65Hcg2zUJjxBO_QAAAjw"]
[Sun Aug 30 03:09:42.269438 2026] [authz_core:error] [pid 512881:tid 513127] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:42.269732 2026] [authz_core:error] [pid 512881:tid 513127] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:42.304659 2026] [security2:error] [pid 512881:tid 513132] [client 20.220.10.235:36998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/xwpg.php"] [unique_id "apPlRgi65Hcg2zUJjxBPAAAAAo0"]
[Sun Aug 30 03:09:42.329810 2026] [security2:error] [pid 512881:tid 513100] [client 4.205.62.107:64675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/grsiuk.php"] [unique_id "apPlRgi65Hcg2zUJjxBPAQAAAm0"]
[Sun Aug 30 03:09:42.345326 2026] [security2:error] [pid 512881:tid 513055] [client 20.151.8.82:27509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/cagor.php"] [unique_id "apPlRgi65Hcg2zUJjxBPAgAAAkA"]
[Sun Aug 30 03:09:42.348145 2026] [security2:error] [pid 512881:tid 513048] [client 20.104.18.15:18327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/wp-includes/ID3/moon.php"] [unique_id "apPlRgi65Hcg2zUJjxBPBAAAAjk"]
[Sun Aug 30 03:09:42.351825 2026] [autoindex:error] [pid 512881:tid 513131] [client 34.237.50.25:31607] AH01276: Cannot serve directory /home1/ajaisingh93/public_html/.website_770d4ac7/: No matching DirectoryIndex (index.html,index.php) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:09:42.353217 2026] [core:error] [pid 512881:tid 513131] [client 34.237.50.25:31607] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:09:42.356494 2026] [security2:error] [pid 512881:tid 513026] [client 52.139.37.240:44625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/av.php"] [unique_id "apPlRgi65Hcg2zUJjxBPBQAAAiM"]
[Sun Aug 30 03:09:42.378628 2026] [security2:error] [pid 512881:tid 513035] [client 20.104.50.220:5604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/system.php"] [unique_id "apPlRgi65Hcg2zUJjxBPBwAAAiw"]
[Sun Aug 30 03:09:42.451701 2026] [security2:error] [pid 512881:tid 513018] [client 20.220.10.235:36973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/sxxb.php"] [unique_id "apPlRgi65Hcg2zUJjxBPCgAAAhs"]
[Sun Aug 30 03:09:42.455983 2026] [security2:error] [pid 512881:tid 513041] [client 158.23.147.79:1984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-content/banners/about.php"] [unique_id "apPlRgi65Hcg2zUJjxBPCwAAAjI"]
[Sun Aug 30 03:09:42.470304 2026] [security2:error] [pid 512881:tid 513057] [client 213.209.159.223:64986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themayorcoffee.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlRgi65Hcg2zUJjxBPDgAAAkI"]
[Sun Aug 30 03:09:42.474007 2026] [security2:error] [pid 512881:tid 513063] [client 20.151.8.82:27617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/billzgs.php"] [unique_id "apPlRgi65Hcg2zUJjxBPEAAAAkg"]
[Sun Aug 30 03:09:42.478307 2026] [authz_core:error] [pid 512881:tid 513015] [client 66.249.66.77:51071] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:42.478587 2026] [authz_core:error] [pid 512881:tid 513015] [client 66.249.66.77:51071] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:42.485447 2026] [authz_core:error] [pid 512881:tid 513023] [client 216.73.216.128:32606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:42.485873 2026] [authz_core:error] [pid 512881:tid 513023] [client 216.73.216.128:32606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:42.503860 2026] [authz_core:error] [pid 512881:tid 513137] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:42.504054 2026] [security2:error] [pid 512881:tid 513123] [client 40.83.93.50:5595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/security.php"] [unique_id "apPlRgi65Hcg2zUJjxBPEwAAAoQ"]
[Sun Aug 30 03:09:42.504132 2026] [authz_core:error] [pid 512881:tid 513137] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:42.547014 2026] [security2:error] [pid 512881:tid 513133] [client 52.139.37.240:13871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/wp-admin/index.php"] [unique_id "apPlRgi65Hcg2zUJjxBPFgAAAo4"]
[Sun Aug 30 03:09:42.594278 2026] [security2:error] [pid 512881:tid 513011] [client 20.220.10.235:36986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/dx.php"] [unique_id "apPlRgi65Hcg2zUJjxBPGQAAAhQ"]
[Sun Aug 30 03:09:42.608273 2026] [security2:error] [pid 512881:tid 513062] [client 20.151.8.82:27609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/BDKR28_u7cn8y3b.php"] [unique_id "apPlRgi65Hcg2zUJjxBPGwAAAkc"]
[Sun Aug 30 03:09:42.619301 2026] [security2:error] [pid 512881:tid 513078] [client 20.48.251.3:59375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/upload.form.php"] [unique_id "apPlRgi65Hcg2zUJjxBPHAAAAlc"]
[Sun Aug 30 03:09:42.625935 2026] [security2:error] [pid 512881:tid 513020] [client 20.48.251.3:59857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/konfig.php"] [unique_id "apPlRgi65Hcg2zUJjxBPHQAAAh0"]
[Sun Aug 30 03:09:42.628338 2026] [security2:error] [pid 512881:tid 513075] [client 20.104.50.220:17321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/file.php"] [unique_id "apPlRgi65Hcg2zUJjxBPHgAAAlQ"]
[Sun Aug 30 03:09:42.646458 2026] [security2:error] [pid 512881:tid 513120] [client 20.104.18.15:35024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/44.php"] [unique_id "apPlRgi65Hcg2zUJjxBPIQAAAoE"]
[Sun Aug 30 03:09:42.649444 2026] [authz_core:error] [pid 512881:tid 513070] [client 66.249.66.70:61505] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:42.649713 2026] [authz_core:error] [pid 512881:tid 513070] [client 66.249.66.70:61505] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:42.665683 2026] [security2:error] [pid 512881:tid 513049] [client 158.158.54.35:16919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/configs.php"] [unique_id "apPlRgi65Hcg2zUJjxBPJAAAAjo"]
[Sun Aug 30 03:09:42.721892 2026] [security2:error] [pid 512881:tid 513092] [client 20.104.50.220:63201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/mosty.php"] [unique_id "apPlRgi65Hcg2zUJjxBPJgAAAmU"]
[Sun Aug 30 03:09:42.732706 2026] [security2:error] [pid 512881:tid 513103] [client 20.220.10.235:36842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPlRgi65Hcg2zUJjxBPKAAAAnA"]
[Sun Aug 30 03:09:42.737842 2026] [security2:error] [pid 512881:tid 513105] [client 20.151.8.82:27640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.8.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.patricchiosprototypes.com"] [uri "/dftwg.php"] [unique_id "apPlRgi65Hcg2zUJjxBPKQAAAnI"]
[Sun Aug 30 03:09:42.738635 2026] [security2:error] [pid 512881:tid 513098] [client 52.139.37.240:44616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "apPlRgi65Hcg2zUJjxBPKgAAAms"]
[Sun Aug 30 03:09:42.789234 2026] [authz_core:error] [pid 512881:tid 513071] [client 66.249.66.64:61060] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:42.789543 2026] [authz_core:error] [pid 512881:tid 513071] [client 66.249.66.64:61060] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:42.819557 2026] [security2:error] [pid 512881:tid 513118] [client 68.155.159.216:62606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/makeasmtp.php"] [unique_id "apPlRgi65Hcg2zUJjxBPMQAAAn8"]
[Sun Aug 30 03:09:42.822214 2026] [security2:error] [pid 512881:tid 513130] [client 20.104.50.220:28688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/mom.php"] [unique_id "apPlRgi65Hcg2zUJjxBPMgAAAos"]
[Sun Aug 30 03:09:42.868806 2026] [security2:error] [pid 512881:tid 513016] [client 20.104.50.220:29163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/on.php"] [unique_id "apPlRgi65Hcg2zUJjxBPOAAAAhk"]
[Sun Aug 30 03:09:42.879052 2026] [security2:error] [pid 512881:tid 513026] [client 20.104.50.220:51606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/ea.php"] [unique_id "apPlRgi65Hcg2zUJjxBPOgAAAiM"]
[Sun Aug 30 03:09:42.885461 2026] [security2:error] [pid 512881:tid 513022] [client 20.220.10.235:36857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/xda.php"] [unique_id "apPlRgi65Hcg2zUJjxBPPAAAAh8"]
[Sun Aug 30 03:09:42.906592 2026] [security2:error] [pid 512881:tid 513072] [client 20.104.18.15:43966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/vpn.php"] [unique_id "apPlRgi65Hcg2zUJjxBPPQAAAlE"]
[Sun Aug 30 03:09:42.911138 2026] [security2:error] [pid 512881:tid 513021] [client 20.48.251.3:13952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/aws_secret_config.php"] [unique_id "apPlRgi65Hcg2zUJjxBPPgAAAh4"]
[Sun Aug 30 03:09:42.929851 2026] [security2:error] [pid 512881:tid 513065] [client 52.139.37.240:44631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/wp-content/themes/pridmag/b.php"] [unique_id "apPlRgi65Hcg2zUJjxBPQQAAAko"]
[Sun Aug 30 03:09:42.933815 2026] [security2:error] [pid 512881:tid 513041] [client 20.151.200.44:28620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/bge.php"] [unique_id "apPlRgi65Hcg2zUJjxBPQwAAAjI"]
[Sun Aug 30 03:09:42.936686 2026] [security2:error] [pid 512881:tid 513061] [client 158.23.147.79:56449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apPlRgi65Hcg2zUJjxBPRAAAAkY"]
[Sun Aug 30 03:09:42.938666 2026] [authz_core:error] [pid 512881:tid 513073] [client 216.73.216.128:32606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:42.939064 2026] [authz_core:error] [pid 512881:tid 513073] [client 216.73.216.128:32606] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:42.977390 2026] [security2:error] [pid 512881:tid 513051] [client 40.83.93.50:23510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "apPlRgi65Hcg2zUJjxBPRgAAAjw"]
[Sun Aug 30 03:09:42.978688 2026] [authz_core:error] [pid 512881:tid 513121] [client 66.249.66.41:46433] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:42.978975 2026] [authz_core:error] [pid 512881:tid 513121] [client 66.249.66.41:46433] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:43.010141 2026] [authz_core:error] [pid 512881:tid 513097] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:43.010443 2026] [authz_core:error] [pid 512881:tid 513097] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:43.016472 2026] [security2:error] [pid 512881:tid 513085] [client 20.104.18.15:22420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/coffexium.php"] [unique_id "apPlRwi65Hcg2zUJjxBPSAAAAl4"]
[Sun Aug 30 03:09:43.024746 2026] [security2:error] [pid 512881:tid 513046] [client 34.100.204.203:37924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/info.php.bak"] [unique_id "apPlRwi65Hcg2zUJjxBPSgAAAjc"]
[Sun Aug 30 03:09:43.025362 2026] [security2:error] [pid 512881:tid 513032] [client 20.220.10.235:36944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPlRwi65Hcg2zUJjxBPSwAAAik"]
[Sun Aug 30 03:09:43.026727 2026] [authz_core:error] [pid 512881:tid 513133] [client 216.73.216.128:52276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:43.026973 2026] [authz_core:error] [pid 512881:tid 513133] [client 216.73.216.128:52276] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:43.029599 2026] [security2:error] [pid 512881:tid 513033] [client 20.104.18.15:16693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/SDsadqwrf.php"] [unique_id "apPlRwi65Hcg2zUJjxBPTAAAAio"]
[Sun Aug 30 03:09:43.033800 2026] [security2:error] [pid 512881:tid 513011] [client 20.48.251.3:64277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/lala.php"] [unique_id "apPlRwi65Hcg2zUJjxBPTQAAAhQ"]
[Sun Aug 30 03:09:43.071211 2026] [security2:error] [pid 512881:tid 513078] [client 20.104.49.130:59998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/wpxml.php"] [unique_id "apPlRwi65Hcg2zUJjxBPUgAAAlc"]
[Sun Aug 30 03:09:43.078866 2026] [security2:error] [pid 512881:tid 513075] [client 4.205.62.107:17101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/groceries/index.php"] [unique_id "apPlRwi65Hcg2zUJjxBPVAAAAlQ"]
[Sun Aug 30 03:09:43.098369 2026] [security2:error] [pid 512881:tid 513049] [client 20.48.251.3:6478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/file59.php"] [unique_id "apPlRwi65Hcg2zUJjxBPVwAAAjo"]
[Sun Aug 30 03:09:43.106234 2026] [security2:error] [pid 512881:tid 513099] [client 213.209.159.223:15906] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/env/.env"] [unique_id "apPlRwi65Hcg2zUJjxBPWQAAAmw"]
[Sun Aug 30 03:09:43.133114 2026] [security2:error] [pid 512881:tid 513039] [client 158.158.54.35:16931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/update.php"] [unique_id "apPlRwi65Hcg2zUJjxBPXAAAAjA"]
[Sun Aug 30 03:09:43.136070 2026] [security2:error] [pid 512881:tid 513080] [client 20.104.50.220:32079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/bless3.php"] [unique_id "apPlRwi65Hcg2zUJjxBPXQAAAlk"]
[Sun Aug 30 03:09:43.167031 2026] [security2:error] [pid 512881:tid 513066] [client 20.220.10.235:36967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/t00l.php"] [unique_id "apPlRwi65Hcg2zUJjxBPYAAAAks"]
[Sun Aug 30 03:09:43.207636 2026] [security2:error] [pid 512881:tid 513047] [client 4.205.62.107:36684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/wp-class.php"] [unique_id "apPlRwi65Hcg2zUJjxBPaAAAAjg"]
[Sun Aug 30 03:09:43.207836 2026] [security2:error] [pid 512881:tid 513012] [client 68.155.159.216:52579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/.well-known/index.php"] [unique_id "apPlRwi65Hcg2zUJjxBPaQAAAhU"]
[Sun Aug 30 03:09:43.224824 2026] [security2:error] [pid 512881:tid 513111] [client 20.104.49.130:64765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/ccc.php"] [unique_id "apPlRwi65Hcg2zUJjxBPawAAAng"]
[Sun Aug 30 03:09:43.270964 2026] [security2:error] [pid 512881:tid 513084] [client 20.104.50.220:33598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/edit.php"] [unique_id "apPlRwi65Hcg2zUJjxBPbwAAAl0"]
[Sun Aug 30 03:09:43.271654 2026] [security2:error] [pid 512881:tid 513037] [client 158.23.147.79:56460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/asd.php"] [unique_id "apPlRwi65Hcg2zUJjxBPcAAAAi4"]
[Sun Aug 30 03:09:43.290044 2026] [security2:error] [pid 512881:tid 513067] [client 20.48.250.41:26507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/click.php"] [unique_id "apPlRwi65Hcg2zUJjxBPcQAAAkw"]
[Sun Aug 30 03:09:43.295384 2026] [security2:error] [pid 512881:tid 513036] [client 216.73.216.128:32606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mysqlupgrade"] [unique_id "apPlRwi65Hcg2zUJjxBPdAAAAi0"]
[Sun Aug 30 03:09:43.309339 2026] [core:alert] [pid 512881:tid 513132] [client 186.121.108.159:0] /home3/lordrcan/public_html/.htaccess: without matching section, referer: http://www.lordrcane.com/
[Sun Aug 30 03:09:43.311105 2026] [security2:error] [pid 512881:tid 513100] [client 4.205.62.107:25738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/ms-edit.php"] [unique_id "apPlRwi65Hcg2zUJjxBPdgAAAm0"]
[Sun Aug 30 03:09:43.313980 2026] [security2:error] [pid 512881:tid 513016] [client 20.48.250.41:49865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/666.php"] [unique_id "apPlRwi65Hcg2zUJjxBPdwAAAhk"]
[Sun Aug 30 03:09:43.318097 2026] [security2:error] [pid 512881:tid 513077] [client 20.220.10.235:36945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/ls.php"] [unique_id "apPlRwi65Hcg2zUJjxBPeAAAAlY"]
[Sun Aug 30 03:09:43.335870 2026] [security2:error] [pid 512881:tid 513104] [client 20.104.49.130:39056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/images.php"] [unique_id "apPlRwi65Hcg2zUJjxBPeQAAAnE"]
[Sun Aug 30 03:09:43.339810 2026] [security2:error] [pid 512881:tid 513048] [client 20.48.250.41:38896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/wp-style.php"] [unique_id "apPlRwi65Hcg2zUJjxBPegAAAjk"]
[Sun Aug 30 03:09:43.362521 2026] [security2:error] [pid 512881:tid 513116] [client 20.104.50.220:61998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/docindex.php"] [unique_id "apPlRwi65Hcg2zUJjxBPfQAAAn0"]
[Sun Aug 30 03:09:43.378510 2026] [security2:error] [pid 512881:tid 513090] [client 52.139.37.240:44606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/0.php"] [unique_id "apPlRwi65Hcg2zUJjxBPfgAAAmM"]
[Sun Aug 30 03:09:43.390612 2026] [security2:error] [pid 512881:tid 513021] [client 20.48.250.41:44966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/xxw.php"] [unique_id "apPlRwi65Hcg2zUJjxBPgAAAAh4"]
[Sun Aug 30 03:09:43.423787 2026] [security2:error] [pid 512881:tid 513065] [client 213.209.159.223:15906] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/src/.env"] [unique_id "apPlRwi65Hcg2zUJjxBPgQAAAko"]
[Sun Aug 30 03:09:43.440636 2026] [security2:error] [pid 512881:tid 513124] [client 40.83.93.50:20961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/system.php"] [unique_id "apPlRwi65Hcg2zUJjxBPggAAAoU"]
[Sun Aug 30 03:09:43.452262 2026] [security2:error] [pid 512881:tid 513119] [client 20.48.250.41:49859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/knmt.php"] [unique_id "apPlRwi65Hcg2zUJjxBPhAAAAoA"]
[Sun Aug 30 03:09:43.454456 2026] [security2:error] [pid 512881:tid 513056] [client 20.48.250.41:26597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/ms.php"] [unique_id "apPlRwi65Hcg2zUJjxBPhQAAAkE"]
[Sun Aug 30 03:09:43.463578 2026] [security2:error] [pid 512881:tid 513052] [client 20.220.10.235:37079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/css/000.php"] [unique_id "apPlRwi65Hcg2zUJjxBPhwAAAj0"]
[Sun Aug 30 03:09:43.466385 2026] [security2:error] [pid 512881:tid 513051] [client 4.205.62.107:58455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/paypal.php"] [unique_id "apPlRwi65Hcg2zUJjxBPiAAAAjw"]
[Sun Aug 30 03:09:43.487861 2026] [security2:error] [pid 512881:tid 513033] [client 20.104.18.15:18374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/xmini4.php"] [unique_id "apPlRwi65Hcg2zUJjxBPiwAAAio"]
[Sun Aug 30 03:09:43.509426 2026] [authz_core:error] [pid 512881:tid 513011] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:43.509727 2026] [authz_core:error] [pid 512881:tid 513011] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:43.527294 2026] [security2:error] [pid 512881:tid 513126] [client 20.48.250.41:38796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/browse.php"] [unique_id "apPlRwi65Hcg2zUJjxBPkwAAAoc"]
[Sun Aug 30 03:09:43.552749 2026] [security2:error] [pid 512881:tid 513133] [client 20.104.50.220:5458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/git.php"] [unique_id "apPlRwi65Hcg2zUJjxBPlQAAAo4"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:43.569757 2026] [security2:error] [pid 512881:tid 513019] [client 52.139.37.240:44575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/autoload_classmap/function.php"] [unique_id "apPlRwi65Hcg2zUJjxBPmQAAAhw"]
[Sun Aug 30 03:09:43.582292 2026] [security2:error] [pid 512881:tid 513035] [client 20.48.250.41:26602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/zxekqlxb.php"] [unique_id "apPlRwi65Hcg2zUJjxBPmgAAAiw"]
[Sun Aug 30 03:09:43.588593 2026] [security2:error] [pid 512881:tid 513092] [client 20.48.250.41:44966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/bolt.php"] [unique_id "apPlRwi65Hcg2zUJjxBPmwAAAmU"]
[Sun Aug 30 03:09:43.602075 2026] [security2:error] [pid 512881:tid 513047] [client 20.220.10.235:36800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/cy.php"] [unique_id "apPlRwi65Hcg2zUJjxBPnAAAAjg"]
[Sun Aug 30 03:09:43.606537 2026] [security2:error] [pid 512881:tid 513012] [client 158.23.147.79:56479] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.ballroomology.com"] [uri "/1.php"] [unique_id "apPlRwi65Hcg2zUJjxBPnQAAAhU"]
[Sun Aug 30 03:09:43.606697 2026] [security2:error] [pid 512881:tid 513012] [client 158.23.147.79:56479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/1.php"] [unique_id "apPlRwi65Hcg2zUJjxBPnQAAAhU"]
[Sun Aug 30 03:09:43.646346 2026] [authz_core:error] [pid 512881:tid 513114] [client 66.249.66.193:56267] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:43.646614 2026] [authz_core:error] [pid 512881:tid 513114] [client 66.249.66.193:56267] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:43.726827 2026] [security2:error] [pid 512881:tid 513102] [client 158.158.54.35:16941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.54.158.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direcorgigames.com"] [uri "/input.php"] [unique_id "apPlRwi65Hcg2zUJjxBPqAAAAm8"]
[Sun Aug 30 03:09:43.739894 2026] [security2:error] [pid 512881:tid 513137] [client 213.209.159.223:15906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themayorcoffee.com"] [uri "/config/app.php"] [unique_id "apPlRwi65Hcg2zUJjxBPqwAAApI"]
[Sun Aug 30 03:09:43.740122 2026] [security2:error] [pid 512881:tid 513100] [client 20.220.10.235:36974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/admin.php/pindex.php"] [unique_id "apPlRwi65Hcg2zUJjxBPrAAAAm0"]
[Sun Aug 30 03:09:43.760699 2026] [security2:error] [pid 512881:tid 513067] [client 52.139.37.240:44627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/dvve.php"] [unique_id "apPlRwi65Hcg2zUJjxBPrwAAAkw"]
[Sun Aug 30 03:09:43.764174 2026] [security2:error] [pid 512881:tid 513077] [client 20.48.251.3:59483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/paths.php"] [unique_id "apPlRwi65Hcg2zUJjxBPsQAAAlY"]
[Sun Aug 30 03:09:43.773097 2026] [security2:error] [pid 512881:tid 512915] [remote 52.167.144.180:18666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themesslab.com"] [uri "/index.php/2016/10/04/peppermill-casino-review-and-free-chips-bonus/"] [unique_id "apPlRwi65Hcg2zUJjxBPsAACFiE"]
[Sun Aug 30 03:09:43.776108 2026] [security2:error] [pid 512881:tid 513113] [client 20.104.50.220:17310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/lsd.php"] [unique_id "apPlRwi65Hcg2zUJjxBPsgAAAno"]
[Sun Aug 30 03:09:43.790839 2026] [security2:error] [pid 512881:tid 513038] [client 34.100.204.203:37940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/phpinfo.php.save"] [unique_id "apPlRwi65Hcg2zUJjxBPswAAAi8"]
[Sun Aug 30 03:09:43.799448 2026] [security2:error] [pid 512881:tid 513104] [client 20.48.251.3:52805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/aws_auth.php"] [unique_id "apPlRwi65Hcg2zUJjxBPtAAAAnE"]
[Sun Aug 30 03:09:43.807776 2026] [security2:error] [pid 512881:tid 513026] [client 20.104.18.15:35141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/h2.php"] [unique_id "apPlRwi65Hcg2zUJjxBPtQAAAiM"]
[Sun Aug 30 03:09:43.845327 2026] [security2:error] [pid 512881:tid 513021] [client 216.73.216.128:20032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/js/sorttable.js"] [unique_id "apPlRwi65Hcg2zUJjxBPuAAAAh4"]
[Sun Aug 30 03:09:43.870527 2026] [security2:error] [pid 512881:tid 513057] [client 20.104.50.220:59719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/dejavu.php"] [unique_id "apPlRwi65Hcg2zUJjxBPvQAAAkI"]
[Sun Aug 30 03:09:43.876422 2026] [security2:error] [pid 512881:tid 513123] [client 20.220.10.235:36862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/admin.php/csv.php"] [unique_id "apPlRwi65Hcg2zUJjxBPvgAAAoQ"]
[Sun Aug 30 03:09:43.925260 2026] [authz_core:error] [pid 512881:tid 513098] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:43.925538 2026] [authz_core:error] [pid 512881:tid 513098] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:43.932230 2026] [security2:error] [pid 512881:tid 513046] [client 158.23.147.79:56472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/ws.php"] [unique_id "apPlRwi65Hcg2zUJjxBPwgAAAjc"]
[Sun Aug 30 03:09:43.932403 2026] [security2:error] [pid 512881:tid 513055] [client 40.83.93.50:20951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/tflow/min.php"] [unique_id "apPlRwi65Hcg2zUJjxBPwwAAAkA"]
[Sun Aug 30 03:09:43.952204 2026] [security2:error] [pid 512881:tid 513033] [client 68.155.159.216:63256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apPlRwi65Hcg2zUJjxBPxwAAAio"]
[Sun Aug 30 03:09:43.954234 2026] [security2:error] [pid 512881:tid 513078] [client 20.104.49.130:54186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/xa.php"] [unique_id "apPlRwi65Hcg2zUJjxBPyAAAAlc"]
[Sun Aug 30 03:09:43.966179 2026] [security2:error] [pid 512881:tid 513095] [client 164.132.207.73:47448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.207.132.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luxtiny.com"] [uri "/wp-login.php"] [unique_id "apPlRwi65Hcg2zUJjxBPxgAAAmg"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:43.976239 2026] [security2:error] [pid 512881:tid 513075] [client 20.104.50.220:62793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/killer.php"] [unique_id "apPlRwi65Hcg2zUJjxBPzAAAAlQ"]
[Sun Aug 30 03:09:43.984063 2026] [authz_core:error] [pid 512881:tid 513079] [client 66.249.66.40:62048] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:43.984511 2026] [authz_core:error] [pid 512881:tid 513079] [client 66.249.66.40:62048] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:43.994162 2026] [autoindex:error] [pid 512881:tid 513096] [client 52.139.37.240:0] AH01276: Cannot serve directory /home2/callahan/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:09:44.009571 2026] [security2:error] [pid 512881:tid 513042] [client 213.209.159.223:46226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themayorcoffee.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlSAi65Hcg2zUJjxBPzwAAAjM"]
[Sun Aug 30 03:09:44.013239 2026] [security2:error] [pid 512881:tid 513099] [client 20.220.10.235:37119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/admin.php/700.php"] [unique_id "apPlSAi65Hcg2zUJjxBP0AAAAmw"]
[Sun Aug 30 03:09:44.016750 2026] [security2:error] [pid 512881:tid 513097] [client 20.104.50.220:51635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/aaaa.php"] [unique_id "apPlSAi65Hcg2zUJjxBP0QAAAmo"]
[Sun Aug 30 03:09:44.031922 2026] [security2:error] [pid 512881:tid 513080] [client 20.104.50.220:62795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/mari.php"] [unique_id "apPlSAi65Hcg2zUJjxBP0wAAAlk"]
[Sun Aug 30 03:09:44.043322 2026] [authz_core:error] [pid 512881:tid 513133] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:44.043609 2026] [authz_core:error] [pid 512881:tid 513133] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:44.048591 2026] [security2:error] [pid 512881:tid 513019] [client 20.104.18.15:43976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/shiny.php"] [unique_id "apPlSAi65Hcg2zUJjxBP1gAAAhw"]
[Sun Aug 30 03:09:44.053100 2026] [security2:error] [pid 512881:tid 513035] [client 20.48.251.3:13418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/snq.php"] [unique_id "apPlSAi65Hcg2zUJjxBP2AAAAiw"]
[Sun Aug 30 03:09:44.059478 2026] [security2:error] [pid 512881:tid 513136] [client 52.139.37.240:44597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/ws77.php"] [unique_id "apPlSAi65Hcg2zUJjxBP2QAAApE"]
[Sun Aug 30 03:09:44.115457 2026] [core:alert] [pid 512881:tid 513087] [client 186.121.108.159:0] /home3/lordrcan/public_html/.htaccess: without matching section, referer: http://www.lordrcane.com/
[Sun Aug 30 03:09:44.158508 2026] [security2:error] [pid 512881:tid 513122] [client 20.220.10.235:36810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/admin.php/007x.php"] [unique_id "apPlSAi65Hcg2zUJjxBP4gAAAoM"]
[Sun Aug 30 03:09:44.164431 2026] [security2:error] [pid 512881:tid 513024] [client 20.104.18.15:22427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/BDKR28WP.php"] [unique_id "apPlSAi65Hcg2zUJjxBP4wAAAiE"]
[Sun Aug 30 03:09:44.175059 2026] [security2:error] [pid 512881:tid 513045] [client 20.48.251.3:65501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/public/bnn_.php.php"] [unique_id "apPlSAi65Hcg2zUJjxBP5QAAAjY"]
[Sun Aug 30 03:09:44.180811 2026] [security2:error] [pid 512881:tid 513107] [client 20.104.18.15:64864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/BDKR28WP.php"] [unique_id "apPlSAi65Hcg2zUJjxBP5gAAAnQ"]
[Sun Aug 30 03:09:44.181278 2026] [security2:error] [pid 512881:tid 513130] [client 20.104.49.130:63573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/chosen.php"] [unique_id "apPlSAi65Hcg2zUJjxBP5wAAAos"]
[Sun Aug 30 03:09:44.224755 2026] [security2:error] [pid 512881:tid 513026] [client 4.205.62.107:17107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/konfig.php"] [unique_id "apPlSAi65Hcg2zUJjxBP7QAAAiM"]
[Sun Aug 30 03:09:44.257808 2026] [security2:error] [pid 512881:tid 513121] [client 20.48.251.3:6490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/cli_bootstrap.php"] [unique_id "apPlSAi65Hcg2zUJjxBP8QAAAoI"]
[Sun Aug 30 03:09:44.260098 2026] [security2:error] [pid 512881:tid 513067] [client 52.139.37.240:43116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/admin/function.php"] [unique_id "apPlSAi65Hcg2zUJjxBP8gAAAkw"]
[Sun Aug 30 03:09:44.260618 2026] [security2:error] [pid 512881:tid 513064] [client 91.92.42.135:45788] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "pfcleanup.org"] [uri "/wp-content/plugins/give/readme.txt"] [unique_id "apPlSAi65Hcg2zUJjxBP8wAAAkk"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:44.318697 2026] [security2:error] [pid 512881:tid 513052] [client 20.104.50.220:32089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wsd.php"] [unique_id "apPlSAi65Hcg2zUJjxBP-wAAAj0"]
[Sun Aug 30 03:09:44.323548 2026] [security2:error] [pid 512881:tid 513123] [client 20.220.10.235:36994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/admin.php/heex.php"] [unique_id "apPlSAi65Hcg2zUJjxBP_QAAAoQ"]
[Sun Aug 30 03:09:44.348894 2026] [authz_core:error] [pid 512881:tid 513120] [client 66.249.66.35:63066] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:44.349242 2026] [authz_core:error] [pid 512881:tid 513120] [client 66.249.66.35:63066] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:44.364221 2026] [security2:error] [pid 512881:tid 513071] [client 4.205.62.107:36031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/database.php"] [unique_id "apPlSAi65Hcg2zUJjxBQAgAAAlA"]
[Sun Aug 30 03:09:44.414826 2026] [security2:error] [pid 512881:tid 513096] [client 20.104.50.220:33074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/11.php"] [unique_id "apPlSAi65Hcg2zUJjxBQAwAAAmk"]
[Sun Aug 30 03:09:44.418050 2026] [security2:error] [pid 512881:tid 513088] [client 68.155.159.216:52562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-content/themes/too.php"] [unique_id "apPlSAi65Hcg2zUJjxBQBAAAAmE"]
[Sun Aug 30 03:09:44.419536 2026] [security2:error] [pid 512881:tid 513063] [client 114.119.151.9:21099] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.tulsaattorney.pro"] [uri "/Tulsa-lawyer-blog/burglary-tools/"] [unique_id "apPlSAi65Hcg2zUJjxBQBQAAAkg"], referer: https://www.tulsaattorney.pro/Tulsa-lawyer-blog/burglary-tools/
[Sun Aug 30 03:09:44.432906 2026] [security2:error] [pid 512881:tid 513109] [client 40.83.93.50:17954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/tflow/pk.php"] [unique_id "apPlSAi65Hcg2zUJjxBQCQAAAnY"]
[Sun Aug 30 03:09:44.454486 2026] [security2:error] [pid 512881:tid 513095] [client 52.139.37.240:43134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/xx.php"] [unique_id "apPlSAi65Hcg2zUJjxBQDgAAAmg"]
[Sun Aug 30 03:09:44.454975 2026] [authz_core:error] [pid 512881:tid 513097] [client 216.73.216.128:18500] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:44.455249 2026] [authz_core:error] [pid 512881:tid 513097] [client 216.73.216.128:18500] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:44.461290 2026] [security2:error] [pid 512881:tid 513035] [client 213.209.159.223:65292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/web/.env"] [unique_id "apPlSAi65Hcg2zUJjxBQEQAAAiw"]
[Sun Aug 30 03:09:44.465815 2026] [authz_core:error] [pid 512881:tid 513030] [client 66.249.66.198:59055] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:44.466083 2026] [authz_core:error] [pid 512881:tid 513030] [client 66.249.66.198:59055] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:44.477800 2026] [security2:error] [pid 512881:tid 513012] [client 20.220.10.235:36988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/tf.php"] [unique_id "apPlSAi65Hcg2zUJjxBQEwAAAhU"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:44.511580 2026] [authz_core:error] [pid 512881:tid 513025] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:44.511888 2026] [authz_core:error] [pid 512881:tid 513025] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:44.514380 2026] [security2:error] [pid 512881:tid 513037] [client 20.104.50.220:59560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/dosya.php"] [unique_id "apPlSAi65Hcg2zUJjxBQFwAAAi4"]
[Sun Aug 30 03:09:44.540994 2026] [security2:error] [pid 512881:tid 513016] [client 34.100.204.203:34588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/staging/phpinfo.php"] [unique_id "apPlSAi65Hcg2zUJjxBQGAAAAhk"]
[Sun Aug 30 03:09:44.541026 2026] [security2:error] [pid 512881:tid 513106] [client 4.205.62.107:25753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/sys.php"] [unique_id "apPlSAi65Hcg2zUJjxBQGQAAAnM"]
[Sun Aug 30 03:09:44.544507 2026] [security2:error] [pid 512881:tid 513101] [client 158.23.147.79:56477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-includes/css/index.php"] [unique_id "apPlSAi65Hcg2zUJjxBQGgAAAm4"]
[Sun Aug 30 03:09:44.594667 2026] [security2:error] [pid 512881:tid 513024] [client 213.209.159.223:65292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themayorcoffee.com"] [uri "/phpinfo.php3"] [unique_id "apPlSAi65Hcg2zUJjxBQHwAAAiE"]
[Sun Aug 30 03:09:44.604764 2026] [security2:error] [pid 512881:tid 513045] [client 4.205.62.107:61752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/userfuns.php"] [unique_id "apPlSAi65Hcg2zUJjxBQIQAAAjY"]
[Sun Aug 30 03:09:44.613889 2026] [security2:error] [pid 512881:tid 513107] [client 20.220.10.235:36990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/update/da222.php"] [unique_id "apPlSAi65Hcg2zUJjxBQIgAAAnQ"]
[Sun Aug 30 03:09:44.619981 2026] [security2:error] [pid 512881:tid 513077] [client 20.48.250.41:49901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/sbhu.php"] [unique_id "apPlSAi65Hcg2zUJjxBQIwAAAlY"]
[Sun Aug 30 03:09:44.638311 2026] [security2:error] [pid 512881:tid 513074] [client 20.104.18.15:18260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/gulu.php"] [unique_id "apPlSAi65Hcg2zUJjxBQJwAAAlM"]
[Sun Aug 30 03:09:44.647252 2026] [security2:error] [pid 512881:tid 513100] [client 52.139.37.240:13835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/wp-content/about.php"] [unique_id "apPlSAi65Hcg2zUJjxBQKQAAAm0"]
[Sun Aug 30 03:09:44.689768 2026] [security2:error] [pid 512881:tid 513015] [client 20.104.50.220:5926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/got.php"] [unique_id "apPlSAi65Hcg2zUJjxBQLwAAAhg"]
[Sun Aug 30 03:09:44.728911 2026] [security2:error] [pid 512881:tid 513021] [client 20.48.250.41:38895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/zoo.php"] [unique_id "apPlSAi65Hcg2zUJjxBQNwAAAh4"]
[Sun Aug 30 03:09:44.739695 2026] [security2:error] [pid 512881:tid 513018] [client 20.104.18.15:16927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlSAi65Hcg2zUJjxBQOwAAAhs"]
[Sun Aug 30 03:09:44.754953 2026] [security2:error] [pid 512881:tid 513119] [client 20.220.10.235:36854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/qi.php"] [unique_id "apPlSAi65Hcg2zUJjxBQPgAAAoA"]
[Sun Aug 30 03:09:44.858797 2026] [security2:error] [pid 512881:tid 513052] [client 52.139.37.240:13873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/wp-the.php"] [unique_id "apPlSAi65Hcg2zUJjxBQSQAAAj0"]
[Sun Aug 30 03:09:44.902685 2026] [security2:error] [pid 512881:tid 513126] [client 20.220.10.235:36860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/px.php"] [unique_id "apPlSAi65Hcg2zUJjxBQTwAAAoc"]
[Sun Aug 30 03:09:44.904207 2026] [security2:error] [pid 512881:tid 513129] [client 20.48.251.3:59843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/olfclass.php"] [unique_id "apPlSAi65Hcg2zUJjxBQUAAAAoo"]
[Sun Aug 30 03:09:44.913626 2026] [security2:error] [pid 512881:tid 513035] [client 20.104.50.220:16584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/as.php"] [unique_id "apPlSAi65Hcg2zUJjxBQUgAAAiw"]
[Sun Aug 30 03:09:44.914022 2026] [security2:error] [pid 512881:tid 513034] [client 40.83.93.50:21310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/theme-check/theme-check.php"] [unique_id "apPlSAi65Hcg2zUJjxBQUwAAAis"]
[Sun Aug 30 03:09:44.939073 2026] [security2:error] [pid 512881:tid 513080] [client 20.48.251.3:55770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/hiquido.com/index.php"] [unique_id "apPlSAi65Hcg2zUJjxBQXAAAAlk"]
[Sun Aug 30 03:09:44.955327 2026] [security2:error] [pid 512881:tid 513087] [client 20.104.18.15:35193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apPlSAi65Hcg2zUJjxBQXQAAAmA"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:45.010192 2026] [authz_core:error] [pid 512881:tid 513037] [client 66.249.66.38:44832] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:45.010659 2026] [authz_core:error] [pid 512881:tid 513037] [client 66.249.66.38:44832] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:45.012170 2026] [authz_core:error] [pid 512881:tid 513024] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:45.012499 2026] [authz_core:error] [pid 512881:tid 513024] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:45.014081 2026] [security2:error] [pid 512881:tid 513045] [client 20.104.50.220:59376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/aaf.php"] [unique_id "apPlSQi65Hcg2zUJjxBQagAAAjY"]
[Sun Aug 30 03:09:45.046830 2026] [security2:error] [pid 512881:tid 513014] [client 20.220.10.235:37098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/is.php"] [unique_id "apPlSQi65Hcg2zUJjxBQcwAAAhc"]
[Sun Aug 30 03:09:45.052467 2026] [security2:error] [pid 512881:tid 513128] [client 52.139.37.240:44620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/ws81.php"] [unique_id "apPlSQi65Hcg2zUJjxBQdgAAAok"]
[Sun Aug 30 03:09:45.067176 2026] [security2:error] [pid 512881:tid 513083] [client 68.155.159.216:62623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apPlSQi65Hcg2zUJjxBQegAAAlw"]
[Sun Aug 30 03:09:45.070698 2026] [security2:error] [pid 512881:tid 513070] [client 158.23.147.79:57703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apPlSQi65Hcg2zUJjxBQbQAAAk8"]
[Sun Aug 30 03:09:45.074077 2026] [authz_core:error] [pid 512881:tid 513015] [client 66.249.66.203:59555] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:45.074370 2026] [authz_core:error] [pid 512881:tid 513015] [client 66.249.66.203:59555] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:45.136164 2026] [security2:error] [pid 512881:tid 513072] [client 20.104.50.220:29135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/Sh3ll.php"] [unique_id "apPlSQi65Hcg2zUJjxBQiQAAAlE"]
[Sun Aug 30 03:09:45.152732 2026] [security2:error] [pid 512881:tid 513065] [client 20.104.50.220:63527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/cinfo.php"] [unique_id "apPlSQi65Hcg2zUJjxBQjQAAAko"]
[Sun Aug 30 03:09:45.176135 2026] [security2:error] [pid 512881:tid 513051] [client 20.104.50.220:62810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/old-index.php"] [unique_id "apPlSQi65Hcg2zUJjxBQkAAAAjw"]
[Sun Aug 30 03:09:45.178409 2026] [security2:error] [pid 512881:tid 513054] [client 20.220.10.235:36958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/od.php"] [unique_id "apPlSQi65Hcg2zUJjxBQkQAAAj8"]
[Sun Aug 30 03:09:45.187140 2026] [security2:error] [pid 512881:tid 513043] [client 20.48.251.3:60506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/wp-access.php"] [unique_id "apPlSQi65Hcg2zUJjxBQkgAAAjQ"]
[Sun Aug 30 03:09:45.195541 2026] [security2:error] [pid 512881:tid 513033] [client 20.104.18.15:44000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/goods.php"] [unique_id "apPlSQi65Hcg2zUJjxBQkwAAAio"]
[Sun Aug 30 03:09:45.249270 2026] [security2:error] [pid 512881:tid 513068] [client 52.139.37.240:44579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/a1.php"] [unique_id "apPlSQi65Hcg2zUJjxBQnAAAAk0"]
[Sun Aug 30 03:09:45.252167 2026] [security2:error] [pid 512881:tid 513089] [client 20.151.200.44:28652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/ssh3ll.php"] [unique_id "apPlSQi65Hcg2zUJjxBQnQAAAmI"]
[Sun Aug 30 03:09:45.307805 2026] [security2:error] [pid 512881:tid 513088] [client 20.104.18.15:22401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/sf.php"] [unique_id "apPlSQi65Hcg2zUJjxBQowAAAmE"]
[Sun Aug 30 03:09:45.313437 2026] [security2:error] [pid 512881:tid 513063] [client 20.48.251.3:54816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/wsws.php"] [unique_id "apPlSQi65Hcg2zUJjxBQpAAAAkg"]
[Sun Aug 30 03:09:45.323307 2026] [security2:error] [pid 512881:tid 513102] [client 20.104.18.15:16716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/sky.php"] [unique_id "apPlSQi65Hcg2zUJjxBQpQAAAm8"]
[Sun Aug 30 03:09:45.340956 2026] [security2:error] [pid 512881:tid 513025] [client 34.100.204.203:34596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/beta/phpinfo.php"] [unique_id "apPlSQi65Hcg2zUJjxBQpgAAAiI"]
[Sun Aug 30 03:09:45.349141 2026] [security2:error] [pid 512881:tid 513105] [client 20.220.10.235:36824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/wp-the.php"] [unique_id "apPlSQi65Hcg2zUJjxBQqAAAAnI"]
[Sun Aug 30 03:09:45.354724 2026] [security2:error] [pid 512881:tid 513062] [client 4.205.62.107:17106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/paths.php"] [unique_id "apPlSQi65Hcg2zUJjxBQqgAAAkc"]
[Sun Aug 30 03:09:45.361211 2026] [security2:error] [pid 512881:tid 513081] [client 20.151.200.44:41976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/tajj.php"] [unique_id "apPlSQi65Hcg2zUJjxBQqwAAAlo"]
[Sun Aug 30 03:09:45.370233 2026] [authz_core:error] [pid 512881:tid 513117] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:45.370635 2026] [authz_core:error] [pid 512881:tid 513117] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:45.378584 2026] [security2:error] [pid 512881:tid 513029] [client 40.83.93.50:21256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/theme/about.php"] [unique_id "apPlSQi65Hcg2zUJjxBQrQAAAiY"]
[Sun Aug 30 03:09:45.402478 2026] [security2:error] [pid 512881:tid 513086] [client 20.104.49.130:60942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wen.php"] [unique_id "apPlSQi65Hcg2zUJjxBQrgAAAl8"]
[Sun Aug 30 03:09:45.404836 2026] [security2:error] [pid 512881:tid 513055] [client 216.73.216.128:52276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlSQi65Hcg2zUJjxBQrwAAAkA"]
[Sun Aug 30 03:09:45.442058 2026] [security2:error] [pid 512881:tid 513097] [client 52.139.37.240:43123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/ca5.php"] [unique_id "apPlSQi65Hcg2zUJjxBQsQAAAmo"]
[Sun Aug 30 03:09:45.477102 2026] [security2:error] [pid 512881:tid 513083] [client 20.104.50.220:32548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/f6.php"] [unique_id "apPlSQi65Hcg2zUJjxBQuAAAAlw"]
[Sun Aug 30 03:09:45.491279 2026] [security2:error] [pid 512881:tid 513100] [client 20.220.10.235:37107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/wt.php"] [unique_id "apPlSQi65Hcg2zUJjxBQuwAAAm0"]
[Sun Aug 30 03:09:45.492128 2026] [authz_core:error] [pid 512881:tid 513093] [client 216.73.216.128:18500] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:45.492430 2026] [authz_core:error] [pid 512881:tid 513093] [client 216.73.216.128:18500] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:45.493175 2026] [security2:error] [pid 512881:tid 513021] [client 158.23.147.79:57668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-content/cong.php"] [unique_id "apPlSQi65Hcg2zUJjxBQvAAAAh4"]
[Sun Aug 30 03:09:45.505942 2026] [security2:error] [pid 512881:tid 513018] [client 4.205.62.107:36628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/atex1.php"] [unique_id "apPlSQi65Hcg2zUJjxBQvgAAAhs"]
[Sun Aug 30 03:09:45.531569 2026] [authz_core:error] [pid 512881:tid 513121] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:45.532020 2026] [authz_core:error] [pid 512881:tid 513121] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:45.557271 2026] [security2:error] [pid 512881:tid 513017] [client 20.104.50.220:33026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/title.php"] [unique_id "apPlSQi65Hcg2zUJjxBQwwAAAho"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:45.608114 2026] [security2:error] [pid 512881:tid 513129] [client 68.155.159.216:54316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/radio.php"] [unique_id "apPlSQi65Hcg2zUJjxBQ0AAAAoo"]
[Sun Aug 30 03:09:45.626549 2026] [security2:error] [pid 512881:tid 513042] [client 20.220.10.235:36834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/im.php"] [unique_id "apPlSQi65Hcg2zUJjxBQ0QAAAjM"]
[Sun Aug 30 03:09:45.658972 2026] [security2:error] [pid 512881:tid 513041] [client 20.104.50.220:63032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/error.php"] [unique_id "apPlSQi65Hcg2zUJjxBQ0wAAAjI"]
[Sun Aug 30 03:09:45.662051 2026] [security2:error] [pid 512881:tid 513111] [client 52.139.37.240:44596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/install.php"] [unique_id "apPlSQi65Hcg2zUJjxBQ1AAAAng"]
[Sun Aug 30 03:09:45.731408 2026] [security2:error] [pid 512881:tid 513080] [client 4.205.62.107:26947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/phpsysinfo.php"] [unique_id "apPlSQi65Hcg2zUJjxBQ2QAAAlk"]
[Sun Aug 30 03:09:45.765014 2026] [security2:error] [pid 512881:tid 513081] [client 20.220.10.235:37071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/file.php"] [unique_id "apPlSQi65Hcg2zUJjxBQ3QAAAlo"]
[Sun Aug 30 03:09:45.778479 2026] [security2:error] [pid 512881:tid 513106] [client 4.205.62.107:58450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/mamzi.php"] [unique_id "apPlSQi65Hcg2zUJjxBQ3gAAAnM"]
[Sun Aug 30 03:09:45.790871 2026] [authz_core:error] [pid 512881:tid 513087] [client 66.249.66.68:52979] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:45.791140 2026] [authz_core:error] [pid 512881:tid 513087] [client 66.249.66.68:52979] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:45.826235 2026] [security2:error] [pid 512881:tid 513057] [client 20.104.18.15:18347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/replace.php"] [unique_id "apPlSQi65Hcg2zUJjxBQ4QAAAkI"]
[Sun Aug 30 03:09:45.840852 2026] [security2:error] [pid 512881:tid 513137] [client 20.104.50.220:5909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/app.php"] [unique_id "apPlSQi65Hcg2zUJjxBQ4wAAApI"]
[Sun Aug 30 03:09:45.852394 2026] [security2:error] [pid 512881:tid 513113] [client 40.83.93.50:17972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/theme/min.php"] [unique_id "apPlSQi65Hcg2zUJjxBQ5gAAAno"]
[Sun Aug 30 03:09:45.860710 2026] [security2:error] [pid 512881:tid 513130] [client 158.23.147.79:56482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPlSQi65Hcg2zUJjxBQ7AAAAos"]
[Sun Aug 30 03:09:45.862123 2026] [authz_core:error] [pid 512881:tid 513086] [client 66.249.66.202:38031] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:45.862441 2026] [authz_core:error] [pid 512881:tid 513086] [client 66.249.66.202:38031] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:45.893429 2026] [security2:error] [pid 512881:tid 513083] [client 20.48.251.3:7362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/dd.php"] [unique_id "apPlSQi65Hcg2zUJjxBQ8gAAAlw"]
[Sun Aug 30 03:09:45.894945 2026] [security2:error] [pid 512881:tid 513070] [client 20.220.10.235:36832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/ca.php"] [unique_id "apPlSQi65Hcg2zUJjxBQ8wAAAk8"]
[Sun Aug 30 03:09:45.897845 2026] [security2:error] [pid 512881:tid 513128] [client 20.104.18.15:16915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlSQi65Hcg2zUJjxBQ9AAAAok"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:45.931162 2026] [autoindex:error] [pid 512881:tid 513027] [client 52.139.37.240:13867] AH01276: Cannot serve directory /home2/callahan/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:09:45.950553 2026] [authz_core:error] [pid 512881:tid 513015] [client 216.73.216.128:2138] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:45.950884 2026] [authz_core:error] [pid 512881:tid 513015] [client 216.73.216.128:2138] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:45.955886 2026] [security2:error] [pid 512881:tid 513013] [client 20.104.49.130:63531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/ty.php"] [unique_id "apPlSQi65Hcg2zUJjxBQ-wAAAhY"]
[Sun Aug 30 03:09:45.995296 2026] [security2:error] [pid 512881:tid 513072] [client 52.139.37.240:13867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/wp-signin.php"] [unique_id "apPlSQi65Hcg2zUJjxBQ_QAAAlE"]
[Sun Aug 30 03:09:46.035697 2026] [security2:error] [pid 512881:tid 513077] [client 20.220.10.235:37085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/pb.php"] [unique_id "apPlSgi65Hcg2zUJjxBQ_wAAAlY"]
[Sun Aug 30 03:09:46.046062 2026] [security2:error] [pid 512881:tid 513104] [client 20.48.251.3:52228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/gnmlc.php"] [unique_id "apPlSgi65Hcg2zUJjxBRAQAAAnE"]
[Sun Aug 30 03:09:46.053313 2026] [security2:error] [pid 512881:tid 513074] [client 149.57.203.122:43350] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "rampd.co"] [uri "/"] [unique_id "apPlSgi65Hcg2zUJjxBRAwAAAlM"]
[Sun Aug 30 03:09:46.055190 2026] [security2:error] [pid 512881:tid 513019] [client 20.104.50.220:17279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wsd.php"] [unique_id "apPlSgi65Hcg2zUJjxBRBAAAAhw"]
[Sun Aug 30 03:09:46.055230 2026] [authz_core:error] [pid 512881:tid 513067] [client 66.249.66.43:36055] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:46.055677 2026] [authz_core:error] [pid 512881:tid 513067] [client 66.249.66.43:36055] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:46.079518 2026] [security2:error] [pid 512881:tid 513109] [client 20.48.251.3:59363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/ws79.php"] [unique_id "apPlSgi65Hcg2zUJjxBRBwAAAnY"]
[Sun Aug 30 03:09:46.107771 2026] [security2:error] [pid 512881:tid 513134] [client 20.104.18.15:35173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/sao.php"] [unique_id "apPlSgi65Hcg2zUJjxBRCgAAAo8"]
[Sun Aug 30 03:09:46.146631 2026] [security2:error] [pid 512881:tid 513069] [client 34.100.204.203:34608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/uat/phpinfo.php"] [unique_id "apPlSgi65Hcg2zUJjxBRDgAAAk4"]
[Sun Aug 30 03:09:46.150911 2026] [security2:error] [pid 512881:tid 513095] [client 20.104.50.220:59386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/b00869ae6e.php"] [unique_id "apPlSgi65Hcg2zUJjxBRDwAAAmg"]
[Sun Aug 30 03:09:46.164627 2026] [security2:error] [pid 512881:tid 513041] [client 20.220.10.235:36831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/pk.php"] [unique_id "apPlSgi65Hcg2zUJjxBREgAAAjI"]
[Sun Aug 30 03:09:46.170490 2026] [security2:error] [pid 512881:tid 513111] [client 68.155.159.216:62639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-content/languages/about.php"] [unique_id "apPlSgi65Hcg2zUJjxBRFAAAAng"]
[Sun Aug 30 03:09:46.195991 2026] [security2:error] [pid 512881:tid 513049] [client 52.139.37.240:43105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/Ov-Simple1.php"] [unique_id "apPlSgi65Hcg2zUJjxBRFwAAAjo"]
[Sun Aug 30 03:09:46.209442 2026] [authz_core:error] [pid 512881:tid 513080] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:46.209753 2026] [authz_core:error] [pid 512881:tid 513080] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:46.265956 2026] [security2:error] [pid 512881:tid 513093] [client 20.104.50.220:29146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/new.php"] [unique_id "apPlSgi65Hcg2zUJjxBRHAAAAmY"]
[Sun Aug 30 03:09:46.286797 2026] [security2:error] [pid 512881:tid 513103] [client 114.119.138.250:39539] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.fremantlewa.com.au"] [uri "/robots.txt"] [unique_id "apPlSgi65Hcg2zUJjxBRHQAAAnA"], referer: http://www.fremantlewa.com.au/robots.txt
[Sun Aug 30 03:09:46.298423 2026] [security2:error] [pid 512881:tid 513106] [client 20.104.50.220:51586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/newfile.php"] [unique_id "apPlSgi65Hcg2zUJjxBRHwAAAnM"]
[Sun Aug 30 03:09:46.311763 2026] [security2:error] [pid 512881:tid 513029] [client 20.220.10.235:36989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/ft.php"] [unique_id "apPlSgi65Hcg2zUJjxBRIQAAAiY"]
[Sun Aug 30 03:09:46.329075 2026] [security2:error] [pid 512881:tid 513011] [client 20.104.50.220:29580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/ocgi.php"] [unique_id "apPlSgi65Hcg2zUJjxBRIgAAAhQ"]
[Sun Aug 30 03:09:46.333899 2026] [security2:error] [pid 512881:tid 513035] [client 40.83.93.50:21300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/themes/about.php"] [unique_id "apPlSgi65Hcg2zUJjxBRIwAAAiw"]
[Sun Aug 30 03:09:46.340521 2026] [security2:error] [pid 512881:tid 513113] [client 20.104.18.15:43992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/alfa.php"] [unique_id "apPlSgi65Hcg2zUJjxBRJAAAAno"]
[Sun Aug 30 03:09:46.353030 2026] [authz_core:error] [pid 512881:tid 513076] [client 66.249.66.71:60792] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:46.353330 2026] [authz_core:error] [pid 512881:tid 513076] [client 66.249.66.71:60792] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:46.384545 2026] [security2:error] [pid 512881:tid 513083] [client 20.48.251.3:13432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/otuz1.php"] [unique_id "apPlSgi65Hcg2zUJjxBRJwAAAlw"]
[Sun Aug 30 03:09:46.390196 2026] [security2:error] [pid 512881:tid 513036] [client 52.139.37.240:43102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/ftde.php"] [unique_id "apPlSgi65Hcg2zUJjxBRKAAAAi0"]
[Sun Aug 30 03:09:46.408168 2026] [authz_core:error] [pid 512881:tid 513128] [client 66.249.66.198:59055] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:46.408492 2026] [authz_core:error] [pid 512881:tid 513128] [client 66.249.66.198:59055] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:46.446128 2026] [security2:error] [pid 512881:tid 513115] [client 20.104.18.15:22454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/k.php"] [unique_id "apPlSgi65Hcg2zUJjxBRLQAAAnw"]
[Sun Aug 30 03:09:46.451794 2026] [security2:error] [pid 512881:tid 513027] [client 20.48.251.3:65508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/localconf.php"] [unique_id "apPlSgi65Hcg2zUJjxBRLwAAAiQ"]
[Sun Aug 30 03:09:46.454427 2026] [security2:error] [pid 512881:tid 513064] [client 20.220.10.235:36977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/wp-ver.php"] [unique_id "apPlSgi65Hcg2zUJjxBRMQAAAkk"]
[Sun Aug 30 03:09:46.454699 2026] [security2:error] [pid 512881:tid 513100] [client 20.104.18.15:16757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/file5.php"] [unique_id "apPlSgi65Hcg2zUJjxBRMgAAAm0"]
[Sun Aug 30 03:09:46.488240 2026] [security2:error] [pid 512881:tid 513104] [client 20.104.49.130:53866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/ano.php"] [unique_id "apPlSgi65Hcg2zUJjxBROQAAAnE"]
[Sun Aug 30 03:09:46.491952 2026] [security2:error] [pid 512881:tid 513114] [client 4.205.62.107:17109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/olfclass.php"] [unique_id "apPlSgi65Hcg2zUJjxBROwAAAns"]
[Sun Aug 30 03:09:46.591312 2026] [security2:error] [pid 512881:tid 513094] [client 20.220.10.235:36940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/ah24.php"] [unique_id "apPlSgi65Hcg2zUJjxBRSAAAAmc"]
[Sun Aug 30 03:09:46.598672 2026] [security2:error] [pid 512881:tid 513092] [client 52.139.37.240:44555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/hplfuns.php"] [unique_id "apPlSgi65Hcg2zUJjxBRSgAAAmU"]
[Sun Aug 30 03:09:46.602541 2026] [security2:error] [pid 512881:tid 513138] [client 149.57.203.122:43364] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "rampd.co"] [uri "/"] [unique_id "apPlSgi65Hcg2zUJjxBRTQAAApM"]
[Sun Aug 30 03:09:46.609956 2026] [security2:error] [pid 512881:tid 513102] [client 20.104.50.220:31915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/he.php"] [unique_id "apPlSgi65Hcg2zUJjxBRTwAAAm8"]
[Sun Aug 30 03:09:46.645814 2026] [security2:error] [pid 512881:tid 513045] [client 4.205.62.107:36701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/aws_sdk_settings.php"] [unique_id "apPlSgi65Hcg2zUJjxBRVAAAAjY"]
[Sun Aug 30 03:09:46.663754 2026] [security2:error] [pid 512881:tid 513091] [client 20.151.200.44:28548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/motu.php"] [unique_id "apPlSgi65Hcg2zUJjxBRXAAAAmQ"]
[Sun Aug 30 03:09:46.704162 2026] [security2:error] [pid 512881:tid 513020] [client 20.104.50.220:33177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/xmlrpc.php"] [unique_id "apPlSgi65Hcg2zUJjxBRXwAAAh0"]
[Sun Aug 30 03:09:46.722805 2026] [authz_core:error] [pid 512881:tid 513021] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:46.723363 2026] [authz_core:error] [pid 512881:tid 513021] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:46.724538 2026] [security2:error] [pid 512881:tid 513072] [client 216.73.216.128:39188] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/usage_202601.html"] [unique_id "apPlSgi65Hcg2zUJjxBRZgAAAlE"]
[Sun Aug 30 03:09:46.736443 2026] [security2:error] [pid 512881:tid 513022] [client 20.220.10.235:36930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPlSgi65Hcg2zUJjxBRbAAAAh8"]
[Sun Aug 30 03:09:46.760855 2026] [security2:error] [pid 512881:tid 513109] [client 20.104.49.130:63608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/ops.php"] [unique_id "apPlSgi65Hcg2zUJjxBRbwAAAnY"]
[Sun Aug 30 03:09:46.785544 2026] [authz_core:error] [pid 512881:tid 513134] [client 66.249.66.64:61060] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:46.786016 2026] [authz_core:error] [pid 512881:tid 513134] [client 66.249.66.64:61060] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:46.791539 2026] [security2:error] [pid 512881:tid 513032] [client 52.139.37.240:13842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/log.php"] [unique_id "apPlSgi65Hcg2zUJjxBRcgAAAik"]
[Sun Aug 30 03:09:46.799282 2026] [security2:error] [pid 512881:tid 513137] [client 40.83.93.50:17925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/themes/panel.php"] [unique_id "apPlSgi65Hcg2zUJjxBRcwAAApI"]
[Sun Aug 30 03:09:46.819501 2026] [authz_core:error] [pid 512881:tid 513040] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp%2Fparameters
[Sun Aug 30 03:09:46.819824 2026] [authz_core:error] [pid 512881:tid 513040] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp%2Fparameters
[Sun Aug 30 03:09:46.853173 2026] [security2:error] [pid 512881:tid 513044] [client 20.104.50.220:59574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/evil.php"] [unique_id "apPlSgi65Hcg2zUJjxBReAAAAjU"]
[Sun Aug 30 03:09:46.869092 2026] [security2:error] [pid 512881:tid 513053] [client 4.205.62.107:25868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/sgd.php"] [unique_id "apPlSgi65Hcg2zUJjxBRfQAAAj4"]
[Sun Aug 30 03:09:46.891795 2026] [security2:error] [pid 512881:tid 513111] [client 20.220.10.235:36837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.willenjs.com"] [uri "/waf.php"] [unique_id "apPlSgi65Hcg2zUJjxBRfgAAAng"]
[Sun Aug 30 03:09:46.960924 2026] [security2:error] [pid 512881:tid 513138] [client 4.205.62.107:58246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/public/rip.php.php"] [unique_id "apPlSgi65Hcg2zUJjxBRgAAAApM"]
[Sun Aug 30 03:09:46.969444 2026] [security2:error] [pid 512881:tid 513015] [client 20.104.18.15:18251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/c4.php"] [unique_id "apPlSgi65Hcg2zUJjxBRgwAAAhg"]
[Sun Aug 30 03:09:46.975425 2026] [security2:error] [pid 512881:tid 513056] [client 213.209.159.223:58073] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/.env"] [unique_id "apPlSgi65Hcg2zUJjxBRhAAAAkE"]
[Sun Aug 30 03:09:46.999861 2026] [security2:error] [pid 512881:tid 513047] [client 34.100.204.203:34618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/qa/phpinfo.php"] [unique_id "apPlSgi65Hcg2zUJjxBRhQAAAjg"]
[Sun Aug 30 03:09:47.000829 2026] [security2:error] [pid 512881:tid 513088] [client 20.104.50.220:5596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/application.php"] [unique_id "apPlSgi65Hcg2zUJjxBRhgAAAmE"]
[Sun Aug 30 03:09:47.000866 2026] [security2:error] [pid 512881:tid 513049] [client 52.139.37.240:43119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/txets.php"] [unique_id "apPlSwi65Hcg2zUJjxBRhwAAAjo"]
[Sun Aug 30 03:09:47.047998 2026] [security2:error] [pid 512881:tid 513090] [client 68.155.159.216:54288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPlSwi65Hcg2zUJjxBRjAAAAmM"]
[Sun Aug 30 03:09:47.050418 2026] [authz_core:error] [pid 512881:tid 513130] [client 216.73.216.128:2138] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:47.050894 2026] [authz_core:error] [pid 512881:tid 513130] [client 216.73.216.128:2138] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:47.054016 2026] [security2:error] [pid 512881:tid 513133] [client 20.104.18.15:17014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/ap.php"] [unique_id "apPlSwi65Hcg2zUJjxBRjQAAAo4"]
[Sun Aug 30 03:09:47.110788 2026] [security2:error] [pid 512881:tid 513083] [client 213.209.159.223:58073] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/api/.env"] [unique_id "apPlSwi65Hcg2zUJjxBRjwAAAlw"]
[Sun Aug 30 03:09:47.175953 2026] [security2:error] [pid 512881:tid 513100] [client 158.23.147.79:56462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPlSwi65Hcg2zUJjxBRlQAAAm0"]
[Sun Aug 30 03:09:47.180517 2026] [security2:error] [pid 512881:tid 513033] [client 20.48.251.3:59489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/koiy.php"] [unique_id "apPlSwi65Hcg2zUJjxBRlgAAAio"]
[Sun Aug 30 03:09:47.187888 2026] [security2:error] [pid 512881:tid 513072] [client 20.104.50.220:16626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/gtc.php"] [unique_id "apPlSwi65Hcg2zUJjxBRlwAAAlE"]
[Sun Aug 30 03:09:47.201199 2026] [security2:error] [pid 512881:tid 513020] [client 52.139.37.240:44622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/wp-admin.php"] [unique_id "apPlSwi65Hcg2zUJjxBRmQAAAh0"]
[Sun Aug 30 03:09:47.216492 2026] [security2:error] [pid 512881:tid 513037] [client 20.48.251.3:55800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/public/wp-blog.php"] [unique_id "apPlSwi65Hcg2zUJjxBRmgAAAi4"]
[Sun Aug 30 03:09:47.231886 2026] [authz_core:error] [pid 512881:tid 513119] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:47.232371 2026] [authz_core:error] [pid 512881:tid 513119] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:47.245512 2026] [security2:error] [pid 512881:tid 513084] [client 213.209.159.223:58073] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/backend/.env"] [unique_id "apPlSwi65Hcg2zUJjxBRnQAAAl0"]
[Sun Aug 30 03:09:47.247565 2026] [security2:error] [pid 512881:tid 513108] [client 20.104.18.15:35776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/dapa.php"] [unique_id "apPlSwi65Hcg2zUJjxBRngAAAnU"]
[Sun Aug 30 03:09:47.278780 2026] [security2:error] [pid 512881:tid 513065] [client 20.48.251.3:7414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/wp-tem.php"] [unique_id "apPlSwi65Hcg2zUJjxBRogAAAko"]
[Sun Aug 30 03:09:47.280865 2026] [core:error] [pid 512881:tid 513131] [client 40.83.93.50:17936] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:09:47.280882 2026] [core:error] [pid 512881:tid 513131] [client 40.83.93.50:17936] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:09:47.310259 2026] [authz_core:error] [pid 512881:tid 513117] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp%2Fparameters
[Sun Aug 30 03:09:47.310557 2026] [authz_core:error] [pid 512881:tid 513117] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp%2Fparameters
[Sun Aug 30 03:09:47.316360 2026] [security2:error] [pid 512881:tid 513116] [client 20.104.50.220:59336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/term.php"] [unique_id "apPlSwi65Hcg2zUJjxBRpQAAAn0"]
[Sun Aug 30 03:09:47.356493 2026] [security2:error] [pid 512881:tid 513096] [client 68.155.159.216:63240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-content/banners/about.php"] [unique_id "apPlSwi65Hcg2zUJjxBRpgAAAmk"]
[Sun Aug 30 03:09:47.379583 2026] [security2:error] [pid 512881:tid 513025] [client 213.209.159.223:58073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themayorcoffee.com"] [uri "/phpinfo.php"] [unique_id "apPlSwi65Hcg2zUJjxBRqAAAAiI"]
[Sun Aug 30 03:09:47.419799 2026] [security2:error] [pid 512881:tid 513067] [client 20.104.50.220:62832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/Sym.php"] [unique_id "apPlSwi65Hcg2zUJjxBRqwAAAkw"]
[Sun Aug 30 03:09:47.447174 2026] [security2:error] [pid 512881:tid 513076] [client 20.104.50.220:63521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/pro.php"] [unique_id "apPlSwi65Hcg2zUJjxBRrAAAAlU"]
[Sun Aug 30 03:09:47.466526 2026] [autoindex:error] [pid 512881:tid 513110] [client 52.139.37.240:13879] AH01276: Cannot serve directory /home2/callahan/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:09:47.468415 2026] [security2:error] [pid 512881:tid 513023] [client 20.104.50.220:52813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/ngocokpeli.php"] [unique_id "apPlSwi65Hcg2zUJjxBRswAAAiA"]
[Sun Aug 30 03:09:47.500049 2026] [security2:error] [pid 512881:tid 513138] [client 20.104.18.15:44002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/33.php"] [unique_id "apPlSwi65Hcg2zUJjxBRugAAApM"]
[Sun Aug 30 03:09:47.529322 2026] [security2:error] [pid 512881:tid 513120] [client 20.48.251.3:14002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/update.php"] [unique_id "apPlSwi65Hcg2zUJjxBRvwAAAoE"]
[Sun Aug 30 03:09:47.584004 2026] [security2:error] [pid 512881:tid 513133] [client 20.104.18.15:22507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/82.php"] [unique_id "apPlSwi65Hcg2zUJjxBRxQAAAo4"]
[Sun Aug 30 03:09:47.587862 2026] [security2:error] [pid 512881:tid 513129] [client 216.73.216.128:17221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPlSwi65Hcg2zUJjxBRxgAAAoo"]
[Sun Aug 30 03:09:47.599262 2026] [security2:error] [pid 512881:tid 513079] [client 20.48.251.3:65494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/bengi.php"] [unique_id "apPlSwi65Hcg2zUJjxBRygAAAlg"]
[Sun Aug 30 03:09:47.600248 2026] [security2:error] [pid 512881:tid 513106] [client 20.104.18.15:18308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlSwi65Hcg2zUJjxBRywAAAnM"]
[Sun Aug 30 03:09:47.601982 2026] [security2:error] [pid 512881:tid 513038] [client 20.104.18.15:16689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/xyn.php"] [unique_id "apPlSwi65Hcg2zUJjxBRzAAAAi8"]
[Sun Aug 30 03:09:47.610201 2026] [security2:error] [pid 512881:tid 513036] [client 20.104.49.130:45142] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "williamcchittick.com"] [uri "/1.php"] [unique_id "apPlSwi65Hcg2zUJjxBRzQAAAi0"]
[Sun Aug 30 03:09:47.610286 2026] [security2:error] [pid 512881:tid 513036] [client 20.104.49.130:45142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/1.php"] [unique_id "apPlSwi65Hcg2zUJjxBRzQAAAi0"]
[Sun Aug 30 03:09:47.638791 2026] [security2:error] [pid 512881:tid 513052] [client 4.205.62.107:17301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/gnmlc.php"] [unique_id "apPlSwi65Hcg2zUJjxBR0AAAAj0"]
[Sun Aug 30 03:09:47.671188 2026] [security2:error] [pid 512881:tid 513082] [client 20.151.200.44:41953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/bge.php"] [unique_id "apPlSwi65Hcg2zUJjxBR1AAAAls"]
[Sun Aug 30 03:09:47.688390 2026] [authz_core:error] [pid 512881:tid 513077] [client 216.73.216.128:2138] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:47.688698 2026] [authz_core:error] [pid 512881:tid 513077] [client 216.73.216.128:2138] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:47.744697 2026] [authz_core:error] [pid 512881:tid 513025] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:47.744964 2026] [authz_core:error] [pid 512881:tid 513025] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:47.750474 2026] [security2:error] [pid 512881:tid 513041] [client 34.100.204.203:34632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/preview/phpinfo.php"] [unique_id "apPlSwi65Hcg2zUJjxBR3gAAAjI"]
[Sun Aug 30 03:09:47.751754 2026] [security2:error] [pid 512881:tid 513055] [client 40.83.93.50:21255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/twentytwentyfive/styles/sections/pk.php"] [unique_id "apPlSwi65Hcg2zUJjxBR3wAAAkA"]
[Sun Aug 30 03:09:47.779780 2026] [security2:error] [pid 512881:tid 513094] [client 4.205.62.107:36711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/setup-config.php"] [unique_id "apPlSwi65Hcg2zUJjxBR4gAAAmc"]
[Sun Aug 30 03:09:47.801205 2026] [security2:error] [pid 512881:tid 513075] [client 20.104.50.220:31903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/aves.php"] [unique_id "apPlSwi65Hcg2zUJjxBR5gAAAlQ"]
[Sun Aug 30 03:09:47.838268 2026] [authz_core:error] [pid 512881:tid 513050] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp%2Fparameters
[Sun Aug 30 03:09:47.838776 2026] [authz_core:error] [pid 512881:tid 513050] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp%2Fparameters
[Sun Aug 30 03:09:47.844628 2026] [security2:error] [pid 512881:tid 513110] [client 20.104.50.220:33165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/pass.php"] [unique_id "apPlSwi65Hcg2zUJjxBR6AAAAnc"]
[Sun Aug 30 03:09:47.932018 2026] [security2:error] [pid 512881:tid 513045] [client 20.104.49.130:54152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/dk.php"] [unique_id "apPlSwi65Hcg2zUJjxBR9AAAAjY"]
[Sun Aug 30 03:09:48.002921 2026] [security2:error] [pid 512881:tid 513035] [client 4.205.62.107:25759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/fleen.php"] [unique_id "apPlTAi65Hcg2zUJjxBR-wAAAiw"]
[Sun Aug 30 03:09:48.045077 2026] [security2:error] [pid 512881:tid 513089] [client 20.104.50.220:62001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/file.php"] [unique_id "apPlTAi65Hcg2zUJjxBSAQAAAmI"]
[Sun Aug 30 03:09:48.058294 2026] [security2:error] [pid 512881:tid 513060] [client 213.209.159.223:35320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/laravel/.env"] [unique_id "apPlTAi65Hcg2zUJjxBSAgAAAkU"]
[Sun Aug 30 03:09:48.107094 2026] [security2:error] [pid 512881:tid 513051] [client 20.104.18.15:18256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/rxr.php"] [unique_id "apPlTAi65Hcg2zUJjxBSAwAAAjw"]
[Sun Aug 30 03:09:48.112134 2026] [security2:error] [pid 512881:tid 513020] [client 4.205.62.107:58446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/environment.php"] [unique_id "apPlTAi65Hcg2zUJjxBSBAAAAh0"]
[Sun Aug 30 03:09:48.149812 2026] [security2:error] [pid 512881:tid 513108] [client 20.104.50.220:5508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/clown.php"] [unique_id "apPlTAi65Hcg2zUJjxBSCQAAAnU"]
[Sun Aug 30 03:09:48.176822 2026] [security2:error] [pid 512881:tid 513096] [client 52.139.37.240:13879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/wp-config-sample.php"] [unique_id "apPlTAi65Hcg2zUJjxBSDwAAAmk"]
[Sun Aug 30 03:09:48.186985 2026] [security2:error] [pid 512881:tid 513119] [client 20.104.18.15:16928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/media.php"] [unique_id "apPlTAi65Hcg2zUJjxBSEAAAAoA"]
[Sun Aug 30 03:09:48.192143 2026] [security2:error] [pid 512881:tid 513018] [client 213.209.159.223:35320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/core/.env"] [unique_id "apPlTAi65Hcg2zUJjxBSEQAAAhs"]
[Sun Aug 30 03:09:48.212882 2026] [security2:error] [pid 512881:tid 513069] [client 68.155.159.216:54295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/makeasmtp.php"] [unique_id "apPlTAi65Hcg2zUJjxBSFgAAAk4"]
[Sun Aug 30 03:09:48.217193 2026] [authz_core:error] [pid 512881:tid 513055] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:48.217496 2026] [authz_core:error] [pid 512881:tid 513055] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:48.239020 2026] [core:error] [pid 512881:tid 513064] [client 40.83.93.50:17966] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:09:48.239042 2026] [core:error] [pid 512881:tid 513064] [client 40.83.93.50:17966] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:09:48.319194 2026] [security2:error] [pid 512881:tid 513088] [client 20.48.251.3:59507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/w.php"] [unique_id "apPlTAi65Hcg2zUJjxBSHQAAAmE"]
[Sun Aug 30 03:09:48.323932 2026] [security2:error] [pid 512881:tid 513071] [client 20.104.50.220:16749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/atx.php"] [unique_id "apPlTAi65Hcg2zUJjxBSHgAAAlA"]
[Sun Aug 30 03:09:48.350618 2026] [security2:error] [pid 512881:tid 513029] [client 20.48.251.3:59348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/php-details.php"] [unique_id "apPlTAi65Hcg2zUJjxBSIwAAAiY"]
[Sun Aug 30 03:09:48.364934 2026] [authz_core:error] [pid 512881:tid 513137] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp%2Fparameters
[Sun Aug 30 03:09:48.365391 2026] [authz_core:error] [pid 512881:tid 513137] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp%2Fparameters
[Sun Aug 30 03:09:48.370008 2026] [security2:error] [pid 512881:tid 513095] [client 52.139.37.240:44600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "medicaidassistants.com"] [uri "/wp-content/packed.php"] [unique_id "apPlTAi65Hcg2zUJjxBSJwAAAmg"]
[Sun Aug 30 03:09:48.398879 2026] [security2:error] [pid 512881:tid 513113] [client 20.104.18.15:35037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/wp-content/l.php"] [unique_id "apPlTAi65Hcg2zUJjxBSMgAAAno"]
[Sun Aug 30 03:09:48.506511 2026] [security2:error] [pid 512881:tid 513114] [client 20.104.50.220:59727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wander.php"] [unique_id "apPlTAi65Hcg2zUJjxBSRQAAAns"]
[Sun Aug 30 03:09:48.510743 2026] [security2:error] [pid 512881:tid 513119] [client 68.155.159.216:62603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apPlTAi65Hcg2zUJjxBSRwAAAoA"]
[Sun Aug 30 03:09:48.514853 2026] [authz_core:error] [pid 512881:tid 513015] [client 216.73.216.128:9185] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:48.515107 2026] [authz_core:error] [pid 512881:tid 513015] [client 216.73.216.128:9185] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:48.534753 2026] [security2:error] [pid 512881:tid 513018] [client 158.23.147.79:57712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apPlTAi65Hcg2zUJjxBSSAAAAhs"]
[Sun Aug 30 03:09:48.579591 2026] [security2:error] [pid 512881:tid 513053] [client 34.100.204.203:34644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/www/phpinfo.php"] [unique_id "apPlTAi65Hcg2zUJjxBSTgAAAj4"]
[Sun Aug 30 03:09:48.591711 2026] [security2:error] [pid 512881:tid 513064] [client 20.104.50.220:52846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/dom.php"] [unique_id "apPlTAi65Hcg2zUJjxBSUgAAAkk"]
[Sun Aug 30 03:09:48.593018 2026] [security2:error] [pid 512881:tid 513075] [client 20.48.251.3:64499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/txets.php"] [unique_id "apPlTAi65Hcg2zUJjxBSVAAAAlQ"]
[Sun Aug 30 03:09:48.597178 2026] [autoindex:error] [pid 512881:tid 513105] [client 52.139.37.240:0] AH01276: Cannot serve directory /home2/callahan/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:09:48.599342 2026] [security2:error] [pid 512881:tid 513024] [client 213.209.159.223:35320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/app/.env"] [unique_id "apPlTAi65Hcg2zUJjxBSVQAAAiE"]
[Sun Aug 30 03:09:48.600004 2026] [security2:error] [pid 512881:tid 513138] [client 20.104.50.220:51582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/edit.php"] [unique_id "apPlTAi65Hcg2zUJjxBSVwAAApM"]
[Sun Aug 30 03:09:48.605158 2026] [security2:error] [pid 512881:tid 513066] [client 20.104.50.220:62793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/new_license.php"] [unique_id "apPlTAi65Hcg2zUJjxBSWAAAAks"]
[Sun Aug 30 03:09:48.656919 2026] [security2:error] [pid 512881:tid 513120] [client 20.104.18.15:43874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/133.php"] [unique_id "apPlTAi65Hcg2zUJjxBSXgAAAoE"]
[Sun Aug 30 03:09:48.674585 2026] [security2:error] [pid 512881:tid 513076] [client 20.48.251.3:56382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/channels.php"] [unique_id "apPlTAi65Hcg2zUJjxBSYAAAAlU"]
[Sun Aug 30 03:09:48.695217 2026] [security2:error] [pid 512881:tid 513135] [client 216.73.216.128:18500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlTAi65Hcg2zUJjxBSYQAAApA"]
[Sun Aug 30 03:09:48.723171 2026] [security2:error] [pid 512881:tid 513035] [client 20.104.18.15:22520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/dex.php"] [unique_id "apPlTAi65Hcg2zUJjxBSZAAAAiw"]
[Sun Aug 30 03:09:48.725436 2026] [security2:error] [pid 512881:tid 513067] [client 40.83.93.50:17940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/twentytwentythree/patterns/index.php"] [unique_id "apPlTAi65Hcg2zUJjxBSZgAAAkw"]
[Sun Aug 30 03:09:48.733256 2026] [security2:error] [pid 512881:tid 513038] [client 213.209.159.223:35320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/dev/.env"] [unique_id "apPlTAi65Hcg2zUJjxBSaQAAAi8"]
[Sun Aug 30 03:09:48.743100 2026] [authz_core:error] [pid 512881:tid 513036] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:48.743410 2026] [authz_core:error] [pid 512881:tid 513036] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:48.744748 2026] [security2:error] [pid 512881:tid 513090] [client 20.48.251.3:65521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/i.php"] [unique_id "apPlTAi65Hcg2zUJjxBSbAAAAmM"]
[Sun Aug 30 03:09:48.748386 2026] [security2:error] [pid 512881:tid 513060] [client 20.104.18.15:16745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/inso.php"] [unique_id "apPlTAi65Hcg2zUJjxBSbQAAAkU"]
[Sun Aug 30 03:09:48.773215 2026] [security2:error] [pid 512881:tid 513089] [client 4.205.62.107:17094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/koiy.php"] [unique_id "apPlTAi65Hcg2zUJjxBSbgAAAmI"]
[Sun Aug 30 03:09:48.774206 2026] [security2:error] [pid 512881:tid 513108] [client 20.151.200.44:28611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/wefile.php"] [unique_id "apPlTAi65Hcg2zUJjxBSbwAAAnU"]
[Sun Aug 30 03:09:48.777278 2026] [security2:error] [pid 512881:tid 513014] [client 20.104.18.15:18382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlTAi65Hcg2zUJjxBScAAAAhc"]
[Sun Aug 30 03:09:48.840993 2026] [authz_core:error] [pid 512881:tid 513133] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp%2Fparameters
[Sun Aug 30 03:09:48.841280 2026] [authz_core:error] [pid 512881:tid 513133] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp%2Fparameters
[Sun Aug 30 03:09:48.883305 2026] [authz_core:error] [pid 512881:tid 513059] [client 216.73.216.128:9185] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:48.883569 2026] [authz_core:error] [pid 512881:tid 513059] [client 216.73.216.128:9185] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:48.917852 2026] [security2:error] [pid 512881:tid 513075] [client 4.205.62.107:36713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/wp-admin/sc.php"] [unique_id "apPlTAi65Hcg2zUJjxBSewAAAlQ"]
[Sun Aug 30 03:09:48.936859 2026] [security2:error] [pid 512881:tid 513123] [client 20.104.50.220:31881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPlTAi65Hcg2zUJjxBSfwAAAoQ"]
[Sun Aug 30 03:09:48.982920 2026] [security2:error] [pid 512881:tid 513134] [client 20.104.49.130:52433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/av.php"] [unique_id "apPlTAi65Hcg2zUJjxBShgAAAo8"]
[Sun Aug 30 03:09:48.989301 2026] [security2:error] [pid 512881:tid 513021] [client 20.104.50.220:33057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/Cpanel.php"] [unique_id "apPlTAi65Hcg2zUJjxBSigAAAh4"]
[Sun Aug 30 03:09:49.002066 2026] [security2:error] [pid 512881:tid 513117] [client 20.104.49.130:64121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/av.php"] [unique_id "apPlTQi65Hcg2zUJjxBSjAAAAn4"]
[Sun Aug 30 03:09:49.002905 2026] [security2:error] [pid 512881:tid 513103] [client 213.209.159.223:35320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/server/.env"] [unique_id "apPlTQi65Hcg2zUJjxBSiwAAAnA"]
[Sun Aug 30 03:09:49.075087 2026] [authz_core:error] [pid 512881:tid 513034] [client 66.249.66.78:41110] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:49.075381 2026] [authz_core:error] [pid 512881:tid 513034] [client 66.249.66.78:41110] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:49.181641 2026] [security2:error] [pid 512881:tid 513137] [client 4.205.62.107:25882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/upload.form.php"] [unique_id "apPlTQi65Hcg2zUJjxBSsAAAApI"]
[Sun Aug 30 03:09:49.210256 2026] [security2:error] [pid 512881:tid 513069] [client 20.104.50.220:61649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/FoxWSO-full.php"] [unique_id "apPlTQi65Hcg2zUJjxBSsQAAAk4"]
[Sun Aug 30 03:09:49.219489 2026] [core:error] [pid 512881:tid 513042] [client 40.83.93.50:21259] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:09:49.219507 2026] [core:error] [pid 512881:tid 513042] [client 40.83.93.50:21259] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:09:49.239740 2026] [authz_core:error] [pid 512881:tid 513062] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:49.240046 2026] [authz_core:error] [pid 512881:tid 513062] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:49.248238 2026] [security2:error] [pid 512881:tid 513132] [client 74.7.241.185:36136] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "ccsinversiones.com"] [uri "/cgi-sys/404.html"] [unique_id "apPlTQi65Hcg2zUJjxBSuAACjRo"]
[Sun Aug 30 03:09:49.264898 2026] [security2:error] [pid 512881:tid 513068] [client 4.205.62.107:64645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/aws_secret_config.php"] [unique_id "apPlTQi65Hcg2zUJjxBSvAAAAk0"]
[Sun Aug 30 03:09:49.279015 2026] [security2:error] [pid 512881:tid 513100] [client 20.104.18.15:18192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "platinumsnowremoval.johnpauljung.com"] [uri "/reviall.php"] [unique_id "apPlTQi65Hcg2zUJjxBSwAAAAm0"]
[Sun Aug 30 03:09:49.306811 2026] [security2:error] [pid 512881:tid 513078] [client 20.104.50.220:6131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/byp403.php"] [unique_id "apPlTQi65Hcg2zUJjxBSwwAAAlc"]
[Sun Aug 30 03:09:49.320615 2026] [authz_core:error] [pid 512881:tid 513111] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp%2Fparameters
[Sun Aug 30 03:09:49.320942 2026] [authz_core:error] [pid 512881:tid 513111] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp%2Fparameters
[Sun Aug 30 03:09:49.326532 2026] [security2:error] [pid 512881:tid 513106] [client 68.155.159.216:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apPlTQi65Hcg2zUJjxBSxwAAAnM"]
[Sun Aug 30 03:09:49.340511 2026] [security2:error] [pid 512881:tid 513122] [client 20.104.18.15:16924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/adminfuns.php"] [unique_id "apPlTQi65Hcg2zUJjxBSyAAAAoM"]
[Sun Aug 30 03:09:49.350484 2026] [security2:error] [pid 512881:tid 513092] [client 34.100.204.203:34660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/htdocs/phpinfo.php"] [unique_id "apPlTQi65Hcg2zUJjxBSygAAAmU"]
[Sun Aug 30 03:09:49.406509 2026] [security2:error] [pid 512881:tid 513046] [client 213.209.159.223:35320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/staging/.env"] [unique_id "apPlTQi65Hcg2zUJjxBS1wAAAjc"]
[Sun Aug 30 03:09:49.421538 2026] [security2:error] [pid 512881:tid 513032] [client 158.23.147.79:57689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-content/radio.php"] [unique_id "apPlTQi65Hcg2zUJjxBS2gAAAik"]
[Sun Aug 30 03:09:49.455917 2026] [security2:error] [pid 512881:tid 513060] [client 20.48.251.3:59870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/btx25.php"] [unique_id "apPlTQi65Hcg2zUJjxBS4gAAAkU"]
[Sun Aug 30 03:09:49.465930 2026] [security2:error] [pid 512881:tid 513014] [client 20.104.50.220:17247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/z60.php"] [unique_id "apPlTQi65Hcg2zUJjxBS6AAAAhc"]
[Sun Aug 30 03:09:49.490901 2026] [security2:error] [pid 512881:tid 513041] [client 20.48.251.3:59267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/routes.php"] [unique_id "apPlTQi65Hcg2zUJjxBS7AAAAjI"]
[Sun Aug 30 03:09:49.494351 2026] [authz_core:error] [pid 512881:tid 513036] [client 66.249.66.195:59124] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:49.494794 2026] [authz_core:error] [pid 512881:tid 513036] [client 66.249.66.195:59124] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:49.549779 2026] [security2:error] [pid 512881:tid 513115] [client 20.104.18.15:35044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/wp-admin/w.php"] [unique_id "apPlTQi65Hcg2zUJjxBS9QAAAnw"]
[Sun Aug 30 03:09:49.612768 2026] [security2:error] [pid 512881:tid 513059] [client 68.155.159.216:62616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/asd.php"] [unique_id "apPlTQi65Hcg2zUJjxBS-gAAAkQ"]
[Sun Aug 30 03:09:49.645872 2026] [security2:error] [pid 512881:tid 513026] [client 20.104.50.220:59390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/ha.php"] [unique_id "apPlTQi65Hcg2zUJjxBS_wAAAiM"]
[Sun Aug 30 03:09:49.683688 2026] [security2:error] [pid 512881:tid 513040] [client 40.83.93.50:21275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/users.php"] [unique_id "apPlTQi65Hcg2zUJjxBTAwAAAjE"]
[Sun Aug 30 03:09:49.705574 2026] [core:alert] [pid 512881:tid 513035] [client 75.65.104.15:0] /home3/lordrcan/public_html/.htaccess: without matching section
[Sun Aug 30 03:09:49.710345 2026] [authz_core:error] [pid 512881:tid 513087] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:49.710628 2026] [authz_core:error] [pid 512881:tid 513087] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:49.719890 2026] [authz_core:error] [pid 512881:tid 513133] [client 66.249.66.67:44579] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:49.720178 2026] [authz_core:error] [pid 512881:tid 513133] [client 66.249.66.67:44579] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:49.746116 2026] [security2:error] [pid 512881:tid 513089] [client 20.104.50.220:29150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/v4ga.php"] [unique_id "apPlTQi65Hcg2zUJjxBTGQAAAmI"]
[Sun Aug 30 03:09:49.746201 2026] [security2:error] [pid 512881:tid 513099] [client 66.249.66.65:49893] ModSecurity: Access denied with code 400 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "67"] [id "390703"] [rev "5"] [msg "Atomicorp.com WAF Rules: Possible URL Encoding Abuse Attack Attempt"] [severity "NOTICE"] [hostname "www.ltr7.com"] [uri "/"] [unique_id "apPlTQi65Hcg2zUJjxBTFwAAAmw"]
[Sun Aug 30 03:09:49.758515 2026] [security2:error] [pid 512881:tid 513023] [client 20.104.50.220:51638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/11.php"] [unique_id "apPlTQi65Hcg2zUJjxBTGgAAAiA"]
[Sun Aug 30 03:09:49.758989 2026] [security2:error] [pid 512881:tid 513108] [client 20.104.50.220:52837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/miyabajingankoe.php"] [unique_id "apPlTQi65Hcg2zUJjxBTGwAAAnU"]
[Sun Aug 30 03:09:49.786882 2026] [authz_core:error] [pid 512881:tid 513029] [client 66.249.66.36:51886] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:49.787165 2026] [authz_core:error] [pid 512881:tid 513029] [client 66.249.66.36:51886] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:49.821175 2026] [security2:error] [pid 512881:tid 513111] [client 20.48.251.3:56328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/zz.php"] [unique_id "apPlTQi65Hcg2zUJjxBTJAAAAng"]
[Sun Aug 30 03:09:49.823351 2026] [security2:error] [pid 512881:tid 513137] [client 20.104.18.15:44012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/sym.php"] [unique_id "apPlTQi65Hcg2zUJjxBTJQAAApI"]
[Sun Aug 30 03:09:49.835958 2026] [security2:error] [pid 512881:tid 513043] [client 20.48.251.3:64405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/time.php"] [unique_id "apPlTQi65Hcg2zUJjxBTJwAAAjQ"]
[Sun Aug 30 03:09:49.838735 2026] [authz_core:error] [pid 512881:tid 513117] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp%2Fparameters
[Sun Aug 30 03:09:49.838998 2026] [authz_core:error] [pid 512881:tid 513117] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp%2Fparameters
[Sun Aug 30 03:09:49.861040 2026] [security2:error] [pid 512881:tid 513123] [client 20.104.18.15:22488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/inso.php"] [unique_id "apPlTQi65Hcg2zUJjxBTKwAAAoQ"]
[Sun Aug 30 03:09:49.887447 2026] [security2:error] [pid 512881:tid 513134] [client 20.104.18.15:64880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/puc.php"] [unique_id "apPlTQi65Hcg2zUJjxBTMgAAAo8"]
[Sun Aug 30 03:09:49.899407 2026] [authz_core:error] [pid 512881:tid 513119] [client 66.249.66.68:61780] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:49.899856 2026] [authz_core:error] [pid 512881:tid 513119] [client 66.249.66.68:61780] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:49.903967 2026] [authz_core:error] [pid 512881:tid 513126] [client 216.73.216.128:44605] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:49.904244 2026] [authz_core:error] [pid 512881:tid 513126] [client 216.73.216.128:44605] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:49.913005 2026] [security2:error] [pid 512881:tid 513095] [client 4.205.62.107:17115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/w.php"] [unique_id "apPlTQi65Hcg2zUJjxBTNQAAAmg"]
[Sun Aug 30 03:09:49.964491 2026] [security2:error] [pid 512881:tid 513079] [client 20.104.18.15:18373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/ap.php"] [unique_id "apPlTQi65Hcg2zUJjxBTQAAAAlg"]
[Sun Aug 30 03:09:49.994951 2026] [security2:error] [pid 512881:tid 513034] [client 20.151.200.44:41960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/ssh3ll.php"] [unique_id "apPlTQi65Hcg2zUJjxBTSgAAAis"]
[Sun Aug 30 03:09:50.067627 2026] [security2:error] [pid 512881:tid 513049] [client 20.48.251.3:64271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/guk.php"] [unique_id "apPlTgi65Hcg2zUJjxBTVQAAAjo"]
[Sun Aug 30 03:09:50.073298 2026] [security2:error] [pid 512881:tid 513042] [client 4.205.62.107:36562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/debug.php"] [unique_id "apPlTgi65Hcg2zUJjxBTWAAAAjM"]
[Sun Aug 30 03:09:50.078833 2026] [security2:error] [pid 512881:tid 513087] [client 216.73.216.128:44605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlTgi65Hcg2zUJjxBTWQAAAmA"]
[Sun Aug 30 03:09:50.087492 2026] [security2:error] [pid 512881:tid 513036] [client 213.209.159.223:35320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/source/.env"] [unique_id "apPlTgi65Hcg2zUJjxBTWwAAAi0"]
[Sun Aug 30 03:09:50.101758 2026] [security2:error] [pid 512881:tid 513083] [client 34.100.204.203:34676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/public_html/phpinfo.php"] [unique_id "apPlTgi65Hcg2zUJjxBTXAAAAlw"]
[Sun Aug 30 03:09:50.119777 2026] [security2:error] [pid 512881:tid 513024] [client 20.104.50.220:32554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/gorila.php"] [unique_id "apPlTgi65Hcg2zUJjxBTXQAAAiE"]
[Sun Aug 30 03:09:50.120692 2026] [security2:error] [pid 512881:tid 513086] [client 20.104.50.220:33289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/unknown.php"] [unique_id "apPlTgi65Hcg2zUJjxBTXgAAAl8"]
[Sun Aug 30 03:09:50.137468 2026] [authz_core:error] [pid 512881:tid 513066] [client 66.249.66.193:50108] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:50.137782 2026] [authz_core:error] [pid 512881:tid 513066] [client 66.249.66.193:50108] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:50.181456 2026] [security2:error] [pid 512881:tid 513109] [client 40.83.93.50:21266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/wp-cron.php"] [unique_id "apPlTgi65Hcg2zUJjxBTZgAAAnY"]
[Sun Aug 30 03:09:50.229371 2026] [security2:error] [pid 512881:tid 513079] [client 158.23.147.79:2042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apPlTgi65Hcg2zUJjxBTcQAAAlg"]
[Sun Aug 30 03:09:50.243359 2026] [authz_core:error] [pid 512881:tid 513107] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:50.243630 2026] [authz_core:error] [pid 512881:tid 513107] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:50.264235 2026] [authz_core:error] [pid 512881:tid 513110] [client 66.249.66.78:43877] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:50.264539 2026] [authz_core:error] [pid 512881:tid 513110] [client 66.249.66.78:43877] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:50.336887 2026] [security2:error] [pid 512881:tid 513050] [client 4.205.62.107:25484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/aws_auth.php"] [unique_id "apPlTgi65Hcg2zUJjxBTewAAAjs"]
[Sun Aug 30 03:09:50.350207 2026] [security2:error] [pid 512881:tid 513128] [client 20.151.200.44:28560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/Contrller.php"] [unique_id "apPlTgi65Hcg2zUJjxBTfQAAAok"]
[Sun Aug 30 03:09:50.354029 2026] [authz_core:error] [pid 512881:tid 513044] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp%2Fparameters
[Sun Aug 30 03:09:50.354299 2026] [authz_core:error] [pid 512881:tid 513044] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp%2Fparameters
[Sun Aug 30 03:09:50.357242 2026] [security2:error] [pid 512881:tid 513032] [client 213.209.159.223:35320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/framework/.env"] [unique_id "apPlTgi65Hcg2zUJjxBTfwAAAik"]
[Sun Aug 30 03:09:50.384603 2026] [security2:error] [pid 512881:tid 513060] [client 20.104.50.220:59544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/FoxWSO.php"] [unique_id "apPlTgi65Hcg2zUJjxBThAAAAkU"]
[Sun Aug 30 03:09:50.398128 2026] [security2:error] [pid 512881:tid 513122] [client 4.205.62.107:61731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/snq.php"] [unique_id "apPlTgi65Hcg2zUJjxBTjQAAAoM"]
[Sun Aug 30 03:09:50.433598 2026] [security2:error] [pid 512881:tid 513087] [client 68.155.159.216:52587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apPlTgi65Hcg2zUJjxBTkQAAAmA"]
[Sun Aug 30 03:09:50.457756 2026] [security2:error] [pid 512881:tid 513083] [client 20.104.50.220:5577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/green.php"] [unique_id "apPlTgi65Hcg2zUJjxBTlQAAAlw"]
[Sun Aug 30 03:09:50.491582 2026] [authz_core:error] [pid 512881:tid 513042] [client 66.249.66.72:58034] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:50.491902 2026] [security2:error] [pid 512881:tid 513134] [client 213.209.159.223:35320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/ikiwiki/.env"] [unique_id "apPlTgi65Hcg2zUJjxBTnAAAAo8"]
[Sun Aug 30 03:09:50.492000 2026] [authz_core:error] [pid 512881:tid 513042] [client 66.249.66.72:58034] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:50.506431 2026] [security2:error] [pid 512881:tid 513043] [client 20.104.18.15:16930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/classwithtostring.php"] [unique_id "apPlTgi65Hcg2zUJjxBTnwAAAjQ"]
[Sun Aug 30 03:09:50.517948 2026] [security2:error] [pid 512881:tid 513097] [client 158.23.147.79:57705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/login.php"] [unique_id "apPlTgi65Hcg2zUJjxBToQAAAmo"]
[Sun Aug 30 03:09:50.597995 2026] [security2:error] [pid 512881:tid 513029] [client 20.104.50.220:17245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/403.php"] [unique_id "apPlTgi65Hcg2zUJjxBTsAAAAiY"]
[Sun Aug 30 03:09:50.599364 2026] [security2:error] [pid 512881:tid 513047] [client 20.48.251.3:59898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/app_dev.php"] [unique_id "apPlTgi65Hcg2zUJjxBTsQAAAjg"]
[Sun Aug 30 03:09:50.625627 2026] [security2:error] [pid 512881:tid 513107] [client 213.209.159.223:35320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themayorcoffee.com"] [uri "/config.inc.php"] [unique_id "apPlTgi65Hcg2zUJjxBTtgAAAnQ"]
[Sun Aug 30 03:09:50.629894 2026] [security2:error] [pid 512881:tid 513089] [client 216.73.216.128:40790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlTgi65Hcg2zUJjxBTuAAAAmI"]
[Sun Aug 30 03:09:50.630926 2026] [security2:error] [pid 512881:tid 513132] [client 66.249.66.70:56724] ModSecurity: Access denied with code 400 (phase 2). Invalid URL Encoding: Not enough characters at the end of input at REQUEST_URI. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "67"] [id "390703"] [rev "5"] [msg "Atomicorp.com WAF Rules: Possible URL Encoding Abuse Attack Attempt"] [severity "NOTICE"] [hostname "www.ltr7.com"] [uri "/"] [unique_id "apPlTgi65Hcg2zUJjxBTuQAAAo0"]
[Sun Aug 30 03:09:50.639080 2026] [security2:error] [pid 512881:tid 513055] [client 20.104.49.130:63496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/txets.php"] [unique_id "apPlTgi65Hcg2zUJjxBTugAAAkA"]
[Sun Aug 30 03:09:50.640105 2026] [security2:error] [pid 512881:tid 513126] [client 20.48.251.3:59306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/aww.php"] [unique_id "apPlTgi65Hcg2zUJjxBTuwAAAoc"]
[Sun Aug 30 03:09:50.663087 2026] [security2:error] [pid 512881:tid 513115] [client 40.83.93.50:17971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/wp-links-opml.php"] [unique_id "apPlTgi65Hcg2zUJjxBTvwAAAnw"]
[Sun Aug 30 03:09:50.676807 2026] [security2:error] [pid 512881:tid 513114] [client 20.104.49.130:63513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/m.php"] [unique_id "apPlTgi65Hcg2zUJjxBTwwAAAns"]
[Sun Aug 30 03:09:50.689318 2026] [security2:error] [pid 512881:tid 513137] [client 20.104.18.15:35465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/wp-content/k.php"] [unique_id "apPlTgi65Hcg2zUJjxBTxAAAApI"]
[Sun Aug 30 03:09:50.722325 2026] [security2:error] [pid 512881:tid 513053] [client 68.155.159.216:62618] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.allforlearn.com"] [uri "/1.php"] [unique_id "apPlTgi65Hcg2zUJjxBTygAAAj4"]
[Sun Aug 30 03:09:50.722417 2026] [security2:error] [pid 512881:tid 513053] [client 68.155.159.216:62618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/1.php"] [unique_id "apPlTgi65Hcg2zUJjxBTygAAAj4"]
[Sun Aug 30 03:09:50.741943 2026] [authz_core:error] [pid 512881:tid 513076] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:50.742238 2026] [authz_core:error] [pid 512881:tid 513076] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:50.761515 2026] [security2:error] [pid 512881:tid 513020] [client 20.48.250.41:44864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/rtx.php"] [unique_id "apPlTgi65Hcg2zUJjxBT0wAAAh0"]
[Sun Aug 30 03:09:50.768881 2026] [security2:error] [pid 512881:tid 513044] [client 20.104.49.130:57528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/wen.php"] [unique_id "apPlTgi65Hcg2zUJjxBT1AAAAjU"]
[Sun Aug 30 03:09:50.782451 2026] [security2:error] [pid 512881:tid 513085] [client 20.104.50.220:59717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/hur.php"] [unique_id "apPlTgi65Hcg2zUJjxBT2AAAAl4"]
[Sun Aug 30 03:09:50.803876 2026] [security2:error] [pid 512881:tid 513013] [client 20.48.250.41:26605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/init.php"] [unique_id "apPlTgi65Hcg2zUJjxBT2QAAAhY"]
[Sun Aug 30 03:09:50.826365 2026] [security2:error] [pid 512881:tid 513092] [client 34.100.204.203:34688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/site/phpinfo.php"] [unique_id "apPlTgi65Hcg2zUJjxBT3QAAAmU"]
[Sun Aug 30 03:09:50.831068 2026] [authz_core:error] [pid 512881:tid 513056] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:50.831486 2026] [authz_core:error] [pid 512881:tid 513056] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:50.896614 2026] [security2:error] [pid 512881:tid 513081] [client 20.104.50.220:62811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/s3c.php"] [unique_id "apPlTgi65Hcg2zUJjxBT6AAAAlo"]
[Sun Aug 30 03:09:50.902610 2026] [security2:error] [pid 512881:tid 513130] [client 20.104.49.130:43777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/666.php"] [unique_id "apPlTgi65Hcg2zUJjxBT6QAAAos"]
[Sun Aug 30 03:09:50.906281 2026] [security2:error] [pid 512881:tid 513025] [client 20.104.50.220:63535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/title.php"] [unique_id "apPlTgi65Hcg2zUJjxBT6wAAAiI"]
[Sun Aug 30 03:09:50.917590 2026] [security2:error] [pid 512881:tid 513125] [client 20.48.250.41:44948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/ckk.php"] [unique_id "apPlTgi65Hcg2zUJjxBT7AAAAoY"]
[Sun Aug 30 03:09:50.924894 2026] [security2:error] [pid 512881:tid 513012] [client 20.104.50.220:28699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/done.php"] [unique_id "apPlTgi65Hcg2zUJjxBT7QAAAhU"]
[Sun Aug 30 03:09:50.954228 2026] [authz_core:error] [pid 512881:tid 513122] [client 66.249.66.73:47892] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:50.954482 2026] [authz_core:error] [pid 512881:tid 513122] [client 66.249.66.73:47892] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:50.960522 2026] [security2:error] [pid 512881:tid 513053] [client 20.48.251.3:13390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/test.php"] [unique_id "apPlTgi65Hcg2zUJjxBT-gAAAj4"]
[Sun Aug 30 03:09:50.966571 2026] [security2:error] [pid 512881:tid 513038] [client 20.48.250.41:26554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/term.php"] [unique_id "apPlTgi65Hcg2zUJjxBT_QAAAi8"]
[Sun Aug 30 03:09:50.968132 2026] [authz_core:error] [pid 512881:tid 513018] [client 66.249.66.206:54205] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:50.968472 2026] [authz_core:error] [pid 512881:tid 513018] [client 66.249.66.206:54205] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:50.984070 2026] [security2:error] [pid 512881:tid 513045] [client 20.104.18.15:43972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/8.php"] [unique_id "apPlTgi65Hcg2zUJjxBUAgAAAjY"]
[Sun Aug 30 03:09:50.995474 2026] [security2:error] [pid 512881:tid 513057] [client 216.73.216.128:2138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPlTgi65Hcg2zUJjxBUBAAAAkI"]
[Sun Aug 30 03:09:51.001020 2026] [security2:error] [pid 512881:tid 513101] [client 20.104.18.15:22408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/aa.php"] [unique_id "apPlTwi65Hcg2zUJjxBUBQAAAm4"]
[Sun Aug 30 03:09:51.023911 2026] [security2:error] [pid 512881:tid 513116] [client 20.104.18.15:16681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/19.php"] [unique_id "apPlTwi65Hcg2zUJjxBUCgAAAn0"]
[Sun Aug 30 03:09:51.029805 2026] [security2:error] [pid 512881:tid 513126] [client 213.209.159.223:64856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/system/.env"] [unique_id "apPlTwi65Hcg2zUJjxBUCwAAAoc"]
[Sun Aug 30 03:09:51.046757 2026] [security2:error] [pid 512881:tid 513047] [client 4.205.62.107:17303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/btx25.php"] [unique_id "apPlTwi65Hcg2zUJjxBUDwAAAjg"]
[Sun Aug 30 03:09:51.061603 2026] [security2:error] [pid 512881:tid 513079] [client 20.48.250.41:44866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mediacoalitionfoundation.org"] [uri "/R57.php"] [unique_id "apPlTwi65Hcg2zUJjxBUFgAAAlg"]
[Sun Aug 30 03:09:51.126983 2026] [security2:error] [pid 512881:tid 513043] [client 40.83.93.50:21309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/wp-load.php"] [unique_id "apPlTwi65Hcg2zUJjxBUGgAAAjQ"]
[Sun Aug 30 03:09:51.145316 2026] [security2:error] [pid 512881:tid 513131] [client 20.104.18.15:18416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/media.php"] [unique_id "apPlTwi65Hcg2zUJjxBUHgAAAow"]
[Sun Aug 30 03:09:51.162634 2026] [security2:error] [pid 512881:tid 513027] [client 213.209.159.223:64856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "themayorcoffee.com"] [uri "/wp-config.php.backup"] [unique_id "apPlTwi65Hcg2zUJjxBUJAAAAiQ"]
[Sun Aug 30 03:09:51.204461 2026] [security2:error] [pid 512881:tid 513101] [client 20.48.250.41:26375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/aaa.php"] [unique_id "apPlTwi65Hcg2zUJjxBUOAAAAm4"]
[Sun Aug 30 03:09:51.226420 2026] [authz_core:error] [pid 512881:tid 513116] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:51.226723 2026] [authz_core:error] [pid 512881:tid 513116] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:51.248217 2026] [authz_core:error] [pid 512881:tid 513103] [client 66.249.66.73:63187] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:51.248509 2026] [authz_core:error] [pid 512881:tid 513103] [client 66.249.66.73:63187] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:51.260991 2026] [security2:error] [pid 512881:tid 513047] [client 4.205.62.107:36680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/nzv.php"] [unique_id "apPlTwi65Hcg2zUJjxBURgAAAjg"]
[Sun Aug 30 03:09:51.268343 2026] [authz_core:error] [pid 512881:tid 513042] [client 66.249.66.32:46756] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:51.268891 2026] [authz_core:error] [pid 512881:tid 513042] [client 66.249.66.32:46756] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:51.270129 2026] [security2:error] [pid 512881:tid 513076] [client 20.104.50.220:33536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/sel.php"] [unique_id "apPlTwi65Hcg2zUJjxBUSgAAAlU"]
[Sun Aug 30 03:09:51.290614 2026] [security2:error] [pid 512881:tid 513120] [client 20.104.50.220:31816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/vanta.php"] [unique_id "apPlTwi65Hcg2zUJjxBUTgAAAoE"]
[Sun Aug 30 03:09:51.295568 2026] [security2:error] [pid 512881:tid 513050] [client 20.104.49.130:35620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/wp.php"] [unique_id "apPlTwi65Hcg2zUJjxBUTwAAAjs"]
[Sun Aug 30 03:09:51.336347 2026] [security2:error] [pid 512881:tid 513115] [client 20.48.250.41:26521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/xsox.php"] [unique_id "apPlTwi65Hcg2zUJjxBUUgAAAnw"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:51.399441 2026] [security2:error] [pid 512881:tid 513112] [client 20.48.251.3:65498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/config_dev.php"] [unique_id "apPlTwi65Hcg2zUJjxBUYgAAAnk"]
[Sun Aug 30 03:09:51.451236 2026] [security2:error] [pid 512881:tid 513117] [client 20.48.251.3:64463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/doc.php"] [unique_id "apPlTwi65Hcg2zUJjxBUZwAAAn4"]
[Sun Aug 30 03:09:51.455259 2026] [security2:error] [pid 512881:tid 513020] [client 216.73.216.128:39188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlTwi65Hcg2zUJjxBUaQAAAh0"]
[Sun Aug 30 03:09:51.478617 2026] [security2:error] [pid 512881:tid 513074] [client 4.205.62.107:26962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/hiquido.com/index.php"] [unique_id "apPlTwi65Hcg2zUJjxBUdAAAAlM"]
[Sun Aug 30 03:09:51.490827 2026] [security2:error] [pid 512881:tid 513060] [client 20.48.250.41:26570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/lkui.php"] [unique_id "apPlTwi65Hcg2zUJjxBUdQAAAkU"]
[Sun Aug 30 03:09:51.509720 2026] [security2:error] [pid 512881:tid 513072] [client 158.23.147.79:56463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/hehehehe.php"] [unique_id "apPlTwi65Hcg2zUJjxBUeQAAAlE"]
[Sun Aug 30 03:09:51.520417 2026] [security2:error] [pid 512881:tid 513066] [client 20.104.50.220:61966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/foxwso.php"] [unique_id "apPlTwi65Hcg2zUJjxBUewAAAks"]
[Sun Aug 30 03:09:51.539529 2026] [security2:error] [pid 512881:tid 513030] [client 68.155.159.216:54278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-content/languages/about.php"] [unique_id "apPlTwi65Hcg2zUJjxBUfwAAAic"]
[Sun Aug 30 03:09:51.542050 2026] [security2:error] [pid 512881:tid 513116] [client 4.205.62.107:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/wp-access.php"] [unique_id "apPlTwi65Hcg2zUJjxBUgAAAAn0"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:51.590740 2026] [security2:error] [pid 512881:tid 513041] [client 34.100.204.203:34700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/docs/phpinfo.php"] [unique_id "apPlTwi65Hcg2zUJjxBUiwAAAjI"]
[Sun Aug 30 03:09:51.609024 2026] [security2:error] [pid 512881:tid 513088] [client 40.83.93.50:17941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/wp-settings.php"] [unique_id "apPlTwi65Hcg2zUJjxBUkQAAAmE"]
[Sun Aug 30 03:09:51.609492 2026] [security2:error] [pid 512881:tid 513048] [client 20.104.50.220:6083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/fm.php"] [unique_id "apPlTwi65Hcg2zUJjxBUlAAAAjk"]
[Sun Aug 30 03:09:51.681401 2026] [security2:error] [pid 512881:tid 513059] [client 20.48.250.41:26593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apPlTwi65Hcg2zUJjxBUoQAAAkQ"]
[Sun Aug 30 03:09:51.688936 2026] [security2:error] [pid 512881:tid 513138] [client 20.104.49.130:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/kj.php"] [unique_id "apPlTwi65Hcg2zUJjxBUowAAApM"]
[Sun Aug 30 03:09:51.689384 2026] [security2:error] [pid 512881:tid 513076] [client 20.104.18.15:17009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPlTwi65Hcg2zUJjxBUpAAAAlU"]
[Sun Aug 30 03:09:51.735374 2026] [security2:error] [pid 512881:tid 513116] [client 20.104.50.220:17262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/m.php"] [unique_id "apPlTwi65Hcg2zUJjxBUrwAAAn0"]
[Sun Aug 30 03:09:51.741875 2026] [security2:error] [pid 512881:tid 513012] [client 20.48.251.3:59515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/php-info.php"] [unique_id "apPlTwi65Hcg2zUJjxBUsQAAAhU"]
[Sun Aug 30 03:09:51.749054 2026] [authz_core:error] [pid 512881:tid 513051] [client 66.249.66.76:41034] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:51.749388 2026] [authz_core:error] [pid 512881:tid 513051] [client 66.249.66.76:41034] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:51.760161 2026] [authz_core:error] [pid 512881:tid 513016] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:51.760483 2026] [authz_core:error] [pid 512881:tid 513016] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:51.777901 2026] [security2:error] [pid 512881:tid 513127] [client 20.48.250.41:49799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/a332.php"] [unique_id "apPlTwi65Hcg2zUJjxBUuAAAAog"]
[Sun Aug 30 03:09:51.782964 2026] [security2:error] [pid 512881:tid 513041] [client 20.48.251.3:55807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/maxro.php"] [unique_id "apPlTwi65Hcg2zUJjxBUugAAAjI"]
[Sun Aug 30 03:09:51.828866 2026] [security2:error] [pid 512881:tid 513046] [client 20.104.18.15:35182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/os.php"] [unique_id "apPlTwi65Hcg2zUJjxBUyAAAAjc"]
[Sun Aug 30 03:09:51.845843 2026] [security2:error] [pid 512881:tid 513107] [client 20.48.250.41:26548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/motu.php"] [unique_id "apPlTwi65Hcg2zUJjxBUzAAAAnQ"]
[Sun Aug 30 03:09:51.857163 2026] [security2:error] [pid 512881:tid 513076] [client 68.155.159.216:62624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/ws.php"] [unique_id "apPlTwi65Hcg2zUJjxBU0QAAAlU"]
[Sun Aug 30 03:09:51.871032 2026] [security2:error] [pid 512881:tid 513120] [client 20.104.49.130:52429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/sym.php"] [unique_id "apPlTwi65Hcg2zUJjxBU2AAAAoE"]
[Sun Aug 30 03:09:51.908168 2026] [security2:error] [pid 512881:tid 513020] [client 20.48.250.41:38876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/elp.php"] [unique_id "apPlTwi65Hcg2zUJjxBU4QAAAh0"]
[Sun Aug 30 03:09:51.908174 2026] [security2:error] [pid 512881:tid 513055] [client 20.48.250.41:49870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/ws66.php"] [unique_id "apPlTwi65Hcg2zUJjxBU4gAAAkA"]
[Sun Aug 30 03:09:51.937348 2026] [security2:error] [pid 512881:tid 513032] [client 20.104.50.220:59356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/2222.php"] [unique_id "apPlTwi65Hcg2zUJjxBU6wAAAik"]
[Sun Aug 30 03:09:51.940119 2026] [authz_core:error] [pid 512881:tid 513095] [client 66.249.66.74:56612] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:51.940633 2026] [authz_core:error] [pid 512881:tid 513095] [client 66.249.66.74:56612] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:51.974387 2026] [autoindex:error] [pid 512881:tid 513110] [client 158.23.184.117:19073] AH01276: Cannot serve directory /home4/belgrade/public_html/glamalot.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:09:51.976890 2026] [security2:error] [pid 512881:tid 513120] [client 213.209.159.223:38549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themayorcoffee.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlTwi65Hcg2zUJjxBU-QAAAoE"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:52.039364 2026] [security2:error] [pid 512881:tid 513050] [client 20.104.50.220:28679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/madspotshell.php"] [unique_id "apPlUAi65Hcg2zUJjxBVBwAAAjs"]
[Sun Aug 30 03:09:52.044203 2026] [security2:error] [pid 512881:tid 513103] [client 20.104.50.220:42450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/xmlrpc.php"] [unique_id "apPlUAi65Hcg2zUJjxBVCQAAAnA"]
[Sun Aug 30 03:09:52.053481 2026] [security2:error] [pid 512881:tid 513043] [client 20.48.250.41:49826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/ws68.php"] [unique_id "apPlUAi65Hcg2zUJjxBVDQAAAjQ"]
[Sun Aug 30 03:09:52.066423 2026] [security2:error] [pid 512881:tid 513020] [client 20.48.250.41:38894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/666.php"] [unique_id "apPlUAi65Hcg2zUJjxBVDwAAAh0"]
[Sun Aug 30 03:09:52.066441 2026] [security2:error] [pid 512881:tid 513055] [client 20.104.50.220:64453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/eviltwin.php"] [unique_id "apPlUAi65Hcg2zUJjxBVEAAAAkA"]
[Sun Aug 30 03:09:52.079016 2026] [security2:error] [pid 512881:tid 513134] [client 40.83.93.50:17280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/themes/wp-signup.php"] [unique_id "apPlUAi65Hcg2zUJjxBVFAAAAo8"]
[Sun Aug 30 03:09:52.103244 2026] [security2:error] [pid 512881:tid 513067] [client 20.48.251.3:56321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/cloud.php"] [unique_id "apPlUAi65Hcg2zUJjxBVFwAAAkw"]
[Sun Aug 30 03:09:52.120875 2026] [security2:error] [pid 512881:tid 513138] [client 20.48.250.41:26557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/Ov-Simple1.php"] [unique_id "apPlUAi65Hcg2zUJjxBVGQAAApM"]
[Sun Aug 30 03:09:52.125500 2026] [security2:error] [pid 512881:tid 513033] [client 20.104.18.15:43961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/goods.php"] [unique_id "apPlUAi65Hcg2zUJjxBVGgAAAio"]
[Sun Aug 30 03:09:52.144186 2026] [security2:error] [pid 512881:tid 513117] [client 20.104.18.15:22430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/img.php"] [unique_id "apPlUAi65Hcg2zUJjxBVHgAAAn4"]
[Sun Aug 30 03:09:52.165986 2026] [security2:error] [pid 512881:tid 513126] [client 20.104.18.15:16706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/133.php"] [unique_id "apPlUAi65Hcg2zUJjxBVJAAAAoc"]
[Sun Aug 30 03:09:52.181464 2026] [security2:error] [pid 512881:tid 513035] [client 20.48.250.41:49877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/users.php"] [unique_id "apPlUAi65Hcg2zUJjxBVKgAAAiw"]
[Sun Aug 30 03:09:52.190484 2026] [security2:error] [pid 512881:tid 513052] [client 4.205.62.107:17126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/app_dev.php"] [unique_id "apPlUAi65Hcg2zUJjxBVLgAAAj0"]
[Sun Aug 30 03:09:52.215605 2026] [security2:error] [pid 512881:tid 513020] [client 20.48.250.41:38827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/knmt.php"] [unique_id "apPlUAi65Hcg2zUJjxBVNwAAAh0"]
[Sun Aug 30 03:09:52.222482 2026] [authz_core:error] [pid 512881:tid 513055] [client 66.249.66.197:37995] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:52.222796 2026] [authz_core:error] [pid 512881:tid 513055] [client 66.249.66.197:37995] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:52.247962 2026] [security2:error] [pid 512881:tid 513134] [client 20.48.250.41:26596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/wp-blogs.php"] [unique_id "apPlUAi65Hcg2zUJjxBVPQAAAo8"]
[Sun Aug 30 03:09:52.261126 2026] [authz_core:error] [pid 512881:tid 513114] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:52.261413 2026] [authz_core:error] [pid 512881:tid 513114] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:52.283420 2026] [security2:error] [pid 512881:tid 513109] [client 20.104.18.15:18381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/adminfuns.php"] [unique_id "apPlUAi65Hcg2zUJjxBVRQAAAnY"]
[Sun Aug 30 03:09:52.287094 2026] [authz_core:error] [pid 512881:tid 513036] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:52.287414 2026] [authz_core:error] [pid 512881:tid 513036] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:52.317899 2026] [security2:error] [pid 512881:tid 513063] [client 20.48.250.41:49810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/bzjdlofz.php"] [unique_id "apPlUAi65Hcg2zUJjxBVSAAAAkg"]
[Sun Aug 30 03:09:52.330812 2026] [core:alert] [pid 512881:tid 513041] [client 187.1.8.57:0] /home3/lordrcan/public_html/.htaccess: without matching section, referer: https://www.google.com/
[Sun Aug 30 03:09:52.332198 2026] [security2:error] [pid 512881:tid 513104] [client 158.23.147.79:2023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apPlUAi65Hcg2zUJjxBVTgAAAnE"]
[Sun Aug 30 03:09:52.343290 2026] [security2:error] [pid 512881:tid 513126] [client 20.48.250.41:38824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/sbhu.php"] [unique_id "apPlUAi65Hcg2zUJjxBVTwAAAoc"]
[Sun Aug 30 03:09:52.356736 2026] [security2:error] [pid 512881:tid 513117] [client 68.155.159.216:46072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-login.php"] [unique_id "apPlUAi65Hcg2zUJjxBVSQAAAn4"]
[Sun Aug 30 03:09:52.360769 2026] [authz_core:error] [pid 512881:tid 513106] [client 66.249.66.66:41765] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:52.361158 2026] [authz_core:error] [pid 512881:tid 513106] [client 66.249.66.66:41765] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:52.364318 2026] [security2:error] [pid 512881:tid 513059] [client 20.104.49.130:43316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/sym.php"] [unique_id "apPlUAi65Hcg2zUJjxBVUgAAAkQ"]
[Sun Aug 30 03:09:52.378201 2026] [security2:error] [pid 512881:tid 513128] [client 20.48.250.41:26448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/mini.php"] [unique_id "apPlUAi65Hcg2zUJjxBVWQAAAok"]
[Sun Aug 30 03:09:52.380727 2026] [security2:error] [pid 512881:tid 513129] [client 213.209.159.223:15318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlUAi65Hcg2zUJjxBVWgAAAoo"]
[Sun Aug 30 03:09:52.410968 2026] [security2:error] [pid 512881:tid 513125] [client 20.104.50.220:33581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/14.php"] [unique_id "apPlUAi65Hcg2zUJjxBVZgAAAoY"]
[Sun Aug 30 03:09:52.432096 2026] [security2:error] [pid 512881:tid 513049] [client 20.104.50.220:32126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/sh3ll.php"] [unique_id "apPlUAi65Hcg2zUJjxBVZwAAAjo"]
[Sun Aug 30 03:09:52.450109 2026] [security2:error] [pid 512881:tid 513088] [client 34.100.204.203:34714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/wp-admin/phpinfo.php"] [unique_id "apPlUAi65Hcg2zUJjxBVaAAAAmE"]
[Sun Aug 30 03:09:52.457984 2026] [security2:error] [pid 512881:tid 513127] [client 20.48.250.41:49797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/selesai.php"] [unique_id "apPlUAi65Hcg2zUJjxBVbAAAAog"]
[Sun Aug 30 03:09:52.498948 2026] [security2:error] [pid 512881:tid 513067] [client 20.48.250.41:38870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/a332.php"] [unique_id "apPlUAi65Hcg2zUJjxBVcwAAAkw"]
[Sun Aug 30 03:09:52.548238 2026] [security2:error] [pid 512881:tid 513059] [client 20.48.251.3:65495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/aws_credentials.php"] [unique_id "apPlUAi65Hcg2zUJjxBVgQAAAkQ"]
[Sun Aug 30 03:09:52.551141 2026] [security2:error] [pid 512881:tid 513072] [client 40.83.93.50:21284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/updraft/about.php"] [unique_id "apPlUAi65Hcg2zUJjxBVhAAAAlE"]
[Sun Aug 30 03:09:52.566206 2026] [security2:error] [pid 512881:tid 513087] [client 20.48.250.41:26546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/amp.php"] [unique_id "apPlUAi65Hcg2zUJjxBVhwAAAmA"]
[Sun Aug 30 03:09:52.568813 2026] [authz_core:error] [pid 512881:tid 513128] [client 66.249.66.69:55158] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:52.569151 2026] [authz_core:error] [pid 512881:tid 513128] [client 66.249.66.69:55158] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:52.582291 2026] [security2:error] [pid 512881:tid 513092] [client 20.104.49.130:63255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/static.php"] [unique_id "apPlUAi65Hcg2zUJjxBViAAAAmU"]
[Sun Aug 30 03:09:52.586335 2026] [security2:error] [pid 512881:tid 513110] [client 4.205.62.107:36625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/66.php"] [unique_id "apPlUAi65Hcg2zUJjxBViwAAAnc"]
[Sun Aug 30 03:09:52.608226 2026] [security2:error] [pid 512881:tid 513115] [client 20.48.250.41:49919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/shlo.php"] [unique_id "apPlUAi65Hcg2zUJjxBVlQAAAnw"]
[Sun Aug 30 03:09:52.619720 2026] [security2:error] [pid 512881:tid 513125] [client 4.205.62.107:25508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/ws79.php"] [unique_id "apPlUAi65Hcg2zUJjxBVmAAAAoY"]
[Sun Aug 30 03:09:52.650805 2026] [authz_core:error] [pid 512881:tid 513049] [client 216.73.216.128:7555] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:52.651177 2026] [authz_core:error] [pid 512881:tid 513049] [client 216.73.216.128:7555] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:52.651955 2026] [security2:error] [pid 512881:tid 513015] [client 213.209.159.223:15318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themayorcoffee.com"] [uri "/php-info.php"] [unique_id "apPlUAi65Hcg2zUJjxBVnAAAAhg"]
[Sun Aug 30 03:09:52.652417 2026] [security2:error] [pid 512881:tid 513051] [client 20.48.250.41:38804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/ws66.php"] [unique_id "apPlUAi65Hcg2zUJjxBVnQAAAjw"]
[Sun Aug 30 03:09:52.656951 2026] [security2:error] [pid 512881:tid 513112] [client 20.104.49.130:63613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/fling.php"] [unique_id "apPlUAi65Hcg2zUJjxBVoAAAAnk"]
[Sun Aug 30 03:09:52.685786 2026] [security2:error] [pid 512881:tid 513082] [client 4.205.62.107:61736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/otuz1.php"] [unique_id "apPlUAi65Hcg2zUJjxBVqwAAAls"]
[Sun Aug 30 03:09:52.708579 2026] [security2:error] [pid 512881:tid 513110] [client 20.48.250.41:26577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/cc13.php"] [unique_id "apPlUAi65Hcg2zUJjxBVswAAAnc"]
[Sun Aug 30 03:09:52.735696 2026] [security2:error] [pid 512881:tid 513043] [client 20.151.200.44:28656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/file66.php"] [unique_id "apPlUAi65Hcg2zUJjxBVvAAAAjQ"]
[Sun Aug 30 03:09:52.745068 2026] [authz_core:error] [pid 512881:tid 513091] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:52.745366 2026] [authz_core:error] [pid 512881:tid 513091] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:52.749688 2026] [security2:error] [pid 512881:tid 513019] [client 20.48.250.41:49867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/asax.php"] [unique_id "apPlUAi65Hcg2zUJjxBVwAAAAhw"]
[Sun Aug 30 03:09:52.761906 2026] [security2:error] [pid 512881:tid 513125] [client 20.104.50.220:5941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/uploads.php"] [unique_id "apPlUAi65Hcg2zUJjxBVxAAAAoY"]
[Sun Aug 30 03:09:52.779375 2026] [security2:error] [pid 512881:tid 513013] [client 20.104.50.220:62004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/gank.php"] [unique_id "apPlUAi65Hcg2zUJjxBVxgAAAhY"]
[Sun Aug 30 03:09:52.801176 2026] [security2:error] [pid 512881:tid 513029] [client 20.48.250.41:38817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/ws68.php"] [unique_id "apPlUAi65Hcg2zUJjxBVzAAAAiY"]
[Sun Aug 30 03:09:52.847636 2026] [security2:error] [pid 512881:tid 513076] [client 20.48.250.41:26530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/aa.php"] [unique_id "apPlUAi65Hcg2zUJjxBV0QAAAlU"]
[Sun Aug 30 03:09:52.868958 2026] [security2:error] [pid 512881:tid 513074] [client 20.104.18.15:16996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/5PJcpMFsD8B.php"] [unique_id "apPlUAi65Hcg2zUJjxBV2gAAAlM"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:09:52.872573 2026] [security2:error] [pid 512881:tid 513024] [client 20.104.50.220:16644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/themes.php"] [unique_id "apPlUAi65Hcg2zUJjxBV2wAAAiE"]
[Sun Aug 30 03:09:52.884988 2026] [security2:error] [pid 512881:tid 513092] [client 20.48.251.3:59853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/infos.php"] [unique_id "apPlUAi65Hcg2zUJjxBV4AAAAmU"]
[Sun Aug 30 03:09:52.898279 2026] [security2:error] [pid 512881:tid 513017] [client 20.48.250.41:49853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/fetch.php"] [unique_id "apPlUAi65Hcg2zUJjxBV5QAAAho"]
[Sun Aug 30 03:09:52.922369 2026] [security2:error] [pid 512881:tid 513031] [client 20.48.251.3:59289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/brc.php"] [unique_id "apPlUAi65Hcg2zUJjxBV5wAAAig"]
[Sun Aug 30 03:09:52.930272 2026] [security2:error] [pid 512881:tid 513019] [client 20.48.250.41:38813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/users.php"] [unique_id "apPlUAi65Hcg2zUJjxBV6QAAAhw"]
[Sun Aug 30 03:09:52.967127 2026] [security2:error] [pid 512881:tid 513108] [client 68.155.159.216:63239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-includes/css/index.php"] [unique_id "apPlUAi65Hcg2zUJjxBV-QAAAnU"]
[Sun Aug 30 03:09:52.976174 2026] [security2:error] [pid 512881:tid 513117] [client 20.104.18.15:35029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/htio.php"] [unique_id "apPlUAi65Hcg2zUJjxBV-gAAAn4"]
[Sun Aug 30 03:09:52.976426 2026] [security2:error] [pid 512881:tid 513075] [client 20.104.49.130:58235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/users.php"] [unique_id "apPlUAi65Hcg2zUJjxBV-wAAAlQ"]
[Sun Aug 30 03:09:52.983346 2026] [security2:error] [pid 512881:tid 513114] [client 20.104.49.130:32829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/mac.php"] [unique_id "apPlUAi65Hcg2zUJjxBV_gAAAns"]
[Sun Aug 30 03:09:53.018704 2026] [security2:error] [pid 512881:tid 513072] [client 40.83.93.50:13390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/upgrade-temp-backup/min.php"] [unique_id "apPlUQi65Hcg2zUJjxBWCwAAAlE"]
[Sun Aug 30 03:09:53.029684 2026] [security2:error] [pid 512881:tid 513132] [client 158.23.147.79:56508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-content/admin.php"] [unique_id "apPlUQi65Hcg2zUJjxBWDgAAAo0"]
[Sun Aug 30 03:09:53.036679 2026] [security2:error] [pid 512881:tid 513017] [client 20.48.250.41:49885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/vx.php"] [unique_id "apPlUQi65Hcg2zUJjxBWDwAAAho"]
[Sun Aug 30 03:09:53.055374 2026] [authz_core:error] [pid 512881:tid 513016] [client 66.249.66.202:59598] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:53.055668 2026] [authz_core:error] [pid 512881:tid 513016] [client 66.249.66.202:59598] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:53.058358 2026] [security2:error] [pid 512881:tid 513125] [client 20.48.250.41:38799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/bzjdlofz.php"] [unique_id "apPlUQi65Hcg2zUJjxBWGgAAAoY"]
[Sun Aug 30 03:09:53.081767 2026] [security2:error] [pid 512881:tid 513063] [client 20.48.250.41:26476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/s1.php"] [unique_id "apPlUQi65Hcg2zUJjxBWHwAAAkg"]
[Sun Aug 30 03:09:53.086286 2026] [security2:error] [pid 512881:tid 513015] [client 20.104.50.220:59715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/h02ugyh.php"] [unique_id "apPlUQi65Hcg2zUJjxBWIAAAAhg"]
[Sun Aug 30 03:09:53.187449 2026] [authz_core:error] [pid 512881:tid 513037] [client 66.249.66.65:65258] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:53.187811 2026] [authz_core:error] [pid 512881:tid 513037] [client 66.249.66.65:65258] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:53.188139 2026] [security2:error] [pid 512881:tid 513079] [client 20.104.50.220:62844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/sa.php"] [unique_id "apPlUQi65Hcg2zUJjxBWPQAAAlg"]
[Sun Aug 30 03:09:53.195840 2026] [security2:error] [pid 512881:tid 513128] [client 20.48.250.41:38884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/selesai.php"] [unique_id "apPlUQi65Hcg2zUJjxBWQwAAAok"]
[Sun Aug 30 03:09:53.203471 2026] [security2:error] [pid 512881:tid 513029] [client 20.48.250.41:49886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/global.php"] [unique_id "apPlUQi65Hcg2zUJjxBWRgAAAiY"]
[Sun Aug 30 03:09:53.204097 2026] [security2:error] [pid 512881:tid 513101] [client 20.104.50.220:62805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/manage.php"] [unique_id "apPlUQi65Hcg2zUJjxBWSAAAAm4"]
[Sun Aug 30 03:09:53.209870 2026] [authz_core:error] [pid 512881:tid 513055] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:53.210160 2026] [authz_core:error] [pid 512881:tid 513055] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:53.213006 2026] [security2:error] [pid 512881:tid 513050] [client 20.104.50.220:51535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/pass.php"] [unique_id "apPlUQi65Hcg2zUJjxBWTQAAAjs"]
[Sun Aug 30 03:09:53.227167 2026] [security2:error] [pid 512881:tid 513024] [client 34.100.204.203:34728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/administrator/phpinfo.php"] [unique_id "apPlUQi65Hcg2zUJjxBWUQAAAiE"]
[Sun Aug 30 03:09:53.249898 2026] [security2:error] [pid 512881:tid 513114] [client 20.48.251.3:60503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/asdf.php"] [unique_id "apPlUQi65Hcg2zUJjxBWVgAAAns"]
[Sun Aug 30 03:09:53.262597 2026] [security2:error] [pid 512881:tid 513047] [client 20.104.49.130:26937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/222.php"] [unique_id "apPlUQi65Hcg2zUJjxBWXAAAAjg"]
[Sun Aug 30 03:09:53.262621 2026] [security2:error] [pid 512881:tid 513057] [client 20.48.250.41:26541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/0byte.php"] [unique_id "apPlUQi65Hcg2zUJjxBWXQAAAkI"]
[Sun Aug 30 03:09:53.269133 2026] [security2:error] [pid 512881:tid 513035] [client 20.104.18.15:44005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/ah.php"] [unique_id "apPlUQi65Hcg2zUJjxBWXgAAAiw"]
[Sun Aug 30 03:09:53.290380 2026] [security2:error] [pid 512881:tid 513131] [client 20.104.18.15:22483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/222.php"] [unique_id "apPlUQi65Hcg2zUJjxBWYwAAAow"]
[Sun Aug 30 03:09:53.301348 2026] [security2:error] [pid 512881:tid 513072] [client 20.104.18.15:16737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/1xmomo.php"] [unique_id "apPlUQi65Hcg2zUJjxBWZQAAAlE"]
[Sun Aug 30 03:09:53.322434 2026] [security2:error] [pid 512881:tid 513099] [client 4.205.62.107:17700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/php-info.php"] [unique_id "apPlUQi65Hcg2zUJjxBWagAAAmw"]
[Sun Aug 30 03:09:53.327058 2026] [security2:error] [pid 512881:tid 513113] [client 213.209.159.223:21530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themayorcoffee.com"] [uri "/info.php.bak"] [unique_id "apPlUQi65Hcg2zUJjxBWawAAAno"]
[Sun Aug 30 03:09:53.333407 2026] [security2:error] [pid 512881:tid 513080] [client 20.48.250.41:38823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/shlo.php"] [unique_id "apPlUQi65Hcg2zUJjxBWbAAAAlk"]
[Sun Aug 30 03:09:53.354610 2026] [security2:error] [pid 512881:tid 513125] [client 20.48.250.41:49871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/fs.php"] [unique_id "apPlUQi65Hcg2zUJjxBWbQAAAoY"]
[Sun Aug 30 03:09:53.378351 2026] [authz_core:error] [pid 512881:tid 513070] [client 216.73.216.128:50614] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:53.378633 2026] [authz_core:error] [pid 512881:tid 513070] [client 216.73.216.128:50614] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:53.431889 2026] [security2:error] [pid 512881:tid 513035] [client 20.104.18.15:18394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/classwithtostring.php"] [unique_id "apPlUQi65Hcg2zUJjxBWgQAAAiw"]
[Sun Aug 30 03:09:53.462314 2026] [security2:error] [pid 512881:tid 513092] [client 20.48.250.41:38824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/asax.php"] [unique_id "apPlUQi65Hcg2zUJjxBWiAAAAmU"]
[Sun Aug 30 03:09:53.492940 2026] [security2:error] [pid 512881:tid 513041] [client 40.83.93.50:13389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/upgrade-temp-backup/pk.php"] [unique_id "apPlUQi65Hcg2zUJjxBWjwAAAjI"]
[Sun Aug 30 03:09:53.501432 2026] [security2:error] [pid 512881:tid 513090] [client 20.48.251.3:6508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/classsmtps.php"] [unique_id "apPlUQi65Hcg2zUJjxBWkwAAAmM"]
[Sun Aug 30 03:09:53.515753 2026] [security2:error] [pid 512881:tid 513013] [client 20.48.250.41:49894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/ioxi.php"] [unique_id "apPlUQi65Hcg2zUJjxBWlAAAAhY"]
[Sun Aug 30 03:09:53.567464 2026] [security2:error] [pid 512881:tid 513127] [client 20.104.50.220:31899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/cabs.php"] [unique_id "apPlUQi65Hcg2zUJjxBWpgAAAog"]
[Sun Aug 30 03:09:53.576770 2026] [security2:error] [pid 512881:tid 513035] [client 158.23.147.79:2017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/xmlrpc.php"] [unique_id "apPlUQi65Hcg2zUJjxBWpwAAAiw"]
[Sun Aug 30 03:09:53.581632 2026] [security2:error] [pid 512881:tid 513018] [client 20.104.50.220:33038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/about.php"] [unique_id "apPlUQi65Hcg2zUJjxBWqAAAAhs"]
[Sun Aug 30 03:09:53.607343 2026] [security2:error] [pid 512881:tid 513017] [client 20.48.250.41:38877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/fetch.php"] [unique_id "apPlUQi65Hcg2zUJjxBWsAAAAho"]
[Sun Aug 30 03:09:53.656310 2026] [authz_core:error] [pid 512881:tid 513099] [client 66.249.66.64:40918] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:53.656760 2026] [authz_core:error] [pid 512881:tid 513099] [client 66.249.66.64:40918] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:53.680894 2026] [security2:error] [pid 512881:tid 513091] [client 20.48.250.41:49911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/bootstrap.php"] [unique_id "apPlUQi65Hcg2zUJjxBWwgAAAmQ"]
[Sun Aug 30 03:09:53.685428 2026] [security2:error] [pid 512881:tid 512932] [remote 66.116.251.167:59872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.251.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "creativelyfree.com"] [uri "/wp-login.php"] [unique_id "apPlUQi65Hcg2zUJjxBWwwACMDI"]
[Sun Aug 30 03:09:53.695682 2026] [security2:error] [pid 512881:tid 513047] [client 20.48.251.3:64311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/aws-credentials.php"] [unique_id "apPlUQi65Hcg2zUJjxBWyQAAAjg"]
[Sun Aug 30 03:09:53.711389 2026] [authz_core:error] [pid 512881:tid 513105] [client 66.249.66.34:59286] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:53.711802 2026] [authz_core:error] [pid 512881:tid 513105] [client 66.249.66.34:59286] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:53.716621 2026] [authz_core:error] [pid 512881:tid 513082] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:53.717092 2026] [authz_core:error] [pid 512881:tid 513082] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:53.736688 2026] [security2:error] [pid 512881:tid 513059] [client 20.48.250.41:26604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/xr.php"] [unique_id "apPlUQi65Hcg2zUJjxBW3wAAAkQ"]
[Sun Aug 30 03:09:53.739044 2026] [security2:error] [pid 512881:tid 513070] [client 216.73.216.128:7555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPlUQi65Hcg2zUJjxBW4AAAAk8"]
[Sun Aug 30 03:09:53.740786 2026] [security2:error] [pid 512881:tid 513029] [client 20.48.250.41:38795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/vx.php"] [unique_id "apPlUQi65Hcg2zUJjxBW4QAAAiY"]
[Sun Aug 30 03:09:53.750977 2026] [security2:error] [pid 512881:tid 513093] [client 20.104.49.130:53706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/xwpg.php"] [unique_id "apPlUQi65Hcg2zUJjxBW5wAAAmY"]
[Sun Aug 30 03:09:53.774991 2026] [security2:error] [pid 512881:tid 513051] [client 4.205.62.107:25776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/public/wp-blog.php"] [unique_id "apPlUQi65Hcg2zUJjxBW7gAAAjw"]
[Sun Aug 30 03:09:53.782272 2026] [security2:error] [pid 512881:tid 513106] [client 213.209.159.223:16474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themayorcoffee.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlUQi65Hcg2zUJjxBW8AAAAnM"]
[Sun Aug 30 03:09:53.787615 2026] [authz_core:error] [pid 512881:tid 513039] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:53.788089 2026] [authz_core:error] [pid 512881:tid 513039] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:53.807367 2026] [security2:error] [pid 512881:tid 513030] [client 20.48.250.41:49887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/export.php"] [unique_id "apPlUQi65Hcg2zUJjxBW-gAAAic"]
[Sun Aug 30 03:09:53.835815 2026] [security2:error] [pid 512881:tid 513053] [client 4.205.62.107:36659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/admin.php"] [unique_id "apPlUQi65Hcg2zUJjxBXAAAAAj4"]
[Sun Aug 30 03:09:53.852991 2026] [security2:error] [pid 512881:tid 513128] [client 4.205.62.107:61792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/update.php"] [unique_id "apPlUQi65Hcg2zUJjxBXBgAAAok"]
[Sun Aug 30 03:09:53.869974 2026] [security2:error] [pid 512881:tid 513046] [client 20.48.250.41:38816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/global.php"] [unique_id "apPlUQi65Hcg2zUJjxBXEQAAAjc"]
[Sun Aug 30 03:09:53.912866 2026] [security2:error] [pid 512881:tid 513115] [client 158.23.147.79:42845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlUQi65Hcg2zUJjxBXHAAAAnw"]
[Sun Aug 30 03:09:53.916740 2026] [security2:error] [pid 512881:tid 513075] [client 20.104.50.220:5497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/uploader.php"] [unique_id "apPlUQi65Hcg2zUJjxBXHQAAAlQ"]
[Sun Aug 30 03:09:53.920204 2026] [security2:error] [pid 512881:tid 513030] [client 20.104.50.220:61473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/gank.php.PhP"] [unique_id "apPlUQi65Hcg2zUJjxBXHgAAAic"]
[Sun Aug 30 03:09:53.928873 2026] [security2:error] [pid 512881:tid 513019] [client 20.48.250.41:26588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/h02ugyh.php"] [unique_id "apPlUQi65Hcg2zUJjxBXIAAAAhw"]
[Sun Aug 30 03:09:53.928881 2026] [authz_core:error] [pid 512881:tid 513112] [client 216.73.216.128:9185] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:53.929300 2026] [authz_core:error] [pid 512881:tid 513112] [client 216.73.216.128:9185] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:53.948699 2026] [security2:error] [pid 512881:tid 513131] [client 68.155.159.216:54273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-content/banners/about.php"] [unique_id "apPlUQi65Hcg2zUJjxBXKQAAAow"]
[Sun Aug 30 03:09:53.951552 2026] [security2:error] [pid 512881:tid 513094] [client 20.48.250.41:49820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/gk.php"] [unique_id "apPlUQi65Hcg2zUJjxBXKgAAAmc"]
[Sun Aug 30 03:09:53.955356 2026] [security2:error] [pid 512881:tid 513067] [client 40.83.93.50:21254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/upgrade-temp-backup/plugins/security.php"] [unique_id "apPlUQi65Hcg2zUJjxBXKwAAAkw"]
[Sun Aug 30 03:09:53.988582 2026] [security2:error] [pid 512881:tid 513109] [client 20.104.49.130:54199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/new.php"] [unique_id "apPlUQi65Hcg2zUJjxBXOAAAAnY"]
[Sun Aug 30 03:09:54.004904 2026] [security2:error] [pid 512881:tid 513103] [client 20.104.18.15:16985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPlUgi65Hcg2zUJjxBXPwAAAnA"]
[Sun Aug 30 03:09:54.014758 2026] [security2:error] [pid 512881:tid 513114] [client 20.104.50.220:16638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-admin/maint/about.php"] [unique_id "apPlUgi65Hcg2zUJjxBXQwAAAns"]
[Sun Aug 30 03:09:54.031213 2026] [security2:error] [pid 512881:tid 513019] [client 20.48.250.41:38873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/fs.php"] [unique_id "apPlUgi65Hcg2zUJjxBXSQAAAhw"]
[Sun Aug 30 03:09:54.039895 2026] [security2:error] [pid 512881:tid 513132] [client 20.48.251.3:59860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/env.php"] [unique_id "apPlUgi65Hcg2zUJjxBXTAAAAo0"]
[Sun Aug 30 03:09:54.046757 2026] [security2:error] [pid 512881:tid 513133] [client 34.100.204.203:34732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/core/phpinfo.php"] [unique_id "apPlUgi65Hcg2zUJjxBXUQAAAo4"]
[Sun Aug 30 03:09:54.073329 2026] [security2:error] [pid 512881:tid 513012] [client 68.155.159.216:63254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apPlUgi65Hcg2zUJjxBXWgAAAhU"]
[Sun Aug 30 03:09:54.074445 2026] [security2:error] [pid 512881:tid 513109] [client 20.48.251.3:55754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/vx.php"] [unique_id "apPlUgi65Hcg2zUJjxBXXAAAAnY"]
[Sun Aug 30 03:09:54.096685 2026] [security2:error] [pid 512881:tid 513046] [client 20.48.250.41:49902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/logs1.php"] [unique_id "apPlUgi65Hcg2zUJjxBXZQAAAjc"]
[Sun Aug 30 03:09:54.100017 2026] [authz_core:error] [pid 512881:tid 513104] [client 66.249.66.193:36005] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:54.100319 2026] [authz_core:error] [pid 512881:tid 513104] [client 66.249.66.193:36005] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:54.130376 2026] [security2:error] [pid 512881:tid 513087] [client 20.104.18.15:35022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/dev.php"] [unique_id "apPlUgi65Hcg2zUJjxBXbAAAAmA"]
[Sun Aug 30 03:09:54.132632 2026] [security2:error] [pid 512881:tid 513110] [client 158.23.147.79:41567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlUgi65Hcg2zUJjxBXbQAAAnc"]
[Sun Aug 30 03:09:54.138327 2026] [security2:error] [pid 512881:tid 513123] [client 158.23.147.79:56481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/atomlib.php"] [unique_id "apPlUgi65Hcg2zUJjxBXcAAAAoQ"]
[Sun Aug 30 03:09:54.172661 2026] [core:alert] [pid 512881:tid 513126] [client 187.1.8.57:0] /home3/lordrcan/public_html/.htaccess: without matching section, referer: http://www.lordrcane.com/
[Sun Aug 30 03:09:54.178374 2026] [security2:error] [pid 512881:tid 513105] [client 20.48.250.41:38910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/ioxi.php"] [unique_id "apPlUgi65Hcg2zUJjxBXggAAAnI"]
[Sun Aug 30 03:09:54.211051 2026] [security2:error] [pid 512881:tid 513025] [client 20.48.250.41:26517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/xxw.php"] [unique_id "apPlUgi65Hcg2zUJjxBXjgAAAiI"]
[Sun Aug 30 03:09:54.222744 2026] [authz_core:error] [pid 512881:tid 513042] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:54.223069 2026] [authz_core:error] [pid 512881:tid 513042] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:54.227055 2026] [security2:error] [pid 512881:tid 513018] [client 20.48.250.41:49798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/inege.php"] [unique_id "apPlUgi65Hcg2zUJjxBXlQAAAhs"]
[Sun Aug 30 03:09:54.228360 2026] [security2:error] [pid 512881:tid 513051] [client 20.104.50.220:31169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/seiso.php"] [unique_id "apPlUgi65Hcg2zUJjxBXlgAAAjw"]
[Sun Aug 30 03:09:54.280572 2026] [security2:error] [pid 512881:tid 513067] [client 20.151.200.44:28585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/blnux.php"] [unique_id "apPlUgi65Hcg2zUJjxBXpAAAAkw"]
[Sun Aug 30 03:09:54.310513 2026] [security2:error] [pid 512881:tid 513084] [client 20.48.250.41:38815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/bootstrap.php"] [unique_id "apPlUgi65Hcg2zUJjxBXrgAAAl0"]
[Sun Aug 30 03:09:54.319506 2026] [authz_core:error] [pid 512881:tid 513069] [client 66.249.66.64:40918] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:54.319972 2026] [authz_core:error] [pid 512881:tid 513069] [client 66.249.66.64:40918] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:54.328690 2026] [security2:error] [pid 512881:tid 513065] [client 68.155.159.216:45963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apPlUgi65Hcg2zUJjxBXsgAAAko"]
[Sun Aug 30 03:09:54.339003 2026] [security2:error] [pid 512881:tid 513106] [client 20.104.50.220:29323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/noname.php"] [unique_id "apPlUgi65Hcg2zUJjxBXtAAAAnM"]
[Sun Aug 30 03:09:54.341941 2026] [security2:error] [pid 512881:tid 513099] [client 20.104.50.220:28731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/mforh.php"] [unique_id "apPlUgi65Hcg2zUJjxBXtgAAAmw"]
[Sun Aug 30 03:09:54.350732 2026] [security2:error] [pid 512881:tid 513029] [client 20.104.50.220:51598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/Cpanel.php"] [unique_id "apPlUgi65Hcg2zUJjxBXuAAAAiY"]
[Sun Aug 30 03:09:54.352284 2026] [security2:error] [pid 512881:tid 513136] [client 20.63.81.20:36739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlUgi65Hcg2zUJjxBXuQAAApE"]
[Sun Aug 30 03:09:54.359895 2026] [security2:error] [pid 512881:tid 513108] [client 20.48.250.41:64599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/wp-link10.php"] [unique_id "apPlUgi65Hcg2zUJjxBXugAAAnU"]
[Sun Aug 30 03:09:54.374739 2026] [security2:error] [pid 512881:tid 513016] [client 20.48.250.41:26535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/bolt.php"] [unique_id "apPlUgi65Hcg2zUJjxBXvwAAAhk"]
[Sun Aug 30 03:09:54.384654 2026] [authz_core:error] [pid 512881:tid 513044] [client 216.73.216.128:9185] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:54.385110 2026] [authz_core:error] [pid 512881:tid 513044] [client 216.73.216.128:9185] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:54.421907 2026] [security2:error] [pid 512881:tid 513132] [client 40.83.93.50:17291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/upgrade-temp-backup/plugins/users.php"] [unique_id "apPlUgi65Hcg2zUJjxBX2gAAAo0"]
[Sun Aug 30 03:09:54.426304 2026] [security2:error] [pid 512881:tid 513019] [client 20.104.18.15:43971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/ws55.php"] [unique_id "apPlUgi65Hcg2zUJjxBX2wAAAhw"]
[Sun Aug 30 03:09:54.427965 2026] [security2:error] [pid 512881:tid 513018] [client 20.104.18.15:22475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/key.php"] [unique_id "apPlUgi65Hcg2zUJjxBX3QAAAhs"]
[Sun Aug 30 03:09:54.442250 2026] [security2:error] [pid 512881:tid 513123] [client 20.104.18.15:64860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/mosty.php"] [unique_id "apPlUgi65Hcg2zUJjxBX3gAAAoQ"]
[Sun Aug 30 03:09:54.457012 2026] [security2:error] [pid 512881:tid 513057] [client 20.48.250.41:38901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/export.php"] [unique_id "apPlUgi65Hcg2zUJjxBX4AAAAkI"]
[Sun Aug 30 03:09:54.473160 2026] [security2:error] [pid 512881:tid 513074] [client 4.205.62.107:17141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/infos.php"] [unique_id "apPlUgi65Hcg2zUJjxBX6gAAAlM"]
[Sun Aug 30 03:09:54.478978 2026] [security2:error] [pid 512881:tid 513086] [client 158.23.147.79:56457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/lv.php"] [unique_id "apPlUgi65Hcg2zUJjxBX7AAAAl8"]
[Sun Aug 30 03:09:54.480383 2026] [security2:error] [pid 512881:tid 513103] [client 20.48.251.3:60524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apPlUgi65Hcg2zUJjxBX7QAAAnA"]
[Sun Aug 30 03:09:54.482499 2026] [security2:error] [pid 512881:tid 513096] [client 20.63.81.20:36825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlUgi65Hcg2zUJjxBX7gAAAmk"]
[Sun Aug 30 03:09:54.506125 2026] [security2:error] [pid 512881:tid 513052] [client 213.209.159.223:39800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/env/.env"] [unique_id "apPlUgi65Hcg2zUJjxBX8wAAAj0"]
[Sun Aug 30 03:09:54.509495 2026] [security2:error] [pid 512881:tid 513031] [client 20.48.250.41:49816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/ww.php"] [unique_id "apPlUgi65Hcg2zUJjxBX9AAAAig"]
[Sun Aug 30 03:09:54.510587 2026] [security2:error] [pid 512881:tid 513012] [client 20.104.49.130:63599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/Jcrop.php"] [unique_id "apPlUgi65Hcg2zUJjxBX9QAAAhU"]
[Sun Aug 30 03:09:54.532886 2026] [security2:error] [pid 512881:tid 513045] [client 20.48.250.41:26538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/rtx.php"] [unique_id "apPlUgi65Hcg2zUJjxBX_QAAAjY"]
[Sun Aug 30 03:09:54.574979 2026] [security2:error] [pid 512881:tid 513087] [client 20.104.18.15:18417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPlUgi65Hcg2zUJjxBYDwAAAmA"]
[Sun Aug 30 03:09:54.579337 2026] [security2:error] [pid 512881:tid 513125] [client 158.23.147.79:42854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apPlUgi65Hcg2zUJjxBYEQAAAoY"]
[Sun Aug 30 03:09:54.593454 2026] [security2:error] [pid 512881:tid 513093] [client 20.48.250.41:38909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/gk.php"] [unique_id "apPlUgi65Hcg2zUJjxBYFgAAAmY"]
[Sun Aug 30 03:09:54.619470 2026] [security2:error] [pid 512881:tid 513065] [client 20.63.81.20:36746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/ser.php"] [unique_id "apPlUgi65Hcg2zUJjxBYIgAAAko"]
[Sun Aug 30 03:09:54.648050 2026] [security2:error] [pid 512881:tid 513136] [client 20.48.250.41:49832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/w1px.php"] [unique_id "apPlUgi65Hcg2zUJjxBYKAAAApE"]
[Sun Aug 30 03:09:54.667350 2026] [security2:error] [pid 512881:tid 513029] [client 20.48.250.41:26529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/ckk.php"] [unique_id "apPlUgi65Hcg2zUJjxBYMQAAAiY"]
[Sun Aug 30 03:09:54.668683 2026] [security2:error] [pid 512881:tid 513090] [client 20.48.251.3:6492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/cache-compat.php"] [unique_id "apPlUgi65Hcg2zUJjxBYMgAAAmM"]
[Sun Aug 30 03:09:54.695454 2026] [security2:error] [pid 512881:tid 513084] [client 20.104.49.130:43298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/kerang.php"] [unique_id "apPlUgi65Hcg2zUJjxBYPwAAAl0"]
[Sun Aug 30 03:09:54.714626 2026] [security2:error] [pid 512881:tid 513131] [client 20.104.49.130:54159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/33.php"] [unique_id "apPlUgi65Hcg2zUJjxBYTAAAAow"]
[Sun Aug 30 03:09:54.715494 2026] [authz_core:error] [pid 512881:tid 513035] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:54.715915 2026] [authz_core:error] [pid 512881:tid 513035] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:54.718844 2026] [security2:error] [pid 512881:tid 513019] [client 20.104.50.220:31827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/filesss.php"] [unique_id "apPlUgi65Hcg2zUJjxBYTwAAAhw"]
[Sun Aug 30 03:09:54.721178 2026] [security2:error] [pid 512881:tid 513136] [client 20.104.50.220:33574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/angel.php"] [unique_id "apPlUgi65Hcg2zUJjxBYUQAAApE"]
[Sun Aug 30 03:09:54.731385 2026] [security2:error] [pid 512881:tid 513018] [client 158.23.147.79:56475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apPlUgi65Hcg2zUJjxBYVwAAAhs"]
[Sun Aug 30 03:09:54.755433 2026] [security2:error] [pid 512881:tid 513033] [client 20.63.81.20:36752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/431.php"] [unique_id "apPlUgi65Hcg2zUJjxBYYAAAAio"]
[Sun Aug 30 03:09:54.765395 2026] [security2:error] [pid 512881:tid 513123] [client 20.48.250.41:38794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/logs1.php"] [unique_id "apPlUgi65Hcg2zUJjxBYYgAAAoQ"]
[Sun Aug 30 03:09:54.768363 2026] [security2:error] [pid 512881:tid 513117] [client 34.100.204.203:57984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.204.100.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bitcoinforum.it"] [uri "/includes/phpinfo.php"] [unique_id "apPlUgi65Hcg2zUJjxBYYwAAAn4"]
[Sun Aug 30 03:09:54.782306 2026] [security2:error] [pid 512881:tid 513072] [client 20.48.250.41:49892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/to.php"] [unique_id "apPlUgi65Hcg2zUJjxBYZwAAAlE"]
[Sun Aug 30 03:09:54.818400 2026] [security2:error] [pid 512881:tid 513049] [client 20.151.200.44:65443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlUgi65Hcg2zUJjxBYdgAAAjo"]
[Sun Aug 30 03:09:54.819399 2026] [security2:error] [pid 512881:tid 512973] [remote 66.116.251.167:59872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.251.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "creativelyfree.com"] [uri "/wp-login.php"] [unique_id "apPlUgi65Hcg2zUJjxBYdwACG1s"], referer: https://creativelyfree.com/wp-login.php
[Sun Aug 30 03:09:54.837907 2026] [security2:error] [pid 512881:tid 513057] [client 20.48.250.41:26436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ucdsafetysystems.com"] [uri "/R57.php"] [unique_id "apPlUgi65Hcg2zUJjxBYfgAAAkI"]
[Sun Aug 30 03:09:54.843599 2026] [security2:error] [pid 512881:tid 513056] [client 20.48.251.3:54809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/4563.php"] [unique_id "apPlUgi65Hcg2zUJjxBYgAAAAkE"]
[Sun Aug 30 03:09:54.868154 2026] [security2:error] [pid 512881:tid 513022] [client 20.151.200.44:28665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/attack.php"] [unique_id "apPlUgi65Hcg2zUJjxBYjQAAAh8"]
[Sun Aug 30 03:09:54.887201 2026] [security2:error] [pid 512881:tid 513031] [client 20.63.81.20:36755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/rxr.php"] [unique_id "apPlUgi65Hcg2zUJjxBYkgAAAig"]
[Sun Aug 30 03:09:54.889566 2026] [security2:error] [pid 512881:tid 513137] [client 40.83.93.50:21299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/upgrade-temp-backup/plugins/wp-blog-header.php"] [unique_id "apPlUgi65Hcg2zUJjxBYlAAAApI"]
[Sun Aug 30 03:09:54.901890 2026] [security2:error] [pid 512881:tid 513097] [client 20.48.250.41:38865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/inege.php"] [unique_id "apPlUgi65Hcg2zUJjxBYlwAAAmo"]
[Sun Aug 30 03:09:54.912415 2026] [security2:error] [pid 512881:tid 513066] [client 20.48.250.41:49851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/thui.php"] [unique_id "apPlUgi65Hcg2zUJjxBYmgAAAks"]
[Sun Aug 30 03:09:54.918060 2026] [security2:error] [pid 512881:tid 513120] [client 158.23.147.79:41566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apPlUgi65Hcg2zUJjxBYnAAAAoE"]
[Sun Aug 30 03:09:54.968202 2026] [security2:error] [pid 512881:tid 513099] [client 20.104.49.130:53626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/ty.php"] [unique_id "apPlUgi65Hcg2zUJjxBYrQAAAmw"]
[Sun Aug 30 03:09:54.972135 2026] [security2:error] [pid 512881:tid 513109] [client 213.209.159.223:39800] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/src/.env"] [unique_id "apPlUgi65Hcg2zUJjxBYrgAAAnY"]
[Sun Aug 30 03:09:54.974092 2026] [security2:error] [pid 512881:tid 513113] [client 4.205.62.107:25511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/php-details.php"] [unique_id "apPlUgi65Hcg2zUJjxBYsQAAAno"]
[Sun Aug 30 03:09:54.996498 2026] [security2:error] [pid 512881:tid 513075] [client 158.23.147.79:57697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/content.php"] [unique_id "apPlUgi65Hcg2zUJjxBYvAAAAlQ"]
[Sun Aug 30 03:09:55.001220 2026] [security2:error] [pid 512881:tid 513044] [client 4.205.62.107:61704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/channels.php"] [unique_id "apPlUwi65Hcg2zUJjxBYvQAAAjU"]
[Sun Aug 30 03:09:55.016194 2026] [security2:error] [pid 512881:tid 513128] [client 20.63.81.20:36834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/csst.php"] [unique_id "apPlUwi65Hcg2zUJjxBYxgAAAok"]
[Sun Aug 30 03:09:55.056492 2026] [security2:error] [pid 512881:tid 513109] [client 20.104.49.130:36779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/wsd.php"] [unique_id "apPlUwi65Hcg2zUJjxBY1AAAAnY"]
[Sun Aug 30 03:09:55.071765 2026] [security2:error] [pid 512881:tid 513059] [client 20.104.50.220:5541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/remote.php"] [unique_id "apPlUwi65Hcg2zUJjxBY1wAAAkQ"]
[Sun Aug 30 03:09:55.105786 2026] [security2:error] [pid 512881:tid 513045] [client 216.73.216.128:9185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_config_quote_replace_string"] [unique_id "apPlUwi65Hcg2zUJjxBY6gAAAjY"]
[Sun Aug 30 03:09:55.115880 2026] [authz_core:error] [pid 512881:tid 513131] [client 66.249.66.194:38212] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:55.116332 2026] [authz_core:error] [pid 512881:tid 513131] [client 66.249.66.194:38212] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:55.124909 2026] [security2:error] [pid 512881:tid 513033] [client 158.23.147.79:41542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/simple.php"] [unique_id "apPlUwi65Hcg2zUJjxBY8AAAAio"]
[Sun Aug 30 03:09:55.136055 2026] [security2:error] [pid 512881:tid 513035] [client 20.220.10.235:26580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlUwi65Hcg2zUJjxBY9AAAAiw"]
[Sun Aug 30 03:09:55.141910 2026] [security2:error] [pid 512881:tid 513122] [client 20.104.18.15:17015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/wsd.php"] [unique_id "apPlUwi65Hcg2zUJjxBY9wAAAoM"]
[Sun Aug 30 03:09:55.143631 2026] [security2:error] [pid 512881:tid 513052] [client 20.63.81.20:36833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp-includes/blocks/query-title/footer.php"] [unique_id "apPlUwi65Hcg2zUJjxBY-AAAAj0"]
[Sun Aug 30 03:09:55.146359 2026] [security2:error] [pid 512881:tid 513105] [client 20.104.50.220:16750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-admin/network/wp-conflg.php"] [unique_id "apPlUwi65Hcg2zUJjxBY-gAAAnI"]
[Sun Aug 30 03:09:55.198558 2026] [security2:error] [pid 512881:tid 513044] [client 20.48.251.3:59864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/xve22.php"] [unique_id "apPlUwi65Hcg2zUJjxBZFAAAAjU"]
[Sun Aug 30 03:09:55.199311 2026] [security2:error] [pid 512881:tid 513018] [client 20.104.50.220:61406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/gh.php"] [unique_id "apPlUwi65Hcg2zUJjxBZFQAAAhs"]
[Sun Aug 30 03:09:55.200094 2026] [security2:error] [pid 512881:tid 513030] [client 4.205.62.107:36633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/png.php"] [unique_id "apPlUwi65Hcg2zUJjxBZFgAAAic"]
[Sun Aug 30 03:09:55.205265 2026] [security2:error] [pid 512881:tid 513048] [client 158.23.147.79:56456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPlUwi65Hcg2zUJjxBZGQAAAjk"]
[Sun Aug 30 03:09:55.212314 2026] [security2:error] [pid 512881:tid 513020] [client 20.48.251.3:59264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/ty.php"] [unique_id "apPlUwi65Hcg2zUJjxBZGwAAAh0"]
[Sun Aug 30 03:09:55.224807 2026] [security2:error] [pid 512881:tid 513103] [client 158.23.147.79:42825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-admin/about.php"] [unique_id "apPlUwi65Hcg2zUJjxBZIAAAAnA"]
[Sun Aug 30 03:09:55.227401 2026] [authz_core:error] [pid 512881:tid 513033] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:55.227706 2026] [authz_core:error] [pid 512881:tid 513033] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:55.233295 2026] [security2:error] [pid 512881:tid 513047] [client 20.104.49.130:53720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/fling.php"] [unique_id "apPlUwi65Hcg2zUJjxBZIwAAAjg"]
[Sun Aug 30 03:09:55.242854 2026] [authz_core:error] [pid 512881:tid 513130] [client 66.249.66.77:46540] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:55.243334 2026] [authz_core:error] [pid 512881:tid 513130] [client 66.249.66.77:46540] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:55.262812 2026] [security2:error] [pid 512881:tid 513108] [client 20.220.10.235:26509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlUwi65Hcg2zUJjxBZLQAAAnU"]
[Sun Aug 30 03:09:55.267132 2026] [security2:error] [pid 512881:tid 513124] [client 20.151.200.44:28623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/wk/index.php"] [unique_id "apPlUwi65Hcg2zUJjxBZLwAAAoU"]
[Sun Aug 30 03:09:55.269742 2026] [security2:error] [pid 512881:tid 513022] [client 20.63.81.20:36851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp-content/uploads/indoex.php"] [unique_id "apPlUwi65Hcg2zUJjxBZMAAAAh8"]
[Sun Aug 30 03:09:55.287132 2026] [authz_core:error] [pid 512881:tid 513012] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:55.287593 2026] [authz_core:error] [pid 512881:tid 513012] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:55.287759 2026] [security2:error] [pid 512881:tid 513076] [client 20.104.18.15:35026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/gos.php"] [unique_id "apPlUwi65Hcg2zUJjxBZNgAAAlU"]
[Sun Aug 30 03:09:55.288956 2026] [security2:error] [pid 512881:tid 513099] [client 216.73.216.128:50614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPlUwi65Hcg2zUJjxBZNwAAAmw"]
[Sun Aug 30 03:09:55.307071 2026] [security2:error] [pid 512881:tid 513072] [client 213.209.159.223:39800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themayorcoffee.com"] [uri "/config/app.php"] [unique_id "apPlUwi65Hcg2zUJjxBZOwAAAlE"]
[Sun Aug 30 03:09:55.339075 2026] [security2:error] [pid 512881:tid 513095] [client 68.155.159.216:63236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-content/cong.php"] [unique_id "apPlUwi65Hcg2zUJjxBZQQAAAmg"]
[Sun Aug 30 03:09:55.353438 2026] [security2:error] [pid 512881:tid 513045] [client 40.83.93.50:21267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/upgrade-temp-backup/plugins/wp-mail.php"] [unique_id "apPlUwi65Hcg2zUJjxBZSAAAAjY"]
[Sun Aug 30 03:09:55.359827 2026] [security2:error] [pid 512881:tid 513031] [client 158.23.147.79:42821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apPlUwi65Hcg2zUJjxBZSQAAAig"]
[Sun Aug 30 03:09:55.382144 2026] [security2:error] [pid 512881:tid 512918] [remote 52.167.144.176:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ibrgroup.ae"] [uri "/nitori/order_status.php"] [unique_id "apPlUwi65Hcg2zUJjxBZVAACdSQ"]
[Sun Aug 30 03:09:55.382251 2026] [security2:error] [pid 512881:tid 513067] [client 20.104.50.220:51398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/155.php"] [unique_id "apPlUwi65Hcg2zUJjxBZVgAAAkw"]
[Sun Aug 30 03:09:55.398846 2026] [security2:error] [pid 512881:tid 513110] [client 20.63.81.20:36856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPlUwi65Hcg2zUJjxBZYQAAAnc"]
[Sun Aug 30 03:09:55.402638 2026] [security2:error] [pid 512881:tid 513119] [client 20.220.10.235:26514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/h02ugyh.php"] [unique_id "apPlUwi65Hcg2zUJjxBZZAAAAoA"]
[Sun Aug 30 03:09:55.438201 2026] [security2:error] [pid 512881:tid 513116] [client 68.155.159.216:46042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-admin/images/about.php"] [unique_id "apPlUwi65Hcg2zUJjxBZaAAAAn0"]
[Sun Aug 30 03:09:55.468128 2026] [security2:error] [pid 512881:tid 513062] [client 158.23.147.79:42878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apPlUwi65Hcg2zUJjxBZcQAAAkc"]
[Sun Aug 30 03:09:55.477702 2026] [security2:error] [pid 512881:tid 513029] [client 68.155.159.216:52566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apPlUwi65Hcg2zUJjxBZdQAAAiY"]
[Sun Aug 30 03:09:55.503368 2026] [security2:error] [pid 512881:tid 513047] [client 20.104.50.220:29280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/kntol.php"] [unique_id "apPlUwi65Hcg2zUJjxBZewAAAjg"]
[Sun Aug 30 03:09:55.516245 2026] [security2:error] [pid 512881:tid 513026] [client 20.104.50.220:42021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/unknown.php"] [unique_id "apPlUwi65Hcg2zUJjxBZfAAAAiM"]
[Sun Aug 30 03:09:55.526523 2026] [security2:error] [pid 512881:tid 513044] [client 20.63.81.20:36858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/haxor.php"] [unique_id "apPlUwi65Hcg2zUJjxBZfQAAAjU"]
[Sun Aug 30 03:09:55.540948 2026] [security2:error] [pid 512881:tid 513065] [client 20.220.10.235:26528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/sf.php"] [unique_id "apPlUwi65Hcg2zUJjxBZgwAAAko"]
[Sun Aug 30 03:09:55.567853 2026] [security2:error] [pid 512881:tid 513085] [client 20.104.18.15:22477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/chosen.php"] [unique_id "apPlUwi65Hcg2zUJjxBZmAAAAl4"]
[Sun Aug 30 03:09:55.582419 2026] [security2:error] [pid 512881:tid 513042] [client 20.104.18.15:43314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/drykl.php"] [unique_id "apPlUwi65Hcg2zUJjxBZmgAAAjM"]
[Sun Aug 30 03:09:55.582762 2026] [security2:error] [pid 512881:tid 513121] [client 20.104.18.15:16729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/blurbs.php"] [unique_id "apPlUwi65Hcg2zUJjxBZmwAAAoI"]
[Sun Aug 30 03:09:55.585306 2026] [security2:error] [pid 512881:tid 513013] [client 158.23.147.79:42856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/chosen.php"] [unique_id "apPlUwi65Hcg2zUJjxBZngAAAhY"]
[Sun Aug 30 03:09:55.613904 2026] [security2:error] [pid 512881:tid 513097] [client 4.205.62.107:17679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/env.php"] [unique_id "apPlUwi65Hcg2zUJjxBZpgAAAmo"]
[Sun Aug 30 03:09:55.655564 2026] [security2:error] [pid 512881:tid 513103] [client 20.63.81.20:36852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/google.php"] [unique_id "apPlUwi65Hcg2zUJjxBZswAAAnA"]
[Sun Aug 30 03:09:55.667577 2026] [security2:error] [pid 512881:tid 513088] [client 20.151.200.44:28570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/dehnl.php"] [unique_id "apPlUwi65Hcg2zUJjxBZuQAAAmE"]
[Sun Aug 30 03:09:55.675278 2026] [security2:error] [pid 512881:tid 513125] [client 20.220.10.235:26582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/4e.php"] [unique_id "apPlUwi65Hcg2zUJjxBZvAAAAoY"]
[Sun Aug 30 03:09:55.685028 2026] [authz_core:error] [pid 512881:tid 513032] [client 66.249.66.194:38212] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:55.685339 2026] [authz_core:error] [pid 512881:tid 513032] [client 66.249.66.194:38212] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:55.686336 2026] [security2:error] [pid 512881:tid 513105] [client 158.23.147.79:42859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/goods.php"] [unique_id "apPlUwi65Hcg2zUJjxBZwAAAAnI"]
[Sun Aug 30 03:09:55.691618 2026] [security2:error] [pid 512881:tid 513049] [client 20.48.251.3:33314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/hochladen.form.php"] [unique_id "apPlUwi65Hcg2zUJjxBZwwAAAjo"]
[Sun Aug 30 03:09:55.709724 2026] [security2:error] [pid 512881:tid 513070] [client 213.209.159.223:60635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themayorcoffee.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlUwi65Hcg2zUJjxBZzgAAAk8"]
[Sun Aug 30 03:09:55.727668 2026] [security2:error] [pid 512881:tid 513097] [client 20.104.18.15:18425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/5PJcpMFsD8B.php"] [unique_id "apPlUwi65Hcg2zUJjxBZ2wAAAmo"]
[Sun Aug 30 03:09:55.743312 2026] [authz_core:error] [pid 512881:tid 513057] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:55.743700 2026] [authz_core:error] [pid 512881:tid 513057] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:55.767814 2026] [security2:error] [pid 512881:tid 513105] [client 158.23.147.79:2041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/goat.php"] [unique_id "apPlUwi65Hcg2zUJjxBZ8AAAAnI"]
[Sun Aug 30 03:09:55.786761 2026] [security2:error] [pid 512881:tid 513108] [client 20.63.81.20:36768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "apPlUwi65Hcg2zUJjxBZ9wAAAnU"]
[Sun Aug 30 03:09:55.803498 2026] [security2:error] [pid 512881:tid 513016] [client 20.220.10.235:26586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/ssss.php"] [unique_id "apPlUwi65Hcg2zUJjxBZ_gAAAhk"]
[Sun Aug 30 03:09:55.828019 2026] [security2:error] [pid 512881:tid 513052] [client 40.83.93.50:21305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/upgrade-temp-backup/themes/admin.php"] [unique_id "apPlUwi65Hcg2zUJjxBaAwAAAj0"]
[Sun Aug 30 03:09:55.842393 2026] [security2:error] [pid 512881:tid 513042] [client 20.151.200.44:41939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/motu.php"] [unique_id "apPlUwi65Hcg2zUJjxBaBwAAAjM"]
[Sun Aug 30 03:09:55.844083 2026] [security2:error] [pid 512881:tid 513138] [client 158.23.147.79:42837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apPlUwi65Hcg2zUJjxBaCgAAApM"]
[Sun Aug 30 03:09:55.855920 2026] [security2:error] [pid 512881:tid 513120] [client 20.104.50.220:31825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/wp-aaa.php"] [unique_id "apPlUwi65Hcg2zUJjxBaEAAAAoE"]
[Sun Aug 30 03:09:55.857715 2026] [security2:error] [pid 512881:tid 513109] [client 20.104.50.220:32884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/c100.php"] [unique_id "apPlUwi65Hcg2zUJjxBaEgAAAnY"]
[Sun Aug 30 03:09:55.861316 2026] [security2:error] [pid 512881:tid 513026] [client 20.48.251.3:7408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/umgebung.php"] [unique_id "apPlUwi65Hcg2zUJjxBaFgAAAiM"]
[Sun Aug 30 03:09:55.913794 2026] [security2:error] [pid 512881:tid 513012] [client 20.63.81.20:36850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/robots.php"] [unique_id "apPlUwi65Hcg2zUJjxBaKAAAAhU"]
[Sun Aug 30 03:09:55.935339 2026] [security2:error] [pid 512881:tid 513061] [client 20.220.10.235:26563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/zoz.php"] [unique_id "apPlUwi65Hcg2zUJjxBaLgAAAkY"]
[Sun Aug 30 03:09:55.995128 2026] [security2:error] [pid 512881:tid 513137] [client 20.48.251.3:54802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/cp2.php"] [unique_id "apPlUwi65Hcg2zUJjxBaTAAAApI"]
[Sun Aug 30 03:09:56.019861 2026] [security2:error] [pid 512881:tid 513016] [client 158.23.147.79:42829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apPlVAi65Hcg2zUJjxBaVgAAAhk"]
[Sun Aug 30 03:09:56.031618 2026] [security2:error] [pid 512881:tid 513045] [client 20.104.49.130:45173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/k.php"] [unique_id "apPlVAi65Hcg2zUJjxBaWwAAAjY"]
[Sun Aug 30 03:09:56.043393 2026] [security2:error] [pid 512881:tid 513031] [client 20.63.81.20:36806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp-content/plugins/ccx/index.php"] [unique_id "apPlVAi65Hcg2zUJjxBaXgAAAig"]
[Sun Aug 30 03:09:56.054266 2026] [security2:error] [pid 512881:tid 513030] [client 20.48.250.41:49842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/Jcrop.php"] [unique_id "apPlVAi65Hcg2zUJjxBaZgAAAic"]
[Sun Aug 30 03:09:56.063813 2026] [security2:error] [pid 512881:tid 513026] [client 20.220.10.235:26574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/kcs.php"] [unique_id "apPlVAi65Hcg2zUJjxBaZwAAAiM"]
[Sun Aug 30 03:09:56.068912 2026] [security2:error] [pid 512881:tid 513079] [client 20.48.250.41:38743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/wp-link10.php"] [unique_id "apPlVAi65Hcg2zUJjxBabAAAAlg"]
[Sun Aug 30 03:09:56.079230 2026] [security2:error] [pid 512881:tid 513024] [client 20.104.49.130:59564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/dk.php"] [unique_id "apPlVAi65Hcg2zUJjxBabgAAAiE"]
[Sun Aug 30 03:09:56.110691 2026] [security2:error] [pid 512881:tid 513016] [client 4.205.62.107:25777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/routes.php"] [unique_id "apPlVAi65Hcg2zUJjxBafgAAAhk"]
[Sun Aug 30 03:09:56.133119 2026] [security2:error] [pid 512881:tid 513116] [client 20.151.200.44:28667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/png.php"] [unique_id "apPlVAi65Hcg2zUJjxBaigAAAn0"]
[Sun Aug 30 03:09:56.141767 2026] [security2:error] [pid 512881:tid 513097] [client 4.205.62.107:58460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/zz.php"] [unique_id "apPlVAi65Hcg2zUJjxBajgAAAmo"]
[Sun Aug 30 03:09:56.148786 2026] [security2:error] [pid 512881:tid 513036] [client 20.104.49.130:36742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/133.php"] [unique_id "apPlVAi65Hcg2zUJjxBakwAAAi0"]
[Sun Aug 30 03:09:56.173569 2026] [security2:error] [pid 512881:tid 513015] [client 20.63.81.20:36848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp-admin/css/colors/maro.php"] [unique_id "apPlVAi65Hcg2zUJjxBaoQAAAhg"]
[Sun Aug 30 03:09:56.193447 2026] [security2:error] [pid 512881:tid 513119] [client 20.220.10.235:26500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/tajj.php"] [unique_id "apPlVAi65Hcg2zUJjxBarQAAAoA"]
[Sun Aug 30 03:09:56.197482 2026] [security2:error] [pid 512881:tid 513046] [client 158.23.147.79:42865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/file.php"] [unique_id "apPlVAi65Hcg2zUJjxBarwAAAjc"]
[Sun Aug 30 03:09:56.197675 2026] [security2:error] [pid 512881:tid 513072] [client 20.48.250.41:49806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/ws58.php"] [unique_id "apPlVAi65Hcg2zUJjxBasAAAAlE"]
[Sun Aug 30 03:09:56.198165 2026] [security2:error] [pid 512881:tid 513044] [client 216.73.216.128:53111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlVAi65Hcg2zUJjxBasQAAAjU"]
[Sun Aug 30 03:09:56.215084 2026] [security2:error] [pid 512881:tid 513051] [client 20.48.250.41:38880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/ww.php"] [unique_id "apPlVAi65Hcg2zUJjxBaswAAAjw"]
[Sun Aug 30 03:09:56.224694 2026] [security2:error] [pid 512881:tid 513123] [client 20.104.50.220:5936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/shellbypass.php"] [unique_id "apPlVAi65Hcg2zUJjxBatQAAAoQ"]
[Sun Aug 30 03:09:56.251202 2026] [security2:error] [pid 512881:tid 513104] [client 213.209.159.223:62014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "themayorcoffee.com"] [uri "/web/.env"] [unique_id "apPlVAi65Hcg2zUJjxBauwAAAnE"]
[Sun Aug 30 03:09:56.278831 2026] [security2:error] [pid 512881:tid 513062] [client 20.104.18.15:17013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/bulet.php"] [unique_id "apPlVAi65Hcg2zUJjxBaxQAAAkc"]
[Sun Aug 30 03:09:56.284897 2026] [security2:error] [pid 512881:tid 513085] [client 20.104.50.220:17339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/click.php"] [unique_id "apPlVAi65Hcg2zUJjxBayQAAAl4"]
[Sun Aug 30 03:09:56.294851 2026] [security2:error] [pid 512881:tid 513095] [client 20.151.200.44:65447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlVAi65Hcg2zUJjxBazgAAAmg"]
[Sun Aug 30 03:09:56.298195 2026] [authz_core:error] [pid 512881:tid 513135] [client 66.249.66.36:36460] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:56.298485 2026] [authz_core:error] [pid 512881:tid 513135] [client 66.249.66.36:36460] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:56.303042 2026] [security2:error] [pid 512881:tid 513044] [client 20.63.81.20:36863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp-admin/css/colors/coffee/marijuana.php"] [unique_id "apPlVAi65Hcg2zUJjxBa0gAAAjU"]
[Sun Aug 30 03:09:56.309207 2026] [security2:error] [pid 512881:tid 513069] [client 40.83.93.50:17293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/upgrade-temp-backup/themes/login.php"] [unique_id "apPlVAi65Hcg2zUJjxBa2AAAAk4"]
[Sun Aug 30 03:09:56.330267 2026] [security2:error] [pid 512881:tid 513130] [client 20.220.10.235:26441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/bge.php"] [unique_id "apPlVAi65Hcg2zUJjxBa3QAAAos"]
[Sun Aug 30 03:09:56.337821 2026] [security2:error] [pid 512881:tid 513019] [client 158.23.147.79:57718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apPlVAi65Hcg2zUJjxBa3gAAAhw"]
[Sun Aug 30 03:09:56.348672 2026] [security2:error] [pid 512881:tid 513117] [client 20.48.251.3:52277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/06.php"] [unique_id "apPlVAi65Hcg2zUJjxBa4gAAAn4"]
[Sun Aug 30 03:09:56.352199 2026] [security2:error] [pid 512881:tid 513127] [client 20.48.251.3:59378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/adminer-4.7.6-en.php"] [unique_id "apPlVAi65Hcg2zUJjxBa5QAAAog"]
[Sun Aug 30 03:09:56.352217 2026] [security2:error] [pid 512881:tid 513131] [client 20.104.50.220:61503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/id.php"] [unique_id "apPlVAi65Hcg2zUJjxBa5gAAAow"]
[Sun Aug 30 03:09:56.357198 2026] [security2:error] [pid 512881:tid 513067] [client 20.48.250.41:49847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/xs.php"] [unique_id "apPlVAi65Hcg2zUJjxBa7QAAAkw"]
[Sun Aug 30 03:09:56.358574 2026] [security2:error] [pid 512881:tid 513125] [client 158.23.147.79:42858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/file17.php"] [unique_id "apPlVAi65Hcg2zUJjxBa7gAAAoY"]
[Sun Aug 30 03:09:56.364746 2026] [security2:error] [pid 512881:tid 513091] [client 20.48.250.41:38752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/w1px.php"] [unique_id "apPlVAi65Hcg2zUJjxBa8wAAAmQ"]
[Sun Aug 30 03:09:56.384578 2026] [security2:error] [pid 512881:tid 513075] [client 213.209.159.223:62014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.159.209.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themayorcoffee.com"] [uri "/phpinfo.php3"] [unique_id "apPlVAi65Hcg2zUJjxBbAwAAAlQ"]
[Sun Aug 30 03:09:56.385960 2026] [authz_core:error] [pid 512881:tid 513085] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:56.386408 2026] [authz_core:error] [pid 512881:tid 513085] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:56.406333 2026] [security2:error] [pid 512881:tid 513030] [client 20.104.49.130:58229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/echkm.php"] [unique_id "apPlVAi65Hcg2zUJjxBbDwAAAic"]
[Sun Aug 30 03:09:56.409172 2026] [authz_core:error] [pid 512881:tid 513134] [client 66.249.66.71:41396] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:56.409666 2026] [authz_core:error] [pid 512881:tid 513134] [client 66.249.66.71:41396] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:56.413327 2026] [security2:error] [pid 512881:tid 513036] [client 4.205.62.107:35995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/chosen.php"] [unique_id "apPlVAi65Hcg2zUJjxBbEQAAAi0"]
[Sun Aug 30 03:09:56.428697 2026] [security2:error] [pid 512881:tid 513110] [client 20.63.81.20:36818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp-admin/css/colors/coffee/mari.php"] [unique_id "apPlVAi65Hcg2zUJjxBbGgAAAnc"]
[Sun Aug 30 03:09:56.429483 2026] [security2:error] [pid 512881:tid 513108] [client 20.104.18.15:35483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/132.php"] [unique_id "apPlVAi65Hcg2zUJjxBbGwAAAnU"]
[Sun Aug 30 03:09:56.466070 2026] [security2:error] [pid 512881:tid 513053] [client 20.220.10.235:26577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/ssh3ll.php"] [unique_id "apPlVAi65Hcg2zUJjxBbKAAAAj4"]
[Sun Aug 30 03:09:56.491966 2026] [security2:error] [pid 512881:tid 513045] [client 20.48.250.41:49794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/zu.php"] [unique_id "apPlVAi65Hcg2zUJjxBbLgAAAjY"]
[Sun Aug 30 03:09:56.497468 2026] [security2:error] [pid 512881:tid 513122] [client 158.23.147.79:41539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/file5.php"] [unique_id "apPlVAi65Hcg2zUJjxBbMgAAAoM"]
[Sun Aug 30 03:09:56.523974 2026] [security2:error] [pid 512881:tid 513031] [client 20.48.250.41:38878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/to.php"] [unique_id "apPlVAi65Hcg2zUJjxBbOQAAAig"]
[Sun Aug 30 03:09:56.533414 2026] [security2:error] [pid 512881:tid 513022] [client 20.104.50.220:51010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/ppp.php"] [unique_id "apPlVAi65Hcg2zUJjxBbPAAAAh8"]
[Sun Aug 30 03:09:56.561505 2026] [security2:error] [pid 512881:tid 513062] [client 20.63.81.20:36823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp-includes/images/crystal/option.php"] [unique_id "apPlVAi65Hcg2zUJjxBbUAAAAkc"]
[Sun Aug 30 03:09:56.587465 2026] [security2:error] [pid 512881:tid 513096] [client 68.155.159.216:62641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPlVAi65Hcg2zUJjxBbXQAAAmk"]
[Sun Aug 30 03:09:56.593161 2026] [authz_core:error] [pid 512881:tid 513110] [client 66.249.66.200:65271] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:56.593459 2026] [authz_core:error] [pid 512881:tid 513110] [client 66.249.66.200:65271] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:56.601618 2026] [security2:error] [pid 512881:tid 513075] [client 20.220.10.235:26579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/motu.php"] [unique_id "apPlVAi65Hcg2zUJjxBbagAAAlQ"]
[Sun Aug 30 03:09:56.603373 2026] [security2:error] [pid 512881:tid 513119] [client 68.155.159.216:46037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPlVAi65Hcg2zUJjxBbawAAAoA"]
[Sun Aug 30 03:09:56.605792 2026] [security2:error] [pid 512881:tid 513047] [client 158.23.147.79:42855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/file88.php"] [unique_id "apPlVAi65Hcg2zUJjxBbbQAAAjg"]
[Sun Aug 30 03:09:56.623422 2026] [security2:error] [pid 512881:tid 513045] [client 20.48.250.41:64607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/lanka.php"] [unique_id "apPlVAi65Hcg2zUJjxBbcgAAAjY"]
[Sun Aug 30 03:09:56.650634 2026] [security2:error] [pid 512881:tid 513099] [client 20.104.50.220:29178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/WSO.php"] [unique_id "apPlVAi65Hcg2zUJjxBbeAAAAmw"]
[Sun Aug 30 03:09:56.657722 2026] [security2:error] [pid 512881:tid 513071] [client 20.48.250.41:38886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/thui.php"] [unique_id "apPlVAi65Hcg2zUJjxBbgQAAAlA"]
[Sun Aug 30 03:09:56.663455 2026] [security2:error] [pid 512881:tid 513046] [client 20.104.50.220:63541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/sel.php"] [unique_id "apPlVAi65Hcg2zUJjxBbgwAAAjc"]
[Sun Aug 30 03:09:56.677464 2026] [security2:error] [pid 512881:tid 513108] [client 20.104.50.220:29619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/mygagal.php"] [unique_id "apPlVAi65Hcg2zUJjxBbigAAAnU"]
[Sun Aug 30 03:09:56.700442 2026] [security2:error] [pid 512881:tid 513057] [client 20.63.81.20:36855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp-includes/pomo/xxx.php"] [unique_id "apPlVAi65Hcg2zUJjxBblgAAAkI"]
[Sun Aug 30 03:09:56.720165 2026] [security2:error] [pid 512881:tid 513071] [client 20.104.18.15:64790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/h.php"] [unique_id "apPlVAi65Hcg2zUJjxBbpwAAAlA"]
[Sun Aug 30 03:09:56.735072 2026] [security2:error] [pid 512881:tid 513117] [client 20.220.10.235:26584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/wefile.php"] [unique_id "apPlVAi65Hcg2zUJjxBbsgAAAn4"]
[Sun Aug 30 03:09:56.736235 2026] [security2:error] [pid 512881:tid 513124] [client 20.104.18.15:22406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/file1221.php"] [unique_id "apPlVAi65Hcg2zUJjxBbswAAAoU"]
[Sun Aug 30 03:09:56.739044 2026] [security2:error] [pid 512881:tid 513125] [client 158.23.147.79:42875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/NewFile.php/"] [unique_id "apPlVAi65Hcg2zUJjxBbtQAAAoY"]
[Sun Aug 30 03:09:56.744671 2026] [authz_core:error] [pid 512881:tid 513103] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:56.744737 2026] [security2:error] [pid 512881:tid 513025] [client 158.23.147.79:57685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apPlVAi65Hcg2zUJjxBbuQAAAiI"]
[Sun Aug 30 03:09:56.745072 2026] [authz_core:error] [pid 512881:tid 513103] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:56.752559 2026] [security2:error] [pid 512881:tid 513084] [client 4.205.62.107:17112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/xve22.php"] [unique_id "apPlVAi65Hcg2zUJjxBbugAAAl0"]
[Sun Aug 30 03:09:56.754325 2026] [security2:error] [pid 512881:tid 513030] [client 68.155.159.216:54283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/asd.php"] [unique_id "apPlVAi65Hcg2zUJjxBbvAAAAic"]
[Sun Aug 30 03:09:56.761877 2026] [security2:error] [pid 512881:tid 513132] [client 20.104.18.15:43320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/backup.php"] [unique_id "apPlVAi65Hcg2zUJjxBbvgAAAo0"]
[Sun Aug 30 03:09:56.773360 2026] [security2:error] [pid 512881:tid 513130] [client 40.83.93.50:17284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/upgrade-temp-backup/themes/test.php"] [unique_id "apPlVAi65Hcg2zUJjxBbwAAAAos"]
[Sun Aug 30 03:09:56.775711 2026] [security2:error] [pid 512881:tid 513099] [client 20.48.250.41:49822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/gettest.php"] [unique_id "apPlVAi65Hcg2zUJjxBbwQAAAmw"]
[Sun Aug 30 03:09:56.810828 2026] [security2:error] [pid 512881:tid 513133] [client 20.48.250.41:38823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/Jcrop.php"] [unique_id "apPlVAi65Hcg2zUJjxBb0AAAAo4"]
[Sun Aug 30 03:09:56.828190 2026] [security2:error] [pid 512881:tid 513013] [client 20.63.81.20:36835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/650.php"] [unique_id "apPlVAi65Hcg2zUJjxBb0wAAAhY"]
[Sun Aug 30 03:09:56.836113 2026] [security2:error] [pid 512881:tid 513127] [client 216.73.216.128:45437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_config_quote_replace_string"] [unique_id "apPlVAi65Hcg2zUJjxBb1QAAAog"]
[Sun Aug 30 03:09:56.842327 2026] [security2:error] [pid 512881:tid 513078] [client 20.48.251.3:13381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/debuggen.php"] [unique_id "apPlVAi65Hcg2zUJjxBb1gAAAlc"]
[Sun Aug 30 03:09:56.867094 2026] [security2:error] [pid 512881:tid 513025] [client 20.220.10.235:26613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/Contrller.php"] [unique_id "apPlVAi65Hcg2zUJjxBb4wAAAiI"]
[Sun Aug 30 03:09:56.875351 2026] [authz_core:error] [pid 512881:tid 513045] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:56.875452 2026] [security2:error] [pid 512881:tid 513060] [client 20.104.18.15:18325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPlVAi65Hcg2zUJjxBb7QAAAkU"]
[Sun Aug 30 03:09:56.875650 2026] [authz_core:error] [pid 512881:tid 513045] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:56.904751 2026] [security2:error] [pid 512881:tid 513013] [client 158.23.147.79:42872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/dropdown.php"] [unique_id "apPlVAi65Hcg2zUJjxBb9QAAAhY"]
[Sun Aug 30 03:09:56.913766 2026] [security2:error] [pid 512881:tid 513032] [client 20.48.250.41:64580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/35.php"] [unique_id "apPlVAi65Hcg2zUJjxBb-AAAAik"]
[Sun Aug 30 03:09:56.920797 2026] [security2:error] [pid 512881:tid 513077] [client 20.104.49.130:36785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/memberfuns.php"] [unique_id "apPlVAi65Hcg2zUJjxBb-QAAAlY"]
[Sun Aug 30 03:09:56.926473 2026] [security2:error] [pid 512881:tid 513033] [client 20.151.200.44:64147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/h02ugyh.php"] [unique_id "apPlVAi65Hcg2zUJjxBb-wAAAio"]
[Sun Aug 30 03:09:56.945639 2026] [security2:error] [pid 512881:tid 513030] [client 20.48.250.41:38911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/ws58.php"] [unique_id "apPlVAi65Hcg2zUJjxBcBgAAAic"]
[Sun Aug 30 03:09:56.955716 2026] [security2:error] [pid 512881:tid 513093] [client 20.63.81.20:36743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/nakrip.php"] [unique_id "apPlVAi65Hcg2zUJjxBcCQAAAmY"]
[Sun Aug 30 03:09:56.995533 2026] [security2:error] [pid 512881:tid 513094] [client 20.104.50.220:31918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/css.php"] [unique_id "apPlVAi65Hcg2zUJjxBcGwAAAmc"]
[Sun Aug 30 03:09:57.008828 2026] [security2:error] [pid 512881:tid 513078] [client 20.104.50.220:33296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/simattacker.php"] [unique_id "apPlVQi65Hcg2zUJjxBcIgAAAlc"]
[Sun Aug 30 03:09:57.010548 2026] [security2:error] [pid 512881:tid 513012] [client 20.220.10.235:26511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/file66.php"] [unique_id "apPlVQi65Hcg2zUJjxBcIwAAAhU"]
[Sun Aug 30 03:09:57.017975 2026] [security2:error] [pid 512881:tid 513106] [client 216.73.216.128:50920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPlVQi65Hcg2zUJjxBcJgAAAnM"]
[Sun Aug 30 03:09:57.037591 2026] [security2:error] [pid 512881:tid 513109] [client 20.104.49.130:43281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/berlin.php"] [unique_id "apPlVQi65Hcg2zUJjxBcLQAAAnY"]
[Sun Aug 30 03:09:57.047513 2026] [security2:error] [pid 512881:tid 513093] [client 20.48.251.3:7372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/old_phpinfo.php"] [unique_id "apPlVQi65Hcg2zUJjxBcMgAAAmY"]
[Sun Aug 30 03:09:57.054443 2026] [security2:error] [pid 512881:tid 513064] [client 20.48.250.41:64594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/maraz.php"] [unique_id "apPlVQi65Hcg2zUJjxBcNwAAAkk"]
[Sun Aug 30 03:09:57.063877 2026] [security2:error] [pid 512881:tid 513071] [client 158.23.147.79:41544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/.well-known/index.php"] [unique_id "apPlVQi65Hcg2zUJjxBcPQAAAlA"]
[Sun Aug 30 03:09:57.066318 2026] [authz_core:error] [pid 512881:tid 513077] [client 66.249.66.203:48534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:57.066636 2026] [authz_core:error] [pid 512881:tid 513077] [client 66.249.66.203:48534] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:57.086783 2026] [security2:error] [pid 512881:tid 513104] [client 20.63.81.20:36817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp-includes/interactivity-api/flower.php"] [unique_id "apPlVQi65Hcg2zUJjxBcRgAAAnE"]
[Sun Aug 30 03:09:57.089426 2026] [security2:error] [pid 512881:tid 513112] [client 20.48.250.41:38845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/xs.php"] [unique_id "apPlVQi65Hcg2zUJjxBcTQAAAnk"]
[Sun Aug 30 03:09:57.089634 2026] [security2:error] [pid 512881:tid 513127] [client 158.23.147.79:56474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apPlVQi65Hcg2zUJjxBcTAAAAog"]
[Sun Aug 30 03:09:57.095800 2026] [authz_core:error] [pid 512881:tid 513063] [client 66.249.66.75:38412] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:57.096161 2026] [authz_core:error] [pid 512881:tid 513063] [client 66.249.66.75:38412] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:57.137542 2026] [security2:error] [pid 512881:tid 513079] [client 20.48.251.3:65486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/xda.php"] [unique_id "apPlVQi65Hcg2zUJjxBcZwAAAlg"]
[Sun Aug 30 03:09:57.141204 2026] [security2:error] [pid 512881:tid 513019] [client 20.220.10.235:26616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/blnux.php"] [unique_id "apPlVQi65Hcg2zUJjxBcaQAAAhw"]
[Sun Aug 30 03:09:57.145187 2026] [security2:error] [pid 512881:tid 513029] [client 20.104.49.130:36780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/one.php"] [unique_id "apPlVQi65Hcg2zUJjxBcagAAAiY"]
[Sun Aug 30 03:09:57.158929 2026] [security2:error] [pid 512881:tid 513133] [client 158.23.147.79:41545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-content/themes/too.php"] [unique_id "apPlVQi65Hcg2zUJjxBcdgAAAo4"]
[Sun Aug 30 03:09:57.211962 2026] [security2:error] [pid 512881:tid 513071] [client 20.63.81.20:36837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/xcc.php"] [unique_id "apPlVQi65Hcg2zUJjxBclgAAAlA"]
[Sun Aug 30 03:09:57.214487 2026] [security2:error] [pid 512881:tid 513019] [client 20.48.250.41:49905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/kbfr.php"] [unique_id "apPlVQi65Hcg2zUJjxBclwAAAhw"]
[Sun Aug 30 03:09:57.217160 2026] [authz_core:error] [pid 512881:tid 513094] [client 66.249.66.66:43618] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:57.217430 2026] [authz_core:error] [pid 512881:tid 513094] [client 66.249.66.66:43618] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:57.241613 2026] [security2:error] [pid 512881:tid 513081] [client 40.83.93.50:17288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/upgrade-temp-backup/themes/wp-links-opml.php"] [unique_id "apPlVQi65Hcg2zUJjxBcoAAAAlo"]
[Sun Aug 30 03:09:57.247082 2026] [security2:error] [pid 512881:tid 513075] [client 20.48.250.41:38738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/zu.php"] [unique_id "apPlVQi65Hcg2zUJjxBcpgAAAlQ"]
[Sun Aug 30 03:09:57.275072 2026] [security2:error] [pid 512881:tid 513051] [client 20.220.10.235:26572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/attack.php"] [unique_id "apPlVQi65Hcg2zUJjxBctgAAAjw"]
[Sun Aug 30 03:09:57.291525 2026] [security2:error] [pid 512881:tid 513072] [client 158.23.147.79:42824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/radio.php"] [unique_id "apPlVQi65Hcg2zUJjxBcxAAAAlE"]
[Sun Aug 30 03:09:57.297086 2026] [security2:error] [pid 512881:tid 513052] [client 4.205.62.107:25745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/aww.php"] [unique_id "apPlVQi65Hcg2zUJjxBcxwAAAj0"]
[Sun Aug 30 03:09:57.297181 2026] [security2:error] [pid 512881:tid 513081] [client 4.205.62.107:64649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/test.php"] [unique_id "apPlVQi65Hcg2zUJjxBcyAAAAlo"]
[Sun Aug 30 03:09:57.313944 2026] [security2:error] [pid 512881:tid 513124] [client 20.104.49.130:52457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/samll.php"] [unique_id "apPlVQi65Hcg2zUJjxBc0QAAAoU"]
[Sun Aug 30 03:09:57.331337 2026] [security2:error] [pid 512881:tid 513065] [client 20.151.200.44:28637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/txets.php"] [unique_id "apPlVQi65Hcg2zUJjxBc1AAAAko"]
[Sun Aug 30 03:09:57.338303 2026] [security2:error] [pid 512881:tid 513015] [client 20.63.81.20:36847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp-includes/Text/Diff/Engine/aaa.php"] [unique_id "apPlVQi65Hcg2zUJjxBc1QAAAhg"]
[Sun Aug 30 03:09:57.342447 2026] [security2:error] [pid 512881:tid 513032] [client 20.48.250.41:49829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/wp-act.php"] [unique_id "apPlVQi65Hcg2zUJjxBc1gAAAik"]
[Sun Aug 30 03:09:57.370950 2026] [authz_core:error] [pid 512881:tid 513051] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:57.371245 2026] [authz_core:error] [pid 512881:tid 513051] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:57.373956 2026] [security2:error] [pid 512881:tid 513071] [client 20.104.50.220:5580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/backup.php"] [unique_id "apPlVQi65Hcg2zUJjxBc5gAAAlA"]
[Sun Aug 30 03:09:57.412072 2026] [security2:error] [pid 512881:tid 513107] [client 20.48.250.41:38755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/lanka.php"] [unique_id "apPlVQi65Hcg2zUJjxBc9wAAAnQ"]
[Sun Aug 30 03:09:57.428077 2026] [security2:error] [pid 512881:tid 513064] [client 20.104.50.220:17249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/install.php"] [unique_id "apPlVQi65Hcg2zUJjxBdAwAAAkk"]
[Sun Aug 30 03:09:57.428198 2026] [security2:error] [pid 512881:tid 513120] [client 20.104.18.15:16952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/av.php"] [unique_id "apPlVQi65Hcg2zUJjxBdAgAAAoE"]
[Sun Aug 30 03:09:57.430258 2026] [security2:error] [pid 512881:tid 513015] [client 20.220.10.235:26510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/wk/index.php"] [unique_id "apPlVQi65Hcg2zUJjxBdBQAAAhg"]
[Sun Aug 30 03:09:57.441129 2026] [security2:error] [pid 512881:tid 513057] [client 158.23.147.79:41595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPlVQi65Hcg2zUJjxBdDQAAAkI"]
[Sun Aug 30 03:09:57.467261 2026] [security2:error] [pid 512881:tid 513078] [client 20.63.81.20:36677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp-includes/style-engine/gecko-new.php"] [unique_id "apPlVQi65Hcg2zUJjxBdGAAAAlc"]
[Sun Aug 30 03:09:57.482255 2026] [security2:error] [pid 512881:tid 513090] [client 20.48.250.41:49864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/24.php"] [unique_id "apPlVQi65Hcg2zUJjxBdGwAAAmM"]
[Sun Aug 30 03:09:57.493184 2026] [security2:error] [pid 512881:tid 513012] [client 20.48.251.3:55692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/phpi.php"] [unique_id "apPlVQi65Hcg2zUJjxBdHgAAAhU"]
[Sun Aug 30 03:09:57.498379 2026] [security2:error] [pid 512881:tid 513120] [client 20.48.251.3:59500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/xin1.php"] [unique_id "apPlVQi65Hcg2zUJjxBdIAAAAoE"]
[Sun Aug 30 03:09:57.507908 2026] [security2:error] [pid 512881:tid 513075] [client 20.104.50.220:61419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/ids.php"] [unique_id "apPlVQi65Hcg2zUJjxBdJAAAAlQ"]
[Sun Aug 30 03:09:57.554849 2026] [security2:error] [pid 512881:tid 513132] [client 20.48.250.41:38853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/gettest.php"] [unique_id "apPlVQi65Hcg2zUJjxBdOwAAAo0"]
[Sun Aug 30 03:09:57.559562 2026] [security2:error] [pid 512881:tid 513104] [client 158.23.147.79:42849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/makeasmtp.php"] [unique_id "apPlVQi65Hcg2zUJjxBdPwAAAnE"]
[Sun Aug 30 03:09:57.579897 2026] [security2:error] [pid 512881:tid 513092] [client 20.104.18.15:35069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/v22.php"] [unique_id "apPlVQi65Hcg2zUJjxBdSgAAAmU"]
[Sun Aug 30 03:09:57.591329 2026] [security2:error] [pid 512881:tid 513058] [client 20.220.10.235:26585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/dehnl.php"] [unique_id "apPlVQi65Hcg2zUJjxBdUQAAAkM"]
[Sun Aug 30 03:09:57.599361 2026] [security2:error] [pid 512881:tid 513086] [client 20.63.81.20:36763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp-settings.php"] [unique_id "apPlVQi65Hcg2zUJjxBdVQAAAl8"]
[Sun Aug 30 03:09:57.628512 2026] [security2:error] [pid 512881:tid 513078] [client 20.48.250.41:49827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/155.php"] [unique_id "apPlVQi65Hcg2zUJjxBdagAAAlc"]
[Sun Aug 30 03:09:57.630165 2026] [security2:error] [pid 512881:tid 513047] [client 4.205.62.107:36696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/admin-ajax.php"] [unique_id "apPlVQi65Hcg2zUJjxBdbAAAAjg"]
[Sun Aug 30 03:09:57.662789 2026] [authz_core:error] [pid 512881:tid 513092] [client 216.73.216.128:13904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:57.663093 2026] [authz_core:error] [pid 512881:tid 513092] [client 216.73.216.128:13904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:57.668457 2026] [security2:error] [pid 512881:tid 513122] [client 158.23.147.79:10190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apPlVQi65Hcg2zUJjxBdfwAAAoM"]
[Sun Aug 30 03:09:57.709727 2026] [security2:error] [pid 512881:tid 513078] [client 20.104.50.220:50368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/201.php"] [unique_id "apPlVQi65Hcg2zUJjxBdmQAAAlc"]
[Sun Aug 30 03:09:57.711260 2026] [security2:error] [pid 512881:tid 513017] [client 40.83.93.50:17320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/upgrade-temp-backup/themes/wp-settings.php"] [unique_id "apPlVQi65Hcg2zUJjxBdmwAAAho"]
[Sun Aug 30 03:09:57.729874 2026] [security2:error] [pid 512881:tid 513026] [client 20.63.81.20:36747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp-signup.php"] [unique_id "apPlVQi65Hcg2zUJjxBdqAAAAiM"]
[Sun Aug 30 03:09:57.734344 2026] [security2:error] [pid 512881:tid 513110] [client 20.48.250.41:38903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/35.php"] [unique_id "apPlVQi65Hcg2zUJjxBdrQAAAnc"]
[Sun Aug 30 03:09:57.735854 2026] [security2:error] [pid 512881:tid 513093] [client 20.220.10.235:26507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/png.php"] [unique_id "apPlVQi65Hcg2zUJjxBdrwAAAmY"]
[Sun Aug 30 03:09:57.754750 2026] [authz_core:error] [pid 512881:tid 513106] [client 216.73.216.128:39800] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:57.755031 2026] [authz_core:error] [pid 512881:tid 513106] [client 216.73.216.128:39800] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:57.757975 2026] [security2:error] [pid 512881:tid 513121] [client 68.155.159.216:62625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPlVQi65Hcg2zUJjxBduQAAAoI"]
[Sun Aug 30 03:09:57.780001 2026] [security2:error] [pid 512881:tid 513048] [client 20.48.250.41:49809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/file.php"] [unique_id "apPlVQi65Hcg2zUJjxBdvwAAAjk"]
[Sun Aug 30 03:09:57.781958 2026] [security2:error] [pid 512881:tid 513074] [client 158.23.147.79:42841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apPlVQi65Hcg2zUJjxBdwQAAAlM"]
[Sun Aug 30 03:09:57.793569 2026] [security2:error] [pid 512881:tid 513029] [client 20.104.50.220:29582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/IndoXploit.php"] [unique_id "apPlVQi65Hcg2zUJjxBdxwAAAiY"]
[Sun Aug 30 03:09:57.801410 2026] [authz_core:error] [pid 512881:tid 513115] [client 66.249.66.45:47505] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:57.801837 2026] [authz_core:error] [pid 512881:tid 513115] [client 66.249.66.45:47505] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:57.804662 2026] [security2:error] [pid 512881:tid 513019] [client 20.104.50.220:42029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/14.php"] [unique_id "apPlVQi65Hcg2zUJjxBdzQAAAhw"]
[Sun Aug 30 03:09:57.818838 2026] [security2:error] [pid 512881:tid 513104] [client 20.104.50.220:62815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/manda.php"] [unique_id "apPlVQi65Hcg2zUJjxBd0AAAAnE"]
[Sun Aug 30 03:09:57.855063 2026] [security2:error] [pid 512881:tid 513133] [client 20.104.18.15:16766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/ano.php"] [unique_id "apPlVQi65Hcg2zUJjxBd2QAAAo4"]
[Sun Aug 30 03:09:57.857175 2026] [security2:error] [pid 512881:tid 513064] [client 20.63.81.20:36826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp-conffg.php"] [unique_id "apPlVQi65Hcg2zUJjxBd3AAAAkk"]
[Sun Aug 30 03:09:57.860725 2026] [security2:error] [pid 512881:tid 513032] [client 68.155.159.216:45970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-admin.php"] [unique_id "apPlVQi65Hcg2zUJjxBd4wAAAik"]
[Sun Aug 30 03:09:57.878757 2026] [security2:error] [pid 512881:tid 513027] [client 20.220.10.235:26597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/txets.php"] [unique_id "apPlVQi65Hcg2zUJjxBd8gAAAiQ"]
[Sun Aug 30 03:09:57.881669 2026] [authz_core:error] [pid 512881:tid 513094] [client 66.249.66.35:42266] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:57.882152 2026] [authz_core:error] [pid 512881:tid 513094] [client 66.249.66.35:42266] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:57.882172 2026] [security2:error] [pid 512881:tid 513034] [client 20.48.250.41:38899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/maraz.php"] [unique_id "apPlVQi65Hcg2zUJjxBd9gAAAis"]
[Sun Aug 30 03:09:57.885099 2026] [security2:error] [pid 512881:tid 513136] [client 20.104.18.15:22519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/nox.php"] [unique_id "apPlVQi65Hcg2zUJjxBd9wAAApE"]
[Sun Aug 30 03:09:57.901795 2026] [authz_core:error] [pid 512881:tid 513050] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:57.902111 2026] [authz_core:error] [pid 512881:tid 513050] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:57.905368 2026] [security2:error] [pid 512881:tid 513042] [client 4.205.62.107:17685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/06.php"] [unique_id "apPlVQi65Hcg2zUJjxBd_wAAAjM"]
[Sun Aug 30 03:09:57.918121 2026] [security2:error] [pid 512881:tid 513086] [client 20.48.250.41:49793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPlVQi65Hcg2zUJjxBeAwAAAl8"]
[Sun Aug 30 03:09:57.928417 2026] [security2:error] [pid 512881:tid 513066] [client 20.151.200.44:64146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/sf.php"] [unique_id "apPlVQi65Hcg2zUJjxBeBQAAAks"]
[Sun Aug 30 03:09:57.937495 2026] [security2:error] [pid 512881:tid 513105] [client 20.104.18.15:43987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/indo.php"] [unique_id "apPlVQi65Hcg2zUJjxBeCwAAAnI"]
[Sun Aug 30 03:09:57.944372 2026] [security2:error] [pid 512881:tid 513124] [client 158.23.147.79:42870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-content/languages/about.php"] [unique_id "apPlVQi65Hcg2zUJjxBeDwAAAoU"]
[Sun Aug 30 03:09:57.984285 2026] [security2:error] [pid 512881:tid 513076] [client 20.63.81.20:36801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp-validate.php"] [unique_id "apPlVQi65Hcg2zUJjxBeIwAAAlU"]
[Sun Aug 30 03:09:57.989385 2026] [security2:error] [pid 512881:tid 513058] [client 20.48.251.3:13411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/pouhg.php"] [unique_id "apPlVQi65Hcg2zUJjxBeJwAAAkM"]
[Sun Aug 30 03:09:58.009600 2026] [security2:error] [pid 512881:tid 513016] [client 20.220.10.235:26609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/wp-login.php"] [unique_id "apPlVgi65Hcg2zUJjxBeMwAAAhk"]
[Sun Aug 30 03:09:58.028477 2026] [security2:error] [pid 512881:tid 513128] [client 20.104.18.15:18413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/wsd.php"] [unique_id "apPlVgi65Hcg2zUJjxBePgAAAok"]
[Sun Aug 30 03:09:58.029925 2026] [authz_core:error] [pid 512881:tid 513020] [client 66.249.66.65:55787] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:58.030376 2026] [authz_core:error] [pid 512881:tid 513020] [client 66.249.66.65:55787] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:58.031217 2026] [security2:error] [pid 512881:tid 513054] [client 20.48.250.41:38814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/kbfr.php"] [unique_id "apPlVgi65Hcg2zUJjxBePwAAAj8"]
[Sun Aug 30 03:09:58.048349 2026] [security2:error] [pid 512881:tid 513046] [client 20.48.250.41:49876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/06.php"] [unique_id "apPlVgi65Hcg2zUJjxBeRwAAAjc"]
[Sun Aug 30 03:09:58.082700 2026] [security2:error] [pid 512881:tid 513052] [client 158.23.147.79:41562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-content/banners/about.php"] [unique_id "apPlVgi65Hcg2zUJjxBeUwAAAj0"]
[Sun Aug 30 03:09:58.112222 2026] [security2:error] [pid 512881:tid 513120] [client 20.63.81.20:36753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/700.php"] [unique_id "apPlVgi65Hcg2zUJjxBeYgAAAoE"]
[Sun Aug 30 03:09:58.139541 2026] [security2:error] [pid 512881:tid 513117] [client 20.220.10.235:26568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/wp-access.php"] [unique_id "apPlVgi65Hcg2zUJjxBecwAAAn4"]
[Sun Aug 30 03:09:58.145473 2026] [security2:error] [pid 512881:tid 513103] [client 20.104.50.220:33341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wsoshell.php"] [unique_id "apPlVgi65Hcg2zUJjxBedAAAAnA"]
[Sun Aug 30 03:09:58.168406 2026] [security2:error] [pid 512881:tid 513084] [client 20.104.50.220:31877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/ioxi-o.php"] [unique_id "apPlVgi65Hcg2zUJjxBehAAAAl0"]
[Sun Aug 30 03:09:58.169134 2026] [authz_core:error] [pid 512881:tid 513061] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:58.169420 2026] [authz_core:error] [pid 512881:tid 513061] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:58.180589 2026] [security2:error] [pid 512881:tid 513097] [client 20.48.250.41:38811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/wp-act.php"] [unique_id "apPlVgi65Hcg2zUJjxBekAAAAmo"]
[Sun Aug 30 03:09:58.188639 2026] [core:error] [pid 512881:tid 513091] [client 40.83.93.50:17963] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:09:58.188672 2026] [core:error] [pid 512881:tid 513091] [client 40.83.93.50:17963] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:09:58.193235 2026] [security2:error] [pid 512881:tid 513098] [client 20.48.250.41:49800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/class.php"] [unique_id "apPlVgi65Hcg2zUJjxBemQAAAms"]
[Sun Aug 30 03:09:58.198439 2026] [security2:error] [pid 512881:tid 513025] [client 20.48.251.3:64501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cxgates.com"] [uri "/wp-act.php"] [unique_id "apPlVgi65Hcg2zUJjxBenAAAAiI"]
[Sun Aug 30 03:09:58.205446 2026] [security2:error] [pid 512881:tid 513112] [client 68.155.159.216:54312] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.coolreels.com"] [uri "/1.php"] [unique_id "apPlVgi65Hcg2zUJjxBeoAAAAnk"]
[Sun Aug 30 03:09:58.205532 2026] [security2:error] [pid 512881:tid 513112] [client 68.155.159.216:54312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/1.php"] [unique_id "apPlVgi65Hcg2zUJjxBeoAAAAnk"]
[Sun Aug 30 03:09:58.216986 2026] [security2:error] [pid 512881:tid 513052] [client 20.104.49.130:63235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/txets.php"] [unique_id "apPlVgi65Hcg2zUJjxBeogAAAj0"]
[Sun Aug 30 03:09:58.244172 2026] [security2:error] [pid 512881:tid 513101] [client 20.63.81.20:36749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/c4.php"] [unique_id "apPlVgi65Hcg2zUJjxBerQAAAm4"]
[Sun Aug 30 03:09:58.253322 2026] [authz_core:error] [pid 512881:tid 513124] [client 66.249.66.43:62039] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:58.253621 2026] [authz_core:error] [pid 512881:tid 513124] [client 66.249.66.43:62039] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:58.257700 2026] [security2:error] [pid 512881:tid 513116] [client 158.23.147.79:42861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apPlVgi65Hcg2zUJjxBesgAAAn0"]
[Sun Aug 30 03:09:58.271304 2026] [security2:error] [pid 512881:tid 513136] [client 20.220.10.235:26503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/wp-content/admin.php"] [unique_id "apPlVgi65Hcg2zUJjxBevQAAApE"]
[Sun Aug 30 03:09:58.296365 2026] [security2:error] [pid 512881:tid 513112] [client 20.48.251.3:54785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/pinfo.php"] [unique_id "apPlVgi65Hcg2zUJjxBeywAAAnk"]
[Sun Aug 30 03:09:58.308817 2026] [security2:error] [pid 512881:tid 513126] [client 20.48.250.41:38732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/24.php"] [unique_id "apPlVgi65Hcg2zUJjxBe1AAAAoc"]
[Sun Aug 30 03:09:58.335665 2026] [security2:error] [pid 512881:tid 513116] [client 20.48.250.41:49878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/8.php"] [unique_id "apPlVgi65Hcg2zUJjxBe2wAAAn0"]
[Sun Aug 30 03:09:58.340682 2026] [security2:error] [pid 512881:tid 513034] [client 20.151.200.44:41957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/wefile.php"] [unique_id "apPlVgi65Hcg2zUJjxBe3gAAAis"]
[Sun Aug 30 03:09:58.368623 2026] [authz_core:error] [pid 512881:tid 513058] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:58.369097 2026] [authz_core:error] [pid 512881:tid 513058] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:58.369453 2026] [security2:error] [pid 512881:tid 513091] [client 20.63.81.20:36756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp-tymanage.php"] [unique_id "apPlVgi65Hcg2zUJjxBe7QAAAmQ"]
[Sun Aug 30 03:09:58.404017 2026] [security2:error] [pid 512881:tid 513050] [client 20.220.10.235:26575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/log.php"] [unique_id "apPlVgi65Hcg2zUJjxBfBAAAAjs"]
[Sun Aug 30 03:09:58.429128 2026] [security2:error] [pid 512881:tid 513037] [client 158.23.147.79:42827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/asd.php"] [unique_id "apPlVgi65Hcg2zUJjxBfDAAAAi4"]
[Sun Aug 30 03:09:58.437948 2026] [security2:error] [pid 512881:tid 513026] [client 4.205.62.107:25919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/maxro.php"] [unique_id "apPlVgi65Hcg2zUJjxBfDgAAAiM"]
[Sun Aug 30 03:09:58.449199 2026] [security2:error] [pid 512881:tid 513084] [client 20.48.250.41:38883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/155.php"] [unique_id "apPlVgi65Hcg2zUJjxBfEgAAAl0"]
[Sun Aug 30 03:09:58.452957 2026] [security2:error] [pid 512881:tid 513111] [client 4.205.62.107:61779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/cloud.php"] [unique_id "apPlVgi65Hcg2zUJjxBfEwAAAng"]
[Sun Aug 30 03:09:58.475957 2026] [security2:error] [pid 512881:tid 513115] [client 20.48.250.41:49869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/0x0x.php"] [unique_id "apPlVgi65Hcg2zUJjxBfHQAAAnw"]
[Sun Aug 30 03:09:58.506028 2026] [security2:error] [pid 512881:tid 513106] [client 20.63.81.20:36738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/ajfto.php"] [unique_id "apPlVgi65Hcg2zUJjxBfKgAAAnM"]
[Sun Aug 30 03:09:58.527171 2026] [security2:error] [pid 512881:tid 513032] [client 20.104.50.220:5933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/pwnd.php"] [unique_id "apPlVgi65Hcg2zUJjxBfMAAAAik"]
[Sun Aug 30 03:09:58.540087 2026] [security2:error] [pid 512881:tid 513038] [client 158.23.147.79:42818] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cwsennalmp.com"] [uri "/1.php"] [unique_id "apPlVgi65Hcg2zUJjxBfNwAAAi8"]
[Sun Aug 30 03:09:58.540214 2026] [security2:error] [pid 512881:tid 513038] [client 158.23.147.79:42818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/1.php"] [unique_id "apPlVgi65Hcg2zUJjxBfNwAAAi8"]
[Sun Aug 30 03:09:58.559915 2026] [security2:error] [pid 512881:tid 513105] [client 20.104.50.220:17300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/lv.php"] [unique_id "apPlVgi65Hcg2zUJjxBfRgAAAnI"]
[Sun Aug 30 03:09:58.569663 2026] [security2:error] [pid 512881:tid 513088] [client 20.220.10.235:26576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/xwpg.php"] [unique_id "apPlVgi65Hcg2zUJjxBfSQAAAmE"]
[Sun Aug 30 03:09:58.571163 2026] [security2:error] [pid 512881:tid 513056] [client 20.104.18.15:16913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/images.php"] [unique_id "apPlVgi65Hcg2zUJjxBfTQAAAkE"]
[Sun Aug 30 03:09:58.602414 2026] [security2:error] [pid 512881:tid 513017] [client 20.48.250.41:64603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/166.php"] [unique_id "apPlVgi65Hcg2zUJjxBfWQAAAho"]
[Sun Aug 30 03:09:58.603187 2026] [authz_core:error] [pid 512881:tid 513026] [client 66.249.66.73:60601] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:58.603640 2026] [authz_core:error] [pid 512881:tid 513026] [client 66.249.66.73:60601] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:58.609296 2026] [security2:error] [pid 512881:tid 513070] [client 20.48.250.41:38907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/file.php"] [unique_id "apPlVgi65Hcg2zUJjxBfXwAAAk8"]
[Sun Aug 30 03:09:58.613593 2026] [security2:error] [pid 512881:tid 513138] [client 167.99.236.220:34418] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ((?:submit(?:\\\\+| )?(request)?(?:\\\\+| )?>+|<<(?:\\\\+| )remove|(?:sign ?in|log ?(?:in|out)|next|modifier|envoyer|add|continue|weiter|account|results|select)(?:\\\\+| )?>+)$|^< ?\\\\??(?: |\\\\+)?xml|^> ?$)" against "ARGS:state" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1093"] [id "350147"] [rev "155"] [msg "Atomicorp.com WAF Rules: Potentially Untrusted Web Content Detected"] [severity "CRITICAL"] [hostname "secure3166.hostgator.com"] [uri "/callback"] [unique_id "apPlVgi65Hcg2zUJjxBfYAAAApM"]
[Sun Aug 30 03:09:58.638300 2026] [security2:error] [pid 512881:tid 513084] [client 20.48.251.3:59848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/sadd.php"] [unique_id "apPlVgi65Hcg2zUJjxBfagAAAl0"]
[Sun Aug 30 03:09:58.643781 2026] [security2:error] [pid 512881:tid 513042] [client 20.63.81.20:36763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp_KwIW0U5F.php"] [unique_id "apPlVgi65Hcg2zUJjxBfbgAAAjM"]
[Sun Aug 30 03:09:58.659461 2026] [security2:error] [pid 512881:tid 513076] [client 20.48.251.3:59387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "apPlVgi65Hcg2zUJjxBfdAAAAlU"]
[Sun Aug 30 03:09:58.660999 2026] [security2:error] [pid 512881:tid 513056] [client 20.104.50.220:63033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/idx.php"] [unique_id "apPlVgi65Hcg2zUJjxBfdwAAAkE"]
[Sun Aug 30 03:09:58.661080 2026] [security2:error] [pid 512881:tid 513126] [client 40.83.93.50:17958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/upgrade/about.php"] [unique_id "apPlVgi65Hcg2zUJjxBfdgAAAoc"]
[Sun Aug 30 03:09:58.670252 2026] [authz_core:error] [pid 512881:tid 513044] [client 66.249.66.40:64345] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:58.670528 2026] [authz_core:error] [pid 512881:tid 513044] [client 66.249.66.40:64345] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:58.709352 2026] [security2:error] [pid 512881:tid 513018] [client 20.220.10.235:26621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/sxxb.php"] [unique_id "apPlVgi65Hcg2zUJjxBflQAAAhs"]
[Sun Aug 30 03:09:58.730041 2026] [security2:error] [pid 512881:tid 513135] [client 20.104.18.15:35140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/wp-activate.php"] [unique_id "apPlVgi65Hcg2zUJjxBfpwAAApA"]
[Sun Aug 30 03:09:58.741866 2026] [security2:error] [pid 512881:tid 513109] [client 20.48.250.41:49833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/h2a2ck.php"] [unique_id "apPlVgi65Hcg2zUJjxBfqgAAAnY"]
[Sun Aug 30 03:09:58.772075 2026] [security2:error] [pid 512881:tid 513106] [client 158.23.147.79:42862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/ws.php"] [unique_id "apPlVgi65Hcg2zUJjxBftQAAAnM"]
[Sun Aug 30 03:09:58.772099 2026] [security2:error] [pid 512881:tid 513127] [client 4.205.62.107:36019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/ms.php"] [unique_id "apPlVgi65Hcg2zUJjxBfswAAAog"]
[Sun Aug 30 03:09:58.772137 2026] [security2:error] [pid 512881:tid 513130] [client 20.63.81.20:36841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp_xiPu52Ut.php"] [unique_id "apPlVgi65Hcg2zUJjxBftAAAAos"]
[Sun Aug 30 03:09:58.780263 2026] [security2:error] [pid 512881:tid 513107] [client 20.104.49.130:45700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/init.php"] [unique_id "apPlVgi65Hcg2zUJjxBfugAAAnQ"]
[Sun Aug 30 03:09:58.785092 2026] [security2:error] [pid 512881:tid 513137] [client 20.48.250.41:38723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPlVgi65Hcg2zUJjxBfvgAAApI"]
[Sun Aug 30 03:09:58.803172 2026] [authz_core:error] [pid 512881:tid 513016] [client 66.249.66.196:36059] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:58.803653 2026] [authz_core:error] [pid 512881:tid 513016] [client 66.249.66.196:36059] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:58.839862 2026] [security2:error] [pid 512881:tid 513109] [client 20.220.10.235:26496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/dx.php"] [unique_id "apPlVgi65Hcg2zUJjxBf0wAAAnY"]
[Sun Aug 30 03:09:58.841788 2026] [security2:error] [pid 512881:tid 513112] [client 216.73.216.128:7213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts2/updateconf"] [unique_id "apPlVgi65Hcg2zUJjxBf1AAAAnk"]
[Sun Aug 30 03:09:58.844748 2026] [security2:error] [pid 512881:tid 513098] [client 20.104.50.220:59726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/ops.php"] [unique_id "apPlVgi65Hcg2zUJjxBf1wAAAms"]
[Sun Aug 30 03:09:58.867580 2026] [security2:error] [pid 512881:tid 513046] [client 68.155.159.216:62599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apPlVgi65Hcg2zUJjxBf6gAAAjc"]
[Sun Aug 30 03:09:58.867826 2026] [security2:error] [pid 512881:tid 513051] [client 20.48.250.41:49848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/error_log.php"] [unique_id "apPlVgi65Hcg2zUJjxBf6wAAAjw"]
[Sun Aug 30 03:09:58.881338 2026] [authz_core:error] [pid 512881:tid 513037] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:58.881675 2026] [authz_core:error] [pid 512881:tid 513037] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:58.900754 2026] [security2:error] [pid 512881:tid 513120] [client 20.63.81.20:36763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp_n5VD7XDh.php"] [unique_id "apPlVgi65Hcg2zUJjxBf_AAAAoE"]
[Sun Aug 30 03:09:58.940000 2026] [security2:error] [pid 512881:tid 513059] [client 20.104.50.220:52852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/bajingan.php"] [unique_id "apPlVgi65Hcg2zUJjxBgDAAAAkQ"]
[Sun Aug 30 03:09:58.941051 2026] [security2:error] [pid 512881:tid 513052] [client 20.48.250.41:38904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/06.php"] [unique_id "apPlVgi65Hcg2zUJjxBgDQAAAj0"]
[Sun Aug 30 03:09:58.942730 2026] [security2:error] [pid 512881:tid 513111] [client 20.104.49.130:36794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/tiny2.php"] [unique_id "apPlVgi65Hcg2zUJjxBgDwAAAng"]
[Sun Aug 30 03:09:58.950335 2026] [security2:error] [pid 512881:tid 513025] [client 20.104.50.220:63506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/about.php"] [unique_id "apPlVgi65Hcg2zUJjxBgEwAAAiI"]
[Sun Aug 30 03:09:58.950797 2026] [security2:error] [pid 512881:tid 513130] [client 20.104.49.130:52451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/images.php"] [unique_id "apPlVgi65Hcg2zUJjxBgFAAAAos"]
[Sun Aug 30 03:09:58.971300 2026] [security2:error] [pid 512881:tid 513056] [client 20.220.10.235:26590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPlVgi65Hcg2zUJjxBgHwAAAkE"]
[Sun Aug 30 03:09:58.980814 2026] [security2:error] [pid 512881:tid 513113] [client 20.104.50.220:29128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/pmemek.php"] [unique_id "apPlVgi65Hcg2zUJjxBgJwAAAno"]
[Sun Aug 30 03:09:58.988666 2026] [security2:error] [pid 512881:tid 513104] [client 20.104.49.130:36765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/abcd.php"] [unique_id "apPlVgi65Hcg2zUJjxBgKQAAAnE"]
[Sun Aug 30 03:09:58.991159 2026] [security2:error] [pid 512881:tid 513042] [client 68.155.159.216:45989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-includes/assets/index.php"] [unique_id "apPlVgi65Hcg2zUJjxBgKwAAAjM"]
[Sun Aug 30 03:09:58.996901 2026] [security2:error] [pid 512881:tid 513128] [client 20.104.18.15:64871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/ai.php"] [unique_id "apPlVgi65Hcg2zUJjxBgMAAAAok"]
[Sun Aug 30 03:09:59.012104 2026] [security2:error] [pid 512881:tid 513019] [client 158.23.147.79:41580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-includes/css/index.php"] [unique_id "apPlVwi65Hcg2zUJjxBgNAAAAhw"]
[Sun Aug 30 03:09:59.012586 2026] [security2:error] [pid 512881:tid 513035] [client 20.48.250.41:64579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/403.php"] [unique_id "apPlVwi65Hcg2zUJjxBgNgAAAiw"]
[Sun Aug 30 03:09:59.032192 2026] [security2:error] [pid 512881:tid 513091] [client 20.63.81.20:36846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp-mini.php"] [unique_id "apPlVwi65Hcg2zUJjxBgQQAAAmQ"]
[Sun Aug 30 03:09:59.038506 2026] [security2:error] [pid 512881:tid 513111] [client 4.205.62.107:17664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/xin1.php"] [unique_id "apPlVwi65Hcg2zUJjxBgRAAAAng"]
[Sun Aug 30 03:09:59.046427 2026] [security2:error] [pid 512881:tid 513124] [client 20.104.18.15:22411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/akismet.php"] [unique_id "apPlVwi65Hcg2zUJjxBgRwAAAoU"]
[Sun Aug 30 03:09:59.078070 2026] [security2:error] [pid 512881:tid 513042] [client 20.104.18.15:43978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/sign.php"] [unique_id "apPlVwi65Hcg2zUJjxBgVQAAAjM"]
[Sun Aug 30 03:09:59.079611 2026] [security2:error] [pid 512881:tid 513128] [client 20.151.200.44:64723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/4e.php"] [unique_id "apPlVwi65Hcg2zUJjxBgVwAAAok"]
[Sun Aug 30 03:09:59.099425 2026] [security2:error] [pid 512881:tid 513060] [client 20.48.250.41:38821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/class.php"] [unique_id "apPlVwi65Hcg2zUJjxBgZgAAAkU"]
[Sun Aug 30 03:09:59.100530 2026] [security2:error] [pid 512881:tid 513109] [client 20.220.10.235:26570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/xda.php"] [unique_id "apPlVwi65Hcg2zUJjxBgaQAAAnY"]
[Sun Aug 30 03:09:59.127986 2026] [security2:error] [pid 512881:tid 513081] [client 20.48.251.3:60542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/phpversion.php"] [unique_id "apPlVwi65Hcg2zUJjxBgeAAAAlo"]
[Sun Aug 30 03:09:59.146937 2026] [security2:error] [pid 512881:tid 513065] [client 40.83.93.50:17296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaysbusservice.deevosdesigns.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "apPlVwi65Hcg2zUJjxBgfQAAAko"]
[Sun Aug 30 03:09:59.159063 2026] [security2:error] [pid 512881:tid 513130] [client 20.48.250.41:64622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/cytyr.php"] [unique_id "apPlVwi65Hcg2zUJjxBghQAAAos"]
[Sun Aug 30 03:09:59.159894 2026] [security2:error] [pid 512881:tid 513050] [client 20.63.81.20:36745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/xmini4.php"] [unique_id "apPlVwi65Hcg2zUJjxBgiAAAAjs"]
[Sun Aug 30 03:09:59.179192 2026] [authz_core:error] [pid 512881:tid 513127] [client 66.249.66.40:62459] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:59.179512 2026] [authz_core:error] [pid 512881:tid 513127] [client 66.249.66.40:62459] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:59.226094 2026] [lsapi:warn] [pid 512881:tid 513032] [client 43.119.100.92:45433] [host tastylandscape.com] Backend log: PHP Warning: Use of undefined constant user_level - assumed 'user_level' (this will throw an Error in a future version of PHP) in /home4/tommed/public_html/wp-content/plugins/ultimate-google-analytics/ultimate_ga.php on line 524\n, referer: https://tastylandscape.com/2014/11/29/best-way-propagate-geranium/
[Sun Aug 30 03:09:59.229462 2026] [security2:error] [pid 512881:tid 513031] [client 20.220.10.235:26604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPlVwi65Hcg2zUJjxBgrwAAAig"]
[Sun Aug 30 03:09:59.257935 2026] [security2:error] [pid 512881:tid 513112] [client 20.104.18.15:18418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/bulet.php"] [unique_id "apPlVwi65Hcg2zUJjxBgvwAAAnk"]
[Sun Aug 30 03:09:59.260735 2026] [security2:error] [pid 512881:tid 513030] [client 20.104.49.130:52126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/samll.php"] [unique_id "apPlVwi65Hcg2zUJjxBgwQAAAic"]
[Sun Aug 30 03:09:59.284920 2026] [security2:error] [pid 512881:tid 513055] [client 20.63.81.20:36799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/reop3.php"] [unique_id "apPlVwi65Hcg2zUJjxBg0QAAAkA"]
[Sun Aug 30 03:09:59.287949 2026] [security2:error] [pid 512881:tid 513088] [client 20.104.50.220:32888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/autoload_classmap.php"] [unique_id "apPlVwi65Hcg2zUJjxBg1QAAAmE"]
[Sun Aug 30 03:09:59.293553 2026] [security2:error] [pid 512881:tid 513121] [client 20.48.250.41:49796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/galer.php"] [unique_id "apPlVwi65Hcg2zUJjxBg2AAAAoI"]
[Sun Aug 30 03:09:59.294342 2026] [security2:error] [pid 512881:tid 513075] [client 20.48.250.41:38825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/8.php"] [unique_id "apPlVwi65Hcg2zUJjxBg2QAAAlQ"]
[Sun Aug 30 03:09:59.300894 2026] [security2:error] [pid 512881:tid 513078] [client 158.23.147.79:10199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apPlVwi65Hcg2zUJjxBg3gAAAlc"]
[Sun Aug 30 03:09:59.320328 2026] [authz_core:error] [pid 512881:tid 513086] [client 66.249.66.65:55787] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:59.320607 2026] [authz_core:error] [pid 512881:tid 513086] [client 66.249.66.65:55787] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:59.331653 2026] [security2:error] [pid 512881:tid 513118] [client 20.104.49.130:43293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/makeasmtp.php"] [unique_id "apPlVwi65Hcg2zUJjxBg5wAAAn8"]
[Sun Aug 30 03:09:59.351021 2026] [security2:error] [pid 512881:tid 513040] [client 20.104.50.220:31829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/classwithtostring.php"] [unique_id "apPlVwi65Hcg2zUJjxBg7AAAAjE"]
[Sun Aug 30 03:09:59.361172 2026] [security2:error] [pid 512881:tid 513038] [client 20.220.10.235:26615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/t00l.php"] [unique_id "apPlVwi65Hcg2zUJjxBg8AAAAi8"]
[Sun Aug 30 03:09:59.376450 2026] [authz_core:error] [pid 512881:tid 513130] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:59.376914 2026] [authz_core:error] [pid 512881:tid 513130] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:59.413521 2026] [security2:error] [pid 512881:tid 513120] [client 20.63.81.20:36828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp-mail.php"] [unique_id "apPlVwi65Hcg2zUJjxBhCwAAAoE"]
[Sun Aug 30 03:09:59.431501 2026] [security2:error] [pid 512881:tid 513020] [client 20.48.250.41:38875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/0x0x.php"] [unique_id "apPlVwi65Hcg2zUJjxBhFQAAAh0"]
[Sun Aug 30 03:09:59.453586 2026] [security2:error] [pid 512881:tid 513025] [client 20.48.250.41:64611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/baixy.php"] [unique_id "apPlVwi65Hcg2zUJjxBhHAAAAiI"]
[Sun Aug 30 03:09:59.484275 2026] [security2:error] [pid 512881:tid 513137] [client 20.104.49.130:53787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/ccc.php"] [unique_id "apPlVwi65Hcg2zUJjxBhJgAAApI"]
[Sun Aug 30 03:09:59.488491 2026] [security2:error] [pid 512881:tid 513032] [client 20.48.251.3:64318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/X57.php"] [unique_id "apPlVwi65Hcg2zUJjxBhJwAAAik"]
[Sun Aug 30 03:09:59.510539 2026] [security2:error] [pid 512881:tid 513093] [client 20.220.10.235:26508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/ls.php"] [unique_id "apPlVwi65Hcg2zUJjxBhLAAAAmY"]
[Sun Aug 30 03:09:59.534235 2026] [security2:error] [pid 512881:tid 513055] [client 158.23.147.79:42874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-content/cong.php"] [unique_id "apPlVwi65Hcg2zUJjxBhMAAAAkA"]
[Sun Aug 30 03:09:59.538794 2026] [security2:error] [pid 512881:tid 513108] [client 20.63.81.20:36795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp-conffg.php"] [unique_id "apPlVwi65Hcg2zUJjxBhNAAAAnU"]
[Sun Aug 30 03:09:59.563861 2026] [security2:error] [pid 512881:tid 513118] [client 20.48.250.41:38788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/166.php"] [unique_id "apPlVwi65Hcg2zUJjxBhRQAAAn8"]
[Sun Aug 30 03:09:59.577677 2026] [authz_core:error] [pid 512881:tid 513056] [client 216.73.216.128:28503] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:59.577973 2026] [authz_core:error] [pid 512881:tid 513056] [client 216.73.216.128:28503] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:59.583142 2026] [security2:error] [pid 512881:tid 513074] [client 20.48.250.41:49882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/ava.php"] [unique_id "apPlVwi65Hcg2zUJjxBhUQAAAlM"]
[Sun Aug 30 03:09:59.585465 2026] [security2:error] [pid 512881:tid 513051] [client 4.205.62.107:25889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/brc.php"] [unique_id "apPlVwi65Hcg2zUJjxBhVAAAAjw"]
[Sun Aug 30 03:09:59.609906 2026] [security2:error] [pid 512881:tid 513030] [client 20.104.49.130:58074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/wen.php"] [unique_id "apPlVwi65Hcg2zUJjxBhYwAAAic"]
[Sun Aug 30 03:09:59.620879 2026] [security2:error] [pid 512881:tid 513108] [client 4.205.62.107:61787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/asdf.php"] [unique_id "apPlVwi65Hcg2zUJjxBhagAAAnU"]
[Sun Aug 30 03:09:59.624615 2026] [authz_core:error] [pid 512881:tid 513138] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:59.624937 2026] [authz_core:error] [pid 512881:tid 513138] [client 74.7.227.8:46944] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:09:59.655122 2026] [security2:error] [pid 512881:tid 513042] [client 20.220.10.235:26605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/css/000.php"] [unique_id "apPlVwi65Hcg2zUJjxBhfAAAAjM"]
[Sun Aug 30 03:09:59.659594 2026] [security2:error] [pid 512881:tid 513059] [client 20.151.200.44:64792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/ssss.php"] [unique_id "apPlVwi65Hcg2zUJjxBhfgAAAkQ"]
[Sun Aug 30 03:09:59.678468 2026] [security2:error] [pid 512881:tid 513106] [client 20.63.81.20:36740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/filefuns.php"] [unique_id "apPlVwi65Hcg2zUJjxBhiAAAAnM"]
[Sun Aug 30 03:09:59.698765 2026] [security2:error] [pid 512881:tid 513017] [client 20.104.50.220:16624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/simple.php"] [unique_id "apPlVwi65Hcg2zUJjxBhkwAAAho"]
[Sun Aug 30 03:09:59.720357 2026] [security2:error] [pid 512881:tid 513088] [client 20.48.250.41:38867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/h2a2ck.php"] [unique_id "apPlVwi65Hcg2zUJjxBhrgAAAmE"]
[Sun Aug 30 03:09:59.725798 2026] [security2:error] [pid 512881:tid 513081] [client 20.48.250.41:49839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/gdn.php"] [unique_id "apPlVwi65Hcg2zUJjxBhsgAAAlo"]
[Sun Aug 30 03:09:59.726740 2026] [security2:error] [pid 512881:tid 513035] [client 20.104.18.15:16932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/ops.php"] [unique_id "apPlVwi65Hcg2zUJjxBhtAAAAiw"]
[Sun Aug 30 03:09:59.727021 2026] [security2:error] [pid 512881:tid 513131] [client 20.151.200.44:28480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/wp-login.php"] [unique_id "apPlVwi65Hcg2zUJjxBhmAAAAow"]
[Sun Aug 30 03:09:59.733138 2026] [security2:error] [pid 512881:tid 513114] [client 20.104.50.220:5533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/root.php"] [unique_id "apPlVwi65Hcg2zUJjxBhuQAAAns"]
[Sun Aug 30 03:09:59.739054 2026] [security2:error] [pid 512881:tid 512909] [remote 52.167.144.182:19405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themesslab.com"] [uri "/index.php/2016/10/04/lion-king-casino/"] [unique_id "apPlVwi65Hcg2zUJjxBhswACcxs"]
[Sun Aug 30 03:09:59.786285 2026] [security2:error] [pid 512881:tid 513012] [client 20.220.10.235:26600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/cy.php"] [unique_id "apPlVwi65Hcg2zUJjxBhyQAAAhU"]
[Sun Aug 30 03:09:59.792884 2026] [security2:error] [pid 512881:tid 513082] [client 20.48.251.3:59461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/application.config.php"] [unique_id "apPlVwi65Hcg2zUJjxBhzAAAAls"]
[Sun Aug 30 03:09:59.796193 2026] [security2:error] [pid 512881:tid 513026] [client 20.48.251.3:59274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/myfile.php"] [unique_id "apPlVwi65Hcg2zUJjxBhzgAAAiM"]
[Sun Aug 30 03:09:59.805982 2026] [security2:error] [pid 512881:tid 513111] [client 158.23.147.79:42848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPlVwi65Hcg2zUJjxBh0wAAAng"]
[Sun Aug 30 03:09:59.809764 2026] [security2:error] [pid 512881:tid 513088] [client 20.104.50.220:61996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/init.php"] [unique_id "apPlVwi65Hcg2zUJjxBh1gAAAmE"]
[Sun Aug 30 03:09:59.812824 2026] [security2:error] [pid 512881:tid 513065] [client 20.63.81.20:36808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp-cron.php"] [unique_id "apPlVwi65Hcg2zUJjxBh1wAAAko"]
[Sun Aug 30 03:09:59.853431 2026] [authz_core:error] [pid 512881:tid 513124] [client 216.73.216.128:13904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:59.853702 2026] [authz_core:error] [pid 512881:tid 513124] [client 216.73.216.128:13904] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:59.873071 2026] [security2:error] [pid 512881:tid 513038] [client 20.48.250.41:64521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/f2.php"] [unique_id "apPlVwi65Hcg2zUJjxBh8gAAAi8"]
[Sun Aug 30 03:09:59.874133 2026] [security2:error] [pid 512881:tid 513029] [client 20.104.18.15:35172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/wp-trackback.php"] [unique_id "apPlVwi65Hcg2zUJjxBh9AAAAiY"]
[Sun Aug 30 03:09:59.881246 2026] [security2:error] [pid 512881:tid 513039] [client 20.151.200.44:64790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/zoz.php"] [unique_id "apPlVwi65Hcg2zUJjxBh-AAAAjA"]
[Sun Aug 30 03:09:59.899038 2026] [security2:error] [pid 512881:tid 513103] [client 20.48.250.41:38847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/error_log.php"] [unique_id "apPlVwi65Hcg2zUJjxBh_wAAAnA"]
[Sun Aug 30 03:09:59.904021 2026] [authz_core:error] [pid 512881:tid 513117] [client 66.249.66.34:49802] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:59.904465 2026] [authz_core:error] [pid 512881:tid 513117] [client 66.249.66.34:49802] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:59.911697 2026] [security2:error] [pid 512881:tid 513088] [client 4.205.62.107:36587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/fucku.php"] [unique_id "apPlVwi65Hcg2zUJjxBiBwAAAmE"]
[Sun Aug 30 03:09:59.921217 2026] [authz_core:error] [pid 512881:tid 513059] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:59.921498 2026] [authz_core:error] [pid 512881:tid 513059] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:09:59.927733 2026] [security2:error] [pid 512881:tid 513066] [client 20.104.49.130:48346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/media.php"] [unique_id "apPlVwi65Hcg2zUJjxBiCgAAAks"]
[Sun Aug 30 03:09:59.928568 2026] [security2:error] [pid 512881:tid 513062] [client 20.220.10.235:26449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/admin.php/pindex.php"] [unique_id "apPlVwi65Hcg2zUJjxBiCwAAAkc"]
[Sun Aug 30 03:09:59.941724 2026] [security2:error] [pid 512881:tid 513032] [client 20.63.81.20:36680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/lock360.php"] [unique_id "apPlVwi65Hcg2zUJjxBiEwAAAik"]
[Sun Aug 30 03:09:59.966783 2026] [security2:error] [pid 512881:tid 513054] [client 158.23.147.79:42863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPlVwi65Hcg2zUJjxBiHQAAAj8"]
[Sun Aug 30 03:09:59.968510 2026] [authz_core:error] [pid 512881:tid 513087] [client 66.249.66.75:35506] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:09:59.968800 2026] [authz_core:error] [pid 512881:tid 513087] [client 66.249.66.75:35506] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:09:59.988015 2026] [security2:error] [pid 512881:tid 513039] [client 68.155.159.216:62613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-content/radio.php"] [unique_id "apPlVwi65Hcg2zUJjxBiLQAAAjA"]
[Sun Aug 30 03:09:59.997829 2026] [security2:error] [pid 512881:tid 513103] [client 20.104.50.220:59338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/samll.php"] [unique_id "apPlVwi65Hcg2zUJjxBiNQAAAnA"]
[Sun Aug 30 03:09:59.997907 2026] [security2:error] [pid 512881:tid 513137] [client 20.48.250.41:49895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/grsiuk.php"] [unique_id "apPlVwi65Hcg2zUJjxBiNgAAApI"]
[Sun Aug 30 03:10:00.033279 2026] [security2:error] [pid 512881:tid 513098] [client 68.155.159.216:54298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/ws.php"] [unique_id "apPlWAi65Hcg2zUJjxBiTgAAAms"]
[Sun Aug 30 03:10:00.044491 2026] [security2:error] [pid 512881:tid 513127] [client 20.104.49.130:53732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/wpxml.php"] [unique_id "apPlWAi65Hcg2zUJjxBiVQAAAog"]
[Sun Aug 30 03:10:00.062602 2026] [security2:error] [pid 512881:tid 513079] [client 20.48.250.41:38835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/403.php"] [unique_id "apPlWAi65Hcg2zUJjxBiXwAAAlg"]
[Sun Aug 30 03:10:00.062602 2026] [security2:error] [pid 512881:tid 513063] [client 20.220.10.235:26559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/admin.php/csv.php"] [unique_id "apPlWAi65Hcg2zUJjxBiXgAAAkg"]
[Sun Aug 30 03:10:00.069857 2026] [security2:error] [pid 512881:tid 513116] [client 20.63.81.20:36609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp-theme.php"] [unique_id "apPlWAi65Hcg2zUJjxBiYAAAAn0"]
[Sun Aug 30 03:10:00.088677 2026] [security2:error] [pid 512881:tid 513040] [client 20.104.50.220:63512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/angel.php"] [unique_id "apPlWAi65Hcg2zUJjxBiawAAAjE"]
[Sun Aug 30 03:10:00.110481 2026] [security2:error] [pid 512881:tid 513070] [client 20.104.50.220:52858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/Good.php"] [unique_id "apPlWAi65Hcg2zUJjxBidwAAAk8"]
[Sun Aug 30 03:10:00.125179 2026] [security2:error] [pid 512881:tid 513035] [client 20.104.50.220:52839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/mmk.php"] [unique_id "apPlWAi65Hcg2zUJjxBiggAAAiw"]
[Sun Aug 30 03:10:00.137389 2026] [security2:error] [pid 512881:tid 513093] [client 20.104.18.15:16648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/sf.php"] [unique_id "apPlWAi65Hcg2zUJjxBiigAAAmY"]
[Sun Aug 30 03:10:00.142286 2026] [security2:error] [pid 512881:tid 513122] [client 158.23.147.79:41549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apPlWAi65Hcg2zUJjxBiiwAAAoM"]
[Sun Aug 30 03:10:00.182618 2026] [security2:error] [pid 512881:tid 513107] [client 20.151.200.44:64798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/kcs.php"] [unique_id "apPlWAi65Hcg2zUJjxBiqQAAAnQ"]
[Sun Aug 30 03:10:00.190588 2026] [security2:error] [pid 512881:tid 513047] [client 20.104.18.15:22480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/ajax.php"] [unique_id "apPlWAi65Hcg2zUJjxBirwAAAjg"]
[Sun Aug 30 03:10:00.191595 2026] [security2:error] [pid 512881:tid 513027] [client 20.220.10.235:26607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/admin.php/700.php"] [unique_id "apPlWAi65Hcg2zUJjxBisgAAAiQ"]
[Sun Aug 30 03:10:00.198265 2026] [security2:error] [pid 512881:tid 513084] [client 20.63.81.20:36777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/2d7433/index.php"] [unique_id "apPlWAi65Hcg2zUJjxBitQAAAl0"]
[Sun Aug 30 03:10:00.203763 2026] [security2:error] [pid 512881:tid 513122] [client 20.48.250.41:49860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/wp-scr1pts.php"] [unique_id "apPlWAi65Hcg2zUJjxBiuAAAAoM"]
[Sun Aug 30 03:10:00.206466 2026] [security2:error] [pid 512881:tid 513058] [client 4.205.62.107:17097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/sadd.php"] [unique_id "apPlWAi65Hcg2zUJjxBiuwAAAkM"]
[Sun Aug 30 03:10:00.211463 2026] [security2:error] [pid 512881:tid 513132] [client 20.48.250.41:38869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/cytyr.php"] [unique_id "apPlWAi65Hcg2zUJjxBivQAAAo0"]
[Sun Aug 30 03:10:00.232020 2026] [security2:error] [pid 512881:tid 513066] [client 20.104.18.15:43846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/wnnjpsby.php"] [unique_id "apPlWAi65Hcg2zUJjxBiwQAAAks"]
[Sun Aug 30 03:10:00.248060 2026] [security2:error] [pid 512881:tid 513040] [client 158.23.147.79:56455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/dropdown.php"] [unique_id "apPlWAi65Hcg2zUJjxBizQAAAjE"]
[Sun Aug 30 03:10:00.271667 2026] [security2:error] [pid 512881:tid 513069] [client 20.151.200.44:41889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/Contrller.php"] [unique_id "apPlWAi65Hcg2zUJjxBi2QAAAk4"]
[Sun Aug 30 03:10:00.282735 2026] [security2:error] [pid 512881:tid 513015] [client 158.23.147.79:10181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-content/radio.php"] [unique_id "apPlWAi65Hcg2zUJjxBi5QAAAhg"]
[Sun Aug 30 03:10:00.301365 2026] [security2:error] [pid 512881:tid 513040] [client 20.48.251.3:13990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/adminfus.php"] [unique_id "apPlWAi65Hcg2zUJjxBi8AAAAjE"]
[Sun Aug 30 03:10:00.320480 2026] [security2:error] [pid 512881:tid 513098] [client 68.155.159.216:46009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/lock.php"] [unique_id "apPlWAi65Hcg2zUJjxBi-wAAAms"]
[Sun Aug 30 03:10:00.322634 2026] [security2:error] [pid 512881:tid 513077] [client 20.220.10.235:26592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/admin.php/007x.php"] [unique_id "apPlWAi65Hcg2zUJjxBi_AAAAlY"]
[Sun Aug 30 03:10:00.342053 2026] [security2:error] [pid 512881:tid 513086] [client 20.48.250.41:49819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/num.php"] [unique_id "apPlWAi65Hcg2zUJjxBjAwAAAl8"]
[Sun Aug 30 03:10:00.345306 2026] [security2:error] [pid 512881:tid 513062] [client 20.48.250.41:38803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/galer.php"] [unique_id "apPlWAi65Hcg2zUJjxBjBQAAAkc"]
[Sun Aug 30 03:10:00.359448 2026] [security2:error] [pid 512881:tid 513048] [client 20.63.81.20:36736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp-login.php"] [unique_id "apPlWAi65Hcg2zUJjxBi_gAAAjk"]
[Sun Aug 30 03:10:00.378560 2026] [security2:error] [pid 512881:tid 513137] [client 43.119.104.137:41853] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "tastylandscape.com"] [uri "/wp-content/plugins/burst-statistics/endpoint.php"] [unique_id "apPlWAi65Hcg2zUJjxBjHAAAApI"], referer: https://tastylandscape.com/2014/11/29/best-way-propagate-geranium/
[Sun Aug 30 03:10:00.398636 2026] [security2:error] [pid 512881:tid 513098] [client 20.104.18.15:18401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/av.php"] [unique_id "apPlWAi65Hcg2zUJjxBjLQAAAms"]
[Sun Aug 30 03:10:00.402829 2026] [authz_core:error] [pid 512881:tid 513090] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:00.403280 2026] [authz_core:error] [pid 512881:tid 513090] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:00.408265 2026] [security2:error] [pid 512881:tid 513039] [client 158.23.147.79:42866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apPlWAi65Hcg2zUJjxBjMgAAAjA"]
[Sun Aug 30 03:10:00.442037 2026] [security2:error] [pid 512881:tid 513015] [client 20.104.50.220:33332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/12.php"] [unique_id "apPlWAi65Hcg2zUJjxBjQAAAAhg"]
[Sun Aug 30 03:10:00.444462 2026] [security2:error] [pid 512881:tid 513128] [client 20.104.49.130:63539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/100.php"] [unique_id "apPlWAi65Hcg2zUJjxBjQwAAAok"]
[Sun Aug 30 03:10:00.455316 2026] [security2:error] [pid 512881:tid 513101] [client 20.220.10.235:26515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/admin.php/heex.php"] [unique_id "apPlWAi65Hcg2zUJjxBjRQAAAm4"]
[Sun Aug 30 03:10:00.467853 2026] [security2:error] [pid 512881:tid 513126] [client 20.48.250.41:49821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/a4.php"] [unique_id "apPlWAi65Hcg2zUJjxBjTgAAAoc"]
[Sun Aug 30 03:10:00.488980 2026] [security2:error] [pid 512881:tid 513132] [client 20.48.250.41:38737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/baixy.php"] [unique_id "apPlWAi65Hcg2zUJjxBjUgAAAo0"]
[Sun Aug 30 03:10:00.491670 2026] [security2:error] [pid 512881:tid 513014] [client 20.63.81.20:36800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/images.php"] [unique_id "apPlWAi65Hcg2zUJjxBjUwAAAhc"]
[Sun Aug 30 03:10:00.503179 2026] [security2:error] [pid 512881:tid 513098] [client 20.104.50.220:31921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "apPlWAi65Hcg2zUJjxBjWQAAAms"]
[Sun Aug 30 03:10:00.516968 2026] [security2:error] [pid 512881:tid 513127] [client 158.23.147.79:42871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/login.php"] [unique_id "apPlWAi65Hcg2zUJjxBjXgAAAog"]
[Sun Aug 30 03:10:00.589003 2026] [security2:error] [pid 512881:tid 513061] [client 20.220.10.235:26499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/tf.php"] [unique_id "apPlWAi65Hcg2zUJjxBjgwAAAkY"]
[Sun Aug 30 03:10:00.619705 2026] [security2:error] [pid 512881:tid 513066] [client 20.48.250.41:38731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/ava.php"] [unique_id "apPlWAi65Hcg2zUJjxBjmAAAAks"]
[Sun Aug 30 03:10:00.620164 2026] [security2:error] [pid 512881:tid 513113] [client 20.151.200.44:64807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/tajj.php"] [unique_id "apPlWAi65Hcg2zUJjxBjmgAAAno"]
[Sun Aug 30 03:10:00.620356 2026] [security2:error] [pid 512881:tid 513029] [client 20.48.250.41:64557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/tfm.php"] [unique_id "apPlWAi65Hcg2zUJjxBjmwAAAiY"]
[Sun Aug 30 03:10:00.636549 2026] [authz_core:error] [pid 512881:tid 513072] [client 66.249.66.70:44145] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:00.636879 2026] [authz_core:error] [pid 512881:tid 513072] [client 66.249.66.70:44145] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:00.651563 2026] [security2:error] [pid 512881:tid 513039] [client 20.48.251.3:64276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/register.php"] [unique_id "apPlWAi65Hcg2zUJjxBjlQAAAjA"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:10:00.862925 2026] [authz_core:error] [pid 512881:tid 513064] [client 216.73.216.128:6524] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:00.863211 2026] [authz_core:error] [pid 512881:tid 513064] [client 216.73.216.128:6524] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:00.904893 2026] [authz_core:error] [pid 512881:tid 513131] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:00.905178 2026] [authz_core:error] [pid 512881:tid 513131] [client 74.7.243.204:45926] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:10:01.364570 2026] [http2:info] [pid 515259:tid 515259] h2_workers: created with min=128 max=192 idle_ms=600000
[Sun Aug 30 03:10:01.393111 2026] [security2:error] [pid 515259:tid 515419] [client 20.104.18.15:64764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/coffexium.php"] [unique_id "apPlWWZcVaai59truiVehgAAAB0"]
[Sun Aug 30 03:10:01.393136 2026] [security2:error] [pid 515259:tid 515423] [client 20.104.18.15:43286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/gigi.php"] [unique_id "apPlWWZcVaai59truiVeiQAAACE"]
[Sun Aug 30 03:10:01.393168 2026] [security2:error] [pid 515259:tid 515405] [client 20.151.200.44:64146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/bge.php"] [unique_id "apPlWWZcVaai59truiVefAAAAA8"]
[Sun Aug 30 03:10:01.393234 2026] [security2:error] [pid 515259:tid 515413] [client 20.48.250.41:38905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/gdn.php"] [unique_id "apPlWWZcVaai59truiVehAAAABc"]
[Sun Aug 30 03:10:01.393283 2026] [security2:error] [pid 515259:tid 515410] [client 4.205.62.107:25514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/vx.php"] [unique_id "apPlWWZcVaai59truiVegQAAABQ"]
[Sun Aug 30 03:10:01.393304 2026] [security2:error] [pid 515259:tid 515412] [client 20.220.10.235:26512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/update/da222.php"] [unique_id "apPlWWZcVaai59truiVegwAAABY"]
[Sun Aug 30 03:10:01.393318 2026] [security2:error] [pid 515259:tid 515396] [client 68.155.159.216:62621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apPlWWZcVaai59truiVeeQAAAAY"]
[Sun Aug 30 03:10:01.393318 2026] [security2:error] [pid 515259:tid 515426] [client 20.48.251.3:59856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/xp.php"] [unique_id "apPlWWZcVaai59truiVejQAAACQ"]
[Sun Aug 30 03:10:01.393385 2026] [security2:error] [pid 515259:tid 515397] [client 158.23.147.79:41597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/hehehehe.php"] [unique_id "apPlWWZcVaai59truiVeewAAAAc"]
[Sun Aug 30 03:10:01.393436 2026] [security2:error] [pid 515259:tid 515409] [client 20.151.200.44:41925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/file66.php"] [unique_id "apPlWWZcVaai59truiVegAAAABM"]
[Sun Aug 30 03:10:01.393452 2026] [security2:error] [pid 515259:tid 515391] [client 20.104.50.220:61637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/kepo.php"] [unique_id "apPlWWZcVaai59truiVeeAAAAAE"]
[Sun Aug 30 03:10:01.393466 2026] [security2:error] [pid 515259:tid 515398] [client 20.63.81.20:36770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/ops.php"] [unique_id "apPlWWZcVaai59truiVeegAAAAg"]
[Sun Aug 30 03:10:01.393546 2026] [security2:error] [pid 515259:tid 515393] [client 20.48.251.3:59301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/lm15.php"] [unique_id "apPlWWZcVaai59truiVedQAAAAM"]
[Sun Aug 30 03:10:01.393560 2026] [security2:error] [pid 515259:tid 515407] [client 20.151.200.44:28626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/wp-access.php"] [unique_id "apPlWWZcVaai59truiVefgAAABE"]
[Sun Aug 30 03:10:01.393639 2026] [security2:error] [pid 515259:tid 515422] [client 20.104.50.220:51559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/c100.php"] [unique_id "apPlWWZcVaai59truiVeiAAAACA"]
[Sun Aug 30 03:10:01.393674 2026] [security2:error] [pid 515259:tid 515394] [client 20.48.250.41:49908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/Geforce.php"] [unique_id "apPlWWZcVaai59truiVedgAAAAQ"]
[Sun Aug 30 03:10:01.393675 2026] [security2:error] [pid 515259:tid 515395] [client 4.205.62.107:58470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apPlWWZcVaai59truiVedwAAAAU"]
[Sun Aug 30 03:10:01.393735 2026] [security2:error] [pid 515259:tid 515411] [client 20.104.50.220:17305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/css.php"] [unique_id "apPlWWZcVaai59truiVeggAAABU"]
[Sun Aug 30 03:10:01.393780 2026] [security2:error] [pid 515259:tid 515424] [client 4.205.62.107:36586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/error_log.php"] [unique_id "apPlWWZcVaai59truiVeiwAAACI"]
[Sun Aug 30 03:10:01.393835 2026] [security2:error] [pid 515259:tid 515392] [client 20.104.50.220:5534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/rootshell.php"] [unique_id "apPlWWZcVaai59truiVecwAAAAI"]
[Sun Aug 30 03:10:01.393865 2026] [security2:error] [pid 515259:tid 515425] [client 20.104.50.220:59369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/ingfo.php"] [unique_id "apPlWWZcVaai59truiVejAAAACM"]
[Sun Aug 30 03:10:01.394883 2026] [security2:error] [pid 515259:tid 515419] [client 20.104.18.15:35052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/pri.php"] [unique_id "apPlWWZcVaai59truiVejwAAAB0"]
[Sun Aug 30 03:10:01.395331 2026] [security2:error] [pid 515259:tid 515433] [client 20.104.50.220:29125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/EvilTwin.php"] [unique_id "apPlWWZcVaai59truiVekAAAACs"]
[Sun Aug 30 03:10:01.396194 2026] [security2:error] [pid 515259:tid 515439] [client 158.23.147.79:56500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/sad/about.php"] [unique_id "apPlWWZcVaai59truiVekQAAADE"]
[Sun Aug 30 03:10:01.396512 2026] [security2:error] [pid 515259:tid 515441] [client 20.104.18.15:16640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/xx.php"] [unique_id "apPlWWZcVaai59truiVekwAAADM"]
[Sun Aug 30 03:10:01.396688 2026] [security2:error] [pid 515259:tid 515440] [client 4.205.62.107:17110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/application.config.php"] [unique_id "apPlWWZcVaai59truiVekgAAADI"]
[Sun Aug 30 03:10:01.397537 2026] [security2:error] [pid 515259:tid 515393] [client 68.155.159.216:54326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-includes/css/index.php"] [unique_id "apPlWWZcVaai59truiVemAAAAAM"]
[Sun Aug 30 03:10:01.397664 2026] [security2:error] [pid 515259:tid 515444] [client 20.104.18.15:22499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/atomlib.php"] [unique_id "apPlWWZcVaai59truiVemgAAADY"]
[Sun Aug 30 03:10:01.403566 2026] [authz_core:error] [pid 515259:tid 515390] [client 66.249.66.73:64993] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:01.404135 2026] [authz_core:error] [pid 515259:tid 515390] [client 66.249.66.73:64993] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:01.407956 2026] [security2:error] [pid 515259:tid 515434] [client 20.104.49.130:32784] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.firedrakegames.com"] [uri "/1.php"] [unique_id "apPlWWZcVaai59truiVetAAAACw"]
[Sun Aug 30 03:10:01.409432 2026] [security2:error] [pid 515259:tid 515434] [client 20.104.49.130:32784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/1.php"] [unique_id "apPlWWZcVaai59truiVetAAAACw"]
[Sun Aug 30 03:10:01.409613 2026] [security2:error] [pid 515259:tid 515432] [client 20.104.49.130:57677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/Jcrop.php"] [unique_id "apPlWWZcVaai59truiVepQAAACo"]
[Sun Aug 30 03:10:01.418347 2026] [authz_core:error] [pid 515259:tid 515406] [client 66.249.66.32:48243] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:01.418738 2026] [authz_core:error] [pid 515259:tid 515406] [client 66.249.66.32:48243] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:01.425542 2026] [authz_core:error] [pid 515259:tid 515432] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:01.425857 2026] [authz_core:error] [pid 515259:tid 515432] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:01.431116 2026] [security2:error] [pid 515259:tid 515461] [client 68.155.159.216:45987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/index/function.php"] [unique_id "apPlWWZcVaai59truiVe_gAAAEc"]
[Sun Aug 30 03:10:01.433231 2026] [security2:error] [pid 515259:tid 515405] [client 216.73.216.128:56556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/ourcollection_images/wp-admin/css/install.css"] [unique_id "apPlWWZcVaai59truiVe-wAAAA8"]
[Sun Aug 30 03:10:01.437230 2026] [authz_core:error] [pid 515259:tid 515407] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:01.437735 2026] [authz_core:error] [pid 515259:tid 515407] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:01.439448 2026] [security2:error] [pid 512881:tid 513063] [client 20.48.251.3:33334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/avim.php"] [unique_id "apPlWQi65Hcg2zUJjxBkFAAAAkg"]
[Sun Aug 30 03:10:01.469563 2026] [authz_core:error] [pid 515259:tid 515435] [client 66.249.66.198:53290] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:01.470013 2026] [authz_core:error] [pid 515259:tid 515435] [client 66.249.66.198:53290] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:01.519367 2026] [security2:error] [pid 512881:tid 513107] [client 20.63.81.20:36815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPlWQi65Hcg2zUJjxBkRwAAAnQ"]
[Sun Aug 30 03:10:01.521140 2026] [security2:error] [pid 512881:tid 513131] [client 20.48.250.41:64578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/click.php"] [unique_id "apPlWQi65Hcg2zUJjxBkSAAAAow"]
[Sun Aug 30 03:10:01.525932 2026] [security2:error] [pid 512881:tid 513064] [client 158.23.147.79:42873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apPlWQi65Hcg2zUJjxBkSQAAAkk"]
[Sun Aug 30 03:10:01.537498 2026] [security2:error] [pid 512881:tid 513049] [client 20.220.10.235:26546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/qi.php"] [unique_id "apPlWQi65Hcg2zUJjxBkTAAAAjo"]
[Sun Aug 30 03:10:01.551355 2026] [security2:error] [pid 512881:tid 513018] [client 20.104.18.15:18421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/images.php"] [unique_id "apPlWQi65Hcg2zUJjxBkTwAAAhs"]
[Sun Aug 30 03:10:01.563619 2026] [security2:error] [pid 512881:tid 513078] [client 20.48.250.41:38874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/f2.php"] [unique_id "apPlWQi65Hcg2zUJjxBkVQAAAlc"]
[Sun Aug 30 03:10:01.585141 2026] [security2:error] [pid 512881:tid 513042] [client 20.104.50.220:33589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wikiindex.php"] [unique_id "apPlWQi65Hcg2zUJjxBkWAAAAjM"]
[Sun Aug 30 03:10:01.639598 2026] [security2:error] [pid 515259:tid 515466] [client 158.23.147.79:41568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-content/admin.php"] [unique_id "apPlWWZcVaai59truiVfPgAAAEw"]
[Sun Aug 30 03:10:01.649443 2026] [security2:error] [pid 512881:tid 513125] [client 20.63.81.20:36779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPlWQi65Hcg2zUJjxBkZQAAAoY"]
[Sun Aug 30 03:10:01.657714 2026] [authz_core:error] [pid 512881:tid 513101] [client 66.249.66.64:37801] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:01.658096 2026] [authz_core:error] [pid 512881:tid 513101] [client 66.249.66.64:37801] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:01.659421 2026] [security2:error] [pid 515259:tid 515450] [client 20.104.50.220:32080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/fm.php"] [unique_id "apPlWWZcVaai59truiVfQQAAADw"]
[Sun Aug 30 03:10:01.684198 2026] [security2:error] [pid 512881:tid 513119] [client 20.220.10.235:26456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/px.php"] [unique_id "apPlWQi65Hcg2zUJjxBkfAAAAoA"]
[Sun Aug 30 03:10:01.710128 2026] [security2:error] [pid 512881:tid 513093] [client 20.151.200.44:41924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/blnux.php"] [unique_id "apPlWQi65Hcg2zUJjxBkhgAAAmY"]
[Sun Aug 30 03:10:01.765708 2026] [security2:error] [pid 512881:tid 513137] [client 158.23.147.79:42847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/xmlrpc.php"] [unique_id "apPlWQi65Hcg2zUJjxBkpAAAApI"]
[Sun Aug 30 03:10:01.781398 2026] [security2:error] [pid 512881:tid 513126] [client 20.63.81.20:36849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/about.php"] [unique_id "apPlWQi65Hcg2zUJjxBkrAAAAoc"]
[Sun Aug 30 03:10:01.797171 2026] [security2:error] [pid 515259:tid 515442] [client 20.48.251.3:64284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/xqq.php"] [unique_id "apPlWWZcVaai59truiVfTQAAADQ"]
[Sun Aug 30 03:10:01.814496 2026] [security2:error] [pid 512881:tid 513048] [client 20.220.10.235:26518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/is.php"] [unique_id "apPlWQi65Hcg2zUJjxBkvwAAAjk"]
[Sun Aug 30 03:10:01.883942 2026] [authz_core:error] [pid 515259:tid 515408] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:01.884447 2026] [authz_core:error] [pid 515259:tid 515408] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:01.906657 2026] [security2:error] [pid 512881:tid 513105] [client 20.63.81.20:36819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/admin.php/admin.php"] [unique_id "apPlWQi65Hcg2zUJjxBk9AAAAnI"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:10:01.948114 2026] [security2:error] [pid 515259:tid 515439] [client 20.220.10.235:26544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/od.php"] [unique_id "apPlWWZcVaai59truiVfXAAAADE"]
[Sun Aug 30 03:10:01.964851 2026] [authz_core:error] [pid 515259:tid 515488] [client 216.73.216.128:12206] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:01.965366 2026] [authz_core:error] [pid 515259:tid 515488] [client 216.73.216.128:12206] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:01.988420 2026] [security2:error] [pid 512881:tid 513052] [client 158.23.147.79:42876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/atomlib.php"] [unique_id "apPlWQi65Hcg2zUJjxBlDQAAAj0"]
[Sun Aug 30 03:10:02.002943 2026] [authz_core:error] [pid 512881:tid 513037] [client 66.249.66.40:60887] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:02.003418 2026] [authz_core:error] [pid 512881:tid 513037] [client 66.249.66.40:60887] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:02.037921 2026] [security2:error] [pid 515259:tid 515484] [client 20.63.81.20:36778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/media.php"] [unique_id "apPlWmZcVaai59truiVfdAAAAF4"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:10:02.091113 2026] [security2:error] [pid 512881:tid 513013] [client 20.220.10.235:26610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/wp-the.php"] [unique_id "apPlWgi65Hcg2zUJjxBlLQAAAhY"]
[Sun Aug 30 03:10:02.128213 2026] [authz_core:error] [pid 515259:tid 515477] [client 66.249.66.197:52359] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:02.128847 2026] [authz_core:error] [pid 515259:tid 515477] [client 66.249.66.197:52359] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:02.185757 2026] [security2:error] [pid 515259:tid 515516] [client 20.104.49.130:54153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/az.php"] [unique_id "apPlWmZcVaai59truiVfgAAAAH4"]
[Sun Aug 30 03:10:02.191042 2026] [security2:error] [pid 515259:tid 515430] [client 20.63.81.20:36676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/mac.php"] [unique_id "apPlWmZcVaai59truiVfgQAAACg"]
[Sun Aug 30 03:10:02.196082 2026] [security2:error] [pid 515259:tid 515506] [client 158.23.147.79:42860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/lv.php"] [unique_id "apPlWmZcVaai59truiVfhQAAAHQ"]
[Sun Aug 30 03:10:02.209222 2026] [security2:error] [pid 512881:tid 513012] [client 158.23.147.79:2036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/admin.php"] [unique_id "apPlWgi65Hcg2zUJjxBlWAAAAhU"]
[Sun Aug 30 03:10:02.219992 2026] [security2:error] [pid 512881:tid 513086] [client 20.220.10.235:26619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/wt.php"] [unique_id "apPlWgi65Hcg2zUJjxBlXQAAAl8"]
[Sun Aug 30 03:10:02.301106 2026] [security2:error] [pid 512881:tid 513052] [client 20.151.200.44:41970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/attack.php"] [unique_id "apPlWgi65Hcg2zUJjxBlbAAAAj0"]
[Sun Aug 30 03:10:02.311875 2026] [security2:error] [pid 512881:tid 513095] [client 158.23.147.79:42844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apPlWgi65Hcg2zUJjxBlbgAAAmg"]
[Sun Aug 30 03:10:02.321541 2026] [security2:error] [pid 512881:tid 513056] [client 20.63.81.20:36751] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.beyondmycross.com"] [uri "/1.php"] [unique_id "apPlWgi65Hcg2zUJjxBlcQAAAkE"]
[Sun Aug 30 03:10:02.321704 2026] [security2:error] [pid 512881:tid 513056] [client 20.63.81.20:36751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/1.php"] [unique_id "apPlWgi65Hcg2zUJjxBlcQAAAkE"]
[Sun Aug 30 03:10:02.347755 2026] [security2:error] [pid 512881:tid 513117] [client 20.220.10.235:26578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/im.php"] [unique_id "apPlWgi65Hcg2zUJjxBldQAAAn4"]
[Sun Aug 30 03:10:02.402790 2026] [authz_core:error] [pid 515259:tid 515478] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:02.403104 2026] [authz_core:error] [pid 515259:tid 515478] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:02.447504 2026] [security2:error] [pid 512881:tid 513069] [client 20.63.81.20:36674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/classwithtostring.php"] [unique_id "apPlWgi65Hcg2zUJjxBldwAAAk4"]
[Sun Aug 30 03:10:02.496058 2026] [security2:error] [pid 515259:tid 515494] [client 216.73.216.128:12206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/',b,'"] [unique_id "apPlWmZcVaai59truiVfnQAAAGg"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:10:02.498971 2026] [security2:error] [pid 515259:tid 515468] [client 68.155.159.216:57025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/login.php"] [unique_id "apPlWmZcVaai59truiVfngAAAE4"]
[Sun Aug 30 03:10:02.503058 2026] [security2:error] [pid 512881:tid 513051] [client 20.220.10.235:26587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/file.php"] [unique_id "apPlWgi65Hcg2zUJjxBlegAAAjw"]
[Sun Aug 30 03:10:02.520972 2026] [security2:error] [pid 512881:tid 513086] [client 158.23.147.79:42830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/content.php"] [unique_id "apPlWgi65Hcg2zUJjxBlewAAAl8"]
[Sun Aug 30 03:10:02.524389 2026] [security2:error] [pid 512881:tid 513128] [client 20.104.18.15:16931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/BDKR28WP.php"] [unique_id "apPlWgi65Hcg2zUJjxBlfAAAAok"]
[Sun Aug 30 03:10:02.527478 2026] [security2:error] [pid 515259:tid 515400] [client 20.104.50.220:17277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/cong.php"] [unique_id "apPlWmZcVaai59truiVfoAAAAAo"]
[Sun Aug 30 03:10:02.528457 2026] [security2:error] [pid 512881:tid 513029] [client 20.104.50.220:31507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/error_log.php"] [unique_id "apPlWgi65Hcg2zUJjxBlfgAAAiY"]
[Sun Aug 30 03:10:02.531884 2026] [security2:error] [pid 512881:tid 513102] [client 68.155.159.216:46057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/.well-known/content.php"] [unique_id "apPlWgi65Hcg2zUJjxBlfwAAAm8"]
[Sun Aug 30 03:10:02.533116 2026] [security2:error] [pid 512881:tid 513062] [client 20.48.251.3:55759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/test.config.php"] [unique_id "apPlWgi65Hcg2zUJjxBlgAAAAkc"]
[Sun Aug 30 03:10:02.533468 2026] [security2:error] [pid 515259:tid 515472] [client 4.205.62.107:25902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/ty.php"] [unique_id "apPlWmZcVaai59truiVfoQAAAFI"]
[Sun Aug 30 03:10:02.537450 2026] [security2:error] [pid 512881:tid 513105] [client 4.205.62.107:17290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/xp.php"] [unique_id "apPlWgi65Hcg2zUJjxBlgwAAAnI"]
[Sun Aug 30 03:10:02.537490 2026] [security2:error] [pid 512881:tid 513014] [client 20.104.18.15:35164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/wp_blog_footer.php"] [unique_id "apPlWgi65Hcg2zUJjxBlggAAAhc"]
[Sun Aug 30 03:10:02.538871 2026] [security2:error] [pid 512881:tid 513042] [client 20.104.18.15:16711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/uwu.php"] [unique_id "apPlWgi65Hcg2zUJjxBlhQAAAjM"]
[Sun Aug 30 03:10:02.539884 2026] [security2:error] [pid 512881:tid 513078] [client 20.104.50.220:42037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/simattacker.php"] [unique_id "apPlWgi65Hcg2zUJjxBlhgAAAlc"]
[Sun Aug 30 03:10:02.544018 2026] [security2:error] [pid 512881:tid 513138] [client 20.48.251.3:52232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/g3.php"] [unique_id "apPlWgi65Hcg2zUJjxBlhwAAApM"]
[Sun Aug 30 03:10:02.547360 2026] [security2:error] [pid 512881:tid 513103] [client 20.104.50.220:61439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/kk.php"] [unique_id "apPlWgi65Hcg2zUJjxBliAAAAnA"]
[Sun Aug 30 03:10:02.552752 2026] [security2:error] [pid 512881:tid 513096] [client 20.104.50.220:28729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/da111.php"] [unique_id "apPlWgi65Hcg2zUJjxBliQAAAmk"]
[Sun Aug 30 03:10:02.554203 2026] [security2:error] [pid 512881:tid 513106] [client 20.104.18.15:22403] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "gracejolliffe.com"] [uri "/1.php"] [unique_id "apPlWgi65Hcg2zUJjxBligAAAnM"]
[Sun Aug 30 03:10:02.554292 2026] [security2:error] [pid 512881:tid 513106] [client 20.104.18.15:22403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/1.php"] [unique_id "apPlWgi65Hcg2zUJjxBligAAAnM"]
[Sun Aug 30 03:10:02.562508 2026] [security2:error] [pid 512881:tid 513025] [client 20.104.50.220:5472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/yuuki.php"] [unique_id "apPlWgi65Hcg2zUJjxBljQAAAiI"]
[Sun Aug 30 03:10:02.572825 2026] [security2:error] [pid 512881:tid 513113] [client 20.104.18.15:43918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/info.php/new.php"] [unique_id "apPlWgi65Hcg2zUJjxBlkAAAAno"]
[Sun Aug 30 03:10:02.572970 2026] [security2:error] [pid 515259:tid 515460] [client 20.63.81.20:36751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp-ws68.php"] [unique_id "apPlWmZcVaai59truiVfpgAAAEY"]
[Sun Aug 30 03:10:02.574185 2026] [security2:error] [pid 515259:tid 515391] [client 20.48.251.3:60529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/nw.php"] [unique_id "apPlWmZcVaai59truiVfpwAAAAE"]
[Sun Aug 30 03:10:02.584703 2026] [security2:error] [pid 515259:tid 515484] [client 158.23.147.79:60162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlWmZcVaai59truiVfqQAAAF4"]
[Sun Aug 30 03:10:02.591574 2026] [security2:error] [pid 515259:tid 515493] [client 4.205.62.107:61820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/hochladen.form.php"] [unique_id "apPlWmZcVaai59truiVfqgAAAGc"]
[Sun Aug 30 03:10:02.597595 2026] [security2:error] [pid 515259:tid 515474] [client 68.155.159.216:54272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apPlWmZcVaai59truiVfrAAAAFQ"]
[Sun Aug 30 03:10:02.640023 2026] [security2:error] [pid 512881:tid 513104] [client 20.220.10.235:26591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/ca.php"] [unique_id "apPlWgi65Hcg2zUJjxBloAAAAnE"]
[Sun Aug 30 03:10:02.692161 2026] [security2:error] [pid 512881:tid 513102] [client 20.104.18.15:18399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/ops.php"] [unique_id "apPlWgi65Hcg2zUJjxBlvAAAAm8"]
[Sun Aug 30 03:10:02.694424 2026] [security2:error] [pid 512881:tid 513078] [client 20.151.200.44:40901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlWgi65Hcg2zUJjxBlvQAAAlc"]
[Sun Aug 30 03:10:02.719440 2026] [security2:error] [pid 512881:tid 513038] [client 20.63.81.20:36859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/simple.php"] [unique_id "apPlWgi65Hcg2zUJjxBl0wAAAi8"]
[Sun Aug 30 03:10:02.732928 2026] [security2:error] [pid 515259:tid 515471] [client 20.104.50.220:32868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/alex.php"] [unique_id "apPlWmZcVaai59truiVfugAAAFE"]
[Sun Aug 30 03:10:02.737179 2026] [authz_core:error] [pid 515259:tid 515396] [client 66.249.66.64:44067] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:02.737550 2026] [authz_core:error] [pid 515259:tid 515396] [client 66.249.66.64:44067] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:02.772388 2026] [security2:error] [pid 512881:tid 513125] [client 20.220.10.235:26603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/pb.php"] [unique_id "apPlWgi65Hcg2zUJjxBl6QAAAoY"]
[Sun Aug 30 03:10:02.776574 2026] [security2:error] [pid 512881:tid 513059] [client 216.73.216.128:31351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/collection.html"] [unique_id "apPlWgi65Hcg2zUJjxBl7AAAAkQ"]
[Sun Aug 30 03:10:02.780720 2026] [security2:error] [pid 515259:tid 515269] [remote 57.141.14.29:64898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.14.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.texascleanteam.com"] [uri "/index.php/about-us/"] [unique_id "apPlWmZcVaai59truiVfwAAABQg"]
[Sun Aug 30 03:10:02.781133 2026] [security2:error] [pid 512881:tid 513100] [client 158.23.147.79:41548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPlWgi65Hcg2zUJjxBl8AAAAm0"]
[Sun Aug 30 03:10:02.816138 2026] [security2:error] [pid 512881:tid 513025] [client 20.104.50.220:31874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/403.php"] [unique_id "apPlWgi65Hcg2zUJjxBl-QAAAiI"]
[Sun Aug 30 03:10:02.841883 2026] [security2:error] [pid 512881:tid 513096] [client 20.151.200.44:65425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/ssh3ll.php"] [unique_id "apPlWgi65Hcg2zUJjxBmAAAAAmk"]
[Sun Aug 30 03:10:02.851744 2026] [security2:error] [pid 512881:tid 513034] [client 20.63.81.20:36820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/aaa.php"] [unique_id "apPlWgi65Hcg2zUJjxBmCQAAAis"]
[Sun Aug 30 03:10:02.861453 2026] [authz_core:error] [pid 512881:tid 513124] [client 66.249.66.78:53977] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:02.861939 2026] [authz_core:error] [pid 512881:tid 513124] [client 66.249.66.78:53977] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:02.864664 2026] [authz_core:error] [pid 515259:tid 515429] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:02.865060 2026] [authz_core:error] [pid 515259:tid 515429] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:02.867448 2026] [security2:error] [pid 512881:tid 513137] [client 216.73.216.128:2293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_config_quote_replace_string"] [unique_id "apPlWgi65Hcg2zUJjxBmGgAAApI"]
[Sun Aug 30 03:10:02.901377 2026] [security2:error] [pid 512881:tid 513060] [client 20.220.10.235:26445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/pk.php"] [unique_id "apPlWgi65Hcg2zUJjxBmLAAAAkU"]
[Sun Aug 30 03:10:02.937836 2026] [security2:error] [pid 512881:tid 513131] [client 4.205.62.107:36692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/phina.php"] [unique_id "apPlWgi65Hcg2zUJjxBmOwAAAow"]
[Sun Aug 30 03:10:02.948619 2026] [authz_core:error] [pid 515259:tid 515393] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:02.949063 2026] [authz_core:error] [pid 515259:tid 515393] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:02.957547 2026] [security2:error] [pid 512881:tid 513029] [client 20.48.251.3:64279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/a1vx.php"] [unique_id "apPlWgi65Hcg2zUJjxBmSAAAAiY"]
[Sun Aug 30 03:10:02.971391 2026] [authz_core:error] [pid 515259:tid 515443] [client 216.73.216.128:49549] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:02.971890 2026] [authz_core:error] [pid 515259:tid 515443] [client 216.73.216.128:49549] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:03.016159 2026] [security2:error] [pid 512881:tid 513061] [client 158.23.147.79:42864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/goat.php"] [unique_id "apPlWwi65Hcg2zUJjxBmZQAAAkY"]
[Sun Aug 30 03:10:03.025900 2026] [security2:error] [pid 515259:tid 515474] [client 20.104.50.220:64453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/pas.php"] [unique_id "apPlW2ZcVaai59truiVf5QAAAFQ"]
[Sun Aug 30 03:10:03.026225 2026] [security2:error] [pid 515259:tid 515493] [client 20.104.49.130:52479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/ano.php"] [unique_id "apPlW2ZcVaai59truiVf5gAAAGc"]
[Sun Aug 30 03:10:03.030332 2026] [security2:error] [pid 512881:tid 513085] [client 20.220.10.235:26567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/ft.php"] [unique_id "apPlWwi65Hcg2zUJjxBmagAAAl4"]
[Sun Aug 30 03:10:03.109002 2026] [security2:error] [pid 512881:tid 513101] [client 158.23.147.79:57727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-admin/admin.php"] [unique_id "apPlWwi65Hcg2zUJjxBmkAAAAm4"]
[Sun Aug 30 03:10:03.141354 2026] [security2:error] [pid 512881:tid 513097] [client 158.23.184.117:13239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/wp-includes/ID3/config.php"] [unique_id "apPlWwi65Hcg2zUJjxBmoAAAAmo"]
[Sun Aug 30 03:10:03.156839 2026] [security2:error] [pid 515259:tid 515497] [client 20.220.10.235:26614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/wp-ver.php"] [unique_id "apPlW2ZcVaai59truiVf_gAAAGs"]
[Sun Aug 30 03:10:03.166966 2026] [security2:error] [pid 515259:tid 515498] [client 158.23.147.79:10129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apPlW2ZcVaai59truiVgAAAAAGw"]
[Sun Aug 30 03:10:03.214006 2026] [security2:error] [pid 515259:tid 515446] [client 20.63.81.20:36788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/shiny.php"] [unique_id "apPlW2ZcVaai59truiVgCQAAADg"]
[Sun Aug 30 03:10:03.287459 2026] [security2:error] [pid 512881:tid 513119] [client 20.220.10.235:26535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/ah24.php"] [unique_id "apPlWwi65Hcg2zUJjxBmxgAAAoA"]
[Sun Aug 30 03:10:03.300769 2026] [security2:error] [pid 515259:tid 515422] [client 158.23.184.117:12883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/test1.php"] [unique_id "apPlW2ZcVaai59truiVgEAAAACA"]
[Sun Aug 30 03:10:03.322834 2026] [authz_core:error] [pid 512881:tid 513133] [client 66.249.66.67:51858] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:03.323386 2026] [authz_core:error] [pid 512881:tid 513133] [client 66.249.66.67:51858] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:03.340361 2026] [security2:error] [pid 512881:tid 513018] [client 20.63.81.20:36862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/goods.php"] [unique_id "apPlWwi65Hcg2zUJjxBmygAAAhs"]
[Sun Aug 30 03:10:03.404034 2026] [security2:error] [pid 512881:tid 513040] [client 158.23.147.79:41570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apPlWwi65Hcg2zUJjxBm0AAAAjE"]
[Sun Aug 30 03:10:03.411123 2026] [authz_core:error] [pid 515259:tid 515420] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:03.411556 2026] [authz_core:error] [pid 515259:tid 515420] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:03.414449 2026] [security2:error] [pid 515259:tid 515483] [client 20.220.10.235:26513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPlW2ZcVaai59truiVgFQAAAF0"]
[Sun Aug 30 03:10:03.440829 2026] [security2:error] [pid 512881:tid 513050] [client 158.23.184.117:13215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/wp-admin/edit-tags.php"] [unique_id "apPlWwi65Hcg2zUJjxBm0wAAAjs"]
[Sun Aug 30 03:10:03.466356 2026] [security2:error] [pid 512881:tid 513085] [client 20.63.81.20:36831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/000.php/index.php"] [unique_id "apPlWwi65Hcg2zUJjxBm2QAAAl4"]
[Sun Aug 30 03:10:03.472507 2026] [authz_core:error] [pid 515259:tid 515457] [client 66.249.66.195:65435] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:03.472957 2026] [authz_core:error] [pid 515259:tid 515457] [client 66.249.66.195:65435] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:03.508173 2026] [security2:error] [pid 512881:tid 513047] [client 216.73.216.128:2339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_config_auto_include_reply"] [unique_id "apPlWwi65Hcg2zUJjxBm3AAAAjg"]
[Sun Aug 30 03:10:03.530830 2026] [security2:error] [pid 512881:tid 513124] [client 20.151.200.44:28639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/wp-content/admin.php"] [unique_id "apPlWwi65Hcg2zUJjxBm3wAAAoU"]
[Sun Aug 30 03:10:03.546118 2026] [security2:error] [pid 515259:tid 515504] [client 20.220.10.235:26501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.thebelgradegroup.com"] [uri "/waf.php"] [unique_id "apPlW2ZcVaai59truiVgGgAAAHI"]
[Sun Aug 30 03:10:03.551320 2026] [security2:error] [pid 515259:tid 515492] [client 20.104.49.130:52148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/ty.php"] [unique_id "apPlW2ZcVaai59truiVgGwAAAGY"]
[Sun Aug 30 03:10:03.564676 2026] [security2:error] [pid 512881:tid 513101] [client 158.23.147.79:41543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apPlWwi65Hcg2zUJjxBm6AAAAm4"]
[Sun Aug 30 03:10:03.582140 2026] [security2:error] [pid 512881:tid 513067] [client 158.23.184.117:13184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/xmlrpc.php"] [unique_id "apPlWwi65Hcg2zUJjxBm6wAAAkw"]
[Sun Aug 30 03:10:03.598871 2026] [security2:error] [pid 515259:tid 515473] [client 20.63.81.20:36675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/Jcrop.php"] [unique_id "apPlW2ZcVaai59truiVgHQAAAFM"]
[Sun Aug 30 03:10:03.607023 2026] [security2:error] [pid 512881:tid 513122] [client 68.155.159.216:62638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/hehehehe.php"] [unique_id "apPlWwi65Hcg2zUJjxBm7gAAAoM"]
[Sun Aug 30 03:10:03.663858 2026] [security2:error] [pid 515259:tid 515493] [client 68.155.159.216:45995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/cong.php"] [unique_id "apPlW2ZcVaai59truiVgIgAAAGc"]
[Sun Aug 30 03:10:03.666256 2026] [security2:error] [pid 512881:tid 513114] [client 20.104.50.220:16756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPlWwi65Hcg2zUJjxBnCAAAAns"]
[Sun Aug 30 03:10:03.676169 2026] [security2:error] [pid 512881:tid 513070] [client 4.205.62.107:17129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/g3.php"] [unique_id "apPlWwi65Hcg2zUJjxBnCwAAAk8"]
[Sun Aug 30 03:10:03.676630 2026] [security2:error] [pid 512881:tid 513069] [client 20.104.18.15:16661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/signon.php"] [unique_id "apPlWwi65Hcg2zUJjxBnDAAAAk4"]
[Sun Aug 30 03:10:03.679841 2026] [security2:error] [pid 515259:tid 515482] [client 20.48.251.3:59494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-konfig.php"] [unique_id "apPlW2ZcVaai59truiVgJwAAAFw"]
[Sun Aug 30 03:10:03.684999 2026] [security2:error] [pid 515259:tid 515430] [client 20.48.251.3:55765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/gecko-litespeed.php"] [unique_id "apPlW2ZcVaai59truiVgKgAAACg"]
[Sun Aug 30 03:10:03.685205 2026] [security2:error] [pid 515259:tid 515451] [client 20.104.50.220:59347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/xenon1337.php"] [unique_id "apPlW2ZcVaai59truiVgKwAAAD0"]
[Sun Aug 30 03:10:03.687161 2026] [security2:error] [pid 512881:tid 513022] [client 158.23.147.79:2018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apPlWwi65Hcg2zUJjxBnFQAAAh8"]
[Sun Aug 30 03:10:03.690969 2026] [security2:error] [pid 512881:tid 513066] [client 20.104.18.15:16916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/sf.php"] [unique_id "apPlWwi65Hcg2zUJjxBnGQAAAks"]
[Sun Aug 30 03:10:03.692606 2026] [security2:error] [pid 515259:tid 515391] [client 147.182.191.52:55291] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "yourdreampet.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "apPlW2ZcVaai59truiVgLAAAAAE"]
[Sun Aug 30 03:10:03.698413 2026] [security2:error] [pid 512881:tid 513094] [client 20.104.18.15:35156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/sushi.php"] [unique_id "apPlWwi65Hcg2zUJjxBnIQAAAmc"]
[Sun Aug 30 03:10:03.703394 2026] [security2:error] [pid 512881:tid 513020] [client 20.104.50.220:61446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/kndw1.php"] [unique_id "apPlWwi65Hcg2zUJjxBnJAAAAh0"]
[Sun Aug 30 03:10:03.705615 2026] [security2:error] [pid 512881:tid 513015] [client 20.104.50.220:42461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wsoshell.php"] [unique_id "apPlWwi65Hcg2zUJjxBnKQAAAhg"]
[Sun Aug 30 03:10:03.708817 2026] [security2:error] [pid 512881:tid 513029] [client 20.104.18.15:22410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/samll.php"] [unique_id "apPlWwi65Hcg2zUJjxBnKwAAAiY"]
[Sun Aug 30 03:10:03.712272 2026] [security2:error] [pid 512881:tid 513071] [client 158.23.147.79:41547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/dropdown.php"] [unique_id "apPlWwi65Hcg2zUJjxBnMAAAAlA"]
[Sun Aug 30 03:10:03.715269 2026] [security2:error] [pid 512881:tid 513031] [client 20.48.251.3:60480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/product.php"] [unique_id "apPlWwi65Hcg2zUJjxBnMQAAAig"]
[Sun Aug 30 03:10:03.729112 2026] [security2:error] [pid 512881:tid 513112] [client 20.63.81.20:36672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/35iDq8NAjLu.php"] [unique_id "apPlWwi65Hcg2zUJjxBnPwAAAnk"]
[Sun Aug 30 03:10:03.736487 2026] [authz_core:error] [pid 512881:tid 513097] [client 66.249.66.45:49848] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:03.736952 2026] [authz_core:error] [pid 512881:tid 513097] [client 66.249.66.45:49848] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:03.740084 2026] [security2:error] [pid 515259:tid 515461] [client 4.205.62.107:25769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/adminer-4.7.6-en.php"] [unique_id "apPlW2ZcVaai59truiVgMAAAAEc"]
[Sun Aug 30 03:10:03.746509 2026] [security2:error] [pid 515259:tid 515488] [client 4.205.62.107:61757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/debuggen.php"] [unique_id "apPlW2ZcVaai59truiVgMgAAAGI"]
[Sun Aug 30 03:10:03.753250 2026] [security2:error] [pid 515259:tid 515500] [client 68.155.159.216:54324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-content/cong.php"] [unique_id "apPlW2ZcVaai59truiVgMwAAAG4"]
[Sun Aug 30 03:10:03.810142 2026] [security2:error] [pid 512881:tid 513106] [client 20.104.18.15:43991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/w.php"] [unique_id "apPlWwi65Hcg2zUJjxBnXgAAAnM"]
[Sun Aug 30 03:10:03.818583 2026] [security2:error] [pid 512881:tid 513056] [client 158.23.184.117:13208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/wp-admin/.cfg_aae.php"] [unique_id "apPlWwi65Hcg2zUJjxBnYQAAAkE"]
[Sun Aug 30 03:10:03.843727 2026] [security2:error] [pid 515259:tid 515419] [client 20.104.18.15:18422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/coffexium.php"] [unique_id "apPlW2ZcVaai59truiVgPAAAAB0"]
[Sun Aug 30 03:10:03.849359 2026] [security2:error] [pid 515259:tid 515467] [client 158.23.147.79:42842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/sad/about.php"] [unique_id "apPlW2ZcVaai59truiVgPwAAAE0"]
[Sun Aug 30 03:10:03.855904 2026] [security2:error] [pid 512881:tid 513012] [client 20.104.50.220:5940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/register.php"] [unique_id "apPlWwi65Hcg2zUJjxBndQAAAhU"]
[Sun Aug 30 03:10:03.856359 2026] [security2:error] [pid 512881:tid 513060] [client 20.63.81.20:36754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/btx25.php"] [unique_id "apPlWwi65Hcg2zUJjxBndgAAAkU"]
[Sun Aug 30 03:10:03.862185 2026] [authz_core:error] [pid 515259:tid 515455] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:03.862483 2026] [authz_core:error] [pid 515259:tid 515455] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:03.892533 2026] [security2:error] [pid 512881:tid 513048] [client 20.104.50.220:33053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-0.php"] [unique_id "apPlWwi65Hcg2zUJjxBnkAAAAjk"]
[Sun Aug 30 03:10:03.931990 2026] [authz_core:error] [pid 515259:tid 515444] [client 66.249.66.39:59225] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:03.932391 2026] [authz_core:error] [pid 515259:tid 515444] [client 66.249.66.39:59225] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:03.961473 2026] [security2:error] [pid 512881:tid 513106] [client 158.23.184.117:13202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/wp-content/.wp_a1f.php"] [unique_id "apPlWwi65Hcg2zUJjxBnsAAAAnM"]
[Sun Aug 30 03:10:03.987996 2026] [security2:error] [pid 512881:tid 513103] [client 20.63.81.20:36780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/radio.php"] [unique_id "apPlWwi65Hcg2zUJjxBnwwAAAnA"]
[Sun Aug 30 03:10:03.991223 2026] [security2:error] [pid 512881:tid 513020] [client 158.23.147.79:41576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/admin.php"] [unique_id "apPlWwi65Hcg2zUJjxBnxQAAAh0"]
[Sun Aug 30 03:10:04.017008 2026] [security2:error] [pid 512881:tid 513030] [client 20.104.50.220:31815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/admin.php"] [unique_id "apPlXAi65Hcg2zUJjxBn1QAAAic"]
[Sun Aug 30 03:10:04.031895 2026] [security2:error] [pid 512881:tid 513023] [client 158.23.147.79:1995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/classwithtostring.php"] [unique_id "apPlXAi65Hcg2zUJjxBn2QAAAiA"]
[Sun Aug 30 03:10:04.074691 2026] [security2:error] [pid 512881:tid 513121] [client 20.151.200.44:28555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/log.php"] [unique_id "apPlXAi65Hcg2zUJjxBn6AAAAoI"]
[Sun Aug 30 03:10:04.101323 2026] [security2:error] [pid 512881:tid 513112] [client 158.23.184.117:13214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/12.php"] [unique_id "apPlXAi65Hcg2zUJjxBn-gAAAnk"]
[Sun Aug 30 03:10:04.103681 2026] [security2:error] [pid 515259:tid 515471] [client 20.48.160.90:61409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlXGZcVaai59truiVgZwAAAFE"]
[Sun Aug 30 03:10:04.115114 2026] [security2:error] [pid 515259:tid 515417] [client 20.63.81.20:36679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/dex.php"] [unique_id "apPlXGZcVaai59truiVgaQAAABs"]
[Sun Aug 30 03:10:04.115200 2026] [security2:error] [pid 512881:tid 513109] [client 158.23.147.79:42850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-admin/admin.php"] [unique_id "apPlXAi65Hcg2zUJjxBn_wAAAnY"]
[Sun Aug 30 03:10:04.119326 2026] [security2:error] [pid 512881:tid 513053] [client 20.48.251.3:65519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/public/vx.php"] [unique_id "apPlXAi65Hcg2zUJjxBoAgAAAj4"]
[Sun Aug 30 03:10:04.131014 2026] [security2:error] [pid 512881:tid 513119] [client 20.151.200.44:65454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/motu.php"] [unique_id "apPlXAi65Hcg2zUJjxBoBAAAAoA"]
[Sun Aug 30 03:10:04.150069 2026] [security2:error] [pid 512881:tid 513056] [client 4.205.62.107:36679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/koiy.php"] [unique_id "apPlXAi65Hcg2zUJjxBoCgAAAkE"]
[Sun Aug 30 03:10:04.176986 2026] [security2:error] [pid 515259:tid 515416] [client 20.104.50.220:28706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/abc.php"] [unique_id "apPlXGZcVaai59truiVgbwAAABo"]
[Sun Aug 30 03:10:04.224757 2026] [security2:error] [pid 515259:tid 515484] [client 158.23.147.79:41549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apPlXGZcVaai59truiVgdgAAAF4"]
[Sun Aug 30 03:10:04.240925 2026] [security2:error] [pid 515259:tid 515405] [client 158.23.184.117:13226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/colour.php"] [unique_id "apPlXGZcVaai59truiVgewAAAA8"]
[Sun Aug 30 03:10:04.241552 2026] [security2:error] [pid 515259:tid 515406] [client 20.63.81.20:36840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/giodywky.php"] [unique_id "apPlXGZcVaai59truiVgfAAAABA"]
[Sun Aug 30 03:10:04.304916 2026] [authz_core:error] [pid 512881:tid 513057] [client 216.73.216.128:4446] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:04.305295 2026] [authz_core:error] [pid 512881:tid 513057] [client 216.73.216.128:4446] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:04.325953 2026] [security2:error] [pid 512881:tid 513121] [client 158.23.147.79:42848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/classwithtostring.php"] [unique_id "apPlXAi65Hcg2zUJjxBoOwAAAoI"]
[Sun Aug 30 03:10:04.354815 2026] [security2:error] [pid 515259:tid 515403] [client 20.48.160.90:61429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlXGZcVaai59truiVggAAAAA0"]
[Sun Aug 30 03:10:04.367981 2026] [authz_core:error] [pid 515259:tid 515456] [client 66.249.66.194:56292] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:04.368233 2026] [security2:error] [pid 512881:tid 513051] [client 20.63.81.20:36760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp-kz.php"] [unique_id "apPlXAi65Hcg2zUJjxBoPwAAAjw"]
[Sun Aug 30 03:10:04.368445 2026] [authz_core:error] [pid 515259:tid 515456] [client 66.249.66.194:56292] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:04.373084 2026] [authz_core:error] [pid 512881:tid 513032] [client 66.249.66.69:54891] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:04.373545 2026] [authz_core:error] [pid 512881:tid 513032] [client 66.249.66.69:54891] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:04.379553 2026] [security2:error] [pid 512881:tid 513062] [client 158.23.184.117:12868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/wp-admin/network/themes.php"] [unique_id "apPlXAi65Hcg2zUJjxBoQAAAAkc"]
[Sun Aug 30 03:10:04.394773 2026] [authz_core:error] [pid 515259:tid 515450] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:04.395243 2026] [authz_core:error] [pid 515259:tid 515450] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:04.418747 2026] [authz_core:error] [pid 515259:tid 515477] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:04.419247 2026] [authz_core:error] [pid 515259:tid 515477] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:04.422083 2026] [core:error] [pid 515259:tid 515494] [client 158.23.184.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:10:04.422109 2026] [core:error] [pid 515259:tid 515494] [client 158.23.184.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:10:04.443839 2026] [security2:error] [pid 512881:tid 513024] [client 158.23.147.79:41550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/install.php"] [unique_id "apPlXAi65Hcg2zUJjxBoRAAAAiE"]
[Sun Aug 30 03:10:04.461496 2026] [security2:error] [pid 512881:tid 513103] [client 158.23.147.79:60187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlXAi65Hcg2zUJjxBoSAAAAnA"]
[Sun Aug 30 03:10:04.481354 2026] [security2:error] [pid 512881:tid 512950] [remote 68.155.159.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ibrgroup.in"] [uri "/.well-known/content.php"] [unique_id "apPlXAi65Hcg2zUJjxBoSwACiUQ"]
[Sun Aug 30 03:10:04.494006 2026] [security2:error] [pid 512881:tid 513036] [client 20.63.81.20:36697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp-includes/ID3/getid.php"] [unique_id "apPlXAi65Hcg2zUJjxBoTAAAAi0"]
[Sun Aug 30 03:10:04.518945 2026] [security2:error] [pid 512881:tid 513126] [client 158.23.184.117:13201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/wp-admin/post.php"] [unique_id "apPlXAi65Hcg2zUJjxBoUgAAAoc"]
[Sun Aug 30 03:10:04.532195 2026] [security2:error] [pid 512881:tid 513082] [client 20.48.160.90:61411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/ap.php"] [unique_id "apPlXAi65Hcg2zUJjxBoVQAAAls"]
[Sun Aug 30 03:10:04.549198 2026] [security2:error] [pid 512881:tid 513112] [client 158.23.147.79:41581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-content/x/index.php"] [unique_id "apPlXAi65Hcg2zUJjxBoWwAAAnk"]
[Sun Aug 30 03:10:04.590907 2026] [security2:error] [pid 515259:tid 515492] [client 158.23.147.79:57676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/install.php"] [unique_id "apPlXGZcVaai59truiVgkAAAAGY"]
[Sun Aug 30 03:10:04.609077 2026] [authz_core:error] [pid 512881:tid 513094] [client 216.73.216.128:4446] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:04.609355 2026] [authz_core:error] [pid 512881:tid 513094] [client 216.73.216.128:4446] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:04.623081 2026] [security2:error] [pid 512881:tid 513026] [client 20.63.81.20:36757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/session.php"] [unique_id "apPlXAi65Hcg2zUJjxBocAAAAiM"]
[Sun Aug 30 03:10:04.659427 2026] [security2:error] [pid 512881:tid 513108] [client 158.23.184.117:13242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPlXAi65Hcg2zUJjxBohgAAAnU"]
[Sun Aug 30 03:10:04.673051 2026] [security2:error] [pid 512881:tid 513132] [client 20.48.160.90:61394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/media.php"] [unique_id "apPlXAi65Hcg2zUJjxBojwAAAo0"]
[Sun Aug 30 03:10:04.682467 2026] [security2:error] [pid 512881:tid 513082] [client 20.104.49.130:53640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/dk.php"] [unique_id "apPlXAi65Hcg2zUJjxBolAAAAls"]
[Sun Aug 30 03:10:04.704197 2026] [security2:error] [pid 515259:tid 515397] [client 20.104.49.130:36791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/load.php"] [unique_id "apPlXGZcVaai59truiVgpQAAAAc"]
[Sun Aug 30 03:10:04.705370 2026] [security2:error] [pid 515259:tid 515481] [client 20.151.200.44:41978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/wk/index.php"] [unique_id "apPlXGZcVaai59truiVgpgAAAFs"]
[Sun Aug 30 03:10:04.720605 2026] [security2:error] [pid 512881:tid 513070] [client 158.23.147.79:10210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apPlXAi65Hcg2zUJjxBopgAAAk8"]
[Sun Aug 30 03:10:04.724872 2026] [security2:error] [pid 512881:tid 513102] [client 68.155.159.216:63277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apPlXAi65Hcg2zUJjxBorAAAAm8"]
[Sun Aug 30 03:10:04.750622 2026] [security2:error] [pid 512881:tid 513072] [client 20.63.81.20:36742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/eagle.php"] [unique_id "apPlXAi65Hcg2zUJjxBouQAAAlE"]
[Sun Aug 30 03:10:04.763272 2026] [security2:error] [pid 512881:tid 513054] [client 68.155.159.216:46003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-includes/js/index.php"] [unique_id "apPlXAi65Hcg2zUJjxBovgAAAj8"]
[Sun Aug 30 03:10:04.798777 2026] [security2:error] [pid 512881:tid 513110] [client 20.104.50.220:17229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/cong.php"] [unique_id "apPlXAi65Hcg2zUJjxBozAAAAnc"]
[Sun Aug 30 03:10:04.802419 2026] [security2:error] [pid 515259:tid 515394] [client 20.104.49.130:54176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/v2.php"] [unique_id "apPlXGZcVaai59truiVgsQAAAAQ"]
[Sun Aug 30 03:10:04.813681 2026] [security2:error] [pid 515259:tid 515423] [client 20.104.18.15:64879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/file61.php"] [unique_id "apPlXGZcVaai59truiVgswAAACE"]
[Sun Aug 30 03:10:04.813962 2026] [security2:error] [pid 512881:tid 513071] [client 4.205.62.107:17117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/wp-konfig.php"] [unique_id "apPlXAi65Hcg2zUJjxBo0QAAAlA"]
[Sun Aug 30 03:10:04.823424 2026] [security2:error] [pid 512881:tid 513106] [client 20.104.50.220:51008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/test11.php"] [unique_id "apPlXAi65Hcg2zUJjxBo1QAAAnM"]
[Sun Aug 30 03:10:04.824011 2026] [security2:error] [pid 512881:tid 513093] [client 20.48.251.3:59333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/goods.php"] [unique_id "apPlXAi65Hcg2zUJjxBo1gAAAmY"]
[Sun Aug 30 03:10:04.831066 2026] [security2:error] [pid 512881:tid 513062] [client 20.48.251.3:59477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/25.php"] [unique_id "apPlXAi65Hcg2zUJjxBo3QAAAkc"]
[Sun Aug 30 03:10:04.844080 2026] [security2:error] [pid 512881:tid 513057] [client 20.48.160.90:61325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/adminfuns.php"] [unique_id "apPlXAi65Hcg2zUJjxBo4wAAAkI"]
[Sun Aug 30 03:10:04.846820 2026] [security2:error] [pid 512881:tid 513087] [client 158.23.147.79:41538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apPlXAi65Hcg2zUJjxBo5gAAAmA"]
[Sun Aug 30 03:10:04.850231 2026] [security2:error] [pid 512881:tid 513085] [client 20.48.251.3:13415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/fun.php"] [unique_id "apPlXAi65Hcg2zUJjxBo6wAAAl4"]
[Sun Aug 30 03:10:04.858049 2026] [security2:error] [pid 512881:tid 513045] [client 158.23.184.117:12885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/wp-content/post.php"] [unique_id "apPlXAi65Hcg2zUJjxBo8gAAAjY"]
[Sun Aug 30 03:10:04.861989 2026] [security2:error] [pid 512881:tid 513063] [client 20.104.18.15:22512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/she11.php"] [unique_id "apPlXAi65Hcg2zUJjxBo9gAAAkg"]
[Sun Aug 30 03:10:04.863626 2026] [security2:error] [pid 512881:tid 513091] [client 20.104.18.15:16933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/k.php"] [unique_id "apPlXAi65Hcg2zUJjxBo-gAAAmQ"]
[Sun Aug 30 03:10:04.864129 2026] [security2:error] [pid 512881:tid 513130] [client 20.104.18.15:35177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/manga.php"] [unique_id "apPlXAi65Hcg2zUJjxBo-wAAAos"]
[Sun Aug 30 03:10:04.867252 2026] [security2:error] [pid 512881:tid 513081] [client 20.104.50.220:61652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/la.php"] [unique_id "apPlXAi65Hcg2zUJjxBpAAAAAlo"]
[Sun Aug 30 03:10:04.868460 2026] [security2:error] [pid 512881:tid 513016] [client 4.205.62.107:25893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/phpi.php"] [unique_id "apPlXAi65Hcg2zUJjxBpAgAAAhk"]
[Sun Aug 30 03:10:04.879334 2026] [security2:error] [pid 512881:tid 513099] [client 20.104.50.220:63519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/autoload_classmap.php"] [unique_id "apPlXAi65Hcg2zUJjxBpBwAAAmw"]
[Sun Aug 30 03:10:04.885326 2026] [security2:error] [pid 515259:tid 515415] [client 20.63.81.20:36836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/up-kon.php"] [unique_id "apPlXGZcVaai59truiVgwQAAABk"]
[Sun Aug 30 03:10:04.900875 2026] [security2:error] [pid 512881:tid 513100] [client 4.205.62.107:61751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/pouhg.php"] [unique_id "apPlXAi65Hcg2zUJjxBpEwAAAm0"]
[Sun Aug 30 03:10:04.906346 2026] [authz_core:error] [pid 515259:tid 515440] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:04.906673 2026] [authz_core:error] [pid 515259:tid 515440] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:04.929238 2026] [security2:error] [pid 512881:tid 513014] [client 20.104.50.220:29131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/DA.php"] [unique_id "apPlXAi65Hcg2zUJjxBpIAAAAhc"]
[Sun Aug 30 03:10:04.950533 2026] [security2:error] [pid 512881:tid 513133] [client 20.104.18.15:44017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/x.php"] [unique_id "apPlXAi65Hcg2zUJjxBpKAAAAo4"]
[Sun Aug 30 03:10:04.952214 2026] [security2:error] [pid 512881:tid 513114] [client 158.23.147.79:10176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-login.php"] [unique_id "apPlXAi65Hcg2zUJjxBpKgAAAns"]
[Sun Aug 30 03:10:04.979307 2026] [security2:error] [pid 512881:tid 513123] [client 20.48.160.90:63918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/classwithtostring.php"] [unique_id "apPlXAi65Hcg2zUJjxBpQgAAAoQ"]
[Sun Aug 30 03:10:04.986924 2026] [security2:error] [pid 512881:tid 513050] [client 68.155.159.216:52576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPlXAi65Hcg2zUJjxBpRwAAAjs"]
[Sun Aug 30 03:10:05.015067 2026] [security2:error] [pid 515259:tid 515441] [client 20.63.81.20:36814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/tinny.php"] [unique_id "apPlXWZcVaai59truiVg1wAAADM"]
[Sun Aug 30 03:10:05.016858 2026] [security2:error] [pid 512881:tid 513098] [client 20.104.18.15:18390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/BDKR28WP.php"] [unique_id "apPlXQi65Hcg2zUJjxBpVAAAAms"]
[Sun Aug 30 03:10:05.024368 2026] [security2:error] [pid 512881:tid 513013] [client 158.23.147.79:57711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-content/x/index.php"] [unique_id "apPlXQi65Hcg2zUJjxBpWAAAAhY"]
[Sun Aug 30 03:10:05.036031 2026] [security2:error] [pid 512881:tid 513133] [client 20.104.50.220:33161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-1.php"] [unique_id "apPlXQi65Hcg2zUJjxBpXAAAAo4"]
[Sun Aug 30 03:10:05.047271 2026] [security2:error] [pid 512881:tid 513036] [client 20.104.49.130:63562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/menu.php"] [unique_id "apPlXQi65Hcg2zUJjxBpYQAAAi0"]
[Sun Aug 30 03:10:05.058903 2026] [security2:error] [pid 515259:tid 515416] [client 158.23.147.79:41573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apPlXWZcVaai59truiVg2wAAABo"]
[Sun Aug 30 03:10:05.069721 2026] [security2:error] [pid 512881:tid 513071] [client 158.23.184.117:13244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "apPlXQi65Hcg2zUJjxBpagAAAlA"]
[Sun Aug 30 03:10:05.097768 2026] [security2:error] [pid 515259:tid 515486] [client 20.104.50.220:5212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/developer.php"] [unique_id "apPlXWZcVaai59truiVg4QAAAGA"]
[Sun Aug 30 03:10:05.112398 2026] [authz_core:error] [pid 515259:tid 515489] [client 66.249.66.198:58631] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:05.112701 2026] [authz_core:error] [pid 515259:tid 515489] [client 66.249.66.198:58631] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:05.145721 2026] [security2:error] [pid 512881:tid 513133] [client 20.63.81.20:36699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp-easy.php"] [unique_id "apPlXQi65Hcg2zUJjxBpjQAAAo4"]
[Sun Aug 30 03:10:05.149303 2026] [security2:error] [pid 512881:tid 513036] [client 20.48.160.90:63945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPlXQi65Hcg2zUJjxBpkQAAAi0"]
[Sun Aug 30 03:10:05.159504 2026] [security2:error] [pid 515259:tid 515456] [client 158.23.147.79:42832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-admin/images/about.php"] [unique_id "apPlXWZcVaai59truiVg8AAAAEI"]
[Sun Aug 30 03:10:05.167747 2026] [security2:error] [pid 512881:tid 513118] [client 20.104.50.220:31843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.38cupscreen.cover789.com"] [uri "/lv.php"] [unique_id "apPlXQi65Hcg2zUJjxBpmgAAAn8"]
[Sun Aug 30 03:10:05.202698 2026] [security2:error] [pid 512881:tid 513100] [client 20.151.200.44:64178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/wefile.php"] [unique_id "apPlXQi65Hcg2zUJjxBppgAAAm0"]
[Sun Aug 30 03:10:05.261789 2026] [security2:error] [pid 512881:tid 513099] [client 158.23.147.79:41546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPlXQi65Hcg2zUJjxBprAAAAmw"]
[Sun Aug 30 03:10:05.265127 2026] [security2:error] [pid 515259:tid 515429] [client 20.48.251.3:64287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/log.php"] [unique_id "apPlXWZcVaai59truiVg_gAAACc"]
[Sun Aug 30 03:10:05.272657 2026] [security2:error] [pid 512881:tid 513019] [client 20.63.81.20:36703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/d7.php"] [unique_id "apPlXQi65Hcg2zUJjxBprQAAAhw"]
[Sun Aug 30 03:10:05.286120 2026] [security2:error] [pid 515259:tid 515507] [client 158.23.184.117:13210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/ma.php"] [unique_id "apPlXWZcVaai59truiVhAQAAAHU"]
[Sun Aug 30 03:10:05.308887 2026] [security2:error] [pid 512881:tid 513079] [client 4.205.62.107:36735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/queue.php"] [unique_id "apPlXQi65Hcg2zUJjxBptAAAAlg"]
[Sun Aug 30 03:10:05.325153 2026] [security2:error] [pid 512881:tid 513124] [client 20.104.50.220:29126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/indexx.php"] [unique_id "apPlXQi65Hcg2zUJjxBpvAAAAoU"]
[Sun Aug 30 03:10:05.350653 2026] [security2:error] [pid 512881:tid 513035] [client 20.48.160.90:63924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/5PJcpMFsD8B.php"] [unique_id "apPlXQi65Hcg2zUJjxBpvQAAAiw"]
[Sun Aug 30 03:10:05.376416 2026] [authz_core:error] [pid 515259:tid 515492] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:05.376912 2026] [authz_core:error] [pid 515259:tid 515492] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:05.377355 2026] [security2:error] [pid 512881:tid 513116] [client 158.23.147.79:57709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apPlXQi65Hcg2zUJjxBpwgAAAn0"]
[Sun Aug 30 03:10:05.399972 2026] [security2:error] [pid 515259:tid 515425] [client 20.63.81.20:36769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/v5.php"] [unique_id "apPlXWZcVaai59truiVhBAAAACM"]
[Sun Aug 30 03:10:05.455793 2026] [security2:error] [pid 512881:tid 513113] [client 158.23.147.79:42838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-admin.php"] [unique_id "apPlXQi65Hcg2zUJjxBpywAAAno"]
[Sun Aug 30 03:10:05.478327 2026] [security2:error] [pid 512881:tid 513076] [client 158.23.184.117:13237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/xleet.php"] [unique_id "apPlXQi65Hcg2zUJjxBp0AAAAlU"]
[Sun Aug 30 03:10:05.484072 2026] [security2:error] [pid 515259:tid 515469] [client 20.48.160.90:63952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPlXWZcVaai59truiVhBgAAAE8"]
[Sun Aug 30 03:10:05.516839 2026] [authz_core:error] [pid 512881:tid 513128] [client 66.249.66.42:37567] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:05.517315 2026] [authz_core:error] [pid 512881:tid 513128] [client 66.249.66.42:37567] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:05.527892 2026] [security2:error] [pid 512881:tid 513071] [client 20.63.81.20:36861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/az.php"] [unique_id "apPlXQi65Hcg2zUJjxBp1wAAAlA"]
[Sun Aug 30 03:10:05.564548 2026] [security2:error] [pid 515259:tid 515466] [client 20.151.200.44:28589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/xwpg.php"] [unique_id "apPlXWZcVaai59truiVhCwAAAEw"]
[Sun Aug 30 03:10:05.597457 2026] [security2:error] [pid 515259:tid 515461] [client 158.23.147.79:41591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apPlXWZcVaai59truiVhEgAAAEc"]
[Sun Aug 30 03:10:05.620199 2026] [security2:error] [pid 515259:tid 515482] [client 158.23.184.117:13218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/.well-known/pki-validation/fm.php"] [unique_id "apPlXWZcVaai59truiVhFAAAAFw"]
[Sun Aug 30 03:10:05.654394 2026] [security2:error] [pid 515259:tid 515500] [client 20.63.81.20:36687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/js.php"] [unique_id "apPlXWZcVaai59truiVhGQAAAG4"]
[Sun Aug 30 03:10:05.695661 2026] [security2:error] [pid 515259:tid 515409] [client 216.73.216.128:53251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPlXWZcVaai59truiVhHAAAABM"]
[Sun Aug 30 03:10:05.705373 2026] [security2:error] [pid 512881:tid 513085] [client 158.23.147.79:41556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/lock.php"] [unique_id "apPlXQi65Hcg2zUJjxBqHQAAAl4"]
[Sun Aug 30 03:10:05.712106 2026] [security2:error] [pid 512881:tid 513063] [client 20.48.160.90:63973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/wsd.php"] [unique_id "apPlXQi65Hcg2zUJjxBqJAAAAkg"]
[Sun Aug 30 03:10:05.719381 2026] [authz_core:error] [pid 512881:tid 513094] [client 66.249.66.43:41466] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:05.719813 2026] [authz_core:error] [pid 512881:tid 513094] [client 66.249.66.43:41466] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:05.758530 2026] [security2:error] [pid 512881:tid 513021] [client 158.23.184.117:12865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/wp-admin/user.php"] [unique_id "apPlXQi65Hcg2zUJjxBqQQAAAh4"]
[Sun Aug 30 03:10:05.792441 2026] [authz_core:error] [pid 512881:tid 513114] [client 216.73.216.128:29937] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:05.792762 2026] [authz_core:error] [pid 512881:tid 513114] [client 216.73.216.128:29937] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:05.794837 2026] [security2:error] [pid 512881:tid 513020] [client 20.104.49.130:52151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/images.php"] [unique_id "apPlXQi65Hcg2zUJjxBqTgAAAh0"]
[Sun Aug 30 03:10:05.795303 2026] [security2:error] [pid 512881:tid 513029] [client 20.63.81.20:36857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/hd.php"] [unique_id "apPlXQi65Hcg2zUJjxBqTwAAAiY"]
[Sun Aug 30 03:10:05.844036 2026] [security2:error] [pid 512881:tid 513116] [client 158.23.147.79:10213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/index/function.php"] [unique_id "apPlXQi65Hcg2zUJjxBqYgAAAn0"]
[Sun Aug 30 03:10:05.852828 2026] [security2:error] [pid 512881:tid 513040] [client 68.155.159.216:63233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-content/admin.php"] [unique_id "apPlXQi65Hcg2zUJjxBqbAAAAjE"]
[Sun Aug 30 03:10:05.855993 2026] [authz_core:error] [pid 515259:tid 515443] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:05.856451 2026] [authz_core:error] [pid 515259:tid 515443] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:05.878061 2026] [security2:error] [pid 512881:tid 513056] [client 216.73.216.128:4446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/'+this.controller.state().get("] [unique_id "apPlXQi65Hcg2zUJjxBqhQAAAkE"]
[Sun Aug 30 03:10:05.881344 2026] [security2:error] [pid 515259:tid 515412] [client 20.48.160.90:63972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/bulet.php"] [unique_id "apPlXWZcVaai59truiVhLAAAABY"]
[Sun Aug 30 03:10:05.897764 2026] [security2:error] [pid 512881:tid 513031] [client 158.23.184.117:12873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/wp-admin/radio.php"] [unique_id "apPlXQi65Hcg2zUJjxBqkwAAAig"]
[Sun Aug 30 03:10:05.904271 2026] [security2:error] [pid 512881:tid 513074] [client 68.155.159.216:46063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-content/index.php"] [unique_id "apPlXQi65Hcg2zUJjxBqmAAAAlM"]
[Sun Aug 30 03:10:05.923284 2026] [security2:error] [pid 512881:tid 513019] [client 20.63.81.20:36805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/xl2023.php"] [unique_id "apPlXQi65Hcg2zUJjxBqoQAAAhw"]
[Sun Aug 30 03:10:05.936941 2026] [authz_core:error] [pid 515259:tid 515501] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:05.937234 2026] [authz_core:error] [pid 515259:tid 515501] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:05.941880 2026] [security2:error] [pid 512881:tid 513072] [client 20.104.50.220:17219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/w.php"] [unique_id "apPlXQi65Hcg2zUJjxBqpwAAAlE"]
[Sun Aug 30 03:10:05.950142 2026] [security2:error] [pid 515259:tid 515436] [client 4.205.62.107:17125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/25.php"] [unique_id "apPlXWZcVaai59truiVhMgAAAC4"]
[Sun Aug 30 03:10:05.951849 2026] [security2:error] [pid 512881:tid 513109] [client 20.104.18.15:64838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/copypaths.php"] [unique_id "apPlXQi65Hcg2zUJjxBqrAAAAnY"]
[Sun Aug 30 03:10:05.962051 2026] [security2:error] [pid 512881:tid 513121] [client 20.48.251.3:59328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/loxi-o.php"] [unique_id "apPlXQi65Hcg2zUJjxBqtAAAAoI"]
[Sun Aug 30 03:10:05.968267 2026] [security2:error] [pid 515259:tid 515427] [client 158.23.147.79:42879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/.well-known/content.php"] [unique_id "apPlXWZcVaai59truiVhNgAAACU"]
[Sun Aug 30 03:10:05.971946 2026] [authz_core:error] [pid 512881:tid 513020] [client 66.249.66.69:54891] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:05.972339 2026] [authz_core:error] [pid 512881:tid 513020] [client 66.249.66.69:54891] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:05.977136 2026] [security2:error] [pid 515259:tid 515476] [client 20.104.50.220:59348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/koala.php"] [unique_id "apPlXWZcVaai59truiVhOgAAAFY"]
[Sun Aug 30 03:10:05.987443 2026] [security2:error] [pid 515259:tid 515391] [client 20.48.251.3:59509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/nlnub.php"] [unique_id "apPlXWZcVaai59truiVhOwAAAAE"]
[Sun Aug 30 03:10:06.012436 2026] [security2:error] [pid 515259:tid 515489] [client 20.104.18.15:16921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/82.php"] [unique_id "apPlXmZcVaai59truiVhQwAAAGM"]
[Sun Aug 30 03:10:06.014201 2026] [security2:error] [pid 515259:tid 515505] [client 20.104.50.220:63523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/12.php"] [unique_id "apPlXmZcVaai59truiVhRgAAAHM"]
[Sun Aug 30 03:10:06.015234 2026] [security2:error] [pid 512881:tid 513056] [client 20.104.18.15:22402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/kerang.php"] [unique_id "apPlXgi65Hcg2zUJjxBq0wAAAkE"]
[Sun Aug 30 03:10:06.015460 2026] [security2:error] [pid 512881:tid 513012] [client 20.104.18.15:35179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/asdfghj.php"] [unique_id "apPlXgi65Hcg2zUJjxBq1AAAAhU"]
[Sun Aug 30 03:10:06.039458 2026] [security2:error] [pid 512881:tid 513025] [client 4.205.62.107:25876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/wp-admin/css/bolt.php"] [unique_id "apPlXgi65Hcg2zUJjxBq2QAAAiI"]
[Sun Aug 30 03:10:06.042333 2026] [security2:error] [pid 512881:tid 513072] [client 20.104.50.220:61416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/lnedx.php"] [unique_id "apPlXgi65Hcg2zUJjxBq3AAAAlE"]
[Sun Aug 30 03:10:06.051475 2026] [security2:error] [pid 512881:tid 513075] [client 20.63.81.20:36773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/V2.php"] [unique_id "apPlXgi65Hcg2zUJjxBq4AAAAlQ"]
[Sun Aug 30 03:10:06.064476 2026] [security2:error] [pid 512881:tid 513079] [client 20.48.251.3:56322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/kedi.php"] [unique_id "apPlXgi65Hcg2zUJjxBq5wAAAlg"]
[Sun Aug 30 03:10:06.077518 2026] [security2:error] [pid 512881:tid 513104] [client 20.104.50.220:62830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/bismilah.php"] [unique_id "apPlXgi65Hcg2zUJjxBq7AAAAnE"]
[Sun Aug 30 03:10:06.084639 2026] [security2:error] [pid 512881:tid 513036] [client 158.23.147.79:41563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/cong.php"] [unique_id "apPlXgi65Hcg2zUJjxBq8wAAAi0"]
[Sun Aug 30 03:10:06.089357 2026] [security2:error] [pid 515259:tid 515472] [client 20.104.18.15:43275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/ssla.php"] [unique_id "apPlXmZcVaai59truiVhUgAAAFI"]
[Sun Aug 30 03:10:06.095654 2026] [security2:error] [pid 512881:tid 513044] [client 158.23.184.117:13221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/bypass.php7"] [unique_id "apPlXgi65Hcg2zUJjxBq-AAAAjU"]
[Sun Aug 30 03:10:06.102842 2026] [security2:error] [pid 512881:tid 513084] [client 4.205.62.107:61783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/phpversion.php"] [unique_id "apPlXgi65Hcg2zUJjxBrAAAAAl0"]
[Sun Aug 30 03:10:06.149609 2026] [security2:error] [pid 512881:tid 513109] [client 20.151.200.44:40847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlXgi65Hcg2zUJjxBrFgAAAnY"]
[Sun Aug 30 03:10:06.163064 2026] [security2:error] [pid 512881:tid 513036] [client 20.104.18.15:18324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/sf.php"] [unique_id "apPlXgi65Hcg2zUJjxBrHQAAAi0"]
[Sun Aug 30 03:10:06.177534 2026] [security2:error] [pid 515259:tid 515448] [client 20.63.81.20:36839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/mad.php"] [unique_id "apPlXmZcVaai59truiVhVwAAADo"]
[Sun Aug 30 03:10:06.187042 2026] [security2:error] [pid 515259:tid 515409] [client 158.23.147.79:42834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-includes/js/index.php"] [unique_id "apPlXmZcVaai59truiVhWQAAABM"]
[Sun Aug 30 03:10:06.187853 2026] [security2:error] [pid 512881:tid 513026] [client 20.104.50.220:33553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/xindex.php"] [unique_id "apPlXgi65Hcg2zUJjxBrKQAAAiM"]
[Sun Aug 30 03:10:06.196448 2026] [security2:error] [pid 512881:tid 513091] [client 20.48.160.90:61387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/av.php"] [unique_id "apPlXgi65Hcg2zUJjxBrKwAAAmQ"]
[Sun Aug 30 03:10:06.213470 2026] [authz_core:error] [pid 512881:tid 513034] [client 216.73.216.128:14137] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:06.213764 2026] [authz_core:error] [pid 512881:tid 513034] [client 216.73.216.128:14137] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:06.236634 2026] [security2:error] [pid 512881:tid 513015] [client 158.23.184.117:13241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/wp-admin/css/colors/midnight/wp-login.php"] [unique_id "apPlXgi65Hcg2zUJjxBrPQAAAhg"]
[Sun Aug 30 03:10:06.246565 2026] [security2:error] [pid 512881:tid 513101] [client 20.104.50.220:5530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/dev.php"] [unique_id "apPlXgi65Hcg2zUJjxBrQQAAAm4"]
[Sun Aug 30 03:10:06.257352 2026] [authz_core:error] [pid 515259:tid 515400] [client 216.73.216.128:49549] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:06.257800 2026] [authz_core:error] [pid 515259:tid 515400] [client 216.73.216.128:49549] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:06.267730 2026] [security2:error] [pid 512881:tid 513090] [client 68.155.159.216:54292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPlXgi65Hcg2zUJjxBrRwAAAmM"]
[Sun Aug 30 03:10:06.317527 2026] [security2:error] [pid 512881:tid 513051] [client 20.63.81.20:36762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/st.php"] [unique_id "apPlXgi65Hcg2zUJjxBrTgAAAjw"]
[Sun Aug 30 03:10:06.346461 2026] [authz_core:error] [pid 512881:tid 513107] [client 216.73.216.128:29937] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:06.346755 2026] [authz_core:error] [pid 512881:tid 513107] [client 216.73.216.128:29937] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:06.354255 2026] [security2:error] [pid 512881:tid 513102] [client 158.23.147.79:60222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apPlXgi65Hcg2zUJjxBrVQAAAm8"]
[Sun Aug 30 03:10:06.359237 2026] [security2:error] [pid 512881:tid 513016] [client 20.48.160.90:61316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/images.php"] [unique_id "apPlXgi65Hcg2zUJjxBrVgAAAhk"]
[Sun Aug 30 03:10:06.362598 2026] [authz_core:error] [pid 515259:tid 515499] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:06.363061 2026] [authz_core:error] [pid 515259:tid 515499] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:06.365332 2026] [security2:error] [pid 512881:tid 513038] [client 158.23.147.79:41564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-content/index.php"] [unique_id "apPlXgi65Hcg2zUJjxBrVwAAAi8"]
[Sun Aug 30 03:10:06.377166 2026] [security2:error] [pid 512881:tid 513072] [client 158.23.184.117:12864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/leafmailer.php"] [unique_id "apPlXgi65Hcg2zUJjxBrWAAAAlE"]
[Sun Aug 30 03:10:06.407165 2026] [security2:error] [pid 515259:tid 515503] [client 20.48.251.3:65526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/ebahvhhh.php"] [unique_id "apPlXmZcVaai59truiVhaQAAAHE"]
[Sun Aug 30 03:10:06.426460 2026] [authz_core:error] [pid 515259:tid 515412] [client 66.249.66.41:40790] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:06.426790 2026] [authz_core:error] [pid 515259:tid 515412] [client 66.249.66.41:40790] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:06.443305 2026] [security2:error] [pid 512881:tid 513061] [client 20.63.81.20:36737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/alfanew.php"] [unique_id "apPlXgi65Hcg2zUJjxBrXQAAAkY"]
[Sun Aug 30 03:10:06.481467 2026] [security2:error] [pid 512881:tid 513131] [client 20.104.50.220:28726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/browse.php"] [unique_id "apPlXgi65Hcg2zUJjxBraAAAAow"]
[Sun Aug 30 03:10:06.488969 2026] [security2:error] [pid 515259:tid 515393] [client 20.48.160.90:63875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/ops.php"] [unique_id "apPlXmZcVaai59truiVhbgAAAAM"]
[Sun Aug 30 03:10:06.507687 2026] [authz_core:error] [pid 512881:tid 513104] [client 66.249.66.77:44549] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:06.508024 2026] [authz_core:error] [pid 512881:tid 513104] [client 66.249.66.77:44549] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:06.510391 2026] [security2:error] [pid 512881:tid 513026] [client 158.23.147.79:10222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/about/function.php"] [unique_id "apPlXgi65Hcg2zUJjxBrbgAAAiM"]
[Sun Aug 30 03:10:06.517569 2026] [security2:error] [pid 512881:tid 513099] [client 158.23.184.117:12916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/hplfuns.php"] [unique_id "apPlXgi65Hcg2zUJjxBrcAAAAmw"]
[Sun Aug 30 03:10:06.532108 2026] [security2:error] [pid 515259:tid 515444] [client 4.205.62.107:36551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/doc.php"] [unique_id "apPlXmZcVaai59truiVhcwAAADY"]
[Sun Aug 30 03:10:06.571670 2026] [security2:error] [pid 512881:tid 513064] [client 20.63.81.20:36733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/ioxi.php"] [unique_id "apPlXgi65Hcg2zUJjxBreQAAAkk"]
[Sun Aug 30 03:10:06.632805 2026] [security2:error] [pid 515259:tid 515493] [client 20.48.160.90:61377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/coffexium.php"] [unique_id "apPlXmZcVaai59truiVhfAAAAGc"]
[Sun Aug 30 03:10:06.633249 2026] [security2:error] [pid 512881:tid 513082] [client 158.23.147.79:57672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apPlXgi65Hcg2zUJjxBrjQAAAls"]
[Sun Aug 30 03:10:06.635904 2026] [authz_core:error] [pid 512881:tid 513014] [client 216.73.216.128:29937] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:06.636351 2026] [authz_core:error] [pid 512881:tid 513014] [client 216.73.216.128:29937] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:06.641865 2026] [security2:error] [pid 515259:tid 515438] [client 158.23.147.79:41589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apPlXmZcVaai59truiVhfQAAADA"]
[Sun Aug 30 03:10:06.696306 2026] [authz_core:error] [pid 512881:tid 513081] [client 66.249.66.76:51079] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:06.696700 2026] [authz_core:error] [pid 512881:tid 513081] [client 66.249.66.76:51079] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:06.698113 2026] [security2:error] [pid 512881:tid 513105] [client 20.63.81.20:36791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/TNT.php"] [unique_id "apPlXgi65Hcg2zUJjxBruwAAAnI"]
[Sun Aug 30 03:10:06.755680 2026] [authz_core:error] [pid 512881:tid 513138] [client 66.249.66.78:52005] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:06.756013 2026] [authz_core:error] [pid 512881:tid 513138] [client 66.249.66.78:52005] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:06.759252 2026] [security2:error] [pid 515259:tid 515416] [client 158.23.147.79:42852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-admin/index.php"] [unique_id "apPlXmZcVaai59truiVhjAAAABo"]
[Sun Aug 30 03:10:06.762637 2026] [security2:error] [pid 512881:tid 513107] [client 158.23.184.117:12880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/autoload_classmap/function.php"] [unique_id "apPlXgi65Hcg2zUJjxBr4gAAAnQ"]
[Sun Aug 30 03:10:06.790587 2026] [security2:error] [pid 512881:tid 513077] [client 20.48.160.90:61408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/BDKR28WP.php"] [unique_id "apPlXgi65Hcg2zUJjxBr7gAAAlY"]
[Sun Aug 30 03:10:06.832189 2026] [security2:error] [pid 515259:tid 515394] [client 20.63.81.20:36802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/cd.php"] [unique_id "apPlXmZcVaai59truiVhlQAAAAQ"]
[Sun Aug 30 03:10:06.838824 2026] [security2:error] [pid 515259:tid 515475] [client 20.104.49.130:52521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/Jcrop.php"] [unique_id "apPlXmZcVaai59truiVhlwAAAFU"]
[Sun Aug 30 03:10:06.839163 2026] [security2:error] [pid 515259:tid 515440] [client 20.151.200.44:41926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/dehnl.php"] [unique_id "apPlXmZcVaai59truiVhmQAAADI"]
[Sun Aug 30 03:10:06.844131 2026] [security2:error] [pid 515259:tid 515454] [client 20.104.49.130:52138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/ano.php"] [unique_id "apPlXmZcVaai59truiVhnAAAAEA"]
[Sun Aug 30 03:10:06.845761 2026] [security2:error] [pid 515259:tid 515407] [client 20.104.49.130:53865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/wp.php"] [unique_id "apPlXmZcVaai59truiVhngAAABE"]
[Sun Aug 30 03:10:06.888034 2026] [authz_core:error] [pid 515259:tid 515426] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:06.888317 2026] [authz_core:error] [pid 515259:tid 515426] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:06.910400 2026] [authz_core:error] [pid 512881:tid 513097] [client 66.249.66.66:42658] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:06.910684 2026] [authz_core:error] [pid 512881:tid 513097] [client 66.249.66.66:42658] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:06.952869 2026] [security2:error] [pid 512881:tid 513068] [client 158.23.147.79:42877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPlXgi65Hcg2zUJjxBsTAAAAk0"]
[Sun Aug 30 03:10:06.959781 2026] [security2:error] [pid 512881:tid 513069] [client 68.155.159.216:63268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/xmlrpc.php"] [unique_id "apPlXgi65Hcg2zUJjxBsUwAAAk4"]
[Sun Aug 30 03:10:06.968406 2026] [security2:error] [pid 512881:tid 513122] [client 20.63.81.20:36860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/luuf.php"] [unique_id "apPlXgi65Hcg2zUJjxBsXgAAAoM"]
[Sun Aug 30 03:10:06.987204 2026] [authz_core:error] [pid 512881:tid 513102] [client 66.249.66.65:64144] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:06.987659 2026] [authz_core:error] [pid 512881:tid 513102] [client 66.249.66.65:64144] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:07.003294 2026] [security2:error] [pid 512881:tid 513066] [client 158.23.184.117:13211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/wp-includes/wp-includes/box.php"] [unique_id "apPlXwi65Hcg2zUJjxBsdwAAAks"]
[Sun Aug 30 03:10:07.016423 2026] [security2:error] [pid 512881:tid 513013] [client 20.151.200.44:28655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/sxxb.php"] [unique_id "apPlXwi65Hcg2zUJjxBsegAAAhY"]
[Sun Aug 30 03:10:07.054711 2026] [authz_core:error] [pid 512881:tid 513017] [client 66.249.66.69:54891] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:07.054982 2026] [authz_core:error] [pid 512881:tid 513017] [client 66.249.66.69:54891] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:07.057735 2026] [security2:error] [pid 512881:tid 513060] [client 20.104.49.130:60127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/js.php"] [unique_id "apPlXwi65Hcg2zUJjxBsjgAAAkU"]
[Sun Aug 30 03:10:07.077066 2026] [security2:error] [pid 515259:tid 515486] [client 20.104.50.220:17267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/404.php"] [unique_id "apPlX2ZcVaai59truiVhwwAAAGA"]
[Sun Aug 30 03:10:07.091530 2026] [security2:error] [pid 512881:tid 513137] [client 20.104.18.15:16726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/bless6.php"] [unique_id "apPlXwi65Hcg2zUJjxBsowAAApI"]
[Sun Aug 30 03:10:07.096833 2026] [security2:error] [pid 515259:tid 515410] [client 20.63.81.20:36771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/fex.php"] [unique_id "apPlX2ZcVaai59truiVhygAAABQ"]
[Sun Aug 30 03:10:07.098455 2026] [security2:error] [pid 512881:tid 513128] [client 4.205.62.107:17689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/nlnub.php"] [unique_id "apPlXwi65Hcg2zUJjxBspgAAAok"]
[Sun Aug 30 03:10:07.099571 2026] [security2:error] [pid 512881:tid 513096] [client 20.48.160.90:37624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/sf.php"] [unique_id "apPlXwi65Hcg2zUJjxBspwAAAmk"]
[Sun Aug 30 03:10:07.105422 2026] [security2:error] [pid 515259:tid 515497] [client 20.48.251.3:55720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/f35.php"] [unique_id "apPlX2ZcVaai59truiVhzQAAAGs"]
[Sun Aug 30 03:10:07.117772 2026] [security2:error] [pid 512881:tid 513018] [client 20.151.200.44:64767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/Contrller.php"] [unique_id "apPlXwi65Hcg2zUJjxBsswAAAhs"]
[Sun Aug 30 03:10:07.127963 2026] [security2:error] [pid 512881:tid 513014] [client 20.48.251.3:59844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/mga.php"] [unique_id "apPlXwi65Hcg2zUJjxBsuAAAAhc"]
[Sun Aug 30 03:10:07.133065 2026] [authz_core:error] [pid 515259:tid 515434] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:07.133590 2026] [authz_core:error] [pid 515259:tid 515434] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:07.143677 2026] [security2:error] [pid 515259:tid 515460] [client 158.23.184.117:12869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/wp-content/uploads/wp.php"] [unique_id "apPlX2ZcVaai59truiVh0QAAAEY"]
[Sun Aug 30 03:10:07.146277 2026] [security2:error] [pid 515259:tid 515455] [client 20.104.50.220:51011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/mac.php"] [unique_id "apPlX2ZcVaai59truiVh0gAAAEE"]
[Sun Aug 30 03:10:07.159045 2026] [security2:error] [pid 515259:tid 515428] [client 20.104.18.15:16997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/dex.php"] [unique_id "apPlX2ZcVaai59truiVh1wAAACY"]
[Sun Aug 30 03:10:07.162239 2026] [security2:error] [pid 512881:tid 513077] [client 20.104.18.15:35458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/dragonshell.php"] [unique_id "apPlXwi65Hcg2zUJjxBsxgAAAlY"]
[Sun Aug 30 03:10:07.167069 2026] [security2:error] [pid 515259:tid 515452] [client 20.104.18.15:22524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/m.php"] [unique_id "apPlX2ZcVaai59truiVh2QAAAD4"]
[Sun Aug 30 03:10:07.168529 2026] [security2:error] [pid 515259:tid 515456] [client 20.104.50.220:42028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wikiindex.php"] [unique_id "apPlX2ZcVaai59truiVh2gAAAEI"]
[Sun Aug 30 03:10:07.188862 2026] [security2:error] [pid 512881:tid 513062] [client 158.23.147.79:42857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/about.php"] [unique_id "apPlXwi65Hcg2zUJjxBs0wAAAkc"]
[Sun Aug 30 03:10:07.202800 2026] [security2:error] [pid 512881:tid 513026] [client 20.104.49.130:52427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/mac.php"] [unique_id "apPlXwi65Hcg2zUJjxBs1QAAAiM"]
[Sun Aug 30 03:10:07.208768 2026] [security2:error] [pid 512881:tid 513070] [client 184.154.76.13:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "dejulschoolofdance.com"] [uri "/index.php"] [unique_id "apPlXgi65Hcg2zUJjxBsbgAAAk8"]
[Sun Aug 30 03:10:07.209686 2026] [security2:error] [pid 512881:tid 513110] [client 184.154.76.13:51744] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "dejulschoolofdance.com"] [uri "/th1s_1s_a_4o4.html"] [unique_id "apPlXgi65Hcg2zUJjxBsYAAAAnc"]
[Sun Aug 30 03:10:07.216319 2026] [security2:error] [pid 512881:tid 513066] [client 20.48.251.3:60523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/oc460l3x.php"] [unique_id "apPlXwi65Hcg2zUJjxBs1wAAAks"]
[Sun Aug 30 03:10:07.223100 2026] [security2:error] [pid 515259:tid 515515] [client 20.63.81.20:36803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/l.php"] [unique_id "apPlX2ZcVaai59truiVh4gAAAH0"]
[Sun Aug 30 03:10:07.237741 2026] [security2:error] [pid 512881:tid 513038] [client 20.104.18.15:43849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apPlXwi65Hcg2zUJjxBs4AAAAi8"]
[Sun Aug 30 03:10:07.238701 2026] [security2:error] [pid 512881:tid 513022] [client 4.205.62.107:58452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/adminfus.php"] [unique_id "apPlXwi65Hcg2zUJjxBs4QAAAh8"]
[Sun Aug 30 03:10:07.251252 2026] [security2:error] [pid 512881:tid 513085] [client 4.205.62.107:25872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/myfile.php"] [unique_id "apPlXwi65Hcg2zUJjxBs4gAAAl4"]
[Sun Aug 30 03:10:07.254575 2026] [security2:error] [pid 512881:tid 513091] [client 20.104.50.220:28727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/.dha.php"] [unique_id "apPlXwi65Hcg2zUJjxBs5AAAAmQ"]
[Sun Aug 30 03:10:07.254693 2026] [security2:error] [pid 512881:tid 513012] [client 158.23.147.79:58393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-content/plugins/index.php"] [unique_id "apPlXwi65Hcg2zUJjxBs4wAAAhU"]
[Sun Aug 30 03:10:07.259478 2026] [security2:error] [pid 512881:tid 513101] [client 20.104.50.220:62256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/local.php"] [unique_id "apPlXwi65Hcg2zUJjxBs5QAAAm4"]
[Sun Aug 30 03:10:07.282263 2026] [security2:error] [pid 512881:tid 513025] [client 158.23.147.79:41557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apPlXwi65Hcg2zUJjxBs6QAAAiI"]
[Sun Aug 30 03:10:07.296215 2026] [security2:error] [pid 512881:tid 513074] [client 20.104.18.15:18430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/k.php"] [unique_id "apPlXwi65Hcg2zUJjxBs6wAAAlM"]
[Sun Aug 30 03:10:07.320893 2026] [security2:error] [pid 512881:tid 513027] [client 158.23.184.117:12900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/wp-includes/css//index.php"] [unique_id "apPlXwi65Hcg2zUJjxBs8QAAAiQ"]
[Sun Aug 30 03:10:07.332206 2026] [security2:error] [pid 512881:tid 513056] [client 20.48.160.90:63971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/k.php"] [unique_id "apPlXwi65Hcg2zUJjxBs9AAAAkE"]
[Sun Aug 30 03:10:07.332544 2026] [security2:error] [pid 512881:tid 513053] [client 20.104.50.220:32887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wiki-index.php"] [unique_id "apPlXwi65Hcg2zUJjxBs9QAAAj4"]
[Sun Aug 30 03:10:07.359506 2026] [security2:error] [pid 515259:tid 515489] [client 195.178.110.155:28614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innatalybridal.com"] [uri "/index.php"] [unique_id "apPlX2ZcVaai59truiVh7gAAAGM"]
[Sun Aug 30 03:10:07.362719 2026] [security2:error] [pid 512881:tid 513034] [client 20.63.81.20:36764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/xr.php"] [unique_id "apPlXwi65Hcg2zUJjxBs9wAAAis"]
[Sun Aug 30 03:10:07.398103 2026] [security2:error] [pid 512881:tid 513039] [client 20.104.50.220:5539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/devil.php"] [unique_id "apPlXwi65Hcg2zUJjxBs-wAAAjA"]
[Sun Aug 30 03:10:07.400693 2026] [authz_core:error] [pid 515259:tid 515498] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:07.401070 2026] [authz_core:error] [pid 515259:tid 515498] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:07.402437 2026] [security2:error] [pid 515259:tid 515414] [client 68.155.159.216:45838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/about/function.php"] [unique_id "apPlX2ZcVaai59truiVh8QAAABg"]
[Sun Aug 30 03:10:07.414892 2026] [security2:error] [pid 512881:tid 513087] [client 68.155.159.216:54329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apPlXwi65Hcg2zUJjxBs_QAAAmA"]
[Sun Aug 30 03:10:07.419790 2026] [security2:error] [pid 512881:tid 513062] [client 158.23.147.79:56488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-login.php"] [unique_id "apPlXwi65Hcg2zUJjxBs_wAAAkc"]
[Sun Aug 30 03:10:07.446483 2026] [security2:error] [pid 512881:tid 513125] [client 20.104.49.130:43312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/txets.php"] [unique_id "apPlXwi65Hcg2zUJjxBtBwAAAoY"]
[Sun Aug 30 03:10:07.468470 2026] [security2:error] [pid 512881:tid 513078] [client 158.23.147.79:41585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/themes.php"] [unique_id "apPlXwi65Hcg2zUJjxBtEgAAAlc"]
[Sun Aug 30 03:10:07.489559 2026] [security2:error] [pid 515259:tid 515472] [client 20.63.81.20:36750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/Q3.php"] [unique_id "apPlX2ZcVaai59truiVh-AAAAFI"]
[Sun Aug 30 03:10:07.490850 2026] [security2:error] [pid 512881:tid 513121] [client 158.23.184.117:13220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/index2.php"] [unique_id "apPlXwi65Hcg2zUJjxBtGQAAAoI"]
[Sun Aug 30 03:10:07.514572 2026] [security2:error] [pid 512881:tid 513025] [client 20.48.160.90:63990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/82.php"] [unique_id "apPlXwi65Hcg2zUJjxBtHgAAAiI"]
[Sun Aug 30 03:10:07.522081 2026] [security2:error] [pid 512881:tid 513084] [client 195.178.110.155:28622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innatalybridal.com"] [uri "/index.php"] [unique_id "apPlXwi65Hcg2zUJjxBtIQAAAl0"]
[Sun Aug 30 03:10:07.605722 2026] [security2:error] [pid 512881:tid 513106] [client 20.151.200.44:28549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/dx.php"] [unique_id "apPlXwi65Hcg2zUJjxBtMwAAAnM"]
[Sun Aug 30 03:10:07.607252 2026] [security2:error] [pid 512881:tid 513079] [client 158.23.147.79:42836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-mail.php"] [unique_id "apPlXwi65Hcg2zUJjxBtNgAAAlg"]
[Sun Aug 30 03:10:07.615606 2026] [security2:error] [pid 512881:tid 513099] [client 20.104.50.220:62823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/up1.php"] [unique_id "apPlXwi65Hcg2zUJjxBtOAAAAmw"]
[Sun Aug 30 03:10:07.617856 2026] [security2:error] [pid 515259:tid 515516] [client 20.63.81.20:36612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/Q1.php"] [unique_id "apPlX2ZcVaai59truiViAgAAAH4"]
[Sun Aug 30 03:10:07.625754 2026] [security2:error] [pid 512881:tid 513132] [client 20.48.251.3:64299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/asa.php"] [unique_id "apPlXwi65Hcg2zUJjxBtPAAAAo0"]
[Sun Aug 30 03:10:07.643841 2026] [security2:error] [pid 512881:tid 513075] [client 20.48.160.90:63877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/dex.php"] [unique_id "apPlXwi65Hcg2zUJjxBtSgAAAlQ"]
[Sun Aug 30 03:10:07.679520 2026] [security2:error] [pid 515259:tid 515428] [client 158.23.184.117:13228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/wp-admin/images/about.php"] [unique_id "apPlX2ZcVaai59truiViDQAAACY"]
[Sun Aug 30 03:10:07.683319 2026] [security2:error] [pid 515259:tid 515439] [client 4.205.62.107:36574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/css.php"] [unique_id "apPlX2ZcVaai59truiViDgAAADE"]
[Sun Aug 30 03:10:07.745083 2026] [security2:error] [pid 515259:tid 515429] [client 158.23.147.79:41561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/cgi-bin/index.php"] [unique_id "apPlX2ZcVaai59truiViGQAAACc"]
[Sun Aug 30 03:10:07.746518 2026] [security2:error] [pid 512881:tid 513074] [client 20.63.81.20:36853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/nz.php"] [unique_id "apPlXwi65Hcg2zUJjxBtlAAAAlM"]
[Sun Aug 30 03:10:07.789917 2026] [authz_core:error] [pid 512881:tid 513108] [client 66.249.66.65:40385] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:07.790241 2026] [authz_core:error] [pid 512881:tid 513108] [client 66.249.66.65:40385] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:07.823426 2026] [authz_core:error] [pid 512881:tid 513039] [client 216.73.216.128:14137] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:07.823890 2026] [authz_core:error] [pid 512881:tid 513039] [client 216.73.216.128:14137] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:07.825416 2026] [security2:error] [pid 512881:tid 513063] [client 20.48.160.90:61393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/inso.php"] [unique_id "apPlXwi65Hcg2zUJjxBttwAAAkg"]
[Sun Aug 30 03:10:07.843561 2026] [security2:error] [pid 512881:tid 513024] [client 158.23.147.79:41553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPlXwi65Hcg2zUJjxBtwQAAAiE"]
[Sun Aug 30 03:10:07.860706 2026] [authz_core:error] [pid 515259:tid 515403] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:07.861012 2026] [authz_core:error] [pid 515259:tid 515403] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:07.868173 2026] [security2:error] [pid 512881:tid 513030] [client 158.23.184.117:13190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/wp-includes/theme-compat.php"] [unique_id "apPlXwi65Hcg2zUJjxBt2wAAAic"]
[Sun Aug 30 03:10:07.895531 2026] [security2:error] [pid 512881:tid 513112] [client 20.63.81.20:36704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/sg.php"] [unique_id "apPlXwi65Hcg2zUJjxBt7gAAAnk"]
[Sun Aug 30 03:10:07.903888 2026] [authz_core:error] [pid 512881:tid 513044] [client 66.249.66.69:35640] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:07.904181 2026] [authz_core:error] [pid 512881:tid 513044] [client 66.249.66.69:35640] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:07.997797 2026] [security2:error] [pid 512881:tid 513018] [client 216.73.216.128:14137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlXwi65Hcg2zUJjxBuKAAAAhs"]
[Sun Aug 30 03:10:08.011385 2026] [security2:error] [pid 512881:tid 513109] [client 158.23.184.117:12899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/NewFile.php"] [unique_id "apPlYAi65Hcg2zUJjxBuLgAAAnY"]
[Sun Aug 30 03:10:08.021333 2026] [security2:error] [pid 512881:tid 513019] [client 20.63.81.20:36692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/hypo.php"] [unique_id "apPlYAi65Hcg2zUJjxBuMQAAAhw"]
[Sun Aug 30 03:10:08.040931 2026] [security2:error] [pid 512881:tid 513090] [client 158.23.147.79:41552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-includes/content.php"] [unique_id "apPlYAi65Hcg2zUJjxBuNgAAAmM"]
[Sun Aug 30 03:10:08.061249 2026] [security2:error] [pid 515259:tid 515517] [client 68.155.159.216:62635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/atomlib.php"] [unique_id "apPlYGZcVaai59truiViQgAAAH8"]
[Sun Aug 30 03:10:08.094280 2026] [security2:error] [pid 512881:tid 513027] [client 20.48.160.90:37582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/aa.php"] [unique_id "apPlYAi65Hcg2zUJjxBuWAAAAiQ"]
[Sun Aug 30 03:10:08.094464 2026] [security2:error] [pid 515259:tid 515417] [client 20.104.49.130:51527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/zoo2.php"] [unique_id "apPlYGZcVaai59truiViSAAAABs"]
[Sun Aug 30 03:10:08.126122 2026] [authz_core:error] [pid 515259:tid 515510] [client 66.249.66.72:43517] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:08.126407 2026] [authz_core:error] [pid 515259:tid 515510] [client 66.249.66.72:43517] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:08.148294 2026] [security2:error] [pid 515259:tid 515456] [client 158.23.147.79:42819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-admin/css/index.php"] [unique_id "apPlYGZcVaai59truiViTAAAAEI"]
[Sun Aug 30 03:10:08.149366 2026] [security2:error] [pid 512881:tid 513137] [client 20.63.81.20:36854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/Hd.php"] [unique_id "apPlYAi65Hcg2zUJjxBudwAAApI"]
[Sun Aug 30 03:10:08.152954 2026] [security2:error] [pid 512881:tid 513096] [client 158.23.184.117:13186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/wp-admin/css/colors/sunrise.php"] [unique_id "apPlYAi65Hcg2zUJjxBuegAAAmk"]
[Sun Aug 30 03:10:08.216319 2026] [security2:error] [pid 512881:tid 513038] [client 20.104.50.220:16766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/ioxi-o.php"] [unique_id "apPlYAi65Hcg2zUJjxBukAAAAi8"]
[Sun Aug 30 03:10:08.226640 2026] [security2:error] [pid 515259:tid 515507] [client 20.104.18.15:64025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/special.php"] [unique_id "apPlYGZcVaai59truiViVQAAAHU"]
[Sun Aug 30 03:10:08.229347 2026] [security2:error] [pid 512881:tid 513131] [client 4.205.62.107:17281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/mga.php"] [unique_id "apPlYAi65Hcg2zUJjxBukgAAAow"]
[Sun Aug 30 03:10:08.250494 2026] [security2:error] [pid 515259:tid 515479] [client 20.104.49.130:54188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/red.php"] [unique_id "apPlYGZcVaai59truiViWgAAAFk"]
[Sun Aug 30 03:10:08.251936 2026] [security2:error] [pid 512881:tid 513018] [client 158.23.147.79:41537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-admin/images/index.php"] [unique_id "apPlYAi65Hcg2zUJjxBumQAAAhs"]
[Sun Aug 30 03:10:08.254583 2026] [security2:error] [pid 515259:tid 515441] [client 20.48.251.3:59326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/api.php"] [unique_id "apPlYGZcVaai59truiViWwAAADM"]
[Sun Aug 30 03:10:08.254863 2026] [security2:error] [pid 515259:tid 515391] [client 20.48.160.90:63895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/img.php"] [unique_id "apPlYGZcVaai59truiViXAAAAAE"]
[Sun Aug 30 03:10:08.267103 2026] [security2:error] [pid 512881:tid 513135] [client 20.48.251.3:59487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/ccou.php"] [unique_id "apPlYAi65Hcg2zUJjxBumwAAApA"]
[Sun Aug 30 03:10:08.274135 2026] [security2:error] [pid 512881:tid 513112] [client 20.63.81.20:36633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/im.php"] [unique_id "apPlYAi65Hcg2zUJjxBunwAAAnk"]
[Sun Aug 30 03:10:08.297123 2026] [security2:error] [pid 512881:tid 513014] [client 20.104.50.220:31519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/25d653587fdfd1.php"] [unique_id "apPlYAi65Hcg2zUJjxBupQAAAhc"]
[Sun Aug 30 03:10:08.300101 2026] [security2:error] [pid 512881:tid 513132] [client 20.104.18.15:35165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/wp-safe.php"] [unique_id "apPlYAi65Hcg2zUJjxBuqAAAAo0"]
[Sun Aug 30 03:10:08.305333 2026] [security2:error] [pid 512881:tid 513105] [client 20.104.50.220:42758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/alex.php"] [unique_id "apPlYAi65Hcg2zUJjxBuqgAAAnI"]
[Sun Aug 30 03:10:08.307381 2026] [security2:error] [pid 512881:tid 513116] [client 20.104.18.15:22404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/fling.php"] [unique_id "apPlYAi65Hcg2zUJjxBurAAAAn0"]
[Sun Aug 30 03:10:08.315773 2026] [security2:error] [pid 512881:tid 513053] [client 158.23.184.117:12879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/ova.php"] [unique_id "apPlYAi65Hcg2zUJjxBurQAAAj4"]
[Sun Aug 30 03:10:08.324809 2026] [security2:error] [pid 512881:tid 513042] [client 20.104.18.15:16969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/inso.php"] [unique_id "apPlYAi65Hcg2zUJjxBusQAAAjM"]
[Sun Aug 30 03:10:08.360913 2026] [security2:error] [pid 512881:tid 513127] [client 20.48.251.3:13434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/drykl.php"] [unique_id "apPlYAi65Hcg2zUJjxButQAAAog"]
[Sun Aug 30 03:10:08.378979 2026] [security2:error] [pid 512881:tid 513069] [client 4.205.62.107:58248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/avim.php"] [unique_id "apPlYAi65Hcg2zUJjxButwAAAk4"]
[Sun Aug 30 03:10:08.384307 2026] [security2:error] [pid 512881:tid 513026] [client 20.104.18.15:44008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/wp-aothait.php"] [unique_id "apPlYAi65Hcg2zUJjxBuuAAAAiM"]
[Sun Aug 30 03:10:08.393507 2026] [security2:error] [pid 515259:tid 515489] [client 20.104.50.220:52840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/cpanel.php"] [unique_id "apPlYGZcVaai59truiViYAAAAGM"]
[Sun Aug 30 03:10:08.396753 2026] [security2:error] [pid 512881:tid 513114] [client 20.48.160.90:61321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/222.php"] [unique_id "apPlYAi65Hcg2zUJjxBuuwAAAns"]
[Sun Aug 30 03:10:08.398737 2026] [security2:error] [pid 512881:tid 513012] [client 20.104.50.220:61459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/lolzk.php"] [unique_id "apPlYAi65Hcg2zUJjxBuvAAAAhU"]
[Sun Aug 30 03:10:08.401566 2026] [authz_core:error] [pid 515259:tid 515399] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:08.401862 2026] [authz_core:error] [pid 515259:tid 515399] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:08.407676 2026] [core:alert] [pid 512881:tid 513059] [client 171.22.167.52:38610] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:10:08.415067 2026] [security2:error] [pid 512881:tid 513074] [client 20.63.81.20:36813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/fc.php"] [unique_id "apPlYAi65Hcg2zUJjxBuwAAAAlM"]
[Sun Aug 30 03:10:08.434697 2026] [security2:error] [pid 515259:tid 515396] [client 20.151.200.44:28641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPlYGZcVaai59truiViYgAAAAY"]
[Sun Aug 30 03:10:08.443845 2026] [security2:error] [pid 515259:tid 515453] [client 20.104.18.15:18312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/82.php"] [unique_id "apPlYGZcVaai59truiViZAAAAD8"]
[Sun Aug 30 03:10:08.466247 2026] [security2:error] [pid 515259:tid 515447] [client 20.151.200.44:64813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/file66.php"] [unique_id "apPlYGZcVaai59truiViaAAAADk"]
[Sun Aug 30 03:10:08.475980 2026] [security2:error] [pid 515259:tid 515404] [client 158.23.184.117:12912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/wp-admin/network/about.php"] [unique_id "apPlYGZcVaai59truiViawAAAA4"]
[Sun Aug 30 03:10:08.484033 2026] [security2:error] [pid 515259:tid 515461] [client 20.104.50.220:32882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/Bulle.php"] [unique_id "apPlYGZcVaai59truiVibAAAAEc"]
[Sun Aug 30 03:10:08.532406 2026] [security2:error] [pid 512881:tid 513015] [client 20.104.49.130:52428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/ccc.php"] [unique_id "apPlYAi65Hcg2zUJjxBu3AAAAhg"]
[Sun Aug 30 03:10:08.540327 2026] [security2:error] [pid 512881:tid 513132] [client 158.23.147.79:41586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-includes/index.php"] [unique_id "apPlYAi65Hcg2zUJjxBu3wAAAo0"]
[Sun Aug 30 03:10:08.542207 2026] [security2:error] [pid 512881:tid 513105] [client 20.63.81.20:36786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/ke.php"] [unique_id "apPlYAi65Hcg2zUJjxBu4AAAAnI"]
[Sun Aug 30 03:10:08.552869 2026] [security2:error] [pid 512881:tid 513104] [client 20.48.160.90:63930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/key.php"] [unique_id "apPlYAi65Hcg2zUJjxBu4gAAAnE"]
[Sun Aug 30 03:10:08.552918 2026] [authz_core:error] [pid 512881:tid 513049] [client 216.73.216.128:62743] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:08.553231 2026] [authz_core:error] [pid 512881:tid 513049] [client 216.73.216.128:62743] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:08.563714 2026] [security2:error] [pid 515259:tid 515449] [client 20.104.50.220:5591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/zero.php"] [unique_id "apPlYGZcVaai59truiVicQAAADs"]
[Sun Aug 30 03:10:08.595761 2026] [authz_core:error] [pid 515259:tid 515486] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:08.596165 2026] [authz_core:error] [pid 515259:tid 515486] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:08.619130 2026] [security2:error] [pid 512881:tid 513084] [client 68.155.159.216:45953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-includes/customize/index.php"] [unique_id "apPlYAi65Hcg2zUJjxBu9QAAAl0"]
[Sun Aug 30 03:10:08.629633 2026] [security2:error] [pid 512881:tid 513021] [client 20.104.49.130:64116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/mac.php"] [unique_id "apPlYAi65Hcg2zUJjxBu_QAAAh4"]
[Sun Aug 30 03:10:08.635254 2026] [security2:error] [pid 512881:tid 513119] [client 158.23.184.117:13189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/dashboard.php"] [unique_id "apPlYAi65Hcg2zUJjxBvAAAAAoA"]
[Sun Aug 30 03:10:08.635287 2026] [security2:error] [pid 512881:tid 513098] [client 216.73.216.128:29937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/_runtime"] [unique_id "apPlYAi65Hcg2zUJjxBu_wAAAms"]
[Sun Aug 30 03:10:08.662963 2026] [authz_core:error] [pid 512881:tid 513024] [client 66.249.66.64:65373] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:08.663252 2026] [authz_core:error] [pid 512881:tid 513024] [client 66.249.66.64:65373] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:08.667586 2026] [security2:error] [pid 515259:tid 515394] [client 20.63.81.20:36793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/tf.php"] [unique_id "apPlYGZcVaai59truiVigAAAAAQ"]
[Sun Aug 30 03:10:08.677616 2026] [security2:error] [pid 512881:tid 513053] [client 4.205.62.107:25748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/lm15.php"] [unique_id "apPlYAi65Hcg2zUJjxBvHwAAAj4"]
[Sun Aug 30 03:10:08.689349 2026] [security2:error] [pid 512881:tid 513023] [client 20.48.160.90:63894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/chosen.php"] [unique_id "apPlYAi65Hcg2zUJjxBvJwAAAiA"]
[Sun Aug 30 03:10:08.694067 2026] [security2:error] [pid 512881:tid 513022] [client 68.155.159.216:54297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-content/radio.php"] [unique_id "apPlYAi65Hcg2zUJjxBvLAAAAh8"]
[Sun Aug 30 03:10:08.698509 2026] [security2:error] [pid 512881:tid 513101] [client 20.48.250.41:49866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/ms.php"] [unique_id "apPlYAi65Hcg2zUJjxBvLgAAAm4"]
[Sun Aug 30 03:10:08.700878 2026] [security2:error] [pid 515259:tid 515485] [client 158.23.147.79:42868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/mah.php"] [unique_id "apPlYGZcVaai59truiVigwAAAF8"]
[Sun Aug 30 03:10:08.726938 2026] [security2:error] [pid 515259:tid 515470] [client 216.73.216.128:49549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mysqlupgrade"] [unique_id "apPlYGZcVaai59truiVihwAAAFA"]
[Sun Aug 30 03:10:08.755083 2026] [security2:error] [pid 512881:tid 513053] [client 20.104.50.220:52832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/haha.php"] [unique_id "apPlYAi65Hcg2zUJjxBvVQAAAj4"]
[Sun Aug 30 03:10:08.766288 2026] [security2:error] [pid 512881:tid 513127] [client 20.48.251.3:54799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/radio.php"] [unique_id "apPlYAi65Hcg2zUJjxBvWQAAAog"]
[Sun Aug 30 03:10:08.776538 2026] [security2:error] [pid 515259:tid 515456] [client 158.23.184.117:12872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/wp-content/plugins/sid/sidwso.php"] [unique_id "apPlYGZcVaai59truiVikAAAAEI"]
[Sun Aug 30 03:10:08.798404 2026] [security2:error] [pid 512881:tid 513086] [client 20.63.81.20:36741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/px.php"] [unique_id "apPlYAi65Hcg2zUJjxBvaAAAAl8"]
[Sun Aug 30 03:10:08.829926 2026] [security2:error] [pid 512881:tid 513126] [client 4.205.62.107:36622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/php_info.php"] [unique_id "apPlYAi65Hcg2zUJjxBvfAAAAoc"]
[Sun Aug 30 03:10:08.835750 2026] [security2:error] [pid 512881:tid 513128] [client 20.48.250.41:49836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/zxekqlxb.php"] [unique_id "apPlYAi65Hcg2zUJjxBvggAAAok"]
[Sun Aug 30 03:10:08.841848 2026] [security2:error] [pid 512881:tid 513015] [client 20.48.160.90:61391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/file1221.php"] [unique_id "apPlYAi65Hcg2zUJjxBvhQAAAhg"]
[Sun Aug 30 03:10:08.844395 2026] [security2:error] [pid 515259:tid 515511] [client 158.23.147.79:42843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-blog-header.php"] [unique_id "apPlYGZcVaai59truiVilAAAAHk"]
[Sun Aug 30 03:10:08.917476 2026] [authz_core:error] [pid 515259:tid 515473] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:08.917827 2026] [authz_core:error] [pid 515259:tid 515473] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:08.928041 2026] [security2:error] [pid 512881:tid 513132] [client 20.63.81.20:36787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/jg.php"] [unique_id "apPlYAi65Hcg2zUJjxBvxAAAAo0"]
[Sun Aug 30 03:10:08.963459 2026] [security2:error] [pid 512881:tid 513017] [client 20.48.250.41:38885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/grsiuk.php"] [unique_id "apPlYAi65Hcg2zUJjxBv2gAAAho"]
[Sun Aug 30 03:10:08.964297 2026] [security2:error] [pid 512881:tid 513056] [client 158.23.147.79:10227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apPlYAi65Hcg2zUJjxBv2wAAAkE"]
[Sun Aug 30 03:10:08.969074 2026] [security2:error] [pid 512881:tid 513054] [client 158.23.184.117:13222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/admin/index.php"] [unique_id "apPlYAi65Hcg2zUJjxBv3QAAAj8"]
[Sun Aug 30 03:10:08.980785 2026] [security2:error] [pid 512881:tid 513052] [client 20.48.250.41:49831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/init.php"] [unique_id "apPlYAi65Hcg2zUJjxBv5QAAAj0"]
[Sun Aug 30 03:10:08.981099 2026] [security2:error] [pid 512881:tid 513114] [client 158.23.147.79:60197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/simple.php"] [unique_id "apPlYAi65Hcg2zUJjxBv5gAAAns"]
[Sun Aug 30 03:10:08.992883 2026] [security2:error] [pid 515259:tid 515449] [client 20.48.160.90:63985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/nox.php"] [unique_id "apPlYGZcVaai59truiVirgAAADs"]
[Sun Aug 30 03:10:09.055978 2026] [security2:error] [pid 515259:tid 515516] [client 20.63.81.20:36705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/yj.php"] [unique_id "apPlYWZcVaai59truiViswAAAH4"]
[Sun Aug 30 03:10:09.099000 2026] [security2:error] [pid 512881:tid 513049] [client 158.23.147.79:42840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-admin/user/index.php"] [unique_id "apPlYQi65Hcg2zUJjxBwJAAAAjo"]
[Sun Aug 30 03:10:09.112302 2026] [security2:error] [pid 512881:tid 513065] [client 20.48.250.41:49863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/term.php"] [unique_id "apPlYQi65Hcg2zUJjxBwMgAAAko"]
[Sun Aug 30 03:10:09.133479 2026] [authz_core:error] [pid 512881:tid 513018] [client 66.249.66.76:64124] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:09.133770 2026] [authz_core:error] [pid 512881:tid 513018] [client 66.249.66.76:64124] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:09.160583 2026] [security2:error] [pid 512881:tid 513108] [client 158.23.184.117:12703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/wp-includes/blocks/block/index.php"] [unique_id "apPlYQi65Hcg2zUJjxBwSgAAAnU"]
[Sun Aug 30 03:10:09.170557 2026] [security2:error] [pid 512881:tid 513107] [client 68.155.159.216:62628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/lv.php"] [unique_id "apPlYQi65Hcg2zUJjxBwUAAAAnQ"]
[Sun Aug 30 03:10:09.182225 2026] [security2:error] [pid 515259:tid 515440] [client 20.63.81.20:36822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/zi.php"] [unique_id "apPlYWZcVaai59truiViwwAAADI"]
[Sun Aug 30 03:10:09.184636 2026] [security2:error] [pid 512881:tid 513048] [client 216.73.216.128:16041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/js/sorttable.js"] [unique_id "apPlYQi65Hcg2zUJjxBwWQAAAjk"]
[Sun Aug 30 03:10:09.191943 2026] [security2:error] [pid 512881:tid 513059] [client 20.48.160.90:63968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/akismet.php"] [unique_id "apPlYQi65Hcg2zUJjxBwXQAAAkQ"]
[Sun Aug 30 03:10:09.222103 2026] [security2:error] [pid 512881:tid 513015] [client 158.23.147.79:41571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-includes/plugins.php"] [unique_id "apPlYQi65Hcg2zUJjxBwYgAAAhg"]
[Sun Aug 30 03:10:09.237333 2026] [security2:error] [pid 512881:tid 513044] [client 20.104.49.130:63521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/82.php"] [unique_id "apPlYQi65Hcg2zUJjxBwZQAAAjU"]
[Sun Aug 30 03:10:09.243215 2026] [security2:error] [pid 515259:tid 515419] [client 20.48.250.41:49879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/aaa.php"] [unique_id "apPlYWZcVaai59truiViyAAAAB0"]
[Sun Aug 30 03:10:09.256480 2026] [security2:error] [pid 512881:tid 513031] [client 20.104.49.130:43264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/kj.php"] [unique_id "apPlYQi65Hcg2zUJjxBwaAAAAig"]
[Sun Aug 30 03:10:09.283178 2026] [authz_core:error] [pid 512881:tid 513138] [client 216.73.216.128:62743] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:09.283449 2026] [authz_core:error] [pid 512881:tid 513138] [client 216.73.216.128:62743] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:09.302799 2026] [security2:error] [pid 512881:tid 513041] [client 158.23.184.117:12884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.melissaspaulding.com"] [uri "/bolt.php"] [unique_id "apPlYQi65Hcg2zUJjxBwcgAAAjI"]
[Sun Aug 30 03:10:09.309034 2026] [security2:error] [pid 515259:tid 515458] [client 20.63.81.20:36766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/ue.php"] [unique_id "apPlYWZcVaai59truiVizAAAAEQ"]
[Sun Aug 30 03:10:09.317560 2026] [security2:error] [pid 512881:tid 513046] [client 20.104.49.130:52153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/ccc.php"] [unique_id "apPlYQi65Hcg2zUJjxBwdwAAAjc"]
[Sun Aug 30 03:10:09.324555 2026] [security2:error] [pid 512881:tid 513023] [client 20.48.160.90:63947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/ajax.php"] [unique_id "apPlYQi65Hcg2zUJjxBwewAAAiA"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:10:09.362628 2026] [security2:error] [pid 512881:tid 513038] [client 20.104.50.220:16592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/0x.php"] [unique_id "apPlYQi65Hcg2zUJjxBwhAAAAi8"]
[Sun Aug 30 03:10:09.366242 2026] [security2:error] [pid 512881:tid 513048] [client 20.48.250.41:38787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/wp-scr1pts.php"] [unique_id "apPlYQi65Hcg2zUJjxBwhwAAAjk"]
[Sun Aug 30 03:10:09.370416 2026] [security2:error] [pid 512881:tid 513100] [client 20.48.250.41:49792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/xsox.php"] [unique_id "apPlYQi65Hcg2zUJjxBwiQAAAm0"]
[Sun Aug 30 03:10:09.376442 2026] [security2:error] [pid 515259:tid 515421] [client 4.205.62.107:17710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/ccou.php"] [unique_id "apPlYWZcVaai59truiVizwAAAB8"]
[Sun Aug 30 03:10:09.376973 2026] [security2:error] [pid 512881:tid 513097] [client 20.104.18.15:16712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/fz.php"] [unique_id "apPlYQi65Hcg2zUJjxBwiwAAAmo"]
[Sun Aug 30 03:10:09.388889 2026] [authz_core:error] [pid 515259:tid 515456] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:09.389161 2026] [authz_core:error] [pid 515259:tid 515456] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:09.391948 2026] [security2:error] [pid 512881:tid 513053] [client 20.48.251.3:59382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/temp.php"] [unique_id "apPlYQi65Hcg2zUJjxBwjQAAAj4"]
[Sun Aug 30 03:10:09.415610 2026] [security2:error] [pid 515259:tid 515406] [client 158.23.147.79:10125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apPlYWZcVaai59truiVi0QAAABA"]
[Sun Aug 30 03:10:09.419957 2026] [security2:error] [pid 512881:tid 513064] [client 20.48.251.3:52246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/rum.or.php"] [unique_id "apPlYQi65Hcg2zUJjxBwjwAAAkk"]
[Sun Aug 30 03:10:09.435079 2026] [security2:error] [pid 512881:tid 513059] [client 20.63.81.20:36821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/nv.php"] [unique_id "apPlYQi65Hcg2zUJjxBwkgAAAkQ"]
[Sun Aug 30 03:10:09.443142 2026] [security2:error] [pid 512881:tid 513071] [client 20.104.50.220:56712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-0.php"] [unique_id "apPlYQi65Hcg2zUJjxBwlAAAAlA"]
[Sun Aug 30 03:10:09.455258 2026] [security2:error] [pid 512881:tid 513086] [client 20.104.18.15:35496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/gjewuagf.php"] [unique_id "apPlYQi65Hcg2zUJjxBwmgAAAl8"]
[Sun Aug 30 03:10:09.455426 2026] [security2:error] [pid 515259:tid 515441] [client 20.104.50.220:59358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wefile.php"] [unique_id "apPlYWZcVaai59truiVi1QAAADM"]
[Sun Aug 30 03:10:09.473988 2026] [security2:error] [pid 512881:tid 513031] [client 20.104.18.15:16986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/aa.php"] [unique_id "apPlYQi65Hcg2zUJjxBwpQAAAig"]
[Sun Aug 30 03:10:09.479687 2026] [security2:error] [pid 512881:tid 513112] [client 20.104.18.15:22441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/btyuio.php"] [unique_id "apPlYQi65Hcg2zUJjxBwpgAAAnk"]
[Sun Aug 30 03:10:09.481472 2026] [security2:error] [pid 512881:tid 513035] [client 20.48.160.90:63983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/atomlib.php"] [unique_id "apPlYQi65Hcg2zUJjxBwpwAAAiw"]
[Sun Aug 30 03:10:09.523251 2026] [security2:error] [pid 515259:tid 515487] [client 20.48.251.3:13376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/rpk.php"] [unique_id "apPlYWZcVaai59truiVi2gAAAGE"]
[Sun Aug 30 03:10:09.525758 2026] [security2:error] [pid 515259:tid 515400] [client 20.48.250.41:64612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/lkui.php"] [unique_id "apPlYWZcVaai59truiVi2wAAAAo"]
[Sun Aug 30 03:10:09.526635 2026] [security2:error] [pid 515259:tid 515489] [client 158.23.147.79:57687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apPlYWZcVaai59truiVi3AAAAGM"]
[Sun Aug 30 03:10:09.532097 2026] [security2:error] [pid 515259:tid 515477] [client 20.104.18.15:43308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/wp-includes/index.php"] [unique_id "apPlYWZcVaai59truiVi3gAAAFc"]
[Sun Aug 30 03:10:09.533258 2026] [security2:error] [pid 515259:tid 515422] [client 4.205.62.107:61718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/nw.php"] [unique_id "apPlYWZcVaai59truiVi3wAAACA"]
[Sun Aug 30 03:10:09.543111 2026] [security2:error] [pid 512881:tid 513091] [client 20.104.50.220:62211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/marijuana.php"] [unique_id "apPlYQi65Hcg2zUJjxBwugAAAmQ"]
[Sun Aug 30 03:10:09.545556 2026] [security2:error] [pid 512881:tid 513038] [client 20.104.50.220:29165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/devill.php"] [unique_id "apPlYQi65Hcg2zUJjxBwvAAAAi8"]
[Sun Aug 30 03:10:09.559061 2026] [security2:error] [pid 512881:tid 513026] [client 209.141.32.143:59736] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "lorenzosnowcones.com"] [uri "/wp-content/plugins/tutor/readme.txt"] [unique_id "apPlYQi65Hcg2zUJjxBwwQAAAiM"]
[Sun Aug 30 03:10:09.566022 2026] [security2:error] [pid 512881:tid 513029] [client 20.63.81.20:36678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/jw.php"] [unique_id "apPlYQi65Hcg2zUJjxBwxQAAAiY"]
[Sun Aug 30 03:10:09.567677 2026] [authz_core:error] [pid 512881:tid 513060] [client 66.249.66.34:48195] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:09.567956 2026] [authz_core:error] [pid 512881:tid 513060] [client 66.249.66.34:48195] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:09.568930 2026] [security2:error] [pid 512881:tid 513125] [client 158.23.147.79:42822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/goat1.php"] [unique_id "apPlYQi65Hcg2zUJjxBwxgAAAoY"]
[Sun Aug 30 03:10:09.582571 2026] [security2:error] [pid 512881:tid 513103] [client 20.104.18.15:18405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/dex.php"] [unique_id "apPlYQi65Hcg2zUJjxBwzQAAAnA"]
[Sun Aug 30 03:10:09.624834 2026] [security2:error] [pid 515259:tid 515443] [client 20.104.50.220:32931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/srx.php"] [unique_id "apPlYWZcVaai59truiVi5gAAADU"]
[Sun Aug 30 03:10:09.626056 2026] [security2:error] [pid 512881:tid 513012] [client 20.48.250.41:38882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/num.php"] [unique_id "apPlYQi65Hcg2zUJjxBw2wAAAhU"]
[Sun Aug 30 03:10:09.655466 2026] [security2:error] [pid 515259:tid 515408] [client 20.48.160.90:37568] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.biospherecampus.com"] [uri "/1.php"] [unique_id "apPlYWZcVaai59truiVi7AAAABI"]
[Sun Aug 30 03:10:09.655571 2026] [security2:error] [pid 515259:tid 515408] [client 20.48.160.90:37568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/1.php"] [unique_id "apPlYWZcVaai59truiVi7AAAABI"]
[Sun Aug 30 03:10:09.657891 2026] [security2:error] [pid 512881:tid 513013] [client 20.48.250.41:64590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apPlYQi65Hcg2zUJjxBw9AAAAhY"]
[Sun Aug 30 03:10:09.697224 2026] [security2:error] [pid 512881:tid 513068] [client 20.63.81.20:36683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/or.php"] [unique_id "apPlYQi65Hcg2zUJjxBxCQAAAk0"]
[Sun Aug 30 03:10:09.732075 2026] [security2:error] [pid 512881:tid 513083] [client 20.104.50.220:5892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/byte.php"] [unique_id "apPlYQi65Hcg2zUJjxBxJgAAAlw"]
[Sun Aug 30 03:10:09.734304 2026] [security2:error] [pid 512881:tid 513051] [client 158.23.147.79:41593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apPlYQi65Hcg2zUJjxBxKwAAAjw"]
[Sun Aug 30 03:10:09.759557 2026] [security2:error] [pid 512881:tid 513108] [client 68.155.159.216:45899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-admin/index.php"] [unique_id "apPlYQi65Hcg2zUJjxBxPAAAAnU"]
[Sun Aug 30 03:10:09.779744 2026] [security2:error] [pid 515259:tid 515394] [client 216.73.216.128:58374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlYWZcVaai59truiVi-QAAAAQ"]
[Sun Aug 30 03:10:09.786351 2026] [security2:error] [pid 515259:tid 515488] [client 20.48.250.41:38864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/a4.php"] [unique_id "apPlYWZcVaai59truiVi-gAAAGI"]
[Sun Aug 30 03:10:09.793503 2026] [security2:error] [pid 512881:tid 513050] [client 20.48.250.41:49855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/motu.php"] [unique_id "apPlYQi65Hcg2zUJjxBxSwAAAjs"]
[Sun Aug 30 03:10:09.827890 2026] [security2:error] [pid 512881:tid 513052] [client 20.63.81.20:36744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/ile56.php"] [unique_id "apPlYQi65Hcg2zUJjxBxYwAAAj0"]
[Sun Aug 30 03:10:09.828086 2026] [security2:error] [pid 512881:tid 513087] [client 20.151.200.44:41943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/png.php"] [unique_id "apPlYQi65Hcg2zUJjxBxZAAAAmA"]
[Sun Aug 30 03:10:09.849936 2026] [security2:error] [pid 512881:tid 513050] [client 20.48.160.90:61410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/samll.php"] [unique_id "apPlYQi65Hcg2zUJjxBxcwAAAjs"]
[Sun Aug 30 03:10:09.854595 2026] [security2:error] [pid 512881:tid 513016] [client 4.205.62.107:25768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/test.config.php"] [unique_id "apPlYQi65Hcg2zUJjxBxfAAAAhk"]
[Sun Aug 30 03:10:09.858047 2026] [rewrite:warn] [pid 515259:tid 515304] AH00665: RewriteCond: NoCase option for non-regex pattern '-d' is not supported and will be ignored. (/home3/keilan/public_html/.htaccess:12)
[Sun Aug 30 03:10:09.858059 2026] [rewrite:warn] [pid 515259:tid 515304] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home3/keilan/public_html/.htaccess:13)
[Sun Aug 30 03:10:09.880299 2026] [security2:error] [pid 515259:tid 515411] [client 158.23.147.79:41558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-admin/network/index.php"] [unique_id "apPlYWZcVaai59truiVjBAAAABU"]
[Sun Aug 30 03:10:09.882637 2026] [security2:error] [pid 512881:tid 513047] [client 158.23.147.79:1999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-admin/images/about.php"] [unique_id "apPlYQi65Hcg2zUJjxBxkwAAAjg"]
[Sun Aug 30 03:10:09.896135 2026] [authz_core:error] [pid 515259:tid 515419] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:09.896590 2026] [authz_core:error] [pid 515259:tid 515419] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:09.897495 2026] [security2:error] [pid 515259:tid 515483] [client 68.155.159.216:52590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apPlYWZcVaai59truiVjBwAAAF0"]
[Sun Aug 30 03:10:09.913805 2026] [security2:error] [pid 512881:tid 513136] [client 20.48.251.3:54796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/xa.php"] [unique_id "apPlYQi65Hcg2zUJjxBxoQAAApE"]
[Sun Aug 30 03:10:09.920243 2026] [security2:error] [pid 512881:tid 513039] [client 20.48.250.41:64585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/Ov-Simple1.php"] [unique_id "apPlYQi65Hcg2zUJjxBxpgAAAjA"]
[Sun Aug 30 03:10:09.926087 2026] [security2:error] [pid 515259:tid 515435] [client 20.104.50.220:62845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/sc.php"] [unique_id "apPlYWZcVaai59truiVjCgAAAC0"]
[Sun Aug 30 03:10:09.941825 2026] [security2:error] [pid 515259:tid 515430] [client 20.104.49.130:60951] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "enterden.den-enterprises.com"] [uri "/1.php"] [unique_id "apPlYWZcVaai59truiVjCwAAACg"]
[Sun Aug 30 03:10:09.941925 2026] [security2:error] [pid 515259:tid 515430] [client 20.104.49.130:60951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/1.php"] [unique_id "apPlYWZcVaai59truiVjCwAAACg"]
[Sun Aug 30 03:10:09.956285 2026] [security2:error] [pid 512881:tid 513079] [client 20.63.81.20:36830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/emmh.php"] [unique_id "apPlYQi65Hcg2zUJjxBxvAAAAlg"]
[Sun Aug 30 03:10:09.969867 2026] [security2:error] [pid 512881:tid 513132] [client 20.104.49.130:43795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/menu.php"] [unique_id "apPlYQi65Hcg2zUJjxBxygAAAo0"]
[Sun Aug 30 03:10:09.988582 2026] [authz_core:error] [pid 515259:tid 515456] [client 66.249.66.73:49077] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:09.989053 2026] [authz_core:error] [pid 515259:tid 515456] [client 66.249.66.73:49077] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:09.995315 2026] [authz_core:error] [pid 515259:tid 515422] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:09.995791 2026] [authz_core:error] [pid 515259:tid 515422] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:10.037126 2026] [security2:error] [pid 515259:tid 515473] [client 158.23.147.79:10189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apPlYmZcVaai59truiVjKgAAAFM"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:10:10.068165 2026] [security2:error] [pid 515259:tid 515510] [client 20.48.250.41:49814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/wp-blogs.php"] [unique_id "apPlYmZcVaai59truiVjLwAAAHg"]
[Sun Aug 30 03:10:10.072060 2026] [security2:error] [pid 515259:tid 515448] [client 20.104.49.130:64095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/new.php"] [unique_id "apPlYmZcVaai59truiVjMQAAADo"]
[Sun Aug 30 03:10:10.076007 2026] [security2:error] [pid 512881:tid 513017] [client 4.205.62.107:36655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/session.php"] [unique_id "apPlYgi65Hcg2zUJjxByCQAAAho"]
[Sun Aug 30 03:10:10.083916 2026] [security2:error] [pid 512881:tid 513099] [client 20.63.81.20:36717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/em.php"] [unique_id "apPlYgi65Hcg2zUJjxByEgAAAmw"]
[Sun Aug 30 03:10:10.103853 2026] [security2:error] [pid 512881:tid 513125] [client 20.48.160.90:61422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/she11.php"] [unique_id "apPlYgi65Hcg2zUJjxByHAAAAoY"]
[Sun Aug 30 03:10:10.121699 2026] [core:alert] [pid 512881:tid 512997] [remote 216.73.217.63:42024] /home3/lordrcan/public_html/.htaccess: without matching section
[Sun Aug 30 03:10:10.163112 2026] [security2:error] [pid 512881:tid 513117] [client 158.23.147.79:41577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/.well-knownold/index.php"] [unique_id "apPlYgi65Hcg2zUJjxByOQAAAn4"]
[Sun Aug 30 03:10:10.194928 2026] [security2:error] [pid 512881:tid 513047] [client 20.48.250.41:64514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/mini.php"] [unique_id "apPlYgi65Hcg2zUJjxByTQAAAjg"]
[Sun Aug 30 03:10:10.209446 2026] [security2:error] [pid 512881:tid 513044] [client 20.63.81.20:36811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/dvve.php"] [unique_id "apPlYgi65Hcg2zUJjxByUAAAAjU"]
[Sun Aug 30 03:10:10.212677 2026] [authz_core:error] [pid 512881:tid 513136] [client 66.249.66.196:44586] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:10.212952 2026] [authz_core:error] [pid 512881:tid 513136] [client 66.249.66.196:44586] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:10.235660 2026] [security2:error] [pid 512881:tid 513076] [client 20.48.250.41:38785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/tfm.php"] [unique_id "apPlYgi65Hcg2zUJjxByVQAAAlU"]
[Sun Aug 30 03:10:10.263892 2026] [security2:error] [pid 515259:tid 515391] [client 158.23.147.79:41541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apPlYmZcVaai59truiVjTAAAAAE"]
[Sun Aug 30 03:10:10.277969 2026] [security2:error] [pid 512881:tid 513091] [client 68.155.159.216:62597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apPlYgi65Hcg2zUJjxByXwAAAmQ"]
[Sun Aug 30 03:10:10.293510 2026] [security2:error] [pid 512881:tid 513060] [client 20.48.160.90:63981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/kerang.php"] [unique_id "apPlYgi65Hcg2zUJjxByZQAAAkU"]
[Sun Aug 30 03:10:10.322967 2026] [security2:error] [pid 515259:tid 515464] [client 20.48.250.41:64601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/amp.php"] [unique_id "apPlYmZcVaai59truiVjTwAAAEo"]
[Sun Aug 30 03:10:10.323379 2026] [authz_core:error] [pid 515259:tid 515487] [client 66.249.66.72:43517] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:10.323674 2026] [authz_core:error] [pid 515259:tid 515487] [client 66.249.66.72:43517] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:10.336163 2026] [security2:error] [pid 512881:tid 513054] [client 20.63.81.20:36715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/doo.php"] [unique_id "apPlYgi65Hcg2zUJjxBybwAAAj8"]
[Sun Aug 30 03:10:10.366915 2026] [security2:error] [pid 515259:tid 515477] [client 20.63.81.20:31709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlYmZcVaai59truiVjUwAAAFc"]
[Sun Aug 30 03:10:10.368170 2026] [security2:error] [pid 515259:tid 515474] [client 20.48.250.41:38887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/Geforce.php"] [unique_id "apPlYmZcVaai59truiVjVAAAAFQ"]
[Sun Aug 30 03:10:10.369773 2026] [authz_core:error] [pid 515259:tid 515489] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:10.370243 2026] [authz_core:error] [pid 515259:tid 515489] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:10.403577 2026] [security2:error] [pid 512881:tid 513137] [client 158.23.147.79:10217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPlYgi65Hcg2zUJjxBydgAAApI"]
[Sun Aug 30 03:10:10.432171 2026] [security2:error] [pid 515259:tid 515472] [client 20.48.160.90:63933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/m.php"] [unique_id "apPlYmZcVaai59truiVjWQAAAFI"]
[Sun Aug 30 03:10:10.454279 2026] [security2:error] [pid 515259:tid 515408] [client 20.48.250.41:49825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/cc13.php"] [unique_id "apPlYmZcVaai59truiVjXwAAABI"]
[Sun Aug 30 03:10:10.461963 2026] [security2:error] [pid 515259:tid 515466] [client 20.63.81.20:36714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/adminer-4.6.6.php"] [unique_id "apPlYmZcVaai59truiVjYQAAAEw"]
[Sun Aug 30 03:10:10.497567 2026] [security2:error] [pid 512881:tid 513128] [client 20.63.81.20:31684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlYgi65Hcg2zUJjxByiQAAAok"]
[Sun Aug 30 03:10:10.500777 2026] [security2:error] [pid 515259:tid 515419] [client 20.104.50.220:17223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/css.php"] [unique_id "apPlYmZcVaai59truiVjaQAAAB0"]
[Sun Aug 30 03:10:10.503071 2026] [core:alert] [pid 512881:tid 513030] [client 37.77.49.208:53338] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:10:10.509351 2026] [security2:error] [pid 512881:tid 513093] [client 20.104.18.15:16645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/clque.php"] [unique_id "apPlYgi65Hcg2zUJjxByjgAAAmY"]
[Sun Aug 30 03:10:10.509351 2026] [security2:error] [pid 512881:tid 513015] [client 20.48.250.41:17381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlYgi65Hcg2zUJjxBykAAAAhg"]
[Sun Aug 30 03:10:10.515382 2026] [security2:error] [pid 512881:tid 513098] [client 158.23.147.79:41554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/images/index.php"] [unique_id "apPlYgi65Hcg2zUJjxBylQAAAms"]
[Sun Aug 30 03:10:10.520307 2026] [security2:error] [pid 512881:tid 513087] [client 4.205.62.107:17282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/rum.or.php"] [unique_id "apPlYgi65Hcg2zUJjxBylwAAAmA"]
[Sun Aug 30 03:10:10.525322 2026] [security2:error] [pid 515259:tid 515495] [client 20.48.250.41:38807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/click.php"] [unique_id "apPlYmZcVaai59truiVjbQAAAGk"]
[Sun Aug 30 03:10:10.532619 2026] [security2:error] [pid 512881:tid 513039] [client 20.48.251.3:55781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/fm.php"] [unique_id "apPlYgi65Hcg2zUJjxBymAAAAjA"]
[Sun Aug 30 03:10:10.560489 2026] [security2:error] [pid 512881:tid 513138] [client 20.48.251.3:52186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/xmy.php"] [unique_id "apPlYgi65Hcg2zUJjxBypQAAApM"]
[Sun Aug 30 03:10:10.588655 2026] [security2:error] [pid 515259:tid 515423] [client 20.48.160.90:63998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/fling.php"] [unique_id "apPlYmZcVaai59truiVjdQAAACE"]
[Sun Aug 30 03:10:10.594096 2026] [security2:error] [pid 512881:tid 513101] [client 57.131.147.191:53387] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rampd.co"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "apPlYgi65Hcg2zUJjxByrgAAAm4"]
[Sun Aug 30 03:10:10.596632 2026] [security2:error] [pid 512881:tid 513110] [client 20.104.50.220:51594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-1.php"] [unique_id "apPlYgi65Hcg2zUJjxByrwAAAnc"]
[Sun Aug 30 03:10:10.603261 2026] [security2:error] [pid 515259:tid 515393] [client 20.48.250.41:49907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/aa.php"] [unique_id "apPlYmZcVaai59truiVjdwAAAAM"]
[Sun Aug 30 03:10:10.603546 2026] [security2:error] [pid 512881:tid 513130] [client 20.63.81.20:36702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/gelap1.php"] [unique_id "apPlYgi65Hcg2zUJjxBysQAAAos"]
[Sun Aug 30 03:10:10.604312 2026] [security2:error] [pid 512881:tid 513102] [client 20.104.18.15:35163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/tnglzqmv.php"] [unique_id "apPlYgi65Hcg2zUJjxBysgAAAm8"]
[Sun Aug 30 03:10:10.605285 2026] [security2:error] [pid 515259:tid 515416] [client 20.104.50.220:59382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "apPlYmZcVaai59truiVjeAAAABo"]
[Sun Aug 30 03:10:10.617193 2026] [security2:error] [pid 512881:tid 513094] [client 20.104.18.15:16974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/img.php"] [unique_id "apPlYgi65Hcg2zUJjxBytAAAAmc"]
[Sun Aug 30 03:10:10.624973 2026] [security2:error] [pid 515259:tid 515455] [client 20.104.18.15:22423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/dehnl.php"] [unique_id "apPlYmZcVaai59truiVjeQAAAEE"]
[Sun Aug 30 03:10:10.633273 2026] [security2:error] [pid 512881:tid 513131] [client 20.63.81.20:31618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/ser.php"] [unique_id "apPlYgi65Hcg2zUJjxByugAAAow"]
[Sun Aug 30 03:10:10.659285 2026] [security2:error] [pid 512881:tid 513081] [client 158.23.147.79:10232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apPlYgi65Hcg2zUJjxByzQAAAlo"]
[Sun Aug 30 03:10:10.667379 2026] [security2:error] [pid 512881:tid 513031] [client 4.205.62.107:61769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/product.php"] [unique_id "apPlYgi65Hcg2zUJjxBy1QAAAig"]
[Sun Aug 30 03:10:10.670016 2026] [security2:error] [pid 512881:tid 513050] [client 20.48.251.3:13402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/saml.php"] [unique_id "apPlYgi65Hcg2zUJjxBy2AAAAjs"]
[Sun Aug 30 03:10:10.670446 2026] [authz_core:error] [pid 512881:tid 513128] [client 66.249.66.65:40385] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:10.670708 2026] [authz_core:error] [pid 512881:tid 513128] [client 66.249.66.65:40385] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:10.683123 2026] [security2:error] [pid 515259:tid 515406] [client 20.104.50.220:52863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/dikne.php"] [unique_id "apPlYmZcVaai59truiVjjAAAABA"]
[Sun Aug 30 03:10:10.684737 2026] [security2:error] [pid 512881:tid 513079] [client 20.48.250.41:38789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/ms.php"] [unique_id "apPlYgi65Hcg2zUJjxBy5gAAAlg"]
[Sun Aug 30 03:10:10.685940 2026] [security2:error] [pid 512881:tid 513029] [client 20.104.50.220:61636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/mas.php"] [unique_id "apPlYgi65Hcg2zUJjxBy5wAAAiY"]
[Sun Aug 30 03:10:10.693335 2026] [security2:error] [pid 515259:tid 515309] [remote 152.53.108.193:60130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.108.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tulsabankruptcyattorney.pro"] [uri "/wp-login.php"] [unique_id "apPlYmZcVaai59truiVjjgAAdTA"]
[Sun Aug 30 03:10:10.705975 2026] [security2:error] [pid 512881:tid 513018] [client 20.48.250.41:17399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlYgi65Hcg2zUJjxBy_AAAAhs"]
[Sun Aug 30 03:10:10.708468 2026] [authz_core:error] [pid 512881:tid 513102] [client 66.249.66.77:44549] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:10.708762 2026] [authz_core:error] [pid 512881:tid 513102] [client 66.249.66.77:44549] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:10.717757 2026] [security2:error] [pid 512881:tid 513126] [client 20.48.160.90:63906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/btyuio.php"] [unique_id "apPlYgi65Hcg2zUJjxBzBwAAAoc"]
[Sun Aug 30 03:10:10.721923 2026] [security2:error] [pid 515259:tid 515505] [client 20.104.18.15:44024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/file31.php"] [unique_id "apPlYmZcVaai59truiVjkQAAAHM"]
[Sun Aug 30 03:10:10.737221 2026] [security2:error] [pid 512881:tid 513054] [client 20.63.81.20:36673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/rsjlrria.php"] [unique_id "apPlYgi65Hcg2zUJjxBzHgAAAj8"]
[Sun Aug 30 03:10:10.743074 2026] [security2:error] [pid 512881:tid 513135] [client 20.48.250.41:49891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/s1.php"] [unique_id "apPlYgi65Hcg2zUJjxBzJAAAApA"]
[Sun Aug 30 03:10:10.757952 2026] [security2:error] [pid 512881:tid 513035] [client 20.104.18.15:18323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/inso.php"] [unique_id "apPlYgi65Hcg2zUJjxBzKwAAAiw"]
[Sun Aug 30 03:10:10.764455 2026] [security2:error] [pid 512881:tid 513045] [client 20.63.81.20:31683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/431.php"] [unique_id "apPlYgi65Hcg2zUJjxBzLwAAAjY"]
[Sun Aug 30 03:10:10.765708 2026] [security2:error] [pid 512881:tid 513041] [client 20.104.50.220:33215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-content/plugins/owfsmac/mar.php"] [unique_id "apPlYgi65Hcg2zUJjxBzMQAAAjI"]
[Sun Aug 30 03:10:10.769809 2026] [security2:error] [pid 515259:tid 515398] [client 158.23.147.79:42831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apPlYmZcVaai59truiVjlwAAAAg"]
[Sun Aug 30 03:10:10.821820 2026] [security2:error] [pid 512881:tid 513092] [client 20.48.250.41:38822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/zxekqlxb.php"] [unique_id "apPlYgi65Hcg2zUJjxBzSwAAAmU"]
[Sun Aug 30 03:10:10.863060 2026] [security2:error] [pid 512881:tid 513076] [client 20.63.81.20:36812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/AxAo.php"] [unique_id "apPlYgi65Hcg2zUJjxBzZQAAAlU"]
[Sun Aug 30 03:10:10.868271 2026] [security2:error] [pid 512881:tid 513056] [client 20.48.160.90:63979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/dehnl.php"] [unique_id "apPlYgi65Hcg2zUJjxBzbwAAAkE"]
[Sun Aug 30 03:10:10.875231 2026] [security2:error] [pid 512881:tid 513038] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/.env"] [unique_id "apPlYgi65Hcg2zUJjxBzcAAAAi8"]
[Sun Aug 30 03:10:10.875282 2026] [security2:error] [pid 512881:tid 513081] [client 20.48.250.41:49812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/0byte.php"] [unique_id "apPlYgi65Hcg2zUJjxBzcQAAAlo"]
[Sun Aug 30 03:10:10.876709 2026] [security2:error] [pid 515259:tid 515448] [client 20.104.50.220:6095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/+.php"] [unique_id "apPlYmZcVaai59truiVjrAAAADo"]
[Sun Aug 30 03:10:10.884934 2026] [authz_core:error] [pid 515259:tid 515460] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:10.885198 2026] [authz_core:error] [pid 515259:tid 515460] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:10.886376 2026] [security2:error] [pid 512881:tid 513078] [client 158.23.147.79:10229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apPlYgi65Hcg2zUJjxBzfgAAAlc"]
[Sun Aug 30 03:10:10.901966 2026] [security2:error] [pid 515259:tid 515420] [client 20.63.81.20:31731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/rxr.php"] [unique_id "apPlYmZcVaai59truiVjsgAAAB4"]
[Sun Aug 30 03:10:10.905122 2026] [security2:error] [pid 515259:tid 515311] [remote 152.53.108.193:60130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.108.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tulsabankruptcyattorney.pro"] [uri "/wp-login.php"] [unique_id "apPlYmZcVaai59truiVjswAAJjI"], referer: https://tulsabankruptcyattorney.pro/wp-login.php
[Sun Aug 30 03:10:10.908500 2026] [security2:error] [pid 512881:tid 513029] [client 68.155.159.216:45922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-content/themes/index.php"] [unique_id "apPlYgi65Hcg2zUJjxBziwAAAiY"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:10:10.991755 2026] [security2:error] [pid 515259:tid 515435] [client 20.63.81.20:36725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/class17.php"] [unique_id "apPlYmZcVaai59truiVjxgAAAC0"]
[Sun Aug 30 03:10:10.998138 2026] [security2:error] [pid 512881:tid 513086] [client 158.23.147.79:10154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apPlYgi65Hcg2zUJjxBzzAAAAl8"]
[Sun Aug 30 03:10:11.009790 2026] [security2:error] [pid 512881:tid 513024] [client 20.104.49.130:53748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/memberfuns.php"] [unique_id "apPlYwi65Hcg2zUJjxBz0gAAAiE"]
[Sun Aug 30 03:10:11.013229 2026] [security2:error] [pid 512881:tid 513045] [client 20.48.250.41:64635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/xr.php"] [unique_id "apPlYwi65Hcg2zUJjxBz1AAAAjY"]
[Sun Aug 30 03:10:11.021654 2026] [security2:error] [pid 512881:tid 513014] [client 20.48.160.90:63957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/zoo2.php"] [unique_id "apPlYwi65Hcg2zUJjxBz1wAAAhc"]
[Sun Aug 30 03:10:11.027127 2026] [security2:error] [pid 512881:tid 513126] [client 20.63.81.20:31622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/csst.php"] [unique_id "apPlYwi65Hcg2zUJjxBz2wAAAoc"]
[Sun Aug 30 03:10:11.035949 2026] [security2:error] [pid 512881:tid 513031] [client 20.48.250.41:38727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/init.php"] [unique_id "apPlYwi65Hcg2zUJjxBz3gAAAig"]
[Sun Aug 30 03:10:11.054470 2026] [security2:error] [pid 512881:tid 513064] [client 20.48.251.3:54791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/ws61.php"] [unique_id "apPlYwi65Hcg2zUJjxBz6gAAAkk"]
[Sun Aug 30 03:10:11.063133 2026] [security2:error] [pid 515259:tid 515443] [client 20.104.50.220:62815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/fvck.php"] [unique_id "apPlY2ZcVaai59truiVj0gAAADU"]
[Sun Aug 30 03:10:11.072238 2026] [security2:error] [pid 512881:tid 513136] [client 68.155.159.216:54281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/login.php"] [unique_id "apPlYwi65Hcg2zUJjxBz8QAAApE"]
[Sun Aug 30 03:10:11.076274 2026] [authz_core:error] [pid 512881:tid 513035] [client 66.249.66.70:40566] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:11.076707 2026] [authz_core:error] [pid 512881:tid 513035] [client 66.249.66.70:40566] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:11.102740 2026] [security2:error] [pid 512881:tid 513081] [client 4.205.62.107:25766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/gecko-litespeed.php"] [unique_id "apPlYwi65Hcg2zUJjxB0DgAAAlo"]
[Sun Aug 30 03:10:11.119370 2026] [security2:error] [pid 512881:tid 513117] [client 20.63.81.20:36608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/okxoby.php"] [unique_id "apPlYwi65Hcg2zUJjxB0FwAAAn4"]
[Sun Aug 30 03:10:11.131348 2026] [security2:error] [pid 512881:tid 513059] [client 158.23.147.79:10202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/nf_tracking.php"] [unique_id "apPlYwi65Hcg2zUJjxB0HQAAAkQ"]
[Sun Aug 30 03:10:11.141395 2026] [security2:error] [pid 515259:tid 515312] [remote 114.119.129.200:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.dallasfortworthbreastthermography.com"] [uri "/wp-content/themes/thermo17/config-layerslider/LayerSlider/static/layerslider/skins/lightskin"] [unique_id "apPlY2ZcVaai59truiVj4gAAMTM"], referer: https://www.dallasfortworthbreastthermography.com/wp-content/themes/thermo17/config-layerslider/LayerSlider/static/layerslider/skins?C=N%3BO%3DD
[Sun Aug 30 03:10:11.153000 2026] [security2:error] [pid 515259:tid 515459] [client 20.63.81.20:31732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp-includes/blocks/query-title/footer.php"] [unique_id "apPlY2ZcVaai59truiVj5AAAAEU"]
[Sun Aug 30 03:10:11.159080 2026] [security2:error] [pid 515259:tid 515424] [client 20.104.49.130:32778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/222.php"] [unique_id "apPlY2ZcVaai59truiVj5QAAACI"]
[Sun Aug 30 03:10:11.168371 2026] [security2:error] [pid 512881:tid 513037] [client 20.48.250.41:64536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/h02ugyh.php"] [unique_id "apPlYwi65Hcg2zUJjxB0LwAAAi4"]
[Sun Aug 30 03:10:11.215086 2026] [security2:error] [pid 515259:tid 515484] [client 20.48.160.90:63915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/zoo1.php"] [unique_id "apPlY2ZcVaai59truiVj8gAAAF4"]
[Sun Aug 30 03:10:11.235574 2026] [security2:error] [pid 512881:tid 513020] [client 158.23.147.79:10233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wzy.php"] [unique_id "apPlYwi65Hcg2zUJjxB0OgAAAh0"]
[Sun Aug 30 03:10:11.240266 2026] [authz_core:error] [pid 512881:tid 513047] [client 66.249.66.70:38388] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:11.240523 2026] [authz_core:error] [pid 512881:tid 513047] [client 66.249.66.70:38388] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:11.245610 2026] [security2:error] [pid 512881:tid 513102] [client 20.63.81.20:36816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/esuutzzx.php"] [unique_id "apPlYwi65Hcg2zUJjxB0QAAAAm8"]
[Sun Aug 30 03:10:11.257545 2026] [security2:error] [pid 512881:tid 513067] [client 20.48.250.41:17385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/ff1.php"] [unique_id "apPlYwi65Hcg2zUJjxB0QgAAAkw"]
[Sun Aug 30 03:10:11.262598 2026] [security2:error] [pid 512881:tid 513130] [client 4.205.62.107:36699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/h.php"] [unique_id "apPlYwi65Hcg2zUJjxB0RQAAAos"]
[Sun Aug 30 03:10:11.284129 2026] [security2:error] [pid 512881:tid 513124] [client 20.48.250.41:38892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/term.php"] [unique_id "apPlYwi65Hcg2zUJjxB0TAAAAoU"]
[Sun Aug 30 03:10:11.284135 2026] [security2:error] [pid 512881:tid 513014] [client 20.63.81.20:31738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp-content/uploads/indoex.php"] [unique_id "apPlYwi65Hcg2zUJjxB0TQAAAhc"]
[Sun Aug 30 03:10:11.287680 2026] [security2:error] [pid 512881:tid 513098] [client 20.104.49.130:64086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/tiny2.php"] [unique_id "apPlYwi65Hcg2zUJjxB0TwAAAms"]
[Sun Aug 30 03:10:11.295316 2026] [security2:error] [pid 512881:tid 513053] [client 20.48.250.41:49841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/xxw.php"] [unique_id "apPlYwi65Hcg2zUJjxB0UgAAAj4"]
[Sun Aug 30 03:10:11.298158 2026] [security2:error] [pid 515259:tid 515447] [client 20.104.49.130:57669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/menu.php"] [unique_id "apPlY2ZcVaai59truiVj9wAAADk"]
[Sun Aug 30 03:10:11.304574 2026] [security2:error] [pid 512881:tid 513046] [client 57.131.147.191:49947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.147.131.57.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rampd.co"] [uri "/xmlrpc.php"] [unique_id "apPlYwi65Hcg2zUJjxB0SwAAAjc"]
[Sun Aug 30 03:10:11.372700 2026] [security2:error] [pid 512881:tid 513119] [client 20.63.81.20:36632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/replace.php"] [unique_id "apPlYwi65Hcg2zUJjxB0ZAAAAoA"]
[Sun Aug 30 03:10:11.399426 2026] [security2:error] [pid 512881:tid 513052] [client 68.155.159.216:63257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/content.php"] [unique_id "apPlYwi65Hcg2zUJjxB0agAAAj0"]
[Sun Aug 30 03:10:11.410270 2026] [authz_core:error] [pid 515259:tid 515503] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:11.410545 2026] [authz_core:error] [pid 515259:tid 515503] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:11.413808 2026] [security2:error] [pid 512881:tid 513100] [client 20.63.81.20:31726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPlYwi65Hcg2zUJjxB0awAAAm0"]
[Sun Aug 30 03:10:11.416543 2026] [security2:error] [pid 512881:tid 513087] [client 20.151.200.44:28668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/xda.php"] [unique_id "apPlYwi65Hcg2zUJjxB0bQAAAmA"]
[Sun Aug 30 03:10:11.419173 2026] [security2:error] [pid 515259:tid 515470] [client 20.48.250.41:17368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/t.php"] [unique_id "apPlY2ZcVaai59truiVj-QAAAFA"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:10:11.434761 2026] [security2:error] [pid 512881:tid 513018] [client 20.48.250.41:64610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/bolt.php"] [unique_id "apPlYwi65Hcg2zUJjxB0cQAAAhs"]
[Sun Aug 30 03:10:11.457624 2026] [authz_core:error] [pid 515259:tid 515508] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:11.457895 2026] [authz_core:error] [pid 515259:tid 515508] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:11.460831 2026] [security2:error] [pid 512881:tid 513034] [client 158.23.147.79:10126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apPlYwi65Hcg2zUJjxB0eAAAAis"]
[Sun Aug 30 03:10:11.505932 2026] [security2:error] [pid 512881:tid 513118] [client 20.63.81.20:36696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/gulu.php"] [unique_id "apPlYwi65Hcg2zUJjxB0hwAAAn8"]
[Sun Aug 30 03:10:11.525051 2026] [security2:error] [pid 512881:tid 513019] [client 20.48.250.41:38868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/aaa.php"] [unique_id "apPlYwi65Hcg2zUJjxB0jQAAAhw"]
[Sun Aug 30 03:10:11.541856 2026] [security2:error] [pid 512881:tid 513093] [client 20.63.81.20:31628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/haxor.php"] [unique_id "apPlYwi65Hcg2zUJjxB0kwAAAmY"]
[Sun Aug 30 03:10:11.551930 2026] [security2:error] [pid 512881:tid 513131] [client 20.48.160.90:61420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/radio.php"] [unique_id "apPlYwi65Hcg2zUJjxB0lwAAAow"]
[Sun Aug 30 03:10:11.566734 2026] [security2:error] [pid 512881:tid 513104] [client 20.48.250.41:49811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/rtx.php"] [unique_id "apPlYwi65Hcg2zUJjxB0ngAAAnE"]
[Sun Aug 30 03:10:11.598129 2026] [security2:error] [pid 512881:tid 513074] [client 20.48.250.41:17282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/erty.php"] [unique_id "apPlYwi65Hcg2zUJjxB0rAAAAlM"]
[Sun Aug 30 03:10:11.601077 2026] [core:alert] [pid 515259:tid 515405] [client 72.255.11.62:50714] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:10:11.614338 2026] [security2:error] [pid 512881:tid 513081] [client 158.23.147.79:41575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apPlYwi65Hcg2zUJjxB0sAAAAlo"]
[Sun Aug 30 03:10:11.632695 2026] [security2:error] [pid 512881:tid 513058] [client 20.63.81.20:36759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/gtghklk.php"] [unique_id "apPlYwi65Hcg2zUJjxB0twAAAkM"]
[Sun Aug 30 03:10:11.638069 2026] [security2:error] [pid 512881:tid 513048] [client 20.104.50.220:16629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/222.php"] [unique_id "apPlYwi65Hcg2zUJjxB0vAAAAjk"]
[Sun Aug 30 03:10:11.648122 2026] [security2:error] [pid 512881:tid 513099] [client 20.104.18.15:16682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/nano.php"] [unique_id "apPlYwi65Hcg2zUJjxB0xQAAAmw"]
[Sun Aug 30 03:10:11.653757 2026] [authz_core:error] [pid 512881:tid 513053] [client 216.73.216.128:41146] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:11.654038 2026] [authz_core:error] [pid 512881:tid 513053] [client 216.73.216.128:41146] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:11.658769 2026] [security2:error] [pid 512881:tid 513082] [client 4.205.62.107:16804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/xmy.php"] [unique_id "apPlYwi65Hcg2zUJjxB01AAAAls"]
[Sun Aug 30 03:10:11.668202 2026] [security2:error] [pid 512881:tid 513078] [client 20.48.251.3:52815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/tinyfilemanager.php"] [unique_id "apPlYwi65Hcg2zUJjxB03QAAAlc"]
[Sun Aug 30 03:10:11.674484 2026] [security2:error] [pid 512881:tid 513018] [client 20.63.81.20:31700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/google.php"] [unique_id "apPlYwi65Hcg2zUJjxB04QAAAhs"]
[Sun Aug 30 03:10:11.683488 2026] [security2:error] [pid 512881:tid 513117] [client 20.48.160.90:63989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/one.php"] [unique_id "apPlYwi65Hcg2zUJjxB06gAAAn4"]
[Sun Aug 30 03:10:11.684107 2026] [security2:error] [pid 512881:tid 513044] [client 20.48.250.41:38850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/xsox.php"] [unique_id "apPlYwi65Hcg2zUJjxB06wAAAjU"]
[Sun Aug 30 03:10:11.693593 2026] [security2:error] [pid 512881:tid 513067] [client 20.48.251.3:59505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/ms-edit.php"] [unique_id "apPlYwi65Hcg2zUJjxB09QAAAkw"]
[Sun Aug 30 03:10:11.706445 2026] [security2:error] [pid 512881:tid 513102] [client 20.48.250.41:49903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/ckk.php"] [unique_id "apPlYwi65Hcg2zUJjxB0_wAAAm8"]
[Sun Aug 30 03:10:11.712826 2026] [security2:error] [pid 512881:tid 513124] [client 158.23.147.79:42820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apPlYwi65Hcg2zUJjxB1BwAAAoU"]
[Sun Aug 30 03:10:11.715741 2026] [security2:error] [pid 512881:tid 513110] [client 20.104.49.130:52097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/az.php"] [unique_id "apPlYwi65Hcg2zUJjxB1CwAAAnc"]
[Sun Aug 30 03:10:11.723038 2026] [authz_core:error] [pid 512881:tid 513037] [client 66.249.66.68:60397] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:11.723455 2026] [authz_core:error] [pid 512881:tid 513037] [client 66.249.66.68:60397] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:11.737118 2026] [security2:error] [pid 512881:tid 513061] [client 20.104.50.220:51574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/xindex.php"] [unique_id "apPlYwi65Hcg2zUJjxB1IwAAAkY"]
[Sun Aug 30 03:10:11.740153 2026] [security2:error] [pid 512881:tid 513131] [client 20.104.18.15:35814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/wefile.php"] [unique_id "apPlYwi65Hcg2zUJjxB1JgAAAow"]
[Sun Aug 30 03:10:11.754797 2026] [security2:error] [pid 512881:tid 513136] [client 20.104.18.15:17004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/222.php"] [unique_id "apPlYwi65Hcg2zUJjxB1MAAAApE"]
[Sun Aug 30 03:10:11.759212 2026] [security2:error] [pid 512881:tid 513102] [client 20.63.81.20:36627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/comand.php"] [unique_id "apPlYwi65Hcg2zUJjxB1MgAAAm8"]
[Sun Aug 30 03:10:11.768760 2026] [security2:error] [pid 512881:tid 513076] [client 20.48.250.41:17390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/0x.php"] [unique_id "apPlYwi65Hcg2zUJjxB1NgAAAlU"]
[Sun Aug 30 03:10:11.800174 2026] [security2:error] [pid 512881:tid 513097] [client 20.104.18.15:22522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/zoo2.php"] [unique_id "apPlYwi65Hcg2zUJjxB1TAAAAmo"]
[Sun Aug 30 03:10:11.800255 2026] [security2:error] [pid 512881:tid 513018] [client 20.63.81.20:31707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "apPlYwi65Hcg2zUJjxB1TgAAAhs"]
[Sun Aug 30 03:10:11.806516 2026] [security2:error] [pid 515259:tid 515492] [client 4.205.62.107:61802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/fun.php"] [unique_id "apPlY2ZcVaai59truiVkDwAAAGY"]
[Sun Aug 30 03:10:11.807140 2026] [security2:error] [pid 512881:tid 513061] [client 20.48.251.3:13430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/aws_settings.php"] [unique_id "apPlYwi65Hcg2zUJjxB1UwAAAkY"]
[Sun Aug 30 03:10:11.811708 2026] [security2:error] [pid 512881:tid 513101] [client 20.104.49.130:45756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPlYwi65Hcg2zUJjxB1VgAAAm4"]
[Sun Aug 30 03:10:11.813423 2026] [security2:error] [pid 512881:tid 513048] [client 20.48.250.41:38851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/lkui.php"] [unique_id "apPlYwi65Hcg2zUJjxB1WAAAAjk"]
[Sun Aug 30 03:10:11.820026 2026] [security2:error] [pid 515259:tid 515421] [client 158.23.147.79:41596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apPlY2ZcVaai59truiVkEQAAAB8"]
[Sun Aug 30 03:10:11.852739 2026] [security2:error] [pid 512881:tid 513088] [client 20.104.50.220:28694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/cPanel.php"] [unique_id "apPlYwi65Hcg2zUJjxB1cgAAAmE"]
[Sun Aug 30 03:10:11.857091 2026] [security2:error] [pid 512881:tid 513105] [client 20.48.160.90:63976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/503.php"] [unique_id "apPlYwi65Hcg2zUJjxB1eAAAAnI"]
[Sun Aug 30 03:10:11.858708 2026] [security2:error] [pid 512881:tid 513107] [client 20.48.250.41:49881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.jeanbooknerdmedia.com"] [uri "/R57.php"] [unique_id "apPlYwi65Hcg2zUJjxB1eQAAAnQ"]
[Sun Aug 30 03:10:11.879116 2026] [security2:error] [pid 512881:tid 513126] [client 20.104.18.15:43325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/dk.php"] [unique_id "apPlYwi65Hcg2zUJjxB1iwAAAoc"]
[Sun Aug 30 03:10:11.887695 2026] [security2:error] [pid 512881:tid 513071] [client 20.63.81.20:36629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp_motu_myk3v.php"] [unique_id "apPlYwi65Hcg2zUJjxB1jgAAAlA"]
[Sun Aug 30 03:10:11.892734 2026] [authz_core:error] [pid 515259:tid 515433] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:11.893000 2026] [authz_core:error] [pid 515259:tid 515433] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:11.898975 2026] [security2:error] [pid 515259:tid 515471] [client 20.104.50.220:61635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/mini.php"] [unique_id "apPlY2ZcVaai59truiVkHgAAAFE"]
[Sun Aug 30 03:10:11.903053 2026] [security2:error] [pid 512881:tid 513096] [client 20.104.18.15:18415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/aa.php"] [unique_id "apPlYwi65Hcg2zUJjxB1nQAAAmk"]
[Sun Aug 30 03:10:11.905079 2026] [security2:error] [pid 515259:tid 515399] [client 20.104.50.220:33182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/tersembunyi.php"] [unique_id "apPlY2ZcVaai59truiVkIAAAAAk"]
[Sun Aug 30 03:10:11.906762 2026] [authz_core:error] [pid 512881:tid 513112] [client 66.249.66.78:56554] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:11.907070 2026] [authz_core:error] [pid 512881:tid 513112] [client 66.249.66.78:56554] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:11.918901 2026] [security2:error] [pid 512881:tid 513133] [client 158.23.147.79:10196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apPlYwi65Hcg2zUJjxB1pAAAAo4"]
[Sun Aug 30 03:10:11.927310 2026] [security2:error] [pid 512881:tid 513046] [client 20.63.81.20:31729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/robots.php"] [unique_id "apPlYwi65Hcg2zUJjxB1pgAAAjc"]
[Sun Aug 30 03:10:11.935029 2026] [security2:error] [pid 515259:tid 515499] [client 20.48.250.41:17292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/66.php"] [unique_id "apPlY2ZcVaai59truiVkIgAAAG0"]
[Sun Aug 30 03:10:11.951485 2026] [security2:error] [pid 515259:tid 515432] [client 20.48.250.41:38856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apPlY2ZcVaai59truiVkKAAAACo"]
[Sun Aug 30 03:10:11.967457 2026] [security2:error] [pid 512881:tid 513018] [client 158.23.147.79:56491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPlYwi65Hcg2zUJjxB1wQAAAhs"]
[Sun Aug 30 03:10:11.971112 2026] [security2:error] [pid 515259:tid 515393] [client 20.104.49.130:53743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/v2.php"] [unique_id "apPlY2ZcVaai59truiVkNwAAAAM"]
[Sun Aug 30 03:10:12.002487 2026] [security2:error] [pid 515259:tid 515479] [client 158.23.147.79:43859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlZGZcVaai59truiVkQQAAAFk"]
[Sun Aug 30 03:10:12.009352 2026] [security2:error] [pid 512881:tid 513026] [client 20.104.50.220:63200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-admin/css/colour.php"] [unique_id "apPlZAi65Hcg2zUJjxB13wAAAiM"]
[Sun Aug 30 03:10:12.015688 2026] [security2:error] [pid 512881:tid 513092] [client 20.63.81.20:36621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/wp_motu_ypdat.php"] [unique_id "apPlZAi65Hcg2zUJjxB14QAAAmU"]
[Sun Aug 30 03:10:12.024612 2026] [security2:error] [pid 512881:tid 513077] [client 20.48.160.90:61419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/504.php"] [unique_id "apPlZAi65Hcg2zUJjxB15QAAAlY"]
[Sun Aug 30 03:10:12.031076 2026] [security2:error] [pid 512881:tid 513118] [client 20.104.50.220:5608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/ucenhaxor.php"] [unique_id "apPlZAi65Hcg2zUJjxB16QAAAn8"]
[Sun Aug 30 03:10:12.048013 2026] [security2:error] [pid 512881:tid 513122] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/.env.bak"] [unique_id "apPlZAi65Hcg2zUJjxB18AAAAoM"]
[Sun Aug 30 03:10:12.053328 2026] [security2:error] [pid 515259:tid 515405] [client 20.63.81.20:31630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp-content/plugins/ccx/index.php"] [unique_id "apPlZGZcVaai59truiVkRgAAAA8"]
[Sun Aug 30 03:10:12.080023 2026] [security2:error] [pid 515259:tid 515435] [client 158.23.147.79:41559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/packed.php"] [unique_id "apPlZGZcVaai59truiVkTAAAAC0"]
[Sun Aug 30 03:10:12.089208 2026] [security2:error] [pid 512881:tid 512987] [remote 170.64.135.172:34602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.135.64.170.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nhlhockeybythenumbers.com"] [uri "/wp-login.php"] [unique_id "apPlZAi65Hcg2zUJjxB1-gACUWk"]
[Sun Aug 30 03:10:12.089993 2026] [authz_core:error] [pid 512881:tid 513074] [client 66.249.66.193:55577] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:12.090270 2026] [authz_core:error] [pid 512881:tid 513074] [client 66.249.66.193:55577] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:12.108976 2026] [security2:error] [pid 512881:tid 513058] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/.env.backup"] [unique_id "apPlZAi65Hcg2zUJjxB2DgAAAkM"]
[Sun Aug 30 03:10:12.109102 2026] [security2:error] [pid 515259:tid 515443] [client 20.48.250.41:38897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/motu.php"] [unique_id "apPlZGZcVaai59truiVkVQAAADU"]
[Sun Aug 30 03:10:12.115221 2026] [authz_core:error] [pid 512881:tid 513125] [client 216.73.216.128:41146] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:12.115531 2026] [authz_core:error] [pid 512881:tid 513125] [client 216.73.216.128:41146] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:12.133937 2026] [security2:error] [pid 512881:tid 513078] [client 68.155.159.216:46069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/about.php"] [unique_id "apPlZAi65Hcg2zUJjxB2GwAAAlc"]
[Sun Aug 30 03:10:12.134026 2026] [security2:error] [pid 512881:tid 513015] [client 20.48.250.41:17361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/f35.php"] [unique_id "apPlZAi65Hcg2zUJjxB2GgAAAhg"]
[Sun Aug 30 03:10:12.141053 2026] [security2:error] [pid 512881:tid 513023] [client 20.63.81.20:36789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/edit.php"] [unique_id "apPlZAi65Hcg2zUJjxB2IgAAAiA"]
[Sun Aug 30 03:10:12.156431 2026] [security2:error] [pid 515259:tid 515444] [client 20.48.160.90:61438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/admin.php"] [unique_id "apPlZGZcVaai59truiVkWwAAADY"]
[Sun Aug 30 03:10:12.174639 2026] [security2:error] [pid 515259:tid 515473] [client 68.155.159.216:52604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/hehehehe.php"] [unique_id "apPlZGZcVaai59truiVkXgAAAFM"]
[Sun Aug 30 03:10:12.179207 2026] [security2:error] [pid 512881:tid 513057] [client 20.63.81.20:31739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp-admin/css/colors/maro.php"] [unique_id "apPlZAi65Hcg2zUJjxB2OQAAAkI"]
[Sun Aug 30 03:10:12.203008 2026] [security2:error] [pid 512881:tid 513100] [client 20.104.50.220:52862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/0x.php"] [unique_id "apPlZAi65Hcg2zUJjxB2QAAAAm0"]
[Sun Aug 30 03:10:12.220208 2026] [security2:error] [pid 512881:tid 513019] [client 158.23.147.79:10178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-content/packed.php"] [unique_id "apPlZAi65Hcg2zUJjxB2RQAAAhw"]
[Sun Aug 30 03:10:12.225848 2026] [security2:error] [pid 512881:tid 513065] [client 20.48.251.3:65517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/xza.php"] [unique_id "apPlZAi65Hcg2zUJjxB2RwAAAko"]
[Sun Aug 30 03:10:12.268195 2026] [security2:error] [pid 512881:tid 513109] [client 20.63.81.20:36842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/tqkdqbbv.php"] [unique_id "apPlZAi65Hcg2zUJjxB2WgAAAnY"]
[Sun Aug 30 03:10:12.303872 2026] [security2:error] [pid 512881:tid 513115] [client 20.48.250.41:38766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/Ov-Simple1.php"] [unique_id "apPlZAi65Hcg2zUJjxB2ZQAAAnw"]
[Sun Aug 30 03:10:12.304407 2026] [security2:error] [pid 512881:tid 513013] [client 20.48.250.41:17318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/wen.php"] [unique_id "apPlZAi65Hcg2zUJjxB2ZgAAAhY"]
[Sun Aug 30 03:10:12.305153 2026] [security2:error] [pid 512881:tid 513039] [client 20.48.160.90:63961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/ws85.php"] [unique_id "apPlZAi65Hcg2zUJjxB2ZwAAAjA"]
[Sun Aug 30 03:10:12.305315 2026] [security2:error] [pid 512881:tid 513116] [client 20.63.81.20:31695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp-admin/css/colors/coffee/marijuana.php"] [unique_id "apPlZAi65Hcg2zUJjxB2aAAAAn0"]
[Sun Aug 30 03:10:12.323839 2026] [security2:error] [pid 512881:tid 513093] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/.env.old"] [unique_id "apPlZAi65Hcg2zUJjxB2bQAAAmY"]
[Sun Aug 30 03:10:12.340985 2026] [security2:error] [pid 512881:tid 513100] [client 4.205.62.107:25871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/goods.php"] [unique_id "apPlZAi65Hcg2zUJjxB2bwAAAm0"]
[Sun Aug 30 03:10:12.357104 2026] [security2:error] [pid 512881:tid 513037] [client 20.104.49.130:43315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/js.php"] [unique_id "apPlZAi65Hcg2zUJjxB2cgAAAi4"]
[Sun Aug 30 03:10:12.380387 2026] [security2:error] [pid 512881:tid 513079] [client 158.23.147.79:42816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-l0gin.php"] [unique_id "apPlZAi65Hcg2zUJjxB2eQAAAlg"]
[Sun Aug 30 03:10:12.394098 2026] [security2:error] [pid 515259:tid 515409] [client 20.63.81.20:36710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/kjyehoxl.php"] [unique_id "apPlZGZcVaai59truiVkbAAAABM"]
[Sun Aug 30 03:10:12.403534 2026] [authz_core:error] [pid 515259:tid 515442] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:12.404034 2026] [authz_core:error] [pid 515259:tid 515442] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:12.414222 2026] [authz_core:error] [pid 512881:tid 513012] [client 66.249.66.76:58794] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:12.414493 2026] [authz_core:error] [pid 512881:tid 513012] [client 66.249.66.76:58794] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:12.415195 2026] [security2:error] [pid 515259:tid 515437] [client 4.205.62.107:36643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/bootstrap.php"] [unique_id "apPlZGZcVaai59truiVkbgAAAC8"]
[Sun Aug 30 03:10:12.437484 2026] [security2:error] [pid 512881:tid 513111] [client 20.48.250.41:38850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/wp-blogs.php"] [unique_id "apPlZAi65Hcg2zUJjxB2hQAAAng"]
[Sun Aug 30 03:10:12.439390 2026] [security2:error] [pid 512881:tid 513108] [client 20.48.160.90:61415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/ffs.php"] [unique_id "apPlZAi65Hcg2zUJjxB2iAAAAnU"]
[Sun Aug 30 03:10:12.439493 2026] [security2:error] [pid 515259:tid 515412] [client 20.63.81.20:31626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp-admin/css/colors/coffee/mari.php"] [unique_id "apPlZGZcVaai59truiVkcAAAABY"]
[Sun Aug 30 03:10:12.447840 2026] [security2:error] [pid 512881:tid 513099] [client 20.48.250.41:17355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/inc.php"] [unique_id "apPlZAi65Hcg2zUJjxB2igAAAmw"]
[Sun Aug 30 03:10:12.452236 2026] [security2:error] [pid 515259:tid 515452] [client 20.104.49.130:63493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/x1da.php"] [unique_id "apPlZGZcVaai59truiVkcgAAAD4"]
[Sun Aug 30 03:10:12.491340 2026] [security2:error] [pid 512881:tid 513046] [client 158.23.147.79:10219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apPlZAi65Hcg2zUJjxB2mQAAAjc"]
[Sun Aug 30 03:10:12.516852 2026] [security2:error] [pid 512881:tid 513123] [client 68.155.159.216:62614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPlZAi65Hcg2zUJjxB2ogAAAoQ"]
[Sun Aug 30 03:10:12.521137 2026] [security2:error] [pid 512881:tid 513072] [client 20.63.81.20:36824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/llyuxaqd.php"] [unique_id "apPlZAi65Hcg2zUJjxB2pAAAAlE"]
[Sun Aug 30 03:10:12.568012 2026] [security2:error] [pid 512881:tid 512991] [remote 170.64.135.172:34602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.135.64.170.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nhlhockeybythenumbers.com"] [uri "/wp-login.php"] [unique_id "apPlZAi65Hcg2zUJjxB2sAACaG0"], referer: https://nhlhockeybythenumbers.com/wp-login.php
[Sun Aug 30 03:10:12.569180 2026] [authz_core:error] [pid 512881:tid 513065] [client 216.73.216.128:62743] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:12.569476 2026] [authz_core:error] [pid 512881:tid 513065] [client 216.73.216.128:62743] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:12.579827 2026] [security2:error] [pid 512881:tid 513131] [client 20.63.81.20:31724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp-includes/images/crystal/option.php"] [unique_id "apPlZAi65Hcg2zUJjxB2tQAAAow"]
[Sun Aug 30 03:10:12.581387 2026] [security2:error] [pid 512881:tid 513052] [client 158.23.147.79:43844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlZAi65Hcg2zUJjxB2twAAAj0"]
[Sun Aug 30 03:10:12.587131 2026] [security2:error] [pid 512881:tid 513085] [client 20.48.160.90:63960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/nano.php"] [unique_id "apPlZAi65Hcg2zUJjxB2ugAAAl4"]
[Sun Aug 30 03:10:12.588186 2026] [security2:error] [pid 512881:tid 513138] [client 20.48.250.41:17391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/6bcwiqwj.php"] [unique_id "apPlZAi65Hcg2zUJjxB2uwAAApM"]
[Sun Aug 30 03:10:12.590544 2026] [security2:error] [pid 512881:tid 513084] [client 20.48.250.41:38690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/mini.php"] [unique_id "apPlZAi65Hcg2zUJjxB2vwAAAl0"]
[Sun Aug 30 03:10:12.590613 2026] [security2:error] [pid 512881:tid 513049] [client 20.104.49.130:43319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/red.php"] [unique_id "apPlZAi65Hcg2zUJjxB2vgAAAjo"]
[Sun Aug 30 03:10:12.596005 2026] [authz_core:error] [pid 512881:tid 513100] [client 66.249.66.73:47672] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:12.596292 2026] [authz_core:error] [pid 512881:tid 513100] [client 66.249.66.73:47672] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:12.647037 2026] [security2:error] [pid 512881:tid 513102] [client 20.63.81.20:36776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/nbwxolou.php"] [unique_id "apPlZAi65Hcg2zUJjxB22QAAAm8"]
[Sun Aug 30 03:10:12.654073 2026] [security2:error] [pid 515259:tid 515440] [client 216.73.216.128:21482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts2/updateconf"] [unique_id "apPlZGZcVaai59truiVkgQAAADI"]
[Sun Aug 30 03:10:12.701577 2026] [security2:error] [pid 512881:tid 513060] [client 158.23.147.79:42853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPlZAi65Hcg2zUJjxB3BAAAAkU"]
[Sun Aug 30 03:10:12.714923 2026] [security2:error] [pid 515259:tid 515464] [client 20.63.81.20:31640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp-includes/pomo/xxx.php"] [unique_id "apPlZGZcVaai59truiVkiQAAAEo"]
[Sun Aug 30 03:10:12.716711 2026] [authz_core:error] [pid 512881:tid 513079] [client 66.249.66.71:38496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:12.717159 2026] [authz_core:error] [pid 512881:tid 513079] [client 66.249.66.71:38496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:12.720298 2026] [security2:error] [pid 515259:tid 515396] [client 20.48.250.41:38761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/amp.php"] [unique_id "apPlZGZcVaai59truiVkigAAAAY"]
[Sun Aug 30 03:10:12.726490 2026] [security2:error] [pid 512881:tid 513088] [client 20.48.160.90:63919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/ano.php"] [unique_id "apPlZAi65Hcg2zUJjxB3GgAAAmE"]
[Sun Aug 30 03:10:12.744599 2026] [security2:error] [pid 512881:tid 513023] [client 216.73.216.128:41146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/'+this.controller.state().get("] [unique_id "apPlZAi65Hcg2zUJjxB3KgAAAiA"]
[Sun Aug 30 03:10:12.753235 2026] [security2:error] [pid 515259:tid 515395] [client 20.48.250.41:17367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/easy.php"] [unique_id "apPlZGZcVaai59truiVkkQAAAAU"]
[Sun Aug 30 03:10:12.754772 2026] [core:alert] [pid 512881:tid 513123] [client 201.210.214.34:39234] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:10:12.773398 2026] [security2:error] [pid 512881:tid 513076] [client 20.104.50.220:16757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-content/index.php"] [unique_id "apPlZAi65Hcg2zUJjxB3OwAAAlU"]
[Sun Aug 30 03:10:12.777380 2026] [security2:error] [pid 512881:tid 513066] [client 20.63.81.20:36775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/nsxeubyv.php"] [unique_id "apPlZAi65Hcg2zUJjxB3PQAAAks"]
[Sun Aug 30 03:10:12.780679 2026] [security2:error] [pid 512881:tid 513124] [client 20.104.18.15:64852] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "autodiscover.larb.info"] [uri "/.mopj.php"] [unique_id "apPlZAi65Hcg2zUJjxB3QQAAAoU"]
[Sun Aug 30 03:10:12.785556 2026] [security2:error] [pid 515259:tid 515406] [client 184.154.76.13:60784] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "dejulschoolofdance.com"] [uri "/wp-content/plugins/elementor/assets/css/widget-image-carousel.min.css"] [unique_id "apPlZGZcVaai59truiVklgAAABA"]
[Sun Aug 30 03:10:12.796259 2026] [security2:error] [pid 515259:tid 515438] [client 4.205.62.107:17105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/ms-edit.php"] [unique_id "apPlZGZcVaai59truiVkmwAAADA"]
[Sun Aug 30 03:10:12.798589 2026] [security2:error] [pid 515259:tid 515489] [client 20.48.251.3:59296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/05.php"] [unique_id "apPlZGZcVaai59truiVknQAAAGM"]
[Sun Aug 30 03:10:12.832078 2026] [security2:error] [pid 512881:tid 513056] [client 20.48.251.3:59462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/sys.php"] [unique_id "apPlZAi65Hcg2zUJjxB3WgAAAkE"]
[Sun Aug 30 03:10:12.841455 2026] [authz_core:error] [pid 512881:tid 513128] [client 216.73.216.128:62743] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:12.841759 2026] [authz_core:error] [pid 512881:tid 513128] [client 216.73.216.128:62743] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:12.842631 2026] [security2:error] [pid 512881:tid 513063] [client 158.23.147.79:10133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/ans.php"] [unique_id "apPlZAi65Hcg2zUJjxB3XwAAAkg"]
[Sun Aug 30 03:10:12.851035 2026] [security2:error] [pid 512881:tid 513106] [client 20.63.81.20:31690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/650.php"] [unique_id "apPlZAi65Hcg2zUJjxB3ZQAAAnM"]
[Sun Aug 30 03:10:12.853948 2026] [security2:error] [pid 512881:tid 513065] [client 20.48.160.90:63916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/mgrr.php"] [unique_id "apPlZAi65Hcg2zUJjxB3agAAAko"]
[Sun Aug 30 03:10:12.860929 2026] [security2:error] [pid 512881:tid 513087] [client 20.48.250.41:38871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/cc13.php"] [unique_id "apPlZAi65Hcg2zUJjxB3cgAAAmA"]
[Sun Aug 30 03:10:12.865590 2026] [authz_core:error] [pid 515259:tid 515418] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:12.866012 2026] [authz_core:error] [pid 515259:tid 515418] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:12.887392 2026] [security2:error] [pid 512881:tid 513131] [client 20.104.50.220:42752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wiki-index.php"] [unique_id "apPlZAi65Hcg2zUJjxB3iwAAAow"]
[Sun Aug 30 03:10:12.893583 2026] [security2:error] [pid 512881:tid 513069] [client 20.104.18.15:16991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/key.php"] [unique_id "apPlZAi65Hcg2zUJjxB3lAAAAk4"]
[Sun Aug 30 03:10:12.894298 2026] [security2:error] [pid 512881:tid 513106] [client 20.104.18.15:35733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/blog.php"] [unique_id "apPlZAi65Hcg2zUJjxB3lgAAAnM"]
[Sun Aug 30 03:10:12.896814 2026] [security2:error] [pid 512881:tid 513087] [client 20.48.250.41:17395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/fresh3.php"] [unique_id "apPlZAi65Hcg2zUJjxB3mAAAAmA"]
[Sun Aug 30 03:10:12.911282 2026] [security2:error] [pid 512881:tid 513125] [client 20.63.81.20:36610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/zfqipfss.php"] [unique_id "apPlZAi65Hcg2zUJjxB3nwAAAoY"]
[Sun Aug 30 03:10:12.917504 2026] [security2:error] [pid 512881:tid 513014] [client 20.104.49.130:43283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/x1da.php"] [unique_id "apPlZAi65Hcg2zUJjxB3ogAAAhc"]
[Sun Aug 30 03:10:12.938448 2026] [security2:error] [pid 512881:tid 513103] [client 20.104.18.15:22518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/zoo1.php"] [unique_id "apPlZAi65Hcg2zUJjxB3sAAAAnA"]
[Sun Aug 30 03:10:12.941089 2026] [security2:error] [pid 512881:tid 513072] [client 158.23.147.79:42817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/worksec.php"] [unique_id "apPlZAi65Hcg2zUJjxB3tQAAAlE"]
[Sun Aug 30 03:10:12.949019 2026] [security2:error] [pid 512881:tid 513052] [client 4.205.62.107:58445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/kedi.php"] [unique_id "apPlZAi65Hcg2zUJjxB3uQAAAj0"]
[Sun Aug 30 03:10:12.952492 2026] [security2:error] [pid 512881:tid 513062] [client 20.104.49.130:52145] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.bluegrassatthelake.com"] [uri "/1.php"] [unique_id "apPlZAi65Hcg2zUJjxB3wQAAAkc"]
[Sun Aug 30 03:10:12.952586 2026] [security2:error] [pid 512881:tid 513062] [client 20.104.49.130:52145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/1.php"] [unique_id "apPlZAi65Hcg2zUJjxB3wQAAAkc"]
[Sun Aug 30 03:10:12.965584 2026] [security2:error] [pid 512881:tid 513083] [client 20.48.251.3:33313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/wp-konfig.backup.php"] [unique_id "apPlZAi65Hcg2zUJjxB30gAAAlw"]
[Sun Aug 30 03:10:12.986680 2026] [security2:error] [pid 512881:tid 513050] [client 20.63.81.20:31711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/nakrip.php"] [unique_id "apPlZAi65Hcg2zUJjxB35gAAAjs"]
[Sun Aug 30 03:10:12.987925 2026] [security2:error] [pid 512881:tid 513065] [client 20.48.160.90:63963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/mac.php"] [unique_id "apPlZAi65Hcg2zUJjxB35wAAAko"]
[Sun Aug 30 03:10:12.995755 2026] [security2:error] [pid 512881:tid 513048] [client 20.48.250.41:38859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/aa.php"] [unique_id "apPlZAi65Hcg2zUJjxB37wAAAjk"]
[Sun Aug 30 03:10:13.000056 2026] [security2:error] [pid 512881:tid 513034] [client 184.154.76.13:60788] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "dejulschoolofdance.com"] [uri "/wp-content/plugins/elementor/assets/css/widget-spacer.min.css"] [unique_id "apPlZAi65Hcg2zUJjxB38AAAAis"]
[Sun Aug 30 03:10:13.008045 2026] [security2:error] [pid 512881:tid 513088] [client 20.104.50.220:62811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/cargo.php"] [unique_id "apPlZQi65Hcg2zUJjxB3-gAAAmE"]
[Sun Aug 30 03:10:13.022227 2026] [authz_core:error] [pid 512881:tid 513013] [client 66.249.66.65:40941] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:13.022503 2026] [authz_core:error] [pid 512881:tid 513013] [client 66.249.66.65:40941] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:13.034963 2026] [security2:error] [pid 515259:tid 515482] [client 20.48.250.41:17346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/bgymj.php"] [unique_id "apPlZWZcVaai59truiVkuwAAAFw"]
[Sun Aug 30 03:10:13.039063 2026] [security2:error] [pid 512881:tid 513118] [client 20.104.18.15:18330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/img.php"] [unique_id "apPlZQi65Hcg2zUJjxB4DAAAAn8"]
[Sun Aug 30 03:10:13.042377 2026] [security2:error] [pid 512881:tid 513068] [client 20.104.18.15:43924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/ta.php"] [unique_id "apPlZQi65Hcg2zUJjxB4DgAAAk0"]
[Sun Aug 30 03:10:13.046705 2026] [security2:error] [pid 512881:tid 513026] [client 158.23.147.79:10228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/x.php"] [unique_id "apPlZQi65Hcg2zUJjxB4EQAAAiM"]
[Sun Aug 30 03:10:13.053201 2026] [security2:error] [pid 512881:tid 513054] [client 20.104.50.220:32853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/lab.php"] [unique_id "apPlZQi65Hcg2zUJjxB4GAAAAj8"]
[Sun Aug 30 03:10:13.054686 2026] [security2:error] [pid 512881:tid 513048] [client 20.151.200.44:40910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/h02ugyh.php"] [unique_id "apPlZQi65Hcg2zUJjxB4GQAAAjk"]
[Sun Aug 30 03:10:13.070764 2026] [security2:error] [pid 512881:tid 513047] [client 20.63.81.20:36693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.beyondmycross.com"] [uri "/zrjuyoos.php"] [unique_id "apPlZQi65Hcg2zUJjxB4HwAAAjg"]
[Sun Aug 30 03:10:13.108182 2026] [security2:error] [pid 512881:tid 513096] [client 20.104.50.220:61695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/minik.php"] [unique_id "apPlZQi65Hcg2zUJjxB4MQAAAmk"]
[Sun Aug 30 03:10:13.117208 2026] [security2:error] [pid 512881:tid 513022] [client 20.63.81.20:31623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp-includes/interactivity-api/flower.php"] [unique_id "apPlZQi65Hcg2zUJjxB4OgAAAh8"]
[Sun Aug 30 03:10:13.141065 2026] [authz_core:error] [pid 515259:tid 515460] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:13.141418 2026] [authz_core:error] [pid 515259:tid 515460] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:13.149441 2026] [security2:error] [pid 512881:tid 513095] [client 20.104.50.220:63218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/2P.php"] [unique_id "apPlZQi65Hcg2zUJjxB4RgAAAmg"]
[Sun Aug 30 03:10:13.149444 2026] [security2:error] [pid 515259:tid 515413] [client 20.48.160.90:37622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/simple.php"] [unique_id "apPlZWZcVaai59truiVk1QAAABc"]
[Sun Aug 30 03:10:13.161000 2026] [security2:error] [pid 512881:tid 513083] [client 20.48.250.41:17372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/ws69.php"] [unique_id "apPlZQi65Hcg2zUJjxB4TQAAAlw"]
[Sun Aug 30 03:10:13.172928 2026] [security2:error] [pid 512881:tid 513046] [client 20.104.49.130:52121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/1xmomo.php"] [unique_id "apPlZQi65Hcg2zUJjxB4WQAAAjc"]
[Sun Aug 30 03:10:13.184726 2026] [security2:error] [pid 512881:tid 513114] [client 20.104.50.220:5630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/radio.php"] [unique_id "apPlZQi65Hcg2zUJjxB4YQAAAns"]
[Sun Aug 30 03:10:13.199339 2026] [security2:error] [pid 515259:tid 515481] [client 20.48.250.41:38888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/s1.php"] [unique_id "apPlZWZcVaai59truiVk2wAAAFs"]
[Sun Aug 30 03:10:13.241440 2026] [authz_core:error] [pid 512881:tid 513115] [client 66.249.66.70:38388] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:13.241909 2026] [authz_core:error] [pid 512881:tid 513115] [client 66.249.66.70:38388] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:13.246889 2026] [security2:error] [pid 512881:tid 513030] [client 20.63.81.20:31624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/xcc.php"] [unique_id "apPlZQi65Hcg2zUJjxB4dgAAAic"]
[Sun Aug 30 03:10:13.253514 2026] [security2:error] [pid 512881:tid 513057] [client 68.155.159.216:46052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apPlZQi65Hcg2zUJjxB4eQAAAkI"]
[Sun Aug 30 03:10:13.257497 2026] [security2:error] [pid 512881:tid 513083] [client 158.23.147.79:10155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-content/x.php"] [unique_id "apPlZQi65Hcg2zUJjxB4ewAAAlw"]
[Sun Aug 30 03:10:13.293978 2026] [security2:error] [pid 512881:tid 513053] [client 20.48.160.90:61402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/xty.php"] [unique_id "apPlZQi65Hcg2zUJjxB4hwAAAj4"]
[Sun Aug 30 03:10:13.313427 2026] [security2:error] [pid 512881:tid 513093] [client 68.155.159.216:52546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apPlZQi65Hcg2zUJjxB4jAAAAmY"]
[Sun Aug 30 03:10:13.317477 2026] [security2:error] [pid 512881:tid 513119] [client 20.48.250.41:17401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/ccs.php"] [unique_id "apPlZQi65Hcg2zUJjxB4jwAAAoA"]
[Sun Aug 30 03:10:13.326977 2026] [security2:error] [pid 512881:tid 513116] [client 20.48.250.41:38854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/0byte.php"] [unique_id "apPlZQi65Hcg2zUJjxB4kwAAAn0"]
[Sun Aug 30 03:10:13.328015 2026] [security2:error] [pid 512881:tid 513088] [client 158.23.147.79:52274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apPlZQi65Hcg2zUJjxB4lAAAAmE"]
[Sun Aug 30 03:10:13.343209 2026] [authz_core:error] [pid 512881:tid 513122] [client 66.249.66.204:53397] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:13.343468 2026] [authz_core:error] [pid 512881:tid 513122] [client 66.249.66.204:53397] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:13.357390 2026] [security2:error] [pid 512881:tid 513123] [client 158.23.147.79:10216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPlZQi65Hcg2zUJjxB4mgAAAoQ"]
[Sun Aug 30 03:10:13.364613 2026] [security2:error] [pid 515259:tid 515463] [client 20.104.50.220:62829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/up.php5"] [unique_id "apPlZWZcVaai59truiVk5wAAAEk"]
[Sun Aug 30 03:10:13.379959 2026] [security2:error] [pid 512881:tid 513016] [client 20.48.251.3:64290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/ms-edit.php"] [unique_id "apPlZQi65Hcg2zUJjxB4ngAAAhk"]
[Sun Aug 30 03:10:13.383250 2026] [security2:error] [pid 512881:tid 513058] [client 20.63.81.20:31685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp-includes/Text/Diff/Engine/aaa.php"] [unique_id "apPlZQi65Hcg2zUJjxB4nwAAAkM"]
[Sun Aug 30 03:10:13.384270 2026] [security2:error] [pid 512881:tid 513105] [client 216.73.216.128:62743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/'+this.controller.state().get("] [unique_id "apPlZQi65Hcg2zUJjxB4oAAAAnI"]
[Sun Aug 30 03:10:13.388772 2026] [security2:error] [pid 512881:tid 513022] [client 158.23.147.79:60219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-admin/about.php"] [unique_id "apPlZQi65Hcg2zUJjxB4ogAAAh8"]
[Sun Aug 30 03:10:13.389859 2026] [security2:error] [pid 512881:tid 513102] [client 20.104.49.130:52159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/reviall.php"] [unique_id "apPlZQi65Hcg2zUJjxB4owAAAm8"]
[Sun Aug 30 03:10:13.401696 2026] [security2:error] [pid 512881:tid 513092] [client 20.104.49.130:57476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPlZQi65Hcg2zUJjxB4pgAAAmU"]
[Sun Aug 30 03:10:13.405433 2026] [authz_core:error] [pid 515259:tid 515500] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:13.405905 2026] [authz_core:error] [pid 515259:tid 515500] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:13.406141 2026] [security2:error] [pid 515259:tid 515462] [client 57.131.147.191:63528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.147.131.57.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rampd.co"] [uri "/wp-login.php"] [unique_id "apPlZWZcVaai59truiVk7AAAAEg"]
[Sun Aug 30 03:10:13.423588 2026] [security2:error] [pid 515259:tid 515452] [client 20.48.160.90:61400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/sallu.php"] [unique_id "apPlZWZcVaai59truiVk7QAAAD4"]
[Sun Aug 30 03:10:13.462236 2026] [authz_core:error] [pid 512881:tid 513042] [client 66.249.66.35:38375] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:13.462496 2026] [authz_core:error] [pid 512881:tid 513042] [client 66.249.66.35:38375] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:13.471859 2026] [security2:error] [pid 512881:tid 513072] [client 4.205.62.107:25894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/loxi-o.php"] [unique_id "apPlZQi65Hcg2zUJjxB4vQAAAlE"]
[Sun Aug 30 03:10:13.500085 2026] [security2:error] [pid 512881:tid 513088] [client 20.48.250.41:17382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/mar.php"] [unique_id "apPlZQi65Hcg2zUJjxB4xQAAAmE"]
[Sun Aug 30 03:10:13.501231 2026] [security2:error] [pid 512881:tid 513108] [client 158.23.147.79:10197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/log-mama/function.php"] [unique_id "apPlZQi65Hcg2zUJjxB4xwAAAnU"]
[Sun Aug 30 03:10:13.502695 2026] [security2:error] [pid 512881:tid 513045] [client 20.48.250.41:38674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/xr.php"] [unique_id "apPlZQi65Hcg2zUJjxB4yQAAAjY"]
[Sun Aug 30 03:10:13.514127 2026] [security2:error] [pid 512881:tid 513123] [client 20.63.81.20:31702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp-includes/style-engine/gecko-new.php"] [unique_id "apPlZQi65Hcg2zUJjxB4zwAAAoQ"]
[Sun Aug 30 03:10:13.552439 2026] [security2:error] [pid 512881:tid 513056] [client 20.104.49.130:52105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/pfm.php"] [unique_id "apPlZQi65Hcg2zUJjxB43AAAAkE"]
[Sun Aug 30 03:10:13.557601 2026] [security2:error] [pid 512881:tid 513112] [client 20.48.160.90:61344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/codex.php"] [unique_id "apPlZQi65Hcg2zUJjxB43wAAAnk"]
[Sun Aug 30 03:10:13.582234 2026] [security2:error] [pid 512881:tid 513086] [client 114.119.134.67:38965] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "stlacademy.org"] [uri "/stlsummer/"] [unique_id "apPlZQi65Hcg2zUJjxB46gAAAl8"], referer: https://stlacademy.org/stlsummer/
[Sun Aug 30 03:10:13.593592 2026] [security2:error] [pid 512881:tid 513019] [client 4.205.62.107:36704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/333.php"] [unique_id "apPlZQi65Hcg2zUJjxB48QAAAhw"]
[Sun Aug 30 03:10:13.626536 2026] [security2:error] [pid 512881:tid 513041] [client 68.155.159.216:63286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/goat.php"] [unique_id "apPlZQi65Hcg2zUJjxB4_AAAAjI"]
[Sun Aug 30 03:10:13.645943 2026] [security2:error] [pid 512881:tid 513106] [client 20.63.81.20:31736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp-settings.php"] [unique_id "apPlZQi65Hcg2zUJjxB5BQAAAnM"]
[Sun Aug 30 03:10:13.661883 2026] [security2:error] [pid 512881:tid 513016] [client 20.48.250.41:17358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/ccu.php"] [unique_id "apPlZQi65Hcg2zUJjxB5EgAAAhk"]
[Sun Aug 30 03:10:13.693037 2026] [security2:error] [pid 512881:tid 513084] [client 158.23.147.79:41594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/bk/index.php"] [unique_id "apPlZQi65Hcg2zUJjxB5LAAAAl0"]
[Sun Aug 30 03:10:13.694528 2026] [security2:error] [pid 515259:tid 515436] [client 20.151.200.44:28631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPlZWZcVaai59truiVlAwAAAC4"]
[Sun Aug 30 03:10:13.711190 2026] [security2:error] [pid 512881:tid 513016] [client 20.48.160.90:61381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/5656.php"] [unique_id "apPlZQi65Hcg2zUJjxB5OQAAAhk"]
[Sun Aug 30 03:10:13.747371 2026] [security2:error] [pid 512881:tid 513116] [client 20.104.49.130:64090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/albin.php"] [unique_id "apPlZQi65Hcg2zUJjxB5XAAAAn0"]
[Sun Aug 30 03:10:13.754607 2026] [security2:error] [pid 512881:tid 513050] [client 158.23.147.79:52225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apPlZQi65Hcg2zUJjxB5ZAAAAjs"]
[Sun Aug 30 03:10:13.779085 2026] [security2:error] [pid 512881:tid 513076] [client 20.63.81.20:31651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp-signup.php"] [unique_id "apPlZQi65Hcg2zUJjxB5bgAAAlU"]
[Sun Aug 30 03:10:13.779562 2026] [authz_core:error] [pid 512881:tid 513131] [client 66.249.66.66:48737] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:13.779895 2026] [authz_core:error] [pid 512881:tid 513131] [client 66.249.66.66:48737] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:13.795957 2026] [security2:error] [pid 512881:tid 513021] [client 20.48.250.41:17219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/ak.php"] [unique_id "apPlZQi65Hcg2zUJjxB5eAAAAh4"]
[Sun Aug 30 03:10:13.824203 2026] [security2:error] [pid 515259:tid 515401] [client 20.48.250.41:38749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/h02ugyh.php"] [unique_id "apPlZWZcVaai59truiVlEAAAAAs"]
[Sun Aug 30 03:10:13.836784 2026] [security2:error] [pid 512881:tid 513124] [client 158.23.147.79:41555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cwsennalmp.com"] [uri "/first.php"] [unique_id "apPlZQi65Hcg2zUJjxB5lgAAAoU"]
[Sun Aug 30 03:10:13.859836 2026] [security2:error] [pid 515259:tid 515399] [client 20.48.160.90:37531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/w3lls.php"] [unique_id "apPlZWZcVaai59truiVlGQAAAAk"]
[Sun Aug 30 03:10:13.901120 2026] [security2:error] [pid 512881:tid 513113] [client 158.23.147.79:43867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/simple.php"] [unique_id "apPlZQi65Hcg2zUJjxB5zgAAAno"]
[Sun Aug 30 03:10:13.905266 2026] [authz_core:error] [pid 515259:tid 515467] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:13.905715 2026] [authz_core:error] [pid 515259:tid 515467] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:13.910741 2026] [security2:error] [pid 512881:tid 513086] [client 20.104.50.220:16971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/admin.php"] [unique_id "apPlZQi65Hcg2zUJjxB51wAAAl8"]
[Sun Aug 30 03:10:13.917084 2026] [security2:error] [pid 512881:tid 513016] [client 20.63.81.20:31632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp-conffg.php"] [unique_id "apPlZQi65Hcg2zUJjxB52gAAAhk"]
[Sun Aug 30 03:10:13.917605 2026] [security2:error] [pid 512881:tid 513051] [client 20.104.18.15:64840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/bengi.php"] [unique_id "apPlZQi65Hcg2zUJjxB52wAAAjw"]
[Sun Aug 30 03:10:13.924756 2026] [security2:error] [pid 512881:tid 513133] [client 20.104.49.130:52127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/wp-login.php"] [unique_id "apPlZQi65Hcg2zUJjxB53AAAAo4"]
[Sun Aug 30 03:10:13.929487 2026] [security2:error] [pid 512881:tid 513013] [client 20.48.251.3:55762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/wp-blog.php"] [unique_id "apPlZQi65Hcg2zUJjxB53QAAAhY"]
[Sun Aug 30 03:10:13.934297 2026] [security2:error] [pid 512881:tid 513091] [client 4.205.62.107:17091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/sys.php"] [unique_id "apPlZQi65Hcg2zUJjxB54gAAAmQ"]
[Sun Aug 30 03:10:13.940751 2026] [security2:error] [pid 515259:tid 515501] [client 158.23.147.79:1866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-admin.php"] [unique_id "apPlZWZcVaai59truiVlIQAAAG8"]
[Sun Aug 30 03:10:13.975004 2026] [authz_core:error] [pid 512881:tid 513058] [client 66.249.66.77:39195] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:13.975344 2026] [authz_core:error] [pid 512881:tid 513058] [client 66.249.66.77:39195] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:13.986573 2026] [security2:error] [pid 515259:tid 515409] [client 20.48.251.3:59467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/phpsysinfo.php"] [unique_id "apPlZWZcVaai59truiVlLgAAABM"]
[Sun Aug 30 03:10:13.987607 2026] [security2:error] [pid 515259:tid 515454] [client 20.48.250.41:17293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/lib.php"] [unique_id "apPlZWZcVaai59truiVlMQAAAEA"]
[Sun Aug 30 03:10:14.003523 2026] [security2:error] [pid 515259:tid 515455] [client 20.48.160.90:61427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/fpwch.php"] [unique_id "apPlZmZcVaai59truiVlOAAAAEE"]
[Sun Aug 30 03:10:14.024575 2026] [security2:error] [pid 512881:tid 513085] [client 20.104.18.15:35789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/wp-admin/js/wp-load.php"] [unique_id "apPlZgi65Hcg2zUJjxB6GwAAAl4"]
[Sun Aug 30 03:10:14.046992 2026] [security2:error] [pid 515259:tid 515442] [client 20.104.18.15:16897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/chosen.php"] [unique_id "apPlZmZcVaai59truiVlPAAAADQ"]
[Sun Aug 30 03:10:14.053996 2026] [security2:error] [pid 515259:tid 515514] [client 20.104.50.220:51600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/Bulle.php"] [unique_id "apPlZmZcVaai59truiVlPgAAAHw"]
[Sun Aug 30 03:10:14.058793 2026] [security2:error] [pid 512881:tid 513132] [client 20.63.81.20:31647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp-validate.php"] [unique_id "apPlZgi65Hcg2zUJjxB6MAAAAo0"]
[Sun Aug 30 03:10:14.067948 2026] [security2:error] [pid 512881:tid 513083] [client 20.48.250.41:38818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/xxw.php"] [unique_id "apPlZgi65Hcg2zUJjxB6NQAAAlw"]
[Sun Aug 30 03:10:14.099069 2026] [authz_core:error] [pid 515259:tid 515417] [client 66.249.66.74:59272] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:14.099537 2026] [authz_core:error] [pid 515259:tid 515417] [client 66.249.66.74:59272] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:14.103988 2026] [security2:error] [pid 515259:tid 515429] [client 20.104.18.15:22405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/radio.php"] [unique_id "apPlZmZcVaai59truiVlSwAAACc"]
[Sun Aug 30 03:10:14.105235 2026] [security2:error] [pid 515259:tid 515421] [client 20.48.251.3:60532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/packed.php"] [unique_id "apPlZmZcVaai59truiVlTAAAAB8"]
[Sun Aug 30 03:10:14.113939 2026] [security2:error] [pid 515259:tid 515493] [client 20.104.49.130:52109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/ohct.php"] [unique_id "apPlZmZcVaai59truiVlUQAAAGc"]
[Sun Aug 30 03:10:14.135717 2026] [security2:error] [pid 515259:tid 515407] [client 20.48.160.90:63934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/domvf.php"] [unique_id "apPlZmZcVaai59truiVlVAAAABE"]
[Sun Aug 30 03:10:14.137300 2026] [security2:error] [pid 515259:tid 515391] [client 4.205.62.107:61699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/oc460l3x.php"] [unique_id "apPlZmZcVaai59truiVlVQAAAAE"]
[Sun Aug 30 03:10:14.154065 2026] [security2:error] [pid 512881:tid 513132] [client 158.23.147.79:43882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-admin/about.php"] [unique_id "apPlZgi65Hcg2zUJjxB6aAAAAo0"]
[Sun Aug 30 03:10:14.155038 2026] [security2:error] [pid 515259:tid 515469] [client 20.104.50.220:29153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/col1.php"] [unique_id "apPlZmZcVaai59truiVlWQAAAE8"]
[Sun Aug 30 03:10:14.167888 2026] [security2:error] [pid 512881:tid 513120] [client 20.48.250.41:17366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/wp-style.php"] [unique_id "apPlZgi65Hcg2zUJjxB6bgAAAoE"]
[Sun Aug 30 03:10:14.177518 2026] [security2:error] [pid 512881:tid 513012] [client 20.104.18.15:18427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/222.php"] [unique_id "apPlZgi65Hcg2zUJjxB6dgAAAhU"]
[Sun Aug 30 03:10:14.189396 2026] [security2:error] [pid 515259:tid 515471] [client 20.63.81.20:31719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/700.php"] [unique_id "apPlZmZcVaai59truiVlXgAAAFE"]
[Sun Aug 30 03:10:14.207759 2026] [security2:error] [pid 512881:tid 513036] [client 20.104.18.15:43289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/bo.php"] [unique_id "apPlZgi65Hcg2zUJjxB6fwAAAi0"]
[Sun Aug 30 03:10:14.229119 2026] [authz_core:error] [pid 515259:tid 515439] [client 66.249.66.37:60539] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:14.229563 2026] [authz_core:error] [pid 515259:tid 515439] [client 66.249.66.37:60539] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:14.236348 2026] [authz_core:error] [pid 515259:tid 515497] [client 66.249.66.75:54935] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:14.236819 2026] [authz_core:error] [pid 515259:tid 515497] [client 66.249.66.75:54935] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:14.261065 2026] [security2:error] [pid 515259:tid 515476] [client 20.48.250.41:38837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/bolt.php"] [unique_id "apPlZmZcVaai59truiVlagAAAFY"]
[Sun Aug 30 03:10:14.265940 2026] [security2:error] [pid 515259:tid 515462] [client 20.104.49.130:53637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/log.php"] [unique_id "apPlZmZcVaai59truiVlbAAAAEg"]
[Sun Aug 30 03:10:14.271891 2026] [security2:error] [pid 515259:tid 515498] [client 20.48.160.90:37569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/biufile.php"] [unique_id "apPlZmZcVaai59truiVlbQAAAGw"]
[Sun Aug 30 03:10:14.296962 2026] [security2:error] [pid 512881:tid 513046] [client 20.48.250.41:17295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/browse.php"] [unique_id "apPlZgi65Hcg2zUJjxB6mQAAAjc"]
[Sun Aug 30 03:10:14.298778 2026] [security2:error] [pid 512881:tid 513110] [client 20.104.50.220:61660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/minishell.php"] [unique_id "apPlZgi65Hcg2zUJjxB6nAAAAnc"]
[Sun Aug 30 03:10:14.302909 2026] [security2:error] [pid 512881:tid 513128] [client 20.104.50.220:59345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/tires.php"] [unique_id "apPlZgi65Hcg2zUJjxB6oAAAAok"]
[Sun Aug 30 03:10:14.327308 2026] [security2:error] [pid 512881:tid 513059] [client 20.63.81.20:31635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/c4.php"] [unique_id "apPlZgi65Hcg2zUJjxB6pQAAAkQ"]
[Sun Aug 30 03:10:14.328503 2026] [core:alert] [pid 512881:tid 513106] [client 37.111.148.35:32257] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:10:14.356292 2026] [security2:error] [pid 512881:tid 513033] [client 20.104.50.220:5603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/coba.php"] [unique_id "apPlZgi65Hcg2zUJjxB6sAAAAio"]
[Sun Aug 30 03:10:14.361460 2026] [authz_core:error] [pid 515259:tid 515412] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:14.361858 2026] [authz_core:error] [pid 515259:tid 515412] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:14.389774 2026] [security2:error] [pid 515259:tid 515418] [client 20.104.49.130:45759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/ws85.php"] [unique_id "apPlZmZcVaai59truiVldQAAABw"]
[Sun Aug 30 03:10:14.389973 2026] [security2:error] [pid 512881:tid 513066] [client 20.48.250.41:38808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/rtx.php"] [unique_id "apPlZgi65Hcg2zUJjxB6vQAAAks"]
[Sun Aug 30 03:10:14.396542 2026] [security2:error] [pid 512881:tid 513115] [client 20.104.49.130:52441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/222.php"] [unique_id "apPlZgi65Hcg2zUJjxB6vwAAAnw"]
[Sun Aug 30 03:10:14.413719 2026] [security2:error] [pid 512881:tid 513095] [client 20.48.160.90:37558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/blacks.php"] [unique_id "apPlZgi65Hcg2zUJjxB6wQAAAmg"]
[Sun Aug 30 03:10:14.430281 2026] [security2:error] [pid 512881:tid 513078] [client 20.48.250.41:17357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/zoo.php"] [unique_id "apPlZgi65Hcg2zUJjxB6xQAAAlc"]
[Sun Aug 30 03:10:14.430345 2026] [security2:error] [pid 512881:tid 513053] [client 158.23.147.79:52232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apPlZgi65Hcg2zUJjxB6xAAAAj4"]
[Sun Aug 30 03:10:14.431152 2026] [security2:error] [pid 512881:tid 513101] [client 68.155.159.216:54285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-content/admin.php"] [unique_id "apPlZgi65Hcg2zUJjxB6xgAAAm4"]
[Sun Aug 30 03:10:14.443778 2026] [security2:error] [pid 512881:tid 513085] [client 68.155.159.216:45958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/themes.php"] [unique_id "apPlZgi65Hcg2zUJjxB6zwAAAl4"]
[Sun Aug 30 03:10:14.457328 2026] [security2:error] [pid 512881:tid 513083] [client 20.63.81.20:31722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp-tymanage.php"] [unique_id "apPlZgi65Hcg2zUJjxB62gAAAlw"]
[Sun Aug 30 03:10:14.479748 2026] [security2:error] [pid 512881:tid 513087] [client 20.104.49.130:43322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/sta.php"] [unique_id "apPlZgi65Hcg2zUJjxB65AAAAmA"]
[Sun Aug 30 03:10:14.484742 2026] [security2:error] [pid 512881:tid 513094] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/.env.swp"] [unique_id "apPlZgi65Hcg2zUJjxB65QAAAmc"]
[Sun Aug 30 03:10:14.512900 2026] [security2:error] [pid 512881:tid 513016] [client 20.48.251.3:54788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/lmfi2.php"] [unique_id "apPlZgi65Hcg2zUJjxB67AAAAhk"]
[Sun Aug 30 03:10:14.534604 2026] [security2:error] [pid 512881:tid 513107] [client 20.48.250.41:38773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/ckk.php"] [unique_id "apPlZgi65Hcg2zUJjxB69QAAAnQ"]
[Sun Aug 30 03:10:14.544870 2026] [security2:error] [pid 512881:tid 513051] [client 20.48.160.90:63888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/beck.php"] [unique_id "apPlZgi65Hcg2zUJjxB6_gAAAjw"]
[Sun Aug 30 03:10:14.549161 2026] [security2:error] [pid 512881:tid 513113] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/.env~"] [unique_id "apPlZgi65Hcg2zUJjxB6_wAAAno"]
[Sun Aug 30 03:10:14.568009 2026] [security2:error] [pid 515259:tid 515457] [client 20.48.250.41:17400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/elp.php"] [unique_id "apPlZmZcVaai59truiVlfAAAAEM"]
[Sun Aug 30 03:10:14.571994 2026] [security2:error] [pid 512881:tid 513116] [client 20.104.50.220:29575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/shell.php5"] [unique_id "apPlZgi65Hcg2zUJjxB7CwAAAn0"]
[Sun Aug 30 03:10:14.596741 2026] [security2:error] [pid 512881:tid 513109] [client 20.63.81.20:31637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/ajfto.php"] [unique_id "apPlZgi65Hcg2zUJjxB7EAAAAnY"]
[Sun Aug 30 03:10:14.598573 2026] [security2:error] [pid 512881:tid 513100] [client 158.23.147.79:43846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apPlZgi65Hcg2zUJjxB7EgAAAm0"]
[Sun Aug 30 03:10:14.605308 2026] [authz_core:error] [pid 515259:tid 515503] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:14.605581 2026] [authz_core:error] [pid 515259:tid 515503] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:14.660039 2026] [authz_core:error] [pid 512881:tid 513133] [client 66.249.66.76:61035] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:14.660480 2026] [authz_core:error] [pid 512881:tid 513133] [client 66.249.66.76:61035] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:14.665097 2026] [security2:error] [pid 515259:tid 515496] [client 4.205.62.107:25498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/f35.php"] [unique_id "apPlZmZcVaai59truiVljAAAAGo"]
[Sun Aug 30 03:10:14.665963 2026] [authz_core:error] [pid 512881:tid 513115] [client 216.73.216.128:27257] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:14.666399 2026] [authz_core:error] [pid 512881:tid 513115] [client 216.73.216.128:27257] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:14.689918 2026] [security2:error] [pid 512881:tid 513130] [client 20.48.160.90:61379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/t3.php"] [unique_id "apPlZgi65Hcg2zUJjxB7RwAAAos"]
[Sun Aug 30 03:10:14.700196 2026] [security2:error] [pid 512881:tid 513021] [client 20.48.250.41:17287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/666.php"] [unique_id "apPlZgi65Hcg2zUJjxB7TQAAAh4"]
[Sun Aug 30 03:10:14.711376 2026] [security2:error] [pid 515259:tid 515434] [client 20.104.49.130:64115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/bdroot.php"] [unique_id "apPlZmZcVaai59truiVllwAAACw"]
[Sun Aug 30 03:10:14.717037 2026] [security2:error] [pid 512881:tid 513061] [client 158.23.147.79:43870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/chosen.php"] [unique_id "apPlZgi65Hcg2zUJjxB7WwAAAkY"]
[Sun Aug 30 03:10:14.725606 2026] [security2:error] [pid 512881:tid 513060] [client 20.63.81.20:31702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp_KwIW0U5F.php"] [unique_id "apPlZgi65Hcg2zUJjxB7YgAAAkU"]
[Sun Aug 30 03:10:14.733915 2026] [security2:error] [pid 512881:tid 513137] [client 68.155.159.216:63270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apPlZgi65Hcg2zUJjxB7bAAAApI"]
[Sun Aug 30 03:10:14.762511 2026] [security2:error] [pid 512881:tid 513042] [client 20.48.250.41:38720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.kennethdanford.com"] [uri "/R57.php"] [unique_id "apPlZgi65Hcg2zUJjxB7hQAAAjM"]
[Sun Aug 30 03:10:14.772737 2026] [security2:error] [pid 512881:tid 513128] [client 20.151.200.44:28649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/t00l.php"] [unique_id "apPlZgi65Hcg2zUJjxB7igAAAok"]
[Sun Aug 30 03:10:14.778443 2026] [security2:error] [pid 515259:tid 515452] [client 4.205.62.107:36685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/G-in.php"] [unique_id "apPlZmZcVaai59truiVloAAAAD4"]
[Sun Aug 30 03:10:14.810140 2026] [security2:error] [pid 515259:tid 515448] [client 20.104.49.130:36764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/read.php"] [unique_id "apPlZmZcVaai59truiVlpwAAADo"]
[Sun Aug 30 03:10:14.830221 2026] [security2:error] [pid 512881:tid 513025] [client 20.48.160.90:63882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/wp.php"] [unique_id "apPlZgi65Hcg2zUJjxB7rAAAAiI"]
[Sun Aug 30 03:10:14.835072 2026] [security2:error] [pid 512881:tid 513113] [client 20.48.250.41:17291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/knmt.php"] [unique_id "apPlZgi65Hcg2zUJjxB7sAAAAno"]
[Sun Aug 30 03:10:14.864215 2026] [security2:error] [pid 512881:tid 513052] [client 20.63.81.20:31710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp_xiPu52Ut.php"] [unique_id "apPlZgi65Hcg2zUJjxB7zQAAAj0"]
[Sun Aug 30 03:10:14.878348 2026] [security2:error] [pid 512881:tid 513015] [client 158.23.147.79:52251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/goods.php"] [unique_id "apPlZgi65Hcg2zUJjxB73gAAAhg"]
[Sun Aug 30 03:10:14.879517 2026] [authz_core:error] [pid 515259:tid 515500] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:14.879798 2026] [authz_core:error] [pid 515259:tid 515500] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:14.909929 2026] [security2:error] [pid 512881:tid 513071] [client 20.104.49.130:64089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/talkxkej.php"] [unique_id "apPlZgi65Hcg2zUJjxB79AAAAlA"]
[Sun Aug 30 03:10:14.936658 2026] [security2:error] [pid 512881:tid 513030] [client 216.73.216.128:2445] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/ourcollection_images/wp-admin/css/install.css"] [unique_id "apPlZgi65Hcg2zUJjxB7-gAAAic"]
[Sun Aug 30 03:10:14.960485 2026] [security2:error] [pid 512881:tid 513125] [client 20.48.160.90:37571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/abcd.php"] [unique_id "apPlZgi65Hcg2zUJjxB8DgAAAoY"]
[Sun Aug 30 03:10:14.964800 2026] [core:alert] [pid 512881:tid 513123] [client 45.143.29.112:44820] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:10:14.972712 2026] [security2:error] [pid 512881:tid 513126] [client 20.48.250.41:17389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/sbhu.php"] [unique_id "apPlZgi65Hcg2zUJjxB8HgAAAoc"]
[Sun Aug 30 03:10:14.978006 2026] [authz_core:error] [pid 515259:tid 515429] [client 66.249.66.68:44839] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:14.978473 2026] [authz_core:error] [pid 515259:tid 515429] [client 66.249.66.68:44839] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:14.995397 2026] [security2:error] [pid 512881:tid 513071] [client 20.63.81.20:31571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp_n5VD7XDh.php"] [unique_id "apPlZgi65Hcg2zUJjxB8MgAAAlA"]
[Sun Aug 30 03:10:15.049990 2026] [security2:error] [pid 512881:tid 513108] [client 20.104.50.220:16729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-admin/maint/maint.php"] [unique_id "apPlZwi65Hcg2zUJjxB8TgAAAnU"]
[Sun Aug 30 03:10:15.057450 2026] [security2:error] [pid 512881:tid 513015] [client 20.104.18.15:64861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/file2.php"] [unique_id "apPlZwi65Hcg2zUJjxB8VQAAAhg"]
[Sun Aug 30 03:10:15.065421 2026] [security2:error] [pid 512881:tid 513112] [client 20.48.251.3:59353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/erty.php"] [unique_id "apPlZwi65Hcg2zUJjxB8WQAAAnk"]
[Sun Aug 30 03:10:15.088543 2026] [security2:error] [pid 515259:tid 515431] [client 4.205.62.107:17343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/phpsysinfo.php"] [unique_id "apPlZ2ZcVaai59truiVl2wAAACk"]
[Sun Aug 30 03:10:15.102485 2026] [security2:error] [pid 512881:tid 513095] [client 20.48.250.41:17280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/a332.php"] [unique_id "apPlZwi65Hcg2zUJjxB8bgAAAmg"]
[Sun Aug 30 03:10:15.103729 2026] [security2:error] [pid 512881:tid 513047] [client 20.48.160.90:63938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/nofile.php"] [unique_id "apPlZwi65Hcg2zUJjxB8cwAAAjg"]
[Sun Aug 30 03:10:15.116400 2026] [security2:error] [pid 512881:tid 513077] [client 216.73.216.128:27257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlZwi65Hcg2zUJjxB8fQAAAlY"]
[Sun Aug 30 03:10:15.123627 2026] [security2:error] [pid 512881:tid 513041] [client 20.63.81.20:31554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp-mini.php"] [unique_id "apPlZwi65Hcg2zUJjxB8hAAAAjI"]
[Sun Aug 30 03:10:15.124187 2026] [security2:error] [pid 512881:tid 513104] [client 20.48.251.3:59887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/sgd.php"] [unique_id "apPlZwi65Hcg2zUJjxB8hQAAAnE"]
[Sun Aug 30 03:10:15.132361 2026] [security2:error] [pid 512881:tid 513079] [client 158.23.147.79:52230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apPlZwi65Hcg2zUJjxB8iAAAAlg"]
[Sun Aug 30 03:10:15.169300 2026] [security2:error] [pid 512881:tid 513040] [client 20.104.49.130:43287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/run.php"] [unique_id "apPlZwi65Hcg2zUJjxB8mQAAAjE"]
[Sun Aug 30 03:10:15.170547 2026] [security2:error] [pid 512881:tid 513121] [client 20.104.18.15:35018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/robot.php"] [unique_id "apPlZwi65Hcg2zUJjxB8mgAAAoI"]
[Sun Aug 30 03:10:15.190436 2026] [security2:error] [pid 512881:tid 513013] [client 20.104.18.15:16920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/file1221.php"] [unique_id "apPlZwi65Hcg2zUJjxB8pAAAAhY"]
[Sun Aug 30 03:10:15.195606 2026] [security2:error] [pid 512881:tid 513054] [client 20.104.50.220:51577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/srx.php"] [unique_id "apPlZwi65Hcg2zUJjxB8pwAAAj8"]
[Sun Aug 30 03:10:15.213488 2026] [authz_core:error] [pid 512881:tid 513033] [client 216.73.216.128:18440] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:15.213772 2026] [authz_core:error] [pid 512881:tid 513033] [client 216.73.216.128:18440] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:15.239086 2026] [authz_core:error] [pid 512881:tid 513086] [client 66.249.66.200:59584] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:15.239351 2026] [authz_core:error] [pid 512881:tid 513086] [client 66.249.66.200:59584] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:15.242962 2026] [security2:error] [pid 512881:tid 513106] [client 20.104.18.15:22461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/one.php"] [unique_id "apPlZwi65Hcg2zUJjxB8tgAAAnM"]
[Sun Aug 30 03:10:15.251818 2026] [security2:error] [pid 512881:tid 513111] [client 20.63.81.20:31627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/xmini4.php"] [unique_id "apPlZwi65Hcg2zUJjxB8vAAAAng"]
[Sun Aug 30 03:10:15.256956 2026] [security2:error] [pid 512881:tid 513038] [client 20.104.49.130:64712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/btyuio.php"] [unique_id "apPlZwi65Hcg2zUJjxB8vwAAAi8"]
[Sun Aug 30 03:10:15.261457 2026] [security2:error] [pid 512881:tid 513114] [client 20.48.250.41:17362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/ws66.php"] [unique_id "apPlZwi65Hcg2zUJjxB8wgAAAns"]
[Sun Aug 30 03:10:15.275634 2026] [security2:error] [pid 515259:tid 515455] [client 20.151.200.44:40955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/sf.php"] [unique_id "apPlZ2ZcVaai59truiVl7QAAAEE"]
[Sun Aug 30 03:10:15.275994 2026] [security2:error] [pid 512881:tid 513101] [client 20.48.160.90:61378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/run.php"] [unique_id "apPlZwi65Hcg2zUJjxB8yAAAAm4"]
[Sun Aug 30 03:10:15.293482 2026] [security2:error] [pid 512881:tid 513031] [client 20.104.50.220:29147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/coli.php"] [unique_id "apPlZwi65Hcg2zUJjxB8zwAAAig"]
[Sun Aug 30 03:10:15.293626 2026] [security2:error] [pid 512881:tid 513092] [client 20.48.251.3:14097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/wp-info.php"] [unique_id "apPlZwi65Hcg2zUJjxB8zgAAAmU"]
[Sun Aug 30 03:10:15.304773 2026] [authz_core:error] [pid 512881:tid 513012] [client 66.249.66.74:44019] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:15.305217 2026] [authz_core:error] [pid 512881:tid 513012] [client 66.249.66.74:44019] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:15.311972 2026] [security2:error] [pid 512881:tid 513064] [client 4.205.62.107:61708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/drykl.php"] [unique_id "apPlZwi65Hcg2zUJjxB82AAAAkk"]
[Sun Aug 30 03:10:15.329180 2026] [security2:error] [pid 515259:tid 515418] [client 20.104.18.15:18423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/key.php"] [unique_id "apPlZ2ZcVaai59truiVl7wAAABw"]
[Sun Aug 30 03:10:15.346188 2026] [security2:error] [pid 512881:tid 513083] [client 184.154.76.13:60826] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "dejulschoolofdance.com"] [uri "/wp-content/plugins/elementor/assets/css/widget-divider.min.css"] [unique_id "apPlZwi65Hcg2zUJjxB84QAAAlw"]
[Sun Aug 30 03:10:15.368832 2026] [security2:error] [pid 515259:tid 515491] [client 20.104.18.15:44009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/44.php"] [unique_id "apPlZ2ZcVaai59truiVl8AAAAGU"]
[Sun Aug 30 03:10:15.378204 2026] [authz_core:error] [pid 515259:tid 515480] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:15.378461 2026] [authz_core:error] [pid 515259:tid 515480] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:15.384548 2026] [security2:error] [pid 512881:tid 513090] [client 20.63.81.20:31735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/reop3.php"] [unique_id "apPlZwi65Hcg2zUJjxB85wAAAmM"]
[Sun Aug 30 03:10:15.392189 2026] [security2:error] [pid 515259:tid 515450] [client 20.104.49.130:53753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/srontol.php"] [unique_id "apPlZ2ZcVaai59truiVl9QAAADw"]
[Sun Aug 30 03:10:15.403499 2026] [security2:error] [pid 515259:tid 515460] [client 20.48.250.41:17356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/ws68.php"] [unique_id "apPlZ2ZcVaai59truiVl-QAAAEY"]
[Sun Aug 30 03:10:15.407995 2026] [security2:error] [pid 515259:tid 515442] [client 20.48.160.90:63927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/new.php"] [unique_id "apPlZ2ZcVaai59truiVl-wAAADQ"]
[Sun Aug 30 03:10:15.446574 2026] [security2:error] [pid 512881:tid 513057] [client 20.104.50.220:61453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/mrjn.php"] [unique_id "apPlZwi65Hcg2zUJjxB89QAAAkI"]
[Sun Aug 30 03:10:15.492022 2026] [security2:error] [pid 515259:tid 515473] [client 20.104.50.220:5558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/replace.php"] [unique_id "apPlZ2ZcVaai59truiVmEQAAAFM"]
[Sun Aug 30 03:10:15.523117 2026] [security2:error] [pid 512881:tid 513107] [client 20.63.81.20:31678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp-mail.php"] [unique_id "apPlZwi65Hcg2zUJjxB9CAAAAnQ"]
[Sun Aug 30 03:10:15.546487 2026] [security2:error] [pid 512881:tid 513127] [client 20.48.160.90:61428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/inx.php"] [unique_id "apPlZwi65Hcg2zUJjxB9DQAAAog"]
[Sun Aug 30 03:10:15.553186 2026] [security2:error] [pid 512881:tid 513031] [client 20.48.250.41:17397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/users.php"] [unique_id "apPlZwi65Hcg2zUJjxB9EAAAAig"]
[Sun Aug 30 03:10:15.555094 2026] [security2:error] [pid 512881:tid 513062] [client 68.155.159.216:46034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-mail.php"] [unique_id "apPlZwi65Hcg2zUJjxB9EQAAAkc"]
[Sun Aug 30 03:10:15.558461 2026] [security2:error] [pid 512881:tid 513015] [client 20.151.200.44:41876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/txets.php"] [unique_id "apPlZwi65Hcg2zUJjxB9EwAAAhg"]
[Sun Aug 30 03:10:15.570987 2026] [security2:error] [pid 515259:tid 515471] [client 20.104.50.220:31547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/.well-known/about.php"] [unique_id "apPlZ2ZcVaai59truiVmGwAAAFE"]
[Sun Aug 30 03:10:15.572415 2026] [security2:error] [pid 512881:tid 513121] [client 68.155.159.216:52577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/xmlrpc.php"] [unique_id "apPlZwi65Hcg2zUJjxB9HgAAAoI"]
[Sun Aug 30 03:10:15.586367 2026] [security2:error] [pid 512881:tid 513035] [client 20.104.49.130:64126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/static.php"] [unique_id "apPlZwi65Hcg2zUJjxB9KwAAAiw"]
[Sun Aug 30 03:10:15.657558 2026] [security2:error] [pid 512881:tid 513094] [client 20.48.251.3:65499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/wpver.php"] [unique_id "apPlZwi65Hcg2zUJjxB9SAAAAmc"]
[Sun Aug 30 03:10:15.666788 2026] [security2:error] [pid 512881:tid 513101] [client 20.63.81.20:31687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp-conffg.php"] [unique_id "apPlZwi65Hcg2zUJjxB9TwAAAm4"]
[Sun Aug 30 03:10:15.689669 2026] [security2:error] [pid 512881:tid 513085] [client 20.48.160.90:36930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/vpn.php"] [unique_id "apPlZwi65Hcg2zUJjxB9ZAAAAl4"]
[Sun Aug 30 03:10:15.693383 2026] [security2:error] [pid 512881:tid 513033] [client 20.48.250.41:17335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/bzjdlofz.php"] [unique_id "apPlZwi65Hcg2zUJjxB9aAAAAio"]
[Sun Aug 30 03:10:15.708765 2026] [security2:error] [pid 515259:tid 515412] [client 20.104.50.220:28703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/inc/config.php"] [unique_id "apPlZ2ZcVaai59truiVmMwAAABY"]
[Sun Aug 30 03:10:15.714066 2026] [authz_core:error] [pid 515259:tid 515450] [client 66.249.66.37:60539] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:15.714408 2026] [authz_core:error] [pid 515259:tid 515450] [client 66.249.66.37:60539] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:15.728526 2026] [security2:error] [pid 512881:tid 513096] [client 158.23.147.79:43880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apPlZwi65Hcg2zUJjxB9iwAAAmk"]
[Sun Aug 30 03:10:15.740505 2026] [security2:error] [pid 512881:tid 513069] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/app/.env"] [unique_id "apPlZwi65Hcg2zUJjxB9kwAAAk4"]
[Sun Aug 30 03:10:15.742658 2026] [security2:error] [pid 515259:tid 515394] [client 20.104.49.130:53595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/new.php"] [unique_id "apPlZ2ZcVaai59truiVmPAAAAAQ"]
[Sun Aug 30 03:10:15.777471 2026] [security2:error] [pid 512881:tid 513048] [client 20.151.200.44:40945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/4e.php"] [unique_id "apPlZwi65Hcg2zUJjxB9rQAAAjk"]
[Sun Aug 30 03:10:15.793127 2026] [security2:error] [pid 512881:tid 513077] [client 4.205.62.107:25477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/api.php"] [unique_id "apPlZwi65Hcg2zUJjxB9tgAAAlY"]
[Sun Aug 30 03:10:15.794404 2026] [security2:error] [pid 512881:tid 513082] [client 20.63.81.20:31706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/filefuns.php"] [unique_id "apPlZwi65Hcg2zUJjxB9twAAAls"]
[Sun Aug 30 03:10:15.801904 2026] [security2:error] [pid 512881:tid 513072] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/apps/.env"] [unique_id "apPlZwi65Hcg2zUJjxB9ugAAAlE"]
[Sun Aug 30 03:10:15.802160 2026] [security2:error] [pid 512881:tid 513086] [client 20.104.49.130:43318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/crgio.php"] [unique_id "apPlZwi65Hcg2zUJjxB9uwAAAl8"]
[Sun Aug 30 03:10:15.821918 2026] [security2:error] [pid 515259:tid 515443] [client 20.48.250.41:17396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/selesai.php"] [unique_id "apPlZ2ZcVaai59truiVmRgAAADU"]
[Sun Aug 30 03:10:15.825031 2026] [security2:error] [pid 512881:tid 513019] [client 20.48.160.90:61351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/shiny.php"] [unique_id "apPlZwi65Hcg2zUJjxB9xwAAAhw"]
[Sun Aug 30 03:10:15.856236 2026] [security2:error] [pid 512881:tid 513130] [client 68.155.159.216:63244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apPlZwi65Hcg2zUJjxB95gAAAos"]
[Sun Aug 30 03:10:15.865232 2026] [security2:error] [pid 512881:tid 513059] [client 158.23.147.79:56458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apPlZwi65Hcg2zUJjxB96wAAAkQ"]
[Sun Aug 30 03:10:15.866993 2026] [security2:error] [pid 512881:tid 513088] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/api/.env"] [unique_id "apPlZwi65Hcg2zUJjxB97gAAAmE"]
[Sun Aug 30 03:10:15.869762 2026] [security2:error] [pid 515259:tid 515464] [client 13.154.16.73:61424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.16.154.13.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "killmigraine.com"] [uri "/wp-login.php"] [unique_id "apPlZ2ZcVaai59truiVmQgAAAEo"], referer: http://killmigraine.com/wp-login.php?redirect_to=http%3A%2F%2Fkillmigraine.com%2Fyour-migraine%2Fthe-procedure%2F
[Sun Aug 30 03:10:15.873827 2026] [authz_core:error] [pid 515259:tid 515461] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:15.874311 2026] [authz_core:error] [pid 515259:tid 515461] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:15.923298 2026] [security2:error] [pid 515259:tid 515468] [client 20.63.81.20:31681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp-cron.php"] [unique_id "apPlZ2ZcVaai59truiVmVgAAAE4"]
[Sun Aug 30 03:10:15.926513 2026] [security2:error] [pid 515259:tid 515516] [client 20.104.49.130:60971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/media.php"] [unique_id "apPlZ2ZcVaai59truiVmVwAAAH4"]
[Sun Aug 30 03:10:15.938451 2026] [security2:error] [pid 512881:tid 513094] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/web/.env"] [unique_id "apPlZwi65Hcg2zUJjxB-GQAAAmc"]
[Sun Aug 30 03:10:15.956806 2026] [security2:error] [pid 515259:tid 515427] [client 20.48.160.90:63907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/goods.php"] [unique_id "apPlZ2ZcVaai59truiVmXgAAACU"]
[Sun Aug 30 03:10:15.965780 2026] [security2:error] [pid 512881:tid 513114] [client 4.205.62.107:36581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/apikeys.php"] [unique_id "apPlZwi65Hcg2zUJjxB-KwAAAns"]
[Sun Aug 30 03:10:15.992140 2026] [security2:error] [pid 512881:tid 513030] [client 20.48.250.41:17404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/shlo.php"] [unique_id "apPlZwi65Hcg2zUJjxB-QwAAAic"]
[Sun Aug 30 03:10:15.999299 2026] [security2:error] [pid 512881:tid 513107] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/site/.env"] [unique_id "apPlZwi65Hcg2zUJjxB-TQAAAnQ"]
[Sun Aug 30 03:10:16.003938 2026] [security2:error] [pid 512881:tid 513029] [client 20.104.49.130:64112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/reop3.php"] [unique_id "apPlaAi65Hcg2zUJjxB-TwAAAiY"]
[Sun Aug 30 03:10:16.007399 2026] [security2:error] [pid 512881:tid 513090] [client 20.104.49.130:60743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/ws85.php"] [unique_id "apPlaAi65Hcg2zUJjxB-UQAAAmM"]
[Sun Aug 30 03:10:16.030466 2026] [security2:error] [pid 512881:tid 513098] [client 216.73.216.128:59528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlaAi65Hcg2zUJjxB-WgAAAms"]
[Sun Aug 30 03:10:16.049272 2026] [security2:error] [pid 515259:tid 515483] [client 20.63.81.20:31633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/lock360.php"] [unique_id "apPlaGZcVaai59truiVmcwAAAF0"]
[Sun Aug 30 03:10:16.060454 2026] [security2:error] [pid 512881:tid 513095] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/public/.env"] [unique_id "apPlaAi65Hcg2zUJjxB-ZgAAAmg"]
[Sun Aug 30 03:10:16.073553 2026] [authz_core:error] [pid 512881:tid 513104] [client 66.249.66.38:59948] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:16.073861 2026] [authz_core:error] [pid 512881:tid 513104] [client 66.249.66.38:59948] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:16.100163 2026] [security2:error] [pid 512881:tid 513137] [client 20.48.160.90:61431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/alfa.php"] [unique_id "apPlaAi65Hcg2zUJjxB-gwAAApI"]
[Sun Aug 30 03:10:16.120827 2026] [authz_core:error] [pid 515259:tid 515417] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:16.121097 2026] [authz_core:error] [pid 515259:tid 515417] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:16.126203 2026] [authz_core:error] [pid 512881:tid 513119] [client 216.73.216.128:18440] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:16.126517 2026] [authz_core:error] [pid 512881:tid 513119] [client 216.73.216.128:18440] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:16.161836 2026] [security2:error] [pid 512881:tid 513071] [client 20.48.250.41:17373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/asax.php"] [unique_id "apPlaAi65Hcg2zUJjxB-qgAAAlA"]
[Sun Aug 30 03:10:16.169066 2026] [security2:error] [pid 512881:tid 513031] [client 158.23.147.79:60192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-content/uploads/index.php"] [unique_id "apPlaAi65Hcg2zUJjxB-rwAAAig"]
[Sun Aug 30 03:10:16.172245 2026] [security2:error] [pid 512881:tid 513116] [client 158.23.147.79:52265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/file.php"] [unique_id "apPlaAi65Hcg2zUJjxB-swAAAn0"]
[Sun Aug 30 03:10:16.185338 2026] [security2:error] [pid 512881:tid 513067] [client 20.63.81.20:31694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp-theme.php"] [unique_id "apPlaAi65Hcg2zUJjxB-vAAAAkw"]
[Sun Aug 30 03:10:16.187873 2026] [security2:error] [pid 512881:tid 513109] [client 20.104.50.220:16623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/classwithtostring.php"] [unique_id "apPlaAi65Hcg2zUJjxB-vgAAAnY"]
[Sun Aug 30 03:10:16.204126 2026] [security2:error] [pid 512881:tid 513029] [client 20.48.251.3:59329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/wp-config.backup.php"] [unique_id "apPlaAi65Hcg2zUJjxB-wQAAAiY"]
[Sun Aug 30 03:10:16.205672 2026] [security2:error] [pid 512881:tid 513051] [client 20.104.18.15:64862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/gm.php"] [unique_id "apPlaAi65Hcg2zUJjxB-wgAAAjw"]
[Sun Aug 30 03:10:16.223093 2026] [authz_core:error] [pid 512881:tid 513047] [client 216.73.216.128:2445] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:16.223580 2026] [authz_core:error] [pid 512881:tid 513047] [client 216.73.216.128:2445] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:16.235653 2026] [security2:error] [pid 512881:tid 513015] [client 4.205.62.107:17287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/sgd.php"] [unique_id "apPlaAi65Hcg2zUJjxB-0AAAAhg"]
[Sun Aug 30 03:10:16.236007 2026] [authz_core:error] [pid 512881:tid 513064] [client 66.249.66.78:48525] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:16.236284 2026] [authz_core:error] [pid 512881:tid 513064] [client 66.249.66.78:48525] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:16.248984 2026] [security2:error] [pid 512881:tid 513045] [client 20.48.160.90:37597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/33.php"] [unique_id "apPlaAi65Hcg2zUJjxB-2AAAAjY"]
[Sun Aug 30 03:10:16.255046 2026] [security2:error] [pid 512881:tid 513055] [client 20.48.251.3:52183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/fleen.php"] [unique_id "apPlaAi65Hcg2zUJjxB-3AAAAkA"]
[Sun Aug 30 03:10:16.259907 2026] [security2:error] [pid 512881:tid 513106] [client 20.104.49.130:64064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/f35.update.php"] [unique_id "apPlaAi65Hcg2zUJjxB-3gAAAnM"]
[Sun Aug 30 03:10:16.289436 2026] [security2:error] [pid 512881:tid 513125] [client 20.48.250.41:17289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/fetch.php"] [unique_id "apPlaAi65Hcg2zUJjxB-6gAAAoY"]
[Sun Aug 30 03:10:16.313313 2026] [security2:error] [pid 512881:tid 513034] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/backend/.env"] [unique_id "apPlaAi65Hcg2zUJjxB-8AAAAis"]
[Sun Aug 30 03:10:16.316530 2026] [security2:error] [pid 512881:tid 513088] [client 20.104.18.15:35065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/revo.php"] [unique_id "apPlaAi65Hcg2zUJjxB-8QAAAmE"]
[Sun Aug 30 03:10:16.320046 2026] [security2:error] [pid 515259:tid 515464] [client 20.104.50.220:32878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-raze.php"] [unique_id "apPlaGZcVaai59truiVmjAAAAEo"]
[Sun Aug 30 03:10:16.320678 2026] [security2:error] [pid 512881:tid 513120] [client 20.63.81.20:31666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/2d7433/index.php"] [unique_id "apPlaAi65Hcg2zUJjxB-9wAAAoE"]
[Sun Aug 30 03:10:16.323850 2026] [security2:error] [pid 512881:tid 513057] [client 20.104.18.15:64729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/nox.php"] [unique_id "apPlaAi65Hcg2zUJjxB--gAAAkI"]
[Sun Aug 30 03:10:16.333415 2026] [security2:error] [pid 512881:tid 513078] [client 20.104.50.220:51544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-content/plugins/owfsmac/mar.php"] [unique_id "apPlaAi65Hcg2zUJjxB-_AAAAlc"]
[Sun Aug 30 03:10:16.384801 2026] [security2:error] [pid 512881:tid 513061] [client 20.48.160.90:63939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/133.php"] [unique_id "apPlaAi65Hcg2zUJjxB_BQAAAkY"]
[Sun Aug 30 03:10:16.387843 2026] [security2:error] [pid 512881:tid 513060] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/server/.env"] [unique_id "apPlaAi65Hcg2zUJjxB_BgAAAkU"]
[Sun Aug 30 03:10:16.394881 2026] [authz_core:error] [pid 515259:tid 515400] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:16.395165 2026] [authz_core:error] [pid 515259:tid 515400] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:16.398691 2026] [security2:error] [pid 515259:tid 515466] [client 20.104.18.15:22490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/503.php"] [unique_id "apPlaGZcVaai59truiVmkgAAAEw"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:10:16.424601 2026] [security2:error] [pid 512881:tid 513091] [client 20.48.251.3:13408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/fns.php"] [unique_id "apPlaAi65Hcg2zUJjxB_DQAAAmQ"]
[Sun Aug 30 03:10:16.431412 2026] [security2:error] [pid 512881:tid 513045] [client 158.23.147.79:52237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/file17.php"] [unique_id "apPlaAi65Hcg2zUJjxB_EAAAAjY"]
[Sun Aug 30 03:10:16.434365 2026] [security2:error] [pid 515259:tid 515473] [client 20.48.250.41:17398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/vx.php"] [unique_id "apPlaGZcVaai59truiVmlgAAAFM"]
[Sun Aug 30 03:10:16.440790 2026] [security2:error] [pid 512881:tid 513098] [client 20.104.50.220:29317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/cylul.php"] [unique_id "apPlaAi65Hcg2zUJjxB_FgAAAms"]
[Sun Aug 30 03:10:16.441037 2026] [security2:error] [pid 512881:tid 513069] [client 20.104.49.130:43294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/wp.php"] [unique_id "apPlaAi65Hcg2zUJjxB_FwAAAk4"]
[Sun Aug 30 03:10:16.450627 2026] [security2:error] [pid 512881:tid 513084] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/frontend/.env"] [unique_id "apPlaAi65Hcg2zUJjxB_HQAAAl0"]
[Sun Aug 30 03:10:16.450790 2026] [security2:error] [pid 512881:tid 513106] [client 20.63.81.20:31625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp-login.php"] [unique_id "apPlaAi65Hcg2zUJjxB_HgAAAnM"]
[Sun Aug 30 03:10:16.480157 2026] [security2:error] [pid 512881:tid 513049] [client 20.104.18.15:18414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/chosen.php"] [unique_id "apPlaAi65Hcg2zUJjxB_LAAAAjo"]
[Sun Aug 30 03:10:16.506680 2026] [security2:error] [pid 512881:tid 513019] [client 4.205.62.107:61790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/rpk.php"] [unique_id "apPlaAi65Hcg2zUJjxB_NQAAAhw"]
[Sun Aug 30 03:10:16.513759 2026] [authz_core:error] [pid 512881:tid 513066] [client 216.73.216.128:2445] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:16.514231 2026] [authz_core:error] [pid 512881:tid 513066] [client 216.73.216.128:2445] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:16.517229 2026] [security2:error] [pid 512881:tid 513051] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/src/.env"] [unique_id "apPlaAi65Hcg2zUJjxB_NwAAAjw"]
[Sun Aug 30 03:10:16.517241 2026] [security2:error] [pid 512881:tid 513013] [client 20.104.18.15:43967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/h2.php"] [unique_id "apPlaAi65Hcg2zUJjxB_OQAAAhY"]
[Sun Aug 30 03:10:16.523315 2026] [security2:error] [pid 512881:tid 513020] [client 20.104.49.130:53649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/term.php"] [unique_id "apPlaAi65Hcg2zUJjxB_PAAAAh0"]
[Sun Aug 30 03:10:16.549004 2026] [security2:error] [pid 515259:tid 515444] [client 20.48.160.90:61395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/sym.php"] [unique_id "apPlaGZcVaai59truiVmnQAAADY"]
[Sun Aug 30 03:10:16.563663 2026] [authz_core:error] [pid 515259:tid 515401] [client 66.249.66.43:37637] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:16.563935 2026] [authz_core:error] [pid 515259:tid 515401] [client 66.249.66.43:37637] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:16.578441 2026] [security2:error] [pid 512881:tid 513052] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/core/.env"] [unique_id "apPlaAi65Hcg2zUJjxB_TQAAAj0"]
[Sun Aug 30 03:10:16.588490 2026] [security2:error] [pid 512881:tid 513087] [client 20.63.81.20:31620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/images.php"] [unique_id "apPlaAi65Hcg2zUJjxB_VAAAAmA"]
[Sun Aug 30 03:10:16.603478 2026] [security2:error] [pid 512881:tid 513125] [client 20.48.250.41:17300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/global.php"] [unique_id "apPlaAi65Hcg2zUJjxB_XgAAAoY"]
[Sun Aug 30 03:10:16.632779 2026] [security2:error] [pid 512881:tid 513042] [client 20.104.50.220:61435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/ninja.php"] [unique_id "apPlaAi65Hcg2zUJjxB_cwAAAjM"]
[Sun Aug 30 03:10:16.638138 2026] [security2:error] [pid 512881:tid 513056] [client 20.104.50.220:6096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/echo.php"] [unique_id "apPlaAi65Hcg2zUJjxB_dgAAAkE"]
[Sun Aug 30 03:10:16.640605 2026] [security2:error] [pid 512881:tid 513051] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/core/app/.env"] [unique_id "apPlaAi65Hcg2zUJjxB_dwAAAjw"]
[Sun Aug 30 03:10:16.645758 2026] [security2:error] [pid 512881:tid 513054] [client 20.104.49.130:54186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/1xmomo.php"] [unique_id "apPlaAi65Hcg2zUJjxB_fQAAAj8"]
[Sun Aug 30 03:10:16.673828 2026] [security2:error] [pid 512881:tid 513132] [client 68.155.159.216:46054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/cgi-bin/index.php"] [unique_id "apPlaAi65Hcg2zUJjxB_mgAAAo0"]
[Sun Aug 30 03:10:16.686179 2026] [security2:error] [pid 512881:tid 513101] [client 20.48.160.90:61426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/8.php"] [unique_id "apPlaAi65Hcg2zUJjxB_pwAAAm4"]
[Sun Aug 30 03:10:16.687284 2026] [security2:error] [pid 512881:tid 513091] [client 20.151.200.44:28488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/ls.php"] [unique_id "apPlaAi65Hcg2zUJjxB_qQAAAmQ"]
[Sun Aug 30 03:10:16.704481 2026] [security2:error] [pid 515259:tid 515513] [client 68.155.159.216:52224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/atomlib.php"] [unique_id "apPlaGZcVaai59truiVmrwAAAHs"]
[Sun Aug 30 03:10:16.704890 2026] [security2:error] [pid 512881:tid 513057] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/config/.env"] [unique_id "apPlaAi65Hcg2zUJjxB_tQAAAkI"]
[Sun Aug 30 03:10:16.727181 2026] [security2:error] [pid 512881:tid 513135] [client 20.104.50.220:59721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "apPlaAi65Hcg2zUJjxB_xgAAApA"]
[Sun Aug 30 03:10:16.745193 2026] [security2:error] [pid 512881:tid 513126] [client 20.63.81.20:31716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/ops.php"] [unique_id "apPlaAi65Hcg2zUJjxB_2wAAAoc"]
[Sun Aug 30 03:10:16.749623 2026] [security2:error] [pid 512881:tid 513084] [client 20.48.250.41:17216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/fs.php"] [unique_id "apPlaAi65Hcg2zUJjxB_3gAAAl0"]
[Sun Aug 30 03:10:16.754526 2026] [security2:error] [pid 512881:tid 513091] [client 20.151.200.44:40959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/ssss.php"] [unique_id "apPlaAi65Hcg2zUJjxB_4wAAAmQ"]
[Sun Aug 30 03:10:16.772376 2026] [security2:error] [pid 512881:tid 513056] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/private/.env"] [unique_id "apPlaAi65Hcg2zUJjxB_7gAAAkE"]
[Sun Aug 30 03:10:16.793195 2026] [security2:error] [pid 512881:tid 513135] [client 20.104.49.130:52131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/sd.php"] [unique_id "apPlaAi65Hcg2zUJjxB__QAAApA"]
[Sun Aug 30 03:10:16.810714 2026] [security2:error] [pid 515259:tid 515467] [client 20.48.251.3:64301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/ah25.php"] [unique_id "apPlaGZcVaai59truiVmvwAAAE0"]
[Sun Aug 30 03:10:16.816500 2026] [security2:error] [pid 512881:tid 513070] [client 20.48.160.90:63946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/goods.php"] [unique_id "apPlaAi65Hcg2zUJjxCACAAAAk8"]
[Sun Aug 30 03:10:16.819632 2026] [security2:error] [pid 512881:tid 513107] [client 20.104.49.130:48001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/memberfuns.php"] [unique_id "apPlaAi65Hcg2zUJjxCADAAAAnQ"]
[Sun Aug 30 03:10:16.832715 2026] [security2:error] [pid 512881:tid 513132] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/application/.env"] [unique_id "apPlaAi65Hcg2zUJjxCAEQAAAo0"]
[Sun Aug 30 03:10:16.855322 2026] [security2:error] [pid 515259:tid 515511] [client 158.23.147.79:58389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apPlaGZcVaai59truiVmygAAAHk"]
[Sun Aug 30 03:10:16.858361 2026] [security2:error] [pid 515259:tid 515435] [client 158.23.147.79:52276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/file5.php"] [unique_id "apPlaGZcVaai59truiVmzQAAAC0"]
[Sun Aug 30 03:10:16.859392 2026] [security2:error] [pid 512881:tid 512904] [remote 172.70.19.4:1261] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bcwinetrends.com"] [uri "/"] [unique_id "apPlaAi65Hcg2zUJjxCAKgACcxY"]
[Sun Aug 30 03:10:16.873338 2026] [security2:error] [pid 512881:tid 513039] [client 20.63.81.20:31741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPlaAi65Hcg2zUJjxCAOgAAAjA"]
[Sun Aug 30 03:10:16.878889 2026] [authz_core:error] [pid 515259:tid 515500] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:16.879229 2026] [authz_core:error] [pid 515259:tid 515500] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:16.882155 2026] [security2:error] [pid 512881:tid 513049] [client 20.48.250.41:17352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/ioxi.php"] [unique_id "apPlaAi65Hcg2zUJjxCAQQAAAjo"]
[Sun Aug 30 03:10:16.895377 2026] [security2:error] [pid 512881:tid 513100] [client 20.104.50.220:62842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/ix.php"] [unique_id "apPlaAi65Hcg2zUJjxCASwAAAm0"]
[Sun Aug 30 03:10:16.917923 2026] [security2:error] [pid 512881:tid 513122] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/bootstrap/.env"] [unique_id "apPlaAi65Hcg2zUJjxCAWwAAAoM"]
[Sun Aug 30 03:10:16.968333 2026] [authz_core:error] [pid 512881:tid 513075] [client 66.249.66.202:63590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:16.968772 2026] [authz_core:error] [pid 512881:tid 513075] [client 66.249.66.202:63590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:16.973111 2026] [authz_core:error] [pid 512881:tid 513120] [client 216.73.216.128:18440] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:16.973431 2026] [authz_core:error] [pid 512881:tid 513120] [client 216.73.216.128:18440] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:16.977076 2026] [security2:error] [pid 512881:tid 513099] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/database/.env"] [unique_id "apPlaAi65Hcg2zUJjxCAegAAAmw"]
[Sun Aug 30 03:10:16.979701 2026] [security2:error] [pid 512881:tid 513110] [client 4.205.62.107:25503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/temp.php"] [unique_id "apPlaAi65Hcg2zUJjxCAfgAAAnc"]
[Sun Aug 30 03:10:16.980189 2026] [security2:error] [pid 512881:tid 513045] [client 20.48.160.90:63974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/ah.php"] [unique_id "apPlaAi65Hcg2zUJjxCAfwAAAjY"]
[Sun Aug 30 03:10:16.980971 2026] [security2:error] [pid 512881:tid 513118] [client 68.155.159.216:63252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apPlaAi65Hcg2zUJjxCAggAAAn8"]
[Sun Aug 30 03:10:17.006783 2026] [security2:error] [pid 512881:tid 513084] [client 20.63.81.20:31721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPlaQi65Hcg2zUJjxCAnAAAAl0"]
[Sun Aug 30 03:10:17.020704 2026] [security2:error] [pid 512881:tid 513088] [client 20.104.49.130:53715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/wp-blog-header.php"] [unique_id "apPlaQi65Hcg2zUJjxCAowAAAmE"]
[Sun Aug 30 03:10:17.036860 2026] [security2:error] [pid 512881:tid 513046] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/storage/.env"] [unique_id "apPlaQi65Hcg2zUJjxCAqQAAAjc"]
[Sun Aug 30 03:10:17.067737 2026] [security2:error] [pid 512881:tid 513078] [client 20.48.250.41:17319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/bootstrap.php"] [unique_id "apPlaQi65Hcg2zUJjxCAsgAAAlc"]
[Sun Aug 30 03:10:17.086887 2026] [security2:error] [pid 512881:tid 512897] [remote 192.250.232.93:49130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.232.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftballs.com"] [uri "/wp-login.php"] [unique_id "apPlaQi65Hcg2zUJjxCAtQACHg8"]
[Sun Aug 30 03:10:17.096428 2026] [security2:error] [pid 512881:tid 513071] [client 4.205.62.107:36564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/motu.php"] [unique_id "apPlaQi65Hcg2zUJjxCAxAAAAlA"]
[Sun Aug 30 03:10:17.099842 2026] [security2:error] [pid 512881:tid 513101] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/var/www/.env"] [unique_id "apPlaQi65Hcg2zUJjxCAyAAAAm4"]
[Sun Aug 30 03:10:17.106418 2026] [security2:error] [pid 515259:tid 515453] [client 20.104.49.130:36746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/reviall.php"] [unique_id "apPlaWZcVaai59truiVm_wAAAD8"]
[Sun Aug 30 03:10:17.132672 2026] [security2:error] [pid 512881:tid 513106] [client 20.63.81.20:31704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/about.php"] [unique_id "apPlaQi65Hcg2zUJjxCA4QAAAnM"]
[Sun Aug 30 03:10:17.148417 2026] [authz_core:error] [pid 512881:tid 513076] [client 66.249.66.70:38388] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:17.148713 2026] [authz_core:error] [pid 512881:tid 513076] [client 66.249.66.70:38388] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:17.159972 2026] [security2:error] [pid 512881:tid 513045] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/var/www/html/.env"] [unique_id "apPlaQi65Hcg2zUJjxCA8wAAAjY"]
[Sun Aug 30 03:10:17.191062 2026] [security2:error] [pid 515259:tid 515407] [client 20.48.160.90:63959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/ws55.php"] [unique_id "apPlaWZcVaai59truiVnCQAAABE"]
[Sun Aug 30 03:10:17.205442 2026] [security2:error] [pid 512881:tid 513067] [client 20.48.250.41:17288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/export.php"] [unique_id "apPlaQi65Hcg2zUJjxCBDQAAAkw"]
[Sun Aug 30 03:10:17.221074 2026] [security2:error] [pid 512881:tid 513051] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/current/.env"] [unique_id "apPlaQi65Hcg2zUJjxCBDwAAAjw"]
[Sun Aug 30 03:10:17.230752 2026] [security2:error] [pid 512881:tid 513113] [client 158.23.147.79:52226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/file88.php"] [unique_id "apPlaQi65Hcg2zUJjxCBEAAAAno"]
[Sun Aug 30 03:10:17.232433 2026] [security2:error] [pid 512881:tid 513017] [client 158.23.147.79:60194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/chosen.php"] [unique_id "apPlaQi65Hcg2zUJjxCBEgAAAho"]
[Sun Aug 30 03:10:17.256812 2026] [core:alert] [pid 512881:tid 513130] [client 47.79.13.63:48822] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:10:17.260040 2026] [security2:error] [pid 512881:tid 513034] [client 20.104.49.130:43285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/dragonshell.php"] [unique_id "apPlaQi65Hcg2zUJjxCBIwAAAis"]
[Sun Aug 30 03:10:17.265740 2026] [security2:error] [pid 512881:tid 513063] [client 20.63.81.20:31616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/admin.php/admin.php"] [unique_id "apPlaQi65Hcg2zUJjxCBKAAAAkg"]
[Sun Aug 30 03:10:17.275509 2026] [security2:error] [pid 512881:tid 513018] [client 158.23.147.79:57673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/lock.php"] [unique_id "apPlaQi65Hcg2zUJjxCBMAAAAhs"]
[Sun Aug 30 03:10:17.298954 2026] [security2:error] [pid 512881:tid 513057] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/release/.env"] [unique_id "apPlaQi65Hcg2zUJjxCBNgAAAkI"]
[Sun Aug 30 03:10:17.329361 2026] [security2:error] [pid 512881:tid 513079] [client 20.104.50.220:16579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/abcd.php"] [unique_id "apPlaQi65Hcg2zUJjxCBPgAAAlg"]
[Sun Aug 30 03:10:17.333132 2026] [security2:error] [pid 512881:tid 513027] [client 20.48.250.41:17283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/gk.php"] [unique_id "apPlaQi65Hcg2zUJjxCBQAAAAiQ"]
[Sun Aug 30 03:10:17.342041 2026] [security2:error] [pid 512881:tid 513115] [client 20.48.251.3:52839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/edit.php"] [unique_id "apPlaQi65Hcg2zUJjxCBRAAAAnw"]
[Sun Aug 30 03:10:17.345077 2026] [security2:error] [pid 512881:tid 513038] [client 20.104.18.15:64837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/ws55.php"] [unique_id "apPlaQi65Hcg2zUJjxCBRgAAAi8"]
[Sun Aug 30 03:10:17.351312 2026] [authz_core:error] [pid 512881:tid 513059] [client 66.249.66.36:39161] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:17.351574 2026] [authz_core:error] [pid 512881:tid 513059] [client 66.249.66.36:39161] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:17.357788 2026] [security2:error] [pid 512881:tid 513138] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/releases/.env"] [unique_id "apPlaQi65Hcg2zUJjxCBSgAAApM"]
[Sun Aug 30 03:10:17.364848 2026] [security2:error] [pid 512881:tid 513105] [client 4.205.62.107:17311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/fleen.php"] [unique_id "apPlaQi65Hcg2zUJjxCBSwAAAnI"]
[Sun Aug 30 03:10:17.370716 2026] [authz_core:error] [pid 515259:tid 515404] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:17.371173 2026] [authz_core:error] [pid 515259:tid 515404] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:17.396316 2026] [security2:error] [pid 512881:tid 513109] [client 20.48.160.90:61331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/drykl.php"] [unique_id "apPlaQi65Hcg2zUJjxCBTwAAAnY"]
[Sun Aug 30 03:10:17.397009 2026] [security2:error] [pid 512881:tid 513119] [client 20.63.81.20:31646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/media.php"] [unique_id "apPlaQi65Hcg2zUJjxCBUAAAAoA"]
[Sun Aug 30 03:10:17.399991 2026] [security2:error] [pid 512881:tid 513017] [client 20.48.251.3:59842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/upload.form.php"] [unique_id "apPlaQi65Hcg2zUJjxCBUwAAAho"]
[Sun Aug 30 03:10:17.418268 2026] [security2:error] [pid 512881:tid 513083] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/shared/.env"] [unique_id "apPlaQi65Hcg2zUJjxCBWQAAAlw"]
[Sun Aug 30 03:10:17.418355 2026] [security2:error] [pid 512881:tid 513026] [client 20.104.49.130:26657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/xa.php"] [unique_id "apPlaQi65Hcg2zUJjxCBWgAAAiM"]
[Sun Aug 30 03:10:17.434820 2026] [security2:error] [pid 512881:tid 513092] [client 158.23.147.79:43871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/NewFile.php/"] [unique_id "apPlaQi65Hcg2zUJjxCBYgAAAmU"]
[Sun Aug 30 03:10:17.441309 2026] [security2:error] [pid 512881:tid 513044] [client 20.104.49.130:52110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/wp-blogs.php"] [unique_id "apPlaQi65Hcg2zUJjxCBZQAAAjU"]
[Sun Aug 30 03:10:17.466548 2026] [security2:error] [pid 512881:tid 513012] [client 20.104.50.220:33077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-init.php"] [unique_id "apPlaQi65Hcg2zUJjxCBcQAAAhU"]
[Sun Aug 30 03:10:17.468721 2026] [security2:error] [pid 512881:tid 513058] [client 20.104.18.15:16970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/akismet.php"] [unique_id "apPlaQi65Hcg2zUJjxCBcgAAAkM"]
[Sun Aug 30 03:10:17.479399 2026] [security2:error] [pid 512881:tid 513117] [client 20.104.18.15:35832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/birrs.php"] [unique_id "apPlaQi65Hcg2zUJjxCBdAAAAn4"]
[Sun Aug 30 03:10:17.482069 2026] [security2:error] [pid 512881:tid 513091] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/deploy/.env"] [unique_id "apPlaQi65Hcg2zUJjxCBdgAAAmQ"]
[Sun Aug 30 03:10:17.485211 2026] [security2:error] [pid 512881:tid 513024] [client 20.104.50.220:63520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/tersembunyi.php"] [unique_id "apPlaQi65Hcg2zUJjxCBdwAAAiE"]
[Sun Aug 30 03:10:17.490284 2026] [security2:error] [pid 512881:tid 513128] [client 20.48.250.41:17294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/logs1.php"] [unique_id "apPlaQi65Hcg2zUJjxCBeQAAAok"]
[Sun Aug 30 03:10:17.511704 2026] [authz_core:error] [pid 512881:tid 513062] [client 66.249.66.77:39195] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:17.512229 2026] [authz_core:error] [pid 512881:tid 513062] [client 66.249.66.77:39195] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:17.513443 2026] [autoindex:error] [pid 512881:tid 513121] [client 32.197.93.224:0] AH01276: Cannot serve directory /home3/ucdsscom/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:10:17.529905 2026] [security2:error] [pid 515259:tid 515480] [client 20.63.81.20:31686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/mac.php"] [unique_id "apPlaWZcVaai59truiVnHQAAAFo"]
[Sun Aug 30 03:10:17.544278 2026] [security2:error] [pid 512881:tid 513047] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/build/.env"] [unique_id "apPlaQi65Hcg2zUJjxCBjQAAAjg"]
[Sun Aug 30 03:10:17.560046 2026] [security2:error] [pid 512881:tid 513016] [client 20.48.160.90:63967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/backup.php"] [unique_id "apPlaQi65Hcg2zUJjxCBkgAAAhk"]
[Sun Aug 30 03:10:17.564983 2026] [security2:error] [pid 512881:tid 513092] [client 20.104.18.15:22467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/504.php"] [unique_id "apPlaQi65Hcg2zUJjxCBlAAAAmU"]
[Sun Aug 30 03:10:17.574168 2026] [authz_core:error] [pid 512881:tid 513050] [client 66.249.66.42:52553] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:17.574457 2026] [authz_core:error] [pid 512881:tid 513050] [client 66.249.66.42:52553] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:17.578025 2026] [security2:error] [pid 512881:tid 513078] [client 20.48.251.3:14087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/params.php"] [unique_id "apPlaQi65Hcg2zUJjxCBnAAAAlc"]
[Sun Aug 30 03:10:17.584160 2026] [authz_core:error] [pid 515259:tid 515402] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:17.584473 2026] [authz_core:error] [pid 515259:tid 515402] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:17.586250 2026] [security2:error] [pid 512881:tid 513053] [client 20.104.50.220:28688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/Cylul007.php"] [unique_id "apPlaQi65Hcg2zUJjxCBoQAAAj4"]
[Sun Aug 30 03:10:17.608053 2026] [security2:error] [pid 512881:tid 513115] [client 216.73.216.128:64043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mysqlupgrade"] [unique_id "apPlaQi65Hcg2zUJjxCBrwAAAnw"]
[Sun Aug 30 03:10:17.615207 2026] [security2:error] [pid 515259:tid 515451] [client 158.23.147.79:60201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/goods.php"] [unique_id "apPlaWZcVaai59truiVnKwAAAD0"]
[Sun Aug 30 03:10:17.619581 2026] [security2:error] [pid 515259:tid 515499] [client 20.48.250.41:17238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/inege.php"] [unique_id "apPlaWZcVaai59truiVnLAAAAG0"]
[Sun Aug 30 03:10:17.621419 2026] [security2:error] [pid 512881:tid 512894] [remote 192.250.232.93:49130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.232.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftballs.com"] [uri "/wp-login.php"] [unique_id "apPlaQi65Hcg2zUJjxCBsQACkgw"], referer: https://giftballs.com/wp-login.php
[Sun Aug 30 03:10:17.632053 2026] [security2:error] [pid 512881:tid 513066] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/dist/.env"] [unique_id "apPlaQi65Hcg2zUJjxCBuwAAAks"]
[Sun Aug 30 03:10:17.637631 2026] [security2:error] [pid 512881:tid 513133] [client 20.104.49.130:64093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/worksec.php"] [unique_id "apPlaQi65Hcg2zUJjxCBwAAAAo4"]
[Sun Aug 30 03:10:17.642165 2026] [security2:error] [pid 512881:tid 513131] [client 20.104.18.15:18407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/file1221.php"] [unique_id "apPlaQi65Hcg2zUJjxCBxAAAAow"]
[Sun Aug 30 03:10:17.658578 2026] [security2:error] [pid 515259:tid 515485] [client 4.205.62.107:61741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/saml.php"] [unique_id "apPlaWZcVaai59truiVnNQAAAF8"]
[Sun Aug 30 03:10:17.663306 2026] [security2:error] [pid 512881:tid 513069] [client 20.63.81.20:31743] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "proactivemaintenancesolutions.com"] [uri "/1.php"] [unique_id "apPlaQi65Hcg2zUJjxCB1AAAAk4"]
[Sun Aug 30 03:10:17.663388 2026] [security2:error] [pid 512881:tid 513069] [client 20.63.81.20:31743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/1.php"] [unique_id "apPlaQi65Hcg2zUJjxCB1AAAAk4"]
[Sun Aug 30 03:10:17.664952 2026] [security2:error] [pid 512881:tid 513077] [client 20.104.18.15:44006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apPlaQi65Hcg2zUJjxCB1QAAAlY"]
[Sun Aug 30 03:10:17.681730 2026] [security2:error] [pid 515259:tid 515420] [client 20.104.49.130:60658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/tiny2.php"] [unique_id "apPlaWZcVaai59truiVnOQAAAB4"]
[Sun Aug 30 03:10:17.688823 2026] [security2:error] [pid 512881:tid 513118] [client 20.48.160.90:63884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/indo.php"] [unique_id "apPlaQi65Hcg2zUJjxCB7QAAAn8"]
[Sun Aug 30 03:10:17.696562 2026] [security2:error] [pid 512881:tid 513127] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/public_html/.env"] [unique_id "apPlaQi65Hcg2zUJjxCB8QAAAog"]
[Sun Aug 30 03:10:17.752300 2026] [security2:error] [pid 512881:tid 513012] [client 20.48.250.41:17333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/wp-link10.php"] [unique_id "apPlaQi65Hcg2zUJjxCCHQAAAhU"]
[Sun Aug 30 03:10:17.752539 2026] [authz_core:error] [pid 512881:tid 513111] [client 66.249.66.67:44109] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:17.752998 2026] [authz_core:error] [pid 512881:tid 513111] [client 66.249.66.67:44109] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:17.754791 2026] [security2:error] [pid 512881:tid 513046] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/htdocs/.env"] [unique_id "apPlaQi65Hcg2zUJjxCCHwAAAjc"]
[Sun Aug 30 03:10:17.769318 2026] [authz_core:error] [pid 512881:tid 513102] [client 66.249.66.74:51344] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:17.769776 2026] [authz_core:error] [pid 512881:tid 513102] [client 66.249.66.74:51344] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:17.771227 2026] [security2:error] [pid 515259:tid 515505] [client 68.155.159.216:46005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPlaWZcVaai59truiVnRAAAAHM"]
[Sun Aug 30 03:10:17.783836 2026] [security2:error] [pid 512881:tid 513108] [client 20.104.50.220:6126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/haxor.php"] [unique_id "apPlaQi65Hcg2zUJjxCCNQAAAnU"]
[Sun Aug 30 03:10:17.791498 2026] [security2:error] [pid 512881:tid 513049] [client 20.63.81.20:31573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/classwithtostring.php"] [unique_id "apPlaQi65Hcg2zUJjxCCOwAAAjo"]
[Sun Aug 30 03:10:17.794501 2026] [security2:error] [pid 512881:tid 513114] [client 20.104.49.130:64098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/browse.php"] [unique_id "apPlaQi65Hcg2zUJjxCCPwAAAns"]
[Sun Aug 30 03:10:17.802453 2026] [security2:error] [pid 512881:tid 513058] [client 20.104.50.220:61962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/ohayo.php"] [unique_id "apPlaQi65Hcg2zUJjxCCQgAAAkM"]
[Sun Aug 30 03:10:17.815103 2026] [security2:error] [pid 512881:tid 513068] [client 158.23.147.79:43854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/dropdown.php"] [unique_id "apPlaQi65Hcg2zUJjxCCTAAAAk0"]
[Sun Aug 30 03:10:17.828174 2026] [security2:error] [pid 512881:tid 513071] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/www/.env"] [unique_id "apPlaQi65Hcg2zUJjxCCWAAAAlA"]
[Sun Aug 30 03:10:17.842327 2026] [security2:error] [pid 512881:tid 513109] [client 68.155.159.216:52578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/lv.php"] [unique_id "apPlaQi65Hcg2zUJjxCCZQAAAnY"]
[Sun Aug 30 03:10:17.857133 2026] [security2:error] [pid 512881:tid 513031] [client 20.48.160.90:37515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/sign.php"] [unique_id "apPlaQi65Hcg2zUJjxCCdAAAAig"]
[Sun Aug 30 03:10:17.878792 2026] [security2:error] [pid 512881:tid 513040] [client 20.104.50.220:63195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/bob.php"] [unique_id "apPlaQi65Hcg2zUJjxCChAAAAjE"]
[Sun Aug 30 03:10:17.886552 2026] [security2:error] [pid 512881:tid 513051] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/html/.env"] [unique_id "apPlaQi65Hcg2zUJjxCCiQAAAjw"]
[Sun Aug 30 03:10:17.895079 2026] [authz_core:error] [pid 515259:tid 515439] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:17.895719 2026] [authz_core:error] [pid 515259:tid 515439] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:17.898765 2026] [security2:error] [pid 515259:tid 515482] [client 20.48.250.41:17296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/ww.php"] [unique_id "apPlaWZcVaai59truiVnYAAAAFw"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:10:17.924746 2026] [security2:error] [pid 512881:tid 513049] [client 20.63.81.20:31701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp-ws68.php"] [unique_id "apPlaQi65Hcg2zUJjxCCnwAAAjo"]
[Sun Aug 30 03:10:17.929798 2026] [security2:error] [pid 515259:tid 515516] [client 158.23.147.79:52287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/.well-known/index.php"] [unique_id "apPlaWZcVaai59truiVnZAAAAH4"]
[Sun Aug 30 03:10:17.935320 2026] [authz_core:error] [pid 515259:tid 515417] [client 66.249.66.71:43784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:17.935602 2026] [authz_core:error] [pid 515259:tid 515417] [client 66.249.66.71:43784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:17.966476 2026] [security2:error] [pid 512881:tid 513066] [client 20.48.251.3:64307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/groceries/index.php"] [unique_id "apPlaQi65Hcg2zUJjxCCvAAAAks"]
[Sun Aug 30 03:10:17.977542 2026] [security2:error] [pid 512881:tid 513049] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/live/.env"] [unique_id "apPlaQi65Hcg2zUJjxCCxwAAAjo"]
[Sun Aug 30 03:10:17.980509 2026] [security2:error] [pid 512881:tid 513031] [client 20.104.49.130:43311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/002.php"] [unique_id "apPlaQi65Hcg2zUJjxCCzAAAAig"]
[Sun Aug 30 03:10:17.990224 2026] [security2:error] [pid 515259:tid 515513] [client 20.48.160.90:63913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/wnnjpsby.php"] [unique_id "apPlaWZcVaai59truiVndwAAAHs"]
[Sun Aug 30 03:10:18.027979 2026] [security2:error] [pid 512881:tid 513074] [client 20.48.250.41:17374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/w1px.php"] [unique_id "apPlagi65Hcg2zUJjxCC3gAAAlM"]
[Sun Aug 30 03:10:18.038206 2026] [security2:error] [pid 512881:tid 513078] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/prod/.env"] [unique_id "apPlagi65Hcg2zUJjxCC5AAAAlc"]
[Sun Aug 30 03:10:18.049573 2026] [security2:error] [pid 512881:tid 513079] [client 20.104.50.220:52829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/r0x.php"] [unique_id "apPlagi65Hcg2zUJjxCC6wAAAlg"]
[Sun Aug 30 03:10:18.051213 2026] [security2:error] [pid 512881:tid 513066] [client 20.63.81.20:31712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/simple.php"] [unique_id "apPlagi65Hcg2zUJjxCC7AAAAks"]
[Sun Aug 30 03:10:18.061301 2026] [security2:error] [pid 512881:tid 513072] [client 158.23.147.79:60198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apPlagi65Hcg2zUJjxCC8QAAAlE"]
[Sun Aug 30 03:10:18.084405 2026] [authz_core:error] [pid 512881:tid 513055] [client 216.73.216.128:2445] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:18.084855 2026] [authz_core:error] [pid 512881:tid 513055] [client 216.73.216.128:2445] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:18.085593 2026] [security2:error] [pid 512881:tid 513061] [client 68.155.159.216:57053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/dropdown.php"] [unique_id "apPlagi65Hcg2zUJjxCC_wAAAkY"]
[Sun Aug 30 03:10:18.099991 2026] [security2:error] [pid 512881:tid 513087] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/dev/.env"] [unique_id "apPlagi65Hcg2zUJjxCDBwAAAmA"]
[Sun Aug 30 03:10:18.108902 2026] [authz_core:error] [pid 512881:tid 513047] [client 66.249.66.73:47672] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:18.109372 2026] [authz_core:error] [pid 512881:tid 513047] [client 66.249.66.73:47672] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:18.117387 2026] [security2:error] [pid 512881:tid 513052] [client 4.205.62.107:25481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/fm.php"] [unique_id "apPlagi65Hcg2zUJjxCDHAAAAj0"]
[Sun Aug 30 03:10:18.123336 2026] [security2:error] [pid 512881:tid 513138] [client 20.104.49.130:52128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/jp.php"] [unique_id "apPlagi65Hcg2zUJjxCDIgAAApM"]
[Sun Aug 30 03:10:18.127722 2026] [security2:error] [pid 512881:tid 513131] [client 20.48.160.90:63942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/gigi.php"] [unique_id "apPlagi65Hcg2zUJjxCDJQAAAow"]
[Sun Aug 30 03:10:18.127749 2026] [security2:error] [pid 512881:tid 513027] [client 158.23.147.79:52241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/themes/too.php"] [unique_id "apPlagi65Hcg2zUJjxCDJAAAAiQ"]
[Sun Aug 30 03:10:18.173198 2026] [security2:error] [pid 512881:tid 513063] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/staging/.env"] [unique_id "apPlagi65Hcg2zUJjxCDQAAAAkg"]
[Sun Aug 30 03:10:18.176372 2026] [security2:error] [pid 512881:tid 513101] [client 20.63.81.20:31728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/aaa.php"] [unique_id "apPlagi65Hcg2zUJjxCDRgAAAm4"]
[Sun Aug 30 03:10:18.182721 2026] [security2:error] [pid 512881:tid 513098] [client 20.48.250.41:17359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/to.php"] [unique_id "apPlagi65Hcg2zUJjxCDSQAAAms"]
[Sun Aug 30 03:10:18.220469 2026] [security2:error] [pid 512881:tid 513057] [client 216.73.216.128:48472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPlagi65Hcg2zUJjxCDWAAAAkI"]
[Sun Aug 30 03:10:18.232379 2026] [security2:error] [pid 512881:tid 513060] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/opt/.env"] [unique_id "apPlagi65Hcg2zUJjxCDWQAAAkU"]
[Sun Aug 30 03:10:18.257805 2026] [security2:error] [pid 512881:tid 513038] [client 4.205.62.107:36670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/public/mah.php.php"] [unique_id "apPlagi65Hcg2zUJjxCDaQAAAi8"]
[Sun Aug 30 03:10:18.259664 2026] [authz_core:error] [pid 512881:tid 513013] [client 66.249.66.70:65171] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:18.259950 2026] [authz_core:error] [pid 512881:tid 513013] [client 66.249.66.70:65171] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:10:18.280040 2026] [security2:error] [pid 512881:tid 513092] [client 20.48.160.90:61332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/info.php/new.php"] [unique_id "apPlagi65Hcg2zUJjxCDcQAAAmU"]
[Sun Aug 30 03:10:18.289503 2026] [security2:error] [pid 512881:tid 513114] [client 20.104.49.130:52136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/about.php"] [unique_id "apPlagi65Hcg2zUJjxCDdgAAAns"]
[Sun Aug 30 03:10:18.293656 2026] [security2:error] [pid 512881:tid 513051] [client 158.23.147.79:60165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-admin/includes/nav.php"] [unique_id "apPlagi65Hcg2zUJjxCDeAAAAjw"]
[Sun Aug 30 03:10:18.293745 2026] [security2:error] [pid 512881:tid 513063] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/laravel/.env"] [unique_id "apPlagi65Hcg2zUJjxCDdwAAAkg"]
[Sun Aug 30 03:10:18.306922 2026] [security2:error] [pid 512881:tid 513132] [client 158.23.147.79:43857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/radio.php"] [unique_id "apPlagi65Hcg2zUJjxCDfQAAAo0"]
[Sun Aug 30 03:10:18.326233 2026] [security2:error] [pid 512881:tid 513034] [client 20.48.250.41:17281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/thui.php"] [unique_id "apPlagi65Hcg2zUJjxCDggAAAis"]
[Sun Aug 30 03:10:18.362034 2026] [security2:error] [pid 512881:tid 513106] [client 34.130.99.179:42964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/symfony/.env"] [unique_id "apPlagi65Hcg2zUJjxCDhwAAAnM"]
[Sun Aug 30 03:10:18.375418 2026] [authz_core:error] [pid 515259:tid 515432] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:18.375722 2026] [authz_core:error] [pid 515259:tid 515432] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:18.387706 2026] [authz_core:error] [pid 512881:tid 513091] [client 66.249.66.71:58220] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:18.387982 2026] [authz_core:error] [pid 512881:tid 513091] [client 66.249.66.71:58220] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:18.426762 2026] [security2:error] [pid 515259:tid 515425] [client 20.151.200.44:28654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/css/000.php"] [unique_id "apPlamZcVaai59truiVnrQAAACM"]
[Sun Aug 30 03:10:18.446948 2026] [security2:error] [pid 512881:tid 513060] [client 20.63.81.20:31670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/shiny.php"] [unique_id "apPlagi65Hcg2zUJjxCDmQAAAkU"]
[Sun Aug 30 03:10:18.454227 2026] [security2:error] [pid 512881:tid 513050] [client 20.48.250.41:17297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/Jcrop.php"] [unique_id "apPlagi65Hcg2zUJjxCDngAAAjs"]
[Sun Aug 30 03:10:18.454404 2026] [security2:error] [pid 512881:tid 513036] [client 158.23.147.79:57693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/index/function.php"] [unique_id "apPlagi65Hcg2zUJjxCDnwAAAi0"]
[Sun Aug 30 03:10:18.467197 2026] [security2:error] [pid 515259:tid 515449] [client 20.104.50.220:16649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/autoload_classmap.php"] [unique_id "apPlamZcVaai59truiVnugAAADs"]
[Sun Aug 30 03:10:18.480990 2026] [security2:error] [pid 515259:tid 515433] [client 20.48.251.3:55806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/8.php"] [unique_id "apPlamZcVaai59truiVnvgAAACs"]
[Sun Aug 30 03:10:18.481957 2026] [security2:error] [pid 512881:tid 513026] [client 20.104.18.15:64873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/m.php"] [unique_id "apPlagi65Hcg2zUJjxCDrQAAAiM"]
[Sun Aug 30 03:10:18.501128 2026] [security2:error] [pid 512881:tid 513114] [client 20.48.160.90:61326] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.biospherecampus.com"] [uri "/wp-content/uploads/"] [unique_id "apPlagi65Hcg2zUJjxCDsgAAAns"]
[Sun Aug 30 03:10:18.508222 2026] [security2:error] [pid 512881:tid 513063] [client 20.104.49.130:52113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/classwithtostring.php"] [unique_id "apPlagi65Hcg2zUJjxCDtAAAAkg"]
[Sun Aug 30 03:10:18.509546 2026] [security2:error] [pid 515259:tid 515437] [client 4.205.62.107:17148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/upload.form.php"] [unique_id "apPlamZcVaai59truiVnvwAAAC8"]
[Sun Aug 30 03:10:18.575325 2026] [security2:error] [pid 512881:tid 513137] [client 34.130.99.179:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/wordpress/.env"] [unique_id "apPlagi65Hcg2zUJjxCDxwAAApI"]
[Sun Aug 30 03:10:18.580117 2026] [security2:error] [pid 512881:tid 513077] [client 20.63.81.20:31674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/goods.php"] [unique_id "apPlagi65Hcg2zUJjxCDyQAAAlY"]
[Sun Aug 30 03:10:18.585979 2026] [security2:error] [pid 512881:tid 513061] [client 20.48.251.3:59885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/aws_auth.php"] [unique_id "apPlagi65Hcg2zUJjxCDzAAAAkY"]
[Sun Aug 30 03:10:18.601761 2026] [security2:error] [pid 512881:tid 513078] [client 20.48.250.41:17240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/ws58.php"] [unique_id "apPlagi65Hcg2zUJjxCD0QAAAlc"]
[Sun Aug 30 03:10:18.602124 2026] [security2:error] [pid 512881:tid 513086] [client 20.104.50.220:33183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/lyda.php"] [unique_id "apPlagi65Hcg2zUJjxCD0gAAAl8"]
[Sun Aug 30 03:10:18.615307 2026] [security2:error] [pid 512881:tid 513072] [client 20.104.18.15:17011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/ajax.php"] [unique_id "apPlagi65Hcg2zUJjxCD2QAAAlE"]
[Sun Aug 30 03:10:18.623441 2026] [security2:error] [pid 512881:tid 513012] [client 20.104.18.15:35192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/sss.php"] [unique_id "apPlagi65Hcg2zUJjxCD3wAAAhU"]
[Sun Aug 30 03:10:18.631702 2026] [security2:error] [pid 512881:tid 513065] [client 20.48.160.90:61401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/w.php"] [unique_id "apPlagi65Hcg2zUJjxCD5QAAAko"]
[Sun Aug 30 03:10:18.633587 2026] [security2:error] [pid 512881:tid 513092] [client 20.151.200.44:40913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/zoz.php"] [unique_id "apPlagi65Hcg2zUJjxCD6AAAAmU"]
[Sun Aug 30 03:10:18.635122 2026] [security2:error] [pid 512881:tid 513127] [client 34.130.99.179:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/wp/.env"] [unique_id "apPlagi65Hcg2zUJjxCD6QAAAog"]
[Sun Aug 30 03:10:18.642365 2026] [security2:error] [pid 512881:tid 513014] [client 20.104.50.220:63496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/lab.php"] [unique_id "apPlagi65Hcg2zUJjxCD8AAAAhc"]
[Sun Aug 30 03:10:18.695679 2026] [security2:error] [pid 512881:tid 513050] [client 34.130.99.179:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/cms/.env"] [unique_id "apPlagi65Hcg2zUJjxCEGQAAAjs"]
[Sun Aug 30 03:10:18.697110 2026] [security2:error] [pid 512881:tid 513069] [client 158.23.147.79:52285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPlagi65Hcg2zUJjxCEGwAAAk4"]
[Sun Aug 30 03:10:18.716046 2026] [security2:error] [pid 512881:tid 513063] [client 20.63.81.20:31605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/000.php/index.php"] [unique_id "apPlagi65Hcg2zUJjxCEJQAAAkg"]
[Sun Aug 30 03:10:18.716326 2026] [security2:error] [pid 512881:tid 513081] [client 20.48.251.3:13959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/gjm.php"] [unique_id "apPlagi65Hcg2zUJjxCEJgAAAlo"]
[Sun Aug 30 03:10:18.727065 2026] [security2:error] [pid 512881:tid 513058] [client 20.104.50.220:29340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/cgi-alfa.php"] [unique_id "apPlagi65Hcg2zUJjxCEMAAAAkM"]
[Sun Aug 30 03:10:18.740880 2026] [security2:error] [pid 515259:tid 515438] [client 20.48.250.41:17393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/xs.php"] [unique_id "apPlamZcVaai59truiVn3QAAADA"]
[Sun Aug 30 03:10:18.756408 2026] [security2:error] [pid 515259:tid 515516] [client 158.23.147.79:60212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/file.php"] [unique_id "apPlamZcVaai59truiVn4QAAAH4"]
[Sun Aug 30 03:10:18.771176 2026] [security2:error] [pid 512881:tid 513012] [client 20.104.18.15:22502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/admin.php"] [unique_id "apPlagi65Hcg2zUJjxCEUwAAAhU"]
[Sun Aug 30 03:10:18.771803 2026] [security2:error] [pid 512881:tid 513047] [client 34.130.99.179:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/drupal/.env"] [unique_id "apPlagi65Hcg2zUJjxCEVAAAAjg"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:10:18.799329 2026] [security2:error] [pid 512881:tid 513130] [client 4.205.62.107:61715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/aws_settings.php"] [unique_id "apPlagi65Hcg2zUJjxCEYgAAAos"]
[Sun Aug 30 03:10:18.810853 2026] [security2:error] [pid 512881:tid 513132] [client 20.104.18.15:18338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/nox.php"] [unique_id "apPlagi65Hcg2zUJjxCEagAAAo0"]
[Sun Aug 30 03:10:18.813120 2026] [security2:error] [pid 512881:tid 513015] [client 20.104.18.15:43950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/sao.php"] [unique_id "apPlagi65Hcg2zUJjxCEbQAAAhg"]
[Sun Aug 30 03:10:18.823793 2026] [authz_core:error] [pid 512881:tid 513029] [client 216.73.216.128:2445] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:18.824181 2026] [authz_core:error] [pid 512881:tid 513029] [client 216.73.216.128:2445] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:18.828967 2026] [security2:error] [pid 512881:tid 513117] [client 20.104.49.130:59570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/az.php"] [unique_id "apPlagi65Hcg2zUJjxCEdgAAAn4"]
[Sun Aug 30 03:10:18.830602 2026] [security2:error] [pid 512881:tid 513110] [client 34.130.99.179:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/joomla/.env"] [unique_id "apPlagi65Hcg2zUJjxCEeQAAAnc"]
[Sun Aug 30 03:10:18.841410 2026] [security2:error] [pid 512881:tid 513086] [client 20.48.160.90:61425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/x.php"] [unique_id "apPlagi65Hcg2zUJjxCEfgAAAl8"]
[Sun Aug 30 03:10:18.856507 2026] [security2:error] [pid 515259:tid 515393] [client 20.63.81.20:31655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/Jcrop.php"] [unique_id "apPlamZcVaai59truiVn8gAAAAM"]
[Sun Aug 30 03:10:18.864942 2026] [security2:error] [pid 512881:tid 513081] [client 20.104.49.130:43307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/666.php"] [unique_id "apPlagi65Hcg2zUJjxCEmwAAAlo"]
[Sun Aug 30 03:10:18.871810 2026] [authz_core:error] [pid 512881:tid 513136] [client 66.249.66.64:53607] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:18.872077 2026] [authz_core:error] [pid 512881:tid 513136] [client 66.249.66.64:53607] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:18.876827 2026] [security2:error] [pid 512881:tid 513113] [client 68.155.159.216:45892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-includes/content.php"] [unique_id "apPlagi65Hcg2zUJjxCEpwAAAno"]
[Sun Aug 30 03:10:18.880785 2026] [authz_core:error] [pid 515259:tid 515449] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:18.881046 2026] [authz_core:error] [pid 515259:tid 515449] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:18.894821 2026] [security2:error] [pid 512881:tid 513051] [client 34.130.99.179:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/magento/.env"] [unique_id "apPlagi65Hcg2zUJjxCEsgAAAjw"]
[Sun Aug 30 03:10:18.895060 2026] [security2:error] [pid 515259:tid 515453] [client 20.48.250.41:17353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/zu.php"] [unique_id "apPlamZcVaai59truiVn_QAAAD8"]
[Sun Aug 30 03:10:18.922759 2026] [security2:error] [pid 515259:tid 515394] [client 158.23.147.79:52258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/makeasmtp.php"] [unique_id "apPlamZcVaai59truiVoCgAAAAQ"]
[Sun Aug 30 03:10:18.938352 2026] [security2:error] [pid 512881:tid 513076] [client 20.104.50.220:6134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/sym.php"] [unique_id "apPlagi65Hcg2zUJjxCExQAAAlU"]
[Sun Aug 30 03:10:18.941762 2026] [security2:error] [pid 512881:tid 513081] [client 20.104.50.220:62208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/olux.php"] [unique_id "apPlagi65Hcg2zUJjxCExwAAAlo"]
[Sun Aug 30 03:10:18.943684 2026] [security2:error] [pid 515259:tid 515441] [client 68.155.159.216:52307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apPlamZcVaai59truiVoCwAAADM"]
[Sun Aug 30 03:10:18.957491 2026] [security2:error] [pid 512881:tid 513013] [client 34.130.99.179:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/shopify/.env"] [unique_id "apPlagi65Hcg2zUJjxCE0QAAAhY"]
[Sun Aug 30 03:10:18.963961 2026] [security2:error] [pid 512881:tid 513030] [client 20.151.200.44:40843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/kcs.php"] [unique_id "apPlagi65Hcg2zUJjxCE2QAAAic"]
[Sun Aug 30 03:10:18.976464 2026] [security2:error] [pid 512881:tid 513057] [client 20.104.49.130:58052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/wp-the.php"] [unique_id "apPlagi65Hcg2zUJjxCE5QAAAkI"]
[Sun Aug 30 03:10:18.977089 2026] [security2:error] [pid 512881:tid 513057] [client 20.48.160.90:61322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/ssla.php"] [unique_id "apPlagi65Hcg2zUJjxCE5gAAAkI"]
[Sun Aug 30 03:10:18.993467 2026] [security2:error] [pid 512881:tid 513082] [client 20.63.81.20:31656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/35iDq8NAjLu.php"] [unique_id "apPlagi65Hcg2zUJjxCE9QAAAls"]
[Sun Aug 30 03:10:19.015658 2026] [security2:error] [pid 512881:tid 513056] [client 34.130.99.179:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/prestashop/.env"] [unique_id "apPlawi65Hcg2zUJjxCFAwAAAkE"]
[Sun Aug 30 03:10:19.030638 2026] [security2:error] [pid 512881:tid 513114] [client 20.104.50.220:59718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/t3s.php"] [unique_id "apPlawi65Hcg2zUJjxCFBwAAAns"]
[Sun Aug 30 03:10:19.074287 2026] [security2:error] [pid 512881:tid 513113] [client 20.104.49.130:53722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/users.php"] [unique_id "apPlawi65Hcg2zUJjxCFIwAAAno"]
[Sun Aug 30 03:10:19.077569 2026] [security2:error] [pid 512881:tid 513065] [client 34.130.99.179:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/codeigniter/.env"] [unique_id "apPlawi65Hcg2zUJjxCFJQAAAko"]
[Sun Aug 30 03:10:19.077728 2026] [security2:error] [pid 512881:tid 513044] [client 20.48.250.41:17236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/lanka.php"] [unique_id "apPlawi65Hcg2zUJjxCFJwAAAjU"]
[Sun Aug 30 03:10:19.089989 2026] [security2:error] [pid 512881:tid 513029] [client 20.104.49.130:53718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/222.php"] [unique_id "apPlawi65Hcg2zUJjxCFMgAAAiY"]
[Sun Aug 30 03:10:19.093487 2026] [authz_core:error] [pid 515259:tid 515429] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:19.093840 2026] [authz_core:error] [pid 515259:tid 515429] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:19.096770 2026] [security2:error] [pid 515259:tid 515497] [client 20.48.251.3:54775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/konfig.php"] [unique_id "apPla2ZcVaai59truiVoKgAAAGs"]
[Sun Aug 30 03:10:19.151561 2026] [security2:error] [pid 515259:tid 515477] [client 158.23.147.79:58394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/file17.php"] [unique_id "apPla2ZcVaai59truiVoMQAAAFc"]
[Sun Aug 30 03:10:19.169820 2026] [security2:error] [pid 512881:tid 513058] [client 34.130.99.179:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/cakephp/.env"] [unique_id "apPlawi65Hcg2zUJjxCFWAAAAkM"]
[Sun Aug 30 03:10:19.182077 2026] [authz_core:error] [pid 512881:tid 513065] [client 66.249.66.73:47672] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:19.182496 2026] [authz_core:error] [pid 512881:tid 513065] [client 66.249.66.73:47672] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:19.199569 2026] [security2:error] [pid 512881:tid 513023] [client 20.63.81.20:31636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/btx25.php"] [unique_id "apPlawi65Hcg2zUJjxCFbQAAAiA"]
[Sun Aug 30 03:10:19.199569 2026] [security2:error] [pid 515259:tid 515505] [client 20.104.50.220:29142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/bn.php"] [unique_id "apPla2ZcVaai59truiVoQgAAAHM"]
[Sun Aug 30 03:10:19.203618 2026] [security2:error] [pid 515259:tid 515430] [client 20.48.160.90:61338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apPla2ZcVaai59truiVoQwAAACg"]
[Sun Aug 30 03:10:19.214265 2026] [security2:error] [pid 515259:tid 515446] [client 68.155.159.216:57068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/sad/about.php"] [unique_id "apPla2ZcVaai59truiVoRgAAADg"]
[Sun Aug 30 03:10:19.218847 2026] [security2:error] [pid 515259:tid 515437] [client 20.48.250.41:17227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/gettest.php"] [unique_id "apPla2ZcVaai59truiVoRwAAAC8"]
[Sun Aug 30 03:10:19.227994 2026] [security2:error] [pid 512881:tid 513031] [client 34.130.99.179:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/zend/.env"] [unique_id "apPlawi65Hcg2zUJjxCFdQAAAig"]
[Sun Aug 30 03:10:19.254128 2026] [security2:error] [pid 512881:tid 513069] [client 4.205.62.107:25866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/tinyfilemanager.php"] [unique_id "apPlawi65Hcg2zUJjxCFhgAAAk4"]
[Sun Aug 30 03:10:19.254289 2026] [security2:error] [pid 512881:tid 513092] [client 158.23.147.79:43886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apPlawi65Hcg2zUJjxCFhwAAAmU"]
[Sun Aug 30 03:10:19.269072 2026] [security2:error] [pid 512881:tid 513020] [client 184.154.76.13:45788] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "dejulschoolofdance.com"] [uri "/wp-content/uploads/elementor/google-fonts/css/roboto.css"] [unique_id "apPlawi65Hcg2zUJjxCFdAAAAnE"]
[Sun Aug 30 03:10:19.275076 2026] [security2:error] [pid 512881:tid 513120] [client 20.104.49.130:36771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/pfm.php"] [unique_id "apPlawi65Hcg2zUJjxCFkgAAAoE"]
[Sun Aug 30 03:10:19.285478 2026] [security2:error] [pid 512881:tid 513017] [client 34.130.99.179:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/yii/.env"] [unique_id "apPlawi65Hcg2zUJjxCFlAAAAho"]
[Sun Aug 30 03:10:19.337158 2026] [security2:error] [pid 515259:tid 515399] [client 20.63.81.20:31617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/radio.php"] [unique_id "apPla2ZcVaai59truiVoUQAAAAk"]
[Sun Aug 30 03:10:19.340697 2026] [security2:error] [pid 512881:tid 513099] [client 20.104.49.130:51073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/echkm.php"] [unique_id "apPlawi65Hcg2zUJjxCFoAAAAmw"]
[Sun Aug 30 03:10:19.347663 2026] [security2:error] [pid 512881:tid 513078] [client 20.48.160.90:61434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/wp-aothait.php"] [unique_id "apPlawi65Hcg2zUJjxCFowAAAlc"]
[Sun Aug 30 03:10:19.354790 2026] [security2:error] [pid 512881:tid 513067] [client 34.130.99.179:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/laravel5/.env"] [unique_id "apPlawi65Hcg2zUJjxCFpgAAAkw"]
[Sun Aug 30 03:10:19.358839 2026] [security2:error] [pid 512881:tid 513094] [client 216.73.216.128:54940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/usage_202601.html"] [unique_id "apPlawi65Hcg2zUJjxCFpwAAAmc"]
[Sun Aug 30 03:10:19.362580 2026] [authz_core:error] [pid 512881:tid 513082] [client 66.249.66.32:56830] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:19.363037 2026] [authz_core:error] [pid 512881:tid 513082] [client 66.249.66.32:56830] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:19.375096 2026] [authz_core:error] [pid 515259:tid 515398] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:19.375381 2026] [authz_core:error] [pid 515259:tid 515398] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:19.391351 2026] [security2:error] [pid 512881:tid 513045] [client 4.205.62.107:36734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/zaza.php"] [unique_id "apPlawi65Hcg2zUJjxCFswAAAjY"]
[Sun Aug 30 03:10:19.393935 2026] [security2:error] [pid 512881:tid 513126] [client 20.48.250.41:17236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/35.php"] [unique_id "apPlawi65Hcg2zUJjxCFtQAAAoc"]
[Sun Aug 30 03:10:19.417554 2026] [security2:error] [pid 512881:tid 513064] [client 34.130.99.179:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/v1/.env"] [unique_id "apPlawi65Hcg2zUJjxCFuwAAAkk"]
[Sun Aug 30 03:10:19.464236 2026] [security2:error] [pid 512881:tid 513115] [client 20.63.81.20:31696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/dex.php"] [unique_id "apPlawi65Hcg2zUJjxCF1QAAAnw"]
[Sun Aug 30 03:10:19.475170 2026] [security2:error] [pid 512881:tid 513015] [client 34.130.99.179:55440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/v2/.env"] [unique_id "apPlawi65Hcg2zUJjxCF2AAAAhg"]
[Sun Aug 30 03:10:19.482155 2026] [security2:error] [pid 512881:tid 513047] [client 158.23.147.79:56511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/.well-known/content.php"] [unique_id "apPlawi65Hcg2zUJjxCF2gAAAjg"]
[Sun Aug 30 03:10:19.491405 2026] [security2:error] [pid 512881:tid 513118] [client 20.48.160.90:63917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/wp-includes/index.php"] [unique_id "apPlawi65Hcg2zUJjxCF3AAAAn8"]
[Sun Aug 30 03:10:19.499995 2026] [security2:error] [pid 515259:tid 515468] [client 20.151.200.44:40914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/tajj.php"] [unique_id "apPla2ZcVaai59truiVoWAAAAE4"]
[Sun Aug 30 03:10:19.557920 2026] [security2:error] [pid 515259:tid 515434] [client 20.104.49.130:52149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/amax.php"] [unique_id "apPla2ZcVaai59truiVoYAAAACw"]
[Sun Aug 30 03:10:19.561940 2026] [security2:error] [pid 515259:tid 515482] [client 20.48.250.41:17305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/maraz.php"] [unique_id "apPla2ZcVaai59truiVoYQAAAFw"]
[Sun Aug 30 03:10:19.579936 2026] [security2:error] [pid 515259:tid 515481] [client 158.23.147.79:60214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/file5.php"] [unique_id "apPla2ZcVaai59truiVoYgAAAFs"]
[Sun Aug 30 03:10:19.585782 2026] [security2:error] [pid 515259:tid 515496] [client 158.23.147.79:52269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apPla2ZcVaai59truiVoYwAAAGo"]
[Sun Aug 30 03:10:19.591525 2026] [security2:error] [pid 515259:tid 515456] [client 20.63.81.20:31742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/giodywky.php"] [unique_id "apPla2ZcVaai59truiVoZAAAAEI"]
[Sun Aug 30 03:10:19.603715 2026] [security2:error] [pid 515259:tid 515405] [client 20.104.50.220:16719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/inputs.php"] [unique_id "apPla2ZcVaai59truiVoaAAAAA8"]
[Sun Aug 30 03:10:19.618552 2026] [security2:error] [pid 515259:tid 515485] [client 20.104.18.15:64870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/33.php"] [unique_id "apPla2ZcVaai59truiVobQAAAF8"]
[Sun Aug 30 03:10:19.620079 2026] [security2:error] [pid 515259:tid 515506] [client 20.48.251.3:55803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/thui.php"] [unique_id "apPla2ZcVaai59truiVobwAAAHQ"]
[Sun Aug 30 03:10:19.621503 2026] [security2:error] [pid 515259:tid 515443] [client 20.48.160.90:61348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/file31.php"] [unique_id "apPla2ZcVaai59truiVocQAAADU"]
[Sun Aug 30 03:10:19.641246 2026] [security2:error] [pid 515259:tid 515393] [client 4.205.62.107:17305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/aws_auth.php"] [unique_id "apPla2ZcVaai59truiVodQAAAAM"]
[Sun Aug 30 03:10:19.689699 2026] [security2:error] [pid 515259:tid 515414] [client 20.48.250.41:17285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/kbfr.php"] [unique_id "apPla2ZcVaai59truiVogAAAABg"]
[Sun Aug 30 03:10:19.720710 2026] [security2:error] [pid 515259:tid 515420] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/api/v1/.env"] [unique_id "apPla2ZcVaai59truiVohAAAAB4"]
[Sun Aug 30 03:10:19.721531 2026] [security2:error] [pid 515259:tid 515435] [client 20.63.81.20:31737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp-kz.php"] [unique_id "apPla2ZcVaai59truiVohQAAAC0"]
[Sun Aug 30 03:10:19.728448 2026] [security2:error] [pid 515259:tid 515460] [client 20.48.251.3:59486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/hiquido.com/index.php"] [unique_id "apPla2ZcVaai59truiVohgAAAEY"]
[Sun Aug 30 03:10:19.742851 2026] [security2:error] [pid 515259:tid 515475] [client 20.104.50.220:33035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/alfashell.php"] [unique_id "apPla2ZcVaai59truiVoiQAAAFU"]
[Sun Aug 30 03:10:19.755362 2026] [security2:error] [pid 515259:tid 515484] [client 20.104.49.130:64094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/init.php"] [unique_id "apPla2ZcVaai59truiVoigAAAF4"]
[Sun Aug 30 03:10:19.755776 2026] [security2:error] [pid 515259:tid 515442] [client 20.104.18.15:17007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/atomlib.php"] [unique_id "apPla2ZcVaai59truiVoiwAAADQ"]
[Sun Aug 30 03:10:19.759940 2026] [security2:error] [pid 515259:tid 515447] [client 20.151.200.44:40866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/bge.php"] [unique_id "apPla2ZcVaai59truiVojQAAADk"]
[Sun Aug 30 03:10:19.763497 2026] [security2:error] [pid 515259:tid 515479] [client 20.48.160.90:63992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/dk.php"] [unique_id "apPla2ZcVaai59truiVojgAAAFk"]
[Sun Aug 30 03:10:19.785805 2026] [security2:error] [pid 515259:tid 515487] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/api/v2/.env"] [unique_id "apPla2ZcVaai59truiVolAAAAGE"]
[Sun Aug 30 03:10:19.793343 2026] [security2:error] [pid 515259:tid 515472] [client 20.104.49.130:48348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/m.php"] [unique_id "apPla2ZcVaai59truiVolgAAAFI"]
[Sun Aug 30 03:10:19.800804 2026] [security2:error] [pid 515259:tid 515473] [client 158.23.147.79:43861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/languages/about.php"] [unique_id "apPla2ZcVaai59truiVomAAAAFM"]
[Sun Aug 30 03:10:19.853563 2026] [security2:error] [pid 515259:tid 515480] [client 20.48.250.41:17246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/wp-act.php"] [unique_id "apPla2ZcVaai59truiVooQAAAFo"]
[Sun Aug 30 03:10:19.854912 2026] [security2:error] [pid 515259:tid 515397] [client 20.48.251.3:33306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/configuration.php"] [unique_id "apPla2ZcVaai59truiVoogAAAAc"]
[Sun Aug 30 03:10:19.861884 2026] [security2:error] [pid 515259:tid 515474] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/rest/.env"] [unique_id "apPla2ZcVaai59truiVopAAAAFQ"]
[Sun Aug 30 03:10:19.865676 2026] [security2:error] [pid 515259:tid 515438] [client 20.63.81.20:31634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp-includes/ID3/getid.php"] [unique_id "apPla2ZcVaai59truiVopwAAADA"]
[Sun Aug 30 03:10:19.871813 2026] [authz_core:error] [pid 515259:tid 515396] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:19.872091 2026] [authz_core:error] [pid 515259:tid 515396] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:19.882838 2026] [security2:error] [pid 515259:tid 515499] [client 20.104.50.220:29568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/cok.php"] [unique_id "apPla2ZcVaai59truiVorAAAAG0"]
[Sun Aug 30 03:10:19.885883 2026] [authz_core:error] [pid 515259:tid 515456] [client 66.249.66.67:44407] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:19.886170 2026] [authz_core:error] [pid 515259:tid 515456] [client 66.249.66.67:44407] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:19.908515 2026] [security2:error] [pid 515259:tid 515406] [client 20.104.49.130:54171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/albin.php"] [unique_id "apPla2ZcVaai59truiVosAAAABA"]
[Sun Aug 30 03:10:19.911895 2026] [security2:error] [pid 515259:tid 515443] [client 20.48.160.90:63885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/ta.php"] [unique_id "apPla2ZcVaai59truiVosQAAADU"]
[Sun Aug 30 03:10:19.920870 2026] [security2:error] [pid 515259:tid 515425] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/graphql/.env"] [unique_id "apPla2ZcVaai59truiVotAAAACM"]
[Sun Aug 30 03:10:19.934122 2026] [security2:error] [pid 515259:tid 515410] [client 20.104.18.15:22486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/ws85.php"] [unique_id "apPla2ZcVaai59truiVotgAAABQ"]
[Sun Aug 30 03:10:19.951948 2026] [security2:error] [pid 515259:tid 515495] [client 4.205.62.107:64467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/wp-konfig.backup.php"] [unique_id "apPla2ZcVaai59truiVotwAAAGk"]
[Sun Aug 30 03:10:19.960511 2026] [security2:error] [pid 515259:tid 515393] [client 20.104.49.130:53678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/wen.php"] [unique_id "apPla2ZcVaai59truiVouAAAAAM"]
[Sun Aug 30 03:10:19.977090 2026] [security2:error] [pid 515259:tid 515461] [client 20.104.18.15:43999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/dapa.php"] [unique_id "apPla2ZcVaai59truiVovwAAAEc"]
[Sun Aug 30 03:10:19.980094 2026] [security2:error] [pid 515259:tid 515413] [client 20.104.18.15:18368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/akismet.php"] [unique_id "apPla2ZcVaai59truiVowQAAABc"]
[Sun Aug 30 03:10:19.982680 2026] [security2:error] [pid 515259:tid 515467] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/gateway/.env"] [unique_id "apPla2ZcVaai59truiVowwAAAE0"]
[Sun Aug 30 03:10:19.996226 2026] [security2:error] [pid 515259:tid 515435] [client 20.63.81.20:31631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/session.php"] [unique_id "apPla2ZcVaai59truiVozAAAAC0"]
[Sun Aug 30 03:10:19.997692 2026] [security2:error] [pid 515259:tid 515446] [client 20.48.250.41:17322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/24.php"] [unique_id "apPla2ZcVaai59truiVozQAAADg"]
[Sun Aug 30 03:10:20.024296 2026] [security2:error] [pid 515259:tid 515514] [client 68.155.159.216:45914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-admin/css/index.php"] [unique_id "apPlbGZcVaai59truiVo0AAAAHw"]
[Sun Aug 30 03:10:20.036506 2026] [security2:error] [pid 515259:tid 515470] [client 20.151.200.44:40923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/ssh3ll.php"] [unique_id "apPlbGZcVaai59truiVo1AAAAFA"]
[Sun Aug 30 03:10:20.043718 2026] [security2:error] [pid 515259:tid 515391] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/microservice/.env"] [unique_id "apPlbGZcVaai59truiVo1QAAAAE"]
[Sun Aug 30 03:10:20.047337 2026] [security2:error] [pid 515259:tid 515422] [client 68.155.159.216:52549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/content.php"] [unique_id "apPlbGZcVaai59truiVo1wAAACA"]
[Sun Aug 30 03:10:20.063937 2026] [security2:error] [pid 515259:tid 515416] [client 20.104.50.220:42807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-raze.php"] [unique_id "apPlbGZcVaai59truiVo2gAAABo"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:10:20.095748 2026] [authz_core:error] [pid 515259:tid 515438] [client 216.73.216.128:30028] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:20.096023 2026] [authz_core:error] [pid 515259:tid 515438] [client 216.73.216.128:30028] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:20.096319 2026] [security2:error] [pid 515259:tid 515499] [client 20.104.50.220:5568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/symlink.php"] [unique_id "apPlbGZcVaai59truiVo5AAAAG0"]
[Sun Aug 30 03:10:20.097079 2026] [security2:error] [pid 515259:tid 515469] [client 20.104.50.220:61693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/phpinfo.php"] [unique_id "apPlbGZcVaai59truiVo5QAAAE8"]
[Sun Aug 30 03:10:20.121928 2026] [security2:error] [pid 515259:tid 515444] [client 20.63.81.20:31560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/eagle.php"] [unique_id "apPlbGZcVaai59truiVo6AAAADY"]
[Sun Aug 30 03:10:20.121928 2026] [security2:error] [pid 515259:tid 515506] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/service/.env"] [unique_id "apPlbGZcVaai59truiVo5wAAAHQ"]
[Sun Aug 30 03:10:20.146551 2026] [security2:error] [pid 515259:tid 515425] [client 20.48.160.90:61435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/bo.php"] [unique_id "apPlbGZcVaai59truiVo7QAAACM"]
[Sun Aug 30 03:10:20.146579 2026] [security2:error] [pid 515259:tid 515408] [client 20.104.49.130:52122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/Jcrop.php"] [unique_id "apPlbGZcVaai59truiVo7AAAABI"]
[Sun Aug 30 03:10:20.152975 2026] [security2:error] [pid 515259:tid 515477] [client 20.48.250.41:17394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/155.php"] [unique_id "apPlbGZcVaai59truiVo7gAAAFc"]
[Sun Aug 30 03:10:20.180016 2026] [security2:error] [pid 515259:tid 515393] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/api/v3/.env"] [unique_id "apPlbGZcVaai59truiVo9AAAAAM"]
[Sun Aug 30 03:10:20.241087 2026] [security2:error] [pid 515259:tid 515460] [client 20.48.251.3:65516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/paths.php"] [unique_id "apPlbGZcVaai59truiVpAgAAAEY"]
[Sun Aug 30 03:10:20.247584 2026] [security2:error] [pid 515259:tid 515475] [client 20.63.81.20:31553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/up-kon.php"] [unique_id "apPlbGZcVaai59truiVpAwAAAFU"]
[Sun Aug 30 03:10:20.253057 2026] [security2:error] [pid 515259:tid 515435] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/api/dev/.env"] [unique_id "apPlbGZcVaai59truiVpBAAAAC0"]
[Sun Aug 30 03:10:20.280551 2026] [security2:error] [pid 515259:tid 515441] [client 20.220.10.235:5124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlbGZcVaai59truiVpCQAAADM"]
[Sun Aug 30 03:10:20.281002 2026] [security2:error] [pid 515259:tid 515479] [client 20.48.250.41:17312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/file.php"] [unique_id "apPlbGZcVaai59truiVpCgAAAFk"]
[Sun Aug 30 03:10:20.303598 2026] [security2:error] [pid 515259:tid 515407] [client 20.48.160.90:63905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/44.php"] [unique_id "apPlbGZcVaai59truiVpEwAAABE"]
[Sun Aug 30 03:10:20.313626 2026] [security2:error] [pid 515259:tid 515426] [client 20.104.49.130:64068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/menu.php"] [unique_id "apPlbGZcVaai59truiVpFAAAACQ"]
[Sun Aug 30 03:10:20.314022 2026] [security2:error] [pid 515259:tid 515422] [client 68.155.159.216:62650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/admin.php"] [unique_id "apPlbGZcVaai59truiVpFQAAACA"]
[Sun Aug 30 03:10:20.315741 2026] [security2:error] [pid 515259:tid 515399] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/api/staging/.env"] [unique_id "apPlbGZcVaai59truiVpFwAAAAk"]
[Sun Aug 30 03:10:20.345930 2026] [security2:error] [pid 515259:tid 515424] [client 158.23.147.79:52244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/banners/about.php"] [unique_id "apPlbGZcVaai59truiVpHAAAACI"]
[Sun Aug 30 03:10:20.374774 2026] [security2:error] [pid 515259:tid 515481] [client 20.104.49.130:60936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/zoo2.php"] [unique_id "apPlbGZcVaai59truiVpIQAAAFs"]
[Sun Aug 30 03:10:20.375956 2026] [security2:error] [pid 515259:tid 515466] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/vendor/.env"] [unique_id "apPlbGZcVaai59truiVpIAAAAEw"]
[Sun Aug 30 03:10:20.377965 2026] [security2:error] [pid 515259:tid 515496] [client 20.63.81.20:31552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/tinny.php"] [unique_id "apPlbGZcVaai59truiVpJAAAAGo"]
[Sun Aug 30 03:10:20.384624 2026] [authz_core:error] [pid 515259:tid 515474] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:20.385072 2026] [authz_core:error] [pid 515259:tid 515474] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:20.398495 2026] [security2:error] [pid 515259:tid 515406] [client 4.205.62.107:25494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/05.php"] [unique_id "apPlbGZcVaai59truiVpKQAAABA"]
[Sun Aug 30 03:10:20.410781 2026] [security2:error] [pid 515259:tid 515493] [client 20.48.250.41:17340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPlbGZcVaai59truiVpLQAAAGc"]
[Sun Aug 30 03:10:20.415893 2026] [security2:error] [pid 515259:tid 515497] [client 20.104.50.220:52816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/dm.php"] [unique_id "apPlbGZcVaai59truiVpLgAAAGs"]
[Sun Aug 30 03:10:20.437062 2026] [security2:error] [pid 515259:tid 515452] [client 20.104.50.220:31171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/uwu.php"] [unique_id "apPlbGZcVaai59truiVpMgAAAD4"]
[Sun Aug 30 03:10:20.449816 2026] [security2:error] [pid 515259:tid 515423] [client 20.104.49.130:52102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPlbGZcVaai59truiVpNwAAACE"]
[Sun Aug 30 03:10:20.452227 2026] [security2:error] [pid 515259:tid 515403] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/lib/.env"] [unique_id "apPlbGZcVaai59truiVpOQAAAA0"]
[Sun Aug 30 03:10:20.459187 2026] [security2:error] [pid 515259:tid 515461] [client 20.48.160.90:63914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/h2.php"] [unique_id "apPlbGZcVaai59truiVpPQAAAEc"]
[Sun Aug 30 03:10:20.459318 2026] [security2:error] [pid 515259:tid 515439] [client 20.220.10.235:5250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlbGZcVaai59truiVpPgAAADE"]
[Sun Aug 30 03:10:20.475053 2026] [security2:error] [pid 515259:tid 515503] [client 20.151.200.44:40845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/motu.php"] [unique_id "apPlbGZcVaai59truiVpQQAAAHE"]
[Sun Aug 30 03:10:20.485568 2026] [security2:error] [pid 515259:tid 515411] [client 158.23.147.79:60199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/file88.php"] [unique_id "apPlbGZcVaai59truiVpQgAAABU"]
[Sun Aug 30 03:10:20.497738 2026] [authz_core:error] [pid 515259:tid 515420] [client 66.249.66.75:39797] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:20.498020 2026] [authz_core:error] [pid 515259:tid 515420] [client 66.249.66.75:39797] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:20.507540 2026] [security2:error] [pid 515259:tid 515396] [client 20.63.81.20:31733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp-easy.php"] [unique_id "apPlbGZcVaai59truiVpRAAAAAY"]
[Sun Aug 30 03:10:20.514825 2026] [security2:error] [pid 515259:tid 515394] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/resources/.env"] [unique_id "apPlbGZcVaai59truiVpRgAAAAQ"]
[Sun Aug 30 03:10:20.523763 2026] [security2:error] [pid 515259:tid 515430] [client 20.151.200.44:28565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/cy.php"] [unique_id "apPlbGZcVaai59truiVpSQAAACg"]
[Sun Aug 30 03:10:20.531835 2026] [security2:error] [pid 515259:tid 515472] [client 4.205.62.107:36689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/u88.php"] [unique_id "apPlbGZcVaai59truiVpTAAAAFI"]
[Sun Aug 30 03:10:20.553894 2026] [security2:error] [pid 515259:tid 515426] [client 20.48.250.41:17235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/06.php"] [unique_id "apPlbGZcVaai59truiVpUwAAACQ"]
[Sun Aug 30 03:10:20.560602 2026] [security2:error] [pid 515259:tid 515458] [client 20.104.49.130:59556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/v2.php"] [unique_id "apPlbGZcVaai59truiVpVgAAAEQ"]
[Sun Aug 30 03:10:20.575495 2026] [security2:error] [pid 515259:tid 515473] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/assets/.env"] [unique_id "apPlbGZcVaai59truiVpWQAAAFM"]
[Sun Aug 30 03:10:20.586551 2026] [security2:error] [pid 515259:tid 515496] [client 20.104.49.130:53641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/ws85.php"] [unique_id "apPlbGZcVaai59truiVpXAAAAGo"]
[Sun Aug 30 03:10:20.597610 2026] [authz_core:error] [pid 515259:tid 515446] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:20.598056 2026] [authz_core:error] [pid 515259:tid 515446] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:20.599868 2026] [security2:error] [pid 515259:tid 515444] [client 20.48.160.90:61382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apPlbGZcVaai59truiVpYgAAADY"]
[Sun Aug 30 03:10:20.616001 2026] [authz_core:error] [pid 515259:tid 515442] [client 66.249.66.67:62094] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:20.616296 2026] [authz_core:error] [pid 515259:tid 515442] [client 66.249.66.67:62094] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:20.645471 2026] [security2:error] [pid 515259:tid 515410] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/uploads/.env"] [unique_id "apPlbGZcVaai59truiVpbAAAABQ"]
[Sun Aug 30 03:10:20.650115 2026] [security2:error] [pid 515259:tid 515459] [client 20.63.81.20:31575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/d7.php"] [unique_id "apPlbGZcVaai59truiVpbgAAAEU"]
[Sun Aug 30 03:10:20.652626 2026] [security2:error] [pid 515259:tid 515501] [client 20.220.10.235:5816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/h02ugyh.php"] [unique_id "apPlbGZcVaai59truiVpbwAAAG8"]
[Sun Aug 30 03:10:20.705212 2026] [security2:error] [pid 515259:tid 515494] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/internal/.env"] [unique_id "apPlbGZcVaai59truiVpdwAAAGg"]
[Sun Aug 30 03:10:20.712399 2026] [security2:error] [pid 515259:tid 515429] [client 20.48.250.41:17378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/class.php"] [unique_id "apPlbGZcVaai59truiVpeQAAACc"]
[Sun Aug 30 03:10:20.730970 2026] [authz_core:error] [pid 515259:tid 515394] [client 216.73.216.128:41694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:20.731268 2026] [authz_core:error] [pid 515259:tid 515394] [client 216.73.216.128:41694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:20.733625 2026] [security2:error] [pid 515259:tid 515430] [client 20.48.160.90:37575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/sao.php"] [unique_id "apPlbGZcVaai59truiVpfAAAACg"]
[Sun Aug 30 03:10:20.745669 2026] [security2:error] [pid 515259:tid 515478] [client 184.154.76.13:45810] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "dejulschoolofdance.com"] [uri "/wp-content/plugins/contact-form-7/readme.txt"] [unique_id "apPlbGZcVaai59truiVpgAAAAFg"]
[Sun Aug 30 03:10:20.745811 2026] [security2:error] [pid 515259:tid 515478] [client 184.154.76.13:45810] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dejulschoolofdance.com"] [uri "/wp-content/plugins/contact-form-7/readme.txt"] [unique_id "apPlbGZcVaai59truiVpgAAAAFg"]
[Sun Aug 30 03:10:20.746103 2026] [security2:error] [pid 515259:tid 515500] [client 20.104.50.220:16962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/about.php"] [unique_id "apPlbGZcVaai59truiVpfwAAAG4"]
[Sun Aug 30 03:10:20.756478 2026] [security2:error] [pid 515259:tid 515407] [client 20.104.18.15:64034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/packed.php"] [unique_id "apPlbGZcVaai59truiVpggAAABE"]
[Sun Aug 30 03:10:20.756794 2026] [security2:error] [pid 515259:tid 515400] [client 20.104.49.130:64066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/wp-the.php"] [unique_id "apPlbGZcVaai59truiVpgwAAAAo"]
[Sun Aug 30 03:10:20.764879 2026] [security2:error] [pid 515259:tid 515414] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/tools/.env"] [unique_id "apPlbGZcVaai59truiVphQAAABg"]
[Sun Aug 30 03:10:20.766921 2026] [security2:error] [pid 515259:tid 515507] [client 20.104.18.15:35184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/wp-includes/ID3/moon.php"] [unique_id "apPlbGZcVaai59truiVphwAAAHU"]
[Sun Aug 30 03:10:20.771371 2026] [security2:error] [pid 515259:tid 515398] [client 20.48.251.3:52810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/file21.php"] [unique_id "apPlbGZcVaai59truiVpiQAAAAg"]
[Sun Aug 30 03:10:20.774784 2026] [security2:error] [pid 515259:tid 515419] [client 20.151.200.44:40851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/wefile.php"] [unique_id "apPlbGZcVaai59truiVpjgAAAB0"]
[Sun Aug 30 03:10:20.779170 2026] [security2:error] [pid 515259:tid 515457] [client 4.205.62.107:17674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/hiquido.com/index.php"] [unique_id "apPlbGZcVaai59truiVpkAAAAEM"]
[Sun Aug 30 03:10:20.785861 2026] [security2:error] [pid 515259:tid 515485] [client 20.63.81.20:31697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/v5.php"] [unique_id "apPlbGZcVaai59truiVplQAAAF8"]
[Sun Aug 30 03:10:20.824251 2026] [security2:error] [pid 515259:tid 515425] [client 158.23.147.79:52275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apPlbGZcVaai59truiVpmwAAACM"]
[Sun Aug 30 03:10:20.825197 2026] [security2:error] [pid 515259:tid 515483] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/scripts/.env"] [unique_id "apPlbGZcVaai59truiVpnAAAAF0"]
[Sun Aug 30 03:10:20.862338 2026] [authz_core:error] [pid 515259:tid 515459] [client 66.249.66.71:43784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:20.862609 2026] [security2:error] [pid 515259:tid 515486] [client 20.48.251.3:59847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/ws79.php"] [unique_id "apPlbGZcVaai59truiVpoQAAAGA"]
[Sun Aug 30 03:10:20.862682 2026] [authz_core:error] [pid 515259:tid 515459] [client 66.249.66.71:43784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:20.866939 2026] [security2:error] [pid 515259:tid 515461] [client 20.48.250.41:17307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/8.php"] [unique_id "apPlbGZcVaai59truiVpowAAAEc"]
[Sun Aug 30 03:10:20.869301 2026] [security2:error] [pid 515259:tid 515432] [client 20.48.160.90:61319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/dapa.php"] [unique_id "apPlbGZcVaai59truiVppAAAACo"]
[Sun Aug 30 03:10:20.880296 2026] [security2:error] [pid 515259:tid 515427] [client 20.220.10.235:5858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/sf.php"] [unique_id "apPlbGZcVaai59truiVppQAAACU"]
[Sun Aug 30 03:10:20.885921 2026] [security2:error] [pid 515259:tid 515412] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/bin/.env"] [unique_id "apPlbGZcVaai59truiVppgAAABY"]
[Sun Aug 30 03:10:20.889991 2026] [security2:error] [pid 515259:tid 515443] [client 20.104.49.130:52134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/155.php"] [unique_id "apPlbGZcVaai59truiVpqAAAADU"]
[Sun Aug 30 03:10:20.899849 2026] [authz_core:error] [pid 515259:tid 515475] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:20.900335 2026] [authz_core:error] [pid 515259:tid 515475] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:20.900628 2026] [security2:error] [pid 515259:tid 515408] [client 20.104.49.130:53789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/media.php"] [unique_id "apPlbGZcVaai59truiVpqgAAABI"]
[Sun Aug 30 03:10:20.905308 2026] [security2:error] [pid 515259:tid 515393] [client 20.104.18.15:64733] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/1.php"] [unique_id "apPlbGZcVaai59truiVprgAAAAM"]
[Sun Aug 30 03:10:20.905405 2026] [security2:error] [pid 515259:tid 515393] [client 20.104.18.15:64733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/1.php"] [unique_id "apPlbGZcVaai59truiVprgAAAAM"]
[Sun Aug 30 03:10:20.905567 2026] [security2:error] [pid 515259:tid 515509] [client 216.73.216.128:30028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/images/tips.html"] [unique_id "apPlbGZcVaai59truiVprwAAAHc"]
[Sun Aug 30 03:10:20.911537 2026] [security2:error] [pid 515259:tid 515489] [client 20.104.50.220:33333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/av.php"] [unique_id "apPlbGZcVaai59truiVpsQAAAGM"]
[Sun Aug 30 03:10:20.921348 2026] [security2:error] [pid 515259:tid 515494] [client 20.63.81.20:31659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/az.php"] [unique_id "apPlbGZcVaai59truiVptgAAAGg"]
[Sun Aug 30 03:10:20.944732 2026] [security2:error] [pid 515259:tid 515467] [client 184.154.76.13:45812] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "dejulschoolofdance.com"] [uri "/wp-content/plugins/ocean-extra/readme.txt"] [unique_id "apPlbGZcVaai59truiVpugAAAE0"]
[Sun Aug 30 03:10:20.944854 2026] [security2:error] [pid 515259:tid 515467] [client 184.154.76.13:45812] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dejulschoolofdance.com"] [uri "/wp-content/plugins/ocean-extra/readme.txt"] [unique_id "apPlbGZcVaai59truiVpugAAAE0"]
[Sun Aug 30 03:10:20.945961 2026] [security2:error] [pid 515259:tid 515439] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/sbin/.env"] [unique_id "apPlbGZcVaai59truiVpuQAAADE"]
[Sun Aug 30 03:10:20.965651 2026] [security2:error] [pid 515259:tid 515407] [client 20.151.200.44:40937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/Contrller.php"] [unique_id "apPlbGZcVaai59truiVpvAAAABE"]
[Sun Aug 30 03:10:20.969175 2026] [security2:error] [pid 515259:tid 515498] [client 20.197.61.180:16876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/data.php"] [unique_id "apPlbGZcVaai59truiVpvgAAAGw"]
[Sun Aug 30 03:10:21.004404 2026] [security2:error] [pid 515259:tid 515433] [client 20.48.160.90:63908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/wp-content/l.php"] [unique_id "apPlbWZcVaai59truiVpxgAAACs"]
[Sun Aug 30 03:10:21.007792 2026] [security2:error] [pid 515259:tid 515496] [client 20.48.251.3:56353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/server_info.php"] [unique_id "apPlbWZcVaai59truiVpyAAAAGo"]
[Sun Aug 30 03:10:21.010656 2026] [security2:error] [pid 515259:tid 515421] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/local/.env"] [unique_id "apPlbWZcVaai59truiVpyQAAAB8"]
[Sun Aug 30 03:10:21.016749 2026] [security2:error] [pid 515259:tid 515424] [client 20.48.250.41:17299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/0x0x.php"] [unique_id "apPlbWZcVaai59truiVpzAAAACI"]
[Sun Aug 30 03:10:21.018777 2026] [security2:error] [pid 515259:tid 515466] [client 20.104.50.220:62806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/cgipro.php"] [unique_id "apPlbWZcVaai59truiVpzQAAAEw"]
[Sun Aug 30 03:10:21.020517 2026] [security2:error] [pid 515259:tid 515458] [client 20.104.49.130:64104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/fs.php"] [unique_id "apPlbWZcVaai59truiVpzgAAAEQ"]
[Sun Aug 30 03:10:21.047149 2026] [security2:error] [pid 515259:tid 515493] [client 20.63.81.20:31734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/js.php"] [unique_id "apPlbWZcVaai59truiVp0gAAAGc"]
[Sun Aug 30 03:10:21.068794 2026] [security2:error] [pid 515259:tid 515484] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/portal/.env"] [unique_id "apPlbWZcVaai59truiVp1gAAAF4"]
[Sun Aug 30 03:10:21.094621 2026] [security2:error] [pid 515259:tid 515443] [client 4.205.62.107:61778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/packed.php"] [unique_id "apPlbWZcVaai59truiVp4AAAADU"]
[Sun Aug 30 03:10:21.094720 2026] [authz_core:error] [pid 515259:tid 515432] [client 216.73.216.128:41694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:21.095037 2026] [authz_core:error] [pid 515259:tid 515432] [client 216.73.216.128:41694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:21.100404 2026] [security2:error] [pid 515259:tid 515408] [client 20.104.18.15:22425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/ffs.php"] [unique_id "apPlbWZcVaai59truiVp4QAAABI"]
[Sun Aug 30 03:10:21.114089 2026] [security2:error] [pid 515259:tid 515456] [client 20.104.18.15:43926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/wp-content/l.php"] [unique_id "apPlbWZcVaai59truiVp4gAAAEI"]
[Sun Aug 30 03:10:21.119833 2026] [security2:error] [pid 515259:tid 515418] [client 20.104.18.15:18357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/ajax.php"] [unique_id "apPlbWZcVaai59truiVp5AAAABw"]
[Sun Aug 30 03:10:21.129544 2026] [security2:error] [pid 515259:tid 515474] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/dashboard/.env"] [unique_id "apPlbWZcVaai59truiVp5QAAAFQ"]
[Sun Aug 30 03:10:21.140022 2026] [security2:error] [pid 515259:tid 515506] [client 184.154.76.13:45818] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "dejulschoolofdance.com"] [uri "/wp-content/plugins/elementor/readme.txt"] [unique_id "apPlbWZcVaai59truiVp6QAAAHQ"]
[Sun Aug 30 03:10:21.140126 2026] [security2:error] [pid 515259:tid 515506] [client 184.154.76.13:45818] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dejulschoolofdance.com"] [uri "/wp-content/plugins/elementor/readme.txt"] [unique_id "apPlbWZcVaai59truiVp6QAAAHQ"]
[Sun Aug 30 03:10:21.145084 2026] [security2:error] [pid 515259:tid 515395] [client 195.178.110.247:6062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confuzal.suprensa.com"] [uri "/index.php"] [unique_id "apPlbWZcVaai59truiVp6wAAAAU"]
[Sun Aug 30 03:10:21.145862 2026] [security2:error] [pid 515259:tid 515472] [client 20.220.10.235:5792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/4e.php"] [unique_id "apPlbWZcVaai59truiVp7AAAAFI"]
[Sun Aug 30 03:10:21.152955 2026] [security2:error] [pid 515259:tid 515417] [client 20.104.49.130:53699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/kgoc6awap3napxxxdCdefault.php"] [unique_id "apPlbWZcVaai59truiVp7gAAABs"]
[Sun Aug 30 03:10:21.168780 2026] [security2:error] [pid 515259:tid 515431] [client 20.48.250.41:17406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/166.php"] [unique_id "apPlbWZcVaai59truiVp7wAAACk"]
[Sun Aug 30 03:10:21.173154 2026] [security2:error] [pid 515259:tid 515478] [client 20.63.81.20:31639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/hd.php"] [unique_id "apPlbWZcVaai59truiVp8AAAAFg"]
[Sun Aug 30 03:10:21.188912 2026] [security2:error] [pid 515259:tid 515467] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/panel/.env"] [unique_id "apPlbWZcVaai59truiVp8gAAAE0"]
[Sun Aug 30 03:10:21.217229 2026] [security2:error] [pid 515259:tid 515420] [client 68.155.159.216:52545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPlbWZcVaai59truiVp9gAAAB4"]
[Sun Aug 30 03:10:21.223854 2026] [security2:error] [pid 515259:tid 515492] [client 20.104.50.220:42003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-init.php"] [unique_id "apPlbWZcVaai59truiVp9wAAAGY"]
[Sun Aug 30 03:10:21.229264 2026] [security2:error] [pid 515259:tid 515416] [client 20.48.160.90:63986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/wp-admin/w.php"] [unique_id "apPlbWZcVaai59truiVp-QAAABo"]
[Sun Aug 30 03:10:21.231853 2026] [authz_core:error] [pid 515259:tid 515400] [client 66.249.66.34:48430] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:21.232127 2026] [authz_core:error] [pid 515259:tid 515400] [client 66.249.66.34:48430] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:21.243140 2026] [security2:error] [pid 515259:tid 515479] [client 20.104.50.220:6105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/sym403.php"] [unique_id "apPlbWZcVaai59truiVp_AAAAFk"]
[Sun Aug 30 03:10:21.259215 2026] [security2:error] [pid 515259:tid 515496] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/crm/.env"] [unique_id "apPlbWZcVaai59truiVqAAAAAGo"]
[Sun Aug 30 03:10:21.292275 2026] [security2:error] [pid 515259:tid 515475] [client 20.104.50.220:61989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/postfs.php"] [unique_id "apPlbWZcVaai59truiVqBwAAAFU"]
[Sun Aug 30 03:10:21.293134 2026] [security2:error] [pid 515259:tid 515458] [client 20.104.49.130:52123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/ms-edit.php"] [unique_id "apPlbWZcVaai59truiVqCAAAAEQ"]
[Sun Aug 30 03:10:21.297317 2026] [security2:error] [pid 515259:tid 515448] [client 195.178.110.247:14610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "confuzal.suprensa.com"] [uri "/index.php"] [unique_id "apPlbWZcVaai59truiVqCgAAADo"]
[Sun Aug 30 03:10:21.301723 2026] [security2:error] [pid 515259:tid 515511] [client 20.63.81.20:31574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/xl2023.php"] [unique_id "apPlbWZcVaai59truiVqDAAAAHk"]
[Sun Aug 30 03:10:21.309883 2026] [security2:error] [pid 515259:tid 515476] [client 158.23.147.79:60166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/NewFile.php/"] [unique_id "apPlbWZcVaai59truiVqDQAAAFY"]
[Sun Aug 30 03:10:21.318796 2026] [security2:error] [pid 515259:tid 515391] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/erp/.env"] [unique_id "apPlbWZcVaai59truiVqDgAAAAE"]
[Sun Aug 30 03:10:21.325284 2026] [security2:error] [pid 515259:tid 515483] [client 20.48.250.41:17388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/h2a2ck.php"] [unique_id "apPlbWZcVaai59truiVqEAAAAF0"]
[Sun Aug 30 03:10:21.328941 2026] [security2:error] [pid 515259:tid 515484] [client 20.220.10.235:5292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/ssss.php"] [unique_id "apPlbWZcVaai59truiVqEQAAAF4"]
[Sun Aug 30 03:10:21.374224 2026] [security2:error] [pid 515259:tid 515470] [client 68.155.159.216:45900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-admin/images/index.php"] [unique_id "apPlbWZcVaai59truiVqEwAAAFA"]
[Sun Aug 30 03:10:21.375242 2026] [security2:error] [pid 515259:tid 515452] [client 20.48.251.3:54804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/olfclass.php"] [unique_id "apPlbWZcVaai59truiVqFAAAAD4"]
[Sun Aug 30 03:10:21.381336 2026] [security2:error] [pid 515259:tid 515460] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/shop/.env"] [unique_id "apPlbWZcVaai59truiVqFQAAAEY"]
[Sun Aug 30 03:10:21.381565 2026] [authz_core:error] [pid 515259:tid 515461] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:21.381963 2026] [authz_core:error] [pid 515259:tid 515461] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:21.411072 2026] [security2:error] [pid 515259:tid 515443] [client 216.73.216.128:47291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlbWZcVaai59truiVqGQAAADU"]
[Sun Aug 30 03:10:21.422183 2026] [security2:error] [pid 515259:tid 515394] [client 68.155.159.216:63276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-admin/admin.php"] [unique_id "apPlbWZcVaai59truiVqGgAAAAQ"]
[Sun Aug 30 03:10:21.429781 2026] [security2:error] [pid 515259:tid 515456] [client 20.63.81.20:31688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/V2.php"] [unique_id "apPlbWZcVaai59truiVqHAAAAEI"]
[Sun Aug 30 03:10:21.442881 2026] [security2:error] [pid 515259:tid 515453] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/store/.env"] [unique_id "apPlbWZcVaai59truiVqHgAAAD8"]
[Sun Aug 30 03:10:21.446516 2026] [security2:error] [pid 515259:tid 515474] [client 20.48.160.90:61349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/wp-content/k.php"] [unique_id "apPlbWZcVaai59truiVqIQAAAFQ"]
[Sun Aug 30 03:10:21.448553 2026] [security2:error] [pid 515259:tid 515477] [client 20.104.49.130:64109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/tool.php"] [unique_id "apPlbWZcVaai59truiVqIgAAAFc"]
[Sun Aug 30 03:10:21.502433 2026] [security2:error] [pid 515259:tid 515431] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/saas/.env"] [unique_id "apPlbWZcVaai59truiVqKAAAACk"]
[Sun Aug 30 03:10:21.534440 2026] [security2:error] [pid 515259:tid 515487] [client 20.48.250.41:17306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/error_log.php"] [unique_id "apPlbWZcVaai59truiVqLQAAAGE"]
[Sun Aug 30 03:10:21.537537 2026] [security2:error] [pid 515259:tid 515432] [client 20.220.10.235:5804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/zoz.php"] [unique_id "apPlbWZcVaai59truiVqLgAAACo"]
[Sun Aug 30 03:10:21.559760 2026] [security2:error] [pid 515259:tid 515498] [client 20.63.81.20:31567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/mad.php"] [unique_id "apPlbWZcVaai59truiVqMAAAAGw"]
[Sun Aug 30 03:10:21.563389 2026] [security2:error] [pid 515259:tid 515390] [client 4.205.62.107:25502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/wp-blog.php"] [unique_id "apPlbWZcVaai59truiVqMQAAAAA"]
[Sun Aug 30 03:10:21.564705 2026] [security2:error] [pid 515259:tid 515515] [client 158.23.147.79:1996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/cong.php"] [unique_id "apPlbWZcVaai59truiVqMgAAAH0"]
[Sun Aug 30 03:10:21.567998 2026] [security2:error] [pid 515259:tid 515507] [client 20.104.50.220:29140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/gator.php"] [unique_id "apPlbWZcVaai59truiVqMwAAAHU"]
[Sun Aug 30 03:10:21.601921 2026] [security2:error] [pid 515259:tid 515392] [client 20.104.49.130:53690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/abc.php"] [unique_id "apPlbWZcVaai59truiVqPQAAAAI"]
[Sun Aug 30 03:10:21.606073 2026] [security2:error] [pid 515259:tid 515424] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/client/.env"] [unique_id "apPlbWZcVaai59truiVqPwAAACI"]
[Sun Aug 30 03:10:21.606225 2026] [security2:error] [pid 515259:tid 515475] [client 20.104.50.220:63204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/uwa.php"] [unique_id "apPlbWZcVaai59truiVqQAAAAFU"]
[Sun Aug 30 03:10:21.645969 2026] [security2:error] [pid 515259:tid 515401] [client 158.23.147.79:52266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/asd.php"] [unique_id "apPlbWZcVaai59truiVqRAAAAAs"]
[Sun Aug 30 03:10:21.663954 2026] [authz_core:error] [pid 515259:tid 515406] [client 66.249.66.68:62580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:21.664226 2026] [authz_core:error] [pid 515259:tid 515406] [client 66.249.66.68:62580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:21.664976 2026] [security2:error] [pid 515259:tid 515476] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/project/.env"] [unique_id "apPlbWZcVaai59truiVqSgAAAFY"]
[Sun Aug 30 03:10:21.667041 2026] [security2:error] [pid 515259:tid 515503] [client 20.151.200.44:40850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/file66.php"] [unique_id "apPlbWZcVaai59truiVqSwAAAHE"]
[Sun Aug 30 03:10:21.684513 2026] [security2:error] [pid 515259:tid 515512] [client 20.197.61.180:3643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/dt-the7/css/static-less/plugins/admin.php"] [unique_id "apPlbWZcVaai59truiVqTwAAAHo"]
[Sun Aug 30 03:10:21.688355 2026] [security2:error] [pid 515259:tid 515452] [client 20.48.250.41:17376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/403.php"] [unique_id "apPlbWZcVaai59truiVqUAAAAD4"]
[Sun Aug 30 03:10:21.689374 2026] [security2:error] [pid 515259:tid 515460] [client 20.63.81.20:31661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/st.php"] [unique_id "apPlbWZcVaai59truiVqUQAAAEY"]
[Sun Aug 30 03:10:21.698378 2026] [security2:error] [pid 515259:tid 515405] [client 20.48.160.90:31215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/os.php"] [unique_id "apPlbWZcVaai59truiVqUwAAAA8"]
[Sun Aug 30 03:10:21.723847 2026] [security2:error] [pid 515259:tid 515393] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/admin-panel/.env"] [unique_id "apPlbWZcVaai59truiVqVQAAAAM"]
[Sun Aug 30 03:10:21.734412 2026] [security2:error] [pid 515259:tid 515462] [client 20.104.49.130:64091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/ioxi-o.php"] [unique_id "apPlbWZcVaai59truiVqWAAAAEg"]
[Sun Aug 30 03:10:21.758948 2026] [security2:error] [pid 515259:tid 515409] [client 4.205.62.107:36566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/config/laravolt/css/index.php"] [unique_id "apPlbWZcVaai59truiVqWwAAABM"]
[Sun Aug 30 03:10:21.794308 2026] [security2:error] [pid 515259:tid 515363] [remote 103.138.189.49:53748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.189.138.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sixty4sixty.com"] [uri "/wp-login.php"] [unique_id "apPlbWZcVaai59truiVqYgAAfmY"]
[Sun Aug 30 03:10:21.803792 2026] [security2:error] [pid 515259:tid 515418] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/control-panel/.env"] [unique_id "apPlbWZcVaai59truiVqZQAAABw"]
[Sun Aug 30 03:10:21.819873 2026] [security2:error] [pid 515259:tid 515514] [client 20.63.81.20:31569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/alfanew.php"] [unique_id "apPlbWZcVaai59truiVqaAAAAHw"]
[Sun Aug 30 03:10:21.839373 2026] [security2:error] [pid 515259:tid 515504] [client 20.48.160.90:37611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/htio.php"] [unique_id "apPlbWZcVaai59truiVqagAAAHI"]
[Sun Aug 30 03:10:21.858812 2026] [authz_core:error] [pid 515259:tid 515515] [client 66.249.66.33:59777] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:21.859031 2026] [authz_core:error] [pid 515259:tid 515455] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:21.859080 2026] [authz_core:error] [pid 515259:tid 515515] [client 66.249.66.33:59777] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:21.859305 2026] [authz_core:error] [pid 515259:tid 515455] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:21.861514 2026] [security2:error] [pid 515259:tid 515492] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/user-panel/.env"] [unique_id "apPlbWZcVaai59truiVqbwAAAGY"]
[Sun Aug 30 03:10:21.878071 2026] [security2:error] [pid 515259:tid 515420] [client 20.104.49.130:52151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/bthil.php"] [unique_id "apPlbWZcVaai59truiVqcwAAAB4"]
[Sun Aug 30 03:10:21.881079 2026] [security2:error] [pid 515259:tid 515485] [client 20.104.50.220:16637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/alfa.php"] [unique_id "apPlbWZcVaai59truiVqdAAAAF8"]
[Sun Aug 30 03:10:21.885500 2026] [security2:error] [pid 515259:tid 515422] [client 20.104.18.15:16668] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.larb.info"] [uri "/wp-content/uploads/"] [unique_id "apPlbWZcVaai59truiVqdQAAACA"]
[Sun Aug 30 03:10:21.891167 2026] [security2:error] [pid 515259:tid 515439] [client 20.48.250.41:17371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/cytyr.php"] [unique_id "apPlbWZcVaai59truiVqdgAAADE"]
[Sun Aug 30 03:10:21.919603 2026] [security2:error] [pid 515259:tid 515475] [client 4.205.62.107:17673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/ws79.php"] [unique_id "apPlbWZcVaai59truiVqfAAAAFU"]
[Sun Aug 30 03:10:21.920900 2026] [security2:error] [pid 515259:tid 515517] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/node/.env"] [unique_id "apPlbWZcVaai59truiVqfgAAAH8"]
[Sun Aug 30 03:10:21.923944 2026] [security2:error] [pid 515259:tid 515466] [client 20.104.18.15:35194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/xmini4.php"] [unique_id "apPlbWZcVaai59truiVqfwAAAEw"]
[Sun Aug 30 03:10:21.926556 2026] [security2:error] [pid 515259:tid 515482] [client 20.48.251.3:55703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/mcebraed.php"] [unique_id "apPlbWZcVaai59truiVqgQAAAFw"]
[Sun Aug 30 03:10:21.933375 2026] [security2:error] [pid 515259:tid 515441] [client 20.220.10.235:5268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/kcs.php"] [unique_id "apPlbWZcVaai59truiVqhAAAADM"]
[Sun Aug 30 03:10:21.950438 2026] [security2:error] [pid 515259:tid 515512] [client 20.63.81.20:31580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/ioxi.php"] [unique_id "apPlbWZcVaai59truiVqhwAAAHo"]
[Sun Aug 30 03:10:21.976721 2026] [security2:error] [pid 515259:tid 515458] [client 20.48.160.90:63944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/dev.php"] [unique_id "apPlbWZcVaai59truiVqjAAAAEQ"]
[Sun Aug 30 03:10:21.986716 2026] [security2:error] [pid 515259:tid 515495] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/express/.env"] [unique_id "apPlbWZcVaai59truiVqjwAAAGk"]
[Sun Aug 30 03:10:21.994456 2026] [security2:error] [pid 515259:tid 515393] [client 216.244.66.238:49274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arcaneguardians.com"] [uri "/zgxgbcfh/notion-attendance-template"] [unique_id "apPlbWZcVaai59truiVqkgAAAAM"]
[Sun Aug 30 03:10:21.994549 2026] [security2:error] [pid 515259:tid 515393] [client 216.244.66.238:49274] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "arcaneguardians.com"] [uri "/zgxgbcfh/notion-attendance-template"] [unique_id "apPlbWZcVaai59truiVqkgAAAAM"]
[Sun Aug 30 03:10:22.005451 2026] [authz_core:error] [pid 515259:tid 515410] [client 216.73.216.128:62395] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:22.005740 2026] [authz_core:error] [pid 515259:tid 515410] [client 216.73.216.128:62395] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:22.005915 2026] [security2:error] [pid 515259:tid 515513] [client 20.104.49.130:64123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/xwx1.php"] [unique_id "apPlbmZcVaai59truiVqlwAAAHs"]
[Sun Aug 30 03:10:22.008762 2026] [security2:error] [pid 515259:tid 515423] [client 20.48.251.3:59513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/public/wp-blog.php"] [unique_id "apPlbmZcVaai59truiVqmQAAACE"]
[Sun Aug 30 03:10:22.018748 2026] [authz_core:error] [pid 515259:tid 515429] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:22.019161 2026] [authz_core:error] [pid 515259:tid 515429] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:22.024480 2026] [security2:error] [pid 515259:tid 515366] [remote 67.205.0.102:43714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.0.205.67.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-login.php"] [unique_id "apPlbmZcVaai59truiVqnAAAUmk"]
[Sun Aug 30 03:10:22.027042 2026] [authz_core:error] [pid 515259:tid 515421] [client 66.249.66.204:57991] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:22.027336 2026] [authz_core:error] [pid 515259:tid 515421] [client 66.249.66.204:57991] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:22.047088 2026] [security2:error] [pid 515259:tid 515505] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/next/.env"] [unique_id "apPlbmZcVaai59truiVqogAAAHM"]
[Sun Aug 30 03:10:22.059695 2026] [security2:error] [pid 515259:tid 515431] [client 20.104.18.15:16946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/samll.php"] [unique_id "apPlbmZcVaai59truiVqpwAAACk"]
[Sun Aug 30 03:10:22.064695 2026] [security2:error] [pid 515259:tid 515428] [client 20.104.50.220:33557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/upl.php"] [unique_id "apPlbmZcVaai59truiVqqQAAACY"]
[Sun Aug 30 03:10:22.075251 2026] [security2:error] [pid 515259:tid 515432] [client 20.63.81.20:31500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/TNT.php"] [unique_id "apPlbmZcVaai59truiVqqwAAACo"]
[Sun Aug 30 03:10:22.084431 2026] [security2:error] [pid 515259:tid 515479] [client 20.48.250.41:17341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/galer.php"] [unique_id "apPlbmZcVaai59truiVqrwAAAFk"]
[Sun Aug 30 03:10:22.105905 2026] [security2:error] [pid 515259:tid 515422] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/nuxt/.env"] [unique_id "apPlbmZcVaai59truiVqswAAACA"]
[Sun Aug 30 03:10:22.109437 2026] [security2:error] [pid 515259:tid 515439] [client 158.23.147.79:60202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/dropdown.php"] [unique_id "apPlbmZcVaai59truiVqtAAAADE"]
[Sun Aug 30 03:10:22.132605 2026] [security2:error] [pid 515259:tid 515444] [client 20.48.160.90:37572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/gos.php"] [unique_id "apPlbmZcVaai59truiVquQAAADY"]
[Sun Aug 30 03:10:22.142542 2026] [security2:error] [pid 515259:tid 515447] [client 20.48.251.3:60509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/hosty.php"] [unique_id "apPlbmZcVaai59truiVqvQAAADk"]
[Sun Aug 30 03:10:22.157370 2026] [security2:error] [pid 515259:tid 515369] [remote 103.138.189.49:53748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.189.138.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sixty4sixty.com"] [uri "/wp-login.php"] [unique_id "apPlbmZcVaai59truiVqwQAAXWw"], referer: https://sixty4sixty.com/wp-login.php
[Sun Aug 30 03:10:22.159051 2026] [security2:error] [pid 515259:tid 515449] [client 20.104.49.130:51081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/bolt.php"] [unique_id "apPlbmZcVaai59truiVqwgAAADs"]
[Sun Aug 30 03:10:22.167089 2026] [security2:error] [pid 515259:tid 515503] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/nest/.env"] [unique_id "apPlbmZcVaai59truiVqwwAAAHE"]
[Sun Aug 30 03:10:22.190354 2026] [security2:error] [pid 515259:tid 515396] [client 20.104.50.220:29144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/css.php"] [unique_id "apPlbmZcVaai59truiVqxwAAAAY"]
[Sun Aug 30 03:10:22.221767 2026] [security2:error] [pid 515259:tid 515427] [client 20.220.10.235:5820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/tajj.php"] [unique_id "apPlbmZcVaai59truiVqzwAAACU"]
[Sun Aug 30 03:10:22.225017 2026] [security2:error] [pid 515259:tid 515370] [remote 67.205.0.102:43714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.0.205.67.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tgifa.org"] [uri "/wp-login.php"] [unique_id "apPlbmZcVaai59truiVqzAAATm0"], referer: https://tgifa.org/wp-login.php
[Sun Aug 30 03:10:22.225919 2026] [security2:error] [pid 515259:tid 515460] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/react/.env"] [unique_id "apPlbmZcVaai59truiVq0QAAAEY"]
[Sun Aug 30 03:10:22.227540 2026] [security2:error] [pid 515259:tid 515450] [client 20.63.81.20:31577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/cd.php"] [unique_id "apPlbmZcVaai59truiVq0wAAADw"]
[Sun Aug 30 03:10:22.230308 2026] [security2:error] [pid 515259:tid 515434] [client 20.48.250.41:17303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/baixy.php"] [unique_id "apPlbmZcVaai59truiVq1gAAACw"]
[Sun Aug 30 03:10:22.233168 2026] [security2:error] [pid 515259:tid 515393] [client 20.104.18.15:22492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/nano.php"] [unique_id "apPlbmZcVaai59truiVq2QAAAAM"]
[Sun Aug 30 03:10:22.254797 2026] [security2:error] [pid 515259:tid 515408] [client 20.104.18.15:43293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/wp-admin/w.php"] [unique_id "apPlbmZcVaai59truiVq3AAAABI"]
[Sun Aug 30 03:10:22.269503 2026] [security2:error] [pid 515259:tid 515474] [client 20.104.18.15:18397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/atomlib.php"] [unique_id "apPlbmZcVaai59truiVq3gAAAFQ"]
[Sun Aug 30 03:10:22.278220 2026] [security2:error] [pid 515259:tid 515437] [client 158.23.147.79:52270] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.hebrews111.com"] [uri "/1.php"] [unique_id "apPlbmZcVaai59truiVq4AAAAC8"]
[Sun Aug 30 03:10:22.278314 2026] [security2:error] [pid 515259:tid 515437] [client 158.23.147.79:52270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/1.php"] [unique_id "apPlbmZcVaai59truiVq4AAAAC8"]
[Sun Aug 30 03:10:22.287686 2026] [security2:error] [pid 515259:tid 515505] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/vue/.env"] [unique_id "apPlbmZcVaai59truiVq5AAAAHM"]
[Sun Aug 30 03:10:22.294741 2026] [security2:error] [pid 515259:tid 515428] [client 20.48.160.90:61439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/132.php"] [unique_id "apPlbmZcVaai59truiVq5wAAACY"]
[Sun Aug 30 03:10:22.318517 2026] [security2:error] [pid 515259:tid 515498] [client 4.205.62.107:61780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/wp-info.php"] [unique_id "apPlbmZcVaai59truiVq7AAAAGw"]
[Sun Aug 30 03:10:22.324949 2026] [security2:error] [pid 515259:tid 515416] [client 68.155.159.216:52557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/goat.php"] [unique_id "apPlbmZcVaai59truiVq8AAAABo"]
[Sun Aug 30 03:10:22.342450 2026] [security2:error] [pid 515259:tid 515403] [client 20.104.49.130:52156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/cilus.php"] [unique_id "apPlbmZcVaai59truiVq8wAAAA0"]
[Sun Aug 30 03:10:22.347604 2026] [security2:error] [pid 515259:tid 515485] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/angular/.env"] [unique_id "apPlbmZcVaai59truiVq9QAAAF8"]
[Sun Aug 30 03:10:22.354167 2026] [security2:error] [pid 515259:tid 515424] [client 20.63.81.20:31720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/luuf.php"] [unique_id "apPlbmZcVaai59truiVq9wAAACI"]
[Sun Aug 30 03:10:22.366513 2026] [security2:error] [pid 515259:tid 515447] [client 20.220.10.235:5843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/bge.php"] [unique_id "apPlbmZcVaai59truiVq-gAAADk"]
[Sun Aug 30 03:10:22.374578 2026] [security2:error] [pid 515259:tid 515506] [client 20.104.50.220:51550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/lyda.php"] [unique_id "apPlbmZcVaai59truiVq_AAAAHQ"]
[Sun Aug 30 03:10:22.380573 2026] [authz_core:error] [pid 515259:tid 515443] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:22.380991 2026] [authz_core:error] [pid 515259:tid 515443] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:22.382059 2026] [security2:error] [pid 515259:tid 515457] [client 20.104.50.220:5593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/fw.php"] [unique_id "apPlbmZcVaai59truiVq_QAAAEM"]
[Sun Aug 30 03:10:22.385153 2026] [security2:error] [pid 515259:tid 515509] [client 20.48.250.41:17269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/ava.php"] [unique_id "apPlbmZcVaai59truiVq_gAAAHc"]
[Sun Aug 30 03:10:22.403979 2026] [security2:error] [pid 515259:tid 515402] [client 20.197.61.180:3642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/hideo/network.php"] [unique_id "apPlbmZcVaai59truiVrBAAAAAw"]
[Sun Aug 30 03:10:22.406606 2026] [security2:error] [pid 515259:tid 515396] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/svelte/.env"] [unique_id "apPlbmZcVaai59truiVrBgAAAAY"]
[Sun Aug 30 03:10:22.416109 2026] [authz_core:error] [pid 515259:tid 515471] [client 66.249.66.75:44509] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:22.416392 2026] [authz_core:error] [pid 515259:tid 515471] [client 66.249.66.75:44509] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:22.426885 2026] [security2:error] [pid 515259:tid 515463] [client 20.48.160.90:63995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/v22.php"] [unique_id "apPlbmZcVaai59truiVrCAAAAEk"]
[Sun Aug 30 03:10:22.455066 2026] [security2:error] [pid 515259:tid 515427] [client 216.73.216.128:62395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_config_quote_replace_string"] [unique_id "apPlbmZcVaai59truiVrDwAAACU"]
[Sun Aug 30 03:10:22.455604 2026] [security2:error] [pid 515259:tid 515468] [client 158.23.147.79:57669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-includes/js/index.php"] [unique_id "apPlbmZcVaai59truiVrEAAAAE4"]
[Sun Aug 30 03:10:22.470427 2026] [security2:error] [pid 515259:tid 515405] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/vite/.env"] [unique_id "apPlbmZcVaai59truiVrEQAAAA8"]
[Sun Aug 30 03:10:22.470777 2026] [security2:error] [pid 515259:tid 515393] [client 20.104.49.130:52118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/ws78.php"] [unique_id "apPlbmZcVaai59truiVrEgAAAAM"]
[Sun Aug 30 03:10:22.480691 2026] [security2:error] [pid 515259:tid 515399] [client 20.63.81.20:31649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/fex.php"] [unique_id "apPlbmZcVaai59truiVrEwAAAAk"]
[Sun Aug 30 03:10:22.514324 2026] [security2:error] [pid 515259:tid 515423] [client 20.48.251.3:64312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/gnmlc.php"] [unique_id "apPlbmZcVaai59truiVrFQAAACE"]
[Sun Aug 30 03:10:22.514705 2026] [security2:error] [pid 515259:tid 515510] [client 20.104.50.220:62228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/pref.php"] [unique_id "apPlbmZcVaai59truiVrFgAAAHg"]
[Sun Aug 30 03:10:22.527486 2026] [security2:error] [pid 515259:tid 515491] [client 68.155.159.216:62644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apPlbmZcVaai59truiVrGAAAAGU"]
[Sun Aug 30 03:10:22.530345 2026] [authz_core:error] [pid 515259:tid 515407] [client 66.249.66.44:46407] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:22.530718 2026] [security2:error] [pid 515259:tid 515464] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/backup/.env"] [unique_id "apPlbmZcVaai59truiVrGQAAAEo"]
[Sun Aug 30 03:10:22.530797 2026] [authz_core:error] [pid 515259:tid 515407] [client 66.249.66.44:46407] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:22.534621 2026] [security2:error] [pid 515259:tid 515421] [client 158.23.147.79:52235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/ws.php"] [unique_id "apPlbmZcVaai59truiVrHAAAAB8"]
[Sun Aug 30 03:10:22.550614 2026] [security2:error] [pid 515259:tid 515428] [client 20.48.250.41:17321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/gdn.php"] [unique_id "apPlbmZcVaai59truiVrHwAAACY"]
[Sun Aug 30 03:10:22.575599 2026] [security2:error] [pid 515259:tid 515433] [client 20.104.49.130:63586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-the.php"] [unique_id "apPlbmZcVaai59truiVrIgAAACs"]
[Sun Aug 30 03:10:22.579450 2026] [security2:error] [pid 515259:tid 515454] [client 103.153.183.69:30436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intentionalrounding.com"] [uri "/wp/index.php"] [unique_id "apPlbmZcVaai59truiVrIwAAAEA"], referer: https://intentionalrounding.com/wp/wp-admin/
[Sun Aug 30 03:10:22.586812 2026] [security2:error] [pid 515259:tid 515432] [client 20.48.160.90:37573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/wp-activate.php"] [unique_id "apPlbmZcVaai59truiVrJQAAACo"]
[Sun Aug 30 03:10:22.589551 2026] [security2:error] [pid 515259:tid 515513] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/backups/.env"] [unique_id "apPlbmZcVaai59truiVrJwAAAHs"]
[Sun Aug 30 03:10:22.598947 2026] [security2:error] [pid 515259:tid 515422] [client 20.104.49.130:43303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/ws58.php"] [unique_id "apPlbmZcVaai59truiVrLQAAACA"]
[Sun Aug 30 03:10:22.612531 2026] [security2:error] [pid 515259:tid 515410] [client 20.220.10.235:5566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/ssh3ll.php"] [unique_id "apPlbmZcVaai59truiVrMQAAABQ"]
[Sun Aug 30 03:10:22.612761 2026] [security2:error] [pid 515259:tid 515459] [client 20.63.81.20:31597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/l.php"] [unique_id "apPlbmZcVaai59truiVrMgAAAEU"]
[Sun Aug 30 03:10:22.643172 2026] [authz_core:error] [pid 515259:tid 515435] [client 216.73.216.128:41694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:22.643466 2026] [authz_core:error] [pid 515259:tid 515435] [client 216.73.216.128:41694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:22.667667 2026] [security2:error] [pid 515259:tid 515483] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/old/.env"] [unique_id "apPlbmZcVaai59truiVrPAAAAF0"]
[Sun Aug 30 03:10:22.697824 2026] [authz_core:error] [pid 515259:tid 515397] [client 66.249.66.34:35917] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:22.698129 2026] [authz_core:error] [pid 515259:tid 515397] [client 66.249.66.34:35917] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:22.715128 2026] [security2:error] [pid 515259:tid 515504] [client 20.48.250.41:17403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/f2.php"] [unique_id "apPlbmZcVaai59truiVrPwAAAHI"]
[Sun Aug 30 03:10:22.717567 2026] [security2:error] [pid 515259:tid 515452] [client 20.48.160.90:63889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/wp-trackback.php"] [unique_id "apPlbmZcVaai59truiVrQAAAAD4"]
[Sun Aug 30 03:10:22.726653 2026] [core:alert] [pid 515259:tid 515495] [client 197.217.27.235:38852] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:10:22.737052 2026] [security2:error] [pid 515259:tid 515427] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/tmp/.env"] [unique_id "apPlbmZcVaai59truiVrRgAAACU"]
[Sun Aug 30 03:10:22.745396 2026] [security2:error] [pid 515259:tid 515469] [client 20.104.50.220:59367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/crgio.php"] [unique_id "apPlbmZcVaai59truiVrSwAAAE8"]
[Sun Aug 30 03:10:22.754301 2026] [security2:error] [pid 515259:tid 515442] [client 20.63.219.114:14720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/aaa.php"] [unique_id "apPlbmZcVaai59truiVrTQAAADQ"]
[Sun Aug 30 03:10:22.754976 2026] [security2:error] [pid 515259:tid 515443] [client 20.63.81.20:31621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/xr.php"] [unique_id "apPlbmZcVaai59truiVrTgAAADU"]
[Sun Aug 30 03:10:22.763244 2026] [security2:error] [pid 515259:tid 515510] [client 20.104.49.130:64116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/ws45.php"] [unique_id "apPlbmZcVaai59truiVrUQAAAHg"]
[Sun Aug 30 03:10:22.796355 2026] [security2:error] [pid 515259:tid 515475] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/temp/.env"] [unique_id "apPlbmZcVaai59truiVrXQAAAFU"]
[Sun Aug 30 03:10:22.807022 2026] [security2:error] [pid 515259:tid 515490] [client 4.205.62.107:25476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/erty.php"] [unique_id "apPlbmZcVaai59truiVrXgAAAGQ"]
[Sun Aug 30 03:10:22.824019 2026] [security2:error] [pid 515259:tid 515411] [client 158.23.147.79:2007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-content/index.php"] [unique_id "apPlbmZcVaai59truiVrYQAAABU"]
[Sun Aug 30 03:10:22.832935 2026] [security2:error] [pid 515259:tid 515445] [client 20.220.10.235:5145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/motu.php"] [unique_id "apPlbmZcVaai59truiVrYwAAADc"]
[Sun Aug 30 03:10:22.856487 2026] [security2:error] [pid 515259:tid 515415] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/lab/.env"] [unique_id "apPlbmZcVaai59truiVrZgAAABk"]
[Sun Aug 30 03:10:22.879549 2026] [security2:error] [pid 515259:tid 515482] [client 20.48.250.41:17383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/grsiuk.php"] [unique_id "apPlbmZcVaai59truiVragAAAFw"]
[Sun Aug 30 03:10:22.880569 2026] [authz_core:error] [pid 515259:tid 515493] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:22.880865 2026] [authz_core:error] [pid 515259:tid 515493] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:22.883929 2026] [security2:error] [pid 515259:tid 515401] [client 20.63.81.20:31723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/Q3.php"] [unique_id "apPlbmZcVaai59truiVrawAAAAs"]
[Sun Aug 30 03:10:22.891235 2026] [security2:error] [pid 515259:tid 515497] [client 20.104.49.130:51103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/ortasekerli1.php"] [unique_id "apPlbmZcVaai59truiVrbQAAAGs"]
[Sun Aug 30 03:10:22.901319 2026] [security2:error] [pid 515259:tid 515402] [client 4.205.62.107:36646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/87.php"] [unique_id "apPlbmZcVaai59truiVrbwAAAAw"]
[Sun Aug 30 03:10:22.903480 2026] [security2:error] [pid 515259:tid 515426] [client 20.63.219.114:14736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/atomlib.php"] [unique_id "apPlbmZcVaai59truiVrcgAAACQ"]
[Sun Aug 30 03:10:22.922569 2026] [security2:error] [pid 515259:tid 515400] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/cronlab/.env"] [unique_id "apPlbmZcVaai59truiVreQAAAAo"]
[Sun Aug 30 03:10:22.922709 2026] [security2:error] [pid 515259:tid 515486] [client 20.48.160.90:63909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/pri.php"] [unique_id "apPlbmZcVaai59truiVregAAAGA"]
[Sun Aug 30 03:10:22.982511 2026] [security2:error] [pid 515259:tid 515517] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/cron/.env"] [unique_id "apPlbmZcVaai59truiVrhAAAAH8"]
[Sun Aug 30 03:10:22.982714 2026] [security2:error] [pid 515259:tid 515393] [client 20.220.10.235:5365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/wefile.php"] [unique_id "apPlbmZcVaai59truiVrhgAAAAM"]
[Sun Aug 30 03:10:23.015204 2026] [security2:error] [pid 515259:tid 515430] [client 20.63.81.20:31725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/Q1.php"] [unique_id "apPlb2ZcVaai59truiVrkQAAACg"]
[Sun Aug 30 03:10:23.019850 2026] [security2:error] [pid 515259:tid 515514] [client 20.104.50.220:16581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/themes/twentytwentytwo/index.php"] [unique_id "apPlb2ZcVaai59truiVrkwAAAHw"]
[Sun Aug 30 03:10:23.029703 2026] [security2:error] [pid 515259:tid 515418] [client 20.104.49.130:53721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/t.php"] [unique_id "apPlb2ZcVaai59truiVrlQAAABw"]
[Sun Aug 30 03:10:23.036385 2026] [security2:error] [pid 515259:tid 515454] [client 20.104.18.15:16691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/w.php"] [unique_id "apPlb2ZcVaai59truiVrmAAAAEA"]
[Sun Aug 30 03:10:23.041677 2026] [security2:error] [pid 515259:tid 515456] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/en/.env"] [unique_id "apPlb2ZcVaai59truiVrmgAAAEI"]
[Sun Aug 30 03:10:23.055986 2026] [security2:error] [pid 515259:tid 515398] [client 4.205.62.107:17295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/public/wp-blog.php"] [unique_id "apPlb2ZcVaai59truiVrngAAAAg"]
[Sun Aug 30 03:10:23.058001 2026] [security2:error] [pid 515259:tid 515505] [client 158.23.147.79:1991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/about/function.php"] [unique_id "apPlb2ZcVaai59truiVrnwAAAHM"]
[Sun Aug 30 03:10:23.058472 2026] [security2:error] [pid 515259:tid 515475] [client 20.48.160.90:61404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/wp_blog_footer.php"] [unique_id "apPlb2ZcVaai59truiVroAAAAFU"]
[Sun Aug 30 03:10:23.063257 2026] [security2:error] [pid 515259:tid 515515] [client 158.23.147.79:61956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/css/index.php"] [unique_id "apPlb2ZcVaai59truiVrogAAAH0"]
[Sun Aug 30 03:10:23.063364 2026] [security2:error] [pid 515259:tid 515395] [client 20.48.251.3:59319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/server-info.php"] [unique_id "apPlb2ZcVaai59truiVrowAAAAU"]
[Sun Aug 30 03:10:23.079302 2026] [security2:error] [pid 515259:tid 515416] [client 20.104.18.15:35056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/gulu.php"] [unique_id "apPlb2ZcVaai59truiVrpgAAABo"]
[Sun Aug 30 03:10:23.088870 2026] [authz_core:error] [pid 515259:tid 515445] [client 66.249.66.196:65341] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:23.089158 2026] [authz_core:error] [pid 515259:tid 515445] [client 66.249.66.196:65341] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:23.101276 2026] [security2:error] [pid 515259:tid 515482] [client 68.155.159.216:46055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-includes/index.php"] [unique_id "apPlb2ZcVaai59truiVrrQAAAFw"]
[Sun Aug 30 03:10:23.110970 2026] [security2:error] [pid 515259:tid 515426] [client 20.48.250.41:17316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/wp-scr1pts.php"] [unique_id "apPlb2ZcVaai59truiVrrwAAACQ"]
[Sun Aug 30 03:10:23.125742 2026] [security2:error] [pid 515259:tid 515485] [client 20.197.61.180:12231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPlb2ZcVaai59truiVrsAAAAF8"]
[Sun Aug 30 03:10:23.137505 2026] [security2:error] [pid 515259:tid 515472] [client 20.48.251.3:52273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/php-details.php"] [unique_id "apPlb2ZcVaai59truiVrtAAAAFI"]
[Sun Aug 30 03:10:23.139417 2026] [security2:error] [pid 515259:tid 515484] [client 20.104.49.130:60636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/js.php"] [unique_id "apPlb2ZcVaai59truiVrtgAAAF4"]
[Sun Aug 30 03:10:23.145754 2026] [security2:error] [pid 515259:tid 515468] [client 20.63.81.20:31692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/nz.php"] [unique_id "apPlb2ZcVaai59truiVrtwAAAE4"]
[Sun Aug 30 03:10:23.153108 2026] [security2:error] [pid 515259:tid 515497] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/administrator/.env"] [unique_id "apPlb2ZcVaai59truiVrrgAAAGs"]
[Sun Aug 30 03:10:23.165770 2026] [security2:error] [pid 515259:tid 515462] [client 20.151.200.44:28551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/admin.php/pindex.php"] [unique_id "apPlb2ZcVaai59truiVruAAAAEg"]
[Sun Aug 30 03:10:23.173919 2026] [security2:error] [pid 515259:tid 515492] [client 20.104.49.130:53719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/wp-good.php"] [unique_id "apPlb2ZcVaai59truiVruQAAAGY"]
[Sun Aug 30 03:10:23.188990 2026] [security2:error] [pid 515259:tid 515452] [client 158.23.147.79:52249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apPlb2ZcVaai59truiVrvQAAAD4"]
[Sun Aug 30 03:10:23.194509 2026] [security2:error] [pid 515259:tid 515495] [client 20.48.160.90:61320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/sushi.php"] [unique_id "apPlb2ZcVaai59truiVrvwAAAGk"]
[Sun Aug 30 03:10:23.199427 2026] [security2:error] [pid 515259:tid 515506] [client 20.220.10.235:5353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/Contrller.php"] [unique_id "apPlb2ZcVaai59truiVrwQAAAHQ"]
[Sun Aug 30 03:10:23.202100 2026] [security2:error] [pid 515259:tid 515517] [client 20.104.18.15:16906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/she11.php"] [unique_id "apPlb2ZcVaai59truiVrwwAAAH8"]
[Sun Aug 30 03:10:23.213378 2026] [security2:error] [pid 515259:tid 515471] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/psnlink/.env"] [unique_id "apPlb2ZcVaai59truiVrxwAAAFE"]
[Sun Aug 30 03:10:23.260450 2026] [security2:error] [pid 515259:tid 515491] [client 20.48.250.41:17183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/num.php"] [unique_id "apPlb2ZcVaai59truiVr1QAAAGU"]
[Sun Aug 30 03:10:23.264821 2026] [security2:error] [pid 515259:tid 515400] [client 20.63.219.114:15211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/buy.php"] [unique_id "apPlb2ZcVaai59truiVr1gAAAAo"]
[Sun Aug 30 03:10:23.266913 2026] [security2:error] [pid 515259:tid 515398] [client 20.104.49.130:63605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/btyuio.php"] [unique_id "apPlb2ZcVaai59truiVr1wAAAAg"]
[Sun Aug 30 03:10:23.273731 2026] [security2:error] [pid 515259:tid 515475] [client 20.63.81.20:31499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/sg.php"] [unique_id "apPlb2ZcVaai59truiVr2QAAAFU"]
[Sun Aug 30 03:10:23.283386 2026] [security2:error] [pid 515259:tid 515513] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/exapi/.env"] [unique_id "apPlb2ZcVaai59truiVr3wAAAHs"]
[Sun Aug 30 03:10:23.283923 2026] [security2:error] [pid 515259:tid 515431] [client 158.23.147.79:56487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apPlb2ZcVaai59truiVr4AAAACk"]
[Sun Aug 30 03:10:23.285601 2026] [authz_core:error] [pid 515259:tid 515490] [client 216.73.216.128:23221] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:23.285604 2026] [security2:error] [pid 515259:tid 515416] [client 20.48.251.3:56378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/pass4.php"] [unique_id "apPlb2ZcVaai59truiVr4gAAABo"]
[Sun Aug 30 03:10:23.285882 2026] [authz_core:error] [pid 515259:tid 515490] [client 216.73.216.128:23221] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:23.329717 2026] [security2:error] [pid 515259:tid 515401] [client 20.104.49.130:43296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/as.php"] [unique_id "apPlb2ZcVaai59truiVr6wAAAAs"]
[Sun Aug 30 03:10:23.339537 2026] [security2:error] [pid 515259:tid 515419] [client 20.48.160.90:36983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/manga.php"] [unique_id "apPlb2ZcVaai59truiVr7wAAAB0"]
[Sun Aug 30 03:10:23.342986 2026] [security2:error] [pid 515259:tid 515484] [client 20.104.50.220:52838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/cp.php"] [unique_id "apPlb2ZcVaai59truiVr8QAAAF4"]
[Sun Aug 30 03:10:23.343545 2026] [security2:error] [pid 515259:tid 515468] [client 40.83.93.50:22140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/aaa.php"] [unique_id "apPlb2ZcVaai59truiVr8gAAAE4"]
[Sun Aug 30 03:10:23.344493 2026] [security2:error] [pid 515259:tid 515497] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/sitemaps/.env"] [unique_id "apPlb2ZcVaai59truiVr8wAAAGs"]
[Sun Aug 30 03:10:23.359614 2026] [security2:error] [pid 515259:tid 515507] [client 20.151.200.44:40912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/blnux.php"] [unique_id "apPlb2ZcVaai59truiVr9AAAAHU"]
[Sun Aug 30 03:10:23.371191 2026] [security2:error] [pid 515259:tid 515390] [client 20.104.18.15:22508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/ano.php"] [unique_id "apPlb2ZcVaai59truiVr9wAAAAA"]
[Sun Aug 30 03:10:23.377166 2026] [authz_core:error] [pid 515259:tid 515488] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:23.377445 2026] [authz_core:error] [pid 515259:tid 515488] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:23.388900 2026] [security2:error] [pid 515259:tid 515423] [client 20.220.10.235:5532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/file66.php"] [unique_id "apPlb2ZcVaai59truiVr-QAAACE"]
[Sun Aug 30 03:10:23.403702 2026] [security2:error] [pid 515259:tid 515437] [client 20.63.81.20:31715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/hypo.php"] [unique_id "apPlb2ZcVaai59truiVr-wAAAC8"]
[Sun Aug 30 03:10:23.409483 2026] [security2:error] [pid 515259:tid 515399] [client 20.104.18.15:44022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/wp-content/k.php"] [unique_id "apPlb2ZcVaai59truiVr_QAAAAk"]
[Sun Aug 30 03:10:23.410484 2026] [security2:error] [pid 515259:tid 515450] [client 20.104.49.130:63504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/wp-login.php"] [unique_id "apPlb2ZcVaai59truiVr_gAAADw"]
[Sun Aug 30 03:10:23.416694 2026] [security2:error] [pid 515259:tid 515414] [client 20.48.250.41:17162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/a4.php"] [unique_id "apPlb2ZcVaai59truiVsAQAAABg"]
[Sun Aug 30 03:10:23.423077 2026] [security2:error] [pid 515259:tid 515471] [client 20.104.18.15:18311] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/1.php"] [unique_id "apPlb2ZcVaai59truiVsAgAAAFE"]
[Sun Aug 30 03:10:23.423166 2026] [security2:error] [pid 515259:tid 515471] [client 20.104.18.15:18311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/1.php"] [unique_id "apPlb2ZcVaai59truiVsAgAAAFE"]
[Sun Aug 30 03:10:23.456849 2026] [security2:error] [pid 515259:tid 515428] [client 20.104.49.130:43302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/mh.php"] [unique_id "apPlb2ZcVaai59truiVsCgAAACY"]
[Sun Aug 30 03:10:23.471743 2026] [authz_core:error] [pid 515259:tid 515510] [client 66.249.66.195:59452] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:23.472094 2026] [authz_core:error] [pid 515259:tid 515510] [client 66.249.66.195:59452] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:23.476248 2026] [security2:error] [pid 515259:tid 515442] [client 20.48.160.90:61324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/asdfghj.php"] [unique_id "apPlb2ZcVaai59truiVsDQAAADQ"]
[Sun Aug 30 03:10:23.479499 2026] [security2:error] [pid 515259:tid 515508] [client 68.155.159.216:52568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apPlb2ZcVaai59truiVsDgAAAHY"]
[Sun Aug 30 03:10:23.496879 2026] [security2:error] [pid 515259:tid 515446] [client 4.205.62.107:64489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/fns.php"] [unique_id "apPlb2ZcVaai59truiVsDwAAADg"]
[Sun Aug 30 03:10:23.502084 2026] [security2:error] [pid 515259:tid 515403] [client 40.83.93.50:22131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/atomlib.php"] [unique_id "apPlb2ZcVaai59truiVsEAAAAA0"]
[Sun Aug 30 03:10:23.522823 2026] [security2:error] [pid 515259:tid 515481] [client 20.104.50.220:42488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/alfashell.php"] [unique_id "apPlb2ZcVaai59truiVsEgAAAFs"]
[Sun Aug 30 03:10:23.529619 2026] [authz_core:error] [pid 515259:tid 515491] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:23.529925 2026] [authz_core:error] [pid 515259:tid 515491] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:23.535635 2026] [security2:error] [pid 515259:tid 515513] [client 20.220.10.235:5773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/blnux.php"] [unique_id "apPlb2ZcVaai59truiVsFQAAAHs"]
[Sun Aug 30 03:10:23.537259 2026] [security2:error] [pid 515259:tid 515392] [client 20.63.81.20:31689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/Hd.php"] [unique_id "apPlb2ZcVaai59truiVsFgAAAAI"]
[Sun Aug 30 03:10:23.558051 2026] [security2:error] [pid 515259:tid 515435] [client 158.23.147.79:60206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/.well-known/index.php"] [unique_id "apPlb2ZcVaai59truiVsGQAAAC0"]
[Sun Aug 30 03:10:23.566167 2026] [security2:error] [pid 515259:tid 515447] [client 20.104.50.220:5461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/xyz.php"] [unique_id "apPlb2ZcVaai59truiVsGwAAADk"]
[Sun Aug 30 03:10:23.581897 2026] [authz_core:error] [pid 515259:tid 515451] [client 216.73.216.128:23221] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:23.582181 2026] [authz_core:error] [pid 515259:tid 515451] [client 216.73.216.128:23221] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:23.584346 2026] [security2:error] [pid 515259:tid 515417] [client 20.104.49.130:52144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/press.php"] [unique_id "apPlb2ZcVaai59truiVsHwAAABs"]
[Sun Aug 30 03:10:23.615016 2026] [security2:error] [pid 515259:tid 515426] [client 20.48.160.90:61373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/dragonshell.php"] [unique_id "apPlb2ZcVaai59truiVsKQAAACQ"]
[Sun Aug 30 03:10:23.618837 2026] [security2:error] [pid 515259:tid 515492] [client 20.48.250.41:17311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/tfm.php"] [unique_id "apPlb2ZcVaai59truiVsKgAAAGY"]
[Sun Aug 30 03:10:23.625222 2026] [security2:error] [pid 515259:tid 515457] [client 158.23.147.79:57716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-admin/index.php"] [unique_id "apPlb2ZcVaai59truiVsLAAAAEM"]
[Sun Aug 30 03:10:23.632927 2026] [security2:error] [pid 515259:tid 515443] [client 20.63.219.114:14734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/hello.php"] [unique_id "apPlb2ZcVaai59truiVsLQAAADU"]
[Sun Aug 30 03:10:23.638967 2026] [security2:error] [pid 515259:tid 515441] [client 68.155.159.216:57071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/classwithtostring.php"] [unique_id "apPlb2ZcVaai59truiVsLgAAADM"]
[Sun Aug 30 03:10:23.654349 2026] [security2:error] [pid 515259:tid 515474] [client 20.48.251.3:64266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/koiy.php"] [unique_id "apPlb2ZcVaai59truiVsMQAAAFQ"]
[Sun Aug 30 03:10:23.663316 2026] [security2:error] [pid 515259:tid 515452] [client 20.63.81.20:31717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/im.php"] [unique_id "apPlb2ZcVaai59truiVsNAAAAD4"]
[Sun Aug 30 03:10:23.663371 2026] [security2:error] [pid 515259:tid 515495] [client 20.104.50.220:61953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/priv.php"] [unique_id "apPlb2ZcVaai59truiVsNQAAAGk"]
[Sun Aug 30 03:10:23.696731 2026] [security2:error] [pid 515259:tid 515429] [client 20.220.10.235:5315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/attack.php"] [unique_id "apPlb2ZcVaai59truiVsOwAAACc"]
[Sun Aug 30 03:10:23.716962 2026] [security2:error] [pid 515259:tid 515394] [client 20.104.49.130:64073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.biospherecampus.com"] [uri "/edit.php"] [unique_id "apPlb2ZcVaai59truiVsQQAAAAQ"]
[Sun Aug 30 03:10:23.726477 2026] [security2:error] [pid 515259:tid 515496] [client 158.23.147.79:52238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/cong.php"] [unique_id "apPlb2ZcVaai59truiVsRwAAAGo"]
[Sun Aug 30 03:10:23.757533 2026] [security2:error] [pid 515259:tid 515446] [client 20.48.160.90:63928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/wp-safe.php"] [unique_id "apPlb2ZcVaai59truiVsSwAAADg"]
[Sun Aug 30 03:10:23.766783 2026] [authz_core:error] [pid 515259:tid 515490] [client 66.249.66.197:53142] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:23.767066 2026] [authz_core:error] [pid 515259:tid 515490] [client 66.249.66.197:53142] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:23.768708 2026] [authz_core:error] [pid 515259:tid 515456] [client 216.73.216.128:41694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:23.768986 2026] [authz_core:error] [pid 515259:tid 515456] [client 216.73.216.128:41694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:23.787062 2026] [security2:error] [pid 515259:tid 515475] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/logs/.env"] [unique_id "apPlb2ZcVaai59truiVsVwAAAFU"]
[Sun Aug 30 03:10:23.791793 2026] [security2:error] [pid 515259:tid 515480] [client 20.63.81.20:31619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/fc.php"] [unique_id "apPlb2ZcVaai59truiVsWQAAAFo"]
[Sun Aug 30 03:10:23.810163 2026] [security2:error] [pid 515259:tid 515417] [client 20.48.250.41:17344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/Geforce.php"] [unique_id "apPlb2ZcVaai59truiVsWwAAABs"]
[Sun Aug 30 03:10:23.840541 2026] [security2:error] [pid 515259:tid 515486] [client 20.197.61.180:12229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/intense/block-css.php"] [unique_id "apPlb2ZcVaai59truiVsXAAAAGA"]
[Sun Aug 30 03:10:23.846694 2026] [security2:error] [pid 515259:tid 515422] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/cache/.env"] [unique_id "apPlb2ZcVaai59truiVsXQAAACA"]
[Sun Aug 30 03:10:23.851473 2026] [security2:error] [pid 515259:tid 515482] [client 216.73.216.128:23221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_config_quote_replace_string"] [unique_id "apPlb2ZcVaai59truiVsXgAAAFw"]
[Sun Aug 30 03:10:23.856849 2026] [core:alert] [pid 515259:tid 515472] [client 5.21.132.75:12353] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:10:23.900661 2026] [authz_core:error] [pid 515259:tid 515443] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:23.900947 2026] [authz_core:error] [pid 515259:tid 515443] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:23.901923 2026] [security2:error] [pid 515259:tid 515474] [client 20.48.160.90:37509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/gjewuagf.php"] [unique_id "apPlb2ZcVaai59truiVsbAAAAFQ"]
[Sun Aug 30 03:10:23.915242 2026] [security2:error] [pid 515259:tid 515476] [client 20.104.50.220:59352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/geforce.php"] [unique_id "apPlb2ZcVaai59truiVscAAAAFY"]
[Sun Aug 30 03:10:23.915360 2026] [security2:error] [pid 515259:tid 515424] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/mailer/.env"] [unique_id "apPlb2ZcVaai59truiVsbwAAACI"]
[Sun Aug 30 03:10:23.924416 2026] [security2:error] [pid 515259:tid 515511] [client 20.63.81.20:31581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/ke.php"] [unique_id "apPlb2ZcVaai59truiVscwAAAHk"]
[Sun Aug 30 03:10:23.925087 2026] [security2:error] [pid 515259:tid 515478] [client 20.220.10.235:5274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/wk/index.php"] [unique_id "apPlb2ZcVaai59truiVsdAAAAFg"]
[Sun Aug 30 03:10:23.931049 2026] [authz_core:error] [pid 515259:tid 515511] [client 66.249.66.195:51390] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:23.931332 2026] [authz_core:error] [pid 515259:tid 515511] [client 66.249.66.195:51390] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:23.955638 2026] [authz_core:error] [pid 515259:tid 515390] [client 66.249.66.200:38561] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:23.955934 2026] [authz_core:error] [pid 515259:tid 515390] [client 66.249.66.200:38561] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:23.973990 2026] [security2:error] [pid 515259:tid 515496] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/mail/.env"] [unique_id "apPlb2ZcVaai59truiVsfwAAAGo"]
[Sun Aug 30 03:10:23.978356 2026] [security2:error] [pid 515259:tid 515411] [client 158.23.147.79:52264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPlb2ZcVaai59truiVshAAAABU"]
[Sun Aug 30 03:10:23.989817 2026] [security2:error] [pid 515259:tid 515463] [client 40.83.93.50:6234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/buy.php"] [unique_id "apPlb2ZcVaai59truiVshwAAAEk"]
[Sun Aug 30 03:10:24.003860 2026] [security2:error] [pid 515259:tid 515416] [client 4.205.62.107:25885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/wp-config.backup.php"] [unique_id "apPlcGZcVaai59truiVsigAAABo"]
[Sun Aug 30 03:10:24.013195 2026] [security2:error] [pid 515259:tid 515433] [client 20.63.219.114:2511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/g.php"] [unique_id "apPlcGZcVaai59truiVsjAAAACs"]
[Sun Aug 30 03:10:24.013443 2026] [security2:error] [pid 515259:tid 515505] [client 20.48.250.41:17256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/click.php"] [unique_id "apPlcGZcVaai59truiVsjQAAAHM"]
[Sun Aug 30 03:10:24.032734 2026] [security2:error] [pid 515259:tid 515395] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/email/.env"] [unique_id "apPlcGZcVaai59truiVskQAAAAU"]
[Sun Aug 30 03:10:24.036913 2026] [security2:error] [pid 515259:tid 515459] [client 158.23.147.79:57725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPlcGZcVaai59truiVslAAAAEU"]
[Sun Aug 30 03:10:24.049939 2026] [security2:error] [pid 515259:tid 515447] [client 4.205.62.107:36557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/plss3.php"] [unique_id "apPlcGZcVaai59truiVslwAAADk"]
[Sun Aug 30 03:10:24.050547 2026] [security2:error] [pid 515259:tid 515430] [client 20.63.81.20:31708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/tf.php"] [unique_id "apPlcGZcVaai59truiVsmAAAACg"]
[Sun Aug 30 03:10:24.051176 2026] [security2:error] [pid 515259:tid 515410] [client 20.48.160.90:63954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/tnglzqmv.php"] [unique_id "apPlcGZcVaai59truiVsmQAAABQ"]
[Sun Aug 30 03:10:24.074430 2026] [fcgid:warn] [pid 515259:tid 515426] (70014)End of file found: [client 207.154.212.47:53194] mod_fcgid: can't get data from http client
[Sun Aug 30 03:10:24.099334 2026] [security2:error] [pid 515259:tid 515445] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/smtp/.env"] [unique_id "apPlcGZcVaai59truiVspwAAADc"]
[Sun Aug 30 03:10:24.116716 2026] [security2:error] [pid 515259:tid 515414] [client 20.104.49.130:63524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/ohct.php"] [unique_id "apPlcGZcVaai59truiVsqQAAABg"]
[Sun Aug 30 03:10:24.117593 2026] [security2:error] [pid 515259:tid 515456] [client 20.104.49.130:26655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/33.php"] [unique_id "apPlcGZcVaai59truiVsqgAAAEI"]
[Sun Aug 30 03:10:24.133238 2026] [authz_core:error] [pid 515259:tid 515496] [client 216.73.216.128:51580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:24.133511 2026] [authz_core:error] [pid 515259:tid 515496] [client 216.73.216.128:51580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:24.153966 2026] [security2:error] [pid 515259:tid 515477] [client 20.104.50.220:17253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-admin/js/wp-conflg.php"] [unique_id "apPlcGZcVaai59truiVssgAAAFc"]
[Sun Aug 30 03:10:24.158672 2026] [security2:error] [pid 515259:tid 515446] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/mailing/.env"] [unique_id "apPlcGZcVaai59truiVsswAAADg"]
[Sun Aug 30 03:10:24.171912 2026] [security2:error] [pid 515259:tid 515418] [client 20.104.18.15:16719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/ccc.php"] [unique_id "apPlcGZcVaai59truiVstQAAABw"]
[Sun Aug 30 03:10:24.177236 2026] [security2:error] [pid 515259:tid 515463] [client 20.63.81.20:31680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/px.php"] [unique_id "apPlcGZcVaai59truiVstgAAAEk"]
[Sun Aug 30 03:10:24.191508 2026] [security2:error] [pid 515259:tid 515416] [client 4.205.62.107:17697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/php-details.php"] [unique_id "apPlcGZcVaai59truiVstwAAABo"]
[Sun Aug 30 03:10:24.193478 2026] [security2:error] [pid 515259:tid 515470] [client 20.104.49.130:60973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/xa.php"] [unique_id "apPlcGZcVaai59truiVsuQAAAFA"]
[Sun Aug 30 03:10:24.197708 2026] [security2:error] [pid 515259:tid 515434] [client 20.48.250.41:17338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/ms.php"] [unique_id "apPlcGZcVaai59truiVsuwAAACw"]
[Sun Aug 30 03:10:24.200131 2026] [security2:error] [pid 515259:tid 515443] [client 20.220.10.235:5546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/dehnl.php"] [unique_id "apPlcGZcVaai59truiVsvAAAADU"]
[Sun Aug 30 03:10:24.202157 2026] [security2:error] [pid 515259:tid 515514] [client 20.48.251.3:59299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/gk.php"] [unique_id "apPlcGZcVaai59truiVsvQAAAHw"]
[Sun Aug 30 03:10:24.217395 2026] [security2:error] [pid 515259:tid 515459] [client 20.48.160.90:61392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/wefile.php"] [unique_id "apPlcGZcVaai59truiVswAAAAEU"]
[Sun Aug 30 03:10:24.218829 2026] [security2:error] [pid 515259:tid 515447] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/notifications/.env"] [unique_id "apPlcGZcVaai59truiVswgAAADk"]
[Sun Aug 30 03:10:24.232911 2026] [security2:error] [pid 515259:tid 515467] [client 20.104.50.220:62818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/mail.php"] [unique_id "apPlcGZcVaai59truiVsxgAAAE0"]
[Sun Aug 30 03:10:24.236856 2026] [security2:error] [pid 515259:tid 515486] [client 20.104.18.15:35034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/replace.php"] [unique_id "apPlcGZcVaai59truiVsxwAAAGA"]
[Sun Aug 30 03:10:24.278857 2026] [security2:error] [pid 515259:tid 515497] [client 158.23.147.79:43878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPlcGZcVaai59truiVszQAAAGs"]
[Sun Aug 30 03:10:24.287461 2026] [security2:error] [pid 515259:tid 515503] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/notify/.env"] [unique_id "apPlcGZcVaai59truiVs0gAAAHE"]
[Sun Aug 30 03:10:24.293167 2026] [security2:error] [pid 515259:tid 515469] [client 20.48.251.3:52237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/routes.php"] [unique_id "apPlcGZcVaai59truiVs2QAAAE8"]
[Sun Aug 30 03:10:24.303009 2026] [security2:error] [pid 515259:tid 515415] [client 20.63.81.20:31662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/jg.php"] [unique_id "apPlcGZcVaai59truiVs3gAAABk"]
[Sun Aug 30 03:10:24.323367 2026] [authz_core:error] [pid 515259:tid 515437] [client 66.249.66.42:43858] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:24.323665 2026] [authz_core:error] [pid 515259:tid 515437] [client 66.249.66.42:43858] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:24.340750 2026] [security2:error] [pid 515259:tid 515479] [client 20.104.18.15:16944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/kerang.php"] [unique_id "apPlcGZcVaai59truiVs5QAAAFk"]
[Sun Aug 30 03:10:24.346346 2026] [security2:error] [pid 515259:tid 515414] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/sender/.env"] [unique_id "apPlcGZcVaai59truiVs5gAAABg"]
[Sun Aug 30 03:10:24.365394 2026] [security2:error] [pid 515259:tid 515413] [client 20.48.250.41:17379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/zxekqlxb.php"] [unique_id "apPlcGZcVaai59truiVs6QAAABc"]
[Sun Aug 30 03:10:24.383784 2026] [security2:error] [pid 515259:tid 515508] [client 20.220.10.235:5147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/png.php"] [unique_id "apPlcGZcVaai59truiVs6wAAAHY"]
[Sun Aug 30 03:10:24.403885 2026] [authz_core:error] [pid 515259:tid 515403] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:24.404176 2026] [authz_core:error] [pid 515259:tid 515403] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:24.406480 2026] [security2:error] [pid 515259:tid 515432] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/campaign/.env"] [unique_id "apPlcGZcVaai59truiVs8gAAACo"]
[Sun Aug 30 03:10:24.409859 2026] [authz_core:error] [pid 515259:tid 515436] [client 66.249.66.77:41081] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:24.410304 2026] [authz_core:error] [pid 515259:tid 515436] [client 66.249.66.77:41081] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:24.414401 2026] [core:alert] [pid 515259:tid 515463] [client 102.33.181.138:32788] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:10:24.426781 2026] [security2:error] [pid 515259:tid 515490] [client 20.48.251.3:60504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/cu.php"] [unique_id "apPlcGZcVaai59truiVs9QAAAGQ"]
[Sun Aug 30 03:10:24.429112 2026] [security2:error] [pid 515259:tid 515470] [client 20.63.81.20:31699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/yj.php"] [unique_id "apPlcGZcVaai59truiVs9wAAAFA"]
[Sun Aug 30 03:10:24.484782 2026] [security2:error] [pid 515259:tid 515410] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/newsletter/.env"] [unique_id "apPlcGZcVaai59truiVtAwAAABQ"]
[Sun Aug 30 03:10:24.497455 2026] [security2:error] [pid 515259:tid 515480] [client 20.104.50.220:28701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/cyto.php"] [unique_id "apPlcGZcVaai59truiVtBgAAAFo"]
[Sun Aug 30 03:10:24.516500 2026] [security2:error] [pid 515259:tid 515471] [client 20.48.250.41:17384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/init.php"] [unique_id "apPlcGZcVaai59truiVtCAAAAFE"]
[Sun Aug 30 03:10:24.516829 2026] [autoindex:error] [pid 515259:tid 515462] [client 40.83.93.50:11713] AH01276: Cannot serve directory /home3/antgre7/top15healthinsurance.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:10:24.523516 2026] [security2:error] [pid 515259:tid 515466] [client 20.104.18.15:22400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/mgrr.php"] [unique_id "apPlcGZcVaai59truiVtCQAAAEw"]
[Sun Aug 30 03:10:24.538437 2026] [security2:error] [pid 515259:tid 515515] [client 20.63.219.114:2543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/cc.php"] [unique_id "apPlcGZcVaai59truiVtDQAAAH0"]
[Sun Aug 30 03:10:24.540320 2026] [security2:error] [pid 515259:tid 515419] [client 40.83.93.50:6148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/hello.php"] [unique_id "apPlcGZcVaai59truiVtDwAAAB0"]
[Sun Aug 30 03:10:24.545075 2026] [security2:error] [pid 515259:tid 515497] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/ses/.env"] [unique_id "apPlcGZcVaai59truiVtEAAAAGs"]
[Sun Aug 30 03:10:24.562072 2026] [security2:error] [pid 515259:tid 515498] [client 20.197.61.180:3592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/login.php"] [unique_id "apPlcGZcVaai59truiVtEwAAAGw"]
[Sun Aug 30 03:10:24.562093 2026] [security2:error] [pid 515259:tid 515396] [client 20.63.81.20:31718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/zi.php"] [unique_id "apPlcGZcVaai59truiVtFAAAAAY"]
[Sun Aug 30 03:10:24.569237 2026] [security2:error] [pid 515259:tid 515448] [client 20.104.18.15:18326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/samll.php"] [unique_id "apPlcGZcVaai59truiVtFQAAADo"]
[Sun Aug 30 03:10:24.577605 2026] [security2:error] [pid 515259:tid 515493] [client 20.104.49.130:59520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/red.php"] [unique_id "apPlcGZcVaai59truiVtFwAAAGc"]
[Sun Aug 30 03:10:24.585103 2026] [security2:error] [pid 515259:tid 515452] [client 20.104.18.15:43944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/os.php"] [unique_id "apPlcGZcVaai59truiVtHQAAAD4"]
[Sun Aug 30 03:10:24.592624 2026] [security2:error] [pid 515259:tid 515393] [client 20.104.50.220:33300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/gelay.php"] [unique_id "apPlcGZcVaai59truiVtIAAAAAM"]
[Sun Aug 30 03:10:24.597792 2026] [security2:error] [pid 515259:tid 515506] [client 68.155.159.216:46035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/mah.php"] [unique_id "apPlcGZcVaai59truiVtJAAAAHQ"]
[Sun Aug 30 03:10:24.599542 2026] [authz_core:error] [pid 515259:tid 515485] [client 66.249.66.67:35280] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:24.599862 2026] [authz_core:error] [pid 515259:tid 515485] [client 66.249.66.67:35280] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:24.605792 2026] [security2:error] [pid 515259:tid 515482] [client 68.155.159.216:54287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apPlcGZcVaai59truiVtJQAAAFw"]
[Sun Aug 30 03:10:24.609248 2026] [security2:error] [pid 515259:tid 515456] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/sendgrid/.env"] [unique_id "apPlcGZcVaai59truiVtKAAAAEI"]
[Sun Aug 30 03:10:24.615068 2026] [security2:error] [pid 515259:tid 515266] [remote 95.108.213.87:58128] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "ourcalmchrysalis.com"] [uri "/wzy.php"] [unique_id "apPlcGZcVaai59truiVtFgAAPwU"]
[Sun Aug 30 03:10:24.648130 2026] [security2:error] [pid 515259:tid 515400] [client 4.205.62.107:64483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/params.php"] [unique_id "apPlcGZcVaai59truiVtKwAAAAo"]
[Sun Aug 30 03:10:24.659025 2026] [security2:error] [pid 515259:tid 515406] [client 20.220.10.235:5350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/txets.php"] [unique_id "apPlcGZcVaai59truiVtMAAAABA"]
[Sun Aug 30 03:10:24.668763 2026] [security2:error] [pid 515259:tid 515443] [client 20.48.250.41:17405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/term.php"] [unique_id "apPlcGZcVaai59truiVtMwAAADU"]
[Sun Aug 30 03:10:24.671630 2026] [security2:error] [pid 515259:tid 515505] [client 20.151.200.44:40875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/attack.php"] [unique_id "apPlcGZcVaai59truiVtNAAAAHM"]
[Sun Aug 30 03:10:24.679667 2026] [security2:error] [pid 515259:tid 515464] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/sparkpost/.env"] [unique_id "apPlcGZcVaai59truiVtNgAAAEo"]
[Sun Aug 30 03:10:24.684169 2026] [authz_core:error] [pid 515259:tid 515511] [client 216.73.216.128:64209] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:24.684524 2026] [authz_core:error] [pid 515259:tid 515511] [client 216.73.216.128:64209] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:24.688754 2026] [security2:error] [pid 515259:tid 515512] [client 20.48.160.90:37587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/blog.php"] [unique_id "apPlcGZcVaai59truiVtOgAAAHo"]
[Sun Aug 30 03:10:24.689406 2026] [security2:error] [pid 515259:tid 515459] [client 20.63.81.20:31714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/ue.php"] [unique_id "apPlcGZcVaai59truiVtOwAAAEU"]
[Sun Aug 30 03:10:24.691171 2026] [security2:error] [pid 515259:tid 515431] [client 20.104.50.220:63524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/av.php"] [unique_id "apPlcGZcVaai59truiVtPQAAACk"]
[Sun Aug 30 03:10:24.698864 2026] [authz_core:error] [pid 515259:tid 515467] [client 66.249.66.43:44608] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:24.699130 2026] [authz_core:error] [pid 515259:tid 515467] [client 66.249.66.43:44608] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:24.727421 2026] [authz_core:error] [pid 515259:tid 515416] [client 66.249.66.70:57162] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:24.727712 2026] [authz_core:error] [pid 515259:tid 515416] [client 66.249.66.70:57162] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:24.733904 2026] [security2:error] [pid 515259:tid 515462] [client 20.104.50.220:6113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/tolol.php"] [unique_id "apPlcGZcVaai59truiVtQwAAAEg"]
[Sun Aug 30 03:10:24.738960 2026] [security2:error] [pid 515259:tid 515515] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/postmark/.env"] [unique_id "apPlcGZcVaai59truiVtRQAAAH0"]
[Sun Aug 30 03:10:24.739367 2026] [security2:error] [pid 515259:tid 515390] [client 68.155.159.216:63281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/install.php"] [unique_id "apPlcGZcVaai59truiVtRwAAAAA"]
[Sun Aug 30 03:10:24.740762 2026] [security2:error] [pid 515259:tid 515435] [client 20.104.49.130:57691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/ws85.php"] [unique_id "apPlcGZcVaai59truiVtSQAAAC0"]
[Sun Aug 30 03:10:24.788592 2026] [authz_core:error] [pid 515259:tid 515471] [client 66.249.66.203:61548] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:24.788880 2026] [authz_core:error] [pid 515259:tid 515471] [client 66.249.66.203:61548] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:24.792928 2026] [security2:error] [pid 515259:tid 515444] [client 20.48.251.3:64285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/w.php"] [unique_id "apPlcGZcVaai59truiVtWgAAADY"]
[Sun Aug 30 03:10:24.799112 2026] [security2:error] [pid 515259:tid 515517] [client 34.130.99.179:55452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/mailgun/.env"] [unique_id "apPlcGZcVaai59truiVtWwAAAH8"]
[Sun Aug 30 03:10:24.817550 2026] [security2:error] [pid 515259:tid 515482] [client 20.63.81.20:31718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/nv.php"] [unique_id "apPlcGZcVaai59truiVtXAAAAFw"]
[Sun Aug 30 03:10:24.824700 2026] [security2:error] [pid 515259:tid 515394] [client 20.220.10.235:5832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/wp-login.php"] [unique_id "apPlcGZcVaai59truiVtXQAAAAQ"]
[Sun Aug 30 03:10:24.837019 2026] [security2:error] [pid 515259:tid 515405] [client 20.104.50.220:61379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/priv8.php"] [unique_id "apPlcGZcVaai59truiVtXgAAAA8"]
[Sun Aug 30 03:10:24.848762 2026] [security2:error] [pid 515259:tid 515456] [client 20.48.250.41:17249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/aaa.php"] [unique_id "apPlcGZcVaai59truiVtYgAAAEI"]
[Sun Aug 30 03:10:24.853580 2026] [authz_core:error] [pid 515259:tid 515437] [client 66.249.66.194:62118] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:24.853887 2026] [authz_core:error] [pid 515259:tid 515437] [client 66.249.66.194:62118] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:24.872941 2026] [security2:error] [pid 515259:tid 515490] [client 20.48.160.90:37588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/wp-admin/js/wp-load.php"] [unique_id "apPlcGZcVaai59truiVtbQAAAGQ"]
[Sun Aug 30 03:10:24.895505 2026] [authz_core:error] [pid 515259:tid 515464] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:24.895792 2026] [authz_core:error] [pid 515259:tid 515464] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:24.920886 2026] [security2:error] [pid 515259:tid 515488] [client 20.63.219.114:15186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/f35.php"] [unique_id "apPlcGZcVaai59truiVteQAAAGI"]
[Sun Aug 30 03:10:24.926769 2026] [security2:error] [pid 515259:tid 515447] [client 158.23.147.79:60177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-content/themes/too.php"] [unique_id "apPlcGZcVaai59truiVtfAAAADk"]
[Sun Aug 30 03:10:24.929225 2026] [security2:error] [pid 515259:tid 515410] [client 158.23.147.79:61978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apPlcGZcVaai59truiVtfQAAABQ"]
[Sun Aug 30 03:10:24.944588 2026] [authz_core:error] [pid 515259:tid 515422] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:24.944879 2026] [authz_core:error] [pid 515259:tid 515422] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:24.947417 2026] [security2:error] [pid 515259:tid 515395] [client 20.63.81.20:31564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/jw.php"] [unique_id "apPlcGZcVaai59truiVtggAAAAU"]
[Sun Aug 30 03:10:25.024335 2026] [security2:error] [pid 515259:tid 515515] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/mandrill/.env"] [unique_id "apPlcWZcVaai59truiVtkAAAAH0"]
[Sun Aug 30 03:10:25.041183 2026] [security2:error] [pid 515259:tid 515428] [client 216.73.216.128:41694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPlcWZcVaai59truiVtlgAAACY"]
[Sun Aug 30 03:10:25.044938 2026] [security2:error] [pid 515259:tid 515451] [client 40.83.93.50:6541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/g.php"] [unique_id "apPlcWZcVaai59truiVtmAAAAD0"]
[Sun Aug 30 03:10:25.059162 2026] [fcgid:warn] [pid 515259:tid 515412] (70014)End of file found: [client 207.154.212.47:53198] mod_fcgid: can't get data from http client
[Sun Aug 30 03:10:25.067072 2026] [security2:error] [pid 515259:tid 515502] [client 20.48.160.90:37555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/robot.php"] [unique_id "apPlcWZcVaai59truiVtnwAAAHA"]
[Sun Aug 30 03:10:25.072380 2026] [security2:error] [pid 515259:tid 515468] [client 20.63.81.20:31660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/or.php"] [unique_id "apPlcWZcVaai59truiVtoQAAAE4"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:10:25.084632 2026] [security2:error] [pid 515259:tid 515490] [client 20.104.50.220:59368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/pucci.php"] [unique_id "apPlcWZcVaai59truiVtqAAAAGQ"]
[Sun Aug 30 03:10:25.101562 2026] [security2:error] [pid 515259:tid 515401] [client 20.48.250.41:17363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/xsox.php"] [unique_id "apPlcWZcVaai59truiVtrwAAAAs"]
[Sun Aug 30 03:10:25.109242 2026] [security2:error] [pid 515259:tid 515420] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/mailjet/.env"] [unique_id "apPlcWZcVaai59truiVtsAAAAB4"]
[Sun Aug 30 03:10:25.117179 2026] [authz_core:error] [pid 515259:tid 515501] [client 66.249.66.199:38310] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:25.117468 2026] [authz_core:error] [pid 515259:tid 515501] [client 66.249.66.199:38310] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:25.146719 2026] [security2:error] [pid 515259:tid 515486] [client 4.205.62.107:25775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/edit.php"] [unique_id "apPlcWZcVaai59truiVttgAAAGA"]
[Sun Aug 30 03:10:25.155994 2026] [security2:error] [pid 515259:tid 515488] [client 20.104.49.130:60736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/m.php"] [unique_id "apPlcWZcVaai59truiVttwAAAGI"]
[Sun Aug 30 03:10:25.176569 2026] [security2:error] [pid 515259:tid 515447] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/brevo/.env"] [unique_id "apPlcWZcVaai59truiVtuwAAADk"]
[Sun Aug 30 03:10:25.195027 2026] [security2:error] [pid 515259:tid 515489] [client 20.220.10.235:5294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/wp-access.php"] [unique_id "apPlcWZcVaai59truiVtvwAAAGM"]
[Sun Aug 30 03:10:25.202156 2026] [security2:error] [pid 515259:tid 515439] [client 20.63.81.20:31672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/ile56.php"] [unique_id "apPlcWZcVaai59truiVtwgAAADE"]
[Sun Aug 30 03:10:25.205129 2026] [security2:error] [pid 515259:tid 515475] [client 20.48.160.90:63900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/revo.php"] [unique_id "apPlcWZcVaai59truiVtwwAAAFU"]
[Sun Aug 30 03:10:25.220763 2026] [core:alert] [pid 515259:tid 515408] [client 105.233.230.247:34616] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:10:25.230594 2026] [security2:error] [pid 515259:tid 515483] [client 158.23.147.79:52256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/radio.php"] [unique_id "apPlcWZcVaai59truiVtyQAAAF0"]
[Sun Aug 30 03:10:25.239694 2026] [security2:error] [pid 515259:tid 515416] [client 4.205.62.107:36695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/aws.php"] [unique_id "apPlcWZcVaai59truiVtywAAABo"]
[Sun Aug 30 03:10:25.250508 2026] [security2:error] [pid 515259:tid 515498] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/transactional/.env"] [unique_id "apPlcWZcVaai59truiVtzgAAAGw"]
[Sun Aug 30 03:10:25.265685 2026] [security2:error] [pid 515259:tid 515403] [client 20.197.61.180:15754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/min.php"] [unique_id "apPlcWZcVaai59truiVt0QAAAA0"]
[Sun Aug 30 03:10:25.282255 2026] [security2:error] [pid 515259:tid 515407] [client 20.48.250.41:17342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/lkui.php"] [unique_id "apPlcWZcVaai59truiVt0wAAABE"]
[Sun Aug 30 03:10:25.291966 2026] [security2:error] [pid 515259:tid 515462] [client 20.104.50.220:17269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-admin/wp-conflg.php"] [unique_id "apPlcWZcVaai59truiVt1wAAAEg"]
[Sun Aug 30 03:10:25.301978 2026] [security2:error] [pid 515259:tid 515468] [client 20.151.200.44:28632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/admin.php/csv.php"] [unique_id "apPlcWZcVaai59truiVt2wAAAE4"]
[Sun Aug 30 03:10:25.308867 2026] [security2:error] [pid 515259:tid 515492] [client 20.104.18.15:16667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/file15.php"] [unique_id "apPlcWZcVaai59truiVt3wAAAGY"]
[Sun Aug 30 03:10:25.324657 2026] [security2:error] [pid 515259:tid 515443] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/bulk/.env"] [unique_id "apPlcWZcVaai59truiVt4AAAADU"]
[Sun Aug 30 03:10:25.333534 2026] [security2:error] [pid 515259:tid 515413] [client 158.23.147.79:56459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/about.php"] [unique_id "apPlcWZcVaai59truiVt4wAAABc"]
[Sun Aug 30 03:10:25.333592 2026] [security2:error] [pid 515259:tid 515438] [client 4.205.62.107:17128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/routes.php"] [unique_id "apPlcWZcVaai59truiVt5AAAADA"]
[Sun Aug 30 03:10:25.343879 2026] [security2:error] [pid 515259:tid 515458] [client 20.63.81.20:31698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/emmh.php"] [unique_id "apPlcWZcVaai59truiVt6QAAAEQ"]
[Sun Aug 30 03:10:25.343923 2026] [security2:error] [pid 515259:tid 515406] [client 20.48.251.3:55697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/god.php"] [unique_id "apPlcWZcVaai59truiVt6AAAABA"]
[Sun Aug 30 03:10:25.351658 2026] [security2:error] [pid 515259:tid 515505] [client 20.48.160.90:63928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/birrs.php"] [unique_id "apPlcWZcVaai59truiVt6gAAAHM"]
[Sun Aug 30 03:10:25.384442 2026] [security2:error] [pid 515259:tid 515420] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/aws/.env"] [unique_id "apPlcWZcVaai59truiVt6wAAAB4"]
[Sun Aug 30 03:10:25.399253 2026] [security2:error] [pid 515259:tid 515459] [client 20.104.50.220:62806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/mailer.php"] [unique_id "apPlcWZcVaai59truiVt7wAAAEU"]
[Sun Aug 30 03:10:25.401279 2026] [authz_core:error] [pid 515259:tid 515512] [client 66.249.66.70:40708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:25.401719 2026] [authz_core:error] [pid 515259:tid 515512] [client 66.249.66.70:40708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:25.408168 2026] [security2:error] [pid 515259:tid 515497] [client 20.104.18.15:35039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/c4.php"] [unique_id "apPlcWZcVaai59truiVt8gAAAGs"]
[Sun Aug 30 03:10:25.417520 2026] [security2:error] [pid 515259:tid 515487] [client 20.220.10.235:5344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/wp-content/admin.php"] [unique_id "apPlcWZcVaai59truiVt9AAAAGE"]
[Sun Aug 30 03:10:25.431890 2026] [security2:error] [pid 515259:tid 515428] [client 20.63.219.114:15246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/classsmtps.php"] [unique_id "apPlcWZcVaai59truiVt9wAAACY"]
[Sun Aug 30 03:10:25.434593 2026] [security2:error] [pid 515259:tid 515510] [client 158.23.147.79:52248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apPlcWZcVaai59truiVt-AAAAHg"]
[Sun Aug 30 03:10:25.442602 2026] [security2:error] [pid 515259:tid 515419] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/azure/.env"] [unique_id "apPlcWZcVaai59truiVt_AAAAB0"]
[Sun Aug 30 03:10:25.450684 2026] [security2:error] [pid 515259:tid 515439] [client 20.48.251.3:43102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/aww.php"] [unique_id "apPlcWZcVaai59truiVuAAAAADE"]
[Sun Aug 30 03:10:25.451784 2026] [authz_core:error] [pid 515259:tid 515460] [client 66.249.66.200:38561] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:25.452076 2026] [authz_core:error] [pid 515259:tid 515460] [client 66.249.66.200:38561] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:25.456815 2026] [security2:error] [pid 515259:tid 515514] [client 20.48.250.41:17286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apPlcWZcVaai59truiVuBAAAAHw"]
[Sun Aug 30 03:10:25.481017 2026] [security2:error] [pid 515259:tid 515478] [client 20.104.18.15:16935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/m.php"] [unique_id "apPlcWZcVaai59truiVuCQAAAFg"]
[Sun Aug 30 03:10:25.483323 2026] [security2:error] [pid 515259:tid 515493] [client 20.48.160.90:63929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/sss.php"] [unique_id "apPlcWZcVaai59truiVuCgAAAGc"]
[Sun Aug 30 03:10:25.498428 2026] [security2:error] [pid 515259:tid 515472] [client 20.63.81.20:31644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/em.php"] [unique_id "apPlcWZcVaai59truiVuDQAAAFI"]
[Sun Aug 30 03:10:25.503989 2026] [security2:error] [pid 515259:tid 515424] [client 20.104.49.130:45158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/wsd.php"] [unique_id "apPlcWZcVaai59truiVuDgAAACI"]
[Sun Aug 30 03:10:25.521725 2026] [authz_core:error] [pid 515259:tid 515407] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:25.521995 2026] [authz_core:error] [pid 515259:tid 515407] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:25.524508 2026] [security2:error] [pid 515259:tid 515444] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/gcp/.env"] [unique_id "apPlcWZcVaai59truiVuFAAAADY"]
[Sun Aug 30 03:10:25.539461 2026] [security2:error] [pid 515259:tid 515418] [client 40.83.93.50:22093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/cc.php"] [unique_id "apPlcWZcVaai59truiVuGAAAABw"]
[Sun Aug 30 03:10:25.575221 2026] [security2:error] [pid 515259:tid 515443] [client 20.48.251.3:60535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/services.php"] [unique_id "apPlcWZcVaai59truiVuHAAAADU"]
[Sun Aug 30 03:10:25.589404 2026] [security2:error] [pid 515259:tid 515400] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/cloud/.env"] [unique_id "apPlcWZcVaai59truiVuHwAAAAo"]
[Sun Aug 30 03:10:25.624709 2026] [security2:error] [pid 515259:tid 515432] [client 20.220.10.235:5133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/log.php"] [unique_id "apPlcWZcVaai59truiVuKQAAACo"]
[Sun Aug 30 03:10:25.627845 2026] [security2:error] [pid 515259:tid 515491] [client 20.48.160.90:61413] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.biospherecampus.com"] [uri "/wp-content/themes/gaukingo/"] [unique_id "apPlcWZcVaai59truiVuKgAAAGU"]
[Sun Aug 30 03:10:25.633973 2026] [security2:error] [pid 515259:tid 515420] [client 20.104.50.220:52861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/con7.php"] [unique_id "apPlcWZcVaai59truiVuKwAAAB4"]
[Sun Aug 30 03:10:25.635088 2026] [security2:error] [pid 515259:tid 515477] [client 20.63.81.20:31556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/dvve.php"] [unique_id "apPlcWZcVaai59truiVuLAAAAFc"]
[Sun Aug 30 03:10:25.652050 2026] [security2:error] [pid 515259:tid 515461] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/infrastructure/.env"] [unique_id "apPlcWZcVaai59truiVuLgAAAEc"]
[Sun Aug 30 03:10:25.657344 2026] [security2:error] [pid 515259:tid 515486] [client 20.48.250.41:17264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/motu.php"] [unique_id "apPlcWZcVaai59truiVuMQAAAGA"]
[Sun Aug 30 03:10:25.684175 2026] [security2:error] [pid 515259:tid 515428] [client 20.104.18.15:22510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/mac.php"] [unique_id "apPlcWZcVaai59truiVuNgAAACY"]
[Sun Aug 30 03:10:25.709195 2026] [security2:error] [pid 515259:tid 515503] [client 20.104.18.15:18358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/she11.php"] [unique_id "apPlcWZcVaai59truiVuPgAAAHE"]
[Sun Aug 30 03:10:25.740711 2026] [security2:error] [pid 515259:tid 515445] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/docker/.env"] [unique_id "apPlcWZcVaai59truiVuQgAAADc"]
[Sun Aug 30 03:10:25.758345 2026] [security2:error] [pid 515259:tid 515397] [client 20.104.18.15:43298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/htio.php"] [unique_id "apPlcWZcVaai59truiVuRwAAAAc"]
[Sun Aug 30 03:10:25.759566 2026] [security2:error] [pid 515259:tid 515393] [client 20.48.160.90:61376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/wp-includes/ID3/moon.php"] [unique_id "apPlcWZcVaai59truiVuSAAAAAM"]
[Sun Aug 30 03:10:25.771297 2026] [security2:error] [pid 515259:tid 515496] [client 20.63.81.20:31652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/doo.php"] [unique_id "apPlcWZcVaai59truiVuSgAAAGo"]
[Sun Aug 30 03:10:25.784435 2026] [security2:error] [pid 515259:tid 515415] [client 68.155.159.216:46011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apPlcWZcVaai59truiVuUAAAABk"]
[Sun Aug 30 03:10:25.786120 2026] [security2:error] [pid 515259:tid 515490] [client 20.220.10.235:5162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/xwpg.php"] [unique_id "apPlcWZcVaai59truiVuUgAAAGQ"]
[Sun Aug 30 03:10:25.786218 2026] [security2:error] [pid 515259:tid 515492] [client 4.205.62.107:61706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/gjm.php"] [unique_id "apPlcWZcVaai59truiVuUQAAAGY"]
[Sun Aug 30 03:10:25.793330 2026] [security2:error] [pid 515259:tid 515446] [client 158.23.147.79:57708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apPlcWZcVaai59truiVuVAAAADg"]
[Sun Aug 30 03:10:25.810966 2026] [security2:error] [pid 515259:tid 515505] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/k8s/.env"] [unique_id "apPlcWZcVaai59truiVuWAAAAHM"]
[Sun Aug 30 03:10:25.813590 2026] [security2:error] [pid 515259:tid 515430] [client 68.155.159.216:52341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apPlcWZcVaai59truiVuWQAAACg"]
[Sun Aug 30 03:10:25.822954 2026] [security2:error] [pid 515259:tid 515455] [client 158.23.147.79:61986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/login.php"] [unique_id "apPlcWZcVaai59truiVuWgAAAEE"]
[Sun Aug 30 03:10:25.836160 2026] [security2:error] [pid 515259:tid 515473] [client 20.104.50.220:63536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/upl.php"] [unique_id "apPlcWZcVaai59truiVuWwAAAFM"]
[Sun Aug 30 03:10:25.838307 2026] [security2:error] [pid 515259:tid 515404] [client 68.155.159.216:63282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-content/x/index.php"] [unique_id "apPlcWZcVaai59truiVuXAAAAA4"]
[Sun Aug 30 03:10:25.855164 2026] [security2:error] [pid 515259:tid 515495] [client 20.48.250.41:17343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/Ov-Simple1.php"] [unique_id "apPlcWZcVaai59truiVuXgAAAGk"]
[Sun Aug 30 03:10:25.856512 2026] [security2:error] [pid 515259:tid 515407] [client 20.104.50.220:32859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/darkshell.php"] [unique_id "apPlcWZcVaai59truiVuXwAAABE"]
[Sun Aug 30 03:10:25.869522 2026] [security2:error] [pid 515259:tid 515481] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/kubernetes/.env"] [unique_id "apPlcWZcVaai59truiVuYQAAAFs"]
[Sun Aug 30 03:10:25.874678 2026] [security2:error] [pid 515259:tid 515471] [client 20.104.50.220:5531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/anjing.php"] [unique_id "apPlcWZcVaai59truiVuYwAAAFE"]
[Sun Aug 30 03:10:25.880325 2026] [authz_core:error] [pid 515259:tid 515487] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:25.880622 2026] [authz_core:error] [pid 515259:tid 515487] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:25.887239 2026] [security2:error] [pid 515259:tid 515428] [client 158.23.147.79:60209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/radio.php"] [unique_id "apPlcWZcVaai59truiVuZQAAACY"]
[Sun Aug 30 03:10:25.892453 2026] [security2:error] [pid 515259:tid 515467] [client 20.48.160.90:61328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/xmini4.php"] [unique_id "apPlcWZcVaai59truiVuZgAAAE0"]
[Sun Aug 30 03:10:25.904972 2026] [security2:error] [pid 515259:tid 515480] [client 20.63.81.20:31705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/adminer-4.6.6.php"] [unique_id "apPlcWZcVaai59truiVuawAAAFo"]
[Sun Aug 30 03:10:25.910013 2026] [security2:error] [pid 515259:tid 515435] [client 20.151.200.44:40836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/wk/index.php"] [unique_id "apPlcWZcVaai59truiVubgAAAC0"]
[Sun Aug 30 03:10:25.917229 2026] [security2:error] [pid 515259:tid 515499] [client 20.220.10.235:5805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/sxxb.php"] [unique_id "apPlcWZcVaai59truiVucwAAAG0"]
[Sun Aug 30 03:10:25.931626 2026] [security2:error] [pid 515259:tid 515493] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/terraform/.env"] [unique_id "apPlcWZcVaai59truiVudwAAAGc"]
[Sun Aug 30 03:10:25.933513 2026] [security2:error] [pid 515259:tid 515512] [client 20.104.18.15:43944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/dev.php"] [unique_id "apPlcWZcVaai59truiVueAAAAHo"]
[Sun Aug 30 03:10:25.945272 2026] [security2:error] [pid 515259:tid 515394] [client 20.48.251.3:65507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/btx25.php"] [unique_id "apPlcWZcVaai59truiVuewAAAAQ"]
[Sun Aug 30 03:10:25.967269 2026] [authz_core:error] [pid 515259:tid 515456] [client 66.249.66.204:36194] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:25.967541 2026] [authz_core:error] [pid 515259:tid 515456] [client 66.249.66.204:36194] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:25.983225 2026] [security2:error] [pid 515259:tid 515440] [client 20.197.61.180:15769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/module.php"] [unique_id "apPlcWZcVaai59truiVugwAAADI"]
[Sun Aug 30 03:10:25.996912 2026] [security2:error] [pid 515259:tid 515461] [client 20.63.219.114:2600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/install.php"] [unique_id "apPlcWZcVaai59truiVuhwAAAEc"]
[Sun Aug 30 03:10:26.001543 2026] [security2:error] [pid 515259:tid 515517] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/ansible/.env"] [unique_id "apPlcmZcVaai59truiVuigAAAH8"]
[Sun Aug 30 03:10:26.018046 2026] [security2:error] [pid 515259:tid 515433] [client 158.23.147.79:43864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/hehehehe.php"] [unique_id "apPlcmZcVaai59truiVujQAAACs"]
[Sun Aug 30 03:10:26.029338 2026] [security2:error] [pid 515259:tid 515462] [client 20.104.50.220:61683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/qindex.php"] [unique_id "apPlcmZcVaai59truiVujgAAAEg"]
[Sun Aug 30 03:10:26.042026 2026] [security2:error] [pid 515259:tid 515420] [client 20.63.81.20:31691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/gelap1.php"] [unique_id "apPlcmZcVaai59truiVukQAAAB4"]
[Sun Aug 30 03:10:26.050446 2026] [security2:error] [pid 515259:tid 515458] [client 20.48.250.41:17308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/wp-blogs.php"] [unique_id "apPlcmZcVaai59truiVulQAAAEQ"]
[Sun Aug 30 03:10:26.055918 2026] [authz_core:error] [pid 515259:tid 515469] [client 66.249.66.65:43331] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:26.056209 2026] [authz_core:error] [pid 515259:tid 515469] [client 66.249.66.65:43331] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:26.063414 2026] [security2:error] [pid 515259:tid 515495] [client 20.48.160.90:63879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/gulu.php"] [unique_id "apPlcmZcVaai59truiVumQAAAGk"]
[Sun Aug 30 03:10:26.068214 2026] [security2:error] [pid 515259:tid 515471] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/.git/.env"] [unique_id "apPlcmZcVaai59truiVunQAAAFE"]
[Sun Aug 30 03:10:26.138810 2026] [security2:error] [pid 515259:tid 515485] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/ci/.env"] [unique_id "apPlcmZcVaai59truiVutAAAAF8"]
[Sun Aug 30 03:10:26.158390 2026] [security2:error] [pid 515259:tid 515492] [client 20.104.49.130:52140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/k.php"] [unique_id "apPlcmZcVaai59truiVuuAAAAGY"]
[Sun Aug 30 03:10:26.176539 2026] [security2:error] [pid 515259:tid 515416] [client 40.83.93.50:6233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/f35.php"] [unique_id "apPlcmZcVaai59truiVuvQAAABo"]
[Sun Aug 30 03:10:26.192735 2026] [security2:error] [pid 515259:tid 515447] [client 20.63.81.20:31585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/rsjlrria.php"] [unique_id "apPlcmZcVaai59truiVuwgAAADk"]
[Sun Aug 30 03:10:26.208451 2026] [security2:error] [pid 515259:tid 515411] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/cd/.env"] [unique_id "apPlcmZcVaai59truiVuyAAAABU"]
[Sun Aug 30 03:10:26.209993 2026] [security2:error] [pid 515259:tid 515432] [client 20.48.250.41:17224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/mini.php"] [unique_id "apPlcmZcVaai59truiVuyQAAACo"]
[Sun Aug 30 03:10:26.224692 2026] [security2:error] [pid 515259:tid 515430] [client 20.48.160.90:61371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/replace.php"] [unique_id "apPlcmZcVaai59truiVuywAAACg"]
[Sun Aug 30 03:10:26.230412 2026] [security2:error] [pid 515259:tid 515405] [client 20.104.49.130:60745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/33.php"] [unique_id "apPlcmZcVaai59truiVuzgAAAA8"]
[Sun Aug 30 03:10:26.271263 2026] [security2:error] [pid 515259:tid 515495] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/jenkins/.env"] [unique_id "apPlcmZcVaai59truiVu1wAAAGk"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Sun Aug 30 03:10:26.288880 2026] [security2:error] [pid 515259:tid 515486] [client 20.220.10.235:5766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/dx.php"] [unique_id "apPlcmZcVaai59truiVu3QAAAGA"]
[Sun Aug 30 03:10:26.292453 2026] [security2:error] [pid 515259:tid 515437] [client 4.205.62.107:25770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/8.php"] [unique_id "apPlcmZcVaai59truiVu3wAAAC8"]
[Sun Aug 30 03:10:26.319017 2026] [authz_core:error] [pid 515259:tid 515402] [client 66.249.66.68:57740] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:26.319302 2026] [authz_core:error] [pid 515259:tid 515402] [client 66.249.66.68:57740] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:26.321102 2026] [security2:error] [pid 515259:tid 515395] [client 20.63.81.20:31667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/AxAo.php"] [unique_id "apPlcmZcVaai59truiVu6AAAAAU"]
[Sun Aug 30 03:10:26.322042 2026] [security2:error] [pid 515259:tid 515466] [client 158.23.147.79:43902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apPlcmZcVaai59truiVu6QAAAEw"]
[Sun Aug 30 03:10:26.327208 2026] [security2:error] [pid 515259:tid 515419] [client 20.151.200.44:41913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/wp-login.php"] [unique_id "apPlcmZcVaai59truiVu6gAAAB0"]
[Sun Aug 30 03:10:26.330707 2026] [security2:error] [pid 515259:tid 515509] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/gitlab/.env"] [unique_id "apPlcmZcVaai59truiVu6wAAAHc"]
[Sun Aug 30 03:10:26.362034 2026] [security2:error] [pid 515259:tid 515475] [client 20.48.160.90:37591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/c4.php"] [unique_id "apPlcmZcVaai59truiVu8QAAAFU"]
[Sun Aug 30 03:10:26.363307 2026] [authz_core:error] [pid 515259:tid 515478] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:26.363574 2026] [authz_core:error] [pid 515259:tid 515478] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:26.371759 2026] [security2:error] [pid 515259:tid 515483] [client 20.48.250.41:17233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/amp.php"] [unique_id "apPlcmZcVaai59truiVu8wAAAF0"]
[Sun Aug 30 03:10:26.413803 2026] [security2:error] [pid 515259:tid 515490] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/github/.env"] [unique_id "apPlcmZcVaai59truiVu-gAAAGQ"]
[Sun Aug 30 03:10:26.429077 2026] [security2:error] [pid 515259:tid 515429] [client 20.104.50.220:16761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-admin/css/wp-conflg.php"] [unique_id "apPlcmZcVaai59truiVu_AAAACc"]
[Sun Aug 30 03:10:26.440258 2026] [security2:error] [pid 515259:tid 515479] [client 20.220.10.235:5550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPlcmZcVaai59truiVu_wAAAFk"]
[Sun Aug 30 03:10:26.449844 2026] [security2:error] [pid 515259:tid 515484] [client 20.104.18.15:64890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/jp.php"] [unique_id "apPlcmZcVaai59truiVvBgAAAF4"]
[Sun Aug 30 03:10:26.452249 2026] [security2:error] [pid 515259:tid 515517] [client 20.104.50.220:31509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-temp.php"] [unique_id "apPlcmZcVaai59truiVvCAAAAH8"]
[Sun Aug 30 03:10:26.452947 2026] [security2:error] [pid 515259:tid 515411] [client 20.63.81.20:31679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/class17.php"] [unique_id "apPlcmZcVaai59truiVvCQAAABU"]
[Sun Aug 30 03:10:26.466762 2026] [authz_core:error] [pid 515259:tid 515409] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:26.467244 2026] [authz_core:error] [pid 515259:tid 515409] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:26.468244 2026] [security2:error] [pid 515259:tid 515491] [client 4.205.62.107:36553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/app.default.php"] [unique_id "apPlcmZcVaai59truiVvEAAAAGU"]
[Sun Aug 30 03:10:26.476364 2026] [security2:error] [pid 515259:tid 515516] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/actions/.env"] [unique_id "apPlcmZcVaai59truiVvEwAAAH4"]
[Sun Aug 30 03:10:26.483263 2026] [security2:error] [pid 515259:tid 515495] [client 20.48.251.3:59295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/fff.php"] [unique_id "apPlcmZcVaai59truiVvFQAAAGk"]
[Sun Aug 30 03:10:26.484704 2026] [security2:error] [pid 515259:tid 515449] [client 4.205.62.107:17709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/aww.php"] [unique_id "apPlcmZcVaai59truiVvFgAAADs"]
[Sun Aug 30 03:10:26.492870 2026] [security2:error] [pid 515259:tid 515500] [client 20.48.160.90:61346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/rxr.php"] [unique_id "apPlcmZcVaai59truiVvGQAAAG4"]
[Sun Aug 30 03:10:26.529081 2026] [security2:error] [pid 515259:tid 515397] [client 20.63.219.114:15618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/wp.php"] [unique_id "apPlcmZcVaai59truiVvHQAAAAc"]
[Sun Aug 30 03:10:26.531640 2026] [security2:error] [pid 515259:tid 515480] [client 20.48.250.41:17301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/cc13.php"] [unique_id "apPlcmZcVaai59truiVvHgAAAFo"]
[Sun Aug 30 03:10:26.540086 2026] [security2:error] [pid 515259:tid 515497] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/circleci/.env"] [unique_id "apPlcmZcVaai59truiVvIQAAAGs"]
[Sun Aug 30 03:10:26.545755 2026] [security2:error] [pid 515259:tid 515417] [client 20.104.18.15:35020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/rxr.php"] [unique_id "apPlcmZcVaai59truiVvJAAAABs"]
[Sun Aug 30 03:10:26.565686 2026] [authz_core:error] [pid 515259:tid 515399] [client 20.104.50.220:0] AH01630: client denied by server configuration: /home2/egenolfm/nhlhockeybythenumbers.com/php.ini
[Sun Aug 30 03:10:26.586058 2026] [security2:error] [pid 515259:tid 515514] [client 20.104.49.130:63553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/155.php"] [unique_id "apPlcmZcVaai59truiVvLgAAAHw"]
[Sun Aug 30 03:10:26.591805 2026] [security2:error] [pid 515259:tid 515408] [client 20.48.251.3:43075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/maxro.php"] [unique_id "apPlcmZcVaai59truiVvMAAAABI"]
[Sun Aug 30 03:10:26.601598 2026] [security2:error] [pid 515259:tid 515501] [client 20.63.81.20:31676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/okxoby.php"] [unique_id "apPlcmZcVaai59truiVvNQAAAG8"]
[Sun Aug 30 03:10:26.619763 2026] [security2:error] [pid 515259:tid 515474] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/travis/.env"] [unique_id "apPlcmZcVaai59truiVvPQAAAFQ"]
[Sun Aug 30 03:10:26.623175 2026] [security2:error] [pid 515259:tid 515517] [client 20.48.160.90:63982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.biospherecampus.com"] [uri "/reviall.php"] [unique_id "apPlcmZcVaai59truiVvPwAAAH8"]
[Sun Aug 30 03:10:26.647070 2026] [security2:error] [pid 515259:tid 515443] [client 20.104.18.15:17018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/fling.php"] [unique_id "apPlcmZcVaai59truiVvQQAAADU"]
[Sun Aug 30 03:10:26.660604 2026] [security2:error] [pid 515259:tid 515477] [client 20.220.10.235:5512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/xda.php"] [unique_id "apPlcmZcVaai59truiVvRgAAAFc"]
[Sun Aug 30 03:10:26.663806 2026] [security2:error] [pid 515259:tid 515406] [client 20.104.50.220:28735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/modul.php"] [unique_id "apPlcmZcVaai59truiVvRwAAABA"]
[Sun Aug 30 03:10:26.689606 2026] [security2:error] [pid 515259:tid 515441] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/buildkite/.env"] [unique_id "apPlcmZcVaai59truiVvTgAAADM"]
[Sun Aug 30 03:10:26.693975 2026] [security2:error] [pid 515259:tid 515513] [client 20.197.61.180:3585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/ms-files.php"] [unique_id "apPlcmZcVaai59truiVvUAAAAHs"]
[Sun Aug 30 03:10:26.719308 2026] [security2:error] [pid 515259:tid 515434] [client 20.104.49.130:63538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/log.php"] [unique_id "apPlcmZcVaai59truiVvUwAAACw"]
[Sun Aug 30 03:10:26.734105 2026] [security2:error] [pid 515259:tid 515475] [client 40.83.93.50:6163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/classsmtps.php"] [unique_id "apPlcmZcVaai59truiVvVAAAAFU"]
[Sun Aug 30 03:10:26.736458 2026] [security2:error] [pid 515259:tid 515471] [client 20.48.251.3:56374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/filesystems.php"] [unique_id "apPlcmZcVaai59truiVvVQAAAFE"]
[Sun Aug 30 03:10:26.736995 2026] [security2:error] [pid 515259:tid 515458] [client 20.63.81.20:31559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/esuutzzx.php"] [unique_id "apPlcmZcVaai59truiVvVgAAAEQ"]
[Sun Aug 30 03:10:26.739458 2026] [security2:error] [pid 515259:tid 515494] [client 20.48.250.41:17336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/aa.php"] [unique_id "apPlcmZcVaai59truiVvVwAAAGg"]
[Sun Aug 30 03:10:26.753660 2026] [security2:error] [pid 515259:tid 515508] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/mysql/.env"] [unique_id "apPlcmZcVaai59truiVvWAAAAHY"]
[Sun Aug 30 03:10:26.780513 2026] [security2:error] [pid 515259:tid 515466] [client 158.23.147.79:56476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/themes.php"] [unique_id "apPlcmZcVaai59truiVvYwAAAEw"]
[Sun Aug 30 03:10:26.803237 2026] [security2:error] [pid 515259:tid 515408] [client 20.104.50.220:64452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/locale.php"] [unique_id "apPlcmZcVaai59truiVvaAAAABI"]
[Sun Aug 30 03:10:26.815062 2026] [security2:error] [pid 515259:tid 515502] [client 20.104.18.15:22437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/simple.php"] [unique_id "apPlcmZcVaai59truiVvaQAAAHA"]
[Sun Aug 30 03:10:26.815250 2026] [security2:error] [pid 515259:tid 515501] [client 20.220.10.235:5848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/wp-admin/js/index.php"] [unique_id "apPlcmZcVaai59truiVvagAAAG8"]
[Sun Aug 30 03:10:26.822760 2026] [security2:error] [pid 515259:tid 515454] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/postgres/.env"] [unique_id "apPlcmZcVaai59truiVvbAAAAEA"]
[Sun Aug 30 03:10:26.840261 2026] [authz_core:error] [pid 515259:tid 515428] [client 66.249.66.70:55408] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:26.840541 2026] [authz_core:error] [pid 515259:tid 515428] [client 66.249.66.70:55408] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:26.853057 2026] [security2:error] [pid 515259:tid 515429] [client 20.104.18.15:18426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/kerang.php"] [unique_id "apPlcmZcVaai59truiVvbwAAACc"]
[Sun Aug 30 03:10:26.878240 2026] [security2:error] [pid 515259:tid 515503] [client 20.63.81.20:31643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/replace.php"] [unique_id "apPlcmZcVaai59truiVvdQAAAHE"]
[Sun Aug 30 03:10:26.880219 2026] [authz_core:error] [pid 515259:tid 515440] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:26.880502 2026] [authz_core:error] [pid 515259:tid 515440] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:26.885533 2026] [security2:error] [pid 515259:tid 515396] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/mongodb/.env"] [unique_id "apPlcmZcVaai59truiVvdwAAAAY"]
[Sun Aug 30 03:10:26.892383 2026] [security2:error] [pid 515259:tid 515474] [client 20.104.49.130:43647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/zoo2.php"] [unique_id "apPlcmZcVaai59truiVveQAAAFQ"]
[Sun Aug 30 03:10:26.913266 2026] [security2:error] [pid 515259:tid 515420] [client 68.155.159.216:45966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-admin/user/index.php"] [unique_id "apPlcmZcVaai59truiVvgQAAAB4"]
[Sun Aug 30 03:10:26.918532 2026] [security2:error] [pid 515259:tid 515401] [client 20.48.250.41:17168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/s1.php"] [unique_id "apPlcmZcVaai59truiVvhAAAAAs"]
[Sun Aug 30 03:10:26.937017 2026] [security2:error] [pid 515259:tid 515456] [client 68.155.159.216:63294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apPlcmZcVaai59truiVvhwAAAEI"]
[Sun Aug 30 03:10:26.940318 2026] [security2:error] [pid 515259:tid 515516] [client 68.155.159.216:52599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/dropdown.php"] [unique_id "apPlcmZcVaai59truiVviAAAAH4"]
[Sun Aug 30 03:10:26.943790 2026] [security2:error] [pid 515259:tid 515445] [client 20.104.49.130:52474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/fs.php"] [unique_id "apPlcmZcVaai59truiVviQAAADc"]
[Sun Aug 30 03:10:26.944783 2026] [security2:error] [pid 515259:tid 515495] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/redis/.env"] [unique_id "apPlcmZcVaai59truiVvigAAAGk"]
[Sun Aug 30 03:10:26.952455 2026] [security2:error] [pid 515259:tid 515449] [client 4.205.62.107:58453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/configuration.php"] [unique_id "apPlcmZcVaai59truiVviwAAADs"]
[Sun Aug 30 03:10:26.959628 2026] [authz_core:error] [pid 515259:tid 515448] [client 216.73.216.128:64209] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:26.959946 2026] [authz_core:error] [pid 515259:tid 515448] [client 216.73.216.128:64209] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:26.962813 2026] [authz_core:error] [pid 515259:tid 515511] [client 66.249.66.40:41233] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:26.963098 2026] [authz_core:error] [pid 515259:tid 515511] [client 66.249.66.40:41233] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:27.004737 2026] [security2:error] [pid 515259:tid 515394] [client 20.63.81.20:31587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/gulu.php"] [unique_id "apPlc2ZcVaai59truiVvmwAAAAQ"]
[Sun Aug 30 03:10:27.010401 2026] [security2:error] [pid 515259:tid 515423] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/elasticsearch/.env"] [unique_id "apPlc2ZcVaai59truiVvnAAAACE"]
[Sun Aug 30 03:10:27.027629 2026] [security2:error] [pid 515259:tid 515480] [client 20.104.50.220:5595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/memek.php"] [unique_id "apPlc2ZcVaai59truiVvngAAAFo"]
[Sun Aug 30 03:10:27.049275 2026] [authz_core:error] [pid 515259:tid 515504] [client 216.73.216.128:51580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:27.049546 2026] [authz_core:error] [pid 515259:tid 515504] [client 216.73.216.128:51580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:27.053283 2026] [security2:error] [pid 515259:tid 515402] [client 20.104.50.220:42802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/gelay.php"] [unique_id "apPlc2ZcVaai59truiVvqAAAAAw"]
[Sun Aug 30 03:10:27.068232 2026] [security2:error] [pid 515259:tid 515476] [client 158.23.147.79:43866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/admin.php"] [unique_id "apPlc2ZcVaai59truiVvrAAAAFY"]
[Sun Aug 30 03:10:27.082448 2026] [security2:error] [pid 515259:tid 515416] [client 20.104.50.220:33549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/gel4y.php"] [unique_id "apPlc2ZcVaai59truiVvsgAAABo"]
[Sun Aug 30 03:10:27.084723 2026] [security2:error] [pid 515259:tid 515503] [client 20.48.250.41:17317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/0byte.php"] [unique_id "apPlc2ZcVaai59truiVvswAAAHE"]
[Sun Aug 30 03:10:27.086533 2026] [security2:error] [pid 515259:tid 515396] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/rabbitmq/.env"] [unique_id "apPlc2ZcVaai59truiVvtAAAAAY"]
[Sun Aug 30 03:10:27.091341 2026] [security2:error] [pid 515259:tid 515517] [client 20.48.251.3:54822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/app_dev.php"] [unique_id "apPlc2ZcVaai59truiVvuAAAAH8"]
[Sun Aug 30 03:10:27.118179 2026] [security2:error] [pid 515259:tid 515420] [client 20.220.10.235:5522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/t00l.php"] [unique_id "apPlc2ZcVaai59truiVvuwAAAB4"]
[Sun Aug 30 03:10:27.143803 2026] [security2:error] [pid 515259:tid 515392] [client 20.63.81.20:31641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/gtghklk.php"] [unique_id "apPlc2ZcVaai59truiVvwQAAAAI"]
[Sun Aug 30 03:10:27.146716 2026] [security2:error] [pid 515259:tid 515411] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/kafka/.env"] [unique_id "apPlc2ZcVaai59truiVvwwAAABU"]
[Sun Aug 30 03:10:27.197134 2026] [security2:error] [pid 515259:tid 515424] [client 20.104.50.220:61421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/radio.php"] [unique_id "apPlc2ZcVaai59truiVvyQAAACI"]
[Sun Aug 30 03:10:27.215891 2026] [security2:error] [pid 515259:tid 515500] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/queue/.env"] [unique_id "apPlc2ZcVaai59truiVvzAAAAG4"]
[Sun Aug 30 03:10:27.232179 2026] [security2:error] [pid 515259:tid 515480] [client 20.48.250.41:17329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/xr.php"] [unique_id "apPlc2ZcVaai59truiVv1AAAAFo"]
[Sun Aug 30 03:10:27.260373 2026] [security2:error] [pid 515259:tid 515484] [client 20.63.219.114:15632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/error.php"] [unique_id "apPlc2ZcVaai59truiVv2QAAAF4"]
[Sun Aug 30 03:10:27.278976 2026] [security2:error] [pid 515259:tid 515458] [client 20.63.81.20:31657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/comand.php"] [unique_id "apPlc2ZcVaai59truiVv3QAAAEQ"]
[Sun Aug 30 03:10:27.293672 2026] [security2:error] [pid 515259:tid 515493] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/worker/.env"] [unique_id "apPlc2ZcVaai59truiVv5AAAAGc"]
[Sun Aug 30 03:10:27.295343 2026] [security2:error] [pid 515259:tid 515460] [client 158.23.147.79:52286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/xmlrpc.php"] [unique_id "apPlc2ZcVaai59truiVv5QAAAEY"]
[Sun Aug 30 03:10:27.295941 2026] [security2:error] [pid 515259:tid 515481] [client 158.23.184.117:8132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "apPlc2ZcVaai59truiVv5gAAAFs"]
[Sun Aug 30 03:10:27.303191 2026] [security2:error] [pid 515259:tid 515476] [client 20.220.10.235:5316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/ls.php"] [unique_id "apPlc2ZcVaai59truiVv6QAAAFY"]
[Sun Aug 30 03:10:27.305131 2026] [security2:error] [pid 515259:tid 515433] [client 20.104.18.15:43865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/gos.php"] [unique_id "apPlc2ZcVaai59truiVv6wAAACs"]
[Sun Aug 30 03:10:27.326034 2026] [authz_core:error] [pid 515259:tid 515417] [client 66.249.66.43:44608] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:27.326301 2026] [authz_core:error] [pid 515259:tid 515417] [client 66.249.66.43:44608] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:27.335796 2026] [security2:error] [pid 515259:tid 515492] [client 20.104.49.130:34508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/wp-the.php"] [unique_id "apPlc2ZcVaai59truiVv9QAAAGY"]
[Sun Aug 30 03:10:27.349445 2026] [security2:error] [pid 515259:tid 515415] [client 40.83.93.50:6165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/install.php"] [unique_id "apPlc2ZcVaai59truiVv-gAAABk"]
[Sun Aug 30 03:10:27.358133 2026] [security2:error] [pid 515259:tid 515462] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/job/.env"] [unique_id "apPlc2ZcVaai59truiVv-wAAAEg"]
[Sun Aug 30 03:10:27.363742 2026] [security2:error] [pid 515259:tid 515401] [client 20.151.200.44:40928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/dehnl.php"] [unique_id "apPlc2ZcVaai59truiVv_AAAAAs"]
[Sun Aug 30 03:10:27.400540 2026] [authz_core:error] [pid 515259:tid 515441] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:27.400842 2026] [authz_core:error] [pid 515259:tid 515441] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:27.406376 2026] [security2:error] [pid 515259:tid 515439] [client 20.63.81.20:31535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp_motu_myk3v.php"] [unique_id "apPlc2ZcVaai59truiVwAwAAADE"]
[Sun Aug 30 03:10:27.406772 2026] [security2:error] [pid 515259:tid 515456] [client 20.197.61.180:16880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/news-portal/error.php"] [unique_id "apPlc2ZcVaai59truiVwBAAAAEI"]
[Sun Aug 30 03:10:27.409740 2026] [security2:error] [pid 515259:tid 515424] [client 20.151.200.44:28666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/admin.php/700.php"] [unique_id "apPlc2ZcVaai59truiVwBwAAACI"]
[Sun Aug 30 03:10:27.413678 2026] [authz_core:error] [pid 515259:tid 515427] [client 216.73.216.128:51580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:27.413962 2026] [authz_core:error] [pid 515259:tid 515427] [client 216.73.216.128:51580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:27.415921 2026] [security2:error] [pid 515259:tid 515507] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/test/.env"] [unique_id "apPlc2ZcVaai59truiVwCAAAAHU"]
[Sun Aug 30 03:10:27.441076 2026] [security2:error] [pid 515259:tid 515430] [client 158.23.184.117:8152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/light.php"] [unique_id "apPlc2ZcVaai59truiVwCwAAACg"]
[Sun Aug 30 03:10:27.452809 2026] [security2:error] [pid 515259:tid 515422] [client 20.48.250.41:17284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/h02ugyh.php"] [unique_id "apPlc2ZcVaai59truiVwEwAAACA"]
[Sun Aug 30 03:10:27.477189 2026] [security2:error] [pid 515259:tid 515481] [client 158.23.147.79:52239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/atomlib.php"] [unique_id "apPlc2ZcVaai59truiVwHQAAAFs"]
[Sun Aug 30 03:10:27.490254 2026] [security2:error] [pid 515259:tid 515503] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/qa/.env"] [unique_id "apPlc2ZcVaai59truiVwIAAAAHE"]
[Sun Aug 30 03:10:27.506111 2026] [authz_core:error] [pid 515259:tid 515469] [client 216.73.216.128:64209] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:27.506527 2026] [authz_core:error] [pid 515259:tid 515469] [client 216.73.216.128:64209] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:27.536492 2026] [security2:error] [pid 515259:tid 515393] [client 20.63.81.20:31592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/wp_motu_ypdat.php"] [unique_id "apPlc2ZcVaai59truiVwJgAAAAM"]
[Sun Aug 30 03:10:27.541217 2026] [authz_core:error] [pid 515259:tid 515502] [client 66.249.66.75:39812] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:27.541660 2026] [authz_core:error] [pid 515259:tid 515502] [client 66.249.66.75:39812] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:27.543925 2026] [security2:error] [pid 515259:tid 515416] [client 20.220.10.235:5374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/css/000.php"] [unique_id "apPlc2ZcVaai59truiVwKAAAABo"]
[Sun Aug 30 03:10:27.550355 2026] [security2:error] [pid 515259:tid 515408] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/preview/.env"] [unique_id "apPlc2ZcVaai59truiVwKQAAABI"]
[Sun Aug 30 03:10:27.559992 2026] [security2:error] [pid 515259:tid 515472] [client 4.205.62.107:25475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/thui.php"] [unique_id "apPlc2ZcVaai59truiVwLAAAAFI"]
[Sun Aug 30 03:10:27.567631 2026] [security2:error] [pid 515259:tid 515412] [client 20.104.50.220:17273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/manager.php"] [unique_id "apPlc2ZcVaai59truiVwLgAAABY"]
[Sun Aug 30 03:10:27.583248 2026] [security2:error] [pid 515259:tid 515498] [client 20.104.18.15:16746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/f35.php"] [unique_id "apPlc2ZcVaai59truiVwMAAAAGw"]
[Sun Aug 30 03:10:27.589491 2026] [security2:error] [pid 515259:tid 515479] [client 158.23.184.117:8176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/wp-admin/css/about.php7"] [unique_id "apPlc2ZcVaai59truiVwMQAAAFk"]
[Sun Aug 30 03:10:27.619958 2026] [security2:error] [pid 515259:tid 515415] [client 4.205.62.107:36709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/app_local.php"] [unique_id "apPlc2ZcVaai59truiVwOQAAABk"]
[Sun Aug 30 03:10:27.620477 2026] [security2:error] [pid 515259:tid 515513] [client 20.48.251.3:59272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/autogooey.php"] [unique_id "apPlc2ZcVaai59truiVwOwAAAHs"]
[Sun Aug 30 03:10:27.622930 2026] [security2:error] [pid 515259:tid 515443] [client 4.205.62.107:17335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/maxro.php"] [unique_id "apPlc2ZcVaai59truiVwPQAAADU"]
[Sun Aug 30 03:10:27.630548 2026] [security2:error] [pid 515259:tid 515406] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/beta/.env"] [unique_id "apPlc2ZcVaai59truiVwQAAAABA"]
[Sun Aug 30 03:10:27.660048 2026] [security2:error] [pid 515259:tid 515511] [client 20.220.10.235:34844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlc2ZcVaai59truiVwTQAAAHk"]
[Sun Aug 30 03:10:27.662421 2026] [security2:error] [pid 515259:tid 515461] [client 20.48.250.41:17258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/xxw.php"] [unique_id "apPlc2ZcVaai59truiVwTgAAAEc"]
[Sun Aug 30 03:10:27.666418 2026] [security2:error] [pid 515259:tid 515484] [client 20.63.81.20:31558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/edit.php"] [unique_id "apPlc2ZcVaai59truiVwUgAAAF4"]
[Sun Aug 30 03:10:27.685564 2026] [security2:error] [pid 515259:tid 515466] [client 20.104.18.15:35785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "firesouq.com"] [uri "/reviall.php"] [unique_id "apPlc2ZcVaai59truiVwVgAAAEw"]
[Sun Aug 30 03:10:27.706638 2026] [security2:error] [pid 515259:tid 515434] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/uat/.env"] [unique_id "apPlc2ZcVaai59truiVwWgAAACw"]
[Sun Aug 30 03:10:27.739204 2026] [security2:error] [pid 515259:tid 515481] [client 158.23.184.117:8161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/alf.php"] [unique_id "apPlc2ZcVaai59truiVwXQAAAFs"]
[Sun Aug 30 03:10:27.742257 2026] [security2:error] [pid 515259:tid 515402] [client 20.104.50.220:63216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/mode.php"] [unique_id "apPlc2ZcVaai59truiVwXgAAAAw"]
[Sun Aug 30 03:10:27.748867 2026] [security2:error] [pid 515259:tid 515460] [client 20.48.251.3:52260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/brc.php"] [unique_id "apPlc2ZcVaai59truiVwYAAAAEY"]
[Sun Aug 30 03:10:27.764838 2026] [security2:error] [pid 515259:tid 515427] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/stage/.env"] [unique_id "apPlc2ZcVaai59truiVwZAAAACU"]
[Sun Aug 30 03:10:27.772085 2026] [security2:error] [pid 515259:tid 515432] [client 20.220.10.235:5296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/cy.php"] [unique_id "apPlc2ZcVaai59truiVwZwAAACo"]
[Sun Aug 30 03:10:27.789043 2026] [security2:error] [pid 515259:tid 515489] [client 20.104.18.15:16989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/btyuio.php"] [unique_id "apPlc2ZcVaai59truiVwcAAAAGM"]
[Sun Aug 30 03:10:27.801225 2026] [security2:error] [pid 515259:tid 515438] [client 20.220.10.235:34840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlc2ZcVaai59truiVwdAAAADA"]
[Sun Aug 30 03:10:27.805456 2026] [security2:error] [pid 515259:tid 515457] [client 20.63.81.20:31727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/tqkdqbbv.php"] [unique_id "apPlc2ZcVaai59truiVwdQAAAEM"]
[Sun Aug 30 03:10:27.808097 2026] [security2:error] [pid 515259:tid 515513] [client 158.23.147.79:43896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/lv.php"] [unique_id "apPlc2ZcVaai59truiVwdwAAAHs"]
[Sun Aug 30 03:10:27.809302 2026] [security2:error] [pid 515259:tid 515443] [client 158.23.147.79:2029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-mail.php"] [unique_id "apPlc2ZcVaai59truiVweAAAADU"]
[Sun Aug 30 03:10:27.817095 2026] [security2:error] [pid 515259:tid 515403] [client 20.104.50.220:52813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/configuration.php"] [unique_id "apPlc2ZcVaai59truiVwfAAAAA0"]
[Sun Aug 30 03:10:27.839159 2026] [security2:error] [pid 515259:tid 515485] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/development/.env"] [unique_id "apPlc2ZcVaai59truiVwfwAAAF8"]
[Sun Aug 30 03:10:27.846626 2026] [security2:error] [pid 515259:tid 515411] [client 20.104.49.130:63572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/wsd.php"] [unique_id "apPlc2ZcVaai59truiVwgAAAABU"]
[Sun Aug 30 03:10:27.876394 2026] [authz_core:error] [pid 515259:tid 515425] [client 216.73.216.128:51580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:27.876864 2026] [authz_core:error] [pid 515259:tid 515425] [client 216.73.216.128:51580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:27.881832 2026] [authz_core:error] [pid 515259:tid 515422] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:27.882292 2026] [authz_core:error] [pid 515259:tid 515422] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:27.884124 2026] [security2:error] [pid 515259:tid 515436] [client 20.48.250.41:17330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/bolt.php"] [unique_id "apPlc2ZcVaai59truiVwiAAAAC4"]
[Sun Aug 30 03:10:27.901629 2026] [security2:error] [pid 515259:tid 515463] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/production/.env"] [unique_id "apPlc2ZcVaai59truiVwjAAAAEk"]
[Sun Aug 30 03:10:27.915257 2026] [authz_core:error] [pid 515259:tid 515397] [client 66.249.66.70:58425] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:27.915587 2026] [authz_core:error] [pid 515259:tid 515397] [client 66.249.66.70:58425] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:27.934206 2026] [security2:error] [pid 515259:tid 515442] [client 20.220.10.235:5788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/admin.php/pindex.php"] [unique_id "apPlc2ZcVaai59truiVwmAAAADQ"]
[Sun Aug 30 03:10:27.935733 2026] [security2:error] [pid 515259:tid 515402] [client 20.220.10.235:34951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/h02ugyh.php"] [unique_id "apPlc2ZcVaai59truiVwmgAAAAw"]
[Sun Aug 30 03:10:27.936973 2026] [security2:error] [pid 515259:tid 515429] [client 20.63.81.20:31598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/kjyehoxl.php"] [unique_id "apPlc2ZcVaai59truiVwmwAAACc"]
[Sun Aug 30 03:10:27.939529 2026] [security2:error] [pid 515259:tid 515476] [client 20.63.219.114:14764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/profile.php"] [unique_id "apPlc2ZcVaai59truiVwngAAAFY"]
[Sun Aug 30 03:10:27.945314 2026] [authz_core:error] [pid 515259:tid 515460] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:27.945580 2026] [authz_core:error] [pid 515259:tid 515460] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:27.963537 2026] [security2:error] [pid 515259:tid 515472] [client 20.104.50.220:29368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/enter.php"] [unique_id "apPlc2ZcVaai59truiVwowAAAFI"]
[Sun Aug 30 03:10:27.964391 2026] [security2:error] [pid 515259:tid 515433] [client 20.48.251.3:13976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/tax.php"] [unique_id "apPlc2ZcVaai59truiVwpAAAACs"]
[Sun Aug 30 03:10:27.965943 2026] [security2:error] [pid 515259:tid 515482] [client 20.104.18.15:22489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/xty.php"] [unique_id "apPlc2ZcVaai59truiVwpgAAAFw"]
[Sun Aug 30 03:10:27.966823 2026] [security2:error] [pid 515259:tid 515417] [client 34.130.99.179:55454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pisaderesistance.com"] [uri "/config/app/.env"] [unique_id "apPlc2ZcVaai59truiVwpwAAABs"]
[Sun Aug 30 03:10:27.984635 2026] [security2:error] [pid 515259:tid 515509] [client 158.23.184.117:8183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/wp-admin/import.php"] [unique_id "apPlc2ZcVaai59truiVwrwAAAHc"]
[Sun Aug 30 03:10:28.012908 2026] [security2:error] [pid 515259:tid 515502] [client 20.104.18.15:18384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/m.php"] [unique_id "apPldGZcVaai59truiVwtgAAAHA"]
[Sun Aug 30 03:10:28.031590 2026] [security2:error] [pid 515259:tid 515423] [client 20.48.250.41:17347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/rtx.php"] [unique_id "apPldGZcVaai59truiVwvAAAACE"]
[Sun Aug 30 03:10:28.047988 2026] [security2:error] [pid 515259:tid 515421] [client 34.130.99.179:55454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/phpinfo.php"] [unique_id "apPldGZcVaai59truiVwvgAAAB8"]
[Sun Aug 30 03:10:28.063383 2026] [security2:error] [pid 515259:tid 515477] [client 20.63.81.20:31582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/llyuxaqd.php"] [unique_id "apPldGZcVaai59truiVwyQAAAFc"]
[Sun Aug 30 03:10:28.071541 2026] [security2:error] [pid 515259:tid 515480] [client 68.155.159.216:62646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apPldGZcVaai59truiVwzAAAAFo"]
[Sun Aug 30 03:10:28.084218 2026] [security2:error] [pid 515259:tid 515478] [client 20.220.10.235:34844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/sf.php"] [unique_id "apPldGZcVaai59truiVw0gAAAFg"]
[Sun Aug 30 03:10:28.088001 2026] [security2:error] [pid 515259:tid 515458] [client 40.83.93.50:22125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/wp.php"] [unique_id "apPldGZcVaai59truiVw0wAAAEQ"]
[Sun Aug 30 03:10:28.097598 2026] [authz_core:error] [pid 515259:tid 515515] [client 66.249.66.37:50320] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:28.097922 2026] [authz_core:error] [pid 515259:tid 515515] [client 66.249.66.37:50320] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:28.102366 2026] [security2:error] [pid 515259:tid 515487] [client 68.155.159.216:52554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/sad/about.php"] [unique_id "apPldGZcVaai59truiVw2gAAAGE"]
[Sun Aug 30 03:10:28.108676 2026] [security2:error] [pid 515259:tid 515459] [client 20.197.61.180:3229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/nvt/includes/plugins/wp-blog-header.php"] [unique_id "apPldGZcVaai59truiVw3gAAAEU"]
[Sun Aug 30 03:10:28.109924 2026] [security2:error] [pid 515259:tid 515482] [client 20.220.10.235:5844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/admin.php/csv.php"] [unique_id "apPldGZcVaai59truiVw3wAAAFw"]
[Sun Aug 30 03:10:28.122432 2026] [security2:error] [pid 515259:tid 515498] [client 20.104.104.62:62919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPldGZcVaai59truiVw4wAAAGw"]
[Sun Aug 30 03:10:28.126825 2026] [security2:error] [pid 515259:tid 515471] [client 158.23.184.117:8181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "apPldGZcVaai59truiVw5AAAAFE"]
[Sun Aug 30 03:10:28.144567 2026] [security2:error] [pid 515259:tid 515483] [client 4.205.62.107:38417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/server_info.php"] [unique_id "apPldGZcVaai59truiVw7gAAAF0"]
[Sun Aug 30 03:10:28.173927 2026] [security2:error] [pid 515259:tid 515497] [client 20.48.250.41:17386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/ckk.php"] [unique_id "apPldGZcVaai59truiVw9gAAAGs"]
[Sun Aug 30 03:10:28.188289 2026] [security2:error] [pid 515259:tid 515468] [client 20.104.49.130:36781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/sta.php"] [unique_id "apPldGZcVaai59truiVw-QAAAE4"]
[Sun Aug 30 03:10:28.194925 2026] [security2:error] [pid 515259:tid 515450] [client 20.63.81.20:31638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/nbwxolou.php"] [unique_id "apPldGZcVaai59truiVw-wAAADw"]
[Sun Aug 30 03:10:28.200193 2026] [security2:error] [pid 515259:tid 515419] [client 20.104.50.220:51553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/darkshell.php"] [unique_id "apPldGZcVaai59truiVw_QAAAB0"]
[Sun Aug 30 03:10:28.201334 2026] [security2:error] [pid 515259:tid 515446] [client 20.104.50.220:5485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/jancok.php"] [unique_id "apPldGZcVaai59truiVw_gAAADg"]
[Sun Aug 30 03:10:28.212560 2026] [security2:error] [pid 515259:tid 515462] [client 158.23.147.79:43863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apPldGZcVaai59truiVxAAAAAEg"]
[Sun Aug 30 03:10:28.234077 2026] [security2:error] [pid 515259:tid 515463] [client 20.220.10.235:34847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/4e.php"] [unique_id "apPldGZcVaai59truiVxAwAAAEk"]
[Sun Aug 30 03:10:28.234971 2026] [authz_core:error] [pid 515259:tid 515430] [client 216.73.216.128:51580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:28.235268 2026] [authz_core:error] [pid 515259:tid 515430] [client 216.73.216.128:51580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:28.246947 2026] [security2:error] [pid 515259:tid 515447] [client 34.130.99.179:51874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/info.php"] [unique_id "apPldGZcVaai59truiVxCQAAADk"]
[Sun Aug 30 03:10:28.265895 2026] [security2:error] [pid 515259:tid 515504] [client 20.48.251.3:64274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/php-info.php"] [unique_id "apPldGZcVaai59truiVxCwAAAHI"]
[Sun Aug 30 03:10:28.272508 2026] [security2:error] [pid 515259:tid 515418] [client 20.104.104.62:49613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPldGZcVaai59truiVxDQAAABw"]
[Sun Aug 30 03:10:28.272961 2026] [cgid:error] [pid 515259:tid 515454] [client 158.23.184.117:8170] AH01265: stderr from /home1/tmcd/public_html/faceofaustralia.com.au/cgi-bin/: attempt to invoke directory as script
[Sun Aug 30 03:10:28.309101 2026] [security2:error] [pid 515259:tid 515452] [client 20.48.250.41:17331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.troop678.com"] [uri "/R57.php"] [unique_id "apPldGZcVaai59truiVxGgAAAD4"]
[Sun Aug 30 03:10:28.319076 2026] [core:alert] [pid 515259:tid 515405] [client 41.121.136.5:17736] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:10:28.324601 2026] [security2:error] [pid 515259:tid 515437] [client 20.63.81.20:31588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/nsxeubyv.php"] [unique_id "apPldGZcVaai59truiVxIgAAAC8"]
[Sun Aug 30 03:10:28.324676 2026] [security2:error] [pid 515259:tid 515485] [client 20.104.50.220:33596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/contacts.php"] [unique_id "apPldGZcVaai59truiVxIQAAAF8"]
[Sun Aug 30 03:10:28.365362 2026] [security2:error] [pid 515259:tid 515497] [client 20.104.50.220:61976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/shell20211028.php"] [unique_id "apPldGZcVaai59truiVxJgAAAGs"]
[Sun Aug 30 03:10:28.366444 2026] [security2:error] [pid 515259:tid 515475] [client 158.23.147.79:52268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/content.php"] [unique_id "apPldGZcVaai59truiVxKAAAAFU"]
[Sun Aug 30 03:10:28.374482 2026] [security2:error] [pid 515259:tid 515435] [client 20.220.10.235:5321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/admin.php/700.php"] [unique_id "apPldGZcVaai59truiVxKwAAAC0"]
[Sun Aug 30 03:10:28.382529 2026] [authz_core:error] [pid 515259:tid 515488] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:28.382889 2026] [authz_core:error] [pid 515259:tid 515488] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:28.387223 2026] [security2:error] [pid 515259:tid 515439] [client 20.220.10.235:34871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/ssss.php"] [unique_id "apPldGZcVaai59truiVxLgAAADE"]
[Sun Aug 30 03:10:28.402902 2026] [security2:error] [pid 515259:tid 515500] [client 158.23.184.117:8170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/wp-admin/admin-post.php"] [unique_id "apPldGZcVaai59truiVxNAAAAG4"]
[Sun Aug 30 03:10:28.405072 2026] [security2:error] [pid 515259:tid 515466] [client 20.104.104.62:2924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/h02ugyh.php"] [unique_id "apPldGZcVaai59truiVxNQAAAEw"]
[Sun Aug 30 03:10:28.446126 2026] [security2:error] [pid 515259:tid 515393] [client 20.104.18.15:43284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/132.php"] [unique_id "apPldGZcVaai59truiVxPAAAAAM"]
[Sun Aug 30 03:10:28.447777 2026] [security2:error] [pid 515259:tid 515478] [client 20.104.49.130:58202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/155.php"] [unique_id "apPldGZcVaai59truiVxQAAAAFg"]
[Sun Aug 30 03:10:28.451474 2026] [security2:error] [pid 515259:tid 515505] [client 34.130.99.179:51890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/php.php"] [unique_id "apPldGZcVaai59truiVxQgAAAHM"]
[Sun Aug 30 03:10:28.455794 2026] [security2:error] [pid 515259:tid 515436] [client 20.63.81.20:31668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/zfqipfss.php"] [unique_id "apPldGZcVaai59truiVxRAAAAC4"]
[Sun Aug 30 03:10:28.461199 2026] [security2:error] [pid 515259:tid 515471] [client 20.151.200.44:28618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/admin.php/007x.php"] [unique_id "apPldGZcVaai59truiVxSQAAAFE"]
[Sun Aug 30 03:10:28.507561 2026] [security2:error] [pid 515259:tid 515452] [client 68.155.159.216:46067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-includes/plugins.php"] [unique_id "apPldGZcVaai59truiVxUAAAAD4"]
[Sun Aug 30 03:10:28.513080 2026] [authz_core:error] [pid 515259:tid 515489] [client 216.73.216.128:46513] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:28.513515 2026] [authz_core:error] [pid 515259:tid 515489] [client 216.73.216.128:46513] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:28.534449 2026] [security2:error] [pid 515259:tid 515395] [client 20.220.10.235:34944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/zoz.php"] [unique_id "apPldGZcVaai59truiVxUQAAAAU"]
[Sun Aug 30 03:10:28.546762 2026] [security2:error] [pid 515259:tid 515498] [client 158.23.184.117:8171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/favicon.php"] [unique_id "apPldGZcVaai59truiVxVAAAAGw"]
[Sun Aug 30 03:10:28.546850 2026] [security2:error] [pid 515259:tid 515468] [client 20.63.219.114:14755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/sql.php"] [unique_id "apPldGZcVaai59truiVxVQAAAE4"]
[Sun Aug 30 03:10:28.547661 2026] [security2:error] [pid 515259:tid 515469] [client 20.104.104.62:49642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/sf.php"] [unique_id "apPldGZcVaai59truiVxVgAAAE8"]
[Sun Aug 30 03:10:28.566851 2026] [security2:error] [pid 515259:tid 515444] [client 20.220.10.235:5806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/admin.php/007x.php"] [unique_id "apPldGZcVaai59truiVxXAAAADY"]
[Sun Aug 30 03:10:28.582990 2026] [security2:error] [pid 515259:tid 515516] [client 20.63.81.20:31572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "proactivemaintenancesolutions.com"] [uri "/zrjuyoos.php"] [unique_id "apPldGZcVaai59truiVxYwAAAH4"]
[Sun Aug 30 03:10:28.637119 2026] [authz_core:error] [pid 515259:tid 515427] [client 66.249.66.39:50902] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:28.637540 2026] [authz_core:error] [pid 515259:tid 515427] [client 66.249.66.39:50902] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:28.639619 2026] [security2:error] [pid 515259:tid 515484] [client 158.23.147.79:43841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPldGZcVaai59truiVxcgAAAF4"]
[Sun Aug 30 03:10:28.661689 2026] [security2:error] [pid 515259:tid 515517] [client 34.130.99.179:51904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/i.php"] [unique_id "apPldGZcVaai59truiVxeQAAAH8"]
[Sun Aug 30 03:10:28.671217 2026] [security2:error] [pid 515259:tid 515454] [client 20.220.10.235:34858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/kcs.php"] [unique_id "apPldGZcVaai59truiVxfQAAAEA"]
[Sun Aug 30 03:10:28.675467 2026] [security2:error] [pid 515259:tid 515422] [client 20.104.104.62:65218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/4e.php"] [unique_id "apPldGZcVaai59truiVxfgAAACA"]
[Sun Aug 30 03:10:28.675511 2026] [security2:error] [pid 515259:tid 515418] [client 40.83.93.50:6171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/error.php"] [unique_id "apPldGZcVaai59truiVxfwAAABw"]
[Sun Aug 30 03:10:28.686102 2026] [security2:error] [pid 515259:tid 515499] [client 158.23.184.117:8144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/wp-admin/css/my.php"] [unique_id "apPldGZcVaai59truiVxhgAAAG0"]
[Sun Aug 30 03:10:28.690438 2026] [authz_core:error] [pid 515259:tid 515459] [client 216.73.216.128:51580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:28.690728 2026] [authz_core:error] [pid 515259:tid 515459] [client 216.73.216.128:51580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:28.706861 2026] [security2:error] [pid 515259:tid 515506] [client 20.104.50.220:16736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/item.php"] [unique_id "apPldGZcVaai59truiVxiwAAAHQ"]
[Sun Aug 30 03:10:28.710582 2026] [security2:error] [pid 515259:tid 515425] [client 20.104.18.15:64784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/shiny.php"] [unique_id "apPldGZcVaai59truiVxjQAAACM"]
[Sun Aug 30 03:10:28.710612 2026] [security2:error] [pid 515259:tid 515401] [client 20.104.49.130:63570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/kgoc6awap3napxxxdCdefault.php"] [unique_id "apPldGZcVaai59truiVxjAAAAAs"]
[Sun Aug 30 03:10:28.754158 2026] [security2:error] [pid 515259:tid 515399] [client 20.48.251.3:59345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/sdsa.php"] [unique_id "apPldGZcVaai59truiVxlgAAAAk"]
[Sun Aug 30 03:10:28.754664 2026] [security2:error] [pid 515259:tid 515406] [client 4.205.62.107:25913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/file21.php"] [unique_id "apPldGZcVaai59truiVxlwAAABA"]
[Sun Aug 30 03:10:28.773429 2026] [security2:error] [pid 515259:tid 515421] [client 4.205.62.107:17299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/brc.php"] [unique_id "apPldGZcVaai59truiVxnAAAAB8"]
[Sun Aug 30 03:10:28.784693 2026] [security2:error] [pid 515259:tid 515417] [client 4.205.62.107:36576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/ws62.php"] [unique_id "apPldGZcVaai59truiVxogAAABs"]
[Sun Aug 30 03:10:28.793777 2026] [security2:error] [pid 515259:tid 515439] [client 20.220.10.235:5829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/admin.php/heex.php"] [unique_id "apPldGZcVaai59truiVxpgAAADE"]
[Sun Aug 30 03:10:28.801508 2026] [security2:error] [pid 515259:tid 515447] [client 158.23.147.79:57675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/cgi-bin/index.php"] [unique_id "apPldGZcVaai59truiVxpwAAADk"]
[Sun Aug 30 03:10:28.806512 2026] [security2:error] [pid 515259:tid 515416] [client 20.220.10.235:34863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/tajj.php"] [unique_id "apPldGZcVaai59truiVxqAAAABo"]
[Sun Aug 30 03:10:28.810927 2026] [security2:error] [pid 515259:tid 515433] [client 20.104.104.62:49661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/ssss.php"] [unique_id "apPldGZcVaai59truiVxqQAAACs"]
[Sun Aug 30 03:10:28.830007 2026] [security2:error] [pid 515259:tid 515477] [client 20.197.61.180:3626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/oceanwp/sass/components/plugins/panel.php"] [unique_id "apPldGZcVaai59truiVxqgAAAFc"]
[Sun Aug 30 03:10:28.839274 2026] [security2:error] [pid 515259:tid 515446] [client 158.23.184.117:8169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/wp-content/images/doc.php"] [unique_id "apPldGZcVaai59truiVxrAAAADg"]
[Sun Aug 30 03:10:28.849674 2026] [authz_core:error] [pid 515259:tid 515431] [client 66.249.66.34:35113] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:28.850117 2026] [authz_core:error] [pid 515259:tid 515431] [client 66.249.66.34:35113] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:28.853947 2026] [security2:error] [pid 515259:tid 515478] [client 20.104.49.130:43626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/btyuio.php"] [unique_id "apPldGZcVaai59truiVxrgAAAFg"]
[Sun Aug 30 03:10:28.869489 2026] [security2:error] [pid 515259:tid 515500] [client 34.130.99.179:51906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/pi.php"] [unique_id "apPldGZcVaai59truiVxsgAAAG4"]
[Sun Aug 30 03:10:28.875680 2026] [authz_core:error] [pid 515259:tid 515396] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:28.875960 2026] [authz_core:error] [pid 515259:tid 515396] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:28.899952 2026] [security2:error] [pid 515259:tid 515487] [client 20.104.50.220:59360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPldGZcVaai59truiVxtgAAAGE"]
[Sun Aug 30 03:10:28.907508 2026] [security2:error] [pid 515259:tid 515471] [client 20.48.251.3:59466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/vx.php"] [unique_id "apPldGZcVaai59truiVxuQAAAFE"]
[Sun Aug 30 03:10:28.913959 2026] [security2:error] [pid 515259:tid 515497] [client 20.63.219.114:20495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/index.bak.php"] [unique_id "apPldGZcVaai59truiVxuwAAAGs"]
[Sun Aug 30 03:10:28.924571 2026] [security2:error] [pid 515259:tid 515432] [client 20.104.18.15:16988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/dehnl.php"] [unique_id "apPldGZcVaai59truiVxvwAAACo"]
[Sun Aug 30 03:10:28.925813 2026] [authz_core:error] [pid 515259:tid 515503] [client 216.73.216.128:55788] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:28.926126 2026] [authz_core:error] [pid 515259:tid 515503] [client 216.73.216.128:55788] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:28.935138 2026] [security2:error] [pid 515259:tid 515414] [client 20.220.10.235:34846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/bge.php"] [unique_id "apPldGZcVaai59truiVxwQAAABg"]
[Sun Aug 30 03:10:28.939864 2026] [security2:error] [pid 515259:tid 515442] [client 20.104.104.62:2914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/zoz.php"] [unique_id "apPldGZcVaai59truiVxwgAAADQ"]
[Sun Aug 30 03:10:28.940672 2026] [security2:error] [pid 515259:tid 515483] [client 20.104.49.130:53611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/x1da.php"] [unique_id "apPldGZcVaai59truiVxwwAAAF0"]
[Sun Aug 30 03:10:28.946872 2026] [security2:error] [pid 515259:tid 515508] [client 158.23.147.79:60169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPldGZcVaai59truiVxxAAAAHY"]
[Sun Aug 30 03:10:28.969640 2026] [security2:error] [pid 515259:tid 515425] [client 20.104.50.220:29608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/tai.php"] [unique_id "apPldGZcVaai59truiVxygAAACM"]
[Sun Aug 30 03:10:28.974196 2026] [security2:error] [pid 515259:tid 515491] [client 20.220.10.235:5288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/tf.php"] [unique_id "apPldGZcVaai59truiVxzwAAAGU"]
[Sun Aug 30 03:10:28.979242 2026] [security2:error] [pid 515259:tid 515513] [client 158.23.184.117:8091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/wp-comments.php"] [unique_id "apPldGZcVaai59truiVx0QAAAHs"]
[Sun Aug 30 03:10:29.051553 2026] [security2:error] [pid 515259:tid 515484] [client 158.23.147.79:1989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPldWZcVaai59truiVx6gAAAF4"]
[Sun Aug 30 03:10:29.067638 2026] [security2:error] [pid 515259:tid 515517] [client 20.104.104.62:65217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/kcs.php"] [unique_id "apPldWZcVaai59truiVx8QAAAH8"]
[Sun Aug 30 03:10:29.094014 2026] [security2:error] [pid 515259:tid 515502] [client 34.130.99.179:51916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/pinfo.php"] [unique_id "apPldWZcVaai59truiVx_gAAAHA"]
[Sun Aug 30 03:10:29.099321 2026] [security2:error] [pid 515259:tid 515414] [client 20.220.10.235:34826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/ssh3ll.php"] [unique_id "apPldWZcVaai59truiVx_wAAABg"]
[Sun Aug 30 03:10:29.112574 2026] [security2:error] [pid 515259:tid 515481] [client 20.104.50.220:29143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-enter.php"] [unique_id "apPldWZcVaai59truiVyAQAAAFs"]
[Sun Aug 30 03:10:29.120690 2026] [security2:error] [pid 515259:tid 515401] [client 20.48.251.3:33281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPldWZcVaai59truiVyAwAAAAs"]
[Sun Aug 30 03:10:29.126516 2026] [security2:error] [pid 515259:tid 515471] [client 158.23.184.117:8077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/wp-includes/panel.php"] [unique_id "apPldWZcVaai59truiVyBQAAAFE"]
[Sun Aug 30 03:10:29.129609 2026] [security2:error] [pid 515259:tid 515425] [client 20.104.18.15:22348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/sallu.php"] [unique_id "apPldWZcVaai59truiVyBgAAACM"]
[Sun Aug 30 03:10:29.146706 2026] [security2:error] [pid 515259:tid 515475] [client 158.23.147.79:52278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/goat.php"] [unique_id "apPldWZcVaai59truiVyDwAAAFU"]
[Sun Aug 30 03:10:29.147667 2026] [authz_core:error] [pid 515259:tid 515413] [client 216.73.216.128:3243] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:29.147950 2026] [authz_core:error] [pid 515259:tid 515413] [client 216.73.216.128:3243] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:29.180271 2026] [security2:error] [pid 515259:tid 515417] [client 68.155.159.216:62634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-login.php"] [unique_id "apPldWZcVaai59truiVyEgAAABs"]
[Sun Aug 30 03:10:29.183375 2026] [security2:error] [pid 515259:tid 515511] [client 20.104.18.15:18321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/fling.php"] [unique_id "apPldWZcVaai59truiVyFAAAAHk"]
[Sun Aug 30 03:10:29.200526 2026] [authz_core:error] [pid 515259:tid 515510] [client 66.249.66.72:47160] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:29.200883 2026] [authz_core:error] [pid 515259:tid 515510] [client 66.249.66.72:47160] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:29.209441 2026] [security2:error] [pid 515259:tid 515433] [client 20.104.104.62:62918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/tajj.php"] [unique_id "apPldWZcVaai59truiVyGwAAACs"]
[Sun Aug 30 03:10:29.216293 2026] [security2:error] [pid 515259:tid 515486] [client 20.220.10.235:5520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/update/da222.php"] [unique_id "apPldWZcVaai59truiVyHQAAAGA"]
[Sun Aug 30 03:10:29.218611 2026] [security2:error] [pid 515259:tid 515478] [client 68.155.159.216:52606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/admin.php"] [unique_id "apPldWZcVaai59truiVyHgAAAFg"]
[Sun Aug 30 03:10:29.239762 2026] [authz_core:error] [pid 515259:tid 515412] [client 216.73.216.128:46513] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:29.240060 2026] [authz_core:error] [pid 515259:tid 515412] [client 216.73.216.128:46513] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:29.252316 2026] [security2:error] [pid 515259:tid 515514] [client 20.151.200.44:41975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/wp-access.php"] [unique_id "apPldWZcVaai59truiVyKgAAAHw"]
[Sun Aug 30 03:10:29.254282 2026] [security2:error] [pid 515259:tid 515451] [client 20.220.10.235:34950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/motu.php"] [unique_id "apPldWZcVaai59truiVyKwAAAD0"]
[Sun Aug 30 03:10:29.282284 2026] [security2:error] [pid 515259:tid 515480] [client 4.205.62.107:38434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/hosty.php"] [unique_id "apPldWZcVaai59truiVyLwAAAFo"]
[Sun Aug 30 03:10:29.284684 2026] [security2:error] [pid 515259:tid 515446] [client 34.130.99.179:51932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/test.php"] [unique_id "apPldWZcVaai59truiVyMQAAADg"]
[Sun Aug 30 03:10:29.323699 2026] [core:alert] [pid 515259:tid 515495] [client 213.196.109.114:62515] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:10:29.337788 2026] [security2:error] [pid 515259:tid 515475] [client 20.104.50.220:5519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/goblok.php"] [unique_id "apPldWZcVaai59truiVyQgAAAFU"]
[Sun Aug 30 03:10:29.339672 2026] [security2:error] [pid 515259:tid 515396] [client 40.83.93.50:22130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/profile.php"] [unique_id "apPldWZcVaai59truiVyQwAAAAY"]
[Sun Aug 30 03:10:29.348282 2026] [security2:error] [pid 515259:tid 515485] [client 20.104.104.62:49639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/bge.php"] [unique_id "apPldWZcVaai59truiVyRQAAAF8"]
[Sun Aug 30 03:10:29.350494 2026] [security2:error] [pid 515259:tid 515450] [client 158.23.184.117:8081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/www.php"] [unique_id "apPldWZcVaai59truiVyRgAAADw"]
[Sun Aug 30 03:10:29.354562 2026] [security2:error] [pid 515259:tid 515457] [client 20.104.50.220:42809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/gel4y.php"] [unique_id "apPldWZcVaai59truiVyRwAAAEM"]
[Sun Aug 30 03:10:29.374446 2026] [authz_core:error] [pid 515259:tid 515421] [client 66.249.66.70:40708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:29.374903 2026] [authz_core:error] [pid 515259:tid 515421] [client 66.249.66.70:40708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:29.399394 2026] [security2:error] [pid 515259:tid 515506] [client 20.220.10.235:34982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/wefile.php"] [unique_id "apPldWZcVaai59truiVyTgAAAHQ"]
[Sun Aug 30 03:10:29.400802 2026] [authz_core:error] [pid 515259:tid 515462] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:29.401166 2026] [authz_core:error] [pid 515259:tid 515462] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:29.403744 2026] [security2:error] [pid 515259:tid 515440] [client 202.181.99.82:57807] ModSecurity: Warning. Matched phrase "LWP::Simple" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "bcwinetrends.com"] [uri "/2017/07/03/rose-gold-at-the-acwc/"] [unique_id "apPldWZcVaai59truiVySwAAADI"]
[Sun Aug 30 03:10:29.404969 2026] [security2:error] [pid 515259:tid 515477] [client 20.63.219.114:15240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/log.php"] [unique_id "apPldWZcVaai59truiVyTwAAAFc"]
[Sun Aug 30 03:10:29.418369 2026] [security2:error] [pid 515259:tid 515409] [client 20.220.10.235:5506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/qi.php"] [unique_id "apPldWZcVaai59truiVyUgAAABM"]
[Sun Aug 30 03:10:29.420230 2026] [security2:error] [pid 515259:tid 515470] [client 20.48.251.3:65505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/infos.php"] [unique_id "apPldWZcVaai59truiVyUwAAAFA"]
[Sun Aug 30 03:10:29.468408 2026] [security2:error] [pid 515259:tid 515404] [client 158.23.147.79:52272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apPldWZcVaai59truiVyYAAAAA4"]
[Sun Aug 30 03:10:29.474354 2026] [security2:error] [pid 515259:tid 515490] [client 20.104.104.62:56543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/ssh3ll.php"] [unique_id "apPldWZcVaai59truiVyYgAAAGQ"]
[Sun Aug 30 03:10:29.480082 2026] [security2:error] [pid 515259:tid 515434] [client 20.104.50.220:33174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/yo.php"] [unique_id "apPldWZcVaai59truiVyZAAAACw"]
[Sun Aug 30 03:10:29.484970 2026] [security2:error] [pid 515259:tid 515454] [client 20.151.200.44:40954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/png.php"] [unique_id "apPldWZcVaai59truiVyZgAAAEA"]
[Sun Aug 30 03:10:29.492215 2026] [security2:error] [pid 515259:tid 515426] [client 158.23.184.117:8080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/.well-known/core.php"] [unique_id "apPldWZcVaai59truiVyaQAAACQ"]
[Sun Aug 30 03:10:29.532449 2026] [security2:error] [pid 515259:tid 515502] [client 20.197.61.180:12283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/options.php"] [unique_id "apPldWZcVaai59truiVybgAAAHA"]
[Sun Aug 30 03:10:29.541071 2026] [security2:error] [pid 515259:tid 515456] [client 20.220.10.235:34824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/Contrller.php"] [unique_id "apPldWZcVaai59truiVycgAAAEI"]
[Sun Aug 30 03:10:29.551281 2026] [security2:error] [pid 515259:tid 515496] [client 20.104.50.220:59573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/shells.php"] [unique_id "apPldWZcVaai59truiVydQAAAGo"]
[Sun Aug 30 03:10:29.600019 2026] [security2:error] [pid 515259:tid 515469] [client 20.104.49.130:60652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/1xmomo.php"] [unique_id "apPldWZcVaai59truiVyhAAAAE8"]
[Sun Aug 30 03:10:29.600984 2026] [security2:error] [pid 515259:tid 515443] [client 20.104.104.62:65275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/motu.php"] [unique_id "apPldWZcVaai59truiVyhQAAADU"]
[Sun Aug 30 03:10:29.602312 2026] [security2:error] [pid 515259:tid 515485] [client 20.104.18.15:43952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/v22.php"] [unique_id "apPldWZcVaai59truiVyhwAAAF8"]
[Sun Aug 30 03:10:29.603576 2026] [authz_core:error] [pid 515259:tid 515406] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:29.603856 2026] [authz_core:error] [pid 515259:tid 515406] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:29.631792 2026] [security2:error] [pid 515259:tid 515410] [client 34.130.99.179:51934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/p.php"] [unique_id "apPldWZcVaai59truiVyjQAAABQ"]
[Sun Aug 30 03:10:29.633217 2026] [security2:error] [pid 515259:tid 515424] [client 158.23.184.117:7969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/akcc.php"] [unique_id "apPldWZcVaai59truiVyjgAAACI"]
[Sun Aug 30 03:10:29.651801 2026] [security2:error] [pid 515259:tid 515409] [client 20.220.10.235:5867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/px.php"] [unique_id "apPldWZcVaai59truiVykAAAABM"]
[Sun Aug 30 03:10:29.668158 2026] [security2:error] [pid 515259:tid 515393] [client 20.220.10.235:34949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/file66.php"] [unique_id "apPldWZcVaai59truiVylgAAAAM"]
[Sun Aug 30 03:10:29.683423 2026] [security2:error] [pid 515259:tid 515447] [client 20.104.49.130:43302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/media.php"] [unique_id "apPldWZcVaai59truiVymgAAADk"]
[Sun Aug 30 03:10:29.714028 2026] [authz_core:error] [pid 515259:tid 515482] [client 216.73.216.128:46513] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:29.714478 2026] [authz_core:error] [pid 515259:tid 515482] [client 216.73.216.128:46513] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:29.733195 2026] [security2:error] [pid 515259:tid 515439] [client 20.104.104.62:56539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/wefile.php"] [unique_id "apPldWZcVaai59truiVypgAAADE"]
[Sun Aug 30 03:10:29.733535 2026] [authz_core:error] [pid 515259:tid 515404] [client 66.249.66.205:60522] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:29.733811 2026] [authz_core:error] [pid 515259:tid 515404] [client 66.249.66.205:60522] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:29.744897 2026] [authz_core:error] [pid 515259:tid 515497] [client 66.249.66.201:39837] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:29.745180 2026] [authz_core:error] [pid 515259:tid 515497] [client 66.249.66.201:39837] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:29.755186 2026] [security2:error] [pid 515259:tid 515392] [client 20.104.49.130:60983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/133.php"] [unique_id "apPldWZcVaai59truiVyrAAAAAI"]
[Sun Aug 30 03:10:29.774975 2026] [security2:error] [pid 515259:tid 515509] [client 158.23.184.117:8100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/themes7.php"] [unique_id "apPldWZcVaai59truiVyswAAAHc"]
[Sun Aug 30 03:10:29.776361 2026] [security2:error] [pid 515259:tid 515510] [client 20.63.219.114:2082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/bak.php"] [unique_id "apPldWZcVaai59truiVytgAAAHg"]
[Sun Aug 30 03:10:29.798661 2026] [security2:error] [pid 515259:tid 515466] [client 158.23.147.79:52233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apPldWZcVaai59truiVyugAAAEw"]
[Sun Aug 30 03:10:29.804908 2026] [security2:error] [pid 515259:tid 515445] [client 20.220.10.235:34948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/blnux.php"] [unique_id "apPldWZcVaai59truiVyvQAAADc"]
[Sun Aug 30 03:10:29.813297 2026] [security2:error] [pid 515259:tid 515463] [client 40.83.93.50:22137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/sql.php"] [unique_id "apPldWZcVaai59truiVyvgAAAEk"]
[Sun Aug 30 03:10:29.842176 2026] [security2:error] [pid 515259:tid 515506] [client 20.104.50.220:17251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/plugins/Cache/footer.php"] [unique_id "apPldWZcVaai59truiVyxAAAAHQ"]
[Sun Aug 30 03:10:29.843322 2026] [security2:error] [pid 515259:tid 515440] [client 20.220.10.235:5554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/is.php"] [unique_id "apPldWZcVaai59truiVyxQAAADI"]
[Sun Aug 30 03:10:29.844326 2026] [security2:error] [pid 515259:tid 515511] [client 68.155.159.216:45956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apPldWZcVaai59truiVyxgAAAHk"]
[Sun Aug 30 03:10:29.847634 2026] [security2:error] [pid 515259:tid 515475] [client 20.104.18.15:16764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/images.php"] [unique_id "apPldWZcVaai59truiVyxwAAAFU"]
[Sun Aug 30 03:10:29.854751 2026] [security2:error] [pid 515259:tid 515437] [client 34.130.99.179:51938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/debug.php"] [unique_id "apPldWZcVaai59truiVyywAAAC8"]
[Sun Aug 30 03:10:29.862452 2026] [security2:error] [pid 515259:tid 515397] [client 20.104.104.62:62955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/Contrller.php"] [unique_id "apPldWZcVaai59truiVyzQAAAAc"]
[Sun Aug 30 03:10:29.901655 2026] [security2:error] [pid 515259:tid 515476] [client 4.205.62.107:16775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/vx.php"] [unique_id "apPldWZcVaai59truiVy2AAAAFY"]
[Sun Aug 30 03:10:29.902860 2026] [authz_core:error] [pid 515259:tid 515515] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:29.903239 2026] [authz_core:error] [pid 515259:tid 515515] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:29.908931 2026] [security2:error] [pid 515259:tid 515454] [client 4.205.62.107:25757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/mcebraed.php"] [unique_id "apPldWZcVaai59truiVy2gAAAEA"]
[Sun Aug 30 03:10:29.911125 2026] [security2:error] [pid 515259:tid 515418] [client 20.48.251.3:59313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/sale.php"] [unique_id "apPldWZcVaai59truiVy3AAAABw"]
[Sun Aug 30 03:10:29.916489 2026] [security2:error] [pid 515259:tid 515410] [client 158.23.184.117:8148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/wp-admin/images.php"] [unique_id "apPldWZcVaai59truiVy3wAAABQ"]
[Sun Aug 30 03:10:29.920381 2026] [security2:error] [pid 515259:tid 515402] [client 4.205.62.107:36652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/grsiuk.php"] [unique_id "apPldWZcVaai59truiVy4AAAAAw"]
[Sun Aug 30 03:10:29.933754 2026] [security2:error] [pid 515259:tid 515435] [client 20.220.10.235:34838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/attack.php"] [unique_id "apPldWZcVaai59truiVy4wAAAC0"]
[Sun Aug 30 03:10:29.950373 2026] [authz_core:error] [pid 515259:tid 515492] [client 66.249.66.76:48181] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:29.950634 2026] [authz_core:error] [pid 515259:tid 515492] [client 66.249.66.76:48181] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:29.988808 2026] [security2:error] [pid 515259:tid 515401] [client 20.104.104.62:56549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/file66.php"] [unique_id "apPldWZcVaai59truiVy-QAAAAs"]
[Sun Aug 30 03:10:30.021676 2026] [security2:error] [pid 515259:tid 515413] [client 146.190.222.47:57356] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "pornchai-insulation.cover789.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "apPldmZcVaai59truiVzAQAAABc"]
[Sun Aug 30 03:10:30.046110 2026] [security2:error] [pid 515259:tid 515484] [client 20.104.49.130:63546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/bdroot.php"] [unique_id "apPldmZcVaai59truiVzCwAAAF4"]
[Sun Aug 30 03:10:30.049680 2026] [security2:error] [pid 515259:tid 515436] [client 20.48.251.3:59468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/ty.php"] [unique_id "apPldmZcVaai59truiVzDgAAAC4"]
[Sun Aug 30 03:10:30.053880 2026] [security2:error] [pid 515259:tid 515447] [client 20.151.200.44:28566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/admin.php/heex.php"] [unique_id "apPldmZcVaai59truiVzEAAAADk"]
[Sun Aug 30 03:10:30.054748 2026] [security2:error] [pid 515259:tid 515409] [client 158.23.147.79:43858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apPldmZcVaai59truiVzCQAAABM"]
[Sun Aug 30 03:10:30.056185 2026] [security2:error] [pid 515259:tid 515399] [client 20.104.50.220:59378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/dx.php"] [unique_id "apPldmZcVaai59truiVzEQAAAAk"]
[Sun Aug 30 03:10:30.066524 2026] [security2:error] [pid 515259:tid 515501] [client 20.220.10.235:34827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/wk/index.php"] [unique_id "apPldmZcVaai59truiVzFQAAAG8"]
[Sun Aug 30 03:10:30.068050 2026] [security2:error] [pid 515259:tid 515428] [client 20.104.18.15:16907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/zoo2.php"] [unique_id "apPldmZcVaai59truiVzGAAAACY"]
[Sun Aug 30 03:10:30.071789 2026] [security2:error] [pid 515259:tid 515461] [client 158.23.184.117:8130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/wp-content/themes/haha.php"] [unique_id "apPldmZcVaai59truiVzGgAAAEc"]
[Sun Aug 30 03:10:30.081322 2026] [security2:error] [pid 515259:tid 515449] [client 34.130.99.179:51954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/admin/phpinfo.php"] [unique_id "apPldmZcVaai59truiVzIAAAADs"]
[Sun Aug 30 03:10:30.119658 2026] [security2:error] [pid 515259:tid 515512] [client 20.104.104.62:56573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/blnux.php"] [unique_id "apPldmZcVaai59truiVzKQAAAHo"]
[Sun Aug 30 03:10:30.121204 2026] [security2:error] [pid 515259:tid 515468] [client 158.23.147.79:57700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-includes/content.php"] [unique_id "apPldmZcVaai59truiVzKgAAAE4"]
[Sun Aug 30 03:10:30.138483 2026] [security2:error] [pid 515259:tid 515513] [client 20.104.50.220:52841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/www.php"] [unique_id "apPldmZcVaai59truiVzLwAAAHs"]
[Sun Aug 30 03:10:30.148484 2026] [security2:error] [pid 515259:tid 515463] [client 20.220.10.235:5271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/od.php"] [unique_id "apPldmZcVaai59truiVzMQAAAEk"]
[Sun Aug 30 03:10:30.211734 2026] [security2:error] [pid 515259:tid 515396] [client 158.23.184.117:8166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/wp-mail.php"] [unique_id "apPldmZcVaai59truiVzPwAAAAY"]
[Sun Aug 30 03:10:30.232027 2026] [security2:error] [pid 515259:tid 515424] [client 20.220.10.235:34875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/dehnl.php"] [unique_id "apPldmZcVaai59truiVzRAAAACI"]
[Sun Aug 30 03:10:30.241325 2026] [security2:error] [pid 515259:tid 515429] [client 20.197.61.180:15777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/panel.php"] [unique_id "apPldmZcVaai59truiVzRwAAACc"]
[Sun Aug 30 03:10:30.253138 2026] [security2:error] [pid 515259:tid 515474] [client 20.104.104.62:62959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/attack.php"] [unique_id "apPldmZcVaai59truiVzSwAAAFQ"]
[Sun Aug 30 03:10:30.259384 2026] [authz_core:error] [pid 515259:tid 515454] [client 216.73.216.128:55788] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:30.259719 2026] [authz_core:error] [pid 515259:tid 515454] [client 216.73.216.128:55788] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:30.263714 2026] [security2:error] [pid 515259:tid 515400] [client 20.104.49.130:63269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/reviall.php"] [unique_id "apPldmZcVaai59truiVzTQAAAAo"]
[Sun Aug 30 03:10:30.267213 2026] [authz_core:error] [pid 515259:tid 515500] [client 66.249.66.64:55835] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:30.267659 2026] [authz_core:error] [pid 515259:tid 515500] [client 66.249.66.64:55835] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:30.271713 2026] [security2:error] [pid 515259:tid 515420] [client 20.48.251.3:60505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPldmZcVaai59truiVzTgAAAB4"]
[Sun Aug 30 03:10:30.275357 2026] [security2:error] [pid 515259:tid 515460] [client 20.104.18.15:22418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/codex.php"] [unique_id "apPldmZcVaai59truiVzTwAAAEY"]
[Sun Aug 30 03:10:30.276124 2026] [security2:error] [pid 515259:tid 515442] [client 20.104.50.220:52820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/cakt.php"] [unique_id "apPldmZcVaai59truiVzUAAAADQ"]
[Sun Aug 30 03:10:30.284973 2026] [security2:error] [pid 515259:tid 515430] [client 34.130.99.179:51966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/test/phpinfo.php"] [unique_id "apPldmZcVaai59truiVzVAAAACg"]
[Sun Aug 30 03:10:30.287235 2026] [security2:error] [pid 515259:tid 515432] [client 68.155.159.216:57036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apPldmZcVaai59truiVzVQAAACo"]
[Sun Aug 30 03:10:30.311513 2026] [security2:error] [pid 515259:tid 515512] [client 158.23.147.79:52283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/dropdown.php"] [unique_id "apPldmZcVaai59truiVzXgAAAHo"]
[Sun Aug 30 03:10:30.323700 2026] [security2:error] [pid 515259:tid 515504] [client 20.104.18.15:18322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/btyuio.php"] [unique_id "apPldmZcVaai59truiVzYAAAAHI"]
[Sun Aug 30 03:10:30.332757 2026] [core:alert] [pid 515259:tid 515488] [client 36.252.252.128:1412] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:10:30.351457 2026] [security2:error] [pid 515259:tid 515425] [client 158.23.184.117:8096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/root.php"] [unique_id "apPldmZcVaai59truiVzZgAAACM"]
[Sun Aug 30 03:10:30.366430 2026] [authz_core:error] [pid 515259:tid 515482] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:30.366773 2026] [authz_core:error] [pid 515259:tid 515482] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:30.374401 2026] [security2:error] [pid 515259:tid 515502] [client 40.83.93.50:6160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/index.bak.php"] [unique_id "apPldmZcVaai59truiVzaAAAAHA"]
[Sun Aug 30 03:10:30.381089 2026] [security2:error] [pid 515259:tid 515411] [client 68.155.159.216:54318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-admin/admin.php"] [unique_id "apPldmZcVaai59truiVzaQAAABU"]
[Sun Aug 30 03:10:30.383850 2026] [security2:error] [pid 515259:tid 515516] [client 20.220.10.235:34901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/png.php"] [unique_id "apPldmZcVaai59truiVzagAAAH4"]
[Sun Aug 30 03:10:30.386235 2026] [security2:error] [pid 515259:tid 515446] [client 20.104.104.62:65279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/wk/index.php"] [unique_id "apPldmZcVaai59truiVzawAAADg"]
[Sun Aug 30 03:10:30.397174 2026] [core:alert] [pid 515259:tid 515426] [client 113.191.159.96:59582] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:10:30.419069 2026] [security2:error] [pid 515259:tid 515476] [client 20.63.219.114:2562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/pages.php"] [unique_id "apPldmZcVaai59truiVzcAAAAFY"]
[Sun Aug 30 03:10:30.421446 2026] [security2:error] [pid 515259:tid 515511] [client 4.205.62.107:64693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/pass4.php"] [unique_id "apPldmZcVaai59truiVzcQAAAHk"]
[Sun Aug 30 03:10:30.473518 2026] [security2:error] [pid 515259:tid 515393] [client 20.104.50.220:5923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wso1.php"] [unique_id "apPldmZcVaai59truiVzhAAAAAM"]
[Sun Aug 30 03:10:30.491838 2026] [security2:error] [pid 515259:tid 515422] [client 20.104.50.220:51551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/contacts.php"] [unique_id "apPldmZcVaai59truiVziQAAACA"]
[Sun Aug 30 03:10:30.494239 2026] [security2:error] [pid 515259:tid 515462] [client 158.23.184.117:8082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/ae.php"] [unique_id "apPldmZcVaai59truiVzigAAAEg"]
[Sun Aug 30 03:10:30.517735 2026] [security2:error] [pid 515259:tid 515508] [client 20.104.104.62:62954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/dehnl.php"] [unique_id "apPldmZcVaai59truiVzjQAAAHY"]
[Sun Aug 30 03:10:30.518352 2026] [security2:error] [pid 515259:tid 515404] [client 20.220.10.235:34880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/txets.php"] [unique_id "apPldmZcVaai59truiVzjgAAAA4"]
[Sun Aug 30 03:10:30.518436 2026] [security2:error] [pid 515259:tid 515514] [client 158.23.147.79:60193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/makeasmtp.php"] [unique_id "apPldmZcVaai59truiVzjwAAAHw"]
[Sun Aug 30 03:10:30.529730 2026] [security2:error] [pid 515259:tid 515467] [client 34.130.99.179:51970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/dev/phpinfo.php"] [unique_id "apPldmZcVaai59truiVzkgAAAE0"]
[Sun Aug 30 03:10:30.585487 2026] [security2:error] [pid 515259:tid 515411] [client 20.48.251.3:64263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/env.php"] [unique_id "apPldmZcVaai59truiVzogAAABU"]
[Sun Aug 30 03:10:30.597157 2026] [security2:error] [pid 515259:tid 515451] [client 20.220.10.235:5323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/wp-the.php"] [unique_id "apPldmZcVaai59truiVzpwAAAD0"]
[Sun Aug 30 03:10:30.620060 2026] [security2:error] [pid 515259:tid 515436] [client 20.104.50.220:33195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-content/fm.php"] [unique_id "apPldmZcVaai59truiVzrgAAAC4"]
[Sun Aug 30 03:10:30.625276 2026] [authz_core:error] [pid 515259:tid 515431] [client 216.73.216.128:55788] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:30.625548 2026] [authz_core:error] [pid 515259:tid 515431] [client 216.73.216.128:55788] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:30.636462 2026] [security2:error] [pid 515259:tid 515495] [client 158.23.184.117:8134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/admin/controller/extension/ultra.php"] [unique_id "apPldmZcVaai59truiVzsgAAAGk"]
[Sun Aug 30 03:10:30.644865 2026] [security2:error] [pid 515259:tid 515428] [client 20.220.10.235:34823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/wp-login.php"] [unique_id "apPldmZcVaai59truiVzswAAACY"]
[Sun Aug 30 03:10:30.646086 2026] [security2:error] [pid 515259:tid 515471] [client 20.104.104.62:62968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/png.php"] [unique_id "apPldmZcVaai59truiVztgAAAFE"]
[Sun Aug 30 03:10:30.651507 2026] [authz_core:error] [pid 515259:tid 515486] [client 66.249.66.73:51079] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:30.651789 2026] [authz_core:error] [pid 515259:tid 515486] [client 66.249.66.73:51079] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:30.711496 2026] [security2:error] [pid 515259:tid 515442] [client 158.23.147.79:43899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/sad/about.php"] [unique_id "apPldmZcVaai59truiVzyQAAADQ"]
[Sun Aug 30 03:10:30.737621 2026] [security2:error] [pid 515259:tid 515396] [client 34.130.99.179:51976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/old/phpinfo.php"] [unique_id "apPldmZcVaai59truiVzzAAAAAY"]
[Sun Aug 30 03:10:30.748026 2026] [security2:error] [pid 515259:tid 515506] [client 20.104.50.220:61692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/stupid.php"] [unique_id "apPldmZcVaai59truiVzzwAAAHQ"]
[Sun Aug 30 03:10:30.762525 2026] [security2:error] [pid 515259:tid 515488] [client 20.220.10.235:5369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/wt.php"] [unique_id "apPldmZcVaai59truiVz0wAAAGI"]
[Sun Aug 30 03:10:30.773713 2026] [security2:error] [pid 515259:tid 515425] [client 20.220.10.235:34962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/wp-access.php"] [unique_id "apPldmZcVaai59truiVz1wAAACM"]
[Sun Aug 30 03:10:30.777341 2026] [security2:error] [pid 515259:tid 515411] [client 20.104.104.62:56552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/txets.php"] [unique_id "apPldmZcVaai59truiVz2wAAABU"]
[Sun Aug 30 03:10:30.777662 2026] [security2:error] [pid 515259:tid 515494] [client 158.23.184.117:8067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/wp-content/import.php"] [unique_id "apPldmZcVaai59truiVz2gAAAGg"]
[Sun Aug 30 03:10:30.806402 2026] [security2:error] [pid 515259:tid 515448] [client 20.104.18.15:43974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/wp-activate.php"] [unique_id "apPldmZcVaai59truiVz4gAAADo"]
[Sun Aug 30 03:10:30.871654 2026] [authz_core:error] [pid 515259:tid 515438] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:30.871941 2026] [authz_core:error] [pid 515259:tid 515438] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:30.884061 2026] [security2:error] [pid 515259:tid 515487] [client 40.83.93.50:10688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/log.php"] [unique_id "apPldmZcVaai59truiVz8QAAAGE"]
[Sun Aug 30 03:10:30.888484 2026] [security2:error] [pid 515259:tid 515414] [client 20.63.219.114:15266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/albin.php"] [unique_id "apPldmZcVaai59truiVz8gAAABg"]
[Sun Aug 30 03:10:30.922774 2026] [security2:error] [pid 515259:tid 515429] [client 158.23.184.117:8114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/wp-includes/fonts/admin.php"] [unique_id "apPldmZcVaai59truiVz-wAAACc"]
[Sun Aug 30 03:10:30.930442 2026] [security2:error] [pid 515259:tid 515449] [client 20.220.10.235:34945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/wp-content/admin.php"] [unique_id "apPldmZcVaai59truiVz_AAAADs"]
[Sun Aug 30 03:10:30.956047 2026] [security2:error] [pid 515259:tid 515499] [client 20.197.61.180:12252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/reboot/assets/js/plugins/home.php"] [unique_id "apPldmZcVaai59truiVz_gAAAG0"]
[Sun Aug 30 03:10:30.960329 2026] [security2:error] [pid 515259:tid 515458] [client 20.104.104.62:56538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/wp-login.php"] [unique_id "apPldmZcVaai59truiVz9wAAAEQ"]
[Sun Aug 30 03:10:30.961026 2026] [security2:error] [pid 515259:tid 515408] [client 34.130.99.179:51988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/tmp/phpinfo.php"] [unique_id "apPldmZcVaai59truiV0AQAAABI"]
[Sun Aug 30 03:10:30.974037 2026] [security2:error] [pid 515259:tid 515505] [client 20.104.18.15:16665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/82.php"] [unique_id "apPldmZcVaai59truiV0CgAAAHM"]
[Sun Aug 30 03:10:30.992924 2026] [security2:error] [pid 515259:tid 515407] [client 20.104.50.220:16615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/404.php"] [unique_id "apPldmZcVaai59truiV0FQAAABE"]
[Sun Aug 30 03:10:30.995746 2026] [security2:error] [pid 515259:tid 515502] [client 20.104.49.130:57349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/talkxkej.php"] [unique_id "apPldmZcVaai59truiV0GQAAAHA"]
[Sun Aug 30 03:10:31.004033 2026] [security2:error] [pid 515259:tid 515485] [client 158.23.147.79:56499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-admin/css/index.php"] [unique_id "apPld2ZcVaai59truiV0GwAAAF8"]
[Sun Aug 30 03:10:31.019372 2026] [authz_core:error] [pid 515259:tid 515439] [client 66.249.66.204:60876] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:31.019856 2026] [authz_core:error] [pid 515259:tid 515439] [client 66.249.66.204:60876] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:31.037334 2026] [security2:error] [pid 515259:tid 515478] [client 4.205.62.107:17332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/ty.php"] [unique_id "apPld2ZcVaai59truiV0JgAAAFg"]
[Sun Aug 30 03:10:31.050126 2026] [security2:error] [pid 515259:tid 515487] [client 4.205.62.107:25880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/server-info.php"] [unique_id "apPld2ZcVaai59truiV0LAAAAGE"]
[Sun Aug 30 03:10:31.063136 2026] [security2:error] [pid 515259:tid 515433] [client 20.48.251.3:55740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/wp-class.php"] [unique_id "apPld2ZcVaai59truiV0MAAAACs"]
[Sun Aug 30 03:10:31.064739 2026] [security2:error] [pid 515259:tid 515475] [client 158.23.184.117:8087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/222.php"] [unique_id "apPld2ZcVaai59truiV0MQAAAFU"]
[Sun Aug 30 03:10:31.071205 2026] [security2:error] [pid 515259:tid 515462] [client 158.23.147.79:43848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/admin.php"] [unique_id "apPld2ZcVaai59truiV0NAAAAEg"]
[Sun Aug 30 03:10:31.083760 2026] [security2:error] [pid 515259:tid 515499] [client 20.220.10.235:34876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/log.php"] [unique_id "apPld2ZcVaai59truiV0PAAAAG0"]
[Sun Aug 30 03:10:31.085739 2026] [security2:error] [pid 515259:tid 515458] [client 20.104.104.62:2938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/wp-access.php"] [unique_id "apPld2ZcVaai59truiV0PQAAAEQ"]
[Sun Aug 30 03:10:31.085800 2026] [security2:error] [pid 515259:tid 515408] [client 4.205.62.107:36579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/paypal.php"] [unique_id "apPld2ZcVaai59truiV0PgAAABI"]
[Sun Aug 30 03:10:31.096428 2026] [security2:error] [pid 515259:tid 515470] [client 114.119.149.150:31861] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "balancebyplants365.com"] [uri "/about"] [unique_id "apPld2ZcVaai59truiV0RQAAAFA"], referer: https://balancebyplants365.com/about
[Sun Aug 30 03:10:31.132568 2026] [security2:error] [pid 515259:tid 515506] [client 68.155.159.216:45996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/goat1.php"] [unique_id "apPld2ZcVaai59truiV0SQAAAHQ"]
[Sun Aug 30 03:10:31.151440 2026] [security2:error] [pid 515259:tid 515448] [client 20.220.10.235:5556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/im.php"] [unique_id "apPld2ZcVaai59truiV0UQAAADo"]
[Sun Aug 30 03:10:31.152720 2026] [authz_core:error] [pid 515259:tid 515502] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fmultipart
[Sun Aug 30 03:10:31.152998 2026] [authz_core:error] [pid 515259:tid 515502] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fmultipart
[Sun Aug 30 03:10:31.169623 2026] [security2:error] [pid 515259:tid 515401] [client 34.130.99.179:51994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/public/phpinfo.php"] [unique_id "apPld2ZcVaai59truiV0VAAAAAs"]
[Sun Aug 30 03:10:31.199840 2026] [security2:error] [pid 515259:tid 515492] [client 20.48.251.3:52242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/adminer-4.7.6-en.php"] [unique_id "apPld2ZcVaai59truiV0WwAAAGY"]
[Sun Aug 30 03:10:31.204462 2026] [security2:error] [pid 515259:tid 515390] [client 20.104.50.220:63197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/puc.php"] [unique_id "apPld2ZcVaai59truiV0XAAAAAA"]
[Sun Aug 30 03:10:31.207592 2026] [security2:error] [pid 515259:tid 515446] [client 158.23.184.117:8141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/wp-content/languages.php"] [unique_id "apPld2ZcVaai59truiV0XgAAADg"]
[Sun Aug 30 03:10:31.211753 2026] [security2:error] [pid 515259:tid 515461] [client 20.104.104.62:56569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/wp-content/admin.php"] [unique_id "apPld2ZcVaai59truiV0YQAAAEc"]
[Sun Aug 30 03:10:31.228837 2026] [security2:error] [pid 515259:tid 515402] [client 20.104.49.130:63285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/pfm.php"] [unique_id "apPld2ZcVaai59truiV0ZQAAAAw"]
[Sun Aug 30 03:10:31.229283 2026] [security2:error] [pid 515259:tid 515459] [client 20.104.18.15:16902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/zoo1.php"] [unique_id "apPld2ZcVaai59truiV0ZAAAAEU"]
[Sun Aug 30 03:10:31.245705 2026] [security2:error] [pid 515259:tid 515422] [client 20.220.10.235:35006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/xwpg.php"] [unique_id "apPld2ZcVaai59truiV0awAAACA"]
[Sun Aug 30 03:10:31.258896 2026] [security2:error] [pid 515259:tid 515462] [client 20.151.200.44:28671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/tf.php"] [unique_id "apPld2ZcVaai59truiV0bgAAAEg"]
[Sun Aug 30 03:10:31.266654 2026] [authz_core:error] [pid 515259:tid 515501] [client 216.73.216.128:64209] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:31.267095 2026] [authz_core:error] [pid 515259:tid 515501] [client 216.73.216.128:64209] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:31.323299 2026] [security2:error] [pid 515259:tid 515498] [client 20.104.50.220:29153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/x13.php"] [unique_id "apPld2ZcVaai59truiV0fgAAAGw"]
[Sun Aug 30 03:10:31.344071 2026] [security2:error] [pid 515259:tid 515403] [client 20.104.104.62:62991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/log.php"] [unique_id "apPld2ZcVaai59truiV0gwAAAA0"]
[Sun Aug 30 03:10:31.347361 2026] [security2:error] [pid 515259:tid 515506] [client 158.23.184.117:8098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/wp-config-sample.php"] [unique_id "apPld2ZcVaai59truiV0hwAAAHQ"]
[Sun Aug 30 03:10:31.363452 2026] [security2:error] [pid 515259:tid 515410] [client 40.83.93.50:22086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/bak.php"] [unique_id "apPld2ZcVaai59truiV0iQAAABQ"]
[Sun Aug 30 03:10:31.375778 2026] [security2:error] [pid 515259:tid 515481] [client 20.63.219.114:15197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/an.php"] [unique_id "apPld2ZcVaai59truiV0jAAAAFs"]
[Sun Aug 30 03:10:31.380685 2026] [authz_core:error] [pid 515259:tid 515413] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:31.380945 2026] [authz_core:error] [pid 515259:tid 515413] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:31.385040 2026] [security2:error] [pid 515259:tid 515417] [client 20.151.200.44:40950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/txets.php"] [unique_id "apPld2ZcVaai59truiV0jgAAABs"]
[Sun Aug 30 03:10:31.392393 2026] [security2:error] [pid 515259:tid 515438] [client 20.104.49.130:45701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/fs.php"] [unique_id "apPld2ZcVaai59truiV0kQAAADA"]
[Sun Aug 30 03:10:31.398352 2026] [security2:error] [pid 515259:tid 515493] [client 20.220.10.235:34843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/sxxb.php"] [unique_id "apPld2ZcVaai59truiV0kwAAAGc"]
[Sun Aug 30 03:10:31.404622 2026] [security2:error] [pid 515259:tid 515453] [client 68.155.159.216:62653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-admin/images/about.php"] [unique_id "apPld2ZcVaai59truiV0lQAAAD8"]
[Sun Aug 30 03:10:31.411595 2026] [security2:error] [pid 515259:tid 515394] [client 20.48.251.3:14100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/agg.php"] [unique_id "apPld2ZcVaai59truiV0mQAAAAQ"]
[Sun Aug 30 03:10:31.417288 2026] [authz_core:error] [pid 515259:tid 515414] [client 66.249.66.36:54937] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:31.417527 2026] [authz_core:error] [pid 515259:tid 515414] [client 66.249.66.36:54937] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:31.418262 2026] [security2:error] [pid 515259:tid 515397] [client 20.220.10.235:5765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/file.php"] [unique_id "apPld2ZcVaai59truiV0mwAAAAc"]
[Sun Aug 30 03:10:31.418282 2026] [security2:error] [pid 515259:tid 515441] [client 20.104.50.220:52856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/CytoXploit.php"] [unique_id "apPld2ZcVaai59truiV0nAAAADM"]
[Sun Aug 30 03:10:31.459400 2026] [security2:error] [pid 515259:tid 515491] [client 20.104.18.15:18431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/dehnl.php"] [unique_id "apPld2ZcVaai59truiV0rgAAAGU"]
[Sun Aug 30 03:10:31.474451 2026] [security2:error] [pid 515259:tid 515454] [client 20.104.104.62:65232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/xwpg.php"] [unique_id "apPld2ZcVaai59truiV0swAAAEA"]
[Sun Aug 30 03:10:31.479805 2026] [security2:error] [pid 515259:tid 515452] [client 20.104.18.15:22514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/5656.php"] [unique_id "apPld2ZcVaai59truiV0tQAAAD4"]
[Sun Aug 30 03:10:31.499127 2026] [security2:error] [pid 515259:tid 515429] [client 158.23.184.117:8088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/wp-admin/install-helper.php"] [unique_id "apPld2ZcVaai59truiV0twAAACc"]
[Sun Aug 30 03:10:31.524483 2026] [security2:error] [pid 515259:tid 515400] [client 158.23.147.79:52284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-admin/admin.php"] [unique_id "apPld2ZcVaai59truiV0uAAAAAo"]
[Sun Aug 30 03:10:31.529228 2026] [security2:error] [pid 515259:tid 515450] [client 216.73.216.128:46513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_config_key_macro_rules"] [unique_id "apPld2ZcVaai59truiV0ugAAADw"]
[Sun Aug 30 03:10:31.539628 2026] [security2:error] [pid 515259:tid 515507] [client 20.220.10.235:34865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/dx.php"] [unique_id "apPld2ZcVaai59truiV0vQAAAHU"]
[Sun Aug 30 03:10:31.546989 2026] [security2:error] [pid 515259:tid 515506] [client 68.155.159.216:52305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apPld2ZcVaai59truiV0wAAAAHQ"]
[Sun Aug 30 03:10:31.568868 2026] [security2:error] [pid 515259:tid 515496] [client 4.205.62.107:61740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/cu.php"] [unique_id "apPld2ZcVaai59truiV0xwAAAGo"]
[Sun Aug 30 03:10:31.574748 2026] [core:alert] [pid 515259:tid 515474] [client 102.134.13.104:56058] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:10:31.600736 2026] [security2:error] [pid 515259:tid 515390] [client 34.130.99.179:52000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/php-info.php"] [unique_id "apPld2ZcVaai59truiV01QAAAAA"]
[Sun Aug 30 03:10:31.606719 2026] [security2:error] [pid 515259:tid 515418] [client 20.104.104.62:65254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/sxxb.php"] [unique_id "apPld2ZcVaai59truiV01gAAABw"]
[Sun Aug 30 03:10:31.626601 2026] [security2:error] [pid 515259:tid 515404] [client 20.104.50.220:5932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/admin.php"] [unique_id "apPld2ZcVaai59truiV03gAAAA4"]
[Sun Aug 30 03:10:31.643873 2026] [security2:error] [pid 515259:tid 515412] [client 158.23.184.117:8093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/wp-includes/fonts/classmap.php"] [unique_id "apPld2ZcVaai59truiV03wAAABY"]
[Sun Aug 30 03:10:31.647184 2026] [security2:error] [pid 515259:tid 515469] [client 20.104.50.220:51587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/yo.php"] [unique_id "apPld2ZcVaai59truiV04AAAAE8"]
[Sun Aug 30 03:10:31.657363 2026] [security2:error] [pid 515259:tid 515495] [client 20.197.61.180:3202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/salient/css/build/plugins/login.php"] [unique_id "apPld2ZcVaai59truiV05gAAAGk"]
[Sun Aug 30 03:10:31.667371 2026] [security2:error] [pid 515259:tid 515464] [client 20.220.10.235:34818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPld2ZcVaai59truiV05wAAAEo"]
[Sun Aug 30 03:10:31.688076 2026] [security2:error] [pid 515259:tid 515396] [client 20.151.200.44:28622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/update/da222.php"] [unique_id "apPld2ZcVaai59truiV06QAAAAY"]
[Sun Aug 30 03:10:31.705066 2026] [authz_core:error] [pid 515259:tid 515415] [client 66.249.66.73:41213] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:31.705358 2026] [authz_core:error] [pid 515259:tid 515415] [client 66.249.66.73:41213] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:31.710350 2026] [security2:error] [pid 515259:tid 515483] [client 216.73.216.128:3243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPld2ZcVaai59truiV0-AAAAF0"]
[Sun Aug 30 03:10:31.733862 2026] [security2:error] [pid 515259:tid 515426] [client 20.104.104.62:2904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/dx.php"] [unique_id "apPld2ZcVaai59truiV0-wAAACQ"]
[Sun Aug 30 03:10:31.751681 2026] [authz_core:error] [pid 515259:tid 515430] [client 66.249.66.195:49094] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:31.752120 2026] [authz_core:error] [pid 515259:tid 515430] [client 66.249.66.195:49094] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:31.763334 2026] [security2:error] [pid 515259:tid 515511] [client 20.220.10.235:58903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/ca.php"] [unique_id "apPld2ZcVaai59truiV1AgAAAHk"]
[Sun Aug 30 03:10:31.770619 2026] [security2:error] [pid 515259:tid 515509] [client 20.104.50.220:33196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-content/a.php"] [unique_id "apPld2ZcVaai59truiV1BAAAAHc"]
[Sun Aug 30 03:10:31.784754 2026] [security2:error] [pid 515259:tid 515411] [client 158.23.184.117:8145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/adminfuns.php/.well-known/acme-challenge/file.php"] [unique_id "apPld2ZcVaai59truiV1CgAAABU"]
[Sun Aug 30 03:10:31.800027 2026] [security2:error] [pid 515259:tid 515461] [client 20.220.10.235:34841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/xda.php"] [unique_id "apPld2ZcVaai59truiV1EAAAAEc"]
[Sun Aug 30 03:10:31.805340 2026] [security2:error] [pid 515259:tid 515446] [client 20.48.251.3:65497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/xve22.php"] [unique_id "apPld2ZcVaai59truiV1EgAAADg"]
[Sun Aug 30 03:10:31.820726 2026] [security2:error] [pid 515259:tid 515424] [client 158.23.147.79:52277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apPld2ZcVaai59truiV1GQAAACI"]
[Sun Aug 30 03:10:31.822936 2026] [security2:error] [pid 515259:tid 515481] [client 34.130.99.179:52012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/phpversion.php"] [unique_id "apPld2ZcVaai59truiV1GgAAAFs"]
[Sun Aug 30 03:10:31.831079 2026] [security2:error] [pid 515259:tid 515503] [client 40.83.93.50:6145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/pages.php"] [unique_id "apPld2ZcVaai59truiV1HAAAAHE"]
[Sun Aug 30 03:10:31.862671 2026] [security2:error] [pid 515259:tid 515514] [client 20.104.104.62:62964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPld2ZcVaai59truiV1KAAAAHw"]
[Sun Aug 30 03:10:31.882467 2026] [authz_core:error] [pid 515259:tid 515401] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:31.882897 2026] [authz_core:error] [pid 515259:tid 515401] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:31.910096 2026] [security2:error] [pid 515259:tid 515485] [client 114.119.132.104:47731] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "luxielectronics.com"] [uri "/attachments/File/Luxi_DIY-30BS10_specs.pdf"] [unique_id "apPld2ZcVaai59truiV1MQAAAF8"], referer: http://luxielectronics.com/cables.html
[Sun Aug 30 03:10:31.914407 2026] [security2:error] [pid 515259:tid 515418] [client 20.63.219.114:15252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/mini.php"] [unique_id "apPld2ZcVaai59truiV1MwAAABw"]
[Sun Aug 30 03:10:31.921482 2026] [security2:error] [pid 515259:tid 515426] [client 20.104.50.220:59554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/sys.php"] [unique_id "apPld2ZcVaai59truiV1NgAAACQ"]
[Sun Aug 30 03:10:31.932731 2026] [security2:error] [pid 515259:tid 515517] [client 20.220.10.235:34953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPld2ZcVaai59truiV1OgAAAH8"]
[Sun Aug 30 03:10:31.939059 2026] [authz_core:error] [pid 515259:tid 515511] [client 66.249.66.40:64468] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:31.939380 2026] [authz_core:error] [pid 515259:tid 515511] [client 66.249.66.40:64468] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:31.940758 2026] [security2:error] [pid 515259:tid 515489] [client 20.104.18.15:43282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/wp-trackback.php"] [unique_id "apPld2ZcVaai59truiV1PAAAAGM"]
[Sun Aug 30 03:10:31.944366 2026] [security2:error] [pid 515259:tid 515403] [client 158.23.184.117:8108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/wp-content/themes/aa.php"] [unique_id "apPld2ZcVaai59truiV1PgAAAA0"]
[Sun Aug 30 03:10:32.002887 2026] [security2:error] [pid 515259:tid 515449] [client 20.104.104.62:56534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/xda.php"] [unique_id "apPleGZcVaai59truiV1TwAAADs"]
[Sun Aug 30 03:10:32.015406 2026] [security2:error] [pid 515259:tid 515478] [client 34.130.99.179:52020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/_phpinfo.php"] [unique_id "apPleGZcVaai59truiV1UwAAAFg"]
[Sun Aug 30 03:10:32.051428 2026] [security2:error] [pid 515259:tid 515402] [client 20.220.10.235:5884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/pb.php"] [unique_id "apPleGZcVaai59truiV1XwAAAAw"]
[Sun Aug 30 03:10:32.081846 2026] [security2:error] [pid 515259:tid 515471] [client 20.220.10.235:34862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/t00l.php"] [unique_id "apPleGZcVaai59truiV1ZwAAAFE"]
[Sun Aug 30 03:10:32.099778 2026] [security2:error] [pid 515259:tid 515476] [client 158.23.184.117:8117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/chosen.php"] [unique_id "apPleGZcVaai59truiV1bAAAAFY"]
[Sun Aug 30 03:10:32.112704 2026] [security2:error] [pid 515259:tid 515517] [client 20.104.18.15:64859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/files.php/new.php"] [unique_id "apPleGZcVaai59truiV1cgAAAH8"]
[Sun Aug 30 03:10:32.120237 2026] [security2:error] [pid 515259:tid 515489] [client 20.104.50.220:17259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/mail.php"] [unique_id "apPleGZcVaai59truiV1cwAAAGM"]
[Sun Aug 30 03:10:32.141390 2026] [security2:error] [pid 515259:tid 515467] [client 20.104.104.62:65225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPleGZcVaai59truiV1eAAAAE0"]
[Sun Aug 30 03:10:32.176827 2026] [security2:error] [pid 515259:tid 515500] [client 4.205.62.107:17721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/adminer-4.7.6-en.php"] [unique_id "apPleGZcVaai59truiV1ggAAAG4"]
[Sun Aug 30 03:10:32.198796 2026] [security2:error] [pid 515259:tid 515459] [client 20.48.251.3:55682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/database.php"] [unique_id "apPleGZcVaai59truiV1igAAAEU"]
[Sun Aug 30 03:10:32.210403 2026] [security2:error] [pid 515259:tid 515508] [client 4.205.62.107:25891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/gk.php"] [unique_id "apPleGZcVaai59truiV1jwAAAHY"]
[Sun Aug 30 03:10:32.218044 2026] [security2:error] [pid 515259:tid 515507] [client 20.220.10.235:34878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/ls.php"] [unique_id "apPleGZcVaai59truiV1kAAAAHU"]
[Sun Aug 30 03:10:32.226889 2026] [security2:error] [pid 515259:tid 515474] [client 34.130.99.179:52022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/old_phpinfo.php"] [unique_id "apPleGZcVaai59truiV1kQAAAFQ"]
[Sun Aug 30 03:10:32.239974 2026] [security2:error] [pid 515259:tid 515396] [client 158.23.184.117:8142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/admin/function.php"] [unique_id "apPleGZcVaai59truiV1lgAAAAY"]
[Sun Aug 30 03:10:32.254561 2026] [security2:error] [pid 515259:tid 515506] [client 4.205.62.107:36724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/userfuns.php"] [unique_id "apPleGZcVaai59truiV1mAAAAHQ"]
[Sun Aug 30 03:10:32.255517 2026] [security2:error] [pid 515259:tid 515490] [client 158.23.147.79:56471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-admin/images/index.php"] [unique_id "apPleGZcVaai59truiV1mQAAAGQ"]
[Sun Aug 30 03:10:32.271959 2026] [security2:error] [pid 515259:tid 515392] [client 20.104.104.62:65276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/t00l.php"] [unique_id "apPleGZcVaai59truiV1mwAAAAI"]
[Sun Aug 30 03:10:32.288314 2026] [security2:error] [pid 515259:tid 515467] [client 20.220.10.235:5281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/pk.php"] [unique_id "apPleGZcVaai59truiV1ogAAAE0"]
[Sun Aug 30 03:10:32.328762 2026] [security2:error] [pid 515259:tid 515402] [client 20.63.219.114:15911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/robots.php"] [unique_id "apPleGZcVaai59truiV1sAAAAAw"]
[Sun Aug 30 03:10:32.341321 2026] [security2:error] [pid 515259:tid 515491] [client 20.104.50.220:59354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/themes.php"] [unique_id "apPleGZcVaai59truiV1swAAAGU"]
[Sun Aug 30 03:10:32.354777 2026] [security2:error] [pid 515259:tid 515405] [client 20.48.251.3:52252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/phpi.php"] [unique_id "apPleGZcVaai59truiV1tgAAAA8"]
[Sun Aug 30 03:10:32.355531 2026] [security2:error] [pid 515259:tid 515393] [client 20.104.49.130:43323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/zoo2.php"] [unique_id "apPleGZcVaai59truiV1twAAAAM"]
[Sun Aug 30 03:10:32.371989 2026] [security2:error] [pid 515259:tid 515418] [client 20.104.18.15:16964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/radio.php"] [unique_id "apPleGZcVaai59truiV1uQAAABw"]
[Sun Aug 30 03:10:32.378275 2026] [authz_core:error] [pid 515259:tid 515423] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:32.378694 2026] [authz_core:error] [pid 515259:tid 515423] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:32.383496 2026] [security2:error] [pid 515259:tid 515431] [client 20.197.61.180:12268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/security.php"] [unique_id "apPleGZcVaai59truiV1ugAAACk"]
[Sun Aug 30 03:10:32.386983 2026] [security2:error] [pid 515259:tid 515509] [client 158.23.184.117:8103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/wxo.php"] [unique_id "apPleGZcVaai59truiV1uwAAAHc"]
[Sun Aug 30 03:10:32.413125 2026] [security2:error] [pid 515259:tid 515448] [client 20.220.10.235:34860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/css/000.php"] [unique_id "apPleGZcVaai59truiV1wAAAADo"]
[Sun Aug 30 03:10:32.426586 2026] [security2:error] [pid 515259:tid 515459] [client 68.155.159.216:46024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-includes/certificates/index.php"] [unique_id "apPleGZcVaai59truiV1wwAAAEU"]
[Sun Aug 30 03:10:32.438822 2026] [security2:error] [pid 515259:tid 515403] [client 34.130.99.179:52026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/server-info.php"] [unique_id "apPleGZcVaai59truiV1xwAAAA0"]
[Sun Aug 30 03:10:32.442023 2026] [security2:error] [pid 515259:tid 515463] [client 20.104.104.62:62976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/ls.php"] [unique_id "apPleGZcVaai59truiV1ywAAAEk"]
[Sun Aug 30 03:10:32.460897 2026] [security2:error] [pid 515259:tid 515437] [client 20.104.50.220:29124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/ntaps.php"] [unique_id "apPleGZcVaai59truiV11AAAAC8"]
[Sun Aug 30 03:10:32.469445 2026] [security2:error] [pid 515259:tid 515479] [client 40.83.93.50:6557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/albin.php"] [unique_id "apPleGZcVaai59truiV12AAAAFk"]
[Sun Aug 30 03:10:32.479323 2026] [security2:error] [pid 515259:tid 515411] [client 20.220.10.235:5543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/ft.php"] [unique_id "apPleGZcVaai59truiV13AAAABU"]
[Sun Aug 30 03:10:32.500059 2026] [security2:error] [pid 515259:tid 515517] [client 20.104.49.130:63585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/one.php"] [unique_id "apPleGZcVaai59truiV13gAAAH8"]
[Sun Aug 30 03:10:32.520492 2026] [authz_core:error] [pid 515259:tid 515506] [client 66.249.66.68:36706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:32.520786 2026] [authz_core:error] [pid 515259:tid 515506] [client 66.249.66.68:36706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:32.529791 2026] [security2:error] [pid 515259:tid 515450] [client 158.23.184.117:8153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/wp-admin/theme-editor.php"] [unique_id "apPleGZcVaai59truiV14QAAADw"]
[Sun Aug 30 03:10:32.533192 2026] [security2:error] [pid 515259:tid 515457] [client 68.155.159.216:12228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPleGZcVaai59truiV15QAAAEM"]
[Sun Aug 30 03:10:32.540800 2026] [authz_core:error] [pid 515259:tid 515420] [client 66.249.66.73:54482] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:32.541235 2026] [authz_core:error] [pid 515259:tid 515420] [client 66.249.66.73:54482] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:32.547377 2026] [security2:error] [pid 515259:tid 515434] [client 158.23.147.79:62003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/classwithtostring.php"] [unique_id "apPleGZcVaai59truiV16AAAACw"]
[Sun Aug 30 03:10:32.548889 2026] [security2:error] [pid 515259:tid 515446] [client 20.220.10.235:34955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/cy.php"] [unique_id "apPleGZcVaai59truiV16QAAADg"]
[Sun Aug 30 03:10:32.549477 2026] [security2:error] [pid 515259:tid 515510] [client 20.48.251.3:13397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/requirements.php"] [unique_id "apPleGZcVaai59truiV16gAAAHg"]
[Sun Aug 30 03:10:32.572658 2026] [security2:error] [pid 515259:tid 515393] [client 20.104.50.220:29180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/ccc.php"] [unique_id "apPleGZcVaai59truiV19gAAAAM"]
[Sun Aug 30 03:10:32.575738 2026] [authz_core:error] [pid 515259:tid 515439] [client 66.249.66.194:55662] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:32.576171 2026] [authz_core:error] [pid 515259:tid 515439] [client 66.249.66.194:55662] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:32.585538 2026] [security2:error] [pid 515259:tid 515516] [client 20.104.104.62:2929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/css/000.php"] [unique_id "apPleGZcVaai59truiV2AQAAAH4"]
[Sun Aug 30 03:10:32.596632 2026] [security2:error] [pid 515259:tid 515460] [client 20.104.18.15:18429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/zoo2.php"] [unique_id "apPleGZcVaai59truiV2BwAAAEY"]
[Sun Aug 30 03:10:32.624795 2026] [security2:error] [pid 515259:tid 515407] [client 20.104.18.15:22414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/w3lls.php"] [unique_id "apPleGZcVaai59truiV2EwAAABE"]
[Sun Aug 30 03:10:32.645182 2026] [core:alert] [pid 515259:tid 515447] [client 177.220.183.172:5500] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:10:32.673159 2026] [authz_core:error] [pid 515259:tid 515399] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp
[Sun Aug 30 03:10:32.673576 2026] [authz_core:error] [pid 515259:tid 515399] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Fccp
[Sun Aug 30 03:10:32.687929 2026] [security2:error] [pid 515259:tid 515491] [client 20.220.10.235:34963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/admin.php/pindex.php"] [unique_id "apPleGZcVaai59truiV2IwAAAGU"]
[Sun Aug 30 03:10:32.695978 2026] [security2:error] [pid 515259:tid 515474] [client 34.130.99.179:52028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/server-status.php"] [unique_id "apPleGZcVaai59truiV2JgAAAFQ"]
[Sun Aug 30 03:10:32.697214 2026] [security2:error] [pid 515259:tid 515497] [client 20.151.200.44:28561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/qi.php"] [unique_id "apPleGZcVaai59truiV2KAAAAGs"]
[Sun Aug 30 03:10:32.701386 2026] [security2:error] [pid 515259:tid 515462] [client 4.205.62.107:61733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/services.php"] [unique_id "apPleGZcVaai59truiV2KgAAAEg"]
[Sun Aug 30 03:10:32.715119 2026] [security2:error] [pid 515259:tid 515448] [client 20.104.104.62:56554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/cy.php"] [unique_id "apPleGZcVaai59truiV2MQAAADo"]
[Sun Aug 30 03:10:32.757366 2026] [security2:error] [pid 515259:tid 515471] [client 158.23.184.117:8129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/termps.php"] [unique_id "apPleGZcVaai59truiV2OAAAAFE"]
[Sun Aug 30 03:10:32.772367 2026] [authz_core:error] [pid 515259:tid 515478] [client 66.249.66.200:47039] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:32.772677 2026] [authz_core:error] [pid 515259:tid 515478] [client 66.249.66.200:47039] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:32.778796 2026] [security2:error] [pid 515259:tid 515500] [client 68.155.159.216:52603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/classwithtostring.php"] [unique_id "apPleGZcVaai59truiV2QQAAAG4"]
[Sun Aug 30 03:10:32.779945 2026] [security2:error] [pid 515259:tid 515453] [client 20.104.50.220:5560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wso.php"] [unique_id "apPleGZcVaai59truiV2QgAAAD8"]
[Sun Aug 30 03:10:32.800621 2026] [security2:error] [pid 515259:tid 515415] [client 20.104.50.220:63518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-content/fm.php"] [unique_id "apPleGZcVaai59truiV2SQAAABk"]
[Sun Aug 30 03:10:32.815274 2026] [security2:error] [pid 515259:tid 515433] [client 20.63.219.114:20577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/cron.php"] [unique_id "apPleGZcVaai59truiV2SgAAACs"]
[Sun Aug 30 03:10:32.822433 2026] [security2:error] [pid 515259:tid 515492] [client 20.220.10.235:34992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/admin.php/csv.php"] [unique_id "apPleGZcVaai59truiV2SwAAAGY"]
[Sun Aug 30 03:10:32.854264 2026] [security2:error] [pid 515259:tid 515483] [client 20.104.104.62:56540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/admin.php/pindex.php"] [unique_id "apPleGZcVaai59truiV2VQAAAF0"]
[Sun Aug 30 03:10:32.861387 2026] [authz_core:error] [pid 515259:tid 515450] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:32.861698 2026] [authz_core:error] [pid 515259:tid 515450] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:32.876308 2026] [security2:error] [pid 515259:tid 515418] [client 158.23.147.79:1920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-includes/index.php"] [unique_id "apPleGZcVaai59truiV2YQAAABw"]
[Sun Aug 30 03:10:32.879982 2026] [security2:error] [pid 515259:tid 515438] [client 20.151.200.44:41928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/wp-content/admin.php"] [unique_id "apPleGZcVaai59truiV2YwAAADA"]
[Sun Aug 30 03:10:32.889780 2026] [security2:error] [pid 515259:tid 515511] [client 20.104.49.130:48048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/albin.php"] [unique_id "apPleGZcVaai59truiV2aAAAAHk"]
[Sun Aug 30 03:10:32.897987 2026] [security2:error] [pid 515259:tid 515496] [client 158.23.184.117:7622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/fix.php"] [unique_id "apPleGZcVaai59truiV2bAAAAGo"]
[Sun Aug 30 03:10:32.901071 2026] [authz_core:error] [pid 515259:tid 515477] [client 216.73.216.128:64209] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:32.901374 2026] [authz_core:error] [pid 515259:tid 515477] [client 216.73.216.128:64209] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:32.907723 2026] [security2:error] [pid 515259:tid 515417] [client 20.104.50.220:33208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/images/sym.php"] [unique_id "apPleGZcVaai59truiV2bwAAABs"]
[Sun Aug 30 03:10:32.942905 2026] [security2:error] [pid 515259:tid 515410] [client 40.83.93.50:22110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/an.php"] [unique_id "apPleGZcVaai59truiV2eAAAABQ"]
[Sun Aug 30 03:10:32.943177 2026] [security2:error] [pid 515259:tid 515419] [client 20.151.200.44:40905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/wp-login.php"] [unique_id "apPleGZcVaai59truiV2eQAAAB0"]
[Sun Aug 30 03:10:32.943337 2026] [security2:error] [pid 515259:tid 515344] [remote 194.163.183.171:49778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.183.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "onestoptestshop.waterwaync.com"] [uri "/wp-login.php"] [unique_id "apPleGZcVaai59truiV2dwAAUlM"]
[Sun Aug 30 03:10:32.949225 2026] [security2:error] [pid 515259:tid 515499] [client 20.48.251.3:54777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/06.php"] [unique_id "apPleGZcVaai59truiV2egAAAG0"]
[Sun Aug 30 03:10:32.962132 2026] [security2:error] [pid 515259:tid 515425] [client 20.220.10.235:5279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/wp-ver.php"] [unique_id "apPleGZcVaai59truiV2fQAAACM"]
[Sun Aug 30 03:10:32.968578 2026] [security2:error] [pid 515259:tid 515429] [client 20.220.10.235:34849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/admin.php/700.php"] [unique_id "apPleGZcVaai59truiV2fwAAACc"]
[Sun Aug 30 03:10:32.989963 2026] [security2:error] [pid 515259:tid 515506] [client 20.104.49.130:54181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/run.php"] [unique_id "apPleGZcVaai59truiV2hgAAAHQ"]
[Sun Aug 30 03:10:32.990811 2026] [security2:error] [pid 515259:tid 515484] [client 20.104.104.62:65227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/admin.php/csv.php"] [unique_id "apPleGZcVaai59truiV2hwAAAF4"]
[Sun Aug 30 03:10:33.039191 2026] [security2:error] [pid 515259:tid 515399] [client 158.23.184.117:8064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/wp-includes/ID3/admin.php"] [unique_id "apPleWZcVaai59truiV2lAAAAAk"]
[Sun Aug 30 03:10:33.059149 2026] [security2:error] [pid 515259:tid 515514] [client 20.104.50.220:61661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/tes.php"] [unique_id "apPleWZcVaai59truiV2nQAAAHw"]
[Sun Aug 30 03:10:33.093742 2026] [security2:error] [pid 515259:tid 515460] [client 20.104.18.15:43904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/pri.php"] [unique_id "apPleWZcVaai59truiV2qwAAAEY"]
[Sun Aug 30 03:10:33.104224 2026] [security2:error] [pid 515259:tid 515453] [client 20.220.10.235:34895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/admin.php/007x.php"] [unique_id "apPleWZcVaai59truiV2rQAAAD8"]
[Sun Aug 30 03:10:33.109473 2026] [security2:error] [pid 515259:tid 515461] [client 20.197.61.180:3636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "apPleWZcVaai59truiV2rwAAAEc"]
[Sun Aug 30 03:10:33.126924 2026] [security2:error] [pid 515259:tid 515425] [client 20.104.104.62:49614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/admin.php/700.php"] [unique_id "apPleWZcVaai59truiV2tAAAACM"]
[Sun Aug 30 03:10:33.143917 2026] [authz_core:error] [pid 515259:tid 515503] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:33.144253 2026] [authz_core:error] [pid 515259:tid 515503] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:33.148176 2026] [security2:error] [pid 515259:tid 515347] [remote 194.163.183.171:49778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.183.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "onestoptestshop.waterwaync.com"] [uri "/wp-login.php"] [unique_id "apPleWZcVaai59truiV2uwAATVY"], referer: https://onestoptestshop.waterwaync.com/wp-login.php
[Sun Aug 30 03:10:33.177293 2026] [security2:error] [pid 515259:tid 515474] [client 20.63.219.114:15244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/goat.php"] [unique_id "apPleWZcVaai59truiV2wAAAAFQ"]
[Sun Aug 30 03:10:33.182473 2026] [security2:error] [pid 515259:tid 515501] [client 158.23.184.117:8168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/tiny.php"] [unique_id "apPleWZcVaai59truiV2wgAAAG8"]
[Sun Aug 30 03:10:33.235591 2026] [security2:error] [pid 515259:tid 515445] [client 20.220.10.235:34825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/admin.php/heex.php"] [unique_id "apPleWZcVaai59truiV20wAAADc"]
[Sun Aug 30 03:10:33.246787 2026] [security2:error] [pid 515259:tid 515456] [client 20.104.18.15:16699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/mghnhykio.php/new.php"] [unique_id "apPleWZcVaai59truiV22AAAAEI"]
[Sun Aug 30 03:10:33.257778 2026] [security2:error] [pid 515259:tid 515438] [client 20.104.104.62:49625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/admin.php/007x.php"] [unique_id "apPleWZcVaai59truiV22wAAADA"]
[Sun Aug 30 03:10:33.258193 2026] [security2:error] [pid 515259:tid 515514] [client 20.104.50.220:16688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apPleWZcVaai59truiV22gAAAHw"]
[Sun Aug 30 03:10:33.261105 2026] [security2:error] [pid 515259:tid 515401] [client 158.23.147.79:56484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/mah.php"] [unique_id "apPleWZcVaai59truiV23QAAAAs"]
[Sun Aug 30 03:10:33.314133 2026] [security2:error] [pid 515259:tid 515468] [client 4.205.62.107:17308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/phpi.php"] [unique_id "apPleWZcVaai59truiV28AAAAE4"]
[Sun Aug 30 03:10:33.322994 2026] [security2:error] [pid 515259:tid 515432] [client 158.23.184.117:8165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/css/classwithtostring.php"] [unique_id "apPleWZcVaai59truiV28wAAACo"]
[Sun Aug 30 03:10:33.337907 2026] [security2:error] [pid 515259:tid 515415] [client 20.48.251.3:59308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/atex1.php"] [unique_id "apPleWZcVaai59truiV29gAAABk"]
[Sun Aug 30 03:10:33.340128 2026] [security2:error] [pid 515259:tid 515484] [client 4.205.62.107:25482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/god.php"] [unique_id "apPleWZcVaai59truiV29wAAAF4"]
[Sun Aug 30 03:10:33.344227 2026] [security2:error] [pid 515259:tid 515440] [client 34.130.99.179:52038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/webroot/index.php/_environment"] [unique_id "apPleWZcVaai59truiV2-gAAADI"]
[Sun Aug 30 03:10:33.353153 2026] [authz_core:error] [pid 515259:tid 515487] [client 66.249.66.199:55715] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:33.353427 2026] [authz_core:error] [pid 515259:tid 515487] [client 66.249.66.199:55715] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:33.366064 2026] [security2:error] [pid 515259:tid 515390] [client 158.23.147.79:61792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/install.php"] [unique_id "apPleWZcVaai59truiV3AAAAAAA"]
[Sun Aug 30 03:10:33.372171 2026] [security2:error] [pid 515259:tid 515439] [client 20.220.10.235:34968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/tf.php"] [unique_id "apPleWZcVaai59truiV3AQAAADE"]
[Sun Aug 30 03:10:33.386543 2026] [security2:error] [pid 515259:tid 515510] [client 4.205.62.107:36693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/mamzi.php"] [unique_id "apPleWZcVaai59truiV3BAAAAHg"]
[Sun Aug 30 03:10:33.392221 2026] [security2:error] [pid 515259:tid 515403] [client 20.104.104.62:2939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/admin.php/heex.php"] [unique_id "apPleWZcVaai59truiV3BwAAAA0"]
[Sun Aug 30 03:10:33.422389 2026] [authz_core:error] [pid 515259:tid 515441] [client 66.249.66.77:60412] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:33.422677 2026] [authz_core:error] [pid 515259:tid 515441] [client 66.249.66.77:60412] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:33.442080 2026] [security2:error] [pid 515259:tid 515411] [client 40.83.93.50:10689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/mini.php"] [unique_id "apPleWZcVaai59truiV3EAAAABU"]
[Sun Aug 30 03:10:33.460549 2026] [security2:error] [pid 515259:tid 515452] [client 158.23.184.117:8158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/buy.php"] [unique_id "apPleWZcVaai59truiV3FgAAAD4"]
[Sun Aug 30 03:10:33.473061 2026] [security2:error] [pid 515259:tid 515488] [client 20.220.10.235:5785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/ah24.php"] [unique_id "apPleWZcVaai59truiV3GgAAAGI"]
[Sun Aug 30 03:10:33.484283 2026] [security2:error] [pid 515259:tid 515479] [client 20.104.50.220:63199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/dx.php"] [unique_id "apPleWZcVaai59truiV3HgAAAFk"]
[Sun Aug 30 03:10:33.490599 2026] [security2:error] [pid 515259:tid 515463] [client 20.48.251.3:52213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "apPleWZcVaai59truiV3IAAAAEk"]
[Sun Aug 30 03:10:33.509628 2026] [security2:error] [pid 515259:tid 515426] [client 20.104.18.15:16977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/one.php"] [unique_id "apPleWZcVaai59truiV3IwAAACQ"]
[Sun Aug 30 03:10:33.526280 2026] [security2:error] [pid 515259:tid 515397] [client 20.104.104.62:62960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/tf.php"] [unique_id "apPleWZcVaai59truiV3JQAAAAc"]
[Sun Aug 30 03:10:33.531549 2026] [security2:error] [pid 515259:tid 515500] [client 68.155.159.216:45985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-admin/network/index.php"] [unique_id "apPleWZcVaai59truiV3JwAAAG4"]
[Sun Aug 30 03:10:33.534674 2026] [security2:error] [pid 515259:tid 515394] [client 20.151.200.44:28629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/px.php"] [unique_id "apPleWZcVaai59truiV3KQAAAAQ"]
[Sun Aug 30 03:10:33.541875 2026] [security2:error] [pid 515259:tid 515434] [client 20.63.219.114:15626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/gg.php"] [unique_id "apPleWZcVaai59truiV3KwAAACw"]
[Sun Aug 30 03:10:33.555715 2026] [security2:error] [pid 515259:tid 515419] [client 20.220.10.235:34868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/update/da222.php"] [unique_id "apPleWZcVaai59truiV3LgAAAB0"]
[Sun Aug 30 03:10:33.580060 2026] [security2:error] [pid 515259:tid 515406] [client 20.104.49.130:35587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/133.php"] [unique_id "apPleWZcVaai59truiV3OQAAABA"]
[Sun Aug 30 03:10:33.595050 2026] [security2:error] [pid 515259:tid 515498] [client 34.130.99.179:52044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/mail/phpinfo.php"] [unique_id "apPleWZcVaai59truiV3QgAAAGw"]
[Sun Aug 30 03:10:33.598775 2026] [security2:error] [pid 515259:tid 515457] [client 20.104.50.220:62810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/zip.php"] [unique_id "apPleWZcVaai59truiV3RAAAAEM"]
[Sun Aug 30 03:10:33.600356 2026] [security2:error] [pid 515259:tid 515420] [client 158.23.184.117:8099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/bk.php"] [unique_id "apPleWZcVaai59truiV3RQAAAB4"]
[Sun Aug 30 03:10:33.650372 2026] [security2:error] [pid 515259:tid 515466] [client 68.155.159.216:57084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-admin.php"] [unique_id "apPleWZcVaai59truiV3TwAAAEw"]
[Sun Aug 30 03:10:33.658556 2026] [security2:error] [pid 515259:tid 515512] [client 20.104.104.62:62935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/update/da222.php"] [unique_id "apPleWZcVaai59truiV3VAAAAHo"]
[Sun Aug 30 03:10:33.686487 2026] [security2:error] [pid 515259:tid 515495] [client 20.220.10.235:34980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/qi.php"] [unique_id "apPleWZcVaai59truiV3WQAAAGk"]
[Sun Aug 30 03:10:33.690987 2026] [security2:error] [pid 515259:tid 515453] [client 20.48.251.3:13423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/var/www/wallet/index.php"] [unique_id "apPleWZcVaai59truiV3XAAAAD8"]
[Sun Aug 30 03:10:33.696038 2026] [authz_core:error] [pid 515259:tid 515488] [client 66.249.66.194:48582] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:33.696309 2026] [authz_core:error] [pid 515259:tid 515488] [client 66.249.66.194:48582] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:33.709882 2026] [security2:error] [pid 515259:tid 515458] [client 20.104.50.220:52844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/cxc.php"] [unique_id "apPleWZcVaai59truiV3YQAAAEQ"]
[Sun Aug 30 03:10:33.744482 2026] [security2:error] [pid 515259:tid 515394] [client 158.23.184.117:8189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/.trash7309/index.php"] [unique_id "apPleWZcVaai59truiV3awAAAAQ"]
[Sun Aug 30 03:10:33.761132 2026] [security2:error] [pid 515259:tid 515405] [client 20.104.18.15:22361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/fpwch.php"] [unique_id "apPleWZcVaai59truiV3cQAAAA8"]
[Sun Aug 30 03:10:33.766796 2026] [security2:error] [pid 515259:tid 515427] [client 20.104.18.15:18337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/zoo1.php"] [unique_id "apPleWZcVaai59truiV3cwAAACU"]
[Sun Aug 30 03:10:33.797538 2026] [security2:error] [pid 515259:tid 515440] [client 34.130.99.179:52050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/cpanel/phpinfo.php"] [unique_id "apPleWZcVaai59truiV3fgAAADI"]
[Sun Aug 30 03:10:33.797627 2026] [security2:error] [pid 515259:tid 515469] [client 20.197.61.180:16867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/system.php"] [unique_id "apPleWZcVaai59truiV3fwAAAE8"]
[Sun Aug 30 03:10:33.806308 2026] [security2:error] [pid 515259:tid 515401] [client 20.104.104.62:53171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/qi.php"] [unique_id "apPleWZcVaai59truiV3gQAAAAs"]
[Sun Aug 30 03:10:33.808893 2026] [authz_core:error] [pid 515259:tid 515475] [client 216.73.216.128:64209] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:33.809157 2026] [authz_core:error] [pid 515259:tid 515475] [client 216.73.216.128:64209] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:33.817619 2026] [security2:error] [pid 515259:tid 515513] [client 20.220.10.235:34981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/px.php"] [unique_id "apPleWZcVaai59truiV3ggAAAHs"]
[Sun Aug 30 03:10:33.825362 2026] [security2:error] [pid 515259:tid 515514] [client 20.220.10.235:5787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/wp-admin/zwso.php"] [unique_id "apPleWZcVaai59truiV3gwAAAHw"]
[Sun Aug 30 03:10:33.853716 2026] [security2:error] [pid 515259:tid 515496] [client 4.205.62.107:64454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/filesystems.php"] [unique_id "apPleWZcVaai59truiV3iwAAAGo"]
[Sun Aug 30 03:10:33.888527 2026] [security2:error] [pid 515259:tid 515468] [client 158.23.184.117:8163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/jp.php"] [unique_id "apPleWZcVaai59truiV3kgAAAE4"]
[Sun Aug 30 03:10:33.897951 2026] [security2:error] [pid 515259:tid 515510] [client 20.63.219.114:2076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/defaults.php"] [unique_id "apPleWZcVaai59truiV3lAAAAHg"]
[Sun Aug 30 03:10:33.919359 2026] [security2:error] [pid 515259:tid 515413] [client 20.104.50.220:5441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/fox.php"] [unique_id "apPleWZcVaai59truiV3mgAAABc"]
[Sun Aug 30 03:10:33.935637 2026] [security2:error] [pid 515259:tid 515446] [client 20.104.104.62:56553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/px.php"] [unique_id "apPleWZcVaai59truiV3oQAAADg"]
[Sun Aug 30 03:10:33.942111 2026] [security2:error] [pid 515259:tid 515422] [client 20.104.50.220:63489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-content/a.php"] [unique_id "apPleWZcVaai59truiV3ogAAACA"]
[Sun Aug 30 03:10:33.957970 2026] [security2:error] [pid 515259:tid 515406] [client 20.220.10.235:34836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/is.php"] [unique_id "apPleWZcVaai59truiV3pgAAABA"]
[Sun Aug 30 03:10:33.991542 2026] [authz_core:error] [pid 515259:tid 515457] [client 216.73.216.128:51580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:33.991844 2026] [authz_core:error] [pid 515259:tid 515457] [client 216.73.216.128:51580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:33.995994 2026] [security2:error] [pid 515259:tid 515470] [client 40.83.93.50:22099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/robots.php"] [unique_id "apPleWZcVaai59truiV3uQAAAFA"]
[Sun Aug 30 03:10:34.001670 2026] [security2:error] [pid 515259:tid 515421] [client 34.130.99.179:52060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/hosting/phpinfo.php"] [unique_id "apPlemZcVaai59truiV3uwAAAB8"]
[Sun Aug 30 03:10:34.029020 2026] [security2:error] [pid 515259:tid 515414] [client 158.23.184.117:8177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/item.php"] [unique_id "apPlemZcVaai59truiV3wwAAABg"]
[Sun Aug 30 03:10:34.060550 2026] [security2:error] [pid 515259:tid 515512] [client 20.104.50.220:33175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/images/shell.php"] [unique_id "apPlemZcVaai59truiV3zgAAAHo"]
[Sun Aug 30 03:10:34.061842 2026] [security2:error] [pid 515259:tid 515399] [client 20.104.104.62:49656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/is.php"] [unique_id "apPlemZcVaai59truiV30AAAAAk"]
[Sun Aug 30 03:10:34.085716 2026] [security2:error] [pid 515259:tid 515413] [client 20.220.10.235:34874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/od.php"] [unique_id "apPlemZcVaai59truiV32gAAABc"]
[Sun Aug 30 03:10:34.100404 2026] [security2:error] [pid 515259:tid 515446] [client 20.48.251.3:64272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/xin1.php"] [unique_id "apPlemZcVaai59truiV34wAAADg"]
[Sun Aug 30 03:10:34.106208 2026] [security2:error] [pid 515259:tid 515422] [client 68.155.159.216:52290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/install.php"] [unique_id "apPlemZcVaai59truiV35AAAACA"]
[Sun Aug 30 03:10:34.118248 2026] [authz_core:error] [pid 515259:tid 515507] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:34.118527 2026] [authz_core:error] [pid 515259:tid 515507] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:34.139304 2026] [security2:error] [pid 515259:tid 515439] [client 20.220.10.235:5313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.geotravel.am"] [uri "/waf.php"] [unique_id "apPlemZcVaai59truiV38gAAADE"]
[Sun Aug 30 03:10:34.173804 2026] [security2:error] [pid 515259:tid 515467] [client 158.23.184.117:8066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/wp-admin/controller.php"] [unique_id "apPlemZcVaai59truiV3-wAAAE0"]
[Sun Aug 30 03:10:34.180321 2026] [security2:error] [pid 515259:tid 515515] [client 20.104.49.130:53527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/srontol.php"] [unique_id "apPlemZcVaai59truiV3_QAAAH0"]
[Sun Aug 30 03:10:34.189850 2026] [core:alert] [pid 515259:tid 515442] [client 103.156.189.230:36480] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:10:34.192697 2026] [security2:error] [pid 515259:tid 515483] [client 20.104.104.62:49629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/od.php"] [unique_id "apPlemZcVaai59truiV4AAAAAF0"]
[Sun Aug 30 03:10:34.212865 2026] [security2:error] [pid 515259:tid 515466] [client 20.104.50.220:62000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/teslav.php"] [unique_id "apPlemZcVaai59truiV4CQAAAEw"]
[Sun Aug 30 03:10:34.218553 2026] [security2:error] [pid 515259:tid 515496] [client 20.220.10.235:34889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/wp-the.php"] [unique_id "apPlemZcVaai59truiV4CwAAAGo"]
[Sun Aug 30 03:10:34.253695 2026] [security2:error] [pid 515259:tid 515484] [client 20.104.18.15:44018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/wp_blog_footer.php"] [unique_id "apPlemZcVaai59truiV4EwAAAF4"]
[Sun Aug 30 03:10:34.257791 2026] [security2:error] [pid 515259:tid 515423] [client 34.130.99.179:52064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/webmail/phpinfo.php"] [unique_id "apPlemZcVaai59truiV4FQAAACE"]
[Sun Aug 30 03:10:34.327708 2026] [security2:error] [pid 515259:tid 515408] [client 20.63.219.114:2053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/h.php"] [unique_id "apPlemZcVaai59truiV4MgAAABI"]
[Sun Aug 30 03:10:34.335893 2026] [security2:error] [pid 515259:tid 515444] [client 20.104.104.62:62927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/wp-the.php"] [unique_id "apPlemZcVaai59truiV4NAAAADY"]
[Sun Aug 30 03:10:34.351080 2026] [security2:error] [pid 515259:tid 515490] [client 20.220.10.235:34832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/wt.php"] [unique_id "apPlemZcVaai59truiV4NwAAAGQ"]
[Sun Aug 30 03:10:34.385367 2026] [security2:error] [pid 515259:tid 515456] [client 20.104.18.15:64885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/admin.php/nope.php"] [unique_id "apPlemZcVaai59truiV4OgAAAEI"]
[Sun Aug 30 03:10:34.398913 2026] [security2:error] [pid 515259:tid 515411] [client 20.104.50.220:16630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/sx.php"] [unique_id "apPlemZcVaai59truiV4PQAAABU"]
[Sun Aug 30 03:10:34.402202 2026] [security2:error] [pid 515259:tid 515497] [client 158.23.184.117:8089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/wp-configs.php"] [unique_id "apPlemZcVaai59truiV4PgAAAGs"]
[Sun Aug 30 03:10:34.436936 2026] [security2:error] [pid 515259:tid 515414] [client 158.23.147.79:57694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-blog-header.php"] [unique_id "apPlemZcVaai59truiV4RQAAABg"]
[Sun Aug 30 03:10:34.453663 2026] [security2:error] [pid 515259:tid 515494] [client 4.205.62.107:17340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "apPlemZcVaai59truiV4TwAAAGg"]
[Sun Aug 30 03:10:34.475656 2026] [security2:error] [pid 515259:tid 515476] [client 20.48.251.3:55763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/aws_sdk_settings.php"] [unique_id "apPlemZcVaai59truiV4XAAAAFY"]
[Sun Aug 30 03:10:34.477382 2026] [security2:error] [pid 515259:tid 515504] [client 40.83.93.50:6157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/cron.php"] [unique_id "apPlemZcVaai59truiV4XwAAAHI"]
[Sun Aug 30 03:10:34.480055 2026] [security2:error] [pid 515259:tid 515486] [client 4.205.62.107:25898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/fff.php"] [unique_id "apPlemZcVaai59truiV4YAAAAGA"]
[Sun Aug 30 03:10:34.497257 2026] [security2:error] [pid 515259:tid 515405] [client 20.220.10.235:34850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/im.php"] [unique_id "apPlemZcVaai59truiV4YwAAAA8"]
[Sun Aug 30 03:10:34.497279 2026] [security2:error] [pid 515259:tid 515517] [client 20.104.104.62:49600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/wt.php"] [unique_id "apPlemZcVaai59truiV4ZAAAAH8"]
[Sun Aug 30 03:10:34.520927 2026] [security2:error] [pid 515259:tid 515423] [client 34.130.99.179:52076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/smtp/phpinfo.php"] [unique_id "apPlemZcVaai59truiV4ZQAAACE"]
[Sun Aug 30 03:10:34.529076 2026] [security2:error] [pid 515259:tid 515400] [client 20.197.61.180:16874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/tflow/min.php"] [unique_id "apPlemZcVaai59truiV4aAAAAAo"]
[Sun Aug 30 03:10:34.547132 2026] [security2:error] [pid 515259:tid 515470] [client 158.23.184.117:8151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/wp-admin/user/credits.php"] [unique_id "apPlemZcVaai59truiV4bgAAAFA"]
[Sun Aug 30 03:10:34.548105 2026] [authz_core:error] [pid 515259:tid 515429] [client 66.249.66.196:39635] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:34.548572 2026] [authz_core:error] [pid 515259:tid 515429] [client 66.249.66.196:39635] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:34.575399 2026] [security2:error] [pid 515259:tid 515458] [client 4.205.62.107:36673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/public/rip.php.php"] [unique_id "apPlemZcVaai59truiV4eAAAAEQ"]
[Sun Aug 30 03:10:34.616298 2026] [authz_core:error] [pid 515259:tid 515425] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:34.616575 2026] [authz_core:error] [pid 515259:tid 515425] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:34.623955 2026] [security2:error] [pid 515259:tid 515422] [client 20.104.104.62:63013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/im.php"] [unique_id "apPlemZcVaai59truiV4iwAAACA"]
[Sun Aug 30 03:10:34.624874 2026] [security2:error] [pid 515259:tid 515413] [client 20.48.251.3:59478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/myfile.php"] [unique_id "apPlemZcVaai59truiV4jAAAABc"]
[Sun Aug 30 03:10:34.636724 2026] [security2:error] [pid 515259:tid 515390] [client 20.104.50.220:31496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/11.php"] [unique_id "apPlemZcVaai59truiV4kQAAAAA"]
[Sun Aug 30 03:10:34.642400 2026] [security2:error] [pid 515259:tid 515412] [client 20.220.10.235:34856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/file.php"] [unique_id "apPlemZcVaai59truiV4kwAAABY"]
[Sun Aug 30 03:10:34.644547 2026] [authz_core:error] [pid 515259:tid 515431] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:34.644855 2026] [authz_core:error] [pid 515259:tid 515431] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:34.647765 2026] [security2:error] [pid 515259:tid 515476] [client 20.104.18.15:17008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/503.php"] [unique_id "apPlemZcVaai59truiV4lAAAAFY"]
[Sun Aug 30 03:10:34.689516 2026] [security2:error] [pid 515259:tid 515501] [client 158.23.184.117:8075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "apPlemZcVaai59truiV4owAAAG8"]
[Sun Aug 30 03:10:34.720709 2026] [security2:error] [pid 515259:tid 515461] [client 20.63.219.114:19141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/num.php"] [unique_id "apPlemZcVaai59truiV4rgAAAEc"]
[Sun Aug 30 03:10:34.742875 2026] [security2:error] [pid 515259:tid 515486] [client 34.130.99.179:52078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlemZcVaai59truiV4tQAAAGA"]
[Sun Aug 30 03:10:34.750597 2026] [security2:error] [pid 515259:tid 515415] [client 20.104.50.220:28714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/@.php"] [unique_id "apPlemZcVaai59truiV4tgAAABk"]
[Sun Aug 30 03:10:34.752682 2026] [security2:error] [pid 515259:tid 515443] [client 20.104.104.62:56558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/file.php"] [unique_id "apPlemZcVaai59truiV4uAAAADU"]
[Sun Aug 30 03:10:34.776398 2026] [security2:error] [pid 515259:tid 515396] [client 20.220.10.235:34883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/ca.php"] [unique_id "apPlemZcVaai59truiV4wAAAAAY"]
[Sun Aug 30 03:10:34.806565 2026] [security2:error] [pid 515259:tid 515474] [client 158.69.118.189:50725] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "158.69.118.189" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPlemZcVaai59truiV4xwAAAFQ"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:10:34.806680 2026] [security2:error] [pid 515259:tid 515474] [client 158.69.118.189:50725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPlemZcVaai59truiV4xwAAAFQ"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:10:34.827073 2026] [security2:error] [pid 515259:tid 515466] [client 20.48.251.3:13393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/124.php"] [unique_id "apPlemZcVaai59truiV4yQAAAEw"]
[Sun Aug 30 03:10:34.828965 2026] [security2:error] [pid 515259:tid 515460] [client 158.23.184.117:8174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/.well-known/about/function.php"] [unique_id "apPlemZcVaai59truiV4ygAAAEY"]
[Sun Aug 30 03:10:34.853395 2026] [security2:error] [pid 515259:tid 515464] [client 20.104.50.220:63046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/constant.php"] [unique_id "apPlemZcVaai59truiV40AAAAEo"]
[Sun Aug 30 03:10:34.863340 2026] [security2:error] [pid 515259:tid 515403] [client 68.155.159.216:62645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apPlemZcVaai59truiV41QAAAA0"]
[Sun Aug 30 03:10:34.881888 2026] [security2:error] [pid 515259:tid 515426] [client 20.104.104.62:2896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/ca.php"] [unique_id "apPlemZcVaai59truiV43QAAACQ"]
[Sun Aug 30 03:10:34.904333 2026] [security2:error] [pid 515259:tid 515501] [client 195.178.110.155:56632] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "innatalybridal.com"] [uri "/livewire/update"] [unique_id "apPlemZcVaai59truiV44QAAAG8"]
[Sun Aug 30 03:10:34.908535 2026] [security2:error] [pid 515259:tid 515447] [client 20.104.18.15:18319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/radio.php"] [unique_id "apPlemZcVaai59truiV44wAAADk"]
[Sun Aug 30 03:10:34.910471 2026] [security2:error] [pid 515259:tid 515475] [client 20.220.10.235:34960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/pb.php"] [unique_id "apPlemZcVaai59truiV45AAAAFU"]
[Sun Aug 30 03:10:34.912440 2026] [security2:error] [pid 515259:tid 515480] [client 20.151.200.44:28568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/is.php"] [unique_id "apPlemZcVaai59truiV45QAAAFo"]
[Sun Aug 30 03:10:34.913853 2026] [security2:error] [pid 515259:tid 515498] [client 20.104.18.15:22463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/domvf.php"] [unique_id "apPlemZcVaai59truiV46AAAAGw"]
[Sun Aug 30 03:10:34.922114 2026] [security2:error] [pid 515259:tid 515515] [client 68.155.159.216:46065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apPlemZcVaai59truiV46wAAAH0"]
[Sun Aug 30 03:10:34.946441 2026] [security2:error] [pid 515259:tid 515427] [client 34.130.99.179:52086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/phpinfo.php.old"] [unique_id "apPlemZcVaai59truiV49AAAACU"]
[Sun Aug 30 03:10:34.954061 2026] [authz_core:error] [pid 515259:tid 515470] [client 66.249.66.200:46413] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:34.954524 2026] [authz_core:error] [pid 515259:tid 515470] [client 66.249.66.200:46413] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:34.970526 2026] [security2:error] [pid 515259:tid 515478] [client 158.23.184.117:8185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPlemZcVaai59truiV4_AAAAFg"]
[Sun Aug 30 03:10:35.011373 2026] [security2:error] [pid 515259:tid 515513] [client 20.104.104.62:65237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/pb.php"] [unique_id "apPle2ZcVaai59truiV5CgAAAHs"]
[Sun Aug 30 03:10:35.022002 2026] [security2:error] [pid 515259:tid 515506] [client 4.205.62.107:61712] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/retu11.PhP"] [unique_id "apPle2ZcVaai59truiV5DAAAAHQ"]
[Sun Aug 30 03:10:35.043514 2026] [security2:error] [pid 515259:tid 515412] [client 20.220.10.235:34835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/pk.php"] [unique_id "apPle2ZcVaai59truiV5EgAAABY"]
[Sun Aug 30 03:10:35.061306 2026] [security2:error] [pid 515259:tid 515493] [client 20.104.50.220:5483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/CNsAwv8e6ui.php"] [unique_id "apPle2ZcVaai59truiV5GwAAAGc"]
[Sun Aug 30 03:10:35.086966 2026] [authz_core:error] [pid 515259:tid 515456] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:35.087251 2026] [authz_core:error] [pid 515259:tid 515456] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:35.088006 2026] [security2:error] [pid 515259:tid 515394] [client 40.83.93.50:6529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/goat.php"] [unique_id "apPle2ZcVaai59truiV5KgAAAAQ"]
[Sun Aug 30 03:10:35.094163 2026] [security2:error] [pid 515259:tid 515442] [client 20.104.50.220:51636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/images/sym.php"] [unique_id "apPle2ZcVaai59truiV5MAAAADQ"]
[Sun Aug 30 03:10:35.111119 2026] [authz_core:error] [pid 515259:tid 515436] [client 66.249.66.70:36018] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:35.111503 2026] [security2:error] [pid 515259:tid 515450] [client 158.23.184.117:8137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/gg.php"] [unique_id "apPle2ZcVaai59truiV5NgAAADw"]
[Sun Aug 30 03:10:35.111576 2026] [authz_core:error] [pid 515259:tid 515436] [client 66.249.66.70:36018] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:35.114084 2026] [authz_core:error] [pid 515259:tid 515393] [client 216.73.216.128:51580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:35.114564 2026] [authz_core:error] [pid 515259:tid 515393] [client 216.73.216.128:51580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:35.142839 2026] [security2:error] [pid 515259:tid 515466] [client 20.104.104.62:65224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/pk.php"] [unique_id "apPle2ZcVaai59truiV5PgAAAEw"]
[Sun Aug 30 03:10:35.146749 2026] [security2:error] [pid 515259:tid 515509] [client 158.69.118.189:50735] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "158.69.118.189" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPle2ZcVaai59truiV5QQAAAHc"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:10:35.146854 2026] [security2:error] [pid 515259:tid 515509] [client 158.69.118.189:50735] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPle2ZcVaai59truiV5QQAAAHc"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:10:35.178327 2026] [security2:error] [pid 515259:tid 515403] [client 20.220.10.235:34976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/ft.php"] [unique_id "apPle2ZcVaai59truiV5RgAAAA0"]
[Sun Aug 30 03:10:35.198409 2026] [security2:error] [pid 515259:tid 515446] [client 20.104.50.220:33180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/images/mini.php"] [unique_id "apPle2ZcVaai59truiV5SwAAADg"]
[Sun Aug 30 03:10:35.203024 2026] [security2:error] [pid 515259:tid 515414] [client 34.130.99.179:52098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/phpinfo.php~"] [unique_id "apPle2ZcVaai59truiV5TQAAABg"]
[Sun Aug 30 03:10:35.249170 2026] [security2:error] [pid 515259:tid 515460] [client 20.197.61.180:15753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/tflow/pk.php"] [unique_id "apPle2ZcVaai59truiV5WwAAAEY"]
[Sun Aug 30 03:10:35.255197 2026] [security2:error] [pid 515259:tid 515402] [client 158.23.184.117:8085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/wp-admin/includes/post.php"] [unique_id "apPle2ZcVaai59truiV5XAAAAAw"]
[Sun Aug 30 03:10:35.266305 2026] [security2:error] [pid 515259:tid 515475] [client 20.48.251.3:64268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/sadd.php"] [unique_id "apPle2ZcVaai59truiV5XQAAAFU"]
[Sun Aug 30 03:10:35.271310 2026] [security2:error] [pid 515259:tid 515394] [client 20.104.104.62:2900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/ft.php"] [unique_id "apPle2ZcVaai59truiV5XwAAAAQ"]
[Sun Aug 30 03:10:35.310872 2026] [security2:error] [pid 515259:tid 515499] [client 20.220.10.235:34829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/wp-ver.php"] [unique_id "apPle2ZcVaai59truiV5eQAAAG0"]
[Sun Aug 30 03:10:35.328481 2026] [security2:error] [pid 515259:tid 515412] [client 20.63.219.114:15616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/abc.php"] [unique_id "apPle2ZcVaai59truiV5fwAAABY"]
[Sun Aug 30 03:10:35.387971 2026] [security2:error] [pid 515259:tid 515501] [client 20.104.50.220:61647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/tshop.php"] [unique_id "apPle2ZcVaai59truiV5hAAAAG8"]
[Sun Aug 30 03:10:35.407839 2026] [security2:error] [pid 515259:tid 515429] [client 34.130.99.179:52102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/info.php.bak"] [unique_id "apPle2ZcVaai59truiV5iQAAACc"]
[Sun Aug 30 03:10:35.414224 2026] [security2:error] [pid 515259:tid 515490] [client 20.104.104.62:65268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/wp-ver.php"] [unique_id "apPle2ZcVaai59truiV5igAAAGQ"]
[Sun Aug 30 03:10:35.420542 2026] [security2:error] [pid 515259:tid 515485] [client 20.104.18.15:43310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/sushi.php"] [unique_id "apPle2ZcVaai59truiV5jAAAAF8"]
[Sun Aug 30 03:10:35.423530 2026] [authz_core:error] [pid 515259:tid 515390] [client 66.249.66.37:50243] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:35.423975 2026] [authz_core:error] [pid 515259:tid 515390] [client 66.249.66.37:50243] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:35.446882 2026] [security2:error] [pid 515259:tid 515408] [client 20.220.10.235:34859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/ah24.php"] [unique_id "apPle2ZcVaai59truiV5kwAAABI"]
[Sun Aug 30 03:10:35.480824 2026] [authz_core:error] [pid 515259:tid 515425] [client 216.73.216.128:55788] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:35.481101 2026] [authz_core:error] [pid 515259:tid 515425] [client 216.73.216.128:55788] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:35.489488 2026] [security2:error] [pid 515259:tid 515410] [client 158.23.184.117:8190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.faceofaustralia.rosscosmetics.com"] [uri "/wp-act.php"] [unique_id "apPle2ZcVaai59truiV5oQAAABQ"]
[Sun Aug 30 03:10:35.510134 2026] [security2:error] [pid 515259:tid 515399] [client 20.151.200.44:28584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/od.php"] [unique_id "apPle2ZcVaai59truiV5owAAAAk"]
[Sun Aug 30 03:10:35.530932 2026] [security2:error] [pid 515259:tid 515441] [client 20.104.18.15:64892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/lib.php/new.php"] [unique_id "apPle2ZcVaai59truiV5qQAAADM"]
[Sun Aug 30 03:10:35.531723 2026] [security2:error] [pid 515259:tid 515494] [client 158.23.147.79:57696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apPle2ZcVaai59truiV5rAAAAGg"]
[Sun Aug 30 03:10:35.531756 2026] [security2:error] [pid 515259:tid 515458] [client 20.104.50.220:16743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "apPle2ZcVaai59truiV5qwAAAEQ"]
[Sun Aug 30 03:10:35.554597 2026] [security2:error] [pid 515259:tid 515433] [client 20.104.104.62:49658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/ah24.php"] [unique_id "apPle2ZcVaai59truiV5sgAAACs"]
[Sun Aug 30 03:10:35.573926 2026] [authz_core:error] [pid 515259:tid 515495] [client 216.73.216.128:51580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:35.574201 2026] [authz_core:error] [pid 515259:tid 515495] [client 216.73.216.128:51580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:35.584310 2026] [security2:error] [pid 515259:tid 515412] [client 20.220.10.235:34888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPle2ZcVaai59truiV5vgAAABY"]
[Sun Aug 30 03:10:35.586359 2026] [authz_core:error] [pid 515259:tid 515421] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:35.586807 2026] [authz_core:error] [pid 515259:tid 515421] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:35.595670 2026] [security2:error] [pid 515259:tid 515437] [client 40.83.93.50:22115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/gg.php"] [unique_id "apPle2ZcVaai59truiV5xAAAAC8"]
[Sun Aug 30 03:10:35.602473 2026] [security2:error] [pid 515259:tid 515501] [client 4.205.62.107:17325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/myfile.php"] [unique_id "apPle2ZcVaai59truiV5xwAAAG8"]
[Sun Aug 30 03:10:35.613014 2026] [security2:error] [pid 515259:tid 515485] [client 20.48.251.3:59371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/setup-config.php"] [unique_id "apPle2ZcVaai59truiV5yQAAAF8"]
[Sun Aug 30 03:10:35.624438 2026] [security2:error] [pid 515259:tid 515487] [client 34.130.99.179:52106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/phpinfo.php.save"] [unique_id "apPle2ZcVaai59truiV5zgAAAGE"]
[Sun Aug 30 03:10:35.682511 2026] [security2:error] [pid 515259:tid 515402] [client 4.205.62.107:25728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/autogooey.php"] [unique_id "apPle2ZcVaai59truiV51wAAAAw"]
[Sun Aug 30 03:10:35.683815 2026] [security2:error] [pid 515259:tid 515498] [client 20.104.104.62:65238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPle2ZcVaai59truiV52QAAAGw"]
[Sun Aug 30 03:10:35.704521 2026] [core:alert] [pid 515259:tid 515395] [client 5.1.110.94:40068] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:10:35.712456 2026] [security2:error] [pid 515259:tid 515497] [client 4.205.62.107:36725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/environment.php"] [unique_id "apPle2ZcVaai59truiV54AAAAGs"]
[Sun Aug 30 03:10:35.729154 2026] [authz_core:error] [pid 515259:tid 515420] [client 66.249.66.65:36140] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:35.729426 2026] [authz_core:error] [pid 515259:tid 515420] [client 66.249.66.65:36140] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:35.732211 2026] [security2:error] [pid 515259:tid 515410] [client 20.220.10.235:34851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.iamthevoiceofonecallinginthewilderness.com"] [uri "/waf.php"] [unique_id "apPle2ZcVaai59truiV54wAAABQ"]
[Sun Aug 30 03:10:35.748902 2026] [security2:error] [pid 515259:tid 515472] [client 20.63.219.114:2552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/default.php"] [unique_id "apPle2ZcVaai59truiV56wAAAFI"]
[Sun Aug 30 03:10:35.751639 2026] [security2:error] [pid 515259:tid 515494] [client 158.23.147.79:43845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/x/index.php"] [unique_id "apPle2ZcVaai59truiV57AAAAGg"]
[Sun Aug 30 03:10:35.758664 2026] [authz_core:error] [pid 515259:tid 515442] [client 216.73.216.128:51580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:35.759130 2026] [authz_core:error] [pid 515259:tid 515442] [client 216.73.216.128:51580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:35.766384 2026] [security2:error] [pid 515259:tid 515413] [client 20.48.251.3:59862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/lm15.php"] [unique_id "apPle2ZcVaai59truiV58wAAABc"]
[Sun Aug 30 03:10:35.772663 2026] [security2:error] [pid 515259:tid 515397] [client 20.104.50.220:51392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/p.php"] [unique_id "apPle2ZcVaai59truiV59wAAAAc"]
[Sun Aug 30 03:10:35.792556 2026] [security2:error] [pid 515259:tid 515437] [client 20.104.18.15:16984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/504.php"] [unique_id "apPle2ZcVaai59truiV6AAAAAC8"]
[Sun Aug 30 03:10:35.817672 2026] [security2:error] [pid 515259:tid 515515] [client 20.104.104.62:62924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillebiblechurch.com"] [uri "/waf.php"] [unique_id "apPle2ZcVaai59truiV6AgAAAH0"]
[Sun Aug 30 03:10:35.822183 2026] [security2:error] [pid 515259:tid 515432] [client 34.130.99.179:52110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/staging/phpinfo.php"] [unique_id "apPle2ZcVaai59truiV6AwAAACo"]
[Sun Aug 30 03:10:35.849847 2026] [authz_core:error] [pid 515259:tid 515435] [client 66.249.66.43:65020] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:35.850150 2026] [authz_core:error] [pid 515259:tid 515435] [client 66.249.66.43:65020] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:35.872072 2026] [security2:error] [pid 515259:tid 515481] [client 20.104.49.130:53569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/wp-login.php"] [unique_id "apPle2ZcVaai59truiV6BAAAAFs"]
[Sun Aug 30 03:10:35.936335 2026] [security2:error] [pid 515259:tid 515503] [client 20.104.50.220:63042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/ea.php"] [unique_id "apPle2ZcVaai59truiV6HgAAAHE"]
[Sun Aug 30 03:10:35.964417 2026] [security2:error] [pid 515259:tid 515450] [client 20.197.61.180:3164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/theme-check/theme-check.php"] [unique_id "apPle2ZcVaai59truiV6JAAAADw"]
[Sun Aug 30 03:10:35.965014 2026] [authz_core:error] [pid 515259:tid 515384] [remote 216.73.217.178:64946] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:35.965398 2026] [authz_core:error] [pid 515259:tid 515384] [remote 216.73.217.178:64946] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:35.967305 2026] [security2:error] [pid 515259:tid 515513] [client 20.48.251.3:13957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/test1.php"] [unique_id "apPle2ZcVaai59truiV6JwAAAHs"]
[Sun Aug 30 03:10:35.978528 2026] [security2:error] [pid 515259:tid 515412] [client 68.155.159.216:62632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/lock.php"] [unique_id "apPle2ZcVaai59truiV6LAAAABY"]
[Sun Aug 30 03:10:36.013007 2026] [security2:error] [pid 515259:tid 515482] [client 20.104.50.220:62807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/celeng.php"] [unique_id "apPlfGZcVaai59truiV6NQAAAFw"]
[Sun Aug 30 03:10:36.013155 2026] [security2:error] [pid 515259:tid 515411] [client 34.130.99.179:52126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/beta/phpinfo.php"] [unique_id "apPlfGZcVaai59truiV6NgAAABU"]
[Sun Aug 30 03:10:36.056956 2026] [security2:error] [pid 515259:tid 515487] [client 20.104.49.130:57689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/155.php"] [unique_id "apPlfGZcVaai59truiV6QgAAAGE"]
[Sun Aug 30 03:10:36.078485 2026] [security2:error] [pid 515259:tid 515392] [client 20.104.49.130:63537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/static.php"] [unique_id "apPlfGZcVaai59truiV6TQAAAAI"]
[Sun Aug 30 03:10:36.085436 2026] [authz_core:error] [pid 515259:tid 515476] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:36.085714 2026] [authz_core:error] [pid 515259:tid 515476] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:36.090313 2026] [security2:error] [pid 515259:tid 515495] [client 20.104.18.15:18339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/one.php"] [unique_id "apPlfGZcVaai59truiV6VQAAAGk"]
[Sun Aug 30 03:10:36.096990 2026] [security2:error] [pid 515259:tid 515502] [client 40.83.93.50:6568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/defaults.php"] [unique_id "apPlfGZcVaai59truiV6VwAAAHA"]
[Sun Aug 30 03:10:36.108921 2026] [security2:error] [pid 515259:tid 515478] [client 20.104.18.15:22456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/biufile.php"] [unique_id "apPlfGZcVaai59truiV6XAAAAFg"]
[Sun Aug 30 03:10:36.125480 2026] [authz_core:error] [pid 515259:tid 515444] [client 216.73.216.128:31067] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:36.125968 2026] [authz_core:error] [pid 515259:tid 515444] [client 216.73.216.128:31067] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:36.151355 2026] [authz_core:error] [pid 515259:tid 515450] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:36.151628 2026] [authz_core:error] [pid 515259:tid 515450] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:36.159565 2026] [security2:error] [pid 515259:tid 515449] [client 4.205.62.107:58490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/tax.php"] [unique_id "apPlfGZcVaai59truiV6ZwAAADs"]
[Sun Aug 30 03:10:36.226044 2026] [security2:error] [pid 515259:tid 515453] [client 20.104.50.220:5627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/mass.php"] [unique_id "apPlfGZcVaai59truiV6cwAAAD8"]
[Sun Aug 30 03:10:36.228799 2026] [security2:error] [pid 515259:tid 515506] [client 68.155.159.216:45825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/.well-knownold/index.php"] [unique_id "apPlfGZcVaai59truiV6dAAAAHQ"]
[Sun Aug 30 03:10:36.229106 2026] [security2:error] [pid 515259:tid 515487] [client 20.104.50.220:42435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/images/shell.php"] [unique_id "apPlfGZcVaai59truiV6dgAAAGE"]
[Sun Aug 30 03:10:36.229952 2026] [security2:error] [pid 515259:tid 515475] [client 34.130.99.179:52138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/uat/phpinfo.php"] [unique_id "apPlfGZcVaai59truiV6dwAAAFU"]
[Sun Aug 30 03:10:36.302737 2026] [authz_core:error] [pid 515259:tid 515408] [client 66.249.66.203:57566] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:36.303223 2026] [authz_core:error] [pid 515259:tid 515408] [client 66.249.66.203:57566] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:36.352718 2026] [security2:error] [pid 515259:tid 515409] [client 20.104.50.220:32952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/images/mar.php"] [unique_id "apPlfGZcVaai59truiV6jAAAABM"]
[Sun Aug 30 03:10:36.355694 2026] [security2:error] [pid 515259:tid 515418] [client 20.63.219.114:15877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/cloud.php"] [unique_id "apPlfGZcVaai59truiV6jQAAABw"]
[Sun Aug 30 03:10:36.420307 2026] [security2:error] [pid 515259:tid 515400] [client 20.48.251.3:54784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/application.config.php"] [unique_id "apPlfGZcVaai59truiV6lAAAAAo"]
[Sun Aug 30 03:10:36.425458 2026] [authz_core:error] [pid 515259:tid 515479] [client 66.249.66.204:40022] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:36.425899 2026] [authz_core:error] [pid 515259:tid 515479] [client 66.249.66.204:40022] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:36.455705 2026] [security2:error] [pid 515259:tid 515446] [client 34.130.99.179:52142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/qa/phpinfo.php"] [unique_id "apPlfGZcVaai59truiV6lwAAADg"]
[Sun Aug 30 03:10:36.568771 2026] [security2:error] [pid 515259:tid 515489] [client 20.104.18.15:43307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/manga.php"] [unique_id "apPlfGZcVaai59truiV6mgAAAGM"]
[Sun Aug 30 03:10:36.596870 2026] [security2:error] [pid 515259:tid 515476] [client 20.104.50.220:61991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/twin.php"] [unique_id "apPlfGZcVaai59truiV6nAAAAFY"]
[Sun Aug 30 03:10:36.601157 2026] [security2:error] [pid 515259:tid 515419] [client 20.104.49.130:52113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/xa.php"] [unique_id "apPlfGZcVaai59truiV6ngAAAB0"]
[Sun Aug 30 03:10:36.603051 2026] [authz_core:error] [pid 515259:tid 515498] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:36.603323 2026] [authz_core:error] [pid 515259:tid 515498] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:36.622441 2026] [security2:error] [pid 515259:tid 515433] [client 40.83.93.50:10526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/h.php"] [unique_id "apPlfGZcVaai59truiV6nwAAACs"]
[Sun Aug 30 03:10:36.632110 2026] [security2:error] [pid 515259:tid 515467] [client 158.23.147.79:52240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apPlfGZcVaai59truiV6oAAAAE0"]
[Sun Aug 30 03:10:36.655817 2026] [security2:error] [pid 515259:tid 515490] [client 34.130.99.179:52158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/preview/phpinfo.php"] [unique_id "apPlfGZcVaai59truiV6oQAAAGQ"]
[Sun Aug 30 03:10:36.668387 2026] [security2:error] [pid 515259:tid 515511] [client 20.104.50.220:17003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/alfa.php"] [unique_id "apPlfGZcVaai59truiV6pAAAAHk"]
[Sun Aug 30 03:10:36.668794 2026] [security2:error] [pid 515259:tid 515447] [client 20.197.61.180:15744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/theme/about.php"] [unique_id "apPlfGZcVaai59truiV6pQAAADk"]
[Sun Aug 30 03:10:36.677756 2026] [security2:error] [pid 515259:tid 515510] [client 20.104.18.15:64773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/info.php/new.php"] [unique_id "apPlfGZcVaai59truiV6qAAAAHg"]
[Sun Aug 30 03:10:36.752564 2026] [security2:error] [pid 515259:tid 515458] [client 20.48.251.3:52847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/wp-admin/sc.php"] [unique_id "apPlfGZcVaai59truiV6qwAAAEQ"]
[Sun Aug 30 03:10:36.755021 2026] [security2:error] [pid 515259:tid 515425] [client 20.63.219.114:15243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/admin.php"] [unique_id "apPlfGZcVaai59truiV6rAAAACM"]
[Sun Aug 30 03:10:36.767709 2026] [security2:error] [pid 515259:tid 515466] [client 4.205.62.107:17675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/lm15.php"] [unique_id "apPlfGZcVaai59truiV6rgAAAEw"]
[Sun Aug 30 03:10:36.772589 2026] [authz_core:error] [pid 515259:tid 515477] [client 216.73.216.128:31067] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:36.773049 2026] [authz_core:error] [pid 515259:tid 515477] [client 216.73.216.128:31067] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:36.816891 2026] [security2:error] [pid 515259:tid 515269] [remote 50.6.200.195:37502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.200.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ucdsafetysystems.com"] [uri "/wp-login.php"] [unique_id "apPlfGZcVaai59truiV6sQAAKAg"]
[Sun Aug 30 03:10:36.840395 2026] [security2:error] [pid 515259:tid 515492] [client 34.130.99.179:54926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/www/phpinfo.php"] [unique_id "apPlfGZcVaai59truiV6tAAAAGY"]
[Sun Aug 30 03:10:36.859783 2026] [authz_core:error] [pid 515259:tid 515474] [client 216.73.216.128:2664] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:36.860062 2026] [authz_core:error] [pid 515259:tid 515474] [client 216.73.216.128:2664] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:36.906024 2026] [security2:error] [pid 515259:tid 515456] [client 20.48.251.3:52184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/test.config.php"] [unique_id "apPlfGZcVaai59truiV6uQAAAEI"]
[Sun Aug 30 03:10:36.952402 2026] [security2:error] [pid 515259:tid 515451] [client 20.104.18.15:17021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/admin.php"] [unique_id "apPlfGZcVaai59truiV6vQAAAD0"]
[Sun Aug 30 03:10:36.955829 2026] [security2:error] [pid 515259:tid 515405] [client 4.205.62.107:36731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/aws_secret_config.php"] [unique_id "apPlfGZcVaai59truiV6vgAAAA8"]
[Sun Aug 30 03:10:36.967930 2026] [security2:error] [pid 515259:tid 515421] [client 4.205.62.107:25904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/sdsa.php"] [unique_id "apPlfGZcVaai59truiV6vwAAAB8"]
[Sun Aug 30 03:10:37.022569 2026] [security2:error] [pid 515259:tid 515400] [client 20.151.200.44:41878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/log.php"] [unique_id "apPlfWZcVaai59truiV6xgAAAAo"]
[Sun Aug 30 03:10:37.027251 2026] [security2:error] [pid 515259:tid 515397] [client 34.130.99.179:54938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/htdocs/phpinfo.php"] [unique_id "apPlfWZcVaai59truiV6yAAAAAc"]
[Sun Aug 30 03:10:37.041098 2026] [security2:error] [pid 515259:tid 515506] [client 20.104.50.220:63196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/bthil.php"] [unique_id "apPlfWZcVaai59truiV6ygAAAHQ"]
[Sun Aug 30 03:10:37.079780 2026] [authz_core:error] [pid 515259:tid 515516] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:37.080196 2026] [authz_core:error] [pid 515259:tid 515516] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:37.092017 2026] [security2:error] [pid 515259:tid 515277] [remote 50.6.200.195:37502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.200.6.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ucdsafetysystems.com"] [uri "/wp-login.php"] [unique_id "apPlfWZcVaai59truiV6zwAAYBA"], referer: https://ucdsafetysystems.com/wp-login.php
[Sun Aug 30 03:10:37.092081 2026] [security2:error] [pid 515259:tid 515439] [client 20.104.50.220:62799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/aaaa.php"] [unique_id "apPlfWZcVaai59truiV6zgAAADE"]
[Sun Aug 30 03:10:37.100300 2026] [security2:error] [pid 515259:tid 515398] [client 68.155.159.216:63291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/index/function.php"] [unique_id "apPlfWZcVaai59truiV60AAAAAg"]
[Sun Aug 30 03:10:37.103653 2026] [security2:error] [pid 515259:tid 515420] [client 20.48.251.3:13431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/bigdump.php"] [unique_id "apPlfWZcVaai59truiV60QAAAB4"]
[Sun Aug 30 03:10:37.107214 2026] [security2:error] [pid 515259:tid 515495] [client 40.83.93.50:6529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/num.php"] [unique_id "apPlfWZcVaai59truiV60gAAAGk"]
[Sun Aug 30 03:10:37.137161 2026] [security2:error] [pid 515259:tid 515491] [client 20.63.219.114:15226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/index.php"] [unique_id "apPlfWZcVaai59truiV61QAAAGU"]
[Sun Aug 30 03:10:37.152513 2026] [authz_core:error] [pid 515259:tid 515392] [client 66.249.66.36:42841] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:37.152885 2026] [authz_core:error] [pid 515259:tid 515392] [client 66.249.66.36:42841] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:37.157038 2026] [security2:error] [pid 515259:tid 515511] [client 20.104.50.220:62836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/bypassing.php"] [unique_id "apPlfWZcVaai59truiV61wAAAHk"]
[Sun Aug 30 03:10:37.237887 2026] [security2:error] [pid 515259:tid 515441] [client 20.104.18.15:18316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/503.php"] [unique_id "apPlfWZcVaai59truiV62QAAADM"]
[Sun Aug 30 03:10:37.245492 2026] [security2:error] [pid 515259:tid 515431] [client 34.130.99.179:54942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/public_html/phpinfo.php"] [unique_id "apPlfWZcVaai59truiV62gAAACk"]
[Sun Aug 30 03:10:37.247036 2026] [security2:error] [pid 515259:tid 515434] [client 20.104.18.15:22487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/blacks.php"] [unique_id "apPlfWZcVaai59truiV62wAAACw"]
[Sun Aug 30 03:10:37.282539 2026] [security2:error] [pid 515259:tid 515458] [client 158.23.147.79:2011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-admin/user/index.php"] [unique_id "apPlfWZcVaai59truiV63wAAAEQ"]
[Sun Aug 30 03:10:37.297504 2026] [security2:error] [pid 515259:tid 515478] [client 4.205.62.107:64449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPlfWZcVaai59truiV64QAAAFg"]
[Sun Aug 30 03:10:37.366665 2026] [security2:error] [pid 515259:tid 515494] [client 20.104.50.220:63542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/images/mini.php"] [unique_id "apPlfWZcVaai59truiV65AAAAGg"]
[Sun Aug 30 03:10:37.381534 2026] [security2:error] [pid 515259:tid 515497] [client 20.104.50.220:5585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/digi.php"] [unique_id "apPlfWZcVaai59truiV65QAAAGs"]
[Sun Aug 30 03:10:37.388640 2026] [security2:error] [pid 515259:tid 515472] [client 20.151.200.44:40915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/wp-access.php"] [unique_id "apPlfWZcVaai59truiV65gAAAFI"]
[Sun Aug 30 03:10:37.391549 2026] [security2:error] [pid 515259:tid 515484] [client 20.197.61.180:16885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/theme/min.php"] [unique_id "apPlfWZcVaai59truiV65wAAAF4"]
[Sun Aug 30 03:10:37.409214 2026] [security2:error] [pid 515259:tid 515451] [client 151.240.53.33:30881] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "paulgarrigan.com"] [uri "/"] [unique_id "apPlfWZcVaai59truiV66gAAAD0"]
[Sun Aug 30 03:10:37.436862 2026] [security2:error] [pid 515259:tid 515479] [client 34.130.99.179:54954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/site/phpinfo.php"] [unique_id "apPlfWZcVaai59truiV66wAAAFk"]
[Sun Aug 30 03:10:37.455466 2026] [security2:error] [pid 515259:tid 515509] [client 158.23.147.79:43872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apPlfWZcVaai59truiV67AAAAHc"]
[Sun Aug 30 03:10:37.492323 2026] [security2:error] [pid 515259:tid 515432] [client 20.104.50.220:33555] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.icanto.com"] [uri "/images/1.php"] [unique_id "apPlfWZcVaai59truiV67wAAACo"]
[Sun Aug 30 03:10:37.492452 2026] [security2:error] [pid 515259:tid 515432] [client 20.104.50.220:33555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/images/1.php"] [unique_id "apPlfWZcVaai59truiV67wAAACo"]
[Sun Aug 30 03:10:37.510195 2026] [security2:error] [pid 515259:tid 515474] [client 68.155.159.216:45942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apPlfWZcVaai59truiV68AAAAFQ"]
[Sun Aug 30 03:10:37.567912 2026] [security2:error] [pid 515259:tid 515420] [client 20.48.251.3:64291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/xp.php"] [unique_id "apPlfWZcVaai59truiV69wAAAB4"]
[Sun Aug 30 03:10:37.589083 2026] [authz_core:error] [pid 515259:tid 515495] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:37.589573 2026] [authz_core:error] [pid 515259:tid 515495] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:37.601446 2026] [security2:error] [pid 515259:tid 515414] [client 20.63.219.114:19186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/php8.php"] [unique_id "apPlfWZcVaai59truiV6-gAAABg"]
[Sun Aug 30 03:10:37.619347 2026] [authz_core:error] [pid 515259:tid 515517] [client 66.249.66.44:64311] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:37.619667 2026] [authz_core:error] [pid 515259:tid 515517] [client 66.249.66.44:64311] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:37.639330 2026] [core:alert] [pid 515259:tid 515491] [client 191.242.195.127:27008] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:10:37.651067 2026] [security2:error] [pid 515259:tid 515409] [client 40.83.93.50:6579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/abc.php"] [unique_id "apPlfWZcVaai59truiV6_gAAABM"]
[Sun Aug 30 03:10:37.664837 2026] [security2:error] [pid 515259:tid 515419] [client 34.130.99.179:54968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/docs/phpinfo.php"] [unique_id "apPlfWZcVaai59truiV7AgAAAB0"]
[Sun Aug 30 03:10:37.668907 2026] [authz_core:error] [pid 515259:tid 515453] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:37.669195 2026] [authz_core:error] [pid 515259:tid 515453] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:37.677991 2026] [authz_core:error] [pid 515259:tid 515393] [client 66.249.66.206:50689] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:37.678264 2026] [authz_core:error] [pid 515259:tid 515393] [client 66.249.66.206:50689] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:37.678874 2026] [authz_core:error] [pid 515259:tid 515511] [client 216.73.216.128:2664] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:37.679378 2026] [authz_core:error] [pid 515259:tid 515511] [client 216.73.216.128:2664] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:37.723032 2026] [security2:error] [pid 515259:tid 515431] [client 20.104.18.15:43960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/asdfghj.php"] [unique_id "apPlfWZcVaai59truiV7DgAAACk"]
[Sun Aug 30 03:10:37.806429 2026] [security2:error] [pid 515259:tid 515478] [client 20.104.50.220:17272] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/1.php"] [unique_id "apPlfWZcVaai59truiV7FAAAAFg"]
[Sun Aug 30 03:10:37.806589 2026] [security2:error] [pid 515259:tid 515478] [client 20.104.50.220:17272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/1.php"] [unique_id "apPlfWZcVaai59truiV7FAAAAFg"]
[Sun Aug 30 03:10:37.817209 2026] [security2:error] [pid 515259:tid 515412] [client 20.104.50.220:59580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/upload.php"] [unique_id "apPlfWZcVaai59truiV7FgAAABY"]
[Sun Aug 30 03:10:37.821431 2026] [security2:error] [pid 515259:tid 515399] [client 20.104.18.15:16697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/db.php/new.php"] [unique_id "apPlfWZcVaai59truiV7GAAAAAk"]
[Sun Aug 30 03:10:37.855268 2026] [security2:error] [pid 515259:tid 515497] [client 216.73.216.128:31067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/usage_202601.html"] [unique_id "apPlfWZcVaai59truiV7GQAAAGs"]
[Sun Aug 30 03:10:37.876226 2026] [core:alert] [pid 515259:tid 515498] [client 179.42.170.36:49340] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:10:37.886021 2026] [security2:error] [pid 515259:tid 515415] [client 20.48.251.3:59322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/debug.php"] [unique_id "apPlfWZcVaai59truiV7GwAAABk"]
[Sun Aug 30 03:10:37.894158 2026] [security2:error] [pid 515259:tid 515470] [client 34.130.99.179:54978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "apPlfWZcVaai59truiV7HAAAAFA"]
[Sun Aug 30 03:10:37.899913 2026] [security2:error] [pid 515259:tid 515448] [client 4.205.62.107:17292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/test.config.php"] [unique_id "apPlfWZcVaai59truiV7HQAAADo"]
[Sun Aug 30 03:10:38.040568 2026] [security2:error] [pid 515259:tid 515486] [client 20.151.200.44:65354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/attack.php"] [unique_id "apPlfmZcVaai59truiV7IgAAAGA"]
[Sun Aug 30 03:10:38.059204 2026] [security2:error] [pid 515259:tid 515435] [client 20.48.251.3:52249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/gecko-litespeed.php"] [unique_id "apPlfmZcVaai59truiV7IwAAAC0"]
[Sun Aug 30 03:10:38.086586 2026] [authz_core:error] [pid 515259:tid 515390] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:38.086906 2026] [authz_core:error] [pid 515259:tid 515390] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:38.090720 2026] [security2:error] [pid 515259:tid 515421] [client 20.63.219.114:15201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/function.php"] [unique_id "apPlfmZcVaai59truiV7JQAAAB8"]
[Sun Aug 30 03:10:38.091979 2026] [security2:error] [pid 515259:tid 515472] [client 20.197.61.180:16856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/themes/about.php"] [unique_id "apPlfmZcVaai59truiV7JgAAAFI"]
[Sun Aug 30 03:10:38.095392 2026] [security2:error] [pid 515259:tid 515467] [client 20.104.18.15:16937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/ws85.php"] [unique_id "apPlfmZcVaai59truiV7JwAAAE0"]
[Sun Aug 30 03:10:38.096359 2026] [security2:error] [pid 515259:tid 515474] [client 34.130.99.179:54982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/administrator/phpinfo.php"] [unique_id "apPlfmZcVaai59truiV7KAAAAFQ"]
[Sun Aug 30 03:10:38.122171 2026] [security2:error] [pid 515259:tid 515432] [client 40.83.93.50:22124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/default.php"] [unique_id "apPlfmZcVaai59truiV7KgAAACo"]
[Sun Aug 30 03:10:38.161182 2026] [security2:error] [pid 515259:tid 515394] [client 4.205.62.107:26957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/sale.php"] [unique_id "apPlfmZcVaai59truiV7LQAAAAQ"]
[Sun Aug 30 03:10:38.179287 2026] [security2:error] [pid 515259:tid 515396] [client 20.104.50.220:31515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/7.php"] [unique_id "apPlfmZcVaai59truiV7LwAAAAY"]
[Sun Aug 30 03:10:38.186467 2026] [security2:error] [pid 515259:tid 515464] [client 4.205.62.107:36718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/snq.php"] [unique_id "apPlfmZcVaai59truiV7MAAAAEo"]
[Sun Aug 30 03:10:38.225522 2026] [authz_core:error] [pid 515259:tid 515438] [client 216.73.216.128:55788] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:38.225796 2026] [authz_core:error] [pid 515259:tid 515438] [client 216.73.216.128:55788] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:38.231513 2026] [security2:error] [pid 515259:tid 515418] [client 20.104.50.220:62788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/cinfo.php"] [unique_id "apPlfmZcVaai59truiV7MwAAABw"]
[Sun Aug 30 03:10:38.251653 2026] [security2:error] [pid 515259:tid 515513] [client 68.155.159.216:62602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/.well-known/content.php"] [unique_id "apPlfmZcVaai59truiV7NwAAAHs"]
[Sun Aug 30 03:10:38.258520 2026] [security2:error] [pid 515259:tid 515480] [client 20.104.49.130:63523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/crgio.php"] [unique_id "apPlfmZcVaai59truiV7OAAAAFo"]
[Sun Aug 30 03:10:38.284302 2026] [authz_core:error] [pid 515259:tid 515457] [client 66.249.66.67:46837] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:38.284570 2026] [authz_core:error] [pid 515259:tid 515457] [client 66.249.66.67:46837] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:38.288678 2026] [security2:error] [pid 515259:tid 515492] [client 20.48.251.3:56379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/wdf.php"] [unique_id "apPlfmZcVaai59truiV7PAAAAGY"]
[Sun Aug 30 03:10:38.296334 2026] [security2:error] [pid 515259:tid 515459] [client 34.130.99.179:54998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/core/phpinfo.php"] [unique_id "apPlfmZcVaai59truiV7PgAAAEU"]
[Sun Aug 30 03:10:38.310553 2026] [security2:error] [pid 515259:tid 515481] [client 20.104.50.220:28702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/bypshell.php"] [unique_id "apPlfmZcVaai59truiV7QQAAAFs"]
[Sun Aug 30 03:10:38.352174 2026] [security2:error] [pid 515259:tid 515468] [client 158.23.147.79:16330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apPlfmZcVaai59truiV7QgAAAE4"]
[Sun Aug 30 03:10:38.382054 2026] [security2:error] [pid 515259:tid 515504] [client 114.119.157.33:62367] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.americanqualityhomeinspections.com"] [uri "/wp-content/uploads/2017/01/deal-breakers-home-inspection-1.jpg"] [unique_id "apPlfmZcVaai59truiV7RQAAAHI"], referer: http://www.americanqualityhomeinspections.com/certifications-4
[Sun Aug 30 03:10:38.398299 2026] [security2:error] [pid 515259:tid 515403] [client 20.104.18.15:22444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/beck.php"] [unique_id "apPlfmZcVaai59truiV7SAAAAA0"]
[Sun Aug 30 03:10:38.442681 2026] [security2:error] [pid 515259:tid 515486] [client 20.104.49.130:45156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/one.php"] [unique_id "apPlfmZcVaai59truiV7TAAAAGA"]
[Sun Aug 30 03:10:38.454966 2026] [security2:error] [pid 515259:tid 515420] [client 4.205.62.107:61805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPlfmZcVaai59truiV7TgAAAB4"]
[Sun Aug 30 03:10:38.456418 2026] [core:alert] [pid 515259:tid 515496] [client 36.50.23.2:41948] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:10:38.461436 2026] [authz_core:error] [pid 515259:tid 515433] [client 66.249.66.202:44959] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:38.461725 2026] [authz_core:error] [pid 515259:tid 515433] [client 66.249.66.202:44959] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:38.499089 2026] [security2:error] [pid 515259:tid 515454] [client 20.104.18.15:18378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/504.php"] [unique_id "apPlfmZcVaai59truiV7UQAAAEA"]
[Sun Aug 30 03:10:38.504260 2026] [security2:error] [pid 515259:tid 515435] [client 20.104.50.220:51595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/images/mar.php"] [unique_id "apPlfmZcVaai59truiV7UgAAAC0"]
[Sun Aug 30 03:10:38.538943 2026] [security2:error] [pid 515259:tid 515450] [client 34.130.99.179:55014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.99.130.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pisaderesistance.com"] [uri "/includes/phpinfo.php"] [unique_id "apPlfmZcVaai59truiV7VAAAADw"]
[Sun Aug 30 03:10:38.548310 2026] [security2:error] [pid 515259:tid 515483] [client 20.63.219.114:15669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/about.php"] [unique_id "apPlfmZcVaai59truiV7VQAAAF0"]
[Sun Aug 30 03:10:38.552828 2026] [security2:error] [pid 515259:tid 515472] [client 20.104.50.220:6116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/indoxploit.php"] [unique_id "apPlfmZcVaai59truiV7VgAAAFI"]
[Sun Aug 30 03:10:38.562595 2026] [security2:error] [pid 515259:tid 515467] [client 158.23.147.79:43851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-login.php"] [unique_id "apPlfmZcVaai59truiV7VwAAAE0"]
[Sun Aug 30 03:10:38.598971 2026] [authz_core:error] [pid 515259:tid 515414] [client 66.249.66.41:43047] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:38.599260 2026] [authz_core:error] [pid 515259:tid 515414] [client 66.249.66.41:43047] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:38.613435 2026] [security2:error] [pid 515259:tid 515398] [client 40.83.93.50:6550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/cloud.php"] [unique_id "apPlfmZcVaai59truiV7XgAAAAg"]
[Sun Aug 30 03:10:38.621686 2026] [authz_core:error] [pid 515259:tid 515396] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:38.621953 2026] [authz_core:error] [pid 515259:tid 515396] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:38.626419 2026] [security2:error] [pid 515259:tid 515464] [client 158.23.147.79:1933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-includes/plugins.php"] [unique_id "apPlfmZcVaai59truiV7YAAAAEo"]
[Sun Aug 30 03:10:38.634484 2026] [security2:error] [pid 515259:tid 515423] [client 20.104.50.220:33155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/imageswp-init.php"] [unique_id "apPlfmZcVaai59truiV7YgAAACE"]
[Sun Aug 30 03:10:38.640495 2026] [security2:error] [pid 515259:tid 515434] [client 20.151.200.44:40943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/wp-content/admin.php"] [unique_id "apPlfmZcVaai59truiV7ZAAAACw"]
[Sun Aug 30 03:10:38.680820 2026] [authz_core:error] [pid 515259:tid 515439] [client 216.73.216.128:2664] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:38.681074 2026] [authz_core:error] [pid 515259:tid 515439] [client 216.73.216.128:2664] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:38.688758 2026] [security2:error] [pid 515259:tid 515444] [client 20.104.49.130:57685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/fs.php"] [unique_id "apPlfmZcVaai59truiV7ZwAAADY"]
[Sun Aug 30 03:10:38.705627 2026] [security2:error] [pid 515259:tid 515412] [client 20.48.251.3:54810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/g3.php"] [unique_id "apPlfmZcVaai59truiV7aAAAABY"]
[Sun Aug 30 03:10:38.716895 2026] [security2:error] [pid 515259:tid 515480] [client 68.155.159.216:46007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPlfmZcVaai59truiV7aQAAAFo"]
[Sun Aug 30 03:10:38.774642 2026] [authz_core:error] [pid 515259:tid 515413] [client 216.73.216.128:55788] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:38.774958 2026] [authz_core:error] [pid 515259:tid 515413] [client 216.73.216.128:55788] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:38.813465 2026] [security2:error] [pid 515259:tid 515426] [client 20.197.61.180:12266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/themes/panel.php"] [unique_id "apPlfmZcVaai59truiV7bQAAACQ"]
[Sun Aug 30 03:10:38.838817 2026] [security2:error] [pid 515259:tid 515402] [client 158.23.147.79:52229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apPlfmZcVaai59truiV7bgAAAAw"]
[Sun Aug 30 03:10:38.849809 2026] [security2:error] [pid 515259:tid 515508] [client 20.104.18.15:43863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/dragonshell.php"] [unique_id "apPlfmZcVaai59truiV7cAAAAHY"]
[Sun Aug 30 03:10:38.925571 2026] [security2:error] [pid 515259:tid 515395] [client 20.151.200.44:28664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/wp-the.php"] [unique_id "apPlfmZcVaai59truiV7eQAAAAU"]
[Sun Aug 30 03:10:38.942127 2026] [authz_core:error] [pid 515259:tid 515462] [client 66.249.66.78:58265] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:38.942396 2026] [authz_core:error] [pid 515259:tid 515462] [client 66.249.66.78:58265] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:38.943586 2026] [security2:error] [pid 515259:tid 515463] [client 20.104.50.220:16654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/byp.php"] [unique_id "apPlfmZcVaai59truiV7ewAAAEk"]
[Sun Aug 30 03:10:38.971664 2026] [security2:error] [pid 515259:tid 515501] [client 20.104.18.15:64071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/kuda.php"] [unique_id "apPlfmZcVaai59truiV7fgAAAG8"]
[Sun Aug 30 03:10:39.002112 2026] [security2:error] [pid 515259:tid 515488] [client 20.104.49.130:64115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/33.php"] [unique_id "apPlf2ZcVaai59truiV7fwAAAGI"]
[Sun Aug 30 03:10:39.012305 2026] [security2:error] [pid 515259:tid 515404] [client 158.23.147.79:61973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-admin/images/about.php"] [unique_id "apPlf2ZcVaai59truiV7gwAAAA4"]
[Sun Aug 30 03:10:39.025709 2026] [authz_core:error] [pid 515259:tid 515454] [client 66.249.66.40:59708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:39.025973 2026] [authz_core:error] [pid 515259:tid 515454] [client 66.249.66.40:59708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:39.027095 2026] [security2:error] [pid 515259:tid 515485] [client 20.48.251.3:59265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/nzv.php"] [unique_id "apPlf2ZcVaai59truiV7hgAAAF8"]
[Sun Aug 30 03:10:39.036606 2026] [security2:error] [pid 515259:tid 515424] [client 4.205.62.107:17338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/gecko-litespeed.php"] [unique_id "apPlf2ZcVaai59truiV7iQAAACI"]
[Sun Aug 30 03:10:39.046154 2026] [security2:error] [pid 515259:tid 515511] [client 20.63.219.114:15651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/new.php"] [unique_id "apPlf2ZcVaai59truiV7iwAAAHk"]
[Sun Aug 30 03:10:39.087468 2026] [authz_core:error] [pid 515259:tid 515421] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:39.088181 2026] [authz_core:error] [pid 515259:tid 515421] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:39.094534 2026] [security2:error] [pid 515259:tid 515500] [client 20.104.50.220:62012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/ups.php"] [unique_id "apPlf2ZcVaai59truiV7kQAAAG4"]
[Sun Aug 30 03:10:39.151417 2026] [security2:error] [pid 515259:tid 515510] [client 40.83.93.50:6175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/admin.php"] [unique_id "apPlf2ZcVaai59truiV7owAAAHg"]
[Sun Aug 30 03:10:39.181215 2026] [authz_core:error] [pid 515259:tid 515439] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:39.181476 2026] [authz_core:error] [pid 515259:tid 515439] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:39.192870 2026] [authz_core:error] [pid 515259:tid 515456] [client 66.249.66.206:43097] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:39.193307 2026] [authz_core:error] [pid 515259:tid 515456] [client 66.249.66.206:43097] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:39.199134 2026] [security2:error] [pid 515259:tid 515478] [client 20.48.251.3:59502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/goods.php"] [unique_id "apPlf2ZcVaai59truiV7qQAAAFg"]
[Sun Aug 30 03:10:39.230904 2026] [security2:error] [pid 515259:tid 515461] [client 20.104.18.15:16962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/ffs.php"] [unique_id "apPlf2ZcVaai59truiV7rQAAAEc"]
[Sun Aug 30 03:10:39.263904 2026] [security2:error] [pid 515259:tid 515498] [client 158.23.147.79:52250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPlf2ZcVaai59truiV7tgAAAGw"]
[Sun Aug 30 03:10:39.296291 2026] [security2:error] [pid 515259:tid 515496] [client 4.205.62.107:25857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/wp-class.php"] [unique_id "apPlf2ZcVaai59truiV7uwAAAGo"]
[Sun Aug 30 03:10:39.315116 2026] [security2:error] [pid 515259:tid 515467] [client 4.205.62.107:36563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/wp-access.php"] [unique_id "apPlf2ZcVaai59truiV7vgAAAE0"]
[Sun Aug 30 03:10:39.319999 2026] [security2:error] [pid 515259:tid 515453] [client 68.155.159.216:52567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-content/x/index.php"] [unique_id "apPlf2ZcVaai59truiV7wAAAAD8"]
[Sun Aug 30 03:10:39.329476 2026] [security2:error] [pid 515259:tid 515509] [client 20.104.50.220:31495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/8.php"] [unique_id "apPlf2ZcVaai59truiV7wQAAAHc"]
[Sun Aug 30 03:10:39.384110 2026] [security2:error] [pid 515259:tid 515427] [client 20.104.50.220:29606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/newfile.php"] [unique_id "apPlf2ZcVaai59truiV7xgAAACU"]
[Sun Aug 30 03:10:39.393669 2026] [core:alert] [pid 515259:tid 515490] [client 185.217.186.67:40182] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:10:39.408112 2026] [security2:error] [pid 515259:tid 515400] [client 20.104.49.130:52309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/kgoc6awap3napxxxdCdefault.php"] [unique_id "apPlf2ZcVaai59truiV7zwAAAAo"]
[Sun Aug 30 03:10:39.441038 2026] [security2:error] [pid 515259:tid 515494] [client 68.155.159.216:62612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/cong.php"] [unique_id "apPlf2ZcVaai59truiV70QAAAGg"]
[Sun Aug 30 03:10:39.443834 2026] [security2:error] [pid 515259:tid 515407] [client 20.48.251.3:14000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/bb.php"] [unique_id "apPlf2ZcVaai59truiV70gAAABE"]
[Sun Aug 30 03:10:39.447611 2026] [security2:error] [pid 515259:tid 515478] [client 20.104.50.220:62837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/bingo.php"] [unique_id "apPlf2ZcVaai59truiV70wAAAFg"]
[Sun Aug 30 03:10:39.484779 2026] [security2:error] [pid 515259:tid 515403] [client 20.104.104.62:52086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlf2ZcVaai59truiV71QAAAA0"]
[Sun Aug 30 03:10:39.486294 2026] [security2:error] [pid 515259:tid 515475] [client 158.23.147.79:60164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apPlf2ZcVaai59truiV71gAAAFU"]
[Sun Aug 30 03:10:39.509546 2026] [security2:error] [pid 515259:tid 515434] [client 20.63.219.114:15251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/goods.php"] [unique_id "apPlf2ZcVaai59truiV72QAAACw"]
[Sun Aug 30 03:10:39.515575 2026] [security2:error] [pid 515259:tid 515477] [client 20.104.49.130:32803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/xa.php"] [unique_id "apPlf2ZcVaai59truiV72gAAAFc"]
[Sun Aug 30 03:10:39.529019 2026] [security2:error] [pid 515259:tid 515498] [client 158.23.147.79:2024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apPlf2ZcVaai59truiV73QAAAGw"]
[Sun Aug 30 03:10:39.542687 2026] [security2:error] [pid 515259:tid 515514] [client 20.104.18.15:22417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/t3.php"] [unique_id "apPlf2ZcVaai59truiV74AAAAHw"]
[Sun Aug 30 03:10:39.579757 2026] [security2:error] [pid 515259:tid 515453] [client 158.23.147.79:52227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-admin.php"] [unique_id "apPlf2ZcVaai59truiV75AAAAD8"]
[Sun Aug 30 03:10:39.586267 2026] [authz_core:error] [pid 515259:tid 515390] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:39.586532 2026] [authz_core:error] [pid 515259:tid 515390] [client 74.7.243.204:45714] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:39.592406 2026] [security2:error] [pid 515259:tid 515462] [client 20.104.49.130:43304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/wsd.php"] [unique_id "apPlf2ZcVaai59truiV76AAAAEg"]
[Sun Aug 30 03:10:39.595241 2026] [security2:error] [pid 515259:tid 515473] [client 4.205.62.107:38404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/agg.php"] [unique_id "apPlf2ZcVaai59truiV76QAAAFM"]
[Sun Aug 30 03:10:39.617895 2026] [security2:error] [pid 515259:tid 515419] [client 20.104.104.62:52089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlf2ZcVaai59truiV76wAAAB0"]
[Sun Aug 30 03:10:39.641439 2026] [authz_core:error] [pid 515259:tid 515441] [client 66.249.66.78:60068] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:39.641895 2026] [authz_core:error] [pid 515259:tid 515441] [client 66.249.66.78:60068] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:39.649056 2026] [security2:error] [pid 515259:tid 515391] [client 20.104.18.15:18388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/admin.php"] [unique_id "apPlf2ZcVaai59truiV78QAAAAE"]
[Sun Aug 30 03:10:39.664532 2026] [security2:error] [pid 515259:tid 515459] [client 40.83.93.50:6545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/index.php"] [unique_id "apPlf2ZcVaai59truiV79gAAAEU"]
[Sun Aug 30 03:10:39.674459 2026] [security2:error] [pid 515259:tid 515403] [client 20.104.50.220:42493] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.love-texas-holdem.com"] [uri "/images/1.php"] [unique_id "apPlf2ZcVaai59truiV7-AAAAA0"]
[Sun Aug 30 03:10:39.674567 2026] [security2:error] [pid 515259:tid 515403] [client 20.104.50.220:42493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/images/1.php"] [unique_id "apPlf2ZcVaai59truiV7-AAAAA0"]
[Sun Aug 30 03:10:39.688065 2026] [security2:error] [pid 515259:tid 515450] [client 20.104.50.220:5579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/tesla.php"] [unique_id "apPlf2ZcVaai59truiV7-wAAADw"]
[Sun Aug 30 03:10:39.754474 2026] [security2:error] [pid 515259:tid 515446] [client 20.104.104.62:52088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/h02ugyh.php"] [unique_id "apPlf2ZcVaai59truiV8CAAAADg"]
[Sun Aug 30 03:10:39.756122 2026] [security2:error] [pid 515259:tid 515404] [client 20.104.49.130:60947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/abcd.php"] [unique_id "apPlf2ZcVaai59truiV8CQAAAA4"]
[Sun Aug 30 03:10:39.759848 2026] [authz_core:error] [pid 515259:tid 515424] [client 66.249.66.204:55955] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:39.760110 2026] [authz_core:error] [pid 515259:tid 515424] [client 66.249.66.204:55955] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:39.767839 2026] [security2:error] [pid 515259:tid 515443] [client 20.104.50.220:33033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/images/upload.php"] [unique_id "apPlf2ZcVaai59truiV8DQAAADU"]
[Sun Aug 30 03:10:39.770851 2026] [security2:error] [pid 515259:tid 515414] [client 20.197.61.180:15778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/twentytwentyfive/styles/sections/pk.php"] [unique_id "apPlf2ZcVaai59truiV8DgAAABg"]
[Sun Aug 30 03:10:39.781948 2026] [security2:error] [pid 515259:tid 515490] [client 158.23.147.79:52282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apPlf2ZcVaai59truiV8EgAAAGQ"]
[Sun Aug 30 03:10:39.847587 2026] [security2:error] [pid 515259:tid 515412] [client 20.48.251.3:54724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/wp-konfig.php"] [unique_id "apPlf2ZcVaai59truiV8GgAAABY"]
[Sun Aug 30 03:10:39.860735 2026] [security2:error] [pid 515259:tid 515487] [client 20.151.200.44:40949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/log.php"] [unique_id "apPlf2ZcVaai59truiV8GwAAAGE"]
[Sun Aug 30 03:10:39.893547 2026] [security2:error] [pid 515259:tid 515515] [client 20.104.104.62:52087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/sf.php"] [unique_id "apPlf2ZcVaai59truiV8HwAAAH0"]
[Sun Aug 30 03:10:39.932264 2026] [security2:error] [pid 515259:tid 515403] [client 158.23.147.79:52279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/lock.php"] [unique_id "apPlf2ZcVaai59truiV8JAAAAA0"]
[Sun Aug 30 03:10:39.940859 2026] [security2:error] [pid 515259:tid 515409] [client 68.155.159.216:46077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/images/index.php"] [unique_id "apPlf2ZcVaai59truiV8JQAAABM"]
[Sun Aug 30 03:10:39.979473 2026] [authz_core:error] [pid 515259:tid 515413] [client 66.249.66.71:36514] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:39.979928 2026] [authz_core:error] [pid 515259:tid 515413] [client 66.249.66.71:36514] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:40.011041 2026] [security2:error] [pid 515259:tid 515435] [client 20.104.18.15:43921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/wp-safe.php"] [unique_id "apPlgGZcVaai59truiV8MAAAAC0"]
[Sun Aug 30 03:10:40.035956 2026] [authz_core:error] [pid 515259:tid 515507] [client 66.249.66.65:54919] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:40.036254 2026] [authz_core:error] [pid 515259:tid 515507] [client 66.249.66.65:54919] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:40.044967 2026] [security2:error] [pid 515259:tid 515464] [client 20.63.219.114:19175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/m.php"] [unique_id "apPlgGZcVaai59truiV8NQAAAEo"]
[Sun Aug 30 03:10:40.063561 2026] [security2:error] [pid 515259:tid 515451] [client 20.104.104.62:36961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/4e.php"] [unique_id "apPlgGZcVaai59truiV8OQAAAD0"]
[Sun Aug 30 03:10:40.065970 2026] [security2:error] [pid 515259:tid 515462] [client 20.151.200.44:64786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/wk/index.php"] [unique_id "apPlgGZcVaai59truiV8OwAAAEg"]
[Sun Aug 30 03:10:40.080117 2026] [security2:error] [pid 515259:tid 515469] [client 20.104.50.220:16619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-trackback.php"] [unique_id "apPlgGZcVaai59truiV8PwAAAE8"]
[Sun Aug 30 03:10:40.124245 2026] [security2:error] [pid 515259:tid 515407] [client 158.23.147.79:57717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/goat1.php"] [unique_id "apPlgGZcVaai59truiV8SgAAABE"]
[Sun Aug 30 03:10:40.125225 2026] [security2:error] [pid 515259:tid 515394] [client 20.104.18.15:64853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/sure.php"] [unique_id "apPlgGZcVaai59truiV8TAAAAAQ"]
[Sun Aug 30 03:10:40.144872 2026] [authz_core:error] [pid 515259:tid 515459] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:40.145356 2026] [authz_core:error] [pid 515259:tid 515459] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:40.179500 2026] [security2:error] [pid 515259:tid 515405] [client 40.83.93.50:10708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/php8.php"] [unique_id "apPlgGZcVaai59truiV8VQAAAA8"]
[Sun Aug 30 03:10:40.183077 2026] [security2:error] [pid 515259:tid 515474] [client 4.205.62.107:17705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/goods.php"] [unique_id "apPlgGZcVaai59truiV8VwAAAFQ"]
[Sun Aug 30 03:10:40.206146 2026] [security2:error] [pid 515259:tid 515435] [client 158.23.147.79:43883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/index/function.php"] [unique_id "apPlgGZcVaai59truiV8WQAAAC0"]
[Sun Aug 30 03:10:40.212172 2026] [security2:error] [pid 515259:tid 515464] [client 20.48.251.3:59341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/66.php"] [unique_id "apPlgGZcVaai59truiV8WgAAAEo"]
[Sun Aug 30 03:10:40.216774 2026] [security2:error] [pid 515259:tid 515453] [client 20.104.104.62:60469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/ssss.php"] [unique_id "apPlgGZcVaai59truiV8XAAAAD8"]
[Sun Aug 30 03:10:40.217786 2026] [security2:error] [pid 515259:tid 515463] [client 20.104.49.130:63495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/reop3.php"] [unique_id "apPlgGZcVaai59truiV8XQAAAEk"]
[Sun Aug 30 03:10:40.254776 2026] [security2:error] [pid 515259:tid 515415] [client 20.104.50.220:59548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/usb.php"] [unique_id "apPlgGZcVaai59truiV8ZgAAABk"]
[Sun Aug 30 03:10:40.335388 2026] [security2:error] [pid 515259:tid 515461] [client 20.48.251.3:59518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/loxi-o.php"] [unique_id "apPlgGZcVaai59truiV8eAAAAEc"]
[Sun Aug 30 03:10:40.355608 2026] [security2:error] [pid 515259:tid 515458] [client 20.104.104.62:52057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/zoz.php"] [unique_id "apPlgGZcVaai59truiV8ewAAAEQ"]
[Sun Aug 30 03:10:40.376865 2026] [security2:error] [pid 515259:tid 515420] [client 158.23.147.79:61997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/.well-known/content.php"] [unique_id "apPlgGZcVaai59truiV8gAAAAB4"]
[Sun Aug 30 03:10:40.389494 2026] [security2:error] [pid 515259:tid 515427] [client 20.104.18.15:16963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/nano.php"] [unique_id "apPlgGZcVaai59truiV8iQAAACU"]
[Sun Aug 30 03:10:40.442312 2026] [core:alert] [pid 515259:tid 515478] [client 82.115.33.188:2547] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:10:40.449335 2026] [security2:error] [pid 515259:tid 515394] [client 20.63.219.114:7791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/doc.php"] [unique_id "apPlgGZcVaai59truiV8mgAAAAQ"]
[Sun Aug 30 03:10:40.466344 2026] [security2:error] [pid 515259:tid 515409] [client 4.205.62.107:36700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/otuz1.php"] [unique_id "apPlgGZcVaai59truiV8ngAAABM"]
[Sun Aug 30 03:10:40.466521 2026] [security2:error] [pid 515259:tid 515441] [client 20.104.50.220:59349] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.mumbaidailys.com"] [uri "/1.php"] [unique_id "apPlgGZcVaai59truiV8nwAAADM"]
[Sun Aug 30 03:10:40.466614 2026] [security2:error] [pid 515259:tid 515441] [client 20.104.50.220:59349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/1.php"] [unique_id "apPlgGZcVaai59truiV8nwAAADM"]
[Sun Aug 30 03:10:40.491880 2026] [security2:error] [pid 515259:tid 515454] [client 20.104.104.62:60467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/kcs.php"] [unique_id "apPlgGZcVaai59truiV8pAAAAEA"]
[Sun Aug 30 03:10:40.499725 2026] [security2:error] [pid 515259:tid 515470] [client 158.23.147.79:58375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-content/languages/about.php"] [unique_id "apPlgGZcVaai59truiV8pgAAAFA"]
[Sun Aug 30 03:10:40.508095 2026] [security2:error] [pid 515259:tid 515438] [client 4.205.62.107:25495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/database.php"] [unique_id "apPlgGZcVaai59truiV8qAAAADA"]
[Sun Aug 30 03:10:40.538836 2026] [security2:error] [pid 515259:tid 515432] [client 20.104.50.220:29136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/pro.php"] [unique_id "apPlgGZcVaai59truiV8sAAAACo"]
[Sun Aug 30 03:10:40.581637 2026] [authz_core:error] [pid 515259:tid 515398] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:40.581923 2026] [authz_core:error] [pid 515259:tid 515398] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:40.600199 2026] [security2:error] [pid 515259:tid 515515] [client 20.48.251.3:60521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/file59.php"] [unique_id "apPlgGZcVaai59truiV8vAAAAH0"]
[Sun Aug 30 03:10:40.604240 2026] [authz_core:error] [pid 515259:tid 515517] [client 66.249.66.194:52370] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:40.604686 2026] [authz_core:error] [pid 515259:tid 515517] [client 66.249.66.194:52370] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:40.609203 2026] [security2:error] [pid 515259:tid 515314] [remote 103.124.95.115:58906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.95.124.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catherinevalewines.com.au"] [uri "/wp-login.php"] [unique_id "apPlgGZcVaai59truiV8vwAAODU"]
[Sun Aug 30 03:10:40.621420 2026] [security2:error] [pid 515259:tid 515478] [client 68.155.159.216:63264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-includes/js/index.php"] [unique_id "apPlgGZcVaai59truiV8wQAAAFg"]
[Sun Aug 30 03:10:40.622406 2026] [security2:error] [pid 515259:tid 515407] [client 20.104.104.62:52039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/tajj.php"] [unique_id "apPlgGZcVaai59truiV8wgAAABE"]
[Sun Aug 30 03:10:40.656206 2026] [security2:error] [pid 515259:tid 515409] [client 158.23.147.79:52257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/cong.php"] [unique_id "apPlgGZcVaai59truiV8ygAAABM"]
[Sun Aug 30 03:10:40.667916 2026] [security2:error] [pid 515259:tid 515397] [client 20.104.50.220:62847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/backd00rshit.php"] [unique_id "apPlgGZcVaai59truiV8zQAAAAc"]
[Sun Aug 30 03:10:40.673086 2026] [authz_core:error] [pid 515259:tid 515438] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:40.673371 2026] [authz_core:error] [pid 515259:tid 515438] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:40.677300 2026] [security2:error] [pid 515259:tid 515430] [client 20.151.200.44:28662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/wt.php"] [unique_id "apPlgGZcVaai59truiV8zwAAACg"]
[Sun Aug 30 03:10:40.692595 2026] [security2:error] [pid 515259:tid 515448] [client 20.104.18.15:22523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/wp.php"] [unique_id "apPlgGZcVaai59truiV80QAAADo"]
[Sun Aug 30 03:10:40.729784 2026] [security2:error] [pid 515259:tid 515436] [client 20.197.61.180:3257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/twentytwentythree/patterns/index.php"] [unique_id "apPlgGZcVaai59truiV82gAAAC4"]
[Sun Aug 30 03:10:40.744895 2026] [security2:error] [pid 515259:tid 515421] [client 4.205.62.107:64671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/requirements.php"] [unique_id "apPlgGZcVaai59truiV83gAAAB8"]
[Sun Aug 30 03:10:40.755173 2026] [security2:error] [pid 515259:tid 515460] [client 20.104.104.62:36933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/bge.php"] [unique_id "apPlgGZcVaai59truiV84AAAAEY"]
[Sun Aug 30 03:10:40.797235 2026] [authz_core:error] [pid 515259:tid 515452] [client 216.73.216.128:51580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:40.797514 2026] [authz_core:error] [pid 515259:tid 515452] [client 216.73.216.128:51580] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:40.809678 2026] [security2:error] [pid 515259:tid 515409] [client 20.104.18.15:18392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/ws85.php"] [unique_id "apPlgGZcVaai59truiV86QAAABM"]
[Sun Aug 30 03:10:40.810375 2026] [authz_core:error] [pid 515259:tid 515491] [client 66.249.66.38:49477] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:40.810853 2026] [authz_core:error] [pid 515259:tid 515491] [client 66.249.66.38:49477] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:40.811848 2026] [security2:error] [pid 515259:tid 515454] [client 20.104.50.220:51609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/imageswp-init.php"] [unique_id "apPlgGZcVaai59truiV86gAAAEA"]
[Sun Aug 30 03:10:40.814926 2026] [security2:error] [pid 515259:tid 515394] [client 40.83.93.50:6182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/function.php"] [unique_id "apPlgGZcVaai59truiV86wAAAAQ"]
[Sun Aug 30 03:10:40.825819 2026] [security2:error] [pid 515259:tid 515470] [client 20.104.50.220:5492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/alfates.php"] [unique_id "apPlgGZcVaai59truiV87AAAAFA"]
[Sun Aug 30 03:10:40.827708 2026] [security2:error] [pid 515259:tid 515504] [client 20.104.49.130:52482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/ms-edit.php"] [unique_id "apPlgGZcVaai59truiV87QAAAHI"]
[Sun Aug 30 03:10:40.889509 2026] [security2:error] [pid 515259:tid 515463] [client 20.104.104.62:36959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/ssh3ll.php"] [unique_id "apPlgGZcVaai59truiV89wAAAEk"]
[Sun Aug 30 03:10:40.902743 2026] [security2:error] [pid 515259:tid 515432] [client 20.63.219.114:15678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/users.php"] [unique_id "apPlgGZcVaai59truiV8-wAAACo"]
[Sun Aug 30 03:10:40.925611 2026] [security2:error] [pid 515259:tid 515416] [client 157.90.156.63:59078] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "arcexploration.com.au"] [uri "/wp-content/endurance-page-cache/_index.html"] [unique_id "apPlgGZcVaai59truiV8_QAAABo"], referer: https://arcexploration.com.au/
[Sun Aug 30 03:10:40.925987 2026] [security2:error] [pid 515259:tid 515413] [client 20.104.50.220:32864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/images/fox.php"] [unique_id "apPlgGZcVaai59truiV8_gAAABc"]
[Sun Aug 30 03:10:40.943072 2026] [security2:error] [pid 515259:tid 515507] [client 158.23.147.79:57702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apPlgGZcVaai59truiV9AgAAAHU"]
[Sun Aug 30 03:10:40.946167 2026] [security2:error] [pid 515259:tid 515485] [client 158.23.147.79:61970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/js/index.php"] [unique_id "apPlgGZcVaai59truiV9AwAAAF8"]
[Sun Aug 30 03:10:40.967755 2026] [security2:error] [pid 515259:tid 515443] [client 20.104.49.130:63599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/100.php"] [unique_id "apPlgGZcVaai59truiV9CgAAADU"]
[Sun Aug 30 03:10:40.975857 2026] [authz_core:error] [pid 515259:tid 515446] [client 216.73.216.128:64209] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:40.976157 2026] [authz_core:error] [pid 515259:tid 515446] [client 216.73.216.128:64209] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:40.997002 2026] [security2:error] [pid 515259:tid 515454] [client 20.48.251.3:54729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/25.php"] [unique_id "apPlgGZcVaai59truiV9EgAAAEA"]
[Sun Aug 30 03:10:41.039946 2026] [security2:error] [pid 515259:tid 515509] [client 20.104.104.62:36943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/motu.php"] [unique_id "apPlgWZcVaai59truiV9GQAAAHc"]
[Sun Aug 30 03:10:41.068783 2026] [security2:error] [pid 515259:tid 515412] [client 158.23.147.79:60203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-content/banners/about.php"] [unique_id "apPlgWZcVaai59truiV9IwAAABY"]
[Sun Aug 30 03:10:41.072710 2026] [security2:error] [pid 515259:tid 515320] [remote 103.124.95.115:58906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.95.124.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catherinevalewines.com.au"] [uri "/wp-login.php"] [unique_id "apPlgWZcVaai59truiV9JQAARjs"], referer: https://catherinevalewines.com.au/wp-login.php
[Sun Aug 30 03:10:41.112331 2026] [authz_core:error] [pid 515259:tid 515451] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:41.112599 2026] [authz_core:error] [pid 515259:tid 515451] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:41.121346 2026] [authz_core:error] [pid 515259:tid 515462] [client 66.249.66.192:58172] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:41.121617 2026] [authz_core:error] [pid 515259:tid 515462] [client 66.249.66.192:58172] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:41.150965 2026] [security2:error] [pid 515259:tid 515516] [client 20.104.18.15:44029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/gjewuagf.php"] [unique_id "apPlgWZcVaai59truiV9RgAAAH4"]
[Sun Aug 30 03:10:41.162172 2026] [authz_core:error] [pid 515259:tid 515514] [client 216.73.216.128:64209] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:41.162591 2026] [authz_core:error] [pid 515259:tid 515514] [client 216.73.216.128:64209] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:41.168063 2026] [security2:error] [pid 515259:tid 515412] [client 68.155.159.216:45912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-includes/widgets/index.php"] [unique_id "apPlgWZcVaai59truiV9TgAAABY"]
[Sun Aug 30 03:10:41.184342 2026] [security2:error] [pid 515259:tid 515396] [client 20.104.104.62:52052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/wefile.php"] [unique_id "apPlgWZcVaai59truiV9TwAAAAY"]
[Sun Aug 30 03:10:41.193669 2026] [security2:error] [pid 515259:tid 515480] [client 158.23.147.79:43891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/index.php"] [unique_id "apPlgWZcVaai59truiV9UQAAAFo"]
[Sun Aug 30 03:10:41.213972 2026] [security2:error] [pid 515259:tid 515495] [client 20.104.50.220:16723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/.well-known/index.php"] [unique_id "apPlgWZcVaai59truiV9UwAAAGk"]
[Sun Aug 30 03:10:41.242600 2026] [security2:error] [pid 515259:tid 515393] [client 216.73.216.128:55788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/nameserverconfig"] [unique_id "apPlgWZcVaai59truiV9WwAAAAM"]
[Sun Aug 30 03:10:41.264456 2026] [security2:error] [pid 515259:tid 515478] [client 20.104.18.15:64854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/gray.php"] [unique_id "apPlgWZcVaai59truiV9YAAAAFg"]
[Sun Aug 30 03:10:41.314380 2026] [security2:error] [pid 515259:tid 515400] [client 4.205.62.107:17688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/loxi-o.php"] [unique_id "apPlgWZcVaai59truiV9bAAAAAo"]
[Sun Aug 30 03:10:41.338874 2026] [security2:error] [pid 515259:tid 515453] [client 20.104.104.62:52056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/Contrller.php"] [unique_id "apPlgWZcVaai59truiV9dQAAAD8"]
[Sun Aug 30 03:10:41.347103 2026] [security2:error] [pid 515259:tid 515515] [client 40.83.93.50:6571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/about.php"] [unique_id "apPlgWZcVaai59truiV9eAAAAH0"]
[Sun Aug 30 03:10:41.350626 2026] [security2:error] [pid 515259:tid 515469] [client 20.48.251.3:52834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/admin.php"] [unique_id "apPlgWZcVaai59truiV9eQAAAE8"]
[Sun Aug 30 03:10:41.369477 2026] [authz_core:error] [pid 515259:tid 515451] [client 66.249.66.42:56567] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:41.369953 2026] [authz_core:error] [pid 515259:tid 515451] [client 66.249.66.42:56567] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:41.470559 2026] [security2:error] [pid 515259:tid 515477] [client 20.48.251.3:52219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/f35.php"] [unique_id "apPlgWZcVaai59truiV9mAAAAFc"]
[Sun Aug 30 03:10:41.480943 2026] [security2:error] [pid 515259:tid 515396] [client 20.104.104.62:60438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/file66.php"] [unique_id "apPlgWZcVaai59truiV9mwAAAAY"]
[Sun Aug 30 03:10:41.486215 2026] [security2:error] [pid 515259:tid 515489] [client 20.104.50.220:62007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/usr.php"] [unique_id "apPlgWZcVaai59truiV9ngAAAGM"]
[Sun Aug 30 03:10:41.509838 2026] [security2:error] [pid 515259:tid 515435] [client 158.23.147.79:61988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/about/function.php"] [unique_id "apPlgWZcVaai59truiV9pgAAAC0"]
[Sun Aug 30 03:10:41.526290 2026] [security2:error] [pid 515259:tid 515491] [client 20.104.18.15:64746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/ano.php"] [unique_id "apPlgWZcVaai59truiV9qQAAAGU"]
[Sun Aug 30 03:10:41.528207 2026] [authz_core:error] [pid 515259:tid 515500] [client 216.73.216.128:64209] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:41.528655 2026] [authz_core:error] [pid 515259:tid 515500] [client 216.73.216.128:64209] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:41.588682 2026] [security2:error] [pid 515259:tid 515416] [client 158.23.147.79:57715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-admin/network/index.php"] [unique_id "apPlgWZcVaai59truiV9tAAAABo"]
[Sun Aug 30 03:10:41.599722 2026] [authz_core:error] [pid 515259:tid 515420] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:10:41.600013 2026] [authz_core:error] [pid 515259:tid 515420] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:10:41.604907 2026] [security2:error] [pid 515259:tid 515468] [client 20.104.50.220:50373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/100.php"] [unique_id "apPlgWZcVaai59truiV9uQAAAE4"]
[Sun Aug 30 03:10:41.607344 2026] [security2:error] [pid 515259:tid 515486] [client 20.63.219.114:15267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/class.php"] [unique_id "apPlgWZcVaai59truiV9uwAAAGA"]
[Sun Aug 30 03:10:41.613353 2026] [authz_core:error] [pid 515259:tid 515467] [client 216.73.216.128:2664] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:41.613663 2026] [authz_core:error] [pid 515259:tid 515467] [client 216.73.216.128:2664] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:41.622057 2026] [security2:error] [pid 515259:tid 515400] [client 4.205.62.107:36568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/update.php"] [unique_id "apPlgWZcVaai59truiV9vQAAAAo"]
[Sun Aug 30 03:10:41.628748 2026] [security2:error] [pid 515259:tid 515413] [client 20.104.49.130:53554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/f35.update.php"] [unique_id "apPlgWZcVaai59truiV9vgAAABc"]
[Sun Aug 30 03:10:41.638765 2026] [security2:error] [pid 515259:tid 515480] [client 20.104.104.62:52037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/blnux.php"] [unique_id "apPlgWZcVaai59truiV9wQAAAFo"]
[Sun Aug 30 03:10:41.660125 2026] [security2:error] [pid 515259:tid 515507] [client 68.155.159.216:52561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apPlgWZcVaai59truiV9ywAAAHU"]
[Sun Aug 30 03:10:41.674751 2026] [security2:error] [pid 515259:tid 515454] [client 20.104.50.220:29170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/edit.php"] [unique_id "apPlgWZcVaai59truiV9zQAAAEA"]
[Sun Aug 30 03:10:41.696974 2026] [security2:error] [pid 515259:tid 515399] [client 20.197.61.180:3835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/users.php"] [unique_id "apPlgWZcVaai59truiV90QAAAAk"]
[Sun Aug 30 03:10:41.697851 2026] [security2:error] [pid 515259:tid 515424] [client 216.73.216.128:51580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/about.html"] [unique_id "apPlgWZcVaai59truiV90gAAACI"]
[Sun Aug 30 03:10:41.735498 2026] [security2:error] [pid 515259:tid 515476] [client 20.48.251.3:60502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/cli_bootstrap.php"] [unique_id "apPlgWZcVaai59truiV94AAAAFY"]
[Sun Aug 30 03:10:41.736527 2026] [security2:error] [pid 515259:tid 515510] [client 158.23.147.79:43865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apPlgWZcVaai59truiV94QAAAHg"]
[Sun Aug 30 03:10:41.747923 2026] [security2:error] [pid 515259:tid 515400] [client 4.205.62.107:25788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/atex1.php"] [unique_id "apPlgWZcVaai59truiV95QAAAAo"]
[Sun Aug 30 03:10:41.777391 2026] [security2:error] [pid 515259:tid 515485] [client 68.155.159.216:62615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-content/index.php"] [unique_id "apPlgWZcVaai59truiV97gAAAF8"]
[Sun Aug 30 03:10:41.799230 2026] [authz_core:error] [pid 515259:tid 515507] [client 216.73.216.128:2664] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:41.799664 2026] [authz_core:error] [pid 515259:tid 515507] [client 216.73.216.128:2664] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:41.804788 2026] [security2:error] [pid 515259:tid 515418] [client 20.104.104.62:60448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/attack.php"] [unique_id "apPlgWZcVaai59truiV99gAAABw"]
[Sun Aug 30 03:10:41.846036 2026] [security2:error] [pid 515259:tid 515487] [client 20.104.50.220:62809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/ichi.php"] [unique_id "apPlgWZcVaai59truiV9-wAAAGE"]
[Sun Aug 30 03:10:41.856918 2026] [security2:error] [pid 515259:tid 515429] [client 20.104.18.15:22343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/abcd.php"] [unique_id "apPlgWZcVaai59truiV9_QAAACc"]
[Sun Aug 30 03:10:41.865911 2026] [security2:error] [pid 515259:tid 515503] [client 40.83.93.50:6531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/new.php"] [unique_id "apPlgWZcVaai59truiV-AgAAAHE"]
[Sun Aug 30 03:10:41.883804 2026] [security2:error] [pid 515259:tid 515401] [client 4.205.62.107:61700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/var/www/wallet/index.php"] [unique_id "apPlgWZcVaai59truiV-BgAAAAs"]
[Sun Aug 30 03:10:41.929238 2026] [security2:error] [pid 515259:tid 515489] [client 158.23.147.79:2030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apPlgWZcVaai59truiV-CwAAAGM"]
[Sun Aug 30 03:10:41.935849 2026] [security2:error] [pid 515259:tid 515443] [client 20.104.104.62:36951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/wk/index.php"] [unique_id "apPlgWZcVaai59truiV-DAAAADU"]
[Sun Aug 30 03:10:41.947052 2026] [authz_core:error] [pid 515259:tid 515445] [client 66.249.66.193:54637] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:41.947348 2026] [authz_core:error] [pid 515259:tid 515445] [client 66.249.66.193:54637] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:41.954082 2026] [security2:error] [pid 515259:tid 515419] [client 20.104.50.220:51536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/images/upload.php"] [unique_id "apPlgWZcVaai59truiV-EgAAAB0"]
[Sun Aug 30 03:10:41.956541 2026] [security2:error] [pid 515259:tid 515425] [client 20.104.18.15:18403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/ffs.php"] [unique_id "apPlgWZcVaai59truiV-FAAAACM"]
[Sun Aug 30 03:10:41.959757 2026] [security2:error] [pid 515259:tid 515434] [client 158.23.147.79:58377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-includes/Text/about.php"] [unique_id "apPlgWZcVaai59truiV-FgAAACw"]
[Sun Aug 30 03:10:42.000158 2026] [security2:error] [pid 515259:tid 515473] [client 20.104.50.220:5442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/themes.php"] [unique_id "apPlgWZcVaai59truiV-IwAAAFM"]
[Sun Aug 30 03:10:42.070959 2026] [security2:error] [pid 515259:tid 515442] [client 20.104.50.220:33207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/images/fw.php"] [unique_id "apPlgmZcVaai59truiV-NwAAADQ"]
[Sun Aug 30 03:10:42.071764 2026] [security2:error] [pid 515259:tid 515462] [client 20.104.104.62:36956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/dehnl.php"] [unique_id "apPlgmZcVaai59truiV-OAAAAEg"]
[Sun Aug 30 03:10:42.077143 2026] [authz_core:error] [pid 515259:tid 515516] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:42.077472 2026] [authz_core:error] [pid 515259:tid 515516] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:42.098568 2026] [security2:error] [pid 515259:tid 515435] [client 20.151.200.44:65413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/dehnl.php"] [unique_id "apPlgmZcVaai59truiV-QgAAAC0"]
[Sun Aug 30 03:10:42.147062 2026] [authz_core:error] [pid 515259:tid 515451] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:42.147331 2026] [authz_core:error] [pid 515259:tid 515451] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:42.155945 2026] [security2:error] [pid 515259:tid 515437] [client 20.151.200.44:28545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/im.php"] [unique_id "apPlgmZcVaai59truiV-VwAAAC8"]
[Sun Aug 30 03:10:42.167096 2026] [security2:error] [pid 515259:tid 515506] [client 20.48.251.3:65475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/nlnub.php"] [unique_id "apPlgmZcVaai59truiV-WwAAAHQ"]
[Sun Aug 30 03:10:42.193589 2026] [security2:error] [pid 515259:tid 515395] [client 158.23.147.79:61715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-admin/index.php"] [unique_id "apPlgmZcVaai59truiV-YgAAAAU"]
[Sun Aug 30 03:10:42.195474 2026] [security2:error] [pid 515259:tid 515485] [client 20.63.219.114:2541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/auth.php"] [unique_id "apPlgmZcVaai59truiV-YwAAAF8"]
[Sun Aug 30 03:10:42.242034 2026] [security2:error] [pid 515259:tid 515392] [client 20.104.104.62:52058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/png.php"] [unique_id "apPlgmZcVaai59truiV-cQAAAAI"]
[Sun Aug 30 03:10:42.266506 2026] [security2:error] [pid 515259:tid 515418] [client 20.104.49.130:36763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/dehnl.php"] [unique_id "apPlgmZcVaai59truiV-dQAAABw"]
[Sun Aug 30 03:10:42.304150 2026] [authz_core:error] [pid 515259:tid 515473] [client 216.73.216.128:35448] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:42.304431 2026] [authz_core:error] [pid 515259:tid 515473] [client 216.73.216.128:35448] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:42.353497 2026] [security2:error] [pid 515259:tid 515507] [client 20.104.50.220:16981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "apPlgmZcVaai59truiV-lQAAAHU"]
[Sun Aug 30 03:10:42.359013 2026] [security2:error] [pid 515259:tid 515458] [client 68.155.159.216:46008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apPlgmZcVaai59truiV-mQAAAEQ"]
[Sun Aug 30 03:10:42.362248 2026] [authz_core:error] [pid 515259:tid 515488] [client 66.249.66.73:52782] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:42.362735 2026] [authz_core:error] [pid 515259:tid 515488] [client 66.249.66.73:52782] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:42.363416 2026] [security2:error] [pid 515259:tid 515427] [client 158.23.147.79:43893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPlgmZcVaai59truiV-mwAAACU"]
[Sun Aug 30 03:10:42.383094 2026] [security2:error] [pid 515259:tid 515400] [client 20.104.104.62:36969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/txets.php"] [unique_id "apPlgmZcVaai59truiV-oAAAAAo"]
[Sun Aug 30 03:10:42.383961 2026] [security2:error] [pid 515259:tid 515513] [client 40.83.93.50:6535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/goods.php"] [unique_id "apPlgmZcVaai59truiV-ogAAAHs"]
[Sun Aug 30 03:10:42.384019 2026] [security2:error] [pid 515259:tid 515408] [client 20.104.18.15:43930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/tnglzqmv.php"] [unique_id "apPlgmZcVaai59truiV-oQAAABI"]
[Sun Aug 30 03:10:42.416795 2026] [security2:error] [pid 515259:tid 515456] [client 20.197.61.180:12280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/wp-cron.php"] [unique_id "apPlgmZcVaai59truiV-qgAAAEI"]
[Sun Aug 30 03:10:42.420262 2026] [http2:info] [pid 517995:tid 517995] h2_workers: created with min=128 max=192 idle_ms=600000
[Sun Aug 30 03:10:42.440518 2026] [security2:error] [pid 517995:tid 518128] [client 20.104.18.15:16641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/puki.php"] [unique_id "apPlgrz-S0xMfHBNth5p6AAAAQs"]
[Sun Aug 30 03:10:42.450216 2026] [security2:error] [pid 517995:tid 518144] [client 4.205.62.107:16797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/f35.php"] [unique_id "apPlgrz-S0xMfHBNth5p9QAAARs"]
[Sun Aug 30 03:10:42.470790 2026] [security2:error] [pid 515259:tid 515443] [client 195.178.110.155:62968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innatalybridal.com"] [uri "/index.php"] [unique_id "apPlgmZcVaai59truiV-tAAAADU"]
[Sun Aug 30 03:10:42.488676 2026] [security2:error] [pid 515259:tid 515499] [client 20.48.251.3:55706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/png.php"] [unique_id "apPlgmZcVaai59truiV-uQAAAG0"]
[Sun Aug 30 03:10:42.514237 2026] [security2:error] [pid 515259:tid 515471] [client 20.104.104.62:36965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/wp-login.php"] [unique_id "apPlgmZcVaai59truiV-vQAAAFE"]
[Sun Aug 30 03:10:42.585883 2026] [authz_core:error] [pid 515259:tid 515421] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:42.586180 2026] [authz_core:error] [pid 515259:tid 515421] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:42.598903 2026] [security2:error] [pid 517995:tid 518184] [client 158.23.147.79:43875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/about.php"] [unique_id "apPlgrz-S0xMfHBNth5qBAAAAUM"]
[Sun Aug 30 03:10:42.611291 2026] [security2:error] [pid 515259:tid 515411] [client 20.48.251.3:59511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/api.php"] [unique_id "apPlgmZcVaai59truiV-1wAAABU"]
[Sun Aug 30 03:10:42.618417 2026] [authz_core:error] [pid 515259:tid 515445] [client 216.73.216.128:35448] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:42.618700 2026] [authz_core:error] [pid 515259:tid 515445] [client 216.73.216.128:35448] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:42.622981 2026] [security2:error] [pid 515259:tid 515486] [client 158.23.147.79:58401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/asd.php"] [unique_id "apPlgmZcVaai59truiV-2QAAAGA"]
[Sun Aug 30 03:10:42.649593 2026] [security2:error] [pid 515259:tid 515432] [client 20.104.104.62:60419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/wp-access.php"] [unique_id "apPlgmZcVaai59truiV-4wAAACo"]
[Sun Aug 30 03:10:42.665062 2026] [security2:error] [pid 515259:tid 515502] [client 20.104.18.15:16950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/mgrr.php"] [unique_id "apPlgmZcVaai59truiV-6QAAAHA"]
[Sun Aug 30 03:10:42.666868 2026] [security2:error] [pid 515259:tid 515331] [remote 68.155.159.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ibrgroup.in"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apPlgmZcVaai59truiV-6gAAHkY"]
[Sun Aug 30 03:10:42.677837 2026] [security2:error] [pid 515259:tid 515467] [client 20.104.49.130:45740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/tool.php"] [unique_id "apPlgmZcVaai59truiV-7QAAAE0"]
[Sun Aug 30 03:10:42.710378 2026] [security2:error] [pid 517995:tid 518204] [client 20.151.200.44:40939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/xwpg.php"] [unique_id "apPlgrz-S0xMfHBNth5qCwAAAVc"]
[Sun Aug 30 03:10:42.723220 2026] [authz_core:error] [pid 515259:tid 515503] [client 216.73.216.128:21613] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:42.723535 2026] [authz_core:error] [pid 515259:tid 515503] [client 216.73.216.128:21613] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:42.766547 2026] [security2:error] [pid 515259:tid 515463] [client 20.104.50.220:51013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/about.php"] [unique_id "apPlgmZcVaai59truiV_CgAAAEk"]
[Sun Aug 30 03:10:42.781819 2026] [security2:error] [pid 515259:tid 515419] [client 20.104.104.62:36962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/wp-content/admin.php"] [unique_id "apPlgmZcVaai59truiV_DQAAAB0"]
[Sun Aug 30 03:10:42.783881 2026] [security2:error] [pid 517995:tid 518170] [client 20.63.219.114:20523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/adminfuns.php"] [unique_id "apPlgrz-S0xMfHBNth5qEAAAATU"]
[Sun Aug 30 03:10:42.799868 2026] [authz_core:error] [pid 515259:tid 515455] [client 216.73.216.128:64209] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:42.800145 2026] [authz_core:error] [pid 515259:tid 515455] [client 216.73.216.128:64209] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:42.843964 2026] [security2:error] [pid 517995:tid 518221] [client 20.104.50.220:52822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/11.php"] [unique_id "apPlgrz-S0xMfHBNth5qFAAAAWg"]
[Sun Aug 30 03:10:42.849313 2026] [security2:error] [pid 517995:tid 518222] [client 4.205.62.107:36590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/channels.php"] [unique_id "apPlgrz-S0xMfHBNth5qFQAAAWk"]
[Sun Aug 30 03:10:42.862575 2026] [security2:error] [pid 515259:tid 515411] [client 158.23.147.79:62000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apPlgmZcVaai59truiV_IAAAABU"]
[Sun Aug 30 03:10:42.874811 2026] [security2:error] [pid 515259:tid 515417] [client 20.48.251.3:60486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/dd.php"] [unique_id "apPlgmZcVaai59truiV_JwAAABs"]
[Sun Aug 30 03:10:42.893677 2026] [authz_core:error] [pid 515259:tid 515474] [client 216.73.216.128:35448] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:42.894116 2026] [authz_core:error] [pid 515259:tid 515474] [client 216.73.216.128:35448] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:42.912890 2026] [security2:error] [pid 515259:tid 515427] [client 20.104.104.62:60422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/log.php"] [unique_id "apPlgmZcVaai59truiV_MQAAACU"]
[Sun Aug 30 03:10:42.918892 2026] [security2:error] [pid 515259:tid 515502] [client 40.83.93.50:10703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/m.php"] [unique_id "apPlgmZcVaai59truiV_MgAAAHA"]
[Sun Aug 30 03:10:42.919825 2026] [security2:error] [pid 517995:tid 518232] [client 20.151.200.44:28547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/file.php"] [unique_id "apPlgrz-S0xMfHBNth5qGgAAAXM"]
[Sun Aug 30 03:10:42.929331 2026] [security2:error] [pid 515259:tid 515499] [client 68.155.159.216:57045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/about/function.php"] [unique_id "apPlgmZcVaai59truiV_NQAAAG0"]
[Sun Aug 30 03:10:42.986450 2026] [authz_core:error] [pid 515259:tid 515476] [client 216.73.216.128:21613] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:42.986934 2026] [authz_core:error] [pid 515259:tid 515476] [client 216.73.216.128:21613] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:42.987710 2026] [security2:error] [pid 515259:tid 515417] [client 20.104.50.220:28722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/~.php"] [unique_id "apPlgmZcVaai59truiV_QwAAABs"]
[Sun Aug 30 03:10:43.014352 2026] [security2:error] [pid 517995:tid 518247] [client 20.104.18.15:22428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/nofile.php"] [unique_id "apPlg7z-S0xMfHBNth5qIAAAAYI"]
[Sun Aug 30 03:10:43.021480 2026] [security2:error] [pid 517995:tid 518249] [client 4.205.62.107:61727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/124.php"] [unique_id "apPlg7z-S0xMfHBNth5qIgAAAYQ"]
[Sun Aug 30 03:10:43.038852 2026] [security2:error] [pid 515259:tid 515405] [client 20.104.104.62:52045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/xwpg.php"] [unique_id "apPlg2ZcVaai59truiV_WQAAAA8"]
[Sun Aug 30 03:10:43.071112 2026] [security2:error] [pid 517995:tid 518135] [client 4.205.62.107:25483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/aws_sdk_settings.php"] [unique_id "apPlg7z-S0xMfHBNth5qJQAAARI"]
[Sun Aug 30 03:10:43.077027 2026] [core:alert] [pid 517995:tid 518133] [client 191.5.210.44:38679] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:10:43.091101 2026] [security2:error] [pid 515259:tid 515448] [client 20.104.50.220:42016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/images/fox.php"] [unique_id "apPlg2ZcVaai59truiV_cwAAADo"]
[Sun Aug 30 03:10:43.092127 2026] [authz_core:error] [pid 515259:tid 515502] [client 66.249.66.74:49995] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:43.092416 2026] [authz_core:error] [pid 515259:tid 515502] [client 66.249.66.74:49995] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:43.110789 2026] [security2:error] [pid 517995:tid 518145] [client 20.104.18.15:18315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/nano.php"] [unique_id "apPlg7z-S0xMfHBNth5qKgAAARw"]
[Sun Aug 30 03:10:43.126395 2026] [authz_core:error] [pid 515259:tid 515450] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:43.126684 2026] [authz_core:error] [pid 515259:tid 515450] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:43.142502 2026] [security2:error] [pid 515259:tid 515472] [client 20.197.61.180:3226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/wp-links-opml.php"] [unique_id "apPlg2ZcVaai59truiV_hwAAAFI"]
[Sun Aug 30 03:10:43.149801 2026] [security2:error] [pid 517995:tid 518153] [client 20.104.50.220:5233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/update.php"] [unique_id "apPlg7z-S0xMfHBNth5qLwAAASQ"]
[Sun Aug 30 03:10:43.155577 2026] [security2:error] [pid 517995:tid 518139] [client 20.151.200.44:64755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/png.php"] [unique_id "apPlg7z-S0xMfHBNth5qMAAAARY"]
[Sun Aug 30 03:10:43.167136 2026] [security2:error] [pid 515259:tid 515439] [client 20.104.104.62:60436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/sxxb.php"] [unique_id "apPlg2ZcVaai59truiV_kAAAADE"]
[Sun Aug 30 03:10:43.214785 2026] [security2:error] [pid 517995:tid 518169] [client 20.104.50.220:33181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/images/alfa.php"] [unique_id "apPlg7z-S0xMfHBNth5qNgAAATQ"]
[Sun Aug 30 03:10:43.235957 2026] [security2:error] [pid 517995:tid 518175] [client 158.23.147.79:43874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/themes.php"] [unique_id "apPlg7z-S0xMfHBNth5qOQAAATo"]
[Sun Aug 30 03:10:43.335737 2026] [security2:error] [pid 517995:tid 518217] [client 20.104.104.62:60435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/dx.php"] [unique_id "apPlg7z-S0xMfHBNth5qSgAAAWQ"]
[Sun Aug 30 03:10:43.343893 2026] [security2:error] [pid 517995:tid 518219] [client 20.48.251.3:65500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/mga.php"] [unique_id "apPlg7z-S0xMfHBNth5qTAAAAWY"]
[Sun Aug 30 03:10:43.347342 2026] [authz_core:error] [pid 515259:tid 515500] [client 216.73.216.128:2664] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:43.347649 2026] [authz_core:error] [pid 515259:tid 515500] [client 216.73.216.128:2664] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:43.370547 2026] [security2:error] [pid 515259:tid 515456] [client 158.23.147.79:60208] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.brandscape.qa"] [uri "/1.php"] [unique_id "apPlg2ZcVaai59truiV_xgAAAEI"]
[Sun Aug 30 03:10:43.370651 2026] [security2:error] [pid 515259:tid 515456] [client 158.23.147.79:60208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/1.php"] [unique_id "apPlg2ZcVaai59truiV_xgAAAEI"]
[Sun Aug 30 03:10:43.396417 2026] [security2:error] [pid 517995:tid 518239] [client 158.23.147.79:56469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/.well-knownold/index.php"] [unique_id "apPlg7z-S0xMfHBNth5qVAAAAXo"]
[Sun Aug 30 03:10:43.412671 2026] [security2:error] [pid 515259:tid 515427] [client 195.178.110.247:6810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "congresolatammtto.com"] [uri "/index.php"] [unique_id "apPlg2ZcVaai59truiV_2QAAACU"]
[Sun Aug 30 03:10:43.448731 2026] [security2:error] [pid 515259:tid 515496] [client 40.83.93.50:6574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/doc.php"] [unique_id "apPlg2ZcVaai59truiV_4wAAAGo"]
[Sun Aug 30 03:10:43.464818 2026] [security2:error] [pid 515259:tid 515345] [remote 52.167.144.180:18642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "themesslab.com"] [uri "/index.php/2016/10/04/super-grand-pokie-machine/"] [unique_id "apPlg2ZcVaai59truiV_6AAAQlQ"]
[Sun Aug 30 03:10:43.478315 2026] [core:alert] [pid 515259:tid 515411] [client 186.12.184.40:29820] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:10:43.493693 2026] [security2:error] [pid 515259:tid 515448] [client 20.104.50.220:17246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-admin/about.php"] [unique_id "apPlg2ZcVaai59truiV_7QAAADo"]
[Sun Aug 30 03:10:43.494282 2026] [security2:error] [pid 515259:tid 515405] [client 20.48.250.41:40958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlg2ZcVaai59truiV_7gAAAA8"]
[Sun Aug 30 03:10:43.508827 2026] [security2:error] [pid 515259:tid 515424] [client 20.104.104.62:36946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPlg2ZcVaai59truiV_8QAAACI"]
[Sun Aug 30 03:10:43.550575 2026] [security2:error] [pid 515259:tid 515514] [client 158.23.147.79:61961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-mail.php"] [unique_id "apPlg2ZcVaai59truiV__gAAAHw"]
[Sun Aug 30 03:10:43.568861 2026] [security2:error] [pid 515259:tid 515423] [client 20.104.18.15:43294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/wefile.php"] [unique_id "apPlg2ZcVaai59truiWAAgAAACE"]
[Sun Aug 30 03:10:43.571025 2026] [security2:error] [pid 517995:tid 518173] [client 20.104.18.15:64779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/sonic.php"] [unique_id "apPlg7z-S0xMfHBNth5qbAAAATg"]
[Sun Aug 30 03:10:43.580435 2026] [security2:error] [pid 517995:tid 518127] [client 195.178.110.247:61176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "congresolatammtto.com"] [uri "/index.php"] [unique_id "apPlg7z-S0xMfHBNth5qbQAAAQo"]
[Sun Aug 30 03:10:43.593129 2026] [authz_core:error] [pid 515259:tid 515496] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:43.593263 2026] [security2:error] [pid 517995:tid 518185] [client 4.205.62.107:16795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/api.php"] [unique_id "apPlg7z-S0xMfHBNth5qcAAAAUQ"]
[Sun Aug 30 03:10:43.593616 2026] [authz_core:error] [pid 515259:tid 515496] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:43.605440 2026] [security2:error] [pid 515259:tid 515511] [client 68.155.159.216:45954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apPlg2ZcVaai59truiWADgAAAHk"]
[Sun Aug 30 03:10:43.619260 2026] [security2:error] [pid 515259:tid 515343] [remote 38.211.240.4:40702] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "tastylandscape.com"] [uri "/wp-content/plugins/burst-statistics/endpoint.php"] [unique_id "apPlg2ZcVaai59truiWAFAAAOlI"], referer: https://tastylandscape.com/2014/11/29/best-way-propagate-geranium/
[Sun Aug 30 03:10:43.628283 2026] [security2:error] [pid 515259:tid 515424] [client 20.48.251.3:55749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/chosen.php"] [unique_id "apPlg2ZcVaai59truiWAFwAAACI"]
[Sun Aug 30 03:10:43.643949 2026] [security2:error] [pid 517995:tid 518194] [client 20.104.104.62:52072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/xda.php"] [unique_id "apPlg7z-S0xMfHBNth5qcwAAAU0"]
[Sun Aug 30 03:10:43.654104 2026] [security2:error] [pid 515259:tid 515514] [client 20.48.250.41:40898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlg2ZcVaai59truiWAIgAAAHw"]
[Sun Aug 30 03:10:43.654313 2026] [security2:error] [pid 517995:tid 518149] [client 20.63.219.114:15886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/rip.php"] [unique_id "apPlg7z-S0xMfHBNth5qdwAAASA"]
[Sun Aug 30 03:10:43.658618 2026] [security2:error] [pid 515259:tid 515460] [client 20.151.200.44:40871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/sxxb.php"] [unique_id "apPlg2ZcVaai59truiWAJQAAAEY"]
[Sun Aug 30 03:10:43.711394 2026] [authz_core:error] [pid 517995:tid 518211] [client 216.73.216.128:15412] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:43.711835 2026] [authz_core:error] [pid 517995:tid 518211] [client 216.73.216.128:15412] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:43.718810 2026] [authz_core:error] [pid 515259:tid 515404] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:43.719200 2026] [authz_core:error] [pid 515259:tid 515404] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:43.749045 2026] [security2:error] [pid 515259:tid 515515] [client 20.48.251.3:59851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/temp.php"] [unique_id "apPlg2ZcVaai59truiWARQAAAH0"]
[Sun Aug 30 03:10:43.782028 2026] [security2:error] [pid 515259:tid 515433] [client 20.104.104.62:60453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPlg2ZcVaai59truiWATwAAACs"]
[Sun Aug 30 03:10:43.802217 2026] [authz_core:error] [pid 515259:tid 515425] [client 216.73.216.128:2664] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:43.802485 2026] [authz_core:error] [pid 515259:tid 515425] [client 216.73.216.128:2664] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:43.804244 2026] [security2:error] [pid 517995:tid 518239] [client 20.48.250.41:40936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/ff1.php"] [unique_id "apPlg7z-S0xMfHBNth5qgwAAAXo"]
[Sun Aug 30 03:10:43.805158 2026] [security2:error] [pid 515259:tid 515418] [client 20.104.18.15:16903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/mac.php"] [unique_id "apPlg2ZcVaai59truiWAUQAAABw"]
[Sun Aug 30 03:10:43.829203 2026] [autoindex:error] [pid 515259:tid 515439] [client 158.23.184.117:31764] AH01276: Cannot serve directory /home2/alvarons/ccsinversiones.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:10:43.848611 2026] [security2:error] [pid 517995:tid 518252] [client 20.104.49.130:32779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/m.php"] [unique_id "apPlg7z-S0xMfHBNth5qhwAAAYc"]
[Sun Aug 30 03:10:43.848633 2026] [security2:error] [pid 515259:tid 515481] [client 158.23.147.79:61959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/cgi-bin/index.php"] [unique_id "apPlg2ZcVaai59truiWAXAAAAFs"]
[Sun Aug 30 03:10:43.863438 2026] [security2:error] [pid 515259:tid 515438] [client 20.197.61.180:16889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/wp-load.php"] [unique_id "apPlg2ZcVaai59truiWAYwAAADA"]
[Sun Aug 30 03:10:43.878578 2026] [authz_core:error] [pid 517995:tid 518249] [client 66.249.66.72:63550] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:43.878951 2026] [authz_core:error] [pid 517995:tid 518249] [client 66.249.66.72:63550] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:43.894345 2026] [security2:error] [pid 515259:tid 515407] [client 20.104.49.130:57487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/kgoc6awap3napxxxdCdefault.php"] [unique_id "apPlg2ZcVaai59truiWAcAAAABE"]
[Sun Aug 30 03:10:43.902805 2026] [security2:error] [pid 517995:tid 518143] [client 4.205.62.107:16341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlg7z-S0xMfHBNth5qkwAAARo"]
[Sun Aug 30 03:10:43.912027 2026] [security2:error] [pid 517995:tid 518144] [client 20.104.104.62:60466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/t00l.php"] [unique_id "apPlg7z-S0xMfHBNth5qlAAAARs"]
[Sun Aug 30 03:10:43.913052 2026] [security2:error] [pid 517995:tid 518147] [client 20.104.50.220:51015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/admin.php"] [unique_id "apPlg7z-S0xMfHBNth5qlQAAAR4"]
[Sun Aug 30 03:10:43.925629 2026] [security2:error] [pid 515259:tid 515489] [client 219.94.163.141:57440] ModSecurity: Warning. Matched phrase "LWP::Simple" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "bcwinetrends.com"] [uri "/2017/07/03/rose-gold-at-the-acwc/"] [unique_id "apPlg2ZcVaai59truiWAbwAAAGM"]
[Sun Aug 30 03:10:43.938460 2026] [security2:error] [pid 515259:tid 515441] [client 20.48.250.41:40922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/t.php"] [unique_id "apPlg2ZcVaai59truiWAewAAADM"]
[Sun Aug 30 03:10:43.950399 2026] [core:alert] [pid 515259:tid 515487] [client 102.91.93.69:49578] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:10:43.969732 2026] [security2:error] [pid 515259:tid 515432] [client 40.83.93.50:22094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/users.php"] [unique_id "apPlg2ZcVaai59truiWAgwAAACo"]
[Sun Aug 30 03:10:43.980675 2026] [security2:error] [pid 517995:tid 518136] [client 4.205.62.107:36049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/zz.php"] [unique_id "apPlg7z-S0xMfHBNth5qnAAAARM"]
[Sun Aug 30 03:10:43.981038 2026] [security2:error] [pid 515259:tid 515497] [client 158.23.147.79:43881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPlg2ZcVaai59truiWAigAAAGs"]
[Sun Aug 30 03:10:43.993149 2026] [security2:error] [pid 517995:tid 518134] [client 20.104.49.130:51076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/133.php"] [unique_id "apPlg7z-S0xMfHBNth5qoAAAARE"]
[Sun Aug 30 03:10:44.002210 2026] [security2:error] [pid 515259:tid 515396] [client 20.104.50.220:63043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/title.php"] [unique_id "apPlhGZcVaai59truiWAkQAAAAY"]
[Sun Aug 30 03:10:44.016149 2026] [security2:error] [pid 517995:tid 518173] [client 20.48.251.3:56341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/wp-tem.php"] [unique_id "apPlhLz-S0xMfHBNth5qpQAAATg"]
[Sun Aug 30 03:10:44.024498 2026] [security2:error] [pid 515259:tid 515510] [client 20.63.219.114:15259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/ws.php"] [unique_id "apPlhGZcVaai59truiWAnwAAAHg"]
[Sun Aug 30 03:10:44.038797 2026] [security2:error] [pid 517995:tid 518188] [client 20.104.104.62:52076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/ls.php"] [unique_id "apPlhLz-S0xMfHBNth5qqQAAAUc"]
[Sun Aug 30 03:10:44.070103 2026] [security2:error] [pid 515259:tid 515424] [client 20.48.250.41:40933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/erty.php"] [unique_id "apPlhGZcVaai59truiWAuAAAACI"]
[Sun Aug 30 03:10:44.081556 2026] [authz_core:error] [pid 515259:tid 515452] [client 216.73.216.128:64209] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:44.081848 2026] [authz_core:error] [pid 515259:tid 515452] [client 216.73.216.128:64209] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:44.101808 2026] [authz_core:error] [pid 515259:tid 515483] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:44.102065 2026] [authz_core:error] [pid 515259:tid 515483] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:44.126003 2026] [security2:error] [pid 517995:tid 518210] [client 20.104.50.220:29573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/lock360.php"] [unique_id "apPlhLz-S0xMfHBNth5qsAAAAV0"]
[Sun Aug 30 03:10:44.156172 2026] [security2:error] [pid 517995:tid 518246] [client 20.104.18.15:22426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/run.php"] [unique_id "apPlhLz-S0xMfHBNth5qtQAAAYE"]
[Sun Aug 30 03:10:44.157866 2026] [security2:error] [pid 515259:tid 515432] [client 4.205.62.107:61714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/test1.php"] [unique_id "apPlhGZcVaai59truiWA5wAAACo"]
[Sun Aug 30 03:10:44.171448 2026] [security2:error] [pid 515259:tid 515489] [client 20.104.104.62:23377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/css/000.php"] [unique_id "apPlhGZcVaai59truiWA7AAAAGM"]
[Sun Aug 30 03:10:44.184159 2026] [security2:error] [pid 517995:tid 518227] [client 68.155.159.216:57057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apPlhLz-S0xMfHBNth5quAAAAW4"]
[Sun Aug 30 03:10:44.240476 2026] [security2:error] [pid 515259:tid 515410] [client 20.48.250.41:40925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/0x.php"] [unique_id "apPlhGZcVaai59truiWA9gAAABQ"]
[Sun Aug 30 03:10:44.240859 2026] [security2:error] [pid 515259:tid 515514] [client 20.104.50.220:51646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/images/fw.php"] [unique_id "apPlhGZcVaai59truiWA9wAAAHw"]
[Sun Aug 30 03:10:44.249341 2026] [security2:error] [pid 515259:tid 515509] [client 20.104.18.15:18370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/ano.php"] [unique_id "apPlhGZcVaai59truiWA-QAAAHc"]
[Sun Aug 30 03:10:44.255575 2026] [security2:error] [pid 515259:tid 515464] [client 20.151.200.44:28615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/ca.php"] [unique_id "apPlhGZcVaai59truiWA-wAAAEo"]
[Sun Aug 30 03:10:44.268921 2026] [security2:error] [pid 517995:tid 518244] [client 158.23.147.79:58371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/ws.php"] [unique_id "apPlhLz-S0xMfHBNth5qwQAAAX8"]
[Sun Aug 30 03:10:44.327530 2026] [security2:error] [pid 515259:tid 515429] [client 20.104.50.220:5897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/upgrade.php"] [unique_id "apPlhGZcVaai59truiWBGAAAACc"]
[Sun Aug 30 03:10:44.342128 2026] [security2:error] [pid 517995:tid 518173] [client 20.104.104.62:23408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/cy.php"] [unique_id "apPlhLz-S0xMfHBNth5q1QAAATg"]
[Sun Aug 30 03:10:44.350786 2026] [security2:error] [pid 515259:tid 515430] [client 20.104.50.220:32893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/images/alfashell.php"] [unique_id "apPlhGZcVaai59truiWBJwAAACg"]
[Sun Aug 30 03:10:44.354420 2026] [security2:error] [pid 515259:tid 515464] [client 158.23.147.79:57678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apPlhGZcVaai59truiWBKAAAAEo"]
[Sun Aug 30 03:10:44.384563 2026] [security2:error] [pid 517995:tid 518150] [client 20.48.250.41:40846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/66.php"] [unique_id "apPlhLz-S0xMfHBNth5q1wAAASE"]
[Sun Aug 30 03:10:44.409395 2026] [security2:error] [pid 515259:tid 515403] [client 20.63.219.114:15644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/t.php"] [unique_id "apPlhGZcVaai59truiWBPgAAAA0"]
[Sun Aug 30 03:10:44.440559 2026] [security2:error] [pid 515259:tid 515431] [client 216.73.216.128:2664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlhGZcVaai59truiWBTgAAACk"]
[Sun Aug 30 03:10:44.445218 2026] [security2:error] [pid 517995:tid 518251] [client 40.83.93.50:6555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/class.php"] [unique_id "apPlhLz-S0xMfHBNth5q6wAAAYY"]
[Sun Aug 30 03:10:44.446387 2026] [authz_core:error] [pid 515259:tid 515430] [client 66.249.66.32:43430] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:44.446844 2026] [authz_core:error] [pid 515259:tid 515430] [client 66.249.66.32:43430] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:44.473509 2026] [security2:error] [pid 515259:tid 515456] [client 158.23.147.79:61731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/content.php"] [unique_id "apPlhGZcVaai59truiWBVwAAAEI"]
[Sun Aug 30 03:10:44.480132 2026] [security2:error] [pid 515259:tid 515396] [client 20.48.251.3:54732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/ccou.php"] [unique_id "apPlhGZcVaai59truiWBWQAAAAY"]
[Sun Aug 30 03:10:44.505806 2026] [security2:error] [pid 515259:tid 515441] [client 20.104.104.62:52084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/admin.php/pindex.php"] [unique_id "apPlhGZcVaai59truiWBXgAAADM"]
[Sun Aug 30 03:10:44.541760 2026] [authz_core:error] [pid 515259:tid 515457] [client 216.73.216.128:64209] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:44.542239 2026] [authz_core:error] [pid 515259:tid 515457] [client 216.73.216.128:64209] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:44.556613 2026] [security2:error] [pid 515259:tid 515460] [client 20.104.50.220:59547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/v3.php"] [unique_id "apPlhGZcVaai59truiWBdQAAAEY"]
[Sun Aug 30 03:10:44.579296 2026] [security2:error] [pid 517995:tid 518172] [client 20.197.61.180:3237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/wp-settings.php"] [unique_id "apPlhLz-S0xMfHBNth5q9gAAATc"]
[Sun Aug 30 03:10:44.625496 2026] [authz_core:error] [pid 515259:tid 515419] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:44.625829 2026] [authz_core:error] [pid 515259:tid 515419] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:44.632474 2026] [security2:error] [pid 515259:tid 515472] [client 20.48.250.41:40953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/f35.php"] [unique_id "apPlhGZcVaai59truiWBlQAAAFI"]
[Sun Aug 30 03:10:44.632796 2026] [security2:error] [pid 515259:tid 515463] [client 20.104.50.220:17312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/gmo.php"] [unique_id "apPlhGZcVaai59truiWBlwAAAEk"]
[Sun Aug 30 03:10:44.640440 2026] [security2:error] [pid 517995:tid 518231] [client 20.104.104.62:52090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/admin.php/csv.php"] [unique_id "apPlhLz-S0xMfHBNth5q-gAAAXI"]
[Sun Aug 30 03:10:44.668372 2026] [security2:error] [pid 515259:tid 515412] [client 158.23.147.79:61994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-admin/css/index.php"] [unique_id "apPlhGZcVaai59truiWBpQAAABY"]
[Sun Aug 30 03:10:44.707173 2026] [security2:error] [pid 515259:tid 515403] [client 20.104.18.15:44028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/blog.php"] [unique_id "apPlhGZcVaai59truiWBsQAAAA0"]
[Sun Aug 30 03:10:44.714157 2026] [security2:error] [pid 517995:tid 518189] [client 20.104.18.15:64068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/pop.php"] [unique_id "apPlhLz-S0xMfHBNth5rEwAAAUg"]
[Sun Aug 30 03:10:44.733636 2026] [security2:error] [pid 517995:tid 518218] [client 4.205.62.107:17722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/temp.php"] [unique_id "apPlhLz-S0xMfHBNth5rIgAAAWU"]
[Sun Aug 30 03:10:44.742441 2026] [security2:error] [pid 515259:tid 515408] [client 20.104.49.130:36798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/term.php"] [unique_id "apPlhGZcVaai59truiWBwAAAABI"]
[Sun Aug 30 03:10:44.761583 2026] [security2:error] [pid 517995:tid 518243] [client 68.155.159.216:45946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-includes/pomo/index.php"] [unique_id "apPlhLz-S0xMfHBNth5rLgAAAX4"]
[Sun Aug 30 03:10:44.765250 2026] [authz_core:error] [pid 515259:tid 515458] [client 66.249.66.36:51166] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:44.765271 2026] [security2:error] [pid 515259:tid 515406] [client 20.48.251.3:55699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/admin-ajax.php"] [unique_id "apPlhGZcVaai59truiWByAAAABA"]
[Sun Aug 30 03:10:44.765706 2026] [authz_core:error] [pid 515259:tid 515458] [client 66.249.66.36:51166] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:44.773893 2026] [security2:error] [pid 517995:tid 518141] [client 20.104.49.130:59533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/ohct.php"] [unique_id "apPlhLz-S0xMfHBNth5rMgAAARg"]
[Sun Aug 30 03:10:44.775132 2026] [security2:error] [pid 517995:tid 518143] [client 20.104.104.62:60464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/admin.php/700.php"] [unique_id "apPlhLz-S0xMfHBNth5rNAAAARo"]
[Sun Aug 30 03:10:44.777901 2026] [security2:error] [pid 517995:tid 518133] [client 20.63.219.114:2172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/fw.php"] [unique_id "apPlhLz-S0xMfHBNth5rNgAAARA"]
[Sun Aug 30 03:10:44.779314 2026] [security2:error] [pid 517995:tid 518129] [client 20.48.250.41:40945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/wen.php"] [unique_id "apPlhLz-S0xMfHBNth5rNwAAAQw"]
[Sun Aug 30 03:10:44.782917 2026] [security2:error] [pid 517995:tid 518138] [client 158.23.147.79:61976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-admin/images/index.php"] [unique_id "apPlhLz-S0xMfHBNth5rOAAAARU"]
[Sun Aug 30 03:10:44.787314 2026] [security2:error] [pid 517995:tid 518146] [client 4.205.62.107:26965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/setup-config.php"] [unique_id "apPlhLz-S0xMfHBNth5rOwAAAR0"]
[Sun Aug 30 03:10:44.886422 2026] [security2:error] [pid 517995:tid 518249] [client 20.48.251.3:52263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/fm.php"] [unique_id "apPlhLz-S0xMfHBNth5rVwAAAYQ"]
[Sun Aug 30 03:10:44.894068 2026] [security2:error] [pid 517995:tid 518254] [client 219.94.129.223:56682] ModSecurity: Warning. Matched phrase "LWP::Simple" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "bcwinetrends.com"] [uri "/2017/07/03/rose-gold-at-the-acwc/"] [unique_id "apPlhLz-S0xMfHBNth5rVgAAAYk"]
[Sun Aug 30 03:10:44.916065 2026] [security2:error] [pid 515259:tid 515513] [client 40.83.93.50:6196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/auth.php"] [unique_id "apPlhGZcVaai59truiWB4QAAAHs"]
[Sun Aug 30 03:10:44.923669 2026] [security2:error] [pid 517995:tid 518132] [client 20.104.104.62:60473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/admin.php/007x.php"] [unique_id "apPlhLz-S0xMfHBNth5rZAAAAQ8"]
[Sun Aug 30 03:10:44.934404 2026] [security2:error] [pid 515259:tid 515457] [client 20.48.250.41:40904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/inc.php"] [unique_id "apPlhGZcVaai59truiWB5wAAAEM"]
[Sun Aug 30 03:10:44.939658 2026] [security2:error] [pid 515259:tid 515483] [client 20.104.18.15:64725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/simple.php"] [unique_id "apPlhGZcVaai59truiWB6QAAAF0"]
[Sun Aug 30 03:10:44.974869 2026] [security2:error] [pid 515259:tid 515406] [client 20.151.200.44:40873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/dx.php"] [unique_id "apPlhGZcVaai59truiWB-AAAABA"]
[Sun Aug 30 03:10:45.033388 2026] [security2:error] [pid 515259:tid 515515] [client 158.23.147.79:60186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-includes/css/index.php"] [unique_id "apPlhWZcVaai59truiWCEwAAAH0"]
[Sun Aug 30 03:10:45.049110 2026] [security2:error] [pid 515259:tid 515429] [client 4.205.62.107:15995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlhWZcVaai59truiWCGQAAACc"]
[Sun Aug 30 03:10:45.051272 2026] [security2:error] [pid 515259:tid 515451] [client 20.104.50.220:31181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/edit.php"] [unique_id "apPlhWZcVaai59truiWCGgAAAD0"]
[Sun Aug 30 03:10:45.052763 2026] [security2:error] [pid 515259:tid 515390] [client 20.104.104.62:52078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/admin.php/heex.php"] [unique_id "apPlhWZcVaai59truiWCHAAAAAA"]
[Sun Aug 30 03:10:45.067292 2026] [security2:error] [pid 517995:tid 518243] [client 20.48.250.41:40947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/6bcwiqwj.php"] [unique_id "apPlhbz-S0xMfHBNth5rgwAAAX4"]
[Sun Aug 30 03:10:45.085695 2026] [security2:error] [pid 515259:tid 515420] [client 216.73.216.128:64209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_config_quote_replace_string"] [unique_id "apPlhWZcVaai59truiWCKwAAAB4"]
[Sun Aug 30 03:10:45.090357 2026] [authz_core:error] [pid 515259:tid 515393] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:45.090635 2026] [authz_core:error] [pid 515259:tid 515393] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:45.128418 2026] [security2:error] [pid 517995:tid 518147] [client 4.205.62.107:36042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/test.php"] [unique_id "apPlhbz-S0xMfHBNth5rjwAAAR4"]
[Sun Aug 30 03:10:45.129332 2026] [security2:error] [pid 517995:tid 518161] [client 158.23.147.79:43885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/index.php"] [unique_id "apPlhbz-S0xMfHBNth5rkAAAASw"]
[Sun Aug 30 03:10:45.155232 2026] [security2:error] [pid 517995:tid 518168] [client 20.48.251.3:60498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/txets.php"] [unique_id "apPlhbz-S0xMfHBNth5rnAAAATM"]
[Sun Aug 30 03:10:45.179205 2026] [authz_core:error] [pid 517995:tid 518215] [client 66.249.66.44:39986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:45.179665 2026] [authz_core:error] [pid 517995:tid 518215] [client 66.249.66.44:39986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:45.180433 2026] [authz_core:error] [pid 515259:tid 515511] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:45.180906 2026] [authz_core:error] [pid 515259:tid 515511] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:45.181786 2026] [security2:error] [pid 515259:tid 515490] [client 20.104.104.62:36947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/tf.php"] [unique_id "apPlhWZcVaai59truiWCVQAAAGQ"]
[Sun Aug 30 03:10:45.203476 2026] [security2:error] [pid 515259:tid 515482] [client 20.104.50.220:29141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/xmlrpc.php"] [unique_id "apPlhWZcVaai59truiWCXAAAAFw"]
[Sun Aug 30 03:10:45.203804 2026] [security2:error] [pid 517995:tid 518141] [client 20.63.219.114:15265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/test.php"] [unique_id "apPlhbz-S0xMfHBNth5rowAAARg"]
[Sun Aug 30 03:10:45.216243 2026] [security2:error] [pid 515259:tid 515465] [client 20.151.200.44:41959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/xwpg.php"] [unique_id "apPlhWZcVaai59truiWCYQAAAEs"]
[Sun Aug 30 03:10:45.220048 2026] [security2:error] [pid 515259:tid 515492] [client 20.48.250.41:40844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/easy.php"] [unique_id "apPlhWZcVaai59truiWCZQAAAGY"]
[Sun Aug 30 03:10:45.264811 2026] [security2:error] [pid 515259:tid 515463] [client 20.104.50.220:29347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/licensi.php"] [unique_id "apPlhWZcVaai59truiWCcwAAAEk"]
[Sun Aug 30 03:10:45.284163 2026] [core:alert] [pid 517995:tid 518237] [client 223.123.112.114:3254] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:10:45.299265 2026] [security2:error] [pid 515259:tid 515414] [client 4.205.62.107:58462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/bigdump.php"] [unique_id "apPlhWZcVaai59truiWCigAAABg"]
[Sun Aug 30 03:10:45.302548 2026] [security2:error] [pid 515259:tid 515417] [client 20.197.61.180:3329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/themes/wp-signup.php"] [unique_id "apPlhWZcVaai59truiWCiwAAABs"]
[Sun Aug 30 03:10:45.302864 2026] [security2:error] [pid 517995:tid 518167] [client 20.104.18.15:22495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/new.php"] [unique_id "apPlhbz-S0xMfHBNth5rugAAATI"]
[Sun Aug 30 03:10:45.304101 2026] [security2:error] [pid 515259:tid 515392] [client 68.155.159.216:63287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-admin/index.php"] [unique_id "apPlhWZcVaai59truiWCjgAAAAI"]
[Sun Aug 30 03:10:45.315008 2026] [security2:error] [pid 515259:tid 515413] [client 158.23.147.79:43868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/mah.php"] [unique_id "apPlhWZcVaai59truiWCkwAAABc"]
[Sun Aug 30 03:10:45.320242 2026] [security2:error] [pid 515259:tid 515395] [client 20.104.104.62:52093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/update/da222.php"] [unique_id "apPlhWZcVaai59truiWCmAAAAAU"]
[Sun Aug 30 03:10:45.364850 2026] [authz_core:error] [pid 515259:tid 515451] [client 216.73.216.128:21613] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:45.364922 2026] [security2:error] [pid 515259:tid 515463] [client 20.48.250.41:40863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/fresh3.php"] [unique_id "apPlhWZcVaai59truiWCpAAAAEk"]
[Sun Aug 30 03:10:45.365119 2026] [authz_core:error] [pid 515259:tid 515451] [client 216.73.216.128:21613] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:45.387669 2026] [security2:error] [pid 515259:tid 515512] [client 20.104.18.15:18341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/mgrr.php"] [unique_id "apPlhWZcVaai59truiWCswAAAHo"]
[Sun Aug 30 03:10:45.390346 2026] [security2:error] [pid 515259:tid 515478] [client 20.104.49.130:43640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/33.php"] [unique_id "apPlhWZcVaai59truiWCtQAAAFg"]
[Sun Aug 30 03:10:45.393365 2026] [security2:error] [pid 517995:tid 518201] [client 20.104.50.220:42456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/images/alfa.php"] [unique_id "apPlhbz-S0xMfHBNth5r1AAAAVQ"]
[Sun Aug 30 03:10:45.406685 2026] [authz_core:error] [pid 515259:tid 515450] [client 66.249.66.43:47120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:45.406958 2026] [authz_core:error] [pid 515259:tid 515450] [client 66.249.66.43:47120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:45.426197 2026] [security2:error] [pid 515259:tid 515489] [client 40.83.93.50:10750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/adminfuns.php"] [unique_id "apPlhWZcVaai59truiWCygAAAGM"]
[Sun Aug 30 03:10:45.444807 2026] [core:alert] [pid 517995:tid 518211] [client 38.25.81.172:18368] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:10:45.450870 2026] [security2:error] [pid 515259:tid 515483] [client 20.104.104.62:36988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/qi.php"] [unique_id "apPlhWZcVaai59truiWC1wAAAF0"]
[Sun Aug 30 03:10:45.488456 2026] [security2:error] [pid 515259:tid 515416] [client 20.104.50.220:5185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/ajax.php"] [unique_id "apPlhWZcVaai59truiWC5gAAABo"]
[Sun Aug 30 03:10:45.490431 2026] [security2:error] [pid 515259:tid 515432] [client 20.104.18.15:31688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlhWZcVaai59truiWC5wAAACo"]
[Sun Aug 30 03:10:45.491558 2026] [security2:error] [pid 515259:tid 515490] [client 158.23.147.79:43901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-blog-header.php"] [unique_id "apPlhWZcVaai59truiWC6QAAAGQ"]
[Sun Aug 30 03:10:45.499842 2026] [security2:error] [pid 517995:tid 518190] [client 20.48.250.41:40840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/bgymj.php"] [unique_id "apPlhbz-S0xMfHBNth5r4QAAAUk"]
[Sun Aug 30 03:10:45.501077 2026] [security2:error] [pid 517995:tid 518137] [client 20.104.50.220:33583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/images/gelay.php"] [unique_id "apPlhbz-S0xMfHBNth5r4gAAARQ"]
[Sun Aug 30 03:10:45.555055 2026] [security2:error] [pid 517995:tid 518238] [client 20.151.200.44:40840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPlhbz-S0xMfHBNth5r8gAAAXk"]
[Sun Aug 30 03:10:45.569830 2026] [security2:error] [pid 517995:tid 518193] [client 158.23.147.79:2012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPlhbz-S0xMfHBNth5r-AAAAUw"]
[Sun Aug 30 03:10:45.587410 2026] [security2:error] [pid 515259:tid 515483] [client 20.151.200.44:64752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/txets.php"] [unique_id "apPlhWZcVaai59truiWDAQAAAF0"]
[Sun Aug 30 03:10:45.607700 2026] [security2:error] [pid 517995:tid 518185] [client 20.104.104.62:60423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/px.php"] [unique_id "apPlhbz-S0xMfHBNth5sAAAAAUQ"]
[Sun Aug 30 03:10:45.608176 2026] [security2:error] [pid 517995:tid 518231] [client 20.48.251.3:54779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/rum.or.php"] [unique_id "apPlhbz-S0xMfHBNth5sAgAAAXI"]
[Sun Aug 30 03:10:45.610167 2026] [security2:error] [pid 515259:tid 515392] [client 20.63.219.114:13003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/dropdown.php"] [unique_id "apPlhWZcVaai59truiWDBwAAAAI"]
[Sun Aug 30 03:10:45.618071 2026] [authz_core:error] [pid 515259:tid 515404] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:45.618332 2026] [authz_core:error] [pid 515259:tid 515404] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:45.640694 2026] [security2:error] [pid 517995:tid 518179] [client 20.48.250.41:40879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/ws69.php"] [unique_id "apPlhbz-S0xMfHBNth5sDAAAAT4"]
[Sun Aug 30 03:10:45.645783 2026] [security2:error] [pid 517995:tid 518010] [remote 170.64.135.172:54458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.135.64.170.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upcorn.agency"] [uri "/wp-login.php"] [unique_id "apPlhbz-S0xMfHBNth5sDwABFww"]
[Sun Aug 30 03:10:45.645930 2026] [security2:error] [pid 517995:tid 518251] [client 158.23.147.79:58379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/cgi-bin/wp-login.php"] [unique_id "apPlhbz-S0xMfHBNth5sDgAAAYY"]
[Sun Aug 30 03:10:45.654634 2026] [core:alert] [pid 517995:tid 518237] [client 177.37.234.54:24208] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:10:45.704380 2026] [security2:error] [pid 517995:tid 518183] [client 158.23.147.79:43892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apPlhbz-S0xMfHBNth5sLAAAAUI"]
[Sun Aug 30 03:10:45.705133 2026] [security2:error] [pid 517995:tid 518130] [client 20.104.50.220:61650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/v4.php"] [unique_id "apPlhbz-S0xMfHBNth5sLQAAAQ0"]
[Sun Aug 30 03:10:45.741739 2026] [authz_core:error] [pid 515259:tid 515483] [client 216.73.216.128:21613] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:45.742172 2026] [authz_core:error] [pid 515259:tid 515483] [client 216.73.216.128:21613] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:45.744055 2026] [security2:error] [pid 515259:tid 515430] [client 20.104.104.62:36945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/is.php"] [unique_id "apPlhWZcVaai59truiWDOQAAACg"]
[Sun Aug 30 03:10:45.760091 2026] [security2:error] [pid 517995:tid 518199] [client 20.104.49.130:64065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/one.php"] [unique_id "apPlhbz-S0xMfHBNth5sQwAAAVI"]
[Sun Aug 30 03:10:45.762778 2026] [security2:error] [pid 517995:tid 518138] [client 20.104.50.220:16598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "apPlhbz-S0xMfHBNth5sRAAAARU"]
[Sun Aug 30 03:10:45.764031 2026] [security2:error] [pid 515259:tid 515462] [client 68.155.159.216:52560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apPlhWZcVaai59truiWDQAAAAEg"]
[Sun Aug 30 03:10:45.803022 2026] [security2:error] [pid 517995:tid 518139] [client 20.48.250.41:40869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/ccs.php"] [unique_id "apPlhbz-S0xMfHBNth5sRwAAARY"]
[Sun Aug 30 03:10:45.813330 2026] [security2:error] [pid 515259:tid 515489] [client 20.104.49.130:58178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/abc.php"] [unique_id "apPlhWZcVaai59truiWDTgAAAGM"]
[Sun Aug 30 03:10:45.818061 2026] [security2:error] [pid 515259:tid 515497] [client 158.23.147.79:43877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-admin/user/index.php"] [unique_id "apPlhWZcVaai59truiWDUAAAAGs"]
[Sun Aug 30 03:10:45.827551 2026] [security2:error] [pid 515259:tid 515420] [client 20.104.49.130:54187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/yawa.php"] [unique_id "apPlhWZcVaai59truiWDVQAAAB4"]
[Sun Aug 30 03:10:45.834163 2026] [authz_core:error] [pid 517995:tid 518178] [client 216.73.216.128:15412] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:45.834487 2026] [authz_core:error] [pid 517995:tid 518178] [client 216.73.216.128:15412] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:45.849262 2026] [security2:error] [pid 515259:tid 515436] [client 20.104.18.15:64101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/503.php"] [unique_id "apPlhWZcVaai59truiWDXAAAAC4"]
[Sun Aug 30 03:10:45.855094 2026] [security2:error] [pid 515259:tid 515392] [client 20.104.18.15:43916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/wp-admin/js/wp-load.php"] [unique_id "apPlhWZcVaai59truiWDXwAAAAI"]
[Sun Aug 30 03:10:45.865800 2026] [security2:error] [pid 517995:tid 518212] [client 4.205.62.107:16798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/fm.php"] [unique_id "apPlhbz-S0xMfHBNth5sTgAAAV8"]
[Sun Aug 30 03:10:45.874194 2026] [authz_core:error] [pid 517995:tid 518136] [client 66.249.66.75:37474] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:45.874452 2026] [authz_core:error] [pid 517995:tid 518136] [client 66.249.66.75:37474] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:45.881790 2026] [security2:error] [pid 515259:tid 515507] [client 20.104.104.62:60455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/od.php"] [unique_id "apPlhWZcVaai59truiWDbQAAAHU"]
[Sun Aug 30 03:10:45.895395 2026] [security2:error] [pid 515259:tid 515429] [client 59.106.19.195:55932] ModSecurity: Warning. Matched phrase "LWP::Simple" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "bcwinetrends.com"] [uri "/2017/07/03/rose-gold-at-the-acwc/"] [unique_id "apPlhWZcVaai59truiWDagAAACc"]
[Sun Aug 30 03:10:45.902897 2026] [security2:error] [pid 515259:tid 515490] [client 20.48.251.3:59277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/ms.php"] [unique_id "apPlhWZcVaai59truiWDdAAAAGQ"]
[Sun Aug 30 03:10:45.905065 2026] [security2:error] [pid 517995:tid 518253] [client 40.83.93.50:22120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/rip.php"] [unique_id "apPlhbz-S0xMfHBNth5sZwAAAYg"]
[Sun Aug 30 03:10:45.925738 2026] [security2:error] [pid 515259:tid 515410] [client 68.155.159.216:46060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/nf_tracking.php"] [unique_id "apPlhWZcVaai59truiWDfQAAABQ"]
[Sun Aug 30 03:10:45.934800 2026] [security2:error] [pid 517995:tid 518140] [client 20.48.250.41:40921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/mar.php"] [unique_id "apPlhbz-S0xMfHBNth5scQAAARc"]
[Sun Aug 30 03:10:45.980468 2026] [security2:error] [pid 517995:tid 518223] [client 20.151.200.44:64784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/wp-login.php"] [unique_id "apPlhbz-S0xMfHBNth5sggAAAWo"]
[Sun Aug 30 03:10:46.008792 2026] [security2:error] [pid 515259:tid 515435] [client 20.197.61.180:3647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/updraft/about.php"] [unique_id "apPlhmZcVaai59truiWDogAAAC0"]
[Sun Aug 30 03:10:46.014867 2026] [security2:error] [pid 517995:tid 518188] [client 20.48.251.3:59881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/tinyfilemanager.php"] [unique_id "apPlhrz-S0xMfHBNth5snAAAAUc"]
[Sun Aug 30 03:10:46.016412 2026] [security2:error] [pid 517995:tid 518220] [client 20.104.104.62:23418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/wp-the.php"] [unique_id "apPlhrz-S0xMfHBNth5snwAAAWc"]
[Sun Aug 30 03:10:46.078599 2026] [security2:error] [pid 517995:tid 518235] [client 20.104.18.15:16923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/xty.php"] [unique_id "apPlhrz-S0xMfHBNth5suAAAAXY"]
[Sun Aug 30 03:10:46.092872 2026] [authz_core:error] [pid 515259:tid 515473] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:46.093170 2026] [authz_core:error] [pid 515259:tid 515473] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:46.100312 2026] [security2:error] [pid 517995:tid 518185] [client 20.48.250.41:40934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/ccu.php"] [unique_id "apPlhrz-S0xMfHBNth5sxQAAAUQ"]
[Sun Aug 30 03:10:46.100866 2026] [security2:error] [pid 515259:tid 515454] [client 20.63.219.114:19176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/mar.php"] [unique_id "apPlhmZcVaai59truiWDvQAAAEA"]
[Sun Aug 30 03:10:46.124319 2026] [security2:error] [pid 517995:tid 518014] [remote 170.64.135.172:54458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.135.64.170.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "upcorn.agency"] [uri "/wp-login.php"] [unique_id "apPlhrz-S0xMfHBNth5szAABXBA"], referer: https://upcorn.agency/wp-login.php
[Sun Aug 30 03:10:46.145413 2026] [security2:error] [pid 517995:tid 518232] [client 20.104.104.62:60434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/wt.php"] [unique_id "apPlhrz-S0xMfHBNth5s0wAAAXM"]
[Sun Aug 30 03:10:46.191988 2026] [security2:error] [pid 517995:tid 518149] [client 20.104.49.130:34526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/ms-edit.php"] [unique_id "apPlhrz-S0xMfHBNth5s7wAAASA"]
[Sun Aug 30 03:10:46.205608 2026] [security2:error] [pid 515259:tid 515429] [client 20.104.50.220:59380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-content/admin.php"] [unique_id "apPlhmZcVaai59truiWD2gAAACc"]
[Sun Aug 30 03:10:46.206574 2026] [security2:error] [pid 515259:tid 515460] [client 4.205.62.107:15944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/cloud.php"] [unique_id "apPlhmZcVaai59truiWD3AAAAEY"]
[Sun Aug 30 03:10:46.216760 2026] [security2:error] [pid 517995:tid 518178] [client 158.23.147.79:60200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-content/cong.php"] [unique_id "apPlhrz-S0xMfHBNth5s9AAAAT0"]
[Sun Aug 30 03:10:46.236372 2026] [security2:error] [pid 517995:tid 518227] [client 20.104.49.130:63577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/load.php"] [unique_id "apPlhrz-S0xMfHBNth5s-AAAAW4"]
[Sun Aug 30 03:10:46.250986 2026] [security2:error] [pid 517995:tid 518193] [client 158.23.147.79:61971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/plugins.php"] [unique_id "apPlhrz-S0xMfHBNth5tBwAAAUw"]
[Sun Aug 30 03:10:46.258638 2026] [security2:error] [pid 517995:tid 518250] [client 20.48.250.41:40940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/ak.php"] [unique_id "apPlhrz-S0xMfHBNth5tCwAAAYU"]
[Sun Aug 30 03:10:46.272344 2026] [security2:error] [pid 517995:tid 518130] [client 4.205.62.107:36599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/cloud.php"] [unique_id "apPlhrz-S0xMfHBNth5tFQAAAQ0"]
[Sun Aug 30 03:10:46.275131 2026] [security2:error] [pid 515259:tid 515465] [client 20.104.104.62:60443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/im.php"] [unique_id "apPlhmZcVaai59truiWD6QAAAEs"]
[Sun Aug 30 03:10:46.318267 2026] [security2:error] [pid 517995:tid 518193] [client 20.48.251.3:56343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/time.php"] [unique_id "apPlhrz-S0xMfHBNth5tMAAAAUw"]
[Sun Aug 30 03:10:46.343052 2026] [authz_core:error] [pid 515259:tid 515508] [client 216.73.216.128:7620] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:46.343404 2026] [authz_core:error] [pid 515259:tid 515508] [client 216.73.216.128:7620] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:46.358579 2026] [security2:error] [pid 517995:tid 518198] [client 20.104.50.220:28682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/pass.php"] [unique_id "apPlhrz-S0xMfHBNth5tSQAAAVE"]
[Sun Aug 30 03:10:46.380712 2026] [security2:error] [pid 517995:tid 518158] [client 40.83.93.50:6359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/ws.php"] [unique_id "apPlhrz-S0xMfHBNth5tUQAAASk"]
[Sun Aug 30 03:10:46.404780 2026] [security2:error] [pid 517995:tid 518184] [client 20.104.50.220:29161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/Marvins.php"] [unique_id "apPlhrz-S0xMfHBNth5tZwAAAUM"]
[Sun Aug 30 03:10:46.405340 2026] [security2:error] [pid 517995:tid 518250] [client 20.104.104.62:52094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/file.php"] [unique_id "apPlhrz-S0xMfHBNth5taAAAAYU"]
[Sun Aug 30 03:10:46.412290 2026] [security2:error] [pid 517995:tid 518127] [client 20.48.250.41:40941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/lib.php"] [unique_id "apPlhrz-S0xMfHBNth5tbQAAAQo"]
[Sun Aug 30 03:10:46.420902 2026] [security2:error] [pid 515259:tid 515463] [client 20.151.200.44:28657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/pb.php"] [unique_id "apPlhmZcVaai59truiWEGQAAAEk"]
[Sun Aug 30 03:10:46.427568 2026] [security2:error] [pid 517995:tid 518239] [client 20.151.200.44:64705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/wp-access.php"] [unique_id "apPlhrz-S0xMfHBNth5tcAAAAXo"]
[Sun Aug 30 03:10:46.437229 2026] [security2:error] [pid 515259:tid 515458] [client 4.205.62.107:38420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/wdf.php"] [unique_id "apPlhmZcVaai59truiWEIgAAAEQ"]
[Sun Aug 30 03:10:46.442099 2026] [security2:error] [pid 517995:tid 518138] [client 68.155.159.216:63278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPlhrz-S0xMfHBNth5tdQAAARU"]
[Sun Aug 30 03:10:46.455488 2026] [security2:error] [pid 517995:tid 518212] [client 20.104.18.15:22525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/inx.php"] [unique_id "apPlhrz-S0xMfHBNth5teQAAAV8"]
[Sun Aug 30 03:10:46.523776 2026] [authz_core:error] [pid 517995:tid 518178] [client 66.249.66.38:48652] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:46.524185 2026] [authz_core:error] [pid 517995:tid 518178] [client 66.249.66.38:48652] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:46.544569 2026] [security2:error] [pid 517995:tid 518187] [client 20.104.104.62:60458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/ca.php"] [unique_id "apPlhrz-S0xMfHBNth5tiwAAAUY"]
[Sun Aug 30 03:10:46.550127 2026] [security2:error] [pid 515259:tid 515450] [client 20.104.50.220:63488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/images/alfashell.php"] [unique_id "apPlhmZcVaai59truiWEQgAAADw"]
[Sun Aug 30 03:10:46.554021 2026] [security2:error] [pid 517995:tid 518230] [client 20.104.18.15:18380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/mac.php"] [unique_id "apPlhrz-S0xMfHBNth5tkAAAAXE"]
[Sun Aug 30 03:10:46.556053 2026] [security2:error] [pid 517995:tid 518219] [client 158.23.147.79:43895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apPlhrz-S0xMfHBNth5tlQAAAWY"]
[Sun Aug 30 03:10:46.578420 2026] [authz_core:error] [pid 515259:tid 515407] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:10:46.578751 2026] [authz_core:error] [pid 515259:tid 515407] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:10:46.581009 2026] [security2:error] [pid 517995:tid 518176] [client 20.48.250.41:40884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/wp-style.php"] [unique_id "apPlhrz-S0xMfHBNth5tpwAAATs"]
[Sun Aug 30 03:10:46.586219 2026] [security2:error] [pid 517995:tid 518166] [client 20.63.219.114:2587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/css.php"] [unique_id "apPlhrz-S0xMfHBNth5tqQAAATE"]
[Sun Aug 30 03:10:46.626278 2026] [security2:error] [pid 517995:tid 518149] [client 20.151.200.44:40942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/xda.php"] [unique_id "apPlhrz-S0xMfHBNth5ttQAAASA"]
[Sun Aug 30 03:10:46.641240 2026] [security2:error] [pid 517995:tid 518192] [client 20.104.50.220:5602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-mail.php"] [unique_id "apPlhrz-S0xMfHBNth5twAAAAUs"]
[Sun Aug 30 03:10:46.656843 2026] [security2:error] [pid 517995:tid 518244] [client 20.104.50.220:33163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/images/byps.php"] [unique_id "apPlhrz-S0xMfHBNth5tywAAAX8"]
[Sun Aug 30 03:10:46.659668 2026] [security2:error] [pid 515259:tid 515418] [client 20.104.18.15:31711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlhmZcVaai59truiWEaQAAABw"]
[Sun Aug 30 03:10:46.667829 2026] [security2:error] [pid 515259:tid 515477] [client 158.23.147.79:61977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/goat1.php"] [unique_id "apPlhmZcVaai59truiWEbQAAAFc"]
[Sun Aug 30 03:10:46.671272 2026] [authz_core:error] [pid 515259:tid 515451] [client 216.73.216.128:21613] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:46.671751 2026] [authz_core:error] [pid 515259:tid 515451] [client 216.73.216.128:21613] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:46.681314 2026] [authz_core:error] [pid 517995:tid 518142] [client 66.249.66.74:55110] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:46.681794 2026] [authz_core:error] [pid 517995:tid 518142] [client 66.249.66.74:55110] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:46.688980 2026] [security2:error] [pid 517995:tid 518140] [client 20.104.104.62:52064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/pb.php"] [unique_id "apPlhrz-S0xMfHBNth5t2QAAARc"]
[Sun Aug 30 03:10:46.708762 2026] [security2:error] [pid 517995:tid 518022] [remote 112.78.134.58:49384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.134.78.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hillaryboucher.com"] [uri "/wp-login.php"] [unique_id "apPlhrz-S0xMfHBNth5t3gABfBg"]
[Sun Aug 30 03:10:46.708969 2026] [authz_core:error] [pid 515259:tid 515392] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:46.709414 2026] [authz_core:error] [pid 515259:tid 515392] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:46.736946 2026] [security2:error] [pid 517995:tid 518224] [client 20.197.61.180:3629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/upgrade-temp-backup/min.php"] [unique_id "apPlhrz-S0xMfHBNth5t-gAAAWs"]
[Sun Aug 30 03:10:46.749178 2026] [security2:error] [pid 517995:tid 518231] [client 20.48.251.3:65483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/xmy.php"] [unique_id "apPlhrz-S0xMfHBNth5uBAAAAXI"]
[Sun Aug 30 03:10:46.754868 2026] [security2:error] [pid 517995:tid 518140] [client 20.151.200.44:41946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/sxxb.php"] [unique_id "apPlhrz-S0xMfHBNth5uCgAAARc"]
[Sun Aug 30 03:10:46.771756 2026] [security2:error] [pid 515259:tid 515499] [client 20.48.250.41:40919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/browse.php"] [unique_id "apPlhmZcVaai59truiWEkgAAAG0"]
[Sun Aug 30 03:10:46.791469 2026] [security2:error] [pid 515259:tid 515456] [client 4.205.62.107:25878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/wp-admin/sc.php"] [unique_id "apPlhmZcVaai59truiWElQAAAEI"]
[Sun Aug 30 03:10:46.823031 2026] [security2:error] [pid 515259:tid 515513] [client 20.104.104.62:23409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/pk.php"] [unique_id "apPlhmZcVaai59truiWEoQAAAHs"]
[Sun Aug 30 03:10:46.855034 2026] [authz_core:error] [pid 515259:tid 515459] [client 216.73.216.128:35448] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:46.855557 2026] [authz_core:error] [pid 515259:tid 515459] [client 216.73.216.128:35448] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:46.861920 2026] [security2:error] [pid 515259:tid 515507] [client 158.23.147.79:52252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apPlhmZcVaai59truiWEuAAAAHU"]
[Sun Aug 30 03:10:46.878867 2026] [security2:error] [pid 517995:tid 518236] [client 40.83.93.50:6388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/t.php"] [unique_id "apPlhrz-S0xMfHBNth5uLQAAAXc"]
[Sun Aug 30 03:10:46.900956 2026] [security2:error] [pid 517995:tid 518250] [client 20.104.50.220:16587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/css/index.php"] [unique_id "apPlhrz-S0xMfHBNth5uPAAAAYU"]
[Sun Aug 30 03:10:46.908452 2026] [security2:error] [pid 517995:tid 518230] [client 20.104.50.220:59571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wikindex.php"] [unique_id "apPlhrz-S0xMfHBNth5uRAAAAXE"]
[Sun Aug 30 03:10:46.938951 2026] [security2:error] [pid 517995:tid 518176] [client 20.48.250.41:40897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/zoo.php"] [unique_id "apPlhrz-S0xMfHBNth5uTgAAATs"]
[Sun Aug 30 03:10:46.951728 2026] [security2:error] [pid 517995:tid 518140] [client 20.104.104.62:52036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/ft.php"] [unique_id "apPlhrz-S0xMfHBNth5uWgAAARc"]
[Sun Aug 30 03:10:46.960024 2026] [security2:error] [pid 517995:tid 518161] [client 20.151.200.44:64704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/wp-content/admin.php"] [unique_id "apPlhrz-S0xMfHBNth5uXQAAASw"]
[Sun Aug 30 03:10:46.961961 2026] [security2:error] [pid 517995:tid 518030] [remote 47.128.25.230:41106] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gracelikestogarden.com"] [uri "/wildflowers-of-the-wild-atlantic-way/cowslips/"] [unique_id "apPlhrz-S0xMfHBNth5uYAABdyA"]
[Sun Aug 30 03:10:46.987006 2026] [security2:error] [pid 515259:tid 515460] [client 20.104.18.15:64803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/fxp.php"] [unique_id "apPlhmZcVaai59truiWE4gAAAEY"]
[Sun Aug 30 03:10:47.000685 2026] [security2:error] [pid 515259:tid 515473] [client 20.104.18.15:44007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/robot.php"] [unique_id "apPlhmZcVaai59truiWE6AAAAFM"]
[Sun Aug 30 03:10:47.003422 2026] [security2:error] [pid 515259:tid 515393] [client 4.205.62.107:17291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/tinyfilemanager.php"] [unique_id "apPlh2ZcVaai59truiWE6gAAAAM"]
[Sun Aug 30 03:10:47.032710 2026] [security2:error] [pid 515259:tid 515465] [client 68.155.159.216:46039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wzy.php"] [unique_id "apPlh2ZcVaai59truiWE-AAAAEs"]
[Sun Aug 30 03:10:47.039837 2026] [security2:error] [pid 515259:tid 515509] [client 20.48.251.3:59330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/fucku.php"] [unique_id "apPlh2ZcVaai59truiWE_AAAAHc"]
[Sun Aug 30 03:10:47.044663 2026] [security2:error] [pid 517995:tid 518181] [client 20.104.49.130:36740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/sd.php"] [unique_id "apPlh7z-S0xMfHBNth5ukQAAAUA"]
[Sun Aug 30 03:10:47.074412 2026] [security2:error] [pid 515259:tid 515398] [client 158.23.147.79:57726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/images/index.php"] [unique_id "apPlh2ZcVaai59truiWFDwAAAAg"]
[Sun Aug 30 03:10:47.082176 2026] [security2:error] [pid 515259:tid 515404] [client 20.104.104.62:23411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/wp-ver.php"] [unique_id "apPlh2ZcVaai59truiWFFwAAAA4"]
[Sun Aug 30 03:10:47.084301 2026] [authz_core:error] [pid 515259:tid 515444] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:10:47.084908 2026] [authz_core:error] [pid 515259:tid 515444] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:10:47.110869 2026] [security2:error] [pid 515259:tid 515415] [client 158.23.147.79:58370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPlh2ZcVaai59truiWFIgAAABk"]
[Sun Aug 30 03:10:47.112428 2026] [security2:error] [pid 515259:tid 515500] [client 20.48.250.41:40926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/elp.php"] [unique_id "apPlh2ZcVaai59truiWFJQAAAG4"]
[Sun Aug 30 03:10:47.134799 2026] [authz_core:error] [pid 515259:tid 515465] [client 216.73.216.128:35448] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:47.135077 2026] [authz_core:error] [pid 515259:tid 515465] [client 216.73.216.128:35448] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:47.159323 2026] [security2:error] [pid 515259:tid 515487] [client 20.48.251.3:59871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/05.php"] [unique_id "apPlh2ZcVaai59truiWFPQAAAGE"]
[Sun Aug 30 03:10:47.171367 2026] [security2:error] [pid 517995:tid 518138] [client 158.23.147.79:52247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-admin/network/index.php"] [unique_id "apPlh7z-S0xMfHBNth5u1gAAARU"]
[Sun Aug 30 03:10:47.191626 2026] [security2:error] [pid 517995:tid 518045] [remote 112.78.134.58:49384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.134.78.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hillaryboucher.com"] [uri "/wp-login.php"] [unique_id "apPlh7z-S0xMfHBNth5u5AABhi8"], referer: https://hillaryboucher.com/wp-login.php
[Sun Aug 30 03:10:47.210567 2026] [security2:error] [pid 517995:tid 518171] [client 20.104.104.62:60475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/ah24.php"] [unique_id "apPlh7z-S0xMfHBNth5u7wAAATY"]
[Sun Aug 30 03:10:47.214614 2026] [security2:error] [pid 517995:tid 518143] [client 20.63.219.114:19193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/autoload_classmap.php"] [unique_id "apPlh7z-S0xMfHBNth5u8AAAARo"]
[Sun Aug 30 03:10:47.229813 2026] [security2:error] [pid 517995:tid 518132] [client 20.104.18.15:16976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/sallu.php"] [unique_id "apPlh7z-S0xMfHBNth5u9AAAAQ8"]
[Sun Aug 30 03:10:47.258112 2026] [security2:error] [pid 517995:tid 518252] [client 20.48.250.41:40837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/666.php"] [unique_id "apPlh7z-S0xMfHBNth5vAQAAAYc"]
[Sun Aug 30 03:10:47.283838 2026] [security2:error] [pid 515259:tid 515427] [client 20.104.49.130:52114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/abcd.php"] [unique_id "apPlh2ZcVaai59truiWFZgAAACU"]
[Sun Aug 30 03:10:47.341640 2026] [security2:error] [pid 515259:tid 515404] [client 20.104.50.220:50372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/f6.php"] [unique_id "apPlh2ZcVaai59truiWFjQAAAA4"]
[Sun Aug 30 03:10:47.346887 2026] [security2:error] [pid 515259:tid 515470] [client 20.104.104.62:52034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPlh2ZcVaai59truiWFkAAAAFA"]
[Sun Aug 30 03:10:47.356593 2026] [security2:error] [pid 515259:tid 515427] [client 4.205.62.107:15985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/kerang.php"] [unique_id "apPlh2ZcVaai59truiWFlgAAACU"]
[Sun Aug 30 03:10:47.358513 2026] [security2:error] [pid 517995:tid 518133] [client 40.83.93.50:6147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/fw.php"] [unique_id "apPlh7z-S0xMfHBNth5vGgAAARA"]
[Sun Aug 30 03:10:47.375186 2026] [security2:error] [pid 515259:tid 515481] [client 20.151.200.44:65398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/log.php"] [unique_id "apPlh2ZcVaai59truiWFowAAAFs"]
[Sun Aug 30 03:10:47.407739 2026] [authz_core:error] [pid 515259:tid 515454] [client 216.73.216.128:5489] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:47.408029 2026] [authz_core:error] [pid 515259:tid 515454] [client 216.73.216.128:5489] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:47.417703 2026] [security2:error] [pid 517995:tid 518246] [client 4.205.62.107:36569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/asdf.php"] [unique_id "apPlh7z-S0xMfHBNth5vKQAAAYE"]
[Sun Aug 30 03:10:47.429531 2026] [security2:error] [pid 517995:tid 518242] [client 20.151.200.44:40835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPlh7z-S0xMfHBNth5vLQAAAX0"]
[Sun Aug 30 03:10:47.433251 2026] [security2:error] [pid 517995:tid 518210] [client 20.48.250.41:40902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/knmt.php"] [unique_id "apPlh7z-S0xMfHBNth5vLwAAAV0"]
[Sun Aug 30 03:10:47.449389 2026] [security2:error] [pid 517995:tid 518138] [client 20.197.61.180:12271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/upgrade-temp-backup/pk.php"] [unique_id "apPlh7z-S0xMfHBNth5vMwAAARU"]
[Sun Aug 30 03:10:47.461095 2026] [security2:error] [pid 515259:tid 515492] [client 20.48.251.3:56383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/doc.php"] [unique_id "apPlh2ZcVaai59truiWF1gAAAGY"]
[Sun Aug 30 03:10:47.478544 2026] [security2:error] [pid 515259:tid 515494] [client 20.104.104.62:36979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.giantcameraphotobooth.com"] [uri "/waf.php"] [unique_id "apPlh2ZcVaai59truiWF3AAAAGg"]
[Sun Aug 30 03:10:47.492638 2026] [security2:error] [pid 515259:tid 515478] [client 20.104.50.220:28696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/Cpanel.php"] [unique_id "apPlh2ZcVaai59truiWF5QAAAFg"]
[Sun Aug 30 03:10:47.496908 2026] [authz_core:error] [pid 515259:tid 515498] [client 216.73.216.128:21613] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:47.497206 2026] [authz_core:error] [pid 515259:tid 515498] [client 216.73.216.128:21613] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:47.538068 2026] [security2:error] [pid 515259:tid 515449] [client 79.133.42.228:53046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.42.133.79.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "flashflooring.co.uk"] [uri "/wp-login.php"] [unique_id "apPlh2ZcVaai59truiWF7QAAADs"]
[Sun Aug 30 03:10:47.556445 2026] [security2:error] [pid 517995:tid 518164] [client 20.104.50.220:62796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/lolz.php"] [unique_id "apPlh7z-S0xMfHBNth5vSwAAAS8"]
[Sun Aug 30 03:10:47.573005 2026] [security2:error] [pid 517995:tid 518179] [client 4.205.62.107:58250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/bb.php"] [unique_id "apPlh7z-S0xMfHBNth5vWAAAAT4"]
[Sun Aug 30 03:10:47.575283 2026] [security2:error] [pid 517995:tid 518209] [client 68.155.159.216:63234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/about.php"] [unique_id "apPlh7z-S0xMfHBNth5vWgAAAVw"]
[Sun Aug 30 03:10:47.586159 2026] [authz_core:error] [pid 515259:tid 515512] [client 66.249.66.192:46211] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:47.586351 2026] [security2:error] [pid 517995:tid 518208] [client 20.104.18.15:22442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/vpn.php"] [unique_id "apPlh7z-S0xMfHBNth5vZAAAAVs"]
[Sun Aug 30 03:10:47.586689 2026] [authz_core:error] [pid 515259:tid 515512] [client 66.249.66.192:46211] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:47.621621 2026] [authz_core:error] [pid 515259:tid 515401] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:10:47.621919 2026] [authz_core:error] [pid 515259:tid 515401] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:10:47.636626 2026] [security2:error] [pid 515259:tid 515487] [client 20.48.250.41:40913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/sbhu.php"] [unique_id "apPlh2ZcVaai59truiWGFgAAAGE"]
[Sun Aug 30 03:10:47.645918 2026] [security2:error] [pid 517995:tid 518236] [client 20.104.49.130:54201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/dex.php"] [unique_id "apPlh7z-S0xMfHBNth5vhwAAAXc"]
[Sun Aug 30 03:10:47.658684 2026] [security2:error] [pid 517995:tid 518174] [client 20.104.49.130:52467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/tool.php"] [unique_id "apPlh7z-S0xMfHBNth5vkAAAATk"]
[Sun Aug 30 03:10:47.697874 2026] [security2:error] [pid 517995:tid 518146] [client 20.104.18.15:18386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/simple.php"] [unique_id "apPlh7z-S0xMfHBNth5vrAAAAR0"]
[Sun Aug 30 03:10:47.702293 2026] [security2:error] [pid 517995:tid 518245] [client 20.104.50.220:51599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/images/gelay.php"] [unique_id "apPlh7z-S0xMfHBNth5vsQAAAYA"]
[Sun Aug 30 03:10:47.706096 2026] [authz_core:error] [pid 517995:tid 518182] [client 66.249.66.68:40202] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:47.706560 2026] [authz_core:error] [pid 517995:tid 518182] [client 66.249.66.68:40202] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:47.724938 2026] [security2:error] [pid 517995:tid 518194] [client 20.151.200.44:40903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/t00l.php"] [unique_id "apPlh7z-S0xMfHBNth5vxAAAAU0"]
[Sun Aug 30 03:10:47.745896 2026] [authz_core:error] [pid 515259:tid 515493] [client 66.249.66.194:63249] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:47.746406 2026] [authz_core:error] [pid 515259:tid 515493] [client 66.249.66.194:63249] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:47.756317 2026] [authz_core:error] [pid 517995:tid 518253] [client 66.249.66.196:52295] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:47.756652 2026] [authz_core:error] [pid 517995:tid 518253] [client 66.249.66.196:52295] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:47.763486 2026] [security2:error] [pid 517995:tid 518190] [client 20.63.219.114:15257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/info.php"] [unique_id "apPlh7z-S0xMfHBNth5v4AAAAUk"]
[Sun Aug 30 03:10:47.763872 2026] [security2:error] [pid 517995:tid 518181] [client 20.48.250.41:40842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/a332.php"] [unique_id "apPlh7z-S0xMfHBNth5v4QAAAUA"]
[Sun Aug 30 03:10:47.784494 2026] [security2:error] [pid 517995:tid 518142] [client 195.178.110.247:64902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.michaelegenolf.com"] [uri "/index.php"] [unique_id "apPlh7z-S0xMfHBNth5v6gAAARk"]
[Sun Aug 30 03:10:47.796434 2026] [security2:error] [pid 517995:tid 518228] [client 20.104.50.220:5906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/dashboard.php"] [unique_id "apPlh7z-S0xMfHBNth5v7wAAAW8"]
[Sun Aug 30 03:10:47.798174 2026] [security2:error] [pid 517995:tid 518130] [client 20.104.50.220:33331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/images/bypass.php"] [unique_id "apPlh7z-S0xMfHBNth5v8AAAAQ0"]
[Sun Aug 30 03:10:47.816734 2026] [security2:error] [pid 517995:tid 518213] [client 158.23.147.79:61981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apPlh7z-S0xMfHBNth5v9wAAAWA"]
[Sun Aug 30 03:10:47.834921 2026] [security2:error] [pid 515259:tid 515439] [client 20.104.18.15:31633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/media.php"] [unique_id "apPlh2ZcVaai59truiWGTgAAADE"]
[Sun Aug 30 03:10:47.874711 2026] [security2:error] [pid 517995:tid 518221] [client 20.151.200.44:40838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/ls.php"] [unique_id "apPlh7z-S0xMfHBNth5wEQAAAWg"]
[Sun Aug 30 03:10:47.885574 2026] [security2:error] [pid 517995:tid 518224] [client 20.48.251.3:64264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/ms-edit.php"] [unique_id "apPlh7z-S0xMfHBNth5wFgAAAWs"]
[Sun Aug 30 03:10:47.913360 2026] [security2:error] [pid 517995:tid 518251] [client 40.83.93.50:22095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/test.php"] [unique_id "apPlh7z-S0xMfHBNth5wNAAAAYY"]
[Sun Aug 30 03:10:47.917176 2026] [security2:error] [pid 517995:tid 518188] [client 158.23.147.79:56495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apPlh7z-S0xMfHBNth5wOAAAAUc"]
[Sun Aug 30 03:10:47.938464 2026] [security2:error] [pid 517995:tid 518244] [client 4.205.62.107:25497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/debug.php"] [unique_id "apPlh7z-S0xMfHBNth5wPwAAAX8"]
[Sun Aug 30 03:10:47.943836 2026] [security2:error] [pid 517995:tid 518153] [client 20.48.250.41:40915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/ws66.php"] [unique_id "apPlh7z-S0xMfHBNth5wSAAAASQ"]
[Sun Aug 30 03:10:47.948092 2026] [security2:error] [pid 517995:tid 518132] [client 195.178.110.247:64740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.michaelegenolf.com"] [uri "/index.php"] [unique_id "apPlh7z-S0xMfHBNth5wTAAAAQ8"]
[Sun Aug 30 03:10:47.954242 2026] [authz_core:error] [pid 517995:tid 518189] [client 66.249.66.65:42353] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:47.954763 2026] [authz_core:error] [pid 517995:tid 518189] [client 66.249.66.65:42353] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:48.009303 2026] [security2:error] [pid 517995:tid 518167] [client 20.151.200.44:65453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/xwpg.php"] [unique_id "apPliLz-S0xMfHBNth5wdgAAATI"]
[Sun Aug 30 03:10:48.037369 2026] [security2:error] [pid 517995:tid 518145] [client 20.104.50.220:17333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-includes/SimplePie/wp-login.php"] [unique_id "apPliLz-S0xMfHBNth5wpgAAARw"]
[Sun Aug 30 03:10:48.051148 2026] [security2:error] [pid 517995:tid 518169] [client 20.104.50.220:61689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-2019.php"] [unique_id "apPliLz-S0xMfHBNth5wsgAAATQ"]
[Sun Aug 30 03:10:48.077091 2026] [authz_core:error] [pid 515259:tid 515512] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:10:48.077387 2026] [authz_core:error] [pid 515259:tid 515512] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:10:48.093511 2026] [security2:error] [pid 517995:tid 518149] [client 158.23.147.79:61990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/.well-knownold/index.php"] [unique_id "apPliLz-S0xMfHBNth5wwQAAASA"]
[Sun Aug 30 03:10:48.109360 2026] [security2:error] [pid 517995:tid 518202] [client 20.151.200.44:40772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/css/000.php"] [unique_id "apPliLz-S0xMfHBNth5wxQAAAVU"]
[Sun Aug 30 03:10:48.119665 2026] [security2:error] [pid 517995:tid 518169] [client 158.23.147.79:58398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPliLz-S0xMfHBNth5wygAAATQ"]
[Sun Aug 30 03:10:48.124935 2026] [security2:error] [pid 517995:tid 518233] [client 20.104.18.15:64866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/vv.php"] [unique_id "apPliLz-S0xMfHBNth5wzQAAAXQ"]
[Sun Aug 30 03:10:48.128567 2026] [security2:error] [pid 517995:tid 518251] [client 20.48.250.41:40851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/ws68.php"] [unique_id "apPliLz-S0xMfHBNth5w0QAAAYY"]
[Sun Aug 30 03:10:48.155696 2026] [security2:error] [pid 517995:tid 518142] [client 20.104.18.15:44003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/revo.php"] [unique_id "apPliLz-S0xMfHBNth5w4gAAARk"]
[Sun Aug 30 03:10:48.157595 2026] [security2:error] [pid 517995:tid 518145] [client 4.205.62.107:17317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/05.php"] [unique_id "apPliLz-S0xMfHBNth5w5AAAARw"]
[Sun Aug 30 03:10:48.157701 2026] [security2:error] [pid 517995:tid 518151] [client 20.197.61.180:12249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/upgrade-temp-backup/plugins/security.php"] [unique_id "apPliLz-S0xMfHBNth5w5gAAASI"]
[Sun Aug 30 03:10:48.162237 2026] [authz_core:error] [pid 515259:tid 515479] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:48.162546 2026] [authz_core:error] [pid 515259:tid 515479] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:48.173048 2026] [security2:error] [pid 517995:tid 518141] [client 68.155.159.216:46019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-admin/setup-config.php"] [unique_id "apPliLz-S0xMfHBNth5w8wAAARg"]
[Sun Aug 30 03:10:48.173197 2026] [authz_core:error] [pid 517995:tid 518221] [client 66.249.66.77:39767] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:48.174834 2026] [authz_core:error] [pid 517995:tid 518221] [client 66.249.66.77:39767] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:48.179090 2026] [security2:error] [pid 515259:tid 515491] [client 20.48.251.3:59310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/error_log.php"] [unique_id "apPliGZcVaai59truiWGtwAAAGU"]
[Sun Aug 30 03:10:48.180866 2026] [authz_core:error] [pid 515259:tid 515475] [client 66.249.66.32:43430] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:48.181311 2026] [authz_core:error] [pid 515259:tid 515475] [client 66.249.66.32:43430] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:48.239283 2026] [security2:error] [pid 517995:tid 518170] [client 20.151.200.44:40948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/cy.php"] [unique_id "apPliLz-S0xMfHBNth5xFQAAATU"]
[Sun Aug 30 03:10:48.283943 2026] [security2:error] [pid 517995:tid 518200] [client 20.48.250.41:40870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/users.php"] [unique_id "apPliLz-S0xMfHBNth5xLwAAAVM"]
[Sun Aug 30 03:10:48.301358 2026] [security2:error] [pid 517995:tid 518178] [client 20.48.251.3:52239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-blog.php"] [unique_id "apPliLz-S0xMfHBNth5xPAAAAT0"]
[Sun Aug 30 03:10:48.325659 2026] [core:alert] [pid 515259:tid 515402] [client 122.129.65.165:46189] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:10:48.332385 2026] [security2:error] [pid 517995:tid 518248] [client 85.209.9.49:57632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.9.209.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nonfictionnomads.com"] [uri "/wp-login.php"] [unique_id "apPliLz-S0xMfHBNth5xRAAAAYM"]
[Sun Aug 30 03:10:48.339350 2026] [security2:error] [pid 515259:tid 515454] [client 20.63.219.114:15253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/b.php"] [unique_id "apPliGZcVaai59truiWG_wAAAEA"]
[Sun Aug 30 03:10:48.343873 2026] [security2:error] [pid 517995:tid 518236] [client 158.23.147.79:43888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apPliLz-S0xMfHBNth5xVgAAAXc"]
[Sun Aug 30 03:10:48.346867 2026] [security2:error] [pid 517995:tid 518202] [client 158.23.147.79:56502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apPliLz-S0xMfHBNth5xVwAAAVU"]
[Sun Aug 30 03:10:48.381360 2026] [security2:error] [pid 517995:tid 518153] [client 20.104.18.15:64758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/codex.php"] [unique_id "apPliLz-S0xMfHBNth5xbQAAASQ"]
[Sun Aug 30 03:10:48.432600 2026] [security2:error] [pid 515259:tid 515440] [client 40.83.93.50:6358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/dropdown.php"] [unique_id "apPliGZcVaai59truiWHHQAAADI"]
[Sun Aug 30 03:10:48.437178 2026] [security2:error] [pid 517995:tid 518142] [client 20.48.250.41:40871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/bzjdlofz.php"] [unique_id "apPliLz-S0xMfHBNth5xkQAAARk"]
[Sun Aug 30 03:10:48.479903 2026] [security2:error] [pid 517995:tid 518217] [client 20.104.50.220:50374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/inputs.php"] [unique_id "apPliLz-S0xMfHBNth5xpQAAAWQ"]
[Sun Aug 30 03:10:48.492842 2026] [security2:error] [pid 515259:tid 515498] [client 4.205.62.107:15966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/rem.php"] [unique_id "apPliGZcVaai59truiWHMgAAAGw"]
[Sun Aug 30 03:10:48.497265 2026] [security2:error] [pid 515259:tid 515438] [client 20.151.200.44:40916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/admin.php/pindex.php"] [unique_id "apPliGZcVaai59truiWHNAAAADA"]
[Sun Aug 30 03:10:48.508222 2026] [security2:error] [pid 517995:tid 518129] [client 57.131.147.192:64547] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdsafetysystems.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "apPliLz-S0xMfHBNth5xrAAAAQw"]
[Sun Aug 30 03:10:48.521356 2026] [core:alert] [pid 517995:tid 518197] [client 141.94.79.3:54526] /home3/lordrcan/public_html/.htaccess: without matching section
[Sun Aug 30 03:10:48.542484 2026] [security2:error] [pid 517995:tid 518248] [client 20.151.200.44:64766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/sxxb.php"] [unique_id "apPliLz-S0xMfHBNth5xtAAAAYM"]
[Sun Aug 30 03:10:48.549114 2026] [security2:error] [pid 517995:tid 518133] [client 4.205.62.107:36547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apPliLz-S0xMfHBNth5xuAAAARA"]
[Sun Aug 30 03:10:48.569688 2026] [security2:error] [pid 517995:tid 518217] [client 158.23.147.79:61801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPliLz-S0xMfHBNth5xygAAAWQ"]
[Sun Aug 30 03:10:48.572478 2026] [security2:error] [pid 517995:tid 518199] [client 158.23.147.79:57674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apPliLz-S0xMfHBNth5xywAAAVI"]
[Sun Aug 30 03:10:48.576260 2026] [security2:error] [pid 517995:tid 518224] [client 20.48.250.41:40873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/selesai.php"] [unique_id "apPliLz-S0xMfHBNth5xzgAAAWs"]
[Sun Aug 30 03:10:48.579277 2026] [authz_core:error] [pid 515259:tid 515506] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:10:48.579732 2026] [authz_core:error] [pid 515259:tid 515506] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:10:48.597950 2026] [security2:error] [pid 517995:tid 518212] [client 20.48.251.3:14099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/classsmtps.php"] [unique_id "apPliLz-S0xMfHBNth5x1AAAAV8"]
[Sun Aug 30 03:10:48.599939 2026] [authz_core:error] [pid 515259:tid 515425] [client 216.73.216.128:35448] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:48.600384 2026] [authz_core:error] [pid 515259:tid 515425] [client 216.73.216.128:35448] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:48.630957 2026] [security2:error] [pid 515259:tid 515400] [client 20.104.50.220:64451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/unknown.php"] [unique_id "apPliGZcVaai59truiWHWgAAAAo"]
[Sun Aug 30 03:10:48.636869 2026] [security2:error] [pid 517995:tid 518204] [client 20.151.200.44:40920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/admin.php/csv.php"] [unique_id "apPliLz-S0xMfHBNth5x9gAAAVc"]
[Sun Aug 30 03:10:48.693101 2026] [security2:error] [pid 517995:tid 518237] [client 20.104.50.220:29581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/libs-func.php"] [unique_id "apPliLz-S0xMfHBNth5yHAAAAXg"]
[Sun Aug 30 03:10:48.712457 2026] [security2:error] [pid 517995:tid 518192] [client 4.205.62.107:64507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/file59.php"] [unique_id "apPliLz-S0xMfHBNth5yMQAAAUs"]
[Sun Aug 30 03:10:48.717749 2026] [security2:error] [pid 517995:tid 518143] [client 20.48.250.41:40911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/shlo.php"] [unique_id "apPliLz-S0xMfHBNth5yNQAAARo"]
[Sun Aug 30 03:10:48.725205 2026] [security2:error] [pid 517995:tid 518221] [client 20.104.18.15:22481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/shiny.php"] [unique_id "apPliLz-S0xMfHBNth5yPwAAAWg"]
[Sun Aug 30 03:10:48.733438 2026] [security2:error] [pid 517995:tid 518209] [client 219.94.162.187:59590] ModSecurity: Warning. Matched phrase "LWP::Simple" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "bcwinetrends.com"] [uri "/2017/07/03/rose-gold-at-the-acwc/"] [unique_id "apPliLz-S0xMfHBNth5yMwAAAVw"]
[Sun Aug 30 03:10:48.736572 2026] [security2:error] [pid 517995:tid 518250] [client 20.104.49.130:34543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/tool.php"] [unique_id "apPliLz-S0xMfHBNth5ySwAAAYU"]
[Sun Aug 30 03:10:48.750383 2026] [security2:error] [pid 515259:tid 515465] [client 68.155.159.216:57040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apPliGZcVaai59truiWHewAAAEs"]
[Sun Aug 30 03:10:48.782004 2026] [authz_core:error] [pid 517995:tid 518212] [client 216.73.216.128:15412] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:48.782451 2026] [authz_core:error] [pid 517995:tid 518212] [client 216.73.216.128:15412] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:48.786920 2026] [security2:error] [pid 517995:tid 518137] [client 195.178.110.247:6818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "congresolatamrrhh.com"] [uri "/index.php"] [unique_id "apPliLz-S0xMfHBNth5yXAAAARQ"]
[Sun Aug 30 03:10:48.789342 2026] [security2:error] [pid 517995:tid 518143] [client 145.239.10.137:39395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitemountaincabinrentals.com"] [uri "/wp-content/plugins/pwnd/Footer.php"] [unique_id "apPliLz-S0xMfHBNth5yXgAAARo"], referer: http://whitemountaincabinrentals.com/wp-content/plugins/pwnd/Footer.php
[Sun Aug 30 03:10:48.797246 2026] [security2:error] [pid 515259:tid 515440] [client 20.151.200.44:40879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/admin.php/700.php"] [unique_id "apPliGZcVaai59truiWHiwAAADI"]
[Sun Aug 30 03:10:48.798002 2026] [core:alert] [pid 515259:tid 515429] [client 105.127.16.31:7738] /home3/lordrcan/public_html/.htaccess: without matching section, referer: https://arcaneguardians.com/
[Sun Aug 30 03:10:48.832233 2026] [security2:error] [pid 517995:tid 518238] [client 20.104.18.15:18367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/xty.php"] [unique_id "apPliLz-S0xMfHBNth5ybwAAAXk"]
[Sun Aug 30 03:10:48.840113 2026] [authz_core:error] [pid 517995:tid 518228] [client 66.249.66.39:47613] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:48.840544 2026] [authz_core:error] [pid 517995:tid 518228] [client 66.249.66.39:47613] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:48.842423 2026] [security2:error] [pid 517995:tid 518186] [client 20.104.50.220:51633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/images/byps.php"] [unique_id "apPliLz-S0xMfHBNth5ydgAAAUU"]
[Sun Aug 30 03:10:48.870593 2026] [security2:error] [pid 515259:tid 515478] [client 20.197.61.180:16862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/upgrade-temp-backup/plugins/users.php"] [unique_id "apPliGZcVaai59truiWHtQAAAFg"]
[Sun Aug 30 03:10:48.885662 2026] [security2:error] [pid 515259:tid 515407] [client 158.23.147.79:61953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/images/index.php"] [unique_id "apPliGZcVaai59truiWHvAAAABE"]
[Sun Aug 30 03:10:48.913254 2026] [security2:error] [pid 515259:tid 515443] [client 40.83.93.50:22113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/mar.php"] [unique_id "apPliGZcVaai59truiWHzAAAADU"]
[Sun Aug 30 03:10:48.916667 2026] [security2:error] [pid 515259:tid 515417] [client 20.63.219.114:2111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/wp-login.php"] [unique_id "apPliGZcVaai59truiWHugAAABs"]
[Sun Aug 30 03:10:48.925020 2026] [security2:error] [pid 517995:tid 518131] [client 20.48.250.41:40942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/asax.php"] [unique_id "apPliLz-S0xMfHBNth5yogAAAQ4"]
[Sun Aug 30 03:10:48.935625 2026] [security2:error] [pid 517995:tid 518183] [client 20.104.50.220:33173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/images/x.php"] [unique_id "apPliLz-S0xMfHBNth5ypgAAAUI"]
[Sun Aug 30 03:10:48.942475 2026] [security2:error] [pid 515259:tid 515497] [client 20.151.200.44:40880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/admin.php/007x.php"] [unique_id "apPliGZcVaai59truiWH2AAAAGs"]
[Sun Aug 30 03:10:48.947445 2026] [security2:error] [pid 517995:tid 518216] [client 195.178.110.247:61192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "congresolatamrrhh.com"] [uri "/index.php"] [unique_id "apPliLz-S0xMfHBNth5yrQAAAWM"]
[Sun Aug 30 03:10:48.958515 2026] [security2:error] [pid 517995:tid 518195] [client 20.104.50.220:5506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/misc.php"] [unique_id "apPliLz-S0xMfHBNth5ytgAAAU4"]
[Sun Aug 30 03:10:48.968980 2026] [security2:error] [pid 515259:tid 515489] [client 20.104.49.130:36737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/wp-blog-header.php"] [unique_id "apPliGZcVaai59truiWH5AAAAGM"]
[Sun Aug 30 03:10:49.000225 2026] [security2:error] [pid 517995:tid 518204] [client 20.104.18.15:31629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/adminfuns.php"] [unique_id "apPliLz-S0xMfHBNth5yxAAAAVc"]
[Sun Aug 30 03:10:49.026052 2026] [security2:error] [pid 517995:tid 518147] [client 20.104.49.130:60737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/82.php"] [unique_id "apPlibz-S0xMfHBNth5y1AAAAR4"]
[Sun Aug 30 03:10:49.027444 2026] [security2:error] [pid 515259:tid 515459] [client 20.48.251.3:64292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/sys.php"] [unique_id "apPliWZcVaai59truiWICQAAAEU"]
[Sun Aug 30 03:10:49.046108 2026] [security2:error] [pid 515259:tid 515416] [client 158.23.147.79:1994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apPliWZcVaai59truiWIGwAAABo"]
[Sun Aug 30 03:10:49.052152 2026] [security2:error] [pid 517995:tid 518225] [client 145.239.10.137:43957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitemountainoutdoorrentals.com"] [uri "/wp-content/plugins/pwnd/Footer.php"] [unique_id "apPlibz-S0xMfHBNth5y4AAAAWw"], referer: http://whitemountainoutdoorrentals.com/wp-content/plugins/pwnd/Footer.php
[Sun Aug 30 03:10:49.102978 2026] [authz_core:error] [pid 515259:tid 515483] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:49.103270 2026] [authz_core:error] [pid 515259:tid 515483] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:49.112152 2026] [security2:error] [pid 515259:tid 515405] [client 20.48.250.41:40912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/fetch.php"] [unique_id "apPliWZcVaai59truiWIQwAAAA8"]
[Sun Aug 30 03:10:49.125380 2026] [security2:error] [pid 515259:tid 515404] [client 4.205.62.107:26960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/nzv.php"] [unique_id "apPliWZcVaai59truiWISwAAAA4"]
[Sun Aug 30 03:10:49.146588 2026] [authz_core:error] [pid 515259:tid 515424] [client 216.73.216.128:35448] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:49.146924 2026] [authz_core:error] [pid 515259:tid 515424] [client 216.73.216.128:35448] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:49.174731 2026] [security2:error] [pid 515259:tid 515437] [client 20.104.50.220:17258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-content/themes/about.php"] [unique_id "apPliWZcVaai59truiWIZgAAAC8"]
[Sun Aug 30 03:10:49.178291 2026] [authz_core:error] [pid 515259:tid 515508] [client 66.249.66.41:53948] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:49.178612 2026] [authz_core:error] [pid 515259:tid 515508] [client 66.249.66.41:53948] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:49.184743 2026] [security2:error] [pid 515259:tid 515467] [client 57.131.147.192:54938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.147.131.57.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ucdsafetysystems.com"] [uri "/xmlrpc.php"] [unique_id "apPliWZcVaai59truiWIXwAAAE0"]
[Sun Aug 30 03:10:49.213765 2026] [security2:error] [pid 517995:tid 518208] [client 20.104.50.220:59555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-atom.php"] [unique_id "apPlibz-S0xMfHBNth5zQQAAAVs"]
[Sun Aug 30 03:10:49.222745 2026] [core:alert] [pid 515259:tid 515509] [client 57.129.81.224:47984] /home3/lordrcan/public_html/.htaccess: without matching section
[Sun Aug 30 03:10:49.224079 2026] [security2:error] [pid 515259:tid 515405] [client 68.155.159.216:54296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-login.php"] [unique_id "apPliWZcVaai59truiWIeQAAAA8"]
[Sun Aug 30 03:10:49.254355 2026] [security2:error] [pid 515259:tid 515393] [client 20.151.200.44:64722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/dx.php"] [unique_id "apPliWZcVaai59truiWIhgAAAAM"]
[Sun Aug 30 03:10:49.271884 2026] [security2:error] [pid 517995:tid 518208] [client 20.104.18.15:16734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/bossu.php"] [unique_id "apPlibz-S0xMfHBNth5zYQAAAVs"]
[Sun Aug 30 03:10:49.297199 2026] [security2:error] [pid 517995:tid 518225] [client 20.48.250.41:40843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/vx.php"] [unique_id "apPlibz-S0xMfHBNth5zbQAAAWw"]
[Sun Aug 30 03:10:49.301867 2026] [security2:error] [pid 517995:tid 518212] [client 4.205.62.107:17696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/wp-blog.php"] [unique_id "apPlibz-S0xMfHBNth5zbwAAAV8"]
[Sun Aug 30 03:10:49.315571 2026] [security2:error] [pid 517995:tid 518137] [client 20.104.18.15:44010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/birrs.php"] [unique_id "apPlibz-S0xMfHBNth5zfQAAARQ"]
[Sun Aug 30 03:10:49.316799 2026] [security2:error] [pid 517995:tid 518181] [client 20.48.251.3:55713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/phina.php"] [unique_id "apPlibz-S0xMfHBNth5zfwAAAUA"]
[Sun Aug 30 03:10:49.317885 2026] [authz_core:error] [pid 517995:tid 518148] [client 66.249.66.36:54218] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:49.318219 2026] [authz_core:error] [pid 517995:tid 518148] [client 66.249.66.36:54218] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:49.323668 2026] [security2:error] [pid 515259:tid 515504] [client 216.73.216.128:35448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/files.html"] [unique_id "apPliWZcVaai59truiWIogAAAHI"]
[Sun Aug 30 03:10:49.332438 2026] [security2:error] [pid 517995:tid 518161] [client 68.155.159.216:45984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apPlibz-S0xMfHBNth5zjQAAASw"]
[Sun Aug 30 03:10:49.388247 2026] [security2:error] [pid 517995:tid 518138] [client 20.63.219.114:15176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/aa.php"] [unique_id "apPlibz-S0xMfHBNth5zrAAAARU"]
[Sun Aug 30 03:10:49.390150 2026] [security2:error] [pid 517995:tid 518211] [client 158.23.147.79:62015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apPlibz-S0xMfHBNth5zrgAAAV4"]
[Sun Aug 30 03:10:49.439127 2026] [http2:info] [pid 518600:tid 518600] h2_workers: created with min=128 max=192 idle_ms=600000
[Sun Aug 30 03:10:49.459300 2026] [security2:error] [pid 518600:tid 518733] [client 20.48.251.3:59457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/erty.php"] [unique_id "apPlie349Tv4SB45P2m8DAAAAIU"]
[Sun Aug 30 03:10:49.481746 2026] [security2:error] [pid 518600:tid 518767] [client 20.48.250.41:40907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/global.php"] [unique_id "apPlie349Tv4SB45P2m8GwAAAKc"]
[Sun Aug 30 03:10:49.514365 2026] [authz_core:error] [pid 515259:tid 515498] [client 216.73.216.128:5489] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:49.514828 2026] [authz_core:error] [pid 515259:tid 515498] [client 216.73.216.128:5489] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:49.520783 2026] [security2:error] [pid 515259:tid 515503] [client 40.83.93.50:6209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/css.php"] [unique_id "apPliWZcVaai59truiWI2QAAAHE"]
[Sun Aug 30 03:10:49.524971 2026] [security2:error] [pid 517995:tid 518167] [client 20.104.18.15:16911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/5656.php"] [unique_id "apPlibz-S0xMfHBNth5zzgAAATI"]
[Sun Aug 30 03:10:49.532606 2026] [authz_core:error] [pid 515259:tid 515491] [client 66.249.66.43:47120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:49.533062 2026] [authz_core:error] [pid 515259:tid 515491] [client 66.249.66.43:47120] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:49.577851 2026] [security2:error] [pid 515259:tid 515439] [client 20.151.200.44:41947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/dx.php"] [unique_id "apPliWZcVaai59truiWI-QAAADE"]
[Sun Aug 30 03:10:49.587931 2026] [security2:error] [pid 517995:tid 518192] [client 20.197.61.180:16849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/upgrade-temp-backup/plugins/wp-blog-header.php"] [unique_id "apPlibz-S0xMfHBNth5z6wAAAUs"]
[Sun Aug 30 03:10:49.592955 2026] [security2:error] [pid 517995:tid 518208] [client 158.23.147.79:61813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apPlibz-S0xMfHBNth5z7AAAAVs"]
[Sun Aug 30 03:10:49.601168 2026] [security2:error] [pid 515259:tid 515482] [client 20.151.200.44:40958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/admin.php/heex.php"] [unique_id "apPliWZcVaai59truiWJCQAAAFw"]
[Sun Aug 30 03:10:49.603828 2026] [authz_core:error] [pid 515259:tid 515512] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:49.604088 2026] [authz_core:error] [pid 515259:tid 515512] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:49.612619 2026] [security2:error] [pid 518600:tid 518747] [client 20.48.250.41:40772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/fs.php"] [unique_id "apPlie349Tv4SB45P2m8SwAAAJM"]
[Sun Aug 30 03:10:49.617899 2026] [security2:error] [pid 518600:tid 518736] [client 162.19.94.70:36736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "921"] [severity "CRITICAL"] [tag "SQLi"] [hostname "whyshamanismnow.com"] [uri "/"] [unique_id "apPlie349Tv4SB45P2m8TAAAAIg"]
[Sun Aug 30 03:10:49.623323 2026] [security2:error] [pid 517995:tid 518138] [client 20.104.50.220:31535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/av.php"] [unique_id "apPlibz-S0xMfHBNth5z-AAAARU"]
[Sun Aug 30 03:10:49.659178 2026] [core:alert] [pid 518600:tid 518772] [client 151.80.133.130:49252] /home3/lordrcan/public_html/.htaccess: without matching section
[Sun Aug 30 03:10:49.662472 2026] [security2:error] [pid 517995:tid 518215] [client 4.205.62.107:16327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/min.php"] [unique_id "apPlibz-S0xMfHBNth50CAAAAWI"]
[Sun Aug 30 03:10:49.687202 2026] [security2:error] [pid 517995:tid 518212] [client 4.205.62.107:36721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/hochladen.form.php"] [unique_id "apPlibz-S0xMfHBNth50HwAAAV8"]
[Sun Aug 30 03:10:49.738621 2026] [authz_core:error] [pid 517995:tid 518225] [client 66.249.66.72:59075] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:49.738960 2026] [authz_core:error] [pid 517995:tid 518225] [client 66.249.66.72:59075] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:49.766704 2026] [security2:error] [pid 517995:tid 518190] [client 20.48.251.3:60508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/cache-compat.php"] [unique_id "apPlibz-S0xMfHBNth50TAAAAUk"]
[Sun Aug 30 03:10:49.772579 2026] [security2:error] [pid 517995:tid 518220] [client 20.48.250.41:40924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/ioxi.php"] [unique_id "apPlibz-S0xMfHBNth50UgAAAWc"]
[Sun Aug 30 03:10:49.782712 2026] [security2:error] [pid 517995:tid 518160] [client 20.104.50.220:29138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/sel.php"] [unique_id "apPlibz-S0xMfHBNth50WwAAASs"]
[Sun Aug 30 03:10:49.868558 2026] [security2:error] [pid 518600:tid 518742] [client 4.205.62.107:58482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/cli_bootstrap.php"] [unique_id "apPlie349Tv4SB45P2m8dQAAAI4"]
[Sun Aug 30 03:10:49.872056 2026] [security2:error] [pid 517995:tid 518235] [client 57.131.147.192:62641] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdsafetysystems.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "apPlibz-S0xMfHBNth50iAAAAXY"]
[Sun Aug 30 03:10:49.875892 2026] [security2:error] [pid 517995:tid 518222] [client 68.155.159.216:62617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/themes.php"] [unique_id "apPlibz-S0xMfHBNth50jgAAAWk"]
[Sun Aug 30 03:10:49.887426 2026] [security2:error] [pid 515259:tid 515500] [client 20.104.18.15:22357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/goods.php"] [unique_id "apPliWZcVaai59truiWJXwAAAG4"]
[Sun Aug 30 03:10:49.961548 2026] [security2:error] [pid 518600:tid 518758] [client 20.48.250.41:40834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/bootstrap.php"] [unique_id "apPlie349Tv4SB45P2m8hwAAAJ4"]
[Sun Aug 30 03:10:49.981120 2026] [security2:error] [pid 518600:tid 518783] [client 20.104.18.15:18363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/sallu.php"] [unique_id "apPlie349Tv4SB45P2m8jQAAALc"]
[Sun Aug 30 03:10:49.989612 2026] [security2:error] [pid 517995:tid 518227] [client 20.104.49.130:52334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/ioxi-o.php"] [unique_id "apPlibz-S0xMfHBNth501wAAAW4"]
[Sun Aug 30 03:10:49.993083 2026] [security2:error] [pid 518600:tid 518766] [client 20.104.50.220:63546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/images/bypass.php"] [unique_id "apPlie349Tv4SB45P2m8kgAAAKY"]
[Sun Aug 30 03:10:50.003637 2026] [security2:error] [pid 518600:tid 518830] [client 40.83.93.50:6397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/autoload_classmap.php"] [unique_id "apPliu349Tv4SB45P2m8lwAAAOY"]
[Sun Aug 30 03:10:50.080009 2026] [security2:error] [pid 515259:tid 515407] [client 162.19.94.70:36774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "whyshamanismnow.com"] [uri "/"] [unique_id "apPlimZcVaai59truiWJnAAAABE"]
[Sun Aug 30 03:10:50.102506 2026] [security2:error] [pid 518600:tid 518830] [client 20.104.50.220:33183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/images/leaf.php"] [unique_id "apPliu349Tv4SB45P2m80AAAAOY"]
[Sun Aug 30 03:10:50.103439 2026] [security2:error] [pid 518600:tid 518797] [client 20.104.50.220:5221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/class-IXR.php"] [unique_id "apPliu349Tv4SB45P2m80QAAAMU"]
[Sun Aug 30 03:10:50.115926 2026] [security2:error] [pid 517995:tid 518248] [client 20.63.219.114:19169] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpanel.mirlabs.com"] [uri "/c99.php"] [unique_id "apPlirz-S0xMfHBNth51DAAAAYM"]
[Sun Aug 30 03:10:50.123950 2026] [security2:error] [pid 517995:tid 518223] [client 20.48.250.41:40928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/export.php"] [unique_id "apPlirz-S0xMfHBNth51EwAAAWo"]
[Sun Aug 30 03:10:50.134064 2026] [autoindex:error] [pid 517995:tid 518177] [client 137.184.183.40:32916] AH01276: Cannot serve directory /home1/mudassar/public_html/admin/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:10:50.134289 2026] [authz_core:error] [pid 518600:tid 518820] [client 66.249.66.44:43913] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:50.134548 2026] [authz_core:error] [pid 518600:tid 518820] [client 66.249.66.44:43913] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:50.148376 2026] [security2:error] [pid 518600:tid 518845] [client 20.104.18.15:31687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/classwithtostring.php"] [unique_id "apPliu349Tv4SB45P2m88AAAAPU"]
[Sun Aug 30 03:10:50.174908 2026] [security2:error] [pid 517995:tid 518204] [client 20.48.251.3:65524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/phpsysinfo.php"] [unique_id "apPlirz-S0xMfHBNth51KgAAAVc"]
[Sun Aug 30 03:10:50.185220 2026] [autoindex:error] [pid 517995:tid 518161] [client 212.156.70.154:12043] AH01276: Cannot serve directory /home4/ariotti/KonstructCollective.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:10:50.206083 2026] [security2:error] [pid 515259:tid 515459] [client 158.23.147.79:58373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-includes/Requests/network.php"] [unique_id "apPlimZcVaai59truiWJxgAAAEU"]
[Sun Aug 30 03:10:50.213243 2026] [security2:error] [pid 515259:tid 515417] [client 158.23.147.79:61972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apPlimZcVaai59truiWJzQAAABs"]
[Sun Aug 30 03:10:50.260657 2026] [security2:error] [pid 518600:tid 518794] [client 20.48.250.41:40833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/gk.php"] [unique_id "apPliu349Tv4SB45P2m9AgAAAMI"]
[Sun Aug 30 03:10:50.298749 2026] [security2:error] [pid 518600:tid 518849] [client 20.197.61.180:3811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/upgrade-temp-backup/plugins/wp-mail.php"] [unique_id "apPliu349Tv4SB45P2m9DAAAAPk"]
[Sun Aug 30 03:10:50.302659 2026] [security2:error] [pid 515259:tid 515477] [client 20.104.50.220:16725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/filemanager/dialog.php"] [unique_id "apPlimZcVaai59truiWJ7AAAAFc"]
[Sun Aug 30 03:10:50.307534 2026] [security2:error] [pid 518600:tid 518764] [client 4.205.62.107:25504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/66.php"] [unique_id "apPliu349Tv4SB45P2m9DwAAAKQ"]
[Sun Aug 30 03:10:50.318689 2026] [authz_core:error] [pid 517995:tid 518208] [client 66.249.66.195:46075] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:50.319125 2026] [authz_core:error] [pid 517995:tid 518208] [client 66.249.66.195:46075] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:50.356182 2026] [core:alert] [pid 517995:tid 518166] [client 57.129.81.227:54966] /home3/lordrcan/public_html/.htaccess: without matching section
[Sun Aug 30 03:10:50.365614 2026] [security2:error] [pid 517995:tid 518233] [client 20.104.50.220:61467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-bita.php"] [unique_id "apPlirz-S0xMfHBNth51fQAAAXQ"]
[Sun Aug 30 03:10:50.377345 2026] [authz_core:error] [pid 515259:tid 515395] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:50.377600 2026] [authz_core:error] [pid 515259:tid 515395] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:50.403830 2026] [security2:error] [pid 518600:tid 518772] [client 20.104.18.15:16721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/504.php"] [unique_id "apPliu349Tv4SB45P2m9KwAAAKw"]
[Sun Aug 30 03:10:50.407988 2026] [security2:error] [pid 518600:tid 518742] [client 20.48.250.41:40957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/logs1.php"] [unique_id "apPliu349Tv4SB45P2m9MQAAAI4"]
[Sun Aug 30 03:10:50.429620 2026] [security2:error] [pid 517995:tid 518223] [client 4.205.62.107:17327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/erty.php"] [unique_id "apPlirz-S0xMfHBNth51nAAAAWo"]
[Sun Aug 30 03:10:50.459413 2026] [security2:error] [pid 515259:tid 515449] [client 20.104.18.15:43913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/sss.php"] [unique_id "apPlimZcVaai59truiWKNgAAADs"]
[Sun Aug 30 03:10:50.459601 2026] [security2:error] [pid 515259:tid 515474] [client 20.48.251.3:42372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/koiy.php"] [unique_id "apPlimZcVaai59truiWKNwAAAFQ"]
[Sun Aug 30 03:10:50.476526 2026] [security2:error] [pid 517995:tid 518187] [client 68.155.159.216:46051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apPlirz-S0xMfHBNth51rQAAAUY"]
[Sun Aug 30 03:10:50.486115 2026] [security2:error] [pid 517995:tid 518206] [client 40.83.93.50:22138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/info.php"] [unique_id "apPlirz-S0xMfHBNth51rwAAAVk"]
[Sun Aug 30 03:10:50.488289 2026] [authz_core:error] [pid 518600:tid 518801] [client 66.249.66.72:52478] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:50.488545 2026] [authz_core:error] [pid 518600:tid 518801] [client 66.249.66.72:52478] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:50.491464 2026] [security2:error] [pid 515259:tid 515398] [client 20.104.49.130:52444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/read.php"] [unique_id "apPlimZcVaai59truiWKRQAAAAg"]
[Sun Aug 30 03:10:50.546124 2026] [security2:error] [pid 518600:tid 518736] [client 162.19.94.70:36805] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "whyshamanismnow.com"] [uri "/"] [unique_id "apPliu349Tv4SB45P2m9RwAAAIg"]
[Sun Aug 30 03:10:50.552216 2026] [security2:error] [pid 515259:tid 515424] [client 57.131.147.192:59147] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdsafetysystems.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "apPlimZcVaai59truiWKWQAAACI"]
[Sun Aug 30 03:10:50.564199 2026] [security2:error] [pid 517995:tid 518144] [client 20.48.250.41:40835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/inege.php"] [unique_id "apPlirz-S0xMfHBNth51zAAAARs"]
[Sun Aug 30 03:10:50.600931 2026] [security2:error] [pid 518600:tid 518762] [client 20.48.251.3:59899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-config.backup.php"] [unique_id "apPliu349Tv4SB45P2m9YQAAAKI"]
[Sun Aug 30 03:10:50.675231 2026] [security2:error] [pid 518600:tid 518762] [client 20.104.18.15:64724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/w3lls.php"] [unique_id "apPliu349Tv4SB45P2m9hwAAAKI"]
[Sun Aug 30 03:10:50.681472 2026] [security2:error] [pid 515259:tid 515489] [client 20.63.219.114:2930] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpanel.mirlabs.com"] [uri "/c99.php"] [unique_id "apPlimZcVaai59truiWKeQAAAGM"]
[Sun Aug 30 03:10:50.695270 2026] [security2:error] [pid 517995:tid 518144] [client 158.23.147.79:62002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apPlirz-S0xMfHBNth518QAAARs"]
[Sun Aug 30 03:10:50.704316 2026] [security2:error] [pid 518600:tid 518797] [client 20.48.250.41:40892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/wp-link10.php"] [unique_id "apPliu349Tv4SB45P2m9qQAAAMU"]
[Sun Aug 30 03:10:50.789716 2026] [core:alert] [pid 515259:tid 515447] [client 154.192.119.62:3258] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:10:50.797985 2026] [security2:error] [pid 517995:tid 518214] [client 20.151.200.44:40940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/tf.php"] [unique_id "apPlirz-S0xMfHBNth52IwAAAWE"]
[Sun Aug 30 03:10:50.800395 2026] [security2:error] [pid 518600:tid 518789] [client 4.205.62.107:15981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/saiga.php"] [unique_id "apPliu349Tv4SB45P2m9wgAAAL0"]
[Sun Aug 30 03:10:50.802532 2026] [security2:error] [pid 515259:tid 515456] [client 20.104.50.220:31492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/classwithtostring.php"] [unique_id "apPlimZcVaai59truiWKtgAAAEI"]
[Sun Aug 30 03:10:50.828200 2026] [security2:error] [pid 517995:tid 518238] [client 4.205.62.107:36705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/debuggen.php"] [unique_id "apPlirz-S0xMfHBNth52KgAAAXk"]
[Sun Aug 30 03:10:50.845184 2026] [security2:error] [pid 515259:tid 515455] [client 20.48.250.41:40849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/ww.php"] [unique_id "apPlimZcVaai59truiWKzgAAAEE"]
[Sun Aug 30 03:10:50.867743 2026] [authz_core:error] [pid 515259:tid 515516] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:50.867995 2026] [authz_core:error] [pid 515259:tid 515516] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:50.872407 2026] [authz_core:error] [pid 518600:tid 518802] [client 66.249.66.75:51091] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:50.872675 2026] [authz_core:error] [pid 518600:tid 518802] [client 66.249.66.75:51091] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:50.880543 2026] [authz_core:error] [pid 515259:tid 515462] [client 216.73.216.128:33811] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:50.880809 2026] [authz_core:error] [pid 515259:tid 515462] [client 216.73.216.128:33811] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:50.907004 2026] [security2:error] [pid 517995:tid 518144] [client 20.48.251.3:13953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/aws_keys.php"] [unique_id "apPlirz-S0xMfHBNth52XAAAARs"]
[Sun Aug 30 03:10:50.922282 2026] [security2:error] [pid 518600:tid 518753] [client 20.104.50.220:62822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/14.php"] [unique_id "apPliu349Tv4SB45P2m93gAAAJk"]
[Sun Aug 30 03:10:50.969828 2026] [authz_core:error] [pid 515259:tid 515387] [remote 216.73.217.178:64946] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:50.970241 2026] [authz_core:error] [pid 515259:tid 515387] [remote 216.73.217.178:64946] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:50.995960 2026] [security2:error] [pid 515259:tid 515398] [client 162.19.94.70:36844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "911"] [severity "CRITICAL"] [tag "SQLi"] [hostname "whyshamanismnow.com"] [uri "/"] [unique_id "apPlimZcVaai59truiWK-wAAAAg"]
[Sun Aug 30 03:10:51.005834 2026] [security2:error] [pid 515259:tid 515412] [client 40.83.93.50:6395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/b.php"] [unique_id "apPli2ZcVaai59truiWK_gAAABY"]
[Sun Aug 30 03:10:51.006381 2026] [security2:error] [pid 515259:tid 515433] [client 4.205.62.107:58471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/dd.php"] [unique_id "apPli2ZcVaai59truiWK_wAAACs"]
[Sun Aug 30 03:10:51.022124 2026] [security2:error] [pid 517995:tid 518213] [client 20.104.49.130:54146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/dragonshell.php"] [unique_id "apPli7z-S0xMfHBNth52rAAAAWA"]
[Sun Aug 30 03:10:51.024927 2026] [security2:error] [pid 518600:tid 518844] [client 20.197.61.180:16853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/upgrade-temp-backup/themes/admin.php"] [unique_id "apPli-349Tv4SB45P2m9-gAAAPQ"]
[Sun Aug 30 03:10:51.037228 2026] [security2:error] [pid 517995:tid 518142] [client 20.48.250.41:40768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/w1px.php"] [unique_id "apPli7z-S0xMfHBNth52uwAAARk"]
[Sun Aug 30 03:10:51.046875 2026] [security2:error] [pid 518600:tid 518842] [client 20.104.18.15:22351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/alfa.php"] [unique_id "apPli-349Tv4SB45P2m-AAAAAPI"]
[Sun Aug 30 03:10:51.066787 2026] [security2:error] [pid 517995:tid 518225] [client 68.155.159.216:62629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-mail.php"] [unique_id "apPli7z-S0xMfHBNth521gAAAWw"]
[Sun Aug 30 03:10:51.104716 2026] [security2:error] [pid 517995:tid 518203] [client 158.23.147.79:43850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/nf_tracking.php"] [unique_id "apPli7z-S0xMfHBNth528AAAAVY"]
[Sun Aug 30 03:10:51.131880 2026] [security2:error] [pid 517995:tid 518189] [client 20.104.18.15:18318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/codex.php"] [unique_id "apPli7z-S0xMfHBNth53DQAAAUg"]
[Sun Aug 30 03:10:51.132871 2026] [security2:error] [pid 517995:tid 518143] [client 20.104.50.220:51618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/images/x.php"] [unique_id "apPli7z-S0xMfHBNth53DwAAARo"]
[Sun Aug 30 03:10:51.135428 2026] [authz_core:error] [pid 515259:tid 515496] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:51.135886 2026] [authz_core:error] [pid 515259:tid 515496] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:51.192912 2026] [core:alert] [pid 515259:tid 515448] [client 141.94.79.3:54528] /home3/lordrcan/public_html/.htaccess: without matching section
[Sun Aug 30 03:10:51.208681 2026] [security2:error] [pid 515259:tid 515470] [client 20.48.250.41:40951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/to.php"] [unique_id "apPli2ZcVaai59truiWLSwAAAFA"]
[Sun Aug 30 03:10:51.236313 2026] [security2:error] [pid 518600:tid 518814] [client 57.131.147.192:57252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdsafetysystems.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "apPli-349Tv4SB45P2m-PwAAANY"]
[Sun Aug 30 03:10:51.243923 2026] [authz_core:error] [pid 515259:tid 515515] [client 216.73.216.128:7620] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:51.244045 2026] [security2:error] [pid 515259:tid 515472] [client 20.104.50.220:33168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/images/wso.php"] [unique_id "apPli2ZcVaai59truiWLXAAAAFI"]
[Sun Aug 30 03:10:51.244194 2026] [authz_core:error] [pid 515259:tid 515515] [client 216.73.216.128:7620] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:51.261021 2026] [authz_core:error] [pid 518600:tid 518784] [client 66.249.66.201:35249] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:51.261368 2026] [authz_core:error] [pid 518600:tid 518784] [client 66.249.66.201:35249] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:51.262576 2026] [security2:error] [pid 517995:tid 518143] [client 20.151.200.44:40919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/update/da222.php"] [unique_id "apPli7z-S0xMfHBNth53VAAAARo"]
[Sun Aug 30 03:10:51.271024 2026] [security2:error] [pid 517995:tid 518237] [client 20.151.200.44:64712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPli7z-S0xMfHBNth53VwAAAXg"]
[Sun Aug 30 03:10:51.272908 2026] [security2:error] [pid 517995:tid 518132] [client 20.104.50.220:5542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/plugin.php"] [unique_id "apPli7z-S0xMfHBNth53WgAAAQ8"]
[Sun Aug 30 03:10:51.309450 2026] [security2:error] [pid 517995:tid 518140] [client 20.104.18.15:31680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPli7z-S0xMfHBNth53dgAAARc"]
[Sun Aug 30 03:10:51.340582 2026] [security2:error] [pid 515259:tid 515409] [client 20.48.251.3:65518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/sgd.php"] [unique_id "apPli2ZcVaai59truiWLlgAAABM"]
[Sun Aug 30 03:10:51.363379 2026] [authz_core:error] [pid 515259:tid 515478] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:51.363794 2026] [authz_core:error] [pid 515259:tid 515478] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:51.377604 2026] [security2:error] [pid 515259:tid 515416] [client 20.48.250.41:40860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/thui.php"] [unique_id "apPli2ZcVaai59truiWLqAAAABo"]
[Sun Aug 30 03:10:51.427177 2026] [authz_core:error] [pid 517995:tid 518236] [client 66.249.66.200:48451] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:51.427451 2026] [authz_core:error] [pid 517995:tid 518236] [client 66.249.66.200:48451] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:51.435092 2026] [security2:error] [pid 515259:tid 515429] [client 20.104.50.220:16697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apPli2ZcVaai59truiWLyAAAACc"]
[Sun Aug 30 03:10:51.447934 2026] [security2:error] [pid 518600:tid 518780] [client 162.19.94.70:36881] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "whyshamanismnow.com"] [uri "/"] [unique_id "apPli-349Tv4SB45P2m-ZgAAALQ"]
[Sun Aug 30 03:10:51.452544 2026] [security2:error] [pid 515259:tid 515468] [client 158.23.147.79:52236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wzy.php"] [unique_id "apPli2ZcVaai59truiWL0gAAAE4"]
[Sun Aug 30 03:10:51.467526 2026] [security2:error] [pid 517995:tid 518216] [client 20.151.200.44:28582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/pk.php"] [unique_id "apPli7z-S0xMfHBNth53vQAAAWM"]
[Sun Aug 30 03:10:51.469371 2026] [security2:error] [pid 517995:tid 518203] [client 4.205.62.107:26983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/admin.php"] [unique_id "apPli7z-S0xMfHBNth53vwAAAVY"]
[Sun Aug 30 03:10:51.479360 2026] [security2:error] [pid 517995:tid 518249] [client 20.104.49.130:48338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/abcd.php"] [unique_id "apPli7z-S0xMfHBNth53wQAAAYQ"]
[Sun Aug 30 03:10:51.512185 2026] [security2:error] [pid 517995:tid 518202] [client 40.83.93.50:6336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/wp-login.php"] [unique_id "apPli7z-S0xMfHBNth53ywAAAVU"]
[Sun Aug 30 03:10:51.517344 2026] [security2:error] [pid 517995:tid 518131] [client 20.48.250.41:40927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/Jcrop.php"] [unique_id "apPli7z-S0xMfHBNth532AAAAQ4"]
[Sun Aug 30 03:10:51.542504 2026] [security2:error] [pid 517995:tid 518187] [client 20.104.18.15:64092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/nice.php"] [unique_id "apPli7z-S0xMfHBNth534wAAAUY"]
[Sun Aug 30 03:10:51.559851 2026] [security2:error] [pid 517995:tid 518249] [client 20.104.50.220:61687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-conflg.php"] [unique_id "apPli7z-S0xMfHBNth537wAAAYQ"]
[Sun Aug 30 03:10:51.572004 2026] [core:alert] [pid 517995:tid 518201] [client 167.249.28.88:39431] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:10:51.578002 2026] [security2:error] [pid 517995:tid 518190] [client 20.151.200.44:41908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPli7z-S0xMfHBNth53_AAAAUk"]
[Sun Aug 30 03:10:51.582996 2026] [security2:error] [pid 517995:tid 518246] [client 4.205.62.107:16794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/wp-config.backup.php"] [unique_id "apPli7z-S0xMfHBNth54AAAAAYE"]
[Sun Aug 30 03:10:51.597850 2026] [security2:error] [pid 518600:tid 518777] [client 20.48.251.3:52811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/queue.php"] [unique_id "apPli-349Tv4SB45P2m-cwAAALE"]
[Sun Aug 30 03:10:51.652534 2026] [security2:error] [pid 515259:tid 515511] [client 20.48.250.41:40932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/ws58.php"] [unique_id "apPli2ZcVaai59truiWMOAAAAHk"]
[Sun Aug 30 03:10:51.675923 2026] [security2:error] [pid 518600:tid 518743] [client 68.155.159.216:45824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apPli-349Tv4SB45P2m-hQAAAI8"]
[Sun Aug 30 03:10:51.692560 2026] [security2:error] [pid 517995:tid 518181] [client 20.104.18.15:43845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/wp-includes/ID3/moon.php"] [unique_id "apPli7z-S0xMfHBNth54PgAAAUA"]
[Sun Aug 30 03:10:51.720206 2026] [security2:error] [pid 517995:tid 518133] [client 20.63.219.114:32254] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpanel.mirlabs.com"] [uri "/c99.php"] [unique_id "apPli7z-S0xMfHBNth54WgAAARA"]
[Sun Aug 30 03:10:51.728156 2026] [security2:error] [pid 517995:tid 518188] [client 20.197.61.180:3828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/upgrade-temp-backup/themes/login.php"] [unique_id "apPli7z-S0xMfHBNth54ZgAAAUc"]
[Sun Aug 30 03:10:51.729908 2026] [authz_core:error] [pid 515259:tid 515423] [client 216.73.216.128:7620] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:51.730219 2026] [authz_core:error] [pid 515259:tid 515423] [client 216.73.216.128:7620] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:51.746447 2026] [security2:error] [pid 517995:tid 518131] [client 20.48.251.3:59874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/edit.php"] [unique_id "apPli7z-S0xMfHBNth54dgAAAQ4"]
[Sun Aug 30 03:10:51.787634 2026] [security2:error] [pid 517995:tid 518169] [client 158.23.147.79:61797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apPli7z-S0xMfHBNth54igAAATQ"]
[Sun Aug 30 03:10:51.811754 2026] [security2:error] [pid 515259:tid 515511] [client 20.104.49.130:60949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/abc.php"] [unique_id "apPli2ZcVaai59truiWMdgAAAHk"]
[Sun Aug 30 03:10:51.814220 2026] [security2:error] [pid 518600:tid 518780] [client 20.48.250.41:40770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/xs.php"] [unique_id "apPli-349Tv4SB45P2m-nQAAALQ"]
[Sun Aug 30 03:10:51.844217 2026] [security2:error] [pid 518600:tid 518858] [client 20.104.18.15:64708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/fpwch.php"] [unique_id "apPli-349Tv4SB45P2m-ogAAAQI"]
[Sun Aug 30 03:10:51.888754 2026] [authz_core:error] [pid 515259:tid 515452] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:51.889209 2026] [authz_core:error] [pid 515259:tid 515452] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:51.889355 2026] [core:alert] [pid 518600:tid 518788] [client 213.32.68.81:56420] /home3/lordrcan/public_html/.htaccess: without matching section
[Sun Aug 30 03:10:51.897276 2026] [security2:error] [pid 515259:tid 515397] [client 57.131.147.192:59572] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdsafetysystems.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "apPli2ZcVaai59truiWMjwAAAAc"]
[Sun Aug 30 03:10:51.924194 2026] [security2:error] [pid 515259:tid 515474] [client 162.19.94.70:36907] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "whyshamanismnow.com"] [uri "/"] [unique_id "apPli2ZcVaai59truiWMmAAAAFQ"]
[Sun Aug 30 03:10:51.937957 2026] [security2:error] [pid 517995:tid 518192] [client 4.205.62.107:15954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/ammika.php"] [unique_id "apPli7z-S0xMfHBNth55GQAAAUs"]
[Sun Aug 30 03:10:51.965525 2026] [security2:error] [pid 517995:tid 518190] [client 20.104.50.220:63220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPli7z-S0xMfHBNth55NQAAAUk"]
[Sun Aug 30 03:10:51.965678 2026] [security2:error] [pid 517995:tid 518218] [client 4.205.62.107:36088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/pouhg.php"] [unique_id "apPli7z-S0xMfHBNth55NgAAAWU"]
[Sun Aug 30 03:10:51.977934 2026] [security2:error] [pid 515259:tid 515494] [client 20.48.250.41:40833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/zu.php"] [unique_id "apPli2ZcVaai59truiWMrQAAAGg"]
[Sun Aug 30 03:10:51.996922 2026] [authz_core:error] [pid 517995:tid 518186] [client 66.249.66.67:62036] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:51.997371 2026] [authz_core:error] [pid 517995:tid 518186] [client 66.249.66.67:62036] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:52.006790 2026] [authz_core:error] [pid 515259:tid 515503] [client 216.73.216.128:21613] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:52.007069 2026] [authz_core:error] [pid 515259:tid 515503] [client 216.73.216.128:21613] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:52.034676 2026] [security2:error] [pid 517995:tid 518226] [client 158.23.147.79:61771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apPljLz-S0xMfHBNth55YQAAAW0"]
[Sun Aug 30 03:10:52.047402 2026] [security2:error] [pid 517995:tid 518150] [client 20.48.251.3:14108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/umgebung.php"] [unique_id "apPljLz-S0xMfHBNth55cAAAASE"]
[Sun Aug 30 03:10:52.075502 2026] [security2:error] [pid 517995:tid 518206] [client 20.104.50.220:52839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/about.php"] [unique_id "apPljLz-S0xMfHBNth55kAAAAVk"]
[Sun Aug 30 03:10:52.079336 2026] [security2:error] [pid 517995:tid 518161] [client 40.83.93.50:10706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/aa.php"] [unique_id "apPljLz-S0xMfHBNth55kgAAASw"]
[Sun Aug 30 03:10:52.110694 2026] [authz_core:error] [pid 517995:tid 518232] [client 66.249.66.33:62684] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:52.110989 2026] [authz_core:error] [pid 517995:tid 518232] [client 66.249.66.33:62684] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:52.138805 2026] [security2:error] [pid 518600:tid 518840] [client 20.48.250.41:40944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/lanka.php"] [unique_id "apPljO349Tv4SB45P2m-5gAAAPA"]
[Sun Aug 30 03:10:52.147081 2026] [security2:error] [pid 517995:tid 518220] [client 158.23.147.79:61992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apPljLz-S0xMfHBNth551gAAAWc"]
[Sun Aug 30 03:10:52.158877 2026] [security2:error] [pid 518600:tid 518778] [client 4.205.62.107:61717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/wp-tem.php"] [unique_id "apPljO349Tv4SB45P2m-6wAAALI"]
[Sun Aug 30 03:10:52.216190 2026] [security2:error] [pid 517995:tid 518170] [client 20.104.18.15:22484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/33.php"] [unique_id "apPljLz-S0xMfHBNth56GQAAATU"]
[Sun Aug 30 03:10:52.245051 2026] [security2:error] [pid 517995:tid 518176] [client 20.104.50.220:62843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/anu.php"] [unique_id "apPljLz-S0xMfHBNth56KAAAATs"]
[Sun Aug 30 03:10:52.245121 2026] [security2:error] [pid 515259:tid 515508] [client 68.155.159.216:62649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/cgi-bin/index.php"] [unique_id "apPljGZcVaai59truiWNDQAAAHY"]
[Sun Aug 30 03:10:52.266736 2026] [security2:error] [pid 518600:tid 518815] [client 20.48.250.41:40784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/gettest.php"] [unique_id "apPljO349Tv4SB45P2m--AAAANc"]
[Sun Aug 30 03:10:52.269600 2026] [security2:error] [pid 517995:tid 518142] [client 20.104.18.15:18260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/5656.php"] [unique_id "apPljLz-S0xMfHBNth56OQAAARk"]
[Sun Aug 30 03:10:52.285391 2026] [security2:error] [pid 517995:tid 518180] [client 20.104.50.220:51572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/images/leaf.php"] [unique_id "apPljLz-S0xMfHBNth56QwAAAT8"]
[Sun Aug 30 03:10:52.330200 2026] [security2:error] [pid 517995:tid 518243] [client 158.23.147.79:61768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apPljLz-S0xMfHBNth56dwAAAX4"]
[Sun Aug 30 03:10:52.366532 2026] [authz_core:error] [pid 515259:tid 515498] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:52.366932 2026] [authz_core:error] [pid 515259:tid 515498] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:52.397083 2026] [security2:error] [pid 517995:tid 518131] [client 20.48.250.41:40818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/35.php"] [unique_id "apPljLz-S0xMfHBNth56pAAAAQ4"]
[Sun Aug 30 03:10:52.405075 2026] [security2:error] [pid 518600:tid 518850] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPljO349Tv4SB45P2m_KgAAAPo"]
[Sun Aug 30 03:10:52.420025 2026] [authz_core:error] [pid 515259:tid 515405] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:52.420399 2026] [authz_core:error] [pid 515259:tid 515405] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:52.426282 2026] [security2:error] [pid 515259:tid 515467] [client 20.104.50.220:6104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/revision.php"] [unique_id "apPljGZcVaai59truiWNVAAAAE0"]
[Sun Aug 30 03:10:52.429898 2026] [security2:error] [pid 517995:tid 518130] [client 20.104.50.220:32838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/images/sym403.php"] [unique_id "apPljLz-S0xMfHBNth56ugAAAQ0"]
[Sun Aug 30 03:10:52.432749 2026] [security2:error] [pid 515259:tid 515478] [client 20.197.61.180:15762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/upgrade-temp-backup/themes/test.php"] [unique_id "apPljGZcVaai59truiWNVgAAAFg"]
[Sun Aug 30 03:10:52.447694 2026] [security2:error] [pid 517995:tid 518212] [client 20.104.18.15:31713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPljLz-S0xMfHBNth56zQAAAV8"]
[Sun Aug 30 03:10:52.450925 2026] [security2:error] [pid 515259:tid 515410] [client 195.178.110.247:53238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mta-sts.autoinsurancefor.me"] [uri "/index.php"] [unique_id "apPljGZcVaai59truiWNYAAAABQ"]
[Sun Aug 30 03:10:52.467943 2026] [security2:error] [pid 518600:tid 518851] [client 20.48.251.3:64258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/fleen.php"] [unique_id "apPljO349Tv4SB45P2m_OgAAAPs"]
[Sun Aug 30 03:10:52.525718 2026] [security2:error] [pid 517995:tid 518143] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPljLz-S0xMfHBNth566wAAARo"]
[Sun Aug 30 03:10:52.544325 2026] [security2:error] [pid 517995:tid 518208] [client 20.48.250.41:40931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/maraz.php"] [unique_id "apPljLz-S0xMfHBNth56-QAAAVs"]
[Sun Aug 30 03:10:52.574298 2026] [security2:error] [pid 515259:tid 515413] [client 20.104.50.220:16668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-includes/customize/about.php"] [unique_id "apPljGZcVaai59truiWNkAAAABc"]
[Sun Aug 30 03:10:52.586164 2026] [security2:error] [pid 515259:tid 515454] [client 57.131.147.192:62094] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdsafetysystems.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "apPljGZcVaai59truiWNlwAAAEA"]
[Sun Aug 30 03:10:52.593728 2026] [security2:error] [pid 517995:tid 518232] [client 68.155.159.216:52262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apPljLz-S0xMfHBNth57IgAAAXM"]
[Sun Aug 30 03:10:52.615526 2026] [security2:error] [pid 517995:tid 518252] [client 195.178.110.247:33490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mta-sts.autoinsurancefor.me"] [uri "/index.php"] [unique_id "apPljLz-S0xMfHBNth57NAAAAYc"]
[Sun Aug 30 03:10:52.647657 2026] [security2:error] [pid 517995:tid 518150] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/images/cong.php"] [unique_id "apPljLz-S0xMfHBNth57PAAAASE"]
[Sun Aug 30 03:10:52.677217 2026] [security2:error] [pid 518600:tid 518748] [client 40.83.93.50:6260] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpanel.riverglenhoa.com"] [uri "/c99.php"] [unique_id "apPljO349Tv4SB45P2m_ZAAAAJQ"]
[Sun Aug 30 03:10:52.678163 2026] [security2:error] [pid 517995:tid 518137] [client 20.104.18.15:64875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/beence.php"] [unique_id "apPljLz-S0xMfHBNth57WgAAARQ"]
[Sun Aug 30 03:10:52.679363 2026] [security2:error] [pid 517995:tid 518209] [client 20.48.250.41:40920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/kbfr.php"] [unique_id "apPljLz-S0xMfHBNth57WwAAAVw"]
[Sun Aug 30 03:10:52.681389 2026] [security2:error] [pid 518600:tid 518796] [client 4.205.62.107:26970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/png.php"] [unique_id "apPljO349Tv4SB45P2m_ZQAAAMQ"]
[Sun Aug 30 03:10:52.716522 2026] [core:alert] [pid 517995:tid 518162] [client 67.230.45.49:49896] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:10:52.736544 2026] [security2:error] [pid 518600:tid 518793] [client 4.205.62.107:17098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/edit.php"] [unique_id "apPljO349Tv4SB45P2m_cQAAAME"]
[Sun Aug 30 03:10:52.761750 2026] [authz_core:error] [pid 515259:tid 515484] [client 216.73.216.128:21613] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:52.762011 2026] [authz_core:error] [pid 515259:tid 515484] [client 216.73.216.128:21613] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:52.764811 2026] [authz_core:error] [pid 517995:tid 518162] [client 66.249.66.78:54251] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:52.765067 2026] [authz_core:error] [pid 517995:tid 518162] [client 66.249.66.78:54251] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:52.765523 2026] [security2:error] [pid 518600:tid 518780] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp-admin/load-styles.php"] [unique_id "apPljO349Tv4SB45P2m_fgAAALQ"]
[Sun Aug 30 03:10:52.800465 2026] [security2:error] [pid 517995:tid 518221] [client 20.48.251.3:55739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/doc.php"] [unique_id "apPljLz-S0xMfHBNth57twAAAWg"]
[Sun Aug 30 03:10:52.805940 2026] [security2:error] [pid 518600:tid 518803] [client 20.151.200.44:28550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/ft.php"] [unique_id "apPljO349Tv4SB45P2m_hgAAAMs"]
[Sun Aug 30 03:10:52.806298 2026] [security2:error] [pid 517995:tid 518149] [client 20.104.50.220:61447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-ctac.php"] [unique_id "apPljLz-S0xMfHBNth57vwAAASA"]
[Sun Aug 30 03:10:52.813160 2026] [security2:error] [pid 517995:tid 518183] [client 20.48.250.41:40937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/wp-act.php"] [unique_id "apPljLz-S0xMfHBNth57xQAAAUI"]
[Sun Aug 30 03:10:52.841325 2026] [security2:error] [pid 517995:tid 518198] [client 20.104.18.15:43996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/xmini4.php"] [unique_id "apPljLz-S0xMfHBNth574QAAAVE"]
[Sun Aug 30 03:10:52.846686 2026] [authz_core:error] [pid 515259:tid 515443] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:52.847154 2026] [authz_core:error] [pid 515259:tid 515443] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:52.881693 2026] [authz_core:error] [pid 517995:tid 518174] [client 66.249.66.198:62996] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:52.882131 2026] [authz_core:error] [pid 517995:tid 518174] [client 66.249.66.198:62996] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:52.887354 2026] [security2:error] [pid 517995:tid 518169] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/images/wp-2019.php"] [unique_id "apPljLz-S0xMfHBNth58EQAAATQ"]
[Sun Aug 30 03:10:52.895591 2026] [security2:error] [pid 518600:tid 518798] [client 20.63.219.114:2936] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpanel.mirlabs.com"] [uri "/c99.php"] [unique_id "apPljO349Tv4SB45P2m_kwAAAMY"]
[Sun Aug 30 03:10:52.910047 2026] [security2:error] [pid 518600:tid 518839] [client 20.48.251.3:52188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/8.php"] [unique_id "apPljO349Tv4SB45P2m_lAAAAO8"]
[Sun Aug 30 03:10:52.946533 2026] [authz_core:error] [pid 518600:tid 518821] [client 66.249.66.200:46999] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:52.946971 2026] [authz_core:error] [pid 518600:tid 518821] [client 66.249.66.200:46999] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:52.964120 2026] [authz_core:error] [pid 515259:tid 515447] [client 216.73.216.128:21613] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:52.964428 2026] [authz_core:error] [pid 515259:tid 515447] [client 216.73.216.128:21613] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:52.966919 2026] [security2:error] [pid 517995:tid 518180] [client 20.48.250.41:40850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/24.php"] [unique_id "apPljLz-S0xMfHBNth58VgAAAT8"]
[Sun Aug 30 03:10:52.987537 2026] [security2:error] [pid 517995:tid 518137] [client 20.104.18.15:17002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/domvf.php"] [unique_id "apPljLz-S0xMfHBNth58aAAAARQ"]
[Sun Aug 30 03:10:53.006550 2026] [security2:error] [pid 517995:tid 518141] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/images/getid3s.php"] [unique_id "apPljbz-S0xMfHBNth58cgAAARg"]
[Sun Aug 30 03:10:53.012540 2026] [core:alert] [pid 515259:tid 515435] [client 103.162.185.66:58978] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:10:53.052907 2026] [authz_core:error] [pid 515259:tid 515407] [client 216.73.216.128:5489] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:53.053192 2026] [authz_core:error] [pid 515259:tid 515407] [client 216.73.216.128:5489] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:53.075832 2026] [security2:error] [pid 518600:tid 518839] [client 4.205.62.107:15955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/broadcasting.php"] [unique_id "apPlje349Tv4SB45P2m_ywAAAO8"]
[Sun Aug 30 03:10:53.076999 2026] [security2:error] [pid 518600:tid 518838] [client 158.23.147.79:61778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apPlje349Tv4SB45P2m_zAAAAO4"]
[Sun Aug 30 03:10:53.108570 2026] [security2:error] [pid 518600:tid 518845] [client 20.48.250.41:40774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/155.php"] [unique_id "apPlje349Tv4SB45P2m_3AAAAPU"]
[Sun Aug 30 03:10:53.112348 2026] [security2:error] [pid 518600:tid 518814] [client 20.104.50.220:63211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-blog.php"] [unique_id "apPlje349Tv4SB45P2m_4AAAANY"]
[Sun Aug 30 03:10:53.123936 2026] [security2:error] [pid 517995:tid 518172] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPljbz-S0xMfHBNth581QAAATc"]
[Sun Aug 30 03:10:53.127953 2026] [security2:error] [pid 518600:tid 518856] [client 4.205.62.107:36090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/phpversion.php"] [unique_id "apPlje349Tv4SB45P2m_6AAAAQA"]
[Sun Aug 30 03:10:53.141460 2026] [security2:error] [pid 517995:tid 518109] [remote 66.116.251.167:34326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.251.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "basichoa.com"] [uri "/wp-login.php"] [unique_id "apPljbz-S0xMfHBNth586wABDG8"]
[Sun Aug 30 03:10:53.145818 2026] [security2:error] [pid 517995:tid 518205] [client 20.197.61.180:16850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/upgrade-temp-backup/themes/wp-links-opml.php"] [unique_id "apPljbz-S0xMfHBNth587gAAAVg"]
[Sun Aug 30 03:10:53.182334 2026] [security2:error] [pid 518600:tid 518810] [client 20.48.251.3:13429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/old_phpinfo.php"] [unique_id "apPlje349Tv4SB45P2m_-gAAANI"]
[Sun Aug 30 03:10:53.183638 2026] [security2:error] [pid 517995:tid 518238] [client 40.83.93.50:6254] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpanel.riverglenhoa.com"] [uri "/c99.php"] [unique_id "apPljbz-S0xMfHBNth59EgAAAXk"]
[Sun Aug 30 03:10:53.213470 2026] [security2:error] [pid 517995:tid 518144] [client 20.104.50.220:29584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/angel.php"] [unique_id "apPljbz-S0xMfHBNth59IQAAARs"]
[Sun Aug 30 03:10:53.244865 2026] [security2:error] [pid 517995:tid 518153] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/404.php"] [unique_id "apPljbz-S0xMfHBNth59MgAAASQ"]
[Sun Aug 30 03:10:53.252498 2026] [authz_core:error] [pid 515259:tid 515395] [client 66.249.66.199:60822] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:53.252919 2026] [authz_core:error] [pid 515259:tid 515395] [client 66.249.66.199:60822] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:53.276994 2026] [security2:error] [pid 518600:tid 518816] [client 57.131.147.192:51806] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdsafetysystems.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "apPlje349Tv4SB45P2nABQAAANg"]
[Sun Aug 30 03:10:53.298830 2026] [security2:error] [pid 518600:tid 518834] [client 20.48.250.41:40956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/file.php"] [unique_id "apPlje349Tv4SB45P2nADQAAAOo"]
[Sun Aug 30 03:10:53.300952 2026] [security2:error] [pid 517995:tid 518178] [client 20.151.200.44:40909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/qi.php"] [unique_id "apPljbz-S0xMfHBNth59XgAAAT0"]
[Sun Aug 30 03:10:53.301063 2026] [authz_core:error] [pid 517995:tid 518194] [client 66.249.66.202:45262] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:53.301328 2026] [authz_core:error] [pid 517995:tid 518194] [client 66.249.66.202:45262] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:53.311491 2026] [security2:error] [pid 518600:tid 518738] [client 4.205.62.107:58437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/txets.php"] [unique_id "apPlje349Tv4SB45P2nAFAAAAIo"]
[Sun Aug 30 03:10:53.356805 2026] [authz_core:error] [pid 515259:tid 515411] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:53.357091 2026] [authz_core:error] [pid 515259:tid 515411] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:53.362180 2026] [security2:error] [pid 517995:tid 518148] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp-includes/post.php"] [unique_id "apPljbz-S0xMfHBNth59kQAAAR8"]
[Sun Aug 30 03:10:53.365695 2026] [security2:error] [pid 518600:tid 518794] [client 68.155.159.216:57070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPlje349Tv4SB45P2nAMwAAAMI"]
[Sun Aug 30 03:10:53.385868 2026] [security2:error] [pid 518600:tid 518786] [client 20.104.50.220:28679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/loip2.php"] [unique_id "apPlje349Tv4SB45P2nAPAAAALo"]
[Sun Aug 30 03:10:53.390503 2026] [security2:error] [pid 517995:tid 518247] [client 20.104.18.15:22432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/133.php"] [unique_id "apPljbz-S0xMfHBNth59tAAAAYI"]
[Sun Aug 30 03:10:53.417610 2026] [security2:error] [pid 518600:tid 518773] [client 20.104.18.15:18255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/w3lls.php"] [unique_id "apPlje349Tv4SB45P2nASgAAAK0"]
[Sun Aug 30 03:10:53.424512 2026] [security2:error] [pid 517995:tid 518180] [client 20.104.50.220:42033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/images/wso.php"] [unique_id "apPljbz-S0xMfHBNth591AAAAT8"]
[Sun Aug 30 03:10:53.424547 2026] [authz_core:error] [pid 515259:tid 515487] [client 216.73.216.128:21613] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:53.424926 2026] [authz_core:error] [pid 515259:tid 515487] [client 216.73.216.128:21613] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:53.431496 2026] [security2:error] [pid 517995:tid 518236] [client 68.155.159.216:45896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apPljbz-S0xMfHBNth591gAAAXc"]
[Sun Aug 30 03:10:53.458540 2026] [security2:error] [pid 518600:tid 518767] [client 20.48.250.41:40954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPlje349Tv4SB45P2nAVgAAAKc"]
[Sun Aug 30 03:10:53.480638 2026] [security2:error] [pid 517995:tid 518187] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/filefuns.php"] [unique_id "apPljbz-S0xMfHBNth596AAAAUY"]
[Sun Aug 30 03:10:53.523283 2026] [authz_core:error] [pid 515259:tid 515457] [client 216.73.216.128:5489] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:53.523725 2026] [authz_core:error] [pid 515259:tid 515457] [client 216.73.216.128:5489] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:53.557932 2026] [security2:error] [pid 518600:tid 518794] [client 158.23.147.79:61954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/packed.php"] [unique_id "apPlje349Tv4SB45P2nAaAAAAMI"]
[Sun Aug 30 03:10:53.577135 2026] [security2:error] [pid 517995:tid 518181] [client 20.104.50.220:5505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/screen.php"] [unique_id "apPljbz-S0xMfHBNth5-RQAAAUA"]
[Sun Aug 30 03:10:53.582342 2026] [security2:error] [pid 515259:tid 515498] [client 20.104.50.220:33203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/images/leafmailer2.8.php"] [unique_id "apPljWZcVaai59truiWPEQAAAGw"]
[Sun Aug 30 03:10:53.585739 2026] [security2:error] [pid 517995:tid 518129] [client 20.104.18.15:31725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wsd.php"] [unique_id "apPljbz-S0xMfHBNth5-SQAAAQw"]
[Sun Aug 30 03:10:53.599217 2026] [security2:error] [pid 517995:tid 518195] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp-admin/load-scripts.php"] [unique_id "apPljbz-S0xMfHBNth5-VgAAAU4"]
[Sun Aug 30 03:10:53.609526 2026] [security2:error] [pid 517995:tid 518141] [client 20.48.250.41:40905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/06.php"] [unique_id "apPljbz-S0xMfHBNth5-XAAAARg"]
[Sun Aug 30 03:10:53.610961 2026] [security2:error] [pid 517995:tid 518164] [client 20.48.251.3:54758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/upload.form.php"] [unique_id "apPljbz-S0xMfHBNth5-YgAAAS8"]
[Sun Aug 30 03:10:53.619913 2026] [authz_core:error] [pid 517995:tid 518136] [client 66.249.66.203:59936] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:53.620385 2026] [authz_core:error] [pid 517995:tid 518136] [client 66.249.66.203:59936] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:53.642508 2026] [authz_core:error] [pid 515259:tid 515445] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:53.642801 2026] [authz_core:error] [pid 515259:tid 515445] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:53.696079 2026] [security2:error] [pid 515259:tid 515469] [client 216.73.216.128:5489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts2/updateconf"] [unique_id "apPljWZcVaai59truiWPNgAAAE8"]
[Sun Aug 30 03:10:53.710370 2026] [security2:error] [pid 517995:tid 518141] [client 20.104.50.220:17297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/index/function.php"] [unique_id "apPljbz-S0xMfHBNth5-vgAAARg"]
[Sun Aug 30 03:10:53.718470 2026] [security2:error] [pid 517995:tid 518217] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp-cron.php"] [unique_id "apPljbz-S0xMfHBNth5-xAAAAWQ"]
[Sun Aug 30 03:10:53.736029 2026] [security2:error] [pid 518600:tid 518857] [client 20.48.250.41:40888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/class.php"] [unique_id "apPlje349Tv4SB45P2nAnAAAAQE"]
[Sun Aug 30 03:10:53.769917 2026] [security2:error] [pid 517995:tid 518184] [client 195.178.110.247:22452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.midwestdancefest.com"] [uri "/index.php"] [unique_id "apPljbz-S0xMfHBNth5-6AAAAUM"]
[Sun Aug 30 03:10:53.812380 2026] [security2:error] [pid 517995:tid 518250] [client 40.83.93.50:22132] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpanel.riverglenhoa.com"] [uri "/c99.php"] [unique_id "apPljbz-S0xMfHBNth5--gAAAYU"]
[Sun Aug 30 03:10:53.817156 2026] [security2:error] [pid 517995:tid 518216] [client 20.104.18.15:64870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/222.php"] [unique_id "apPljbz-S0xMfHBNth5_AAAAAWM"]
[Sun Aug 30 03:10:53.842047 2026] [security2:error] [pid 517995:tid 518230] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/btx25.php"] [unique_id "apPljbz-S0xMfHBNth5_HQAAAXE"]
[Sun Aug 30 03:10:53.847783 2026] [authz_core:error] [pid 518600:tid 518748] [client 66.249.66.204:58303] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:53.848082 2026] [authz_core:error] [pid 518600:tid 518748] [client 66.249.66.204:58303] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:53.868670 2026] [security2:error] [pid 515259:tid 515431] [client 20.197.61.180:3803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/upgrade-temp-backup/themes/wp-settings.php"] [unique_id "apPljWZcVaai59truiWPfQAAACk"]
[Sun Aug 30 03:10:53.869398 2026] [security2:error] [pid 517995:tid 518239] [client 20.48.250.41:40791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/8.php"] [unique_id "apPljbz-S0xMfHBNth5_LwAAAXo"]
[Sun Aug 30 03:10:53.875792 2026] [security2:error] [pid 517995:tid 518192] [client 4.205.62.107:17680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/8.php"] [unique_id "apPljbz-S0xMfHBNth5_NQAAAUs"]
[Sun Aug 30 03:10:53.888132 2026] [authz_core:error] [pid 515259:tid 515476] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:53.888594 2026] [authz_core:error] [pid 515259:tid 515476] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:53.895958 2026] [security2:error] [pid 518600:tid 518845] [client 20.63.219.114:14733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/test1.php"] [unique_id "apPlje349Tv4SB45P2nAwgAAAPU"]
[Sun Aug 30 03:10:53.904341 2026] [security2:error] [pid 518600:tid 518824] [client 20.104.49.130:63590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/gecko-new.php"] [unique_id "apPlje349Tv4SB45P2nAzAAAAOA"]
[Sun Aug 30 03:10:53.912863 2026] [authz_core:error] [pid 517995:tid 518225] [client 66.249.66.41:60154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:53.913323 2026] [authz_core:error] [pid 517995:tid 518225] [client 66.249.66.41:60154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:53.940967 2026] [security2:error] [pid 518600:tid 518774] [client 195.178.110.247:64796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.midwestdancefest.com"] [uri "/index.php"] [unique_id "apPlje349Tv4SB45P2nA2wAAAK4"]
[Sun Aug 30 03:10:53.943536 2026] [security2:error] [pid 517995:tid 518236] [client 57.131.147.192:56627] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdsafetysystems.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "apPljbz-S0xMfHBNth5_dgAAAXc"]
[Sun Aug 30 03:10:53.949098 2026] [security2:error] [pid 515259:tid 515507] [client 20.48.251.3:59271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/css.php"] [unique_id "apPljWZcVaai59truiWPmQAAAHU"]
[Sun Aug 30 03:10:53.961286 2026] [security2:error] [pid 515259:tid 515470] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/images/g3.php"] [unique_id "apPljWZcVaai59truiWPnwAAAFA"]
[Sun Aug 30 03:10:53.978688 2026] [security2:error] [pid 518600:tid 518859] [client 4.205.62.107:25487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/chosen.php"] [unique_id "apPlje349Tv4SB45P2nA5QAAAQM"]
[Sun Aug 30 03:10:53.987653 2026] [security2:error] [pid 517995:tid 518147] [client 20.104.50.220:61377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-defaul.php"] [unique_id "apPljbz-S0xMfHBNth5_mQAAAR4"]
[Sun Aug 30 03:10:53.990266 2026] [security2:error] [pid 517995:tid 518243] [client 20.104.18.15:43867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/gulu.php"] [unique_id "apPljbz-S0xMfHBNth5_mwAAAX4"]
[Sun Aug 30 03:10:53.999050 2026] [security2:error] [pid 517995:tid 518169] [client 20.48.250.41:40896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/0x0x.php"] [unique_id "apPljbz-S0xMfHBNth5_ogAAATQ"]
[Sun Aug 30 03:10:54.064064 2026] [security2:error] [pid 518600:tid 518831] [client 20.48.251.3:52205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/thui.php"] [unique_id "apPlju349Tv4SB45P2nBBwAAAOc"]
[Sun Aug 30 03:10:54.077739 2026] [security2:error] [pid 517995:tid 518238] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp-theme.php"] [unique_id "apPljrz-S0xMfHBNth5_4wAAAXk"]
[Sun Aug 30 03:10:54.082632 2026] [security2:error] [pid 518600:tid 518610] [remote 47.128.31.197:27040] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cravegoldcoast.com.au"] [uri "/directory/takeaways.html"] [unique_id "apPlju349Tv4SB45P2nBEQAAwwY"]
[Sun Aug 30 03:10:54.124794 2026] [security2:error] [pid 517995:tid 518229] [client 20.104.18.15:16995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/biufile.php"] [unique_id "apPljrz-S0xMfHBNth6ADwAAAXA"]
[Sun Aug 30 03:10:54.142148 2026] [security2:error] [pid 517995:tid 518250] [client 20.48.250.41:40858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/166.php"] [unique_id "apPljrz-S0xMfHBNth6AJQAAAYU"]
[Sun Aug 30 03:10:54.159320 2026] [authz_core:error] [pid 515259:tid 515438] [client 216.73.216.128:33811] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:54.159572 2026] [authz_core:error] [pid 515259:tid 515438] [client 216.73.216.128:33811] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:54.169105 2026] [security2:error] [pid 517995:tid 518198] [client 68.155.159.216:52301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-admin/images/about.php"] [unique_id "apPljrz-S0xMfHBNth6APgAAAVE"]
[Sun Aug 30 03:10:54.187074 2026] [core:alert] [pid 515259:tid 515456] [client 45.225.57.85:22126] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:10:54.200782 2026] [security2:error] [pid 515259:tid 515458] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/admin.php/admin.php"] [unique_id "apPljmZcVaai59truiWQIgAAAEQ"]
[Sun Aug 30 03:10:54.216380 2026] [security2:error] [pid 517995:tid 518147] [client 4.205.62.107:16322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/aws_config.php"] [unique_id "apPljrz-S0xMfHBNth6AVgAAAR4"]
[Sun Aug 30 03:10:54.248966 2026] [authz_core:error] [pid 518600:tid 518769] [client 216.73.216.128:52324] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:54.249222 2026] [authz_core:error] [pid 518600:tid 518769] [client 216.73.216.128:52324] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:54.286350 2026] [security2:error] [pid 517995:tid 518175] [client 20.48.250.41:40793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/h2a2ck.php"] [unique_id "apPljrz-S0xMfHBNth6AeQAAATo"]
[Sun Aug 30 03:10:54.303526 2026] [security2:error] [pid 518600:tid 518773] [client 4.205.62.107:36086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/adminfus.php"] [unique_id "apPlju349Tv4SB45P2nBPAAAAK0"]
[Sun Aug 30 03:10:54.319711 2026] [security2:error] [pid 518600:tid 518738] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/simple.php"] [unique_id "apPlju349Tv4SB45P2nBSQAAAIo"]
[Sun Aug 30 03:10:54.329431 2026] [security2:error] [pid 515259:tid 515415] [client 40.83.93.50:22084] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpanel.riverglenhoa.com"] [uri "/c99.php"] [unique_id "apPljmZcVaai59truiWQcwAAABk"]
[Sun Aug 30 03:10:54.334903 2026] [security2:error] [pid 517995:tid 518182] [client 20.48.251.3:14139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dieflanders.de"] [uri "/wp-act.php"] [unique_id "apPljrz-S0xMfHBNth6AlwAAAUE"]
[Sun Aug 30 03:10:54.346308 2026] [authz_core:error] [pid 515259:tid 515473] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:54.346563 2026] [authz_core:error] [pid 515259:tid 515473] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:54.354002 2026] [security2:error] [pid 515259:tid 515429] [client 20.63.219.114:15873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/data.php"] [unique_id "apPljmZcVaai59truiWQfQAAACc"]
[Sun Aug 30 03:10:54.354534 2026] [security2:error] [pid 518600:tid 518799] [client 20.104.50.220:29598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/c100.php"] [unique_id "apPlju349Tv4SB45P2nBWAAAAMc"]
[Sun Aug 30 03:10:54.360731 2026] [security2:error] [pid 515259:tid 515478] [client 20.104.50.220:63193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-content/admin.php"] [unique_id "apPljmZcVaai59truiWQgwAAAFg"]
[Sun Aug 30 03:10:54.369947 2026] [security2:error] [pid 518600:tid 518733] [client 195.178.110.247:41792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.michelleshell.com"] [uri "/index.php"] [unique_id "apPlju349Tv4SB45P2nBYQAAAIU"]
[Sun Aug 30 03:10:54.390618 2026] [security2:error] [pid 518600:tid 518802] [client 158.23.147.79:60184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-content/radio.php"] [unique_id "apPlju349Tv4SB45P2nBaQAAAMo"]
[Sun Aug 30 03:10:54.437033 2026] [security2:error] [pid 517995:tid 518183] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp-ws68.php"] [unique_id "apPljrz-S0xMfHBNth6A6QAAAUI"]
[Sun Aug 30 03:10:54.441209 2026] [security2:error] [pid 517995:tid 518224] [client 20.48.250.41:40801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/error_log.php"] [unique_id "apPljrz-S0xMfHBNth6A7QAAAWs"]
[Sun Aug 30 03:10:54.455167 2026] [security2:error] [pid 517995:tid 518166] [client 4.205.62.107:58255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/time.php"] [unique_id "apPljrz-S0xMfHBNth6A-AAAATE"]
[Sun Aug 30 03:10:54.480180 2026] [security2:error] [pid 517995:tid 518234] [client 68.155.159.216:63271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-includes/content.php"] [unique_id "apPljrz-S0xMfHBNth6A-wAAAXU"]
[Sun Aug 30 03:10:54.509381 2026] [security2:error] [pid 517995:tid 518238] [client 20.151.200.44:28616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/wp-ver.php"] [unique_id "apPljrz-S0xMfHBNth6BCwAAAXk"]
[Sun Aug 30 03:10:54.525707 2026] [security2:error] [pid 517995:tid 518179] [client 20.104.50.220:29179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/json.php"] [unique_id "apPljrz-S0xMfHBNth6BEwAAAT4"]
[Sun Aug 30 03:10:54.534512 2026] [security2:error] [pid 517995:tid 518119] [remote 66.116.251.167:34326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.251.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "basichoa.com"] [uri "/wp-login.php"] [unique_id "apPljrz-S0xMfHBNth6BFQABEnk"], referer: https://basichoa.com/wp-login.php
[Sun Aug 30 03:10:54.540083 2026] [security2:error] [pid 517995:tid 518184] [client 195.178.110.247:52188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.michelleshell.com"] [uri "/index.php"] [unique_id "apPljrz-S0xMfHBNth6BHAAAAUM"]
[Sun Aug 30 03:10:54.553373 2026] [security2:error] [pid 515259:tid 515413] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/mac.php"] [unique_id "apPljmZcVaai59truiWQ3QAAABc"]
[Sun Aug 30 03:10:54.565858 2026] [security2:error] [pid 517995:tid 518182] [client 20.104.18.15:22494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/sym.php"] [unique_id "apPljrz-S0xMfHBNth6BOgAAAUE"]
[Sun Aug 30 03:10:54.576328 2026] [security2:error] [pid 517995:tid 518179] [client 20.48.250.41:40877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/403.php"] [unique_id "apPljrz-S0xMfHBNth6BRgAAAT4"]
[Sun Aug 30 03:10:54.592227 2026] [security2:error] [pid 517995:tid 518239] [client 20.104.50.220:42763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/images/sym403.php"] [unique_id "apPljrz-S0xMfHBNth6BTQAAAXo"]
[Sun Aug 30 03:10:54.598989 2026] [security2:error] [pid 515259:tid 515390] [client 20.104.18.15:18409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/fpwch.php"] [unique_id "apPljmZcVaai59truiWQ-AAAAAA"]
[Sun Aug 30 03:10:54.606234 2026] [security2:error] [pid 515259:tid 515500] [client 216.73.216.128:33811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/classes.html"] [unique_id "apPljmZcVaai59truiWQ_gAAAG4"]
[Sun Aug 30 03:10:54.618626 2026] [security2:error] [pid 515259:tid 515398] [client 57.131.147.192:54523] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdsafetysystems.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "apPljmZcVaai59truiWRAwAAAAg"]
[Sun Aug 30 03:10:54.670614 2026] [security2:error] [pid 515259:tid 515476] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/aaa.php"] [unique_id "apPljmZcVaai59truiWRJQAAAFY"]
[Sun Aug 30 03:10:54.678396 2026] [authz_core:error] [pid 518600:tid 518750] [client 66.249.66.201:35249] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:54.678856 2026] [authz_core:error] [pid 518600:tid 518750] [client 66.249.66.201:35249] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:54.682485 2026] [security2:error] [pid 517995:tid 518120] [remote 114.119.162.58:31791] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "whyshamanismnow.com"] [uri "/tags/veterans/"] [unique_id "apPljrz-S0xMfHBNth6BhgABEHo"]
[Sun Aug 30 03:10:54.712290 2026] [security2:error] [pid 518600:tid 518781] [client 20.48.250.41:40955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/cytyr.php"] [unique_id "apPlju349Tv4SB45P2nB0gAAALU"]
[Sun Aug 30 03:10:54.717590 2026] [security2:error] [pid 518600:tid 518799] [client 20.104.18.15:31703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/bulet.php"] [unique_id "apPlju349Tv4SB45P2nB1AAAAMc"]
[Sun Aug 30 03:10:54.723851 2026] [security2:error] [pid 518600:tid 518805] [client 20.104.50.220:33312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/images/lux.php"] [unique_id "apPlju349Tv4SB45P2nB3gAAAM0"]
[Sun Aug 30 03:10:54.734662 2026] [security2:error] [pid 518600:tid 518753] [client 20.104.50.220:6082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/atomlib.php"] [unique_id "apPlju349Tv4SB45P2nB7AAAAJk"]
[Sun Aug 30 03:10:54.746044 2026] [security2:error] [pid 515259:tid 515494] [client 20.63.219.114:15904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/classwithtostring.php"] [unique_id "apPljmZcVaai59truiWRQQAAAGg"]
[Sun Aug 30 03:10:54.748708 2026] [security2:error] [pid 518600:tid 518845] [client 20.48.251.3:54834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/aws_auth.php"] [unique_id "apPlju349Tv4SB45P2nB_AAAAPU"]
[Sun Aug 30 03:10:54.789670 2026] [security2:error] [pid 517995:tid 518229] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/mail.php"] [unique_id "apPljrz-S0xMfHBNth6BpwAAAXA"]
[Sun Aug 30 03:10:54.818659 2026] [security2:error] [pid 517995:tid 518166] [client 40.83.93.50:3077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/test1.php"] [unique_id "apPljrz-S0xMfHBNth6BsQAAATE"]
[Sun Aug 30 03:10:54.839602 2026] [security2:error] [pid 517995:tid 518237] [client 20.197.61.180:15797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/upgrade/about.php"] [unique_id "apPljrz-S0xMfHBNth6BuAAAAXg"]
[Sun Aug 30 03:10:54.852246 2026] [security2:error] [pid 518600:tid 518753] [client 20.104.50.220:17268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/uploads/autoload_classmap.php"] [unique_id "apPlju349Tv4SB45P2nCUAAAAJk"]
[Sun Aug 30 03:10:54.855377 2026] [authz_core:error] [pid 515259:tid 515464] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:54.856474 2026] [authz_core:error] [pid 515259:tid 515464] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:54.919475 2026] [security2:error] [pid 518600:tid 518851] [client 20.104.49.130:52441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/ioxi-o.php"] [unique_id "apPlju349Tv4SB45P2nCdgAAAPs"]
[Sun Aug 30 03:10:54.924074 2026] [security2:error] [pid 518600:tid 518765] [client 20.48.250.41:40856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/galer.php"] [unique_id "apPlju349Tv4SB45P2nCeAAAAKU"]
[Sun Aug 30 03:10:54.964586 2026] [authz_core:error] [pid 515259:tid 515483] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:54.965056 2026] [authz_core:error] [pid 515259:tid 515483] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:54.966781 2026] [security2:error] [pid 518600:tid 518801] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/images/yes.php"] [unique_id "apPlju349Tv4SB45P2nChAAAAMk"]
[Sun Aug 30 03:10:54.977779 2026] [security2:error] [pid 518600:tid 518738] [client 195.178.110.247:22462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mieloma.es"] [uri "/index.php"] [unique_id "apPlju349Tv4SB45P2nClgAAAIo"]
[Sun Aug 30 03:10:54.988859 2026] [security2:error] [pid 518600:tid 518765] [client 20.104.18.15:64769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/ops.php"] [unique_id "apPlju349Tv4SB45P2nCsgAAAKU"]
[Sun Aug 30 03:10:54.989400 2026] [security2:error] [pid 518600:tid 518757] [client 158.23.147.79:60196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-admin/dropdown.php"] [unique_id "apPlju349Tv4SB45P2nCtAAAAJ0"]
[Sun Aug 30 03:10:55.012733 2026] [security2:error] [pid 518600:tid 518818] [client 4.205.62.107:17089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/thui.php"] [unique_id "apPlj-349Tv4SB45P2nC7QAAANo"]
[Sun Aug 30 03:10:55.082986 2026] [security2:error] [pid 518600:tid 518762] [client 20.104.49.130:60931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/dehnl.php"] [unique_id "apPlj-349Tv4SB45P2nDIwAAAKI"]
[Sun Aug 30 03:10:55.084146 2026] [security2:error] [pid 517995:tid 518182] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/media.php"] [unique_id "apPlj7z-S0xMfHBNth6CQQAAAUE"]
[Sun Aug 30 03:10:55.086963 2026] [security2:error] [pid 518600:tid 518816] [client 20.48.251.3:59373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/php_info.php"] [unique_id "apPlj-349Tv4SB45P2nDJQAAANg"]
[Sun Aug 30 03:10:55.122723 2026] [security2:error] [pid 517995:tid 518227] [client 4.205.62.107:26946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/admin-ajax.php"] [unique_id "apPlj7z-S0xMfHBNth6CZQAAAW4"]
[Sun Aug 30 03:10:55.130469 2026] [security2:error] [pid 518600:tid 518784] [client 20.48.250.41:40891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/baixy.php"] [unique_id "apPlj-349Tv4SB45P2nDNgAAALg"]
[Sun Aug 30 03:10:55.143127 2026] [security2:error] [pid 518600:tid 518821] [client 195.178.110.247:64808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mieloma.es"] [uri "/index.php"] [unique_id "apPlj-349Tv4SB45P2nDOwAAAN0"]
[Sun Aug 30 03:10:55.143511 2026] [lsapi:warn] [pid 518600:tid 518749] [client 185.231.154.128:65524] [host tastylandscape.com] Backend log: PHP Warning: Use of undefined constant user_level - assumed 'user_level' (this will throw an Error in a future version of PHP) in /home4/tommed/public_html/wp-content/plugins/ultimate-google-analytics/ultimate_ga.php on line 524\n, referer: http://tastylandscape.com/2015/09/05/dragon-fruit-diseases/
[Sun Aug 30 03:10:55.147001 2026] [security2:error] [pid 517995:tid 518127] [client 20.104.18.15:43273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/replace.php"] [unique_id "apPlj7z-S0xMfHBNth6CgAAAAQo"]
[Sun Aug 30 03:10:55.170297 2026] [security2:error] [pid 517995:tid 518227] [client 20.151.200.44:28630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/ah24.php"] [unique_id "apPlj7z-S0xMfHBNth6CkwAAAW4"]
[Sun Aug 30 03:10:55.175631 2026] [security2:error] [pid 517995:tid 518133] [client 20.63.219.114:19170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/en.php"] [unique_id "apPlj7z-S0xMfHBNth6CmAAAARA"]
[Sun Aug 30 03:10:55.201545 2026] [security2:error] [pid 517995:tid 518204] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/images/class-config.php"] [unique_id "apPlj7z-S0xMfHBNth6CqgAAAVc"]
[Sun Aug 30 03:10:55.204376 2026] [security2:error] [pid 515259:tid 515437] [client 20.104.50.220:62010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-hmdra.php"] [unique_id "apPlj2ZcVaai59truiWSAAAAAC8"]
[Sun Aug 30 03:10:55.210603 2026] [security2:error] [pid 517995:tid 518168] [client 20.48.251.3:52268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/file21.php"] [unique_id "apPlj7z-S0xMfHBNth6CrgAAATM"]
[Sun Aug 30 03:10:55.242691 2026] [security2:error] [pid 517995:tid 518130] [client 20.151.200.44:64801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/xda.php"] [unique_id "apPlj7z-S0xMfHBNth6CvgAAAQ0"]
[Sun Aug 30 03:10:55.260873 2026] [security2:error] [pid 517995:tid 518152] [client 20.48.250.41:40857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/ava.php"] [unique_id "apPlj7z-S0xMfHBNth6CxQAAASM"]
[Sun Aug 30 03:10:55.268636 2026] [security2:error] [pid 517995:tid 518149] [client 20.104.18.15:16909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/blacks.php"] [unique_id "apPlj7z-S0xMfHBNth6CzQAAASA"]
[Sun Aug 30 03:10:55.308843 2026] [security2:error] [pid 518600:tid 518817] [client 57.131.147.192:59281] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdsafetysystems.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "apPlj-349Tv4SB45P2nDZQAAANk"]
[Sun Aug 30 03:10:55.320568 2026] [security2:error] [pid 517995:tid 518130] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/kill.php"] [unique_id "apPlj7z-S0xMfHBNth6C9AAAAQ0"]
[Sun Aug 30 03:10:55.334164 2026] [security2:error] [pid 517995:tid 518223] [client 40.83.93.50:6542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/data.php"] [unique_id "apPlj7z-S0xMfHBNth6C_gAAAWo"]
[Sun Aug 30 03:10:55.343225 2026] [authz_core:error] [pid 515259:tid 515423] [client 216.73.216.128:21613] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:55.343517 2026] [authz_core:error] [pid 515259:tid 515423] [client 216.73.216.128:21613] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:55.348031 2026] [authz_core:error] [pid 515259:tid 515410] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:55.348329 2026] [authz_core:error] [pid 515259:tid 515410] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:55.356145 2026] [security2:error] [pid 515259:tid 515492] [client 4.205.62.107:16345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/dialog.php"] [unique_id "apPlj2ZcVaai59truiWSUQAAAGY"]
[Sun Aug 30 03:10:55.438927 2026] [security2:error] [pid 517995:tid 518245] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/166.php"] [unique_id "apPlj7z-S0xMfHBNth6DVAAAAYA"]
[Sun Aug 30 03:10:55.454707 2026] [security2:error] [pid 515259:tid 515458] [client 20.48.250.41:40778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/gdn.php"] [unique_id "apPlj2ZcVaai59truiWSgAAAAEQ"]
[Sun Aug 30 03:10:55.494713 2026] [security2:error] [pid 517995:tid 518254] [client 68.155.159.216:54332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPlj7z-S0xMfHBNth6DbAAAAYk"]
[Sun Aug 30 03:10:55.514969 2026] [security2:error] [pid 515259:tid 515404] [client 20.104.50.220:59722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/adminfuns.php"] [unique_id "apPlj2ZcVaai59truiWSpAAAAA4"]
[Sun Aug 30 03:10:55.519905 2026] [security2:error] [pid 517995:tid 518134] [client 20.104.50.220:28716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/simattacker.php"] [unique_id "apPlj7z-S0xMfHBNth6DeQAAARE"]
[Sun Aug 30 03:10:55.533855 2026] [security2:error] [pid 515259:tid 515470] [client 20.197.61.180:3641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garypia.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "apPlj2ZcVaai59truiWSswAAAFA"]
[Sun Aug 30 03:10:55.535596 2026] [security2:error] [pid 517995:tid 518185] [client 158.23.147.79:60195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/login.php"] [unique_id "apPlj7z-S0xMfHBNth6DggAAAUQ"]
[Sun Aug 30 03:10:55.538394 2026] [security2:error] [pid 517995:tid 518162] [client 158.23.147.79:61701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/packed.php"] [unique_id "apPlj7z-S0xMfHBNth6DhwAAAS0"]
[Sun Aug 30 03:10:55.555569 2026] [security2:error] [pid 518600:tid 518755] [client 4.205.62.107:35996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/avim.php"] [unique_id "apPlj-349Tv4SB45P2nDowAAAJs"]
[Sun Aug 30 03:10:55.556692 2026] [security2:error] [pid 518600:tid 518812] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/ops.php"] [unique_id "apPlj-349Tv4SB45P2nDpAAAANQ"]
[Sun Aug 30 03:10:55.591594 2026] [security2:error] [pid 518600:tid 518746] [client 4.205.62.107:64458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/doc.php"] [unique_id "apPlj-349Tv4SB45P2nDrwAAAJI"]
[Sun Aug 30 03:10:55.610523 2026] [security2:error] [pid 515259:tid 515478] [client 216.73.216.128:7620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_compose_send"] [unique_id "apPlj2ZcVaai59truiWS0wAAAFg"]
[Sun Aug 30 03:10:55.644021 2026] [security2:error] [pid 517995:tid 518247] [client 68.155.159.216:63293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-admin/css/index.php"] [unique_id "apPlj7z-S0xMfHBNth6D6wAAAYI"]
[Sun Aug 30 03:10:55.674013 2026] [security2:error] [pid 517995:tid 518254] [client 20.48.250.41:40918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/f2.php"] [unique_id "apPlj7z-S0xMfHBNth6EBwAAAYk"]
[Sun Aug 30 03:10:55.676215 2026] [security2:error] [pid 517995:tid 518205] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/403.php"] [unique_id "apPlj7z-S0xMfHBNth6ECQAAAVg"]
[Sun Aug 30 03:10:55.701593 2026] [security2:error] [pid 518600:tid 518749] [client 20.104.50.220:28709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/java.php"] [unique_id "apPlj-349Tv4SB45P2nD5gAAAJU"]
[Sun Aug 30 03:10:55.733227 2026] [security2:error] [pid 518600:tid 518838] [client 20.104.50.220:51629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/images/leafmailer2.8.php"] [unique_id "apPlj-349Tv4SB45P2nEAgAAAO4"]
[Sun Aug 30 03:10:55.755811 2026] [security2:error] [pid 517995:tid 518201] [client 20.63.219.114:19183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/13.php"] [unique_id "apPlj7z-S0xMfHBNth6ENAAAAVQ"]
[Sun Aug 30 03:10:55.757129 2026] [security2:error] [pid 517995:tid 518162] [client 20.104.18.15:22424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/8.php"] [unique_id "apPlj7z-S0xMfHBNth6ENQAAAS0"]
[Sun Aug 30 03:10:55.793210 2026] [security2:error] [pid 518600:tid 518793] [client 20.104.18.15:18246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/domvf.php"] [unique_id "apPlj-349Tv4SB45P2nELQAAAME"]
[Sun Aug 30 03:10:55.797643 2026] [security2:error] [pid 518600:tid 518838] [client 20.104.50.220:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cagtu.com"] [uri "/images/c99.php"] [unique_id "apPlj-349Tv4SB45P2nELwAAAO4"]
[Sun Aug 30 03:10:55.817589 2026] [authz_core:error] [pid 518600:tid 518814] [client 66.249.66.42:63858] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:55.817904 2026] [authz_core:error] [pid 518600:tid 518814] [client 66.249.66.42:63858] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:55.820211 2026] [security2:error] [pid 517995:tid 518152] [client 40.83.93.50:10737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/classwithtostring.php"] [unique_id "apPlj7z-S0xMfHBNth6EUgAAASM"]
[Sun Aug 30 03:10:55.820515 2026] [security2:error] [pid 518600:tid 518839] [client 20.48.250.41:40862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/grsiuk.php"] [unique_id "apPlj-349Tv4SB45P2nEQQAAAO8"]
[Sun Aug 30 03:10:55.831260 2026] [security2:error] [pid 517995:tid 518218] [client 20.48.160.90:51920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlj7z-S0xMfHBNth6EYAAAAWU"]
[Sun Aug 30 03:10:55.850186 2026] [authz_core:error] [pid 515259:tid 515413] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:55.850607 2026] [authz_core:error] [pid 515259:tid 515413] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:55.858076 2026] [security2:error] [pid 515259:tid 515486] [client 20.104.18.15:31701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/av.php"] [unique_id "apPlj2ZcVaai59truiWTGgAAAGA"]
[Sun Aug 30 03:10:55.866826 2026] [security2:error] [pid 518600:tid 518824] [client 158.23.147.79:56506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/nf_tracking.php"] [unique_id "apPlj-349Tv4SB45P2nEWgAAAOA"]
[Sun Aug 30 03:10:55.870746 2026] [security2:error] [pid 518600:tid 518838] [client 20.104.50.220:5520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/class-wp.php"] [unique_id "apPlj-349Tv4SB45P2nEXQAAAO4"]
[Sun Aug 30 03:10:55.880065 2026] [security2:error] [pid 517995:tid 518189] [client 20.104.50.220:33339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/w3llstore.php"] [unique_id "apPlj7z-S0xMfHBNth6EhQAAAUg"]
[Sun Aug 30 03:10:55.882840 2026] [security2:error] [pid 515259:tid 515448] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/images/ty.php"] [unique_id "apPlj2ZcVaai59truiWTIwAAADo"]
[Sun Aug 30 03:10:55.888011 2026] [security2:error] [pid 518600:tid 518804] [client 20.48.251.3:54823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/hiquido.com/index.php"] [unique_id "apPlj-349Tv4SB45P2nEYAAAAMw"]
[Sun Aug 30 03:10:55.909003 2026] [lsapi:error] [pid 517995:tid 518147] [client 73.94.13.107:53990] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.yandex.com/
[Sun Aug 30 03:10:55.909025 2026] [lsapi:error] [pid 517995:tid 518147] [client 73.94.13.107:53990] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.yandex.com/
[Sun Aug 30 03:10:55.910287 2026] [lsapi:error] [pid 517995:tid 518147] [client 73.94.13.107:53990] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n, referer: https://www.yandex.com/
[Sun Aug 30 03:10:55.973792 2026] [security2:error] [pid 518600:tid 518810] [client 20.48.250.41:40916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/wp-scr1pts.php"] [unique_id "apPlj-349Tv4SB45P2nEswAAANI"]
[Sun Aug 30 03:10:55.982583 2026] [security2:error] [pid 517995:tid 518181] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/dex.php"] [unique_id "apPlj7z-S0xMfHBNth6EwQAAAUA"]
[Sun Aug 30 03:10:55.984927 2026] [security2:error] [pid 517995:tid 518185] [client 57.131.147.192:59857] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdsafetysystems.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "apPlj7z-S0xMfHBNth6ExAAAAUQ"]
[Sun Aug 30 03:10:55.987083 2026] [security2:error] [pid 518600:tid 518830] [client 20.104.50.220:17270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-includes/style-engine/about.php"] [unique_id "apPlj-349Tv4SB45P2nEvQAAAOY"]
[Sun Aug 30 03:10:56.039924 2026] [security2:error] [pid 515259:tid 515416] [client 20.48.160.90:28088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlkGZcVaai59truiWTWgAAABo"]
[Sun Aug 30 03:10:56.069797 2026] [core:alert] [pid 517995:tid 518179] [client 205.147.22.19:42864] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:10:56.083443 2026] [security2:error] [pid 517995:tid 518168] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/images/13.php"] [unique_id "apPlkLz-S0xMfHBNth6FHgAAATM"]
[Sun Aug 30 03:10:56.088601 2026] [security2:error] [pid 517995:tid 518155] [client 20.104.49.130:63517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/wp-blogs.php"] [unique_id "apPlkLz-S0xMfHBNth6FHwAAASY"]
[Sun Aug 30 03:10:56.118476 2026] [security2:error] [pid 517995:tid 518164] [client 20.63.219.114:14727] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.mirlabs.com"] [uri "/1.php"] [unique_id "apPlkLz-S0xMfHBNth6FOgAAAS8"]
[Sun Aug 30 03:10:56.118583 2026] [security2:error] [pid 517995:tid 518164] [client 20.63.219.114:14727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/1.php"] [unique_id "apPlkLz-S0xMfHBNth6FOgAAAS8"]
[Sun Aug 30 03:10:56.120876 2026] [security2:error] [pid 518600:tid 518837] [client 20.48.250.41:40787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/num.php"] [unique_id "apPlkO349Tv4SB45P2nE6gAAAO0"]
[Sun Aug 30 03:10:56.132439 2026] [security2:error] [pid 518600:tid 518793] [client 20.104.18.15:16724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPlkO349Tv4SB45P2nE-wAAAME"]
[Sun Aug 30 03:10:56.154468 2026] [security2:error] [pid 517995:tid 518239] [client 4.205.62.107:17684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/file21.php"] [unique_id "apPlkLz-S0xMfHBNth6FRQAAAXo"]
[Sun Aug 30 03:10:56.164422 2026] [authz_core:error] [pid 515259:tid 515438] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:56.164748 2026] [authz_core:error] [pid 515259:tid 515438] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:56.183614 2026] [security2:error] [pid 517995:tid 518185] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/inx.php"] [unique_id "apPlkLz-S0xMfHBNth6FZgAAAUQ"]
[Sun Aug 30 03:10:56.201715 2026] [security2:error] [pid 515259:tid 515451] [client 158.23.147.79:58369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/hehehehe.php"] [unique_id "apPlkGZcVaai59truiWTlgAAAD0"]
[Sun Aug 30 03:10:56.223117 2026] [security2:error] [pid 517995:tid 518179] [client 20.48.251.3:52763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/session.php"] [unique_id "apPlkLz-S0xMfHBNth6FgAAAAT4"]
[Sun Aug 30 03:10:56.234490 2026] [security2:error] [pid 518600:tid 518781] [client 20.48.160.90:51940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/ap.php"] [unique_id "apPlkO349Tv4SB45P2nFOAAAALU"]
[Sun Aug 30 03:10:56.246949 2026] [security2:error] [pid 515259:tid 515445] [client 68.155.159.216:45914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/packed.php"] [unique_id "apPlkGZcVaai59truiWTrgAAADc"]
[Sun Aug 30 03:10:56.248800 2026] [security2:error] [pid 515259:tid 515467] [client 20.48.250.41:40773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/a4.php"] [unique_id "apPlkGZcVaai59truiWTsAAAAE0"]
[Sun Aug 30 03:10:56.289123 2026] [security2:error] [pid 517995:tid 518200] [client 4.205.62.107:25771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/ms.php"] [unique_id "apPlkLz-S0xMfHBNth6FogAAAVM"]
[Sun Aug 30 03:10:56.313062 2026] [security2:error] [pid 515259:tid 515454] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/images/mar.php"] [unique_id "apPlkGZcVaai59truiWTygAAAEA"]
[Sun Aug 30 03:10:56.313662 2026] [security2:error] [pid 518600:tid 518753] [client 40.83.93.50:6386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/en.php"] [unique_id "apPlkO349Tv4SB45P2nFWQAAAJk"]
[Sun Aug 30 03:10:56.338524 2026] [authz_core:error] [pid 518600:tid 518830] [client 66.249.66.77:52214] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:56.338959 2026] [authz_core:error] [pid 518600:tid 518830] [client 66.249.66.77:52214] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:56.346789 2026] [security2:error] [pid 517995:tid 518176] [client 20.104.18.15:44014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/c4.php"] [unique_id "apPlkLz-S0xMfHBNth6F1wAAATs"]
[Sun Aug 30 03:10:56.347853 2026] [security2:error] [pid 518600:tid 518745] [client 20.104.50.220:61957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-iav.php"] [unique_id "apPlkO349Tv4SB45P2nFaAAAAJE"]
[Sun Aug 30 03:10:56.350789 2026] [security2:error] [pid 517995:tid 518239] [client 20.48.251.3:59459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/mcebraed.php"] [unique_id "apPlkLz-S0xMfHBNth6F2gAAAXo"]
[Sun Aug 30 03:10:56.371731 2026] [authz_core:error] [pid 515259:tid 515459] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:56.372281 2026] [authz_core:error] [pid 515259:tid 515459] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:56.404180 2026] [security2:error] [pid 518600:tid 518840] [client 20.104.18.15:16899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/beck.php"] [unique_id "apPlkO349Tv4SB45P2nFmgAAAPA"]
[Sun Aug 30 03:10:56.422417 2026] [security2:error] [pid 517995:tid 518218] [client 20.48.160.90:28056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/media.php"] [unique_id "apPlkLz-S0xMfHBNth6GFAAAAWU"]
[Sun Aug 30 03:10:56.425978 2026] [core:alert] [pid 515259:tid 515441] [client 5.37.218.96:42180] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:10:56.429099 2026] [security2:error] [pid 515259:tid 515475] [client 20.48.250.41:40939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/tfm.php"] [unique_id "apPlkGZcVaai59truiWT9wAAAFU"]
[Sun Aug 30 03:10:56.434548 2026] [security2:error] [pid 518600:tid 518762] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/shiny.php"] [unique_id "apPlkO349Tv4SB45P2nFqQAAAKI"]
[Sun Aug 30 03:10:56.474380 2026] [security2:error] [pid 518600:tid 518771] [client 216.252.238.248:51496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.238.252.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "acs-ent.com"] [uri "/wp-login.php"] [unique_id "apPlkO349Tv4SB45P2nFsQAAAKs"]
[Sun Aug 30 03:10:56.490015 2026] [security2:error] [pid 517995:tid 518132] [client 4.205.62.107:15988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/phpinfo01.php"] [unique_id "apPlkLz-S0xMfHBNth6GNQAAAQ8"]
[Sun Aug 30 03:10:56.554481 2026] [security2:error] [pid 517995:tid 518233] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPlkLz-S0xMfHBNth6GWgAAAXQ"]
[Sun Aug 30 03:10:56.566649 2026] [authz_core:error] [pid 517995:tid 518183] [client 216.73.216.128:8959] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:56.567053 2026] [authz_core:error] [pid 517995:tid 518183] [client 216.73.216.128:8959] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:56.573690 2026] [security2:error] [pid 517995:tid 518213] [client 20.48.160.90:28115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/adminfuns.php"] [unique_id "apPlkLz-S0xMfHBNth6GbAAAAWA"]
[Sun Aug 30 03:10:56.575780 2026] [security2:error] [pid 518600:tid 518850] [client 20.48.250.41:40878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/Geforce.php"] [unique_id "apPlkO349Tv4SB45P2nF7QAAAPo"]
[Sun Aug 30 03:10:56.607218 2026] [security2:error] [pid 518600:tid 518735] [client 20.63.219.114:2503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/as.php"] [unique_id "apPlkO349Tv4SB45P2nF_QAAAIc"]
[Sun Aug 30 03:10:56.657470 2026] [security2:error] [pid 517995:tid 518227] [client 20.104.50.220:29579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wsoshell.php"] [unique_id "apPlkLz-S0xMfHBNth6GsAAAAW4"]
[Sun Aug 30 03:10:56.668319 2026] [security2:error] [pid 518600:tid 518802] [client 57.131.147.192:52285] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdsafetysystems.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "apPlkO349Tv4SB45P2nGFAAAAMo"]
[Sun Aug 30 03:10:56.670404 2026] [security2:error] [pid 517995:tid 518232] [client 20.104.50.220:51397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/goods.php"] [unique_id "apPlkLz-S0xMfHBNth6GvQAAAXM"]
[Sun Aug 30 03:10:56.672609 2026] [security2:error] [pid 517995:tid 518167] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/lock360.php"] [unique_id "apPlkLz-S0xMfHBNth6GvwAAATI"]
[Sun Aug 30 03:10:56.694222 2026] [security2:error] [pid 518600:tid 518782] [client 4.205.62.107:36607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/nw.php"] [unique_id "apPlkO349Tv4SB45P2nGKwAAALY"]
[Sun Aug 30 03:10:56.708255 2026] [security2:error] [pid 517995:tid 518227] [client 20.104.49.130:52446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/yawa.php"] [unique_id "apPlkLz-S0xMfHBNth6G4wAAAW4"]
[Sun Aug 30 03:10:56.726439 2026] [security2:error] [pid 517995:tid 518172] [client 4.205.62.107:58473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/classsmtps.php"] [unique_id "apPlkLz-S0xMfHBNth6G9AAAATc"]
[Sun Aug 30 03:10:56.746587 2026] [security2:error] [pid 515259:tid 515440] [client 68.155.159.216:63247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-admin/images/index.php"] [unique_id "apPlkGZcVaai59truiWUTgAAADI"]
[Sun Aug 30 03:10:56.764870 2026] [security2:error] [pid 517995:tid 518186] [client 20.104.49.130:36771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/css.php"] [unique_id "apPlkLz-S0xMfHBNth6HDwAAAUU"]
[Sun Aug 30 03:10:56.777061 2026] [security2:error] [pid 518600:tid 518829] [client 20.48.250.41:40875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/click.php"] [unique_id "apPlkO349Tv4SB45P2nGVQAAAOU"]
[Sun Aug 30 03:10:56.790612 2026] [security2:error] [pid 518600:tid 518828] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/giodywky.php"] [unique_id "apPlkO349Tv4SB45P2nGXAAAAOQ"]
[Sun Aug 30 03:10:56.793115 2026] [security2:error] [pid 518600:tid 518808] [client 20.48.160.90:28089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/classwithtostring.php"] [unique_id "apPlkO349Tv4SB45P2nGYQAAANA"]
[Sun Aug 30 03:10:56.829440 2026] [autoindex:error] [pid 517995:tid 518187] [client 158.23.184.117:63138] AH01276: Cannot serve directory /home3/shutters/public_html/ann-tiques.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:10:56.835782 2026] [security2:error] [pid 517995:tid 518142] [client 40.83.93.50:6399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/13.php"] [unique_id "apPlkLz-S0xMfHBNth6HPwAAARk"]
[Sun Aug 30 03:10:56.858291 2026] [core:alert] [pid 515259:tid 515394] [client 102.204.4.10:33492] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:10:56.864532 2026] [authz_core:error] [pid 515259:tid 515459] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:56.864944 2026] [authz_core:error] [pid 515259:tid 515459] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:56.877825 2026] [security2:error] [pid 517995:tid 518133] [client 68.155.159.216:54308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-admin.php"] [unique_id "apPlkLz-S0xMfHBNth6HXwAAARA"]
[Sun Aug 30 03:10:56.878781 2026] [security2:error] [pid 517995:tid 518227] [client 20.104.50.220:52815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/kntl.php"] [unique_id "apPlkLz-S0xMfHBNth6HYQAAAW4"]
[Sun Aug 30 03:10:56.884133 2026] [security2:error] [pid 515259:tid 515427] [client 20.104.50.220:63529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/images/lux.php"] [unique_id "apPlkGZcVaai59truiWUfwAAACU"]
[Sun Aug 30 03:10:56.904279 2026] [security2:error] [pid 515259:tid 515486] [client 20.104.18.15:22516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/goods.php"] [unique_id "apPlkGZcVaai59truiWUhgAAAGA"]
[Sun Aug 30 03:10:56.907123 2026] [security2:error] [pid 515259:tid 515390] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/images/images/cache.php"] [unique_id "apPlkGZcVaai59truiWUiAAAAAA"]
[Sun Aug 30 03:10:56.937823 2026] [security2:error] [pid 517995:tid 518162] [client 20.104.18.15:18305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/biufile.php"] [unique_id "apPlkLz-S0xMfHBNth6HjwAAAS0"]
[Sun Aug 30 03:10:56.943313 2026] [security2:error] [pid 518600:tid 518750] [client 20.104.49.130:57633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/abc.php"] [unique_id "apPlkO349Tv4SB45P2nGwAAAAJY"]
[Sun Aug 30 03:10:56.979444 2026] [security2:error] [pid 517995:tid 518213] [client 20.63.219.114:19149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/credits.php"] [unique_id "apPlkLz-S0xMfHBNth6HqgAAAWA"]
[Sun Aug 30 03:10:56.985428 2026] [security2:error] [pid 517995:tid 518202] [client 20.48.160.90:28122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPlkLz-S0xMfHBNth6HrwAAAVU"]
[Sun Aug 30 03:10:57.010886 2026] [security2:error] [pid 517995:tid 518132] [client 20.104.50.220:5780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/date.php"] [unique_id "apPlkbz-S0xMfHBNth6HvQAAAQ8"]
[Sun Aug 30 03:10:57.018198 2026] [security2:error] [pid 517995:tid 518144] [client 20.104.49.130:52461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wdfjba.org"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlkbz-S0xMfHBNth6HwgAAARs"]
[Sun Aug 30 03:10:57.020928 2026] [security2:error] [pid 517995:tid 518211] [client 20.104.50.220:32871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/alfi.php"] [unique_id "apPlkbz-S0xMfHBNth6HwwAAAV4"]
[Sun Aug 30 03:10:57.021693 2026] [security2:error] [pid 517995:tid 518251] [client 20.48.251.3:64314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/ws79.php"] [unique_id "apPlkbz-S0xMfHBNth6HxgAAAYY"]
[Sun Aug 30 03:10:57.027287 2026] [security2:error] [pid 518600:tid 518750] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp-includes/version.php"] [unique_id "apPlke349Tv4SB45P2nG5gAAAJY"]
[Sun Aug 30 03:10:57.032772 2026] [security2:error] [pid 518600:tid 518752] [client 20.104.18.15:31702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/images.php"] [unique_id "apPlke349Tv4SB45P2nG6AAAAJg"]
[Sun Aug 30 03:10:57.090064 2026] [authz_core:error] [pid 517995:tid 518226] [client 66.249.66.205:35068] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:57.090341 2026] [authz_core:error] [pid 517995:tid 518226] [client 66.249.66.205:35068] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:57.094739 2026] [security2:error] [pid 515259:tid 515476] [client 20.48.250.41:40853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/ms.php"] [unique_id "apPlkWZcVaai59truiWU3AAAAFY"]
[Sun Aug 30 03:10:57.102502 2026] [security2:error] [pid 517995:tid 518234] [client 158.23.147.79:58392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-includes/fonts/about.php"] [unique_id "apPlkbz-S0xMfHBNth6IGQAAAXU"]
[Sun Aug 30 03:10:57.121372 2026] [security2:error] [pid 517995:tid 518147] [client 20.104.50.220:16650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/ww1.php"] [unique_id "apPlkbz-S0xMfHBNth6IKAAAAR4"]
[Sun Aug 30 03:10:57.128935 2026] [security2:error] [pid 517995:tid 518167] [client 145.239.10.137:56120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whitemountainthingstodo.com"] [uri "/wp-content/plugins/pwnd/Footer.php"] [unique_id "apPlkbz-S0xMfHBNth6ILwAAATI"], referer: http://whitemountainthingstodo.com/wp-content/plugins/pwnd/Footer.php
[Sun Aug 30 03:10:57.144397 2026] [security2:error] [pid 517995:tid 518203] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/images/index.php"] [unique_id "apPlkbz-S0xMfHBNth6IOgAAAVY"]
[Sun Aug 30 03:10:57.166001 2026] [security2:error] [pid 517995:tid 518200] [client 20.48.160.90:51938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/5PJcpMFsD8B.php"] [unique_id "apPlkbz-S0xMfHBNth6IRAAAAVM"]
[Sun Aug 30 03:10:57.179673 2026] [authz_core:error] [pid 518600:tid 518804] [client 66.249.66.45:36131] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:57.180238 2026] [authz_core:error] [pid 518600:tid 518804] [client 66.249.66.45:36131] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:57.263754 2026] [security2:error] [pid 515259:tid 515489] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/images/2008.php"] [unique_id "apPlkWZcVaai59truiWVIQAAAGM"]
[Sun Aug 30 03:10:57.268422 2026] [security2:error] [pid 515259:tid 515451] [client 20.104.18.15:16705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPlkWZcVaai59truiWVIwAAAD0"]
[Sun Aug 30 03:10:57.286877 2026] [security2:error] [pid 515259:tid 515404] [client 20.48.250.41:40852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/zxekqlxb.php"] [unique_id "apPlkWZcVaai59truiWVLAAAAA4"]
[Sun Aug 30 03:10:57.293836 2026] [security2:error] [pid 518600:tid 518752] [client 4.205.62.107:16772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/mcebraed.php"] [unique_id "apPlke349Tv4SB45P2nHfAAAAJg"]
[Sun Aug 30 03:10:57.305254 2026] [security2:error] [pid 517995:tid 518218] [client 40.83.93.50:6548] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.riverglenhoa.com"] [uri "/1.php"] [unique_id "apPlkbz-S0xMfHBNth6IlAAAAWU"]
[Sun Aug 30 03:10:57.305342 2026] [security2:error] [pid 517995:tid 518218] [client 40.83.93.50:6548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/1.php"] [unique_id "apPlkbz-S0xMfHBNth6IlAAAAWU"]
[Sun Aug 30 03:10:57.337595 2026] [authz_core:error] [pid 517995:tid 518219] [client 216.73.216.128:8959] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:57.338061 2026] [authz_core:error] [pid 517995:tid 518219] [client 216.73.216.128:8959] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:57.353800 2026] [security2:error] [pid 517995:tid 518181] [client 158.23.147.79:1873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wzy.php"] [unique_id "apPlkbz-S0xMfHBNth6IpwAAAUA"]
[Sun Aug 30 03:10:57.358957 2026] [security2:error] [pid 517995:tid 518200] [client 20.63.219.114:15658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/cache.php"] [unique_id "apPlkbz-S0xMfHBNth6IrAAAAVM"]
[Sun Aug 30 03:10:57.360129 2026] [security2:error] [pid 517995:tid 518247] [client 57.131.147.192:57161] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdsafetysystems.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "apPlkbz-S0xMfHBNth6IsQAAAYI"]
[Sun Aug 30 03:10:57.361826 2026] [security2:error] [pid 517995:tid 518196] [client 20.48.251.3:55684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/h.php"] [unique_id "apPlkbz-S0xMfHBNth6IswAAAU8"]
[Sun Aug 30 03:10:57.364744 2026] [authz_core:error] [pid 515259:tid 515498] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:57.365282 2026] [authz_core:error] [pid 515259:tid 515498] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:57.374538 2026] [security2:error] [pid 517995:tid 518206] [client 20.48.160.90:51907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPlkbz-S0xMfHBNth6IvwAAAVk"]
[Sun Aug 30 03:10:57.381388 2026] [security2:error] [pid 518600:tid 518774] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp-content/plugins/hello.php"] [unique_id "apPlke349Tv4SB45P2nHygAAAK4"]
[Sun Aug 30 03:10:57.415153 2026] [security2:error] [pid 518600:tid 518782] [client 20.48.250.41:40832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/init.php"] [unique_id "apPlke349Tv4SB45P2nH6AAAALY"]
[Sun Aug 30 03:10:57.447158 2026] [security2:error] [pid 517995:tid 518194] [client 4.205.62.107:25786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/fucku.php"] [unique_id "apPlkbz-S0xMfHBNth6I7wAAAU0"]
[Sun Aug 30 03:10:57.484910 2026] [security2:error] [pid 518600:tid 518771] [client 20.48.251.3:52243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/server-info.php"] [unique_id "apPlke349Tv4SB45P2nH9gAAAKs"]
[Sun Aug 30 03:10:57.498979 2026] [security2:error] [pid 517995:tid 518130] [client 20.104.50.220:61997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-info.php"] [unique_id "apPlkbz-S0xMfHBNth6JCwAAAQ0"]
[Sun Aug 30 03:10:57.499670 2026] [security2:error] [pid 517995:tid 518205] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp-includes/class-wp.php"] [unique_id "apPlkbz-S0xMfHBNth6JDAAAAVg"]
[Sun Aug 30 03:10:57.519385 2026] [security2:error] [pid 517995:tid 518134] [client 20.48.160.90:28106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/wsd.php"] [unique_id "apPlkbz-S0xMfHBNth6JGwAAARE"]
[Sun Aug 30 03:10:57.522584 2026] [security2:error] [pid 515259:tid 515424] [client 20.104.18.15:43908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/rxr.php"] [unique_id "apPlkWZcVaai59truiWVjQAAACI"]
[Sun Aug 30 03:10:57.535728 2026] [security2:error] [pid 518600:tid 518780] [client 20.104.18.15:64753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/t3.php"] [unique_id "apPlke349Tv4SB45P2nIAgAAALQ"]
[Sun Aug 30 03:10:57.573960 2026] [security2:error] [pid 515259:tid 515444] [client 20.151.200.44:28501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPlkWZcVaai59truiWVogAAADY"]
[Sun Aug 30 03:10:57.584722 2026] [security2:error] [pid 515259:tid 515511] [client 20.48.250.41:40839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/term.php"] [unique_id "apPlkWZcVaai59truiWVqQAAAHk"]
[Sun Aug 30 03:10:57.621769 2026] [security2:error] [pid 517995:tid 518163] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/classwithtostring.php"] [unique_id "apPlkbz-S0xMfHBNth6JYQAAAS4"]
[Sun Aug 30 03:10:57.629972 2026] [security2:error] [pid 517995:tid 518178] [client 4.205.62.107:15961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/cxc.php"] [unique_id "apPlkbz-S0xMfHBNth6JYgAAAT0"]
[Sun Aug 30 03:10:57.630337 2026] [authz_core:error] [pid 515259:tid 515400] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:57.630797 2026] [authz_core:error] [pid 515259:tid 515400] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:57.664545 2026] [security2:error] [pid 517995:tid 518181] [client 20.48.160.90:28079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/bulet.php"] [unique_id "apPlkbz-S0xMfHBNth6JfwAAAUA"]
[Sun Aug 30 03:10:57.739427 2026] [security2:error] [pid 515259:tid 515410] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/images.php"] [unique_id "apPlkWZcVaai59truiWV7wAAABQ"]
[Sun Aug 30 03:10:57.768260 2026] [security2:error] [pid 517995:tid 518188] [client 20.48.250.41:40838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/aaa.php"] [unique_id "apPlkbz-S0xMfHBNth6JxgAAAUc"]
[Sun Aug 30 03:10:57.780418 2026] [security2:error] [pid 518600:tid 518826] [client 20.104.49.130:53701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/100.php"] [unique_id "apPlke349Tv4SB45P2nIjwAAAOI"]
[Sun Aug 30 03:10:57.823347 2026] [security2:error] [pid 517995:tid 518197] [client 20.104.50.220:28711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/autoload_classmap.php"] [unique_id "apPlkbz-S0xMfHBNth6J5gAAAVA"]
[Sun Aug 30 03:10:57.825027 2026] [security2:error] [pid 518600:tid 518786] [client 20.104.50.220:51394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/ms-edit.php"] [unique_id "apPlke349Tv4SB45P2nIsQAAALo"]
[Sun Aug 30 03:10:57.828924 2026] [security2:error] [pid 518600:tid 518756] [client 20.63.219.114:15239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/fix.php"] [unique_id "apPlke349Tv4SB45P2nIuAAAAJw"]
[Sun Aug 30 03:10:57.836172 2026] [authz_core:error] [pid 518600:tid 518820] [client 66.249.66.73:55745] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:57.836679 2026] [authz_core:error] [pid 518600:tid 518820] [client 66.249.66.73:55745] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:57.855290 2026] [security2:error] [pid 517995:tid 518204] [client 4.205.62.107:58244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/cache-compat.php"] [unique_id "apPlkbz-S0xMfHBNth6J_QAAAVc"]
[Sun Aug 30 03:10:57.856341 2026] [authz_core:error] [pid 515259:tid 515481] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:57.856734 2026] [authz_core:error] [pid 515259:tid 515481] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:57.857093 2026] [security2:error] [pid 515259:tid 515431] [client 20.104.50.220:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cagtu.com"] [uri "/1.php"] [unique_id "apPlkWZcVaai59truiWWIgAAACk"]
[Sun Aug 30 03:10:57.857211 2026] [security2:error] [pid 515259:tid 515431] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/1.php"] [unique_id "apPlkWZcVaai59truiWWIgAAACk"]
[Sun Aug 30 03:10:57.857262 2026] [security2:error] [pid 517995:tid 518147] [client 40.83.93.50:10720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/as.php"] [unique_id "apPlkbz-S0xMfHBNth6J_gAAAR4"]
[Sun Aug 30 03:10:57.863886 2026] [security2:error] [pid 517995:tid 518211] [client 68.155.159.216:63259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-includes/index.php"] [unique_id "apPlkbz-S0xMfHBNth6KBAAAAV4"]
[Sun Aug 30 03:10:57.893692 2026] [security2:error] [pid 518600:tid 518620] [remote 114.119.154.242:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alphabraingummies.com"] [uri "/vital-vitamins-brain-supplements-mental-alertness/"] [unique_id "apPlke349Tv4SB45P2nI4gAAtBA"], referer: https://rukorma.ru/exploring-alpha-brain-supplements-gummies-cognitive-support-and-wellness
[Sun Aug 30 03:10:57.901060 2026] [security2:error] [pid 518600:tid 518831] [client 20.151.200.44:40936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/px.php"] [unique_id "apPlke349Tv4SB45P2nI6wAAAOc"]
[Sun Aug 30 03:10:57.901661 2026] [security2:error] [pid 518600:tid 518765] [client 20.48.160.90:28128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/av.php"] [unique_id "apPlke349Tv4SB45P2nI7AAAAKU"]
[Sun Aug 30 03:10:57.932283 2026] [security2:error] [pid 518600:tid 518812] [client 20.48.250.41:40890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/xsox.php"] [unique_id "apPlke349Tv4SB45P2nJCQAAANQ"]
[Sun Aug 30 03:10:57.941399 2026] [security2:error] [pid 518600:tid 518839] [client 4.205.62.107:36602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/product.php"] [unique_id "apPlke349Tv4SB45P2nJEAAAAO8"]
[Sun Aug 30 03:10:57.949421 2026] [authz_core:error] [pid 518600:tid 518765] [client 66.249.66.195:63858] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:57.949761 2026] [authz_core:error] [pid 518600:tid 518765] [client 66.249.66.195:63858] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:57.975695 2026] [authz_core:error] [pid 517995:tid 518147] [client 216.73.216.128:55057] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:57.976179 2026] [authz_core:error] [pid 517995:tid 518147] [client 216.73.216.128:55057] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:57.981344 2026] [security2:error] [pid 517995:tid 518162] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/images/wp.php"] [unique_id "apPlkbz-S0xMfHBNth6KQwAAAS0"]
[Sun Aug 30 03:10:57.991279 2026] [security2:error] [pid 517995:tid 518225] [client 195.178.110.247:3180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.migrationconsultants.net"] [uri "/index.php"] [unique_id "apPlkbz-S0xMfHBNth6KSAAAAWw"]
[Sun Aug 30 03:10:58.030281 2026] [authz_core:error] [pid 518600:tid 518781] [client 66.249.66.206:38745] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:58.032070 2026] [authz_core:error] [pid 518600:tid 518781] [client 66.249.66.206:38745] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:58.039032 2026] [security2:error] [pid 518600:tid 518784] [client 20.104.50.220:52808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/klee.php"] [unique_id "apPlku349Tv4SB45P2nJYgAAALg"]
[Sun Aug 30 03:10:58.039198 2026] [security2:error] [pid 518600:tid 518777] [client 20.104.50.220:63490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/w3llstore.php"] [unique_id "apPlku349Tv4SB45P2nJYQAAALE"]
[Sun Aug 30 03:10:58.042494 2026] [security2:error] [pid 515259:tid 515494] [client 20.48.160.90:51913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/images.php"] [unique_id "apPlkmZcVaai59truiWWXAAAAGg"]
[Sun Aug 30 03:10:58.057555 2026] [security2:error] [pid 518600:tid 518743] [client 57.131.147.192:59490] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdsafetysystems.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "apPlku349Tv4SB45P2nJfAAAAI8"]
[Sun Aug 30 03:10:58.072334 2026] [security2:error] [pid 518600:tid 518829] [client 20.104.18.15:22371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/ah.php"] [unique_id "apPlku349Tv4SB45P2nJlAAAAOU"]
[Sun Aug 30 03:10:58.086082 2026] [security2:error] [pid 517995:tid 518162] [client 20.104.18.15:18346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/blacks.php"] [unique_id "apPlkrz-S0xMfHBNth6KdwAAAS0"]
[Sun Aug 30 03:10:58.101704 2026] [security2:error] [pid 518600:tid 518812] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/000.php/index.php"] [unique_id "apPlku349Tv4SB45P2nJpwAAANQ"]
[Sun Aug 30 03:10:58.122827 2026] [security2:error] [pid 518600:tid 518784] [client 68.155.159.216:46070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-content/packed.php"] [unique_id "apPlku349Tv4SB45P2nJvQAAALg"]
[Sun Aug 30 03:10:58.133408 2026] [security2:error] [pid 518600:tid 518824] [client 20.48.250.41:40803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/lkui.php"] [unique_id "apPlku349Tv4SB45P2nJzgAAAOA"]
[Sun Aug 30 03:10:58.154719 2026] [security2:error] [pid 517995:tid 518141] [client 195.178.110.247:35774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.migrationconsultants.net"] [uri "/index.php"] [unique_id "apPlkrz-S0xMfHBNth6KmwAAARg"]
[Sun Aug 30 03:10:58.166832 2026] [security2:error] [pid 518600:tid 518835] [client 20.48.251.3:64256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/public/wp-blog.php"] [unique_id "apPlku349Tv4SB45P2nJ9AAAAOs"]
[Sun Aug 30 03:10:58.167059 2026] [security2:error] [pid 518600:tid 518736] [client 20.104.50.220:33305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/DC.php"] [unique_id "apPlku349Tv4SB45P2nJ9gAAAIg"]
[Sun Aug 30 03:10:58.175678 2026] [security2:error] [pid 518600:tid 518860] [client 20.104.50.220:6081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/deprecated.php"] [unique_id "apPlku349Tv4SB45P2nKBQAAAQQ"]
[Sun Aug 30 03:10:58.175701 2026] [security2:error] [pid 518600:tid 518799] [client 20.104.18.15:31651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/ops.php"] [unique_id "apPlku349Tv4SB45P2nKBwAAAMc"]
[Sun Aug 30 03:10:58.177175 2026] [security2:error] [pid 518600:tid 518851] [client 20.48.160.90:51958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/ops.php"] [unique_id "apPlku349Tv4SB45P2nKCAAAAPs"]
[Sun Aug 30 03:10:58.177189 2026] [authz_core:error] [pid 518600:tid 518755] [client 216.73.216.128:52324] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:58.177464 2026] [authz_core:error] [pid 518600:tid 518755] [client 216.73.216.128:52324] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:58.193938 2026] [security2:error] [pid 517995:tid 518184] [client 158.23.184.117:7515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "apPlkrz-S0xMfHBNth6KqQAAAUM"]
[Sun Aug 30 03:10:58.219414 2026] [security2:error] [pid 517995:tid 518168] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/2d7433/index.php"] [unique_id "apPlkrz-S0xMfHBNth6KuAAAATM"]
[Sun Aug 30 03:10:58.262185 2026] [security2:error] [pid 515259:tid 515477] [client 20.104.50.220:16613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/about/function.php"] [unique_id "apPlkmZcVaai59truiWWtwAAAFc"]
[Sun Aug 30 03:10:58.266224 2026] [security2:error] [pid 518600:tid 518735] [client 20.48.250.41:40855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apPlku349Tv4SB45P2nKSAAAAIc"]
[Sun Aug 30 03:10:58.270105 2026] [authz_core:error] [pid 517995:tid 518186] [client 216.73.216.128:55057] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:58.270584 2026] [authz_core:error] [pid 517995:tid 518186] [client 216.73.216.128:55057] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:58.306228 2026] [security2:error] [pid 517995:tid 518241] [client 158.23.147.79:16339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-content/admin.php"] [unique_id "apPlkrz-S0xMfHBNth6K8gAAAXw"]
[Sun Aug 30 03:10:58.307748 2026] [security2:error] [pid 518600:tid 518847] [client 20.48.160.90:28093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/coffexium.php"] [unique_id "apPlku349Tv4SB45P2nKWgAAAPc"]
[Sun Aug 30 03:10:58.333912 2026] [security2:error] [pid 515259:tid 515503] [client 158.23.184.117:7436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/light.php"] [unique_id "apPlkmZcVaai59truiWW2AAAAHE"]
[Sun Aug 30 03:10:58.341827 2026] [security2:error] [pid 518600:tid 518789] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/radio.php"] [unique_id "apPlku349Tv4SB45P2nKdgAAAL0"]
[Sun Aug 30 03:10:58.366076 2026] [security2:error] [pid 518600:tid 518834] [client 40.83.93.50:6347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/credits.php"] [unique_id "apPlku349Tv4SB45P2nKhgAAAOo"]
[Sun Aug 30 03:10:58.389534 2026] [authz_core:error] [pid 515259:tid 515465] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:58.389999 2026] [authz_core:error] [pid 515259:tid 515465] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:58.414276 2026] [security2:error] [pid 518600:tid 518737] [client 20.104.18.15:64090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/f.php"] [unique_id "apPlku349Tv4SB45P2nKqwAAAIk"]
[Sun Aug 30 03:10:58.419577 2026] [security2:error] [pid 517995:tid 518182] [client 20.48.250.41:40946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/motu.php"] [unique_id "apPlkrz-S0xMfHBNth6LQwAAAUE"]
[Sun Aug 30 03:10:58.423823 2026] [security2:error] [pid 517995:tid 518152] [client 20.151.200.44:64809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPlkrz-S0xMfHBNth6LRQAAASM"]
[Sun Aug 30 03:10:58.430034 2026] [security2:error] [pid 517995:tid 518195] [client 4.205.62.107:17699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/server-info.php"] [unique_id "apPlkrz-S0xMfHBNth6LSwAAAU4"]
[Sun Aug 30 03:10:58.463469 2026] [security2:error] [pid 515259:tid 515459] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp-includes/user.php"] [unique_id "apPlkmZcVaai59truiWXDgAAAEU"]
[Sun Aug 30 03:10:58.467126 2026] [lsapi:error] [pid 517995:tid 518036] [remote 172.88.202.161:48128] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.google.com/
[Sun Aug 30 03:10:58.467294 2026] [lsapi:error] [pid 517995:tid 518036] [remote 172.88.202.161:48128] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.google.com/
[Sun Aug 30 03:10:58.468733 2026] [lsapi:error] [pid 517995:tid 518036] [remote 172.88.202.161:48128] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n, referer: https://www.google.com/
[Sun Aug 30 03:10:58.469425 2026] [security2:error] [pid 515259:tid 515469] [client 20.48.160.90:28046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/BDKR28WP.php"] [unique_id "apPlkmZcVaai59truiWXFAAAAE8"]
[Sun Aug 30 03:10:58.474978 2026] [security2:error] [pid 517995:tid 518240] [client 158.23.184.117:7441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/wp-admin/css/about.php7"] [unique_id "apPlkrz-S0xMfHBNth6LawAAAXs"]
[Sun Aug 30 03:10:58.502158 2026] [security2:error] [pid 515259:tid 515461] [client 20.48.251.3:55732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/bootstrap.php"] [unique_id "apPlkmZcVaai59truiWXIQAAAEc"]
[Sun Aug 30 03:10:58.582775 2026] [security2:error] [pid 515259:tid 515439] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/images/wp-login.php"] [unique_id "apPlkmZcVaai59truiWXQgAAADE"]
[Sun Aug 30 03:10:58.596442 2026] [security2:error] [pid 517995:tid 518138] [client 158.23.147.79:57724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apPlkrz-S0xMfHBNth6LwwAAARU"]
[Sun Aug 30 03:10:58.616113 2026] [security2:error] [pid 517995:tid 518219] [client 158.23.184.117:7472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/alf.php"] [unique_id "apPlkrz-S0xMfHBNth6L1gAAAWY"]
[Sun Aug 30 03:10:58.621376 2026] [security2:error] [pid 517995:tid 518245] [client 20.48.251.3:59872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/gk.php"] [unique_id "apPlkrz-S0xMfHBNth6L2gAAAYA"]
[Sun Aug 30 03:10:58.628395 2026] [security2:error] [pid 517995:tid 518142] [client 20.48.250.41:40894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/Ov-Simple1.php"] [unique_id "apPlkrz-S0xMfHBNth6L3QAAARk"]
[Sun Aug 30 03:10:58.645312 2026] [security2:error] [pid 518600:tid 518829] [client 20.48.160.90:28065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/sf.php"] [unique_id "apPlku349Tv4SB45P2nLHgAAAOU"]
[Sun Aug 30 03:10:58.645581 2026] [security2:error] [pid 518600:tid 518767] [client 68.155.159.216:52572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apPlku349Tv4SB45P2nLIAAAAKc"]
[Sun Aug 30 03:10:58.648770 2026] [authz_core:error] [pid 515259:tid 515402] [client 66.249.66.34:37660] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:58.649041 2026] [authz_core:error] [pid 515259:tid 515402] [client 66.249.66.34:37660] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:58.667225 2026] [security2:error] [pid 517995:tid 518160] [client 158.23.147.79:58386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/xmlrpc.php"] [unique_id "apPlkrz-S0xMfHBNth6L_gAAASs"]
[Sun Aug 30 03:10:58.683847 2026] [security2:error] [pid 518600:tid 518751] [client 20.104.18.15:64741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/wp.php"] [unique_id "apPlku349Tv4SB45P2nLLQAAAJc"]
[Sun Aug 30 03:10:58.684935 2026] [security2:error] [pid 518600:tid 518825] [client 20.104.50.220:62008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-inlcudes.php"] [unique_id "apPlku349Tv4SB45P2nLLgAAAOE"]
[Sun Aug 30 03:10:58.689037 2026] [security2:error] [pid 518600:tid 518770] [client 20.104.18.15:43938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.robertpitti.it"] [uri "/reviall.php"] [unique_id "apPlku349Tv4SB45P2nLNAAAAKo"]
[Sun Aug 30 03:10:58.703197 2026] [security2:error] [pid 518600:tid 518844] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp-includes/option.php"] [unique_id "apPlku349Tv4SB45P2nLPgAAAPQ"]
[Sun Aug 30 03:10:58.725954 2026] [security2:error] [pid 518600:tid 518856] [client 4.205.62.107:25737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/error_log.php"] [unique_id "apPlku349Tv4SB45P2nLXQAAAQA"]
[Sun Aug 30 03:10:58.728116 2026] [security2:error] [pid 518600:tid 518803] [client 57.131.147.192:51292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdsafetysystems.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "apPlku349Tv4SB45P2nLYAAAAMs"]
[Sun Aug 30 03:10:58.766205 2026] [security2:error] [pid 518600:tid 518858] [client 4.205.62.107:15950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/oiko6u.php"] [unique_id "apPlku349Tv4SB45P2nLiQAAAQI"]
[Sun Aug 30 03:10:58.767240 2026] [authz_core:error] [pid 518600:tid 518837] [client 66.249.66.32:43809] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:58.767579 2026] [authz_core:error] [pid 518600:tid 518837] [client 66.249.66.32:43809] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:58.779551 2026] [security2:error] [pid 518600:tid 518834] [client 20.48.250.41:40880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/wp-blogs.php"] [unique_id "apPlku349Tv4SB45P2nLlwAAAOo"]
[Sun Aug 30 03:10:58.797580 2026] [security2:error] [pid 518600:tid 518778] [client 20.48.160.90:51933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/k.php"] [unique_id "apPlku349Tv4SB45P2nLpgAAALI"]
[Sun Aug 30 03:10:58.807686 2026] [security2:error] [pid 515259:tid 515440] [client 216.73.216.128:21613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_config_viewer_headers"] [unique_id "apPlkmZcVaai59truiWXkQAAADI"]
[Sun Aug 30 03:10:58.821892 2026] [security2:error] [pid 518600:tid 518850] [client 158.23.184.117:7460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/wp-admin/import.php"] [unique_id "apPlku349Tv4SB45P2nLxQAAAPo"]
[Sun Aug 30 03:10:58.828951 2026] [security2:error] [pid 518600:tid 518739] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/images/mail.php"] [unique_id "apPlku349Tv4SB45P2nL2AAAAIs"]
[Sun Aug 30 03:10:58.862732 2026] [authz_core:error] [pid 515259:tid 515498] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:58.863265 2026] [authz_core:error] [pid 515259:tid 515498] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:58.912717 2026] [security2:error] [pid 518600:tid 518811] [client 40.83.93.50:6188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/cache.php"] [unique_id "apPlku349Tv4SB45P2nMCwAAANM"]
[Sun Aug 30 03:10:58.914796 2026] [authz_core:error] [pid 515259:tid 515460] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:58.915067 2026] [authz_core:error] [pid 515259:tid 515460] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:10:58.923429 2026] [security2:error] [pid 515259:tid 515442] [client 20.48.250.41:40868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/mini.php"] [unique_id "apPlkmZcVaai59truiWXtwAAADQ"]
[Sun Aug 30 03:10:58.926500 2026] [security2:error] [pid 518600:tid 518748] [client 134.185.86.231:55444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.86.185.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drhorton.iframe360.com"] [uri "/wp-login.php"] [unique_id "apPlku349Tv4SB45P2nMDQAAAJQ"], referer: https://wordpress.org/
[Sun Aug 30 03:10:58.950662 2026] [security2:error] [pid 515259:tid 515394] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/themes/Divi/page.php"] [unique_id "apPlkmZcVaai59truiWXxwAAAAQ"]
[Sun Aug 30 03:10:58.962551 2026] [security2:error] [pid 518600:tid 518845] [client 158.23.184.117:7449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "apPlku349Tv4SB45P2nMHAAAAPU"]
[Sun Aug 30 03:10:58.967400 2026] [security2:error] [pid 518600:tid 518833] [client 20.104.50.220:62798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/12.php"] [unique_id "apPlku349Tv4SB45P2nMHgAAAOk"]
[Sun Aug 30 03:10:58.977093 2026] [security2:error] [pid 517995:tid 518229] [client 20.104.50.220:51009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/222.php"] [unique_id "apPlkrz-S0xMfHBNth6M3AAAAXA"]
[Sun Aug 30 03:10:58.977288 2026] [security2:error] [pid 517995:tid 518254] [client 20.48.160.90:51867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/82.php"] [unique_id "apPlkrz-S0xMfHBNth6M3QAAAYk"]
[Sun Aug 30 03:10:58.988362 2026] [security2:error] [pid 517995:tid 518182] [client 68.155.159.216:57027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/mah.php"] [unique_id "apPlkrz-S0xMfHBNth6M6gAAAUE"]
[Sun Aug 30 03:10:58.990276 2026] [security2:error] [pid 517995:tid 518170] [client 216.73.216.128:55057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlkrz-S0xMfHBNth6M7AAAATU"]
[Sun Aug 30 03:10:59.000591 2026] [security2:error] [pid 517995:tid 518202] [client 4.205.62.107:61743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/aws_keys.php"] [unique_id "apPlk7z-S0xMfHBNth6M8wAAAVU"]
[Sun Aug 30 03:10:59.051851 2026] [security2:error] [pid 518600:tid 518784] [client 20.151.200.44:28552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arcaneguardians.com"] [uri "/waf.php"] [unique_id "apPlk-349Tv4SB45P2nMRAAAALg"]
[Sun Aug 30 03:10:59.066480 2026] [security2:error] [pid 517995:tid 518185] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/class-wp-hook.php"] [unique_id "apPlk7z-S0xMfHBNth6NNAAAAUQ"]
[Sun Aug 30 03:10:59.071266 2026] [security2:error] [pid 518600:tid 518751] [client 4.205.62.107:36698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/fun.php"] [unique_id "apPlk-349Tv4SB45P2nMUwAAAJc"]
[Sun Aug 30 03:10:59.072774 2026] [security2:error] [pid 518600:tid 518803] [client 20.48.250.41:40930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/amp.php"] [unique_id "apPlk-349Tv4SB45P2nMVQAAAMs"]
[Sun Aug 30 03:10:59.094797 2026] [authz_core:error] [pid 518600:tid 518843] [client 66.249.66.42:63858] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:59.095245 2026] [authz_core:error] [pid 518600:tid 518843] [client 66.249.66.42:63858] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:59.112421 2026] [security2:error] [pid 518600:tid 518852] [client 20.48.160.90:28111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/dex.php"] [unique_id "apPlk-349Tv4SB45P2nMbQAAAPw"]
[Sun Aug 30 03:10:59.115175 2026] [cgid:error] [pid 518600:tid 518749] [client 158.23.184.117:7427] AH01265: stderr from /home1/tommy99/public_html/e/ermes-it_it/cgi-bin/: attempt to invoke directory as script
[Sun Aug 30 03:10:59.166774 2026] [security2:error] [pid 517995:tid 518225] [client 158.23.147.79:61983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-l0gin.php"] [unique_id "apPlk7z-S0xMfHBNth6NgwAAAWw"]
[Sun Aug 30 03:10:59.185485 2026] [security2:error] [pid 518600:tid 518773] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/Jcrop.php"] [unique_id "apPlk-349Tv4SB45P2nMswAAAK0"]
[Sun Aug 30 03:10:59.190130 2026] [security2:error] [pid 517995:tid 518217] [client 20.104.50.220:63526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/alfi.php"] [unique_id "apPlk7z-S0xMfHBNth6NlwAAAWQ"]
[Sun Aug 30 03:10:59.208687 2026] [security2:error] [pid 518600:tid 518857] [client 158.23.184.117:7427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/wp-admin/admin-post.php"] [unique_id "apPlk-349Tv4SB45P2nMtgAAAQE"]
[Sun Aug 30 03:10:59.210564 2026] [security2:error] [pid 517995:tid 518198] [client 20.48.250.41:40872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/cc13.php"] [unique_id "apPlk7z-S0xMfHBNth6NpQAAAVE"]
[Sun Aug 30 03:10:59.219945 2026] [security2:error] [pid 518600:tid 518783] [client 20.104.18.15:22506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/ws55.php"] [unique_id "apPlk-349Tv4SB45P2nMvAAAALc"]
[Sun Aug 30 03:10:59.222722 2026] [security2:error] [pid 517995:tid 518215] [client 20.104.50.220:29142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/kalokataitusayagatauya.php"] [unique_id "apPlk7z-S0xMfHBNth6NrgAAAWI"]
[Sun Aug 30 03:10:59.234231 2026] [security2:error] [pid 518600:tid 518853] [client 20.63.219.114:2098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/alfa.php"] [unique_id "apPlk-349Tv4SB45P2nMwwAAAP0"]
[Sun Aug 30 03:10:59.251995 2026] [security2:error] [pid 515259:tid 515433] [client 20.104.49.130:63503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/worksec.php"] [unique_id "apPlk2ZcVaai59truiWYRgAAACs"]
[Sun Aug 30 03:10:59.254264 2026] [security2:error] [pid 517995:tid 518147] [client 20.104.18.15:18396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/beck.php"] [unique_id "apPlk7z-S0xMfHBNth6NuAAAAR4"]
[Sun Aug 30 03:10:59.260176 2026] [security2:error] [pid 518600:tid 518832] [client 158.23.147.79:56485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apPlk-349Tv4SB45P2nMxAAAAOg"]
[Sun Aug 30 03:10:59.260204 2026] [security2:error] [pid 518600:tid 518802] [client 20.48.160.90:51967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/inso.php"] [unique_id "apPlk-349Tv4SB45P2nMxQAAAMo"]
[Sun Aug 30 03:10:59.293676 2026] [security2:error] [pid 518600:tid 518736] [client 59.106.171.52:62195] ModSecurity: Warning. Matched phrase "LWP::Simple" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "bcwinetrends.com"] [uri "/2017/07/03/rose-gold-at-the-acwc/"] [unique_id "apPlk-349Tv4SB45P2nM2gAAAIg"]
[Sun Aug 30 03:10:59.302507 2026] [security2:error] [pid 517995:tid 518164] [client 134.185.86.231:55971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.86.185.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drhorton.iframe360.com"] [uri "/wp-login.php"] [unique_id "apPlk7z-S0xMfHBNth6N3QAAAS8"], referer: https://www.bing.com/
[Sun Aug 30 03:10:59.305131 2026] [security2:error] [pid 518600:tid 518804] [client 20.104.50.220:32939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-content/uploads/simple-file-list/DC.php"] [unique_id "apPlk-349Tv4SB45P2nM9wAAAMw"]
[Sun Aug 30 03:10:59.317097 2026] [security2:error] [pid 517995:tid 518195] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/Debug.php"] [unique_id "apPlk7z-S0xMfHBNth6N6QAAAU4"]
[Sun Aug 30 03:10:59.321119 2026] [security2:error] [pid 518600:tid 518752] [client 20.104.50.220:5928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/feed-atom.php"] [unique_id "apPlk-349Tv4SB45P2nNAwAAAJg"]
[Sun Aug 30 03:10:59.332492 2026] [security2:error] [pid 518600:tid 518754] [client 20.48.251.3:65485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/php-details.php"] [unique_id "apPlk-349Tv4SB45P2nNEQAAAJo"]
[Sun Aug 30 03:10:59.345333 2026] [security2:error] [pid 517995:tid 518196] [client 20.104.18.15:31632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/BDKR28WP.php"] [unique_id "apPlk7z-S0xMfHBNth6OBwAAAU8"]
[Sun Aug 30 03:10:59.348148 2026] [authz_core:error] [pid 515259:tid 515489] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:59.348410 2026] [authz_core:error] [pid 515259:tid 515489] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:59.349996 2026] [security2:error] [pid 518600:tid 518748] [client 158.23.184.117:7439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/favicon.php"] [unique_id "apPlk-349Tv4SB45P2nNHwAAAJQ"]
[Sun Aug 30 03:10:59.358373 2026] [security2:error] [pid 517995:tid 518164] [client 20.48.250.41:40909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/aa.php"] [unique_id "apPlk7z-S0xMfHBNth6ODwAAAS8"]
[Sun Aug 30 03:10:59.373143 2026] [authz_core:error] [pid 518600:tid 518833] [client 66.249.66.65:60560] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:59.373437 2026] [authz_core:error] [pid 518600:tid 518833] [client 66.249.66.65:60560] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:59.391264 2026] [security2:error] [pid 517995:tid 518236] [client 20.104.50.220:16628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/admin/function.php"] [unique_id "apPlk7z-S0xMfHBNth6OJAAAAXc"]
[Sun Aug 30 03:10:59.396029 2026] [security2:error] [pid 517995:tid 518180] [client 57.131.147.192:50720] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdsafetysystems.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "apPlk7z-S0xMfHBNth6OKQAAAT8"]
[Sun Aug 30 03:10:59.410223 2026] [security2:error] [pid 517995:tid 518224] [client 20.48.160.90:51915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/aa.php"] [unique_id "apPlk7z-S0xMfHBNth6ONQAAAWs"]
[Sun Aug 30 03:10:59.420911 2026] [security2:error] [pid 515259:tid 515513] [client 40.83.93.50:22134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/fix.php"] [unique_id "apPlk2ZcVaai59truiWYhAAAAHs"]
[Sun Aug 30 03:10:59.438000 2026] [security2:error] [pid 517995:tid 518248] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/canonical.php"] [unique_id "apPlk7z-S0xMfHBNth6OQAAAAYM"]
[Sun Aug 30 03:10:59.443621 2026] [security2:error] [pid 515259:tid 515455] [client 195.178.110.247:22476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mieloma.org"] [uri "/index.php"] [unique_id "apPlk2ZcVaai59truiWYjwAAAEE"]
[Sun Aug 30 03:10:59.489886 2026] [security2:error] [pid 517995:tid 518164] [client 158.23.184.117:7508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/wp-admin/css/my.php"] [unique_id "apPlk7z-S0xMfHBNth6OWQAAAS8"]
[Sun Aug 30 03:10:59.501100 2026] [security2:error] [pid 515259:tid 515417] [client 20.48.250.41:40775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/s1.php"] [unique_id "apPlk2ZcVaai59truiWYowAAABs"]
[Sun Aug 30 03:10:59.525282 2026] [authz_core:error] [pid 518600:tid 518789] [client 66.249.66.44:54527] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:59.525559 2026] [authz_core:error] [pid 518600:tid 518789] [client 66.249.66.44:54527] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:59.541079 2026] [security2:error] [pid 518600:tid 518779] [client 20.48.160.90:51917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/img.php"] [unique_id "apPlk-349Tv4SB45P2nNlwAAALM"]
[Sun Aug 30 03:10:59.560740 2026] [security2:error] [pid 518600:tid 518845] [client 20.104.18.15:64855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.larb.info"] [uri "/1dfcd2d08f.php"] [unique_id "apPlk-349Tv4SB45P2nNswAAAPU"]
[Sun Aug 30 03:10:59.564909 2026] [security2:error] [pid 518600:tid 518785] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/connection.php"] [unique_id "apPlk-349Tv4SB45P2nNugAAALk"]
[Sun Aug 30 03:10:59.582201 2026] [security2:error] [pid 517995:tid 518215] [client 4.205.62.107:17708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/gk.php"] [unique_id "apPlk7z-S0xMfHBNth6OjgAAAWI"]
[Sun Aug 30 03:10:59.596363 2026] [security2:error] [pid 517995:tid 518209] [client 195.178.110.247:64820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mieloma.org"] [uri "/index.php"] [unique_id "apPlk7z-S0xMfHBNth6OmAAAAVw"]
[Sun Aug 30 03:10:59.618397 2026] [security2:error] [pid 518600:tid 518800] [client 68.155.159.216:45994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-l0gin.php"] [unique_id "apPlk-349Tv4SB45P2nN6QAAAMg"]
[Sun Aug 30 03:10:59.628813 2026] [security2:error] [pid 518600:tid 518766] [client 20.48.250.41:40935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/0byte.php"] [unique_id "apPlk-349Tv4SB45P2nN7gAAAKY"]
[Sun Aug 30 03:10:59.632533 2026] [security2:error] [pid 518600:tid 518761] [client 158.23.184.117:7473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/wp-content/images/doc.php"] [unique_id "apPlk-349Tv4SB45P2nN8AAAAKE"]
[Sun Aug 30 03:10:59.671417 2026] [security2:error] [pid 518600:tid 518756] [client 20.48.251.3:52759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/333.php"] [unique_id "apPlk-349Tv4SB45P2nODgAAAJw"]
[Sun Aug 30 03:10:59.686396 2026] [security2:error] [pid 518600:tid 518766] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/I18N/Arabic.php"] [unique_id "apPlk-349Tv4SB45P2nOJAAAAKY"]
[Sun Aug 30 03:10:59.688221 2026] [security2:error] [pid 518600:tid 518782] [client 20.48.160.90:51937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/222.php"] [unique_id "apPlk-349Tv4SB45P2nOJQAAALY"]
[Sun Aug 30 03:10:59.725525 2026] [authz_core:error] [pid 517995:tid 518148] [client 66.249.66.70:49073] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:59.725984 2026] [authz_core:error] [pid 517995:tid 518148] [client 66.249.66.70:49073] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:59.726844 2026] [authz_core:error] [pid 517995:tid 518196] [client 216.73.216.128:8959] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:59.727247 2026] [authz_core:error] [pid 517995:tid 518196] [client 216.73.216.128:8959] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:59.748941 2026] [security2:error] [pid 517995:tid 518134] [client 20.151.200.44:41929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/xda.php"] [unique_id "apPlk7z-S0xMfHBNth6O5wAAARE"]
[Sun Aug 30 03:10:59.760233 2026] [security2:error] [pid 517995:tid 518129] [client 20.48.251.3:52211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/god.php"] [unique_id "apPlk7z-S0xMfHBNth6O7AAAAQw"]
[Sun Aug 30 03:10:59.763690 2026] [security2:error] [pid 518600:tid 518767] [client 20.48.250.41:40781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/xr.php"] [unique_id "apPlk-349Tv4SB45P2nOkwAAAKc"]
[Sun Aug 30 03:10:59.785900 2026] [security2:error] [pid 518600:tid 518785] [client 158.23.184.117:7437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/wp-comments.php"] [unique_id "apPlk-349Tv4SB45P2nOmgAAALk"]
[Sun Aug 30 03:10:59.792611 2026] [security2:error] [pid 518600:tid 518836] [client 20.63.219.114:15274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/wp-blog-header.php"] [unique_id "apPlk-349Tv4SB45P2nOqgAAAOw"]
[Sun Aug 30 03:10:59.807072 2026] [security2:error] [pid 518600:tid 518776] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/include/footer.php"] [unique_id "apPlk-349Tv4SB45P2nOswAAALA"]
[Sun Aug 30 03:10:59.816777 2026] [security2:error] [pid 518600:tid 518850] [client 158.23.147.79:60183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/atomlib.php"] [unique_id "apPlk-349Tv4SB45P2nOvAAAAPo"]
[Sun Aug 30 03:10:59.819241 2026] [security2:error] [pid 515259:tid 515423] [client 20.48.160.90:51910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/key.php"] [unique_id "apPlk2ZcVaai59truiWZDwAAACE"]
[Sun Aug 30 03:10:59.838662 2026] [security2:error] [pid 517995:tid 518133] [client 20.104.18.15:16949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/abcd.php"] [unique_id "apPlk7z-S0xMfHBNth6PIgAAARA"]
[Sun Aug 30 03:10:59.849714 2026] [security2:error] [pid 515259:tid 515504] [client 20.151.200.44:40863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/is.php"] [unique_id "apPlk2ZcVaai59truiWZIAAAAHI"]
[Sun Aug 30 03:10:59.852131 2026] [security2:error] [pid 518600:tid 518737] [client 20.104.50.220:61670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-installer.php"] [unique_id "apPlk-349Tv4SB45P2nO1AAAAIk"]
[Sun Aug 30 03:10:59.886751 2026] [authz_core:error] [pid 515259:tid 515509] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:59.887181 2026] [authz_core:error] [pid 515259:tid 515509] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:10:59.894784 2026] [security2:error] [pid 517995:tid 518177] [client 20.48.250.41:40810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/h02ugyh.php"] [unique_id "apPlk7z-S0xMfHBNth6PQwAAATw"]
[Sun Aug 30 03:10:59.905057 2026] [security2:error] [pid 518600:tid 518851] [client 68.155.159.216:54314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/lock.php"] [unique_id "apPlk-349Tv4SB45P2nO_AAAAPs"]
[Sun Aug 30 03:10:59.911383 2026] [authz_core:error] [pid 518600:tid 518823] [client 216.73.216.128:48547] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:59.911836 2026] [authz_core:error] [pid 518600:tid 518823] [client 216.73.216.128:48547] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:59.919832 2026] [security2:error] [pid 518600:tid 518794] [client 4.205.62.107:15994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/fraro.php"] [unique_id "apPlk-349Tv4SB45P2nPFQAAAMI"]
[Sun Aug 30 03:10:59.925405 2026] [security2:error] [pid 518600:tid 518770] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/include/header.php"] [unique_id "apPlk-349Tv4SB45P2nPHgAAAKo"]
[Sun Aug 30 03:10:59.940348 2026] [security2:error] [pid 517995:tid 518192] [client 158.23.184.117:7454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/wp-includes/panel.php"] [unique_id "apPlk7z-S0xMfHBNth6PXAAAAUs"]
[Sun Aug 30 03:10:59.959027 2026] [security2:error] [pid 518600:tid 518830] [client 20.48.160.90:51914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/chosen.php"] [unique_id "apPlk-349Tv4SB45P2nPQQAAAOY"]
[Sun Aug 30 03:10:59.968058 2026] [authz_core:error] [pid 518600:tid 518775] [client 66.249.66.34:39450] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:10:59.968546 2026] [authz_core:error] [pid 518600:tid 518775] [client 66.249.66.34:39450] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:10:59.980423 2026] [security2:error] [pid 517995:tid 518143] [client 40.83.93.50:6556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/alfa.php"] [unique_id "apPlk7z-S0xMfHBNth6PcwAAARo"]
[Sun Aug 30 03:10:59.981985 2026] [security2:error] [pid 518600:tid 518744] [client 157.7.105.142:33608] ModSecurity: Warning. Matched phrase "LWP::Simple" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "bcwinetrends.com"] [uri "/2017/07/03/rose-gold-at-the-acwc/"] [unique_id "apPlk-349Tv4SB45P2nPSwAAAJA"]
[Sun Aug 30 03:10:59.985894 2026] [security2:error] [pid 518600:tid 518773] [client 52.139.37.240:13859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apPlk-349Tv4SB45P2nPVgAAAK0"]
[Sun Aug 30 03:10:59.991224 2026] [security2:error] [pid 517995:tid 518177] [client 216.73.216.128:8959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPlk7z-S0xMfHBNth6PfQAAATw"]
[Sun Aug 30 03:11:00.005245 2026] [authz_core:error] [pid 515259:tid 515423] [client 66.249.66.202:60061] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:00.005726 2026] [authz_core:error] [pid 515259:tid 515423] [client 66.249.66.202:60061] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:00.022772 2026] [authz_core:error] [pid 518600:tid 518803] [client 66.249.66.204:60175] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:00.023256 2026] [authz_core:error] [pid 518600:tid 518803] [client 66.249.66.204:60175] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:00.043154 2026] [security2:error] [pid 518600:tid 518852] [client 20.48.250.41:40797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/xxw.php"] [unique_id "apPllO349Tv4SB45P2nPjgAAAPw"]
[Sun Aug 30 03:11:00.091125 2026] [security2:error] [pid 518600:tid 518788] [client 178.156.181.172:32872] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "omconsulting-group.com"] [uri "/index.php"] [unique_id "apPlku349Tv4SB45P2nK4QAAALw"], referer: https://omconsulting-group.com
[Sun Aug 30 03:11:00.114678 2026] [security2:error] [pid 518600:tid 518821] [client 4.205.62.107:25899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/phina.php"] [unique_id "apPllO349Tv4SB45P2nP7QAAAN0"]
[Sun Aug 30 03:11:00.119419 2026] [security2:error] [pid 517995:tid 518251] [client 20.104.50.220:31168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/cgi-bin/index.php"] [unique_id "apPllLz-S0xMfHBNth6PzQAAAYY"]
[Sun Aug 30 03:11:00.121110 2026] [security2:error] [pid 517995:tid 518215] [client 20.104.50.220:29125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wikiindex.php"] [unique_id "apPllLz-S0xMfHBNth6P0QAAAWI"]
[Sun Aug 30 03:11:00.133532 2026] [security2:error] [pid 518600:tid 518738] [client 68.155.159.216:62652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-blog-header.php"] [unique_id "apPllO349Tv4SB45P2nQAAAAAIo"]
[Sun Aug 30 03:11:00.134127 2026] [security2:error] [pid 517995:tid 518211] [client 158.23.184.117:7469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/www.php"] [unique_id "apPllLz-S0xMfHBNth6P4AAAAV4"]
[Sun Aug 30 03:11:00.142785 2026] [security2:error] [pid 517995:tid 518241] [client 4.205.62.107:61811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/umgebung.php"] [unique_id "apPllLz-S0xMfHBNth6P5QAAAXw"]
[Sun Aug 30 03:11:00.161749 2026] [authz_core:error] [pid 515259:tid 515474] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:11:00.162034 2026] [authz_core:error] [pid 515259:tid 515474] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:11:00.168473 2026] [security2:error] [pid 515259:tid 515310] [remote 97.74.87.194:57020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ltr7.com"] [uri "/wp-login.php"] [unique_id "apPllGZcVaai59truiWZlAAAdjE"]
[Sun Aug 30 03:11:00.177182 2026] [security2:error] [pid 517995:tid 518159] [client 158.23.147.79:2005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apPllLz-S0xMfHBNth6QBQAAASo"]
[Sun Aug 30 03:11:00.197779 2026] [security2:error] [pid 518600:tid 518801] [client 52.139.37.240:13878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/wp-content/uploads/min.php"] [unique_id "apPllO349Tv4SB45P2nQMwAAAMk"]
[Sun Aug 30 03:11:00.197940 2026] [security2:error] [pid 518600:tid 518789] [client 20.48.250.41:40771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/bolt.php"] [unique_id "apPllO349Tv4SB45P2nQOgAAAL0"]
[Sun Aug 30 03:11:00.234530 2026] [security2:error] [pid 517995:tid 518218] [client 20.104.49.130:58188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/bthil.php"] [unique_id "apPllLz-S0xMfHBNth6QIAAAAWU"]
[Sun Aug 30 03:11:00.243369 2026] [security2:error] [pid 518600:tid 518772] [client 20.104.49.130:53522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/browse.php"] [unique_id "apPllO349Tv4SB45P2nQZQAAAKw"]
[Sun Aug 30 03:11:00.254425 2026] [security2:error] [pid 518600:tid 518833] [client 20.48.160.90:51860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/file1221.php"] [unique_id "apPllO349Tv4SB45P2nQaAAAAOk"]
[Sun Aug 30 03:11:00.275807 2026] [security2:error] [pid 517995:tid 518190] [client 158.23.184.117:7470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/.well-known/core.php"] [unique_id "apPllLz-S0xMfHBNth6QOwAAAUk"]
[Sun Aug 30 03:11:00.347323 2026] [security2:error] [pid 518600:tid 518738] [client 20.104.50.220:63516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/DC.php"] [unique_id "apPllO349Tv4SB45P2nQpAAAAIo"]
[Sun Aug 30 03:11:00.363657 2026] [authz_core:error] [pid 515259:tid 515446] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:00.364038 2026] [authz_core:error] [pid 515259:tid 515446] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:00.374935 2026] [security2:error] [pid 518600:tid 518809] [client 20.104.18.15:22431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/drykl.php"] [unique_id "apPllO349Tv4SB45P2nQswAAANE"]
[Sun Aug 30 03:11:00.377203 2026] [security2:error] [pid 518600:tid 518836] [client 20.104.50.220:29150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/jpg.php"] [unique_id "apPllO349Tv4SB45P2nQtwAAAOw"]
[Sun Aug 30 03:11:00.391402 2026] [security2:error] [pid 518600:tid 518840] [client 20.104.18.15:18317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/t3.php"] [unique_id "apPllO349Tv4SB45P2nQywAAAPA"]
[Sun Aug 30 03:11:00.395199 2026] [security2:error] [pid 518600:tid 518737] [client 20.48.250.41:40823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/rtx.php"] [unique_id "apPllO349Tv4SB45P2nQ0AAAAIk"]
[Sun Aug 30 03:11:00.398264 2026] [security2:error] [pid 518600:tid 518826] [client 4.205.62.107:36647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/kedi.php"] [unique_id "apPllO349Tv4SB45P2nQ1QAAAOI"]
[Sun Aug 30 03:11:00.402406 2026] [security2:error] [pid 517995:tid 518169] [client 52.139.37.240:43104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/zoom1.php"] [unique_id "apPllLz-S0xMfHBNth6QmAAAATQ"]
[Sun Aug 30 03:11:00.409175 2026] [authz_core:error] [pid 517995:tid 518247] [client 66.249.66.32:55879] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:00.409683 2026] [authz_core:error] [pid 517995:tid 518247] [client 66.249.66.32:55879] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:00.416986 2026] [security2:error] [pid 518600:tid 518766] [client 158.23.184.117:7481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/akcc.php"] [unique_id "apPllO349Tv4SB45P2nQ6QAAAKY"]
[Sun Aug 30 03:11:00.430867 2026] [security2:error] [pid 517995:tid 518239] [client 20.63.219.114:15242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/s.php"] [unique_id "apPllLz-S0xMfHBNth6QuAAAAXo"]
[Sun Aug 30 03:11:00.458474 2026] [security2:error] [pid 517995:tid 518217] [client 20.104.50.220:33209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-content/uploads/simple-file-list/shell.php"] [unique_id "apPllLz-S0xMfHBNth6QxgAAAWQ"]
[Sun Aug 30 03:11:00.467482 2026] [security2:error] [pid 518600:tid 518745] [client 40.83.93.50:6211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/wp-blog-header.php"] [unique_id "apPllO349Tv4SB45P2nQ-AAAAJE"]
[Sun Aug 30 03:11:00.482115 2026] [security2:error] [pid 517995:tid 518185] [client 20.104.49.130:60757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/dex.php"] [unique_id "apPllLz-S0xMfHBNth6QzwAAAUQ"]
[Sun Aug 30 03:11:00.483663 2026] [security2:error] [pid 517995:tid 518162] [client 20.48.251.3:65474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/routes.php"] [unique_id "apPllLz-S0xMfHBNth6Q0AAAAS0"]
[Sun Aug 30 03:11:00.485860 2026] [security2:error] [pid 518600:tid 518844] [client 20.104.50.220:5606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/feed.php"] [unique_id "apPllO349Tv4SB45P2nRAAAAAPQ"]
[Sun Aug 30 03:11:00.494195 2026] [security2:error] [pid 517995:tid 518173] [client 20.104.18.15:31707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/k.php"] [unique_id "apPllLz-S0xMfHBNth6Q2AAAATg"]
[Sun Aug 30 03:11:00.514496 2026] [access_compat:error] [pid 518600:tid 518823] [client 207.154.212.47:49804] AH01797: client denied by server configuration: /home2/church/public_html/eessel.com/server-status
[Sun Aug 30 03:11:00.522021 2026] [security2:error] [pid 518600:tid 518794] [client 20.104.50.220:17275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPllO349Tv4SB45P2nRHQAAAMI"]
[Sun Aug 30 03:11:00.523704 2026] [security2:error] [pid 518600:tid 518849] [client 20.48.160.90:51945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/nox.php"] [unique_id "apPllO349Tv4SB45P2nRIAAAAPk"]
[Sun Aug 30 03:11:00.524389 2026] [authz_core:error] [pid 515259:tid 515472] [client 66.249.66.75:57514] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:00.524843 2026] [authz_core:error] [pid 515259:tid 515472] [client 66.249.66.75:57514] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:00.532818 2026] [security2:error] [pid 517995:tid 518229] [client 20.48.250.41:40910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/ckk.php"] [unique_id "apPllLz-S0xMfHBNth6Q7QAAAXA"]
[Sun Aug 30 03:11:00.563374 2026] [security2:error] [pid 518600:tid 518836] [client 158.23.184.117:7434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/themes7.php"] [unique_id "apPllO349Tv4SB45P2nROgAAAOw"]
[Sun Aug 30 03:11:00.572533 2026] [authz_core:error] [pid 518600:tid 518768] [client 66.249.66.77:51751] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:00.573701 2026] [authz_core:error] [pid 518600:tid 518768] [client 66.249.66.77:51751] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:00.599165 2026] [security2:error] [pid 515259:tid 515317] [remote 97.74.87.194:57020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ltr7.com"] [uri "/wp-login.php"] [unique_id "apPllGZcVaai59truiWaNwAAeDg"], referer: https://ltr7.com/wp-login.php
[Sun Aug 30 03:11:00.604015 2026] [security2:error] [pid 515259:tid 515492] [client 52.139.37.240:13847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/lock360.php"] [unique_id "apPllGZcVaai59truiWaOQAAAGY"]
[Sun Aug 30 03:11:00.619483 2026] [security2:error] [pid 518600:tid 518743] [client 158.23.147.79:56504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apPllO349Tv4SB45P2nRcQAAAI8"]
[Sun Aug 30 03:11:00.663080 2026] [security2:error] [pid 517995:tid 518252] [client 20.48.250.41:40886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.katbacon.com"] [uri "/R57.php"] [unique_id "apPllLz-S0xMfHBNth6RMAAAAYc"]
[Sun Aug 30 03:11:00.705826 2026] [security2:error] [pid 518600:tid 518799] [client 20.48.160.90:28158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/akismet.php"] [unique_id "apPllO349Tv4SB45P2nR1gAAAMc"]
[Sun Aug 30 03:11:00.707073 2026] [security2:error] [pid 518600:tid 518813] [client 158.23.184.117:7520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/wp-admin/images.php"] [unique_id "apPllO349Tv4SB45P2nR1wAAANU"]
[Sun Aug 30 03:11:00.724979 2026] [security2:error] [pid 517995:tid 518200] [client 178.156.181.172:32882] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "omconsulting-group.com"] [uri "/index.php"] [unique_id "apPllLz-S0xMfHBNth6QOAAAAVM"], referer: https://omconsulting-group.com
[Sun Aug 30 03:11:00.725451 2026] [security2:error] [pid 518600:tid 518781] [client 4.205.62.107:17726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/god.php"] [unique_id "apPllO349Tv4SB45P2nR7AAAALU"]
[Sun Aug 30 03:11:00.734977 2026] [core:alert] [pid 518600:tid 518805] [client 175.100.33.103:14965] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:11:00.808160 2026] [security2:error] [pid 518600:tid 518797] [client 52.139.37.240:13864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/r.php"] [unique_id "apPllO349Tv4SB45P2nSNQAAAMU"]
[Sun Aug 30 03:11:00.809584 2026] [security2:error] [pid 518600:tid 518814] [client 20.48.251.3:59269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/G-in.php"] [unique_id "apPllO349Tv4SB45P2nSTgAAANY"]
[Sun Aug 30 03:11:00.845578 2026] [security2:error] [pid 517995:tid 518127] [client 158.23.184.117:7434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/wp-content/themes/haha.php"] [unique_id "apPllLz-S0xMfHBNth6RpAAAAQo"]
[Sun Aug 30 03:11:00.855745 2026] [security2:error] [pid 518600:tid 518805] [client 20.48.160.90:28100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/ajax.php"] [unique_id "apPllO349Tv4SB45P2nScQAAAM0"]
[Sun Aug 30 03:11:00.878676 2026] [security2:error] [pid 517995:tid 518187] [client 20.63.219.114:2084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/php.php"] [unique_id "apPllLz-S0xMfHBNth6RvwAAAUY"]
[Sun Aug 30 03:11:00.883320 2026] [security2:error] [pid 517995:tid 518129] [client 20.104.49.130:53702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/load.php"] [unique_id "apPllLz-S0xMfHBNth6RwgAAAQw"]
[Sun Aug 30 03:11:00.889595 2026] [authz_core:error] [pid 515259:tid 515510] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:00.890111 2026] [authz_core:error] [pid 515259:tid 515510] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:00.920676 2026] [security2:error] [pid 518600:tid 518738] [client 158.23.147.79:58385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/lv.php"] [unique_id "apPllO349Tv4SB45P2nSpwAAAIo"]
[Sun Aug 30 03:11:00.957863 2026] [security2:error] [pid 517995:tid 518204] [client 20.48.251.3:43088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/fff.php"] [unique_id "apPllLz-S0xMfHBNth6SDQAAAVc"]
[Sun Aug 30 03:11:00.971224 2026] [security2:error] [pid 515259:tid 515455] [client 40.83.93.50:6362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/s.php"] [unique_id "apPllGZcVaai59truiWatAAAAEE"]
[Sun Aug 30 03:11:00.974692 2026] [security2:error] [pid 518600:tid 518826] [client 20.104.18.15:16905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/nofile.php"] [unique_id "apPllO349Tv4SB45P2nSzQAAAOI"]
[Sun Aug 30 03:11:00.985893 2026] [security2:error] [pid 518600:tid 518808] [client 158.23.184.117:7489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/wp-mail.php"] [unique_id "apPllO349Tv4SB45P2nSzwAAANA"]
[Sun Aug 30 03:11:00.999084 2026] [authz_core:error] [pid 517995:tid 518244] [client 216.73.216.128:1958] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:00.999390 2026] [authz_core:error] [pid 517995:tid 518244] [client 216.73.216.128:1958] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:01.003520 2026] [authz_core:error] [pid 517995:tid 518147] [client 66.249.66.75:53925] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:01.004016 2026] [authz_core:error] [pid 517995:tid 518147] [client 66.249.66.75:53925] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:01.010453 2026] [security2:error] [pid 515259:tid 515447] [client 20.104.49.130:53545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/002.php"] [unique_id "apPllWZcVaai59truiWaxAAAADk"]
[Sun Aug 30 03:11:01.014307 2026] [security2:error] [pid 515259:tid 515514] [client 20.104.50.220:61830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-js.php"] [unique_id "apPllWZcVaai59truiWayQAAAHw"]
[Sun Aug 30 03:11:01.015596 2026] [security2:error] [pid 518600:tid 518772] [client 52.139.37.240:44613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/sf.php"] [unique_id "apPlle349Tv4SB45P2nS0wAAAKw"]
[Sun Aug 30 03:11:01.032357 2026] [security2:error] [pid 518600:tid 518850] [client 20.48.160.90:51844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/atomlib.php"] [unique_id "apPlle349Tv4SB45P2nS4AAAAPo"]
[Sun Aug 30 03:11:01.062563 2026] [security2:error] [pid 518600:tid 518805] [client 158.23.147.79:56480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apPlle349Tv4SB45P2nTCwAAAM0"]
[Sun Aug 30 03:11:01.062961 2026] [security2:error] [pid 515259:tid 515437] [client 68.155.159.216:52586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/index/function.php"] [unique_id "apPllWZcVaai59truiWa3wAAAC8"]
[Sun Aug 30 03:11:01.072499 2026] [security2:error] [pid 518600:tid 518803] [client 4.205.62.107:16370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/thui.php"] [unique_id "apPlle349Tv4SB45P2nTEwAAAMs"]
[Sun Aug 30 03:11:01.092109 2026] [authz_core:error] [pid 518600:tid 518765] [client 216.73.216.128:60050] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:01.092400 2026] [authz_core:error] [pid 518600:tid 518765] [client 216.73.216.128:60050] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:01.122971 2026] [security2:error] [pid 518600:tid 518759] [client 68.155.159.216:45997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apPlle349Tv4SB45P2nTVgAAAJ8"]
[Sun Aug 30 03:11:01.124870 2026] [security2:error] [pid 518600:tid 518837] [client 158.23.184.117:7482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/root.php"] [unique_id "apPlle349Tv4SB45P2nTXQAAAO0"]
[Sun Aug 30 03:11:01.167037 2026] [security2:error] [pid 517995:tid 518230] [client 20.48.160.90:28135] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "dirkhoag.com"] [uri "/1.php"] [unique_id "apPllbz-S0xMfHBNth6SogAAAXE"]
[Sun Aug 30 03:11:01.167147 2026] [security2:error] [pid 517995:tid 518230] [client 20.48.160.90:28135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/1.php"] [unique_id "apPllbz-S0xMfHBNth6SogAAAXE"]
[Sun Aug 30 03:11:01.216572 2026] [security2:error] [pid 518600:tid 518645] [remote 112.78.134.58:42458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.134.78.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ionicfab.com"] [uri "/wp-login.php"] [unique_id "apPlle349Tv4SB45P2nTpAAApCk"]
[Sun Aug 30 03:11:01.222780 2026] [security2:error] [pid 518600:tid 518752] [client 52.139.37.240:44566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/7.php"] [unique_id "apPlle349Tv4SB45P2nToQAAAJg"]
[Sun Aug 30 03:11:01.255511 2026] [security2:error] [pid 518600:tid 518822] [client 68.155.159.216:57085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apPlle349Tv4SB45P2nTxAAAAN4"]
[Sun Aug 30 03:11:01.267770 2026] [security2:error] [pid 517995:tid 518208] [client 20.104.50.220:62784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/alex.php"] [unique_id "apPllbz-S0xMfHBNth6S2gAAAVs"]
[Sun Aug 30 03:11:01.272058 2026] [security2:error] [pid 518600:tid 518743] [client 20.151.200.44:40932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/od.php"] [unique_id "apPlle349Tv4SB45P2nTyAAAAI8"]
[Sun Aug 30 03:11:01.279513 2026] [security2:error] [pid 518600:tid 518794] [client 158.23.184.117:7549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/ae.php"] [unique_id "apPlle349Tv4SB45P2nT0gAAAMI"]
[Sun Aug 30 03:11:01.288468 2026] [security2:error] [pid 518600:tid 518786] [client 20.151.200.44:64728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/t00l.php"] [unique_id "apPlle349Tv4SB45P2nT2gAAALo"]
[Sun Aug 30 03:11:01.311297 2026] [security2:error] [pid 518600:tid 518748] [client 20.48.160.90:28087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/samll.php"] [unique_id "apPlle349Tv4SB45P2nT9wAAAJQ"]
[Sun Aug 30 03:11:01.374323 2026] [security2:error] [pid 517995:tid 518171] [client 20.104.50.220:59337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/BDKR28WP.php"] [unique_id "apPllbz-S0xMfHBNth6THQAAATY"]
[Sun Aug 30 03:11:01.385016 2026] [authz_core:error] [pid 518600:tid 518790] [client 66.249.66.200:56519] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:01.385513 2026] [authz_core:error] [pid 518600:tid 518790] [client 66.249.66.200:56519] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:01.386762 2026] [security2:error] [pid 517995:tid 518198] [client 4.205.62.107:58266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/old_phpinfo.php"] [unique_id "apPllbz-S0xMfHBNth6THwAAAVE"]
[Sun Aug 30 03:11:01.404886 2026] [authz_core:error] [pid 515259:tid 515440] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:01.409696 2026] [authz_core:error] [pid 515259:tid 515440] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:01.415633 2026] [security2:error] [pid 518600:tid 518767] [client 158.23.147.79:2001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/packed.php"] [unique_id "apPlle349Tv4SB45P2nUZwAAAKc"]
[Sun Aug 30 03:11:01.417261 2026] [security2:error] [pid 517995:tid 518166] [client 158.23.184.117:7428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/admin/controller/extension/ultra.php"] [unique_id "apPllbz-S0xMfHBNth6TMAAAATE"]
[Sun Aug 30 03:11:01.424624 2026] [authz_core:error] [pid 515259:tid 515441] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:11:01.425042 2026] [authz_core:error] [pid 515259:tid 515441] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:11:01.430845 2026] [security2:error] [pid 517995:tid 518159] [client 52.139.37.240:44591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/b.php"] [unique_id "apPllbz-S0xMfHBNth6TMwAAASo"]
[Sun Aug 30 03:11:01.454564 2026] [lsapi:error] [pid 517995:tid 518045] [remote 172.88.202.161:48138] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:11:01.454696 2026] [lsapi:error] [pid 517995:tid 518045] [remote 172.88.202.161:48138] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:11:01.456058 2026] [lsapi:error] [pid 517995:tid 518045] [remote 172.88.202.161:48138] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:11:01.483414 2026] [security2:error] [pid 518600:tid 518801] [client 20.104.50.220:51589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-content/uploads/simple-file-list/DC.php"] [unique_id "apPlle349Tv4SB45P2nUjAAAAMk"]
[Sun Aug 30 03:11:01.484160 2026] [security2:error] [pid 518600:tid 518753] [client 20.48.160.90:51919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/she11.php"] [unique_id "apPlle349Tv4SB45P2nUjQAAAJk"]
[Sun Aug 30 03:11:01.494526 2026] [security2:error] [pid 518600:tid 518757] [client 40.83.93.50:10749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/php.php"] [unique_id "apPlle349Tv4SB45P2nUlQAAAJ0"]
[Sun Aug 30 03:11:01.511624 2026] [security2:error] [pid 518600:tid 518850] [client 20.104.18.15:22372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/backup.php"] [unique_id "apPlle349Tv4SB45P2nUrgAAAPo"]
[Sun Aug 30 03:11:01.524274 2026] [security2:error] [pid 518600:tid 518837] [client 20.104.50.220:52858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/jak.php"] [unique_id "apPlle349Tv4SB45P2nUtgAAAO0"]
[Sun Aug 30 03:11:01.547413 2026] [security2:error] [pid 518600:tid 518777] [client 20.104.18.15:18419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/wp.php"] [unique_id "apPlle349Tv4SB45P2nUzAAAALE"]
[Sun Aug 30 03:11:01.556380 2026] [security2:error] [pid 518600:tid 518782] [client 4.205.62.107:25528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/koiy.php"] [unique_id "apPlle349Tv4SB45P2nU0wAAALY"]
[Sun Aug 30 03:11:01.559255 2026] [security2:error] [pid 518600:tid 518809] [client 158.23.184.117:7451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/wp-content/import.php"] [unique_id "apPlle349Tv4SB45P2nU2QAAANE"]
[Sun Aug 30 03:11:01.612683 2026] [security2:error] [pid 517995:tid 518161] [client 20.104.50.220:33338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-content/uploads/simple-file-list/fox.php"] [unique_id "apPllbz-S0xMfHBNth6TjgAAASw"]
[Sun Aug 30 03:11:01.619597 2026] [security2:error] [pid 518600:tid 518737] [client 20.48.160.90:51846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/kerang.php"] [unique_id "apPlle349Tv4SB45P2nVIwAAAIk"]
[Sun Aug 30 03:11:01.627911 2026] [security2:error] [pid 518600:tid 518860] [client 20.104.50.220:6139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/defense.php"] [unique_id "apPlle349Tv4SB45P2nVLgAAAQQ"]
[Sun Aug 30 03:11:01.640680 2026] [security2:error] [pid 517995:tid 518180] [client 20.48.251.3:65527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/aww.php"] [unique_id "apPllbz-S0xMfHBNth6ToQAAAT8"]
[Sun Aug 30 03:11:01.645062 2026] [security2:error] [pid 518600:tid 518790] [client 20.104.18.15:31730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/dex.php"] [unique_id "apPlle349Tv4SB45P2nVNgAAAL4"]
[Sun Aug 30 03:11:01.645268 2026] [security2:error] [pid 518600:tid 518762] [client 52.139.37.240:13852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/buy.php"] [unique_id "apPlle349Tv4SB45P2nVLQAAAKI"]
[Sun Aug 30 03:11:01.679229 2026] [security2:error] [pid 518600:tid 518856] [client 20.104.50.220:17343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/css/colors/blue/index.php"] [unique_id "apPlle349Tv4SB45P2nVTAAAAQA"]
[Sun Aug 30 03:11:01.689186 2026] [security2:error] [pid 517995:tid 518148] [client 4.205.62.107:36027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/oc460l3x.php"] [unique_id "apPllbz-S0xMfHBNth6TzgAAAR8"]
[Sun Aug 30 03:11:01.700394 2026] [security2:error] [pid 518600:tid 518770] [client 158.23.184.117:7539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/wp-includes/fonts/admin.php"] [unique_id "apPlle349Tv4SB45P2nVWAAAAKo"]
[Sun Aug 30 03:11:01.700946 2026] [security2:error] [pid 518600:tid 518650] [remote 112.78.134.58:42458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.134.78.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ionicfab.com"] [uri "/wp-login.php"] [unique_id "apPlle349Tv4SB45P2nVVwAA-y4"], referer: https://ionicfab.com/wp-login.php
[Sun Aug 30 03:11:01.728933 2026] [security2:error] [pid 517995:tid 518204] [client 20.104.49.130:53542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/wp-css.php"] [unique_id "apPllbz-S0xMfHBNth6T-wAAAVc"]
[Sun Aug 30 03:11:01.731690 2026] [authz_core:error] [pid 518600:tid 518787] [client 216.73.216.128:60050] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:01.732205 2026] [authz_core:error] [pid 518600:tid 518787] [client 216.73.216.128:60050] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:01.733515 2026] [security2:error] [pid 518600:tid 518744] [client 158.23.147.79:62011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apPlle349Tv4SB45P2nVagAAAJA"]
[Sun Aug 30 03:11:01.750019 2026] [security2:error] [pid 517995:tid 518226] [client 20.104.49.130:53552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/jp.php"] [unique_id "apPllbz-S0xMfHBNth6UEAAAAW0"]
[Sun Aug 30 03:11:01.773600 2026] [security2:error] [pid 515259:tid 515452] [client 20.48.160.90:51923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/m.php"] [unique_id "apPllWZcVaai59truiWb8gAAAD4"]
[Sun Aug 30 03:11:01.802362 2026] [authz_core:error] [pid 517995:tid 518252] [client 66.249.66.197:54518] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:01.802777 2026] [authz_core:error] [pid 517995:tid 518252] [client 66.249.66.197:54518] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:01.815776 2026] [core:error] [pid 517995:tid 518049] [remote 216.73.216.95:32769] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:11:01.815802 2026] [core:error] [pid 517995:tid 518049] [remote 216.73.216.95:32769] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:11:01.845748 2026] [security2:error] [pid 517995:tid 518248] [client 158.23.184.117:7516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/222.php"] [unique_id "apPllbz-S0xMfHBNth6UYQAAAYM"]
[Sun Aug 30 03:11:01.852479 2026] [security2:error] [pid 517995:tid 518192] [client 52.139.37.240:43118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/config.php"] [unique_id "apPllbz-S0xMfHBNth6UXwAAAUs"]
[Sun Aug 30 03:11:01.855340 2026] [authz_core:error] [pid 515259:tid 515396] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:01.855616 2026] [authz_core:error] [pid 515259:tid 515396] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:01.874930 2026] [security2:error] [pid 517995:tid 518148] [client 4.205.62.107:17693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/fff.php"] [unique_id "apPllbz-S0xMfHBNth6UcAAAAR8"]
[Sun Aug 30 03:11:01.926841 2026] [security2:error] [pid 518600:tid 518792] [client 20.48.160.90:28074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/fling.php"] [unique_id "apPlle349Tv4SB45P2nV9AAAAMA"]
[Sun Aug 30 03:11:01.962229 2026] [security2:error] [pid 515259:tid 515449] [client 20.48.251.3:52826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/apikeys.php"] [unique_id "apPllWZcVaai59truiWcNQAAADs"]
[Sun Aug 30 03:11:01.969540 2026] [authz_core:error] [pid 518600:tid 518770] [client 66.249.66.200:63491] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:01.970003 2026] [authz_core:error] [pid 518600:tid 518770] [client 66.249.66.200:63491] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:01.981034 2026] [security2:error] [pid 517995:tid 518234] [client 158.23.147.79:57699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-content/packed.php"] [unique_id "apPllbz-S0xMfHBNth6U0wAAAXU"]
[Sun Aug 30 03:11:01.985624 2026] [security2:error] [pid 517995:tid 518174] [client 20.63.219.114:19161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/system_log.php"] [unique_id "apPllbz-S0xMfHBNth6U1gAAATk"]
[Sun Aug 30 03:11:01.989955 2026] [security2:error] [pid 518600:tid 518797] [client 158.23.184.117:7502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/wp-content/languages.php"] [unique_id "apPlle349Tv4SB45P2nWGQAAAMU"]
[Sun Aug 30 03:11:02.059059 2026] [security2:error] [pid 517995:tid 518221] [client 52.139.37.240:44593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/num.php"] [unique_id "apPllrz-S0xMfHBNth6VFAAAAWg"]
[Sun Aug 30 03:11:02.060599 2026] [security2:error] [pid 517995:tid 518250] [client 20.48.160.90:51905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/btyuio.php"] [unique_id "apPllrz-S0xMfHBNth6VIwAAAYU"]
[Sun Aug 30 03:11:02.101007 2026] [security2:error] [pid 518600:tid 518773] [client 20.48.251.3:59514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/autogooey.php"] [unique_id "apPllu349Tv4SB45P2nWXQAAAK0"]
[Sun Aug 30 03:11:02.125995 2026] [security2:error] [pid 518600:tid 518786] [client 20.104.18.15:16992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/run.php"] [unique_id "apPllu349Tv4SB45P2nWhQAAALo"]
[Sun Aug 30 03:11:02.140091 2026] [security2:error] [pid 517995:tid 518162] [client 158.23.184.117:7446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/wp-config-sample.php"] [unique_id "apPllrz-S0xMfHBNth6VfwAAAS0"]
[Sun Aug 30 03:11:02.147401 2026] [security2:error] [pid 518600:tid 518819] [client 40.83.93.50:6396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/system_log.php"] [unique_id "apPllu349Tv4SB45P2nWoAAAANs"]
[Sun Aug 30 03:11:02.162788 2026] [security2:error] [pid 517995:tid 518163] [client 20.104.50.220:59575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-mails.php"] [unique_id "apPllrz-S0xMfHBNth6VjwAAAS4"]
[Sun Aug 30 03:11:02.196344 2026] [security2:error] [pid 518600:tid 518776] [client 20.48.160.90:28040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/dehnl.php"] [unique_id "apPllu349Tv4SB45P2nWyAAAALA"]
[Sun Aug 30 03:11:02.205719 2026] [security2:error] [pid 518600:tid 518779] [client 4.205.62.107:16338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/lala.php"] [unique_id "apPllu349Tv4SB45P2nW0wAAALM"]
[Sun Aug 30 03:11:02.246611 2026] [security2:error] [pid 517995:tid 518233] [client 68.155.159.216:52553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/.well-known/content.php"] [unique_id "apPllrz-S0xMfHBNth6VxgAAAXQ"]
[Sun Aug 30 03:11:02.257543 2026] [security2:error] [pid 515259:tid 515420] [client 52.139.37.240:44564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/areak1.php"] [unique_id "apPllmZcVaai59truiWctQAAAB4"]
[Sun Aug 30 03:11:02.281116 2026] [security2:error] [pid 517995:tid 518198] [client 158.23.184.117:7426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/wp-admin/install-helper.php"] [unique_id "apPllrz-S0xMfHBNth6V2QAAAVE"]
[Sun Aug 30 03:11:02.351837 2026] [authz_core:error] [pid 515259:tid 515396] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:02.352096 2026] [authz_core:error] [pid 515259:tid 515396] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:02.383191 2026] [security2:error] [pid 517995:tid 518201] [client 20.48.160.90:51882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/zoo2.php"] [unique_id "apPllrz-S0xMfHBNth6WJQAAAVQ"]
[Sun Aug 30 03:11:02.400964 2026] [security2:error] [pid 517995:tid 518187] [client 68.155.159.216:57030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-admin/user/index.php"] [unique_id "apPllrz-S0xMfHBNth6WMgAAAUY"]
[Sun Aug 30 03:11:02.420943 2026] [security2:error] [pid 517995:tid 518151] [client 158.23.184.117:7458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/wp-includes/fonts/classmap.php"] [unique_id "apPllrz-S0xMfHBNth6WPQAAASI"]
[Sun Aug 30 03:11:02.426442 2026] [security2:error] [pid 518600:tid 518789] [client 20.104.50.220:28730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-0.php"] [unique_id "apPllu349Tv4SB45P2nXdQAAAL0"]
[Sun Aug 30 03:11:02.438615 2026] [security2:error] [pid 517995:tid 518238] [client 158.23.147.79:1944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-l0gin.php"] [unique_id "apPllrz-S0xMfHBNth6WRQAAAXk"]
[Sun Aug 30 03:11:02.463676 2026] [authz_core:error] [pid 517995:tid 518225] [client 66.249.66.38:53390] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:02.463952 2026] [authz_core:error] [pid 517995:tid 518225] [client 66.249.66.38:53390] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:02.468597 2026] [security2:error] [pid 517995:tid 518247] [client 52.139.37.240:14035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/vc.php"] [unique_id "apPllrz-S0xMfHBNth6WVwAAAYI"]
[Sun Aug 30 03:11:02.557259 2026] [security2:error] [pid 517995:tid 518158] [client 20.48.160.90:28131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/zoo1.php"] [unique_id "apPllrz-S0xMfHBNth6WnAAAASk"]
[Sun Aug 30 03:11:02.564483 2026] [security2:error] [pid 515259:tid 515480] [client 158.23.184.117:7443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/adminfuns.php/.well-known/acme-challenge/file.php"] [unique_id "apPllmZcVaai59truiWdLQAAAFo"]
[Sun Aug 30 03:11:02.600224 2026] [security2:error] [pid 518600:tid 518815] [client 68.155.159.216:45915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPllu349Tv4SB45P2nX4gAAANc"]
[Sun Aug 30 03:11:02.617773 2026] [security2:error] [pid 517995:tid 518245] [client 40.83.93.50:6379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/w.php"] [unique_id "apPllrz-S0xMfHBNth6WyQAAAYA"]
[Sun Aug 30 03:11:02.619883 2026] [security2:error] [pid 517995:tid 518228] [client 20.63.219.114:15661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/w.php"] [unique_id "apPllrz-S0xMfHBNth6WzAAAAW8"]
[Sun Aug 30 03:11:02.624997 2026] [security2:error] [pid 515259:tid 515456] [client 4.205.62.107:64699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.michaeldanzerphoto.com"] [uri "/wp-act.php"] [unique_id "apPllmZcVaai59truiWdSQAAAEI"]
[Sun Aug 30 03:11:02.631563 2026] [authz_core:error] [pid 518600:tid 518774] [client 66.249.66.37:40896] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:02.632086 2026] [authz_core:error] [pid 518600:tid 518774] [client 66.249.66.37:40896] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:02.642506 2026] [security2:error] [pid 517995:tid 518182] [client 20.104.50.220:41984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-content/uploads/simple-file-list/shell.php"] [unique_id "apPllrz-S0xMfHBNth6W3AAAAUE"]
[Sun Aug 30 03:11:02.657615 2026] [security2:error] [pid 517995:tid 518213] [client 20.104.18.15:22472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/indo.php"] [unique_id "apPllrz-S0xMfHBNth6W6QAAAWA"]
[Sun Aug 30 03:11:02.665423 2026] [security2:error] [pid 517995:tid 518160] [client 20.104.50.220:62822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/image.php"] [unique_id "apPllrz-S0xMfHBNth6W8AAAASs"]
[Sun Aug 30 03:11:02.671371 2026] [security2:error] [pid 518600:tid 518740] [client 52.139.37.240:14028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPllu349Tv4SB45P2nYFAAAAIw"]
[Sun Aug 30 03:11:02.676098 2026] [security2:error] [pid 518600:tid 518825] [client 158.23.147.79:61726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPllu349Tv4SB45P2nYHgAAAOE"]
[Sun Aug 30 03:11:02.683820 2026] [authz_core:error] [pid 515259:tid 515442] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:11:02.684288 2026] [authz_core:error] [pid 515259:tid 515442] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:11:02.686851 2026] [autoindex:error] [pid 517995:tid 518170] [client 57.131.147.192:0] AH01276: Cannot serve directory /home3/ucdsscom/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:11:02.700037 2026] [security2:error] [pid 518600:tid 518747] [client 20.104.18.15:18251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/abcd.php"] [unique_id "apPllu349Tv4SB45P2nYNwAAAJM"]
[Sun Aug 30 03:11:02.704901 2026] [security2:error] [pid 515259:tid 515512] [client 158.23.184.117:7518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/wp-content/themes/aa.php"] [unique_id "apPllmZcVaai59truiWdawAAAHo"]
[Sun Aug 30 03:11:02.705993 2026] [security2:error] [pid 518600:tid 518753] [client 20.48.160.90:28119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/radio.php"] [unique_id "apPllu349Tv4SB45P2nYQAAAAJk"]
[Sun Aug 30 03:11:02.740963 2026] [security2:error] [pid 517995:tid 518196] [client 158.23.147.79:58390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-includes/Text/index.php"] [unique_id "apPllrz-S0xMfHBNth6XGQAAAU8"]
[Sun Aug 30 03:11:02.747179 2026] [security2:error] [pid 517995:tid 518182] [client 20.104.50.220:59351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp.php"] [unique_id "apPllrz-S0xMfHBNth6XIAAAAUE"]
[Sun Aug 30 03:11:02.750444 2026] [security2:error] [pid 518600:tid 518859] [client 20.104.50.220:32955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-content/uploads/simple-file-list/fw.php"] [unique_id "apPllu349Tv4SB45P2nYfwAAAQM"]
[Sun Aug 30 03:11:02.756273 2026] [security2:error] [pid 517995:tid 518201] [client 216.73.216.128:1958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPllrz-S0xMfHBNth6XJwAAAVQ"]
[Sun Aug 30 03:11:02.766395 2026] [security2:error] [pid 517995:tid 518144] [client 20.104.50.220:5921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/defend.php"] [unique_id "apPllrz-S0xMfHBNth6XMAAAARs"]
[Sun Aug 30 03:11:02.781231 2026] [security2:error] [pid 518600:tid 518736] [client 20.48.251.3:54798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/maxro.php"] [unique_id "apPllu349Tv4SB45P2nYjwAAAIg"]
[Sun Aug 30 03:11:02.783356 2026] [security2:error] [pid 518600:tid 518789] [client 20.104.18.15:31718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/img.php"] [unique_id "apPllu349Tv4SB45P2nYkgAAAL0"]
[Sun Aug 30 03:11:02.815748 2026] [security2:error] [pid 518600:tid 518843] [client 20.104.50.220:17221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/security.php"] [unique_id "apPllu349Tv4SB45P2nYqAAAAPM"]
[Sun Aug 30 03:11:02.842097 2026] [security2:error] [pid 517995:tid 518215] [client 158.23.184.117:7523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/chosen.php"] [unique_id "apPllrz-S0xMfHBNth6XbgAAAWI"]
[Sun Aug 30 03:11:02.868754 2026] [authz_core:error] [pid 515259:tid 515435] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:02.869210 2026] [authz_core:error] [pid 515259:tid 515435] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:02.878243 2026] [security2:error] [pid 517995:tid 518228] [client 52.139.37.240:43092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/core.php"] [unique_id "apPllrz-S0xMfHBNth6XfwAAAW8"]
[Sun Aug 30 03:11:02.906489 2026] [security2:error] [pid 518600:tid 518737] [client 20.48.160.90:46544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/one.php"] [unique_id "apPllu349Tv4SB45P2nY8wAAAIk"]
[Sun Aug 30 03:11:02.918592 2026] [autoindex:error] [pid 518600:tid 518836] [client 57.131.147.192:0] AH01276: Cannot serve directory /home3/ucdsscom/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:11:02.923213 2026] [security2:error] [pid 517995:tid 518182] [client 4.205.62.107:36571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/drykl.php"] [unique_id "apPllrz-S0xMfHBNth6XuAAAAUE"]
[Sun Aug 30 03:11:02.938780 2026] [security2:error] [pid 518600:tid 518655] [remote 78.47.229.96:36298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.229.47.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "maidtoglisten.com"] [uri "/wp-login.php"] [unique_id "apPllu349Tv4SB45P2nZDAAAozM"]
[Sun Aug 30 03:11:02.968503 2026] [security2:error] [pid 518600:tid 518807] [client 4.205.62.107:25882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/queue.php"] [unique_id "apPllu349Tv4SB45P2nZLwAAAM8"]
[Sun Aug 30 03:11:02.974544 2026] [security2:error] [pid 515259:tid 515411] [client 20.48.251.3:36837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPllmZcVaai59truiWd1wAAABU"]
[Sun Aug 30 03:11:02.987072 2026] [security2:error] [pid 517995:tid 518227] [client 158.23.184.117:7435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/admin/function.php"] [unique_id "apPllrz-S0xMfHBNth6X9QAAAW4"]
[Sun Aug 30 03:11:03.011540 2026] [authz_core:error] [pid 517995:tid 518159] [client 66.249.66.68:57052] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:03.011970 2026] [authz_core:error] [pid 517995:tid 518159] [client 66.249.66.68:57052] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:03.017427 2026] [security2:error] [pid 518600:tid 518770] [client 4.205.62.107:17707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/autogooey.php"] [unique_id "apPll-349Tv4SB45P2nZTgAAAKo"]
[Sun Aug 30 03:11:03.018566 2026] [security2:error] [pid 518600:tid 518833] [client 20.104.49.130:52418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/css.php"] [unique_id "apPll-349Tv4SB45P2nZTwAAAOk"]
[Sun Aug 30 03:11:03.037516 2026] [security2:error] [pid 517995:tid 518242] [client 20.48.160.90:28108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/503.php"] [unique_id "apPll7z-S0xMfHBNth6YHAAAAX0"]
[Sun Aug 30 03:11:03.052095 2026] [security2:error] [pid 518600:tid 518812] [client 158.23.147.79:52280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/ans.php"] [unique_id "apPll-349Tv4SB45P2nZbgAAANQ"]
[Sun Aug 30 03:11:03.070722 2026] [security2:error] [pid 518600:tid 518844] [client 20.63.219.114:7776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/wp.php"] [unique_id "apPll-349Tv4SB45P2nZiAAAAPQ"]
[Sun Aug 30 03:11:03.079773 2026] [security2:error] [pid 517995:tid 518215] [client 57.131.147.192:52633] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdss.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "apPll7z-S0xMfHBNth6YRgAAAWI"]
[Sun Aug 30 03:11:03.083755 2026] [security2:error] [pid 517995:tid 518158] [client 52.139.37.240:44583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/wp-content/min.php"] [unique_id "apPll7z-S0xMfHBNth6YPwAAASk"]
[Sun Aug 30 03:11:03.087631 2026] [lsapi:error] [pid 515259:tid 515322] [remote 149.143.159.250:33028] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n
[Sun Aug 30 03:11:03.087792 2026] [lsapi:error] [pid 515259:tid 515322] [remote 149.143.159.250:33028] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n
[Sun Aug 30 03:11:03.089142 2026] [lsapi:error] [pid 515259:tid 515322] [remote 149.143.159.250:33028] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n
[Sun Aug 30 03:11:03.099421 2026] [security2:error] [pid 517995:tid 518167] [client 20.48.251.3:59383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/motu.php"] [unique_id "apPll7z-S0xMfHBNth6YVQAAATI"]
[Sun Aug 30 03:11:03.126832 2026] [security2:error] [pid 518600:tid 518656] [remote 78.47.229.96:36298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.229.47.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "maidtoglisten.com"] [uri "/wp-login.php"] [unique_id "apPll-349Tv4SB45P2nZrgAA7zQ"], referer: https://maidtoglisten.com/wp-login.php
[Sun Aug 30 03:11:03.127572 2026] [security2:error] [pid 517995:tid 518133] [client 158.23.184.117:7533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/wxo.php"] [unique_id "apPll7z-S0xMfHBNth6YeAAAARA"]
[Sun Aug 30 03:11:03.127785 2026] [security2:error] [pid 518600:tid 518804] [client 40.83.93.50:6360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/wp.php"] [unique_id "apPll-349Tv4SB45P2nZsQAAAMw"]
[Sun Aug 30 03:11:03.150679 2026] [security2:error] [pid 518600:tid 518771] [client 20.104.49.130:36746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/ab.php"] [unique_id "apPll-349Tv4SB45P2nZ3AAAAKs"]
[Sun Aug 30 03:11:03.172121 2026] [authz_core:error] [pid 517995:tid 518187] [client 66.249.66.192:42820] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:03.172490 2026] [authz_core:error] [pid 517995:tid 518187] [client 66.249.66.192:42820] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:03.188629 2026] [security2:error] [pid 517995:tid 518236] [client 20.151.200.44:40768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/wp-the.php"] [unique_id "apPll7z-S0xMfHBNth6YoQAAAXc"]
[Sun Aug 30 03:11:03.204924 2026] [security2:error] [pid 518600:tid 518853] [client 20.48.160.90:46548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/504.php"] [unique_id "apPll-349Tv4SB45P2naBgAAAP0"]
[Sun Aug 30 03:11:03.271435 2026] [security2:error] [pid 517995:tid 518143] [client 20.104.18.15:16936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/new.php"] [unique_id "apPll7z-S0xMfHBNth6Y1gAAARo"]
[Sun Aug 30 03:11:03.275558 2026] [security2:error] [pid 518600:tid 518749] [client 158.23.184.117:7438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/wp-admin/theme-editor.php"] [unique_id "apPll-349Tv4SB45P2naIwAAAJU"]
[Sun Aug 30 03:11:03.284206 2026] [security2:error] [pid 517995:tid 518147] [client 52.139.37.240:13848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/wp-content/plugins/beteng88/ws83.php"] [unique_id "apPll7z-S0xMfHBNth6Y3AAAAR4"]
[Sun Aug 30 03:11:03.284516 2026] [security2:error] [pid 515259:tid 515422] [client 20.48.251.3:52248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/sdsa.php"] [unique_id "apPll2ZcVaai59truiWeVQAAACA"]
[Sun Aug 30 03:11:03.299974 2026] [security2:error] [pid 518600:tid 518659] [remote 168.63.79.147:46706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hebrews111.com"] [uri "/wp-login.php"] [unique_id "apPll-349Tv4SB45P2naKgAA8Dc"]
[Sun Aug 30 03:11:03.304990 2026] [security2:error] [pid 518600:tid 518844] [client 20.151.200.44:64745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/ls.php"] [unique_id "apPll-349Tv4SB45P2naNQAAAPQ"]
[Sun Aug 30 03:11:03.314193 2026] [security2:error] [pid 518600:tid 518778] [client 20.104.50.220:61677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-one.php"] [unique_id "apPll-349Tv4SB45P2naRAAAALI"]
[Sun Aug 30 03:11:03.314694 2026] [authz_core:error] [pid 518600:tid 518767] [client 216.73.216.128:48547] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:03.315159 2026] [authz_core:error] [pid 518600:tid 518767] [client 216.73.216.128:48547] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:03.334555 2026] [security2:error] [pid 518600:tid 518836] [client 20.48.160.90:28050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/admin.php"] [unique_id "apPll-349Tv4SB45P2naVQAAAOw"]
[Sun Aug 30 03:11:03.347638 2026] [security2:error] [pid 517995:tid 518242] [client 4.205.62.107:15814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/public/bnn_.php.php"] [unique_id "apPll7z-S0xMfHBNth6ZGQAAAX0"]
[Sun Aug 30 03:11:03.351519 2026] [security2:error] [pid 517995:tid 518147] [client 68.155.159.216:54289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/cong.php"] [unique_id "apPll7z-S0xMfHBNth6ZHAAAAR4"]
[Sun Aug 30 03:11:03.359677 2026] [authz_core:error] [pid 515259:tid 515444] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:03.360194 2026] [authz_core:error] [pid 515259:tid 515444] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:03.402219 2026] [security2:error] [pid 517995:tid 518120] [remote 103.156.21.26:46578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.21.156.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aholyambition.org"] [uri "/wp-login.php"] [unique_id "apPll7z-S0xMfHBNth6ZOgABXno"]
[Sun Aug 30 03:11:03.419962 2026] [security2:error] [pid 517995:tid 518197] [client 57.131.147.192:62123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.147.131.57.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ucdss.com"] [uri "/xmlrpc.php"] [unique_id "apPll7z-S0xMfHBNth6ZSAAAAVA"]
[Sun Aug 30 03:11:03.435464 2026] [security2:error] [pid 515259:tid 515465] [client 158.23.147.79:52224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/worksec.php"] [unique_id "apPll2ZcVaai59truiWelwAAAEs"]
[Sun Aug 30 03:11:03.465012 2026] [security2:error] [pid 518600:tid 518829] [client 158.23.184.117:7511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/termps.php"] [unique_id "apPll-349Tv4SB45P2nawwAAAOU"]
[Sun Aug 30 03:11:03.468946 2026] [security2:error] [pid 518600:tid 518661] [remote 168.63.79.147:46706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hebrews111.com"] [uri "/wp-login.php"] [unique_id "apPll-349Tv4SB45P2naxAAAsjk"], referer: https://hebrews111.com/wp-login.php
[Sun Aug 30 03:11:03.476905 2026] [security2:error] [pid 517995:tid 518220] [client 57.131.147.192:62135] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdsafetysystems.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "apPll7z-S0xMfHBNth6ZZwAAAWc"]
[Sun Aug 30 03:11:03.479665 2026] [security2:error] [pid 515259:tid 515404] [client 20.104.49.130:57664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/ioxi-o.php"] [unique_id "apPll2ZcVaai59truiWeqwAAAA4"]
[Sun Aug 30 03:11:03.486923 2026] [security2:error] [pid 518600:tid 518780] [client 52.139.37.240:44618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/ws37.php"] [unique_id "apPll-349Tv4SB45P2naxwAAALQ"]
[Sun Aug 30 03:11:03.493850 2026] [security2:error] [pid 517995:tid 518199] [client 20.63.219.114:13034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/composer.php"] [unique_id "apPll7z-S0xMfHBNth6ZcwAAAVI"]
[Sun Aug 30 03:11:03.496292 2026] [authz_core:error] [pid 518600:tid 518799] [client 216.73.216.128:48547] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:03.496714 2026] [authz_core:error] [pid 518600:tid 518799] [client 216.73.216.128:48547] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:03.510030 2026] [security2:error] [pid 518600:tid 518777] [client 20.48.160.90:28134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/ws85.php"] [unique_id "apPll-349Tv4SB45P2na1gAAALE"]
[Sun Aug 30 03:11:03.510581 2026] [security2:error] [pid 518600:tid 518779] [client 158.23.147.79:1936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apPll-349Tv4SB45P2na1wAAALM"]
[Sun Aug 30 03:11:03.517025 2026] [security2:error] [pid 515259:tid 515424] [client 68.155.159.216:12176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-includes/plugins.php"] [unique_id "apPll2ZcVaai59truiWeuAAAACI"]
[Sun Aug 30 03:11:03.532486 2026] [security2:error] [pid 515259:tid 515411] [client 20.63.81.20:59123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPll2ZcVaai59truiWevAAAABU"]
[Sun Aug 30 03:11:03.543925 2026] [authz_core:error] [pid 517995:tid 518147] [client 66.249.66.40:52038] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:03.544254 2026] [authz_core:error] [pid 517995:tid 518147] [client 66.249.66.40:52038] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:03.581454 2026] [security2:error] [pid 517995:tid 518220] [client 20.104.50.220:29321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-1.php"] [unique_id "apPll7z-S0xMfHBNth6ZpQAAAWc"]
[Sun Aug 30 03:11:03.589143 2026] [autoindex:error] [pid 518600:tid 518662] [remote 2a06:98c0:3600::103:0] AH01276: Cannot serve directory /home2/thorbyte/public_html/stillgelegt/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:11:03.599047 2026] [authz_core:error] [pid 518600:tid 518847] [client 216.73.216.128:60050] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:03.599531 2026] [authz_core:error] [pid 518600:tid 518847] [client 216.73.216.128:60050] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:03.626019 2026] [security2:error] [pid 518600:tid 518787] [client 158.23.184.117:7724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/fix.php"] [unique_id "apPll-349Tv4SB45P2nbRwAAALs"]
[Sun Aug 30 03:11:03.638505 2026] [security2:error] [pid 518600:tid 518784] [client 20.48.160.90:51854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/ffs.php"] [unique_id "apPll-349Tv4SB45P2nbTgAAALg"]
[Sun Aug 30 03:11:03.639163 2026] [security2:error] [pid 515259:tid 515406] [client 40.83.93.50:22121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/composer.php"] [unique_id "apPll2ZcVaai59truiWe3QAAABA"]
[Sun Aug 30 03:11:03.677116 2026] [security2:error] [pid 518600:tid 518743] [client 20.63.81.20:59106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPll-349Tv4SB45P2nbagAAAI8"]
[Sun Aug 30 03:11:03.702383 2026] [security2:error] [pid 518600:tid 518768] [client 52.139.37.240:43100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/new.php"] [unique_id "apPll-349Tv4SB45P2nbgQAAAKg"]
[Sun Aug 30 03:11:03.766073 2026] [security2:error] [pid 518600:tid 518827] [client 158.23.184.117:7488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/wp-includes/ID3/admin.php"] [unique_id "apPll-349Tv4SB45P2nbyQAAAOM"]
[Sun Aug 30 03:11:03.769906 2026] [authz_core:error] [pid 518600:tid 518751] [client 216.73.216.128:48547] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:03.770365 2026] [authz_core:error] [pid 518600:tid 518751] [client 216.73.216.128:48547] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:03.787809 2026] [security2:error] [pid 518600:tid 518855] [client 20.104.18.15:22501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/sign.php"] [unique_id "apPll-349Tv4SB45P2nb4QAAAP8"]
[Sun Aug 30 03:11:03.787998 2026] [security2:error] [pid 518600:tid 518810] [client 20.151.200.44:41893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPll-349Tv4SB45P2nb4wAAANI"]
[Sun Aug 30 03:11:03.792809 2026] [security2:error] [pid 518600:tid 518821] [client 20.104.49.130:52347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/xwx1.php"] [unique_id "apPll-349Tv4SB45P2nb6gAAAN0"]
[Sun Aug 30 03:11:03.795752 2026] [autoindex:error] [pid 518600:tid 518736] [client 57.131.147.192:0] AH01276: Cannot serve directory /home3/ucdsscom/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:11:03.802662 2026] [security2:error] [pid 518600:tid 518855] [client 20.63.81.20:59105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/ser.php"] [unique_id "apPll-349Tv4SB45P2nb9gAAAP8"]
[Sun Aug 30 03:11:03.803668 2026] [security2:error] [pid 518600:tid 518818] [client 20.48.160.90:28066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/nano.php"] [unique_id "apPll-349Tv4SB45P2nb-QAAANo"]
[Sun Aug 30 03:11:03.804346 2026] [security2:error] [pid 518600:tid 518813] [client 20.104.50.220:42241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-content/uploads/simple-file-list/fox.php"] [unique_id "apPll-349Tv4SB45P2nb-wAAANU"]
[Sun Aug 30 03:11:03.807897 2026] [security2:error] [pid 517995:tid 518002] [remote 103.156.21.26:46578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.21.156.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aholyambition.org"] [uri "/wp-login.php"] [unique_id "apPll7z-S0xMfHBNth6aHAABeQQ"], referer: https://aholyambition.org/wp-login.php
[Sun Aug 30 03:11:03.821859 2026] [security2:error] [pid 518600:tid 518768] [client 20.104.50.220:29607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/images.php"] [unique_id "apPll-349Tv4SB45P2ncDwAAAKg"]
[Sun Aug 30 03:11:03.850423 2026] [security2:error] [pid 518600:tid 518818] [client 158.23.147.79:61957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/x.php"] [unique_id "apPll-349Tv4SB45P2ncHAAAANo"]
[Sun Aug 30 03:11:03.859241 2026] [security2:error] [pid 518600:tid 518785] [client 68.155.159.216:46014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/ans.php"] [unique_id "apPll-349Tv4SB45P2ncJgAAALk"]
[Sun Aug 30 03:11:03.866389 2026] [authz_core:error] [pid 518600:tid 518772] [client 66.249.66.193:58620] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:03.866666 2026] [authz_core:error] [pid 518600:tid 518772] [client 66.249.66.193:58620] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:03.871102 2026] [security2:error] [pid 518600:tid 518791] [client 20.104.18.15:18369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/nofile.php"] [unique_id "apPll-349Tv4SB45P2ncKgAAAL8"]
[Sun Aug 30 03:11:03.881973 2026] [authz_core:error] [pid 515259:tid 515407] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:03.882419 2026] [authz_core:error] [pid 515259:tid 515407] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:03.894855 2026] [security2:error] [pid 518600:tid 518825] [client 20.104.50.220:31207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/abcd.php"] [unique_id "apPll-349Tv4SB45P2ncQgAAAOE"]
[Sun Aug 30 03:11:03.904827 2026] [security2:error] [pid 518600:tid 518851] [client 20.104.50.220:5896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/load.php"] [unique_id "apPll-349Tv4SB45P2ncSwAAAPs"]
[Sun Aug 30 03:11:03.907091 2026] [security2:error] [pid 518600:tid 518820] [client 158.23.184.117:7425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/tiny.php"] [unique_id "apPll-349Tv4SB45P2ncTAAAANw"]
[Sun Aug 30 03:11:03.908787 2026] [security2:error] [pid 518600:tid 518760] [client 20.63.219.114:2077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/abcd.php"] [unique_id "apPll-349Tv4SB45P2ncTQAAAKA"]
[Sun Aug 30 03:11:03.930772 2026] [security2:error] [pid 518600:tid 518770] [client 20.104.18.15:31726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/222.php"] [unique_id "apPll-349Tv4SB45P2ncVAAAAKo"]
[Sun Aug 30 03:11:03.931103 2026] [security2:error] [pid 518600:tid 518765] [client 20.104.50.220:33065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-content/uploads/simple-file-list/alfa.php"] [unique_id "apPll-349Tv4SB45P2ncWAAAAKU"]
[Sun Aug 30 03:11:03.931493 2026] [security2:error] [pid 518600:tid 518831] [client 20.48.251.3:54740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/brc.php"] [unique_id "apPll-349Tv4SB45P2ncWQAAAOc"]
[Sun Aug 30 03:11:03.933233 2026] [security2:error] [pid 518600:tid 518834] [client 20.63.81.20:59080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/431.php"] [unique_id "apPll-349Tv4SB45P2ncXAAAAOo"]
[Sun Aug 30 03:11:03.942422 2026] [security2:error] [pid 518600:tid 518739] [client 216.73.216.128:48547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_config_viewer_margin_left"] [unique_id "apPll-349Tv4SB45P2ncaAAAAIs"]
[Sun Aug 30 03:11:03.953461 2026] [qos:error] [pid 517995:tid 518164] [client 38.187.23.6:59257] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.187.23.6, id=apPll7z-S0xMfHBNth6aTAAAAS8
[Sun Aug 30 03:11:03.953696 2026] [qos:error] [pid 517995:tid 518210] [client 103.99.136.22:57848] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.99.136.22, id=apPll7z-S0xMfHBNth6aTQAAAV0
[Sun Aug 30 03:11:03.953908 2026] [qos:error] [pid 515259:tid 515406] [client 132.145.207.194:51110] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=132.145.207.194, id=apPll2ZcVaai59truiWfNwAAABA
[Sun Aug 30 03:11:03.954010 2026] [security2:error] [pid 518600:tid 518736] [client 20.104.50.220:17254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-admin/user/about.php"] [unique_id "apPll-349Tv4SB45P2ncbAAAAIg"]
[Sun Aug 30 03:11:03.954244 2026] [qos:error] [pid 515259:tid 515492] [client 221.223.18.76:46964] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=221.223.18.76, id=apPll2ZcVaai59truiWfOAAAAGY
[Sun Aug 30 03:11:03.954572 2026] [qos:error] [pid 517995:tid 518219] [client 103.51.205.108:40280] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.51.205.108, id=apPll7z-S0xMfHBNth6aTgAAAWY
[Sun Aug 30 03:11:03.955881 2026] [qos:error] [pid 517995:tid 518195] [client 103.9.148.198:54843] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.9.148.198, id=apPll7z-S0xMfHBNth6aTwAAAU4
[Sun Aug 30 03:11:03.968192 2026] [authz_core:error] [pid 515259:tid 515487] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:11:03.968658 2026] [authz_core:error] [pid 515259:tid 515487] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:11:03.993774 2026] [qos:error] [pid 518600:tid 518793] [client 154.18.255.135:48936] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=154.18.255.135, id=apPll-349Tv4SB45P2nciQAAAME
[Sun Aug 30 03:11:03.995280 2026] [qos:error] [pid 515259:tid 515439] [client 46.36.123.18:60406] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=46.36.123.18, id=apPll2ZcVaai59truiWfQwAAADE
[Sun Aug 30 03:11:03.999239 2026] [security2:error] [pid 518600:tid 518785] [client 20.48.160.90:51939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/ano.php"] [unique_id "apPll-349Tv4SB45P2ncjgAAALk"]
[Sun Aug 30 03:11:03.999441 2026] [qos:error] [pid 518600:tid 518749] [client 122.246.3.12:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPll-349Tv4SB45P2ncjwAAAJU
[Sun Aug 30 03:11:04.002667 2026] [qos:error] [pid 517995:tid 518184] [client 185.42.192.218:57783] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=185.42.192.218, id=apPlmLz-S0xMfHBNth6aWQAAAUM
[Sun Aug 30 03:11:04.002850 2026] [qos:error] [pid 518600:tid 518733] [client 109.203.202.140:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlmO349Tv4SB45P2nclwAAAIU
[Sun Aug 30 03:11:04.013383 2026] [qos:error] [pid 518600:tid 518843] [client 95.3.69.222:33203] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=95.3.69.222, id=apPlmO349Tv4SB45P2ncngAAAPM
[Sun Aug 30 03:11:04.013563 2026] [qos:error] [pid 515259:tid 515438] [client 181.39.25.196:40470] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=181.39.25.196, id=apPlmGZcVaai59truiWfRgAAADA
[Sun Aug 30 03:11:04.014190 2026] [qos:error] [pid 515259:tid 515514] [client 163.223.150.21:41786] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=163.223.150.21, id=apPlmGZcVaai59truiWfRwAAAHw
[Sun Aug 30 03:11:04.015429 2026] [qos:error] [pid 517995:tid 518225] [client 43.164.136.189:32990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=43.164.136.189, id=apPlmLz-S0xMfHBNth6aXwAAAWw
[Sun Aug 30 03:11:04.016494 2026] [qos:error] [pid 517995:tid 518233] [client 62.68.238.92:47882] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=62.68.238.92, id=apPlmLz-S0xMfHBNth6aYAAAAXQ
[Sun Aug 30 03:11:04.017525 2026] [security2:error] [pid 518600:tid 518831] [client 57.131.147.192:56940] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdss.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "apPlmO349Tv4SB45P2ncnwAAAOc"]
[Sun Aug 30 03:11:04.023048 2026] [qos:error] [pid 518600:tid 518749] [client 171.25.158.95:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlmO349Tv4SB45P2ncogAAAJU
[Sun Aug 30 03:11:04.025876 2026] [qos:error] [pid 515259:tid 515420] [client 126.209.13.194:33070] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=126.209.13.194, id=apPlmGZcVaai59truiWfSgAAAB4
[Sun Aug 30 03:11:04.026371 2026] [autoindex:error] [pid 518600:tid 518818] [client 52.139.37.240:44615] AH01276: Cannot serve directory /home3/ragtimec/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:11:04.027963 2026] [qos:error] [pid 515259:tid 515516] [client 157.10.105.57:47488] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=157.10.105.57, id=apPlmGZcVaai59truiWfTAAAAH4
[Sun Aug 30 03:11:04.027968 2026] [qos:error] [pid 515259:tid 515400] [client 192.145.124.230:31901] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=192.145.124.230, id=apPlmGZcVaai59truiWfSwAAAAo
[Sun Aug 30 03:11:04.029340 2026] [qos:error] [pid 517995:tid 518163] [client 103.126.107.244:58832] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.126.107.244, id=apPlmLz-S0xMfHBNth6aYQAAAS4
[Sun Aug 30 03:11:04.030290 2026] [qos:error] [pid 517995:tid 518192] [client 167.250.47.60:51776] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=167.250.47.60, id=apPlmLz-S0xMfHBNth6aYgAAAUs
[Sun Aug 30 03:11:04.030531 2026] [qos:error] [pid 515259:tid 515409] [client 107.148.2.104:39506] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=107.148.2.104, id=apPlmGZcVaai59truiWfTQAAABM
[Sun Aug 30 03:11:04.030702 2026] [qos:error] [pid 517995:tid 518247] [client 177.54.40.12:59420] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=177.54.40.12, id=apPlmLz-S0xMfHBNth6aYwAAAYI
[Sun Aug 30 03:11:04.032624 2026] [qos:error] [pid 515259:tid 515402] [client 182.23.46.118:48700] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=182.23.46.118, id=apPlmGZcVaai59truiWfTgAAAAw
[Sun Aug 30 03:11:04.033751 2026] [qos:error] [pid 518600:tid 518753] [client 159.223.52.199:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlmO349Tv4SB45P2ncpQAAAJk
[Sun Aug 30 03:11:04.034168 2026] [qos:error] [pid 515259:tid 515426] [client 187.108.236.70:33872] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=187.108.236.70, id=apPlmGZcVaai59truiWfTwAAACQ
[Sun Aug 30 03:11:04.034280 2026] [qos:error] [pid 517995:tid 518166] [client 203.115.123.163:39240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=203.115.123.163, id=apPlmLz-S0xMfHBNth6aZAAAATE
[Sun Aug 30 03:11:04.039152 2026] [qos:error] [pid 518600:tid 518835] [client 157.10.97.101:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlmO349Tv4SB45P2ncqAAAAOs
[Sun Aug 30 03:11:04.044771 2026] [qos:error] [pid 517995:tid 518229] [client 195.226.213.254:39326] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=195.226.213.254, id=apPlmLz-S0xMfHBNth6aaAAAAXA
[Sun Aug 30 03:11:04.045982 2026] [qos:error] [pid 515259:tid 515478] [client 213.21.57.244:51930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=213.21.57.244, id=apPlmGZcVaai59truiWfUwAAAFg
[Sun Aug 30 03:11:04.046442 2026] [qos:error] [pid 517995:tid 518214] [client 212.87.194.103:35176] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=212.87.194.103, id=apPlmLz-S0xMfHBNth6aaQAAAWE
[Sun Aug 30 03:11:04.046657 2026] [qos:error] [pid 518600:tid 518762] [client 43.132.189.30:54480] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=43.132.189.30, id=apPlmO349Tv4SB45P2ncswAAAKI
[Sun Aug 30 03:11:04.046874 2026] [security2:error] [pid 518600:tid 518765] [client 68.44.131.73:57696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.131.44.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/administrator/"] [unique_id "apPll-349Tv4SB45P2ncjAAAAKU"]
[Sun Aug 30 03:11:04.047535 2026] [qos:error] [pid 518600:tid 518848] [client 124.70.144.96:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlmO349Tv4SB45P2nctQAAAPg
[Sun Aug 30 03:11:04.048009 2026] [qos:error] [pid 517995:tid 518132] [client 190.97.35.249:42198] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=190.97.35.249, id=apPlmLz-S0xMfHBNth6aawAAAQ8
[Sun Aug 30 03:11:04.048573 2026] [qos:error] [pid 517995:tid 518203] [client 209.61.50.3:43212] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=209.61.50.3, id=apPlmLz-S0xMfHBNth6abAAAAVY
[Sun Aug 30 03:11:04.048817 2026] [qos:error] [pid 517995:tid 518145] [client 205.209.65.102:39328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=205.209.65.102, id=apPlmLz-S0xMfHBNth6abQAAARw
[Sun Aug 30 03:11:04.049126 2026] [qos:error] [pid 517995:tid 518154] [client 195.46.183.181:55875] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=195.46.183.181, id=apPlmLz-S0xMfHBNth6abgAAASU
[Sun Aug 30 03:11:04.050037 2026] [security2:error] [pid 518600:tid 518735] [client 158.23.184.117:7494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/css/classwithtostring.php"] [unique_id "apPlmO349Tv4SB45P2nctgAAAIc"]
[Sun Aug 30 03:11:04.050159 2026] [qos:error] [pid 517995:tid 518222] [client 45.172.226.48:50041] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.172.226.48, id=apPlmLz-S0xMfHBNth6abwAAAWk
[Sun Aug 30 03:11:04.050577 2026] [qos:error] [pid 517995:tid 518169] [client 203.91.118.210:58466] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=203.91.118.210, id=apPlmLz-S0xMfHBNth6acAAAATQ
[Sun Aug 30 03:11:04.051104 2026] [qos:error] [pid 515259:tid 515508] [client 41.72.199.106:60528] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=41.72.199.106, id=apPlmGZcVaai59truiWfVAAAAHY
[Sun Aug 30 03:11:04.055707 2026] [qos:error] [pid 515259:tid 515440] [client 117.2.121.198:33470] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=117.2.121.198, id=apPlmGZcVaai59truiWfVQAAADI
[Sun Aug 30 03:11:04.056024 2026] [qos:error] [pid 517995:tid 518137] [client 59.174.111.219:63894] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=59.174.111.219, id=apPlmLz-S0xMfHBNth6acQAAARQ
[Sun Aug 30 03:11:04.056404 2026] [qos:error] [pid 518600:tid 518785] [client 89.213.106.98:43899] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=89.213.106.98, id=apPlmO349Tv4SB45P2ncuQAAALk
[Sun Aug 30 03:11:04.058015 2026] [qos:error] [pid 518600:tid 518846] [client 110.74.195.34:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlmO349Tv4SB45P2ncugAAAPY
[Sun Aug 30 03:11:04.059130 2026] [qos:error] [pid 515259:tid 515394] [client 43.245.131.213:59940] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=43.245.131.213, id=apPlmGZcVaai59truiWfVgAAAAQ
[Sun Aug 30 03:11:04.059361 2026] [qos:error] [pid 515259:tid 515460] [client 179.225.55.3:48522] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=179.225.55.3, id=apPlmGZcVaai59truiWfVwAAAEY
[Sun Aug 30 03:11:04.060157 2026] [qos:error] [pid 518600:tid 518849] [client 186.33.20.139:36026] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=186.33.20.139, id=apPlmO349Tv4SB45P2ncvAAAAPk
[Sun Aug 30 03:11:04.061198 2026] [qos:error] [pid 515259:tid 515410] [client 123.25.252.5:47745] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=123.25.252.5, id=apPlmGZcVaai59truiWfWAAAABQ
[Sun Aug 30 03:11:04.062912 2026] [qos:error] [pid 515259:tid 515416] [client 190.100.200.3:52638] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=190.100.200.3, id=apPlmGZcVaai59truiWfWQAAABo
[Sun Aug 30 03:11:04.063740 2026] [qos:error] [pid 515259:tid 515489] [client 38.183.150.10:45370] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=38.183.150.10, id=apPlmGZcVaai59truiWfWgAAAGM
[Sun Aug 30 03:11:04.065201 2026] [qos:error] [pid 515259:tid 515507] [client 181.13.210.60:46502] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=181.13.210.60, id=apPlmGZcVaai59truiWfWwAAAHU
[Sun Aug 30 03:11:04.066860 2026] [qos:error] [pid 515259:tid 515417] [client 122.246.4.6:38007] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=122.246.4.6, id=apPlmGZcVaai59truiWfXAAAABs
[Sun Aug 30 03:11:04.068181 2026] [security2:error] [pid 518600:tid 518778] [client 4.205.62.107:36667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/rpk.php"] [unique_id "apPlmO349Tv4SB45P2ncvQAAALI"]
[Sun Aug 30 03:11:04.068336 2026] [qos:error] [pid 518600:tid 518843] [client 103.13.235.18:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlmO349Tv4SB45P2ncvwAAAPM
[Sun Aug 30 03:11:04.068370 2026] [security2:error] [pid 518600:tid 518818] [client 20.63.81.20:59017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/rxr.php"] [unique_id "apPlmO349Tv4SB45P2ncwAAAANo"]
[Sun Aug 30 03:11:04.103224 2026] [security2:error] [pid 518600:tid 518804] [client 52.139.37.240:44615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/il.php"] [unique_id "apPlmO349Tv4SB45P2nc4QAAAMw"]
[Sun Aug 30 03:11:04.114607 2026] [qos:error] [pid 515259:tid 515425] [client 72.62.59.63:40002] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=72.62.59.63, id=apPlmGZcVaai59truiWfagAAACM
[Sun Aug 30 03:11:04.115033 2026] [qos:error] [pid 515259:tid 515422] [client 181.224.175.206:33908] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=181.224.175.206, id=apPlmGZcVaai59truiWfawAAACA
[Sun Aug 30 03:11:04.115125 2026] [qos:error] [pid 518600:tid 518757] [client 220.158.232.118:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlmO349Tv4SB45P2nc-AAAAJ0
[Sun Aug 30 03:11:04.115225 2026] [qos:error] [pid 518600:tid 518785] [client 1.53.159.155:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlmO349Tv4SB45P2nc-QAAALk
[Sun Aug 30 03:11:04.115332 2026] [qos:error] [pid 518600:tid 518799] [client 187.77.24.67:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlmO349Tv4SB45P2nc-gAAAMc
[Sun Aug 30 03:11:04.115391 2026] [qos:error] [pid 518600:tid 518754] [client 5.253.196.143:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlmO349Tv4SB45P2nc-wAAAJo
[Sun Aug 30 03:11:04.115999 2026] [qos:error] [pid 517995:tid 518239] [client 67.207.92.87:44664] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=67.207.92.87, id=apPlmLz-S0xMfHBNth6afgAAAXo
[Sun Aug 30 03:11:04.116206 2026] [qos:error] [pid 517995:tid 518249] [client 139.59.77.170:41404] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=139.59.77.170, id=apPlmLz-S0xMfHBNth6afwAAAYQ
[Sun Aug 30 03:11:04.116538 2026] [qos:error] [pid 517995:tid 518239] [client 67.207.92.87:44664] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=67.207.92.87, id=apPlmLz-S0xMfHBNth6agAAAAXo
[Sun Aug 30 03:11:04.116976 2026] [qos:error] [pid 515259:tid 515482] [client 200.30.130.50:54812] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=200.30.130.50, id=apPlmGZcVaai59truiWfbAAAAFw
[Sun Aug 30 03:11:04.117047 2026] [qos:error] [pid 517995:tid 518178] [client 102.211.146.31:48648] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=102.211.146.31, id=apPlmLz-S0xMfHBNth6agQAAAT0
[Sun Aug 30 03:11:04.119243 2026] [security2:error] [pid 518600:tid 518859] [client 40.83.93.50:6551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/abcd.php"] [unique_id "apPlmO349Tv4SB45P2nc_QAAAQM"]
[Sun Aug 30 03:11:04.119562 2026] [qos:error] [pid 517995:tid 518220] [client 180.148.25.78:38821] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=180.148.25.78, id=apPlmLz-S0xMfHBNth6agwAAAWc
[Sun Aug 30 03:11:04.119761 2026] [qos:error] [pid 518600:tid 518857] [client 103.249.18.148:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlmO349Tv4SB45P2nc_gAAAQE
[Sun Aug 30 03:11:04.122112 2026] [qos:error] [pid 518600:tid 518739] [client 190.14.147.19:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlmO349Tv4SB45P2nc_wAAAIs
[Sun Aug 30 03:11:04.123063 2026] [qos:error] [pid 517995:tid 518212] [client 154.27.203.36:60817] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=154.27.203.36, id=apPlmLz-S0xMfHBNth6ahQAAAV8
[Sun Aug 30 03:11:04.123443 2026] [qos:error] [pid 517995:tid 518230] [client 103.86.117.27:44562] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.86.117.27, id=apPlmLz-S0xMfHBNth6ahgAAAXE
[Sun Aug 30 03:11:04.124926 2026] [qos:error] [pid 517995:tid 518216] [client 210.16.85.42:38592] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=210.16.85.42, id=apPlmLz-S0xMfHBNth6ahwAAAWM
[Sun Aug 30 03:11:04.125461 2026] [qos:error] [pid 515259:tid 515442] [client 149.28.251.187:52052] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=149.28.251.187, id=apPlmGZcVaai59truiWfbQAAADQ
[Sun Aug 30 03:11:04.126295 2026] [qos:error] [pid 518600:tid 518784] [client 45.198.32.229:49818] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=45.198.32.229, id=apPlmO349Tv4SB45P2ndAwAAALg
[Sun Aug 30 03:11:04.126333 2026] [qos:error] [pid 517995:tid 518136] [client 150.107.105.129:49816] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=150.107.105.129, id=apPlmLz-S0xMfHBNth6aiAAAARM
[Sun Aug 30 03:11:04.130861 2026] [qos:error] [pid 515259:tid 515474] [client 82.114.228.67:56822] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=82.114.228.67, id=apPlmGZcVaai59truiWfbgAAAFQ
[Sun Aug 30 03:11:04.131396 2026] [qos:error] [pid 515259:tid 515480] [client 2.144.6.41:59602] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=2.144.6.41, id=apPlmGZcVaai59truiWfbwAAAFo
[Sun Aug 30 03:11:04.132328 2026] [security2:error] [pid 518600:tid 518850] [client 20.48.160.90:43608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/mgrr.php"] [unique_id "apPlmO349Tv4SB45P2ndBwAAAPo"]
[Sun Aug 30 03:11:04.132526 2026] [qos:error] [pid 518600:tid 518825] [client 109.224.242.6:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlmO349Tv4SB45P2ndBgAAAOE
[Sun Aug 30 03:11:04.132549 2026] [security2:error] [pid 518600:tid 518808] [client 20.48.251.3:37157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlmO349Tv4SB45P2ndCAAAANA"]
[Sun Aug 30 03:11:04.134190 2026] [qos:error] [pid 517995:tid 518186] [client 85.60.193.47:49096] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=85.60.193.47, id=apPlmLz-S0xMfHBNth6aiQAAAUU
[Sun Aug 30 03:11:04.136500 2026] [qos:error] [pid 517995:tid 518164] [client 103.217.216.65:48348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=103.217.216.65, id=apPlmLz-S0xMfHBNth6aigAAAS8
[Sun Aug 30 03:11:04.136986 2026] [qos:error] [pid 515259:tid 515459] [client 37.150.97.11:51900] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=37.150.97.11, id=apPlmGZcVaai59truiWfcQAAAEU
[Sun Aug 30 03:11:04.137039 2026] [qos:error] [pid 518600:tid 518855] [client 146.70.137.34:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.92.44, id=apPlmO349Tv4SB45P2ndDQAAAP8
[Sun Aug 30 03:11:04.137126 2026] [qos:error] [pid 518600:tid 518740] [client 103.238.232.114:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlmO349Tv4SB45P2ndDAAAAIw
[Sun Aug 30 03:11:04.148098 2026] [qos:error] [pid 518600:tid 518786] [client 176.111.37.216:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlmO349Tv4SB45P2ndIQAAALo
[Sun Aug 30 03:11:04.148373 2026] [qos:error] [pid 518600:tid 518855] [client 38.45.67.95:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.92.44, id=apPlmO349Tv4SB45P2ndIwAAAP8
[Sun Aug 30 03:11:04.148474 2026] [qos:error] [pid 515259:tid 515437] [client 112.203.223.79:56718] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=112.203.223.79, id=apPlmGZcVaai59truiWfdQAAAC8
[Sun Aug 30 03:11:04.158920 2026] [security2:error] [pid 518600:tid 518738] [client 4.205.62.107:17324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/sdsa.php"] [unique_id "apPlmO349Tv4SB45P2ndOgAAAIo"]
[Sun Aug 30 03:11:04.161318 2026] [security2:error] [pid 518600:tid 518805] [client 158.23.147.79:58381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/content.php"] [unique_id "apPlmO349Tv4SB45P2ndQgAAAM0"]
[Sun Aug 30 03:11:04.177318 2026] [security2:error] [pid 518600:tid 518816] [client 158.23.147.79:57677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPlmO349Tv4SB45P2ndVQAAANg"]
[Sun Aug 30 03:11:04.187364 2026] [security2:error] [pid 518600:tid 518813] [client 57.131.147.192:65432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.147.131.57.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ucdsafetysystems.com"] [uri "/xmlrpc.php"] [unique_id "apPlmO349Tv4SB45P2ndcAAAANU"]
[Sun Aug 30 03:11:04.191293 2026] [security2:error] [pid 518600:tid 518803] [client 158.23.184.117:7713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/buy.php"] [unique_id "apPlmO349Tv4SB45P2ndegAAAMs"]
[Sun Aug 30 03:11:04.199171 2026] [security2:error] [pid 518600:tid 518813] [client 20.63.81.20:59019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/csst.php"] [unique_id "apPlmO349Tv4SB45P2ndigAAANU"]
[Sun Aug 30 03:11:04.229336 2026] [security2:error] [pid 518600:tid 518816] [client 4.205.62.107:26982] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/wp-includes/js/tinymce/themes/inlite"] [unique_id "apPlmO349Tv4SB45P2nd1wAAANg"]
[Sun Aug 30 03:11:04.241751 2026] [security2:error] [pid 518600:tid 518852] [client 20.48.251.3:59389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/public/mah.php.php"] [unique_id "apPlmO349Tv4SB45P2nd7AAAAPw"]
[Sun Aug 30 03:11:04.297753 2026] [core:alert] [pid 517995:tid 518232] [client 85.235.85.127:37686] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:11:04.311506 2026] [security2:error] [pid 518600:tid 518846] [client 20.63.219.114:14752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/sf.php"] [unique_id "apPlmO349Tv4SB45P2neVwAAAPY"]
[Sun Aug 30 03:11:04.319087 2026] [security2:error] [pid 518600:tid 518826] [client 20.48.160.90:51950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/mac.php"] [unique_id "apPlmO349Tv4SB45P2neYwAAAOI"]
[Sun Aug 30 03:11:04.320694 2026] [security2:error] [pid 518600:tid 518840] [client 52.139.37.240:13863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/images/index.php"] [unique_id "apPlmO349Tv4SB45P2neVgAAAPA"]
[Sun Aug 30 03:11:04.331024 2026] [security2:error] [pid 518600:tid 518834] [client 20.63.81.20:59079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp-includes/blocks/query-title/footer.php"] [unique_id "apPlmO349Tv4SB45P2neeQAAAOo"]
[Sun Aug 30 03:11:04.332875 2026] [security2:error] [pid 517995:tid 518185] [client 158.23.184.117:7518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/bk.php"] [unique_id "apPlmLz-S0xMfHBNth6a3AAAAUQ"]
[Sun Aug 30 03:11:04.336455 2026] [security2:error] [pid 517995:tid 518134] [client 57.131.147.192:50516] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdss.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "apPlmLz-S0xMfHBNth6a3QAAARE"]
[Sun Aug 30 03:11:04.344369 2026] [authz_core:error] [pid 518600:tid 518753] [client 66.249.66.205:36848] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:04.344995 2026] [authz_core:error] [pid 518600:tid 518753] [client 66.249.66.205:36848] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:04.365802 2026] [authz_core:error] [pid 515259:tid 515418] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:04.366208 2026] [authz_core:error] [pid 515259:tid 515418] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:04.385724 2026] [security2:error] [pid 518600:tid 518738] [client 158.23.147.79:61975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/x.php"] [unique_id "apPlmO349Tv4SB45P2nesAAAAIo"]
[Sun Aug 30 03:11:04.430000 2026] [security2:error] [pid 518600:tid 518852] [client 20.48.251.3:59889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/sale.php"] [unique_id "apPlmO349Tv4SB45P2ne4gAAAPw"]
[Sun Aug 30 03:11:04.431632 2026] [security2:error] [pid 518600:tid 518793] [client 20.104.18.15:16945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/inx.php"] [unique_id "apPlmO349Tv4SB45P2ne5gAAAME"]
[Sun Aug 30 03:11:04.451429 2026] [security2:error] [pid 517995:tid 518129] [client 20.104.50.220:61400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-pluging.php"] [unique_id "apPlmLz-S0xMfHBNth6bMQAAAQw"]
[Sun Aug 30 03:11:04.462864 2026] [security2:error] [pid 518600:tid 518771] [client 20.63.81.20:59107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp-content/uploads/indoex.php"] [unique_id "apPlmO349Tv4SB45P2ne-AAAAKs"]
[Sun Aug 30 03:11:04.466787 2026] [lsapi:error] [pid 518600:tid 518666] [remote 149.143.159.250:33038] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:11:04.466938 2026] [lsapi:error] [pid 518600:tid 518666] [remote 149.143.159.250:33038] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:11:04.468479 2026] [lsapi:error] [pid 518600:tid 518666] [remote 149.143.159.250:33038] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:11:04.476461 2026] [security2:error] [pid 518600:tid 518775] [client 20.48.160.90:51906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/simple.php"] [unique_id "apPlmO349Tv4SB45P2ne_AAAAK8"]
[Sun Aug 30 03:11:04.478072 2026] [http2:info] [pid 519566:tid 519566] h2_workers: created with min=128 max=192 idle_ms=600000
[Sun Aug 30 03:11:04.491826 2026] [security2:error] [pid 518600:tid 518744] [client 158.23.184.117:7692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/.trash7309/index.php"] [unique_id "apPlmO349Tv4SB45P2ne_wAAAJA"]
[Sun Aug 30 03:11:04.501501 2026] [security2:error] [pid 519566:tid 519697] [client 4.205.62.107:16351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/wsws.php"] [unique_id "apPlmNKCPt8cS-VWcMmHXgAAA6Q"]
[Sun Aug 30 03:11:04.524484 2026] [security2:error] [pid 517995:tid 518245] [client 52.139.37.240:43121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/lite.php"] [unique_id "apPlmLz-S0xMfHBNth6bUQAAAYA"]
[Sun Aug 30 03:11:04.538845 2026] [security2:error] [pid 515259:tid 515420] [client 20.104.49.130:26881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/100.php"] [unique_id "apPlmGZcVaai59truiWf5gAAAB4"]
[Sun Aug 30 03:11:04.564224 2026] [security2:error] [pid 519566:tid 519736] [client 68.44.131.73:57699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.131.44.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/administrator/index.php"] [unique_id "apPlmNKCPt8cS-VWcMmHdQAAA8s"]
[Sun Aug 30 03:11:04.591881 2026] [security2:error] [pid 515259:tid 515486] [client 20.63.81.20:59125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPlmGZcVaai59truiWf-wAAAGA"]
[Sun Aug 30 03:11:04.594479 2026] [security2:error] [pid 519566:tid 519756] [client 68.155.159.216:54274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-includes/js/index.php"] [unique_id "apPlmNKCPt8cS-VWcMmHfgAAA98"]
[Sun Aug 30 03:11:04.598973 2026] [authz_core:error] [pid 517995:tid 518136] [client 66.249.66.74:49925] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:04.599279 2026] [authz_core:error] [pid 517995:tid 518136] [client 66.249.66.74:49925] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:04.605230 2026] [security2:error] [pid 517995:tid 518137] [client 40.83.93.50:6368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/sf.php"] [unique_id "apPlmLz-S0xMfHBNth6brwAAARQ"]
[Sun Aug 30 03:11:04.612987 2026] [security2:error] [pid 518600:tid 518792] [client 40.83.93.50:22091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/aaa.php"] [unique_id "apPlmO349Tv4SB45P2nfOAAAAMA"]
[Sun Aug 30 03:11:04.619505 2026] [security2:error] [pid 517995:tid 518179] [client 20.48.160.90:28139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/xty.php"] [unique_id "apPlmLz-S0xMfHBNth6bvgAAAT4"]
[Sun Aug 30 03:11:04.634205 2026] [security2:error] [pid 517995:tid 518204] [client 158.23.184.117:7527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/jp.php"] [unique_id "apPlmLz-S0xMfHBNth6bywAAAVc"]
[Sun Aug 30 03:11:04.662394 2026] [authz_core:error] [pid 519566:tid 519764] [client 66.249.66.203:58948] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:04.662666 2026] [authz_core:error] [pid 519566:tid 519764] [client 66.249.66.203:58948] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:04.665288 2026] [security2:error] [pid 518600:tid 518821] [client 20.63.219.114:2924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/gel4y.php"] [unique_id "apPlmO349Tv4SB45P2nfPwAAAN0"]
[Sun Aug 30 03:11:04.676402 2026] [security2:error] [pid 517995:tid 518155] [client 20.104.49.130:59552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/sta.php"] [unique_id "apPlmLz-S0xMfHBNth6b8QAAASY"]
[Sun Aug 30 03:11:04.677751 2026] [security2:error] [pid 517995:tid 518245] [client 57.131.147.192:52611] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdss.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "apPlmLz-S0xMfHBNth6b9gAAAYA"]
[Sun Aug 30 03:11:04.720775 2026] [security2:error] [pid 518600:tid 518841] [client 20.104.50.220:29155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/xindex.php"] [unique_id "apPlmO349Tv4SB45P2nfSwAAAPE"]
[Sun Aug 30 03:11:04.729803 2026] [security2:error] [pid 519566:tid 519707] [client 20.63.81.20:59078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/haxor.php"] [unique_id "apPlmNKCPt8cS-VWcMmHwQAAA64"]
[Sun Aug 30 03:11:04.732084 2026] [security2:error] [pid 519566:tid 519776] [client 68.155.159.216:57031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apPlmNKCPt8cS-VWcMmHxAAAA_M"]
[Sun Aug 30 03:11:04.742028 2026] [security2:error] [pid 517995:tid 518224] [client 158.23.147.79:2006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/ans.php"] [unique_id "apPlmLz-S0xMfHBNth6cKQAAAWs"]
[Sun Aug 30 03:11:04.747856 2026] [security2:error] [pid 519566:tid 519815] [client 52.139.37.240:13853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/xda.php"] [unique_id "apPlmNKCPt8cS-VWcMmH0AAABBo"]
[Sun Aug 30 03:11:04.758225 2026] [security2:error] [pid 519566:tid 519810] [client 20.48.160.90:51856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/sallu.php"] [unique_id "apPlmNKCPt8cS-VWcMmH1gAABBU"]
[Sun Aug 30 03:11:04.776119 2026] [security2:error] [pid 519566:tid 519770] [client 158.23.184.117:7536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/item.php"] [unique_id "apPlmNKCPt8cS-VWcMmH3QAAA-0"]
[Sun Aug 30 03:11:04.803046 2026] [security2:error] [pid 519566:tid 519814] [client 158.23.147.79:61995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPlmNKCPt8cS-VWcMmH4wAABBk"]
[Sun Aug 30 03:11:04.817112 2026] [security2:error] [pid 519566:tid 519762] [client 40.83.93.50:6394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/atomlib.php"] [unique_id "apPlmNKCPt8cS-VWcMmH6AAAA-U"]
[Sun Aug 30 03:11:04.844125 2026] [authz_core:error] [pid 519566:tid 519708] [client 66.249.66.204:45331] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:04.844569 2026] [authz_core:error] [pid 519566:tid 519708] [client 66.249.66.204:45331] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:04.846287 2026] [authz_core:error] [pid 515259:tid 515474] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:04.846614 2026] [authz_core:error] [pid 515259:tid 515474] [client 74.7.243.204:36882] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:04.855858 2026] [security2:error] [pid 518600:tid 518772] [client 20.63.81.20:59099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/google.php"] [unique_id "apPlmO349Tv4SB45P2nffgAAAKw"]
[Sun Aug 30 03:11:04.892979 2026] [security2:error] [pid 519566:tid 519696] [client 20.48.160.90:28092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/codex.php"] [unique_id "apPlmNKCPt8cS-VWcMmIIAAAA6M"]
[Sun Aug 30 03:11:04.897184 2026] [security2:error] [pid 518600:tid 518738] [client 158.23.147.79:58407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPlmO349Tv4SB45P2nfoQAAAIo"]
[Sun Aug 30 03:11:04.917381 2026] [security2:error] [pid 518600:tid 518790] [client 158.23.184.117:7455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/wp-admin/controller.php"] [unique_id "apPlmO349Tv4SB45P2nftQAAAL4"]
[Sun Aug 30 03:11:04.919651 2026] [security2:error] [pid 517995:tid 518148] [client 20.104.49.130:54202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/about.php"] [unique_id "apPlmLz-S0xMfHBNth6cjgAAAR8"]
[Sun Aug 30 03:11:04.942235 2026] [security2:error] [pid 517995:tid 518169] [client 20.104.50.220:51564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-content/uploads/simple-file-list/fw.php"] [unique_id "apPlmLz-S0xMfHBNth6cqwAAATQ"]
[Sun Aug 30 03:11:04.965788 2026] [security2:error] [pid 519566:tid 519796] [client 52.139.37.240:13846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/.trash7206/index.php"] [unique_id "apPlmNKCPt8cS-VWcMmISAAABAc"]
[Sun Aug 30 03:11:04.976381 2026] [security2:error] [pid 519566:tid 519717] [client 20.104.50.220:28710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/htdocs.php"] [unique_id "apPlmNKCPt8cS-VWcMmITgAAA7g"]
[Sun Aug 30 03:11:04.995581 2026] [security2:error] [pid 515259:tid 515446] [client 20.63.81.20:59113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "apPlmGZcVaai59truiWgjwAAADg"]
[Sun Aug 30 03:11:05.013417 2026] [security2:error] [pid 517995:tid 518195] [client 20.104.18.15:18377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/run.php"] [unique_id "apPlmbz-S0xMfHBNth6c4gAAAU4"]
[Sun Aug 30 03:11:05.017179 2026] [security2:error] [pid 517995:tid 518209] [client 57.131.147.192:49256] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdss.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "apPlmbz-S0xMfHBNth6c5QAAAVw"]
[Sun Aug 30 03:11:05.019084 2026] [security2:error] [pid 519566:tid 519753] [client 20.104.18.15:22493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/wnnjpsby.php"] [unique_id "apPlmdKCPt8cS-VWcMmIWgAAA9w"]
[Sun Aug 30 03:11:05.024152 2026] [security2:error] [pid 518600:tid 518776] [client 20.48.160.90:28049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/5656.php"] [unique_id "apPlme349Tv4SB45P2nf1QAAALA"]
[Sun Aug 30 03:11:05.039013 2026] [security2:error] [pid 515259:tid 515422] [client 20.104.50.220:6140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/options.php"] [unique_id "apPlmWZcVaai59truiWgowAAACA"]
[Sun Aug 30 03:11:05.045334 2026] [core:alert] [pid 518600:tid 518860] [client 188.167.253.49:65398] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:11:05.047121 2026] [security2:error] [pid 517995:tid 518188] [client 20.104.50.220:31172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/a1.php"] [unique_id "apPlmbz-S0xMfHBNth6dCAAAAUc"]
[Sun Aug 30 03:11:05.070783 2026] [security2:error] [pid 519566:tid 519697] [client 20.48.251.3:64283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/vx.php"] [unique_id "apPlmdKCPt8cS-VWcMmIbAAAA6Q"]
[Sun Aug 30 03:11:05.073814 2026] [security2:error] [pid 515259:tid 515450] [client 20.104.50.220:33152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/Ninja.php"] [unique_id "apPlmWZcVaai59truiWgvAAAADw"]
[Sun Aug 30 03:11:05.080604 2026] [security2:error] [pid 517995:tid 518197] [client 68.44.131.73:57700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.131.44.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/wp-login.php"] [unique_id "apPlmbz-S0xMfHBNth6dJAAAAVA"]
[Sun Aug 30 03:11:05.103900 2026] [security2:error] [pid 517995:tid 518130] [client 20.104.50.220:16721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPlmbz-S0xMfHBNth6dOgAAAQ0"]
[Sun Aug 30 03:11:05.109595 2026] [security2:error] [pid 517995:tid 518251] [client 158.23.184.117:7503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/wp-configs.php"] [unique_id "apPlmbz-S0xMfHBNth6dRAAAAYY"]
[Sun Aug 30 03:11:05.110509 2026] [security2:error] [pid 517995:tid 518232] [client 40.83.93.50:6365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/gel4y.php"] [unique_id "apPlmbz-S0xMfHBNth6dRQAAAXM"]
[Sun Aug 30 03:11:05.127043 2026] [security2:error] [pid 517995:tid 518222] [client 20.63.81.20:59090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/robots.php"] [unique_id "apPlmbz-S0xMfHBNth6dWgAAAWk"]
[Sun Aug 30 03:11:05.139056 2026] [security2:error] [pid 519566:tid 519738] [client 20.104.18.15:31717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/key.php"] [unique_id "apPlmdKCPt8cS-VWcMmIkAAAA80"]
[Sun Aug 30 03:11:05.151322 2026] [security2:error] [pid 517995:tid 518132] [client 20.63.219.114:19181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/leaf.php"] [unique_id "apPlmbz-S0xMfHBNth6ddQAAAQ8"]
[Sun Aug 30 03:11:05.159101 2026] [security2:error] [pid 517995:tid 518241] [client 20.48.160.90:51947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/w3lls.php"] [unique_id "apPlmbz-S0xMfHBNth6dgQAAAXw"]
[Sun Aug 30 03:11:05.170163 2026] [security2:error] [pid 519566:tid 519808] [client 52.139.37.240:44605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/storage/index.php"] [unique_id "apPlmdKCPt8cS-VWcMmIlwAABBM"]
[Sun Aug 30 03:11:05.200584 2026] [security2:error] [pid 518600:tid 518748] [client 20.104.49.130:60955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/wp-css.php"] [unique_id "apPlme349Tv4SB45P2ngDQAAAJQ"]
[Sun Aug 30 03:11:05.235161 2026] [security2:error] [pid 515259:tid 515474] [client 4.205.62.107:36559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/saml.php"] [unique_id "apPlmWZcVaai59truiWhIQAAAFQ"]
[Sun Aug 30 03:11:05.238597 2026] [security2:error] [pid 517995:tid 518227] [client 4.205.62.107:52923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlmbz-S0xMfHBNth6dugAAAW4"]
[Sun Aug 30 03:11:05.245994 2026] [authz_core:error] [pid 515259:tid 515399] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:11:05.246270 2026] [authz_core:error] [pid 515259:tid 515399] [client 74.7.227.8:56986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:11:05.246390 2026] [security2:error] [pid 515259:tid 515393] [client 158.23.184.117:7507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/wp-admin/user/credits.php"] [unique_id "apPlmWZcVaai59truiWhJwAAAAM"]
[Sun Aug 30 03:11:05.251522 2026] [security2:error] [pid 515259:tid 515418] [client 68.155.159.216:45973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/worksec.php"] [unique_id "apPlmWZcVaai59truiWhLAAAABw"]
[Sun Aug 30 03:11:05.252706 2026] [security2:error] [pid 517995:tid 518242] [client 195.178.110.247:24748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mieloma.eu"] [uri "/index.php"] [unique_id "apPlmbz-S0xMfHBNth6dxwAAAX0"]
[Sun Aug 30 03:11:05.253455 2026] [security2:error] [pid 515259:tid 515422] [client 20.63.81.20:59028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp-content/plugins/ccx/index.php"] [unique_id "apPlmWZcVaai59truiWhLQAAACA"]
[Sun Aug 30 03:11:05.254953 2026] [authz_core:error] [pid 518600:tid 518835] [client 216.73.216.128:43907] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:05.255376 2026] [authz_core:error] [pid 518600:tid 518835] [client 216.73.216.128:43907] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:05.272284 2026] [security2:error] [pid 518600:tid 518759] [client 20.48.251.3:37150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/cloud.php"] [unique_id "apPlme349Tv4SB45P2ngHQAAAJ8"]
[Sun Aug 30 03:11:05.296485 2026] [security2:error] [pid 517995:tid 518214] [client 4.205.62.107:17111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/sale.php"] [unique_id "apPlmbz-S0xMfHBNth6d8QAAAWE"]
[Sun Aug 30 03:11:05.309278 2026] [security2:error] [pid 519566:tid 519752] [client 20.48.160.90:46566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/fpwch.php"] [unique_id "apPlmdKCPt8cS-VWcMmIuwAAA9s"]
[Sun Aug 30 03:11:05.316073 2026] [security2:error] [pid 517995:tid 518154] [client 158.23.147.79:2031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/worksec.php"] [unique_id "apPlmbz-S0xMfHBNth6d_AAAASU"]
[Sun Aug 30 03:11:05.316462 2026] [security2:error] [pid 517995:tid 518129] [client 20.104.49.130:63546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/well.php"] [unique_id "apPlmbz-S0xMfHBNth6d_QAAAQw"]
[Sun Aug 30 03:11:05.353058 2026] [security2:error] [pid 519566:tid 519806] [client 57.131.147.192:49186] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdss.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "apPlmdKCPt8cS-VWcMmIvwAABBE"]
[Sun Aug 30 03:11:05.358939 2026] [security2:error] [pid 519566:tid 519801] [client 40.83.93.50:6377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/buy.php"] [unique_id "apPlmdKCPt8cS-VWcMmIwAAABAw"]
[Sun Aug 30 03:11:05.366954 2026] [security2:error] [pid 518600:tid 518733] [client 4.205.62.107:25501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/doc.php"] [unique_id "apPlme349Tv4SB45P2ngOQAAAIU"]
[Sun Aug 30 03:11:05.368505 2026] [security2:error] [pid 517995:tid 518167] [client 52.139.37.240:14044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPlmbz-S0xMfHBNth6eFgAAATI"]
[Sun Aug 30 03:11:05.375391 2026] [security2:error] [pid 519566:tid 519796] [client 20.48.251.3:59338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/zaza.php"] [unique_id "apPlmdKCPt8cS-VWcMmIxAAABAc"]
[Sun Aug 30 03:11:05.390037 2026] [security2:error] [pid 518600:tid 518810] [client 158.23.184.117:7529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "apPlme349Tv4SB45P2ngSAAAANI"]
[Sun Aug 30 03:11:05.392416 2026] [security2:error] [pid 518600:tid 518754] [client 158.23.147.79:43890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/log-mama/function.php"] [unique_id "apPlme349Tv4SB45P2ngSQAAAJo"]
[Sun Aug 30 03:11:05.394894 2026] [authz_core:error] [pid 517995:tid 518132] [client 74.7.243.204:59484] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:05.395414 2026] [authz_core:error] [pid 517995:tid 518132] [client 74.7.243.204:59484] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:05.397793 2026] [security2:error] [pid 517995:tid 518229] [client 20.63.81.20:59067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp-admin/css/colors/maro.php"] [unique_id "apPlmbz-S0xMfHBNth6eLgAAAXA"]
[Sun Aug 30 03:11:05.416617 2026] [security2:error] [pid 517995:tid 518228] [client 195.178.110.247:27856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mieloma.eu"] [uri "/index.php"] [unique_id "apPlmbz-S0xMfHBNth6eNgAAAW8"]
[Sun Aug 30 03:11:05.487981 2026] [security2:error] [pid 519566:tid 519815] [client 20.48.160.90:28105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/domvf.php"] [unique_id "apPlmdKCPt8cS-VWcMmI4wAABBo"]
[Sun Aug 30 03:11:05.497021 2026] [authz_core:error] [pid 517995:tid 518147] [client 66.249.66.40:52038] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:05.497282 2026] [authz_core:error] [pid 517995:tid 518147] [client 66.249.66.40:52038] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:05.504030 2026] [security2:error] [pid 518600:tid 518859] [client 20.104.49.130:63294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/bdroot.php"] [unique_id "apPlme349Tv4SB45P2ngWQAAAQM"]
[Sun Aug 30 03:11:05.529586 2026] [security2:error] [pid 517995:tid 518201] [client 158.23.184.117:7521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/.well-known/about/function.php"] [unique_id "apPlmbz-S0xMfHBNth6eZgAAAVQ"]
[Sun Aug 30 03:11:05.535870 2026] [security2:error] [pid 517995:tid 518133] [client 20.63.81.20:59096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp-admin/css/colors/coffee/marijuana.php"] [unique_id "apPlmbz-S0xMfHBNth6eawAAARA"]
[Sun Aug 30 03:11:05.545109 2026] [lsapi:warn] [pid 519566:tid 519783] [client 148.153.56.62:0] [host 162.144.0.169] Backend log: PHP Warning: PHP Request Shutdown: Cannot call session save handler in a recursive manner in Unknown on line 0\n
[Sun Aug 30 03:11:05.545132 2026] [lsapi:warn] [pid 519566:tid 519783] [client 148.153.56.62:0] [host 162.144.0.169] Backend log: PHP Warning: PHP Request Shutdown: Failed to write session data using user defined save handler. (session.save_path: /var/cpanel/php/sessions/ea-php83, handler: write) in Unknown on line 0\n
[Sun Aug 30 03:11:05.574482 2026] [security2:error] [pid 517995:tid 518211] [client 52.139.37.240:13868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/wp-blog.php"] [unique_id "apPlmbz-S0xMfHBNth6elwAAAV4"]
[Sun Aug 30 03:11:05.576164 2026] [security2:error] [pid 519566:tid 519819] [client 20.104.18.15:16908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/vpn.php"] [unique_id "apPlmdKCPt8cS-VWcMmI-gAABB4"]
[Sun Aug 30 03:11:05.577676 2026] [security2:error] [pid 519566:tid 519800] [client 20.48.251.3:52226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-class.php"] [unique_id "apPlmdKCPt8cS-VWcMmI_QAABAs"]
[Sun Aug 30 03:11:05.590777 2026] [security2:error] [pid 517995:tid 518212] [client 20.104.50.220:61988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-plugins.php"] [unique_id "apPlmbz-S0xMfHBNth6eqAAAAV8"]
[Sun Aug 30 03:11:05.612343 2026] [security2:error] [pid 518600:tid 518782] [client 20.63.219.114:19137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/k.php"] [unique_id "apPlme349Tv4SB45P2ngbQAAALY"]
[Sun Aug 30 03:11:05.629577 2026] [security2:error] [pid 517995:tid 518231] [client 20.151.200.44:41911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/t00l.php"] [unique_id "apPlmbz-S0xMfHBNth6exAAAAXI"]
[Sun Aug 30 03:11:05.640877 2026] [security2:error] [pid 517995:tid 518129] [client 4.205.62.107:15989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/localconf.php"] [unique_id "apPlmbz-S0xMfHBNth6ezQAAAQw"]
[Sun Aug 30 03:11:05.653794 2026] [security2:error] [pid 517995:tid 518168] [client 20.48.160.90:51960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/biufile.php"] [unique_id "apPlmbz-S0xMfHBNth6e1QAAATM"]
[Sun Aug 30 03:11:05.664926 2026] [security2:error] [pid 517995:tid 518182] [client 40.83.93.50:6384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/leaf.php"] [unique_id "apPlmbz-S0xMfHBNth6e2wAAAUE"]
[Sun Aug 30 03:11:05.665380 2026] [security2:error] [pid 517995:tid 518193] [client 20.63.81.20:59124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp-admin/css/colors/coffee/mari.php"] [unique_id "apPlmbz-S0xMfHBNth6e3QAAAUw"]
[Sun Aug 30 03:11:05.669901 2026] [security2:error] [pid 519566:tid 519729] [client 158.23.184.117:7738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPlmdKCPt8cS-VWcMmJEgAAA8Q"]
[Sun Aug 30 03:11:05.671026 2026] [security2:error] [pid 517995:tid 518031] [remote 40.77.167.67:55694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "laurelhollowfl.com"] [uri "/bhoa-content/maintenance/maint-sprinklers-edit-db.php"] [unique_id "apPlmbz-S0xMfHBNth6e2QABVyE"]
[Sun Aug 30 03:11:05.689032 2026] [security2:error] [pid 517995:tid 518183] [client 20.104.49.130:52116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/82.php"] [unique_id "apPlmbz-S0xMfHBNth6e-QAAAUI"]
[Sun Aug 30 03:11:05.690217 2026] [security2:error] [pid 519566:tid 519776] [client 57.131.147.192:57137] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdss.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "apPlmdKCPt8cS-VWcMmJGQAAA_M"]
[Sun Aug 30 03:11:05.726237 2026] [authz_core:error] [pid 518600:tid 518733] [client 216.73.216.128:60050] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:05.726543 2026] [authz_core:error] [pid 518600:tid 518733] [client 216.73.216.128:60050] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:05.793300 2026] [security2:error] [pid 517995:tid 518223] [client 20.63.81.20:59018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp-includes/images/crystal/option.php"] [unique_id "apPlmbz-S0xMfHBNth6fMgAAAWo"]
[Sun Aug 30 03:11:05.799543 2026] [security2:error] [pid 517995:tid 518231] [client 20.48.160.90:28097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/blacks.php"] [unique_id "apPlmbz-S0xMfHBNth6fPAAAAXI"]
[Sun Aug 30 03:11:05.809925 2026] [security2:error] [pid 517995:tid 518155] [client 20.151.200.44:40897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/wt.php"] [unique_id "apPlmbz-S0xMfHBNth6fRAAAASY"]
[Sun Aug 30 03:11:05.814370 2026] [security2:error] [pid 517995:tid 518224] [client 158.23.184.117:7547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/gg.php"] [unique_id "apPlmbz-S0xMfHBNth6fSQAAAWs"]
[Sun Aug 30 03:11:05.815729 2026] [security2:error] [pid 517995:tid 518185] [client 52.139.37.240:44626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/xmlrpc.php"] [unique_id "apPlmbz-S0xMfHBNth6fLwAAAUQ"]
[Sun Aug 30 03:11:05.818811 2026] [authz_core:error] [pid 519566:tid 519723] [client 216.73.216.128:22164] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:05.819238 2026] [authz_core:error] [pid 519566:tid 519723] [client 216.73.216.128:22164] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:05.825891 2026] [security2:error] [pid 519566:tid 519768] [client 20.104.49.130:63545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/forum.php"] [unique_id "apPlmdKCPt8cS-VWcMmJRAAAA-s"]
[Sun Aug 30 03:11:05.836617 2026] [security2:error] [pid 518600:tid 518783] [client 68.155.159.216:62609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/goat1.php"] [unique_id "apPlme349Tv4SB45P2nglgAAALc"]
[Sun Aug 30 03:11:05.853977 2026] [authz_core:error] [pid 517995:tid 518232] [client 74.7.243.204:59484] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:05.854253 2026] [authz_core:error] [pid 517995:tid 518232] [client 74.7.243.204:59484] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:05.854831 2026] [security2:error] [pid 519566:tid 519727] [client 20.104.50.220:29577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wiki-index.php"] [unique_id "apPlmdKCPt8cS-VWcMmJSgAAA8I"]
[Sun Aug 30 03:11:05.859372 2026] [security2:error] [pid 517995:tid 518227] [client 40.83.93.50:6358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/hello.php"] [unique_id "apPlmbz-S0xMfHBNth6fdQAAAW4"]
[Sun Aug 30 03:11:05.919632 2026] [security2:error] [pid 519566:tid 519714] [client 158.23.147.79:56494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/x.php"] [unique_id "apPlmdKCPt8cS-VWcMmJUgAAA7U"]
[Sun Aug 30 03:11:05.920849 2026] [security2:error] [pid 519566:tid 519769] [client 20.63.81.20:59024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp-includes/pomo/xxx.php"] [unique_id "apPlmdKCPt8cS-VWcMmJUwAAA-w"]
[Sun Aug 30 03:11:05.924577 2026] [security2:error] [pid 519566:tid 519760] [client 68.155.159.216:52575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-content/index.php"] [unique_id "apPlmdKCPt8cS-VWcMmJVAAAA-M"]
[Sun Aug 30 03:11:05.949101 2026] [authz_core:error] [pid 518600:tid 518793] [client 66.249.66.65:56553] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:05.949396 2026] [authz_core:error] [pid 518600:tid 518793] [client 66.249.66.65:56553] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:05.958998 2026] [security2:error] [pid 519566:tid 519770] [client 158.23.184.117:7433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/wp-admin/includes/post.php"] [unique_id "apPlmdKCPt8cS-VWcMmJVwAAA-0"]
[Sun Aug 30 03:11:05.969910 2026] [security2:error] [pid 518600:tid 518784] [client 158.23.147.79:52255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/bk/index.php"] [unique_id "apPlme349Tv4SB45P2ngtQAAALg"]
[Sun Aug 30 03:11:05.976242 2026] [security2:error] [pid 518600:tid 518811] [client 20.48.160.90:51929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/beck.php"] [unique_id "apPlme349Tv4SB45P2nguAAAANM"]
[Sun Aug 30 03:11:06.016819 2026] [lsapi:error] [pid 517995:tid 518162] [client 95.163.151.108:30618] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n
[Sun Aug 30 03:11:06.016931 2026] [lsapi:error] [pid 517995:tid 518162] [client 95.163.151.108:30618] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n
[Sun Aug 30 03:11:06.018248 2026] [lsapi:error] [pid 517995:tid 518162] [client 95.163.151.108:30618] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n
[Sun Aug 30 03:11:06.018722 2026] [security2:error] [pid 519566:tid 519771] [client 52.139.37.240:43113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/lu4.php"] [unique_id "apPlmtKCPt8cS-VWcMmJXAAAA-4"]
[Sun Aug 30 03:11:06.022947 2026] [security2:error] [pid 519566:tid 519786] [client 57.131.147.192:64239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.147.131.57.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ucdsafetysystems.com"] [uri "/wp-login.php"] [unique_id "apPlmtKCPt8cS-VWcMmJYQAAA_0"]
[Sun Aug 30 03:11:06.042074 2026] [security2:error] [pid 519566:tid 519821] [client 57.131.147.192:63387] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdss.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "apPlmtKCPt8cS-VWcMmJZAAABCA"]
[Sun Aug 30 03:11:06.048449 2026] [security2:error] [pid 519566:tid 519702] [client 20.63.81.20:59102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/650.php"] [unique_id "apPlmtKCPt8cS-VWcMmJZQAAA6k"]
[Sun Aug 30 03:11:06.086015 2026] [security2:error] [pid 519566:tid 519800] [client 20.104.50.220:42757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-content/uploads/simple-file-list/alfa.php"] [unique_id "apPlmtKCPt8cS-VWcMmJagAABAs"]
[Sun Aug 30 03:11:06.088872 2026] [authz_core:error] [pid 518600:tid 518813] [client 216.73.216.128:60050] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:06.089414 2026] [authz_core:error] [pid 518600:tid 518813] [client 216.73.216.128:60050] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:06.108799 2026] [security2:error] [pid 519566:tid 519734] [client 20.104.49.130:53604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/talkxkej.php"] [unique_id "apPlmtKCPt8cS-VWcMmJcAAAA8k"]
[Sun Aug 30 03:11:06.114848 2026] [security2:error] [pid 519566:tid 519816] [client 20.48.160.90:28142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/t3.php"] [unique_id "apPlmtKCPt8cS-VWcMmJdAAABBs"]
[Sun Aug 30 03:11:06.140233 2026] [security2:error] [pid 519566:tid 519738] [client 20.104.50.220:29582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/hello.php"] [unique_id "apPlmtKCPt8cS-VWcMmJewAAA80"]
[Sun Aug 30 03:11:06.147069 2026] [security2:error] [pid 519566:tid 519768] [client 158.23.184.117:7500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ermes-it-org.webnet-hosting4.com"] [uri "/wp-act.php"] [unique_id "apPlmtKCPt8cS-VWcMmJgAAAA-s"]
[Sun Aug 30 03:11:06.148130 2026] [security2:error] [pid 519566:tid 519705] [client 20.104.18.15:18190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/new.php"] [unique_id "apPlmtKCPt8cS-VWcMmJgQAAA6w"]
[Sun Aug 30 03:11:06.167488 2026] [security2:error] [pid 518600:tid 518810] [client 20.104.18.15:22439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/gigi.php"] [unique_id "apPlmu349Tv4SB45P2ng3QAAANI"]
[Sun Aug 30 03:11:06.180266 2026] [security2:error] [pid 519566:tid 519802] [client 20.63.81.20:59023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/nakrip.php"] [unique_id "apPlmtKCPt8cS-VWcMmJhwAABA0"]
[Sun Aug 30 03:11:06.190481 2026] [security2:error] [pid 519566:tid 519712] [client 20.104.50.220:31544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "apPlmtKCPt8cS-VWcMmJiwAAA7M"]
[Sun Aug 30 03:11:06.209101 2026] [security2:error] [pid 519566:tid 519745] [client 40.83.93.50:3080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/k.php"] [unique_id "apPlmtKCPt8cS-VWcMmJjwAAA9Q"]
[Sun Aug 30 03:11:06.211576 2026] [security2:error] [pid 518600:tid 518791] [client 20.48.251.3:64304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/ty.php"] [unique_id "apPlmu349Tv4SB45P2ng5wAAAL8"]
[Sun Aug 30 03:11:06.211587 2026] [security2:error] [pid 518600:tid 518740] [client 20.104.50.220:33049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-incleude.php"] [unique_id "apPlmu349Tv4SB45P2ng6AAAAIw"]
[Sun Aug 30 03:11:06.213811 2026] [security2:error] [pid 518600:tid 518832] [client 20.104.50.220:5929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/option.php"] [unique_id "apPlmu349Tv4SB45P2ng6gAAAOg"]
[Sun Aug 30 03:11:06.219830 2026] [security2:error] [pid 519566:tid 519725] [client 52.139.37.240:44621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "apPlmtKCPt8cS-VWcMmJkQAAA8A"]
[Sun Aug 30 03:11:06.239178 2026] [security2:error] [pid 518600:tid 518817] [client 20.104.50.220:17317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-content/upgrade/about.php"] [unique_id "apPlmu349Tv4SB45P2ng8QAAANk"]
[Sun Aug 30 03:11:06.254126 2026] [lsapi:warn] [pid 519566:tid 519790] [client 148.153.56.62:0] [host 162.144.0.169] Backend log: PHP Warning: PHP Request Shutdown: Cannot call session save handler in a recursive manner in Unknown on line 0\n
[Sun Aug 30 03:11:06.254165 2026] [lsapi:warn] [pid 519566:tid 519790] [client 148.153.56.62:0] [host 162.144.0.169] Backend log: PHP Warning: PHP Request Shutdown: Failed to write session data using user defined save handler. (session.save_path: /var/cpanel/php/sessions/ea-php83, handler: write) in Unknown on line 0\n
[Sun Aug 30 03:11:06.276197 2026] [security2:error] [pid 518600:tid 518848] [client 158.23.147.79:61714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/first.php"] [unique_id "apPlmu349Tv4SB45P2ng9wAAAPg"]
[Sun Aug 30 03:11:06.311093 2026] [security2:error] [pid 518600:tid 518759] [client 20.63.81.20:59130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp-includes/interactivity-api/flower.php"] [unique_id "apPlmu349Tv4SB45P2nhAwAAAJ8"]
[Sun Aug 30 03:11:06.314174 2026] [security2:error] [pid 519566:tid 519744] [client 20.48.160.90:28116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/wp.php"] [unique_id "apPlmtKCPt8cS-VWcMmJqgAAA9M"]
[Sun Aug 30 03:11:06.335717 2026] [security2:error] [pid 519566:tid 519707] [client 40.83.93.50:6530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/g.php"] [unique_id "apPlmtKCPt8cS-VWcMmJtQAAA64"]
[Sun Aug 30 03:11:06.358082 2026] [security2:error] [pid 518600:tid 518846] [client 20.63.219.114:19153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/chosen.php"] [unique_id "apPlmu349Tv4SB45P2nhHQAAAPY"]
[Sun Aug 30 03:11:06.371043 2026] [security2:error] [pid 518600:tid 518735] [client 4.205.62.107:52895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlmu349Tv4SB45P2nhIAAAAIc"]
[Sun Aug 30 03:11:06.382590 2026] [security2:error] [pid 518600:tid 518768] [client 4.205.62.107:36052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/aws_settings.php"] [unique_id "apPlmu349Tv4SB45P2nhJAAAAKg"]
[Sun Aug 30 03:11:06.390360 2026] [security2:error] [pid 519566:tid 519726] [client 57.131.147.192:53636] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdss.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "apPlmtKCPt8cS-VWcMmJwQAAA8E"]
[Sun Aug 30 03:11:06.399867 2026] [security2:error] [pid 518600:tid 518832] [client 20.104.18.15:31616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/chosen.php"] [unique_id "apPlmu349Tv4SB45P2nhKgAAAOg"]
[Sun Aug 30 03:11:06.405370 2026] [security2:error] [pid 518600:tid 518859] [client 20.48.251.3:36839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/kerang.php"] [unique_id "apPlmu349Tv4SB45P2nhLAAAAQM"]
[Sun Aug 30 03:11:06.427768 2026] [authz_core:error] [pid 519566:tid 519729] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:06.428166 2026] [authz_core:error] [pid 519566:tid 519729] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:06.436269 2026] [security2:error] [pid 519566:tid 519785] [client 52.139.37.240:43112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "apPlmtKCPt8cS-VWcMmJyQAAA_w"]
[Sun Aug 30 03:11:06.439405 2026] [security2:error] [pid 518600:tid 518677] [remote 20.237.251.56:6205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.251.237.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anantiapolytechnic.ng"] [uri "/wp-login.php"] [unique_id "apPlmu349Tv4SB45P2nhMgAA0Uk"]
[Sun Aug 30 03:11:06.447285 2026] [security2:error] [pid 519566:tid 519822] [client 4.205.62.107:17337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/wp-class.php"] [unique_id "apPlmtKCPt8cS-VWcMmJzQAABCE"]
[Sun Aug 30 03:11:06.448258 2026] [security2:error] [pid 519566:tid 519807] [client 20.63.81.20:59075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/xcc.php"] [unique_id "apPlmtKCPt8cS-VWcMmJzwAABBI"]
[Sun Aug 30 03:11:06.448767 2026] [security2:error] [pid 519566:tid 519788] [client 20.48.160.90:51901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/abcd.php"] [unique_id "apPlmtKCPt8cS-VWcMmJ0AAAA_8"]
[Sun Aug 30 03:11:06.465760 2026] [security2:error] [pid 518600:tid 518813] [client 20.151.200.44:40938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/im.php"] [unique_id "apPlmu349Tv4SB45P2nhOAAAANU"]
[Sun Aug 30 03:11:06.493416 2026] [security2:error] [pid 519566:tid 519812] [client 20.104.49.130:51558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/load.php"] [unique_id "apPlmtKCPt8cS-VWcMmJ1gAABBc"]
[Sun Aug 30 03:11:06.503265 2026] [authz_core:error] [pid 519566:tid 519782] [client 66.249.66.75:60983] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:06.503552 2026] [authz_core:error] [pid 519566:tid 519782] [client 66.249.66.75:60983] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:06.507904 2026] [security2:error] [pid 518600:tid 518807] [client 20.104.49.130:53630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/run.php"] [unique_id "apPlmu349Tv4SB45P2nhQAAAAM8"]
[Sun Aug 30 03:11:06.513793 2026] [security2:error] [pid 519566:tid 519798] [client 20.48.251.3:55794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/u88.php"] [unique_id "apPlmtKCPt8cS-VWcMmJ3QAABAk"]
[Sun Aug 30 03:11:06.537116 2026] [authz_core:error] [pid 519566:tid 519737] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:11:06.537405 2026] [authz_core:error] [pid 519566:tid 519737] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:11:06.540489 2026] [security2:error] [pid 519566:tid 519748] [client 4.205.62.107:25529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/css.php"] [unique_id "apPlmtKCPt8cS-VWcMmJ4gAAA9c"]
[Sun Aug 30 03:11:06.553148 2026] [security2:error] [pid 519566:tid 519820] [client 20.151.200.44:65363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/css/000.php"] [unique_id "apPlmtKCPt8cS-VWcMmJ5gAABB8"]
[Sun Aug 30 03:11:06.576587 2026] [security2:error] [pid 519566:tid 519801] [client 20.63.81.20:59082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp-includes/Text/Diff/Engine/aaa.php"] [unique_id "apPlmtKCPt8cS-VWcMmJ7wAABAw"]
[Sun Aug 30 03:11:06.591062 2026] [lsapi:warn] [pid 519566:tid 519768] [client 148.153.56.62:0] [host 162.144.0.169] Backend log: PHP Warning: PHP Request Shutdown: Cannot call session save handler in a recursive manner in Unknown on line 0\n
[Sun Aug 30 03:11:06.591083 2026] [lsapi:warn] [pid 519566:tid 519768] [client 148.153.56.62:0] [host 162.144.0.169] Backend log: PHP Warning: PHP Request Shutdown: Failed to write session data using user defined save handler. (session.save_path: /var/cpanel/php/sessions/ea-php83, handler: write) in Unknown on line 0\n
[Sun Aug 30 03:11:06.598751 2026] [security2:error] [pid 519566:tid 519802] [client 20.104.49.130:53805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/133.php"] [unique_id "apPlmtKCPt8cS-VWcMmJ9AAABA0"]
[Sun Aug 30 03:11:06.610181 2026] [security2:error] [pid 519566:tid 519715] [client 20.48.160.90:28132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/nofile.php"] [unique_id "apPlmtKCPt8cS-VWcMmJ-QAAA7Y"]
[Sun Aug 30 03:11:06.614768 2026] [security2:error] [pid 519566:tid 519799] [client 20.104.49.130:52430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/ab.php"] [unique_id "apPlmtKCPt8cS-VWcMmJ-wAABAo"]
[Sun Aug 30 03:11:06.624913 2026] [security2:error] [pid 519566:tid 519743] [client 158.23.147.79:57665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-content/x.php"] [unique_id "apPlmtKCPt8cS-VWcMmJ_gAAA9I"]
[Sun Aug 30 03:11:06.629165 2026] [security2:error] [pid 518600:tid 518678] [remote 20.237.251.56:6205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.251.237.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anantiapolytechnic.ng"] [uri "/wp-login.php"] [unique_id "apPlmu349Tv4SB45P2nhWQAA_0o"], referer: https://anantiapolytechnic.ng/wp-login.php
[Sun Aug 30 03:11:06.636334 2026] [security2:error] [pid 518600:tid 518753] [client 52.139.37.240:44580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "apPlmu349Tv4SB45P2nhXQAAAJk"]
[Sun Aug 30 03:11:06.638413 2026] [authz_core:error] [pid 518600:tid 518797] [client 216.73.216.128:60050] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:06.638855 2026] [authz_core:error] [pid 518600:tid 518797] [client 216.73.216.128:60050] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:06.662619 2026] [security2:error] [pid 519566:tid 519742] [client 20.196.209.81:15063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/data.php"] [unique_id "apPlmtKCPt8cS-VWcMmKBwAAA9E"]
[Sun Aug 30 03:11:06.663114 2026] [security2:error] [pid 519566:tid 519740] [client 158.23.147.79:58426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/goat.php"] [unique_id "apPlmtKCPt8cS-VWcMmKCAAAA88"]
[Sun Aug 30 03:11:06.707697 2026] [security2:error] [pid 519566:tid 519758] [client 20.63.81.20:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp-includes/style-engine/gecko-new.php"] [unique_id "apPlmtKCPt8cS-VWcMmKDwAAA-E"]
[Sun Aug 30 03:11:06.719473 2026] [security2:error] [pid 518600:tid 518818] [client 20.104.18.15:17017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/shiny.php"] [unique_id "apPlmu349Tv4SB45P2nhZQAAANo"]
[Sun Aug 30 03:11:06.720152 2026] [security2:error] [pid 519566:tid 519800] [client 216.73.216.128:22164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/'+this.controller.state().get("] [unique_id "apPlmtKCPt8cS-VWcMmKEQAABAs"]
[Sun Aug 30 03:11:06.731584 2026] [security2:error] [pid 519566:tid 519767] [client 20.48.251.3:59868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/database.php"] [unique_id "apPlmtKCPt8cS-VWcMmKFAAAA-o"]
[Sun Aug 30 03:11:06.742333 2026] [security2:error] [pid 519566:tid 519734] [client 57.131.147.192:65207] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdss.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "apPlmtKCPt8cS-VWcMmKFgAAA8k"]
[Sun Aug 30 03:11:06.745746 2026] [security2:error] [pid 518600:tid 518827] [client 40.83.93.50:22122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/chosen.php"] [unique_id "apPlmu349Tv4SB45P2nhawAAAOM"]
[Sun Aug 30 03:11:06.746500 2026] [security2:error] [pid 519566:tid 519819] [client 20.104.50.220:61410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-rss.php"] [unique_id "apPlmtKCPt8cS-VWcMmKGAAABB4"]
[Sun Aug 30 03:11:06.764528 2026] [security2:error] [pid 519566:tid 519806] [client 20.48.160.90:51841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/run.php"] [unique_id "apPlmtKCPt8cS-VWcMmKHQAABBE"]
[Sun Aug 30 03:11:06.778438 2026] [security2:error] [pid 519566:tid 519724] [client 4.205.62.107:15951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/bengi.php"] [unique_id "apPlmtKCPt8cS-VWcMmKIgAAA78"]
[Sun Aug 30 03:11:06.798953 2026] [security2:error] [pid 519566:tid 519787] [client 20.196.209.81:15078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/dt-the7/css/static-less/plugins/admin.php"] [unique_id "apPlmtKCPt8cS-VWcMmKJQAAA_4"]
[Sun Aug 30 03:11:06.815401 2026] [security2:error] [pid 519566:tid 519822] [client 40.83.93.50:10714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/cc.php"] [unique_id "apPlmtKCPt8cS-VWcMmKJwAABCE"]
[Sun Aug 30 03:11:06.834947 2026] [security2:error] [pid 518600:tid 518790] [client 20.63.81.20:59101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp-settings.php"] [unique_id "apPlmu349Tv4SB45P2nheAAAAL4"]
[Sun Aug 30 03:11:06.839201 2026] [security2:error] [pid 518600:tid 518820] [client 52.139.37.240:44598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/ant.php"] [unique_id "apPlmu349Tv4SB45P2nhdgAAANw"]
[Sun Aug 30 03:11:06.882466 2026] [authz_core:error] [pid 518600:tid 518776] [client 66.249.66.205:36848] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:06.882748 2026] [authz_core:error] [pid 518600:tid 518776] [client 66.249.66.205:36848] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:06.886523 2026] [authz_core:error] [pid 519566:tid 519808] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:06.886813 2026] [authz_core:error] [pid 519566:tid 519808] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:06.900953 2026] [security2:error] [pid 519566:tid 519720] [client 20.48.160.90:51842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/new.php"] [unique_id "apPlmtKCPt8cS-VWcMmKMwAAA7s"]
[Sun Aug 30 03:11:06.950849 2026] [security2:error] [pid 519566:tid 519735] [client 68.155.159.216:63241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apPlmtKCPt8cS-VWcMmKOQAAA8o"]
[Sun Aug 30 03:11:06.961596 2026] [security2:error] [pid 519566:tid 519812] [client 20.63.81.20:59081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp-signup.php"] [unique_id "apPlmtKCPt8cS-VWcMmKPgAABBc"]
[Sun Aug 30 03:11:06.983123 2026] [security2:error] [pid 519566:tid 519705] [client 20.63.219.114:2940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/radio.php"] [unique_id "apPlmtKCPt8cS-VWcMmKQwAAA6w"]
[Sun Aug 30 03:11:06.993516 2026] [security2:error] [pid 519566:tid 519739] [client 20.104.50.220:28704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/Bulle.php"] [unique_id "apPlmtKCPt8cS-VWcMmKRgAAA84"]
[Sun Aug 30 03:11:07.049838 2026] [security2:error] [pid 518600:tid 518761] [client 20.48.160.90:28120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/inx.php"] [unique_id "apPlm-349Tv4SB45P2nhowAAAKE"]
[Sun Aug 30 03:11:07.052388 2026] [security2:error] [pid 518600:tid 518763] [client 68.155.159.216:52595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/about/function.php"] [unique_id "apPlm-349Tv4SB45P2nhpgAAAKM"]
[Sun Aug 30 03:11:07.058209 2026] [security2:error] [pid 519566:tid 519753] [client 68.155.159.216:46078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/x.php"] [unique_id "apPlm9KCPt8cS-VWcMmKUQAAA9w"]
[Sun Aug 30 03:11:07.061495 2026] [security2:error] [pid 519566:tid 519731] [client 52.139.37.240:43101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/autoload_classmap.php"] [unique_id "apPlm9KCPt8cS-VWcMmKUAAAA8Y"]
[Sun Aug 30 03:11:07.087976 2026] [security2:error] [pid 519566:tid 519783] [client 20.63.81.20:59014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp-conffg.php"] [unique_id "apPlm9KCPt8cS-VWcMmKVQAAA_o"]
[Sun Aug 30 03:11:07.089023 2026] [security2:error] [pid 519566:tid 519789] [client 57.131.147.192:56271] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdss.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "apPlm9KCPt8cS-VWcMmKVgAABAA"]
[Sun Aug 30 03:11:07.176969 2026] [security2:error] [pid 519566:tid 519785] [client 20.48.160.90:28130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/vpn.php"] [unique_id "apPlm9KCPt8cS-VWcMmKbAAAA_w"]
[Sun Aug 30 03:11:07.194305 2026] [security2:error] [pid 519566:tid 519751] [client 20.196.209.81:19164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/hideo/network.php"] [unique_id "apPlm9KCPt8cS-VWcMmKcwAAA9o"]
[Sun Aug 30 03:11:07.215385 2026] [security2:error] [pid 519566:tid 519791] [client 20.63.81.20:59085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp-validate.php"] [unique_id "apPlm9KCPt8cS-VWcMmKeQAABAI"]
[Sun Aug 30 03:11:07.238119 2026] [security2:error] [pid 519566:tid 519734] [client 20.104.50.220:42806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/Ninja.php"] [unique_id "apPlm9KCPt8cS-VWcMmKggAAA8k"]
[Sun Aug 30 03:11:07.267625 2026] [security2:error] [pid 518600:tid 518771] [client 52.139.37.240:43093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/storage/rip.php"] [unique_id "apPlm-349Tv4SB45P2nh0AAAAKs"]
[Sun Aug 30 03:11:07.274123 2026] [authz_core:error] [pid 518600:tid 518848] [client 216.73.216.128:43907] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:07.274275 2026] [security2:error] [pid 519566:tid 519721] [client 40.83.93.50:6560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/radio.php"] [unique_id "apPlm9KCPt8cS-VWcMmKiQAAA7w"]
[Sun Aug 30 03:11:07.274397 2026] [authz_core:error] [pid 518600:tid 518848] [client 216.73.216.128:43907] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:07.279154 2026] [security2:error] [pid 518600:tid 518759] [client 20.104.50.220:62804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/info.php"] [unique_id "apPlm-349Tv4SB45P2nh1gAAAJ8"]
[Sun Aug 30 03:11:07.289393 2026] [security2:error] [pid 519566:tid 519724] [client 20.104.18.15:18274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/inx.php"] [unique_id "apPlm9KCPt8cS-VWcMmKjAAAA78"]
[Sun Aug 30 03:11:07.309234 2026] [security2:error] [pid 519566:tid 519727] [client 20.48.160.90:46567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/shiny.php"] [unique_id "apPlm9KCPt8cS-VWcMmKlgAAA8I"]
[Sun Aug 30 03:11:07.313347 2026] [security2:error] [pid 518600:tid 518808] [client 40.83.93.50:6379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/f35.php"] [unique_id "apPlm-349Tv4SB45P2nh5AAAANA"]
[Sun Aug 30 03:11:07.320460 2026] [lsapi:error] [pid 519566:tid 519814] [client 95.163.151.108:30632] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:11:07.320671 2026] [lsapi:error] [pid 519566:tid 519814] [client 95.163.151.108:30632] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:11:07.322009 2026] [lsapi:error] [pid 519566:tid 519814] [client 95.163.151.108:30632] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:11:07.325655 2026] [security2:error] [pid 519566:tid 519785] [client 20.104.50.220:51014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/bal.php"] [unique_id "apPlm9KCPt8cS-VWcMmKoAAAA_w"]
[Sun Aug 30 03:11:07.342211 2026] [security2:error] [pid 519566:tid 519760] [client 20.63.81.20:59112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/700.php"] [unique_id "apPlm9KCPt8cS-VWcMmKpQAAA-M"]
[Sun Aug 30 03:11:07.351388 2026] [security2:error] [pid 518600:tid 518761] [client 20.104.50.220:32836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/fpebr.php"] [unique_id "apPlm-349Tv4SB45P2nh9AAAAKE"]
[Sun Aug 30 03:11:07.357502 2026] [authz_core:error] [pid 518600:tid 518843] [client 66.249.66.45:51523] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:07.357843 2026] [authz_core:error] [pid 518600:tid 518843] [client 66.249.66.45:51523] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:07.362560 2026] [security2:error] [pid 519566:tid 519765] [client 20.104.50.220:5513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/query.php"] [unique_id "apPlm9KCPt8cS-VWcMmKqwAAA-g"]
[Sun Aug 30 03:11:07.365762 2026] [security2:error] [pid 518600:tid 518753] [client 20.48.251.3:64260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/adminer-4.7.6-en.php"] [unique_id "apPlm-349Tv4SB45P2nh-AAAAJk"]
[Sun Aug 30 03:11:07.373459 2026] [security2:error] [pid 519566:tid 519791] [client 20.104.50.220:16977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apPlm9KCPt8cS-VWcMmKrAAABAI"]
[Sun Aug 30 03:11:07.379288 2026] [security2:error] [pid 519566:tid 519801] [client 20.63.219.114:15189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/functions.php"] [unique_id "apPlm9KCPt8cS-VWcMmKrgAABAw"]
[Sun Aug 30 03:11:07.381862 2026] [security2:error] [pid 519566:tid 519771] [client 20.104.18.15:22407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/info.php/new.php"] [unique_id "apPlm9KCPt8cS-VWcMmKsQAAA-4"]
[Sun Aug 30 03:11:07.394939 2026] [authz_core:error] [pid 519566:tid 519767] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:07.395404 2026] [authz_core:error] [pid 519566:tid 519767] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:07.409605 2026] [security2:error] [pid 519566:tid 519744] [client 20.151.200.44:41890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/ls.php"] [unique_id "apPlm9KCPt8cS-VWcMmKuQAAA9M"]
[Sun Aug 30 03:11:07.421343 2026] [security2:error] [pid 519566:tid 519816] [client 57.131.147.192:49234] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdss.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "apPlm9KCPt8cS-VWcMmKvQAABBs"]
[Sun Aug 30 03:11:07.447036 2026] [security2:error] [pid 519566:tid 519730] [client 20.48.160.90:28129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/goods.php"] [unique_id "apPlm9KCPt8cS-VWcMmKxQAAA8U"]
[Sun Aug 30 03:11:07.473023 2026] [security2:error] [pid 518600:tid 518832] [client 20.63.81.20:59011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/c4.php"] [unique_id "apPlm-349Tv4SB45P2niDAAAAOg"]
[Sun Aug 30 03:11:07.487600 2026] [security2:error] [pid 519566:tid 519703] [client 52.139.37.240:44603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/tinyfilemanager.php"] [unique_id "apPlm9KCPt8cS-VWcMmKywAAA6o"]
[Sun Aug 30 03:11:07.512375 2026] [security2:error] [pid 519566:tid 519757] [client 4.205.62.107:52817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/cloud.php"] [unique_id "apPlm9KCPt8cS-VWcMmK1QAAA-A"]
[Sun Aug 30 03:11:07.525957 2026] [security2:error] [pid 518600:tid 518748] [client 20.151.200.44:40827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/file.php"] [unique_id "apPlm-349Tv4SB45P2niGAAAAJQ"]
[Sun Aug 30 03:11:07.540895 2026] [security2:error] [pid 518600:tid 518791] [client 216.73.216.128:43907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlm-349Tv4SB45P2niGwAAAL8"]
[Sun Aug 30 03:11:07.546183 2026] [security2:error] [pid 518600:tid 518743] [client 20.48.251.3:36861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/rem.php"] [unique_id "apPlm-349Tv4SB45P2niHQAAAI8"]
[Sun Aug 30 03:11:07.576288 2026] [security2:error] [pid 518600:tid 518757] [client 20.48.160.90:28125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/alfa.php"] [unique_id "apPlm-349Tv4SB45P2niJgAAAJ0"]
[Sun Aug 30 03:11:07.584035 2026] [security2:error] [pid 518600:tid 518760] [client 4.205.62.107:17672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/database.php"] [unique_id "apPlm-349Tv4SB45P2niKgAAAKA"]
[Sun Aug 30 03:11:07.585575 2026] [security2:error] [pid 519566:tid 519803] [client 4.205.62.107:36035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/wp-konfig.backup.php"] [unique_id "apPlm9KCPt8cS-VWcMmK7AAABA4"]
[Sun Aug 30 03:11:07.586168 2026] [security2:error] [pid 519566:tid 519733] [client 20.196.209.81:21719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPlm9KCPt8cS-VWcMmK7QAAA8g"]
[Sun Aug 30 03:11:07.616788 2026] [security2:error] [pid 519566:tid 519696] [client 20.63.81.20:59008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp-tymanage.php"] [unique_id "apPlm9KCPt8cS-VWcMmK9QAAA6M"]
[Sun Aug 30 03:11:07.630305 2026] [security2:error] [pid 519566:tid 519713] [client 20.151.200.44:64130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/cy.php"] [unique_id "apPlm9KCPt8cS-VWcMmK9wAAA7Q"]
[Sun Aug 30 03:11:07.635726 2026] [lsapi:warn] [pid 515259:tid 515497] [client 185.231.154.128:49974] [host tastylandscape.com] Backend log: PHP Warning: Use of undefined constant user_level - assumed 'user_level' (this will throw an Error in a future version of PHP) in /home4/tommed/public_html/wp-content/plugins/ultimate-google-analytics/ultimate_ga.php on line 524\n, referer: https://tastylandscape.com/2015/09/05/dragon-fruit-diseases/
[Sun Aug 30 03:11:07.640681 2026] [authz_core:error] [pid 518600:tid 518770] [client 216.73.216.128:60050] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:07.641092 2026] [authz_core:error] [pid 518600:tid 518770] [client 216.73.216.128:60050] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:07.645711 2026] [security2:error] [pid 518600:tid 518854] [client 20.48.251.3:59377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/config/laravolt/css/index.php"] [unique_id "apPlm-349Tv4SB45P2niOAAAAP4"]
[Sun Aug 30 03:11:07.667176 2026] [security2:error] [pid 518600:tid 518772] [client 158.23.147.79:1930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPlm-349Tv4SB45P2niPQAAAKw"]
[Sun Aug 30 03:11:07.687708 2026] [security2:error] [pid 519566:tid 519773] [client 20.104.18.15:31630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/file1221.php"] [unique_id "apPlm9KCPt8cS-VWcMmLBAAAA_A"]
[Sun Aug 30 03:11:07.706988 2026] [security2:error] [pid 519566:tid 519823] [client 4.205.62.107:25774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/php_info.php"] [unique_id "apPlm9KCPt8cS-VWcMmLDAAABCI"]
[Sun Aug 30 03:11:07.730361 2026] [security2:error] [pid 518600:tid 518818] [client 20.48.160.90:28138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/33.php"] [unique_id "apPlm-349Tv4SB45P2niTwAAANo"]
[Sun Aug 30 03:11:07.732839 2026] [authz_core:error] [pid 518600:tid 518751] [client 216.73.216.128:52324] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:07.733120 2026] [authz_core:error] [pid 518600:tid 518751] [client 216.73.216.128:52324] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:07.748250 2026] [security2:error] [pid 518600:tid 518830] [client 20.63.81.20:59093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/ajfto.php"] [unique_id "apPlm-349Tv4SB45P2niUwAAAOY"]
[Sun Aug 30 03:11:07.751297 2026] [security2:error] [pid 518600:tid 518787] [client 40.83.93.50:22089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/functions.php"] [unique_id "apPlm-349Tv4SB45P2niVQAAALs"]
[Sun Aug 30 03:11:07.752986 2026] [authz_core:error] [pid 519566:tid 519782] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:11:07.753252 2026] [authz_core:error] [pid 519566:tid 519782] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmime%2Fapplication
[Sun Aug 30 03:11:07.758205 2026] [security2:error] [pid 518600:tid 518833] [client 20.63.219.114:12997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/elp.php"] [unique_id "apPlm-349Tv4SB45P2niVwAAAOk"]
[Sun Aug 30 03:11:07.773214 2026] [security2:error] [pid 519566:tid 519762] [client 57.131.147.192:56114] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdss.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "apPlm9KCPt8cS-VWcMmLEwAAA-U"]
[Sun Aug 30 03:11:07.837297 2026] [security2:error] [pid 519566:tid 519709] [client 40.83.93.50:10741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/classsmtps.php"] [unique_id "apPlm9KCPt8cS-VWcMmLGgAAA7A"]
[Sun Aug 30 03:11:07.870821 2026] [security2:error] [pid 518600:tid 518816] [client 20.48.251.3:59865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/atex1.php"] [unique_id "apPlm-349Tv4SB45P2nidwAAANg"]
[Sun Aug 30 03:11:07.875077 2026] [security2:error] [pid 518600:tid 518828] [client 20.63.81.20:58944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp_KwIW0U5F.php"] [unique_id "apPlm-349Tv4SB45P2nieAAAAOQ"]
[Sun Aug 30 03:11:07.875150 2026] [authz_core:error] [pid 518600:tid 518733] [client 66.249.66.77:61502] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:07.875617 2026] [authz_core:error] [pid 518600:tid 518733] [client 66.249.66.77:61502] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:07.882201 2026] [security2:error] [pid 519566:tid 519780] [client 20.104.18.15:64745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/goods.php"] [unique_id "apPlm9KCPt8cS-VWcMmLHwAAA_c"]
[Sun Aug 30 03:11:07.886497 2026] [security2:error] [pid 519566:tid 519733] [client 20.48.160.90:46490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/133.php"] [unique_id "apPlm9KCPt8cS-VWcMmLIQAAA8g"]
[Sun Aug 30 03:11:07.888108 2026] [authz_core:error] [pid 519566:tid 519767] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:07.888600 2026] [authz_core:error] [pid 519566:tid 519767] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:07.906320 2026] [security2:error] [pid 518600:tid 518849] [client 20.104.50.220:59578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-singupp.php"] [unique_id "apPlm-349Tv4SB45P2nigwAAAPk"]
[Sun Aug 30 03:11:07.916434 2026] [security2:error] [pid 518600:tid 518799] [client 4.205.62.107:16326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/i.php"] [unique_id "apPlm-349Tv4SB45P2nihQAAAMc"]
[Sun Aug 30 03:11:07.959641 2026] [security2:error] [pid 519566:tid 519703] [client 20.104.49.130:60682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/srontol.php"] [unique_id "apPlm9KCPt8cS-VWcMmLMgAAA6o"]
[Sun Aug 30 03:11:07.972633 2026] [security2:error] [pid 519566:tid 519772] [client 20.104.49.130:51074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/gecko-new.php"] [unique_id "apPlm9KCPt8cS-VWcMmLNgAAA-8"]
[Sun Aug 30 03:11:07.976022 2026] [security2:error] [pid 519566:tid 519747] [client 20.196.209.81:11915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/intense/block-css.php"] [unique_id "apPlm9KCPt8cS-VWcMmLOAAAA9Y"]
[Sun Aug 30 03:11:08.002132 2026] [security2:error] [pid 518600:tid 518839] [client 20.63.81.20:59046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp_xiPu52Ut.php"] [unique_id "apPlnO349Tv4SB45P2nijwAAAO8"]
[Sun Aug 30 03:11:08.004843 2026] [lsapi:warn] [pid 519566:tid 519776] [client 148.153.56.62:0] [host 162.144.0.169] Backend log: PHP Warning: PHP Request Shutdown: Cannot call session save handler in a recursive manner in Unknown on line 0\n
[Sun Aug 30 03:11:08.004869 2026] [lsapi:warn] [pid 519566:tid 519776] [client 148.153.56.62:0] [host 162.144.0.169] Backend log: PHP Warning: PHP Request Shutdown: Failed to write session data using user defined save handler. (session.save_path: /var/cpanel/php/sessions/ea-php83, handler: write) in Unknown on line 0\n
[Sun Aug 30 03:11:08.033761 2026] [security2:error] [pid 519566:tid 519804] [client 20.48.160.90:46499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/sym.php"] [unique_id "apPlnNKCPt8cS-VWcMmLRgAABA8"]
[Sun Aug 30 03:11:08.053719 2026] [authz_core:error] [pid 518600:tid 518802] [client 216.73.216.128:2230] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:08.054109 2026] [authz_core:error] [pid 518600:tid 518802] [client 216.73.216.128:2230] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:08.066621 2026] [security2:error] [pid 519566:tid 519800] [client 20.151.200.44:40925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/ca.php"] [unique_id "apPlnNKCPt8cS-VWcMmLTwAABAs"]
[Sun Aug 30 03:11:08.089567 2026] [security2:error] [pid 518600:tid 518836] [client 20.151.200.44:64161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/admin.php/pindex.php"] [unique_id "apPlnO349Tv4SB45P2nipgAAAOw"]
[Sun Aug 30 03:11:08.093044 2026] [authz_core:error] [pid 518600:tid 518829] [client 216.73.216.128:60050] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:08.093327 2026] [authz_core:error] [pid 518600:tid 518829] [client 216.73.216.128:60050] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:08.103812 2026] [security2:error] [pid 519566:tid 519769] [client 57.131.147.192:54342] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ucdss.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "apPlnNKCPt8cS-VWcMmLWAAAA-w"]
[Sun Aug 30 03:11:08.129385 2026] [security2:error] [pid 518600:tid 518832] [client 20.63.219.114:2904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/options-reading.php"] [unique_id "apPlnO349Tv4SB45P2nirQAAAOg"]
[Sun Aug 30 03:11:08.132972 2026] [security2:error] [pid 519566:tid 519748] [client 20.63.81.20:59132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp_n5VD7XDh.php"] [unique_id "apPlnNKCPt8cS-VWcMmLXAAAA9c"]
[Sun Aug 30 03:11:08.134052 2026] [security2:error] [pid 519566:tid 519729] [client 20.104.50.220:62803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/srx.php"] [unique_id "apPlnNKCPt8cS-VWcMmLXQAAA8Q"]
[Sun Aug 30 03:11:08.175837 2026] [security2:error] [pid 519566:tid 519773] [client 68.155.159.216:52319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apPlnNKCPt8cS-VWcMmLbQAAA_A"]
[Sun Aug 30 03:11:08.178417 2026] [security2:error] [pid 519566:tid 519713] [client 20.48.160.90:28085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/8.php"] [unique_id "apPlnNKCPt8cS-VWcMmLbgAAA7Q"]
[Sun Aug 30 03:11:08.187212 2026] [authz_core:error] [pid 518600:tid 518828] [client 216.73.216.128:52324] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:08.187614 2026] [authz_core:error] [pid 518600:tid 518828] [client 216.73.216.128:52324] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:08.238150 2026] [security2:error] [pid 519566:tid 519803] [client 40.83.93.50:10726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/elp.php"] [unique_id "apPlnNKCPt8cS-VWcMmLegAABA4"]
[Sun Aug 30 03:11:08.267599 2026] [security2:error] [pid 519566:tid 519778] [client 20.63.81.20:59073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp-mini.php"] [unique_id "apPlnNKCPt8cS-VWcMmLgAAAA_U"]
[Sun Aug 30 03:11:08.311051 2026] [security2:error] [pid 519566:tid 519791] [client 20.48.160.90:28063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/goods.php"] [unique_id "apPlnNKCPt8cS-VWcMmLiQAABAI"]
[Sun Aug 30 03:11:08.345492 2026] [security2:error] [pid 519566:tid 519743] [client 40.83.93.50:6336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/install.php"] [unique_id "apPlnNKCPt8cS-VWcMmLlAAAA9I"]
[Sun Aug 30 03:11:08.351331 2026] [authz_core:error] [pid 519566:tid 519816] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:08.351596 2026] [authz_core:error] [pid 519566:tid 519816] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:08.367089 2026] [security2:error] [pid 519566:tid 519752] [client 20.196.209.81:19160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/login.php"] [unique_id "apPlnNKCPt8cS-VWcMmLnQAAA9s"]
[Sun Aug 30 03:11:08.372298 2026] [authz_core:error] [pid 519566:tid 519702] [client 66.249.66.67:39806] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:08.372697 2026] [authz_core:error] [pid 519566:tid 519702] [client 66.249.66.67:39806] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:08.373986 2026] [security2:error] [pid 518600:tid 518843] [client 68.155.159.216:63290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-admin/network/index.php"] [unique_id "apPlnO349Tv4SB45P2ni9QAAAPM"]
[Sun Aug 30 03:11:08.398408 2026] [security2:error] [pid 519566:tid 519706] [client 20.63.81.20:59111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/xmini4.php"] [unique_id "apPlnNKCPt8cS-VWcMmLpAAAA60"]
[Sun Aug 30 03:11:08.405951 2026] [security2:error] [pid 519566:tid 519745] [client 20.104.50.220:51569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-incleude.php"] [unique_id "apPlnNKCPt8cS-VWcMmLpgAAA9Q"]
[Sun Aug 30 03:11:08.434441 2026] [security2:error] [pid 519566:tid 519766] [client 20.104.50.220:29164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/ini.php"] [unique_id "apPlnNKCPt8cS-VWcMmLqwAAA-k"]
[Sun Aug 30 03:11:08.439704 2026] [security2:error] [pid 519566:tid 519802] [client 20.104.18.15:18270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/vpn.php"] [unique_id "apPlnNKCPt8cS-VWcMmLrQAABA0"]
[Sun Aug 30 03:11:08.441004 2026] [security2:error] [pid 518600:tid 518763] [client 20.48.160.90:28038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/ah.php"] [unique_id "apPlnO349Tv4SB45P2njAQAAAKM"]
[Sun Aug 30 03:11:08.498218 2026] [security2:error] [pid 518600:tid 518832] [client 20.63.219.114:2092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/db.php"] [unique_id "apPlnO349Tv4SB45P2njEgAAAOg"]
[Sun Aug 30 03:11:08.502909 2026] [security2:error] [pid 518600:tid 518850] [client 20.104.50.220:5510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/post.php"] [unique_id "apPlnO349Tv4SB45P2njFAAAAPo"]
[Sun Aug 30 03:11:08.502912 2026] [security2:error] [pid 519566:tid 519799] [client 20.104.50.220:17242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-content/radio.php"] [unique_id "apPlnNKCPt8cS-VWcMmLuAAABAo"]
[Sun Aug 30 03:11:08.502991 2026] [security2:error] [pid 519566:tid 519779] [client 20.104.50.220:32855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/snd21.php"] [unique_id "apPlnNKCPt8cS-VWcMmLuQAAA_Y"]
[Sun Aug 30 03:11:08.517109 2026] [security2:error] [pid 519566:tid 519784] [client 20.48.251.3:54793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/phpi.php"] [unique_id "apPlnNKCPt8cS-VWcMmLvQAAA_s"]
[Sun Aug 30 03:11:08.521176 2026] [security2:error] [pid 519566:tid 519765] [client 20.104.50.220:31497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/cgi-bin/admin.php"] [unique_id "apPlnNKCPt8cS-VWcMmLvwAAA-g"]
[Sun Aug 30 03:11:08.579901 2026] [security2:error] [pid 519566:tid 519719] [client 20.63.81.20:59050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/reop3.php"] [unique_id "apPlnNKCPt8cS-VWcMmLzAAAA7o"]
[Sun Aug 30 03:11:08.580579 2026] [autoindex:error] [pid 519566:tid 519754] [client 20.104.18.15:22344] AH01276: Cannot serve directory /home2/gracej/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:11:08.621400 2026] [security2:error] [pid 519566:tid 519817] [client 20.48.160.90:28156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/ws55.php"] [unique_id "apPlnNKCPt8cS-VWcMmL1QAABBw"]
[Sun Aug 30 03:11:08.643633 2026] [authz_core:error] [pid 519566:tid 519767] [client 216.73.216.128:45868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:08.644125 2026] [authz_core:error] [pid 519566:tid 519767] [client 216.73.216.128:45868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:08.666320 2026] [security2:error] [pid 519566:tid 519809] [client 4.205.62.107:52876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/kerang.php"] [unique_id "apPlnNKCPt8cS-VWcMmL3wAABBQ"]
[Sun Aug 30 03:11:08.674266 2026] [security2:error] [pid 519566:tid 519753] [client 20.104.18.15:22344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/w.php"] [unique_id "apPlnNKCPt8cS-VWcMmL4wAAA9w"]
[Sun Aug 30 03:11:08.683104 2026] [security2:error] [pid 519566:tid 519807] [client 20.48.251.3:36855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/min.php"] [unique_id "apPlnNKCPt8cS-VWcMmL5gAABBI"]
[Sun Aug 30 03:11:08.701203 2026] [security2:error] [pid 519566:tid 519709] [client 158.23.147.79:2028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/log-mama/function.php"] [unique_id "apPlnNKCPt8cS-VWcMmL6wAAA7A"]
[Sun Aug 30 03:11:08.714431 2026] [security2:error] [pid 518600:tid 518800] [client 20.104.49.130:39055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/one.php"] [unique_id "apPlnO349Tv4SB45P2njVQAAAMg"]
[Sun Aug 30 03:11:08.723103 2026] [authz_core:error] [pid 519566:tid 519766] [client 66.249.66.200:64666] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:08.723381 2026] [authz_core:error] [pid 519566:tid 519766] [client 66.249.66.200:64666] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:08.734932 2026] [security2:error] [pid 519566:tid 519798] [client 4.205.62.107:17122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/atex1.php"] [unique_id "apPlnNKCPt8cS-VWcMmL9QAABAk"]
[Sun Aug 30 03:11:08.740025 2026] [security2:error] [pid 518600:tid 518768] [client 20.63.81.20:59068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp-mail.php"] [unique_id "apPlnO349Tv4SB45P2njXQAAAKg"]
[Sun Aug 30 03:11:08.760398 2026] [security2:error] [pid 519566:tid 519786] [client 4.205.62.107:36545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/packed.php"] [unique_id "apPlnNKCPt8cS-VWcMmL_AAAA_0"]
[Sun Aug 30 03:11:08.772446 2026] [security2:error] [pid 519566:tid 519752] [client 20.48.160.90:51962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/drykl.php"] [unique_id "apPlnNKCPt8cS-VWcMmMAgAAA9s"]
[Sun Aug 30 03:11:08.785566 2026] [security2:error] [pid 518600:tid 518765] [client 20.48.251.3:52856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/87.php"] [unique_id "apPlnO349Tv4SB45P2njZwAAAKU"]
[Sun Aug 30 03:11:08.796093 2026] [security2:error] [pid 519566:tid 519724] [client 20.104.49.130:57675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/bthil.php"] [unique_id "apPlnNKCPt8cS-VWcMmMAwAAA78"]
[Sun Aug 30 03:11:08.799611 2026] [security2:error] [pid 519566:tid 519785] [client 20.196.209.81:15093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/min.php"] [unique_id "apPlnNKCPt8cS-VWcMmMBgAAA_w"]
[Sun Aug 30 03:11:08.833612 2026] [security2:error] [pid 519566:tid 519760] [client 40.83.93.50:6398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/wp.php"] [unique_id "apPlnNKCPt8cS-VWcMmMDQAAA-M"]
[Sun Aug 30 03:11:08.837428 2026] [security2:error] [pid 519566:tid 519770] [client 20.104.18.15:31700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/nox.php"] [unique_id "apPlnNKCPt8cS-VWcMmMDwAAA-0"]
[Sun Aug 30 03:11:08.844778 2026] [security2:error] [pid 518600:tid 518789] [client 4.205.62.107:25522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/session.php"] [unique_id "apPlnO349Tv4SB45P2njfwAAAL0"]
[Sun Aug 30 03:11:08.864330 2026] [authz_core:error] [pid 519566:tid 519822] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:08.864606 2026] [authz_core:error] [pid 519566:tid 519822] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:08.867774 2026] [security2:error] [pid 519566:tid 519816] [client 68.155.159.216:46032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-content/x.php"] [unique_id "apPlnNKCPt8cS-VWcMmMFAAABBs"]
[Sun Aug 30 03:11:08.867951 2026] [lsapi:error] [pid 519566:tid 519580] [remote 107.174.216.217:40180] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.google.com/
[Sun Aug 30 03:11:08.868121 2026] [lsapi:error] [pid 519566:tid 519580] [remote 107.174.216.217:40180] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.google.com/
[Sun Aug 30 03:11:08.868583 2026] [security2:error] [pid 519566:tid 519807] [client 20.63.81.20:58963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp-conffg.php"] [unique_id "apPlnNKCPt8cS-VWcMmMFQAABBI"]
[Sun Aug 30 03:11:08.869509 2026] [lsapi:error] [pid 519566:tid 519580] [remote 107.174.216.217:40180] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n, referer: https://www.google.com/
[Sun Aug 30 03:11:08.884441 2026] [security2:error] [pid 518600:tid 518825] [client 20.63.219.114:15272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/server.php"] [unique_id "apPlnO349Tv4SB45P2njggAAAOE"]
[Sun Aug 30 03:11:08.907593 2026] [security2:error] [pid 519566:tid 519802] [client 20.48.160.90:46576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/backup.php"] [unique_id "apPlnNKCPt8cS-VWcMmMGQAABA0"]
[Sun Aug 30 03:11:08.916131 2026] [authz_core:error] [pid 518600:tid 518775] [client 216.73.216.128:2230] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:08.916490 2026] [authz_core:error] [pid 518600:tid 518775] [client 216.73.216.128:2230] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:08.970010 2026] [security2:error] [pid 519566:tid 519733] [client 20.104.49.130:53610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/static.php"] [unique_id "apPlnNKCPt8cS-VWcMmMIQAAA8g"]
[Sun Aug 30 03:11:08.981887 2026] [authz_core:error] [pid 519566:tid 519808] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule
[Sun Aug 30 03:11:08.982180 2026] [authz_core:error] [pid 519566:tid 519808] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule
[Sun Aug 30 03:11:08.997232 2026] [security2:error] [pid 518600:tid 518776] [client 20.63.81.20:59135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/filefuns.php"] [unique_id "apPlnO349Tv4SB45P2njmAAAALA"]
[Sun Aug 30 03:11:09.007240 2026] [security2:error] [pid 519566:tid 519729] [client 20.48.251.3:59481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/aws_sdk_settings.php"] [unique_id "apPlndKCPt8cS-VWcMmMJgAAA8Q"]
[Sun Aug 30 03:11:09.018075 2026] [core:alert] [pid 519566:tid 519767] [client 190.164.205.155:46558] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:11:09.018397 2026] [security2:error] [pid 519566:tid 519820] [client 20.151.200.44:41897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/css/000.php"] [unique_id "apPlndKCPt8cS-VWcMmMKwAABB8"]
[Sun Aug 30 03:11:09.055055 2026] [security2:error] [pid 519566:tid 519775] [client 4.205.62.107:16357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/guk.php"] [unique_id "apPlndKCPt8cS-VWcMmMNQAAA_I"]
[Sun Aug 30 03:11:09.065615 2026] [security2:error] [pid 519566:tid 519701] [client 20.104.18.15:64757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/alfa.php"] [unique_id "apPlndKCPt8cS-VWcMmMPAAAA6g"]
[Sun Aug 30 03:11:09.065615 2026] [security2:error] [pid 519566:tid 519789] [client 20.104.50.220:61662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-site.php"] [unique_id "apPlndKCPt8cS-VWcMmMPQAABAA"]
[Sun Aug 30 03:11:09.076565 2026] [authz_core:error] [pid 519566:tid 519823] [client 66.249.66.36:62174] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:09.077032 2026] [authz_core:error] [pid 519566:tid 519823] [client 66.249.66.36:62174] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:09.085783 2026] [security2:error] [pid 519566:tid 519704] [client 20.48.160.90:51935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/indo.php"] [unique_id "apPlndKCPt8cS-VWcMmMQAAAA6s"]
[Sun Aug 30 03:11:09.096835 2026] [security2:error] [pid 519566:tid 519738] [client 158.23.184.117:32150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/bgymj.php"] [unique_id "apPlndKCPt8cS-VWcMmMQgAAA80"]
[Sun Aug 30 03:11:09.134928 2026] [security2:error] [pid 519566:tid 519807] [client 20.63.81.20:59038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp-cron.php"] [unique_id "apPlndKCPt8cS-VWcMmMSgAABBI"]
[Sun Aug 30 03:11:09.146281 2026] [security2:error] [pid 518600:tid 518785] [client 158.23.184.117:31788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/bk/index.php"] [unique_id "apPlne349Tv4SB45P2njvAAAALk"]
[Sun Aug 30 03:11:09.167566 2026] [core:alert] [pid 519566:tid 519759] [client 190.138.116.166:51152] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:11:09.177246 2026] [security2:error] [pid 519566:tid 519754] [client 40.83.93.50:7057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/options-reading.php"] [unique_id "apPlndKCPt8cS-VWcMmMUwAAA90"]
[Sun Aug 30 03:11:09.192931 2026] [security2:error] [pid 519566:tid 519703] [client 20.196.209.81:15087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/module.php"] [unique_id "apPlndKCPt8cS-VWcMmMWgAAA6o"]
[Sun Aug 30 03:11:09.219377 2026] [security2:error] [pid 519566:tid 519729] [client 20.48.160.90:46545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/sign.php"] [unique_id "apPlndKCPt8cS-VWcMmMXwAAA8Q"]
[Sun Aug 30 03:11:09.270390 2026] [security2:error] [pid 518600:tid 518782] [client 20.104.50.220:29137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-content/plugins/owfsmac/mar.php"] [unique_id "apPlne349Tv4SB45P2nj2wAAALY"]
[Sun Aug 30 03:11:09.271666 2026] [security2:error] [pid 519566:tid 519719] [client 20.63.81.20:58959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/lock360.php"] [unique_id "apPlndKCPt8cS-VWcMmMawAAA7o"]
[Sun Aug 30 03:11:09.287529 2026] [security2:error] [pid 518600:tid 518779] [client 158.23.184.117:31801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/bootstrap.php"] [unique_id "apPlne349Tv4SB45P2nj4AAAALM"]
[Sun Aug 30 03:11:09.288770 2026] [security2:error] [pid 518600:tid 518788] [client 20.63.219.114:19187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/favicon.php"] [unique_id "apPlne349Tv4SB45P2nj4gAAALw"]
[Sun Aug 30 03:11:09.338863 2026] [security2:error] [pid 518600:tid 518795] [client 40.83.93.50:22085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/error.php"] [unique_id "apPlne349Tv4SB45P2nj9QAAAMM"]
[Sun Aug 30 03:11:09.369209 2026] [security2:error] [pid 519566:tid 519716] [client 20.48.160.90:51952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/wnnjpsby.php"] [unique_id "apPlndKCPt8cS-VWcMmMiwAAA7c"]
[Sun Aug 30 03:11:09.375870 2026] [authz_core:error] [pid 518600:tid 518812] [client 216.73.216.128:2230] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:09.376287 2026] [authz_core:error] [pid 518600:tid 518812] [client 216.73.216.128:2230] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:09.380628 2026] [authz_core:error] [pid 519566:tid 519739] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:09.380924 2026] [authz_core:error] [pid 519566:tid 519739] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:09.392061 2026] [security2:error] [pid 519566:tid 519731] [client 68.155.159.216:52555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-admin/index.php"] [unique_id "apPlndKCPt8cS-VWcMmMjwAAA8Y"]
[Sun Aug 30 03:11:09.404962 2026] [security2:error] [pid 518600:tid 518827] [client 20.63.81.20:59042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp-theme.php"] [unique_id "apPlne349Tv4SB45P2nkAwAAAOM"]
[Sun Aug 30 03:11:09.426563 2026] [authz_core:error] [pid 519566:tid 519784] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fvar%2Flog
[Sun Aug 30 03:11:09.426849 2026] [authz_core:error] [pid 519566:tid 519784] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fvar%2Flog
[Sun Aug 30 03:11:09.428049 2026] [security2:error] [pid 518600:tid 518833] [client 158.23.184.117:32144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/bs1.php"] [unique_id "apPlne349Tv4SB45P2nkBwAAAOk"]
[Sun Aug 30 03:11:09.466609 2026] [authz_core:error] [pid 519566:tid 519817] [client 216.73.216.128:45868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:09.467047 2026] [authz_core:error] [pid 519566:tid 519817] [client 216.73.216.128:45868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:09.500111 2026] [security2:error] [pid 518600:tid 518807] [client 20.48.160.90:28127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/gigi.php"] [unique_id "apPlne349Tv4SB45P2nkFwAAAM8"]
[Sun Aug 30 03:11:09.526822 2026] [security2:error] [pid 519566:tid 519770] [client 156.245.246.131:63895] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "lenoreashwood.com"] [uri "/wp-comments-post.php"] [unique_id "apPlndKCPt8cS-VWcMmMpwAAA-0"], referer: https://lenoreashwood.com
[Sun Aug 30 03:11:09.538240 2026] [security2:error] [pid 518600:tid 518737] [client 20.63.81.20:58961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/2d7433/index.php"] [unique_id "apPlne349Tv4SB45P2nkHgAAAIk"]
[Sun Aug 30 03:11:09.541970 2026] [security2:error] [pid 518600:tid 518782] [client 20.104.50.220:63492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/fpebr.php"] [unique_id "apPlne349Tv4SB45P2nkIAAAALY"]
[Sun Aug 30 03:11:09.559097 2026] [authz_core:error] [pid 518600:tid 518849] [client 216.73.216.128:60050] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:09.559534 2026] [authz_core:error] [pid 518600:tid 518849] [client 216.73.216.128:60050] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:09.568673 2026] [security2:error] [pid 519566:tid 519816] [client 158.23.184.117:31777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/bthil.php"] [unique_id "apPlndKCPt8cS-VWcMmMugAABBs"]
[Sun Aug 30 03:11:09.583948 2026] [security2:error] [pid 519566:tid 519746] [client 20.151.200.44:40854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/pb.php"] [unique_id "apPlndKCPt8cS-VWcMmMwwAAA9U"]
[Sun Aug 30 03:11:09.586188 2026] [security2:error] [pid 519566:tid 519705] [client 20.196.209.81:21735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/ms-files.php"] [unique_id "apPlndKCPt8cS-VWcMmMxQAAA6w"]
[Sun Aug 30 03:11:09.589130 2026] [security2:error] [pid 519566:tid 519806] [client 20.104.50.220:29177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/help.php"] [unique_id "apPlndKCPt8cS-VWcMmMyQAABBE"]
[Sun Aug 30 03:11:09.597148 2026] [security2:error] [pid 519566:tid 519740] [client 52.139.37.240:43122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/403.php"] [unique_id "apPlndKCPt8cS-VWcMmMyAAAA88"]
[Sun Aug 30 03:11:09.598106 2026] [security2:error] [pid 519566:tid 519767] [client 20.104.18.15:18182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/shiny.php"] [unique_id "apPlndKCPt8cS-VWcMmM0AAAA-o"]
[Sun Aug 30 03:11:09.633252 2026] [security2:error] [pid 518600:tid 518754] [client 20.48.160.90:28147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/info.php/new.php"] [unique_id "apPlne349Tv4SB45P2nkNgAAAJo"]
[Sun Aug 30 03:11:09.639344 2026] [security2:error] [pid 518600:tid 518819] [client 20.104.50.220:16764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "apPlne349Tv4SB45P2nkOAAAANs"]
[Sun Aug 30 03:11:09.648729 2026] [security2:error] [pid 518600:tid 518829] [client 20.104.50.220:32869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/olu.php"] [unique_id "apPlne349Tv4SB45P2nkPAAAAOU"]
[Sun Aug 30 03:11:09.663709 2026] [security2:error] [pid 519566:tid 519701] [client 20.104.50.220:31536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/gettest.php"] [unique_id "apPlndKCPt8cS-VWcMmM3AAAA6g"]
[Sun Aug 30 03:11:09.667360 2026] [security2:error] [pid 519566:tid 519807] [client 20.63.219.114:2073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/gecko.php"] [unique_id "apPlndKCPt8cS-VWcMmM3wAABBI"]
[Sun Aug 30 03:11:09.668449 2026] [security2:error] [pid 518600:tid 518847] [client 20.48.251.3:64267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "apPlne349Tv4SB45P2nkQgAAAPc"]
[Sun Aug 30 03:11:09.669109 2026] [security2:error] [pid 518600:tid 518845] [client 20.63.81.20:59011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp-login.php"] [unique_id "apPlne349Tv4SB45P2nkRAAAAPU"]
[Sun Aug 30 03:11:09.669212 2026] [security2:error] [pid 518600:tid 518798] [client 40.83.93.50:7093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/db.php"] [unique_id "apPlne349Tv4SB45P2nkRQAAAMY"]
[Sun Aug 30 03:11:09.675111 2026] [security2:error] [pid 518600:tid 518806] [client 20.104.50.220:6089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/sessions.php"] [unique_id "apPlne349Tv4SB45P2nkSQAAAM4"]
[Sun Aug 30 03:11:09.679979 2026] [security2:error] [pid 519566:tid 519753] [client 158.23.147.79:16355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apPlndKCPt8cS-VWcMmM4gAAA9w"]
[Sun Aug 30 03:11:09.698227 2026] [security2:error] [pid 519566:tid 519722] [client 158.23.147.79:57664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/bk/index.php"] [unique_id "apPlndKCPt8cS-VWcMmM5AAAA70"]
[Sun Aug 30 03:11:09.708419 2026] [security2:error] [pid 518600:tid 518752] [client 158.23.184.117:32159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/buy.php"] [unique_id "apPlne349Tv4SB45P2nkTwAAAJg"]
[Sun Aug 30 03:11:09.728823 2026] [security2:error] [pid 519566:tid 519714] [client 158.23.147.79:39142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlndKCPt8cS-VWcMmM7AAAA7U"]
[Sun Aug 30 03:11:09.742595 2026] [authz_core:error] [pid 519566:tid 519793] [client 66.249.66.41:38493] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:09.742880 2026] [authz_core:error] [pid 519566:tid 519793] [client 66.249.66.41:38493] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:09.743995 2026] [security2:error] [pid 519566:tid 519770] [client 156.245.246.131:63895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "lenoreashwood.com"] [uri "/wp-comments-post.php"] [unique_id "apPlndKCPt8cS-VWcMmMpwAAA-0"], referer: https://lenoreashwood.com
[Sun Aug 30 03:11:09.755628 2026] [authz_core:error] [pid 518600:tid 518745] [client 66.249.66.205:56246] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:09.755921 2026] [authz_core:error] [pid 518600:tid 518745] [client 66.249.66.205:56246] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:09.779942 2026] [autoindex:error] [pid 518600:tid 518842] [client 20.48.160.90:51847] AH01276: Cannot serve directory /home2/dirkhoag/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:11:09.796592 2026] [security2:error] [pid 518600:tid 518843] [client 20.63.81.20:59103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/images.php"] [unique_id "apPlne349Tv4SB45P2nkZwAAAPM"]
[Sun Aug 30 03:11:09.802367 2026] [security2:error] [pid 518600:tid 518797] [client 52.139.37.240:13828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/av.php"] [unique_id "apPlne349Tv4SB45P2nkZgAAAMU"]
[Sun Aug 30 03:11:09.817701 2026] [security2:error] [pid 519566:tid 519769] [client 4.205.62.107:52801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/rem.php"] [unique_id "apPlndKCPt8cS-VWcMmNAQAAA-w"]
[Sun Aug 30 03:11:09.820033 2026] [security2:error] [pid 519566:tid 519761] [client 20.48.251.3:36850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/saiga.php"] [unique_id "apPlndKCPt8cS-VWcMmNAgAAA-Q"]
[Sun Aug 30 03:11:09.826431 2026] [security2:error] [pid 518600:tid 518786] [client 20.104.18.15:22498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/x.php"] [unique_id "apPlne349Tv4SB45P2nkcgAAALo"]
[Sun Aug 30 03:11:09.833399 2026] [security2:error] [pid 519566:tid 519823] [client 158.23.147.79:39110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlndKCPt8cS-VWcMmNCgAABCI"]
[Sun Aug 30 03:11:09.834790 2026] [security2:error] [pid 518600:tid 518769] [client 40.83.93.50:6342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/profile.php"] [unique_id "apPlne349Tv4SB45P2nkcwAAAKk"]
[Sun Aug 30 03:11:09.844325 2026] [authz_core:error] [pid 519566:tid 519711] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:09.844724 2026] [authz_core:error] [pid 519566:tid 519711] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:09.847670 2026] [security2:error] [pid 519566:tid 519732] [client 158.23.184.117:31807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/byp.php"] [unique_id "apPlndKCPt8cS-VWcMmNDwAAA8c"]
[Sun Aug 30 03:11:09.874669 2026] [security2:error] [pid 518600:tid 518855] [client 20.48.160.90:51847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/w.php"] [unique_id "apPlne349Tv4SB45P2nkegAAAP8"]
[Sun Aug 30 03:11:09.879232 2026] [security2:error] [pid 519566:tid 519760] [client 4.205.62.107:17683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/aws_sdk_settings.php"] [unique_id "apPlndKCPt8cS-VWcMmNEgAAA-M"]
[Sun Aug 30 03:11:09.888835 2026] [security2:error] [pid 519566:tid 519817] [client 20.151.200.44:64794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/admin.php/csv.php"] [unique_id "apPlndKCPt8cS-VWcMmNFwAABBw"]
[Sun Aug 30 03:11:09.910561 2026] [rewrite:warn] [pid 518600:tid 518697] AH00665: RewriteCond: NoCase option for non-regex pattern '-d' is not supported and will be ignored. (/home3/keilan/public_html/.htaccess:12)
[Sun Aug 30 03:11:09.910573 2026] [rewrite:warn] [pid 518600:tid 518697] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home3/keilan/public_html/.htaccess:13)
[Sun Aug 30 03:11:09.921999 2026] [security2:error] [pid 519566:tid 519697] [client 68.155.159.216:57087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apPlndKCPt8cS-VWcMmNIAAAA6Q"]
[Sun Aug 30 03:11:09.923005 2026] [security2:error] [pid 519566:tid 519819] [client 20.63.81.20:59032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/ops.php"] [unique_id "apPlndKCPt8cS-VWcMmNIQAABB4"]
[Sun Aug 30 03:11:09.927902 2026] [security2:error] [pid 519566:tid 519706] [client 20.48.251.3:55767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/plss3.php"] [unique_id "apPlndKCPt8cS-VWcMmNIwAAA60"]
[Sun Aug 30 03:11:09.929927 2026] [security2:error] [pid 519566:tid 519808] [client 4.205.62.107:36032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/wp-info.php"] [unique_id "apPlndKCPt8cS-VWcMmNJAAABBM"]
[Sun Aug 30 03:11:09.943057 2026] [authz_core:error] [pid 519566:tid 519792] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fvar%2Flog
[Sun Aug 30 03:11:09.943568 2026] [authz_core:error] [pid 519566:tid 519792] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fvar%2Flog
[Sun Aug 30 03:11:09.956900 2026] [security2:error] [pid 518600:tid 518806] [client 20.104.49.130:53506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/classwithtostring.php"] [unique_id "apPlne349Tv4SB45P2nkjwAAAM4"]
[Sun Aug 30 03:11:09.979330 2026] [security2:error] [pid 518600:tid 518741] [client 20.196.209.81:15043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/news-portal/error.php"] [unique_id "apPlne349Tv4SB45P2nklQAAAI0"]
[Sun Aug 30 03:11:09.985967 2026] [security2:error] [pid 519566:tid 519731] [client 20.104.18.15:31736] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "gtepetrochem.com"] [uri "/1.php"] [unique_id "apPlndKCPt8cS-VWcMmNMwAAA8Y"]
[Sun Aug 30 03:11:09.986046 2026] [security2:error] [pid 519566:tid 519731] [client 20.104.18.15:31736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/1.php"] [unique_id "apPlndKCPt8cS-VWcMmNMwAAA8Y"]
[Sun Aug 30 03:11:09.986787 2026] [security2:error] [pid 519566:tid 519708] [client 158.23.184.117:32134] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "dejulschoolofdance.com"] [uri "/c99.php"] [unique_id "apPlndKCPt8cS-VWcMmNNAAAA68"]
[Sun Aug 30 03:11:10.002450 2026] [security2:error] [pid 519566:tid 519814] [client 52.139.37.240:14031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/wp-admin/index.php"] [unique_id "apPlndKCPt8cS-VWcMmNNgAABBk"]
[Sun Aug 30 03:11:10.006530 2026] [security2:error] [pid 518600:tid 518846] [client 4.205.62.107:26985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/h.php"] [unique_id "apPlnu349Tv4SB45P2nknwAAAPY"]
[Sun Aug 30 03:11:10.014027 2026] [security2:error] [pid 519566:tid 519728] [client 158.23.147.79:43608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apPlntKCPt8cS-VWcMmNOQAAA8M"]
[Sun Aug 30 03:11:10.021721 2026] [security2:error] [pid 519566:tid 519698] [client 20.48.160.90:28114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/x.php"] [unique_id "apPlntKCPt8cS-VWcMmNOwAAA6U"]
[Sun Aug 30 03:11:10.057992 2026] [security2:error] [pid 519566:tid 519734] [client 20.63.81.20:59126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPlntKCPt8cS-VWcMmNQQAAA8k"]
[Sun Aug 30 03:11:10.078398 2026] [security2:error] [pid 519566:tid 519741] [client 20.63.219.114:15177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/ioxi-o.php"] [unique_id "apPlntKCPt8cS-VWcMmNRQAAA9A"]
[Sun Aug 30 03:11:10.110998 2026] [security2:error] [pid 519566:tid 519756] [client 158.23.147.79:43625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-content/plugins/index.php"] [unique_id "apPlntKCPt8cS-VWcMmNUAAAA98"]
[Sun Aug 30 03:11:10.125373 2026] [security2:error] [pid 519566:tid 519739] [client 158.23.184.117:31784] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "dejulschoolofdance.com"] [uri "/c99.php"] [unique_id "apPlntKCPt8cS-VWcMmNUwAAA84"]
[Sun Aug 30 03:11:10.149111 2026] [security2:error] [pid 519566:tid 519754] [client 40.83.93.50:22106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/server.php"] [unique_id "apPlntKCPt8cS-VWcMmNWQAAA90"]
[Sun Aug 30 03:11:10.160417 2026] [security2:error] [pid 519566:tid 519779] [client 20.48.251.3:59901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/setup-config.php"] [unique_id "apPlntKCPt8cS-VWcMmNXQAAA_Y"]
[Sun Aug 30 03:11:10.194740 2026] [security2:error] [pid 519566:tid 519801] [client 4.205.62.107:15947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/config_dev.php"] [unique_id "apPlntKCPt8cS-VWcMmNZgAABAw"]
[Sun Aug 30 03:11:10.195253 2026] [security2:error] [pid 519566:tid 519725] [client 20.63.81.20:58965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPlntKCPt8cS-VWcMmNZwAAA8A"]
[Sun Aug 30 03:11:10.204637 2026] [security2:error] [pid 518600:tid 518784] [client 20.104.18.15:17019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/33.php"] [unique_id "apPlnu349Tv4SB45P2nkxgAAALg"]
[Sun Aug 30 03:11:10.213415 2026] [security2:error] [pid 519566:tid 519697] [client 52.139.37.240:13829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "apPlntKCPt8cS-VWcMmNagAAA6Q"]
[Sun Aug 30 03:11:10.218519 2026] [security2:error] [pid 519566:tid 519729] [client 20.48.160.90:28133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/ssla.php"] [unique_id "apPlntKCPt8cS-VWcMmNbAAAA8Q"]
[Sun Aug 30 03:11:10.224058 2026] [security2:error] [pid 519566:tid 519814] [client 158.23.147.79:39309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/simple.php"] [unique_id "apPlntKCPt8cS-VWcMmNcAAABBk"]
[Sun Aug 30 03:11:10.263031 2026] [security2:error] [pid 519566:tid 519823] [client 20.104.50.220:61413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-system.php"] [unique_id "apPlntKCPt8cS-VWcMmNdgAABCI"]
[Sun Aug 30 03:11:10.264291 2026] [security2:error] [pid 518600:tid 518853] [client 158.23.184.117:32153] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "dejulschoolofdance.com"] [uri "/c99.php"] [unique_id "apPlnu349Tv4SB45P2nk1wAAAP0"]
[Sun Aug 30 03:11:10.319852 2026] [security2:error] [pid 519566:tid 519796] [client 40.83.93.50:7071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/sql.php"] [unique_id "apPlntKCPt8cS-VWcMmNhQAABAc"]
[Sun Aug 30 03:11:10.335364 2026] [security2:error] [pid 519566:tid 519768] [client 158.23.147.79:43058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-admin/about.php"] [unique_id "apPlntKCPt8cS-VWcMmNkAAAA-s"]
[Sun Aug 30 03:11:10.340486 2026] [security2:error] [pid 518600:tid 518828] [client 20.63.81.20:59022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/about.php"] [unique_id "apPlnu349Tv4SB45P2nk9wAAAOQ"]
[Sun Aug 30 03:11:10.350339 2026] [security2:error] [pid 519566:tid 519719] [client 20.48.160.90:51845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apPlntKCPt8cS-VWcMmNlQAAA7o"]
[Sun Aug 30 03:11:10.394656 2026] [authz_core:error] [pid 519566:tid 519698] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:10.395086 2026] [authz_core:error] [pid 519566:tid 519698] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:10.403402 2026] [security2:error] [pid 518600:tid 518781] [client 20.196.209.81:21754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/nvt/includes/plugins/wp-blog-header.php"] [unique_id "apPlnu349Tv4SB45P2nlCwAAALU"]
[Sun Aug 30 03:11:10.419180 2026] [security2:error] [pid 519566:tid 519716] [client 52.139.37.240:13831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/wp-content/themes/pridmag/b.php"] [unique_id "apPlntKCPt8cS-VWcMmNowAAA7c"]
[Sun Aug 30 03:11:10.420232 2026] [security2:error] [pid 518600:tid 518763] [client 158.23.147.79:2014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.ballroomology.com"] [uri "/first.php"] [unique_id "apPlnu349Tv4SB45P2nlDgAAAKM"]
[Sun Aug 30 03:11:10.443744 2026] [security2:error] [pid 519566:tid 519701] [client 20.63.219.114:2109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.219.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mirlabs.com"] [uri "/lock.php"] [unique_id "apPlntKCPt8cS-VWcMmNqQAAA6g"]
[Sun Aug 30 03:11:10.444868 2026] [security2:error] [pid 519566:tid 519723] [client 20.104.50.220:29166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/tersembunyi.php"] [unique_id "apPlntKCPt8cS-VWcMmNqgAAA74"]
[Sun Aug 30 03:11:10.465260 2026] [authz_core:error] [pid 519566:tid 519732] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fopt%2Falt
[Sun Aug 30 03:11:10.465717 2026] [authz_core:error] [pid 519566:tid 519732] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fopt%2Falt
[Sun Aug 30 03:11:10.473625 2026] [authz_core:error] [pid 519566:tid 519809] [client 66.249.66.196:57293] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:10.473960 2026] [authz_core:error] [pid 519566:tid 519809] [client 66.249.66.196:57293] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:10.478860 2026] [security2:error] [pid 519566:tid 519722] [client 20.48.160.90:51930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/wp-aothait.php"] [unique_id "apPlntKCPt8cS-VWcMmNugAAA70"]
[Sun Aug 30 03:11:10.480926 2026] [security2:error] [pid 519566:tid 519805] [client 20.63.81.20:59087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/admin.php/admin.php"] [unique_id "apPlntKCPt8cS-VWcMmNuwAABBA"]
[Sun Aug 30 03:11:10.482869 2026] [security2:error] [pid 519566:tid 519753] [client 158.23.147.79:43594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-content/uploads/index.php"] [unique_id "apPlntKCPt8cS-VWcMmNvQAAA9w"]
[Sun Aug 30 03:11:10.587724 2026] [security2:error] [pid 519566:tid 519763] [client 20.104.49.130:52417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/well.php"] [unique_id "apPlntKCPt8cS-VWcMmN4wAAA-Y"]
[Sun Aug 30 03:11:10.588999 2026] [authz_core:error] [pid 519566:tid 519735] [client 66.249.66.67:39161] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:10.589284 2026] [authz_core:error] [pid 519566:tid 519735] [client 66.249.66.67:39161] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:10.612415 2026] [security2:error] [pid 519566:tid 519722] [client 20.48.160.90:51862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/wp-includes/index.php"] [unique_id "apPlntKCPt8cS-VWcMmN6gAAA70"]
[Sun Aug 30 03:11:10.629604 2026] [security2:error] [pid 518600:tid 518800] [client 40.83.93.50:10717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/favicon.php"] [unique_id "apPlnu349Tv4SB45P2nlOwAAAMg"]
[Sun Aug 30 03:11:10.642614 2026] [security2:error] [pid 519566:tid 519795] [client 20.63.81.20:59015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/media.php"] [unique_id "apPlntKCPt8cS-VWcMmN7gAABAY"]
[Sun Aug 30 03:11:10.655015 2026] [authz_core:error] [pid 519566:tid 519714] [client 216.73.216.128:45868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:10.655480 2026] [authz_core:error] [pid 519566:tid 519714] [client 216.73.216.128:45868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:10.690281 2026] [security2:error] [pid 518600:tid 518749] [client 20.104.50.220:51580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/snd21.php"] [unique_id "apPlnu349Tv4SB45P2nlRwAAAJU"]
[Sun Aug 30 03:11:10.692236 2026] [security2:error] [pid 518600:tid 518748] [client 158.23.147.79:43037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apPlnu349Tv4SB45P2nlSAAAAJQ"]
[Sun Aug 30 03:11:10.719876 2026] [security2:error] [pid 519566:tid 519765] [client 68.155.159.216:45846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPlntKCPt8cS-VWcMmN_QAAA-g"]
[Sun Aug 30 03:11:10.749640 2026] [security2:error] [pid 519566:tid 519799] [client 52.139.37.240:14065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/0.php"] [unique_id "apPlntKCPt8cS-VWcMmOAgAABAo"]
[Sun Aug 30 03:11:10.758246 2026] [security2:error] [pid 519566:tid 519800] [client 158.23.184.117:31805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/cache/cache/min.php"] [unique_id "apPlntKCPt8cS-VWcMmOCQAABAs"]
[Sun Aug 30 03:11:10.759194 2026] [security2:error] [pid 519566:tid 519750] [client 20.104.18.15:18349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/goods.php"] [unique_id "apPlntKCPt8cS-VWcMmOCgAAA9k"]
[Sun Aug 30 03:11:10.759769 2026] [security2:error] [pid 519566:tid 519800] [client 20.48.160.90:46569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/file31.php"] [unique_id "apPlntKCPt8cS-VWcMmOCwAABAs"]
[Sun Aug 30 03:11:10.772940 2026] [security2:error] [pid 518600:tid 518802] [client 68.155.159.216:52332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPlnu349Tv4SB45P2nlVwAAAMo"]
[Sun Aug 30 03:11:10.777729 2026] [security2:error] [pid 518600:tid 518814] [client 20.104.50.220:17335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/.well-known/admin.php"] [unique_id "apPlnu349Tv4SB45P2nlWAAAANY"]
[Sun Aug 30 03:11:10.789170 2026] [security2:error] [pid 518600:tid 518779] [client 20.63.81.20:59127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/mac.php"] [unique_id "apPlnu349Tv4SB45P2nlWQAAALM"]
[Sun Aug 30 03:11:10.791397 2026] [security2:error] [pid 518600:tid 518818] [client 40.83.93.50:6385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/index.bak.php"] [unique_id "apPlnu349Tv4SB45P2nlWgAAANo"]
[Sun Aug 30 03:11:10.796675 2026] [security2:error] [pid 519566:tid 519823] [client 20.104.50.220:33325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/tuco.php"] [unique_id "apPlntKCPt8cS-VWcMmOEQAABCI"]
[Sun Aug 30 03:11:10.801401 2026] [security2:error] [pid 519566:tid 519720] [client 20.196.209.81:11909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/oceanwp/sass/components/plugins/panel.php"] [unique_id "apPlntKCPt8cS-VWcMmOFAAAA7s"]
[Sun Aug 30 03:11:10.812818 2026] [security2:error] [pid 518600:tid 518769] [client 20.104.50.220:5545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/rss.php"] [unique_id "apPlnu349Tv4SB45P2nlZAAAAKk"]
[Sun Aug 30 03:11:10.819961 2026] [security2:error] [pid 519566:tid 519820] [client 20.104.50.220:59353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-content/BypassBest.php"] [unique_id "apPlntKCPt8cS-VWcMmOGQAABB8"]
[Sun Aug 30 03:11:10.823546 2026] [security2:error] [pid 518600:tid 518852] [client 20.48.251.3:54766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/myfile.php"] [unique_id "apPlnu349Tv4SB45P2nlagAAAPw"]
[Sun Aug 30 03:11:10.826336 2026] [security2:error] [pid 518600:tid 518809] [client 216.73.216.128:2230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_takeaddr_screen"] [unique_id "apPlnu349Tv4SB45P2nlawAAANE"]
[Sun Aug 30 03:11:10.845104 2026] [security2:error] [pid 519566:tid 519702] [client 158.23.147.79:16354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-content/uploads/about.php"] [unique_id "apPlntKCPt8cS-VWcMmOIgAAA6k"]
[Sun Aug 30 03:11:10.845311 2026] [security2:error] [pid 519566:tid 519803] [client 158.23.147.79:39127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/chosen.php"] [unique_id "apPlntKCPt8cS-VWcMmOIQAABA4"]
[Sun Aug 30 03:11:10.871942 2026] [authz_core:error] [pid 519566:tid 519779] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:10.872330 2026] [authz_core:error] [pid 519566:tid 519779] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:10.908215 2026] [security2:error] [pid 519566:tid 519807] [client 158.23.184.117:31751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/catalogbypass.php"] [unique_id "apPlntKCPt8cS-VWcMmOMAAABBI"]
[Sun Aug 30 03:11:10.917575 2026] [security2:error] [pid 518600:tid 518789] [client 20.63.81.20:59129] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.wholebeingportland.com"] [uri "/1.php"] [unique_id "apPlnu349Tv4SB45P2nlfwAAAL0"]
[Sun Aug 30 03:11:10.917714 2026] [security2:error] [pid 518600:tid 518789] [client 20.63.81.20:59129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/1.php"] [unique_id "apPlnu349Tv4SB45P2nlfwAAAL0"]
[Sun Aug 30 03:11:10.931271 2026] [security2:error] [pid 519566:tid 519801] [client 20.48.160.90:28060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/dk.php"] [unique_id "apPlntKCPt8cS-VWcMmONQAABAw"]
[Sun Aug 30 03:11:10.953761 2026] [security2:error] [pid 519566:tid 519799] [client 20.104.49.130:63506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/666.php"] [unique_id "apPlntKCPt8cS-VWcMmOOwAABAo"]
[Sun Aug 30 03:11:10.954720 2026] [security2:error] [pid 519566:tid 519815] [client 52.139.37.240:44589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/autoload_classmap/function.php"] [unique_id "apPlntKCPt8cS-VWcMmONgAABBo"]
[Sun Aug 30 03:11:10.956265 2026] [security2:error] [pid 519566:tid 519770] [client 4.205.62.107:52892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/min.php"] [unique_id "apPlntKCPt8cS-VWcMmOPAAAA-0"]
[Sun Aug 30 03:11:10.959403 2026] [authz_core:error] [pid 519566:tid 519708] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fvar%2Fspool
[Sun Aug 30 03:11:10.959838 2026] [authz_core:error] [pid 519566:tid 519708] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fvar%2Fspool
[Sun Aug 30 03:11:10.960398 2026] [security2:error] [pid 518600:tid 518807] [client 158.23.147.79:43605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/goods.php"] [unique_id "apPlnu349Tv4SB45P2nliQAAAM8"]
[Sun Aug 30 03:11:10.962528 2026] [security2:error] [pid 519566:tid 519781] [client 20.48.251.3:36823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/ammika.php"] [unique_id "apPlntKCPt8cS-VWcMmOPwAAA_g"]
[Sun Aug 30 03:11:10.975354 2026] [security2:error] [pid 518600:tid 518735] [client 20.104.18.15:22433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/ssla.php"] [unique_id "apPlnu349Tv4SB45P2nlkAAAAIc"]
[Sun Aug 30 03:11:11.016650 2026] [security2:error] [pid 518600:tid 518841] [client 4.205.62.107:17409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/setup-config.php"] [unique_id "apPln-349Tv4SB45P2nlmQAAAPE"]
[Sun Aug 30 03:11:11.018470 2026] [authz_core:error] [pid 518600:tid 518756] [client 216.73.216.128:52324] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:11.018918 2026] [authz_core:error] [pid 518600:tid 518756] [client 216.73.216.128:52324] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:11.034275 2026] [lsapi:error] [pid 519566:tid 519588] [remote 76.31.145.178:33282] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.bing.com/
[Sun Aug 30 03:11:11.034445 2026] [lsapi:error] [pid 519566:tid 519588] [remote 76.31.145.178:33282] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.bing.com/
[Sun Aug 30 03:11:11.036022 2026] [lsapi:error] [pid 519566:tid 519588] [remote 76.31.145.178:33282] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n, referer: https://www.bing.com/
[Sun Aug 30 03:11:11.049833 2026] [security2:error] [pid 519566:tid 519744] [client 158.23.184.117:31794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/cc.php"] [unique_id "apPln9KCPt8cS-VWcMmOUgAAA9M"]
[Sun Aug 30 03:11:11.049835 2026] [security2:error] [pid 518600:tid 518790] [client 20.63.81.20:59074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/classwithtostring.php"] [unique_id "apPln-349Tv4SB45P2nlnwAAAL4"]
[Sun Aug 30 03:11:11.065491 2026] [security2:error] [pid 518600:tid 518799] [client 20.48.160.90:51955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/ta.php"] [unique_id "apPln-349Tv4SB45P2nlpAAAAMc"]
[Sun Aug 30 03:11:11.066457 2026] [security2:error] [pid 518600:tid 518743] [client 20.48.251.3:55690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/aws.php"] [unique_id "apPln-349Tv4SB45P2nlpQAAAI8"]
[Sun Aug 30 03:11:11.098353 2026] [security2:error] [pid 518600:tid 518855] [client 158.23.147.79:43632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apPln-349Tv4SB45P2nlqgAAAP8"]
[Sun Aug 30 03:11:11.107519 2026] [security2:error] [pid 518600:tid 518840] [client 20.104.49.130:58079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/bolt.php"] [unique_id "apPln-349Tv4SB45P2nlrgAAAPA"]
[Sun Aug 30 03:11:11.121518 2026] [security2:error] [pid 519566:tid 519745] [client 68.155.159.216:12258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/.well-knownold/index.php"] [unique_id "apPln9KCPt8cS-VWcMmOXgAAA9Q"]
[Sun Aug 30 03:11:11.134594 2026] [security2:error] [pid 518600:tid 518755] [client 20.104.18.15:31685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/m.php"] [unique_id "apPln-349Tv4SB45P2nltAAAAJs"]
[Sun Aug 30 03:11:11.154559 2026] [security2:error] [pid 519566:tid 519804] [client 4.205.62.107:26988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/bootstrap.php"] [unique_id "apPln9KCPt8cS-VWcMmObAAABA8"]
[Sun Aug 30 03:11:11.154920 2026] [security2:error] [pid 519566:tid 519762] [client 52.139.37.240:44578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/dvve.php"] [unique_id "apPln9KCPt8cS-VWcMmOagAAA-U"]
[Sun Aug 30 03:11:11.160462 2026] [security2:error] [pid 519566:tid 519748] [client 4.205.62.107:36565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/fns.php"] [unique_id "apPln9KCPt8cS-VWcMmObQAAA9c"]
[Sun Aug 30 03:11:11.189708 2026] [security2:error] [pid 519566:tid 519737] [client 158.23.184.117:32151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/cgi-bin/admin.php"] [unique_id "apPln9KCPt8cS-VWcMmOdgAAA8w"]
[Sun Aug 30 03:11:11.190676 2026] [authz_core:error] [pid 519566:tid 519786] [client 66.249.66.193:49197] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:11.190742 2026] [security2:error] [pid 519566:tid 519816] [client 20.63.81.20:59010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp-ws68.php"] [unique_id "apPln9KCPt8cS-VWcMmOdwAABBs"]
[Sun Aug 30 03:11:11.190986 2026] [authz_core:error] [pid 519566:tid 519786] [client 66.249.66.193:49197] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:11.191573 2026] [security2:error] [pid 519566:tid 519715] [client 20.196.209.81:11955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/options.php"] [unique_id "apPln9KCPt8cS-VWcMmOeAAAA7Y"]
[Sun Aug 30 03:11:11.209606 2026] [core:alert] [pid 518600:tid 518796] [client 165.16.188.62:8297] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:11:11.230291 2026] [security2:error] [pid 519566:tid 519724] [client 20.48.160.90:28069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/bo.php"] [unique_id "apPln9KCPt8cS-VWcMmOgAAAA78"]
[Sun Aug 30 03:11:11.250874 2026] [security2:error] [pid 519566:tid 519717] [client 158.23.147.79:39330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-admin/includes/nav.php"] [unique_id "apPln9KCPt8cS-VWcMmOigAAA7g"]
[Sun Aug 30 03:11:11.259301 2026] [authz_core:error] [pid 519566:tid 519752] [client 216.73.216.128:45868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:11.259747 2026] [authz_core:error] [pid 519566:tid 519752] [client 216.73.216.128:45868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:11.280050 2026] [security2:error] [pid 519566:tid 519706] [client 40.83.93.50:7074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/log.php"] [unique_id "apPln9KCPt8cS-VWcMmOkAAAA60"]
[Sun Aug 30 03:11:11.315078 2026] [security2:error] [pid 519566:tid 519729] [client 20.151.200.44:41952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/cy.php"] [unique_id "apPln9KCPt8cS-VWcMmOnQAAA8Q"]
[Sun Aug 30 03:11:11.318975 2026] [security2:error] [pid 519566:tid 519808] [client 20.63.81.20:59063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/simple.php"] [unique_id "apPln9KCPt8cS-VWcMmOngAABBM"]
[Sun Aug 30 03:11:11.333907 2026] [security2:error] [pid 519566:tid 519720] [client 4.205.62.107:16360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/aws_credentials.php"] [unique_id "apPln9KCPt8cS-VWcMmOpwAAA7s"]
[Sun Aug 30 03:11:11.342494 2026] [security2:error] [pid 518600:tid 518855] [client 20.104.18.15:64734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/133.php"] [unique_id "apPln-349Tv4SB45P2nl7AAAAP8"]
[Sun Aug 30 03:11:11.349212 2026] [security2:error] [pid 518600:tid 518781] [client 40.83.93.50:22117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/gecko.php"] [unique_id "apPln-349Tv4SB45P2nl7wAAALU"]
[Sun Aug 30 03:11:11.361612 2026] [security2:error] [pid 519566:tid 519733] [client 20.104.49.130:36763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/users.php"] [unique_id "apPln9KCPt8cS-VWcMmOtAAAA8g"]
[Sun Aug 30 03:11:11.370004 2026] [authz_core:error] [pid 518600:tid 518761] [client 66.249.66.70:61734] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:11.370342 2026] [authz_core:error] [pid 518600:tid 518761] [client 66.249.66.70:61734] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:11.378519 2026] [security2:error] [pid 519566:tid 519774] [client 158.23.147.79:39123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/file.php"] [unique_id "apPln9KCPt8cS-VWcMmOuwAAA_E"]
[Sun Aug 30 03:11:11.382552 2026] [autoindex:error] [pid 519566:tid 519725] [client 52.139.37.240:43110] AH01276: Cannot serve directory /home3/ragtimec/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:11:11.404382 2026] [security2:error] [pid 519566:tid 519703] [client 20.48.251.3:43134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-admin/sc.php"] [unique_id "apPln9KCPt8cS-VWcMmOwwAAA6o"]
[Sun Aug 30 03:11:11.409826 2026] [security2:error] [pid 519566:tid 519763] [client 20.48.160.90:28123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/44.php"] [unique_id "apPln9KCPt8cS-VWcMmOxgAAA-Y"]
[Sun Aug 30 03:11:11.412501 2026] [authz_core:error] [pid 519566:tid 519794] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:11.413063 2026] [authz_core:error] [pid 519566:tid 519794] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:11.426214 2026] [security2:error] [pid 519566:tid 519793] [client 20.104.49.130:63261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/crgio.php"] [unique_id "apPln9KCPt8cS-VWcMmOyAAABAQ"]
[Sun Aug 30 03:11:11.432983 2026] [authz_core:error] [pid 519566:tid 519700] [client 216.73.216.128:24387] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:11.433265 2026] [authz_core:error] [pid 519566:tid 519700] [client 216.73.216.128:24387] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:11.433711 2026] [authz_core:error] [pid 519566:tid 519801] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fvar%2Flib
[Sun Aug 30 03:11:11.434009 2026] [authz_core:error] [pid 519566:tid 519801] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fvar%2Flib
[Sun Aug 30 03:11:11.454159 2026] [security2:error] [pid 519566:tid 519772] [client 20.104.50.220:61431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-title.php"] [unique_id "apPln9KCPt8cS-VWcMmO0wAAA-8"]
[Sun Aug 30 03:11:11.458546 2026] [security2:error] [pid 519566:tid 519808] [client 52.139.37.240:43110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/ws77.php"] [unique_id "apPln9KCPt8cS-VWcMmO0QAABBM"]
[Sun Aug 30 03:11:11.465705 2026] [security2:error] [pid 519566:tid 519728] [client 20.63.81.20:59118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/aaa.php"] [unique_id "apPln9KCPt8cS-VWcMmO2AAAA8M"]
[Sun Aug 30 03:11:11.469391 2026] [authz_core:error] [pid 518600:tid 518831] [client 216.73.216.128:60050] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:11.469684 2026] [authz_core:error] [pid 518600:tid 518831] [client 216.73.216.128:60050] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:11.539623 2026] [security2:error] [pid 518600:tid 518805] [client 20.48.160.90:28149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/h2.php"] [unique_id "apPln-349Tv4SB45P2nmGgAAAM0"]
[Sun Aug 30 03:11:11.582287 2026] [security2:error] [pid 519566:tid 519804] [client 20.196.209.81:11964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/panel.php"] [unique_id "apPln9KCPt8cS-VWcMmPAAAABA8"]
[Sun Aug 30 03:11:11.619318 2026] [security2:error] [pid 519566:tid 519823] [client 158.23.147.79:43596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/file17.php"] [unique_id "apPln9KCPt8cS-VWcMmPEQAABCI"]
[Sun Aug 30 03:11:11.623878 2026] [security2:error] [pid 519566:tid 519777] [client 158.23.184.117:31782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/config.php"] [unique_id "apPln9KCPt8cS-VWcMmPEwAAA_Q"]
[Sun Aug 30 03:11:11.642689 2026] [security2:error] [pid 519566:tid 519734] [client 20.104.50.220:52851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/lab.php"] [unique_id "apPln9KCPt8cS-VWcMmPFQAAA8k"]
[Sun Aug 30 03:11:11.671175 2026] [security2:error] [pid 519566:tid 519816] [client 52.139.37.240:13886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/admin/function.php"] [unique_id "apPln9KCPt8cS-VWcMmPGgAABBs"]
[Sun Aug 30 03:11:11.672591 2026] [security2:error] [pid 519566:tid 519776] [client 20.48.160.90:28067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apPln9KCPt8cS-VWcMmPHwAAA_M"]
[Sun Aug 30 03:11:11.726551 2026] [security2:error] [pid 518600:tid 518736] [client 158.23.147.79:39151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/file5.php"] [unique_id "apPln-349Tv4SB45P2nmNAAAAIg"]
[Sun Aug 30 03:11:11.749614 2026] [authz_core:error] [pid 519566:tid 519745] [client 66.249.66.192:43508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:11.749887 2026] [authz_core:error] [pid 519566:tid 519745] [client 66.249.66.192:43508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:11.754220 2026] [security2:error] [pid 519566:tid 519808] [client 20.63.81.20:59041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/shiny.php"] [unique_id "apPln9KCPt8cS-VWcMmPLgAABBM"]
[Sun Aug 30 03:11:11.763779 2026] [security2:error] [pid 518600:tid 518836] [client 40.83.93.50:22084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/bak.php"] [unique_id "apPln-349Tv4SB45P2nmOwAAAOw"]
[Sun Aug 30 03:11:11.763800 2026] [security2:error] [pid 519566:tid 519730] [client 158.23.184.117:32142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/login.php"] [unique_id "apPln9KCPt8cS-VWcMmPMAAAA8U"]
[Sun Aug 30 03:11:11.809254 2026] [security2:error] [pid 518600:tid 518810] [client 20.48.160.90:51909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/sao.php"] [unique_id "apPln-349Tv4SB45P2nmRAAAANI"]
[Sun Aug 30 03:11:11.832852 2026] [security2:error] [pid 519566:tid 519733] [client 20.104.50.220:51531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/olu.php"] [unique_id "apPln9KCPt8cS-VWcMmPQQAAA8g"]
[Sun Aug 30 03:11:11.840701 2026] [security2:error] [pid 519566:tid 519820] [client 158.23.147.79:43644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/file88.php"] [unique_id "apPln9KCPt8cS-VWcMmPRwAABB8"]
[Sun Aug 30 03:11:11.864016 2026] [security2:error] [pid 519566:tid 519807] [client 40.83.93.50:10729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/ioxi-o.php"] [unique_id "apPln9KCPt8cS-VWcMmPSwAABBI"]
[Sun Aug 30 03:11:11.887423 2026] [authz_core:error] [pid 519566:tid 519812] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:11.887719 2026] [authz_core:error] [pid 519566:tid 519812] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:11.889422 2026] [security2:error] [pid 518600:tid 518816] [client 52.139.37.240:14050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/xx.php"] [unique_id "apPln-349Tv4SB45P2nmUwAAANg"]
[Sun Aug 30 03:11:11.889458 2026] [security2:error] [pid 519566:tid 519761] [client 20.63.81.20:59131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/goods.php"] [unique_id "apPln9KCPt8cS-VWcMmPUQAAA-Q"]
[Sun Aug 30 03:11:11.904693 2026] [security2:error] [pid 519566:tid 519791] [client 158.23.184.117:32135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/index.php"] [unique_id "apPln9KCPt8cS-VWcMmPVAAABAI"]
[Sun Aug 30 03:11:11.910623 2026] [security2:error] [pid 519566:tid 519800] [client 20.104.18.15:18178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/alfa.php"] [unique_id "apPln9KCPt8cS-VWcMmPVQAABAs"]
[Sun Aug 30 03:11:11.914702 2026] [security2:error] [pid 519566:tid 519785] [client 20.104.50.220:17317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-content/admin.php"] [unique_id "apPln9KCPt8cS-VWcMmPVgAAA_w"]
[Sun Aug 30 03:11:11.923595 2026] [authz_core:error] [pid 519566:tid 519819] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare
[Sun Aug 30 03:11:11.923958 2026] [authz_core:error] [pid 519566:tid 519819] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare
[Sun Aug 30 03:11:11.933698 2026] [security2:error] [pid 518600:tid 518844] [client 20.104.50.220:33291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/ice.php"] [unique_id "apPln-349Tv4SB45P2nmWgAAAPQ"]
[Sun Aug 30 03:11:11.938579 2026] [security2:error] [pid 518600:tid 518839] [client 216.73.216.128:52324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPln-349Tv4SB45P2nmXQAAAO8"]
[Sun Aug 30 03:11:11.949226 2026] [security2:error] [pid 519566:tid 519735] [client 158.23.147.79:39315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/NewFile.php/"] [unique_id "apPln9KCPt8cS-VWcMmPXgAAA8o"]
[Sun Aug 30 03:11:11.960968 2026] [security2:error] [pid 519566:tid 519763] [client 20.48.251.3:64295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/lm15.php"] [unique_id "apPln9KCPt8cS-VWcMmPYAAAA-Y"]
[Sun Aug 30 03:11:11.962029 2026] [security2:error] [pid 518600:tid 518770] [client 20.104.50.220:6133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/sitemaps.php"] [unique_id "apPln-349Tv4SB45P2nmZgAAAKo"]
[Sun Aug 30 03:11:11.972432 2026] [security2:error] [pid 519566:tid 519789] [client 20.196.209.81:19199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/reboot/assets/js/plugins/home.php"] [unique_id "apPln9KCPt8cS-VWcMmPZAAABAA"]
[Sun Aug 30 03:11:11.975454 2026] [security2:error] [pid 519566:tid 519716] [client 20.151.200.44:62986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPln9KCPt8cS-VWcMmPZgAAA7c"]
[Sun Aug 30 03:11:11.982017 2026] [security2:error] [pid 519566:tid 519730] [client 20.104.49.130:63599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wdfjba.org"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPln9KCPt8cS-VWcMmPaQAAA8U"]
[Sun Aug 30 03:11:11.985683 2026] [security2:error] [pid 518600:tid 518804] [client 20.48.160.90:46585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/dapa.php"] [unique_id "apPln-349Tv4SB45P2nmbQAAAMw"]
[Sun Aug 30 03:11:12.000588 2026] [security2:error] [pid 518600:tid 518746] [client 68.155.159.216:52297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/about.php"] [unique_id "apPloO349Tv4SB45P2nmcwAAAJI"]
[Sun Aug 30 03:11:12.003669 2026] [security2:error] [pid 519566:tid 519720] [client 20.104.50.220:29606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/high.php"] [unique_id "apPloNKCPt8cS-VWcMmPbgAAA7s"]
[Sun Aug 30 03:11:12.018780 2026] [security2:error] [pid 519566:tid 519733] [client 20.63.81.20:58952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/000.php/index.php"] [unique_id "apPloNKCPt8cS-VWcMmPcgAAA8g"]
[Sun Aug 30 03:11:12.064005 2026] [security2:error] [pid 519566:tid 519748] [client 158.23.184.117:32157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/min.php"] [unique_id "apPloNKCPt8cS-VWcMmPfwAAA9c"]
[Sun Aug 30 03:11:12.067547 2026] [security2:error] [pid 518600:tid 518836] [client 20.104.50.220:31508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/simple.php"] [unique_id "apPloO349Tv4SB45P2nmgQAAAOw"]
[Sun Aug 30 03:11:12.074841 2026] [authz_core:error] [pid 518600:tid 518799] [client 66.249.66.65:59998] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:12.075118 2026] [authz_core:error] [pid 518600:tid 518799] [client 66.249.66.65:59998] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:12.090510 2026] [security2:error] [pid 519566:tid 519782] [client 52.139.37.240:43090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/wp-content/about.php"] [unique_id "apPloNKCPt8cS-VWcMmPgQAAA_k"]
[Sun Aug 30 03:11:12.094535 2026] [security2:error] [pid 518600:tid 518840] [client 4.205.62.107:52904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/saiga.php"] [unique_id "apPloO349Tv4SB45P2nmiAAAAPA"]
[Sun Aug 30 03:11:12.097086 2026] [security2:error] [pid 519566:tid 519802] [client 20.48.251.3:36828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/broadcasting.php"] [unique_id "apPloNKCPt8cS-VWcMmPhgAABA0"]
[Sun Aug 30 03:11:12.118325 2026] [security2:error] [pid 519566:tid 519751] [client 20.104.18.15:22354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apPloNKCPt8cS-VWcMmPjwAAA9o"]
[Sun Aug 30 03:11:12.127228 2026] [security2:error] [pid 519566:tid 519746] [client 20.48.160.90:51941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/wp-content/l.php"] [unique_id "apPloNKCPt8cS-VWcMmPkgAAA9U"]
[Sun Aug 30 03:11:12.153267 2026] [security2:error] [pid 518600:tid 518762] [client 4.205.62.107:17302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/wp-admin/sc.php"] [unique_id "apPloO349Tv4SB45P2nmlAAAAKI"]
[Sun Aug 30 03:11:12.153267 2026] [security2:error] [pid 519566:tid 519788] [client 158.23.147.79:39109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/dropdown.php"] [unique_id "apPloNKCPt8cS-VWcMmPlwAAA_8"]
[Sun Aug 30 03:11:12.183820 2026] [security2:error] [pid 518600:tid 518833] [client 20.63.81.20:59092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/Jcrop.php"] [unique_id "apPloO349Tv4SB45P2nmngAAAOk"]
[Sun Aug 30 03:11:12.206905 2026] [security2:error] [pid 519566:tid 519803] [client 158.23.184.117:32177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/options.php"] [unique_id "apPloNKCPt8cS-VWcMmPqAAABA4"]
[Sun Aug 30 03:11:12.208899 2026] [security2:error] [pid 519566:tid 519704] [client 20.48.251.3:55773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/app.default.php"] [unique_id "apPloNKCPt8cS-VWcMmPqgAAA6s"]
[Sun Aug 30 03:11:12.230295 2026] [security2:error] [pid 519566:tid 519794] [client 40.83.93.50:7047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/pages.php"] [unique_id "apPloNKCPt8cS-VWcMmPsgAABAU"]
[Sun Aug 30 03:11:12.248559 2026] [security2:error] [pid 519566:tid 519782] [client 20.104.49.130:52099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/dehnl.php"] [unique_id "apPloNKCPt8cS-VWcMmPtwAAA_k"]
[Sun Aug 30 03:11:12.251667 2026] [security2:error] [pid 519566:tid 519779] [client 158.23.147.79:43595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/.well-known/index.php"] [unique_id "apPloNKCPt8cS-VWcMmPuQAAA_Y"]
[Sun Aug 30 03:11:12.267544 2026] [security2:error] [pid 519566:tid 519700] [client 20.48.160.90:51921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/wp-admin/w.php"] [unique_id "apPloNKCPt8cS-VWcMmPwgAAA6c"]
[Sun Aug 30 03:11:12.271728 2026] [security2:error] [pid 519566:tid 519799] [client 207.154.212.47:56018] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.eessel.com"] [uri "/.env"] [unique_id "apPloNKCPt8cS-VWcMmPxAAABAo"]
[Sun Aug 30 03:11:12.272443 2026] [security2:error] [pid 519566:tid 519716] [client 20.104.18.15:31693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/fling.php"] [unique_id "apPloNKCPt8cS-VWcMmPxQAAA7c"]
[Sun Aug 30 03:11:12.295360 2026] [security2:error] [pid 519566:tid 519807] [client 52.139.37.240:14056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/wp-the.php"] [unique_id "apPloNKCPt8cS-VWcMmPzAAABBI"]
[Sun Aug 30 03:11:12.302733 2026] [security2:error] [pid 519566:tid 519722] [client 4.205.62.107:26975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/333.php"] [unique_id "apPloNKCPt8cS-VWcMmP0QAAA70"]
[Sun Aug 30 03:11:12.327759 2026] [security2:error] [pid 519566:tid 519752] [client 20.63.81.20:59121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/35iDq8NAjLu.php"] [unique_id "apPloNKCPt8cS-VWcMmP3gAAA9s"]
[Sun Aug 30 03:11:12.346260 2026] [security2:error] [pid 519566:tid 519759] [client 4.205.62.107:36567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/params.php"] [unique_id "apPloNKCPt8cS-VWcMmP5gAAA-I"]
[Sun Aug 30 03:11:12.349547 2026] [security2:error] [pid 519566:tid 519740] [client 158.23.184.117:32169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/pk.php"] [unique_id "apPloNKCPt8cS-VWcMmP5wAAA88"]
[Sun Aug 30 03:11:12.371666 2026] [security2:error] [pid 518600:tid 518783] [client 20.196.209.81:11910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/salient/css/build/plugins/login.php"] [unique_id "apPloO349Tv4SB45P2nm0QAAALc"]
[Sun Aug 30 03:11:12.389152 2026] [authz_core:error] [pid 519566:tid 519815] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:11:12.389540 2026] [authz_core:error] [pid 519566:tid 519815] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:11:12.405869 2026] [security2:error] [pid 519566:tid 519808] [client 20.48.160.90:28071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/wp-content/k.php"] [unique_id "apPloNKCPt8cS-VWcMmP9AAABBM"]
[Sun Aug 30 03:11:12.419955 2026] [security2:error] [pid 519566:tid 519715] [client 40.83.93.50:6231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.riverglenhoa.com"] [uri "/lock.php"] [unique_id "apPloNKCPt8cS-VWcMmP-AAAA7Y"]
[Sun Aug 30 03:11:12.433721 2026] [security2:error] [pid 518600:tid 518860] [client 20.104.49.130:63488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/echkm.php"] [unique_id "apPloO349Tv4SB45P2nm3QAAAQQ"]
[Sun Aug 30 03:11:12.447159 2026] [authz_core:error] [pid 518600:tid 518844] [client 66.249.66.39:48255] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:12.447246 2026] [authz_core:error] [pid 519566:tid 519784] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fvar%2Flib
[Sun Aug 30 03:11:12.447506 2026] [authz_core:error] [pid 519566:tid 519784] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fvar%2Flib
[Sun Aug 30 03:11:12.447581 2026] [authz_core:error] [pid 518600:tid 518844] [client 66.249.66.39:48255] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:12.468118 2026] [security2:error] [pid 519566:tid 519749] [client 4.205.62.107:16359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/aws-credentials.php"] [unique_id "apPloNKCPt8cS-VWcMmQCAAAA9g"]
[Sun Aug 30 03:11:12.478721 2026] [security2:error] [pid 518600:tid 518859] [client 158.23.147.79:39306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-content/themes/too.php"] [unique_id "apPloO349Tv4SB45P2nm7wAAAQM"]
[Sun Aug 30 03:11:12.490968 2026] [security2:error] [pid 518600:tid 518788] [client 158.23.184.117:32143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/index.php"] [unique_id "apPloO349Tv4SB45P2nm9QAAALw"]
[Sun Aug 30 03:11:12.496424 2026] [security2:error] [pid 518600:tid 518742] [client 52.139.37.240:13845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/ws81.php"] [unique_id "apPloO349Tv4SB45P2nm8AAAAI4"]
[Sun Aug 30 03:11:12.499006 2026] [security2:error] [pid 519566:tid 519727] [client 20.104.18.15:64750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/sym.php"] [unique_id "apPloNKCPt8cS-VWcMmQEgAAA8I"]
[Sun Aug 30 03:11:12.503186 2026] [authz_core:error] [pid 519566:tid 519806] [client 66.249.66.32:65530] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:12.503305 2026] [lsapi:error] [pid 519566:tid 519597] [remote 76.31.145.178:33290] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:11:12.503408 2026] [lsapi:error] [pid 519566:tid 519597] [remote 76.31.145.178:33290] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:11:12.503469 2026] [authz_core:error] [pid 519566:tid 519806] [client 66.249.66.32:65530] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:12.504875 2026] [lsapi:error] [pid 519566:tid 519597] [remote 76.31.145.178:33290] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:11:12.512064 2026] [security2:error] [pid 518600:tid 518764] [client 20.63.81.20:59097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/btx25.php"] [unique_id "apPloO349Tv4SB45P2nm-wAAAKQ"]
[Sun Aug 30 03:11:12.542023 2026] [security2:error] [pid 519566:tid 519740] [client 20.48.160.90:51892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/os.php"] [unique_id "apPloNKCPt8cS-VWcMmQGwAAA88"]
[Sun Aug 30 03:11:12.544041 2026] [security2:error] [pid 518600:tid 518812] [client 20.48.251.3:52174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/debug.php"] [unique_id "apPloO349Tv4SB45P2nnBQAAANQ"]
[Sun Aug 30 03:11:12.556815 2026] [security2:error] [pid 519566:tid 519741] [client 20.104.49.130:43595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/abcd.php"] [unique_id "apPloNKCPt8cS-VWcMmQIgAAA9A"]
[Sun Aug 30 03:11:12.572350 2026] [security2:error] [pid 518600:tid 518790] [client 68.155.159.216:57043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apPloO349Tv4SB45P2nnFQAAAL4"]
[Sun Aug 30 03:11:12.583210 2026] [security2:error] [pid 519566:tid 519808] [client 158.23.147.79:39146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/radio.php"] [unique_id "apPloNKCPt8cS-VWcMmQLgAABBM"]
[Sun Aug 30 03:11:12.635492 2026] [security2:error] [pid 518600:tid 518753] [client 158.23.184.117:32149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/cgi-bin/index.php"] [unique_id "apPloO349Tv4SB45P2nnJgAAAJk"]
[Sun Aug 30 03:11:12.640961 2026] [security2:error] [pid 519566:tid 519733] [client 20.104.50.220:59583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-we.php"] [unique_id "apPloNKCPt8cS-VWcMmQPQAAA8g"]
[Sun Aug 30 03:11:12.672035 2026] [security2:error] [pid 518600:tid 518795] [client 20.63.81.20:59110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/radio.php"] [unique_id "apPloO349Tv4SB45P2nnLQAAAMM"]
[Sun Aug 30 03:11:12.680833 2026] [security2:error] [pid 518600:tid 518780] [client 20.48.160.90:51874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/htio.php"] [unique_id "apPloO349Tv4SB45P2nnMQAAALQ"]
[Sun Aug 30 03:11:12.697972 2026] [security2:error] [pid 518600:tid 518785] [client 52.139.37.240:14059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/a1.php"] [unique_id "apPloO349Tv4SB45P2nnNAAAALk"]
[Sun Aug 30 03:11:12.729756 2026] [security2:error] [pid 519566:tid 519740] [client 158.23.147.79:43041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPloNKCPt8cS-VWcMmQRwAAA88"]
[Sun Aug 30 03:11:12.730029 2026] [security2:error] [pid 519566:tid 519816] [client 40.83.93.50:6378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/albin.php"] [unique_id "apPloNKCPt8cS-VWcMmQSQAABBs"]
[Sun Aug 30 03:11:12.764711 2026] [authz_core:error] [pid 519566:tid 519753] [client 216.73.216.128:24387] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:12.765044 2026] [authz_core:error] [pid 519566:tid 519753] [client 216.73.216.128:24387] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:12.765199 2026] [security2:error] [pid 518600:tid 518857] [client 20.196.209.81:15059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/security.php"] [unique_id "apPloO349Tv4SB45P2nnRAAAAQE"]
[Sun Aug 30 03:11:12.779140 2026] [security2:error] [pid 518600:tid 518744] [client 158.23.184.117:31800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/cgi-bin/load.php"] [unique_id "apPloO349Tv4SB45P2nnRgAAAJA"]
[Sun Aug 30 03:11:12.800863 2026] [security2:error] [pid 519566:tid 519735] [client 20.63.81.20:59058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/dex.php"] [unique_id "apPloNKCPt8cS-VWcMmQWQAAA8o"]
[Sun Aug 30 03:11:12.825848 2026] [security2:error] [pid 518600:tid 518743] [client 20.48.160.90:51843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/dev.php"] [unique_id "apPloO349Tv4SB45P2nnVQAAAI8"]
[Sun Aug 30 03:11:12.860980 2026] [authz_core:error] [pid 519566:tid 519731] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:12.861283 2026] [authz_core:error] [pid 519566:tid 519731] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:12.902145 2026] [security2:error] [pid 518600:tid 518821] [client 52.139.37.240:13827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/ca5.php"] [unique_id "apPloO349Tv4SB45P2nnYwAAAN0"]
[Sun Aug 30 03:11:12.918311 2026] [security2:error] [pid 519566:tid 519751] [client 158.23.184.117:31793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/cgi-bin/ms-files.php"] [unique_id "apPloNKCPt8cS-VWcMmQdwAAA9o"]
[Sun Aug 30 03:11:12.931950 2026] [security2:error] [pid 519566:tid 519791] [client 20.63.81.20:59065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/giodywky.php"] [unique_id "apPloNKCPt8cS-VWcMmQewAABAI"]
[Sun Aug 30 03:11:12.941902 2026] [authz_core:error] [pid 519566:tid 519740] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fvar%2Flock
[Sun Aug 30 03:11:12.942183 2026] [authz_core:error] [pid 519566:tid 519740] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fvar%2Flock
[Sun Aug 30 03:11:12.948115 2026] [authz_core:error] [pid 519566:tid 519816] [client 216.73.216.128:24387] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:12.948450 2026] [authz_core:error] [pid 519566:tid 519816] [client 216.73.216.128:24387] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:12.963299 2026] [authz_core:error] [pid 519566:tid 519709] [client 66.249.66.43:37378] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:12.963631 2026] [authz_core:error] [pid 519566:tid 519709] [client 66.249.66.43:37378] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:12.972509 2026] [security2:error] [pid 518600:tid 518845] [client 20.48.160.90:51949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/gos.php"] [unique_id "apPloO349Tv4SB45P2nndgAAAPU"]
[Sun Aug 30 03:11:12.976186 2026] [security2:error] [pid 519566:tid 519792] [client 158.23.147.79:43600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/makeasmtp.php"] [unique_id "apPloNKCPt8cS-VWcMmQjgAABAM"]
[Sun Aug 30 03:11:12.986442 2026] [security2:error] [pid 518600:tid 518752] [client 20.104.50.220:51538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/tuco.php"] [unique_id "apPloO349Tv4SB45P2nneAAAAJg"]
[Sun Aug 30 03:11:13.012325 2026] [security2:error] [pid 519566:tid 519754] [client 20.104.49.130:57524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/xwx1.php"] [unique_id "apPlodKCPt8cS-VWcMmQlgAAA90"]
[Sun Aug 30 03:11:13.052129 2026] [security2:error] [pid 518600:tid 518830] [client 20.104.50.220:16621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPloe349Tv4SB45P2nnhwAAAOY"]
[Sun Aug 30 03:11:13.059834 2026] [security2:error] [pid 519566:tid 519796] [client 158.23.184.117:31806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/cgi-bin/wp-activate.php"] [unique_id "apPlodKCPt8cS-VWcMmQoAAABAc"]
[Sun Aug 30 03:11:13.071807 2026] [security2:error] [pid 518600:tid 518774] [client 20.104.50.220:33199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/codeboy1877x.php"] [unique_id "apPloe349Tv4SB45P2nnjgAAAK4"]
[Sun Aug 30 03:11:13.079977 2026] [security2:error] [pid 518600:tid 518740] [client 20.63.81.20:59091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp-kz.php"] [unique_id "apPloe349Tv4SB45P2nnjwAAAIw"]
[Sun Aug 30 03:11:13.097954 2026] [security2:error] [pid 518600:tid 518831] [client 158.23.147.79:43641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apPloe349Tv4SB45P2nnkwAAAOc"]
[Sun Aug 30 03:11:13.099027 2026] [security2:error] [pid 518600:tid 518812] [client 20.104.50.220:5193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/template.php"] [unique_id "apPloe349Tv4SB45P2nnlAAAANQ"]
[Sun Aug 30 03:11:13.101366 2026] [security2:error] [pid 518600:tid 518778] [client 20.48.160.90:51911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/132.php"] [unique_id "apPloe349Tv4SB45P2nnlQAAALI"]
[Sun Aug 30 03:11:13.111715 2026] [security2:error] [pid 519566:tid 519745] [client 52.139.37.240:43089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/install.php"] [unique_id "apPlodKCPt8cS-VWcMmQqgAAA9Q"]
[Sun Aug 30 03:11:13.113838 2026] [security2:error] [pid 518600:tid 518791] [client 20.104.18.15:18307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/33.php"] [unique_id "apPloe349Tv4SB45P2nnlwAAAL8"]
[Sun Aug 30 03:11:13.122610 2026] [security2:error] [pid 519566:tid 519767] [client 158.23.147.79:58400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-admin/maint/index.php"] [unique_id "apPlodKCPt8cS-VWcMmQrwAAA-o"]
[Sun Aug 30 03:11:13.146599 2026] [security2:error] [pid 519566:tid 519734] [client 20.48.251.3:64281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/test.config.php"] [unique_id "apPlodKCPt8cS-VWcMmQtQAAA8k"]
[Sun Aug 30 03:11:13.156524 2026] [security2:error] [pid 518600:tid 518810] [client 20.196.209.81:21703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "apPloe349Tv4SB45P2nnnwAAANI"]
[Sun Aug 30 03:11:13.166466 2026] [security2:error] [pid 519566:tid 519797] [client 68.155.159.216:52548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apPlodKCPt8cS-VWcMmQugAABAg"]
[Sun Aug 30 03:11:13.201349 2026] [security2:error] [pid 518600:tid 518773] [client 158.23.184.117:31781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/cgi-bin/wp-load.php"] [unique_id "apPloe349Tv4SB45P2nnrQAAAK0"]
[Sun Aug 30 03:11:13.201461 2026] [security2:error] [pid 519566:tid 519732] [client 40.83.93.50:6337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/an.php"] [unique_id "apPlodKCPt8cS-VWcMmQxQAAA8c"]
[Sun Aug 30 03:11:13.204887 2026] [security2:error] [pid 519566:tid 519779] [client 20.104.50.220:28724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/hehee.php"] [unique_id "apPlodKCPt8cS-VWcMmQwQAAA_Y"]
[Sun Aug 30 03:11:13.217214 2026] [security2:error] [pid 518600:tid 518795] [client 20.63.81.20:58958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp-includes/ID3/getid.php"] [unique_id "apPloe349Tv4SB45P2nnuQAAAMM"]
[Sun Aug 30 03:11:13.232464 2026] [security2:error] [pid 519566:tid 519772] [client 20.48.160.90:46498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/v22.php"] [unique_id "apPlodKCPt8cS-VWcMmQyQAAA-8"]
[Sun Aug 30 03:11:13.233202 2026] [security2:error] [pid 519566:tid 519817] [client 20.104.50.220:31518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/kj.php"] [unique_id "apPlodKCPt8cS-VWcMmQygAABBw"]
[Sun Aug 30 03:11:13.236906 2026] [security2:error] [pid 519566:tid 519778] [client 4.205.62.107:52824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/ammika.php"] [unique_id "apPlodKCPt8cS-VWcMmQywAAA_U"]
[Sun Aug 30 03:11:13.237599 2026] [security2:error] [pid 519566:tid 519778] [client 158.23.147.79:43010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apPlodKCPt8cS-VWcMmQzQAAA_U"]
[Sun Aug 30 03:11:13.285892 2026] [security2:error] [pid 519566:tid 519812] [client 20.48.251.3:36833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/aws_config.php"] [unique_id "apPlodKCPt8cS-VWcMmQ2wAABBc"]
[Sun Aug 30 03:11:13.288524 2026] [security2:error] [pid 519566:tid 519782] [client 68.155.159.216:45888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/log-mama/function.php"] [unique_id "apPlodKCPt8cS-VWcMmQ3gAAA_k"]
[Sun Aug 30 03:11:13.291501 2026] [security2:error] [pid 519566:tid 519723] [client 4.205.62.107:17666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/debug.php"] [unique_id "apPlodKCPt8cS-VWcMmQ4gAAA74"]
[Sun Aug 30 03:11:13.292027 2026] [security2:error] [pid 519566:tid 519702] [client 20.104.18.15:22340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/wp-aothait.php"] [unique_id "apPlodKCPt8cS-VWcMmQ4wAAA6k"]
[Sun Aug 30 03:11:13.301356 2026] [authz_core:error] [pid 519566:tid 519720] [client 66.249.66.197:37686] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:13.301670 2026] [authz_core:error] [pid 519566:tid 519720] [client 66.249.66.197:37686] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:13.314423 2026] [authz_core:error] [pid 518600:tid 518806] [client 216.73.216.128:60050] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:13.314699 2026] [authz_core:error] [pid 518600:tid 518806] [client 216.73.216.128:60050] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:13.338080 2026] [security2:error] [pid 519566:tid 519794] [client 158.23.184.117:31752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/cgi-bin/wp-mail.php"] [unique_id "apPlodKCPt8cS-VWcMmQ-wAABAU"]
[Sun Aug 30 03:11:13.341672 2026] [security2:error] [pid 519566:tid 519719] [client 20.48.251.3:55802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/app_local.php"] [unique_id "apPlodKCPt8cS-VWcMmQ_gAAA7o"]
[Sun Aug 30 03:11:13.356257 2026] [authz_core:error] [pid 519566:tid 519752] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:13.356702 2026] [authz_core:error] [pid 519566:tid 519752] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:13.357690 2026] [security2:error] [pid 519566:tid 519751] [client 158.23.147.79:43610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-content/languages/about.php"] [unique_id "apPlodKCPt8cS-VWcMmRBQAAA9o"]
[Sun Aug 30 03:11:13.360790 2026] [security2:error] [pid 519566:tid 519767] [client 20.48.160.90:28148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/wp-activate.php"] [unique_id "apPlodKCPt8cS-VWcMmRBgAAA-o"]
[Sun Aug 30 03:11:13.364776 2026] [security2:error] [pid 519566:tid 519761] [client 20.63.81.20:59115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/session.php"] [unique_id "apPlodKCPt8cS-VWcMmRCgAAA-Q"]
[Sun Aug 30 03:11:13.398535 2026] [security2:error] [pid 519566:tid 519723] [client 216.73.216.128:24387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/globals_u.html"] [unique_id "apPlodKCPt8cS-VWcMmREAAAA74"]
[Sun Aug 30 03:11:13.400459 2026] [autoindex:error] [pid 518600:tid 518756] [client 52.139.37.240:13850] AH01276: Cannot serve directory /home3/ragtimec/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:11:13.412855 2026] [security2:error] [pid 519566:tid 519744] [client 20.104.18.15:31706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/btyuio.php"] [unique_id "apPlodKCPt8cS-VWcMmRFQAAA9M"]
[Sun Aug 30 03:11:13.425637 2026] [security2:error] [pid 519566:tid 519698] [client 20.151.200.44:41968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/admin.php/pindex.php"] [unique_id "apPlodKCPt8cS-VWcMmRGAAAA6U"]
[Sun Aug 30 03:11:13.446311 2026] [security2:error] [pid 518600:tid 518773] [client 4.205.62.107:25671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/G-in.php"] [unique_id "apPloe349Tv4SB45P2nn7wAAAK0"]
[Sun Aug 30 03:11:13.454131 2026] [authz_core:error] [pid 519566:tid 519713] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus
[Sun Aug 30 03:11:13.454693 2026] [authz_core:error] [pid 519566:tid 519713] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus
[Sun Aug 30 03:11:13.474209 2026] [security2:error] [pid 518600:tid 518825] [client 52.139.37.240:13850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/wp-signin.php"] [unique_id "apPloe349Tv4SB45P2nn-AAAAOE"]
[Sun Aug 30 03:11:13.478862 2026] [security2:error] [pid 519566:tid 519808] [client 158.23.184.117:31764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "apPlodKCPt8cS-VWcMmRLAAABBM"]
[Sun Aug 30 03:11:13.479096 2026] [security2:error] [pid 519566:tid 519755] [client 20.104.49.130:63601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/forum.php"] [unique_id "apPlodKCPt8cS-VWcMmRLQAAA94"]
[Sun Aug 30 03:11:13.489095 2026] [security2:error] [pid 519566:tid 519780] [client 4.205.62.107:36071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/gjm.php"] [unique_id "apPlodKCPt8cS-VWcMmRLwAAA_c"]
[Sun Aug 30 03:11:13.496109 2026] [security2:error] [pid 519566:tid 519767] [client 158.23.147.79:43296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-content/banners/about.php"] [unique_id "apPlodKCPt8cS-VWcMmRMwAAA-o"]
[Sun Aug 30 03:11:13.497291 2026] [security2:error] [pid 519566:tid 519704] [client 20.48.160.90:46467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/wp-trackback.php"] [unique_id "apPlodKCPt8cS-VWcMmRNAAAA6s"]
[Sun Aug 30 03:11:13.510212 2026] [security2:error] [pid 519566:tid 519800] [client 20.63.81.20:59071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/eagle.php"] [unique_id "apPlodKCPt8cS-VWcMmROAAABAs"]
[Sun Aug 30 03:11:13.548039 2026] [security2:error] [pid 519566:tid 519738] [client 20.196.209.81:21697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/system.php"] [unique_id "apPlodKCPt8cS-VWcMmRRgAAA80"]
[Sun Aug 30 03:11:13.597969 2026] [security2:error] [pid 519566:tid 519796] [client 4.205.62.107:16347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/4563.php"] [unique_id "apPlodKCPt8cS-VWcMmRWgAABAc"]
[Sun Aug 30 03:11:13.620809 2026] [security2:error] [pid 519566:tid 519795] [client 158.23.184.117:31771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/chosen.php"] [unique_id "apPlodKCPt8cS-VWcMmRZwAABAY"]
[Sun Aug 30 03:11:13.623397 2026] [security2:error] [pid 518600:tid 518776] [client 158.23.147.79:43584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-includes/Text/about.php"] [unique_id "apPloe349Tv4SB45P2noIAAAALA"]
[Sun Aug 30 03:11:13.636455 2026] [security2:error] [pid 519566:tid 519740] [client 20.104.18.15:16980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/8.php"] [unique_id "apPlodKCPt8cS-VWcMmRaAAAA88"]
[Sun Aug 30 03:11:13.638867 2026] [security2:error] [pid 519566:tid 519792] [client 20.48.160.90:28091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/pri.php"] [unique_id "apPlodKCPt8cS-VWcMmRagAABAM"]
[Sun Aug 30 03:11:13.649988 2026] [security2:error] [pid 519566:tid 519607] [remote 69.57.172.119:49402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.172.57.69.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petra-jordan-attractions.com"] [uri "/wp-login.php"] [unique_id "apPlodKCPt8cS-VWcMmRaQAEECg"]
[Sun Aug 30 03:11:13.660891 2026] [security2:error] [pid 519566:tid 519809] [client 20.63.81.20:59054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/up-kon.php"] [unique_id "apPlodKCPt8cS-VWcMmRbwAABBQ"]
[Sun Aug 30 03:11:13.666461 2026] [security2:error] [pid 518600:tid 518852] [client 40.83.93.50:10710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/mini.php"] [unique_id "apPloe349Tv4SB45P2noKAAAAPw"]
[Sun Aug 30 03:11:13.674259 2026] [security2:error] [pid 519566:tid 519780] [client 52.139.37.240:13988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/Ov-Simple1.php"] [unique_id "apPlodKCPt8cS-VWcMmRcQAAA_c"]
[Sun Aug 30 03:11:13.676748 2026] [security2:error] [pid 519566:tid 519782] [client 20.104.49.130:43278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/yawa.php"] [unique_id "apPlodKCPt8cS-VWcMmRdQAAA_k"]
[Sun Aug 30 03:11:13.686502 2026] [security2:error] [pid 518600:tid 518806] [client 20.48.251.3:59484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/nzv.php"] [unique_id "apPloe349Tv4SB45P2noLgAAAM4"]
[Sun Aug 30 03:11:13.704941 2026] [authz_core:error] [pid 518600:tid 518828] [client 66.249.66.201:58157] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:13.705217 2026] [authz_core:error] [pid 518600:tid 518828] [client 66.249.66.201:58157] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:13.709680 2026] [security2:error] [pid 519566:tid 519725] [client 20.104.49.130:52417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wdfjba.org"] [uri "/coffexium.php"] [unique_id "apPlodKCPt8cS-VWcMmRewAAA8A"]
[Sun Aug 30 03:11:13.741638 2026] [security2:error] [pid 519566:tid 519794] [client 68.155.159.216:63251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPlodKCPt8cS-VWcMmRhwAABAU"]
[Sun Aug 30 03:11:13.743795 2026] [security2:error] [pid 519566:tid 519777] [client 158.23.147.79:39116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/asd.php"] [unique_id "apPlodKCPt8cS-VWcMmRigAAA_Q"]
[Sun Aug 30 03:11:13.772165 2026] [authz_core:error] [pid 518600:tid 518839] [client 216.73.216.128:60050] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:13.772440 2026] [authz_core:error] [pid 518600:tid 518839] [client 216.73.216.128:60050] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:13.778922 2026] [security2:error] [pid 519566:tid 519743] [client 20.104.50.220:61665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wpindex.php"] [unique_id "apPlodKCPt8cS-VWcMmRkwAAA9I"]
[Sun Aug 30 03:11:13.789822 2026] [security2:error] [pid 519566:tid 519715] [client 20.63.81.20:59120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/tinny.php"] [unique_id "apPlodKCPt8cS-VWcMmRlQAAA7Y"]
[Sun Aug 30 03:11:13.807736 2026] [security2:error] [pid 518600:tid 518848] [client 20.48.160.90:28044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/wp_blog_footer.php"] [unique_id "apPloe349Tv4SB45P2noRgAAAPg"]
[Sun Aug 30 03:11:13.863088 2026] [security2:error] [pid 519566:tid 519703] [client 158.23.147.79:39112] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/1.php"] [unique_id "apPlodKCPt8cS-VWcMmRpAAAA6o"]
[Sun Aug 30 03:11:13.863190 2026] [security2:error] [pid 519566:tid 519703] [client 158.23.147.79:39112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/1.php"] [unique_id "apPlodKCPt8cS-VWcMmRpAAAA6o"]
[Sun Aug 30 03:11:13.866875 2026] [authz_core:error] [pid 519566:tid 519700] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:13.867324 2026] [authz_core:error] [pid 519566:tid 519700] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:13.877371 2026] [security2:error] [pid 519566:tid 519793] [client 20.151.200.44:41930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/admin.php/csv.php"] [unique_id "apPlodKCPt8cS-VWcMmRqwAABAQ"]
[Sun Aug 30 03:11:13.891348 2026] [security2:error] [pid 519566:tid 519727] [client 52.139.37.240:43095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/ftde.php"] [unique_id "apPlodKCPt8cS-VWcMmRrAAAA8I"]
[Sun Aug 30 03:11:13.903583 2026] [security2:error] [pid 519566:tid 519773] [client 20.151.200.44:40860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/pk.php"] [unique_id "apPlodKCPt8cS-VWcMmRsQAAA_A"]
[Sun Aug 30 03:11:13.917514 2026] [security2:error] [pid 518600:tid 518772] [client 20.63.81.20:59053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp-easy.php"] [unique_id "apPloe349Tv4SB45P2noVgAAAKw"]
[Sun Aug 30 03:11:13.941550 2026] [security2:error] [pid 519566:tid 519794] [client 20.48.160.90:28102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/sushi.php"] [unique_id "apPlodKCPt8cS-VWcMmRuQAABAU"]
[Sun Aug 30 03:11:13.942004 2026] [authz_core:error] [pid 519566:tid 519711] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare
[Sun Aug 30 03:11:13.942328 2026] [authz_core:error] [pid 519566:tid 519711] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare
[Sun Aug 30 03:11:13.944908 2026] [authz_core:error] [pid 519566:tid 519789] [client 66.249.66.196:57293] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:13.945329 2026] [authz_core:error] [pid 519566:tid 519789] [client 66.249.66.196:57293] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:13.967453 2026] [security2:error] [pid 519566:tid 519797] [client 20.196.209.81:22462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/tflow/min.php"] [unique_id "apPlodKCPt8cS-VWcMmRvgAABAg"]
[Sun Aug 30 03:11:14.028688 2026] [security2:error] [pid 519566:tid 519793] [client 158.23.147.79:58374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/dropdown.php"] [unique_id "apPlotKCPt8cS-VWcMmR1AAABAQ"]
[Sun Aug 30 03:11:14.045580 2026] [security2:error] [pid 518600:tid 518754] [client 216.73.216.128:60050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlou349Tv4SB45P2nodQAAAJo"]
[Sun Aug 30 03:11:14.062105 2026] [security2:error] [pid 518600:tid 518789] [client 20.63.81.20:59021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/d7.php"] [unique_id "apPlou349Tv4SB45P2noeQAAAL0"]
[Sun Aug 30 03:11:14.080487 2026] [security2:error] [pid 519566:tid 519722] [client 20.48.160.90:51918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/manga.php"] [unique_id "apPlotKCPt8cS-VWcMmR6AAAA70"]
[Sun Aug 30 03:11:14.088700 2026] [security2:error] [pid 519566:tid 519785] [client 158.23.147.79:43021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/ws.php"] [unique_id "apPlotKCPt8cS-VWcMmR7AAAA_w"]
[Sun Aug 30 03:11:14.090206 2026] [security2:error] [pid 519566:tid 519805] [client 52.139.37.240:44568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/hplfuns.php"] [unique_id "apPlotKCPt8cS-VWcMmR6gAABBA"]
[Sun Aug 30 03:11:14.093058 2026] [security2:error] [pid 519566:tid 519764] [client 158.23.184.117:32410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/class-wp-logo-new.php"] [unique_id "apPlotKCPt8cS-VWcMmR7wAAA-c"]
[Sun Aug 30 03:11:14.100773 2026] [security2:error] [pid 519566:tid 519745] [client 20.151.200.44:41858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/admin.php/700.php"] [unique_id "apPlotKCPt8cS-VWcMmR9QAAA9Q"]
[Sun Aug 30 03:11:14.131333 2026] [security2:error] [pid 518600:tid 518848] [client 20.104.50.220:51623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/ice.php"] [unique_id "apPlou349Tv4SB45P2noiQAAAPg"]
[Sun Aug 30 03:11:14.186817 2026] [security2:error] [pid 518600:tid 518753] [client 158.23.147.79:43014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-includes/css/index.php"] [unique_id "apPlou349Tv4SB45P2nolQAAAJk"]
[Sun Aug 30 03:11:14.188968 2026] [security2:error] [pid 519566:tid 519803] [client 20.104.50.220:16656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-content/themes/twentytwentytwo/index.php"] [unique_id "apPlotKCPt8cS-VWcMmSDQAABA4"]
[Sun Aug 30 03:11:14.198073 2026] [security2:error] [pid 519566:tid 519706] [client 20.63.81.20:59037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/v5.php"] [unique_id "apPlotKCPt8cS-VWcMmSEwAAA60"]
[Sun Aug 30 03:11:14.212384 2026] [security2:error] [pid 518600:tid 518832] [client 20.104.50.220:33072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wsanon.php"] [unique_id "apPlou349Tv4SB45P2nomQAAAOg"]
[Sun Aug 30 03:11:14.223566 2026] [security2:error] [pid 519566:tid 519777] [client 40.83.93.50:6397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/robots.php"] [unique_id "apPlotKCPt8cS-VWcMmSGAAAA_Q"]
[Sun Aug 30 03:11:14.232685 2026] [security2:error] [pid 519566:tid 519753] [client 158.23.184.117:32427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/classwithtostring.php"] [unique_id "apPlotKCPt8cS-VWcMmSIAAAA9w"]
[Sun Aug 30 03:11:14.234758 2026] [security2:error] [pid 519566:tid 519741] [client 20.104.49.130:48022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/reop3.php"] [unique_id "apPlotKCPt8cS-VWcMmSIgAAA9A"]
[Sun Aug 30 03:11:14.255379 2026] [security2:error] [pid 519566:tid 519748] [client 20.104.50.220:5947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/vars.php"] [unique_id "apPlotKCPt8cS-VWcMmSKQAAA9c"]
[Sun Aug 30 03:11:14.261871 2026] [security2:error] [pid 519566:tid 519702] [client 20.48.160.90:46492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/asdfghj.php"] [unique_id "apPlotKCPt8cS-VWcMmSLwAAA6k"]
[Sun Aug 30 03:11:14.269250 2026] [security2:error] [pid 518600:tid 518784] [client 20.104.18.15:18348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/133.php"] [unique_id "apPlou349Tv4SB45P2noqgAAALg"]
[Sun Aug 30 03:11:14.272048 2026] [authz_core:error] [pid 518600:tid 518739] [client 66.249.66.33:43738] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:14.272347 2026] [authz_core:error] [pid 518600:tid 518739] [client 66.249.66.33:43738] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:14.287862 2026] [security2:error] [pid 519566:tid 519774] [client 20.48.251.3:64280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/gecko-litespeed.php"] [unique_id "apPlotKCPt8cS-VWcMmSNwAAA_E"]
[Sun Aug 30 03:11:14.288783 2026] [security2:error] [pid 518600:tid 518821] [client 52.139.37.240:43132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/log.php"] [unique_id "apPlou349Tv4SB45P2norgAAAN0"]
[Sun Aug 30 03:11:14.289437 2026] [security2:error] [pid 519566:tid 519709] [client 68.155.159.216:52574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/themes.php"] [unique_id "apPlotKCPt8cS-VWcMmSOQAAA7A"]
[Sun Aug 30 03:11:14.318886 2026] [security2:error] [pid 518600:tid 518782] [client 20.104.49.130:57726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/bolt.php"] [unique_id "apPlou349Tv4SB45P2novAAAALY"]
[Sun Aug 30 03:11:14.326509 2026] [authz_core:error] [pid 519566:tid 519721] [client 216.73.216.128:45868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:14.326836 2026] [authz_core:error] [pid 519566:tid 519721] [client 216.73.216.128:45868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:14.331914 2026] [security2:error] [pid 519566:tid 519768] [client 158.23.147.79:43590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/cgi-bin/wp-login.php"] [unique_id "apPlotKCPt8cS-VWcMmSRQAAA-s"]
[Sun Aug 30 03:11:14.332065 2026] [security2:error] [pid 518600:tid 518760] [client 20.63.81.20:59013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/az.php"] [unique_id "apPlou349Tv4SB45P2nowgAAAKA"]
[Sun Aug 30 03:11:14.360309 2026] [security2:error] [pid 519566:tid 519761] [client 20.196.209.81:19148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/tflow/pk.php"] [unique_id "apPlotKCPt8cS-VWcMmSWgAAA-Q"]
[Sun Aug 30 03:11:14.366714 2026] [security2:error] [pid 519566:tid 519702] [client 20.104.50.220:52835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/human.php"] [unique_id "apPlotKCPt8cS-VWcMmSXgAAA6k"]
[Sun Aug 30 03:11:14.369626 2026] [security2:error] [pid 518600:tid 518797] [client 4.205.62.107:52899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/broadcasting.php"] [unique_id "apPlou349Tv4SB45P2nozQAAAMU"]
[Sun Aug 30 03:11:14.370567 2026] [authz_core:error] [pid 519566:tid 519723] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:14.370973 2026] [authz_core:error] [pid 519566:tid 519723] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:14.372541 2026] [security2:error] [pid 519566:tid 519820] [client 158.23.184.117:31796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/cms.php"] [unique_id "apPlotKCPt8cS-VWcMmSYAAABB8"]
[Sun Aug 30 03:11:14.395603 2026] [security2:error] [pid 518600:tid 518839] [client 20.48.160.90:51963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/dragonshell.php"] [unique_id "apPlou349Tv4SB45P2no2wAAAO8"]
[Sun Aug 30 03:11:14.415292 2026] [core:alert] [pid 518600:tid 518742] [client 138.185.147.94:48748] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:11:14.423995 2026] [security2:error] [pid 518600:tid 518809] [client 20.104.50.220:59385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/xxx.php"] [unique_id "apPlou349Tv4SB45P2no6AAAANE"]
[Sun Aug 30 03:11:14.428375 2026] [security2:error] [pid 519566:tid 519728] [client 4.205.62.107:17092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/nzv.php"] [unique_id "apPlotKCPt8cS-VWcMmScAAAA8M"]
[Sun Aug 30 03:11:14.445597 2026] [authz_core:error] [pid 519566:tid 519758] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Ftls
[Sun Aug 30 03:11:14.446061 2026] [authz_core:error] [pid 519566:tid 519758] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Ftls
[Sun Aug 30 03:11:14.477570 2026] [security2:error] [pid 518600:tid 518756] [client 20.63.81.20:58953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/js.php"] [unique_id "apPlou349Tv4SB45P2no-wAAAJw"]
[Sun Aug 30 03:11:14.480097 2026] [security2:error] [pid 518600:tid 518846] [client 20.48.251.3:59342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/ws62.php"] [unique_id "apPlou349Tv4SB45P2no_QAAAPY"]
[Sun Aug 30 03:11:14.483462 2026] [security2:error] [pid 518600:tid 518801] [client 20.48.251.3:36809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/dialog.php"] [unique_id "apPlou349Tv4SB45P2no_wAAAMk"]
[Sun Aug 30 03:11:14.488550 2026] [authz_core:error] [pid 518600:tid 518820] [client 66.249.66.76:49853] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:14.488668 2026] [security2:error] [pid 518600:tid 518837] [client 52.139.37.240:13849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/txets.php"] [unique_id "apPlou349Tv4SB45P2no_AAAAO0"]
[Sun Aug 30 03:11:14.488991 2026] [authz_core:error] [pid 518600:tid 518820] [client 66.249.66.76:49853] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:14.489202 2026] [security2:error] [pid 519566:tid 519715] [client 20.104.18.15:22378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/wp-includes/index.php"] [unique_id "apPlotKCPt8cS-VWcMmSgQAAA7Y"]
[Sun Aug 30 03:11:14.514687 2026] [security2:error] [pid 518600:tid 518844] [client 158.23.184.117:31758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/config.php"] [unique_id "apPlou349Tv4SB45P2npCQAAAPQ"]
[Sun Aug 30 03:11:14.516582 2026] [security2:error] [pid 519566:tid 519822] [client 158.23.147.79:43013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-content/cong.php"] [unique_id "apPlotKCPt8cS-VWcMmSiwAABCE"]
[Sun Aug 30 03:11:14.582426 2026] [security2:error] [pid 518600:tid 518765] [client 20.104.18.15:31617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/dehnl.php"] [unique_id "apPlou349Tv4SB45P2npGQAAAKU"]
[Sun Aug 30 03:11:14.583117 2026] [security2:error] [pid 518600:tid 518817] [client 20.48.160.90:28094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/wp-safe.php"] [unique_id "apPlou349Tv4SB45P2npGgAAANk"]
[Sun Aug 30 03:11:14.583539 2026] [core:alert] [pid 519566:tid 519823] [client 188.113.205.243:16102] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:11:14.612790 2026] [security2:error] [pid 518600:tid 518740] [client 20.63.81.20:58945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/hd.php"] [unique_id "apPlou349Tv4SB45P2npJgAAAIw"]
[Sun Aug 30 03:11:14.627941 2026] [security2:error] [pid 519566:tid 519781] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/.env"] [unique_id "apPlotKCPt8cS-VWcMmSsgAAA_g"]
[Sun Aug 30 03:11:14.656057 2026] [security2:error] [pid 519566:tid 519704] [client 158.23.184.117:32402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/configs.php"] [unique_id "apPlotKCPt8cS-VWcMmSuQAAA6s"]
[Sun Aug 30 03:11:14.681114 2026] [security2:error] [pid 519566:tid 519736] [client 4.205.62.107:36683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/configuration.php"] [unique_id "apPlotKCPt8cS-VWcMmSvgAAA8s"]
[Sun Aug 30 03:11:14.682515 2026] [security2:error] [pid 519566:tid 519702] [client 4.205.62.107:25493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/apikeys.php"] [unique_id "apPlotKCPt8cS-VWcMmSvwAAA6k"]
[Sun Aug 30 03:11:14.688220 2026] [security2:error] [pid 519566:tid 519749] [client 52.139.37.240:44585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/wp-admin.php"] [unique_id "apPlotKCPt8cS-VWcMmSvQAAA9g"]
[Sun Aug 30 03:11:14.707064 2026] [security2:error] [pid 519566:tid 519773] [client 158.23.147.79:43014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPlotKCPt8cS-VWcMmSxwAAA_A"]
[Sun Aug 30 03:11:14.720021 2026] [security2:error] [pid 519566:tid 519819] [client 20.48.160.90:51932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/gjewuagf.php"] [unique_id "apPlotKCPt8cS-VWcMmSzQAABB4"]
[Sun Aug 30 03:11:14.744356 2026] [security2:error] [pid 518600:tid 518853] [client 4.205.62.107:15943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/cp2.php"] [unique_id "apPlou349Tv4SB45P2npTAAAAP0"]
[Sun Aug 30 03:11:14.753860 2026] [security2:error] [pid 519566:tid 519721] [client 20.63.81.20:59072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/xl2023.php"] [unique_id "apPlotKCPt8cS-VWcMmS3AAAA7w"]
[Sun Aug 30 03:11:14.758373 2026] [security2:error] [pid 518600:tid 518761] [client 20.196.209.81:15083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/theme-check/theme-check.php"] [unique_id "apPlou349Tv4SB45P2npTgAAAKE"]
[Sun Aug 30 03:11:14.766678 2026] [security2:error] [pid 519566:tid 519803] [client 40.83.93.50:3954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/cron.php"] [unique_id "apPlotKCPt8cS-VWcMmS4gAABA4"]
[Sun Aug 30 03:11:14.774375 2026] [security2:error] [pid 519566:tid 519752] [client 20.104.18.15:17003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/goods.php"] [unique_id "apPlotKCPt8cS-VWcMmS5AAAA9s"]
[Sun Aug 30 03:11:14.788771 2026] [security2:error] [pid 519566:tid 519722] [client 20.151.200.44:62981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlotKCPt8cS-VWcMmS5QAAA70"]
[Sun Aug 30 03:11:14.795710 2026] [security2:error] [pid 519566:tid 519739] [client 158.23.184.117:32133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/configuration.php"] [unique_id "apPlotKCPt8cS-VWcMmS5gAAA84"]
[Sun Aug 30 03:11:14.808216 2026] [security2:error] [pid 518600:tid 518743] [client 158.23.147.79:39300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPlou349Tv4SB45P2npVwAAAI8"]
[Sun Aug 30 03:11:14.830281 2026] [security2:error] [pid 518600:tid 518855] [client 20.151.200.44:64774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/admin.php/700.php"] [unique_id "apPlou349Tv4SB45P2npXgAAAP8"]
[Sun Aug 30 03:11:14.849408 2026] [security2:error] [pid 519566:tid 519740] [client 158.23.147.79:60182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/sad/about.php"] [unique_id "apPlotKCPt8cS-VWcMmTAAAAA88"]
[Sun Aug 30 03:11:14.862383 2026] [authz_core:error] [pid 519566:tid 519723] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:14.862694 2026] [authz_core:error] [pid 519566:tid 519723] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:14.882218 2026] [security2:error] [pid 519566:tid 519768] [client 20.63.81.20:59051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/V2.php"] [unique_id "apPlotKCPt8cS-VWcMmTCwAAA-s"]
[Sun Aug 30 03:11:14.889242 2026] [security2:error] [pid 519566:tid 519786] [client 20.48.251.3:59886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/66.php"] [unique_id "apPlotKCPt8cS-VWcMmTDAAAA_0"]
[Sun Aug 30 03:11:14.898915 2026] [security2:error] [pid 519566:tid 519711] [client 20.48.160.90:43594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/tnglzqmv.php"] [unique_id "apPlotKCPt8cS-VWcMmTDgAAA7I"]
[Sun Aug 30 03:11:14.906449 2026] [security2:error] [pid 519566:tid 519722] [client 20.104.50.220:52818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-raze.php"] [unique_id "apPlotKCPt8cS-VWcMmTEgAAA70"]
[Sun Aug 30 03:11:14.921019 2026] [authz_core:error] [pid 519566:tid 519729] [client 66.249.66.192:43508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:14.921404 2026] [authz_core:error] [pid 519566:tid 519729] [client 66.249.66.192:43508] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:14.933987 2026] [security2:error] [pid 519566:tid 519737] [client 20.151.200.44:41868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/admin.php/007x.php"] [unique_id "apPlotKCPt8cS-VWcMmTGgAAA8w"]
[Sun Aug 30 03:11:14.934010 2026] [security2:error] [pid 519566:tid 519794] [client 158.23.184.117:32186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/content.php"] [unique_id "apPlotKCPt8cS-VWcMmTGwAABAU"]
[Sun Aug 30 03:11:14.947623 2026] [security2:error] [pid 519566:tid 519701] [client 68.155.159.216:63258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/images/index.php"] [unique_id "apPlotKCPt8cS-VWcMmTHgAAA6g"]
[Sun Aug 30 03:11:14.948350 2026] [security2:error] [pid 519566:tid 519720] [client 20.104.49.130:53723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/dex.php"] [unique_id "apPlotKCPt8cS-VWcMmTHwAAA7s"]
[Sun Aug 30 03:11:14.964039 2026] [security2:error] [pid 519566:tid 519808] [client 158.23.147.79:43012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-includes/Requests/network.php"] [unique_id "apPlotKCPt8cS-VWcMmTJAAABBM"]
[Sun Aug 30 03:11:14.967443 2026] [security2:error] [pid 519566:tid 519785] [client 68.155.159.216:45992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/bk/index.php"] [unique_id "apPlotKCPt8cS-VWcMmTJQAAA_w"]
[Sun Aug 30 03:11:14.970851 2026] [authz_core:error] [pid 519566:tid 519709] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Ftls
[Sun Aug 30 03:11:14.971244 2026] [authz_core:error] [pid 519566:tid 519709] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Ftls
[Sun Aug 30 03:11:14.992086 2026] [autoindex:error] [pid 519566:tid 519765] [client 52.139.37.240:13832] AH01276: Cannot serve directory /home3/ragtimec/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:11:15.018832 2026] [security2:error] [pid 519566:tid 519803] [client 20.63.81.20:59025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/mad.php"] [unique_id "apPlo9KCPt8cS-VWcMmTNgAABA4"]
[Sun Aug 30 03:11:15.034541 2026] [security2:error] [pid 518600:tid 518789] [client 20.48.160.90:51853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/wefile.php"] [unique_id "apPlo-349Tv4SB45P2nphwAAAL0"]
[Sun Aug 30 03:11:15.046911 2026] [security2:error] [pid 519566:tid 519769] [client 20.104.50.220:61999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp_wrong_datlib.php"] [unique_id "apPlo9KCPt8cS-VWcMmTPgAAA-w"]
[Sun Aug 30 03:11:15.053473 2026] [security2:error] [pid 518600:tid 518844] [client 20.151.200.44:64827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/admin.php/007x.php"] [unique_id "apPlo-349Tv4SB45P2npjQAAAPQ"]
[Sun Aug 30 03:11:15.058925 2026] [security2:error] [pid 519566:tid 519702] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp-settings.php"] [unique_id "apPlo9KCPt8cS-VWcMmTQgAAA6k"]
[Sun Aug 30 03:11:15.075748 2026] [security2:error] [pid 519566:tid 519734] [client 158.23.184.117:32406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/core.php"] [unique_id "apPlo9KCPt8cS-VWcMmTTAAAA8k"]
[Sun Aug 30 03:11:15.101615 2026] [authz_core:error] [pid 518600:tid 518843] [client 66.249.66.70:61734] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:15.101901 2026] [authz_core:error] [pid 518600:tid 518843] [client 66.249.66.70:61734] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:15.146424 2026] [security2:error] [pid 518600:tid 518848] [client 20.63.81.20:59055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/st.php"] [unique_id "apPlo-349Tv4SB45P2nprwAAAPg"]
[Sun Aug 30 03:11:15.149182 2026] [security2:error] [pid 519566:tid 519738] [client 20.196.209.81:21742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/theme/about.php"] [unique_id "apPlo9KCPt8cS-VWcMmTZgAAA80"]
[Sun Aug 30 03:11:15.169574 2026] [security2:error] [pid 519566:tid 519714] [client 20.48.160.90:51961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/blog.php"] [unique_id "apPlo9KCPt8cS-VWcMmTcAAAA7U"]
[Sun Aug 30 03:11:15.180185 2026] [security2:error] [pid 519566:tid 519763] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/var/sites/gtag.php"] [unique_id "apPlo9KCPt8cS-VWcMmTdgAAA-Y"]
[Sun Aug 30 03:11:15.214057 2026] [security2:error] [pid 518600:tid 518744] [client 20.151.200.44:64168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/admin.php/heex.php"] [unique_id "apPlo-349Tv4SB45P2npxAAAAJA"]
[Sun Aug 30 03:11:15.216488 2026] [security2:error] [pid 519566:tid 519779] [client 158.23.184.117:32182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/data.php"] [unique_id "apPlo9KCPt8cS-VWcMmTfgAAA_Y"]
[Sun Aug 30 03:11:15.217999 2026] [security2:error] [pid 519566:tid 519724] [client 20.104.49.130:54177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/sxxb.php"] [unique_id "apPlo9KCPt8cS-VWcMmTgQAAA78"]
[Sun Aug 30 03:11:15.233969 2026] [security2:error] [pid 519566:tid 519792] [client 40.83.93.50:3948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/goat.php"] [unique_id "apPlo9KCPt8cS-VWcMmTiAAABAM"]
[Sun Aug 30 03:11:15.282633 2026] [security2:error] [pid 519566:tid 519738] [client 20.104.50.220:51637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/codeboy1877x.php"] [unique_id "apPlo9KCPt8cS-VWcMmTlQAAA80"]
[Sun Aug 30 03:11:15.283765 2026] [security2:error] [pid 518600:tid 518812] [client 20.63.81.20:59098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/alfanew.php"] [unique_id "apPlo-349Tv4SB45P2np4QAAANQ"]
[Sun Aug 30 03:11:15.298457 2026] [security2:error] [pid 519566:tid 519795] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp-load.php"] [unique_id "apPlo9KCPt8cS-VWcMmTnQAABAY"]
[Sun Aug 30 03:11:15.301442 2026] [security2:error] [pid 519566:tid 519763] [client 158.23.147.79:43599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-content/radio.php"] [unique_id "apPlo9KCPt8cS-VWcMmTngAAA-Y"]
[Sun Aug 30 03:11:15.324815 2026] [security2:error] [pid 519566:tid 519709] [client 74.7.241.128:33058] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.benjamindock.fairybowmother.com"] [uri "/cgi-sys/404.html"] [unique_id "apPlo9KCPt8cS-VWcMmTpwADsDE"]
[Sun Aug 30 03:11:15.326889 2026] [authz_core:error] [pid 519566:tid 519822] [client 216.73.216.128:45868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:15.327241 2026] [authz_core:error] [pid 519566:tid 519822] [client 216.73.216.128:45868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:15.332634 2026] [security2:error] [pid 519566:tid 519761] [client 20.48.160.90:51948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/wp-admin/js/wp-load.php"] [unique_id "apPlo9KCPt8cS-VWcMmTqwAAA-Q"]
[Sun Aug 30 03:11:15.336386 2026] [security2:error] [pid 518600:tid 518735] [client 20.104.50.220:17330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/.well-known/log.php"] [unique_id "apPlo-349Tv4SB45P2np8wAAAIc"]
[Sun Aug 30 03:11:15.356039 2026] [security2:error] [pid 519566:tid 519768] [client 158.23.184.117:32400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/database.php"] [unique_id "apPlo9KCPt8cS-VWcMmTsAAAA-s"]
[Sun Aug 30 03:11:15.363553 2026] [security2:error] [pid 519566:tid 519759] [client 20.104.50.220:33330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/Alfa.php"] [unique_id "apPlo9KCPt8cS-VWcMmTtAAAA-I"]
[Sun Aug 30 03:11:15.369362 2026] [authz_core:error] [pid 519566:tid 519766] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:11:15.369650 2026] [authz_core:error] [pid 519566:tid 519766] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:11:15.377895 2026] [authz_core:error] [pid 519566:tid 519734] [client 66.249.66.43:59047] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:15.378176 2026] [authz_core:error] [pid 519566:tid 519734] [client 66.249.66.43:59047] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:15.407263 2026] [security2:error] [pid 519566:tid 519713] [client 52.139.37.240:13832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/wp-config-sample.php"] [unique_id "apPlo9KCPt8cS-VWcMmTvQAAA7Q"]
[Sun Aug 30 03:11:15.410927 2026] [security2:error] [pid 518600:tid 518747] [client 20.63.81.20:59036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/ioxi.php"] [unique_id "apPlo-349Tv4SB45P2nqFAAAAJM"]
[Sun Aug 30 03:11:15.416852 2026] [security2:error] [pid 519566:tid 519698] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/admin/login.php"] [unique_id "apPlo9KCPt8cS-VWcMmTxgAAA6U"]
[Sun Aug 30 03:11:15.420951 2026] [authz_core:error] [pid 519566:tid 519784] [client 216.73.216.128:52619] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:15.421338 2026] [authz_core:error] [pid 519566:tid 519784] [client 216.73.216.128:52619] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:15.423097 2026] [security2:error] [pid 518600:tid 518756] [client 74.7.241.187:58926] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "cpcalendars.phl.jwb.temporary.site"] [uri "/___proxy_subdomain_cpcalendars/robots.txt"] [unique_id "apPlo-349Tv4SB45P2nqEQAAAJw"]
[Sun Aug 30 03:11:15.423684 2026] [security2:error] [pid 518600:tid 518741] [client 20.48.251.3:54832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/goods.php"] [unique_id "apPlo-349Tv4SB45P2nqFgAAAI0"]
[Sun Aug 30 03:11:15.432669 2026] [authz_core:error] [pid 519566:tid 519708] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Ftls
[Sun Aug 30 03:11:15.432959 2026] [authz_core:error] [pid 519566:tid 519708] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Ftls
[Sun Aug 30 03:11:15.438828 2026] [security2:error] [pid 518600:tid 518802] [client 20.104.50.220:5548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/version.php"] [unique_id "apPlo-349Tv4SB45P2nqGQAAAMo"]
[Sun Aug 30 03:11:15.439394 2026] [security2:error] [pid 519566:tid 519721] [client 20.104.49.130:48363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/82.php"] [unique_id "apPlo9KCPt8cS-VWcMmTzAAAA7w"]
[Sun Aug 30 03:11:15.455198 2026] [security2:error] [pid 519566:tid 519794] [client 20.104.18.15:18398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/sym.php"] [unique_id "apPlo9KCPt8cS-VWcMmT0QAABAU"]
[Sun Aug 30 03:11:15.463258 2026] [security2:error] [pid 518600:tid 518791] [client 20.48.160.90:28032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/robot.php"] [unique_id "apPlo-349Tv4SB45P2nqIwAAAL8"]
[Sun Aug 30 03:11:15.496926 2026] [security2:error] [pid 519566:tid 519772] [client 158.23.184.117:31749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/db.php"] [unique_id "apPlo9KCPt8cS-VWcMmT4gAAA-8"]
[Sun Aug 30 03:11:15.507403 2026] [security2:error] [pid 519566:tid 519713] [client 4.205.62.107:52909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/aws_config.php"] [unique_id "apPlo9KCPt8cS-VWcMmT6QAAA7Q"]
[Sun Aug 30 03:11:15.513724 2026] [security2:error] [pid 518600:tid 518819] [client 20.104.50.220:52832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/him.php"] [unique_id "apPlo-349Tv4SB45P2nqNAAAANs"]
[Sun Aug 30 03:11:15.535389 2026] [security2:error] [pid 518600:tid 518785] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/elrekt.php"] [unique_id "apPlo-349Tv4SB45P2nqOAAAALk"]
[Sun Aug 30 03:11:15.539098 2026] [security2:error] [pid 519566:tid 519822] [client 20.104.49.130:60141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/amax.php"] [unique_id "apPlo9KCPt8cS-VWcMmT9gAABCE"]
[Sun Aug 30 03:11:15.549082 2026] [security2:error] [pid 518600:tid 518780] [client 20.196.209.81:15050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/theme/min.php"] [unique_id "apPlo-349Tv4SB45P2nqPAAAALQ"]
[Sun Aug 30 03:11:15.550478 2026] [security2:error] [pid 518600:tid 518789] [client 20.63.81.20:59128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/TNT.php"] [unique_id "apPlo-349Tv4SB45P2nqPQAAAL0"]
[Sun Aug 30 03:11:15.569667 2026] [security2:error] [pid 518600:tid 518860] [client 68.155.159.216:54279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-mail.php"] [unique_id "apPlo-349Tv4SB45P2nqSAAAAQQ"]
[Sun Aug 30 03:11:15.576717 2026] [security2:error] [pid 519566:tid 519729] [client 20.104.50.220:63209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/hypo.php"] [unique_id "apPlo9KCPt8cS-VWcMmUBAAAA8Q"]
[Sun Aug 30 03:11:15.581580 2026] [security2:error] [pid 519566:tid 519768] [client 4.205.62.107:17280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/66.php"] [unique_id "apPlo9KCPt8cS-VWcMmUBwAAA-s"]
[Sun Aug 30 03:11:15.585612 2026] [security2:error] [pid 519566:tid 519805] [client 158.23.147.79:43642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-admin/dropdown.php"] [unique_id "apPlo9KCPt8cS-VWcMmUCAAABBA"]
[Sun Aug 30 03:11:15.593983 2026] [security2:error] [pid 519566:tid 519817] [client 20.48.160.90:51870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/revo.php"] [unique_id "apPlo9KCPt8cS-VWcMmUDgAABBw"]
[Sun Aug 30 03:11:15.609721 2026] [security2:error] [pid 519566:tid 519696] [client 52.139.37.240:44604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "briankornblum.com"] [uri "/wp-content/packed.php"] [unique_id "apPlo9KCPt8cS-VWcMmUEwAAA6M"]
[Sun Aug 30 03:11:15.617882 2026] [security2:error] [pid 518600:tid 518757] [client 20.48.251.3:52796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/grsiuk.php"] [unique_id "apPlo-349Tv4SB45P2nqWwAAAJ0"]
[Sun Aug 30 03:11:15.622392 2026] [security2:error] [pid 518600:tid 518852] [client 20.48.251.3:37170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/phpinfo01.php"] [unique_id "apPlo-349Tv4SB45P2nqXwAAAPw"]
[Sun Aug 30 03:11:15.628855 2026] [security2:error] [pid 519566:tid 519698] [client 20.104.18.15:22359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/file31.php"] [unique_id "apPlo9KCPt8cS-VWcMmUHAAAA6U"]
[Sun Aug 30 03:11:15.638593 2026] [security2:error] [pid 519566:tid 519812] [client 158.23.184.117:32128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/default.php"] [unique_id "apPlo9KCPt8cS-VWcMmUHwAABBc"]
[Sun Aug 30 03:11:15.657449 2026] [security2:error] [pid 519566:tid 519811] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/manager/login.php"] [unique_id "apPlo9KCPt8cS-VWcMmUJAAABBY"]
[Sun Aug 30 03:11:15.672469 2026] [security2:error] [pid 519566:tid 519620] [remote 206.189.132.124:54282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.132.189.206.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thehortonlawfirm.com"] [uri "/wp-login.php"] [unique_id "apPlo9KCPt8cS-VWcMmUIwADyjU"]
[Sun Aug 30 03:11:15.681817 2026] [security2:error] [pid 519566:tid 519775] [client 20.63.81.20:59027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/cd.php"] [unique_id "apPlo9KCPt8cS-VWcMmULAAAA_I"]
[Sun Aug 30 03:11:15.688999 2026] [security2:error] [pid 519566:tid 519779] [client 158.23.147.79:60223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/admin.php"] [unique_id "apPlo9KCPt8cS-VWcMmULgAAA_Y"]
[Sun Aug 30 03:11:15.704848 2026] [security2:error] [pid 519566:tid 519763] [client 40.83.93.50:7102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/gg.php"] [unique_id "apPlo9KCPt8cS-VWcMmUNAAAA-Y"]
[Sun Aug 30 03:11:15.720043 2026] [security2:error] [pid 519566:tid 519801] [client 20.104.18.15:31638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/zoo1.php"] [unique_id "apPlo9KCPt8cS-VWcMmUOAAABAw"]
[Sun Aug 30 03:11:15.726048 2026] [security2:error] [pid 519566:tid 519743] [client 20.48.160.90:43612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/birrs.php"] [unique_id "apPlo9KCPt8cS-VWcMmUOgAAA9I"]
[Sun Aug 30 03:11:15.779716 2026] [security2:error] [pid 518600:tid 518844] [client 20.104.50.220:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "/_?#?(?:(?:p(?:ma_?(?:bd)?)?(?:hp)?)?\\\\d?)?-?(?:mya?d?)?(?:sql)?\\\\d?_?-?(?:php(?:as)?)?(?:db)?(?:(database)?ad?mm??i?n?s?(?:istrator)?(?:\\\\.old)?)?-?_?(?:(?:(?:\\\\d\\\\.?){1,5})?-?(?:pl\\\\d?|rc\\\\d?|beta\\\\d?)?)/(scripts/setup|config/config\\\\.inc)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1305"] [id "999995"] [rev "2"] [msg "PHPMyadmin Script Attack"] [severity "WARNING"] [hostname "cagtu.com"] [uri "/phpMyAdmin/scripts/setup.php"] [unique_id "apPlo-349Tv4SB45P2nqhgAAAPQ"]
[Sun Aug 30 03:11:15.797054 2026] [security2:error] [pid 519566:tid 519742] [client 158.23.184.117:32156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/dev1s.php"] [unique_id "apPlo9KCPt8cS-VWcMmUUAAAA9E"]
[Sun Aug 30 03:11:15.814482 2026] [security2:error] [pid 518600:tid 518798] [client 20.63.81.20:59066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/luuf.php"] [unique_id "apPlo-349Tv4SB45P2nqjQAAAMY"]
[Sun Aug 30 03:11:15.827275 2026] [autoindex:error] [pid 518600:tid 518830] [client 52.139.37.240:44590] AH01276: Cannot serve directory /home3/ragtimec/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:11:15.860088 2026] [security2:error] [pid 519566:tid 519745] [client 20.48.160.90:28152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/sss.php"] [unique_id "apPlo9KCPt8cS-VWcMmUZAAAA9Q"]
[Sun Aug 30 03:11:15.865162 2026] [security2:error] [pid 519566:tid 519727] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/dede/login.php"] [unique_id "apPlo9KCPt8cS-VWcMmUZgAAA8I"]
[Sun Aug 30 03:11:15.875661 2026] [core:alert] [pid 519566:tid 519785] [client 185.171.73.115:29908] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:11:15.882788 2026] [authz_core:error] [pid 519566:tid 519743] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:15.882933 2026] [security2:error] [pid 519566:tid 519805] [client 158.23.147.79:43022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/login.php"] [unique_id "apPlo9KCPt8cS-VWcMmUbAAABBA"]
[Sun Aug 30 03:11:15.883216 2026] [authz_core:error] [pid 519566:tid 519743] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:15.886150 2026] [security2:error] [pid 519566:tid 519820] [client 4.205.62.107:15826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/xda.php"] [unique_id "apPlo9KCPt8cS-VWcMmUbgAABB8"]
[Sun Aug 30 03:11:15.887990 2026] [security2:error] [pid 519566:tid 519766] [client 4.205.62.107:36593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/server_info.php"] [unique_id "apPlo9KCPt8cS-VWcMmUbwAAA-k"]
[Sun Aug 30 03:11:15.893097 2026] [authz_core:error] [pid 519566:tid 519787] [client 216.73.216.128:52619] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:15.893461 2026] [authz_core:error] [pid 519566:tid 519787] [client 216.73.216.128:52619] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:15.908249 2026] [security2:error] [pid 519566:tid 519696] [client 4.205.62.107:25879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/motu.php"] [unique_id "apPlo9KCPt8cS-VWcMmUdQAAA6M"]
[Sun Aug 30 03:11:15.927430 2026] [security2:error] [pid 519566:tid 519737] [client 20.104.18.15:16954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/ah.php"] [unique_id "apPlo9KCPt8cS-VWcMmUewAAA8w"]
[Sun Aug 30 03:11:15.934352 2026] [authz_core:error] [pid 519566:tid 519768] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Ftls
[Sun Aug 30 03:11:15.934631 2026] [authz_core:error] [pid 519566:tid 519768] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Ftls
[Sun Aug 30 03:11:15.937595 2026] [security2:error] [pid 518600:tid 518832] [client 158.23.184.117:32132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/dex.php"] [unique_id "apPlo-349Tv4SB45P2nqqAAAAOg"]
[Sun Aug 30 03:11:15.938537 2026] [security2:error] [pid 519566:tid 519811] [client 20.196.209.81:21732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/themes/about.php"] [unique_id "apPlo9KCPt8cS-VWcMmUfAAABBY"]
[Sun Aug 30 03:11:15.939005 2026] [lsapi:error] [pid 519566:tid 519617] [remote 201.87.20.9:40186] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n
[Sun Aug 30 03:11:15.939107 2026] [lsapi:error] [pid 519566:tid 519617] [remote 201.87.20.9:40186] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n
[Sun Aug 30 03:11:15.940546 2026] [lsapi:error] [pid 519566:tid 519617] [remote 201.87.20.9:40186] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n
[Sun Aug 30 03:11:15.941803 2026] [security2:error] [pid 518600:tid 518820] [client 20.63.81.20:59069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/fex.php"] [unique_id "apPlo-349Tv4SB45P2nqqgAAANw"]
[Sun Aug 30 03:11:15.963617 2026] [security2:error] [pid 519566:tid 519782] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/admindede/login.php"] [unique_id "apPlo9KCPt8cS-VWcMmUiwAAA_k"]
[Sun Aug 30 03:11:16.033391 2026] [authz_core:error] [pid 519566:tid 519703] [client 66.249.66.36:60464] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:16.033669 2026] [authz_core:error] [pid 519566:tid 519703] [client 66.249.66.36:60464] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:16.058153 2026] [security2:error] [pid 519566:tid 519728] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/phpinfo.php"] [unique_id "apPlpNKCPt8cS-VWcMmUqgAAA8M"]
[Sun Aug 30 03:11:16.058818 2026] [security2:error] [pid 519566:tid 519712] [client 20.48.251.3:52279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/admin.php"] [unique_id "apPlpNKCPt8cS-VWcMmUqwAAA7M"]
[Sun Aug 30 03:11:16.069159 2026] [security2:error] [pid 519566:tid 519746] [client 68.155.159.216:63288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apPlpNKCPt8cS-VWcMmUrwAAA9U"]
[Sun Aug 30 03:11:16.072851 2026] [security2:error] [pid 518600:tid 518811] [client 20.63.81.20:59052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/l.php"] [unique_id "apPlpO349Tv4SB45P2nqvgAAANM"]
[Sun Aug 30 03:11:16.073556 2026] [authz_core:error] [pid 519566:tid 519742] [client 216.73.216.128:52619] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:16.074011 2026] [authz_core:error] [pid 519566:tid 519742] [client 216.73.216.128:52619] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:16.075611 2026] [security2:error] [pid 519566:tid 519716] [client 158.23.184.117:32162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/disagrsxr.php"] [unique_id "apPlpNKCPt8cS-VWcMmUsAAAA7c"]
[Sun Aug 30 03:11:16.078978 2026] [security2:error] [pid 519566:tid 519782] [client 158.23.147.79:43056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/hehehehe.php"] [unique_id "apPlpNKCPt8cS-VWcMmUtgAAA_k"]
[Sun Aug 30 03:11:16.081550 2026] [security2:error] [pid 519566:tid 519779] [client 20.104.50.220:28700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-init.php"] [unique_id "apPlpNKCPt8cS-VWcMmUuAAAA_Y"]
[Sun Aug 30 03:11:16.102702 2026] [security2:error] [pid 519566:tid 519727] [client 20.151.200.44:65386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/tf.php"] [unique_id "apPlpNKCPt8cS-VWcMmUxwAAA8I"]
[Sun Aug 30 03:11:16.185305 2026] [security2:error] [pid 519566:tid 519766] [client 40.83.93.50:6384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/defaults.php"] [unique_id "apPlpNKCPt8cS-VWcMmU4wAAA-k"]
[Sun Aug 30 03:11:16.198759 2026] [security2:error] [pid 519566:tid 519803] [client 68.155.159.216:45889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.localconnections.info"] [uri "/first.php"] [unique_id "apPlpNKCPt8cS-VWcMmU7AAABA4"]
[Sun Aug 30 03:11:16.217447 2026] [security2:error] [pid 519566:tid 519736] [client 20.63.81.20:59045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/xr.php"] [unique_id "apPlpNKCPt8cS-VWcMmU8QAAA8s"]
[Sun Aug 30 03:11:16.217567 2026] [security2:error] [pid 519566:tid 519725] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/.env.bak"] [unique_id "apPlpNKCPt8cS-VWcMmU8AAAA8A"]
[Sun Aug 30 03:11:16.219493 2026] [security2:error] [pid 519566:tid 519749] [client 20.151.200.44:63661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/h02ugyh.php"] [unique_id "apPlpNKCPt8cS-VWcMmU8gAAA9g"]
[Sun Aug 30 03:11:16.235533 2026] [security2:error] [pid 519566:tid 519809] [client 158.23.184.117:31755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/domvf.php"] [unique_id "apPlpNKCPt8cS-VWcMmU-wAABBQ"]
[Sun Aug 30 03:11:16.247522 2026] [authz_core:error] [pid 519566:tid 519705] [client 66.249.66.71:43197] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:16.247858 2026] [authz_core:error] [pid 519566:tid 519705] [client 66.249.66.71:43197] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:16.283157 2026] [security2:error] [pid 519566:tid 519732] [client 158.23.147.79:43034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-includes/fonts/about.php"] [unique_id "apPlpNKCPt8cS-VWcMmVCAAAA8c"]
[Sun Aug 30 03:11:16.299227 2026] [security2:error] [pid 519566:tid 519806] [client 20.104.50.220:62011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/ws.php"] [unique_id "apPlpNKCPt8cS-VWcMmVDwAABBE"]
[Sun Aug 30 03:11:16.328658 2026] [security2:error] [pid 519566:tid 519696] [client 20.196.209.81:21705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/themes/panel.php"] [unique_id "apPlpNKCPt8cS-VWcMmVHAAAA6M"]
[Sun Aug 30 03:11:16.330164 2026] [security2:error] [pid 519566:tid 519756] [client 159.194.220.18:55274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.220.194.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oklahomacitydivorceattorney.pro"] [uri "/wp-login.php"] [unique_id "apPlpNKCPt8cS-VWcMmVFgAAA98"]
[Sun Aug 30 03:11:16.347930 2026] [security2:error] [pid 519566:tid 519740] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/installer.php"] [unique_id "apPlpNKCPt8cS-VWcMmVLAAAA88"]
[Sun Aug 30 03:11:16.358320 2026] [security2:error] [pid 519566:tid 519774] [client 20.63.81.20:59089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/Q3.php"] [unique_id "apPlpNKCPt8cS-VWcMmVMgAAA_E"]
[Sun Aug 30 03:11:16.359024 2026] [authz_core:error] [pid 519566:tid 519742] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:16.359429 2026] [authz_core:error] [pid 519566:tid 519742] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:16.362804 2026] [security2:error] [pid 519566:tid 519746] [client 158.23.147.79:60174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-admin/admin.php"] [unique_id "apPlpNKCPt8cS-VWcMmVNQAAA9U"]
[Sun Aug 30 03:11:16.378223 2026] [security2:error] [pid 519566:tid 519816] [client 158.23.184.117:31776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/donate.php"] [unique_id "apPlpNKCPt8cS-VWcMmVPAAABBs"]
[Sun Aug 30 03:11:16.420479 2026] [security2:error] [pid 519566:tid 519807] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/.env.backup"] [unique_id "apPlpNKCPt8cS-VWcMmVSwAABBI"]
[Sun Aug 30 03:11:16.450836 2026] [security2:error] [pid 519566:tid 519792] [client 158.23.147.79:39164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-content/admin.php"] [unique_id "apPlpNKCPt8cS-VWcMmVWgAABAM"]
[Sun Aug 30 03:11:16.456472 2026] [authz_core:error] [pid 519566:tid 519776] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Ftls
[Sun Aug 30 03:11:16.456950 2026] [authz_core:error] [pid 519566:tid 519776] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Ftls
[Sun Aug 30 03:11:16.466146 2026] [security2:error] [pid 519566:tid 519788] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/web/index.php"] [unique_id "apPlpNKCPt8cS-VWcMmVZQAAA_8"]
[Sun Aug 30 03:11:16.470519 2026] [security2:error] [pid 519566:tid 519770] [client 20.104.50.220:16676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/class.php"] [unique_id "apPlpNKCPt8cS-VWcMmVZgAAA-0"]
[Sun Aug 30 03:11:16.476013 2026] [security2:error] [pid 518600:tid 518776] [client 20.151.200.44:41912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/admin.php/heex.php"] [unique_id "apPlpO349Tv4SB45P2nrHQAAALA"]
[Sun Aug 30 03:11:16.490107 2026] [security2:error] [pid 519566:tid 519780] [client 20.63.81.20:59057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/Q1.php"] [unique_id "apPlpNKCPt8cS-VWcMmVbQAAA_c"]
[Sun Aug 30 03:11:16.509450 2026] [security2:error] [pid 519566:tid 519772] [client 20.104.50.220:42754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wsanon.php"] [unique_id "apPlpNKCPt8cS-VWcMmVcQAAA-8"]
[Sun Aug 30 03:11:16.517983 2026] [security2:error] [pid 519566:tid 519807] [client 20.104.50.220:33314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-admin/includes/mailer.php.php"] [unique_id "apPlpNKCPt8cS-VWcMmVewAABBI"]
[Sun Aug 30 03:11:16.518719 2026] [security2:error] [pid 519566:tid 519817] [client 158.23.184.117:31783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/dropdown.php"] [unique_id "apPlpNKCPt8cS-VWcMmVfAAABBw"]
[Sun Aug 30 03:11:16.561980 2026] [security2:error] [pid 519566:tid 519765] [client 20.48.251.3:64310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/loxi-o.php"] [unique_id "apPlpNKCPt8cS-VWcMmVigAAA-g"]
[Sun Aug 30 03:11:16.562284 2026] [security2:error] [pid 518600:tid 518735] [client 158.23.147.79:43607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/xmlrpc.php"] [unique_id "apPlpO349Tv4SB45P2nrSQAAAIc"]
[Sun Aug 30 03:11:16.580932 2026] [security2:error] [pid 518600:tid 518821] [client 20.104.50.220:5601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/user.php"] [unique_id "apPlpO349Tv4SB45P2nrUQAAAN0"]
[Sun Aug 30 03:11:16.587143 2026] [security2:error] [pid 518600:tid 518806] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/unzip.php"] [unique_id "apPlpO349Tv4SB45P2nrVAAAAM4"]
[Sun Aug 30 03:11:16.606869 2026] [security2:error] [pid 518600:tid 518753] [client 20.104.18.15:18356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/8.php"] [unique_id "apPlpO349Tv4SB45P2nrYgAAAJk"]
[Sun Aug 30 03:11:16.622234 2026] [security2:error] [pid 519566:tid 519628] [remote 206.189.132.124:54282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.132.189.206.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thehortonlawfirm.com"] [uri "/wp-login.php"] [unique_id "apPlpNKCPt8cS-VWcMmVkQAD-D0"], referer: https://thehortonlawfirm.com/wp-login.php
[Sun Aug 30 03:11:16.626282 2026] [security2:error] [pid 518600:tid 518827] [client 20.63.81.20:59133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/nz.php"] [unique_id "apPlpO349Tv4SB45P2nrcAAAAOM"]
[Sun Aug 30 03:11:16.646526 2026] [security2:error] [pid 519566:tid 519738] [client 4.205.62.107:52918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/dialog.php"] [unique_id "apPlpNKCPt8cS-VWcMmVlwAAA80"]
[Sun Aug 30 03:11:16.659359 2026] [security2:error] [pid 518600:tid 518829] [client 158.23.184.117:31791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/edit.php"] [unique_id "apPlpO349Tv4SB45P2nrfAAAAOU"]
[Sun Aug 30 03:11:16.662051 2026] [security2:error] [pid 519566:tid 519785] [client 20.104.50.220:28718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/hh.php"] [unique_id "apPlpNKCPt8cS-VWcMmVoAAAA_w"]
[Sun Aug 30 03:11:16.668863 2026] [security2:error] [pid 518600:tid 518784] [client 158.23.147.79:43590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/atomlib.php"] [unique_id "apPlpO349Tv4SB45P2nrfgAAALg"]
[Sun Aug 30 03:11:16.682038 2026] [security2:error] [pid 519566:tid 519786] [client 40.83.93.50:3937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/h.php"] [unique_id "apPlpNKCPt8cS-VWcMmVqgAAA_0"]
[Sun Aug 30 03:11:16.709820 2026] [security2:error] [pid 519566:tid 519740] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/info.php"] [unique_id "apPlpNKCPt8cS-VWcMmVswAAA88"]
[Sun Aug 30 03:11:16.712702 2026] [authz_core:error] [pid 519566:tid 519711] [client 216.73.216.128:45868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:16.713094 2026] [authz_core:error] [pid 519566:tid 519711] [client 216.73.216.128:45868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:16.725172 2026] [security2:error] [pid 518600:tid 518765] [client 4.205.62.107:17283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/admin.php"] [unique_id "apPlpO349Tv4SB45P2nrjAAAAKU"]
[Sun Aug 30 03:11:16.755344 2026] [autoindex:error] [pid 518600:tid 518787] [client 20.196.209.81:19168] AH01276: Cannot serve directory /home3/shutters/advoutpost.com/wp-content/themes/twentytwentyfive/styles/sections/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:11:16.757960 2026] [security2:error] [pid 519566:tid 519738] [client 20.48.251.3:55743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/paypal.php"] [unique_id "apPlpNKCPt8cS-VWcMmVxgAAA80"]
[Sun Aug 30 03:11:16.761749 2026] [security2:error] [pid 519566:tid 519806] [client 20.48.251.3:37145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/cxc.php"] [unique_id "apPlpNKCPt8cS-VWcMmVygAABBE"]
[Sun Aug 30 03:11:16.772882 2026] [security2:error] [pid 518600:tid 518746] [client 20.63.81.20:58950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/sg.php"] [unique_id "apPlpO349Tv4SB45P2nrnwAAAJI"]
[Sun Aug 30 03:11:16.800178 2026] [security2:error] [pid 518600:tid 518770] [client 158.23.184.117:31772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/ee.php"] [unique_id "apPlpO349Tv4SB45P2nrowAAAKo"]
[Sun Aug 30 03:11:16.826800 2026] [security2:error] [pid 519566:tid 519706] [client 20.104.18.15:22469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/dk.php"] [unique_id "apPlpNKCPt8cS-VWcMmV3QAAA60"]
[Sun Aug 30 03:11:16.828481 2026] [security2:error] [pid 518600:tid 518779] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/up.php"] [unique_id "apPlpO349Tv4SB45P2nrrgAAALM"]
[Sun Aug 30 03:11:16.829215 2026] [security2:error] [pid 519566:tid 519753] [client 20.104.50.220:31501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/chosen.php"] [unique_id "apPlpNKCPt8cS-VWcMmV4AAAA9w"]
[Sun Aug 30 03:11:16.855019 2026] [security2:error] [pid 519566:tid 519629] [remote 69.57.172.119:49402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.172.57.69.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petra-jordan-attractions.com"] [uri "/wp-login.php"] [unique_id "apPlpNKCPt8cS-VWcMmV5QADwj4"], referer: https://petra-jordan-attractions.com/wp-login.php
[Sun Aug 30 03:11:16.858147 2026] [security2:error] [pid 519566:tid 519737] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/.env.old"] [unique_id "apPlpNKCPt8cS-VWcMmV5gAAA8w"]
[Sun Aug 30 03:11:16.873376 2026] [security2:error] [pid 519566:tid 519721] [client 20.104.18.15:31621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/radio.php"] [unique_id "apPlpNKCPt8cS-VWcMmV6QAAA7w"]
[Sun Aug 30 03:11:16.874515 2026] [security2:error] [pid 518600:tid 518801] [client 158.23.147.79:43631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/lv.php"] [unique_id "apPlpO349Tv4SB45P2nrsQAAAMk"]
[Sun Aug 30 03:11:16.877097 2026] [authz_core:error] [pid 519566:tid 519809] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:11:16.877374 2026] [authz_core:error] [pid 519566:tid 519809] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:11:16.884896 2026] [security2:error] [pid 518600:tid 518795] [client 20.196.209.81:19168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/twentytwentyfive/styles/sections/pk.php"] [unique_id "apPlpO349Tv4SB45P2nrsgAAAMM"]
[Sun Aug 30 03:11:16.889842 2026] [security2:error] [pid 518600:tid 518803] [client 20.104.49.130:52463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/sxxb.php"] [unique_id "apPlpO349Tv4SB45P2nrtQAAAMs"]
[Sun Aug 30 03:11:16.901372 2026] [security2:error] [pid 519566:tid 519733] [client 20.63.81.20:59039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/hypo.php"] [unique_id "apPlpNKCPt8cS-VWcMmV9AAAA8g"]
[Sun Aug 30 03:11:16.903022 2026] [authz_core:error] [pid 519566:tid 519766] [client 216.73.216.128:52619] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:16.903361 2026] [authz_core:error] [pid 519566:tid 519766] [client 216.73.216.128:52619] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:16.940844 2026] [security2:error] [pid 519566:tid 519746] [client 158.23.184.117:31792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/elp.php"] [unique_id "apPlpNKCPt8cS-VWcMmWAQAAA9U"]
[Sun Aug 30 03:11:16.945256 2026] [authz_core:error] [pid 519566:tid 519772] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Ftls
[Sun Aug 30 03:11:16.945694 2026] [authz_core:error] [pid 519566:tid 519772] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Ftls
[Sun Aug 30 03:11:16.947345 2026] [security2:error] [pid 519566:tid 519790] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/unzipper.php"] [unique_id "apPlpNKCPt8cS-VWcMmWBQAABAE"]
[Sun Aug 30 03:11:16.973408 2026] [authz_core:error] [pid 518600:tid 518736] [client 66.249.66.201:58157] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:16.973775 2026] [authz_core:error] [pid 518600:tid 518736] [client 66.249.66.201:58157] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:17.019605 2026] [security2:error] [pid 519566:tid 519718] [client 4.205.62.107:15937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/pinfo.php"] [unique_id "apPlpdKCPt8cS-VWcMmWJAAAA7k"]
[Sun Aug 30 03:11:17.030538 2026] [security2:error] [pid 518600:tid 518842] [client 20.63.81.20:58999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/Hd.php"] [unique_id "apPlpe349Tv4SB45P2nr0QAAAPI"]
[Sun Aug 30 03:11:17.035365 2026] [security2:error] [pid 518600:tid 518792] [client 68.155.159.216:52588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/cgi-bin/index.php"] [unique_id "apPlpe349Tv4SB45P2nr0wAAAMA"]
[Sun Aug 30 03:11:17.050244 2026] [security2:error] [pid 518600:tid 518841] [client 4.205.62.107:36682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/hosty.php"] [unique_id "apPlpe349Tv4SB45P2nr2QAAAPE"]
[Sun Aug 30 03:11:17.050602 2026] [security2:error] [pid 519566:tid 519804] [client 4.205.62.107:25791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/public/mah.php.php"] [unique_id "apPlpdKCPt8cS-VWcMmWLwAABA8"]
[Sun Aug 30 03:11:17.066102 2026] [security2:error] [pid 518600:tid 518815] [client 20.104.18.15:16960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/ws55.php"] [unique_id "apPlpe349Tv4SB45P2nr3AAAANc"]
[Sun Aug 30 03:11:17.066657 2026] [security2:error] [pid 519566:tid 519778] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/upload.php"] [unique_id "apPlpdKCPt8cS-VWcMmWNQAAA_U"]
[Sun Aug 30 03:11:17.068520 2026] [security2:error] [pid 519566:tid 519802] [client 158.23.147.79:39133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-includes/Text/index.php"] [unique_id "apPlpdKCPt8cS-VWcMmWNwAABA0"]
[Sun Aug 30 03:11:17.068599 2026] [security2:error] [pid 519566:tid 519817] [client 158.23.184.117:8542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/new.php"] [unique_id "apPlpdKCPt8cS-VWcMmWNgAABBw"]
[Sun Aug 30 03:11:17.082282 2026] [security2:error] [pid 518600:tid 518744] [client 158.23.184.117:31798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/en.php"] [unique_id "apPlpe349Tv4SB45P2nr3gAAAJA"]
[Sun Aug 30 03:11:17.167828 2026] [security2:error] [pid 519566:tid 519732] [client 216.73.216.128:52619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/usage_202607.html"] [unique_id "apPlpdKCPt8cS-VWcMmWUQAAA8c"]
[Sun Aug 30 03:11:17.174094 2026] [security2:error] [pid 518600:tid 518801] [client 20.63.81.20:59020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/im.php"] [unique_id "apPlpe349Tv4SB45P2nr9gAAAMk"]
[Sun Aug 30 03:11:17.183115 2026] [security2:error] [pid 519566:tid 519715] [client 40.83.93.50:7046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/num.php"] [unique_id "apPlpdKCPt8cS-VWcMmWWgAAA7Y"]
[Sun Aug 30 03:11:17.184092 2026] [security2:error] [pid 518600:tid 518817] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/panel/settings.php"] [unique_id "apPlpe349Tv4SB45P2nr-QAAANk"]
[Sun Aug 30 03:11:17.200026 2026] [security2:error] [pid 519566:tid 519758] [client 20.48.251.3:59504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/png.php"] [unique_id "apPlpdKCPt8cS-VWcMmWZgAAA-E"]
[Sun Aug 30 03:11:17.211762 2026] [security2:error] [pid 519566:tid 519741] [client 68.155.159.216:57060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apPlpdKCPt8cS-VWcMmWawAAA9A"]
[Sun Aug 30 03:11:17.224851 2026] [security2:error] [pid 519566:tid 519743] [client 158.23.184.117:31767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dejulschoolofdance.com"] [uri "/error.php"] [unique_id "apPlpdKCPt8cS-VWcMmWcQAAA9I"]
[Sun Aug 30 03:11:17.224911 2026] [security2:error] [pid 519566:tid 519798] [client 20.104.50.220:62843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/lyda.php"] [unique_id "apPlpdKCPt8cS-VWcMmWcgAABAk"]
[Sun Aug 30 03:11:17.237381 2026] [security2:error] [pid 519566:tid 519777] [client 20.151.200.44:41892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/tf.php"] [unique_id "apPlpdKCPt8cS-VWcMmWdgAAA_Q"]
[Sun Aug 30 03:11:17.287310 2026] [security2:error] [pid 518600:tid 518842] [client 20.151.200.44:62992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/sf.php"] [unique_id "apPlpe349Tv4SB45P2nsGAAAAPI"]
[Sun Aug 30 03:11:17.298830 2026] [security2:error] [pid 519566:tid 519731] [client 185.231.154.128:60125] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "185.231.154.128" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "tastylandscape.com"] [uri "/wp-comments-post.php"] [unique_id "apPlpdKCPt8cS-VWcMmWigAAA8Y"], referer: https://tastylandscape.com/2015/09/05/dragon-fruit-diseases/
[Sun Aug 30 03:11:17.298935 2026] [security2:error] [pid 519566:tid 519731] [client 185.231.154.128:60125] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "tastylandscape.com"] [uri "/wp-comments-post.php"] [unique_id "apPlpdKCPt8cS-VWcMmWigAAA8Y"], referer: https://tastylandscape.com/2015/09/05/dragon-fruit-diseases/
[Sun Aug 30 03:11:17.300342 2026] [security2:error] [pid 519566:tid 519775] [client 20.63.81.20:59049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/fc.php"] [unique_id "apPlpdKCPt8cS-VWcMmWjAAAA_I"]
[Sun Aug 30 03:11:17.306034 2026] [autoindex:error] [pid 519566:tid 519803] [client 20.196.209.81:15048] AH01276: Cannot serve directory /home3/shutters/advoutpost.com/wp-content/themes/twentytwentythree/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:11:17.307535 2026] [security2:error] [pid 519566:tid 519778] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/uploader.php"] [unique_id "apPlpdKCPt8cS-VWcMmWkwAAA_U"]
[Sun Aug 30 03:11:17.348816 2026] [authz_core:error] [pid 519566:tid 519735] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:11:17.349294 2026] [authz_core:error] [pid 519566:tid 519735] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:11:17.359250 2026] [security2:error] [pid 518600:tid 518733] [client 158.23.147.79:60168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-includes/IXR/index.php"] [unique_id "apPlpe349Tv4SB45P2nsLwAAAIU"]
[Sun Aug 30 03:11:17.379726 2026] [security2:error] [pid 519566:tid 519731] [client 158.23.147.79:43604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/content.php"] [unique_id "apPlpdKCPt8cS-VWcMmWtgAAA8Y"]
[Sun Aug 30 03:11:17.380199 2026] [security2:error] [pid 519566:tid 519775] [client 20.151.200.44:40931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/ft.php"] [unique_id "apPlpdKCPt8cS-VWcMmWtwAAA_I"]
[Sun Aug 30 03:11:17.404175 2026] [security2:error] [pid 519566:tid 519704] [client 158.23.184.117:8514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/bypass.php"] [unique_id "apPlpdKCPt8cS-VWcMmWuwAAA6s"]
[Sun Aug 30 03:11:17.428028 2026] [security2:error] [pid 519566:tid 519771] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/page-footer.php"] [unique_id "apPlpdKCPt8cS-VWcMmWwAAAA-4"]
[Sun Aug 30 03:11:17.432489 2026] [security2:error] [pid 519566:tid 519730] [client 20.63.81.20:58988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/ke.php"] [unique_id "apPlpdKCPt8cS-VWcMmWxAAAA8U"]
[Sun Aug 30 03:11:17.438271 2026] [security2:error] [pid 519566:tid 519736] [client 20.196.209.81:15048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/twentytwentythree/patterns/index.php"] [unique_id "apPlpdKCPt8cS-VWcMmWxgAAA8s"]
[Sun Aug 30 03:11:17.448935 2026] [authz_core:error] [pid 519566:tid 519709] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmisc
[Sun Aug 30 03:11:17.449416 2026] [authz_core:error] [pid 519566:tid 519709] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmisc
[Sun Aug 30 03:11:17.470363 2026] [authz_core:error] [pid 519566:tid 519819] [client 66.249.66.75:45211] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:17.470658 2026] [authz_core:error] [pid 519566:tid 519819] [client 66.249.66.75:45211] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:17.491211 2026] [security2:error] [pid 519566:tid 519743] [client 20.104.50.220:61434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/notfound.php"] [unique_id "apPlpdKCPt8cS-VWcMmW2wAAA9I"]
[Sun Aug 30 03:11:17.541152 2026] [authz_core:error] [pid 519566:tid 519721] [client 216.73.216.128:8101] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:17.541549 2026] [authz_core:error] [pid 519566:tid 519721] [client 216.73.216.128:8101] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:17.544806 2026] [security2:error] [pid 519566:tid 519755] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/attachment.php"] [unique_id "apPlpdKCPt8cS-VWcMmW8gAAA94"]
[Sun Aug 30 03:11:17.546273 2026] [security2:error] [pid 519566:tid 519770] [client 158.23.184.117:8569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/db/uploader.php"] [unique_id "apPlpdKCPt8cS-VWcMmW8wAAA-0"]
[Sun Aug 30 03:11:17.564244 2026] [security2:error] [pid 519566:tid 519720] [client 20.63.81.20:59122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/tf.php"] [unique_id "apPlpdKCPt8cS-VWcMmW9wAAA7s"]
[Sun Aug 30 03:11:17.576935 2026] [authz_core:error] [pid 519566:tid 519806] [client 66.249.66.32:63996] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:17.577333 2026] [authz_core:error] [pid 519566:tid 519806] [client 66.249.66.32:63996] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:17.601482 2026] [core:alert] [pid 519566:tid 519768] [client 45.175.15.186:19259] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:11:17.601947 2026] [security2:error] [pid 519566:tid 519790] [client 20.104.50.220:16718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/bless5.php"] [unique_id "apPlpdKCPt8cS-VWcMmXAQAABAE"]
[Sun Aug 30 03:11:17.629219 2026] [authz_core:error] [pid 519566:tid 519793] [client 216.73.216.128:18817] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:17.629335 2026] [security2:error] [pid 519566:tid 519737] [client 20.48.160.90:51943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/wp-includes/ID3/moon.php"] [unique_id "apPlpdKCPt8cS-VWcMmXBAAAA8w"]
[Sun Aug 30 03:11:17.629505 2026] [authz_core:error] [pid 519566:tid 519793] [client 216.73.216.128:18817] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:17.657314 2026] [security2:error] [pid 519566:tid 519728] [client 20.104.50.220:33045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-admin/maint/mailer.php.php"] [unique_id "apPlpdKCPt8cS-VWcMmXBgAAA8M"]
[Sun Aug 30 03:11:17.658385 2026] [security2:error] [pid 519566:tid 519738] [client 40.83.93.50:6399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/abc.php"] [unique_id "apPlpdKCPt8cS-VWcMmXBwAAA80"]
[Sun Aug 30 03:11:17.664151 2026] [security2:error] [pid 519566:tid 519707] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/showthread.php"] [unique_id "apPlpdKCPt8cS-VWcMmXCQAAA64"]
[Sun Aug 30 03:11:17.674437 2026] [security2:error] [pid 519566:tid 519743] [client 20.104.50.220:42001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/Alfa.php"] [unique_id "apPlpdKCPt8cS-VWcMmXDwAAA9I"]
[Sun Aug 30 03:11:17.689169 2026] [security2:error] [pid 519566:tid 519816] [client 158.23.184.117:8512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/i.php"] [unique_id "apPlpdKCPt8cS-VWcMmXEQAABBs"]
[Sun Aug 30 03:11:17.696256 2026] [security2:error] [pid 519566:tid 519734] [client 20.63.81.20:59086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/px.php"] [unique_id "apPlpdKCPt8cS-VWcMmXFAAAA8k"]
[Sun Aug 30 03:11:17.700374 2026] [security2:error] [pid 519566:tid 519777] [client 20.48.251.3:54787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/f35.php"] [unique_id "apPlpdKCPt8cS-VWcMmXFwAAA_Q"]
[Sun Aug 30 03:11:17.731463 2026] [security2:error] [pid 519566:tid 519804] [client 20.104.50.220:5619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/widgets.php"] [unique_id "apPlpdKCPt8cS-VWcMmXIgAABA8"]
[Sun Aug 30 03:11:17.753696 2026] [security2:error] [pid 519566:tid 519704] [client 20.104.18.15:18340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/goods.php"] [unique_id "apPlpdKCPt8cS-VWcMmXLAAAA6s"]
[Sun Aug 30 03:11:17.754384 2026] [security2:error] [pid 519566:tid 519720] [client 158.23.147.79:43289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPlpdKCPt8cS-VWcMmXLQAAA7s"]
[Sun Aug 30 03:11:17.767301 2026] [security2:error] [pid 519566:tid 519803] [client 20.48.160.90:28157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/xmini4.php"] [unique_id "apPlpdKCPt8cS-VWcMmXNAAABA4"]
[Sun Aug 30 03:11:17.773054 2026] [security2:error] [pid 519566:tid 519801] [client 158.23.147.79:58397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/classwithtostring.php"] [unique_id "apPlpdKCPt8cS-VWcMmXNQAABAw"]
[Sun Aug 30 03:11:17.784100 2026] [security2:error] [pid 519566:tid 519738] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/syndication.php"] [unique_id "apPlpdKCPt8cS-VWcMmXOgAAA80"]
[Sun Aug 30 03:11:17.805769 2026] [security2:error] [pid 519566:tid 519760] [client 20.104.50.220:52846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/hz.php"] [unique_id "apPlpdKCPt8cS-VWcMmXQAAAA-M"]
[Sun Aug 30 03:11:17.825588 2026] [security2:error] [pid 519566:tid 519780] [client 20.63.81.20:59059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/jg.php"] [unique_id "apPlpdKCPt8cS-VWcMmXQwAAA_c"]
[Sun Aug 30 03:11:17.859525 2026] [security2:error] [pid 519566:tid 519749] [client 4.205.62.107:17694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/png.php"] [unique_id "apPlpdKCPt8cS-VWcMmXTQAAA9g"]
[Sun Aug 30 03:11:17.861237 2026] [autoindex:error] [pid 519566:tid 519795] [client 20.196.209.81:15068] AH01276: Cannot serve directory /home3/shutters/advoutpost.com/wp-content/themes/twentytwentytwo/parts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:11:17.874620 2026] [authz_core:error] [pid 519566:tid 519785] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:11:17.874948 2026] [security2:error] [pid 519566:tid 519776] [client 4.205.62.107:52871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/phpinfo01.php"] [unique_id "apPlpdKCPt8cS-VWcMmXUgAAA_M"]
[Sun Aug 30 03:11:17.875088 2026] [authz_core:error] [pid 519566:tid 519785] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:11:17.886567 2026] [security2:error] [pid 519566:tid 519717] [client 20.48.251.3:55798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/userfuns.php"] [unique_id "apPlpdKCPt8cS-VWcMmXUwAAA7g"]
[Sun Aug 30 03:11:17.897243 2026] [security2:error] [pid 519566:tid 519700] [client 20.48.160.90:28054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/gulu.php"] [unique_id "apPlpdKCPt8cS-VWcMmXVwAAA6c"]
[Sun Aug 30 03:11:17.900525 2026] [security2:error] [pid 519566:tid 519722] [client 20.48.251.3:37123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/oiko6u.php"] [unique_id "apPlpdKCPt8cS-VWcMmXWAAAA70"]
[Sun Aug 30 03:11:17.909073 2026] [security2:error] [pid 519566:tid 519720] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/misc.php"] [unique_id "apPlpdKCPt8cS-VWcMmXWgAAA7s"]
[Sun Aug 30 03:11:17.953269 2026] [security2:error] [pid 519566:tid 519801] [client 20.63.81.20:58977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/yj.php"] [unique_id "apPlpdKCPt8cS-VWcMmXZgAABAw"]
[Sun Aug 30 03:11:17.962496 2026] [authz_core:error] [pid 519566:tid 519803] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmisc
[Sun Aug 30 03:11:17.962967 2026] [authz_core:error] [pid 519566:tid 519803] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Fmisc
[Sun Aug 30 03:11:17.981113 2026] [security2:error] [pid 519566:tid 519774] [client 158.23.184.117:8522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/wp-admin/css/index.php"] [unique_id "apPlpdKCPt8cS-VWcMmXcwAAA_E"]
[Sun Aug 30 03:11:17.991738 2026] [security2:error] [pid 519566:tid 519780] [client 20.196.209.81:15068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/users.php"] [unique_id "apPlpdKCPt8cS-VWcMmXewAAA_c"]
[Sun Aug 30 03:11:18.012568 2026] [security2:error] [pid 519566:tid 519823] [client 20.104.18.15:31684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/one.php"] [unique_id "apPlptKCPt8cS-VWcMmXfwAABCI"]
[Sun Aug 30 03:11:18.013092 2026] [security2:error] [pid 519566:tid 519714] [client 20.104.18.15:22440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/ta.php"] [unique_id "apPlptKCPt8cS-VWcMmXgAAAA7U"]
[Sun Aug 30 03:11:18.029888 2026] [security2:error] [pid 519566:tid 519778] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/global.php"] [unique_id "apPlptKCPt8cS-VWcMmXhAAAA_U"]
[Sun Aug 30 03:11:18.036207 2026] [security2:error] [pid 519566:tid 519709] [client 20.48.160.90:51863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/replace.php"] [unique_id "apPlptKCPt8cS-VWcMmXhgAAA7A"]
[Sun Aug 30 03:11:18.088202 2026] [security2:error] [pid 519566:tid 519773] [client 20.63.81.20:58972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/zi.php"] [unique_id "apPlptKCPt8cS-VWcMmXkQAAA_A"]
[Sun Aug 30 03:11:18.089255 2026] [security2:error] [pid 519566:tid 519754] [client 20.151.200.44:64735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/update/da222.php"] [unique_id "apPlptKCPt8cS-VWcMmXkgAAA90"]
[Sun Aug 30 03:11:18.094353 2026] [security2:error] [pid 519566:tid 519725] [client 20.104.50.220:50370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/gg.php"] [unique_id "apPlptKCPt8cS-VWcMmXlgAAA8A"]
[Sun Aug 30 03:11:18.108635 2026] [authz_core:error] [pid 519566:tid 519802] [client 66.249.66.35:50168] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:18.108926 2026] [authz_core:error] [pid 519566:tid 519802] [client 66.249.66.35:50168] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:18.121741 2026] [security2:error] [pid 519566:tid 519755] [client 158.23.184.117:8552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/wp-content/index.php"] [unique_id "apPlptKCPt8cS-VWcMmXnQAAA94"]
[Sun Aug 30 03:11:18.136813 2026] [lsapi:error] [pid 519566:tid 519636] [remote 177.227.75.254:10986] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://gracelikestogarden.com/
[Sun Aug 30 03:11:18.137005 2026] [lsapi:error] [pid 519566:tid 519636] [remote 177.227.75.254:10986] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://gracelikestogarden.com/
[Sun Aug 30 03:11:18.138384 2026] [lsapi:error] [pid 519566:tid 519636] [remote 177.227.75.254:10986] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n, referer: https://gracelikestogarden.com/
[Sun Aug 30 03:11:18.150688 2026] [security2:error] [pid 519566:tid 519800] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/inc/class_plugins.php"] [unique_id "apPlptKCPt8cS-VWcMmXoQAABAs"]
[Sun Aug 30 03:11:18.159396 2026] [security2:error] [pid 519566:tid 519701] [client 4.205.62.107:16361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/X57.php"] [unique_id "apPlptKCPt8cS-VWcMmXowAAA6g"]
[Sun Aug 30 03:11:18.165183 2026] [security2:error] [pid 519566:tid 519814] [client 40.83.93.50:10692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/default.php"] [unique_id "apPlptKCPt8cS-VWcMmXpAAABBk"]
[Sun Aug 30 03:11:18.165848 2026] [security2:error] [pid 519566:tid 519743] [client 158.23.147.79:39137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/goat.php"] [unique_id "apPlptKCPt8cS-VWcMmXpgAAA9I"]
[Sun Aug 30 03:11:18.186757 2026] [security2:error] [pid 519566:tid 519768] [client 4.205.62.107:26953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/zaza.php"] [unique_id "apPlptKCPt8cS-VWcMmXswAAA-s"]
[Sun Aug 30 03:11:18.186845 2026] [security2:error] [pid 519566:tid 519706] [client 20.48.160.90:28051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/c4.php"] [unique_id "apPlptKCPt8cS-VWcMmXsQAAA60"]
[Sun Aug 30 03:11:18.192457 2026] [security2:error] [pid 519566:tid 519760] [client 4.205.62.107:36070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/pass4.php"] [unique_id "apPlptKCPt8cS-VWcMmXtwAAA-M"]
[Sun Aug 30 03:11:18.202369 2026] [security2:error] [pid 519566:tid 519779] [client 20.104.104.62:14342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlptKCPt8cS-VWcMmXvgAAA_Y"]
[Sun Aug 30 03:11:18.221113 2026] [security2:error] [pid 519566:tid 519777] [client 20.104.18.15:16896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/drykl.php"] [unique_id "apPlptKCPt8cS-VWcMmXwwAAA_Q"]
[Sun Aug 30 03:11:18.221758 2026] [security2:error] [pid 519566:tid 519741] [client 20.63.81.20:58969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/ue.php"] [unique_id "apPlptKCPt8cS-VWcMmXxAAAA9A"]
[Sun Aug 30 03:11:18.262829 2026] [security2:error] [pid 519566:tid 519716] [client 20.151.200.44:41961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/update/da222.php"] [unique_id "apPlptKCPt8cS-VWcMmXzAAAA7c"]
[Sun Aug 30 03:11:18.262852 2026] [security2:error] [pid 519566:tid 519742] [client 158.23.184.117:8201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPlptKCPt8cS-VWcMmXzQAAA9E"]
[Sun Aug 30 03:11:18.268068 2026] [security2:error] [pid 519566:tid 519702] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/forumdisplay.php"] [unique_id "apPlptKCPt8cS-VWcMmXzgAAA6k"]
[Sun Aug 30 03:11:18.276602 2026] [authz_core:error] [pid 519566:tid 519720] [client 66.249.66.67:50867] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:18.276885 2026] [authz_core:error] [pid 519566:tid 519720] [client 66.249.66.67:50867] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:18.318338 2026] [authz_core:error] [pid 519566:tid 519787] [client 216.73.216.128:28133] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:18.318606 2026] [authz_core:error] [pid 519566:tid 519787] [client 216.73.216.128:28133] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:18.323569 2026] [security2:error] [pid 519566:tid 519790] [client 20.48.160.90:51922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/rxr.php"] [unique_id "apPlptKCPt8cS-VWcMmX1gAABAE"]
[Sun Aug 30 03:11:18.330877 2026] [security2:error] [pid 519566:tid 519774] [client 68.155.159.216:63267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apPlptKCPt8cS-VWcMmX1wAAA_E"]
[Sun Aug 30 03:11:18.342140 2026] [security2:error] [pid 519566:tid 519783] [client 20.104.104.62:15314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlptKCPt8cS-VWcMmX2wAAA_o"]
[Sun Aug 30 03:11:18.348447 2026] [authz_core:error] [pid 519566:tid 519746] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:18.348873 2026] [authz_core:error] [pid 519566:tid 519746] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:18.353499 2026] [security2:error] [pid 519566:tid 519743] [client 20.63.81.20:58885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/nv.php"] [unique_id "apPlptKCPt8cS-VWcMmX3gAAA9I"]
[Sun Aug 30 03:11:18.362461 2026] [security2:error] [pid 519566:tid 519791] [client 20.48.251.3:52230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/chosen.php"] [unique_id "apPlptKCPt8cS-VWcMmX4AAABAI"]
[Sun Aug 30 03:11:18.384210 2026] [security2:error] [pid 519566:tid 519767] [client 20.196.209.81:15060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/wp-cron.php"] [unique_id "apPlptKCPt8cS-VWcMmX4gAAA-o"]
[Sun Aug 30 03:11:18.385416 2026] [security2:error] [pid 519566:tid 519782] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/inc/plugins/favcons.php"] [unique_id "apPlptKCPt8cS-VWcMmX4wAAA_k"]
[Sun Aug 30 03:11:18.390280 2026] [security2:error] [pid 519566:tid 519753] [client 20.104.50.220:29151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/alfashell.php"] [unique_id "apPlptKCPt8cS-VWcMmX5AAAA9w"]
[Sun Aug 30 03:11:18.405320 2026] [security2:error] [pid 519566:tid 519740] [client 158.23.184.117:8517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPlptKCPt8cS-VWcMmX5wAAA88"]
[Sun Aug 30 03:11:18.452293 2026] [authz_core:error] [pid 519566:tid 519777] [client 216.73.216.128:18817] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:18.452835 2026] [authz_core:error] [pid 519566:tid 519777] [client 216.73.216.128:18817] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:18.458158 2026] [authz_core:error] [pid 519566:tid 519714] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Ftls
[Sun Aug 30 03:11:18.458624 2026] [authz_core:error] [pid 519566:tid 519714] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Ftls
[Sun Aug 30 03:11:18.471416 2026] [security2:error] [pid 519566:tid 519756] [client 20.104.104.62:14810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/h02ugyh.php"] [unique_id "apPlptKCPt8cS-VWcMmYAQAAA98"]
[Sun Aug 30 03:11:18.479890 2026] [security2:error] [pid 519566:tid 519783] [client 20.48.160.90:46539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dirkhoag.com"] [uri "/reviall.php"] [unique_id "apPlptKCPt8cS-VWcMmYBgAAA_o"]
[Sun Aug 30 03:11:18.484964 2026] [security2:error] [pid 519566:tid 519807] [client 20.104.50.220:24837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlptKCPt8cS-VWcMmYCAAABBI"]
[Sun Aug 30 03:11:18.499380 2026] [security2:error] [pid 519566:tid 519765] [client 20.63.81.20:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/jw.php"] [unique_id "apPlptKCPt8cS-VWcMmYDAAAA-g"]
[Sun Aug 30 03:11:18.509074 2026] [security2:error] [pid 519566:tid 519748] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/printthread.php"] [unique_id "apPlptKCPt8cS-VWcMmYDgAAA9c"]
[Sun Aug 30 03:11:18.539383 2026] [security2:error] [pid 519566:tid 519795] [client 158.23.184.117:1353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "apPlptKCPt8cS-VWcMmYIQAABAY"]
[Sun Aug 30 03:11:18.543435 2026] [security2:error] [pid 519566:tid 519804] [client 20.104.49.130:60991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/3.php"] [unique_id "apPlptKCPt8cS-VWcMmYIwAABA8"]
[Sun Aug 30 03:11:18.546007 2026] [security2:error] [pid 519566:tid 519725] [client 20.151.200.44:41963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/qi.php"] [unique_id "apPlptKCPt8cS-VWcMmYJQAAA8A"]
[Sun Aug 30 03:11:18.587240 2026] [security2:error] [pid 519566:tid 519729] [client 158.23.184.117:1361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/light.php"] [unique_id "apPlptKCPt8cS-VWcMmYMwAAA8Q"]
[Sun Aug 30 03:11:18.599197 2026] [security2:error] [pid 519566:tid 519783] [client 20.104.104.62:14395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/sf.php"] [unique_id "apPlptKCPt8cS-VWcMmYNwAAA_o"]
[Sun Aug 30 03:11:18.625633 2026] [security2:error] [pid 519566:tid 519741] [client 128.140.41.193:18384] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.sjbauthority.com"] [uri "/index.php"] [unique_id "apPlptKCPt8cS-VWcMmYLwAAA9A"], referer: http://www.sjbauthority.com
[Sun Aug 30 03:11:18.627291 2026] [security2:error] [pid 519566:tid 519819] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/newreply.php"] [unique_id "apPlptKCPt8cS-VWcMmYPgAABB4"]
[Sun Aug 30 03:11:18.639421 2026] [security2:error] [pid 519566:tid 519700] [client 20.63.81.20:59009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/or.php"] [unique_id "apPlptKCPt8cS-VWcMmYPwAAA6c"]
[Sun Aug 30 03:11:18.648434 2026] [security2:error] [pid 519566:tid 519761] [client 20.104.50.220:61633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wso1337.php"] [unique_id "apPlptKCPt8cS-VWcMmYQAAAA-Q"]
[Sun Aug 30 03:11:18.655079 2026] [security2:error] [pid 519566:tid 519726] [client 20.151.200.44:23573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/4e.php"] [unique_id "apPlptKCPt8cS-VWcMmYRAAAA8E"]
[Sun Aug 30 03:11:18.699162 2026] [security2:error] [pid 519566:tid 519696] [client 40.83.93.50:6344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/cloud.php"] [unique_id "apPlptKCPt8cS-VWcMmYVQAAA6M"]
[Sun Aug 30 03:11:18.711551 2026] [security2:error] [pid 519566:tid 519817] [client 158.23.184.117:8193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/wp-load.php"] [unique_id "apPlptKCPt8cS-VWcMmYXAAABBw"]
[Sun Aug 30 03:11:18.726694 2026] [security2:error] [pid 519566:tid 519795] [client 158.23.184.117:1371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/wp-admin/css/about.php7"] [unique_id "apPlptKCPt8cS-VWcMmYYQAABAY"]
[Sun Aug 30 03:11:18.726773 2026] [security2:error] [pid 519566:tid 519729] [client 20.104.49.130:63507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/3.php"] [unique_id "apPlptKCPt8cS-VWcMmYYgAAA8Q"]
[Sun Aug 30 03:11:18.728304 2026] [security2:error] [pid 519566:tid 519800] [client 20.104.104.62:14808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/4e.php"] [unique_id "apPlptKCPt8cS-VWcMmYYwAABAs"]
[Sun Aug 30 03:11:18.740391 2026] [security2:error] [pid 519566:tid 519809] [client 158.23.147.79:60204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/install.php"] [unique_id "apPlptKCPt8cS-VWcMmYaQAABBQ"]
[Sun Aug 30 03:11:18.744333 2026] [security2:error] [pid 519566:tid 519807] [client 20.104.50.220:16970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-includes/js/codemirror/index.php"] [unique_id "apPlptKCPt8cS-VWcMmYawAABBI"]
[Sun Aug 30 03:11:18.745351 2026] [security2:error] [pid 519566:tid 519739] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/portal.php"] [unique_id "apPlptKCPt8cS-VWcMmYbQAAA84"]
[Sun Aug 30 03:11:18.771854 2026] [security2:error] [pid 519566:tid 519697] [client 20.63.81.20:59083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/ile56.php"] [unique_id "apPlptKCPt8cS-VWcMmYdwAAA6Q"]
[Sun Aug 30 03:11:18.779458 2026] [security2:error] [pid 519566:tid 519803] [client 20.196.209.81:21729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/wp-links-opml.php"] [unique_id "apPlptKCPt8cS-VWcMmYfAAABA4"]
[Sun Aug 30 03:11:18.799556 2026] [security2:error] [pid 519566:tid 519722] [client 20.104.104.62:22719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlptKCPt8cS-VWcMmYfwAAA70"]
[Sun Aug 30 03:11:18.823195 2026] [security2:error] [pid 519566:tid 519702] [client 20.104.50.220:42780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-admin/includes/mailer.php.php"] [unique_id "apPlptKCPt8cS-VWcMmYgwAAA6k"]
[Sun Aug 30 03:11:18.828374 2026] [security2:error] [pid 519566:tid 519798] [client 20.104.50.220:33320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-admin/css/mailer.php.php"] [unique_id "apPlptKCPt8cS-VWcMmYhAAABAk"]
[Sun Aug 30 03:11:18.841455 2026] [security2:error] [pid 519566:tid 519717] [client 20.48.251.3:64306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/api.php"] [unique_id "apPlptKCPt8cS-VWcMmYigAAA7g"]
[Sun Aug 30 03:11:18.850526 2026] [security2:error] [pid 519566:tid 519711] [client 158.23.184.117:8203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/222.php"] [unique_id "apPlptKCPt8cS-VWcMmYkQAAA7I"]
[Sun Aug 30 03:11:18.862616 2026] [security2:error] [pid 519566:tid 519795] [client 20.104.104.62:15350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/ssss.php"] [unique_id "apPlptKCPt8cS-VWcMmYkwAABAY"]
[Sun Aug 30 03:11:18.865943 2026] [security2:error] [pid 519566:tid 519784] [client 158.23.184.117:1356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/alf.php"] [unique_id "apPlptKCPt8cS-VWcMmYlQAAA_s"]
[Sun Aug 30 03:11:18.898579 2026] [security2:error] [pid 519566:tid 519756] [client 20.63.81.20:58982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/emmh.php"] [unique_id "apPlptKCPt8cS-VWcMmYoAAAA98"]
[Sun Aug 30 03:11:18.908897 2026] [authz_core:error] [pid 519566:tid 519819] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:18.909312 2026] [authz_core:error] [pid 519566:tid 519819] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:18.911303 2026] [authz_core:error] [pid 519566:tid 519791] [client 66.249.66.70:58537] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:18.911579 2026] [authz_core:error] [pid 519566:tid 519791] [client 66.249.66.70:58537] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:18.943319 2026] [security2:error] [pid 519566:tid 519755] [client 20.104.50.220:52812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/here.php"] [unique_id "apPlptKCPt8cS-VWcMmYtAAAA94"]
[Sun Aug 30 03:11:18.948742 2026] [security2:error] [pid 519566:tid 519780] [client 20.104.50.220:5536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/theme.php"] [unique_id "apPlptKCPt8cS-VWcMmYtwAAA_c"]
[Sun Aug 30 03:11:18.956552 2026] [security2:error] [pid 519566:tid 519753] [client 20.104.104.62:22657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlptKCPt8cS-VWcMmYuAAAA9w"]
[Sun Aug 30 03:11:18.956638 2026] [security2:error] [pid 519566:tid 519702] [client 20.151.200.44:41877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/px.php"] [unique_id "apPlptKCPt8cS-VWcMmYuQAAA6k"]
[Sun Aug 30 03:11:18.975078 2026] [authz_core:error] [pid 519566:tid 519776] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory
[Sun Aug 30 03:11:18.975401 2026] [authz_core:error] [pid 519566:tid 519776] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory
[Sun Aug 30 03:11:18.993724 2026] [security2:error] [pid 519566:tid 519754] [client 158.23.184.117:8544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/aaa.php"] [unique_id "apPlptKCPt8cS-VWcMmYxwAAA90"]
[Sun Aug 30 03:11:18.996741 2026] [security2:error] [pid 519566:tid 519715] [client 4.205.62.107:17108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/chosen.php"] [unique_id "apPlptKCPt8cS-VWcMmYyQAAA7Y"]
[Sun Aug 30 03:11:18.998800 2026] [security2:error] [pid 519566:tid 519807] [client 20.104.104.62:14365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/zoz.php"] [unique_id "apPlptKCPt8cS-VWcMmYygAABBI"]
[Sun Aug 30 03:11:19.016253 2026] [security2:error] [pid 519566:tid 519771] [client 4.205.62.107:52800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/cxc.php"] [unique_id "apPlp9KCPt8cS-VWcMmYzgAAA-4"]
[Sun Aug 30 03:11:19.028799 2026] [security2:error] [pid 519566:tid 519756] [client 20.63.81.20:59088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/em.php"] [unique_id "apPlp9KCPt8cS-VWcMmY0gAAA98"]
[Sun Aug 30 03:11:19.031143 2026] [authz_core:error] [pid 519566:tid 519700] [client 66.249.66.68:61328] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:19.031402 2026] [authz_core:error] [pid 519566:tid 519700] [client 66.249.66.68:61328] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:19.035885 2026] [security2:error] [pid 519566:tid 519809] [client 20.48.251.3:55786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/mamzi.php"] [unique_id "apPlp9KCPt8cS-VWcMmY1QAABBQ"]
[Sun Aug 30 03:11:19.037290 2026] [security2:error] [pid 519566:tid 519726] [client 20.48.251.3:36814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/fraro.php"] [unique_id "apPlp9KCPt8cS-VWcMmY1gAAA8E"]
[Sun Aug 30 03:11:19.050231 2026] [security2:error] [pid 519566:tid 519732] [client 158.23.147.79:39331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apPlp9KCPt8cS-VWcMmY3AAAA8c"]
[Sun Aug 30 03:11:19.058576 2026] [security2:error] [pid 519566:tid 519804] [client 158.23.184.117:1578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/wp-admin/import.php"] [unique_id "apPlp9KCPt8cS-VWcMmY5AAABA8"]
[Sun Aug 30 03:11:19.060835 2026] [security2:error] [pid 519566:tid 519719] [client 20.104.49.130:32772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/100.php"] [unique_id "apPlp9KCPt8cS-VWcMmY5wAAA7o"]
[Sun Aug 30 03:11:19.086259 2026] [security2:error] [pid 519566:tid 519733] [client 20.104.104.62:45958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/h02ugyh.php"] [unique_id "apPlp9KCPt8cS-VWcMmY7wAAA8g"]
[Sun Aug 30 03:11:19.092517 2026] [security2:error] [pid 519566:tid 519712] [client 68.155.159.216:54303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPlp9KCPt8cS-VWcMmY8gAAA7M"]
[Sun Aug 30 03:11:19.099886 2026] [security2:error] [pid 519566:tid 519823] [client 20.104.18.15:18310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/ah.php"] [unique_id "apPlp9KCPt8cS-VWcMmY9gAABCI"]
[Sun Aug 30 03:11:19.129941 2026] [security2:error] [pid 519566:tid 519807] [client 20.104.104.62:15297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/kcs.php"] [unique_id "apPlp9KCPt8cS-VWcMmZAAAABBI"]
[Sun Aug 30 03:11:19.133457 2026] [security2:error] [pid 519566:tid 519742] [client 158.23.184.117:8548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/admin/function.php"] [unique_id "apPlp9KCPt8cS-VWcMmZAgAAA9E"]
[Sun Aug 30 03:11:19.151268 2026] [security2:error] [pid 519566:tid 519772] [client 20.104.18.15:31722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/504.php"] [unique_id "apPlp9KCPt8cS-VWcMmZBQAAA-8"]
[Sun Aug 30 03:11:19.165045 2026] [security2:error] [pid 519566:tid 519739] [client 20.63.81.20:59030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/dvve.php"] [unique_id "apPlp9KCPt8cS-VWcMmZCAAAA84"]
[Sun Aug 30 03:11:19.173150 2026] [security2:error] [pid 519566:tid 519748] [client 20.196.209.81:11957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/wp-load.php"] [unique_id "apPlp9KCPt8cS-VWcMmZDwAAA9c"]
[Sun Aug 30 03:11:19.177244 2026] [security2:error] [pid 519566:tid 519801] [client 40.83.93.50:6354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/admin.php"] [unique_id "apPlp9KCPt8cS-VWcMmZEgAABAw"]
[Sun Aug 30 03:11:19.182639 2026] [security2:error] [pid 519566:tid 519732] [client 20.104.18.15:22496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/bo.php"] [unique_id "apPlp9KCPt8cS-VWcMmZFAAAA8c"]
[Sun Aug 30 03:11:19.214842 2026] [security2:error] [pid 519566:tid 519709] [client 158.23.184.117:1573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "apPlp9KCPt8cS-VWcMmZIAAAA7A"]
[Sun Aug 30 03:11:19.231626 2026] [security2:error] [pid 519566:tid 519798] [client 20.104.104.62:41627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/sf.php"] [unique_id "apPlp9KCPt8cS-VWcMmZJQAABAk"]
[Sun Aug 30 03:11:19.239719 2026] [security2:error] [pid 519566:tid 519750] [client 20.104.49.130:53732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/css.php"] [unique_id "apPlp9KCPt8cS-VWcMmZKQAAA9k"]
[Sun Aug 30 03:11:19.265537 2026] [security2:error] [pid 519566:tid 519789] [client 20.104.104.62:14786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/tajj.php"] [unique_id "apPlp9KCPt8cS-VWcMmZMAAABAA"]
[Sun Aug 30 03:11:19.265916 2026] [security2:error] [pid 519566:tid 519723] [client 20.104.50.220:31513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/als.php"] [unique_id "apPlp9KCPt8cS-VWcMmZMQAAA74"]
[Sun Aug 30 03:11:19.294767 2026] [core:alert] [pid 519566:tid 519708] [client 186.2.221.219:56172] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:11:19.297465 2026] [security2:error] [pid 519566:tid 519716] [client 20.63.81.20:58966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/doo.php"] [unique_id "apPlp9KCPt8cS-VWcMmZOQAAA7c"]
[Sun Aug 30 03:11:19.350695 2026] [authz_core:error] [pid 519566:tid 519819] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:19.351121 2026] [authz_core:error] [pid 519566:tid 519819] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:19.351868 2026] [security2:error] [pid 519566:tid 519758] [client 216.73.216.128:18817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/$src"] [unique_id "apPlp9KCPt8cS-VWcMmZRQAAA-E"]
[Sun Aug 30 03:11:19.358282 2026] [security2:error] [pid 519566:tid 519782] [client 20.104.18.15:16951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/backup.php"] [unique_id "apPlp9KCPt8cS-VWcMmZRgAAA_k"]
[Sun Aug 30 03:11:19.359504 2026] [security2:error] [pid 519566:tid 519804] [client 20.104.104.62:45972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/4e.php"] [unique_id "apPlp9KCPt8cS-VWcMmZSAAABA8"]
[Sun Aug 30 03:11:19.360603 2026] [security2:error] [pid 519566:tid 519787] [client 4.205.62.107:25496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/u88.php"] [unique_id "apPlp9KCPt8cS-VWcMmZSgAAA_4"]
[Sun Aug 30 03:11:19.366886 2026] [security2:error] [pid 519566:tid 519760] [client 4.205.62.107:15967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/register.php"] [unique_id "apPlp9KCPt8cS-VWcMmZPwAAA-M"]
[Sun Aug 30 03:11:19.397777 2026] [security2:error] [pid 519566:tid 519766] [client 4.205.62.107:36694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/cu.php"] [unique_id "apPlp9KCPt8cS-VWcMmZUAAAA-k"]
[Sun Aug 30 03:11:19.401405 2026] [security2:error] [pid 519566:tid 519745] [client 20.104.104.62:14834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/bge.php"] [unique_id "apPlp9KCPt8cS-VWcMmZUQAAA9Q"]
[Sun Aug 30 03:11:19.426319 2026] [security2:error] [pid 519566:tid 519753] [client 20.63.81.20:59077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/adminer-4.6.6.php"] [unique_id "apPlp9KCPt8cS-VWcMmZVQAAA9w"]
[Sun Aug 30 03:11:19.431006 2026] [security2:error] [pid 519566:tid 519790] [client 158.23.184.117:8214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/system_log.php"] [unique_id "apPlp9KCPt8cS-VWcMmZWwAABAE"]
[Sun Aug 30 03:11:19.469163 2026] [authz_core:error] [pid 519566:tid 519740] [client 66.249.66.197:60138] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:19.469610 2026] [authz_core:error] [pid 519566:tid 519740] [client 66.249.66.197:60138] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:19.469784 2026] [security2:error] [pid 519566:tid 519801] [client 158.23.184.117:1571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/wp-admin/admin-post.php"] [unique_id "apPlp9KCPt8cS-VWcMmZbQAABAw"]
[Sun Aug 30 03:11:19.470887 2026] [authz_core:error] [pid 519566:tid 519808] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory
[Sun Aug 30 03:11:19.471201 2026] [authz_core:error] [pid 519566:tid 519808] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory
[Sun Aug 30 03:11:19.487300 2026] [security2:error] [pid 519566:tid 519743] [client 20.104.104.62:45980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/ssss.php"] [unique_id "apPlp9KCPt8cS-VWcMmZcQAAA9I"]
[Sun Aug 30 03:11:19.506291 2026] [security2:error] [pid 519566:tid 519704] [client 20.48.251.3:52270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/admin-ajax.php"] [unique_id "apPlp9KCPt8cS-VWcMmZdAAAA6s"]
[Sun Aug 30 03:11:19.535154 2026] [security2:error] [pid 519566:tid 519805] [client 20.104.104.62:14838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/ssh3ll.php"] [unique_id "apPlp9KCPt8cS-VWcMmZhAAABBA"]
[Sun Aug 30 03:11:19.537897 2026] [security2:error] [pid 519566:tid 519733] [client 68.155.159.216:63284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apPlp9KCPt8cS-VWcMmZhQAAA8g"]
[Sun Aug 30 03:11:19.541114 2026] [authz_core:error] [pid 519566:tid 519730] [client 216.73.216.128:45868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:19.541374 2026] [authz_core:error] [pid 519566:tid 519730] [client 216.73.216.128:45868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:19.542105 2026] [security2:error] [pid 519566:tid 519822] [client 20.104.50.220:29602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/av.php"] [unique_id "apPlp9KCPt8cS-VWcMmZhwAABCE"]
[Sun Aug 30 03:11:19.542971 2026] [security2:error] [pid 519566:tid 519791] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/.env.swp"] [unique_id "apPlp9KCPt8cS-VWcMmZiAAABAI"]
[Sun Aug 30 03:11:19.564015 2026] [security2:error] [pid 519566:tid 519751] [client 20.63.81.20:59048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/gelap1.php"] [unique_id "apPlp9KCPt8cS-VWcMmZjwAAA9o"]
[Sun Aug 30 03:11:19.567671 2026] [security2:error] [pid 519566:tid 519702] [client 20.196.209.81:15074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/wp-settings.php"] [unique_id "apPlp9KCPt8cS-VWcMmZkQAAA6k"]
[Sun Aug 30 03:11:19.599487 2026] [authz_core:error] [pid 519566:tid 519755] [client 66.249.66.68:40519] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:19.599765 2026] [authz_core:error] [pid 519566:tid 519755] [client 66.249.66.68:40519] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:19.615129 2026] [security2:error] [pid 519566:tid 519807] [client 20.104.104.62:41645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/zoz.php"] [unique_id "apPlp9KCPt8cS-VWcMmZmgAABBI"]
[Sun Aug 30 03:11:19.615147 2026] [security2:error] [pid 519566:tid 519779] [client 20.104.50.220:24858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlp9KCPt8cS-VWcMmZmwAAA_Y"]
[Sun Aug 30 03:11:19.626185 2026] [security2:error] [pid 519566:tid 519725] [client 158.23.184.117:1344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/favicon.php"] [unique_id "apPlp9KCPt8cS-VWcMmZngAAA8A"]
[Sun Aug 30 03:11:19.644339 2026] [authz_core:error] [pid 519566:tid 519795] [client 66.249.66.78:38570] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:19.644612 2026] [authz_core:error] [pid 519566:tid 519795] [client 66.249.66.78:38570] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:19.652773 2026] [security2:error] [pid 519566:tid 519731] [client 20.104.49.130:60679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/f35.update.php"] [unique_id "apPlp9KCPt8cS-VWcMmZoQAAA8Y"]
[Sun Aug 30 03:11:19.682866 2026] [security2:error] [pid 519566:tid 519737] [client 40.83.93.50:22116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/index.php"] [unique_id "apPlp9KCPt8cS-VWcMmZqgAAA8w"]
[Sun Aug 30 03:11:19.683265 2026] [security2:error] [pid 519566:tid 519775] [client 20.104.104.62:14784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/motu.php"] [unique_id "apPlp9KCPt8cS-VWcMmZqwAAA_I"]
[Sun Aug 30 03:11:19.697039 2026] [security2:error] [pid 519566:tid 519760] [client 20.63.81.20:58971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/rsjlrria.php"] [unique_id "apPlp9KCPt8cS-VWcMmZtQAAA-M"]
[Sun Aug 30 03:11:19.743697 2026] [security2:error] [pid 519566:tid 519738] [client 20.104.104.62:45990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/kcs.php"] [unique_id "apPlp9KCPt8cS-VWcMmZzwAAA80"]
[Sun Aug 30 03:11:19.746704 2026] [security2:error] [pid 519566:tid 519778] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/.env~"] [unique_id "apPlp9KCPt8cS-VWcMmZ0AAAA_U"]
[Sun Aug 30 03:11:19.767292 2026] [security2:error] [pid 519566:tid 519754] [client 158.23.184.117:1570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/wp-admin/css/my.php"] [unique_id "apPlp9KCPt8cS-VWcMmZ2QAAA90"]
[Sun Aug 30 03:11:19.809338 2026] [security2:error] [pid 519566:tid 519784] [client 158.23.147.79:43636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-content/uploads/about.php"] [unique_id "apPlp9KCPt8cS-VWcMmZ6gAAA_s"]
[Sun Aug 30 03:11:19.811082 2026] [security2:error] [pid 519566:tid 519752] [client 20.104.104.62:14381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/wefile.php"] [unique_id "apPlp9KCPt8cS-VWcMmZ6wAAA9s"]
[Sun Aug 30 03:11:19.835708 2026] [security2:error] [pid 519566:tid 519726] [client 20.104.50.220:61956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wso2.php"] [unique_id "apPlp9KCPt8cS-VWcMmZ7wAAA8E"]
[Sun Aug 30 03:11:19.836738 2026] [security2:error] [pid 519566:tid 519719] [client 20.63.81.20:58881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/AxAo.php"] [unique_id "apPlp9KCPt8cS-VWcMmZ8QAAA7o"]
[Sun Aug 30 03:11:19.841751 2026] [authz_core:error] [pid 519566:tid 519748] [client 66.249.66.70:59802] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:19.842233 2026] [authz_core:error] [pid 519566:tid 519748] [client 66.249.66.70:59802] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:19.861867 2026] [authz_core:error] [pid 519566:tid 519716] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:19.862155 2026] [authz_core:error] [pid 519566:tid 519716] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:19.877753 2026] [security2:error] [pid 519566:tid 519770] [client 20.104.50.220:17236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-includes/block-patterns/index.php"] [unique_id "apPlp9KCPt8cS-VWcMmaBQAAA-0"]
[Sun Aug 30 03:11:19.896408 2026] [security2:error] [pid 519566:tid 519722] [client 20.104.104.62:45957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/tajj.php"] [unique_id "apPlp9KCPt8cS-VWcMmaBwAAA70"]
[Sun Aug 30 03:11:19.907640 2026] [security2:error] [pid 519566:tid 519714] [client 158.23.184.117:1556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/wp-content/images/doc.php"] [unique_id "apPlp9KCPt8cS-VWcMmaCgAAA7U"]
[Sun Aug 30 03:11:19.935088 2026] [security2:error] [pid 519566:tid 519807] [client 20.151.200.44:41884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/is.php"] [unique_id "apPlp9KCPt8cS-VWcMmaEgAABBI"]
[Sun Aug 30 03:11:19.964797 2026] [security2:error] [pid 519566:tid 519777] [client 20.196.209.81:21740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/themes/wp-signup.php"] [unique_id "apPlp9KCPt8cS-VWcMmaHQAAA_Q"]
[Sun Aug 30 03:11:19.966890 2026] [security2:error] [pid 519566:tid 519774] [client 158.23.184.117:8533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/wp-content/uploads/admin.php"] [unique_id "apPlp9KCPt8cS-VWcMmaHwAAA_E"]
[Sun Aug 30 03:11:19.973961 2026] [authz_core:error] [pid 519566:tid 519697] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Ftls
[Sun Aug 30 03:11:19.974259 2026] [authz_core:error] [pid 519566:tid 519697] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Ftls
[Sun Aug 30 03:11:19.981541 2026] [security2:error] [pid 519566:tid 519734] [client 20.63.81.20:59035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/class17.php"] [unique_id "apPlp9KCPt8cS-VWcMmaKQAAA8k"]
[Sun Aug 30 03:11:19.981747 2026] [security2:error] [pid 519566:tid 519822] [client 20.48.251.3:54819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/temp.php"] [unique_id "apPlp9KCPt8cS-VWcMmaKAAABCE"]
[Sun Aug 30 03:11:19.991350 2026] [security2:error] [pid 519566:tid 519729] [client 20.104.104.62:14390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/Contrller.php"] [unique_id "apPlp9KCPt8cS-VWcMmaLQAAA8Q"]
[Sun Aug 30 03:11:20.000339 2026] [security2:error] [pid 519566:tid 519738] [client 20.104.50.220:51625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-admin/maint/mailer.php.php"] [unique_id "apPlp9KCPt8cS-VWcMmaLwAAA80"]
[Sun Aug 30 03:11:20.002299 2026] [security2:error] [pid 519566:tid 519778] [client 156.59.198.135:57580] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.mediacoalition.org"] [uri "/legal/Big%20Hat%20Books%20v%20Prosecutors/Complaint5.7.08.pdf"] [unique_id "apPlqNKCPt8cS-VWcMmaMQAAA_U"]
[Sun Aug 30 03:11:20.004229 2026] [security2:error] [pid 519566:tid 519717] [client 20.104.50.220:33210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-includes/css/mailer.php.php"] [unique_id "apPlqNKCPt8cS-VWcMmaMgAAA7g"]
[Sun Aug 30 03:11:20.044686 2026] [security2:error] [pid 519566:tid 519783] [client 20.104.104.62:45960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/bge.php"] [unique_id "apPlqNKCPt8cS-VWcMmaPwAAA_o"]
[Sun Aug 30 03:11:20.050865 2026] [security2:error] [pid 519566:tid 519768] [client 158.23.184.117:1375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/wp-comments.php"] [unique_id "apPlqNKCPt8cS-VWcMmaRQAAA-s"]
[Sun Aug 30 03:11:20.083470 2026] [lsapi:error] [pid 519566:tid 519659] [remote 177.227.75.254:10987] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:11:20.083585 2026] [lsapi:error] [pid 519566:tid 519659] [remote 177.227.75.254:10987] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:11:20.084941 2026] [lsapi:error] [pid 519566:tid 519659] [remote 177.227.75.254:10987] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:11:20.085803 2026] [security2:error] [pid 519566:tid 519726] [client 20.104.50.220:63045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/hxh.php"] [unique_id "apPlqNKCPt8cS-VWcMmaSwAAA8E"]
[Sun Aug 30 03:11:20.090068 2026] [security2:error] [pid 519566:tid 519720] [client 20.104.50.220:6130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/category.php"] [unique_id "apPlqNKCPt8cS-VWcMmaTQAAA7s"]
[Sun Aug 30 03:11:20.112563 2026] [security2:error] [pid 519566:tid 519702] [client 20.63.81.20:59134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/okxoby.php"] [unique_id "apPlqNKCPt8cS-VWcMmaVwAAA6k"]
[Sun Aug 30 03:11:20.139552 2026] [security2:error] [pid 519566:tid 519778] [client 4.205.62.107:17706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/admin-ajax.php"] [unique_id "apPlqNKCPt8cS-VWcMmaXAAAA_U"]
[Sun Aug 30 03:11:20.149712 2026] [security2:error] [pid 519566:tid 519811] [client 20.104.104.62:14375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/file66.php"] [unique_id "apPlqNKCPt8cS-VWcMmaXQAABBY"]
[Sun Aug 30 03:11:20.161455 2026] [security2:error] [pid 519566:tid 519723] [client 4.205.62.107:52911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/oiko6u.php"] [unique_id "apPlqNKCPt8cS-VWcMmaXgAAA74"]
[Sun Aug 30 03:11:20.173081 2026] [security2:error] [pid 519566:tid 519701] [client 40.83.93.50:3923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/php8.php"] [unique_id "apPlqNKCPt8cS-VWcMmaZQAAA6g"]
[Sun Aug 30 03:11:20.173252 2026] [security2:error] [pid 519566:tid 519775] [client 158.23.184.117:8200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/wp-links-opml.php"] [unique_id "apPlqNKCPt8cS-VWcMmaZgAAA_I"]
[Sun Aug 30 03:11:20.174766 2026] [security2:error] [pid 519566:tid 519732] [client 20.104.104.62:41648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/ssh3ll.php"] [unique_id "apPlqNKCPt8cS-VWcMmaaQAAA8c"]
[Sun Aug 30 03:11:20.178547 2026] [security2:error] [pid 519566:tid 519739] [client 20.48.251.3:36838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/thui.php"] [unique_id "apPlqNKCPt8cS-VWcMmaawAAA84"]
[Sun Aug 30 03:11:20.186731 2026] [security2:error] [pid 519566:tid 519761] [client 20.48.251.3:52806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/public/rip.php.php"] [unique_id "apPlqNKCPt8cS-VWcMmacAAAA-Q"]
[Sun Aug 30 03:11:20.192022 2026] [security2:error] [pid 519566:tid 519780] [client 158.23.184.117:1404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/wp-includes/panel.php"] [unique_id "apPlqNKCPt8cS-VWcMmacwAAA_c"]
[Sun Aug 30 03:11:20.203099 2026] [security2:error] [pid 519566:tid 519715] [client 20.104.49.130:26663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/read.php"] [unique_id "apPlqNKCPt8cS-VWcMmadwAAA7Y"]
[Sun Aug 30 03:11:20.240017 2026] [security2:error] [pid 519566:tid 519729] [client 20.104.18.15:18336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/ws55.php"] [unique_id "apPlqNKCPt8cS-VWcMmaggAAA8Q"]
[Sun Aug 30 03:11:20.243533 2026] [security2:error] [pid 519566:tid 519787] [client 20.63.81.20:58957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/esuutzzx.php"] [unique_id "apPlqNKCPt8cS-VWcMmagwAAA_4"]
[Sun Aug 30 03:11:20.290315 2026] [security2:error] [pid 519566:tid 519723] [client 20.104.104.62:14811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/blnux.php"] [unique_id "apPlqNKCPt8cS-VWcMmakgAAA74"]
[Sun Aug 30 03:11:20.303766 2026] [security2:error] [pid 519566:tid 519732] [client 20.104.18.15:31743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/ano.php"] [unique_id "apPlqNKCPt8cS-VWcMmalgAAA8c"]
[Sun Aug 30 03:11:20.312246 2026] [security2:error] [pid 519566:tid 519773] [client 20.104.104.62:41621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/motu.php"] [unique_id "apPlqNKCPt8cS-VWcMmamQAAA_A"]
[Sun Aug 30 03:11:20.314019 2026] [security2:error] [pid 519566:tid 519738] [client 158.23.184.117:8566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/wp.php"] [unique_id "apPlqNKCPt8cS-VWcMmamgAAA80"]
[Sun Aug 30 03:11:20.325626 2026] [security2:error] [pid 519566:tid 519737] [client 20.104.18.15:22460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/44.php"] [unique_id "apPlqNKCPt8cS-VWcMmanAAAA8w"]
[Sun Aug 30 03:11:20.334779 2026] [security2:error] [pid 519566:tid 519792] [client 68.155.159.216:54335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-includes/content.php"] [unique_id "apPlqNKCPt8cS-VWcMmanwAABAM"]
[Sun Aug 30 03:11:20.355591 2026] [security2:error] [pid 519566:tid 519698] [client 20.196.209.81:21736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/updraft/about.php"] [unique_id "apPlqNKCPt8cS-VWcMmapgAAA6U"]
[Sun Aug 30 03:11:20.356334 2026] [authz_core:error] [pid 519566:tid 519722] [client 66.249.66.78:38570] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:20.356627 2026] [authz_core:error] [pid 519566:tid 519722] [client 66.249.66.78:38570] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:20.371054 2026] [security2:error] [pid 519566:tid 519766] [client 20.63.81.20:59062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/replace.php"] [unique_id "apPlqNKCPt8cS-VWcMmapwAAA-k"]
[Sun Aug 30 03:11:20.385130 2026] [security2:error] [pid 519566:tid 519760] [client 158.23.184.117:1347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/www.php"] [unique_id "apPlqNKCPt8cS-VWcMmaqgAAA-M"]
[Sun Aug 30 03:11:20.398919 2026] [authz_core:error] [pid 519566:tid 519804] [client 66.249.66.67:46076] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:20.398919 2026] [authz_core:error] [pid 519566:tid 519708] [client 66.249.66.41:63885] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:20.399422 2026] [authz_core:error] [pid 519566:tid 519708] [client 66.249.66.41:63885] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:20.399422 2026] [authz_core:error] [pid 519566:tid 519804] [client 66.249.66.67:46076] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:20.415404 2026] [security2:error] [pid 519566:tid 519742] [client 20.104.50.220:63222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/pol.php"] [unique_id "apPlqNKCPt8cS-VWcMmatAAAA9E"]
[Sun Aug 30 03:11:20.420689 2026] [authz_core:error] [pid 519566:tid 519817] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:20.420820 2026] [security2:error] [pid 519566:tid 519736] [client 20.104.104.62:14359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/attack.php"] [unique_id "apPlqNKCPt8cS-VWcMmatgAAA8s"]
[Sun Aug 30 03:11:20.420975 2026] [authz_core:error] [pid 519566:tid 519817] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:20.444959 2026] [security2:error] [pid 519566:tid 519803] [client 20.104.104.62:22685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/wefile.php"] [unique_id "apPlqNKCPt8cS-VWcMmaxQAABA4"]
[Sun Aug 30 03:11:20.445152 2026] [authz_core:error] [pid 519566:tid 519716] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory
[Sun Aug 30 03:11:20.445600 2026] [authz_core:error] [pid 519566:tid 519716] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory
[Sun Aug 30 03:11:20.452950 2026] [security2:error] [pid 519566:tid 519818] [client 158.23.184.117:8519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/.well-known/hp2.php"] [unique_id "apPlqNKCPt8cS-VWcMmaywAABB0"]
[Sun Aug 30 03:11:20.464413 2026] [security2:error] [pid 519566:tid 519775] [client 20.104.49.130:63549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/init.php"] [unique_id "apPlqNKCPt8cS-VWcMma0AAAA_I"]
[Sun Aug 30 03:11:20.482375 2026] [security2:error] [pid 519566:tid 519714] [client 158.23.147.79:43053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-admin/maint/index.php"] [unique_id "apPlqNKCPt8cS-VWcMma1gAAA7U"]
[Sun Aug 30 03:11:20.483787 2026] [authz_core:error] [pid 519566:tid 519724] [client 66.249.66.202:37777] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:20.484059 2026] [authz_core:error] [pid 519566:tid 519724] [client 66.249.66.202:37777] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:20.493443 2026] [security2:error] [pid 519566:tid 519731] [client 20.151.200.44:65378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/qi.php"] [unique_id "apPlqNKCPt8cS-VWcMma2QAAA8Y"]
[Sun Aug 30 03:11:20.495694 2026] [security2:error] [pid 519566:tid 519758] [client 20.104.18.15:16900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/indo.php"] [unique_id "apPlqNKCPt8cS-VWcMma2gAAA-E"]
[Sun Aug 30 03:11:20.506338 2026] [security2:error] [pid 519566:tid 519698] [client 20.104.49.130:57723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/cilus.php"] [unique_id "apPlqNKCPt8cS-VWcMma3AAAA6U"]
[Sun Aug 30 03:11:20.509278 2026] [security2:error] [pid 519566:tid 519769] [client 4.205.62.107:15860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/xqq.php"] [unique_id "apPlqNKCPt8cS-VWcMma3gAAA-w"]
[Sun Aug 30 03:11:20.514696 2026] [security2:error] [pid 519566:tid 519808] [client 20.63.81.20:59119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/gulu.php"] [unique_id "apPlqNKCPt8cS-VWcMma4QAABBM"]
[Sun Aug 30 03:11:20.527272 2026] [security2:error] [pid 519566:tid 519768] [client 158.23.184.117:1346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/.well-known/core.php"] [unique_id "apPlqNKCPt8cS-VWcMma6gAAA-s"]
[Sun Aug 30 03:11:20.537462 2026] [security2:error] [pid 519566:tid 519745] [client 4.205.62.107:25896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/config/laravolt/css/index.php"] [unique_id "apPlqNKCPt8cS-VWcMma8QAAA9Q"]
[Sun Aug 30 03:11:20.558576 2026] [security2:error] [pid 519566:tid 519781] [client 20.151.200.44:63617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/ssss.php"] [unique_id "apPlqNKCPt8cS-VWcMma9wAAA_g"]
[Sun Aug 30 03:11:20.562519 2026] [security2:error] [pid 519566:tid 519793] [client 4.205.62.107:36661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/services.php"] [unique_id "apPlqNKCPt8cS-VWcMma-AAABAQ"]
[Sun Aug 30 03:11:20.563421 2026] [security2:error] [pid 519566:tid 519770] [client 20.104.104.62:15327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/wk/index.php"] [unique_id "apPlqNKCPt8cS-VWcMma-QAAA-0"]
[Sun Aug 30 03:11:20.575311 2026] [security2:error] [pid 519566:tid 519798] [client 20.104.104.62:45988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/Contrller.php"] [unique_id "apPlqNKCPt8cS-VWcMma_gAABAk"]
[Sun Aug 30 03:11:20.578172 2026] [authz_core:error] [pid 519566:tid 519719] [client 66.249.66.194:59021] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:20.578584 2026] [authz_core:error] [pid 519566:tid 519719] [client 66.249.66.194:59021] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:20.591380 2026] [security2:error] [pid 519566:tid 519730] [client 158.23.184.117:8574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/.well-known/mh.php"] [unique_id "apPlqNKCPt8cS-VWcMmbAAAAA8U"]
[Sun Aug 30 03:11:20.646408 2026] [security2:error] [pid 519566:tid 519740] [client 20.48.251.3:52189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/ms.php"] [unique_id "apPlqNKCPt8cS-VWcMmbBwAAA88"]
[Sun Aug 30 03:11:20.652116 2026] [security2:error] [pid 519566:tid 519761] [client 40.83.93.50:3929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/function.php"] [unique_id "apPlqNKCPt8cS-VWcMmbCAAAA-Q"]
[Sun Aug 30 03:11:20.663839 2026] [security2:error] [pid 519566:tid 519790] [client 20.63.81.20:58910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/gtghklk.php"] [unique_id "apPlqNKCPt8cS-VWcMmbDAAABAE"]
[Sun Aug 30 03:11:20.669398 2026] [security2:error] [pid 519566:tid 519738] [client 158.23.184.117:1365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/akcc.php"] [unique_id "apPlqNKCPt8cS-VWcMmbDwAAA80"]
[Sun Aug 30 03:11:20.680539 2026] [security2:error] [pid 519566:tid 519759] [client 20.104.50.220:29153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/upl.php"] [unique_id "apPlqNKCPt8cS-VWcMmbEQAAA-I"]
[Sun Aug 30 03:11:20.681352 2026] [security2:error] [pid 519566:tid 519758] [client 68.155.159.216:57072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/nf_tracking.php"] [unique_id "apPlqNKCPt8cS-VWcMmbEgAAA-E"]
[Sun Aug 30 03:11:20.702847 2026] [security2:error] [pid 519566:tid 519711] [client 20.104.104.62:41602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/file66.php"] [unique_id "apPlqNKCPt8cS-VWcMmbHgAAA7I"]
[Sun Aug 30 03:11:20.711476 2026] [security2:error] [pid 519566:tid 519725] [client 20.151.200.44:40858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/wp-ver.php"] [unique_id "apPlqNKCPt8cS-VWcMmbIgAAA8A"]
[Sun Aug 30 03:11:20.715701 2026] [security2:error] [pid 519566:tid 519812] [client 20.104.104.62:14386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/dehnl.php"] [unique_id "apPlqNKCPt8cS-VWcMmbIwAABBc"]
[Sun Aug 30 03:11:20.724992 2026] [authz_core:error] [pid 519566:tid 519705] [client 216.73.216.128:8101] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:20.725268 2026] [authz_core:error] [pid 519566:tid 519705] [client 216.73.216.128:8101] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:20.733366 2026] [security2:error] [pid 519566:tid 519700] [client 158.23.184.117:8560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/about/function.php"] [unique_id "apPlqNKCPt8cS-VWcMmbKgAAA6c"]
[Sun Aug 30 03:11:20.746004 2026] [security2:error] [pid 519566:tid 519749] [client 20.196.209.81:21756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/upgrade-temp-backup/min.php"] [unique_id "apPlqNKCPt8cS-VWcMmbLwAAA9g"]
[Sun Aug 30 03:11:20.765634 2026] [security2:error] [pid 519566:tid 519777] [client 20.104.50.220:25439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/x.php"] [unique_id "apPlqNKCPt8cS-VWcMmbNQAAA_Q"]
[Sun Aug 30 03:11:20.792550 2026] [security2:error] [pid 519566:tid 519763] [client 20.63.81.20:58955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/comand.php"] [unique_id "apPlqNKCPt8cS-VWcMmbQwAAA-Y"]
[Sun Aug 30 03:11:20.811685 2026] [security2:error] [pid 519566:tid 519803] [client 158.23.184.117:1565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/themes7.php"] [unique_id "apPlqNKCPt8cS-VWcMmbVAAABA4"]
[Sun Aug 30 03:11:20.815411 2026] [authz_core:error] [pid 519566:tid 519780] [client 216.73.216.128:28133] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:20.815681 2026] [authz_core:error] [pid 519566:tid 519780] [client 216.73.216.128:28133] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:20.830609 2026] [security2:error] [pid 519566:tid 519781] [client 20.151.200.44:63597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/zoz.php"] [unique_id "apPlqNKCPt8cS-VWcMmbWAAAA_g"]
[Sun Aug 30 03:11:20.839017 2026] [security2:error] [pid 519566:tid 519779] [client 20.104.104.62:41658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/blnux.php"] [unique_id "apPlqNKCPt8cS-VWcMmbXgAAA_Y"]
[Sun Aug 30 03:11:20.847087 2026] [authz_core:error] [pid 519566:tid 519811] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:20.847378 2026] [authz_core:error] [pid 519566:tid 519811] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:20.864626 2026] [security2:error] [pid 519566:tid 519714] [client 20.104.104.62:14827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/png.php"] [unique_id "apPlqNKCPt8cS-VWcMmbaQAAA7U"]
[Sun Aug 30 03:11:20.898079 2026] [security2:error] [pid 519566:tid 519749] [client 158.23.184.117:8205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/an.php"] [unique_id "apPlqNKCPt8cS-VWcMmbbwAAA9g"]
[Sun Aug 30 03:11:20.920629 2026] [security2:error] [pid 519566:tid 519787] [client 20.63.81.20:58983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp_motu_myk3v.php"] [unique_id "apPlqNKCPt8cS-VWcMmbdAAAA_4"]
[Sun Aug 30 03:11:20.929462 2026] [security2:error] [pid 519566:tid 519781] [client 20.151.200.44:41862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/od.php"] [unique_id "apPlqNKCPt8cS-VWcMmbdwAAA_g"]
[Sun Aug 30 03:11:20.953250 2026] [security2:error] [pid 519566:tid 519791] [client 158.23.184.117:1560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/wp-admin/images.php"] [unique_id "apPlqNKCPt8cS-VWcMmbgAAABAI"]
[Sun Aug 30 03:11:20.967832 2026] [authz_core:error] [pid 519566:tid 519717] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Frbld
[Sun Aug 30 03:11:20.968114 2026] [authz_core:error] [pid 519566:tid 519717] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fusr%2Fshare%2Frbld
[Sun Aug 30 03:11:20.977478 2026] [security2:error] [pid 519566:tid 519804] [client 20.104.104.62:22665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/attack.php"] [unique_id "apPlqNKCPt8cS-VWcMmbiQAABA8"]
[Sun Aug 30 03:11:20.983400 2026] [security2:error] [pid 519566:tid 519723] [client 20.151.200.44:64164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/px.php"] [unique_id "apPlqNKCPt8cS-VWcMmbjwAAA74"]
[Sun Aug 30 03:11:21.005186 2026] [security2:error] [pid 519566:tid 519738] [client 20.104.104.62:14368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/txets.php"] [unique_id "apPlqdKCPt8cS-VWcMmbkwAAA80"]
[Sun Aug 30 03:11:21.013878 2026] [security2:error] [pid 519566:tid 519767] [client 20.104.18.15:51089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlqdKCPt8cS-VWcMmbnAAAA-o"]
[Sun Aug 30 03:11:21.015566 2026] [security2:error] [pid 519566:tid 519703] [client 20.104.50.220:17282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/lock360.php"] [unique_id "apPlqdKCPt8cS-VWcMmbngAAA6o"]
[Sun Aug 30 03:11:21.039975 2026] [security2:error] [pid 519566:tid 519756] [client 158.23.184.117:8546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/buy.php"] [unique_id "apPlqdKCPt8cS-VWcMmbqQAAA98"]
[Sun Aug 30 03:11:21.049197 2026] [security2:error] [pid 519566:tid 519787] [client 20.63.81.20:59094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/wp_motu_ypdat.php"] [unique_id "apPlqdKCPt8cS-VWcMmbrgAAA_4"]
[Sun Aug 30 03:11:21.052032 2026] [authz_core:error] [pid 519566:tid 519713] [client 216.73.216.128:44927] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:21.052452 2026] [authz_core:error] [pid 519566:tid 519713] [client 216.73.216.128:44927] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:21.067468 2026] [core:alert] [pid 519566:tid 519678] [remote 40.77.167.156:12601] /home3/lordrcan/public_html/.htaccess: without matching section
[Sun Aug 30 03:11:21.082655 2026] [security2:error] [pid 519566:tid 519790] [client 216.73.216.128:28133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlqdKCPt8cS-VWcMmbsQAABAE"]
[Sun Aug 30 03:11:21.096728 2026] [security2:error] [pid 519566:tid 519792] [client 158.23.184.117:1117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/wp-content/themes/haha.php"] [unique_id "apPlqdKCPt8cS-VWcMmbtwAABAM"]
[Sun Aug 30 03:11:21.100708 2026] [security2:error] [pid 519566:tid 519807] [client 20.151.200.44:63011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/kcs.php"] [unique_id "apPlqdKCPt8cS-VWcMmbuAAABBI"]
[Sun Aug 30 03:11:21.105206 2026] [security2:error] [pid 519566:tid 519783] [client 20.104.50.220:61485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/xcv.php"] [unique_id "apPlqdKCPt8cS-VWcMmbuwAAA_o"]
[Sun Aug 30 03:11:21.112950 2026] [security2:error] [pid 519566:tid 519761] [client 20.104.104.62:41610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/wk/index.php"] [unique_id "apPlqdKCPt8cS-VWcMmbvwAAA-Q"]
[Sun Aug 30 03:11:21.136691 2026] [security2:error] [pid 519566:tid 519798] [client 20.104.104.62:14392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/wp-login.php"] [unique_id "apPlqdKCPt8cS-VWcMmbxwAABAk"]
[Sun Aug 30 03:11:21.141103 2026] [security2:error] [pid 519566:tid 519776] [client 20.104.50.220:51614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-admin/css/mailer.php.php"] [unique_id "apPlqdKCPt8cS-VWcMmbyQAAA_M"]
[Sun Aug 30 03:11:21.143238 2026] [security2:error] [pid 519566:tid 519750] [client 20.196.209.81:22433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/upgrade-temp-backup/pk.php"] [unique_id "apPlqdKCPt8cS-VWcMmbygAAA9k"]
[Sun Aug 30 03:11:21.177603 2026] [security2:error] [pid 519566:tid 519736] [client 20.104.50.220:33306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-admin/mailer.php"] [unique_id "apPlqdKCPt8cS-VWcMmb0gAAA8s"]
[Sun Aug 30 03:11:21.177620 2026] [security2:error] [pid 519566:tid 519787] [client 20.63.81.20:59006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/edit.php"] [unique_id "apPlqdKCPt8cS-VWcMmb0wAAA_4"]
[Sun Aug 30 03:11:21.181534 2026] [security2:error] [pid 519566:tid 519806] [client 158.23.184.117:8524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/config.php"] [unique_id "apPlqdKCPt8cS-VWcMmb1AAABBE"]
[Sun Aug 30 03:11:21.199761 2026] [security2:error] [pid 519566:tid 519679] [remote 162.240.171.12:54720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.171.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ihz.grr.temporary.site"] [uri "/wp-login.php"] [unique_id "apPlqdKCPt8cS-VWcMmb3QAEBnA"]
[Sun Aug 30 03:11:21.201577 2026] [security2:error] [pid 519566:tid 519718] [client 20.48.251.3:54828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/fm.php"] [unique_id "apPlqdKCPt8cS-VWcMmb4gAAA7k"]
[Sun Aug 30 03:11:21.207313 2026] [security2:error] [pid 519566:tid 519783] [client 158.23.147.79:39115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/dropdown.php"] [unique_id "apPlqdKCPt8cS-VWcMmb5AAAA_o"]
[Sun Aug 30 03:11:21.230190 2026] [security2:error] [pid 519566:tid 519748] [client 20.197.61.180:12232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/data.php"] [unique_id "apPlqdKCPt8cS-VWcMmb6wAAA9c"]
[Sun Aug 30 03:11:21.236780 2026] [security2:error] [pid 519566:tid 519818] [client 40.83.93.50:6366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/about.php"] [unique_id "apPlqdKCPt8cS-VWcMmb7QAABB0"]
[Sun Aug 30 03:11:21.237031 2026] [security2:error] [pid 519566:tid 519705] [client 158.23.184.117:1368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/wp-mail.php"] [unique_id "apPlqdKCPt8cS-VWcMmb7gAAA6w"]
[Sun Aug 30 03:11:21.239791 2026] [security2:error] [pid 519566:tid 519793] [client 20.104.50.220:6094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/block.php"] [unique_id "apPlqdKCPt8cS-VWcMmb7wAABAQ"]
[Sun Aug 30 03:11:21.249688 2026] [security2:error] [pid 519566:tid 519785] [client 20.104.104.62:45963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/dehnl.php"] [unique_id "apPlqdKCPt8cS-VWcMmb8QAAA_w"]
[Sun Aug 30 03:11:21.253376 2026] [security2:error] [pid 519566:tid 519820] [client 20.104.50.220:52823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/FX.php"] [unique_id "apPlqdKCPt8cS-VWcMmb9AAABB8"]
[Sun Aug 30 03:11:21.266294 2026] [security2:error] [pid 519566:tid 519810] [client 216.73.216.128:45868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/usage_202601.html"] [unique_id "apPlqdKCPt8cS-VWcMmb-QAABBU"]
[Sun Aug 30 03:11:21.277114 2026] [security2:error] [pid 519566:tid 519717] [client 4.205.62.107:17419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/ms.php"] [unique_id "apPlqdKCPt8cS-VWcMmb-wAAA7g"]
[Sun Aug 30 03:11:21.288490 2026] [security2:error] [pid 519566:tid 519776] [client 20.104.104.62:14363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/wp-access.php"] [unique_id "apPlqdKCPt8cS-VWcMmb_gAAA_M"]
[Sun Aug 30 03:11:21.304561 2026] [security2:error] [pid 519566:tid 519734] [client 20.63.81.20:59070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/tqkdqbbv.php"] [unique_id "apPlqdKCPt8cS-VWcMmcAAAAA8k"]
[Sun Aug 30 03:11:21.308919 2026] [security2:error] [pid 519566:tid 519787] [client 4.205.62.107:52804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/fraro.php"] [unique_id "apPlqdKCPt8cS-VWcMmcAgAAA_4"]
[Sun Aug 30 03:11:21.313976 2026] [security2:error] [pid 519566:tid 519803] [client 20.48.251.3:37147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/lala.php"] [unique_id "apPlqdKCPt8cS-VWcMmcBAAABA4"]
[Sun Aug 30 03:11:21.324896 2026] [security2:error] [pid 519566:tid 519760] [client 158.23.184.117:8199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/inputs.php"] [unique_id "apPlqdKCPt8cS-VWcMmcBQAAA-M"]
[Sun Aug 30 03:11:21.328786 2026] [security2:error] [pid 519566:tid 519812] [client 20.151.200.44:65348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/is.php"] [unique_id "apPlqdKCPt8cS-VWcMmcBwAABBc"]
[Sun Aug 30 03:11:21.357027 2026] [security2:error] [pid 519566:tid 519770] [client 20.48.251.3:52830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/environment.php"] [unique_id "apPlqdKCPt8cS-VWcMmcDQAAA-0"]
[Sun Aug 30 03:11:21.364611 2026] [authz_core:error] [pid 519566:tid 519755] [client 216.73.216.128:8101] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:21.364913 2026] [authz_core:error] [pid 519566:tid 519755] [client 216.73.216.128:8101] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:21.372740 2026] [security2:error] [pid 519566:tid 519796] [client 20.104.18.15:18410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/drykl.php"] [unique_id "apPlqdKCPt8cS-VWcMmcEQAABAc"]
[Sun Aug 30 03:11:21.380205 2026] [security2:error] [pid 519566:tid 519763] [client 158.23.184.117:1564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/root.php"] [unique_id "apPlqdKCPt8cS-VWcMmcEwAAA-Y"]
[Sun Aug 30 03:11:21.381870 2026] [security2:error] [pid 519566:tid 519780] [client 20.104.104.62:41653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/png.php"] [unique_id "apPlqdKCPt8cS-VWcMmcFQAAA_c"]
[Sun Aug 30 03:11:21.433717 2026] [security2:error] [pid 519566:tid 519740] [client 20.104.104.62:14799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/wp-content/admin.php"] [unique_id "apPlqdKCPt8cS-VWcMmcJAAAA88"]
[Sun Aug 30 03:11:21.433787 2026] [security2:error] [pid 519566:tid 519804] [client 20.63.81.20:58922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/kjyehoxl.php"] [unique_id "apPlqdKCPt8cS-VWcMmcJQAABA8"]
[Sun Aug 30 03:11:21.437347 2026] [security2:error] [pid 519566:tid 519798] [client 20.104.49.130:64073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/wp-css.php"] [unique_id "apPlqdKCPt8cS-VWcMmcKQAABAk"]
[Sun Aug 30 03:11:21.442141 2026] [security2:error] [pid 519566:tid 519702] [client 20.104.18.15:31739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/mac.php"] [unique_id "apPlqdKCPt8cS-VWcMmcLwAAA6k"]
[Sun Aug 30 03:11:21.444758 2026] [security2:error] [pid 519566:tid 519720] [client 20.104.49.130:57727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/ws78.php"] [unique_id "apPlqdKCPt8cS-VWcMmcMwAAA7s"]
[Sun Aug 30 03:11:21.445317 2026] [authz_core:error] [pid 519566:tid 519696] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Ftls
[Sun Aug 30 03:11:21.445854 2026] [authz_core:error] [pid 519566:tid 519696] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Ftls
[Sun Aug 30 03:11:21.448755 2026] [security2:error] [pid 519566:tid 519682] [remote 162.240.171.12:54720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.171.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ihz.grr.temporary.site"] [uri "/wp-login.php"] [unique_id "apPlqdKCPt8cS-VWcMmcNQADxnM"], referer: https://ihz.grr.temporary.site/wp-login.php
[Sun Aug 30 03:11:21.465215 2026] [security2:error] [pid 519566:tid 519793] [client 158.23.184.117:8554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/radio.php"] [unique_id "apPlqdKCPt8cS-VWcMmcPgAABAQ"]
[Sun Aug 30 03:11:21.468803 2026] [security2:error] [pid 519566:tid 519766] [client 20.104.18.15:22358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/h2.php"] [unique_id "apPlqdKCPt8cS-VWcMmcPwAAA-k"]
[Sun Aug 30 03:11:21.490499 2026] [authz_core:error] [pid 519566:tid 519779] [client 66.249.66.76:35678] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:21.490780 2026] [authz_core:error] [pid 519566:tid 519779] [client 66.249.66.76:35678] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:21.517883 2026] [security2:error] [pid 519566:tid 519728] [client 20.104.104.62:41642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/txets.php"] [unique_id "apPlqdKCPt8cS-VWcMmcTgAAA8M"]
[Sun Aug 30 03:11:21.524080 2026] [security2:error] [pid 519566:tid 519792] [client 158.23.184.117:1542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/ae.php"] [unique_id "apPlqdKCPt8cS-VWcMmcVAAABAM"]
[Sun Aug 30 03:11:21.551398 2026] [security2:error] [pid 519566:tid 519735] [client 216.73.216.128:8101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/usage_202608.html"] [unique_id "apPlqdKCPt8cS-VWcMmcWwAAA8o"]
[Sun Aug 30 03:11:21.555935 2026] [security2:error] [pid 519566:tid 519712] [client 158.23.147.79:39165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/sad/about.php"] [unique_id "apPlqdKCPt8cS-VWcMmcXwAAA7M"]
[Sun Aug 30 03:11:21.563722 2026] [security2:error] [pid 519566:tid 519709] [client 20.63.81.20:59064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/llyuxaqd.php"] [unique_id "apPlqdKCPt8cS-VWcMmcYgAAA7A"]
[Sun Aug 30 03:11:21.564477 2026] [security2:error] [pid 519566:tid 519707] [client 20.196.209.81:22422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/upgrade-temp-backup/plugins/security.php"] [unique_id "apPlqdKCPt8cS-VWcMmcYwAAA64"]
[Sun Aug 30 03:11:21.567347 2026] [security2:error] [pid 519566:tid 519760] [client 20.104.104.62:15234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/log.php"] [unique_id "apPlqdKCPt8cS-VWcMmcZQAAA-M"]
[Sun Aug 30 03:11:21.600589 2026] [security2:error] [pid 519566:tid 519776] [client 20.104.50.220:59346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/006.php"] [unique_id "apPlqdKCPt8cS-VWcMmcawAAA_M"]
[Sun Aug 30 03:11:21.602000 2026] [security2:error] [pid 519566:tid 519702] [client 158.23.184.117:8221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/storage/rip.php"] [unique_id "apPlqdKCPt8cS-VWcMmcbAAAA6k"]
[Sun Aug 30 03:11:21.638141 2026] [security2:error] [pid 519566:tid 519765] [client 216.73.216.128:44927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_config_quote_replace_string"] [unique_id "apPlqdKCPt8cS-VWcMmcbgAAA-g"]
[Sun Aug 30 03:11:21.638674 2026] [security2:error] [pid 519566:tid 519730] [client 20.104.18.15:64672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/sign.php"] [unique_id "apPlqdKCPt8cS-VWcMmcbwAAA8U"]
[Sun Aug 30 03:11:21.645065 2026] [security2:error] [pid 519566:tid 519785] [client 20.104.104.62:41600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/wp-login.php"] [unique_id "apPlqdKCPt8cS-VWcMmccAAAA_w"]
[Sun Aug 30 03:11:21.650586 2026] [security2:error] [pid 519566:tid 519744] [client 4.205.62.107:15970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/a1vx.php"] [unique_id "apPlqdKCPt8cS-VWcMmccgAAA9M"]
[Sun Aug 30 03:11:21.658232 2026] [authz_core:error] [pid 519566:tid 519815] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:21.658508 2026] [authz_core:error] [pid 519566:tid 519815] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:21.660396 2026] [security2:error] [pid 519566:tid 519786] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/app/.env"] [unique_id "apPlqdKCPt8cS-VWcMmcdQAAA_0"]
[Sun Aug 30 03:11:21.664372 2026] [security2:error] [pid 519566:tid 519766] [client 158.23.184.117:1575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/admin/controller/extension/ultra.php"] [unique_id "apPlqdKCPt8cS-VWcMmcdgAAA-k"]
[Sun Aug 30 03:11:21.674870 2026] [security2:error] [pid 519566:tid 519769] [client 20.151.200.44:63564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/tajj.php"] [unique_id "apPlqdKCPt8cS-VWcMmcegAAA-w"]
[Sun Aug 30 03:11:21.679399 2026] [security2:error] [pid 519566:tid 519726] [client 158.23.147.79:58382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-content/x/index.php"] [unique_id "apPlqdKCPt8cS-VWcMmcfAAAA8E"]
[Sun Aug 30 03:11:21.692096 2026] [security2:error] [pid 519566:tid 519713] [client 20.63.81.20:58994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/nbwxolou.php"] [unique_id "apPlqdKCPt8cS-VWcMmchAAAA7Q"]
[Sun Aug 30 03:11:21.701736 2026] [security2:error] [pid 519566:tid 519801] [client 20.104.104.62:14340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/xwpg.php"] [unique_id "apPlqdKCPt8cS-VWcMmcjAAABAw"]
[Sun Aug 30 03:11:21.710066 2026] [security2:error] [pid 519566:tid 519724] [client 20.104.49.130:32796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/load.php"] [unique_id "apPlqdKCPt8cS-VWcMmcjwAAA78"]
[Sun Aug 30 03:11:21.716404 2026] [security2:error] [pid 519566:tid 519735] [client 20.151.200.44:41955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/wp-the.php"] [unique_id "apPlqdKCPt8cS-VWcMmckQAAA8o"]
[Sun Aug 30 03:11:21.721591 2026] [security2:error] [pid 519566:tid 519803] [client 40.83.93.50:7040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/new.php"] [unique_id "apPlqdKCPt8cS-VWcMmclQAABA4"]
[Sun Aug 30 03:11:21.745438 2026] [security2:error] [pid 519566:tid 519792] [client 158.23.184.117:8540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/wp-admin.php"] [unique_id "apPlqdKCPt8cS-VWcMmcqQAABAM"]
[Sun Aug 30 03:11:21.747283 2026] [security2:error] [pid 519566:tid 519702] [client 4.205.62.107:36093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/filesystems.php"] [unique_id "apPlqdKCPt8cS-VWcMmcqwAAA6k"]
[Sun Aug 30 03:11:21.756084 2026] [core:alert] [pid 519566:tid 519717] [client 102.68.120.19:38782] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:11:21.761388 2026] [security2:error] [pid 519566:tid 519785] [client 158.23.147.79:43036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/admin.php"] [unique_id "apPlqdKCPt8cS-VWcMmcsAAAA_w"]
[Sun Aug 30 03:11:21.773959 2026] [security2:error] [pid 519566:tid 519795] [client 20.104.104.62:41661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/wp-access.php"] [unique_id "apPlqdKCPt8cS-VWcMmcuAAABAY"]
[Sun Aug 30 03:11:21.786016 2026] [security2:error] [pid 519566:tid 519705] [client 4.205.62.107:25672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/87.php"] [unique_id "apPlqdKCPt8cS-VWcMmcuwAAA6w"]
[Sun Aug 30 03:11:21.790351 2026] [security2:error] [pid 519566:tid 519735] [client 20.48.251.3:52234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/fucku.php"] [unique_id "apPlqdKCPt8cS-VWcMmcvgAAA8o"]
[Sun Aug 30 03:11:21.798128 2026] [security2:error] [pid 519566:tid 519797] [client 68.155.159.216:57069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wzy.php"] [unique_id "apPlqdKCPt8cS-VWcMmcxAAABAg"]
[Sun Aug 30 03:11:21.803984 2026] [security2:error] [pid 519566:tid 519765] [client 158.23.184.117:1402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/wp-content/import.php"] [unique_id "apPlqdKCPt8cS-VWcMmcyQAAA-g"]
[Sun Aug 30 03:11:21.823232 2026] [security2:error] [pid 519566:tid 519746] [client 20.63.81.20:58960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/nsxeubyv.php"] [unique_id "apPlqdKCPt8cS-VWcMmczgAAA9U"]
[Sun Aug 30 03:11:21.841280 2026] [security2:error] [pid 519566:tid 519702] [client 20.104.104.62:14371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/sxxb.php"] [unique_id "apPlqdKCPt8cS-VWcMmc1wAAA6k"]
[Sun Aug 30 03:11:21.862773 2026] [security2:error] [pid 519566:tid 519783] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/apps/.env"] [unique_id "apPlqdKCPt8cS-VWcMmc3wAAA_o"]
[Sun Aug 30 03:11:21.902174 2026] [security2:error] [pid 519566:tid 519713] [client 20.104.104.62:45959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/wp-content/admin.php"] [unique_id "apPlqdKCPt8cS-VWcMmc6QAAA7Q"]
[Sun Aug 30 03:11:21.910684 2026] [security2:error] [pid 519566:tid 519789] [client 20.104.50.220:25434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/by.php"] [unique_id "apPlqdKCPt8cS-VWcMmc7AAABAA"]
[Sun Aug 30 03:11:21.941502 2026] [security2:error] [pid 519566:tid 519816] [client 158.23.147.79:39141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-admin/admin.php"] [unique_id "apPlqdKCPt8cS-VWcMmc9wAABBs"]
[Sun Aug 30 03:11:21.945153 2026] [security2:error] [pid 519566:tid 519742] [client 158.23.184.117:1392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/wp-includes/fonts/admin.php"] [unique_id "apPlqdKCPt8cS-VWcMmc-AAAA9E"]
[Sun Aug 30 03:11:21.952926 2026] [security2:error] [pid 519566:tid 519818] [client 20.197.61.180:12256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/dt-the7/css/static-less/plugins/admin.php"] [unique_id "apPlqdKCPt8cS-VWcMmc_QAABB0"]
[Sun Aug 30 03:11:21.956145 2026] [security2:error] [pid 519566:tid 519736] [client 20.196.209.81:22453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/upgrade-temp-backup/plugins/users.php"] [unique_id "apPlqdKCPt8cS-VWcMmc_wAAA8s"]
[Sun Aug 30 03:11:21.961717 2026] [security2:error] [pid 519566:tid 519712] [client 20.63.81.20:58980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/zfqipfss.php"] [unique_id "apPlqdKCPt8cS-VWcMmdAQAAA7M"]
[Sun Aug 30 03:11:21.974950 2026] [security2:error] [pid 519566:tid 519753] [client 20.104.104.62:15336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/dx.php"] [unique_id "apPlqdKCPt8cS-VWcMmdCAAAA9w"]
[Sun Aug 30 03:11:21.982003 2026] [authz_core:error] [pid 519566:tid 519811] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory
[Sun Aug 30 03:11:21.982369 2026] [authz_core:error] [pid 519566:tid 519811] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory
[Sun Aug 30 03:11:21.996958 2026] [core:alert] [pid 519566:tid 519785] [client 14.239.94.103:59692] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:11:22.044656 2026] [security2:error] [pid 519566:tid 519708] [client 20.104.104.62:46013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/log.php"] [unique_id "apPlqtKCPt8cS-VWcMmdLAAAA68"]
[Sun Aug 30 03:11:22.065274 2026] [security2:error] [pid 519566:tid 519816] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/api/.env"] [unique_id "apPlqtKCPt8cS-VWcMmdMAAABBs"]
[Sun Aug 30 03:11:22.083979 2026] [security2:error] [pid 519566:tid 519748] [client 158.23.184.117:1382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/222.php"] [unique_id "apPlqtKCPt8cS-VWcMmdMgAAA9c"]
[Sun Aug 30 03:11:22.088814 2026] [security2:error] [pid 519566:tid 519818] [client 20.63.81.20:59109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.81.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wholebeingportland.com"] [uri "/zrjuyoos.php"] [unique_id "apPlqtKCPt8cS-VWcMmdNAAABB0"]
[Sun Aug 30 03:11:22.108236 2026] [security2:error] [pid 519566:tid 519738] [client 20.104.104.62:14399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPlqtKCPt8cS-VWcMmdQAAAA80"]
[Sun Aug 30 03:11:22.114308 2026] [security2:error] [pid 519566:tid 519717] [client 20.104.49.130:60930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/df.php"] [unique_id "apPlqtKCPt8cS-VWcMmdRQAAA7g"]
[Sun Aug 30 03:11:22.134989 2026] [security2:error] [pid 519566:tid 519785] [client 20.104.49.130:26931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/gecko-new.php"] [unique_id "apPlqtKCPt8cS-VWcMmdSQAAA_w"]
[Sun Aug 30 03:11:22.146970 2026] [security2:error] [pid 519566:tid 519711] [client 158.23.184.117:8532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/wp-content.php"] [unique_id "apPlqtKCPt8cS-VWcMmdSwAAA7I"]
[Sun Aug 30 03:11:22.152316 2026] [security2:error] [pid 519566:tid 519786] [client 20.104.18.15:51189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlqtKCPt8cS-VWcMmdTQAAA_0"]
[Sun Aug 30 03:11:22.154752 2026] [security2:error] [pid 519566:tid 519743] [client 68.155.159.216:52234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-admin/css/index.php"] [unique_id "apPlqtKCPt8cS-VWcMmdTwAAA9I"]
[Sun Aug 30 03:11:22.157844 2026] [authz_core:error] [pid 519566:tid 519752] [client 216.73.216.128:62316] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:22.158100 2026] [authz_core:error] [pid 519566:tid 519752] [client 216.73.216.128:62316] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:22.161870 2026] [security2:error] [pid 519566:tid 519806] [client 20.104.50.220:17340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/f35.php"] [unique_id "apPlqtKCPt8cS-VWcMmdUQAABBE"]
[Sun Aug 30 03:11:22.164276 2026] [security2:error] [pid 519566:tid 519700] [client 20.104.49.130:54165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/wen.php"] [unique_id "apPlqtKCPt8cS-VWcMmdUgAAA6c"]
[Sun Aug 30 03:11:22.165757 2026] [authz_core:error] [pid 519566:tid 519807] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:11:22.166196 2026] [authz_core:error] [pid 519566:tid 519807] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:11:22.172864 2026] [authz_core:error] [pid 519566:tid 519704] [client 66.249.66.197:60138] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:22.173130 2026] [authz_core:error] [pid 519566:tid 519704] [client 66.249.66.197:60138] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:22.184860 2026] [security2:error] [pid 519566:tid 519778] [client 20.104.104.62:45970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/xwpg.php"] [unique_id "apPlqtKCPt8cS-VWcMmdWwAAA_U"]
[Sun Aug 30 03:11:22.195311 2026] [security2:error] [pid 519566:tid 519705] [client 40.83.93.50:7066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/goods.php"] [unique_id "apPlqtKCPt8cS-VWcMmdYQAAA6w"]
[Sun Aug 30 03:11:22.195995 2026] [security2:error] [pid 519566:tid 519797] [client 158.23.147.79:43025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-includes/IXR/index.php"] [unique_id "apPlqtKCPt8cS-VWcMmdYwAABAg"]
[Sun Aug 30 03:11:22.201112 2026] [security2:error] [pid 519566:tid 519730] [client 20.151.200.44:63534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/od.php"] [unique_id "apPlqtKCPt8cS-VWcMmdaAAAA8U"]
[Sun Aug 30 03:11:22.226451 2026] [security2:error] [pid 519566:tid 519719] [client 158.23.184.117:1599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/wp-content/languages.php"] [unique_id "apPlqtKCPt8cS-VWcMmdcAAAA7o"]
[Sun Aug 30 03:11:22.232584 2026] [security2:error] [pid 519566:tid 519741] [client 158.23.147.79:60217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-includes/Requests/about.php"] [unique_id "apPlqtKCPt8cS-VWcMmdcwAAA9A"]
[Sun Aug 30 03:11:22.238458 2026] [security2:error] [pid 519566:tid 519720] [client 20.104.104.62:14380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/xda.php"] [unique_id "apPlqtKCPt8cS-VWcMmddQAAA7s"]
[Sun Aug 30 03:11:22.246403 2026] [security2:error] [pid 519566:tid 519758] [client 20.151.200.44:41972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/wt.php"] [unique_id "apPlqtKCPt8cS-VWcMmddwAAA-E"]
[Sun Aug 30 03:11:22.267231 2026] [security2:error] [pid 519566:tid 519727] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/web/.env"] [unique_id "apPlqtKCPt8cS-VWcMmdfwAAA8I"]
[Sun Aug 30 03:11:22.295057 2026] [authz_core:error] [pid 519566:tid 519721] [client 216.73.216.128:45868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:22.295324 2026] [authz_core:error] [pid 519566:tid 519721] [client 216.73.216.128:45868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:22.296982 2026] [security2:error] [pid 519566:tid 519717] [client 158.23.184.117:8545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/wp-content/about.php"] [unique_id "apPlqtKCPt8cS-VWcMmdhwAAA7g"]
[Sun Aug 30 03:11:22.316959 2026] [security2:error] [pid 519566:tid 519778] [client 20.104.104.62:22715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/sxxb.php"] [unique_id "apPlqtKCPt8cS-VWcMmdigAAA_U"]
[Sun Aug 30 03:11:22.327491 2026] [security2:error] [pid 519566:tid 519782] [client 20.104.50.220:61409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/xl.php"] [unique_id "apPlqtKCPt8cS-VWcMmdjQAAA_k"]
[Sun Aug 30 03:11:22.331587 2026] [security2:error] [pid 519566:tid 519729] [client 20.48.251.3:64313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/tinyfilemanager.php"] [unique_id "apPlqtKCPt8cS-VWcMmdkAAAA8Q"]
[Sun Aug 30 03:11:22.335785 2026] [security2:error] [pid 519566:tid 519812] [client 20.104.50.220:33568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-content/mailer.php"] [unique_id "apPlqtKCPt8cS-VWcMmdkwAABBc"]
[Sun Aug 30 03:11:22.351337 2026] [security2:error] [pid 519566:tid 519753] [client 20.196.209.81:11916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/upgrade-temp-backup/plugins/wp-blog-header.php"] [unique_id "apPlqtKCPt8cS-VWcMmdmgAAA9w"]
[Sun Aug 30 03:11:22.368826 2026] [security2:error] [pid 519566:tid 519763] [client 20.104.104.62:15344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPlqtKCPt8cS-VWcMmdnAAAA-Y"]
[Sun Aug 30 03:11:22.369564 2026] [security2:error] [pid 519566:tid 519737] [client 158.23.184.117:1563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/wp-config-sample.php"] [unique_id "apPlqtKCPt8cS-VWcMmdnQAAA8w"]
[Sun Aug 30 03:11:22.375101 2026] [security2:error] [pid 519566:tid 519766] [client 20.48.250.41:49393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlqtKCPt8cS-VWcMmdoAAAA-k"]
[Sun Aug 30 03:11:22.375366 2026] [security2:error] [pid 519566:tid 519820] [client 158.23.147.79:43046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/classwithtostring.php"] [unique_id "apPlqtKCPt8cS-VWcMmdoQAABB8"]
[Sun Aug 30 03:11:22.378813 2026] [security2:error] [pid 519566:tid 519718] [client 20.104.50.220:5523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/admin-bar.php"] [unique_id "apPlqtKCPt8cS-VWcMmdowAAA7k"]
[Sun Aug 30 03:11:22.389075 2026] [security2:error] [pid 519566:tid 519801] [client 20.104.50.220:51602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-includes/css/mailer.php.php"] [unique_id "apPlqtKCPt8cS-VWcMmdpwAABAw"]
[Sun Aug 30 03:11:22.404147 2026] [security2:error] [pid 519566:tid 519735] [client 20.104.50.220:29169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/ga.php"] [unique_id "apPlqtKCPt8cS-VWcMmdqwAAA8o"]
[Sun Aug 30 03:11:22.411257 2026] [security2:error] [pid 519566:tid 519788] [client 4.205.62.107:17712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/fucku.php"] [unique_id "apPlqtKCPt8cS-VWcMmdrQAAA_8"]
[Sun Aug 30 03:11:22.411878 2026] [security2:error] [pid 519566:tid 519741] [client 20.151.200.44:63584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/bge.php"] [unique_id "apPlqtKCPt8cS-VWcMmdrgAAA9A"]
[Sun Aug 30 03:11:22.446368 2026] [security2:error] [pid 519566:tid 519760] [client 4.205.62.107:52910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/thui.php"] [unique_id "apPlqtKCPt8cS-VWcMmdwAAAA-M"]
[Sun Aug 30 03:11:22.447764 2026] [authz_core:error] [pid 519566:tid 519773] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory
[Sun Aug 30 03:11:22.448058 2026] [authz_core:error] [pid 519566:tid 519773] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory
[Sun Aug 30 03:11:22.458476 2026] [security2:error] [pid 519566:tid 519823] [client 20.104.104.62:54999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/dx.php"] [unique_id "apPlqtKCPt8cS-VWcMmdxgAABCI"]
[Sun Aug 30 03:11:22.469452 2026] [security2:error] [pid 519566:tid 519797] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/site/.env"] [unique_id "apPlqtKCPt8cS-VWcMmdywAABAg"]
[Sun Aug 30 03:11:22.492855 2026] [security2:error] [pid 519566:tid 519781] [client 20.48.251.3:36857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/public/bnn_.php.php"] [unique_id "apPlqtKCPt8cS-VWcMmd1AAAA_g"]
[Sun Aug 30 03:11:22.494608 2026] [security2:error] [pid 519566:tid 519804] [client 20.48.251.3:59362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/aws_secret_config.php"] [unique_id "apPlqtKCPt8cS-VWcMmd1QAABA8"]
[Sun Aug 30 03:11:22.499937 2026] [security2:error] [pid 519566:tid 519818] [client 20.104.104.62:14384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/t00l.php"] [unique_id "apPlqtKCPt8cS-VWcMmd1gAABB0"]
[Sun Aug 30 03:11:22.510713 2026] [security2:error] [pid 519566:tid 519755] [client 158.23.184.117:1376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/wp-admin/install-helper.php"] [unique_id "apPlqtKCPt8cS-VWcMmd3gAAA94"]
[Sun Aug 30 03:11:22.517270 2026] [security2:error] [pid 519566:tid 519777] [client 20.104.18.15:18276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/backup.php"] [unique_id "apPlqtKCPt8cS-VWcMmd4QAAA_Q"]
[Sun Aug 30 03:11:22.562374 2026] [security2:error] [pid 519566:tid 519785] [client 20.48.250.41:49358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlqtKCPt8cS-VWcMmd-QAAA_w"]
[Sun Aug 30 03:11:22.586309 2026] [security2:error] [pid 519566:tid 519787] [client 20.104.104.62:54567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPlqtKCPt8cS-VWcMmeAAAAA_4"]
[Sun Aug 30 03:11:22.610039 2026] [autoindex:error] [pid 519566:tid 519745] [client 205.169.39.8:53660] AH01276: Cannot serve directory /home4/ariotti/KonstructCollective.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:11:22.613286 2026] [security2:error] [pid 519566:tid 519732] [client 20.104.18.15:31667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/simple.php"] [unique_id "apPlqtKCPt8cS-VWcMmeBwAAA8c"]
[Sun Aug 30 03:11:22.629432 2026] [security2:error] [pid 519566:tid 519769] [client 20.104.104.62:14816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/ls.php"] [unique_id "apPlqtKCPt8cS-VWcMmeCgAAA-w"]
[Sun Aug 30 03:11:22.634997 2026] [security2:error] [pid 519566:tid 519804] [client 20.104.18.15:22515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apPlqtKCPt8cS-VWcMmeDAAABA8"]
[Sun Aug 30 03:11:22.641147 2026] [security2:error] [pid 519566:tid 519818] [client 158.23.184.117:8551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/x.php"] [unique_id "apPlqtKCPt8cS-VWcMmeDQAABB0"]
[Sun Aug 30 03:11:22.653294 2026] [security2:error] [pid 519566:tid 519729] [client 158.23.184.117:1396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/wp-includes/fonts/classmap.php"] [unique_id "apPlqtKCPt8cS-VWcMmeDgAAA8Q"]
[Sun Aug 30 03:11:22.673278 2026] [security2:error] [pid 519566:tid 519763] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/public/.env"] [unique_id "apPlqtKCPt8cS-VWcMmeFAAAA-Y"]
[Sun Aug 30 03:11:22.676421 2026] [security2:error] [pid 519566:tid 519794] [client 20.197.61.180:3848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/hideo/network.php"] [unique_id "apPlqtKCPt8cS-VWcMmeFQAABAU"]
[Sun Aug 30 03:11:22.684555 2026] [security2:error] [pid 519566:tid 519723] [client 40.83.93.50:7068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/m.php"] [unique_id "apPlqtKCPt8cS-VWcMmeFwAAA74"]
[Sun Aug 30 03:11:22.699252 2026] [authz_core:error] [pid 519566:tid 519803] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:22.699593 2026] [authz_core:error] [pid 519566:tid 519803] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:22.713000 2026] [security2:error] [pid 519566:tid 519706] [client 20.104.104.62:45966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/xda.php"] [unique_id "apPlqtKCPt8cS-VWcMmeLAAAA60"]
[Sun Aug 30 03:11:22.739606 2026] [security2:error] [pid 519566:tid 519708] [client 20.48.250.41:49357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/ff1.php"] [unique_id "apPlqtKCPt8cS-VWcMmeOwAAA68"]
[Sun Aug 30 03:11:22.748542 2026] [security2:error] [pid 519566:tid 519811] [client 20.196.209.81:22443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/upgrade-temp-backup/plugins/wp-mail.php"] [unique_id "apPlqtKCPt8cS-VWcMmePgAABBY"]
[Sun Aug 30 03:11:22.772403 2026] [security2:error] [pid 519566:tid 519766] [client 20.104.50.220:63205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/file5.php"] [unique_id "apPlqtKCPt8cS-VWcMmeSwAAA-k"]
[Sun Aug 30 03:11:22.778534 2026] [security2:error] [pid 519566:tid 519759] [client 20.104.18.15:16956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/wnnjpsby.php"] [unique_id "apPlqtKCPt8cS-VWcMmeUAAAA-I"]
[Sun Aug 30 03:11:22.780590 2026] [authz_core:error] [pid 519566:tid 519793] [client 66.249.66.75:42453] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:22.780962 2026] [authz_core:error] [pid 519566:tid 519793] [client 66.249.66.75:42453] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:22.789073 2026] [security2:error] [pid 519566:tid 519722] [client 4.205.62.107:15871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/public/vx.php"] [unique_id "apPlqtKCPt8cS-VWcMmeVQAAA70"]
[Sun Aug 30 03:11:22.790733 2026] [security2:error] [pid 519566:tid 519786] [client 158.23.184.117:1145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/adminfuns.php/.well-known/acme-challenge/file.php"] [unique_id "apPlqtKCPt8cS-VWcMmeVgAAA_0"]
[Sun Aug 30 03:11:22.801599 2026] [security2:error] [pid 519566:tid 519750] [client 20.104.104.62:14805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/css/000.php"] [unique_id "apPlqtKCPt8cS-VWcMmeXAAAA9k"]
[Sun Aug 30 03:11:22.818817 2026] [authz_core:error] [pid 519566:tid 519738] [client 66.249.66.70:58537] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:22.819246 2026] [authz_core:error] [pid 519566:tid 519738] [client 66.249.66.70:58537] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:22.846258 2026] [security2:error] [pid 519566:tid 519789] [client 20.104.104.62:41612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/wp-admin/js/index.php"] [unique_id "apPlqtKCPt8cS-VWcMmebQAABAA"]
[Sun Aug 30 03:11:22.853029 2026] [core:alert] [pid 519566:tid 519773] [client 81.16.14.2:50364] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:11:22.886271 2026] [security2:error] [pid 519566:tid 519782] [client 158.23.147.79:43067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/install.php"] [unique_id "apPlqtKCPt8cS-VWcMmegAAAA_k"]
[Sun Aug 30 03:11:22.911941 2026] [security2:error] [pid 519566:tid 519817] [client 68.155.159.216:62633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apPlqtKCPt8cS-VWcMmeiAAABBw"]
[Sun Aug 30 03:11:22.931942 2026] [security2:error] [pid 519566:tid 519770] [client 20.48.251.3:52283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/error_log.php"] [unique_id "apPlqtKCPt8cS-VWcMmekAAAA-0"]
[Sun Aug 30 03:11:22.935042 2026] [security2:error] [pid 519566:tid 519707] [client 20.48.250.41:49306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/t.php"] [unique_id "apPlqtKCPt8cS-VWcMmekQAAA64"]
[Sun Aug 30 03:11:22.937315 2026] [security2:error] [pid 519566:tid 519726] [client 20.104.104.62:14364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/cy.php"] [unique_id "apPlqtKCPt8cS-VWcMmekwAAA8E"]
[Sun Aug 30 03:11:22.944748 2026] [authz_core:error] [pid 519566:tid 519801] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule
[Sun Aug 30 03:11:22.945031 2026] [authz_core:error] [pid 519566:tid 519801] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule
[Sun Aug 30 03:11:22.950996 2026] [security2:error] [pid 519566:tid 519719] [client 158.23.184.117:1405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/wp-content/themes/aa.php"] [unique_id "apPlqtKCPt8cS-VWcMmelwAAA7o"]
[Sun Aug 30 03:11:22.951020 2026] [security2:error] [pid 519566:tid 519755] [client 158.23.184.117:8547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/a.php"] [unique_id "apPlqtKCPt8cS-VWcMmemAAAA94"]
[Sun Aug 30 03:11:22.954705 2026] [security2:error] [pid 519566:tid 519718] [client 4.205.62.107:36197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/tax.php"] [unique_id "apPlqtKCPt8cS-VWcMmemwAAA7k"]
[Sun Aug 30 03:11:22.978604 2026] [security2:error] [pid 519566:tid 519709] [client 20.104.104.62:45987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/t00l.php"] [unique_id "apPlqtKCPt8cS-VWcMmeogAAA7A"]
[Sun Aug 30 03:11:23.019537 2026] [security2:error] [pid 519566:tid 519729] [client 4.205.62.107:25533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/plss3.php"] [unique_id "apPlq9KCPt8cS-VWcMmetgAAA8Q"]
[Sun Aug 30 03:11:23.061837 2026] [security2:error] [pid 519566:tid 519736] [client 20.104.50.220:25425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/cxs.php"] [unique_id "apPlq9KCPt8cS-VWcMmexwAAA8s"]
[Sun Aug 30 03:11:23.066762 2026] [security2:error] [pid 519566:tid 519708] [client 20.48.250.41:49290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/erty.php"] [unique_id "apPlq9KCPt8cS-VWcMmeyQAAA68"]
[Sun Aug 30 03:11:23.077889 2026] [security2:error] [pid 519566:tid 519752] [client 20.104.104.62:14813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/admin.php/pindex.php"] [unique_id "apPlq9KCPt8cS-VWcMmezQAAA9s"]
[Sun Aug 30 03:11:23.092406 2026] [security2:error] [pid 519566:tid 519785] [client 158.23.184.117:1540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/chosen.php"] [unique_id "apPlq9KCPt8cS-VWcMme1QAAA_w"]
[Sun Aug 30 03:11:23.093704 2026] [security2:error] [pid 519566:tid 519721] [client 158.23.184.117:8919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/admin/index.php"] [unique_id "apPlq9KCPt8cS-VWcMme2AAAA7w"]
[Sun Aug 30 03:11:23.111453 2026] [security2:error] [pid 519566:tid 519759] [client 20.104.104.62:22678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/ls.php"] [unique_id "apPlq9KCPt8cS-VWcMme5AAAA-I"]
[Sun Aug 30 03:11:23.120348 2026] [core:alert] [pid 519566:tid 519805] [client 103.189.158.118:35892] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:11:23.124957 2026] [security2:error] [pid 519566:tid 519777] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/backend/.env"] [unique_id "apPlq9KCPt8cS-VWcMme6gAAA_Q"]
[Sun Aug 30 03:11:23.168211 2026] [security2:error] [pid 519566:tid 519782] [client 40.83.93.50:3943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/doc.php"] [unique_id "apPlq9KCPt8cS-VWcMme-QAAA_k"]
[Sun Aug 30 03:11:23.170729 2026] [core:alert] [pid 519566:tid 519770] [client 45.224.207.138:40027] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:11:23.170925 2026] [security2:error] [pid 519566:tid 519706] [client 20.196.209.81:17604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/upgrade-temp-backup/themes/admin.php"] [unique_id "apPlq9KCPt8cS-VWcMme_gAAA60"]
[Sun Aug 30 03:11:23.172170 2026] [authz_core:error] [pid 519566:tid 519719] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:23.172604 2026] [authz_core:error] [pid 519566:tid 519719] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:23.208294 2026] [security2:error] [pid 519566:tid 519787] [client 20.104.104.62:14389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/admin.php/csv.php"] [unique_id "apPlq9KCPt8cS-VWcMmfDQAAA_4"]
[Sun Aug 30 03:11:23.234544 2026] [security2:error] [pid 519566:tid 519785] [client 158.23.184.117:1391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/admin/function.php"] [unique_id "apPlq9KCPt8cS-VWcMmfGAAAA_w"]
[Sun Aug 30 03:11:23.234597 2026] [security2:error] [pid 519566:tid 519732] [client 158.23.184.117:8523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/ahax.php"] [unique_id "apPlq9KCPt8cS-VWcMmfGQAAA8c"]
[Sun Aug 30 03:11:23.245318 2026] [security2:error] [pid 519566:tid 519817] [client 20.48.250.41:49311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/0x.php"] [unique_id "apPlq9KCPt8cS-VWcMmfGwAABBw"]
[Sun Aug 30 03:11:23.267690 2026] [security2:error] [pid 519566:tid 519754] [client 20.104.104.62:45985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/css/000.php"] [unique_id "apPlq9KCPt8cS-VWcMmfJQAAA90"]
[Sun Aug 30 03:11:23.290363 2026] [security2:error] [pid 519566:tid 519789] [client 20.104.18.15:51072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/ap.php"] [unique_id "apPlq9KCPt8cS-VWcMmfKwAABAA"]
[Sun Aug 30 03:11:23.291049 2026] [security2:error] [pid 519566:tid 519721] [client 20.104.50.220:16657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/ioxi-o1.php"] [unique_id "apPlq9KCPt8cS-VWcMmfLAAAA7w"]
[Sun Aug 30 03:11:23.320106 2026] [security2:error] [pid 519566:tid 519725] [client 158.23.147.79:43606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-content/x/index.php"] [unique_id "apPlq9KCPt8cS-VWcMmfMQAAA8A"]
[Sun Aug 30 03:11:23.328203 2026] [security2:error] [pid 519566:tid 519766] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/server/.env"] [unique_id "apPlq9KCPt8cS-VWcMmfMgAAA-k"]
[Sun Aug 30 03:11:23.338031 2026] [security2:error] [pid 519566:tid 519711] [client 20.104.50.220:28672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/gelay.php"] [unique_id "apPlq9KCPt8cS-VWcMmfNQAAA7I"]
[Sun Aug 30 03:11:23.345459 2026] [security2:error] [pid 519566:tid 519811] [client 20.104.104.62:14346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/admin.php/700.php"] [unique_id "apPlq9KCPt8cS-VWcMmfOAAABBY"]
[Sun Aug 30 03:11:23.375492 2026] [security2:error] [pid 519566:tid 519822] [client 158.23.184.117:8543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/alfa.php"] [unique_id "apPlq9KCPt8cS-VWcMmfPAAABCE"]
[Sun Aug 30 03:11:23.376493 2026] [security2:error] [pid 519566:tid 519763] [client 158.23.184.117:1537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/wxo.php"] [unique_id "apPlq9KCPt8cS-VWcMmfPgAAA-Y"]
[Sun Aug 30 03:11:23.380282 2026] [security2:error] [pid 519566:tid 519819] [client 158.23.147.79:58399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-admin/includes/index.php"] [unique_id "apPlq9KCPt8cS-VWcMmfQQAABB4"]
[Sun Aug 30 03:11:23.387081 2026] [security2:error] [pid 519566:tid 519704] [client 20.48.250.41:49362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/66.php"] [unique_id "apPlq9KCPt8cS-VWcMmfRAAAA6s"]
[Sun Aug 30 03:11:23.391869 2026] [security2:error] [pid 519566:tid 519733] [client 20.197.61.180:3852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPlq9KCPt8cS-VWcMmfRwAAA8g"]
[Sun Aug 30 03:11:23.402675 2026] [security2:error] [pid 519566:tid 519779] [client 20.104.104.62:45981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/cy.php"] [unique_id "apPlq9KCPt8cS-VWcMmfTQAAA_Y"]
[Sun Aug 30 03:11:23.403978 2026] [security2:error] [pid 519566:tid 519797] [client 68.155.159.216:52564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-admin/images/index.php"] [unique_id "apPlq9KCPt8cS-VWcMmfTgAABAg"]
[Sun Aug 30 03:11:23.444284 2026] [security2:error] [pid 519566:tid 519738] [client 158.23.147.79:43019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-includes/Requests/about.php"] [unique_id "apPlq9KCPt8cS-VWcMmfXgAAA80"]
[Sun Aug 30 03:11:23.472033 2026] [security2:error] [pid 519566:tid 519816] [client 20.48.251.3:54840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/05.php"] [unique_id "apPlq9KCPt8cS-VWcMmfaQAABBs"]
[Sun Aug 30 03:11:23.473737 2026] [security2:error] [pid 519566:tid 519763] [client 20.104.50.220:33205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-includes/mailer.php"] [unique_id "apPlq9KCPt8cS-VWcMmfawAAA-Y"]
[Sun Aug 30 03:11:23.478673 2026] [security2:error] [pid 519566:tid 519734] [client 20.104.104.62:14398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/admin.php/007x.php"] [unique_id "apPlq9KCPt8cS-VWcMmfbgAAA8k"]
[Sun Aug 30 03:11:23.485145 2026] [authz_core:error] [pid 519566:tid 519731] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fproc%2Ftty
[Sun Aug 30 03:11:23.485581 2026] [authz_core:error] [pid 519566:tid 519731] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fproc%2Ftty
[Sun Aug 30 03:11:23.498380 2026] [authz_core:error] [pid 519566:tid 519721] [client 66.249.66.205:37446] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:23.498665 2026] [authz_core:error] [pid 519566:tid 519721] [client 66.249.66.205:37446] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:23.514196 2026] [security2:error] [pid 519566:tid 519705] [client 20.104.50.220:59556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/xleet.php"] [unique_id "apPlq9KCPt8cS-VWcMmfggAAA6w"]
[Sun Aug 30 03:11:23.520182 2026] [security2:error] [pid 519566:tid 519822] [client 158.23.184.117:1348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/wp-admin/theme-editor.php"] [unique_id "apPlq9KCPt8cS-VWcMmfiAAABCE"]
[Sun Aug 30 03:11:23.528385 2026] [security2:error] [pid 519566:tid 519697] [client 20.104.104.62:54980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/admin.php/pindex.php"] [unique_id "apPlq9KCPt8cS-VWcMmfjgAAA6Q"]
[Sun Aug 30 03:11:23.528412 2026] [security2:error] [pid 519566:tid 519760] [client 20.104.50.220:51541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-admin/mailer.php"] [unique_id "apPlq9KCPt8cS-VWcMmfjQAAA-M"]
[Sun Aug 30 03:11:23.530455 2026] [security2:error] [pid 519566:tid 519755] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/frontend/.env"] [unique_id "apPlq9KCPt8cS-VWcMmfkgAAA94"]
[Sun Aug 30 03:11:23.536209 2026] [security2:error] [pid 519566:tid 519763] [client 20.48.250.41:49387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/f35.php"] [unique_id "apPlq9KCPt8cS-VWcMmflQAAA-Y"]
[Sun Aug 30 03:11:23.539393 2026] [security2:error] [pid 519566:tid 519734] [client 20.104.50.220:5916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/mar.php"] [unique_id "apPlq9KCPt8cS-VWcMmflwAAA8k"]
[Sun Aug 30 03:11:23.542076 2026] [security2:error] [pid 519566:tid 519792] [client 20.104.50.220:62821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/ganz.php"] [unique_id "apPlq9KCPt8cS-VWcMmfmwAABAM"]
[Sun Aug 30 03:11:23.549696 2026] [security2:error] [pid 519566:tid 519785] [client 4.205.62.107:16789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/error_log.php"] [unique_id "apPlq9KCPt8cS-VWcMmfnQAAA_w"]
[Sun Aug 30 03:11:23.553715 2026] [security2:error] [pid 519566:tid 519715] [client 158.23.147.79:39132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-admin/includes/index.php"] [unique_id "apPlq9KCPt8cS-VWcMmfnwAAA7Y"]
[Sun Aug 30 03:11:23.563736 2026] [security2:error] [pid 519566:tid 519707] [client 20.196.209.81:22402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/upgrade-temp-backup/themes/login.php"] [unique_id "apPlq9KCPt8cS-VWcMmfpAAAA64"]
[Sun Aug 30 03:11:23.565093 2026] [authz_core:error] [pid 519566:tid 519733] [client 66.249.66.45:44813] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:23.565364 2026] [authz_core:error] [pid 519566:tid 519733] [client 66.249.66.45:44813] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:23.583686 2026] [security2:error] [pid 519566:tid 519797] [client 4.205.62.107:52847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/lala.php"] [unique_id "apPlq9KCPt8cS-VWcMmfqAAABAg"]
[Sun Aug 30 03:11:23.588510 2026] [security2:error] [pid 519566:tid 519814] [client 20.151.200.44:40941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/ah24.php"] [unique_id "apPlq9KCPt8cS-VWcMmfqgAABBk"]
[Sun Aug 30 03:11:23.607446 2026] [security2:error] [pid 519566:tid 519793] [client 20.104.104.62:15322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/admin.php/heex.php"] [unique_id "apPlq9KCPt8cS-VWcMmfrgAABAQ"]
[Sun Aug 30 03:11:23.633154 2026] [security2:error] [pid 519566:tid 519822] [client 20.48.251.3:52795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/snq.php"] [unique_id "apPlq9KCPt8cS-VWcMmfsAAABCE"]
[Sun Aug 30 03:11:23.656772 2026] [security2:error] [pid 519566:tid 519810] [client 20.104.104.62:45991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/admin.php/csv.php"] [unique_id "apPlq9KCPt8cS-VWcMmftAAABBU"]
[Sun Aug 30 03:11:23.660114 2026] [security2:error] [pid 519566:tid 519800] [client 20.48.251.3:36851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/wsws.php"] [unique_id "apPlq9KCPt8cS-VWcMmftwAABAs"]
[Sun Aug 30 03:11:23.667034 2026] [authz_core:error] [pid 519566:tid 519755] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:23.667311 2026] [authz_core:error] [pid 519566:tid 519755] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:23.670413 2026] [security2:error] [pid 519566:tid 519783] [client 40.83.93.50:7081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/users.php"] [unique_id "apPlq9KCPt8cS-VWcMmfuwAAA_o"]
[Sun Aug 30 03:11:23.673108 2026] [security2:error] [pid 519566:tid 519816] [client 20.48.250.41:49359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/wen.php"] [unique_id "apPlq9KCPt8cS-VWcMmfvQAABBs"]
[Sun Aug 30 03:11:23.709554 2026] [security2:error] [pid 519566:tid 519762] [client 20.104.18.15:18265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/indo.php"] [unique_id "apPlq9KCPt8cS-VWcMmf2QAAA-U"]
[Sun Aug 30 03:11:23.718246 2026] [security2:error] [pid 519566:tid 519714] [client 158.23.184.117:8216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/chosen.php"] [unique_id "apPlq9KCPt8cS-VWcMmf3gAAA7U"]
[Sun Aug 30 03:11:23.718814 2026] [security2:error] [pid 519566:tid 519758] [client 158.23.184.117:1551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/termps.php"] [unique_id "apPlq9KCPt8cS-VWcMmf3wAAA-E"]
[Sun Aug 30 03:11:23.732422 2026] [security2:error] [pid 519566:tid 519778] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/src/.env"] [unique_id "apPlq9KCPt8cS-VWcMmf5gAAA_U"]
[Sun Aug 30 03:11:23.751852 2026] [security2:error] [pid 519566:tid 519801] [client 20.104.18.15:31655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/sallu.php"] [unique_id "apPlq9KCPt8cS-VWcMmf8AAABAw"]
[Sun Aug 30 03:11:23.766462 2026] [security2:error] [pid 519566:tid 519726] [client 20.104.104.62:15252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/tf.php"] [unique_id "apPlq9KCPt8cS-VWcMmf-gAAA8E"]
[Sun Aug 30 03:11:23.784755 2026] [security2:error] [pid 519566:tid 519814] [client 20.104.104.62:41663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/admin.php/700.php"] [unique_id "apPlq9KCPt8cS-VWcMmgAAAABBk"]
[Sun Aug 30 03:11:23.800737 2026] [security2:error] [pid 519566:tid 519792] [client 20.104.18.15:22466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/sao.php"] [unique_id "apPlq9KCPt8cS-VWcMmgCgAABAM"]
[Sun Aug 30 03:11:23.816825 2026] [security2:error] [pid 519566:tid 519578] [remote 103.255.134.61:52204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-a4f4a229.maarifado.com"] [uri "/wp-login.php"] [unique_id "apPlq9KCPt8cS-VWcMmgDQAD0Qs"]
[Sun Aug 30 03:11:23.859558 2026] [security2:error] [pid 519566:tid 519720] [client 158.23.184.117:8202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/hplfuns.php"] [unique_id "apPlq9KCPt8cS-VWcMmgHgAAA7s"]
[Sun Aug 30 03:11:23.862313 2026] [security2:error] [pid 519566:tid 519791] [client 158.23.184.117:1383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/fix.php"] [unique_id "apPlq9KCPt8cS-VWcMmgHwAABAI"]
[Sun Aug 30 03:11:23.863863 2026] [security2:error] [pid 519566:tid 519820] [client 20.104.49.130:48044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/term.php"] [unique_id "apPlq9KCPt8cS-VWcMmgIgAABB8"]
[Sun Aug 30 03:11:23.864431 2026] [security2:error] [pid 519566:tid 519700] [client 158.23.147.79:39150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-login.php"] [unique_id "apPlq9KCPt8cS-VWcMmgIwAAA6c"]
[Sun Aug 30 03:11:23.897044 2026] [security2:error] [pid 519566:tid 519796] [client 20.104.104.62:15333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/update/da222.php"] [unique_id "apPlq9KCPt8cS-VWcMmgLAAABAc"]
[Sun Aug 30 03:11:23.908370 2026] [security2:error] [pid 519566:tid 519811] [client 20.104.50.220:31504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPlq9KCPt8cS-VWcMmgMQAABBY"]
[Sun Aug 30 03:11:23.915258 2026] [security2:error] [pid 519566:tid 519766] [client 20.104.104.62:45969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/admin.php/007x.php"] [unique_id "apPlq9KCPt8cS-VWcMmgNwAAA-k"]
[Sun Aug 30 03:11:23.922556 2026] [security2:error] [pid 519566:tid 519715] [client 20.48.250.41:49401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/inc.php"] [unique_id "apPlq9KCPt8cS-VWcMmgOgAAA7Y"]
[Sun Aug 30 03:11:23.930379 2026] [security2:error] [pid 519566:tid 519792] [client 4.205.62.107:15965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/log.php"] [unique_id "apPlq9KCPt8cS-VWcMmgPQAABAM"]
[Sun Aug 30 03:11:23.935438 2026] [security2:error] [pid 519566:tid 519746] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/core/.env"] [unique_id "apPlq9KCPt8cS-VWcMmgQQAAA9U"]
[Sun Aug 30 03:11:23.951408 2026] [authz_core:error] [pid 519566:tid 519752] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Ftls%2Fsections
[Sun Aug 30 03:11:23.951676 2026] [authz_core:error] [pid 519566:tid 519752] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Ftls%2Fsections
[Sun Aug 30 03:11:23.960687 2026] [security2:error] [pid 519566:tid 519728] [client 20.196.209.81:11943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/upgrade-temp-backup/themes/test.php"] [unique_id "apPlq9KCPt8cS-VWcMmgSAAAA8M"]
[Sun Aug 30 03:11:23.966680 2026] [security2:error] [pid 519566:tid 519705] [client 20.104.18.15:17022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/gigi.php"] [unique_id "apPlq9KCPt8cS-VWcMmgTAAAA6w"]
[Sun Aug 30 03:11:24.004972 2026] [security2:error] [pid 519566:tid 519742] [client 158.23.184.117:1569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/wp-includes/ID3/admin.php"] [unique_id "apPlrNKCPt8cS-VWcMmgXQAAA9E"]
[Sun Aug 30 03:11:24.040145 2026] [security2:error] [pid 519566:tid 519766] [client 20.104.104.62:15329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/qi.php"] [unique_id "apPlrNKCPt8cS-VWcMmgawAAA-k"]
[Sun Aug 30 03:11:24.060391 2026] [security2:error] [pid 519566:tid 519718] [client 20.104.104.62:22682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/admin.php/heex.php"] [unique_id "apPlrNKCPt8cS-VWcMmgcAAAA7k"]
[Sun Aug 30 03:11:24.070944 2026] [security2:error] [pid 519566:tid 519785] [client 20.48.251.3:52284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/phina.php"] [unique_id "apPlrNKCPt8cS-VWcMmgcgAAA_w"]
[Sun Aug 30 03:11:24.099042 2026] [security2:error] [pid 519566:tid 519724] [client 158.23.147.79:39297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apPlrNKCPt8cS-VWcMmgfQAAA78"]
[Sun Aug 30 03:11:24.111571 2026] [security2:error] [pid 519566:tid 519738] [client 20.197.61.180:8475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/intense/block-css.php"] [unique_id "apPlrNKCPt8cS-VWcMmghQAAA80"]
[Sun Aug 30 03:11:24.113507 2026] [core:alert] [pid 519566:tid 519803] [client 37.236.31.44:50784] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:11:24.127105 2026] [security2:error] [pid 519566:tid 519791] [client 20.48.250.41:49292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/6bcwiqwj.php"] [unique_id "apPlrNKCPt8cS-VWcMmgiQAABAI"]
[Sun Aug 30 03:11:24.132463 2026] [security2:error] [pid 519566:tid 519706] [client 68.155.159.216:57051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apPlrNKCPt8cS-VWcMmgiwAAA60"]
[Sun Aug 30 03:11:24.133307 2026] [security2:error] [pid 519566:tid 519819] [client 158.23.184.117:8572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/lite.php"] [unique_id "apPlrNKCPt8cS-VWcMmgjAAABB4"]
[Sun Aug 30 03:11:24.139160 2026] [security2:error] [pid 519566:tid 519820] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/core/app/.env"] [unique_id "apPlrNKCPt8cS-VWcMmgjQAABB8"]
[Sun Aug 30 03:11:24.146157 2026] [security2:error] [pid 519566:tid 519740] [client 158.23.184.117:1544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/tiny.php"] [unique_id "apPlrNKCPt8cS-VWcMmgkAAAA88"]
[Sun Aug 30 03:11:24.162383 2026] [authz_core:error] [pid 519566:tid 519709] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:24.162656 2026] [authz_core:error] [pid 519566:tid 519709] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:24.168392 2026] [security2:error] [pid 519566:tid 519760] [client 20.104.104.62:14791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/px.php"] [unique_id "apPlrNKCPt8cS-VWcMmglQAAA-M"]
[Sun Aug 30 03:11:24.199453 2026] [security2:error] [pid 519566:tid 519775] [client 20.104.104.62:41636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/tf.php"] [unique_id "apPlrNKCPt8cS-VWcMmgpAAAA_I"]
[Sun Aug 30 03:11:24.218977 2026] [security2:error] [pid 519566:tid 519729] [client 4.205.62.107:36044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPlrNKCPt8cS-VWcMmgqgAAA8Q"]
[Sun Aug 30 03:11:24.221507 2026] [security2:error] [pid 519566:tid 519747] [client 20.104.50.220:25440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/coffexium.php"] [unique_id "apPlrNKCPt8cS-VWcMmgrAAAA9Y"]
[Sun Aug 30 03:11:24.253382 2026] [security2:error] [pid 519566:tid 519797] [client 20.151.200.44:63587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/ssh3ll.php"] [unique_id "apPlrNKCPt8cS-VWcMmgsgAABAg"]
[Sun Aug 30 03:11:24.260947 2026] [security2:error] [pid 519566:tid 519735] [client 40.83.93.50:10691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/class.php"] [unique_id "apPlrNKCPt8cS-VWcMmgtQAAA8o"]
[Sun Aug 30 03:11:24.265871 2026] [security2:error] [pid 519566:tid 519815] [client 4.205.62.107:25531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/aws.php"] [unique_id "apPlrNKCPt8cS-VWcMmgtwAABBo"]
[Sun Aug 30 03:11:24.271598 2026] [security2:error] [pid 519566:tid 519734] [client 20.48.250.41:49286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/easy.php"] [unique_id "apPlrNKCPt8cS-VWcMmguQAAA8k"]
[Sun Aug 30 03:11:24.273348 2026] [security2:error] [pid 519566:tid 519773] [client 158.23.184.117:8922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/r.php"] [unique_id "apPlrNKCPt8cS-VWcMmgvAAAA_A"]
[Sun Aug 30 03:11:24.287935 2026] [security2:error] [pid 519566:tid 519762] [client 158.23.184.117:1369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/css/classwithtostring.php"] [unique_id "apPlrNKCPt8cS-VWcMmgwgAAA-U"]
[Sun Aug 30 03:11:24.304579 2026] [security2:error] [pid 519566:tid 519778] [client 20.104.104.62:14844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/is.php"] [unique_id "apPlrNKCPt8cS-VWcMmgyAAAA_U"]
[Sun Aug 30 03:11:24.334506 2026] [security2:error] [pid 519566:tid 519585] [remote 103.255.134.61:52204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-a4f4a229.maarifado.com"] [uri "/wp-login.php"] [unique_id "apPlrNKCPt8cS-VWcMmg0wAEFhI"], referer: https://website-a4f4a229.maarifado.com/wp-login.php
[Sun Aug 30 03:11:24.341264 2026] [security2:error] [pid 519566:tid 519715] [client 20.104.104.62:22671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/update/da222.php"] [unique_id "apPlrNKCPt8cS-VWcMmg1wAAA7Y"]
[Sun Aug 30 03:11:24.341447 2026] [security2:error] [pid 519566:tid 519768] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/config/.env"] [unique_id "apPlrNKCPt8cS-VWcMmg1gAAA-s"]
[Sun Aug 30 03:11:24.353340 2026] [authz_core:error] [pid 519566:tid 519806] [client 66.249.66.206:54355] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:24.353749 2026] [security2:error] [pid 519566:tid 519790] [client 20.196.209.81:22458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/upgrade-temp-backup/themes/wp-links-opml.php"] [unique_id "apPlrNKCPt8cS-VWcMmg3QAABAE"]
[Sun Aug 30 03:11:24.353821 2026] [authz_core:error] [pid 519566:tid 519806] [client 66.249.66.206:54355] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:24.376507 2026] [security2:error] [pid 519566:tid 519766] [client 158.23.147.79:43640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-admin/images/about.php"] [unique_id "apPlrNKCPt8cS-VWcMmg4AAAA-k"]
[Sun Aug 30 03:11:24.415620 2026] [security2:error] [pid 519566:tid 519725] [client 158.23.184.117:8573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/shell.php"] [unique_id "apPlrNKCPt8cS-VWcMmg7gAAA8A"]
[Sun Aug 30 03:11:24.426408 2026] [security2:error] [pid 519566:tid 519696] [client 20.104.50.220:16600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/juuuu.php"] [unique_id "apPlrNKCPt8cS-VWcMmg8gAAA6M"]
[Sun Aug 30 03:11:24.431708 2026] [security2:error] [pid 519566:tid 519723] [client 20.104.18.15:51078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/media.php"] [unique_id "apPlrNKCPt8cS-VWcMmg9wAAA74"]
[Sun Aug 30 03:11:24.432669 2026] [security2:error] [pid 519566:tid 519778] [client 20.48.250.41:49296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/fresh3.php"] [unique_id "apPlrNKCPt8cS-VWcMmg-QAAA_U"]
[Sun Aug 30 03:11:24.434532 2026] [security2:error] [pid 519566:tid 519698] [client 158.23.184.117:1393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/buy.php"] [unique_id "apPlrNKCPt8cS-VWcMmg-gAAA6U"]
[Sun Aug 30 03:11:24.436602 2026] [security2:error] [pid 519566:tid 519754] [client 20.104.104.62:14372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/od.php"] [unique_id "apPlrNKCPt8cS-VWcMmg-wAAA90"]
[Sun Aug 30 03:11:24.474995 2026] [security2:error] [pid 519566:tid 519709] [client 20.104.104.62:22677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/qi.php"] [unique_id "apPlrNKCPt8cS-VWcMmhCwAAA7A"]
[Sun Aug 30 03:11:24.486977 2026] [authz_core:error] [pid 519566:tid 519701] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Ftls%2Fsections
[Sun Aug 30 03:11:24.487241 2026] [authz_core:error] [pid 519566:tid 519701] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Ftls%2Fsections
[Sun Aug 30 03:11:24.530639 2026] [security2:error] [pid 519566:tid 519761] [client 20.151.200.44:41941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/im.php"] [unique_id "apPlrNKCPt8cS-VWcMmhIgAAA-Q"]
[Sun Aug 30 03:11:24.534371 2026] [security2:error] [pid 519566:tid 519816] [client 20.104.50.220:64449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/darkshell.php"] [unique_id "apPlrNKCPt8cS-VWcMmhJAAABBs"]
[Sun Aug 30 03:11:24.543529 2026] [security2:error] [pid 519566:tid 519798] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/private/.env"] [unique_id "apPlrNKCPt8cS-VWcMmhKAAABAk"]
[Sun Aug 30 03:11:24.558488 2026] [security2:error] [pid 519566:tid 519743] [client 158.23.184.117:8535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hnfood.co.kr"] [uri "/themes.php"] [unique_id "apPlrNKCPt8cS-VWcMmhLgAAA9I"]
[Sun Aug 30 03:11:24.572812 2026] [security2:error] [pid 519566:tid 519703] [client 20.104.104.62:14788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/wp-the.php"] [unique_id "apPlrNKCPt8cS-VWcMmhMQAAA6o"]
[Sun Aug 30 03:11:24.573526 2026] [security2:error] [pid 519566:tid 519782] [client 20.48.250.41:49382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/bgymj.php"] [unique_id "apPlrNKCPt8cS-VWcMmhMgAAA_k"]
[Sun Aug 30 03:11:24.576068 2026] [security2:error] [pid 519566:tid 519727] [client 158.23.184.117:1557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/bk.php"] [unique_id "apPlrNKCPt8cS-VWcMmhNQAAA8I"]
[Sun Aug 30 03:11:24.606369 2026] [security2:error] [pid 519566:tid 519718] [client 20.104.104.62:41616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/px.php"] [unique_id "apPlrNKCPt8cS-VWcMmhPAAAA7k"]
[Sun Aug 30 03:11:24.607564 2026] [security2:error] [pid 519566:tid 519768] [client 20.104.50.220:33328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/ym.php"] [unique_id "apPlrNKCPt8cS-VWcMmhPQAAA-s"]
[Sun Aug 30 03:11:24.609487 2026] [security2:error] [pid 519566:tid 519751] [client 20.48.251.3:54742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/wp-blog.php"] [unique_id "apPlrNKCPt8cS-VWcMmhPgAAA9o"]
[Sun Aug 30 03:11:24.622484 2026] [security2:error] [pid 519566:tid 519704] [client 158.23.147.79:43643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPlrNKCPt8cS-VWcMmhQAAAA6s"]
[Sun Aug 30 03:11:24.656781 2026] [security2:error] [pid 519566:tid 519742] [client 20.104.50.220:61992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/XxX.php"] [unique_id "apPlrNKCPt8cS-VWcMmhQgAAA9E"]
[Sun Aug 30 03:11:24.680014 2026] [authz_core:error] [pid 519566:tid 519801] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:24.680447 2026] [authz_core:error] [pid 519566:tid 519801] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:24.681369 2026] [security2:error] [pid 519566:tid 519809] [client 20.104.50.220:42800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-content/mailer.php"] [unique_id "apPlrNKCPt8cS-VWcMmhTAAABBQ"]
[Sun Aug 30 03:11:24.687705 2026] [security2:error] [pid 519566:tid 519756] [client 4.205.62.107:17100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/phina.php"] [unique_id "apPlrNKCPt8cS-VWcMmhUAAAA98"]
[Sun Aug 30 03:11:24.692542 2026] [security2:error] [pid 519566:tid 519791] [client 20.151.200.44:65446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/wp-the.php"] [unique_id "apPlrNKCPt8cS-VWcMmhVQAABAI"]
[Sun Aug 30 03:11:24.695258 2026] [security2:error] [pid 519566:tid 519805] [client 20.104.50.220:29145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/gas.php"] [unique_id "apPlrNKCPt8cS-VWcMmhWgAABBA"]
[Sun Aug 30 03:11:24.697267 2026] [security2:error] [pid 519566:tid 519787] [client 68.155.159.216:54333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-includes/index.php"] [unique_id "apPlrNKCPt8cS-VWcMmhXQAAA_4"]
[Sun Aug 30 03:11:24.704975 2026] [security2:error] [pid 519566:tid 519711] [client 20.104.104.62:14376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/wt.php"] [unique_id "apPlrNKCPt8cS-VWcMmhYAAAA7I"]
[Sun Aug 30 03:11:24.716908 2026] [security2:error] [pid 519566:tid 519728] [client 20.104.50.220:6114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/revisi.php"] [unique_id "apPlrNKCPt8cS-VWcMmhagAAA8M"]
[Sun Aug 30 03:11:24.717360 2026] [security2:error] [pid 519566:tid 519746] [client 158.23.184.117:1367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/.trash7309/index.php"] [unique_id "apPlrNKCPt8cS-VWcMmhawAAA9U"]
[Sun Aug 30 03:11:24.720750 2026] [security2:error] [pid 519566:tid 519700] [client 4.205.62.107:52873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/public/bnn_.php.php"] [unique_id "apPlrNKCPt8cS-VWcMmhbgAAA6c"]
[Sun Aug 30 03:11:24.732576 2026] [security2:error] [pid 519566:tid 519738] [client 20.104.104.62:41603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/is.php"] [unique_id "apPlrNKCPt8cS-VWcMmhdgAAA80"]
[Sun Aug 30 03:11:24.745456 2026] [security2:error] [pid 519566:tid 519741] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/application/.env"] [unique_id "apPlrNKCPt8cS-VWcMmhewAAA9A"]
[Sun Aug 30 03:11:24.754557 2026] [security2:error] [pid 519566:tid 519796] [client 20.196.209.81:21747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/upgrade-temp-backup/themes/wp-settings.php"] [unique_id "apPlrNKCPt8cS-VWcMmhfwAABAc"]
[Sun Aug 30 03:11:24.763499 2026] [security2:error] [pid 519566:tid 519733] [client 40.83.93.50:6551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/auth.php"] [unique_id "apPlrNKCPt8cS-VWcMmhhAAAA8g"]
[Sun Aug 30 03:11:24.788004 2026] [security2:error] [pid 519566:tid 519711] [client 20.48.251.3:59318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/wp-access.php"] [unique_id "apPlrNKCPt8cS-VWcMmhiwAAA7I"]
[Sun Aug 30 03:11:24.795559 2026] [security2:error] [pid 519566:tid 519798] [client 20.48.250.41:49289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/ws69.php"] [unique_id "apPlrNKCPt8cS-VWcMmhjwAABAk"]
[Sun Aug 30 03:11:24.806268 2026] [security2:error] [pid 519566:tid 519815] [client 158.23.147.79:43043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-admin.php"] [unique_id "apPlrNKCPt8cS-VWcMmhlgAABBo"]
[Sun Aug 30 03:11:24.808823 2026] [security2:error] [pid 519566:tid 519759] [client 20.197.61.180:12234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/login.php"] [unique_id "apPlrNKCPt8cS-VWcMmhlwAAA-I"]
[Sun Aug 30 03:11:24.809179 2026] [security2:error] [pid 519566:tid 519714] [client 20.48.251.3:37165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/localconf.php"] [unique_id "apPlrNKCPt8cS-VWcMmhmAAAA7U"]
[Sun Aug 30 03:11:24.834122 2026] [core:alert] [pid 519566:tid 519732] [client 103.41.114.106:39072] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:11:24.841282 2026] [security2:error] [pid 519566:tid 519782] [client 20.104.104.62:15311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/im.php"] [unique_id "apPlrNKCPt8cS-VWcMmhpQAAA_k"]
[Sun Aug 30 03:11:24.856551 2026] [security2:error] [pid 519566:tid 519720] [client 158.23.184.117:1541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/jp.php"] [unique_id "apPlrNKCPt8cS-VWcMmhrQAAA7s"]
[Sun Aug 30 03:11:24.867171 2026] [security2:error] [pid 519566:tid 519751] [client 20.104.104.62:41619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/od.php"] [unique_id "apPlrNKCPt8cS-VWcMmhsQAAA9o"]
[Sun Aug 30 03:11:24.881528 2026] [security2:error] [pid 519566:tid 519709] [client 20.104.18.15:18208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/sign.php"] [unique_id "apPlrNKCPt8cS-VWcMmhtwAAA7A"]
[Sun Aug 30 03:11:24.889663 2026] [authz_core:error] [pid 519566:tid 519811] [client 66.249.66.43:52544] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:24.890142 2026] [authz_core:error] [pid 519566:tid 519811] [client 66.249.66.43:52544] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:24.910428 2026] [security2:error] [pid 519566:tid 519797] [client 20.104.18.15:31628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/biufile.php"] [unique_id "apPlrNKCPt8cS-VWcMmhvwAABAg"]
[Sun Aug 30 03:11:24.947531 2026] [security2:error] [pid 519566:tid 519721] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/bootstrap/.env"] [unique_id "apPlrNKCPt8cS-VWcMmhywAAA7w"]
[Sun Aug 30 03:11:24.948016 2026] [security2:error] [pid 519566:tid 519698] [client 20.48.250.41:19427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/ccs.php"] [unique_id "apPlrNKCPt8cS-VWcMmhzAAAA6U"]
[Sun Aug 30 03:11:24.962989 2026] [security2:error] [pid 519566:tid 519778] [client 20.104.18.15:22462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/dapa.php"] [unique_id "apPlrNKCPt8cS-VWcMmh0QAAA_U"]
[Sun Aug 30 03:11:24.967573 2026] [authz_core:error] [pid 519566:tid 519714] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Ftls%2Fsections
[Sun Aug 30 03:11:24.967914 2026] [authz_core:error] [pid 519566:tid 519714] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Ftls%2Fsections
[Sun Aug 30 03:11:24.976821 2026] [security2:error] [pid 519566:tid 519730] [client 20.104.104.62:15334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/file.php"] [unique_id "apPlrNKCPt8cS-VWcMmh1wAAA8U"]
[Sun Aug 30 03:11:24.989125 2026] [core:alert] [pid 519566:tid 519736] [client 160.113.20.45:4649] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:11:24.996777 2026] [security2:error] [pid 519566:tid 519822] [client 158.23.184.117:1099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/item.php"] [unique_id "apPlrNKCPt8cS-VWcMmh5AAABCE"]
[Sun Aug 30 03:11:25.002124 2026] [security2:error] [pid 519566:tid 519750] [client 158.23.147.79:39310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-includes/assets/index.php"] [unique_id "apPlrdKCPt8cS-VWcMmh5QAAA9k"]
[Sun Aug 30 03:11:25.006075 2026] [security2:error] [pid 519566:tid 519812] [client 20.104.104.62:41652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/wp-the.php"] [unique_id "apPlrdKCPt8cS-VWcMmh6AAABBc"]
[Sun Aug 30 03:11:25.046391 2026] [security2:error] [pid 519566:tid 519701] [client 20.104.50.220:51396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/file.php"] [unique_id "apPlrdKCPt8cS-VWcMmh-wAAA6g"]
[Sun Aug 30 03:11:25.080492 2026] [security2:error] [pid 519566:tid 519729] [client 4.205.62.107:16352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/ebahvhhh.php"] [unique_id "apPlrdKCPt8cS-VWcMmiBAAAA8Q"]
[Sun Aug 30 03:11:25.083900 2026] [authz_core:error] [pid 519566:tid 519708] [client 66.249.66.34:36167] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:25.084168 2026] [authz_core:error] [pid 519566:tid 519708] [client 66.249.66.34:36167] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:25.105003 2026] [security2:error] [pid 519566:tid 519730] [client 20.104.104.62:14337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/ca.php"] [unique_id "apPlrdKCPt8cS-VWcMmiEQAAA8U"]
[Sun Aug 30 03:11:25.112225 2026] [security2:error] [pid 519566:tid 519736] [client 158.23.147.79:58378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-login.php"] [unique_id "apPlrdKCPt8cS-VWcMmiFAAAA8s"]
[Sun Aug 30 03:11:25.112494 2026] [security2:error] [pid 519566:tid 519726] [client 20.104.18.15:16965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/info.php/new.php"] [unique_id "apPlrdKCPt8cS-VWcMmiFQAAA8E"]
[Sun Aug 30 03:11:25.133706 2026] [security2:error] [pid 519566:tid 519754] [client 158.23.184.117:1358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/wp-admin/controller.php"] [unique_id "apPlrdKCPt8cS-VWcMmiGwAAA90"]
[Sun Aug 30 03:11:25.141405 2026] [security2:error] [pid 519566:tid 519774] [client 20.104.104.62:46011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/wt.php"] [unique_id "apPlrdKCPt8cS-VWcMmiIAAAA_E"]
[Sun Aug 30 03:11:25.149768 2026] [security2:error] [pid 519566:tid 519720] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/database/.env"] [unique_id "apPlrdKCPt8cS-VWcMmiIQAAA7s"]
[Sun Aug 30 03:11:25.164155 2026] [autoindex:error] [pid 519566:tid 519768] [client 20.196.209.81:17602] AH01276: Cannot serve directory /home3/shutters/advoutpost.com/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:11:25.182528 2026] [security2:error] [pid 519566:tid 519734] [client 20.48.250.41:49304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/mar.php"] [unique_id "apPlrdKCPt8cS-VWcMmiLAAAA8k"]
[Sun Aug 30 03:11:25.200436 2026] [authz_core:error] [pid 519566:tid 519733] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:25.200711 2026] [authz_core:error] [pid 519566:tid 519733] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:25.210356 2026] [security2:error] [pid 519566:tid 519819] [client 20.48.251.3:59506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/koiy.php"] [unique_id "apPlrdKCPt8cS-VWcMmiOQAABB4"]
[Sun Aug 30 03:11:25.231548 2026] [security2:error] [pid 519566:tid 519778] [client 158.23.147.79:43587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/lock.php"] [unique_id "apPlrdKCPt8cS-VWcMmiPQAAA_U"]
[Sun Aug 30 03:11:25.243943 2026] [core:alert] [pid 519566:tid 519696] [client 95.212.102.57:54084] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:11:25.273758 2026] [security2:error] [pid 519566:tid 519761] [client 20.104.104.62:14350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/pb.php"] [unique_id "apPlrdKCPt8cS-VWcMmiTgAAA-Q"]
[Sun Aug 30 03:11:25.276425 2026] [security2:error] [pid 519566:tid 519705] [client 20.104.104.62:22656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/im.php"] [unique_id "apPlrdKCPt8cS-VWcMmiTwAAA6w"]
[Sun Aug 30 03:11:25.278505 2026] [lsapi:error] [pid 519566:tid 519587] [remote 109.201.55.2:54527] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://gracelikestogarden.com/
[Sun Aug 30 03:11:25.278639 2026] [lsapi:error] [pid 519566:tid 519587] [remote 109.201.55.2:54527] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://gracelikestogarden.com/
[Sun Aug 30 03:11:25.280160 2026] [lsapi:error] [pid 519566:tid 519587] [remote 109.201.55.2:54527] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n, referer: https://gracelikestogarden.com/
[Sun Aug 30 03:11:25.295821 2026] [security2:error] [pid 519566:tid 519714] [client 20.196.209.81:17602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/upgrade/about.php"] [unique_id "apPlrdKCPt8cS-VWcMmiUwAAA7U"]
[Sun Aug 30 03:11:25.313456 2026] [security2:error] [pid 519566:tid 519775] [client 20.104.49.130:48361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/dehnl.php"] [unique_id "apPlrdKCPt8cS-VWcMmiWQAAA_I"]
[Sun Aug 30 03:11:25.314126 2026] [security2:error] [pid 519566:tid 519720] [client 68.155.159.216:63280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apPlrdKCPt8cS-VWcMmiWgAAA7s"]
[Sun Aug 30 03:11:25.324805 2026] [security2:error] [pid 519566:tid 519707] [client 20.48.250.41:49297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/ccu.php"] [unique_id "apPlrdKCPt8cS-VWcMmiWwAAA64"]
[Sun Aug 30 03:11:25.327306 2026] [security2:error] [pid 519566:tid 519712] [client 40.83.93.50:3956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/adminfuns.php"] [unique_id "apPlrdKCPt8cS-VWcMmiXgAAA7M"]
[Sun Aug 30 03:11:25.330566 2026] [security2:error] [pid 519566:tid 519768] [client 158.23.184.117:1107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/wp-configs.php"] [unique_id "apPlrdKCPt8cS-VWcMmiYAAAA-s"]
[Sun Aug 30 03:11:25.337977 2026] [authz_core:error] [pid 519566:tid 519734] [client 216.73.216.128:62316] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:25.338253 2026] [authz_core:error] [pid 519566:tid 519734] [client 216.73.216.128:62316] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:25.353391 2026] [security2:error] [pid 519566:tid 519819] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/storage/.env"] [unique_id "apPlrdKCPt8cS-VWcMmiawAABB4"]
[Sun Aug 30 03:11:25.360455 2026] [security2:error] [pid 519566:tid 519797] [client 20.104.50.220:24840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/asdf.php"] [unique_id "apPlrdKCPt8cS-VWcMmibAAABAg"]
[Sun Aug 30 03:11:25.364234 2026] [security2:error] [pid 519566:tid 519809] [client 4.205.62.107:36060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPlrdKCPt8cS-VWcMmibgAABBQ"]
[Sun Aug 30 03:11:25.368749 2026] [authz_core:error] [pid 519566:tid 519704] [client 66.249.66.76:35678] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:25.369082 2026] [authz_core:error] [pid 519566:tid 519704] [client 66.249.66.76:35678] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:25.401109 2026] [security2:error] [pid 519566:tid 519730] [client 20.104.104.62:15312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/pk.php"] [unique_id "apPlrdKCPt8cS-VWcMmifAAAA8U"]
[Sun Aug 30 03:11:25.409386 2026] [security2:error] [pid 519566:tid 519759] [client 158.23.147.79:39138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/index/function.php"] [unique_id "apPlrdKCPt8cS-VWcMmifQAAA-I"]
[Sun Aug 30 03:11:25.417965 2026] [security2:error] [pid 519566:tid 519772] [client 20.104.104.62:45974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/file.php"] [unique_id "apPlrdKCPt8cS-VWcMmifwAAA-8"]
[Sun Aug 30 03:11:25.444611 2026] [security2:error] [pid 519566:tid 519807] [client 4.205.62.107:25912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/app.default.php"] [unique_id "apPlrdKCPt8cS-VWcMmilQAABBI"]
[Sun Aug 30 03:11:25.469911 2026] [security2:error] [pid 519566:tid 519785] [client 158.23.184.117:1374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/wp-admin/user/credits.php"] [unique_id "apPlrdKCPt8cS-VWcMminQAAA_w"]
[Sun Aug 30 03:11:25.473095 2026] [authz_core:error] [pid 519566:tid 519783] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Ftls%2Fholders
[Sun Aug 30 03:11:25.473428 2026] [authz_core:error] [pid 519566:tid 519783] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Ftls%2Fholders
[Sun Aug 30 03:11:25.477030 2026] [security2:error] [pid 519566:tid 519800] [client 20.48.250.41:49364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/ak.php"] [unique_id "apPlrdKCPt8cS-VWcMmioAAABAs"]
[Sun Aug 30 03:11:25.479975 2026] [security2:error] [pid 519566:tid 519727] [client 20.104.49.130:57665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/ws58.php"] [unique_id "apPlrdKCPt8cS-VWcMmioQAAA8I"]
[Sun Aug 30 03:11:25.525118 2026] [authz_core:error] [pid 519566:tid 519811] [client 216.73.216.128:15237] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:25.525538 2026] [authz_core:error] [pid 519566:tid 519811] [client 216.73.216.128:15237] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:25.526007 2026] [security2:error] [pid 519566:tid 519728] [client 20.197.61.180:18067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/min.php"] [unique_id "apPlrdKCPt8cS-VWcMmisAAAA8M"]
[Sun Aug 30 03:11:25.553749 2026] [security2:error] [pid 519566:tid 519714] [client 20.104.104.62:45971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/ca.php"] [unique_id "apPlrdKCPt8cS-VWcMmiuwAAA7U"]
[Sun Aug 30 03:11:25.553763 2026] [security2:error] [pid 519566:tid 519724] [client 20.104.104.62:15258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/ft.php"] [unique_id "apPlrdKCPt8cS-VWcMmivAAAA78"]
[Sun Aug 30 03:11:25.554625 2026] [security2:error] [pid 519566:tid 519801] [client 20.151.200.44:40853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPlrdKCPt8cS-VWcMmivgAABAw"]
[Sun Aug 30 03:11:25.555123 2026] [security2:error] [pid 519566:tid 519720] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/var/www/.env"] [unique_id "apPlrdKCPt8cS-VWcMmivwAAA7s"]
[Sun Aug 30 03:11:25.563499 2026] [security2:error] [pid 519566:tid 519754] [client 20.104.50.220:16967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/ha.php"] [unique_id "apPlrdKCPt8cS-VWcMmiwgAAA90"]
[Sun Aug 30 03:11:25.564797 2026] [security2:error] [pid 519566:tid 519750] [client 20.104.18.15:51149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/adminfuns.php"] [unique_id "apPlrdKCPt8cS-VWcMmiwwAAA9k"]
[Sun Aug 30 03:11:25.606283 2026] [security2:error] [pid 519566:tid 519768] [client 158.23.147.79:39125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/.well-known/content.php"] [unique_id "apPlrdKCPt8cS-VWcMmizAAAA-s"]
[Sun Aug 30 03:11:25.610518 2026] [security2:error] [pid 519566:tid 519795] [client 158.23.184.117:1090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "apPlrdKCPt8cS-VWcMmizgAABAY"]
[Sun Aug 30 03:11:25.615882 2026] [authz_core:error] [pid 519566:tid 519702] [client 216.73.216.128:62316] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:25.616167 2026] [authz_core:error] [pid 519566:tid 519702] [client 216.73.216.128:62316] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:25.629381 2026] [security2:error] [pid 519566:tid 519800] [client 20.48.250.41:49337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/lib.php"] [unique_id "apPlrdKCPt8cS-VWcMmi0gAABAs"]
[Sun Aug 30 03:11:25.629439 2026] [security2:error] [pid 519566:tid 519758] [client 20.104.49.130:43274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/well.php"] [unique_id "apPlrdKCPt8cS-VWcMmi0wAAA-E"]
[Sun Aug 30 03:11:25.630655 2026] [authz_core:error] [pid 519566:tid 519770] [client 66.249.66.66:56466] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:25.630932 2026] [authz_core:error] [pid 519566:tid 519770] [client 66.249.66.66:56466] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:25.658057 2026] [authz_core:error] [pid 519566:tid 519717] [client 66.249.66.66:38819] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:25.658551 2026] [authz_core:error] [pid 519566:tid 519717] [client 66.249.66.66:38819] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:25.686407 2026] [security2:error] [pid 519566:tid 519730] [client 20.104.104.62:15308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/wp-ver.php"] [unique_id "apPlrdKCPt8cS-VWcMmi5wAAA8U"]
[Sun Aug 30 03:11:25.687279 2026] [security2:error] [pid 519566:tid 519711] [client 20.104.104.62:22681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/pb.php"] [unique_id "apPlrdKCPt8cS-VWcMmi6QAAA7I"]
[Sun Aug 30 03:11:25.688144 2026] [security2:error] [pid 519566:tid 519822] [client 20.196.209.81:21758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advoutpost.mikeshell.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "apPlrdKCPt8cS-VWcMmi6wAABCE"]
[Sun Aug 30 03:11:25.697094 2026] [authz_core:error] [pid 519566:tid 519798] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:25.697367 2026] [authz_core:error] [pid 519566:tid 519798] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:25.706835 2026] [security2:error] [pid 519566:tid 519750] [client 20.104.50.220:28720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/gel4y.php"] [unique_id "apPlrdKCPt8cS-VWcMmi-gAAA9k"]
[Sun Aug 30 03:11:25.746395 2026] [security2:error] [pid 519566:tid 519718] [client 20.48.251.3:54829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/erty.php"] [unique_id "apPlrdKCPt8cS-VWcMmjDAAAA7k"]
[Sun Aug 30 03:11:25.750344 2026] [security2:error] [pid 519566:tid 519818] [client 20.104.50.220:33154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/alfa1.php"] [unique_id "apPlrdKCPt8cS-VWcMmjDwAABB0"]
[Sun Aug 30 03:11:25.750526 2026] [security2:error] [pid 519566:tid 519725] [client 158.23.184.117:1559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/.well-known/about/function.php"] [unique_id "apPlrdKCPt8cS-VWcMmjEAAAA8A"]
[Sun Aug 30 03:11:25.757459 2026] [security2:error] [pid 519566:tid 519802] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/var/www/html/.env"] [unique_id "apPlrdKCPt8cS-VWcMmjEgAABA0"]
[Sun Aug 30 03:11:25.795231 2026] [authz_core:error] [pid 519566:tid 519794] [client 66.249.66.201:63858] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:25.795664 2026] [authz_core:error] [pid 519566:tid 519794] [client 66.249.66.201:63858] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:25.819409 2026] [security2:error] [pid 519566:tid 519803] [client 20.104.104.62:15324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/ah24.php"] [unique_id "apPlrdKCPt8cS-VWcMmjLwAABA4"]
[Sun Aug 30 03:11:25.821208 2026] [security2:error] [pid 519566:tid 519810] [client 20.48.250.41:49307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/wp-style.php"] [unique_id "apPlrdKCPt8cS-VWcMmjMAAABBU"]
[Sun Aug 30 03:11:25.821502 2026] [security2:error] [pid 519566:tid 519811] [client 4.205.62.107:16820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/koiy.php"] [unique_id "apPlrdKCPt8cS-VWcMmjMQAABBY"]
[Sun Aug 30 03:11:25.825887 2026] [security2:error] [pid 519566:tid 519758] [client 20.104.50.220:51532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-includes/mailer.php"] [unique_id "apPlrdKCPt8cS-VWcMmjMwAAA-E"]
[Sun Aug 30 03:11:25.827665 2026] [security2:error] [pid 519566:tid 519800] [client 158.23.147.79:43358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/cong.php"] [unique_id "apPlrdKCPt8cS-VWcMmjNAAABAs"]
[Sun Aug 30 03:11:25.830509 2026] [security2:error] [pid 519566:tid 519727] [client 20.104.104.62:22709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/pk.php"] [unique_id "apPlrdKCPt8cS-VWcMmjNgAAA8I"]
[Sun Aug 30 03:11:25.835369 2026] [security2:error] [pid 519566:tid 519698] [client 40.83.93.50:3910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/rip.php"] [unique_id "apPlrdKCPt8cS-VWcMmjOAAAA6U"]
[Sun Aug 30 03:11:25.835737 2026] [security2:error] [pid 519566:tid 519753] [client 20.104.50.220:64451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/gg.php"] [unique_id "apPlrdKCPt8cS-VWcMmjOgAAA9w"]
[Sun Aug 30 03:11:25.854973 2026] [security2:error] [pid 519566:tid 519741] [client 20.104.50.220:5613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-activate.php"] [unique_id "apPlrdKCPt8cS-VWcMmjQwAAA9A"]
[Sun Aug 30 03:11:25.889428 2026] [security2:error] [pid 519566:tid 519775] [client 158.23.184.117:1136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPlrdKCPt8cS-VWcMmjTwAAA_I"]
[Sun Aug 30 03:11:25.889470 2026] [security2:error] [pid 519566:tid 519814] [client 20.104.50.220:62009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/zk.php"] [unique_id "apPlrdKCPt8cS-VWcMmjUAAABBk"]
[Sun Aug 30 03:11:25.906482 2026] [security2:error] [pid 519566:tid 519732] [client 4.205.62.107:52803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/wsws.php"] [unique_id "apPlrdKCPt8cS-VWcMmjVAAAA8c"]
[Sun Aug 30 03:11:25.920671 2026] [security2:error] [pid 519566:tid 519806] [client 68.155.159.216:52581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/mah.php"] [unique_id "apPlrdKCPt8cS-VWcMmjXwAABBE"]
[Sun Aug 30 03:11:25.924690 2026] [security2:error] [pid 519566:tid 519700] [client 20.48.251.3:59315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/otuz1.php"] [unique_id "apPlrdKCPt8cS-VWcMmjYgAAA6c"]
[Sun Aug 30 03:11:25.949531 2026] [security2:error] [pid 519566:tid 519725] [client 20.104.104.62:15342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPlrdKCPt8cS-VWcMmjbwAAA8A"]
[Sun Aug 30 03:11:25.957001 2026] [security2:error] [pid 519566:tid 519735] [client 20.48.250.41:49383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/browse.php"] [unique_id "apPlrdKCPt8cS-VWcMmjcgAAA8o"]
[Sun Aug 30 03:11:25.961745 2026] [security2:error] [pid 519566:tid 519818] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/current/.env"] [unique_id "apPlrdKCPt8cS-VWcMmjdAAABB0"]
[Sun Aug 30 03:11:25.979618 2026] [security2:error] [pid 519566:tid 519716] [client 20.48.251.3:36829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/bengi.php"] [unique_id "apPlrdKCPt8cS-VWcMmjfgAAA7c"]
[Sun Aug 30 03:11:25.980109 2026] [authz_core:error] [pid 519566:tid 519759] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:11:25.980398 2026] [authz_core:error] [pid 519566:tid 519759] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:11:25.984549 2026] [security2:error] [pid 519566:tid 519814] [client 20.104.104.62:41647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/ft.php"] [unique_id "apPlrdKCPt8cS-VWcMmjgQAABBk"]
[Sun Aug 30 03:11:25.995937 2026] [security2:error] [pid 519566:tid 519597] [remote 47.128.45.33:19572] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "acs-ent.com"] [uri "/equipment-dealer/"] [unique_id "apPlrdKCPt8cS-VWcMmjhgADxx4"]
[Sun Aug 30 03:11:26.021713 2026] [security2:error] [pid 519566:tid 519806] [client 20.104.18.15:18203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/wnnjpsby.php"] [unique_id "apPlrtKCPt8cS-VWcMmjkgAABBE"]
[Sun Aug 30 03:11:26.029441 2026] [security2:error] [pid 519566:tid 519804] [client 158.23.184.117:1388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/gg.php"] [unique_id "apPlrtKCPt8cS-VWcMmjlwAABA8"]
[Sun Aug 30 03:11:26.043168 2026] [security2:error] [pid 519566:tid 519718] [client 20.104.18.15:31732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/blacks.php"] [unique_id "apPlrtKCPt8cS-VWcMmjoAAAA7k"]
[Sun Aug 30 03:11:26.063821 2026] [security2:error] [pid 519566:tid 519725] [client 158.23.147.79:58384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apPlrtKCPt8cS-VWcMmjpQAAA8A"]
[Sun Aug 30 03:11:26.075619 2026] [security2:error] [pid 519566:tid 519715] [client 20.104.104.62:14388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cue-magic.com"] [uri "/waf.php"] [unique_id "apPlrtKCPt8cS-VWcMmjpgAAA7Y"]
[Sun Aug 30 03:11:26.097524 2026] [security2:error] [pid 519566:tid 519696] [client 158.23.147.79:39117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-includes/js/index.php"] [unique_id "apPlrtKCPt8cS-VWcMmjsQAAA6M"]
[Sun Aug 30 03:11:26.113355 2026] [security2:error] [pid 519566:tid 519732] [client 20.104.18.15:22277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/wp-content/l.php"] [unique_id "apPlrtKCPt8cS-VWcMmjtQAAA8c"]
[Sun Aug 30 03:11:26.133258 2026] [security2:error] [pid 519566:tid 519708] [client 20.104.104.62:54988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/wp-ver.php"] [unique_id "apPlrtKCPt8cS-VWcMmjvQAAA68"]
[Sun Aug 30 03:11:26.143294 2026] [security2:error] [pid 519566:tid 519773] [client 20.104.49.130:53799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/82.php"] [unique_id "apPlrtKCPt8cS-VWcMmjwAAAA_A"]
[Sun Aug 30 03:11:26.158563 2026] [security2:error] [pid 519566:tid 519705] [client 20.48.250.41:49300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/zoo.php"] [unique_id "apPlrtKCPt8cS-VWcMmjwgAAA6w"]
[Sun Aug 30 03:11:26.164300 2026] [security2:error] [pid 519566:tid 519772] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/release/.env"] [unique_id "apPlrtKCPt8cS-VWcMmjwwAAA-8"]
[Sun Aug 30 03:11:26.167967 2026] [security2:error] [pid 519566:tid 519740] [client 158.23.184.117:1398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/wp-admin/includes/post.php"] [unique_id "apPlrtKCPt8cS-VWcMmjxgAAA88"]
[Sun Aug 30 03:11:26.174798 2026] [authz_core:error] [pid 519566:tid 519792] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:26.175067 2026] [authz_core:error] [pid 519566:tid 519792] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:26.185048 2026] [authz_core:error] [pid 519566:tid 519786] [client 66.249.66.64:53258] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:26.185320 2026] [authz_core:error] [pid 519566:tid 519786] [client 66.249.66.64:53258] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:26.185994 2026] [security2:error] [pid 519566:tid 519766] [client 20.104.50.220:63202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/cfile.php"] [unique_id "apPlrtKCPt8cS-VWcMmj0gAAA-k"]
[Sun Aug 30 03:11:26.187359 2026] [authz_core:error] [pid 519566:tid 519742] [client 216.73.216.128:61973] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:26.187856 2026] [authz_core:error] [pid 519566:tid 519742] [client 216.73.216.128:61973] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:26.216221 2026] [security2:error] [pid 519566:tid 519728] [client 20.197.61.180:3201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/module.php"] [unique_id "apPlrtKCPt8cS-VWcMmj4QAAA8M"]
[Sun Aug 30 03:11:26.217406 2026] [security2:error] [pid 519566:tid 519760] [client 4.205.62.107:15946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/asa.php"] [unique_id "apPlrtKCPt8cS-VWcMmj4wAAA-M"]
[Sun Aug 30 03:11:26.265673 2026] [security2:error] [pid 519566:tid 519722] [client 20.104.104.62:22690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/ah24.php"] [unique_id "apPlrtKCPt8cS-VWcMmj8QAAA70"]
[Sun Aug 30 03:11:26.288217 2026] [security2:error] [pid 519566:tid 519712] [client 20.48.250.41:49352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/elp.php"] [unique_id "apPlrtKCPt8cS-VWcMmj-AAAA7M"]
[Sun Aug 30 03:11:26.336730 2026] [security2:error] [pid 519566:tid 519751] [client 40.83.93.50:6387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/ws.php"] [unique_id "apPlrtKCPt8cS-VWcMmkBAAAA9o"]
[Sun Aug 30 03:11:26.348480 2026] [security2:error] [pid 519566:tid 519801] [client 20.48.251.3:52276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/queue.php"] [unique_id "apPlrtKCPt8cS-VWcMmkBwAABAw"]
[Sun Aug 30 03:11:26.365751 2026] [security2:error] [pid 519566:tid 519727] [client 158.23.184.117:1366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.pediatricplaytherapy.com"] [uri "/wp-act.php"] [unique_id "apPlrtKCPt8cS-VWcMmkCQAAA8I"]
[Sun Aug 30 03:11:26.366293 2026] [security2:error] [pid 519566:tid 519718] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/releases/.env"] [unique_id "apPlrtKCPt8cS-VWcMmkCgAAA7k"]
[Sun Aug 30 03:11:26.383945 2026] [authz_core:error] [pid 519566:tid 519740] [client 66.249.66.66:49784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:26.384394 2026] [authz_core:error] [pid 519566:tid 519740] [client 66.249.66.66:49784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:26.401057 2026] [authz_core:error] [pid 519566:tid 519756] [client 66.249.66.70:60564] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:26.401338 2026] [authz_core:error] [pid 519566:tid 519756] [client 66.249.66.70:60564] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:26.424440 2026] [security2:error] [pid 519566:tid 519818] [client 20.104.104.62:22670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/wp-admin/zwso.php"] [unique_id "apPlrtKCPt8cS-VWcMmkHAAABB0"]
[Sun Aug 30 03:11:26.432506 2026] [core:alert] [pid 519566:tid 519789] [client 102.64.162.12:52428] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:11:26.443735 2026] [authz_core:error] [pid 519566:tid 519815] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:11:26.444023 2026] [authz_core:error] [pid 519566:tid 519815] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:11:26.451569 2026] [security2:error] [pid 519566:tid 519734] [client 68.155.159.216:62610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apPlrtKCPt8cS-VWcMmkLwAAA8k"]
[Sun Aug 30 03:11:26.455719 2026] [security2:error] [pid 519566:tid 519720] [client 216.73.216.128:15237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/usage_202601.html"] [unique_id "apPlrtKCPt8cS-VWcMmkMwAAA7s"]
[Sun Aug 30 03:11:26.471810 2026] [security2:error] [pid 519566:tid 519772] [client 158.23.147.79:43064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-content/index.php"] [unique_id "apPlrtKCPt8cS-VWcMmkOwAAA-8"]
[Sun Aug 30 03:11:26.476954 2026] [security2:error] [pid 519566:tid 519807] [client 20.151.200.44:62961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/motu.php"] [unique_id "apPlrtKCPt8cS-VWcMmkPgAABBI"]
[Sun Aug 30 03:11:26.488777 2026] [security2:error] [pid 519566:tid 519758] [client 20.48.250.41:49367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/666.php"] [unique_id "apPlrtKCPt8cS-VWcMmkQgAAA-E"]
[Sun Aug 30 03:11:26.500948 2026] [security2:error] [pid 519566:tid 519805] [client 20.220.10.235:20476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlrtKCPt8cS-VWcMmkRAAABBA"]
[Sun Aug 30 03:11:26.529372 2026] [security2:error] [pid 519566:tid 519794] [client 20.104.50.220:24854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/red.php"] [unique_id "apPlrtKCPt8cS-VWcMmkVQAABAU"]
[Sun Aug 30 03:11:26.529715 2026] [security2:error] [pid 519566:tid 519753] [client 4.205.62.107:36732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/agg.php"] [unique_id "apPlrtKCPt8cS-VWcMmkVgAAA9w"]
[Sun Aug 30 03:11:26.550745 2026] [security2:error] [pid 519566:tid 519823] [client 20.104.49.130:36751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/df.php"] [unique_id "apPlrtKCPt8cS-VWcMmkXAAABCI"]
[Sun Aug 30 03:11:26.561386 2026] [security2:error] [pid 519566:tid 519732] [client 20.104.104.62:22669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.104.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thomas-joachim-richter.info"] [uri "/waf.php"] [unique_id "apPlrtKCPt8cS-VWcMmkYQAAA8c"]
[Sun Aug 30 03:11:26.568479 2026] [security2:error] [pid 519566:tid 519731] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/shared/.env"] [unique_id "apPlrtKCPt8cS-VWcMmkYgAAA8Y"]
[Sun Aug 30 03:11:26.634856 2026] [security2:error] [pid 519566:tid 519712] [client 20.220.10.235:20433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlrtKCPt8cS-VWcMmkcgAAA7M"]
[Sun Aug 30 03:11:26.650200 2026] [security2:error] [pid 519566:tid 519761] [client 20.48.250.41:49304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/knmt.php"] [unique_id "apPlrtKCPt8cS-VWcMmkdQAAA-Q"]
[Sun Aug 30 03:11:26.652368 2026] [security2:error] [pid 519566:tid 519772] [client 4.205.62.107:25519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/app_local.php"] [unique_id "apPlrtKCPt8cS-VWcMmkdgAAA-8"]
[Sun Aug 30 03:11:26.676912 2026] [authz_core:error] [pid 519566:tid 519786] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:26.677299 2026] [authz_core:error] [pid 519566:tid 519786] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:26.699473 2026] [security2:error] [pid 519566:tid 519714] [client 20.104.50.220:16716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/gg.php"] [unique_id "apPlrtKCPt8cS-VWcMmkiwAAA7U"]
[Sun Aug 30 03:11:26.722459 2026] [security2:error] [pid 519566:tid 519736] [client 20.104.18.15:51142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/classwithtostring.php"] [unique_id "apPlrtKCPt8cS-VWcMmklAAAA8s"]
[Sun Aug 30 03:11:26.723790 2026] [security2:error] [pid 519566:tid 519788] [client 158.23.147.79:43374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/about/function.php"] [unique_id "apPlrtKCPt8cS-VWcMmklwAAA_8"]
[Sun Aug 30 03:11:26.728461 2026] [authz_core:error] [pid 519566:tid 519822] [client 66.249.66.199:44284] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:26.728803 2026] [authz_core:error] [pid 519566:tid 519822] [client 66.249.66.199:44284] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:26.766182 2026] [security2:error] [pid 519566:tid 519772] [client 20.220.10.235:20464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/h02ugyh.php"] [unique_id "apPlrtKCPt8cS-VWcMmkrAAAA-8"]
[Sun Aug 30 03:11:26.772774 2026] [security2:error] [pid 519566:tid 519769] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/deploy/.env"] [unique_id "apPlrtKCPt8cS-VWcMmkrwAAA-w"]
[Sun Aug 30 03:11:26.810506 2026] [security2:error] [pid 519566:tid 519714] [client 20.48.250.41:49345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/sbhu.php"] [unique_id "apPlrtKCPt8cS-VWcMmkuwAAA7U"]
[Sun Aug 30 03:11:26.851858 2026] [security2:error] [pid 519566:tid 519705] [client 40.83.93.50:22092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/t.php"] [unique_id "apPlrtKCPt8cS-VWcMmkzwAAA6w"]
[Sun Aug 30 03:11:26.873226 2026] [security2:error] [pid 519566:tid 519744] [client 20.104.50.220:62800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/contacts.php"] [unique_id "apPlrtKCPt8cS-VWcMmk1QAAA9M"]
[Sun Aug 30 03:11:26.885746 2026] [security2:error] [pid 519566:tid 519749] [client 20.48.251.3:65502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/wp-config.backup.php"] [unique_id "apPlrtKCPt8cS-VWcMmk3QAAA9g"]
[Sun Aug 30 03:11:26.887113 2026] [security2:error] [pid 519566:tid 519748] [client 20.104.50.220:32852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/159.php"] [unique_id "apPlrtKCPt8cS-VWcMmk3gAAA9c"]
[Sun Aug 30 03:11:26.900724 2026] [security2:error] [pid 519566:tid 519759] [client 20.220.10.235:20437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/sf.php"] [unique_id "apPlrtKCPt8cS-VWcMmk5QAAA-I"]
[Sun Aug 30 03:11:26.904552 2026] [security2:error] [pid 519566:tid 519786] [client 158.23.147.79:39312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-includes/customize/index.php"] [unique_id "apPlrtKCPt8cS-VWcMmk6AAAA_0"]
[Sun Aug 30 03:11:26.908395 2026] [security2:error] [pid 519566:tid 519773] [client 20.104.49.130:48013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/sd.php"] [unique_id "apPlrtKCPt8cS-VWcMmk6gAAA_A"]
[Sun Aug 30 03:11:26.910284 2026] [security2:error] [pid 519566:tid 519718] [client 216.73.216.128:62316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/js/sorttable.js"] [unique_id "apPlrtKCPt8cS-VWcMmk7AAAA7k"]
[Sun Aug 30 03:11:26.912680 2026] [security2:error] [pid 519566:tid 519763] [client 20.197.61.180:3166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/ms-files.php"] [unique_id "apPlrtKCPt8cS-VWcMmk7gAAA-Y"]
[Sun Aug 30 03:11:26.947028 2026] [security2:error] [pid 519566:tid 519730] [client 4.205.62.107:17116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/queue.php"] [unique_id "apPlrtKCPt8cS-VWcMmk_gAAA8U"]
[Sun Aug 30 03:11:26.961887 2026] [security2:error] [pid 519566:tid 519736] [client 20.48.250.41:49291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/a332.php"] [unique_id "apPlrtKCPt8cS-VWcMmlAgAAA8s"]
[Sun Aug 30 03:11:26.971289 2026] [security2:error] [pid 519566:tid 519811] [client 20.104.50.220:29617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/gelis.php"] [unique_id "apPlrtKCPt8cS-VWcMmlBAAABBY"]
[Sun Aug 30 03:11:26.975199 2026] [security2:error] [pid 519566:tid 519818] [client 20.104.50.220:56717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/ym.php"] [unique_id "apPlrtKCPt8cS-VWcMmlCAAABB0"]
[Sun Aug 30 03:11:26.975729 2026] [security2:error] [pid 519566:tid 519722] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/build/.env"] [unique_id "apPlrtKCPt8cS-VWcMmlCQAAA70"]
[Sun Aug 30 03:11:27.000519 2026] [authz_core:error] [pid 519566:tid 519711] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:11:27.000807 2026] [authz_core:error] [pid 519566:tid 519711] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:11:27.008423 2026] [security2:error] [pid 519566:tid 519748] [client 20.104.50.220:5610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/xmrlpc.php"] [unique_id "apPlr9KCPt8cS-VWcMmlHAAAA9c"]
[Sun Aug 30 03:11:27.027302 2026] [security2:error] [pid 519566:tid 519762] [client 20.104.50.220:61648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/zone.php"] [unique_id "apPlr9KCPt8cS-VWcMmlJgAAA-U"]
[Sun Aug 30 03:11:27.037761 2026] [security2:error] [pid 519566:tid 519766] [client 20.220.10.235:20420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/4e.php"] [unique_id "apPlr9KCPt8cS-VWcMmlLAAAA-k"]
[Sun Aug 30 03:11:27.042209 2026] [security2:error] [pid 519566:tid 519741] [client 158.23.147.79:39298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-admin/index.php"] [unique_id "apPlr9KCPt8cS-VWcMmlLwAAA9A"]
[Sun Aug 30 03:11:27.062595 2026] [security2:error] [pid 519566:tid 519789] [client 20.48.251.3:59283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/update.php"] [unique_id "apPlr9KCPt8cS-VWcMmlNAAABAA"]
[Sun Aug 30 03:11:27.103115 2026] [security2:error] [pid 519566:tid 519728] [client 68.155.159.216:52571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-blog-header.php"] [unique_id "apPlr9KCPt8cS-VWcMmlPwAAA8M"]
[Sun Aug 30 03:11:27.107501 2026] [security2:error] [pid 519566:tid 519760] [client 20.48.250.41:49398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/ws66.php"] [unique_id "apPlr9KCPt8cS-VWcMmlQQAAA-M"]
[Sun Aug 30 03:11:27.129033 2026] [security2:error] [pid 519566:tid 519797] [client 20.48.251.3:36913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/i.php"] [unique_id "apPlr9KCPt8cS-VWcMmlSwAABAg"]
[Sun Aug 30 03:11:27.134029 2026] [security2:error] [pid 519566:tid 519748] [client 4.205.62.107:52891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/localconf.php"] [unique_id "apPlr9KCPt8cS-VWcMmlTwAAA9c"]
[Sun Aug 30 03:11:27.142351 2026] [security2:error] [pid 519566:tid 519696] [client 158.23.147.79:39303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-content/themes/index.php"] [unique_id "apPlr9KCPt8cS-VWcMmlUgAAA6M"]
[Sun Aug 30 03:11:27.160304 2026] [security2:error] [pid 519566:tid 519773] [client 20.104.18.15:18374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/gigi.php"] [unique_id "apPlr9KCPt8cS-VWcMmlVQAAA_A"]
[Sun Aug 30 03:11:27.178019 2026] [security2:error] [pid 519566:tid 519718] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/dist/.env"] [unique_id "apPlr9KCPt8cS-VWcMmlXQAAA7k"]
[Sun Aug 30 03:11:27.184070 2026] [security2:error] [pid 519566:tid 519703] [client 20.104.18.15:31626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp.php"] [unique_id "apPlr9KCPt8cS-VWcMmlXwAAA6o"]
[Sun Aug 30 03:11:27.185829 2026] [security2:error] [pid 519566:tid 519726] [client 20.220.10.235:20382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/ssss.php"] [unique_id "apPlr9KCPt8cS-VWcMmlYAAAA8E"]
[Sun Aug 30 03:11:27.202027 2026] [authz_core:error] [pid 519566:tid 519790] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:27.202303 2026] [authz_core:error] [pid 519566:tid 519790] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:27.204598 2026] [authz_core:error] [pid 519566:tid 519816] [client 66.249.66.67:65009] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:27.205080 2026] [authz_core:error] [pid 519566:tid 519816] [client 66.249.66.67:65009] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:27.242497 2026] [authz_core:error] [pid 519566:tid 519795] [client 66.249.66.74:54976] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:27.242792 2026] [authz_core:error] [pid 519566:tid 519795] [client 66.249.66.74:54976] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:27.277522 2026] [security2:error] [pid 519566:tid 519774] [client 20.48.250.41:49403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/ws68.php"] [unique_id "apPlr9KCPt8cS-VWcMmlgAAAA_E"]
[Sun Aug 30 03:11:27.284097 2026] [security2:error] [pid 519566:tid 519704] [client 20.104.18.15:22517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/wp-admin/w.php"] [unique_id "apPlr9KCPt8cS-VWcMmlgQAAA6s"]
[Sun Aug 30 03:11:27.287385 2026] [security2:error] [pid 519566:tid 519697] [client 158.23.147.79:39108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/about.php"] [unique_id "apPlr9KCPt8cS-VWcMmlhAAAA6Q"]
[Sun Aug 30 03:11:27.293041 2026] [authz_core:error] [pid 519566:tid 519749] [client 216.73.216.128:45868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:27.293324 2026] [authz_core:error] [pid 519566:tid 519749] [client 216.73.216.128:45868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:27.316606 2026] [security2:error] [pid 519566:tid 519773] [client 20.220.10.235:20472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/zoz.php"] [unique_id "apPlr9KCPt8cS-VWcMmljQAAA_A"]
[Sun Aug 30 03:11:27.322178 2026] [security2:error] [pid 519566:tid 519711] [client 20.104.50.220:31526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/class-wp.php"] [unique_id "apPlr9KCPt8cS-VWcMmljwAAA7I"]
[Sun Aug 30 03:11:27.328795 2026] [security2:error] [pid 519566:tid 519762] [client 40.83.93.50:7064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/fw.php"] [unique_id "apPlr9KCPt8cS-VWcMmlkQAAA-U"]
[Sun Aug 30 03:11:27.358197 2026] [security2:error] [pid 519566:tid 519715] [client 4.205.62.107:15952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/radio.php"] [unique_id "apPlr9KCPt8cS-VWcMmlnQAAA7Y"]
[Sun Aug 30 03:11:27.358777 2026] [security2:error] [pid 519566:tid 519741] [client 20.151.200.44:63018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/wefile.php"] [unique_id "apPlr9KCPt8cS-VWcMmlngAAA9A"]
[Sun Aug 30 03:11:27.381901 2026] [security2:error] [pid 519566:tid 519802] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/public_html/.env"] [unique_id "apPlr9KCPt8cS-VWcMmlpQAABA0"]
[Sun Aug 30 03:11:27.442005 2026] [security2:error] [pid 519566:tid 519733] [client 158.23.147.79:43039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apPlr9KCPt8cS-VWcMmluAAAA8g"]
[Sun Aug 30 03:11:27.443468 2026] [security2:error] [pid 519566:tid 519772] [client 20.220.10.235:20357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/kcs.php"] [unique_id "apPlr9KCPt8cS-VWcMmlugAAA-8"]
[Sun Aug 30 03:11:27.458093 2026] [security2:error] [pid 519566:tid 519752] [client 20.48.250.41:49298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/users.php"] [unique_id "apPlr9KCPt8cS-VWcMmlwgAAA9s"]
[Sun Aug 30 03:11:27.474587 2026] [authz_core:error] [pid 519566:tid 519786] [client 216.73.216.128:45868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:27.474923 2026] [authz_core:error] [pid 519566:tid 519786] [client 216.73.216.128:45868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:27.480026 2026] [authz_core:error] [pid 519566:tid 519798] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:11:27.480324 2026] [authz_core:error] [pid 519566:tid 519798] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:11:27.516253 2026] [authz_core:error] [pid 519566:tid 519762] [client 66.249.66.192:53946] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:27.516527 2026] [authz_core:error] [pid 519566:tid 519762] [client 66.249.66.192:53946] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:27.526904 2026] [security2:error] [pid 519566:tid 519800] [client 20.104.18.15:16901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/w.php"] [unique_id "apPlr9KCPt8cS-VWcMml3QAABAs"]
[Sun Aug 30 03:11:27.576417 2026] [security2:error] [pid 519566:tid 519712] [client 20.220.10.235:20441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/tajj.php"] [unique_id "apPlr9KCPt8cS-VWcMml8AAAA7M"]
[Sun Aug 30 03:11:27.582263 2026] [security2:error] [pid 519566:tid 519733] [client 158.23.147.79:39144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/themes.php"] [unique_id "apPlr9KCPt8cS-VWcMml8gAAA8g"]
[Sun Aug 30 03:11:27.584022 2026] [security2:error] [pid 519566:tid 519772] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/htdocs/.env"] [unique_id "apPlr9KCPt8cS-VWcMml8wAAA-8"]
[Sun Aug 30 03:11:27.585329 2026] [security2:error] [pid 519566:tid 519819] [client 20.48.251.3:52274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/doc.php"] [unique_id "apPlr9KCPt8cS-VWcMml9AAABB4"]
[Sun Aug 30 03:11:27.593992 2026] [authz_core:error] [pid 519566:tid 519722] [client 66.249.66.69:35636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:27.594308 2026] [authz_core:error] [pid 519566:tid 519722] [client 66.249.66.69:35636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:27.627464 2026] [security2:error] [pid 519566:tid 519769] [client 20.197.61.180:12254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/news-portal/error.php"] [unique_id "apPlr9KCPt8cS-VWcMml_QAAA-w"]
[Sun Aug 30 03:11:27.639280 2026] [security2:error] [pid 519566:tid 519812] [client 20.48.250.41:49397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/bzjdlofz.php"] [unique_id "apPlr9KCPt8cS-VWcMml_wAABBc"]
[Sun Aug 30 03:11:27.674097 2026] [security2:error] [pid 519566:tid 519721] [client 68.155.159.216:57034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apPlr9KCPt8cS-VWcMmmCAAAA7w"]
[Sun Aug 30 03:11:27.687545 2026] [authz_core:error] [pid 519566:tid 519727] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:27.687915 2026] [authz_core:error] [pid 519566:tid 519727] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:27.694426 2026] [authz_core:error] [pid 519566:tid 519758] [client 66.249.66.66:38819] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:27.694698 2026] [authz_core:error] [pid 519566:tid 519758] [client 66.249.66.66:38819] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:27.695900 2026] [security2:error] [pid 519566:tid 519746] [client 46.36.217.244:55858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.217.36.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "garypia.co"] [uri "/wp-login.php"] [unique_id "apPlr9KCPt8cS-VWcMmmDQAAA9U"]
[Sun Aug 30 03:11:27.705013 2026] [security2:error] [pid 519566:tid 519738] [client 20.220.10.235:20355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/bge.php"] [unique_id "apPlr9KCPt8cS-VWcMmmHwAAA80"]
[Sun Aug 30 03:11:27.707423 2026] [security2:error] [pid 519566:tid 519782] [client 158.23.147.79:43335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-mail.php"] [unique_id "apPlr9KCPt8cS-VWcMmmIwAAA_k"]
[Sun Aug 30 03:11:27.735940 2026] [security2:error] [pid 519566:tid 519770] [client 4.205.62.107:36603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/requirements.php"] [unique_id "apPlr9KCPt8cS-VWcMmmLwAAA-0"]
[Sun Aug 30 03:11:27.751626 2026] [authz_core:error] [pid 519566:tid 519777] [client 216.73.216.128:61973] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:27.752068 2026] [authz_core:error] [pid 519566:tid 519777] [client 216.73.216.128:61973] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:27.784169 2026] [security2:error] [pid 519566:tid 519717] [client 4.205.62.107:25478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/ws62.php"] [unique_id "apPlr9KCPt8cS-VWcMmmQwAAA7g"]
[Sun Aug 30 03:11:27.784479 2026] [security2:error] [pid 519566:tid 519740] [client 20.104.50.220:24838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "apPlr9KCPt8cS-VWcMmmRAAAA88"]
[Sun Aug 30 03:11:27.785487 2026] [security2:error] [pid 519566:tid 519759] [client 20.48.250.41:49293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/selesai.php"] [unique_id "apPlr9KCPt8cS-VWcMmmSAAAA-I"]
[Sun Aug 30 03:11:27.785593 2026] [security2:error] [pid 519566:tid 519761] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/www/.env"] [unique_id "apPlr9KCPt8cS-VWcMmmRwAAA-Q"]
[Sun Aug 30 03:11:27.833560 2026] [security2:error] [pid 519566:tid 519776] [client 20.220.10.235:20465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/ssh3ll.php"] [unique_id "apPlr9KCPt8cS-VWcMmmVQAAA_M"]
[Sun Aug 30 03:11:27.837357 2026] [security2:error] [pid 519566:tid 519734] [client 20.104.50.220:17021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/we2.php"] [unique_id "apPlr9KCPt8cS-VWcMmmWQAAA8k"]
[Sun Aug 30 03:11:27.839936 2026] [security2:error] [pid 519566:tid 519808] [client 40.83.93.50:3934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/test.php"] [unique_id "apPlr9KCPt8cS-VWcMmmWwAABBM"]
[Sun Aug 30 03:11:27.848080 2026] [security2:error] [pid 519566:tid 519725] [client 20.151.200.44:65458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/wt.php"] [unique_id "apPlr9KCPt8cS-VWcMmmXwAAA8A"]
[Sun Aug 30 03:11:27.874702 2026] [security2:error] [pid 519566:tid 519711] [client 20.104.18.15:51193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPlr9KCPt8cS-VWcMmmbAAAA7I"]
[Sun Aug 30 03:11:27.889937 2026] [security2:error] [pid 519566:tid 519720] [client 158.23.147.79:39149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/cgi-bin/index.php"] [unique_id "apPlr9KCPt8cS-VWcMmmcwAAA7s"]
[Sun Aug 30 03:11:27.919708 2026] [authz_core:error] [pid 519566:tid 519781] [client 66.249.66.65:63931] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:27.919980 2026] [authz_core:error] [pid 519566:tid 519781] [client 66.249.66.65:63931] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:27.934495 2026] [security2:error] [pid 519566:tid 519789] [client 216.73.216.128:61973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_config_quote_replace_string"] [unique_id "apPlr9KCPt8cS-VWcMmmggAABAA"]
[Sun Aug 30 03:11:27.936887 2026] [security2:error] [pid 519566:tid 519716] [client 20.48.250.41:49281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/shlo.php"] [unique_id "apPlr9KCPt8cS-VWcMmmhgAAA7c"]
[Sun Aug 30 03:11:27.952673 2026] [authz_core:error] [pid 519566:tid 519778] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:11:27.952966 2026] [authz_core:error] [pid 519566:tid 519778] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:11:27.952960 2026] [security2:error] [pid 519566:tid 519619] [remote 191.101.44.2:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.44.101.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ibrgroup.in"] [uri "/wp-login.php"] [unique_id "apPlr9KCPt8cS-VWcMmmiwAD9jQ"]
[Sun Aug 30 03:11:27.960415 2026] [security2:error] [pid 519566:tid 519823] [client 20.220.10.235:20427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/motu.php"] [unique_id "apPlr9KCPt8cS-VWcMmmkgAABCI"]
[Sun Aug 30 03:11:27.980771 2026] [authz_core:error] [pid 519566:tid 519696] [client 66.249.66.72:37877] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:27.981062 2026] [authz_core:error] [pid 519566:tid 519696] [client 66.249.66.72:37877] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:27.988093 2026] [security2:error] [pid 519566:tid 519782] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/html/.env"] [unique_id "apPlr9KCPt8cS-VWcMmmoAAAA_k"]
[Sun Aug 30 03:11:28.015328 2026] [security2:error] [pid 519566:tid 519712] [client 20.104.49.130:60119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/Jcrop.php"] [unique_id "apPlsNKCPt8cS-VWcMmmrwAAA7M"]
[Sun Aug 30 03:11:28.023806 2026] [security2:error] [pid 519566:tid 519702] [client 20.48.251.3:46240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/edit.php"] [unique_id "apPlsNKCPt8cS-VWcMmmsgAAA6k"]
[Sun Aug 30 03:11:28.025808 2026] [security2:error] [pid 519566:tid 519721] [client 20.104.50.220:32895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/tesla1.php"] [unique_id "apPlsNKCPt8cS-VWcMmmtwAAA7w"]
[Sun Aug 30 03:11:28.030310 2026] [security2:error] [pid 519566:tid 519789] [client 20.104.50.220:62801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/yo.php"] [unique_id "apPlsNKCPt8cS-VWcMmmuwAABAA"]
[Sun Aug 30 03:11:28.044267 2026] [security2:error] [pid 519566:tid 519817] [client 158.23.147.79:43622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPlsNKCPt8cS-VWcMmmwQAABBw"]
[Sun Aug 30 03:11:28.078661 2026] [security2:error] [pid 519566:tid 519756] [client 20.151.200.44:40852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drmonicaguzman.com"] [uri "/waf.php"] [unique_id "apPlsNKCPt8cS-VWcMmmxAAAA98"]
[Sun Aug 30 03:11:28.089631 2026] [security2:error] [pid 519566:tid 519760] [client 20.220.10.235:20438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/wefile.php"] [unique_id "apPlsNKCPt8cS-VWcMmmyAAAA-M"]
[Sun Aug 30 03:11:28.110268 2026] [security2:error] [pid 519566:tid 519792] [client 20.104.50.220:29178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/FierzaXploit.php"] [unique_id "apPlsNKCPt8cS-VWcMmm1AAABAM"]
[Sun Aug 30 03:11:28.111825 2026] [security2:error] [pid 519566:tid 519711] [client 20.104.50.220:42463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/alfa1.php"] [unique_id "apPlsNKCPt8cS-VWcMmm1QAAA7I"]
[Sun Aug 30 03:11:28.111977 2026] [security2:error] [pid 519566:tid 519744] [client 20.48.250.41:49308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/asax.php"] [unique_id "apPlsNKCPt8cS-VWcMmm1gAAA9M"]
[Sun Aug 30 03:11:28.116665 2026] [security2:error] [pid 519566:tid 519747] [client 20.104.49.130:63583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/xmini4.php"] [unique_id "apPlsNKCPt8cS-VWcMmm2QAAA9Y"]
[Sun Aug 30 03:11:28.122667 2026] [authz_core:error] [pid 519566:tid 519733] [client 216.73.216.128:29228] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:28.122934 2026] [authz_core:error] [pid 519566:tid 519733] [client 216.73.216.128:29228] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:28.139679 2026] [security2:error] [pid 519566:tid 519720] [client 20.104.49.130:43281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/forum.php"] [unique_id "apPlsNKCPt8cS-VWcMmm4gAAA7s"]
[Sun Aug 30 03:11:28.146732 2026] [security2:error] [pid 519566:tid 519785] [client 20.104.50.220:5538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-settings.php"] [unique_id "apPlsNKCPt8cS-VWcMmm6AAAA_w"]
[Sun Aug 30 03:11:28.147230 2026] [authz_core:error] [pid 519566:tid 519714] [client 66.249.66.67:40893] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:28.147631 2026] [authz_core:error] [pid 519566:tid 519714] [client 66.249.66.67:40893] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:28.149025 2026] [security2:error] [pid 519566:tid 519812] [client 158.23.147.79:43045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-includes/content.php"] [unique_id "apPlsNKCPt8cS-VWcMmm6QAABBc"]
[Sun Aug 30 03:11:28.169502 2026] [security2:error] [pid 519566:tid 519624] [remote 191.101.44.2:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.44.101.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ibrgroup.in"] [uri "/wp-login.php"] [unique_id "apPlsNKCPt8cS-VWcMmm6gAEAjk"], referer: https://ibrgroup.in/wp-login.php
[Sun Aug 30 03:11:28.189815 2026] [security2:error] [pid 519566:tid 519756] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/live/.env"] [unique_id "apPlsNKCPt8cS-VWcMmm-gAAA98"]
[Sun Aug 30 03:11:28.194511 2026] [security2:error] [pid 519566:tid 519736] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/bootstrap.php"] [unique_id "apPlsNKCPt8cS-VWcMmm_QAAA8s"]
[Sun Aug 30 03:11:28.199329 2026] [authz_core:error] [pid 519566:tid 519760] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:28.199429 2026] [security2:error] [pid 519566:tid 519704] [client 4.205.62.107:17690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/doc.php"] [unique_id "apPlsNKCPt8cS-VWcMmnAgAAA6s"]
[Sun Aug 30 03:11:28.199575 2026] [authz_core:error] [pid 519566:tid 519760] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:28.231415 2026] [security2:error] [pid 519566:tid 519717] [client 20.48.251.3:55796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/channels.php"] [unique_id "apPlsNKCPt8cS-VWcMmnEwAAA7g"]
[Sun Aug 30 03:11:28.233552 2026] [authz_core:error] [pid 519566:tid 519754] [client 66.249.66.73:34982] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:28.233873 2026] [authz_core:error] [pid 519566:tid 519754] [client 66.249.66.73:34982] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:28.242544 2026] [security2:error] [pid 519566:tid 519719] [client 20.48.250.41:49378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/fetch.php"] [unique_id "apPlsNKCPt8cS-VWcMmnGQAAA7o"]
[Sun Aug 30 03:11:28.245451 2026] [security2:error] [pid 519566:tid 519738] [client 158.23.147.79:16326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-admin/images/about.php"] [unique_id "apPlsNKCPt8cS-VWcMmnHAAAA80"]
[Sun Aug 30 03:11:28.248328 2026] [security2:error] [pid 519566:tid 519732] [client 20.104.50.220:61961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/zx.php"] [unique_id "apPlsNKCPt8cS-VWcMmnHQAAA8c"]
[Sun Aug 30 03:11:28.257338 2026] [security2:error] [pid 519566:tid 519816] [client 20.220.10.235:20440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/Contrller.php"] [unique_id "apPlsNKCPt8cS-VWcMmnHwAABBs"]
[Sun Aug 30 03:11:28.269826 2026] [security2:error] [pid 519566:tid 519715] [client 20.48.251.3:37161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/guk.php"] [unique_id "apPlsNKCPt8cS-VWcMmnIgAAA7Y"]
[Sun Aug 30 03:11:28.278983 2026] [core:alert] [pid 519566:tid 519761] [client 176.29.150.12:28157] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:11:28.298838 2026] [security2:error] [pid 519566:tid 519766] [client 4.205.62.107:52855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/bengi.php"] [unique_id "apPlsNKCPt8cS-VWcMmnKwAAA-k"]
[Sun Aug 30 03:11:28.300197 2026] [security2:error] [pid 519566:tid 519823] [client 20.104.18.15:18243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/info.php/new.php"] [unique_id "apPlsNKCPt8cS-VWcMmnLAAABCI"]
[Sun Aug 30 03:11:28.302016 2026] [security2:error] [pid 519566:tid 519749] [client 78.46.215.1:32624] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "atstechsolution.com"] [uri "/index.html"] [unique_id "apPlsNKCPt8cS-VWcMmnKgAAA9g"], referer: https://atstechsolution.com
[Sun Aug 30 03:11:28.309465 2026] [authz_core:error] [pid 519566:tid 519756] [client 216.73.216.128:29228] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:28.309739 2026] [authz_core:error] [pid 519566:tid 519756] [client 216.73.216.128:29228] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:28.319967 2026] [security2:error] [pid 519566:tid 519777] [client 68.155.159.216:54294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apPlsNKCPt8cS-VWcMmnMwAAA_Q"]
[Sun Aug 30 03:11:28.324841 2026] [security2:error] [pid 519566:tid 519815] [client 40.83.93.50:6395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/dropdown.php"] [unique_id "apPlsNKCPt8cS-VWcMmnNQAABBo"]
[Sun Aug 30 03:11:28.332667 2026] [security2:error] [pid 519566:tid 519774] [client 20.197.61.180:12245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/nvt/includes/plugins/wp-blog-header.php"] [unique_id "apPlsNKCPt8cS-VWcMmnOAAAA_E"]
[Sun Aug 30 03:11:28.355127 2026] [autoindex:error] [pid 519566:tid 519741] [client 35.247.242.193:45298] AH01276: Cannot serve directory /home4/filtagr/public_html/website_abc5208c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:11:28.369933 2026] [security2:error] [pid 519566:tid 519733] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/mls.php"] [unique_id "apPlsNKCPt8cS-VWcMmnQwAAA8g"]
[Sun Aug 30 03:11:28.370539 2026] [security2:error] [pid 519566:tid 519818] [client 20.104.18.15:31642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wander.php"] [unique_id "apPlsNKCPt8cS-VWcMmnRAAABB0"]
[Sun Aug 30 03:11:28.381727 2026] [security2:error] [pid 519566:tid 519720] [client 158.23.147.79:43592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-admin/css/index.php"] [unique_id "apPlsNKCPt8cS-VWcMmnSAAAA7s"]
[Sun Aug 30 03:11:28.383890 2026] [security2:error] [pid 519566:tid 519703] [client 20.220.10.235:20450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/file66.php"] [unique_id "apPlsNKCPt8cS-VWcMmnSgAAA6o"]
[Sun Aug 30 03:11:28.393867 2026] [security2:error] [pid 519566:tid 519702] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/prod/.env"] [unique_id "apPlsNKCPt8cS-VWcMmnTgAAA6k"]
[Sun Aug 30 03:11:28.409255 2026] [security2:error] [pid 519566:tid 519819] [client 20.48.250.41:49407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/vx.php"] [unique_id "apPlsNKCPt8cS-VWcMmnUgAABB4"]
[Sun Aug 30 03:11:28.425782 2026] [security2:error] [pid 519566:tid 519715] [client 216.73.216.128:45868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlsNKCPt8cS-VWcMmnVAAAA7Y"]
[Sun Aug 30 03:11:28.431256 2026] [security2:error] [pid 519566:tid 519808] [client 20.104.18.15:22458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/wp-content/k.php"] [unique_id "apPlsNKCPt8cS-VWcMmnWgAABBM"]
[Sun Aug 30 03:11:28.431898 2026] [security2:error] [pid 519566:tid 519729] [client 20.151.200.44:63031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/Contrller.php"] [unique_id "apPlsNKCPt8cS-VWcMmnWwAAA8Q"]
[Sun Aug 30 03:11:28.477101 2026] [security2:error] [pid 519566:tid 519718] [client 20.104.50.220:51393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/admin.php"] [unique_id "apPlsNKCPt8cS-VWcMmncAAAA7k"]
[Sun Aug 30 03:11:28.490282 2026] [authz_core:error] [pid 519566:tid 519717] [client 66.249.66.70:60564] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:28.490550 2026] [authz_core:error] [pid 519566:tid 519717] [client 66.249.66.70:60564] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:28.492326 2026] [security2:error] [pid 519566:tid 519743] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/clients.php"] [unique_id "apPlsNKCPt8cS-VWcMmndwAAA9I"]
[Sun Aug 30 03:11:28.493549 2026] [security2:error] [pid 519566:tid 519781] [client 4.205.62.107:16375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/xa.php"] [unique_id "apPlsNKCPt8cS-VWcMmneAAAA_g"]
[Sun Aug 30 03:11:28.498074 2026] [authz_core:error] [pid 519566:tid 519785] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:11:28.498491 2026] [authz_core:error] [pid 519566:tid 519785] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:11:28.510036 2026] [security2:error] [pid 519566:tid 519798] [client 20.220.10.235:20436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/blnux.php"] [unique_id "apPlsNKCPt8cS-VWcMmnfAAABAk"]
[Sun Aug 30 03:11:28.592677 2026] [security2:error] [pid 519566:tid 519723] [client 20.48.250.41:19399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/global.php"] [unique_id "apPlsNKCPt8cS-VWcMmnmwAAA74"]
[Sun Aug 30 03:11:28.595603 2026] [security2:error] [pid 519566:tid 519749] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/dev/.env"] [unique_id "apPlsNKCPt8cS-VWcMmnnQAAA9g"]
[Sun Aug 30 03:11:28.606586 2026] [security2:error] [pid 519566:tid 519775] [client 158.23.147.79:39316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-admin/images/index.php"] [unique_id "apPlsNKCPt8cS-VWcMmnoQAAA_I"]
[Sun Aug 30 03:11:28.616569 2026] [security2:error] [pid 519566:tid 519805] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/idx/results.php"] [unique_id "apPlsNKCPt8cS-VWcMmnpQAABBA"]
[Sun Aug 30 03:11:28.637941 2026] [security2:error] [pid 519566:tid 519776] [client 20.220.10.235:20469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/attack.php"] [unique_id "apPlsNKCPt8cS-VWcMmnqQAAA_M"]
[Sun Aug 30 03:11:28.681897 2026] [security2:error] [pid 519566:tid 519709] [client 20.104.18.15:16917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/x.php"] [unique_id "apPlsNKCPt8cS-VWcMmnuQAAA7A"]
[Sun Aug 30 03:11:28.683523 2026] [authz_core:error] [pid 519566:tid 519703] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:28.683885 2026] [authz_core:error] [pid 519566:tid 519703] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:28.737587 2026] [security2:error] [pid 519566:tid 519789] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/2Fedit.php"] [unique_id "apPlsNKCPt8cS-VWcMmn1AAABAA"]
[Sun Aug 30 03:11:28.753551 2026] [core:alert] [pid 519566:tid 519739] [client 213.230.78.38:27425] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:11:28.769594 2026] [security2:error] [pid 519566:tid 519747] [client 20.48.250.41:49288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/fs.php"] [unique_id "apPlsNKCPt8cS-VWcMmn5QAAA9Y"]
[Sun Aug 30 03:11:28.774423 2026] [security2:error] [pid 519566:tid 519730] [client 20.220.10.235:20444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/wk/index.php"] [unique_id "apPlsNKCPt8cS-VWcMmn5wAAA8U"]
[Sun Aug 30 03:11:28.794559 2026] [security2:error] [pid 519566:tid 519734] [client 20.48.251.3:52209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/css.php"] [unique_id "apPlsNKCPt8cS-VWcMmn8QAAA8k"]
[Sun Aug 30 03:11:28.797375 2026] [security2:error] [pid 519566:tid 519752] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/staging/.env"] [unique_id "apPlsNKCPt8cS-VWcMmn8wAAA9s"]
[Sun Aug 30 03:11:28.822710 2026] [security2:error] [pid 519566:tid 519810] [client 68.155.159.216:57073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/packed.php"] [unique_id "apPlsNKCPt8cS-VWcMmn-wAABBU"]
[Sun Aug 30 03:11:28.837009 2026] [security2:error] [pid 519566:tid 519740] [client 158.23.147.79:39160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-includes/index.php"] [unique_id "apPlsNKCPt8cS-VWcMmoAQAAA88"]
[Sun Aug 30 03:11:28.861870 2026] [security2:error] [pid 519566:tid 519718] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp-admin/edit.php"] [unique_id "apPlsNKCPt8cS-VWcMmoDAAAA7k"]
[Sun Aug 30 03:11:28.875606 2026] [security2:error] [pid 519566:tid 519760] [client 40.83.93.50:7070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/mar.php"] [unique_id "apPlsNKCPt8cS-VWcMmoEQAAA-M"]
[Sun Aug 30 03:11:28.901556 2026] [authz_core:error] [pid 519566:tid 519772] [client 66.249.66.76:52096] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:28.902021 2026] [authz_core:error] [pid 519566:tid 519772] [client 66.249.66.76:52096] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:28.903419 2026] [security2:error] [pid 519566:tid 519781] [client 20.220.10.235:20358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/dehnl.php"] [unique_id "apPlsNKCPt8cS-VWcMmoGQAAA_g"]
[Sun Aug 30 03:11:28.922949 2026] [security2:error] [pid 519566:tid 519795] [client 4.205.62.107:36649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/var/www/wallet/index.php"] [unique_id "apPlsNKCPt8cS-VWcMmoIgAABAY"]
[Sun Aug 30 03:11:28.935605 2026] [security2:error] [pid 519566:tid 519801] [client 4.205.62.107:25534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/grsiuk.php"] [unique_id "apPlsNKCPt8cS-VWcMmoJQAABAw"]
[Sun Aug 30 03:11:28.970747 2026] [security2:error] [pid 519566:tid 519722] [client 20.48.250.41:49310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/ioxi.php"] [unique_id "apPlsNKCPt8cS-VWcMmoNAAAA70"]
[Sun Aug 30 03:11:28.975663 2026] [security2:error] [pid 519566:tid 519751] [client 20.104.50.220:17014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/04.php"] [unique_id "apPlsNKCPt8cS-VWcMmoNwAAA9o"]
[Sun Aug 30 03:11:28.999173 2026] [security2:error] [pid 519566:tid 519715] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/opt/.env"] [unique_id "apPlsNKCPt8cS-VWcMmoRwAAA7Y"]
[Sun Aug 30 03:11:29.003655 2026] [authz_core:error] [pid 519566:tid 519809] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:11:29.004108 2026] [authz_core:error] [pid 519566:tid 519809] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:11:29.006097 2026] [security2:error] [pid 519566:tid 519732] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/fr/wp-login.php"] [unique_id "apPlsNKCPt8cS-VWcMmoPAAAA8c"]
[Sun Aug 30 03:11:29.012641 2026] [security2:error] [pid 519566:tid 519724] [client 20.104.18.15:51174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/5PJcpMFsD8B.php"] [unique_id "apPlsdKCPt8cS-VWcMmoTAAAA78"]
[Sun Aug 30 03:11:29.032689 2026] [security2:error] [pid 519566:tid 519716] [client 20.220.10.235:20368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/png.php"] [unique_id "apPlsdKCPt8cS-VWcMmoVwAAA7c"]
[Sun Aug 30 03:11:29.055909 2026] [security2:error] [pid 519566:tid 519696] [client 20.197.61.180:18053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/oceanwp/sass/components/plugins/panel.php"] [unique_id "apPlsdKCPt8cS-VWcMmoZwAAA6M"]
[Sun Aug 30 03:11:29.061615 2026] [security2:error] [pid 519566:tid 519740] [client 20.104.50.220:25458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/footer.php"] [unique_id "apPlsdKCPt8cS-VWcMmoagAAA88"]
[Sun Aug 30 03:11:29.126852 2026] [security2:error] [pid 519566:tid 519789] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/2Fwp-seo.php"] [unique_id "apPlsdKCPt8cS-VWcMmohgAABAA"]
[Sun Aug 30 03:11:29.129298 2026] [authz_core:error] [pid 519566:tid 519747] [client 66.249.66.74:54976] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:29.129571 2026] [authz_core:error] [pid 519566:tid 519747] [client 66.249.66.74:54976] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:29.154616 2026] [security2:error] [pid 519566:tid 519774] [client 158.23.147.79:43616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/mah.php"] [unique_id "apPlsdKCPt8cS-VWcMmoiwAAA_E"]
[Sun Aug 30 03:11:29.160931 2026] [security2:error] [pid 519566:tid 519738] [client 20.48.251.3:64317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/8.php"] [unique_id "apPlsdKCPt8cS-VWcMmojAAAA80"]
[Sun Aug 30 03:11:29.164230 2026] [security2:error] [pid 519566:tid 519746] [client 20.220.10.235:20359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/txets.php"] [unique_id "apPlsdKCPt8cS-VWcMmojQAAA9U"]
[Sun Aug 30 03:11:29.170589 2026] [security2:error] [pid 519566:tid 519770] [client 20.48.250.41:49368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/bootstrap.php"] [unique_id "apPlsdKCPt8cS-VWcMmokQAAA-0"]
[Sun Aug 30 03:11:29.174629 2026] [security2:error] [pid 519566:tid 519755] [client 20.104.50.220:29585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-content/fm.php"] [unique_id "apPlsdKCPt8cS-VWcMmolQAAA94"]
[Sun Aug 30 03:11:29.180758 2026] [security2:error] [pid 519566:tid 519720] [client 20.104.50.220:33034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/shadowx.php"] [unique_id "apPlsdKCPt8cS-VWcMmomAAAA7s"]
[Sun Aug 30 03:11:29.181127 2026] [authz_core:error] [pid 519566:tid 519761] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:29.181563 2026] [authz_core:error] [pid 519566:tid 519761] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:29.188199 2026] [authz_core:error] [pid 519566:tid 519820] [client 66.249.66.42:51588] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:29.188478 2026] [authz_core:error] [pid 519566:tid 519820] [client 66.249.66.42:51588] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:29.202083 2026] [security2:error] [pid 519566:tid 519782] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/laravel/.env"] [unique_id "apPlsdKCPt8cS-VWcMmoowAAA_k"]
[Sun Aug 30 03:11:29.246595 2026] [security2:error] [pid 519566:tid 519787] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/2Fwp-rocket.php"] [unique_id "apPlsdKCPt8cS-VWcMmorAAAA_4"]
[Sun Aug 30 03:11:29.252553 2026] [security2:error] [pid 519566:tid 519796] [client 20.104.50.220:62845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/fxshell.php"] [unique_id "apPlsdKCPt8cS-VWcMmorwAABAc"]
[Sun Aug 30 03:11:29.298674 2026] [security2:error] [pid 519566:tid 519789] [client 20.104.50.220:51548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/159.php"] [unique_id "apPlsdKCPt8cS-VWcMmowQAABAA"]
[Sun Aug 30 03:11:29.316775 2026] [security2:error] [pid 519566:tid 519753] [client 20.104.50.220:5468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/kon.php"] [unique_id "apPlsdKCPt8cS-VWcMmozQAAA9w"]
[Sun Aug 30 03:11:29.327940 2026] [security2:error] [pid 519566:tid 519738] [client 20.220.10.235:20352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/wp-login.php"] [unique_id "apPlsdKCPt8cS-VWcMmozAAAA80"]
[Sun Aug 30 03:11:29.338869 2026] [security2:error] [pid 519566:tid 519706] [client 4.205.62.107:16783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/css.php"] [unique_id "apPlsdKCPt8cS-VWcMmo1gAAA60"]
[Sun Aug 30 03:11:29.343472 2026] [security2:error] [pid 519566:tid 519700] [client 20.48.250.41:19434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/export.php"] [unique_id "apPlsdKCPt8cS-VWcMmo2AAAA6c"]
[Sun Aug 30 03:11:29.365070 2026] [security2:error] [pid 519566:tid 519769] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/.env"] [unique_id "apPlsdKCPt8cS-VWcMmo3wAAA-w"]
[Sun Aug 30 03:11:29.369307 2026] [security2:error] [pid 519566:tid 519760] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp-admin/plugins.php"] [unique_id "apPlsdKCPt8cS-VWcMmo4AAAA-M"]
[Sun Aug 30 03:11:29.377572 2026] [security2:error] [pid 519566:tid 519756] [client 40.83.93.50:3927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/css.php"] [unique_id "apPlsdKCPt8cS-VWcMmo5AAAA98"]
[Sun Aug 30 03:11:29.386185 2026] [security2:error] [pid 519566:tid 519753] [client 20.48.251.3:59356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/zz.php"] [unique_id "apPlsdKCPt8cS-VWcMmo5wAAA9w"]
[Sun Aug 30 03:11:29.397120 2026] [security2:error] [pid 519566:tid 519814] [client 20.48.250.41:11112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlsdKCPt8cS-VWcMmo7QAABBk"]
[Sun Aug 30 03:11:29.405529 2026] [security2:error] [pid 519566:tid 519727] [client 34.15.159.88:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/symfony/.env"] [unique_id "apPlsdKCPt8cS-VWcMmo8AAAA8I"]
[Sun Aug 30 03:11:29.431569 2026] [security2:error] [pid 519566:tid 519797] [client 20.104.50.220:63036] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/.conf.php"] [unique_id "apPlsdKCPt8cS-VWcMmo9gAABAg"]
[Sun Aug 30 03:11:29.435778 2026] [security2:error] [pid 519566:tid 519742] [client 20.48.251.3:36862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/config_dev.php"] [unique_id "apPlsdKCPt8cS-VWcMmo-QAAA9E"]
[Sun Aug 30 03:11:29.436250 2026] [security2:error] [pid 519566:tid 519739] [client 68.155.159.216:54275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-admin/user/index.php"] [unique_id "apPlsdKCPt8cS-VWcMmo-wAAA84"]
[Sun Aug 30 03:11:29.455813 2026] [security2:error] [pid 519566:tid 519702] [client 20.220.10.235:20432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/wp-access.php"] [unique_id "apPlsdKCPt8cS-VWcMmpCAAAA6k"]
[Sun Aug 30 03:11:29.457207 2026] [authz_core:error] [pid 519566:tid 519762] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:11:29.457461 2026] [authz_core:error] [pid 519566:tid 519762] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:11:29.458947 2026] [lsapi:error] [pid 519566:tid 519635] [remote 109.201.55.2:10038] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:11:29.459024 2026] [authz_core:error] [pid 519566:tid 519707] [client 66.249.66.74:58155] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:29.459128 2026] [lsapi:error] [pid 519566:tid 519635] [remote 109.201.55.2:10038] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:11:29.459292 2026] [authz_core:error] [pid 519566:tid 519707] [client 66.249.66.74:58155] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:29.460504 2026] [lsapi:error] [pid 519566:tid 519635] [remote 109.201.55.2:10038] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:11:29.464290 2026] [security2:error] [pid 519566:tid 519711] [client 4.205.62.107:52926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/i.php"] [unique_id "apPlsdKCPt8cS-VWcMmpDQAAA7I"]
[Sun Aug 30 03:11:29.488475 2026] [security2:error] [pid 519566:tid 519802] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp-admin/post.php"] [unique_id "apPlsdKCPt8cS-VWcMmpGAAABA0"]
[Sun Aug 30 03:11:29.492700 2026] [security2:error] [pid 519566:tid 519738] [client 20.48.250.41:49406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/gk.php"] [unique_id "apPlsdKCPt8cS-VWcMmpGgAAA80"]
[Sun Aug 30 03:11:29.506788 2026] [security2:error] [pid 519566:tid 519735] [client 20.104.18.15:31740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/abcd.php"] [unique_id "apPlsdKCPt8cS-VWcMmpIAAAA8o"]
[Sun Aug 30 03:11:29.525964 2026] [security2:error] [pid 519566:tid 519804] [client 20.104.18.15:18190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/w.php"] [unique_id "apPlsdKCPt8cS-VWcMmpOQAABA8"]
[Sun Aug 30 03:11:29.547215 2026] [security2:error] [pid 519566:tid 519752] [client 20.48.250.41:11154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlsdKCPt8cS-VWcMmpRwAAA9s"]
[Sun Aug 30 03:11:29.573425 2026] [security2:error] [pid 519566:tid 519822] [client 20.104.18.15:22293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/os.php"] [unique_id "apPlsdKCPt8cS-VWcMmpUAAABCE"]
[Sun Aug 30 03:11:29.587505 2026] [security2:error] [pid 519566:tid 519738] [client 20.220.10.235:20417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/wp-content/admin.php"] [unique_id "apPlsdKCPt8cS-VWcMmpUgAAA80"]
[Sun Aug 30 03:11:29.588901 2026] [authz_core:error] [pid 519566:tid 519802] [client 216.73.216.128:13745] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:29.589171 2026] [authz_core:error] [pid 519566:tid 519802] [client 216.73.216.128:13745] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:29.607401 2026] [security2:error] [pid 519566:tid 519728] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/bdatos.php"] [unique_id "apPlsdKCPt8cS-VWcMmpWQAAA8M"]
[Sun Aug 30 03:11:29.615220 2026] [security2:error] [pid 519566:tid 519808] [client 20.104.50.220:59344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/aa2.php"] [unique_id "apPlsdKCPt8cS-VWcMmpXAAABBM"]
[Sun Aug 30 03:11:29.648993 2026] [security2:error] [pid 519566:tid 519783] [client 4.205.62.107:16344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/ws61.php"] [unique_id "apPlsdKCPt8cS-VWcMmpYgAAA_o"]
[Sun Aug 30 03:11:29.655789 2026] [authz_core:error] [pid 519566:tid 519775] [client 66.249.66.196:47789] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:29.656243 2026] [authz_core:error] [pid 519566:tid 519775] [client 66.249.66.196:47789] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:29.717151 2026] [security2:error] [pid 519566:tid 519762] [client 20.48.250.41:11202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/ff1.php"] [unique_id "apPlsdKCPt8cS-VWcMmphwAAA-U"]
[Sun Aug 30 03:11:29.718965 2026] [authz_core:error] [pid 519566:tid 519718] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:29.719434 2026] [authz_core:error] [pid 519566:tid 519718] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:29.719705 2026] [security2:error] [pid 519566:tid 519749] [client 20.220.10.235:20353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/log.php"] [unique_id "apPlsdKCPt8cS-VWcMmpiQAAA9g"]
[Sun Aug 30 03:11:29.722163 2026] [authz_core:error] [pid 519566:tid 519735] [client 66.249.66.72:40545] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:29.722566 2026] [authz_core:error] [pid 519566:tid 519735] [client 66.249.66.72:40545] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:29.725750 2026] [security2:error] [pid 519566:tid 519763] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/public/index.php"] [unique_id "apPlsdKCPt8cS-VWcMmpjAAAA-Y"]
[Sun Aug 30 03:11:29.735885 2026] [authz_core:error] [pid 519566:tid 519754] [client 66.249.66.71:60633] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:29.736179 2026] [authz_core:error] [pid 519566:tid 519754] [client 66.249.66.71:60633] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:29.767180 2026] [security2:error] [pid 519566:tid 519715] [client 20.197.61.180:12227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/options.php"] [unique_id "apPlsdKCPt8cS-VWcMmpnAAAA7Y"]
[Sun Aug 30 03:11:29.815392 2026] [security2:error] [pid 519566:tid 519720] [client 158.23.147.79:39336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-blog-header.php"] [unique_id "apPlsdKCPt8cS-VWcMmprwAAA7s"]
[Sun Aug 30 03:11:29.822937 2026] [security2:error] [pid 519566:tid 519781] [client 20.48.250.41:49351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/logs1.php"] [unique_id "apPlsdKCPt8cS-VWcMmpsQAAA_g"]
[Sun Aug 30 03:11:29.840361 2026] [security2:error] [pid 519566:tid 519762] [client 20.104.18.15:16971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/ssla.php"] [unique_id "apPlsdKCPt8cS-VWcMmpvQAAA-U"]
[Sun Aug 30 03:11:29.844586 2026] [security2:error] [pid 519566:tid 519795] [client 20.48.250.41:11227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/t.php"] [unique_id "apPlsdKCPt8cS-VWcMmpwAAABAY"]
[Sun Aug 30 03:11:29.846502 2026] [security2:error] [pid 519566:tid 519763] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/htadmin/login.php"] [unique_id "apPlsdKCPt8cS-VWcMmpwQAAA-Y"]
[Sun Aug 30 03:11:29.852050 2026] [security2:error] [pid 519566:tid 519804] [client 20.220.10.235:20457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/xwpg.php"] [unique_id "apPlsdKCPt8cS-VWcMmpxwAABA8"]
[Sun Aug 30 03:11:29.883923 2026] [security2:error] [pid 519566:tid 519703] [client 40.83.93.50:7096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/autoload_classmap.php"] [unique_id "apPlsdKCPt8cS-VWcMmp1AAAA6o"]
[Sun Aug 30 03:11:29.934818 2026] [security2:error] [pid 519566:tid 519822] [client 20.48.251.3:52212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/php_info.php"] [unique_id "apPlsdKCPt8cS-VWcMmp5QAABCE"]
[Sun Aug 30 03:11:29.969002 2026] [security2:error] [pid 519566:tid 519724] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/manage/login.php"] [unique_id "apPlsdKCPt8cS-VWcMmp9AAAA78"]
[Sun Aug 30 03:11:29.969369 2026] [authz_core:error] [pid 519566:tid 519753] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:11:29.969680 2026] [authz_core:error] [pid 519566:tid 519753] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:11:29.976485 2026] [security2:error] [pid 519566:tid 519734] [client 68.155.159.216:63248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-content/packed.php"] [unique_id "apPlsdKCPt8cS-VWcMmp-AAAA8k"]
[Sun Aug 30 03:11:29.978503 2026] [security2:error] [pid 519566:tid 519749] [client 20.151.200.44:62923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/file66.php"] [unique_id "apPlsdKCPt8cS-VWcMmp-gAAA9g"]
[Sun Aug 30 03:11:29.980119 2026] [core:alert] [pid 519566:tid 519782] [client 102.249.6.12:10090] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:11:29.982635 2026] [security2:error] [pid 519566:tid 519765] [client 20.220.10.235:20445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/sxxb.php"] [unique_id "apPlsdKCPt8cS-VWcMmp_wAAA-g"]
[Sun Aug 30 03:11:30.013264 2026] [security2:error] [pid 519566:tid 519766] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/wordpress/.env"] [unique_id "apPlstKCPt8cS-VWcMmqDAAAA-k"]
[Sun Aug 30 03:11:30.024089 2026] [security2:error] [pid 519566:tid 519727] [client 20.48.250.41:11191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/erty.php"] [unique_id "apPlstKCPt8cS-VWcMmqEwAAA8I"]
[Sun Aug 30 03:11:30.069011 2026] [security2:error] [pid 519566:tid 519742] [client 4.205.62.107:35985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/124.php"] [unique_id "apPlstKCPt8cS-VWcMmqJwAAA9E"]
[Sun Aug 30 03:11:30.074960 2026] [security2:error] [pid 519566:tid 519701] [client 4.205.62.107:25900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/paypal.php"] [unique_id "apPlstKCPt8cS-VWcMmqKAAAA6g"]
[Sun Aug 30 03:11:30.087656 2026] [security2:error] [pid 519566:tid 519801] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/TP/index.php"] [unique_id "apPlstKCPt8cS-VWcMmqLQAABAw"]
[Sun Aug 30 03:11:30.112638 2026] [security2:error] [pid 519566:tid 519707] [client 20.220.10.235:20291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/dx.php"] [unique_id "apPlstKCPt8cS-VWcMmqPAAAA64"]
[Sun Aug 30 03:11:30.115980 2026] [security2:error] [pid 519566:tid 519792] [client 20.104.50.220:17280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/333.php"] [unique_id "apPlstKCPt8cS-VWcMmqPgAABAM"]
[Sun Aug 30 03:11:30.134110 2026] [security2:error] [pid 519566:tid 519740] [client 158.23.147.79:58370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPlstKCPt8cS-VWcMmqRgAAA88"]
[Sun Aug 30 03:11:30.158168 2026] [security2:error] [pid 519566:tid 519718] [client 20.104.18.15:51144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPlstKCPt8cS-VWcMmqSgAAA7k"]
[Sun Aug 30 03:11:30.164386 2026] [authz_core:error] [pid 519566:tid 519789] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:30.164655 2026] [authz_core:error] [pid 519566:tid 519789] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:30.206029 2026] [security2:error] [pid 519566:tid 519774] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/Broker.php"] [unique_id "apPlstKCPt8cS-VWcMmqXwAAA_E"]
[Sun Aug 30 03:11:30.210771 2026] [security2:error] [pid 519566:tid 519742] [client 20.48.250.41:49369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/inege.php"] [unique_id "apPlstKCPt8cS-VWcMmqYgAAA9E"]
[Sun Aug 30 03:11:30.216860 2026] [security2:error] [pid 519566:tid 519801] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/wp/.env"] [unique_id "apPlstKCPt8cS-VWcMmqZAAABAw"]
[Sun Aug 30 03:11:30.243519 2026] [authz_core:error] [pid 519566:tid 519732] [client 216.73.216.128:40285] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:30.243793 2026] [authz_core:error] [pid 519566:tid 519732] [client 216.73.216.128:40285] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:30.250561 2026] [security2:error] [pid 519566:tid 519769] [client 20.220.10.235:20366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPlstKCPt8cS-VWcMmqawAAA-w"]
[Sun Aug 30 03:11:30.257037 2026] [autoindex:error] [pid 519566:tid 519763] [client 34.204.184.214:46358] AH01276: Cannot serve directory /home3/palmer/tween.pplak.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:11:30.267312 2026] [security2:error] [pid 519566:tid 519765] [client 20.48.250.41:11224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/0x.php"] [unique_id "apPlstKCPt8cS-VWcMmqcQAAA-g"]
[Sun Aug 30 03:11:30.269022 2026] [authz_core:error] [pid 519566:tid 519701] [client 66.249.66.73:64567] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:30.269335 2026] [authz_core:error] [pid 519566:tid 519701] [client 66.249.66.73:64567] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:30.284781 2026] [security2:error] [pid 519566:tid 519649] [remote 52.167.144.182:19405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jacobs-treasures.com"] [uri "/index.php/product-category/blue-water-laundry-strips-coupon"] [unique_id "apPlstKCPt8cS-VWcMmqeQAD2lI"]
[Sun Aug 30 03:11:30.308803 2026] [security2:error] [pid 519566:tid 519718] [client 20.104.50.220:29169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-content/a.php"] [unique_id "apPlstKCPt8cS-VWcMmqgQAAA7k"]
[Sun Aug 30 03:11:30.313906 2026] [security2:error] [pid 519566:tid 519761] [client 20.48.251.3:54835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/thui.php"] [unique_id "apPlstKCPt8cS-VWcMmqgwAAA-Q"]
[Sun Aug 30 03:11:30.324421 2026] [security2:error] [pid 519566:tid 519795] [client 20.104.50.220:24835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/wp-content/index.php"] [unique_id "apPlstKCPt8cS-VWcMmqhwAABAY"]
[Sun Aug 30 03:11:30.327639 2026] [security2:error] [pid 519566:tid 519781] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/Store.php"] [unique_id "apPlstKCPt8cS-VWcMmqiQAAA_g"]
[Sun Aug 30 03:11:30.331099 2026] [security2:error] [pid 519566:tid 519754] [client 20.104.50.220:33327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/hexor.php"] [unique_id "apPlstKCPt8cS-VWcMmqjAAAA90"]
[Sun Aug 30 03:11:30.349743 2026] [authz_core:error] [pid 519566:tid 519774] [client 66.249.66.195:35310] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:30.350002 2026] [authz_core:error] [pid 519566:tid 519774] [client 66.249.66.195:35310] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:30.359280 2026] [security2:error] [pid 519566:tid 519814] [client 40.83.93.50:3957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/info.php"] [unique_id "apPlstKCPt8cS-VWcMmqlgAABBk"]
[Sun Aug 30 03:11:30.384308 2026] [security2:error] [pid 519566:tid 519786] [client 20.104.50.220:52842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/fk.php7"] [unique_id "apPlstKCPt8cS-VWcMmqoQAAA_0"]
[Sun Aug 30 03:11:30.385099 2026] [security2:error] [pid 519566:tid 519817] [client 20.220.10.235:20461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/xda.php"] [unique_id "apPlstKCPt8cS-VWcMmqogAABBw"]
[Sun Aug 30 03:11:30.418564 2026] [security2:error] [pid 519566:tid 519729] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/cms/.env"] [unique_id "apPlstKCPt8cS-VWcMmqsQAAA8Q"]
[Sun Aug 30 03:11:30.424335 2026] [authz_core:error] [pid 519566:tid 519790] [client 216.73.216.128:40285] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:30.424657 2026] [authz_core:error] [pid 519566:tid 519790] [client 216.73.216.128:40285] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:30.439537 2026] [security2:error] [pid 519566:tid 519717] [client 20.48.250.41:11167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/66.php"] [unique_id "apPlstKCPt8cS-VWcMmquQAAA7g"]
[Sun Aug 30 03:11:30.444557 2026] [security2:error] [pid 519566:tid 519822] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/Pdo.php"] [unique_id "apPlstKCPt8cS-VWcMmqvQAABCE"]
[Sun Aug 30 03:11:30.458023 2026] [authz_core:error] [pid 519566:tid 519797] [client 66.249.66.67:57396] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:30.458290 2026] [authz_core:error] [pid 519566:tid 519797] [client 66.249.66.67:57396] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:30.460197 2026] [security2:error] [pid 519566:tid 519736] [client 158.23.147.79:43283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apPlstKCPt8cS-VWcMmqyQAAA8s"]
[Sun Aug 30 03:11:30.460879 2026] [authz_core:error] [pid 519566:tid 519773] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:11:30.461072 2026] [security2:error] [pid 519566:tid 519698] [client 20.48.250.41:49363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/wp-link10.php"] [unique_id "apPlstKCPt8cS-VWcMmqygAAA6U"]
[Sun Aug 30 03:11:30.461179 2026] [authz_core:error] [pid 519566:tid 519773] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:11:30.470406 2026] [security2:error] [pid 519566:tid 519733] [client 20.104.50.220:5569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/kontol.php"] [unique_id "apPlstKCPt8cS-VWcMmq0QAAA8g"]
[Sun Aug 30 03:11:30.476507 2026] [security2:error] [pid 519566:tid 519777] [client 4.205.62.107:17331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/php_info.php"] [unique_id "apPlstKCPt8cS-VWcMmq0wAAA_Q"]
[Sun Aug 30 03:11:30.477911 2026] [security2:error] [pid 519566:tid 519817] [client 20.104.50.220:63513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/tesla1.php"] [unique_id "apPlstKCPt8cS-VWcMmq1gAABBw"]
[Sun Aug 30 03:11:30.478321 2026] [authz_core:error] [pid 519566:tid 519756] [client 66.249.66.73:47032] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:30.478752 2026] [authz_core:error] [pid 519566:tid 519756] [client 66.249.66.73:47032] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:30.489107 2026] [security2:error] [pid 519566:tid 519785] [client 20.197.61.180:3206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/panel.php"] [unique_id "apPlstKCPt8cS-VWcMmq2wAAA_w"]
[Sun Aug 30 03:11:30.506006 2026] [security2:error] [pid 519566:tid 519714] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/.env.bak"] [unique_id "apPlstKCPt8cS-VWcMmq3gAAA7U"]
[Sun Aug 30 03:11:30.511604 2026] [security2:error] [pid 519566:tid 519789] [client 20.220.10.235:20428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/wp-admin/js/index.php"] [unique_id "apPlstKCPt8cS-VWcMmq4QAABAA"]
[Sun Aug 30 03:11:30.516895 2026] [authz_core:error] [pid 519566:tid 519806] [client 216.73.216.128:54671] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:30.517327 2026] [authz_core:error] [pid 519566:tid 519806] [client 216.73.216.128:54671] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:30.525486 2026] [security2:error] [pid 519566:tid 519729] [client 20.48.251.3:59369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/test.php"] [unique_id "apPlstKCPt8cS-VWcMmq6QAAA8Q"]
[Sun Aug 30 03:11:30.538878 2026] [security2:error] [pid 519566:tid 519741] [client 20.104.49.130:60779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/xwpg.php"] [unique_id "apPlstKCPt8cS-VWcMmq8QAAA9A"]
[Sun Aug 30 03:11:30.548055 2026] [security2:error] [pid 519566:tid 519754] [client 20.104.49.130:60642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/wp-blog-header.php"] [unique_id "apPlstKCPt8cS-VWcMmq9gAAA90"]
[Sun Aug 30 03:11:30.562254 2026] [security2:error] [pid 519566:tid 519703] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/core.php"] [unique_id "apPlstKCPt8cS-VWcMmq-wAAA6o"]
[Sun Aug 30 03:11:30.567469 2026] [security2:error] [pid 519566:tid 519780] [client 20.48.250.41:11164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/f35.php"] [unique_id "apPlstKCPt8cS-VWcMmq_AAAA_c"]
[Sun Aug 30 03:11:30.577127 2026] [security2:error] [pid 519566:tid 519719] [client 20.48.251.3:37128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/aws_credentials.php"] [unique_id "apPlstKCPt8cS-VWcMmq_gAAA7o"]
[Sun Aug 30 03:11:30.618173 2026] [security2:error] [pid 519566:tid 519744] [client 20.151.200.44:46037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlstKCPt8cS-VWcMmrCAAAA9M"]
[Sun Aug 30 03:11:30.620565 2026] [security2:error] [pid 519566:tid 519804] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/drupal/.env"] [unique_id "apPlstKCPt8cS-VWcMmrCgAABA8"]
[Sun Aug 30 03:11:30.644388 2026] [security2:error] [pid 519566:tid 519808] [client 20.104.18.15:31699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/nofile.php"] [unique_id "apPlstKCPt8cS-VWcMmrCwAABBM"]
[Sun Aug 30 03:11:30.645701 2026] [security2:error] [pid 519566:tid 519770] [client 20.220.10.235:20435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/t00l.php"] [unique_id "apPlstKCPt8cS-VWcMmrDAAAA-0"]
[Sun Aug 30 03:11:30.647827 2026] [security2:error] [pid 519566:tid 519712] [client 20.104.50.220:61430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/decer.php"] [unique_id "apPlstKCPt8cS-VWcMmrDQAAA7M"]
[Sun Aug 30 03:11:30.650435 2026] [security2:error] [pid 519566:tid 519766] [client 4.205.62.107:52808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/guk.php"] [unique_id "apPlstKCPt8cS-VWcMmrDgAAA-k"]
[Sun Aug 30 03:11:30.656860 2026] [authz_core:error] [pid 519566:tid 519714] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:30.657160 2026] [authz_core:error] [pid 519566:tid 519714] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:30.668740 2026] [security2:error] [pid 519566:tid 519729] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/.env.backup"] [unique_id "apPlstKCPt8cS-VWcMmrFQAAA8Q"]
[Sun Aug 30 03:11:30.670871 2026] [security2:error] [pid 519566:tid 519697] [client 20.104.18.15:18304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/x.php"] [unique_id "apPlstKCPt8cS-VWcMmrFwAAA6Q"]
[Sun Aug 30 03:11:30.678657 2026] [security2:error] [pid 519566:tid 519822] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/www.php"] [unique_id "apPlstKCPt8cS-VWcMmrGgAABCE"]
[Sun Aug 30 03:11:30.682509 2026] [security2:error] [pid 519566:tid 519704] [client 20.48.250.41:49375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/ww.php"] [unique_id "apPlstKCPt8cS-VWcMmrHQAAA6s"]
[Sun Aug 30 03:11:30.699942 2026] [authz_core:error] [pid 519566:tid 519823] [client 216.73.216.128:13745] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:30.700211 2026] [authz_core:error] [pid 519566:tid 519823] [client 216.73.216.128:13745] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:30.704710 2026] [security2:error] [pid 519566:tid 519811] [client 68.155.159.216:52583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-includes/plugins.php"] [unique_id "apPlstKCPt8cS-VWcMmrLAAABBY"]
[Sun Aug 30 03:11:30.736363 2026] [security2:error] [pid 519566:tid 519774] [client 20.104.18.15:22349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/htio.php"] [unique_id "apPlstKCPt8cS-VWcMmrOQAAA_E"]
[Sun Aug 30 03:11:30.751445 2026] [core:alert] [pid 519566:tid 519767] [client 5.240.181.241:33662] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:11:30.763002 2026] [security2:error] [pid 519566:tid 519814] [client 20.48.250.41:11015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/wen.php"] [unique_id "apPlstKCPt8cS-VWcMmrRgAABBk"]
[Sun Aug 30 03:11:30.768966 2026] [security2:error] [pid 519566:tid 519770] [client 20.104.50.220:31534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/ccou.php"] [unique_id "apPlstKCPt8cS-VWcMmrSQAAA-0"]
[Sun Aug 30 03:11:30.777237 2026] [security2:error] [pid 519566:tid 519769] [client 20.220.10.235:20406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/ls.php"] [unique_id "apPlstKCPt8cS-VWcMmrTAAAA-w"]
[Sun Aug 30 03:11:30.787267 2026] [security2:error] [pid 519566:tid 519772] [client 4.205.62.107:15816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/xza.php"] [unique_id "apPlstKCPt8cS-VWcMmrUQAAA-8"]
[Sun Aug 30 03:11:30.794830 2026] [authz_core:error] [pid 519566:tid 519697] [client 216.73.216.128:54671] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:30.795286 2026] [authz_core:error] [pid 519566:tid 519697] [client 216.73.216.128:54671] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:30.796082 2026] [security2:error] [pid 519566:tid 519811] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/Smarty.php"] [unique_id "apPlstKCPt8cS-VWcMmrWQAABBY"]
[Sun Aug 30 03:11:30.798794 2026] [authz_core:error] [pid 519566:tid 519730] [client 66.249.66.72:37877] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:30.799075 2026] [authz_core:error] [pid 519566:tid 519730] [client 66.249.66.72:37877] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:30.826286 2026] [security2:error] [pid 519566:tid 519776] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/joomla/.env"] [unique_id "apPlstKCPt8cS-VWcMmrZQAAA_M"]
[Sun Aug 30 03:11:30.865437 2026] [core:alert] [pid 519566:tid 519727] [client 160.202.146.14:47092] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:11:30.875196 2026] [security2:error] [pid 519566:tid 519741] [client 20.104.49.130:57647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/ws45.php"] [unique_id "apPlstKCPt8cS-VWcMmrewAAA9A"]
[Sun Aug 30 03:11:30.887811 2026] [authz_core:error] [pid 519566:tid 519804] [client 66.249.66.44:56305] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:30.888098 2026] [authz_core:error] [pid 519566:tid 519804] [client 66.249.66.44:56305] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:30.894315 2026] [security2:error] [pid 519566:tid 519716] [client 20.48.250.41:11072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/inc.php"] [unique_id "apPlstKCPt8cS-VWcMmrgQAAA7c"]
[Sun Aug 30 03:11:30.910394 2026] [security2:error] [pid 519566:tid 519807] [client 20.220.10.235:20292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/css/000.php"] [unique_id "apPlstKCPt8cS-VWcMmrhwAABBI"]
[Sun Aug 30 03:11:30.934978 2026] [security2:error] [pid 519566:tid 519761] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/Redis.php"] [unique_id "apPlstKCPt8cS-VWcMmrkAAAA-Q"]
[Sun Aug 30 03:11:30.957632 2026] [security2:error] [pid 519566:tid 519754] [client 40.83.93.50:3938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/b.php"] [unique_id "apPlstKCPt8cS-VWcMmrmAAAA90"]
[Sun Aug 30 03:11:30.977704 2026] [authz_core:error] [pid 519566:tid 519781] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:11:30.977997 2026] [authz_core:error] [pid 519566:tid 519781] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:11:30.982005 2026] [security2:error] [pid 519566:tid 519701] [client 20.104.18.15:16982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apPlstKCPt8cS-VWcMmrpwAAA6g"]
[Sun Aug 30 03:11:30.991388 2026] [security2:error] [pid 519566:tid 519778] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/.env.old"] [unique_id "apPlstKCPt8cS-VWcMmrrQAAA_U"]
[Sun Aug 30 03:11:31.027623 2026] [security2:error] [pid 519566:tid 519788] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/magento/.env"] [unique_id "apPls9KCPt8cS-VWcMmrvgAAA_8"]
[Sun Aug 30 03:11:31.039570 2026] [security2:error] [pid 519566:tid 519735] [client 20.220.10.235:20475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/cy.php"] [unique_id "apPls9KCPt8cS-VWcMmrxQAAA8o"]
[Sun Aug 30 03:11:31.039672 2026] [authz_core:error] [pid 519566:tid 519728] [client 66.249.66.37:57897] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:31.040114 2026] [authz_core:error] [pid 519566:tid 519728] [client 66.249.66.37:57897] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:31.052742 2026] [security2:error] [pid 519566:tid 519796] [client 20.48.250.41:49309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/w1px.php"] [unique_id "apPls9KCPt8cS-VWcMmrygAABAc"]
[Sun Aug 30 03:11:31.053919 2026] [security2:error] [pid 519566:tid 519767] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/nginx_error.php"] [unique_id "apPls9KCPt8cS-VWcMmrzAAAA-o"]
[Sun Aug 30 03:11:31.073465 2026] [security2:error] [pid 519566:tid 519702] [client 20.48.251.3:59497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/session.php"] [unique_id "apPls9KCPt8cS-VWcMmrzwAAA6k"]
[Sun Aug 30 03:11:31.074299 2026] [security2:error] [pid 519566:tid 519720] [client 207.154.212.47:55030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.212.154.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eessel.com"] [uri "/info.php"] [unique_id "apPls9KCPt8cS-VWcMmrzgAAA7s"]
[Sun Aug 30 03:11:31.076925 2026] [security2:error] [pid 519566:tid 519766] [client 20.48.250.41:11183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/6bcwiqwj.php"] [unique_id "apPls9KCPt8cS-VWcMmr0AAAA-k"]
[Sun Aug 30 03:11:31.087419 2026] [security2:error] [pid 519566:tid 519749] [client 158.23.147.79:39313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-admin/user/index.php"] [unique_id "apPls9KCPt8cS-VWcMmr0wAAA9g"]
[Sun Aug 30 03:11:31.110594 2026] [autoindex:error] [pid 519566:tid 519786] [client 34.237.50.25:33369] AH01276: Cannot serve directory /home3/palmer/tweens.pplak.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:11:31.148686 2026] [security2:error] [pid 519566:tid 519733] [client 68.155.159.216:57061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-l0gin.php"] [unique_id "apPls9KCPt8cS-VWcMmr6gAAA8g"]
[Sun Aug 30 03:11:31.155008 2026] [authz_core:error] [pid 519566:tid 519713] [client 216.73.216.128:13745] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:31.155014 2026] [authz_core:error] [pid 519566:tid 519792] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:31.155287 2026] [authz_core:error] [pid 519566:tid 519713] [client 216.73.216.128:13745] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:31.155306 2026] [authz_core:error] [pid 519566:tid 519792] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:31.168029 2026] [security2:error] [pid 519566:tid 519736] [client 20.220.10.235:20459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/admin.php/pindex.php"] [unique_id "apPls9KCPt8cS-VWcMmr8QAAA8s"]
[Sun Aug 30 03:11:31.172322 2026] [security2:error] [pid 519566:tid 519716] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/compat.php"] [unique_id "apPls9KCPt8cS-VWcMmr9QAAA7c"]
[Sun Aug 30 03:11:31.191761 2026] [security2:error] [pid 519566:tid 519785] [client 20.197.61.180:18054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/reboot/assets/js/plugins/home.php"] [unique_id "apPls9KCPt8cS-VWcMmr_gAAA_w"]
[Sun Aug 30 03:11:31.213542 2026] [security2:error] [pid 519566:tid 519775] [client 4.205.62.107:25905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/userfuns.php"] [unique_id "apPls9KCPt8cS-VWcMmsCwAAA_I"]
[Sun Aug 30 03:11:31.214333 2026] [security2:error] [pid 519566:tid 519729] [client 4.205.62.107:36730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/test1.php"] [unique_id "apPls9KCPt8cS-VWcMmsDQAAA8Q"]
[Sun Aug 30 03:11:31.228003 2026] [security2:error] [pid 519566:tid 519786] [client 20.104.49.130:52135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/sxxb.php"] [unique_id "apPls9KCPt8cS-VWcMmsEQAAA_0"]
[Sun Aug 30 03:11:31.228968 2026] [security2:error] [pid 519566:tid 519802] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/shopify/.env"] [unique_id "apPls9KCPt8cS-VWcMmsEgAABA0"]
[Sun Aug 30 03:11:31.236080 2026] [security2:error] [pid 519566:tid 519790] [client 20.48.250.41:11189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/easy.php"] [unique_id "apPls9KCPt8cS-VWcMmsFQAABAE"]
[Sun Aug 30 03:11:31.249382 2026] [security2:error] [pid 519566:tid 519808] [client 20.104.50.220:16645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/520.php"] [unique_id "apPls9KCPt8cS-VWcMmsGQAABBM"]
[Sun Aug 30 03:11:31.267595 2026] [security2:error] [pid 519566:tid 519748] [client 20.48.250.41:49376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/to.php"] [unique_id "apPls9KCPt8cS-VWcMmsHwAAA9c"]
[Sun Aug 30 03:11:31.274912 2026] [authz_core:error] [pid 519566:tid 519787] [client 66.249.66.64:40645] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:31.275256 2026] [authz_core:error] [pid 519566:tid 519787] [client 66.249.66.64:40645] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:31.291896 2026] [security2:error] [pid 519566:tid 519736] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/class-wpdb.php"] [unique_id "apPls9KCPt8cS-VWcMmsKAAAA8s"]
[Sun Aug 30 03:11:31.304160 2026] [security2:error] [pid 519566:tid 519784] [client 20.104.18.15:51176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/wsd.php"] [unique_id "apPls9KCPt8cS-VWcMmsKwAAA_s"]
[Sun Aug 30 03:11:31.326341 2026] [security2:error] [pid 519566:tid 519742] [client 20.220.10.235:20443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/admin.php/csv.php"] [unique_id "apPls9KCPt8cS-VWcMmsMQAAA9E"]
[Sun Aug 30 03:11:31.390580 2026] [security2:error] [pid 519566:tid 519786] [client 20.48.250.41:11120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/fresh3.php"] [unique_id "apPls9KCPt8cS-VWcMmsSgAAA_0"]
[Sun Aug 30 03:11:31.414097 2026] [security2:error] [pid 519566:tid 519724] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/base.php"] [unique_id "apPls9KCPt8cS-VWcMmsVQAAA78"]
[Sun Aug 30 03:11:31.431562 2026] [security2:error] [pid 519566:tid 519703] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/prestashop/.env"] [unique_id "apPls9KCPt8cS-VWcMmsXAAAA6o"]
[Sun Aug 30 03:11:31.433219 2026] [authz_core:error] [pid 519566:tid 519715] [client 216.73.216.128:40285] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:31.433473 2026] [authz_core:error] [pid 519566:tid 519715] [client 216.73.216.128:40285] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:31.442383 2026] [authz_core:error] [pid 519566:tid 519810] [client 66.249.66.68:44514] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:31.442653 2026] [authz_core:error] [pid 519566:tid 519810] [client 66.249.66.68:44514] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:31.443115 2026] [security2:error] [pid 519566:tid 519770] [client 40.83.93.50:10719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/wp-login.php"] [unique_id "apPls9KCPt8cS-VWcMmsYQAAA-0"]
[Sun Aug 30 03:11:31.458457 2026] [security2:error] [pid 519566:tid 519820] [client 20.48.251.3:65488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/file21.php"] [unique_id "apPls9KCPt8cS-VWcMmsaQAABB8"]
[Sun Aug 30 03:11:31.460782 2026] [security2:error] [pid 519566:tid 519814] [client 20.220.10.235:20434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/admin.php/700.php"] [unique_id "apPls9KCPt8cS-VWcMmsbAAABBk"]
[Sun Aug 30 03:11:31.467508 2026] [security2:error] [pid 519566:tid 519785] [client 20.104.50.220:29174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/images/sym.php"] [unique_id "apPls9KCPt8cS-VWcMmsdQAAA_w"]
[Sun Aug 30 03:11:31.471182 2026] [security2:error] [pid 519566:tid 519791] [client 20.104.50.220:32881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/leaf.php"] [unique_id "apPls9KCPt8cS-VWcMmsdwAABAI"]
[Sun Aug 30 03:11:31.472189 2026] [authz_core:error] [pid 519566:tid 519804] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory27
[Sun Aug 30 03:11:31.472447 2026] [authz_core:error] [pid 519566:tid 519804] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory27
[Sun Aug 30 03:11:31.505883 2026] [autoindex:error] [pid 519566:tid 519822] [client 20.104.50.220:25421] AH01276: Cannot serve directory /var/www/html/images/: No matching DirectoryIndex (index.cgi,index.php,index.html,index.htm) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:11:31.514013 2026] [security2:error] [pid 519566:tid 519707] [client 158.23.147.79:58376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-admin.php"] [unique_id "apPls9KCPt8cS-VWcMmsgQAAA64"]
[Sun Aug 30 03:11:31.518280 2026] [security2:error] [pid 519566:tid 519773] [client 20.104.50.220:62829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/eagle.php"] [unique_id "apPls9KCPt8cS-VWcMmshQAAA_A"]
[Sun Aug 30 03:11:31.531432 2026] [security2:error] [pid 519566:tid 519803] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/Module.php"] [unique_id "apPls9KCPt8cS-VWcMmsjgAABA4"]
[Sun Aug 30 03:11:31.557606 2026] [security2:error] [pid 519566:tid 519814] [client 20.48.250.41:11166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/bgymj.php"] [unique_id "apPls9KCPt8cS-VWcMmsmAAABBk"]
[Sun Aug 30 03:11:31.557606 2026] [security2:error] [pid 519566:tid 519820] [client 20.48.250.41:49374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/thui.php"] [unique_id "apPls9KCPt8cS-VWcMmslwAABB8"]
[Sun Aug 30 03:11:31.573841 2026] [security2:error] [pid 519566:tid 519796] [client 20.104.50.220:25421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/zoro.php"] [unique_id "apPls9KCPt8cS-VWcMmsnAAABAc"]
[Sun Aug 30 03:11:31.581598 2026] [security2:error] [pid 519566:tid 519792] [client 195.178.110.247:21548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mimiflores.com"] [uri "/index.php"] [unique_id "apPls9KCPt8cS-VWcMmsnQAABAM"]
[Sun Aug 30 03:11:31.582507 2026] [security2:error] [pid 519566:tid 519720] [client 20.151.200.44:46017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPls9KCPt8cS-VWcMmsngAAA7s"]
[Sun Aug 30 03:11:31.585862 2026] [security2:error] [pid 519566:tid 519738] [client 158.23.147.79:39296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-includes/plugins.php"] [unique_id "apPls9KCPt8cS-VWcMmsnwAAA80"]
[Sun Aug 30 03:11:31.588362 2026] [security2:error] [pid 519566:tid 519806] [client 20.220.10.235:20471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/admin.php/007x.php"] [unique_id "apPls9KCPt8cS-VWcMmsoAAABBE"]
[Sun Aug 30 03:11:31.618672 2026] [security2:error] [pid 519566:tid 519702] [client 20.104.50.220:42293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/shadowx.php"] [unique_id "apPls9KCPt8cS-VWcMmsqgAAA6k"]
[Sun Aug 30 03:11:31.624810 2026] [security2:error] [pid 519566:tid 519729] [client 4.205.62.107:16773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/session.php"] [unique_id "apPls9KCPt8cS-VWcMmsqwAAA8Q"]
[Sun Aug 30 03:11:31.629293 2026] [security2:error] [pid 519566:tid 519704] [client 20.104.50.220:5586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp.php"] [unique_id "apPls9KCPt8cS-VWcMmsrQAAA6s"]
[Sun Aug 30 03:11:31.633762 2026] [security2:error] [pid 519566:tid 519822] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/codeigniter/.env"] [unique_id "apPls9KCPt8cS-VWcMmsrgAABCE"]
[Sun Aug 30 03:11:31.648868 2026] [security2:error] [pid 519566:tid 519705] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/Query.php"] [unique_id "apPls9KCPt8cS-VWcMmssAAAA6w"]
[Sun Aug 30 03:11:31.661765 2026] [authz_core:error] [pid 519566:tid 519749] [client 66.249.66.64:45996] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:31.662049 2026] [authz_core:error] [pid 519566:tid 519749] [client 66.249.66.64:45996] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:31.678387 2026] [security2:error] [pid 519566:tid 519776] [client 20.48.251.3:55752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/cloud.php"] [unique_id "apPls9KCPt8cS-VWcMmstwAAA_M"]
[Sun Aug 30 03:11:31.688589 2026] [security2:error] [pid 519566:tid 519801] [client 20.48.250.41:11082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/ws69.php"] [unique_id "apPls9KCPt8cS-VWcMmsvQAABAw"]
[Sun Aug 30 03:11:31.711888 2026] [security2:error] [pid 519566:tid 519701] [client 20.48.251.3:37125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/aws-credentials.php"] [unique_id "apPls9KCPt8cS-VWcMmsywAAA6g"]
[Sun Aug 30 03:11:31.719480 2026] [authz_core:error] [pid 519566:tid 519735] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:31.719801 2026] [authz_core:error] [pid 519566:tid 519735] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:31.723801 2026] [security2:error] [pid 519566:tid 519783] [client 20.220.10.235:20431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/admin.php/heex.php"] [unique_id "apPls9KCPt8cS-VWcMms0gAAA_o"]
[Sun Aug 30 03:11:31.732693 2026] [security2:error] [pid 519566:tid 519772] [client 158.23.147.79:43630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apPls9KCPt8cS-VWcMms1wAAA-8"]
[Sun Aug 30 03:11:31.742333 2026] [security2:error] [pid 519566:tid 519762] [client 195.178.110.247:27298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mimiflores.com"] [uri "/index.php"] [unique_id "apPls9KCPt8cS-VWcMms3AAAA-U"]
[Sun Aug 30 03:11:31.747831 2026] [lsapi:error] [pid 519566:tid 519795] [client 69.243.153.173:37860] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n
[Sun Aug 30 03:11:31.747978 2026] [lsapi:error] [pid 519566:tid 519795] [client 69.243.153.173:37860] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n
[Sun Aug 30 03:11:31.749416 2026] [lsapi:error] [pid 519566:tid 519795] [client 69.243.153.173:37860] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n
[Sun Aug 30 03:11:31.765279 2026] [security2:error] [pid 519566:tid 519758] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/DB.php"] [unique_id "apPls9KCPt8cS-VWcMms6QAAA-E"]
[Sun Aug 30 03:11:31.785505 2026] [authz_core:error] [pid 519566:tid 519706] [client 66.249.66.77:35214] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:31.785770 2026] [authz_core:error] [pid 519566:tid 519706] [client 66.249.66.77:35214] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:31.793660 2026] [security2:error] [pid 519566:tid 519721] [client 20.104.18.15:31564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/run.php"] [unique_id "apPls9KCPt8cS-VWcMms9wAAA7w"]
[Sun Aug 30 03:11:31.815857 2026] [security2:error] [pid 519566:tid 519783] [client 20.104.18.15:18371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/ssla.php"] [unique_id "apPls9KCPt8cS-VWcMmtCAAAA_o"]
[Sun Aug 30 03:11:31.824780 2026] [security2:error] [pid 519566:tid 519709] [client 20.104.50.220:61980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/auto_seo.php"] [unique_id "apPls9KCPt8cS-VWcMmtCwAAA7A"]
[Sun Aug 30 03:11:31.835499 2026] [security2:error] [pid 519566:tid 519809] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/cakephp/.env"] [unique_id "apPls9KCPt8cS-VWcMmtEQAABBQ"]
[Sun Aug 30 03:11:31.842330 2026] [security2:error] [pid 519566:tid 519769] [client 20.48.250.41:49384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/Jcrop.php"] [unique_id "apPls9KCPt8cS-VWcMmtFgAAA-w"]
[Sun Aug 30 03:11:31.850191 2026] [security2:error] [pid 519566:tid 519704] [client 4.205.62.107:52810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/config_dev.php"] [unique_id "apPls9KCPt8cS-VWcMmtHgAAA6s"]
[Sun Aug 30 03:11:31.853120 2026] [security2:error] [pid 519566:tid 519722] [client 20.220.10.235:20397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/tf.php"] [unique_id "apPls9KCPt8cS-VWcMmtIAAAA70"]
[Sun Aug 30 03:11:31.853221 2026] [security2:error] [pid 519566:tid 519801] [client 20.151.200.44:41916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/file.php"] [unique_id "apPls9KCPt8cS-VWcMmtIgAABAw"]
[Sun Aug 30 03:11:31.882042 2026] [security2:error] [pid 519566:tid 519782] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/OAuth.php"] [unique_id "apPls9KCPt8cS-VWcMmtLwAAA_k"]
[Sun Aug 30 03:11:31.885815 2026] [security2:error] [pid 519566:tid 519759] [client 158.23.147.79:39333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/goat1.php"] [unique_id "apPls9KCPt8cS-VWcMmtNAAAA-I"]
[Sun Aug 30 03:11:31.906162 2026] [security2:error] [pid 519566:tid 519807] [client 20.104.50.220:50371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/dr.php"] [unique_id "apPls9KCPt8cS-VWcMmtPAAABBI"]
[Sun Aug 30 03:11:31.915320 2026] [security2:error] [pid 519566:tid 519741] [client 20.197.61.180:3835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/salient/css/build/plugins/login.php"] [unique_id "apPls9KCPt8cS-VWcMmtQgAAA9A"]
[Sun Aug 30 03:11:31.919736 2026] [security2:error] [pid 519566:tid 519772] [client 20.48.250.41:11174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/ccs.php"] [unique_id "apPls9KCPt8cS-VWcMmtQwAAA-8"]
[Sun Aug 30 03:11:31.921688 2026] [security2:error] [pid 519566:tid 519735] [client 20.104.18.15:22468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/dev.php"] [unique_id "apPls9KCPt8cS-VWcMmtRwAAA8o"]
[Sun Aug 30 03:11:31.923766 2026] [security2:error] [pid 519566:tid 519733] [client 4.205.62.107:16371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/ms-edit.php"] [unique_id "apPls9KCPt8cS-VWcMmtSQAAA8g"]
[Sun Aug 30 03:11:31.935947 2026] [security2:error] [pid 519566:tid 519659] [remote 101.101.97.26:28996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.97.101.101.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allsaintsbowie.org"] [uri "/wp-login.php"] [unique_id "apPls9KCPt8cS-VWcMmtRAAD31w"]
[Sun Aug 30 03:11:31.946689 2026] [security2:error] [pid 519566:tid 519817] [client 40.83.93.50:7058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/aa.php"] [unique_id "apPls9KCPt8cS-VWcMmtUAAABBw"]
[Sun Aug 30 03:11:31.980552 2026] [authz_core:error] [pid 519566:tid 519802] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory29
[Sun Aug 30 03:11:31.980830 2026] [authz_core:error] [pid 519566:tid 519802] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory29
[Sun Aug 30 03:11:31.985270 2026] [security2:error] [pid 519566:tid 519731] [client 20.220.10.235:20462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/update/da222.php"] [unique_id "apPls9KCPt8cS-VWcMmtZAAAA8Y"]
[Sun Aug 30 03:11:31.994865 2026] [security2:error] [pid 519566:tid 519798] [client 20.48.250.41:49320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/ws58.php"] [unique_id "apPls9KCPt8cS-VWcMmtaQAABAk"]
[Sun Aug 30 03:11:31.996129 2026] [authz_core:error] [pid 519566:tid 519805] [client 66.249.66.205:44548] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:31.996398 2026] [authz_core:error] [pid 519566:tid 519805] [client 66.249.66.205:44548] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:31.998996 2026] [security2:error] [pid 519566:tid 519766] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/Nonce.php"] [unique_id "apPls9KCPt8cS-VWcMmtbgAAA-k"]
[Sun Aug 30 03:11:32.009268 2026] [security2:error] [pid 519566:tid 519784] [client 68.155.159.216:54282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apPltNKCPt8cS-VWcMmtdgAAA_s"]
[Sun Aug 30 03:11:32.019124 2026] [security2:error] [pid 519566:tid 519750] [client 158.23.147.79:43634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-includes/certificates/index.php"] [unique_id "apPltNKCPt8cS-VWcMmtegAAA9k"]
[Sun Aug 30 03:11:32.037123 2026] [security2:error] [pid 519566:tid 519714] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/zend/.env"] [unique_id "apPltNKCPt8cS-VWcMmthAAAA7U"]
[Sun Aug 30 03:11:32.048983 2026] [security2:error] [pid 519566:tid 519730] [client 20.48.250.41:11196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/mar.php"] [unique_id "apPltNKCPt8cS-VWcMmtigAAA8U"]
[Sun Aug 30 03:11:32.053393 2026] [authz_core:error] [pid 519566:tid 519721] [client 66.249.66.75:63107] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:32.053833 2026] [authz_core:error] [pid 519566:tid 519721] [client 66.249.66.75:63107] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:32.066001 2026] [security2:error] [pid 519566:tid 519758] [client 20.104.49.130:53571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/dragonshell.php"] [unique_id "apPltNKCPt8cS-VWcMmtjQAAA-E"]
[Sun Aug 30 03:11:32.114258 2026] [security2:error] [pid 519566:tid 519806] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/common.php"] [unique_id "apPltNKCPt8cS-VWcMmtnQAABBE"]
[Sun Aug 30 03:11:32.115121 2026] [security2:error] [pid 519566:tid 519780] [client 20.220.10.235:20371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/qi.php"] [unique_id "apPltNKCPt8cS-VWcMmtnwAAA_c"]
[Sun Aug 30 03:11:32.124889 2026] [authz_core:error] [pid 519566:tid 519822] [client 216.73.216.128:54671] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:32.125158 2026] [authz_core:error] [pid 519566:tid 519822] [client 216.73.216.128:54671] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:32.171188 2026] [security2:error] [pid 519566:tid 519762] [client 20.104.18.15:16914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/wp-aothait.php"] [unique_id "apPltNKCPt8cS-VWcMmtswAAA-U"]
[Sun Aug 30 03:11:32.178564 2026] [authz_core:error] [pid 519566:tid 519815] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:32.178844 2026] [authz_core:error] [pid 519566:tid 519815] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:32.184921 2026] [security2:error] [pid 519566:tid 519775] [client 158.23.147.79:43015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-admin/network/index.php"] [unique_id "apPltNKCPt8cS-VWcMmtuQAAA_I"]
[Sun Aug 30 03:11:32.201990 2026] [security2:error] [pid 519566:tid 519729] [client 20.48.250.41:11130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/ccu.php"] [unique_id "apPltNKCPt8cS-VWcMmtwgAAA8Q"]
[Sun Aug 30 03:11:32.216531 2026] [security2:error] [pid 519566:tid 519808] [client 20.48.251.3:59485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/h.php"] [unique_id "apPltNKCPt8cS-VWcMmtxgAABBM"]
[Sun Aug 30 03:11:32.229743 2026] [security2:error] [pid 519566:tid 519758] [client 20.48.250.41:19426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/xs.php"] [unique_id "apPltNKCPt8cS-VWcMmtyQAAA-E"]
[Sun Aug 30 03:11:32.233850 2026] [security2:error] [pid 519566:tid 519782] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/Block.php"] [unique_id "apPltNKCPt8cS-VWcMmtzQAAA_k"]
[Sun Aug 30 03:11:32.240410 2026] [security2:error] [pid 519566:tid 519739] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/yii/.env"] [unique_id "apPltNKCPt8cS-VWcMmt0AAAA84"]
[Sun Aug 30 03:11:32.248382 2026] [security2:error] [pid 519566:tid 519818] [client 20.220.10.235:20430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/px.php"] [unique_id "apPltNKCPt8cS-VWcMmt1AAABB0"]
[Sun Aug 30 03:11:32.285500 2026] [security2:error] [pid 519566:tid 519754] [client 68.155.159.216:57080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apPltNKCPt8cS-VWcMmt3gAAA90"]
[Sun Aug 30 03:11:32.311437 2026] [security2:error] [pid 519566:tid 519775] [client 158.23.147.79:43328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apPltNKCPt8cS-VWcMmt5gAAA_I"]
[Sun Aug 30 03:11:32.335863 2026] [security2:error] [pid 519566:tid 519718] [client 20.48.250.41:11190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/ak.php"] [unique_id "apPltNKCPt8cS-VWcMmt6wAAA7k"]
[Sun Aug 30 03:11:32.352063 2026] [authz_core:error] [pid 519566:tid 519796] [client 66.249.66.194:37878] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:32.352316 2026] [authz_core:error] [pid 519566:tid 519796] [client 66.249.66.194:37878] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:32.357072 2026] [security2:error] [pid 519566:tid 519801] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp-Block.php"] [unique_id "apPltNKCPt8cS-VWcMmt8QAABAw"]
[Sun Aug 30 03:11:32.384466 2026] [security2:error] [pid 519566:tid 519748] [client 20.104.50.220:17314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/ar.php"] [unique_id "apPltNKCPt8cS-VWcMmt-AAAA9c"]
[Sun Aug 30 03:11:32.390153 2026] [authz_core:error] [pid 519566:tid 519723] [client 216.73.216.128:54671] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:32.390428 2026] [authz_core:error] [pid 519566:tid 519723] [client 216.73.216.128:54671] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:32.391323 2026] [security2:error] [pid 519566:tid 519713] [client 20.220.10.235:20463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/is.php"] [unique_id "apPltNKCPt8cS-VWcMmt_gAAA7Q"]
[Sun Aug 30 03:11:32.437196 2026] [security2:error] [pid 519566:tid 519715] [client 158.23.147.79:43586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/.well-knownold/index.php"] [unique_id "apPltNKCPt8cS-VWcMmuCgAAA7Y"]
[Sun Aug 30 03:11:32.442040 2026] [security2:error] [pid 519566:tid 519724] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/laravel5/.env"] [unique_id "apPltNKCPt8cS-VWcMmuDQAAA78"]
[Sun Aug 30 03:11:32.448592 2026] [security2:error] [pid 519566:tid 519754] [client 20.104.18.15:51186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/bulet.php"] [unique_id "apPltNKCPt8cS-VWcMmuEgAAA90"]
[Sun Aug 30 03:11:32.457271 2026] [authz_core:error] [pid 519566:tid 519822] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory20
[Sun Aug 30 03:11:32.457598 2026] [authz_core:error] [pid 519566:tid 519822] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory20
[Sun Aug 30 03:11:32.461366 2026] [security2:error] [pid 519566:tid 519738] [client 4.205.62.107:36706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/bigdump.php"] [unique_id "apPltNKCPt8cS-VWcMmuHQAAA80"]
[Sun Aug 30 03:11:32.464785 2026] [security2:error] [pid 519566:tid 519669] [remote 101.101.97.26:28996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.97.101.101.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allsaintsbowie.org"] [uri "/wp-login.php"] [unique_id "apPltNKCPt8cS-VWcMmuIgADu2Y"], referer: https://allsaintsbowie.org/wp-login.php
[Sun Aug 30 03:11:32.466096 2026] [security2:error] [pid 519566:tid 519802] [client 40.83.93.50:7056] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webmail.thebelgradegroup.com"] [uri "/c99.php"] [unique_id "apPltNKCPt8cS-VWcMmuJAAABA0"]
[Sun Aug 30 03:11:32.475606 2026] [security2:error] [pid 519566:tid 519698] [client 4.205.62.107:26996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/mamzi.php"] [unique_id "apPltNKCPt8cS-VWcMmuJwAAA6U"]
[Sun Aug 30 03:11:32.475769 2026] [security2:error] [pid 519566:tid 519722] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/yes.php"] [unique_id "apPltNKCPt8cS-VWcMmuKAAAA70"]
[Sun Aug 30 03:11:32.483931 2026] [security2:error] [pid 519566:tid 519705] [client 20.151.200.44:65452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/im.php"] [unique_id "apPltNKCPt8cS-VWcMmuMAAAA6w"]
[Sun Aug 30 03:11:32.494273 2026] [security2:error] [pid 519566:tid 519798] [client 20.48.250.41:11012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/lib.php"] [unique_id "apPltNKCPt8cS-VWcMmuNAAABAk"]
[Sun Aug 30 03:11:32.526150 2026] [security2:error] [pid 519566:tid 519755] [client 66.249.66.76:49703] ModSecurity: Access denied with code 400 (phase 2). Invalid URL Encoding: Not enough characters at the end of input at REQUEST_URI. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "67"] [id "390703"] [rev "5"] [msg "Atomicorp.com WAF Rules: Possible URL Encoding Abuse Attack Attempt"] [severity "NOTICE"] [hostname "www.ltr7.com"] [uri "/"] [unique_id "apPltNKCPt8cS-VWcMmuQQAAA94"]
[Sun Aug 30 03:11:32.528850 2026] [security2:error] [pid 519566:tid 519809] [client 20.220.10.235:20390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/od.php"] [unique_id "apPltNKCPt8cS-VWcMmuQwAABBQ"]
[Sun Aug 30 03:11:32.541199 2026] [authz_core:error] [pid 519566:tid 519759] [client 66.249.66.32:44366] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:32.541597 2026] [authz_core:error] [pid 519566:tid 519759] [client 66.249.66.32:44366] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:32.557592 2026] [security2:error] [pid 519566:tid 519801] [client 20.48.250.41:49360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/zu.php"] [unique_id "apPltNKCPt8cS-VWcMmuVAAABAw"]
[Sun Aug 30 03:11:32.592290 2026] [security2:error] [pid 519566:tid 519718] [client 20.48.251.3:64316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/mcebraed.php"] [unique_id "apPltNKCPt8cS-VWcMmuXgAAA7k"]
[Sun Aug 30 03:11:32.598340 2026] [security2:error] [pid 519566:tid 519703] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/2008.php"] [unique_id "apPltNKCPt8cS-VWcMmuYQAAA6o"]
[Sun Aug 30 03:11:32.606050 2026] [security2:error] [pid 519566:tid 519697] [client 20.104.50.220:29609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/images/shell.php"] [unique_id "apPltNKCPt8cS-VWcMmuZQAAA6Q"]
[Sun Aug 30 03:11:32.606731 2026] [security2:error] [pid 519566:tid 519770] [client 20.104.50.220:32865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/FoxWSOv1.php"] [unique_id "apPltNKCPt8cS-VWcMmuZgAAA-0"]
[Sun Aug 30 03:11:32.622081 2026] [security2:error] [pid 519566:tid 519782] [client 20.197.61.180:3799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/security.php"] [unique_id "apPltNKCPt8cS-VWcMmuagAAA_k"]
[Sun Aug 30 03:11:32.644729 2026] [security2:error] [pid 519566:tid 519773] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/v1/.env"] [unique_id "apPltNKCPt8cS-VWcMmubAAAA_A"]
[Sun Aug 30 03:11:32.667412 2026] [security2:error] [pid 519566:tid 519746] [client 158.23.147.79:39354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apPltNKCPt8cS-VWcMmucgAAA9U"]
[Sun Aug 30 03:11:32.667458 2026] [authz_core:error] [pid 519566:tid 519797] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:32.667923 2026] [authz_core:error] [pid 519566:tid 519797] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:32.671757 2026] [security2:error] [pid 519566:tid 519719] [client 20.220.10.235:20369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/wp-the.php"] [unique_id "apPltNKCPt8cS-VWcMmudQAAA7o"]
[Sun Aug 30 03:11:32.674033 2026] [security2:error] [pid 519566:tid 519780] [client 20.104.50.220:29157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/Eagle.php"] [unique_id "apPltNKCPt8cS-VWcMmudwAAA_c"]
[Sun Aug 30 03:11:32.699176 2026] [security2:error] [pid 519566:tid 519758] [client 20.48.250.41:11175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/wp-style.php"] [unique_id "apPltNKCPt8cS-VWcMmuhwAAA-E"]
[Sun Aug 30 03:11:32.715834 2026] [security2:error] [pid 519566:tid 519770] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/wp-cli.php"] [unique_id "apPltNKCPt8cS-VWcMmukQAAA-0"]
[Sun Aug 30 03:11:32.725677 2026] [security2:error] [pid 519566:tid 519739] [client 20.104.50.220:24850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/wm.php"] [unique_id "apPltNKCPt8cS-VWcMmulgAAA84"]
[Sun Aug 30 03:11:32.757868 2026] [security2:error] [pid 519566:tid 519735] [client 20.104.50.220:51604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/hexor.php"] [unique_id "apPltNKCPt8cS-VWcMmupgAAA8o"]
[Sun Aug 30 03:11:32.763618 2026] [security2:error] [pid 519566:tid 519712] [client 4.205.62.107:17671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/h.php"] [unique_id "apPltNKCPt8cS-VWcMmuqgAAA7M"]
[Sun Aug 30 03:11:32.770349 2026] [security2:error] [pid 519566:tid 519815] [client 158.23.147.79:43061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPltNKCPt8cS-VWcMmurQAABBo"]
[Sun Aug 30 03:11:32.777505 2026] [security2:error] [pid 519566:tid 519696] [client 20.104.50.220:6110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/readme.php"] [unique_id "apPltNKCPt8cS-VWcMmusgAAA6M"]
[Sun Aug 30 03:11:32.805992 2026] [security2:error] [pid 519566:tid 519801] [client 20.220.10.235:20477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/wt.php"] [unique_id "apPltNKCPt8cS-VWcMmuwQAABAw"]
[Sun Aug 30 03:11:32.809259 2026] [security2:error] [pid 519566:tid 519704] [client 20.48.250.41:49385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/lanka.php"] [unique_id "apPltNKCPt8cS-VWcMmuwwAAA6s"]
[Sun Aug 30 03:11:32.816117 2026] [security2:error] [pid 519566:tid 519770] [client 20.48.251.3:42388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/asdf.php"] [unique_id "apPltNKCPt8cS-VWcMmuxgAAA-0"]
[Sun Aug 30 03:11:32.818624 2026] [security2:error] [pid 519566:tid 519798] [client 20.151.200.44:62912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/blnux.php"] [unique_id "apPltNKCPt8cS-VWcMmuxwAABAk"]
[Sun Aug 30 03:11:32.818851 2026] [security2:error] [pid 519566:tid 519766] [client 20.104.49.130:43644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/read.php"] [unique_id "apPltNKCPt8cS-VWcMmuyAAAA-k"]
[Sun Aug 30 03:11:32.819677 2026] [authz_core:error] [pid 519566:tid 519786] [client 66.249.66.65:54365] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:32.819941 2026] [authz_core:error] [pid 519566:tid 519786] [client 66.249.66.65:54365] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:32.838458 2026] [security2:error] [pid 519566:tid 519816] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/cong.php"] [unique_id "apPltNKCPt8cS-VWcMmu0QAABBs"]
[Sun Aug 30 03:11:32.839703 2026] [lsapi:warn] [pid 519566:tid 519675] [remote 69.171.231.3:64682] [host mail.tastylandscape.com] Backend log: PHP Warning: Use of undefined constant user_level - assumed 'user_level' (this will throw an Error in a future version of PHP) in /home4/tommed/public_html/wp-content/plugins/ultimate-google-analytics/ultimate_ga.php on line 524\n
[Sun Aug 30 03:11:32.846704 2026] [security2:error] [pid 519566:tid 519811] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/v2/.env"] [unique_id "apPltNKCPt8cS-VWcMmu1QAABBY"]
[Sun Aug 30 03:11:32.847196 2026] [authz_core:error] [pid 519566:tid 519780] [client 66.249.66.78:40680] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:32.847459 2026] [authz_core:error] [pid 519566:tid 519780] [client 66.249.66.78:40680] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:32.849820 2026] [security2:error] [pid 519566:tid 519778] [client 20.48.250.41:11223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/browse.php"] [unique_id "apPltNKCPt8cS-VWcMmu2wAAA_U"]
[Sun Aug 30 03:11:32.864997 2026] [security2:error] [pid 519566:tid 519746] [client 20.48.251.3:36847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/4563.php"] [unique_id "apPltNKCPt8cS-VWcMmu4QAAA9U"]
[Sun Aug 30 03:11:32.895161 2026] [security2:error] [pid 519566:tid 519740] [client 158.23.147.79:43031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/images/index.php"] [unique_id "apPltNKCPt8cS-VWcMmu6AAAA88"]
[Sun Aug 30 03:11:32.929581 2026] [security2:error] [pid 519566:tid 519787] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/.env.swp"] [unique_id "apPltNKCPt8cS-VWcMmu9QAAA_4"]
[Sun Aug 30 03:11:32.935675 2026] [security2:error] [pid 519566:tid 519822] [client 20.220.10.235:20367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/im.php"] [unique_id "apPltNKCPt8cS-VWcMmu-AAABCE"]
[Sun Aug 30 03:11:32.951230 2026] [security2:error] [pid 519566:tid 519733] [client 40.83.93.50:10749] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webmail.thebelgradegroup.com"] [uri "/c99.php"] [unique_id "apPltNKCPt8cS-VWcMmvAQAAA8g"]
[Sun Aug 30 03:11:32.957955 2026] [security2:error] [pid 519566:tid 519752] [client 20.104.18.15:31620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/new.php"] [unique_id "apPltNKCPt8cS-VWcMmvBgAAA9s"]
[Sun Aug 30 03:11:32.976175 2026] [security2:error] [pid 519566:tid 519735] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/getid3s.php"] [unique_id "apPltNKCPt8cS-VWcMmvDAAAA8o"]
[Sun Aug 30 03:11:32.976879 2026] [security2:error] [pid 519566:tid 519742] [client 20.104.50.220:61964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/alone.php"] [unique_id "apPltNKCPt8cS-VWcMmvDQAAA9E"]
[Sun Aug 30 03:11:32.978388 2026] [security2:error] [pid 519566:tid 519814] [client 20.48.250.41:11098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/zoo.php"] [unique_id "apPltNKCPt8cS-VWcMmvDwAABBk"]
[Sun Aug 30 03:11:32.982830 2026] [security2:error] [pid 519566:tid 519810] [client 20.104.18.15:18355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apPltNKCPt8cS-VWcMmvFAAABBU"]
[Sun Aug 30 03:11:32.991454 2026] [authz_core:error] [pid 519566:tid 519720] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory24
[Sun Aug 30 03:11:32.991850 2026] [authz_core:error] [pid 519566:tid 519720] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory24
[Sun Aug 30 03:11:33.031549 2026] [security2:error] [pid 519566:tid 519761] [client 158.23.147.79:39136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-includes/widgets/index.php"] [unique_id "apPltdKCPt8cS-VWcMmvLwAAA-Q"]
[Sun Aug 30 03:11:33.031623 2026] [security2:error] [pid 519566:tid 519788] [client 20.48.250.41:19410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/gettest.php"] [unique_id "apPltdKCPt8cS-VWcMmvLgAAA_8"]
[Sun Aug 30 03:11:33.049046 2026] [security2:error] [pid 519566:tid 519702] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/v3/.env"] [unique_id "apPltdKCPt8cS-VWcMmvOgAAA6k"]
[Sun Aug 30 03:11:33.051088 2026] [security2:error] [pid 519566:tid 519742] [client 4.205.62.107:52915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/aws_credentials.php"] [unique_id "apPltdKCPt8cS-VWcMmvOwAAA9E"]
[Sun Aug 30 03:11:33.054289 2026] [security2:error] [pid 519566:tid 519814] [client 4.205.62.107:16369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/lmfi2.php"] [unique_id "apPltdKCPt8cS-VWcMmvPgAABBk"]
[Sun Aug 30 03:11:33.055811 2026] [security2:error] [pid 519566:tid 519804] [client 20.104.50.220:31532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/xamp.php"] [unique_id "apPltdKCPt8cS-VWcMmvPwAABA8"]
[Sun Aug 30 03:11:33.073011 2026] [security2:error] [pid 519566:tid 519731] [client 20.220.10.235:20293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/file.php"] [unique_id "apPltdKCPt8cS-VWcMmvQQAAA8Y"]
[Sun Aug 30 03:11:33.090967 2026] [security2:error] [pid 519566:tid 519794] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/.env~"] [unique_id "apPltdKCPt8cS-VWcMmvRAAABAU"]
[Sun Aug 30 03:11:33.094302 2026] [security2:error] [pid 519566:tid 519762] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/row.php"] [unique_id "apPltdKCPt8cS-VWcMmvSAAAA-U"]
[Sun Aug 30 03:11:33.114125 2026] [security2:error] [pid 519566:tid 519763] [client 20.104.18.15:22373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/gos.php"] [unique_id "apPltdKCPt8cS-VWcMmvUwAAA-Y"]
[Sun Aug 30 03:11:33.134729 2026] [security2:error] [pid 519566:tid 519727] [client 68.155.159.216:6083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/goat1.php"] [unique_id "apPltdKCPt8cS-VWcMmvXwAAA8I"]
[Sun Aug 30 03:11:33.137772 2026] [authz_core:error] [pid 519566:tid 519797] [client 66.249.66.64:57231] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:33.138194 2026] [authz_core:error] [pid 519566:tid 519797] [client 66.249.66.64:57231] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:33.146237 2026] [authz_core:error] [pid 519566:tid 519696] [client 66.249.66.64:45996] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:33.146706 2026] [authz_core:error] [pid 519566:tid 519696] [client 66.249.66.64:45996] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:33.163970 2026] [security2:error] [pid 519566:tid 519719] [client 20.48.250.41:11218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/elp.php"] [unique_id "apPltdKCPt8cS-VWcMmvZQAAA7o"]
[Sun Aug 30 03:11:33.167601 2026] [security2:error] [pid 519566:tid 519732] [client 158.23.147.79:43615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apPltdKCPt8cS-VWcMmvaAAAA8c"]
[Sun Aug 30 03:11:33.187777 2026] [security2:error] [pid 519566:tid 519740] [client 20.48.250.41:49399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/35.php"] [unique_id "apPltdKCPt8cS-VWcMmvdgAAA88"]
[Sun Aug 30 03:11:33.197917 2026] [authz_core:error] [pid 519566:tid 519706] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:33.198191 2026] [authz_core:error] [pid 519566:tid 519706] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:33.206463 2026] [security2:error] [pid 519566:tid 519788] [client 20.220.10.235:20381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/ca.php"] [unique_id "apPltdKCPt8cS-VWcMmvgQAAA_8"]
[Sun Aug 30 03:11:33.212507 2026] [security2:error] [pid 519566:tid 519796] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/export.php"] [unique_id "apPltdKCPt8cS-VWcMmvhAAABAc"]
[Sun Aug 30 03:11:33.223661 2026] [authz_core:error] [pid 519566:tid 519806] [client 216.73.216.128:13745] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:33.223940 2026] [authz_core:error] [pid 519566:tid 519806] [client 216.73.216.128:13745] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:33.236461 2026] [authz_core:error] [pid 519566:tid 519775] [client 66.249.66.75:53878] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:33.236749 2026] [authz_core:error] [pid 519566:tid 519775] [client 66.249.66.75:53878] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:33.251539 2026] [security2:error] [pid 519566:tid 519705] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/api/v1/.env"] [unique_id "apPltdKCPt8cS-VWcMmvmAAAA6w"]
[Sun Aug 30 03:11:33.254927 2026] [authz_core:error] [pid 519566:tid 519741] [client 66.249.66.199:47430] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:33.255326 2026] [authz_core:error] [pid 519566:tid 519741] [client 66.249.66.199:47430] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:33.288585 2026] [security2:error] [pid 519566:tid 519756] [client 158.23.147.79:39305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apPltdKCPt8cS-VWcMmvowAAA98"]
[Sun Aug 30 03:11:33.296167 2026] [security2:error] [pid 519566:tid 519743] [client 20.48.250.41:11119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/666.php"] [unique_id "apPltdKCPt8cS-VWcMmvpQAAA9I"]
[Sun Aug 30 03:11:33.319038 2026] [fcgid:warn] [pid 519566:tid 519750] (70014)End of file found: [client 199.45.154.115:53358] mod_fcgid: can't get data from http client
[Sun Aug 30 03:11:33.326328 2026] [security2:error] [pid 519566:tid 519798] [client 20.48.250.41:49327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/maraz.php"] [unique_id "apPltdKCPt8cS-VWcMmvqwAABAk"]
[Sun Aug 30 03:11:33.343128 2026] [security2:error] [pid 519566:tid 519787] [client 20.220.10.235:20317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/pb.php"] [unique_id "apPltdKCPt8cS-VWcMmvtAAAA_4"]
[Sun Aug 30 03:11:33.343170 2026] [security2:error] [pid 519566:tid 519704] [client 20.104.18.15:16966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/wp-includes/index.php"] [unique_id "apPltdKCPt8cS-VWcMmvswAAA6s"]
[Sun Aug 30 03:11:33.343267 2026] [security2:error] [pid 519566:tid 519734] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/boot-fs.php"] [unique_id "apPltdKCPt8cS-VWcMmvtQAAA8k"]
[Sun Aug 30 03:11:33.345609 2026] [authz_core:error] [pid 519566:tid 519718] [client 216.73.216.128:40285] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:33.345902 2026] [authz_core:error] [pid 519566:tid 519718] [client 216.73.216.128:40285] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:33.348866 2026] [security2:error] [pid 519566:tid 519811] [client 20.48.251.3:52280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/bootstrap.php"] [unique_id "apPltdKCPt8cS-VWcMmvuQAABBY"]
[Sun Aug 30 03:11:33.350052 2026] [security2:error] [pid 519566:tid 519755] [client 20.197.61.180:3838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "apPltdKCPt8cS-VWcMmvugAAA94"]
[Sun Aug 30 03:11:33.369480 2026] [lsapi:error] [pid 519566:tid 519683] [remote 68.2.124.49:43172] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n
[Sun Aug 30 03:11:33.369611 2026] [lsapi:error] [pid 519566:tid 519683] [remote 68.2.124.49:43172] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n
[Sun Aug 30 03:11:33.371074 2026] [lsapi:error] [pid 519566:tid 519683] [remote 68.2.124.49:43172] [host www.gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n
[Sun Aug 30 03:11:33.405594 2026] [security2:error] [pid 519566:tid 519720] [client 158.23.147.79:58419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-includes/assets/index.php"] [unique_id "apPltdKCPt8cS-VWcMmvygAAA7s"]
[Sun Aug 30 03:11:33.430111 2026] [security2:error] [pid 519566:tid 519807] [client 20.48.250.41:11113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/knmt.php"] [unique_id "apPltdKCPt8cS-VWcMmv2QAABBI"]
[Sun Aug 30 03:11:33.436357 2026] [authz_core:error] [pid 519566:tid 519730] [client 216.73.216.128:54671] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:33.436614 2026] [authz_core:error] [pid 519566:tid 519730] [client 216.73.216.128:54671] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:33.443531 2026] [security2:error] [pid 519566:tid 519765] [client 40.83.93.50:6789] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webmail.thebelgradegroup.com"] [uri "/c99.php"] [unique_id "apPltdKCPt8cS-VWcMmv5QAAA-g"]
[Sun Aug 30 03:11:33.450820 2026] [authz_core:error] [pid 519566:tid 519759] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory25
[Sun Aug 30 03:11:33.451246 2026] [authz_core:error] [pid 519566:tid 519759] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory25
[Sun Aug 30 03:11:33.454043 2026] [security2:error] [pid 519566:tid 519772] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/api/v2/.env"] [unique_id "apPltdKCPt8cS-VWcMmv5wAAA-8"]
[Sun Aug 30 03:11:33.460815 2026] [security2:error] [pid 519566:tid 519715] [client 158.23.147.79:43032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-includes/pomo/index.php"] [unique_id "apPltdKCPt8cS-VWcMmv8AAAA7Y"]
[Sun Aug 30 03:11:33.468203 2026] [security2:error] [pid 519566:tid 519806] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/taxonomy.php"] [unique_id "apPltdKCPt8cS-VWcMmv9gAABBE"]
[Sun Aug 30 03:11:33.483367 2026] [security2:error] [pid 519566:tid 519792] [client 20.220.10.235:20398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/pk.php"] [unique_id "apPltdKCPt8cS-VWcMmv_AAABAM"]
[Sun Aug 30 03:11:33.492731 2026] [security2:error] [pid 519566:tid 519732] [client 20.48.250.41:49294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/kbfr.php"] [unique_id "apPltdKCPt8cS-VWcMmv_wAAA8c"]
[Sun Aug 30 03:11:33.516566 2026] [security2:error] [pid 519566:tid 519736] [client 20.151.200.44:65365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/file.php"] [unique_id "apPltdKCPt8cS-VWcMmwBQAAA8s"]
[Sun Aug 30 03:11:33.521478 2026] [security2:error] [pid 519566:tid 519738] [client 20.104.50.220:16710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/x.php"] [unique_id "apPltdKCPt8cS-VWcMmwDAAAA80"]
[Sun Aug 30 03:11:33.536402 2026] [core:alert] [pid 519566:tid 519703] [client 41.24.90.51:51006] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:11:33.586672 2026] [security2:error] [pid 519566:tid 519773] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/g3.php"] [unique_id "apPltdKCPt8cS-VWcMmwIgAAA_A"]
[Sun Aug 30 03:11:33.587714 2026] [security2:error] [pid 519566:tid 519716] [client 20.104.18.15:51157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/av.php"] [unique_id "apPltdKCPt8cS-VWcMmwIwAAA7c"]
[Sun Aug 30 03:11:33.617423 2026] [security2:error] [pid 519566:tid 519769] [client 20.48.250.41:11243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/sbhu.php"] [unique_id "apPltdKCPt8cS-VWcMmwLQAAA-w"]
[Sun Aug 30 03:11:33.617528 2026] [security2:error] [pid 519566:tid 519747] [client 20.220.10.235:20332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/ft.php"] [unique_id "apPltdKCPt8cS-VWcMmwLgAAA9Y"]
[Sun Aug 30 03:11:33.624200 2026] [authz_core:error] [pid 519566:tid 519698] [client 216.73.216.128:13745] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:33.624560 2026] [authz_core:error] [pid 519566:tid 519698] [client 216.73.216.128:13745] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:33.626525 2026] [security2:error] [pid 519566:tid 519707] [client 20.48.250.41:19347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/wp-act.php"] [unique_id "apPltdKCPt8cS-VWcMmwMQAAA64"]
[Sun Aug 30 03:11:33.643463 2026] [security2:error] [pid 519566:tid 519731] [client 158.23.147.79:39158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/nf_tracking.php"] [unique_id "apPltdKCPt8cS-VWcMmwNgAAA8Y"]
[Sun Aug 30 03:11:33.653785 2026] [security2:error] [pid 519566:tid 519743] [client 4.205.62.107:25517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/public/rip.php.php"] [unique_id "apPltdKCPt8cS-VWcMmwOAAAA9I"]
[Sun Aug 30 03:11:33.656428 2026] [security2:error] [pid 519566:tid 519703] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/rest/.env"] [unique_id "apPltdKCPt8cS-VWcMmwOQAAA6o"]
[Sun Aug 30 03:11:33.667470 2026] [security2:error] [pid 519566:tid 519822] [client 20.104.49.130:26934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/yawa.php"] [unique_id "apPltdKCPt8cS-VWcMmwQgAABCE"]
[Sun Aug 30 03:11:33.670115 2026] [authz_core:error] [pid 519566:tid 519798] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:33.670390 2026] [authz_core:error] [pid 519566:tid 519798] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:33.685173 2026] [autoindex:error] [pid 519566:tid 519721] [client 139.28.219.68:0] AH01276: Cannot serve directory /home1/jacob511/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:11:33.700604 2026] [authz_core:error] [pid 519566:tid 519767] [client 66.249.66.77:40867] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:33.700969 2026] [authz_core:error] [pid 519566:tid 519767] [client 66.249.66.77:40867] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:33.709703 2026] [security2:error] [pid 519566:tid 519799] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/Yamarket.php"] [unique_id "apPltdKCPt8cS-VWcMmwXAAABAo"]
[Sun Aug 30 03:11:33.734690 2026] [security2:error] [pid 519566:tid 519743] [client 68.155.159.216:12240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPltdKCPt8cS-VWcMmwaAAAA9I"]
[Sun Aug 30 03:11:33.736480 2026] [security2:error] [pid 519566:tid 519734] [client 158.23.147.79:39147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wzy.php"] [unique_id "apPltdKCPt8cS-VWcMmwaQAAA8k"]
[Sun Aug 30 03:11:33.745450 2026] [security2:error] [pid 519566:tid 519810] [client 20.220.10.235:20370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/wp-ver.php"] [unique_id "apPltdKCPt8cS-VWcMmwbAAABBU"]
[Sun Aug 30 03:11:33.747211 2026] [security2:error] [pid 519566:tid 519704] [client 20.104.50.220:33307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/foxwsov1.php"] [unique_id "apPltdKCPt8cS-VWcMmwbgAAA6s"]
[Sun Aug 30 03:11:33.752712 2026] [security2:error] [pid 519566:tid 519778] [client 20.104.50.220:52835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/images/mini.php"] [unique_id "apPltdKCPt8cS-VWcMmwcAAAA_U"]
[Sun Aug 30 03:11:33.766011 2026] [security2:error] [pid 519566:tid 519806] [client 20.48.250.41:11142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/a332.php"] [unique_id "apPltdKCPt8cS-VWcMmwdwAABBE"]
[Sun Aug 30 03:11:33.771667 2026] [authz_core:error] [pid 519566:tid 519791] [client 66.249.66.192:43237] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:33.772148 2026] [authz_core:error] [pid 519566:tid 519791] [client 66.249.66.192:43237] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:33.821636 2026] [security2:error] [pid 519566:tid 519792] [client 20.48.251.3:54731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/server-info.php"] [unique_id "apPltdKCPt8cS-VWcMmwkwAABAM"]
[Sun Aug 30 03:11:33.826260 2026] [security2:error] [pid 519566:tid 519736] [client 20.151.200.44:45958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/h02ugyh.php"] [unique_id "apPltdKCPt8cS-VWcMmwlQAAA8s"]
[Sun Aug 30 03:11:33.828408 2026] [security2:error] [pid 519566:tid 519734] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/globales.php"] [unique_id "apPltdKCPt8cS-VWcMmwlgAAA8k"]
[Sun Aug 30 03:11:33.830375 2026] [security2:error] [pid 519566:tid 519796] [client 20.104.50.220:29176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/.error_log.php"] [unique_id "apPltdKCPt8cS-VWcMmwmAAABAc"]
[Sun Aug 30 03:11:33.843023 2026] [security2:error] [pid 519566:tid 519775] [client 4.205.62.107:36679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/wdf.php"] [unique_id "apPltdKCPt8cS-VWcMmwngAAA_I"]
[Sun Aug 30 03:11:33.857904 2026] [security2:error] [pid 519566:tid 519820] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/graphql/.env"] [unique_id "apPltdKCPt8cS-VWcMmwowAABB8"]
[Sun Aug 30 03:11:33.867981 2026] [security2:error] [pid 519566:tid 519700] [client 158.23.147.79:43635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-admin/setup-config.php"] [unique_id "apPltdKCPt8cS-VWcMmwqgAAA6c"]
[Sun Aug 30 03:11:33.880315 2026] [security2:error] [pid 519566:tid 519776] [client 20.104.50.220:25437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/bajah.php"] [unique_id "apPltdKCPt8cS-VWcMmwrgAAA_M"]
[Sun Aug 30 03:11:33.883283 2026] [security2:error] [pid 519566:tid 519798] [client 20.48.250.41:49332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/24.php"] [unique_id "apPltdKCPt8cS-VWcMmwsQAABAk"]
[Sun Aug 30 03:11:33.896321 2026] [security2:error] [pid 519566:tid 519805] [client 20.220.10.235:20458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/ah24.php"] [unique_id "apPltdKCPt8cS-VWcMmwtgAABBA"]
[Sun Aug 30 03:11:33.901738 2026] [security2:error] [pid 519566:tid 519731] [client 4.205.62.107:17119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/bootstrap.php"] [unique_id "apPltdKCPt8cS-VWcMmwuQAAA8Y"]
[Sun Aug 30 03:11:33.914546 2026] [security2:error] [pid 519566:tid 519800] [client 40.83.93.50:10736] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webmail.thebelgradegroup.com"] [uri "/c99.php"] [unique_id "apPltdKCPt8cS-VWcMmwvwAABAs"]
[Sun Aug 30 03:11:33.931594 2026] [security2:error] [pid 519566:tid 519770] [client 20.104.50.220:6112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/error_log.php"] [unique_id "apPltdKCPt8cS-VWcMmwwwAAA-0"]
[Sun Aug 30 03:11:33.936033 2026] [security2:error] [pid 519566:tid 519748] [client 20.48.250.41:11185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/ws66.php"] [unique_id "apPltdKCPt8cS-VWcMmwxAAAA9c"]
[Sun Aug 30 03:11:33.940950 2026] [security2:error] [pid 519566:tid 519736] [client 20.104.50.220:42785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/leaf.php"] [unique_id "apPltdKCPt8cS-VWcMmwyAAAA8s"]
[Sun Aug 30 03:11:33.949031 2026] [security2:error] [pid 519566:tid 519810] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/init.php"] [unique_id "apPltdKCPt8cS-VWcMmwzAAABBU"]
[Sun Aug 30 03:11:33.970491 2026] [authz_core:error] [pid 519566:tid 519721] [client 66.249.66.75:53878] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:33.970854 2026] [authz_core:error] [pid 519566:tid 519721] [client 66.249.66.75:53878] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:33.975661 2026] [security2:error] [pid 519566:tid 519795] [client 20.48.251.3:59370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apPltdKCPt8cS-VWcMmw3QAABAY"]
[Sun Aug 30 03:11:33.987461 2026] [authz_core:error] [pid 519566:tid 519784] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory25
[Sun Aug 30 03:11:33.987773 2026] [authz_core:error] [pid 519566:tid 519784] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory25
[Sun Aug 30 03:11:33.992640 2026] [security2:error] [pid 519566:tid 519713] [client 158.23.147.79:43655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apPltdKCPt8cS-VWcMmw6AAAA7Q"]
[Sun Aug 30 03:11:33.997402 2026] [authz_core:error] [pid 519566:tid 519707] [client 216.73.216.128:13745] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:33.997680 2026] [authz_core:error] [pid 519566:tid 519707] [client 216.73.216.128:13745] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:34.006982 2026] [security2:error] [pid 519566:tid 519697] [client 20.48.251.3:37126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/cp2.php"] [unique_id "apPlttKCPt8cS-VWcMmw8QAAA6Q"]
[Sun Aug 30 03:11:34.014404 2026] [security2:error] [pid 519566:tid 519770] [client 20.48.250.41:49379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/155.php"] [unique_id "apPlttKCPt8cS-VWcMmw9QAAA-0"]
[Sun Aug 30 03:11:34.022587 2026] [security2:error] [pid 519566:tid 519716] [client 20.220.10.235:20466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/wp-admin/zwso.php"] [unique_id "apPlttKCPt8cS-VWcMmw-QAAA7c"]
[Sun Aug 30 03:11:34.059413 2026] [security2:error] [pid 519566:tid 519717] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/gateway/.env"] [unique_id "apPlttKCPt8cS-VWcMmxCQAAA7g"]
[Sun Aug 30 03:11:34.066066 2026] [security2:error] [pid 519566:tid 519742] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/inicio.php"] [unique_id "apPlttKCPt8cS-VWcMmxCwAAA9E"]
[Sun Aug 30 03:11:34.069353 2026] [security2:error] [pid 519566:tid 519698] [client 20.197.61.180:15788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/system.php"] [unique_id "apPlttKCPt8cS-VWcMmxDAAAA6U"]
[Sun Aug 30 03:11:34.109412 2026] [security2:error] [pid 519566:tid 519773] [client 20.48.250.41:11252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/ws68.php"] [unique_id "apPlttKCPt8cS-VWcMmxGQAAA_A"]
[Sun Aug 30 03:11:34.122251 2026] [security2:error] [pid 519566:tid 519793] [client 20.104.18.15:31721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/vpn.php"] [unique_id "apPlttKCPt8cS-VWcMmxHAAABAQ"]
[Sun Aug 30 03:11:34.125347 2026] [security2:error] [pid 519566:tid 519714] [client 20.104.18.15:18186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/wp-aothait.php"] [unique_id "apPlttKCPt8cS-VWcMmxIQAAA7U"]
[Sun Aug 30 03:11:34.154532 2026] [security2:error] [pid 519566:tid 519749] [client 20.220.10.235:20453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tulsadivorceattorney.pro"] [uri "/waf.php"] [unique_id "apPlttKCPt8cS-VWcMmxLgAAA9g"]
[Sun Aug 30 03:11:34.163727 2026] [security2:error] [pid 519566:tid 519822] [client 20.48.250.41:49361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/file.php"] [unique_id "apPlttKCPt8cS-VWcMmxMAAABCE"]
[Sun Aug 30 03:11:34.182779 2026] [security2:error] [pid 519566:tid 519701] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/Model.php"] [unique_id "apPlttKCPt8cS-VWcMmxOAAAA6g"]
[Sun Aug 30 03:11:34.183607 2026] [security2:error] [pid 519566:tid 519769] [client 158.23.147.79:43626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apPlttKCPt8cS-VWcMmxOgAAA-w"]
[Sun Aug 30 03:11:34.188200 2026] [security2:error] [pid 519566:tid 519778] [client 20.104.50.220:61443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/error.php"] [unique_id "apPlttKCPt8cS-VWcMmxPAAAA_U"]
[Sun Aug 30 03:11:34.196568 2026] [authz_core:error] [pid 519566:tid 519799] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:34.196937 2026] [authz_core:error] [pid 519566:tid 519799] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:34.198675 2026] [security2:error] [pid 519566:tid 519727] [client 4.205.62.107:15500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/wpver.php"] [unique_id "apPlttKCPt8cS-VWcMmxQwAAA8I"]
[Sun Aug 30 03:11:34.201475 2026] [security2:error] [pid 519566:tid 519823] [client 20.104.50.220:51399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/bless.php"] [unique_id "apPlttKCPt8cS-VWcMmxRgAABCI"]
[Sun Aug 30 03:11:34.253791 2026] [security2:error] [pid 519566:tid 519733] [client 4.205.62.107:52897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/aws-credentials.php"] [unique_id "apPlttKCPt8cS-VWcMmxVgAAA8g"]
[Sun Aug 30 03:11:34.256488 2026] [security2:error] [pid 519566:tid 519815] [client 20.48.250.41:11100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/users.php"] [unique_id "apPlttKCPt8cS-VWcMmxWQAABBo"]
[Sun Aug 30 03:11:34.256515 2026] [security2:error] [pid 519566:tid 519762] [client 20.104.18.15:22339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/132.php"] [unique_id "apPlttKCPt8cS-VWcMmxWgAAA-U"]
[Sun Aug 30 03:11:34.261174 2026] [security2:error] [pid 519566:tid 519722] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/microservice/.env"] [unique_id "apPlttKCPt8cS-VWcMmxXwAAA70"]
[Sun Aug 30 03:11:34.291892 2026] [security2:error] [pid 519566:tid 519763] [client 20.104.49.130:51353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/cilus.php"] [unique_id "apPlttKCPt8cS-VWcMmxZwAAA-Y"]
[Sun Aug 30 03:11:34.302276 2026] [authz_core:error] [pid 519566:tid 519758] [client 66.249.66.72:37877] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:34.302558 2026] [authz_core:error] [pid 519566:tid 519758] [client 66.249.66.72:37877] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:34.302749 2026] [security2:error] [pid 519566:tid 519715] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/Kernel.php"] [unique_id "apPlttKCPt8cS-VWcMmxbQAAA7Y"]
[Sun Aug 30 03:11:34.312156 2026] [security2:error] [pid 519566:tid 519807] [client 68.155.159.216:54323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apPlttKCPt8cS-VWcMmxcwAABBI"]
[Sun Aug 30 03:11:34.313360 2026] [security2:error] [pid 519566:tid 519811] [client 20.48.250.41:49284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPlttKCPt8cS-VWcMmxdQAABBY"]
[Sun Aug 30 03:11:34.385318 2026] [security2:error] [pid 519566:tid 519786] [client 40.83.93.50:3928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/test1.php"] [unique_id "apPlttKCPt8cS-VWcMmxigAAA_0"]
[Sun Aug 30 03:11:34.394436 2026] [security2:error] [pid 519566:tid 519746] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/app/.env"] [unique_id "apPlttKCPt8cS-VWcMmxkAAAA9U"]
[Sun Aug 30 03:11:34.404662 2026] [security2:error] [pid 519566:tid 519715] [client 20.48.250.41:11115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/bzjdlofz.php"] [unique_id "apPlttKCPt8cS-VWcMmxlAAAA7Y"]
[Sun Aug 30 03:11:34.407950 2026] [authz_core:error] [pid 519566:tid 519804] [client 66.249.66.206:48452] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:34.408215 2026] [authz_core:error] [pid 519566:tid 519804] [client 66.249.66.206:48452] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:34.421298 2026] [security2:error] [pid 519566:tid 519742] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/Builder.php"] [unique_id "apPlttKCPt8cS-VWcMmxmAAAA9E"]
[Sun Aug 30 03:11:34.459095 2026] [authz_core:error] [pid 519566:tid 519815] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory25
[Sun Aug 30 03:11:34.459377 2026] [authz_core:error] [pid 519566:tid 519815] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory25
[Sun Aug 30 03:11:34.462379 2026] [security2:error] [pid 519566:tid 519739] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/service/.env"] [unique_id "apPlttKCPt8cS-VWcMmxrAAAA84"]
[Sun Aug 30 03:11:34.489946 2026] [security2:error] [pid 519566:tid 519696] [client 20.48.251.3:52231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/333.php"] [unique_id "apPlttKCPt8cS-VWcMmxugAAA6M"]
[Sun Aug 30 03:11:34.500765 2026] [security2:error] [pid 519566:tid 519729] [client 158.23.147.79:39351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apPlttKCPt8cS-VWcMmxvAAAA8Q"]
[Sun Aug 30 03:11:34.503318 2026] [security2:error] [pid 519566:tid 519778] [client 20.104.18.15:64711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/file31.php"] [unique_id "apPlttKCPt8cS-VWcMmxvQAAA_U"]
[Sun Aug 30 03:11:34.510879 2026] [security2:error] [pid 519566:tid 519769] [client 20.48.250.41:19405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/06.php"] [unique_id "apPlttKCPt8cS-VWcMmxwQAAA-w"]
[Sun Aug 30 03:11:34.537834 2026] [security2:error] [pid 519566:tid 519807] [client 20.104.50.220:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cagtu.com"] [uri "/View.php"] [unique_id "apPlttKCPt8cS-VWcMmx0gAABBI"]
[Sun Aug 30 03:11:34.557121 2026] [security2:error] [pid 519566:tid 519800] [client 20.104.49.130:63524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/xmini4.php"] [unique_id "apPlttKCPt8cS-VWcMmx2AAABAs"]
[Sun Aug 30 03:11:34.563500 2026] [security2:error] [pid 519566:tid 519749] [client 20.48.250.41:11040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/selesai.php"] [unique_id "apPlttKCPt8cS-VWcMmx3QAAA9g"]
[Sun Aug 30 03:11:34.564105 2026] [security2:error] [pid 519566:tid 519739] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/apps/.env"] [unique_id "apPlttKCPt8cS-VWcMmx3AAAA84"]
[Sun Aug 30 03:11:34.588986 2026] [lsapi:error] [pid 519566:tid 519672] [remote 68.2.124.49:43176] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:11:34.589082 2026] [lsapi:error] [pid 519566:tid 519672] [remote 68.2.124.49:43176] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:11:34.590365 2026] [lsapi:error] [pid 519566:tid 519672] [remote 68.2.124.49:43176] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n, referer: https://www.gracelikestogarden.com/
[Sun Aug 30 03:11:34.611439 2026] [security2:error] [pid 519566:tid 519780] [client 158.23.147.79:43324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apPlttKCPt8cS-VWcMmx8QAAA_c"]
[Sun Aug 30 03:11:34.649329 2026] [security2:error] [pid 519566:tid 519795] [client 20.48.250.41:49366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/class.php"] [unique_id "apPlttKCPt8cS-VWcMmx8wAABAY"]
[Sun Aug 30 03:11:34.655665 2026] [security2:error] [pid 519566:tid 519808] [client 20.104.50.220:16661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/xx.php"] [unique_id "apPlttKCPt8cS-VWcMmx-AAABBM"]
[Sun Aug 30 03:11:34.665441 2026] [security2:error] [pid 519566:tid 519801] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/api/v3/.env"] [unique_id "apPlttKCPt8cS-VWcMmx-wAABAw"]
[Sun Aug 30 03:11:34.689471 2026] [authz_core:error] [pid 519566:tid 519787] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:34.689911 2026] [authz_core:error] [pid 519566:tid 519787] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:34.709149 2026] [security2:error] [pid 519566:tid 519712] [client 158.23.147.79:39353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/packed.php"] [unique_id "apPlttKCPt8cS-VWcMmyEQAAA7M"]
[Sun Aug 30 03:11:34.728020 2026] [security2:error] [pid 519566:tid 519729] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/api/.env"] [unique_id "apPlttKCPt8cS-VWcMmyHQAAA8Q"]
[Sun Aug 30 03:11:34.735088 2026] [security2:error] [pid 519566:tid 519770] [client 20.104.18.15:51152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/images.php"] [unique_id "apPlttKCPt8cS-VWcMmyIQAAA-0"]
[Sun Aug 30 03:11:34.743566 2026] [security2:error] [pid 519566:tid 519815] [client 20.48.250.41:11048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/shlo.php"] [unique_id "apPlttKCPt8cS-VWcMmyKQAABBo"]
[Sun Aug 30 03:11:34.751610 2026] [security2:error] [pid 519566:tid 519735] [client 20.151.200.44:63009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/attack.php"] [unique_id "apPlttKCPt8cS-VWcMmyLQAAA8o"]
[Sun Aug 30 03:11:34.772860 2026] [authz_core:error] [pid 519566:tid 519816] [client 216.73.216.128:13745] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:34.773210 2026] [authz_core:error] [pid 519566:tid 519816] [client 216.73.216.128:13745] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:34.788390 2026] [security2:error] [pid 519566:tid 519716] [client 20.197.61.180:18062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/tflow/min.php"] [unique_id "apPlttKCPt8cS-VWcMmyPgAAA7c"]
[Sun Aug 30 03:11:34.792059 2026] [authz_core:error] [pid 519566:tid 519769] [client 66.249.66.72:55486] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:34.792518 2026] [authz_core:error] [pid 519566:tid 519769] [client 66.249.66.72:55486] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:34.803939 2026] [security2:error] [pid 519566:tid 519772] [client 158.23.147.79:43044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-content/packed.php"] [unique_id "apPlttKCPt8cS-VWcMmySQAAA-8"]
[Sun Aug 30 03:11:34.835230 2026] [security2:error] [pid 519566:tid 519746] [client 20.48.250.41:19420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/8.php"] [unique_id "apPlttKCPt8cS-VWcMmyVAAAA9U"]
[Sun Aug 30 03:11:34.843006 2026] [authz_core:error] [pid 519566:tid 519743] [client 66.249.66.70:60564] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:34.843287 2026] [authz_core:error] [pid 519566:tid 519743] [client 66.249.66.70:60564] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:34.847241 2026] [security2:error] [pid 519566:tid 519797] [client 4.205.62.107:25892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/environment.php"] [unique_id "apPlttKCPt8cS-VWcMmyXAAABAg"]
[Sun Aug 30 03:11:34.866864 2026] [security2:error] [pid 519566:tid 519704] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/api/dev/.env"] [unique_id "apPlttKCPt8cS-VWcMmyZAAAA6s"]
[Sun Aug 30 03:11:34.868278 2026] [authz_core:error] [pid 519566:tid 519697] [client 216.73.216.128:40285] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:34.868558 2026] [authz_core:error] [pid 519566:tid 519697] [client 216.73.216.128:40285] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:34.887857 2026] [security2:error] [pid 519566:tid 519823] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/web/.env"] [unique_id "apPlttKCPt8cS-VWcMmyagAABCI"]
[Sun Aug 30 03:11:34.888780 2026] [security2:error] [pid 519566:tid 519716] [client 20.104.50.220:29261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/images/mar.php"] [unique_id "apPlttKCPt8cS-VWcMmybAAAA7c"]
[Sun Aug 30 03:11:34.889864 2026] [security2:error] [pid 519566:tid 519810] [client 40.83.93.50:6833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/data.php"] [unique_id "apPlttKCPt8cS-VWcMmybQAABBU"]
[Sun Aug 30 03:11:34.901407 2026] [security2:error] [pid 519566:tid 519711] [client 158.23.147.79:39318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-l0gin.php"] [unique_id "apPlttKCPt8cS-VWcMmycgAAA7I"]
[Sun Aug 30 03:11:34.902722 2026] [security2:error] [pid 519566:tid 519788] [client 20.104.50.220:33157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/FoxWSOv2.php"] [unique_id "apPlttKCPt8cS-VWcMmycwAAA_8"]
[Sun Aug 30 03:11:34.930630 2026] [authz_core:error] [pid 519566:tid 519732] [client 66.249.66.77:36305] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:34.931051 2026] [authz_core:error] [pid 519566:tid 519732] [client 66.249.66.77:36305] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:34.943391 2026] [security2:error] [pid 519566:tid 519815] [client 20.48.250.41:11010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/asax.php"] [unique_id "apPlttKCPt8cS-VWcMmygwAABBo"]
[Sun Aug 30 03:11:34.949777 2026] [security2:error] [pid 519566:tid 519802] [client 204.10.194.195:50045] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "ccsinversiones.com"] [uri "/wp-content/plugins/pods/readme.txt"] [unique_id "apPlttKCPt8cS-VWcMmyhAAABA0"]
[Sun Aug 30 03:11:34.973419 2026] [security2:error] [pid 519566:tid 519804] [client 20.104.50.220:52830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/666.php"] [unique_id "apPlttKCPt8cS-VWcMmylAAABA8"]
[Sun Aug 30 03:11:34.980845 2026] [authz_core:error] [pid 519566:tid 519705] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory21
[Sun Aug 30 03:11:34.981104 2026] [authz_core:error] [pid 519566:tid 519705] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory21
[Sun Aug 30 03:11:34.986189 2026] [security2:error] [pid 519566:tid 519740] [client 68.155.159.216:57046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/ans.php"] [unique_id "apPlttKCPt8cS-VWcMmyngAAA88"]
[Sun Aug 30 03:11:34.992530 2026] [security2:error] [pid 519566:tid 519733] [client 20.48.250.41:49282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/0x0x.php"] [unique_id "apPlttKCPt8cS-VWcMmyoAAAA8g"]
[Sun Aug 30 03:11:35.022298 2026] [security2:error] [pid 519566:tid 519709] [client 20.104.50.220:24849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/cream1.php"] [unique_id "apPlt9KCPt8cS-VWcMmytwAAA7A"]
[Sun Aug 30 03:11:35.028213 2026] [security2:error] [pid 519566:tid 519703] [client 158.23.147.79:43070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apPlt9KCPt8cS-VWcMmyugAAA6o"]
[Sun Aug 30 03:11:35.046826 2026] [security2:error] [pid 519566:tid 519789] [client 4.205.62.107:17339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/333.php"] [unique_id "apPlt9KCPt8cS-VWcMmywQAABAA"]
[Sun Aug 30 03:11:35.049083 2026] [security2:error] [pid 519566:tid 519777] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/site/.env"] [unique_id "apPlt9KCPt8cS-VWcMmywgAAA_Q"]
[Sun Aug 30 03:11:35.068356 2026] [security2:error] [pid 519566:tid 519748] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/api/staging/.env"] [unique_id "apPlt9KCPt8cS-VWcMmyxQAAA9c"]
[Sun Aug 30 03:11:35.092676 2026] [security2:error] [pid 519566:tid 519816] [client 20.104.50.220:5493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-admin.php"] [unique_id "apPlt9KCPt8cS-VWcMmyygAABBs"]
[Sun Aug 30 03:11:35.109380 2026] [security2:error] [pid 519566:tid 519700] [client 20.48.251.3:55764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/hochladen.form.php"] [unique_id "apPlt9KCPt8cS-VWcMmy0QAAA6c"]
[Sun Aug 30 03:11:35.118332 2026] [security2:error] [pid 519566:tid 519717] [client 20.48.250.41:11211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/fetch.php"] [unique_id "apPlt9KCPt8cS-VWcMmy1wAAA7g"]
[Sun Aug 30 03:11:35.129827 2026] [security2:error] [pid 519566:tid 519715] [client 20.104.50.220:63497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/FoxWSOv1.php"] [unique_id "apPlt9KCPt8cS-VWcMmy4gAAA7Y"]
[Sun Aug 30 03:11:35.176640 2026] [security2:error] [pid 519566:tid 519797] [client 20.48.251.3:36808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/xda.php"] [unique_id "apPlt9KCPt8cS-VWcMmy7wAABAg"]
[Sun Aug 30 03:11:35.186238 2026] [security2:error] [pid 519566:tid 519804] [client 158.23.147.79:43345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPlt9KCPt8cS-VWcMmy8wAABA8"]
[Sun Aug 30 03:11:35.186306 2026] [security2:error] [pid 519566:tid 519748] [client 20.48.250.41:49334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/166.php"] [unique_id "apPlt9KCPt8cS-VWcMmy9AAAA9c"]
[Sun Aug 30 03:11:35.211583 2026] [security2:error] [pid 519566:tid 519704] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/public/.env"] [unique_id "apPlt9KCPt8cS-VWcMmzAAAAA6s"]
[Sun Aug 30 03:11:35.211800 2026] [authz_core:error] [pid 519566:tid 519741] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:35.212242 2026] [authz_core:error] [pid 519566:tid 519741] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:35.222705 2026] [security2:error] [pid 519566:tid 519822] [client 20.104.49.130:43290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/3.php"] [unique_id "apPlt9KCPt8cS-VWcMmzBwAABCE"]
[Sun Aug 30 03:11:35.232803 2026] [security2:error] [pid 519566:tid 519772] [client 20.48.251.3:54843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/gk.php"] [unique_id "apPlt9KCPt8cS-VWcMmzCwAAA-8"]
[Sun Aug 30 03:11:35.237215 2026] [security2:error] [pid 519566:tid 519585] [remote 94.152.153.134:41652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.153.152.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "flatironmelbourne.com.au"] [uri "/wp-login.php"] [unique_id "apPlt9KCPt8cS-VWcMmzCQAEFBI"]
[Sun Aug 30 03:11:35.257992 2026] [security2:error] [pid 519566:tid 519746] [client 20.48.250.41:11133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/vx.php"] [unique_id "apPlt9KCPt8cS-VWcMmzEgAAA9U"]
[Sun Aug 30 03:11:35.262970 2026] [security2:error] [pid 519566:tid 519762] [client 4.205.62.107:36583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/bb.php"] [unique_id "apPlt9KCPt8cS-VWcMmzFQAAA-U"]
[Sun Aug 30 03:11:35.270016 2026] [security2:error] [pid 519566:tid 519696] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/vendor/.env"] [unique_id "apPlt9KCPt8cS-VWcMmzFwAAA6M"]
[Sun Aug 30 03:11:35.274940 2026] [security2:error] [pid 519566:tid 519805] [client 20.104.18.15:18352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/wp-includes/index.php"] [unique_id "apPlt9KCPt8cS-VWcMmzGwAABBA"]
[Sun Aug 30 03:11:35.293124 2026] [security2:error] [pid 519566:tid 519801] [client 20.104.18.15:31647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/goods.php"] [unique_id "apPlt9KCPt8cS-VWcMmzHgAABAw"]
[Sun Aug 30 03:11:35.303227 2026] [security2:error] [pid 519566:tid 519739] [client 158.23.147.79:16332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/lock.php"] [unique_id "apPlt9KCPt8cS-VWcMmzIAAAA84"]
[Sun Aug 30 03:11:35.342260 2026] [security2:error] [pid 519566:tid 519704] [client 4.205.62.107:15963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/ah25.php"] [unique_id "apPlt9KCPt8cS-VWcMmzLQAAA6s"]
[Sun Aug 30 03:11:35.344078 2026] [security2:error] [pid 519566:tid 519700] [client 20.104.50.220:59576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/x.php"] [unique_id "apPlt9KCPt8cS-VWcMmzMAAAA6c"]
[Sun Aug 30 03:11:35.354534 2026] [security2:error] [pid 519566:tid 519788] [client 20.104.50.220:59359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/file46.php"] [unique_id "apPlt9KCPt8cS-VWcMmzNQAAA_8"]
[Sun Aug 30 03:11:35.375995 2026] [security2:error] [pid 519566:tid 519703] [client 20.151.200.44:46079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/sf.php"] [unique_id "apPlt9KCPt8cS-VWcMmzPQAAA6o"]
[Sun Aug 30 03:11:35.376202 2026] [security2:error] [pid 519566:tid 519803] [client 40.83.93.50:3962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/classwithtostring.php"] [unique_id "apPlt9KCPt8cS-VWcMmzPgAABA4"]
[Sun Aug 30 03:11:35.381852 2026] [security2:error] [pid 519566:tid 519727] [client 158.23.147.79:39106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/ans.php"] [unique_id "apPlt9KCPt8cS-VWcMmzRwAAA8I"]
[Sun Aug 30 03:11:35.385597 2026] [security2:error] [pid 519566:tid 519792] [client 204.10.194.195:50053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.194.10.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ccsinversiones.com"] [uri "/wp-content/plugins/pods/init.php"] [unique_id "apPlt9KCPt8cS-VWcMmzOwAABAM"]
[Sun Aug 30 03:11:35.408840 2026] [security2:error] [pid 519566:tid 519796] [client 20.104.18.15:22341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/v22.php"] [unique_id "apPlt9KCPt8cS-VWcMmzUgAABAc"]
[Sun Aug 30 03:11:35.456210 2026] [authz_core:error] [pid 519566:tid 519788] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory22
[Sun Aug 30 03:11:35.456505 2026] [authz_core:error] [pid 519566:tid 519788] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory22
[Sun Aug 30 03:11:35.458496 2026] [security2:error] [pid 519566:tid 519709] [client 4.205.62.107:52821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/4563.php"] [unique_id "apPlt9KCPt8cS-VWcMmzaQAAA7A"]
[Sun Aug 30 03:11:35.462245 2026] [security2:error] [pid 519566:tid 519711] [client 20.48.250.41:11122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/global.php"] [unique_id "apPlt9KCPt8cS-VWcMmzbQAAA7I"]
[Sun Aug 30 03:11:35.471337 2026] [security2:error] [pid 519566:tid 519701] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/lib/.env"] [unique_id "apPlt9KCPt8cS-VWcMmzcgAAA6g"]
[Sun Aug 30 03:11:35.475619 2026] [authz_core:error] [pid 519566:tid 519803] [client 66.249.66.74:58532] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:35.476011 2026] [authz_core:error] [pid 519566:tid 519803] [client 66.249.66.74:58532] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:35.486803 2026] [authz_core:error] [pid 519566:tid 519696] [client 66.249.66.198:39183] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:35.487095 2026] [authz_core:error] [pid 519566:tid 519696] [client 66.249.66.198:39183] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:35.502938 2026] [security2:error] [pid 519566:tid 519712] [client 20.197.61.180:12263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/tflow/pk.php"] [unique_id "apPlt9KCPt8cS-VWcMmzfgAAA7M"]
[Sun Aug 30 03:11:35.503382 2026] [security2:error] [pid 519566:tid 519746] [client 20.48.250.41:19436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/h2a2ck.php"] [unique_id "apPlt9KCPt8cS-VWcMmzfwAAA9U"]
[Sun Aug 30 03:11:35.549483 2026] [security2:error] [pid 519566:tid 519751] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/backend/.env"] [unique_id "apPlt9KCPt8cS-VWcMmzkgAAA9o"]
[Sun Aug 30 03:11:35.569557 2026] [authz_core:error] [pid 519566:tid 519744] [client 66.249.66.198:41833] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:35.569839 2026] [authz_core:error] [pid 519566:tid 519744] [client 66.249.66.198:41833] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:35.604454 2026] [authz_core:error] [pid 519566:tid 519820] [client 66.249.66.33:35766] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:35.604874 2026] [authz_core:error] [pid 519566:tid 519820] [client 66.249.66.33:35766] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:35.614135 2026] [security2:error] [pid 519566:tid 519759] [client 20.48.250.41:11017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/fs.php"] [unique_id "apPlt9KCPt8cS-VWcMmzpQAAA-I"]
[Sun Aug 30 03:11:35.641244 2026] [security2:error] [pid 519566:tid 519802] [client 20.48.251.3:52206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/G-in.php"] [unique_id "apPlt9KCPt8cS-VWcMmzqQAABA0"]
[Sun Aug 30 03:11:35.642000 2026] [security2:error] [pid 519566:tid 519732] [client 20.104.18.15:17006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/dk.php"] [unique_id "apPlt9KCPt8cS-VWcMmzqgAAA8c"]
[Sun Aug 30 03:11:35.643672 2026] [security2:error] [pid 519566:tid 519705] [client 20.104.49.130:59571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/wp-blogs.php"] [unique_id "apPlt9KCPt8cS-VWcMmzqwAAA6w"]
[Sun Aug 30 03:11:35.662964 2026] [security2:error] [pid 519566:tid 519743] [client 204.10.194.195:50061] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "ccsinversiones.com"] [uri "/wp-content/plugins/pods/readme.txt"] [unique_id "apPlt9KCPt8cS-VWcMmzswAAA9I"]
[Sun Aug 30 03:11:35.668337 2026] [authz_core:error] [pid 519566:tid 519756] [client 66.249.66.72:37877] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:35.668612 2026] [authz_core:error] [pid 519566:tid 519756] [client 66.249.66.72:37877] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:35.669413 2026] [authz_core:error] [pid 519566:tid 519718] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:35.669702 2026] [authz_core:error] [pid 519566:tid 519718] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:35.673938 2026] [security2:error] [pid 519566:tid 519722] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/resources/.env"] [unique_id "apPlt9KCPt8cS-VWcMmztgAAA70"]
[Sun Aug 30 03:11:35.676108 2026] [security2:error] [pid 519566:tid 519736] [client 68.155.159.216:52312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-admin/network/index.php"] [unique_id "apPlt9KCPt8cS-VWcMmzuAAAA8s"]
[Sun Aug 30 03:11:35.679877 2026] [security2:error] [pid 519566:tid 519712] [client 20.48.250.41:19419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/error_log.php"] [unique_id "apPlt9KCPt8cS-VWcMmzugAAA7M"]
[Sun Aug 30 03:11:35.721439 2026] [security2:error] [pid 519566:tid 519769] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/server/.env"] [unique_id "apPlt9KCPt8cS-VWcMmz0gAAA-w"]
[Sun Aug 30 03:11:35.775554 2026] [security2:error] [pid 519566:tid 519758] [client 20.48.250.41:11077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/ioxi.php"] [unique_id "apPlt9KCPt8cS-VWcMmz8gAAA-E"]
[Sun Aug 30 03:11:35.777394 2026] [security2:error] [pid 519566:tid 519751] [client 20.104.49.130:53783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/gecko-new.php"] [unique_id "apPlt9KCPt8cS-VWcMmz8wAAA9o"]
[Sun Aug 30 03:11:35.799331 2026] [security2:error] [pid 519566:tid 519823] [client 47.128.29.208:47540] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.lordrcane.com"] [uri "/rift-bronze-quest/"] [unique_id "apPlt9KCPt8cS-VWcMmz_wAABCI"]
[Sun Aug 30 03:11:35.806193 2026] [security2:error] [pid 519566:tid 519814] [client 20.104.50.220:17286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/gifclass4.php"] [unique_id "apPlt9KCPt8cS-VWcMm0AwAABBk"]
[Sun Aug 30 03:11:35.860569 2026] [authz_core:error] [pid 519566:tid 519791] [client 66.249.66.65:40795] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:35.860848 2026] [authz_core:error] [pid 519566:tid 519791] [client 66.249.66.65:40795] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:35.862018 2026] [security2:error] [pid 519566:tid 519749] [client 20.48.250.41:49299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/403.php"] [unique_id "apPlt9KCPt8cS-VWcMm0GAAAA9g"]
[Sun Aug 30 03:11:35.870981 2026] [security2:error] [pid 519566:tid 519804] [client 20.104.18.15:51175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/ops.php"] [unique_id "apPlt9KCPt8cS-VWcMm0GgAABA8"]
[Sun Aug 30 03:11:35.871754 2026] [security2:error] [pid 519566:tid 519785] [client 40.83.93.50:22118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/en.php"] [unique_id "apPlt9KCPt8cS-VWcMm0HAAAA_w"]
[Sun Aug 30 03:11:35.874990 2026] [security2:error] [pid 519566:tid 519799] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/assets/.env"] [unique_id "apPlt9KCPt8cS-VWcMm0HgAABAo"]
[Sun Aug 30 03:11:35.881156 2026] [security2:error] [pid 519566:tid 519705] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/frontend/.env"] [unique_id "apPlt9KCPt8cS-VWcMm0HwAAA6w"]
[Sun Aug 30 03:11:35.940022 2026] [security2:error] [pid 519566:tid 519767] [client 204.10.194.195:50063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.194.10.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ccsinversiones.com"] [uri "/wp-content/plugins/pods/init.php"] [unique_id "apPlt9KCPt8cS-VWcMm0NAAAA-o"]
[Sun Aug 30 03:11:35.974724 2026] [security2:error] [pid 519566:tid 519700] [client 20.48.250.41:11238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/bootstrap.php"] [unique_id "apPlt9KCPt8cS-VWcMm0QQAAA6c"]
[Sun Aug 30 03:11:35.987033 2026] [authz_core:error] [pid 519566:tid 519749] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory12
[Sun Aug 30 03:11:35.987329 2026] [authz_core:error] [pid 519566:tid 519749] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory12
[Sun Aug 30 03:11:35.994906 2026] [security2:error] [pid 519566:tid 519705] [client 216.73.216.128:12207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPlt9KCPt8cS-VWcMm0TQAAA6w"]
[Sun Aug 30 03:11:35.997742 2026] [security2:error] [pid 519566:tid 519801] [client 158.23.147.79:43068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/worksec.php"] [unique_id "apPlt9KCPt8cS-VWcMm0TwAABAw"]
[Sun Aug 30 03:11:35.998820 2026] [security2:error] [pid 519566:tid 519777] [client 4.205.62.107:25524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/aws_secret_config.php"] [unique_id "apPlt9KCPt8cS-VWcMm0UgAAA_Q"]
[Sun Aug 30 03:11:36.012157 2026] [security2:error] [pid 519566:tid 519715] [client 20.48.250.41:19401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/cytyr.php"] [unique_id "apPluNKCPt8cS-VWcMm0XAAAA7Y"]
[Sun Aug 30 03:11:36.042150 2026] [security2:error] [pid 519566:tid 519795] [client 20.104.50.220:62814] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/images/1.php"] [unique_id "apPluNKCPt8cS-VWcMm0aAAABAY"]
[Sun Aug 30 03:11:36.042228 2026] [security2:error] [pid 519566:tid 519795] [client 20.104.50.220:62814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/images/1.php"] [unique_id "apPluNKCPt8cS-VWcMm0aAAABAY"]
[Sun Aug 30 03:11:36.046182 2026] [security2:error] [pid 519566:tid 519756] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/src/.env"] [unique_id "apPluNKCPt8cS-VWcMm0agAAA98"]
[Sun Aug 30 03:11:36.052120 2026] [security2:error] [pid 519566:tid 519774] [client 20.104.50.220:32899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/foxwsov2.php"] [unique_id "apPluNKCPt8cS-VWcMm0bQAAA_E"]
[Sun Aug 30 03:11:36.077740 2026] [security2:error] [pid 519566:tid 519794] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/uploads/.env"] [unique_id "apPluNKCPt8cS-VWcMm0bwAABAU"]
[Sun Aug 30 03:11:36.078633 2026] [security2:error] [pid 519566:tid 519815] [client 20.151.200.44:65439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/ca.php"] [unique_id "apPluNKCPt8cS-VWcMm0cAAABBo"]
[Sun Aug 30 03:11:36.126300 2026] [security2:error] [pid 519566:tid 519715] [client 20.104.50.220:29139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/Xzd.php"] [unique_id "apPluNKCPt8cS-VWcMm0hQAAA7Y"]
[Sun Aug 30 03:11:36.141435 2026] [security2:error] [pid 519566:tid 519787] [client 20.48.250.41:49314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/galer.php"] [unique_id "apPluNKCPt8cS-VWcMm0iwAAA_4"]
[Sun Aug 30 03:11:36.171007 2026] [authz_core:error] [pid 519566:tid 519810] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:36.171496 2026] [authz_core:error] [pid 519566:tid 519810] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:36.177804 2026] [security2:error] [pid 519566:tid 519701] [client 20.104.50.220:25449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/lim.php"] [unique_id "apPluNKCPt8cS-VWcMm0lgAAA6g"]
[Sun Aug 30 03:11:36.177898 2026] [security2:error] [pid 519566:tid 519730] [client 68.155.159.216:63232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/worksec.php"] [unique_id "apPluNKCPt8cS-VWcMm0lQAAA8U"]
[Sun Aug 30 03:11:36.178708 2026] [security2:error] [pid 519566:tid 519747] [client 4.205.62.107:16807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/G-in.php"] [unique_id "apPluNKCPt8cS-VWcMm0lwAAA9Y"]
[Sun Aug 30 03:11:36.185350 2026] [security2:error] [pid 519566:tid 519744] [client 20.104.49.130:52474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wdfjba.org"] [uri "/chosen.php"] [unique_id "apPluNKCPt8cS-VWcMm0mwAAA9M"]
[Sun Aug 30 03:11:36.192218 2026] [authz_core:error] [pid 519566:tid 519803] [client 216.73.216.128:65420] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:36.192481 2026] [authz_core:error] [pid 519566:tid 519803] [client 216.73.216.128:65420] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:36.197391 2026] [security2:error] [pid 519566:tid 519797] [client 20.48.250.41:11157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/export.php"] [unique_id "apPluNKCPt8cS-VWcMm0oQAABAg"]
[Sun Aug 30 03:11:36.205550 2026] [security2:error] [pid 519566:tid 519770] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/core/.env"] [unique_id "apPluNKCPt8cS-VWcMm0pQAAA-0"]
[Sun Aug 30 03:11:36.210579 2026] [authz_core:error] [pid 519566:tid 519753] [client 66.249.66.37:41193] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:36.211017 2026] [authz_core:error] [pid 519566:tid 519753] [client 66.249.66.37:41193] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:36.218295 2026] [security2:error] [pid 519566:tid 519806] [client 20.197.61.180:12260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/theme-check/theme-check.php"] [unique_id "apPluNKCPt8cS-VWcMm0rAAABBE"]
[Sun Aug 30 03:11:36.230979 2026] [security2:error] [pid 519566:tid 519788] [client 20.151.200.44:45962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/4e.php"] [unique_id "apPluNKCPt8cS-VWcMm0sAAAA_8"]
[Sun Aug 30 03:11:36.235076 2026] [security2:error] [pid 519566:tid 519769] [client 158.23.147.79:43337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/x.php"] [unique_id "apPluNKCPt8cS-VWcMm0tAAAA-w"]
[Sun Aug 30 03:11:36.255852 2026] [security2:error] [pid 519566:tid 519752] [client 20.48.251.3:55766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/debuggen.php"] [unique_id "apPluNKCPt8cS-VWcMm0twAAA9s"]
[Sun Aug 30 03:11:36.274906 2026] [security2:error] [pid 519566:tid 519823] [client 20.48.250.41:19397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/baixy.php"] [unique_id "apPluNKCPt8cS-VWcMm0wAAABCI"]
[Sun Aug 30 03:11:36.278113 2026] [authz_core:error] [pid 519566:tid 519786] [client 66.249.66.66:36976] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:36.278388 2026] [authz_core:error] [pid 519566:tid 519786] [client 66.249.66.66:36976] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:36.278889 2026] [security2:error] [pid 519566:tid 519703] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/internal/.env"] [unique_id "apPluNKCPt8cS-VWcMm0wgAAA6o"]
[Sun Aug 30 03:11:36.280659 2026] [security2:error] [pid 519566:tid 519799] [client 20.104.50.220:42812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/foxwsov1.php"] [unique_id "apPluNKCPt8cS-VWcMm0wwAABAo"]
[Sun Aug 30 03:11:36.312768 2026] [security2:error] [pid 519566:tid 519800] [client 43.160.219.206:33968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.219.160.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontal.do"] [uri "/login.php"] [unique_id "apPluNKCPt8cS-VWcMm0yQAABAs"], referer: http://pontal.do
[Sun Aug 30 03:11:36.317576 2026] [authz_core:error] [pid 519566:tid 519774] [client 66.249.66.66:65474] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:36.317859 2026] [authz_core:error] [pid 519566:tid 519774] [client 66.249.66.66:65474] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:36.347489 2026] [security2:error] [pid 519566:tid 519713] [client 20.48.251.3:36806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/pinfo.php"] [unique_id "apPluNKCPt8cS-VWcMm02AAAA7Q"]
[Sun Aug 30 03:11:36.370122 2026] [security2:error] [pid 519566:tid 519736] [client 20.104.50.220:6097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-login.php"] [unique_id "apPluNKCPt8cS-VWcMm04QAAA8s"]
[Sun Aug 30 03:11:36.376003 2026] [security2:error] [pid 519566:tid 519754] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/core/app/.env"] [unique_id "apPluNKCPt8cS-VWcMm04wAAA90"]
[Sun Aug 30 03:11:36.392773 2026] [security2:error] [pid 519566:tid 519823] [client 20.48.250.41:11021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/gk.php"] [unique_id "apPluNKCPt8cS-VWcMm07gAABCI"]
[Sun Aug 30 03:11:36.400664 2026] [security2:error] [pid 519566:tid 519789] [client 4.205.62.107:35983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/file59.php"] [unique_id "apPluNKCPt8cS-VWcMm08gAABAA"]
[Sun Aug 30 03:11:36.407321 2026] [security2:error] [pid 519566:tid 519795] [client 20.48.251.3:54800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/god.php"] [unique_id "apPluNKCPt8cS-VWcMm09QAABAY"]
[Sun Aug 30 03:11:36.429681 2026] [security2:error] [pid 519566:tid 519778] [client 20.104.18.15:31652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/alfa.php"] [unique_id "apPluNKCPt8cS-VWcMm0-gAAA_U"]
[Sun Aug 30 03:11:36.444667 2026] [authz_core:error] [pid 519566:tid 519697] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory32
[Sun Aug 30 03:11:36.444954 2026] [authz_core:error] [pid 519566:tid 519697] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory32
[Sun Aug 30 03:11:36.450881 2026] [security2:error] [pid 519566:tid 519794] [client 20.104.18.15:18379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/file31.php"] [unique_id "apPluNKCPt8cS-VWcMm1CQAABAU"]
[Sun Aug 30 03:11:36.462937 2026] [security2:error] [pid 519566:tid 519733] [client 20.48.250.41:49321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/ava.php"] [unique_id "apPluNKCPt8cS-VWcMm1FAAAA8g"]
[Sun Aug 30 03:11:36.465986 2026] [security2:error] [pid 519566:tid 519772] [client 40.83.93.50:6820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/13.php"] [unique_id "apPluNKCPt8cS-VWcMm1GAAAA-8"]
[Sun Aug 30 03:11:36.475422 2026] [security2:error] [pid 519566:tid 519702] [client 4.205.62.107:15983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/groceries/index.php"] [unique_id "apPluNKCPt8cS-VWcMm1HgAAA6k"]
[Sun Aug 30 03:11:36.480623 2026] [security2:error] [pid 519566:tid 519759] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/tools/.env"] [unique_id "apPluNKCPt8cS-VWcMm1IQAAA-I"]
[Sun Aug 30 03:11:36.493391 2026] [security2:error] [pid 519566:tid 519735] [client 20.104.50.220:59379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/eee.php"] [unique_id "apPluNKCPt8cS-VWcMm1JQAAA8o"]
[Sun Aug 30 03:11:36.518633 2026] [security2:error] [pid 519566:tid 519749] [client 20.104.50.220:61986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/xx.php"] [unique_id "apPluNKCPt8cS-VWcMm1LQAAA9g"]
[Sun Aug 30 03:11:36.536199 2026] [security2:error] [pid 519566:tid 519770] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/config/.env"] [unique_id "apPluNKCPt8cS-VWcMm1NgAAA-0"]
[Sun Aug 30 03:11:36.537359 2026] [security2:error] [pid 519566:tid 519742] [client 20.48.250.41:11090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/logs1.php"] [unique_id "apPluNKCPt8cS-VWcMm1NwAAA9E"]
[Sun Aug 30 03:11:36.548008 2026] [lsapi:error] [pid 519566:tid 519587] [remote 216.38.225.46:39369] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://gracelikestogarden.com/
[Sun Aug 30 03:11:36.548165 2026] [lsapi:error] [pid 519566:tid 519587] [remote 216.38.225.46:39369] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 262144 bytes) in Unknown on line 0\n, referer: https://gracelikestogarden.com/
[Sun Aug 30 03:11:36.549535 2026] [lsapi:error] [pid 519566:tid 519587] [remote 216.38.225.46:39369] [host gracelikestogarden.com] Backend fatal error: PHP Fatal error: Allowed memory size of 536870912 bytes exhausted (tried to allocate 1024000 bytes) in Unknown on line 0\n, referer: https://gracelikestogarden.com/
[Sun Aug 30 03:11:36.554300 2026] [security2:error] [pid 519566:tid 519740] [client 20.151.200.44:46069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/ssss.php"] [unique_id "apPluNKCPt8cS-VWcMm1QAAAA88"]
[Sun Aug 30 03:11:36.605731 2026] [security2:error] [pid 519566:tid 519721] [client 20.48.250.41:49386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/gdn.php"] [unique_id "apPluNKCPt8cS-VWcMm1TwAAA7w"]
[Sun Aug 30 03:11:36.606676 2026] [security2:error] [pid 519566:tid 519776] [client 4.205.62.107:52906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/cp2.php"] [unique_id "apPluNKCPt8cS-VWcMm1UgAAA_M"]
[Sun Aug 30 03:11:36.606700 2026] [security2:error] [pid 519566:tid 519788] [client 158.23.147.79:39134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-content/x.php"] [unique_id "apPluNKCPt8cS-VWcMm1UwAAA_8"]
[Sun Aug 30 03:11:36.608393 2026] [security2:error] [pid 519566:tid 519729] [client 20.104.18.15:22438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/wp-activate.php"] [unique_id "apPluNKCPt8cS-VWcMm1VAAAA8Q"]
[Sun Aug 30 03:11:36.656697 2026] [authz_core:error] [pid 519566:tid 519704] [client 216.73.216.128:13745] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:36.657114 2026] [authz_core:error] [pid 519566:tid 519704] [client 216.73.216.128:13745] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:36.668605 2026] [authz_core:error] [pid 519566:tid 519766] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:36.669030 2026] [authz_core:error] [pid 519566:tid 519766] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:36.678089 2026] [security2:error] [pid 519566:tid 519801] [client 20.48.250.41:11172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/inege.php"] [unique_id "apPluNKCPt8cS-VWcMm1ZQAABAw"]
[Sun Aug 30 03:11:36.682731 2026] [security2:error] [pid 519566:tid 519815] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/scripts/.env"] [unique_id "apPluNKCPt8cS-VWcMm1ZwAABBo"]
[Sun Aug 30 03:11:36.692595 2026] [authz_core:error] [pid 519566:tid 519752] [client 66.249.66.69:59063] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:36.693019 2026] [authz_core:error] [pid 519566:tid 519752] [client 66.249.66.69:59063] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:36.695352 2026] [security2:error] [pid 519566:tid 519738] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/private/.env"] [unique_id "apPluNKCPt8cS-VWcMm1dAAAA80"]
[Sun Aug 30 03:11:36.745149 2026] [authz_core:error] [pid 519566:tid 519723] [client 216.73.216.128:40285] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:36.745416 2026] [authz_core:error] [pid 519566:tid 519723] [client 216.73.216.128:40285] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:36.762076 2026] [security2:error] [pid 519566:tid 519798] [client 20.48.250.41:19428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/f2.php"] [unique_id "apPluNKCPt8cS-VWcMm1owAABAk"]
[Sun Aug 30 03:11:36.777956 2026] [security2:error] [pid 519566:tid 519805] [client 20.48.251.3:59463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/apikeys.php"] [unique_id "apPluNKCPt8cS-VWcMm1qgAABBA"]
[Sun Aug 30 03:11:36.779226 2026] [security2:error] [pid 519566:tid 519793] [client 20.104.18.15:64714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/ta.php"] [unique_id "apPluNKCPt8cS-VWcMm1rQAABAQ"]
[Sun Aug 30 03:11:36.812047 2026] [security2:error] [pid 519566:tid 519712] [client 20.48.250.41:11107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/wp-link10.php"] [unique_id "apPluNKCPt8cS-VWcMm1vAAAA7M"]
[Sun Aug 30 03:11:36.857807 2026] [security2:error] [pid 519566:tid 519782] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/application/.env"] [unique_id "apPluNKCPt8cS-VWcMm1zQAAA_k"]
[Sun Aug 30 03:11:36.886662 2026] [security2:error] [pid 519566:tid 519801] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/bin/.env"] [unique_id "apPluNKCPt8cS-VWcMm11AAABAw"]
[Sun Aug 30 03:11:36.888200 2026] [security2:error] [pid 519566:tid 519798] [client 68.155.159.216:54315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apPluNKCPt8cS-VWcMm11QAABAk"]
[Sun Aug 30 03:11:36.908373 2026] [security2:error] [pid 519566:tid 519770] [client 20.48.250.41:49354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/grsiuk.php"] [unique_id "apPluNKCPt8cS-VWcMm13gAAA-0"]
[Sun Aug 30 03:11:36.945589 2026] [security2:error] [pid 519566:tid 519762] [client 20.197.61.180:12261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/theme/about.php"] [unique_id "apPluNKCPt8cS-VWcMm17QAAA-U"]
[Sun Aug 30 03:11:36.948620 2026] [security2:error] [pid 519566:tid 519703] [client 20.104.50.220:17306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/2clas.php"] [unique_id "apPluNKCPt8cS-VWcMm17wAAA6o"]
[Sun Aug 30 03:11:36.949257 2026] [security2:error] [pid 519566:tid 519816] [client 40.83.93.50:22128] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.thebelgradegroup.com"] [uri "/1.php"] [unique_id "apPluNKCPt8cS-VWcMm18AAABBs"]
[Sun Aug 30 03:11:36.949316 2026] [security2:error] [pid 519566:tid 519816] [client 40.83.93.50:22128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/1.php"] [unique_id "apPluNKCPt8cS-VWcMm18AAABBs"]
[Sun Aug 30 03:11:36.950615 2026] [authz_core:error] [pid 519566:tid 519803] [client 66.249.66.36:53750] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:36.950962 2026] [authz_core:error] [pid 519566:tid 519803] [client 66.249.66.36:53750] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:36.980674 2026] [security2:error] [pid 519566:tid 519734] [client 20.48.250.41:11208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/ww.php"] [unique_id "apPluNKCPt8cS-VWcMm2AgAAA8k"]
[Sun Aug 30 03:11:36.984366 2026] [security2:error] [pid 519566:tid 519776] [client 158.23.147.79:43597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPluNKCPt8cS-VWcMm2BAAAA_M"]
[Sun Aug 30 03:11:37.010102 2026] [security2:error] [pid 519566:tid 519739] [client 20.104.18.15:51136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/coffexium.php"] [unique_id "apPludKCPt8cS-VWcMm2DwAAA84"]
[Sun Aug 30 03:11:37.011288 2026] [security2:error] [pid 519566:tid 519767] [client 158.23.147.79:60173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/index/function.php"] [unique_id "apPludKCPt8cS-VWcMm2EAAAA-o"]
[Sun Aug 30 03:11:37.017780 2026] [security2:error] [pid 519566:tid 519742] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/bootstrap/.env"] [unique_id "apPludKCPt8cS-VWcMm2FgAAA9E"]
[Sun Aug 30 03:11:37.022929 2026] [authz_core:error] [pid 519566:tid 519781] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory32
[Sun Aug 30 03:11:37.023384 2026] [authz_core:error] [pid 519566:tid 519781] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory32
[Sun Aug 30 03:11:37.037948 2026] [security2:error] [pid 519566:tid 519731] [client 20.48.250.41:19435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/wp-scr1pts.php"] [unique_id "apPludKCPt8cS-VWcMm2IQAAA8Y"]
[Sun Aug 30 03:11:37.088611 2026] [security2:error] [pid 519566:tid 519717] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/sbin/.env"] [unique_id "apPludKCPt8cS-VWcMm2NAAAA7g"]
[Sun Aug 30 03:11:37.089280 2026] [security2:error] [pid 519566:tid 519792] [client 54.39.18.217:57787] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "54.39.18.217" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPludKCPt8cS-VWcMm2NQAABAM"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:11:37.089361 2026] [security2:error] [pid 519566:tid 519792] [client 54.39.18.217:57787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPludKCPt8cS-VWcMm2NQAABAM"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:11:37.114189 2026] [authz_core:error] [pid 519566:tid 519739] [client 216.73.216.128:54671] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:37.114611 2026] [authz_core:error] [pid 519566:tid 519739] [client 216.73.216.128:54671] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:37.120839 2026] [security2:error] [pid 519566:tid 519777] [client 20.151.200.44:41798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/ca.php"] [unique_id "apPludKCPt8cS-VWcMm2RAAAA_Q"]
[Sun Aug 30 03:11:37.139384 2026] [security2:error] [pid 519566:tid 519800] [client 158.23.147.79:43011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/log-mama/function.php"] [unique_id "apPludKCPt8cS-VWcMm2TwAABAs"]
[Sun Aug 30 03:11:37.155317 2026] [authz_core:error] [pid 519566:tid 519762] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:37.155570 2026] [authz_core:error] [pid 519566:tid 519762] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:37.167418 2026] [authz_core:error] [pid 519566:tid 519744] [client 66.249.66.197:55790] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:37.167800 2026] [authz_core:error] [pid 519566:tid 519744] [client 66.249.66.197:55790] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:37.171739 2026] [security2:error] [pid 519566:tid 519736] [client 20.48.250.41:11088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/w1px.php"] [unique_id "apPludKCPt8cS-VWcMm2VQAAA8s"]
[Sun Aug 30 03:11:37.178903 2026] [security2:error] [pid 519566:tid 519746] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/database/.env"] [unique_id "apPludKCPt8cS-VWcMm2WAAAA9U"]
[Sun Aug 30 03:11:37.180865 2026] [security2:error] [pid 519566:tid 519774] [client 20.104.50.220:29601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/imageswp-init.php"] [unique_id "apPludKCPt8cS-VWcMm2XAAAA_E"]
[Sun Aug 30 03:11:37.185367 2026] [security2:error] [pid 519566:tid 519791] [client 20.151.200.44:45901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/zoz.php"] [unique_id "apPludKCPt8cS-VWcMm2XgAABAI"]
[Sun Aug 30 03:11:37.203607 2026] [security2:error] [pid 519566:tid 519792] [client 20.104.50.220:33537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/shellx.php"] [unique_id "apPludKCPt8cS-VWcMm2ZwAABAM"]
[Sun Aug 30 03:11:37.204778 2026] [security2:error] [pid 519566:tid 519734] [client 20.48.250.41:49323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/num.php"] [unique_id "apPludKCPt8cS-VWcMm2aQAAA8k"]
[Sun Aug 30 03:11:37.219765 2026] [security2:error] [pid 519566:tid 519769] [client 4.205.62.107:25499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/snq.php"] [unique_id "apPludKCPt8cS-VWcMm2bgAAA-w"]
[Sun Aug 30 03:11:37.260677 2026] [security2:error] [pid 519566:tid 519696] [client 20.104.50.220:63044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/ms-sitess.php"] [unique_id "apPludKCPt8cS-VWcMm2eAAAA6M"]
[Sun Aug 30 03:11:37.269143 2026] [security2:error] [pid 519566:tid 519801] [client 158.23.147.79:39107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/bk/index.php"] [unique_id "apPludKCPt8cS-VWcMm2fwAABAw"]
[Sun Aug 30 03:11:37.290458 2026] [security2:error] [pid 519566:tid 519711] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/local/.env"] [unique_id "apPludKCPt8cS-VWcMm2ggAAA7I"]
[Sun Aug 30 03:11:37.296574 2026] [security2:error] [pid 519566:tid 519753] [client 20.151.200.44:65422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/pb.php"] [unique_id "apPludKCPt8cS-VWcMm2hAAAA9w"]
[Sun Aug 30 03:11:37.308139 2026] [security2:error] [pid 519566:tid 519791] [client 20.104.50.220:25454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/heat3.php"] [unique_id "apPludKCPt8cS-VWcMm2jAAABAI"]
[Sun Aug 30 03:11:37.309362 2026] [security2:error] [pid 519566:tid 519749] [client 20.48.250.41:11092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/to.php"] [unique_id "apPludKCPt8cS-VWcMm2jQAAA9g"]
[Sun Aug 30 03:11:37.312512 2026] [authz_core:error] [pid 519566:tid 519755] [client 216.73.216.128:54671] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:37.312808 2026] [authz_core:error] [pid 519566:tid 519755] [client 216.73.216.128:54671] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:37.315930 2026] [security2:error] [pid 519566:tid 519810] [client 4.205.62.107:17136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/apikeys.php"] [unique_id "apPludKCPt8cS-VWcMm2kgAABBU"]
[Sun Aug 30 03:11:37.316998 2026] [security2:error] [pid 519566:tid 519714] [client 68.155.159.216:63245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/x.php"] [unique_id "apPludKCPt8cS-VWcMm2lAAAA7U"]
[Sun Aug 30 03:11:37.338527 2026] [security2:error] [pid 519566:tid 519769] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/storage/.env"] [unique_id "apPludKCPt8cS-VWcMm2nAAAA-w"]
[Sun Aug 30 03:11:37.357987 2026] [security2:error] [pid 519566:tid 519722] [client 20.48.250.41:19395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/a4.php"] [unique_id "apPludKCPt8cS-VWcMm2owAAA70"]
[Sun Aug 30 03:11:37.373580 2026] [security2:error] [pid 519566:tid 519723] [client 158.23.147.79:43071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.greenvillenazarene.org"] [uri "/first.php"] [unique_id "apPludKCPt8cS-VWcMm2qQAAA74"]
[Sun Aug 30 03:11:37.388402 2026] [authz_core:error] [pid 519566:tid 519762] [client 66.249.66.75:53878] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:37.388716 2026] [authz_core:error] [pid 519566:tid 519762] [client 66.249.66.75:53878] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:37.405475 2026] [authz_core:error] [pid 519566:tid 519740] [client 216.73.216.128:13745] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:37.405786 2026] [security2:error] [pid 519566:tid 519756] [client 20.48.251.3:52753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/pouhg.php"] [unique_id "apPludKCPt8cS-VWcMm2vQAAA98"]
[Sun Aug 30 03:11:37.405935 2026] [authz_core:error] [pid 519566:tid 519740] [client 216.73.216.128:13745] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:37.419627 2026] [security2:error] [pid 519566:tid 519747] [client 54.39.18.217:57798] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "54.39.18.217" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPludKCPt8cS-VWcMm2wAAAA9Y"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:11:37.419769 2026] [security2:error] [pid 519566:tid 519747] [client 54.39.18.217:57798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPludKCPt8cS-VWcMm2wAAAA9Y"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:11:37.456221 2026] [security2:error] [pid 519566:tid 519789] [client 40.83.93.50:6339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/as.php"] [unique_id "apPludKCPt8cS-VWcMm20wAABAA"]
[Sun Aug 30 03:11:37.471046 2026] [authz_core:error] [pid 519566:tid 519781] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory32
[Sun Aug 30 03:11:37.471331 2026] [authz_core:error] [pid 519566:tid 519781] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory32
[Sun Aug 30 03:11:37.492640 2026] [security2:error] [pid 519566:tid 519752] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/portal/.env"] [unique_id "apPludKCPt8cS-VWcMm25gAAA9s"]
[Sun Aug 30 03:11:37.497045 2026] [security2:error] [pid 519566:tid 519700] [client 20.104.50.220:42781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/FoxWSOv2.php"] [unique_id "apPludKCPt8cS-VWcMm26AAAA6c"]
[Sun Aug 30 03:11:37.499447 2026] [security2:error] [pid 519566:tid 519703] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/var/www/.env"] [unique_id "apPludKCPt8cS-VWcMm26QAAA6o"]
[Sun Aug 30 03:11:37.507826 2026] [security2:error] [pid 519566:tid 519736] [client 20.104.50.220:5908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/administrator.php"] [unique_id "apPludKCPt8cS-VWcMm26wAAA8s"]
[Sun Aug 30 03:11:37.511268 2026] [security2:error] [pid 519566:tid 519746] [client 20.48.251.3:36811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/X57.php"] [unique_id "apPludKCPt8cS-VWcMm27gAAA9U"]
[Sun Aug 30 03:11:37.515106 2026] [security2:error] [pid 519566:tid 519809] [client 20.48.250.41:49405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/tfm.php"] [unique_id "apPludKCPt8cS-VWcMm28AAABBQ"]
[Sun Aug 30 03:11:37.546407 2026] [security2:error] [pid 519566:tid 519758] [client 20.48.251.3:54738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/fff.php"] [unique_id "apPludKCPt8cS-VWcMm3AgAAA-E"]
[Sun Aug 30 03:11:37.547172 2026] [security2:error] [pid 519566:tid 519707] [client 4.205.62.107:36082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/cli_bootstrap.php"] [unique_id "apPludKCPt8cS-VWcMm3AwAAA64"]
[Sun Aug 30 03:11:37.569287 2026] [security2:error] [pid 519566:tid 519789] [client 20.104.18.15:31568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/133.php"] [unique_id "apPludKCPt8cS-VWcMm3CAAABAA"]
[Sun Aug 30 03:11:37.595305 2026] [security2:error] [pid 519566:tid 519794] [client 20.104.18.15:18351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/dk.php"] [unique_id "apPludKCPt8cS-VWcMm3DwAABAU"]
[Sun Aug 30 03:11:37.610816 2026] [security2:error] [pid 519566:tid 519750] [client 4.205.62.107:15987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/konfig.php"] [unique_id "apPludKCPt8cS-VWcMm3EwAAA9k"]
[Sun Aug 30 03:11:37.657213 2026] [authz_core:error] [pid 519566:tid 519729] [client 66.249.66.199:44963] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:37.657472 2026] [authz_core:error] [pid 519566:tid 519729] [client 66.249.66.199:44963] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:37.663556 2026] [security2:error] [pid 519566:tid 519765] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/var/www/html/.env"] [unique_id "apPludKCPt8cS-VWcMm3GAAAA-g"]
[Sun Aug 30 03:11:37.666994 2026] [security2:error] [pid 519566:tid 519738] [client 20.197.61.180:12266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/theme/min.php"] [unique_id "apPludKCPt8cS-VWcMm3GQAAA80"]
[Sun Aug 30 03:11:37.681184 2026] [authz_core:error] [pid 519566:tid 519752] [client 216.73.216.128:54671] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:37.681428 2026] [authz_core:error] [pid 519566:tid 519752] [client 216.73.216.128:54671] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:37.683855 2026] [security2:error] [pid 519566:tid 519718] [client 20.104.50.220:63194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/file25.php"] [unique_id "apPludKCPt8cS-VWcMm3HwAAA7k"]
[Sun Aug 30 03:11:37.687880 2026] [authz_core:error] [pid 519566:tid 519755] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:37.688317 2026] [authz_core:error] [pid 519566:tid 519755] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:37.694724 2026] [security2:error] [pid 519566:tid 519814] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/dashboard/.env"] [unique_id "apPludKCPt8cS-VWcMm3JAAABBk"]
[Sun Aug 30 03:11:37.718695 2026] [security2:error] [pid 519566:tid 519733] [client 20.104.50.220:61641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/222.php"] [unique_id "apPludKCPt8cS-VWcMm3MAAAA8g"]
[Sun Aug 30 03:11:37.736346 2026] [security2:error] [pid 519566:tid 519789] [client 20.48.250.41:49390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/Geforce.php"] [unique_id "apPludKCPt8cS-VWcMm3PwAABAA"]
[Sun Aug 30 03:11:37.755227 2026] [security2:error] [pid 519566:tid 519774] [client 4.205.62.107:52837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/xda.php"] [unique_id "apPludKCPt8cS-VWcMm3TAAAA_E"]
[Sun Aug 30 03:11:37.765845 2026] [security2:error] [pid 519566:tid 519743] [client 20.48.250.41:11050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/thui.php"] [unique_id "apPludKCPt8cS-VWcMm3UQAAA9I"]
[Sun Aug 30 03:11:37.771496 2026] [security2:error] [pid 519566:tid 519703] [client 20.104.18.15:22476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/wp-trackback.php"] [unique_id "apPludKCPt8cS-VWcMm3VAAAA6o"]
[Sun Aug 30 03:11:37.775180 2026] [authz_core:error] [pid 519566:tid 519721] [client 216.73.216.128:40285] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:37.775633 2026] [authz_core:error] [pid 519566:tid 519721] [client 216.73.216.128:40285] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:37.824591 2026] [security2:error] [pid 519566:tid 519696] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/current/.env"] [unique_id "apPludKCPt8cS-VWcMm3ZgAAA6M"]
[Sun Aug 30 03:11:37.831137 2026] [security2:error] [pid 519566:tid 519605] [remote 94.152.153.134:41652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.153.152.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "flatironmelbourne.com.au"] [uri "/wp-login.php"] [unique_id "apPludKCPt8cS-VWcMm3agAEDiY"], referer: https://flatironmelbourne.com.au/wp-login.php
[Sun Aug 30 03:11:37.870272 2026] [security2:error] [pid 519566:tid 519741] [client 20.48.250.41:49344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/click.php"] [unique_id "apPludKCPt8cS-VWcMm3fQAAA9A"]
[Sun Aug 30 03:11:37.871229 2026] [security2:error] [pid 519566:tid 519776] [client 20.104.49.130:45741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/ws78.php"] [unique_id "apPludKCPt8cS-VWcMm3fgAAA_M"]
[Sun Aug 30 03:11:37.896250 2026] [security2:error] [pid 519566:tid 519801] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/panel/.env"] [unique_id "apPludKCPt8cS-VWcMm3hAAABAw"]
[Sun Aug 30 03:11:37.917402 2026] [security2:error] [pid 519566:tid 519736] [client 20.48.251.3:52250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/motu.php"] [unique_id "apPludKCPt8cS-VWcMm3jwAAA8s"]
[Sun Aug 30 03:11:37.923779 2026] [security2:error] [pid 519566:tid 519780] [client 20.48.250.41:11085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/Jcrop.php"] [unique_id "apPludKCPt8cS-VWcMm3lQAAA_c"]
[Sun Aug 30 03:11:37.934654 2026] [security2:error] [pid 519566:tid 519714] [client 20.104.18.15:16918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/bo.php"] [unique_id "apPludKCPt8cS-VWcMm3lwAAA7U"]
[Sun Aug 30 03:11:37.943408 2026] [authz_core:error] [pid 519566:tid 519759] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory12
[Sun Aug 30 03:11:37.943683 2026] [authz_core:error] [pid 519566:tid 519759] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory12
[Sun Aug 30 03:11:37.986088 2026] [security2:error] [pid 519566:tid 519698] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/release/.env"] [unique_id "apPludKCPt8cS-VWcMm3rwAAA6U"]
[Sun Aug 30 03:11:38.011198 2026] [security2:error] [pid 519566:tid 519716] [client 68.155.159.216:52593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/.well-knownold/index.php"] [unique_id "apPlutKCPt8cS-VWcMm3uwAAA7c"]
[Sun Aug 30 03:11:38.037025 2026] [security2:error] [pid 519566:tid 519747] [client 20.48.250.41:49313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/ms.php"] [unique_id "apPlutKCPt8cS-VWcMm3yQAAA9Y"]
[Sun Aug 30 03:11:38.056154 2026] [security2:error] [pid 519566:tid 519786] [client 20.48.250.41:11118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/ws58.php"] [unique_id "apPlutKCPt8cS-VWcMm3zwAAA_0"]
[Sun Aug 30 03:11:38.091724 2026] [security2:error] [pid 519566:tid 519739] [client 20.104.50.220:16651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/ave.php"] [unique_id "apPlutKCPt8cS-VWcMm31AAAA84"]
[Sun Aug 30 03:11:38.097984 2026] [security2:error] [pid 519566:tid 519789] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/crm/.env"] [unique_id "apPlutKCPt8cS-VWcMm32AAABAA"]
[Sun Aug 30 03:11:38.134771 2026] [security2:error] [pid 519566:tid 519806] [client 40.83.93.50:6348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/credits.php"] [unique_id "apPlutKCPt8cS-VWcMm37wAABBE"]
[Sun Aug 30 03:11:38.139707 2026] [authz_core:error] [pid 519566:tid 519791] [client 216.73.216.128:65420] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:38.140076 2026] [authz_core:error] [pid 519566:tid 519791] [client 216.73.216.128:65420] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:38.146257 2026] [security2:error] [pid 519566:tid 519797] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/releases/.env"] [unique_id "apPlutKCPt8cS-VWcMm3-AAABAg"]
[Sun Aug 30 03:11:38.149013 2026] [security2:error] [pid 519566:tid 519766] [client 20.104.18.15:51197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/BDKR28WP.php"] [unique_id "apPlutKCPt8cS-VWcMm3-wAAA-k"]
[Sun Aug 30 03:11:38.184674 2026] [authz_core:error] [pid 519566:tid 519780] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:38.184950 2026] [authz_core:error] [pid 519566:tid 519780] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:38.231834 2026] [security2:error] [pid 519566:tid 519721] [client 20.48.250.41:49380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/zxekqlxb.php"] [unique_id "apPlutKCPt8cS-VWcMm4HQAAA7w"]
[Sun Aug 30 03:11:38.232201 2026] [security2:error] [pid 519566:tid 519774] [client 20.48.250.41:11125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/xs.php"] [unique_id "apPlutKCPt8cS-VWcMm4HwAAA_E"]
[Sun Aug 30 03:11:38.300575 2026] [security2:error] [pid 519566:tid 519739] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/erp/.env"] [unique_id "apPlutKCPt8cS-VWcMm4OgAAA84"]
[Sun Aug 30 03:11:38.305658 2026] [security2:error] [pid 519566:tid 519756] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/shared/.env"] [unique_id "apPlutKCPt8cS-VWcMm4PAAAA98"]
[Sun Aug 30 03:11:38.335956 2026] [security2:error] [pid 519566:tid 519742] [client 20.104.50.220:28678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/images/upload.php"] [unique_id "apPlutKCPt8cS-VWcMm4RwAAA9E"]
[Sun Aug 30 03:11:38.364199 2026] [security2:error] [pid 519566:tid 519712] [client 20.104.50.220:33317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/1index.php"] [unique_id "apPlutKCPt8cS-VWcMm4TQAAA7M"]
[Sun Aug 30 03:11:38.394011 2026] [security2:error] [pid 519566:tid 519706] [client 20.197.61.180:15777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/themes/about.php"] [unique_id "apPlutKCPt8cS-VWcMm4XAAAA60"]
[Sun Aug 30 03:11:38.418254 2026] [authz_core:error] [pid 519566:tid 519778] [client 216.73.216.128:54671] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:38.418528 2026] [authz_core:error] [pid 519566:tid 519778] [client 216.73.216.128:54671] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:38.420439 2026] [security2:error] [pid 519566:tid 519814] [client 20.151.200.44:63563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/wk/index.php"] [unique_id "apPlutKCPt8cS-VWcMm4ZAAABBk"]
[Sun Aug 30 03:11:38.429546 2026] [security2:error] [pid 519566:tid 519777] [client 20.104.50.220:62825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/aku.php"] [unique_id "apPlutKCPt8cS-VWcMm4aQAAA_Q"]
[Sun Aug 30 03:11:38.452680 2026] [security2:error] [pid 519566:tid 519763] [client 20.104.50.220:25460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/greap.php"] [unique_id "apPlutKCPt8cS-VWcMm4fgAAA-Y"]
[Sun Aug 30 03:11:38.466104 2026] [security2:error] [pid 519566:tid 519811] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/deploy/.env"] [unique_id "apPlutKCPt8cS-VWcMm4iQAABBY"]
[Sun Aug 30 03:11:38.469355 2026] [security2:error] [pid 519566:tid 519803] [client 4.205.62.107:16776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/motu.php"] [unique_id "apPlutKCPt8cS-VWcMm4jQAABA4"]
[Sun Aug 30 03:11:38.480370 2026] [authz_core:error] [pid 519566:tid 519770] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory21
[Sun Aug 30 03:11:38.480670 2026] [authz_core:error] [pid 519566:tid 519770] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory21
[Sun Aug 30 03:11:38.496543 2026] [security2:error] [pid 519566:tid 519807] [client 20.48.250.41:49318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/init.php"] [unique_id "apPlutKCPt8cS-VWcMm4mgAABBI"]
[Sun Aug 30 03:11:38.496658 2026] [security2:error] [pid 519566:tid 519777] [client 4.205.62.107:25667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/wp-access.php"] [unique_id "apPlutKCPt8cS-VWcMm4mQAAA_Q"]
[Sun Aug 30 03:11:38.498065 2026] [security2:error] [pid 519566:tid 519756] [client 20.48.250.41:11123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/zu.php"] [unique_id "apPlutKCPt8cS-VWcMm4mwAAA98"]
[Sun Aug 30 03:11:38.502889 2026] [security2:error] [pid 519566:tid 519800] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/shop/.env"] [unique_id "apPlutKCPt8cS-VWcMm4nQAABAs"]
[Sun Aug 30 03:11:38.515734 2026] [security2:error] [pid 519566:tid 519718] [client 74.7.175.173:52482] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.website-04321a97.filtagreen.com"] [uri "/cgi-sys/404.html"] [unique_id "apPlutKCPt8cS-VWcMm4oQADuS8"]
[Sun Aug 30 03:11:38.540060 2026] [security2:error] [pid 519566:tid 519709] [client 68.155.159.216:12233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-content/x.php"] [unique_id "apPlutKCPt8cS-VWcMm4sQAAA7A"]
[Sun Aug 30 03:11:38.593415 2026] [security2:error] [pid 519566:tid 519816] [client 158.23.147.79:60221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/.well-known/content.php"] [unique_id "apPlutKCPt8cS-VWcMm4vAAABBs"]
[Sun Aug 30 03:11:38.597210 2026] [security2:error] [pid 519566:tid 519728] [client 20.48.251.3:55775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/phpversion.php"] [unique_id "apPlutKCPt8cS-VWcMm4vwAAA8M"]
[Sun Aug 30 03:11:38.602370 2026] [authz_core:error] [pid 519566:tid 519751] [client 216.73.216.128:54671] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:38.602630 2026] [authz_core:error] [pid 519566:tid 519751] [client 216.73.216.128:54671] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:38.605823 2026] [security2:error] [pid 519566:tid 519719] [client 20.104.49.130:39084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/dehnl.php"] [unique_id "apPlutKCPt8cS-VWcMm4wgAAA7o"]
[Sun Aug 30 03:11:38.632271 2026] [security2:error] [pid 519566:tid 519792] [client 40.83.93.50:3932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/cache.php"] [unique_id "apPlutKCPt8cS-VWcMm4xwAABAM"]
[Sun Aug 30 03:11:38.639371 2026] [security2:error] [pid 519566:tid 519703] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/build/.env"] [unique_id "apPlutKCPt8cS-VWcMm4yAAAA6o"]
[Sun Aug 30 03:11:38.656842 2026] [security2:error] [pid 519566:tid 519823] [client 20.48.250.41:11041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/lanka.php"] [unique_id "apPlutKCPt8cS-VWcMm4zAAABCI"]
[Sun Aug 30 03:11:38.659792 2026] [authz_core:error] [pid 519566:tid 519800] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:38.660218 2026] [authz_core:error] [pid 519566:tid 519800] [client 74.7.243.204:59496] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:38.666881 2026] [security2:error] [pid 519566:tid 519805] [client 20.104.50.220:42014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/foxwsov2.php"] [unique_id "apPlutKCPt8cS-VWcMm40AAABBA"]
[Sun Aug 30 03:11:38.675082 2026] [security2:error] [pid 519566:tid 519765] [client 20.104.50.220:5512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-load.php"] [unique_id "apPlutKCPt8cS-VWcMm40wAAA-g"]
[Sun Aug 30 03:11:38.697301 2026] [security2:error] [pid 519566:tid 519817] [client 20.48.251.3:37146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/register.php"] [unique_id "apPlutKCPt8cS-VWcMm4ywAABBw"]
[Sun Aug 30 03:11:38.704138 2026] [security2:error] [pid 519566:tid 519795] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/store/.env"] [unique_id "apPlutKCPt8cS-VWcMm45wAABAY"]
[Sun Aug 30 03:11:38.706498 2026] [security2:error] [pid 519566:tid 519786] [client 20.48.250.41:49348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/term.php"] [unique_id "apPlutKCPt8cS-VWcMm46AAAA_0"]
[Sun Aug 30 03:11:38.709605 2026] [authz_core:error] [pid 519566:tid 519778] [client 66.249.66.66:65474] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:38.709886 2026] [authz_core:error] [pid 519566:tid 519778] [client 66.249.66.66:65474] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:38.714838 2026] [security2:error] [pid 519566:tid 519742] [client 20.48.251.3:64300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/autogooey.php"] [unique_id "apPlutKCPt8cS-VWcMm47QAAA9E"]
[Sun Aug 30 03:11:38.728564 2026] [security2:error] [pid 519566:tid 519698] [client 20.104.18.15:31643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/sym.php"] [unique_id "apPlutKCPt8cS-VWcMm49QAAA6U"]
[Sun Aug 30 03:11:38.743029 2026] [security2:error] [pid 519566:tid 519794] [client 4.205.62.107:36045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/dd.php"] [unique_id "apPlutKCPt8cS-VWcMm4_wAABAU"]
[Sun Aug 30 03:11:38.774155 2026] [security2:error] [pid 519566:tid 519787] [client 20.104.18.15:18350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/ta.php"] [unique_id "apPlutKCPt8cS-VWcMm5CgAAA_4"]
[Sun Aug 30 03:11:38.780385 2026] [security2:error] [pid 519566:tid 519739] [client 4.205.62.107:16320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/paths.php"] [unique_id "apPlutKCPt8cS-VWcMm5DQAAA84"]
[Sun Aug 30 03:11:38.798695 2026] [security2:error] [pid 519566:tid 519741] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/dist/.env"] [unique_id "apPlutKCPt8cS-VWcMm5GwAAA9A"]
[Sun Aug 30 03:11:38.816094 2026] [security2:error] [pid 519566:tid 519820] [client 20.104.50.220:31533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/hg.php"] [unique_id "apPlutKCPt8cS-VWcMm5JAAABB8"]
[Sun Aug 30 03:11:38.843290 2026] [security2:error] [pid 519566:tid 519756] [client 20.48.250.41:11180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/gettest.php"] [unique_id "apPlutKCPt8cS-VWcMm5NAAAA98"]
[Sun Aug 30 03:11:38.885532 2026] [security2:error] [pid 519566:tid 519749] [client 20.48.250.41:49365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/aaa.php"] [unique_id "apPlutKCPt8cS-VWcMm5RAAAA9g"]
[Sun Aug 30 03:11:38.886419 2026] [security2:error] [pid 519566:tid 519777] [client 20.151.200.44:46031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/kcs.php"] [unique_id "apPlutKCPt8cS-VWcMm5RQAAA_Q"]
[Sun Aug 30 03:11:38.895245 2026] [security2:error] [pid 519566:tid 519807] [client 20.104.50.220:61671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/444.php"] [unique_id "apPlutKCPt8cS-VWcMm5SgAABBI"]
[Sun Aug 30 03:11:38.906287 2026] [security2:error] [pid 519566:tid 519700] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/saas/.env"] [unique_id "apPlutKCPt8cS-VWcMm5TQAAA6c"]
[Sun Aug 30 03:11:38.919760 2026] [security2:error] [pid 519566:tid 519784] [client 20.104.18.15:22434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/pri.php"] [unique_id "apPlutKCPt8cS-VWcMm5UwAAA_s"]
[Sun Aug 30 03:11:38.945787 2026] [authz_core:error] [pid 519566:tid 519751] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory12
[Sun Aug 30 03:11:38.946151 2026] [authz_core:error] [pid 519566:tid 519751] [client 74.7.227.8:37694] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory12
[Sun Aug 30 03:11:38.958535 2026] [security2:error] [pid 519566:tid 519767] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/public_html/.env"] [unique_id "apPlutKCPt8cS-VWcMm5YwAAA-o"]
[Sun Aug 30 03:11:38.973593 2026] [authz_core:error] [pid 519566:tid 519743] [client 216.73.216.128:54671] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:38.973904 2026] [authz_core:error] [pid 519566:tid 519743] [client 216.73.216.128:54671] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:38.978408 2026] [security2:error] [pid 519566:tid 519806] [client 4.205.62.107:52887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/pinfo.php"] [unique_id "apPlutKCPt8cS-VWcMm5bAAABBE"]
[Sun Aug 30 03:11:38.987735 2026] [security2:error] [pid 519566:tid 519702] [client 20.48.250.41:11101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/35.php"] [unique_id "apPlutKCPt8cS-VWcMm5cwAAA6k"]
[Sun Aug 30 03:11:39.017118 2026] [security2:error] [pid 519566:tid 519715] [client 20.48.250.41:49315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/xsox.php"] [unique_id "apPlu9KCPt8cS-VWcMm5ggAAA7Y"]
[Sun Aug 30 03:11:39.055175 2026] [security2:error] [pid 519566:tid 519763] [client 20.48.251.3:59479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/public/mah.php.php"] [unique_id "apPlu9KCPt8cS-VWcMm5lAAAA-Y"]
[Sun Aug 30 03:11:39.069674 2026] [security2:error] [pid 519566:tid 519785] [client 20.104.18.15:16939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/44.php"] [unique_id "apPlu9KCPt8cS-VWcMm5mgAAA_w"]
[Sun Aug 30 03:11:39.109871 2026] [security2:error] [pid 519566:tid 519787] [client 34.15.159.88:36856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/client/.env"] [unique_id "apPlu9KCPt8cS-VWcMm5sQAAA_4"]
[Sun Aug 30 03:11:39.116861 2026] [security2:error] [pid 519566:tid 519798] [client 20.197.61.180:3783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/themes/panel.php"] [unique_id "apPlu9KCPt8cS-VWcMm5tQAABAk"]
[Sun Aug 30 03:11:39.120744 2026] [security2:error] [pid 519566:tid 519810] [client 20.48.250.41:11109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/maraz.php"] [unique_id "apPlu9KCPt8cS-VWcMm5uQAABBU"]
[Sun Aug 30 03:11:39.131242 2026] [security2:error] [pid 519566:tid 519727] [client 35.247.242.193:45298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/htdocs/.env"] [unique_id "apPlu9KCPt8cS-VWcMm5vQAAA8I"]
[Sun Aug 30 03:11:39.143517 2026] [security2:error] [pid 519566:tid 519795] [client 40.83.93.50:7085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/fix.php"] [unique_id "apPlu9KCPt8cS-VWcMm51wAABAY"]
[Sun Aug 30 03:11:39.524672 2026] [http2:info] [pid 521505:tid 521505] h2_workers: created with min=128 max=192 idle_ms=600000
[Sun Aug 30 03:11:39.543694 2026] [security2:error] [pid 521505:tid 521637] [client 20.104.50.220:33187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/2index.php"] [unique_id "apPlu28byYE0iXl--K5keAAAAyA"]
[Sun Aug 30 03:11:39.544627 2026] [security2:error] [pid 521505:tid 521636] [client 20.104.50.220:62827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/images/fox.php"] [unique_id "apPlu28byYE0iXl--K5kegAAAx8"]
[Sun Aug 30 03:11:39.545220 2026] [security2:error] [pid 521505:tid 521640] [client 20.151.200.44:65382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/pk.php"] [unique_id "apPlu28byYE0iXl--K5kfQAAAyM"]
[Sun Aug 30 03:11:39.545253 2026] [security2:error] [pid 521505:tid 521639] [client 20.104.18.15:51074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/sf.php"] [unique_id "apPlu28byYE0iXl--K5kfAAAAyI"]
[Sun Aug 30 03:11:39.545698 2026] [security2:error] [pid 521505:tid 521642] [client 20.104.50.220:16755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wrt.php"] [unique_id "apPlu28byYE0iXl--K5kfgAAAyU"]
[Sun Aug 30 03:11:39.546008 2026] [security2:error] [pid 521505:tid 521641] [client 20.48.250.41:19415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/lkui.php"] [unique_id "apPlu28byYE0iXl--K5kfwAAAyQ"]
[Sun Aug 30 03:11:39.546484 2026] [security2:error] [pid 521505:tid 521644] [client 68.155.159.216:52313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apPlu28byYE0iXl--K5kgQAAAyc"]
[Sun Aug 30 03:11:39.546513 2026] [security2:error] [pid 521505:tid 521652] [client 20.48.250.41:11207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/kbfr.php"] [unique_id "apPlu28byYE0iXl--K5kggAAAy8"]
[Sun Aug 30 03:11:39.546720 2026] [core:alert] [pid 521505:tid 521643] [client 86.45.77.174:45788] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:11:39.547511 2026] [core:alert] [pid 521505:tid 521653] [client 177.230.70.128:7654] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:11:39.557155 2026] [authz_core:error] [pid 521505:tid 521659] [client 66.249.66.43:54398] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:39.557312 2026] [authz_core:error] [pid 521505:tid 521660] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory21
[Sun Aug 30 03:11:39.557451 2026] [authz_core:error] [pid 521505:tid 521659] [client 66.249.66.43:54398] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:39.557611 2026] [authz_core:error] [pid 521505:tid 521660] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory21
[Sun Aug 30 03:11:39.572088 2026] [security2:error] [pid 521505:tid 521667] [client 20.151.200.44:26562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlu28byYE0iXl--K5kkAAAAz4"]
[Sun Aug 30 03:11:39.582081 2026] [security2:error] [pid 521505:tid 521671] [client 20.104.50.220:62798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/syg.php"] [unique_id "apPlu28byYE0iXl--K5kkQAAA0I"]
[Sun Aug 30 03:11:39.606593 2026] [security2:error] [pid 521505:tid 521677] [client 20.104.50.220:25467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/177.php"] [unique_id "apPlu28byYE0iXl--K5klQAAA0g"]
[Sun Aug 30 03:11:39.607036 2026] [authz_core:error] [pid 521505:tid 521646] [client 66.249.66.45:63970] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:39.607340 2026] [authz_core:error] [pid 521505:tid 521646] [client 66.249.66.45:63970] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:39.607710 2026] [security2:error] [pid 521505:tid 521678] [client 4.205.62.107:16823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/public/mah.php.php"] [unique_id "apPlu28byYE0iXl--K5klgAAA0k"]
[Sun Aug 30 03:11:39.697628 2026] [authz_core:error] [pid 521505:tid 521689] [client 66.249.66.192:37709] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:39.698050 2026] [authz_core:error] [pid 521505:tid 521689] [client 66.249.66.192:37709] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:39.707652 2026] [authz_core:error] [pid 521505:tid 521702] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:39.708071 2026] [authz_core:error] [pid 521505:tid 521702] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:39.709855 2026] [security2:error] [pid 521505:tid 521704] [client 68.155.159.216:12242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPlu28byYE0iXl--K5kpwAAA2M"]
[Sun Aug 30 03:11:39.715570 2026] [security2:error] [pid 521505:tid 521649] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/html/.env"] [unique_id "apPlu28byYE0iXl--K5kqAAAAyw"]
[Sun Aug 30 03:11:39.718488 2026] [security2:error] [pid 521505:tid 521705] [client 20.48.250.41:19443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apPlu28byYE0iXl--K5kqQAAA2Q"]
[Sun Aug 30 03:11:39.722261 2026] [security2:error] [pid 521505:tid 521706] [client 20.48.250.41:11022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/wp-act.php"] [unique_id "apPlu28byYE0iXl--K5kqgAAA2U"]
[Sun Aug 30 03:11:39.745568 2026] [security2:error] [pid 521505:tid 521709] [client 20.48.251.3:59291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/adminfus.php"] [unique_id "apPlu28byYE0iXl--K5krAAAA2g"]
[Sun Aug 30 03:11:39.752483 2026] [security2:error] [pid 521505:tid 521663] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/admin-panel/.env"] [unique_id "apPlu28byYE0iXl--K5krQAAAzo"]
[Sun Aug 30 03:11:39.771184 2026] [security2:error] [pid 521505:tid 521684] [client 40.83.93.50:7049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/alfa.php"] [unique_id "apPlu28byYE0iXl--K5krwAAA08"]
[Sun Aug 30 03:11:39.812499 2026] [security2:error] [pid 521505:tid 521719] [client 20.104.50.220:5951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-includes.php"] [unique_id "apPlu28byYE0iXl--K5ktAAAA3I"]
[Sun Aug 30 03:11:39.821989 2026] [security2:error] [pid 521505:tid 521724] [client 4.205.62.107:26978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/otuz1.php"] [unique_id "apPlu28byYE0iXl--K5ktgAAA3c"]
[Sun Aug 30 03:11:39.838738 2026] [security2:error] [pid 521505:tid 521728] [client 20.48.251.3:37139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/xqq.php"] [unique_id "apPlu28byYE0iXl--K5k5AAAA3s"]
[Sun Aug 30 03:11:39.849868 2026] [security2:error] [pid 521505:tid 521731] [client 20.104.50.220:63547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/shellx.php"] [unique_id "apPlu28byYE0iXl--K5k-gAAA34"]
[Sun Aug 30 03:11:39.875005 2026] [security2:error] [pid 521505:tid 521737] [client 4.205.62.107:36065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/wp-tem.php"] [unique_id "apPlu28byYE0iXl--K5lAAAAA4Q"]
[Sun Aug 30 03:11:39.875675 2026] [security2:error] [pid 521505:tid 521736] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/live/.env"] [unique_id "apPlu28byYE0iXl--K5k_wAAA4M"]
[Sun Aug 30 03:11:39.881925 2026] [core:alert] [pid 521505:tid 521739] [client 47.79.13.63:56490] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:11:39.885552 2026] [security2:error] [pid 521505:tid 521740] [client 20.104.49.130:60982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/ws78.php"] [unique_id "apPlu28byYE0iXl--K5lAgAAA4c"]
[Sun Aug 30 03:11:39.903452 2026] [security2:error] [pid 521505:tid 521745] [client 20.48.251.3:54782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/sdsa.php"] [unique_id "apPlu28byYE0iXl--K5lBAAAA4w"]
[Sun Aug 30 03:11:39.922909 2026] [security2:error] [pid 521505:tid 521748] [client 158.23.147.79:40004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlu28byYE0iXl--K5lBQAAA48"]
[Sun Aug 30 03:11:39.924595 2026] [security2:error] [pid 521505:tid 521749] [client 20.104.18.15:31572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/8.php"] [unique_id "apPlu28byYE0iXl--K5lBgAAA5A"]
[Sun Aug 30 03:11:39.924725 2026] [security2:error] [pid 521505:tid 521750] [client 20.48.250.41:11028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/24.php"] [unique_id "apPlu28byYE0iXl--K5lBwAAA5E"]
[Sun Aug 30 03:11:39.936054 2026] [security2:error] [pid 521505:tid 521753] [client 4.205.62.107:16329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/olfclass.php"] [unique_id "apPlu28byYE0iXl--K5lCAAAA5Q"]
[Sun Aug 30 03:11:39.943256 2026] [security2:error] [pid 521505:tid 521755] [client 20.104.18.15:18297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/bo.php"] [unique_id "apPlu28byYE0iXl--K5lCQAAA5Y"]
[Sun Aug 30 03:11:39.951593 2026] [authz_core:error] [pid 521505:tid 521756] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory20
[Sun Aug 30 03:11:39.951900 2026] [authz_core:error] [pid 521505:tid 521756] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory20
[Sun Aug 30 03:11:39.952580 2026] [security2:error] [pid 521505:tid 521758] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/control-panel/.env"] [unique_id "apPlu28byYE0iXl--K5lCwAAA5k"]
[Sun Aug 30 03:11:39.973189 2026] [security2:error] [pid 521505:tid 521761] [client 20.104.50.220:59361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/file48.php"] [unique_id "apPlu28byYE0iXl--K5lDQAAA5w"]
[Sun Aug 30 03:11:39.998566 2026] [authz_core:error] [pid 521505:tid 521641] [client 216.73.216.128:45356] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:39.999014 2026] [authz_core:error] [pid 521505:tid 521641] [client 216.73.216.128:45356] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:40.015498 2026] [security2:error] [pid 521505:tid 521664] [client 20.48.250.41:19337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/motu.php"] [unique_id "apPlvG8byYE0iXl--K5lEQAAAzs"]
[Sun Aug 30 03:11:40.026697 2026] [security2:error] [pid 521505:tid 521667] [client 20.104.49.130:53883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/yawa.php"] [unique_id "apPlvG8byYE0iXl--K5lEwAAAz4"]
[Sun Aug 30 03:11:40.036588 2026] [security2:error] [pid 521505:tid 521668] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/prod/.env"] [unique_id "apPlvG8byYE0iXl--K5lFAAAAz8"]
[Sun Aug 30 03:11:40.055401 2026] [security2:error] [pid 521505:tid 521669] [client 20.104.50.220:61452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/file9.php"] [unique_id "apPlvG8byYE0iXl--K5lFQAAA0A"]
[Sun Aug 30 03:11:40.064699 2026] [security2:error] [pid 521505:tid 521675] [client 20.197.61.180:18051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/twentytwentyfive/styles/sections/pk.php"] [unique_id "apPlvG8byYE0iXl--K5lFgAAA0Y"]
[Sun Aug 30 03:11:40.083573 2026] [security2:error] [pid 521505:tid 521679] [client 20.104.18.15:22497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/wp_blog_footer.php"] [unique_id "apPlvG8byYE0iXl--K5lGAAAA0o"]
[Sun Aug 30 03:11:40.119095 2026] [security2:error] [pid 521505:tid 521683] [client 20.48.250.41:11025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/155.php"] [unique_id "apPlvG8byYE0iXl--K5lGQAAA04"]
[Sun Aug 30 03:11:40.124792 2026] [security2:error] [pid 521505:tid 521686] [client 158.23.147.79:60185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/cong.php"] [unique_id "apPlvG8byYE0iXl--K5lGgAAA1E"]
[Sun Aug 30 03:11:40.151675 2026] [security2:error] [pid 521505:tid 521638] [client 20.151.200.44:64742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/ft.php"] [unique_id "apPlvG8byYE0iXl--K5lHAAAAyE"]
[Sun Aug 30 03:11:40.152713 2026] [security2:error] [pid 521505:tid 521655] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/user-panel/.env"] [unique_id "apPlvG8byYE0iXl--K5lHQAAAzI"]
[Sun Aug 30 03:11:40.172243 2026] [security2:error] [pid 521505:tid 521694] [client 20.48.250.41:49316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/Ov-Simple1.php"] [unique_id "apPlvG8byYE0iXl--K5lIAAAA1k"]
[Sun Aug 30 03:11:40.176022 2026] [authz_core:error] [pid 521505:tid 521693] [client 216.73.216.128:16988] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:40.176278 2026] [authz_core:error] [pid 521505:tid 521693] [client 216.73.216.128:16988] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:40.197421 2026] [security2:error] [pid 521505:tid 521700] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/dev/.env"] [unique_id "apPlvG8byYE0iXl--K5lJAAAA18"]
[Sun Aug 30 03:11:40.201152 2026] [security2:error] [pid 521505:tid 521704] [client 4.205.62.107:52831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/X57.php"] [unique_id "apPlvG8byYE0iXl--K5lJQAAA2M"]
[Sun Aug 30 03:11:40.202033 2026] [authz_core:error] [pid 521505:tid 521657] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:40.202276 2026] [authz_core:error] [pid 521505:tid 521657] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:40.208456 2026] [security2:error] [pid 521505:tid 521649] [client 20.104.49.130:64710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/dex.php"] [unique_id "apPlvG8byYE0iXl--K5lJgAAAyw"]
[Sun Aug 30 03:11:40.212183 2026] [security2:error] [pid 521505:tid 521705] [client 20.104.18.15:16967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/h2.php"] [unique_id "apPlvG8byYE0iXl--K5lJwAAA2Q"]
[Sun Aug 30 03:11:40.229688 2026] [security2:error] [pid 521505:tid 521706] [client 20.48.251.3:52229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/zaza.php"] [unique_id "apPlvG8byYE0iXl--K5lKQAAA2U"]
[Sun Aug 30 03:11:40.256309 2026] [security2:error] [pid 521505:tid 521682] [client 40.83.93.50:6346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/wp-blog-header.php"] [unique_id "apPlvG8byYE0iXl--K5lKgAAA00"]
[Sun Aug 30 03:11:40.263720 2026] [security2:error] [pid 521505:tid 521709] [client 20.48.250.41:11131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/file.php"] [unique_id "apPlvG8byYE0iXl--K5lKwAAA2g"]
[Sun Aug 30 03:11:40.331631 2026] [security2:error] [pid 521505:tid 521718] [client 20.48.250.41:49341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/wp-blogs.php"] [unique_id "apPlvG8byYE0iXl--K5lLgAAA3E"]
[Sun Aug 30 03:11:40.353591 2026] [security2:error] [pid 521505:tid 521720] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/node/.env"] [unique_id "apPlvG8byYE0iXl--K5lMAAAA3M"]
[Sun Aug 30 03:11:40.358050 2026] [security2:error] [pid 521505:tid 521721] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/staging/.env"] [unique_id "apPlvG8byYE0iXl--K5lMQAAA3Q"]
[Sun Aug 30 03:11:40.440110 2026] [security2:error] [pid 521505:tid 521737] [client 20.48.250.41:10999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPlvG8byYE0iXl--K5lOgAAA4Q"]
[Sun Aug 30 03:11:40.462918 2026] [security2:error] [pid 521505:tid 521702] [client 158.23.147.79:39953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlvG8byYE0iXl--K5lPgAAA2E"]
[Sun Aug 30 03:11:40.469401 2026] [security2:error] [pid 521505:tid 521743] [client 20.48.250.41:19392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/mini.php"] [unique_id "apPlvG8byYE0iXl--K5lQAAAA4o"]
[Sun Aug 30 03:11:40.487887 2026] [authz_core:error] [pid 521505:tid 521744] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory24
[Sun Aug 30 03:11:40.488153 2026] [authz_core:error] [pid 521505:tid 521744] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory24
[Sun Aug 30 03:11:40.525938 2026] [security2:error] [pid 521505:tid 521680] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/opt/.env"] [unique_id "apPlvG8byYE0iXl--K5lRAAAA0s"]
[Sun Aug 30 03:11:40.543949 2026] [authz_core:error] [pid 521505:tid 521747] [client 66.249.66.206:65395] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:40.544232 2026] [authz_core:error] [pid 521505:tid 521747] [client 66.249.66.206:65395] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:40.554854 2026] [security2:error] [pid 521505:tid 521758] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/express/.env"] [unique_id "apPlvG8byYE0iXl--K5lRwAAA5k"]
[Sun Aug 30 03:11:40.588511 2026] [security2:error] [pid 521505:tid 521760] [client 20.48.250.41:11140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/06.php"] [unique_id "apPlvG8byYE0iXl--K5lSQAAA5s"]
[Sun Aug 30 03:11:40.632318 2026] [security2:error] [pid 521505:tid 521692] [client 20.48.250.41:49312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/amp.php"] [unique_id "apPlvG8byYE0iXl--K5lTQAAA1c"]
[Sun Aug 30 03:11:40.633456 2026] [security2:error] [pid 521505:tid 521716] [client 20.151.200.44:23599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/dehnl.php"] [unique_id "apPlvG8byYE0iXl--K5lTgAAA28"]
[Sun Aug 30 03:11:40.674058 2026] [security2:error] [pid 521505:tid 521643] [client 20.151.200.44:26509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlvG8byYE0iXl--K5lTwAAAyY"]
[Sun Aug 30 03:11:40.677552 2026] [security2:error] [pid 521505:tid 521650] [client 20.104.50.220:17298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/bibil.php"] [unique_id "apPlvG8byYE0iXl--K5lUAAAAy0"]
[Sun Aug 30 03:11:40.686883 2026] [security2:error] [pid 521505:tid 521662] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/laravel/.env"] [unique_id "apPlvG8byYE0iXl--K5lUQAAAzk"]
[Sun Aug 30 03:11:40.697897 2026] [security2:error] [pid 521505:tid 521732] [client 20.104.18.15:51148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/k.php"] [unique_id "apPlvG8byYE0iXl--K5lVAAAA38"]
[Sun Aug 30 03:11:40.698006 2026] [security2:error] [pid 521505:tid 521659] [client 20.104.50.220:62826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/images/fw.php"] [unique_id "apPlvG8byYE0iXl--K5lUwAAAzY"]
[Sun Aug 30 03:11:40.699576 2026] [security2:error] [pid 521505:tid 521671] [client 20.151.200.44:41813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/pb.php"] [unique_id "apPlvG8byYE0iXl--K5lVQAAA0I"]
[Sun Aug 30 03:11:40.700266 2026] [authz_core:error] [pid 521505:tid 521667] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:40.700599 2026] [authz_core:error] [pid 521505:tid 521667] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:40.701678 2026] [security2:error] [pid 521505:tid 521674] [client 20.104.50.220:33052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/3index.php"] [unique_id "apPlvG8byYE0iXl--K5lVgAAA0U"]
[Sun Aug 30 03:11:40.732235 2026] [security2:error] [pid 521505:tid 521727] [client 40.83.93.50:6800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/s.php"] [unique_id "apPlvG8byYE0iXl--K5lWQAAA3o"]
[Sun Aug 30 03:11:40.733990 2026] [security2:error] [pid 521505:tid 521715] [client 178.20.43.173:63765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.43.20.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.maarifado.com"] [uri "/register/"] [unique_id "apPlvG8byYE0iXl--K5lVwAAA24"], referer: http://www.maarifado.com/membership-account/membership-levels/
[Sun Aug 30 03:11:40.734107 2026] [security2:error] [pid 521505:tid 521715] [client 178.20.43.173:63765] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "160"] [id "900408"] [msg "register POST logging"] [data "409"] [hostname "www.maarifado.com"] [uri "/register/"] [unique_id "apPlvG8byYE0iXl--K5lVwAAA24"], referer: http://www.maarifado.com/membership-account/membership-levels/
[Sun Aug 30 03:11:40.742513 2026] [security2:error] [pid 521505:tid 521648] [client 68.155.159.216:52299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPlvG8byYE0iXl--K5lWgAAAys"]
[Sun Aug 30 03:11:40.747699 2026] [security2:error] [pid 521505:tid 521742] [client 4.205.62.107:17337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/zaza.php"] [unique_id "apPlvG8byYE0iXl--K5lWwAAA4k"]
[Sun Aug 30 03:11:40.754990 2026] [security2:error] [pid 521505:tid 521677] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/next/.env"] [unique_id "apPlvG8byYE0iXl--K5lXAAAA0g"]
[Sun Aug 30 03:11:40.763530 2026] [security2:error] [pid 521505:tid 521679] [client 20.48.250.41:19272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/cc13.php"] [unique_id "apPlvG8byYE0iXl--K5lXQAAA0o"]
[Sun Aug 30 03:11:40.768176 2026] [security2:error] [pid 521505:tid 521756] [client 20.104.50.220:52847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/contactz.php"] [unique_id "apPlvG8byYE0iXl--K5lXgAAA5c"]
[Sun Aug 30 03:11:40.780104 2026] [security2:error] [pid 521505:tid 521686] [client 20.104.50.220:25422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/199.php"] [unique_id "apPlvG8byYE0iXl--K5lYAAAA1E"]
[Sun Aug 30 03:11:40.814155 2026] [security2:error] [pid 521505:tid 521700] [client 216.73.216.128:59099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/readme-html.dir/readme.pt-br.html"] [unique_id "apPlvG8byYE0iXl--K5lZwAAA18"]
[Sun Aug 30 03:11:40.819568 2026] [security2:error] [pid 521505:tid 521649] [client 20.104.49.130:63249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/worksec.php"] [unique_id "apPlvG8byYE0iXl--K5laAAAAyw"]
[Sun Aug 30 03:11:40.820791 2026] [security2:error] [pid 521505:tid 521696] [client 68.155.159.216:62605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/log-mama/function.php"] [unique_id "apPlvG8byYE0iXl--K5laQAAA1s"]
[Sun Aug 30 03:11:40.822310 2026] [security2:error] [pid 521505:tid 521706] [client 20.104.49.130:63601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wdfjba.org"] [uri "/ops.php"] [unique_id "apPlvG8byYE0iXl--K5lagAAA2U"]
[Sun Aug 30 03:11:40.823407 2026] [security2:error] [pid 521505:tid 521647] [client 20.48.250.41:11140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/class.php"] [unique_id "apPlvG8byYE0iXl--K5lbAAAAyo"]
[Sun Aug 30 03:11:40.846883 2026] [security2:error] [pid 521505:tid 521708] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/symfony/.env"] [unique_id "apPlvG8byYE0iXl--K5lbwAAA2c"]
[Sun Aug 30 03:11:40.878525 2026] [security2:error] [pid 521505:tid 521635] [client 20.48.251.3:55748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/avim.php"] [unique_id "apPlvG8byYE0iXl--K5lcQAAAx4"]
[Sun Aug 30 03:11:40.879860 2026] [authz_core:error] [pid 521505:tid 521676] [client 66.249.66.192:34784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:40.880121 2026] [authz_core:error] [pid 521505:tid 521676] [client 66.249.66.192:34784] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:40.914802 2026] [security2:error] [pid 521505:tid 521718] [client 20.48.250.41:49356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/aa.php"] [unique_id "apPlvG8byYE0iXl--K5lcwAAA3E"]
[Sun Aug 30 03:11:40.953805 2026] [security2:error] [pid 521505:tid 521658] [client 20.48.250.41:11096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/8.php"] [unique_id "apPlvG8byYE0iXl--K5ldAAAAzU"]
[Sun Aug 30 03:11:40.955815 2026] [security2:error] [pid 521505:tid 521721] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/nuxt/.env"] [unique_id "apPlvG8byYE0iXl--K5ldQAAA3Q"]
[Sun Aug 30 03:11:40.964144 2026] [authz_core:error] [pid 521505:tid 521657] [client 66.249.66.196:45572] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:40.964460 2026] [authz_core:error] [pid 521505:tid 521657] [client 66.249.66.196:45572] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:40.966109 2026] [security2:error] [pid 521505:tid 521728] [client 20.104.50.220:5199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-content.php"] [unique_id "apPlvG8byYE0iXl--K5leQAAA3s"]
[Sun Aug 30 03:11:40.981525 2026] [security2:error] [pid 521505:tid 521734] [client 20.48.251.3:37144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/a1vx.php"] [unique_id "apPlvG8byYE0iXl--K5lewAAA4E"]
[Sun Aug 30 03:11:40.990427 2026] [authz_core:error] [pid 521505:tid 521688] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory23
[Sun Aug 30 03:11:40.990713 2026] [authz_core:error] [pid 521505:tid 521688] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory23
[Sun Aug 30 03:11:41.006364 2026] [security2:error] [pid 521505:tid 521740] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/wordpress/.env"] [unique_id "apPlvW8byYE0iXl--K5lgAAAA4c"]
[Sun Aug 30 03:11:41.010277 2026] [security2:error] [pid 521505:tid 521702] [client 20.104.50.220:51585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/1index.php"] [unique_id "apPlvW8byYE0iXl--K5lgQAAA2E"]
[Sun Aug 30 03:11:41.010657 2026] [security2:error] [pid 521505:tid 521665] [client 114.119.140.239:21499] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tgifa.org"] [uri "/webinars/"] [unique_id "apPlvW8byYE0iXl--K5lggAAAzw"], referer: https://tgifa.org/webinars/
[Sun Aug 30 03:11:41.015272 2026] [security2:error] [pid 521505:tid 521743] [client 4.205.62.107:36552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/txets.php"] [unique_id "apPlvW8byYE0iXl--K5lgwAAA4o"]
[Sun Aug 30 03:11:41.021377 2026] [security2:error] [pid 521505:tid 521745] [client 20.197.61.180:8263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/twentytwentythree/patterns/index.php"] [unique_id "apPlvW8byYE0iXl--K5lhAAAA4w"]
[Sun Aug 30 03:11:41.089077 2026] [security2:error] [pid 521505:tid 521754] [client 20.104.18.15:18294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/44.php"] [unique_id "apPlvW8byYE0iXl--K5lhwAAA5U"]
[Sun Aug 30 03:11:41.094547 2026] [security2:error] [pid 521505:tid 521707] [client 4.205.62.107:15969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/gnmlc.php"] [unique_id "apPlvW8byYE0iXl--K5liAAAA2Y"]
[Sun Aug 30 03:11:41.099109 2026] [security2:error] [pid 521505:tid 521758] [client 20.48.250.41:49347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/s1.php"] [unique_id "apPlvW8byYE0iXl--K5liQAAA5k"]
[Sun Aug 30 03:11:41.103032 2026] [security2:error] [pid 521505:tid 521755] [client 20.48.250.41:11263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/0x0x.php"] [unique_id "apPlvW8byYE0iXl--K5ligAAA5Y"]
[Sun Aug 30 03:11:41.109185 2026] [security2:error] [pid 521505:tid 521760] [client 20.104.50.220:31500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/ff.php"] [unique_id "apPlvW8byYE0iXl--K5ljAAAA5s"]
[Sun Aug 30 03:11:41.112083 2026] [security2:error] [pid 521505:tid 521699] [client 20.104.18.15:31723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/ws55.php"] [unique_id "apPlvW8byYE0iXl--K5ljQAAA14"]
[Sun Aug 30 03:11:41.114171 2026] [security2:error] [pid 521505:tid 521636] [client 20.48.251.3:54768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/sale.php"] [unique_id "apPlvW8byYE0iXl--K5ljgAAAx8"]
[Sun Aug 30 03:11:41.140899 2026] [security2:error] [pid 521505:tid 521736] [client 158.23.147.79:40024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apPlvW8byYE0iXl--K5lkAAAA4M"]
[Sun Aug 30 03:11:41.156785 2026] [security2:error] [pid 521505:tid 521692] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/nest/.env"] [unique_id "apPlvW8byYE0iXl--K5lkQAAA1c"]
[Sun Aug 30 03:11:41.168316 2026] [authz_core:error] [pid 521505:tid 521744] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZA%2FLC_MESSAGES
[Sun Aug 30 03:11:41.168671 2026] [authz_core:error] [pid 521505:tid 521744] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_ZA%2FLC_MESSAGES
[Sun Aug 30 03:11:41.170005 2026] [security2:error] [pid 521505:tid 521751] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/wp/.env"] [unique_id "apPlvW8byYE0iXl--K5lkwAAA5I"]
[Sun Aug 30 03:11:41.226859 2026] [security2:error] [pid 521505:tid 521697] [client 20.104.18.15:22365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/sushi.php"] [unique_id "apPlvW8byYE0iXl--K5lmAAAA1w"]
[Sun Aug 30 03:11:41.247708 2026] [security2:error] [pid 521505:tid 521715] [client 20.48.250.41:49396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/0byte.php"] [unique_id "apPlvW8byYE0iXl--K5lmQAAA24"]
[Sun Aug 30 03:11:41.258742 2026] [security2:error] [pid 521505:tid 521684] [client 40.83.93.50:6818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/php.php"] [unique_id "apPlvW8byYE0iXl--K5lmgAAA08"]
[Sun Aug 30 03:11:41.263757 2026] [security2:error] [pid 521505:tid 521675] [client 20.48.250.41:11192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/166.php"] [unique_id "apPlvW8byYE0iXl--K5lmwAAA0Y"]
[Sun Aug 30 03:11:41.288385 2026] [authz_core:error] [pid 521505:tid 521757] [client 66.249.66.193:40145] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:41.288858 2026] [authz_core:error] [pid 521505:tid 521757] [client 66.249.66.193:40145] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:41.321867 2026] [security2:error] [pid 521505:tid 521756] [client 4.205.62.107:25701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/update.php"] [unique_id "apPlvW8byYE0iXl--K5loAAAA5c"]
[Sun Aug 30 03:11:41.324922 2026] [security2:error] [pid 521505:tid 521683] [client 20.104.50.220:61667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/filesss.php"] [unique_id "apPlvW8byYE0iXl--K5loQAAA04"]
[Sun Aug 30 03:11:41.333694 2026] [security2:error] [pid 521505:tid 521638] [client 20.151.200.44:46072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/tajj.php"] [unique_id "apPlvW8byYE0iXl--K5lpQAAAyE"]
[Sun Aug 30 03:11:41.334186 2026] [security2:error] [pid 521505:tid 521690] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/cms/.env"] [unique_id "apPlvW8byYE0iXl--K5logAAA1U"]
[Sun Aug 30 03:11:41.357009 2026] [security2:error] [pid 521505:tid 521703] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/react/.env"] [unique_id "apPlvW8byYE0iXl--K5lqQAAA2I"]
[Sun Aug 30 03:11:41.360385 2026] [security2:error] [pid 521505:tid 521704] [client 20.104.18.15:64721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apPlvW8byYE0iXl--K5lqwAAA2M"]
[Sun Aug 30 03:11:41.364088 2026] [security2:error] [pid 521505:tid 521656] [client 20.48.251.3:59900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/u88.php"] [unique_id "apPlvW8byYE0iXl--K5lrAAAAzM"]
[Sun Aug 30 03:11:41.374550 2026] [security2:error] [pid 521505:tid 521649] [client 20.48.250.41:19437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/xr.php"] [unique_id "apPlvW8byYE0iXl--K5lrQAAAyw"]
[Sun Aug 30 03:11:41.391526 2026] [security2:error] [pid 521505:tid 521637] [client 20.48.250.41:11134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/h2a2ck.php"] [unique_id "apPlvW8byYE0iXl--K5lrwAAAyA"]
[Sun Aug 30 03:11:41.406374 2026] [security2:error] [pid 521505:tid 521708] [client 158.23.147.79:58395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-includes/js/index.php"] [unique_id "apPlvW8byYE0iXl--K5lsAAAA2c"]
[Sun Aug 30 03:11:41.425594 2026] [security2:error] [pid 521505:tid 521759] [client 4.205.62.107:52825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/register.php"] [unique_id "apPlvW8byYE0iXl--K5lsQAAA5o"]
[Sun Aug 30 03:11:41.495815 2026] [security2:error] [pid 521505:tid 521719] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/drupal/.env"] [unique_id "apPlvW8byYE0iXl--K5ltQAAA3I"]
[Sun Aug 30 03:11:41.506268 2026] [authz_core:error] [pid 521505:tid 521685] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory28
[Sun Aug 30 03:11:41.506535 2026] [authz_core:error] [pid 521505:tid 521685] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory28
[Sun Aug 30 03:11:41.508229 2026] [security2:error] [pid 521505:tid 521658] [client 20.48.250.41:19421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/h02ugyh.php"] [unique_id "apPlvW8byYE0iXl--K5luAAAAzU"]
[Sun Aug 30 03:11:41.558619 2026] [security2:error] [pid 521505:tid 521729] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/vue/.env"] [unique_id "apPlvW8byYE0iXl--K5lwAAAA3w"]
[Sun Aug 30 03:11:41.574328 2026] [security2:error] [pid 521505:tid 521741] [client 20.48.250.41:11074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/error_log.php"] [unique_id "apPlvW8byYE0iXl--K5lwgAAA4g"]
[Sun Aug 30 03:11:41.588569 2026] [security2:error] [pid 521505:tid 521609] [remote 129.121.76.191:52548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.76.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ionicfab.net"] [uri "/wp-login.php"] [unique_id "apPlvW8byYE0iXl--K5lwwADiWc"]
[Sun Aug 30 03:11:41.601153 2026] [authz_core:error] [pid 521505:tid 521691] [client 66.249.66.199:48832] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:41.601476 2026] [authz_core:error] [pid 521505:tid 521691] [client 66.249.66.199:48832] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:41.651862 2026] [core:alert] [pid 521505:tid 521660] [client 202.70.139.242:26256] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:11:41.655294 2026] [security2:error] [pid 521505:tid 521752] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/joomla/.env"] [unique_id "apPlvW8byYE0iXl--K5lxwAAA5M"]
[Sun Aug 30 03:11:41.657696 2026] [authz_core:error] [pid 521505:tid 521748] [client 216.73.216.128:45356] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:41.657959 2026] [authz_core:error] [pid 521505:tid 521748] [client 216.73.216.128:45356] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:41.667968 2026] [security2:error] [pid 521505:tid 521738] [client 20.151.200.44:63536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/wp-ver.php"] [unique_id "apPlvW8byYE0iXl--K5lyQAAA4U"]
[Sun Aug 30 03:11:41.672992 2026] [authz_core:error] [pid 521505:tid 521749] [client 66.249.66.40:49766] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:41.673251 2026] [authz_core:error] [pid 521505:tid 521749] [client 66.249.66.40:49766] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:41.725543 2026] [authz_core:error] [pid 521505:tid 521713] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IL%2FLC_MESSAGES
[Sun Aug 30 03:11:41.725801 2026] [authz_core:error] [pid 521505:tid 521713] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IL%2FLC_MESSAGES
[Sun Aug 30 03:11:41.743214 2026] [security2:error] [pid 521505:tid 521610] [remote 112.78.134.58:38902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.134.78.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hobnobberssycamore.com"] [uri "/wp-login.php"] [unique_id "apPlvW8byYE0iXl--K5lzAADO2g"]
[Sun Aug 30 03:11:41.749185 2026] [security2:error] [pid 521505:tid 521707] [client 207.154.212.47:47888] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "mail.eessel.com"] [uri "/"] [unique_id "apPlvW8byYE0iXl--K5lzQAAA2Y"]
[Sun Aug 30 03:11:41.758434 2026] [security2:error] [pid 521505:tid 521755] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/angular/.env"] [unique_id "apPlvW8byYE0iXl--K5lzwAAA5Y"]
[Sun Aug 30 03:11:41.764660 2026] [security2:error] [pid 521505:tid 521740] [client 40.83.93.50:6809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/system_log.php"] [unique_id "apPlvW8byYE0iXl--K5l0AAAA4c"]
[Sun Aug 30 03:11:41.815713 2026] [security2:error] [pid 521505:tid 521761] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/magento/.env"] [unique_id "apPlvW8byYE0iXl--K5l1wAAA5w"]
[Sun Aug 30 03:11:41.816014 2026] [security2:error] [pid 521505:tid 521687] [client 20.104.50.220:17278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/radio.php"] [unique_id "apPlvW8byYE0iXl--K5l2AAAA1I"]
[Sun Aug 30 03:11:41.839772 2026] [security2:error] [pid 521505:tid 521673] [client 20.104.18.15:51091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/82.php"] [unique_id "apPlvW8byYE0iXl--K5l2gAAA0Q"]
[Sun Aug 30 03:11:41.839773 2026] [security2:error] [pid 521505:tid 521652] [client 20.104.49.130:57514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/ortasekerli1.php"] [unique_id "apPlvW8byYE0iXl--K5l2wAAAy8"]
[Sun Aug 30 03:11:41.846206 2026] [security2:error] [pid 521505:tid 521751] [client 20.104.50.220:33029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/4index.php"] [unique_id "apPlvW8byYE0iXl--K5l3QAAA5I"]
[Sun Aug 30 03:11:41.854285 2026] [security2:error] [pid 521505:tid 521613] [remote 129.121.76.191:52548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.76.121.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ionicfab.net"] [uri "/wp-login.php"] [unique_id "apPlvW8byYE0iXl--K5l3gADLWs"], referer: https://ionicfab.net/wp-login.php
[Sun Aug 30 03:11:41.863533 2026] [security2:error] [pid 521505:tid 521662] [client 158.23.147.79:40032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apPlvW8byYE0iXl--K5l3wAAAzk"]
[Sun Aug 30 03:11:41.863552 2026] [security2:error] [pid 521505:tid 521722] [client 20.104.50.220:28717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/images/alfa.php"] [unique_id "apPlvW8byYE0iXl--K5l4AAAA3U"]
[Sun Aug 30 03:11:41.886143 2026] [security2:error] [pid 521505:tid 521732] [client 4.205.62.107:17695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/u88.php"] [unique_id "apPlvW8byYE0iXl--K5l4QAAA38"]
[Sun Aug 30 03:11:41.928892 2026] [security2:error] [pid 521505:tid 521697] [client 68.155.159.216:57081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/bk/index.php"] [unique_id "apPlvW8byYE0iXl--K5l4wAAA1w"]
[Sun Aug 30 03:11:41.932736 2026] [security2:error] [pid 521505:tid 521646] [client 20.104.50.220:25430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/file52.php"] [unique_id "apPlvW8byYE0iXl--K5l5QAAAyk"]
[Sun Aug 30 03:11:41.952044 2026] [security2:error] [pid 521505:tid 521677] [client 158.23.147.79:60215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-content/index.php"] [unique_id "apPlvW8byYE0iXl--K5l5gAAA0g"]
[Sun Aug 30 03:11:41.954295 2026] [security2:error] [pid 521505:tid 521753] [client 20.104.50.220:62817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/orange.php"] [unique_id "apPlvW8byYE0iXl--K5l5wAAA5Q"]
[Sun Aug 30 03:11:41.954751 2026] [security2:error] [pid 521505:tid 521676] [client 20.197.61.180:3229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/users.php"] [unique_id "apPlvW8byYE0iXl--K5l6AAAA0c"]
[Sun Aug 30 03:11:41.959248 2026] [security2:error] [pid 521505:tid 521657] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/svelte/.env"] [unique_id "apPlvW8byYE0iXl--K5l6QAAAzQ"]
[Sun Aug 30 03:11:41.971952 2026] [security2:error] [pid 521505:tid 521641] [client 68.155.159.216:54310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/images/index.php"] [unique_id "apPlvW8byYE0iXl--K5l7QAAAyQ"]
[Sun Aug 30 03:11:41.979618 2026] [security2:error] [pid 521505:tid 521638] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/shopify/.env"] [unique_id "apPlvW8byYE0iXl--K5l8AAAAyE"]
[Sun Aug 30 03:11:41.981426 2026] [authz_core:error] [pid 521505:tid 521686] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory23
[Sun Aug 30 03:11:41.981752 2026] [authz_core:error] [pid 521505:tid 521686] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory23
[Sun Aug 30 03:11:42.001179 2026] [authz_core:error] [pid 521505:tid 521669] [client 66.249.66.205:50399] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:42.001595 2026] [authz_core:error] [pid 521505:tid 521669] [client 66.249.66.205:50399] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:42.013696 2026] [security2:error] [pid 521505:tid 521649] [client 20.48.251.3:52842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/nw.php"] [unique_id "apPlvm8byYE0iXl--K5l8wAAAyw"]
[Sun Aug 30 03:11:42.020980 2026] [security2:error] [pid 521505:tid 521706] [client 20.104.49.130:52476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wdfjba.org"] [uri "/av.php"] [unique_id "apPlvm8byYE0iXl--K5l9AAAA2U"]
[Sun Aug 30 03:11:42.119077 2026] [security2:error] [pid 521505:tid 521658] [client 20.48.251.3:36859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/public/vx.php"] [unique_id "apPlvm8byYE0iXl--K5l_AAAAzU"]
[Sun Aug 30 03:11:42.119106 2026] [security2:error] [pid 521505:tid 521698] [client 20.104.50.220:5471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/index.php"] [unique_id "apPlvm8byYE0iXl--K5l_QAAA10"]
[Sun Aug 30 03:11:42.140687 2026] [security2:error] [pid 521505:tid 521639] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/prestashop/.env"] [unique_id "apPlvm8byYE0iXl--K5l_gAAAyI"]
[Sun Aug 30 03:11:42.144512 2026] [security2:error] [pid 521505:tid 521670] [client 20.104.50.220:63525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/2index.php"] [unique_id "apPlvm8byYE0iXl--K5l_wAAA0E"]
[Sun Aug 30 03:11:42.156412 2026] [security2:error] [pid 521505:tid 521661] [client 4.205.62.107:36635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/time.php"] [unique_id "apPlvm8byYE0iXl--K5mAAAAAzg"]
[Sun Aug 30 03:11:42.160536 2026] [security2:error] [pid 521505:tid 521734] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/vite/.env"] [unique_id "apPlvm8byYE0iXl--K5mAQAAA4E"]
[Sun Aug 30 03:11:42.190975 2026] [authz_core:error] [pid 521505:tid 521711] [client 66.249.66.68:37736] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:42.191240 2026] [authz_core:error] [pid 521505:tid 521711] [client 66.249.66.68:37736] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:42.195230 2026] [security2:error] [pid 521505:tid 521665] [client 20.151.200.44:65359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/ah24.php"] [unique_id "apPlvm8byYE0iXl--K5mBwAAAzw"]
[Sun Aug 30 03:11:42.201458 2026] [authz_core:error] [pid 521505:tid 521689] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IE%2FLC_MESSAGES
[Sun Aug 30 03:11:42.201897 2026] [authz_core:error] [pid 521505:tid 521689] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IE%2FLC_MESSAGES
[Sun Aug 30 03:11:42.222278 2026] [authz_core:error] [pid 521505:tid 521700] [client 216.73.216.128:16988] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:42.222543 2026] [authz_core:error] [pid 521505:tid 521700] [client 216.73.216.128:16988] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:42.242760 2026] [security2:error] [pid 521505:tid 521752] [client 4.205.62.107:15962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/koiy.php"] [unique_id "apPlvm8byYE0iXl--K5mCgAAA5M"]
[Sun Aug 30 03:11:42.243992 2026] [security2:error] [pid 521505:tid 521750] [client 20.104.18.15:18428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/h2.php"] [unique_id "apPlvm8byYE0iXl--K5mCwAAA5E"]
[Sun Aug 30 03:11:42.253085 2026] [security2:error] [pid 521505:tid 521746] [client 20.48.251.3:64293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/wp-class.php"] [unique_id "apPlvm8byYE0iXl--K5mDAAAA40"]
[Sun Aug 30 03:11:42.272495 2026] [security2:error] [pid 521505:tid 521666] [client 20.104.50.220:31206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/file31.php"] [unique_id "apPlvm8byYE0iXl--K5mDQAAAz0"]
[Sun Aug 30 03:11:42.292115 2026] [security2:error] [pid 521505:tid 521719] [client 40.83.93.50:7077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/w.php"] [unique_id "apPlvm8byYE0iXl--K5mDwAAA3I"]
[Sun Aug 30 03:11:42.297133 2026] [security2:error] [pid 521505:tid 521754] [client 20.104.18.15:31631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/indo.php"] [unique_id "apPlvm8byYE0iXl--K5mEQAAA5U"]
[Sun Aug 30 03:11:42.299988 2026] [security2:error] [pid 521505:tid 521757] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/codeigniter/.env"] [unique_id "apPlvm8byYE0iXl--K5mEgAAA5g"]
[Sun Aug 30 03:11:42.309567 2026] [authz_core:error] [pid 521505:tid 521664] [client 66.249.66.67:65445] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:42.309855 2026] [authz_core:error] [pid 521505:tid 521664] [client 66.249.66.67:65445] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:42.361761 2026] [security2:error] [pid 521505:tid 521735] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/backup/.env"] [unique_id "apPlvm8byYE0iXl--K5mFwAAA4I"]
[Sun Aug 30 03:11:42.371321 2026] [security2:error] [pid 521505:tid 521687] [client 20.104.18.15:22448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/manga.php"] [unique_id "apPlvm8byYE0iXl--K5mGQAAA1I"]
[Sun Aug 30 03:11:42.455032 2026] [security2:error] [pid 521505:tid 521674] [client 20.151.200.44:45986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/bge.php"] [unique_id "apPlvm8byYE0iXl--K5mHQAAA0U"]
[Sun Aug 30 03:11:42.463793 2026] [security2:error] [pid 521505:tid 521646] [client 4.205.62.107:25909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/channels.php"] [unique_id "apPlvm8byYE0iXl--K5mHwAAAyk"]
[Sun Aug 30 03:11:42.464230 2026] [security2:error] [pid 521505:tid 521684] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/cakephp/.env"] [unique_id "apPlvm8byYE0iXl--K5mHgAAA08"]
[Sun Aug 30 03:11:42.487919 2026] [core:alert] [pid 521505:tid 521749] [client 154.198.94.0:53510] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:11:42.503980 2026] [authz_core:error] [pid 521505:tid 521677] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory22
[Sun Aug 30 03:11:42.504247 2026] [authz_core:error] [pid 521505:tid 521677] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory22
[Sun Aug 30 03:11:42.504863 2026] [security2:error] [pid 521505:tid 521676] [client 20.104.18.15:16929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/sao.php"] [unique_id "apPlvm8byYE0iXl--K5mJAAAA0c"]
[Sun Aug 30 03:11:42.506902 2026] [core:alert] [pid 521505:tid 521641] [client 181.78.100.194:37208] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:11:42.508029 2026] [security2:error] [pid 521505:tid 521683] [client 20.48.251.3:52233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/config/laravolt/css/index.php"] [unique_id "apPlvm8byYE0iXl--K5mJgAAA04"]
[Sun Aug 30 03:11:42.562353 2026] [security2:error] [pid 521505:tid 521762] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/backups/.env"] [unique_id "apPlvm8byYE0iXl--K5mKQAAA50"]
[Sun Aug 30 03:11:42.579115 2026] [security2:error] [pid 521505:tid 521747] [client 20.151.200.44:65376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPlvm8byYE0iXl--K5mKwAAA44"]
[Sun Aug 30 03:11:42.587622 2026] [security2:error] [pid 521505:tid 521622] [remote 112.78.134.58:38902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.134.78.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hobnobberssycamore.com"] [uri "/wp-login.php"] [unique_id "apPlvm8byYE0iXl--K5mKgADRnQ"], referer: https://hobnobberssycamore.com/wp-login.php
[Sun Aug 30 03:11:42.589829 2026] [security2:error] [pid 521505:tid 521667] [client 4.205.62.107:52866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/xqq.php"] [unique_id "apPlvm8byYE0iXl--K5mLQAAAz4"]
[Sun Aug 30 03:11:42.617663 2026] [authz_core:error] [pid 521505:tid 521637] [client 66.249.66.38:46658] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:42.617935 2026] [authz_core:error] [pid 521505:tid 521637] [client 66.249.66.38:46658] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:42.622420 2026] [security2:error] [pid 521505:tid 521623] [remote 103.74.116.219:47296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.116.74.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlebousquet.bayoutents.com"] [uri "/wp-login.php"] [unique_id "apPlvm8byYE0iXl--K5mLwADgHU"]
[Sun Aug 30 03:11:42.624827 2026] [security2:error] [pid 521505:tid 521712] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/zend/.env"] [unique_id "apPlvm8byYE0iXl--K5mMAAAA2s"]
[Sun Aug 30 03:11:42.637018 2026] [security2:error] [pid 521505:tid 521718] [client 158.23.147.79:40033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/simple.php"] [unique_id "apPlvm8byYE0iXl--K5mMQAAA3E"]
[Sun Aug 30 03:11:42.638555 2026] [security2:error] [pid 521505:tid 521643] [client 20.104.50.220:59561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/file88.php"] [unique_id "apPlvm8byYE0iXl--K5mMgAAAyY"]
[Sun Aug 30 03:11:42.664030 2026] [security2:error] [pid 521505:tid 521647] [client 20.48.250.41:49338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/xxw.php"] [unique_id "apPlvm8byYE0iXl--K5mMwAAAyo"]
[Sun Aug 30 03:11:42.672266 2026] [security2:error] [pid 521505:tid 521659] [client 20.197.61.180:3836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/wp-cron.php"] [unique_id "apPlvm8byYE0iXl--K5mNQAAAzY"]
[Sun Aug 30 03:11:42.677148 2026] [authz_core:error] [pid 521505:tid 521686] [client 216.73.216.128:16988] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:42.677389 2026] [authz_core:error] [pid 521505:tid 521686] [client 216.73.216.128:16988] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:42.699513 2026] [authz_core:error] [pid 521505:tid 521661] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_CA%2FLC_MESSAGES
[Sun Aug 30 03:11:42.699782 2026] [authz_core:error] [pid 521505:tid 521661] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_CA%2FLC_MESSAGES
[Sun Aug 30 03:11:42.727889 2026] [security2:error] [pid 521505:tid 521656] [client 158.23.147.79:60179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/about/function.php"] [unique_id "apPlvm8byYE0iXl--K5mOgAAAzM"]
[Sun Aug 30 03:11:42.762661 2026] [security2:error] [pid 521505:tid 521636] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/old/.env"] [unique_id "apPlvm8byYE0iXl--K5mOwAAAx8"]
[Sun Aug 30 03:11:42.774448 2026] [security2:error] [pid 521505:tid 521743] [client 20.48.250.41:11086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/403.php"] [unique_id "apPlvm8byYE0iXl--K5mPQAAA4o"]
[Sun Aug 30 03:11:42.784502 2026] [security2:error] [pid 521505:tid 521679] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/yii/.env"] [unique_id "apPlvm8byYE0iXl--K5mQAAAA0o"]
[Sun Aug 30 03:11:42.793835 2026] [security2:error] [pid 521505:tid 521750] [client 20.48.250.41:19449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/bolt.php"] [unique_id "apPlvm8byYE0iXl--K5mRAAAA5E"]
[Sun Aug 30 03:11:42.795398 2026] [security2:error] [pid 521505:tid 521746] [client 20.104.49.130:51535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/css.php"] [unique_id "apPlvm8byYE0iXl--K5mRQAAA40"]
[Sun Aug 30 03:11:42.795974 2026] [authz_core:error] [pid 521505:tid 521665] [client 66.249.66.72:40037] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:42.796216 2026] [authz_core:error] [pid 521505:tid 521665] [client 66.249.66.72:40037] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:42.872975 2026] [authz_core:error] [pid 521505:tid 521735] [client 216.73.216.128:16988] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:42.873274 2026] [authz_core:error] [pid 521505:tid 521735] [client 216.73.216.128:16988] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:42.881665 2026] [security2:error] [pid 521505:tid 521696] [client 51.68.236.71:19791] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bridgesofcourage.org"] [uri "/robots.txt"] [unique_id "apPlvm8byYE0iXl--K5mTwAAA1s"]
[Sun Aug 30 03:11:42.881799 2026] [security2:error] [pid 521505:tid 521696] [client 51.68.236.71:19791] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bridgesofcourage.org"] [uri "/robots.txt"] [unique_id "apPlvm8byYE0iXl--K5mTwAAA1s"]
[Sun Aug 30 03:11:42.893700 2026] [security2:error] [pid 521505:tid 521741] [client 40.83.93.50:3920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/wp.php"] [unique_id "apPlvm8byYE0iXl--K5mUQAAA4g"]
[Sun Aug 30 03:11:42.900814 2026] [security2:error] [pid 521505:tid 521728] [client 20.48.250.41:11033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/cytyr.php"] [unique_id "apPlvm8byYE0iXl--K5mUgAAA3s"]
[Sun Aug 30 03:11:42.948663 2026] [security2:error] [pid 521505:tid 521654] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/laravel5/.env"] [unique_id "apPlvm8byYE0iXl--K5mVQAAAzE"]
[Sun Aug 30 03:11:42.963428 2026] [security2:error] [pid 521505:tid 521710] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/tmp/.env"] [unique_id "apPlvm8byYE0iXl--K5mVwAAA2k"]
[Sun Aug 30 03:11:42.967143 2026] [security2:error] [pid 521505:tid 521758] [client 20.104.50.220:17324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/files.php"] [unique_id "apPlvm8byYE0iXl--K5mWwAAA5k"]
[Sun Aug 30 03:11:42.976030 2026] [security2:error] [pid 521505:tid 521759] [client 178.20.43.173:56861] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "178.20.43.173" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.maarifado.com"] [uri "/wp-login.php"] [unique_id "apPlvm8byYE0iXl--K5mXAAAA5o"], referer: http://www.maarifado.com/membership-account/membership-levels/
[Sun Aug 30 03:11:42.976177 2026] [security2:error] [pid 521505:tid 521759] [client 178.20.43.173:56861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.maarifado.com"] [uri "/wp-login.php"] [unique_id "apPlvm8byYE0iXl--K5mXAAAA5o"], referer: http://www.maarifado.com/membership-account/membership-levels/
[Sun Aug 30 03:11:42.986268 2026] [authz_core:error] [pid 521505:tid 521709] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory28
[Sun Aug 30 03:11:42.986533 2026] [authz_core:error] [pid 521505:tid 521709] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory28
[Sun Aug 30 03:11:42.991882 2026] [authz_core:error] [pid 521505:tid 521700] [client 66.249.66.35:48622] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:42.992329 2026] [authz_core:error] [pid 521505:tid 521700] [client 66.249.66.35:48622] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:42.999861 2026] [security2:error] [pid 521505:tid 521662] [client 20.104.50.220:32832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/5index.php"] [unique_id "apPlvm8byYE0iXl--K5mYAAAAzk"]
[Sun Aug 30 03:11:43.009401 2026] [security2:error] [pid 521505:tid 521713] [client 20.104.18.15:51008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/dex.php"] [unique_id "apPlv28byYE0iXl--K5mYQAAA2w"]
[Sun Aug 30 03:11:43.023174 2026] [security2:error] [pid 521505:tid 521685] [client 4.205.62.107:17090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/config/laravolt/css/index.php"] [unique_id "apPlv28byYE0iXl--K5mZAAAA1A"]
[Sun Aug 30 03:11:43.037763 2026] [security2:error] [pid 521505:tid 521674] [client 68.155.159.216:62643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.allforlearn.com"] [uri "/first.php"] [unique_id "apPlv28byYE0iXl--K5mZQAAA0U"]
[Sun Aug 30 03:11:43.039044 2026] [security2:error] [pid 521505:tid 521725] [client 158.23.147.79:39956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-admin/about.php"] [unique_id "apPlv28byYE0iXl--K5mZgAAA3g"]
[Sun Aug 30 03:11:43.068840 2026] [security2:error] [pid 521505:tid 521749] [client 216.73.216.128:16988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mysqlupgrade"] [unique_id "apPlv28byYE0iXl--K5mZwAAA5A"]
[Sun Aug 30 03:11:43.078437 2026] [security2:error] [pid 521505:tid 521711] [client 20.104.50.220:24930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/122.php"] [unique_id "apPlv28byYE0iXl--K5maAAAA2o"]
[Sun Aug 30 03:11:43.081898 2026] [security2:error] [pid 521505:tid 521753] [client 20.104.50.220:62847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/images/alfashell.php"] [unique_id "apPlv28byYE0iXl--K5maQAAA5Q"]
[Sun Aug 30 03:11:43.106018 2026] [security2:error] [pid 521505:tid 521632] [remote 103.74.116.219:47296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.116.74.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlebousquet.bayoutents.com"] [uri "/wp-login.php"] [unique_id "apPlv28byYE0iXl--K5mawADl34"], referer: https://littlebousquet.bayoutents.com/wp-login.php
[Sun Aug 30 03:11:43.108042 2026] [security2:error] [pid 521505:tid 521644] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/v1/.env"] [unique_id "apPlv28byYE0iXl--K5mbAAAAyc"]
[Sun Aug 30 03:11:43.110238 2026] [security2:error] [pid 521505:tid 521690] [client 20.104.50.220:29181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/hcd01.php"] [unique_id "apPlv28byYE0iXl--K5mbQAAA1U"]
[Sun Aug 30 03:11:43.154675 2026] [security2:error] [pid 521505:tid 521682] [client 68.155.159.216:52570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apPlv28byYE0iXl--K5mbwAAA00"]
[Sun Aug 30 03:11:43.156401 2026] [security2:error] [pid 521505:tid 521688] [client 20.48.251.3:55761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/product.php"] [unique_id "apPlv28byYE0iXl--K5mcQAAA1M"]
[Sun Aug 30 03:11:43.163634 2026] [security2:error] [pid 521505:tid 521762] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/temp/.env"] [unique_id "apPlv28byYE0iXl--K5mcgAAA50"]
[Sun Aug 30 03:11:43.194470 2026] [security2:error] [pid 521505:tid 521658] [client 207.154.212.47:47898] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "mail.eessel.com"] [uri "/"] [unique_id "apPlv28byYE0iXl--K5mdAAAAzU"]
[Sun Aug 30 03:11:43.208657 2026] [authz_core:error] [pid 521505:tid 521647] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:43.208936 2026] [authz_core:error] [pid 521505:tid 521647] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:43.258164 2026] [security2:error] [pid 521505:tid 521702] [client 20.48.251.3:37121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/log.php"] [unique_id "apPlv28byYE0iXl--K5meAAAA2E"]
[Sun Aug 30 03:11:43.267349 2026] [security2:error] [pid 521505:tid 521640] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/v2/.env"] [unique_id "apPlv28byYE0iXl--K5megAAAyM"]
[Sun Aug 30 03:11:43.272013 2026] [security2:error] [pid 521505:tid 521664] [client 20.104.50.220:5440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/bypp.php"] [unique_id "apPlv28byYE0iXl--K5mewAAAzs"]
[Sun Aug 30 03:11:43.284093 2026] [security2:error] [pid 521505:tid 521636] [client 20.104.50.220:51578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/3index.php"] [unique_id "apPlv28byYE0iXl--K5mfQAAAx8"]
[Sun Aug 30 03:11:43.289021 2026] [authz_core:error] [pid 521505:tid 521653] [client 66.249.66.201:56090] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:43.289324 2026] [authz_core:error] [pid 521505:tid 521653] [client 66.249.66.201:56090] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:43.326093 2026] [security2:error] [pid 521505:tid 521750] [client 4.205.62.107:36085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/doc.php"] [unique_id "apPlv28byYE0iXl--K5mfwAAA5E"]
[Sun Aug 30 03:11:43.333050 2026] [security2:error] [pid 521505:tid 521746] [client 20.104.49.130:57533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/t.php"] [unique_id "apPlv28byYE0iXl--K5mgAAAA40"]
[Sun Aug 30 03:11:43.364430 2026] [security2:error] [pid 521505:tid 521745] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/lab/.env"] [unique_id "apPlv28byYE0iXl--K5mgwAAA4w"]
[Sun Aug 30 03:11:43.370303 2026] [security2:error] [pid 521505:tid 521703] [client 20.197.61.180:12248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/wp-links-opml.php"] [unique_id "apPlv28byYE0iXl--K5mhQAAA2I"]
[Sun Aug 30 03:11:43.380557 2026] [security2:error] [pid 521505:tid 521707] [client 4.205.62.107:15846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/w.php"] [unique_id "apPlv28byYE0iXl--K5mhgAAA2Y"]
[Sun Aug 30 03:11:43.381367 2026] [security2:error] [pid 521505:tid 521659] [client 40.83.93.50:6393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/composer.php"] [unique_id "apPlv28byYE0iXl--K5mhwAAAzY"]
[Sun Aug 30 03:11:43.382625 2026] [security2:error] [pid 521505:tid 521693] [client 20.104.18.15:18248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apPlv28byYE0iXl--K5miAAAA1g"]
[Sun Aug 30 03:11:43.425138 2026] [security2:error] [pid 521505:tid 521652] [client 20.104.50.220:59341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/file6.php"] [unique_id "apPlv28byYE0iXl--K5mjAAAAy8"]
[Sun Aug 30 03:11:43.430762 2026] [security2:error] [pid 521505:tid 521655] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/v3/.env"] [unique_id "apPlv28byYE0iXl--K5mjQAAAzI"]
[Sun Aug 30 03:11:43.453348 2026] [authz_core:error] [pid 521505:tid 521710] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory22
[Sun Aug 30 03:11:43.453605 2026] [authz_core:error] [pid 521505:tid 521710] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory22
[Sun Aug 30 03:11:43.462831 2026] [security2:error] [pid 521505:tid 521635] [client 20.104.18.15:31560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wnnjpsby.php"] [unique_id "apPlv28byYE0iXl--K5mkAAAAx4"]
[Sun Aug 30 03:11:43.487051 2026] [security2:error] [pid 521505:tid 521651] [client 20.48.251.3:64296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/database.php"] [unique_id "apPlv28byYE0iXl--K5mkwAAAy4"]
[Sun Aug 30 03:11:43.491943 2026] [core:alert] [pid 521505:tid 521751] [client 187.189.40.46:51756] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:11:43.529212 2026] [security2:error] [pid 521505:tid 521674] [client 20.104.18.15:22370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/asdfghj.php"] [unique_id "apPlv28byYE0iXl--K5mlwAAA0U"]
[Sun Aug 30 03:11:43.540917 2026] [authz_core:error] [pid 521505:tid 521665] [client 216.73.216.128:45356] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:43.541337 2026] [authz_core:error] [pid 521505:tid 521665] [client 216.73.216.128:45356] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:43.549848 2026] [security2:error] [pid 521505:tid 521698] [client 20.151.200.44:45965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/ssh3ll.php"] [unique_id "apPlv28byYE0iXl--K5mmwAAA10"]
[Sun Aug 30 03:11:43.562282 2026] [security2:error] [pid 521505:tid 521657] [client 20.151.200.44:64820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.buythebookbookstore.com"] [uri "/waf.php"] [unique_id "apPlv28byYE0iXl--K5mnAAAAzQ"]
[Sun Aug 30 03:11:43.564514 2026] [security2:error] [pid 521505:tid 521660] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/cronlab/.env"] [unique_id "apPlv28byYE0iXl--K5mnQAAAzc"]
[Sun Aug 30 03:11:43.592764 2026] [security2:error] [pid 521505:tid 521683] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/api/v1/.env"] [unique_id "apPlv28byYE0iXl--K5mngAAA04"]
[Sun Aug 30 03:11:43.604890 2026] [security2:error] [pid 521505:tid 521644] [client 20.151.200.44:41885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/pk.php"] [unique_id "apPlv28byYE0iXl--K5mnwAAAyc"]
[Sun Aug 30 03:11:43.625919 2026] [security2:error] [pid 521505:tid 521717] [client 158.23.147.79:58429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-includes/customize/index.php"] [unique_id "apPlv28byYE0iXl--K5moQAAA3A"]
[Sun Aug 30 03:11:43.629678 2026] [security2:error] [pid 521505:tid 521681] [client 4.205.62.107:25506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/zz.php"] [unique_id "apPlv28byYE0iXl--K5mowAAA0w"]
[Sun Aug 30 03:11:43.631060 2026] [authz_core:error] [pid 521505:tid 521742] [client 216.73.216.128:13341] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:43.631324 2026] [authz_core:error] [pid 521505:tid 521742] [client 216.73.216.128:13341] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:43.639530 2026] [security2:error] [pid 521505:tid 521699] [client 20.48.251.3:59474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/87.php"] [unique_id "apPlv28byYE0iXl--K5mpAAAA14"]
[Sun Aug 30 03:11:43.641165 2026] [security2:error] [pid 521505:tid 521714] [client 20.104.18.15:64755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/dapa.php"] [unique_id "apPlv28byYE0iXl--K5mpQAAA20"]
[Sun Aug 30 03:11:43.710045 2026] [authz_core:error] [pid 521505:tid 521692] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:43.710293 2026] [authz_core:error] [pid 521505:tid 521692] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:43.717391 2026] [security2:error] [pid 521505:tid 521691] [client 20.104.49.130:53536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPlv28byYE0iXl--K5mqQAAA1Y"]
[Sun Aug 30 03:11:43.722230 2026] [authz_core:error] [pid 521505:tid 521680] [client 66.249.66.64:56045] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:43.722491 2026] [authz_core:error] [pid 521505:tid 521680] [client 66.249.66.64:56045] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:43.742671 2026] [security2:error] [pid 521505:tid 521682] [client 20.104.49.130:48330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/wp-css.php"] [unique_id "apPlv28byYE0iXl--K5mqgAAA00"]
[Sun Aug 30 03:11:43.753424 2026] [security2:error] [pid 521505:tid 521708] [client 4.205.62.107:52830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/a1vx.php"] [unique_id "apPlv28byYE0iXl--K5mrAAAA2c"]
[Sun Aug 30 03:11:43.753463 2026] [security2:error] [pid 521505:tid 521762] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/api/v2/.env"] [unique_id "apPlv28byYE0iXl--K5mqwAAA50"]
[Sun Aug 30 03:11:43.764311 2026] [security2:error] [pid 521505:tid 521747] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/cron/.env"] [unique_id "apPlv28byYE0iXl--K5mrQAAA44"]
[Sun Aug 30 03:11:43.802463 2026] [security2:error] [pid 521505:tid 521712] [client 20.104.50.220:61829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/gifclass4.php"] [unique_id "apPlv28byYE0iXl--K5msQAAA2s"]
[Sun Aug 30 03:11:43.816745 2026] [security2:error] [pid 521505:tid 521658] [client 20.104.49.130:53882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/dex.php"] [unique_id "apPlv28byYE0iXl--K5mtAAAAzU"]
[Sun Aug 30 03:11:43.879656 2026] [security2:error] [pid 521505:tid 521664] [client 20.104.18.15:2007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlv28byYE0iXl--K5muwAAAzs"]
[Sun Aug 30 03:11:43.886096 2026] [security2:error] [pid 521505:tid 521719] [client 40.83.93.50:6386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/abcd.php"] [unique_id "apPlv28byYE0iXl--K5mvAAAA3I"]
[Sun Aug 30 03:11:43.892091 2026] [security2:error] [pid 521505:tid 521679] [client 20.104.49.130:53578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/browse.php"] [unique_id "apPlv28byYE0iXl--K5mvQAAA0o"]
[Sun Aug 30 03:11:43.905808 2026] [authz_core:error] [pid 521505:tid 521686] [client 216.73.216.128:8686] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:43.906085 2026] [authz_core:error] [pid 521505:tid 521686] [client 216.73.216.128:8686] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:43.914637 2026] [security2:error] [pid 521505:tid 521750] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/rest/.env"] [unique_id "apPlv28byYE0iXl--K5mvwAAA5E"]
[Sun Aug 30 03:11:43.928675 2026] [security2:error] [pid 521505:tid 521746] [client 20.48.250.41:49377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/rtx.php"] [unique_id "apPlv28byYE0iXl--K5mwAAAA40"]
[Sun Aug 30 03:11:43.965323 2026] [security2:error] [pid 521505:tid 521745] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/en/.env"] [unique_id "apPlv28byYE0iXl--K5mwgAAA4w"]
[Sun Aug 30 03:11:43.977799 2026] [authz_core:error] [pid 521505:tid 521726] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory27
[Sun Aug 30 03:11:43.978260 2026] [authz_core:error] [pid 521505:tid 521726] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory27
[Sun Aug 30 03:11:44.032965 2026] [security2:error] [pid 521505:tid 521652] [client 20.48.250.41:11016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/galer.php"] [unique_id "apPlwG8byYE0iXl--K5mygAAAy8"]
[Sun Aug 30 03:11:44.072635 2026] [security2:error] [pid 521505:tid 521695] [client 207.154.212.47:47900] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "mail.eessel.com"] [uri "/wp-json/batch/v1"] [unique_id "apPlwG8byYE0iXl--K5mzQAAA1o"]
[Sun Aug 30 03:11:44.074197 2026] [security2:error] [pid 521505:tid 521720] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/graphql/.env"] [unique_id "apPlwG8byYE0iXl--K5mzgAAA3M"]
[Sun Aug 30 03:11:44.074347 2026] [security2:error] [pid 521505:tid 521635] [client 20.48.250.41:49394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/ckk.php"] [unique_id "apPlwG8byYE0iXl--K5mzwAAAx4"]
[Sun Aug 30 03:11:44.085073 2026] [security2:error] [pid 521505:tid 521677] [client 20.197.61.180:18086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/wp-load.php"] [unique_id "apPlwG8byYE0iXl--K5m0AAAA0g"]
[Sun Aug 30 03:11:44.103294 2026] [security2:error] [pid 521505:tid 521651] [client 158.23.147.79:40006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apPlwG8byYE0iXl--K5m0QAAAy4"]
[Sun Aug 30 03:11:44.107573 2026] [security2:error] [pid 521505:tid 521751] [client 20.104.50.220:17336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/file7.php"] [unique_id "apPlwG8byYE0iXl--K5m0gAAA5I"]
[Sun Aug 30 03:11:44.146373 2026] [security2:error] [pid 521505:tid 521738] [client 20.104.50.220:33051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/6index.php"] [unique_id "apPlwG8byYE0iXl--K5m1wAAA4U"]
[Sun Aug 30 03:11:44.162223 2026] [security2:error] [pid 521505:tid 521669] [client 4.205.62.107:17715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/87.php"] [unique_id "apPlwG8byYE0iXl--K5m2AAAA0A"]
[Sun Aug 30 03:11:44.175550 2026] [security2:error] [pid 521505:tid 521739] [client 20.104.18.15:51195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/inso.php"] [unique_id "apPlwG8byYE0iXl--K5m2wAAA4Y"]
[Sun Aug 30 03:11:44.176973 2026] [security2:error] [pid 521505:tid 521697] [client 20.48.250.41:11222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/baixy.php"] [unique_id "apPlwG8byYE0iXl--K5m3AAAA1w"]
[Sun Aug 30 03:11:44.189028 2026] [authz_core:error] [pid 521505:tid 521711] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:44.189467 2026] [authz_core:error] [pid 521505:tid 521711] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:11:44.212808 2026] [security2:error] [pid 521505:tid 521715] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/administrator/.env"] [unique_id "apPlwG8byYE0iXl--K5m2QAAA24"]
[Sun Aug 30 03:11:44.217499 2026] [security2:error] [pid 521505:tid 521660] [client 20.104.50.220:25426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/green1.php"] [unique_id "apPlwG8byYE0iXl--K5m3wAAAzc"]
[Sun Aug 30 03:11:44.231536 2026] [security2:error] [pid 521505:tid 521694] [client 20.104.50.220:28715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/images/gelay.php"] [unique_id "apPlwG8byYE0iXl--K5m4AAAA1k"]
[Sun Aug 30 03:11:44.235936 2026] [security2:error] [pid 521505:tid 521676] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/gateway/.env"] [unique_id "apPlwG8byYE0iXl--K5m4QAAA0c"]
[Sun Aug 30 03:11:44.262630 2026] [security2:error] [pid 521505:tid 521690] [client 68.155.159.216:52596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apPlwG8byYE0iXl--K5m5AAAA1U"]
[Sun Aug 30 03:11:44.293959 2026] [security2:error] [pid 521505:tid 521665] [client 20.48.251.3:59281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/fun.php"] [unique_id "apPlwG8byYE0iXl--K5m5wAAAzw"]
[Sun Aug 30 03:11:44.297372 2026] [security2:error] [pid 521505:tid 521725] [client 20.104.50.220:29342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/prof.php"] [unique_id "apPlwG8byYE0iXl--K5m6AAAA3g"]
[Sun Aug 30 03:11:44.396730 2026] [security2:error] [pid 521505:tid 521712] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/microservice/.env"] [unique_id "apPlwG8byYE0iXl--K5m7gAAA2s"]
[Sun Aug 30 03:11:44.398633 2026] [security2:error] [pid 521505:tid 521718] [client 20.48.251.3:37138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/ebahvhhh.php"] [unique_id "apPlwG8byYE0iXl--K5m7wAAA3E"]
[Sun Aug 30 03:11:44.407747 2026] [security2:error] [pid 521505:tid 521760] [client 40.83.93.50:10711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/sf.php"] [unique_id "apPlwG8byYE0iXl--K5m8AAAA5s"]
[Sun Aug 30 03:11:44.413079 2026] [security2:error] [pid 521505:tid 521740] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/psnlink/.env"] [unique_id "apPlwG8byYE0iXl--K5m8wAAA4c"]
[Sun Aug 30 03:11:44.415801 2026] [security2:error] [pid 521505:tid 521701] [client 20.151.200.44:63029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/png.php"] [unique_id "apPlwG8byYE0iXl--K5m9AAAA2A"]
[Sun Aug 30 03:11:44.418302 2026] [authz_core:error] [pid 521505:tid 521708] [client 66.249.66.203:38300] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:44.418617 2026] [authz_core:error] [pid 521505:tid 521708] [client 66.249.66.203:38300] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:44.426225 2026] [security2:error] [pid 521505:tid 521639] [client 20.104.50.220:5524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/byp7.php"] [unique_id "apPlwG8byYE0iXl--K5m9QAAAyI"]
[Sun Aug 30 03:11:44.436098 2026] [security2:error] [pid 521505:tid 521658] [client 20.104.50.220:42803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/4index.php"] [unique_id "apPlwG8byYE0iXl--K5m9gAAAzU"]
[Sun Aug 30 03:11:44.446026 2026] [security2:error] [pid 521505:tid 521645] [client 158.23.147.79:40054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apPlwG8byYE0iXl--K5m-AAAAyg"]
[Sun Aug 30 03:11:44.450248 2026] [security2:error] [pid 521505:tid 521692] [client 20.104.49.130:26676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/ab.php"] [unique_id "apPlwG8byYE0iXl--K5m-QAAA1c"]
[Sun Aug 30 03:11:44.463719 2026] [authz_core:error] [pid 521505:tid 521719] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory29
[Sun Aug 30 03:11:44.464000 2026] [authz_core:error] [pid 521505:tid 521719] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory29
[Sun Aug 30 03:11:44.510357 2026] [security2:error] [pid 521505:tid 521743] [client 4.205.62.107:16349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/btx25.php"] [unique_id "apPlwG8byYE0iXl--K5m_QAAA4o"]
[Sun Aug 30 03:11:44.511000 2026] [security2:error] [pid 521505:tid 521721] [client 4.205.62.107:36578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/classsmtps.php"] [unique_id "apPlwG8byYE0iXl--K5m_gAAA3Q"]
[Sun Aug 30 03:11:44.529307 2026] [security2:error] [pid 521505:tid 521752] [client 20.104.18.15:18257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/sao.php"] [unique_id "apPlwG8byYE0iXl--K5m_wAAA5M"]
[Sun Aug 30 03:11:44.571286 2026] [security2:error] [pid 521505:tid 521659] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/service/.env"] [unique_id "apPlwG8byYE0iXl--K5nAgAAAzY"]
[Sun Aug 30 03:11:44.571580 2026] [security2:error] [pid 521505:tid 521731] [client 20.104.50.220:30925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/a2.php"] [unique_id "apPlwG8byYE0iXl--K5nAwAAA34"]
[Sun Aug 30 03:11:44.614755 2026] [security2:error] [pid 521505:tid 521655] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/exapi/.env"] [unique_id "apPlwG8byYE0iXl--K5nBAAAAzI"]
[Sun Aug 30 03:11:44.637277 2026] [authz_core:error] [pid 521505:tid 521720] [client 216.73.216.128:13341] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:44.637631 2026] [authz_core:error] [pid 521505:tid 521720] [client 216.73.216.128:13341] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:44.663576 2026] [security2:error] [pid 521505:tid 521686] [client 20.104.18.15:22500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/dragonshell.php"] [unique_id "apPlwG8byYE0iXl--K5nBgAAA1E"]
[Sun Aug 30 03:11:44.685067 2026] [security2:error] [pid 521505:tid 521671] [client 20.104.49.130:63569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wdfjba.org"] [uri "/sym.php"] [unique_id "apPlwG8byYE0iXl--K5nBwAAA0I"]
[Sun Aug 30 03:11:44.701271 2026] [authz_core:error] [pid 521505:tid 521651] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:11:44.701597 2026] [authz_core:error] [pid 521505:tid 521651] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:11:44.709110 2026] [security2:error] [pid 521505:tid 521680] [client 20.104.49.130:48051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/reop3.php"] [unique_id "apPlwG8byYE0iXl--K5nCQAAA0s"]
[Sun Aug 30 03:11:44.720788 2026] [authz_core:error] [pid 521505:tid 521713] [client 66.249.66.198:36749] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:44.721098 2026] [authz_core:error] [pid 521505:tid 521713] [client 66.249.66.198:36749] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:44.726491 2026] [authz_core:error] [pid 521505:tid 521738] [client 216.73.216.128:45356] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:44.726828 2026] [authz_core:error] [pid 521505:tid 521738] [client 216.73.216.128:45356] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:44.732761 2026] [security2:error] [pid 521505:tid 521739] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/api/v3/.env"] [unique_id "apPlwG8byYE0iXl--K5nEAAAA4Y"]
[Sun Aug 30 03:11:44.756533 2026] [security2:error] [pid 521505:tid 521637] [client 20.48.251.3:46177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/atex1.php"] [unique_id "apPlwG8byYE0iXl--K5nEQAAAyA"]
[Sun Aug 30 03:11:44.766541 2026] [security2:error] [pid 521505:tid 521724] [client 20.104.18.15:31636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/info.php/new.php"] [unique_id "apPlwG8byYE0iXl--K5nEgAAA3c"]
[Sun Aug 30 03:11:44.767842 2026] [security2:error] [pid 521505:tid 521744] [client 20.104.49.130:57665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alarm-monitoring.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlwG8byYE0iXl--K5nEwAAA4s"]
[Sun Aug 30 03:11:44.773364 2026] [security2:error] [pid 521505:tid 521675] [client 158.23.147.79:60181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-admin/index.php"] [unique_id "apPlwG8byYE0iXl--K5nFAAAA0Y"]
[Sun Aug 30 03:11:44.780772 2026] [security2:error] [pid 521505:tid 521698] [client 20.104.18.15:16998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/wp-content/l.php"] [unique_id "apPlwG8byYE0iXl--K5nFQAAA10"]
[Sun Aug 30 03:11:44.790707 2026] [security2:error] [pid 521505:tid 521641] [client 20.48.251.3:52282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/plss3.php"] [unique_id "apPlwG8byYE0iXl--K5nGAAAAyQ"]
[Sun Aug 30 03:11:44.797654 2026] [security2:error] [pid 521505:tid 521661] [client 20.197.61.180:3211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/wp-settings.php"] [unique_id "apPlwG8byYE0iXl--K5nGQAAAzg"]
[Sun Aug 30 03:11:44.816456 2026] [security2:error] [pid 521505:tid 521683] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/sitemaps/.env"] [unique_id "apPlwG8byYE0iXl--K5nHAAAA04"]
[Sun Aug 30 03:11:44.870812 2026] [security2:error] [pid 521505:tid 521717] [client 4.205.62.107:25483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/test.php"] [unique_id "apPlwG8byYE0iXl--K5nHgAAA3A"]
[Sun Aug 30 03:11:44.900553 2026] [security2:error] [pid 521505:tid 521748] [client 40.83.93.50:7054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/gel4y.php"] [unique_id "apPlwG8byYE0iXl--K5nHwAAA48"]
[Sun Aug 30 03:11:44.906012 2026] [security2:error] [pid 521505:tid 521714] [client 4.205.62.107:52867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/public/vx.php"] [unique_id "apPlwG8byYE0iXl--K5nIgAAA20"]
[Sun Aug 30 03:11:44.906917 2026] [security2:error] [pid 521505:tid 521737] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/api/dev/.env"] [unique_id "apPlwG8byYE0iXl--K5nIQAAA4Q"]
[Sun Aug 30 03:11:44.952285 2026] [authz_core:error] [pid 521505:tid 521725] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory32
[Sun Aug 30 03:11:44.952591 2026] [authz_core:error] [pid 521505:tid 521725] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory32
[Sun Aug 30 03:11:44.955930 2026] [security2:error] [pid 521505:tid 521649] [client 20.104.50.220:61955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/class19.php"] [unique_id "apPlwG8byYE0iXl--K5nJAAAAyw"]
[Sun Aug 30 03:11:44.958834 2026] [security2:error] [pid 521505:tid 521691] [client 158.23.147.79:40015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/chosen.php"] [unique_id "apPlwG8byYE0iXl--K5nJgAAA1Y"]
[Sun Aug 30 03:11:44.993902 2026] [security2:error] [pid 521505:tid 521711] [client 216.73.216.128:13341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_config_quote_replace_string"] [unique_id "apPlwG8byYE0iXl--K5nLAAAA2o"]
[Sun Aug 30 03:11:44.999656 2026] [authz_core:error] [pid 521505:tid 521705] [client 66.249.66.197:49489] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:45.000025 2026] [authz_core:error] [pid 521505:tid 521705] [client 66.249.66.197:49489] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:45.015697 2026] [security2:error] [pid 521505:tid 521733] [client 20.104.18.15:2010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlwW8byYE0iXl--K5nLgAAA4A"]
[Sun Aug 30 03:11:45.072826 2026] [security2:error] [pid 521505:tid 521679] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/api/staging/.env"] [unique_id "apPlwW8byYE0iXl--K5nNAAAA0o"]
[Sun Aug 30 03:11:45.093827 2026] [authz_core:error] [pid 521505:tid 521750] [client 66.249.66.76:56108] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:45.094099 2026] [authz_core:error] [pid 521505:tid 521750] [client 66.249.66.76:56108] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:45.161490 2026] [authz_core:error] [pid 521505:tid 521754] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fs-nail
[Sun Aug 30 03:11:45.161766 2026] [authz_core:error] [pid 521505:tid 521754] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fs-nail
[Sun Aug 30 03:11:45.189879 2026] [security2:error] [pid 521505:tid 521703] [client 20.104.49.130:26647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/well.php"] [unique_id "apPlwW8byYE0iXl--K5nOAAAA2I"]
[Sun Aug 30 03:11:45.209071 2026] [security2:error] [pid 521505:tid 521743] [client 20.48.250.41:19412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.drainzit.com"] [uri "/R57.php"] [unique_id "apPlwW8byYE0iXl--K5nOgAAA4o"]
[Sun Aug 30 03:11:45.236210 2026] [security2:error] [pid 521505:tid 521688] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/vendor/.env"] [unique_id "apPlwW8byYE0iXl--K5nOwAAA1M"]
[Sun Aug 30 03:11:45.246116 2026] [security2:error] [pid 521505:tid 521663] [client 20.104.50.220:16715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/gifclass.php"] [unique_id "apPlwW8byYE0iXl--K5nPAAAAzo"]
[Sun Aug 30 03:11:45.250761 2026] [security2:error] [pid 521505:tid 521659] [client 20.104.49.130:48596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/kerang.php"] [unique_id "apPlwW8byYE0iXl--K5nPQAAAzY"]
[Sun Aug 30 03:11:45.286728 2026] [security2:error] [pid 521505:tid 521666] [client 20.104.50.220:33340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/7index.php"] [unique_id "apPlwW8byYE0iXl--K5nQwAAAz0"]
[Sun Aug 30 03:11:45.303686 2026] [security2:error] [pid 521505:tid 521677] [client 4.205.62.107:16787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/plss3.php"] [unique_id "apPlwW8byYE0iXl--K5nRAAAA0g"]
[Sun Aug 30 03:11:45.310722 2026] [security2:error] [pid 521505:tid 521671] [client 20.151.200.44:41870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/ft.php"] [unique_id "apPlwW8byYE0iXl--K5nRQAAA0I"]
[Sun Aug 30 03:11:45.328265 2026] [security2:error] [pid 521505:tid 521751] [client 20.104.18.15:51164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/aa.php"] [unique_id "apPlwW8byYE0iXl--K5nRwAAA5I"]
[Sun Aug 30 03:11:45.355424 2026] [security2:error] [pid 521505:tid 521697] [client 20.104.50.220:24919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/sukce.php"] [unique_id "apPlwW8byYE0iXl--K5nSQAAA1w"]
[Sun Aug 30 03:11:45.367913 2026] [security2:error] [pid 521505:tid 521721] [client 40.83.93.50:22090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/leaf.php"] [unique_id "apPlwW8byYE0iXl--K5nTAAAA3Q"]
[Sun Aug 30 03:11:45.373750 2026] [authz_core:error] [pid 521505:tid 521680] [client 66.249.66.194:38116] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:45.374038 2026] [authz_core:error] [pid 521505:tid 521680] [client 66.249.66.194:38116] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:45.384865 2026] [security2:error] [pid 521505:tid 521724] [client 20.104.50.220:52844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/images/byps.php"] [unique_id "apPlwW8byYE0iXl--K5nTQAAA3c"]
[Sun Aug 30 03:11:45.384947 2026] [security2:error] [pid 521505:tid 521744] [client 20.48.250.41:11216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/ava.php"] [unique_id "apPlwW8byYE0iXl--K5nTwAAA4s"]
[Sun Aug 30 03:11:45.391677 2026] [security2:error] [pid 521505:tid 521698] [client 68.155.159.216:52238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apPlwW8byYE0iXl--K5nUAAAA10"]
[Sun Aug 30 03:11:45.402300 2026] [security2:error] [pid 521505:tid 521641] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/lib/.env"] [unique_id "apPlwW8byYE0iXl--K5nUQAAAyQ"]
[Sun Aug 30 03:11:45.430183 2026] [authz_core:error] [pid 521505:tid 521694] [client 66.249.66.44:57630] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:45.430454 2026] [authz_core:error] [pid 521505:tid 521694] [client 66.249.66.44:57630] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:45.432033 2026] [security2:error] [pid 521505:tid 521759] [client 20.48.251.3:55700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/kedi.php"] [unique_id "apPlwW8byYE0iXl--K5nUwAAA5o"]
[Sun Aug 30 03:11:45.447885 2026] [security2:error] [pid 521505:tid 521673] [client 20.104.50.220:29588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/AkuSayangKamu45.php"] [unique_id "apPlwW8byYE0iXl--K5nVAAAA0Q"]
[Sun Aug 30 03:11:45.449561 2026] [security2:error] [pid 521505:tid 521638] [client 20.220.10.235:24688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlwW8byYE0iXl--K5nVQAAAyE"]
[Sun Aug 30 03:11:45.458221 2026] [security2:error] [pid 521505:tid 521756] [client 158.23.147.79:40023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/goods.php"] [unique_id "apPlwW8byYE0iXl--K5nVwAAA5c"]
[Sun Aug 30 03:11:45.459375 2026] [authz_core:error] [pid 521505:tid 521683] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory27
[Sun Aug 30 03:11:45.459633 2026] [authz_core:error] [pid 521505:tid 521683] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory27
[Sun Aug 30 03:11:45.464301 2026] [security2:error] [pid 521505:tid 521706] [client 207.154.212.47:47906] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "mail.eessel.com"] [uri "/wp-json/batch/v1"] [unique_id "apPlwW8byYE0iXl--K5nWAAAA2U"]
[Sun Aug 30 03:11:45.471865 2026] [authz_core:error] [pid 521505:tid 521761] [client 66.249.66.77:40073] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:45.472152 2026] [authz_core:error] [pid 521505:tid 521761] [client 66.249.66.77:40073] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:45.473247 2026] [security2:error] [pid 521505:tid 521654] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/logs/.env"] [unique_id "apPlwW8byYE0iXl--K5nXQAAAzE"]
[Sun Aug 30 03:11:45.484533 2026] [security2:error] [pid 521505:tid 521682] [client 20.48.160.90:37707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlwW8byYE0iXl--K5nXwAAA00"]
[Sun Aug 30 03:11:45.511289 2026] [security2:error] [pid 521505:tid 521693] [client 20.197.61.180:15783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/themes/wp-signup.php"] [unique_id "apPlwW8byYE0iXl--K5nYgAAA1g"]
[Sun Aug 30 03:11:45.535628 2026] [security2:error] [pid 521505:tid 521709] [client 20.48.250.41:11081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/gdn.php"] [unique_id "apPlwW8byYE0iXl--K5nZQAAA2g"]
[Sun Aug 30 03:11:45.568272 2026] [security2:error] [pid 521505:tid 521718] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/resources/.env"] [unique_id "apPlwW8byYE0iXl--K5naAAAA3E"]
[Sun Aug 30 03:11:45.576621 2026] [security2:error] [pid 521505:tid 521701] [client 20.220.10.235:24690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlwW8byYE0iXl--K5nawAAA2A"]
[Sun Aug 30 03:11:45.576769 2026] [security2:error] [pid 521505:tid 521740] [client 20.104.50.220:5186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/anonsec.php"] [unique_id "apPlwW8byYE0iXl--K5nagAAA4c"]
[Sun Aug 30 03:11:45.579344 2026] [security2:error] [pid 521505:tid 521658] [client 20.104.50.220:51607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/5index.php"] [unique_id "apPlwW8byYE0iXl--K5nbAAAAzU"]
[Sun Aug 30 03:11:45.614941 2026] [security2:error] [pid 521505:tid 521762] [client 20.48.251.3:36807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/asa.php"] [unique_id "apPlwW8byYE0iXl--K5nbQAAA50"]
[Sun Aug 30 03:11:45.643576 2026] [authz_core:error] [pid 521505:tid 521645] [client 66.249.66.205:46410] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:45.643890 2026] [authz_core:error] [pid 521505:tid 521645] [client 66.249.66.205:46410] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:45.647964 2026] [security2:error] [pid 521505:tid 521689] [client 4.205.62.107:36614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/cache-compat.php"] [unique_id "apPlwW8byYE0iXl--K5nbwAAA1Q"]
[Sun Aug 30 03:11:45.651719 2026] [security2:error] [pid 521505:tid 521524] [remote 156.59.198.135:39460] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arcexploration.com.au"] [uri "/wp-content/uploads/AnnualReportYearEnding31December2018_29Mar19.pdf"] [unique_id "apPlwW8byYE0iXl--K5ncQADVxI"]
[Sun Aug 30 03:11:45.655964 2026] [security2:error] [pid 521505:tid 521679] [client 4.205.62.107:16372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/app_dev.php"] [unique_id "apPlwW8byYE0iXl--K5ncwAAA0o"]
[Sun Aug 30 03:11:45.673860 2026] [security2:error] [pid 521505:tid 521703] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/cache/.env"] [unique_id "apPlwW8byYE0iXl--K5ndwAAA2I"]
[Sun Aug 30 03:11:45.677994 2026] [security2:error] [pid 521505:tid 521743] [client 20.48.160.90:61503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlwW8byYE0iXl--K5neQAAA4o"]
[Sun Aug 30 03:11:45.694254 2026] [security2:error] [pid 521505:tid 521659] [client 20.104.18.15:18404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/dapa.php"] [unique_id "apPlwW8byYE0iXl--K5newAAAzY"]
[Sun Aug 30 03:11:45.695777 2026] [security2:error] [pid 521505:tid 521731] [client 158.23.147.79:58405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-content/themes/index.php"] [unique_id "apPlwW8byYE0iXl--K5nfAAAA34"]
[Sun Aug 30 03:11:45.701768 2026] [authz_core:error] [pid 521505:tid 521663] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:11:45.702216 2026] [authz_core:error] [pid 521505:tid 521663] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:11:45.706353 2026] [security2:error] [pid 521505:tid 521687] [client 20.220.10.235:24771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/h02ugyh.php"] [unique_id "apPlwW8byYE0iXl--K5nfQAAA1I"]
[Sun Aug 30 03:11:45.741106 2026] [security2:error] [pid 521505:tid 521642] [client 20.104.50.220:59716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/file15.php"] [unique_id "apPlwW8byYE0iXl--K5ngAAAAyU"]
[Sun Aug 30 03:11:45.741537 2026] [security2:error] [pid 521505:tid 521668] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/assets/.env"] [unique_id "apPlwW8byYE0iXl--K5nfwAAAz8"]
[Sun Aug 30 03:11:45.750305 2026] [security2:error] [pid 521505:tid 521647] [client 216.73.216.128:63441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPlwW8byYE0iXl--K5nggAAAyo"]
[Sun Aug 30 03:11:45.806712 2026] [security2:error] [pid 521505:tid 521744] [client 20.48.250.41:11178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/f2.php"] [unique_id "apPlwW8byYE0iXl--K5nhwAAA4s"]
[Sun Aug 30 03:11:45.819867 2026] [security2:error] [pid 521505:tid 521750] [client 20.104.18.15:22390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/wp-safe.php"] [unique_id "apPlwW8byYE0iXl--K5niQAAA5E"]
[Sun Aug 30 03:11:45.839195 2026] [security2:error] [pid 521505:tid 521648] [client 158.23.147.79:39963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apPlwW8byYE0iXl--K5njAAAAys"]
[Sun Aug 30 03:11:45.844405 2026] [security2:error] [pid 521505:tid 521715] [client 20.48.160.90:61458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/ser.php"] [unique_id "apPlwW8byYE0iXl--K5njgAAA24"]
[Sun Aug 30 03:11:45.846709 2026] [security2:error] [pid 521505:tid 521672] [client 20.220.10.235:24696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/sf.php"] [unique_id "apPlwW8byYE0iXl--K5njwAAA0M"]
[Sun Aug 30 03:11:45.849028 2026] [security2:error] [pid 521505:tid 521688] [client 40.83.93.50:6389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/k.php"] [unique_id "apPlwW8byYE0iXl--K5nkAAAA1M"]
[Sun Aug 30 03:11:45.874140 2026] [security2:error] [pid 521505:tid 521654] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/mailer/.env"] [unique_id "apPlwW8byYE0iXl--K5nkgAAAzE"]
[Sun Aug 30 03:11:45.903062 2026] [security2:error] [pid 521505:tid 521714] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/uploads/.env"] [unique_id "apPlwW8byYE0iXl--K5nlwAAA20"]
[Sun Aug 30 03:11:45.919318 2026] [security2:error] [pid 521505:tid 521742] [client 20.48.251.3:64298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/aws_sdk_settings.php"] [unique_id "apPlwW8byYE0iXl--K5nmQAAA4k"]
[Sun Aug 30 03:11:45.920539 2026] [security2:error] [pid 521505:tid 521716] [client 20.104.18.15:16938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/wp-admin/w.php"] [unique_id "apPlwW8byYE0iXl--K5nmgAAA28"]
[Sun Aug 30 03:11:45.947290 2026] [security2:error] [pid 521505:tid 521749] [client 20.48.251.3:52223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/aws.php"] [unique_id "apPlwW8byYE0iXl--K5nnAAAA5A"]
[Sun Aug 30 03:11:45.966532 2026] [authz_core:error] [pid 521505:tid 521653] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory23
[Sun Aug 30 03:11:45.967024 2026] [authz_core:error] [pid 521505:tid 521653] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory23
[Sun Aug 30 03:11:45.978045 2026] [security2:error] [pid 521505:tid 521683] [client 20.48.250.41:11066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/grsiuk.php"] [unique_id "apPlwW8byYE0iXl--K5nogAAA04"]
[Sun Aug 30 03:11:46.001462 2026] [security2:error] [pid 521505:tid 521636] [client 20.220.10.235:24641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/4e.php"] [unique_id "apPlwm8byYE0iXl--K5npAAAAx8"]
[Sun Aug 30 03:11:46.003338 2026] [security2:error] [pid 521505:tid 521679] [client 20.48.160.90:37652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/431.php"] [unique_id "apPlwm8byYE0iXl--K5npgAAA0o"]
[Sun Aug 30 03:11:46.025136 2026] [security2:error] [pid 521505:tid 521726] [client 4.205.62.107:26979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/cloud.php"] [unique_id "apPlwm8byYE0iXl--K5nrAAAA3k"]
[Sun Aug 30 03:11:46.045229 2026] [security2:error] [pid 521505:tid 521732] [client 4.205.62.107:52925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/log.php"] [unique_id "apPlwm8byYE0iXl--K5nrwAAA38"]
[Sun Aug 30 03:11:46.063699 2026] [security2:error] [pid 521505:tid 521647] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/internal/.env"] [unique_id "apPlwm8byYE0iXl--K5nswAAAyo"]
[Sun Aug 30 03:11:46.076162 2026] [security2:error] [pid 521505:tid 521739] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/mail/.env"] [unique_id "apPlwm8byYE0iXl--K5ntQAAA4Y"]
[Sun Aug 30 03:11:46.131102 2026] [authz_core:error] [pid 521505:tid 521705] [client 216.73.216.128:45356] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:46.131597 2026] [authz_core:error] [pid 521505:tid 521705] [client 216.73.216.128:45356] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:46.132143 2026] [security2:error] [pid 521505:tid 521729] [client 20.220.10.235:24779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/ssss.php"] [unique_id "apPlwm8byYE0iXl--K5nuAAAA3w"]
[Sun Aug 30 03:11:46.139070 2026] [security2:error] [pid 521505:tid 521698] [client 20.48.160.90:37737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/rxr.php"] [unique_id "apPlwm8byYE0iXl--K5nuQAAA10"]
[Sun Aug 30 03:11:46.140097 2026] [security2:error] [pid 521505:tid 521721] [client 20.48.250.41:11182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/wp-scr1pts.php"] [unique_id "apPlwm8byYE0iXl--K5nugAAA3Q"]
[Sun Aug 30 03:11:46.154777 2026] [security2:error] [pid 521505:tid 521663] [client 20.104.18.15:1926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/media.php"] [unique_id "apPlwm8byYE0iXl--K5nuwAAAzo"]
[Sun Aug 30 03:11:46.164385 2026] [security2:error] [pid 521505:tid 521650] [client 20.104.50.220:59545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/2clas.php"] [unique_id "apPlwm8byYE0iXl--K5nvAAAAy0"]
[Sun Aug 30 03:11:46.178850 2026] [authz_core:error] [pid 521505:tid 521641] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:11:46.179268 2026] [authz_core:error] [pid 521505:tid 521641] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:11:46.205923 2026] [security2:error] [pid 521505:tid 521762] [client 20.197.61.180:12267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/updraft/about.php"] [unique_id "apPlwm8byYE0iXl--K5nvgAAA50"]
[Sun Aug 30 03:11:46.208029 2026] [security2:error] [pid 521505:tid 521759] [client 216.73.216.128:11388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_config_quote_replace_string"] [unique_id "apPlwm8byYE0iXl--K5nvwAAA5o"]
[Sun Aug 30 03:11:46.225867 2026] [security2:error] [pid 521505:tid 521688] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/tools/.env"] [unique_id "apPlwm8byYE0iXl--K5nwAAAA1M"]
[Sun Aug 30 03:11:46.242310 2026] [security2:error] [pid 521505:tid 521753] [client 158.23.147.79:58404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/about.php"] [unique_id "apPlwm8byYE0iXl--K5nwgAAA5Q"]
[Sun Aug 30 03:11:46.276274 2026] [security2:error] [pid 521505:tid 521708] [client 20.220.10.235:24785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/zoz.php"] [unique_id "apPlwm8byYE0iXl--K5nxwAAA2c"]
[Sun Aug 30 03:11:46.277264 2026] [security2:error] [pid 521505:tid 521676] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/email/.env"] [unique_id "apPlwm8byYE0iXl--K5nxgAAA0c"]
[Sun Aug 30 03:11:46.284435 2026] [security2:error] [pid 521505:tid 521675] [client 20.48.160.90:61440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/csst.php"] [unique_id "apPlwm8byYE0iXl--K5nyAAAA0Y"]
[Sun Aug 30 03:11:46.295368 2026] [security2:error] [pid 521505:tid 521649] [client 20.48.250.41:11020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/num.php"] [unique_id "apPlwm8byYE0iXl--K5nyQAAAyw"]
[Sun Aug 30 03:11:46.331691 2026] [security2:error] [pid 521505:tid 521750] [client 40.83.93.50:3953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/chosen.php"] [unique_id "apPlwm8byYE0iXl--K5nywAAA5E"]
[Sun Aug 30 03:11:46.334094 2026] [security2:error] [pid 521505:tid 521691] [client 158.23.147.79:40052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apPlwm8byYE0iXl--K5nzAAAA1Y"]
[Sun Aug 30 03:11:46.384566 2026] [security2:error] [pid 521505:tid 521662] [client 20.104.50.220:16727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "apPlwm8byYE0iXl--K5nzgAAAzk"]
[Sun Aug 30 03:11:46.388770 2026] [security2:error] [pid 521505:tid 521711] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/scripts/.env"] [unique_id "apPlwm8byYE0iXl--K5nzwAAA2o"]
[Sun Aug 30 03:11:46.410795 2026] [authz_core:error] [pid 521505:tid 521747] [client 66.249.66.200:56275] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:46.411273 2026] [authz_core:error] [pid 521505:tid 521747] [client 66.249.66.200:56275] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:46.426728 2026] [security2:error] [pid 521505:tid 521651] [client 20.48.160.90:37969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp-includes/blocks/query-title/footer.php"] [unique_id "apPlwm8byYE0iXl--K5n0wAAAy4"]
[Sun Aug 30 03:11:46.432724 2026] [security2:error] [pid 521505:tid 521685] [client 20.104.50.220:32856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/8index.php"] [unique_id "apPlwm8byYE0iXl--K5n1AAAA1A"]
[Sun Aug 30 03:11:46.436948 2026] [fcgid:warn] [pid 521505:tid 521718] (70014)End of file found: [client 66.132.172.218:58338] mod_fcgid: can't get data from http client
[Sun Aug 30 03:11:46.437146 2026] [security2:error] [pid 521505:tid 521740] [client 4.205.62.107:16781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/aws.php"] [unique_id "apPlwm8byYE0iXl--K5n1gAAA4c"]
[Sun Aug 30 03:11:46.437768 2026] [security2:error] [pid 521505:tid 521734] [client 20.220.10.235:24703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/kcs.php"] [unique_id "apPlwm8byYE0iXl--K5n1wAAA4E"]
[Sun Aug 30 03:11:46.455821 2026] [security2:error] [pid 521505:tid 521678] [client 20.48.250.41:11169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/a4.php"] [unique_id "apPlwm8byYE0iXl--K5n2wAAA0k"]
[Sun Aug 30 03:11:46.465260 2026] [authz_core:error] [pid 521505:tid 521722] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory28
[Sun Aug 30 03:11:46.465666 2026] [authz_core:error] [pid 521505:tid 521722] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory28
[Sun Aug 30 03:11:46.478273 2026] [security2:error] [pid 521505:tid 521701] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/smtp/.env"] [unique_id "apPlwm8byYE0iXl--K5n3QAAA2A"]
[Sun Aug 30 03:11:46.484423 2026] [security2:error] [pid 521505:tid 521679] [client 20.104.18.15:51183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/img.php"] [unique_id "apPlwm8byYE0iXl--K5n3wAAA0o"]
[Sun Aug 30 03:11:46.494342 2026] [security2:error] [pid 521505:tid 521637] [client 20.104.50.220:24842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/xb.php"] [unique_id "apPlwm8byYE0iXl--K5n4AAAAyA"]
[Sun Aug 30 03:11:46.537627 2026] [security2:error] [pid 521505:tid 521726] [client 158.23.147.79:40025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/file.php"] [unique_id "apPlwm8byYE0iXl--K5n4wAAA3k"]
[Sun Aug 30 03:11:46.550889 2026] [security2:error] [pid 521505:tid 521756] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/bin/.env"] [unique_id "apPlwm8byYE0iXl--K5n5QAAA5c"]
[Sun Aug 30 03:11:46.562953 2026] [security2:error] [pid 521505:tid 521686] [client 20.104.50.220:28680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/images/bypass.php"] [unique_id "apPlwm8byYE0iXl--K5n5gAAA1E"]
[Sun Aug 30 03:11:46.564817 2026] [security2:error] [pid 521505:tid 521669] [client 20.220.10.235:24704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/tajj.php"] [unique_id "apPlwm8byYE0iXl--K5n5wAAA0A"]
[Sun Aug 30 03:11:46.574194 2026] [security2:error] [pid 521505:tid 521668] [client 20.48.251.3:55768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/oc460l3x.php"] [unique_id "apPlwm8byYE0iXl--K5n6wAAAz8"]
[Sun Aug 30 03:11:46.590803 2026] [security2:error] [pid 521505:tid 521664] [client 20.48.160.90:37998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp-content/uploads/indoex.php"] [unique_id "apPlwm8byYE0iXl--K5n7QAAAzs"]
[Sun Aug 30 03:11:46.606569 2026] [security2:error] [pid 521505:tid 521739] [client 20.151.200.44:46058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/motu.php"] [unique_id "apPlwm8byYE0iXl--K5n7wAAA4Y"]
[Sun Aug 30 03:11:46.612508 2026] [security2:error] [pid 521505:tid 521684] [client 20.104.50.220:28719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/googlebots.php"] [unique_id "apPlwm8byYE0iXl--K5n8AAAA08"]
[Sun Aug 30 03:11:46.642733 2026] [security2:error] [pid 521505:tid 521695] [client 20.104.49.130:63568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/ws58.php"] [unique_id "apPlwm8byYE0iXl--K5n8wAAA1o"]
[Sun Aug 30 03:11:46.661887 2026] [authz_core:error] [pid 521505:tid 521663] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:11:46.662220 2026] [authz_core:error] [pid 521505:tid 521663] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:11:46.662513 2026] [security2:error] [pid 521505:tid 521755] [client 20.104.18.15:31668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/w.php"] [unique_id "apPlwm8byYE0iXl--K5n9wAAA5Y"]
[Sun Aug 30 03:11:46.678505 2026] [security2:error] [pid 521505:tid 521648] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/mailing/.env"] [unique_id "apPlwm8byYE0iXl--K5n-gAAAys"]
[Sun Aug 30 03:11:46.701638 2026] [security2:error] [pid 521505:tid 521753] [client 20.220.10.235:24773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/bge.php"] [unique_id "apPlwm8byYE0iXl--K5n_AAAA5Q"]
[Sun Aug 30 03:11:46.711954 2026] [security2:error] [pid 521505:tid 521682] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/sbin/.env"] [unique_id "apPlwm8byYE0iXl--K5n_gAAA00"]
[Sun Aug 30 03:11:46.734893 2026] [security2:error] [pid 521505:tid 521708] [client 20.104.50.220:6109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/anon.php"] [unique_id "apPlwm8byYE0iXl--K5oAAAAA2c"]
[Sun Aug 30 03:11:46.751060 2026] [security2:error] [pid 521505:tid 521641] [client 20.104.50.220:42815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/6index.php"] [unique_id "apPlwm8byYE0iXl--K5oAwAAAyQ"]
[Sun Aug 30 03:11:46.769055 2026] [security2:error] [pid 521505:tid 521691] [client 20.48.160.90:61564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPlwm8byYE0iXl--K5oBQAAA1Y"]
[Sun Aug 30 03:11:46.773746 2026] [security2:error] [pid 521505:tid 521742] [client 20.48.251.3:36873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/radio.php"] [unique_id "apPlwm8byYE0iXl--K5oBgAAA4k"]
[Sun Aug 30 03:11:46.784901 2026] [authz_core:error] [pid 521505:tid 521709] [client 66.249.66.72:55159] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:46.784920 2026] [security2:error] [pid 521505:tid 521656] [client 20.151.200.44:26609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/h02ugyh.php"] [unique_id "apPlwm8byYE0iXl--K5oCwAAAzM"]
[Sun Aug 30 03:11:46.785154 2026] [authz_core:error] [pid 521505:tid 521709] [client 66.249.66.72:55159] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:46.793935 2026] [security2:error] [pid 521505:tid 521706] [client 4.205.62.107:16356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/php-info.php"] [unique_id "apPlwm8byYE0iXl--K5oDwAAA2U"]
[Sun Aug 30 03:11:46.805315 2026] [security2:error] [pid 521505:tid 521678] [client 158.23.147.79:16338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apPlwm8byYE0iXl--K5oEgAAA0k"]
[Sun Aug 30 03:11:46.832622 2026] [security2:error] [pid 521505:tid 521701] [client 20.104.18.15:18344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/wp-content/l.php"] [unique_id "apPlwm8byYE0iXl--K5oFAAAA2A"]
[Sun Aug 30 03:11:46.832670 2026] [security2:error] [pid 521505:tid 521707] [client 20.220.10.235:24776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/ssh3ll.php"] [unique_id "apPlwm8byYE0iXl--K5oEwAAA2Y"]
[Sun Aug 30 03:11:46.873047 2026] [security2:error] [pid 521505:tid 521713] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/local/.env"] [unique_id "apPlwm8byYE0iXl--K5oGAAAA2w"]
[Sun Aug 30 03:11:46.880021 2026] [security2:error] [pid 521505:tid 521735] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/notifications/.env"] [unique_id "apPlwm8byYE0iXl--K5oGQAAA4I"]
[Sun Aug 30 03:11:46.886368 2026] [security2:error] [pid 521505:tid 521638] [client 40.83.93.50:6356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/radio.php"] [unique_id "apPlwm8byYE0iXl--K5oGgAAAyE"]
[Sun Aug 30 03:11:46.895951 2026] [security2:error] [pid 521505:tid 521692] [client 20.104.50.220:59384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/no1.php"] [unique_id "apPlwm8byYE0iXl--K5oHAAAA1c"]
[Sun Aug 30 03:11:46.903629 2026] [security2:error] [pid 521505:tid 521670] [client 4.205.62.107:36546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/aws_keys.php"] [unique_id "apPlwm8byYE0iXl--K5oHgAAA0E"]
[Sun Aug 30 03:11:46.905375 2026] [security2:error] [pid 521505:tid 521693] [client 68.155.159.216:52573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apPlwm8byYE0iXl--K5oHwAAA1g"]
[Sun Aug 30 03:11:46.913893 2026] [security2:error] [pid 521505:tid 521732] [client 20.48.160.90:37719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/haxor.php"] [unique_id "apPlwm8byYE0iXl--K5oIQAAA38"]
[Sun Aug 30 03:11:46.924047 2026] [security2:error] [pid 521505:tid 521715] [client 20.197.61.180:3790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/upgrade-temp-backup/min.php"] [unique_id "apPlwm8byYE0iXl--K5oIgAAA24"]
[Sun Aug 30 03:11:46.955437 2026] [security2:error] [pid 521505:tid 521751] [client 20.104.18.15:22396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/gjewuagf.php"] [unique_id "apPlwm8byYE0iXl--K5oKAAAA5I"]
[Sun Aug 30 03:11:46.963207 2026] [security2:error] [pid 521505:tid 521684] [client 20.220.10.235:24772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/motu.php"] [unique_id "apPlwm8byYE0iXl--K5oKwAAA08"]
[Sun Aug 30 03:11:46.966003 2026] [authz_core:error] [pid 521505:tid 521647] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory20
[Sun Aug 30 03:11:46.966478 2026] [authz_core:error] [pid 521505:tid 521647] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory20
[Sun Aug 30 03:11:46.975454 2026] [security2:error] [pid 521505:tid 521672] [client 20.104.49.130:52103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/xmini4.php"] [unique_id "apPlwm8byYE0iXl--K5oLQAAA0M"]
[Sun Aug 30 03:11:46.983920 2026] [security2:error] [pid 521505:tid 521695] [client 158.23.147.79:40049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/file17.php"] [unique_id "apPlwm8byYE0iXl--K5oLwAAA1o"]
[Sun Aug 30 03:11:47.027603 2026] [core:alert] [pid 521505:tid 521731] [client 223.123.125.107:33918] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:11:47.035935 2026] [security2:error] [pid 521505:tid 521661] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/portal/.env"] [unique_id "apPlw28byYE0iXl--K5oOQAAAzg"]
[Sun Aug 30 03:11:47.052436 2026] [security2:error] [pid 521505:tid 521761] [client 20.48.160.90:61512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/google.php"] [unique_id "apPlw28byYE0iXl--K5oOwAAA5w"]
[Sun Aug 30 03:11:47.068604 2026] [security2:error] [pid 521505:tid 521640] [client 20.48.251.3:46241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/setup-config.php"] [unique_id "apPlw28byYE0iXl--K5oPgAAAyM"]
[Sun Aug 30 03:11:47.080024 2026] [security2:error] [pid 521505:tid 521734] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/notify/.env"] [unique_id "apPlw28byYE0iXl--K5oQQAAA4E"]
[Sun Aug 30 03:11:47.090698 2026] [security2:error] [pid 521505:tid 521740] [client 20.48.251.3:59516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/app.default.php"] [unique_id "apPlw28byYE0iXl--K5oQgAAA4c"]
[Sun Aug 30 03:11:47.095442 2026] [security2:error] [pid 521505:tid 521678] [client 20.220.10.235:24694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/wefile.php"] [unique_id "apPlw28byYE0iXl--K5oQwAAA0k"]
[Sun Aug 30 03:11:47.103166 2026] [security2:error] [pid 521505:tid 521730] [client 20.104.18.15:20423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/wp-content/k.php"] [unique_id "apPlw28byYE0iXl--K5oRAAAA30"]
[Sun Aug 30 03:11:47.120533 2026] [security2:error] [pid 521505:tid 521723] [client 216.73.216.128:45356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_config_quote_replace_string"] [unique_id "apPlw28byYE0iXl--K5oRQAAA3Y"]
[Sun Aug 30 03:11:47.129376 2026] [security2:error] [pid 521505:tid 521749] [client 20.151.200.44:62235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/txets.php"] [unique_id "apPlw28byYE0iXl--K5oRwAAA5A"]
[Sun Aug 30 03:11:47.154441 2026] [security2:error] [pid 521505:tid 521655] [client 158.23.147.79:58388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/themes.php"] [unique_id "apPlw28byYE0iXl--K5oSgAAAzI"]
[Sun Aug 30 03:11:47.166765 2026] [security2:error] [pid 521505:tid 521660] [client 4.205.62.107:25512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/asdf.php"] [unique_id "apPlw28byYE0iXl--K5oSwAAAzc"]
[Sun Aug 30 03:11:47.176144 2026] [authz_core:error] [pid 521505:tid 521713] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fman-db
[Sun Aug 30 03:11:47.176497 2026] [authz_core:error] [pid 521505:tid 521713] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fman-db
[Sun Aug 30 03:11:47.192770 2026] [security2:error] [pid 521505:tid 521747] [client 20.48.160.90:61557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "apPlw28byYE0iXl--K5oUQAAA44"]
[Sun Aug 30 03:11:47.197850 2026] [security2:error] [pid 521505:tid 521670] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/dashboard/.env"] [unique_id "apPlw28byYE0iXl--K5oUgAAA0E"]
[Sun Aug 30 03:11:47.229473 2026] [security2:error] [pid 521505:tid 521743] [client 20.220.10.235:24665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/Contrller.php"] [unique_id "apPlw28byYE0iXl--K5oWAAAA4o"]
[Sun Aug 30 03:11:47.243955 2026] [security2:error] [pid 521505:tid 521540] [remote 69.72.248.158:40316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.248.72.69.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tulsacriminalattorney.pro"] [uri "/wp-login.php"] [unique_id "apPlw28byYE0iXl--K5oVgADRCI"]
[Sun Aug 30 03:11:47.276068 2026] [authz_core:error] [pid 521505:tid 521726] [client 66.249.66.68:59052] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:47.276524 2026] [authz_core:error] [pid 521505:tid 521726] [client 66.249.66.68:59052] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:47.283362 2026] [security2:error] [pid 521505:tid 521671] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/sender/.env"] [unique_id "apPlw28byYE0iXl--K5oZwAAA0I"]
[Sun Aug 30 03:11:47.293483 2026] [security2:error] [pid 521505:tid 521644] [client 20.104.18.15:2033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/adminfuns.php"] [unique_id "apPlw28byYE0iXl--K5oaQAAAyc"]
[Sun Aug 30 03:11:47.310920 2026] [security2:error] [pid 521505:tid 521650] [client 20.104.50.220:61690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/bless5.php"] [unique_id "apPlw28byYE0iXl--K5obAAAAy0"]
[Sun Aug 30 03:11:47.327158 2026] [security2:error] [pid 521505:tid 521755] [client 20.48.160.90:61561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/robots.php"] [unique_id "apPlw28byYE0iXl--K5obQAAA5Y"]
[Sun Aug 30 03:11:47.331088 2026] [security2:error] [pid 521505:tid 521737] [client 158.23.147.79:39983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/file5.php"] [unique_id "apPlw28byYE0iXl--K5obgAAA4Q"]
[Sun Aug 30 03:11:47.358900 2026] [security2:error] [pid 521505:tid 521753] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/panel/.env"] [unique_id "apPlw28byYE0iXl--K5oeAAAA5Q"]
[Sun Aug 30 03:11:47.385946 2026] [security2:error] [pid 521505:tid 521750] [client 20.220.10.235:24695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/file66.php"] [unique_id "apPlw28byYE0iXl--K5ofwAAA5E"]
[Sun Aug 30 03:11:47.402156 2026] [security2:error] [pid 521505:tid 521662] [client 4.205.62.107:52802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/ebahvhhh.php"] [unique_id "apPlw28byYE0iXl--K5ogQAAAzk"]
[Sun Aug 30 03:11:47.431118 2026] [security2:error] [pid 521505:tid 521680] [client 40.83.93.50:10739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/functions.php"] [unique_id "apPlw28byYE0iXl--K5ogwAAA0s"]
[Sun Aug 30 03:11:47.435697 2026] [security2:error] [pid 521505:tid 521557] [remote 69.72.248.158:40316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.248.72.69.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tulsacriminalattorney.pro"] [uri "/wp-login.php"] [unique_id "apPlw28byYE0iXl--K5ohAADajM"], referer: https://tulsacriminalattorney.pro/wp-login.php
[Sun Aug 30 03:11:47.468165 2026] [security2:error] [pid 521505:tid 521686] [client 20.48.160.90:37979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp-content/plugins/ccx/index.php"] [unique_id "apPlw28byYE0iXl--K5ojQAAA1E"]
[Sun Aug 30 03:11:47.475018 2026] [authz_core:error] [pid 521505:tid 521727] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory25
[Sun Aug 30 03:11:47.475295 2026] [authz_core:error] [pid 521505:tid 521727] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory25
[Sun Aug 30 03:11:47.484401 2026] [security2:error] [pid 521505:tid 521707] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/campaign/.env"] [unique_id "apPlw28byYE0iXl--K5ojgAAA2Y"]
[Sun Aug 30 03:11:47.487584 2026] [security2:error] [pid 521505:tid 521702] [client 158.23.147.79:40005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/file88.php"] [unique_id "apPlw28byYE0iXl--K5ojwAAA2E"]
[Sun Aug 30 03:11:47.513244 2026] [security2:error] [pid 521505:tid 521635] [client 20.220.10.235:24648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/blnux.php"] [unique_id "apPlw28byYE0iXl--K5okQAAAx4"]
[Sun Aug 30 03:11:47.519516 2026] [security2:error] [pid 521505:tid 521679] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/crm/.env"] [unique_id "apPlw28byYE0iXl--K5okgAAA0o"]
[Sun Aug 30 03:11:47.520338 2026] [security2:error] [pid 521505:tid 521728] [client 20.104.50.220:16730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/nox.php"] [unique_id "apPlw28byYE0iXl--K5okwAAA3s"]
[Sun Aug 30 03:11:47.575899 2026] [security2:error] [pid 521505:tid 521729] [client 4.205.62.107:17667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/app.default.php"] [unique_id "apPlw28byYE0iXl--K5omAAAA3w"]
[Sun Aug 30 03:11:47.579742 2026] [security2:error] [pid 521505:tid 521652] [client 20.104.50.220:32848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/9index.php"] [unique_id "apPlw28byYE0iXl--K5omgAAAy8"]
[Sun Aug 30 03:11:47.595793 2026] [security2:error] [pid 521505:tid 521717] [client 20.151.200.44:26575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/sf.php"] [unique_id "apPlw28byYE0iXl--K5ongAAA3A"]
[Sun Aug 30 03:11:47.601835 2026] [security2:error] [pid 521505:tid 521751] [client 20.48.160.90:37986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp-admin/css/colors/maro.php"] [unique_id "apPlw28byYE0iXl--K5ooAAAA5I"]
[Sun Aug 30 03:11:47.626531 2026] [security2:error] [pid 521505:tid 521671] [client 20.104.18.15:51080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/222.php"] [unique_id "apPlw28byYE0iXl--K5ooQAAA0I"]
[Sun Aug 30 03:11:47.634791 2026] [security2:error] [pid 521505:tid 521695] [client 20.104.50.220:25428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/biufile.php"] [unique_id "apPlw28byYE0iXl--K5oogAAA1o"]
[Sun Aug 30 03:11:47.641072 2026] [security2:error] [pid 521505:tid 521675] [client 20.197.61.180:12268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/upgrade-temp-backup/pk.php"] [unique_id "apPlw28byYE0iXl--K5oowAAA0Y"]
[Sun Aug 30 03:11:47.654200 2026] [security2:error] [pid 521505:tid 521722] [client 20.220.10.235:24646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/attack.php"] [unique_id "apPlw28byYE0iXl--K5opAAAA3U"]
[Sun Aug 30 03:11:47.664390 2026] [authz_core:error] [pid 521505:tid 521715] [client 66.249.66.65:58349] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:47.664661 2026] [authz_core:error] [pid 521505:tid 521715] [client 66.249.66.65:58349] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:47.683190 2026] [security2:error] [pid 521505:tid 521721] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/erp/.env"] [unique_id "apPlw28byYE0iXl--K5opgAAA3Q"]
[Sun Aug 30 03:11:47.685898 2026] [security2:error] [pid 521505:tid 521651] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/newsletter/.env"] [unique_id "apPlw28byYE0iXl--K5opwAAAy4"]
[Sun Aug 30 03:11:47.734509 2026] [security2:error] [pid 521505:tid 521682] [client 20.48.251.3:59275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/drykl.php"] [unique_id "apPlw28byYE0iXl--K5oqQAAA00"]
[Sun Aug 30 03:11:47.741386 2026] [authz_core:error] [pid 521505:tid 521690] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:47.741663 2026] [authz_core:error] [pid 521505:tid 521690] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:47.767364 2026] [security2:error] [pid 521505:tid 521653] [client 20.104.50.220:63044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/images/x.php"] [unique_id "apPlw28byYE0iXl--K5oqwAAAzA"]
[Sun Aug 30 03:11:47.786159 2026] [security2:error] [pid 521505:tid 521691] [client 20.48.160.90:61516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp-admin/css/colors/coffee/marijuana.php"] [unique_id "apPlw28byYE0iXl--K5orgAAA1Y"]
[Sun Aug 30 03:11:47.792561 2026] [security2:error] [pid 521505:tid 521677] [client 20.220.10.235:24701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/wk/index.php"] [unique_id "apPlw28byYE0iXl--K5osAAAA0g"]
[Sun Aug 30 03:11:47.805510 2026] [security2:error] [pid 521505:tid 521643] [client 20.104.18.15:31640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/x.php"] [unique_id "apPlw28byYE0iXl--K5osgAAAyY"]
[Sun Aug 30 03:11:47.842571 2026] [security2:error] [pid 521505:tid 521680] [client 20.104.50.220:29155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/ben.php"] [unique_id "apPlw28byYE0iXl--K5oswAAA0s"]
[Sun Aug 30 03:11:47.853266 2026] [security2:error] [pid 521505:tid 521706] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/shop/.env"] [unique_id "apPlw28byYE0iXl--K5otQAAA2U"]
[Sun Aug 30 03:11:47.853586 2026] [security2:error] [pid 521505:tid 521740] [client 143.244.48.3:16587] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "3226online.com"] [uri "/.env"] [unique_id "apPlw28byYE0iXl--K5otgAAA4c"]
[Sun Aug 30 03:11:47.871811 2026] [security2:error] [pid 521505:tid 521685] [client 20.104.50.220:5502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/bypas.php"] [unique_id "apPlw28byYE0iXl--K5ouAAAA1A"]
[Sun Aug 30 03:11:47.885935 2026] [security2:error] [pid 521505:tid 521734] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/ses/.env"] [unique_id "apPlw28byYE0iXl--K5ouwAAA4E"]
[Sun Aug 30 03:11:47.902489 2026] [security2:error] [pid 521505:tid 521639] [client 158.23.147.79:40018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/NewFile.php/"] [unique_id "apPlw28byYE0iXl--K5ovwAAAyI"]
[Sun Aug 30 03:11:47.917836 2026] [security2:error] [pid 521505:tid 521750] [client 40.83.93.50:6587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/elp.php"] [unique_id "apPlw28byYE0iXl--K5owQAAA5E"]
[Sun Aug 30 03:11:47.923503 2026] [security2:error] [pid 521505:tid 521635] [client 20.48.160.90:61443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp-admin/css/colors/coffee/mari.php"] [unique_id "apPlw28byYE0iXl--K5owgAAAx4"]
[Sun Aug 30 03:11:47.925640 2026] [security2:error] [pid 521505:tid 521699] [client 20.220.10.235:24678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/dehnl.php"] [unique_id "apPlw28byYE0iXl--K5owwAAA14"]
[Sun Aug 30 03:11:47.930964 2026] [security2:error] [pid 521505:tid 521733] [client 4.205.62.107:15960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/infos.php"] [unique_id "apPlw28byYE0iXl--K5oxAAAA4A"]
[Sun Aug 30 03:11:47.959651 2026] [security2:error] [pid 521505:tid 521745] [client 20.104.50.220:56713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/7index.php"] [unique_id "apPlw28byYE0iXl--K5oyAAAA4w"]
[Sun Aug 30 03:11:47.962691 2026] [security2:error] [pid 521505:tid 521747] [client 20.48.251.3:36894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/xa.php"] [unique_id "apPlw28byYE0iXl--K5oyQAAA44"]
[Sun Aug 30 03:11:47.998181 2026] [authz_core:error] [pid 521505:tid 521652] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory29
[Sun Aug 30 03:11:47.998448 2026] [authz_core:error] [pid 521505:tid 521652] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory29
[Sun Aug 30 03:11:48.003207 2026] [authz_core:error] [pid 521505:tid 521703] [client 66.249.66.72:53226] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:48.003471 2026] [authz_core:error] [pid 521505:tid 521703] [client 66.249.66.72:53226] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:48.013218 2026] [security2:error] [pid 521505:tid 521672] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/store/.env"] [unique_id "apPlxG8byYE0iXl--K5o0gAAA0M"]
[Sun Aug 30 03:11:48.035184 2026] [security2:error] [pid 521505:tid 521751] [client 20.104.18.15:18354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/wp-admin/w.php"] [unique_id "apPlxG8byYE0iXl--K5o1wAAA5I"]
[Sun Aug 30 03:11:48.039363 2026] [security2:error] [pid 521505:tid 521671] [client 4.205.62.107:36202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/umgebung.php"] [unique_id "apPlxG8byYE0iXl--K5o2QAAA0I"]
[Sun Aug 30 03:11:48.055553 2026] [security2:error] [pid 521505:tid 521744] [client 20.104.50.220:31549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/jp.php"] [unique_id "apPlxG8byYE0iXl--K5o3QAAA4s"]
[Sun Aug 30 03:11:48.060747 2026] [security2:error] [pid 521505:tid 521722] [client 20.220.10.235:24667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/png.php"] [unique_id "apPlxG8byYE0iXl--K5o4AAAA3U"]
[Sun Aug 30 03:11:48.086611 2026] [security2:error] [pid 521505:tid 521719] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/sendgrid/.env"] [unique_id "apPlxG8byYE0iXl--K5o5wAAA3I"]
[Sun Aug 30 03:11:48.086790 2026] [security2:error] [pid 521505:tid 521713] [client 20.48.160.90:37632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp-includes/images/crystal/option.php"] [unique_id "apPlxG8byYE0iXl--K5o6AAAA2w"]
[Sun Aug 30 03:11:48.093362 2026] [authz_core:error] [pid 521505:tid 521669] [client 66.249.66.38:61805] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:48.093634 2026] [authz_core:error] [pid 521505:tid 521669] [client 66.249.66.38:61805] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:48.106931 2026] [security2:error] [pid 521505:tid 521737] [client 20.151.200.44:62998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/wp-login.php"] [unique_id "apPlxG8byYE0iXl--K5o4wAAA4Q"]
[Sun Aug 30 03:11:48.110436 2026] [security2:error] [pid 521505:tid 521762] [client 20.104.18.15:22479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/tnglzqmv.php"] [unique_id "apPlxG8byYE0iXl--K5o6gAAA50"]
[Sun Aug 30 03:11:48.169350 2026] [authz_core:error] [pid 521505:tid 521680] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:48.169747 2026] [authz_core:error] [pid 521505:tid 521680] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:48.178047 2026] [security2:error] [pid 521505:tid 521706] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/saas/.env"] [unique_id "apPlxG8byYE0iXl--K5o8wAAA2U"]
[Sun Aug 30 03:11:48.192078 2026] [security2:error] [pid 521505:tid 521685] [client 20.220.10.235:24650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/txets.php"] [unique_id "apPlxG8byYE0iXl--K5o9AAAA1A"]
[Sun Aug 30 03:11:48.224802 2026] [security2:error] [pid 521505:tid 521686] [client 20.48.251.3:59469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/app_local.php"] [unique_id "apPlxG8byYE0iXl--K5o-AAAA1E"]
[Sun Aug 30 03:11:48.249749 2026] [security2:error] [pid 521505:tid 521738] [client 20.104.18.15:16948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/os.php"] [unique_id "apPlxG8byYE0iXl--K5o_QAAA4U"]
[Sun Aug 30 03:11:48.286053 2026] [security2:error] [pid 521505:tid 521699] [client 20.48.251.3:64269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/wp-admin/sc.php"] [unique_id "apPlxG8byYE0iXl--K5o_wAAA14"]
[Sun Aug 30 03:11:48.287605 2026] [security2:error] [pid 521505:tid 521733] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/sparkpost/.env"] [unique_id "apPlxG8byYE0iXl--K5pAAAAA4A"]
[Sun Aug 30 03:11:48.292568 2026] [security2:error] [pid 521505:tid 521696] [client 68.155.159.216:52289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/nf_tracking.php"] [unique_id "apPlxG8byYE0iXl--K5pAgAAA1s"]
[Sun Aug 30 03:11:48.311595 2026] [security2:error] [pid 521505:tid 521760] [client 20.48.250.41:11155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/tfm.php"] [unique_id "apPlxG8byYE0iXl--K5pAwAAA5s"]
[Sun Aug 30 03:11:48.315809 2026] [security2:error] [pid 521505:tid 521679] [client 20.48.160.90:61545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp-includes/pomo/xxx.php"] [unique_id "apPlxG8byYE0iXl--K5pBAAAA0o"]
[Sun Aug 30 03:11:48.316920 2026] [security2:error] [pid 521505:tid 521690] [client 4.205.62.107:25761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apPlxG8byYE0iXl--K5pBQAAA1U"]
[Sun Aug 30 03:11:48.339213 2026] [security2:error] [pid 521505:tid 521725] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/client/.env"] [unique_id "apPlxG8byYE0iXl--K5pBwAAA3g"]
[Sun Aug 30 03:11:48.345078 2026] [authz_core:error] [pid 521505:tid 521745] [client 66.249.66.68:59052] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:48.345381 2026] [authz_core:error] [pid 521505:tid 521745] [client 66.249.66.68:59052] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:48.349324 2026] [security2:error] [pid 521505:tid 521642] [client 20.197.61.180:3789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/upgrade-temp-backup/plugins/security.php"] [unique_id "apPlxG8byYE0iXl--K5pCwAAAyU"]
[Sun Aug 30 03:11:48.350881 2026] [security2:error] [pid 521505:tid 521732] [client 20.220.10.235:24781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/wp-login.php"] [unique_id "apPlxG8byYE0iXl--K5pDAAAA38"]
[Sun Aug 30 03:11:48.425951 2026] [security2:error] [pid 521505:tid 521707] [client 40.83.93.50:6353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/options-reading.php"] [unique_id "apPlxG8byYE0iXl--K5pEgAAA2Y"]
[Sun Aug 30 03:11:48.446565 2026] [security2:error] [pid 521505:tid 521727] [client 20.104.18.15:1984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/classwithtostring.php"] [unique_id "apPlxG8byYE0iXl--K5pHAAAA3o"]
[Sun Aug 30 03:11:48.449327 2026] [authz_core:error] [pid 521505:tid 521668] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory24
[Sun Aug 30 03:11:48.449791 2026] [authz_core:error] [pid 521505:tid 521668] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory24
[Sun Aug 30 03:11:48.461554 2026] [security2:error] [pid 521505:tid 521637] [client 20.48.160.90:61527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/650.php"] [unique_id "apPlxG8byYE0iXl--K5pIAAAAyA"]
[Sun Aug 30 03:11:48.464902 2026] [security2:error] [pid 521505:tid 521651] [client 20.104.50.220:62236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/file15.php"] [unique_id "apPlxG8byYE0iXl--K5pIQAAAy4"]
[Sun Aug 30 03:11:48.466324 2026] [security2:error] [pid 521505:tid 521754] [client 47.128.61.173:28106] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.hotelgaleriashn.com"] [uri "/"] [unique_id "apPlxG8byYE0iXl--K5pIgAAA5U"]
[Sun Aug 30 03:11:48.467210 2026] [security2:error] [pid 521505:tid 521705] [client 20.151.200.44:41733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/wp-ver.php"] [unique_id "apPlxG8byYE0iXl--K5pIwAAA2Q"]
[Sun Aug 30 03:11:48.479194 2026] [security2:error] [pid 521505:tid 521636] [client 20.220.10.235:24680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/wp-access.php"] [unique_id "apPlxG8byYE0iXl--K5pJwAAAx8"]
[Sun Aug 30 03:11:48.487123 2026] [security2:error] [pid 521505:tid 521670] [client 158.23.184.117:19621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/bgymj.php"] [unique_id "apPlxG8byYE0iXl--K5pKAAAA0E"]
[Sun Aug 30 03:11:48.489282 2026] [security2:error] [pid 521505:tid 521726] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/postmark/.env"] [unique_id "apPlxG8byYE0iXl--K5pKQAAA3k"]
[Sun Aug 30 03:11:48.499398 2026] [security2:error] [pid 521505:tid 521653] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/project/.env"] [unique_id "apPlxG8byYE0iXl--K5pKgAAAzA"]
[Sun Aug 30 03:11:48.537060 2026] [security2:error] [pid 521505:tid 521737] [client 158.23.184.117:19726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/bk/index.php"] [unique_id "apPlxG8byYE0iXl--K5pLgAAA4Q"]
[Sun Aug 30 03:11:48.583408 2026] [security2:error] [pid 521505:tid 521663] [client 4.205.62.107:52806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/asa.php"] [unique_id "apPlxG8byYE0iXl--K5pNAAAAzo"]
[Sun Aug 30 03:11:48.583409 2026] [security2:error] [pid 521505:tid 521758] [client 157.90.155.240:34652] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.cravegoldcoast.com.au"] [uri "/wp-content/endurance-page-cache/_index.html"] [unique_id "apPlxG8byYE0iXl--K5pMAAAA5k"], referer: http://www.cravegoldcoast.com.au/
[Sun Aug 30 03:11:48.608691 2026] [security2:error] [pid 521505:tid 521658] [client 20.220.10.235:24683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/wp-content/admin.php"] [unique_id "apPlxG8byYE0iXl--K5pOAAAAzU"]
[Sun Aug 30 03:11:48.627262 2026] [security2:error] [pid 521505:tid 521694] [client 20.48.160.90:61493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/nakrip.php"] [unique_id "apPlxG8byYE0iXl--K5pOQAAA1k"]
[Sun Aug 30 03:11:48.646214 2026] [security2:error] [pid 521505:tid 521645] [client 20.104.50.220:16689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/file48.php"] [unique_id "apPlxG8byYE0iXl--K5pOgAAAyg"]
[Sun Aug 30 03:11:48.659422 2026] [security2:error] [pid 521505:tid 521739] [client 158.23.147.79:40051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/dropdown.php"] [unique_id "apPlxG8byYE0iXl--K5pOwAAA4Y"]
[Sun Aug 30 03:11:48.661495 2026] [security2:error] [pid 521505:tid 521702] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/admin-panel/.env"] [unique_id "apPlxG8byYE0iXl--K5pPAAAA2E"]
[Sun Aug 30 03:11:48.677537 2026] [security2:error] [pid 521505:tid 521738] [client 158.23.184.117:19636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/bootstrap.php"] [unique_id "apPlxG8byYE0iXl--K5pPgAAA4U"]
[Sun Aug 30 03:11:48.682799 2026] [authz_core:error] [pid 521505:tid 521728] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:48.683070 2026] [authz_core:error] [pid 521505:tid 521728] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:48.690052 2026] [security2:error] [pid 521505:tid 521760] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/mailgun/.env"] [unique_id "apPlxG8byYE0iXl--K5pQAAAA5s"]
[Sun Aug 30 03:11:48.693402 2026] [security2:error] [pid 521505:tid 521747] [client 20.48.250.41:11009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/Geforce.php"] [unique_id "apPlxG8byYE0iXl--K5pQQAAA44"]
[Sun Aug 30 03:11:48.717523 2026] [security2:error] [pid 521505:tid 521664] [client 20.104.50.220:33171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/index4.php"] [unique_id "apPlxG8byYE0iXl--K5pRAAAAzs"]
[Sun Aug 30 03:11:48.727538 2026] [security2:error] [pid 521505:tid 521732] [client 4.205.62.107:16782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/app_local.php"] [unique_id "apPlxG8byYE0iXl--K5pRgAAA38"]
[Sun Aug 30 03:11:48.738639 2026] [security2:error] [pid 521505:tid 521680] [client 20.220.10.235:24775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/log.php"] [unique_id "apPlxG8byYE0iXl--K5pRwAAA0s"]
[Sun Aug 30 03:11:48.757972 2026] [security2:error] [pid 521505:tid 521665] [client 20.104.49.130:60629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/f35.update.php"] [unique_id "apPlxG8byYE0iXl--K5pSQAAAzw"]
[Sun Aug 30 03:11:48.762886 2026] [security2:error] [pid 521505:tid 521684] [client 20.48.160.90:61489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp-includes/interactivity-api/flower.php"] [unique_id "apPlxG8byYE0iXl--K5pSgAAA08"]
[Sun Aug 30 03:11:48.768730 2026] [security2:error] [pid 521505:tid 521723] [client 20.104.50.220:24832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/wpconf.php"] [unique_id "apPlxG8byYE0iXl--K5pSwAAA3Y"]
[Sun Aug 30 03:11:48.801080 2026] [security2:error] [pid 521505:tid 521650] [client 20.104.18.15:51158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/key.php"] [unique_id "apPlxG8byYE0iXl--K5pUQAAAy0"]
[Sun Aug 30 03:11:48.819037 2026] [security2:error] [pid 521505:tid 521703] [client 158.23.184.117:19739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/bs1.php"] [unique_id "apPlxG8byYE0iXl--K5pVQAAA2I"]
[Sun Aug 30 03:11:48.821630 2026] [security2:error] [pid 521505:tid 521637] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/control-panel/.env"] [unique_id "apPlxG8byYE0iXl--K5pVgAAAyA"]
[Sun Aug 30 03:11:48.856798 2026] [authz_core:error] [pid 521505:tid 521741] [client 66.249.66.202:39418] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:48.857105 2026] [authz_core:error] [pid 521505:tid 521741] [client 66.249.66.202:39418] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:48.869697 2026] [security2:error] [pid 521505:tid 521688] [client 20.220.10.235:24681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/xwpg.php"] [unique_id "apPlxG8byYE0iXl--K5pXQAAA1M"]
[Sun Aug 30 03:11:48.880413 2026] [security2:error] [pid 521505:tid 521677] [client 20.48.251.3:52843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/rpk.php"] [unique_id "apPlxG8byYE0iXl--K5pYQAAA0g"]
[Sun Aug 30 03:11:48.895697 2026] [security2:error] [pid 521505:tid 521659] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/mandrill/.env"] [unique_id "apPlxG8byYE0iXl--K5pYwAAAzY"]
[Sun Aug 30 03:11:48.898987 2026] [security2:error] [pid 521505:tid 521715] [client 20.48.160.90:61563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/xcc.php"] [unique_id "apPlxG8byYE0iXl--K5pZwAAA24"]
[Sun Aug 30 03:11:48.901844 2026] [security2:error] [pid 521505:tid 521737] [client 20.48.250.41:11106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/click.php"] [unique_id "apPlxG8byYE0iXl--K5paAAAA4Q"]
[Sun Aug 30 03:11:48.903139 2026] [authz_core:error] [pid 521505:tid 521640] [client 66.249.66.35:59842] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:48.903426 2026] [authz_core:error] [pid 521505:tid 521640] [client 66.249.66.35:59842] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:48.924571 2026] [security2:error] [pid 521505:tid 521730] [client 20.104.50.220:52848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/images/leaf.php"] [unique_id "apPlxG8byYE0iXl--K5paQAAA30"]
[Sun Aug 30 03:11:48.949950 2026] [authz_core:error] [pid 521505:tid 521709] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory22
[Sun Aug 30 03:11:48.950242 2026] [authz_core:error] [pid 521505:tid 521709] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory22
[Sun Aug 30 03:11:48.951013 2026] [security2:error] [pid 521505:tid 521749] [client 20.104.18.15:31697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apPlxG8byYE0iXl--K5pbQAAA5A"]
[Sun Aug 30 03:11:48.961364 2026] [security2:error] [pid 521505:tid 521718] [client 158.23.184.117:19718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/bthil.php"] [unique_id "apPlxG8byYE0iXl--K5pcAAAA3E"]
[Sun Aug 30 03:11:48.974226 2026] [core:alert] [pid 521505:tid 521691] [client 192.232.43.194:48462] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:11:48.981868 2026] [security2:error] [pid 521505:tid 521739] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/user-panel/.env"] [unique_id "apPlxG8byYE0iXl--K5pdAAAA4Y"]
[Sun Aug 30 03:11:48.999051 2026] [security2:error] [pid 521505:tid 521639] [client 20.104.50.220:63041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/9191.php"] [unique_id "apPlxG8byYE0iXl--K5pdgAAAyI"]
[Sun Aug 30 03:11:49.001427 2026] [security2:error] [pid 521505:tid 521699] [client 20.220.10.235:24778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/sxxb.php"] [unique_id "apPlxW8byYE0iXl--K5pdwAAA14"]
[Sun Aug 30 03:11:49.009696 2026] [security2:error] [pid 521505:tid 521738] [client 20.104.50.220:5785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/ucen.php"] [unique_id "apPlxW8byYE0iXl--K5peQAAA4U"]
[Sun Aug 30 03:11:49.034397 2026] [security2:error] [pid 521505:tid 521652] [client 20.48.160.90:37988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp-includes/Text/Diff/Engine/aaa.php"] [unique_id "apPlxW8byYE0iXl--K5pewAAAy8"]
[Sun Aug 30 03:11:49.049166 2026] [security2:error] [pid 521505:tid 521656] [client 20.48.250.41:11057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/ms.php"] [unique_id "apPlxW8byYE0iXl--K5pggAAAzM"]
[Sun Aug 30 03:11:49.059743 2026] [security2:error] [pid 521505:tid 521673] [client 40.83.93.50:6360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/db.php"] [unique_id "apPlxW8byYE0iXl--K5phQAAA0Q"]
[Sun Aug 30 03:11:49.082194 2026] [security2:error] [pid 521505:tid 521753] [client 20.197.61.180:3209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/upgrade-temp-backup/plugins/users.php"] [unique_id "apPlxW8byYE0iXl--K5piwAAA5Q"]
[Sun Aug 30 03:11:49.085959 2026] [security2:error] [pid 521505:tid 521705] [client 4.205.62.107:15998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/env.php"] [unique_id "apPlxW8byYE0iXl--K5pjQAAA2Q"]
[Sun Aug 30 03:11:49.096735 2026] [security2:error] [pid 521505:tid 521744] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/mailjet/.env"] [unique_id "apPlxW8byYE0iXl--K5pjgAAA4s"]
[Sun Aug 30 03:11:49.102360 2026] [security2:error] [pid 521505:tid 521665] [client 158.23.184.117:19586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/buy.php"] [unique_id "apPlxW8byYE0iXl--K5pjwAAAzw"]
[Sun Aug 30 03:11:49.110927 2026] [security2:error] [pid 521505:tid 521649] [client 20.48.251.3:36825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/ws61.php"] [unique_id "apPlxW8byYE0iXl--K5pkAAAAyw"]
[Sun Aug 30 03:11:49.129575 2026] [security2:error] [pid 521505:tid 521713] [client 20.220.10.235:24669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/dx.php"] [unique_id "apPlxW8byYE0iXl--K5pkgAAA2w"]
[Sun Aug 30 03:11:49.130894 2026] [security2:error] [pid 521505:tid 521729] [client 20.104.50.220:51571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/8index.php"] [unique_id "apPlxW8byYE0iXl--K5pkwAAA3w"]
[Sun Aug 30 03:11:49.138820 2026] [security2:error] [pid 521505:tid 521757] [client 20.104.49.130:57606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/wp-good.php"] [unique_id "apPlxW8byYE0iXl--K5plQAAA5g"]
[Sun Aug 30 03:11:49.141785 2026] [security2:error] [pid 521505:tid 521670] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/node/.env"] [unique_id "apPlxW8byYE0iXl--K5plgAAA0E"]
[Sun Aug 30 03:11:49.166967 2026] [security2:error] [pid 521505:tid 521659] [client 20.48.160.90:61538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp-includes/style-engine/gecko-new.php"] [unique_id "apPlxW8byYE0iXl--K5pmwAAAzY"]
[Sun Aug 30 03:11:49.180449 2026] [security2:error] [pid 521505:tid 521638] [client 20.104.18.15:18343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/wp-content/k.php"] [unique_id "apPlxW8byYE0iXl--K5pnQAAAyE"]
[Sun Aug 30 03:11:49.198014 2026] [authz_core:error] [pid 521505:tid 521730] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:49.198294 2026] [authz_core:error] [pid 521505:tid 521730] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:49.198416 2026] [security2:error] [pid 521505:tid 521663] [client 20.104.49.130:53752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/xwpg.php"] [unique_id "apPlxW8byYE0iXl--K5pnwAAAzo"]
[Sun Aug 30 03:11:49.204537 2026] [security2:error] [pid 521505:tid 521710] [client 20.104.50.220:31220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/f35.php"] [unique_id "apPlxW8byYE0iXl--K5poAAAA2k"]
[Sun Aug 30 03:11:49.219157 2026] [security2:error] [pid 521505:tid 521700] [client 20.48.250.41:11083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/zxekqlxb.php"] [unique_id "apPlxW8byYE0iXl--K5powAAA18"]
[Sun Aug 30 03:11:49.244904 2026] [security2:error] [pid 521505:tid 521758] [client 158.23.184.117:19630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/byp.php"] [unique_id "apPlxW8byYE0iXl--K5pqgAAA5k"]
[Sun Aug 30 03:11:49.256672 2026] [security2:error] [pid 521505:tid 521698] [client 20.220.10.235:24692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPlxW8byYE0iXl--K5prQAAA10"]
[Sun Aug 30 03:11:49.259821 2026] [security2:error] [pid 521505:tid 521639] [client 20.151.200.44:46049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/wefile.php"] [unique_id "apPlxW8byYE0iXl--K5prgAAAyI"]
[Sun Aug 30 03:11:49.265060 2026] [security2:error] [pid 521505:tid 521733] [client 158.23.147.79:60166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-mail.php"] [unique_id "apPlxW8byYE0iXl--K5prwAAA4A"]
[Sun Aug 30 03:11:49.268550 2026] [security2:error] [pid 521505:tid 521760] [client 20.104.18.15:22527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/wefile.php"] [unique_id "apPlxW8byYE0iXl--K5psAAAA5s"]
[Sun Aug 30 03:11:49.270592 2026] [security2:error] [pid 521505:tid 521745] [client 4.205.62.107:35998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/old_phpinfo.php"] [unique_id "apPlxW8byYE0iXl--K5psQAAA4w"]
[Sun Aug 30 03:11:49.297624 2026] [security2:error] [pid 521505:tid 521736] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/brevo/.env"] [unique_id "apPlxW8byYE0iXl--K5psgAAA4M"]
[Sun Aug 30 03:11:49.303458 2026] [security2:error] [pid 521505:tid 521747] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/express/.env"] [unique_id "apPlxW8byYE0iXl--K5pswAAA44"]
[Sun Aug 30 03:11:49.309315 2026] [security2:error] [pid 521505:tid 521652] [client 20.48.160.90:37965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp-settings.php"] [unique_id "apPlxW8byYE0iXl--K5ptAAAAy8"]
[Sun Aug 30 03:11:49.359913 2026] [security2:error] [pid 521505:tid 521725] [client 20.48.251.3:52272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/ws62.php"] [unique_id "apPlxW8byYE0iXl--K5puwAAA3g"]
[Sun Aug 30 03:11:49.386630 2026] [security2:error] [pid 521505:tid 521759] [client 158.23.184.117:19609] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webmail.watertownchessclub.com"] [uri "/c99.php"] [unique_id "apPlxW8byYE0iXl--K5pvQAAA5o"]
[Sun Aug 30 03:11:49.393050 2026] [security2:error] [pid 521505:tid 521717] [client 158.23.147.79:21459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/.well-known/index.php"] [unique_id "apPlxW8byYE0iXl--K5pvgAAA3A"]
[Sun Aug 30 03:11:49.396352 2026] [security2:error] [pid 521505:tid 521753] [client 20.104.18.15:17023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/htio.php"] [unique_id "apPlxW8byYE0iXl--K5pwAAAA5Q"]
[Sun Aug 30 03:11:49.409310 2026] [security2:error] [pid 521505:tid 521751] [client 20.48.250.41:10972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/init.php"] [unique_id "apPlxW8byYE0iXl--K5pwwAAA5I"]
[Sun Aug 30 03:11:49.413280 2026] [security2:error] [pid 521505:tid 521719] [client 20.151.200.44:26597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/4e.php"] [unique_id "apPlxW8byYE0iXl--K5pxQAAA3I"]
[Sun Aug 30 03:11:49.416000 2026] [authz_core:error] [pid 521505:tid 521693] [client 66.249.66.64:54232] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:49.416270 2026] [authz_core:error] [pid 521505:tid 521693] [client 66.249.66.64:54232] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:49.418946 2026] [security2:error] [pid 521505:tid 521729] [client 20.220.10.235:24670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/xda.php"] [unique_id "apPlxW8byYE0iXl--K5pyQAAA3w"]
[Sun Aug 30 03:11:49.442709 2026] [security2:error] [pid 521505:tid 521683] [client 20.48.160.90:61461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp-signup.php"] [unique_id "apPlxW8byYE0iXl--K5p0QAAA04"]
[Sun Aug 30 03:11:49.455027 2026] [authz_core:error] [pid 521505:tid 521685] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory12
[Sun Aug 30 03:11:49.455314 2026] [authz_core:error] [pid 521505:tid 521685] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory12
[Sun Aug 30 03:11:49.463053 2026] [security2:error] [pid 521505:tid 521710] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/next/.env"] [unique_id "apPlxW8byYE0iXl--K5p2AAAA2k"]
[Sun Aug 30 03:11:49.479481 2026] [security2:error] [pid 521505:tid 521642] [client 68.155.159.216:52331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wzy.php"] [unique_id "apPlxW8byYE0iXl--K5p3AAAAyU"]
[Sun Aug 30 03:11:49.485144 2026] [authz_core:error] [pid 521505:tid 521658] [client 66.249.66.72:43584] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:49.485435 2026] [authz_core:error] [pid 521505:tid 521658] [client 66.249.66.72:43584] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:49.489592 2026] [security2:error] [pid 521505:tid 521586] [remote 185.93.89.167:24307] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tw.mariegronley.com"] [uri "/.env"] [unique_id "apPlxW8byYE0iXl--K5p3QADWVA"]
[Sun Aug 30 03:11:49.498204 2026] [security2:error] [pid 521505:tid 521758] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/transactional/.env"] [unique_id "apPlxW8byYE0iXl--K5p3wAAA5k"]
[Sun Aug 30 03:11:49.528491 2026] [security2:error] [pid 521505:tid 521743] [client 158.23.184.117:19642] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webmail.watertownchessclub.com"] [uri "/c99.php"] [unique_id "apPlxW8byYE0iXl--K5p6AAAA4o"]
[Sun Aug 30 03:11:49.534806 2026] [security2:error] [pid 521505:tid 521588] [remote 185.93.89.167:26309] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "piwik.mariegronley.com"] [uri "/.env"] [unique_id "apPlxW8byYE0iXl--K5p6QADgFI"]
[Sun Aug 30 03:11:49.535056 2026] [security2:error] [pid 521505:tid 521760] [client 4.205.62.107:25679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/hochladen.form.php"] [unique_id "apPlxW8byYE0iXl--K5p6wAAA5s"]
[Sun Aug 30 03:11:49.539518 2026] [security2:error] [pid 521505:tid 521679] [client 20.48.250.41:11145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/term.php"] [unique_id "apPlxW8byYE0iXl--K5p7QAAA0o"]
[Sun Aug 30 03:11:49.540230 2026] [security2:error] [pid 521505:tid 521594] [remote 185.93.89.167:64215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/.env"] [unique_id "apPlxW8byYE0iXl--K5p7AADVFg"]
[Sun Aug 30 03:11:49.541446 2026] [security2:error] [pid 521505:tid 521690] [client 20.104.49.130:48008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/002.php"] [unique_id "apPlxW8byYE0iXl--K5p7gAAA1U"]
[Sun Aug 30 03:11:49.544860 2026] [security2:error] [pid 521505:tid 521747] [client 20.220.10.235:24679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/wp-admin/js/index.php"] [unique_id "apPlxW8byYE0iXl--K5p7wAAA44"]
[Sun Aug 30 03:11:49.545871 2026] [security2:error] [pid 521505:tid 521652] [client 20.48.251.3:54752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/debug.php"] [unique_id "apPlxW8byYE0iXl--K5p8AAAAy8"]
[Sun Aug 30 03:11:49.570628 2026] [security2:error] [pid 521505:tid 521591] [remote 185.93.89.167:36485] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shopping.mariegronley.com"] [uri "/.env"] [unique_id "apPlxW8byYE0iXl--K5p9AADc1U"]
[Sun Aug 30 03:11:49.574153 2026] [security2:error] [pid 521505:tid 521650] [client 20.48.160.90:61534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp-conffg.php"] [unique_id "apPlxW8byYE0iXl--K5p-AAAAy0"]
[Sun Aug 30 03:11:49.575941 2026] [security2:error] [pid 521505:tid 521728] [client 158.23.147.79:39940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-content/themes/too.php"] [unique_id "apPlxW8byYE0iXl--K5p-QAAA3s"]
[Sun Aug 30 03:11:49.587576 2026] [security2:error] [pid 521505:tid 521636] [client 40.83.93.50:10712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/server.php"] [unique_id "apPlxW8byYE0iXl--K5p_wAAAx8"]
[Sun Aug 30 03:11:49.602260 2026] [security2:error] [pid 521505:tid 521713] [client 20.104.18.15:1985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPlxW8byYE0iXl--K5qBAAAA2w"]
[Sun Aug 30 03:11:49.620786 2026] [security2:error] [pid 521505:tid 521653] [client 20.104.50.220:62268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/333.php"] [unique_id "apPlxW8byYE0iXl--K5qBgAAAzA"]
[Sun Aug 30 03:11:49.624096 2026] [security2:error] [pid 521505:tid 521601] [remote 185.93.89.167:24307] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tw.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxW8byYE0iXl--K5qBwADTl8"]
[Sun Aug 30 03:11:49.624267 2026] [security2:error] [pid 521505:tid 521715] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/nuxt/.env"] [unique_id "apPlxW8byYE0iXl--K5qCAAAA24"]
[Sun Aug 30 03:11:49.626268 2026] [security2:error] [pid 521505:tid 521602] [remote 185.93.89.167:62859] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mailgw.mariegronley.com"] [uri "/.env"] [unique_id "apPlxW8byYE0iXl--K5qCQADnWA"]
[Sun Aug 30 03:11:49.650459 2026] [security2:error] [pid 521505:tid 521605] [remote 185.93.89.167:30871] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pro.mariegronley.com"] [uri "/.env"] [unique_id "apPlxW8byYE0iXl--K5qCgADTGM"]
[Sun Aug 30 03:11:49.668690 2026] [security2:error] [pid 521505:tid 521659] [client 158.23.184.117:19740] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webmail.watertownchessclub.com"] [uri "/c99.php"] [unique_id "apPlxW8byYE0iXl--K5qDQAAAzY"]
[Sun Aug 30 03:11:49.668827 2026] [security2:error] [pid 521505:tid 521609] [remote 185.93.89.167:26309] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "piwik.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxW8byYE0iXl--K5qDAADf2c"]
[Sun Aug 30 03:11:49.670212 2026] [security2:error] [pid 521505:tid 521603] [remote 185.93.89.167:42909] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "direct.mariegronley.com"] [uri "/.env"] [unique_id "apPlxW8byYE0iXl--K5qDwADSGE"]
[Sun Aug 30 03:11:49.672238 2026] [security2:error] [pid 521505:tid 521749] [client 20.220.10.235:24662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/t00l.php"] [unique_id "apPlxW8byYE0iXl--K5qEAAAA5A"]
[Sun Aug 30 03:11:49.672849 2026] [security2:error] [pid 521505:tid 521692] [client 20.48.250.41:11135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/aaa.php"] [unique_id "apPlxW8byYE0iXl--K5qEQAAA1c"]
[Sun Aug 30 03:11:49.673925 2026] [security2:error] [pid 521505:tid 521604] [remote 185.93.89.167:64215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxW8byYE0iXl--K5qEgADnGI"]
[Sun Aug 30 03:11:49.685755 2026] [security2:error] [pid 521505:tid 521613] [remote 185.93.89.167:59907] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "health.mariegronley.com"] [uri "/.env"] [unique_id "apPlxW8byYE0iXl--K5qGAADP2s"]
[Sun Aug 30 03:11:49.685917 2026] [security2:error] [pid 521505:tid 521612] [remote 185.93.89.167:7437] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images7.mariegronley.com"] [uri "/.env"] [unique_id "apPlxW8byYE0iXl--K5qGQADNGo"]
[Sun Aug 30 03:11:49.686652 2026] [authz_core:error] [pid 521505:tid 521638] [client 66.249.66.73:65130] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:49.686929 2026] [authz_core:error] [pid 521505:tid 521638] [client 66.249.66.73:65130] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:49.698767 2026] [security2:error] [pid 521505:tid 521639] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/bulk/.env"] [unique_id "apPlxW8byYE0iXl--K5qHgAAAyI"]
[Sun Aug 30 03:11:49.699115 2026] [authz_core:error] [pid 521505:tid 521739] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:49.699452 2026] [authz_core:error] [pid 521505:tid 521739] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:49.702870 2026] [security2:error] [pid 521505:tid 521660] [client 20.48.160.90:37980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp-validate.php"] [unique_id "apPlxW8byYE0iXl--K5qIAAAAzc"]
[Sun Aug 30 03:11:49.704505 2026] [security2:error] [pid 521505:tid 521619] [remote 185.93.89.167:36485] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shopping.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxW8byYE0iXl--K5qIgADW3E"]
[Sun Aug 30 03:11:49.717725 2026] [security2:error] [pid 521505:tid 521606] [remote 185.93.89.167:18729] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ntp1.mariegronley.com"] [uri "/.env"] [unique_id "apPlxW8byYE0iXl--K5qIwADgGQ"]
[Sun Aug 30 03:11:49.729826 2026] [security2:error] [pid 521505:tid 521705] [client 4.205.62.107:52822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/radio.php"] [unique_id "apPlxW8byYE0iXl--K5qJAAAA2Q"]
[Sun Aug 30 03:11:49.733213 2026] [security2:error] [pid 521505:tid 521615] [remote 185.93.89.167:41989] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ipfixe.mariegronley.com"] [uri "/.env"] [unique_id "apPlxW8byYE0iXl--K5qJQADVW0"]
[Sun Aug 30 03:11:49.736096 2026] [security2:error] [pid 521505:tid 521616] [remote 185.93.89.167:10145] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "g.mariegronley.com"] [uri "/.env"] [unique_id "apPlxW8byYE0iXl--K5qJwADPG4"]
[Sun Aug 30 03:11:49.736953 2026] [security2:error] [pid 521505:tid 521618] [remote 185.93.89.167:1175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pgsql.mariegronley.com"] [uri "/.env"] [unique_id "apPlxW8byYE0iXl--K5qJgADL3A"]
[Sun Aug 30 03:11:49.742242 2026] [security2:error] [pid 521505:tid 521620] [remote 185.93.89.167:57109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "development.mariegronley.com"] [uri "/.env"] [unique_id "apPlxW8byYE0iXl--K5qKQADJHI"]
[Sun Aug 30 03:11:49.758059 2026] [security2:error] [pid 521505:tid 521622] [remote 185.93.89.167:24307] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tw.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxW8byYE0iXl--K5qKwADcXQ"]
[Sun Aug 30 03:11:49.759823 2026] [security2:error] [pid 521505:tid 521623] [remote 185.93.89.167:62859] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mailgw.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxW8byYE0iXl--K5qLAADI3U"]
[Sun Aug 30 03:11:49.785427 2026] [security2:error] [pid 521505:tid 521626] [remote 185.93.89.167:30871] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pro.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxW8byYE0iXl--K5qLgADmng"]
[Sun Aug 30 03:11:49.787031 2026] [security2:error] [pid 521505:tid 521730] [client 20.197.61.180:3152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/upgrade-temp-backup/plugins/wp-blog-header.php"] [unique_id "apPlxW8byYE0iXl--K5qMQAAA30"]
[Sun Aug 30 03:11:49.787529 2026] [security2:error] [pid 521505:tid 521697] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/nest/.env"] [unique_id "apPlxW8byYE0iXl--K5qMAAAA1w"]
[Sun Aug 30 03:11:49.800667 2026] [security2:error] [pid 521505:tid 521715] [client 20.104.50.220:16747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/info.php"] [unique_id "apPlxW8byYE0iXl--K5qNQAAA24"]
[Sun Aug 30 03:11:49.803003 2026] [security2:error] [pid 521505:tid 521631] [remote 185.93.89.167:26309] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "piwik.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxW8byYE0iXl--K5qNgADUH0"]
[Sun Aug 30 03:11:49.804780 2026] [security2:error] [pid 521505:tid 521629] [remote 185.93.89.167:42909] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "direct.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxW8byYE0iXl--K5qOAADaHs"]
[Sun Aug 30 03:11:49.806180 2026] [security2:error] [pid 521505:tid 521681] [client 20.220.10.235:24676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/ls.php"] [unique_id "apPlxW8byYE0iXl--K5qOQAAA0w"]
[Sun Aug 30 03:11:49.808158 2026] [security2:error] [pid 521505:tid 521625] [remote 185.93.89.167:64215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxW8byYE0iXl--K5qOgADZ3c"]
[Sun Aug 30 03:11:49.810422 2026] [security2:error] [pid 521505:tid 521630] [remote 185.93.89.167:45621] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images8.mariegronley.com"] [uri "/.env"] [unique_id "apPlxW8byYE0iXl--K5qPAADkHw"]
[Sun Aug 30 03:11:49.813735 2026] [security2:error] [pid 521505:tid 521627] [remote 185.93.89.167:48523] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/.env"] [unique_id "apPlxW8byYE0iXl--K5qPgADV3k"]
[Sun Aug 30 03:11:49.820498 2026] [security2:error] [pid 521505:tid 521516] [remote 185.93.89.167:7437] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images7.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxW8byYE0iXl--K5qQAADggo"]
[Sun Aug 30 03:11:49.820501 2026] [security2:error] [pid 521505:tid 521515] [remote 185.93.89.167:59907] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "health.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxW8byYE0iXl--K5qPwADnAk"]
[Sun Aug 30 03:11:49.832042 2026] [security2:error] [pid 521505:tid 521509] [remote 185.93.89.167:47169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "order.mariegronley.com"] [uri "/.env"] [unique_id "apPlxW8byYE0iXl--K5qQwADNAM"]
[Sun Aug 30 03:11:49.834405 2026] [security2:error] [pid 521505:tid 521511] [remote 185.93.89.167:62709] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp3.mariegronley.com"] [uri "/.env"] [unique_id "apPlxW8byYE0iXl--K5qRQADQAU"]
[Sun Aug 30 03:11:49.838709 2026] [security2:error] [pid 521505:tid 521514] [remote 185.93.89.167:36485] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shopping.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxW8byYE0iXl--K5qRgADlQg"]
[Sun Aug 30 03:11:49.839232 2026] [security2:error] [pid 521505:tid 521513] [remote 185.93.89.167:34607] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sports.mariegronley.com"] [uri "/.env"] [unique_id "apPlxW8byYE0iXl--K5qRwADSwc"]
[Sun Aug 30 03:11:49.840270 2026] [security2:error] [pid 521505:tid 521675] [client 20.48.160.90:37958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/700.php"] [unique_id "apPlxW8byYE0iXl--K5qSAAAA0Y"]
[Sun Aug 30 03:11:49.851238 2026] [security2:error] [pid 521505:tid 521506] [remote 185.93.89.167:18729] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ntp1.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxW8byYE0iXl--K5qTAADkQA"]
[Sun Aug 30 03:11:49.866431 2026] [security2:error] [pid 521505:tid 521696] [client 4.205.62.107:16791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/ws62.php"] [unique_id "apPlxW8byYE0iXl--K5qTwAAA1s"]
[Sun Aug 30 03:11:49.868473 2026] [security2:error] [pid 521505:tid 521507] [remote 185.93.89.167:41989] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ipfixe.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxW8byYE0iXl--K5qTgADgQE"]
[Sun Aug 30 03:11:49.869544 2026] [security2:error] [pid 521505:tid 521518] [remote 185.93.89.167:10145] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "g.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxW8byYE0iXl--K5qUQADmww"]
[Sun Aug 30 03:11:49.870061 2026] [security2:error] [pid 521505:tid 521705] [client 20.104.50.220:33538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/index5.php"] [unique_id "apPlxW8byYE0iXl--K5qUgAAA2Q"]
[Sun Aug 30 03:11:49.870490 2026] [security2:error] [pid 521505:tid 521530] [remote 185.93.89.167:1175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pgsql.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxW8byYE0iXl--K5qUwADVBg"]
[Sun Aug 30 03:11:49.875882 2026] [security2:error] [pid 521505:tid 521520] [remote 185.93.89.167:57109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "development.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxW8byYE0iXl--K5qVgADRA4"]
[Sun Aug 30 03:11:49.884180 2026] [security2:error] [pid 521505:tid 521728] [client 20.48.250.41:11019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/xsox.php"] [unique_id "apPlxW8byYE0iXl--K5qWwAAA3s"]
[Sun Aug 30 03:11:49.885797 2026] [authz_core:error] [pid 521505:tid 521707] [client 66.249.66.199:58301] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:49.886248 2026] [authz_core:error] [pid 521505:tid 521707] [client 66.249.66.199:58301] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:49.891866 2026] [security2:error] [pid 521505:tid 521531] [remote 185.93.89.167:31113] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "math.mariegronley.com"] [uri "/.env"] [unique_id "apPlxW8byYE0iXl--K5qYQADYRk"]
[Sun Aug 30 03:11:49.893425 2026] [security2:error] [pid 521505:tid 521533] [remote 185.93.89.167:62859] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mailgw.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxW8byYE0iXl--K5qYwADcxs"]
[Sun Aug 30 03:11:49.899820 2026] [security2:error] [pid 521505:tid 521641] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/aws/.env"] [unique_id "apPlxW8byYE0iXl--K5qZQAAAyQ"]
[Sun Aug 30 03:11:49.902105 2026] [security2:error] [pid 521505:tid 521727] [client 195.178.110.247:16974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mirlabs.com"] [uri "/index.php"] [unique_id "apPlxW8byYE0iXl--K5qZgAAA3o"]
[Sun Aug 30 03:11:49.908311 2026] [security2:error] [pid 521505:tid 521636] [client 20.104.50.220:25408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/ultradybbuks.php"] [unique_id "apPlxW8byYE0iXl--K5qZwAAAx8"]
[Sun Aug 30 03:11:49.920433 2026] [security2:error] [pid 521505:tid 521562] [remote 185.93.89.167:30871] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pro.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxW8byYE0iXl--K5qawADLjg"]
[Sun Aug 30 03:11:49.920569 2026] [security2:error] [pid 521505:tid 521718] [client 158.23.147.79:21451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/radio.php"] [unique_id "apPlxW8byYE0iXl--K5qbQAAA3E"]
[Sun Aug 30 03:11:49.921433 2026] [security2:error] [pid 521505:tid 521661] [client 20.104.49.130:60937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wdfjba.org"] [uri "/ano.php"] [unique_id "apPlxW8byYE0iXl--K5qbgAAAzg"]
[Sun Aug 30 03:11:49.927453 2026] [security2:error] [pid 521505:tid 521564] [remote 185.93.89.167:57009] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "static2.mariegronley.com"] [uri "/.env"] [unique_id "apPlxW8byYE0iXl--K5qcAADTTo"]
[Sun Aug 30 03:11:49.928232 2026] [security2:error] [pid 521505:tid 521538] [remote 185.93.89.167:24307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tw.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxW8byYE0iXl--K5qXwADbSA"]
[Sun Aug 30 03:11:49.936253 2026] [security2:error] [pid 521505:tid 521544] [remote 185.93.89.167:26309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piwik.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxW8byYE0iXl--K5qcgADXCY"]
[Sun Aug 30 03:11:49.939429 2026] [security2:error] [pid 521505:tid 521535] [remote 185.93.89.167:42909] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "direct.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxW8byYE0iXl--K5qcwADgx0"]
[Sun Aug 30 03:11:49.941392 2026] [security2:error] [pid 521505:tid 521643] [client 20.220.10.235:24787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/css/000.php"] [unique_id "apPlxW8byYE0iXl--K5qdQAAAyY"]
[Sun Aug 30 03:11:49.941419 2026] [security2:error] [pid 521505:tid 521566] [remote 185.93.89.167:64215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m1.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxW8byYE0iXl--K5qdgADMDw"]
[Sun Aug 30 03:11:49.944352 2026] [security2:error] [pid 521505:tid 521628] [remote 185.93.89.167:45621] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images8.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxW8byYE0iXl--K5qdwADbno"]
[Sun Aug 30 03:11:49.947177 2026] [security2:error] [pid 521505:tid 521703] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/react/.env"] [unique_id "apPlxW8byYE0iXl--K5qeAAAA2I"]
[Sun Aug 30 03:11:49.947682 2026] [security2:error] [pid 521505:tid 521570] [remote 185.93.89.167:48523] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxW8byYE0iXl--K5qeQADUEA"]
[Sun Aug 30 03:11:49.949382 2026] [authz_core:error] [pid 521505:tid 521671] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory22
[Sun Aug 30 03:11:49.949850 2026] [authz_core:error] [pid 521505:tid 521671] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory22
[Sun Aug 30 03:11:49.954421 2026] [security2:error] [pid 521505:tid 521554] [remote 185.93.89.167:59907] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "health.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxW8byYE0iXl--K5qfAADfzA"]
[Sun Aug 30 03:11:49.954510 2026] [security2:error] [pid 521505:tid 521565] [remote 185.93.89.167:7437] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images7.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxW8byYE0iXl--K5qewADTDs"]
[Sun Aug 30 03:11:49.961779 2026] [security2:error] [pid 521505:tid 521743] [client 20.104.18.15:51196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/chosen.php"] [unique_id "apPlxW8byYE0iXl--K5qgAAAA4o"]
[Sun Aug 30 03:11:49.962344 2026] [security2:error] [pid 521505:tid 521569] [remote 185.93.89.167:42995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns12.mariegronley.com"] [uri "/.env"] [unique_id "apPlxW8byYE0iXl--K5qgQADVz8"]
[Sun Aug 30 03:11:49.965602 2026] [security2:error] [pid 521505:tid 521568] [remote 185.93.89.167:47169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "order.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxW8byYE0iXl--K5qggADJT4"]
[Sun Aug 30 03:11:49.967949 2026] [security2:error] [pid 521505:tid 521543] [remote 185.93.89.167:62709] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp3.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxW8byYE0iXl--K5qhgADPyU"]
[Sun Aug 30 03:11:49.971702 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:36485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shopping.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxW8byYE0iXl--K5qhwADWE0"]
[Sun Aug 30 03:11:49.973243 2026] [security2:error] [pid 521505:tid 521582] [remote 185.93.89.167:34607] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sports.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxW8byYE0iXl--K5qiQADlUw"]
[Sun Aug 30 03:11:49.980972 2026] [security2:error] [pid 521505:tid 521580] [remote 185.93.89.167:8597] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "drupal.mariegronley.com"] [uri "/.env"] [unique_id "apPlxW8byYE0iXl--K5qiwADRko"]
[Sun Aug 30 03:11:49.986594 2026] [security2:error] [pid 521505:tid 521532] [remote 185.93.89.167:18729] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ntp1.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxW8byYE0iXl--K5qjAADkRo"]
[Sun Aug 30 03:11:49.989445 2026] [security2:error] [pid 521505:tid 521679] [client 20.48.160.90:37633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/c4.php"] [unique_id "apPlxW8byYE0iXl--K5qjgAAA0o"]
[Sun Aug 30 03:11:49.994417 2026] [authz_core:error] [pid 521505:tid 521666] [client 66.249.66.33:58901] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:49.994978 2026] [authz_core:error] [pid 521505:tid 521666] [client 66.249.66.33:58901] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:50.002464 2026] [security2:error] [pid 521505:tid 521542] [remote 185.93.89.167:41989] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ipfixe.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5qlAADRCQ"]
[Sun Aug 30 03:11:50.003033 2026] [security2:error] [pid 521505:tid 521537] [remote 185.93.89.167:10145] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "g.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5qlwADex8"]
[Sun Aug 30 03:11:50.003925 2026] [security2:error] [pid 521505:tid 521523] [remote 185.93.89.167:1175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pgsql.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5qmAADLxE"]
[Sun Aug 30 03:11:50.009679 2026] [security2:error] [pid 521505:tid 521557] [remote 185.93.89.167:57109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "development.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5qmgADWjM"]
[Sun Aug 30 03:11:50.015392 2026] [security2:error] [pid 521505:tid 521581] [remote 185.93.89.167:4287] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "php.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5qnQADhUs"]
[Sun Aug 30 03:11:50.023289 2026] [security2:error] [pid 521505:tid 521571] [remote 185.93.89.167:13069] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sc.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5qoQADcUE"]
[Sun Aug 30 03:11:50.025965 2026] [security2:error] [pid 521505:tid 521585] [remote 185.93.89.167:31113] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "math.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5qogADTU8"]
[Sun Aug 30 03:11:50.026368 2026] [security2:error] [pid 521505:tid 521550] [remote 185.93.89.167:2579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "love.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5qowADUSw"]
[Sun Aug 30 03:11:50.026671 2026] [security2:error] [pid 521505:tid 521528] [remote 185.93.89.167:62859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailgw.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5qpQADchY"]
[Sun Aug 30 03:11:50.026874 2026] [security2:error] [pid 521505:tid 521536] [remote 185.93.89.167:29333] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reg.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5qpAADhB4"]
[Sun Aug 30 03:11:50.027294 2026] [security2:error] [pid 521505:tid 521525] [remote 185.93.89.167:53853] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atlas.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5qpgADmhM"]
[Sun Aug 30 03:11:50.036370 2026] [security2:error] [pid 521505:tid 521736] [client 20.48.251.3:52836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/saml.php"] [unique_id "apPlxm8byYE0iXl--K5qqAAAA4M"]
[Sun Aug 30 03:11:50.048350 2026] [security2:error] [pid 521505:tid 521577] [remote 185.93.89.167:5225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "preprod.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5qrwADZ0c"]
[Sun Aug 30 03:11:50.048370 2026] [security2:error] [pid 521505:tid 521522] [remote 185.93.89.167:56175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "press.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5qrgADTBA"]
[Sun Aug 30 03:11:50.049335 2026] [security2:error] [pid 521505:tid 521578] [remote 185.93.89.167:39177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "register.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5qsAADUkg"]
[Sun Aug 30 03:11:50.053974 2026] [security2:error] [pid 521505:tid 521552] [remote 185.93.89.167:30871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pro.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5qsgADVy4"]
[Sun Aug 30 03:11:50.061571 2026] [security2:error] [pid 521505:tid 521579] [remote 185.93.89.167:57009] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "static2.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5qtQADdkk"]
[Sun Aug 30 03:11:50.063443 2026] [security2:error] [pid 521505:tid 521753] [client 195.178.110.247:15284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mirlabs.com"] [uri "/index.php"] [unique_id "apPlxm8byYE0iXl--K5qtwAAA5Q"]
[Sun Aug 30 03:11:50.070329 2026] [security2:error] [pid 521505:tid 521574] [remote 185.93.89.167:7863] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adserver.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5qvQADkUQ"]
[Sun Aug 30 03:11:50.072809 2026] [security2:error] [pid 521505:tid 521526] [remote 185.93.89.167:42909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direct.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5qvwADIhQ"]
[Sun Aug 30 03:11:50.076284 2026] [authz_core:error] [pid 521505:tid 521641] [client 66.249.66.75:44867] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:50.076768 2026] [authz_core:error] [pid 521505:tid 521641] [client 66.249.66.75:44867] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:50.078535 2026] [security2:error] [pid 521505:tid 521560] [remote 185.93.89.167:45621] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images8.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5qwQADZDY"]
[Sun Aug 30 03:11:50.079190 2026] [security2:error] [pid 521505:tid 521673] [client 20.220.10.235:24661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/cy.php"] [unique_id "apPlxm8byYE0iXl--K5qwwAAA0Q"]
[Sun Aug 30 03:11:50.080254 2026] [security2:error] [pid 521505:tid 521728] [client 158.23.184.117:19607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/cache/cache/min.php"] [unique_id "apPlxm8byYE0iXl--K5qxAAAA3s"]
[Sun Aug 30 03:11:50.081535 2026] [security2:error] [pid 521505:tid 521572] [remote 185.93.89.167:48523] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5qxQADYUI"]
[Sun Aug 30 03:11:50.087417 2026] [security2:error] [pid 521505:tid 521744] [client 20.48.250.41:11126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/lkui.php"] [unique_id "apPlxm8byYE0iXl--K5qyAAAA4s"]
[Sun Aug 30 03:11:50.087570 2026] [security2:error] [pid 521505:tid 521563] [remote 185.93.89.167:7437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images7.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5qyQADIDk"]
[Sun Aug 30 03:11:50.087658 2026] [security2:error] [pid 521505:tid 521586] [remote 185.93.89.167:59907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "health.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5qygADc1A"]
[Sun Aug 30 03:11:50.091996 2026] [security2:error] [pid 521505:tid 521587] [remote 185.93.89.167:24213] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "in.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5qywADhlE"]
[Sun Aug 30 03:11:50.096306 2026] [security2:error] [pid 521505:tid 521527] [remote 185.93.89.167:42995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns12.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5qzgADOBU"]
[Sun Aug 30 03:11:50.099022 2026] [security2:error] [pid 521505:tid 521588] [remote 185.93.89.167:47169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "order.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5qzwADbFI"]
[Sun Aug 30 03:11:50.099693 2026] [security2:error] [pid 521505:tid 521718] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/azure/.env"] [unique_id "apPlxm8byYE0iXl--K5q0AAAA3E"]
[Sun Aug 30 03:11:50.102854 2026] [security2:error] [pid 521505:tid 521594] [remote 185.93.89.167:16627] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "education.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5q0gADhFg"]
[Sun Aug 30 03:11:50.102866 2026] [security2:error] [pid 521505:tid 521593] [remote 185.93.89.167:62709] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp3.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5q0QADTVc"]
[Sun Aug 30 03:11:50.106659 2026] [security2:error] [pid 521505:tid 521659] [client 20.104.18.15:31684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-includes/index.php"] [unique_id "apPlxm8byYE0iXl--K5q1QAAAzY"]
[Sun Aug 30 03:11:50.107972 2026] [security2:error] [pid 521505:tid 521595] [remote 185.93.89.167:34607] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sports.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5q1AADl1k"]
[Sun Aug 30 03:11:50.108813 2026] [security2:error] [pid 521505:tid 521683] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/vue/.env"] [unique_id "apPlxm8byYE0iXl--K5q1gAAA04"]
[Sun Aug 30 03:11:50.114917 2026] [security2:error] [pid 521505:tid 521591] [remote 185.93.89.167:8597] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "drupal.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5q1wADmFU"]
[Sun Aug 30 03:11:50.119855 2026] [security2:error] [pid 521505:tid 521592] [remote 185.93.89.167:18729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ntp1.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5q2AADXFY"]
[Sun Aug 30 03:11:50.124430 2026] [security2:error] [pid 521505:tid 521709] [client 20.48.160.90:37646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp-tymanage.php"] [unique_id "apPlxm8byYE0iXl--K5q2gAAA2g"]
[Sun Aug 30 03:11:50.125625 2026] [security2:error] [pid 521505:tid 521599] [remote 185.93.89.167:11075] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "redirect.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5q2wADZ10"]
[Sun Aug 30 03:11:50.127655 2026] [security2:error] [pid 521505:tid 521600] [remote 185.93.89.167:42991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "venus.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5q3AADUl4"]
[Sun Aug 30 03:11:50.135732 2026] [security2:error] [pid 521505:tid 521598] [remote 185.93.89.167:41989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ipfixe.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5q4AADYFw"]
[Sun Aug 30 03:11:50.136103 2026] [security2:error] [pid 521505:tid 521735] [client 40.83.93.50:6357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/favicon.php"] [unique_id "apPlxm8byYE0iXl--K5q4gAAA4I"]
[Sun Aug 30 03:11:50.136141 2026] [security2:error] [pid 521505:tid 521601] [remote 185.93.89.167:10145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5q4QADgF8"]
[Sun Aug 30 03:11:50.137276 2026] [security2:error] [pid 521505:tid 521602] [remote 185.93.89.167:1175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pgsql.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5q4wADQGA"]
[Sun Aug 30 03:11:50.138012 2026] [security2:error] [pid 521505:tid 521605] [remote 185.93.89.167:55243] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oldmail.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5q5QADWWM"]
[Sun Aug 30 03:11:50.142787 2026] [security2:error] [pid 521505:tid 521609] [remote 185.93.89.167:57109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "development.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5q6AADZGc"]
[Sun Aug 30 03:11:50.146989 2026] [security2:error] [pid 521505:tid 521603] [remote 185.93.89.167:36741] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "software.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5q6gADRGE"]
[Sun Aug 30 03:11:50.149757 2026] [security2:error] [pid 521505:tid 521604] [remote 185.93.89.167:4287] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "php.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5q6wADU2I"]
[Sun Aug 30 03:11:50.157288 2026] [security2:error] [pid 521505:tid 521610] [remote 185.93.89.167:13069] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sc.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5q7QADi2g"]
[Sun Aug 30 03:11:50.159922 2026] [security2:error] [pid 521505:tid 521608] [remote 185.93.89.167:31113] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "math.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5q7gADc2Y"]
[Sun Aug 30 03:11:50.160527 2026] [security2:error] [pid 521505:tid 521613] [remote 185.93.89.167:2579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "love.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5q7wADhWs"]
[Sun Aug 30 03:11:50.160568 2026] [security2:error] [pid 521505:tid 521614] [remote 185.93.89.167:29333] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reg.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5q8QADVmw"]
[Sun Aug 30 03:11:50.161557 2026] [security2:error] [pid 521505:tid 521611] [remote 185.93.89.167:53853] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atlas.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5q8gADhmk"]
[Sun Aug 30 03:11:50.163823 2026] [security2:error] [pid 521505:tid 521689] [client 20.104.50.220:6106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/miya.php"] [unique_id "apPlxm8byYE0iXl--K5q9AAAA1Q"]
[Sun Aug 30 03:11:50.182352 2026] [security2:error] [pid 521505:tid 521617] [remote 185.93.89.167:56175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "press.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5q9gADbW8"]
[Sun Aug 30 03:11:50.182414 2026] [security2:error] [pid 521505:tid 521606] [remote 185.93.89.167:5225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "preprod.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5q9wADbGQ"]
[Sun Aug 30 03:11:50.183950 2026] [security2:error] [pid 521505:tid 521615] [remote 185.93.89.167:39177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "register.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5q-AADcW0"]
[Sun Aug 30 03:11:50.195743 2026] [security2:error] [pid 521505:tid 521618] [remote 185.93.89.167:57009] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "static2.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5q-wADmnA"]
[Sun Aug 30 03:11:50.197292 2026] [security2:error] [pid 521505:tid 521644] [client 20.104.50.220:29172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/images/wso.php"] [unique_id "apPlxm8byYE0iXl--K5q_AAAAyc"]
[Sun Aug 30 03:11:50.204323 2026] [security2:error] [pid 521505:tid 521607] [remote 185.93.89.167:7863] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adserver.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5q_gADXGU"]
[Sun Aug 30 03:11:50.204397 2026] [authz_core:error] [pid 521505:tid 521683] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:50.204843 2026] [authz_core:error] [pid 521505:tid 521683] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:50.208777 2026] [security2:error] [pid 521505:tid 521671] [client 20.220.10.235:24655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/admin.php/pindex.php"] [unique_id "apPlxm8byYE0iXl--K5rBAAAA0I"]
[Sun Aug 30 03:11:50.211871 2026] [security2:error] [pid 521505:tid 521623] [remote 185.93.89.167:45621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images8.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5rBgADUnU"]
[Sun Aug 30 03:11:50.215081 2026] [security2:error] [pid 521505:tid 521624] [remote 185.93.89.167:48523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "web01.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5rCAADgnY"]
[Sun Aug 30 03:11:50.221704 2026] [security2:error] [pid 521505:tid 521661] [client 158.23.184.117:19623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/catalogbypass.php"] [unique_id "apPlxm8byYE0iXl--K5rDAAAAzg"]
[Sun Aug 30 03:11:50.222818 2026] [security2:error] [pid 521505:tid 521693] [client 4.205.62.107:16353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/xve22.php"] [unique_id "apPlxm8byYE0iXl--K5rDQAAA1g"]
[Sun Aug 30 03:11:50.225410 2026] [security2:error] [pid 521505:tid 521625] [remote 185.93.89.167:24213] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "in.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5rDgADZHc"]
[Sun Aug 30 03:11:50.229671 2026] [security2:error] [pid 521505:tid 521627] [remote 185.93.89.167:42995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns12.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5rEQADe3k"]
[Sun Aug 30 03:11:50.230759 2026] [security2:error] [pid 521505:tid 521516] [remote 185.93.89.167:37521] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5rEwADUwo"]
[Sun Aug 30 03:11:50.232150 2026] [security2:error] [pid 521505:tid 521515] [remote 185.93.89.167:47169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "order.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5rFAADYQk"]
[Sun Aug 30 03:11:50.235770 2026] [security2:error] [pid 521505:tid 521509] [remote 185.93.89.167:62709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp3.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5rFgADcwM"]
[Sun Aug 30 03:11:50.236411 2026] [security2:error] [pid 521505:tid 521511] [remote 185.93.89.167:16627] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "education.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5rFwADVgU"]
[Sun Aug 30 03:11:50.241181 2026] [security2:error] [pid 521505:tid 521514] [remote 185.93.89.167:34607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sports.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5rGwADhgg"]
[Sun Aug 30 03:11:50.248970 2026] [security2:error] [pid 521505:tid 521633] [remote 185.93.89.167:8597] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "drupal.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5rHwADI38"]
[Sun Aug 30 03:11:50.249711 2026] [security2:error] [pid 521505:tid 521714] [client 20.48.250.41:11188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apPlxm8byYE0iXl--K5rIAAAA20"]
[Sun Aug 30 03:11:50.256294 2026] [security2:error] [pid 521505:tid 521507] [remote 185.93.89.167:3789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vc.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5rIgADTQE"]
[Sun Aug 30 03:11:50.260336 2026] [security2:error] [pid 521505:tid 521518] [remote 185.93.89.167:11075] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "redirect.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5rIwADMgw"]
[Sun Aug 30 03:11:50.260950 2026] [security2:error] [pid 521505:tid 521762] [client 20.104.50.220:62789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/kjtpoad.php"] [unique_id "apPlxm8byYE0iXl--K5rJAAAA50"]
[Sun Aug 30 03:11:50.261412 2026] [security2:error] [pid 521505:tid 521530] [remote 185.93.89.167:42991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "venus.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5rJQADXxg"]
[Sun Aug 30 03:11:50.262794 2026] [security2:error] [pid 521505:tid 521659] [client 20.48.160.90:61556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/ajfto.php"] [unique_id "apPlxm8byYE0iXl--K5rJgAAAzY"]
[Sun Aug 30 03:11:50.270241 2026] [security2:error] [pid 521505:tid 521671] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/angular/.env"] [unique_id "apPlxm8byYE0iXl--K5rKAAAA0I"]
[Sun Aug 30 03:11:50.270457 2026] [security2:error] [pid 521505:tid 521638] [client 20.48.251.3:37182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/xza.php"] [unique_id "apPlxm8byYE0iXl--K5rKwAAAyE"]
[Sun Aug 30 03:11:50.271783 2026] [security2:error] [pid 521505:tid 521531] [remote 185.93.89.167:55243] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oldmail.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5rLAADLRk"]
[Sun Aug 30 03:11:50.280541 2026] [security2:error] [pid 521505:tid 521546] [remote 185.93.89.167:36741] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "software.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5rLgADgCg"]
[Sun Aug 30 03:11:50.283599 2026] [security2:error] [pid 521505:tid 521719] [client 20.104.50.220:51647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/9index.php"] [unique_id "apPlxm8byYE0iXl--K5rMQAAA3I"]
[Sun Aug 30 03:11:50.283819 2026] [security2:error] [pid 521505:tid 521533] [remote 185.93.89.167:4287] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "php.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5rLwADkBs"]
[Sun Aug 30 03:11:50.291150 2026] [security2:error] [pid 521505:tid 521529] [remote 185.93.89.167:13069] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sc.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5rMgADWRc"]
[Sun Aug 30 03:11:50.293270 2026] [security2:error] [pid 521505:tid 521524] [remote 185.93.89.167:31113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "math.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5rMwADZBI"]
[Sun Aug 30 03:11:50.294264 2026] [security2:error] [pid 521505:tid 521555] [remote 185.93.89.167:2579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "love.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5rNAADkTE"]
[Sun Aug 30 03:11:50.294305 2026] [security2:error] [pid 521505:tid 521556] [remote 185.93.89.167:29333] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reg.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5rNQADlDI"]
[Sun Aug 30 03:11:50.295202 2026] [security2:error] [pid 521505:tid 521562] [remote 185.93.89.167:53853] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atlas.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5rNgADljg"]
[Sun Aug 30 03:11:50.299210 2026] [security2:error] [pid 521505:tid 521728] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/gcp/.env"] [unique_id "apPlxm8byYE0iXl--K5rOQAAA3s"]
[Sun Aug 30 03:11:50.301882 2026] [security2:error] [pid 521505:tid 521517] [remote 185.93.89.167:53985] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "img3.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5rOgADbws"]
[Sun Aug 30 03:11:50.316850 2026] [security2:error] [pid 521505:tid 521548] [remote 185.93.89.167:5225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "preprod.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5rPQADbSo"]
[Sun Aug 30 03:11:50.317745 2026] [security2:error] [pid 521505:tid 521544] [remote 185.93.89.167:56175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "press.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5rPAADIyY"]
[Sun Aug 30 03:11:50.318095 2026] [security2:error] [pid 521505:tid 521535] [remote 185.93.89.167:39177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "register.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5rPgADTR0"]
[Sun Aug 30 03:11:50.329041 2026] [security2:error] [pid 521505:tid 521570] [remote 185.93.89.167:57009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "static2.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5rQgADmEA"]
[Sun Aug 30 03:11:50.333198 2026] [security2:error] [pid 521505:tid 521650] [client 158.23.147.79:39965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPlxm8byYE0iXl--K5rRAAAAy0"]
[Sun Aug 30 03:11:50.337248 2026] [security2:error] [pid 521505:tid 521554] [remote 185.93.89.167:24307] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tw.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5rRQADjTA"]
[Sun Aug 30 03:11:50.338277 2026] [security2:error] [pid 521505:tid 521565] [remote 185.93.89.167:7863] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adserver.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5rRwADdzs"]
[Sun Aug 30 03:11:50.342320 2026] [security2:error] [pid 521505:tid 521534] [remote 185.93.89.167:26309] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "piwik.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5rSAADSBw"]
[Sun Aug 30 03:11:50.348243 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:64215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5rTwADfE0"]
[Sun Aug 30 03:11:50.358605 2026] [authz_core:error] [pid 521505:tid 521728] [client 66.249.66.193:49634] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:50.358961 2026] [security2:error] [pid 521505:tid 521561] [remote 185.93.89.167:24213] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "in.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5rWgADnTc"]
[Sun Aug 30 03:11:50.359073 2026] [authz_core:error] [pid 521505:tid 521728] [client 66.249.66.193:49634] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:50.362232 2026] [security2:error] [pid 521505:tid 521558] [remote 185.93.89.167:37843] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jupiter.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5rXAADQjQ"]
[Sun Aug 30 03:11:50.362391 2026] [security2:error] [pid 521505:tid 521757] [client 20.104.18.15:18383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/os.php"] [unique_id "apPlxm8byYE0iXl--K5rXQAAA5g"]
[Sun Aug 30 03:11:50.362563 2026] [security2:error] [pid 521505:tid 521674] [client 20.220.10.235:24788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/admin.php/csv.php"] [unique_id "apPlxm8byYE0iXl--K5rXwAAA0U"]
[Sun Aug 30 03:11:50.362619 2026] [security2:error] [pid 521505:tid 521542] [remote 185.93.89.167:42995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns12.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5rXgADOSQ"]
[Sun Aug 30 03:11:50.364257 2026] [security2:error] [pid 521505:tid 521537] [remote 185.93.89.167:37521] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5rYAADjR8"]
[Sun Aug 30 03:11:50.370316 2026] [security2:error] [pid 521505:tid 521573] [remote 185.93.89.167:16627] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "education.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5rZgADSEM"]
[Sun Aug 30 03:11:50.370668 2026] [security2:error] [pid 521505:tid 521713] [client 158.23.184.117:20168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/cc.php"] [unique_id "apPlxm8byYE0iXl--K5rZwAAA2w"]
[Sun Aug 30 03:11:50.371293 2026] [security2:error] [pid 521505:tid 521581] [remote 185.93.89.167:63379] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reviews.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5raAADW0s"]
[Sun Aug 30 03:11:50.378177 2026] [security2:error] [pid 521505:tid 521550] [remote 185.93.89.167:36485] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shopping.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5rbQADliw"]
[Sun Aug 30 03:11:50.382319 2026] [security2:error] [pid 521505:tid 521528] [remote 185.93.89.167:8597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drupal.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5rbgADLhY"]
[Sun Aug 30 03:11:50.390495 2026] [security2:error] [pid 521505:tid 521536] [remote 185.93.89.167:3789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vc.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5rcAADUB4"]
[Sun Aug 30 03:11:50.393833 2026] [security2:error] [pid 521505:tid 521577] [remote 185.93.89.167:11075] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "redirect.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5rcwADm0c"]
[Sun Aug 30 03:11:50.396206 2026] [security2:error] [pid 521505:tid 521522] [remote 185.93.89.167:42991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "venus.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5rdAADlxA"]
[Sun Aug 30 03:11:50.398415 2026] [security2:error] [pid 521505:tid 521759] [client 20.104.50.220:31498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-load.php"] [unique_id "apPlxm8byYE0iXl--K5rdgAAA5o"]
[Sun Aug 30 03:11:50.402565 2026] [security2:error] [pid 521505:tid 521718] [client 20.48.160.90:37746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp_KwIW0U5F.php"] [unique_id "apPlxm8byYE0iXl--K5rdwAAA3E"]
[Sun Aug 30 03:11:50.405635 2026] [security2:error] [pid 521505:tid 521519] [remote 185.93.89.167:55243] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oldmail.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5reAADnQ0"]
[Sun Aug 30 03:11:50.412408 2026] [security2:error] [pid 521505:tid 521739] [client 20.48.250.41:11203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/motu.php"] [unique_id "apPlxm8byYE0iXl--K5rfwAAA4Y"]
[Sun Aug 30 03:11:50.414280 2026] [security2:error] [pid 521505:tid 521560] [remote 185.93.89.167:36741] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "software.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5rgAADmDY"]
[Sun Aug 30 03:11:50.417079 2026] [security2:error] [pid 521505:tid 521539] [remote 185.93.89.167:4287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "php.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5rggADJiE"]
[Sun Aug 30 03:11:50.424197 2026] [security2:error] [pid 521505:tid 521572] [remote 185.93.89.167:13069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sc.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5rhwADN0I"]
[Sun Aug 30 03:11:50.428140 2026] [security2:error] [pid 521505:tid 521680] [client 20.104.18.15:22422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/blog.php"] [unique_id "apPlxm8byYE0iXl--K5rjAAAA0s"]
[Sun Aug 30 03:11:50.428199 2026] [security2:error] [pid 521505:tid 521545] [remote 185.93.89.167:29333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reg.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5riwADiSc"]
[Sun Aug 30 03:11:50.428214 2026] [security2:error] [pid 521505:tid 521587] [remote 185.93.89.167:2579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "love.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5rigADLFE"]
[Sun Aug 30 03:11:50.428673 2026] [security2:error] [pid 521505:tid 521527] [remote 185.93.89.167:53853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atlas.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5rjQADlRU"]
[Sun Aug 30 03:11:50.433158 2026] [security2:error] [pid 521505:tid 521588] [remote 185.93.89.167:40249] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tracking.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5rkAADaFI"]
[Sun Aug 30 03:11:50.447389 2026] [security2:error] [pid 521505:tid 521589] [remote 185.93.89.167:62859] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mailgw.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5rjwADWFM"]
[Sun Aug 30 03:11:50.448793 2026] [security2:error] [pid 521505:tid 521594] [remote 185.93.89.167:53985] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "img3.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5rlAADbFg"]
[Sun Aug 30 03:11:50.448960 2026] [security2:error] [pid 521505:tid 521652] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/svelte/.env"] [unique_id "apPlxm8byYE0iXl--K5rkgAAAy8"]
[Sun Aug 30 03:11:50.450505 2026] [security2:error] [pid 521505:tid 521596] [remote 185.93.89.167:5225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preprod.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5rnAADd1o"]
[Sun Aug 30 03:11:50.451242 2026] [security2:error] [pid 521505:tid 521591] [remote 185.93.89.167:56175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "press.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5rnwADRlU"]
[Sun Aug 30 03:11:50.451448 2026] [security2:error] [pid 521505:tid 521592] [remote 185.93.89.167:39177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "register.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5roAADIFY"]
[Sun Aug 30 03:11:50.457654 2026] [authz_core:error] [pid 521505:tid 521667] [client 66.249.66.66:62778] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:50.458014 2026] [authz_core:error] [pid 521505:tid 521678] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory21
[Sun Aug 30 03:11:50.458097 2026] [authz_core:error] [pid 521505:tid 521667] [client 66.249.66.66:62778] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:50.458467 2026] [authz_core:error] [pid 521505:tid 521678] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory21
[Sun Aug 30 03:11:50.462333 2026] [security2:error] [pid 521505:tid 521597] [remote 185.93.89.167:53363] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "work.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5rpQADUFs"]
[Sun Aug 30 03:11:50.464804 2026] [security2:error] [pid 521505:tid 521600] [remote 185.93.89.167:30871] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pro.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5rpwADK14"]
[Sun Aug 30 03:11:50.469623 2026] [authz_core:error] [pid 521505:tid 521638] [client 66.249.66.43:50616] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:50.470061 2026] [authz_core:error] [pid 521505:tid 521638] [client 66.249.66.43:50616] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:50.471104 2026] [security2:error] [pid 521505:tid 521601] [remote 185.93.89.167:24307] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tw.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5rqQADml8"]
[Sun Aug 30 03:11:50.471448 2026] [security2:error] [pid 521505:tid 521602] [remote 185.93.89.167:7863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adserver.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5rqgADZmA"]
[Sun Aug 30 03:11:50.475633 2026] [security2:error] [pid 521505:tid 521605] [remote 185.93.89.167:26309] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "piwik.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5rqwADcWM"]
[Sun Aug 30 03:11:50.478457 2026] [security2:error] [pid 521505:tid 521551] [remote 185.93.89.167:42909] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "direct.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5rrAADnS0"]
[Sun Aug 30 03:11:50.481417 2026] [security2:error] [pid 521505:tid 521735] [client 4.205.62.107:36051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.ballyyahoo.com"] [uri "/wp-act.php"] [unique_id "apPlxm8byYE0iXl--K5rrQAAA4I"]
[Sun Aug 30 03:11:50.482028 2026] [security2:error] [pid 521505:tid 521609] [remote 185.93.89.167:64215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5rrgADI2c"]
[Sun Aug 30 03:11:50.492637 2026] [security2:error] [pid 521505:tid 521608] [remote 185.93.89.167:24213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "in.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5rsgADQmY"]
[Sun Aug 30 03:11:50.492840 2026] [security2:error] [pid 521505:tid 521613] [remote 185.93.89.167:59907] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "health.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5rswADnGs"]
[Sun Aug 30 03:11:50.493710 2026] [security2:error] [pid 521505:tid 521614] [remote 185.93.89.167:7437] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images7.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5rtAADJmw"]
[Sun Aug 30 03:11:50.495861 2026] [security2:error] [pid 521505:tid 521611] [remote 185.93.89.167:37843] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jupiter.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5rtgADQGk"]
[Sun Aug 30 03:11:50.497844 2026] [security2:error] [pid 521505:tid 521619] [remote 185.93.89.167:37521] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5ruAADS3E"]
[Sun Aug 30 03:11:50.498819 2026] [security2:error] [pid 521505:tid 521746] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/cloud/.env"] [unique_id "apPlxm8byYE0iXl--K5ruQAAA40"]
[Sun Aug 30 03:11:50.503463 2026] [security2:error] [pid 521505:tid 521606] [remote 185.93.89.167:16627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "education.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5ruwADP2Q"]
[Sun Aug 30 03:11:50.506454 2026] [security2:error] [pid 521505:tid 521615] [remote 185.93.89.167:63379] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reviews.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5rvAADbm0"]
[Sun Aug 30 03:11:50.507672 2026] [security2:error] [pid 521505:tid 521755] [client 20.151.200.44:26497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/ssss.php"] [unique_id "apPlxm8byYE0iXl--K5rvgAAA5Y"]
[Sun Aug 30 03:11:50.508786 2026] [security2:error] [pid 521505:tid 521705] [client 20.220.10.235:24689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/admin.php/700.php"] [unique_id "apPlxm8byYE0iXl--K5rwAAAA2Q"]
[Sun Aug 30 03:11:50.509693 2026] [security2:error] [pid 521505:tid 521697] [client 20.197.61.180:12279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/upgrade-temp-backup/plugins/wp-mail.php"] [unique_id "apPlxm8byYE0iXl--K5rwgAAA1w"]
[Sun Aug 30 03:11:50.510278 2026] [security2:error] [pid 521505:tid 521760] [client 158.23.184.117:19716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/cgi-bin/admin.php"] [unique_id "apPlxm8byYE0iXl--K5rwwAAA5s"]
[Sun Aug 30 03:11:50.510665 2026] [security2:error] [pid 521505:tid 521618] [remote 185.93.89.167:3495] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5rwQADbHA"]
[Sun Aug 30 03:11:50.511295 2026] [security2:error] [pid 521505:tid 521607] [remote 185.93.89.167:34357] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banners.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5rxQADL2U"]
[Sun Aug 30 03:11:50.511802 2026] [security2:error] [pid 521505:tid 521621] [remote 185.93.89.167:36485] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shopping.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5rxwADYXM"]
[Sun Aug 30 03:11:50.513636 2026] [security2:error] [pid 521505:tid 521675] [client 20.48.251.3:52216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/grsiuk.php"] [unique_id "apPlxm8byYE0iXl--K5ryQAAA0Y"]
[Sun Aug 30 03:11:50.521094 2026] [security2:error] [pid 521505:tid 521714] [client 158.23.147.79:40029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/makeasmtp.php"] [unique_id "apPlxm8byYE0iXl--K5rzQAAA20"]
[Sun Aug 30 03:11:50.525997 2026] [security2:error] [pid 521505:tid 521626] [remote 185.93.89.167:3789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vc.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5rzwADWng"]
[Sun Aug 30 03:11:50.526536 2026] [security2:error] [pid 521505:tid 521624] [remote 185.93.89.167:18729] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ntp1.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5r0AADNHY"]
[Sun Aug 30 03:11:50.527695 2026] [security2:error] [pid 521505:tid 521629] [remote 185.93.89.167:11075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redirect.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5r0gADTHs"]
[Sun Aug 30 03:11:50.528291 2026] [security2:error] [pid 521505:tid 521631] [remote 185.93.89.167:9731] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images5.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5r0wADb30"]
[Sun Aug 30 03:11:50.529616 2026] [security2:error] [pid 521505:tid 521625] [remote 185.93.89.167:42991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "venus.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5r1AADfHc"]
[Sun Aug 30 03:11:50.530858 2026] [security2:error] [pid 521505:tid 521749] [client 114.119.139.112:50057] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "laurelhollowfl.com"] [uri "/"] [unique_id "apPlxm8byYE0iXl--K5r1QAAA5A"], referer: https://laurelhollowfl.com/
[Sun Aug 30 03:11:50.534540 2026] [security2:error] [pid 521505:tid 521630] [remote 185.93.89.167:16669] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "links.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5r1gADinw"]
[Sun Aug 30 03:11:50.537939 2026] [security2:error] [pid 521505:tid 521732] [client 20.104.18.15:16972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/dev.php"] [unique_id "apPlxm8byYE0iXl--K5r1wAAA38"]
[Sun Aug 30 03:11:50.539102 2026] [security2:error] [pid 521505:tid 521627] [remote 185.93.89.167:55243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldmail.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5r2AADdnk"]
[Sun Aug 30 03:11:50.540611 2026] [security2:error] [pid 521505:tid 521516] [remote 185.93.89.167:41989] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ipfixe.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5r2QADOgo"]
[Sun Aug 30 03:11:50.543427 2026] [security2:error] [pid 521505:tid 521509] [remote 185.93.89.167:10145] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "g.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5r2gADOQM"]
[Sun Aug 30 03:11:50.543467 2026] [security2:error] [pid 521505:tid 521515] [remote 185.93.89.167:1175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pgsql.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5r2wADhAk"]
[Sun Aug 30 03:11:50.544294 2026] [security2:error] [pid 521505:tid 521510] [remote 185.93.89.167:50005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fax.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5r3QADdQQ"]
[Sun Aug 30 03:11:50.544294 2026] [security2:error] [pid 521505:tid 521511] [remote 185.93.89.167:32655] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lync.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5r3AADLQU"]
[Sun Aug 30 03:11:50.546629 2026] [security2:error] [pid 521505:tid 521756] [client 20.48.160.90:37961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp_xiPu52Ut.php"] [unique_id "apPlxm8byYE0iXl--K5r3gAAA5c"]
[Sun Aug 30 03:11:50.547478 2026] [security2:error] [pid 521505:tid 521514] [remote 185.93.89.167:36741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "software.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5r3wADKwg"]
[Sun Aug 30 03:11:50.548936 2026] [security2:error] [pid 521505:tid 521513] [remote 185.93.89.167:57109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "development.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5r4QADjwc"]
[Sun Aug 30 03:11:50.561359 2026] [security2:error] [pid 521505:tid 521518] [remote 185.93.89.167:14453] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5r5QADNQw"]
[Sun Aug 30 03:11:50.566309 2026] [security2:error] [pid 521505:tid 521549] [remote 185.93.89.167:40249] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tracking.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5r6wADQis"]
[Sun Aug 30 03:11:50.581961 2026] [security2:error] [pid 521505:tid 521533] [remote 185.93.89.167:62859] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mailgw.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5r9AADPxs"]
[Sun Aug 30 03:11:50.582587 2026] [security2:error] [pid 521505:tid 521524] [remote 185.93.89.167:53985] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "img3.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5r9gADgRI"]
[Sun Aug 30 03:11:50.583467 2026] [security2:error] [pid 521505:tid 521556] [remote 185.93.89.167:60123] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "up.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5r-AADbjI"]
[Sun Aug 30 03:11:50.583605 2026] [security2:error] [pid 521505:tid 521555] [remote 185.93.89.167:49893] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mdm.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5r9wADhTE"]
[Sun Aug 30 03:11:50.584935 2026] [security2:error] [pid 521505:tid 521517] [remote 185.93.89.167:63579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "wifi.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5r_AADXws"]
[Sun Aug 30 03:11:50.595750 2026] [security2:error] [pid 521505:tid 521548] [remote 185.93.89.167:53363] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "work.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5sAQADJSo"]
[Sun Aug 30 03:11:50.598411 2026] [security2:error] [pid 521505:tid 521535] [remote 185.93.89.167:30871] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pro.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5sAwADbx0"]
[Sun Aug 30 03:11:50.599930 2026] [security2:error] [pid 521505:tid 521651] [client 216.73.216.128:58790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts2/updateconf"] [unique_id "apPlxm8byYE0iXl--K5sBAAAAy4"]
[Sun Aug 30 03:11:50.603995 2026] [security2:error] [pid 521505:tid 521570] [remote 185.93.89.167:6761] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banner.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5sBgADd0A"]
[Sun Aug 30 03:11:50.607192 2026] [security2:error] [pid 521505:tid 521732] [client 158.23.147.79:60170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/cgi-bin/index.php"] [unique_id "apPlxm8byYE0iXl--K5sCQAAA38"]
[Sun Aug 30 03:11:50.608249 2026] [security2:error] [pid 521505:tid 521723] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/vite/.env"] [unique_id "apPlxm8byYE0iXl--K5sCgAAA3Y"]
[Sun Aug 30 03:11:50.612316 2026] [security2:error] [pid 521505:tid 521565] [remote 185.93.89.167:42909] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "direct.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5sDQADTTs"]
[Sun Aug 30 03:11:50.617853 2026] [security2:error] [pid 521505:tid 521568] [remote 185.93.89.167:45621] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images8.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5sEAADUD4"]
[Sun Aug 30 03:11:50.619918 2026] [security2:error] [pid 521505:tid 521731] [client 20.48.250.41:11108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/Ov-Simple1.php"] [unique_id "apPlxm8byYE0iXl--K5sEQAAA34"]
[Sun Aug 30 03:11:50.625931 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:48523] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5sEgADUU0"]
[Sun Aug 30 03:11:50.626804 2026] [security2:error] [pid 521505:tid 521582] [remote 185.93.89.167:59907] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "health.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5sFQADk0w"]
[Sun Aug 30 03:11:50.627204 2026] [security2:error] [pid 521505:tid 521580] [remote 185.93.89.167:7437] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images7.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5sFgADXko"]
[Sun Aug 30 03:11:50.627849 2026] [security2:error] [pid 521505:tid 521662] [client 20.104.49.130:53717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/kerang.php"] [unique_id "apPlxm8byYE0iXl--K5sFwAAAzk"]
[Sun Aug 30 03:11:50.629166 2026] [security2:error] [pid 521505:tid 521650] [client 20.104.49.130:57636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/as.php"] [unique_id "apPlxm8byYE0iXl--K5sGQAAAy0"]
[Sun Aug 30 03:11:50.629545 2026] [security2:error] [pid 521505:tid 521561] [remote 185.93.89.167:37843] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jupiter.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5sGAADlzc"]
[Sun Aug 30 03:11:50.630832 2026] [security2:error] [pid 521505:tid 521532] [remote 185.93.89.167:37521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5sGgADjxo"]
[Sun Aug 30 03:11:50.633593 2026] [security2:error] [pid 521505:tid 521542] [remote 185.93.89.167:15177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5sHAADcSQ"]
[Sun Aug 30 03:11:50.637009 2026] [security2:error] [pid 521505:tid 521523] [remote 185.93.89.167:47169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "order.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5sHwADNRE"]
[Sun Aug 30 03:11:50.640035 2026] [security2:error] [pid 521505:tid 521567] [remote 185.93.89.167:63379] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reviews.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5sIAADLD0"]
[Sun Aug 30 03:11:50.640800 2026] [security2:error] [pid 521505:tid 521573] [remote 185.93.89.167:62709] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp3.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5sIQADhkM"]
[Sun Aug 30 03:11:50.641247 2026] [security2:error] [pid 521505:tid 521758] [client 40.83.93.50:7072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/gecko.php"] [unique_id "apPlxm8byYE0iXl--K5sIgAAA5k"]
[Sun Aug 30 03:11:50.643122 2026] [security2:error] [pid 521505:tid 521757] [client 20.220.10.235:24693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/admin.php/007x.php"] [unique_id "apPlxm8byYE0iXl--K5sIwAAA5g"]
[Sun Aug 30 03:11:50.644928 2026] [security2:error] [pid 521505:tid 521581] [remote 185.93.89.167:34357] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banners.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5sJAADnEs"]
[Sun Aug 30 03:11:50.646759 2026] [security2:error] [pid 521505:tid 521571] [remote 185.93.89.167:34607] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sports.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5sJwADJEE"]
[Sun Aug 30 03:11:50.647111 2026] [security2:error] [pid 521505:tid 521550] [remote 185.93.89.167:1995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lp.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5sKAADRCw"]
[Sun Aug 30 03:11:50.651146 2026] [security2:error] [pid 521505:tid 521528] [remote 185.93.89.167:3495] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5sKQADQBY"]
[Sun Aug 30 03:11:50.657576 2026] [security2:error] [pid 521505:tid 521687] [client 88.208.198.68:50558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.198.208.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "planb-b2b.com"] [uri "/wp-login.php"] [unique_id "apPlxm8byYE0iXl--K5sHQAAA1I"]
[Sun Aug 30 03:11:50.659573 2026] [security2:error] [pid 521505:tid 521577] [remote 185.93.89.167:3789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vc.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5sLQADP0c"]
[Sun Aug 30 03:11:50.660449 2026] [security2:error] [pid 521505:tid 521590] [remote 185.93.89.167:18729] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ntp1.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5sLgADgVQ"]
[Sun Aug 30 03:11:50.661778 2026] [security2:error] [pid 521505:tid 521578] [remote 185.93.89.167:29329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mars.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5sMAADhUg"]
[Sun Aug 30 03:11:50.662529 2026] [security2:error] [pid 521505:tid 521519] [remote 185.93.89.167:9731] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images5.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5sMQADWQ0"]
[Sun Aug 30 03:11:50.668321 2026] [security2:error] [pid 521505:tid 521579] [remote 185.93.89.167:16669] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "links.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5sNQADiUk"]
[Sun Aug 30 03:11:50.674717 2026] [security2:error] [pid 521505:tid 521574] [remote 185.93.89.167:41989] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ipfixe.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5sOQADU0Q"]
[Sun Aug 30 03:11:50.677553 2026] [security2:error] [pid 521505:tid 521560] [remote 185.93.89.167:1175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pgsql.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5sPAADZjY"]
[Sun Aug 30 03:11:50.677587 2026] [security2:error] [pid 521505:tid 521575] [remote 185.93.89.167:10145] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "g.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5sOwADRkU"]
[Sun Aug 30 03:11:50.677693 2026] [security2:error] [pid 521505:tid 521526] [remote 185.93.89.167:32655] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lync.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5sPgADmxQ"]
[Sun Aug 30 03:11:50.677901 2026] [security2:error] [pid 521505:tid 521539] [remote 185.93.89.167:50005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fax.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5sPwADYSE"]
[Sun Aug 30 03:11:50.682452 2026] [security2:error] [pid 521505:tid 521563] [remote 185.93.89.167:57109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "development.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5sQgADbTk"]
[Sun Aug 30 03:11:50.682487 2026] [authz_core:error] [pid 521505:tid 521666] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:50.682928 2026] [authz_core:error] [pid 521505:tid 521666] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:50.683798 2026] [security2:error] [pid 521505:tid 521639] [client 20.48.160.90:61496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp_n5VD7XDh.php"] [unique_id "apPlxm8byYE0iXl--K5sQwAAAyI"]
[Sun Aug 30 03:11:50.686638 2026] [autoindex:error] [pid 521505:tid 521746] [client 128.90.161.20:36890] AH01276: Cannot serve directory /home3/antgre7/healthquotemall.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://healthquotemall.com/
[Sun Aug 30 03:11:50.691498 2026] [security2:error] [pid 521505:tid 521657] [client 20.104.49.130:63587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/makeasmtp.php"] [unique_id "apPlxm8byYE0iXl--K5sRgAAAzQ"]
[Sun Aug 30 03:11:50.694901 2026] [security2:error] [pid 521505:tid 521586] [remote 185.93.89.167:14453] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5sSQADb1A"]
[Sun Aug 30 03:11:50.699442 2026] [security2:error] [pid 521505:tid 521589] [remote 185.93.89.167:31113] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "math.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5sTAADalM"]
[Sun Aug 30 03:11:50.699480 2026] [security2:error] [pid 521505:tid 521595] [remote 185.93.89.167:40249] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tracking.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5sTgADkFk"]
[Sun Aug 30 03:11:50.700942 2026] [security2:error] [pid 521505:tid 521723] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/infrastructure/.env"] [unique_id "apPlxm8byYE0iXl--K5sTwAAA3Y"]
[Sun Aug 30 03:11:50.701628 2026] [security2:error] [pid 521505:tid 521750] [client 68.155.159.216:52333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apPlxm8byYE0iXl--K5sUgAAA5E"]
[Sun Aug 30 03:11:50.701759 2026] [security2:error] [pid 521505:tid 521632] [remote 185.93.89.167:27945] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5sUQADYn4"]
[Sun Aug 30 03:11:50.703152 2026] [security2:error] [pid 521505:tid 521596] [remote 185.93.89.167:64329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5sUwADTVo"]
[Sun Aug 30 03:11:50.703862 2026] [security2:error] [pid 521505:tid 521710] [client 158.23.184.117:19730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/config.php"] [unique_id "apPlxm8byYE0iXl--K5sVAAAA2k"]
[Sun Aug 30 03:11:50.715998 2026] [security2:error] [pid 521505:tid 521593] [remote 185.93.89.167:53985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "img3.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5sVgADk1c"]
[Sun Aug 30 03:11:50.717015 2026] [security2:error] [pid 521505:tid 521592] [remote 185.93.89.167:49893] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mdm.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5sVwADhFY"]
[Sun Aug 30 03:11:50.717142 2026] [security2:error] [pid 521505:tid 521597] [remote 185.93.89.167:60123] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "up.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5sWAADXls"]
[Sun Aug 30 03:11:50.718194 2026] [security2:error] [pid 521505:tid 521600] [remote 185.93.89.167:9557] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "s4.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5sWQADVV4"]
[Sun Aug 30 03:11:50.718575 2026] [security2:error] [pid 521505:tid 521599] [remote 185.93.89.167:63579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "wifi.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5sWgADdV0"]
[Sun Aug 30 03:11:50.729136 2026] [security2:error] [pid 521505:tid 521551] [remote 185.93.89.167:53363] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "work.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5sYAADly0"]
[Sun Aug 30 03:11:50.731988 2026] [security2:error] [pid 521505:tid 521609] [remote 185.93.89.167:54151] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "affiliate.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5sYgADmmc"]
[Sun Aug 30 03:11:50.735868 2026] [security2:error] [pid 521505:tid 521604] [remote 185.93.89.167:57009] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "static2.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5sZAADI2I"]
[Sun Aug 30 03:11:50.737345 2026] [security2:error] [pid 521505:tid 521613] [remote 185.93.89.167:6761] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banner.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5sZgADLGs"]
[Sun Aug 30 03:11:50.751562 2026] [security2:error] [pid 521505:tid 521617] [remote 185.93.89.167:45621] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images8.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5sbwADRG8"]
[Sun Aug 30 03:11:50.753930 2026] [security2:error] [pid 521505:tid 521677] [client 20.104.18.15:1962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPlxm8byYE0iXl--K5scAAAA0g"]
[Sun Aug 30 03:11:50.757502 2026] [security2:error] [pid 521505:tid 521660] [client 20.48.250.41:11129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/wp-blogs.php"] [unique_id "apPlxm8byYE0iXl--K5scQAAAzc"]
[Sun Aug 30 03:11:50.760818 2026] [security2:error] [pid 521505:tid 521615] [remote 185.93.89.167:48523] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5scgADOG0"]
[Sun Aug 30 03:11:50.762473 2026] [security2:error] [pid 521505:tid 521621] [remote 185.93.89.167:37843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jupiter.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5sdgADgXM"]
[Sun Aug 30 03:11:50.767117 2026] [security2:error] [pid 521505:tid 521622] [remote 185.93.89.167:42995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns12.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5seQADX3Q"]
[Sun Aug 30 03:11:50.768619 2026] [security2:error] [pid 521505:tid 521700] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/backup/.env"] [unique_id "apPlxm8byYE0iXl--K5sewAAA18"]
[Sun Aug 30 03:11:50.770466 2026] [security2:error] [pid 521505:tid 521626] [remote 185.93.89.167:47169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "order.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5sfQADm3g"]
[Sun Aug 30 03:11:50.773195 2026] [security2:error] [pid 521505:tid 521508] [remote 185.93.89.167:63379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviews.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5sgAADMgI"]
[Sun Aug 30 03:11:50.773348 2026] [security2:error] [pid 521505:tid 521629] [remote 185.93.89.167:15177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5sfwADVHs"]
[Sun Aug 30 03:11:50.773612 2026] [security2:error] [pid 521505:tid 521714] [client 20.220.10.235:24728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/admin.php/heex.php"] [unique_id "apPlxm8byYE0iXl--K5sggAAA20"]
[Sun Aug 30 03:11:50.773949 2026] [security2:error] [pid 521505:tid 521631] [remote 185.93.89.167:62709] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp3.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5sgQADS30"]
[Sun Aug 30 03:11:50.778083 2026] [security2:error] [pid 521505:tid 521625] [remote 185.93.89.167:34357] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banners.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5sgwADjXc"]
[Sun Aug 30 03:11:50.781139 2026] [security2:error] [pid 521505:tid 521543] [remote 185.93.89.167:34607] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sports.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5shAADTCU"]
[Sun Aug 30 03:11:50.781572 2026] [security2:error] [pid 521505:tid 521627] [remote 185.93.89.167:11851] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "biblioteca.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5shgADNHk"]
[Sun Aug 30 03:11:50.781631 2026] [security2:error] [pid 521505:tid 521516] [remote 185.93.89.167:1995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lp.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5shwADZQo"]
[Sun Aug 30 03:11:50.782593 2026] [security2:error] [pid 521505:tid 521642] [client 20.48.251.3:54780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/nzv.php"] [unique_id "apPlxm8byYE0iXl--K5siQAAAyU"]
[Sun Aug 30 03:11:50.786962 2026] [security2:error] [pid 521505:tid 521584] [remote 185.93.89.167:11225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "da.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5siwADLk4"]
[Sun Aug 30 03:11:50.787350 2026] [security2:error] [pid 521505:tid 521559] [remote 185.93.89.167:8597] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "drupal.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5sjAADRzU"]
[Sun Aug 30 03:11:50.791438 2026] [security2:error] [pid 521505:tid 521509] [remote 185.93.89.167:3495] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5sjgADRQM"]
[Sun Aug 30 03:11:50.795927 2026] [security2:error] [pid 521505:tid 521511] [remote 185.93.89.167:29329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mars.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5skwADWwU"]
[Sun Aug 30 03:11:50.796418 2026] [security2:error] [pid 521505:tid 521514] [remote 185.93.89.167:9731] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images5.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5slAADkQg"]
[Sun Aug 30 03:11:50.801640 2026] [authz_core:error] [pid 521505:tid 521753] [client 66.249.66.192:45261] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:50.801757 2026] [security2:error] [pid 521505:tid 521531] [remote 185.93.89.167:16669] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "links.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5smQADUBk"]
[Sun Aug 30 03:11:50.801909 2026] [authz_core:error] [pid 521505:tid 521753] [client 66.249.66.192:45261] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:50.802538 2026] [authz_core:error] [pid 521505:tid 521730] [client 66.249.66.35:38069] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:50.802829 2026] [authz_core:error] [pid 521505:tid 521730] [client 66.249.66.35:38069] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:50.811273 2026] [security2:error] [pid 521505:tid 521520] [remote 185.93.89.167:32655] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lync.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5snAADNg4"]
[Sun Aug 30 03:11:50.811336 2026] [security2:error] [pid 521505:tid 521546] [remote 185.93.89.167:50005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fax.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5snwADkyg"]
[Sun Aug 30 03:11:50.820588 2026] [security2:error] [pid 521505:tid 521690] [client 20.48.160.90:37977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp-mini.php"] [unique_id "apPlxm8byYE0iXl--K5sogAAA1U"]
[Sun Aug 30 03:11:50.824959 2026] [security2:error] [pid 521505:tid 521648] [client 158.23.147.79:40040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apPlxm8byYE0iXl--K5spgAAAys"]
[Sun Aug 30 03:11:50.825423 2026] [security2:error] [pid 521505:tid 521556] [remote 185.93.89.167:4287] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "php.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5spQADOTI"]
[Sun Aug 30 03:11:50.826628 2026] [security2:error] [pid 521505:tid 521695] [client 4.205.62.107:25863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/debuggen.php"] [unique_id "apPlxm8byYE0iXl--K5sqAAAA1o"]
[Sun Aug 30 03:11:50.827001 2026] [security2:error] [pid 521505:tid 521555] [remote 185.93.89.167:14833] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "se.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5spwADKDE"]
[Sun Aug 30 03:11:50.828558 2026] [security2:error] [pid 521505:tid 521529] [remote 185.93.89.167:14453] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5sqQADXBc"]
[Sun Aug 30 03:11:50.829592 2026] [security2:error] [pid 521505:tid 521517] [remote 185.93.89.167:13069] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sc.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5sqwADLws"]
[Sun Aug 30 03:11:50.832304 2026] [security2:error] [pid 521505:tid 521562] [remote 185.93.89.167:40249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracking.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5srAADSTg"]
[Sun Aug 30 03:11:50.832905 2026] [security2:error] [pid 521505:tid 521564] [remote 185.93.89.167:31113] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "math.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5srQADIzo"]
[Sun Aug 30 03:11:50.833210 2026] [security2:error] [pid 521505:tid 521538] [remote 185.93.89.167:29333] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reg.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5srgADfCA"]
[Sun Aug 30 03:11:50.833431 2026] [security2:error] [pid 521505:tid 521507] [remote 185.93.89.167:2579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "love.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5srwADLAE"]
[Sun Aug 30 03:11:50.833899 2026] [security2:error] [pid 521505:tid 521548] [remote 185.93.89.167:53853] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atlas.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5ssAADhio"]
[Sun Aug 30 03:11:50.835279 2026] [security2:error] [pid 521505:tid 521544] [remote 185.93.89.167:27945] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5ssQADeCY"]
[Sun Aug 30 03:11:50.836176 2026] [security2:error] [pid 521505:tid 521535] [remote 185.93.89.167:64329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5ssgADmR0"]
[Sun Aug 30 03:11:50.845972 2026] [security2:error] [pid 521505:tid 521703] [client 158.23.184.117:19585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/login.php"] [unique_id "apPlxm8byYE0iXl--K5stAAAA2I"]
[Sun Aug 30 03:11:50.849974 2026] [autoindex:error] [pid 521505:tid 521757] [client 40.83.93.50:0] AH01276: Cannot serve directory /home2/iiti/public_html/mainstayglobal.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:11:50.850424 2026] [security2:error] [pid 521505:tid 521570] [remote 185.93.89.167:49893] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mdm.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5stgADbEA"]
[Sun Aug 30 03:11:50.850977 2026] [security2:error] [pid 521505:tid 521512] [remote 185.93.89.167:60123] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "up.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5stwADQAY"]
[Sun Aug 30 03:11:50.852035 2026] [security2:error] [pid 521505:tid 521554] [remote 185.93.89.167:9557] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "s4.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5suQADiDA"]
[Sun Aug 30 03:11:50.852037 2026] [security2:error] [pid 521505:tid 521565] [remote 185.93.89.167:63579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "wifi.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5sugADSjs"]
[Sun Aug 30 03:11:50.855654 2026] [security2:error] [pid 521505:tid 521534] [remote 185.93.89.167:56175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "press.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5suwADZxw"]
[Sun Aug 30 03:11:50.855716 2026] [security2:error] [pid 521505:tid 521568] [remote 185.93.89.167:39177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "register.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5svAADPD4"]
[Sun Aug 30 03:11:50.856760 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:5225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "preprod.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5svQADPE0"]
[Sun Aug 30 03:11:50.860293 2026] [security2:error] [pid 521505:tid 521582] [remote 185.93.89.167:61033] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5svgADP0w"]
[Sun Aug 30 03:11:50.861958 2026] [security2:error] [pid 521505:tid 521580] [remote 185.93.89.167:53363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "work.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5svwADUko"]
[Sun Aug 30 03:11:50.865431 2026] [security2:error] [pid 521505:tid 521540] [remote 185.93.89.167:54151] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "affiliate.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5swAADiSI"]
[Sun Aug 30 03:11:50.869511 2026] [security2:error] [pid 521505:tid 521558] [remote 185.93.89.167:57009] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "static2.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5sxQADXzQ"]
[Sun Aug 30 03:11:50.869784 2026] [security2:error] [pid 521505:tid 521684] [client 4.205.62.107:52908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/xa.php"] [unique_id "apPlxm8byYE0iXl--K5sxgAAA08"]
[Sun Aug 30 03:11:50.870504 2026] [security2:error] [pid 521505:tid 521523] [remote 185.93.89.167:23169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5syAADZhE"]
[Sun Aug 30 03:11:50.870659 2026] [security2:error] [pid 521505:tid 521537] [remote 185.93.89.167:6761] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banner.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5syQADQh8"]
[Sun Aug 30 03:11:50.871578 2026] [security2:error] [pid 521505:tid 521671] [client 20.104.50.220:63039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/alpa.php"] [unique_id "apPlxm8byYE0iXl--K5sygAAA0I"]
[Sun Aug 30 03:11:50.873049 2026] [security2:error] [pid 521505:tid 521567] [remote 185.93.89.167:24307] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tw.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlxm8byYE0iXl--K5sywADMj0"]
[Sun Aug 30 03:11:50.874743 2026] [security2:error] [pid 521505:tid 521573] [remote 185.93.89.167:56429] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mb.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5szQADVEM"]
[Sun Aug 30 03:11:50.876430 2026] [security2:error] [pid 521505:tid 521581] [remote 185.93.89.167:7863] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adserver.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5szwADS0s"]
[Sun Aug 30 03:11:50.879847 2026] [security2:error] [pid 521505:tid 521571] [remote 185.93.89.167:26309] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "piwik.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlxm8byYE0iXl--K5s0QADIkE"]
[Sun Aug 30 03:11:50.885410 2026] [security2:error] [pid 521505:tid 521528] [remote 185.93.89.167:64215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlxm8byYE0iXl--K5s1gADlRY"]
[Sun Aug 30 03:11:50.897335 2026] [security2:error] [pid 521505:tid 521578] [remote 185.93.89.167:24213] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "in.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5s4QADf0g"]
[Sun Aug 30 03:11:50.900179 2026] [security2:error] [pid 521505:tid 521682] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/docker/.env"] [unique_id "apPlxm8byYE0iXl--K5s5AAAA00"]
[Sun Aug 30 03:11:50.901037 2026] [security2:error] [pid 521505:tid 521552] [remote 185.93.89.167:42995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns12.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5s5QADPS4"]
[Sun Aug 30 03:11:50.907393 2026] [security2:error] [pid 521505:tid 521560] [remote 185.93.89.167:39923] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sitebuilder.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5s6gADfjY"]
[Sun Aug 30 03:11:50.907473 2026] [security2:error] [pid 521505:tid 521575] [remote 185.93.89.167:16627] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "education.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5s6wADhEU"]
[Sun Aug 30 03:11:50.907515 2026] [security2:error] [pid 521505:tid 521701] [client 20.220.10.235:24770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/tf.php"] [unique_id "apPlxm8byYE0iXl--K5s7AAAA2A"]
[Sun Aug 30 03:11:50.911364 2026] [security2:error] [pid 521505:tid 521526] [remote 185.93.89.167:34357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "banners.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5s7wADKxQ"]
[Sun Aug 30 03:11:50.912796 2026] [security2:error] [pid 521505:tid 521539] [remote 185.93.89.167:15177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5s8AADKCE"]
[Sun Aug 30 03:11:50.915414 2026] [security2:error] [pid 521505:tid 521545] [remote 185.93.89.167:36485] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shopping.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlxm8byYE0iXl--K5s8wADXCc"]
[Sun Aug 30 03:11:50.915674 2026] [security2:error] [pid 521505:tid 521572] [remote 185.93.89.167:11851] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "biblioteca.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5s8gADcUI"]
[Sun Aug 30 03:11:50.915957 2026] [security2:error] [pid 521505:tid 521587] [remote 185.93.89.167:1995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lp.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5s9AADL1E"]
[Sun Aug 30 03:11:50.921184 2026] [security2:error] [pid 521505:tid 521586] [remote 185.93.89.167:11225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "da.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5s9gADSVA"]
[Sun Aug 30 03:11:50.921668 2026] [security2:error] [pid 521505:tid 521527] [remote 185.93.89.167:8597] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "drupal.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5s9wADIxU"]
[Sun Aug 30 03:11:50.927597 2026] [security2:error] [pid 521505:tid 521649] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/backups/.env"] [unique_id "apPlxm8byYE0iXl--K5s-QAAAyw"]
[Sun Aug 30 03:11:50.929358 2026] [security2:error] [pid 521505:tid 521589] [remote 185.93.89.167:29329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mars.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5s-gADhlM"]
[Sun Aug 30 03:11:50.930566 2026] [security2:error] [pid 521505:tid 521588] [remote 185.93.89.167:9731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images5.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5s_AADmVI"]
[Sun Aug 30 03:11:50.931232 2026] [security2:error] [pid 521505:tid 521569] [remote 185.93.89.167:3495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail5.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5s_QADJj8"]
[Sun Aug 30 03:11:50.933163 2026] [security2:error] [pid 521505:tid 521632] [remote 185.93.89.167:11075] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "redirect.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5tAAADYn4"]
[Sun Aug 30 03:11:50.933788 2026] [security2:error] [pid 521505:tid 521596] [remote 185.93.89.167:59097] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web6.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5tAQADJFo"]
[Sun Aug 30 03:11:50.934228 2026] [security2:error] [pid 521505:tid 521757] [client 20.48.250.41:10954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/mini.php"] [unique_id "apPlxm8byYE0iXl--K5tAgAAA5g"]
[Sun Aug 30 03:11:50.934819 2026] [security2:error] [pid 521505:tid 521593] [remote 185.93.89.167:16669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "links.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5tAwADl1c"]
[Sun Aug 30 03:11:50.935892 2026] [security2:error] [pid 521505:tid 521592] [remote 185.93.89.167:42991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "venus.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5tBQADc1Y"]
[Sun Aug 30 03:11:50.936558 2026] [security2:error] [pid 521505:tid 521679] [client 20.104.50.220:16708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/class9.php"] [unique_id "apPlxm8byYE0iXl--K5tBgAAA0o"]
[Sun Aug 30 03:11:50.939417 2026] [security2:error] [pid 521505:tid 521597] [remote 185.93.89.167:4349] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mm.mariegronley.com"] [uri "/.env"] [unique_id "apPlxm8byYE0iXl--K5tCAADSFs"]
[Sun Aug 30 03:11:50.944312 2026] [security2:error] [pid 521505:tid 521600] [remote 185.93.89.167:32655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lync.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5tCgADUl4"]
[Sun Aug 30 03:11:50.944340 2026] [security2:error] [pid 521505:tid 521599] [remote 185.93.89.167:50005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fax.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5tCwADiV0"]
[Sun Aug 30 03:11:50.946267 2026] [security2:error] [pid 521505:tid 521605] [remote 185.93.89.167:55243] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oldmail.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5tEAADU2M"]
[Sun Aug 30 03:11:50.952071 2026] [security2:error] [pid 521505:tid 521609] [remote 185.93.89.167:36741] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "software.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlxm8byYE0iXl--K5tEgADZmc"]
[Sun Aug 30 03:11:50.954946 2026] [security2:error] [pid 521505:tid 521671] [client 20.48.160.90:61506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/xmini4.php"] [unique_id "apPlxm8byYE0iXl--K5tEwAAA0I"]
[Sun Aug 30 03:11:50.959722 2026] [security2:error] [pid 521505:tid 521603] [remote 185.93.89.167:4287] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "php.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5tFQADMmE"]
[Sun Aug 30 03:11:50.960840 2026] [security2:error] [pid 521505:tid 521604] [remote 185.93.89.167:14833] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "se.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5tFwADVGI"]
[Sun Aug 30 03:11:50.961709 2026] [security2:error] [pid 521505:tid 521608] [remote 185.93.89.167:14453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mobil.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5tGQADS2Y"]
[Sun Aug 30 03:11:50.961963 2026] [security2:error] [pid 521505:tid 521602] [remote 20.16.180.61:27174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.180.16.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/wp-login.php"] [unique_id "apPlxm8byYE0iXl--K5tDAADZGA"]
[Sun Aug 30 03:11:50.962963 2026] [security2:error] [pid 521505:tid 521613] [remote 185.93.89.167:13069] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sc.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5tGgADjWs"]
[Sun Aug 30 03:11:50.966831 2026] [security2:error] [pid 521505:tid 521619] [remote 185.93.89.167:2579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "love.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5tIAADYXE"]
[Sun Aug 30 03:11:50.967108 2026] [security2:error] [pid 521505:tid 521614] [remote 185.93.89.167:29333] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reg.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5tHwADTGw"]
[Sun Aug 30 03:11:50.967428 2026] [security2:error] [pid 521505:tid 521612] [remote 185.93.89.167:53853] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atlas.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5tIQADLmo"]
[Sun Aug 30 03:11:50.968718 2026] [security2:error] [pid 521505:tid 521617] [remote 185.93.89.167:27945] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5tIwADRW8"]
[Sun Aug 30 03:11:50.969292 2026] [security2:error] [pid 521505:tid 521606] [remote 185.93.89.167:64329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5tJAADd2Q"]
[Sun Aug 30 03:11:50.983787 2026] [security2:error] [pid 521505:tid 521521] [remote 185.93.89.167:49893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdm.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5tKgADTg8"]
[Sun Aug 30 03:11:50.984251 2026] [security2:error] [pid 521505:tid 521618] [remote 185.93.89.167:60123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "up.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5tKwADaXA"]
[Sun Aug 30 03:11:50.985191 2026] [security2:error] [pid 521505:tid 521616] [remote 185.93.89.167:63579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wifi.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlxm8byYE0iXl--K5tLAADfm4"]
[Sun Aug 30 03:11:50.986311 2026] [security2:error] [pid 521505:tid 521621] [remote 185.93.89.167:9557] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "s4.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5tLQADhHM"]
[Sun Aug 30 03:11:50.986895 2026] [security2:error] [pid 521505:tid 521607] [remote 185.93.89.167:62859] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mailgw.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlxm8byYE0iXl--K5tLwADYGU"]
[Sun Aug 30 03:11:50.987732 2026] [security2:error] [pid 521505:tid 521738] [client 158.23.184.117:19738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/index.php"] [unique_id "apPlxm8byYE0iXl--K5tMQAAA4U"]
[Sun Aug 30 03:11:50.989123 2026] [security2:error] [pid 521505:tid 521622] [remote 185.93.89.167:56175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "press.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5tMgADVXQ"]
[Sun Aug 30 03:11:50.989578 2026] [security2:error] [pid 521505:tid 521626] [remote 185.93.89.167:39177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "register.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5tMwADi3g"]
[Sun Aug 30 03:11:50.990399 2026] [security2:error] [pid 521505:tid 521508] [remote 185.93.89.167:5225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "preprod.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlxm8byYE0iXl--K5tNQADIQI"]
[Sun Aug 30 03:11:50.994591 2026] [security2:error] [pid 521505:tid 521629] [remote 185.93.89.167:61033] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlxm8byYE0iXl--K5tNwADOXs"]
[Sun Aug 30 03:11:50.999606 2026] [security2:error] [pid 521505:tid 521631] [remote 185.93.89.167:54151] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "affiliate.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlxm8byYE0iXl--K5tOwADkH0"]
[Sun Aug 30 03:11:50.999974 2026] [authz_core:error] [pid 521505:tid 521699] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory23
[Sun Aug 30 03:11:51.000457 2026] [authz_core:error] [pid 521505:tid 521699] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory23
[Sun Aug 30 03:11:51.003555 2026] [security2:error] [pid 521505:tid 521624] [remote 185.93.89.167:30871] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pro.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5tPQADb3Y"]
[Sun Aug 30 03:11:51.003785 2026] [security2:error] [pid 521505:tid 521516] [remote 185.93.89.167:6761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "banner.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlx28byYE0iXl--K5tQQADMAo"]
[Sun Aug 30 03:11:51.004056 2026] [security2:error] [pid 521505:tid 521543] [remote 185.93.89.167:37133] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/.env"] [unique_id "apPlx28byYE0iXl--K5tPwADXCU"]
[Sun Aug 30 03:11:51.004244 2026] [security2:error] [pid 521505:tid 521627] [remote 185.93.89.167:23169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlx28byYE0iXl--K5tQAADcXk"]
[Sun Aug 30 03:11:51.006519 2026] [security2:error] [pid 521505:tid 521630] [remote 185.93.89.167:24307] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tw.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5tQgADI3w"]
[Sun Aug 30 03:11:51.008117 2026] [security2:error] [pid 521505:tid 521584] [remote 185.93.89.167:56429] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mb.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlx28byYE0iXl--K5tRAADhk4"]
[Sun Aug 30 03:11:51.009854 2026] [security2:error] [pid 521505:tid 521559] [remote 185.93.89.167:7863] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adserver.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5tRQADeDU"]
[Sun Aug 30 03:11:51.013343 2026] [security2:error] [pid 521505:tid 521511] [remote 185.93.89.167:26309] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "piwik.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5tRwADJgU"]
[Sun Aug 30 03:11:51.016357 2026] [security2:error] [pid 521505:tid 521510] [remote 185.93.89.167:42909] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "direct.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5tSAADOAQ"]
[Sun Aug 30 03:11:51.018157 2026] [security2:error] [pid 521505:tid 521669] [client 4.205.62.107:17342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/grsiuk.php"] [unique_id "apPlx28byYE0iXl--K5tSgAAA0A"]
[Sun Aug 30 03:11:51.019597 2026] [security2:error] [pid 521505:tid 521514] [remote 185.93.89.167:64215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5tSwADRAg"]
[Sun Aug 30 03:11:51.025981 2026] [security2:error] [pid 521505:tid 521679] [client 20.104.50.220:33337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/index6.php"] [unique_id "apPlx28byYE0iXl--K5tTgAAA0o"]
[Sun Aug 30 03:11:51.030919 2026] [security2:error] [pid 521505:tid 521518] [remote 185.93.89.167:24213] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "in.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5tUwADfAw"]
[Sun Aug 30 03:11:51.031004 2026] [security2:error] [pid 521505:tid 521506] [remote 185.93.89.167:7437] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images7.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5tUAADigA"]
[Sun Aug 30 03:11:51.031028 2026] [security2:error] [pid 521505:tid 521633] [remote 185.93.89.167:59907] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "health.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5tUQADZ38"]
[Sun Aug 30 03:11:51.036512 2026] [security2:error] [pid 521505:tid 521520] [remote 185.93.89.167:37521] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5tVwADPw4"]
[Sun Aug 30 03:11:51.037350 2026] [security2:error] [pid 521505:tid 521712] [client 20.220.10.235:24721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/update/da222.php"] [unique_id "apPlx28byYE0iXl--K5tWgAAA2s"]
[Sun Aug 30 03:11:51.040996 2026] [security2:error] [pid 521505:tid 521547] [remote 185.93.89.167:16627] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "education.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5tXQADNSk"]
[Sun Aug 30 03:11:51.041247 2026] [security2:error] [pid 521505:tid 521553] [remote 185.93.89.167:39923] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sitebuilder.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlx28byYE0iXl--K5tXgADQi8"]
[Sun Aug 30 03:11:51.041452 2026] [security2:error] [pid 521505:tid 521549] [remote 185.93.89.167:62291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rs.mariegronley.com"] [uri "/.env"] [unique_id "apPlx28byYE0iXl--K5tXwADMis"]
[Sun Aug 30 03:11:51.049227 2026] [security2:error] [pid 521505:tid 521555] [remote 185.93.89.167:36485] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shopping.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5tZwADTDE"]
[Sun Aug 30 03:11:51.049298 2026] [security2:error] [pid 521505:tid 521529] [remote 185.93.89.167:11851] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "biblioteca.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlx28byYE0iXl--K5taAADLhc"]
[Sun Aug 30 03:11:51.050473 2026] [security2:error] [pid 521505:tid 521562] [remote 185.93.89.167:1995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlx28byYE0iXl--K5tagADgDg"]
[Sun Aug 30 03:11:51.052534 2026] [security2:error] [pid 521505:tid 521564] [remote 185.93.89.167:15177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "forms.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlx28byYE0iXl--K5tawADWzo"]
[Sun Aug 30 03:11:51.055287 2026] [security2:error] [pid 521505:tid 521538] [remote 185.93.89.167:11225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "da.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlx28byYE0iXl--K5tbQADfyA"]
[Sun Aug 30 03:11:51.062834 2026] [security2:error] [pid 521505:tid 521548] [remote 185.93.89.167:29329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mars.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlx28byYE0iXl--K5tdAADTio"]
[Sun Aug 30 03:11:51.064319 2026] [security2:error] [pid 521505:tid 521544] [remote 185.93.89.167:18729] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ntp1.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5tdQADaSY"]
[Sun Aug 30 03:11:51.067636 2026] [security2:error] [pid 521505:tid 521512] [remote 185.93.89.167:59097] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web6.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlx28byYE0iXl--K5tegADUAY"]
[Sun Aug 30 03:11:51.067673 2026] [security2:error] [pid 521505:tid 521570] [remote 185.93.89.167:11075] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "redirect.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5teAADhEA"]
[Sun Aug 30 03:11:51.069013 2026] [security2:error] [pid 521505:tid 521554] [remote 185.93.89.167:3789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vc.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5tfAADYzA"]
[Sun Aug 30 03:11:51.069748 2026] [security2:error] [pid 521505:tid 521628] [remote 185.93.89.167:42991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "venus.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5tfQADbXo"]
[Sun Aug 30 03:11:51.074877 2026] [security2:error] [pid 521505:tid 521676] [client 20.104.50.220:25416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/novax.php"] [unique_id "apPlx28byYE0iXl--K5tgQAAA0c"]
[Sun Aug 30 03:11:51.077212 2026] [security2:error] [pid 521505:tid 521568] [remote 185.93.89.167:41989] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ipfixe.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5tgwADWj4"]
[Sun Aug 30 03:11:51.080217 2026] [security2:error] [pid 521505:tid 521580] [remote 185.93.89.167:4349] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mm.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlx28byYE0iXl--K5thgADkEo"]
[Sun Aug 30 03:11:51.080770 2026] [security2:error] [pid 521505:tid 521540] [remote 185.93.89.167:55243] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oldmail.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5thwADKyI"]
[Sun Aug 30 03:11:51.080921 2026] [security2:error] [pid 521505:tid 521561] [remote 185.93.89.167:10145] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "g.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5tiAADMDc"]
[Sun Aug 30 03:11:51.081793 2026] [security2:error] [pid 521505:tid 521558] [remote 185.93.89.167:1175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pgsql.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5tiQADXDQ"]
[Sun Aug 30 03:11:51.085535 2026] [security2:error] [pid 521505:tid 521532] [remote 185.93.89.167:36741] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "software.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5tiwADKBo"]
[Sun Aug 30 03:11:51.086150 2026] [security2:error] [pid 521505:tid 521523] [remote 185.93.89.167:57109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "development.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5tjAADIxE"]
[Sun Aug 30 03:11:51.087208 2026] [security2:error] [pid 521505:tid 521717] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/old/.env"] [unique_id "apPlx28byYE0iXl--K5tjQAAA3A"]
[Sun Aug 30 03:11:51.087722 2026] [authz_core:error] [pid 521505:tid 521734] [client 66.249.66.204:44429] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:51.087994 2026] [authz_core:error] [pid 521505:tid 521734] [client 66.249.66.204:44429] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:51.095191 2026] [security2:error] [pid 521505:tid 521567] [remote 185.93.89.167:14833] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "se.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlx28byYE0iXl--K5tkQADOD0"]
[Sun Aug 30 03:11:51.099684 2026] [security2:error] [pid 521505:tid 521762] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/k8s/.env"] [unique_id "apPlx28byYE0iXl--K5tlAAAA50"]
[Sun Aug 30 03:11:51.099874 2026] [security2:error] [pid 521505:tid 521756] [client 20.104.18.15:51153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/file1221.php"] [unique_id "apPlx28byYE0iXl--K5tlQAAA5c"]
[Sun Aug 30 03:11:51.100461 2026] [security2:error] [pid 521505:tid 521673] [client 20.48.160.90:61549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/reop3.php"] [unique_id "apPlx28byYE0iXl--K5tmQAAA0Q"]
[Sun Aug 30 03:11:51.101764 2026] [security2:error] [pid 521505:tid 521525] [remote 185.93.89.167:27945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images6.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlx28byYE0iXl--K5tnAADdBM"]
[Sun Aug 30 03:11:51.102210 2026] [security2:error] [pid 521505:tid 521536] [remote 185.93.89.167:64329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digital.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlx28byYE0iXl--K5tnQADSB4"]
[Sun Aug 30 03:11:51.103447 2026] [security2:error] [pid 521505:tid 521688] [client 20.48.250.41:11056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/amp.php"] [unique_id "apPlx28byYE0iXl--K5tngAAA1M"]
[Sun Aug 30 03:11:51.105322 2026] [security2:error] [pid 521505:tid 521684] [client 158.23.147.79:40017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apPlx28byYE0iXl--K5tnwAAA08"]
[Sun Aug 30 03:11:51.120022 2026] [security2:error] [pid 521505:tid 521519] [remote 185.93.89.167:9557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "s4.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlx28byYE0iXl--K5tpAADNQ0"]
[Sun Aug 30 03:11:51.121018 2026] [security2:error] [pid 521505:tid 521522] [remote 185.93.89.167:62859] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mailgw.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5tpQADQhA"]
[Sun Aug 30 03:11:51.122849 2026] [security2:error] [pid 521505:tid 521560] [remote 185.93.89.167:53985] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "img3.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5tpwADYTY"]
[Sun Aug 30 03:11:51.124283 2026] [security2:error] [pid 521505:tid 521754] [client 40.83.93.50:22093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/ioxi-o.php"] [unique_id "apPlx28byYE0iXl--K5tqgAAA5U"]
[Sun Aug 30 03:11:51.127853 2026] [security2:error] [pid 521505:tid 521574] [remote 185.93.89.167:61033] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlx28byYE0iXl--K5trAADLkQ"]
[Sun Aug 30 03:11:51.128473 2026] [security2:error] [pid 521505:tid 521718] [client 158.23.184.117:19618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/min.php"] [unique_id "apPlx28byYE0iXl--K5trQAAA3E"]
[Sun Aug 30 03:11:51.133169 2026] [security2:error] [pid 521505:tid 521539] [remote 185.93.89.167:54151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "affiliate.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlx28byYE0iXl--K5tsAADWyE"]
[Sun Aug 30 03:11:51.137465 2026] [security2:error] [pid 521505:tid 521572] [remote 185.93.89.167:30871] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pro.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5tsgADkUI"]
[Sun Aug 30 03:11:51.137907 2026] [security2:error] [pid 521505:tid 521587] [remote 185.93.89.167:23169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlx28byYE0iXl--K5ttAADQ1E"]
[Sun Aug 30 03:11:51.137909 2026] [security2:error] [pid 521505:tid 521563] [remote 185.93.89.167:37133] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlx28byYE0iXl--K5tswADbDk"]
[Sun Aug 30 03:11:51.141625 2026] [security2:error] [pid 521505:tid 521589] [remote 185.93.89.167:56429] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mb.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlx28byYE0iXl--K5ttwADS1M"]
[Sun Aug 30 03:11:51.142834 2026] [security2:error] [pid 521505:tid 521675] [client 216.73.216.128:8686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_config_quote_replace_string"] [unique_id "apPlx28byYE0iXl--K5tugAAA0Y"]
[Sun Aug 30 03:11:51.150056 2026] [security2:error] [pid 521505:tid 521569] [remote 185.93.89.167:42909] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "direct.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5tvgADhD8"]
[Sun Aug 30 03:11:51.155842 2026] [autoindex:error] [pid 521505:tid 521731] [client 66.132.172.218:30972] AH01276: Cannot serve directory /home3/dylans/hobbylords.au/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:11:51.156258 2026] [security2:error] [pid 521505:tid 521596] [remote 185.93.89.167:45621] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images8.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5twQADk1o"]
[Sun Aug 30 03:11:51.157553 2026] [security2:error] [pid 521505:tid 521592] [remote 185.93.89.167:59215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "users.mariegronley.com"] [uri "/.env"] [unique_id "apPlx28byYE0iXl--K5txAADLVY"]
[Sun Aug 30 03:11:51.158397 2026] [security2:error] [pid 521505:tid 521593] [remote 20.16.180.61:27174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.180.16.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marazul.com.pa"] [uri "/wp-login.php"] [unique_id "apPlx28byYE0iXl--K5twgADIVc"], referer: https://marazul.com.pa/wp-login.php
[Sun Aug 30 03:11:51.164860 2026] [security2:error] [pid 521505:tid 521591] [remote 185.93.89.167:7437] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images7.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5txwADkFU"]
[Sun Aug 30 03:11:51.164876 2026] [security2:error] [pid 521505:tid 521600] [remote 185.93.89.167:59907] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "health.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5tyAADj14"]
[Sun Aug 30 03:11:51.166029 2026] [security2:error] [pid 521505:tid 521722] [client 20.220.10.235:24682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/qi.php"] [unique_id "apPlx28byYE0iXl--K5tyQAAA3U"]
[Sun Aug 30 03:11:51.166509 2026] [security2:error] [pid 521505:tid 521599] [remote 185.93.89.167:37843] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jupiter.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5tygADMF0"]
[Sun Aug 30 03:11:51.167220 2026] [security2:error] [pid 521505:tid 521605] [remote 185.93.89.167:48523] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5tywADmmM"]
[Sun Aug 30 03:11:51.169925 2026] [security2:error] [pid 521505:tid 521598] [remote 185.93.89.167:37521] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5tzQADKFw"]
[Sun Aug 30 03:11:51.172992 2026] [security2:error] [pid 521505:tid 521609] [remote 185.93.89.167:47169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "order.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5tzwADI2c"]
[Sun Aug 30 03:11:51.174095 2026] [security2:error] [pid 521505:tid 521659] [client 20.48.251.3:42394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/aws_settings.php"] [unique_id "apPlx28byYE0iXl--K5t0QAAAzY"]
[Sun Aug 30 03:11:51.174962 2026] [security2:error] [pid 521505:tid 521603] [remote 185.93.89.167:39923] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sitebuilder.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlx28byYE0iXl--K5t0gADJmE"]
[Sun Aug 30 03:11:51.178160 2026] [security2:error] [pid 521505:tid 521604] [remote 185.93.89.167:62709] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp3.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5t0wADVWI"]
[Sun Aug 30 03:11:51.178608 2026] [security2:error] [pid 521505:tid 521608] [remote 185.93.89.167:63379] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reviews.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5t1AADYmY"]
[Sun Aug 30 03:11:51.180894 2026] [security2:error] [pid 521505:tid 521602] [remote 185.93.89.167:62291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rs.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlx28byYE0iXl--K5t1gADOmA"]
[Sun Aug 30 03:11:51.182374 2026] [security2:error] [pid 521505:tid 521614] [remote 185.93.89.167:11851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biblioteca.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlx28byYE0iXl--K5t2QADmGw"]
[Sun Aug 30 03:11:51.185029 2026] [security2:error] [pid 521505:tid 521611] [remote 185.93.89.167:34607] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sports.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5t2wADiGk"]
[Sun Aug 30 03:11:51.188174 2026] [authz_core:error] [pid 521505:tid 521728] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:51.188524 2026] [security2:error] [pid 521505:tid 521610] [remote 185.93.89.167:11225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "da.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlx28byYE0iXl--K5t3AADl2g"]
[Sun Aug 30 03:11:51.188598 2026] [authz_core:error] [pid 521505:tid 521728] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:51.197884 2026] [security2:error] [pid 521505:tid 521616] [remote 185.93.89.167:18729] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ntp1.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5t4QADSG4"]
[Sun Aug 30 03:11:51.201156 2026] [security2:error] [pid 521505:tid 521620] [remote 185.93.89.167:59097] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web6.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlx28byYE0iXl--K5t4wADZ3I"]
[Sun Aug 30 03:11:51.202414 2026] [security2:error] [pid 521505:tid 521622] [remote 185.93.89.167:3789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vc.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5t5QADT3Q"]
[Sun Aug 30 03:11:51.211266 2026] [security2:error] [pid 521505:tid 521623] [remote 185.93.89.167:41989] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ipfixe.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5t6wADQnU"]
[Sun Aug 30 03:11:51.214481 2026] [security2:error] [pid 521505:tid 521624] [remote 185.93.89.167:10145] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "g.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5t7gADZHY"]
[Sun Aug 30 03:11:51.215098 2026] [security2:error] [pid 521505:tid 521625] [remote 185.93.89.167:1175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pgsql.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5t8gADSXc"]
[Sun Aug 30 03:11:51.219583 2026] [security2:error] [pid 521505:tid 521559] [remote 185.93.89.167:57109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "development.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5t9gADWzU"]
[Sun Aug 30 03:11:51.219951 2026] [security2:error] [pid 521505:tid 521511] [remote 185.93.89.167:4349] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mm.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlx28byYE0iXl--K5t9wADdgU"]
[Sun Aug 30 03:11:51.227820 2026] [core:alert] [pid 521505:tid 521750] [client 103.103.89.159:33080] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:11:51.228285 2026] [security2:error] [pid 521505:tid 521510] [remote 185.93.89.167:14833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "se.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlx28byYE0iXl--K5t_QADQwQ"]
[Sun Aug 30 03:11:51.237191 2026] [security2:error] [pid 521505:tid 521520] [remote 185.93.89.167:40249] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tracking.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5uCAADbg4"]
[Sun Aug 30 03:11:51.237293 2026] [security2:error] [pid 521505:tid 521546] [remote 185.93.89.167:31113] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "math.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5uCQADfSg"]
[Sun Aug 30 03:11:51.239851 2026] [authz_core:error] [pid 521505:tid 521687] [client 66.249.66.198:51807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:51.240117 2026] [authz_core:error] [pid 521505:tid 521687] [client 66.249.66.198:51807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:51.242555 2026] [security2:error] [pid 521505:tid 521664] [client 20.197.61.180:12270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/upgrade-temp-backup/themes/admin.php"] [unique_id "apPlx28byYE0iXl--K5uDQAAAzs"]
[Sun Aug 30 03:11:51.243369 2026] [security2:error] [pid 521505:tid 521710] [client 20.104.49.130:59559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/jp.php"] [unique_id "apPlx28byYE0iXl--K5uDgAAA2k"]
[Sun Aug 30 03:11:51.246120 2026] [security2:error] [pid 521505:tid 521685] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/tmp/.env"] [unique_id "apPlx28byYE0iXl--K5uEAAAA1A"]
[Sun Aug 30 03:11:51.256567 2026] [security2:error] [pid 521505:tid 521555] [remote 185.93.89.167:53985] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "img3.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5uGQADczE"]
[Sun Aug 30 03:11:51.258383 2026] [security2:error] [pid 521505:tid 521748] [client 20.48.160.90:61543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp-mail.php"] [unique_id "apPlx28byYE0iXl--K5uHAAAA48"]
[Sun Aug 30 03:11:51.259660 2026] [security2:error] [pid 521505:tid 521653] [client 20.104.18.15:31727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/dk.php"] [unique_id "apPlx28byYE0iXl--K5uHwAAAzA"]
[Sun Aug 30 03:11:51.260687 2026] [security2:error] [pid 521505:tid 521538] [remote 185.93.89.167:61033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "analytics.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlx28byYE0iXl--K5uIAADmiA"]
[Sun Aug 30 03:11:51.267972 2026] [security2:error] [pid 521505:tid 521542] [remote 185.93.89.167:53363] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "work.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5uIwADlCQ"]
[Sun Aug 30 03:11:51.270891 2026] [security2:error] [pid 521505:tid 521512] [remote 185.93.89.167:23169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www7.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlx28byYE0iXl--K5uJwADbQY"]
[Sun Aug 30 03:11:51.271092 2026] [security2:error] [pid 521505:tid 521535] [remote 185.93.89.167:37133] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlx28byYE0iXl--K5uJgADeB0"]
[Sun Aug 30 03:11:51.273776 2026] [security2:error] [pid 521505:tid 521570] [remote 185.93.89.167:57009] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "static2.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5uKAADNkA"]
[Sun Aug 30 03:11:51.274407 2026] [security2:error] [pid 521505:tid 521565] [remote 185.93.89.167:56429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mb.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlx28byYE0iXl--K5uKwADXjs"]
[Sun Aug 30 03:11:51.274607 2026] [security2:error] [pid 521505:tid 521628] [remote 185.93.89.167:24307] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tw.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5uKgADUXo"]
[Sun Aug 30 03:11:51.281618 2026] [security2:error] [pid 521505:tid 521568] [remote 185.93.89.167:26309] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "piwik.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5uLQADOj4"]
[Sun Aug 30 03:11:51.287066 2026] [security2:error] [pid 521505:tid 521735] [client 158.23.184.117:19743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/options.php"] [unique_id "apPlx28byYE0iXl--K5uLwAAA4I"]
[Sun Aug 30 03:11:51.288402 2026] [security2:error] [pid 521505:tid 521580] [remote 185.93.89.167:64215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5uMQADmUo"]
[Sun Aug 30 03:11:51.290278 2026] [security2:error] [pid 521505:tid 521540] [remote 185.93.89.167:45621] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images8.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5uMgADliI"]
[Sun Aug 30 03:11:51.290928 2026] [security2:error] [pid 521505:tid 521582] [remote 185.93.89.167:59215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "users.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlx28byYE0iXl--K5uMwADJEw"]
[Sun Aug 30 03:11:51.292442 2026] [security2:error] [pid 521505:tid 521561] [remote 185.93.89.167:24005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "radius.mariegronley.com"] [uri "/.env"] [unique_id "apPlx28byYE0iXl--K5uNAADlzc"]
[Sun Aug 30 03:11:51.294124 2026] [authz_core:error] [pid 521505:tid 521661] [client 216.73.216.128:37868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:51.294428 2026] [authz_core:error] [pid 521505:tid 521661] [client 216.73.216.128:37868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:51.296185 2026] [security2:error] [pid 521505:tid 521673] [client 20.220.10.235:24792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/px.php"] [unique_id "apPlx28byYE0iXl--K5uNQAAA0Q"]
[Sun Aug 30 03:11:51.299803 2026] [security2:error] [pid 521505:tid 521706] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "board.mariegronley.com"] [uri "/index.cgi"] [unique_id "apPlx28byYE0iXl--K5uNgADZU0"]
[Sun Aug 30 03:11:51.299845 2026] [security2:error] [pid 521505:tid 521509] [remote 185.93.89.167:37843] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jupiter.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5uOgADdAM"]
[Sun Aug 30 03:11:51.300730 2026] [security2:error] [pid 521505:tid 521509] [remote 185.93.89.167:48523] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5uOwADSAM"]
[Sun Aug 30 03:11:51.300932 2026] [security2:error] [pid 521505:tid 521669] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/kubernetes/.env"] [unique_id "apPlx28byYE0iXl--K5uPAAAA0A"]
[Sun Aug 30 03:11:51.301915 2026] [security2:error] [pid 521505:tid 521708] [client 20.48.250.41:10956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/cc13.php"] [unique_id "apPlx28byYE0iXl--K5uPQAAA2c"]
[Sun Aug 30 03:11:51.303529 2026] [security2:error] [pid 521505:tid 521581] [remote 185.93.89.167:42995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns12.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5uPwADT0s"]
[Sun Aug 30 03:11:51.306252 2026] [security2:error] [pid 521505:tid 521573] [remote 185.93.89.167:47169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "order.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5uQAADikM"]
[Sun Aug 30 03:11:51.308236 2026] [security2:error] [pid 521505:tid 521525] [remote 185.93.89.167:39923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sitebuilder.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlx28byYE0iXl--K5uQQADPxM"]
[Sun Aug 30 03:11:51.311231 2026] [security2:error] [pid 521505:tid 521571] [remote 185.93.89.167:62709] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp3.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5uQwADQkE"]
[Sun Aug 30 03:11:51.312176 2026] [security2:error] [pid 521505:tid 521550] [remote 185.93.89.167:63379] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reviews.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5uRAADZCw"]
[Sun Aug 30 03:11:51.316608 2026] [security2:error] [pid 521505:tid 521577] [remote 185.93.89.167:34357] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banners.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5uRgADjkc"]
[Sun Aug 30 03:11:51.316983 2026] [security2:error] [pid 521505:tid 521585] [remote 185.93.89.167:36485] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shopping.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5uRwADlU8"]
[Sun Aug 30 03:11:51.318488 2026] [security2:error] [pid 521505:tid 521578] [remote 185.93.89.167:34607] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sports.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5uSAADVEg"]
[Sun Aug 30 03:11:51.320569 2026] [security2:error] [pid 521505:tid 521519] [remote 185.93.89.167:62291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rs.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlx28byYE0iXl--K5uSQADjQ0"]
[Sun Aug 30 03:11:51.325052 2026] [security2:error] [pid 521505:tid 521560] [remote 185.93.89.167:14659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/.env"] [unique_id "apPlx28byYE0iXl--K5uTAADNTY"]
[Sun Aug 30 03:11:51.325257 2026] [security2:error] [pid 521505:tid 521552] [remote 185.93.89.167:8597] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "drupal.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5uTQADRS4"]
[Sun Aug 30 03:11:51.332844 2026] [security2:error] [pid 521505:tid 521750] [client 20.104.50.220:6142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/error.php"] [unique_id "apPlx28byYE0iXl--K5uUAAAA5E"]
[Sun Aug 30 03:11:51.334419 2026] [security2:error] [pid 521505:tid 521574] [remote 185.93.89.167:59097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "web6.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlx28byYE0iXl--K5uUgADQ0Q"]
[Sun Aug 30 03:11:51.335238 2026] [security2:error] [pid 521505:tid 521539] [remote 185.93.89.167:9731] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images5.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5uUwADZiE"]
[Sun Aug 30 03:11:51.338909 2026] [security2:error] [pid 521505:tid 521563] [remote 185.93.89.167:16669] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "links.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5uVwADRjk"]
[Sun Aug 30 03:11:51.349290 2026] [security2:error] [pid 521505:tid 521589] [remote 185.93.89.167:50005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fax.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5uXAADd1M"]
[Sun Aug 30 03:11:51.349296 2026] [security2:error] [pid 521505:tid 521588] [remote 185.93.89.167:32655] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lync.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5uXgADH1I"]
[Sun Aug 30 03:11:51.355105 2026] [security2:error] [pid 521505:tid 521596] [remote 185.93.89.167:3495] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5uYwADalo"]
[Sun Aug 30 03:11:51.358318 2026] [security2:error] [pid 521505:tid 521695] [client 4.205.62.107:16321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/06.php"] [unique_id "apPlx28byYE0iXl--K5uZQAAA1o"]
[Sun Aug 30 03:11:51.359206 2026] [security2:error] [pid 521505:tid 521682] [client 158.23.147.79:39979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-content/languages/about.php"] [unique_id "apPlx28byYE0iXl--K5uZgAAA00"]
[Sun Aug 30 03:11:51.359305 2026] [security2:error] [pid 521505:tid 521592] [remote 185.93.89.167:4349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mm.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlx28byYE0iXl--K5uZwADflY"]
[Sun Aug 30 03:11:51.363969 2026] [security2:error] [pid 521505:tid 521594] [remote 185.93.89.167:4287] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "php.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5uagADj1g"]
[Sun Aug 30 03:11:51.365625 2026] [security2:error] [pid 521505:tid 521591] [remote 185.93.89.167:13069] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sc.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5uawADL1U"]
[Sun Aug 30 03:11:51.365817 2026] [security2:error] [pid 521505:tid 521600] [remote 185.93.89.167:14453] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5ubAADdV4"]
[Sun Aug 30 03:11:51.370321 2026] [security2:error] [pid 521505:tid 521605] [remote 185.93.89.167:40249] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tracking.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5ubwADXGM"]
[Sun Aug 30 03:11:51.370326 2026] [security2:error] [pid 521505:tid 521597] [remote 185.93.89.167:53853] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atlas.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5ubQADcFs"]
[Sun Aug 30 03:11:51.370412 2026] [security2:error] [pid 521505:tid 521599] [remote 185.93.89.167:2579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "love.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5ubgADlF0"]
[Sun Aug 30 03:11:51.370708 2026] [security2:error] [pid 521505:tid 521598] [remote 185.93.89.167:29333] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reg.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5ucAADk1w"]
[Sun Aug 30 03:11:51.371083 2026] [security2:error] [pid 521505:tid 521601] [remote 185.93.89.167:31113] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "math.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5ucQADOV8"]
[Sun Aug 30 03:11:51.371772 2026] [security2:error] [pid 521505:tid 521603] [remote 185.93.89.167:44659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "p.mariegronley.com"] [uri "/.env"] [unique_id "apPlx28byYE0iXl--K5ucwADbWE"]
[Sun Aug 30 03:11:51.372849 2026] [security2:error] [pid 521505:tid 521604] [remote 185.93.89.167:25969] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dbadmin.mariegronley.com"] [uri "/.env"] [unique_id "apPlx28byYE0iXl--K5udQADHmI"]
[Sun Aug 30 03:11:51.388656 2026] [security2:error] [pid 521505:tid 521614] [remote 185.93.89.167:49893] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mdm.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5ueQADgmw"]
[Sun Aug 30 03:11:51.390176 2026] [security2:error] [pid 521505:tid 521613] [remote 185.93.89.167:60123] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "up.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5uegADmWs"]
[Sun Aug 30 03:11:51.390317 2026] [security2:error] [pid 521505:tid 521610] [remote 185.93.89.167:14991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "barracuda.mariegronley.com"] [uri "/.env"] [unique_id "apPlx28byYE0iXl--K5ufgADl2g"]
[Sun Aug 30 03:11:51.390375 2026] [security2:error] [pid 521505:tid 521619] [remote 185.93.89.167:62859] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mailgw.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5uewADiHE"]
[Sun Aug 30 03:11:51.390491 2026] [security2:error] [pid 521505:tid 521673] [client 20.104.49.130:59533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/term.php"] [unique_id "apPlx28byYE0iXl--K5ufwAAA0Q"]
[Sun Aug 30 03:11:51.391620 2026] [security2:error] [pid 521505:tid 521606] [remote 185.93.89.167:56175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "press.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5ugQADN2Q"]
[Sun Aug 30 03:11:51.391771 2026] [security2:error] [pid 521505:tid 521706] [client 20.104.49.130:60106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/ws85.php"] [unique_id "apPlx28byYE0iXl--K5uggAAA2U"]
[Sun Aug 30 03:11:51.392520 2026] [security2:error] [pid 521505:tid 521521] [remote 185.93.89.167:63579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "wifi.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5ugwADdA8"]
[Sun Aug 30 03:11:51.393515 2026] [security2:error] [pid 521505:tid 521618] [remote 185.93.89.167:5225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "preprod.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5uhQADnXA"]
[Sun Aug 30 03:11:51.393615 2026] [security2:error] [pid 521505:tid 521616] [remote 185.93.89.167:39177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "register.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5uhAADfG4"]
[Sun Aug 30 03:11:51.395362 2026] [security2:error] [pid 521505:tid 521669] [client 20.48.160.90:37759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp-conffg.php"] [unique_id "apPlx28byYE0iXl--K5uiAAAA0A"]
[Sun Aug 30 03:11:51.401833 2026] [security2:error] [pid 521505:tid 521621] [remote 185.93.89.167:53363] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "work.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5uiQADZ3M"]
[Sun Aug 30 03:11:51.403918 2026] [security2:error] [pid 521505:tid 521668] [client 20.104.50.220:28734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/images/sym403.php"] [unique_id "apPlx28byYE0iXl--K5uiwAAAz8"]
[Sun Aug 30 03:11:51.403943 2026] [security2:error] [pid 521505:tid 521626] [remote 185.93.89.167:37133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kb.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlx28byYE0iXl--K5ujQADQng"]
[Sun Aug 30 03:11:51.405358 2026] [security2:error] [pid 521505:tid 521508] [remote 185.93.89.167:1591] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/.env"] [unique_id "apPlx28byYE0iXl--K5ujgADZAI"]
[Sun Aug 30 03:11:51.406153 2026] [security2:error] [pid 521505:tid 521623] [remote 185.93.89.167:30871] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pro.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5ujwADlXU"]
[Sun Aug 30 03:11:51.407290 2026] [security2:error] [pid 521505:tid 521624] [remote 185.93.89.167:57009] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "static2.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5ukAADVHY"]
[Sun Aug 30 03:11:51.408613 2026] [security2:error] [pid 521505:tid 521516] [remote 185.93.89.167:6761] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banner.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5ulQADcQo"]
[Sun Aug 30 03:11:51.408670 2026] [security2:error] [pid 521505:tid 521732] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/temp/.env"] [unique_id "apPlx28byYE0iXl--K5ulAAAA38"]
[Sun Aug 30 03:11:51.411783 2026] [security2:error] [pid 521505:tid 521543] [remote 185.93.89.167:7863] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adserver.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5umAADeyU"]
[Sun Aug 30 03:11:51.413793 2026] [security2:error] [pid 521505:tid 521651] [client 20.48.251.3:36849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/ms-edit.php"] [unique_id "apPlx28byYE0iXl--K5umQAAAy4"]
[Sun Aug 30 03:11:51.417124 2026] [autoindex:error] [pid 521505:tid 521678] [client 128.90.161.20:36890] AH01276: Cannot serve directory /home3/antgre7/healthquotemall.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://healthquotemall.com/
[Sun Aug 30 03:11:51.418412 2026] [authz_core:error] [pid 521505:tid 521650] [client 66.249.66.40:58630] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:51.418690 2026] [authz_core:error] [pid 521505:tid 521650] [client 66.249.66.40:58630] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:51.419691 2026] [security2:error] [pid 521505:tid 521559] [remote 185.93.89.167:42909] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "direct.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5ungADQzU"]
[Sun Aug 30 03:11:51.421552 2026] [security2:error] [pid 521505:tid 521707] [client 20.104.50.220:63505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/index4.php"] [unique_id "apPlx28byYE0iXl--K5uoQAAA2Y"]
[Sun Aug 30 03:11:51.424365 2026] [security2:error] [pid 521505:tid 521510] [remote 185.93.89.167:59215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "users.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlx28byYE0iXl--K5upAADRgQ"]
[Sun Aug 30 03:11:51.426200 2026] [security2:error] [pid 521505:tid 521514] [remote 185.93.89.167:24005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "radius.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlx28byYE0iXl--K5upQADbgg"]
[Sun Aug 30 03:11:51.429459 2026] [security2:error] [pid 521505:tid 521664] [client 20.48.250.41:11024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/aa.php"] [unique_id "apPlx28byYE0iXl--K5upwAAAzs"]
[Sun Aug 30 03:11:51.431892 2026] [security2:error] [pid 521505:tid 521663] [client 158.23.184.117:19587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/pk.php"] [unique_id "apPlx28byYE0iXl--K5uqgAAAzo"]
[Sun Aug 30 03:11:51.433207 2026] [security2:error] [pid 521505:tid 521633] [remote 185.93.89.167:7437] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images7.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5urAADY38"]
[Sun Aug 30 03:11:51.433294 2026] [security2:error] [pid 521505:tid 521513] [remote 185.93.89.167:62949] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "board.mariegronley.com"] [uri "/.env"] [unique_id "apPlx28byYE0iXl--K5uqwADTAc"]
[Sun Aug 30 03:11:51.433457 2026] [security2:error] [pid 521505:tid 521681] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "board.mariegronley.com"] [uri "/.env"] [unique_id "apPlx28byYE0iXl--K5uqwADTAc"]
[Sun Aug 30 03:11:51.433659 2026] [security2:error] [pid 521505:tid 521531] [remote 185.93.89.167:24213] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "in.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5urgADIBk"]
[Sun Aug 30 03:11:51.434712 2026] [security2:error] [pid 521505:tid 521520] [remote 185.93.89.167:59907] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "health.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5urwADIQ4"]
[Sun Aug 30 03:11:51.436866 2026] [security2:error] [pid 521505:tid 521547] [remote 185.93.89.167:42995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns12.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5usgADMik"]
[Sun Aug 30 03:11:51.443140 2026] [security2:error] [pid 521505:tid 521553] [remote 185.93.89.167:16627] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "education.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5utwADLy8"]
[Sun Aug 30 03:11:51.449951 2026] [security2:error] [pid 521505:tid 521555] [remote 185.93.89.167:34357] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banners.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5uvQADkzE"]
[Sun Aug 30 03:11:51.458856 2026] [security2:error] [pid 521505:tid 521538] [remote 185.93.89.167:8597] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "drupal.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5uxwADRCA"]
[Sun Aug 30 03:11:51.458856 2026] [security2:error] [pid 521505:tid 521564] [remote 185.93.89.167:14659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlx28byYE0iXl--K5uxgADJDo"]
[Sun Aug 30 03:11:51.458960 2026] [security2:error] [pid 521505:tid 521517] [remote 185.93.89.167:1995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lp.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5uxAADiAs"]
[Sun Aug 30 03:11:51.459754 2026] [security2:error] [pid 521505:tid 521542] [remote 185.93.89.167:62291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rs.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlx28byYE0iXl--K5uyAADNyQ"]
[Sun Aug 30 03:11:51.466360 2026] [security2:error] [pid 521505:tid 521507] [remote 185.93.89.167:18729] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ntp1.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5uygADnQE"]
[Sun Aug 30 03:11:51.468720 2026] [security2:error] [pid 521505:tid 521548] [remote 185.93.89.167:29329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mars.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5uzAADSCo"]
[Sun Aug 30 03:11:51.469524 2026] [security2:error] [pid 521505:tid 521535] [remote 185.93.89.167:9731] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images5.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5uzQADUx0"]
[Sun Aug 30 03:11:51.470858 2026] [security2:error] [pid 521505:tid 521570] [remote 185.93.89.167:11075] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "redirect.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5uzwADP0A"]
[Sun Aug 30 03:11:51.472210 2026] [security2:error] [pid 521505:tid 521565] [remote 185.93.89.167:16669] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "links.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5u0AADTzs"]
[Sun Aug 30 03:11:51.472753 2026] [security2:error] [pid 521505:tid 521628] [remote 185.93.89.167:42991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "venus.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5u0QADZHo"]
[Sun Aug 30 03:11:51.473953 2026] [security2:error] [pid 521505:tid 521554] [remote 185.93.89.167:15177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5u0wADcjA"]
[Sun Aug 30 03:11:51.478918 2026] [authz_core:error] [pid 521505:tid 521754] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory12
[Sun Aug 30 03:11:51.479213 2026] [authz_core:error] [pid 521505:tid 521754] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory12
[Sun Aug 30 03:11:51.479749 2026] [security2:error] [pid 521505:tid 521566] [remote 185.93.89.167:41989] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ipfixe.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5u1AADjTw"]
[Sun Aug 30 03:11:51.480906 2026] [security2:error] [pid 521505:tid 521568] [remote 185.93.89.167:45765] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns01.mariegronley.com"] [uri "/.env"] [unique_id "apPlx28byYE0iXl--K5u1QADWz4"]
[Sun Aug 30 03:11:51.482671 2026] [security2:error] [pid 521505:tid 521580] [remote 185.93.89.167:32655] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lync.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5u1wADLko"]
[Sun Aug 30 03:11:51.483277 2026] [security2:error] [pid 521505:tid 521540] [remote 185.93.89.167:50005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fax.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5u2AADTiI"]
[Sun Aug 30 03:11:51.483326 2026] [security2:error] [pid 521505:tid 521582] [remote 185.93.89.167:1175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pgsql.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5u2QADNUw"]
[Sun Aug 30 03:11:51.483592 2026] [security2:error] [pid 521505:tid 521561] [remote 185.93.89.167:10145] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "g.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5u2gADSTc"]
[Sun Aug 30 03:11:51.484122 2026] [security2:error] [pid 521505:tid 521672] [client 20.220.10.235:24780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/is.php"] [unique_id "apPlx28byYE0iXl--K5u2wAAA0M"]
[Sun Aug 30 03:11:51.484410 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:55243] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oldmail.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5u3AADWU0"]
[Sun Aug 30 03:11:51.488290 2026] [security2:error] [pid 521505:tid 521567] [remote 185.93.89.167:57109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "development.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5u3QADWD0"]
[Sun Aug 30 03:11:51.488455 2026] [security2:error] [pid 521505:tid 521558] [remote 185.93.89.167:36741] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "software.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5u3gADRjQ"]
[Sun Aug 30 03:11:51.495179 2026] [security2:error] [pid 521505:tid 521629] [remote 185.93.89.167:3495] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5u4AADH3s"]
[Sun Aug 30 03:11:51.497988 2026] [security2:error] [pid 521505:tid 521509] [remote 185.93.89.167:4287] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "php.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5u4QADVQM"]
[Sun Aug 30 03:11:51.498993 2026] [security2:error] [pid 521505:tid 521573] [remote 185.93.89.167:13069] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sc.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5u5AADd0M"]
[Sun Aug 30 03:11:51.499606 2026] [security2:error] [pid 521505:tid 521525] [remote 185.93.89.167:14453] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5u5QADWhM"]
[Sun Aug 30 03:11:51.500261 2026] [security2:error] [pid 521505:tid 521704] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/terraform/.env"] [unique_id "apPlx28byYE0iXl--K5u5gAAA2M"]
[Sun Aug 30 03:11:51.503558 2026] [security2:error] [pid 521505:tid 521571] [remote 185.93.89.167:53853] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atlas.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5u6AADfkE"]
[Sun Aug 30 03:11:51.504003 2026] [security2:error] [pid 521505:tid 521550] [remote 185.93.89.167:2579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "love.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5u6QADmyw"]
[Sun Aug 30 03:11:51.504318 2026] [security2:error] [pid 521505:tid 521577] [remote 185.93.89.167:29333] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reg.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5u6gADIUc"]
[Sun Aug 30 03:11:51.505295 2026] [security2:error] [pid 521505:tid 521578] [remote 185.93.89.167:44659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "p.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlx28byYE0iXl--K5u7AADMkg"]
[Sun Aug 30 03:11:51.505933 2026] [security2:error] [pid 521505:tid 521536] [remote 185.93.89.167:27945] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5u7QADjx4"]
[Sun Aug 30 03:11:51.507360 2026] [security2:error] [pid 521505:tid 521522] [remote 185.93.89.167:25969] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dbadmin.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlx28byYE0iXl--K5u7wADkBA"]
[Sun Aug 30 03:11:51.507372 2026] [security2:error] [pid 521505:tid 521519] [remote 185.93.89.167:64329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5u7gADLw0"]
[Sun Aug 30 03:11:51.508857 2026] [security2:error] [pid 521505:tid 521645] [client 20.104.18.15:18345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/htio.php"] [unique_id "apPlx28byYE0iXl--K5u8gAAAyg"]
[Sun Aug 30 03:11:51.513370 2026] [security2:error] [pid 521505:tid 521759] [client 158.23.147.79:40043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-content/banners/about.php"] [unique_id "apPlx28byYE0iXl--K5u9QAAA5o"]
[Sun Aug 30 03:11:51.515745 2026] [security2:error] [pid 521505:tid 521560] [remote 185.93.89.167:21227] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "outlook.mariegronley.com"] [uri "/.env"] [unique_id "apPlx28byYE0iXl--K5u9gADfTY"]
[Sun Aug 30 03:11:51.522580 2026] [security2:error] [pid 521505:tid 521552] [remote 185.93.89.167:49893] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mdm.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5u-AADdS4"]
[Sun Aug 30 03:11:51.524115 2026] [security2:error] [pid 521505:tid 521574] [remote 185.93.89.167:60123] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "up.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5u-wADbUQ"]
[Sun Aug 30 03:11:51.524184 2026] [security2:error] [pid 521505:tid 521576] [remote 185.93.89.167:14991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "barracuda.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlx28byYE0iXl--K5u_AADHkY"]
[Sun Aug 30 03:11:51.524921 2026] [security2:error] [pid 521505:tid 521575] [remote 185.93.89.167:56175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "press.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5u_QADJkU"]
[Sun Aug 30 03:11:51.525662 2026] [security2:error] [pid 521505:tid 521526] [remote 185.93.89.167:9557] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "s4.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5u_wADaRQ"]
[Sun Aug 30 03:11:51.526332 2026] [security2:error] [pid 521505:tid 521557] [remote 185.93.89.167:63579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "wifi.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5vAAADhTM"]
[Sun Aug 30 03:11:51.527105 2026] [security2:error] [pid 521505:tid 521572] [remote 185.93.89.167:5225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "preprod.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5vAQADUEI"]
[Sun Aug 30 03:11:51.527323 2026] [security2:error] [pid 521505:tid 521563] [remote 185.93.89.167:39177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "register.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5vAgADlzk"]
[Sun Aug 30 03:11:51.535866 2026] [security2:error] [pid 521505:tid 521642] [client 20.151.200.44:26505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/zoz.php"] [unique_id "apPlx28byYE0iXl--K5vBgAAAyU"]
[Sun Aug 30 03:11:51.538239 2026] [security2:error] [pid 521505:tid 521588] [remote 185.93.89.167:54151] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "affiliate.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5vCAADfFI"]
[Sun Aug 30 03:11:51.538716 2026] [security2:error] [pid 521505:tid 521527] [remote 185.93.89.167:1591] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlx28byYE0iXl--K5vCQADdBU"]
[Sun Aug 30 03:11:51.541931 2026] [security2:error] [pid 521505:tid 521632] [remote 185.93.89.167:6761] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banner.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5vDgADjn4"]
[Sun Aug 30 03:11:51.545096 2026] [security2:error] [pid 521505:tid 521594] [remote 185.93.89.167:7863] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adserver.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5vEgADT1g"]
[Sun Aug 30 03:11:51.557659 2026] [security2:error] [pid 521505:tid 521597] [remote 185.93.89.167:59215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "users.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlx28byYE0iXl--K5vGAADLls"]
[Sun Aug 30 03:11:51.559794 2026] [security2:error] [pid 521505:tid 521598] [remote 185.93.89.167:45621] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images8.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5vGgADTlw"]
[Sun Aug 30 03:11:51.560450 2026] [security2:error] [pid 521505:tid 521601] [remote 185.93.89.167:24005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "radius.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlx28byYE0iXl--K5vGwADSV8"]
[Sun Aug 30 03:11:51.567825 2026] [security2:error] [pid 521505:tid 521604] [remote 185.93.89.167:24213] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "in.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5vHgADRmI"]
[Sun Aug 30 03:11:51.567839 2026] [security2:error] [pid 521505:tid 521609] [remote 185.93.89.167:62949] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "board.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlx28byYE0iXl--K5vHQADWGc"]
[Sun Aug 30 03:11:51.568031 2026] [security2:error] [pid 521505:tid 521693] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "board.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlx28byYE0iXl--K5vHQADWGc"]
[Sun Aug 30 03:11:51.570229 2026] [security2:error] [pid 521505:tid 521614] [remote 185.93.89.167:48523] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5vIQADbmw"]
[Sun Aug 30 03:11:51.573026 2026] [security2:error] [pid 521505:tid 521610] [remote 185.93.89.167:37521] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5vJAADc2g"]
[Sun Aug 30 03:11:51.573503 2026] [security2:error] [pid 521505:tid 521670] [client 158.23.184.117:19766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/index.php"] [unique_id "apPlx28byYE0iXl--K5vJQAAA0E"]
[Sun Aug 30 03:11:51.574953 2026] [security2:error] [pid 521505:tid 521619] [remote 185.93.89.167:47169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "order.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5vJgADNnE"]
[Sun Aug 30 03:11:51.576620 2026] [security2:error] [pid 521505:tid 521612] [remote 185.93.89.167:16627] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "education.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5vKgADWmo"]
[Sun Aug 30 03:11:51.576718 2026] [security2:error] [pid 521505:tid 521664] [client 20.48.160.90:37658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/filefuns.php"] [unique_id "apPlx28byYE0iXl--K5vKwAAAzs"]
[Sun Aug 30 03:11:51.578032 2026] [security2:error] [pid 521505:tid 521704] [client 20.104.50.220:63227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/xwpg.php"] [unique_id "apPlx28byYE0iXl--K5vLgAAA2M"]
[Sun Aug 30 03:11:51.578952 2026] [security2:error] [pid 521505:tid 521663] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/lab/.env"] [unique_id "apPlx28byYE0iXl--K5vLAAAAzo"]
[Sun Aug 30 03:11:51.582226 2026] [security2:error] [pid 521505:tid 521521] [remote 185.93.89.167:62709] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp3.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5vMgADmw8"]
[Sun Aug 30 03:11:51.587003 2026] [security2:error] [pid 521505:tid 521620] [remote 185.93.89.167:11851] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "biblioteca.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5vNQADj3I"]
[Sun Aug 30 03:11:51.587684 2026] [security2:error] [pid 521505:tid 521621] [remote 185.93.89.167:34607] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sports.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5vNgADanM"]
[Sun Aug 30 03:11:51.592539 2026] [security2:error] [pid 521505:tid 521622] [remote 185.93.89.167:14659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlx28byYE0iXl--K5vOgADXHQ"]
[Sun Aug 30 03:11:51.593388 2026] [security2:error] [pid 521505:tid 521607] [remote 185.93.89.167:1995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lp.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5vPQADnGU"]
[Sun Aug 30 03:11:51.593447 2026] [security2:error] [pid 521505:tid 521623] [remote 185.93.89.167:11225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "da.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5vPAADmnU"]
[Sun Aug 30 03:11:51.598246 2026] [security2:error] [pid 521505:tid 521662] [client 20.104.18.15:22275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/wp-admin/js/wp-load.php"] [unique_id "apPlx28byYE0iXl--K5vQAAAAzk"]
[Sun Aug 30 03:11:51.602605 2026] [security2:error] [pid 521505:tid 521631] [remote 185.93.89.167:29329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mars.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5vQwADk30"]
[Sun Aug 30 03:11:51.604857 2026] [security2:error] [pid 521505:tid 521559] [remote 185.93.89.167:11075] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "redirect.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5vRwADUDU"]
[Sun Aug 30 03:11:51.606252 2026] [security2:error] [pid 521505:tid 521584] [remote 185.93.89.167:42991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "venus.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5vSgADRE4"]
[Sun Aug 30 03:11:51.606334 2026] [security2:error] [pid 521505:tid 521510] [remote 185.93.89.167:3789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vc.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5vSQADhAQ"]
[Sun Aug 30 03:11:51.613137 2026] [security2:error] [pid 521505:tid 521654] [client 128.90.161.20:44484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.161.90.128.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "healthquotemall.com"] [uri "/wp-login.php"] [unique_id "apPlx28byYE0iXl--K5vPwAAAzE"]
[Sun Aug 30 03:11:51.613488 2026] [security2:error] [pid 521505:tid 521633] [remote 185.93.89.167:15177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5vTgADeX8"]
[Sun Aug 30 03:11:51.614509 2026] [security2:error] [pid 521505:tid 521513] [remote 185.93.89.167:45765] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns01.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlx28byYE0iXl--K5vTwADJQc"]
[Sun Aug 30 03:11:51.616894 2026] [security2:error] [pid 521505:tid 521547] [remote 185.93.89.167:13143] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "net.mariegronley.com"] [uri "/.env"] [unique_id "apPlx28byYE0iXl--K5vVAADfCk"]
[Sun Aug 30 03:11:51.617972 2026] [security2:error] [pid 521505:tid 521530] [remote 185.93.89.167:55243] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oldmail.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5vVQADdBg"]
[Sun Aug 30 03:11:51.620007 2026] [security2:error] [pid 521505:tid 521677] [client 20.104.50.220:29124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/blackcat.php"] [unique_id "apPlx28byYE0iXl--K5vVgAAA0g"]
[Sun Aug 30 03:11:51.621763 2026] [security2:error] [pid 521505:tid 521553] [remote 185.93.89.167:36741] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "software.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5vWQADZC8"]
[Sun Aug 30 03:11:51.625850 2026] [security2:error] [pid 521505:tid 521718] [client 20.48.250.41:10966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/s1.php"] [unique_id "apPlx28byYE0iXl--K5vXQAAA3E"]
[Sun Aug 30 03:11:51.628178 2026] [security2:error] [pid 521505:tid 521556] [remote 185.93.89.167:14681] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mc.mariegronley.com"] [uri "/.env"] [unique_id "apPlx28byYE0iXl--K5vXgADfzI"]
[Sun Aug 30 03:11:51.633032 2026] [security2:error] [pid 521505:tid 521524] [remote 185.93.89.167:14833] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "se.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5vYQADjBI"]
[Sun Aug 30 03:11:51.637068 2026] [security2:error] [pid 521505:tid 521683] [client 20.220.10.235:24795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/od.php"] [unique_id "apPlx28byYE0iXl--K5vZgAAA04"]
[Sun Aug 30 03:11:51.638924 2026] [security2:error] [pid 521505:tid 521542] [remote 185.93.89.167:44659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "p.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlx28byYE0iXl--K5vawADWSQ"]
[Sun Aug 30 03:11:51.639473 2026] [security2:error] [pid 521505:tid 521507] [remote 185.93.89.167:27945] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5vbAADmAE"]
[Sun Aug 30 03:11:51.639588 2026] [security2:error] [pid 521505:tid 521548] [remote 185.93.89.167:31113] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "math.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5vbQADbio"]
[Sun Aug 30 03:11:51.640833 2026] [security2:error] [pid 521505:tid 521535] [remote 185.93.89.167:64329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5vbgADSh0"]
[Sun Aug 30 03:11:51.641922 2026] [security2:error] [pid 521505:tid 521570] [remote 185.93.89.167:25969] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dbadmin.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlx28byYE0iXl--K5vcAADNkA"]
[Sun Aug 30 03:11:51.644197 2026] [security2:error] [pid 521505:tid 521565] [remote 185.93.89.167:52789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "market.mariegronley.com"] [uri "/.env"] [unique_id "apPlx28byYE0iXl--K5vcgADgTs"]
[Sun Aug 30 03:11:51.649798 2026] [security2:error] [pid 521505:tid 521628] [remote 185.93.89.167:21227] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "outlook.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlx28byYE0iXl--K5vcwADWno"]
[Sun Aug 30 03:11:51.652411 2026] [security2:error] [pid 521505:tid 521704] [client 20.48.251.3:52173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/paypal.php"] [unique_id "apPlx28byYE0iXl--K5vdAAAA2M"]
[Sun Aug 30 03:11:51.658171 2026] [security2:error] [pid 521505:tid 521554] [remote 185.93.89.167:14991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "barracuda.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlx28byYE0iXl--K5vdwADIDA"]
[Sun Aug 30 03:11:51.659325 2026] [security2:error] [pid 521505:tid 521580] [remote 185.93.89.167:9557] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "s4.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5vegADIUo"]
[Sun Aug 30 03:11:51.660098 2026] [security2:error] [pid 521505:tid 521561] [remote 185.93.89.167:53985] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "img3.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5vfQADMjc"]
[Sun Aug 30 03:11:51.667304 2026] [security2:error] [pid 521505:tid 521567] [remote 185.93.89.167:61033] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5vggADkD0"]
[Sun Aug 30 03:11:51.671996 2026] [security2:error] [pid 521505:tid 521532] [remote 185.93.89.167:54151] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "affiliate.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5vhgADTBo"]
[Sun Aug 30 03:11:51.672244 2026] [security2:error] [pid 521505:tid 521523] [remote 185.93.89.167:1591] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlx28byYE0iXl--K5vhwADfRE"]
[Sun Aug 30 03:11:51.673147 2026] [security2:error] [pid 521505:tid 521682] [client 20.104.18.15:17012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/gos.php"] [unique_id "apPlx28byYE0iXl--K5vigAAA00"]
[Sun Aug 30 03:11:51.673717 2026] [authz_core:error] [pid 521505:tid 521761] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:51.674002 2026] [authz_core:error] [pid 521505:tid 521761] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:51.675511 2026] [security2:error] [pid 521505:tid 521573] [remote 185.93.89.167:23169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5vjAADOUM"]
[Sun Aug 30 03:11:51.675884 2026] [security2:error] [pid 521505:tid 521525] [remote 185.93.89.167:57009] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "static2.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5vjwADaRM"]
[Sun Aug 30 03:11:51.678387 2026] [security2:error] [pid 521505:tid 521550] [remote 185.93.89.167:24307] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tw.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlx28byYE0iXl--K5vkgADZyw"]
[Sun Aug 30 03:11:51.678606 2026] [security2:error] [pid 521505:tid 521537] [remote 185.93.89.167:56429] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mb.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5vkAADkx8"]
[Sun Aug 30 03:11:51.684504 2026] [security2:error] [pid 521505:tid 521577] [remote 185.93.89.167:26309] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "piwik.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlx28byYE0iXl--K5vlAADHkc"]
[Sun Aug 30 03:11:51.691354 2026] [security2:error] [pid 521505:tid 521536] [remote 185.93.89.167:64215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlx28byYE0iXl--K5vlwADeR4"]
[Sun Aug 30 03:11:51.694108 2026] [security2:error] [pid 521505:tid 521522] [remote 185.93.89.167:24005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radius.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlx28byYE0iXl--K5vmQADNxA"]
[Sun Aug 30 03:11:51.694988 2026] [security2:error] [pid 521505:tid 521519] [remote 185.93.89.167:64795] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jp.mariegronley.com"] [uri "/.env"] [unique_id "apPlx28byYE0iXl--K5vmgADNA0"]
[Sun Aug 30 03:11:51.694987 2026] [security2:error] [pid 521505:tid 521590] [remote 185.93.89.167:10845] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "campus.mariegronley.com"] [uri "/.env"] [unique_id "apPlx28byYE0iXl--K5vnAADdFQ"]
[Sun Aug 30 03:11:51.699547 2026] [authz_core:error] [pid 521505:tid 521729] [client 66.249.66.70:63620] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:51.699749 2026] [security2:error] [pid 521505:tid 521698] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/ansible/.env"] [unique_id "apPlx28byYE0iXl--K5vnwAAA10"]
[Sun Aug 30 03:11:51.699969 2026] [authz_core:error] [pid 521505:tid 521729] [client 66.249.66.70:63620] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:51.701277 2026] [security2:error] [pid 521505:tid 521552] [remote 185.93.89.167:62949] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "board.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlx28byYE0iXl--K5voAADOC4"]
[Sun Aug 30 03:11:51.701406 2026] [security2:error] [pid 521505:tid 521661] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "board.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlx28byYE0iXl--K5voAADOC4"]
[Sun Aug 30 03:11:51.704553 2026] [security2:error] [pid 521505:tid 521579] [remote 185.93.89.167:37843] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jupiter.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5vpQADckk"]
[Sun Aug 30 03:11:51.705984 2026] [security2:error] [pid 521505:tid 521557] [remote 185.93.89.167:42995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns12.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5vpgADijM"]
[Sun Aug 30 03:11:51.706346 2026] [security2:error] [pid 521505:tid 521572] [remote 185.93.89.167:37521] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5vqAADI0I"]
[Sun Aug 30 03:11:51.714220 2026] [security2:error] [pid 521505:tid 521589] [remote 185.93.89.167:39923] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sitebuilder.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5vqwADcVM"]
[Sun Aug 30 03:11:51.714274 2026] [security2:error] [pid 521505:tid 521759] [client 158.23.184.117:19639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/cgi-bin/index.php"] [unique_id "apPlx28byYE0iXl--K5vrQAAA5o"]
[Sun Aug 30 03:11:51.714547 2026] [security2:error] [pid 521505:tid 521630] [remote 185.93.89.167:63379] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reviews.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5vrAADf3w"]
[Sun Aug 30 03:11:51.716256 2026] [security2:error] [pid 521505:tid 521658] [client 40.83.93.50:10707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.93.83.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.thebelgradegroup.com"] [uri "/lock.php"] [unique_id "apPlx28byYE0iXl--K5vrwAAAzU"]
[Sun Aug 30 03:11:51.719923 2026] [security2:error] [pid 521505:tid 521586] [remote 185.93.89.167:36485] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shopping.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlx28byYE0iXl--K5vsQADW1A"]
[Sun Aug 30 03:11:51.720387 2026] [security2:error] [pid 521505:tid 521545] [remote 185.93.89.167:11851] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "biblioteca.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5vsgADTic"]
[Sun Aug 30 03:11:51.725531 2026] [security2:error] [pid 521505:tid 521632] [remote 185.93.89.167:14659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "otrs.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlx28byYE0iXl--K5vtAADWH4"]
[Sun Aug 30 03:11:51.726340 2026] [security2:error] [pid 521505:tid 521569] [remote 185.93.89.167:15109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "linux.mariegronley.com"] [uri "/.env"] [unique_id "apPlx28byYE0iXl--K5vtQADKj8"]
[Sun Aug 30 03:11:51.727263 2026] [security2:error] [pid 521505:tid 521594] [remote 185.93.89.167:11225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "da.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5vtgADSVg"]
[Sun Aug 30 03:11:51.727842 2026] [security2:error] [pid 521505:tid 521592] [remote 185.93.89.167:8597] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "drupal.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5vtwADWVY"]
[Sun Aug 30 03:11:51.738512 2026] [security2:error] [pid 521505:tid 521597] [remote 185.93.89.167:37291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "st.mariegronley.com"] [uri "/.env"] [unique_id "apPlx28byYE0iXl--K5vvQADSls"]
[Sun Aug 30 03:11:51.738586 2026] [security2:error] [pid 521505:tid 521598] [remote 185.93.89.167:59097] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web6.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5vwAADgVw"]
[Sun Aug 30 03:11:51.739258 2026] [security2:error] [pid 521505:tid 521664] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/cronlab/.env"] [unique_id "apPlx28byYE0iXl--K5vwgAAAzs"]
[Sun Aug 30 03:11:51.741372 2026] [security2:error] [pid 521505:tid 521605] [remote 185.93.89.167:3789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vc.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5vxgADO2M"]
[Sun Aug 30 03:11:51.748389 2026] [security2:error] [pid 521505:tid 521602] [remote 185.93.89.167:45765] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns01.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlx28byYE0iXl--K5vzAADj2A"]
[Sun Aug 30 03:11:51.750335 2026] [security2:error] [pid 521505:tid 521613] [remote 185.93.89.167:13143] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "net.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlx28byYE0iXl--K5vzwADa2s"]
[Sun Aug 30 03:11:51.761758 2026] [security2:error] [pid 521505:tid 521616] [remote 185.93.89.167:14681] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mc.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlx28byYE0iXl--K5v2gADbW4"]
[Sun Aug 30 03:11:51.766927 2026] [security2:error] [pid 521505:tid 521621] [remote 185.93.89.167:14833] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "se.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5v3AADk3M"]
[Sun Aug 30 03:11:51.767733 2026] [security2:error] [pid 521505:tid 521622] [remote 185.93.89.167:4287] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "php.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5v3QADYnQ"]
[Sun Aug 30 03:11:51.768011 2026] [security2:error] [pid 521505:tid 521607] [remote 185.93.89.167:13069] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sc.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5v4AADRGU"]
[Sun Aug 30 03:11:51.771903 2026] [security2:error] [pid 521505:tid 521623] [remote 185.93.89.167:53853] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atlas.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5v4QADlHU"]
[Sun Aug 30 03:11:51.772032 2026] [security2:error] [pid 521505:tid 521516] [remote 185.93.89.167:44659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlx28byYE0iXl--K5v4wADHgo"]
[Sun Aug 30 03:11:51.772532 2026] [security2:error] [pid 521505:tid 521508] [remote 185.93.89.167:40249] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tracking.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5v4gADlwI"]
[Sun Aug 30 03:11:51.772823 2026] [security2:error] [pid 521505:tid 521624] [remote 185.93.89.167:2579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "love.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5v5QADhHY"]
[Sun Aug 30 03:11:51.773614 2026] [security2:error] [pid 521505:tid 521625] [remote 185.93.89.167:29333] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reg.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5v5wADeXc"]
[Sun Aug 30 03:11:51.776107 2026] [security2:error] [pid 521505:tid 521584] [remote 185.93.89.167:25969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dbadmin.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlx28byYE0iXl--K5v6gADMU4"]
[Sun Aug 30 03:11:51.777362 2026] [security2:error] [pid 521505:tid 521511] [remote 185.93.89.167:52789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "market.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlx28byYE0iXl--K5v6wADdAU"]
[Sun Aug 30 03:11:51.779036 2026] [security2:error] [pid 521505:tid 521665] [client 20.220.10.235:24742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/wp-the.php"] [unique_id "apPlx28byYE0iXl--K5v7AAAAzw"]
[Sun Aug 30 03:11:51.782231 2026] [security2:error] [pid 521505:tid 521510] [remote 185.93.89.167:4349] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mm.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5v7gADZQQ"]
[Sun Aug 30 03:11:51.783080 2026] [security2:error] [pid 521505:tid 521633] [remote 185.93.89.167:21227] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "outlook.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlx28byYE0iXl--K5v7wADdX8"]
[Sun Aug 30 03:11:51.791405 2026] [security2:error] [pid 521505:tid 521513] [remote 185.93.89.167:14991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "barracuda.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlx28byYE0iXl--K5v8wADPwc"]
[Sun Aug 30 03:11:51.792791 2026] [security2:error] [pid 521505:tid 521531] [remote 185.93.89.167:56175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "press.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5v9QADTxk"]
[Sun Aug 30 03:11:51.793740 2026] [security2:error] [pid 521505:tid 521520] [remote 185.93.89.167:53985] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "img3.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5v9wADUw4"]
[Sun Aug 30 03:11:51.793880 2026] [security2:error] [pid 521505:tid 521541] [remote 185.93.89.167:62859] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mailgw.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlx28byYE0iXl--K5v-AADciM"]
[Sun Aug 30 03:11:51.795494 2026] [security2:error] [pid 521505:tid 521553] [remote 185.93.89.167:39177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "register.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5v-gADji8"]
[Sun Aug 30 03:11:51.796330 2026] [security2:error] [pid 521505:tid 521506] [remote 185.93.89.167:5225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "preprod.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5v-wADigA"]
[Sun Aug 30 03:11:51.801222 2026] [security2:error] [pid 521505:tid 521556] [remote 185.93.89.167:61033] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5v_AADVDI"]
[Sun Aug 30 03:11:51.804484 2026] [security2:error] [pid 521505:tid 521524] [remote 185.93.89.167:53363] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "work.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5v_gADiBI"]
[Sun Aug 30 03:11:51.805296 2026] [security2:error] [pid 521505:tid 521549] [remote 185.93.89.167:1591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thumbs.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlx28byYE0iXl--K5v_wADjCs"]
[Sun Aug 30 03:11:51.807508 2026] [security2:error] [pid 521505:tid 521555] [remote 185.93.89.167:37133] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5wAQADLjE"]
[Sun Aug 30 03:11:51.808959 2026] [security2:error] [pid 521505:tid 521533] [remote 185.93.89.167:23169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5wAgADQhs"]
[Sun Aug 30 03:11:51.810383 2026] [security2:error] [pid 521505:tid 521562] [remote 185.93.89.167:30871] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pro.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlx28byYE0iXl--K5wBQADjTg"]
[Sun Aug 30 03:11:51.811801 2026] [security2:error] [pid 521505:tid 521507] [remote 185.93.89.167:56429] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mb.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5wBwADQAE"]
[Sun Aug 30 03:11:51.812898 2026] [security2:error] [pid 521505:tid 521548] [remote 185.93.89.167:7863] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adserver.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5wCAADQyo"]
[Sun Aug 30 03:11:51.823227 2026] [security2:error] [pid 521505:tid 521535] [remote 185.93.89.167:42909] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "direct.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlx28byYE0iXl--K5wCwADSR0"]
[Sun Aug 30 03:11:51.828422 2026] [security2:error] [pid 521505:tid 521544] [remote 185.93.89.167:64795] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jp.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlx28byYE0iXl--K5wEAADUiY"]
[Sun Aug 30 03:11:51.828433 2026] [security2:error] [pid 521505:tid 521554] [remote 185.93.89.167:10845] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "campus.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlx28byYE0iXl--K5wEQADbjA"]
[Sun Aug 30 03:11:51.831117 2026] [security2:error] [pid 521505:tid 521540] [remote 185.93.89.167:54367] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webservices.mariegronley.com"] [uri "/.env"] [unique_id "apPlx28byYE0iXl--K5wEgADNiI"]
[Sun Aug 30 03:11:51.834366 2026] [security2:error] [pid 521505:tid 521580] [remote 185.93.89.167:62949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "board.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlx28byYE0iXl--K5wEwADh0o"]
[Sun Aug 30 03:11:51.834498 2026] [security2:error] [pid 521505:tid 521740] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "board.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlx28byYE0iXl--K5wEwADh0o"]
[Sun Aug 30 03:11:51.837351 2026] [security2:error] [pid 521505:tid 521568] [remote 185.93.89.167:24213] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "in.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5wFAADWj4"]
[Sun Aug 30 03:11:51.837877 2026] [security2:error] [pid 521505:tid 521561] [remote 185.93.89.167:7437] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images7.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlx28byYE0iXl--K5wFQADUTc"]
[Sun Aug 30 03:11:51.837950 2026] [security2:error] [pid 521505:tid 521582] [remote 185.93.89.167:37843] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jupiter.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5wFgADSkw"]
[Sun Aug 30 03:11:51.838814 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:59907] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "health.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlx28byYE0iXl--K5wGAADS00"]
[Sun Aug 30 03:11:51.844828 2026] [security2:error] [pid 521505:tid 521532] [remote 185.93.89.167:16627] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "education.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5wHAADYxo"]
[Sun Aug 30 03:11:51.848308 2026] [security2:error] [pid 521505:tid 521523] [remote 185.93.89.167:39923] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sitebuilder.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5wHQADOhE"]
[Sun Aug 30 03:11:51.848319 2026] [security2:error] [pid 521505:tid 521629] [remote 185.93.89.167:63379] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reviews.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5wHgADIXs"]
[Sun Aug 30 03:11:51.853708 2026] [security2:error] [pid 521505:tid 521733] [client 20.48.160.90:37712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp-cron.php"] [unique_id "apPlx28byYE0iXl--K5wIwAAA4A"]
[Sun Aug 30 03:11:51.854306 2026] [security2:error] [pid 521505:tid 521550] [remote 185.93.89.167:34357] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banners.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5wJAADMiw"]
[Sun Aug 30 03:11:51.854818 2026] [security2:error] [pid 521505:tid 521658] [client 158.23.184.117:19589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/cgi-bin/load.php"] [unique_id "apPlx28byYE0iXl--K5wJQAAAzU"]
[Sun Aug 30 03:11:51.854833 2026] [security2:error] [pid 521505:tid 521757] [client 20.48.250.41:10965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/0byte.php"] [unique_id "apPlx28byYE0iXl--K5wJgAAA5g"]
[Sun Aug 30 03:11:51.859557 2026] [security2:error] [pid 521505:tid 521577] [remote 185.93.89.167:15109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "linux.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlx28byYE0iXl--K5wKQADlkc"]
[Sun Aug 30 03:11:51.870486 2026] [security2:error] [pid 521505:tid 521585] [remote 185.93.89.167:18729] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ntp1.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlx28byYE0iXl--K5wLQADgk8"]
[Sun Aug 30 03:11:51.872223 2026] [security2:error] [pid 521505:tid 521519] [remote 185.93.89.167:59097] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web6.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5wLwADag0"]
[Sun Aug 30 03:11:51.872283 2026] [security2:error] [pid 521505:tid 521578] [remote 185.93.89.167:37291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "st.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlx28byYE0iXl--K5wLgADRUg"]
[Sun Aug 30 03:11:51.873751 2026] [security2:error] [pid 521505:tid 521552] [remote 185.93.89.167:9731] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images5.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5wMwADTC4"]
[Sun Aug 30 03:11:51.874497 2026] [security2:error] [pid 521505:tid 521560] [remote 185.93.89.167:11075] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "redirect.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5wMgADfTY"]
[Sun Aug 30 03:11:51.874798 2026] [security2:error] [pid 521505:tid 521518] [remote 185.93.89.167:16669] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "links.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5wNAADTAw"]
[Sun Aug 30 03:11:51.875497 2026] [security2:error] [pid 521505:tid 521576] [remote 185.93.89.167:42991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "venus.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5wNgADJkY"]
[Sun Aug 30 03:11:51.876257 2026] [security2:error] [pid 521505:tid 521714] [client 158.23.147.79:39976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apPlx28byYE0iXl--K5wOAAAA20"]
[Sun Aug 30 03:11:51.881757 2026] [security2:error] [pid 521505:tid 521579] [remote 185.93.89.167:45765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns01.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlx28byYE0iXl--K5wPAADKEk"]
[Sun Aug 30 03:11:51.882437 2026] [security2:error] [pid 521505:tid 521526] [remote 185.93.89.167:41989] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ipfixe.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlx28byYE0iXl--K5wPQADIBQ"]
[Sun Aug 30 03:11:51.883249 2026] [security2:error] [pid 521505:tid 521575] [remote 185.93.89.167:62291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rs.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5wPgADREU"]
[Sun Aug 30 03:11:51.883737 2026] [security2:error] [pid 521505:tid 521557] [remote 185.93.89.167:13143] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "net.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlx28byYE0iXl--K5wQAADcDM"]
[Sun Aug 30 03:11:51.884053 2026] [security2:error] [pid 521505:tid 521572] [remote 185.93.89.167:22281] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "labs.mariegronley.com"] [uri "/.env"] [unique_id "apPlx28byYE0iXl--K5wQQADlEI"]
[Sun Aug 30 03:11:51.884823 2026] [security2:error] [pid 521505:tid 521563] [remote 185.93.89.167:28567] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "user.mariegronley.com"] [uri "/.env"] [unique_id "apPlx28byYE0iXl--K5wQwADhDk"]
[Sun Aug 30 03:11:51.885800 2026] [security2:error] [pid 521505:tid 521589] [remote 185.93.89.167:10145] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "g.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlx28byYE0iXl--K5wRQADJFM"]
[Sun Aug 30 03:11:51.886119 2026] [security2:error] [pid 521505:tid 521630] [remote 185.93.89.167:50005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fax.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5wRgADJXw"]
[Sun Aug 30 03:11:51.886387 2026] [security2:error] [pid 521505:tid 521588] [remote 185.93.89.167:1175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pgsql.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlx28byYE0iXl--K5wRwADPFI"]
[Sun Aug 30 03:11:51.886408 2026] [security2:error] [pid 521505:tid 521587] [remote 185.93.89.167:32655] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lync.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5wRAADkVE"]
[Sun Aug 30 03:11:51.886859 2026] [security2:error] [pid 521505:tid 521586] [remote 185.93.89.167:55243] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oldmail.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5wSAADZVA"]
[Sun Aug 30 03:11:51.890165 2026] [security2:error] [pid 521505:tid 521545] [remote 185.93.89.167:36741] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "software.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5wSwADdSc"]
[Sun Aug 30 03:11:51.890806 2026] [security2:error] [pid 521505:tid 521527] [remote 185.93.89.167:57109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "development.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlx28byYE0iXl--K5wTAADPxU"]
[Sun Aug 30 03:11:51.895145 2026] [security2:error] [pid 521505:tid 521569] [remote 185.93.89.167:14681] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mc.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlx28byYE0iXl--K5wUAADOD8"]
[Sun Aug 30 03:11:51.899268 2026] [security2:error] [pid 521505:tid 521719] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/.git/.env"] [unique_id "apPlx28byYE0iXl--K5wVAAAA3I"]
[Sun Aug 30 03:11:51.902567 2026] [security2:error] [pid 521505:tid 521617] [remote 185.93.89.167:14453] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5wWAADI28"]
[Sun Aug 30 03:11:51.902893 2026] [security2:error] [pid 521505:tid 521741] [client 35.247.242.193:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/cron/.env"] [unique_id "apPlx28byYE0iXl--K5wWQAAA4g"]
[Sun Aug 30 03:11:51.905868 2026] [security2:error] [pid 521505:tid 521591] [remote 185.93.89.167:40249] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tracking.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5wXAADf1U"]
[Sun Aug 30 03:11:51.907077 2026] [security2:error] [pid 521505:tid 521651] [client 20.104.18.15:2019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/wsd.php"] [unique_id "apPlx28byYE0iXl--K5wYQAAAy4"]
[Sun Aug 30 03:11:51.910181 2026] [security2:error] [pid 521505:tid 521669] [client 68.155.159.216:52563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apPlx28byYE0iXl--K5wZAAAA0A"]
[Sun Aug 30 03:11:51.910893 2026] [security2:error] [pid 521505:tid 521601] [remote 185.93.89.167:52789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "market.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlx28byYE0iXl--K5wZQADQ18"]
[Sun Aug 30 03:11:51.916112 2026] [security2:error] [pid 521505:tid 521603] [remote 185.93.89.167:21227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "outlook.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlx28byYE0iXl--K5waAADWWE"]
[Sun Aug 30 03:11:51.916672 2026] [security2:error] [pid 521505:tid 521613] [remote 185.93.89.167:3495] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5waQADdms"]
[Sun Aug 30 03:11:51.922002 2026] [security2:error] [pid 521505:tid 521614] [remote 185.93.89.167:4349] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mm.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5wawADg2w"]
[Sun Aug 30 03:11:51.926427 2026] [security2:error] [pid 521505:tid 521610] [remote 185.93.89.167:49893] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mdm.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5wcAADSmg"]
[Sun Aug 30 03:11:51.927042 2026] [security2:error] [pid 521505:tid 521606] [remote 185.93.89.167:60123] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "up.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5wcQADS2Q"]
[Sun Aug 30 03:11:51.928037 2026] [security2:error] [pid 521505:tid 521680] [client 20.220.10.235:24677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/wt.php"] [unique_id "apPlx28byYE0iXl--K5wdwAAA0s"]
[Sun Aug 30 03:11:51.928469 2026] [security2:error] [pid 521505:tid 521521] [remote 185.93.89.167:63579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "wifi.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5weAADlQ8"]
[Sun Aug 30 03:11:51.937774 2026] [security2:error] [pid 521505:tid 521622] [remote 185.93.89.167:53363] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "work.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5wfQADPnQ"]
[Sun Aug 30 03:11:51.941520 2026] [security2:error] [pid 521505:tid 521626] [remote 185.93.89.167:37133] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlx28byYE0iXl--K5wfwADX3g"]
[Sun Aug 30 03:11:51.945147 2026] [security2:error] [pid 521505:tid 521625] [remote 185.93.89.167:6761] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banner.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5whAADVXc"]
[Sun Aug 30 03:11:51.954847 2026] [security2:error] [pid 521505:tid 521728] [client 20.197.61.180:3262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/upgrade-temp-backup/themes/login.php"] [unique_id "apPlx28byYE0iXl--K5wiQAAA3s"]
[Sun Aug 30 03:11:51.962596 2026] [security2:error] [pid 521505:tid 521513] [remote 185.93.89.167:59215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "users.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlx28byYE0iXl--K5wkQADJAc"]
[Sun Aug 30 03:11:51.962597 2026] [security2:error] [pid 521505:tid 521633] [remote 185.93.89.167:10845] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "campus.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlx28byYE0iXl--K5wkAADhH8"]
[Sun Aug 30 03:11:51.962685 2026] [security2:error] [pid 521505:tid 521510] [remote 185.93.89.167:64795] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jp.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlx28byYE0iXl--K5wjwADeQQ"]
[Sun Aug 30 03:11:51.962698 2026] [security2:error] [pid 521505:tid 521531] [remote 185.93.89.167:45621] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images8.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlx28byYE0iXl--K5wkgADJRk"]
[Sun Aug 30 03:11:51.964771 2026] [security2:error] [pid 521505:tid 521547] [remote 185.93.89.167:54367] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webservices.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlx28byYE0iXl--K5wlQADZSk"]
[Sun Aug 30 03:11:51.971538 2026] [security2:error] [pid 521505:tid 521661] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "board.mariegronley.com"] [uri "/index.cgi"] [unique_id "apPlx28byYE0iXl--K5wmAADOA4"]
[Sun Aug 30 03:11:51.972478 2026] [authz_core:error] [pid 521505:tid 521722] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory21
[Sun Aug 30 03:11:51.972820 2026] [authz_core:error] [pid 521505:tid 521722] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory21
[Sun Aug 30 03:11:51.973549 2026] [security2:error] [pid 521505:tid 521506] [remote 185.93.89.167:48523] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlx28byYE0iXl--K5woAADfwA"]
[Sun Aug 30 03:11:51.976077 2026] [security2:error] [pid 521505:tid 521524] [remote 185.93.89.167:37521] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlx28byYE0iXl--K5wogADSBI"]
[Sun Aug 30 03:11:51.978699 2026] [security2:error] [pid 521505:tid 521555] [remote 185.93.89.167:47169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "order.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlx28byYE0iXl--K5wpAADcTE"]
[Sun Aug 30 03:11:51.980859 2026] [security2:error] [pid 521505:tid 521746] [client 20.48.250.41:11102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/xr.php"] [unique_id "apPlx28byYE0iXl--K5wpQAAA40"]
[Sun Aug 30 03:11:51.985936 2026] [security2:error] [pid 521505:tid 521562] [remote 185.93.89.167:62709] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp3.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlx28byYE0iXl--K5wqAADQzg"]
[Sun Aug 30 03:11:51.987502 2026] [security2:error] [pid 521505:tid 521538] [remote 185.93.89.167:34357] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banners.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlx28byYE0iXl--K5wqQADSSA"]
[Sun Aug 30 03:11:51.991114 2026] [security2:error] [pid 521505:tid 521548] [remote 185.93.89.167:34607] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sports.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlx28byYE0iXl--K5wrAADUio"]
[Sun Aug 30 03:11:51.992936 2026] [security2:error] [pid 521505:tid 521564] [remote 185.93.89.167:15109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "linux.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlx28byYE0iXl--K5wrgADgzo"]
[Sun Aug 30 03:11:52.001180 2026] [security2:error] [pid 521505:tid 521544] [remote 185.93.89.167:1995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lp.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlx28byYE0iXl--K5wtAADYyY"]
[Sun Aug 30 03:11:52.003093 2026] [security2:error] [pid 521505:tid 521680] [client 4.205.62.107:29133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/ws61.php"] [unique_id "apPlyG8byYE0iXl--K5wuAAAA0s"]
[Sun Aug 30 03:11:52.005938 2026] [security2:error] [pid 521505:tid 521565] [remote 185.93.89.167:37291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "st.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlyG8byYE0iXl--K5wugADUTs"]
[Sun Aug 30 03:11:52.007075 2026] [security2:error] [pid 521505:tid 521540] [remote 185.93.89.167:29329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mars.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K5wvAADlSI"]
[Sun Aug 30 03:11:52.007278 2026] [security2:error] [pid 521505:tid 521580] [remote 185.93.89.167:9731] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images5.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5wvQADO0o"]
[Sun Aug 30 03:11:52.008146 2026] [security2:error] [pid 521505:tid 521561] [remote 185.93.89.167:16669] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "links.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5wvwADITc"]
[Sun Aug 30 03:11:52.010736 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:3789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vc.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5wwQADgU0"]
[Sun Aug 30 03:11:52.013719 2026] [security2:error] [pid 521505:tid 521753] [client 158.23.184.117:19717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/cgi-bin/ms-files.php"] [unique_id "apPlyG8byYE0iXl--K5wxAAAA5Q"]
[Sun Aug 30 03:11:52.016142 2026] [authz_core:error] [pid 521505:tid 521717] [client 66.249.66.45:53812] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:52.016432 2026] [authz_core:error] [pid 521505:tid 521717] [client 66.249.66.45:53812] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:52.016916 2026] [security2:error] [pid 521505:tid 521567] [remote 185.93.89.167:13143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "net.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlyG8byYE0iXl--K5wxwADjz0"]
[Sun Aug 30 03:11:52.017635 2026] [security2:error] [pid 521505:tid 521532] [remote 185.93.89.167:22281] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "labs.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlyG8byYE0iXl--K5wyAADMho"]
[Sun Aug 30 03:11:52.018667 2026] [security2:error] [pid 521505:tid 521558] [remote 185.93.89.167:28567] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "user.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlyG8byYE0iXl--K5wygADmDQ"]
[Sun Aug 30 03:11:52.019630 2026] [security2:error] [pid 521505:tid 521629] [remote 185.93.89.167:50005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fax.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5wzAADa3s"]
[Sun Aug 30 03:11:52.019676 2026] [security2:error] [pid 521505:tid 521525] [remote 185.93.89.167:32655] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lync.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5wzQADbhM"]
[Sun Aug 30 03:11:52.022815 2026] [security2:error] [pid 521505:tid 521581] [remote 185.93.89.167:62291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rs.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlyG8byYE0iXl--K5w0gADaks"]
[Sun Aug 30 03:11:52.024309 2026] [security2:error] [pid 521505:tid 521730] [client 20.104.50.220:61691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/file21.php"] [unique_id "apPlyG8byYE0iXl--K5w1gAAA30"]
[Sun Aug 30 03:11:52.028394 2026] [security2:error] [pid 521505:tid 521571] [remote 185.93.89.167:14681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mc.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlyG8byYE0iXl--K5w2AADm0E"]
[Sun Aug 30 03:11:52.034510 2026] [security2:error] [pid 521505:tid 521737] [client 4.205.62.107:27004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/pouhg.php"] [unique_id "apPlyG8byYE0iXl--K5w2wAAA4Q"]
[Sun Aug 30 03:11:52.034828 2026] [security2:error] [pid 521505:tid 521528] [remote 185.93.89.167:15177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K5w2gADJBY"]
[Sun Aug 30 03:11:52.036105 2026] [security2:error] [pid 521505:tid 521585] [remote 185.93.89.167:14453] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5w3wADkU8"]
[Sun Aug 30 03:11:52.041811 2026] [security2:error] [pid 521505:tid 521518] [remote 185.93.89.167:27945] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K5w5wADXQw"]
[Sun Aug 30 03:11:52.043004 2026] [security2:error] [pid 521505:tid 521576] [remote 185.93.89.167:31113] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "math.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5w6QADikY"]
[Sun Aug 30 03:11:52.043412 2026] [security2:error] [pid 521505:tid 521574] [remote 185.93.89.167:64329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K5w6gADSEQ"]
[Sun Aug 30 03:11:52.043865 2026] [security2:error] [pid 521505:tid 521579] [remote 185.93.89.167:52789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "market.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlyG8byYE0iXl--K5w6wADaEk"]
[Sun Aug 30 03:11:52.057178 2026] [security2:error] [pid 521505:tid 521557] [remote 185.93.89.167:3495] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5w8AADWzM"]
[Sun Aug 30 03:11:52.060244 2026] [security2:error] [pid 521505:tid 521572] [remote 185.93.89.167:49893] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mdm.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5w8wADWUI"]
[Sun Aug 30 03:11:52.060837 2026] [security2:error] [pid 521505:tid 521563] [remote 185.93.89.167:60123] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "up.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5w9QADbzk"]
[Sun Aug 30 03:11:52.062167 2026] [security2:error] [pid 521505:tid 521586] [remote 185.93.89.167:63579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "wifi.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5w-wADkFA"]
[Sun Aug 30 03:11:52.063484 2026] [security2:error] [pid 521505:tid 521527] [remote 185.93.89.167:9557] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "s4.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K5w_QADhxU"]
[Sun Aug 30 03:11:52.063594 2026] [security2:error] [pid 521505:tid 521545] [remote 185.93.89.167:53985] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "img3.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5w_AADUSc"]
[Sun Aug 30 03:11:52.066045 2026] [security2:error] [pid 521505:tid 521720] [client 20.220.10.235:24786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/im.php"] [unique_id "apPlyG8byYE0iXl--K5xAgAAA3M"]
[Sun Aug 30 03:11:52.076988 2026] [security2:error] [pid 521505:tid 521597] [remote 185.93.89.167:54151] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "affiliate.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K5xDQADals"]
[Sun Aug 30 03:11:52.078607 2026] [security2:error] [pid 521505:tid 521600] [remote 185.93.89.167:6761] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banner.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5xEAADKl4"]
[Sun Aug 30 03:11:52.079411 2026] [security2:error] [pid 521505:tid 521605] [remote 185.93.89.167:57009] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "static2.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5xEQADH2M"]
[Sun Aug 30 03:11:52.088510 2026] [security2:error] [pid 521505:tid 521685] [client 20.104.50.220:17308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/la.php"] [unique_id "apPlyG8byYE0iXl--K5xGQAAA1A"]
[Sun Aug 30 03:11:52.095755 2026] [security2:error] [pid 521505:tid 521606] [remote 185.93.89.167:64795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jp.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlyG8byYE0iXl--K5xHgADMWQ"]
[Sun Aug 30 03:11:52.095943 2026] [security2:error] [pid 521505:tid 521551] [remote 185.93.89.167:10845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "campus.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlyG8byYE0iXl--K5xIAADHi0"]
[Sun Aug 30 03:11:52.096138 2026] [security2:error] [pid 521505:tid 521610] [remote 185.93.89.167:59215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "users.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlyG8byYE0iXl--K5xHQADYmg"]
[Sun Aug 30 03:11:52.098321 2026] [security2:error] [pid 521505:tid 521612] [remote 185.93.89.167:24005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "radius.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlyG8byYE0iXl--K5xIgADMGo"]
[Sun Aug 30 03:11:52.098456 2026] [security2:error] [pid 521505:tid 521614] [remote 185.93.89.167:54367] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webservices.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlyG8byYE0iXl--K5xIQADJGw"]
[Sun Aug 30 03:11:52.098930 2026] [security2:error] [pid 521505:tid 521750] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/ci/.env"] [unique_id "apPlyG8byYE0iXl--K5xIwAAA5E"]
[Sun Aug 30 03:11:52.100981 2026] [authz_core:error] [pid 521505:tid 521723] [client 66.249.66.65:58349] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:52.101421 2026] [authz_core:error] [pid 521505:tid 521723] [client 66.249.66.65:58349] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:52.106848 2026] [security2:error] [pid 521505:tid 521616] [remote 185.93.89.167:37843] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jupiter.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5xKAADfm4"]
[Sun Aug 30 03:11:52.107293 2026] [security2:error] [pid 521505:tid 521726] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "board.mariegronley.com"] [uri "/index.cgi"] [unique_id "apPlyG8byYE0iXl--K5xJAADeXE"]
[Sun Aug 30 03:11:52.108589 2026] [security2:error] [pid 521505:tid 521626] [remote 185.93.89.167:42995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns12.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5xKwADjHg"]
[Sun Aug 30 03:11:52.116401 2026] [security2:error] [pid 521505:tid 521625] [remote 185.93.89.167:63379] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reviews.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5xLwADinc"]
[Sun Aug 30 03:11:52.123392 2026] [security2:error] [pid 521505:tid 521543] [remote 185.93.89.167:11851] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "biblioteca.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K5xNAADnCU"]
[Sun Aug 30 03:11:52.123901 2026] [security2:error] [pid 521505:tid 521746] [client 158.23.147.79:16345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPlyG8byYE0iXl--K5xNQAAA40"]
[Sun Aug 30 03:11:52.125885 2026] [security2:error] [pid 521505:tid 521627] [remote 185.93.89.167:15109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "linux.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlyG8byYE0iXl--K5xNwADW3k"]
[Sun Aug 30 03:11:52.130000 2026] [security2:error] [pid 521505:tid 521513] [remote 185.93.89.167:14659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlyG8byYE0iXl--K5xOgADlgc"]
[Sun Aug 30 03:11:52.131332 2026] [security2:error] [pid 521505:tid 521633] [remote 185.93.89.167:8597] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "drupal.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5xOwADTn8"]
[Sun Aug 30 03:11:52.131980 2026] [security2:error] [pid 521505:tid 521510] [remote 185.93.89.167:11225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "da.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K5xPAADNgQ"]
[Sun Aug 30 03:11:52.135577 2026] [security2:error] [pid 521505:tid 521531] [remote 185.93.89.167:1995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lp.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5xPgADWRk"]
[Sun Aug 30 03:11:52.137798 2026] [security2:error] [pid 521505:tid 521547] [remote 185.93.89.167:11687] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pr.mariegronley.com"] [uri "/.env"] [unique_id "apPlyG8byYE0iXl--K5xPwADbyk"]
[Sun Aug 30 03:11:52.139151 2026] [security2:error] [pid 521505:tid 521520] [remote 185.93.89.167:37291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "st.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlyG8byYE0iXl--K5xQQADkA4"]
[Sun Aug 30 03:11:52.141052 2026] [security2:error] [pid 521505:tid 521530] [remote 185.93.89.167:29329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mars.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5xQwADOxg"]
[Sun Aug 30 03:11:52.152252 2026] [security2:error] [pid 521505:tid 521533] [remote 185.93.89.167:28567] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "user.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlyG8byYE0iXl--K5xTgADURs"]
[Sun Aug 30 03:11:52.152484 2026] [security2:error] [pid 521505:tid 521719] [client 158.23.184.117:19599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/cgi-bin/wp-activate.php"] [unique_id "apPlyG8byYE0iXl--K5xTwAAA3I"]
[Sun Aug 30 03:11:52.152992 2026] [security2:error] [pid 521505:tid 521549] [remote 185.93.89.167:22281] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "labs.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlyG8byYE0iXl--K5xTQADIys"]
[Sun Aug 30 03:11:52.156008 2026] [security2:error] [pid 521505:tid 521722] [client 20.48.250.41:10981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/h02ugyh.php"] [unique_id "apPlyG8byYE0iXl--K5xVwAAA3U"]
[Sun Aug 30 03:11:52.158810 2026] [security2:error] [pid 521505:tid 521733] [client 4.205.62.107:17336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/paypal.php"] [unique_id "apPlyG8byYE0iXl--K5xWwAAA4A"]
[Sun Aug 30 03:11:52.162932 2026] [security2:error] [pid 521505:tid 521670] [client 20.48.251.3:64286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/66.php"] [unique_id "apPlyG8byYE0iXl--K5xXwAAA0E"]
[Sun Aug 30 03:11:52.163627 2026] [authz_core:error] [pid 521505:tid 521720] [client 216.73.216.128:23116] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:52.163896 2026] [authz_core:error] [pid 521505:tid 521720] [client 216.73.216.128:23116] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:52.170889 2026] [security2:error] [pid 521505:tid 521565] [remote 185.93.89.167:13069] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sc.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5xZAADVTs"]
[Sun Aug 30 03:11:52.171048 2026] [security2:error] [pid 521505:tid 521628] [remote 185.93.89.167:14833] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "se.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K5xYwADH3o"]
[Sun Aug 30 03:11:52.171482 2026] [security2:error] [pid 521505:tid 521554] [remote 185.93.89.167:4287] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "php.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5xYgADZzA"]
[Sun Aug 30 03:11:52.174462 2026] [security2:error] [pid 521505:tid 521540] [remote 185.93.89.167:40249] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tracking.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5xZwADdyI"]
[Sun Aug 30 03:11:52.174560 2026] [security2:error] [pid 521505:tid 521517] [remote 185.93.89.167:15177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5xZgADIAs"]
[Sun Aug 30 03:11:52.175543 2026] [security2:error] [pid 521505:tid 521561] [remote 185.93.89.167:53853] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atlas.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5xaQADkzc"]
[Sun Aug 30 03:11:52.175948 2026] [security2:error] [pid 521505:tid 521580] [remote 185.93.89.167:27945] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5xaAADX0o"]
[Sun Aug 30 03:11:52.176511 2026] [security2:error] [pid 521505:tid 521568] [remote 185.93.89.167:2579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "love.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5xagADmT4"]
[Sun Aug 30 03:11:52.177093 2026] [security2:error] [pid 521505:tid 521534] [remote 185.93.89.167:29333] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reg.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5xbgADHhw"]
[Sun Aug 30 03:11:52.177251 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:64329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5xbAADJk0"]
[Sun Aug 30 03:11:52.177867 2026] [security2:error] [pid 521505:tid 521534] [remote 185.93.89.167:44659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "p.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlyG8byYE0iXl--K5xcAADmxw"]
[Sun Aug 30 03:11:52.178070 2026] [security2:error] [pid 521505:tid 521703] [client 20.104.49.130:63610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wdfjba.org"] [uri "/mac.php"] [unique_id "apPlyG8byYE0iXl--K5xcQAAA2I"]
[Sun Aug 30 03:11:52.186150 2026] [security2:error] [pid 521505:tid 521629] [remote 185.93.89.167:25969] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dbadmin.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlyG8byYE0iXl--K5xdAADhHs"]
[Sun Aug 30 03:11:52.190303 2026] [security2:error] [pid 521505:tid 521641] [client 20.104.50.220:32861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/index7.php"] [unique_id "apPlyG8byYE0iXl--K5xdwAAAyQ"]
[Sun Aug 30 03:11:52.193461 2026] [authz_core:error] [pid 521505:tid 521673] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:52.193826 2026] [authz_core:error] [pid 521505:tid 521673] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:52.195628 2026] [security2:error] [pid 521505:tid 521509] [remote 185.93.89.167:56175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "press.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5xfAADfwM"]
[Sun Aug 30 03:11:52.196839 2026] [security2:error] [pid 521505:tid 521620] [remote 185.93.89.167:14991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "barracuda.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlyG8byYE0iXl--K5xfgADLnI"]
[Sun Aug 30 03:11:52.197563 2026] [security2:error] [pid 521505:tid 521571] [remote 185.93.89.167:9557] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "s4.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5xgQADdEE"]
[Sun Aug 30 03:11:52.199219 2026] [security2:error] [pid 521505:tid 521585] [remote 185.93.89.167:39177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "register.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5xhAADVE8"]
[Sun Aug 30 03:11:52.199406 2026] [security2:error] [pid 521505:tid 521528] [remote 185.93.89.167:5225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "preprod.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5xhQADWxY"]
[Sun Aug 30 03:11:52.203163 2026] [security2:error] [pid 521505:tid 521713] [client 20.220.10.235:24674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/file.php"] [unique_id "apPlyG8byYE0iXl--K5xhwAAA2w"]
[Sun Aug 30 03:11:52.205315 2026] [security2:error] [pid 521505:tid 521519] [remote 185.93.89.167:61033] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K5xiQADWQ0"]
[Sun Aug 30 03:11:52.205863 2026] [security2:error] [pid 521505:tid 521573] [remote 185.93.89.167:53363] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "work.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5xigADb0M"]
[Sun Aug 30 03:11:52.210919 2026] [security2:error] [pid 521505:tid 521552] [remote 185.93.89.167:1591] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlyG8byYE0iXl--K5xkAADZi4"]
[Sun Aug 30 03:11:52.210962 2026] [security2:error] [pid 521505:tid 521518] [remote 185.93.89.167:54151] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "affiliate.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5xjwADYww"]
[Sun Aug 30 03:11:52.211448 2026] [security2:error] [pid 521505:tid 521590] [remote 185.93.89.167:53553] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "demo2.mariegronley.com"] [uri "/.env"] [unique_id "apPlyG8byYE0iXl--K5xkQADOlQ"]
[Sun Aug 30 03:11:52.212285 2026] [authz_core:error] [pid 521505:tid 521655] [client 66.249.66.34:61653] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:52.212570 2026] [authz_core:error] [pid 521505:tid 521655] [client 66.249.66.34:61653] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:52.212778 2026] [security2:error] [pid 521505:tid 521574] [remote 185.93.89.167:23169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K5xkwADNEQ"]
[Sun Aug 30 03:11:52.214421 2026] [security2:error] [pid 521505:tid 521579] [remote 185.93.89.167:56429] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mb.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K5xlQADckk"]
[Sun Aug 30 03:11:52.216182 2026] [security2:error] [pid 521505:tid 521575] [remote 185.93.89.167:7863] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adserver.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5xmAADgUU"]
[Sun Aug 30 03:11:52.231486 2026] [security2:error] [pid 521505:tid 521527] [remote 185.93.89.167:54367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webservices.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlyG8byYE0iXl--K5xogADQRU"]
[Sun Aug 30 03:11:52.231734 2026] [security2:error] [pid 521505:tid 521587] [remote 185.93.89.167:24005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "radius.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlyG8byYE0iXl--K5xoQADjlE"]
[Sun Aug 30 03:11:52.232264 2026] [security2:error] [pid 521505:tid 521652] [client 20.104.50.220:24859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/mosty.php"] [unique_id "apPlyG8byYE0iXl--K5xowAAAy8"]
[Sun Aug 30 03:11:52.234172 2026] [security2:error] [pid 521505:tid 521699] [client 20.104.18.15:51171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/nox.php"] [unique_id "apPlyG8byYE0iXl--K5xpAAAA14"]
[Sun Aug 30 03:11:52.240833 2026] [security2:error] [pid 521505:tid 521545] [remote 185.93.89.167:62949] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "board.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlyG8byYE0iXl--K5xpQADTSc"]
[Sun Aug 30 03:11:52.240975 2026] [security2:error] [pid 521505:tid 521682] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "board.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlyG8byYE0iXl--K5xpQADTSc"]
[Sun Aug 30 03:11:52.241841 2026] [security2:error] [pid 521505:tid 521569] [remote 185.93.89.167:24213] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "in.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5xpwADnT8"]
[Sun Aug 30 03:11:52.249163 2026] [security2:error] [pid 521505:tid 521609] [remote 185.93.89.167:16627] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "education.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5xrwADX2c"]
[Sun Aug 30 03:11:52.251711 2026] [security2:error] [pid 521505:tid 521605] [remote 185.93.89.167:39923] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sitebuilder.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K5xsQADHmM"]
[Sun Aug 30 03:11:52.255743 2026] [security2:error] [pid 521505:tid 521757] [client 20.48.160.90:61540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/lock360.php"] [unique_id "apPlyG8byYE0iXl--K5xtgAAA5g"]
[Sun Aug 30 03:11:52.256217 2026] [security2:error] [pid 521505:tid 521604] [remote 185.93.89.167:34357] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banners.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5xtQADhGI"]
[Sun Aug 30 03:11:52.257140 2026] [security2:error] [pid 521505:tid 521601] [remote 185.93.89.167:11851] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "biblioteca.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5xtwADYV8"]
[Sun Aug 30 03:11:52.263409 2026] [security2:error] [pid 521505:tid 521551] [remote 185.93.89.167:14659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlyG8byYE0iXl--K5xuwADjC0"]
[Sun Aug 30 03:11:52.265516 2026] [security2:error] [pid 521505:tid 521613] [remote 185.93.89.167:11225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "da.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5xvQADSGs"]
[Sun Aug 30 03:11:52.271412 2026] [security2:error] [pid 521505:tid 521608] [remote 185.93.89.167:11687] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pr.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlyG8byYE0iXl--K5xwgADP2Y"]
[Sun Aug 30 03:11:52.275117 2026] [security2:error] [pid 521505:tid 521619] [remote 185.93.89.167:59097] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web6.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K5xxgADmnE"]
[Sun Aug 30 03:11:52.276056 2026] [security2:error] [pid 521505:tid 521611] [remote 185.93.89.167:16669] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "links.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5xxwADTGk"]
[Sun Aug 30 03:11:52.276482 2026] [security2:error] [pid 521505:tid 521626] [remote 185.93.89.167:9731] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images5.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5xyAADQHg"]
[Sun Aug 30 03:11:52.277883 2026] [security2:error] [pid 521505:tid 521607] [remote 185.93.89.167:11075] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "redirect.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5xyQADlmU"]
[Sun Aug 30 03:11:52.278680 2026] [security2:error] [pid 521505:tid 521621] [remote 185.93.89.167:42991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "venus.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5xygADVHM"]
[Sun Aug 30 03:11:52.283600 2026] [security2:error] [pid 521505:tid 521694] [client 158.23.147.79:39990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/asd.php"] [unique_id "apPlyG8byYE0iXl--K5xzgAAA1k"]
[Sun Aug 30 03:11:52.283635 2026] [security2:error] [pid 521505:tid 521659] [client 20.48.250.41:11030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/xxw.php"] [unique_id "apPlyG8byYE0iXl--K5xzQAAAzY"]
[Sun Aug 30 03:11:52.285706 2026] [security2:error] [pid 521505:tid 521618] [remote 185.93.89.167:28567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "user.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlyG8byYE0iXl--K5xzwADSXA"]
[Sun Aug 30 03:11:52.286090 2026] [security2:error] [pid 521505:tid 521623] [remote 185.93.89.167:22281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "labs.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlyG8byYE0iXl--K5x0AADlXU"]
[Sun Aug 30 03:11:52.288233 2026] [security2:error] [pid 521505:tid 521625] [remote 185.93.89.167:45765] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns01.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlyG8byYE0iXl--K5x0gADZnc"]
[Sun Aug 30 03:11:52.288786 2026] [security2:error] [pid 521505:tid 521624] [remote 185.93.89.167:32655] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lync.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5x1AADOnY"]
[Sun Aug 30 03:11:52.289323 2026] [core:alert] [pid 521505:tid 521671] [client 102.0.28.12:36574] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:11:52.289428 2026] [security2:error] [pid 521505:tid 521543] [remote 185.93.89.167:50005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fax.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5x1gADUSU"]
[Sun Aug 30 03:11:52.290912 2026] [security2:error] [pid 521505:tid 521627] [remote 185.93.89.167:55243] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oldmail.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5x2QADcnk"]
[Sun Aug 30 03:11:52.293326 2026] [security2:error] [pid 521505:tid 521584] [remote 185.93.89.167:36741] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "software.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5x2gADgU4"]
[Sun Aug 30 03:11:52.293381 2026] [security2:error] [pid 521505:tid 521680] [client 20.104.49.130:53709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/berlin.php"] [unique_id "apPlyG8byYE0iXl--K5x2wAAA0s"]
[Sun Aug 30 03:11:52.293872 2026] [security2:error] [pid 521505:tid 521637] [client 158.23.184.117:19728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/cgi-bin/wp-load.php"] [unique_id "apPlyG8byYE0iXl--K5x3AAAAyA"]
[Sun Aug 30 03:11:52.298546 2026] [security2:error] [pid 521505:tid 521695] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/cd/.env"] [unique_id "apPlyG8byYE0iXl--K5x3wAAA1o"]
[Sun Aug 30 03:11:52.305034 2026] [security2:error] [pid 521505:tid 521547] [remote 185.93.89.167:14833] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "se.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5x4gADSik"]
[Sun Aug 30 03:11:52.306748 2026] [security2:error] [pid 521505:tid 521530] [remote 185.93.89.167:14453] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5x5AADOxg"]
[Sun Aug 30 03:11:52.311326 2026] [security2:error] [pid 521505:tid 521533] [remote 185.93.89.167:44659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "p.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlyG8byYE0iXl--K5x7AADRhs"]
[Sun Aug 30 03:11:52.317255 2026] [security2:error] [pid 521505:tid 521710] [client 20.48.251.3:55705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/wp-konfig.backup.php"] [unique_id "apPlyG8byYE0iXl--K5x8AAAA2k"]
[Sun Aug 30 03:11:52.320684 2026] [security2:error] [pid 521505:tid 521529] [remote 185.93.89.167:25969] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dbadmin.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlyG8byYE0iXl--K5x8gADnRc"]
[Sun Aug 30 03:11:52.321738 2026] [security2:error] [pid 521505:tid 521562] [remote 185.93.89.167:21227] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "outlook.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlyG8byYE0iXl--K5x8wADajg"]
[Sun Aug 30 03:11:52.330084 2026] [security2:error] [pid 521505:tid 521524] [remote 185.93.89.167:49893] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mdm.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5x9AADZxI"]
[Sun Aug 30 03:11:52.331001 2026] [security2:error] [pid 521505:tid 521538] [remote 185.93.89.167:14991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "barracuda.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlyG8byYE0iXl--K5x9gADdyA"]
[Sun Aug 30 03:11:52.331200 2026] [security2:error] [pid 521505:tid 521507] [remote 185.93.89.167:60123] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "up.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5x9wADXwE"]
[Sun Aug 30 03:11:52.331575 2026] [security2:error] [pid 521505:tid 521548] [remote 185.93.89.167:63579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "wifi.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5x-AADHio"]
[Sun Aug 30 03:11:52.337981 2026] [security2:error] [pid 521505:tid 521628] [remote 185.93.89.167:3495] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5x_wADkXo"]
[Sun Aug 30 03:11:52.338522 2026] [security2:error] [pid 521505:tid 521702] [client 20.220.10.235:24698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/ca.php"] [unique_id "apPlyG8byYE0iXl--K5yAAAAA2E"]
[Sun Aug 30 03:11:52.339017 2026] [security2:error] [pid 521505:tid 521554] [remote 185.93.89.167:61033] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5yAQADfjA"]
[Sun Aug 30 03:11:52.343695 2026] [security2:error] [pid 521505:tid 521517] [remote 185.93.89.167:4349] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mm.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K5yBwADaAs"]
[Sun Aug 30 03:11:52.343767 2026] [security2:error] [pid 521505:tid 521561] [remote 185.93.89.167:37133] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K5yCAADjTc"]
[Sun Aug 30 03:11:52.344536 2026] [security2:error] [pid 521505:tid 521580] [remote 185.93.89.167:1591] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlyG8byYE0iXl--K5yCQADm0o"]
[Sun Aug 30 03:11:52.344898 2026] [security2:error] [pid 521505:tid 521532] [remote 185.93.89.167:53553] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "demo2.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlyG8byYE0iXl--K5yDAADJho"]
[Sun Aug 30 03:11:52.346112 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:23169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5yDQADP00"]
[Sun Aug 30 03:11:52.347282 2026] [security2:error] [pid 521505:tid 521582] [remote 185.93.89.167:6761] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banner.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5yDgADdEw"]
[Sun Aug 30 03:11:52.348256 2026] [security2:error] [pid 521505:tid 521567] [remote 185.93.89.167:56429] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mb.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5yEAADmj0"]
[Sun Aug 30 03:11:52.350586 2026] [security2:error] [pid 521505:tid 521525] [remote 185.93.89.167:24307] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tw.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K5yFAADnBM"]
[Sun Aug 30 03:11:52.356746 2026] [security2:error] [pid 521505:tid 521523] [remote 185.93.89.167:26309] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "piwik.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K5yFwADhRE"]
[Sun Aug 30 03:11:52.358276 2026] [security2:error] [pid 521505:tid 521661] [client 20.151.200.44:41948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/ah24.php"] [unique_id "apPlyG8byYE0iXl--K5yGAAAAzg"]
[Sun Aug 30 03:11:52.365904 2026] [security2:error] [pid 521505:tid 521537] [remote 185.93.89.167:64215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K5yIAADYx8"]
[Sun Aug 30 03:11:52.374567 2026] [security2:error] [pid 521505:tid 521585] [remote 185.93.89.167:62949] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "board.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlyG8byYE0iXl--K5yJAADWk8"]
[Sun Aug 30 03:11:52.374752 2026] [security2:error] [pid 521505:tid 521695] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "board.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlyG8byYE0iXl--K5yJAADWk8"]
[Sun Aug 30 03:11:52.379102 2026] [security2:error] [pid 521505:tid 521552] [remote 185.93.89.167:37521] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5yKwADQy4"]
[Sun Aug 30 03:11:52.385162 2026] [security2:error] [pid 521505:tid 521576] [remote 185.93.89.167:39923] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sitebuilder.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5yLwADjkY"]
[Sun Aug 30 03:11:52.392283 2026] [security2:error] [pid 521505:tid 521575] [remote 185.93.89.167:36485] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shopping.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K5yMwADXkU"]
[Sun Aug 30 03:11:52.394616 2026] [security2:error] [pid 521505:tid 521715] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/en/.env"] [unique_id "apPlyG8byYE0iXl--K5yNAAAA24"]
[Sun Aug 30 03:11:52.398498 2026] [security2:error] [pid 521505:tid 521711] [client 20.104.18.15:31689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apPlyG8byYE0iXl--K5yOQAAA2o"]
[Sun Aug 30 03:11:52.404905 2026] [security2:error] [pid 521505:tid 521724] [client 20.48.160.90:61480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp-theme.php"] [unique_id "apPlyG8byYE0iXl--K5yPgAAA3c"]
[Sun Aug 30 03:11:52.405284 2026] [security2:error] [pid 521505:tid 521572] [remote 185.93.89.167:11687] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pr.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlyG8byYE0iXl--K5yPQADX0I"]
[Sun Aug 30 03:11:52.406554 2026] [security2:error] [pid 521505:tid 521572] [remote 185.93.89.167:1995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lp.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5yQAADHkI"]
[Sun Aug 30 03:11:52.409065 2026] [security2:error] [pid 521505:tid 521589] [remote 185.93.89.167:59097] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web6.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5yQgADmVM"]
[Sun Aug 30 03:11:52.410048 2026] [security2:error] [pid 521505:tid 521569] [remote 185.93.89.167:29329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mars.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5yRAADUD8"]
[Sun Aug 30 03:11:52.414098 2026] [security2:error] [pid 521505:tid 521591] [remote 185.93.89.167:3789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vc.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5ySgADflU"]
[Sun Aug 30 03:11:52.421914 2026] [security2:error] [pid 521505:tid 521598] [remote 185.93.89.167:45765] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns01.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlyG8byYE0iXl--K5yUQADdFw"]
[Sun Aug 30 03:11:52.423076 2026] [security2:error] [pid 521505:tid 521601] [remote 185.93.89.167:13143] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "net.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlyG8byYE0iXl--K5yVgADVF8"]
[Sun Aug 30 03:11:52.433617 2026] [security2:error] [pid 521505:tid 521610] [remote 185.93.89.167:14681] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mc.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlyG8byYE0iXl--K5yYgADNmg"]
[Sun Aug 30 03:11:52.433680 2026] [security2:error] [pid 521505:tid 521675] [client 158.23.184.117:19622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/cgi-bin/wp-mail.php"] [unique_id "apPlyG8byYE0iXl--K5yYwAAA0Y"]
[Sun Aug 30 03:11:52.444142 2026] [security2:error] [pid 521505:tid 521626] [remote 185.93.89.167:62291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rs.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K5ybgADXHg"]
[Sun Aug 30 03:11:52.444275 2026] [security2:error] [pid 521505:tid 521616] [remote 185.93.89.167:27945] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5ybwADlm4"]
[Sun Aug 30 03:11:52.445684 2026] [security2:error] [pid 521505:tid 521618] [remote 185.93.89.167:64329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5ydAADWnA"]
[Sun Aug 30 03:11:52.447700 2026] [security2:error] [pid 521505:tid 521625] [remote 185.93.89.167:52789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "market.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlyG8byYE0iXl--K5ydgADSnc"]
[Sun Aug 30 03:11:52.454928 2026] [security2:error] [pid 521505:tid 521624] [remote 185.93.89.167:15177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5yeAADgHY"]
[Sun Aug 30 03:11:52.455486 2026] [security2:error] [pid 521505:tid 521543] [remote 185.93.89.167:21227] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "outlook.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlyG8byYE0iXl--K5yeQADQSU"]
[Sun Aug 30 03:11:52.463374 2026] [authz_core:error] [pid 521505:tid 521747] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory25
[Sun Aug 30 03:11:52.463771 2026] [authz_core:error] [pid 521505:tid 521747] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory25
[Sun Aug 30 03:11:52.466195 2026] [security2:error] [pid 521505:tid 521513] [remote 185.93.89.167:62859] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mailgw.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K5ygwADagc"]
[Sun Aug 30 03:11:52.467187 2026] [security2:error] [pid 521505:tid 521633] [remote 185.93.89.167:53985] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "img3.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5yhAADl38"]
[Sun Aug 30 03:11:52.467231 2026] [security2:error] [pid 521505:tid 521510] [remote 185.93.89.167:9557] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "s4.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5yhQADUwQ"]
[Sun Aug 30 03:11:52.471474 2026] [security2:error] [pid 521505:tid 521700] [client 20.104.50.220:6102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/alfav.php"] [unique_id "apPlyG8byYE0iXl--K5yiQAAA18"]
[Sun Aug 30 03:11:52.477246 2026] [security2:error] [pid 521505:tid 521541] [remote 185.93.89.167:37133] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5yjAADmSM"]
[Sun Aug 30 03:11:52.478365 2026] [security2:error] [pid 521505:tid 521546] [remote 185.93.89.167:53553] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "demo2.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlyG8byYE0iXl--K5yjwADYig"]
[Sun Aug 30 03:11:52.479780 2026] [security2:error] [pid 521505:tid 521533] [remote 185.93.89.167:54151] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "affiliate.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5ykAADkRs"]
[Sun Aug 30 03:11:52.483456 2026] [security2:error] [pid 521505:tid 521555] [remote 185.93.89.167:4349] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mm.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5ylQADZzE"]
[Sun Aug 30 03:11:52.484506 2026] [security2:error] [pid 521505:tid 521632] [remote 185.93.89.167:30871] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pro.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K5ymAADdH4"]
[Sun Aug 30 03:11:52.497534 2026] [security2:error] [pid 521505:tid 521643] [client 20.220.10.235:24685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/pb.php"] [unique_id "apPlyG8byYE0iXl--K5ymgAAAyY"]
[Sun Aug 30 03:11:52.499150 2026] [security2:error] [pid 521505:tid 521759] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/jenkins/.env"] [unique_id "apPlyG8byYE0iXl--K5ymwAAA5o"]
[Sun Aug 30 03:11:52.500061 2026] [security2:error] [pid 521505:tid 521535] [remote 185.93.89.167:59215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "users.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K5ynQADih0"]
[Sun Aug 30 03:11:52.500937 2026] [security2:error] [pid 521505:tid 521564] [remote 185.93.89.167:64795] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jp.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlyG8byYE0iXl--K5yoAADXTo"]
[Sun Aug 30 03:11:52.500991 2026] [security2:error] [pid 521505:tid 521548] [remote 185.93.89.167:42909] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "direct.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K5yngADnCo"]
[Sun Aug 30 03:11:52.501700 2026] [security2:error] [pid 521505:tid 521507] [remote 185.93.89.167:10845] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "campus.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlyG8byYE0iXl--K5yogADhQE"]
[Sun Aug 30 03:11:52.503323 2026] [security2:error] [pid 521505:tid 521661] [client 4.205.62.107:16379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/xin1.php"] [unique_id "apPlyG8byYE0iXl--K5ypAAAAzg"]
[Sun Aug 30 03:11:52.503830 2026] [security2:error] [pid 521505:tid 521677] [client 20.151.200.44:46077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/Contrller.php"] [unique_id "apPlyG8byYE0iXl--K5ypQAAA0g"]
[Sun Aug 30 03:11:52.508260 2026] [security2:error] [pid 521505:tid 521752] [client 20.48.250.41:11042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/bolt.php"] [unique_id "apPlyG8byYE0iXl--K5ypwAAA5M"]
[Sun Aug 30 03:11:52.510118 2026] [security2:error] [pid 521505:tid 521628] [remote 185.93.89.167:37843] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jupiter.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5yqAADeXo"]
[Sun Aug 30 03:11:52.510242 2026] [security2:error] [pid 521505:tid 521746] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "board.mariegronley.com"] [uri "/index.cgi"] [unique_id "apPlyG8byYE0iXl--K5ypgADjTs"]
[Sun Aug 30 03:11:52.511629 2026] [security2:error] [pid 521505:tid 521580] [remote 185.93.89.167:59907] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "health.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K5yrQADb0o"]
[Sun Aug 30 03:11:52.511766 2026] [security2:error] [pid 521505:tid 521517] [remote 185.93.89.167:7437] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images7.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K5yqwADRgs"]
[Sun Aug 30 03:11:52.519075 2026] [security2:error] [pid 521505:tid 521582] [remote 185.93.89.167:63379] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reviews.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5ytAADOkw"]
[Sun Aug 30 03:11:52.525308 2026] [security2:error] [pid 521505:tid 521629] [remote 185.93.89.167:11851] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "biblioteca.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5yuQADRXs"]
[Sun Aug 30 03:11:52.532445 2026] [security2:error] [pid 521505:tid 521540] [remote 185.93.89.167:15109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "linux.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlyG8byYE0iXl--K5yvAADjCI"]
[Sun Aug 30 03:11:52.534427 2026] [security2:error] [pid 521505:tid 521509] [remote 185.93.89.167:11225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "da.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5yvwADlAM"]
[Sun Aug 30 03:11:52.538329 2026] [security2:error] [pid 521505:tid 521571] [remote 185.93.89.167:11687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pr.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlyG8byYE0iXl--K5ywQADI0E"]
[Sun Aug 30 03:11:52.543824 2026] [security2:error] [pid 521505:tid 521550] [remote 185.93.89.167:37291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "st.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlyG8byYE0iXl--K5yxgADJyw"]
[Sun Aug 30 03:11:52.544941 2026] [security2:error] [pid 521505:tid 521511] [remote 185.93.89.167:18729] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ntp1.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K5yyAADOwU"]
[Sun Aug 30 03:11:52.551360 2026] [security2:error] [pid 521505:tid 521699] [client 20.48.251.3:37143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/lmfi2.php"] [unique_id "apPlyG8byYE0iXl--K5yzwAAA14"]
[Sun Aug 30 03:11:52.556617 2026] [security2:error] [pid 521505:tid 521552] [remote 185.93.89.167:13143] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "net.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlyG8byYE0iXl--K5y0gADbi4"]
[Sun Aug 30 03:11:52.557664 2026] [security2:error] [pid 521505:tid 521574] [remote 185.93.89.167:41989] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ipfixe.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K5y1gADd0Q"]
[Sun Aug 30 03:11:52.558474 2026] [security2:error] [pid 521505:tid 521539] [remote 185.93.89.167:1175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pgsql.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K5y2QADhCE"]
[Sun Aug 30 03:11:52.558843 2026] [security2:error] [pid 521505:tid 521560] [remote 185.93.89.167:10145] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "g.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K5y2gADPDY"]
[Sun Aug 30 03:11:52.563396 2026] [security2:error] [pid 521505:tid 521714] [client 20.104.50.220:29132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/images/leafmailer2.8.php"] [unique_id "apPlyG8byYE0iXl--K5y3QAAA20"]
[Sun Aug 30 03:11:52.563904 2026] [security2:error] [pid 521505:tid 521557] [remote 185.93.89.167:57109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "development.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K5y3gADUDM"]
[Sun Aug 30 03:11:52.566835 2026] [security2:error] [pid 521505:tid 521630] [remote 185.93.89.167:14681] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mc.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlyG8byYE0iXl--K5y3wADe3w"]
[Sun Aug 30 03:11:52.573674 2026] [security2:error] [pid 521505:tid 521680] [client 158.23.184.117:19771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "apPlyG8byYE0iXl--K5y4AAAA0s"]
[Sun Aug 30 03:11:52.575507 2026] [security2:error] [pid 521505:tid 521527] [remote 185.93.89.167:14833] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "se.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5y5AADaBU"]
[Sun Aug 30 03:11:52.577808 2026] [security2:error] [pid 521505:tid 521617] [remote 185.93.89.167:40249] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tracking.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5y6QADTm8"]
[Sun Aug 30 03:11:52.580934 2026] [security2:error] [pid 521505:tid 521595] [remote 185.93.89.167:52789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "market.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlyG8byYE0iXl--K5y8wADQFk"]
[Sun Aug 30 03:11:52.581118 2026] [security2:error] [pid 521505:tid 521732] [client 20.48.160.90:37720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/2d7433/index.php"] [unique_id "apPlyG8byYE0iXl--K5y9AAAA38"]
[Sun Aug 30 03:11:52.583769 2026] [security2:error] [pid 521505:tid 521591] [remote 185.93.89.167:62291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rs.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5y9QADOFU"]
[Sun Aug 30 03:11:52.589966 2026] [authz_core:error] [pid 521505:tid 521677] [client 66.249.66.77:37226] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:52.590260 2026] [authz_core:error] [pid 521505:tid 521677] [client 66.249.66.77:37226] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:52.591315 2026] [security2:error] [pid 521505:tid 521752] [client 20.104.50.220:42753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/index5.php"] [unique_id "apPlyG8byYE0iXl--K5y-gAAA5M"]
[Sun Aug 30 03:11:52.599867 2026] [security2:error] [pid 521505:tid 521710] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/administrator/.env"] [unique_id "apPlyG8byYE0iXl--K5y1AAAA2k"]
[Sun Aug 30 03:11:52.607526 2026] [security2:error] [pid 521505:tid 521608] [remote 185.93.89.167:61033] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5zCQADMGY"]
[Sun Aug 30 03:11:52.608466 2026] [security2:error] [pid 521505:tid 521521] [remote 185.93.89.167:53363] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "work.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5zCgADgg8"]
[Sun Aug 30 03:11:52.611557 2026] [security2:error] [pid 521505:tid 521626] [remote 185.93.89.167:53553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "demo2.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlyG8byYE0iXl--K5zDQADg3g"]
[Sun Aug 30 03:11:52.612015 2026] [security2:error] [pid 521505:tid 521638] [client 20.104.49.130:64122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/makeasmtp.php"] [unique_id "apPlyG8byYE0iXl--K5zDwAAAyE"]
[Sun Aug 30 03:11:52.614157 2026] [security2:error] [pid 521505:tid 521611] [remote 185.93.89.167:23169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5zEwADI2k"]
[Sun Aug 30 03:11:52.615695 2026] [security2:error] [pid 521505:tid 521607] [remote 185.93.89.167:56429] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mb.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5zFQADSmU"]
[Sun Aug 30 03:11:52.619023 2026] [security2:error] [pid 521505:tid 521624] [remote 185.93.89.167:24307] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tw.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyG8byYE0iXl--K5zGgADgHY"]
[Sun Aug 30 03:11:52.625617 2026] [security2:error] [pid 521505:tid 521516] [remote 185.93.89.167:26309] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "piwik.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyG8byYE0iXl--K5zHQADkAo"]
[Sun Aug 30 03:11:52.632769 2026] [security2:error] [pid 521505:tid 521715] [client 20.220.10.235:24815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/pk.php"] [unique_id "apPlyG8byYE0iXl--K5zIAAAA24"]
[Sun Aug 30 03:11:52.633787 2026] [security2:error] [pid 521505:tid 521508] [remote 185.93.89.167:59215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "users.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5zIQADOQI"]
[Sun Aug 30 03:11:52.634246 2026] [security2:error] [pid 521505:tid 521513] [remote 185.93.89.167:64795] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jp.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlyG8byYE0iXl--K5zIgADagc"]
[Sun Aug 30 03:11:52.635453 2026] [security2:error] [pid 521505:tid 521584] [remote 185.93.89.167:10845] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "campus.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlyG8byYE0iXl--K5zJAADKE4"]
[Sun Aug 30 03:11:52.636067 2026] [security2:error] [pid 521505:tid 521631] [remote 185.93.89.167:45621] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images8.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K5zJQADnX0"]
[Sun Aug 30 03:11:52.636202 2026] [security2:error] [pid 521505:tid 521627] [remote 185.93.89.167:24005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "radius.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K5zJgADhHk"]
[Sun Aug 30 03:11:52.636222 2026] [security2:error] [pid 521505:tid 521633] [remote 185.93.89.167:64215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyG8byYE0iXl--K5zJwADa38"]
[Sun Aug 30 03:11:52.636989 2026] [security2:error] [pid 521505:tid 521510] [remote 185.93.89.167:54367] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webservices.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlyG8byYE0iXl--K5zKAADPAQ"]
[Sun Aug 30 03:11:52.644477 2026] [security2:error] [pid 521505:tid 521692] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "board.mariegronley.com"] [uri "/index.cgi"] [unique_id "apPlyG8byYE0iXl--K5zKgADVyk"]
[Sun Aug 30 03:11:52.646580 2026] [security2:error] [pid 521505:tid 521553] [remote 185.93.89.167:48523] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K5zMAADmC8"]
[Sun Aug 30 03:11:52.648606 2026] [security2:error] [pid 521505:tid 521533] [remote 185.93.89.167:47169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "order.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K5zMgADaBs"]
[Sun Aug 30 03:11:52.654497 2026] [security2:error] [pid 521505:tid 521556] [remote 185.93.89.167:39923] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sitebuilder.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5zNQADTjI"]
[Sun Aug 30 03:11:52.658146 2026] [security2:error] [pid 521505:tid 521549] [remote 185.93.89.167:34357] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banners.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5zNgADiis"]
[Sun Aug 30 03:11:52.661067 2026] [security2:error] [pid 521505:tid 521632] [remote 185.93.89.167:62709] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp3.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K5zOAADnH4"]
[Sun Aug 30 03:11:52.661080 2026] [security2:error] [pid 521505:tid 521562] [remote 185.93.89.167:36485] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shopping.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyG8byYE0iXl--K5zOQADXTg"]
[Sun Aug 30 03:11:52.663821 2026] [security2:error] [pid 521505:tid 521529] [remote 185.93.89.167:34607] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sports.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K5zOwADNxc"]
[Sun Aug 30 03:11:52.665760 2026] [security2:error] [pid 521505:tid 521524] [remote 185.93.89.167:15109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "linux.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlyG8byYE0iXl--K5zPQADOBI"]
[Sun Aug 30 03:11:52.667392 2026] [security2:error] [pid 521505:tid 521535] [remote 185.93.89.167:14659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K5zPgADTR0"]
[Sun Aug 30 03:11:52.676009 2026] [security2:error] [pid 521505:tid 521671] [client 20.104.18.15:18332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/dev.php"] [unique_id "apPlyG8byYE0iXl--K5zSAAAA0I"]
[Sun Aug 30 03:11:52.677795 2026] [security2:error] [pid 521505:tid 521542] [remote 185.93.89.167:37291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "st.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlyG8byYE0iXl--K5zSgADNiQ"]
[Sun Aug 30 03:11:52.678185 2026] [security2:error] [pid 521505:tid 521538] [remote 185.93.89.167:59097] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web6.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5zSwADfiA"]
[Sun Aug 30 03:11:52.679173 2026] [security2:error] [pid 521505:tid 521565] [remote 185.93.89.167:16669] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "links.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5zTgADRjs"]
[Sun Aug 30 03:11:52.679563 2026] [security2:error] [pid 521505:tid 521628] [remote 185.93.89.167:9731] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images5.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5zTwADRHo"]
[Sun Aug 30 03:11:52.679568 2026] [security2:error] [pid 521505:tid 521686] [client 20.197.61.180:12226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/upgrade-temp-backup/themes/test.php"] [unique_id "apPlyG8byYE0iXl--K5zUAAAA1E"]
[Sun Aug 30 03:11:52.691494 2026] [security2:error] [pid 521505:tid 521568] [remote 185.93.89.167:32655] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lync.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5zXAADMD4"]
[Sun Aug 30 03:11:52.691818 2026] [security2:error] [pid 521505:tid 521582] [remote 185.93.89.167:28567] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "user.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlyG8byYE0iXl--K5zXQADgkw"]
[Sun Aug 30 03:11:52.692354 2026] [security2:error] [pid 521505:tid 521534] [remote 185.93.89.167:50005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fax.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5zYAADjBw"]
[Sun Aug 30 03:11:52.692620 2026] [security2:error] [pid 521505:tid 521629] [remote 185.93.89.167:22281] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "labs.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlyG8byYE0iXl--K5zYgADlHs"]
[Sun Aug 30 03:11:52.693491 2026] [authz_core:error] [pid 521505:tid 521655] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:52.693920 2026] [authz_core:error] [pid 521505:tid 521655] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:52.697421 2026] [authz_core:error] [pid 521505:tid 521635] [client 66.249.66.77:36914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:52.697700 2026] [authz_core:error] [pid 521505:tid 521635] [client 66.249.66.77:36914] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:52.699020 2026] [security2:error] [pid 521505:tid 521644] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/gitlab/.env"] [unique_id "apPlyG8byYE0iXl--K5zZwAAAyc"]
[Sun Aug 30 03:11:52.710870 2026] [security2:error] [pid 521505:tid 521509] [remote 185.93.89.167:14453] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5zbQADVQM"]
[Sun Aug 30 03:11:52.714423 2026] [security2:error] [pid 521505:tid 521511] [remote 185.93.89.167:44659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "p.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K5zdgADbgU"]
[Sun Aug 30 03:11:52.714452 2026] [security2:error] [pid 521505:tid 521717] [client 158.23.184.117:19584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/chosen.php"] [unique_id "apPlyG8byYE0iXl--K5zeAAAA3A"]
[Sun Aug 30 03:11:52.714780 2026] [security2:error] [pid 521505:tid 521528] [remote 185.93.89.167:31113] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "math.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K5zdwADUhY"]
[Sun Aug 30 03:11:52.727840 2026] [security2:error] [pid 521505:tid 521552] [remote 185.93.89.167:25969] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dbadmin.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K5zfgADdy4"]
[Sun Aug 30 03:11:52.729998 2026] [security2:error] [pid 521505:tid 521573] [remote 185.93.89.167:12177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tr.mariegronley.com"] [uri "/.env"] [unique_id "apPlyG8byYE0iXl--K5zgAADX0M"]
[Sun Aug 30 03:11:52.733620 2026] [security2:error] [pid 521505:tid 521574] [remote 185.93.89.167:49893] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mdm.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5zggADYEQ"]
[Sun Aug 30 03:11:52.734597 2026] [security2:error] [pid 521505:tid 521560] [remote 185.93.89.167:63579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "wifi.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5zhgADZDY"]
[Sun Aug 30 03:11:52.734625 2026] [security2:error] [pid 521505:tid 521518] [remote 185.93.89.167:62859] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mailgw.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyG8byYE0iXl--K5zhAADXgw"]
[Sun Aug 30 03:11:52.734638 2026] [security2:error] [pid 521505:tid 521574] [remote 185.93.89.167:14991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "barracuda.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K5zhQADe0Q"]
[Sun Aug 30 03:11:52.734691 2026] [security2:error] [pid 521505:tid 521579] [remote 185.93.89.167:60123] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "up.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5zhwADmEk"]
[Sun Aug 30 03:11:52.745612 2026] [security2:error] [pid 521505:tid 521587] [remote 185.93.89.167:37133] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5zlQADN1E"]
[Sun Aug 30 03:11:52.746526 2026] [security2:error] [pid 521505:tid 521617] [remote 185.93.89.167:1591] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K5zlgADTW8"]
[Sun Aug 30 03:11:52.749872 2026] [security2:error] [pid 521505:tid 521596] [remote 185.93.89.167:6761] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banner.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5zmgADeVo"]
[Sun Aug 30 03:11:52.750704 2026] [security2:error] [pid 521505:tid 521545] [remote 185.93.89.167:57009] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "static2.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K5zmwADQic"]
[Sun Aug 30 03:11:52.752463 2026] [security2:error] [pid 521505:tid 521595] [remote 185.93.89.167:24307] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tw.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyG8byYE0iXl--K5znAADflk"]
[Sun Aug 30 03:11:52.752532 2026] [security2:error] [pid 521505:tid 521593] [remote 185.93.89.167:30871] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pro.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyG8byYE0iXl--K5znQADY1c"]
[Sun Aug 30 03:11:52.758898 2026] [security2:error] [pid 521505:tid 521591] [remote 185.93.89.167:26309] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "piwik.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyG8byYE0iXl--K5zoAADb1U"]
[Sun Aug 30 03:11:52.759058 2026] [security2:error] [pid 521505:tid 521563] [remote 185.93.89.167:3495] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5zoQADSTk"]
[Sun Aug 30 03:11:52.761562 2026] [security2:error] [pid 521505:tid 521637] [client 158.23.147.79:39950] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/1.php"] [unique_id "apPlyG8byYE0iXl--K5zowAAAyA"]
[Sun Aug 30 03:11:52.761671 2026] [security2:error] [pid 521505:tid 521637] [client 158.23.147.79:39950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/1.php"] [unique_id "apPlyG8byYE0iXl--K5zowAAAyA"]
[Sun Aug 30 03:11:52.761694 2026] [security2:error] [pid 521505:tid 521663] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/psnlink/.env"] [unique_id "apPlyG8byYE0iXl--K5zogAAAzo"]
[Sun Aug 30 03:11:52.765706 2026] [security2:error] [pid 521505:tid 521598] [remote 185.93.89.167:4349] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mm.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K5zpAADllw"]
[Sun Aug 30 03:11:52.766976 2026] [security2:error] [pid 521505:tid 521674] [client 20.220.10.235:24824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/ft.php"] [unique_id "apPlyG8byYE0iXl--K5zpgAAA0U"]
[Sun Aug 30 03:11:52.767747 2026] [security2:error] [pid 521505:tid 521674] [client 20.104.18.15:22521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/robot.php"] [unique_id "apPlyG8byYE0iXl--K5zqAAAA0U"]
[Sun Aug 30 03:11:52.769104 2026] [security2:error] [pid 521505:tid 521737] [client 20.48.160.90:37728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp-login.php"] [unique_id "apPlyG8byYE0iXl--K5zfAAAA4Q"]
[Sun Aug 30 03:11:52.769729 2026] [security2:error] [pid 521505:tid 521604] [remote 185.93.89.167:24005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "radius.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5zqwADXGI"]
[Sun Aug 30 03:11:52.769740 2026] [security2:error] [pid 521505:tid 521600] [remote 185.93.89.167:64215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyG8byYE0iXl--K5zrAADiF4"]
[Sun Aug 30 03:11:52.770074 2026] [security2:error] [pid 521505:tid 521605] [remote 185.93.89.167:42909] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "direct.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyG8byYE0iXl--K5zrQADfGM"]
[Sun Aug 30 03:11:52.770385 2026] [security2:error] [pid 521505:tid 521603] [remote 185.93.89.167:54367] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webservices.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlyG8byYE0iXl--K5zrgADLmE"]
[Sun Aug 30 03:11:52.778452 2026] [security2:error] [pid 521505:tid 521602] [remote 185.93.89.167:62949] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "board.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K5zrwADdmA"]
[Sun Aug 30 03:11:52.778596 2026] [security2:error] [pid 521505:tid 521723] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "board.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K5zrwADdmA"]
[Sun Aug 30 03:11:52.778988 2026] [security2:error] [pid 521505:tid 521684] [client 20.104.49.130:60953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/ws45.php"] [unique_id "apPlyG8byYE0iXl--K5zsQAAA08"]
[Sun Aug 30 03:11:52.780074 2026] [security2:error] [pid 521505:tid 521613] [remote 185.93.89.167:42995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns12.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K5zswADjGs"]
[Sun Aug 30 03:11:52.780167 2026] [security2:error] [pid 521505:tid 521610] [remote 185.93.89.167:7437] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images7.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyG8byYE0iXl--K5ztAADH2g"]
[Sun Aug 30 03:11:52.780513 2026] [security2:error] [pid 521505:tid 521736] [client 20.48.250.41:11061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/rtx.php"] [unique_id "apPlyG8byYE0iXl--K5ztwAAA4M"]
[Sun Aug 30 03:11:52.780569 2026] [security2:error] [pid 521505:tid 521608] [remote 185.93.89.167:59907] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "health.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyG8byYE0iXl--K5ztgADIWY"]
[Sun Aug 30 03:11:52.794347 2026] [security2:error] [pid 521505:tid 521624] [remote 185.93.89.167:36485] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shopping.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyG8byYE0iXl--K5zxAADbnY"]
[Sun Aug 30 03:11:52.800887 2026] [security2:error] [pid 521505:tid 521625] [remote 185.93.89.167:14659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5zyAADknc"]
[Sun Aug 30 03:11:52.803990 2026] [security2:error] [pid 521505:tid 521543] [remote 185.93.89.167:8597] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "drupal.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K5zzAADOSU"]
[Sun Aug 30 03:11:52.805990 2026] [security2:error] [pid 521505:tid 521732] [client 20.48.251.3:52160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/userfuns.php"] [unique_id "apPlyG8byYE0iXl--K5zzQAAA38"]
[Sun Aug 30 03:11:52.810450 2026] [security2:error] [pid 521505:tid 521665] [client 20.104.18.15:64722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/132.php"] [unique_id "apPlyG8byYE0iXl--K5z0AAAAzw"]
[Sun Aug 30 03:11:52.811915 2026] [security2:error] [pid 521505:tid 521631] [remote 185.93.89.167:1995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lp.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5z0wADYH0"]
[Sun Aug 30 03:11:52.812628 2026] [security2:error] [pid 521505:tid 521627] [remote 185.93.89.167:18729] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ntp1.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyG8byYE0iXl--K5z1AADXnk"]
[Sun Aug 30 03:11:52.813470 2026] [security2:error] [pid 521505:tid 521510] [remote 185.93.89.167:29329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mars.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5z1wADVwQ"]
[Sun Aug 30 03:11:52.824976 2026] [security2:error] [pid 521505:tid 521520] [remote 185.93.89.167:45765] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns01.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K5z3gADdA4"]
[Sun Aug 30 03:11:52.825752 2026] [security2:error] [pid 521505:tid 521546] [remote 185.93.89.167:28567] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "user.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlyG8byYE0iXl--K5z3wADiig"]
[Sun Aug 30 03:11:52.825895 2026] [security2:error] [pid 521505:tid 521533] [remote 185.93.89.167:41989] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ipfixe.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyG8byYE0iXl--K5z4AADbRs"]
[Sun Aug 30 03:11:52.826060 2026] [security2:error] [pid 521505:tid 521594] [remote 185.93.89.167:22281] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "labs.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlyG8byYE0iXl--K5z4gADOFg"]
[Sun Aug 30 03:11:52.826870 2026] [security2:error] [pid 521505:tid 521506] [remote 185.93.89.167:1175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pgsql.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyG8byYE0iXl--K5z5AADfQA"]
[Sun Aug 30 03:11:52.826884 2026] [security2:error] [pid 521505:tid 521556] [remote 185.93.89.167:10145] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "g.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyG8byYE0iXl--K5z5QADbTI"]
[Sun Aug 30 03:11:52.832224 2026] [security2:error] [pid 521505:tid 521632] [remote 185.93.89.167:57109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "development.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyG8byYE0iXl--K5z6gADeX4"]
[Sun Aug 30 03:11:52.834224 2026] [authz_core:error] [pid 521505:tid 521739] [client 66.249.66.206:54106] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:52.834481 2026] [authz_core:error] [pid 521505:tid 521739] [client 66.249.66.206:54106] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:52.838698 2026] [security2:error] [pid 521505:tid 521704] [client 20.104.50.220:63225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/ddd.php"] [unique_id "apPlyG8byYE0iXl--K5z7AAAA2M"]
[Sun Aug 30 03:11:52.840964 2026] [security2:error] [pid 521505:tid 521675] [client 20.104.50.220:28728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/sure.php"] [unique_id "apPlyG8byYE0iXl--K5z7QAAA0Y"]
[Sun Aug 30 03:11:52.844864 2026] [security2:error] [pid 521505:tid 521535] [remote 185.93.89.167:13069] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sc.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K5z8QADbx0"]
[Sun Aug 30 03:11:52.845550 2026] [security2:error] [pid 521505:tid 521507] [remote 185.93.89.167:4287] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "php.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K5z9AADaQE"]
[Sun Aug 30 03:11:52.846385 2026] [security2:error] [pid 521505:tid 521512] [remote 185.93.89.167:27945] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5z9QADOgY"]
[Sun Aug 30 03:11:52.848078 2026] [security2:error] [pid 521505:tid 521542] [remote 185.93.89.167:44659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "p.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5z9gADliQ"]
[Sun Aug 30 03:11:52.848161 2026] [security2:error] [pid 521505:tid 521565] [remote 185.93.89.167:64329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K5z-QADhDs"]
[Sun Aug 30 03:11:52.848218 2026] [security2:error] [pid 521505:tid 521628] [remote 185.93.89.167:53853] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atlas.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K5z-gADjXo"]
[Sun Aug 30 03:11:52.849007 2026] [security2:error] [pid 521505:tid 521570] [remote 185.93.89.167:2579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "love.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K5z-wADXEA"]
[Sun Aug 30 03:11:52.849405 2026] [security2:error] [pid 521505:tid 521580] [remote 185.93.89.167:29333] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reg.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K5z_AADiEo"]
[Sun Aug 30 03:11:52.857255 2026] [security2:error] [pid 521505:tid 521544] [remote 185.93.89.167:21227] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "outlook.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K5z_gADkyY"]
[Sun Aug 30 03:11:52.862539 2026] [security2:error] [pid 521505:tid 521517] [remote 185.93.89.167:25969] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dbadmin.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K5z_wADfAs"]
[Sun Aug 30 03:11:52.863406 2026] [security2:error] [pid 521505:tid 521561] [remote 185.93.89.167:12177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tr.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlyG8byYE0iXl--K50AAADJjc"]
[Sun Aug 30 03:11:52.866107 2026] [security2:error] [pid 521505:tid 521568] [remote 185.93.89.167:62291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rs.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K50AgADaz4"]
[Sun Aug 30 03:11:52.867839 2026] [security2:error] [pid 521505:tid 521534] [remote 185.93.89.167:62859] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mailgw.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyG8byYE0iXl--K50BAADTxw"]
[Sun Aug 30 03:11:52.868092 2026] [security2:error] [pid 521505:tid 521532] [remote 185.93.89.167:56175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "press.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K50BQADjBo"]
[Sun Aug 30 03:11:52.868140 2026] [security2:error] [pid 521505:tid 521629] [remote 185.93.89.167:14991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "barracuda.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K50BgADH3s"]
[Sun Aug 30 03:11:52.870754 2026] [security2:error] [pid 521505:tid 521558] [remote 185.93.89.167:39177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "register.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K50CgADgjQ"]
[Sun Aug 30 03:11:52.871282 2026] [security2:error] [pid 521505:tid 521566] [remote 185.93.89.167:9557] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "s4.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K50CwADlDw"]
[Sun Aug 30 03:11:52.871852 2026] [security2:error] [pid 521505:tid 521523] [remote 185.93.89.167:5225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "preprod.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K50DAADJRE"]
[Sun Aug 30 03:11:52.875621 2026] [security2:error] [pid 521505:tid 521537] [remote 185.93.89.167:15177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K50DwADSh8"]
[Sun Aug 30 03:11:52.880259 2026] [security2:error] [pid 521505:tid 521571] [remote 185.93.89.167:1591] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K50FQADTkE"]
[Sun Aug 30 03:11:52.882411 2026] [security2:error] [pid 521505:tid 521511] [remote 185.93.89.167:54151] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "affiliate.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K50GQADPgU"]
[Sun Aug 30 03:11:52.885489 2026] [security2:error] [pid 521505:tid 521577] [remote 185.93.89.167:24307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tw.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyG8byYE0iXl--K50IAADkkc"]
[Sun Aug 30 03:11:52.886086 2026] [security2:error] [pid 521505:tid 521578] [remote 185.93.89.167:30871] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pro.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyG8byYE0iXl--K50IQADTEg"]
[Sun Aug 30 03:11:52.888110 2026] [security2:error] [pid 521505:tid 521536] [remote 185.93.89.167:7863] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adserver.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K50IgADLx4"]
[Sun Aug 30 03:11:52.892113 2026] [security2:error] [pid 521505:tid 521519] [remote 185.93.89.167:26309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piwik.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyG8byYE0iXl--K50JAADKg0"]
[Sun Aug 30 03:11:52.901095 2026] [security2:error] [pid 521505:tid 521700] [client 20.220.10.235:24774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/wp-ver.php"] [unique_id "apPlyG8byYE0iXl--K50LgAAA18"]
[Sun Aug 30 03:11:52.902175 2026] [security2:error] [pid 521505:tid 521655] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/github/.env"] [unique_id "apPlyG8byYE0iXl--K50LwAAAzI"]
[Sun Aug 30 03:11:52.902233 2026] [security2:error] [pid 521505:tid 521703] [client 158.23.184.117:19608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/class-wp-logo-new.php"] [unique_id "apPlyG8byYE0iXl--K50MQAAA2I"]
[Sun Aug 30 03:11:52.902966 2026] [security2:error] [pid 521505:tid 521539] [remote 185.93.89.167:59215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "users.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyG8byYE0iXl--K50MAADmSE"]
[Sun Aug 30 03:11:52.903007 2026] [security2:error] [pid 521505:tid 521518] [remote 185.93.89.167:64215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m1.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyG8byYE0iXl--K50MwADagw"]
[Sun Aug 30 03:11:52.903636 2026] [security2:error] [pid 521505:tid 521579] [remote 185.93.89.167:42909] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "direct.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyG8byYE0iXl--K50NQADN0k"]
[Sun Aug 30 03:11:52.904495 2026] [security2:error] [pid 521505:tid 521575] [remote 185.93.89.167:45621] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images8.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyG8byYE0iXl--K50OAADJEU"]
[Sun Aug 30 03:11:52.911931 2026] [security2:error] [pid 521505:tid 521526] [remote 185.93.89.167:62949] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "board.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K50PAADYRQ"]
[Sun Aug 30 03:11:52.912088 2026] [security2:error] [pid 521505:tid 521702] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "board.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K50PAADYRQ"]
[Sun Aug 30 03:11:52.913562 2026] [security2:error] [pid 521505:tid 521527] [remote 185.93.89.167:7437] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images7.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyG8byYE0iXl--K50QQADfhU"]
[Sun Aug 30 03:11:52.914204 2026] [security2:error] [pid 521505:tid 521587] [remote 185.93.89.167:59907] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "health.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyG8byYE0iXl--K50QwADXVE"]
[Sun Aug 30 03:11:52.915202 2026] [security2:error] [pid 521505:tid 521617] [remote 185.93.89.167:48523] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyG8byYE0iXl--K50RAADNm8"]
[Sun Aug 30 03:11:52.915852 2026] [security2:error] [pid 521505:tid 521589] [remote 185.93.89.167:24213] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "in.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K50RQADWFM"]
[Sun Aug 30 03:11:52.915880 2026] [security2:error] [pid 521505:tid 521586] [remote 185.93.89.167:47169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "order.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyG8byYE0iXl--K50RwADeFA"]
[Sun Aug 30 03:11:52.921154 2026] [security2:error] [pid 521505:tid 521755] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/exapi/.env"] [unique_id "apPlyG8byYE0iXl--K50SwAAA5Y"]
[Sun Aug 30 03:11:52.922496 2026] [security2:error] [pid 521505:tid 521569] [remote 185.93.89.167:16627] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "education.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K50TAADjT8"]
[Sun Aug 30 03:11:52.927341 2026] [security2:error] [pid 521505:tid 521591] [remote 185.93.89.167:36485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shopping.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyG8byYE0iXl--K50UgADKFU"]
[Sun Aug 30 03:11:52.927453 2026] [security2:error] [pid 521505:tid 521597] [remote 185.93.89.167:11851] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "biblioteca.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K50UQADk1s"]
[Sun Aug 30 03:11:52.928829 2026] [security2:error] [pid 521505:tid 521563] [remote 185.93.89.167:62709] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp3.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyG8byYE0iXl--K50UwADfDk"]
[Sun Aug 30 03:11:52.931486 2026] [security2:error] [pid 521505:tid 521598] [remote 185.93.89.167:34607] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sports.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyG8byYE0iXl--K50VQADT1w"]
[Sun Aug 30 03:11:52.937868 2026] [security2:error] [pid 521505:tid 521735] [client 20.104.49.130:59972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/wp-the.php"] [unique_id "apPlyG8byYE0iXl--K50WgAAA4I"]
[Sun Aug 30 03:11:52.938098 2026] [security2:error] [pid 521505:tid 521599] [remote 185.93.89.167:11225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "da.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K50WQADlF0"]
[Sun Aug 30 03:11:52.942923 2026] [security2:error] [pid 521505:tid 521605] [remote 185.93.89.167:11687] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pr.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlyG8byYE0iXl--K50XAADIWM"]
[Sun Aug 30 03:11:52.945805 2026] [security2:error] [pid 521505:tid 521606] [remote 185.93.89.167:18729] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ntp1.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyG8byYE0iXl--K50XgADLWQ"]
[Sun Aug 30 03:11:52.949493 2026] [security2:error] [pid 521505:tid 521626] [remote 185.93.89.167:11075] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "redirect.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K50ZAADO3g"]
[Sun Aug 30 03:11:52.952426 2026] [security2:error] [pid 521505:tid 521613] [remote 185.93.89.167:42991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "venus.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K50ZgADWWs"]
[Sun Aug 30 03:11:52.958596 2026] [security2:error] [pid 521505:tid 521619] [remote 185.93.89.167:45765] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns01.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K50aAADbnE"]
[Sun Aug 30 03:11:52.959095 2026] [security2:error] [pid 521505:tid 521616] [remote 185.93.89.167:41989] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ipfixe.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyG8byYE0iXl--K50agADkm4"]
[Sun Aug 30 03:11:52.959770 2026] [security2:error] [pid 521505:tid 521607] [remote 185.93.89.167:13143] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "net.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K50bgADc2U"]
[Sun Aug 30 03:11:52.960220 2026] [security2:error] [pid 521505:tid 521618] [remote 185.93.89.167:10145] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "g.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyG8byYE0iXl--K50bwADSHA"]
[Sun Aug 30 03:11:52.960285 2026] [security2:error] [pid 521505:tid 521624] [remote 185.93.89.167:1175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pgsql.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyG8byYE0iXl--K50cAADXnY"]
[Sun Aug 30 03:11:52.963822 2026] [security2:error] [pid 521505:tid 521614] [remote 185.93.89.167:55243] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oldmail.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K50dAADV2w"]
[Sun Aug 30 03:11:52.964362 2026] [security2:error] [pid 521505:tid 521625] [remote 185.93.89.167:36741] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "software.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyG8byYE0iXl--K50dgADmnc"]
[Sun Aug 30 03:11:52.965950 2026] [security2:error] [pid 521505:tid 521623] [remote 185.93.89.167:57109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "development.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyG8byYE0iXl--K50dwADZHU"]
[Sun Aug 30 03:11:52.970252 2026] [security2:error] [pid 521505:tid 521543] [remote 185.93.89.167:14681] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mc.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K50egADOSU"]
[Sun Aug 30 03:11:52.971848 2026] [security2:error] [pid 521505:tid 521721] [client 20.48.250.41:10946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/ckk.php"] [unique_id "apPlyG8byYE0iXl--K50fAAAA3Q"]
[Sun Aug 30 03:11:52.979701 2026] [security2:error] [pid 521505:tid 521513] [remote 185.93.89.167:14833] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "se.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyG8byYE0iXl--K50hAADiQc"]
[Sun Aug 30 03:11:52.982622 2026] [security2:error] [pid 521505:tid 521531] [remote 185.93.89.167:52789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "market.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyG8byYE0iXl--K50iwADnBk"]
[Sun Aug 30 03:11:52.983000 2026] [security2:error] [pid 521505:tid 521553] [remote 185.93.89.167:31113] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "math.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyG8byYE0iXl--K50jQADfi8"]
[Sun Aug 30 03:11:52.986784 2026] [authz_core:error] [pid 521505:tid 521714] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory29
[Sun Aug 30 03:11:52.987036 2026] [authz_core:error] [pid 521505:tid 521714] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory29
[Sun Aug 30 03:11:52.990594 2026] [security2:error] [pid 521505:tid 521546] [remote 185.93.89.167:21227] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "outlook.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyG8byYE0iXl--K50kgADYyg"]
[Sun Aug 30 03:11:52.993474 2026] [security2:error] [pid 521505:tid 521659] [client 20.48.160.90:61513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/images.php"] [unique_id "apPlyG8byYE0iXl--K50kwAAAzY"]
[Sun Aug 30 03:11:52.996983 2026] [security2:error] [pid 521505:tid 521541] [remote 185.93.89.167:12177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tr.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlyG8byYE0iXl--K50lQADWCM"]
[Sun Aug 30 03:11:53.000686 2026] [security2:error] [pid 521505:tid 521594] [remote 185.93.89.167:62859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailgw.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K50mAADVVg"]
[Sun Aug 30 03:11:53.010651 2026] [security2:error] [pid 521505:tid 521524] [remote 185.93.89.167:61033] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyW8byYE0iXl--K50pwADdhI"]
[Sun Aug 30 03:11:53.012793 2026] [security2:error] [pid 521505:tid 521636] [client 20.104.49.130:53719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/wpxml.php"] [unique_id "apPlyW8byYE0iXl--K50qQAAAx8"]
[Sun Aug 30 03:11:53.016878 2026] [security2:error] [pid 521505:tid 521565] [remote 185.93.89.167:53553] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "demo2.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlyW8byYE0iXl--K50rwADLTs"]
[Sun Aug 30 03:11:53.017405 2026] [security2:error] [pid 521505:tid 521628] [remote 185.93.89.167:23169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyW8byYE0iXl--K50sAADJXo"]
[Sun Aug 30 03:11:53.018011 2026] [security2:error] [pid 521505:tid 521570] [remote 185.93.89.167:56429] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mb.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyW8byYE0iXl--K50sQADSkA"]
[Sun Aug 30 03:11:53.018540 2026] [security2:error] [pid 521505:tid 521592] [remote 185.93.89.167:57009] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "static2.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K50swADbFY"]
[Sun Aug 30 03:11:53.018701 2026] [security2:error] [pid 521505:tid 521580] [remote 185.93.89.167:24307] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tw.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K50tAADWUo"]
[Sun Aug 30 03:11:53.019117 2026] [security2:error] [pid 521505:tid 521544] [remote 185.93.89.167:30871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pro.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K50tQADbCY"]
[Sun Aug 30 03:11:53.021468 2026] [security2:error] [pid 521505:tid 521677] [client 158.23.147.79:40002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/ws.php"] [unique_id "apPlyW8byYE0iXl--K50uAAAA0g"]
[Sun Aug 30 03:11:53.025329 2026] [security2:error] [pid 521505:tid 521561] [remote 185.93.89.167:26309] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "piwik.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K50uQADTDc"]
[Sun Aug 30 03:11:53.036582 2026] [security2:error] [pid 521505:tid 521534] [remote 185.93.89.167:64215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K50vQADmBw"]
[Sun Aug 30 03:11:53.036889 2026] [security2:error] [pid 521505:tid 521532] [remote 185.93.89.167:42909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direct.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K50vgADmho"]
[Sun Aug 30 03:11:53.038107 2026] [security2:error] [pid 521505:tid 521629] [remote 185.93.89.167:45621] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images8.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K50vwADX3s"]
[Sun Aug 30 03:11:53.038595 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:24005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "radius.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyW8byYE0iXl--K50wgADOU0"]
[Sun Aug 30 03:11:53.038658 2026] [security2:error] [pid 521505:tid 521582] [remote 185.93.89.167:64795] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jp.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyW8byYE0iXl--K50wAADYkw"]
[Sun Aug 30 03:11:53.039076 2026] [security2:error] [pid 521505:tid 521558] [remote 185.93.89.167:10845] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "campus.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyW8byYE0iXl--K50wwADdDQ"]
[Sun Aug 30 03:11:53.039214 2026] [security2:error] [pid 521505:tid 521676] [client 20.220.10.235:24814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/ah24.php"] [unique_id "apPlyW8byYE0iXl--K50xAAAA0c"]
[Sun Aug 30 03:11:53.041898 2026] [security2:error] [pid 521505:tid 521725] [client 158.23.184.117:19721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/classwithtostring.php"] [unique_id "apPlyW8byYE0iXl--K50xwAAA3g"]
[Sun Aug 30 03:11:53.045988 2026] [security2:error] [pid 521505:tid 521711] [client 20.104.18.15:2031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/bulet.php"] [unique_id "apPlyW8byYE0iXl--K50ywAAA2o"]
[Sun Aug 30 03:11:53.046153 2026] [security2:error] [pid 521505:tid 521660] [client 68.155.159.216:54309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apPlyW8byYE0iXl--K50zQAAAzc"]
[Sun Aug 30 03:11:53.046396 2026] [security2:error] [pid 521505:tid 521537] [remote 185.93.89.167:7437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images7.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K50zgADOB8"]
[Sun Aug 30 03:11:53.047237 2026] [security2:error] [pid 521505:tid 521665] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "board.mariegronley.com"] [uri "/index.cgi"] [unique_id "apPlyW8byYE0iXl--K50yQADPBM"]
[Sun Aug 30 03:11:53.047392 2026] [security2:error] [pid 521505:tid 521540] [remote 185.93.89.167:59907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "health.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K50zwADiSI"]
[Sun Aug 30 03:11:53.048233 2026] [security2:error] [pid 521505:tid 521509] [remote 185.93.89.167:42995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns12.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K500QADQQM"]
[Sun Aug 30 03:11:53.048656 2026] [security2:error] [pid 521505:tid 521620] [remote 185.93.89.167:48523] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K500wADfXI"]
[Sun Aug 30 03:11:53.048953 2026] [security2:error] [pid 521505:tid 521511] [remote 185.93.89.167:47169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "order.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K501AADUAU"]
[Sun Aug 30 03:11:53.051068 2026] [security2:error] [pid 521505:tid 521528] [remote 185.93.89.167:37521] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K501gADfhY"]
[Sun Aug 30 03:11:53.057558 2026] [security2:error] [pid 521505:tid 521550] [remote 185.93.89.167:39923] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sitebuilder.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyW8byYE0iXl--K502QADRiw"]
[Sun Aug 30 03:11:53.060553 2026] [security2:error] [pid 521505:tid 521578] [remote 185.93.89.167:36485] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shopping.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K503QADTUg"]
[Sun Aug 30 03:11:53.061905 2026] [security2:error] [pid 521505:tid 521519] [remote 185.93.89.167:62709] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp3.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K503wADRA0"]
[Sun Aug 30 03:11:53.065206 2026] [security2:error] [pid 521505:tid 521573] [remote 185.93.89.167:34607] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sports.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K504gADQkM"]
[Sun Aug 30 03:11:53.068816 2026] [security2:error] [pid 521505:tid 521539] [remote 185.93.89.167:15109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "linux.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyW8byYE0iXl--K505wADNiE"]
[Sun Aug 30 03:11:53.070240 2026] [security2:error] [pid 521505:tid 521518] [remote 185.93.89.167:14659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyW8byYE0iXl--K506QADVQw"]
[Sun Aug 30 03:11:53.072169 2026] [security2:error] [pid 521505:tid 521575] [remote 185.93.89.167:8597] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "drupal.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K507AADlkU"]
[Sun Aug 30 03:11:53.076715 2026] [security2:error] [pid 521505:tid 521590] [remote 185.93.89.167:11687] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pr.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlyW8byYE0iXl--K507QADiFQ"]
[Sun Aug 30 03:11:53.078842 2026] [security2:error] [pid 521505:tid 521574] [remote 185.93.89.167:18729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ntp1.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K508AADfEQ"]
[Sun Aug 30 03:11:53.080348 2026] [security2:error] [pid 521505:tid 521560] [remote 185.93.89.167:37291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "st.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyW8byYE0iXl--K508QADTzY"]
[Sun Aug 30 03:11:53.080378 2026] [security2:error] [pid 521505:tid 521643] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/sitemaps/.env"] [unique_id "apPlyW8byYE0iXl--K508gAAAyY"]
[Sun Aug 30 03:11:53.081518 2026] [security2:error] [pid 521505:tid 521557] [remote 185.93.89.167:59097] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web6.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyW8byYE0iXl--K509AADdjM"]
[Sun Aug 30 03:11:53.085239 2026] [security2:error] [pid 521505:tid 521617] [remote 185.93.89.167:3789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vc.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K50-gADIW8"]
[Sun Aug 30 03:11:53.092070 2026] [security2:error] [pid 521505:tid 521529] [remote 185.93.89.167:41989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ipfixe.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K50_gADPhc"]
[Sun Aug 30 03:11:53.092308 2026] [authz_core:error] [pid 521505:tid 521705] [client 66.249.66.38:48368] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:53.092565 2026] [authz_core:error] [pid 521505:tid 521705] [client 66.249.66.38:48368] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:53.093089 2026] [security2:error] [pid 521505:tid 521596] [remote 185.93.89.167:13143] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "net.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyW8byYE0iXl--K50_wADnVo"]
[Sun Aug 30 03:11:53.093218 2026] [security2:error] [pid 521505:tid 521569] [remote 185.93.89.167:10145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K51AAADJT8"]
[Sun Aug 30 03:11:53.093359 2026] [security2:error] [pid 521505:tid 521595] [remote 185.93.89.167:1175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pgsql.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K51AgADQFk"]
[Sun Aug 30 03:11:53.099025 2026] [security2:error] [pid 521505:tid 521601] [remote 185.93.89.167:57109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "development.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K51CQADkl8"]
[Sun Aug 30 03:11:53.102591 2026] [security2:error] [pid 521505:tid 521699] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/actions/.env"] [unique_id "apPlyW8byYE0iXl--K51CgAAA14"]
[Sun Aug 30 03:11:53.103565 2026] [security2:error] [pid 521505:tid 521599] [remote 185.93.89.167:14681] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mc.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyW8byYE0iXl--K51CwADa10"]
[Sun Aug 30 03:11:53.114812 2026] [security2:error] [pid 521505:tid 521605] [remote 185.93.89.167:13069] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sc.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K51DQADmmM"]
[Sun Aug 30 03:11:53.114815 2026] [security2:error] [pid 521505:tid 521602] [remote 185.93.89.167:4287] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "php.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K51EAADOWA"]
[Sun Aug 30 03:11:53.116078 2026] [security2:error] [pid 521505:tid 521551] [remote 185.93.89.167:52789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "market.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyW8byYE0iXl--K51EwADRy0"]
[Sun Aug 30 03:11:53.116481 2026] [security2:error] [pid 521505:tid 521626] [remote 185.93.89.167:53853] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atlas.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K51FgADl3g"]
[Sun Aug 30 03:11:53.116554 2026] [security2:error] [pid 521505:tid 521610] [remote 185.93.89.167:31113] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "math.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K51FQADJ2g"]
[Sun Aug 30 03:11:53.117333 2026] [security2:error] [pid 521505:tid 521613] [remote 185.93.89.167:2579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "love.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K51GAADams"]
[Sun Aug 30 03:11:53.117501 2026] [security2:error] [pid 521505:tid 521612] [remote 185.93.89.167:44659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "p.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyW8byYE0iXl--K51FwADeGo"]
[Sun Aug 30 03:11:53.117618 2026] [security2:error] [pid 521505:tid 521619] [remote 185.93.89.167:29333] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reg.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K51GQADN3E"]
[Sun Aug 30 03:11:53.121251 2026] [authz_core:error] [pid 521505:tid 521721] [client 66.249.66.34:61653] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:53.121524 2026] [authz_core:error] [pid 521505:tid 521721] [client 66.249.66.34:61653] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:53.130304 2026] [security2:error] [pid 521505:tid 521607] [remote 185.93.89.167:12177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tr.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlyW8byYE0iXl--K51HAADiWU"]
[Sun Aug 30 03:11:53.132362 2026] [security2:error] [pid 521505:tid 521670] [client 20.48.250.41:11089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.benchcreative.com.au"] [uri "/R57.php"] [unique_id "apPlyW8byYE0iXl--K51HgAAA0E"]
[Sun Aug 30 03:11:53.133873 2026] [security2:error] [pid 521505:tid 521618] [remote 185.93.89.167:62859] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mailgw.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K51HwADfXA"]
[Sun Aug 30 03:11:53.135604 2026] [security2:error] [pid 521505:tid 521622] [remote 185.93.89.167:56175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "press.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K51IQADcHQ"]
[Sun Aug 30 03:11:53.135613 2026] [security2:error] [pid 521505:tid 521624] [remote 185.93.89.167:25969] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dbadmin.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyW8byYE0iXl--K51IAADLHY"]
[Sun Aug 30 03:11:53.138619 2026] [security2:error] [pid 521505:tid 521614] [remote 185.93.89.167:14991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "barracuda.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyW8byYE0iXl--K51JQADf2w"]
[Sun Aug 30 03:11:53.138674 2026] [security2:error] [pid 521505:tid 521625] [remote 185.93.89.167:39177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "register.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K51JgADkHc"]
[Sun Aug 30 03:11:53.139814 2026] [security2:error] [pid 521505:tid 521552] [remote 185.93.89.167:53985] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "img3.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K51KAADWy4"]
[Sun Aug 30 03:11:53.140439 2026] [security2:error] [pid 521505:tid 521543] [remote 185.93.89.167:5225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "preprod.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K51KQADRiU"]
[Sun Aug 30 03:11:53.149073 2026] [security2:error] [pid 521505:tid 521508] [remote 185.93.89.167:1591] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyW8byYE0iXl--K51MAADRAI"]
[Sun Aug 30 03:11:53.149096 2026] [security2:error] [pid 521505:tid 521627] [remote 185.93.89.167:37133] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyW8byYE0iXl--K51LwADmXk"]
[Sun Aug 30 03:11:53.150574 2026] [security2:error] [pid 521505:tid 521531] [remote 185.93.89.167:53553] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "demo2.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlyW8byYE0iXl--K51MgADUhk"]
[Sun Aug 30 03:11:53.151471 2026] [security2:error] [pid 521505:tid 521559] [remote 185.93.89.167:24307] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "tw.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K51NgADljU"]
[Sun Aug 30 03:11:53.152144 2026] [security2:error] [pid 521505:tid 521516] [remote 185.93.89.167:57009] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "static2.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K51NQADVQo"]
[Sun Aug 30 03:11:53.152715 2026] [security2:error] [pid 521505:tid 521520] [remote 185.93.89.167:30871] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pro.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K51OAADKA4"]
[Sun Aug 30 03:11:53.155579 2026] [security2:error] [pid 521505:tid 521541] [remote 185.93.89.167:7863] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adserver.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K51OwADiCM"]
[Sun Aug 30 03:11:53.157950 2026] [security2:error] [pid 521505:tid 521533] [remote 185.93.89.167:26309] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "piwik.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K51PgADMhs"]
[Sun Aug 30 03:11:53.165341 2026] [security2:error] [pid 521505:tid 521729] [client 20.104.50.220:61474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/ut.php"] [unique_id "apPlyW8byYE0iXl--K51PwAAA3w"]
[Sun Aug 30 03:11:53.169179 2026] [security2:error] [pid 521505:tid 521674] [client 20.220.10.235:24672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/wp-admin/zwso.php"] [unique_id "apPlyW8byYE0iXl--K51QQAAA0U"]
[Sun Aug 30 03:11:53.169605 2026] [security2:error] [pid 521505:tid 521594] [remote 185.93.89.167:64215] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "m1.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K51QgADIFg"]
[Sun Aug 30 03:11:53.170419 2026] [security2:error] [pid 521505:tid 521745] [client 20.104.49.130:39432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/about.php"] [unique_id "apPlyW8byYE0iXl--K51QwAAA4w"]
[Sun Aug 30 03:11:53.171034 2026] [security2:error] [pid 521505:tid 521515] [remote 185.93.89.167:42909] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "direct.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K51RAADIwk"]
[Sun Aug 30 03:11:53.171258 2026] [security2:error] [pid 521505:tid 521549] [remote 185.93.89.167:45621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images8.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K51RQADJis"]
[Sun Aug 30 03:11:53.172169 2026] [security2:error] [pid 521505:tid 521514] [remote 185.93.89.167:64795] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jp.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyW8byYE0iXl--K51RwADOgg"]
[Sun Aug 30 03:11:53.172619 2026] [security2:error] [pid 521505:tid 521530] [remote 185.93.89.167:10845] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "campus.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyW8byYE0iXl--K51SQADlBg"]
[Sun Aug 30 03:11:53.173292 2026] [security2:error] [pid 521505:tid 521555] [remote 185.93.89.167:54367] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webservices.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyW8byYE0iXl--K51SgADMDE"]
[Sun Aug 30 03:11:53.179817 2026] [security2:error] [pid 521505:tid 521632] [remote 185.93.89.167:7437] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images7.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K51TAADIX4"]
[Sun Aug 30 03:11:53.180349 2026] [security2:error] [pid 521505:tid 521562] [remote 185.93.89.167:62949] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "board.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyW8byYE0iXl--K51TQADgDg"]
[Sun Aug 30 03:11:53.180496 2026] [security2:error] [pid 521505:tid 521733] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "board.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyW8byYE0iXl--K51TQADgDg"]
[Sun Aug 30 03:11:53.180830 2026] [security2:error] [pid 521505:tid 521524] [remote 185.93.89.167:59907] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "health.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K51TwADThI"]
[Sun Aug 30 03:11:53.181666 2026] [security2:error] [pid 521505:tid 521507] [remote 185.93.89.167:42995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns12.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K51UAADggE"]
[Sun Aug 30 03:11:53.181695 2026] [security2:error] [pid 521505:tid 521564] [remote 185.93.89.167:47169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "order.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K51UQADLTo"]
[Sun Aug 30 03:11:53.181736 2026] [security2:error] [pid 521505:tid 521512] [remote 185.93.89.167:48523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "web01.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K51UgADPgY"]
[Sun Aug 30 03:11:53.182107 2026] [security2:error] [pid 521505:tid 521685] [client 158.23.184.117:19720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/cms.php"] [unique_id "apPlyW8byYE0iXl--K51UwAAA1A"]
[Sun Aug 30 03:11:53.182842 2026] [security2:error] [pid 521505:tid 521548] [remote 185.93.89.167:37843] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jupiter.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K51VAADnSo"]
[Sun Aug 30 03:11:53.184050 2026] [security2:error] [pid 521505:tid 521542] [remote 185.93.89.167:24213] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "in.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K51VQADJSQ"]
[Sun Aug 30 03:11:53.186922 2026] [security2:error] [pid 521505:tid 521628] [remote 185.93.89.167:4349] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mm.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyW8byYE0iXl--K51VwADP3o"]
[Sun Aug 30 03:11:53.187150 2026] [authz_core:error] [pid 521505:tid 521704] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:53.187398 2026] [authz_core:error] [pid 521505:tid 521704] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:53.190387 2026] [security2:error] [pid 521505:tid 521570] [remote 185.93.89.167:16627] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "education.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K51WAADSUA"]
[Sun Aug 30 03:11:53.191878 2026] [security2:error] [pid 521505:tid 521580] [remote 185.93.89.167:63379] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reviews.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K51WgADbEo"]
[Sun Aug 30 03:11:53.193253 2026] [security2:error] [pid 521505:tid 521538] [remote 185.93.89.167:36485] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "shopping.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K51WwADSiA"]
[Sun Aug 30 03:11:53.194752 2026] [security2:error] [pid 521505:tid 521517] [remote 185.93.89.167:62709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp3.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K51XQADSAs"]
[Sun Aug 30 03:11:53.198339 2026] [security2:error] [pid 521505:tid 521534] [remote 185.93.89.167:34607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sports.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K51XwADkhw"]
[Sun Aug 30 03:11:53.202241 2026] [security2:error] [pid 521505:tid 521532] [remote 185.93.89.167:15109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "linux.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyW8byYE0iXl--K51YAADexo"]
[Sun Aug 30 03:11:53.203393 2026] [security2:error] [pid 521505:tid 521737] [client 4.205.62.107:52836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/xza.php"] [unique_id "apPlyW8byYE0iXl--K51YgAAA4Q"]
[Sun Aug 30 03:11:53.205706 2026] [security2:error] [pid 521505:tid 521568] [remote 185.93.89.167:8597] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "drupal.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K51YwADaz4"]
[Sun Aug 30 03:11:53.212381 2026] [security2:error] [pid 521505:tid 521558] [remote 185.93.89.167:18729] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ntp1.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K51aAADRzQ"]
[Sun Aug 30 03:11:53.214103 2026] [security2:error] [pid 521505:tid 521567] [remote 185.93.89.167:37291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "st.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyW8byYE0iXl--K51aQADYj0"]
[Sun Aug 30 03:11:53.217977 2026] [security2:error] [pid 521505:tid 521540] [remote 185.93.89.167:11075] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "redirect.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K51bgADiyI"]
[Sun Aug 30 03:11:53.220544 2026] [security2:error] [pid 521505:tid 521511] [remote 185.93.89.167:42991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "venus.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K51cgADQQU"]
[Sun Aug 30 03:11:53.225711 2026] [security2:error] [pid 521505:tid 521571] [remote 185.93.89.167:41989] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ipfixe.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K51cwADYEE"]
[Sun Aug 30 03:11:53.226431 2026] [security2:error] [pid 521505:tid 521528] [remote 185.93.89.167:10145] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "g.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K51dQADkBY"]
[Sun Aug 30 03:11:53.226896 2026] [security2:error] [pid 521505:tid 521554] [remote 185.93.89.167:1175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pgsql.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K51dgADaDA"]
[Sun Aug 30 03:11:53.228392 2026] [security2:error] [pid 521505:tid 521581] [remote 185.93.89.167:28567] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "user.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyW8byYE0iXl--K51eQADVEs"]
[Sun Aug 30 03:11:53.228795 2026] [security2:error] [pid 521505:tid 521550] [remote 185.93.89.167:45765] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns01.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyW8byYE0iXl--K51eAADRiw"]
[Sun Aug 30 03:11:53.228815 2026] [security2:error] [pid 521505:tid 521578] [remote 185.93.89.167:22281] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "labs.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyW8byYE0iXl--K51egADfkg"]
[Sun Aug 30 03:11:53.229295 2026] [security2:error] [pid 521505:tid 521726] [client 20.104.50.220:17264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/bless11.php"] [unique_id "apPlyW8byYE0iXl--K51fAAAA3k"]
[Sun Aug 30 03:11:53.231904 2026] [security2:error] [pid 521505:tid 521519] [remote 185.93.89.167:55243] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oldmail.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K51fQADPA0"]
[Sun Aug 30 03:11:53.231985 2026] [security2:error] [pid 521505:tid 521536] [remote 185.93.89.167:36741] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "software.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K51fgADTR4"]
[Sun Aug 30 03:11:53.232471 2026] [security2:error] [pid 521505:tid 521573] [remote 185.93.89.167:57109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "development.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K51fwADbkM"]
[Sun Aug 30 03:11:53.233010 2026] [security2:error] [pid 521505:tid 521539] [remote 185.93.89.167:48785] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns02.mariegronley.com"] [uri "/.env"] [unique_id "apPlyW8byYE0iXl--K51gAADmSE"]
[Sun Aug 30 03:11:53.248221 2026] [security2:error] [pid 521505:tid 521575] [remote 185.93.89.167:13069] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sc.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K51hQADYUU"]
[Sun Aug 30 03:11:53.248680 2026] [security2:error] [pid 521505:tid 521579] [remote 185.93.89.167:4287] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "php.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K51hgADm0k"]
[Sun Aug 30 03:11:53.249246 2026] [security2:error] [pid 521505:tid 521557] [remote 185.93.89.167:40249] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tracking.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K51igADMjM"]
[Sun Aug 30 03:11:53.249832 2026] [security2:error] [pid 521505:tid 521526] [remote 185.93.89.167:53853] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atlas.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K51jAADbRQ"]
[Sun Aug 30 03:11:53.250093 2026] [security2:error] [pid 521505:tid 521576] [remote 185.93.89.167:31113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "math.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K51jwADK0Y"]
[Sun Aug 30 03:11:53.250810 2026] [security2:error] [pid 521505:tid 521630] [remote 185.93.89.167:2579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "love.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K51kQADjHw"]
[Sun Aug 30 03:11:53.251121 2026] [security2:error] [pid 521505:tid 521589] [remote 185.93.89.167:29333] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reg.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K51kwADJlM"]
[Sun Aug 30 03:11:53.254208 2026] [authz_core:error] [pid 521505:tid 521746] [client 216.73.216.128:40150] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:53.254454 2026] [authz_core:error] [pid 521505:tid 521746] [client 216.73.216.128:40150] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:53.258812 2026] [security2:error] [pid 521505:tid 521529] [remote 185.93.89.167:21227] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "outlook.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyW8byYE0iXl--K51mAADIRc"]
[Sun Aug 30 03:11:53.266467 2026] [security2:error] [pid 521505:tid 521569] [remote 185.93.89.167:62859] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mailgw.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K51mwADgj8"]
[Sun Aug 30 03:11:53.268676 2026] [security2:error] [pid 521505:tid 521595] [remote 185.93.89.167:56175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "press.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K51nAADPlk"]
[Sun Aug 30 03:11:53.272047 2026] [security2:error] [pid 521505:tid 521591] [remote 185.93.89.167:39177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "register.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K51nwADQFU"]
[Sun Aug 30 03:11:53.273952 2026] [security2:error] [pid 521505:tid 521601] [remote 185.93.89.167:5225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "preprod.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K51pAADWV8"]
[Sun Aug 30 03:11:53.279018 2026] [security2:error] [pid 521505:tid 521605] [remote 185.93.89.167:53363] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "work.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K51pwADKmM"]
[Sun Aug 30 03:11:53.284552 2026] [security2:error] [pid 521505:tid 521712] [client 158.23.147.79:58408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-includes/content.php"] [unique_id "apPlyW8byYE0iXl--K51qwAAA2s"]
[Sun Aug 30 03:11:53.285279 2026] [security2:error] [pid 521505:tid 521626] [remote 185.93.89.167:57009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "static2.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K51rwADhXg"]
[Sun Aug 30 03:11:53.285916 2026] [security2:error] [pid 521505:tid 521613] [remote 185.93.89.167:30871] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "pro.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K51sQADV2s"]
[Sun Aug 30 03:11:53.287565 2026] [security2:error] [pid 521505:tid 521612] [remote 185.93.89.167:62291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rs.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyW8byYE0iXl--K51swADl2o"]
[Sun Aug 30 03:11:53.288777 2026] [security2:error] [pid 521505:tid 521619] [remote 185.93.89.167:7863] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adserver.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K51tAADi3E"]
[Sun Aug 30 03:11:53.294968 2026] [security2:error] [pid 521505:tid 521730] [client 20.104.49.130:57517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/mh.php"] [unique_id "apPlyW8byYE0iXl--K51twAAA30"]
[Sun Aug 30 03:11:53.297796 2026] [security2:error] [pid 521505:tid 521649] [client 4.205.62.107:17313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/userfuns.php"] [unique_id "apPlyW8byYE0iXl--K51uQAAAyw"]
[Sun Aug 30 03:11:53.301836 2026] [security2:error] [pid 521505:tid 521662] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/circleci/.env"] [unique_id "apPlyW8byYE0iXl--K51ugAAAzk"]
[Sun Aug 30 03:11:53.303324 2026] [security2:error] [pid 521505:tid 521749] [client 20.220.10.235:24645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.filtakleen.biz"] [uri "/waf.php"] [unique_id "apPlyW8byYE0iXl--K51vAAAA5A"]
[Sun Aug 30 03:11:53.303353 2026] [security2:error] [pid 521505:tid 521696] [client 20.48.251.3:54749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/admin.php"] [unique_id "apPlyW8byYE0iXl--K51vQAAA1s"]
[Sun Aug 30 03:11:53.304104 2026] [security2:error] [pid 521505:tid 521624] [remote 185.93.89.167:42909] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "direct.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K51vwADf3Y"]
[Sun Aug 30 03:11:53.304581 2026] [security2:error] [pid 521505:tid 521622] [remote 185.93.89.167:45621] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images8.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K51vgADaHQ"]
[Sun Aug 30 03:11:53.306716 2026] [security2:error] [pid 521505:tid 521611] [remote 185.93.89.167:59215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "users.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyW8byYE0iXl--K51wwADfmk"]
[Sun Aug 30 03:11:53.306764 2026] [security2:error] [pid 521505:tid 521625] [remote 185.93.89.167:54367] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webservices.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyW8byYE0iXl--K51wgADRnc"]
[Sun Aug 30 03:11:53.312455 2026] [security2:error] [pid 521505:tid 521621] [remote 185.93.89.167:7437] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "images7.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K51xQADeXM"]
[Sun Aug 30 03:11:53.313639 2026] [security2:error] [pid 521505:tid 521623] [remote 185.93.89.167:59907] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "health.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K51yAADRHU"]
[Sun Aug 30 03:11:53.314458 2026] [security2:error] [pid 521505:tid 521631] [remote 185.93.89.167:42995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns12.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K51ygADbn0"]
[Sun Aug 30 03:11:53.314720 2026] [security2:error] [pid 521505:tid 521657] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "board.mariegronley.com"] [uri "/index.cgi"] [unique_id "apPlyW8byYE0iXl--K51xgADNCU"]
[Sun Aug 30 03:11:53.314823 2026] [security2:error] [pid 521505:tid 521513] [remote 185.93.89.167:47169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "order.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K51yQADTQc"]
[Sun Aug 30 03:11:53.315147 2026] [security2:error] [pid 521505:tid 521510] [remote 185.93.89.167:48523] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K51ywADmQQ"]
[Sun Aug 30 03:11:53.317251 2026] [security2:error] [pid 521505:tid 521627] [remote 185.93.89.167:24213] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "in.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K51zQADS3k"]
[Sun Aug 30 03:11:53.318835 2026] [security2:error] [pid 521505:tid 521531] [remote 185.93.89.167:37521] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K51zwADaRk"]
[Sun Aug 30 03:11:53.322359 2026] [security2:error] [pid 521505:tid 521677] [client 158.23.184.117:20171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/config.php"] [unique_id "apPlyW8byYE0iXl--K510QAAA0g"]
[Sun Aug 30 03:11:53.323482 2026] [security2:error] [pid 521505:tid 521553] [remote 185.93.89.167:16627] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "education.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K510gADVS8"]
[Sun Aug 30 03:11:53.328242 2026] [security2:error] [pid 521505:tid 521547] [remote 185.93.89.167:62709] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp3.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K512AADkSk"]
[Sun Aug 30 03:11:53.329987 2026] [security2:error] [pid 521505:tid 521615] [remote 185.93.89.167:34357] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banners.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K512QADMm0"]
[Sun Aug 30 03:11:53.331654 2026] [security2:error] [pid 521505:tid 521541] [remote 185.93.89.167:34607] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sports.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K512gADbSM"]
[Sun Aug 30 03:11:53.333789 2026] [security2:error] [pid 521505:tid 521666] [client 20.104.50.220:33041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/index8.php"] [unique_id "apPlyW8byYE0iXl--K513AAAAz0"]
[Sun Aug 30 03:11:53.338698 2026] [security2:error] [pid 521505:tid 521549] [remote 185.93.89.167:8597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drupal.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K514AADJis"]
[Sun Aug 30 03:11:53.345012 2026] [security2:error] [pid 521505:tid 521555] [remote 185.93.89.167:18729] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "ntp1.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K515gADlDE"]
[Sun Aug 30 03:11:53.350660 2026] [security2:error] [pid 521505:tid 521562] [remote 185.93.89.167:16669] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "links.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K516wADITg"]
[Sun Aug 30 03:11:53.351297 2026] [security2:error] [pid 521505:tid 521524] [remote 185.93.89.167:9731] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images5.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K517AADIhI"]
[Sun Aug 30 03:11:53.351337 2026] [security2:error] [pid 521505:tid 521564] [remote 185.93.89.167:11075] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "redirect.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K517QADgDo"]
[Sun Aug 30 03:11:53.353322 2026] [security2:error] [pid 521505:tid 521507] [remote 185.93.89.167:3789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vc.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K517wADgQE"]
[Sun Aug 30 03:11:53.354045 2026] [security2:error] [pid 521505:tid 521535] [remote 185.93.89.167:42991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "venus.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K518QADgh0"]
[Sun Aug 30 03:11:53.358348 2026] [security2:error] [pid 521505:tid 521548] [remote 185.93.89.167:41989] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "ipfixe.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K518wADdSo"]
[Sun Aug 30 03:11:53.359088 2026] [security2:error] [pid 521505:tid 521542] [remote 185.93.89.167:10145] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "g.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K519AADUCQ"]
[Sun Aug 30 03:11:53.359705 2026] [security2:error] [pid 521505:tid 521565] [remote 185.93.89.167:1175] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "pgsql.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K519QADQDs"]
[Sun Aug 30 03:11:53.361233 2026] [security2:error] [pid 521505:tid 521628] [remote 185.93.89.167:13143] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "net.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyW8byYE0iXl--K519gADJXo"]
[Sun Aug 30 03:11:53.361857 2026] [security2:error] [pid 521505:tid 521570] [remote 185.93.89.167:28567] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "user.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyW8byYE0iXl--K519wADSUA"]
[Sun Aug 30 03:11:53.362427 2026] [security2:error] [pid 521505:tid 521580] [remote 185.93.89.167:22281] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "labs.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyW8byYE0iXl--K51-AADWUo"]
[Sun Aug 30 03:11:53.362494 2026] [security2:error] [pid 521505:tid 521538] [remote 185.93.89.167:32655] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lync.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K51-gADbCA"]
[Sun Aug 30 03:11:53.364728 2026] [security2:error] [pid 521505:tid 521517] [remote 185.93.89.167:50005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fax.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K51-wADSgs"]
[Sun Aug 30 03:11:53.365272 2026] [security2:error] [pid 521505:tid 521561] [remote 185.93.89.167:57109] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "development.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K51_gADhDc"]
[Sun Aug 30 03:11:53.365367 2026] [security2:error] [pid 521505:tid 521534] [remote 185.93.89.167:55243] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oldmail.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K51_QADOxw"]
[Sun Aug 30 03:11:53.365436 2026] [security2:error] [pid 521505:tid 521544] [remote 185.93.89.167:36741] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "software.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K51_AADKiY"]
[Sun Aug 30 03:11:53.366265 2026] [security2:error] [pid 521505:tid 521544] [remote 185.93.89.167:48785] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns02.mariegronley.com"] [uri "/api/.env"] [unique_id "apPlyW8byYE0iXl--K51_wADmCY"]
[Sun Aug 30 03:11:53.369021 2026] [security2:error] [pid 521505:tid 521738] [client 20.104.50.220:25463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/dejavu.php"] [unique_id "apPlyW8byYE0iXl--K52AQAAA4U"]
[Sun Aug 30 03:11:53.371072 2026] [security2:error] [pid 521505:tid 521629] [remote 185.93.89.167:14681] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mc.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyW8byYE0iXl--K52AgADR3s"]
[Sun Aug 30 03:11:53.381251 2026] [security2:error] [pid 521505:tid 521568] [remote 185.93.89.167:13069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sc.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K52AwADYj4"]
[Sun Aug 30 03:11:53.381919 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:4287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "php.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K52BAADX00"]
[Sun Aug 30 03:11:53.382693 2026] [security2:error] [pid 521505:tid 521558] [remote 185.93.89.167:53853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atlas.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K52BgADajQ"]
[Sun Aug 30 03:11:53.383539 2026] [security2:error] [pid 521505:tid 521567] [remote 185.93.89.167:31113] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "math.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K52BwADiz0"]
[Sun Aug 30 03:11:53.383788 2026] [security2:error] [pid 521505:tid 521523] [remote 185.93.89.167:52789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "market.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyW8byYE0iXl--K52CQADiRE"]
[Sun Aug 30 03:11:53.383830 2026] [security2:error] [pid 521505:tid 521537] [remote 185.93.89.167:2579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "love.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K52CgADlR8"]
[Sun Aug 30 03:11:53.384177 2026] [security2:error] [pid 521505:tid 521540] [remote 185.93.89.167:29333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reg.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K52DAADeiI"]
[Sun Aug 30 03:11:53.384452 2026] [security2:error] [pid 521505:tid 521523] [remote 185.93.89.167:14453] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K52DQADQRE"]
[Sun Aug 30 03:11:53.387876 2026] [security2:error] [pid 521505:tid 521693] [client 20.197.61.180:3145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/upgrade-temp-backup/themes/wp-links-opml.php"] [unique_id "apPlyW8byYE0iXl--K52EAAAA1g"]
[Sun Aug 30 03:11:53.388214 2026] [security2:error] [pid 521505:tid 521759] [client 20.104.18.15:51181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/akismet.php"] [unique_id "apPlyW8byYE0iXl--K52EQAAA5o"]
[Sun Aug 30 03:11:53.392712 2026] [security2:error] [pid 521505:tid 521749] [client 4.205.62.107:25485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/phpversion.php"] [unique_id "apPlyW8byYE0iXl--K52EwAAA5A"]
[Sun Aug 30 03:11:53.401424 2026] [security2:error] [pid 521505:tid 521585] [remote 185.93.89.167:56175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "press.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K52FgADW08"]
[Sun Aug 30 03:11:53.405283 2026] [security2:error] [pid 521505:tid 521581] [remote 185.93.89.167:39177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "register.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K52GAADfks"]
[Sun Aug 30 03:11:53.405776 2026] [security2:error] [pid 521505:tid 521578] [remote 185.93.89.167:49893] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mdm.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K52GgADVEg"]
[Sun Aug 30 03:11:53.406947 2026] [security2:error] [pid 521505:tid 521577] [remote 185.93.89.167:60123] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "up.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K52HAADnEc"]
[Sun Aug 30 03:11:53.407007 2026] [security2:error] [pid 521505:tid 521519] [remote 185.93.89.167:5225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preprod.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K52HQADeQ0"]
[Sun Aug 30 03:11:53.407625 2026] [security2:error] [pid 521505:tid 521536] [remote 185.93.89.167:53985] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "img3.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K52HgADRB4"]
[Sun Aug 30 03:11:53.408381 2026] [security2:error] [pid 521505:tid 521536] [remote 185.93.89.167:63579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "wifi.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K52HwADbh4"]
[Sun Aug 30 03:11:53.418544 2026] [security2:error] [pid 521505:tid 521557] [remote 185.93.89.167:57009] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "static2.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K52KAADVTM"]
[Sun Aug 30 03:11:53.421302 2026] [security2:error] [pid 521505:tid 521560] [remote 185.93.89.167:6761] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banner.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K52LwADZzY"]
[Sun Aug 30 03:11:53.421673 2026] [security2:error] [pid 521505:tid 521589] [remote 185.93.89.167:7863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adserver.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K52MQADXVM"]
[Sun Aug 30 03:11:53.437412 2026] [security2:error] [pid 521505:tid 521596] [remote 185.93.89.167:45621] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "images8.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K52PQADIlo"]
[Sun Aug 30 03:11:53.440035 2026] [security2:error] [pid 521505:tid 521591] [remote 185.93.89.167:64795] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jp.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyW8byYE0iXl--K52QAADQ1U"]
[Sun Aug 30 03:11:53.441688 2026] [security2:error] [pid 521505:tid 521545] [remote 185.93.89.167:10845] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "campus.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyW8byYE0iXl--K52QQADTic"]
[Sun Aug 30 03:11:53.441785 2026] [security2:error] [pid 521505:tid 521593] [remote 185.93.89.167:24005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "radius.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyW8byYE0iXl--K52QwADLVc"]
[Sun Aug 30 03:11:53.447329 2026] [security2:error] [pid 521505:tid 521598] [remote 185.93.89.167:47169] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "order.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K52SQADQFw"]
[Sun Aug 30 03:11:53.447488 2026] [security2:error] [pid 521505:tid 521563] [remote 185.93.89.167:42995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns12.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K52RwADdTk"]
[Sun Aug 30 03:11:53.448055 2026] [security2:error] [pid 521505:tid 521605] [remote 185.93.89.167:48523] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "web01.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K52SgADJWM"]
[Sun Aug 30 03:11:53.449037 2026] [security2:error] [pid 521505:tid 521685] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "board.mariegronley.com"] [uri "/index.cgi"] [unique_id "apPlyW8byYE0iXl--K52SAADUF4"]
[Sun Aug 30 03:11:53.450140 2026] [security2:error] [pid 521505:tid 521599] [remote 185.93.89.167:24213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "in.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K52SwADjV0"]
[Sun Aug 30 03:11:53.451060 2026] [security2:error] [pid 521505:tid 521606] [remote 185.93.89.167:37843] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jupiter.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K52TAADHmQ"]
[Sun Aug 30 03:11:53.452116 2026] [security2:error] [pid 521505:tid 521602] [remote 185.93.89.167:37521] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K52TgADhGA"]
[Sun Aug 30 03:11:53.456326 2026] [security2:error] [pid 521505:tid 521604] [remote 185.93.89.167:16627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "education.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K52UgADV2I"]
[Sun Aug 30 03:11:53.460877 2026] [security2:error] [pid 521505:tid 521603] [remote 185.93.89.167:62709] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "smtp3.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K52WAADi2E"]
[Sun Aug 30 03:11:53.461148 2026] [security2:error] [pid 521505:tid 521626] [remote 185.93.89.167:63379] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reviews.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K52VQADYng"]
[Sun Aug 30 03:11:53.461859 2026] [security2:error] [pid 521505:tid 521610] [remote 185.93.89.167:3495] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K52WQADiWg"]
[Sun Aug 30 03:11:53.464390 2026] [security2:error] [pid 521505:tid 521612] [remote 185.93.89.167:34607] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "sports.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K52XAADlWo"]
[Sun Aug 30 03:11:53.465693 2026] [security2:error] [pid 521505:tid 521727] [client 20.48.251.3:59303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/packed.php"] [unique_id "apPlyW8byYE0iXl--K52XQAAA3o"]
[Sun Aug 30 03:11:53.466899 2026] [security2:error] [pid 521505:tid 521760] [client 158.23.184.117:19597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/configs.php"] [unique_id "apPlyW8byYE0iXl--K52YAAAA5s"]
[Sun Aug 30 03:11:53.470737 2026] [security2:error] [pid 521505:tid 521616] [remote 185.93.89.167:15109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "linux.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyW8byYE0iXl--K52YgADfW4"]
[Sun Aug 30 03:11:53.471960 2026] [security2:error] [pid 521505:tid 521607] [remote 185.93.89.167:8597] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "drupal.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K52YwADWGU"]
[Sun Aug 30 03:11:53.472136 2026] [security2:error] [pid 521505:tid 521618] [remote 185.93.89.167:14659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyW8byYE0iXl--K52ZAADkHA"]
[Sun Aug 30 03:11:53.479757 2026] [security2:error] [pid 521505:tid 521611] [remote 185.93.89.167:11687] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pr.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyW8byYE0iXl--K52aAADaGk"]
[Sun Aug 30 03:11:53.482237 2026] [authz_core:error] [pid 521505:tid 521732] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory27
[Sun Aug 30 03:11:53.482306 2026] [security2:error] [pid 521505:tid 521625] [remote 185.93.89.167:37291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "st.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyW8byYE0iXl--K52aQADfnc"]
[Sun Aug 30 03:11:53.482627 2026] [authz_core:error] [pid 521505:tid 521732] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory27
[Sun Aug 30 03:11:53.484536 2026] [security2:error] [pid 521505:tid 521621] [remote 185.93.89.167:11075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redirect.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K52bQADeXM"]
[Sun Aug 30 03:11:53.485037 2026] [security2:error] [pid 521505:tid 521623] [remote 185.93.89.167:29329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mars.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K52bgADRHU"]
[Sun Aug 30 03:11:53.486908 2026] [security2:error] [pid 521505:tid 521631] [remote 185.93.89.167:3789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vc.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K52bwADbn0"]
[Sun Aug 30 03:11:53.487068 2026] [security2:error] [pid 521505:tid 521543] [remote 185.93.89.167:42991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "venus.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K52cAADTSU"]
[Sun Aug 30 03:11:53.488975 2026] [security2:error] [pid 521505:tid 521513] [remote 185.93.89.167:1995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lp.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K52cQADNAc"]
[Sun Aug 30 03:11:53.498441 2026] [security2:error] [pid 521505:tid 521547] [remote 185.93.89.167:36741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "software.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K52fAADZyk"]
[Sun Aug 30 03:11:53.498556 2026] [security2:error] [pid 521505:tid 521615] [remote 185.93.89.167:55243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldmail.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K52fQADXW0"]
[Sun Aug 30 03:11:53.499402 2026] [security2:error] [pid 521505:tid 521541] [remote 185.93.89.167:48785] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns02.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPlyW8byYE0iXl--K52fgADkSM"]
[Sun Aug 30 03:11:53.500923 2026] [security2:error] [pid 521505:tid 521655] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/travis/.env"] [unique_id "apPlyW8byYE0iXl--K52fwAAAzI"]
[Sun Aug 30 03:11:53.514674 2026] [security2:error] [pid 521505:tid 521533] [remote 185.93.89.167:13069] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sc.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K52gQADdhs"]
[Sun Aug 30 03:11:53.515833 2026] [security2:error] [pid 521505:tid 521549] [remote 185.93.89.167:4287] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "php.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K52ggADRSs"]
[Sun Aug 30 03:11:53.515857 2026] [security2:error] [pid 521505:tid 521515] [remote 185.93.89.167:53853] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atlas.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K52gwADIgk"]
[Sun Aug 30 03:11:53.516432 2026] [security2:error] [pid 521505:tid 521514] [remote 185.93.89.167:31113] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "math.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K52hAADMAg"]
[Sun Aug 30 03:11:53.517243 2026] [security2:error] [pid 521505:tid 521530] [remote 185.93.89.167:40249] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tracking.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K52hgADihg"]
[Sun Aug 30 03:11:53.517297 2026] [security2:error] [pid 521505:tid 521556] [remote 185.93.89.167:2579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "love.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K52hwADgTI"]
[Sun Aug 30 03:11:53.517755 2026] [security2:error] [pid 521505:tid 521524] [remote 185.93.89.167:27945] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K52iwADLRI"]
[Sun Aug 30 03:11:53.517765 2026] [security2:error] [pid 521505:tid 521562] [remote 185.93.89.167:29333] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reg.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K52iQADgjg"]
[Sun Aug 30 03:11:53.518994 2026] [security2:error] [pid 521505:tid 521564] [remote 185.93.89.167:64329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K52jAADOjo"]
[Sun Aug 30 03:11:53.520143 2026] [security2:error] [pid 521505:tid 521507] [remote 185.93.89.167:44659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "p.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyW8byYE0iXl--K52jgADPwE"]
[Sun Aug 30 03:11:53.534471 2026] [security2:error] [pid 521505:tid 521643] [client 20.104.18.15:31659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/xc.php"] [unique_id "apPlyW8byYE0iXl--K52lQAAAyY"]
[Sun Aug 30 03:11:53.534677 2026] [security2:error] [pid 521505:tid 521548] [remote 185.93.89.167:56175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "press.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K52kwADJSo"]
[Sun Aug 30 03:11:53.534707 2026] [security2:error] [pid 521505:tid 521542] [remote 185.93.89.167:12177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tr.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlyW8byYE0iXl--K52lAADUCQ"]
[Sun Aug 30 03:11:53.538711 2026] [security2:error] [pid 521505:tid 521565] [remote 185.93.89.167:39177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "register.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K52lwADjTs"]
[Sun Aug 30 03:11:53.540530 2026] [security2:error] [pid 521505:tid 521580] [remote 185.93.89.167:5225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "preprod.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K52mwADlEo"]
[Sun Aug 30 03:11:53.541243 2026] [security2:error] [pid 521505:tid 521592] [remote 185.93.89.167:53985] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "img3.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K52nQADklY"]
[Sun Aug 30 03:11:53.541268 2026] [security2:error] [pid 521505:tid 521517] [remote 185.93.89.167:14991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "barracuda.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyW8byYE0iXl--K52ngADmAs"]
[Sun Aug 30 03:11:53.541339 2026] [security2:error] [pid 521505:tid 521538] [remote 185.93.89.167:25969] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dbadmin.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyW8byYE0iXl--K52nAADKiA"]
[Sun Aug 30 03:11:53.543683 2026] [security2:error] [pid 521505:tid 521534] [remote 185.93.89.167:9557] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "s4.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K52ogADXhw"]
[Sun Aug 30 03:11:53.545505 2026] [security2:error] [pid 521505:tid 521692] [client 20.151.200.44:26616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/kcs.php"] [unique_id "apPlyW8byYE0iXl--K52pAAAA1c"]
[Sun Aug 30 03:11:53.546396 2026] [security2:error] [pid 521505:tid 521532] [remote 185.93.89.167:53363] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "work.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K52pQADSho"]
[Sun Aug 30 03:11:53.550438 2026] [security2:error] [pid 521505:tid 521568] [remote 185.93.89.167:1591] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyW8byYE0iXl--K52qAADhj4"]
[Sun Aug 30 03:11:53.551348 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:57009] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "static2.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K52qQADi00"]
[Sun Aug 30 03:11:53.552603 2026] [security2:error] [pid 521505:tid 521558] [remote 185.93.89.167:53553] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "demo2.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlyW8byYE0iXl--K52qgADYjQ"]
[Sun Aug 30 03:11:53.554107 2026] [security2:error] [pid 521505:tid 521537] [remote 185.93.89.167:54151] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "affiliate.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K52rgADhR8"]
[Sun Aug 30 03:11:53.555044 2026] [security2:error] [pid 521505:tid 521566] [remote 185.93.89.167:7863] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adserver.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K52sgADbDw"]
[Sun Aug 30 03:11:53.563530 2026] [security2:error] [pid 521505:tid 521661] [client 20.104.49.130:52470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/ty.php"] [unique_id "apPlyW8byYE0iXl--K52tAAAAzg"]
[Sun Aug 30 03:11:53.565984 2026] [security2:error] [pid 521505:tid 521644] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/logs/.env"] [unique_id "apPlyW8byYE0iXl--K52tQAAAyc"]
[Sun Aug 30 03:11:53.574010 2026] [security2:error] [pid 521505:tid 521581] [remote 185.93.89.167:54367] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webservices.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyW8byYE0iXl--K52vgADaEs"]
[Sun Aug 30 03:11:53.576792 2026] [security2:error] [pid 521505:tid 521577] [remote 185.93.89.167:15177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K52xAADRkc"]
[Sun Aug 30 03:11:53.580003 2026] [security2:error] [pid 521505:tid 521573] [remote 185.93.89.167:42995] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "ns12.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K52yAADmUM"]
[Sun Aug 30 03:11:53.582551 2026] [security2:error] [pid 521505:tid 521587] [remote 185.93.89.167:62949] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "board.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyW8byYE0iXl--K52ywADLlE"]
[Sun Aug 30 03:11:53.582701 2026] [security2:error] [pid 521505:tid 521651] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "board.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyW8byYE0iXl--K52ywADLlE"]
[Sun Aug 30 03:11:53.583547 2026] [security2:error] [pid 521505:tid 521518] [remote 185.93.89.167:24213] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "in.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K52zAADVQw"]
[Sun Aug 30 03:11:53.584209 2026] [security2:error] [pid 521505:tid 521588] [remote 185.93.89.167:37843] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jupiter.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K52zQADQlI"]
[Sun Aug 30 03:11:53.585186 2026] [security2:error] [pid 521505:tid 521575] [remote 185.93.89.167:37521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K52zgADZ0U"]
[Sun Aug 30 03:11:53.589410 2026] [security2:error] [pid 521505:tid 521557] [remote 185.93.89.167:16627] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "education.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K520gADljM"]
[Sun Aug 30 03:11:53.594447 2026] [security2:error] [pid 521505:tid 521526] [remote 185.93.89.167:63379] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reviews.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K521AADIhQ"]
[Sun Aug 30 03:11:53.597905 2026] [security2:error] [pid 521505:tid 521574] [remote 185.93.89.167:34357] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banners.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K522AADLUQ"]
[Sun Aug 30 03:11:53.601627 2026] [security2:error] [pid 521505:tid 521560] [remote 185.93.89.167:11851] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "biblioteca.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K522QADITY"]
[Sun Aug 30 03:11:53.604691 2026] [security2:error] [pid 521505:tid 521572] [remote 185.93.89.167:8597] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "drupal.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K523AADQEI"]
[Sun Aug 30 03:11:53.608293 2026] [security2:error] [pid 521505:tid 521637] [client 20.104.50.220:5807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/alpas.php"] [unique_id "apPlyW8byYE0iXl--K523wAAAyA"]
[Sun Aug 30 03:11:53.608726 2026] [security2:error] [pid 521505:tid 521725] [client 158.23.184.117:19735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/configuration.php"] [unique_id "apPlyW8byYE0iXl--K524AAAA3g"]
[Sun Aug 30 03:11:53.609718 2026] [security2:error] [pid 521505:tid 521529] [remote 185.93.89.167:11225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "da.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K524gADJhc"]
[Sun Aug 30 03:11:53.613052 2026] [security2:error] [pid 521505:tid 521591] [remote 185.93.89.167:11687] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pr.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyW8byYE0iXl--K525QADjVU"]
[Sun Aug 30 03:11:53.617831 2026] [security2:error] [pid 521505:tid 521595] [remote 185.93.89.167:16669] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "links.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K526AADlFk"]
[Sun Aug 30 03:11:53.617958 2026] [security2:error] [pid 521505:tid 521545] [remote 185.93.89.167:11075] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "redirect.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K526QADmCc"]
[Sun Aug 30 03:11:53.618833 2026] [security2:error] [pid 521505:tid 521598] [remote 185.93.89.167:9731] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images5.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K527AADe1w"]
[Sun Aug 30 03:11:53.619949 2026] [security2:error] [pid 521505:tid 521563] [remote 185.93.89.167:3789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vc.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K527QADjDk"]
[Sun Aug 30 03:11:53.620394 2026] [security2:error] [pid 521505:tid 521601] [remote 185.93.89.167:42991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "venus.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K527gADKF8"]
[Sun Aug 30 03:11:53.629843 2026] [security2:error] [pid 521505:tid 521603] [remote 185.93.89.167:28567] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "user.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyW8byYE0iXl--K52-QADWWE"]
[Sun Aug 30 03:11:53.630075 2026] [security2:error] [pid 521505:tid 521626] [remote 185.93.89.167:32655] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lync.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K52-gADN3g"]
[Sun Aug 30 03:11:53.630579 2026] [security2:error] [pid 521505:tid 521610] [remote 185.93.89.167:22281] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "labs.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlyW8byYE0iXl--K52-wADl2g"]
[Sun Aug 30 03:11:53.631839 2026] [security2:error] [pid 521505:tid 521551] [remote 185.93.89.167:36741] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "software.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K52_AADbC0"]
[Sun Aug 30 03:11:53.632029 2026] [security2:error] [pid 521505:tid 521613] [remote 185.93.89.167:55243] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oldmail.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K52_QADlWs"]
[Sun Aug 30 03:11:53.632252 2026] [security2:error] [pid 521505:tid 521609] [remote 185.93.89.167:48785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns02.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPlyW8byYE0iXl--K53AAADemc"]
[Sun Aug 30 03:11:53.632272 2026] [security2:error] [pid 521505:tid 521521] [remote 185.93.89.167:50005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fax.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K52_wADSw8"]
[Sun Aug 30 03:11:53.632335 2026] [security2:error] [pid 521505:tid 521612] [remote 185.93.89.167:45765] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns01.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyW8byYE0iXl--K52_gADamo"]
[Sun Aug 30 03:11:53.636735 2026] [security2:error] [pid 521505:tid 521661] [client 4.205.62.107:16348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/sadd.php"] [unique_id "apPlyW8byYE0iXl--K53AwAAAzg"]
[Sun Aug 30 03:11:53.647456 2026] [security2:error] [pid 521505:tid 521607] [remote 185.93.89.167:13069] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "sc.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K53BQADNmU"]
[Sun Aug 30 03:11:53.648620 2026] [security2:error] [pid 521505:tid 521618] [remote 185.93.89.167:53853] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "atlas.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K53BgADaHA"]
[Sun Aug 30 03:11:53.648683 2026] [security2:error] [pid 521505:tid 521624] [remote 185.93.89.167:4287] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "php.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K53BwADWHY"]
[Sun Aug 30 03:11:53.650008 2026] [security2:error] [pid 521505:tid 521625] [remote 185.93.89.167:2579] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "love.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K53CgADVHc"]
[Sun Aug 30 03:11:53.650597 2026] [security2:error] [pid 521505:tid 521611] [remote 185.93.89.167:40249] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tracking.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K53CQADeWk"]
[Sun Aug 30 03:11:53.650613 2026] [security2:error] [pid 521505:tid 521623] [remote 185.93.89.167:29333] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "reg.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K53DQADTXU"]
[Sun Aug 30 03:11:53.653038 2026] [security2:error] [pid 521505:tid 521552] [remote 185.93.89.167:14453] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K53DwADNC4"]
[Sun Aug 30 03:11:53.653405 2026] [security2:error] [pid 521505:tid 521631] [remote 185.93.89.167:14833] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "se.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K53EAADLn0"]
[Sun Aug 30 03:11:53.660027 2026] [security2:error] [pid 521505:tid 521513] [remote 185.93.89.167:21227] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "outlook.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyW8byYE0iXl--K53EwADjwc"]
[Sun Aug 30 03:11:53.667221 2026] [security2:error] [pid 521505:tid 521510] [remote 185.93.89.167:56175] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "press.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K53FwADkQQ"]
[Sun Aug 30 03:11:53.667904 2026] [security2:error] [pid 521505:tid 521627] [remote 185.93.89.167:12177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tr.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlyW8byYE0iXl--K53GAADO3k"]
[Sun Aug 30 03:11:53.671595 2026] [security2:error] [pid 521505:tid 521531] [remote 185.93.89.167:39177] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "register.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K53HQADfhk"]
[Sun Aug 30 03:11:53.673235 2026] [security2:error] [pid 521505:tid 521559] [remote 185.93.89.167:49893] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mdm.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K53IAADkDU"]
[Sun Aug 30 03:11:53.673454 2026] [security2:error] [pid 521505:tid 521553] [remote 185.93.89.167:5225] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "preprod.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K53IgADRS8"]
[Sun Aug 30 03:11:53.674594 2026] [security2:error] [pid 521505:tid 521547] [remote 185.93.89.167:53985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "img3.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K53JAADMCk"]
[Sun Aug 30 03:11:53.675507 2026] [security2:error] [pid 521505:tid 521615] [remote 185.93.89.167:60123] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "up.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K53JgADgm0"]
[Sun Aug 30 03:11:53.676170 2026] [security2:error] [pid 521505:tid 521633] [remote 185.93.89.167:63579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "wifi.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K53KAADTn8"]
[Sun Aug 30 03:11:53.679486 2026] [security2:error] [pid 521505:tid 521541] [remote 185.93.89.167:53363] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "work.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K53LAADJiM"]
[Sun Aug 30 03:11:53.680590 2026] [security2:error] [pid 521505:tid 521546] [remote 185.93.89.167:61033] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K53LgADJSg"]
[Sun Aug 30 03:11:53.686034 2026] [security2:error] [pid 521505:tid 521515] [remote 185.93.89.167:53553] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "demo2.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlyW8byYE0iXl--K53NgADhAk"]
[Sun Aug 30 03:11:53.687295 2026] [authz_core:error] [pid 521505:tid 521697] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:53.687678 2026] [security2:error] [pid 521505:tid 521530] [remote 185.93.89.167:7863] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "adserver.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K53OAADUBg"]
[Sun Aug 30 03:11:53.687713 2026] [authz_core:error] [pid 521505:tid 521697] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:53.688554 2026] [security2:error] [pid 521505:tid 521556] [remote 185.93.89.167:56429] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mb.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K53OQADSTI"]
[Sun Aug 30 03:11:53.688625 2026] [security2:error] [pid 521505:tid 521684] [client 20.48.251.3:36841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/wpver.php"] [unique_id "apPlyW8byYE0iXl--K53PAAAA08"]
[Sun Aug 30 03:11:53.688718 2026] [security2:error] [pid 521505:tid 521524] [remote 185.93.89.167:23169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K53OgADfBI"]
[Sun Aug 30 03:11:53.692959 2026] [security2:error] [pid 521505:tid 521555] [remote 185.93.89.167:26309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piwik.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlyW8byYE0iXl--K53PwADhjE"]
[Sun Aug 30 03:11:53.696466 2026] [security2:error] [pid 521505:tid 521660] [client 20.48.160.90:61461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/ops.php"] [unique_id "apPlyW8byYE0iXl--K53QQAAAzc"]
[Sun Aug 30 03:11:53.700174 2026] [security2:error] [pid 521505:tid 521713] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/buildkite/.env"] [unique_id "apPlyW8byYE0iXl--K53QgAAA2w"]
[Sun Aug 30 03:11:53.705984 2026] [security2:error] [pid 521505:tid 521632] [remote 185.93.89.167:64215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m1.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlyW8byYE0iXl--K53RwADan4"]
[Sun Aug 30 03:11:53.716264 2026] [security2:error] [pid 521505:tid 521532] [remote 185.93.89.167:24213] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "in.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K53VwADNBo"]
[Sun Aug 30 03:11:53.717032 2026] [security2:error] [pid 521505:tid 521544] [remote 185.93.89.167:37843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jupiter.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K53WQADbiY"]
[Sun Aug 30 03:11:53.718574 2026] [security2:error] [pid 521505:tid 521568] [remote 185.93.89.167:37521] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K53WgADLj4"]
[Sun Aug 30 03:11:53.722015 2026] [security2:error] [pid 521505:tid 521629] [remote 185.93.89.167:16627] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "education.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K53XAADY3s"]
[Sun Aug 30 03:11:53.726188 2026] [security2:error] [pid 521505:tid 521732] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/cache/.env"] [unique_id "apPlyW8byYE0iXl--K53XQAAA38"]
[Sun Aug 30 03:11:53.727703 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:63379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviews.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K53XgADR00"]
[Sun Aug 30 03:11:53.729252 2026] [security2:error] [pid 521505:tid 521558] [remote 185.93.89.167:36485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shopping.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlyW8byYE0iXl--K53YAADSjQ"]
[Sun Aug 30 03:11:53.730836 2026] [security2:error] [pid 521505:tid 521566] [remote 185.93.89.167:39923] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sitebuilder.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K53YQADXTw"]
[Sun Aug 30 03:11:53.730931 2026] [security2:error] [pid 521505:tid 521540] [remote 185.93.89.167:34357] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banners.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K53YwADkSI"]
[Sun Aug 30 03:11:53.741724 2026] [security2:error] [pid 521505:tid 521571] [remote 185.93.89.167:3495] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K53bAADLUE"]
[Sun Aug 30 03:11:53.747763 2026] [authz_core:error] [pid 521505:tid 521700] [client 66.249.66.196:50537] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:53.748155 2026] [authz_core:error] [pid 521505:tid 521700] [client 66.249.66.196:50537] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:53.748970 2026] [security2:error] [pid 521505:tid 521727] [client 158.23.184.117:20191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/content.php"] [unique_id "apPlyW8byYE0iXl--K53dwAAA3o"]
[Sun Aug 30 03:11:53.750802 2026] [security2:error] [pid 521505:tid 521577] [remote 185.93.89.167:11075] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "redirect.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K53ewADJkc"]
[Sun Aug 30 03:11:53.751169 2026] [security2:error] [pid 521505:tid 521550] [remote 185.93.89.167:16669] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "links.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K53egADQCw"]
[Sun Aug 30 03:11:53.752288 2026] [security2:error] [pid 521505:tid 521519] [remote 185.93.89.167:29329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mars.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K53fQADPQ0"]
[Sun Aug 30 03:11:53.752504 2026] [security2:error] [pid 521505:tid 521573] [remote 185.93.89.167:9731] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images5.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K53fAADJUM"]
[Sun Aug 30 03:11:53.752801 2026] [security2:error] [pid 521505:tid 521705] [client 20.104.50.220:51555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/index6.php"] [unique_id "apPlyW8byYE0iXl--K53fwAAA2Q"]
[Sun Aug 30 03:11:53.752880 2026] [security2:error] [pid 521505:tid 521522] [remote 185.93.89.167:59097] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web6.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K53fgADRBA"]
[Sun Aug 30 03:11:53.753328 2026] [security2:error] [pid 521505:tid 521587] [remote 185.93.89.167:42991] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "venus.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K53gQADRFE"]
[Sun Aug 30 03:11:53.753420 2026] [security2:error] [pid 521505:tid 521536] [remote 185.93.89.167:3789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vc.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K53gAADjR4"]
[Sun Aug 30 03:11:53.758986 2026] [security2:error] [pid 521505:tid 521539] [remote 185.93.89.167:1995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lp.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K53gwADTCE"]
[Sun Aug 30 03:11:53.760082 2026] [security2:error] [pid 521505:tid 521757] [client 20.104.50.220:62836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/images/lux.php"] [unique_id "apPlyW8byYE0iXl--K53hgAAA5g"]
[Sun Aug 30 03:11:53.763210 2026] [security2:error] [pid 521505:tid 521557] [remote 185.93.89.167:13143] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "net.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyW8byYE0iXl--K53igADTzM"]
[Sun Aug 30 03:11:53.763227 2026] [security2:error] [pid 521505:tid 521526] [remote 185.93.89.167:32655] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lync.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K53iwADfBQ"]
[Sun Aug 30 03:11:53.764793 2026] [security2:error] [pid 521505:tid 521576] [remote 185.93.89.167:36741] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "software.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K53jgADi0Y"]
[Sun Aug 30 03:11:53.764934 2026] [security2:error] [pid 521505:tid 521630] [remote 185.93.89.167:55243] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "oldmail.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K53kAADKnw"]
[Sun Aug 30 03:11:53.765722 2026] [security2:error] [pid 521505:tid 521560] [remote 185.93.89.167:50005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fax.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K53kQADWTY"]
[Sun Aug 30 03:11:53.773548 2026] [security2:error] [pid 521505:tid 521572] [remote 185.93.89.167:14681] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mc.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyW8byYE0iXl--K53lAADbEI"]
[Sun Aug 30 03:11:53.783391 2026] [security2:error] [pid 521505:tid 521569] [remote 185.93.89.167:40249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracking.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K53mQADYj8"]
[Sun Aug 30 03:11:53.785481 2026] [security2:error] [pid 521505:tid 521595] [remote 185.93.89.167:27945] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K53nAADOFk"]
[Sun Aug 30 03:11:53.785592 2026] [security2:error] [pid 521505:tid 521598] [remote 185.93.89.167:52789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "market.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyW8byYE0iXl--K53nQADJ1w"]
[Sun Aug 30 03:11:53.786312 2026] [security2:error] [pid 521505:tid 521593] [remote 185.93.89.167:64329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K53nwADLFc"]
[Sun Aug 30 03:11:53.786715 2026] [security2:error] [pid 521505:tid 521597] [remote 185.93.89.167:14453] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K53oAADV1s"]
[Sun Aug 30 03:11:53.798039 2026] [security2:error] [pid 521505:tid 521677] [client 158.23.147.79:39952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-includes/css/index.php"] [unique_id "apPlyW8byYE0iXl--K53pgAAA0g"]
[Sun Aug 30 03:11:53.802659 2026] [security2:error] [pid 521505:tid 521602] [remote 185.93.89.167:62859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailgw.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlyW8byYE0iXl--K53qQADRmA"]
[Sun Aug 30 03:11:53.803897 2026] [authz_core:error] [pid 521505:tid 521657] [client 216.73.216.128:37868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:53.804169 2026] [authz_core:error] [pid 521505:tid 521657] [client 216.73.216.128:37868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:53.806641 2026] [security2:error] [pid 521505:tid 521603] [remote 185.93.89.167:49893] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mdm.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K53rAADQmE"]
[Sun Aug 30 03:11:53.808681 2026] [security2:error] [pid 521505:tid 521610] [remote 185.93.89.167:53985] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "img3.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K53rwADO2g"]
[Sun Aug 30 03:11:53.808922 2026] [security2:error] [pid 521505:tid 521551] [remote 185.93.89.167:60123] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "up.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K53sQADKy0"]
[Sun Aug 30 03:11:53.810028 2026] [security2:error] [pid 521505:tid 521613] [remote 185.93.89.167:63579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "wifi.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K53sgADfms"]
[Sun Aug 30 03:11:53.812338 2026] [security2:error] [pid 521505:tid 521619] [remote 185.93.89.167:53363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "work.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K53tgADcXE"]
[Sun Aug 30 03:11:53.812522 2026] [security2:error] [pid 521505:tid 521612] [remote 185.93.89.167:9557] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "s4.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K53tQADMGo"]
[Sun Aug 30 03:11:53.815354 2026] [security2:error] [pid 521505:tid 521668] [client 20.104.18.15:18269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/gos.php"] [unique_id "apPlyW8byYE0iXl--K53uQAAAz8"]
[Sun Aug 30 03:11:53.818757 2026] [security2:error] [pid 521505:tid 521618] [remote 185.93.89.167:37133] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K53vAADenA"]
[Sun Aug 30 03:11:53.822277 2026] [security2:error] [pid 521505:tid 521621] [remote 185.93.89.167:54151] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "affiliate.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K53xQADJXM"]
[Sun Aug 30 03:11:53.823088 2026] [security2:error] [pid 521505:tid 521608] [remote 185.93.89.167:30871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pro.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlyW8byYE0iXl--K53xgADZGY"]
[Sun Aug 30 03:11:53.826530 2026] [security2:error] [pid 521505:tid 521614] [remote 185.93.89.167:26309] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "piwik.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlyW8byYE0iXl--K53xwADe2w"]
[Sun Aug 30 03:11:53.833648 2026] [authz_core:error] [pid 521505:tid 521745] [client 66.249.66.73:65130] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:53.833912 2026] [authz_core:error] [pid 521505:tid 521745] [client 66.249.66.73:65130] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:53.840554 2026] [security2:error] [pid 521505:tid 521552] [remote 185.93.89.167:64215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlyW8byYE0iXl--K53ywADRC4"]
[Sun Aug 30 03:11:53.841309 2026] [security2:error] [pid 521505:tid 521543] [remote 185.93.89.167:42909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direct.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlyW8byYE0iXl--K53zgADjSU"]
[Sun Aug 30 03:11:53.842979 2026] [security2:error] [pid 521505:tid 521510] [remote 185.93.89.167:64795] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jp.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyW8byYE0iXl--K530QADTAQ"]
[Sun Aug 30 03:11:53.845136 2026] [security2:error] [pid 521505:tid 521508] [remote 185.93.89.167:10845] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "campus.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyW8byYE0iXl--K530wADIgI"]
[Sun Aug 30 03:11:53.848904 2026] [security2:error] [pid 521505:tid 521553] [remote 185.93.89.167:7437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images7.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlyW8byYE0iXl--K531gADHi8"]
[Sun Aug 30 03:11:53.849793 2026] [security2:error] [pid 521505:tid 521633] [remote 185.93.89.167:59907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "health.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlyW8byYE0iXl--K532QADUH8"]
[Sun Aug 30 03:11:53.850598 2026] [security2:error] [pid 521505:tid 521584] [remote 185.93.89.167:37843] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jupiter.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K532gADOk4"]
[Sun Aug 30 03:11:53.851425 2026] [security2:error] [pid 521505:tid 521516] [remote 185.93.89.167:37521] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "internal.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K533AADcwo"]
[Sun Aug 30 03:11:53.856661 2026] [security2:error] [pid 521505:tid 521546] [remote 185.93.89.167:15177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K533wADfCg"]
[Sun Aug 30 03:11:53.861211 2026] [security2:error] [pid 521505:tid 521594] [remote 185.93.89.167:63379] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reviews.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K534AADT1g"]
[Sun Aug 30 03:11:53.862568 2026] [security2:error] [pid 521505:tid 521549] [remote 185.93.89.167:36485] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "shopping.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlyW8byYE0iXl--K534gADKis"]
[Sun Aug 30 03:11:53.863697 2026] [security2:error] [pid 521505:tid 521515] [remote 185.93.89.167:34357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "banners.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K534wADIQk"]
[Sun Aug 30 03:11:53.869522 2026] [security2:error] [pid 521505:tid 521524] [remote 185.93.89.167:11851] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "biblioteca.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K535wADYhI"]
[Sun Aug 30 03:11:53.873337 2026] [security2:error] [pid 521505:tid 521514] [remote 185.93.89.167:15109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "linux.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyW8byYE0iXl--K536AADOAg"]
[Sun Aug 30 03:11:53.877859 2026] [security2:error] [pid 521505:tid 521632] [remote 185.93.89.167:11225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "da.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlyW8byYE0iXl--K537AADTX4"]
[Sun Aug 30 03:11:53.880805 2026] [security2:error] [pid 521505:tid 521564] [remote 185.93.89.167:18729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ntp1.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlyW8byYE0iXl--K537gADRjo"]
[Sun Aug 30 03:11:53.881701 2026] [security2:error] [pid 521505:tid 521506] [remote 185.93.89.167:3495] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K537wADdAA"]
[Sun Aug 30 03:11:53.884041 2026] [security2:error] [pid 521505:tid 521542] [remote 185.93.89.167:16669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "links.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K538wADkCQ"]
[Sun Aug 30 03:11:53.884052 2026] [security2:error] [pid 521505:tid 521548] [remote 185.93.89.167:37291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "st.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlyW8byYE0iXl--K538AADfyo"]
[Sun Aug 30 03:11:53.885549 2026] [security2:error] [pid 521505:tid 521759] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/mailer/.env"] [unique_id "apPlyW8byYE0iXl--K539AAAA5o"]
[Sun Aug 30 03:11:53.885613 2026] [security2:error] [pid 521505:tid 521565] [remote 185.93.89.167:29329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mars.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K539QADOTs"]
[Sun Aug 30 03:11:53.885626 2026] [security2:error] [pid 521505:tid 521512] [remote 185.93.89.167:9731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images5.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K539gADfgY"]
[Sun Aug 30 03:11:53.886265 2026] [security2:error] [pid 521505:tid 521592] [remote 185.93.89.167:3789] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "vc.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K53-gADIFY"]
[Sun Aug 30 03:11:53.889170 2026] [security2:error] [pid 521505:tid 521532] [remote 185.93.89.167:4349] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mm.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlyW8byYE0iXl--K53_AADSxo"]
[Sun Aug 30 03:11:53.893019 2026] [security2:error] [pid 521505:tid 521544] [remote 185.93.89.167:41989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ipfixe.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlyW8byYE0iXl--K53_wADQCY"]
[Sun Aug 30 03:11:53.893671 2026] [security2:error] [pid 521505:tid 521538] [remote 185.93.89.167:1995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lp.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K53_gADZCA"]
[Sun Aug 30 03:11:53.894917 2026] [security2:error] [pid 521505:tid 521534] [remote 185.93.89.167:10145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlyW8byYE0iXl--K54AAADVRw"]
[Sun Aug 30 03:11:53.896300 2026] [security2:error] [pid 521505:tid 521561] [remote 185.93.89.167:32655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lync.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K54AQADSjc"]
[Sun Aug 30 03:11:53.898995 2026] [security2:error] [pid 521505:tid 521537] [remote 185.93.89.167:50005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fax.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K54BQADRB8"]
[Sun Aug 30 03:11:53.902020 2026] [security2:error] [pid 521505:tid 521746] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/mysql/.env"] [unique_id "apPlyW8byYE0iXl--K54BgAAA40"]
[Sun Aug 30 03:11:53.917654 2026] [security2:error] [pid 521505:tid 521566] [remote 185.93.89.167:40249] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tracking.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K54CAADIjw"]
[Sun Aug 30 03:11:53.918948 2026] [security2:error] [pid 521505:tid 521540] [remote 185.93.89.167:27945] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K54CQADHiI"]
[Sun Aug 30 03:11:53.919990 2026] [security2:error] [pid 521505:tid 521620] [remote 185.93.89.167:14453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mobil.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K54DQADknI"]
[Sun Aug 30 03:11:53.920702 2026] [security2:error] [pid 521505:tid 521582] [remote 185.93.89.167:64329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K54CwADOkw"]
[Sun Aug 30 03:11:53.936998 2026] [security2:error] [pid 521505:tid 521525] [remote 185.93.89.167:62859] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mailgw.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlyW8byYE0iXl--K54DgADTxM"]
[Sun Aug 30 03:11:53.939703 2026] [security2:error] [pid 521505:tid 521511] [remote 185.93.89.167:49893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdm.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K54DwADKgU"]
[Sun Aug 30 03:11:53.941772 2026] [security2:error] [pid 521505:tid 521571] [remote 185.93.89.167:53985] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "img3.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K54EAADIUE"]
[Sun Aug 30 03:11:53.942003 2026] [security2:error] [pid 521505:tid 521528] [remote 185.93.89.167:60123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "up.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K54EQADhBY"]
[Sun Aug 30 03:11:53.943115 2026] [security2:error] [pid 521505:tid 521554] [remote 185.93.89.167:63579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wifi.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlyW8byYE0iXl--K54EgADUTA"]
[Sun Aug 30 03:11:53.946038 2026] [security2:error] [pid 521505:tid 521585] [remote 185.93.89.167:53363] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "work.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K54EwADN08"]
[Sun Aug 30 03:11:53.946223 2026] [security2:error] [pid 521505:tid 521578] [remote 185.93.89.167:9557] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "s4.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K54FAADa0g"]
[Sun Aug 30 03:11:53.956124 2026] [security2:error] [pid 521505:tid 521550] [remote 185.93.89.167:54151] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "affiliate.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K54FgADJyw"]
[Sun Aug 30 03:11:53.956958 2026] [security2:error] [pid 521505:tid 521519] [remote 185.93.89.167:30871] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "pro.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlyW8byYE0iXl--K54FwADXg0"]
[Sun Aug 30 03:11:53.975586 2026] [security2:error] [pid 521505:tid 521587] [remote 185.93.89.167:42909] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "direct.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlyW8byYE0iXl--K54HQADf1E"]
[Sun Aug 30 03:11:53.977862 2026] [security2:error] [pid 521505:tid 521662] [client 216.73.216.128:13393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_config_quote_replace_string"] [unique_id "apPlyW8byYE0iXl--K54HwAAAzk"]
[Sun Aug 30 03:11:53.983276 2026] [security2:error] [pid 521505:tid 521588] [remote 185.93.89.167:37843] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "jupiter.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K54IwADP1I"]
[Sun Aug 30 03:11:53.983390 2026] [security2:error] [pid 521505:tid 521539] [remote 185.93.89.167:7437] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "images7.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlyW8byYE0iXl--K54IQADKyE"]
[Sun Aug 30 03:11:53.983782 2026] [security2:error] [pid 521505:tid 521518] [remote 185.93.89.167:59907] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "health.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlyW8byYE0iXl--K54IgADIAw"]
[Sun Aug 30 03:11:53.994040 2026] [security2:error] [pid 521505:tid 521526] [remote 185.93.89.167:63379] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "reviews.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlyW8byYE0iXl--K54JwADZBQ"]
[Sun Aug 30 03:11:53.996427 2026] [security2:error] [pid 521505:tid 521630] [remote 185.93.89.167:15177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlyW8byYE0iXl--K54KQADVXw"]
[Sun Aug 30 03:11:53.996859 2026] [security2:error] [pid 521505:tid 521560] [remote 185.93.89.167:34357] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banners.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlyW8byYE0iXl--K54KgADSjY"]
[Sun Aug 30 03:11:53.999211 2026] [security2:error] [pid 521505:tid 521572] [remote 185.93.89.167:1175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pgsql.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlyW8byYE0iXl--K54LAADhkI"]
[Sun Aug 30 03:11:53.999761 2026] [security2:error] [pid 521505:tid 521569] [remote 185.93.89.167:34607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sports.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlyW8byYE0iXl--K54LQADYz8"]
[Sun Aug 30 03:11:54.000455 2026] [authz_core:error] [pid 521505:tid 521669] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory20
[Sun Aug 30 03:11:54.000842 2026] [authz_core:error] [pid 521505:tid 521669] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory20
[Sun Aug 30 03:11:54.002978 2026] [security2:error] [pid 521505:tid 521595] [remote 185.93.89.167:11851] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "biblioteca.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlym8byYE0iXl--K54LgADe1k"]
[Sun Aug 30 03:11:54.011492 2026] [security2:error] [pid 521505:tid 521602] [remote 185.93.89.167:11225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "da.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlym8byYE0iXl--K54MgADHmA"]
[Sun Aug 30 03:11:54.014779 2026] [security2:error] [pid 521505:tid 521603] [remote 185.93.89.167:18729] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "ntp1.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K54MwADl2E"]
[Sun Aug 30 03:11:54.017382 2026] [security2:error] [pid 521505:tid 521610] [remote 185.93.89.167:16669] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "links.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlym8byYE0iXl--K54NAADNGg"]
[Sun Aug 30 03:11:54.018622 2026] [security2:error] [pid 521505:tid 521613] [remote 185.93.89.167:29329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mars.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlym8byYE0iXl--K54NwADOms"]
[Sun Aug 30 03:11:54.019076 2026] [security2:error] [pid 521505:tid 521619] [remote 185.93.89.167:9731] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images5.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlym8byYE0iXl--K54OAADQXE"]
[Sun Aug 30 03:11:54.020923 2026] [security2:error] [pid 521505:tid 521608] [remote 185.93.89.167:3495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail5.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlym8byYE0iXl--K54PAADIWY"]
[Sun Aug 30 03:11:54.021115 2026] [security2:error] [pid 521505:tid 521614] [remote 185.93.89.167:59097] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web6.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlym8byYE0iXl--K54PQADhGw"]
[Sun Aug 30 03:11:54.026221 2026] [security2:error] [pid 521505:tid 521552] [remote 185.93.89.167:41989] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "ipfixe.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K54PgADUS4"]
[Sun Aug 30 03:11:54.027767 2026] [security2:error] [pid 521505:tid 521510] [remote 185.93.89.167:1995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlym8byYE0iXl--K54QAADawQ"]
[Sun Aug 30 03:11:54.028230 2026] [security2:error] [pid 521505:tid 521508] [remote 185.93.89.167:10145] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "g.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K54QQADYgI"]
[Sun Aug 30 03:11:54.029274 2026] [security2:error] [pid 521505:tid 521633] [remote 185.93.89.167:32655] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lync.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlym8byYE0iXl--K54QwADN38"]
[Sun Aug 30 03:11:54.032508 2026] [security2:error] [pid 521505:tid 521516] [remote 185.93.89.167:50005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fax.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlym8byYE0iXl--K54RQADTQo"]
[Sun Aug 30 03:11:54.045219 2026] [security2:error] [pid 521505:tid 521759] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/mail/.env"] [unique_id "apPlym8byYE0iXl--K54TAAAA5o"]
[Sun Aug 30 03:11:54.050577 2026] [security2:error] [pid 521505:tid 521575] [remote 185.93.89.167:40249] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "tracking.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlym8byYE0iXl--K54TQADP0U"]
[Sun Aug 30 03:11:54.051716 2026] [security2:error] [pid 521505:tid 521556] [remote 185.93.89.167:27945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images6.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlym8byYE0iXl--K54TgADKzI"]
[Sun Aug 30 03:11:54.052187 2026] [security2:error] [pid 521505:tid 521524] [remote 185.93.89.167:57109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "development.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K54TwADIBI"]
[Sun Aug 30 03:11:54.053519 2026] [security2:error] [pid 521505:tid 521579] [remote 185.93.89.167:64329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digital.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlym8byYE0iXl--K54UgADZEk"]
[Sun Aug 30 03:11:54.054364 2026] [security2:error] [pid 521505:tid 521562] [remote 185.93.89.167:14453] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlym8byYE0iXl--K54UQADnDg"]
[Sun Aug 30 03:11:54.072834 2026] [security2:error] [pid 521505:tid 521506] [remote 185.93.89.167:49893] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mdm.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlym8byYE0iXl--K54WgADlAA"]
[Sun Aug 30 03:11:54.075448 2026] [security2:error] [pid 521505:tid 521548] [remote 185.93.89.167:60123] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "up.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlym8byYE0iXl--K54XAADHio"]
[Sun Aug 30 03:11:54.076434 2026] [security2:error] [pid 521505:tid 521512] [remote 185.93.89.167:63579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "wifi.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlym8byYE0iXl--K54XQADIgY"]
[Sun Aug 30 03:11:54.078704 2026] [security2:error] [pid 521505:tid 521565] [remote 185.93.89.167:53363] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "work.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlym8byYE0iXl--K54XgADlzs"]
[Sun Aug 30 03:11:54.079655 2026] [security2:error] [pid 521505:tid 521580] [remote 185.93.89.167:9557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "s4.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlym8byYE0iXl--K54XwADNEo"]
[Sun Aug 30 03:11:54.087358 2026] [security2:error] [pid 521505:tid 521592] [remote 185.93.89.167:37133] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlym8byYE0iXl--K54YAADOlY"]
[Sun Aug 30 03:11:54.089267 2026] [security2:error] [pid 521505:tid 521507] [remote 185.93.89.167:54151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "affiliate.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlym8byYE0iXl--K54YgADQQE"]
[Sun Aug 30 03:11:54.093523 2026] [security2:error] [pid 521505:tid 521532] [remote 185.93.89.167:26309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piwik.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlym8byYE0iXl--K54ZAADIRo"]
[Sun Aug 30 03:11:54.101529 2026] [security2:error] [pid 521505:tid 521737] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/postgres/.env"] [unique_id "apPlym8byYE0iXl--K54ZQAAA4Q"]
[Sun Aug 30 03:11:54.109876 2026] [security2:error] [pid 521505:tid 521538] [remote 185.93.89.167:64215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m1.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlym8byYE0iXl--K54ZwADKiA"]
[Sun Aug 30 03:11:54.129505 2026] [security2:error] [pid 521505:tid 521589] [remote 185.93.89.167:34357] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "banners.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlym8byYE0iXl--K54cgADdFM"]
[Sun Aug 30 03:11:54.131383 2026] [security2:error] [pid 521505:tid 521558] [remote 185.93.89.167:36485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shopping.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlym8byYE0iXl--K54cwADZzQ"]
[Sun Aug 30 03:11:54.133321 2026] [security2:error] [pid 521505:tid 521540] [remote 185.93.89.167:34607] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "sports.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K54dQADkCI"]
[Sun Aug 30 03:11:54.133323 2026] [security2:error] [pid 521505:tid 521566] [remote 185.93.89.167:1175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "pgsql.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K54dAADfzw"]
[Sun Aug 30 03:11:54.135432 2026] [security2:error] [pid 521505:tid 521527] [remote 185.93.89.167:15177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "forms.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlym8byYE0iXl--K54dgADmhU"]
[Sun Aug 30 03:11:54.136058 2026] [security2:error] [pid 521505:tid 521620] [remote 185.93.89.167:11851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biblioteca.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlym8byYE0iXl--K54dwADfnI"]
[Sun Aug 30 03:11:54.143194 2026] [security2:error] [pid 521505:tid 521582] [remote 185.93.89.167:8597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drupal.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K54eQADK0w"]
[Sun Aug 30 03:11:54.144574 2026] [security2:error] [pid 521505:tid 521574] [remote 185.93.89.167:11225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "da.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlym8byYE0iXl--K54egADIEQ"]
[Sun Aug 30 03:11:54.145034 2026] [security2:error] [pid 521505:tid 521525] [remote 185.93.89.167:28567] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "user.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlym8byYE0iXl--K54ewADZBM"]
[Sun Aug 30 03:11:54.150014 2026] [security2:error] [pid 521505:tid 521571] [remote 185.93.89.167:16669] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "links.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlym8byYE0iXl--K54fQADMEE"]
[Sun Aug 30 03:11:54.151969 2026] [security2:error] [pid 521505:tid 521585] [remote 185.93.89.167:9731] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "images5.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlym8byYE0iXl--K54gAADjU8"]
[Sun Aug 30 03:11:54.152218 2026] [security2:error] [pid 521505:tid 521554] [remote 185.93.89.167:29329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mars.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlym8byYE0iXl--K54fwADejA"]
[Sun Aug 30 03:11:54.154524 2026] [security2:error] [pid 521505:tid 521577] [remote 185.93.89.167:59097] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web6.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlym8byYE0iXl--K54ggADHkc"]
[Sun Aug 30 03:11:54.160426 2026] [security2:error] [pid 521505:tid 521587] [remote 185.93.89.167:3495] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlym8byYE0iXl--K54hwADcVE"]
[Sun Aug 30 03:11:54.161929 2026] [security2:error] [pid 521505:tid 521588] [remote 185.93.89.167:32655] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "lync.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlym8byYE0iXl--K54jAADIVI"]
[Sun Aug 30 03:11:54.162040 2026] [security2:error] [pid 521505:tid 521628] [remote 185.93.89.167:22281] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "labs.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlym8byYE0iXl--K54igADQXo"]
[Sun Aug 30 03:11:54.162157 2026] [security2:error] [pid 521505:tid 521536] [remote 185.93.89.167:1995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lp.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlym8byYE0iXl--K54iwADkh4"]
[Sun Aug 30 03:11:54.165280 2026] [security2:error] [pid 521505:tid 521518] [remote 185.93.89.167:50005] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "fax.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlym8byYE0iXl--K54jwADdQw"]
[Sun Aug 30 03:11:54.169594 2026] [authz_core:error] [pid 521505:tid 521737] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:54.169857 2026] [authz_core:error] [pid 521505:tid 521737] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:54.170009 2026] [security2:error] [pid 521505:tid 521630] [remote 185.93.89.167:4349] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mm.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlym8byYE0iXl--K54kgADa3w"]
[Sun Aug 30 03:11:54.185087 2026] [security2:error] [pid 521505:tid 521569] [remote 185.93.89.167:27945] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlym8byYE0iXl--K54lgADOD8"]
[Sun Aug 30 03:11:54.186125 2026] [security2:error] [pid 521505:tid 521595] [remote 185.93.89.167:57109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "development.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K54lwADTVk"]
[Sun Aug 30 03:11:54.186691 2026] [security2:error] [pid 521505:tid 521598] [remote 185.93.89.167:64329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlym8byYE0iXl--K54mAADdFw"]
[Sun Aug 30 03:11:54.187385 2026] [security2:error] [pid 521505:tid 521593] [remote 185.93.89.167:14453] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mobil.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlym8byYE0iXl--K54mQADLlc"]
[Sun Aug 30 03:11:54.196457 2026] [security2:error] [pid 521505:tid 521597] [remote 185.93.89.167:48785] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns02.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPlym8byYE0iXl--K54mwADf1s"]
[Sun Aug 30 03:11:54.204113 2026] [security2:error] [pid 521505:tid 521603] [remote 185.93.89.167:62859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailgw.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlym8byYE0iXl--K54nAADkGE"]
[Sun Aug 30 03:11:54.205456 2026] [security2:error] [pid 521505:tid 521610] [remote 185.93.89.167:49893] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mdm.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlym8byYE0iXl--K54nQADX2g"]
[Sun Aug 30 03:11:54.207296 2026] [security2:error] [pid 521505:tid 521759] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/email/.env"] [unique_id "apPlym8byYE0iXl--K54ngAAA5o"]
[Sun Aug 30 03:11:54.208442 2026] [security2:error] [pid 521505:tid 521551] [remote 185.93.89.167:60123] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "up.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlym8byYE0iXl--K54oAADjC0"]
[Sun Aug 30 03:11:54.209360 2026] [security2:error] [pid 521505:tid 521613] [remote 185.93.89.167:63579] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "wifi.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlym8byYE0iXl--K54oQADP2s"]
[Sun Aug 30 03:11:54.213236 2026] [security2:error] [pid 521505:tid 521608] [remote 185.93.89.167:9557] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "s4.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlym8byYE0iXl--K54pAADZGY"]
[Sun Aug 30 03:11:54.220475 2026] [security2:error] [pid 521505:tid 521614] [remote 185.93.89.167:37133] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlym8byYE0iXl--K54pQADnGw"]
[Sun Aug 30 03:11:54.222613 2026] [security2:error] [pid 521505:tid 521618] [remote 185.93.89.167:54151] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "affiliate.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlym8byYE0iXl--K54pgADMHA"]
[Sun Aug 30 03:11:54.225146 2026] [security2:error] [pid 521505:tid 521621] [remote 185.93.89.167:30871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pro.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlym8byYE0iXl--K54pwADjXM"]
[Sun Aug 30 03:11:54.245362 2026] [security2:error] [pid 521505:tid 521508] [remote 185.93.89.167:42909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direct.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlym8byYE0iXl--K54rAADTAI"]
[Sun Aug 30 03:11:54.250787 2026] [security2:error] [pid 521505:tid 521553] [remote 185.93.89.167:7437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images7.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlym8byYE0iXl--K54rwADNC8"]
[Sun Aug 30 03:11:54.251718 2026] [security2:error] [pid 521505:tid 521516] [remote 185.93.89.167:59907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "health.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlym8byYE0iXl--K54sQADIQo"]
[Sun Aug 30 03:11:54.251815 2026] [security2:error] [pid 521505:tid 521751] [client 216.73.216.128:40150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts2/tweakftp"] [unique_id "apPlym8byYE0iXl--K54swAAA5I"]
[Sun Aug 30 03:11:54.269278 2026] [security2:error] [pid 521505:tid 521524] [remote 185.93.89.167:11851] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "biblioteca.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlym8byYE0iXl--K54ugADaxI"]
[Sun Aug 30 03:11:54.275709 2026] [security2:error] [pid 521505:tid 521579] [remote 185.93.89.167:15177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlym8byYE0iXl--K54uwADJ0k"]
[Sun Aug 30 03:11:54.276630 2026] [security2:error] [pid 521505:tid 521514] [remote 185.93.89.167:8597] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "drupal.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K54vQADNwg"]
[Sun Aug 30 03:11:54.277789 2026] [security2:error] [pid 521505:tid 521632] [remote 185.93.89.167:11225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "da.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlym8byYE0iXl--K54vgADYn4"]
[Sun Aug 30 03:11:54.282486 2026] [security2:error] [pid 521505:tid 521564] [remote 185.93.89.167:18729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ntp1.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlym8byYE0iXl--K54wAADdDo"]
[Sun Aug 30 03:11:54.285033 2026] [security2:error] [pid 521505:tid 521542] [remote 185.93.89.167:29329] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mars.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlym8byYE0iXl--K54wwADfyQ"]
[Sun Aug 30 03:11:54.287628 2026] [security2:error] [pid 521505:tid 521565] [remote 185.93.89.167:59097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "web6.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlym8byYE0iXl--K54xQADXzs"]
[Sun Aug 30 03:11:54.288680 2026] [security2:error] [pid 521505:tid 521592] [remote 185.93.89.167:11075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redirect.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K54xwADjFY"]
[Sun Aug 30 03:11:54.289175 2026] [security2:error] [pid 521505:tid 521507] [remote 185.93.89.167:42991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "venus.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K54yAADPwE"]
[Sun Aug 30 03:11:54.293167 2026] [security2:error] [pid 521505:tid 521535] [remote 185.93.89.167:41989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ipfixe.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlym8byYE0iXl--K54yQADKx0"]
[Sun Aug 30 03:11:54.295155 2026] [security2:error] [pid 521505:tid 521544] [remote 185.93.89.167:10145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlym8byYE0iXl--K54zAADnCY"]
[Sun Aug 30 03:11:54.295913 2026] [security2:error] [pid 521505:tid 521590] [remote 185.93.89.167:1995] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "lp.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlym8byYE0iXl--K54zQADMFQ"]
[Sun Aug 30 03:11:54.299388 2026] [security2:error] [pid 521505:tid 521561] [remote 185.93.89.167:3495] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail5.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlym8byYE0iXl--K540AADRDc"]
[Sun Aug 30 03:11:54.300763 2026] [security2:error] [pid 521505:tid 521537] [remote 185.93.89.167:36741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "software.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K540gADTB8"]
[Sun Aug 30 03:11:54.301031 2026] [security2:error] [pid 521505:tid 521753] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/mongodb/.env"] [unique_id "apPlym8byYE0iXl--K540QAAA5Q"]
[Sun Aug 30 03:11:54.301782 2026] [security2:error] [pid 521505:tid 521629] [remote 185.93.89.167:55243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldmail.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K540wADl3s"]
[Sun Aug 30 03:11:54.309925 2026] [security2:error] [pid 521505:tid 521558] [remote 185.93.89.167:4349] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mm.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlym8byYE0iXl--K541gADezQ"]
[Sun Aug 30 03:11:54.318139 2026] [security2:error] [pid 521505:tid 521566] [remote 185.93.89.167:27945] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "images6.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlym8byYE0iXl--K542QADOjw"]
[Sun Aug 30 03:11:54.319215 2026] [security2:error] [pid 521505:tid 521620] [remote 185.93.89.167:64329] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "digital.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlym8byYE0iXl--K542wADKnI"]
[Sun Aug 30 03:11:54.330444 2026] [security2:error] [pid 521505:tid 521574] [remote 185.93.89.167:48785] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns02.mariegronley.com"] [uri "/core/.env"] [unique_id "apPlym8byYE0iXl--K543gADa0Q"]
[Sun Aug 30 03:11:54.346268 2026] [security2:error] [pid 521505:tid 521577] [remote 185.93.89.167:9557] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "s4.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlym8byYE0iXl--K545wADLkc"]
[Sun Aug 30 03:11:54.353589 2026] [security2:error] [pid 521505:tid 521550] [remote 185.93.89.167:37133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kb.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlym8byYE0iXl--K546QADZyw"]
[Sun Aug 30 03:11:54.355632 2026] [security2:error] [pid 521505:tid 521578] [remote 185.93.89.167:54151] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "affiliate.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlym8byYE0iXl--K546gADkEg"]
[Sun Aug 30 03:11:54.368103 2026] [security2:error] [pid 521505:tid 521761] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/smtp/.env"] [unique_id "apPlym8byYE0iXl--K547gAAA5w"]
[Sun Aug 30 03:11:54.388274 2026] [security2:error] [pid 521505:tid 521526] [remote 185.93.89.167:37521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K549gADTBQ"]
[Sun Aug 30 03:11:54.400407 2026] [security2:error] [pid 521505:tid 521572] [remote 185.93.89.167:34607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sports.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlym8byYE0iXl--K54-wADe0I"]
[Sun Aug 30 03:11:54.402151 2026] [security2:error] [pid 521505:tid 521569] [remote 185.93.89.167:11851] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "biblioteca.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlym8byYE0iXl--K54_AADIT8"]
[Sun Aug 30 03:11:54.402537 2026] [security2:error] [pid 521505:tid 521595] [remote 185.93.89.167:1175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pgsql.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlym8byYE0iXl--K54_QADOlk"]
[Sun Aug 30 03:11:54.410620 2026] [security2:error] [pid 521505:tid 521602] [remote 185.93.89.167:11225] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "da.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlym8byYE0iXl--K55AAADdWA"]
[Sun Aug 30 03:11:54.414542 2026] [security2:error] [pid 521505:tid 521603] [remote 185.93.89.167:15177] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "forms.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlym8byYE0iXl--K55AgADQGE"]
[Sun Aug 30 03:11:54.420971 2026] [security2:error] [pid 521505:tid 521612] [remote 185.93.89.167:59097] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web6.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlym8byYE0iXl--K55CgADLmo"]
[Sun Aug 30 03:11:54.422345 2026] [security2:error] [pid 521505:tid 521614] [remote 185.93.89.167:11075] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "redirect.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K55CwADdGw"]
[Sun Aug 30 03:11:54.422730 2026] [security2:error] [pid 521505:tid 521618] [remote 185.93.89.167:42991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "venus.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K55DAADZ3A"]
[Sun Aug 30 03:11:54.423401 2026] [security2:error] [pid 521505:tid 521621] [remote 185.93.89.167:3789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vc.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K55DQADkHM"]
[Sun Aug 30 03:11:54.433197 2026] [security2:error] [pid 521505:tid 521516] [remote 185.93.89.167:13143] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "net.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlym8byYE0iXl--K55FgADRAo"]
[Sun Aug 30 03:11:54.434226 2026] [security2:error] [pid 521505:tid 521584] [remote 185.93.89.167:36741] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "software.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K55FwADjU4"]
[Sun Aug 30 03:11:54.435512 2026] [security2:error] [pid 521505:tid 521546] [remote 185.93.89.167:55243] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "oldmail.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K55GQADHig"]
[Sun Aug 30 03:11:54.441284 2026] [security2:error] [pid 521505:tid 521549] [remote 185.93.89.167:45765] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns01.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlym8byYE0iXl--K55HAADlys"]
[Sun Aug 30 03:11:54.444184 2026] [security2:error] [pid 521505:tid 521515] [remote 185.93.89.167:14681] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mc.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlym8byYE0iXl--K55HgADewk"]
[Sun Aug 30 03:11:54.449179 2026] [security2:error] [pid 521505:tid 521556] [remote 185.93.89.167:4349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mm.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlym8byYE0iXl--K55HwADITI"]
[Sun Aug 30 03:11:54.454091 2026] [security2:error] [pid 521505:tid 521575] [remote 185.93.89.167:57109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "development.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlym8byYE0iXl--K55JAADT0U"]
[Sun Aug 30 03:11:54.457397 2026] [security2:error] [pid 521505:tid 521632] [remote 185.93.89.167:52789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "market.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlym8byYE0iXl--K55JgADa34"]
[Sun Aug 30 03:11:54.466095 2026] [authz_core:error] [pid 521505:tid 521686] [client 66.249.66.35:38069] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:54.466358 2026] [authz_core:error] [pid 521505:tid 521686] [client 66.249.66.35:38069] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:54.478637 2026] [security2:error] [pid 521505:tid 521512] [remote 185.93.89.167:53985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "img3.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K55LQADZwY"]
[Sun Aug 30 03:11:54.487028 2026] [security2:error] [pid 521505:tid 521507] [remote 185.93.89.167:37133] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlym8byYE0iXl--K55MAADjAE"]
[Sun Aug 30 03:11:54.494546 2026] [security2:error] [pid 521505:tid 521544] [remote 185.93.89.167:26309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piwik.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlym8byYE0iXl--K55MwADRCY"]
[Sun Aug 30 03:11:54.500551 2026] [security2:error] [pid 521505:tid 521746] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/redis/.env"] [unique_id "apPlym8byYE0iXl--K55NAAAA40"]
[Sun Aug 30 03:11:54.514785 2026] [security2:error] [pid 521505:tid 521590] [remote 185.93.89.167:64215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m1.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlym8byYE0iXl--K55NgADHlQ"]
[Sun Aug 30 03:11:54.515788 2026] [security2:error] [pid 521505:tid 521532] [remote 185.93.89.167:64795] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jp.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlym8byYE0iXl--K55OAADlxo"]
[Sun Aug 30 03:11:54.518199 2026] [security2:error] [pid 521505:tid 521561] [remote 185.93.89.167:10845] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "campus.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlym8byYE0iXl--K55OQADezc"]
[Sun Aug 30 03:11:54.519250 2026] [security2:error] [pid 521505:tid 521537] [remote 185.93.89.167:37843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jupiter.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K55PAADcR8"]
[Sun Aug 30 03:11:54.522414 2026] [security2:error] [pid 521505:tid 521629] [remote 185.93.89.167:37521] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "internal.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K55PQADdXs"]
[Sun Aug 30 03:11:54.528276 2026] [security2:error] [pid 521505:tid 521669] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/mailing/.env"] [unique_id "apPlym8byYE0iXl--K55QAAAA0A"]
[Sun Aug 30 03:11:54.530943 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:63379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviews.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K55QQADa00"]
[Sun Aug 30 03:11:54.531956 2026] [security2:error] [pid 521505:tid 521589] [remote 185.93.89.167:36485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shopping.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlym8byYE0iXl--K55QwADLlM"]
[Sun Aug 30 03:11:54.543943 2026] [security2:error] [pid 521505:tid 521509] [remote 185.93.89.167:8597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drupal.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlym8byYE0iXl--K55SgADjAM"]
[Sun Aug 30 03:11:54.545010 2026] [security2:error] [pid 521505:tid 521582] [remote 185.93.89.167:15109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "linux.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlym8byYE0iXl--K55SwADMEw"]
[Sun Aug 30 03:11:54.546323 2026] [authz_core:error] [pid 521505:tid 521749] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory28
[Sun Aug 30 03:11:54.546567 2026] [authz_core:error] [pid 521505:tid 521749] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory28
[Sun Aug 30 03:11:54.547466 2026] [http2:info] [pid 524122:tid 524122] h2_workers: created with min=128 max=192 idle_ms=600000
[Sun Aug 30 03:11:54.553966 2026] [security2:error] [pid 521505:tid 521554] [remote 185.93.89.167:59097] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "web6.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlym8byYE0iXl--K55UQADlzA"]
[Sun Aug 30 03:11:54.554457 2026] [security2:error] [pid 521505:tid 521577] [remote 185.93.89.167:37291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "st.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlym8byYE0iXl--K55UgADTEc"]
[Sun Aug 30 03:11:54.557204 2026] [security2:error] [pid 521505:tid 521519] [remote 185.93.89.167:3789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "vc.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K55VgADOg0"]
[Sun Aug 30 03:11:54.569939 2026] [security2:error] [pid 524122:tid 524256] [client 20.151.200.44:46050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/file66.php"] [unique_id "apPlyn3lhEjKFiK_nBJ5wgAAAZI"]
[Sun Aug 30 03:11:54.569965 2026] [security2:error] [pid 524122:tid 524273] [client 20.48.251.3:52285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/mamzi.php"] [unique_id "apPlyn3lhEjKFiK_nBJ5ygAAAaM"]
[Sun Aug 30 03:11:54.570030 2026] [security2:error] [pid 524122:tid 524271] [client 20.104.50.220:16753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/ccou.php"] [unique_id "apPlyn3lhEjKFiK_nBJ5yAAAAaE"]
[Sun Aug 30 03:11:54.570074 2026] [security2:error] [pid 524122:tid 524279] [client 20.104.50.220:61982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/inde.php"] [unique_id "apPlyn3lhEjKFiK_nBJ5ywAAAak"]
[Sun Aug 30 03:11:54.570118 2026] [security2:error] [pid 524122:tid 524259] [client 20.104.49.130:53735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/dk.php"] [unique_id "apPlyn3lhEjKFiK_nBJ5xQAAAZU"]
[Sun Aug 30 03:11:54.570175 2026] [security2:error] [pid 524122:tid 524270] [client 20.104.49.130:53600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/classwithtostring.php"] [unique_id "apPlyn3lhEjKFiK_nBJ5xwAAAaA"]
[Sun Aug 30 03:11:54.570180 2026] [security2:error] [pid 524122:tid 524269] [client 20.104.18.15:16922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/v22.php"] [unique_id "apPlyn3lhEjKFiK_nBJ5xgAAAZ8"]
[Sun Aug 30 03:11:54.570219 2026] [security2:error] [pid 524122:tid 524255] [client 20.48.160.90:61502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPlyn3lhEjKFiK_nBJ5wAAAAZE"]
[Sun Aug 30 03:11:54.570280 2026] [security2:error] [pid 524122:tid 524253] [client 20.104.18.15:51170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/ajax.php"] [unique_id "apPlyn3lhEjKFiK_nBJ5wQAAAY8"]
[Sun Aug 30 03:11:54.570341 2026] [security2:error] [pid 524122:tid 524257] [client 20.104.18.15:22446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/revo.php"] [unique_id "apPlyn3lhEjKFiK_nBJ5xAAAAZM"]
[Sun Aug 30 03:11:54.570365 2026] [security2:error] [pid 524122:tid 524280] [client 20.104.50.220:62818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/dl.php"] [unique_id "apPlyn3lhEjKFiK_nBJ5zQAAAao"]
[Sun Aug 30 03:11:54.570461 2026] [security2:error] [pid 524122:tid 524258] [client 20.104.49.130:64745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/forum.php"] [unique_id "apPlyn3lhEjKFiK_nBJ5wwAAAZQ"]
[Sun Aug 30 03:11:54.571004 2026] [security2:error] [pid 524122:tid 524281] [client 20.104.18.15:1987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/av.php"] [unique_id "apPlyn3lhEjKFiK_nBJ5zgAAAas"]
[Sun Aug 30 03:11:54.572123 2026] [security2:error] [pid 524122:tid 524285] [client 20.104.50.220:32908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/index9.php"] [unique_id "apPlyn3lhEjKFiK_nBJ50AAAAa8"]
[Sun Aug 30 03:11:54.573291 2026] [security2:error] [pid 524122:tid 524290] [client 68.155.159.216:54286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apPlyn3lhEjKFiK_nBJ50QAAAbQ"]
[Sun Aug 30 03:11:54.573928 2026] [security2:error] [pid 524122:tid 524293] [client 4.205.62.107:52851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/ms-edit.php"] [unique_id "apPlyn3lhEjKFiK_nBJ51AAAAbc"]
[Sun Aug 30 03:11:54.574249 2026] [security2:error] [pid 524122:tid 524296] [client 20.48.251.3:54754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/png.php"] [unique_id "apPlyn3lhEjKFiK_nBJ51QAAAbo"]
[Sun Aug 30 03:11:54.574631 2026] [security2:error] [pid 524122:tid 524299] [client 4.205.62.107:17720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/mamzi.php"] [unique_id "apPlyn3lhEjKFiK_nBJ52AAAAb0"]
[Sun Aug 30 03:11:54.574968 2026] [security2:error] [pid 524122:tid 524302] [client 20.104.50.220:24925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/aaf.php"] [unique_id "apPlyn3lhEjKFiK_nBJ53AAAAcA"]
[Sun Aug 30 03:11:54.579942 2026] [security2:error] [pid 524122:tid 524286] [client 158.23.147.79:21445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apPlyn3lhEjKFiK_nBJ56AAAAbA"]
[Sun Aug 30 03:11:54.582672 2026] [authz_core:error] [pid 524122:tid 524254] [client 66.249.66.38:34780] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:54.583155 2026] [authz_core:error] [pid 524122:tid 524254] [client 66.249.66.38:34780] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:54.588100 2026] [security2:error] [pid 524122:tid 524349] [client 4.205.62.107:27000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/adminfus.php"] [unique_id "apPlyn3lhEjKFiK_nBJ6BwAAAe8"]
[Sun Aug 30 03:11:54.588252 2026] [security2:error] [pid 521505:tid 521595] [remote 185.93.89.167:40249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracking.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K55aQADjVk"]
[Sun Aug 30 03:11:54.589328 2026] [security2:error] [pid 521505:tid 521598] [remote 185.93.89.167:4349] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mm.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlym8byYE0iXl--K55awADjVw"]
[Sun Aug 30 03:11:54.606747 2026] [security2:error] [pid 521505:tid 521610] [remote 185.93.89.167:62859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailgw.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlym8byYE0iXl--K55bwADdWg"]
[Sun Aug 30 03:11:54.614572 2026] [security2:error] [pid 521505:tid 521613] [remote 185.93.89.167:53363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "work.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K55dgADdGs"]
[Sun Aug 30 03:11:54.614654 2026] [security2:error] [pid 524122:tid 524356] [client 20.48.251.3:52755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/wp-info.php"] [unique_id "apPlyn3lhEjKFiK_nBJ6JgAAAfY"]
[Sun Aug 30 03:11:54.615368 2026] [security2:error] [pid 521505:tid 521608] [remote 185.93.89.167:53985] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "img3.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K55dAADhGY"]
[Sun Aug 30 03:11:54.616237 2026] [security2:error] [pid 524122:tid 524261] [client 158.23.184.117:20176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/core.php"] [unique_id "apPlyn3lhEjKFiK_nBJ6LwAAAZc"]
[Sun Aug 30 03:11:54.619728 2026] [security2:error] [pid 521505:tid 521618] [remote 185.93.89.167:37133] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "kb.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlym8byYE0iXl--K55eQADj3A"]
[Sun Aug 30 03:11:54.624493 2026] [authz_core:error] [pid 521505:tid 521653] [client 216.73.216.128:37868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:54.624967 2026] [authz_core:error] [pid 521505:tid 521653] [client 216.73.216.128:37868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:54.626000 2026] [authz_core:error] [pid 524122:tid 524274] [client 66.249.66.69:64246] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:54.626325 2026] [authz_core:error] [pid 524122:tid 524274] [client 66.249.66.69:64246] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:54.627772 2026] [security2:error] [pid 521505:tid 521552] [remote 185.93.89.167:26309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piwik.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlym8byYE0iXl--K55fAADUC4"]
[Sun Aug 30 03:11:54.628291 2026] [security2:error] [pid 521505:tid 521552] [remote 185.93.89.167:30871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pro.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlym8byYE0iXl--K55fQADli4"]
[Sun Aug 30 03:11:54.635514 2026] [core:alert] [pid 524122:tid 524320] [client 31.215.116.188:57448] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:11:54.648462 2026] [security2:error] [pid 521505:tid 521508] [remote 185.93.89.167:64215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m1.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlym8byYE0iXl--K55fwADlwI"]
[Sun Aug 30 03:11:54.649632 2026] [security2:error] [pid 521505:tid 521633] [remote 185.93.89.167:42909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direct.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlym8byYE0iXl--K55gQADJn8"]
[Sun Aug 30 03:11:54.652865 2026] [security2:error] [pid 521505:tid 521553] [remote 185.93.89.167:7437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images7.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlym8byYE0iXl--K55hQADTC8"]
[Sun Aug 30 03:11:54.653272 2026] [security2:error] [pid 521505:tid 521584] [remote 185.93.89.167:37843] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "jupiter.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K55hAADjU4"]
[Sun Aug 30 03:11:54.654246 2026] [security2:error] [pid 521505:tid 521546] [remote 185.93.89.167:59907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "health.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlym8byYE0iXl--K55hgADgCg"]
[Sun Aug 30 03:11:54.656908 2026] [authz_core:error] [pid 521505:tid 521663] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:54.657157 2026] [authz_core:error] [pid 521505:tid 521663] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:11:54.664620 2026] [security2:error] [pid 521505:tid 521549] [remote 185.93.89.167:63379] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "reviews.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K55jAADRis"]
[Sun Aug 30 03:11:54.664879 2026] [security2:error] [pid 521505:tid 521515] [remote 185.93.89.167:36485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shopping.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlym8byYE0iXl--K55jQADdQk"]
[Sun Aug 30 03:11:54.665405 2026] [security2:error] [pid 521505:tid 521556] [remote 185.93.89.167:34357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "banners.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K55jgADQDI"]
[Sun Aug 30 03:11:54.684141 2026] [security2:error] [pid 524122:tid 524344] [client 20.104.18.15:31715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-content/l.php"] [unique_id "apPlyn3lhEjKFiK_nBJ6SwAAAeo"]
[Sun Aug 30 03:11:54.684215 2026] [security2:error] [pid 521505:tid 521564] [remote 185.93.89.167:18729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ntp1.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlym8byYE0iXl--K55nwADjzo"]
[Sun Aug 30 03:11:54.685211 2026] [security2:error] [pid 521505:tid 521506] [remote 185.93.89.167:16669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "links.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K55oAADOwA"]
[Sun Aug 30 03:11:54.685315 2026] [security2:error] [pid 524122:tid 524332] [client 20.104.50.220:59343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/waf.php"] [unique_id "apPlyn3lhEjKFiK_nBJ6TQAAAd4"]
[Sun Aug 30 03:11:54.689007 2026] [security2:error] [pid 521505:tid 521507] [remote 185.93.89.167:9731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images5.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K55qAADkgE"]
[Sun Aug 30 03:11:54.689043 2026] [security2:error] [pid 521505:tid 521565] [remote 185.93.89.167:24307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tw.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K55pgADnDs"]
[Sun Aug 30 03:11:54.689589 2026] [security2:error] [pid 521505:tid 521592] [remote 185.93.89.167:6761] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banner.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlym8byYE0iXl--K55pwADQVY"]
[Sun Aug 30 03:11:54.690584 2026] [security2:error] [pid 521505:tid 521544] [remote 185.93.89.167:11075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redirect.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlym8byYE0iXl--K55qgADcyY"]
[Sun Aug 30 03:11:54.690633 2026] [security2:error] [pid 521505:tid 521535] [remote 185.93.89.167:42991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "venus.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlym8byYE0iXl--K55rAADVx0"]
[Sun Aug 30 03:11:54.693863 2026] [security2:error] [pid 521505:tid 521590] [remote 185.93.89.167:41989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ipfixe.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlym8byYE0iXl--K55rgADJ1Q"]
[Sun Aug 30 03:11:54.696086 2026] [security2:error] [pid 521505:tid 521538] [remote 185.93.89.167:10145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlym8byYE0iXl--K55sAADjCA"]
[Sun Aug 30 03:11:54.697092 2026] [security2:error] [pid 521505:tid 521561] [remote 185.93.89.167:32655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lync.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K55sgADUDc"]
[Sun Aug 30 03:11:54.697422 2026] [security2:error] [pid 521505:tid 521731] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/notifications/.env"] [unique_id "apPlym8byYE0iXl--K55sQAAA34"]
[Sun Aug 30 03:11:54.700061 2026] [security2:error] [pid 521505:tid 521679] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/elasticsearch/.env"] [unique_id "apPlym8byYE0iXl--K55tAAAA0o"]
[Sun Aug 30 03:11:54.701154 2026] [security2:error] [pid 521505:tid 521534] [remote 185.93.89.167:13143] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "net.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlym8byYE0iXl--K55tQADIBw"]
[Sun Aug 30 03:11:54.701571 2026] [security2:error] [pid 521505:tid 521629] [remote 185.93.89.167:36741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "software.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlym8byYE0iXl--K55twADS3s"]
[Sun Aug 30 03:11:54.702006 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:50005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fax.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K55uAADQk0"]
[Sun Aug 30 03:11:54.704937 2026] [security2:error] [pid 521505:tid 521589] [remote 185.93.89.167:55243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldmail.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlym8byYE0iXl--K55uwADK1M"]
[Sun Aug 30 03:11:54.707733 2026] [security2:error] [pid 521505:tid 521643] [client 20.48.160.90:37715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPlym8byYE0iXl--K55vgAAAyY"]
[Sun Aug 30 03:11:54.709421 2026] [security2:error] [pid 521505:tid 521558] [remote 185.93.89.167:45765] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns01.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlym8byYE0iXl--K55vwADjTQ"]
[Sun Aug 30 03:11:54.711929 2026] [security2:error] [pid 521505:tid 521566] [remote 185.93.89.167:14681] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mc.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlym8byYE0iXl--K55wQADVjw"]
[Sun Aug 30 03:11:54.718101 2026] [security2:error] [pid 521505:tid 521696] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "board.mariegronley.com"] [uri "/index.cgi"] [unique_id "apPlyW8byYE0iXl--K53UwADW0A"]
[Sun Aug 30 03:11:54.722308 2026] [security2:error] [pid 521505:tid 521587] [remote 185.93.89.167:40249] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "tracking.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K55xwADb1E"]
[Sun Aug 30 03:11:54.724115 2026] [security2:error] [pid 521505:tid 521527] [remote 185.93.89.167:14453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mobil.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K55ygADhBU"]
[Sun Aug 30 03:11:54.725908 2026] [security2:error] [pid 521505:tid 521574] [remote 185.93.89.167:52789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "market.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlym8byYE0iXl--K55zAADOUQ"]
[Sun Aug 30 03:11:54.728508 2026] [security2:error] [pid 521505:tid 521511] [remote 185.93.89.167:4349] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mm.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlym8byYE0iXl--K55zQADjwU"]
[Sun Aug 30 03:11:54.732066 2026] [security2:error] [pid 521505:tid 521554] [remote 185.93.89.167:48785] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns02.mariegronley.com"] [uri "/app/.env"] [unique_id "apPlym8byYE0iXl--K550AADODA"]
[Sun Aug 30 03:11:54.739552 2026] [security2:error] [pid 521505:tid 521571] [remote 185.93.89.167:62859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailgw.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlym8byYE0iXl--K551AADHkE"]
[Sun Aug 30 03:11:54.743017 2026] [security2:error] [pid 521505:tid 521577] [remote 185.93.89.167:49893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdm.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K552AADk0c"]
[Sun Aug 30 03:11:54.745829 2026] [security2:error] [pid 524122:tid 524267] [client 20.104.49.130:52102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/txets.php"] [unique_id "apPlyn3lhEjKFiK_nBJ6UgAAAZ0"]
[Sun Aug 30 03:11:54.747111 2026] [security2:error] [pid 521505:tid 521585] [remote 185.93.89.167:60123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "up.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K552gADXk8"]
[Sun Aug 30 03:11:54.750391 2026] [security2:error] [pid 521505:tid 521519] [remote 185.93.89.167:63579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wifi.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K553wADhg0"]
[Sun Aug 30 03:11:54.752051 2026] [security2:error] [pid 521505:tid 521528] [remote 185.93.89.167:53363] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "work.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K553AADjhY"]
[Sun Aug 30 03:11:54.758904 2026] [security2:error] [pid 521505:tid 521742] [client 158.23.184.117:19617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/data.php"] [unique_id "apPlym8byYE0iXl--K555AAAA4k"]
[Sun Aug 30 03:11:54.761386 2026] [security2:error] [pid 521505:tid 521628] [remote 185.93.89.167:30871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pro.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlym8byYE0iXl--K555wADlno"]
[Sun Aug 30 03:11:54.775389 2026] [security2:error] [pid 521505:tid 521680] [client 4.205.62.107:15968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/application.config.php"] [unique_id "apPlym8byYE0iXl--K556QAAA0s"]
[Sun Aug 30 03:11:54.778753 2026] [security2:error] [pid 521505:tid 521695] [client 20.104.50.220:5515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/alfa.php"] [unique_id "apPlym8byYE0iXl--K556wAAA1o"]
[Sun Aug 30 03:11:54.782985 2026] [security2:error] [pid 521505:tid 521522] [remote 185.93.89.167:42909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direct.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlym8byYE0iXl--K557wADZxA"]
[Sun Aug 30 03:11:54.785692 2026] [security2:error] [pid 521505:tid 521518] [remote 185.93.89.167:64795] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jp.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlym8byYE0iXl--K558AADNww"]
[Sun Aug 30 03:11:54.785872 2026] [security2:error] [pid 521505:tid 521539] [remote 185.93.89.167:7437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images7.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlym8byYE0iXl--K558wADjSE"]
[Sun Aug 30 03:11:54.787340 2026] [security2:error] [pid 521505:tid 521526] [remote 185.93.89.167:59907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "health.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlym8byYE0iXl--K559QADkBQ"]
[Sun Aug 30 03:11:54.788317 2026] [security2:error] [pid 521505:tid 521630] [remote 185.93.89.167:10845] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "campus.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlym8byYE0iXl--K559gADVXw"]
[Sun Aug 30 03:11:54.791095 2026] [security2:error] [pid 521505:tid 521560] [remote 185.93.89.167:37521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlym8byYE0iXl--K559wADcjY"]
[Sun Aug 30 03:11:54.799023 2026] [security2:error] [pid 521505:tid 521595] [remote 185.93.89.167:34357] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "banners.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K55-gADYlk"]
[Sun Aug 30 03:11:54.803412 2026] [security2:error] [pid 521505:tid 521599] [remote 185.93.89.167:34607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sports.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlym8byYE0iXl--K55_gADO10"]
[Sun Aug 30 03:11:54.805622 2026] [security2:error] [pid 521505:tid 521593] [remote 185.93.89.167:1175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pgsql.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlym8byYE0iXl--K56AAADIlc"]
[Sun Aug 30 03:11:54.813149 2026] [security2:error] [pid 521505:tid 521603] [remote 185.93.89.167:15109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "linux.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlym8byYE0iXl--K56BQADL2E"]
[Sun Aug 30 03:11:54.816718 2026] [security2:error] [pid 521505:tid 521551] [remote 185.93.89.167:28567] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "user.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlym8byYE0iXl--K56BwADZS0"]
[Sun Aug 30 03:11:54.817517 2026] [security2:error] [pid 521505:tid 521614] [remote 185.93.89.167:18729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ntp1.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlym8byYE0iXl--K56CQADk2w"]
[Sun Aug 30 03:11:54.818766 2026] [security2:error] [pid 521505:tid 521608] [remote 185.93.89.167:16669] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "links.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K56CwADV2Y"]
[Sun Aug 30 03:11:54.819087 2026] [security2:error] [pid 524122:tid 524264] [client 20.197.61.180:3204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/upgrade-temp-backup/themes/wp-settings.php"] [unique_id "apPlyn3lhEjKFiK_nBJ6VwAAAZo"]
[Sun Aug 30 03:11:54.822031 2026] [security2:error] [pid 521505:tid 521612] [remote 185.93.89.167:29329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mars.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K56DQADTmo"]
[Sun Aug 30 03:11:54.822617 2026] [security2:error] [pid 521505:tid 521619] [remote 185.93.89.167:24307] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "tw.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K56DwADTXE"]
[Sun Aug 30 03:11:54.822904 2026] [security2:error] [pid 521505:tid 521612] [remote 185.93.89.167:37291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "st.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlym8byYE0iXl--K56EQADX2o"]
[Sun Aug 30 03:11:54.823136 2026] [security2:error] [pid 521505:tid 521552] [remote 185.93.89.167:6761] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banner.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlym8byYE0iXl--K56EgADji4"]
[Sun Aug 30 03:11:54.823249 2026] [security2:error] [pid 521505:tid 521618] [remote 185.93.89.167:9731] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "images5.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K56EAADSHA"]
[Sun Aug 30 03:11:54.825341 2026] [security2:error] [pid 521505:tid 521633] [remote 185.93.89.167:3789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vc.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlym8byYE0iXl--K56FgADmn8"]
[Sun Aug 30 03:11:54.826562 2026] [security2:error] [pid 521505:tid 521543] [remote 185.93.89.167:41989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ipfixe.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlym8byYE0iXl--K56GAADiSU"]
[Sun Aug 30 03:11:54.827818 2026] [security2:error] [pid 521505:tid 521755] [client 20.48.251.3:37039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/ah25.php"] [unique_id "apPlym8byYE0iXl--K56GQAAA5Y"]
[Sun Aug 30 03:11:54.828994 2026] [security2:error] [pid 521505:tid 521553] [remote 185.93.89.167:10145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlym8byYE0iXl--K56HAADSi8"]
[Sun Aug 30 03:11:54.831133 2026] [security2:error] [pid 521505:tid 521584] [remote 185.93.89.167:32655] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "lync.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K56HgADT04"]
[Sun Aug 30 03:11:54.833259 2026] [security2:error] [pid 521505:tid 521546] [remote 185.93.89.167:22281] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "labs.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlym8byYE0iXl--K56IAADWig"]
[Sun Aug 30 03:11:54.833773 2026] [security2:error] [pid 524122:tid 524256] [client 20.104.49.130:52457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/ortasekerli1.php"] [unique_id "apPlyn3lhEjKFiK_nBJ6XQAAAZI"]
[Sun Aug 30 03:11:54.834724 2026] [security2:error] [pid 521505:tid 521516] [remote 185.93.89.167:13143] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "net.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlym8byYE0iXl--K56IQADjAo"]
[Sun Aug 30 03:11:54.835654 2026] [security2:error] [pid 521505:tid 521515] [remote 185.93.89.167:50005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "fax.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K56JAADRAk"]
[Sun Aug 30 03:11:54.836527 2026] [security2:error] [pid 521505:tid 521556] [remote 185.93.89.167:1995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K56JQADZDI"]
[Sun Aug 30 03:11:54.842071 2026] [security2:error] [pid 521505:tid 521738] [client 20.48.160.90:61495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/about.php"] [unique_id "apPlym8byYE0iXl--K56LAAAA4U"]
[Sun Aug 30 03:11:54.843032 2026] [security2:error] [pid 521505:tid 521579] [remote 185.93.89.167:45765] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns01.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlym8byYE0iXl--K56LQADN0k"]
[Sun Aug 30 03:11:54.845075 2026] [security2:error] [pid 521505:tid 521575] [remote 185.93.89.167:14681] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mc.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlym8byYE0iXl--K56LwADm0U"]
[Sun Aug 30 03:11:54.852380 2026] [security2:error] [pid 521505:tid 521667] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "board.mariegronley.com"] [uri "/index.cgi"] [unique_id "apPlym8byYE0iXl--K56MgADPjg"]
[Sun Aug 30 03:11:54.854900 2026] [security2:error] [pid 521505:tid 521632] [remote 185.93.89.167:27945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images6.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K56NgADhH4"]
[Sun Aug 30 03:11:54.855578 2026] [security2:error] [pid 521505:tid 521564] [remote 185.93.89.167:64329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digital.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K56OAADjzo"]
[Sun Aug 30 03:11:54.857869 2026] [security2:error] [pid 521505:tid 521651] [client 94.154.43.180:23528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-70e757b5.rkk.nsk.temporary.site"] [uri "/.env"] [unique_id "apPlym8byYE0iXl--K56OQAAAy4"]
[Sun Aug 30 03:11:54.858161 2026] [security2:error] [pid 521505:tid 521506] [remote 185.93.89.167:14453] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K56OwADJgA"]
[Sun Aug 30 03:11:54.858364 2026] [security2:error] [pid 521505:tid 521542] [remote 185.93.89.167:57109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "development.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlym8byYE0iXl--K56PAADmSQ"]
[Sun Aug 30 03:11:54.859066 2026] [security2:error] [pid 521505:tid 521548] [remote 185.93.89.167:52789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "market.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlym8byYE0iXl--K56PQADOSo"]
[Sun Aug 30 03:11:54.859120 2026] [security2:error] [pid 521505:tid 521722] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/notify/.env"] [unique_id "apPlym8byYE0iXl--K56PgAAA3U"]
[Sun Aug 30 03:11:54.861139 2026] [security2:error] [pid 521505:tid 521507] [remote 185.93.89.167:3495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail5.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K56PwADOAE"]
[Sun Aug 30 03:11:54.865294 2026] [security2:error] [pid 521505:tid 521565] [remote 185.93.89.167:48785] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns02.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPlym8byYE0iXl--K56QAADIjs"]
[Sun Aug 30 03:11:54.876850 2026] [security2:error] [pid 521505:tid 521544] [remote 185.93.89.167:49893] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mdm.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K56RQADLyY"]
[Sun Aug 30 03:11:54.881156 2026] [security2:error] [pid 521505:tid 521535] [remote 185.93.89.167:60123] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "up.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K56SAADUR0"]
[Sun Aug 30 03:11:54.881514 2026] [security2:error] [pid 521505:tid 521580] [remote 185.93.89.167:11687] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pr.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlym8byYE0iXl--K56SQADZUo"]
[Sun Aug 30 03:11:54.884428 2026] [security2:error] [pid 521505:tid 521590] [remote 185.93.89.167:63579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "wifi.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K56SwADk1Q"]
[Sun Aug 30 03:11:54.885767 2026] [security2:error] [pid 521505:tid 521561] [remote 185.93.89.167:53985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "img3.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlym8byYE0iXl--K56TwADMjc"]
[Sun Aug 30 03:11:54.885822 2026] [security2:error] [pid 521505:tid 521538] [remote 185.93.89.167:9557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "s4.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K56TgADgSA"]
[Sun Aug 30 03:11:54.895047 2026] [security2:error] [pid 521505:tid 521629] [remote 185.93.89.167:54151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "affiliate.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K56WAADd3s"]
[Sun Aug 30 03:11:54.897789 2026] [authz_core:error] [pid 521505:tid 521712] [client 66.249.66.32:46138] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:54.898242 2026] [authz_core:error] [pid 521505:tid 521712] [client 66.249.66.32:46138] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:54.898522 2026] [security2:error] [pid 524122:tid 524292] [client 20.104.50.220:63500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/index7.php"] [unique_id "apPlyn3lhEjKFiK_nBJ6YAAAAbY"]
[Sun Aug 30 03:11:54.899856 2026] [security2:error] [pid 521505:tid 521742] [client 34.15.159.88:53774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/rabbitmq/.env"] [unique_id "apPlym8byYE0iXl--K56XAAAA4k"]
[Sun Aug 30 03:11:54.901617 2026] [security2:error] [pid 521505:tid 521721] [client 158.23.184.117:20212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/database.php"] [unique_id "apPlym8byYE0iXl--K56XgAAA3Q"]
[Sun Aug 30 03:11:54.920579 2026] [security2:error] [pid 521505:tid 521587] [remote 185.93.89.167:64795] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jp.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlym8byYE0iXl--K56aQADcFE"]
[Sun Aug 30 03:11:54.921144 2026] [security2:error] [pid 521505:tid 521574] [remote 185.93.89.167:37843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jupiter.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlym8byYE0iXl--K56bgADNkQ"]
[Sun Aug 30 03:11:54.921993 2026] [security2:error] [pid 521505:tid 521511] [remote 185.93.89.167:10845] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "campus.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlym8byYE0iXl--K56bwADhQU"]
[Sun Aug 30 03:11:54.922606 2026] [security2:error] [pid 521505:tid 521554] [remote 185.93.89.167:14833] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "se.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlym8byYE0iXl--K56cAADjTA"]
[Sun Aug 30 03:11:54.932902 2026] [security2:error] [pid 521505:tid 521528] [remote 185.93.89.167:63379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviews.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlym8byYE0iXl--K56dwADmBY"]
[Sun Aug 30 03:11:54.936469 2026] [security2:error] [pid 521505:tid 521550] [remote 185.93.89.167:34607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sports.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlym8byYE0iXl--K56ewADkiw"]
[Sun Aug 30 03:11:54.938594 2026] [security2:error] [pid 521505:tid 521628] [remote 185.93.89.167:1175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pgsql.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlym8byYE0iXl--K56fQADNXo"]
[Sun Aug 30 03:11:54.940557 2026] [security2:error] [pid 521505:tid 521617] [remote 185.93.89.167:11851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biblioteca.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K56gAADh28"]
[Sun Aug 30 03:11:54.946880 2026] [security2:error] [pid 521505:tid 521591] [remote 185.93.89.167:8597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drupal.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlym8byYE0iXl--K56hAADj1U"]
[Sun Aug 30 03:11:54.947328 2026] [security2:error] [pid 521505:tid 521596] [remote 185.93.89.167:15109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "linux.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlym8byYE0iXl--K56gwADhFo"]
[Sun Aug 30 03:11:54.947555 2026] [security2:error] [pid 521505:tid 521557] [remote 185.93.89.167:11225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "da.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K56hgADQzM"]
[Sun Aug 30 03:11:54.950140 2026] [security2:error] [pid 521505:tid 521539] [remote 185.93.89.167:61033] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlym8byYE0iXl--K56hwADbiE"]
[Sun Aug 30 03:11:54.950622 2026] [security2:error] [pid 521505:tid 521651] [client 20.104.49.130:53735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/kj.php"] [unique_id "apPlym8byYE0iXl--K56igAAAy4"]
[Sun Aug 30 03:11:54.955241 2026] [security2:error] [pid 521505:tid 521630] [remote 185.93.89.167:53553] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "demo2.mariegronley.com"] [uri "/server/.env"] [unique_id "apPlym8byYE0iXl--K56jQADOXw"]
[Sun Aug 30 03:11:54.955355 2026] [security2:error] [pid 521505:tid 521758] [client 158.23.147.79:39977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-content/cong.php"] [unique_id "apPlym8byYE0iXl--K56kAAAA5k"]
[Sun Aug 30 03:11:54.955901 2026] [security2:error] [pid 521505:tid 521563] [remote 185.93.89.167:29329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mars.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K56jwADODk"]
[Sun Aug 30 03:11:54.956095 2026] [security2:error] [pid 521505:tid 521576] [remote 185.93.89.167:6761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "banner.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlym8byYE0iXl--K56lAADRkY"]
[Sun Aug 30 03:11:54.956303 2026] [security2:error] [pid 521505:tid 521595] [remote 185.93.89.167:37291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "st.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlym8byYE0iXl--K56kwADJlk"]
[Sun Aug 30 03:11:54.958055 2026] [security2:error] [pid 521505:tid 521598] [remote 185.93.89.167:56429] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mb.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlym8byYE0iXl--K56lwADgFw"]
[Sun Aug 30 03:11:54.958143 2026] [security2:error] [pid 521505:tid 521599] [remote 185.93.89.167:23169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlym8byYE0iXl--K56mAADMF0"]
[Sun Aug 30 03:11:54.964142 2026] [security2:error] [pid 524122:tid 524271] [client 20.104.18.15:18309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/132.php"] [unique_id "apPlyn3lhEjKFiK_nBJ6ZAAAAaE"]
[Sun Aug 30 03:11:54.966376 2026] [authz_core:error] [pid 521505:tid 521652] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory24
[Sun Aug 30 03:11:54.966712 2026] [authz_core:error] [pid 521505:tid 521652] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory24
[Sun Aug 30 03:11:54.967578 2026] [security2:error] [pid 521505:tid 521603] [remote 185.93.89.167:13143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "net.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlym8byYE0iXl--K56pQADX2E"]
[Sun Aug 30 03:11:54.971309 2026] [security2:error] [pid 521505:tid 521551] [remote 185.93.89.167:1995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "lp.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K56qQADPS0"]
[Sun Aug 30 03:11:54.975057 2026] [security2:error] [pid 521505:tid 521608] [remote 185.93.89.167:15177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "forms.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K56rgADIWY"]
[Sun Aug 30 03:11:54.975153 2026] [security2:error] [pid 521505:tid 521614] [remote 185.93.89.167:45621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images8.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K56rQADZmw"]
[Sun Aug 30 03:11:54.976253 2026] [security2:error] [pid 521505:tid 521607] [remote 185.93.89.167:45765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns01.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlym8byYE0iXl--K56rwADXmU"]
[Sun Aug 30 03:11:54.977826 2026] [security2:error] [pid 521505:tid 521621] [remote 185.93.89.167:14681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mc.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlym8byYE0iXl--K56sgADiXM"]
[Sun Aug 30 03:11:54.978054 2026] [security2:error] [pid 521505:tid 521625] [remote 185.93.89.167:59215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "users.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlym8byYE0iXl--K56sAADP3c"]
[Sun Aug 30 03:11:54.978393 2026] [security2:error] [pid 521505:tid 521624] [remote 185.93.89.167:54367] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webservices.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPlym8byYE0iXl--K56sQADQHY"]
[Sun Aug 30 03:11:54.984065 2026] [security2:error] [pid 521505:tid 521684] [client 20.48.160.90:37757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/admin.php/admin.php"] [unique_id "apPlym8byYE0iXl--K56tgAAA08"]
[Sun Aug 30 03:11:54.984835 2026] [security2:error] [pid 521505:tid 521612] [remote 185.93.89.167:47169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "order.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K56twADT2o"]
[Sun Aug 30 03:11:54.985277 2026] [security2:error] [pid 521505:tid 521613] [remote 185.93.89.167:48523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "web01.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K56ugADf2s"]
[Sun Aug 30 03:11:54.987344 2026] [security2:error] [pid 521505:tid 521762] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "board.mariegronley.com"] [uri "/index.cgi"] [unique_id "apPlym8byYE0iXl--K56uAADnS4"]
[Sun Aug 30 03:11:54.988779 2026] [security2:error] [pid 521505:tid 521622] [remote 185.93.89.167:27945] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K56vAADNHQ"]
[Sun Aug 30 03:11:54.989204 2026] [security2:error] [pid 521505:tid 521623] [remote 185.93.89.167:64329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K56vQADXHU"]
[Sun Aug 30 03:11:54.989603 2026] [security2:error] [pid 521505:tid 521510] [remote 185.93.89.167:40249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracking.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlym8byYE0iXl--K56vgADRAQ"]
[Sun Aug 30 03:11:54.991042 2026] [security2:error] [pid 521505:tid 521633] [remote 185.93.89.167:62291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rs.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlym8byYE0iXl--K56wQADU38"]
[Sun Aug 30 03:11:54.991527 2026] [security2:error] [pid 521505:tid 521553] [remote 185.93.89.167:57109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "development.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlym8byYE0iXl--K56wwADQi8"]
[Sun Aug 30 03:11:54.991838 2026] [security2:error] [pid 521505:tid 521584] [remote 185.93.89.167:52789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "market.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlym8byYE0iXl--K56xAADnE4"]
[Sun Aug 30 03:11:54.994870 2026] [security2:error] [pid 521505:tid 521659] [client 20.104.50.220:28732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/w3llstore.php"] [unique_id "apPlym8byYE0iXl--K56xgAAAzY"]
[Sun Aug 30 03:11:54.996835 2026] [security2:error] [pid 521505:tid 521546] [remote 185.93.89.167:62709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp3.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlym8byYE0iXl--K56xwADQSg"]
[Sun Aug 30 03:11:54.999663 2026] [security2:error] [pid 521505:tid 521515] [remote 185.93.89.167:39923] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sitebuilder.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlym8byYE0iXl--K56ygADhQk"]
[Sun Aug 30 03:11:55.001271 2026] [security2:error] [pid 521505:tid 521533] [remote 185.93.89.167:3495] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlym8byYE0iXl--K56ywADahs"]
[Sun Aug 30 03:11:55.019259 2026] [security2:error] [pid 521505:tid 521719] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/sender/.env"] [unique_id "apPly28byYE0iXl--K561AAAA3I"]
[Sun Aug 30 03:11:55.020110 2026] [security2:error] [pid 521505:tid 521531] [remote 185.93.89.167:53363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "work.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K562AADkhk"]
[Sun Aug 30 03:11:55.020200 2026] [security2:error] [pid 521505:tid 521627] [remote 185.93.89.167:9557] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "s4.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K561wADUHk"]
[Sun Aug 30 03:11:55.029169 2026] [security2:error] [pid 521505:tid 521547] [remote 185.93.89.167:54151] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "affiliate.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K562wADhyk"]
[Sun Aug 30 03:11:55.031990 2026] [security2:error] [pid 521505:tid 521562] [remote 185.93.89.167:26309] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "piwik.mariegronley.com"] [uri "/env/.env"] [unique_id "apPly28byYE0iXl--K563QADYTg"]
[Sun Aug 30 03:11:55.042668 2026] [security2:error] [pid 524122:tid 524314] [client 158.23.184.117:20167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/db.php"] [unique_id "apPly33lhEjKFiK_nBJ6aQAAAcw"]
[Sun Aug 30 03:11:55.052218 2026] [security2:error] [pid 521505:tid 521632] [remote 185.93.89.167:64215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/env/.env"] [unique_id "apPly28byYE0iXl--K565QADWX4"]
[Sun Aug 30 03:11:55.053042 2026] [security2:error] [pid 521505:tid 521675] [client 20.151.200.44:26567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/tajj.php"] [unique_id "apPly28byYE0iXl--K566QAAA0Y"]
[Sun Aug 30 03:11:55.053605 2026] [security2:error] [pid 521505:tid 521542] [remote 185.93.89.167:64795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jp.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPly28byYE0iXl--K566wADiyQ"]
[Sun Aug 30 03:11:55.055272 2026] [security2:error] [pid 521505:tid 521565] [remote 185.93.89.167:10845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "campus.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPly28byYE0iXl--K567wADMDs"]
[Sun Aug 30 03:11:55.055702 2026] [security2:error] [pid 521505:tid 521512] [remote 185.93.89.167:31113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "math.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPly28byYE0iXl--K568QADXQY"]
[Sun Aug 30 03:11:55.056025 2026] [security2:error] [pid 521505:tid 521565] [remote 185.93.89.167:14833] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "se.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPly28byYE0iXl--K568wADUTs"]
[Sun Aug 30 03:11:55.059423 2026] [security2:error] [pid 521505:tid 521700] [client 20.151.200.44:45013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPly28byYE0iXl--K569wAAA18"]
[Sun Aug 30 03:11:55.064845 2026] [core:alert] [pid 521505:tid 521747] [client 185.110.104.173:35668] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:11:55.067254 2026] [security2:error] [pid 521505:tid 521561] [remote 185.93.89.167:34357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "banners.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K57AAADITc"]
[Sun Aug 30 03:11:55.067799 2026] [security2:error] [pid 521505:tid 521538] [remote 185.93.89.167:36485] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shopping.mariegronley.com"] [uri "/env/.env"] [unique_id "apPly28byYE0iXl--K57AQADZiA"]
[Sun Aug 30 03:11:55.071429 2026] [security2:error] [pid 521505:tid 521629] [remote 185.93.89.167:12177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tr.mariegronley.com"] [uri "/app/.env"] [unique_id "apPly28byYE0iXl--K57BAADiXs"]
[Sun Aug 30 03:11:55.074600 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:11851] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "biblioteca.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K57BgADQE0"]
[Sun Aug 30 03:11:55.080012 2026] [security2:error] [pid 521505:tid 521566] [remote 185.93.89.167:8597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drupal.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K57DAADTzw"]
[Sun Aug 30 03:11:55.080278 2026] [security2:error] [pid 521505:tid 521620] [remote 185.93.89.167:15109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "linux.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPly28byYE0iXl--K57DQADfHI"]
[Sun Aug 30 03:11:55.081734 2026] [security2:error] [pid 521505:tid 521570] [remote 185.93.89.167:11225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "da.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K57DgADnUA"]
[Sun Aug 30 03:11:55.083478 2026] [security2:error] [pid 521505:tid 521574] [remote 185.93.89.167:61033] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPly28byYE0iXl--K57EwADZEQ"]
[Sun Aug 30 03:11:55.084656 2026] [security2:error] [pid 521505:tid 521509] [remote 185.93.89.167:28567] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "user.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPly28byYE0iXl--K57FAADnAM"]
[Sun Aug 30 03:11:55.086521 2026] [security2:error] [pid 521505:tid 521527] [remote 185.93.89.167:16669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "links.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K57FgADWBU"]
[Sun Aug 30 03:11:55.089330 2026] [security2:error] [pid 521505:tid 521585] [remote 185.93.89.167:37291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "st.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPly28byYE0iXl--K57HAADcE8"]
[Sun Aug 30 03:11:55.089543 2026] [security2:error] [pid 521505:tid 521577] [remote 185.93.89.167:6761] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banner.mariegronley.com"] [uri "/system/.env"] [unique_id "apPly28byYE0iXl--K57GwADH0c"]
[Sun Aug 30 03:11:55.090200 2026] [security2:error] [pid 521505:tid 521519] [remote 185.93.89.167:24307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tw.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K57HwADPA0"]
[Sun Aug 30 03:11:55.090218 2026] [security2:error] [pid 521505:tid 521528] [remote 185.93.89.167:57009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "static2.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPly28byYE0iXl--K57HgADlBY"]
[Sun Aug 30 03:11:55.090951 2026] [security2:error] [pid 521505:tid 521567] [remote 185.93.89.167:9731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images5.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K57IwADSj0"]
[Sun Aug 30 03:11:55.091363 2026] [security2:error] [pid 521505:tid 521523] [remote 185.93.89.167:56429] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mb.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPly28byYE0iXl--K57IgADbRE"]
[Sun Aug 30 03:11:55.091493 2026] [security2:error] [pid 521505:tid 521628] [remote 185.93.89.167:23169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPly28byYE0iXl--K57JAADm3o"]
[Sun Aug 30 03:11:55.091746 2026] [security2:error] [pid 521505:tid 521617] [remote 185.93.89.167:59097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "web6.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPly28byYE0iXl--K57JQADlW8"]
[Sun Aug 30 03:11:55.092951 2026] [security2:error] [pid 521505:tid 521588] [remote 185.93.89.167:42991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "venus.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K57KAADVlI"]
[Sun Aug 30 03:11:55.093036 2026] [security2:error] [pid 521505:tid 521573] [remote 185.93.89.167:11075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redirect.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K57JwADJEM"]
[Sun Aug 30 03:11:55.098164 2026] [security2:error] [pid 521505:tid 521557] [remote 185.93.89.167:32655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lync.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K57LgADKDM"]
[Sun Aug 30 03:11:55.101034 2026] [security2:error] [pid 521505:tid 521529] [remote 185.93.89.167:13143] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "net.mariegronley.com"] [uri "/system/.env"] [unique_id "apPly28byYE0iXl--K57MQADYRc"]
[Sun Aug 30 03:11:55.101527 2026] [security2:error] [pid 521505:tid 521536] [remote 185.93.89.167:22281] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "labs.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPly28byYE0iXl--K57MgADVR4"]
[Sun Aug 30 03:11:55.103519 2026] [security2:error] [pid 521505:tid 521539] [remote 185.93.89.167:50005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fax.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K57NQADYiE"]
[Sun Aug 30 03:11:55.103712 2026] [security2:error] [pid 521505:tid 521586] [remote 185.93.89.167:36741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "software.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K57NgADK1A"]
[Sun Aug 30 03:11:55.106981 2026] [security2:error] [pid 521505:tid 521526] [remote 185.93.89.167:55243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldmail.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K57OQADcxQ"]
[Sun Aug 30 03:11:55.109138 2026] [security2:error] [pid 521505:tid 521630] [remote 185.93.89.167:45621] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "images8.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K57OgADhHw"]
[Sun Aug 30 03:11:55.109805 2026] [security2:error] [pid 521505:tid 521518] [remote 185.93.89.167:45765] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns01.mariegronley.com"] [uri "/system/.env"] [unique_id "apPly28byYE0iXl--K57OwADIww"]
[Sun Aug 30 03:11:55.111142 2026] [security2:error] [pid 521505:tid 521572] [remote 185.93.89.167:14681] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mc.mariegronley.com"] [uri "/system/.env"] [unique_id "apPly28byYE0iXl--K57PQADWUI"]
[Sun Aug 30 03:11:55.114442 2026] [security2:error] [pid 521505:tid 521560] [remote 185.93.89.167:24005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "radius.mariegronley.com"] [uri "/source/.env"] [unique_id "apPly28byYE0iXl--K57QgADODY"]
[Sun Aug 30 03:11:55.114726 2026] [security2:error] [pid 521505:tid 521601] [remote 185.93.89.167:15177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K57QQADOV8"]
[Sun Aug 30 03:11:55.115708 2026] [security2:error] [pid 521505:tid 521605] [remote 185.93.89.167:42995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns12.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPly28byYE0iXl--K57QwADdWM"]
[Sun Aug 30 03:11:55.118620 2026] [security2:error] [pid 521505:tid 521563] [remote 185.93.89.167:47169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "order.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K57RAADJjk"]
[Sun Aug 30 03:11:55.119753 2026] [security2:error] [pid 521505:tid 521598] [remote 185.93.89.167:48523] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K57RQADmVw"]
[Sun Aug 30 03:11:55.121327 2026] [security2:error] [pid 521505:tid 521639] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "board.mariegronley.com"] [uri "/index.cgi"] [unique_id "apPly28byYE0iXl--K57SAADImQ"]
[Sun Aug 30 03:11:55.125102 2026] [security2:error] [pid 521505:tid 521603] [remote 185.93.89.167:52789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "market.mariegronley.com"] [uri "/system/.env"] [unique_id "apPly28byYE0iXl--K57UAADjmE"]
[Sun Aug 30 03:11:55.126630 2026] [security2:error] [pid 521505:tid 521609] [remote 185.93.89.167:14453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mobil.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K57UgADimc"]
[Sun Aug 30 03:11:55.131373 2026] [security2:error] [pid 521505:tid 521597] [remote 185.93.89.167:62709] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "smtp3.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K57VgADgls"]
[Sun Aug 30 03:11:55.133324 2026] [security2:error] [pid 521505:tid 521616] [remote 185.93.89.167:48785] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns02.mariegronley.com"] [uri "/server/.env"] [unique_id "apPly28byYE0iXl--K57WwADXm4"]
[Sun Aug 30 03:11:55.133480 2026] [security2:error] [pid 521505:tid 521551] [remote 185.93.89.167:39923] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sitebuilder.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPly28byYE0iXl--K57WgADiS0"]
[Sun Aug 30 03:11:55.139068 2026] [security2:error] [pid 521505:tid 521721] [client 20.104.49.130:54170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/155.php"] [unique_id "apPly28byYE0iXl--K57XgAAA3Q"]
[Sun Aug 30 03:11:55.141099 2026] [security2:error] [pid 521505:tid 521695] [client 20.104.49.130:43291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/new.php"] [unique_id "apPly28byYE0iXl--K57YgAAA1o"]
[Sun Aug 30 03:11:55.142915 2026] [security2:error] [pid 521505:tid 521614] [remote 185.93.89.167:62859] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mailgw.mariegronley.com"] [uri "/env/.env"] [unique_id "apPly28byYE0iXl--K57YwADT2w"]
[Sun Aug 30 03:11:55.144201 2026] [security2:error] [pid 521505:tid 521621] [remote 185.93.89.167:49893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdm.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K57ZgADZHM"]
[Sun Aug 30 03:11:55.144371 2026] [security2:error] [pid 521505:tid 521607] [remote 185.93.89.167:14659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/source/.env"] [unique_id "apPly28byYE0iXl--K57ZQADXGU"]
[Sun Aug 30 03:11:55.145748 2026] [security2:error] [pid 521505:tid 521689] [client 20.48.160.90:37724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/media.php"] [unique_id "apPly28byYE0iXl--K57ZwAAA1Q"]
[Sun Aug 30 03:11:55.148809 2026] [security2:error] [pid 521505:tid 521625] [remote 185.93.89.167:60123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "up.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K57aQADnHc"]
[Sun Aug 30 03:11:55.152317 2026] [security2:error] [pid 521505:tid 521611] [remote 185.93.89.167:63579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wifi.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K57bAADcGk"]
[Sun Aug 30 03:11:55.155983 2026] [security2:error] [pid 521505:tid 521552] [remote 185.93.89.167:37133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kb.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPly28byYE0iXl--K57cQADfi4"]
[Sun Aug 30 03:11:55.166374 2026] [security2:error] [pid 521505:tid 521510] [remote 185.93.89.167:30871] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pro.mariegronley.com"] [uri "/env/.env"] [unique_id "apPly28byYE0iXl--K57dQADmwQ"]
[Sun Aug 30 03:11:55.177576 2026] [authz_core:error] [pid 521505:tid 521641] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:11:55.178007 2026] [authz_core:error] [pid 521505:tid 521641] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:11:55.181095 2026] [security2:error] [pid 521505:tid 521719] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/campaign/.env"] [unique_id "apPly28byYE0iXl--K57fAAAA3I"]
[Sun Aug 30 03:11:55.186640 2026] [security2:error] [pid 521505:tid 521584] [remote 185.93.89.167:13069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sc.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPly28byYE0iXl--K57gwADYU4"]
[Sun Aug 30 03:11:55.186671 2026] [security2:error] [pid 521505:tid 521543] [remote 185.93.89.167:53853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atlas.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPly28byYE0iXl--K57hAADVSU"]
[Sun Aug 30 03:11:55.187097 2026] [security2:error] [pid 521505:tid 521682] [client 158.23.184.117:19722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/default.php"] [unique_id "apPly28byYE0iXl--K57gAAAA00"]
[Sun Aug 30 03:11:55.187225 2026] [security2:error] [pid 521505:tid 521508] [remote 185.93.89.167:64795] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jp.mariegronley.com"] [uri "/system/.env"] [unique_id "apPly28byYE0iXl--K57gQADZwI"]
[Sun Aug 30 03:11:55.187489 2026] [security2:error] [pid 521505:tid 521515] [remote 185.93.89.167:4287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "php.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPly28byYE0iXl--K57hgADKwk"]
[Sun Aug 30 03:11:55.187502 2026] [security2:error] [pid 521505:tid 521546] [remote 185.93.89.167:2579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "love.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPly28byYE0iXl--K57hQADYSg"]
[Sun Aug 30 03:11:55.187567 2026] [security2:error] [pid 521505:tid 521553] [remote 185.93.89.167:42909] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "direct.mariegronley.com"] [uri "/env/.env"] [unique_id "apPly28byYE0iXl--K57ggADhi8"]
[Sun Aug 30 03:11:55.188909 2026] [security2:error] [pid 521505:tid 521549] [remote 185.93.89.167:10845] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "campus.mariegronley.com"] [uri "/system/.env"] [unique_id "apPly28byYE0iXl--K57iQADhCs"]
[Sun Aug 30 03:11:55.189063 2026] [security2:error] [pid 521505:tid 521524] [remote 185.93.89.167:14833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "se.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPly28byYE0iXl--K57iwADRhI"]
[Sun Aug 30 03:11:55.189175 2026] [security2:error] [pid 521505:tid 521516] [remote 185.93.89.167:7437] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images7.mariegronley.com"] [uri "/env/.env"] [unique_id "apPly28byYE0iXl--K57hwADcwo"]
[Sun Aug 30 03:11:55.189384 2026] [security2:error] [pid 521505:tid 521631] [remote 185.93.89.167:29333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reg.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPly28byYE0iXl--K57jAADUn0"]
[Sun Aug 30 03:11:55.189870 2026] [security2:error] [pid 521505:tid 521556] [remote 185.93.89.167:31113] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "math.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K57igADIzI"]
[Sun Aug 30 03:11:55.190678 2026] [security2:error] [pid 521505:tid 521579] [remote 185.93.89.167:59907] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "health.mariegronley.com"] [uri "/env/.env"] [unique_id "apPly28byYE0iXl--K57jQADOUk"]
[Sun Aug 30 03:11:55.192009 2026] [security2:error] [pid 521505:tid 521513] [remote 185.93.89.167:44659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "p.mariegronley.com"] [uri "/source/.env"] [unique_id "apPly28byYE0iXl--K57jgADdQc"]
[Sun Aug 30 03:11:55.193189 2026] [security2:error] [pid 521505:tid 521600] [remote 185.93.89.167:37521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K57kAADJl4"]
[Sun Aug 30 03:11:55.197870 2026] [authz_core:error] [pid 521505:tid 521653] [client 66.249.66.68:53081] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:55.198168 2026] [authz_core:error] [pid 521505:tid 521653] [client 66.249.66.68:53081] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:55.204681 2026] [security2:error] [pid 521505:tid 521562] [remote 185.93.89.167:56175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "press.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPly28byYE0iXl--K57lwADRTg"]
[Sun Aug 30 03:11:55.204732 2026] [security2:error] [pid 521505:tid 521547] [remote 185.93.89.167:12177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tr.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPly28byYE0iXl--K57lgADjik"]
[Sun Aug 30 03:11:55.209433 2026] [security2:error] [pid 521505:tid 521632] [remote 185.93.89.167:39177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "register.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPly28byYE0iXl--K57mwADb34"]
[Sun Aug 30 03:11:55.212104 2026] [security2:error] [pid 521505:tid 521564] [remote 185.93.89.167:5225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preprod.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPly28byYE0iXl--K57nAADeDo"]
[Sun Aug 30 03:11:55.213633 2026] [security2:error] [pid 521505:tid 521615] [remote 185.93.89.167:15109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "linux.mariegronley.com"] [uri "/system/.env"] [unique_id "apPly28byYE0iXl--K57nwADZW0"]
[Sun Aug 30 03:11:55.216359 2026] [security2:error] [pid 521505:tid 521506] [remote 185.93.89.167:61033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "analytics.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPly28byYE0iXl--K57oQADmgA"]
[Sun Aug 30 03:11:55.217414 2026] [security2:error] [pid 521505:tid 521541] [remote 185.93.89.167:14991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "barracuda.mariegronley.com"] [uri "/source/.env"] [unique_id "apPly28byYE0iXl--K57ogADdCM"]
[Sun Aug 30 03:11:55.218360 2026] [security2:error] [pid 521505:tid 521555] [remote 185.93.89.167:28567] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "user.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPly28byYE0iXl--K57pAADQDE"]
[Sun Aug 30 03:11:55.219443 2026] [security2:error] [pid 521505:tid 521507] [remote 185.93.89.167:25969] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dbadmin.mariegronley.com"] [uri "/source/.env"] [unique_id "apPly28byYE0iXl--K57pQADWgE"]
[Sun Aug 30 03:11:55.219797 2026] [security2:error] [pid 521505:tid 521548] [remote 185.93.89.167:18729] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ntp1.mariegronley.com"] [uri "/env/.env"] [unique_id "apPly28byYE0iXl--K57pgADcSo"]
[Sun Aug 30 03:11:55.222198 2026] [security2:error] [pid 521505:tid 521594] [remote 185.93.89.167:6761] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "banner.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPly28byYE0iXl--K57qQADSFg"]
[Sun Aug 30 03:11:55.223320 2026] [security2:error] [pid 521505:tid 521565] [remote 185.93.89.167:37291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "st.mariegronley.com"] [uri "/system/.env"] [unique_id "apPly28byYE0iXl--K57qAADITs"]
[Sun Aug 30 03:11:55.223556 2026] [security2:error] [pid 521505:tid 521544] [remote 185.93.89.167:1591] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/source/.env"] [unique_id "apPly28byYE0iXl--K57qwADPSY"]
[Sun Aug 30 03:11:55.223770 2026] [security2:error] [pid 521505:tid 521561] [remote 185.93.89.167:29329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mars.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K57rgADfzc"]
[Sun Aug 30 03:11:55.224228 2026] [security2:error] [pid 521505:tid 521538] [remote 185.93.89.167:56429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mb.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPly28byYE0iXl--K57sAADQiA"]
[Sun Aug 30 03:11:55.224404 2026] [security2:error] [pid 521505:tid 521535] [remote 185.93.89.167:57009] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "static2.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K57rAADkR0"]
[Sun Aug 30 03:11:55.224528 2026] [security2:error] [pid 521505:tid 521534] [remote 185.93.89.167:23169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www7.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPly28byYE0iXl--K57sQADOhw"]
[Sun Aug 30 03:11:55.224954 2026] [security2:error] [pid 521505:tid 521537] [remote 185.93.89.167:7863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adserver.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPly28byYE0iXl--K57swADXB8"]
[Sun Aug 30 03:11:55.225739 2026] [security2:error] [pid 521505:tid 521629] [remote 185.93.89.167:59097] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "web6.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K57sgADZHs"]
[Sun Aug 30 03:11:55.226049 2026] [security2:error] [pid 521505:tid 521532] [remote 185.93.89.167:42991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "venus.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K57tAADVBo"]
[Sun Aug 30 03:11:55.226101 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:11075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redirect.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K57tQADTk0"]
[Sun Aug 30 03:11:55.228040 2026] [security2:error] [pid 521505:tid 521568] [remote 185.93.89.167:3789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vc.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K57twADLT4"]
[Sun Aug 30 03:11:55.228559 2026] [security2:error] [pid 521505:tid 521558] [remote 185.93.89.167:41989] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ipfixe.mariegronley.com"] [uri "/env/.env"] [unique_id "apPly28byYE0iXl--K57tgADUzQ"]
[Sun Aug 30 03:11:55.230889 2026] [security2:error] [pid 521505:tid 521566] [remote 185.93.89.167:10145] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "g.mariegronley.com"] [uri "/env/.env"] [unique_id "apPly28byYE0iXl--K57uAADfDw"]
[Sun Aug 30 03:11:55.233819 2026] [security2:error] [pid 521505:tid 521570] [remote 185.93.89.167:13143] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "net.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPly28byYE0iXl--K57ugADhUA"]
[Sun Aug 30 03:11:55.234879 2026] [security2:error] [pid 521505:tid 521574] [remote 185.93.89.167:22281] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "labs.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPly28byYE0iXl--K57uwADV0Q"]
[Sun Aug 30 03:11:55.236703 2026] [security2:error] [pid 521505:tid 521540] [remote 185.93.89.167:36741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "software.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K57vQADHyI"]
[Sun Aug 30 03:11:55.240296 2026] [security2:error] [pid 521505:tid 521509] [remote 185.93.89.167:55243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldmail.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K57vwADfgM"]
[Sun Aug 30 03:11:55.242694 2026] [security2:error] [pid 521505:tid 521585] [remote 185.93.89.167:45765] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "ns01.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPly28byYE0iXl--K57xAADNk8"]
[Sun Aug 30 03:11:55.242753 2026] [security2:error] [pid 521505:tid 521527] [remote 185.93.89.167:1995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K57wwADWxU"]
[Sun Aug 30 03:11:55.243862 2026] [security2:error] [pid 521505:tid 521577] [remote 185.93.89.167:14681] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mc.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPly28byYE0iXl--K57xQADm0c"]
[Sun Aug 30 03:11:55.246392 2026] [security2:error] [pid 521505:tid 521525] [remote 185.93.89.167:59215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "users.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPly28byYE0iXl--K57xwADVhM"]
[Sun Aug 30 03:11:55.249482 2026] [security2:error] [pid 521505:tid 521554] [remote 185.93.89.167:42995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "ns12.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K57zAADUDA"]
[Sun Aug 30 03:11:55.254561 2026] [security2:error] [pid 521505:tid 521617] [remote 185.93.89.167:24213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "in.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPly28byYE0iXl--K570QADYW8"]
[Sun Aug 30 03:11:55.254694 2026] [security2:error] [pid 521505:tid 521628] [remote 185.93.89.167:62949] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "board.mariegronley.com"] [uri "/source/.env"] [unique_id "apPly28byYE0iXl--K570AADTXo"]
[Sun Aug 30 03:11:55.254833 2026] [security2:error] [pid 521505:tid 521682] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "board.mariegronley.com"] [uri "/source/.env"] [unique_id "apPly28byYE0iXl--K570AADTXo"]
[Sun Aug 30 03:11:55.256704 2026] [security2:error] [pid 521505:tid 521550] [remote 185.93.89.167:64329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digital.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K571QADKCw"]
[Sun Aug 30 03:11:55.256740 2026] [security2:error] [pid 521505:tid 521588] [remote 185.93.89.167:27945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images6.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K571gADNVI"]
[Sun Aug 30 03:11:55.257684 2026] [security2:error] [pid 521505:tid 521591] [remote 185.93.89.167:52789] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "market.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPly28byYE0iXl--K572QADOFU"]
[Sun Aug 30 03:11:55.258765 2026] [security2:error] [pid 521505:tid 521522] [remote 185.93.89.167:16627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "education.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPly28byYE0iXl--K572gADRhA"]
[Sun Aug 30 03:11:55.266685 2026] [security2:error] [pid 521505:tid 521539] [remote 185.93.89.167:39923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sitebuilder.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPly28byYE0iXl--K574wADaiE"]
[Sun Aug 30 03:11:55.272352 2026] [security2:error] [pid 521505:tid 521586] [remote 185.93.89.167:62291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rs.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPly28byYE0iXl--K575QADX1A"]
[Sun Aug 30 03:11:55.279349 2026] [security2:error] [pid 521505:tid 521716] [client 20.48.160.90:61454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/mac.php"] [unique_id "apPly28byYE0iXl--K576gAAA28"]
[Sun Aug 30 03:11:55.281202 2026] [security2:error] [pid 521505:tid 521518] [remote 185.93.89.167:3495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail5.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K577AADeAw"]
[Sun Aug 30 03:11:55.285144 2026] [security2:error] [pid 521505:tid 521576] [remote 185.93.89.167:11687] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pr.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPly28byYE0iXl--K577wADkEY"]
[Sun Aug 30 03:11:55.288829 2026] [security2:error] [pid 521505:tid 521563] [remote 185.93.89.167:9557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "s4.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K579AADQDk"]
[Sun Aug 30 03:11:55.289096 2026] [security2:error] [pid 521505:tid 521598] [remote 185.93.89.167:53985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "img3.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K579QADWlw"]
[Sun Aug 30 03:11:55.289511 2026] [security2:error] [pid 521505:tid 521605] [remote 185.93.89.167:37133] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K578gADdGM"]
[Sun Aug 30 03:11:55.291269 2026] [security2:error] [pid 521505:tid 521606] [remote 185.93.89.167:4349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mm.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPly28byYE0iXl--K579gADYGQ"]
[Sun Aug 30 03:11:55.299215 2026] [security2:error] [pid 521505:tid 521582] [remote 185.93.89.167:54151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "affiliate.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K57-AADPUw"]
[Sun Aug 30 03:11:55.300195 2026] [security2:error] [pid 521505:tid 521604] [remote 185.93.89.167:26309] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "piwik.mariegronley.com"] [uri "/src/.env"] [unique_id "apPly28byYE0iXl--K57-gADQmI"]
[Sun Aug 30 03:11:55.313723 2026] [security2:error] [pid 521505:tid 521762] [client 20.104.49.130:57690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/press.php"] [unique_id "apPly28byYE0iXl--K57_AAAA50"]
[Sun Aug 30 03:11:55.319923 2026] [security2:error] [pid 521505:tid 521705] [client 20.104.49.130:52110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/memberfuns.php"] [unique_id "apPly28byYE0iXl--K57_wAAA2Q"]
[Sun Aug 30 03:11:55.320305 2026] [security2:error] [pid 521505:tid 521626] [remote 185.93.89.167:64795] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "jp.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPly28byYE0iXl--K58AgADLXg"]
[Sun Aug 30 03:11:55.320340 2026] [security2:error] [pid 521505:tid 521603] [remote 185.93.89.167:13069] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "sc.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K58AQADTmE"]
[Sun Aug 30 03:11:55.320373 2026] [security2:error] [pid 521505:tid 521602] [remote 185.93.89.167:53853] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "atlas.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K58AAADVGA"]
[Sun Aug 30 03:11:55.321200 2026] [security2:error] [pid 521505:tid 521521] [remote 185.93.89.167:2579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "love.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K58AwADUw8"]
[Sun Aug 30 03:11:55.321279 2026] [security2:error] [pid 521505:tid 521609] [remote 185.93.89.167:4287] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "php.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K58BAADfGc"]
[Sun Aug 30 03:11:55.321825 2026] [security2:error] [pid 521505:tid 521551] [remote 185.93.89.167:10845] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "campus.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPly28byYE0iXl--K58CAADhS0"]
[Sun Aug 30 03:11:55.321840 2026] [security2:error] [pid 521505:tid 521610] [remote 185.93.89.167:64215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/src/.env"] [unique_id "apPly28byYE0iXl--K58BgADP2g"]
[Sun Aug 30 03:11:55.322567 2026] [security2:error] [pid 521505:tid 521551] [remote 185.93.89.167:14833] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "se.mariegronley.com"] [uri "/system/.env"] [unique_id "apPly28byYE0iXl--K58CQADly0"]
[Sun Aug 30 03:11:55.323476 2026] [security2:error] [pid 521505:tid 521607] [remote 185.93.89.167:37843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jupiter.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K58DAADcGU"]
[Sun Aug 30 03:11:55.323845 2026] [security2:error] [pid 521505:tid 521614] [remote 185.93.89.167:29333] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "reg.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K58CgADbGw"]
[Sun Aug 30 03:11:55.326482 2026] [security2:error] [pid 521505:tid 521619] [remote 185.93.89.167:37521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K58EAADm3E"]
[Sun Aug 30 03:11:55.327082 2026] [security2:error] [pid 521505:tid 521743] [client 158.23.184.117:19637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/dev1s.php"] [unique_id "apPly28byYE0iXl--K58EQAAA4o"]
[Sun Aug 30 03:11:55.331697 2026] [security2:error] [pid 521505:tid 521611] [remote 185.93.89.167:21227] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "outlook.mariegronley.com"] [uri "/source/.env"] [unique_id "apPly28byYE0iXl--K58EgADjGk"]
[Sun Aug 30 03:11:55.335756 2026] [security2:error] [pid 521505:tid 521613] [remote 185.93.89.167:63379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviews.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K58FQADYWs"]
[Sun Aug 30 03:11:55.335856 2026] [security2:error] [pid 521505:tid 521612] [remote 185.93.89.167:36485] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shopping.mariegronley.com"] [uri "/src/.env"] [unique_id "apPly28byYE0iXl--K58EwADUGo"]
[Sun Aug 30 03:11:55.338780 2026] [security2:error] [pid 521505:tid 521552] [remote 185.93.89.167:56175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "press.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K58FgADTS4"]
[Sun Aug 30 03:11:55.339805 2026] [security2:error] [pid 521505:tid 521622] [remote 185.93.89.167:34607] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sports.mariegronley.com"] [uri "/env/.env"] [unique_id "apPly28byYE0iXl--K58GQADKHQ"]
[Sun Aug 30 03:11:55.341364 2026] [security2:error] [pid 521505:tid 521623] [remote 185.93.89.167:1175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pgsql.mariegronley.com"] [uri "/env/.env"] [unique_id "apPly28byYE0iXl--K58GwADZ3U"]
[Sun Aug 30 03:11:55.341916 2026] [security2:error] [pid 521505:tid 521648] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/newsletter/.env"] [unique_id "apPly28byYE0iXl--K58HAAAAys"]
[Sun Aug 30 03:11:55.342575 2026] [security2:error] [pid 521505:tid 521584] [remote 185.93.89.167:11851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biblioteca.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K58HQADhE4"]
[Sun Aug 30 03:11:55.343562 2026] [security2:error] [pid 521505:tid 521543] [remote 185.93.89.167:39177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "register.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K58HgADQSU"]
[Sun Aug 30 03:11:55.346301 2026] [security2:error] [pid 521505:tid 521515] [remote 185.93.89.167:15109] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "linux.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPly28byYE0iXl--K58IQADWQk"]
[Sun Aug 30 03:11:55.346383 2026] [security2:error] [pid 521505:tid 521508] [remote 185.93.89.167:5225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "preprod.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K58IAADbQI"]
[Sun Aug 30 03:11:55.350010 2026] [security2:error] [pid 521505:tid 521633] [remote 185.93.89.167:11225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "da.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K58JAADSn8"]
[Sun Aug 30 03:11:55.350236 2026] [security2:error] [pid 521505:tid 521553] [remote 185.93.89.167:61033] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/system/.env"] [unique_id "apPly28byYE0iXl--K58IwADPC8"]
[Sun Aug 30 03:11:55.351574 2026] [security2:error] [pid 521505:tid 521524] [remote 185.93.89.167:28567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "user.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPly28byYE0iXl--K58KAADexI"]
[Sun Aug 30 03:11:55.356154 2026] [security2:error] [pid 521505:tid 521579] [remote 185.93.89.167:37291] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "st.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPly28byYE0iXl--K58LwADkkk"]
[Sun Aug 30 03:11:55.357430 2026] [security2:error] [pid 521505:tid 521599] [remote 185.93.89.167:56429] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mb.mariegronley.com"] [uri "/system/.env"] [unique_id "apPly28byYE0iXl--K58MgADX10"]
[Sun Aug 30 03:11:55.358048 2026] [security2:error] [pid 521505:tid 521559] [remote 185.93.89.167:23169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/system/.env"] [unique_id "apPly28byYE0iXl--K58NAADMjU"]
[Sun Aug 30 03:11:55.358754 2026] [security2:error] [pid 521505:tid 521627] [remote 185.93.89.167:7863] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "adserver.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K58NQADY3k"]
[Sun Aug 30 03:11:55.359175 2026] [security2:error] [pid 521505:tid 521562] [remote 185.93.89.167:53553] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "demo2.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPly28byYE0iXl--K58NwADZjg"]
[Sun Aug 30 03:11:55.361331 2026] [security2:error] [pid 521505:tid 521578] [remote 185.93.89.167:3789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vc.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K58PAADN0g"]
[Sun Aug 30 03:11:55.367940 2026] [security2:error] [pid 521505:tid 521517] [remote 185.93.89.167:22281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "labs.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPly28byYE0iXl--K58QQADSQs"]
[Sun Aug 30 03:11:55.377837 2026] [security2:error] [pid 521505:tid 521565] [remote 185.93.89.167:45621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images8.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K58SAADfzs"]
[Sun Aug 30 03:11:55.379603 2026] [security2:error] [pid 521505:tid 521590] [remote 185.93.89.167:59215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "users.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPly28byYE0iXl--K58SQADPVQ"]
[Sun Aug 30 03:11:55.382955 2026] [security2:error] [pid 521505:tid 521535] [remote 185.93.89.167:24005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "radius.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPly28byYE0iXl--K58TAADSB0"]
[Sun Aug 30 03:11:55.385975 2026] [security2:error] [pid 521505:tid 521534] [remote 185.93.89.167:47169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "order.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K58TgADkRw"]
[Sun Aug 30 03:11:55.388024 2026] [security2:error] [pid 521505:tid 521592] [remote 185.93.89.167:48523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "web01.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K58UQADnVY"]
[Sun Aug 30 03:11:55.388707 2026] [security2:error] [pid 521505:tid 521580] [remote 185.93.89.167:24213] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "in.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K58UAADeko"]
[Sun Aug 30 03:11:55.389007 2026] [security2:error] [pid 521505:tid 521663] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "board.mariegronley.com"] [uri "/index.cgi"] [unique_id "apPly28byYE0iXl--K58TwADOh8"]
[Sun Aug 30 03:11:55.391298 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:40249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracking.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K58VgADTk0"]
[Sun Aug 30 03:11:55.392081 2026] [authz_core:error] [pid 521505:tid 521710] [client 66.249.66.205:41653] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:55.392553 2026] [authz_core:error] [pid 521505:tid 521710] [client 66.249.66.205:41653] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:55.392583 2026] [security2:error] [pid 521505:tid 521568] [remote 185.93.89.167:16627] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "education.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K58VwADVD4"]
[Sun Aug 30 03:11:55.393868 2026] [security2:error] [pid 521505:tid 521558] [remote 185.93.89.167:57109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "development.mariegronley.com"] [uri "/env/.env"] [unique_id "apPly28byYE0iXl--K58WAADUzQ"]
[Sun Aug 30 03:11:55.395160 2026] [security2:error] [pid 521505:tid 521620] [remote 185.93.89.167:15177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "forms.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K58WgADV3I"]
[Sun Aug 30 03:11:55.398400 2026] [security2:error] [pid 521505:tid 521570] [remote 185.93.89.167:62709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp3.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K58WwADhUA"]
[Sun Aug 30 03:11:55.400116 2026] [security2:error] [pid 521505:tid 521574] [remote 185.93.89.167:39923] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sitebuilder.mariegronley.com"] [uri "/system/.env"] [unique_id "apPly28byYE0iXl--K58XQADl0Q"]
[Sun Aug 30 03:11:55.411201 2026] [security2:error] [pid 521505:tid 521587] [remote 185.93.89.167:62859] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mailgw.mariegronley.com"] [uri "/src/.env"] [unique_id "apPly28byYE0iXl--K58YAADm1E"]
[Sun Aug 30 03:11:55.412231 2026] [security2:error] [pid 521505:tid 521509] [remote 185.93.89.167:62291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rs.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPly28byYE0iXl--K58YQADWwM"]
[Sun Aug 30 03:11:55.412984 2026] [security2:error] [pid 521505:tid 521527] [remote 185.93.89.167:14659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPly28byYE0iXl--K58ZAADTxU"]
[Sun Aug 30 03:11:55.422590 2026] [security2:error] [pid 521505:tid 521571] [remote 185.93.89.167:53985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "img3.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K58bwADc0E"]
[Sun Aug 30 03:11:55.422611 2026] [security2:error] [pid 521505:tid 521617] [remote 185.93.89.167:53363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "work.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K58cAADQW8"]
[Sun Aug 30 03:11:55.431847 2026] [security2:error] [pid 521505:tid 521628] [remote 185.93.89.167:4349] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mm.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K58cwADLno"]
[Sun Aug 30 03:11:55.434796 2026] [security2:error] [pid 521505:tid 521550] [remote 185.93.89.167:30871] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pro.mariegronley.com"] [uri "/src/.env"] [unique_id "apPly28byYE0iXl--K58egADLCw"]
[Sun Aug 30 03:11:55.455521 2026] [security2:error] [pid 521505:tid 521536] [remote 185.93.89.167:14833] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "se.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPly28byYE0iXl--K58hwADmh4"]
[Sun Aug 30 03:11:55.455608 2026] [security2:error] [pid 521505:tid 521539] [remote 185.93.89.167:42909] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "direct.mariegronley.com"] [uri "/src/.env"] [unique_id "apPly28byYE0iXl--K58hgADNyE"]
[Sun Aug 30 03:11:55.456463 2026] [security2:error] [pid 521505:tid 521545] [remote 185.93.89.167:37843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jupiter.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K58iQADkyc"]
[Sun Aug 30 03:11:55.456862 2026] [security2:error] [pid 521505:tid 521586] [remote 185.93.89.167:7437] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images7.mariegronley.com"] [uri "/src/.env"] [unique_id "apPly28byYE0iXl--K58iAADkFA"]
[Sun Aug 30 03:11:55.458926 2026] [security2:error] [pid 521505:tid 521630] [remote 185.93.89.167:31113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "math.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K58jQADSXw"]
[Sun Aug 30 03:11:55.459929 2026] [security2:error] [pid 521505:tid 521630] [remote 185.93.89.167:59907] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "health.mariegronley.com"] [uri "/src/.env"] [unique_id "apPly28byYE0iXl--K58jgADcXw"]
[Sun Aug 30 03:11:55.460737 2026] [security2:error] [pid 521505:tid 521576] [remote 185.93.89.167:44659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "p.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPly28byYE0iXl--K58kAADXkY"]
[Sun Aug 30 03:11:55.464655 2026] [security2:error] [pid 521505:tid 521654] [client 158.23.147.79:21472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPly28byYE0iXl--K58kgAAAzE"]
[Sun Aug 30 03:11:55.468016 2026] [security2:error] [pid 521505:tid 521709] [client 158.23.184.117:19612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/dex.php"] [unique_id "apPly28byYE0iXl--K58kwAAA2g"]
[Sun Aug 30 03:11:55.469410 2026] [security2:error] [pid 521505:tid 521530] [remote 185.93.89.167:63379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviews.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K58lQADYBg"]
[Sun Aug 30 03:11:55.469872 2026] [security2:error] [pid 521505:tid 521598] [remote 185.93.89.167:34357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "banners.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K58lwADf1w"]
[Sun Aug 30 03:11:55.472932 2026] [security2:error] [pid 521505:tid 521560] [remote 185.93.89.167:12177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tr.mariegronley.com"] [uri "/server/.env"] [unique_id "apPly28byYE0iXl--K58mQADizY"]
[Sun Aug 30 03:11:55.482999 2026] [security2:error] [pid 521505:tid 521602] [remote 185.93.89.167:61033] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "analytics.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPly28byYE0iXl--K58pAADTmA"]
[Sun Aug 30 03:11:55.484268 2026] [security2:error] [pid 521505:tid 521521] [remote 185.93.89.167:8597] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "drupal.mariegronley.com"] [uri "/env/.env"] [unique_id "apPly28byYE0iXl--K58pQADUw8"]
[Sun Aug 30 03:11:55.484660 2026] [authz_core:error] [pid 521505:tid 521727] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory32
[Sun Aug 30 03:11:55.484914 2026] [authz_core:error] [pid 521505:tid 521727] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory32
[Sun Aug 30 03:11:55.485159 2026] [security2:error] [pid 521505:tid 521609] [remote 185.93.89.167:28567] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "user.mariegronley.com"] [uri "/system/.env"] [unique_id "apPly28byYE0iXl--K58pgADfGc"]
[Sun Aug 30 03:11:55.486077 2026] [security2:error] [pid 521505:tid 521609] [remote 185.93.89.167:14991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "barracuda.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPly28byYE0iXl--K58pwADP2c"]
[Sun Aug 30 03:11:55.487731 2026] [security2:error] [pid 521505:tid 521610] [remote 185.93.89.167:18729] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ntp1.mariegronley.com"] [uri "/src/.env"] [unique_id "apPly28byYE0iXl--K58qAADhWg"]
[Sun Aug 30 03:11:55.488899 2026] [security2:error] [pid 521505:tid 521597] [remote 185.93.89.167:16669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "links.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K58qQADl1s"]
[Sun Aug 30 03:11:55.489954 2026] [security2:error] [pid 521505:tid 521614] [remote 185.93.89.167:56429] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mb.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPly28byYE0iXl--K58rQADbGw"]
[Sun Aug 30 03:11:55.490379 2026] [security2:error] [pid 521505:tid 521607] [remote 185.93.89.167:25969] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dbadmin.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPly28byYE0iXl--K58rAADH2U"]
[Sun Aug 30 03:11:55.490835 2026] [security2:error] [pid 521505:tid 521621] [remote 185.93.89.167:23169] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www7.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPly28byYE0iXl--K58rgADnHM"]
[Sun Aug 30 03:11:55.491991 2026] [security2:error] [pid 521505:tid 521619] [remote 185.93.89.167:1591] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPly28byYE0iXl--K58sAADnHE"]
[Sun Aug 30 03:11:55.492612 2026] [security2:error] [pid 521505:tid 521613] [remote 185.93.89.167:57009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "static2.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K58swADT2s"]
[Sun Aug 30 03:11:55.493179 2026] [security2:error] [pid 521505:tid 521612] [remote 185.93.89.167:24307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tw.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K58tAADNmo"]
[Sun Aug 30 03:11:55.493231 2026] [security2:error] [pid 521505:tid 521618] [remote 185.93.89.167:9731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images5.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K58tQADinA"]
[Sun Aug 30 03:11:55.493682 2026] [security2:error] [pid 521505:tid 521569] [remote 185.93.89.167:59097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "web6.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K58twADVj8"]
[Sun Aug 30 03:11:55.496207 2026] [security2:error] [pid 521505:tid 521584] [remote 185.93.89.167:41989] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ipfixe.mariegronley.com"] [uri "/src/.env"] [unique_id "apPly28byYE0iXl--K58ugADYU4"]
[Sun Aug 30 03:11:55.498613 2026] [security2:error] [pid 521505:tid 521543] [remote 185.93.89.167:10145] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "g.mariegronley.com"] [uri "/src/.env"] [unique_id "apPly28byYE0iXl--K58uwADNCU"]
[Sun Aug 30 03:11:55.500002 2026] [security2:error] [pid 521505:tid 521515] [remote 185.93.89.167:32655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lync.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K58vAADVQk"]
[Sun Aug 30 03:11:55.501250 2026] [security2:error] [pid 521505:tid 521508] [remote 185.93.89.167:22281] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "labs.mariegronley.com"] [uri "/system/.env"] [unique_id "apPly28byYE0iXl--K58vQADZwI"]
[Sun Aug 30 03:11:55.503036 2026] [security2:error] [pid 521505:tid 521720] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/ses/.env"] [unique_id "apPly28byYE0iXl--K58vwAAA3M"]
[Sun Aug 30 03:11:55.505510 2026] [security2:error] [pid 521505:tid 521697] [client 34.15.159.88:50716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/kafka/.env"] [unique_id "apPly28byYE0iXl--K58wQAAA1w"]
[Sun Aug 30 03:11:55.505839 2026] [security2:error] [pid 521505:tid 521546] [remote 185.93.89.167:50005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fax.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K58wgADIyg"]
[Sun Aug 30 03:11:55.511317 2026] [security2:error] [pid 521505:tid 521714] [client 20.48.160.90:37736] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "bayoutents.com"] [uri "/1.php"] [unique_id "apPly28byYE0iXl--K58yQAAA20"]
[Sun Aug 30 03:11:55.511413 2026] [security2:error] [pid 521505:tid 521714] [client 20.48.160.90:37736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/1.php"] [unique_id "apPly28byYE0iXl--K58yQAAA20"]
[Sun Aug 30 03:11:55.512457 2026] [security2:error] [pid 521505:tid 521533] [remote 185.93.89.167:59215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "users.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPly28byYE0iXl--K58ywADKBs"]
[Sun Aug 30 03:11:55.516767 2026] [security2:error] [pid 521505:tid 521575] [remote 185.93.89.167:24005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "radius.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPly28byYE0iXl--K58zwADRUU"]
[Sun Aug 30 03:11:55.517151 2026] [security2:error] [pid 521505:tid 521559] [remote 185.93.89.167:42995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns12.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K580AADJjU"]
[Sun Aug 30 03:11:55.521990 2026] [security2:error] [pid 521505:tid 521531] [remote 185.93.89.167:62949] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "board.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPly28byYE0iXl--K581AADXxk"]
[Sun Aug 30 03:11:55.522118 2026] [security2:error] [pid 521505:tid 521700] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "board.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPly28byYE0iXl--K581AADXxk"]
[Sun Aug 30 03:11:55.524091 2026] [security2:error] [pid 521505:tid 521632] [remote 185.93.89.167:40249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracking.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K581wADPH4"]
[Sun Aug 30 03:11:55.525675 2026] [security2:error] [pid 524122:tid 524347] [client 20.104.49.130:63293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/666.php"] [unique_id "apPly33lhEjKFiK_nBJ6ggAAAe0"]
[Sun Aug 30 03:11:55.529198 2026] [security2:error] [pid 521505:tid 521564] [remote 185.93.89.167:14453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mobil.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K582wADZjo"]
[Sun Aug 30 03:11:55.532995 2026] [security2:error] [pid 521505:tid 521542] [remote 185.93.89.167:39923] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "sitebuilder.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPly28byYE0iXl--K583gADQyQ"]
[Sun Aug 30 03:11:55.535352 2026] [security2:error] [pid 521505:tid 521506] [remote 185.93.89.167:48785] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns02.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPly28byYE0iXl--K584AADQAA"]
[Sun Aug 30 03:11:55.538316 2026] [authz_core:error] [pid 521505:tid 521716] [client 216.73.216.128:23116] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:55.538556 2026] [authz_core:error] [pid 521505:tid 521716] [client 216.73.216.128:23116] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:55.546373 2026] [security2:error] [pid 521505:tid 521507] [remote 185.93.89.167:49893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdm.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K585AADcQE"]
[Sun Aug 30 03:11:55.546672 2026] [security2:error] [pid 521505:tid 521555] [remote 185.93.89.167:14659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPly28byYE0iXl--K584wADSTE"]
[Sun Aug 30 03:11:55.551384 2026] [security2:error] [pid 521505:tid 521565] [remote 185.93.89.167:62291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rs.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPly28byYE0iXl--K585gADIDs"]
[Sun Aug 30 03:11:55.552584 2026] [security2:error] [pid 521505:tid 521548] [remote 185.93.89.167:60123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "up.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K586AADZSo"]
[Sun Aug 30 03:11:55.554511 2026] [security2:error] [pid 521505:tid 521512] [remote 185.93.89.167:63579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wifi.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K586gADYAY"]
[Sun Aug 30 03:11:55.555510 2026] [security2:error] [pid 524122:tid 524265] [client 47.128.40.225:50966] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtrphotography.net"] [uri "/robots.txt"] [unique_id "apPly33lhEjKFiK_nBJ6hAAAAZs"]
[Sun Aug 30 03:11:55.555569 2026] [security2:error] [pid 521505:tid 521590] [remote 185.93.89.167:53363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "work.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K586wADh1Q"]
[Sun Aug 30 03:11:55.556910 2026] [security2:error] [pid 521505:tid 521535] [remote 185.93.89.167:37133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kb.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K587gADgx0"]
[Sun Aug 30 03:11:55.567367 2026] [security2:error] [pid 521505:tid 521592] [remote 185.93.89.167:26309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piwik.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPly28byYE0iXl--K588gADa1Y"]
[Sun Aug 30 03:11:55.571605 2026] [security2:error] [pid 521505:tid 521729] [client 20.104.49.130:64067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/tiny2.php"] [unique_id "apPly28byYE0iXl--K58-AAAA3w"]
[Sun Aug 30 03:11:55.578860 2026] [authz_core:error] [pid 521505:tid 521668] [client 66.249.66.38:54686] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:55.579270 2026] [authz_core:error] [pid 521505:tid 521668] [client 66.249.66.38:54686] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:55.588739 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:13069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sc.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K59AgADik0"]
[Sun Aug 30 03:11:55.588826 2026] [security2:error] [pid 521505:tid 521629] [remote 185.93.89.167:53853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atlas.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K59AQADcHs"]
[Sun Aug 30 03:11:55.589333 2026] [security2:error] [pid 521505:tid 521570] [remote 185.93.89.167:2579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "love.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K59BwADYUA"]
[Sun Aug 30 03:11:55.589378 2026] [security2:error] [pid 521505:tid 521566] [remote 185.93.89.167:4287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "php.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K59CAADWDw"]
[Sun Aug 30 03:11:55.589913 2026] [security2:error] [pid 521505:tid 521540] [remote 185.93.89.167:64215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m1.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPly28byYE0iXl--K59CwADZyI"]
[Sun Aug 30 03:11:55.591431 2026] [security2:error] [pid 521505:tid 521587] [remote 185.93.89.167:29333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reg.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K59DQADIlE"]
[Sun Aug 30 03:11:55.594122 2026] [security2:error] [pid 521505:tid 521577] [remote 185.93.89.167:44659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "p.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPly28byYE0iXl--K59EQADI0c"]
[Sun Aug 30 03:11:55.599421 2026] [security2:error] [pid 521505:tid 521511] [remote 185.93.89.167:21227] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "outlook.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPly28byYE0iXl--K59EgADbQU"]
[Sun Aug 30 03:11:55.602721 2026] [security2:error] [pid 521505:tid 521519] [remote 185.93.89.167:34357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "banners.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K59FAADJA0"]
[Sun Aug 30 03:11:55.602955 2026] [security2:error] [pid 521505:tid 521571] [remote 185.93.89.167:36485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shopping.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPly28byYE0iXl--K59FQADhkE"]
[Sun Aug 30 03:11:55.606416 2026] [security2:error] [pid 521505:tid 521528] [remote 185.93.89.167:56175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "press.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K59FwADOxY"]
[Sun Aug 30 03:11:55.608151 2026] [security2:error] [pid 521505:tid 521554] [remote 185.93.89.167:34607] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sports.mariegronley.com"] [uri "/src/.env"] [unique_id "apPly28byYE0iXl--K59GAADTTA"]
[Sun Aug 30 03:11:55.609085 2026] [security2:error] [pid 521505:tid 521628] [remote 185.93.89.167:1175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pgsql.mariegronley.com"] [uri "/src/.env"] [unique_id "apPly28byYE0iXl--K59GQADjHo"]
[Sun Aug 30 03:11:55.611903 2026] [security2:error] [pid 521505:tid 521567] [remote 185.93.89.167:39177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "register.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K59HAADez0"]
[Sun Aug 30 03:11:55.614512 2026] [security2:error] [pid 521505:tid 521536] [remote 185.93.89.167:5225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preprod.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K59HwADdR4"]
[Sun Aug 30 03:11:55.618104 2026] [security2:error] [pid 521505:tid 521573] [remote 185.93.89.167:28567] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "user.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPly28byYE0iXl--K59IwADWUM"]
[Sun Aug 30 03:11:55.618919 2026] [security2:error] [pid 524122:tid 524310] [client 158.23.184.117:19764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/disagrsxr.php"] [unique_id "apPly33lhEjKFiK_nBJ6hwAAAcg"]
[Sun Aug 30 03:11:55.619631 2026] [security2:error] [pid 521505:tid 521596] [remote 185.93.89.167:14991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "barracuda.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPly28byYE0iXl--K59JgADZlo"]
[Sun Aug 30 03:11:55.621785 2026] [security2:error] [pid 521505:tid 521529] [remote 185.93.89.167:16669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "links.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K59KQADXRc"]
[Sun Aug 30 03:11:55.625115 2026] [security2:error] [pid 521505:tid 521518] [remote 185.93.89.167:25969] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dbadmin.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPly28byYE0iXl--K59MAADlAw"]
[Sun Aug 30 03:11:55.625388 2026] [security2:error] [pid 521505:tid 521630] [remote 185.93.89.167:1591] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPly28byYE0iXl--K59MQADcXw"]
[Sun Aug 30 03:11:55.625878 2026] [security2:error] [pid 521505:tid 521630] [remote 185.93.89.167:29329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mars.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K59MwADkHw"]
[Sun Aug 30 03:11:55.625912 2026] [security2:error] [pid 521505:tid 521595] [remote 185.93.89.167:7863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adserver.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K59NAADXlk"]
[Sun Aug 30 03:11:55.626207 2026] [security2:error] [pid 521505:tid 521530] [remote 185.93.89.167:24307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tw.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K59NQADkhg"]
[Sun Aug 30 03:11:55.626289 2026] [security2:error] [pid 521505:tid 521598] [remote 185.93.89.167:9731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images5.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K59NgADWlw"]
[Sun Aug 30 03:11:55.628390 2026] [security2:error] [pid 521505:tid 521605] [remote 185.93.89.167:11075] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "redirect.mariegronley.com"] [uri "/env/.env"] [unique_id "apPly28byYE0iXl--K59OQADZWM"]
[Sun Aug 30 03:11:55.628712 2026] [security2:error] [pid 521505:tid 521601] [remote 185.93.89.167:42991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "venus.mariegronley.com"] [uri "/env/.env"] [unique_id "apPly28byYE0iXl--K59OgADYF8"]
[Sun Aug 30 03:11:55.632903 2026] [security2:error] [pid 521505:tid 521589] [remote 185.93.89.167:32655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lync.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K59QAADSFM"]
[Sun Aug 30 03:11:55.634102 2026] [security2:error] [pid 521505:tid 521626] [remote 185.93.89.167:22281] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "labs.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPly28byYE0iXl--K59QQADf3g"]
[Sun Aug 30 03:11:55.638419 2026] [security2:error] [pid 521505:tid 521521] [remote 185.93.89.167:36741] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "software.mariegronley.com"] [uri "/env/.env"] [unique_id "apPly28byYE0iXl--K59QwADaA8"]
[Sun Aug 30 03:11:55.638866 2026] [security2:error] [pid 521505:tid 521608] [remote 185.93.89.167:50005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fax.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K59RAADZGY"]
[Sun Aug 30 03:11:55.642873 2026] [security2:error] [pid 521505:tid 521729] [client 20.48.160.90:38008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/classwithtostring.php"] [unique_id "apPly28byYE0iXl--K59RQAAA3w"]
[Sun Aug 30 03:11:55.643469 2026] [security2:error] [pid 521505:tid 521603] [remote 185.93.89.167:55243] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oldmail.mariegronley.com"] [uri "/env/.env"] [unique_id "apPly28byYE0iXl--K59RgADiGE"]
[Sun Aug 30 03:11:55.646300 2026] [security2:error] [pid 521505:tid 521609] [remote 185.93.89.167:59215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "users.mariegronley.com"] [uri "/system/.env"] [unique_id "apPly28byYE0iXl--K59RwADS2c"]
[Sun Aug 30 03:11:55.647922 2026] [security2:error] [pid 521505:tid 521607] [remote 185.93.89.167:1995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K59SwADVGU"]
[Sun Aug 30 03:11:55.648612 2026] [security2:error] [pid 521505:tid 521551] [remote 185.93.89.167:54367] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webservices.mariegronley.com"] [uri "/source/.env"] [unique_id "apPly28byYE0iXl--K59TAADTy0"]
[Sun Aug 30 03:11:55.649865 2026] [security2:error] [pid 521505:tid 521621] [remote 185.93.89.167:24005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radius.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPly28byYE0iXl--K59TQADinM"]
[Sun Aug 30 03:11:55.655024 2026] [security2:error] [pid 521505:tid 521613] [remote 185.93.89.167:62949] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "board.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPly28byYE0iXl--K59UAADYWs"]
[Sun Aug 30 03:11:55.655154 2026] [security2:error] [pid 521505:tid 521702] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "board.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPly28byYE0iXl--K59UAADYWs"]
[Sun Aug 30 03:11:55.655774 2026] [security2:error] [pid 521505:tid 521624] [remote 185.93.89.167:24213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "in.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K59UgADYXY"]
[Sun Aug 30 03:11:55.658203 2026] [security2:error] [pid 521505:tid 521618] [remote 185.93.89.167:64329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digital.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K59VgADH3A"]
[Sun Aug 30 03:11:55.658669 2026] [security2:error] [pid 521505:tid 521569] [remote 185.93.89.167:27945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images6.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K59WAADKz8"]
[Sun Aug 30 03:11:55.660310 2026] [security2:error] [pid 521505:tid 521622] [remote 185.93.89.167:16627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "education.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K59WQADW3Q"]
[Sun Aug 30 03:11:55.661597 2026] [security2:error] [pid 521505:tid 521552] [remote 185.93.89.167:57109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "development.mariegronley.com"] [uri "/src/.env"] [unique_id "apPly28byYE0iXl--K59XAADVS4"]
[Sun Aug 30 03:11:55.662369 2026] [security2:error] [pid 521505:tid 521623] [remote 185.93.89.167:14453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mobil.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K59XwADd3U"]
[Sun Aug 30 03:11:55.662625 2026] [security2:error] [pid 521505:tid 521760] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/sendgrid/.env"] [unique_id "apPly28byYE0iXl--K59XgAAA5s"]
[Sun Aug 30 03:11:55.678917 2026] [security2:error] [pid 521505:tid 521606] [remote 185.93.89.167:62859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailgw.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPly28byYE0iXl--K59cgADN2Q"]
[Sun Aug 30 03:11:55.679285 2026] [security2:error] [pid 521505:tid 521633] [remote 185.93.89.167:49893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdm.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K59cwADXX8"]
[Sun Aug 30 03:11:55.679523 2026] [security2:error] [pid 521505:tid 521553] [remote 185.93.89.167:14659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "otrs.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPly28byYE0iXl--K59dAADdi8"]
[Sun Aug 30 03:11:55.685860 2026] [security2:error] [pid 521505:tid 521546] [remote 185.93.89.167:60123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "up.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K59eQADXig"]
[Sun Aug 30 03:11:55.687599 2026] [security2:error] [pid 521505:tid 521524] [remote 185.93.89.167:63579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wifi.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K59egADeBI"]
[Sun Aug 30 03:11:55.690682 2026] [security2:error] [pid 521505:tid 521631] [remote 185.93.89.167:62291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rs.mariegronley.com"] [uri "/system/.env"] [unique_id "apPly28byYE0iXl--K59gQADIH0"]
[Sun Aug 30 03:11:55.692672 2026] [security2:error] [pid 521505:tid 521599] [remote 185.93.89.167:9557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "s4.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K59gwADg10"]
[Sun Aug 30 03:11:55.700392 2026] [security2:error] [pid 521505:tid 521575] [remote 185.93.89.167:26309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piwik.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPly28byYE0iXl--K59hwADV0U"]
[Sun Aug 30 03:11:55.701973 2026] [security2:error] [pid 521505:tid 521559] [remote 185.93.89.167:3495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail5.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K59iAADfzU"]
[Sun Aug 30 03:11:55.702739 2026] [security2:error] [pid 521505:tid 521510] [remote 185.93.89.167:54151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "affiliate.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K59iQADmQQ"]
[Sun Aug 30 03:11:55.702768 2026] [security2:error] [pid 521505:tid 521513] [remote 185.93.89.167:30871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pro.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPly28byYE0iXl--K59igADUwc"]
[Sun Aug 30 03:11:55.704204 2026] [security2:error] [pid 521505:tid 521709] [client 20.104.18.15:2038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/images.php"] [unique_id "apPly28byYE0iXl--K59jAAAA2g"]
[Sun Aug 30 03:11:55.706894 2026] [security2:error] [pid 521505:tid 521705] [client 34.15.159.88:50716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/queue/.env"] [unique_id "apPly28byYE0iXl--K59jQAAA2Q"]
[Sun Aug 30 03:11:55.708889 2026] [authz_core:error] [pid 521505:tid 521683] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:11:55.708909 2026] [security2:error] [pid 521505:tid 521680] [client 20.104.50.220:24852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/b00869ae6e.php"] [unique_id "apPly28byYE0iXl--K59jgAAA0s"]
[Sun Aug 30 03:11:55.709187 2026] [authz_core:error] [pid 521505:tid 521683] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:11:55.709415 2026] [security2:error] [pid 524122:tid 524312] [client 4.205.62.107:17289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/public/rip.php.php"] [unique_id "apPly33lhEjKFiK_nBJ6jgAAAco"]
[Sun Aug 30 03:11:55.709696 2026] [security2:error] [pid 524122:tid 524260] [client 20.104.18.15:64765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/wp-activate.php"] [unique_id "apPly33lhEjKFiK_nBJ6jwAAAZY"]
[Sun Aug 30 03:11:55.711702 2026] [security2:error] [pid 521505:tid 521715] [client 20.104.50.220:17231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/ton.php"] [unique_id "apPly28byYE0iXl--K59kAAAA24"]
[Sun Aug 30 03:11:55.711941 2026] [security2:error] [pid 521505:tid 521531] [remote 185.93.89.167:4349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mm.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPly28byYE0iXl--K59kQADnBk"]
[Sun Aug 30 03:11:55.713557 2026] [security2:error] [pid 521505:tid 521755] [client 20.104.50.220:61973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/classgoto24.php"] [unique_id "apPly28byYE0iXl--K59lAAAA5Y"]
[Sun Aug 30 03:11:55.720226 2026] [security2:error] [pid 521505:tid 521693] [client 20.104.50.220:33554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/indeex.php"] [unique_id "apPly28byYE0iXl--K59lgAAA1g"]
[Sun Aug 30 03:11:55.721348 2026] [authz_core:error] [pid 524122:tid 524325] [client 216.73.216.128:46334] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:55.721604 2026] [authz_core:error] [pid 524122:tid 524325] [client 216.73.216.128:46334] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:55.723018 2026] [security2:error] [pid 521505:tid 521514] [remote 185.93.89.167:64215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m1.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPly28byYE0iXl--K59mwADVgg"]
[Sun Aug 30 03:11:55.723423 2026] [security2:error] [pid 521505:tid 521627] [remote 185.93.89.167:42909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direct.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPly28byYE0iXl--K59nAADVXk"]
[Sun Aug 30 03:11:55.723912 2026] [security2:error] [pid 521505:tid 521564] [remote 185.93.89.167:7437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images7.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPly28byYE0iXl--K59nwADSjo"]
[Sun Aug 30 03:11:55.726015 2026] [security2:error] [pid 524122:tid 524274] [client 20.48.251.3:54808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/chosen.php"] [unique_id "apPly33lhEjKFiK_nBJ6kgAAAaQ"]
[Sun Aug 30 03:11:55.727104 2026] [security2:error] [pid 521505:tid 521541] [remote 185.93.89.167:44659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPly28byYE0iXl--K59pQADhiM"]
[Sun Aug 30 03:11:55.727331 2026] [security2:error] [pid 521505:tid 521507] [remote 185.93.89.167:59907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "health.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPly28byYE0iXl--K59pgADbQE"]
[Sun Aug 30 03:11:55.727769 2026] [security2:error] [pid 521505:tid 521682] [client 20.104.18.15:51117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/atomlib.php"] [unique_id "apPly28byYE0iXl--K59pwAAA00"]
[Sun Aug 30 03:11:55.729246 2026] [security2:error] [pid 521505:tid 521555] [remote 185.93.89.167:37521] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal.mariegronley.com"] [uri "/env/.env"] [unique_id "apPly28byYE0iXl--K59qAADjDE"]
[Sun Aug 30 03:11:55.731283 2026] [security2:error] [pid 521505:tid 521728] [client 20.48.251.3:52204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/public/rip.php.php"] [unique_id "apPly28byYE0iXl--K59qgAAA3s"]
[Sun Aug 30 03:11:55.732675 2026] [security2:error] [pid 521505:tid 521549] [remote 185.93.89.167:21227] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "outlook.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPly28byYE0iXl--K59qwADNCs"]
[Sun Aug 30 03:11:55.735880 2026] [security2:error] [pid 521505:tid 521548] [remote 185.93.89.167:36485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shopping.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPly28byYE0iXl--K59rQADMCo"]
[Sun Aug 30 03:11:55.744468 2026] [security2:error] [pid 521505:tid 521538] [remote 185.93.89.167:11851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biblioteca.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K59uAADXCA"]
[Sun Aug 30 03:11:55.752731 2026] [security2:error] [pid 521505:tid 521629] [remote 185.93.89.167:14991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "barracuda.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPly28byYE0iXl--K59wAADYns"]
[Sun Aug 30 03:11:55.752924 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:8597] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "drupal.mariegronley.com"] [uri "/src/.env"] [unique_id "apPly28byYE0iXl--K59vwADeE0"]
[Sun Aug 30 03:11:55.753555 2026] [security2:error] [pid 521505:tid 521570] [remote 185.93.89.167:11225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "da.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K59wgADJkA"]
[Sun Aug 30 03:11:55.754652 2026] [security2:error] [pid 521505:tid 521540] [remote 185.93.89.167:18729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ntp1.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPly28byYE0iXl--K59xAADMSI"]
[Sun Aug 30 03:11:55.757193 2026] [security2:error] [pid 521505:tid 521701] [client 20.48.251.3:55792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/fns.php"] [unique_id "apPly28byYE0iXl--K59xgAAA2A"]
[Sun Aug 30 03:11:55.758155 2026] [security2:error] [pid 521505:tid 521733] [client 158.23.184.117:19646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/domvf.php"] [unique_id "apPly28byYE0iXl--K59ygAAA4A"]
[Sun Aug 30 03:11:55.758192 2026] [security2:error] [pid 521505:tid 521532] [remote 185.93.89.167:6761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "banner.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPly28byYE0iXl--K59yQADmho"]
[Sun Aug 30 03:11:55.758295 2026] [security2:error] [pid 521505:tid 521574] [remote 185.93.89.167:1591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thumbs.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPly28byYE0iXl--K59ywADQkQ"]
[Sun Aug 30 03:11:55.758793 2026] [security2:error] [pid 521505:tid 521587] [remote 185.93.89.167:29329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mars.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K59zgADgVE"]
[Sun Aug 30 03:11:55.759109 2026] [security2:error] [pid 521505:tid 521587] [remote 185.93.89.167:25969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dbadmin.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPly28byYE0iXl--K590AADalE"]
[Sun Aug 30 03:11:55.762903 2026] [security2:error] [pid 521505:tid 521528] [remote 185.93.89.167:41989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ipfixe.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPly28byYE0iXl--K591wADVxY"]
[Sun Aug 30 03:11:55.763439 2026] [security2:error] [pid 521505:tid 521617] [remote 185.93.89.167:3789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vc.mariegronley.com"] [uri "/env/.env"] [unique_id "apPly28byYE0iXl--K592QADOG8"]
[Sun Aug 30 03:11:55.763543 2026] [authz_core:error] [pid 521505:tid 521678] [client 66.249.66.77:37226] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:55.763860 2026] [authz_core:error] [pid 521505:tid 521678] [client 66.249.66.77:37226] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:55.766004 2026] [security2:error] [pid 521505:tid 521628] [remote 185.93.89.167:10145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPly28byYE0iXl--K593AADb3o"]
[Sun Aug 30 03:11:55.770373 2026] [security2:error] [pid 521505:tid 521567] [remote 185.93.89.167:13143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "net.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPly28byYE0iXl--K593gADZD0"]
[Sun Aug 30 03:11:55.773437 2026] [security2:error] [pid 521505:tid 521689] [client 20.48.160.90:37991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp-ws68.php"] [unique_id "apPly28byYE0iXl--K594QAAA1Q"]
[Sun Aug 30 03:11:55.777913 2026] [security2:error] [pid 521505:tid 521702] [client 20.104.49.130:64111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/az.php"] [unique_id "apPly28byYE0iXl--K595AAAA2E"]
[Sun Aug 30 03:11:55.778907 2026] [security2:error] [pid 521505:tid 521573] [remote 185.93.89.167:59215] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "users.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPly28byYE0iXl--K595QADm0M"]
[Sun Aug 30 03:11:55.779993 2026] [security2:error] [pid 521505:tid 521539] [remote 185.93.89.167:14681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mc.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPly28byYE0iXl--K595gADeiE"]
[Sun Aug 30 03:11:55.780384 2026] [security2:error] [pid 521505:tid 521596] [remote 185.93.89.167:45621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images8.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K595wADH1o"]
[Sun Aug 30 03:11:55.780969 2026] [security2:error] [pid 521505:tid 521588] [remote 185.93.89.167:45765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns01.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPly28byYE0iXl--K596AADhFI"]
[Sun Aug 30 03:11:55.781828 2026] [security2:error] [pid 521505:tid 521522] [remote 185.93.89.167:1995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K596gADVhA"]
[Sun Aug 30 03:11:55.783320 2026] [security2:error] [pid 521505:tid 521545] [remote 185.93.89.167:24005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "radius.mariegronley.com"] [uri "/system/.env"] [unique_id "apPly28byYE0iXl--K596wADdyc"]
[Sun Aug 30 03:11:55.787317 2026] [security2:error] [pid 521505:tid 521518] [remote 185.93.89.167:47169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "order.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K597gADWww"]
[Sun Aug 30 03:11:55.787877 2026] [security2:error] [pid 521505:tid 521526] [remote 185.93.89.167:62949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "board.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPly28byYE0iXl--K597wADbRQ"]
[Sun Aug 30 03:11:55.787994 2026] [security2:error] [pid 521505:tid 521714] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "board.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPly28byYE0iXl--K597wADbRQ"]
[Sun Aug 30 03:11:55.790497 2026] [security2:error] [pid 521505:tid 521572] [remote 185.93.89.167:48523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "web01.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K598gADO0I"]
[Sun Aug 30 03:11:55.790951 2026] [security2:error] [pid 521505:tid 521630] [remote 185.93.89.167:64329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digital.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K598wADcHw"]
[Sun Aug 30 03:11:55.791426 2026] [security2:error] [pid 521505:tid 521595] [remote 185.93.89.167:27945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images6.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K599AADTVk"]
[Sun Aug 30 03:11:55.792191 2026] [security2:error] [pid 521505:tid 521598] [remote 185.93.89.167:52789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "market.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPly28byYE0iXl--K599gADQVw"]
[Sun Aug 30 03:11:55.799036 2026] [security2:error] [pid 521505:tid 521605] [remote 185.93.89.167:62709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp3.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K59-gADNmM"]
[Sun Aug 30 03:11:55.805372 2026] [security2:error] [pid 521505:tid 521660] [client 158.23.147.79:40058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPly28byYE0iXl--K59_QAAAzc"]
[Sun Aug 30 03:11:55.811911 2026] [security2:error] [pid 521505:tid 521604] [remote 185.93.89.167:62859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailgw.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPly28byYE0iXl--K59_wADc2I"]
[Sun Aug 30 03:11:55.812618 2026] [security2:error] [pid 521505:tid 521593] [remote 185.93.89.167:14659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/system/.env"] [unique_id "apPly28byYE0iXl--K5-AQADIlc"]
[Sun Aug 30 03:11:55.813269 2026] [security2:error] [pid 521505:tid 521697] [client 20.104.18.15:31710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-admin/w.php"] [unique_id "apPly28byYE0iXl--K5-AgAAA1w"]
[Sun Aug 30 03:11:55.816855 2026] [security2:error] [pid 521505:tid 521626] [remote 185.93.89.167:15177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "forms.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K5-BQADI3g"]
[Sun Aug 30 03:11:55.822455 2026] [security2:error] [pid 521505:tid 521703] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/sparkpost/.env"] [unique_id "apPly28byYE0iXl--K5-DAAAA2I"]
[Sun Aug 30 03:11:55.825881 2026] [security2:error] [pid 521505:tid 521610] [remote 185.93.89.167:9557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "s4.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K5-EQADJmg"]
[Sun Aug 30 03:11:55.826156 2026] [security2:error] [pid 521505:tid 521597] [remote 185.93.89.167:53985] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "img3.mariegronley.com"] [uri "/env/.env"] [unique_id "apPly28byYE0iXl--K5-EAADZls"]
[Sun Aug 30 03:11:55.829418 2026] [security2:error] [pid 521505:tid 521614] [remote 185.93.89.167:62291] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "rs.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPly28byYE0iXl--K5-FgADLmw"]
[Sun Aug 30 03:11:55.834521 2026] [security2:error] [pid 521505:tid 521671] [client 20.104.50.220:62787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/donate.php"] [unique_id "apPly28byYE0iXl--K5-GgAAA0I"]
[Sun Aug 30 03:11:55.835889 2026] [security2:error] [pid 521505:tid 521621] [remote 185.93.89.167:30871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pro.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPly28byYE0iXl--K5-HAADanM"]
[Sun Aug 30 03:11:55.836073 2026] [security2:error] [pid 521505:tid 521551] [remote 185.93.89.167:54151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "affiliate.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K5-GwADgS0"]
[Sun Aug 30 03:11:55.841094 2026] [security2:error] [pid 521505:tid 521616] [remote 185.93.89.167:3495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail5.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K5-IAADcW4"]
[Sun Aug 30 03:11:55.856606 2026] [security2:error] [pid 521505:tid 521569] [remote 185.93.89.167:42909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direct.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPly28byYE0iXl--K5-KwADij8"]
[Sun Aug 30 03:11:55.856867 2026] [security2:error] [pid 521505:tid 521612] [remote 185.93.89.167:7437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images7.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPly28byYE0iXl--K5-LAADbGo"]
[Sun Aug 30 03:11:55.858237 2026] [security2:error] [pid 521505:tid 521552] [remote 185.93.89.167:64795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jp.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPly28byYE0iXl--K5-MAADmy4"]
[Sun Aug 30 03:11:55.858374 2026] [security2:error] [pid 521505:tid 521755] [client 4.205.62.107:52840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/lmfi2.php"] [unique_id "apPly28byYE0iXl--K5-MwAAA5Y"]
[Sun Aug 30 03:11:55.858742 2026] [security2:error] [pid 521505:tid 521584] [remote 185.93.89.167:37843] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jupiter.mariegronley.com"] [uri "/env/.env"] [unique_id "apPly28byYE0iXl--K5-MgADLU4"]
[Sun Aug 30 03:11:55.858746 2026] [security2:error] [pid 521505:tid 521543] [remote 185.93.89.167:10845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "campus.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPly28byYE0iXl--K5-NAADeiU"]
[Sun Aug 30 03:11:55.860427 2026] [security2:error] [pid 521505:tid 521606] [remote 185.93.89.167:59907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "health.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPly28byYE0iXl--K5-NwADhGQ"]
[Sun Aug 30 03:11:55.860546 2026] [security2:error] [pid 521505:tid 521508] [remote 185.93.89.167:44659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "p.mariegronley.com"] [uri "/system/.env"] [unique_id "apPly28byYE0iXl--K5-NgADHwI"]
[Sun Aug 30 03:11:55.860760 2026] [security2:error] [pid 521505:tid 521633] [remote 185.93.89.167:31113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "math.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K5-OAADaH8"]
[Sun Aug 30 03:11:55.862418 2026] [security2:error] [pid 521505:tid 521710] [client 20.104.50.220:31201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/xstelth.php"] [unique_id "apPly28byYE0iXl--K5-OwAAA2k"]
[Sun Aug 30 03:11:55.865506 2026] [security2:error] [pid 521505:tid 521546] [remote 185.93.89.167:21227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "outlook.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPly28byYE0iXl--K5-PQADOyg"]
[Sun Aug 30 03:11:55.871855 2026] [security2:error] [pid 521505:tid 521516] [remote 185.93.89.167:63379] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reviews.mariegronley.com"] [uri "/env/.env"] [unique_id "apPly28byYE0iXl--K5-QAADjAo"]
[Sun Aug 30 03:11:55.875606 2026] [security2:error] [pid 521505:tid 521579] [remote 185.93.89.167:34607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sports.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPly28byYE0iXl--K5-RQADNkk"]
[Sun Aug 30 03:11:55.875928 2026] [security2:error] [pid 521505:tid 521556] [remote 185.93.89.167:12177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tr.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPly28byYE0iXl--K5-QwADNDI"]
[Sun Aug 30 03:11:55.876687 2026] [security2:error] [pid 521505:tid 521575] [remote 185.93.89.167:1175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pgsql.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPly28byYE0iXl--K5-RwADX0U"]
[Sun Aug 30 03:11:55.877421 2026] [security2:error] [pid 521505:tid 521559] [remote 185.93.89.167:11851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biblioteca.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K5-SQADNzU"]
[Sun Aug 30 03:11:55.884723 2026] [security2:error] [pid 521505:tid 521600] [remote 185.93.89.167:15109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "linux.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPly28byYE0iXl--K5-UgADMl4"]
[Sun Aug 30 03:11:55.886399 2026] [security2:error] [pid 521505:tid 521520] [remote 185.93.89.167:14991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "barracuda.mariegronley.com"] [uri "/system/.env"] [unique_id "apPly28byYE0iXl--K5-VAADYg4"]
[Sun Aug 30 03:11:55.886527 2026] [security2:error] [pid 521505:tid 521632] [remote 185.93.89.167:11225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "da.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K5-VwADJn4"]
[Sun Aug 30 03:11:55.887503 2026] [security2:error] [pid 521505:tid 521564] [remote 185.93.89.167:18729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ntp1.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPly28byYE0iXl--K5-WAADWjo"]
[Sun Aug 30 03:11:55.891305 2026] [security2:error] [pid 524122:tid 524296] [client 20.104.18.15:22283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/birrs.php"] [unique_id "apPly33lhEjKFiK_nBJ6nAAAAbo"]
[Sun Aug 30 03:11:55.891424 2026] [security2:error] [pid 521505:tid 521615] [remote 185.93.89.167:1591] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/system/.env"] [unique_id "apPly28byYE0iXl--K5-XAADgG0"]
[Sun Aug 30 03:11:55.892044 2026] [security2:error] [pid 521505:tid 521514] [remote 185.93.89.167:6761] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "banner.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K5-WwADLgg"]
[Sun Aug 30 03:11:55.893214 2026] [security2:error] [pid 521505:tid 521507] [remote 185.93.89.167:37291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "st.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPly28byYE0iXl--K5-YgADQAE"]
[Sun Aug 30 03:11:55.893543 2026] [security2:error] [pid 521505:tid 521541] [remote 185.93.89.167:25969] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dbadmin.mariegronley.com"] [uri "/system/.env"] [unique_id "apPly28byYE0iXl--K5-YAADgSM"]
[Sun Aug 30 03:11:55.895480 2026] [security2:error] [pid 521505:tid 521548] [remote 185.93.89.167:57009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "static2.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K5-ZgADlCo"]
[Sun Aug 30 03:11:55.895489 2026] [security2:error] [pid 521505:tid 521565] [remote 185.93.89.167:59097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "web6.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K5-ZwADdTs"]
[Sun Aug 30 03:11:55.895922 2026] [security2:error] [pid 521505:tid 521512] [remote 185.93.89.167:11075] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "redirect.mariegronley.com"] [uri "/src/.env"] [unique_id "apPly28byYE0iXl--K5-aAADgwY"]
[Sun Aug 30 03:11:55.895927 2026] [security2:error] [pid 521505:tid 521594] [remote 185.93.89.167:41989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ipfixe.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPly28byYE0iXl--K5-aQADklg"]
[Sun Aug 30 03:11:55.896325 2026] [security2:error] [pid 521505:tid 521590] [remote 185.93.89.167:42991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "venus.mariegronley.com"] [uri "/src/.env"] [unique_id "apPly28byYE0iXl--K5-agADMVQ"]
[Sun Aug 30 03:11:55.898872 2026] [security2:error] [pid 521505:tid 521538] [remote 185.93.89.167:10145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPly28byYE0iXl--K5-bwADYCA"]
[Sun Aug 30 03:11:55.899278 2026] [security2:error] [pid 521505:tid 521680] [client 158.23.184.117:20182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/donate.php"] [unique_id "apPly28byYE0iXl--K5-cAAAA0s"]
[Sun Aug 30 03:11:55.903772 2026] [security2:error] [pid 521505:tid 521537] [remote 185.93.89.167:13143] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "net.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K5-cwADdB8"]
[Sun Aug 30 03:11:55.906892 2026] [security2:error] [pid 521505:tid 521629] [remote 185.93.89.167:36741] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "software.mariegronley.com"] [uri "/src/.env"] [unique_id "apPly28byYE0iXl--K5-dgADbHs"]
[Sun Aug 30 03:11:55.907160 2026] [security2:error] [pid 521505:tid 521760] [client 4.205.62.107:25747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/avim.php"] [unique_id "apPly28byYE0iXl--K5-dwAAA5s"]
[Sun Aug 30 03:11:55.907902 2026] [security2:error] [pid 521505:tid 521755] [client 34.15.159.88:50716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/worker/.env"] [unique_id "apPly28byYE0iXl--K5-eAAAA5Y"]
[Sun Aug 30 03:11:55.911445 2026] [security2:error] [pid 521505:tid 521544] [remote 185.93.89.167:55243] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oldmail.mariegronley.com"] [uri "/src/.env"] [unique_id "apPly28byYE0iXl--K5-eQADVCY"]
[Sun Aug 30 03:11:55.913159 2026] [security2:error] [pid 521505:tid 521727] [client 20.48.160.90:37970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/simple.php"] [unique_id "apPly28byYE0iXl--K5-fAAAA3o"]
[Sun Aug 30 03:11:55.913291 2026] [security2:error] [pid 521505:tid 521540] [remote 185.93.89.167:45621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images8.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K5-fQADbiI"]
[Sun Aug 30 03:11:55.913531 2026] [security2:error] [pid 521505:tid 521570] [remote 185.93.89.167:14681] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mc.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K5-ewADLUA"]
[Sun Aug 30 03:11:55.914418 2026] [security2:error] [pid 521505:tid 521690] [client 4.205.62.107:15843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/xp.php"] [unique_id "apPly28byYE0iXl--K5-fwAAA1U"]
[Sun Aug 30 03:11:55.914690 2026] [security2:error] [pid 521505:tid 521566] [remote 185.93.89.167:45765] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "ns01.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K5-fgADYTw"]
[Sun Aug 30 03:11:55.915958 2026] [security2:error] [pid 521505:tid 521532] [remote 185.93.89.167:54367] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webservices.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPly28byYE0iXl--K5-gAADVho"]
[Sun Aug 30 03:11:55.916013 2026] [security2:error] [pid 521505:tid 521574] [remote 185.93.89.167:24005] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "radius.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPly28byYE0iXl--K5-ggADl0Q"]
[Sun Aug 30 03:11:55.917705 2026] [security2:error] [pid 521505:tid 521577] [remote 185.93.89.167:42995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns12.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K5-gwADKkc"]
[Sun Aug 30 03:11:55.920120 2026] [security2:error] [pid 521505:tid 521587] [remote 185.93.89.167:47169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "order.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K5-hQADnVE"]
[Sun Aug 30 03:11:55.920708 2026] [security2:error] [pid 521505:tid 521709] [client 20.104.50.220:6107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/0byte.php"] [unique_id "apPly28byYE0iXl--K5-iAAAA2g"]
[Sun Aug 30 03:11:55.921077 2026] [security2:error] [pid 521505:tid 521581] [remote 185.93.89.167:62949] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "board.mariegronley.com"] [uri "/system/.env"] [unique_id "apPly28byYE0iXl--K5-hgADNUs"]
[Sun Aug 30 03:11:55.921208 2026] [security2:error] [pid 521505:tid 521658] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "board.mariegronley.com"] [uri "/system/.env"] [unique_id "apPly28byYE0iXl--K5-hgADNUs"]
[Sun Aug 30 03:11:55.923491 2026] [security2:error] [pid 521505:tid 521527] [remote 185.93.89.167:48523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "web01.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K5-igADaxU"]
[Sun Aug 30 03:11:55.925590 2026] [security2:error] [pid 521505:tid 521519] [remote 185.93.89.167:52789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "market.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K5-jQADLA0"]
[Sun Aug 30 03:11:55.926661 2026] [security2:error] [pid 521505:tid 521571] [remote 185.93.89.167:40249] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tracking.mariegronley.com"] [uri "/env/.env"] [unique_id "apPly28byYE0iXl--K5-jgADO0E"]
[Sun Aug 30 03:11:55.929090 2026] [security2:error] [pid 521505:tid 521528] [remote 185.93.89.167:57109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "development.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPly28byYE0iXl--K5-kAADUxY"]
[Sun Aug 30 03:11:55.932004 2026] [security2:error] [pid 521505:tid 521511] [remote 185.93.89.167:62709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp3.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K5-kgADQQU"]
[Sun Aug 30 03:11:55.945959 2026] [security2:error] [pid 521505:tid 521523] [remote 185.93.89.167:14659] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "otrs.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPly28byYE0iXl--K5-lwADNBE"]
[Sun Aug 30 03:11:55.956698 2026] [security2:error] [pid 521505:tid 521591] [remote 185.93.89.167:15177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "forms.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K5-nAADOlU"]
[Sun Aug 30 03:11:55.957560 2026] [security2:error] [pid 521505:tid 521573] [remote 185.93.89.167:11687] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pr.mariegronley.com"] [uri "/source/.env"] [unique_id "apPly28byYE0iXl--K5-nQADKEM"]
[Sun Aug 30 03:11:55.958717 2026] [security2:error] [pid 521505:tid 521539] [remote 185.93.89.167:53363] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "work.mariegronley.com"] [uri "/env/.env"] [unique_id "apPly28byYE0iXl--K5-ngADYiE"]
[Sun Aug 30 03:11:55.958816 2026] [security2:error] [pid 521505:tid 521596] [remote 185.93.89.167:37133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kb.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K5-nwADMFo"]
[Sun Aug 30 03:11:55.959772 2026] [core:alert] [pid 521505:tid 521695] [client 119.10.175.30:48372] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:11:55.968234 2026] [security2:error] [pid 521505:tid 521529] [remote 185.93.89.167:26309] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "piwik.mariegronley.com"] [uri "/web/.env"] [unique_id "apPly28byYE0iXl--K5-pgADgBc"]
[Sun Aug 30 03:11:55.981557 2026] [security2:error] [pid 521505:tid 521638] [client 20.104.49.130:43297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/v2.php"] [unique_id "apPly28byYE0iXl--K5-rgAAAyE"]
[Sun Aug 30 03:11:55.982037 2026] [security2:error] [pid 521505:tid 521666] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/postmark/.env"] [unique_id "apPly28byYE0iXl--K5-rQAAAz0"]
[Sun Aug 30 03:11:55.982343 2026] [security2:error] [pid 524122:tid 524368] [client 20.48.251.3:36827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/groceries/index.php"] [unique_id "apPly33lhEjKFiK_nBJ6ogAAAgI"]
[Sun Aug 30 03:11:55.991530 2026] [security2:error] [pid 521505:tid 521595] [remote 185.93.89.167:53853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atlas.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K5-tAADY1k"]
[Sun Aug 30 03:11:55.991560 2026] [security2:error] [pid 521505:tid 521572] [remote 185.93.89.167:13069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sc.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K5-tQADcUI"]
[Sun Aug 30 03:11:55.991638 2026] [security2:error] [pid 521505:tid 521576] [remote 185.93.89.167:2579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "love.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K5-twADYEY"]
[Sun Aug 30 03:11:55.992110 2026] [security2:error] [pid 521505:tid 521530] [remote 185.93.89.167:64215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/web/.env"] [unique_id "apPly28byYE0iXl--K5-tgADVxg"]
[Sun Aug 30 03:11:55.992362 2026] [security2:error] [pid 521505:tid 521630] [remote 185.93.89.167:64795] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "jp.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K5-swADmnw"]
[Sun Aug 30 03:11:55.992531 2026] [security2:error] [pid 521505:tid 521560] [remote 185.93.89.167:10845] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "campus.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPly28byYE0iXl--K5-uQADOTY"]
[Sun Aug 30 03:11:55.992706 2026] [security2:error] [pid 521505:tid 521601] [remote 185.93.89.167:4287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "php.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K5-vAADS18"]
[Sun Aug 30 03:11:55.992727 2026] [security2:error] [pid 521505:tid 521582] [remote 185.93.89.167:14833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "se.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPly28byYE0iXl--K5-vQADmUw"]
[Sun Aug 30 03:11:55.993407 2026] [security2:error] [pid 521505:tid 521593] [remote 185.93.89.167:44659] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "p.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPly28byYE0iXl--K5-vwADiFc"]
[Sun Aug 30 03:11:55.993742 2026] [security2:error] [pid 521505:tid 521589] [remote 185.93.89.167:31113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "math.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPly28byYE0iXl--K5-wAADdFM"]
[Sun Aug 30 03:11:55.993836 2026] [security2:error] [pid 521505:tid 521626] [remote 185.93.89.167:29333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reg.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPly28byYE0iXl--K5-wQADZHg"]
[Sun Aug 30 03:11:55.996741 2026] [security2:error] [pid 521505:tid 521521] [remote 185.93.89.167:37521] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal.mariegronley.com"] [uri "/src/.env"] [unique_id "apPly28byYE0iXl--K5-wgADbA8"]
[Sun Aug 30 03:11:55.998796 2026] [security2:error] [pid 521505:tid 521602] [remote 185.93.89.167:21227] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "outlook.mariegronley.com"] [uri "/system/.env"] [unique_id "apPly28byYE0iXl--K5-xAADRWA"]
[Sun Aug 30 03:11:56.003247 2026] [security2:error] [pid 521505:tid 521608] [remote 185.93.89.167:36485] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "shopping.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzG8byYE0iXl--K5-xgADPGY"]
[Sun Aug 30 03:11:56.004540 2026] [security2:error] [pid 521505:tid 521603] [remote 185.93.89.167:34357] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banners.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K5-xwADb2E"]
[Sun Aug 30 03:11:56.007566 2026] [security2:error] [pid 521505:tid 521609] [remote 185.93.89.167:56175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "press.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzG8byYE0iXl--K5-ywADbmc"]
[Sun Aug 30 03:11:56.008578 2026] [security2:error] [pid 521505:tid 521597] [remote 185.93.89.167:34607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sports.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K5-zAADSFs"]
[Sun Aug 30 03:11:56.009805 2026] [security2:error] [pid 521505:tid 521607] [remote 185.93.89.167:1175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pgsql.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K5-zgADXWU"]
[Sun Aug 30 03:11:56.014274 2026] [security2:error] [pid 521505:tid 521551] [remote 185.93.89.167:39177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "register.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzG8byYE0iXl--K5-0wADKy0"]
[Sun Aug 30 03:11:56.016285 2026] [authz_core:error] [pid 521505:tid 521737] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory29
[Sun Aug 30 03:11:56.016439 2026] [security2:error] [pid 521505:tid 521616] [remote 185.93.89.167:5225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preprod.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzG8byYE0iXl--K5-1AADWG4"]
[Sun Aug 30 03:11:56.016634 2026] [authz_core:error] [pid 521505:tid 521737] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory29
[Sun Aug 30 03:11:56.018270 2026] [security2:error] [pid 521505:tid 521613] [remote 185.93.89.167:15109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "linux.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlzG8byYE0iXl--K5-1QADSms"]
[Sun Aug 30 03:11:56.018779 2026] [security2:error] [pid 521505:tid 521569] [remote 185.93.89.167:61033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "analytics.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlzG8byYE0iXl--K5-1gADfz8"]
[Sun Aug 30 03:11:56.019240 2026] [security2:error] [pid 521505:tid 521552] [remote 185.93.89.167:14991] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "barracuda.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlzG8byYE0iXl--K5-2AADay4"]
[Sun Aug 30 03:11:56.020584 2026] [security2:error] [pid 521505:tid 521624] [remote 185.93.89.167:8597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drupal.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K5-2gADiXY"]
[Sun Aug 30 03:11:56.022941 2026] [security2:error] [pid 521505:tid 521625] [remote 185.93.89.167:16669] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "links.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K5-3AADbXc"]
[Sun Aug 30 03:11:56.024085 2026] [security2:error] [pid 521505:tid 521584] [remote 185.93.89.167:1591] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thumbs.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlzG8byYE0iXl--K5-3gADO04"]
[Sun Aug 30 03:11:56.025018 2026] [security2:error] [pid 521505:tid 521622] [remote 185.93.89.167:56429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mb.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlzG8byYE0iXl--K5-4AADU3Q"]
[Sun Aug 30 03:11:56.026822 2026] [security2:error] [pid 521505:tid 521606] [remote 185.93.89.167:37291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "st.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlzG8byYE0iXl--K5-4gADQWQ"]
[Sun Aug 30 03:11:56.027319 2026] [security2:error] [pid 521505:tid 521508] [remote 185.93.89.167:7863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adserver.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzG8byYE0iXl--K5-4wADZwI"]
[Sun Aug 30 03:11:56.027355 2026] [security2:error] [pid 521505:tid 521546] [remote 185.93.89.167:25969] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "dbadmin.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlzG8byYE0iXl--K5-5wADaSg"]
[Sun Aug 30 03:11:56.027638 2026] [security2:error] [pid 521505:tid 521633] [remote 185.93.89.167:23169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www7.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlzG8byYE0iXl--K5-5QADjH8"]
[Sun Aug 30 03:11:56.027838 2026] [security2:error] [pid 521505:tid 521553] [remote 185.93.89.167:24307] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tw.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K5-5gADey8"]
[Sun Aug 30 03:11:56.027997 2026] [security2:error] [pid 521505:tid 521515] [remote 185.93.89.167:9731] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images5.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K5-5AADnAk"]
[Sun Aug 30 03:11:56.028442 2026] [security2:error] [pid 521505:tid 521524] [remote 185.93.89.167:57009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "static2.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzG8byYE0iXl--K5-6AADNhI"]
[Sun Aug 30 03:11:56.028494 2026] [security2:error] [pid 521505:tid 521533] [remote 185.93.89.167:59097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "web6.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzG8byYE0iXl--K5-6QADNBs"]
[Sun Aug 30 03:11:56.031763 2026] [security2:error] [pid 521505:tid 521575] [remote 185.93.89.167:3789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vc.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K5-7gADXEU"]
[Sun Aug 30 03:11:56.031855 2026] [security2:error] [pid 521505:tid 521556] [remote 185.93.89.167:53553] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "demo2.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlzG8byYE0iXl--K5-7QADTjI"]
[Sun Aug 30 03:11:56.033969 2026] [security2:error] [pid 521505:tid 521510] [remote 185.93.89.167:32655] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lync.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K5-8AADKAQ"]
[Sun Aug 30 03:11:56.041144 2026] [security2:error] [pid 521505:tid 521520] [remote 185.93.89.167:50005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fax.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K5-9gADgA4"]
[Sun Aug 30 03:11:56.041401 2026] [security2:error] [pid 521505:tid 521743] [client 158.23.184.117:19722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/dropdown.php"] [unique_id "apPlzG8byYE0iXl--K5--AAAA4o"]
[Sun Aug 30 03:11:56.048980 2026] [security2:error] [pid 521505:tid 521734] [client 20.48.160.90:61531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/aaa.php"] [unique_id "apPlzG8byYE0iXl--K5-_wAAA4E"]
[Sun Aug 30 03:11:56.049626 2026] [security2:error] [pid 521505:tid 521615] [remote 185.93.89.167:54367] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webservices.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlzG8byYE0iXl--K5_AAADZm0"]
[Sun Aug 30 03:11:56.050867 2026] [security2:error] [pid 521505:tid 521578] [remote 185.93.89.167:42995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns12.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzG8byYE0iXl--K5_AgADUEg"]
[Sun Aug 30 03:11:56.053592 2026] [security2:error] [pid 521505:tid 521541] [remote 185.93.89.167:62949] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "board.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlzG8byYE0iXl--K5_BQADdiM"]
[Sun Aug 30 03:11:56.053725 2026] [security2:error] [pid 521505:tid 521723] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "board.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlzG8byYE0iXl--K5_BQADdiM"]
[Sun Aug 30 03:11:56.053861 2026] [security2:error] [pid 524122:tid 524379] [client 20.104.50.220:42255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/index8.php"] [unique_id "apPlzH3lhEjKFiK_nBJ6qAAAAg0"]
[Sun Aug 30 03:11:56.057063 2026] [security2:error] [pid 521505:tid 521549] [remote 185.93.89.167:24213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "in.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzG8byYE0iXl--K5_CQADdSs"]
[Sun Aug 30 03:11:56.061216 2026] [security2:error] [pid 521505:tid 521512] [remote 185.93.89.167:16627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "education.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzG8byYE0iXl--K5_DwADmQY"]
[Sun Aug 30 03:11:56.062142 2026] [security2:error] [pid 521505:tid 521535] [remote 185.93.89.167:57109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "development.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K5_EAADkB0"]
[Sun Aug 30 03:11:56.064427 2026] [security2:error] [pid 521505:tid 521590] [remote 185.93.89.167:14453] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K5_EQADXlQ"]
[Sun Aug 30 03:11:56.069456 2026] [security2:error] [pid 521505:tid 521561] [remote 185.93.89.167:39923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sitebuilder.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlzG8byYE0iXl--K5_FQADbDc"]
[Sun Aug 30 03:11:56.074171 2026] [security2:error] [pid 521505:tid 521716] [client 68.155.159.216:52237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apPlzG8byYE0iXl--K5_GgAAA28"]
[Sun Aug 30 03:11:56.076762 2026] [authz_core:error] [pid 521505:tid 521731] [client 66.249.66.35:38069] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:56.077189 2026] [authz_core:error] [pid 521505:tid 521731] [client 66.249.66.35:38069] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:56.079484 2026] [security2:error] [pid 521505:tid 521534] [remote 185.93.89.167:62859] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mailgw.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzG8byYE0iXl--K5_HAADYRw"]
[Sun Aug 30 03:11:56.082835 2026] [security2:error] [pid 521505:tid 521537] [remote 185.93.89.167:49893] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mdm.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K5_IAADXR8"]
[Sun Aug 30 03:11:56.088223 2026] [security2:error] [pid 521505:tid 521629] [remote 185.93.89.167:60123] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "up.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K5_IgADK3s"]
[Sun Aug 30 03:11:56.089938 2026] [security2:error] [pid 521505:tid 521580] [remote 185.93.89.167:63579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "wifi.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K5_IwADm0o"]
[Sun Aug 30 03:11:56.091755 2026] [security2:error] [pid 521505:tid 521570] [remote 185.93.89.167:37133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kb.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzG8byYE0iXl--K5_KAADaEA"]
[Sun Aug 30 03:11:56.094907 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:53985] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "img3.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K5_KQADSk0"]
[Sun Aug 30 03:11:56.101078 2026] [security2:error] [pid 521505:tid 521574] [remote 185.93.89.167:26309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piwik.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzG8byYE0iXl--K5_LwADQUQ"]
[Sun Aug 30 03:11:56.104043 2026] [security2:error] [pid 521505:tid 521558] [remote 185.93.89.167:30871] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pro.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzG8byYE0iXl--K5_MgADcDQ"]
[Sun Aug 30 03:11:56.108824 2026] [security2:error] [pid 521505:tid 521659] [client 34.15.159.88:50716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/job/.env"] [unique_id "apPlzG8byYE0iXl--K5_NQAAAzY"]
[Sun Aug 30 03:11:56.118923 2026] [security2:error] [pid 521505:tid 521683] [client 20.197.61.180:12236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/upgrade/about.php"] [unique_id "apPlzG8byYE0iXl--K5_OAAAA04"]
[Sun Aug 30 03:11:56.123217 2026] [security2:error] [pid 524122:tid 524361] [client 20.104.18.15:18395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/v22.php"] [unique_id "apPlzH3lhEjKFiK_nBJ6rwAAAfs"]
[Sun Aug 30 03:11:56.124234 2026] [security2:error] [pid 521505:tid 521568] [remote 185.93.89.167:7437] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images7.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzG8byYE0iXl--K5_QAADgD4"]
[Sun Aug 30 03:11:56.124473 2026] [security2:error] [pid 521505:tid 521509] [remote 185.93.89.167:53853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atlas.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzG8byYE0iXl--K5_QgADQgM"]
[Sun Aug 30 03:11:56.124576 2026] [security2:error] [pid 521505:tid 521620] [remote 185.93.89.167:42909] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "direct.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzG8byYE0iXl--K5_QQADinI"]
[Sun Aug 30 03:11:56.124751 2026] [security2:error] [pid 521505:tid 521568] [remote 185.93.89.167:2579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "love.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzG8byYE0iXl--K5_RAADJD4"]
[Sun Aug 30 03:11:56.125101 2026] [security2:error] [pid 521505:tid 521519] [remote 185.93.89.167:13069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sc.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzG8byYE0iXl--K5_QwADLg0"]
[Sun Aug 30 03:11:56.125189 2026] [security2:error] [pid 521505:tid 521568] [remote 185.93.89.167:64215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m1.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzG8byYE0iXl--K5_RQADMj4"]
[Sun Aug 30 03:11:56.125910 2026] [security2:error] [pid 521505:tid 521617] [remote 185.93.89.167:4287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "php.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzG8byYE0iXl--K5_SgADRm8"]
[Sun Aug 30 03:11:56.126746 2026] [security2:error] [pid 521505:tid 521511] [remote 185.93.89.167:37843] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jupiter.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K5_SAADLgU"]
[Sun Aug 30 03:11:56.126942 2026] [security2:error] [pid 521505:tid 521628] [remote 185.93.89.167:14833] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "se.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlzG8byYE0iXl--K5_SQADIXo"]
[Sun Aug 30 03:11:56.127451 2026] [security2:error] [pid 521505:tid 521567] [remote 185.93.89.167:29333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reg.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzG8byYE0iXl--K5_UAADaj0"]
[Sun Aug 30 03:11:56.129152 2026] [security2:error] [pid 521505:tid 521550] [remote 185.93.89.167:59907] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "health.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzG8byYE0iXl--K5_UQADICw"]
[Sun Aug 30 03:11:56.131421 2026] [security2:error] [pid 521505:tid 521591] [remote 185.93.89.167:21227] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "outlook.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlzG8byYE0iXl--K5_VQADcVU"]
[Sun Aug 30 03:11:56.131612 2026] [security2:error] [pid 521505:tid 521639] [client 20.151.200.44:45040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlzG8byYE0iXl--K5_VAAAAyI"]
[Sun Aug 30 03:11:56.132790 2026] [security2:error] [pid 521505:tid 521573] [remote 185.93.89.167:4349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mm.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzG8byYE0iXl--K5_VgADdUM"]
[Sun Aug 30 03:11:56.136297 2026] [security2:error] [pid 521505:tid 521539] [remote 185.93.89.167:36485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shopping.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzG8byYE0iXl--K5_VwADYCE"]
[Sun Aug 30 03:11:56.139628 2026] [security2:error] [pid 521505:tid 521588] [remote 185.93.89.167:63379] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reviews.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K5_XAADmVI"]
[Sun Aug 30 03:11:56.140301 2026] [security2:error] [pid 521505:tid 521522] [remote 185.93.89.167:56175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "press.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzG8byYE0iXl--K5_XgADPBA"]
[Sun Aug 30 03:11:56.140339 2026] [security2:error] [pid 524122:tid 524358] [client 20.104.49.130:64101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/js.php"] [unique_id "apPlzH3lhEjKFiK_nBJ6swAAAfg"]
[Sun Aug 30 03:11:56.147413 2026] [security2:error] [pid 521505:tid 521526] [remote 185.93.89.167:39177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "register.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzG8byYE0iXl--K5_ZQADdBQ"]
[Sun Aug 30 03:11:56.149569 2026] [security2:error] [pid 521505:tid 521557] [remote 185.93.89.167:5225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preprod.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzG8byYE0iXl--K5_ZgADlzM"]
[Sun Aug 30 03:11:56.150191 2026] [security2:error] [pid 521505:tid 521705] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/mailgun/.env"] [unique_id "apPlzG8byYE0iXl--K5_ZwAAA2Q"]
[Sun Aug 30 03:11:56.152606 2026] [security2:error] [pid 521505:tid 521595] [remote 185.93.89.167:61033] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlzG8byYE0iXl--K5_agADKlk"]
[Sun Aug 30 03:11:56.153594 2026] [security2:error] [pid 521505:tid 521576] [remote 185.93.89.167:8597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drupal.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K5_bAADm0Y"]
[Sun Aug 30 03:11:56.155009 2026] [security2:error] [pid 521505:tid 521630] [remote 185.93.89.167:18729] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ntp1.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzG8byYE0iXl--K5_bwADlnw"]
[Sun Aug 30 03:11:56.155329 2026] [security2:error] [pid 521505:tid 521560] [remote 185.93.89.167:28567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "user.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlzG8byYE0iXl--K5_cQADiTY"]
[Sun Aug 30 03:11:56.158546 2026] [security2:error] [pid 521505:tid 521563] [remote 185.93.89.167:56429] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mb.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlzG8byYE0iXl--K5_dQADcDk"]
[Sun Aug 30 03:11:56.159755 2026] [security2:error] [pid 521505:tid 521605] [remote 185.93.89.167:6761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "banner.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzG8byYE0iXl--K5_dwADTWM"]
[Sun Aug 30 03:11:56.160216 2026] [security2:error] [pid 521505:tid 521589] [remote 185.93.89.167:7863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adserver.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzG8byYE0iXl--K5_egADZ1M"]
[Sun Aug 30 03:11:56.160929 2026] [security2:error] [pid 521505:tid 521626] [remote 185.93.89.167:29329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mars.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K5_ewADNXg"]
[Sun Aug 30 03:11:56.161601 2026] [security2:error] [pid 521505:tid 521604] [remote 185.93.89.167:23169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlzG8byYE0iXl--K5_fAADjGI"]
[Sun Aug 30 03:11:56.161728 2026] [authz_core:error] [pid 521505:tid 521679] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fman-db
[Sun Aug 30 03:11:56.162090 2026] [authz_core:error] [pid 521505:tid 521679] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fman-db
[Sun Aug 30 03:11:56.163520 2026] [security2:error] [pid 521505:tid 521609] [remote 185.93.89.167:41989] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ipfixe.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzG8byYE0iXl--K5_gwADgGc"]
[Sun Aug 30 03:11:56.163789 2026] [security2:error] [pid 521505:tid 521597] [remote 185.93.89.167:11075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redirect.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K5_hAADQls"]
[Sun Aug 30 03:11:56.164261 2026] [security2:error] [pid 521505:tid 521607] [remote 185.93.89.167:42991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "venus.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K5_hQADimU"]
[Sun Aug 30 03:11:56.166138 2026] [security2:error] [pid 521505:tid 521551] [remote 185.93.89.167:10145] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "g.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzG8byYE0iXl--K5_iAADRi0"]
[Sun Aug 30 03:11:56.169410 2026] [security2:error] [pid 521505:tid 521613] [remote 185.93.89.167:22281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "labs.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlzG8byYE0iXl--K5_jAADams"]
[Sun Aug 30 03:11:56.171323 2026] [security2:error] [pid 521505:tid 521552] [remote 185.93.89.167:13143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "net.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzG8byYE0iXl--K5_kAADIC4"]
[Sun Aug 30 03:11:56.171541 2026] [security2:error] [pid 521505:tid 521703] [client 20.151.200.44:26565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/bge.php"] [unique_id "apPlzG8byYE0iXl--K5_kQAAA2I"]
[Sun Aug 30 03:11:56.174044 2026] [security2:error] [pid 521505:tid 521624] [remote 185.93.89.167:36741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "software.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K5_lAADInY"]
[Sun Aug 30 03:11:56.176391 2026] [authz_core:error] [pid 521505:tid 521734] [client 66.249.66.64:44972] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:56.176711 2026] [authz_core:error] [pid 521505:tid 521734] [client 66.249.66.64:44972] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:56.177742 2026] [security2:error] [pid 521505:tid 521749] [client 20.104.50.220:29358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/alfi.php"] [unique_id "apPlzG8byYE0iXl--K5_lwAAA5A"]
[Sun Aug 30 03:11:56.179035 2026] [security2:error] [pid 521505:tid 521618] [remote 185.93.89.167:55243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldmail.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K5_mAADg3A"]
[Sun Aug 30 03:11:56.180270 2026] [security2:error] [pid 521505:tid 521611] [remote 185.93.89.167:14681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mc.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzG8byYE0iXl--K5_mgADmmk"]
[Sun Aug 30 03:11:56.181975 2026] [security2:error] [pid 524122:tid 524290] [client 158.23.184.117:19733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/edit.php"] [unique_id "apPlzH3lhEjKFiK_nBJ6twAAAbQ"]
[Sun Aug 30 03:11:56.182333 2026] [security2:error] [pid 521505:tid 521622] [remote 185.93.89.167:45765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns01.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzG8byYE0iXl--K5_ngADbHQ"]
[Sun Aug 30 03:11:56.182625 2026] [security2:error] [pid 521505:tid 521619] [remote 185.93.89.167:54367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webservices.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlzG8byYE0iXl--K5_nwADmXE"]
[Sun Aug 30 03:11:56.187439 2026] [security2:error] [pid 521505:tid 521623] [remote 185.93.89.167:1995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lp.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K5_pQADPXU"]
[Sun Aug 30 03:11:56.188506 2026] [security2:error] [pid 521505:tid 521662] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "board.mariegronley.com"] [uri "/index.cgi"] [unique_id "apPlzG8byYE0iXl--K5_owADOQI"]
[Sun Aug 30 03:11:56.190094 2026] [security2:error] [pid 521505:tid 521633] [remote 185.93.89.167:24213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "in.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzG8byYE0iXl--K5_pgADMX8"]
[Sun Aug 30 03:11:56.192344 2026] [security2:error] [pid 521505:tid 521515] [remote 185.93.89.167:64329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K5_qQADfAk"]
[Sun Aug 30 03:11:56.192565 2026] [security2:error] [pid 521505:tid 521524] [remote 185.93.89.167:52789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "market.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzG8byYE0iXl--K5_qgADhhI"]
[Sun Aug 30 03:11:56.193110 2026] [security2:error] [pid 521505:tid 521533] [remote 185.93.89.167:27945] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K5_qwADbhs"]
[Sun Aug 30 03:11:56.193863 2026] [security2:error] [pid 521505:tid 521516] [remote 185.93.89.167:40249] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tracking.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K5_rAADVQo"]
[Sun Aug 30 03:11:56.194177 2026] [security2:error] [pid 521505:tid 521631] [remote 185.93.89.167:16627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "education.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzG8byYE0iXl--K5_rQADVn0"]
[Sun Aug 30 03:11:56.203372 2026] [security2:error] [pid 521505:tid 521559] [remote 185.93.89.167:39923] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "sitebuilder.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlzG8byYE0iXl--K5_sgADmzU"]
[Sun Aug 30 03:11:56.205554 2026] [security2:error] [pid 521505:tid 521510] [remote 185.93.89.167:48785] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns02.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlzG8byYE0iXl--K5_swADKwQ"]
[Sun Aug 30 03:11:56.211389 2026] [security2:error] [pid 524122:tid 524309] [client 20.151.200.44:46044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/blnux.php"] [unique_id "apPlzH3lhEjKFiK_nBJ6ugAAAcc"]
[Sun Aug 30 03:11:56.212409 2026] [security2:error] [pid 521505:tid 521513] [remote 185.93.89.167:62859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mailgw.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzG8byYE0iXl--K5_tQADiQc"]
[Sun Aug 30 03:11:56.225902 2026] [security2:error] [pid 521505:tid 521564] [remote 185.93.89.167:11687] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pr.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlzG8byYE0iXl--K5_vAADkzo"]
[Sun Aug 30 03:11:56.226351 2026] [security2:error] [pid 521505:tid 521627] [remote 185.93.89.167:53363] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "work.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K5_vQADNnk"]
[Sun Aug 30 03:11:56.230081 2026] [security2:error] [pid 521505:tid 521615] [remote 185.93.89.167:9557] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "s4.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K5_vwADOG0"]
[Sun Aug 30 03:11:56.237119 2026] [security2:error] [pid 521505:tid 521542] [remote 185.93.89.167:30871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pro.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzG8byYE0iXl--K5_xAADXCQ"]
[Sun Aug 30 03:11:56.238796 2026] [security2:error] [pid 521505:tid 521541] [remote 185.93.89.167:54151] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "affiliate.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K5_xQADUSM"]
[Sun Aug 30 03:11:56.257301 2026] [security2:error] [pid 521505:tid 521549] [remote 185.93.89.167:7437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images7.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzG8byYE0iXl--K5_zwADXys"]
[Sun Aug 30 03:11:56.257867 2026] [security2:error] [pid 521505:tid 521506] [remote 185.93.89.167:42909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "direct.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzG8byYE0iXl--K5_0QADfwA"]
[Sun Aug 30 03:11:56.260369 2026] [security2:error] [pid 521505:tid 521594] [remote 185.93.89.167:64795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jp.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzG8byYE0iXl--K5_2AADWVg"]
[Sun Aug 30 03:11:56.260869 2026] [security2:error] [pid 521505:tid 521538] [remote 185.93.89.167:10845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "campus.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzG8byYE0iXl--K5_2wADkCA"]
[Sun Aug 30 03:11:56.261702 2026] [security2:error] [pid 521505:tid 521535] [remote 185.93.89.167:3495] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K5_3AADex0"]
[Sun Aug 30 03:11:56.262275 2026] [security2:error] [pid 521505:tid 521629] [remote 185.93.89.167:59907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "health.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzG8byYE0iXl--K5_3wADbHs"]
[Sun Aug 30 03:11:56.264535 2026] [security2:error] [pid 521505:tid 521570] [remote 185.93.89.167:37521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K5_4QADV0A"]
[Sun Aug 30 03:11:56.272231 2026] [security2:error] [pid 521505:tid 521540] [remote 185.93.89.167:4349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mm.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzG8byYE0iXl--K5_5gADeCI"]
[Sun Aug 30 03:11:56.272895 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:34357] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banners.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K5_5wADME0"]
[Sun Aug 30 03:11:56.277015 2026] [security2:error] [pid 521505:tid 521574] [remote 185.93.89.167:34607] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sports.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzG8byYE0iXl--K5_6gADYUQ"]
[Sun Aug 30 03:11:56.278487 2026] [security2:error] [pid 521505:tid 521577] [remote 185.93.89.167:1175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pgsql.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzG8byYE0iXl--K5_7AADMUc"]
[Sun Aug 30 03:11:56.279781 2026] [security2:error] [pid 521505:tid 521587] [remote 185.93.89.167:11851] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "biblioteca.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K5_7gADfFE"]
[Sun Aug 30 03:11:56.286108 2026] [security2:error] [pid 521505:tid 521620] [remote 185.93.89.167:15109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "linux.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzG8byYE0iXl--K5_9gADl3I"]
[Sun Aug 30 03:11:56.288081 2026] [security2:error] [pid 521505:tid 521617] [remote 185.93.89.167:18729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ntp1.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzG8byYE0iXl--K5_-gADXW8"]
[Sun Aug 30 03:11:56.289252 2026] [security2:error] [pid 521505:tid 521628] [remote 185.93.89.167:11225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "da.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K5__AADm3o"]
[Sun Aug 30 03:11:56.289495 2026] [security2:error] [pid 521505:tid 521511] [remote 185.93.89.167:28567] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "user.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlzG8byYE0iXl--K5_-wADKgU"]
[Sun Aug 30 03:11:56.290896 2026] [security2:error] [pid 521505:tid 521528] [remote 185.93.89.167:16669] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "links.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K5__QADlhY"]
[Sun Aug 30 03:11:56.294549 2026] [security2:error] [pid 521505:tid 521591] [remote 185.93.89.167:37291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "st.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzG8byYE0iXl--K6ABQADa1U"]
[Sun Aug 30 03:11:56.296281 2026] [security2:error] [pid 521505:tid 521573] [remote 185.93.89.167:24307] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tw.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6ACAADk0M"]
[Sun Aug 30 03:11:56.296350 2026] [security2:error] [pid 521505:tid 521588] [remote 185.93.89.167:41989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ipfixe.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzG8byYE0iXl--K6ACwADKFI"]
[Sun Aug 30 03:11:56.296381 2026] [security2:error] [pid 521505:tid 521539] [remote 185.93.89.167:9731] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images5.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6ACQADZyE"]
[Sun Aug 30 03:11:56.297081 2026] [security2:error] [pid 521505:tid 521529] [remote 185.93.89.167:11075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redirect.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6ADQADnRc"]
[Sun Aug 30 03:11:56.297473 2026] [security2:error] [pid 521505:tid 521586] [remote 185.93.89.167:42991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "venus.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6ADwADTlA"]
[Sun Aug 30 03:11:56.299024 2026] [security2:error] [pid 521505:tid 521518] [remote 185.93.89.167:10145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzG8byYE0iXl--K6AEAADkgw"]
[Sun Aug 30 03:11:56.299170 2026] [security2:error] [pid 521505:tid 521526] [remote 185.93.89.167:3789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vc.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6AEQADSBQ"]
[Sun Aug 30 03:11:56.299911 2026] [security2:error] [pid 521505:tid 521557] [remote 185.93.89.167:53553] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "demo2.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlzG8byYE0iXl--K6AEgADJDM"]
[Sun Aug 30 03:11:56.300784 2026] [security2:error] [pid 521505:tid 521595] [remote 185.93.89.167:32655] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lync.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6AEwADilk"]
[Sun Aug 30 03:11:56.303697 2026] [security2:error] [pid 521505:tid 521598] [remote 185.93.89.167:22281] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "labs.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlzG8byYE0iXl--K6AFAADQFw"]
[Sun Aug 30 03:11:56.307211 2026] [security2:error] [pid 521505:tid 521576] [remote 185.93.89.167:36741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "software.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6AFgADRkY"]
[Sun Aug 30 03:11:56.309742 2026] [security2:error] [pid 521505:tid 521630] [remote 185.93.89.167:50005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fax.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6AFwADUHw"]
[Sun Aug 30 03:11:56.310765 2026] [security2:error] [pid 521505:tid 521700] [client 34.15.159.88:50716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/test/.env"] [unique_id "apPlzG8byYE0iXl--K6AGQAAA18"]
[Sun Aug 30 03:11:56.310881 2026] [security2:error] [pid 521505:tid 521720] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/mandrill/.env"] [unique_id "apPlzG8byYE0iXl--K6AGAAAA3M"]
[Sun Aug 30 03:11:56.312455 2026] [security2:error] [pid 521505:tid 521560] [remote 185.93.89.167:55243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldmail.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6AGgADOjY"]
[Sun Aug 30 03:11:56.315826 2026] [security2:error] [pid 521505:tid 521582] [remote 185.93.89.167:54367] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webservices.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlzG8byYE0iXl--K6AHgADNEw"]
[Sun Aug 30 03:11:56.316094 2026] [security2:error] [pid 521505:tid 521563] [remote 185.93.89.167:59215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "users.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlzG8byYE0iXl--K6AHwADYDk"]
[Sun Aug 30 03:11:56.316506 2026] [security2:error] [pid 521505:tid 521605] [remote 185.93.89.167:45621] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images8.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K6AIAADIGM"]
[Sun Aug 30 03:11:56.321437 2026] [security2:error] [pid 521505:tid 521593] [remote 185.93.89.167:47169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "order.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K6AJAADZVc"]
[Sun Aug 30 03:11:56.321871 2026] [security2:error] [pid 521505:tid 521662] [client 158.23.184.117:19628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/ee.php"] [unique_id "apPlzG8byYE0iXl--K6AJwAAAzk"]
[Sun Aug 30 03:11:56.323183 2026] [security2:error] [pid 521505:tid 521749] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "board.mariegronley.com"] [uri "/index.cgi"] [unique_id "apPlzG8byYE0iXl--K6AJQADkGI"]
[Sun Aug 30 03:11:56.325751 2026] [security2:error] [pid 521505:tid 521610] [remote 185.93.89.167:48523] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K6ALAADmmg"]
[Sun Aug 30 03:11:56.328883 2026] [authz_core:error] [pid 521505:tid 521728] [client 66.249.66.33:57568] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:56.329114 2026] [authz_core:error] [pid 521505:tid 521728] [client 66.249.66.33:57568] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:56.330498 2026] [security2:error] [pid 521505:tid 521614] [remote 185.93.89.167:57109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "development.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzG8byYE0iXl--K6AMQADh2w"]
[Sun Aug 30 03:11:56.332904 2026] [security2:error] [pid 521505:tid 521551] [remote 185.93.89.167:14453] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6AMwADPC0"]
[Sun Aug 30 03:11:56.333891 2026] [security2:error] [pid 521505:tid 521621] [remote 185.93.89.167:62709] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp3.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K6ANAADeHM"]
[Sun Aug 30 03:11:56.344742 2026] [authz_core:error] [pid 521505:tid 521666] [client 66.249.66.36:40942] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:56.345024 2026] [authz_core:error] [pid 521505:tid 521666] [client 66.249.66.36:40942] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:56.350286 2026] [security2:error] [pid 521505:tid 521612] [remote 185.93.89.167:49893] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mdm.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6APgADVWo"]
[Sun Aug 30 03:11:56.357250 2026] [security2:error] [pid 521505:tid 521581] [remote 185.93.89.167:60123] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "up.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6AQgADLUs"]
[Sun Aug 30 03:11:56.358668 2026] [security2:error] [pid 521505:tid 521618] [remote 185.93.89.167:63579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "wifi.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6AQwADm3A"]
[Sun Aug 30 03:11:56.359447 2026] [security2:error] [pid 521505:tid 521622] [remote 185.93.89.167:11687] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pr.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlzG8byYE0iXl--K6ARQADlnQ"]
[Sun Aug 30 03:11:56.359749 2026] [authz_core:error] [pid 521505:tid 521699] [client 216.73.216.128:23116] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:56.360153 2026] [authz_core:error] [pid 521505:tid 521699] [client 216.73.216.128:23116] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:56.362705 2026] [security2:error] [pid 521505:tid 521584] [remote 185.93.89.167:53985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "img3.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6ARwADiU4"]
[Sun Aug 30 03:11:56.368759 2026] [security2:error] [pid 521505:tid 521688] [client 20.104.49.130:52156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/red.php"] [unique_id "apPlzG8byYE0iXl--K6ATQAAA1M"]
[Sun Aug 30 03:11:56.377717 2026] [security2:error] [pid 521505:tid 521633] [remote 185.93.89.167:15177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K6AUQADZn8"]
[Sun Aug 30 03:11:56.381875 2026] [security2:error] [pid 521505:tid 521684] [client 20.104.49.130:52417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/t.php"] [unique_id "apPlzG8byYE0iXl--K6AUwAAA08"]
[Sun Aug 30 03:11:56.390704 2026] [security2:error] [pid 521505:tid 521515] [remote 185.93.89.167:62291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rs.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlzG8byYE0iXl--K6AVQADKAk"]
[Sun Aug 30 03:11:56.393859 2026] [security2:error] [pid 521505:tid 521556] [remote 185.93.89.167:37843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jupiter.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6AXAADkjI"]
[Sun Aug 30 03:11:56.394555 2026] [security2:error] [pid 521505:tid 521513] [remote 185.93.89.167:14833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "se.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzG8byYE0iXl--K6AYAADQAc"]
[Sun Aug 30 03:11:56.396899 2026] [security2:error] [pid 521505:tid 521632] [remote 185.93.89.167:31113] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "math.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K6AZAADan4"]
[Sun Aug 30 03:11:56.397552 2026] [security2:error] [pid 521505:tid 521562] [remote 185.93.89.167:37521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6AZwADWDg"]
[Sun Aug 30 03:11:56.407140 2026] [security2:error] [pid 521505:tid 521542] [remote 185.93.89.167:63379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviews.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6AcAADOSQ"]
[Sun Aug 30 03:11:56.410155 2026] [security2:error] [pid 521505:tid 521578] [remote 185.93.89.167:34607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sports.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzG8byYE0iXl--K6AcgADbEg"]
[Sun Aug 30 03:11:56.411445 2026] [security2:error] [pid 521505:tid 521541] [remote 185.93.89.167:1175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pgsql.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzG8byYE0iXl--K6AdAADWiM"]
[Sun Aug 30 03:11:56.411588 2026] [security2:error] [pid 521505:tid 521759] [client 20.104.49.130:53584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/users.php"] [unique_id "apPlzG8byYE0iXl--K6AdQAAA5o"]
[Sun Aug 30 03:11:56.419362 2026] [security2:error] [pid 521505:tid 521737] [client 158.23.147.79:39948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apPlzG8byYE0iXl--K6AfwAAA4Q"]
[Sun Aug 30 03:11:56.419913 2026] [security2:error] [pid 521505:tid 521565] [remote 185.93.89.167:61033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "analytics.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzG8byYE0iXl--K6AgQADejs"]
[Sun Aug 30 03:11:56.421593 2026] [security2:error] [pid 521505:tid 521534] [remote 185.93.89.167:8597] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "drupal.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzG8byYE0iXl--K6AgwADhhw"]
[Sun Aug 30 03:11:56.425735 2026] [security2:error] [pid 521505:tid 521629] [remote 185.93.89.167:56429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mb.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzG8byYE0iXl--K6AiwADQXs"]
[Sun Aug 30 03:11:56.428942 2026] [security2:error] [pid 521505:tid 521580] [remote 185.93.89.167:29329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mars.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6AkAADU0o"]
[Sun Aug 30 03:11:56.429457 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:23169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www7.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzG8byYE0iXl--K6AlAADbU0"]
[Sun Aug 30 03:11:56.431500 2026] [security2:error] [pid 521505:tid 521558] [remote 185.93.89.167:59097] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web6.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K6AmwADaDQ"]
[Sun Aug 30 03:11:56.431550 2026] [security2:error] [pid 521505:tid 521577] [remote 185.93.89.167:57009] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "static2.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K6AmgADaUc"]
[Sun Aug 30 03:11:56.432445 2026] [security2:error] [pid 521505:tid 521527] [remote 185.93.89.167:3789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vc.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6AnQADcRU"]
[Sun Aug 30 03:11:56.433585 2026] [security2:error] [pid 521505:tid 521519] [remote 185.93.89.167:53553] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "demo2.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlzG8byYE0iXl--K6AoAADjA0"]
[Sun Aug 30 03:11:56.448570 2026] [security2:error] [pid 521505:tid 521567] [remote 185.93.89.167:54367] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "webservices.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlzG8byYE0iXl--K6ArAADdz0"]
[Sun Aug 30 03:11:56.449871 2026] [security2:error] [pid 521505:tid 521568] [remote 185.93.89.167:59215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "users.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlzG8byYE0iXl--K6ArQADRj4"]
[Sun Aug 30 03:11:56.452757 2026] [security2:error] [pid 521505:tid 521554] [remote 185.93.89.167:42995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns12.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K6AsQADOjA"]
[Sun Aug 30 03:11:56.452901 2026] [security2:error] [pid 521505:tid 521550] [remote 185.93.89.167:24005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radius.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlzG8byYE0iXl--K6AsgADdiw"]
[Sun Aug 30 03:11:56.457183 2026] [security2:error] [pid 521505:tid 521706] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "board.mariegronley.com"] [uri "/index.cgi"] [unique_id "apPlzG8byYE0iXl--K6AtwADZR4"]
[Sun Aug 30 03:11:56.457950 2026] [security2:error] [pid 521505:tid 521588] [remote 185.93.89.167:1995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lp.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6AuQADWlI"]
[Sun Aug 30 03:11:56.460339 2026] [security2:error] [pid 521505:tid 521586] [remote 185.93.89.167:64329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6AvAADV1A"]
[Sun Aug 30 03:11:56.460838 2026] [security2:error] [pid 521505:tid 521545] [remote 185.93.89.167:40249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracking.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6AvwADhyc"]
[Sun Aug 30 03:11:56.461150 2026] [security2:error] [pid 521505:tid 521596] [remote 185.93.89.167:27945] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6AvgADg1o"]
[Sun Aug 30 03:11:56.462216 2026] [security2:error] [pid 524122:tid 524310] [client 158.23.184.117:19640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/elp.php"] [unique_id "apPlzH3lhEjKFiK_nBJ6xAAAAcg"]
[Sun Aug 30 03:11:56.462261 2026] [authz_core:error] [pid 521505:tid 521662] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory32
[Sun Aug 30 03:11:56.462513 2026] [authz_core:error] [pid 521505:tid 521662] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory32
[Sun Aug 30 03:11:56.463669 2026] [security2:error] [pid 521505:tid 521526] [remote 185.93.89.167:57109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "development.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzG8byYE0iXl--K6AwQADIBQ"]
[Sun Aug 30 03:11:56.471749 2026] [security2:error] [pid 521505:tid 521598] [remote 185.93.89.167:39923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sitebuilder.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzG8byYE0iXl--K6AxQADelw"]
[Sun Aug 30 03:11:56.474022 2026] [security2:error] [pid 521505:tid 521572] [remote 185.93.89.167:48785] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns02.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlzG8byYE0iXl--K6AxwADfEI"]
[Sun Aug 30 03:11:56.474022 2026] [security2:error] [pid 521505:tid 521653] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/mailjet/.env"] [unique_id "apPlzG8byYE0iXl--K6AxgAAAzA"]
[Sun Aug 30 03:11:56.480098 2026] [security2:error] [pid 521505:tid 521739] [client 20.48.160.90:61499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/shiny.php"] [unique_id "apPlzG8byYE0iXl--K6AyQAAA4Y"]
[Sun Aug 30 03:11:56.482502 2026] [security2:error] [pid 521505:tid 521630] [remote 185.93.89.167:14659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "otrs.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlzG8byYE0iXl--K6AygADZHw"]
[Sun Aug 30 03:11:56.488341 2026] [security2:error] [pid 524122:tid 524256] [client 68.67.112.174:53021] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mediacoalition.org"] [uri "/robots.txt"] [unique_id "apPlzH3lhEjKFiK_nBJ6xQAAAZI"]
[Sun Aug 30 03:11:56.492308 2026] [security2:error] [pid 521505:tid 521563] [remote 185.93.89.167:11687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pr.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlzG8byYE0iXl--K6AzgADVDk"]
[Sun Aug 30 03:11:56.493415 2026] [security2:error] [pid 521505:tid 521605] [remote 185.93.89.167:37133] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K6A0AADKmM"]
[Sun Aug 30 03:11:56.493786 2026] [security2:error] [pid 521505:tid 521601] [remote 185.93.89.167:53363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "work.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6A0QADQV8"]
[Sun Aug 30 03:11:56.496062 2026] [security2:error] [pid 521505:tid 521608] [remote 185.93.89.167:53985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "img3.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6A0gADK2Y"]
[Sun Aug 30 03:11:56.498551 2026] [security2:error] [pid 521505:tid 521589] [remote 185.93.89.167:9557] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "s4.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6A0wADTVM"]
[Sun Aug 30 03:11:56.507015 2026] [security2:error] [pid 521505:tid 521521] [remote 185.93.89.167:54151] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "affiliate.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6A1gADZg8"]
[Sun Aug 30 03:11:56.513114 2026] [security2:error] [pid 521505:tid 521654] [client 34.15.159.88:50716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/qa/.env"] [unique_id "apPlzG8byYE0iXl--K6A2AAAAzE"]
[Sun Aug 30 03:11:56.526468 2026] [security2:error] [pid 521505:tid 521603] [remote 185.93.89.167:53853] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atlas.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K6A3gADcWE"]
[Sun Aug 30 03:11:56.526931 2026] [security2:error] [pid 521505:tid 521609] [remote 185.93.89.167:37843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jupiter.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6A3wADVmc"]
[Sun Aug 30 03:11:56.527510 2026] [security2:error] [pid 521505:tid 521597] [remote 185.93.89.167:13069] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sc.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K6A4AADNVs"]
[Sun Aug 30 03:11:56.527720 2026] [security2:error] [pid 521505:tid 521607] [remote 185.93.89.167:2579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "love.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K6A4QADQmU"]
[Sun Aug 30 03:11:56.530402 2026] [security2:error] [pid 521505:tid 521612] [remote 185.93.89.167:29333] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reg.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K6A6wADQGo"]
[Sun Aug 30 03:11:56.530578 2026] [security2:error] [pid 521505:tid 521552] [remote 185.93.89.167:62291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "rs.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlzG8byYE0iXl--K6A6QADnS4"]
[Sun Aug 30 03:11:56.530751 2026] [security2:error] [pid 521505:tid 521618] [remote 185.93.89.167:44659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlzG8byYE0iXl--K6A7gADanA"]
[Sun Aug 30 03:11:56.530793 2026] [security2:error] [pid 521505:tid 521613] [remote 185.93.89.167:4287] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "php.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K6A6AADXGs"]
[Sun Aug 30 03:11:56.540255 2026] [security2:error] [pid 521505:tid 521619] [remote 185.93.89.167:63379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviews.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6A8wADSHE"]
[Sun Aug 30 03:11:56.540665 2026] [security2:error] [pid 521505:tid 521584] [remote 185.93.89.167:34357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "banners.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6A9AADd04"]
[Sun Aug 30 03:11:56.541347 2026] [security2:error] [pid 521505:tid 521625] [remote 185.93.89.167:56175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "press.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K6A9QADk3c"]
[Sun Aug 30 03:11:56.541437 2026] [security2:error] [pid 521505:tid 521543] [remote 185.93.89.167:3495] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6A9gADNCU"]
[Sun Aug 30 03:11:56.542163 2026] [security2:error] [pid 521505:tid 521636] [client 20.104.49.130:64077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/x1da.php"] [unique_id "apPlzG8byYE0iXl--K6A-AAAAx8"]
[Sun Aug 30 03:11:56.547080 2026] [security2:error] [pid 521505:tid 521633] [remote 185.93.89.167:12177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tr.mariegronley.com"] [uri "/source/.env"] [unique_id "apPlzG8byYE0iXl--K6A_QADT38"]
[Sun Aug 30 03:11:56.547409 2026] [security2:error] [pid 521505:tid 521515] [remote 185.93.89.167:11851] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "biblioteca.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6A_gADYAk"]
[Sun Aug 30 03:11:56.549859 2026] [security2:error] [pid 521505:tid 521553] [remote 185.93.89.167:39177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "register.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K6A_wADOi8"]
[Sun Aug 30 03:11:56.554053 2026] [security2:error] [pid 521505:tid 521516] [remote 185.93.89.167:5225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "preprod.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K6BBAADYQo"]
[Sun Aug 30 03:11:56.554723 2026] [security2:error] [pid 521505:tid 521631] [remote 185.93.89.167:8597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drupal.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzG8byYE0iXl--K6BBQADdX0"]
[Sun Aug 30 03:11:56.557115 2026] [security2:error] [pid 521505:tid 521575] [remote 185.93.89.167:14991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "barracuda.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlzG8byYE0iXl--K6BCQADh0U"]
[Sun Aug 30 03:11:56.557174 2026] [security2:error] [pid 521505:tid 521559] [remote 185.93.89.167:28567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "user.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzG8byYE0iXl--K6BCgADgzU"]
[Sun Aug 30 03:11:56.557451 2026] [security2:error] [pid 521505:tid 521513] [remote 185.93.89.167:11225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "da.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6BCAADhQc"]
[Sun Aug 30 03:11:56.558349 2026] [security2:error] [pid 521505:tid 521510] [remote 185.93.89.167:16669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "links.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6BCwADmQQ"]
[Sun Aug 30 03:11:56.560726 2026] [security2:error] [pid 521505:tid 521531] [remote 185.93.89.167:1591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thumbs.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlzG8byYE0iXl--K6BDQADWxk"]
[Sun Aug 30 03:11:56.561745 2026] [security2:error] [pid 521505:tid 521520] [remote 185.93.89.167:6761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "banner.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzG8byYE0iXl--K6BDwADgQ4"]
[Sun Aug 30 03:11:56.562251 2026] [security2:error] [pid 521505:tid 521600] [remote 185.93.89.167:7863] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adserver.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K6BDgADf14"]
[Sun Aug 30 03:11:56.563859 2026] [security2:error] [pid 521505:tid 521562] [remote 185.93.89.167:9731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images5.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6BFQADejg"]
[Sun Aug 30 03:11:56.564176 2026] [security2:error] [pid 521505:tid 521615] [remote 185.93.89.167:24307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tw.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6BFgADb20"]
[Sun Aug 30 03:11:56.565116 2026] [security2:error] [pid 521505:tid 521541] [remote 185.93.89.167:11075] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "redirect.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzG8byYE0iXl--K6BGQADiCM"]
[Sun Aug 30 03:11:56.565624 2026] [security2:error] [pid 521505:tid 521549] [remote 185.93.89.167:42991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "venus.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzG8byYE0iXl--K6BGgADZCs"]
[Sun Aug 30 03:11:56.566683 2026] [security2:error] [pid 521505:tid 521506] [remote 185.93.89.167:53553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "demo2.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlzG8byYE0iXl--K6BHAADmwA"]
[Sun Aug 30 03:11:56.568079 2026] [security2:error] [pid 521505:tid 521517] [remote 185.93.89.167:32655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lync.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6BHgADHgs"]
[Sun Aug 30 03:11:56.569101 2026] [security2:error] [pid 521505:tid 521555] [remote 185.93.89.167:25969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dbadmin.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlzG8byYE0iXl--K6BIAADQTE"]
[Sun Aug 30 03:11:56.571341 2026] [security2:error] [pid 521505:tid 521590] [remote 185.93.89.167:22281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "labs.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzG8byYE0iXl--K6BIgADTVQ"]
[Sun Aug 30 03:11:56.574167 2026] [security2:error] [pid 521505:tid 521534] [remote 185.93.89.167:13143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "net.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzG8byYE0iXl--K6BJgADiRw"]
[Sun Aug 30 03:11:56.575293 2026] [security2:error] [pid 521505:tid 521594] [remote 185.93.89.167:36741] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "software.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzG8byYE0iXl--K6BJwADbVg"]
[Sun Aug 30 03:11:56.577552 2026] [security2:error] [pid 521505:tid 521538] [remote 185.93.89.167:50005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fax.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6BKwADiyA"]
[Sun Aug 30 03:11:56.581115 2026] [security2:error] [pid 521505:tid 521512] [remote 185.93.89.167:55243] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oldmail.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzG8byYE0iXl--K6BLgADcQY"]
[Sun Aug 30 03:11:56.581494 2026] [security2:error] [pid 521505:tid 521535] [remote 185.93.89.167:14681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mc.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzG8byYE0iXl--K6BMAADJR0"]
[Sun Aug 30 03:11:56.584400 2026] [security2:error] [pid 521505:tid 521561] [remote 185.93.89.167:45621] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images8.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6BMgADNTc"]
[Sun Aug 30 03:11:56.584512 2026] [security2:error] [pid 521505:tid 521570] [remote 185.93.89.167:45765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns01.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzG8byYE0iXl--K6BMwADQkA"]
[Sun Aug 30 03:11:56.586984 2026] [security2:error] [pid 521505:tid 521580] [remote 185.93.89.167:24005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "radius.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlzG8byYE0iXl--K6BNQADkko"]
[Sun Aug 30 03:11:56.588632 2026] [security2:error] [pid 521505:tid 521566] [remote 185.93.89.167:47169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "order.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6BNwADnTw"]
[Sun Aug 30 03:11:56.589826 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:62949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "board.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlzG8byYE0iXl--K6BOQADlk0"]
[Sun Aug 30 03:11:56.589942 2026] [security2:error] [pid 521505:tid 521755] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "board.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlzG8byYE0iXl--K6BOQADlk0"]
[Sun Aug 30 03:11:56.592410 2026] [security2:error] [pid 521505:tid 521544] [remote 185.93.89.167:24213] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "in.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K6BPQADSCY"]
[Sun Aug 30 03:11:56.593797 2026] [security2:error] [pid 521505:tid 521532] [remote 185.93.89.167:52789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "market.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzG8byYE0iXl--K6BQQADUBo"]
[Sun Aug 30 03:11:56.593869 2026] [security2:error] [pid 521505:tid 521577] [remote 185.93.89.167:40249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracking.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6BQAADH0c"]
[Sun Aug 30 03:11:56.593919 2026] [security2:error] [pid 521505:tid 521558] [remote 185.93.89.167:48523] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6BPwADNDQ"]
[Sun Aug 30 03:11:56.595768 2026] [security2:error] [pid 521505:tid 521527] [remote 185.93.89.167:16627] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "education.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K6BQwADlxU"]
[Sun Aug 30 03:11:56.601075 2026] [security2:error] [pid 521505:tid 521571] [remote 185.93.89.167:62709] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp3.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6BRQADOkE"]
[Sun Aug 30 03:11:56.601155 2026] [security2:error] [pid 521505:tid 521509] [remote 185.93.89.167:14453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mobil.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6BRgADJAM"]
[Sun Aug 30 03:11:56.604495 2026] [security2:error] [pid 521505:tid 521639] [client 158.23.184.117:19727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/en.php"] [unique_id "apPlzG8byYE0iXl--K6BSAAAAyI"]
[Sun Aug 30 03:11:56.607159 2026] [security2:error] [pid 521505:tid 521617] [remote 185.93.89.167:48785] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns02.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlzG8byYE0iXl--K6BSgADmm8"]
[Sun Aug 30 03:11:56.616047 2026] [security2:error] [pid 521505:tid 521525] [remote 185.93.89.167:14659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlzG8byYE0iXl--K6BTgADdhM"]
[Sun Aug 30 03:11:56.617335 2026] [security2:error] [pid 521505:tid 521713] [client 20.48.160.90:37648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/goods.php"] [unique_id "apPlzG8byYE0iXl--K6BUAAAA2w"]
[Sun Aug 30 03:11:56.618005 2026] [security2:error] [pid 521505:tid 521628] [remote 185.93.89.167:49893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdm.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6BUQADV3o"]
[Sun Aug 30 03:11:56.625576 2026] [security2:error] [pid 521505:tid 521511] [remote 185.93.89.167:11687] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pr.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlzG8byYE0iXl--K6BVAADhQU"]
[Sun Aug 30 03:11:56.625869 2026] [security2:error] [pid 521505:tid 521567] [remote 185.93.89.167:60123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "up.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6BVQADmT0"]
[Sun Aug 30 03:11:56.626035 2026] [security2:error] [pid 521505:tid 521528] [remote 185.93.89.167:63579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wifi.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6BVgADIBY"]
[Sun Aug 30 03:11:56.626586 2026] [security2:error] [pid 521505:tid 521523] [remote 185.93.89.167:53363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "work.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6BWAADfxE"]
[Sun Aug 30 03:11:56.636000 2026] [security2:error] [pid 521505:tid 521698] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/brevo/.env"] [unique_id "apPlzG8byYE0iXl--K6BXgAAA10"]
[Sun Aug 30 03:11:56.658229 2026] [security2:error] [pid 521505:tid 521536] [remote 185.93.89.167:15177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6BYwADQR4"]
[Sun Aug 30 03:11:56.662459 2026] [security2:error] [pid 521505:tid 521596] [remote 185.93.89.167:64795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jp.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzG8byYE0iXl--K6BbAADaVo"]
[Sun Aug 30 03:11:56.663860 2026] [authz_core:error] [pid 521505:tid 521760] [client 66.249.66.69:36056] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:56.664171 2026] [authz_core:error] [pid 521505:tid 521760] [client 66.249.66.69:36056] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:56.664272 2026] [security2:error] [pid 521505:tid 521598] [remote 185.93.89.167:10845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "campus.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzG8byYE0iXl--K6BcwADclw"]
[Sun Aug 30 03:11:56.664793 2026] [security2:error] [pid 521505:tid 521557] [remote 185.93.89.167:44659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "p.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlzG8byYE0iXl--K6BcAADjDM"]
[Sun Aug 30 03:11:56.665192 2026] [security2:error] [pid 521505:tid 521572] [remote 185.93.89.167:31113] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "math.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6BdAADcUI"]
[Sun Aug 30 03:11:56.665522 2026] [security2:error] [pid 521505:tid 521576] [remote 185.93.89.167:37521] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "internal.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzG8byYE0iXl--K6BdgADckY"]
[Sun Aug 30 03:11:56.666561 2026] [security2:error] [pid 521505:tid 521560] [remote 185.93.89.167:21227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "outlook.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlzG8byYE0iXl--K6BdwADVjY"]
[Sun Aug 30 03:11:56.672893 2026] [authz_core:error] [pid 521505:tid 521715] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_CA
[Sun Aug 30 03:11:56.673322 2026] [authz_core:error] [pid 521505:tid 521715] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_CA
[Sun Aug 30 03:11:56.673575 2026] [security2:error] [pid 521505:tid 521582] [remote 185.93.89.167:34357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "banners.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6BgAADY0w"]
[Sun Aug 30 03:11:56.688392 2026] [security2:error] [pid 521505:tid 521609] [remote 185.93.89.167:15109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "linux.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzG8byYE0iXl--K6BkwADTmc"]
[Sun Aug 30 03:11:56.691279 2026] [security2:error] [pid 521505:tid 521551] [remote 185.93.89.167:16669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "links.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6BmAADmS0"]
[Sun Aug 30 03:11:56.691410 2026] [security2:error] [pid 521505:tid 521621] [remote 185.93.89.167:14991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "barracuda.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlzG8byYE0iXl--K6BlQADdXM"]
[Sun Aug 30 03:11:56.694137 2026] [security2:error] [pid 521505:tid 521612] [remote 185.93.89.167:4349] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mm.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzG8byYE0iXl--K6BmwADgWo"]
[Sun Aug 30 03:11:56.694418 2026] [security2:error] [pid 521505:tid 521614] [remote 185.93.89.167:1591] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlzG8byYE0iXl--K6BmgADf2w"]
[Sun Aug 30 03:11:56.694838 2026] [security2:error] [pid 521505:tid 521552] [remote 185.93.89.167:6761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "banner.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzG8byYE0iXl--K6BnQADhC4"]
[Sun Aug 30 03:11:56.696314 2026] [security2:error] [pid 521505:tid 521613] [remote 185.93.89.167:37291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "st.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzG8byYE0iXl--K6BnwADXms"]
[Sun Aug 30 03:11:56.696395 2026] [security2:error] [pid 521505:tid 521616] [remote 185.93.89.167:29329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mars.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6BoAADSW4"]
[Sun Aug 30 03:11:56.697022 2026] [security2:error] [pid 521505:tid 521624] [remote 185.93.89.167:9731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images5.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6BowADXnY"]
[Sun Aug 30 03:11:56.697044 2026] [security2:error] [pid 521505:tid 521581] [remote 185.93.89.167:24307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tw.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6BpAADiEs"]
[Sun Aug 30 03:11:56.698093 2026] [security2:error] [pid 521505:tid 521619] [remote 185.93.89.167:11075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "redirect.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzG8byYE0iXl--K6BpwADPHE"]
[Sun Aug 30 03:11:56.698595 2026] [security2:error] [pid 521505:tid 521584] [remote 185.93.89.167:42991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "venus.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzG8byYE0iXl--K6BqQADSk4"]
[Sun Aug 30 03:11:56.698826 2026] [security2:error] [pid 521505:tid 521611] [remote 185.93.89.167:57009] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "static2.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6BqAADg2k"]
[Sun Aug 30 03:11:56.699631 2026] [security2:error] [pid 521505:tid 521625] [remote 185.93.89.167:59097] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web6.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6BqgADfHc"]
[Sun Aug 30 03:11:56.700093 2026] [security2:error] [pid 521505:tid 521543] [remote 185.93.89.167:53553] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "demo2.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlzG8byYE0iXl--K6BqwADgiU"]
[Sun Aug 30 03:11:56.700765 2026] [security2:error] [pid 521505:tid 521546] [remote 185.93.89.167:3789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "vc.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzG8byYE0iXl--K6BrAADhig"]
[Sun Aug 30 03:11:56.700919 2026] [security2:error] [pid 521505:tid 521623] [remote 185.93.89.167:32655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lync.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6BrQADQXU"]
[Sun Aug 30 03:11:56.703810 2026] [security2:error] [pid 521505:tid 521553] [remote 185.93.89.167:25969] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "dbadmin.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlzG8byYE0iXl--K6BsAADSy8"]
[Sun Aug 30 03:11:56.707132 2026] [security2:error] [pid 521505:tid 521533] [remote 185.93.89.167:13143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "net.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzG8byYE0iXl--K6BswADMRs"]
[Sun Aug 30 03:11:56.708186 2026] [security2:error] [pid 521505:tid 521631] [remote 185.93.89.167:36741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "software.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzG8byYE0iXl--K6BtQADi30"]
[Sun Aug 30 03:11:56.710529 2026] [security2:error] [pid 521505:tid 521524] [remote 185.93.89.167:50005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fax.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6BtgADjBI"]
[Sun Aug 30 03:11:56.711189 2026] [security2:error] [pid 521505:tid 521718] [client 20.104.49.130:64105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/1xmomo.php"] [unique_id "apPlzG8byYE0iXl--K6BtwAAA3E"]
[Sun Aug 30 03:11:56.714215 2026] [security2:error] [pid 521505:tid 521556] [remote 185.93.89.167:55243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oldmail.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzG8byYE0iXl--K6BuwADVjI"]
[Sun Aug 30 03:11:56.714312 2026] [security2:error] [pid 521505:tid 521606] [remote 185.93.89.167:14681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mc.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzG8byYE0iXl--K6BvAADkmQ"]
[Sun Aug 30 03:11:56.714537 2026] [security2:error] [pid 521505:tid 521706] [client 34.15.159.88:50716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/preview/.env"] [unique_id "apPlzG8byYE0iXl--K6BuQAAA2U"]
[Sun Aug 30 03:11:56.716850 2026] [security2:error] [pid 521505:tid 521575] [remote 185.93.89.167:59215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "users.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzG8byYE0iXl--K6BvgADO0U"]
[Sun Aug 30 03:11:56.717783 2026] [security2:error] [pid 521505:tid 521513] [remote 185.93.89.167:45765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns01.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzG8byYE0iXl--K6BwwADkAc"]
[Sun Aug 30 03:11:56.720503 2026] [security2:error] [pid 521505:tid 521632] [remote 185.93.89.167:42995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns12.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6BxQADan4"]
[Sun Aug 30 03:11:56.723356 2026] [security2:error] [pid 521505:tid 521520] [remote 185.93.89.167:62949] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "board.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlzG8byYE0iXl--K6BxwADmA4"]
[Sun Aug 30 03:11:56.723479 2026] [security2:error] [pid 521505:tid 521757] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "board.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlzG8byYE0iXl--K6BxwADmA4"]
[Sun Aug 30 03:11:56.726527 2026] [security2:error] [pid 521505:tid 521564] [remote 185.93.89.167:52789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "market.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzG8byYE0iXl--K6BywADkzo"]
[Sun Aug 30 03:11:56.727243 2026] [security2:error] [pid 521505:tid 521562] [remote 185.93.89.167:64329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digital.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6BzgADITg"]
[Sun Aug 30 03:11:56.727568 2026] [security2:error] [pid 521505:tid 521615] [remote 185.93.89.167:1995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6BzwADNG0"]
[Sun Aug 30 03:11:56.727918 2026] [security2:error] [pid 521505:tid 521541] [remote 185.93.89.167:27945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images6.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6B0AADaCM"]
[Sun Aug 30 03:11:56.734374 2026] [security2:error] [pid 521505:tid 521578] [remote 185.93.89.167:14453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mobil.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6B2AADT0g"]
[Sun Aug 30 03:11:56.739944 2026] [security2:error] [pid 521505:tid 521507] [remote 185.93.89.167:48785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns02.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlzG8byYE0iXl--K6B2wADOgE"]
[Sun Aug 30 03:11:56.744162 2026] [security2:error] [pid 521505:tid 521694] [client 158.23.184.117:19725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.watertownchessclub.com"] [uri "/error.php"] [unique_id "apPlzG8byYE0iXl--K6B3wAAA1k"]
[Sun Aug 30 03:11:56.750781 2026] [security2:error] [pid 521505:tid 521555] [remote 185.93.89.167:49893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdm.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6B4wADVTE"]
[Sun Aug 30 03:11:56.750817 2026] [security2:error] [pid 521505:tid 521738] [client 20.48.160.90:37748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/000.php/index.php"] [unique_id "apPlzG8byYE0iXl--K6B4gAAA4U"]
[Sun Aug 30 03:11:56.758247 2026] [security2:error] [pid 521505:tid 521565] [remote 185.93.89.167:11687] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "pr.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlzG8byYE0iXl--K6B5QADmTs"]
[Sun Aug 30 03:11:56.759089 2026] [security2:error] [pid 521505:tid 521590] [remote 185.93.89.167:60123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "up.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6B5gADdVQ"]
[Sun Aug 30 03:11:56.759143 2026] [security2:error] [pid 521505:tid 521534] [remote 185.93.89.167:63579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wifi.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6B5wADmhw"]
[Sun Aug 30 03:11:56.759962 2026] [security2:error] [pid 524122:tid 524138] [remote 103.156.21.26:44718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.21.156.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cravegoldcoast.com.au"] [uri "/wp-login.php"] [unique_id "apPlzH3lhEjKFiK_nBJ60QAB0A4"]
[Sun Aug 30 03:11:56.761074 2026] [security2:error] [pid 521505:tid 521538] [remote 185.93.89.167:37133] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6B6QADbCA"]
[Sun Aug 30 03:11:56.764490 2026] [security2:error] [pid 521505:tid 521512] [remote 185.93.89.167:53985] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "img3.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzG8byYE0iXl--K6B6gADgQY"]
[Sun Aug 30 03:11:56.766481 2026] [security2:error] [pid 521505:tid 521535] [remote 185.93.89.167:9557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "s4.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6B7AADhB0"]
[Sun Aug 30 03:11:56.774749 2026] [security2:error] [pid 521505:tid 521548] [remote 185.93.89.167:54151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "affiliate.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6B8gADbyo"]
[Sun Aug 30 03:11:56.783111 2026] [security2:error] [pid 521505:tid 521756] [client 20.104.49.130:51391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/dk.php"] [unique_id "apPlzG8byYE0iXl--K6B8wAAA5c"]
[Sun Aug 30 03:11:56.795183 2026] [security2:error] [pid 521505:tid 521561] [remote 185.93.89.167:37843] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jupiter.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzG8byYE0iXl--K6B9wADSzc"]
[Sun Aug 30 03:11:56.795252 2026] [security2:error] [pid 521505:tid 521629] [remote 185.93.89.167:53853] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atlas.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6B9gADhns"]
[Sun Aug 30 03:11:56.795482 2026] [security2:error] [pid 521505:tid 521540] [remote 185.93.89.167:64795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jp.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzG8byYE0iXl--K6B-wADJSI"]
[Sun Aug 30 03:11:56.795589 2026] [security2:error] [pid 521505:tid 521654] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/transactional/.env"] [unique_id "apPlzG8byYE0iXl--K6B-AAAAzE"]
[Sun Aug 30 03:11:56.795748 2026] [security2:error] [pid 521505:tid 521580] [remote 185.93.89.167:13069] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sc.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6B-gADi0o"]
[Sun Aug 30 03:11:56.795748 2026] [security2:error] [pid 521505:tid 521570] [remote 185.93.89.167:2579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "love.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6B-QADiUA"]
[Sun Aug 30 03:11:56.797325 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:10845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "campus.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzG8byYE0iXl--K6B_gADh00"]
[Sun Aug 30 03:11:56.797416 2026] [security2:error] [pid 521505:tid 521544] [remote 185.93.89.167:14833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "se.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzG8byYE0iXl--K6B_wADNiY"]
[Sun Aug 30 03:11:56.798538 2026] [security2:error] [pid 521505:tid 521558] [remote 185.93.89.167:37521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "internal.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzG8byYE0iXl--K6CAwADZTQ"]
[Sun Aug 30 03:11:56.798915 2026] [security2:error] [pid 521505:tid 521537] [remote 185.93.89.167:4287] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "php.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6CBAADTR8"]
[Sun Aug 30 03:11:56.798998 2026] [security2:error] [pid 521505:tid 521577] [remote 185.93.89.167:29333] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reg.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6CAgADkkc"]
[Sun Aug 30 03:11:56.800473 2026] [security2:error] [pid 521505:tid 521574] [remote 185.93.89.167:21227] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "outlook.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlzG8byYE0iXl--K6CBgADkEQ"]
[Sun Aug 30 03:11:56.808378 2026] [security2:error] [pid 521505:tid 521519] [remote 185.93.89.167:63379] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reviews.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzG8byYE0iXl--K6CCQADag0"]
[Sun Aug 30 03:11:56.808999 2026] [security2:error] [pid 521505:tid 521571] [remote 185.93.89.167:56175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "press.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6CCgADnUE"]
[Sun Aug 30 03:11:56.810469 2026] [security2:error] [pid 521505:tid 521509] [remote 185.93.89.167:62291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rs.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzG8byYE0iXl--K6CDAADigM"]
[Sun Aug 30 03:11:56.815097 2026] [security2:error] [pid 521505:tid 521525] [remote 185.93.89.167:11851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biblioteca.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6CEQADdBM"]
[Sun Aug 30 03:11:56.815584 2026] [security2:error] [pid 521505:tid 521620] [remote 185.93.89.167:12177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tr.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPlzG8byYE0iXl--K6CEgADX3I"]
[Sun Aug 30 03:11:56.818226 2026] [security2:error] [pid 521505:tid 521628] [remote 185.93.89.167:39177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "register.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6CFgADY3o"]
[Sun Aug 30 03:11:56.821350 2026] [security2:error] [pid 521505:tid 521511] [remote 185.93.89.167:15109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "linux.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzG8byYE0iXl--K6CGQADVAU"]
[Sun Aug 30 03:11:56.821670 2026] [security2:error] [pid 521505:tid 521567] [remote 185.93.89.167:3495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail5.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6CGgADHz0"]
[Sun Aug 30 03:11:56.822761 2026] [security2:error] [pid 521505:tid 521523] [remote 185.93.89.167:5225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "preprod.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6CHQADWhE"]
[Sun Aug 30 03:11:56.822837 2026] [security2:error] [pid 521505:tid 521568] [remote 185.93.89.167:61033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "analytics.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzG8byYE0iXl--K6CHgADIj4"]
[Sun Aug 30 03:11:56.823361 2026] [security2:error] [pid 521505:tid 521686] [client 20.197.61.180:12285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rivercrossingca.basichoa.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "apPlzG8byYE0iXl--K6CHwAAA1E"]
[Sun Aug 30 03:11:56.824710 2026] [security2:error] [pid 521505:tid 521573] [remote 185.93.89.167:11225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "da.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6CIgADfUM"]
[Sun Aug 30 03:11:56.826595 2026] [security2:error] [pid 521505:tid 521536] [remote 185.93.89.167:56429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mb.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzG8byYE0iXl--K6CJgADWR4"]
[Sun Aug 30 03:11:56.829479 2026] [security2:error] [pid 521505:tid 521586] [remote 185.93.89.167:37291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "st.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzG8byYE0iXl--K6CKwADmlA"]
[Sun Aug 30 03:11:56.829541 2026] [security2:error] [pid 521505:tid 521588] [remote 185.93.89.167:29329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mars.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6CLAADV1I"]
[Sun Aug 30 03:11:56.830598 2026] [security2:error] [pid 521505:tid 521545] [remote 185.93.89.167:7863] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adserver.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6CLgADbCc"]
[Sun Aug 30 03:11:56.830996 2026] [security2:error] [pid 521505:tid 521598] [remote 185.93.89.167:23169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www7.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzG8byYE0iXl--K6CMgADaVw"]
[Sun Aug 30 03:11:56.832978 2026] [security2:error] [pid 521505:tid 521576] [remote 185.93.89.167:53553] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "demo2.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlzG8byYE0iXl--K6CNwADUkY"]
[Sun Aug 30 03:11:56.833834 2026] [security2:error] [pid 521505:tid 521560] [remote 185.93.89.167:3789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vc.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzG8byYE0iXl--K6COgADiDY"]
[Sun Aug 30 03:11:56.838427 2026] [security2:error] [pid 521505:tid 521665] [client 4.205.62.107:16793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/environment.php"] [unique_id "apPlzG8byYE0iXl--K6CPQAAAzw"]
[Sun Aug 30 03:11:56.838534 2026] [security2:error] [pid 521505:tid 521720] [client 20.104.18.15:2021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/ops.php"] [unique_id "apPlzG8byYE0iXl--K6CPgAAA3M"]
[Sun Aug 30 03:11:56.841910 2026] [security2:error] [pid 521505:tid 521735] [client 20.104.18.15:16934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/wp-trackback.php"] [unique_id "apPlzG8byYE0iXl--K6CRQAAA4I"]
[Sun Aug 30 03:11:56.846884 2026] [security2:error] [pid 521505:tid 521680] [client 20.104.50.220:24886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/term.php"] [unique_id "apPlzG8byYE0iXl--K6CSgAAA0s"]
[Sun Aug 30 03:11:56.847248 2026] [security2:error] [pid 521505:tid 521739] [client 20.104.50.220:16636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/403.php"] [unique_id "apPlzG8byYE0iXl--K6CTAAAA4Y"]
[Sun Aug 30 03:11:56.852036 2026] [security2:error] [pid 521505:tid 521609] [remote 185.93.89.167:45621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images8.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6CUQADQWc"]
[Sun Aug 30 03:11:56.854719 2026] [security2:error] [pid 521505:tid 521602] [remote 185.93.89.167:24005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radius.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzG8byYE0iXl--K6CVQADO2A"]
[Sun Aug 30 03:11:56.855327 2026] [security2:error] [pid 521505:tid 521603] [remote 185.93.89.167:47169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "order.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6CVgADZWE"]
[Sun Aug 30 03:11:56.857326 2026] [security2:error] [pid 521505:tid 521658] [client 20.104.50.220:33322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/jindex.php"] [unique_id "apPlzG8byYE0iXl--K6CWgAAAzU"]
[Sun Aug 30 03:11:56.857980 2026] [security2:error] [pid 521505:tid 521745] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "board.mariegronley.com"] [uri "/index.cgi"] [unique_id "apPlzG8byYE0iXl--K6CWQADjC0"]
[Sun Aug 30 03:11:56.860080 2026] [security2:error] [pid 521505:tid 521610] [remote 185.93.89.167:64329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digital.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6CXwADimg"]
[Sun Aug 30 03:11:56.860298 2026] [security2:error] [pid 521505:tid 521626] [remote 185.93.89.167:24213] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "in.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6CXgADnXg"]
[Sun Aug 30 03:11:56.860774 2026] [security2:error] [pid 521505:tid 521607] [remote 185.93.89.167:27945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images6.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6CYAADOGU"]
[Sun Aug 30 03:11:56.861407 2026] [security2:error] [pid 521505:tid 521607] [remote 185.93.89.167:40249] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tracking.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzG8byYE0iXl--K6CYQADnGU"]
[Sun Aug 30 03:11:56.861411 2026] [security2:error] [pid 521505:tid 521612] [remote 185.93.89.167:48523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "web01.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6CYgADk2o"]
[Sun Aug 30 03:11:56.861484 2026] [security2:error] [pid 521505:tid 521614] [remote 185.93.89.167:1995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6CYwADJ2w"]
[Sun Aug 30 03:11:56.863580 2026] [security2:error] [pid 521505:tid 521552] [remote 185.93.89.167:16627] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "education.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6CZAADdC4"]
[Sun Aug 30 03:11:56.863720 2026] [security2:error] [pid 521505:tid 521657] [client 20.104.50.220:61426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/thh.php"] [unique_id "apPlzG8byYE0iXl--K6CZQAAAzQ"]
[Sun Aug 30 03:11:56.866029 2026] [security2:error] [pid 521505:tid 521689] [client 20.104.49.130:64094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/reviall.php"] [unique_id "apPlzG8byYE0iXl--K6CaAAAA1Q"]
[Sun Aug 30 03:11:56.867942 2026] [security2:error] [pid 521505:tid 521616] [remote 185.93.89.167:62709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp3.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6CawADIm4"]
[Sun Aug 30 03:11:56.873574 2026] [security2:error] [pid 521505:tid 521618] [remote 185.93.89.167:48785] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns02.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlzG8byYE0iXl--K6CbQADWXA"]
[Sun Aug 30 03:11:56.873963 2026] [security2:error] [pid 521505:tid 521624] [remote 185.93.89.167:39923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sitebuilder.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzG8byYE0iXl--K6CbwADVXY"]
[Sun Aug 30 03:11:56.883451 2026] [security2:error] [pid 521505:tid 521581] [remote 185.93.89.167:14659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "otrs.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzG8byYE0iXl--K6CcgADV0s"]
[Sun Aug 30 03:11:56.884880 2026] [security2:error] [pid 524122:tid 524351] [client 20.48.251.3:52240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/environment.php"] [unique_id "apPlzH3lhEjKFiK_nBJ62AAAAfE"]
[Sun Aug 30 03:11:56.884889 2026] [security2:error] [pid 521505:tid 521722] [client 20.104.18.15:51013] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.selectingwinners.com"] [uri "/1.php"] [unique_id "apPlzG8byYE0iXl--K6CdAAAA3U"]
[Sun Aug 30 03:11:56.884975 2026] [security2:error] [pid 521505:tid 521722] [client 20.104.18.15:51013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/1.php"] [unique_id "apPlzG8byYE0iXl--K6CdAAAA3U"]
[Sun Aug 30 03:11:56.886714 2026] [security2:error] [pid 521505:tid 521710] [client 20.48.160.90:37645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/Jcrop.php"] [unique_id "apPlzG8byYE0iXl--K6CdgAAA2k"]
[Sun Aug 30 03:11:56.891208 2026] [security2:error] [pid 521505:tid 521668] [client 20.48.251.3:55693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/params.php"] [unique_id "apPlzG8byYE0iXl--K6CeQAAAz8"]
[Sun Aug 30 03:11:56.894472 2026] [security2:error] [pid 521505:tid 521622] [remote 185.93.89.167:53363] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "work.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzG8byYE0iXl--K6CfwADSXQ"]
[Sun Aug 30 03:11:56.894720 2026] [security2:error] [pid 521505:tid 521687] [client 20.151.200.44:63630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/wp-access.php"] [unique_id "apPlzG8byYE0iXl--K6CgAAAA1I"]
[Sun Aug 30 03:11:56.897686 2026] [security2:error] [pid 521505:tid 521543] [remote 185.93.89.167:53985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "img3.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzG8byYE0iXl--K6CgwADhCU"]
[Sun Aug 30 03:11:56.899846 2026] [security2:error] [pid 521505:tid 521546] [remote 185.93.89.167:9557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "s4.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6ChQADiCg"]
[Sun Aug 30 03:11:56.907926 2026] [security2:error] [pid 521505:tid 521623] [remote 185.93.89.167:54151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "affiliate.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6CiwADbHU"]
[Sun Aug 30 03:11:56.910453 2026] [security2:error] [pid 521505:tid 521736] [client 20.48.251.3:54763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/admin-ajax.php"] [unique_id "apPlzG8byYE0iXl--K6CjAAAA4M"]
[Sun Aug 30 03:11:56.911627 2026] [authz_core:error] [pid 521505:tid 521663] [client 66.249.66.32:46138] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:56.911904 2026] [authz_core:error] [pid 521505:tid 521663] [client 66.249.66.32:46138] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:56.915680 2026] [security2:error] [pid 521505:tid 521716] [client 34.15.159.88:50716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/beta/.env"] [unique_id "apPlzG8byYE0iXl--K6CjgAAA28"]
[Sun Aug 30 03:11:56.928234 2026] [security2:error] [pid 521505:tid 521515] [remote 185.93.89.167:37843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jupiter.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzG8byYE0iXl--K6CkwADfAk"]
[Sun Aug 30 03:11:56.930820 2026] [security2:error] [pid 521505:tid 521533] [remote 185.93.89.167:14833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "se.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzG8byYE0iXl--K6CmgADQRs"]
[Sun Aug 30 03:11:56.932522 2026] [security2:error] [pid 521505:tid 521559] [remote 185.93.89.167:44659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzG8byYE0iXl--K6CnwADkjU"]
[Sun Aug 30 03:11:56.933248 2026] [security2:error] [pid 521505:tid 521632] [remote 185.93.89.167:31113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "math.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6CoAADNX4"]
[Sun Aug 30 03:11:56.937899 2026] [security2:error] [pid 521505:tid 521531] [remote 185.93.89.167:15177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "forms.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6CogADVhk"]
[Sun Aug 30 03:11:56.940842 2026] [security2:error] [pid 521505:tid 521520] [remote 185.93.89.167:34357] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banners.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzG8byYE0iXl--K6CowADjA4"]
[Sun Aug 30 03:11:56.941287 2026] [security2:error] [pid 521505:tid 521564] [remote 185.93.89.167:63379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reviews.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzG8byYE0iXl--K6CpAADezo"]
[Sun Aug 30 03:11:56.948181 2026] [security2:error] [pid 521505:tid 521562] [remote 185.93.89.167:11851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biblioteca.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6CpwADnTg"]
[Sun Aug 30 03:11:56.948883 2026] [security2:error] [pid 521505:tid 521615] [remote 185.93.89.167:12177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tr.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPlzG8byYE0iXl--K6CqAADnG0"]
[Sun Aug 30 03:11:56.955839 2026] [security2:error] [pid 521505:tid 521547] [remote 185.93.89.167:61033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "analytics.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzG8byYE0iXl--K6CrgADHyk"]
[Sun Aug 30 03:11:56.957683 2026] [security2:error] [pid 521505:tid 521514] [remote 185.93.89.167:11225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "da.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6CtAADIgg"]
[Sun Aug 30 03:11:56.958892 2026] [security2:error] [pid 521505:tid 521507] [remote 185.93.89.167:16669] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "links.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzG8byYE0iXl--K6CtQADawE"]
[Sun Aug 30 03:11:56.958921 2026] [security2:error] [pid 521505:tid 521506] [remote 185.93.89.167:14991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "barracuda.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzG8byYE0iXl--K6CtgADWgA"]
[Sun Aug 30 03:11:56.959302 2026] [security2:error] [pid 521505:tid 521667] [client 20.104.18.15:31714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-content/k.php"] [unique_id "apPlzG8byYE0iXl--K6CtwAAAz4"]
[Sun Aug 30 03:11:56.959483 2026] [security2:error] [pid 521505:tid 521517] [remote 185.93.89.167:56429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mb.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzG8byYE0iXl--K6CuAADUQs"]
[Sun Aug 30 03:11:56.959810 2026] [security2:error] [pid 521505:tid 521555] [remote 185.93.89.167:28567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "user.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzG8byYE0iXl--K6CuQADgDE"]
[Sun Aug 30 03:11:56.960805 2026] [security2:error] [pid 521505:tid 521565] [remote 185.93.89.167:3495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail5.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6CvAADWTs"]
[Sun Aug 30 03:11:56.961801 2026] [security2:error] [pid 521505:tid 521590] [remote 185.93.89.167:1591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thumbs.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzG8byYE0iXl--K6CvQADV1Q"]
[Sun Aug 30 03:11:56.964066 2026] [security2:error] [pid 521505:tid 521633] [remote 185.93.89.167:23169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www7.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzG8byYE0iXl--K6CwwADcH8"]
[Sun Aug 30 03:11:56.964668 2026] [authz_core:error] [pid 521505:tid 521700] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory27
[Sun Aug 30 03:11:56.965097 2026] [authz_core:error] [pid 521505:tid 521700] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory27
[Sun Aug 30 03:11:56.965312 2026] [security2:error] [pid 521505:tid 521535] [remote 185.93.89.167:9731] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images5.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzG8byYE0iXl--K6CxAADTh0"]
[Sun Aug 30 03:11:56.965346 2026] [security2:error] [pid 521505:tid 521548] [remote 185.93.89.167:24307] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tw.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzG8byYE0iXl--K6CxgADPyo"]
[Sun Aug 30 03:11:56.965516 2026] [security2:error] [pid 521505:tid 521637] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/bulk/.env"] [unique_id "apPlzG8byYE0iXl--K6CxQAAAyA"]
[Sun Aug 30 03:11:56.966430 2026] [security2:error] [pid 521505:tid 521540] [remote 185.93.89.167:57009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "static2.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6CygADeSI"]
[Sun Aug 30 03:11:56.967621 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:59097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "web6.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6CzgADhE0"]
[Sun Aug 30 03:11:56.968501 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:32655] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lync.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzG8byYE0iXl--K6CzwADiE0"]
[Sun Aug 30 03:11:56.973343 2026] [security2:error] [pid 521505:tid 521558] [remote 185.93.89.167:25969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dbadmin.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzG8byYE0iXl--K6C1AADYTQ"]
[Sun Aug 30 03:11:56.974001 2026] [security2:error] [pid 521505:tid 521566] [remote 185.93.89.167:22281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "labs.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzG8byYE0iXl--K6C1QADczw"]
[Sun Aug 30 03:11:56.974861 2026] [security2:error] [pid 521505:tid 521537] [remote 185.93.89.167:4349] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mm.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzG8byYE0iXl--K6C1gADUB8"]
[Sun Aug 30 03:11:56.976366 2026] [security2:error] [pid 521505:tid 521713] [client 20.104.50.220:62808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/tntmar.php"] [unique_id "apPlzG8byYE0iXl--K6C2gAAA2w"]
[Sun Aug 30 03:11:56.978932 2026] [security2:error] [pid 521505:tid 521532] [remote 185.93.89.167:50005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fax.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzG8byYE0iXl--K6C2wADTBo"]
[Sun Aug 30 03:11:56.984354 2026] [security2:error] [pid 521505:tid 521519] [remote 185.93.89.167:54367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webservices.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlzG8byYE0iXl--K6C3wADgw0"]
[Sun Aug 30 03:11:56.985048 2026] [security2:error] [pid 521505:tid 521509] [remote 185.93.89.167:45621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images8.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6C4QADRQM"]
[Sun Aug 30 03:11:56.987347 2026] [security2:error] [pid 521505:tid 521617] [remote 185.93.89.167:42995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns12.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzG8byYE0iXl--K6C4wADSm8"]
[Sun Aug 30 03:11:56.988218 2026] [security2:error] [pid 521505:tid 521620] [remote 185.93.89.167:47169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "order.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6C5QADmHI"]
[Sun Aug 30 03:11:56.990901 2026] [security2:error] [pid 521505:tid 521628] [remote 185.93.89.167:62949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "board.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzG8byYE0iXl--K6C6AADbno"]
[Sun Aug 30 03:11:56.991032 2026] [security2:error] [pid 521505:tid 521715] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "board.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzG8byYE0iXl--K6C6AADbno"]
[Sun Aug 30 03:11:56.994274 2026] [security2:error] [pid 521505:tid 521528] [remote 185.93.89.167:40249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracking.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzG8byYE0iXl--K6C7wADZRY"]
[Sun Aug 30 03:11:56.994691 2026] [security2:error] [pid 521505:tid 521573] [remote 185.93.89.167:48523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "web01.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzG8byYE0iXl--K6C8AADPUM"]
[Sun Aug 30 03:11:57.000971 2026] [security2:error] [pid 521505:tid 521536] [remote 185.93.89.167:62709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp3.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzW8byYE0iXl--K6C9wADkB4"]
[Sun Aug 30 03:11:57.002471 2026] [security2:error] [pid 521505:tid 521550] [remote 185.93.89.167:14453] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6C-AADWyw"]
[Sun Aug 30 03:11:57.006267 2026] [security2:error] [pid 521505:tid 521522] [remote 185.93.89.167:48785] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "ns02.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlzW8byYE0iXl--K6C-gADahA"]
[Sun Aug 30 03:11:57.007042 2026] [security2:error] [pid 521505:tid 521539] [remote 185.93.89.167:39923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sitebuilder.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzW8byYE0iXl--K6C-wADfiE"]
[Sun Aug 30 03:11:57.012240 2026] [security2:error] [pid 521505:tid 521761] [client 20.104.50.220:59357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "apPlzW8byYE0iXl--K6C_QAAA5w"]
[Sun Aug 30 03:11:57.018498 2026] [security2:error] [pid 521505:tid 521588] [remote 185.93.89.167:49893] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mdm.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6DAAADVFI"]
[Sun Aug 30 03:11:57.027320 2026] [security2:error] [pid 521505:tid 521598] [remote 185.93.89.167:60123] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "up.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6DBAADYFw"]
[Sun Aug 30 03:11:57.027516 2026] [security2:error] [pid 521505:tid 521529] [remote 185.93.89.167:53363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "work.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6DBgADWRc"]
[Sun Aug 30 03:11:57.027587 2026] [security2:error] [pid 521505:tid 521596] [remote 185.93.89.167:63579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "wifi.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6DBQADgFo"]
[Sun Aug 30 03:11:57.028743 2026] [security2:error] [pid 521505:tid 521576] [remote 185.93.89.167:37133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kb.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzW8byYE0iXl--K6DBwADV0Y"]
[Sun Aug 30 03:11:57.047272 2026] [security2:error] [pid 521505:tid 521647] [client 20.48.160.90:37660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/35iDq8NAjLu.php"] [unique_id "apPlzW8byYE0iXl--K6DEAAAAyo"]
[Sun Aug 30 03:11:57.050362 2026] [security2:error] [pid 521505:tid 521652] [client 20.104.18.15:22280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/sss.php"] [unique_id "apPlzW8byYE0iXl--K6DEgAAAy8"]
[Sun Aug 30 03:11:57.050757 2026] [security2:error] [pid 524122:tid 524355] [client 4.205.62.107:15523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/g3.php"] [unique_id "apPlzX3lhEjKFiK_nBJ64wAAAfU"]
[Sun Aug 30 03:11:57.051339 2026] [security2:error] [pid 524122:tid 524355] [client 4.205.62.107:52869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/wpver.php"] [unique_id "apPlzX3lhEjKFiK_nBJ65AAAAfU"]
[Sun Aug 30 03:11:57.053952 2026] [security2:error] [pid 524122:tid 524352] [client 20.104.50.220:6088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/index3.php"] [unique_id "apPlzX3lhEjKFiK_nBJ65QAAAfI"]
[Sun Aug 30 03:11:57.062108 2026] [security2:error] [pid 521505:tid 521675] [client 20.104.49.130:64089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/pfm.php"] [unique_id "apPlzW8byYE0iXl--K6DFgAAA0Y"]
[Sun Aug 30 03:11:57.063177 2026] [security2:error] [pid 521505:tid 521730] [client 4.205.62.107:25790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/nw.php"] [unique_id "apPlzW8byYE0iXl--K6DGAAAA30"]
[Sun Aug 30 03:11:57.063263 2026] [security2:error] [pid 521505:tid 521526] [remote 185.93.89.167:53853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atlas.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzW8byYE0iXl--K6DGQADPBQ"]
[Sun Aug 30 03:11:57.063452 2026] [security2:error] [pid 521505:tid 521518] [remote 185.93.89.167:13069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sc.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzW8byYE0iXl--K6DHAADYQw"]
[Sun Aug 30 03:11:57.063729 2026] [security2:error] [pid 521505:tid 521563] [remote 185.93.89.167:2579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "love.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzW8byYE0iXl--K6DHQADczk"]
[Sun Aug 30 03:11:57.066274 2026] [security2:error] [pid 521505:tid 521608] [remote 185.93.89.167:31113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "math.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzW8byYE0iXl--K6DIgADTWY"]
[Sun Aug 30 03:11:57.066722 2026] [security2:error] [pid 521505:tid 521601] [remote 185.93.89.167:4287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "php.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzW8byYE0iXl--K6DJAADVV8"]
[Sun Aug 30 03:11:57.066734 2026] [security2:error] [pid 521505:tid 521593] [remote 185.93.89.167:29333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reg.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzW8byYE0iXl--K6DJQADf1c"]
[Sun Aug 30 03:11:57.067846 2026] [security2:error] [pid 521505:tid 521589] [remote 185.93.89.167:21227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "outlook.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzW8byYE0iXl--K6DJwADJFM"]
[Sun Aug 30 03:11:57.073738 2026] [security2:error] [pid 521505:tid 521609] [remote 185.93.89.167:34357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "banners.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6DLAADm2c"]
[Sun Aug 30 03:11:57.076318 2026] [security2:error] [pid 521505:tid 521521] [remote 185.93.89.167:56175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "press.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzW8byYE0iXl--K6DLwADWA8"]
[Sun Aug 30 03:11:57.077144 2026] [security2:error] [pid 521505:tid 521602] [remote 185.93.89.167:15177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "forms.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzW8byYE0iXl--K6DMAADSWA"]
[Sun Aug 30 03:11:57.081873 2026] [security2:error] [pid 521505:tid 521551] [remote 185.93.89.167:12177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tr.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPlzW8byYE0iXl--K6DMgADfC0"]
[Sun Aug 30 03:11:57.086247 2026] [security2:error] [pid 521505:tid 521610] [remote 185.93.89.167:39177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "register.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzW8byYE0iXl--K6DNAADbmg"]
[Sun Aug 30 03:11:57.090008 2026] [security2:error] [pid 524122:tid 524339] [client 20.151.200.44:41918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPlzX3lhEjKFiK_nBJ67AAAAeU"]
[Sun Aug 30 03:11:57.090755 2026] [security2:error] [pid 521505:tid 521607] [remote 185.93.89.167:5225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preprod.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzW8byYE0iXl--K6DOgADi2U"]
[Sun Aug 30 03:11:57.091884 2026] [security2:error] [pid 521505:tid 521614] [remote 185.93.89.167:16669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "links.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6DPAADcWw"]
[Sun Aug 30 03:11:57.093018 2026] [security2:error] [pid 521505:tid 521616] [remote 185.93.89.167:28567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "user.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzW8byYE0iXl--K6DQAADkG4"]
[Sun Aug 30 03:11:57.093521 2026] [security2:error] [pid 524122:tid 524341] [client 20.151.200.44:45038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/h02ugyh.php"] [unique_id "apPlzX3lhEjKFiK_nBJ67QAAAec"]
[Sun Aug 30 03:11:57.097457 2026] [security2:error] [pid 521505:tid 521624] [remote 185.93.89.167:6761] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banner.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzW8byYE0iXl--K6DQwADVnY"]
[Sun Aug 30 03:11:57.097518 2026] [security2:error] [pid 521505:tid 521585] [remote 185.93.89.167:29329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mars.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6DRQADjE8"]
[Sun Aug 30 03:11:57.097987 2026] [security2:error] [pid 521505:tid 521619] [remote 185.93.89.167:7863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adserver.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzW8byYE0iXl--K6DRgADe3E"]
[Sun Aug 30 03:11:57.098351 2026] [security2:error] [pid 521505:tid 521611] [remote 185.93.89.167:24307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tw.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6DRwADK2k"]
[Sun Aug 30 03:11:57.098489 2026] [security2:error] [pid 521505:tid 521584] [remote 185.93.89.167:9731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images5.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6DSQADfk4"]
[Sun Aug 30 03:11:57.099432 2026] [security2:error] [pid 521505:tid 521622] [remote 185.93.89.167:57009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "static2.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzW8byYE0iXl--K6DSgADnXQ"]
[Sun Aug 30 03:11:57.100857 2026] [security2:error] [pid 521505:tid 521543] [remote 185.93.89.167:59097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "web6.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzW8byYE0iXl--K6DTAADkyU"]
[Sun Aug 30 03:11:57.101244 2026] [security2:error] [pid 521505:tid 521606] [remote 185.93.89.167:32655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lync.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6DUAADkmQ"]
[Sun Aug 30 03:11:57.107118 2026] [security2:error] [pid 521505:tid 521631] [remote 185.93.89.167:22281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "labs.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzW8byYE0iXl--K6DUwADIX0"]
[Sun Aug 30 03:11:57.109219 2026] [security2:error] [pid 521505:tid 521533] [remote 185.93.89.167:13143] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "net.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzW8byYE0iXl--K6DVQADHxs"]
[Sun Aug 30 03:11:57.111903 2026] [security2:error] [pid 521505:tid 521559] [remote 185.93.89.167:50005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fax.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6DWQADUTU"]
[Sun Aug 30 03:11:57.116483 2026] [security2:error] [pid 521505:tid 521579] [remote 185.93.89.167:14681] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mc.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzW8byYE0iXl--K6DXwADMEk"]
[Sun Aug 30 03:11:57.117062 2026] [security2:error] [pid 521505:tid 521710] [client 34.15.159.88:50716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/uat/.env"] [unique_id "apPlzW8byYE0iXl--K6DYAAAA2k"]
[Sun Aug 30 03:11:57.118242 2026] [security2:error] [pid 521505:tid 521513] [remote 185.93.89.167:54367] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "webservices.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlzW8byYE0iXl--K6DYQADPgc"]
[Sun Aug 30 03:11:57.119003 2026] [security2:error] [pid 521505:tid 521531] [remote 185.93.89.167:59215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "users.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzW8byYE0iXl--K6DZAADeRk"]
[Sun Aug 30 03:11:57.120140 2026] [security2:error] [pid 521505:tid 521564] [remote 185.93.89.167:42995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns12.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzW8byYE0iXl--K6DZgADZzo"]
[Sun Aug 30 03:11:57.120536 2026] [security2:error] [pid 521505:tid 521520] [remote 185.93.89.167:45765] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns01.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzW8byYE0iXl--K6DZQADKg4"]
[Sun Aug 30 03:11:57.125238 2026] [security2:error] [pid 521505:tid 521734] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/aws/.env"] [unique_id "apPlzW8byYE0iXl--K6DagAAA4E"]
[Sun Aug 30 03:11:57.125743 2026] [security2:error] [pid 521505:tid 521759] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "board.mariegronley.com"] [uri "/index.cgi"] [unique_id "apPlzW8byYE0iXl--K6DaQADmm0"]
[Sun Aug 30 03:11:57.127400 2026] [security2:error] [pid 521505:tid 521542] [remote 185.93.89.167:24213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "in.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzW8byYE0iXl--K6DcAADYSQ"]
[Sun Aug 30 03:11:57.127563 2026] [security2:error] [pid 521505:tid 521627] [remote 185.93.89.167:64329] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6DbwADPHk"]
[Sun Aug 30 03:11:57.127983 2026] [security2:error] [pid 521505:tid 521547] [remote 185.93.89.167:52789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "market.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzW8byYE0iXl--K6DcQADcyk"]
[Sun Aug 30 03:11:57.128396 2026] [security2:error] [pid 521505:tid 521578] [remote 185.93.89.167:27945] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6DcwADbEg"]
[Sun Aug 30 03:11:57.131007 2026] [security2:error] [pid 521505:tid 521514] [remote 185.93.89.167:1995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lp.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6DdwADUAg"]
[Sun Aug 30 03:11:57.131137 2026] [security2:error] [pid 521505:tid 521507] [remote 185.93.89.167:16627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "education.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzW8byYE0iXl--K6DeAADTQE"]
[Sun Aug 30 03:11:57.135737 2026] [security2:error] [pid 521505:tid 521517] [remote 185.93.89.167:14453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mobil.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6DegADJAs"]
[Sun Aug 30 03:11:57.137269 2026] [security2:error] [pid 524122:tid 524363] [client 20.48.251.3:37122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/konfig.php"] [unique_id "apPlzX3lhEjKFiK_nBJ67wAAAf0"]
[Sun Aug 30 03:11:57.151547 2026] [security2:error] [pid 521505:tid 521633] [remote 185.93.89.167:49893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdm.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6DgQADg38"]
[Sun Aug 30 03:11:57.160372 2026] [security2:error] [pid 521505:tid 521538] [remote 185.93.89.167:60123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "up.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6DhwADRyA"]
[Sun Aug 30 03:11:57.160742 2026] [security2:error] [pid 521505:tid 521512] [remote 185.93.89.167:63579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wifi.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6DiAADSQY"]
[Sun Aug 30 03:11:57.161505 2026] [security2:error] [pid 521505:tid 521535] [remote 185.93.89.167:37133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kb.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzW8byYE0iXl--K6DiQADkR0"]
[Sun Aug 30 03:11:57.166426 2026] [security2:error] [pid 521505:tid 521744] [client 158.23.147.79:39946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-content/radio.php"] [unique_id "apPlzW8byYE0iXl--K6DjAAAA4s"]
[Sun Aug 30 03:11:57.169316 2026] [security2:error] [pid 521505:tid 521540] [remote 185.93.89.167:9557] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "s4.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6DjgADRSI"]
[Sun Aug 30 03:11:57.176552 2026] [security2:error] [pid 521505:tid 521544] [remote 185.93.89.167:54151] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "affiliate.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6DkAADkCY"]
[Sun Aug 30 03:11:57.194480 2026] [security2:error] [pid 521505:tid 521691] [client 20.48.160.90:37962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/btx25.php"] [unique_id "apPlzW8byYE0iXl--K6DkwAAA1Y"]
[Sun Aug 30 03:11:57.196448 2026] [security2:error] [pid 521505:tid 521561] [remote 185.93.89.167:53853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atlas.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzW8byYE0iXl--K6DlQADezc"]
[Sun Aug 30 03:11:57.196449 2026] [security2:error] [pid 521505:tid 521580] [remote 185.93.89.167:13069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sc.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzW8byYE0iXl--K6DlgADK0o"]
[Sun Aug 30 03:11:57.196809 2026] [security2:error] [pid 521505:tid 521570] [remote 185.93.89.167:2579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "love.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzW8byYE0iXl--K6DlwADW0A"]
[Sun Aug 30 03:11:57.199046 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:64795] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jp.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzW8byYE0iXl--K6DmAADfk0"]
[Sun Aug 30 03:11:57.199830 2026] [security2:error] [pid 521505:tid 521537] [remote 185.93.89.167:29333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reg.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzW8byYE0iXl--K6DmwADkx8"]
[Sun Aug 30 03:11:57.199969 2026] [security2:error] [pid 521505:tid 521577] [remote 185.93.89.167:4287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "php.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzW8byYE0iXl--K6DnAADkkc"]
[Sun Aug 30 03:11:57.200665 2026] [security2:error] [pid 521505:tid 521592] [remote 185.93.89.167:10845] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "campus.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzW8byYE0iXl--K6DnQADnFY"]
[Sun Aug 30 03:11:57.208520 2026] [security2:error] [pid 524122:tid 524330] [client 20.104.49.130:63233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/echkm.php"] [unique_id "apPlzX3lhEjKFiK_nBJ6-QAAAdw"]
[Sun Aug 30 03:11:57.209198 2026] [security2:error] [pid 521505:tid 521571] [remote 185.93.89.167:56175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "press.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzW8byYE0iXl--K6DpgADZEE"]
[Sun Aug 30 03:11:57.213148 2026] [authz_core:error] [pid 521505:tid 521638] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_CA
[Sun Aug 30 03:11:57.213394 2026] [authz_core:error] [pid 521505:tid 521638] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_CA
[Sun Aug 30 03:11:57.215451 2026] [security2:error] [pid 521505:tid 521525] [remote 185.93.89.167:12177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tr.mariegronley.com"] [uri "/system/.env"] [unique_id "apPlzW8byYE0iXl--K6DqAADaxM"]
[Sun Aug 30 03:11:57.216186 2026] [security2:error] [pid 521505:tid 521617] [remote 185.93.89.167:11851] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "biblioteca.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6DqQADYG8"]
[Sun Aug 30 03:11:57.219536 2026] [security2:error] [pid 521505:tid 521587] [remote 185.93.89.167:39177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "register.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzW8byYE0iXl--K6DqwADUVE"]
[Sun Aug 30 03:11:57.223921 2026] [security2:error] [pid 521505:tid 521511] [remote 185.93.89.167:5225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preprod.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzW8byYE0iXl--K6DsAADXgU"]
[Sun Aug 30 03:11:57.223949 2026] [security2:error] [pid 521505:tid 521628] [remote 185.93.89.167:15109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "linux.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzW8byYE0iXl--K6DrgADgHo"]
[Sun Aug 30 03:11:57.225377 2026] [security2:error] [pid 521505:tid 521573] [remote 185.93.89.167:11225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "da.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6DsgADIEM"]
[Sun Aug 30 03:11:57.230462 2026] [security2:error] [pid 521505:tid 521550] [remote 185.93.89.167:62291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rs.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzW8byYE0iXl--K6DuAADKiw"]
[Sun Aug 30 03:11:57.230562 2026] [security2:error] [pid 521505:tid 521522] [remote 185.93.89.167:29329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mars.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6DuQADYxA"]
[Sun Aug 30 03:11:57.230911 2026] [security2:error] [pid 521505:tid 521539] [remote 185.93.89.167:7863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adserver.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzW8byYE0iXl--K6DugADhSE"]
[Sun Aug 30 03:11:57.232072 2026] [security2:error] [pid 521505:tid 521598] [remote 185.93.89.167:37291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "st.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzW8byYE0iXl--K6DvQADYVw"]
[Sun Aug 30 03:11:57.240785 2026] [security2:error] [pid 521505:tid 521572] [remote 185.93.89.167:3495] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6DyAADXEI"]
[Sun Aug 30 03:11:57.251700 2026] [security2:error] [pid 521505:tid 521582] [remote 185.93.89.167:59215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "users.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzW8byYE0iXl--K6D0QADWEw"]
[Sun Aug 30 03:11:57.252601 2026] [security2:error] [pid 521505:tid 521608] [remote 185.93.89.167:45621] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images8.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6D0gADg2Y"]
[Sun Aug 30 03:11:57.254957 2026] [security2:error] [pid 521505:tid 521530] [remote 185.93.89.167:4349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mm.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzW8byYE0iXl--K6D1QADhxg"]
[Sun Aug 30 03:11:57.255565 2026] [security2:error] [pid 521505:tid 521599] [remote 185.93.89.167:47169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "order.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6D1gADdl0"]
[Sun Aug 30 03:11:57.255980 2026] [security2:error] [pid 521505:tid 521589] [remote 185.93.89.167:24005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radius.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzW8byYE0iXl--K6D1wADblM"]
[Sun Aug 30 03:11:57.256734 2026] [security2:error] [pid 524122:tid 524366] [client 20.104.49.130:43327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/albin.php"] [unique_id "apPlzX3lhEjKFiK_nBJ7AAAAAgA"]
[Sun Aug 30 03:11:57.259701 2026] [security2:error] [pid 521505:tid 521735] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "board.mariegronley.com"] [uri "/index.cgi"] [unique_id "apPlzW8byYE0iXl--K6D2AADgj8"]
[Sun Aug 30 03:11:57.260336 2026] [security2:error] [pid 521505:tid 521604] [remote 185.93.89.167:64329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digital.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6D2gADR2I"]
[Sun Aug 30 03:11:57.260375 2026] [security2:error] [pid 521505:tid 521609] [remote 185.93.89.167:24213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "in.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzW8byYE0iXl--K6D2QADZWc"]
[Sun Aug 30 03:11:57.261157 2026] [security2:error] [pid 521505:tid 521602] [remote 185.93.89.167:27945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images6.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6D3AADl2A"]
[Sun Aug 30 03:11:57.262560 2026] [security2:error] [pid 521505:tid 521703] [client 20.104.18.15:18296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/wp-activate.php"] [unique_id "apPlzW8byYE0iXl--K6D3gAAA2I"]
[Sun Aug 30 03:11:57.263009 2026] [security2:error] [pid 521505:tid 521603] [remote 185.93.89.167:48523] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6D3wADMWE"]
[Sun Aug 30 03:11:57.264063 2026] [security2:error] [pid 521505:tid 521610] [remote 185.93.89.167:16627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "education.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzW8byYE0iXl--K6D4AADi2g"]
[Sun Aug 30 03:11:57.264930 2026] [security2:error] [pid 521505:tid 521626] [remote 185.93.89.167:1995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6D4gADeHg"]
[Sun Aug 30 03:11:57.268477 2026] [security2:error] [pid 521505:tid 521621] [remote 185.93.89.167:62709] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "smtp3.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6D5AADkHM"]
[Sun Aug 30 03:11:57.284626 2026] [security2:error] [pid 521505:tid 521751] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/azure/.env"] [unique_id "apPlzW8byYE0iXl--K6D7wAAA5I"]
[Sun Aug 30 03:11:57.285549 2026] [security2:error] [pid 521505:tid 521616] [remote 185.93.89.167:14659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "otrs.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzW8byYE0iXl--K6D8QADhm4"]
[Sun Aug 30 03:11:57.289090 2026] [security2:error] [pid 521505:tid 521721] [client 20.104.50.220:42478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/index9.php"] [unique_id "apPlzW8byYE0iXl--K6D9QAAA3Q"]
[Sun Aug 30 03:11:57.295252 2026] [security2:error] [pid 521505:tid 521585] [remote 185.93.89.167:11687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pr.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlzW8byYE0iXl--K6D-gADUU8"]
[Sun Aug 30 03:11:57.300203 2026] [security2:error] [pid 524122:tid 524140] [remote 103.156.21.26:44718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.21.156.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cravegoldcoast.com.au"] [uri "/wp-login.php"] [unique_id "apPlzX3lhEjKFiK_nBJ7BAABkhA"], referer: https://cravegoldcoast.com.au/wp-login.php
[Sun Aug 30 03:11:57.302599 2026] [security2:error] [pid 521505:tid 521611] [remote 185.93.89.167:9557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "s4.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6D_gADIGk"]
[Sun Aug 30 03:11:57.309655 2026] [security2:error] [pid 521505:tid 521618] [remote 185.93.89.167:54151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "affiliate.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6D_wADMHA"]
[Sun Aug 30 03:11:57.318557 2026] [security2:error] [pid 521505:tid 521667] [client 34.15.159.88:50716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/stage/.env"] [unique_id "apPlzW8byYE0iXl--K6EAgAAAz4"]
[Sun Aug 30 03:11:57.328776 2026] [security2:error] [pid 521505:tid 521708] [client 68.155.159.216:52227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/packed.php"] [unique_id "apPlzW8byYE0iXl--K6EBQAAA2c"]
[Sun Aug 30 03:11:57.332034 2026] [security2:error] [pid 524122:tid 524342] [client 128.90.161.20:48566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.161.90.128.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.healthquotemall.com"] [uri "/wp-login.php"] [unique_id "apPlzX3lhEjKFiK_nBJ7BQAAAeg"]
[Sun Aug 30 03:11:57.334484 2026] [security2:error] [pid 521505:tid 521516] [remote 185.93.89.167:14833] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "se.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzW8byYE0iXl--K6EEAADUAo"]
[Sun Aug 30 03:11:57.334535 2026] [security2:error] [pid 521505:tid 521546] [remote 185.93.89.167:31113] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "math.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6EDwADTSg"]
[Sun Aug 30 03:11:57.335382 2026] [security2:error] [pid 521505:tid 521524] [remote 185.93.89.167:44659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzW8byYE0iXl--K6EEgADXBI"]
[Sun Aug 30 03:11:57.346890 2026] [security2:error] [pid 521505:tid 521755] [client 20.48.160.90:61484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/radio.php"] [unique_id "apPlzW8byYE0iXl--K6EGgAAA5Y"]
[Sun Aug 30 03:11:57.348140 2026] [security2:error] [pid 521505:tid 521579] [remote 185.93.89.167:12177] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "tr.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPlzW8byYE0iXl--K6EHQADf0k"]
[Sun Aug 30 03:11:57.349150 2026] [security2:error] [pid 521505:tid 521575] [remote 185.93.89.167:11851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biblioteca.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6EHgADdUU"]
[Sun Aug 30 03:11:57.352654 2026] [authz_core:error] [pid 521505:tid 521719] [client 66.249.66.206:54106] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:57.352919 2026] [authz_core:error] [pid 521505:tid 521719] [client 66.249.66.206:54106] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:57.357277 2026] [security2:error] [pid 521505:tid 521531] [remote 185.93.89.167:15177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6EJAADhxk"]
[Sun Aug 30 03:11:57.358440 2026] [security2:error] [pid 521505:tid 521520] [remote 185.93.89.167:11225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "da.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6EKAADRw4"]
[Sun Aug 30 03:11:57.358749 2026] [security2:error] [pid 521505:tid 521600] [remote 185.93.89.167:61033] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzW8byYE0iXl--K6EJwADgl4"]
[Sun Aug 30 03:11:57.361515 2026] [security2:error] [pid 521505:tid 521542] [remote 185.93.89.167:56429] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mb.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzW8byYE0iXl--K6EKwADbSQ"]
[Sun Aug 30 03:11:57.361692 2026] [security2:error] [pid 521505:tid 521627] [remote 185.93.89.167:14991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "barracuda.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzW8byYE0iXl--K6ELAADSXk"]
[Sun Aug 30 03:11:57.363777 2026] [security2:error] [pid 521505:tid 521578] [remote 185.93.89.167:1591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thumbs.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzW8byYE0iXl--K6ELwADQEg"]
[Sun Aug 30 03:11:57.365638 2026] [security2:error] [pid 521505:tid 521514] [remote 185.93.89.167:6761] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banner.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzW8byYE0iXl--K6EMgADRQg"]
[Sun Aug 30 03:11:57.366722 2026] [security2:error] [pid 521505:tid 521517] [remote 185.93.89.167:23169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzW8byYE0iXl--K6ENQADkAs"]
[Sun Aug 30 03:11:57.367811 2026] [security2:error] [pid 521505:tid 521555] [remote 185.93.89.167:57009] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "static2.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6ENgADjTE"]
[Sun Aug 30 03:11:57.368428 2026] [security2:error] [pid 521505:tid 521633] [remote 185.93.89.167:59097] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web6.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6EOAADU38"]
[Sun Aug 30 03:11:57.369386 2026] [security2:error] [pid 521505:tid 521590] [remote 185.93.89.167:62291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rs.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzW8byYE0iXl--K6EOQADNVQ"]
[Sun Aug 30 03:11:57.370686 2026] [security2:error] [pid 521505:tid 521538] [remote 185.93.89.167:53553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "demo2.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlzW8byYE0iXl--K6EOgADViA"]
[Sun Aug 30 03:11:57.377076 2026] [security2:error] [pid 521505:tid 521535] [remote 185.93.89.167:13143] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "net.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzW8byYE0iXl--K6EPAADhh0"]
[Sun Aug 30 03:11:57.378410 2026] [security2:error] [pid 521505:tid 521594] [remote 185.93.89.167:25969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dbadmin.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzW8byYE0iXl--K6EPQADj1g"]
[Sun Aug 30 03:11:57.379835 2026] [security2:error] [pid 521505:tid 521548] [remote 185.93.89.167:3495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail5.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6EPwADOyo"]
[Sun Aug 30 03:11:57.383891 2026] [security2:error] [pid 521505:tid 521540] [remote 185.93.89.167:14681] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mc.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzW8byYE0iXl--K6EQAADJyI"]
[Sun Aug 30 03:11:57.385916 2026] [security2:error] [pid 521505:tid 521580] [remote 185.93.89.167:45621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images8.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6EQgADdEo"]
[Sun Aug 30 03:11:57.385926 2026] [security2:error] [pid 521505:tid 521561] [remote 185.93.89.167:54367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webservices.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzW8byYE0iXl--K6EQwADHzc"]
[Sun Aug 30 03:11:57.387382 2026] [security2:error] [pid 521505:tid 521570] [remote 185.93.89.167:42995] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns12.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6ERAADUUA"]
[Sun Aug 30 03:11:57.388344 2026] [security2:error] [pid 521505:tid 521629] [remote 185.93.89.167:47169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "order.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6ERQADa3s"]
[Sun Aug 30 03:11:57.388875 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:45765] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns01.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzW8byYE0iXl--K6ERgADYE0"]
[Sun Aug 30 03:11:57.388927 2026] [security2:error] [pid 521505:tid 521537] [remote 185.93.89.167:24005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radius.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzW8byYE0iXl--K6ERwADiR8"]
[Sun Aug 30 03:11:57.392332 2026] [security2:error] [pid 521505:tid 521577] [remote 185.93.89.167:62949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "board.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzW8byYE0iXl--K6ESAADNEc"]
[Sun Aug 30 03:11:57.392440 2026] [security2:error] [pid 521505:tid 521657] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "board.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzW8byYE0iXl--K6ESAADNEc"]
[Sun Aug 30 03:11:57.394525 2026] [security2:error] [pid 521505:tid 521527] [remote 185.93.89.167:4349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mm.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzW8byYE0iXl--K6ETAADdxU"]
[Sun Aug 30 03:11:57.395584 2026] [security2:error] [pid 521505:tid 521532] [remote 185.93.89.167:52789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "market.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzW8byYE0iXl--K6ETQADVxo"]
[Sun Aug 30 03:11:57.396094 2026] [security2:error] [pid 521505:tid 521519] [remote 185.93.89.167:48523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "web01.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6ETwADjA0"]
[Sun Aug 30 03:11:57.401297 2026] [security2:error] [pid 521505:tid 521525] [remote 185.93.89.167:62709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp3.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6EUwADfhM"]
[Sun Aug 30 03:11:57.409814 2026] [security2:error] [pid 521505:tid 521587] [remote 185.93.89.167:39923] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sitebuilder.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzW8byYE0iXl--K6EVwADMFE"]
[Sun Aug 30 03:11:57.418597 2026] [security2:error] [pid 521505:tid 521511] [remote 185.93.89.167:14659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "otrs.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzW8byYE0iXl--K6EWwADZwU"]
[Sun Aug 30 03:11:57.420211 2026] [security2:error] [pid 521505:tid 521675] [client 20.104.50.220:29127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/DC.php"] [unique_id "apPlzW8byYE0iXl--K6EYAAAA0Y"]
[Sun Aug 30 03:11:57.428746 2026] [security2:error] [pid 521505:tid 521523] [remote 185.93.89.167:37133] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6EaQADXRE"]
[Sun Aug 30 03:11:57.429064 2026] [security2:error] [pid 521505:tid 521528] [remote 185.93.89.167:11687] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "pr.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlzW8byYE0iXl--K6EZwADVRY"]
[Sun Aug 30 03:11:57.443949 2026] [security2:error] [pid 521505:tid 521713] [client 20.104.49.130:52101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/wp-login.php"] [unique_id "apPlzW8byYE0iXl--K6EXgAAA2w"]
[Sun Aug 30 03:11:57.444978 2026] [security2:error] [pid 521505:tid 521737] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/gcp/.env"] [unique_id "apPlzW8byYE0iXl--K6EdgAAA4Q"]
[Sun Aug 30 03:11:57.461945 2026] [authz_core:error] [pid 521505:tid 521723] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory25
[Sun Aug 30 03:11:57.462273 2026] [authz_core:error] [pid 521505:tid 521723] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory25
[Sun Aug 30 03:11:57.464589 2026] [security2:error] [pid 521505:tid 521554] [remote 185.93.89.167:13069] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sc.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6EgQADYjA"]
[Sun Aug 30 03:11:57.464589 2026] [security2:error] [pid 521505:tid 521522] [remote 185.93.89.167:53853] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atlas.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6EgAADQBA"]
[Sun Aug 30 03:11:57.464601 2026] [security2:error] [pid 521505:tid 521539] [remote 185.93.89.167:2579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "love.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6EggADiyE"]
[Sun Aug 30 03:11:57.466504 2026] [security2:error] [pid 521505:tid 521536] [remote 185.93.89.167:64795] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jp.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzW8byYE0iXl--K6EhQADcR4"]
[Sun Aug 30 03:11:57.467522 2026] [security2:error] [pid 521505:tid 521588] [remote 185.93.89.167:31113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "math.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6EiAADLFI"]
[Sun Aug 30 03:11:57.467769 2026] [security2:error] [pid 521505:tid 521586] [remote 185.93.89.167:29333] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "reg.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6EhgADU1A"]
[Sun Aug 30 03:11:57.467845 2026] [security2:error] [pid 521505:tid 521545] [remote 185.93.89.167:4287] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "php.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6EhwADlCc"]
[Sun Aug 30 03:11:57.468511 2026] [security2:error] [pid 521505:tid 521576] [remote 185.93.89.167:44659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzW8byYE0iXl--K6EiwADU0Y"]
[Sun Aug 30 03:11:57.468747 2026] [security2:error] [pid 521505:tid 521596] [remote 185.93.89.167:10845] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "campus.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzW8byYE0iXl--K6EigADklo"]
[Sun Aug 30 03:11:57.469490 2026] [security2:error] [pid 521505:tid 521605] [remote 185.93.89.167:21227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "outlook.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzW8byYE0iXl--K6EjQADhmM"]
[Sun Aug 30 03:11:57.476324 2026] [security2:error] [pid 521505:tid 521630] [remote 185.93.89.167:56175] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "press.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6EkAADIXw"]
[Sun Aug 30 03:11:57.486124 2026] [security2:error] [pid 521505:tid 521752] [client 20.48.160.90:37975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/dex.php"] [unique_id "apPlzW8byYE0iXl--K6ElQAAA5M"]
[Sun Aug 30 03:11:57.487621 2026] [security2:error] [pid 521505:tid 521526] [remote 185.93.89.167:39177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "register.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6ElgADNBQ"]
[Sun Aug 30 03:11:57.492006 2026] [security2:error] [pid 521505:tid 521518] [remote 185.93.89.167:5225] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "preprod.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6EmQADWww"]
[Sun Aug 30 03:11:57.492162 2026] [security2:error] [pid 521505:tid 521608] [remote 185.93.89.167:15109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "linux.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzW8byYE0iXl--K6EmwADV2Y"]
[Sun Aug 30 03:11:57.494851 2026] [security2:error] [pid 521505:tid 521530] [remote 185.93.89.167:14991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "barracuda.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzW8byYE0iXl--K6EngADnRg"]
[Sun Aug 30 03:11:57.495342 2026] [security2:error] [pid 521505:tid 521601] [remote 185.93.89.167:28567] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "user.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzW8byYE0iXl--K6EnwADT18"]
[Sun Aug 30 03:11:57.496292 2026] [security2:error] [pid 521505:tid 521599] [remote 185.93.89.167:15177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "forms.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6EoAADgF0"]
[Sun Aug 30 03:11:57.496785 2026] [security2:error] [pid 521505:tid 521589] [remote 185.93.89.167:1591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thumbs.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzW8byYE0iXl--K6EoQADIFM"]
[Sun Aug 30 03:11:57.498685 2026] [security2:error] [pid 521505:tid 521604] [remote 185.93.89.167:7863] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adserver.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6EowADImI"]
[Sun Aug 30 03:11:57.499932 2026] [security2:error] [pid 521505:tid 521602] [remote 185.93.89.167:37291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "st.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzW8byYE0iXl--K6EpQADQmA"]
[Sun Aug 30 03:11:57.500833 2026] [security2:error] [pid 521505:tid 521610] [remote 185.93.89.167:57009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "static2.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6EqgADPGg"]
[Sun Aug 30 03:11:57.501450 2026] [security2:error] [pid 521505:tid 521626] [remote 185.93.89.167:59097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "web6.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6EqwADZng"]
[Sun Aug 30 03:11:57.504854 2026] [security2:error] [pid 521505:tid 521607] [remote 185.93.89.167:53553] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "demo2.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlzW8byYE0iXl--K6ErQADPmU"]
[Sun Aug 30 03:11:57.510077 2026] [security2:error] [pid 521505:tid 521614] [remote 185.93.89.167:22281] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "labs.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzW8byYE0iXl--K6ErwADTmw"]
[Sun Aug 30 03:11:57.512659 2026] [security2:error] [pid 521505:tid 521612] [remote 185.93.89.167:25969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dbadmin.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzW8byYE0iXl--K6EsgADOWo"]
[Sun Aug 30 03:11:57.513492 2026] [security2:error] [pid 521505:tid 521710] [client 63.143.147.119:0] ModSecurity: Warning. Matched phrase "Octopus" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "barbervillebaptistchurch.org"] [uri "/index.php"] [unique_id "apPlzW8byYE0iXl--K6ElAADaTY"]
[Sun Aug 30 03:11:57.519899 2026] [security2:error] [pid 521505:tid 521741] [client 34.15.159.88:50716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/development/.env"] [unique_id "apPlzW8byYE0iXl--K6EugAAA4g"]
[Sun Aug 30 03:11:57.520173 2026] [security2:error] [pid 521505:tid 521611] [remote 185.93.89.167:42995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns12.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6EuwADdWk"]
[Sun Aug 30 03:11:57.525102 2026] [security2:error] [pid 521505:tid 521622] [remote 185.93.89.167:62949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "board.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzW8byYE0iXl--K6EwAADhHQ"]
[Sun Aug 30 03:11:57.525234 2026] [security2:error] [pid 521505:tid 521737] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "board.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzW8byYE0iXl--K6EwAADhHQ"]
[Sun Aug 30 03:11:57.528018 2026] [security2:error] [pid 521505:tid 521606] [remote 185.93.89.167:24213] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "in.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6EwgADh2Q"]
[Sun Aug 30 03:11:57.531194 2026] [security2:error] [pid 521505:tid 521516] [remote 185.93.89.167:16627] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "education.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6ExwADJgo"]
[Sun Aug 30 03:11:57.542061 2026] [security2:error] [pid 521505:tid 521559] [remote 185.93.89.167:48785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns02.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlzW8byYE0iXl--K6E0QADizU"]
[Sun Aug 30 03:11:57.561666 2026] [security2:error] [pid 521505:tid 521513] [remote 185.93.89.167:37133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kb.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6E2QADUwc"]
[Sun Aug 30 03:11:57.597554 2026] [security2:error] [pid 521505:tid 521562] [remote 185.93.89.167:53853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atlas.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6E6wADPzg"]
[Sun Aug 30 03:11:57.597670 2026] [security2:error] [pid 521505:tid 521615] [remote 185.93.89.167:2579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "love.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6E7QADnW0"]
[Sun Aug 30 03:11:57.597721 2026] [security2:error] [pid 521505:tid 521542] [remote 185.93.89.167:13069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sc.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6E7AADVCQ"]
[Sun Aug 30 03:11:57.598613 2026] [security2:error] [pid 524122:tid 524304] [client 20.151.200.44:45050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/sf.php"] [unique_id "apPlzX3lhEjKFiK_nBJ7FQAAAcI"]
[Sun Aug 30 03:11:57.600902 2026] [security2:error] [pid 521505:tid 521541] [remote 185.93.89.167:4287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "php.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6E8QADMCM"]
[Sun Aug 30 03:11:57.600977 2026] [security2:error] [pid 521505:tid 521547] [remote 185.93.89.167:29333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reg.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6E8AADgCk"]
[Sun Aug 30 03:11:57.602399 2026] [security2:error] [pid 521505:tid 521517] [remote 185.93.89.167:21227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "outlook.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzW8byYE0iXl--K6E9AADQgs"]
[Sun Aug 30 03:11:57.603269 2026] [security2:error] [pid 521505:tid 521507] [remote 185.93.89.167:14833] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "se.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzW8byYE0iXl--K6E9QADKwE"]
[Sun Aug 30 03:11:57.604072 2026] [security2:error] [pid 521505:tid 521704] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/cloud/.env"] [unique_id "apPlzW8byYE0iXl--K6E9gAAA2M"]
[Sun Aug 30 03:11:57.609038 2026] [security2:error] [pid 521505:tid 521506] [remote 185.93.89.167:56175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "press.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6E-AADmgA"]
[Sun Aug 30 03:11:57.620925 2026] [security2:error] [pid 521505:tid 521590] [remote 185.93.89.167:39177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "register.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6E_gADaFQ"]
[Sun Aug 30 03:11:57.625312 2026] [security2:error] [pid 521505:tid 521538] [remote 185.93.89.167:5225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "preprod.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6FAgADmSA"]
[Sun Aug 30 03:11:57.626394 2026] [security2:error] [pid 521505:tid 521512] [remote 185.93.89.167:61033] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzW8byYE0iXl--K6FBAADJAY"]
[Sun Aug 30 03:11:57.629165 2026] [security2:error] [pid 521505:tid 521534] [remote 185.93.89.167:56429] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mb.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzW8byYE0iXl--K6FCQADbBw"]
[Sun Aug 30 03:11:57.631633 2026] [security2:error] [pid 521505:tid 521544] [remote 185.93.89.167:7863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adserver.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6FDAADhCY"]
[Sun Aug 30 03:11:57.633641 2026] [security2:error] [pid 521505:tid 521570] [remote 185.93.89.167:6761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "banner.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzW8byYE0iXl--K6FDwADPUA"]
[Sun Aug 30 03:11:57.634273 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:23169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzW8byYE0iXl--K6FEgADJk0"]
[Sun Aug 30 03:11:57.634704 2026] [security2:error] [pid 524122:tid 524261] [client 64.89.161.160:49282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.161.89.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "memariestyle.com"] [uri "/plugins/file-uploader/server/php/index.php"] [unique_id "apPlzX3lhEjKFiK_nBJ7FwAAAZc"]
[Sun Aug 30 03:11:57.637003 2026] [security2:error] [pid 521505:tid 521757] [client 20.48.160.90:37657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/giodywky.php"] [unique_id "apPlzW8byYE0iXl--K6FFQAAA5g"]
[Sun Aug 30 03:11:57.638172 2026] [security2:error] [pid 521505:tid 521714] [client 20.104.49.130:53704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/ohct.php"] [unique_id "apPlzW8byYE0iXl--K6FFwAAA20"]
[Sun Aug 30 03:11:57.644590 2026] [security2:error] [pid 521505:tid 521558] [remote 185.93.89.167:13143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "net.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzW8byYE0iXl--K6FHAADQzQ"]
[Sun Aug 30 03:11:57.650719 2026] [security2:error] [pid 521505:tid 521574] [remote 185.93.89.167:14681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mc.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzW8byYE0iXl--K6FHwADjUQ"]
[Sun Aug 30 03:11:57.653640 2026] [security2:error] [pid 521505:tid 521525] [remote 185.93.89.167:59215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "users.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzW8byYE0iXl--K6FIgADLBM"]
[Sun Aug 30 03:11:57.656301 2026] [security2:error] [pid 521505:tid 521511] [remote 185.93.89.167:45765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns01.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzW8byYE0iXl--K6FJgADmwU"]
[Sun Aug 30 03:11:57.659121 2026] [security2:error] [pid 521505:tid 521688] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "board.mariegronley.com"] [uri "/index.cgi"] [unique_id "apPlzW8byYE0iXl--K6FKAADU3o"]
[Sun Aug 30 03:11:57.660845 2026] [security2:error] [pid 521505:tid 521528] [remote 185.93.89.167:24213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "in.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6FKwADVhY"]
[Sun Aug 30 03:11:57.662486 2026] [security2:error] [pid 521505:tid 521568] [remote 185.93.89.167:52789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "market.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzW8byYE0iXl--K6FLwADiT4"]
[Sun Aug 30 03:11:57.664039 2026] [security2:error] [pid 521505:tid 521554] [remote 185.93.89.167:16627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "education.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6FNAADeTA"]
[Sun Aug 30 03:11:57.675396 2026] [security2:error] [pid 521505:tid 521536] [remote 185.93.89.167:4349] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mm.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzW8byYE0iXl--K6FPQADTx4"]
[Sun Aug 30 03:11:57.675583 2026] [security2:error] [pid 521505:tid 521588] [remote 185.93.89.167:48785] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "ns02.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlzW8byYE0iXl--K6FPgADKlI"]
[Sun Aug 30 03:11:57.677396 2026] [security2:error] [pid 521505:tid 521586] [remote 185.93.89.167:39923] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sitebuilder.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzW8byYE0iXl--K6FQQADXlA"]
[Sun Aug 30 03:11:57.696370 2026] [security2:error] [pid 521505:tid 521596] [remote 185.93.89.167:11687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pr.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzW8byYE0iXl--K6FTgADf1o"]
[Sun Aug 30 03:11:57.701818 2026] [authz_core:error] [pid 521505:tid 521690] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IE
[Sun Aug 30 03:11:57.702307 2026] [authz_core:error] [pid 521505:tid 521690] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IE
[Sun Aug 30 03:11:57.721327 2026] [security2:error] [pid 521505:tid 521642] [client 34.15.159.88:50716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/production/.env"] [unique_id "apPlzW8byYE0iXl--K6FWwAAAyU"]
[Sun Aug 30 03:11:57.734187 2026] [security2:error] [pid 521505:tid 521526] [remote 185.93.89.167:64795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jp.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzW8byYE0iXl--K6FYwADdRQ"]
[Sun Aug 30 03:11:57.736214 2026] [security2:error] [pid 521505:tid 521530] [remote 185.93.89.167:10845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "campus.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzW8byYE0iXl--K6FaQADZBg"]
[Sun Aug 30 03:11:57.748261 2026] [security2:error] [pid 524122:tid 524331] [client 20.104.49.130:57495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.getabikini.com"] [uri "/edit.php"] [unique_id "apPlzX3lhEjKFiK_nBJ7HgAAAd0"]
[Sun Aug 30 03:11:57.759951 2026] [security2:error] [pid 521505:tid 521609] [remote 185.93.89.167:15109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "linux.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzW8byYE0iXl--K6FegADT2c"]
[Sun Aug 30 03:11:57.763111 2026] [security2:error] [pid 521505:tid 521551] [remote 185.93.89.167:28567] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "user.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzW8byYE0iXl--K6FfgADQi0"]
[Sun Aug 30 03:11:57.766665 2026] [security2:error] [pid 521505:tid 521607] [remote 185.93.89.167:6761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "banner.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzW8byYE0iXl--K6FggADhmU"]
[Sun Aug 30 03:11:57.767556 2026] [security2:error] [pid 521505:tid 521614] [remote 185.93.89.167:37291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "st.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzW8byYE0iXl--K6FhAADK2w"]
[Sun Aug 30 03:11:57.768948 2026] [security2:error] [pid 521505:tid 521711] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/infrastructure/.env"] [unique_id "apPlzW8byYE0iXl--K6FhQAAA2o"]
[Sun Aug 30 03:11:57.772838 2026] [security2:error] [pid 521505:tid 521560] [remote 185.93.89.167:53553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "demo2.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzW8byYE0iXl--K6FiAADjDY"]
[Sun Aug 30 03:11:57.777471 2026] [security2:error] [pid 521505:tid 521552] [remote 185.93.89.167:13143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "net.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzW8byYE0iXl--K6FigADPy4"]
[Sun Aug 30 03:11:57.778463 2026] [security2:error] [pid 521505:tid 521533] [remote 185.93.89.167:22281] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "labs.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzW8byYE0iXl--K6FiwADUhs"]
[Sun Aug 30 03:11:57.783628 2026] [security2:error] [pid 521505:tid 521611] [remote 185.93.89.167:14681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mc.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzW8byYE0iXl--K6FjQADk2k"]
[Sun Aug 30 03:11:57.787509 2026] [security2:error] [pid 521505:tid 521613] [remote 185.93.89.167:54367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webservices.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzW8byYE0iXl--K6FkQADfWs"]
[Sun Aug 30 03:11:57.789357 2026] [security2:error] [pid 521505:tid 521584] [remote 185.93.89.167:45765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns01.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzW8byYE0iXl--K6FlQADcE4"]
[Sun Aug 30 03:11:57.789783 2026] [security2:error] [pid 521505:tid 521581] [remote 185.93.89.167:62291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rs.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzW8byYE0iXl--K6FlAADO0s"]
[Sun Aug 30 03:11:57.791160 2026] [security2:error] [pid 521505:tid 521606] [remote 185.93.89.167:24005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "radius.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzW8byYE0iXl--K6FlwADgGQ"]
[Sun Aug 30 03:11:57.793193 2026] [security2:error] [pid 521505:tid 521762] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "board.mariegronley.com"] [uri "/index.cgi"] [unique_id "apPlzW8byYE0iXl--K6FmQADnSU"]
[Sun Aug 30 03:11:57.795857 2026] [security2:error] [pid 521505:tid 521623] [remote 185.93.89.167:52789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "market.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzW8byYE0iXl--K6FnAADc3U"]
[Sun Aug 30 03:11:57.807280 2026] [security2:error] [pid 521505:tid 521642] [client 20.104.49.130:32831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/css.php"] [unique_id "apPlzW8byYE0iXl--K6FogAAAyU"]
[Sun Aug 30 03:11:57.814774 2026] [security2:error] [pid 521505:tid 521559] [remote 185.93.89.167:4349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mm.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzW8byYE0iXl--K6FpwADhzU"]
[Sun Aug 30 03:11:57.820864 2026] [security2:error] [pid 521505:tid 521632] [remote 185.93.89.167:14659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzW8byYE0iXl--K6FqwADZX4"]
[Sun Aug 30 03:11:57.828175 2026] [security2:error] [pid 521505:tid 521738] [client 20.104.49.130:52130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/log.php"] [unique_id "apPlzW8byYE0iXl--K6FsAAAA4U"]
[Sun Aug 30 03:11:57.831551 2026] [security2:error] [pid 521505:tid 521715] [client 158.23.147.79:39937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apPlzW8byYE0iXl--K6FtQAAA24"]
[Sun Aug 30 03:11:57.852145 2026] [authz_core:error] [pid 524122:tid 524314] [client 66.249.66.74:56300] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:57.852573 2026] [authz_core:error] [pid 524122:tid 524314] [client 66.249.66.74:56300] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:57.867273 2026] [security2:error] [pid 521505:tid 521520] [remote 185.93.89.167:64795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jp.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzW8byYE0iXl--K6FzwADYg4"]
[Sun Aug 30 03:11:57.869472 2026] [security2:error] [pid 521505:tid 521562] [remote 185.93.89.167:10845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "campus.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzW8byYE0iXl--K6F0gADHzg"]
[Sun Aug 30 03:11:57.871203 2026] [security2:error] [pid 521505:tid 521541] [remote 185.93.89.167:44659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "p.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzW8byYE0iXl--K6F1wADUCM"]
[Sun Aug 30 03:11:57.871616 2026] [security2:error] [pid 521505:tid 521547] [remote 185.93.89.167:14833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "se.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzW8byYE0iXl--K6F2AADkyk"]
[Sun Aug 30 03:11:57.886372 2026] [security2:error] [pid 521505:tid 521517] [remote 185.93.89.167:12177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tr.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPlzW8byYE0iXl--K6F4wADXAs"]
[Sun Aug 30 03:11:57.892960 2026] [security2:error] [pid 521505:tid 521514] [remote 185.93.89.167:15109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "linux.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzW8byYE0iXl--K6F5wADZQg"]
[Sun Aug 30 03:11:57.893556 2026] [security2:error] [pid 521505:tid 521506] [remote 185.93.89.167:61033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "analytics.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzW8byYE0iXl--K6F6QADWAA"]
[Sun Aug 30 03:11:57.896287 2026] [security2:error] [pid 521505:tid 521633] [remote 185.93.89.167:56429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mb.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzW8byYE0iXl--K6F7AADKH8"]
[Sun Aug 30 03:11:57.897119 2026] [security2:error] [pid 521505:tid 521590] [remote 185.93.89.167:14991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "barracuda.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzW8byYE0iXl--K6F7QADJlQ"]
[Sun Aug 30 03:11:57.899569 2026] [security2:error] [pid 521505:tid 521565] [remote 185.93.89.167:1591] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzW8byYE0iXl--K6F8AADSjs"]
[Sun Aug 30 03:11:57.900476 2026] [security2:error] [pid 521505:tid 521534] [remote 185.93.89.167:37291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "st.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzW8byYE0iXl--K6F8gADmxw"]
[Sun Aug 30 03:11:57.902598 2026] [security2:error] [pid 521505:tid 521594] [remote 185.93.89.167:23169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www7.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzW8byYE0iXl--K6F9AADYVg"]
[Sun Aug 30 03:11:57.919269 2026] [security2:error] [pid 521505:tid 521629] [remote 185.93.89.167:25969] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dbadmin.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzW8byYE0iXl--K6GAwADLHs"]
[Sun Aug 30 03:11:57.920544 2026] [security2:error] [pid 521505:tid 521537] [remote 185.93.89.167:54367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webservices.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzW8byYE0iXl--K6GBAADQx8"]
[Sun Aug 30 03:11:57.921774 2026] [security2:error] [pid 521505:tid 521577] [remote 185.93.89.167:59215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "users.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzW8byYE0iXl--K6GBQADW0c"]
[Sun Aug 30 03:11:57.922976 2026] [security2:error] [pid 521505:tid 521653] [client 34.15.159.88:50716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/config/app/.env"] [unique_id "apPlzW8byYE0iXl--K6GCQAAAzA"]
[Sun Aug 30 03:11:57.926870 2026] [security2:error] [pid 521505:tid 521532] [remote 185.93.89.167:62949] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "board.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzW8byYE0iXl--K6GDQADURo"]
[Sun Aug 30 03:11:57.927060 2026] [security2:error] [pid 521505:tid 521686] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "board.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzW8byYE0iXl--K6GDQADURo"]
[Sun Aug 30 03:11:57.928236 2026] [security2:error] [pid 521505:tid 521652] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/docker/.env"] [unique_id "apPlzW8byYE0iXl--K6GDgAAAy8"]
[Sun Aug 30 03:11:57.928555 2026] [security2:error] [pid 521505:tid 521647] [client 20.48.160.90:37655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp-kz.php"] [unique_id "apPlzW8byYE0iXl--K6GDwAAAyo"]
[Sun Aug 30 03:11:57.944102 2026] [security2:error] [pid 521505:tid 521617] [remote 185.93.89.167:48785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns02.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzW8byYE0iXl--K6GFgADP28"]
[Sun Aug 30 03:11:57.946256 2026] [security2:error] [pid 521505:tid 521509] [remote 185.93.89.167:39923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sitebuilder.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzW8byYE0iXl--K6GFwADlAM"]
[Sun Aug 30 03:11:57.976757 2026] [security2:error] [pid 521505:tid 521733] [client 4.205.62.107:17676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/aws_secret_config.php"] [unique_id "apPlzW8byYE0iXl--K6GKQAAA4A"]
[Sun Aug 30 03:11:57.984042 2026] [security2:error] [pid 524122:tid 524359] [client 20.104.50.220:17332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/file9.php"] [unique_id "apPlzX3lhEjKFiK_nBJ7KAAAAfk"]
[Sun Aug 30 03:11:57.984492 2026] [security2:error] [pid 521505:tid 521662] [client 20.104.18.15:2023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/BDKR28WP.php"] [unique_id "apPlzW8byYE0iXl--K6GKwAAAzk"]
[Sun Aug 30 03:11:57.987543 2026] [security2:error] [pid 524122:tid 524350] [client 20.104.18.15:16943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/pri.php"] [unique_id "apPlzX3lhEjKFiK_nBJ7KQAAAfA"]
[Sun Aug 30 03:11:57.990470 2026] [security2:error] [pid 521505:tid 521715] [client 20.104.50.220:25470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/wander.php"] [unique_id "apPlzW8byYE0iXl--K6GMAAAA24"]
[Sun Aug 30 03:11:57.993750 2026] [authz_core:error] [pid 521505:tid 521725] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory22
[Sun Aug 30 03:11:57.994029 2026] [authz_core:error] [pid 521505:tid 521725] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory22
[Sun Aug 30 03:11:58.004945 2026] [security2:error] [pid 521505:tid 521554] [remote 185.93.89.167:21227] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "outlook.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzm8byYE0iXl--K6GOwADUzA"]
[Sun Aug 30 03:11:58.004963 2026] [security2:error] [pid 521505:tid 521536] [remote 185.93.89.167:14833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "se.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzm8byYE0iXl--K6GQQADnR4"]
[Sun Aug 30 03:11:58.008547 2026] [security2:error] [pid 521505:tid 521742] [client 20.151.200.44:45022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/4e.php"] [unique_id "apPlzm8byYE0iXl--K6GQwAAA4k"]
[Sun Aug 30 03:11:58.011545 2026] [security2:error] [pid 521505:tid 521638] [client 20.104.50.220:33304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/p0wny-shell.php"] [unique_id "apPlzm8byYE0iXl--K6GRgAAAyE"]
[Sun Aug 30 03:11:58.020924 2026] [security2:error] [pid 521505:tid 521586] [remote 185.93.89.167:12177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "tr.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPlzm8byYE0iXl--K6GRwADbVA"]
[Sun Aug 30 03:11:58.021792 2026] [security2:error] [pid 521505:tid 521649] [client 20.48.251.3:52220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/aws_secret_config.php"] [unique_id "apPlzm8byYE0iXl--K6GSQAAAyw"]
[Sun Aug 30 03:11:58.022013 2026] [security2:error] [pid 521505:tid 521672] [client 20.104.50.220:61971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/fffff.php"] [unique_id "apPlzm8byYE0iXl--K6GSgAAA0M"]
[Sun Aug 30 03:11:58.026703 2026] [security2:error] [pid 521505:tid 521529] [remote 185.93.89.167:61033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "analytics.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzm8byYE0iXl--K6GTgADMBc"]
[Sun Aug 30 03:11:58.029281 2026] [security2:error] [pid 521505:tid 521592] [remote 185.93.89.167:56429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mb.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzm8byYE0iXl--K6GUAADOlY"]
[Sun Aug 30 03:11:58.030770 2026] [security2:error] [pid 521505:tid 521557] [remote 185.93.89.167:28567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "user.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzm8byYE0iXl--K6GUgADIzM"]
[Sun Aug 30 03:11:58.033965 2026] [security2:error] [pid 521505:tid 521689] [client 63.135.161.116:42477] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/000.php"] [unique_id "apPlzm8byYE0iXl--K6GVwAAA1Q"]
[Sun Aug 30 03:11:58.034460 2026] [security2:error] [pid 521505:tid 521530] [remote 185.93.89.167:6761] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "banner.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzm8byYE0iXl--K6GVgADVhg"]
[Sun Aug 30 03:11:58.035748 2026] [security2:error] [pid 521505:tid 521563] [remote 185.93.89.167:23169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www7.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzm8byYE0iXl--K6GWAADYzk"]
[Sun Aug 30 03:11:58.041805 2026] [security2:error] [pid 521505:tid 521723] [client 20.104.18.15:51086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/samll.php"] [unique_id "apPlzm8byYE0iXl--K6GYAAAA3Y"]
[Sun Aug 30 03:11:58.045434 2026] [security2:error] [pid 521505:tid 521582] [remote 185.93.89.167:13143] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "net.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzm8byYE0iXl--K6GYwADZkw"]
[Sun Aug 30 03:11:58.046161 2026] [security2:error] [pid 521505:tid 521601] [remote 185.93.89.167:22281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "labs.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzm8byYE0iXl--K6GZAADUF8"]
[Sun Aug 30 03:11:58.051769 2026] [security2:error] [pid 521505:tid 521595] [remote 185.93.89.167:14681] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mc.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzm8byYE0iXl--K6GZwADk1k"]
[Sun Aug 30 03:11:58.052902 2026] [security2:error] [pid 521505:tid 521667] [client 20.104.49.130:43320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/sta.php"] [unique_id "apPlzm8byYE0iXl--K6GaQAAAz4"]
[Sun Aug 30 03:11:58.058090 2026] [security2:error] [pid 521505:tid 521589] [remote 185.93.89.167:45765] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns01.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzm8byYE0iXl--K6GcgADWFM"]
[Sun Aug 30 03:11:58.059607 2026] [security2:error] [pid 521505:tid 521604] [remote 185.93.89.167:24005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "radius.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzm8byYE0iXl--K6GcwADbmI"]
[Sun Aug 30 03:11:58.060433 2026] [security2:error] [pid 521505:tid 521659] [client 20.48.160.90:37752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp-includes/ID3/getid.php"] [unique_id "apPlzm8byYE0iXl--K6GdgAAAzY"]
[Sun Aug 30 03:11:58.061629 2026] [security2:error] [pid 521505:tid 521712] [client 20.48.251.3:59302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/gjm.php"] [unique_id "apPlzm8byYE0iXl--K6GdwAAA2s"]
[Sun Aug 30 03:11:58.061634 2026] [security2:error] [pid 521505:tid 521645] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "board.mariegronley.com"] [uri "/index.cgi"] [unique_id "apPlzm8byYE0iXl--K6GdQADKGc"]
[Sun Aug 30 03:11:58.063468 2026] [security2:error] [pid 521505:tid 521569] [remote 185.93.89.167:52789] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "market.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzm8byYE0iXl--K6GeAADSz8"]
[Sun Aug 30 03:11:58.065590 2026] [authz_core:error] [pid 521505:tid 521743] [client 66.249.66.76:49738] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:58.066065 2026] [authz_core:error] [pid 521505:tid 521743] [client 66.249.66.76:49738] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:58.070558 2026] [security2:error] [pid 521505:tid 521551] [remote 185.93.89.167:62291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rs.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzm8byYE0iXl--K6GgAADdC0"]
[Sun Aug 30 03:11:58.079462 2026] [security2:error] [pid 521505:tid 521626] [remote 185.93.89.167:39923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sitebuilder.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzm8byYE0iXl--K6GhQADMXg"]
[Sun Aug 30 03:11:58.079605 2026] [security2:error] [pid 521505:tid 521747] [client 20.48.251.3:54827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/ms.php"] [unique_id "apPlzm8byYE0iXl--K6GhgAAA44"]
[Sun Aug 30 03:11:58.089358 2026] [security2:error] [pid 521505:tid 521640] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/k8s/.env"] [unique_id "apPlzm8byYE0iXl--K6GigAAAyM"]
[Sun Aug 30 03:11:58.090398 2026] [security2:error] [pid 521505:tid 521603] [remote 185.93.89.167:14659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzm8byYE0iXl--K6GjAADVGE"]
[Sun Aug 30 03:11:58.098146 2026] [authz_core:error] [pid 524122:tid 524302] [client 216.73.216.128:46334] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:58.098403 2026] [authz_core:error] [pid 524122:tid 524302] [client 216.73.216.128:46334] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:58.099172 2026] [security2:error] [pid 521505:tid 521614] [remote 185.93.89.167:11687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pr.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzm8byYE0iXl--K6GkQADl2w"]
[Sun Aug 30 03:11:58.106742 2026] [security2:error] [pid 521505:tid 521685] [client 20.104.18.15:31657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/dev.php"] [unique_id "apPlzm8byYE0iXl--K6GlAAAA1A"]
[Sun Aug 30 03:11:58.126831 2026] [security2:error] [pid 521505:tid 521739] [client 20.104.49.130:63247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/amax.php"] [unique_id "apPlzm8byYE0iXl--K6GmwAAA4Y"]
[Sun Aug 30 03:11:58.135941 2026] [security2:error] [pid 521505:tid 521673] [client 34.15.159.88:50716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/phpinfo.php"] [unique_id "apPlzm8byYE0iXl--K6GmQAAA0Q"]
[Sun Aug 30 03:11:58.136827 2026] [security2:error] [pid 521505:tid 521597] [remote 185.93.89.167:64795] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jp.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzm8byYE0iXl--K6GogADXFs"]
[Sun Aug 30 03:11:58.139988 2026] [security2:error] [pid 521505:tid 521552] [remote 185.93.89.167:10845] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "campus.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzm8byYE0iXl--K6GqAADWC4"]
[Sun Aug 30 03:11:58.140017 2026] [security2:error] [pid 521505:tid 521560] [remote 185.93.89.167:44659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "p.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzm8byYE0iXl--K6GpwADaDY"]
[Sun Aug 30 03:11:58.149938 2026] [security2:error] [pid 521505:tid 521729] [client 20.104.50.220:31180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-links.php"] [unique_id "apPlzm8byYE0iXl--K6GrAAAA3w"]
[Sun Aug 30 03:11:58.160994 2026] [authz_core:error] [pid 521505:tid 521716] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_CA
[Sun Aug 30 03:11:58.161434 2026] [security2:error] [pid 521505:tid 521611] [remote 185.93.89.167:15109] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "linux.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzm8byYE0iXl--K6GtwADLGk"]
[Sun Aug 30 03:11:58.161445 2026] [authz_core:error] [pid 521505:tid 521716] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_CA
[Sun Aug 30 03:11:58.164108 2026] [security2:error] [pid 521505:tid 521613] [remote 185.93.89.167:28567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "user.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzm8byYE0iXl--K6GuQADWWs"]
[Sun Aug 30 03:11:58.165175 2026] [security2:error] [pid 521505:tid 521619] [remote 185.93.89.167:14991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "barracuda.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzm8byYE0iXl--K6GugADMHE"]
[Sun Aug 30 03:11:58.167574 2026] [security2:error] [pid 521505:tid 521585] [remote 185.93.89.167:6761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "banner.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzm8byYE0iXl--K6GvQADPU8"]
[Sun Aug 30 03:11:58.168025 2026] [security2:error] [pid 521505:tid 521584] [remote 185.93.89.167:37291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "st.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzm8byYE0iXl--K6GvwADZE4"]
[Sun Aug 30 03:11:58.168064 2026] [security2:error] [pid 521505:tid 521618] [remote 185.93.89.167:1591] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzm8byYE0iXl--K6GvgADW3A"]
[Sun Aug 30 03:11:58.176822 2026] [security2:error] [pid 521505:tid 521606] [remote 185.93.89.167:53553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "demo2.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzm8byYE0iXl--K6GxAADIGQ"]
[Sun Aug 30 03:11:58.178311 2026] [security2:error] [pid 521505:tid 521622] [remote 185.93.89.167:13143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "net.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzm8byYE0iXl--K6GxQADO3Q"]
[Sun Aug 30 03:11:58.179153 2026] [security2:error] [pid 521505:tid 521543] [remote 185.93.89.167:22281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "labs.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzm8byYE0iXl--K6GxgADUSU"]
[Sun Aug 30 03:11:58.184562 2026] [security2:error] [pid 521505:tid 521625] [remote 185.93.89.167:14681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mc.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzm8byYE0iXl--K6GyAADXXc"]
[Sun Aug 30 03:11:58.188201 2026] [security2:error] [pid 521505:tid 521707] [client 20.151.200.44:45047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/ssss.php"] [unique_id "apPlzm8byYE0iXl--K6GyQAAA2Y"]
[Sun Aug 30 03:11:58.188285 2026] [security2:error] [pid 521505:tid 521753] [client 20.104.50.220:62826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/dd.php"] [unique_id "apPlzm8byYE0iXl--K6GywAAA5Q"]
[Sun Aug 30 03:11:58.188385 2026] [security2:error] [pid 521505:tid 521685] [client 4.205.62.107:16354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/wp-konfig.php"] [unique_id "apPlzm8byYE0iXl--K6GygAAA1A"]
[Sun Aug 30 03:11:58.189909 2026] [security2:error] [pid 521505:tid 521516] [remote 185.93.89.167:59215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "users.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzm8byYE0iXl--K6GzgADYgo"]
[Sun Aug 30 03:11:58.190477 2026] [security2:error] [pid 521505:tid 521546] [remote 185.93.89.167:25969] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dbadmin.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzm8byYE0iXl--K6GzQADkyg"]
[Sun Aug 30 03:11:58.191092 2026] [security2:error] [pid 521505:tid 521515] [remote 185.93.89.167:45765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns01.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzm8byYE0iXl--K6GzwADPgk"]
[Sun Aug 30 03:11:58.193199 2026] [security2:error] [pid 521505:tid 521700] [client 20.48.160.90:61542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/session.php"] [unique_id "apPlzm8byYE0iXl--K6G0QAAA18"]
[Sun Aug 30 03:11:58.194820 2026] [security2:error] [pid 521505:tid 521631] [remote 185.93.89.167:62949] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "board.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzm8byYE0iXl--K6G0gADNH0"]
[Sun Aug 30 03:11:58.194935 2026] [security2:error] [pid 521505:tid 521657] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "board.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzm8byYE0iXl--K6G0gADNH0"]
[Sun Aug 30 03:11:58.196512 2026] [security2:error] [pid 521505:tid 521556] [remote 185.93.89.167:52789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "market.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzm8byYE0iXl--K6G0wADbDI"]
[Sun Aug 30 03:11:58.197935 2026] [security2:error] [pid 521505:tid 521701] [client 20.104.50.220:6090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/index2.php"] [unique_id "apPlzm8byYE0iXl--K6G1AAAA2A"]
[Sun Aug 30 03:11:58.200597 2026] [security2:error] [pid 521505:tid 521739] [client 4.205.62.107:25895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/product.php"] [unique_id "apPlzm8byYE0iXl--K6G1QAAA4Y"]
[Sun Aug 30 03:11:58.207983 2026] [security2:error] [pid 521505:tid 521674] [client 158.23.147.79:40009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/login.php"] [unique_id "apPlzm8byYE0iXl--K6G2AAAA0U"]
[Sun Aug 30 03:11:58.222781 2026] [security2:error] [pid 521505:tid 521727] [client 4.205.62.107:16333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlzm8byYE0iXl--K6G4AAAA3o"]
[Sun Aug 30 03:11:58.232171 2026] [security2:error] [pid 521505:tid 521520] [remote 185.93.89.167:11687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pr.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzm8byYE0iXl--K6G4wADHw4"]
[Sun Aug 30 03:11:58.232828 2026] [security2:error] [pid 521505:tid 521733] [client 4.205.62.107:52809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/ah25.php"] [unique_id "apPlzm8byYE0iXl--K6G5QAAA4A"]
[Sun Aug 30 03:11:58.249300 2026] [security2:error] [pid 521505:tid 521706] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/kubernetes/.env"] [unique_id "apPlzm8byYE0iXl--K6G6QAAA2U"]
[Sun Aug 30 03:11:58.254033 2026] [security2:error] [pid 524122:tid 524374] [client 20.104.49.130:53707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/bdroot.php"] [unique_id "apPlzn3lhEjKFiK_nBJ7OAAAAgg"]
[Sun Aug 30 03:11:58.270523 2026] [security2:error] [pid 521505:tid 521564] [remote 185.93.89.167:64795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jp.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzm8byYE0iXl--K6G8AADdDo"]
[Sun Aug 30 03:11:58.273371 2026] [security2:error] [pid 521505:tid 521510] [remote 185.93.89.167:10845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "campus.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzm8byYE0iXl--K6G9wADWQQ"]
[Sun Aug 30 03:11:58.273864 2026] [security2:error] [pid 521505:tid 521562] [remote 185.93.89.167:21227] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "outlook.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzm8byYE0iXl--K6G9QADnTg"]
[Sun Aug 30 03:11:58.274597 2026] [security2:error] [pid 521505:tid 521531] [remote 185.93.89.167:14833] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "se.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzm8byYE0iXl--K6G8wADIRk"]
[Sun Aug 30 03:11:58.288441 2026] [security2:error] [pid 521505:tid 521541] [remote 185.93.89.167:12177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tr.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPlzm8byYE0iXl--K6HAgADmyM"]
[Sun Aug 30 03:11:58.289472 2026] [security2:error] [pid 521505:tid 521640] [client 20.48.251.3:37129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/paths.php"] [unique_id "apPlzm8byYE0iXl--K6HAwAAAyM"]
[Sun Aug 30 03:11:58.294445 2026] [security2:error] [pid 521505:tid 521615] [remote 185.93.89.167:61033] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzm8byYE0iXl--K6HBQADfm0"]
[Sun Aug 30 03:11:58.294609 2026] [security2:error] [pid 521505:tid 521542] [remote 185.93.89.167:15109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "linux.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzm8byYE0iXl--K6HBgADICQ"]
[Sun Aug 30 03:11:58.297551 2026] [security2:error] [pid 521505:tid 521547] [remote 185.93.89.167:56429] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mb.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzm8byYE0iXl--K6HBwADXSk"]
[Sun Aug 30 03:11:58.301164 2026] [security2:error] [pid 521505:tid 521506] [remote 185.93.89.167:37291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "st.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzm8byYE0iXl--K6HDAADPgA"]
[Sun Aug 30 03:11:58.304179 2026] [security2:error] [pid 521505:tid 521507] [remote 185.93.89.167:23169] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzm8byYE0iXl--K6HDgADUgE"]
[Sun Aug 30 03:11:58.310477 2026] [security2:error] [pid 521505:tid 521633] [remote 185.93.89.167:53553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "demo2.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzm8byYE0iXl--K6HEAADTX8"]
[Sun Aug 30 03:11:58.321389 2026] [security2:error] [pid 521505:tid 521678] [client 20.104.49.130:60643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/sd.php"] [unique_id "apPlzm8byYE0iXl--K6HFQAAA0k"]
[Sun Aug 30 03:11:58.322985 2026] [security2:error] [pid 521505:tid 521512] [remote 185.93.89.167:59215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "users.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzm8byYE0iXl--K6HFwADQgY"]
[Sun Aug 30 03:11:58.324372 2026] [security2:error] [pid 521505:tid 521748] [client 20.48.160.90:37732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/eagle.php"] [unique_id "apPlzm8byYE0iXl--K6HGQAAA48"]
[Sun Aug 30 03:11:58.325201 2026] [security2:error] [pid 521505:tid 521594] [remote 185.93.89.167:54367] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webservices.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzm8byYE0iXl--K6HGwADK1g"]
[Sun Aug 30 03:11:58.327158 2026] [security2:error] [pid 521505:tid 521548] [remote 185.93.89.167:24005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radius.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzm8byYE0iXl--K6HHAADXio"]
[Sun Aug 30 03:11:58.329431 2026] [security2:error] [pid 521505:tid 521759] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "board.mariegronley.com"] [uri "/index.cgi"] [unique_id "apPlzm8byYE0iXl--K6HHQADmio"]
[Sun Aug 30 03:11:58.345935 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:48785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns02.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzm8byYE0iXl--K6HJwADkk0"]
[Sun Aug 30 03:11:58.347526 2026] [security2:error] [pid 521505:tid 521561] [remote 185.93.89.167:39923] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sitebuilder.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzm8byYE0iXl--K6HKAADVzc"]
[Sun Aug 30 03:11:58.350371 2026] [security2:error] [pid 521505:tid 521580] [remote 185.93.89.167:62291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rs.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzm8byYE0iXl--K6HKgADMko"]
[Sun Aug 30 03:11:58.354311 2026] [security2:error] [pid 521505:tid 521644] [client 31.170.14.25:35210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.14.170.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luxielectronics.com"] [uri "/wp-login.php"] [unique_id "apPlzm8byYE0iXl--K6HJAAAAyc"]
[Sun Aug 30 03:11:58.358141 2026] [security2:error] [pid 521505:tid 521629] [remote 185.93.89.167:14659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "otrs.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzm8byYE0iXl--K6HLAADYXs"]
[Sun Aug 30 03:11:58.382654 2026] [security2:error] [pid 521505:tid 521755] [client 158.23.147.79:58410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-admin/css/index.php"] [unique_id "apPlzm8byYE0iXl--K6HMAAAA5Y"]
[Sun Aug 30 03:11:58.390062 2026] [security2:error] [pid 521505:tid 521746] [client 20.48.160.90:61594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPlzm8byYE0iXl--K6HMQAAA40"]
[Sun Aug 30 03:11:58.399306 2026] [security2:error] [pid 521505:tid 521694] [client 20.104.18.15:18280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/wp-trackback.php"] [unique_id "apPlzm8byYE0iXl--K6HNAAAA1k"]
[Sun Aug 30 03:11:58.407967 2026] [security2:error] [pid 521505:tid 521566] [remote 185.93.89.167:14833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "se.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzm8byYE0iXl--K6HOwADeTw"]
[Sun Aug 30 03:11:58.408537 2026] [security2:error] [pid 521505:tid 521532] [remote 185.93.89.167:44659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzm8byYE0iXl--K6HPQADfBo"]
[Sun Aug 30 03:11:58.409227 2026] [security2:error] [pid 521505:tid 521680] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/terraform/.env"] [unique_id "apPlzm8byYE0iXl--K6HPAAAA0s"]
[Sun Aug 30 03:11:58.427664 2026] [security2:error] [pid 521505:tid 521519] [remote 185.93.89.167:61033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "analytics.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzm8byYE0iXl--K6HSQADdg0"]
[Sun Aug 30 03:11:58.430287 2026] [security2:error] [pid 521505:tid 521757] [client 20.151.200.44:44942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/zoz.php"] [unique_id "apPlzm8byYE0iXl--K6HTgAAA5g"]
[Sun Aug 30 03:11:58.430578 2026] [security2:error] [pid 521505:tid 521571] [remote 185.93.89.167:56429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mb.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzm8byYE0iXl--K6HTwADYkE"]
[Sun Aug 30 03:11:58.433510 2026] [security2:error] [pid 521505:tid 521617] [remote 185.93.89.167:28567] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "user.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzm8byYE0iXl--K6HUgADPm8"]
[Sun Aug 30 03:11:58.433838 2026] [security2:error] [pid 521505:tid 521509] [remote 185.93.89.167:14991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "barracuda.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzm8byYE0iXl--K6HUwADkwM"]
[Sun Aug 30 03:11:58.435653 2026] [security2:error] [pid 521505:tid 521587] [remote 185.93.89.167:1591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thumbs.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzm8byYE0iXl--K6HVwADL1E"]
[Sun Aug 30 03:11:58.437249 2026] [security2:error] [pid 521505:tid 521628] [remote 185.93.89.167:23169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www7.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzm8byYE0iXl--K6HWAADU3o"]
[Sun Aug 30 03:11:58.445078 2026] [security2:error] [pid 521505:tid 521739] [client 20.104.50.220:56718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/indeex.php"] [unique_id "apPlzm8byYE0iXl--K6HXgAAA4Y"]
[Sun Aug 30 03:11:58.447218 2026] [security2:error] [pid 521505:tid 521567] [remote 185.93.89.167:22281] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "labs.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzm8byYE0iXl--K6HYAADST0"]
[Sun Aug 30 03:11:58.453351 2026] [security2:error] [pid 521505:tid 521662] [client 20.104.49.130:53696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/talkxkej.php"] [unique_id "apPlzm8byYE0iXl--K6HZwAAAzk"]
[Sun Aug 30 03:11:58.460016 2026] [security2:error] [pid 521505:tid 521645] [client 20.48.160.90:61476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/up-kon.php"] [unique_id "apPlzm8byYE0iXl--K6HbQAAAyg"]
[Sun Aug 30 03:11:58.460286 2026] [security2:error] [pid 521505:tid 521573] [remote 185.93.89.167:24005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radius.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzm8byYE0iXl--K6HbgADkkM"]
[Sun Aug 30 03:11:58.460632 2026] [security2:error] [pid 521505:tid 521539] [remote 185.93.89.167:25969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dbadmin.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzm8byYE0iXl--K6HbwADVyE"]
[Sun Aug 30 03:11:58.462144 2026] [security2:error] [pid 521505:tid 521522] [remote 185.93.89.167:62949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "board.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzm8byYE0iXl--K6HcQADYRA"]
[Sun Aug 30 03:11:58.462256 2026] [security2:error] [pid 521505:tid 521702] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "board.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzm8byYE0iXl--K6HcQADYRA"]
[Sun Aug 30 03:11:58.464769 2026] [authz_core:error] [pid 524122:tid 524315] [client 216.73.216.128:46334] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:58.465212 2026] [authz_core:error] [pid 524122:tid 524315] [client 216.73.216.128:46334] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:58.470192 2026] [authz_core:error] [pid 521505:tid 521737] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory20
[Sun Aug 30 03:11:58.470455 2026] [authz_core:error] [pid 521505:tid 521737] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory20
[Sun Aug 30 03:11:58.479163 2026] [security2:error] [pid 521505:tid 521586] [remote 185.93.89.167:48785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns02.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzm8byYE0iXl--K6HeAADVVA"]
[Sun Aug 30 03:11:58.480724 2026] [security2:error] [pid 521505:tid 521529] [remote 185.93.89.167:39923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sitebuilder.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzm8byYE0iXl--K6HewADMBc"]
[Sun Aug 30 03:11:58.486386 2026] [security2:error] [pid 521505:tid 521714] [client 20.151.200.44:26514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/ssh3ll.php"] [unique_id "apPlzm8byYE0iXl--K6HfAAAA20"]
[Sun Aug 30 03:11:58.489747 2026] [security2:error] [pid 521505:tid 521596] [remote 185.93.89.167:62291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rs.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzm8byYE0iXl--K6HfQADeVo"]
[Sun Aug 30 03:11:58.491389 2026] [security2:error] [pid 521505:tid 521576] [remote 185.93.89.167:14659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "otrs.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzm8byYE0iXl--K6HfgADfEY"]
[Sun Aug 30 03:11:58.532929 2026] [security2:error] [pid 521505:tid 521663] [client 20.48.160.90:37768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlzm8byYE0iXl--K6HigAAAzo"]
[Sun Aug 30 03:11:58.541920 2026] [security2:error] [pid 521505:tid 521530] [remote 185.93.89.167:44659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzm8byYE0iXl--K6HkwADYxg"]
[Sun Aug 30 03:11:58.542255 2026] [security2:error] [pid 521505:tid 521518] [remote 185.93.89.167:21227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "outlook.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzm8byYE0iXl--K6HlgADNAw"]
[Sun Aug 30 03:11:58.566814 2026] [security2:error] [pid 521505:tid 521601] [remote 185.93.89.167:28567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "user.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzm8byYE0iXl--K6HoAADXl8"]
[Sun Aug 30 03:11:58.567175 2026] [security2:error] [pid 521505:tid 521595] [remote 185.93.89.167:14991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "barracuda.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzm8byYE0iXl--K6HoQADmlk"]
[Sun Aug 30 03:11:58.568615 2026] [security2:error] [pid 521505:tid 521630] [remote 185.93.89.167:1591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thumbs.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzm8byYE0iXl--K6HowADh3w"]
[Sun Aug 30 03:11:58.577505 2026] [security2:error] [pid 521505:tid 521724] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/ansible/.env"] [unique_id "apPlzm8byYE0iXl--K6HqwAAA3c"]
[Sun Aug 30 03:11:58.580499 2026] [security2:error] [pid 521505:tid 521604] [remote 185.93.89.167:22281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "labs.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzm8byYE0iXl--K6HsAADV2I"]
[Sun Aug 30 03:11:58.580499 2026] [security2:error] [pid 524122:tid 524292] [client 20.104.50.220:62786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-content/uploads/simple-file-list/DC.php"] [unique_id "apPlzn3lhEjKFiK_nBJ7RAAAAbY"]
[Sun Aug 30 03:11:58.588055 2026] [authz_core:error] [pid 521505:tid 521675] [client 66.249.66.70:53198] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:58.588507 2026] [authz_core:error] [pid 521505:tid 521675] [client 66.249.66.70:53198] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:58.590570 2026] [security2:error] [pid 521505:tid 521602] [remote 185.93.89.167:59215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "users.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzm8byYE0iXl--K6HvAADcGA"]
[Sun Aug 30 03:11:58.594237 2026] [security2:error] [pid 521505:tid 521578] [remote 185.93.89.167:54367] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webservices.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzm8byYE0iXl--K6HvgADdEg"]
[Sun Aug 30 03:11:58.594895 2026] [security2:error] [pid 521505:tid 521521] [remote 185.93.89.167:25969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dbadmin.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzm8byYE0iXl--K6HwAADiw8"]
[Sun Aug 30 03:11:58.595143 2026] [security2:error] [pid 521505:tid 521626] [remote 185.93.89.167:62949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "board.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzm8byYE0iXl--K6HwQADjXg"]
[Sun Aug 30 03:11:58.595307 2026] [security2:error] [pid 521505:tid 521746] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "board.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzm8byYE0iXl--K6HwQADjXg"]
[Sun Aug 30 03:11:58.609322 2026] [security2:error] [pid 521505:tid 521743] [client 20.48.160.90:38014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/tinny.php"] [unique_id "apPlzm8byYE0iXl--K6HxQAAA4o"]
[Sun Aug 30 03:11:58.629058 2026] [security2:error] [pid 524122:tid 524300] [client 20.104.49.130:52157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/run.php"] [unique_id "apPlzn3lhEjKFiK_nBJ7RgAAAb4"]
[Sun Aug 30 03:11:58.635081 2026] [security2:error] [pid 521505:tid 521616] [remote 185.93.89.167:11687] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pr.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzm8byYE0iXl--K6H0wADk24"]
[Sun Aug 30 03:11:58.644483 2026] [security2:error] [pid 521505:tid 521640] [client 68.155.159.216:52320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-content/packed.php"] [unique_id "apPlzm8byYE0iXl--K6H1gAAAyM"]
[Sun Aug 30 03:11:58.669006 2026] [authz_core:error] [pid 521505:tid 521753] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IL
[Sun Aug 30 03:11:58.669424 2026] [authz_core:error] [pid 521505:tid 521753] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IL
[Sun Aug 30 03:11:58.674384 2026] [security2:error] [pid 521505:tid 521671] [client 20.48.160.90:61587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/ser.php"] [unique_id "apPlzm8byYE0iXl--K6H4gAAA0I"]
[Sun Aug 30 03:11:58.675398 2026] [security2:error] [pid 521505:tid 521560] [remote 185.93.89.167:21227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "outlook.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzm8byYE0iXl--K6H5QADejY"]
[Sun Aug 30 03:11:58.690311 2026] [security2:error] [pid 521505:tid 521533] [remote 185.93.89.167:12177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tr.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPlzm8byYE0iXl--K6H8AADNhs"]
[Sun Aug 30 03:11:58.711967 2026] [security2:error] [pid 521505:tid 521755] [client 20.151.200.44:62916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/wp-content/admin.php"] [unique_id "apPlzm8byYE0iXl--K6H_QAAA5Y"]
[Sun Aug 30 03:11:58.714115 2026] [security2:error] [pid 521505:tid 521606] [remote 185.93.89.167:53553] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "demo2.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzm8byYE0iXl--K6IAAADRGQ"]
[Sun Aug 30 03:11:58.723420 2026] [security2:error] [pid 521505:tid 521543] [remote 185.93.89.167:59215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "users.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzm8byYE0iXl--K6IBQADbSU"]
[Sun Aug 30 03:11:58.727989 2026] [security2:error] [pid 521505:tid 521516] [remote 185.93.89.167:24005] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "radius.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzm8byYE0iXl--K6ICgADeAo"]
[Sun Aug 30 03:11:58.730650 2026] [security2:error] [pid 521505:tid 521679] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "board.mariegronley.com"] [uri "/index.cgi"] [unique_id "apPlzm8byYE0iXl--K6ICwADSig"]
[Sun Aug 30 03:11:58.739302 2026] [security2:error] [pid 521505:tid 521691] [client 34.15.159.88:50720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/info.php"] [unique_id "apPlzm8byYE0iXl--K6IEQAAA1Y"]
[Sun Aug 30 03:11:58.741098 2026] [security2:error] [pid 521505:tid 521730] [client 20.151.200.44:44986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/kcs.php"] [unique_id "apPlzm8byYE0iXl--K6IFAAAA30"]
[Sun Aug 30 03:11:58.743623 2026] [security2:error] [pid 521505:tid 521663] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/.git/.env"] [unique_id "apPlzm8byYE0iXl--K6IFQAAAzo"]
[Sun Aug 30 03:11:58.760177 2026] [security2:error] [pid 521505:tid 521631] [remote 185.93.89.167:14659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzm8byYE0iXl--K6IHAADNH0"]
[Sun Aug 30 03:11:58.764593 2026] [security2:error] [pid 521505:tid 521720] [client 20.48.160.90:37653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp-easy.php"] [unique_id "apPlzm8byYE0iXl--K6IHQAAA3M"]
[Sun Aug 30 03:11:58.770673 2026] [security2:error] [pid 521505:tid 521559] [remote 185.93.89.167:62291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rs.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzm8byYE0iXl--K6IHwADXjU"]
[Sun Aug 30 03:11:58.791458 2026] [authz_core:error] [pid 524122:tid 524348] [client 66.249.66.66:60972] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:58.791961 2026] [authz_core:error] [pid 524122:tid 524348] [client 66.249.66.66:60972] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:58.804461 2026] [security2:error] [pid 521505:tid 521659] [client 20.104.49.130:64110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/srontol.php"] [unique_id "apPlzm8byYE0iXl--K6IKQAAAzY"]
[Sun Aug 30 03:11:58.809427 2026] [security2:error] [pid 521505:tid 521642] [client 20.48.160.90:37775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/431.php"] [unique_id "apPlzm8byYE0iXl--K6ILgAAAyU"]
[Sun Aug 30 03:11:58.811711 2026] [security2:error] [pid 521505:tid 521579] [remote 185.93.89.167:44659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "p.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzm8byYE0iXl--K6ILwADRUk"]
[Sun Aug 30 03:11:58.823449 2026] [security2:error] [pid 521505:tid 521513] [remote 185.93.89.167:12177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tr.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPlzm8byYE0iXl--K6INwADLQc"]
[Sun Aug 30 03:11:58.834050 2026] [security2:error] [pid 521505:tid 521743] [client 158.23.147.79:39958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/hehehehe.php"] [unique_id "apPlzm8byYE0iXl--K6IQAAAA4o"]
[Sun Aug 30 03:11:58.836042 2026] [security2:error] [pid 521505:tid 521562] [remote 185.93.89.167:1591] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzm8byYE0iXl--K6IQwADjTg"]
[Sun Aug 30 03:11:58.836676 2026] [security2:error] [pid 521505:tid 521531] [remote 185.93.89.167:14991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "barracuda.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzm8byYE0iXl--K6IRAADiRk"]
[Sun Aug 30 03:11:58.846341 2026] [authz_core:error] [pid 521505:tid 521760] [client 66.249.66.204:44429] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:58.846719 2026] [authz_core:error] [pid 521505:tid 521760] [client 66.249.66.204:44429] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:58.861182 2026] [security2:error] [pid 521505:tid 521627] [remote 185.93.89.167:24005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "radius.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzm8byYE0iXl--K6IVwADO3k"]
[Sun Aug 30 03:11:58.861392 2026] [security2:error] [pid 521505:tid 521517] [remote 185.93.89.167:54367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webservices.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlzm8byYE0iXl--K6IWAADQgs"]
[Sun Aug 30 03:11:58.863961 2026] [security2:error] [pid 521505:tid 521506] [remote 185.93.89.167:62949] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "board.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzm8byYE0iXl--K6IWgADSQA"]
[Sun Aug 30 03:11:58.864094 2026] [security2:error] [pid 521505:tid 521678] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "board.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzm8byYE0iXl--K6IWgADSQA"]
[Sun Aug 30 03:11:58.864564 2026] [security2:error] [pid 521505:tid 521549] [remote 185.93.89.167:25969] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dbadmin.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzm8byYE0iXl--K6IWwADQCs"]
[Sun Aug 30 03:11:58.875865 2026] [authz_core:error] [pid 521505:tid 521718] [client 66.249.66.64:49335] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:58.876150 2026] [authz_core:error] [pid 521505:tid 521718] [client 66.249.66.64:49335] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:58.882323 2026] [security2:error] [pid 521505:tid 521514] [remote 185.93.89.167:48785] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns02.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlzm8byYE0iXl--K6IYwADUQg"]
[Sun Aug 30 03:11:58.893276 2026] [security2:error] [pid 521505:tid 521555] [remote 185.93.89.167:14659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "otrs.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzm8byYE0iXl--K6IbgADJTE"]
[Sun Aug 30 03:11:58.899138 2026] [security2:error] [pid 521505:tid 521717] [client 20.48.160.90:61445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/d7.php"] [unique_id "apPlzm8byYE0iXl--K6IbwAAA3A"]
[Sun Aug 30 03:11:58.902960 2026] [security2:error] [pid 521505:tid 521645] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/ci/.env"] [unique_id "apPlzm8byYE0iXl--K6IcAAAAyg"]
[Sun Aug 30 03:11:58.904757 2026] [security2:error] [pid 521505:tid 521590] [remote 185.93.89.167:11687] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pr.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzm8byYE0iXl--K6IcgADJFQ"]
[Sun Aug 30 03:11:58.910257 2026] [security2:error] [pid 521505:tid 521565] [remote 185.93.89.167:62291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rs.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzm8byYE0iXl--K6IcwADYDs"]
[Sun Aug 30 03:11:58.917495 2026] [authz_core:error] [pid 521505:tid 521650] [client 216.73.216.128:23116] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:58.917765 2026] [authz_core:error] [pid 521505:tid 521650] [client 216.73.216.128:23116] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:58.938257 2026] [security2:error] [pid 521505:tid 521711] [client 20.104.49.130:63610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-good.php"] [unique_id "apPlzm8byYE0iXl--K6IeAAAA2o"]
[Sun Aug 30 03:11:58.944921 2026] [security2:error] [pid 521505:tid 521594] [remote 185.93.89.167:44659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "p.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzm8byYE0iXl--K6IegADbVg"]
[Sun Aug 30 03:11:58.945118 2026] [security2:error] [pid 521505:tid 521512] [remote 185.93.89.167:21227] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "outlook.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlzm8byYE0iXl--K6IeQADgAY"]
[Sun Aug 30 03:11:58.950353 2026] [security2:error] [pid 521505:tid 521761] [client 20.48.160.90:37769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/rxr.php"] [unique_id "apPlzm8byYE0iXl--K6IewAAA5w"]
[Sun Aug 30 03:11:58.951934 2026] [security2:error] [pid 521505:tid 521743] [client 20.151.200.44:46055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/attack.php"] [unique_id "apPlzm8byYE0iXl--K6IfAAAA4o"]
[Sun Aug 30 03:11:58.962219 2026] [authz_core:error] [pid 524122:tid 524313] [client 66.249.66.196:56604] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:58.962659 2026] [authz_core:error] [pid 524122:tid 524313] [client 66.249.66.196:56604] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:58.969190 2026] [security2:error] [pid 521505:tid 521540] [remote 185.93.89.167:1591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thumbs.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzm8byYE0iXl--K6IhgADMiI"]
[Sun Aug 30 03:11:58.969989 2026] [security2:error] [pid 521505:tid 521548] [remote 185.93.89.167:14991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "barracuda.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzm8byYE0iXl--K6IiAADiCo"]
[Sun Aug 30 03:11:58.972843 2026] [authz_core:error] [pid 521505:tid 521651] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory23
[Sun Aug 30 03:11:58.973277 2026] [authz_core:error] [pid 521505:tid 521651] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory23
[Sun Aug 30 03:11:58.983606 2026] [security2:error] [pid 521505:tid 521583] [remote 185.93.89.167:53553] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "demo2.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlzm8byYE0iXl--K6IjgADQk0"]
[Sun Aug 30 03:11:58.992750 2026] [security2:error] [pid 521505:tid 521756] [client 20.104.49.130:53647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/static.php"] [unique_id "apPlzm8byYE0iXl--K6IlQAAA5c"]
[Sun Aug 30 03:11:58.994388 2026] [security2:error] [pid 521505:tid 521537] [remote 185.93.89.167:54367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webservices.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlzm8byYE0iXl--K6ImQADjx8"]
[Sun Aug 30 03:11:58.996839 2026] [security2:error] [pid 521505:tid 521577] [remote 185.93.89.167:62949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "board.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzm8byYE0iXl--K6ImgADhkc"]
[Sun Aug 30 03:11:58.996977 2026] [security2:error] [pid 521505:tid 521739] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "board.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzm8byYE0iXl--K6ImgADhkc"]
[Sun Aug 30 03:11:58.998815 2026] [security2:error] [pid 521505:tid 521566] [remote 185.93.89.167:25969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dbadmin.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlzm8byYE0iXl--K6InAADjDw"]
[Sun Aug 30 03:11:59.007551 2026] [authz_core:error] [pid 524122:tid 524352] [client 216.73.216.128:46334] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:59.007842 2026] [authz_core:error] [pid 524122:tid 524352] [client 216.73.216.128:46334] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:59.035215 2026] [security2:error] [pid 524122:tid 524298] [client 173.239.211.44:35259] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/chosen.php"] [unique_id "apPlz33lhEjKFiK_nBJ7bQAAAbw"]
[Sun Aug 30 03:11:59.040080 2026] [security2:error] [pid 521505:tid 521703] [client 20.48.160.90:61553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/v5.php"] [unique_id "apPlz28byYE0iXl--K6IpwAAA2I"]
[Sun Aug 30 03:11:59.055585 2026] [security2:error] [pid 521505:tid 521652] [client 20.151.200.44:45035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/tajj.php"] [unique_id "apPlz28byYE0iXl--K6IrQAAAy8"]
[Sun Aug 30 03:11:59.062533 2026] [security2:error] [pid 521505:tid 521733] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/cd/.env"] [unique_id "apPlz28byYE0iXl--K6IsgAAA4A"]
[Sun Aug 30 03:11:59.078479 2026] [security2:error] [pid 521505:tid 521519] [remote 185.93.89.167:21227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "outlook.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlz28byYE0iXl--K6IugADZQ0"]
[Sun Aug 30 03:11:59.086555 2026] [security2:error] [pid 521505:tid 521729] [client 20.48.160.90:37797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/csst.php"] [unique_id "apPlz28byYE0iXl--K6IvwAAA3w"]
[Sun Aug 30 03:11:59.114908 2026] [security2:error] [pid 521505:tid 521686] [client 4.205.62.107:17120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/snq.php"] [unique_id "apPlz28byYE0iXl--K6IyAAAA1E"]
[Sun Aug 30 03:11:59.116192 2026] [security2:error] [pid 521505:tid 521669] [client 20.104.18.15:2013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/k.php"] [unique_id "apPlz28byYE0iXl--K6IygAAA0A"]
[Sun Aug 30 03:11:59.117527 2026] [security2:error] [pid 521505:tid 521689] [client 20.104.18.15:16898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/wp_blog_footer.php"] [unique_id "apPlz28byYE0iXl--K6IzAAAA1Q"]
[Sun Aug 30 03:11:59.118874 2026] [security2:error] [pid 521505:tid 521697] [client 20.104.50.220:16606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/ac.php"] [unique_id "apPlz28byYE0iXl--K6IzwAAA1w"]
[Sun Aug 30 03:11:59.131701 2026] [security2:error] [pid 521505:tid 521692] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "board.mariegronley.com"] [uri "/index.cgi"] [unique_id "apPlz28byYE0iXl--K6I2wADV3o"]
[Sun Aug 30 03:11:59.137348 2026] [security2:error] [pid 521505:tid 521637] [client 20.104.50.220:25471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/ha.php"] [unique_id "apPlz28byYE0iXl--K6I4gAAAyA"]
[Sun Aug 30 03:11:59.149168 2026] [security2:error] [pid 521505:tid 521705] [client 20.104.50.220:33311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/ex0shell.php"] [unique_id "apPlz28byYE0iXl--K6I5wAAA2Q"]
[Sun Aug 30 03:11:59.151387 2026] [security2:error] [pid 521505:tid 521568] [remote 185.93.89.167:48785] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns02.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlz28byYE0iXl--K6I6QADaT4"]
[Sun Aug 30 03:11:59.159745 2026] [security2:error] [pid 521505:tid 521655] [client 20.48.251.3:52235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/snq.php"] [unique_id "apPlz28byYE0iXl--K6I8AAAAzI"]
[Sun Aug 30 03:11:59.166886 2026] [security2:error] [pid 521505:tid 521694] [client 20.104.50.220:61686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/indo.php"] [unique_id "apPlz28byYE0iXl--K6I8wAAA1k"]
[Sun Aug 30 03:11:59.167461 2026] [authz_core:error] [pid 521505:tid 521742] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IL
[Sun Aug 30 03:11:59.167783 2026] [authz_core:error] [pid 521505:tid 521742] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IL
[Sun Aug 30 03:11:59.173250 2026] [security2:error] [pid 521505:tid 521573] [remote 185.93.89.167:11687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pr.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlz28byYE0iXl--K6I9wADfEM"]
[Sun Aug 30 03:11:59.174658 2026] [security2:error] [pid 521505:tid 521737] [client 20.104.18.15:51077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/she11.php"] [unique_id "apPlz28byYE0iXl--K6I-QAAA4Q"]
[Sun Aug 30 03:11:59.181684 2026] [security2:error] [pid 521505:tid 521725] [client 20.104.49.130:53697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/crgio.php"] [unique_id "apPlz28byYE0iXl--K6I-gAAA3g"]
[Sun Aug 30 03:11:59.188589 2026] [security2:error] [pid 521505:tid 521735] [client 20.104.49.130:57627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alarm-monitoring.net"] [uri "/coffexium.php"] [unique_id "apPlz28byYE0iXl--K6I_QAAA4I"]
[Sun Aug 30 03:11:59.196759 2026] [security2:error] [pid 521505:tid 521754] [client 20.48.160.90:30740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/az.php"] [unique_id "apPlz28byYE0iXl--K6JAgAAA5U"]
[Sun Aug 30 03:11:59.216598 2026] [security2:error] [pid 521505:tid 521699] [client 20.48.251.3:55709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/configuration.php"] [unique_id "apPlz28byYE0iXl--K6JCQAAA14"]
[Sun Aug 30 03:11:59.222466 2026] [security2:error] [pid 524122:tid 524330] [client 20.48.160.90:37850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp-includes/blocks/query-title/footer.php"] [unique_id "apPlz33lhEjKFiK_nBJ7gQAAAdw"]
[Sun Aug 30 03:11:59.224852 2026] [security2:error] [pid 521505:tid 521702] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/jenkins/.env"] [unique_id "apPlz28byYE0iXl--K6JDAAAA2E"]
[Sun Aug 30 03:11:59.228264 2026] [security2:error] [pid 521505:tid 521529] [remote 185.93.89.167:12177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tr.mariegronley.com"] [uri "/env/.env"] [unique_id "apPlz28byYE0iXl--K6JEAADYhc"]
[Sun Aug 30 03:11:59.237466 2026] [security2:error] [pid 521505:tid 521661] [client 20.48.251.3:65525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/fucku.php"] [unique_id "apPlz28byYE0iXl--K6JEgAAAzg"]
[Sun Aug 30 03:11:59.252547 2026] [security2:error] [pid 521505:tid 521592] [remote 185.93.89.167:53553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "demo2.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlz28byYE0iXl--K6JHAADI1Y"]
[Sun Aug 30 03:11:59.262818 2026] [security2:error] [pid 521505:tid 521570] [remote 185.93.89.167:54367] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webservices.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlz28byYE0iXl--K6JHwADW0A"]
[Sun Aug 30 03:11:59.265829 2026] [security2:error] [pid 521505:tid 521645] [client 20.104.49.130:48012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/wp-blog-header.php"] [unique_id "apPlz28byYE0iXl--K6JIgAAAyg"]
[Sun Aug 30 03:11:59.268586 2026] [security2:error] [pid 521505:tid 521673] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "board.mariegronley.com"] [uri "/index.cgi"] [unique_id "apPlz28byYE0iXl--K6JIAADRBg"]
[Sun Aug 30 03:11:59.275621 2026] [security2:error] [pid 524122:tid 524254] [client 20.104.18.15:31738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-activate.php"] [unique_id "apPlz33lhEjKFiK_nBJ7iAAAAZA"]
[Sun Aug 30 03:11:59.297914 2026] [security2:error] [pid 524122:tid 524356] [client 20.104.50.220:31510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "apPlz33lhEjKFiK_nBJ7jQAAAfY"]
[Sun Aug 30 03:11:59.306675 2026] [security2:error] [pid 521505:tid 521563] [remote 185.93.89.167:11687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pr.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlz28byYE0iXl--K6JMwADnTk"]
[Sun Aug 30 03:11:59.327335 2026] [security2:error] [pid 521505:tid 521724] [client 63.143.147.119:0] ModSecurity: Warning. Matched phrase "Octopus" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "barbervillebaptistchurch.org"] [uri "/index.php"] [unique_id "apPlz28byYE0iXl--K6I_wADdyE"]
[Sun Aug 30 03:11:59.327640 2026] [security2:error] [pid 524122:tid 524300] [client 20.48.160.90:37758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/js.php"] [unique_id "apPlz33lhEjKFiK_nBJ7jwAAAb4"]
[Sun Aug 30 03:11:59.344890 2026] [security2:error] [pid 521505:tid 521758] [client 34.15.159.88:50734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/php.php"] [unique_id "apPlz28byYE0iXl--K6JPQAAA5k"]
[Sun Aug 30 03:11:59.346818 2026] [security2:error] [pid 524122:tid 524373] [client 20.104.50.220:5590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/index1.php"] [unique_id "apPlz33lhEjKFiK_nBJ7kwAAAgc"]
[Sun Aug 30 03:11:59.348080 2026] [security2:error] [pid 524122:tid 524256] [client 4.205.62.107:15975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/25.php"] [unique_id "apPlz33lhEjKFiK_nBJ7lAAAAZI"]
[Sun Aug 30 03:11:59.350762 2026] [security2:error] [pid 524122:tid 524260] [client 20.151.200.44:62994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/log.php"] [unique_id "apPlz33lhEjKFiK_nBJ7lQAAAZY"]
[Sun Aug 30 03:11:59.358857 2026] [security2:error] [pid 524122:tid 524369] [client 4.205.62.107:16339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPlz33lhEjKFiK_nBJ7lwAAAgM"]
[Sun Aug 30 03:11:59.362246 2026] [security2:error] [pid 521505:tid 521751] [client 20.104.49.130:52122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/reop3.php"] [unique_id "apPlz28byYE0iXl--K6JRQAAA5I"]
[Sun Aug 30 03:11:59.365094 2026] [security2:error] [pid 524122:tid 524309] [client 63.143.147.119:0] ModSecurity: Warning. Matched phrase "Octopus" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "barbervillebaptistchurch.org"] [uri "/index.php"] [unique_id "apPlz33lhEjKFiK_nBJ7fQABxxM"]
[Sun Aug 30 03:11:59.367811 2026] [security2:error] [pid 521505:tid 521703] [client 4.205.62.107:52848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/groceries/index.php"] [unique_id "apPlz28byYE0iXl--K6JSAAAA2I"]
[Sun Aug 30 03:11:59.368217 2026] [security2:error] [pid 521505:tid 521719] [client 20.48.160.90:37882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp-content/uploads/indoex.php"] [unique_id "apPlz28byYE0iXl--K6JSQAAA3I"]
[Sun Aug 30 03:11:59.386359 2026] [security2:error] [pid 521505:tid 521599] [remote 185.93.89.167:53553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "demo2.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlz28byYE0iXl--K6JTgADV10"]
[Sun Aug 30 03:11:59.394657 2026] [security2:error] [pid 521505:tid 521635] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/gitlab/.env"] [unique_id "apPlz28byYE0iXl--K6JUAAAAx4"]
[Sun Aug 30 03:11:59.396771 2026] [security2:error] [pid 521505:tid 521604] [remote 185.93.89.167:54367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webservices.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlz28byYE0iXl--K6JUQADNGI"]
[Sun Aug 30 03:11:59.404486 2026] [security2:error] [pid 521505:tid 521667] [client 185.93.89.167:62949] ModSecurity: Warning. Matched phrase "Ninja" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "board.mariegronley.com"] [uri "/index.cgi"] [unique_id "apPlz28byYE0iXl--K6JVAADPlM"]
[Sun Aug 30 03:11:59.409805 2026] [security2:error] [pid 521505:tid 521715] [client 63.143.147.119:0] ModSecurity: Warning. Matched phrase "Octopus" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "barbervillebaptistchurch.org"] [uri "/index.php"] [unique_id "apPlz28byYE0iXl--K6JAAADbiw"]
[Sun Aug 30 03:11:59.412097 2026] [security2:error] [pid 524122:tid 524290] [client 63.143.147.119:0] ModSecurity: Warning. Matched phrase "Octopus" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "barbervillebaptistchurch.org"] [uri "/index.php"] [unique_id "apPlz33lhEjKFiK_nBJ7fgABtBQ"]
[Sun Aug 30 03:11:59.420602 2026] [security2:error] [pid 521505:tid 521569] [remote 185.93.89.167:48785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns02.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlz28byYE0iXl--K6JXgADTj8"]
[Sun Aug 30 03:11:59.425402 2026] [security2:error] [pid 521505:tid 521711] [client 4.205.62.107:26997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/fun.php"] [unique_id "apPlz28byYE0iXl--K6JYwAAA2o"]
[Sun Aug 30 03:11:59.434573 2026] [security2:error] [pid 521505:tid 521709] [client 51.77.230.139:43710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.230.77.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "chamirgimenez.com"] [uri "/wp-login.php"] [unique_id "apPlz28byYE0iXl--K6JaAAAA2g"]
[Sun Aug 30 03:11:59.455156 2026] [authz_core:error] [pid 524122:tid 524287] [client 66.249.66.199:59990] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:59.455587 2026] [authz_core:error] [pid 524122:tid 524287] [client 66.249.66.199:59990] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:59.460068 2026] [security2:error] [pid 521505:tid 521713] [client 20.48.251.3:36846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/olfclass.php"] [unique_id "apPlz28byYE0iXl--K6JegAAA2w"]
[Sun Aug 30 03:11:59.470585 2026] [security2:error] [pid 521505:tid 521758] [client 20.48.160.90:37686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/hd.php"] [unique_id "apPlz28byYE0iXl--K6JfAAAA5k"]
[Sun Aug 30 03:11:59.496484 2026] [security2:error] [pid 524122:tid 524304] [client 20.48.160.90:37846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPlz33lhEjKFiK_nBJ7oQAAAcI"]
[Sun Aug 30 03:11:59.498758 2026] [security2:error] [pid 521505:tid 521610] [remote 185.93.89.167:12177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tr.mariegronley.com"] [uri "/src/.env"] [unique_id "apPlz28byYE0iXl--K6JggADQmg"]
[Sun Aug 30 03:11:59.506404 2026] [authz_core:error] [pid 521505:tid 521722] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory21
[Sun Aug 30 03:11:59.506876 2026] [authz_core:error] [pid 521505:tid 521722] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory21
[Sun Aug 30 03:11:59.525724 2026] [authz_core:error] [pid 521505:tid 521745] [client 66.249.66.197:49408] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:59.525997 2026] [authz_core:error] [pid 521505:tid 521745] [client 66.249.66.197:49408] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:59.539370 2026] [security2:error] [pid 524122:tid 524377] [client 20.104.18.15:18256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/pri.php"] [unique_id "apPlz33lhEjKFiK_nBJ7pAAAAgs"]
[Sun Aug 30 03:11:59.552410 2026] [security2:error] [pid 524122:tid 524338] [client 20.104.49.130:64091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/f35.update.php"] [unique_id "apPlz33lhEjKFiK_nBJ7pgAAAeQ"]
[Sun Aug 30 03:11:59.554005 2026] [security2:error] [pid 521505:tid 521551] [remote 185.93.89.167:48785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns02.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlz28byYE0iXl--K6JmQADji0"]
[Sun Aug 30 03:11:59.556225 2026] [security2:error] [pid 521505:tid 521676] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/github/.env"] [unique_id "apPlz28byYE0iXl--K6JmgAAA0c"]
[Sun Aug 30 03:11:59.557374 2026] [authz_core:error] [pid 524122:tid 524370] [client 216.73.216.128:46334] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:59.557819 2026] [authz_core:error] [pid 524122:tid 524370] [client 216.73.216.128:46334] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:59.560052 2026] [security2:error] [pid 524122:tid 524368] [client 20.151.200.44:44980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/bge.php"] [unique_id "apPlz33lhEjKFiK_nBJ7pwAAAgI"]
[Sun Aug 30 03:11:59.574912 2026] [security2:error] [pid 521505:tid 521603] [remote 185.93.89.167:11687] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pr.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlz28byYE0iXl--K6JoAADQWE"]
[Sun Aug 30 03:11:59.618111 2026] [security2:error] [pid 521505:tid 521693] [client 20.48.160.90:37651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/xl2023.php"] [unique_id "apPlz28byYE0iXl--K6JrgAAA1g"]
[Sun Aug 30 03:11:59.623832 2026] [security2:error] [pid 521505:tid 521695] [client 20.104.49.130:45163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/sxxb.php"] [unique_id "apPlz28byYE0iXl--K6JsQAAA1o"]
[Sun Aug 30 03:11:59.624180 2026] [security2:error] [pid 521505:tid 521760] [client 20.48.160.90:61604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/haxor.php"] [unique_id "apPlz28byYE0iXl--K6JsgAAA5s"]
[Sun Aug 30 03:11:59.628821 2026] [security2:error] [pid 524122:tid 524281] [client 63.135.161.118:29863] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/wp-admin/css/admin.php"] [unique_id "apPlz33lhEjKFiK_nBJ7sQAAAas"]
[Sun Aug 30 03:11:59.640943 2026] [security2:error] [pid 521505:tid 521671] [client 20.151.200.44:26584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/motu.php"] [unique_id "apPlz28byYE0iXl--K6JvAAAA0I"]
[Sun Aug 30 03:11:59.641791 2026] [security2:error] [pid 524122:tid 524269] [client 20.104.50.220:63522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/jindex.php"] [unique_id "apPlz33lhEjKFiK_nBJ7sgAAAZ8"]
[Sun Aug 30 03:11:59.656226 2026] [security2:error] [pid 521505:tid 521607] [remote 185.93.89.167:53553] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "demo2.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlz28byYE0iXl--K6JvwADQGU"]
[Sun Aug 30 03:11:59.671177 2026] [authz_core:error] [pid 521505:tid 521636] [client 66.249.66.195:54372] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:59.671609 2026] [authz_core:error] [pid 521505:tid 521636] [client 66.249.66.195:54372] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:59.677277 2026] [authz_core:error] [pid 521505:tid 521637] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IE
[Sun Aug 30 03:11:59.677705 2026] [authz_core:error] [pid 521505:tid 521637] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IE
[Sun Aug 30 03:11:59.697609 2026] [security2:error] [pid 524122:tid 524311] [client 158.23.147.79:40034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apPlz33lhEjKFiK_nBJ7uwAAAck"]
[Sun Aug 30 03:11:59.708301 2026] [security2:error] [pid 521505:tid 521759] [client 20.104.49.130:51099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/term.php"] [unique_id "apPlz28byYE0iXl--K6J2wAAA5o"]
[Sun Aug 30 03:11:59.708366 2026] [security2:error] [pid 521505:tid 521560] [remote 185.93.89.167:11687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pr.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlz28byYE0iXl--K6J2gADbTY"]
[Sun Aug 30 03:11:59.715513 2026] [security2:error] [pid 521505:tid 521660] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/actions/.env"] [unique_id "apPlz28byYE0iXl--K6J3wAAAzc"]
[Sun Aug 30 03:11:59.739298 2026] [security2:error] [pid 524122:tid 524306] [client 20.104.50.220:62833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-content/uploads/simple-file-list/shell.php"] [unique_id "apPlz33lhEjKFiK_nBJ7vQAAAcQ"]
[Sun Aug 30 03:11:59.760549 2026] [security2:error] [pid 521505:tid 521642] [client 20.48.160.90:61668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/google.php"] [unique_id "apPlz28byYE0iXl--K6J8wAAAyU"]
[Sun Aug 30 03:11:59.762169 2026] [security2:error] [pid 521505:tid 521671] [client 20.48.160.90:61492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/V2.php"] [unique_id "apPlz28byYE0iXl--K6J9wAAA0I"]
[Sun Aug 30 03:11:59.767156 2026] [security2:error] [pid 521505:tid 521612] [remote 185.93.89.167:12177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tr.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPlz28byYE0iXl--K6J-QADY2o"]
[Sun Aug 30 03:11:59.789516 2026] [security2:error] [pid 521505:tid 521732] [client 63.143.147.119:0] ModSecurity: Warning. Matched phrase "Octopus" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "barbervillebaptistchurch.org"] [uri "/index.php"] [unique_id "apPlz28byYE0iXl--K6J0wADf1s"]
[Sun Aug 30 03:11:59.789537 2026] [security2:error] [pid 521505:tid 521508] [remote 185.93.89.167:53553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "demo2.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlz28byYE0iXl--K6J_wADQAI"]
[Sun Aug 30 03:11:59.823281 2026] [security2:error] [pid 521505:tid 521533] [remote 185.93.89.167:48785] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns02.mariegronley.com"] [uri "/web/.env"] [unique_id "apPlz28byYE0iXl--K6KDQADdRs"]
[Sun Aug 30 03:11:59.825068 2026] [fcgid:warn] [pid 521505:tid 521638] (70014)End of file found: [client 207.90.244.25:33776] mod_fcgid: can't get data from http client
[Sun Aug 30 03:11:59.874259 2026] [security2:error] [pid 521505:tid 521673] [client 20.151.200.44:26570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/wefile.php"] [unique_id "apPlz28byYE0iXl--K6KKQAAA0Q"]
[Sun Aug 30 03:11:59.874857 2026] [security2:error] [pid 521505:tid 521739] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/circleci/.env"] [unique_id "apPlz28byYE0iXl--K6KKAAAA4Y"]
[Sun Aug 30 03:11:59.892459 2026] [security2:error] [pid 521505:tid 521704] [client 20.48.160.90:37767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "apPlz28byYE0iXl--K6KOAAAA2M"]
[Sun Aug 30 03:11:59.893728 2026] [security2:error] [pid 521505:tid 521732] [client 20.48.160.90:37738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/mad.php"] [unique_id "apPlz28byYE0iXl--K6KOgAAA38"]
[Sun Aug 30 03:11:59.900234 2026] [security2:error] [pid 521505:tid 521619] [remote 185.93.89.167:12177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tr.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPlz28byYE0iXl--K6KPgADV3E"]
[Sun Aug 30 03:11:59.903231 2026] [security2:error] [pid 521505:tid 521654] [client 20.104.49.130:46173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/sd.php"] [unique_id "apPlz28byYE0iXl--K6KPwAAAzE"]
[Sun Aug 30 03:11:59.915601 2026] [security2:error] [pid 521505:tid 521640] [client 20.151.200.44:62921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/xwpg.php"] [unique_id "apPlz28byYE0iXl--K6KQgAAAyM"]
[Sun Aug 30 03:11:59.919419 2026] [security2:error] [pid 521505:tid 521737] [client 20.104.49.130:53618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/init.php"] [unique_id "apPlz28byYE0iXl--K6KQwAAA4Q"]
[Sun Aug 30 03:11:59.947652 2026] [security2:error] [pid 521505:tid 521688] [client 34.15.159.88:50740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/i.php"] [unique_id "apPlz28byYE0iXl--K6KTgAAA1M"]
[Sun Aug 30 03:11:59.954653 2026] [authz_core:error] [pid 521505:tid 521649] [client 66.249.66.39:59819] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:11:59.955084 2026] [authz_core:error] [pid 521505:tid 521649] [client 66.249.66.39:59819] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:11:59.956606 2026] [security2:error] [pid 521505:tid 521585] [remote 185.93.89.167:48785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns02.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPlz28byYE0iXl--K6KUAADeU8"]
[Sun Aug 30 03:11:59.981627 2026] [security2:error] [pid 524122:tid 524315] [client 68.155.159.216:52291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-l0gin.php"] [unique_id "apPlz33lhEjKFiK_nBJ7zgAAAc0"]
[Sun Aug 30 03:11:59.992475 2026] [authz_core:error] [pid 521505:tid 521739] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory12
[Sun Aug 30 03:11:59.992783 2026] [authz_core:error] [pid 521505:tid 521739] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory12
[Sun Aug 30 03:12:00.013602 2026] [authz_core:error] [pid 524122:tid 524271] [client 216.73.216.128:46334] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:00.014067 2026] [authz_core:error] [pid 524122:tid 524271] [client 216.73.216.128:46334] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:00.027051 2026] [security2:error] [pid 524122:tid 524353] [client 20.48.160.90:38011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/st.php"] [unique_id "apPl0H3lhEjKFiK_nBJ71AAAAfM"]
[Sun Aug 30 03:12:00.032914 2026] [security2:error] [pid 521505:tid 521761] [client 20.48.160.90:61666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/robots.php"] [unique_id "apPl0G8byYE0iXl--K6KawAAA5w"]
[Sun Aug 30 03:12:00.034456 2026] [security2:error] [pid 521505:tid 521761] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/travis/.env"] [unique_id "apPl0G8byYE0iXl--K6KbgAAA5w"]
[Sun Aug 30 03:12:00.064341 2026] [security2:error] [pid 524122:tid 524304] [client 158.23.147.79:16328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-admin/images/index.php"] [unique_id "apPl0H3lhEjKFiK_nBJ72gAAAcI"]
[Sun Aug 30 03:12:00.093385 2026] [security2:error] [pid 521505:tid 521676] [client 216.73.216.128:51205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_config_newmailwidth"] [unique_id "apPl0G8byYE0iXl--K6KjwAAA0c"]
[Sun Aug 30 03:12:00.102498 2026] [security2:error] [pid 521505:tid 521680] [client 63.143.147.119:0] ModSecurity: Warning. Matched phrase "Octopus" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "barbervillebaptistchurch.org"] [uri "/index.php"] [unique_id "apPlzm8byYE0iXl--K6IVQADSyk"]
[Sun Aug 30 03:12:00.102767 2026] [security2:error] [pid 524122:tid 524146] [remote 185.93.89.167:39769] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ar.mariegronley.com"] [uri "/.env"] [unique_id "apPl0H3lhEjKFiK_nBJ74QAB6xY"]
[Sun Aug 30 03:12:00.111568 2026] [security2:error] [pid 524122:tid 524320] [client 20.104.49.130:64075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/wp-blog-header.php"] [unique_id "apPl0H3lhEjKFiK_nBJ74gAAAdI"]
[Sun Aug 30 03:12:00.144765 2026] [security2:error] [pid 524122:tid 524276] [client 20.151.200.44:45000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/ssh3ll.php"] [unique_id "apPl0H3lhEjKFiK_nBJ76AAAAaY"]
[Sun Aug 30 03:12:00.170377 2026] [security2:error] [pid 521505:tid 521515] [remote 185.93.89.167:12177] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tr.mariegronley.com"] [uri "/web/.env"] [unique_id "apPl0G8byYE0iXl--K6KqQADMQk"]
[Sun Aug 30 03:12:00.172437 2026] [security2:error] [pid 521505:tid 521727] [client 20.48.160.90:61579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp-content/plugins/ccx/index.php"] [unique_id "apPl0G8byYE0iXl--K6KqwAAA3o"]
[Sun Aug 30 03:12:00.181838 2026] [security2:error] [pid 524122:tid 524337] [client 20.48.160.90:37713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/alfanew.php"] [unique_id "apPl0H3lhEjKFiK_nBJ77gAAAeM"]
[Sun Aug 30 03:12:00.188418 2026] [authz_core:error] [pid 521505:tid 521749] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_CA
[Sun Aug 30 03:12:00.188688 2026] [authz_core:error] [pid 521505:tid 521749] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_CA
[Sun Aug 30 03:12:00.197702 2026] [security2:error] [pid 521505:tid 521647] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/buildkite/.env"] [unique_id "apPl0G8byYE0iXl--K6KrwAAAyo"]
[Sun Aug 30 03:12:00.236680 2026] [security2:error] [pid 524122:tid 524147] [remote 185.93.89.167:39769] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ar.mariegronley.com"] [uri "/api/.env"] [unique_id "apPl0H3lhEjKFiK_nBJ78wAB1Bc"]
[Sun Aug 30 03:12:00.243992 2026] [fcgid:warn] [pid 521505:tid 521683] (70014)End of file found: [client 207.90.244.25:33792] mod_fcgid: can't get data from http client
[Sun Aug 30 03:12:00.253485 2026] [security2:error] [pid 521505:tid 521676] [client 4.205.62.107:17143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/wp-access.php"] [unique_id "apPl0G8byYE0iXl--K6KxQAAA0c"]
[Sun Aug 30 03:12:00.253839 2026] [security2:error] [pid 521505:tid 521721] [client 20.104.50.220:17292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/new4.php"] [unique_id "apPl0G8byYE0iXl--K6KxwAAA3Q"]
[Sun Aug 30 03:12:00.255464 2026] [security2:error] [pid 524122:tid 524352] [client 20.104.18.15:2008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/dex.php"] [unique_id "apPl0H3lhEjKFiK_nBJ79gAAAfI"]
[Sun Aug 30 03:12:00.259961 2026] [security2:error] [pid 521505:tid 521707] [client 20.104.18.15:64749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/sushi.php"] [unique_id "apPl0G8byYE0iXl--K6KyQAAA2Y"]
[Sun Aug 30 03:12:00.287748 2026] [security2:error] [pid 521505:tid 521733] [client 20.104.50.220:33297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/exp.php"] [unique_id "apPl0G8byYE0iXl--K6K1wAAA4A"]
[Sun Aug 30 03:12:00.294851 2026] [security2:error] [pid 524122:tid 524327] [client 20.104.50.220:25431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/hur.php"] [unique_id "apPl0H3lhEjKFiK_nBJ7-QAAAdk"]
[Sun Aug 30 03:12:00.298773 2026] [security2:error] [pid 524122:tid 524311] [client 20.48.251.3:59893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-access.php"] [unique_id "apPl0H3lhEjKFiK_nBJ7-gAAAck"]
[Sun Aug 30 03:12:00.302158 2026] [security2:error] [pid 524122:tid 524275] [client 20.104.18.15:22415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/wp-includes/ID3/moon.php"] [unique_id "apPl0H3lhEjKFiK_nBJ7-wAAAaU"]
[Sun Aug 30 03:12:00.303559 2026] [security2:error] [pid 521505:tid 521524] [remote 185.93.89.167:12177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tr.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPl0G8byYE0iXl--K6K4AADWhI"]
[Sun Aug 30 03:12:00.309709 2026] [security2:error] [pid 524122:tid 524302] [client 20.48.160.90:37831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp-admin/css/colors/maro.php"] [unique_id "apPl0H3lhEjKFiK_nBJ7_QAAAcA"]
[Sun Aug 30 03:12:00.312034 2026] [security2:error] [pid 521505:tid 521734] [client 20.104.18.15:51199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/kerang.php"] [unique_id "apPl0G8byYE0iXl--K6K4wAAA4E"]
[Sun Aug 30 03:12:00.332136 2026] [security2:error] [pid 521505:tid 521686] [client 20.48.160.90:37990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/ioxi.php"] [unique_id "apPl0G8byYE0iXl--K6K6QAAA1E"]
[Sun Aug 30 03:12:00.357894 2026] [security2:error] [pid 521505:tid 521731] [client 20.104.50.220:61979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/fileas.php"] [unique_id "apPl0G8byYE0iXl--K6K9gAAA34"]
[Sun Aug 30 03:12:00.361986 2026] [security2:error] [pid 521505:tid 521692] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/mysql/.env"] [unique_id "apPl0G8byYE0iXl--K6K-AAAA1c"]
[Sun Aug 30 03:12:00.362749 2026] [security2:error] [pid 521505:tid 521691] [client 20.151.200.44:45024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/motu.php"] [unique_id "apPl0G8byYE0iXl--K6K-gAAA1Y"]
[Sun Aug 30 03:12:00.369474 2026] [security2:error] [pid 521505:tid 521638] [client 20.48.251.3:54750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/error_log.php"] [unique_id "apPl0G8byYE0iXl--K6K_QAAAyE"]
[Sun Aug 30 03:12:00.370593 2026] [security2:error] [pid 521505:tid 521714] [client 20.48.251.3:55777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/server_info.php"] [unique_id "apPl0G8byYE0iXl--K6K_gAAA20"]
[Sun Aug 30 03:12:00.371902 2026] [security2:error] [pid 524122:tid 524148] [remote 185.93.89.167:39769] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ar.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPl0H3lhEjKFiK_nBJ8AQAB_hg"]
[Sun Aug 30 03:12:00.423357 2026] [security2:error] [pid 521505:tid 521761] [client 20.104.18.15:31558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp_blog_footer.php"] [unique_id "apPl0G8byYE0iXl--K6LEQAAA5w"]
[Sun Aug 30 03:12:00.439724 2026] [security2:error] [pid 524122:tid 524279] [client 20.48.160.90:61687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp-admin/css/colors/coffee/marijuana.php"] [unique_id "apPl0H3lhEjKFiK_nBJ8AgAAAak"]
[Sun Aug 30 03:12:00.441457 2026] [security2:error] [pid 521505:tid 521703] [client 20.104.49.130:53775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/ab.php"] [unique_id "apPl0G8byYE0iXl--K6LIQAAA2I"]
[Sun Aug 30 03:12:00.441746 2026] [security2:error] [pid 521505:tid 521739] [client 20.104.50.220:59374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/class-t.api.php"] [unique_id "apPl0G8byYE0iXl--K6LIwAAA4Y"]
[Sun Aug 30 03:12:00.464112 2026] [security2:error] [pid 524122:tid 524373] [client 20.48.160.90:30733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/TNT.php"] [unique_id "apPl0H3lhEjKFiK_nBJ8BQAAAgc"]
[Sun Aug 30 03:12:00.465753 2026] [security2:error] [pid 521505:tid 521652] [client 20.104.49.130:52155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/dragonshell.php"] [unique_id "apPl0G8byYE0iXl--K6LMAAAAy8"]
[Sun Aug 30 03:12:00.492844 2026] [security2:error] [pid 524122:tid 524369] [client 20.104.50.220:6111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/303.php"] [unique_id "apPl0H3lhEjKFiK_nBJ8BwAAAgM"]
[Sun Aug 30 03:12:00.496558 2026] [authz_core:error] [pid 521505:tid 521691] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory20
[Sun Aug 30 03:12:00.497048 2026] [authz_core:error] [pid 521505:tid 521691] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory20
[Sun Aug 30 03:12:00.497981 2026] [security2:error] [pid 521505:tid 521760] [client 4.205.62.107:16322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/cloud.php"] [unique_id "apPl0G8byYE0iXl--K6LMwAAA5s"]
[Sun Aug 30 03:12:00.498088 2026] [security2:error] [pid 521505:tid 521718] [client 4.205.62.107:15957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/nlnub.php"] [unique_id "apPl0G8byYE0iXl--K6LMgAAA3E"]
[Sun Aug 30 03:12:00.504758 2026] [security2:error] [pid 524122:tid 524342] [client 4.205.62.107:52827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/konfig.php"] [unique_id "apPl0H3lhEjKFiK_nBJ8CQAAAeg"]
[Sun Aug 30 03:12:00.505185 2026] [security2:error] [pid 524122:tid 524149] [remote 185.93.89.167:39769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ar.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPl0H3lhEjKFiK_nBJ8CgABpBk"]
[Sun Aug 30 03:12:00.506714 2026] [security2:error] [pid 524122:tid 524277] [client 63.135.161.121:21781] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/wp-includes/PHPMailer/reading.php"] [unique_id "apPl0H3lhEjKFiK_nBJ8DAAAAac"]
[Sun Aug 30 03:12:00.521486 2026] [security2:error] [pid 521505:tid 521707] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/postgres/.env"] [unique_id "apPl0G8byYE0iXl--K6LOQAAA2Y"]
[Sun Aug 30 03:12:00.547201 2026] [security2:error] [pid 524122:tid 524257] [client 20.104.50.220:28732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/lf.php"] [unique_id "apPl0H3lhEjKFiK_nBJ8FgAAAZM"]
[Sun Aug 30 03:12:00.548781 2026] [security2:error] [pid 524122:tid 524286] [client 34.15.159.88:50756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/pi.php"] [unique_id "apPl0H3lhEjKFiK_nBJ8FwAAAbA"]
[Sun Aug 30 03:12:00.550172 2026] [security2:error] [pid 524122:tid 524304] [client 216.73.216.128:46334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPl0H3lhEjKFiK_nBJ8GAAAAcI"]
[Sun Aug 30 03:12:00.570233 2026] [security2:error] [pid 524122:tid 524340] [client 4.205.62.107:27003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/kedi.php"] [unique_id "apPl0H3lhEjKFiK_nBJ8HAAAAeY"]
[Sun Aug 30 03:12:00.572182 2026] [security2:error] [pid 521505:tid 521758] [client 20.48.160.90:61575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp-admin/css/colors/coffee/mari.php"] [unique_id "apPl0G8byYE0iXl--K6LSQAAA5k"]
[Sun Aug 30 03:12:00.574600 2026] [security2:error] [pid 521505:tid 521642] [client 158.23.147.79:40021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-content/admin.php"] [unique_id "apPl0G8byYE0iXl--K6LSwAAAyU"]
[Sun Aug 30 03:12:00.588900 2026] [security2:error] [pid 524122:tid 524338] [client 20.151.200.44:45016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/wefile.php"] [unique_id "apPl0H3lhEjKFiK_nBJ8HwAAAeQ"]
[Sun Aug 30 03:12:00.599699 2026] [security2:error] [pid 524122:tid 524345] [client 20.48.251.3:37133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/gnmlc.php"] [unique_id "apPl0H3lhEjKFiK_nBJ8IgAAAes"]
[Sun Aug 30 03:12:00.600556 2026] [fcgid:warn] [pid 521505:tid 521684] (70014)End of file found: [client 207.90.244.25:33800] mod_fcgid: can't get data from http client
[Sun Aug 30 03:12:00.603158 2026] [security2:error] [pid 521505:tid 521643] [client 20.48.160.90:38009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/cd.php"] [unique_id "apPl0G8byYE0iXl--K6LWgAAAyY"]
[Sun Aug 30 03:12:00.667373 2026] [security2:error] [pid 524122:tid 524371] [client 20.104.49.130:53570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/wen.php"] [unique_id "apPl0H3lhEjKFiK_nBJ8MAAAAgU"]
[Sun Aug 30 03:12:00.679032 2026] [security2:error] [pid 521505:tid 521678] [client 20.104.18.15:18267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/wp_blog_footer.php"] [unique_id "apPl0G8byYE0iXl--K6LewAAA0k"]
[Sun Aug 30 03:12:00.682417 2026] [security2:error] [pid 521505:tid 521755] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/mongodb/.env"] [unique_id "apPl0G8byYE0iXl--K6LfgAAA5Y"]
[Sun Aug 30 03:12:00.685114 2026] [authz_core:error] [pid 521505:tid 521708] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_CA
[Sun Aug 30 03:12:00.685372 2026] [authz_core:error] [pid 521505:tid 521708] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_CA
[Sun Aug 30 03:12:00.689897 2026] [security2:error] [pid 521505:tid 521753] [client 20.151.200.44:26568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/Contrller.php"] [unique_id "apPl0G8byYE0iXl--K6LggAAA5Q"]
[Sun Aug 30 03:12:00.708859 2026] [security2:error] [pid 524122:tid 524372] [client 20.48.160.90:37886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp-includes/images/crystal/option.php"] [unique_id "apPl0H3lhEjKFiK_nBJ8NwAAAgY"]
[Sun Aug 30 03:12:00.752145 2026] [security2:error] [pid 521505:tid 521704] [client 20.48.160.90:61533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/luuf.php"] [unique_id "apPl0G8byYE0iXl--K6LnQAAA2M"]
[Sun Aug 30 03:12:00.797268 2026] [security2:error] [pid 521505:tid 521652] [client 20.104.50.220:42769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/p0wny-shell.php"] [unique_id "apPl0G8byYE0iXl--K6LpQAAAy8"]
[Sun Aug 30 03:12:00.823325 2026] [security2:error] [pid 521505:tid 521678] [client 173.239.211.54:49807] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/wp-content/plugins/enhanced-text-widget/analyst/src/goods.php"] [unique_id "apPl0G8byYE0iXl--K6LsgAAA0k"]
[Sun Aug 30 03:12:00.829792 2026] [security2:error] [pid 521505:tid 521711] [client 20.104.49.130:64123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/wp-blogs.php"] [unique_id "apPl0G8byYE0iXl--K6LtgAAA2o"]
[Sun Aug 30 03:12:00.838340 2026] [security2:error] [pid 524122:tid 524282] [client 20.48.160.90:37763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp-includes/pomo/xxx.php"] [unique_id "apPl0H3lhEjKFiK_nBJ8RQAAAaw"]
[Sun Aug 30 03:12:00.842296 2026] [security2:error] [pid 521505:tid 521692] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/redis/.env"] [unique_id "apPl0G8byYE0iXl--K6LugAAA1c"]
[Sun Aug 30 03:12:00.876541 2026] [security2:error] [pid 524122:tid 524277] [client 216.73.216.128:33673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPl0H3lhEjKFiK_nBJ8SgAAAac"]
[Sun Aug 30 03:12:00.886362 2026] [security2:error] [pid 524122:tid 524278] [client 20.48.160.90:61504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/fex.php"] [unique_id "apPl0H3lhEjKFiK_nBJ8TAAAAag"]
[Sun Aug 30 03:12:00.910340 2026] [security2:error] [pid 524122:tid 524152] [remote 185.93.89.167:39769] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ar.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPl0H3lhEjKFiK_nBJ8VAABmRw"]
[Sun Aug 30 03:12:00.925108 2026] [authz_core:error] [pid 521505:tid 521675] [client 216.73.216.128:37868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:00.925404 2026] [authz_core:error] [pid 521505:tid 521675] [client 216.73.216.128:37868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:00.951609 2026] [security2:error] [pid 524122:tid 524325] [client 20.104.50.220:62825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-content/uploads/simple-file-list/fox.php"] [unique_id "apPl0H3lhEjKFiK_nBJ8VwAAAdc"]
[Sun Aug 30 03:12:00.960868 2026] [authz_core:error] [pid 521505:tid 521643] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory23
[Sun Aug 30 03:12:00.961160 2026] [authz_core:error] [pid 521505:tid 521643] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory23
[Sun Aug 30 03:12:00.972943 2026] [security2:error] [pid 521505:tid 521730] [client 20.48.160.90:61684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/650.php"] [unique_id "apPl0G8byYE0iXl--K6L4gAAA30"]
[Sun Aug 30 03:12:01.002055 2026] [security2:error] [pid 521505:tid 521727] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/elasticsearch/.env"] [unique_id "apPl0W8byYE0iXl--K6L7QAAA3o"]
[Sun Aug 30 03:12:01.021046 2026] [authz_core:error] [pid 521505:tid 521741] [client 216.73.216.128:23116] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:01.021479 2026] [authz_core:error] [pid 521505:tid 521741] [client 216.73.216.128:23116] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:01.024777 2026] [security2:error] [pid 521505:tid 521672] [client 20.48.160.90:61559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/l.php"] [unique_id "apPl0W8byYE0iXl--K6L9gAAA0M"]
[Sun Aug 30 03:12:01.043981 2026] [security2:error] [pid 524122:tid 524153] [remote 185.93.89.167:39769] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ar.mariegronley.com"] [uri "/core/.env"] [unique_id "apPl0X3lhEjKFiK_nBJ8ZQAB0x0"]
[Sun Aug 30 03:12:01.095697 2026] [security2:error] [pid 521505:tid 521649] [client 68.155.159.216:52316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apPl0W8byYE0iXl--K6MFgAAAyw"]
[Sun Aug 30 03:12:01.104378 2026] [security2:error] [pid 521505:tid 521762] [client 20.151.200.44:45043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/Contrller.php"] [unique_id "apPl0W8byYE0iXl--K6MGQAAA50"]
[Sun Aug 30 03:12:01.122601 2026] [security2:error] [pid 521505:tid 521748] [client 158.23.147.79:58430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-includes/index.php"] [unique_id "apPl0W8byYE0iXl--K6MHQAAA48"]
[Sun Aug 30 03:12:01.133433 2026] [security2:error] [pid 521505:tid 521734] [client 20.48.160.90:61649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/nakrip.php"] [unique_id "apPl0W8byYE0iXl--K6MIwAAA4E"]
[Sun Aug 30 03:12:01.155835 2026] [security2:error] [pid 524122:tid 524333] [client 34.15.159.88:41504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/pinfo.php"] [unique_id "apPl0X3lhEjKFiK_nBJ8cgAAAd8"]
[Sun Aug 30 03:12:01.162831 2026] [authz_core:error] [pid 524122:tid 524269] [client 216.73.216.128:64699] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:01.163284 2026] [authz_core:error] [pid 524122:tid 524269] [client 216.73.216.128:64699] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:01.163967 2026] [security2:error] [pid 521505:tid 521709] [client 20.48.160.90:37718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/xr.php"] [unique_id "apPl0W8byYE0iXl--K6MMgAAA2g"]
[Sun Aug 30 03:12:01.164858 2026] [security2:error] [pid 521505:tid 521666] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/rabbitmq/.env"] [unique_id "apPl0W8byYE0iXl--K6MMQAAAz0"]
[Sun Aug 30 03:12:01.175341 2026] [authz_core:error] [pid 521505:tid 521685] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IL
[Sun Aug 30 03:12:01.175605 2026] [authz_core:error] [pid 521505:tid 521685] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Flib%2Flocale%2Fen_IL
[Sun Aug 30 03:12:01.176477 2026] [security2:error] [pid 521505:tid 521718] [client 20.104.49.130:43271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/worksec.php"] [unique_id "apPl0W8byYE0iXl--K6MOQAAA3E"]
[Sun Aug 30 03:12:01.257201 2026] [security2:error] [pid 524122:tid 524375] [client 158.23.147.79:21440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/xmlrpc.php"] [unique_id "apPl0X3lhEjKFiK_nBJ8fgAAAgk"]
[Sun Aug 30 03:12:01.270075 2026] [security2:error] [pid 521505:tid 521641] [client 20.48.160.90:61694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp-includes/interactivity-api/flower.php"] [unique_id "apPl0W8byYE0iXl--K6MVAAAAyQ"]
[Sun Aug 30 03:12:01.291960 2026] [authz_core:error] [pid 521505:tid 521679] [client 66.249.66.65:37971] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:01.292355 2026] [authz_core:error] [pid 521505:tid 521679] [client 66.249.66.65:37971] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:01.295764 2026] [security2:error] [pid 524122:tid 524347] [client 20.48.160.90:37671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/Q3.php"] [unique_id "apPl0X3lhEjKFiK_nBJ8hwAAAe0"]
[Sun Aug 30 03:12:01.297222 2026] [security2:error] [pid 524122:tid 524279] [client 20.104.49.130:60641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/Jcrop.php"] [unique_id "apPl0X3lhEjKFiK_nBJ8iAAAAak"]
[Sun Aug 30 03:12:01.315768 2026] [authz_core:error] [pid 521505:tid 521702] [client 66.249.66.204:44429] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:01.316064 2026] [authz_core:error] [pid 521505:tid 521702] [client 66.249.66.204:44429] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:01.325834 2026] [security2:error] [pid 521505:tid 521639] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/kafka/.env"] [unique_id "apPl0W8byYE0iXl--K6MagAAAyI"]
[Sun Aug 30 03:12:01.344961 2026] [authz_core:error] [pid 521505:tid 521703] [client 66.249.66.70:53198] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:01.345251 2026] [authz_core:error] [pid 521505:tid 521703] [client 66.249.66.70:53198] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:01.381775 2026] [fcgid:warn] [pid 521505:tid 521756] (70014)End of file found: [client 207.90.244.25:38834] mod_fcgid: can't get data from http client
[Sun Aug 30 03:12:01.390743 2026] [security2:error] [pid 524122:tid 524366] [client 4.205.62.107:16770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/otuz1.php"] [unique_id "apPl0X3lhEjKFiK_nBJ8lgAAAgA"]
[Sun Aug 30 03:12:01.391759 2026] [security2:error] [pid 524122:tid 524353] [client 20.104.50.220:16590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/pop.php"] [unique_id "apPl0X3lhEjKFiK_nBJ8mAAAAfM"]
[Sun Aug 30 03:12:01.397721 2026] [authz_core:error] [pid 524122:tid 524253] [client 66.249.66.200:51733] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:01.398186 2026] [authz_core:error] [pid 524122:tid 524253] [client 66.249.66.200:51733] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:01.409076 2026] [security2:error] [pid 521505:tid 521669] [client 20.48.160.90:61601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/xcc.php"] [unique_id "apPl0W8byYE0iXl--K6MggAAA0A"]
[Sun Aug 30 03:12:01.427788 2026] [security2:error] [pid 521505:tid 521676] [client 20.104.18.15:64702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/manga.php"] [unique_id "apPl0W8byYE0iXl--K6MjAAAA0c"]
[Sun Aug 30 03:12:01.436567 2026] [security2:error] [pid 524122:tid 524300] [client 20.48.251.3:52244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/otuz1.php"] [unique_id "apPl0X3lhEjKFiK_nBJ8nQAAAb4"]
[Sun Aug 30 03:12:01.442059 2026] [security2:error] [pid 524122:tid 524340] [client 20.104.18.15:2036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/img.php"] [unique_id "apPl0X3lhEjKFiK_nBJ8ngAAAeY"]
[Sun Aug 30 03:12:01.444352 2026] [security2:error] [pid 521505:tid 521641] [client 20.48.160.90:37725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/Q1.php"] [unique_id "apPl0W8byYE0iXl--K6MlgAAAyQ"]
[Sun Aug 30 03:12:01.446717 2026] [security2:error] [pid 521505:tid 521736] [client 20.104.50.220:24857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/2222.php"] [unique_id "apPl0W8byYE0iXl--K6MmAAAA4M"]
[Sun Aug 30 03:12:01.448692 2026] [security2:error] [pid 521505:tid 521650] [client 20.104.18.15:22345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/xmini4.php"] [unique_id "apPl0W8byYE0iXl--K6MnAAAAy0"]
[Sun Aug 30 03:12:01.450672 2026] [security2:error] [pid 524122:tid 524156] [remote 185.93.89.167:39769] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ar.mariegronley.com"] [uri "/app/.env"] [unique_id "apPl0X3lhEjKFiK_nBJ8nwABlyA"]
[Sun Aug 30 03:12:01.457063 2026] [security2:error] [pid 521505:tid 521748] [client 20.104.50.220:33184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/pHpINJ.php"] [unique_id "apPl0W8byYE0iXl--K6MowAAA48"]
[Sun Aug 30 03:12:01.464398 2026] [security2:error] [pid 524122:tid 524262] [client 20.104.18.15:51090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/m.php"] [unique_id "apPl0X3lhEjKFiK_nBJ8ogAAAZg"]
[Sun Aug 30 03:12:01.476742 2026] [security2:error] [pid 521505:tid 521689] [client 216.73.216.128:37868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/ourcollection_images/wp-admin/css/install.css"] [unique_id "apPl0W8byYE0iXl--K6MrAAAA1Q"]
[Sun Aug 30 03:12:01.484416 2026] [authz_core:error] [pid 521505:tid 521638] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory29
[Sun Aug 30 03:12:01.484877 2026] [authz_core:error] [pid 521505:tid 521638] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory29
[Sun Aug 30 03:12:01.487276 2026] [security2:error] [pid 521505:tid 521761] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/queue/.env"] [unique_id "apPl0W8byYE0iXl--K6MrwAAA5w"]
[Sun Aug 30 03:12:01.505516 2026] [security2:error] [pid 521505:tid 521637] [client 20.104.50.220:61659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/yellow.php"] [unique_id "apPl0W8byYE0iXl--K6MsQAAAyA"]
[Sun Aug 30 03:12:01.514729 2026] [security2:error] [pid 521505:tid 521667] [client 20.48.251.3:55787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/hosty.php"] [unique_id "apPl0W8byYE0iXl--K6MtAAAAz4"]
[Sun Aug 30 03:12:01.523991 2026] [security2:error] [pid 521505:tid 521746] [client 20.48.251.3:54751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/phina.php"] [unique_id "apPl0W8byYE0iXl--K6MugAAA40"]
[Sun Aug 30 03:12:01.526979 2026] [authz_core:error] [pid 521505:tid 521636] [client 66.249.66.72:47006] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:01.527277 2026] [authz_core:error] [pid 521505:tid 521636] [client 66.249.66.72:47006] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:01.543637 2026] [security2:error] [pid 521505:tid 521660] [client 20.48.160.90:37858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp-includes/Text/Diff/Engine/aaa.php"] [unique_id "apPl0W8byYE0iXl--K6MwwAAAzc"]
[Sun Aug 30 03:12:01.549422 2026] [security2:error] [pid 521505:tid 521760] [client 173.239.211.53:30351] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/wp-includes/hp2.php"] [unique_id "apPl0W8byYE0iXl--K6MygAAA5s"]
[Sun Aug 30 03:12:01.550056 2026] [security2:error] [pid 521505:tid 521742] [client 20.151.200.44:44936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/file66.php"] [unique_id "apPl0W8byYE0iXl--K6MzAAAA4k"]
[Sun Aug 30 03:12:01.551196 2026] [authz_core:error] [pid 521505:tid 521683] [client 66.249.66.66:41799] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:01.551640 2026] [authz_core:error] [pid 521505:tid 521683] [client 66.249.66.66:41799] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:01.576850 2026] [security2:error] [pid 521505:tid 521701] [client 20.48.160.90:37971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/nz.php"] [unique_id "apPl0W8byYE0iXl--K6M2gAAA2A"]
[Sun Aug 30 03:12:01.582887 2026] [security2:error] [pid 524122:tid 524336] [client 20.104.50.220:63213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/zwso.php"] [unique_id "apPl0X3lhEjKFiK_nBJ8sAAAAeI"]
[Sun Aug 30 03:12:01.585447 2026] [security2:error] [pid 524122:tid 524158] [remote 185.93.89.167:39769] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ar.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPl0X3lhEjKFiK_nBJ8sQAB3iI"]
[Sun Aug 30 03:12:01.600605 2026] [security2:error] [pid 521505:tid 521639] [client 20.104.49.130:64071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/002.php"] [unique_id "apPl0W8byYE0iXl--K6M5QAAAyI"]
[Sun Aug 30 03:12:01.603269 2026] [security2:error] [pid 524122:tid 524328] [client 20.104.18.15:31708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wefile.php"] [unique_id "apPl0X3lhEjKFiK_nBJ8tAAAAdo"]
[Sun Aug 30 03:12:01.636781 2026] [security2:error] [pid 521505:tid 521749] [client 20.104.50.220:5575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/505.php"] [unique_id "apPl0W8byYE0iXl--K6M_gAAA5A"]
[Sun Aug 30 03:12:01.648942 2026] [security2:error] [pid 524122:tid 524283] [client 4.205.62.107:16320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/kerang.php"] [unique_id "apPl0X3lhEjKFiK_nBJ8ugAAAa0"]
[Sun Aug 30 03:12:01.649308 2026] [security2:error] [pid 521505:tid 521736] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/worker/.env"] [unique_id "apPl0W8byYE0iXl--K6NAwAAA4M"]
[Sun Aug 30 03:12:01.649479 2026] [security2:error] [pid 524122:tid 524327] [client 4.205.62.107:15978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/mga.php"] [unique_id "apPl0X3lhEjKFiK_nBJ8uwAAAdk"]
[Sun Aug 30 03:12:01.651770 2026] [security2:error] [pid 521505:tid 521686] [client 216.73.216.128:23116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/usage_202601.html"] [unique_id "apPl0W8byYE0iXl--K6NBAAAA1E"]
[Sun Aug 30 03:12:01.662857 2026] [security2:error] [pid 521505:tid 521748] [client 4.205.62.107:52865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/paths.php"] [unique_id "apPl0W8byYE0iXl--K6NCwAAA48"]
[Sun Aug 30 03:12:01.665135 2026] [authz_core:error] [pid 521505:tid 521680] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:01.665678 2026] [authz_core:error] [pid 521505:tid 521680] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:01.678037 2026] [security2:error] [pid 521505:tid 521738] [client 20.48.160.90:61662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp-includes/style-engine/gecko-new.php"] [unique_id "apPl0W8byYE0iXl--K6NFgAAA4U"]
[Sun Aug 30 03:12:01.679857 2026] [security2:error] [pid 521505:tid 521734] [client 20.104.49.130:59572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/dragonshell.php"] [unique_id "apPl0W8byYE0iXl--K6NGQAAA4E"]
[Sun Aug 30 03:12:01.699527 2026] [security2:error] [pid 521505:tid 521709] [client 20.104.50.220:52850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/saya.php"] [unique_id "apPl0W8byYE0iXl--K6NIgAAA2g"]
[Sun Aug 30 03:12:01.712013 2026] [security2:error] [pid 521505:tid 521697] [client 20.48.160.90:37721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/sg.php"] [unique_id "apPl0W8byYE0iXl--K6NJwAAA1w"]
[Sun Aug 30 03:12:01.713097 2026] [security2:error] [pid 521505:tid 521751] [client 20.104.49.130:26687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/3.php"] [unique_id "apPl0W8byYE0iXl--K6NKAAAA5I"]
[Sun Aug 30 03:12:01.720940 2026] [security2:error] [pid 521505:tid 521744] [client 20.104.49.130:48019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/menu.php"] [unique_id "apPl0W8byYE0iXl--K6NLQAAA4s"]
[Sun Aug 30 03:12:01.729743 2026] [authz_core:error] [pid 521505:tid 521745] [client 66.249.66.205:48371] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:01.730025 2026] [authz_core:error] [pid 521505:tid 521745] [client 66.249.66.205:48371] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:01.743454 2026] [security2:error] [pid 524122:tid 524356] [client 216.73.216.128:16209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/'+this.controller.state().get("] [unique_id "apPl0X3lhEjKFiK_nBJ8yAAAAfY"]
[Sun Aug 30 03:12:01.755090 2026] [security2:error] [pid 521505:tid 521690] [client 20.48.251.3:37160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/koiy.php"] [unique_id "apPl0W8byYE0iXl--K6NRAAAA1U"]
[Sun Aug 30 03:12:01.763887 2026] [security2:error] [pid 524122:tid 524335] [client 34.15.159.88:41520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/test.php"] [unique_id "apPl0X3lhEjKFiK_nBJ8ywAAAeE"]
[Sun Aug 30 03:12:01.800147 2026] [security2:error] [pid 521505:tid 521737] [client 158.23.184.117:33088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/bgymj.php"] [unique_id "apPl0W8byYE0iXl--K6NUgAAA4Q"]
[Sun Aug 30 03:12:01.805447 2026] [security2:error] [pid 521505:tid 521675] [client 4.205.62.107:25697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/oc460l3x.php"] [unique_id "apPl0W8byYE0iXl--K6NVAAAA0Y"]
[Sun Aug 30 03:12:01.809422 2026] [authz_core:error] [pid 524122:tid 524346] [client 66.249.66.66:60972] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:01.809751 2026] [authz_core:error] [pid 524122:tid 524346] [client 66.249.66.66:60972] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:01.810830 2026] [security2:error] [pid 521505:tid 521741] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/job/.env"] [unique_id "apPl0W8byYE0iXl--K6NWAAAA4g"]
[Sun Aug 30 03:12:01.811121 2026] [security2:error] [pid 521505:tid 521670] [client 20.48.160.90:61599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp-settings.php"] [unique_id "apPl0W8byYE0iXl--K6NWQAAA0E"]
[Sun Aug 30 03:12:01.834417 2026] [security2:error] [pid 521505:tid 521711] [client 20.104.18.15:18406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/sushi.php"] [unique_id "apPl0W8byYE0iXl--K6NZwAAA2o"]
[Sun Aug 30 03:12:01.849468 2026] [security2:error] [pid 521505:tid 521742] [client 20.48.160.90:37726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/hypo.php"] [unique_id "apPl0W8byYE0iXl--K6NcgAAA4k"]
[Sun Aug 30 03:12:01.854606 2026] [security2:error] [pid 524122:tid 524160] [remote 185.93.89.167:39769] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ar.mariegronley.com"] [uri "/server/.env"] [unique_id "apPl0X3lhEjKFiK_nBJ80gAB0CQ"]
[Sun Aug 30 03:12:01.869007 2026] [security2:error] [pid 524122:tid 524292] [client 20.104.49.130:52131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/about.php"] [unique_id "apPl0X3lhEjKFiK_nBJ81QAAAbY"]
[Sun Aug 30 03:12:01.892977 2026] [security2:error] [pid 524122:tid 524263] [client 20.151.200.44:44945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/blnux.php"] [unique_id "apPl0X3lhEjKFiK_nBJ81wAAAZk"]
[Sun Aug 30 03:12:01.940422 2026] [security2:error] [pid 524122:tid 524317] [client 158.23.184.117:33101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/bk/index.php"] [unique_id "apPl0X3lhEjKFiK_nBJ82gAAAc8"]
[Sun Aug 30 03:12:01.943569 2026] [security2:error] [pid 524122:tid 524326] [client 20.48.160.90:37843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp-signup.php"] [unique_id "apPl0X3lhEjKFiK_nBJ82wAAAdg"]
[Sun Aug 30 03:12:01.949704 2026] [security2:error] [pid 524122:tid 524378] [client 20.104.50.220:42042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/ex0shell.php"] [unique_id "apPl0X3lhEjKFiK_nBJ83AAAAgw"]
[Sun Aug 30 03:12:01.968629 2026] [authz_core:error] [pid 521505:tid 521643] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory24
[Sun Aug 30 03:12:01.969074 2026] [authz_core:error] [pid 521505:tid 521643] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory24
[Sun Aug 30 03:12:01.973227 2026] [security2:error] [pid 521505:tid 521694] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/test/.env"] [unique_id "apPl0W8byYE0iXl--K6NlgAAA1k"]
[Sun Aug 30 03:12:01.986797 2026] [security2:error] [pid 521505:tid 521709] [client 20.48.160.90:30804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/Hd.php"] [unique_id "apPl0W8byYE0iXl--K6NngAAA2g"]
[Sun Aug 30 03:12:02.033057 2026] [security2:error] [pid 521505:tid 521695] [client 173.239.211.47:24521] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/wp-includes/pomo/visualcore.php"] [unique_id "apPl0m8byYE0iXl--K6NqwAAA1o"]
[Sun Aug 30 03:12:02.073345 2026] [security2:error] [pid 521505:tid 521686] [client 20.48.160.90:61580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp-conffg.php"] [unique_id "apPl0m8byYE0iXl--K6NwgAAA1E"]
[Sun Aug 30 03:12:02.080733 2026] [security2:error] [pid 521505:tid 521710] [client 158.23.184.117:33092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/bootstrap.php"] [unique_id "apPl0m8byYE0iXl--K6NwwAAA2k"]
[Sun Aug 30 03:12:02.096759 2026] [security2:error] [pid 524122:tid 524359] [client 20.104.50.220:52861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-content/uploads/simple-file-list/fw.php"] [unique_id "apPl0n3lhEjKFiK_nBJ88QAAAfk"]
[Sun Aug 30 03:12:02.107429 2026] [security2:error] [pid 521505:tid 521677] [client 216.73.216.128:52891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/sasl/developer/testing.html"] [unique_id "apPl0m8byYE0iXl--K6NzgAAA0g"]
[Sun Aug 30 03:12:02.129188 2026] [security2:error] [pid 521505:tid 521701] [client 20.48.160.90:61452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/im.php"] [unique_id "apPl0m8byYE0iXl--K6N2QAAA2A"]
[Sun Aug 30 03:12:02.133419 2026] [security2:error] [pid 521505:tid 521697] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/qa/.env"] [unique_id "apPl0m8byYE0iXl--K6N3AAAA1w"]
[Sun Aug 30 03:12:02.138971 2026] [security2:error] [pid 521505:tid 521756] [client 158.23.147.79:39943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/atomlib.php"] [unique_id "apPl0m8byYE0iXl--K6N3QAAA5c"]
[Sun Aug 30 03:12:02.171104 2026] [authz_core:error] [pid 521505:tid 521754] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:02.171473 2026] [authz_core:error] [pid 521505:tid 521754] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:02.209423 2026] [security2:error] [pid 521505:tid 521680] [client 20.48.160.90:61631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp-validate.php"] [unique_id "apPl0m8byYE0iXl--K6N-gAAA0s"]
[Sun Aug 30 03:12:02.218996 2026] [security2:error] [pid 521505:tid 521738] [client 158.23.184.117:33431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/bs1.php"] [unique_id "apPl0m8byYE0iXl--K6N_QAAA4U"]
[Sun Aug 30 03:12:02.225518 2026] [security2:error] [pid 521505:tid 521675] [client 20.104.49.130:43292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/666.php"] [unique_id "apPl0m8byYE0iXl--K6N_wAAA0Y"]
[Sun Aug 30 03:12:02.259708 2026] [security2:error] [pid 524122:tid 524165] [remote 185.93.89.167:39769] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ar.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPl0n3lhEjKFiK_nBJ9AwACBCk"]
[Sun Aug 30 03:12:02.277222 2026] [security2:error] [pid 521505:tid 521724] [client 20.48.160.90:37743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/fc.php"] [unique_id "apPl0m8byYE0iXl--K6OGQAAA3c"]
[Sun Aug 30 03:12:02.285370 2026] [security2:error] [pid 521505:tid 521669] [client 68.155.159.216:52308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPl0m8byYE0iXl--K6OKAAAA0A"]
[Sun Aug 30 03:12:02.289768 2026] [authz_core:error] [pid 521505:tid 521654] [client 66.249.66.64:47381] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:02.290224 2026] [authz_core:error] [pid 521505:tid 521654] [client 66.249.66.64:47381] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:02.293448 2026] [security2:error] [pid 521505:tid 521758] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/preview/.env"] [unique_id "apPl0m8byYE0iXl--K6OLgAAA5k"]
[Sun Aug 30 03:12:02.330684 2026] [security2:error] [pid 521505:tid 521730] [client 20.151.200.44:63646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/sxxb.php"] [unique_id "apPl0m8byYE0iXl--K6OPQAAA30"]
[Sun Aug 30 03:12:02.348784 2026] [security2:error] [pid 524122:tid 524293] [client 20.48.160.90:37879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/700.php"] [unique_id "apPl0n3lhEjKFiK_nBJ9DgAAAbc"]
[Sun Aug 30 03:12:02.357855 2026] [security2:error] [pid 521505:tid 521711] [client 158.23.184.117:33413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/bthil.php"] [unique_id "apPl0m8byYE0iXl--K6OSQAAA2o"]
[Sun Aug 30 03:12:02.386452 2026] [authz_core:error] [pid 521505:tid 521686] [client 216.73.216.128:37868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:02.386766 2026] [authz_core:error] [pid 521505:tid 521686] [client 216.73.216.128:37868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:02.412273 2026] [security2:error] [pid 524122:tid 524301] [client 20.104.49.130:48011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPl0n3lhEjKFiK_nBJ9FQAAAb8"]
[Sun Aug 30 03:12:02.417433 2026] [security2:error] [pid 521505:tid 521757] [client 20.48.160.90:38007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/ke.php"] [unique_id "apPl0m8byYE0iXl--K6OXQAAA5g"]
[Sun Aug 30 03:12:02.453684 2026] [security2:error] [pid 521505:tid 521671] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/beta/.env"] [unique_id "apPl0m8byYE0iXl--K6OcwAAA0I"]
[Sun Aug 30 03:12:02.488734 2026] [security2:error] [pid 524122:tid 524286] [client 20.48.160.90:37833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/c4.php"] [unique_id "apPl0n3lhEjKFiK_nBJ9HAAAAbA"]
[Sun Aug 30 03:12:02.499007 2026] [security2:error] [pid 521505:tid 521710] [client 158.23.184.117:33425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/buy.php"] [unique_id "apPl0m8byYE0iXl--K6OgAAAA2k"]
[Sun Aug 30 03:12:02.527813 2026] [security2:error] [pid 521505:tid 521707] [client 4.205.62.107:17088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/update.php"] [unique_id "apPl0m8byYE0iXl--K6OjgAAA2Y"]
[Sun Aug 30 03:12:02.530510 2026] [security2:error] [pid 521505:tid 521735] [client 20.104.50.220:17234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/az.php"] [unique_id "apPl0m8byYE0iXl--K6OkAAAA4I"]
[Sun Aug 30 03:12:02.536541 2026] [authz_core:error] [pid 521505:tid 521695] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory24
[Sun Aug 30 03:12:02.536830 2026] [authz_core:error] [pid 521505:tid 521695] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory24
[Sun Aug 30 03:12:02.560084 2026] [security2:error] [pid 524122:tid 524331] [client 20.104.49.130:53727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/users.php"] [unique_id "apPl0n3lhEjKFiK_nBJ9JgAAAd0"]
[Sun Aug 30 03:12:02.565083 2026] [security2:error] [pid 521505:tid 521653] [client 20.48.160.90:37706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/tf.php"] [unique_id "apPl0m8byYE0iXl--K6OoAAAAzA"]
[Sun Aug 30 03:12:02.570143 2026] [authz_core:error] [pid 521505:tid 521680] [client 216.73.216.128:37868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:02.570176 2026] [security2:error] [pid 521505:tid 521721] [client 20.104.18.15:64716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/asdfghj.php"] [unique_id "apPl0m8byYE0iXl--K6OpAAAA3Q"]
[Sun Aug 30 03:12:02.570414 2026] [authz_core:error] [pid 521505:tid 521680] [client 216.73.216.128:37868] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:02.574420 2026] [security2:error] [pid 524122:tid 524296] [client 20.48.251.3:43127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/update.php"] [unique_id "apPl0n3lhEjKFiK_nBJ9KAAAAbo"]
[Sun Aug 30 03:12:02.574561 2026] [security2:error] [pid 521505:tid 521639] [client 20.151.200.44:41934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.esselwebdesign.com"] [uri "/waf.php"] [unique_id "apPl0m8byYE0iXl--K6OpwAAAyI"]
[Sun Aug 30 03:12:02.576948 2026] [authz_core:error] [pid 521505:tid 521670] [client 66.249.66.193:52804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:02.577286 2026] [authz_core:error] [pid 521505:tid 521670] [client 66.249.66.193:52804] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:02.578806 2026] [security2:error] [pid 524122:tid 524271] [client 20.104.18.15:2003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/222.php"] [unique_id "apPl0n3lhEjKFiK_nBJ9KQAAAaE"]
[Sun Aug 30 03:12:02.579267 2026] [security2:error] [pid 521505:tid 521506] [remote 87.250.224.234:50680] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "ourcalmchrysalis.com"] [uri "/wzy.php"] [unique_id "apPl0m8byYE0iXl--K6OlAADfAA"]
[Sun Aug 30 03:12:02.584058 2026] [security2:error] [pid 521505:tid 521743] [client 20.104.50.220:24833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/h02ugyh.php"] [unique_id "apPl0m8byYE0iXl--K6OsAAAA4o"]
[Sun Aug 30 03:12:02.600702 2026] [security2:error] [pid 521505:tid 521691] [client 20.151.200.44:44001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ermes-it.it"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPl0m8byYE0iXl--K6OugAAA1Y"]
[Sun Aug 30 03:12:02.602307 2026] [security2:error] [pid 521505:tid 521688] [client 158.23.147.79:40046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/lv.php"] [unique_id "apPl0m8byYE0iXl--K6OuwAAA1M"]
[Sun Aug 30 03:12:02.607202 2026] [security2:error] [pid 521505:tid 521690] [client 20.104.18.15:22392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/gulu.php"] [unique_id "apPl0m8byYE0iXl--K6OvgAAA1U"]
[Sun Aug 30 03:12:02.613794 2026] [security2:error] [pid 521505:tid 521715] [client 20.104.50.220:33545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/robot.php"] [unique_id "apPl0m8byYE0iXl--K6OwQAAA24"]
[Sun Aug 30 03:12:02.614344 2026] [security2:error] [pid 521505:tid 521644] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/uat/.env"] [unique_id "apPl0m8byYE0iXl--K6OwAAAAyc"]
[Sun Aug 30 03:12:02.614603 2026] [security2:error] [pid 521505:tid 521711] [client 20.104.18.15:51165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/fling.php"] [unique_id "apPl0m8byYE0iXl--K6OwgAAA2o"]
[Sun Aug 30 03:12:02.626768 2026] [security2:error] [pid 521505:tid 521760] [client 20.48.160.90:61693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp-tymanage.php"] [unique_id "apPl0m8byYE0iXl--K6OywAAA5s"]
[Sun Aug 30 03:12:02.633395 2026] [security2:error] [pid 524122:tid 524281] [client 173.239.211.37:62289] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/wp-content/themes.php"] [unique_id "apPl0n3lhEjKFiK_nBJ9MgAAAas"]
[Sun Aug 30 03:12:02.636715 2026] [security2:error] [pid 521505:tid 521685] [client 20.104.49.130:52442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/press.php"] [unique_id "apPl0m8byYE0iXl--K6O0AAAA1A"]
[Sun Aug 30 03:12:02.639894 2026] [security2:error] [pid 521505:tid 521676] [client 158.23.184.117:33423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/byp.php"] [unique_id "apPl0m8byYE0iXl--K6O0wAAA0c"]
[Sun Aug 30 03:12:02.658787 2026] [security2:error] [pid 521505:tid 521732] [client 20.104.50.220:61393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wfile.php"] [unique_id "apPl0m8byYE0iXl--K6O2wAAA38"]
[Sun Aug 30 03:12:02.662388 2026] [security2:error] [pid 524122:tid 524328] [client 20.48.251.3:65514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/koiy.php"] [unique_id "apPl0n3lhEjKFiK_nBJ9NgAAAdo"]
[Sun Aug 30 03:12:02.677726 2026] [authz_core:error] [pid 521505:tid 521730] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:02.677996 2026] [authz_core:error] [pid 521505:tid 521730] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:02.679993 2026] [security2:error] [pid 524122:tid 524333] [client 20.48.251.3:52791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/pass4.php"] [unique_id "apPl0n3lhEjKFiK_nBJ9OwAAAd8"]
[Sun Aug 30 03:12:02.689522 2026] [authz_core:error] [pid 524122:tid 524363] [client 66.249.66.200:64460] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:02.689827 2026] [authz_core:error] [pid 524122:tid 524363] [client 66.249.66.200:64460] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:02.693574 2026] [security2:error] [pid 521505:tid 521702] [client 20.48.160.90:37983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/px.php"] [unique_id "apPl0m8byYE0iXl--K6O8wAAA2E"]
[Sun Aug 30 03:12:02.695110 2026] [security2:error] [pid 524122:tid 524283] [client 20.151.200.44:45036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/attack.php"] [unique_id "apPl0n3lhEjKFiK_nBJ9PgAAAa0"]
[Sun Aug 30 03:12:02.718354 2026] [security2:error] [pid 524122:tid 524313] [client 20.104.50.220:31491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "apPl0n3lhEjKFiK_nBJ9QgAAAcs"]
[Sun Aug 30 03:12:02.737188 2026] [security2:error] [pid 524122:tid 524361] [client 20.104.18.15:31584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-load.php"] [unique_id "apPl0n3lhEjKFiK_nBJ9RgAAAfs"]
[Sun Aug 30 03:12:02.760088 2026] [security2:error] [pid 524122:tid 524306] [client 20.48.160.90:37869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/ajfto.php"] [unique_id "apPl0n3lhEjKFiK_nBJ9TQAAAcQ"]
[Sun Aug 30 03:12:02.774793 2026] [security2:error] [pid 521505:tid 521650] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/stage/.env"] [unique_id "apPl0m8byYE0iXl--K6PFwAAAy0"]
[Sun Aug 30 03:12:02.780218 2026] [security2:error] [pid 524122:tid 524311] [client 158.23.184.117:33110] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "www.blog.lunajos.com"] [uri "/c99.php"] [unique_id "apPl0n3lhEjKFiK_nBJ9TwAAAck"]
[Sun Aug 30 03:12:02.781785 2026] [security2:error] [pid 524122:tid 524335] [client 20.104.50.220:5490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/500.php"] [unique_id "apPl0n3lhEjKFiK_nBJ9UAAAAeE"]
[Sun Aug 30 03:12:02.790370 2026] [security2:error] [pid 524122:tid 524253] [client 4.205.62.107:16342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/ccou.php"] [unique_id "apPl0n3lhEjKFiK_nBJ9UQAAAY8"]
[Sun Aug 30 03:12:02.791742 2026] [security2:error] [pid 521505:tid 521742] [client 4.205.62.107:16323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/rem.php"] [unique_id "apPl0m8byYE0iXl--K6PGwAAA4k"]
[Sun Aug 30 03:12:02.806734 2026] [security2:error] [pid 521505:tid 521722] [client 216.73.216.128:64101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_config_status_msg_delay"] [unique_id "apPl0m8byYE0iXl--K6PIwAAA3U"]
[Sun Aug 30 03:12:02.815587 2026] [security2:error] [pid 521505:tid 521664] [client 4.205.62.107:52805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/olfclass.php"] [unique_id "apPl0m8byYE0iXl--K6PKQAAAzs"]
[Sun Aug 30 03:12:02.825877 2026] [security2:error] [pid 524122:tid 524376] [client 20.151.200.44:26571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/file66.php"] [unique_id "apPl0n3lhEjKFiK_nBJ9WgAAAgo"]
[Sun Aug 30 03:12:02.856606 2026] [security2:error] [pid 521505:tid 521706] [client 20.48.160.90:61498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/jg.php"] [unique_id "apPl0m8byYE0iXl--K6PQwAAA2U"]
[Sun Aug 30 03:12:02.876770 2026] [ssl:error] [pid 521505:tid 521698] [client 199.45.154.52:58748] AH02032: Hostname gator3166.hostgator.com (default host as no SNI was provided) and hostname mail.forensictoxicology.co.uk provided via HTTP have no compatible SSL setup for policy 'secure'
[Sun Aug 30 03:12:02.880449 2026] [security2:error] [pid 521505:tid 521691] [client 158.23.147.79:60167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/mah.php"] [unique_id "apPl0m8byYE0iXl--K6PUAAAA1Y"]
[Sun Aug 30 03:12:02.889229 2026] [security2:error] [pid 521505:tid 521731] [client 20.104.50.220:28675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/do.php"] [unique_id "apPl0m8byYE0iXl--K6PVgAAA34"]
[Sun Aug 30 03:12:02.893080 2026] [security2:error] [pid 521505:tid 521652] [client 20.48.160.90:61617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp_KwIW0U5F.php"] [unique_id "apPl0m8byYE0iXl--K6PWAAAAy8"]
[Sun Aug 30 03:12:02.905865 2026] [security2:error] [pid 521505:tid 521738] [client 20.48.251.3:37001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/w.php"] [unique_id "apPl0m8byYE0iXl--K6PYgAAA4U"]
[Sun Aug 30 03:12:02.906659 2026] [security2:error] [pid 524122:tid 524347] [client 20.104.49.130:43319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/echkm.php"] [unique_id "apPl0n3lhEjKFiK_nBJ9YAAAAe0"]
[Sun Aug 30 03:12:02.920517 2026] [security2:error] [pid 521505:tid 521744] [client 158.23.184.117:33438] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "www.blog.lunajos.com"] [uri "/c99.php"] [unique_id "apPl0m8byYE0iXl--K6PZQAAA4s"]
[Sun Aug 30 03:12:02.934935 2026] [security2:error] [pid 521505:tid 521700] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/development/.env"] [unique_id "apPl0m8byYE0iXl--K6PawAAA18"]
[Sun Aug 30 03:12:02.936360 2026] [security2:error] [pid 524122:tid 524174] [remote 185.93.89.167:39769] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ar.mariegronley.com"] [uri "/source/.env"] [unique_id "apPl0n3lhEjKFiK_nBJ9YgABvjI"]
[Sun Aug 30 03:12:02.944980 2026] [authz_core:error] [pid 521505:tid 521686] [client 66.249.66.35:43266] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:02.945249 2026] [authz_core:error] [pid 521505:tid 521686] [client 66.249.66.35:43266] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:02.957229 2026] [security2:error] [pid 524122:tid 524343] [client 4.205.62.107:25491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/drykl.php"] [unique_id "apPl0n3lhEjKFiK_nBJ9ZgAAAek"]
[Sun Aug 30 03:12:02.963710 2026] [security2:error] [pid 524122:tid 524175] [remote 168.63.79.147:57964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/wp-login.php"] [unique_id "apPl0n3lhEjKFiK_nBJ9aAABljM"]
[Sun Aug 30 03:12:02.970961 2026] [security2:error] [pid 524122:tid 524325] [client 20.104.18.15:18353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/manga.php"] [unique_id "apPl0n3lhEjKFiK_nBJ9agAAAdc"]
[Sun Aug 30 03:12:02.992275 2026] [authz_core:error] [pid 521505:tid 521643] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory28
[Sun Aug 30 03:12:02.992554 2026] [authz_core:error] [pid 521505:tid 521643] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory28
[Sun Aug 30 03:12:02.996391 2026] [security2:error] [pid 521505:tid 521674] [client 20.48.160.90:61509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/yj.php"] [unique_id "apPl0m8byYE0iXl--K6PgQAAA0U"]
[Sun Aug 30 03:12:03.023286 2026] [security2:error] [pid 521505:tid 521730] [client 20.48.160.90:61667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp_xiPu52Ut.php"] [unique_id "apPl028byYE0iXl--K6PjAAAA30"]
[Sun Aug 30 03:12:03.032900 2026] [security2:error] [pid 521505:tid 521675] [client 63.135.161.116:49849] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/gifclass.php"] [unique_id "apPl028byYE0iXl--K6PjgAAA0Y"]
[Sun Aug 30 03:12:03.052434 2026] [authz_core:error] [pid 521505:tid 521671] [client 66.249.66.39:59819] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:03.052850 2026] [authz_core:error] [pid 521505:tid 521671] [client 66.249.66.39:59819] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:03.061218 2026] [security2:error] [pid 521505:tid 521743] [client 158.23.184.117:33123] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "www.blog.lunajos.com"] [uri "/c99.php"] [unique_id "apPl028byYE0iXl--K6PnQAAA4o"]
[Sun Aug 30 03:12:03.065928 2026] [security2:error] [pid 521505:tid 521666] [client 94.154.43.135:24298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.auctionragstoriches.com"] [uri "/.env"] [unique_id "apPl028byYE0iXl--K6PngAAAz0"]
[Sun Aug 30 03:12:03.094493 2026] [security2:error] [pid 521505:tid 521690] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/production/.env"] [unique_id "apPl028byYE0iXl--K6PrgAAA1U"]
[Sun Aug 30 03:12:03.106907 2026] [security2:error] [pid 524122:tid 524298] [client 20.151.200.44:62915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/dx.php"] [unique_id "apPl033lhEjKFiK_nBJ9eQAAAbw"]
[Sun Aug 30 03:12:03.123158 2026] [security2:error] [pid 521505:tid 521722] [client 20.104.50.220:51576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/exp.php"] [unique_id "apPl028byYE0iXl--K6PuQAAA3U"]
[Sun Aug 30 03:12:03.143379 2026] [security2:error] [pid 524122:tid 524177] [remote 168.63.79.147:57964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.79.63.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/wp-login.php"] [unique_id "apPl033lhEjKFiK_nBJ9fgAB4jU"], referer: https://gracejolliffe.com/wp-login.php
[Sun Aug 30 03:12:03.146917 2026] [security2:error] [pid 521505:tid 521714] [client 20.48.160.90:61466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/zi.php"] [unique_id "apPl028byYE0iXl--K6PxAAAA20"]
[Sun Aug 30 03:12:03.151192 2026] [security2:error] [pid 521505:tid 521660] [client 20.48.160.90:37834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp_n5VD7XDh.php"] [unique_id "apPl028byYE0iXl--K6PyQAAAzc"]
[Sun Aug 30 03:12:03.203224 2026] [authz_core:error] [pid 521505:tid 521635] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:03.203497 2026] [authz_core:error] [pid 521505:tid 521635] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:03.204250 2026] [security2:error] [pid 524122:tid 524322] [client 20.104.49.130:52440] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.wdfjba.org"] [uri "/1.php"] [unique_id "apPl033lhEjKFiK_nBJ9hAAAAdQ"]
[Sun Aug 30 03:12:03.204352 2026] [security2:error] [pid 524122:tid 524322] [client 20.104.49.130:52440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wdfjba.org"] [uri "/1.php"] [unique_id "apPl033lhEjKFiK_nBJ9hAAAAdQ"]
[Sun Aug 30 03:12:03.205680 2026] [security2:error] [pid 524122:tid 524178] [remote 185.93.89.167:39769] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ar.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPl033lhEjKFiK_nBJ9hQABzjY"]
[Sun Aug 30 03:12:03.250140 2026] [security2:error] [pid 521505:tid 521732] [client 34.15.159.88:41526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/p.php"] [unique_id "apPl028byYE0iXl--K6P7QAAA38"]
[Sun Aug 30 03:12:03.254088 2026] [security2:error] [pid 521505:tid 521651] [client 35.247.242.193:53606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/config/app/.env"] [unique_id "apPl028byYE0iXl--K6P7gAAAy4"]
[Sun Aug 30 03:12:03.262919 2026] [security2:error] [pid 521505:tid 521676] [client 20.104.50.220:29128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-content/uploads/simple-file-list/alfa.php"] [unique_id "apPl028byYE0iXl--K6P9AAAA0c"]
[Sun Aug 30 03:12:03.277396 2026] [security2:error] [pid 521505:tid 521708] [client 20.48.160.90:61520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/ue.php"] [unique_id "apPl028byYE0iXl--K6QAwAAA2c"]
[Sun Aug 30 03:12:03.283897 2026] [security2:error] [pid 521505:tid 521762] [client 20.104.49.130:43267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/amax.php"] [unique_id "apPl028byYE0iXl--K6QCAAAA50"]
[Sun Aug 30 03:12:03.296054 2026] [security2:error] [pid 524122:tid 524255] [client 158.23.147.79:40059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apPl033lhEjKFiK_nBJ9lQAAAZE"]
[Sun Aug 30 03:12:03.326002 2026] [security2:error] [pid 524122:tid 524311] [client 20.48.160.90:61653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp-mini.php"] [unique_id "apPl033lhEjKFiK_nBJ9lgAAAck"]
[Sun Aug 30 03:12:03.339284 2026] [security2:error] [pid 524122:tid 524179] [remote 185.93.89.167:39769] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ar.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPl033lhEjKFiK_nBJ9lwABzTc"]
[Sun Aug 30 03:12:03.392300 2026] [authz_core:error] [pid 524122:tid 524253] [client 66.249.66.203:41529] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:03.392618 2026] [authz_core:error] [pid 524122:tid 524253] [client 66.249.66.203:41529] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:03.413653 2026] [security2:error] [pid 524122:tid 524368] [client 20.48.160.90:37745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/nv.php"] [unique_id "apPl033lhEjKFiK_nBJ9pAAAAgI"]
[Sun Aug 30 03:12:03.415779 2026] [security2:error] [pid 521505:tid 521652] [client 35.247.242.193:53606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/phpinfo.php"] [unique_id "apPl028byYE0iXl--K6QKAAAAy8"]
[Sun Aug 30 03:12:03.463012 2026] [security2:error] [pid 524122:tid 524374] [client 20.48.160.90:61626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/xmini4.php"] [unique_id "apPl033lhEjKFiK_nBJ9rwAAAgg"]
[Sun Aug 30 03:12:03.472746 2026] [security2:error] [pid 524122:tid 524180] [remote 185.93.89.167:39769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ar.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPl033lhEjKFiK_nBJ9sQAB9zg"]
[Sun Aug 30 03:12:03.476599 2026] [security2:error] [pid 524122:tid 524340] [client 68.155.159.216:54277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/ans.php"] [unique_id "apPl033lhEjKFiK_nBJ9sgAAAeY"]
[Sun Aug 30 03:12:03.496319 2026] [authz_core:error] [pid 521505:tid 521707] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory28
[Sun Aug 30 03:12:03.496755 2026] [authz_core:error] [pid 521505:tid 521707] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory28
[Sun Aug 30 03:12:03.531045 2026] [security2:error] [pid 524122:tid 524348] [client 63.135.161.115:44505] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/bless.php"] [unique_id "apPl033lhEjKFiK_nBJ9twAAAe4"]
[Sun Aug 30 03:12:03.532681 2026] [security2:error] [pid 521505:tid 521683] [client 20.104.49.130:43321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/init.php"] [unique_id "apPl028byYE0iXl--K6QWAAAA04"]
[Sun Aug 30 03:12:03.546355 2026] [security2:error] [pid 524122:tid 524298] [client 20.48.160.90:30819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/jw.php"] [unique_id "apPl033lhEjKFiK_nBJ9uwAAAbw"]
[Sun Aug 30 03:12:03.591323 2026] [security2:error] [pid 524122:tid 524332] [client 20.48.160.90:37857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/reop3.php"] [unique_id "apPl033lhEjKFiK_nBJ9wQAAAd4"]
[Sun Aug 30 03:12:03.606694 2026] [security2:error] [pid 524122:tid 524181] [remote 185.93.89.167:39769] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ar.mariegronley.com"] [uri "/system/.env"] [unique_id "apPl033lhEjKFiK_nBJ9yQABlDk"]
[Sun Aug 30 03:12:03.646821 2026] [security2:error] [pid 521505:tid 521653] [client 20.104.49.130:52326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/ws45.php"] [unique_id "apPl028byYE0iXl--K6QkwAAAzA"]
[Sun Aug 30 03:12:03.650044 2026] [security2:error] [pid 521505:tid 521690] [client 20.104.50.220:16701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/xaz.php"] [unique_id "apPl028byYE0iXl--K6QlQAAA1U"]
[Sun Aug 30 03:12:03.654917 2026] [authz_core:error] [pid 521505:tid 521692] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:03.655176 2026] [authz_core:error] [pid 521505:tid 521692] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:03.664784 2026] [security2:error] [pid 521505:tid 521680] [client 158.23.147.79:16334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-blog-header.php"] [unique_id "apPl028byYE0iXl--K6QnAAAA0s"]
[Sun Aug 30 03:12:03.665922 2026] [security2:error] [pid 524122:tid 524342] [client 4.205.62.107:16819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/channels.php"] [unique_id "apPl033lhEjKFiK_nBJ91AAAAeg"]
[Sun Aug 30 03:12:03.675870 2026] [security2:error] [pid 524122:tid 524373] [client 20.104.49.130:63256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/ws85.php"] [unique_id "apPl033lhEjKFiK_nBJ93AAAAgc"]
[Sun Aug 30 03:12:03.676538 2026] [security2:error] [pid 521505:tid 521717] [client 20.48.160.90:30758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/or.php"] [unique_id "apPl028byYE0iXl--K6QpAAAA3A"]
[Sun Aug 30 03:12:03.709674 2026] [security2:error] [pid 521505:tid 521747] [client 20.48.251.3:43078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/channels.php"] [unique_id "apPl028byYE0iXl--K6QsgAAA44"]
[Sun Aug 30 03:12:03.717069 2026] [security2:error] [pid 521505:tid 521706] [client 20.48.160.90:37848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp-mail.php"] [unique_id "apPl028byYE0iXl--K6QuAAAA2U"]
[Sun Aug 30 03:12:03.717507 2026] [security2:error] [pid 521505:tid 521699] [client 20.104.18.15:1980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/key.php"] [unique_id "apPl028byYE0iXl--K6QuQAAA14"]
[Sun Aug 30 03:12:03.718784 2026] [security2:error] [pid 524122:tid 524312] [client 20.104.18.15:64719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/dragonshell.php"] [unique_id "apPl033lhEjKFiK_nBJ94QAAAco"]
[Sun Aug 30 03:12:03.722289 2026] [security2:error] [pid 524122:tid 524319] [client 20.104.50.220:24836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/seiso.php"] [unique_id "apPl033lhEjKFiK_nBJ94gAAAdE"]
[Sun Aug 30 03:12:03.739854 2026] [security2:error] [pid 524122:tid 524184] [remote 185.93.89.167:39769] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "ar.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPl033lhEjKFiK_nBJ95AAB8zw"]
[Sun Aug 30 03:12:03.758693 2026] [security2:error] [pid 521505:tid 521682] [client 20.104.18.15:51092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/btyuio.php"] [unique_id "apPl028byYE0iXl--K6QzQAAA00"]
[Sun Aug 30 03:12:03.764408 2026] [security2:error] [pid 521505:tid 521744] [client 20.104.18.15:22447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/replace.php"] [unique_id "apPl028byYE0iXl--K6Q0gAAA4s"]
[Sun Aug 30 03:12:03.771877 2026] [security2:error] [pid 524122:tid 524326] [client 20.104.50.220:33570] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "523"] [id "900207"] [msg "Sys[0-9]+ Mailer"] [hostname "mail.icanto.com"] [uri "/sys32.php"] [unique_id "apPl033lhEjKFiK_nBJ95wAAAdg"]
[Sun Aug 30 03:12:03.774606 2026] [security2:error] [pid 521505:tid 521731] [client 20.104.49.130:64093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/wen.php"] [unique_id "apPl028byYE0iXl--K6Q0wAAA34"]
[Sun Aug 30 03:12:03.783110 2026] [authz_core:error] [pid 524122:tid 524351] [client 66.249.66.34:62270] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:03.783385 2026] [authz_core:error] [pid 524122:tid 524351] [client 66.249.66.34:62270] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:03.799387 2026] [security2:error] [pid 521505:tid 521721] [client 20.48.251.3:64259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/queue.php"] [unique_id "apPl028byYE0iXl--K6Q4wAAA3Q"]
[Sun Aug 30 03:12:03.814439 2026] [security2:error] [pid 524122:tid 524355] [client 20.48.251.3:55734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/cu.php"] [unique_id "apPl033lhEjKFiK_nBJ99AAAAfU"]
[Sun Aug 30 03:12:03.827780 2026] [security2:error] [pid 524122:tid 524295] [client 20.48.160.90:30770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/ile56.php"] [unique_id "apPl033lhEjKFiK_nBJ99QAAAbk"]
[Sun Aug 30 03:12:03.831516 2026] [security2:error] [pid 521505:tid 521692] [client 63.135.161.116:52525] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/wp-content/goods.php"] [unique_id "apPl028byYE0iXl--K6Q_QAAA1c"]
[Sun Aug 30 03:12:03.847857 2026] [security2:error] [pid 524122:tid 524281] [client 20.48.160.90:37780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp-conffg.php"] [unique_id "apPl033lhEjKFiK_nBJ9-QAAAas"]
[Sun Aug 30 03:12:03.856836 2026] [security2:error] [pid 524122:tid 524255] [client 34.15.159.88:41532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/debug.php"] [unique_id "apPl033lhEjKFiK_nBJ9_AAAAZE"]
[Sun Aug 30 03:12:03.863222 2026] [security2:error] [pid 521505:tid 521746] [client 20.104.50.220:62006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/class20.php"] [unique_id "apPl028byYE0iXl--K6RCwAAA40"]
[Sun Aug 30 03:12:03.880311 2026] [security2:error] [pid 524122:tid 524280] [client 20.104.50.220:31511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/class19.php"] [unique_id "apPl033lhEjKFiK_nBJ-AwAAAao"]
[Sun Aug 30 03:12:03.887287 2026] [security2:error] [pid 524122:tid 524305] [client 20.104.49.130:52443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/edit.php"] [unique_id "apPl033lhEjKFiK_nBJ-BQAAAcM"]
[Sun Aug 30 03:12:03.890170 2026] [security2:error] [pid 524122:tid 524316] [client 158.23.147.79:40050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/content.php"] [unique_id "apPl033lhEjKFiK_nBJ-BwAAAc4"]
[Sun Aug 30 03:12:03.910356 2026] [security2:error] [pid 521505:tid 521751] [client 20.104.18.15:31734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/robot.php"] [unique_id "apPl028byYE0iXl--K6RHgAAA5I"]
[Sun Aug 30 03:12:03.918506 2026] [security2:error] [pid 521505:tid 521735] [client 20.104.50.220:5582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/77.php"] [unique_id "apPl028byYE0iXl--K6RIAAAA4I"]
[Sun Aug 30 03:12:03.946777 2026] [security2:error] [pid 524122:tid 524258] [client 4.205.62.107:16339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/rum.or.php"] [unique_id "apPl033lhEjKFiK_nBJ-CQAAAZQ"]
[Sun Aug 30 03:12:03.947076 2026] [security2:error] [pid 524122:tid 524361] [client 4.205.62.107:15972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/min.php"] [unique_id "apPl033lhEjKFiK_nBJ-CgAAAfs"]
[Sun Aug 30 03:12:03.953135 2026] [security2:error] [pid 521505:tid 521680] [client 4.205.62.107:52901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/gnmlc.php"] [unique_id "apPl028byYE0iXl--K6RLgAAA0s"]
[Sun Aug 30 03:12:03.963347 2026] [security2:error] [pid 521505:tid 521737] [client 20.48.160.90:61465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/emmh.php"] [unique_id "apPl028byYE0iXl--K6RNgAAA4Q"]
[Sun Aug 30 03:12:03.975907 2026] [security2:error] [pid 521505:tid 521708] [client 20.48.160.90:61659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/filefuns.php"] [unique_id "apPl028byYE0iXl--K6RPQAAA2c"]
[Sun Aug 30 03:12:03.999119 2026] [authz_core:error] [pid 521505:tid 521711] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory25
[Sun Aug 30 03:12:03.999471 2026] [authz_core:error] [pid 521505:tid 521711] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory25
[Sun Aug 30 03:12:04.002361 2026] [security2:error] [pid 521505:tid 521715] [client 20.104.49.130:53715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/Jcrop.php"] [unique_id "apPl1G8byYE0iXl--K6RSQAAA24"]
[Sun Aug 30 03:12:04.028843 2026] [security2:error] [pid 521505:tid 521754] [client 20.104.50.220:28714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/funtion.php"] [unique_id "apPl1G8byYE0iXl--K6RUgAAA5U"]
[Sun Aug 30 03:12:04.044683 2026] [security2:error] [pid 521505:tid 521636] [client 20.48.251.3:37124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/btx25.php"] [unique_id "apPl1G8byYE0iXl--K6RXAAAAx8"]
[Sun Aug 30 03:12:04.056709 2026] [security2:error] [pid 521505:tid 521672] [client 35.247.242.193:42026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/info.php"] [unique_id "apPl1G8byYE0iXl--K6RYgAAA0M"]
[Sun Aug 30 03:12:04.098555 2026] [security2:error] [pid 524122:tid 524376] [client 20.48.160.90:37984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/em.php"] [unique_id "apPl1H3lhEjKFiK_nBJ-FgAAAgo"]
[Sun Aug 30 03:12:04.102714 2026] [security2:error] [pid 521505:tid 521683] [client 20.48.160.90:61671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp-cron.php"] [unique_id "apPl1G8byYE0iXl--K6RdwAAA04"]
[Sun Aug 30 03:12:04.111853 2026] [security2:error] [pid 521505:tid 521687] [client 20.104.18.15:18275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/asdfghj.php"] [unique_id "apPl1G8byYE0iXl--K6RegAAA1I"]
[Sun Aug 30 03:12:04.113433 2026] [security2:error] [pid 524122:tid 524308] [client 216.73.216.128:43516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPl1H3lhEjKFiK_nBJ-FwAAAcY"]
[Sun Aug 30 03:12:04.127691 2026] [security2:error] [pid 524122:tid 524339] [client 4.205.62.107:25724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/rpk.php"] [unique_id "apPl1H3lhEjKFiK_nBJ-GgAAAeU"]
[Sun Aug 30 03:12:04.138032 2026] [security2:error] [pid 524122:tid 524277] [client 173.239.211.35:30007] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/blurbs.php"] [unique_id "apPl1H3lhEjKFiK_nBJ-GwAAAac"]
[Sun Aug 30 03:12:04.171784 2026] [authz_core:error] [pid 521505:tid 521744] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:04.172187 2026] [authz_core:error] [pid 521505:tid 521744] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:04.177080 2026] [security2:error] [pid 521505:tid 521654] [client 20.151.200.44:45008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/wk/index.php"] [unique_id "apPl1G8byYE0iXl--K6RmgAAAzE"]
[Sun Aug 30 03:12:04.229469 2026] [security2:error] [pid 521505:tid 521635] [client 20.48.160.90:61487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/dvve.php"] [unique_id "apPl1G8byYE0iXl--K6RqQAAAx4"]
[Sun Aug 30 03:12:04.229703 2026] [security2:error] [pid 521505:tid 521667] [client 20.48.160.90:37772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/lock360.php"] [unique_id "apPl1G8byYE0iXl--K6RqgAAAz4"]
[Sun Aug 30 03:12:04.241408 2026] [authz_core:error] [pid 521505:tid 521685] [client 66.249.66.74:63936] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:04.241698 2026] [authz_core:error] [pid 521505:tid 521685] [client 66.249.66.74:63936] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:04.280011 2026] [security2:error] [pid 521505:tid 521657] [client 20.104.49.130:52127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPl1G8byYE0iXl--K6RyAAAAzQ"]
[Sun Aug 30 03:12:04.280223 2026] [security2:error] [pid 524122:tid 524188] [remote 185.93.89.167:39769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ar.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPl1H3lhEjKFiK_nBJ-JwAB4EA"]
[Sun Aug 30 03:12:04.281832 2026] [security2:error] [pid 521505:tid 521735] [client 20.104.50.220:51539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/pHpINJ.php"] [unique_id "apPl1G8byYE0iXl--K6RyQAAA4I"]
[Sun Aug 30 03:12:04.363794 2026] [security2:error] [pid 521505:tid 521761] [client 20.48.160.90:61624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp-theme.php"] [unique_id "apPl1G8byYE0iXl--K6R7QAAA5w"]
[Sun Aug 30 03:12:04.383401 2026] [security2:error] [pid 521505:tid 521747] [client 20.48.160.90:37999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/doo.php"] [unique_id "apPl1G8byYE0iXl--K6R9QAAA44"]
[Sun Aug 30 03:12:04.413547 2026] [security2:error] [pid 524122:tid 524268] [client 20.104.49.130:59579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/wp-the.php"] [unique_id "apPl1H3lhEjKFiK_nBJ-OAAAAZ4"]
[Sun Aug 30 03:12:04.414096 2026] [security2:error] [pid 521505:tid 521664] [client 20.104.50.220:62839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/Ninja.php"] [unique_id "apPl1G8byYE0iXl--K6SAAAAAzs"]
[Sun Aug 30 03:12:04.414607 2026] [security2:error] [pid 524122:tid 524190] [remote 185.93.89.167:39769] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "ar.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPl1H3lhEjKFiK_nBJ-NwABpkI"]
[Sun Aug 30 03:12:04.431865 2026] [security2:error] [pid 521505:tid 521726] [client 20.151.200.44:63033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPl1G8byYE0iXl--K6SDwAAA3k"]
[Sun Aug 30 03:12:04.433198 2026] [security2:error] [pid 521505:tid 521677] [client 20.104.49.130:43264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/ws85.php"] [unique_id "apPl1G8byYE0iXl--K6SEgAAA0g"]
[Sun Aug 30 03:12:04.461789 2026] [security2:error] [pid 521505:tid 521722] [client 34.15.159.88:41534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/admin/phpinfo.php"] [unique_id "apPl1G8byYE0iXl--K6SIAAAA3U"]
[Sun Aug 30 03:12:04.464490 2026] [authz_core:error] [pid 521505:tid 521758] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory27
[Sun Aug 30 03:12:04.464788 2026] [authz_core:error] [pid 521505:tid 521758] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory27
[Sun Aug 30 03:12:04.479491 2026] [security2:error] [pid 521505:tid 521761] [client 216.73.216.128:37868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/nameserverconfig"] [unique_id "apPl1G8byYE0iXl--K6SJwAAA5w"]
[Sun Aug 30 03:12:04.500536 2026] [security2:error] [pid 521505:tid 521635] [client 20.48.160.90:51832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/2d7433/index.php"] [unique_id "apPl1G8byYE0iXl--K6SKAAAAx4"]
[Sun Aug 30 03:12:04.529191 2026] [security2:error] [pid 524122:tid 524333] [client 20.48.160.90:37974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/adminer-4.6.6.php"] [unique_id "apPl1H3lhEjKFiK_nBJ-RgAAAd8"]
[Sun Aug 30 03:12:04.538315 2026] [security2:error] [pid 521505:tid 521666] [client 35.247.242.193:42030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/php.php"] [unique_id "apPl1G8byYE0iXl--K6SNgAAAz0"]
[Sun Aug 30 03:12:04.544741 2026] [security2:error] [pid 521505:tid 521751] [client 158.23.147.79:60211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apPl1G8byYE0iXl--K6SPAAAA5I"]
[Sun Aug 30 03:12:04.559604 2026] [security2:error] [pid 521505:tid 521677] [client 20.104.49.130:53708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/wp-the.php"] [unique_id "apPl1G8byYE0iXl--K6SRAAAA0g"]
[Sun Aug 30 03:12:04.573162 2026] [authz_core:error] [pid 524122:tid 524296] [client 66.249.66.74:42210] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:04.573608 2026] [authz_core:error] [pid 524122:tid 524296] [client 66.249.66.74:42210] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:04.611234 2026] [security2:error] [pid 521505:tid 521687] [client 20.104.49.130:52525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/ortasekerli1.php"] [unique_id "apPl1G8byYE0iXl--K6SXwAAA1I"]
[Sun Aug 30 03:12:04.630731 2026] [security2:error] [pid 524122:tid 524304] [client 173.239.211.51:26333] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/wp-admin/css/goods.php"] [unique_id "apPl1H3lhEjKFiK_nBJ-ZgAAAcI"]
[Sun Aug 30 03:12:04.632622 2026] [security2:error] [pid 521505:tid 521736] [client 20.48.160.90:37788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp-login.php"] [unique_id "apPl1G8byYE0iXl--K6SawAAA4M"]
[Sun Aug 30 03:12:04.658717 2026] [security2:error] [pid 521505:tid 521733] [client 20.48.160.90:37747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/gelap1.php"] [unique_id "apPl1G8byYE0iXl--K6ScgAAA4A"]
[Sun Aug 30 03:12:04.663988 2026] [authz_core:error] [pid 521505:tid 521669] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:04.664445 2026] [authz_core:error] [pid 521505:tid 521669] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:04.683986 2026] [security2:error] [pid 521505:tid 521698] [client 68.155.159.216:54327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/worksec.php"] [unique_id "apPl1G8byYE0iXl--K6SgAAAA10"]
[Sun Aug 30 03:12:04.684141 2026] [security2:error] [pid 524122:tid 524193] [remote 185.93.89.167:39769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ar.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPl1H3lhEjKFiK_nBJ-cAACC0U"]
[Sun Aug 30 03:12:04.720748 2026] [authz_core:error] [pid 524122:tid 524357] [client 66.249.66.203:46284] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:04.721144 2026] [authz_core:error] [pid 524122:tid 524357] [client 66.249.66.203:46284] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:04.753582 2026] [security2:error] [pid 521505:tid 521739] [client 158.23.147.79:40011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPl1G8byYE0iXl--K6SsQAAA4Y"]
[Sun Aug 30 03:12:04.766151 2026] [security2:error] [pid 521505:tid 521729] [client 20.48.160.90:61628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/images.php"] [unique_id "apPl1G8byYE0iXl--K6SuwAAA3w"]
[Sun Aug 30 03:12:04.793576 2026] [security2:error] [pid 524122:tid 524337] [client 20.104.50.220:17334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/up4.php"] [unique_id "apPl1H3lhEjKFiK_nBJ-gQAAAeM"]
[Sun Aug 30 03:12:04.796573 2026] [security2:error] [pid 521505:tid 521664] [client 20.104.49.130:53711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/155.php"] [unique_id "apPl1G8byYE0iXl--K6SwAAAAzs"]
[Sun Aug 30 03:12:04.797374 2026] [security2:error] [pid 521505:tid 521648] [client 20.48.160.90:37711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/rsjlrria.php"] [unique_id "apPl1G8byYE0iXl--K6SwgAAAys"]
[Sun Aug 30 03:12:04.811916 2026] [security2:error] [pid 521505:tid 521723] [client 4.205.62.107:17294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/zz.php"] [unique_id "apPl1G8byYE0iXl--K6SyQAAA3Y"]
[Sun Aug 30 03:12:04.853391 2026] [security2:error] [pid 524122:tid 524367] [client 20.48.251.3:52187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/zz.php"] [unique_id "apPl1H3lhEjKFiK_nBJ-iwAAAgE"]
[Sun Aug 30 03:12:04.853471 2026] [security2:error] [pid 524122:tid 524352] [client 20.104.18.15:2035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/chosen.php"] [unique_id "apPl1H3lhEjKFiK_nBJ-jAAAAfI"]
[Sun Aug 30 03:12:04.862367 2026] [security2:error] [pid 524122:tid 524360] [client 20.104.18.15:17010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/wp-safe.php"] [unique_id "apPl1H3lhEjKFiK_nBJ-jwAAAfo"]
[Sun Aug 30 03:12:04.880434 2026] [security2:error] [pid 521505:tid 521683] [client 20.104.50.220:24941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/155.php"] [unique_id "apPl1G8byYE0iXl--K6S6QAAA04"]
[Sun Aug 30 03:12:04.895372 2026] [security2:error] [pid 524122:tid 524270] [client 20.104.18.15:51073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/dehnl.php"] [unique_id "apPl1H3lhEjKFiK_nBJ-lQAAAaA"]
[Sun Aug 30 03:12:04.902832 2026] [security2:error] [pid 521505:tid 521664] [client 20.104.50.220:32912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/simple_cmd.php"] [unique_id "apPl1G8byYE0iXl--K6S9wAAAzs"]
[Sun Aug 30 03:12:04.903299 2026] [security2:error] [pid 524122:tid 524301] [client 20.48.160.90:37762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/ops.php"] [unique_id "apPl1H3lhEjKFiK_nBJ-lgAAAb8"]
[Sun Aug 30 03:12:04.910715 2026] [security2:error] [pid 521505:tid 521672] [client 20.104.18.15:22451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/c4.php"] [unique_id "apPl1G8byYE0iXl--K6S-wAAA0M"]
[Sun Aug 30 03:12:04.925429 2026] [security2:error] [pid 521505:tid 521647] [client 20.151.200.44:45005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/dehnl.php"] [unique_id "apPl1G8byYE0iXl--K6TBAAAAyo"]
[Sun Aug 30 03:12:04.928904 2026] [security2:error] [pid 521505:tid 521738] [client 20.48.160.90:37997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/AxAo.php"] [unique_id "apPl1G8byYE0iXl--K6TBwAAA4U"]
[Sun Aug 30 03:12:04.954201 2026] [security2:error] [pid 524122:tid 524277] [client 20.48.251.3:59367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/services.php"] [unique_id "apPl1H3lhEjKFiK_nBJ-ngAAAac"]
[Sun Aug 30 03:12:04.962857 2026] [security2:error] [pid 521505:tid 521718] [client 20.104.49.130:53691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/fs.php"] [unique_id "apPl1G8byYE0iXl--K6TFQAAA3E"]
[Sun Aug 30 03:12:04.993930 2026] [authz_core:error] [pid 521505:tid 521699] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory12
[Sun Aug 30 03:12:04.994350 2026] [authz_core:error] [pid 521505:tid 521699] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory12
[Sun Aug 30 03:12:05.009161 2026] [security2:error] [pid 521505:tid 521649] [client 20.48.251.3:46159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/doc.php"] [unique_id "apPl1W8byYE0iXl--K6TLAAAAyw"]
[Sun Aug 30 03:12:05.028108 2026] [security2:error] [pid 524122:tid 524278] [client 20.104.50.220:30917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/class20.php"] [unique_id "apPl1X3lhEjKFiK_nBJ-pAAAAag"]
[Sun Aug 30 03:12:05.034819 2026] [security2:error] [pid 521505:tid 521744] [client 20.48.160.90:61581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPl1W8byYE0iXl--K6TMwAAA4s"]
[Sun Aug 30 03:12:05.035241 2026] [security2:error] [pid 521505:tid 521703] [client 35.247.242.193:42042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/i.php"] [unique_id "apPl1W8byYE0iXl--K6TNAAAA2I"]
[Sun Aug 30 03:12:05.036099 2026] [security2:error] [pid 524122:tid 524290] [client 20.104.50.220:61405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/build.php"] [unique_id "apPl1X3lhEjKFiK_nBJ-pgAAAbQ"]
[Sun Aug 30 03:12:05.059478 2026] [security2:error] [pid 521505:tid 521695] [client 20.104.18.15:31664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/sss.php"] [unique_id "apPl1W8byYE0iXl--K6TQwAAA1o"]
[Sun Aug 30 03:12:05.061026 2026] [security2:error] [pid 521505:tid 521689] [client 20.48.160.90:37959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/class17.php"] [unique_id "apPl1W8byYE0iXl--K6TRQAAA1Q"]
[Sun Aug 30 03:12:05.068915 2026] [security2:error] [pid 521505:tid 521701] [client 34.15.159.88:41546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/test/phpinfo.php"] [unique_id "apPl1W8byYE0iXl--K6TTAAAA2A"]
[Sun Aug 30 03:12:05.075139 2026] [security2:error] [pid 521505:tid 521660] [client 20.104.50.220:6123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/76.php"] [unique_id "apPl1W8byYE0iXl--K6TUgAAAzc"]
[Sun Aug 30 03:12:05.078579 2026] [security2:error] [pid 524122:tid 524264] [client 4.205.62.107:16321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/saiga.php"] [unique_id "apPl1X3lhEjKFiK_nBJ-rAAAAZo"]
[Sun Aug 30 03:12:05.079375 2026] [security2:error] [pid 521505:tid 521642] [client 4.205.62.107:15959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/xmy.php"] [unique_id "apPl1W8byYE0iXl--K6TUwAAAyU"]
[Sun Aug 30 03:12:05.089018 2026] [security2:error] [pid 524122:tid 524197] [remote 185.93.89.167:39769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ar.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPl1X3lhEjKFiK_nBJ-sAACDEk"]
[Sun Aug 30 03:12:05.092930 2026] [security2:error] [pid 521505:tid 521747] [client 4.205.62.107:52902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/koiy.php"] [unique_id "apPl1W8byYE0iXl--K6TVwAAA44"]
[Sun Aug 30 03:12:05.106657 2026] [security2:error] [pid 521505:tid 521671] [client 20.104.49.130:64081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/kgoc6awap3napxxxdCdefault.php"] [unique_id "apPl1W8byYE0iXl--K6TWgAAA0I"]
[Sun Aug 30 03:12:05.138139 2026] [authz_core:error] [pid 521505:tid 521729] [client 66.249.66.42:51048] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:05.138582 2026] [authz_core:error] [pid 521505:tid 521729] [client 66.249.66.42:51048] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:05.156746 2026] [security2:error] [pid 521505:tid 521740] [client 20.151.200.44:63622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/xda.php"] [unique_id "apPl1W8byYE0iXl--K6TcAAAA4c"]
[Sun Aug 30 03:12:05.158756 2026] [authz_core:error] [pid 521505:tid 521650] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:05.159088 2026] [authz_core:error] [pid 521505:tid 521650] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:05.173098 2026] [security2:error] [pid 521505:tid 521684] [client 20.48.160.90:37822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPl1W8byYE0iXl--K6TfAAAA08"]
[Sun Aug 30 03:12:05.182692 2026] [security2:error] [pid 521505:tid 521662] [client 20.48.251.3:37140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/app_dev.php"] [unique_id "apPl1W8byYE0iXl--K6TfgAAAzk"]
[Sun Aug 30 03:12:05.183147 2026] [security2:error] [pid 524122:tid 524354] [client 20.104.50.220:29175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/xixi.php"] [unique_id "apPl1X3lhEjKFiK_nBJ-uwAAAfQ"]
[Sun Aug 30 03:12:05.197884 2026] [security2:error] [pid 521505:tid 521673] [client 20.48.160.90:38013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/okxoby.php"] [unique_id "apPl1W8byYE0iXl--K6TgAAAA0Q"]
[Sun Aug 30 03:12:05.209243 2026] [security2:error] [pid 521505:tid 521660] [client 20.104.49.130:51578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/df.php"] [unique_id "apPl1W8byYE0iXl--K6ThAAAAzc"]
[Sun Aug 30 03:12:05.219890 2026] [security2:error] [pid 521505:tid 521709] [client 20.104.49.130:52537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/t.php"] [unique_id "apPl1W8byYE0iXl--K6TigAAA2g"]
[Sun Aug 30 03:12:05.222355 2026] [security2:error] [pid 524122:tid 524198] [remote 185.93.89.167:39769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ar.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPl1X3lhEjKFiK_nBJ-vQAB1Uo"]
[Sun Aug 30 03:12:05.237099 2026] [security2:error] [pid 521505:tid 521674] [client 63.135.161.117:25111] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/abcd.php"] [unique_id "apPl1W8byYE0iXl--K6TkgAAA0U"]
[Sun Aug 30 03:12:05.265475 2026] [security2:error] [pid 521505:tid 521692] [client 20.104.18.15:18411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/dragonshell.php"] [unique_id "apPl1W8byYE0iXl--K6ToAAAA1c"]
[Sun Aug 30 03:12:05.299797 2026] [security2:error] [pid 521505:tid 521718] [client 20.48.160.90:61689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/about.php"] [unique_id "apPl1W8byYE0iXl--K6TwAAAA3E"]
[Sun Aug 30 03:12:05.328148 2026] [security2:error] [pid 521505:tid 521663] [client 20.48.160.90:30806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/esuutzzx.php"] [unique_id "apPl1W8byYE0iXl--K6TxwAAAzo"]
[Sun Aug 30 03:12:05.335406 2026] [security2:error] [pid 521505:tid 521733] [client 4.205.62.107:26944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/saml.php"] [unique_id "apPl1W8byYE0iXl--K6TzAAAA4A"]
[Sun Aug 30 03:12:05.340867 2026] [security2:error] [pid 524122:tid 524346] [client 20.151.200.44:45014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/png.php"] [unique_id "apPl1X3lhEjKFiK_nBJ-ygAAAew"]
[Sun Aug 30 03:12:05.348787 2026] [security2:error] [pid 524122:tid 524360] [client 20.104.49.130:43309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/tool.php"] [unique_id "apPl1X3lhEjKFiK_nBJ-zAAAAfo"]
[Sun Aug 30 03:12:05.358907 2026] [security2:error] [pid 521505:tid 521653] [client 20.104.49.130:63592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/txets.php"] [unique_id "apPl1W8byYE0iXl--K6T2gAAAzA"]
[Sun Aug 30 03:12:05.423896 2026] [security2:error] [pid 524122:tid 524319] [client 20.104.50.220:51581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/robot.php"] [unique_id "apPl1X3lhEjKFiK_nBJ-2gAAAdE"]
[Sun Aug 30 03:12:05.428746 2026] [security2:error] [pid 521505:tid 521761] [client 20.48.160.90:51742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/admin.php/admin.php"] [unique_id "apPl1W8byYE0iXl--K6T9AAAA5w"]
[Sun Aug 30 03:12:05.460726 2026] [security2:error] [pid 524122:tid 524326] [client 158.23.147.79:16300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-admin/user/index.php"] [unique_id "apPl1X3lhEjKFiK_nBJ-3QAAAdg"]
[Sun Aug 30 03:12:05.466878 2026] [authz_core:error] [pid 521505:tid 521643] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory21
[Sun Aug 30 03:12:05.467321 2026] [authz_core:error] [pid 521505:tid 521643] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory21
[Sun Aug 30 03:12:05.473103 2026] [security2:error] [pid 521505:tid 521641] [client 20.48.160.90:61566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/replace.php"] [unique_id "apPl1W8byYE0iXl--K6UDAAAAyQ"]
[Sun Aug 30 03:12:05.521992 2026] [security2:error] [pid 524122:tid 524266] [client 35.247.242.193:42048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/pi.php"] [unique_id "apPl1X3lhEjKFiK_nBJ-5QAAAZw"]
[Sun Aug 30 03:12:05.522810 2026] [security2:error] [pid 521505:tid 521650] [client 20.104.49.130:64113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/abc.php"] [unique_id "apPl1W8byYE0iXl--K6UHAAAAy0"]
[Sun Aug 30 03:12:05.555772 2026] [security2:error] [pid 524122:tid 524343] [client 20.104.50.220:28691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-incleude.php"] [unique_id "apPl1X3lhEjKFiK_nBJ-7AAAAek"]
[Sun Aug 30 03:12:05.575808 2026] [security2:error] [pid 524122:tid 524274] [client 20.48.160.90:61652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/media.php"] [unique_id "apPl1X3lhEjKFiK_nBJ-8wAAAaQ"]
[Sun Aug 30 03:12:05.584544 2026] [security2:error] [pid 521505:tid 521701] [client 20.151.200.44:23576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPl1W8byYE0iXl--K6UNwAAA2A"]
[Sun Aug 30 03:12:05.585028 2026] [authz_core:error] [pid 524122:tid 524295] [client 66.249.66.192:39129] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:05.585586 2026] [authz_core:error] [pid 524122:tid 524295] [client 66.249.66.192:39129] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:05.618792 2026] [security2:error] [pid 524122:tid 524333] [client 20.48.160.90:37661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/gulu.php"] [unique_id "apPl1X3lhEjKFiK_nBJ-_gAAAd8"]
[Sun Aug 30 03:12:05.627952 2026] [security2:error] [pid 524122:tid 524203] [remote 185.93.89.167:39769] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ar.mariegronley.com"] [uri "/env/.env"] [unique_id "apPl1X3lhEjKFiK_nBJ_AAABqk8"]
[Sun Aug 30 03:12:05.671413 2026] [authz_core:error] [pid 524122:tid 524367] [client 216.73.216.128:50934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:05.671892 2026] [authz_core:error] [pid 524122:tid 524367] [client 216.73.216.128:50934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:05.672247 2026] [security2:error] [pid 521505:tid 521752] [client 34.15.159.88:41552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/dev/phpinfo.php"] [unique_id "apPl1W8byYE0iXl--K6UbgAAA5M"]
[Sun Aug 30 03:12:05.682982 2026] [security2:error] [pid 521505:tid 521721] [client 63.135.161.117:29479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.161.135.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "watertownchessclub.com"] [uri "/wp-admin/css/colors/wp-login.php"] [unique_id "apPl1W8byYE0iXl--K6UWwAAA3Q"]
[Sun Aug 30 03:12:05.700449 2026] [authz_core:error] [pid 521505:tid 521724] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:05.700824 2026] [authz_core:error] [pid 521505:tid 521724] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:05.703212 2026] [security2:error] [pid 521505:tid 521738] [client 20.48.160.90:37835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/mac.php"] [unique_id "apPl1W8byYE0iXl--K6UhQAAA4U"]
[Sun Aug 30 03:12:05.709500 2026] [security2:error] [pid 521505:tid 521703] [client 20.151.200.44:45055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/txets.php"] [unique_id "apPl1W8byYE0iXl--K6UigAAA2I"]
[Sun Aug 30 03:12:05.715228 2026] [ssl:error] [pid 524122:tid 524363] [client 207.90.244.25:38854] AH02032: Hostname gator3166.hostgator.com (default host as no SNI was provided) and hostname webdisk.briankornblum.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Sun Aug 30 03:12:05.723570 2026] [security2:error] [pid 521505:tid 521643] [client 20.104.49.130:43317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/bthil.php"] [unique_id "apPl1W8byYE0iXl--K6UlgAAAyY"]
[Sun Aug 30 03:12:05.760982 2026] [security2:error] [pid 521505:tid 521702] [client 20.48.160.90:37708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/gtghklk.php"] [unique_id "apPl1W8byYE0iXl--K6UtgAAA2E"]
[Sun Aug 30 03:12:05.820413 2026] [security2:error] [pid 524122:tid 524373] [client 158.23.184.117:33095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/cache/cache/min.php"] [unique_id "apPl1X3lhEjKFiK_nBJ_EAAAAgc"]
[Sun Aug 30 03:12:05.834272 2026] [security2:error] [pid 521505:tid 521751] [client 20.48.160.90:61596] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/1.php"] [unique_id "apPl1W8byYE0iXl--K6U3gAAA5I"]
[Sun Aug 30 03:12:05.834353 2026] [security2:error] [pid 521505:tid 521751] [client 20.48.160.90:61596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/1.php"] [unique_id "apPl1W8byYE0iXl--K6U3gAAA5I"]
[Sun Aug 30 03:12:05.897294 2026] [security2:error] [pid 521505:tid 521652] [client 20.48.160.90:61450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/comand.php"] [unique_id "apPl1W8byYE0iXl--K6U_wAAAy8"]
[Sun Aug 30 03:12:05.897698 2026] [security2:error] [pid 524122:tid 524205] [remote 185.93.89.167:39769] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ar.mariegronley.com"] [uri "/src/.env"] [unique_id "apPl1X3lhEjKFiK_nBJ_HAAB_1E"]
[Sun Aug 30 03:12:05.898067 2026] [security2:error] [pid 521505:tid 521696] [client 20.104.49.130:64126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/xwx1.php"] [unique_id "apPl1W8byYE0iXl--K6VAQAAA1s"]
[Sun Aug 30 03:12:05.901831 2026] [security2:error] [pid 521505:tid 521695] [client 158.23.147.79:60213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-includes/plugins.php"] [unique_id "apPl1W8byYE0iXl--K6VBQAAA1o"]
[Sun Aug 30 03:12:05.926408 2026] [security2:error] [pid 524122:tid 524372] [client 20.104.50.220:17250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/1aa.php"] [unique_id "apPl1X3lhEjKFiK_nBJ_HwAAAgY"]
[Sun Aug 30 03:12:05.936501 2026] [security2:error] [pid 524122:tid 524261] [client 216.73.216.128:64699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/'+this.controller.state().get("] [unique_id "apPl1X3lhEjKFiK_nBJ_IQAAAZc"]
[Sun Aug 30 03:12:05.946021 2026] [security2:error] [pid 524122:tid 524290] [client 4.205.62.107:16768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/test.php"] [unique_id "apPl1X3lhEjKFiK_nBJ_IgAAAbQ"]
[Sun Aug 30 03:12:05.951092 2026] [security2:error] [pid 521505:tid 521751] [client 20.151.200.44:44879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/wp-login.php"] [unique_id "apPl1W8byYE0iXl--K6VFQAAA5I"]
[Sun Aug 30 03:12:05.961795 2026] [security2:error] [pid 521505:tid 521759] [client 158.23.184.117:33098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/catalogbypass.php"] [unique_id "apPl1W8byYE0iXl--K6VIAAAA5o"]
[Sun Aug 30 03:12:05.963525 2026] [authz_core:error] [pid 521505:tid 521676] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory22
[Sun Aug 30 03:12:05.963865 2026] [authz_core:error] [pid 521505:tid 521676] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory22
[Sun Aug 30 03:12:05.965847 2026] [security2:error] [pid 521505:tid 521730] [client 20.48.160.90:61608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/classwithtostring.php"] [unique_id "apPl1W8byYE0iXl--K6VIgAAA30"]
[Sun Aug 30 03:12:05.986105 2026] [authz_core:error] [pid 521505:tid 521707] [client 66.249.66.35:43266] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:05.986467 2026] [authz_core:error] [pid 521505:tid 521707] [client 66.249.66.35:43266] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:05.991304 2026] [security2:error] [pid 521505:tid 521658] [client 20.104.18.15:2022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/file1221.php"] [unique_id "apPl1W8byYE0iXl--K6VLQAAAzU"]
[Sun Aug 30 03:12:05.999420 2026] [security2:error] [pid 521505:tid 521742] [client 20.104.18.15:64730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/gjewuagf.php"] [unique_id "apPl1W8byYE0iXl--K6VMgAAA4k"]
[Sun Aug 30 03:12:06.006797 2026] [security2:error] [pid 521505:tid 521711] [client 35.247.242.193:42058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/pinfo.php"] [unique_id "apPl1m8byYE0iXl--K6VNQAAA2o"]
[Sun Aug 30 03:12:06.013620 2026] [security2:error] [pid 521505:tid 521686] [client 20.48.251.3:59850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/test.php"] [unique_id "apPl1m8byYE0iXl--K6VNwAAA1E"]
[Sun Aug 30 03:12:06.030671 2026] [security2:error] [pid 524122:tid 524310] [client 20.104.50.220:25424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/ppp.php"] [unique_id "apPl1n3lhEjKFiK_nBJ_LQAAAcg"]
[Sun Aug 30 03:12:06.035457 2026] [security2:error] [pid 521505:tid 521695] [client 20.104.18.15:51194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/zoo2.php"] [unique_id "apPl1m8byYE0iXl--K6VPAAAA1o"]
[Sun Aug 30 03:12:06.043738 2026] [security2:error] [pid 521505:tid 521650] [client 20.48.160.90:37960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp_motu_myk3v.php"] [unique_id "apPl1m8byYE0iXl--K6VQwAAAy0"]
[Sun Aug 30 03:12:06.046408 2026] [security2:error] [pid 521505:tid 521666] [client 20.104.50.220:32876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/alpa.php"] [unique_id "apPl1m8byYE0iXl--K6VRAAAAz0"]
[Sun Aug 30 03:12:06.049835 2026] [security2:error] [pid 524122:tid 524271] [client 20.104.18.15:22286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/rxr.php"] [unique_id "apPl1n3lhEjKFiK_nBJ_MQAAAaE"]
[Sun Aug 30 03:12:06.054767 2026] [security2:error] [pid 524122:tid 524276] [client 173.239.211.43:52483] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/cord.php"] [unique_id "apPl1n3lhEjKFiK_nBJ_NAAAAaY"]
[Sun Aug 30 03:12:06.092346 2026] [security2:error] [pid 524122:tid 524305] [client 20.48.251.3:55694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/filesystems.php"] [unique_id "apPl1n3lhEjKFiK_nBJ_PgAAAcM"]
[Sun Aug 30 03:12:06.099106 2026] [security2:error] [pid 524122:tid 524338] [client 158.23.184.117:33439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/cc.php"] [unique_id "apPl1n3lhEjKFiK_nBJ_PwAAAeQ"]
[Sun Aug 30 03:12:06.109393 2026] [security2:error] [pid 521505:tid 521675] [client 20.48.160.90:61570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp-ws68.php"] [unique_id "apPl1m8byYE0iXl--K6VWQAAA0Y"]
[Sun Aug 30 03:12:06.144939 2026] [security2:error] [pid 521505:tid 521731] [client 68.155.159.216:52328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/x.php"] [unique_id "apPl1m8byYE0iXl--K6VbQAAA34"]
[Sun Aug 30 03:12:06.166269 2026] [security2:error] [pid 521505:tid 521749] [client 20.104.50.220:31546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/admin.php"] [unique_id "apPl1m8byYE0iXl--K6VdwAAA5A"]
[Sun Aug 30 03:12:06.168245 2026] [security2:error] [pid 524122:tid 524208] [remote 185.93.89.167:39769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ar.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPl1n3lhEjKFiK_nBJ_SQABj1Q"]
[Sun Aug 30 03:12:06.174184 2026] [security2:error] [pid 521505:tid 521678] [client 158.23.147.79:40027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/goat.php"] [unique_id "apPl1m8byYE0iXl--K6VewAAA0k"]
[Sun Aug 30 03:12:06.181518 2026] [authz_core:error] [pid 521505:tid 521680] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:06.181937 2026] [authz_core:error] [pid 521505:tid 521680] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:06.185056 2026] [security2:error] [pid 521505:tid 521753] [client 20.48.160.90:30832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/wp_motu_ypdat.php"] [unique_id "apPl1m8byYE0iXl--K6VfgAAA5Q"]
[Sun Aug 30 03:12:06.190572 2026] [security2:error] [pid 521505:tid 521714] [client 20.104.50.220:61487] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/1.php"] [unique_id "apPl1m8byYE0iXl--K6VgAAAA20"]
[Sun Aug 30 03:12:06.190667 2026] [security2:error] [pid 521505:tid 521714] [client 20.104.50.220:61487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/1.php"] [unique_id "apPl1m8byYE0iXl--K6VgAAAA20"]
[Sun Aug 30 03:12:06.192540 2026] [security2:error] [pid 521505:tid 521655] [client 20.48.251.3:65496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/css.php"] [unique_id "apPl1m8byYE0iXl--K6VgQAAAzI"]
[Sun Aug 30 03:12:06.193047 2026] [security2:error] [pid 521505:tid 521636] [client 20.104.49.130:48798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/bolt.php"] [unique_id "apPl1m8byYE0iXl--K6VggAAAx8"]
[Sun Aug 30 03:12:06.209190 2026] [security2:error] [pid 524122:tid 524283] [client 20.104.18.15:31737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/xmini4.php"] [unique_id "apPl1n3lhEjKFiK_nBJ_SwAAAa0"]
[Sun Aug 30 03:12:06.215893 2026] [security2:error] [pid 521505:tid 521689] [client 4.205.62.107:16336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/ms-edit.php"] [unique_id "apPl1m8byYE0iXl--K6VjQAAA1Q"]
[Sun Aug 30 03:12:06.216851 2026] [security2:error] [pid 521505:tid 521744] [client 4.205.62.107:15831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/ammika.php"] [unique_id "apPl1m8byYE0iXl--K6VjgAAA4s"]
[Sun Aug 30 03:12:06.226349 2026] [security2:error] [pid 521505:tid 521642] [client 20.104.50.220:5950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/74.php"] [unique_id "apPl1m8byYE0iXl--K6VkgAAAyU"]
[Sun Aug 30 03:12:06.230265 2026] [security2:error] [pid 524122:tid 524270] [client 4.205.62.107:52924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/w.php"] [unique_id "apPl1n3lhEjKFiK_nBJ_TQAAAaA"]
[Sun Aug 30 03:12:06.246421 2026] [security2:error] [pid 521505:tid 521733] [client 20.48.160.90:61615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/simple.php"] [unique_id "apPl1m8byYE0iXl--K6VnQAAA4A"]
[Sun Aug 30 03:12:06.252018 2026] [security2:error] [pid 521505:tid 521751] [client 158.23.184.117:33414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/cgi-bin/admin.php"] [unique_id "apPl1m8byYE0iXl--K6VogAAA5I"]
[Sun Aug 30 03:12:06.279095 2026] [security2:error] [pid 521505:tid 521638] [client 34.15.159.88:41562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/old/phpinfo.php"] [unique_id "apPl1m8byYE0iXl--K6VtwAAAyE"]
[Sun Aug 30 03:12:06.301559 2026] [security2:error] [pid 524122:tid 524210] [remote 185.93.89.167:39769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ar.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPl1n3lhEjKFiK_nBJ_WQAByVY"]
[Sun Aug 30 03:12:06.317529 2026] [security2:error] [pid 521505:tid 521663] [client 20.48.160.90:61525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/edit.php"] [unique_id "apPl1m8byYE0iXl--K6VygAAAzo"]
[Sun Aug 30 03:12:06.319765 2026] [security2:error] [pid 521505:tid 521647] [client 20.104.49.130:45720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/wp-good.php"] [unique_id "apPl1m8byYE0iXl--K6VzAAAAyo"]
[Sun Aug 30 03:12:06.320360 2026] [security2:error] [pid 524122:tid 524342] [client 20.104.50.220:63047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-cli.php"] [unique_id "apPl1n3lhEjKFiK_nBJ_XAAAAeg"]
[Sun Aug 30 03:12:06.334714 2026] [security2:error] [pid 521505:tid 521700] [client 20.48.251.3:37163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/php-info.php"] [unique_id "apPl1m8byYE0iXl--K6V0QAAA18"]
[Sun Aug 30 03:12:06.348797 2026] [security2:error] [pid 521505:tid 521657] [client 158.23.147.79:16342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apPl1m8byYE0iXl--K6V3QAAAzQ"]
[Sun Aug 30 03:12:06.352734 2026] [security2:error] [pid 521505:tid 521719] [client 20.104.49.130:60624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/155.php"] [unique_id "apPl1m8byYE0iXl--K6V4gAAA3I"]
[Sun Aug 30 03:12:06.385042 2026] [security2:error] [pid 524122:tid 524372] [client 20.104.49.130:53703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/cilus.php"] [unique_id "apPl1n3lhEjKFiK_nBJ_ZAAAAgY"]
[Sun Aug 30 03:12:06.385687 2026] [security2:error] [pid 524122:tid 524261] [client 20.48.160.90:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/aaa.php"] [unique_id "apPl1n3lhEjKFiK_nBJ_ZQAAAZc"]
[Sun Aug 30 03:12:06.409055 2026] [security2:error] [pid 521505:tid 521743] [client 20.104.18.15:18320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/wp-safe.php"] [unique_id "apPl1m8byYE0iXl--K6V8wAAA4o"]
[Sun Aug 30 03:12:06.420280 2026] [security2:error] [pid 521505:tid 521756] [client 20.151.200.44:44934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/wp-access.php"] [unique_id "apPl1m8byYE0iXl--K6V-QAAA5c"]
[Sun Aug 30 03:12:06.450015 2026] [security2:error] [pid 521505:tid 521670] [client 20.48.160.90:37987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/tqkdqbbv.php"] [unique_id "apPl1m8byYE0iXl--K6WEAAAA0E"]
[Sun Aug 30 03:12:06.472533 2026] [authz_core:error] [pid 521505:tid 521635] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory23
[Sun Aug 30 03:12:06.472979 2026] [authz_core:error] [pid 521505:tid 521635] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory23
[Sun Aug 30 03:12:06.481992 2026] [authz_core:error] [pid 521505:tid 521739] [client 66.249.66.64:42913] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:06.482298 2026] [security2:error] [pid 521505:tid 521688] [client 4.205.62.107:25917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/aws_settings.php"] [unique_id "apPl1m8byYE0iXl--K6WGwAAA1M"]
[Sun Aug 30 03:12:06.482312 2026] [authz_core:error] [pid 521505:tid 521739] [client 66.249.66.64:42913] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:06.495333 2026] [security2:error] [pid 521505:tid 521751] [client 35.247.242.193:42066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/test.php"] [unique_id "apPl1m8byYE0iXl--K6WHgAAA5I"]
[Sun Aug 30 03:12:06.503823 2026] [security2:error] [pid 521505:tid 521640] [client 158.23.184.117:33465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/config.php"] [unique_id "apPl1m8byYE0iXl--K6WJQAAAyM"]
[Sun Aug 30 03:12:06.525577 2026] [security2:error] [pid 521505:tid 521701] [client 20.104.49.130:43289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/ws78.php"] [unique_id "apPl1m8byYE0iXl--K6WMwAAA2A"]
[Sun Aug 30 03:12:06.561413 2026] [security2:error] [pid 521505:tid 521718] [client 20.104.50.220:51630] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "523"] [id "900207"] [msg "Sys[0-9]+ Mailer"] [hostname "cpanel.love-texas-holdem.com"] [uri "/sys32.php"] [unique_id "apPl1m8byYE0iXl--K6WRAAAA3E"]
[Sun Aug 30 03:12:06.571078 2026] [security2:error] [pid 524122:tid 524212] [remote 185.93.89.167:39769] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ar.mariegronley.com"] [uri "/web/.env"] [unique_id "apPl1n3lhEjKFiK_nBJ_eQABx1g"]
[Sun Aug 30 03:12:06.573678 2026] [security2:error] [pid 521505:tid 521666] [client 216.73.216.128:16510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPl1m8byYE0iXl--K6WRwAAAz0"]
[Sun Aug 30 03:12:06.617366 2026] [security2:error] [pid 521505:tid 521638] [client 20.104.49.130:52160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/xmini4.php"] [unique_id "apPl1m8byYE0iXl--K6WZgAAAyE"]
[Sun Aug 30 03:12:06.633660 2026] [security2:error] [pid 521505:tid 521652] [client 63.135.161.129:47603] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/dex.php"] [unique_id "apPl1m8byYE0iXl--K6WdAAAAy8"]
[Sun Aug 30 03:12:06.647380 2026] [security2:error] [pid 521505:tid 521672] [client 158.23.184.117:33452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/login.php"] [unique_id "apPl1m8byYE0iXl--K6WegAAA0M"]
[Sun Aug 30 03:12:06.651512 2026] [security2:error] [pid 521505:tid 521759] [client 20.104.49.130:64114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/ws58.php"] [unique_id "apPl1m8byYE0iXl--K6WewAAA5o"]
[Sun Aug 30 03:12:06.667615 2026] [authz_core:error] [pid 521505:tid 521761] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:06.667973 2026] [authz_core:error] [pid 521505:tid 521761] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:06.673974 2026] [authz_core:error] [pid 521505:tid 521663] [client 216.73.216.128:33669] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:06.674408 2026] [authz_core:error] [pid 521505:tid 521663] [client 216.73.216.128:33669] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:06.704416 2026] [security2:error] [pid 524122:tid 524214] [remote 185.93.89.167:39769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ar.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPl1n3lhEjKFiK_nBJ_lQABn1o"]
[Sun Aug 30 03:12:06.714411 2026] [security2:error] [pid 521505:tid 521640] [client 20.104.50.220:29597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/fpebr.php"] [unique_id "apPl1m8byYE0iXl--K6WowAAAyM"]
[Sun Aug 30 03:12:06.776554 2026] [security2:error] [pid 524122:tid 524319] [client 20.104.49.130:60979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wdfjba.org"] [uri "/wp.php"] [unique_id "apPl1n3lhEjKFiK_nBJ_oQAAAdE"]
[Sun Aug 30 03:12:06.786104 2026] [security2:error] [pid 521505:tid 521668] [client 20.104.49.130:43326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/ws45.php"] [unique_id "apPl1m8byYE0iXl--K6WxgAAAz8"]
[Sun Aug 30 03:12:06.789695 2026] [security2:error] [pid 521505:tid 521648] [client 158.23.184.117:33409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/index.php"] [unique_id "apPl1m8byYE0iXl--K6WyAAAAys"]
[Sun Aug 30 03:12:06.855180 2026] [authz_core:error] [pid 524122:tid 524328] [client 216.73.216.128:50934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:06.855473 2026] [authz_core:error] [pid 524122:tid 524328] [client 216.73.216.128:50934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:06.862508 2026] [authz_core:error] [pid 521505:tid 521747] [client 66.249.66.204:53372] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:06.862792 2026] [authz_core:error] [pid 521505:tid 521747] [client 66.249.66.204:53372] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:06.870693 2026] [security2:error] [pid 521505:tid 521685] [client 20.151.200.44:44943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/wp-content/admin.php"] [unique_id "apPl1m8byYE0iXl--K6W9QAAA1A"]
[Sun Aug 30 03:12:06.884365 2026] [security2:error] [pid 521505:tid 521658] [client 34.15.159.88:41576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/tmp/phpinfo.php"] [unique_id "apPl1m8byYE0iXl--K6W_wAAAzU"]
[Sun Aug 30 03:12:06.922603 2026] [authz_core:error] [pid 521505:tid 521734] [client 66.249.66.199:35967] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:06.922948 2026] [authz_core:error] [pid 521505:tid 521734] [client 66.249.66.199:35967] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:06.925320 2026] [security2:error] [pid 521505:tid 521698] [client 20.104.49.130:43298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/ortasekerli1.php"] [unique_id "apPl1m8byYE0iXl--K6XEwAAA10"]
[Sun Aug 30 03:12:06.932910 2026] [security2:error] [pid 524122:tid 524309] [client 158.23.184.117:33435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/min.php"] [unique_id "apPl1n3lhEjKFiK_nBJ_uwAAAcc"]
[Sun Aug 30 03:12:06.937354 2026] [security2:error] [pid 521505:tid 521725] [client 173.239.211.46:26509] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "apPl1m8byYE0iXl--K6XFwAAA3g"]
[Sun Aug 30 03:12:06.966996 2026] [ssl:error] [pid 521505:tid 521752] [client 207.90.244.25:38862] AH02032: Hostname gator3166.hostgator.com (default host as no SNI was provided) and hostname webdisk.briankornblum.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Sun Aug 30 03:12:06.968100 2026] [security2:error] [pid 524122:tid 524354] [client 158.23.147.79:39984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apPl1n3lhEjKFiK_nBJ_vgAAAfQ"]
[Sun Aug 30 03:12:06.977485 2026] [security2:error] [pid 521505:tid 521729] [client 20.104.49.130:45716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/as.php"] [unique_id "apPl1m8byYE0iXl--K6XLwAAA3w"]
[Sun Aug 30 03:12:07.061871 2026] [security2:error] [pid 524122:tid 524306] [client 20.104.50.220:17288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/elp.php"] [unique_id "apPl133lhEjKFiK_nBJ_zwAAAcQ"]
[Sun Aug 30 03:12:07.066767 2026] [security2:error] [pid 524122:tid 524369] [client 20.104.49.130:64069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/t.php"] [unique_id "apPl133lhEjKFiK_nBJ_0gAAAgM"]
[Sun Aug 30 03:12:07.072978 2026] [security2:error] [pid 521505:tid 521658] [client 158.23.184.117:33471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/options.php"] [unique_id "apPl128byYE0iXl--K6XWQAAAzU"]
[Sun Aug 30 03:12:07.086310 2026] [security2:error] [pid 521505:tid 521729] [client 4.205.62.107:17314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/cloud.php"] [unique_id "apPl128byYE0iXl--K6XYAAAA3w"]
[Sun Aug 30 03:12:07.103188 2026] [security2:error] [pid 521505:tid 521643] [client 158.23.147.79:16358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/goat1.php"] [unique_id "apPl128byYE0iXl--K6XYwAAAyY"]
[Sun Aug 30 03:12:07.129775 2026] [security2:error] [pid 521505:tid 521650] [client 20.104.18.15:2034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/nox.php"] [unique_id "apPl128byYE0iXl--K6XcgAAAy0"]
[Sun Aug 30 03:12:07.133143 2026] [security2:error] [pid 521505:tid 521678] [client 20.104.18.15:64665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/tnglzqmv.php"] [unique_id "apPl128byYE0iXl--K6XdAAAA0k"]
[Sun Aug 30 03:12:07.140410 2026] [security2:error] [pid 524122:tid 524275] [client 35.247.242.193:42082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/p.php"] [unique_id "apPl133lhEjKFiK_nBJ_2QAAAaU"]
[Sun Aug 30 03:12:07.155674 2026] [authz_core:error] [pid 521505:tid 521675] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:07.156033 2026] [authz_core:error] [pid 521505:tid 521675] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:07.160529 2026] [security2:error] [pid 521505:tid 521683] [client 20.48.251.3:59503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/cloud.php"] [unique_id "apPl128byYE0iXl--K6XhAAAA04"]
[Sun Aug 30 03:12:07.172197 2026] [security2:error] [pid 521505:tid 521736] [client 20.104.18.15:51102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/zoo1.php"] [unique_id "apPl128byYE0iXl--K6XiwAAA4M"]
[Sun Aug 30 03:12:07.175142 2026] [security2:error] [pid 521505:tid 521628] [remote 162.240.171.12:45090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.171.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "acgcomunicaciones.com"] [uri "/wp-login.php"] [unique_id "apPl128byYE0iXl--K6XjQADQXo"]
[Sun Aug 30 03:12:07.179165 2026] [security2:error] [pid 521505:tid 521699] [client 20.104.50.220:32891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/themes/antioch/acces.php"] [unique_id "apPl128byYE0iXl--K6XjwAAA14"]
[Sun Aug 30 03:12:07.184290 2026] [security2:error] [pid 524122:tid 524373] [client 20.104.50.220:24841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/201.php"] [unique_id "apPl133lhEjKFiK_nBJ_3gAAAgc"]
[Sun Aug 30 03:12:07.195076 2026] [security2:error] [pid 524122:tid 524318] [client 20.104.18.15:22391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gracejolliffe.com"] [uri "/reviall.php"] [unique_id "apPl133lhEjKFiK_nBJ_3wAAAdA"]
[Sun Aug 30 03:12:07.195755 2026] [security2:error] [pid 521505:tid 521653] [client 20.104.49.130:64066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/wp-good.php"] [unique_id "apPl128byYE0iXl--K6XkQAAAzA"]
[Sun Aug 30 03:12:07.211437 2026] [security2:error] [pid 521505:tid 521751] [client 216.73.216.128:33669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/sasl/developer/testing.html"] [unique_id "apPl128byYE0iXl--K6XmAAAA5I"]
[Sun Aug 30 03:12:07.213740 2026] [security2:error] [pid 521505:tid 521757] [client 158.23.184.117:33453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/pk.php"] [unique_id "apPl128byYE0iXl--K6XmwAAA5g"]
[Sun Aug 30 03:12:07.222389 2026] [authz_core:error] [pid 521505:tid 521729] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory32
[Sun Aug 30 03:12:07.222636 2026] [authz_core:error] [pid 521505:tid 521729] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory32
[Sun Aug 30 03:12:07.225738 2026] [security2:error] [pid 521505:tid 521659] [client 20.104.49.130:48033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/fs.php"] [unique_id "apPl128byYE0iXl--K6XogAAAzY"]
[Sun Aug 30 03:12:07.232364 2026] [security2:error] [pid 524122:tid 524365] [client 20.151.200.44:26560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/blnux.php"] [unique_id "apPl133lhEjKFiK_nBJ_4gAAAf8"]
[Sun Aug 30 03:12:07.273197 2026] [authz_core:error] [pid 521505:tid 521739] [client 66.249.66.78:57056] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:07.273663 2026] [authz_core:error] [pid 521505:tid 521739] [client 66.249.66.78:57056] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:07.288295 2026] [security2:error] [pid 521505:tid 521754] [client 20.151.200.44:63039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/t00l.php"] [unique_id "apPl128byYE0iXl--K6XwQAAA5U"]
[Sun Aug 30 03:12:07.304878 2026] [security2:error] [pid 521505:tid 521682] [client 20.104.50.220:31194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/randkeyword.php"] [unique_id "apPl128byYE0iXl--K6XzAAAA00"]
[Sun Aug 30 03:12:07.322355 2026] [security2:error] [pid 521505:tid 521665] [client 45.130.83.245:21463] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/wp-content/plugins/fix//wp%20sittnegc.php"] [unique_id "apPl128byYE0iXl--K6X0wAAAzw"]
[Sun Aug 30 03:12:07.326761 2026] [security2:error] [pid 521505:tid 521647] [client 20.48.251.3:65487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/php_info.php"] [unique_id "apPl128byYE0iXl--K6X1AAAAyo"]
[Sun Aug 30 03:12:07.344523 2026] [security2:error] [pid 524122:tid 524294] [client 20.48.251.3:55776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/tax.php"] [unique_id "apPl133lhEjKFiK_nBJ_9wAAAbg"]
[Sun Aug 30 03:12:07.348376 2026] [security2:error] [pid 521505:tid 521755] [client 20.104.18.15:31694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/gulu.php"] [unique_id "apPl128byYE0iXl--K6X4wAAA5Y"]
[Sun Aug 30 03:12:07.354193 2026] [security2:error] [pid 521505:tid 521644] [client 4.205.62.107:15939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/broadcasting.php"] [unique_id "apPl128byYE0iXl--K6X6QAAAyc"]
[Sun Aug 30 03:12:07.354384 2026] [security2:error] [pid 521505:tid 521748] [client 4.205.62.107:15511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/sys.php"] [unique_id "apPl128byYE0iXl--K6X6wAAA48"]
[Sun Aug 30 03:12:07.354444 2026] [security2:error] [pid 521505:tid 521740] [client 158.23.184.117:33459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/index.php"] [unique_id "apPl128byYE0iXl--K6X6gAAA4c"]
[Sun Aug 30 03:12:07.360418 2026] [core:alert] [pid 521505:tid 521758] [client 164.163.46.15:10057] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:12:07.360700 2026] [security2:error] [pid 521505:tid 521694] [client 20.104.49.130:64112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/as.php"] [unique_id "apPl128byYE0iXl--K6X8AAAA1k"]
[Sun Aug 30 03:12:07.383728 2026] [security2:error] [pid 521505:tid 521686] [client 20.104.50.220:61490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/usep.php"] [unique_id "apPl128byYE0iXl--K6X9wAAA1E"]
[Sun Aug 30 03:12:07.398368 2026] [authz_core:error] [pid 521505:tid 521683] [client 216.73.216.128:52277] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:07.398625 2026] [authz_core:error] [pid 521505:tid 521683] [client 216.73.216.128:52277] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:07.409382 2026] [security2:error] [pid 521505:tid 521721] [client 20.104.50.220:5511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/wp-config.php"] [unique_id "apPl128byYE0iXl--K6YAAAAA3Q"]
[Sun Aug 30 03:12:07.421604 2026] [security2:error] [pid 521505:tid 521528] [remote 162.240.171.12:45090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.171.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "acgcomunicaciones.com"] [uri "/wp-login.php"] [unique_id "apPl128byYE0iXl--K6YCgADWhY"], referer: https://acgcomunicaciones.com/wp-login.php
[Sun Aug 30 03:12:07.428022 2026] [authz_core:error] [pid 524122:tid 524350] [client 66.249.66.193:51519] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:07.428413 2026] [authz_core:error] [pid 524122:tid 524350] [client 66.249.66.193:51519] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:07.459753 2026] [security2:error] [pid 521505:tid 521747] [client 20.104.50.220:62831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/IP.php"] [unique_id "apPl128byYE0iXl--K6YKwAAA44"]
[Sun Aug 30 03:12:07.461245 2026] [security2:error] [pid 521505:tid 521730] [client 68.155.159.216:52550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-content/x.php"] [unique_id "apPl128byYE0iXl--K6YLQAAA30"]
[Sun Aug 30 03:12:07.462330 2026] [security2:error] [pid 521505:tid 521642] [client 4.205.62.107:29135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/btx25.php"] [unique_id "apPl128byYE0iXl--K6YMAAAAyU"]
[Sun Aug 30 03:12:07.475013 2026] [security2:error] [pid 521505:tid 521648] [client 20.48.251.3:36843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/infos.php"] [unique_id "apPl128byYE0iXl--K6YNAAAAys"]
[Sun Aug 30 03:12:07.489496 2026] [security2:error] [pid 521505:tid 521715] [client 34.15.159.88:41578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/public/phpinfo.php"] [unique_id "apPl128byYE0iXl--K6YNgAAA24"]
[Sun Aug 30 03:12:07.489953 2026] [authz_core:error] [pid 521505:tid 521667] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory28
[Sun Aug 30 03:12:07.490403 2026] [authz_core:error] [pid 521505:tid 521667] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory28
[Sun Aug 30 03:12:07.494810 2026] [security2:error] [pid 521505:tid 521720] [client 158.23.184.117:33099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/cgi-bin/index.php"] [unique_id "apPl128byYE0iXl--K6YOQAAA3M"]
[Sun Aug 30 03:12:07.498786 2026] [security2:error] [pid 524122:tid 524320] [client 20.104.49.130:64106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/mh.php"] [unique_id "apPl133lhEjKFiK_nBKAAgAAAdI"]
[Sun Aug 30 03:12:07.541945 2026] [security2:error] [pid 521505:tid 521689] [client 195.178.110.247:5784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mizunewyork.com"] [uri "/index.php"] [unique_id "apPl128byYE0iXl--K6YVAAAA1Q"]
[Sun Aug 30 03:12:07.559399 2026] [security2:error] [pid 521505:tid 521746] [client 20.104.18.15:18291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/gjewuagf.php"] [unique_id "apPl128byYE0iXl--K6YXQAAA40"]
[Sun Aug 30 03:12:07.583596 2026] [security2:error] [pid 524122:tid 524369] [client 20.151.200.44:26572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/attack.php"] [unique_id "apPl133lhEjKFiK_nBKAEAAAAgM"]
[Sun Aug 30 03:12:07.608864 2026] [security2:error] [pid 521505:tid 521644] [client 158.23.147.79:39966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apPl128byYE0iXl--K6YgAAAAyc"]
[Sun Aug 30 03:12:07.619752 2026] [security2:error] [pid 521505:tid 521758] [client 35.247.242.193:42088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/debug.php"] [unique_id "apPl128byYE0iXl--K6YiQAAA5k"]
[Sun Aug 30 03:12:07.621595 2026] [security2:error] [pid 521505:tid 521711] [client 4.205.62.107:26952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/wp-konfig.backup.php"] [unique_id "apPl128byYE0iXl--K6YjAAAA2o"]
[Sun Aug 30 03:12:07.630288 2026] [security2:error] [pid 524122:tid 524269] [client 20.104.49.130:53749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/press.php"] [unique_id "apPl133lhEjKFiK_nBKAGQAAAZ8"]
[Sun Aug 30 03:12:07.641374 2026] [security2:error] [pid 521505:tid 521663] [client 20.104.49.130:60639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/wp-blogs.php"] [unique_id "apPl128byYE0iXl--K6YmgAAAzo"]
[Sun Aug 30 03:12:07.652417 2026] [security2:error] [pid 521505:tid 521691] [client 158.23.184.117:33426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/cgi-bin/load.php"] [unique_id "apPl128byYE0iXl--K6YnQAAA1Y"]
[Sun Aug 30 03:12:07.666258 2026] [authz_core:error] [pid 521505:tid 521732] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:07.666521 2026] [authz_core:error] [pid 521505:tid 521732] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:07.695623 2026] [security2:error] [pid 521505:tid 521652] [client 195.178.110.247:8720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mizunewyork.com"] [uri "/index.php"] [unique_id "apPl128byYE0iXl--K6YuAAAAy8"]
[Sun Aug 30 03:12:07.718035 2026] [security2:error] [pid 521505:tid 521758] [client 20.104.50.220:51610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/simple_cmd.php"] [unique_id "apPl128byYE0iXl--K6YxQAAA5k"]
[Sun Aug 30 03:12:07.719107 2026] [security2:error] [pid 521505:tid 521754] [client 20.151.200.44:26574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/wk/index.php"] [unique_id "apPl128byYE0iXl--K6YxgAAA5U"]
[Sun Aug 30 03:12:07.731988 2026] [security2:error] [pid 524122:tid 524314] [client 173.239.211.52:40439] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/bolt.php"] [unique_id "apPl133lhEjKFiK_nBKAJgAAAcw"]
[Sun Aug 30 03:12:07.762354 2026] [security2:error] [pid 521505:tid 521667] [client 20.104.49.130:52104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.bluegrassatthelake.com"] [uri "/edit.php"] [unique_id "apPl128byYE0iXl--K6Y3wAAAz4"]
[Sun Aug 30 03:12:07.793016 2026] [security2:error] [pid 524122:tid 524282] [client 158.23.184.117:33434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/cgi-bin/ms-files.php"] [unique_id "apPl133lhEjKFiK_nBKANAAAAaw"]
[Sun Aug 30 03:12:07.875688 2026] [authz_core:error] [pid 524122:tid 524348] [client 66.249.66.196:55262] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:07.875985 2026] [authz_core:error] [pid 524122:tid 524348] [client 66.249.66.196:55262] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:07.911565 2026] [security2:error] [pid 521505:tid 521638] [client 20.104.49.130:26631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/xwpg.php"] [unique_id "apPl128byYE0iXl--K6ZJQAAAyE"]
[Sun Aug 30 03:12:07.933898 2026] [security2:error] [pid 524122:tid 524279] [client 158.23.184.117:33417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/cgi-bin/wp-activate.php"] [unique_id "apPl133lhEjKFiK_nBKAVgAAAak"]
[Sun Aug 30 03:12:07.939000 2026] [security2:error] [pid 521505:tid 521753] [client 216.73.216.128:3512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/usage_202509.html"] [unique_id "apPl128byYE0iXl--K6ZKgAAA5Q"]
[Sun Aug 30 03:12:07.951227 2026] [security2:error] [pid 521505:tid 521675] [client 20.104.49.130:63521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/fs.php"] [unique_id "apPl128byYE0iXl--K6ZLwAAA0Y"]
[Sun Aug 30 03:12:07.974368 2026] [authz_core:error] [pid 521505:tid 521759] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory29
[Sun Aug 30 03:12:07.974630 2026] [authz_core:error] [pid 521505:tid 521759] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory29
[Sun Aug 30 03:12:07.979802 2026] [security2:error] [pid 521505:tid 521643] [client 158.23.147.79:39947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apPl128byYE0iXl--K6ZOwAAAyY"]
[Sun Aug 30 03:12:08.001184 2026] [security2:error] [pid 524122:tid 524302] [client 20.151.200.44:26566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/dehnl.php"] [unique_id "apPl2H3lhEjKFiK_nBKAYgAAAcA"]
[Sun Aug 30 03:12:08.014172 2026] [authz_core:error] [pid 521505:tid 521715] [client 66.249.66.64:42734] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:08.014448 2026] [authz_core:error] [pid 521505:tid 521715] [client 66.249.66.64:42734] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:08.073895 2026] [security2:error] [pid 521505:tid 521657] [client 158.23.184.117:33416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/cgi-bin/wp-load.php"] [unique_id "apPl2G8byYE0iXl--K6ZbQAAAzQ"]
[Sun Aug 30 03:12:08.103298 2026] [security2:error] [pid 521505:tid 521713] [client 35.247.242.193:42094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/admin/phpinfo.php"] [unique_id "apPl2G8byYE0iXl--K6ZfAAAA2w"]
[Sun Aug 30 03:12:08.175820 2026] [authz_core:error] [pid 521505:tid 521676] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:08.176091 2026] [authz_core:error] [pid 521505:tid 521676] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:08.185173 2026] [ssl:error] [pid 524122:tid 524373] [client 207.90.244.25:38872] AH02032: Hostname gator3166.hostgator.com (default host as no SNI was provided) and hostname webdisk.briankornblum.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Sun Aug 30 03:12:08.190640 2026] [security2:error] [pid 521505:tid 521724] [client 158.23.147.79:39968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/dropdown.php"] [unique_id "apPl2G8byYE0iXl--K6ZogAAA3c"]
[Sun Aug 30 03:12:08.190929 2026] [security2:error] [pid 521505:tid 521741] [client 20.104.50.220:16608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/wtz.php"] [unique_id "apPl2G8byYE0iXl--K6ZowAAA4g"]
[Sun Aug 30 03:12:08.193569 2026] [security2:error] [pid 521505:tid 521735] [client 20.151.200.44:23593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/ls.php"] [unique_id "apPl2G8byYE0iXl--K6ZpAAAA4I"]
[Sun Aug 30 03:12:08.214823 2026] [security2:error] [pid 521505:tid 521704] [client 158.23.184.117:33096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/cgi-bin/wp-mail.php"] [unique_id "apPl2G8byYE0iXl--K6ZrgAAA2M"]
[Sun Aug 30 03:12:08.217837 2026] [authz_core:error] [pid 521505:tid 521635] [client 216.73.216.128:52277] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:08.218104 2026] [authz_core:error] [pid 521505:tid 521635] [client 216.73.216.128:52277] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:08.219190 2026] [security2:error] [pid 521505:tid 521740] [client 4.205.62.107:16807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/asdf.php"] [unique_id "apPl2G8byYE0iXl--K6ZsQAAA4c"]
[Sun Aug 30 03:12:08.225648 2026] [authz_core:error] [pid 521505:tid 521750] [client 66.249.66.199:35967] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:08.225960 2026] [authz_core:error] [pid 521505:tid 521750] [client 66.249.66.199:35967] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:08.229367 2026] [security2:error] [pid 524122:tid 524309] [client 63.135.161.119:51093] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/wp-admin/css/index.php"] [unique_id "apPl2H3lhEjKFiK_nBKAggAAAcc"]
[Sun Aug 30 03:12:08.269000 2026] [security2:error] [pid 521505:tid 521754] [client 20.104.18.15:2017] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/1.php"] [unique_id "apPl2G8byYE0iXl--K6ZygAAA5U"]
[Sun Aug 30 03:12:08.269120 2026] [security2:error] [pid 521505:tid 521754] [client 20.104.18.15:2017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/1.php"] [unique_id "apPl2G8byYE0iXl--K6ZygAAA5U"]
[Sun Aug 30 03:12:08.283177 2026] [security2:error] [pid 521505:tid 521677] [client 20.104.18.15:64700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/wefile.php"] [unique_id "apPl2G8byYE0iXl--K6Z1gAAA0g"]
[Sun Aug 30 03:12:08.296727 2026] [security2:error] [pid 521505:tid 521676] [client 20.48.251.3:43112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/asdf.php"] [unique_id "apPl2G8byYE0iXl--K6Z4gAAA0c"]
[Sun Aug 30 03:12:08.302939 2026] [security2:error] [pid 524122:tid 524352] [client 216.73.216.128:50934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/classes.html"] [unique_id "apPl2H3lhEjKFiK_nBKAigAAAfI"]
[Sun Aug 30 03:12:08.309699 2026] [security2:error] [pid 521505:tid 521640] [client 20.104.18.15:51187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/radio.php"] [unique_id "apPl2G8byYE0iXl--K6Z5wAAAyM"]
[Sun Aug 30 03:12:08.317953 2026] [security2:error] [pid 521505:tid 521717] [client 20.104.50.220:33200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/su.php"] [unique_id "apPl2G8byYE0iXl--K6Z6wAAA3A"]
[Sun Aug 30 03:12:08.318980 2026] [security2:error] [pid 521505:tid 521736] [client 20.104.50.220:24843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/ops.php"] [unique_id "apPl2G8byYE0iXl--K6Z7QAAA4M"]
[Sun Aug 30 03:12:08.352357 2026] [security2:error] [pid 521505:tid 521668] [client 20.104.50.220:62812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/snd21.php"] [unique_id "apPl2G8byYE0iXl--K6aAQAAAz8"]
[Sun Aug 30 03:12:08.355403 2026] [security2:error] [pid 521505:tid 521727] [client 158.23.184.117:33408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "apPl2G8byYE0iXl--K6aAgAAA3o"]
[Sun Aug 30 03:12:08.444892 2026] [security2:error] [pid 521505:tid 521639] [client 20.104.50.220:63229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/fwe.php"] [unique_id "apPl2G8byYE0iXl--K6aNAAAAyI"]
[Sun Aug 30 03:12:08.467266 2026] [security2:error] [pid 524122:tid 524344] [client 20.48.251.3:46167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/session.php"] [unique_id "apPl2H3lhEjKFiK_nBKAmgAAAeo"]
[Sun Aug 30 03:12:08.481144 2026] [security2:error] [pid 524122:tid 524302] [client 20.104.49.130:58222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/mh.php"] [unique_id "apPl2H3lhEjKFiK_nBKAnQAAAcA"]
[Sun Aug 30 03:12:08.495314 2026] [security2:error] [pid 524122:tid 524256] [client 4.205.62.107:16355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/phpsysinfo.php"] [unique_id "apPl2H3lhEjKFiK_nBKAnwAAAZI"]
[Sun Aug 30 03:12:08.495343 2026] [security2:error] [pid 521505:tid 521709] [client 4.205.62.107:15960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/aws_config.php"] [unique_id "apPl2G8byYE0iXl--K6aRAAAA2g"]
[Sun Aug 30 03:12:08.495343 2026] [security2:error] [pid 524122:tid 524339] [client 20.48.251.3:55686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPl2H3lhEjKFiK_nBKAoAAAAeU"]
[Sun Aug 30 03:12:08.498981 2026] [security2:error] [pid 521505:tid 521649] [client 158.23.184.117:33454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/chosen.php"] [unique_id "apPl2G8byYE0iXl--K6aRgAAAyw"]
[Sun Aug 30 03:12:08.509469 2026] [authz_core:error] [pid 521505:tid 521748] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory24
[Sun Aug 30 03:12:08.509795 2026] [authz_core:error] [pid 521505:tid 521748] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory24
[Sun Aug 30 03:12:08.544690 2026] [security2:error] [pid 521505:tid 521643] [client 158.23.147.79:16353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-includes/certificates/index.php"] [unique_id "apPl2G8byYE0iXl--K6aZwAAAyY"]
[Sun Aug 30 03:12:08.562992 2026] [security2:error] [pid 524122:tid 524375] [client 20.104.50.220:61974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wa.php"] [unique_id "apPl2H3lhEjKFiK_nBKAqQAAAgk"]
[Sun Aug 30 03:12:08.585931 2026] [security2:error] [pid 521505:tid 521740] [client 35.247.242.193:42096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/test/phpinfo.php"] [unique_id "apPl2G8byYE0iXl--K6ahAAAA4c"]
[Sun Aug 30 03:12:08.589976 2026] [security2:error] [pid 524122:tid 524372] [client 20.104.50.220:5535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/75.php"] [unique_id "apPl2H3lhEjKFiK_nBKArAAAAgY"]
[Sun Aug 30 03:12:08.612473 2026] [security2:error] [pid 524122:tid 524307] [client 20.151.200.44:63562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/css/000.php"] [unique_id "apPl2H3lhEjKFiK_nBKAsAAAAcU"]
[Sun Aug 30 03:12:08.622931 2026] [security2:error] [pid 524122:tid 524351] [client 20.104.50.220:29624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/XiXi.php"] [unique_id "apPl2H3lhEjKFiK_nBKAsgAAAfE"]
[Sun Aug 30 03:12:08.625712 2026] [security2:error] [pid 521505:tid 521734] [client 20.104.49.130:59548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/kgoc6awap3napxxxdCdefault.php"] [unique_id "apPl2G8byYE0iXl--K6aqAAAA4E"]
[Sun Aug 30 03:12:08.632692 2026] [security2:error] [pid 521505:tid 521687] [client 20.48.251.3:36863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/env.php"] [unique_id "apPl2G8byYE0iXl--K6asgAAA1I"]
[Sun Aug 30 03:12:08.634485 2026] [security2:error] [pid 521505:tid 521683] [client 63.135.161.123:44461] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/wp-admin/index.php"] [unique_id "apPl2G8byYE0iXl--K6atgAAA04"]
[Sun Aug 30 03:12:08.643676 2026] [security2:error] [pid 524122:tid 524325] [client 4.205.62.107:29128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/app_dev.php"] [unique_id "apPl2H3lhEjKFiK_nBKAtwAAAdc"]
[Sun Aug 30 03:12:08.673521 2026] [authz_core:error] [pid 524122:tid 524336] [client 66.249.66.203:46284] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:08.673911 2026] [authz_core:error] [pid 524122:tid 524336] [client 66.249.66.203:46284] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:08.676953 2026] [security2:error] [pid 521505:tid 521696] [client 20.151.200.44:26496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/png.php"] [unique_id "apPl2G8byYE0iXl--K6azQAAA1s"]
[Sun Aug 30 03:12:08.692895 2026] [security2:error] [pid 521505:tid 521721] [client 68.155.159.216:52326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPl2G8byYE0iXl--K6a2QAAA3Q"]
[Sun Aug 30 03:12:08.695075 2026] [authz_core:error] [pid 521505:tid 521676] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:08.695327 2026] [authz_core:error] [pid 521505:tid 521676] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:08.698738 2026] [security2:error] [pid 521505:tid 521661] [client 20.104.18.15:31583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/replace.php"] [unique_id "apPl2G8byYE0iXl--K6a3AAAAzg"]
[Sun Aug 30 03:12:08.722020 2026] [authz_core:error] [pid 521505:tid 521687] [client 216.73.216.128:15807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:08.722319 2026] [authz_core:error] [pid 521505:tid 521687] [client 216.73.216.128:15807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:08.753832 2026] [security2:error] [pid 521505:tid 521665] [client 20.104.18.15:18271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/tnglzqmv.php"] [unique_id "apPl2G8byYE0iXl--K6bBQAAAzw"]
[Sun Aug 30 03:12:08.767685 2026] [security2:error] [pid 521505:tid 521661] [client 20.151.200.44:44928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/log.php"] [unique_id "apPl2G8byYE0iXl--K6bEAAAAzg"]
[Sun Aug 30 03:12:08.773333 2026] [authz_core:error] [pid 521505:tid 521704] [client 66.249.66.76:48169] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:08.773616 2026] [authz_core:error] [pid 521505:tid 521704] [client 66.249.66.76:48169] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:08.775490 2026] [security2:error] [pid 524122:tid 524321] [client 20.151.200.44:43911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ermes-it.it"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPl2H3lhEjKFiK_nBKAygAAAdM"]
[Sun Aug 30 03:12:08.794052 2026] [security2:error] [pid 521505:tid 521651] [client 158.23.184.117:33467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/class-wp-logo-new.php"] [unique_id "apPl2G8byYE0iXl--K6bFQAAAy4"]
[Sun Aug 30 03:12:08.805730 2026] [security2:error] [pid 521505:tid 521705] [client 20.104.49.130:45137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/kerang.php"] [unique_id "apPl2G8byYE0iXl--K6bHQAAA2Q"]
[Sun Aug 30 03:12:08.810158 2026] [security2:error] [pid 524122:tid 524303] [client 4.205.62.107:25689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/packed.php"] [unique_id "apPl2H3lhEjKFiK_nBKAzQAAAcE"]
[Sun Aug 30 03:12:08.858194 2026] [security2:error] [pid 521505:tid 521699] [client 20.104.50.220:63538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/alpa.php"] [unique_id "apPl2G8byYE0iXl--K6bRQAAA14"]
[Sun Aug 30 03:12:08.932198 2026] [security2:error] [pid 521505:tid 521758] [client 173.239.211.35:39147] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apPl2G8byYE0iXl--K6bawAAA5k"]
[Sun Aug 30 03:12:08.937305 2026] [security2:error] [pid 524122:tid 524369] [client 158.23.184.117:33102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/classwithtostring.php"] [unique_id "apPl2H3lhEjKFiK_nBKA1wAAAgM"]
[Sun Aug 30 03:12:08.975301 2026] [authz_core:error] [pid 521505:tid 521731] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory27
[Sun Aug 30 03:12:08.975742 2026] [authz_core:error] [pid 521505:tid 521731] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory27
[Sun Aug 30 03:12:08.997452 2026] [security2:error] [pid 521505:tid 521698] [client 216.73.216.128:29484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPl2G8byYE0iXl--K6biQAAA10"]
[Sun Aug 30 03:12:09.024146 2026] [security2:error] [pid 524122:tid 524256] [client 34.15.159.88:41584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/php-info.php"] [unique_id "apPl2X3lhEjKFiK_nBKA3gAAAZI"]
[Sun Aug 30 03:12:09.043366 2026] [security2:error] [pid 521505:tid 521736] [client 20.151.200.44:63632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/cy.php"] [unique_id "apPl2W8byYE0iXl--K6boQAAA4M"]
[Sun Aug 30 03:12:09.067686 2026] [security2:error] [pid 524122:tid 524275] [client 35.247.242.193:42110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/dev/phpinfo.php"] [unique_id "apPl2X3lhEjKFiK_nBKA5gAAAaU"]
[Sun Aug 30 03:12:09.082410 2026] [security2:error] [pid 524122:tid 524263] [client 158.23.147.79:39959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/sad/about.php"] [unique_id "apPl2X3lhEjKFiK_nBKA6AAAAZk"]
[Sun Aug 30 03:12:09.090875 2026] [security2:error] [pid 524122:tid 524341] [client 158.23.184.117:33103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/cms.php"] [unique_id "apPl2X3lhEjKFiK_nBKA6QAAAec"]
[Sun Aug 30 03:12:09.181692 2026] [authz_core:error] [pid 521505:tid 521674] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:09.182045 2026] [authz_core:error] [pid 521505:tid 521674] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:09.206053 2026] [authz_core:error] [pid 521505:tid 521683] [client 66.249.66.195:47674] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:09.206325 2026] [authz_core:error] [pid 521505:tid 521683] [client 66.249.66.195:47674] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:09.220641 2026] [authz_core:error] [pid 521505:tid 521730] [client 216.73.216.128:52277] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:09.220923 2026] [authz_core:error] [pid 521505:tid 521730] [client 216.73.216.128:52277] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:09.230188 2026] [security2:error] [pid 521505:tid 521676] [client 158.23.184.117:33462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/config.php"] [unique_id "apPl2W8byYE0iXl--K6b9AAAA0c"]
[Sun Aug 30 03:12:09.321980 2026] [security2:error] [pid 521505:tid 521666] [client 20.104.50.220:17232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/galex.php"] [unique_id "apPl2W8byYE0iXl--K6cIAAAAz0"]
[Sun Aug 30 03:12:09.323001 2026] [security2:error] [pid 521505:tid 521739] [client 45.130.83.244:23943] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/wp-content/index.php"] [unique_id "apPl2W8byYE0iXl--K6cIQAAA4Y"]
[Sun Aug 30 03:12:09.356745 2026] [security2:error] [pid 521505:tid 521692] [client 4.205.62.107:17319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apPl2W8byYE0iXl--K6cOQAAA1c"]
[Sun Aug 30 03:12:09.375273 2026] [security2:error] [pid 521505:tid 521734] [client 158.23.184.117:33109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/configs.php"] [unique_id "apPl2W8byYE0iXl--K6cOgAAA4E"]
[Sun Aug 30 03:12:09.401393 2026] [security2:error] [pid 524122:tid 524272] [client 20.104.49.130:60705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/ms-edit.php"] [unique_id "apPl2X3lhEjKFiK_nBKBBAAAAaI"]
[Sun Aug 30 03:12:09.404932 2026] [security2:error] [pid 521505:tid 521664] [client 20.104.18.15:2026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/m.php"] [unique_id "apPl2W8byYE0iXl--K6cTQAAAzs"]
[Sun Aug 30 03:12:09.409951 2026] [security2:error] [pid 524122:tid 524323] [client 20.151.200.44:44888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/xwpg.php"] [unique_id "apPl2X3lhEjKFiK_nBKBBgAAAdU"]
[Sun Aug 30 03:12:09.428887 2026] [security2:error] [pid 521505:tid 521747] [client 20.104.18.15:64752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/blog.php"] [unique_id "apPl2W8byYE0iXl--K6cYQAAA44"]
[Sun Aug 30 03:12:09.433744 2026] [security2:error] [pid 521505:tid 521653] [client 20.48.251.3:52170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apPl2W8byYE0iXl--K6cZgAAAzA"]
[Sun Aug 30 03:12:09.447878 2026] [security2:error] [pid 521505:tid 521636] [client 20.104.18.15:51106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/one.php"] [unique_id "apPl2W8byYE0iXl--K6cbgAAAx8"]
[Sun Aug 30 03:12:09.455713 2026] [security2:error] [pid 521505:tid 521727] [client 20.104.50.220:33559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/xx.php"] [unique_id "apPl2W8byYE0iXl--K6ccQAAA3o"]
[Sun Aug 30 03:12:09.461117 2026] [security2:error] [pid 521505:tid 521682] [client 20.151.200.44:62995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/admin.php/pindex.php"] [unique_id "apPl2W8byYE0iXl--K6cdQAAA00"]
[Sun Aug 30 03:12:09.466750 2026] [security2:error] [pid 521505:tid 521745] [client 158.23.147.79:21448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/admin.php"] [unique_id "apPl2W8byYE0iXl--K6cdgAAA4w"]
[Sun Aug 30 03:12:09.476354 2026] [security2:error] [pid 521505:tid 521677] [client 20.104.50.220:24844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/samll.php"] [unique_id "apPl2W8byYE0iXl--K6cdwAAA0g"]
[Sun Aug 30 03:12:09.495667 2026] [authz_core:error] [pid 521505:tid 521648] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory20
[Sun Aug 30 03:12:09.496109 2026] [authz_core:error] [pid 521505:tid 521648] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory20
[Sun Aug 30 03:12:09.506862 2026] [security2:error] [pid 521505:tid 521676] [client 20.104.50.220:62821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/olu.php"] [unique_id "apPl2W8byYE0iXl--K6cgwAAA0c"]
[Sun Aug 30 03:12:09.536750 2026] [security2:error] [pid 521505:tid 521708] [client 158.23.184.117:33565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/configuration.php"] [unique_id "apPl2W8byYE0iXl--K6clAAAA2c"]
[Sun Aug 30 03:12:09.546819 2026] [security2:error] [pid 521505:tid 521729] [client 35.247.242.193:42122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/old/phpinfo.php"] [unique_id "apPl2W8byYE0iXl--K6cmAAAA3w"]
[Sun Aug 30 03:12:09.561297 2026] [security2:error] [pid 521505:tid 521638] [client 20.104.49.130:32817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/well.php"] [unique_id "apPl2W8byYE0iXl--K6cnwAAAyE"]
[Sun Aug 30 03:12:09.570368 2026] [authz_core:error] [pid 521505:tid 521705] [client 66.249.66.64:42913] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:09.570750 2026] [authz_core:error] [pid 521505:tid 521705] [client 66.249.66.64:42913] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:09.601935 2026] [security2:error] [pid 521505:tid 521674] [client 20.48.251.3:54765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/h.php"] [unique_id "apPl2W8byYE0iXl--K6cpQAAA0U"]
[Sun Aug 30 03:12:09.603552 2026] [security2:error] [pid 521505:tid 521752] [client 158.23.147.79:16383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-admin/network/index.php"] [unique_id "apPl2W8byYE0iXl--K6cpgAAA5M"]
[Sun Aug 30 03:12:09.618080 2026] [security2:error] [pid 521505:tid 521688] [client 20.104.50.220:31177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/images/m.php"] [unique_id "apPl2W8byYE0iXl--K6cqQAAA1M"]
[Sun Aug 30 03:12:09.629074 2026] [security2:error] [pid 521505:tid 521711] [client 158.23.147.79:39975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-admin/admin.php"] [unique_id "apPl2W8byYE0iXl--K6cqwAAA2o"]
[Sun Aug 30 03:12:09.630466 2026] [security2:error] [pid 524122:tid 524275] [client 4.205.62.107:16323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/sgd.php"] [unique_id "apPl2X3lhEjKFiK_nBKBEwAAAaU"]
[Sun Aug 30 03:12:09.632448 2026] [security2:error] [pid 524122:tid 524261] [client 20.48.251.3:55778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPl2X3lhEjKFiK_nBKBFAAAAZc"]
[Sun Aug 30 03:12:09.632448 2026] [security2:error] [pid 521505:tid 521739] [client 34.15.159.88:41594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/phpversion.php"] [unique_id "apPl2W8byYE0iXl--K6crAAAA4Y"]
[Sun Aug 30 03:12:09.633344 2026] [security2:error] [pid 524122:tid 524300] [client 63.135.161.121:29891] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/wp-content/plugins/fix/000.php"] [unique_id "apPl2X3lhEjKFiK_nBKBFQAAAb4"]
[Sun Aug 30 03:12:09.644837 2026] [security2:error] [pid 521505:tid 521706] [client 4.205.62.107:16354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/dialog.php"] [unique_id "apPl2W8byYE0iXl--K6crQAAA2U"]
[Sun Aug 30 03:12:09.664699 2026] [security2:error] [pid 521505:tid 521647] [client 20.104.49.130:60622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/tool.php"] [unique_id "apPl2W8byYE0iXl--K6crgAAAyo"]
[Sun Aug 30 03:12:09.677055 2026] [security2:error] [pid 521505:tid 521741] [client 158.23.184.117:33461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/content.php"] [unique_id "apPl2W8byYE0iXl--K6csAAAA4g"]
[Sun Aug 30 03:12:09.695897 2026] [authz_core:error] [pid 521505:tid 521653] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:09.696166 2026] [authz_core:error] [pid 521505:tid 521653] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:09.715048 2026] [security2:error] [pid 521505:tid 521744] [client 20.104.50.220:62216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wb.php"] [unique_id "apPl2W8byYE0iXl--K6csgAAA4s"]
[Sun Aug 30 03:12:09.741239 2026] [security2:error] [pid 521505:tid 521694] [client 20.151.200.44:26599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/txets.php"] [unique_id "apPl2W8byYE0iXl--K6cswAAA1k"]
[Sun Aug 30 03:12:09.749541 2026] [security2:error] [pid 521505:tid 521642] [client 20.151.200.44:45028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/sxxb.php"] [unique_id "apPl2W8byYE0iXl--K6ctAAAAyU"]
[Sun Aug 30 03:12:09.763392 2026] [security2:error] [pid 524122:tid 524312] [client 20.104.50.220:5465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/71.php"] [unique_id "apPl2X3lhEjKFiK_nBKBFgAAAco"]
[Sun Aug 30 03:12:09.776029 2026] [security2:error] [pid 521505:tid 521759] [client 20.104.50.220:28698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/.piongroup.php"] [unique_id "apPl2W8byYE0iXl--K6ctgAAA5o"]
[Sun Aug 30 03:12:09.783454 2026] [security2:error] [pid 521505:tid 521655] [client 4.205.62.107:52912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/php-info.php"] [unique_id "apPl2W8byYE0iXl--K6ctwAAAzI"]
[Sun Aug 30 03:12:09.786577 2026] [security2:error] [pid 521505:tid 521692] [client 20.48.251.3:36824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/xve22.php"] [unique_id "apPl2W8byYE0iXl--K6cuAAAA1c"]
[Sun Aug 30 03:12:09.788564 2026] [security2:error] [pid 521505:tid 521707] [client 20.151.200.44:23587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/admin.php/csv.php"] [unique_id "apPl2W8byYE0iXl--K6cuQAAA2Y"]
[Sun Aug 30 03:12:09.814475 2026] [security2:error] [pid 524122:tid 524341] [client 158.23.184.117:33089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/core.php"] [unique_id "apPl2X3lhEjKFiK_nBKBFwAAAec"]
[Sun Aug 30 03:12:09.831740 2026] [security2:error] [pid 521505:tid 521735] [client 158.23.147.79:39941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apPl2W8byYE0iXl--K6cugAAA4I"]
[Sun Aug 30 03:12:09.840664 2026] [security2:error] [pid 521505:tid 521699] [client 68.155.159.216:52240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/log-mama/function.php"] [unique_id "apPl2W8byYE0iXl--K6cvAAAA14"]
[Sun Aug 30 03:12:09.871047 2026] [security2:error] [pid 521505:tid 521680] [client 20.104.49.130:64759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/berlin.php"] [unique_id "apPl2W8byYE0iXl--K6cvgAAA0s"]
[Sun Aug 30 03:12:09.878602 2026] [security2:error] [pid 524122:tid 524259] [client 20.104.18.15:31690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/c4.php"] [unique_id "apPl2X3lhEjKFiK_nBKBGAAAAZU"]
[Sun Aug 30 03:12:09.882105 2026] [rewrite:warn] [pid 524122:tid 524223] AH00665: RewriteCond: NoCase option for non-regex pattern '-d' is not supported and will be ignored. (/home3/keilan/public_html/.htaccess:12)
[Sun Aug 30 03:12:09.882120 2026] [rewrite:warn] [pid 524122:tid 524223] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home3/keilan/public_html/.htaccess:13)
[Sun Aug 30 03:12:09.897424 2026] [security2:error] [pid 521505:tid 521670] [client 20.104.18.15:18200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/wefile.php"] [unique_id "apPl2W8byYE0iXl--K6cwwAAA0E"]
[Sun Aug 30 03:12:09.945691 2026] [security2:error] [pid 524122:tid 524362] [client 4.205.62.107:25715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/wp-info.php"] [unique_id "apPl2X3lhEjKFiK_nBKBGgAAAfw"]
[Sun Aug 30 03:12:09.954724 2026] [security2:error] [pid 521505:tid 521649] [client 158.23.184.117:33542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/data.php"] [unique_id "apPl2W8byYE0iXl--K6cyQAAAyw"]
[Sun Aug 30 03:12:09.972400 2026] [authz_core:error] [pid 521505:tid 521641] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:12:09.972661 2026] [authz_core:error] [pid 521505:tid 521641] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:12:10.043885 2026] [security2:error] [pid 524122:tid 524311] [client 35.247.242.193:42132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/tmp/phpinfo.php"] [unique_id "apPl2n3lhEjKFiK_nBKBHAAAAck"]
[Sun Aug 30 03:12:10.079188 2026] [security2:error] [pid 521505:tid 521677] [client 20.151.200.44:43995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ermes-it.it"] [uri "/h02ugyh.php"] [unique_id "apPl2m8byYE0iXl--K6c1AAAA0g"]
[Sun Aug 30 03:12:10.095368 2026] [security2:error] [pid 524122:tid 524307] [client 158.23.184.117:33100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/database.php"] [unique_id "apPl2n3lhEjKFiK_nBKBHQAAAcU"]
[Sun Aug 30 03:12:10.109749 2026] [security2:error] [pid 524122:tid 524375] [client 20.151.200.44:45044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/dx.php"] [unique_id "apPl2n3lhEjKFiK_nBKBHgAAAgk"]
[Sun Aug 30 03:12:10.115148 2026] [security2:error] [pid 521505:tid 521720] [client 20.104.50.220:63532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/themes/antioch/acces.php"] [unique_id "apPl2m8byYE0iXl--K6c1QAAA3M"]
[Sun Aug 30 03:12:10.127209 2026] [security2:error] [pid 524122:tid 524278] [client 45.130.83.239:56483] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/file.php"] [unique_id "apPl2n3lhEjKFiK_nBKBHwAAAag"]
[Sun Aug 30 03:12:10.138552 2026] [security2:error] [pid 521505:tid 521643] [client 20.151.200.44:23606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/admin.php/700.php"] [unique_id "apPl2m8byYE0iXl--K6c1wAAAyY"]
[Sun Aug 30 03:12:10.210583 2026] [authz_core:error] [pid 521505:tid 521750] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:10.210885 2026] [authz_core:error] [pid 521505:tid 521750] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:10.236064 2026] [security2:error] [pid 521505:tid 521752] [client 158.23.184.117:33415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/db.php"] [unique_id "apPl2m8byYE0iXl--K6c2wAAA5M"]
[Sun Aug 30 03:12:10.240276 2026] [security2:error] [pid 521505:tid 521757] [client 34.15.159.88:41606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/_phpinfo.php"] [unique_id "apPl2m8byYE0iXl--K6c3AAAA5g"]
[Sun Aug 30 03:12:10.280309 2026] [security2:error] [pid 521505:tid 521729] [client 158.23.147.79:40007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/classwithtostring.php"] [unique_id "apPl2m8byYE0iXl--K6c3QAAA3w"]
[Sun Aug 30 03:12:10.378639 2026] [security2:error] [pid 521505:tid 521725] [client 158.23.184.117:33561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/default.php"] [unique_id "apPl2m8byYE0iXl--K6c3wAAA3g"]
[Sun Aug 30 03:12:10.437622 2026] [security2:error] [pid 521505:tid 521672] [client 20.151.200.44:44996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPl2m8byYE0iXl--K6c4wAAA0M"]
[Sun Aug 30 03:12:10.460482 2026] [security2:error] [pid 521505:tid 521706] [client 20.104.50.220:16707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/xb.php"] [unique_id "apPl2m8byYE0iXl--K6c5AAAA2U"]
[Sun Aug 30 03:12:10.474679 2026] [authz_core:error] [pid 521505:tid 521762] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:12:10.474983 2026] [authz_core:error] [pid 521505:tid 521762] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:12:10.493847 2026] [security2:error] [pid 521505:tid 521708] [client 4.205.62.107:16809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/hochladen.form.php"] [unique_id "apPl2m8byYE0iXl--K6c5wAAA2c"]
[Sun Aug 30 03:12:10.521052 2026] [security2:error] [pid 521505:tid 521702] [client 158.23.184.117:33445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/dev1s.php"] [unique_id "apPl2m8byYE0iXl--K6c6QAAA2E"]
[Sun Aug 30 03:12:10.530633 2026] [security2:error] [pid 521505:tid 521738] [client 35.247.242.193:42134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/public/phpinfo.php"] [unique_id "apPl2m8byYE0iXl--K6c6gAAA4U"]
[Sun Aug 30 03:12:10.544511 2026] [security2:error] [pid 521505:tid 521747] [client 20.151.200.44:63648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/admin.php/007x.php"] [unique_id "apPl2m8byYE0iXl--K6c6wAAA44"]
[Sun Aug 30 03:12:10.545338 2026] [security2:error] [pid 524122:tid 524342] [client 20.104.18.15:1936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/fling.php"] [unique_id "apPl2n3lhEjKFiK_nBKBIwAAAeg"]
[Sun Aug 30 03:12:10.554313 2026] [authz_core:error] [pid 524122:tid 524355] [client 216.73.216.128:3031] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:10.554652 2026] [authz_core:error] [pid 524122:tid 524355] [client 216.73.216.128:3031] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:10.582459 2026] [security2:error] [pid 524122:tid 524293] [client 20.48.251.3:59517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/hochladen.form.php"] [unique_id "apPl2n3lhEjKFiK_nBKBJQAAAbc"]
[Sun Aug 30 03:12:10.588826 2026] [security2:error] [pid 521505:tid 521640] [client 20.104.18.15:64728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/wp-admin/js/wp-load.php"] [unique_id "apPl2m8byYE0iXl--K6c7gAAAyM"]
[Sun Aug 30 03:12:10.591523 2026] [authz_core:error] [pid 521505:tid 521638] [client 216.73.216.128:15807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:10.591800 2026] [authz_core:error] [pid 521505:tid 521638] [client 216.73.216.128:15807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:10.593852 2026] [security2:error] [pid 521505:tid 521744] [client 20.104.50.220:33551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/byps.php"] [unique_id "apPl2m8byYE0iXl--K6c7wAAA4s"]
[Sun Aug 30 03:12:10.600902 2026] [security2:error] [pid 521505:tid 521714] [client 20.104.18.15:51182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/503.php"] [unique_id "apPl2m8byYE0iXl--K6c8AAAA20"]
[Sun Aug 30 03:12:10.620264 2026] [security2:error] [pid 524122:tid 524268] [client 63.135.161.122:23311] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "apPl2n3lhEjKFiK_nBKBJgAAAZ4"]
[Sun Aug 30 03:12:10.621639 2026] [security2:error] [pid 521505:tid 521717] [client 20.104.50.220:24917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/ingfo.php"] [unique_id "apPl2m8byYE0iXl--K6c8wAAA3A"]
[Sun Aug 30 03:12:10.623770 2026] [security2:error] [pid 521505:tid 521657] [client 20.151.200.44:45034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/xda.php"] [unique_id "apPl2m8byYE0iXl--K6c9AAAAzQ"]
[Sun Aug 30 03:12:10.645447 2026] [security2:error] [pid 521505:tid 521655] [client 20.104.50.220:29129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/tuco.php"] [unique_id "apPl2m8byYE0iXl--K6c9QAAAzI"]
[Sun Aug 30 03:12:10.676102 2026] [security2:error] [pid 521505:tid 521642] [client 158.23.184.117:33097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/dex.php"] [unique_id "apPl2m8byYE0iXl--K6c-AAAAyU"]
[Sun Aug 30 03:12:10.677040 2026] [authz_core:error] [pid 521505:tid 521676] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:10.677312 2026] [authz_core:error] [pid 521505:tid 521676] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:10.697739 2026] [security2:error] [pid 521505:tid 521671] [client 158.23.147.79:16364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apPl2m8byYE0iXl--K6c-QAAA0I"]
[Sun Aug 30 03:12:10.751409 2026] [security2:error] [pid 521505:tid 521678] [client 20.48.251.3:46239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/bootstrap.php"] [unique_id "apPl2m8byYE0iXl--K6c_AAAA0k"]
[Sun Aug 30 03:12:10.768032 2026] [security2:error] [pid 524122:tid 524290] [client 4.205.62.107:15993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/fleen.php"] [unique_id "apPl2n3lhEjKFiK_nBKBKgAAAbQ"]
[Sun Aug 30 03:12:10.771323 2026] [security2:error] [pid 524122:tid 524359] [client 20.48.251.3:52804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/agg.php"] [unique_id "apPl2n3lhEjKFiK_nBKBLAAAAfk"]
[Sun Aug 30 03:12:10.771420 2026] [security2:error] [pid 524122:tid 524357] [client 20.104.50.220:63198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/g.php"] [unique_id "apPl2n3lhEjKFiK_nBKBKwAAAfc"]
[Sun Aug 30 03:12:10.793559 2026] [security2:error] [pid 521505:tid 521703] [client 4.205.62.107:16336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/phpinfo01.php"] [unique_id "apPl2m8byYE0iXl--K6c_QAAA2I"]
[Sun Aug 30 03:12:10.801082 2026] [security2:error] [pid 521505:tid 521710] [client 20.104.49.130:36792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/kgoc6awap3napxxxdCdefault.php"] [unique_id "apPl2m8byYE0iXl--K6c_wAAA2k"]
[Sun Aug 30 03:12:10.807517 2026] [security2:error] [pid 521505:tid 521749] [client 20.151.200.44:45012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPl2m8byYE0iXl--K6dAAAAA5A"]
[Sun Aug 30 03:12:10.810527 2026] [authz_core:error] [pid 521505:tid 521756] [client 66.249.66.206:55984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:10.810948 2026] [authz_core:error] [pid 521505:tid 521756] [client 66.249.66.206:55984] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:10.816952 2026] [security2:error] [pid 524122:tid 524364] [client 158.23.184.117:33456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/disagrsxr.php"] [unique_id "apPl2n3lhEjKFiK_nBKBLQAAAf4"]
[Sun Aug 30 03:12:10.845110 2026] [security2:error] [pid 521505:tid 521637] [client 20.151.200.44:63575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/admin.php/heex.php"] [unique_id "apPl2m8byYE0iXl--K6dAQAAAyA"]
[Sun Aug 30 03:12:10.845175 2026] [security2:error] [pid 521505:tid 521698] [client 34.15.159.88:41612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/old_phpinfo.php"] [unique_id "apPl2m8byYE0iXl--K6dAgAAA10"]
[Sun Aug 30 03:12:10.855480 2026] [security2:error] [pid 524122:tid 524354] [client 20.104.50.220:62219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/file1.php"] [unique_id "apPl2n3lhEjKFiK_nBKBLgAAAfQ"]
[Sun Aug 30 03:12:10.869953 2026] [security2:error] [pid 521505:tid 521649] [client 158.23.147.79:40001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/install.php"] [unique_id "apPl2m8byYE0iXl--K6dBAAAAyw"]
[Sun Aug 30 03:12:10.922536 2026] [security2:error] [pid 524122:tid 524272] [client 20.48.251.3:37120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/06.php"] [unique_id "apPl2n3lhEjKFiK_nBKBLwAAAaI"]
[Sun Aug 30 03:12:10.933439 2026] [security2:error] [pid 521505:tid 521659] [client 20.104.49.130:53588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/worksec.php"] [unique_id "apPl2m8byYE0iXl--K6dBgAAAzY"]
[Sun Aug 30 03:12:10.935043 2026] [security2:error] [pid 521505:tid 521748] [client 4.205.62.107:29131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/infos.php"] [unique_id "apPl2m8byYE0iXl--K6dBwAAA48"]
[Sun Aug 30 03:12:10.937980 2026] [security2:error] [pid 521505:tid 521682] [client 20.104.50.220:5588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/72.php"] [unique_id "apPl2m8byYE0iXl--K6dCAAAA00"]
[Sun Aug 30 03:12:10.941596 2026] [security2:error] [pid 521505:tid 521677] [client 173.239.211.51:65195] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/wp-content/plugins/fix/wp.php"] [unique_id "apPl2m8byYE0iXl--K6dCQAAA0g"]
[Sun Aug 30 03:12:10.957171 2026] [security2:error] [pid 521505:tid 521660] [client 158.23.184.117:33090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/domvf.php"] [unique_id "apPl2m8byYE0iXl--K6dCwAAAzc"]
[Sun Aug 30 03:12:10.963626 2026] [authz_core:error] [pid 521505:tid 521661] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:12:10.963897 2026] [authz_core:error] [pid 521505:tid 521661] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:12:10.995703 2026] [security2:error] [pid 524122:tid 524291] [client 20.104.49.130:63573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wdfjba.org"] [uri "/222.php"] [unique_id "apPl2n3lhEjKFiK_nBKBMAAAAbU"]
[Sun Aug 30 03:12:10.998605 2026] [security2:error] [pid 521505:tid 521662] [client 68.155.159.216:52582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/bk/index.php"] [unique_id "apPl2m8byYE0iXl--K6dDgAAAzk"]
[Sun Aug 30 03:12:11.007242 2026] [security2:error] [pid 521505:tid 521718] [client 20.104.50.220:28691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/oke.php"] [unique_id "apPl228byYE0iXl--K6dDwAAA3E"]
[Sun Aug 30 03:12:11.019143 2026] [security2:error] [pid 521505:tid 521731] [client 158.23.147.79:39978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-content/x/index.php"] [unique_id "apPl228byYE0iXl--K6dEAAAA34"]
[Sun Aug 30 03:12:11.021484 2026] [security2:error] [pid 521505:tid 521644] [client 20.104.18.15:31627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/rxr.php"] [unique_id "apPl228byYE0iXl--K6dEgAAAyc"]
[Sun Aug 30 03:12:11.053750 2026] [security2:error] [pid 521505:tid 521758] [client 20.104.49.130:64709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/makeasmtp.php"] [unique_id "apPl228byYE0iXl--K6dFwAAA5k"]
[Sun Aug 30 03:12:11.065179 2026] [security2:error] [pid 521505:tid 521733] [client 20.104.18.15:18424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/blog.php"] [unique_id "apPl228byYE0iXl--K6dGAAAA4A"]
[Sun Aug 30 03:12:11.070316 2026] [security2:error] [pid 521505:tid 521679] [client 158.23.147.79:58396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/.well-knownold/index.php"] [unique_id "apPl228byYE0iXl--K6dGQAAA0o"]
[Sun Aug 30 03:12:11.076326 2026] [security2:error] [pid 521505:tid 521750] [client 20.151.200.44:44933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/t00l.php"] [unique_id "apPl228byYE0iXl--K6dGgAAA5E"]
[Sun Aug 30 03:12:11.086006 2026] [security2:error] [pid 521505:tid 521725] [client 20.220.10.235:38761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPl228byYE0iXl--K6dGwAAA3g"]
[Sun Aug 30 03:12:11.097011 2026] [security2:error] [pid 521505:tid 521704] [client 158.23.184.117:33464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/donate.php"] [unique_id "apPl228byYE0iXl--K6dHAAAA2M"]
[Sun Aug 30 03:12:11.105336 2026] [security2:error] [pid 521505:tid 521667] [client 4.205.62.107:25867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/fns.php"] [unique_id "apPl228byYE0iXl--K6dHQAAAz4"]
[Sun Aug 30 03:12:11.141503 2026] [security2:error] [pid 521505:tid 521550] [remote 66.116.251.167:39116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.251.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "michaeldanzerphoto.com"] [uri "/wp-login.php"] [unique_id "apPl228byYE0iXl--K6dHgADUCw"]
[Sun Aug 30 03:12:11.168223 2026] [security2:error] [pid 524122:tid 524338] [client 20.151.200.44:26504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/wp-login.php"] [unique_id "apPl233lhEjKFiK_nBKBMwAAAeQ"]
[Sun Aug 30 03:12:11.174149 2026] [security2:error] [pid 524122:tid 524320] [client 20.151.200.44:62936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/tf.php"] [unique_id "apPl233lhEjKFiK_nBKBNAAAAdI"]
[Sun Aug 30 03:12:11.183065 2026] [authz_core:error] [pid 521505:tid 521728] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:11.183340 2026] [authz_core:error] [pid 521505:tid 521728] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:11.185186 2026] [authz_core:error] [pid 521505:tid 521706] [client 66.249.66.70:61776] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:11.185462 2026] [authz_core:error] [pid 521505:tid 521706] [client 66.249.66.70:61776] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:11.188072 2026] [security2:error] [pid 524122:tid 524287] [client 35.247.242.193:42138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/php-info.php"] [unique_id "apPl233lhEjKFiK_nBKBNQAAAbE"]
[Sun Aug 30 03:12:11.229188 2026] [security2:error] [pid 521505:tid 521743] [client 20.220.10.235:38771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPl228byYE0iXl--K6dJQAAA4o"]
[Sun Aug 30 03:12:11.242063 2026] [security2:error] [pid 524122:tid 524305] [client 158.23.184.117:33432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/dropdown.php"] [unique_id "apPl233lhEjKFiK_nBKBNgAAAcM"]
[Sun Aug 30 03:12:11.262269 2026] [autoindex:error] [pid 521505:tid 521684] [client 100.61.245.67:54133] AH01276: Cannot serve directory /home3/antgre7/tolefefoundation.org/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:12:11.271535 2026] [security2:error] [pid 521505:tid 521761] [client 20.151.200.44:45032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/ls.php"] [unique_id "apPl228byYE0iXl--K6dJwAAA5w"]
[Sun Aug 30 03:12:11.325695 2026] [security2:error] [pid 521505:tid 521714] [client 20.104.50.220:42771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/su.php"] [unique_id "apPl228byYE0iXl--K6dKQAAA20"]
[Sun Aug 30 03:12:11.346522 2026] [security2:error] [pid 521505:tid 521759] [client 158.23.147.79:39971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apPl228byYE0iXl--K6dKwAAA5o"]
[Sun Aug 30 03:12:11.365652 2026] [security2:error] [pid 521505:tid 521762] [client 20.220.10.235:38669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/h02ugyh.php"] [unique_id "apPl228byYE0iXl--K6dLAAAA50"]
[Sun Aug 30 03:12:11.384842 2026] [security2:error] [pid 521505:tid 521753] [client 158.23.184.117:33410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/edit.php"] [unique_id "apPl228byYE0iXl--K6dLQAAA5Q"]
[Sun Aug 30 03:12:11.422877 2026] [security2:error] [pid 521505:tid 521707] [client 20.104.18.15:22511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPl228byYE0iXl--K6dLwAAA2Y"]
[Sun Aug 30 03:12:11.424575 2026] [security2:error] [pid 521505:tid 521642] [client 20.151.200.44:63589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/update/da222.php"] [unique_id "apPl228byYE0iXl--K6dMAAAAyU"]
[Sun Aug 30 03:12:11.440401 2026] [security2:error] [pid 521505:tid 521671] [client 20.104.49.130:60653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/abc.php"] [unique_id "apPl228byYE0iXl--K6dMQAAA0I"]
[Sun Aug 30 03:12:11.445568 2026] [security2:error] [pid 521505:tid 521711] [client 34.15.159.88:44740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/server-info.php"] [unique_id "apPl228byYE0iXl--K6dNAAAA2o"]
[Sun Aug 30 03:12:11.447434 2026] [authz_core:error] [pid 521505:tid 521693] [client 66.249.66.45:55300] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:11.447705 2026] [authz_core:error] [pid 521505:tid 521693] [client 66.249.66.45:55300] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:11.464203 2026] [security2:error] [pid 524122:tid 524352] [client 158.23.147.79:40044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apPl233lhEjKFiK_nBKBNwAAAfI"]
[Sun Aug 30 03:12:11.482806 2026] [security2:error] [pid 524122:tid 524289] [client 158.23.147.79:58391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apPl233lhEjKFiK_nBKBOAAAAbM"]
[Sun Aug 30 03:12:11.490706 2026] [authz_core:error] [pid 521505:tid 521639] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:12:11.491024 2026] [authz_core:error] [pid 521505:tid 521639] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:12:11.495168 2026] [security2:error] [pid 521505:tid 521740] [client 20.220.10.235:38759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/sf.php"] [unique_id "apPl228byYE0iXl--K6dNgAAA4c"]
[Sun Aug 30 03:12:11.503740 2026] [security2:error] [pid 521505:tid 521705] [client 20.151.200.44:44992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/css/000.php"] [unique_id "apPl228byYE0iXl--K6dOAAAA2Q"]
[Sun Aug 30 03:12:11.515244 2026] [security2:error] [pid 524122:tid 524303] [client 173.239.211.47:59947] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/ioxi-o.php"] [unique_id "apPl233lhEjKFiK_nBKBOgAAAcE"]
[Sun Aug 30 03:12:11.525511 2026] [security2:error] [pid 524122:tid 524328] [client 158.23.184.117:33091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/ee.php"] [unique_id "apPl233lhEjKFiK_nBKBOwAAAdo"]
[Sun Aug 30 03:12:11.597907 2026] [security2:error] [pid 521505:tid 521735] [client 20.104.50.220:16739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/ova.php"] [unique_id "apPl228byYE0iXl--K6dOgAAA4I"]
[Sun Aug 30 03:12:11.623306 2026] [security2:error] [pid 521505:tid 521703] [client 20.220.10.235:38774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/4e.php"] [unique_id "apPl228byYE0iXl--K6dOwAAA2I"]
[Sun Aug 30 03:12:11.634976 2026] [security2:error] [pid 524122:tid 524306] [client 4.205.62.107:16805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/debuggen.php"] [unique_id "apPl233lhEjKFiK_nBKBPQAAAcQ"]
[Sun Aug 30 03:12:11.644609 2026] [security2:error] [pid 521505:tid 521710] [client 158.23.147.79:39987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-login.php"] [unique_id "apPl228byYE0iXl--K6dPAAAA2k"]
[Sun Aug 30 03:12:11.666140 2026] [security2:error] [pid 524122:tid 524299] [client 158.23.184.117:33457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/elp.php"] [unique_id "apPl233lhEjKFiK_nBKBPgAAAb0"]
[Sun Aug 30 03:12:11.668386 2026] [security2:error] [pid 521505:tid 521690] [client 35.247.242.193:42142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/phpversion.php"] [unique_id "apPl228byYE0iXl--K6dPQAAA1U"]
[Sun Aug 30 03:12:11.673806 2026] [security2:error] [pid 521505:tid 521637] [client 20.151.200.44:44961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/cy.php"] [unique_id "apPl228byYE0iXl--K6dPgAAAyA"]
[Sun Aug 30 03:12:11.689173 2026] [security2:error] [pid 521505:tid 521700] [client 20.104.18.15:2032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/btyuio.php"] [unique_id "apPl228byYE0iXl--K6dQAAAA18"]
[Sun Aug 30 03:12:11.728396 2026] [authz_core:error] [pid 521505:tid 521649] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:11.728742 2026] [authz_core:error] [pid 521505:tid 521649] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:11.736908 2026] [security2:error] [pid 521505:tid 521653] [client 20.104.50.220:33562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/themes/authentic/gud.php/themes/antioch/shell.php"] [unique_id "apPl228byYE0iXl--K6dQgAAAzA"]
[Sun Aug 30 03:12:11.737166 2026] [security2:error] [pid 521505:tid 521736] [client 20.48.251.3:52176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/debuggen.php"] [unique_id "apPl228byYE0iXl--K6dQwAAA4M"]
[Sun Aug 30 03:12:11.748616 2026] [security2:error] [pid 521505:tid 521694] [client 20.104.18.15:51114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/504.php"] [unique_id "apPl228byYE0iXl--K6dRAAAA1k"]
[Sun Aug 30 03:12:11.750778 2026] [security2:error] [pid 521505:tid 521681] [client 20.104.18.15:16959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/robot.php"] [unique_id "apPl228byYE0iXl--K6dRQAAA0w"]
[Sun Aug 30 03:12:11.753738 2026] [security2:error] [pid 524122:tid 524322] [client 20.220.10.235:38732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/ssss.php"] [unique_id "apPl233lhEjKFiK_nBKBPwAAAdQ"]
[Sun Aug 30 03:12:11.768893 2026] [security2:error] [pid 521505:tid 521748] [client 20.104.50.220:25420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/error_log.php"] [unique_id "apPl228byYE0iXl--K6dRgAAA48"]
[Sun Aug 30 03:12:11.827609 2026] [security2:error] [pid 524122:tid 524286] [client 63.135.161.116:26991] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/txets.php"] [unique_id "apPl233lhEjKFiK_nBKBQQAAAbA"]
[Sun Aug 30 03:12:11.829114 2026] [security2:error] [pid 524122:tid 524327] [client 158.23.184.117:33543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/en.php"] [unique_id "apPl233lhEjKFiK_nBKBQgAAAdk"]
[Sun Aug 30 03:12:11.868823 2026] [security2:error] [pid 521505:tid 521686] [client 158.23.147.79:60171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPl228byYE0iXl--K6dSgAAA1E"]
[Sun Aug 30 03:12:11.881033 2026] [security2:error] [pid 521505:tid 521731] [client 20.104.50.220:29123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/ice.php"] [unique_id "apPl228byYE0iXl--K6dTQAAA34"]
[Sun Aug 30 03:12:11.885474 2026] [authz_core:error] [pid 521505:tid 521760] [client 66.249.66.66:37995] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:11.885768 2026] [authz_core:error] [pid 521505:tid 521760] [client 66.249.66.66:37995] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:11.886888 2026] [security2:error] [pid 521505:tid 521673] [client 20.220.10.235:38762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/zoz.php"] [unique_id "apPl228byYE0iXl--K6dTgAAA0Q"]
[Sun Aug 30 03:12:11.893771 2026] [security2:error] [pid 521505:tid 521746] [client 20.48.251.3:54790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/333.php"] [unique_id "apPl228byYE0iXl--K6dTwAAA40"]
[Sun Aug 30 03:12:11.901195 2026] [security2:error] [pid 524122:tid 524288] [client 158.23.147.79:40063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apPl233lhEjKFiK_nBKBRAAAAbI"]
[Sun Aug 30 03:12:11.902169 2026] [security2:error] [pid 524122:tid 524370] [client 4.205.62.107:15942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/upload.form.php"] [unique_id "apPl233lhEjKFiK_nBKBRQAAAgQ"]
[Sun Aug 30 03:12:11.903488 2026] [security2:error] [pid 524122:tid 524301] [client 20.48.251.3:55688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/requirements.php"] [unique_id "apPl233lhEjKFiK_nBKBRgAAAb8"]
[Sun Aug 30 03:12:11.933763 2026] [security2:error] [pid 521505:tid 521688] [client 20.151.200.44:45025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/admin.php/pindex.php"] [unique_id "apPl228byYE0iXl--K6dUQAAA1M"]
[Sun Aug 30 03:12:11.937371 2026] [security2:error] [pid 521505:tid 521729] [client 20.104.50.220:63226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/tx1.php"] [unique_id "apPl228byYE0iXl--K6dUgAAA3w"]
[Sun Aug 30 03:12:11.941798 2026] [security2:error] [pid 524122:tid 524361] [client 4.205.62.107:15955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/cxc.php"] [unique_id "apPl233lhEjKFiK_nBKBRwAAAfs"]
[Sun Aug 30 03:12:11.963185 2026] [authz_core:error] [pid 521505:tid 521733] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:12:11.963445 2026] [authz_core:error] [pid 521505:tid 521733] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:12:11.970880 2026] [security2:error] [pid 521505:tid 521691] [client 158.23.184.117:33548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.lunajos.com"] [uri "/error.php"] [unique_id "apPl228byYE0iXl--K6dVQAAA1Y"]
[Sun Aug 30 03:12:12.015592 2026] [security2:error] [pid 521505:tid 521725] [client 20.220.10.235:38744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/kcs.php"] [unique_id "apPl3G8byYE0iXl--K6dVgAAA3g"]
[Sun Aug 30 03:12:12.019517 2026] [security2:error] [pid 521505:tid 521739] [client 158.23.147.79:40056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-admin/images/about.php"] [unique_id "apPl3G8byYE0iXl--K6dVwAAA4Y"]
[Sun Aug 30 03:12:12.029197 2026] [security2:error] [pid 521505:tid 521672] [client 20.104.50.220:61959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/gmo.php"] [unique_id "apPl3G8byYE0iXl--K6dWAAAA0M"]
[Sun Aug 30 03:12:12.049726 2026] [security2:error] [pid 521505:tid 521718] [client 34.15.159.88:44750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/server-status.php"] [unique_id "apPl3G8byYE0iXl--K6dWwAAA3E"]
[Sun Aug 30 03:12:12.058493 2026] [security2:error] [pid 524122:tid 524313] [client 20.48.251.3:36842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/xin1.php"] [unique_id "apPl3H3lhEjKFiK_nBKBSQAAAcs"]
[Sun Aug 30 03:12:12.067282 2026] [authz_core:error] [pid 521505:tid 521641] [client 66.249.66.32:59777] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:12.067543 2026] [authz_core:error] [pid 521505:tid 521641] [client 66.249.66.32:59777] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:12.081072 2026] [security2:error] [pid 524122:tid 524266] [client 20.104.50.220:5890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/70.php"] [unique_id "apPl3H3lhEjKFiK_nBKBSwAAAZw"]
[Sun Aug 30 03:12:12.081072 2026] [security2:error] [pid 521505:tid 521708] [client 4.205.62.107:29134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/env.php"] [unique_id "apPl3G8byYE0iXl--K6dYgAAA2c"]
[Sun Aug 30 03:12:12.131879 2026] [security2:error] [pid 524122:tid 524256] [client 158.23.147.79:21450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPl3H3lhEjKFiK_nBKBTAAAAZI"]
[Sun Aug 30 03:12:12.134326 2026] [security2:error] [pid 524122:tid 524318] [client 20.151.200.44:26498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/wp-access.php"] [unique_id "apPl3H3lhEjKFiK_nBKBTQAAAdA"]
[Sun Aug 30 03:12:12.147906 2026] [security2:error] [pid 521505:tid 521683] [client 63.135.161.119:37133] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/wp-content/themes/txets.php"] [unique_id "apPl3G8byYE0iXl--K6dZAAAA04"]
[Sun Aug 30 03:12:12.150780 2026] [security2:error] [pid 521505:tid 521734] [client 35.247.242.193:42146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/_phpinfo.php"] [unique_id "apPl3G8byYE0iXl--K6dZQAAA4E"]
[Sun Aug 30 03:12:12.170385 2026] [security2:error] [pid 524122:tid 524365] [client 20.104.18.15:31622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/reviall.php"] [unique_id "apPl3H3lhEjKFiK_nBKBTgAAAf8"]
[Sun Aug 30 03:12:12.176675 2026] [security2:error] [pid 521505:tid 521754] [client 20.220.10.235:38730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/tajj.php"] [unique_id "apPl3G8byYE0iXl--K6dZgAAA5U"]
[Sun Aug 30 03:12:12.193892 2026] [security2:error] [pid 521505:tid 521728] [client 20.104.50.220:62840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/MKY.php"] [unique_id "apPl3G8byYE0iXl--K6daAAAA3s"]
[Sun Aug 30 03:12:12.200319 2026] [authz_core:error] [pid 521505:tid 521722] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:12.200579 2026] [authz_core:error] [pid 521505:tid 521722] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:12.214111 2026] [security2:error] [pid 524122:tid 524300] [client 20.104.18.15:18314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/wp-admin/js/wp-load.php"] [unique_id "apPl3H3lhEjKFiK_nBKBTwAAAb4"]
[Sun Aug 30 03:12:12.214179 2026] [security2:error] [pid 521505:tid 521756] [client 20.151.200.44:44013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ermes-it.it"] [uri "/sf.php"] [unique_id "apPl3G8byYE0iXl--K6daQAAA5c"]
[Sun Aug 30 03:12:12.246573 2026] [authz_core:error] [pid 521505:tid 521747] [client 216.73.216.128:15807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:12.246853 2026] [authz_core:error] [pid 521505:tid 521747] [client 216.73.216.128:15807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:12.253813 2026] [security2:error] [pid 521505:tid 521753] [client 4.205.62.107:25681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/params.php"] [unique_id "apPl3G8byYE0iXl--K6dawAAA5Q"]
[Sun Aug 30 03:12:12.259069 2026] [security2:error] [pid 521505:tid 521713] [client 20.151.200.44:45004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/admin.php/csv.php"] [unique_id "apPl3G8byYE0iXl--K6dbAAAA2w"]
[Sun Aug 30 03:12:12.299858 2026] [authz_core:error] [pid 521505:tid 521642] [client 66.249.66.75:48337] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:12.300131 2026] [authz_core:error] [pid 521505:tid 521642] [client 66.249.66.75:48337] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:12.306907 2026] [security2:error] [pid 521505:tid 521640] [client 20.220.10.235:38781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/bge.php"] [unique_id "apPl3G8byYE0iXl--K6dbgAAAyM"]
[Sun Aug 30 03:12:12.347469 2026] [security2:error] [pid 521505:tid 521671] [client 20.151.200.44:23553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/qi.php"] [unique_id "apPl3G8byYE0iXl--K6dbwAAA0I"]
[Sun Aug 30 03:12:12.362589 2026] [security2:error] [pid 521505:tid 521711] [client 158.23.147.79:21490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-admin.php"] [unique_id "apPl3G8byYE0iXl--K6dcAAAA2o"]
[Sun Aug 30 03:12:12.421901 2026] [security2:error] [pid 521505:tid 521715] [client 68.155.159.216:52300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.coolreels.com"] [uri "/first.php"] [unique_id "apPl3G8byYE0iXl--K6ddAAAA24"]
[Sun Aug 30 03:12:12.437535 2026] [security2:error] [pid 521505:tid 521670] [client 20.220.10.235:38673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/ssh3ll.php"] [unique_id "apPl3G8byYE0iXl--K6ddQAAA0E"]
[Sun Aug 30 03:12:12.469689 2026] [authz_core:error] [pid 521505:tid 521639] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:12:12.469942 2026] [authz_core:error] [pid 521505:tid 521639] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:12:12.516949 2026] [security2:error] [pid 521505:tid 521693] [client 20.104.50.220:51621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/xx.php"] [unique_id "apPl3G8byYE0iXl--K6dfQAAA1g"]
[Sun Aug 30 03:12:12.521368 2026] [authz_core:error] [pid 521505:tid 521700] [client 216.73.216.128:15807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:12.521670 2026] [authz_core:error] [pid 521505:tid 521700] [client 216.73.216.128:15807] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:12.530533 2026] [security2:error] [pid 521505:tid 521545] [remote 66.116.251.167:39116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.251.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "michaeldanzerphoto.com"] [uri "/wp-login.php"] [unique_id "apPl3G8byYE0iXl--K6dfgADRic"], referer: https://michaeldanzerphoto.com/wp-login.php
[Sun Aug 30 03:12:12.551184 2026] [security2:error] [pid 521505:tid 521678] [client 158.23.147.79:21479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apPl3G8byYE0iXl--K6dfwAAA0k"]
[Sun Aug 30 03:12:12.569238 2026] [security2:error] [pid 524122:tid 524341] [client 20.220.10.235:38658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/motu.php"] [unique_id "apPl3H3lhEjKFiK_nBKBUwAAAec"]
[Sun Aug 30 03:12:12.571453 2026] [security2:error] [pid 524122:tid 524254] [client 20.104.18.15:22468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPl3H3lhEjKFiK_nBKBVAAAAZA"]
[Sun Aug 30 03:12:12.620551 2026] [security2:error] [pid 524122:tid 524259] [client 45.130.83.247:65337] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/wp-admin/txets.php"] [unique_id "apPl3H3lhEjKFiK_nBKBVgAAAZU"]
[Sun Aug 30 03:12:12.634796 2026] [security2:error] [pid 521505:tid 521690] [client 35.247.242.193:42150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/old_phpinfo.php"] [unique_id "apPl3G8byYE0iXl--K6dhAAAA1U"]
[Sun Aug 30 03:12:12.675944 2026] [security2:error] [pid 521505:tid 521638] [client 20.151.200.44:26533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/wp-content/admin.php"] [unique_id "apPl3G8byYE0iXl--K6diQAAAyE"]
[Sun Aug 30 03:12:12.680461 2026] [authz_core:error] [pid 521505:tid 521664] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:12.680911 2026] [authz_core:error] [pid 521505:tid 521664] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:12.696670 2026] [security2:error] [pid 521505:tid 521669] [client 20.220.10.235:38609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/wefile.php"] [unique_id "apPl3G8byYE0iXl--K6diwAAA0A"]
[Sun Aug 30 03:12:12.728845 2026] [security2:error] [pid 521505:tid 521649] [client 158.23.147.79:40039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/lock.php"] [unique_id "apPl3G8byYE0iXl--K6djAAAAyw"]
[Sun Aug 30 03:12:12.734314 2026] [security2:error] [pid 524122:tid 524378] [client 20.104.50.220:16632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/vx.php"] [unique_id "apPl3H3lhEjKFiK_nBKBVwAAAgw"]
[Sun Aug 30 03:12:12.754441 2026] [authz_core:error] [pid 521505:tid 521695] [client 66.249.66.75:48997] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:12.754733 2026] [authz_core:error] [pid 521505:tid 521695] [client 66.249.66.75:48997] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:12.760615 2026] [security2:error] [pid 521505:tid 521731] [client 20.151.200.44:23591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/px.php"] [unique_id "apPl3G8byYE0iXl--K6djgAAA34"]
[Sun Aug 30 03:12:12.771485 2026] [security2:error] [pid 521505:tid 521673] [client 4.205.62.107:17670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/pouhg.php"] [unique_id "apPl3G8byYE0iXl--K6djwAAA0Q"]
[Sun Aug 30 03:12:12.819780 2026] [security2:error] [pid 521505:tid 521752] [client 158.23.147.79:16324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/images/index.php"] [unique_id "apPl3G8byYE0iXl--K6dkQAAA5M"]
[Sun Aug 30 03:12:12.826329 2026] [security2:error] [pid 524122:tid 524311] [client 20.104.18.15:1923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/dehnl.php"] [unique_id "apPl3H3lhEjKFiK_nBKBWAAAAck"]
[Sun Aug 30 03:12:12.835225 2026] [security2:error] [pid 521505:tid 521742] [client 20.220.10.235:38665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/Contrller.php"] [unique_id "apPl3G8byYE0iXl--K6dkgAAA4k"]
[Sun Aug 30 03:12:12.877376 2026] [security2:error] [pid 524122:tid 524278] [client 216.73.216.128:3031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/tips.html"] [unique_id "apPl3H3lhEjKFiK_nBKBXAAAAag"]
[Sun Aug 30 03:12:12.883858 2026] [security2:error] [pid 524122:tid 524331] [client 20.48.251.3:59846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/pouhg.php"] [unique_id "apPl3H3lhEjKFiK_nBKBXQAAAd0"]
[Sun Aug 30 03:12:12.887833 2026] [security2:error] [pid 521505:tid 521665] [client 20.104.18.15:17001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/revo.php"] [unique_id "apPl3G8byYE0iXl--K6dlwAAAzw"]
[Sun Aug 30 03:12:12.890812 2026] [security2:error] [pid 524122:tid 524319] [client 20.104.50.220:33544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/and.php"] [unique_id "apPl3H3lhEjKFiK_nBKBXgAAAdE"]
[Sun Aug 30 03:12:12.894501 2026] [security2:error] [pid 524122:tid 524351] [client 20.104.18.15:51081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/admin.php"] [unique_id "apPl3H3lhEjKFiK_nBKBXwAAAfE"]
[Sun Aug 30 03:12:12.931090 2026] [security2:error] [pid 521505:tid 521739] [client 20.104.50.220:24870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/xenon1337.php"] [unique_id "apPl3G8byYE0iXl--K6dmAAAA4Y"]
[Sun Aug 30 03:12:12.939493 2026] [security2:error] [pid 521505:tid 521667] [client 63.135.161.122:42469] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/wp-includes/txets.php"] [unique_id "apPl3G8byYE0iXl--K6dmQAAAz4"]
[Sun Aug 30 03:12:12.965084 2026] [security2:error] [pid 521505:tid 521709] [client 20.220.10.235:38758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/file66.php"] [unique_id "apPl3G8byYE0iXl--K6dmgAAA2g"]
[Sun Aug 30 03:12:13.007875 2026] [authz_core:error] [pid 521505:tid 521647] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:12:13.008312 2026] [authz_core:error] [pid 521505:tid 521647] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:12:13.032202 2026] [security2:error] [pid 521505:tid 521738] [client 20.104.50.220:28681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/codeboy1877x.php"] [unique_id "apPl3W8byYE0iXl--K6dnQAAA4U"]
[Sun Aug 30 03:12:13.033861 2026] [security2:error] [pid 524122:tid 524268] [client 20.104.49.130:63501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/ms-edit.php"] [unique_id "apPl3X3lhEjKFiK_nBKBYQAAAZ4"]
[Sun Aug 30 03:12:13.033862 2026] [security2:error] [pid 521505:tid 521701] [client 20.48.251.3:54764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/G-in.php"] [unique_id "apPl3W8byYE0iXl--K6dngAAA2A"]
[Sun Aug 30 03:12:13.044903 2026] [security2:error] [pid 524122:tid 524373] [client 4.205.62.107:16358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/aws_auth.php"] [unique_id "apPl3X3lhEjKFiK_nBKBYgAAAgc"]
[Sun Aug 30 03:12:13.047344 2026] [security2:error] [pid 521505:tid 521743] [client 20.48.251.3:55715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/var/www/wallet/index.php"] [unique_id "apPl3W8byYE0iXl--K6doAAAA4o"]
[Sun Aug 30 03:12:13.062219 2026] [security2:error] [pid 521505:tid 521734] [client 20.151.200.44:26588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/log.php"] [unique_id "apPl3W8byYE0iXl--K6doQAAA4E"]
[Sun Aug 30 03:12:13.073717 2026] [authz_core:error] [pid 521505:tid 521761] [client 216.73.216.128:24775] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:13.074110 2026] [authz_core:error] [pid 521505:tid 521761] [client 216.73.216.128:24775] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:13.091062 2026] [security2:error] [pid 521505:tid 521756] [client 4.205.62.107:16353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/oiko6u.php"] [unique_id "apPl3W8byYE0iXl--K6dpAAAA5c"]
[Sun Aug 30 03:12:13.101637 2026] [authz_core:error] [pid 521505:tid 521744] [client 66.249.66.199:42115] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:13.101920 2026] [authz_core:error] [pid 521505:tid 521744] [client 66.249.66.199:42115] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:13.111004 2026] [security2:error] [pid 524122:tid 524359] [client 158.23.147.79:39954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/index/function.php"] [unique_id "apPl3X3lhEjKFiK_nBKBZAAAAfk"]
[Sun Aug 30 03:12:13.114795 2026] [security2:error] [pid 521505:tid 521753] [client 20.220.10.235:38668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/blnux.php"] [unique_id "apPl3W8byYE0iXl--K6dpwAAA5Q"]
[Sun Aug 30 03:12:13.118850 2026] [security2:error] [pid 521505:tid 521655] [client 20.104.50.220:63219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/xv.php"] [unique_id "apPl3W8byYE0iXl--K6dqAAAAzI"]
[Sun Aug 30 03:12:13.139839 2026] [security2:error] [pid 524122:tid 524293] [client 35.247.242.193:42154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/server-info.php"] [unique_id "apPl3X3lhEjKFiK_nBKBZgAAAbc"]
[Sun Aug 30 03:12:13.147735 2026] [security2:error] [pid 521505:tid 521684] [client 20.151.200.44:44997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/admin.php/700.php"] [unique_id "apPl3W8byYE0iXl--K6drQAAA08"]
[Sun Aug 30 03:12:13.148839 2026] [security2:error] [pid 521505:tid 521641] [client 20.151.200.44:62982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/is.php"] [unique_id "apPl3W8byYE0iXl--K6drgAAAyQ"]
[Sun Aug 30 03:12:13.176280 2026] [security2:error] [pid 524122:tid 524364] [client 20.104.50.220:61969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/info.php"] [unique_id "apPl3X3lhEjKFiK_nBKBZwAAAf4"]
[Sun Aug 30 03:12:13.187478 2026] [authz_core:error] [pid 521505:tid 521711] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:13.187763 2026] [authz_core:error] [pid 521505:tid 521711] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:13.197441 2026] [security2:error] [pid 521505:tid 521702] [client 20.48.251.3:36909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/sadd.php"] [unique_id "apPl3W8byYE0iXl--K6dsgAAA2E"]
[Sun Aug 30 03:12:13.229532 2026] [security2:error] [pid 524122:tid 524354] [client 4.205.62.107:52894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/xve22.php"] [unique_id "apPl3X3lhEjKFiK_nBKBagAAAfQ"]
[Sun Aug 30 03:12:13.243803 2026] [security2:error] [pid 524122:tid 524285] [client 20.104.50.220:5584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/69.php"] [unique_id "apPl3X3lhEjKFiK_nBKBawAAAa8"]
[Sun Aug 30 03:12:13.249105 2026] [security2:error] [pid 524122:tid 524294] [client 20.220.10.235:38775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/attack.php"] [unique_id "apPl3X3lhEjKFiK_nBKBbAAAAbg"]
[Sun Aug 30 03:12:13.253731 2026] [security2:error] [pid 521505:tid 521715] [client 173.239.211.46:49721] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/goods.php"] [unique_id "apPl3W8byYE0iXl--K6duAAAA24"]
[Sun Aug 30 03:12:13.258861 2026] [security2:error] [pid 521505:tid 521670] [client 20.104.49.130:63254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/ioxi-o.php"] [unique_id "apPl3W8byYE0iXl--K6duQAAA0E"]
[Sun Aug 30 03:12:13.332431 2026] [security2:error] [pid 521505:tid 521675] [client 20.104.50.220:28720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/xl33t.php"] [unique_id "apPl3W8byYE0iXl--K6dugAAA0Y"]
[Sun Aug 30 03:12:13.357573 2026] [security2:error] [pid 521505:tid 521668] [client 20.104.18.15:18240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/robot.php"] [unique_id "apPl3W8byYE0iXl--K6dvQAAAz8"]
[Sun Aug 30 03:12:13.393525 2026] [security2:error] [pid 521505:tid 521681] [client 20.220.10.235:38741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/wk/index.php"] [unique_id "apPl3W8byYE0iXl--K6dvgAAA0w"]
[Sun Aug 30 03:12:13.402735 2026] [security2:error] [pid 524122:tid 524323] [client 4.205.62.107:26949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/gjm.php"] [unique_id "apPl3X3lhEjKFiK_nBKBbQAAAdU"]
[Sun Aug 30 03:12:13.428457 2026] [security2:error] [pid 521505:tid 521690] [client 216.73.216.128:15807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/globals_u.html"] [unique_id "apPl3W8byYE0iXl--K6dwQAAA1U"]
[Sun Aug 30 03:12:13.464034 2026] [authz_core:error] [pid 521505:tid 521669] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:12:13.464321 2026] [authz_core:error] [pid 521505:tid 521669] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:12:13.467981 2026] [security2:error] [pid 524122:tid 524360] [client 158.23.147.79:21456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/.well-known/content.php"] [unique_id "apPl3X3lhEjKFiK_nBKBbgAAAfo"]
[Sun Aug 30 03:12:13.490770 2026] [security2:error] [pid 521505:tid 521651] [client 158.23.147.79:60163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-includes/widgets/index.php"] [unique_id "apPl3W8byYE0iXl--K6dzAAAAy4"]
[Sun Aug 30 03:12:13.500691 2026] [authz_core:error] [pid 521505:tid 521644] [client 66.249.66.78:59836] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:13.500973 2026] [authz_core:error] [pid 521505:tid 521644] [client 66.249.66.78:59836] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:13.525961 2026] [authz_core:error] [pid 521505:tid 521643] [client 216.73.216.128:52277] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:13.526241 2026] [authz_core:error] [pid 521505:tid 521643] [client 216.73.216.128:52277] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:13.536365 2026] [security2:error] [pid 521505:tid 521688] [client 20.220.10.235:38678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/dehnl.php"] [unique_id "apPl3W8byYE0iXl--K6d0QAAA1M"]
[Sun Aug 30 03:12:13.554223 2026] [security2:error] [pid 521505:tid 521654] [client 20.104.49.130:53557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/tool.php"] [unique_id "apPl3W8byYE0iXl--K6d0wAAAzE"]
[Sun Aug 30 03:12:13.571249 2026] [security2:error] [pid 521505:tid 521687] [client 20.151.200.44:26615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/xwpg.php"] [unique_id "apPl3W8byYE0iXl--K6d1AAAA1I"]
[Sun Aug 30 03:12:13.591157 2026] [security2:error] [pid 524122:tid 524281] [client 20.104.49.130:64705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/wpxml.php"] [unique_id "apPl3X3lhEjKFiK_nBKBcQAAAas"]
[Sun Aug 30 03:12:13.613330 2026] [security2:error] [pid 524122:tid 524305] [client 20.48.160.90:37636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/kjyehoxl.php"] [unique_id "apPl3X3lhEjKFiK_nBKBcwAAAcM"]
[Sun Aug 30 03:12:13.623510 2026] [security2:error] [pid 524122:tid 524348] [client 173.239.211.44:44093] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/wp-editor.php"] [unique_id "apPl3X3lhEjKFiK_nBKBdQAAAe4"]
[Sun Aug 30 03:12:13.633014 2026] [security2:error] [pid 521505:tid 521716] [client 35.247.242.193:42164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/server-status.php"] [unique_id "apPl3W8byYE0iXl--K6d1wAAA28"]
[Sun Aug 30 03:12:13.676816 2026] [security2:error] [pid 521505:tid 521738] [client 20.220.10.235:38777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/png.php"] [unique_id "apPl3W8byYE0iXl--K6d2wAAA4U"]
[Sun Aug 30 03:12:13.681347 2026] [security2:error] [pid 524122:tid 524296] [client 20.48.160.90:25042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/shiny.php"] [unique_id "apPl3X3lhEjKFiK_nBKBeAAAAbo"]
[Sun Aug 30 03:12:13.693260 2026] [authz_core:error] [pid 521505:tid 521751] [client 66.249.66.45:43954] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:13.693664 2026] [authz_core:error] [pid 521505:tid 521751] [client 66.249.66.45:43954] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:13.698779 2026] [authz_core:error] [pid 521505:tid 521732] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:13.699199 2026] [authz_core:error] [pid 521505:tid 521732] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:13.718885 2026] [security2:error] [pid 521505:tid 521728] [client 20.104.18.15:22477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/media.php"] [unique_id "apPl3W8byYE0iXl--K6d3wAAA3s"]
[Sun Aug 30 03:12:13.743460 2026] [security2:error] [pid 521505:tid 521762] [client 20.104.50.220:42790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/byps.php"] [unique_id "apPl3W8byYE0iXl--K6d4AAAA50"]
[Sun Aug 30 03:12:13.745303 2026] [security2:error] [pid 521505:tid 521753] [client 20.48.160.90:61459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/llyuxaqd.php"] [unique_id "apPl3W8byYE0iXl--K6d4QAAA5Q"]
[Sun Aug 30 03:12:13.754890 2026] [security2:error] [pid 521505:tid 521655] [client 158.23.147.79:21473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/cong.php"] [unique_id "apPl3W8byYE0iXl--K6d4gAAAzI"]
[Sun Aug 30 03:12:13.809728 2026] [security2:error] [pid 521505:tid 521684] [client 20.220.10.235:38756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/txets.php"] [unique_id "apPl3W8byYE0iXl--K6d5AAAA08"]
[Sun Aug 30 03:12:13.813551 2026] [security2:error] [pid 521505:tid 521718] [client 20.48.160.90:51734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/goods.php"] [unique_id "apPl3W8byYE0iXl--K6d5QAAA3E"]
[Sun Aug 30 03:12:13.873554 2026] [security2:error] [pid 521505:tid 521695] [client 20.104.50.220:16681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/rh.php"] [unique_id "apPl3W8byYE0iXl--K6d5wAAA1o"]
[Sun Aug 30 03:12:13.884528 2026] [security2:error] [pid 521505:tid 521680] [client 20.48.160.90:61475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/nbwxolou.php"] [unique_id "apPl3W8byYE0iXl--K6d6QAAA0s"]
[Sun Aug 30 03:12:13.905256 2026] [security2:error] [pid 524122:tid 524329] [client 20.151.200.44:63643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/od.php"] [unique_id "apPl3X3lhEjKFiK_nBKBegAAAds"]
[Sun Aug 30 03:12:13.910447 2026] [security2:error] [pid 521505:tid 521702] [client 4.205.62.107:17135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/phpversion.php"] [unique_id "apPl3W8byYE0iXl--K6d6gAAA2E"]
[Sun Aug 30 03:12:13.912823 2026] [security2:error] [pid 521505:tid 521648] [client 34.15.159.88:44756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/webroot/index.php/_environment"] [unique_id "apPl3W8byYE0iXl--K6d6wAAAys"]
[Sun Aug 30 03:12:13.935827 2026] [security2:error] [pid 521505:tid 521747] [client 173.239.211.46:55891] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/lufix.php"] [unique_id "apPl3W8byYE0iXl--K6d7QAAA44"]
[Sun Aug 30 03:12:13.935928 2026] [security2:error] [pid 521505:tid 521740] [client 158.23.147.79:21475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-includes/js/index.php"] [unique_id "apPl3W8byYE0iXl--K6d7AAAA4c"]
[Sun Aug 30 03:12:13.942009 2026] [security2:error] [pid 521505:tid 521685] [client 20.220.10.235:38763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/wp-login.php"] [unique_id "apPl3W8byYE0iXl--K6d7gAAA1A"]
[Sun Aug 30 03:12:13.956369 2026] [security2:error] [pid 521505:tid 521670] [client 20.48.160.90:37885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/000.php/index.php"] [unique_id "apPl3W8byYE0iXl--K6d7wAAA0E"]
[Sun Aug 30 03:12:13.958829 2026] [security2:error] [pid 521505:tid 521676] [client 20.104.18.15:1963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/zoo1.php"] [unique_id "apPl3W8byYE0iXl--K6d8AAAA0c"]
[Sun Aug 30 03:12:13.971753 2026] [authz_core:error] [pid 521505:tid 521692] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:12:13.972003 2026] [authz_core:error] [pid 521505:tid 521692] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:12:14.019132 2026] [security2:error] [pid 521505:tid 521759] [client 20.48.160.90:61560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/nsxeubyv.php"] [unique_id "apPl3m8byYE0iXl--K6d8wAAA5o"]
[Sun Aug 30 03:12:14.026101 2026] [security2:error] [pid 521505:tid 521668] [client 20.104.18.15:16994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/birrs.php"] [unique_id "apPl3m8byYE0iXl--K6d9AAAAz8"]
[Sun Aug 30 03:12:14.037267 2026] [security2:error] [pid 521505:tid 521736] [client 20.104.18.15:51150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/ws85.php"] [unique_id "apPl3m8byYE0iXl--K6d9QAAA4M"]
[Sun Aug 30 03:12:14.040886 2026] [security2:error] [pid 521505:tid 521681] [client 20.104.50.220:33579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/skizoo.php"] [unique_id "apPl3m8byYE0iXl--K6d9gAAA0w"]
[Sun Aug 30 03:12:14.055147 2026] [security2:error] [pid 524122:tid 524306] [client 20.48.251.3:52253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/phpversion.php"] [unique_id "apPl3n3lhEjKFiK_nBKBewAAAcQ"]
[Sun Aug 30 03:12:14.060652 2026] [security2:error] [pid 524122:tid 524299] [client 20.48.160.90:50433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPl3n3lhEjKFiK_nBKBfAAAAb0"]
[Sun Aug 30 03:12:14.074109 2026] [security2:error] [pid 521505:tid 521706] [client 20.220.10.235:38769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/wp-access.php"] [unique_id "apPl3m8byYE0iXl--K6d-AAAA2U"]
[Sun Aug 30 03:12:14.082668 2026] [security2:error] [pid 521505:tid 521756] [client 195.2.84.198:64251] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "195.2.84.198" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "tastylandscape.com"] [uri "/wp-comments-post.php"] [unique_id "apPl3m8byYE0iXl--K6d-QAAA5c"], referer: https://tastylandscape.com/2015/09/05/dragon-fruit-diseases/
[Sun Aug 30 03:12:14.082754 2026] [security2:error] [pid 521505:tid 521756] [client 195.2.84.198:64251] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "tastylandscape.com"] [uri "/wp-comments-post.php"] [unique_id "apPl3m8byYE0iXl--K6d-QAAA5c"], referer: https://tastylandscape.com/2015/09/05/dragon-fruit-diseases/
[Sun Aug 30 03:12:14.095588 2026] [security2:error] [pid 521505:tid 521721] [client 20.104.50.220:25451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/test11.php"] [unique_id "apPl3m8byYE0iXl--K6d-gAAA3Q"]
[Sun Aug 30 03:12:14.112399 2026] [security2:error] [pid 521505:tid 521638] [client 20.48.160.90:37807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/Jcrop.php"] [unique_id "apPl3m8byYE0iXl--K6d-wAAAyE"]
[Sun Aug 30 03:12:14.123809 2026] [security2:error] [pid 521505:tid 521694] [client 158.23.147.79:58411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apPl3m8byYE0iXl--K6d_QAAA1k"]
[Sun Aug 30 03:12:14.126415 2026] [authz_core:error] [pid 521505:tid 521639] [client 216.73.216.128:1326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:14.126865 2026] [authz_core:error] [pid 521505:tid 521639] [client 216.73.216.128:1326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:14.160866 2026] [security2:error] [pid 521505:tid 521686] [client 20.151.200.44:45015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/admin.php/007x.php"] [unique_id "apPl3m8byYE0iXl--K6eAAAAA1E"]
[Sun Aug 30 03:12:14.162649 2026] [security2:error] [pid 521505:tid 521649] [client 158.23.147.79:40048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-content/index.php"] [unique_id "apPl3m8byYE0iXl--K6eAQAAAyw"]
[Sun Aug 30 03:12:14.167955 2026] [security2:error] [pid 521505:tid 521651] [client 20.151.200.44:26600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/sxxb.php"] [unique_id "apPl3m8byYE0iXl--K6eAgAAAy4"]
[Sun Aug 30 03:12:14.175018 2026] [security2:error] [pid 521505:tid 521661] [client 20.48.160.90:37637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/zfqipfss.php"] [unique_id "apPl3m8byYE0iXl--K6eBAAAAzg"]
[Sun Aug 30 03:12:14.175990 2026] [authz_core:error] [pid 521505:tid 521760] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:14.176253 2026] [authz_core:error] [pid 521505:tid 521760] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:14.178571 2026] [security2:error] [pid 521505:tid 521664] [client 20.48.251.3:54753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/apikeys.php"] [unique_id "apPl3m8byYE0iXl--K6eBQAAAzs"]
[Sun Aug 30 03:12:14.181767 2026] [security2:error] [pid 521505:tid 521666] [client 4.205.62.107:16332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/hiquido.com/index.php"] [unique_id "apPl3m8byYE0iXl--K6eBgAAAz0"]
[Sun Aug 30 03:12:14.186815 2026] [security2:error] [pid 521505:tid 521746] [client 20.48.251.3:55780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/124.php"] [unique_id "apPl3m8byYE0iXl--K6eBwAAA40"]
[Sun Aug 30 03:12:14.190183 2026] [security2:error] [pid 521505:tid 521719] [client 20.104.50.220:29588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wsanon.php"] [unique_id "apPl3m8byYE0iXl--K6eCAAAA3I"]
[Sun Aug 30 03:12:14.213675 2026] [security2:error] [pid 521505:tid 521678] [client 20.48.160.90:50450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPl3m8byYE0iXl--K6eCgAAA0k"]
[Sun Aug 30 03:12:14.224966 2026] [security2:error] [pid 521505:tid 521688] [client 20.220.10.235:38661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/wp-content/admin.php"] [unique_id "apPl3m8byYE0iXl--K6eCwAAA1M"]
[Sun Aug 30 03:12:14.229760 2026] [security2:error] [pid 521505:tid 521742] [client 4.205.62.107:15995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/fraro.php"] [unique_id "apPl3m8byYE0iXl--K6eDAAAA4k"]
[Sun Aug 30 03:12:14.241996 2026] [security2:error] [pid 524122:tid 524286] [client 20.48.160.90:37862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/35iDq8NAjLu.php"] [unique_id "apPl3n3lhEjKFiK_nBKBfwAAAbA"]
[Sun Aug 30 03:12:14.253749 2026] [authz_core:error] [pid 521505:tid 521725] [client 216.73.216.128:24775] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:14.254007 2026] [authz_core:error] [pid 521505:tid 521725] [client 216.73.216.128:24775] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:14.270597 2026] [security2:error] [pid 521505:tid 521708] [client 20.104.50.220:31521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/x56.php"] [unique_id "apPl3m8byYE0iXl--K6eEQAAA2c"]
[Sun Aug 30 03:12:14.276472 2026] [security2:error] [pid 521505:tid 521701] [client 158.23.147.79:39955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/about/function.php"] [unique_id "apPl3m8byYE0iXl--K6eEwAAA2A"]
[Sun Aug 30 03:12:14.310667 2026] [security2:error] [pid 521505:tid 521714] [client 20.48.160.90:30731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bayoutents.com"] [uri "/zrjuyoos.php"] [unique_id "apPl3m8byYE0iXl--K6eFQAAA20"]
[Sun Aug 30 03:12:14.333962 2026] [core:alert] [pid 521505:tid 521655] [client 45.184.248.205:11630] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:12:14.335607 2026] [security2:error] [pid 521505:tid 521640] [client 20.48.251.3:36803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/application.config.php"] [unique_id "apPl3m8byYE0iXl--K6eGAAAAyM"]
[Sun Aug 30 03:12:14.344686 2026] [security2:error] [pid 521505:tid 521665] [client 20.104.50.220:62005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/file2.php"] [unique_id "apPl3m8byYE0iXl--K6eGgAAAzw"]
[Sun Aug 30 03:12:14.354632 2026] [security2:error] [pid 521505:tid 521636] [client 20.48.160.90:50518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/ser.php"] [unique_id "apPl3m8byYE0iXl--K6eHAAAAx8"]
[Sun Aug 30 03:12:14.357133 2026] [security2:error] [pid 521505:tid 521699] [client 20.220.10.235:38765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/log.php"] [unique_id "apPl3m8byYE0iXl--K6eHQAAA14"]
[Sun Aug 30 03:12:14.368837 2026] [security2:error] [pid 521505:tid 521684] [client 4.205.62.107:52852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/06.php"] [unique_id "apPl3m8byYE0iXl--K6eHgAAA08"]
[Sun Aug 30 03:12:14.371336 2026] [security2:error] [pid 521505:tid 521641] [client 20.48.160.90:37861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/btx25.php"] [unique_id "apPl3m8byYE0iXl--K6eHwAAAyQ"]
[Sun Aug 30 03:12:14.406755 2026] [security2:error] [pid 524122:tid 524301] [client 158.23.147.79:21476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apPl3n3lhEjKFiK_nBKBgQAAAb8"]
[Sun Aug 30 03:12:14.409094 2026] [security2:error] [pid 521505:tid 521671] [client 20.104.50.220:5522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/68.php"] [unique_id "apPl3m8byYE0iXl--K6eIAAAA0I"]
[Sun Aug 30 03:12:14.465431 2026] [security2:error] [pid 521505:tid 521747] [client 35.247.242.193:55922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/webroot/index.php/_environment"] [unique_id "apPl3m8byYE0iXl--K6eIwAAA44"]
[Sun Aug 30 03:12:14.485069 2026] [security2:error] [pid 524122:tid 524369] [client 20.220.10.235:38660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/xwpg.php"] [unique_id "apPl3n3lhEjKFiK_nBKBgwAAAgM"]
[Sun Aug 30 03:12:14.486302 2026] [security2:error] [pid 521505:tid 521761] [client 20.104.50.220:29599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/1n73ct10n.php"] [unique_id "apPl3m8byYE0iXl--K6eJQAAA5w"]
[Sun Aug 30 03:12:14.493581 2026] [security2:error] [pid 524122:tid 524345] [client 20.48.160.90:50523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/431.php"] [unique_id "apPl3n3lhEjKFiK_nBKBhAAAAes"]
[Sun Aug 30 03:12:14.497761 2026] [security2:error] [pid 524122:tid 524279] [client 20.104.18.15:18293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/revo.php"] [unique_id "apPl3n3lhEjKFiK_nBKBhQAAAak"]
[Sun Aug 30 03:12:14.499100 2026] [security2:error] [pid 521505:tid 521748] [client 20.151.200.44:44935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/admin.php/heex.php"] [unique_id "apPl3m8byYE0iXl--K6eJgAAA48"]
[Sun Aug 30 03:12:14.512526 2026] [authz_core:error] [pid 521505:tid 521685] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:12:14.512812 2026] [authz_core:error] [pid 521505:tid 521685] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:12:14.513677 2026] [security2:error] [pid 521505:tid 521670] [client 63.135.161.115:52419] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "watertownchessclub.com"] [uri "/style.php"] [unique_id "apPl3m8byYE0iXl--K6eKgAAA0E"]
[Sun Aug 30 03:12:14.513715 2026] [authz_core:error] [pid 521505:tid 521754] [client 66.249.66.200:47193] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:14.513983 2026] [security2:error] [pid 521505:tid 521715] [client 20.48.160.90:61593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/radio.php"] [unique_id "apPl3m8byYE0iXl--K6eKQAAA24"]
[Sun Aug 30 03:12:14.513990 2026] [authz_core:error] [pid 521505:tid 521754] [client 66.249.66.200:47193] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:14.518396 2026] [security2:error] [pid 521505:tid 521762] [client 34.15.159.88:44764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/mail/phpinfo.php"] [unique_id "apPl3m8byYE0iXl--K6eKwAAA50"]
[Sun Aug 30 03:12:14.543597 2026] [security2:error] [pid 521505:tid 521711] [client 4.205.62.107:25527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/configuration.php"] [unique_id "apPl3m8byYE0iXl--K6eLgAAA2o"]
[Sun Aug 30 03:12:14.561548 2026] [security2:error] [pid 521505:tid 521675] [client 20.104.49.130:36793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/abc.php"] [unique_id "apPl3m8byYE0iXl--K6eLwAAA0Y"]
[Sun Aug 30 03:12:14.612198 2026] [security2:error] [pid 521505:tid 521736] [client 216.73.216.128:1326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/summary.csv"] [unique_id "apPl3m8byYE0iXl--K6eMQAAA4M"]
[Sun Aug 30 03:12:14.613960 2026] [security2:error] [pid 521505:tid 521681] [client 20.220.10.235:38662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/sxxb.php"] [unique_id "apPl3m8byYE0iXl--K6eMgAAA0w"]
[Sun Aug 30 03:12:14.623953 2026] [security2:error] [pid 521505:tid 521696] [client 20.48.160.90:45376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/rxr.php"] [unique_id "apPl3m8byYE0iXl--K6eMwAAA1s"]
[Sun Aug 30 03:12:14.661898 2026] [security2:error] [pid 521505:tid 521721] [client 20.48.160.90:37873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/dex.php"] [unique_id "apPl3m8byYE0iXl--K6eNgAAA3Q"]
[Sun Aug 30 03:12:14.661960 2026] [authz_core:error] [pid 521505:tid 521677] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:14.662400 2026] [authz_core:error] [pid 521505:tid 521677] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:14.710150 2026] [authz_core:error] [pid 521505:tid 521712] [client 216.73.216.128:52277] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:14.710420 2026] [authz_core:error] [pid 521505:tid 521712] [client 216.73.216.128:52277] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:14.743604 2026] [security2:error] [pid 521505:tid 521651] [client 20.220.10.235:38780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/dx.php"] [unique_id "apPl3m8byYE0iXl--K6eOQAAAy4"]
[Sun Aug 30 03:12:14.748878 2026] [security2:error] [pid 521505:tid 521679] [client 158.23.147.79:16320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apPl3m8byYE0iXl--K6eOgAAA0o"]
[Sun Aug 30 03:12:14.758042 2026] [security2:error] [pid 521505:tid 521664] [client 20.48.160.90:50455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/csst.php"] [unique_id "apPl3m8byYE0iXl--K6ePAAAAzs"]
[Sun Aug 30 03:12:14.787612 2026] [security2:error] [pid 521505:tid 521719] [client 158.23.147.79:39981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-admin/index.php"] [unique_id "apPl3m8byYE0iXl--K6eQAAAA3I"]
[Sun Aug 30 03:12:14.793880 2026] [security2:error] [pid 521505:tid 521674] [client 20.48.160.90:61600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/giodywky.php"] [unique_id "apPl3m8byYE0iXl--K6eQgAAA0U"]
[Sun Aug 30 03:12:14.824035 2026] [security2:error] [pid 521505:tid 521650] [client 20.151.200.44:63600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/wp-the.php"] [unique_id "apPl3m8byYE0iXl--K6eQwAAAy0"]
[Sun Aug 30 03:12:14.837951 2026] [authz_core:error] [pid 521505:tid 521689] [client 66.249.66.197:41521] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:14.838233 2026] [authz_core:error] [pid 521505:tid 521689] [client 66.249.66.197:41521] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:14.866205 2026] [security2:error] [pid 521505:tid 521698] [client 20.104.18.15:22501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/adminfuns.php"] [unique_id "apPl3m8byYE0iXl--K6eSAAAA10"]
[Sun Aug 30 03:12:14.875841 2026] [security2:error] [pid 521505:tid 521660] [client 20.220.10.235:38679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPl3m8byYE0iXl--K6eSQAAAzc"]
[Sun Aug 30 03:12:14.894951 2026] [security2:error] [pid 521505:tid 521716] [client 20.48.160.90:50543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp-includes/blocks/query-title/footer.php"] [unique_id "apPl3m8byYE0iXl--K6eTAAAA28"]
[Sun Aug 30 03:12:14.907686 2026] [security2:error] [pid 521505:tid 521701] [client 20.151.200.44:44946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/tf.php"] [unique_id "apPl3m8byYE0iXl--K6eTQAAA2A"]
[Sun Aug 30 03:12:14.934775 2026] [security2:error] [pid 521505:tid 521743] [client 20.48.160.90:37849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp-kz.php"] [unique_id "apPl3m8byYE0iXl--K6eTgAAA4o"]
[Sun Aug 30 03:12:14.940081 2026] [security2:error] [pid 521505:tid 521727] [client 20.104.50.220:51631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/themes/authentic/gud.php/themes/antioch/shell.php"] [unique_id "apPl3m8byYE0iXl--K6eTwAAA3o"]
[Sun Aug 30 03:12:14.963945 2026] [security2:error] [pid 521505:tid 521752] [client 35.247.242.193:55928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/mail/phpinfo.php"] [unique_id "apPl3m8byYE0iXl--K6eUAAAA5M"]
[Sun Aug 30 03:12:14.989974 2026] [authz_core:error] [pid 521505:tid 521728] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:12:14.990259 2026] [authz_core:error] [pid 521505:tid 521728] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:12:15.005047 2026] [security2:error] [pid 521505:tid 521655] [client 20.220.10.235:38720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/xda.php"] [unique_id "apPl328byYE0iXl--K6eUwAAAzI"]
[Sun Aug 30 03:12:15.010576 2026] [security2:error] [pid 521505:tid 521640] [client 20.104.50.220:16705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/,init.php"] [unique_id "apPl328byYE0iXl--K6eVAAAAyM"]
[Sun Aug 30 03:12:15.012453 2026] [security2:error] [pid 521505:tid 521636] [client 20.151.200.44:26606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/dx.php"] [unique_id "apPl328byYE0iXl--K6eVQAAAx8"]
[Sun Aug 30 03:12:15.030179 2026] [security2:error] [pid 521505:tid 521647] [client 20.48.160.90:45377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp-content/uploads/indoex.php"] [unique_id "apPl328byYE0iXl--K6eWAAAAyo"]
[Sun Aug 30 03:12:15.060995 2026] [security2:error] [pid 521505:tid 521702] [client 4.205.62.107:17458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/adminfus.php"] [unique_id "apPl328byYE0iXl--K6eXAAAA2E"]
[Sun Aug 30 03:12:15.068331 2026] [security2:error] [pid 521505:tid 521642] [client 20.48.160.90:37838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp-includes/ID3/getid.php"] [unique_id "apPl328byYE0iXl--K6eXgAAAyU"]
[Sun Aug 30 03:12:15.101397 2026] [security2:error] [pid 521505:tid 521715] [client 20.104.18.15:2039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/radio.php"] [unique_id "apPl328byYE0iXl--K6eYgAAA24"]
[Sun Aug 30 03:12:15.126262 2026] [security2:error] [pid 521505:tid 521751] [client 34.15.159.88:44766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/cpanel/phpinfo.php"] [unique_id "apPl328byYE0iXl--K6eYwAAA5I"]
[Sun Aug 30 03:12:15.138164 2026] [security2:error] [pid 521505:tid 521710] [client 20.220.10.235:38666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPl328byYE0iXl--K6eZAAAA2k"]
[Sun Aug 30 03:12:15.160924 2026] [security2:error] [pid 521505:tid 521759] [client 20.48.160.90:50464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPl328byYE0iXl--K6eZwAAA5o"]
[Sun Aug 30 03:12:15.169618 2026] [security2:error] [pid 521505:tid 521668] [client 20.104.18.15:51026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/ffs.php"] [unique_id "apPl328byYE0iXl--K6eaAAAAz8"]
[Sun Aug 30 03:12:15.181574 2026] [authz_core:error] [pid 521505:tid 521653] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:15.182030 2026] [authz_core:error] [pid 521505:tid 521653] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:15.184315 2026] [authz_core:error] [pid 521505:tid 521736] [client 66.249.66.69:52763] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:15.184730 2026] [authz_core:error] [pid 521505:tid 521736] [client 66.249.66.69:52763] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:15.186668 2026] [security2:error] [pid 521505:tid 521681] [client 20.104.18.15:16947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/sss.php"] [unique_id "apPl328byYE0iXl--K6eawAAA0w"]
[Sun Aug 30 03:12:15.189878 2026] [security2:error] [pid 521505:tid 521696] [client 20.48.251.3:52200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/adminfus.php"] [unique_id "apPl328byYE0iXl--K6ebAAAA1s"]
[Sun Aug 30 03:12:15.199262 2026] [security2:error] [pid 521505:tid 521706] [client 20.104.50.220:33594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wsmini.php"] [unique_id "apPl328byYE0iXl--K6ebQAAA2U"]
[Sun Aug 30 03:12:15.201350 2026] [security2:error] [pid 521505:tid 521724] [client 20.48.160.90:61619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/session.php"] [unique_id "apPl328byYE0iXl--K6ebgAAA3c"]
[Sun Aug 30 03:12:15.250819 2026] [security2:error] [pid 521505:tid 521685] [client 20.104.50.220:25442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/koala.php"] [unique_id "apPl328byYE0iXl--K6ecAAAA1A"]
[Sun Aug 30 03:12:15.276576 2026] [security2:error] [pid 521505:tid 521694] [client 20.220.10.235:38721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/t00l.php"] [unique_id "apPl328byYE0iXl--K6ecQAAA1k"]
[Sun Aug 30 03:12:15.302533 2026] [security2:error] [pid 521505:tid 521645] [client 20.48.160.90:50497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/haxor.php"] [unique_id "apPl328byYE0iXl--K6ecwAAAyg"]
[Sun Aug 30 03:12:15.304765 2026] [authz_core:error] [pid 521505:tid 521637] [client 216.73.216.128:15601] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:15.304862 2026] [security2:error] [pid 524122:tid 524261] [client 20.151.200.44:44990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/update/da222.php"] [unique_id "apPl333lhEjKFiK_nBKBhwAAAZc"]
[Sun Aug 30 03:12:15.305031 2026] [authz_core:error] [pid 521505:tid 521637] [client 216.73.216.128:15601] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:15.322602 2026] [security2:error] [pid 521505:tid 521651] [client 20.48.251.3:59286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/test1.php"] [unique_id "apPl328byYE0iXl--K6edgAAAy4"]
[Sun Aug 30 03:12:15.324483 2026] [security2:error] [pid 521505:tid 521661] [client 4.205.62.107:15853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/ws79.php"] [unique_id "apPl328byYE0iXl--K6edwAAAzg"]
[Sun Aug 30 03:12:15.338137 2026] [security2:error] [pid 524122:tid 524300] [client 20.48.251.3:46230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/motu.php"] [unique_id "apPl333lhEjKFiK_nBKBiAAAAb4"]
[Sun Aug 30 03:12:15.338295 2026] [security2:error] [pid 521505:tid 521719] [client 20.151.200.44:26595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPl328byYE0iXl--K6eeAAAA3I"]
[Sun Aug 30 03:12:15.345513 2026] [authz_core:error] [pid 521505:tid 521674] [client 216.73.216.128:52277] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:15.345802 2026] [authz_core:error] [pid 521505:tid 521674] [client 216.73.216.128:52277] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:15.353758 2026] [security2:error] [pid 521505:tid 521712] [client 20.48.160.90:61685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/eagle.php"] [unique_id "apPl328byYE0iXl--K6efAAAA2s"]
[Sun Aug 30 03:12:15.353824 2026] [security2:error] [pid 521505:tid 521654] [client 20.104.50.220:52860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/Alfa.php"] [unique_id "apPl328byYE0iXl--K6eewAAAzE"]
[Sun Aug 30 03:12:15.372312 2026] [security2:error] [pid 521505:tid 521749] [client 4.205.62.107:15994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/thui.php"] [unique_id "apPl328byYE0iXl--K6efQAAA5A"]
[Sun Aug 30 03:12:15.380692 2026] [core:alert] [pid 521505:tid 521639] [client 45.226.232.75:57944] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:12:15.381370 2026] [security2:error] [pid 521505:tid 521687] [client 20.151.200.44:63606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/wt.php"] [unique_id "apPl328byYE0iXl--K6efwAAA1I"]
[Sun Aug 30 03:12:15.403710 2026] [security2:error] [pid 521505:tid 521667] [client 20.220.10.235:38688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/ls.php"] [unique_id "apPl328byYE0iXl--K6egAAAAz4"]
[Sun Aug 30 03:12:15.419152 2026] [security2:error] [pid 521505:tid 521709] [client 20.104.50.220:31190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/htaccess.php"] [unique_id "apPl328byYE0iXl--K6egQAAA2g"]
[Sun Aug 30 03:12:15.447357 2026] [security2:error] [pid 521505:tid 521757] [client 35.247.242.193:55936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/cpanel/phpinfo.php"] [unique_id "apPl328byYE0iXl--K6egwAAA5g"]
[Sun Aug 30 03:12:15.448977 2026] [security2:error] [pid 521505:tid 521754] [client 20.48.160.90:50482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/google.php"] [unique_id "apPl328byYE0iXl--K6ehAAAA5U"]
[Sun Aug 30 03:12:15.468115 2026] [authz_core:error] [pid 521505:tid 521743] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory26
[Sun Aug 30 03:12:15.468435 2026] [authz_core:error] [pid 521505:tid 521743] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory26
[Sun Aug 30 03:12:15.472595 2026] [security2:error] [pid 521505:tid 521727] [client 158.23.147.79:39999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPl328byYE0iXl--K6ehgAAA3o"]
[Sun Aug 30 03:12:15.473402 2026] [security2:error] [pid 521505:tid 521657] [client 20.48.251.3:37164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/xp.php"] [unique_id "apPl328byYE0iXl--K6ehwAAAzQ"]
[Sun Aug 30 03:12:15.482668 2026] [security2:error] [pid 521505:tid 521752] [client 20.48.160.90:61622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/up-kon.php"] [unique_id "apPl328byYE0iXl--K6eiQAAA5M"]
[Sun Aug 30 03:12:15.497011 2026] [authz_core:error] [pid 521505:tid 521682] [client 66.249.66.203:62443] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:15.497268 2026] [authz_core:error] [pid 521505:tid 521682] [client 66.249.66.203:62443] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:15.504187 2026] [security2:error] [pid 521505:tid 521707] [client 4.205.62.107:52832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/xin1.php"] [unique_id "apPl328byYE0iXl--K6ejQAAA2Y"]
[Sun Aug 30 03:12:15.515456 2026] [security2:error] [pid 521505:tid 521708] [client 20.151.200.44:44941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/qi.php"] [unique_id "apPl328byYE0iXl--K6ejgAAA2c"]
[Sun Aug 30 03:12:15.530782 2026] [security2:error] [pid 521505:tid 521758] [client 20.104.50.220:59582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/lv.php"] [unique_id "apPl328byYE0iXl--K6ekQAAA5k"]
[Sun Aug 30 03:12:15.535038 2026] [security2:error] [pid 521505:tid 521684] [client 20.220.10.235:38731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/css/000.php"] [unique_id "apPl328byYE0iXl--K6elAAAA08"]
[Sun Aug 30 03:12:15.547770 2026] [security2:error] [pid 521505:tid 521725] [client 20.104.50.220:5526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/66.php"] [unique_id "apPl328byYE0iXl--K6elwAAA3g"]
[Sun Aug 30 03:12:15.568108 2026] [security2:error] [pid 521505:tid 521644] [client 20.104.49.130:60154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/ioxi-o.php"] [unique_id "apPl328byYE0iXl--K6emAAAAyc"]
[Sun Aug 30 03:12:15.586549 2026] [security2:error] [pid 521505:tid 521741] [client 20.48.160.90:50489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "apPl328byYE0iXl--K6emQAAA4g"]
[Sun Aug 30 03:12:15.598269 2026] [security2:error] [pid 521505:tid 521642] [client 20.151.200.44:26610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/xda.php"] [unique_id "apPl328byYE0iXl--K6emgAAAyU"]
[Sun Aug 30 03:12:15.612202 2026] [security2:error] [pid 521505:tid 521703] [client 20.48.160.90:61578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/tinny.php"] [unique_id "apPl328byYE0iXl--K6emwAAA2I"]
[Sun Aug 30 03:12:15.655055 2026] [security2:error] [pid 521505:tid 521715] [client 20.104.18.15:18313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/birrs.php"] [unique_id "apPl328byYE0iXl--K6enQAAA24"]
[Sun Aug 30 03:12:15.660066 2026] [security2:error] [pid 521505:tid 521751] [client 20.104.50.220:52848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/not_acceptable.php"] [unique_id "apPl328byYE0iXl--K6enwAAA5I"]
[Sun Aug 30 03:12:15.663569 2026] [authz_core:error] [pid 521505:tid 521762] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:15.663859 2026] [authz_core:error] [pid 521505:tid 521762] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:15.678476 2026] [security2:error] [pid 521505:tid 521728] [client 4.205.62.107:25685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/server_info.php"] [unique_id "apPl328byYE0iXl--K6eoAAAA3s"]
[Sun Aug 30 03:12:15.679497 2026] [security2:error] [pid 521505:tid 521759] [client 20.151.200.44:44930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/px.php"] [unique_id "apPl328byYE0iXl--K6eoQAAA5o"]
[Sun Aug 30 03:12:15.681015 2026] [security2:error] [pid 521505:tid 521658] [client 20.220.10.235:38754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/cy.php"] [unique_id "apPl328byYE0iXl--K6eowAAAzU"]
[Sun Aug 30 03:12:15.723133 2026] [security2:error] [pid 521505:tid 521696] [client 158.23.147.79:60203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-includes/pomo/index.php"] [unique_id "apPl328byYE0iXl--K6epQAAA1s"]
[Sun Aug 30 03:12:15.728074 2026] [security2:error] [pid 521505:tid 521706] [client 20.48.160.90:50507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/robots.php"] [unique_id "apPl328byYE0iXl--K6epgAAA2U"]
[Sun Aug 30 03:12:15.735067 2026] [security2:error] [pid 524122:tid 524356] [client 34.15.159.88:44780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/hosting/phpinfo.php"] [unique_id "apPl333lhEjKFiK_nBKBiQAAAfY"]
[Sun Aug 30 03:12:15.738903 2026] [security2:error] [pid 521505:tid 521659] [client 20.48.160.90:61675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp-easy.php"] [unique_id "apPl328byYE0iXl--K6epwAAAzY"]
[Sun Aug 30 03:12:15.809312 2026] [security2:error] [pid 521505:tid 521735] [client 20.220.10.235:38605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/admin.php/pindex.php"] [unique_id "apPl328byYE0iXl--K6eqgAAA4I"]
[Sun Aug 30 03:12:15.848351 2026] [security2:error] [pid 521505:tid 521722] [client 20.151.200.44:26513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPl328byYE0iXl--K6erAAAA3U"]
[Sun Aug 30 03:12:15.867568 2026] [security2:error] [pid 521505:tid 521677] [client 20.48.160.90:50448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp-content/plugins/ccx/index.php"] [unique_id "apPl328byYE0iXl--K6erwAAA0g"]
[Sun Aug 30 03:12:15.869988 2026] [security2:error] [pid 524122:tid 524269] [client 20.48.160.90:37824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/d7.php"] [unique_id "apPl333lhEjKFiK_nBKBiwAAAZ8"]
[Sun Aug 30 03:12:15.937841 2026] [security2:error] [pid 521505:tid 521689] [client 35.247.242.193:55940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/hosting/phpinfo.php"] [unique_id "apPl328byYE0iXl--K6etQAAA1Q"]
[Sun Aug 30 03:12:15.940627 2026] [security2:error] [pid 524122:tid 524362] [client 20.220.10.235:38724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/admin.php/csv.php"] [unique_id "apPl333lhEjKFiK_nBKBjAAAAfw"]
[Sun Aug 30 03:12:15.997752 2026] [security2:error] [pid 521505:tid 521687] [client 20.48.160.90:37771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/v5.php"] [unique_id "apPl328byYE0iXl--K6evAAAA1I"]
[Sun Aug 30 03:12:16.001745 2026] [security2:error] [pid 521505:tid 521739] [client 20.48.160.90:50501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp-admin/css/colors/maro.php"] [unique_id "apPl4G8byYE0iXl--K6evQAAA4Y"]
[Sun Aug 30 03:12:16.012749 2026] [authz_core:error] [pid 521505:tid 521744] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory16
[Sun Aug 30 03:12:16.013028 2026] [authz_core:error] [pid 521505:tid 521744] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory16
[Sun Aug 30 03:12:16.053993 2026] [security2:error] [pid 521505:tid 521669] [client 20.151.200.44:26587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/t00l.php"] [unique_id "apPl4G8byYE0iXl--K6ewAAAA0A"]
[Sun Aug 30 03:12:16.055249 2026] [security2:error] [pid 524122:tid 524308] [client 20.104.18.15:22526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/classwithtostring.php"] [unique_id "apPl4H3lhEjKFiK_nBKBjwAAAcY"]
[Sun Aug 30 03:12:16.073478 2026] [security2:error] [pid 521505:tid 521738] [client 20.220.10.235:38751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/admin.php/700.php"] [unique_id "apPl4G8byYE0iXl--K6ewwAAA4U"]
[Sun Aug 30 03:12:16.083512 2026] [security2:error] [pid 521505:tid 521701] [client 20.151.200.44:63610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/im.php"] [unique_id "apPl4G8byYE0iXl--K6exQAAA2A"]
[Sun Aug 30 03:12:16.093863 2026] [security2:error] [pid 521505:tid 521731] [client 20.104.50.220:42485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/and.php"] [unique_id "apPl4G8byYE0iXl--K6exgAAA34"]
[Sun Aug 30 03:12:16.135266 2026] [security2:error] [pid 521505:tid 521643] [client 20.48.160.90:45380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp-admin/css/colors/coffee/marijuana.php"] [unique_id "apPl4G8byYE0iXl--K6eyAAAAyY"]
[Sun Aug 30 03:12:16.145216 2026] [security2:error] [pid 521505:tid 521730] [client 20.48.160.90:61654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/az.php"] [unique_id "apPl4G8byYE0iXl--K6eyQAAA30"]
[Sun Aug 30 03:12:16.159057 2026] [security2:error] [pid 521505:tid 521684] [client 216.73.216.128:24775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/nameserverconfig"] [unique_id "apPl4G8byYE0iXl--K6eygAAA08"]
[Sun Aug 30 03:12:16.179654 2026] [security2:error] [pid 524122:tid 524331] [client 20.104.50.220:16683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/env.php"] [unique_id "apPl4H3lhEjKFiK_nBKBkAAAAd0"]
[Sun Aug 30 03:12:16.181918 2026] [authz_core:error] [pid 521505:tid 521729] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:16.182357 2026] [authz_core:error] [pid 521505:tid 521729] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:16.202255 2026] [security2:error] [pid 521505:tid 521732] [client 4.205.62.107:17417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/avim.php"] [unique_id "apPl4G8byYE0iXl--K6ezQAAA38"]
[Sun Aug 30 03:12:16.218819 2026] [security2:error] [pid 524122:tid 524319] [client 20.220.10.235:38770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/admin.php/007x.php"] [unique_id "apPl4H3lhEjKFiK_nBKBkQAAAdE"]
[Sun Aug 30 03:12:16.237200 2026] [security2:error] [pid 521505:tid 521702] [client 20.104.18.15:1922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/one.php"] [unique_id "apPl4G8byYE0iXl--K6ezgAAA2E"]
[Sun Aug 30 03:12:16.266241 2026] [security2:error] [pid 524122:tid 524317] [client 20.104.49.130:53515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/bthil.php"] [unique_id "apPl4H3lhEjKFiK_nBKBlAAAAc8"]
[Sun Aug 30 03:12:16.275112 2026] [security2:error] [pid 524122:tid 524343] [client 20.104.49.130:51552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/ty.php"] [unique_id "apPl4H3lhEjKFiK_nBKBlQAAAek"]
[Sun Aug 30 03:12:16.278238 2026] [security2:error] [pid 521505:tid 521743] [client 20.48.160.90:50482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp-admin/css/colors/coffee/mari.php"] [unique_id "apPl4G8byYE0iXl--K6e0AAAA4o"]
[Sun Aug 30 03:12:16.290212 2026] [security2:error] [pid 521505:tid 521745] [client 20.48.160.90:37791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/js.php"] [unique_id "apPl4G8byYE0iXl--K6e0gAAA4w"]
[Sun Aug 30 03:12:16.308967 2026] [security2:error] [pid 521505:tid 521710] [client 20.104.18.15:51084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/nano.php"] [unique_id "apPl4G8byYE0iXl--K6e1AAAA2k"]
[Sun Aug 30 03:12:16.328769 2026] [authz_core:error] [pid 521505:tid 521759] [client 66.249.66.32:59777] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:16.329026 2026] [authz_core:error] [pid 521505:tid 521759] [client 66.249.66.32:59777] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:16.338373 2026] [security2:error] [pid 521505:tid 521658] [client 20.151.200.44:26530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/ls.php"] [unique_id "apPl4G8byYE0iXl--K6e1wAAAzU"]
[Sun Aug 30 03:12:16.339266 2026] [security2:error] [pid 524122:tid 524290] [client 20.104.50.220:32913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/86.php"] [unique_id "apPl4H3lhEjKFiK_nBKBmwAAAbQ"]
[Sun Aug 30 03:12:16.340269 2026] [security2:error] [pid 521505:tid 521708] [client 34.15.159.88:44788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/webmail/phpinfo.php"] [unique_id "apPl4G8byYE0iXl--K6e2AAAA2c"]
[Sun Aug 30 03:12:16.358319 2026] [security2:error] [pid 524122:tid 524364] [client 20.220.10.235:38742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/admin.php/heex.php"] [unique_id "apPl4H3lhEjKFiK_nBKBngAAAf4"]
[Sun Aug 30 03:12:16.359750 2026] [security2:error] [pid 524122:tid 524260] [client 20.48.251.3:52196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/avim.php"] [unique_id "apPl4H3lhEjKFiK_nBKBnwAAAZY"]
[Sun Aug 30 03:12:16.399454 2026] [security2:error] [pid 524122:tid 524285] [client 20.104.50.220:24875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/mac.php"] [unique_id "apPl4H3lhEjKFiK_nBKBoQAAAa8"]
[Sun Aug 30 03:12:16.405571 2026] [security2:error] [pid 524122:tid 524380] [client 20.104.18.15:64654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/wp-includes/ID3/moon.php"] [unique_id "apPl4H3lhEjKFiK_nBKBogAAAg4"]
[Sun Aug 30 03:12:16.411767 2026] [security2:error] [pid 521505:tid 521662] [client 20.48.160.90:50534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp-includes/images/crystal/option.php"] [unique_id "apPl4G8byYE0iXl--K6e3wAAAzk"]
[Sun Aug 30 03:12:16.419242 2026] [security2:error] [pid 521505:tid 521736] [client 35.247.242.193:55956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/webmail/phpinfo.php"] [unique_id "apPl4G8byYE0iXl--K6e4AAAA4M"]
[Sun Aug 30 03:12:16.434028 2026] [security2:error] [pid 521505:tid 521685] [client 20.48.160.90:51782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/hd.php"] [unique_id "apPl4G8byYE0iXl--K6e4gAAA1A"]
[Sun Aug 30 03:12:16.458570 2026] [security2:error] [pid 524122:tid 524291] [client 4.205.62.107:15834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/public/wp-blog.php"] [unique_id "apPl4H3lhEjKFiK_nBKBpAAAAbU"]
[Sun Aug 30 03:12:16.482516 2026] [security2:error] [pid 521505:tid 521638] [client 20.48.251.3:55742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/bigdump.php"] [unique_id "apPl4G8byYE0iXl--K6e4wAAAyE"]
[Sun Aug 30 03:12:16.503214 2026] [security2:error] [pid 524122:tid 524338] [client 158.23.147.79:40008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/about.php"] [unique_id "apPl4H3lhEjKFiK_nBKBpQAAAeQ"]
[Sun Aug 30 03:12:16.503780 2026] [security2:error] [pid 524122:tid 524280] [client 20.220.10.235:38698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/tf.php"] [unique_id "apPl4H3lhEjKFiK_nBKBpgAAAao"]
[Sun Aug 30 03:12:16.503803 2026] [security2:error] [pid 524122:tid 524320] [client 4.205.62.107:15986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/lala.php"] [unique_id "apPl4H3lhEjKFiK_nBKBpwAAAdI"]
[Sun Aug 30 03:12:16.511803 2026] [security2:error] [pid 524122:tid 524358] [client 20.48.251.3:46216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/public/mah.php.php"] [unique_id "apPl4H3lhEjKFiK_nBKBqAAAAfg"]
[Sun Aug 30 03:12:16.525239 2026] [authz_core:error] [pid 521505:tid 521755] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory14
[Sun Aug 30 03:12:16.525477 2026] [authz_core:error] [pid 521505:tid 521755] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory14
[Sun Aug 30 03:12:16.525791 2026] [security2:error] [pid 524122:tid 524277] [client 20.151.200.44:45009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/is.php"] [unique_id "apPl4H3lhEjKFiK_nBKBqgAAAac"]
[Sun Aug 30 03:12:16.549120 2026] [security2:error] [pid 521505:tid 521735] [client 20.104.50.220:29133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-admin/includes/mailer.php.php"] [unique_id "apPl4G8byYE0iXl--K6e5gAAA4I"]
[Sun Aug 30 03:12:16.555971 2026] [security2:error] [pid 524122:tid 524281] [client 20.48.160.90:50500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp-includes/pomo/xxx.php"] [unique_id "apPl4H3lhEjKFiK_nBKBrAAAAas"]
[Sun Aug 30 03:12:16.573065 2026] [security2:error] [pid 524122:tid 524333] [client 20.48.160.90:37875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/xl2023.php"] [unique_id "apPl4H3lhEjKFiK_nBKBrQAAAd8"]
[Sun Aug 30 03:12:16.576100 2026] [security2:error] [pid 524122:tid 524289] [client 20.104.50.220:59724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/readme.php"] [unique_id "apPl4H3lhEjKFiK_nBKBrgAAAbM"]
[Sun Aug 30 03:12:16.603598 2026] [authz_core:error] [pid 521505:tid 521734] [client 66.249.66.68:47010] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:16.604025 2026] [authz_core:error] [pid 521505:tid 521734] [client 66.249.66.68:47010] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:16.611571 2026] [security2:error] [pid 524122:tid 524262] [client 20.48.251.3:36819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/g3.php"] [unique_id "apPl4H3lhEjKFiK_nBKBsQAAAZg"]
[Sun Aug 30 03:12:16.638546 2026] [security2:error] [pid 524122:tid 524299] [client 4.205.62.107:52882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/sadd.php"] [unique_id "apPl4H3lhEjKFiK_nBKBsgAAAb0"]
[Sun Aug 30 03:12:16.648926 2026] [security2:error] [pid 521505:tid 521719] [client 20.220.10.235:38617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/update/da222.php"] [unique_id "apPl4G8byYE0iXl--K6e6wAAA3I"]
[Sun Aug 30 03:12:16.670156 2026] [authz_core:error] [pid 521505:tid 521668] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:16.670525 2026] [authz_core:error] [pid 521505:tid 521668] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:16.689895 2026] [security2:error] [pid 524122:tid 524337] [client 20.48.160.90:50515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/650.php"] [unique_id "apPl4H3lhEjKFiK_nBKBtAAAAeM"]
[Sun Aug 30 03:12:16.700976 2026] [security2:error] [pid 521505:tid 521650] [client 20.48.160.90:37826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/V2.php"] [unique_id "apPl4G8byYE0iXl--K6e7wAAAy0"]
[Sun Aug 30 03:12:16.717226 2026] [security2:error] [pid 521505:tid 521705] [client 20.104.50.220:5206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/67.php"] [unique_id "apPl4G8byYE0iXl--K6e8AAAA2Q"]
[Sun Aug 30 03:12:16.725423 2026] [security2:error] [pid 521505:tid 521639] [client 20.104.50.220:61634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/about.php"] [unique_id "apPl4G8byYE0iXl--K6e8QAAAyI"]
[Sun Aug 30 03:12:16.781403 2026] [security2:error] [pid 521505:tid 521672] [client 20.220.10.235:38752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/qi.php"] [unique_id "apPl4G8byYE0iXl--K6e8gAAA0M"]
[Sun Aug 30 03:12:16.791561 2026] [security2:error] [pid 524122:tid 524369] [client 20.104.18.15:18287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/sss.php"] [unique_id "apPl4H3lhEjKFiK_nBKBtgAAAgM"]
[Sun Aug 30 03:12:16.820728 2026] [security2:error] [pid 521505:tid 521738] [client 4.205.62.107:25479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/hosty.php"] [unique_id "apPl4G8byYE0iXl--K6e9QAAA4U"]
[Sun Aug 30 03:12:16.825831 2026] [security2:error] [pid 524122:tid 524353] [client 20.104.50.220:62802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/dada.php"] [unique_id "apPl4H3lhEjKFiK_nBKBtwAAAfM"]
[Sun Aug 30 03:12:16.831370 2026] [security2:error] [pid 521505:tid 521701] [client 20.48.160.90:50465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/nakrip.php"] [unique_id "apPl4G8byYE0iXl--K6e9gAAA2A"]
[Sun Aug 30 03:12:16.831765 2026] [security2:error] [pid 521505:tid 521682] [client 20.48.160.90:61571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/mad.php"] [unique_id "apPl4G8byYE0iXl--K6e9wAAA00"]
[Sun Aug 30 03:12:16.877367 2026] [security2:error] [pid 521505:tid 521731] [client 20.151.200.44:63620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/file.php"] [unique_id "apPl4G8byYE0iXl--K6e-QAAA34"]
[Sun Aug 30 03:12:16.894088 2026] [authz_core:error] [pid 524122:tid 524345] [client 66.249.66.67:52428] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:16.894362 2026] [authz_core:error] [pid 524122:tid 524345] [client 66.249.66.67:52428] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:16.900170 2026] [security2:error] [pid 521505:tid 521687] [client 35.247.242.193:55970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/smtp/phpinfo.php"] [unique_id "apPl4G8byYE0iXl--K6e-wAAA1I"]
[Sun Aug 30 03:12:16.901586 2026] [security2:error] [pid 521505:tid 521707] [client 158.23.147.79:16323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/nf_tracking.php"] [unique_id "apPl4G8byYE0iXl--K6e_AAAA2Y"]
[Sun Aug 30 03:12:16.907763 2026] [security2:error] [pid 521505:tid 521643] [client 20.151.200.44:26561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/css/000.php"] [unique_id "apPl4G8byYE0iXl--K6e_QAAAyY"]
[Sun Aug 30 03:12:16.916612 2026] [security2:error] [pid 521505:tid 521674] [client 20.151.200.44:44957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/od.php"] [unique_id "apPl4G8byYE0iXl--K6e_gAAA0U"]
[Sun Aug 30 03:12:16.916871 2026] [security2:error] [pid 521505:tid 521730] [client 20.220.10.235:38687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/px.php"] [unique_id "apPl4G8byYE0iXl--K6e_wAAA30"]
[Sun Aug 30 03:12:16.939311 2026] [security2:error] [pid 521505:tid 521739] [client 34.15.159.88:44792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/smtp/phpinfo.php"] [unique_id "apPl4G8byYE0iXl--K6fAAAAA4Y"]
[Sun Aug 30 03:12:16.958566 2026] [security2:error] [pid 521505:tid 521758] [client 20.48.160.90:45382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp-includes/interactivity-api/flower.php"] [unique_id "apPl4G8byYE0iXl--K6fAQAAA5k"]
[Sun Aug 30 03:12:16.960924 2026] [security2:error] [pid 521505:tid 521684] [client 20.48.160.90:51779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/st.php"] [unique_id "apPl4G8byYE0iXl--K6fAgAAA08"]
[Sun Aug 30 03:12:16.972419 2026] [security2:error] [pid 521505:tid 521718] [client 20.104.49.130:63499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/xwx1.php"] [unique_id "apPl4G8byYE0iXl--K6fBAAAA3E"]
[Sun Aug 30 03:12:16.974698 2026] [authz_core:error] [pid 521505:tid 521640] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory31
[Sun Aug 30 03:12:16.974969 2026] [authz_core:error] [pid 521505:tid 521640] [client 74.7.227.8:46326] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory31
[Sun Aug 30 03:12:16.983332 2026] [security2:error] [pid 524122:tid 524283] [client 185.191.171.8:49276] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "getabikini.com"] [uri "/robots.txt"] [unique_id "apPl4H3lhEjKFiK_nBKBuwAAAa0"]
[Sun Aug 30 03:12:16.983398 2026] [security2:error] [pid 524122:tid 524283] [client 185.191.171.8:49276] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "getabikini.com"] [uri "/robots.txt"] [unique_id "apPl4H3lhEjKFiK_nBKBuwAAAa0"]
[Sun Aug 30 03:12:17.048430 2026] [security2:error] [pid 521505:tid 521644] [client 20.220.10.235:38735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/is.php"] [unique_id "apPl4W8byYE0iXl--K6fBgAAAyc"]
[Sun Aug 30 03:12:17.098163 2026] [security2:error] [pid 521505:tid 521747] [client 20.48.160.90:50462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/xcc.php"] [unique_id "apPl4W8byYE0iXl--K6fCAAAA44"]
[Sun Aug 30 03:12:17.101434 2026] [security2:error] [pid 524122:tid 524292] [client 20.48.160.90:61646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/alfanew.php"] [unique_id "apPl4X3lhEjKFiK_nBKBvgAAAbY"]
[Sun Aug 30 03:12:17.132664 2026] [authz_core:error] [pid 521505:tid 521741] [client 66.249.66.66:55830] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:17.132935 2026] [authz_core:error] [pid 521505:tid 521741] [client 66.249.66.66:55830] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:17.162159 2026] [authz_core:error] [pid 521505:tid 521743] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:17.162441 2026] [authz_core:error] [pid 521505:tid 521743] [client 74.7.243.204:37940] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:17.184445 2026] [security2:error] [pid 521505:tid 521710] [client 85.208.96.205:50118] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "getabikini.com"] [uri "/photos/hooters/courtney-college-bikini-chick/"] [unique_id "apPl4W8byYE0iXl--K6fDQAAA2k"]
[Sun Aug 30 03:12:17.184548 2026] [security2:error] [pid 521505:tid 521710] [client 85.208.96.205:50118] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "getabikini.com"] [uri "/photos/hooters/courtney-college-bikini-chick/"] [unique_id "apPl4W8byYE0iXl--K6fDQAAA2k"]
[Sun Aug 30 03:12:17.191097 2026] [security2:error] [pid 521505:tid 521728] [client 20.220.10.235:38757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/od.php"] [unique_id "apPl4W8byYE0iXl--K6fDgAAA3s"]
[Sun Aug 30 03:12:17.191417 2026] [security2:error] [pid 521505:tid 521658] [client 20.104.18.15:22418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPl4W8byYE0iXl--K6fDwAAAzU"]
[Sun Aug 30 03:12:17.228166 2026] [security2:error] [pid 521505:tid 521671] [client 20.48.160.90:51776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/ioxi.php"] [unique_id "apPl4W8byYE0iXl--K6fEQAAA0I"]
[Sun Aug 30 03:12:17.239930 2026] [security2:error] [pid 521505:tid 521681] [client 20.48.160.90:50488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp-includes/Text/Diff/Engine/aaa.php"] [unique_id "apPl4W8byYE0iXl--K6fEwAAA0w"]
[Sun Aug 30 03:12:17.298905 2026] [security2:error] [pid 521505:tid 521638] [client 20.104.50.220:42466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/skizoo.php"] [unique_id "apPl4W8byYE0iXl--K6fFQAAAyE"]
[Sun Aug 30 03:12:17.316905 2026] [security2:error] [pid 524122:tid 524365] [client 20.104.50.220:16724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/elf.php"] [unique_id "apPl4X3lhEjKFiK_nBKBwAAAAf8"]
[Sun Aug 30 03:12:17.323633 2026] [security2:error] [pid 524122:tid 524357] [client 20.220.10.235:38722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/wp-the.php"] [unique_id "apPl4X3lhEjKFiK_nBKBwQAAAfc"]
[Sun Aug 30 03:12:17.327257 2026] [security2:error] [pid 521505:tid 521692] [client 158.23.147.79:21446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apPl4W8byYE0iXl--K6fFgAAA1c"]
[Sun Aug 30 03:12:17.340773 2026] [security2:error] [pid 521505:tid 521700] [client 4.205.62.107:17681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/nw.php"] [unique_id "apPl4W8byYE0iXl--K6fFwAAA18"]
[Sun Aug 30 03:12:17.348926 2026] [authz_core:error] [pid 521505:tid 521641] [client 216.73.216.128:59844] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:17.349205 2026] [authz_core:error] [pid 521505:tid 521641] [client 216.73.216.128:59844] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:17.360584 2026] [security2:error] [pid 524122:tid 524326] [client 20.151.200.44:44954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/wp-the.php"] [unique_id "apPl4X3lhEjKFiK_nBKBwgAAAdg"]
[Sun Aug 30 03:12:17.373275 2026] [security2:error] [pid 524122:tid 524266] [client 20.104.18.15:1990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/504.php"] [unique_id "apPl4X3lhEjKFiK_nBKBxAAAAZw"]
[Sun Aug 30 03:12:17.373370 2026] [security2:error] [pid 524122:tid 524336] [client 20.48.160.90:37765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/TNT.php"] [unique_id "apPl4X3lhEjKFiK_nBKBwwAAAeI"]
[Sun Aug 30 03:12:17.383686 2026] [security2:error] [pid 521505:tid 521746] [client 35.247.242.193:55974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/phpinfo.php.bak"] [unique_id "apPl4W8byYE0iXl--K6fGgAAA40"]
[Sun Aug 30 03:12:17.390218 2026] [security2:error] [pid 524122:tid 524367] [client 20.48.160.90:45397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp-includes/style-engine/gecko-new.php"] [unique_id "apPl4X3lhEjKFiK_nBKBxQAAAgE"]
[Sun Aug 30 03:12:17.447158 2026] [security2:error] [pid 521505:tid 521694] [client 20.104.18.15:51191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/ano.php"] [unique_id "apPl4W8byYE0iXl--K6fIAAAA1k"]
[Sun Aug 30 03:12:17.466082 2026] [security2:error] [pid 521505:tid 521691] [client 20.220.10.235:38684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/wt.php"] [unique_id "apPl4W8byYE0iXl--K6fIQAAA1Y"]
[Sun Aug 30 03:12:17.475713 2026] [security2:error] [pid 521505:tid 521721] [client 20.151.200.44:63656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/ca.php"] [unique_id "apPl4W8byYE0iXl--K6fIgAAA3Q"]
[Sun Aug 30 03:12:17.487954 2026] [security2:error] [pid 521505:tid 521705] [client 20.104.50.220:32874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/min.php"] [unique_id "apPl4W8byYE0iXl--K6fJAAAA2Q"]
[Sun Aug 30 03:12:17.491274 2026] [security2:error] [pid 521505:tid 521669] [client 195.178.110.247:4366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mizuforhair.com"] [uri "/index.php"] [unique_id "apPl4W8byYE0iXl--K6fJQAAA0A"]
[Sun Aug 30 03:12:17.496729 2026] [security2:error] [pid 521505:tid 521637] [client 20.48.251.3:59878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/nw.php"] [unique_id "apPl4W8byYE0iXl--K6fJwAAAyA"]
[Sun Aug 30 03:12:17.523267 2026] [security2:error] [pid 521505:tid 521668] [client 20.48.160.90:37853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/cd.php"] [unique_id "apPl4W8byYE0iXl--K6fKAAAAz8"]
[Sun Aug 30 03:12:17.526337 2026] [security2:error] [pid 521505:tid 521738] [client 20.48.160.90:50524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp-settings.php"] [unique_id "apPl4W8byYE0iXl--K6fKgAAA4U"]
[Sun Aug 30 03:12:17.543281 2026] [authz_core:error] [pid 521505:tid 521701] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory33
[Sun Aug 30 03:12:17.543546 2026] [authz_core:error] [pid 521505:tid 521701] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory33
[Sun Aug 30 03:12:17.546502 2026] [security2:error] [pid 521505:tid 521690] [client 34.15.159.88:44804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/phpinfo.php.bak"] [unique_id "apPl4W8byYE0iXl--K6fLAAAA1U"]
[Sun Aug 30 03:12:17.556304 2026] [authz_core:error] [pid 521505:tid 521754] [client 66.249.66.41:63669] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:17.556565 2026] [authz_core:error] [pid 521505:tid 521754] [client 66.249.66.41:63669] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:17.570725 2026] [security2:error] [pid 521505:tid 521687] [client 20.104.18.15:64723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/xmini4.php"] [unique_id "apPl4W8byYE0iXl--K6fLwAAA1I"]
[Sun Aug 30 03:12:17.570743 2026] [security2:error] [pid 521505:tid 521707] [client 20.104.50.220:25445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/25d653587fdfd1.php"] [unique_id "apPl4W8byYE0iXl--K6fMAAAA2Y"]
[Sun Aug 30 03:12:17.596704 2026] [security2:error] [pid 521505:tid 521636] [client 20.220.10.235:38750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/im.php"] [unique_id "apPl4W8byYE0iXl--K6fNQAAAx8"]
[Sun Aug 30 03:12:17.596812 2026] [security2:error] [pid 521505:tid 521688] [client 4.205.62.107:16377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/php-details.php"] [unique_id "apPl4W8byYE0iXl--K6fNgAAA1M"]
[Sun Aug 30 03:12:17.620050 2026] [security2:error] [pid 524122:tid 524312] [client 20.48.251.3:52756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/wdf.php"] [unique_id "apPl4X3lhEjKFiK_nBKBxwAAAco"]
[Sun Aug 30 03:12:17.642593 2026] [security2:error] [pid 521505:tid 521714] [client 4.205.62.107:15940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/public/bnn_.php.php"] [unique_id "apPl4W8byYE0iXl--K6fOgAAA20"]
[Sun Aug 30 03:12:17.653205 2026] [security2:error] [pid 521505:tid 521639] [client 195.178.110.247:31344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mizuforhair.com"] [uri "/index.php"] [unique_id "apPl4W8byYE0iXl--K6fOwAAAyI"]
[Sun Aug 30 03:12:17.657072 2026] [security2:error] [pid 524122:tid 524356] [client 20.48.251.3:64305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/zaza.php"] [unique_id "apPl4X3lhEjKFiK_nBKByAAAAfY"]
[Sun Aug 30 03:12:17.661537 2026] [security2:error] [pid 524122:tid 524341] [client 20.48.160.90:61681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/luuf.php"] [unique_id "apPl4X3lhEjKFiK_nBKByQAAAec"]
[Sun Aug 30 03:12:17.663457 2026] [security2:error] [pid 521505:tid 521734] [client 20.48.160.90:50552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp-signup.php"] [unique_id "apPl4W8byYE0iXl--K6fPAAAA4E"]
[Sun Aug 30 03:12:17.711321 2026] [security2:error] [pid 521505:tid 521702] [client 20.104.50.220:52814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-admin/maint/mailer.php.php"] [unique_id "apPl4W8byYE0iXl--K6fPwAAA2E"]
[Sun Aug 30 03:12:17.723119 2026] [security2:error] [pid 521505:tid 521747] [client 20.104.50.220:31529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/x50.php"] [unique_id "apPl4W8byYE0iXl--K6fQAAAA44"]
[Sun Aug 30 03:12:17.726041 2026] [security2:error] [pid 521505:tid 521740] [client 20.220.10.235:38663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/file.php"] [unique_id "apPl4W8byYE0iXl--K6fQQAAA4c"]
[Sun Aug 30 03:12:17.744284 2026] [authz_core:error] [pid 521505:tid 521729] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:17.744599 2026] [authz_core:error] [pid 521505:tid 521729] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:17.750270 2026] [security2:error] [pid 521505:tid 521751] [client 20.48.251.3:36818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/wp-konfig.php"] [unique_id "apPl4W8byYE0iXl--K6fQwAAA5I"]
[Sun Aug 30 03:12:17.762999 2026] [security2:error] [pid 521505:tid 521720] [client 20.151.200.44:26510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/cy.php"] [unique_id "apPl4W8byYE0iXl--K6fRAAAA3M"]
[Sun Aug 30 03:12:17.791569 2026] [security2:error] [pid 524122:tid 524366] [client 20.48.160.90:50512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp-conffg.php"] [unique_id "apPl4X3lhEjKFiK_nBKBywAAAgA"]
[Sun Aug 30 03:12:17.791602 2026] [security2:error] [pid 524122:tid 524378] [client 20.48.160.90:37854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/fex.php"] [unique_id "apPl4X3lhEjKFiK_nBKBygAAAgw"]
[Sun Aug 30 03:12:17.793508 2026] [security2:error] [pid 521505:tid 521728] [client 4.205.62.107:52898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/application.config.php"] [unique_id "apPl4W8byYE0iXl--K6fRQAAA3s"]
[Sun Aug 30 03:12:17.855565 2026] [security2:error] [pid 524122:tid 524308] [client 20.220.10.235:38672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/ca.php"] [unique_id "apPl4X3lhEjKFiK_nBKBzQAAAcY"]
[Sun Aug 30 03:12:17.875669 2026] [security2:error] [pid 524122:tid 524278] [client 20.104.49.130:60104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/bolt.php"] [unique_id "apPl4X3lhEjKFiK_nBKBzwAAAag"]
[Sun Aug 30 03:12:17.881270 2026] [security2:error] [pid 521505:tid 521733] [client 35.247.242.193:55976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/phpinfo.php.old"] [unique_id "apPl4W8byYE0iXl--K6fSgAAA4A"]
[Sun Aug 30 03:12:17.888996 2026] [security2:error] [pid 524122:tid 524351] [client 20.151.200.44:62945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/pb.php"] [unique_id "apPl4X3lhEjKFiK_nBKB0QAAAfE"]
[Sun Aug 30 03:12:17.925296 2026] [security2:error] [pid 521505:tid 521737] [client 20.104.49.130:48373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/dk.php"] [unique_id "apPl4W8byYE0iXl--K6fTAAAA4Q"]
[Sun Aug 30 03:12:17.927132 2026] [security2:error] [pid 521505:tid 521761] [client 20.48.160.90:37779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/l.php"] [unique_id "apPl4W8byYE0iXl--K6fTQAAA5w"]
[Sun Aug 30 03:12:17.927635 2026] [security2:error] [pid 524122:tid 524284] [client 20.48.160.90:45430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp-validate.php"] [unique_id "apPl4X3lhEjKFiK_nBKB0gAAAa4"]
[Sun Aug 30 03:12:17.929819 2026] [security2:error] [pid 524122:tid 524264] [client 20.104.50.220:5623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/65.php"] [unique_id "apPl4X3lhEjKFiK_nBKB0wAAAZo"]
[Sun Aug 30 03:12:17.961503 2026] [security2:error] [pid 524122:tid 524325] [client 4.205.62.107:25733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/pass4.php"] [unique_id "apPl4X3lhEjKFiK_nBKB1AAAAdc"]
[Sun Aug 30 03:12:17.963628 2026] [authz_core:error] [pid 521505:tid 521692] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory26
[Sun Aug 30 03:12:17.963915 2026] [authz_core:error] [pid 521505:tid 521692] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory26
[Sun Aug 30 03:12:17.965232 2026] [security2:error] [pid 521505:tid 521700] [client 158.23.147.79:58420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wzy.php"] [unique_id "apPl4W8byYE0iXl--K6fUAAAA18"]
[Sun Aug 30 03:12:17.965691 2026] [security2:error] [pid 521505:tid 521745] [client 20.104.50.220:61680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/abcd.php"] [unique_id "apPl4W8byYE0iXl--K6fUQAAA4w"]
[Sun Aug 30 03:12:17.991692 2026] [security2:error] [pid 521505:tid 521698] [client 20.220.10.235:38699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/pb.php"] [unique_id "apPl4W8byYE0iXl--K6fUwAAA10"]
[Sun Aug 30 03:12:18.008516 2026] [security2:error] [pid 521505:tid 521724] [client 20.104.18.15:18334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/wp-includes/ID3/moon.php"] [unique_id "apPl4m8byYE0iXl--K6fVAAAA3c"]
[Sun Aug 30 03:12:18.031692 2026] [security2:error] [pid 521505:tid 521699] [client 20.104.50.220:29371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/0x1337.php"] [unique_id "apPl4m8byYE0iXl--K6fVwAAA14"]
[Sun Aug 30 03:12:18.046067 2026] [security2:error] [pid 521505:tid 521706] [client 20.151.200.44:45048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/wt.php"] [unique_id "apPl4m8byYE0iXl--K6fWAAAA2U"]
[Sun Aug 30 03:12:18.058812 2026] [security2:error] [pid 524122:tid 524354] [client 20.48.160.90:50530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/700.php"] [unique_id "apPl4n3lhEjKFiK_nBKB1gAAAfQ"]
[Sun Aug 30 03:12:18.058940 2026] [security2:error] [pid 524122:tid 524260] [client 20.48.160.90:61610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/xr.php"] [unique_id "apPl4n3lhEjKFiK_nBKB1QAAAZY"]
[Sun Aug 30 03:12:18.078182 2026] [authz_core:error] [pid 521505:tid 521748] [client 216.73.216.128:59844] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:18.078503 2026] [authz_core:error] [pid 521505:tid 521748] [client 216.73.216.128:59844] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:18.104930 2026] [core:alert] [pid 521505:tid 521721] [client 201.4.68.242:57598] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://www.hiagtourism.org/
[Sun Aug 30 03:12:18.115627 2026] [authz_core:error] [pid 521505:tid 521753] [client 66.249.66.69:52763] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:18.115896 2026] [authz_core:error] [pid 521505:tid 521753] [client 66.249.66.69:52763] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:18.121311 2026] [security2:error] [pid 521505:tid 521722] [client 20.220.10.235:38766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/pk.php"] [unique_id "apPl4m8byYE0iXl--K6fXQAAA3U"]
[Sun Aug 30 03:12:18.153987 2026] [security2:error] [pid 524122:tid 524271] [client 34.15.159.88:44808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/phpinfo.php.old"] [unique_id "apPl4n3lhEjKFiK_nBKB1wAAAaE"]
[Sun Aug 30 03:12:18.189714 2026] [security2:error] [pid 521505:tid 521655] [client 20.151.200.44:63037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/pk.php"] [unique_id "apPl4m8byYE0iXl--K6fYAAAAzI"]
[Sun Aug 30 03:12:18.191360 2026] [security2:error] [pid 521505:tid 521659] [client 20.48.160.90:50447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/c4.php"] [unique_id "apPl4m8byYE0iXl--K6fYQAAAzY"]
[Sun Aug 30 03:12:18.195151 2026] [security2:error] [pid 521505:tid 521668] [client 20.48.160.90:61660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/Q3.php"] [unique_id "apPl4m8byYE0iXl--K6fYgAAAz8"]
[Sun Aug 30 03:12:18.248460 2026] [security2:error] [pid 521505:tid 521757] [client 20.151.200.44:43918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ermes-it.it"] [uri "/4e.php"] [unique_id "apPl4m8byYE0iXl--K6fYwAAA5g"]
[Sun Aug 30 03:12:18.254989 2026] [security2:error] [pid 521505:tid 521690] [client 20.220.10.235:38656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/ft.php"] [unique_id "apPl4m8byYE0iXl--K6fZAAAA1U"]
[Sun Aug 30 03:12:18.289118 2026] [security2:error] [pid 521505:tid 521703] [client 158.23.147.79:39945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/themes.php"] [unique_id "apPl4m8byYE0iXl--K6fZQAAA2I"]
[Sun Aug 30 03:12:18.322579 2026] [security2:error] [pid 521505:tid 521730] [client 20.48.160.90:50520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp-tymanage.php"] [unique_id "apPl4m8byYE0iXl--K6fZgAAA30"]
[Sun Aug 30 03:12:18.325329 2026] [security2:error] [pid 521505:tid 521739] [client 20.48.160.90:37860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/Q1.php"] [unique_id "apPl4m8byYE0iXl--K6fZwAAA4Y"]
[Sun Aug 30 03:12:18.333886 2026] [security2:error] [pid 521505:tid 521636] [client 20.104.18.15:22406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPl4m8byYE0iXl--K6faQAAAx8"]
[Sun Aug 30 03:12:18.364778 2026] [security2:error] [pid 521505:tid 521738] [client 35.247.242.193:55978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/phpinfo.php~"] [unique_id "apPl4m8byYE0iXl--K6fbAAAA4U"]
[Sun Aug 30 03:12:18.381582 2026] [security2:error] [pid 524122:tid 524310] [client 20.220.10.235:38632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/wp-ver.php"] [unique_id "apPl4n3lhEjKFiK_nBKB2QAAAcg"]
[Sun Aug 30 03:12:18.390959 2026] [security2:error] [pid 521505:tid 521660] [client 20.151.200.44:26516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/admin.php/pindex.php"] [unique_id "apPl4m8byYE0iXl--K6fbQAAAzc"]
[Sun Aug 30 03:12:18.456141 2026] [security2:error] [pid 521505:tid 521642] [client 20.104.50.220:16612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/cyr6l.php"] [unique_id "apPl4m8byYE0iXl--K6fcwAAAyU"]
[Sun Aug 30 03:12:18.460357 2026] [security2:error] [pid 521505:tid 521740] [client 20.48.160.90:37863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/nz.php"] [unique_id "apPl4m8byYE0iXl--K6fdAAAA4c"]
[Sun Aug 30 03:12:18.462938 2026] [authz_core:error] [pid 521505:tid 521640] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory17
[Sun Aug 30 03:12:18.463208 2026] [authz_core:error] [pid 521505:tid 521640] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory17
[Sun Aug 30 03:12:18.469192 2026] [security2:error] [pid 521505:tid 521704] [client 20.104.50.220:63528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wsmini.php"] [unique_id "apPl4m8byYE0iXl--K6fdQAAA2M"]
[Sun Aug 30 03:12:18.471685 2026] [security2:error] [pid 521505:tid 521751] [client 20.48.160.90:50494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/ajfto.php"] [unique_id "apPl4m8byYE0iXl--K6fdgAAA5I"]
[Sun Aug 30 03:12:18.478669 2026] [security2:error] [pid 521505:tid 521695] [client 4.205.62.107:17334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/product.php"] [unique_id "apPl4m8byYE0iXl--K6fdwAAA1o"]
[Sun Aug 30 03:12:18.512452 2026] [security2:error] [pid 521505:tid 521697] [client 20.104.18.15:1938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/ano.php"] [unique_id "apPl4m8byYE0iXl--K6feAAAA1w"]
[Sun Aug 30 03:12:18.516313 2026] [security2:error] [pid 521505:tid 521710] [client 20.220.10.235:38675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/ah24.php"] [unique_id "apPl4m8byYE0iXl--K6feQAAA2k"]
[Sun Aug 30 03:12:18.542244 2026] [security2:error] [pid 524122:tid 524358] [client 20.151.200.44:23586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/ft.php"] [unique_id "apPl4n3lhEjKFiK_nBKB3QAAAfg"]
[Sun Aug 30 03:12:18.599638 2026] [security2:error] [pid 524122:tid 524287] [client 20.48.160.90:50540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp_KwIW0U5F.php"] [unique_id "apPl4n3lhEjKFiK_nBKB3gAAAbE"]
[Sun Aug 30 03:12:18.601023 2026] [security2:error] [pid 524122:tid 524277] [client 20.104.18.15:51184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/mgrr.php"] [unique_id "apPl4n3lhEjKFiK_nBKB3wAAAac"]
[Sun Aug 30 03:12:18.605559 2026] [security2:error] [pid 521505:tid 521696] [client 20.48.160.90:37883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/sg.php"] [unique_id "apPl4m8byYE0iXl--K6ffwAAA1s"]
[Sun Aug 30 03:12:18.608337 2026] [authz_core:error] [pid 524122:tid 524334] [client 66.249.66.195:45885] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:18.608596 2026] [authz_core:error] [pid 524122:tid 524334] [client 66.249.66.195:45885] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:18.655890 2026] [security2:error] [pid 521505:tid 521761] [client 20.104.50.220:33043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/wp-backup-sql-302.php"] [unique_id "apPl4m8byYE0iXl--K6fhAAAA5w"]
[Sun Aug 30 03:12:18.657608 2026] [security2:error] [pid 521505:tid 521723] [client 44.198.100.35:46136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.100.198.44.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "orthochristiantools.com"] [uri "/wp-login.php"] [unique_id "apPl4m8byYE0iXl--K6fggAAA3Y"]
[Sun Aug 30 03:12:18.661029 2026] [security2:error] [pid 521505:tid 521635] [client 20.48.251.3:52269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/product.php"] [unique_id "apPl4m8byYE0iXl--K6fhQAAAx4"]
[Sun Aug 30 03:12:18.683275 2026] [security2:error] [pid 521505:tid 521700] [client 20.220.10.235:38737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPl4m8byYE0iXl--K6fhgAAA18"]
[Sun Aug 30 03:12:18.707493 2026] [security2:error] [pid 521505:tid 521746] [client 20.104.18.15:20429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/gulu.php"] [unique_id "apPl4m8byYE0iXl--K6fhwAAA40"]
[Sun Aug 30 03:12:18.710328 2026] [security2:error] [pid 521505:tid 521645] [client 20.104.50.220:25411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/wefile.php"] [unique_id "apPl4m8byYE0iXl--K6fiQAAAyg"]
[Sun Aug 30 03:12:18.726777 2026] [security2:error] [pid 521505:tid 521699] [client 20.48.160.90:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp_xiPu52Ut.php"] [unique_id "apPl4m8byYE0iXl--K6figAAA14"]
[Sun Aug 30 03:12:18.732494 2026] [security2:error] [pid 521505:tid 521755] [client 20.48.160.90:37867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/hypo.php"] [unique_id "apPl4m8byYE0iXl--K6fiwAAA5Y"]
[Sun Aug 30 03:12:18.753368 2026] [security2:error] [pid 521505:tid 521657] [client 34.15.159.88:44818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/phpinfo.php~"] [unique_id "apPl4m8byYE0iXl--K6fjAAAAzQ"]
[Sun Aug 30 03:12:18.756292 2026] [security2:error] [pid 521505:tid 521650] [client 4.205.62.107:15518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/routes.php"] [unique_id "apPl4m8byYE0iXl--K6fjQAAAy0"]
[Sun Aug 30 03:12:18.768502 2026] [security2:error] [pid 521505:tid 521726] [client 20.48.251.3:52743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/bb.php"] [unique_id "apPl4m8byYE0iXl--K6fjgAAA3k"]
[Sun Aug 30 03:12:18.801465 2026] [security2:error] [pid 521505:tid 521689] [client 4.205.62.107:16355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/wsws.php"] [unique_id "apPl4m8byYE0iXl--K6fjwAAA1Q"]
[Sun Aug 30 03:12:18.802031 2026] [security2:error] [pid 521505:tid 521713] [client 20.48.251.3:43212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/u88.php"] [unique_id "apPl4m8byYE0iXl--K6fkAAAA2w"]
[Sun Aug 30 03:12:18.811636 2026] [security2:error] [pid 521505:tid 521722] [client 20.220.10.235:38733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.zoohaus.com"] [uri "/waf.php"] [unique_id "apPl4m8byYE0iXl--K6fkQAAA3U"]
[Sun Aug 30 03:12:18.841339 2026] [security2:error] [pid 521505:tid 521669] [client 20.104.49.130:53540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/cilus.php"] [unique_id "apPl4m8byYE0iXl--K6flAAAA0A"]
[Sun Aug 30 03:12:18.848046 2026] [security2:error] [pid 524122:tid 524258] [client 35.247.242.193:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/info.php.bak"] [unique_id "apPl4n3lhEjKFiK_nBKB4wAAAZQ"]
[Sun Aug 30 03:12:18.861325 2026] [security2:error] [pid 524122:tid 524335] [client 20.48.160.90:50454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp_n5VD7XDh.php"] [unique_id "apPl4n3lhEjKFiK_nBKB5AAAAeE"]
[Sun Aug 30 03:12:18.865925 2026] [security2:error] [pid 521505:tid 521672] [client 20.48.160.90:37844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/Hd.php"] [unique_id "apPl4m8byYE0iXl--K6flQAAA0M"]
[Sun Aug 30 03:12:18.877270 2026] [security2:error] [pid 521505:tid 521668] [client 20.104.50.220:59365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/fv.php"] [unique_id "apPl4m8byYE0iXl--K6flgAAAz8"]
[Sun Aug 30 03:12:18.895459 2026] [security2:error] [pid 521505:tid 521712] [client 20.104.50.220:28708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-admin/css/mailer.php.php"] [unique_id "apPl4m8byYE0iXl--K6fmAAAA2s"]
[Sun Aug 30 03:12:18.899710 2026] [security2:error] [pid 524122:tid 524274] [client 20.151.200.44:23600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/wp-ver.php"] [unique_id "apPl4n3lhEjKFiK_nBKB5gAAAaQ"]
[Sun Aug 30 03:12:18.912328 2026] [security2:error] [pid 521505:tid 521708] [client 20.48.251.3:37178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/25.php"] [unique_id "apPl4m8byYE0iXl--K6fmQAAA2c"]
[Sun Aug 30 03:12:18.937434 2026] [security2:error] [pid 524122:tid 524329] [client 20.104.49.130:63268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/bthil.php"] [unique_id "apPl4n3lhEjKFiK_nBKB5wAAAds"]
[Sun Aug 30 03:12:18.980985 2026] [security2:error] [pid 521505:tid 521687] [client 4.205.62.107:28678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/xp.php"] [unique_id "apPl4m8byYE0iXl--K6fmgAAA1I"]
[Sun Aug 30 03:12:18.982532 2026] [security2:error] [pid 521505:tid 521707] [client 216.73.216.128:52277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/sasl/developer/testing.html"] [unique_id "apPl4m8byYE0iXl--K6fmwAAA2Y"]
[Sun Aug 30 03:12:18.988181 2026] [security2:error] [pid 521505:tid 521739] [client 20.48.160.90:50485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp-mini.php"] [unique_id "apPl4m8byYE0iXl--K6fngAAA4Y"]
[Sun Aug 30 03:12:18.990357 2026] [authz_core:error] [pid 521505:tid 521730] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory19
[Sun Aug 30 03:12:18.990604 2026] [authz_core:error] [pid 521505:tid 521730] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory19
[Sun Aug 30 03:12:18.995437 2026] [security2:error] [pid 524122:tid 524255] [client 20.48.160.90:37760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/im.php"] [unique_id "apPl4n3lhEjKFiK_nBKB6AAAAZE"]
[Sun Aug 30 03:12:19.027379 2026] [authz_core:error] [pid 521505:tid 521709] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:19.027624 2026] [authz_core:error] [pid 521505:tid 521709] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:19.050007 2026] [security2:error] [pid 521505:tid 521742] [client 158.23.147.79:39970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-mail.php"] [unique_id "apPl428byYE0iXl--K6foAAAA4k"]
[Sun Aug 30 03:12:19.056165 2026] [authz_core:error] [pid 521505:tid 521714] [client 66.249.66.66:37140] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:19.056421 2026] [authz_core:error] [pid 521505:tid 521714] [client 66.249.66.66:37140] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:19.075524 2026] [security2:error] [pid 524122:tid 524306] [client 20.151.200.44:26622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/admin.php/csv.php"] [unique_id "apPl433lhEjKFiK_nBKB7AAAAcQ"]
[Sun Aug 30 03:12:19.090094 2026] [security2:error] [pid 521505:tid 521647] [client 20.104.50.220:5544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/64.php"] [unique_id "apPl428byYE0iXl--K6fpAAAAyo"]
[Sun Aug 30 03:12:19.119208 2026] [security2:error] [pid 521505:tid 521716] [client 20.48.160.90:40256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/xmini4.php"] [unique_id "apPl428byYE0iXl--K6fpwAAA28"]
[Sun Aug 30 03:12:19.119481 2026] [security2:error] [pid 521505:tid 521666] [client 20.104.50.220:61994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/lock360.php"] [unique_id "apPl428byYE0iXl--K6fqAAAAz0"]
[Sun Aug 30 03:12:19.121093 2026] [security2:error] [pid 521505:tid 521701] [client 158.23.147.79:58431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-admin/setup-config.php"] [unique_id "apPl428byYE0iXl--K6fqQAAA2A"]
[Sun Aug 30 03:12:19.125299 2026] [security2:error] [pid 521505:tid 521747] [client 20.48.160.90:61606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/fc.php"] [unique_id "apPl428byYE0iXl--K6fqgAAA44"]
[Sun Aug 30 03:12:19.128261 2026] [security2:error] [pid 521505:tid 521642] [client 4.205.62.107:27006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/cu.php"] [unique_id "apPl428byYE0iXl--K6fqwAAAyU"]
[Sun Aug 30 03:12:19.145684 2026] [security2:error] [pid 521505:tid 521704] [client 20.104.18.15:18364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/xmini4.php"] [unique_id "apPl428byYE0iXl--K6frAAAA2M"]
[Sun Aug 30 03:12:19.202204 2026] [security2:error] [pid 521505:tid 521664] [client 20.104.49.130:53778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/forum.php"] [unique_id "apPl428byYE0iXl--K6frwAAAzs"]
[Sun Aug 30 03:12:19.211263 2026] [security2:error] [pid 524122:tid 524272] [client 20.104.50.220:28723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/xltavrat.php"] [unique_id "apPl433lhEjKFiK_nBKB7wAAAaI"]
[Sun Aug 30 03:12:19.250445 2026] [security2:error] [pid 524122:tid 524369] [client 20.48.160.90:50475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/reop3.php"] [unique_id "apPl433lhEjKFiK_nBKB8gAAAgM"]
[Sun Aug 30 03:12:19.255402 2026] [security2:error] [pid 524122:tid 524324] [client 216.73.216.128:60133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/keywords.html"] [unique_id "apPl433lhEjKFiK_nBKB9AAAAdY"]
[Sun Aug 30 03:12:19.255562 2026] [security2:error] [pid 524122:tid 524279] [client 20.48.160.90:37847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/ke.php"] [unique_id "apPl433lhEjKFiK_nBKB9QAAAak"]
[Sun Aug 30 03:12:19.257263 2026] [security2:error] [pid 524122:tid 524288] [client 20.151.200.44:23601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/ah24.php"] [unique_id "apPl433lhEjKFiK_nBKB9gAAAbI"]
[Sun Aug 30 03:12:19.333415 2026] [security2:error] [pid 524122:tid 524355] [client 35.247.242.193:56000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/phpinfo.php.save"] [unique_id "apPl433lhEjKFiK_nBKB-AAAAfU"]
[Sun Aug 30 03:12:19.358961 2026] [security2:error] [pid 521505:tid 521674] [client 20.104.49.130:63608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wdfjba.org"] [uri "/media.php"] [unique_id "apPl428byYE0iXl--K6ftQAAA0U"]
[Sun Aug 30 03:12:19.363604 2026] [security2:error] [pid 521505:tid 521695] [client 34.15.159.88:44834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/info.php.bak"] [unique_id "apPl428byYE0iXl--K6ftgAAA1o"]
[Sun Aug 30 03:12:19.386182 2026] [security2:error] [pid 521505:tid 521635] [client 20.48.160.90:51722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/tf.php"] [unique_id "apPl428byYE0iXl--K6fuwAAAx4"]
[Sun Aug 30 03:12:19.388538 2026] [security2:error] [pid 521505:tid 521658] [client 20.48.160.90:45332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp-mail.php"] [unique_id "apPl428byYE0iXl--K6fvAAAAzU"]
[Sun Aug 30 03:12:19.438362 2026] [security2:error] [pid 521505:tid 521732] [client 20.151.200.44:63003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPl428byYE0iXl--K6fvgAAA38"]
[Sun Aug 30 03:12:19.478603 2026] [authz_core:error] [pid 521505:tid 521645] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory13
[Sun Aug 30 03:12:19.479017 2026] [authz_core:error] [pid 521505:tid 521645] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory13
[Sun Aug 30 03:12:19.484442 2026] [security2:error] [pid 521505:tid 521711] [client 20.104.18.15:22492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/wsd.php"] [unique_id "apPl428byYE0iXl--K6fwQAAA2o"]
[Sun Aug 30 03:12:19.501543 2026] [security2:error] [pid 521505:tid 521638] [client 20.151.200.44:44995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/im.php"] [unique_id "apPl428byYE0iXl--K6fwwAAAyE"]
[Sun Aug 30 03:12:19.526923 2026] [security2:error] [pid 521505:tid 521706] [client 20.48.160.90:45414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp-conffg.php"] [unique_id "apPl428byYE0iXl--K6fxAAAA2U"]
[Sun Aug 30 03:12:19.540582 2026] [security2:error] [pid 524122:tid 524318] [client 20.48.160.90:61665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/px.php"] [unique_id "apPl433lhEjKFiK_nBKCAwAAAdA"]
[Sun Aug 30 03:12:19.557410 2026] [authz_core:error] [pid 521505:tid 521657] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:19.557757 2026] [authz_core:error] [pid 521505:tid 521657] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:19.558619 2026] [authz_core:error] [pid 521505:tid 521650] [client 66.249.66.203:62443] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:19.558878 2026] [authz_core:error] [pid 521505:tid 521650] [client 66.249.66.203:62443] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:19.568672 2026] [security2:error] [pid 521505:tid 521648] [client 20.151.200.44:63022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.handyautomation.com"] [uri "/waf.php"] [unique_id "apPl428byYE0iXl--K6fyAAAAys"]
[Sun Aug 30 03:12:19.594843 2026] [security2:error] [pid 521505:tid 521722] [client 20.104.50.220:16702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/51whn.php"] [unique_id "apPl428byYE0iXl--K6fywAAA3U"]
[Sun Aug 30 03:12:19.616429 2026] [security2:error] [pid 524122:tid 524254] [client 4.205.62.107:16812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/fun.php"] [unique_id "apPl433lhEjKFiK_nBKCBQAAAZA"]
[Sun Aug 30 03:12:19.633387 2026] [security2:error] [pid 521505:tid 521637] [client 20.104.50.220:56719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/86.php"] [unique_id "apPl428byYE0iXl--K6f0AAAAyA"]
[Sun Aug 30 03:12:19.644290 2026] [security2:error] [pid 521505:tid 521655] [client 20.151.200.44:43979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ermes-it.it"] [uri "/ssss.php"] [unique_id "apPl428byYE0iXl--K6f0QAAAzI"]
[Sun Aug 30 03:12:19.649036 2026] [security2:error] [pid 521505:tid 521659] [client 20.104.18.15:1937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/mac.php"] [unique_id "apPl428byYE0iXl--K6f0gAAAzY"]
[Sun Aug 30 03:12:19.652835 2026] [security2:error] [pid 521505:tid 521668] [client 20.151.200.44:26607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/admin.php/700.php"] [unique_id "apPl428byYE0iXl--K6f0wAAAz8"]
[Sun Aug 30 03:12:19.677762 2026] [security2:error] [pid 521505:tid 521692] [client 20.48.160.90:37784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/jg.php"] [unique_id "apPl428byYE0iXl--K6f1AAAA1c"]
[Sun Aug 30 03:12:19.681970 2026] [security2:error] [pid 524122:tid 524263] [client 20.48.160.90:50459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/filefuns.php"] [unique_id "apPl433lhEjKFiK_nBKCBgAAAZk"]
[Sun Aug 30 03:12:19.713972 2026] [security2:error] [pid 521505:tid 521729] [client 158.23.147.79:40012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/cgi-bin/index.php"] [unique_id "apPl428byYE0iXl--K6f1QAAA3w"]
[Sun Aug 30 03:12:19.715907 2026] [security2:error] [pid 521505:tid 521756] [client 216.73.216.128:59844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/usage_202601.html"] [unique_id "apPl428byYE0iXl--K6f1gAAA5c"]
[Sun Aug 30 03:12:19.737305 2026] [security2:error] [pid 524122:tid 524278] [client 20.104.49.130:63262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/xwx1.php"] [unique_id "apPl433lhEjKFiK_nBKCCAAAAag"]
[Sun Aug 30 03:12:19.771381 2026] [security2:error] [pid 521505:tid 521739] [client 20.104.18.15:51111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/mac.php"] [unique_id "apPl428byYE0iXl--K6f1wAAA4Y"]
[Sun Aug 30 03:12:19.782716 2026] [security2:error] [pid 521505:tid 521636] [client 20.151.200.44:46020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/dehnl.php"] [unique_id "apPl428byYE0iXl--K6f2AAAAx8"]
[Sun Aug 30 03:12:19.793817 2026] [security2:error] [pid 524122:tid 524351] [client 20.104.50.220:33040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/json-php.php"] [unique_id "apPl433lhEjKFiK_nBKCCQAAAfE"]
[Sun Aug 30 03:12:19.809635 2026] [security2:error] [pid 524122:tid 524343] [client 20.48.160.90:61642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/yj.php"] [unique_id "apPl433lhEjKFiK_nBKCCgAAAek"]
[Sun Aug 30 03:12:19.817723 2026] [security2:error] [pid 524122:tid 524340] [client 20.48.251.3:52254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/fun.php"] [unique_id "apPl433lhEjKFiK_nBKCCwAAAeY"]
[Sun Aug 30 03:12:19.819172 2026] [security2:error] [pid 521505:tid 521672] [client 35.247.242.193:56012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/staging/phpinfo.php"] [unique_id "apPl428byYE0iXl--K6f2gAAA0M"]
[Sun Aug 30 03:12:19.824963 2026] [authz_core:error] [pid 521505:tid 521703] [client 66.249.66.77:43082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:19.825234 2026] [authz_core:error] [pid 521505:tid 521703] [client 66.249.66.77:43082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:19.828080 2026] [security2:error] [pid 524122:tid 524284] [client 20.48.160.90:50516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp-cron.php"] [unique_id "apPl433lhEjKFiK_nBKCDAAAAa4"]
[Sun Aug 30 03:12:19.846705 2026] [security2:error] [pid 521505:tid 521738] [client 20.104.50.220:24877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "apPl428byYE0iXl--K6f2wAAA4U"]
[Sun Aug 30 03:12:19.874762 2026] [security2:error] [pid 521505:tid 521647] [client 20.104.18.15:16942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/replace.php"] [unique_id "apPl428byYE0iXl--K6f3QAAAyo"]
[Sun Aug 30 03:12:19.898385 2026] [security2:error] [pid 521505:tid 521716] [client 216.73.216.128:15601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPl428byYE0iXl--K6f3gAAA28"]
[Sun Aug 30 03:12:19.902199 2026] [security2:error] [pid 521505:tid 521666] [client 20.48.251.3:55774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/file59.php"] [unique_id "apPl428byYE0iXl--K6f3wAAAz0"]
[Sun Aug 30 03:12:19.903135 2026] [security2:error] [pid 524122:tid 524359] [client 4.205.62.107:15809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/aww.php"] [unique_id "apPl433lhEjKFiK_nBKCDgAAAfk"]
[Sun Aug 30 03:12:19.939339 2026] [security2:error] [pid 524122:tid 524260] [client 20.48.160.90:61645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/zi.php"] [unique_id "apPl433lhEjKFiK_nBKCDwAAAZY"]
[Sun Aug 30 03:12:19.940826 2026] [security2:error] [pid 524122:tid 524371] [client 20.48.251.3:46156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/config/laravolt/css/index.php"] [unique_id "apPl433lhEjKFiK_nBKCEAAAAgU"]
[Sun Aug 30 03:12:19.954724 2026] [security2:error] [pid 521505:tid 521704] [client 4.205.62.107:16348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/localconf.php"] [unique_id "apPl428byYE0iXl--K6f4AAAA2M"]
[Sun Aug 30 03:12:19.959594 2026] [security2:error] [pid 524122:tid 524285] [client 20.48.160.90:50437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/lock360.php"] [unique_id "apPl433lhEjKFiK_nBKCEQAAAa8"]
[Sun Aug 30 03:12:19.970469 2026] [security2:error] [pid 521505:tid 521687] [client 34.15.159.88:44842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/phpinfo.php.save"] [unique_id "apPl428byYE0iXl--K6f4QAAA1I"]
[Sun Aug 30 03:12:20.017259 2026] [authz_core:error] [pid 521505:tid 521728] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory10
[Sun Aug 30 03:12:20.017516 2026] [authz_core:error] [pid 521505:tid 521728] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory10
[Sun Aug 30 03:12:20.030244 2026] [security2:error] [pid 524122:tid 524310] [client 158.23.147.79:39974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPl5H3lhEjKFiK_nBKCEwAAAcg"]
[Sun Aug 30 03:12:20.036845 2026] [authz_core:error] [pid 521505:tid 521664] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:20.037094 2026] [authz_core:error] [pid 521505:tid 521664] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:20.049467 2026] [security2:error] [pid 524122:tid 524346] [client 20.104.50.220:29159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-includes/css/mailer.php.php"] [unique_id "apPl5H3lhEjKFiK_nBKCFgAAAew"]
[Sun Aug 30 03:12:20.049496 2026] [security2:error] [pid 524122:tid 524323] [client 20.104.50.220:31490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/file.php"] [unique_id "apPl5H3lhEjKFiK_nBKCFQAAAdU"]
[Sun Aug 30 03:12:20.070357 2026] [security2:error] [pid 521505:tid 521661] [client 20.48.251.3:36816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/nlnub.php"] [unique_id "apPl5G8byYE0iXl--K6f5AAAAzg"]
[Sun Aug 30 03:12:20.081207 2026] [security2:error] [pid 524122:tid 524349] [client 20.48.160.90:51723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/ue.php"] [unique_id "apPl5H3lhEjKFiK_nBKCGAAAAe8"]
[Sun Aug 30 03:12:20.088607 2026] [security2:error] [pid 524122:tid 524309] [client 20.48.160.90:45417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp-theme.php"] [unique_id "apPl5H3lhEjKFiK_nBKCGQAAAcc"]
[Sun Aug 30 03:12:20.119302 2026] [security2:error] [pid 521505:tid 521717] [client 4.205.62.107:29138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/g3.php"] [unique_id "apPl5G8byYE0iXl--K6f5gAAA3A"]
[Sun Aug 30 03:12:20.119669 2026] [authz_core:error] [pid 524122:tid 524358] [client 66.249.66.202:64464] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:20.119935 2026] [authz_core:error] [pid 524122:tid 524358] [client 66.249.66.202:64464] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:20.151845 2026] [security2:error] [pid 521505:tid 521753] [client 158.23.147.79:21467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-includes/content.php"] [unique_id "apPl5G8byYE0iXl--K6f5wAAA5Q"]
[Sun Aug 30 03:12:20.214318 2026] [security2:error] [pid 521505:tid 521720] [client 20.48.160.90:61574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/nv.php"] [unique_id "apPl5G8byYE0iXl--K6f6QAAA3M"]
[Sun Aug 30 03:12:20.226798 2026] [security2:error] [pid 521505:tid 521670] [client 20.104.50.220:5443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/63.php"] [unique_id "apPl5G8byYE0iXl--K6f6gAAA0E"]
[Sun Aug 30 03:12:20.232200 2026] [security2:error] [pid 524122:tid 524305] [client 20.48.160.90:50505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/2d7433/index.php"] [unique_id "apPl5H3lhEjKFiK_nBKCHAAAAcM"]
[Sun Aug 30 03:12:20.256596 2026] [security2:error] [pid 521505:tid 521744] [client 20.151.200.44:44948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/file.php"] [unique_id "apPl5G8byYE0iXl--K6f7QAAA4s"]
[Sun Aug 30 03:12:20.268282 2026] [security2:error] [pid 524122:tid 524253] [client 4.205.62.107:26981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/services.php"] [unique_id "apPl5H3lhEjKFiK_nBKCHQAAAY8"]
[Sun Aug 30 03:12:20.285622 2026] [security2:error] [pid 521505:tid 521635] [client 20.104.50.220:59579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/pp.php"] [unique_id "apPl5G8byYE0iXl--K6f7wAAAx4"]
[Sun Aug 30 03:12:20.302108 2026] [security2:error] [pid 521505:tid 521743] [client 35.247.242.193:56014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/beta/phpinfo.php"] [unique_id "apPl5G8byYE0iXl--K6f8QAAA4o"]
[Sun Aug 30 03:12:20.308059 2026] [security2:error] [pid 524122:tid 524280] [client 20.104.18.15:18402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/gulu.php"] [unique_id "apPl5H3lhEjKFiK_nBKCHwAAAao"]
[Sun Aug 30 03:12:20.344673 2026] [security2:error] [pid 521505:tid 521736] [client 20.48.160.90:37789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/jw.php"] [unique_id "apPl5G8byYE0iXl--K6f8wAAA4M"]
[Sun Aug 30 03:12:20.372418 2026] [security2:error] [pid 524122:tid 524274] [client 20.48.160.90:50479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp-login.php"] [unique_id "apPl5H3lhEjKFiK_nBKCIgAAAaQ"]
[Sun Aug 30 03:12:20.394109 2026] [security2:error] [pid 521505:tid 521746] [client 20.104.50.220:29628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/12j.php"] [unique_id "apPl5G8byYE0iXl--K6f9gAAA40"]
[Sun Aug 30 03:12:20.438853 2026] [security2:error] [pid 521505:tid 521711] [client 20.104.49.130:63606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/kj.php"] [unique_id "apPl5G8byYE0iXl--K6f9wAAA2o"]
[Sun Aug 30 03:12:20.478748 2026] [security2:error] [pid 521505:tid 521719] [client 20.48.160.90:61680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/or.php"] [unique_id "apPl5G8byYE0iXl--K6f-QAAA3I"]
[Sun Aug 30 03:12:20.485724 2026] [authz_core:error] [pid 521505:tid 521699] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory18
[Sun Aug 30 03:12:20.485989 2026] [authz_core:error] [pid 521505:tid 521699] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory18
[Sun Aug 30 03:12:20.510277 2026] [security2:error] [pid 521505:tid 521758] [client 20.48.160.90:50544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/images.php"] [unique_id "apPl5G8byYE0iXl--K6f-wAAA5k"]
[Sun Aug 30 03:12:20.548564 2026] [security2:error] [pid 521505:tid 521691] [client 20.104.49.130:59578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/browse.php"] [unique_id "apPl5G8byYE0iXl--K6f_wAAA1Y"]
[Sun Aug 30 03:12:20.551799 2026] [authz_core:error] [pid 521505:tid 521726] [client 66.249.66.202:58467] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:20.552215 2026] [authz_core:error] [pid 521505:tid 521726] [client 66.249.66.202:58467] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:20.560668 2026] [authz_core:error] [pid 521505:tid 521686] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:20.560928 2026] [authz_core:error] [pid 521505:tid 521686] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:20.579353 2026] [security2:error] [pid 524122:tid 524329] [client 34.15.159.88:44846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/staging/phpinfo.php"] [unique_id "apPl5H3lhEjKFiK_nBKCJAAAAds"]
[Sun Aug 30 03:12:20.615869 2026] [security2:error] [pid 521505:tid 521637] [client 20.151.200.44:44956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/ca.php"] [unique_id "apPl5G8byYE0iXl--K6gBQAAAyA"]
[Sun Aug 30 03:12:20.616208 2026] [security2:error] [pid 521505:tid 521655] [client 158.23.147.79:16361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apPl5G8byYE0iXl--K6gBgAAAzI"]
[Sun Aug 30 03:12:20.619790 2026] [security2:error] [pid 521505:tid 521645] [client 20.48.160.90:37876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/ile56.php"] [unique_id "apPl5G8byYE0iXl--K6gBwAAAyg"]
[Sun Aug 30 03:12:20.634094 2026] [security2:error] [pid 521505:tid 521693] [client 158.23.147.79:39967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-admin/css/index.php"] [unique_id "apPl5G8byYE0iXl--K6gCgAAA1g"]
[Sun Aug 30 03:12:20.638233 2026] [security2:error] [pid 524122:tid 524262] [client 20.48.160.90:50504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/ops.php"] [unique_id "apPl5H3lhEjKFiK_nBKCJgAAAZg"]
[Sun Aug 30 03:12:20.638914 2026] [security2:error] [pid 521505:tid 521657] [client 20.104.18.15:22443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/bulet.php"] [unique_id "apPl5G8byYE0iXl--K6gCwAAAzQ"]
[Sun Aug 30 03:12:20.643260 2026] [authz_core:error] [pid 524122:tid 524316] [client 216.73.216.128:49116] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:20.643557 2026] [authz_core:error] [pid 524122:tid 524316] [client 216.73.216.128:49116] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:20.734834 2026] [security2:error] [pid 524122:tid 524306] [client 20.104.50.220:16642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/alfa-rex.php7"] [unique_id "apPl5H3lhEjKFiK_nBKCKAAAAcQ"]
[Sun Aug 30 03:12:20.755811 2026] [security2:error] [pid 524122:tid 524299] [client 4.205.62.107:17716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/kedi.php"] [unique_id "apPl5H3lhEjKFiK_nBKCKQAAAb0"]
[Sun Aug 30 03:12:20.757356 2026] [security2:error] [pid 521505:tid 521757] [client 20.48.160.90:37839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/emmh.php"] [unique_id "apPl5G8byYE0iXl--K6gDAAAA5g"]
[Sun Aug 30 03:12:20.781257 2026] [security2:error] [pid 524122:tid 524322] [client 20.48.160.90:45419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPl5H3lhEjKFiK_nBKCKgAAAdQ"]
[Sun Aug 30 03:12:20.787100 2026] [security2:error] [pid 521505:tid 521668] [client 35.247.242.193:56024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/uat/phpinfo.php"] [unique_id "apPl5G8byYE0iXl--K6gDgAAAz8"]
[Sun Aug 30 03:12:20.788160 2026] [security2:error] [pid 524122:tid 524332] [client 20.104.18.15:1986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/simple.php"] [unique_id "apPl5H3lhEjKFiK_nBKCKwAAAd4"]
[Sun Aug 30 03:12:20.818006 2026] [authz_core:error] [pid 524122:tid 524265] [client 66.249.66.206:42059] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:20.818288 2026] [authz_core:error] [pid 524122:tid 524265] [client 66.249.66.206:42059] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:20.823344 2026] [security2:error] [pid 524122:tid 524236] [remote 54.87.136.243:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.136.87.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thebaumfamily.net"] [uri "/wp-login.php"] [unique_id "apPl5H3lhEjKFiK_nBKCLgAB8HA"]
[Sun Aug 30 03:12:20.836005 2026] [security2:error] [pid 524122:tid 524324] [client 20.151.200.44:45027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/pb.php"] [unique_id "apPl5H3lhEjKFiK_nBKCMgAAAdY"]
[Sun Aug 30 03:12:20.896345 2026] [security2:error] [pid 521505:tid 521760] [client 20.48.160.90:61676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/em.php"] [unique_id "apPl5G8byYE0iXl--K6gEAAAA5s"]
[Sun Aug 30 03:12:20.922807 2026] [security2:error] [pid 524122:tid 524283] [client 20.48.160.90:45399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPl5H3lhEjKFiK_nBKCNQAAAa0"]
[Sun Aug 30 03:12:20.925215 2026] [security2:error] [pid 521505:tid 521654] [client 20.104.18.15:51109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/simple.php"] [unique_id "apPl5G8byYE0iXl--K6gEgAAAzE"]
[Sun Aug 30 03:12:20.927530 2026] [security2:error] [pid 521505:tid 521636] [client 20.104.50.220:33031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/0x0.php"] [unique_id "apPl5G8byYE0iXl--K6gEwAAAx8"]
[Sun Aug 30 03:12:20.959045 2026] [security2:error] [pid 521505:tid 521705] [client 158.23.147.79:21488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-admin/images/index.php"] [unique_id "apPl5G8byYE0iXl--K6gFAAAA2Q"]
[Sun Aug 30 03:12:20.988367 2026] [security2:error] [pid 521505:tid 521647] [client 20.48.251.3:59897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/kedi.php"] [unique_id "apPl5G8byYE0iXl--K6gFgAAAyo"]
[Sun Aug 30 03:12:20.999943 2026] [security2:error] [pid 521505:tid 521734] [client 216.73.216.128:12342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPl5G8byYE0iXl--K6gFwAAA4E"]
[Sun Aug 30 03:12:21.017889 2026] [authz_core:error] [pid 521505:tid 521716] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory31
[Sun Aug 30 03:12:21.018163 2026] [authz_core:error] [pid 521505:tid 521716] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory31
[Sun Aug 30 03:12:21.031613 2026] [authz_core:error] [pid 521505:tid 521666] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:21.031894 2026] [authz_core:error] [pid 521505:tid 521666] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:21.036439 2026] [security2:error] [pid 521505:tid 521747] [client 20.48.160.90:61613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/dvve.php"] [unique_id "apPl5W8byYE0iXl--K6gGwAAA44"]
[Sun Aug 30 03:12:21.036501 2026] [security2:error] [pid 521505:tid 521701] [client 20.104.18.15:64705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/c4.php"] [unique_id "apPl5W8byYE0iXl--K6gGgAAA2A"]
[Sun Aug 30 03:12:21.040693 2026] [security2:error] [pid 524122:tid 524302] [client 4.205.62.107:15847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/maxro.php"] [unique_id "apPl5X3lhEjKFiK_nBKCNgAAAcA"]
[Sun Aug 30 03:12:21.045225 2026] [security2:error] [pid 524122:tid 524314] [client 20.48.251.3:52833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/cli_bootstrap.php"] [unique_id "apPl5X3lhEjKFiK_nBKCNwAAAcw"]
[Sun Aug 30 03:12:21.061154 2026] [security2:error] [pid 521505:tid 521751] [client 20.48.160.90:50509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/about.php"] [unique_id "apPl5W8byYE0iXl--K6gHQAAA5I"]
[Sun Aug 30 03:12:21.080860 2026] [security2:error] [pid 521505:tid 521687] [client 20.48.251.3:54730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/87.php"] [unique_id "apPl5W8byYE0iXl--K6gIAAAA1I"]
[Sun Aug 30 03:12:21.087718 2026] [security2:error] [pid 521505:tid 521710] [client 4.205.62.107:16344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/bengi.php"] [unique_id "apPl5W8byYE0iXl--K6gIQAAA2k"]
[Sun Aug 30 03:12:21.097931 2026] [authz_core:error] [pid 524122:tid 524375] [client 66.249.66.193:40590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:21.098371 2026] [authz_core:error] [pid 524122:tid 524375] [client 66.249.66.193:40590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:21.109469 2026] [security2:error] [pid 521505:tid 521661] [client 20.104.49.130:48062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/bolt.php"] [unique_id "apPl5W8byYE0iXl--K6gJAAAAzg"]
[Sun Aug 30 03:12:21.117613 2026] [security2:error] [pid 521505:tid 521717] [client 20.104.49.130:43603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/sxxb.php"] [unique_id "apPl5W8byYE0iXl--K6gJQAAA3A"]
[Sun Aug 30 03:12:21.146344 2026] [security2:error] [pid 521505:tid 521728] [client 20.104.50.220:42249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/min.php"] [unique_id "apPl5W8byYE0iXl--K6gJwAAA3s"]
[Sun Aug 30 03:12:21.147594 2026] [security2:error] [pid 521505:tid 521728] [client 20.151.200.44:44969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/pk.php"] [unique_id "apPl5W8byYE0iXl--K6gKAAAA3s"]
[Sun Aug 30 03:12:21.163861 2026] [security2:error] [pid 521505:tid 521643] [client 20.104.50.220:24921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/wp-admin/css/colour.php"] [unique_id "apPl5W8byYE0iXl--K6gKQAAAyY"]
[Sun Aug 30 03:12:21.183551 2026] [security2:error] [pid 521505:tid 521742] [client 34.15.159.88:53778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/beta/phpinfo.php"] [unique_id "apPl5W8byYE0iXl--K6gKgAAA4k"]
[Sun Aug 30 03:12:21.188480 2026] [security2:error] [pid 521505:tid 521703] [client 20.104.50.220:29160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-admin/mailer.php"] [unique_id "apPl5W8byYE0iXl--K6gKwAAA2I"]
[Sun Aug 30 03:12:21.189270 2026] [security2:error] [pid 521505:tid 521640] [client 20.48.160.90:25047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/doo.php"] [unique_id "apPl5W8byYE0iXl--K6gLAAAAyM"]
[Sun Aug 30 03:12:21.189694 2026] [authz_core:error] [pid 524122:tid 524313] [client 216.73.216.128:14524] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:21.190118 2026] [authz_core:error] [pid 524122:tid 524313] [client 216.73.216.128:14524] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:21.202337 2026] [security2:error] [pid 521505:tid 521695] [client 20.104.50.220:59372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/lsd.php"] [unique_id "apPl5W8byYE0iXl--K6gLgAAA1o"]
[Sun Aug 30 03:12:21.207152 2026] [security2:error] [pid 521505:tid 521635] [client 20.48.160.90:50490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/admin.php/admin.php"] [unique_id "apPl5W8byYE0iXl--K6gLwAAAx4"]
[Sun Aug 30 03:12:21.209807 2026] [security2:error] [pid 521505:tid 521658] [client 20.48.251.3:37166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/mga.php"] [unique_id "apPl5W8byYE0iXl--K6gMAAAAzU"]
[Sun Aug 30 03:12:21.240315 2026] [security2:error] [pid 521505:tid 521759] [client 20.104.49.130:26667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/txets.php"] [unique_id "apPl5W8byYE0iXl--K6gMQAAA5o"]
[Sun Aug 30 03:12:21.273936 2026] [security2:error] [pid 521505:tid 521639] [client 35.247.242.193:56038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/qa/phpinfo.php"] [unique_id "apPl5W8byYE0iXl--K6gMgAAAyI"]
[Sun Aug 30 03:12:21.285244 2026] [security2:error] [pid 521505:tid 521754] [client 4.205.62.107:52820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/wp-konfig.php"] [unique_id "apPl5W8byYE0iXl--K6gMwAAA5U"]
[Sun Aug 30 03:12:21.319494 2026] [security2:error] [pid 521505:tid 521677] [client 20.151.200.44:44955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/ft.php"] [unique_id "apPl5W8byYE0iXl--K6gNgAAA0g"]
[Sun Aug 30 03:12:21.327346 2026] [security2:error] [pid 524122:tid 524367] [client 20.48.160.90:37868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/gelap1.php"] [unique_id "apPl5X3lhEjKFiK_nBKCOwAAAgE"]
[Sun Aug 30 03:12:21.335012 2026] [security2:error] [pid 521505:tid 521732] [client 20.48.160.90:45418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/media.php"] [unique_id "apPl5W8byYE0iXl--K6gOAAAA38"]
[Sun Aug 30 03:12:21.374378 2026] [security2:error] [pid 521505:tid 521660] [client 20.104.50.220:5564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/62.php"] [unique_id "apPl5W8byYE0iXl--K6gOgAAAzc"]
[Sun Aug 30 03:12:21.387853 2026] [security2:error] [pid 521505:tid 521715] [client 158.23.147.79:40035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-includes/index.php"] [unique_id "apPl5W8byYE0iXl--K6gPQAAA24"]
[Sun Aug 30 03:12:21.406183 2026] [security2:error] [pid 521505:tid 521657] [client 4.205.62.107:25500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/filesystems.php"] [unique_id "apPl5W8byYE0iXl--K6gPwAAAzQ"]
[Sun Aug 30 03:12:21.423019 2026] [security2:error] [pid 521505:tid 521699] [client 158.23.147.79:16325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apPl5W8byYE0iXl--K6gQAAAA14"]
[Sun Aug 30 03:12:21.439667 2026] [security2:error] [pid 521505:tid 521748] [client 20.104.18.15:18393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/replace.php"] [unique_id "apPl5W8byYE0iXl--K6gQQAAA48"]
[Sun Aug 30 03:12:21.462446 2026] [security2:error] [pid 524122:tid 524256] [client 20.151.200.44:45018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/wp-ver.php"] [unique_id "apPl5X3lhEjKFiK_nBKCPgAAAZI"]
[Sun Aug 30 03:12:21.462450 2026] [security2:error] [pid 524122:tid 524304] [client 20.48.160.90:51820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/rsjlrria.php"] [unique_id "apPl5X3lhEjKFiK_nBKCPwAAAcI"]
[Sun Aug 30 03:12:21.464889 2026] [security2:error] [pid 521505:tid 521692] [client 20.104.50.220:59552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/geck.php"] [unique_id "apPl5W8byYE0iXl--K6gQgAAA1c"]
[Sun Aug 30 03:12:21.469619 2026] [security2:error] [pid 524122:tid 524377] [client 20.48.160.90:50555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/mac.php"] [unique_id "apPl5X3lhEjKFiK_nBKCQAAAAgs"]
[Sun Aug 30 03:12:21.483326 2026] [authz_core:error] [pid 521505:tid 521690] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory17
[Sun Aug 30 03:12:21.483578 2026] [authz_core:error] [pid 521505:tid 521690] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory17
[Sun Aug 30 03:12:21.528286 2026] [authz_core:error] [pid 521505:tid 521722] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:21.528541 2026] [authz_core:error] [pid 521505:tid 521722] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:21.534675 2026] [security2:error] [pid 524122:tid 524339] [client 20.104.50.220:29574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/danon.php"] [unique_id "apPl5X3lhEjKFiK_nBKCQQAAAeU"]
[Sun Aug 30 03:12:21.566303 2026] [authz_core:error] [pid 521505:tid 521651] [client 66.249.66.44:49905] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:21.566558 2026] [authz_core:error] [pid 521505:tid 521651] [client 66.249.66.44:49905] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:21.600492 2026] [security2:error] [pid 524122:tid 524341] [client 20.48.160.90:51795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/AxAo.php"] [unique_id "apPl5X3lhEjKFiK_nBKCQgAAAec"]
[Sun Aug 30 03:12:21.601722 2026] [authz_core:error] [pid 521505:tid 521688] [client 216.73.216.128:16328] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:21.602091 2026] [authz_core:error] [pid 521505:tid 521688] [client 216.73.216.128:16328] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:21.614661 2026] [security2:error] [pid 524122:tid 524254] [client 20.48.160.90:45428] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "buckcreekrhs.com"] [uri "/1.php"] [unique_id "apPl5X3lhEjKFiK_nBKCQwAAAZA"]
[Sun Aug 30 03:12:21.614744 2026] [security2:error] [pid 524122:tid 524254] [client 20.48.160.90:45428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/1.php"] [unique_id "apPl5X3lhEjKFiK_nBKCQwAAAZA"]
[Sun Aug 30 03:12:21.622026 2026] [security2:error] [pid 521505:tid 521636] [client 20.151.200.44:45011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/ah24.php"] [unique_id "apPl5W8byYE0iXl--K6gSwAAAx8"]
[Sun Aug 30 03:12:21.741408 2026] [security2:error] [pid 521505:tid 521738] [client 20.48.160.90:37778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/class17.php"] [unique_id "apPl5W8byYE0iXl--K6gTwAAA4U"]
[Sun Aug 30 03:12:21.750098 2026] [security2:error] [pid 521505:tid 521747] [client 20.48.160.90:50466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/classwithtostring.php"] [unique_id "apPl5W8byYE0iXl--K6gUAAAA44"]
[Sun Aug 30 03:12:21.752502 2026] [security2:error] [pid 521505:tid 521749] [client 35.247.242.193:56040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/preview/phpinfo.php"] [unique_id "apPl5W8byYE0iXl--K6gUQAAA5A"]
[Sun Aug 30 03:12:21.775907 2026] [security2:error] [pid 521505:tid 521679] [client 20.104.18.15:22507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/av.php"] [unique_id "apPl5W8byYE0iXl--K6gUgAAA0o"]
[Sun Aug 30 03:12:21.777610 2026] [security2:error] [pid 524122:tid 524365] [client 20.151.200.44:44953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPl5X3lhEjKFiK_nBKCSAAAAf8"]
[Sun Aug 30 03:12:21.787777 2026] [security2:error] [pid 521505:tid 521707] [client 34.15.159.88:53794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/uat/phpinfo.php"] [unique_id "apPl5W8byYE0iXl--K6gUwAAA2Y"]
[Sun Aug 30 03:12:21.788002 2026] [security2:error] [pid 524122:tid 524295] [client 158.23.147.79:21458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/mah.php"] [unique_id "apPl5X3lhEjKFiK_nBKCSQAAAbk"]
[Sun Aug 30 03:12:21.825368 2026] [security2:error] [pid 521505:tid 521710] [client 20.151.200.44:43999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ermes-it.it"] [uri "/zoz.php"] [unique_id "apPl5W8byYE0iXl--K6gVgAAA2k"]
[Sun Aug 30 03:12:21.845973 2026] [security2:error] [pid 524122:tid 524278] [client 20.151.200.44:52120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPl5X3lhEjKFiK_nBKCSgAAAag"]
[Sun Aug 30 03:12:21.869820 2026] [security2:error] [pid 521505:tid 521671] [client 20.104.50.220:17338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/alfanew.php7"] [unique_id "apPl5W8byYE0iXl--K6gWAAAA0I"]
[Sun Aug 30 03:12:21.875631 2026] [security2:error] [pid 521505:tid 521661] [client 20.48.160.90:61627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/okxoby.php"] [unique_id "apPl5W8byYE0iXl--K6gWQAAAzg"]
[Sun Aug 30 03:12:21.887042 2026] [security2:error] [pid 524122:tid 524345] [client 4.205.62.107:17692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/oc460l3x.php"] [unique_id "apPl5X3lhEjKFiK_nBKCSwAAAes"]
[Sun Aug 30 03:12:21.897108 2026] [security2:error] [pid 521505:tid 521753] [client 20.48.160.90:50472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp-ws68.php"] [unique_id "apPl5W8byYE0iXl--K6gWgAAA5Q"]
[Sun Aug 30 03:12:21.909507 2026] [security2:error] [pid 524122:tid 524319] [client 158.23.147.79:40013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-blog-header.php"] [unique_id "apPl5X3lhEjKFiK_nBKCTAAAAdE"]
[Sun Aug 30 03:12:21.924947 2026] [security2:error] [pid 521505:tid 521684] [client 20.104.18.15:1865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/sallu.php"] [unique_id "apPl5W8byYE0iXl--K6gWwAAA08"]
[Sun Aug 30 03:12:21.967687 2026] [authz_core:error] [pid 521505:tid 521675] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory16
[Sun Aug 30 03:12:21.968019 2026] [authz_core:error] [pid 521505:tid 521675] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory16
[Sun Aug 30 03:12:22.018828 2026] [security2:error] [pid 521505:tid 521716] [client 20.48.160.90:37881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/esuutzzx.php"] [unique_id "apPl5m8byYE0iXl--K6gYgAAA28"]
[Sun Aug 30 03:12:22.031224 2026] [authz_core:error] [pid 521505:tid 521670] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:22.031620 2026] [authz_core:error] [pid 521505:tid 521670] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:22.036309 2026] [security2:error] [pid 521505:tid 521744] [client 20.48.160.90:50478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/simple.php"] [unique_id "apPl5m8byYE0iXl--K6gZAAAA4s"]
[Sun Aug 30 03:12:22.057600 2026] [security2:error] [pid 521505:tid 521681] [client 20.104.50.220:32839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/0z.php"] [unique_id "apPl5m8byYE0iXl--K6gZQAAA0w"]
[Sun Aug 30 03:12:22.058703 2026] [security2:error] [pid 521505:tid 521755] [client 20.151.200.44:45054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.lodestar-media.com"] [uri "/waf.php"] [unique_id "apPl5m8byYE0iXl--K6gZgAAA5Y"]
[Sun Aug 30 03:12:22.067164 2026] [security2:error] [pid 521505:tid 521695] [client 20.104.18.15:51162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/xty.php"] [unique_id "apPl5m8byYE0iXl--K6gZwAAA1o"]
[Sun Aug 30 03:12:22.149801 2026] [security2:error] [pid 521505:tid 521664] [client 20.48.160.90:61691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/replace.php"] [unique_id "apPl5m8byYE0iXl--K6gbgAAAzs"]
[Sun Aug 30 03:12:22.162931 2026] [security2:error] [pid 521505:tid 521662] [client 158.23.147.79:16331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apPl5m8byYE0iXl--K6gbwAAAzk"]
[Sun Aug 30 03:12:22.171225 2026] [security2:error] [pid 524122:tid 524303] [client 20.48.160.90:50549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/aaa.php"] [unique_id "apPl5n3lhEjKFiK_nBKCUwAAAcE"]
[Sun Aug 30 03:12:22.171344 2026] [security2:error] [pid 524122:tid 524372] [client 20.48.251.3:52180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/oc460l3x.php"] [unique_id "apPl5n3lhEjKFiK_nBKCVAAAAgY"]
[Sun Aug 30 03:12:22.179094 2026] [security2:error] [pid 524122:tid 524380] [client 4.205.62.107:15972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/brc.php"] [unique_id "apPl5n3lhEjKFiK_nBKCVgAAAg4"]
[Sun Aug 30 03:12:22.195904 2026] [security2:error] [pid 524122:tid 524259] [client 20.151.200.44:52113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPl5n3lhEjKFiK_nBKCVwAAAZU"]
[Sun Aug 30 03:12:22.207847 2026] [security2:error] [pid 524122:tid 524354] [client 158.23.147.79:40000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apPl5n3lhEjKFiK_nBKCWAAAAfQ"]
[Sun Aug 30 03:12:22.210183 2026] [security2:error] [pid 524122:tid 524346] [client 20.48.251.3:59366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/dd.php"] [unique_id "apPl5n3lhEjKFiK_nBKCWQAAAew"]
[Sun Aug 30 03:12:22.216084 2026] [security2:error] [pid 521505:tid 521724] [client 20.104.18.15:64707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/rxr.php"] [unique_id "apPl5m8byYE0iXl--K6gcQAAA3c"]
[Sun Aug 30 03:12:22.225809 2026] [security2:error] [pid 521505:tid 521730] [client 20.48.251.3:54735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/plss3.php"] [unique_id "apPl5m8byYE0iXl--K6gcgAAA30"]
[Sun Aug 30 03:12:22.233253 2026] [security2:error] [pid 521505:tid 521642] [client 4.205.62.107:16328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/i.php"] [unique_id "apPl5m8byYE0iXl--K6gcwAAAyU"]
[Sun Aug 30 03:12:22.237525 2026] [security2:error] [pid 521505:tid 521658] [client 35.247.242.193:56046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/www/phpinfo.php"] [unique_id "apPl5m8byYE0iXl--K6gdAAAAzU"]
[Sun Aug 30 03:12:22.269130 2026] [security2:error] [pid 524122:tid 524320] [client 216.73.216.128:49116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPl5n3lhEjKFiK_nBKCWgAAAdI"]
[Sun Aug 30 03:12:22.302626 2026] [security2:error] [pid 524122:tid 524277] [client 20.48.160.90:25070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/gulu.php"] [unique_id "apPl5n3lhEjKFiK_nBKCWwAAAac"]
[Sun Aug 30 03:12:22.315689 2026] [security2:error] [pid 524122:tid 524360] [client 20.104.50.220:25456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/2P.php"] [unique_id "apPl5n3lhEjKFiK_nBKCXQAAAfo"]
[Sun Aug 30 03:12:22.330367 2026] [authz_core:error] [pid 524122:tid 524305] [client 20.48.160.90:50538] AH01630: client denied by server configuration: /home1/pabney/public_html/wp-admin/css/colors/modern/index.pl
[Sun Aug 30 03:12:22.334415 2026] [security2:error] [pid 524122:tid 524344] [client 20.104.50.220:29591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-content/mailer.php"] [unique_id "apPl5n3lhEjKFiK_nBKCXgAAAeo"]
[Sun Aug 30 03:12:22.338995 2026] [authz_core:error] [pid 524122:tid 524305] [client 20.48.160.90:50538] AH01630: client denied by server configuration: /home1/pabney/public_html/wp-admin/css/colors/modern/index.cgi
[Sun Aug 30 03:12:22.339408 2026] [security2:error] [pid 524122:tid 524280] [client 20.104.50.220:31173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/as.php"] [unique_id "apPl5n3lhEjKFiK_nBKCXwAAAao"]
[Sun Aug 30 03:12:22.341824 2026] [authz_core:error] [pid 524122:tid 524305] [client 20.48.160.90:50538] AH01630: client denied by server configuration: /home1/pabney/public_html/wp-admin/css/colors/modern/index.jsp
[Sun Aug 30 03:12:22.356365 2026] [authz_core:error] [pid 524122:tid 524305] [client 20.48.160.90:50538] AH01630: client denied by server configuration: /home1/pabney/public_html/wp-admin/css/colors/modern/index.phtml
[Sun Aug 30 03:12:22.362052 2026] [security2:error] [pid 524122:tid 524335] [client 20.48.251.3:36840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/ccou.php"] [unique_id "apPl5n3lhEjKFiK_nBKCYQAAAeE"]
[Sun Aug 30 03:12:22.395982 2026] [security2:error] [pid 524122:tid 524362] [client 34.15.159.88:53796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/qa/phpinfo.php"] [unique_id "apPl5n3lhEjKFiK_nBKCYwAAAfw"]
[Sun Aug 30 03:12:22.422389 2026] [authz_core:error] [pid 521505:tid 521655] [client 66.249.66.202:58467] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:22.422635 2026] [authz_core:error] [pid 521505:tid 521655] [client 66.249.66.202:58467] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:22.430919 2026] [security2:error] [pid 524122:tid 524329] [client 20.48.160.90:61683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/gtghklk.php"] [unique_id "apPl5n3lhEjKFiK_nBKCZAAAAds"]
[Sun Aug 30 03:12:22.460012 2026] [authz_core:error] [pid 524122:tid 524262] [client 20.48.160.90:50538] AH01630: client denied by server configuration: /home1/pabney/public_html/wp-admin/css/colors/sunrise/index.pl
[Sun Aug 30 03:12:22.467244 2026] [security2:error] [pid 524122:tid 524334] [client 20.151.200.44:52117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/h02ugyh.php"] [unique_id "apPl5n3lhEjKFiK_nBKCZgAAAeA"]
[Sun Aug 30 03:12:22.467317 2026] [authz_core:error] [pid 524122:tid 524262] [client 20.48.160.90:50538] AH01630: client denied by server configuration: /home1/pabney/public_html/wp-admin/css/colors/sunrise/index.cgi
[Sun Aug 30 03:12:22.469753 2026] [authz_core:error] [pid 524122:tid 524262] [client 20.48.160.90:50538] AH01630: client denied by server configuration: /home1/pabney/public_html/wp-admin/css/colors/sunrise/index.jsp
[Sun Aug 30 03:12:22.485408 2026] [authz_core:error] [pid 524122:tid 524262] [client 20.48.160.90:50538] AH01630: client denied by server configuration: /home1/pabney/public_html/wp-admin/css/colors/sunrise/index.phtml
[Sun Aug 30 03:12:22.492932 2026] [authz_core:error] [pid 521505:tid 521706] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory13
[Sun Aug 30 03:12:22.493198 2026] [authz_core:error] [pid 521505:tid 521706] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory13
[Sun Aug 30 03:12:22.510639 2026] [security2:error] [pid 524122:tid 524306] [client 4.205.62.107:52903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/25.php"] [unique_id "apPl5n3lhEjKFiK_nBKCaAAAAcQ"]
[Sun Aug 30 03:12:22.517261 2026] [security2:error] [pid 524122:tid 524299] [client 20.104.50.220:5818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/61.php"] [unique_id "apPl5n3lhEjKFiK_nBKCaQAAAb0"]
[Sun Aug 30 03:12:22.567814 2026] [security2:error] [pid 524122:tid 524322] [client 20.48.160.90:50538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/shiny.php"] [unique_id "apPl5n3lhEjKFiK_nBKCawAAAdQ"]
[Sun Aug 30 03:12:22.571829 2026] [security2:error] [pid 521505:tid 521712] [client 20.48.160.90:61609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/comand.php"] [unique_id "apPl5m8byYE0iXl--K6geQAAA2s"]
[Sun Aug 30 03:12:22.582216 2026] [security2:error] [pid 524122:tid 524270] [client 20.104.18.15:18202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/c4.php"] [unique_id "apPl5n3lhEjKFiK_nBKCbAAAAaA"]
[Sun Aug 30 03:12:22.583239 2026] [authz_core:error] [pid 521505:tid 521669] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:22.583505 2026] [authz_core:error] [pid 521505:tid 521669] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:22.587232 2026] [security2:error] [pid 521505:tid 521682] [client 158.23.147.79:39957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-admin/user/index.php"] [unique_id "apPl5m8byYE0iXl--K6gewAAA00"]
[Sun Aug 30 03:12:22.681023 2026] [security2:error] [pid 521505:tid 521726] [client 20.104.50.220:61495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/gm.php"] [unique_id "apPl5m8byYE0iXl--K6gfQAAA3k"]
[Sun Aug 30 03:12:22.699850 2026] [security2:error] [pid 524122:tid 524279] [client 20.48.160.90:51794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp_motu_myk3v.php"] [unique_id "apPl5n3lhEjKFiK_nBKCbgAAAak"]
[Sun Aug 30 03:12:22.702355 2026] [security2:error] [pid 521505:tid 521731] [client 20.104.50.220:29137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/xd.php"] [unique_id "apPl5m8byYE0iXl--K6gfgAAA34"]
[Sun Aug 30 03:12:22.714031 2026] [security2:error] [pid 524122:tid 524283] [client 20.48.160.90:45337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/goods.php"] [unique_id "apPl5n3lhEjKFiK_nBKCbwAAAa0"]
[Sun Aug 30 03:12:22.723833 2026] [security2:error] [pid 521505:tid 521657] [client 35.247.242.193:56052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/htdocs/phpinfo.php"] [unique_id "apPl5m8byYE0iXl--K6gfwAAAzQ"]
[Sun Aug 30 03:12:22.732490 2026] [security2:error] [pid 521505:tid 521750] [client 20.104.50.220:51608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/wp-backup-sql-302.php"] [unique_id "apPl5m8byYE0iXl--K6ggAAAA5E"]
[Sun Aug 30 03:12:22.754352 2026] [security2:error] [pid 521505:tid 521696] [client 4.205.62.107:26999] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/retu11.PhP"] [unique_id "apPl5m8byYE0iXl--K6gggAAA1s"]
[Sun Aug 30 03:12:22.849210 2026] [security2:error] [pid 521505:tid 521756] [client 20.48.160.90:37878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/wp_motu_ypdat.php"] [unique_id "apPl5m8byYE0iXl--K6ghQAAA5c"]
[Sun Aug 30 03:12:22.863527 2026] [security2:error] [pid 521505:tid 521641] [client 20.48.160.90:45386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/000.php/index.php"] [unique_id "apPl5m8byYE0iXl--K6ghgAAAyQ"]
[Sun Aug 30 03:12:22.887437 2026] [security2:error] [pid 521505:tid 521718] [client 158.23.147.79:21405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-includes/plugins.php"] [unique_id "apPl5m8byYE0iXl--K6giAAAA3E"]
[Sun Aug 30 03:12:22.925276 2026] [authz_core:error] [pid 524122:tid 524314] [client 216.73.216.128:17046] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:22.925715 2026] [authz_core:error] [pid 524122:tid 524314] [client 216.73.216.128:17046] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:22.929768 2026] [security2:error] [pid 521505:tid 521663] [client 20.104.18.15:22420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/images.php"] [unique_id "apPl5m8byYE0iXl--K6giQAAAzo"]
[Sun Aug 30 03:12:22.931009 2026] [security2:error] [pid 524122:tid 524374] [client 20.151.200.44:43915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ermes-it.it"] [uri "/kcs.php"] [unique_id "apPl5n3lhEjKFiK_nBKCcwAAAgg"]
[Sun Aug 30 03:12:22.977083 2026] [security2:error] [pid 524122:tid 524361] [client 20.48.160.90:37852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/edit.php"] [unique_id "apPl5n3lhEjKFiK_nBKCdAAAAfs"]
[Sun Aug 30 03:12:23.004001 2026] [authz_core:error] [pid 521505:tid 521741] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory26
[Sun Aug 30 03:12:23.004275 2026] [authz_core:error] [pid 521505:tid 521741] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory26
[Sun Aug 30 03:12:23.006688 2026] [security2:error] [pid 524122:tid 524330] [client 34.15.159.88:53812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/preview/phpinfo.php"] [unique_id "apPl533lhEjKFiK_nBKCdQAAAdw"]
[Sun Aug 30 03:12:23.009280 2026] [security2:error] [pid 521505:tid 521736] [client 20.104.50.220:16588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/tanliste.php"] [unique_id "apPl528byYE0iXl--K6gjQAAA4M"]
[Sun Aug 30 03:12:23.014515 2026] [security2:error] [pid 524122:tid 524370] [client 20.48.160.90:45407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/Jcrop.php"] [unique_id "apPl533lhEjKFiK_nBKCdgAAAgQ"]
[Sun Aug 30 03:12:23.031302 2026] [security2:error] [pid 521505:tid 521738] [client 4.205.62.107:16813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/drykl.php"] [unique_id "apPl528byYE0iXl--K6gjwAAA4U"]
[Sun Aug 30 03:12:23.035931 2026] [authz_core:error] [pid 521505:tid 521761] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:23.036210 2026] [authz_core:error] [pid 521505:tid 521761] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:23.040617 2026] [authz_core:error] [pid 524122:tid 524368] [client 66.249.66.200:58758] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:23.041050 2026] [authz_core:error] [pid 524122:tid 524368] [client 66.249.66.200:58758] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:23.054077 2026] [security2:error] [pid 524122:tid 524300] [client 20.104.49.130:48026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/cilus.php"] [unique_id "apPl533lhEjKFiK_nBKCeAAAAb4"]
[Sun Aug 30 03:12:23.062955 2026] [security2:error] [pid 521505:tid 521686] [client 20.104.18.15:1946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/biufile.php"] [unique_id "apPl528byYE0iXl--K6gkQAAA1E"]
[Sun Aug 30 03:12:23.082535 2026] [security2:error] [pid 521505:tid 521762] [client 75.179.79.26:44488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "filtagreen.com"] [uri "/xmlrpc.php"] [unique_id "apPl5m8byYE0iXl--K6gigAAA50"], referer: http://filtagreen.com/
[Sun Aug 30 03:12:23.105138 2026] [security2:error] [pid 521505:tid 521704] [client 20.48.160.90:61640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/tqkdqbbv.php"] [unique_id "apPl528byYE0iXl--K6gkwAAA2M"]
[Sun Aug 30 03:12:23.109402 2026] [security2:error] [pid 524122:tid 524357] [client 20.151.200.44:52159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/sf.php"] [unique_id "apPl533lhEjKFiK_nBKCegAAAfc"]
[Sun Aug 30 03:12:23.151496 2026] [security2:error] [pid 524122:tid 524375] [client 20.48.160.90:45378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/35iDq8NAjLu.php"] [unique_id "apPl533lhEjKFiK_nBKCewAAAgk"]
[Sun Aug 30 03:12:23.170629 2026] [security2:error] [pid 521505:tid 521717] [client 20.151.200.44:44019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ermes-it.it"] [uri "/tajj.php"] [unique_id "apPl528byYE0iXl--K6glgAAA3A"]
[Sun Aug 30 03:12:23.172561 2026] [security2:error] [pid 521505:tid 521753] [client 20.104.49.130:26660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/kj.php"] [unique_id "apPl528byYE0iXl--K6glwAAA5Q"]
[Sun Aug 30 03:12:23.208482 2026] [security2:error] [pid 521505:tid 521749] [client 35.247.242.193:56064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/public_html/phpinfo.php"] [unique_id "apPl528byYE0iXl--K6gmQAAA5A"]
[Sun Aug 30 03:12:23.208486 2026] [security2:error] [pid 524122:tid 524315] [client 20.104.50.220:33078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/13.php"] [unique_id "apPl533lhEjKFiK_nBKCfAAAAc0"]
[Sun Aug 30 03:12:23.212309 2026] [security2:error] [pid 524122:tid 524304] [client 20.104.18.15:51088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/sallu.php"] [unique_id "apPl533lhEjKFiK_nBKCfQAAAcI"]
[Sun Aug 30 03:12:23.234813 2026] [security2:error] [pid 521505:tid 521720] [client 20.48.160.90:37787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/kjyehoxl.php"] [unique_id "apPl528byYE0iXl--K6gmwAAA3M"]
[Sun Aug 30 03:12:23.283872 2026] [security2:error] [pid 521505:tid 521640] [client 20.48.160.90:50449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/btx25.php"] [unique_id "apPl528byYE0iXl--K6gnAAAAyM"]
[Sun Aug 30 03:12:23.298743 2026] [authz_core:error] [pid 521505:tid 521742] [client 66.249.66.72:60695] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:23.299020 2026] [authz_core:error] [pid 521505:tid 521742] [client 66.249.66.72:60695] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:23.313321 2026] [security2:error] [pid 521505:tid 521744] [client 20.48.251.3:59508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/drykl.php"] [unique_id "apPl528byYE0iXl--K6gnwAAA4s"]
[Sun Aug 30 03:12:23.318186 2026] [security2:error] [pid 524122:tid 524312] [client 4.205.62.107:16367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/vx.php"] [unique_id "apPl533lhEjKFiK_nBKCfwAAAco"]
[Sun Aug 30 03:12:23.354316 2026] [security2:error] [pid 524122:tid 524341] [client 158.23.147.79:39944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apPl533lhEjKFiK_nBKCgAAAAec"]
[Sun Aug 30 03:12:23.354665 2026] [security2:error] [pid 521505:tid 521635] [client 20.48.251.3:55793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/wp-tem.php"] [unique_id "apPl528byYE0iXl--K6goQAAAx4"]
[Sun Aug 30 03:12:23.359409 2026] [security2:error] [pid 524122:tid 524254] [client 20.48.251.3:46180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/aws.php"] [unique_id "apPl533lhEjKFiK_nBKCgQAAAZA"]
[Sun Aug 30 03:12:23.364634 2026] [security2:error] [pid 524122:tid 524275] [client 4.205.62.107:15958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/guk.php"] [unique_id "apPl533lhEjKFiK_nBKCggAAAaU"]
[Sun Aug 30 03:12:23.378436 2026] [security2:error] [pid 524122:tid 524378] [client 20.104.18.15:64747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iamthevoiceofonecallinginthewilderness.com"] [uri "/reviall.php"] [unique_id "apPl533lhEjKFiK_nBKChAAAAgw"]
[Sun Aug 30 03:12:23.381993 2026] [authz_core:error] [pid 521505:tid 521681] [client 66.249.66.202:45757] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:23.382410 2026] [authz_core:error] [pid 521505:tid 521681] [client 66.249.66.202:45757] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:23.451264 2026] [security2:error] [pid 521505:tid 521678] [client 20.104.49.130:60664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/ws78.php"] [unique_id "apPl528byYE0iXl--K6gpwAAA0k"]
[Sun Aug 30 03:12:23.454572 2026] [security2:error] [pid 521505:tid 521664] [client 20.104.50.220:24847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/tires.php"] [unique_id "apPl528byYE0iXl--K6gqAAAAzs"]
[Sun Aug 30 03:12:23.488813 2026] [security2:error] [pid 521505:tid 521723] [client 20.104.49.130:53617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/002.php"] [unique_id "apPl528byYE0iXl--K6gqwAAA3Y"]
[Sun Aug 30 03:12:23.494584 2026] [security2:error] [pid 521505:tid 521732] [client 20.104.50.220:31499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wsd.php"] [unique_id "apPl528byYE0iXl--K6grQAAA38"]
[Sun Aug 30 03:12:23.497418 2026] [authz_core:error] [pid 521505:tid 521677] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory33
[Sun Aug 30 03:12:23.497683 2026] [authz_core:error] [pid 521505:tid 521677] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory33
[Sun Aug 30 03:12:23.502068 2026] [security2:error] [pid 521505:tid 521643] [client 20.48.251.3:36889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/rum.or.php"] [unique_id "apPl528byYE0iXl--K6grgAAAyY"]
[Sun Aug 30 03:12:23.503800 2026] [security2:error] [pid 521505:tid 521709] [client 20.104.50.220:28677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-includes/mailer.php"] [unique_id "apPl528byYE0iXl--K6grwAAA2g"]
[Sun Aug 30 03:12:23.530150 2026] [authz_core:error] [pid 521505:tid 521685] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:23.530423 2026] [authz_core:error] [pid 521505:tid 521685] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:23.539445 2026] [security2:error] [pid 521505:tid 521730] [client 20.151.200.44:43913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ermes-it.it"] [uri "/bge.php"] [unique_id "apPl528byYE0iXl--K6gsgAAA30"]
[Sun Aug 30 03:12:23.547721 2026] [security2:error] [pid 521505:tid 521658] [client 20.151.200.44:46070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/png.php"] [unique_id "apPl528byYE0iXl--K6gswAAAzU"]
[Sun Aug 30 03:12:23.570006 2026] [security2:error] [pid 521505:tid 521660] [client 158.23.147.79:40030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/goat1.php"] [unique_id "apPl528byYE0iXl--K6guAAAAzc"]
[Sun Aug 30 03:12:23.588324 2026] [security2:error] [pid 521505:tid 521639] [client 20.151.200.44:52108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/4e.php"] [unique_id "apPl528byYE0iXl--K6guQAAAyI"]
[Sun Aug 30 03:12:23.617623 2026] [security2:error] [pid 524122:tid 524269] [client 34.15.159.88:53818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/www/phpinfo.php"] [unique_id "apPl533lhEjKFiK_nBKChwAAAZ8"]
[Sun Aug 30 03:12:23.627534 2026] [security2:error] [pid 521505:tid 521693] [client 20.196.209.81:8553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/data.php"] [unique_id "apPl528byYE0iXl--K6guwAAA1g"]
[Sun Aug 30 03:12:23.629901 2026] [security2:error] [pid 521505:tid 521675] [client 95.108.213.202:49510] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "ourcalmchrysalis.com"] [uri "/robots.txt"] [unique_id "apPl528byYE0iXl--K6gvAAAA0Y"]
[Sun Aug 30 03:12:23.645750 2026] [security2:error] [pid 521505:tid 521712] [client 158.23.147.79:16327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apPl528byYE0iXl--K6gvgAAA2s"]
[Sun Aug 30 03:12:23.661475 2026] [security2:error] [pid 524122:tid 524345] [client 20.104.50.220:5528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/60.php"] [unique_id "apPl533lhEjKFiK_nBKCiAAAAes"]
[Sun Aug 30 03:12:23.690323 2026] [security2:error] [pid 521505:tid 521652] [client 35.247.242.193:56070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/site/phpinfo.php"] [unique_id "apPl528byYE0iXl--K6gwgAAAy8"]
[Sun Aug 30 03:12:23.710494 2026] [security2:error] [pid 521505:tid 521706] [client 4.205.62.107:52842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/nlnub.php"] [unique_id "apPl528byYE0iXl--K6gwwAAA2U"]
[Sun Aug 30 03:12:23.730050 2026] [security2:error] [pid 521505:tid 521659] [client 20.104.18.15:18295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/rxr.php"] [unique_id "apPl528byYE0iXl--K6gxAAAAzY"]
[Sun Aug 30 03:12:23.736365 2026] [security2:error] [pid 521505:tid 521726] [client 20.151.200.44:26558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/admin.php/007x.php"] [unique_id "apPl528byYE0iXl--K6gxQAAA3k"]
[Sun Aug 30 03:12:23.749793 2026] [authz_core:error] [pid 521505:tid 521669] [client 66.249.66.42:58721] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:23.750059 2026] [authz_core:error] [pid 521505:tid 521669] [client 66.249.66.42:58721] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:23.754906 2026] [security2:error] [pid 521505:tid 521731] [client 20.151.200.44:43976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ermes-it.it"] [uri "/ssh3ll.php"] [unique_id "apPl528byYE0iXl--K6gxwAAA34"]
[Sun Aug 30 03:12:23.839251 2026] [security2:error] [pid 521505:tid 521641] [client 158.23.147.79:40042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apPl528byYE0iXl--K6gzAAAAyQ"]
[Sun Aug 30 03:12:23.890627 2026] [security2:error] [pid 521505:tid 521705] [client 20.104.50.220:29132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/dada.php"] [unique_id "apPl528byYE0iXl--K6gzwAAA2Q"]
[Sun Aug 30 03:12:23.913506 2026] [security2:error] [pid 521505:tid 521663] [client 20.104.50.220:59581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/file4.php"] [unique_id "apPl528byYE0iXl--K6g0AAAAzo"]
[Sun Aug 30 03:12:23.930684 2026] [security2:error] [pid 521505:tid 521688] [client 4.205.62.107:25886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/tax.php"] [unique_id "apPl528byYE0iXl--K6g0gAAA1M"]
[Sun Aug 30 03:12:23.974809 2026] [authz_core:error] [pid 521505:tid 521689] [client 66.249.66.74:62401] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:23.975252 2026] [authz_core:error] [pid 521505:tid 521689] [client 66.249.66.74:62401] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:23.983978 2026] [authz_core:error] [pid 521505:tid 521654] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory10
[Sun Aug 30 03:12:23.984172 2026] [security2:error] [pid 521505:tid 521687] [client 158.23.147.79:40042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-admin/network/index.php"] [unique_id "apPl528byYE0iXl--K6g1wAAA1I"]
[Sun Aug 30 03:12:23.984408 2026] [authz_core:error] [pid 521505:tid 521654] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory10
[Sun Aug 30 03:12:24.011237 2026] [security2:error] [pid 521505:tid 521721] [client 20.104.50.220:63498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/json-php.php"] [unique_id "apPl6G8byYE0iXl--K6g2AAAA3Q"]
[Sun Aug 30 03:12:24.022977 2026] [authz_core:error] [pid 521505:tid 521651] [client 216.73.216.128:16328] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:24.023291 2026] [authz_core:error] [pid 521505:tid 521651] [client 216.73.216.128:16328] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:24.048288 2026] [security2:error] [pid 521505:tid 521647] [client 20.196.209.81:20948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/dt-the7/css/static-less/plugins/admin.php"] [unique_id "apPl6G8byYE0iXl--K6g2gAAAyo"]
[Sun Aug 30 03:12:24.062378 2026] [security2:error] [pid 521505:tid 521753] [client 20.104.18.15:22467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/ops.php"] [unique_id "apPl6G8byYE0iXl--K6g2wAAA5Q"]
[Sun Aug 30 03:12:24.105462 2026] [security2:error] [pid 521505:tid 521739] [client 20.151.200.44:43975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ermes-it.it"] [uri "/motu.php"] [unique_id "apPl6G8byYE0iXl--K6g3QAAA4Y"]
[Sun Aug 30 03:12:24.106176 2026] [security2:error] [pid 524122:tid 524290] [client 216.73.216.128:14524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPl6H3lhEjKFiK_nBKCjAAAAbQ"]
[Sun Aug 30 03:12:24.147455 2026] [security2:error] [pid 521505:tid 521667] [client 20.104.50.220:17307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/atomlib.php.suspected"] [unique_id "apPl6G8byYE0iXl--K6g3gAAAz4"]
[Sun Aug 30 03:12:24.169854 2026] [authz_core:error] [pid 521505:tid 521672] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:24.169975 2026] [security2:error] [pid 521505:tid 521744] [client 4.205.62.107:17321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/rpk.php"] [unique_id "apPl6G8byYE0iXl--K6g4AAAA4s"]
[Sun Aug 30 03:12:24.170128 2026] [authz_core:error] [pid 521505:tid 521672] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:24.181455 2026] [security2:error] [pid 521505:tid 521661] [client 35.247.242.193:36208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/docs/phpinfo.php"] [unique_id "apPl6G8byYE0iXl--K6g4QAAAzg"]
[Sun Aug 30 03:12:24.202691 2026] [security2:error] [pid 521505:tid 521743] [client 20.104.18.15:2018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/blacks.php"] [unique_id "apPl6G8byYE0iXl--K6g4wAAA4o"]
[Sun Aug 30 03:12:24.224983 2026] [security2:error] [pid 521505:tid 521717] [client 34.15.159.88:53830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/htdocs/phpinfo.php"] [unique_id "apPl6G8byYE0iXl--K6g5AAAA3A"]
[Sun Aug 30 03:12:24.285851 2026] [security2:error] [pid 521505:tid 521723] [client 20.151.200.44:43982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ermes-it.it"] [uri "/wefile.php"] [unique_id "apPl6G8byYE0iXl--K6g5wAAA3Y"]
[Sun Aug 30 03:12:24.288063 2026] [security2:error] [pid 521505:tid 521740] [client 216.73.216.128:4481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPl6G8byYE0iXl--K6g6QAAA4c"]
[Sun Aug 30 03:12:24.328291 2026] [security2:error] [pid 524122:tid 524260] [client 20.104.49.130:43614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/3.php"] [unique_id "apPl6H3lhEjKFiK_nBKCkAAAAZY"]
[Sun Aug 30 03:12:24.336381 2026] [security2:error] [pid 524122:tid 524282] [client 158.23.147.79:16277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/packed.php"] [unique_id "apPl6H3lhEjKFiK_nBKCkQAAAaw"]
[Sun Aug 30 03:12:24.348278 2026] [security2:error] [pid 524122:tid 524380] [client 158.23.147.79:40028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apPl6H3lhEjKFiK_nBKCkwAAAg4"]
[Sun Aug 30 03:12:24.370322 2026] [security2:error] [pid 521505:tid 521648] [client 20.104.18.15:51177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/codex.php"] [unique_id "apPl6G8byYE0iXl--K6g7gAAAys"]
[Sun Aug 30 03:12:24.377865 2026] [security2:error] [pid 521505:tid 521702] [client 20.104.50.220:33293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/1index.php"] [unique_id "apPl6G8byYE0iXl--K6g8QAAA2E"]
[Sun Aug 30 03:12:24.411589 2026] [authz_core:error] [pid 521505:tid 521665] [client 66.249.66.71:60014] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:24.411856 2026] [authz_core:error] [pid 521505:tid 521665] [client 66.249.66.71:60014] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:24.415796 2026] [security2:error] [pid 521505:tid 521715] [client 20.104.49.130:60648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/ws58.php"] [unique_id "apPl6G8byYE0iXl--K6g8wAAA24"]
[Sun Aug 30 03:12:24.440372 2026] [security2:error] [pid 521505:tid 521694] [client 20.196.209.81:9000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/hideo/network.php"] [unique_id "apPl6G8byYE0iXl--K6g9AAAA1k"]
[Sun Aug 30 03:12:24.455516 2026] [security2:error] [pid 524122:tid 524323] [client 4.205.62.107:15870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/ty.php"] [unique_id "apPl6H3lhEjKFiK_nBKClgAAAdU"]
[Sun Aug 30 03:12:24.466386 2026] [authz_core:error] [pid 521505:tid 521682] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory30
[Sun Aug 30 03:12:24.466831 2026] [authz_core:error] [pid 521505:tid 521682] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory30
[Sun Aug 30 03:12:24.467587 2026] [security2:error] [pid 524122:tid 524291] [client 20.48.251.3:43050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/rpk.php"] [unique_id "apPl6H3lhEjKFiK_nBKClwAAAbU"]
[Sun Aug 30 03:12:24.470684 2026] [security2:error] [pid 521505:tid 521677] [client 20.151.200.44:52034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/ssss.php"] [unique_id "apPl6G8byYE0iXl--K6g9wAAA0g"]
[Sun Aug 30 03:12:24.479939 2026] [authz_core:error] [pid 521505:tid 521693] [client 66.249.66.69:58494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:24.480210 2026] [authz_core:error] [pid 521505:tid 521693] [client 66.249.66.69:58494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:24.492690 2026] [security2:error] [pid 521505:tid 521727] [client 20.48.251.3:59314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/txets.php"] [unique_id "apPl6G8byYE0iXl--K6g-QAAA3o"]
[Sun Aug 30 03:12:24.509060 2026] [security2:error] [pid 524122:tid 524309] [client 20.48.251.3:54824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/app.default.php"] [unique_id "apPl6H3lhEjKFiK_nBKCmAAAAcc"]
[Sun Aug 30 03:12:24.516302 2026] [security2:error] [pid 524122:tid 524338] [client 4.205.62.107:15990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/config_dev.php"] [unique_id "apPl6H3lhEjKFiK_nBKCmQAAAeQ"]
[Sun Aug 30 03:12:24.556983 2026] [authz_core:error] [pid 521505:tid 521659] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:24.557331 2026] [authz_core:error] [pid 521505:tid 521659] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:24.638166 2026] [security2:error] [pid 521505:tid 521722] [client 20.48.251.3:37135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/xmy.php"] [unique_id "apPl6G8byYE0iXl--K6g_gAAA3U"]
[Sun Aug 30 03:12:24.652110 2026] [security2:error] [pid 524122:tid 524281] [client 20.104.50.220:31527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/gtc.php"] [unique_id "apPl6H3lhEjKFiK_nBKCnQAAAas"]
[Sun Aug 30 03:12:24.663659 2026] [security2:error] [pid 521505:tid 521652] [client 35.247.242.193:36216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "apPl6G8byYE0iXl--K6g_wAAAy8"]
[Sun Aug 30 03:12:24.666017 2026] [security2:error] [pid 524122:tid 524305] [client 158.23.147.79:40062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/.well-knownold/index.php"] [unique_id "apPl6H3lhEjKFiK_nBKCnwAAAcM"]
[Sun Aug 30 03:12:24.667081 2026] [security2:error] [pid 521505:tid 521690] [client 20.104.50.220:29157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/ym.php"] [unique_id "apPl6G8byYE0iXl--K6hAQAAA1U"]
[Sun Aug 30 03:12:24.723386 2026] [security2:error] [pid 524122:tid 524362] [client 20.104.50.220:24867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/.well-known/about.php"] [unique_id "apPl6H3lhEjKFiK_nBKCoAAAAfw"]
[Sun Aug 30 03:12:24.731612 2026] [authz_core:error] [pid 521505:tid 521699] [client 66.249.66.71:41418] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:24.731992 2026] [authz_core:error] [pid 521505:tid 521699] [client 66.249.66.71:41418] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:24.795149 2026] [security2:error] [pid 524122:tid 524294] [client 20.104.50.220:6087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/58.php"] [unique_id "apPl6H3lhEjKFiK_nBKCoQAAAbg"]
[Sun Aug 30 03:12:24.813006 2026] [security2:error] [pid 521505:tid 521688] [client 158.23.147.79:40041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apPl6G8byYE0iXl--K6hCAAAA1M"]
[Sun Aug 30 03:12:24.815737 2026] [authz_core:error] [pid 521505:tid 521718] [client 66.249.66.73:37139] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:24.816156 2026] [authz_core:error] [pid 521505:tid 521718] [client 66.249.66.73:37139] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:24.830446 2026] [security2:error] [pid 524122:tid 524274] [client 20.196.209.81:20950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPl6H3lhEjKFiK_nBKCogAAAaQ"]
[Sun Aug 30 03:12:24.834095 2026] [security2:error] [pid 521505:tid 521758] [client 34.15.159.88:53836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/public_html/phpinfo.php"] [unique_id "apPl6G8byYE0iXl--K6hCQAAA5k"]
[Sun Aug 30 03:12:24.848838 2026] [security2:error] [pid 521505:tid 521729] [client 4.205.62.107:52870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/mga.php"] [unique_id "apPl6G8byYE0iXl--K6hCwAAA3w"]
[Sun Aug 30 03:12:24.875532 2026] [security2:error] [pid 521505:tid 521676] [client 20.104.18.15:18408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.dallasfortworthbreastthermography.com"] [uri "/reviall.php"] [unique_id "apPl6G8byYE0iXl--K6hDgAAA0c"]
[Sun Aug 30 03:12:24.927719 2026] [authz_core:error] [pid 521505:tid 521707] [client 66.249.66.71:49975] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:24.927988 2026] [authz_core:error] [pid 521505:tid 521707] [client 66.249.66.71:49975] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:24.982773 2026] [authz_core:error] [pid 521505:tid 521673] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory10
[Sun Aug 30 03:12:24.983033 2026] [authz_core:error] [pid 521505:tid 521673] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory10
[Sun Aug 30 03:12:25.026390 2026] [security2:error] [pid 521505:tid 521655] [client 158.23.147.79:39936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPl6W8byYE0iXl--K6hFQAAAzI"]
[Sun Aug 30 03:12:25.037986 2026] [authz_core:error] [pid 521505:tid 521753] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:25.038384 2026] [authz_core:error] [pid 521505:tid 521753] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:25.065483 2026] [security2:error] [pid 521505:tid 521749] [client 20.104.50.220:61638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/520.php"] [unique_id "apPl6W8byYE0iXl--K6hFwAAA5A"]
[Sun Aug 30 03:12:25.118451 2026] [authz_core:error] [pid 521505:tid 521651] [client 66.249.66.199:58076] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:25.118870 2026] [authz_core:error] [pid 521505:tid 521651] [client 66.249.66.199:58076] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:25.150033 2026] [security2:error] [pid 521505:tid 521654] [client 20.104.50.220:52825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/xml.php"] [unique_id "apPl6W8byYE0iXl--K6hGwAAAzE"]
[Sun Aug 30 03:12:25.150491 2026] [security2:error] [pid 521505:tid 521755] [client 20.104.50.220:51644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/0x0.php"] [unique_id "apPl6W8byYE0iXl--K6hHAAAA5Y"]
[Sun Aug 30 03:12:25.151980 2026] [security2:error] [pid 521505:tid 521721] [client 35.247.242.193:36232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/administrator/phpinfo.php"] [unique_id "apPl6W8byYE0iXl--K6hHQAAA3Q"]
[Sun Aug 30 03:12:25.158843 2026] [security2:error] [pid 521505:tid 521744] [client 4.205.62.107:25787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPl6W8byYE0iXl--K6hHgAAA4s"]
[Sun Aug 30 03:12:25.190823 2026] [security2:error] [pid 524122:tid 524258] [client 158.23.147.79:21447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/images/index.php"] [unique_id "apPl6X3lhEjKFiK_nBKCqAAAAZQ"]
[Sun Aug 30 03:12:25.205371 2026] [security2:error] [pid 524122:tid 524270] [client 20.104.18.15:22514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/BDKR28WP.php"] [unique_id "apPl6X3lhEjKFiK_nBKCqQAAAaA"]
[Sun Aug 30 03:12:25.229474 2026] [security2:error] [pid 524122:tid 524369] [client 20.104.49.130:60633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/jp.php"] [unique_id "apPl6X3lhEjKFiK_nBKCqgAAAgM"]
[Sun Aug 30 03:12:25.231571 2026] [security2:error] [pid 521505:tid 521679] [client 20.196.209.81:20987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/intense/block-css.php"] [unique_id "apPl6W8byYE0iXl--K6hIQAAA0o"]
[Sun Aug 30 03:12:25.247372 2026] [security2:error] [pid 524122:tid 524288] [client 20.104.49.130:53518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/ws78.php"] [unique_id "apPl6X3lhEjKFiK_nBKCqwAAAbI"]
[Sun Aug 30 03:12:25.280247 2026] [security2:error] [pid 524122:tid 524279] [client 20.104.50.220:16622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/ehszwsab.php"] [unique_id "apPl6X3lhEjKFiK_nBKCrQAAAak"]
[Sun Aug 30 03:12:25.308319 2026] [security2:error] [pid 521505:tid 521725] [client 4.205.62.107:17310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/saml.php"] [unique_id "apPl6W8byYE0iXl--K6hIwAAA3g"]
[Sun Aug 30 03:12:25.343210 2026] [security2:error] [pid 521505:tid 521745] [client 20.104.18.15:1953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/wp.php"] [unique_id "apPl6W8byYE0iXl--K6hJQAAA4w"]
[Sun Aug 30 03:12:25.394824 2026] [security2:error] [pid 521505:tid 521650] [client 158.23.147.79:40061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apPl6W8byYE0iXl--K6hKAAAAy0"]
[Sun Aug 30 03:12:25.431488 2026] [security2:error] [pid 521505:tid 521711] [client 158.23.184.117:18394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/bgymj.php"] [unique_id "apPl6W8byYE0iXl--K6hKQAAA2o"]
[Sun Aug 30 03:12:25.442873 2026] [security2:error] [pid 524122:tid 524324] [client 34.15.159.88:53848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/site/phpinfo.php"] [unique_id "apPl6X3lhEjKFiK_nBKCsAAAAdY"]
[Sun Aug 30 03:12:25.483581 2026] [security2:error] [pid 521505:tid 521643] [client 158.23.184.117:18007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/bk/index.php"] [unique_id "apPl6W8byYE0iXl--K6hLQAAAyY"]
[Sun Aug 30 03:12:25.504762 2026] [authz_core:error] [pid 521505:tid 521702] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory31
[Sun Aug 30 03:12:25.505041 2026] [authz_core:error] [pid 521505:tid 521702] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory31
[Sun Aug 30 03:12:25.522697 2026] [security2:error] [pid 524122:tid 524370] [client 20.104.18.15:51104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/5656.php"] [unique_id "apPl6X3lhEjKFiK_nBKCtAAAAgQ"]
[Sun Aug 30 03:12:25.523626 2026] [authz_core:error] [pid 524122:tid 524302] [client 66.249.66.78:42783] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:25.524067 2026] [authz_core:error] [pid 524122:tid 524302] [client 66.249.66.78:42783] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:25.539163 2026] [autoindex:error] [pid 524122:tid 524326] [client 3.151.194.164:40539] AH01276: Cannot serve directory /home1/mediacoa/public_html/testing/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:12:25.540838 2026] [security2:error] [pid 524122:tid 524314] [client 20.104.50.220:32892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/22xc.php"] [unique_id "apPl6X3lhEjKFiK_nBKCtgAAAcw"]
[Sun Aug 30 03:12:25.565066 2026] [authz_core:error] [pid 521505:tid 521715] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:25.565340 2026] [authz_core:error] [pid 521505:tid 521715] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:25.587404 2026] [security2:error] [pid 524122:tid 524265] [client 158.23.147.79:39997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apPl6X3lhEjKFiK_nBKCuQAAAZs"]
[Sun Aug 30 03:12:25.609384 2026] [security2:error] [pid 524122:tid 524375] [client 4.205.62.107:15982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/adminer-4.7.6-en.php"] [unique_id "apPl6X3lhEjKFiK_nBKCugAAAgk"]
[Sun Aug 30 03:12:25.624723 2026] [security2:error] [pid 524122:tid 524330] [client 20.196.209.81:8243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/login.php"] [unique_id "apPl6X3lhEjKFiK_nBKCuwAAAdw"]
[Sun Aug 30 03:12:25.627250 2026] [security2:error] [pid 524122:tid 524336] [client 158.23.184.117:18381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/bootstrap.php"] [unique_id "apPl6X3lhEjKFiK_nBKCvAAAAeI"]
[Sun Aug 30 03:12:25.629776 2026] [security2:error] [pid 524122:tid 524256] [client 20.104.49.130:60623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/ws45.php"] [unique_id "apPl6X3lhEjKFiK_nBKCvQAAAZI"]
[Sun Aug 30 03:12:25.638431 2026] [security2:error] [pid 521505:tid 521648] [client 35.247.242.193:36238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/core/phpinfo.php"] [unique_id "apPl6W8byYE0iXl--K6hMgAAAys"]
[Sun Aug 30 03:12:25.657030 2026] [security2:error] [pid 524122:tid 524379] [client 4.205.62.107:16342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/aws_credentials.php"] [unique_id "apPl6X3lhEjKFiK_nBKCvgAAAg0"]
[Sun Aug 30 03:12:25.661449 2026] [authz_core:error] [pid 521505:tid 521712] [client 216.73.216.128:16328] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:25.661720 2026] [authz_core:error] [pid 521505:tid 521712] [client 216.73.216.128:16328] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:25.676714 2026] [security2:error] [pid 524122:tid 524301] [client 20.48.251.3:55716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/time.php"] [unique_id "apPl6X3lhEjKFiK_nBKCwAAAAb8"]
[Sun Aug 30 03:12:25.676781 2026] [authz_core:error] [pid 524122:tid 524353] [client 66.249.66.73:35264] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:25.677093 2026] [authz_core:error] [pid 524122:tid 524353] [client 66.249.66.73:35264] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:25.679999 2026] [security2:error] [pid 524122:tid 524312] [client 20.48.251.3:65481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/app_local.php"] [unique_id "apPl6X3lhEjKFiK_nBKCwQAAAco"]
[Sun Aug 30 03:12:25.738167 2026] [security2:error] [pid 524122:tid 524257] [client 20.48.251.3:59492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/saml.php"] [unique_id "apPl6X3lhEjKFiK_nBKCwgAAAZM"]
[Sun Aug 30 03:12:25.772266 2026] [security2:error] [pid 521505:tid 521694] [client 158.23.184.117:18371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/bs1.php"] [unique_id "apPl6W8byYE0iXl--K6hNQAAA1k"]
[Sun Aug 30 03:12:25.780395 2026] [security2:error] [pid 521505:tid 521677] [client 20.48.251.3:37155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/ms-edit.php"] [unique_id "apPl6W8byYE0iXl--K6hNgAAA0g"]
[Sun Aug 30 03:12:25.807102 2026] [security2:error] [pid 521505:tid 521706] [client 20.104.50.220:31505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/atx.php"] [unique_id "apPl6W8byYE0iXl--K6hNwAAA2U"]
[Sun Aug 30 03:12:25.841073 2026] [security2:error] [pid 521505:tid 521645] [client 20.104.50.220:64450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/alfa1.php"] [unique_id "apPl6W8byYE0iXl--K6hOgAAAyg"]
[Sun Aug 30 03:12:25.842940 2026] [security2:error] [pid 524122:tid 524365] [client 158.23.147.79:21452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apPl6X3lhEjKFiK_nBKCwwAAAf8"]
[Sun Aug 30 03:12:25.868081 2026] [security2:error] [pid 521505:tid 521682] [client 20.104.50.220:25455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "apPl6W8byYE0iXl--K6hPAAAA00"]
[Sun Aug 30 03:12:25.914799 2026] [security2:error] [pid 521505:tid 521748] [client 158.23.184.117:18410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/bthil.php"] [unique_id "apPl6W8byYE0iXl--K6hPQAAA48"]
[Sun Aug 30 03:12:25.965082 2026] [security2:error] [pid 524122:tid 524319] [client 20.151.200.44:52068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/zoz.php"] [unique_id "apPl6X3lhEjKFiK_nBKCxAAAAdE"]
[Sun Aug 30 03:12:25.965093 2026] [authz_core:error] [pid 521505:tid 521714] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory30
[Sun Aug 30 03:12:25.965384 2026] [authz_core:error] [pid 521505:tid 521714] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory30
[Sun Aug 30 03:12:26.000040 2026] [security2:error] [pid 521505:tid 521713] [client 4.205.62.107:29153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/ccou.php"] [unique_id "apPl6W8byYE0iXl--K6hQQAAA2w"]
[Sun Aug 30 03:12:26.015478 2026] [security2:error] [pid 521505:tid 521695] [client 20.104.50.220:5467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/59.php"] [unique_id "apPl6m8byYE0iXl--K6hQgAAA1o"]
[Sun Aug 30 03:12:26.022189 2026] [security2:error] [pid 521505:tid 521663] [client 20.151.200.44:26525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/admin.php/heex.php"] [unique_id "apPl6m8byYE0iXl--K6hQwAAAzo"]
[Sun Aug 30 03:12:26.034773 2026] [authz_core:error] [pid 524122:tid 524316] [client 66.249.66.200:58758] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:26.035054 2026] [authz_core:error] [pid 524122:tid 524316] [client 66.249.66.200:58758] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:26.044605 2026] [security2:error] [pid 524122:tid 524331] [client 20.196.209.81:8977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/min.php"] [unique_id "apPl6n3lhEjKFiK_nBKCyAAAAd0"]
[Sun Aug 30 03:12:26.047243 2026] [authz_core:error] [pid 521505:tid 521688] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:26.047505 2026] [authz_core:error] [pid 521505:tid 521688] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:26.056729 2026] [security2:error] [pid 521505:tid 521668] [client 158.23.184.117:17997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/buy.php"] [unique_id "apPl6m8byYE0iXl--K6hRgAAAz8"]
[Sun Aug 30 03:12:26.080150 2026] [security2:error] [pid 521505:tid 521690] [client 34.15.159.88:53860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/docs/phpinfo.php"] [unique_id "apPl6m8byYE0iXl--K6hRwAAA1U"]
[Sun Aug 30 03:12:26.135147 2026] [security2:error] [pid 521505:tid 521733] [client 35.247.242.193:36246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.242.247.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5208c.filtagreen.com"] [uri "/includes/phpinfo.php"] [unique_id "apPl6m8byYE0iXl--K6hSgAAA4A"]
[Sun Aug 30 03:12:26.199424 2026] [security2:error] [pid 521505:tid 521750] [client 158.23.184.117:17985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/byp.php"] [unique_id "apPl6m8byYE0iXl--K6hSwAAA5E"]
[Sun Aug 30 03:12:26.205567 2026] [security2:error] [pid 521505:tid 521681] [client 158.23.147.79:40055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apPl6m8byYE0iXl--K6hTAAAA0w"]
[Sun Aug 30 03:12:26.229506 2026] [security2:error] [pid 521505:tid 521687] [client 20.104.50.220:59550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/file18.php"] [unique_id "apPl6m8byYE0iXl--K6hTgAAA1I"]
[Sun Aug 30 03:12:26.273078 2026] [security2:error] [pid 521505:tid 521701] [client 20.104.49.130:36750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/ws58.php"] [unique_id "apPl6m8byYE0iXl--K6hTwAAA2A"]
[Sun Aug 30 03:12:26.331533 2026] [security2:error] [pid 521505:tid 521699] [client 20.104.49.130:48032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/ortasekerli1.php"] [unique_id "apPl6m8byYE0iXl--K6hVAAAA14"]
[Sun Aug 30 03:12:26.337252 2026] [security2:error] [pid 521505:tid 521644] [client 158.23.184.117:18421] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpanel.djsevenevents.com"] [uri "/c99.php"] [unique_id "apPl6m8byYE0iXl--K6hVQAAAyc"]
[Sun Aug 30 03:12:26.338590 2026] [security2:error] [pid 521505:tid 521761] [client 20.104.50.220:42793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/0z.php"] [unique_id "apPl6m8byYE0iXl--K6hVgAAA5w"]
[Sun Aug 30 03:12:26.344450 2026] [security2:error] [pid 521505:tid 521753] [client 20.104.18.15:22482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/k.php"] [unique_id "apPl6m8byYE0iXl--K6hVwAAA5Q"]
[Sun Aug 30 03:12:26.371745 2026] [security2:error] [pid 521505:tid 521738] [client 20.104.50.220:52826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/xm.php"] [unique_id "apPl6m8byYE0iXl--K6hWgAAA4U"]
[Sun Aug 30 03:12:26.372484 2026] [security2:error] [pid 524122:tid 524346] [client 158.23.147.79:16366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-content/packed.php"] [unique_id "apPl6n3lhEjKFiK_nBKCzwAAAew"]
[Sun Aug 30 03:12:26.384927 2026] [security2:error] [pid 521505:tid 521759] [client 4.205.62.107:25708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPl6m8byYE0iXl--K6hWwAAA5o"]
[Sun Aug 30 03:12:26.391866 2026] [security2:error] [pid 521505:tid 521679] [client 158.23.184.117:34224] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "orders.lastmaskcenter.org"] [uri "/1.php"] [unique_id "apPl6m8byYE0iXl--K6hXAAAA0o"]
[Sun Aug 30 03:12:26.391992 2026] [security2:error] [pid 521505:tid 521679] [client 158.23.184.117:34224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/1.php"] [unique_id "apPl6m8byYE0iXl--K6hXAAAA0o"]
[Sun Aug 30 03:12:26.399027 2026] [authz_core:error] [pid 524122:tid 524354] [client 66.249.66.203:38927] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:26.399323 2026] [authz_core:error] [pid 524122:tid 524354] [client 66.249.66.203:38927] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:26.405779 2026] [security2:error] [pid 521505:tid 521725] [client 20.104.50.220:16726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/meta.php"] [unique_id "apPl6m8byYE0iXl--K6hXQAAA3g"]
[Sun Aug 30 03:12:26.437342 2026] [security2:error] [pid 521505:tid 521755] [client 20.196.209.81:8988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/module.php"] [unique_id "apPl6m8byYE0iXl--K6hXwAAA5Y"]
[Sun Aug 30 03:12:26.441639 2026] [security2:error] [pid 524122:tid 524323] [client 158.23.184.117:34620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/2.php"] [unique_id "apPl6n3lhEjKFiK_nBKC0QAAAdU"]
[Sun Aug 30 03:12:26.445236 2026] [authz_core:error] [pid 521505:tid 521672] [client 216.73.216.128:57628] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:26.445501 2026] [authz_core:error] [pid 521505:tid 521672] [client 216.73.216.128:57628] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:26.445679 2026] [security2:error] [pid 521505:tid 521664] [client 4.205.62.107:17669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/aws_settings.php"] [unique_id "apPl6m8byYE0iXl--K6hYQAAAzs"]
[Sun Aug 30 03:12:26.478286 2026] [security2:error] [pid 521505:tid 521756] [client 20.104.18.15:1924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/wander.php"] [unique_id "apPl6m8byYE0iXl--K6hYwAAA5c"]
[Sun Aug 30 03:12:26.493176 2026] [authz_core:error] [pid 521505:tid 521642] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory30
[Sun Aug 30 03:12:26.493556 2026] [authz_core:error] [pid 521505:tid 521642] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory30
[Sun Aug 30 03:12:26.497271 2026] [security2:error] [pid 521505:tid 521732] [client 20.151.200.44:46035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/txets.php"] [unique_id "apPl6m8byYE0iXl--K6hZQAAA38"]
[Sun Aug 30 03:12:26.498261 2026] [security2:error] [pid 521505:tid 521707] [client 158.23.184.117:17992] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpanel.djsevenevents.com"] [uri "/c99.php"] [unique_id "apPl6m8byYE0iXl--K6hZgAAA2Y"]
[Sun Aug 30 03:12:26.529542 2026] [authz_core:error] [pid 521505:tid 521638] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:26.529842 2026] [authz_core:error] [pid 521505:tid 521638] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:26.553734 2026] [security2:error] [pid 521505:tid 521662] [client 158.23.147.79:39982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/nf_tracking.php"] [unique_id "apPl6m8byYE0iXl--K6haAAAAzk"]
[Sun Aug 30 03:12:26.562308 2026] [authz_core:error] [pid 521505:tid 521698] [client 66.249.66.203:54411] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:26.562571 2026] [authz_core:error] [pid 521505:tid 521698] [client 66.249.66.203:54411] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:26.580933 2026] [security2:error] [pid 521505:tid 521653] [client 158.23.184.117:34224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/7.php"] [unique_id "apPl6m8byYE0iXl--K6hawAAAzA"]
[Sun Aug 30 03:12:26.642602 2026] [security2:error] [pid 521505:tid 521751] [client 158.23.184.117:18388] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpanel.djsevenevents.com"] [uri "/c99.php"] [unique_id "apPl6m8byYE0iXl--K6hbgAAA5I"]
[Sun Aug 30 03:12:26.668701 2026] [security2:error] [pid 521505:tid 521694] [client 20.151.200.44:52112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/kcs.php"] [unique_id "apPl6m8byYE0iXl--K6hcAAAA1k"]
[Sun Aug 30 03:12:26.671769 2026] [security2:error] [pid 521505:tid 521677] [client 20.104.18.15:51099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/w3lls.php"] [unique_id "apPl6m8byYE0iXl--K6hcQAAA0g"]
[Sun Aug 30 03:12:26.689547 2026] [security2:error] [pid 521505:tid 521661] [client 34.15.159.88:53874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/wp-admin/phpinfo.php"] [unique_id "apPl6m8byYE0iXl--K6hcgAAAzg"]
[Sun Aug 30 03:12:26.693042 2026] [security2:error] [pid 521505:tid 521727] [client 20.104.50.220:32846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/26.php"] [unique_id "apPl6m8byYE0iXl--K6hcwAAA3o"]
[Sun Aug 30 03:12:26.702022 2026] [security2:error] [pid 521505:tid 521728] [client 20.151.200.44:26576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/tf.php"] [unique_id "apPl6m8byYE0iXl--K6hdAAAA3s"]
[Sun Aug 30 03:12:26.720063 2026] [security2:error] [pid 521505:tid 521685] [client 158.23.184.117:51661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/10.php"] [unique_id "apPl6m8byYE0iXl--K6hdgAAA1A"]
[Sun Aug 30 03:12:26.722164 2026] [authz_core:error] [pid 521505:tid 521706] [client 216.73.216.128:39217] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:26.722443 2026] [authz_core:error] [pid 521505:tid 521706] [client 216.73.216.128:39217] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:26.748347 2026] [security2:error] [pid 521505:tid 521680] [client 4.205.62.107:15830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/phpi.php"] [unique_id "apPl6m8byYE0iXl--K6hdwAAA0s"]
[Sun Aug 30 03:12:26.786310 2026] [security2:error] [pid 521505:tid 521712] [client 158.23.184.117:18382] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "cpanel.djsevenevents.com"] [uri "/c99.php"] [unique_id "apPl6m8byYE0iXl--K6hegAAA2s"]
[Sun Aug 30 03:12:26.798303 2026] [security2:error] [pid 524122:tid 524268] [client 4.205.62.107:15985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/aws-credentials.php"] [unique_id "apPl6n3lhEjKFiK_nBKC2AAAAZ4"]
[Sun Aug 30 03:12:26.814562 2026] [security2:error] [pid 521505:tid 521713] [client 20.48.251.3:55769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/doc.php"] [unique_id "apPl6m8byYE0iXl--K6hfAAAA2w"]
[Sun Aug 30 03:12:26.815490 2026] [security2:error] [pid 524122:tid 524281] [client 20.48.251.3:46226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/ws62.php"] [unique_id "apPl6n3lhEjKFiK_nBKC2QAAAas"]
[Sun Aug 30 03:12:26.868863 2026] [core:alert] [pid 521505:tid 521705] [client 102.209.221.87:5779] /home1/kfoudhhw/public_html/hiagtourism/.htaccess: directive missing closing '>', referer: http://hiagtourism.org/
[Sun Aug 30 03:12:26.873018 2026] [security2:error] [pid 524122:tid 524298] [client 20.48.251.3:40013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/aws_settings.php"] [unique_id "apPl6n3lhEjKFiK_nBKC2gAAAbw"]
[Sun Aug 30 03:12:26.877809 2026] [security2:error] [pid 524122:tid 524280] [client 158.23.184.117:51687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/13.php"] [unique_id "apPl6n3lhEjKFiK_nBKC2wAAAao"]
[Sun Aug 30 03:12:26.893539 2026] [security2:error] [pid 521505:tid 521736] [client 158.23.147.79:39973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wzy.php"] [unique_id "apPl6m8byYE0iXl--K6hgAAAA4M"]
[Sun Aug 30 03:12:26.903433 2026] [security2:error] [pid 521505:tid 521683] [client 20.196.209.81:8514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/ms-files.php"] [unique_id "apPl6m8byYE0iXl--K6hgQAAA04"]
[Sun Aug 30 03:12:26.917586 2026] [security2:error] [pid 521505:tid 521762] [client 20.48.251.3:37007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/sys.php"] [unique_id "apPl6m8byYE0iXl--K6hgwAAA50"]
[Sun Aug 30 03:12:26.945634 2026] [authz_core:error] [pid 521505:tid 521637] [client 216.73.216.128:39217] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:26.946172 2026] [authz_core:error] [pid 521505:tid 521637] [client 216.73.216.128:39217] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:26.979562 2026] [security2:error] [pid 524122:tid 524321] [client 20.104.50.220:31227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/z60.php"] [unique_id "apPl6n3lhEjKFiK_nBKC3QAAAdM"]
[Sun Aug 30 03:12:26.989677 2026] [security2:error] [pid 524122:tid 524274] [client 20.104.50.220:29570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/159.php"] [unique_id "apPl6n3lhEjKFiK_nBKC3gAAAaQ"]
[Sun Aug 30 03:12:26.996853 2026] [authz_core:error] [pid 521505:tid 521641] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory19
[Sun Aug 30 03:12:26.997112 2026] [authz_core:error] [pid 521505:tid 521641] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory19
[Sun Aug 30 03:12:27.023519 2026] [security2:error] [pid 524122:tid 524294] [client 158.23.184.117:51703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/100.php"] [unique_id "apPl633lhEjKFiK_nBKC3wAAAbg"]
[Sun Aug 30 03:12:27.026595 2026] [security2:error] [pid 524122:tid 524358] [client 20.104.49.130:60678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/t.php"] [unique_id "apPl633lhEjKFiK_nBKC4AAAAfg"]
[Sun Aug 30 03:12:27.041205 2026] [security2:error] [pid 521505:tid 521693] [client 20.104.50.220:25423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/bob.php"] [unique_id "apPl628byYE0iXl--K6higAAA1g"]
[Sun Aug 30 03:12:27.059476 2026] [authz_core:error] [pid 521505:tid 521757] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:27.059768 2026] [authz_core:error] [pid 521505:tid 521757] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:27.132041 2026] [authz_core:error] [pid 521505:tid 521667] [client 66.249.66.195:48957] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:27.132317 2026] [authz_core:error] [pid 521505:tid 521667] [client 66.249.66.195:48957] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:27.148195 2026] [security2:error] [pid 521505:tid 521749] [client 158.23.147.79:39949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apPl628byYE0iXl--K6hjwAAA5A"]
[Sun Aug 30 03:12:27.166178 2026] [security2:error] [pid 524122:tid 524322] [client 158.23.184.117:34214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/222.php"] [unique_id "apPl633lhEjKFiK_nBKC4wAAAdQ"]
[Sun Aug 30 03:12:27.170356 2026] [security2:error] [pid 521505:tid 521654] [client 20.104.50.220:6122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/57.php/56.php"] [unique_id "apPl628byYE0iXl--K6hkQAAAzE"]
[Sun Aug 30 03:12:27.187062 2026] [security2:error] [pid 521505:tid 521721] [client 4.205.62.107:52914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/rum.or.php"] [unique_id "apPl628byYE0iXl--K6hkgAAA3Q"]
[Sun Aug 30 03:12:27.191239 2026] [security2:error] [pid 521505:tid 521744] [client 20.151.200.44:52141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/tajj.php"] [unique_id "apPl628byYE0iXl--K6hkwAAA4s"]
[Sun Aug 30 03:12:27.202685 2026] [security2:error] [pid 521505:tid 521718] [client 158.23.184.117:18311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/cache/cache/min.php"] [unique_id "apPl628byYE0iXl--K6hlAAAA3E"]
[Sun Aug 30 03:12:27.293067 2026] [security2:error] [pid 524122:tid 524293] [client 34.15.159.88:53890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/administrator/phpinfo.php"] [unique_id "apPl633lhEjKFiK_nBKC5QAAAbc"]
[Sun Aug 30 03:12:27.302936 2026] [security2:error] [pid 521505:tid 521673] [client 20.196.209.81:20947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/news-portal/error.php"] [unique_id "apPl628byYE0iXl--K6hmAAAA0Q"]
[Sun Aug 30 03:12:27.304347 2026] [security2:error] [pid 521505:tid 521640] [client 158.23.184.117:51681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/adminfuns.php"] [unique_id "apPl628byYE0iXl--K6hmQAAAyM"]
[Sun Aug 30 03:12:27.342674 2026] [security2:error] [pid 521505:tid 521704] [client 158.23.147.79:16196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-l0gin.php"] [unique_id "apPl628byYE0iXl--K6hmgAAA2M"]
[Sun Aug 30 03:12:27.343144 2026] [security2:error] [pid 521505:tid 521666] [client 158.23.184.117:18427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/catalogbypass.php"] [unique_id "apPl628byYE0iXl--K6hmwAAAz0"]
[Sun Aug 30 03:12:27.369216 2026] [security2:error] [pid 521505:tid 521650] [client 20.151.200.44:52101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/bge.php"] [unique_id "apPl628byYE0iXl--K6hngAAAy0"]
[Sun Aug 30 03:12:27.371731 2026] [security2:error] [pid 521505:tid 521709] [client 158.23.147.79:21457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apPl628byYE0iXl--K6hnwAAA2g"]
[Sun Aug 30 03:12:27.375795 2026] [security2:error] [pid 521505:tid 521670] [client 20.151.200.44:43983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ermes-it.it"] [uri "/Contrller.php"] [unique_id "apPl628byYE0iXl--K6hoAAAA0E"]
[Sun Aug 30 03:12:27.382270 2026] [security2:error] [pid 524122:tid 524279] [client 20.104.50.220:61676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/ffile.php"] [unique_id "apPl633lhEjKFiK_nBKC5wAAAak"]
[Sun Aug 30 03:12:27.449226 2026] [security2:error] [pid 521505:tid 521730] [client 158.23.184.117:34575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/abcd.php"] [unique_id "apPl628byYE0iXl--K6hogAAA30"]
[Sun Aug 30 03:12:27.475365 2026] [security2:error] [pid 524122:tid 524292] [client 20.104.50.220:63530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/13.php"] [unique_id "apPl633lhEjKFiK_nBKC6QAAAbY"]
[Sun Aug 30 03:12:27.481303 2026] [security2:error] [pid 521505:tid 521658] [client 158.23.184.117:18396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/cc.php"] [unique_id "apPl628byYE0iXl--K6howAAAzU"]
[Sun Aug 30 03:12:27.484114 2026] [security2:error] [pid 521505:tid 521717] [client 20.104.18.15:22464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/dex.php"] [unique_id "apPl628byYE0iXl--K6hpQAAA3A"]
[Sun Aug 30 03:12:27.488339 2026] [authz_core:error] [pid 521505:tid 521644] [client 216.73.216.128:39217] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:27.488611 2026] [authz_core:error] [pid 521505:tid 521644] [client 216.73.216.128:39217] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:27.499088 2026] [authz_core:error] [pid 521505:tid 521660] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory18
[Sun Aug 30 03:12:27.499362 2026] [authz_core:error] [pid 521505:tid 521660] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory18
[Sun Aug 30 03:12:27.510189 2026] [security2:error] [pid 521505:tid 521653] [client 20.104.50.220:62823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/xamp.php"] [unique_id "apPl628byYE0iXl--K6hpwAAAzA"]
[Sun Aug 30 03:12:27.513947 2026] [security2:error] [pid 521505:tid 521672] [client 20.104.49.130:48036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/wp-good.php"] [unique_id "apPl628byYE0iXl--K6hqAAAA0M"]
[Sun Aug 30 03:12:27.536575 2026] [security2:error] [pid 521505:tid 521638] [client 158.23.147.79:40047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apPl628byYE0iXl--K6hqgAAAyE"]
[Sun Aug 30 03:12:27.544328 2026] [security2:error] [pid 521505:tid 521677] [client 20.104.50.220:16686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/colleen986.php"] [unique_id "apPl628byYE0iXl--K6hrAAAA0g"]
[Sun Aug 30 03:12:27.553863 2026] [authz_core:error] [pid 521505:tid 521639] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:27.554156 2026] [authz_core:error] [pid 521505:tid 521639] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:27.566196 2026] [security2:error] [pid 521505:tid 521727] [client 4.205.62.107:25518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/agg.php"] [unique_id "apPl628byYE0iXl--K6hrwAAA3o"]
[Sun Aug 30 03:12:27.589910 2026] [security2:error] [pid 521505:tid 521707] [client 4.205.62.107:17132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/wp-konfig.backup.php"] [unique_id "apPl628byYE0iXl--K6htQAAA2Y"]
[Sun Aug 30 03:12:27.589984 2026] [security2:error] [pid 521505:tid 521642] [client 158.23.184.117:34188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/al.php"] [unique_id "apPl628byYE0iXl--K6htgAAAyU"]
[Sun Aug 30 03:12:27.619280 2026] [security2:error] [pid 524122:tid 524374] [client 20.104.18.15:1996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/abcd.php"] [unique_id "apPl633lhEjKFiK_nBKC7AAAAgg"]
[Sun Aug 30 03:12:27.622276 2026] [security2:error] [pid 521505:tid 521635] [client 158.23.184.117:18406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/cgi-bin/admin.php"] [unique_id "apPl628byYE0iXl--K6htwAAAx4"]
[Sun Aug 30 03:12:27.674650 2026] [authz_core:error] [pid 521505:tid 521705] [client 216.73.216.128:39217] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:27.674907 2026] [authz_core:error] [pid 521505:tid 521705] [client 216.73.216.128:39217] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:27.696338 2026] [security2:error] [pid 521505:tid 521728] [client 20.196.209.81:8536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/nvt/includes/plugins/wp-blog-header.php"] [unique_id "apPl628byYE0iXl--K6huwAAA3s"]
[Sun Aug 30 03:12:27.733885 2026] [security2:error] [pid 524122:tid 524326] [client 158.23.184.117:34176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/alfa.php"] [unique_id "apPl633lhEjKFiK_nBKC7wAAAdg"]
[Sun Aug 30 03:12:27.763324 2026] [authz_core:error] [pid 521505:tid 521762] [client 216.73.216.128:5884] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:27.763724 2026] [authz_core:error] [pid 521505:tid 521762] [client 216.73.216.128:5884] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:27.806914 2026] [security2:error] [pid 524122:tid 524315] [client 20.104.18.15:51021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/fpwch.php"] [unique_id "apPl633lhEjKFiK_nBKC9QAAAc0"]
[Sun Aug 30 03:12:27.818154 2026] [security2:error] [pid 524122:tid 524377] [client 158.23.184.117:18001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/config.php"] [unique_id "apPl633lhEjKFiK_nBKC9gAAAgs"]
[Sun Aug 30 03:12:27.829249 2026] [security2:error] [pid 524122:tid 524304] [client 20.104.50.220:32917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/2index.php"] [unique_id "apPl633lhEjKFiK_nBKC9wAAAcI"]
[Sun Aug 30 03:12:27.840134 2026] [security2:error] [pid 524122:tid 524379] [client 158.23.147.79:60207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apPl633lhEjKFiK_nBKC-AAAAg0"]
[Sun Aug 30 03:12:27.870028 2026] [security2:error] [pid 524122:tid 524301] [client 20.151.200.44:52127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/ssh3ll.php"] [unique_id "apPl633lhEjKFiK_nBKC-QAAAb8"]
[Sun Aug 30 03:12:27.874595 2026] [security2:error] [pid 521505:tid 521675] [client 158.23.184.117:34585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/as.php"] [unique_id "apPl628byYE0iXl--K6hvgAAA0Y"]
[Sun Aug 30 03:12:27.895043 2026] [security2:error] [pid 521505:tid 521758] [client 34.15.159.88:53902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/core/phpinfo.php"] [unique_id "apPl628byYE0iXl--K6hwQAAA5k"]
[Sun Aug 30 03:12:27.902165 2026] [security2:error] [pid 524122:tid 524263] [client 4.205.62.107:15977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/wp-admin/css/bolt.php"] [unique_id "apPl633lhEjKFiK_nBKC_AAAAZk"]
[Sun Aug 30 03:12:27.944802 2026] [authz_core:error] [pid 521505:tid 521681] [client 216.73.216.128:2147] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:27.945073 2026] [authz_core:error] [pid 521505:tid 521681] [client 216.73.216.128:2147] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:27.954398 2026] [security2:error] [pid 524122:tid 524347] [client 20.48.251.3:55735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/classsmtps.php"] [unique_id "apPl633lhEjKFiK_nBKC_gAAAe0"]
[Sun Aug 30 03:12:27.958574 2026] [security2:error] [pid 521505:tid 521648] [client 158.23.184.117:18408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/login.php"] [unique_id "apPl628byYE0iXl--K6hwwAAAys"]
[Sun Aug 30 03:12:27.961611 2026] [security2:error] [pid 524122:tid 524368] [client 158.23.147.79:40057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apPl633lhEjKFiK_nBKC_wAAAgI"]
[Sun Aug 30 03:12:27.964533 2026] [security2:error] [pid 524122:tid 524266] [client 4.205.62.107:16330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/4563.php"] [unique_id "apPl633lhEjKFiK_nBKDAAAAAZw"]
[Sun Aug 30 03:12:27.969052 2026] [security2:error] [pid 524122:tid 524376] [client 20.48.251.3:64273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/grsiuk.php"] [unique_id "apPl633lhEjKFiK_nBKDAQAAAgo"]
[Sun Aug 30 03:12:27.989305 2026] [authz_core:error] [pid 521505:tid 521695] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory18
[Sun Aug 30 03:12:27.989574 2026] [authz_core:error] [pid 521505:tid 521695] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory18
[Sun Aug 30 03:12:28.015706 2026] [security2:error] [pid 521505:tid 521687] [client 158.23.184.117:34191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/aa.php"] [unique_id "apPl7G8byYE0iXl--K6hxgAAA1I"]
[Sun Aug 30 03:12:28.024989 2026] [security2:error] [pid 521505:tid 521671] [client 20.48.251.3:52267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-konfig.backup.php"] [unique_id "apPl7G8byYE0iXl--K6hxwAAA0I"]
[Sun Aug 30 03:12:28.053008 2026] [authz_core:error] [pid 521505:tid 521701] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:28.053268 2026] [authz_core:error] [pid 521505:tid 521701] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:28.060037 2026] [security2:error] [pid 521505:tid 521746] [client 20.48.251.3:37167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/phpsysinfo.php"] [unique_id "apPl7G8byYE0iXl--K6hygAAA40"]
[Sun Aug 30 03:12:28.065185 2026] [authz_core:error] [pid 524122:tid 524269] [client 66.249.66.44:42320] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:28.065450 2026] [authz_core:error] [pid 524122:tid 524269] [client 66.249.66.44:42320] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:28.086613 2026] [security2:error] [pid 524122:tid 524345] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/bgymj.php"] [unique_id "apPl7H3lhEjKFiK_nBKDAwAAAes"]
[Sun Aug 30 03:12:28.092104 2026] [security2:error] [pid 524122:tid 524302] [client 20.196.209.81:20979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/oceanwp/sass/components/plugins/panel.php"] [unique_id "apPl7H3lhEjKFiK_nBKDBAAAAcA"]
[Sun Aug 30 03:12:28.100946 2026] [security2:error] [pid 521505:tid 521722] [client 158.23.184.117:18023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/index.php"] [unique_id "apPl7G8byYE0iXl--K6hzAAAA3U"]
[Sun Aug 30 03:12:28.126529 2026] [security2:error] [pid 521505:tid 521641] [client 20.104.50.220:59723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/403.php"] [unique_id "apPl7G8byYE0iXl--K6h0QAAAyQ"]
[Sun Aug 30 03:12:28.126549 2026] [security2:error] [pid 521505:tid 521731] [client 20.104.50.220:52810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/tesla1.php"] [unique_id "apPl7G8byYE0iXl--K6h0AAAA34"]
[Sun Aug 30 03:12:28.156956 2026] [security2:error] [pid 521505:tid 521741] [client 158.23.184.117:34609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/abc.php"] [unique_id "apPl7G8byYE0iXl--K6h0gAAA4g"]
[Sun Aug 30 03:12:28.191690 2026] [security2:error] [pid 521505:tid 521744] [client 20.104.50.220:25414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/t3s.php"] [unique_id "apPl7G8byYE0iXl--K6h0wAAA4s"]
[Sun Aug 30 03:12:28.194317 2026] [security2:error] [pid 521505:tid 521699] [client 20.151.200.44:26539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/update/da222.php"] [unique_id "apPl7G8byYE0iXl--K6h1AAAA14"]
[Sun Aug 30 03:12:28.212173 2026] [security2:error] [pid 521505:tid 521738] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/bk/index.php"] [unique_id "apPl7G8byYE0iXl--K6h1gAAA4U"]
[Sun Aug 30 03:12:28.219085 2026] [security2:error] [pid 521505:tid 521679] [client 158.23.147.79:60220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPl7G8byYE0iXl--K6h1wAAA0o"]
[Sun Aug 30 03:12:28.242732 2026] [security2:error] [pid 524122:tid 524331] [client 158.23.184.117:18418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/min.php"] [unique_id "apPl7H3lhEjKFiK_nBKDBwAAAd0"]
[Sun Aug 30 03:12:28.288440 2026] [security2:error] [pid 521505:tid 521640] [client 158.23.147.79:21491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apPl7G8byYE0iXl--K6h2AAAAyM"]
[Sun Aug 30 03:12:28.296769 2026] [security2:error] [pid 524122:tid 524264] [client 158.23.184.117:34562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/av.php"] [unique_id "apPl7H3lhEjKFiK_nBKDCQAAAZo"]
[Sun Aug 30 03:12:28.334904 2026] [security2:error] [pid 524122:tid 524259] [client 20.104.50.220:5459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/55.php"] [unique_id "apPl7H3lhEjKFiK_nBKDDAAAAZU"]
[Sun Aug 30 03:12:28.337455 2026] [security2:error] [pid 521505:tid 521666] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/bootstrap.php"] [unique_id "apPl7G8byYE0iXl--K6h2wAAAz0"]
[Sun Aug 30 03:12:28.351249 2026] [security2:error] [pid 524122:tid 524323] [client 4.205.62.107:52900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/xmy.php"] [unique_id "apPl7H3lhEjKFiK_nBKDDQAAAdU"]
[Sun Aug 30 03:12:28.365318 2026] [security2:error] [pid 524122:tid 524316] [client 20.151.200.44:52111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/motu.php"] [unique_id "apPl7H3lhEjKFiK_nBKDDgAAAc4"]
[Sun Aug 30 03:12:28.384421 2026] [security2:error] [pid 524122:tid 524276] [client 158.23.184.117:18003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/options.php"] [unique_id "apPl7H3lhEjKFiK_nBKDDwAAAaY"]
[Sun Aug 30 03:12:28.412783 2026] [security2:error] [pid 521505:tid 521678] [client 20.104.49.130:60608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/as.php"] [unique_id "apPl7G8byYE0iXl--K6h3wAAA0k"]
[Sun Aug 30 03:12:28.438854 2026] [security2:error] [pid 524122:tid 524309] [client 158.23.184.117:34197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/autoload_classmap.php"] [unique_id "apPl7H3lhEjKFiK_nBKDFQAAAcc"]
[Sun Aug 30 03:12:28.462227 2026] [security2:error] [pid 524122:tid 524305] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/bs1.php"] [unique_id "apPl7H3lhEjKFiK_nBKDFwAAAcM"]
[Sun Aug 30 03:12:28.501409 2026] [security2:error] [pid 521505:tid 521739] [client 34.15.159.88:53908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.159.15.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-6159c1bc.learnenglishwithtommy.com"] [uri "/includes/phpinfo.php"] [unique_id "apPl7G8byYE0iXl--K6h5AAAA4Y"]
[Sun Aug 30 03:12:28.503129 2026] [authz_core:error] [pid 521505:tid 521643] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory14
[Sun Aug 30 03:12:28.503410 2026] [authz_core:error] [pid 521505:tid 521643] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory14
[Sun Aug 30 03:12:28.511559 2026] [security2:error] [pid 524122:tid 524349] [client 20.196.209.81:20961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/options.php"] [unique_id "apPl7H3lhEjKFiK_nBKDGAAAAe8"]
[Sun Aug 30 03:12:28.525383 2026] [security2:error] [pid 521505:tid 521667] [client 20.104.50.220:59551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/file7.php"] [unique_id "apPl7G8byYE0iXl--K6h5QAAAz4"]
[Sun Aug 30 03:12:28.526063 2026] [security2:error] [pid 524122:tid 524342] [client 158.23.184.117:18429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/pk.php"] [unique_id "apPl7H3lhEjKFiK_nBKDGQAAAeg"]
[Sun Aug 30 03:12:28.565341 2026] [authz_core:error] [pid 521505:tid 521658] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:28.565629 2026] [authz_core:error] [pid 521505:tid 521658] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:28.566821 2026] [security2:error] [pid 524122:tid 524354] [client 158.23.147.79:39968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/packed.php"] [unique_id "apPl7H3lhEjKFiK_nBKDGgAAAfQ"]
[Sun Aug 30 03:12:28.578610 2026] [security2:error] [pid 521505:tid 521684] [client 158.23.184.117:34564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/asus.php"] [unique_id "apPl7G8byYE0iXl--K6h6AAAA08"]
[Sun Aug 30 03:12:28.589791 2026] [security2:error] [pid 521505:tid 521754] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/bthil.php"] [unique_id "apPl7G8byYE0iXl--K6h6QAAA5U"]
[Sun Aug 30 03:12:28.616984 2026] [security2:error] [pid 521505:tid 521720] [client 20.151.200.44:52154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/wefile.php"] [unique_id "apPl7G8byYE0iXl--K6h6gAAA3M"]
[Sun Aug 30 03:12:28.650385 2026] [security2:error] [pid 521505:tid 521740] [client 20.104.18.15:22481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/img.php"] [unique_id "apPl7G8byYE0iXl--K6h7AAAA4c"]
[Sun Aug 30 03:12:28.666572 2026] [security2:error] [pid 521505:tid 521653] [client 158.23.184.117:18002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/index.php"] [unique_id "apPl7G8byYE0iXl--K6h7gAAAzA"]
[Sun Aug 30 03:12:28.683276 2026] [security2:error] [pid 521505:tid 521727] [client 20.104.50.220:17293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/szezaxab.php"] [unique_id "apPl7G8byYE0iXl--K6h7wAAA3o"]
[Sun Aug 30 03:12:28.708410 2026] [security2:error] [pid 521505:tid 521645] [client 4.205.62.107:25758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/requirements.php"] [unique_id "apPl7G8byYE0iXl--K6h8AAAAyg"]
[Sun Aug 30 03:12:28.711609 2026] [security2:error] [pid 521505:tid 521642] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/buy.php"] [unique_id "apPl7G8byYE0iXl--K6h8gAAAyU"]
[Sun Aug 30 03:12:28.711633 2026] [security2:error] [pid 521505:tid 521707] [client 20.104.50.220:64449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/ya.php"] [unique_id "apPl7G8byYE0iXl--K6h8QAAA2Y"]
[Sun Aug 30 03:12:28.718344 2026] [security2:error] [pid 524122:tid 524338] [client 158.23.184.117:51663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/about.php"] [unique_id "apPl7H3lhEjKFiK_nBKDHQAAAeQ"]
[Sun Aug 30 03:12:28.731946 2026] [security2:error] [pid 521505:tid 521635] [client 20.151.200.44:43978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ermes-it.it"] [uri "/file66.php"] [unique_id "apPl7G8byYE0iXl--K6h8wAAAx4"]
[Sun Aug 30 03:12:28.738722 2026] [security2:error] [pid 521505:tid 521737] [client 4.205.62.107:16792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/packed.php"] [unique_id "apPl7G8byYE0iXl--K6h9AAAA4Q"]
[Sun Aug 30 03:12:28.761195 2026] [security2:error] [pid 524122:tid 524329] [client 20.104.50.220:51603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/1index.php"] [unique_id "apPl7H3lhEjKFiK_nBKDHwAAAds"]
[Sun Aug 30 03:12:28.761836 2026] [security2:error] [pid 521505:tid 521743] [client 20.104.18.15:2020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/nofile.php"] [unique_id "apPl7G8byYE0iXl--K6h9gAAA4o"]
[Sun Aug 30 03:12:28.772486 2026] [security2:error] [pid 521505:tid 521713] [client 158.23.147.79:21462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-content/packed.php"] [unique_id "apPl7G8byYE0iXl--K6h9wAAA2w"]
[Sun Aug 30 03:12:28.775782 2026] [security2:error] [pid 521505:tid 521660] [client 158.23.147.79:58414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/ans.php"] [unique_id "apPl7G8byYE0iXl--K6h-AAAAzc"]
[Sun Aug 30 03:12:28.776362 2026] [security2:error] [pid 524122:tid 524352] [client 20.104.49.130:52453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/new.php"] [unique_id "apPl7H3lhEjKFiK_nBKDIAAAAfI"]
[Sun Aug 30 03:12:28.809250 2026] [security2:error] [pid 524122:tid 524320] [client 158.23.184.117:17995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/cgi-bin/index.php"] [unique_id "apPl7H3lhEjKFiK_nBKDIQAAAdI"]
[Sun Aug 30 03:12:28.839087 2026] [security2:error] [pid 524122:tid 524322] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/byp.php"] [unique_id "apPl7H3lhEjKFiK_nBKDIgAAAdQ"]
[Sun Aug 30 03:12:28.850426 2026] [authz_core:error] [pid 521505:tid 521705] [client 66.249.66.32:63070] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:28.850696 2026] [authz_core:error] [pid 521505:tid 521705] [client 66.249.66.32:63070] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:28.856870 2026] [security2:error] [pid 521505:tid 521736] [client 158.23.184.117:34183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/atomlib.php"] [unique_id "apPl7G8byYE0iXl--K6h_AAAA4M"]
[Sun Aug 30 03:12:28.902636 2026] [security2:error] [pid 524122:tid 524348] [client 20.196.209.81:8192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/panel.php"] [unique_id "apPl7H3lhEjKFiK_nBKDJQAAAe4"]
[Sun Aug 30 03:12:28.912791 2026] [security2:error] [pid 521505:tid 521758] [client 158.23.147.79:21409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-l0gin.php"] [unique_id "apPl7G8byYE0iXl--K6h_wAAA5k"]
[Sun Aug 30 03:12:28.945566 2026] [authz_core:error] [pid 521505:tid 521762] [client 216.73.216.128:39217] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:28.945907 2026] [authz_core:error] [pid 521505:tid 521762] [client 216.73.216.128:39217] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:28.951726 2026] [security2:error] [pid 521505:tid 521665] [client 158.23.184.117:18006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/cgi-bin/load.php"] [unique_id "apPl7G8byYE0iXl--K6iAgAAAzw"]
[Sun Aug 30 03:12:28.957488 2026] [security2:error] [pid 521505:tid 521648] [client 20.104.18.15:51076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/domvf.php"] [unique_id "apPl7G8byYE0iXl--K6iAwAAAys"]
[Sun Aug 30 03:12:28.959993 2026] [security2:error] [pid 521505:tid 521693] [client 158.23.184.117:0] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "webmail.getchellgarden.com"] [uri "/c99.php"] [unique_id "apPl7G8byYE0iXl--K6iBAAAA1g"]
[Sun Aug 30 03:12:28.975675 2026] [authz_core:error] [pid 521505:tid 521687] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory19
[Sun Aug 30 03:12:28.975971 2026] [authz_core:error] [pid 521505:tid 521687] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory19
[Sun Aug 30 03:12:28.989740 2026] [security2:error] [pid 521505:tid 521746] [client 20.104.50.220:32957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/32.php"] [unique_id "apPl7G8byYE0iXl--K6iBwAAA40"]
[Sun Aug 30 03:12:28.997695 2026] [security2:error] [pid 521505:tid 521750] [client 158.23.184.117:51700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/alfa-rex.php7"] [unique_id "apPl7G8byYE0iXl--K6iCQAAA5E"]
[Sun Aug 30 03:12:29.021051 2026] [security2:error] [pid 521505:tid 521733] [client 20.104.49.130:60657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/about.php"] [unique_id "apPl7W8byYE0iXl--K6iCgAAA4A"]
[Sun Aug 30 03:12:29.049420 2026] [security2:error] [pid 521505:tid 521731] [client 4.205.62.107:16330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/myfile.php"] [unique_id "apPl7W8byYE0iXl--K6iDwAAA34"]
[Sun Aug 30 03:12:29.050458 2026] [authz_core:error] [pid 521505:tid 521712] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:29.050763 2026] [authz_core:error] [pid 521505:tid 521712] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:29.089161 2026] [security2:error] [pid 521505:tid 521695] [client 158.23.147.79:39988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apPl7W8byYE0iXl--K6iEQAAA1o"]
[Sun Aug 30 03:12:29.094197 2026] [security2:error] [pid 521505:tid 521668] [client 20.48.251.3:55789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/cache-compat.php"] [unique_id "apPl7W8byYE0iXl--K6iEwAAAz8"]
[Sun Aug 30 03:12:29.099813 2026] [security2:error] [pid 521505:tid 521654] [client 158.23.184.117:18387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/cgi-bin/ms-files.php"] [unique_id "apPl7W8byYE0iXl--K6iFAAAAzE"]
[Sun Aug 30 03:12:29.111004 2026] [security2:error] [pid 521505:tid 521699] [client 20.48.251.3:64282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/paypal.php"] [unique_id "apPl7W8byYE0iXl--K6iFQAAA14"]
[Sun Aug 30 03:12:29.113335 2026] [security2:error] [pid 521505:tid 521637] [client 158.23.147.79:16337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/worksec.php"] [unique_id "apPl7W8byYE0iXl--K6iGAAAAyA"]
[Sun Aug 30 03:12:29.114420 2026] [security2:error] [pid 521505:tid 521738] [client 20.104.49.130:53537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/ws45.php"] [unique_id "apPl7W8byYE0iXl--K6iGQAAA4U"]
[Sun Aug 30 03:12:29.120143 2026] [security2:error] [pid 521505:tid 521725] [client 4.205.62.107:15950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/cp2.php"] [unique_id "apPl7W8byYE0iXl--K6iGgAAA3g"]
[Sun Aug 30 03:12:29.136226 2026] [security2:error] [pid 521505:tid 521757] [client 158.23.184.117:34228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/b.php"] [unique_id "apPl7W8byYE0iXl--K6iHQAAA5g"]
[Sun Aug 30 03:12:29.137636 2026] [authz_core:error] [pid 521505:tid 521636] [client 66.249.66.34:54020] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:29.138050 2026] [authz_core:error] [pid 521505:tid 521636] [client 66.249.66.34:54020] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:29.194833 2026] [security2:error] [pid 521505:tid 521697] [client 20.48.251.3:36896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/sgd.php"] [unique_id "apPl7W8byYE0iXl--K6iHgAAA1w"]
[Sun Aug 30 03:12:29.204729 2026] [security2:error] [pid 524122:tid 524355] [client 20.48.251.3:52175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/packed.php"] [unique_id "apPl7X3lhEjKFiK_nBKDJwAAAfU"]
[Sun Aug 30 03:12:29.241440 2026] [security2:error] [pid 521505:tid 521704] [client 158.23.184.117:18391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/cgi-bin/wp-activate.php"] [unique_id "apPl7W8byYE0iXl--K6iIQAAA2M"]
[Sun Aug 30 03:12:29.243287 2026] [autoindex:error] [pid 521505:tid 521742] [client 35.247.242.193:36262] AH01276: Cannot serve directory /home4/filtagr/public_html/website_abc5208c/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:12:29.267457 2026] [security2:error] [pid 521505:tid 521745] [client 20.104.50.220:63041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/shadowx.php"] [unique_id "apPl7W8byYE0iXl--K6iIwAAA4w"]
[Sun Aug 30 03:12:29.277107 2026] [security2:error] [pid 524122:tid 524292] [client 158.23.184.117:58163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/buy.php"] [unique_id "apPl7X3lhEjKFiK_nBKDKAAAAbY"]
[Sun Aug 30 03:12:29.278499 2026] [security2:error] [pid 521505:tid 521730] [client 20.104.50.220:30916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/m.php"] [unique_id "apPl7W8byYE0iXl--K6iJAAAA30"]
[Sun Aug 30 03:12:29.298009 2026] [security2:error] [pid 524122:tid 524279] [client 20.196.209.81:18003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/reboot/assets/js/plugins/home.php"] [unique_id "apPl7X3lhEjKFiK_nBKDKQAAAak"]
[Sun Aug 30 03:12:29.310360 2026] [authz_core:error] [pid 521505:tid 521709] [client 216.73.216.128:2147] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:29.310656 2026] [authz_core:error] [pid 521505:tid 521709] [client 216.73.216.128:2147] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:29.316381 2026] [security2:error] [pid 521505:tid 521720] [client 158.23.147.79:21482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPl7W8byYE0iXl--K6iJwAAA3M"]
[Sun Aug 30 03:12:29.382565 2026] [security2:error] [pid 521505:tid 521740] [client 158.23.184.117:18015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/cgi-bin/wp-load.php"] [unique_id "apPl7W8byYE0iXl--K6iKwAAA4c"]
[Sun Aug 30 03:12:29.383876 2026] [security2:error] [pid 521505:tid 521644] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/cache/cache/min.php"] [unique_id "apPl7W8byYE0iXl--K6iLAAAAyc"]
[Sun Aug 30 03:12:29.396092 2026] [security2:error] [pid 521505:tid 521682] [client 20.151.200.44:26578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/qi.php"] [unique_id "apPl7W8byYE0iXl--K6iLgAAA00"]
[Sun Aug 30 03:12:29.419055 2026] [security2:error] [pid 521505:tid 521651] [client 158.23.184.117:34602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/bless.php"] [unique_id "apPl7W8byYE0iXl--K6iLwAAAy4"]
[Sun Aug 30 03:12:29.440633 2026] [security2:error] [pid 521505:tid 521635] [client 20.104.49.130:52471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wdfjba.org"] [uri "/zoo2.php"] [unique_id "apPl7W8byYE0iXl--K6iMAAAAx4"]
[Sun Aug 30 03:12:29.453428 2026] [security2:error] [pid 524122:tid 524374] [client 158.23.147.79:40003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/ans.php"] [unique_id "apPl7X3lhEjKFiK_nBKDKgAAAgg"]
[Sun Aug 30 03:12:29.483522 2026] [security2:error] [pid 524122:tid 524326] [client 20.151.200.44:52114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/Contrller.php"] [unique_id "apPl7X3lhEjKFiK_nBKDLAAAAdg"]
[Sun Aug 30 03:12:29.491218 2026] [authz_core:error] [pid 521505:tid 521743] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory17
[Sun Aug 30 03:12:29.491471 2026] [authz_core:error] [pid 521505:tid 521743] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory17
[Sun Aug 30 03:12:29.503499 2026] [security2:error] [pid 524122:tid 524265] [client 20.104.50.220:5556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/54.php"] [unique_id "apPl7X3lhEjKFiK_nBKDLQAAAZs"]
[Sun Aug 30 03:12:29.510294 2026] [security2:error] [pid 524122:tid 524357] [client 4.205.62.107:52807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/ms-edit.php"] [unique_id "apPl7X3lhEjKFiK_nBKDLgAAAfc"]
[Sun Aug 30 03:12:29.512205 2026] [security2:error] [pid 521505:tid 521728] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/catalogbypass.php"] [unique_id "apPl7W8byYE0iXl--K6iNwAAA3s"]
[Sun Aug 30 03:12:29.521950 2026] [security2:error] [pid 524122:tid 524370] [client 158.23.184.117:18011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/cgi-bin/wp-mail.php"] [unique_id "apPl7X3lhEjKFiK_nBKDLwAAAgQ"]
[Sun Aug 30 03:12:29.527921 2026] [authz_core:error] [pid 521505:tid 521759] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:29.528179 2026] [authz_core:error] [pid 521505:tid 521759] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:29.561157 2026] [security2:error] [pid 521505:tid 521696] [client 158.23.184.117:51648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/class-t.api.php"] [unique_id "apPl7W8byYE0iXl--K6iOgAAA1s"]
[Sun Aug 30 03:12:29.576822 2026] [security2:error] [pid 521505:tid 521649] [client 20.104.49.130:63288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/mh.php"] [unique_id "apPl7W8byYE0iXl--K6iOwAAAyw"]
[Sun Aug 30 03:12:29.579004 2026] [security2:error] [pid 521505:tid 521760] [client 20.104.50.220:24846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/uwu.php"] [unique_id "apPl7W8byYE0iXl--K6iPQAAA5s"]
[Sun Aug 30 03:12:29.637713 2026] [security2:error] [pid 521505:tid 521665] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/cc.php"] [unique_id "apPl7W8byYE0iXl--K6iPwAAAzw"]
[Sun Aug 30 03:12:29.652709 2026] [security2:error] [pid 524122:tid 524256] [client 172.104.238.123:30444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.238.104.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "whitemountainthingstodo.com"] [uri "/wp-login.php"] [unique_id "apPl7X3lhEjKFiK_nBKDMAAAAZI"]
[Sun Aug 30 03:12:29.661659 2026] [security2:error] [pid 521505:tid 521688] [client 158.23.184.117:18431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "apPl7W8byYE0iXl--K6iQQAAA1M"]
[Sun Aug 30 03:12:29.675144 2026] [security2:error] [pid 521505:tid 521733] [client 20.104.50.220:62210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/aaa.php"] [unique_id "apPl7W8byYE0iXl--K6iQwAAA4A"]
[Sun Aug 30 03:12:29.693619 2026] [security2:error] [pid 521505:tid 521749] [client 158.23.147.79:39986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/worksec.php"] [unique_id "apPl7W8byYE0iXl--K6iRAAAA5A"]
[Sun Aug 30 03:12:29.693688 2026] [security2:error] [pid 521505:tid 521719] [client 20.196.209.81:20974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/salient/css/build/plugins/login.php"] [unique_id "apPl7W8byYE0iXl--K6iRQAAA3I"]
[Sun Aug 30 03:12:29.701631 2026] [security2:error] [pid 521505:tid 521681] [client 158.23.184.117:58118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/cache.php"] [unique_id "apPl7W8byYE0iXl--K6iRgAAA0w"]
[Sun Aug 30 03:12:29.756035 2026] [security2:error] [pid 521505:tid 521699] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/cgi-bin/admin.php"] [unique_id "apPl7W8byYE0iXl--K6iTAAAA14"]
[Sun Aug 30 03:12:29.800405 2026] [security2:error] [pid 524122:tid 524313] [client 20.104.18.15:22402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/222.php"] [unique_id "apPl7X3lhEjKFiK_nBKDMQAAAcs"]
[Sun Aug 30 03:12:29.800407 2026] [security2:error] [pid 521505:tid 521744] [client 158.23.184.117:18345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/chosen.php"] [unique_id "apPl7W8byYE0iXl--K6iTgAAA4s"]
[Sun Aug 30 03:12:29.825053 2026] [security2:error] [pid 521505:tid 521757] [client 20.104.50.220:16653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/function.php"] [unique_id "apPl7W8byYE0iXl--K6iTwAAA5g"]
[Sun Aug 30 03:12:29.841458 2026] [security2:error] [pid 524122:tid 524379] [client 158.23.184.117:51679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/content.php"] [unique_id "apPl7X3lhEjKFiK_nBKDMgAAAg0"]
[Sun Aug 30 03:12:29.864869 2026] [security2:error] [pid 521505:tid 521693] [client 158.23.147.79:39969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/x.php"] [unique_id "apPl7W8byYE0iXl--K6iUgAAA1g"]
[Sun Aug 30 03:12:29.869804 2026] [security2:error] [pid 521505:tid 521716] [client 20.104.50.220:29182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/zer0.php"] [unique_id "apPl7W8byYE0iXl--K6iUwAAA28"]
[Sun Aug 30 03:12:29.875475 2026] [security2:error] [pid 524122:tid 524254] [client 4.205.62.107:17725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/wp-info.php"] [unique_id "apPl7X3lhEjKFiK_nBKDMwAAAZA"]
[Sun Aug 30 03:12:29.896802 2026] [authz_core:error] [pid 521505:tid 521666] [client 66.249.66.35:49761] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:29.897234 2026] [authz_core:error] [pid 521505:tid 521666] [client 66.249.66.35:49761] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:29.898914 2026] [security2:error] [pid 521505:tid 521669] [client 20.104.18.15:2005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/run.php"] [unique_id "apPl7W8byYE0iXl--K6iVwAAA0A"]
[Sun Aug 30 03:12:29.910294 2026] [security2:error] [pid 521505:tid 521664] [client 20.104.50.220:51592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/22xc.php"] [unique_id "apPl7W8byYE0iXl--K6iWAAAAzs"]
[Sun Aug 30 03:12:29.926401 2026] [security2:error] [pid 521505:tid 521697] [client 4.205.62.107:26992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/var/www/wallet/index.php"] [unique_id "apPl7W8byYE0iXl--K6iWQAAA1w"]
[Sun Aug 30 03:12:29.927896 2026] [security2:error] [pid 524122:tid 524378] [client 158.23.147.79:16274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/x.php"] [unique_id "apPl7X3lhEjKFiK_nBKDNAAAAgw"]
[Sun Aug 30 03:12:29.942884 2026] [security2:error] [pid 521505:tid 521704] [client 216.73.216.128:39217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/nameserverconfig"] [unique_id "apPl7W8byYE0iXl--K6iXAAAA2M"]
[Sun Aug 30 03:12:29.954931 2026] [security2:error] [pid 521505:tid 521718] [client 20.104.49.130:63551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/ortasekerli1.php"] [unique_id "apPl7W8byYE0iXl--K6iXQAAA3E"]
[Sun Aug 30 03:12:29.969101 2026] [security2:error] [pid 521505:tid 521701] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/config.php"] [unique_id "apPl7W8byYE0iXl--K6iXgAAA2A"]
[Sun Aug 30 03:12:29.978214 2026] [security2:error] [pid 521505:tid 521700] [client 158.23.184.117:51659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/classwithtostring.php"] [unique_id "apPl7W8byYE0iXl--K6iYAAAA18"]
[Sun Aug 30 03:12:29.981404 2026] [authz_core:error] [pid 521505:tid 521732] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory14
[Sun Aug 30 03:12:29.981855 2026] [authz_core:error] [pid 521505:tid 521732] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory14
[Sun Aug 30 03:12:29.985840 2026] [security2:error] [pid 521505:tid 521667] [client 158.23.147.79:21463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-content/x.php"] [unique_id "apPl7W8byYE0iXl--K6iYQAAAz4"]
[Sun Aug 30 03:12:29.993617 2026] [security2:error] [pid 524122:tid 524368] [client 158.23.184.117:17999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/class-wp-logo-new.php"] [unique_id "apPl7X3lhEjKFiK_nBKDNgAAAgI"]
[Sun Aug 30 03:12:30.028549 2026] [security2:error] [pid 524122:tid 524365] [client 20.104.49.130:54154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/berlin.php"] [unique_id "apPl7n3lhEjKFiK_nBKDOQAAAf8"]
[Sun Aug 30 03:12:30.048662 2026] [security2:error] [pid 521505:tid 521727] [client 20.151.200.44:26527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/px.php"] [unique_id "apPl7m8byYE0iXl--K6iZgAAA3o"]
[Sun Aug 30 03:12:30.050658 2026] [authz_core:error] [pid 521505:tid 521658] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:30.050926 2026] [authz_core:error] [pid 521505:tid 521658] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:30.089963 2026] [security2:error] [pid 521505:tid 521707] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/login.php"] [unique_id "apPl7m8byYE0iXl--K6iaAAAA2Y"]
[Sun Aug 30 03:12:30.094921 2026] [security2:error] [pid 521505:tid 521761] [client 20.196.209.81:8974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/security.php"] [unique_id "apPl7m8byYE0iXl--K6iaQAAA5w"]
[Sun Aug 30 03:12:30.098918 2026] [security2:error] [pid 521505:tid 521652] [client 20.104.18.15:51139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/biufile.php"] [unique_id "apPl7m8byYE0iXl--K6iagAAAy8"]
[Sun Aug 30 03:12:30.116202 2026] [security2:error] [pid 521505:tid 521644] [client 158.23.184.117:34592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/css.php"] [unique_id "apPl7m8byYE0iXl--K6iawAAAyc"]
[Sun Aug 30 03:12:30.117665 2026] [security2:error] [pid 521505:tid 521635] [client 20.104.49.130:57626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alarm-monitoring.net"] [uri "/av.php"] [unique_id "apPl7m8byYE0iXl--K6ibAAAAx4"]
[Sun Aug 30 03:12:30.133524 2026] [security2:error] [pid 521505:tid 521677] [client 158.23.184.117:18390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/classwithtostring.php"] [unique_id "apPl7m8byYE0iXl--K6ibwAAA0g"]
[Sun Aug 30 03:12:30.135487 2026] [security2:error] [pid 521505:tid 521674] [client 20.151.200.44:46060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/wp-login.php"] [unique_id "apPl7m8byYE0iXl--K6icAAAA0U"]
[Sun Aug 30 03:12:30.139037 2026] [security2:error] [pid 521505:tid 521713] [client 20.104.50.220:33194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/404.php"] [unique_id "apPl7m8byYE0iXl--K6icgAAA2w"]
[Sun Aug 30 03:12:30.185406 2026] [security2:error] [pid 521505:tid 521726] [client 158.23.147.79:39939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPl7m8byYE0iXl--K6icwAAA3k"]
[Sun Aug 30 03:12:30.195798 2026] [security2:error] [pid 524122:tid 524345] [client 4.205.62.107:16382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/lm15.php"] [unique_id "apPl7n3lhEjKFiK_nBKDPQAAAes"]
[Sun Aug 30 03:12:30.214357 2026] [security2:error] [pid 521505:tid 521760] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/index.php"] [unique_id "apPl7m8byYE0iXl--K6idAAAA5s"]
[Sun Aug 30 03:12:30.234836 2026] [security2:error] [pid 521505:tid 521690] [client 20.48.251.3:55784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/aws_keys.php"] [unique_id "apPl7m8byYE0iXl--K6idgAAA1U"]
[Sun Aug 30 03:12:30.251021 2026] [security2:error] [pid 521505:tid 521686] [client 20.48.251.3:54841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/userfuns.php"] [unique_id "apPl7m8byYE0iXl--K6idwAAA1E"]
[Sun Aug 30 03:12:30.254185 2026] [security2:error] [pid 524122:tid 524318] [client 4.205.62.107:15827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/xda.php"] [unique_id "apPl7n3lhEjKFiK_nBKDPgAAAdA"]
[Sun Aug 30 03:12:30.257053 2026] [security2:error] [pid 521505:tid 521703] [client 158.23.184.117:51666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/chosen.php"] [unique_id "apPl7m8byYE0iXl--K6ieAAAA2I"]
[Sun Aug 30 03:12:30.275964 2026] [security2:error] [pid 521505:tid 521680] [client 158.23.184.117:18370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/cms.php"] [unique_id "apPl7m8byYE0iXl--K6ieQAAA0s"]
[Sun Aug 30 03:12:30.310166 2026] [security2:error] [pid 521505:tid 521663] [client 20.104.49.130:52294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.atstechsolution.com"] [uri "/edit.php"] [unique_id "apPl7m8byYE0iXl--K6iewAAAzo"]
[Sun Aug 30 03:12:30.331435 2026] [security2:error] [pid 521505:tid 521681] [client 20.48.251.3:36801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/fleen.php"] [unique_id "apPl7m8byYE0iXl--K6ifQAAA0w"]
[Sun Aug 30 03:12:30.336849 2026] [security2:error] [pid 524122:tid 524300] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/min.php"] [unique_id "apPl7n3lhEjKFiK_nBKDQwAAAb4"]
[Sun Aug 30 03:12:30.368668 2026] [security2:error] [pid 521505:tid 521721] [client 20.48.251.3:43089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-info.php"] [unique_id "apPl7m8byYE0iXl--K6igQAAA3Q"]
[Sun Aug 30 03:12:30.371445 2026] [security2:error] [pid 521505:tid 521654] [client 158.23.147.79:39964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/log-mama/function.php"] [unique_id "apPl7m8byYE0iXl--K6iggAAAzE"]
[Sun Aug 30 03:12:30.396594 2026] [security2:error] [pid 521505:tid 521668] [client 20.104.49.130:60649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/press.php"] [unique_id "apPl7m8byYE0iXl--K6igwAAAz8"]
[Sun Aug 30 03:12:30.396594 2026] [security2:error] [pid 524122:tid 524356] [client 158.23.184.117:34179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/doc.php"] [unique_id "apPl7n3lhEjKFiK_nBKDRQAAAfY"]
[Sun Aug 30 03:12:30.403985 2026] [security2:error] [pid 521505:tid 521699] [client 20.48.160.90:61677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/llyuxaqd.php"] [unique_id "apPl7m8byYE0iXl--K6ihQAAA14"]
[Sun Aug 30 03:12:30.416681 2026] [security2:error] [pid 521505:tid 521735] [client 158.23.184.117:18009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/config.php"] [unique_id "apPl7m8byYE0iXl--K6ihgAAA4I"]
[Sun Aug 30 03:12:30.430718 2026] [security2:error] [pid 521505:tid 521753] [client 20.104.50.220:29576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/hexor.php"] [unique_id "apPl7m8byYE0iXl--K6ihwAAA5Q"]
[Sun Aug 30 03:12:30.443404 2026] [security2:error] [pid 521505:tid 521744] [client 20.48.160.90:50460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/radio.php"] [unique_id "apPl7m8byYE0iXl--K6iigAAA4s"]
[Sun Aug 30 03:12:30.449914 2026] [security2:error] [pid 521505:tid 521705] [client 20.104.50.220:30914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/themes.php"] [unique_id "apPl7m8byYE0iXl--K6iiwAAA2Q"]
[Sun Aug 30 03:12:30.463855 2026] [security2:error] [pid 524122:tid 524346] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/options.php"] [unique_id "apPl7n3lhEjKFiK_nBKDRgAAAew"]
[Sun Aug 30 03:12:30.487993 2026] [security2:error] [pid 524122:tid 524371] [client 20.196.209.81:8195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "apPl7n3lhEjKFiK_nBKDRwAAAgU"]
[Sun Aug 30 03:12:30.498681 2026] [authz_core:error] [pid 521505:tid 521723] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory33
[Sun Aug 30 03:12:30.499151 2026] [authz_core:error] [pid 521505:tid 521723] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory33
[Sun Aug 30 03:12:30.502444 2026] [security2:error] [pid 521505:tid 521752] [client 158.23.147.79:58406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-content/x.php"] [unique_id "apPl7m8byYE0iXl--K6ijwAAA5M"]
[Sun Aug 30 03:12:30.521752 2026] [security2:error] [pid 524122:tid 524264] [client 159.65.217.202:57090] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "playgolfindiana.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "apPl7n3lhEjKFiK_nBKDSAAAAZo"]
[Sun Aug 30 03:12:30.537246 2026] [security2:error] [pid 521505:tid 521650] [client 158.23.184.117:34571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/elp.php"] [unique_id "apPl7m8byYE0iXl--K6ikAAAAy0"]
[Sun Aug 30 03:12:30.538165 2026] [security2:error] [pid 521505:tid 521742] [client 20.48.160.90:51830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/nbwxolou.php"] [unique_id "apPl7m8byYE0iXl--K6ikQAAA4k"]
[Sun Aug 30 03:12:30.558172 2026] [security2:error] [pid 521505:tid 521697] [client 158.23.184.117:18411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/configs.php"] [unique_id "apPl7m8byYE0iXl--K6ilAAAA1w"]
[Sun Aug 30 03:12:30.560175 2026] [authz_core:error] [pid 521505:tid 521687] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:30.560441 2026] [authz_core:error] [pid 521505:tid 521687] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:30.581185 2026] [security2:error] [pid 524122:tid 524276] [client 20.48.160.90:45312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/dex.php"] [unique_id "apPl7n3lhEjKFiK_nBKDSgAAAaY"]
[Sun Aug 30 03:12:30.585805 2026] [security2:error] [pid 524122:tid 524372] [client 20.151.200.44:26569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/is.php"] [unique_id "apPl7n3lhEjKFiK_nBKDSwAAAgY"]
[Sun Aug 30 03:12:30.588906 2026] [security2:error] [pid 521505:tid 521745] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/pk.php"] [unique_id "apPl7m8byYE0iXl--K6ilgAAA4w"]
[Sun Aug 30 03:12:30.643209 2026] [security2:error] [pid 521505:tid 521672] [client 158.23.147.79:21444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/bk/index.php"] [unique_id "apPl7m8byYE0iXl--K6imAAAA0M"]
[Sun Aug 30 03:12:30.663203 2026] [security2:error] [pid 521505:tid 521702] [client 4.205.62.107:29164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/sys.php"] [unique_id "apPl7m8byYE0iXl--K6imQAAA2E"]
[Sun Aug 30 03:12:30.677250 2026] [security2:error] [pid 521505:tid 521710] [client 20.48.160.90:37827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/nsxeubyv.php"] [unique_id "apPl7m8byYE0iXl--K6imwAAA2k"]
[Sun Aug 30 03:12:30.678166 2026] [security2:error] [pid 524122:tid 524360] [client 158.23.184.117:51673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/Exception-class.php"] [unique_id "apPl7n3lhEjKFiK_nBKDTAAAAfo"]
[Sun Aug 30 03:12:30.678370 2026] [authz_core:error] [pid 521505:tid 521657] [client 216.73.216.128:5884] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:30.678742 2026] [authz_core:error] [pid 521505:tid 521657] [client 216.73.216.128:5884] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:30.694129 2026] [security2:error] [pid 524122:tid 524309] [client 20.104.50.220:5935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/53.php"] [unique_id "apPl7n3lhEjKFiK_nBKDTQAAAcc"]
[Sun Aug 30 03:12:30.697791 2026] [security2:error] [pid 521505:tid 521730] [client 158.23.184.117:18334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/configuration.php"] [unique_id "apPl7m8byYE0iXl--K6inAAAA30"]
[Sun Aug 30 03:12:30.709943 2026] [security2:error] [pid 521505:tid 521647] [client 20.48.160.90:50551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/giodywky.php"] [unique_id "apPl7m8byYE0iXl--K6inQAAAyo"]
[Sun Aug 30 03:12:30.712447 2026] [security2:error] [pid 524122:tid 524305] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/index.php"] [unique_id "apPl7n3lhEjKFiK_nBKDTgAAAcM"]
[Sun Aug 30 03:12:30.718637 2026] [security2:error] [pid 524122:tid 524298] [client 20.104.50.220:25452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/uwa.php"] [unique_id "apPl7n3lhEjKFiK_nBKDTwAAAbw"]
[Sun Aug 30 03:12:30.731784 2026] [authz_core:error] [pid 521505:tid 521643] [client 66.249.66.78:35880] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:30.732036 2026] [authz_core:error] [pid 521505:tid 521643] [client 66.249.66.78:35880] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:30.757743 2026] [security2:error] [pid 524122:tid 524342] [client 20.104.49.130:53589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/classwithtostring.php"] [unique_id "apPl7n3lhEjKFiK_nBKDUAAAAeg"]
[Sun Aug 30 03:12:30.769741 2026] [authz_core:error] [pid 521505:tid 521756] [client 216.73.216.128:16328] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:30.770002 2026] [authz_core:error] [pid 521505:tid 521756] [client 216.73.216.128:16328] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:30.818564 2026] [security2:error] [pid 521505:tid 521709] [client 20.48.160.90:61611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/zfqipfss.php"] [unique_id "apPl7m8byYE0iXl--K6ioQAAA2g"]
[Sun Aug 30 03:12:30.819736 2026] [security2:error] [pid 521505:tid 521682] [client 158.23.184.117:51705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/ee.php"] [unique_id "apPl7m8byYE0iXl--K6iogAAA00"]
[Sun Aug 30 03:12:30.822104 2026] [security2:error] [pid 521505:tid 521652] [client 20.151.200.44:52051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/file66.php"] [unique_id "apPl7m8byYE0iXl--K6iowAAAy8"]
[Sun Aug 30 03:12:30.836981 2026] [security2:error] [pid 524122:tid 524294] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/cgi-bin/index.php"] [unique_id "apPl7n3lhEjKFiK_nBKDUgAAAbg"]
[Sun Aug 30 03:12:30.841743 2026] [security2:error] [pid 521505:tid 521644] [client 158.23.147.79:21486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.pediatricplaytherapy.com"] [uri "/first.php"] [unique_id "apPl7m8byYE0iXl--K6ipAAAAyc"]
[Sun Aug 30 03:12:30.843637 2026] [security2:error] [pid 521505:tid 521755] [client 20.48.160.90:50463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp-kz.php"] [unique_id "apPl7m8byYE0iXl--K6ipQAAA5Y"]
[Sun Aug 30 03:12:30.855048 2026] [security2:error] [pid 521505:tid 521761] [client 158.23.184.117:18424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/content.php"] [unique_id "apPl7m8byYE0iXl--K6ipwAAA5w"]
[Sun Aug 30 03:12:30.883866 2026] [security2:error] [pid 521505:tid 521754] [client 20.151.200.44:43921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ermes-it.it"] [uri "/blnux.php"] [unique_id "apPl7m8byYE0iXl--K6iqQAAA5U"]
[Sun Aug 30 03:12:30.888654 2026] [security2:error] [pid 521505:tid 521740] [client 20.196.209.81:8999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/system.php"] [unique_id "apPl7m8byYE0iXl--K6iqgAAA4c"]
[Sun Aug 30 03:12:30.892797 2026] [security2:error] [pid 524122:tid 524358] [client 20.104.50.220:61965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/vee.php"] [unique_id "apPl7n3lhEjKFiK_nBKDUwAAAfg"]
[Sun Aug 30 03:12:30.895679 2026] [security2:error] [pid 521505:tid 521639] [client 20.197.61.180:1288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/aaa.php"] [unique_id "apPl7m8byYE0iXl--K6iqwAAAyI"]
[Sun Aug 30 03:12:30.950030 2026] [security2:error] [pid 521505:tid 521675] [client 20.48.160.90:61573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.blog.socalhomessouthbay.com"] [uri "/zrjuyoos.php"] [unique_id "apPl7m8byYE0iXl--K6irgAAA0Y"]
[Sun Aug 30 03:12:30.952015 2026] [authz_core:error] [pid 524122:tid 524287] [client 216.73.216.128:17046] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:30.952287 2026] [authz_core:error] [pid 524122:tid 524287] [client 216.73.216.128:17046] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:30.958928 2026] [security2:error] [pid 521505:tid 521686] [client 20.104.18.15:22485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/key.php"] [unique_id "apPl7m8byYE0iXl--K6isQAAA1E"]
[Sun Aug 30 03:12:30.959306 2026] [security2:error] [pid 521505:tid 521661] [client 158.23.184.117:51694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/edit.php"] [unique_id "apPl7m8byYE0iXl--K6isgAAAzg"]
[Sun Aug 30 03:12:30.960223 2026] [security2:error] [pid 524122:tid 524329] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/cgi-bin/load.php"] [unique_id "apPl7n3lhEjKFiK_nBKDVQAAAds"]
[Sun Aug 30 03:12:30.960379 2026] [security2:error] [pid 521505:tid 521703] [client 20.104.50.220:17318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/cierra632.php"] [unique_id "apPl7m8byYE0iXl--K6iswAAA2I"]
[Sun Aug 30 03:12:30.964993 2026] [authz_core:error] [pid 521505:tid 521690] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory16
[Sun Aug 30 03:12:30.965452 2026] [authz_core:error] [pid 521505:tid 521690] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory16
[Sun Aug 30 03:12:30.970975 2026] [security2:error] [pid 521505:tid 521680] [client 20.48.160.90:50492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp-includes/ID3/getid.php"] [unique_id "apPl7m8byYE0iXl--K6itQAAA0s"]
[Sun Aug 30 03:12:30.996709 2026] [security2:error] [pid 521505:tid 521758] [client 158.23.184.117:18389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/core.php"] [unique_id "apPl7m8byYE0iXl--K6itgAAA5k"]
[Sun Aug 30 03:12:31.014371 2026] [security2:error] [pid 521505:tid 521743] [client 4.205.62.107:17118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/fns.php"] [unique_id "apPl728byYE0iXl--K6itwAAA4o"]
[Sun Aug 30 03:12:31.039905 2026] [authz_core:error] [pid 521505:tid 521636] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:31.040410 2026] [authz_core:error] [pid 521505:tid 521636] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:31.050919 2026] [security2:error] [pid 524122:tid 524364] [client 20.104.18.15:1948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/new.php"] [unique_id "apPl733lhEjKFiK_nBKDVgAAAf4"]
[Sun Aug 30 03:12:31.051267 2026] [security2:error] [pid 521505:tid 521719] [client 20.104.50.220:28715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/63dor.php"] [unique_id "apPl728byYE0iXl--K6iugAAA3I"]
[Sun Aug 30 03:12:31.069158 2026] [security2:error] [pid 524122:tid 524328] [client 4.205.62.107:26973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/124.php"] [unique_id "apPl733lhEjKFiK_nBKDVwAAAdo"]
[Sun Aug 30 03:12:31.075524 2026] [security2:error] [pid 521505:tid 521720] [client 20.104.49.130:63525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/t.php"] [unique_id "apPl728byYE0iXl--K6iuwAAA3M"]
[Sun Aug 30 03:12:31.082069 2026] [security2:error] [pid 524122:tid 524258] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/cgi-bin/ms-files.php"] [unique_id "apPl733lhEjKFiK_nBKDWAAAAZQ"]
[Sun Aug 30 03:12:31.086758 2026] [security2:error] [pid 521505:tid 521666] [client 20.104.49.130:60615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.killmigraine.com"] [uri "/edit.php"] [unique_id "apPl728byYE0iXl--K6ivAAAAz0"]
[Sun Aug 30 03:12:31.092244 2026] [security2:error] [pid 521505:tid 521695] [client 20.151.200.44:26502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/od.php"] [unique_id "apPl728byYE0iXl--K6ivQAAA1o"]
[Sun Aug 30 03:12:31.101113 2026] [security2:error] [pid 521505:tid 521681] [client 158.23.184.117:34618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/f35.php"] [unique_id "apPl728byYE0iXl--K6ivgAAA0w"]
[Sun Aug 30 03:12:31.104599 2026] [security2:error] [pid 521505:tid 521721] [client 20.48.160.90:50458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/session.php"] [unique_id "apPl728byYE0iXl--K6ivwAAA3Q"]
[Sun Aug 30 03:12:31.125998 2026] [security2:error] [pid 521505:tid 521637] [client 20.104.50.220:51530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/26.php"] [unique_id "apPl728byYE0iXl--K6iwAAAAyA"]
[Sun Aug 30 03:12:31.137617 2026] [security2:error] [pid 521505:tid 521762] [client 20.151.200.44:52130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/blnux.php"] [unique_id "apPl728byYE0iXl--K6iwgAAA50"]
[Sun Aug 30 03:12:31.138241 2026] [security2:error] [pid 524122:tid 524322] [client 158.23.184.117:18407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/data.php"] [unique_id "apPl733lhEjKFiK_nBKDWwAAAdQ"]
[Sun Aug 30 03:12:31.147927 2026] [security2:error] [pid 521505:tid 521706] [client 20.197.61.180:1709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/atomlib.php"] [unique_id "apPl728byYE0iXl--K6iwwAAA2U"]
[Sun Aug 30 03:12:31.206869 2026] [security2:error] [pid 521505:tid 521729] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/cgi-bin/wp-activate.php"] [unique_id "apPl728byYE0iXl--K6ixQAAA3w"]
[Sun Aug 30 03:12:31.241060 2026] [security2:error] [pid 521505:tid 521750] [client 20.48.160.90:45391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/eagle.php"] [unique_id "apPl728byYE0iXl--K6iyAAAA5E"]
[Sun Aug 30 03:12:31.244067 2026] [security2:error] [pid 524122:tid 524286] [client 158.23.184.117:34194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/fff.php"] [unique_id "apPl733lhEjKFiK_nBKDXgAAAbA"]
[Sun Aug 30 03:12:31.250357 2026] [security2:error] [pid 524122:tid 524292] [client 20.104.18.15:51112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/blacks.php"] [unique_id "apPl733lhEjKFiK_nBKDXwAAAbY"]
[Sun Aug 30 03:12:31.280017 2026] [security2:error] [pid 521505:tid 521757] [client 158.23.184.117:18400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/database.php"] [unique_id "apPl728byYE0iXl--K6iygAAA5g"]
[Sun Aug 30 03:12:31.281027 2026] [security2:error] [pid 521505:tid 521685] [client 20.196.209.81:8972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/tflow/min.php"] [unique_id "apPl728byYE0iXl--K6iywAAA1A"]
[Sun Aug 30 03:12:31.288334 2026] [security2:error] [pid 521505:tid 521683] [client 20.104.50.220:33178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/4x4.php"] [unique_id "apPl728byYE0iXl--K6izAAAA04"]
[Sun Aug 30 03:12:31.317699 2026] [authz_core:error] [pid 521505:tid 521747] [client 216.73.216.128:2147] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:31.317985 2026] [authz_core:error] [pid 521505:tid 521747] [client 216.73.216.128:2147] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:31.330503 2026] [security2:error] [pid 521505:tid 521650] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/cgi-bin/wp-load.php"] [unique_id "apPl728byYE0iXl--K6izgAAAy0"]
[Sun Aug 30 03:12:31.331023 2026] [security2:error] [pid 521505:tid 521742] [client 4.205.62.107:16335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/test.config.php"] [unique_id "apPl728byYE0iXl--K6izwAAA4k"]
[Sun Aug 30 03:12:31.337962 2026] [authz_core:error] [pid 521505:tid 521678] [client 66.249.66.65:57016] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:31.338216 2026] [authz_core:error] [pid 521505:tid 521678] [client 66.249.66.65:57016] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:31.368243 2026] [authz_core:error] [pid 521505:tid 521670] [client 66.249.66.71:64750] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:31.368563 2026] [authz_core:error] [pid 521505:tid 521670] [client 66.249.66.71:64750] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:31.368660 2026] [security2:error] [pid 521505:tid 521739] [client 20.48.251.3:55730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/umgebung.php"] [unique_id "apPl728byYE0iXl--K6i1AAAA4Y"]
[Sun Aug 30 03:12:31.370983 2026] [security2:error] [pid 524122:tid 524326] [client 20.48.160.90:50508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/up-kon.php"] [unique_id "apPl733lhEjKFiK_nBKDYAAAAdg"]
[Sun Aug 30 03:12:31.372765 2026] [security2:error] [pid 521505:tid 521688] [client 158.23.147.79:16268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPl728byYE0iXl--K6i1gAAA1M"]
[Sun Aug 30 03:12:31.383725 2026] [security2:error] [pid 521505:tid 521704] [client 158.23.184.117:34622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/ff1.php"] [unique_id "apPl728byYE0iXl--K6i1wAAA2M"]
[Sun Aug 30 03:12:31.395062 2026] [security2:error] [pid 521505:tid 521684] [client 4.205.62.107:15977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/pinfo.php"] [unique_id "apPl728byYE0iXl--K6i2AAAA08"]
[Sun Aug 30 03:12:31.402049 2026] [security2:error] [pid 521505:tid 521672] [client 20.48.251.3:54836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/mamzi.php"] [unique_id "apPl728byYE0iXl--K6i2QAAA0M"]
[Sun Aug 30 03:12:31.408890 2026] [authz_core:error] [pid 524122:tid 524307] [client 216.73.216.128:17046] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:31.409166 2026] [authz_core:error] [pid 524122:tid 524307] [client 216.73.216.128:17046] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:31.420950 2026] [security2:error] [pid 521505:tid 521738] [client 158.23.184.117:18315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/db.php"] [unique_id "apPl728byYE0iXl--K6i2wAAA4U"]
[Sun Aug 30 03:12:31.453379 2026] [security2:error] [pid 524122:tid 524357] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/cgi-bin/wp-mail.php"] [unique_id "apPl733lhEjKFiK_nBKDYgAAAfc"]
[Sun Aug 30 03:12:31.460802 2026] [security2:error] [pid 521505:tid 521653] [client 20.104.49.130:63533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/makeasmtp.php"] [unique_id "apPl728byYE0iXl--K6i3QAAAzA"]
[Sun Aug 30 03:12:31.487023 2026] [security2:error] [pid 524122:tid 524367] [client 20.48.251.3:36858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/upload.form.php"] [unique_id "apPl733lhEjKFiK_nBKDYwAAAgE"]
[Sun Aug 30 03:12:31.491763 2026] [authz_core:error] [pid 521505:tid 521687] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory13
[Sun Aug 30 03:12:31.492015 2026] [authz_core:error] [pid 521505:tid 521687] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory13
[Sun Aug 30 03:12:31.501147 2026] [security2:error] [pid 521505:tid 521709] [client 20.48.160.90:50547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/tinny.php"] [unique_id "apPl728byYE0iXl--K6i4QAAA2g"]
[Sun Aug 30 03:12:31.523966 2026] [security2:error] [pid 524122:tid 524337] [client 158.23.184.117:34617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/flower.php"] [unique_id "apPl733lhEjKFiK_nBKDZAAAAeM"]
[Sun Aug 30 03:12:31.533478 2026] [authz_core:error] [pid 521505:tid 521711] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:31.533943 2026] [authz_core:error] [pid 521505:tid 521711] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:31.543036 2026] [security2:error] [pid 521505:tid 521761] [client 20.48.251.3:59888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/fns.php"] [unique_id "apPl728byYE0iXl--K6i5AAAA5w"]
[Sun Aug 30 03:12:31.557049 2026] [security2:error] [pid 521505:tid 521660] [client 20.151.200.44:26443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/wp-the.php"] [unique_id "apPl728byYE0iXl--K6i5QAAAzc"]
[Sun Aug 30 03:12:31.562455 2026] [security2:error] [pid 524122:tid 524314] [client 158.23.184.117:18426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/default.php"] [unique_id "apPl733lhEjKFiK_nBKDZQAAAcw"]
[Sun Aug 30 03:12:31.575302 2026] [security2:error] [pid 524122:tid 524304] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "apPl733lhEjKFiK_nBKDZgAAAcI"]
[Sun Aug 30 03:12:31.588529 2026] [authz_core:error] [pid 524122:tid 524361] [client 216.73.216.128:17046] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:31.588804 2026] [authz_core:error] [pid 524122:tid 524361] [client 216.73.216.128:17046] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:31.591005 2026] [authz_core:error] [pid 521505:tid 521740] [client 66.249.66.77:35518] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:31.591448 2026] [authz_core:error] [pid 521505:tid 521740] [client 66.249.66.77:35518] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:31.602755 2026] [security2:error] [pid 521505:tid 521639] [client 20.104.50.220:31524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-admin/maint/about.php"] [unique_id "apPl728byYE0iXl--K6i6AAAAyI"]
[Sun Aug 30 03:12:31.612658 2026] [security2:error] [pid 521505:tid 521728] [client 20.104.50.220:52833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/leaf.php"] [unique_id "apPl728byYE0iXl--K6i6QAAA3s"]
[Sun Aug 30 03:12:31.635298 2026] [security2:error] [pid 521505:tid 521715] [client 20.48.160.90:50511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp-easy.php"] [unique_id "apPl728byYE0iXl--K6i7AAAA24"]
[Sun Aug 30 03:12:31.667522 2026] [security2:error] [pid 521505:tid 521726] [client 158.23.184.117:34193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/file.php"] [unique_id "apPl728byYE0iXl--K6i7QAAA3k"]
[Sun Aug 30 03:12:31.668099 2026] [security2:error] [pid 524122:tid 524378] [client 20.151.200.44:52097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/attack.php"] [unique_id "apPl733lhEjKFiK_nBKDaQAAAgw"]
[Sun Aug 30 03:12:31.687202 2026] [security2:error] [pid 521505:tid 521713] [client 20.196.209.81:8513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/tflow/pk.php"] [unique_id "apPl728byYE0iXl--K6i7wAAA2w"]
[Sun Aug 30 03:12:31.702400 2026] [security2:error] [pid 521505:tid 521680] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/chosen.php"] [unique_id "apPl728byYE0iXl--K6i8AAAA0s"]
[Sun Aug 30 03:12:31.703711 2026] [security2:error] [pid 521505:tid 521675] [client 158.23.184.117:18422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/dev1s.php"] [unique_id "apPl728byYE0iXl--K6i8QAAA0Y"]
[Sun Aug 30 03:12:31.770482 2026] [security2:error] [pid 521505:tid 521749] [client 20.48.160.90:50553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/d7.php"] [unique_id "apPl728byYE0iXl--K6i8wAAA5A"]
[Sun Aug 30 03:12:31.808634 2026] [security2:error] [pid 521505:tid 521717] [client 158.23.184.117:34568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/goods.php"] [unique_id "apPl728byYE0iXl--K6i9QAAA3A"]
[Sun Aug 30 03:12:31.845753 2026] [security2:error] [pid 524122:tid 524266] [client 158.23.184.117:17991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/dex.php"] [unique_id "apPl733lhEjKFiK_nBKDawAAAZw"]
[Sun Aug 30 03:12:31.860540 2026] [security2:error] [pid 524122:tid 524311] [client 20.104.50.220:5612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/52.php"] [unique_id "apPl733lhEjKFiK_nBKDbQAAAck"]
[Sun Aug 30 03:12:31.863893 2026] [authz_core:error] [pid 524122:tid 524261] [client 216.73.216.128:17046] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:31.864170 2026] [authz_core:error] [pid 524122:tid 524261] [client 216.73.216.128:17046] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:31.871238 2026] [security2:error] [pid 524122:tid 524345] [client 20.104.50.220:24863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/crgio.php"] [unique_id "apPl733lhEjKFiK_nBKDbwAAAes"]
[Sun Aug 30 03:12:31.905056 2026] [security2:error] [pid 521505:tid 521735] [client 20.48.160.90:50556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/v5.php"] [unique_id "apPl728byYE0iXl--K6i_QAAA4I"]
[Sun Aug 30 03:12:31.909200 2026] [security2:error] [pid 524122:tid 524366] [client 20.197.61.180:1669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/buy.php"] [unique_id "apPl733lhEjKFiK_nBKDcAAAAgA"]
[Sun Aug 30 03:12:31.915311 2026] [security2:error] [pid 521505:tid 521706] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/class-wp-logo-new.php"] [unique_id "apPl728byYE0iXl--K6i_gAAA2U"]
[Sun Aug 30 03:12:31.928195 2026] [security2:error] [pid 521505:tid 521636] [client 4.205.62.107:28692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/phpsysinfo.php"] [unique_id "apPl728byYE0iXl--K6i_wAAAx8"]
[Sun Aug 30 03:12:31.947398 2026] [security2:error] [pid 524122:tid 524308] [client 158.23.184.117:34577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/g.php"] [unique_id "apPl733lhEjKFiK_nBKDcQAAAcY"]
[Sun Aug 30 03:12:31.986422 2026] [security2:error] [pid 521505:tid 521753] [client 158.23.184.117:18313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/disagrsxr.php"] [unique_id "apPl728byYE0iXl--K6jAQAAA5Q"]
[Sun Aug 30 03:12:31.993921 2026] [authz_core:error] [pid 521505:tid 521665] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory30
[Sun Aug 30 03:12:31.994203 2026] [authz_core:error] [pid 521505:tid 521665] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory30
[Sun Aug 30 03:12:32.004260 2026] [authz_core:error] [pid 524122:tid 524312] [client 66.249.66.70:37604] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:32.004730 2026] [authz_core:error] [pid 524122:tid 524312] [client 66.249.66.70:37604] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:32.027780 2026] [authz_core:error] [pid 521505:tid 521648] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:32.028053 2026] [authz_core:error] [pid 521505:tid 521648] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:32.035342 2026] [security2:error] [pid 524122:tid 524346] [client 20.48.160.90:45316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/az.php"] [unique_id "apPl8H3lhEjKFiK_nBKDdwAAAew"]
[Sun Aug 30 03:12:32.037909 2026] [security2:error] [pid 521505:tid 521649] [client 216.73.216.128:5884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_security_considerations"] [unique_id "apPl8G8byYE0iXl--K6jBAAAAyw"]
[Sun Aug 30 03:12:32.038914 2026] [security2:error] [pid 521505:tid 521750] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/classwithtostring.php"] [unique_id "apPl8G8byYE0iXl--K6jBQAAA5E"]
[Sun Aug 30 03:12:32.045348 2026] [security2:error] [pid 524122:tid 524371] [client 20.104.50.220:62270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/efile.php"] [unique_id "apPl8H3lhEjKFiK_nBKDeAAAAgU"]
[Sun Aug 30 03:12:32.062344 2026] [security2:error] [pid 521505:tid 521714] [client 20.151.200.44:52157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/wk/index.php"] [unique_id "apPl8G8byYE0iXl--K6jBgAAA20"]
[Sun Aug 30 03:12:32.080444 2026] [security2:error] [pid 521505:tid 521722] [client 20.196.209.81:20942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/theme-check/theme-check.php"] [unique_id "apPl8G8byYE0iXl--K6jCAAAA3U"]
[Sun Aug 30 03:12:32.085394 2026] [security2:error] [pid 521505:tid 521685] [client 20.48.251.3:59987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dennis-skirvin.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPl8G8byYE0iXl--K6jCQAAA1A"]
[Sun Aug 30 03:12:32.089843 2026] [security2:error] [pid 521505:tid 521734] [client 158.23.184.117:34563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/hplfuns.php"] [unique_id "apPl8G8byYE0iXl--K6jCgAAA4E"]
[Sun Aug 30 03:12:32.097389 2026] [security2:error] [pid 521505:tid 521752] [client 20.104.50.220:16722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/ciera702.php"] [unique_id "apPl8G8byYE0iXl--K6jCwAAA5M"]
[Sun Aug 30 03:12:32.107872 2026] [authz_core:error] [pid 521505:tid 521694] [client 66.249.66.41:53135] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:32.108139 2026] [authz_core:error] [pid 521505:tid 521694] [client 66.249.66.41:53135] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:32.114881 2026] [security2:error] [pid 521505:tid 521731] [client 20.104.18.15:22509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/chosen.php"] [unique_id "apPl8G8byYE0iXl--K6jDgAAA34"]
[Sun Aug 30 03:12:32.125703 2026] [security2:error] [pid 524122:tid 524290] [client 158.23.184.117:18314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/domvf.php"] [unique_id "apPl8H3lhEjKFiK_nBKDeQAAAbQ"]
[Sun Aug 30 03:12:32.130085 2026] [security2:error] [pid 521505:tid 521697] [client 216.73.216.128:2147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/usage_202509.html"] [unique_id "apPl8G8byYE0iXl--K6jDwAAA1w"]
[Sun Aug 30 03:12:32.157597 2026] [security2:error] [pid 524122:tid 524343] [client 4.205.62.107:16816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/params.php"] [unique_id "apPl8H3lhEjKFiK_nBKDewAAAek"]
[Sun Aug 30 03:12:32.160412 2026] [security2:error] [pid 521505:tid 521745] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/cms.php"] [unique_id "apPl8G8byYE0iXl--K6jEAAAA4w"]
[Sun Aug 30 03:12:32.180338 2026] [security2:error] [pid 521505:tid 521684] [client 20.48.160.90:45320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/js.php"] [unique_id "apPl8G8byYE0iXl--K6jEQAAA08"]
[Sun Aug 30 03:12:32.182715 2026] [security2:error] [pid 521505:tid 521744] [client 20.104.18.15:1878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/vpn.php"] [unique_id "apPl8G8byYE0iXl--K6jEgAAA4s"]
[Sun Aug 30 03:12:32.210403 2026] [security2:error] [pid 521505:tid 521730] [client 20.104.50.220:62813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/dh.php"] [unique_id "apPl8G8byYE0iXl--K6jFQAAA30"]
[Sun Aug 30 03:12:32.221698 2026] [security2:error] [pid 524122:tid 524340] [client 216.73.216.128:17046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPl8H3lhEjKFiK_nBKDfAAAAeY"]
[Sun Aug 30 03:12:32.232007 2026] [security2:error] [pid 521505:tid 521662] [client 158.23.184.117:34615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/ioxi-o.php"] [unique_id "apPl8G8byYE0iXl--K6jGAAAAzk"]
[Sun Aug 30 03:12:32.246388 2026] [authz_core:error] [pid 524122:tid 524253] [client 66.249.66.44:42320] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:32.246866 2026] [authz_core:error] [pid 524122:tid 524253] [client 66.249.66.44:42320] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:32.266235 2026] [security2:error] [pid 521505:tid 521653] [client 158.23.184.117:18415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/donate.php"] [unique_id "apPl8G8byYE0iXl--K6jGQAAAzA"]
[Sun Aug 30 03:12:32.276412 2026] [security2:error] [pid 524122:tid 524344] [client 20.104.50.220:42759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/2index.php"] [unique_id "apPl8H3lhEjKFiK_nBKDfwAAAeo"]
[Sun Aug 30 03:12:32.280169 2026] [security2:error] [pid 521505:tid 521671] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/config.php"] [unique_id "apPl8G8byYE0iXl--K6jGgAAA0I"]
[Sun Aug 30 03:12:32.323015 2026] [authz_core:error] [pid 521505:tid 521761] [client 216.73.216.128:16328] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:32.323306 2026] [authz_core:error] [pid 521505:tid 521761] [client 216.73.216.128:16328] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:32.326332 2026] [security2:error] [pid 521505:tid 521754] [client 20.48.160.90:45330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/hd.php"] [unique_id "apPl8G8byYE0iXl--K6jHAAAA5U"]
[Sun Aug 30 03:12:32.363322 2026] [security2:error] [pid 524122:tid 524268] [client 20.104.49.130:59520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/666.php"] [unique_id "apPl8H3lhEjKFiK_nBKDgAAAAZ4"]
[Sun Aug 30 03:12:32.371719 2026] [security2:error] [pid 521505:tid 521732] [client 158.23.184.117:51680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/in.php"] [unique_id "apPl8G8byYE0iXl--K6jHQAAA38"]
[Sun Aug 30 03:12:32.384264 2026] [security2:error] [pid 521505:tid 521664] [client 4.205.62.107:25473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/test1.php"] [unique_id "apPl8G8byYE0iXl--K6jHwAAAzs"]
[Sun Aug 30 03:12:32.387886 2026] [security2:error] [pid 521505:tid 521728] [client 20.104.18.15:51040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/beck.php"] [unique_id "apPl8G8byYE0iXl--K6jIQAAA3s"]
[Sun Aug 30 03:12:32.399052 2026] [security2:error] [pid 521505:tid 521711] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/configs.php"] [unique_id "apPl8G8byYE0iXl--K6jIwAAA2o"]
[Sun Aug 30 03:12:32.406328 2026] [security2:error] [pid 521505:tid 521639] [client 158.23.184.117:18030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/dropdown.php"] [unique_id "apPl8G8byYE0iXl--K6jJAAAAyI"]
[Sun Aug 30 03:12:32.425329 2026] [security2:error] [pid 521505:tid 521713] [client 20.104.50.220:32867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/73.php"] [unique_id "apPl8G8byYE0iXl--K6jJQAAA2w"]
[Sun Aug 30 03:12:32.457780 2026] [security2:error] [pid 524122:tid 524305] [client 20.48.160.90:50491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/xl2023.php"] [unique_id "apPl8H3lhEjKFiK_nBKDgQAAAcM"]
[Sun Aug 30 03:12:32.460158 2026] [authz_core:error] [pid 521505:tid 521655] [client 216.73.216.128:35963] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:32.460431 2026] [authz_core:error] [pid 521505:tid 521655] [client 216.73.216.128:35963] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:32.466529 2026] [security2:error] [pid 521505:tid 521719] [client 4.205.62.107:15586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/gecko-litespeed.php"] [unique_id "apPl8G8byYE0iXl--K6jKgAAA3I"]
[Sun Aug 30 03:12:32.473537 2026] [security2:error] [pid 524122:tid 524360] [client 20.196.209.81:8533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/theme/about.php"] [unique_id "apPl8H3lhEjKFiK_nBKDggAAAfo"]
[Sun Aug 30 03:12:32.506541 2026] [security2:error] [pid 524122:tid 524280] [client 20.48.251.3:59361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/old_phpinfo.php"] [unique_id "apPl8H3lhEjKFiK_nBKDgwAAAao"]
[Sun Aug 30 03:12:32.512493 2026] [security2:error] [pid 521505:tid 521749] [client 158.23.184.117:51664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/info.php"] [unique_id "apPl8G8byYE0iXl--K6jLAAAA5A"]
[Sun Aug 30 03:12:32.516949 2026] [authz_core:error] [pid 521505:tid 521720] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory33
[Sun Aug 30 03:12:32.517402 2026] [authz_core:error] [pid 521505:tid 521720] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory33
[Sun Aug 30 03:12:32.518328 2026] [security2:error] [pid 524122:tid 524349] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/configuration.php"] [unique_id "apPl8H3lhEjKFiK_nBKDhAAAAe8"]
[Sun Aug 30 03:12:32.529241 2026] [security2:error] [pid 524122:tid 524335] [client 4.205.62.107:15861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/X57.php"] [unique_id "apPl8H3lhEjKFiK_nBKDhQAAAeE"]
[Sun Aug 30 03:12:32.540139 2026] [security2:error] [pid 521505:tid 521666] [client 20.48.251.3:65504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/public/rip.php.php"] [unique_id "apPl8G8byYE0iXl--K6jLQAAAz0"]
[Sun Aug 30 03:12:32.550163 2026] [security2:error] [pid 524122:tid 524362] [client 158.23.184.117:18013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/edit.php"] [unique_id "apPl8H3lhEjKFiK_nBKDhgAAAfw"]
[Sun Aug 30 03:12:32.552018 2026] [authz_core:error] [pid 521505:tid 521695] [client 216.73.216.128:2013] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:32.552304 2026] [authz_core:error] [pid 521505:tid 521695] [client 216.73.216.128:2013] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:32.594775 2026] [authz_core:error] [pid 521505:tid 521706] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:32.595231 2026] [authz_core:error] [pid 521505:tid 521706] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:32.595255 2026] [authz_core:error] [pid 521505:tid 521636] [client 216.73.216.128:16328] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:32.595751 2026] [authz_core:error] [pid 521505:tid 521636] [client 216.73.216.128:16328] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:32.597348 2026] [security2:error] [pid 521505:tid 521729] [client 20.48.160.90:50519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/V2.php"] [unique_id "apPl8G8byYE0iXl--K6jNAAAA3w"]
[Sun Aug 30 03:12:32.628197 2026] [security2:error] [pid 524122:tid 524329] [client 20.48.251.3:36995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/aws_auth.php"] [unique_id "apPl8H3lhEjKFiK_nBKDiAAAAds"]
[Sun Aug 30 03:12:32.629197 2026] [security2:error] [pid 524122:tid 524334] [client 20.104.49.130:36794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/wpxml.php"] [unique_id "apPl8H3lhEjKFiK_nBKDiQAAAeA"]
[Sun Aug 30 03:12:32.638562 2026] [security2:error] [pid 521505:tid 521643] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/content.php"] [unique_id "apPl8G8byYE0iXl--K6jNQAAAyY"]
[Sun Aug 30 03:12:32.646706 2026] [security2:error] [pid 521505:tid 521756] [client 20.197.61.180:1703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/hello.php"] [unique_id "apPl8G8byYE0iXl--K6jNwAAA5c"]
[Sun Aug 30 03:12:32.648452 2026] [security2:error] [pid 524122:tid 524358] [client 158.23.184.117:34196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/inputs.php"] [unique_id "apPl8H3lhEjKFiK_nBKDigAAAfg"]
[Sun Aug 30 03:12:32.673827 2026] [security2:error] [pid 524122:tid 524352] [client 20.48.251.3:43098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/params.php"] [unique_id "apPl8H3lhEjKFiK_nBKDiwAAAfI"]
[Sun Aug 30 03:12:32.682451 2026] [authz_core:error] [pid 521505:tid 521698] [client 66.249.66.68:44024] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:32.682793 2026] [authz_core:error] [pid 521505:tid 521698] [client 66.249.66.68:44024] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:32.689879 2026] [security2:error] [pid 521505:tid 521753] [client 158.23.184.117:18010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/ee.php"] [unique_id "apPl8G8byYE0iXl--K6jOgAAA5Q"]
[Sun Aug 30 03:12:32.732952 2026] [security2:error] [pid 521505:tid 521740] [client 20.48.160.90:45398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/mad.php"] [unique_id "apPl8G8byYE0iXl--K6jOwAAA4c"]
[Sun Aug 30 03:12:32.741216 2026] [security2:error] [pid 521505:tid 521693] [client 20.104.50.220:31175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-admin/network/wp-conflg.php"] [unique_id "apPl8G8byYE0iXl--K6jPAAAA1g"]
[Sun Aug 30 03:12:32.760363 2026] [security2:error] [pid 524122:tid 524369] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/core.php"] [unique_id "apPl8H3lhEjKFiK_nBKDjQAAAgM"]
[Sun Aug 30 03:12:32.784471 2026] [security2:error] [pid 521505:tid 521685] [client 20.104.50.220:29614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/FoxWSOv1.php"] [unique_id "apPl8G8byYE0iXl--K6jPQAAA1A"]
[Sun Aug 30 03:12:32.787027 2026] [security2:error] [pid 521505:tid 521679] [client 158.23.184.117:34576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/item.php"] [unique_id "apPl8G8byYE0iXl--K6jPgAAA0o"]
[Sun Aug 30 03:12:32.813287 2026] [authz_core:error] [pid 524122:tid 524322] [client 66.249.66.45:47874] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:32.813547 2026] [authz_core:error] [pid 524122:tid 524322] [client 66.249.66.45:47874] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:32.836684 2026] [security2:error] [pid 521505:tid 521712] [client 158.23.184.117:18425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/elp.php"] [unique_id "apPl8G8byYE0iXl--K6jQQAAA2s"]
[Sun Aug 30 03:12:32.860174 2026] [autoindex:error] [pid 524122:tid 524350] [client 34.237.50.25:18987] AH01276: Cannot serve directory /home3/antgre7/top15healthinsurance.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:12:32.866473 2026] [security2:error] [pid 521505:tid 521716] [client 20.196.209.81:8248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/theme/min.php"] [unique_id "apPl8G8byYE0iXl--K6jRAAAA28"]
[Sun Aug 30 03:12:32.867557 2026] [security2:error] [pid 524122:tid 524321] [client 20.48.160.90:50533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/st.php"] [unique_id "apPl8H3lhEjKFiK_nBKDkQAAAdM"]
[Sun Aug 30 03:12:32.885463 2026] [security2:error] [pid 521505:tid 521701] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/data.php"] [unique_id "apPl8G8byYE0iXl--K6jRQAAA2A"]
[Sun Aug 30 03:12:32.926793 2026] [security2:error] [pid 521505:tid 521762] [client 158.23.184.117:34216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/k.php"] [unique_id "apPl8G8byYE0iXl--K6jRwAAA50"]
[Sun Aug 30 03:12:32.939174 2026] [security2:error] [pid 524122:tid 524286] [client 158.23.147.79:16267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/log-mama/function.php"] [unique_id "apPl8H3lhEjKFiK_nBKDkwAAAbA"]
[Sun Aug 30 03:12:32.958586 2026] [authz_core:error] [pid 524122:tid 524274] [client 66.249.66.78:46556] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:32.958874 2026] [authz_core:error] [pid 524122:tid 524274] [client 66.249.66.78:46556] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:32.978511 2026] [security2:error] [pid 524122:tid 524270] [client 158.23.184.117:18423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/en.php"] [unique_id "apPl8H3lhEjKFiK_nBKDlwAAAaA"]
[Sun Aug 30 03:12:33.011460 2026] [security2:error] [pid 524122:tid 524296] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/database.php"] [unique_id "apPl8X3lhEjKFiK_nBKDmAAAAbo"]
[Sun Aug 30 03:12:33.011897 2026] [security2:error] [pid 524122:tid 524374] [client 20.48.160.90:45413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/alfanew.php"] [unique_id "apPl8X3lhEjKFiK_nBKDmQAAAgg"]
[Sun Aug 30 03:12:33.013820 2026] [authz_core:error] [pid 521505:tid 521744] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory17
[Sun Aug 30 03:12:33.014085 2026] [authz_core:error] [pid 521505:tid 521744] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory17
[Sun Aug 30 03:12:33.014885 2026] [security2:error] [pid 524122:tid 524348] [client 20.104.50.220:6091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/51.php"] [unique_id "apPl8X3lhEjKFiK_nBKDmgAAAe4"]
[Sun Aug 30 03:12:33.019868 2026] [security2:error] [pid 524122:tid 524265] [client 20.104.50.220:24907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/geforce.php"] [unique_id "apPl8X3lhEjKFiK_nBKDmwAAAZs"]
[Sun Aug 30 03:12:33.051470 2026] [authz_core:error] [pid 521505:tid 521640] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:33.051740 2026] [authz_core:error] [pid 521505:tid 521640] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:33.062889 2026] [security2:error] [pid 524122:tid 524336] [client 4.205.62.107:29157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/sgd.php"] [unique_id "apPl8X3lhEjKFiK_nBKDngAAAeI"]
[Sun Aug 30 03:12:33.065422 2026] [security2:error] [pid 524122:tid 524326] [client 158.23.184.117:34226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/license.php"] [unique_id "apPl8X3lhEjKFiK_nBKDnwAAAdg"]
[Sun Aug 30 03:12:33.080320 2026] [security2:error] [pid 521505:tid 521662] [client 20.151.200.44:52155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/dehnl.php"] [unique_id "apPl8W8byYE0iXl--K6jTgAAAzk"]
[Sun Aug 30 03:12:33.122086 2026] [security2:error] [pid 521505:tid 521730] [client 158.23.184.117:18017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.djsevenevents.com"] [uri "/error.php"] [unique_id "apPl8W8byYE0iXl--K6jUAAAA30"]
[Sun Aug 30 03:12:33.129652 2026] [security2:error] [pid 524122:tid 524254] [client 20.151.200.44:26585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/wt.php"] [unique_id "apPl8X3lhEjKFiK_nBKDoAAAAZA"]
[Sun Aug 30 03:12:33.135061 2026] [security2:error] [pid 521505:tid 521647] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/db.php"] [unique_id "apPl8W8byYE0iXl--K6jUgAAAyo"]
[Sun Aug 30 03:12:33.140320 2026] [authz_core:error] [pid 524122:tid 524313] [client 66.249.66.66:46792] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:33.140632 2026] [authz_core:error] [pid 524122:tid 524313] [client 66.249.66.66:46792] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:33.155834 2026] [security2:error] [pid 521505:tid 521651] [client 20.48.160.90:45328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/ioxi.php"] [unique_id "apPl8W8byYE0iXl--K6jUwAAAy4"]
[Sun Aug 30 03:12:33.207363 2026] [security2:error] [pid 524122:tid 524347] [client 158.23.184.117:34619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/load.php"] [unique_id "apPl8X3lhEjKFiK_nBKDowAAAe0"]
[Sun Aug 30 03:12:33.228696 2026] [authz_core:error] [pid 521505:tid 521747] [client 216.73.216.128:35963] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:33.228954 2026] [authz_core:error] [pid 521505:tid 521747] [client 216.73.216.128:35963] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:33.241836 2026] [security2:error] [pid 521505:tid 521657] [client 20.104.50.220:16740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/chaya986.php"] [unique_id "apPl8W8byYE0iXl--K6jVQAAAzQ"]
[Sun Aug 30 03:12:33.252504 2026] [security2:error] [pid 521505:tid 521682] [client 20.104.18.15:22404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/file1221.php"] [unique_id "apPl8W8byYE0iXl--K6jVgAAA00"]
[Sun Aug 30 03:12:33.254395 2026] [security2:error] [pid 521505:tid 521709] [client 20.104.50.220:61462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/afile.php"] [unique_id "apPl8W8byYE0iXl--K6jVwAAA2g"]
[Sun Aug 30 03:12:33.256018 2026] [security2:error] [pid 521505:tid 521653] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/default.php"] [unique_id "apPl8W8byYE0iXl--K6jWAAAAzA"]
[Sun Aug 30 03:12:33.259933 2026] [security2:error] [pid 524122:tid 524363] [client 20.196.209.81:20975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/themes/about.php"] [unique_id "apPl8X3lhEjKFiK_nBKDpgAAAf0"]
[Sun Aug 30 03:12:33.289769 2026] [security2:error] [pid 521505:tid 521644] [client 4.205.62.107:17702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/gjm.php"] [unique_id "apPl8W8byYE0iXl--K6jWQAAAyc"]
[Sun Aug 30 03:12:33.299294 2026] [security2:error] [pid 521505:tid 521755] [client 20.48.160.90:45416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/TNT.php"] [unique_id "apPl8W8byYE0iXl--K6jWgAAA5Y"]
[Sun Aug 30 03:12:33.301115 2026] [security2:error] [pid 521505:tid 521638] [client 20.104.49.130:59993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/wp-good.php"] [unique_id "apPl8W8byYE0iXl--K6jWwAAAyE"]
[Sun Aug 30 03:12:33.324421 2026] [security2:error] [pid 521505:tid 521664] [client 20.104.18.15:1882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/goods.php"] [unique_id "apPl8W8byYE0iXl--K6jXwAAAzs"]
[Sun Aug 30 03:12:33.350034 2026] [security2:error] [pid 524122:tid 524318] [client 158.23.184.117:34204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/manager.php"] [unique_id "apPl8X3lhEjKFiK_nBKDqgAAAdA"]
[Sun Aug 30 03:12:33.358060 2026] [security2:error] [pid 521505:tid 521711] [client 20.104.50.220:62792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/%E5%B9%B3%E4%BB%AE%E5%90%8Ds.php"] [unique_id "apPl8W8byYE0iXl--K6jYAAAA2o"]
[Sun Aug 30 03:12:33.368693 2026] [authz_core:error] [pid 524122:tid 524366] [client 66.249.66.74:53720] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:33.369181 2026] [authz_core:error] [pid 524122:tid 524366] [client 66.249.66.74:53720] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:33.370367 2026] [authz_core:error] [pid 521505:tid 521639] [client 66.249.66.196:62607] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:33.370821 2026] [authz_core:error] [pid 521505:tid 521639] [client 66.249.66.196:62607] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:33.375987 2026] [security2:error] [pid 524122:tid 524373] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/dev1s.php"] [unique_id "apPl8X3lhEjKFiK_nBKDrAAAAgc"]
[Sun Aug 30 03:12:33.377920 2026] [security2:error] [pid 524122:tid 524378] [client 20.197.61.180:1297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/g.php"] [unique_id "apPl8X3lhEjKFiK_nBKDrQAAAgw"]
[Sun Aug 30 03:12:33.406744 2026] [security2:error] [pid 521505:tid 521675] [client 20.104.50.220:41986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/32.php"] [unique_id "apPl8W8byYE0iXl--K6jZwAAA0Y"]
[Sun Aug 30 03:12:33.430529 2026] [security2:error] [pid 521505:tid 521733] [client 20.48.160.90:50476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/cd.php"] [unique_id "apPl8W8byYE0iXl--K6jaAAAA4A"]
[Sun Aug 30 03:12:33.471978 2026] [authz_core:error] [pid 521505:tid 521658] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory19
[Sun Aug 30 03:12:33.472381 2026] [authz_core:error] [pid 521505:tid 521658] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory19
[Sun Aug 30 03:12:33.494216 2026] [security2:error] [pid 521505:tid 521761] [client 158.23.184.117:52845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/media.php"] [unique_id "apPl8W8byYE0iXl--K6jbAAAA5w"]
[Sun Aug 30 03:12:33.496288 2026] [security2:error] [pid 521505:tid 521721] [client 20.151.200.44:52072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/png.php"] [unique_id "apPl8W8byYE0iXl--K6jbQAAA3Q"]
[Sun Aug 30 03:12:33.498240 2026] [security2:error] [pid 524122:tid 524300] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/dex.php"] [unique_id "apPl8X3lhEjKFiK_nBKDrwAAAb4"]
[Sun Aug 30 03:12:33.526910 2026] [security2:error] [pid 521505:tid 521751] [client 20.104.18.15:51180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/t3.php"] [unique_id "apPl8W8byYE0iXl--K6jbwAAA5I"]
[Sun Aug 30 03:12:33.554712 2026] [security2:error] [pid 521505:tid 521729] [client 4.205.62.107:25873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/bigdump.php"] [unique_id "apPl8W8byYE0iXl--K6jcQAAA3w"]
[Sun Aug 30 03:12:33.567619 2026] [security2:error] [pid 521505:tid 521736] [client 20.104.50.220:33058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/al.php"] [unique_id "apPl8W8byYE0iXl--K6jcwAAA4M"]
[Sun Aug 30 03:12:33.570674 2026] [security2:error] [pid 524122:tid 524301] [client 20.48.160.90:50477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/luuf.php"] [unique_id "apPl8X3lhEjKFiK_nBKDsAAAAb8"]
[Sun Aug 30 03:12:33.574694 2026] [authz_core:error] [pid 521505:tid 521756] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:33.575145 2026] [authz_core:error] [pid 521505:tid 521756] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:33.608952 2026] [security2:error] [pid 521505:tid 521708] [client 4.205.62.107:15499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/goods.php"] [unique_id "apPl8W8byYE0iXl--K6jdgAAA2c"]
[Sun Aug 30 03:12:33.623029 2026] [security2:error] [pid 524122:tid 524371] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/disagrsxr.php"] [unique_id "apPl8X3lhEjKFiK_nBKDswAAAgU"]
[Sun Aug 30 03:12:33.638167 2026] [security2:error] [pid 521505:tid 521706] [client 158.23.184.117:34185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/mar.php"] [unique_id "apPl8W8byYE0iXl--K6jeAAAA2U"]
[Sun Aug 30 03:12:33.644043 2026] [security2:error] [pid 521505:tid 521740] [client 20.48.251.3:52771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.greatinjury.com"] [uri "/wp-act.php"] [unique_id "apPl8W8byYE0iXl--K6jeQAAA4c"]
[Sun Aug 30 03:12:33.659809 2026] [security2:error] [pid 521505:tid 521678] [client 20.196.209.81:8975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/themes/panel.php"] [unique_id "apPl8W8byYE0iXl--K6jegAAA0k"]
[Sun Aug 30 03:12:33.668874 2026] [security2:error] [pid 521505:tid 521725] [client 4.205.62.107:15819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/register.php"] [unique_id "apPl8W8byYE0iXl--K6jewAAA3g"]
[Sun Aug 30 03:12:33.676580 2026] [security2:error] [pid 521505:tid 521748] [client 20.151.200.44:52138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/txets.php"] [unique_id "apPl8W8byYE0iXl--K6jfAAAA48"]
[Sun Aug 30 03:12:33.682908 2026] [security2:error] [pid 521505:tid 521679] [client 20.48.251.3:65520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/environment.php"] [unique_id "apPl8W8byYE0iXl--K6jfwAAA0o"]
[Sun Aug 30 03:12:33.707709 2026] [security2:error] [pid 521505:tid 521712] [client 20.48.160.90:50474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/fex.php"] [unique_id "apPl8W8byYE0iXl--K6jgAAAA2s"]
[Sun Aug 30 03:12:33.734377 2026] [authz_core:error] [pid 524122:tid 524264] [client 66.249.66.78:57865] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:33.734655 2026] [authz_core:error] [pid 524122:tid 524264] [client 66.249.66.78:57865] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:33.744052 2026] [security2:error] [pid 521505:tid 521741] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/domvf.php"] [unique_id "apPl8W8byYE0iXl--K6jggAAA4g"]
[Sun Aug 30 03:12:33.764570 2026] [security2:error] [pid 524122:tid 524343] [client 20.48.251.3:37159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/hiquido.com/index.php"] [unique_id "apPl8X3lhEjKFiK_nBKDtQAAAek"]
[Sun Aug 30 03:12:33.778291 2026] [security2:error] [pid 524122:tid 524291] [client 158.23.184.117:52801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/my1.php"] [unique_id "apPl8X3lhEjKFiK_nBKDtwAAAbU"]
[Sun Aug 30 03:12:33.828912 2026] [security2:error] [pid 521505:tid 521701] [client 20.104.49.130:54149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/ty.php"] [unique_id "apPl8W8byYE0iXl--K6jgwAAA2A"]
[Sun Aug 30 03:12:33.842775 2026] [security2:error] [pid 524122:tid 524333] [client 20.48.160.90:50554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/l.php"] [unique_id "apPl8X3lhEjKFiK_nBKDugAAAd8"]
[Sun Aug 30 03:12:33.849008 2026] [security2:error] [pid 521505:tid 521681] [client 20.48.251.3:52178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/gjm.php"] [unique_id "apPl8W8byYE0iXl--K6jhgAAA0w"]
[Sun Aug 30 03:12:33.864140 2026] [security2:error] [pid 524122:tid 524285] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/donate.php"] [unique_id "apPl8X3lhEjKFiK_nBKDuwAAAa8"]
[Sun Aug 30 03:12:33.877132 2026] [authz_core:error] [pid 521505:tid 521677] [client 216.73.216.128:16328] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:33.877397 2026] [authz_core:error] [pid 521505:tid 521677] [client 216.73.216.128:16328] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:33.879790 2026] [security2:error] [pid 521505:tid 521650] [client 20.104.50.220:30926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/click.php"] [unique_id "apPl8W8byYE0iXl--K6jiQAAAy0"]
[Sun Aug 30 03:12:33.884841 2026] [security2:error] [pid 524122:tid 524309] [client 20.151.200.44:44020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ermes-it.it"] [uri "/attack.php"] [unique_id "apPl8X3lhEjKFiK_nBKDvgAAAcc"]
[Sun Aug 30 03:12:33.886109 2026] [authz_core:error] [pid 524122:tid 524268] [client 66.249.66.66:56396] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:33.886391 2026] [authz_core:error] [pid 524122:tid 524268] [client 66.249.66.66:56396] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:33.887679 2026] [authz_core:error] [pid 524122:tid 524344] [client 66.249.66.75:64202] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:33.888031 2026] [authz_core:error] [pid 524122:tid 524344] [client 66.249.66.75:64202] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:33.920341 2026] [security2:error] [pid 521505:tid 521689] [client 158.23.184.117:58112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/mm.php"] [unique_id "apPl8W8byYE0iXl--K6jjAAAA1Q"]
[Sun Aug 30 03:12:33.945596 2026] [security2:error] [pid 521505:tid 521698] [client 158.23.147.79:58403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/bk/index.php"] [unique_id "apPl8W8byYE0iXl--K6jjQAAA10"]
[Sun Aug 30 03:12:33.967188 2026] [security2:error] [pid 521505:tid 521743] [client 3.79.134.69:46390] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "catherinevalewines.com.au"] [uri "/index.php"] [unique_id "apPl728byYE0iXl--K6i-wAAA4o"], referer: https://catherinevalewines.com.au/
[Sun Aug 30 03:12:33.968285 2026] [authz_core:error] [pid 521505:tid 521662] [client 216.73.216.128:2013] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:33.968560 2026] [authz_core:error] [pid 521505:tid 521662] [client 216.73.216.128:2013] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:33.971222 2026] [security2:error] [pid 521505:tid 521640] [client 20.104.50.220:52825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/foxwsov1.php"] [unique_id "apPl8W8byYE0iXl--K6jkQAAAyM"]
[Sun Aug 30 03:12:33.972304 2026] [security2:error] [pid 521505:tid 521667] [client 20.48.160.90:50440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/xr.php"] [unique_id "apPl8W8byYE0iXl--K6jkgAAAz4"]
[Sun Aug 30 03:12:33.976157 2026] [authz_core:error] [pid 521505:tid 521651] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory14
[Sun Aug 30 03:12:33.976427 2026] [authz_core:error] [pid 521505:tid 521651] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory14
[Sun Aug 30 03:12:33.990451 2026] [security2:error] [pid 521505:tid 521744] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/dropdown.php"] [unique_id "apPl8W8byYE0iXl--K6jkwAAA4s"]
[Sun Aug 30 03:12:34.003057 2026] [security2:error] [pid 524122:tid 524298] [client 20.104.49.130:63262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/users.php"] [unique_id "apPl8n3lhEjKFiK_nBKDvwAAAbw"]
[Sun Aug 30 03:12:34.056226 2026] [authz_core:error] [pid 521505:tid 521709] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:34.056484 2026] [authz_core:error] [pid 521505:tid 521709] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:34.060368 2026] [security2:error] [pid 521505:tid 521669] [client 158.23.184.117:51691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/network.php"] [unique_id "apPl8m8byYE0iXl--K6jlgAAA0A"]
[Sun Aug 30 03:12:34.074505 2026] [autoindex:error] [pid 521505:tid 521688] [client 20.196.209.81:8201] AH01276: Cannot serve directory /home1/lehugh/public_html/etax4u.com/wp-content/themes/twentytwentyfive/styles/sections/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:12:34.103618 2026] [security2:error] [pid 521505:tid 521644] [client 20.48.160.90:50486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/Q3.php"] [unique_id "apPl8m8byYE0iXl--K6jmQAAAyc"]
[Sun Aug 30 03:12:34.106651 2026] [security2:error] [pid 521505:tid 521645] [client 20.197.61.180:1303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/cc.php"] [unique_id "apPl8m8byYE0iXl--K6jmgAAAyg"]
[Sun Aug 30 03:12:34.113053 2026] [security2:error] [pid 521505:tid 521754] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/edit.php"] [unique_id "apPl8m8byYE0iXl--K6jmwAAA5U"]
[Sun Aug 30 03:12:34.140691 2026] [security2:error] [pid 521505:tid 521664] [client 20.104.49.130:54195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/dk.php"] [unique_id "apPl8m8byYE0iXl--K6jnAAAAzs"]
[Sun Aug 30 03:12:34.150670 2026] [security2:error] [pid 521505:tid 521728] [client 20.151.200.44:52102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/wp-login.php"] [unique_id "apPl8m8byYE0iXl--K6jngAAA3s"]
[Sun Aug 30 03:12:34.173979 2026] [security2:error] [pid 524122:tid 524362] [client 20.104.50.220:5599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/50.php"] [unique_id "apPl8n3lhEjKFiK_nBKDwQAAAfw"]
[Sun Aug 30 03:12:34.176115 2026] [security2:error] [pid 524122:tid 524316] [client 20.104.50.220:25412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/pucci.php"] [unique_id "apPl8n3lhEjKFiK_nBKDwgAAAc4"]
[Sun Aug 30 03:12:34.202903 2026] [security2:error] [pid 524122:tid 524342] [client 158.23.184.117:34213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/new.php"] [unique_id "apPl8n3lhEjKFiK_nBKDwwAAAeg"]
[Sun Aug 30 03:12:34.205531 2026] [security2:error] [pid 521505:tid 521726] [client 20.196.209.81:8201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/twentytwentyfive/styles/sections/pk.php"] [unique_id "apPl8m8byYE0iXl--K6jnwAAA3k"]
[Sun Aug 30 03:12:34.206230 2026] [security2:error] [pid 521505:tid 521686] [client 4.205.62.107:28713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/fleen.php"] [unique_id "apPl8m8byYE0iXl--K6joAAAA1E"]
[Sun Aug 30 03:12:34.220986 2026] [security2:error] [pid 521505:tid 521661] [client 20.151.200.44:26583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/im.php"] [unique_id "apPl8m8byYE0iXl--K6joQAAAzg"]
[Sun Aug 30 03:12:34.235746 2026] [security2:error] [pid 521505:tid 521707] [client 20.48.160.90:50480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/Q1.php"] [unique_id "apPl8m8byYE0iXl--K6jogAAA2Y"]
[Sun Aug 30 03:12:34.239365 2026] [security2:error] [pid 521505:tid 521759] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/ee.php"] [unique_id "apPl8m8byYE0iXl--K6jowAAA5o"]
[Sun Aug 30 03:12:34.271427 2026] [security2:error] [pid 524122:tid 524320] [client 20.104.49.130:54190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/as.php"] [unique_id "apPl8n3lhEjKFiK_nBKDxgAAAdI"]
[Sun Aug 30 03:12:34.343580 2026] [security2:error] [pid 521505:tid 521719] [client 158.23.184.117:34192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/0x.php"] [unique_id "apPl8m8byYE0iXl--K6jpQAAA3I"]
[Sun Aug 30 03:12:34.360521 2026] [security2:error] [pid 521505:tid 521723] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/elp.php"] [unique_id "apPl8m8byYE0iXl--K6jpgAAA3Y"]
[Sun Aug 30 03:12:34.374842 2026] [security2:error] [pid 524122:tid 524287] [client 20.104.50.220:17326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/charmaine744.php"] [unique_id "apPl8n3lhEjKFiK_nBKDxwAAAbE"]
[Sun Aug 30 03:12:34.378517 2026] [security2:error] [pid 521505:tid 521692] [client 20.48.160.90:45323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/nz.php"] [unique_id "apPl8m8byYE0iXl--K6jqgAAA1c"]
[Sun Aug 30 03:12:34.388551 2026] [security2:error] [pid 521505:tid 521694] [client 20.104.18.15:22517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/nox.php"] [unique_id "apPl8m8byYE0iXl--K6jqwAAA1k"]
[Sun Aug 30 03:12:34.421546 2026] [security2:error] [pid 521505:tid 521705] [client 20.104.50.220:61438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/f35.php"] [unique_id "apPl8m8byYE0iXl--K6jrQAAA2Q"]
[Sun Aug 30 03:12:34.426990 2026] [security2:error] [pid 521505:tid 521736] [client 4.205.62.107:16829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/configuration.php"] [unique_id "apPl8m8byYE0iXl--K6jrgAAA4M"]
[Sun Aug 30 03:12:34.466072 2026] [security2:error] [pid 521505:tid 521740] [client 20.104.18.15:1881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/alfa.php"] [unique_id "apPl8m8byYE0iXl--K6jsQAAA4c"]
[Sun Aug 30 03:12:34.485397 2026] [security2:error] [pid 521505:tid 521708] [client 158.23.184.117:34615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/0.php"] [unique_id "apPl8m8byYE0iXl--K6jtQAAA2c"]
[Sun Aug 30 03:12:34.485512 2026] [security2:error] [pid 521505:tid 521687] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/en.php"] [unique_id "apPl8m8byYE0iXl--K6jtAAAA1I"]
[Sun Aug 30 03:12:34.485969 2026] [authz_core:error] [pid 521505:tid 521678] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory10
[Sun Aug 30 03:12:34.486376 2026] [authz_core:error] [pid 521505:tid 521678] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory10
[Sun Aug 30 03:12:34.508424 2026] [security2:error] [pid 524122:tid 524369] [client 216.73.216.128:37108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPl8n3lhEjKFiK_nBKDygAAAgM"]
[Sun Aug 30 03:12:34.521962 2026] [security2:error] [pid 521505:tid 521748] [client 20.48.160.90:45326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/sg.php"] [unique_id "apPl8m8byYE0iXl--K6jtgAAA48"]
[Sun Aug 30 03:12:34.553380 2026] [security2:error] [pid 521505:tid 521712] [client 20.104.50.220:63502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/404.php"] [unique_id "apPl8m8byYE0iXl--K6jugAAA2s"]
[Sun Aug 30 03:12:34.563017 2026] [authz_core:error] [pid 521505:tid 521731] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:34.563467 2026] [authz_core:error] [pid 521505:tid 521731] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:34.577162 2026] [security2:error] [pid 524122:tid 524321] [client 20.104.50.220:62841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-includes/rest-api/fields/anbu.php"] [unique_id "apPl8n3lhEjKFiK_nBKDzAAAAdM"]
[Sun Aug 30 03:12:34.605039 2026] [security2:error] [pid 521505:tid 521724] [client 158.23.184.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.getchellgarden.com"] [uri "/error.php"] [unique_id "apPl8m8byYE0iXl--K6jvQAAA3c"]
[Sun Aug 30 03:12:34.625872 2026] [security2:error] [pid 521505:tid 521697] [client 158.23.184.117:34608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/oxshell.php"] [unique_id "apPl8m8byYE0iXl--K6jwAAAA1w"]
[Sun Aug 30 03:12:34.645938 2026] [autoindex:error] [pid 521505:tid 521693] [client 20.196.209.81:8993] AH01276: Cannot serve directory /home1/lehugh/public_html/etax4u.com/wp-content/themes/twentytwentythree/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:12:34.657516 2026] [security2:error] [pid 521505:tid 521704] [client 20.48.160.90:45327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/hypo.php"] [unique_id "apPl8m8byYE0iXl--K6jwgAAA2M"]
[Sun Aug 30 03:12:34.666239 2026] [security2:error] [pid 521505:tid 521685] [client 20.104.18.15:51125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/wp.php"] [unique_id "apPl8m8byYE0iXl--K6jwwAAA1A"]
[Sun Aug 30 03:12:34.697649 2026] [authz_core:error] [pid 521505:tid 521673] [client 216.73.216.128:35963] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:34.697909 2026] [authz_core:error] [pid 521505:tid 521673] [client 216.73.216.128:35963] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:34.715964 2026] [security2:error] [pid 521505:tid 521689] [client 20.104.50.220:33323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/alf.php"] [unique_id "apPl8m8byYE0iXl--K6jxQAAA1Q"]
[Sun Aug 30 03:12:34.744208 2026] [security2:error] [pid 521505:tid 521665] [client 4.205.62.107:15815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/loxi-o.php"] [unique_id "apPl8m8byYE0iXl--K6jyQAAAzw"]
[Sun Aug 30 03:12:34.767837 2026] [security2:error] [pid 521505:tid 521757] [client 158.23.184.117:34177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/php8.php"] [unique_id "apPl8m8byYE0iXl--K6jzAAAA5g"]
[Sun Aug 30 03:12:34.784960 2026] [security2:error] [pid 521505:tid 521699] [client 20.196.209.81:8993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/twentytwentythree/patterns/index.php"] [unique_id "apPl8m8byYE0iXl--K6jzgAAA14"]
[Sun Aug 30 03:12:34.786065 2026] [security2:error] [pid 521505:tid 521700] [client 4.205.62.107:25870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/wdf.php"] [unique_id "apPl8m8byYE0iXl--K6jzwAAA18"]
[Sun Aug 30 03:12:34.797046 2026] [security2:error] [pid 521505:tid 521657] [client 20.48.160.90:50498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/Hd.php"] [unique_id "apPl8m8byYE0iXl--K6j0AAAAzQ"]
[Sun Aug 30 03:12:34.806852 2026] [security2:error] [pid 521505:tid 521677] [client 4.205.62.107:15979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/xqq.php"] [unique_id "apPl8m8byYE0iXl--K6j0gAAA0g"]
[Sun Aug 30 03:12:34.844138 2026] [security2:error] [pid 521505:tid 521637] [client 20.48.251.3:54803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/aws_secret_config.php"] [unique_id "apPl8m8byYE0iXl--K6j1AAAAyA"]
[Sun Aug 30 03:12:34.862656 2026] [security2:error] [pid 521505:tid 521695] [client 20.197.61.180:8965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/f35.php"] [unique_id "apPl8m8byYE0iXl--K6j1QAAA1o"]
[Sun Aug 30 03:12:34.907283 2026] [security2:error] [pid 521505:tid 521718] [client 158.23.184.117:51653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/p.php"] [unique_id "apPl8m8byYE0iXl--K6j1gAAA3E"]
[Sun Aug 30 03:12:34.923617 2026] [security2:error] [pid 524122:tid 524289] [client 20.48.160.90:50487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/im.php"] [unique_id "apPl8n3lhEjKFiK_nBKDzQAAAbM"]
[Sun Aug 30 03:12:34.930918 2026] [security2:error] [pid 521505:tid 521709] [client 20.48.251.3:36992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/ws79.php"] [unique_id "apPl8m8byYE0iXl--K6j2AAAA2g"]
[Sun Aug 30 03:12:34.963863 2026] [authz_core:error] [pid 521505:tid 521747] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory18
[Sun Aug 30 03:12:34.964132 2026] [authz_core:error] [pid 521505:tid 521747] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory18
[Sun Aug 30 03:12:34.995545 2026] [security2:error] [pid 524122:tid 524283] [client 20.48.251.3:43101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/configuration.php"] [unique_id "apPl8n3lhEjKFiK_nBKDzwAAAa0"]
[Sun Aug 30 03:12:35.028539 2026] [security2:error] [pid 521505:tid 521676] [client 158.23.147.79:16381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.brandscape.qa"] [uri "/first.php"] [unique_id "apPl828byYE0iXl--K6j3gAAA0c"]
[Sun Aug 30 03:12:35.029750 2026] [authz_core:error] [pid 521505:tid 521675] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:35.030026 2026] [authz_core:error] [pid 521505:tid 521675] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:35.032491 2026] [security2:error] [pid 521505:tid 521733] [client 20.104.50.220:30956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/install.php"] [unique_id "apPl828byYE0iXl--K6j3wAAA4A"]
[Sun Aug 30 03:12:35.047819 2026] [security2:error] [pid 521505:tid 521671] [client 158.23.184.117:51654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/php.php"] [unique_id "apPl828byYE0iXl--K6j4AAAA0I"]
[Sun Aug 30 03:12:35.054175 2026] [security2:error] [pid 521505:tid 521717] [client 20.104.49.130:36776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/mh.php"] [unique_id "apPl828byYE0iXl--K6j4QAAA3A"]
[Sun Aug 30 03:12:35.057185 2026] [security2:error] [pid 521505:tid 521666] [client 20.48.160.90:45368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/fc.php"] [unique_id "apPl828byYE0iXl--K6j4wAAAz0"]
[Sun Aug 30 03:12:35.146022 2026] [security2:error] [pid 521505:tid 521663] [client 216.73.216.128:43463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPl828byYE0iXl--K6j5wAAAzo"]
[Sun Aug 30 03:12:35.160386 2026] [security2:error] [pid 521505:tid 521746] [client 20.104.50.220:29145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/FoxWSOv2.php"] [unique_id "apPl828byYE0iXl--K6j6AAAA40"]
[Sun Aug 30 03:12:35.181584 2026] [authz_core:error] [pid 521505:tid 521729] [client 66.249.66.205:46173] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:35.181861 2026] [authz_core:error] [pid 521505:tid 521729] [client 66.249.66.205:46173] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:35.188293 2026] [security2:error] [pid 521505:tid 521751] [client 158.23.184.117:51660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/past.php"] [unique_id "apPl828byYE0iXl--K6j6wAAA5I"]
[Sun Aug 30 03:12:35.189115 2026] [security2:error] [pid 521505:tid 521705] [client 20.48.160.90:50528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/ke.php"] [unique_id "apPl828byYE0iXl--K6j7AAAA2Q"]
[Sun Aug 30 03:12:35.269150 2026] [security2:error] [pid 521505:tid 521714] [client 20.151.200.44:52125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/wp-access.php"] [unique_id "apPl828byYE0iXl--K6j7gAAA20"]
[Sun Aug 30 03:12:35.274711 2026] [security2:error] [pid 524122:tid 524265] [client 20.151.200.44:46074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/wp-access.php"] [unique_id "apPl833lhEjKFiK_nBKD0QAAAZs"]
[Sun Aug 30 03:12:35.327421 2026] [security2:error] [pid 524122:tid 524357] [client 158.23.184.117:51693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/root.php"] [unique_id "apPl833lhEjKFiK_nBKD0wAAAfc"]
[Sun Aug 30 03:12:35.340243 2026] [security2:error] [pid 521505:tid 521748] [client 4.205.62.107:29148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/upload.form.php"] [unique_id "apPl828byYE0iXl--K6j8gAAA48"]
[Sun Aug 30 03:12:35.350623 2026] [security2:error] [pid 521505:tid 521756] [client 20.48.160.90:45383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/tf.php"] [unique_id "apPl828byYE0iXl--K6j9AAAA5c"]
[Sun Aug 30 03:12:35.353055 2026] [security2:error] [pid 524122:tid 524336] [client 20.104.50.220:5498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/49.php"] [unique_id "apPl833lhEjKFiK_nBKD1AAAAeI"]
[Sun Aug 30 03:12:35.360809 2026] [security2:error] [pid 521505:tid 521735] [client 20.196.209.81:20990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/users.php"] [unique_id "apPl828byYE0iXl--K6j9QAAA4I"]
[Sun Aug 30 03:12:35.424588 2026] [authz_core:error] [pid 524122:tid 524314] [client 66.249.66.74:53720] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:35.424943 2026] [authz_core:error] [pid 524122:tid 524314] [client 66.249.66.74:53720] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:35.467249 2026] [security2:error] [pid 524122:tid 524256] [client 158.23.184.117:51674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/r.php"] [unique_id "apPl833lhEjKFiK_nBKD1wAAAZI"]
[Sun Aug 30 03:12:35.487690 2026] [authz_core:error] [pid 521505:tid 521745] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory16
[Sun Aug 30 03:12:35.487951 2026] [authz_core:error] [pid 521505:tid 521745] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory16
[Sun Aug 30 03:12:35.488537 2026] [security2:error] [pid 521505:tid 521742] [client 20.48.160.90:45325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/px.php"] [unique_id "apPl828byYE0iXl--K6j_QAAA4k"]
[Sun Aug 30 03:12:35.511369 2026] [security2:error] [pid 521505:tid 521678] [client 20.104.50.220:16639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/charity744.php"] [unique_id "apPl828byYE0iXl--K6j_wAAA0k"]
[Sun Aug 30 03:12:35.556454 2026] [security2:error] [pid 524122:tid 524322] [client 20.104.50.220:25465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/wp-temp.php"] [unique_id "apPl833lhEjKFiK_nBKD2AAAAdQ"]
[Sun Aug 30 03:12:35.559719 2026] [security2:error] [pid 521505:tid 521684] [client 216.73.216.128:23664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_abook_opened"] [unique_id "apPl828byYE0iXl--K6kBQAAA08"]
[Sun Aug 30 03:12:35.563254 2026] [security2:error] [pid 521505:tid 521665] [client 20.104.50.220:62252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/goods.php"] [unique_id "apPl828byYE0iXl--K6kBgAAAzw"]
[Sun Aug 30 03:12:35.565086 2026] [authz_core:error] [pid 521505:tid 521689] [client 66.249.66.35:49884] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:35.565374 2026] [authz_core:error] [pid 521505:tid 521689] [client 66.249.66.35:49884] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:35.565503 2026] [security2:error] [pid 524122:tid 524379] [client 4.205.62.107:17416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/server_info.php"] [unique_id "apPl833lhEjKFiK_nBKD2QAAAg0"]
[Sun Aug 30 03:12:35.567882 2026] [authz_core:error] [pid 521505:tid 521710] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:35.568317 2026] [authz_core:error] [pid 521505:tid 521710] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:35.570576 2026] [security2:error] [pid 524122:tid 524254] [client 20.104.18.15:22478] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "appsneakpeek.com"] [uri "/1.php"] [unique_id "apPl833lhEjKFiK_nBKD2gAAAZA"]
[Sun Aug 30 03:12:35.570698 2026] [security2:error] [pid 524122:tid 524254] [client 20.104.18.15:22478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/1.php"] [unique_id "apPl833lhEjKFiK_nBKD2gAAAZA"]
[Sun Aug 30 03:12:35.592897 2026] [security2:error] [pid 521505:tid 521734] [client 20.197.61.180:1689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/classsmtps.php"] [unique_id "apPl828byYE0iXl--K6kCQAAA4E"]
[Sun Aug 30 03:12:35.598550 2026] [autoindex:error] [pid 521505:tid 521649] [client 20.63.219.114:13822] AH01276: Cannot serve directory /home4/devstol/public_html/deevosdesigns.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:12:35.599724 2026] [security2:error] [pid 524122:tid 524272] [client 20.104.18.15:1893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/133.php"] [unique_id "apPl833lhEjKFiK_nBKD2wAAAaI"]
[Sun Aug 30 03:12:35.607503 2026] [security2:error] [pid 521505:tid 521730] [client 158.23.184.117:34613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/sid3.php"] [unique_id "apPl828byYE0iXl--K6kCwAAA30"]
[Sun Aug 30 03:12:35.608609 2026] [authz_core:error] [pid 521505:tid 521744] [client 216.73.216.128:2013] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:35.608893 2026] [authz_core:error] [pid 521505:tid 521744] [client 216.73.216.128:2013] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:35.608912 2026] [fcgid:warn] [pid 524122:tid 524347] (70014)End of file found: [client 199.45.154.60:38744] mod_fcgid: can't get data from http client
[Sun Aug 30 03:12:35.628519 2026] [security2:error] [pid 521505:tid 521720] [client 20.48.160.90:45392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/jg.php"] [unique_id "apPl828byYE0iXl--K6kDAAAA3M"]
[Sun Aug 30 03:12:35.646862 2026] [security2:error] [pid 521505:tid 521653] [client 20.104.49.130:63237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/echkm.php"] [unique_id "apPl828byYE0iXl--K6kDQAAAzA"]
[Sun Aug 30 03:12:35.706897 2026] [security2:error] [pid 524122:tid 524330] [client 20.104.50.220:42011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/4x4.php"] [unique_id "apPl833lhEjKFiK_nBKD3QAAAdw"]
[Sun Aug 30 03:12:35.710057 2026] [security2:error] [pid 521505:tid 521638] [client 20.104.50.220:29359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/anbu.php"] [unique_id "apPl828byYE0iXl--K6kDwAAAyE"]
[Sun Aug 30 03:12:35.747556 2026] [security2:error] [pid 524122:tid 524275] [client 158.23.184.117:34587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/ss.php"] [unique_id "apPl833lhEjKFiK_nBKD3gAAAaU"]
[Sun Aug 30 03:12:35.756793 2026] [security2:error] [pid 521505:tid 521754] [client 20.48.160.90:50513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/yj.php"] [unique_id "apPl828byYE0iXl--K6kEAAAA5U"]
[Sun Aug 30 03:12:35.788919 2026] [security2:error] [pid 521505:tid 521688] [client 20.196.209.81:9009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/wp-cron.php"] [unique_id "apPl828byYE0iXl--K6kEQAAA1M"]
[Sun Aug 30 03:12:35.832244 2026] [security2:error] [pid 521505:tid 521664] [client 20.104.18.15:51082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/abcd.php"] [unique_id "apPl828byYE0iXl--K6kEgAAAzs"]
[Sun Aug 30 03:12:35.873061 2026] [security2:error] [pid 524122:tid 524378] [client 20.104.50.220:33158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/alf4.php"] [unique_id "apPl833lhEjKFiK_nBKD4AAAAgw"]
[Sun Aug 30 03:12:35.879458 2026] [security2:error] [pid 521505:tid 521728] [client 4.205.62.107:15494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/f35.php"] [unique_id "apPl828byYE0iXl--K6kFQAAA3s"]
[Sun Aug 30 03:12:35.886764 2026] [security2:error] [pid 521505:tid 521673] [client 158.23.184.117:34215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/sts.php"] [unique_id "apPl828byYE0iXl--K6kFgAAA0Q"]
[Sun Aug 30 03:12:35.891474 2026] [security2:error] [pid 521505:tid 521760] [client 20.48.160.90:45335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/zi.php"] [unique_id "apPl828byYE0iXl--K6kFwAAA5s"]
[Sun Aug 30 03:12:35.919325 2026] [security2:error] [pid 524122:tid 524299] [client 4.205.62.107:25732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/bb.php"] [unique_id "apPl833lhEjKFiK_nBKD4QAAAb0"]
[Sun Aug 30 03:12:35.943810 2026] [security2:error] [pid 521505:tid 521709] [client 4.205.62.107:16325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/a1vx.php"] [unique_id "apPl828byYE0iXl--K6kGAAAA2g"]
[Sun Aug 30 03:12:35.986687 2026] [security2:error] [pid 521505:tid 521759] [client 20.48.251.3:65484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/snq.php"] [unique_id "apPl828byYE0iXl--K6kGgAAA5o"]
[Sun Aug 30 03:12:35.989795 2026] [authz_core:error] [pid 521505:tid 521680] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory13
[Sun Aug 30 03:12:35.990077 2026] [authz_core:error] [pid 521505:tid 521680] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory13
[Sun Aug 30 03:12:36.021384 2026] [security2:error] [pid 521505:tid 521660] [client 20.48.160.90:50527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/ue.php"] [unique_id "apPl9G8byYE0iXl--K6kGwAAAzc"]
[Sun Aug 30 03:12:36.023058 2026] [security2:error] [pid 521505:tid 521659] [client 20.104.49.130:63493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/txets.php"] [unique_id "apPl9G8byYE0iXl--K6kHAAAAzY"]
[Sun Aug 30 03:12:36.026782 2026] [security2:error] [pid 521505:tid 521686] [client 158.23.184.117:58125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/shell.php"] [unique_id "apPl9G8byYE0iXl--K6kHQAAA1E"]
[Sun Aug 30 03:12:36.047156 2026] [authz_core:error] [pid 521505:tid 521691] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:36.047468 2026] [authz_core:error] [pid 521505:tid 521691] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:36.065018 2026] [security2:error] [pid 521505:tid 521702] [client 20.151.200.44:52122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/wp-content/admin.php"] [unique_id "apPl9G8byYE0iXl--K6kHwAAA2E"]
[Sun Aug 30 03:12:36.103690 2026] [security2:error] [pid 524122:tid 524323] [client 20.48.251.3:37016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/public/wp-blog.php"] [unique_id "apPl9H3lhEjKFiK_nBKD5gAAAdU"]
[Sun Aug 30 03:12:36.127009 2026] [authz_core:error] [pid 524122:tid 524276] [client 66.249.66.44:42320] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:36.127439 2026] [authz_core:error] [pid 524122:tid 524276] [client 66.249.66.44:42320] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:36.154050 2026] [security2:error] [pid 521505:tid 521747] [client 20.48.160.90:40291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/nv.php"] [unique_id "apPl9G8byYE0iXl--K6kIwAAA44"]
[Sun Aug 30 03:12:36.165615 2026] [security2:error] [pid 524122:tid 524297] [client 20.48.251.3:52256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/server_info.php"] [unique_id "apPl9H3lhEjKFiK_nBKD6AAAAbs"]
[Sun Aug 30 03:12:36.166801 2026] [security2:error] [pid 524122:tid 524290] [client 158.23.184.117:34182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/setup-config.php"] [unique_id "apPl9H3lhEjKFiK_nBKD6QAAAbQ"]
[Sun Aug 30 03:12:36.178528 2026] [security2:error] [pid 524122:tid 524368] [client 20.104.50.220:63192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/lv.php"] [unique_id "apPl9H3lhEjKFiK_nBKD6gAAAgI"]
[Sun Aug 30 03:12:36.212592 2026] [security2:error] [pid 524122:tid 524260] [client 20.196.209.81:20932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/wp-links-opml.php"] [unique_id "apPl9H3lhEjKFiK_nBKD6wAAAZY"]
[Sun Aug 30 03:12:36.250327 2026] [authz_core:error] [pid 524122:tid 524310] [client 216.73.216.128:18347] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:36.250603 2026] [authz_core:error] [pid 524122:tid 524310] [client 216.73.216.128:18347] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:36.295710 2026] [security2:error] [pid 521505:tid 521652] [client 20.48.160.90:45321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/jw.php"] [unique_id "apPl9G8byYE0iXl--K6kJwAAAy8"]
[Sun Aug 30 03:12:36.306207 2026] [security2:error] [pid 524122:tid 524359] [client 158.23.184.117:51704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/t.php"] [unique_id "apPl9H3lhEjKFiK_nBKD7gAAAfk"]
[Sun Aug 30 03:12:36.312819 2026] [security2:error] [pid 524122:tid 524376] [client 20.197.61.180:1307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/install.php"] [unique_id "apPl9H3lhEjKFiK_nBKD7wAAAgo"]
[Sun Aug 30 03:12:36.316310 2026] [security2:error] [pid 524122:tid 524282] [client 20.104.50.220:52863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/foxwsov2.php"] [unique_id "apPl9H3lhEjKFiK_nBKD8AAAAaw"]
[Sun Aug 30 03:12:36.398029 2026] [security2:error] [pid 524122:tid 524305] [client 20.151.200.44:26519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/file.php"] [unique_id "apPl9H3lhEjKFiK_nBKD8wAAAcM"]
[Sun Aug 30 03:12:36.436492 2026] [security2:error] [pid 524122:tid 524269] [client 20.104.49.130:36769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/press.php"] [unique_id "apPl9H3lhEjKFiK_nBKD9QAAAZ8"]
[Sun Aug 30 03:12:36.444538 2026] [security2:error] [pid 521505:tid 521707] [client 20.48.160.90:45357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/or.php"] [unique_id "apPl9G8byYE0iXl--K6kLQAAA2Y"]
[Sun Aug 30 03:12:36.447626 2026] [security2:error] [pid 524122:tid 524360] [client 158.23.184.117:34586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/up.php"] [unique_id "apPl9H3lhEjKFiK_nBKD9gAAAfo"]
[Sun Aug 30 03:12:36.479419 2026] [authz_core:error] [pid 521505:tid 521694] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory31
[Sun Aug 30 03:12:36.479685 2026] [authz_core:error] [pid 521505:tid 521694] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory31
[Sun Aug 30 03:12:36.480097 2026] [security2:error] [pid 524122:tid 524264] [client 4.205.62.107:29147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/aws_auth.php"] [unique_id "apPl9H3lhEjKFiK_nBKD9wAAAZo"]
[Sun Aug 30 03:12:36.510315 2026] [security2:error] [pid 524122:tid 524255] [client 20.104.50.220:6125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/48.php"] [unique_id "apPl9H3lhEjKFiK_nBKD-AAAAZE"]
[Sun Aug 30 03:12:36.565192 2026] [authz_core:error] [pid 521505:tid 521756] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:36.565453 2026] [authz_core:error] [pid 521505:tid 521756] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:36.580460 2026] [security2:error] [pid 521505:tid 521735] [client 20.48.160.90:45409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/ile56.php"] [unique_id "apPl9G8byYE0iXl--K6kMAAAA4I"]
[Sun Aug 30 03:12:36.592073 2026] [security2:error] [pid 524122:tid 524316] [client 158.23.184.117:52863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/ultra.php"] [unique_id "apPl9H3lhEjKFiK_nBKD-gAAAc4"]
[Sun Aug 30 03:12:36.603458 2026] [security2:error] [pid 524122:tid 524267] [client 20.196.209.81:8219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/wp-load.php"] [unique_id "apPl9H3lhEjKFiK_nBKD-wAAAZ0"]
[Sun Aug 30 03:12:36.648011 2026] [security2:error] [pid 521505:tid 521729] [client 20.104.50.220:17319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/camryn118.php"] [unique_id "apPl9G8byYE0iXl--K6kMwAAA3w"]
[Sun Aug 30 03:12:36.708613 2026] [security2:error] [pid 524122:tid 524364] [client 4.205.62.107:17427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/hosty.php"] [unique_id "apPl9H3lhEjKFiK_nBKD_gAAAf4"]
[Sun Aug 30 03:12:36.711594 2026] [security2:error] [pid 521505:tid 521681] [client 20.104.50.220:62212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/enclas.php"] [unique_id "apPl9G8byYE0iXl--K6kOAAAA0w"]
[Sun Aug 30 03:12:36.713246 2026] [security2:error] [pid 521505:tid 521704] [client 20.104.18.15:22410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/m.php"] [unique_id "apPl9G8byYE0iXl--K6kOQAAA2M"]
[Sun Aug 30 03:12:36.718782 2026] [security2:error] [pid 524122:tid 524268] [client 20.48.160.90:45404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/emmh.php"] [unique_id "apPl9H3lhEjKFiK_nBKD_wAAAZ4"]
[Sun Aug 30 03:12:36.734540 2026] [security2:error] [pid 524122:tid 524352] [client 158.23.184.117:51670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/vv.php"] [unique_id "apPl9H3lhEjKFiK_nBKEAAAAAfI"]
[Sun Aug 30 03:12:36.751863 2026] [security2:error] [pid 524122:tid 524328] [client 20.104.18.15:1934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/sym.php"] [unique_id "apPl9H3lhEjKFiK_nBKEAQAAAdo"]
[Sun Aug 30 03:12:36.823313 2026] [security2:error] [pid 521505:tid 521684] [client 20.104.50.220:24851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/mode.php"] [unique_id "apPl9G8byYE0iXl--K6kPAAAA08"]
[Sun Aug 30 03:12:36.834827 2026] [authz_core:error] [pid 521505:tid 521665] [client 66.249.66.78:43390] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:36.835081 2026] [authz_core:error] [pid 521505:tid 521665] [client 66.249.66.78:43390] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:36.850935 2026] [security2:error] [pid 524122:tid 524344] [client 20.48.160.90:50481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/em.php"] [unique_id "apPl9H3lhEjKFiK_nBKEAgAAAeo"]
[Sun Aug 30 03:12:36.860549 2026] [security2:error] [pid 521505:tid 521743] [client 20.104.50.220:42007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/73.php"] [unique_id "apPl9G8byYE0iXl--K6kPgAAA4o"]
[Sun Aug 30 03:12:36.868785 2026] [security2:error] [pid 524122:tid 524321] [client 20.104.50.220:63042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-content/%E5%B9%B3%E4%BB%AE%E5%90%8Ds.php"] [unique_id "apPl9H3lhEjKFiK_nBKEAwAAAdM"]
[Sun Aug 30 03:12:36.875346 2026] [security2:error] [pid 521505:tid 521642] [client 158.23.184.117:52818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/V5.php"] [unique_id "apPl9G8byYE0iXl--K6kPwAAAyU"]
[Sun Aug 30 03:12:36.891071 2026] [security2:error] [pid 521505:tid 521657] [client 20.104.49.130:63260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/amax.php"] [unique_id "apPl9G8byYE0iXl--K6kQwAAAzQ"]
[Sun Aug 30 03:12:36.975079 2026] [security2:error] [pid 521505:tid 521755] [client 20.104.18.15:51095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/nofile.php"] [unique_id "apPl9G8byYE0iXl--K6kSAAAA5Y"]
[Sun Aug 30 03:12:36.981727 2026] [security2:error] [pid 521505:tid 521698] [client 20.48.160.90:45340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/dvve.php"] [unique_id "apPl9G8byYE0iXl--K6kSQAAA10"]
[Sun Aug 30 03:12:36.984448 2026] [security2:error] [pid 521505:tid 521638] [client 20.151.200.44:46068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/wp-content/admin.php"] [unique_id "apPl9G8byYE0iXl--K6kSgAAAyE"]
[Sun Aug 30 03:12:36.994814 2026] [security2:error] [pid 524122:tid 524369] [client 20.196.209.81:20989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/wp-settings.php"] [unique_id "apPl9H3lhEjKFiK_nBKEBwAAAgM"]
[Sun Aug 30 03:12:37.008511 2026] [security2:error] [pid 521505:tid 521753] [client 20.104.49.130:54193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.perfectsalesperson.com"] [uri "/edit.php"] [unique_id "apPl9W8byYE0iXl--K6kTQAAA5Q"]
[Sun Aug 30 03:12:37.016284 2026] [security2:error] [pid 521505:tid 521745] [client 158.23.184.117:58139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/wp-user.php"] [unique_id "apPl9W8byYE0iXl--K6kTwAAA4w"]
[Sun Aug 30 03:12:37.018950 2026] [security2:error] [pid 521505:tid 521645] [client 4.205.62.107:16381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/api.php"] [unique_id "apPl9W8byYE0iXl--K6kUAAAAyg"]
[Sun Aug 30 03:12:37.022561 2026] [authz_core:error] [pid 521505:tid 521635] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory26
[Sun Aug 30 03:12:37.022836 2026] [authz_core:error] [pid 521505:tid 521635] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory26
[Sun Aug 30 03:12:37.026580 2026] [security2:error] [pid 521505:tid 521654] [client 20.104.50.220:33201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/alfa-shell-v4.php"] [unique_id "apPl9W8byYE0iXl--K6kUgAAAzE"]
[Sun Aug 30 03:12:37.030532 2026] [authz_core:error] [pid 521505:tid 521703] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:37.030965 2026] [authz_core:error] [pid 521505:tid 521703] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:37.043496 2026] [security2:error] [pid 524122:tid 524154] [remote 97.74.87.194:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "flixytvstick.net"] [uri "/wp-login.php"] [unique_id "apPl9X3lhEjKFiK_nBKECAABmB4"]
[Sun Aug 30 03:12:37.050092 2026] [security2:error] [pid 521505:tid 521693] [client 20.197.61.180:8976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/wp.php"] [unique_id "apPl9W8byYE0iXl--K6kUwAAA1g"]
[Sun Aug 30 03:12:37.055098 2026] [security2:error] [pid 521505:tid 521637] [client 4.205.62.107:26956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/file59.php"] [unique_id "apPl9W8byYE0iXl--K6kVAAAAyA"]
[Sun Aug 30 03:12:37.080470 2026] [security2:error] [pid 521505:tid 521662] [client 4.205.62.107:15946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/public/vx.php"] [unique_id "apPl9W8byYE0iXl--K6kVgAAAzk"]
[Sun Aug 30 03:12:37.117268 2026] [security2:error] [pid 524122:tid 524327] [client 20.48.160.90:45329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/doo.php"] [unique_id "apPl9X3lhEjKFiK_nBKECQAAAdk"]
[Sun Aug 30 03:12:37.118187 2026] [security2:error] [pid 524122:tid 524289] [client 20.48.251.3:64309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/wp-access.php"] [unique_id "apPl9X3lhEjKFiK_nBKECgAAAbM"]
[Sun Aug 30 03:12:37.156669 2026] [security2:error] [pid 521505:tid 521718] [client 158.23.184.117:34566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/wp-blog.php"] [unique_id "apPl9W8byYE0iXl--K6kWwAAA3E"]
[Sun Aug 30 03:12:37.228299 2026] [authz_core:error] [pid 521505:tid 521686] [client 66.249.66.75:49739] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:37.228592 2026] [authz_core:error] [pid 521505:tid 521686] [client 66.249.66.75:49739] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:37.239366 2026] [security2:error] [pid 521505:tid 521737] [client 20.48.251.3:36852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/php-details.php"] [unique_id "apPl9W8byYE0iXl--K6kXQAAA4Q"]
[Sun Aug 30 03:12:37.243486 2026] [security2:error] [pid 521505:tid 521674] [client 216.73.216.128:16328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_config_quote_replace_string"] [unique_id "apPl9W8byYE0iXl--K6kXgAAA0U"]
[Sun Aug 30 03:12:37.250074 2026] [security2:error] [pid 521505:tid 521690] [client 20.48.160.90:45339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/adminer-4.6.6.php"] [unique_id "apPl9W8byYE0iXl--K6kXwAAA1U"]
[Sun Aug 30 03:12:37.288929 2026] [security2:error] [pid 524122:tid 524265] [client 20.104.49.130:32819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/df.php"] [unique_id "apPl9X3lhEjKFiK_nBKEDQAAAZs"]
[Sun Aug 30 03:12:37.297188 2026] [security2:error] [pid 521505:tid 521719] [client 158.23.184.117:34202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/wp.php"] [unique_id "apPl9W8byYE0iXl--K6kYAAAA3I"]
[Sun Aug 30 03:12:37.302699 2026] [security2:error] [pid 524122:tid 524357] [client 20.48.251.3:52167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/hosty.php"] [unique_id "apPl9X3lhEjKFiK_nBKEDgAAAfc"]
[Sun Aug 30 03:12:37.325240 2026] [security2:error] [pid 521505:tid 521751] [client 20.104.50.220:31512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/simple.php"] [unique_id "apPl9W8byYE0iXl--K6kYQAAA5I"]
[Sun Aug 30 03:12:37.382866 2026] [security2:error] [pid 524122:tid 524315] [client 20.48.160.90:45393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/gelap1.php"] [unique_id "apPl9X3lhEjKFiK_nBKEEAAAAc0"]
[Sun Aug 30 03:12:37.395312 2026] [security2:error] [pid 524122:tid 524348] [client 20.196.209.81:8220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/themes/wp-signup.php"] [unique_id "apPl9X3lhEjKFiK_nBKEEQAAAe4"]
[Sun Aug 30 03:12:37.438109 2026] [security2:error] [pid 521505:tid 521655] [client 158.23.184.117:34219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/worksec.php"] [unique_id "apPl9W8byYE0iXl--K6kYwAAAzI"]
[Sun Aug 30 03:12:37.467760 2026] [authz_core:error] [pid 521505:tid 521670] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory33
[Sun Aug 30 03:12:37.468012 2026] [authz_core:error] [pid 521505:tid 521670] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory33
[Sun Aug 30 03:12:37.516400 2026] [security2:error] [pid 521505:tid 521725] [client 20.48.160.90:45344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/rsjlrria.php"] [unique_id "apPl9W8byYE0iXl--K6kZgAAA3g"]
[Sun Aug 30 03:12:37.532987 2026] [security2:error] [pid 524122:tid 524341] [client 20.104.50.220:52854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/shellx.php"] [unique_id "apPl9X3lhEjKFiK_nBKEEwAAAec"]
[Sun Aug 30 03:12:37.558012 2026] [authz_core:error] [pid 521505:tid 521715] [client 66.249.66.68:36222] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:37.558401 2026] [authz_core:error] [pid 521505:tid 521715] [client 66.249.66.68:36222] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:37.563592 2026] [authz_core:error] [pid 521505:tid 521708] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:37.563860 2026] [authz_core:error] [pid 521505:tid 521708] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:37.581232 2026] [security2:error] [pid 524122:tid 524322] [client 158.23.184.117:34580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/wp-themes.php"] [unique_id "apPl9X3lhEjKFiK_nBKEFQAAAdQ"]
[Sun Aug 30 03:12:37.622996 2026] [security2:error] [pid 521505:tid 521668] [client 4.205.62.107:52863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/hiquido.com/index.php"] [unique_id "apPl9W8byYE0iXl--K6kbQAAAz8"]
[Sun Aug 30 03:12:37.654536 2026] [security2:error] [pid 521505:tid 521724] [client 20.48.160.90:45401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/AxAo.php"] [unique_id "apPl9W8byYE0iXl--K6kbwAAA3c"]
[Sun Aug 30 03:12:37.661555 2026] [security2:error] [pid 521505:tid 521694] [client 20.151.200.44:45964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/log.php"] [unique_id "apPl9W8byYE0iXl--K6kcAAAA1k"]
[Sun Aug 30 03:12:37.698832 2026] [security2:error] [pid 521505:tid 521704] [client 20.104.50.220:5611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/47.php"] [unique_id "apPl9W8byYE0iXl--K6kcQAAA2M"]
[Sun Aug 30 03:12:37.704785 2026] [authz_core:error] [pid 524122:tid 524274] [client 216.73.216.128:59424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:37.705049 2026] [authz_core:error] [pid 524122:tid 524274] [client 216.73.216.128:59424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:37.727668 2026] [security2:error] [pid 521505:tid 521722] [client 158.23.184.117:52859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/wp-signin.php"] [unique_id "apPl9W8byYE0iXl--K6kcgAAA3U"]
[Sun Aug 30 03:12:37.757776 2026] [security2:error] [pid 521505:tid 521540] [remote 170.64.135.172:45374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.135.64.170.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bac2myrootz.com"] [uri "/wp-login.php"] [unique_id "apPl9W8byYE0iXl--K6kdAADSyI"]
[Sun Aug 30 03:12:37.783449 2026] [security2:error] [pid 521505:tid 521684] [client 20.48.160.90:50525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/class17.php"] [unique_id "apPl9W8byYE0iXl--K6kdQAAA08"]
[Sun Aug 30 03:12:37.786310 2026] [security2:error] [pid 521505:tid 521707] [client 20.197.61.180:11331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/error.php"] [unique_id "apPl9W8byYE0iXl--K6kdgAAA2Y"]
[Sun Aug 30 03:12:37.790383 2026] [security2:error] [pid 521505:tid 521642] [client 20.104.50.220:16717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/byrdie906.php"] [unique_id "apPl9W8byYE0iXl--K6keAAAAyU"]
[Sun Aug 30 03:12:37.810913 2026] [security2:error] [pid 521505:tid 521734] [client 20.151.200.44:43980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ermes-it.it"] [uri "/wk/index.php"] [unique_id "apPl9W8byYE0iXl--K6keQAAA4E"]
[Sun Aug 30 03:12:37.819073 2026] [security2:error] [pid 521505:tid 521729] [client 20.196.209.81:20972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/updraft/about.php"] [unique_id "apPl9W8byYE0iXl--K6kewAAA3w"]
[Sun Aug 30 03:12:37.820543 2026] [security2:error] [pid 521505:tid 521561] [remote 97.74.87.194:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "flixytvstick.net"] [uri "/wp-login.php"] [unique_id "apPl9W8byYE0iXl--K6kegADXjc"], referer: https://flixytvstick.net/wp-login.php
[Sun Aug 30 03:12:37.854809 2026] [security2:error] [pid 521505:tid 521636] [client 20.104.18.15:22513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/fling.php"] [unique_id "apPl9W8byYE0iXl--K6kfgAAAx8"]
[Sun Aug 30 03:12:37.864719 2026] [security2:error] [pid 521505:tid 521653] [client 4.205.62.107:17222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/pass4.php"] [unique_id "apPl9W8byYE0iXl--K6kgAAAAzA"]
[Sun Aug 30 03:12:37.868457 2026] [security2:error] [pid 521505:tid 521700] [client 158.23.184.117:51699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/wp-blog-header.php"] [unique_id "apPl9W8byYE0iXl--K6kgQAAA18"]
[Sun Aug 30 03:12:37.873702 2026] [security2:error] [pid 521505:tid 521742] [client 20.151.200.44:62913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPl9W8byYE0iXl--K6kggAAA4k"]
[Sun Aug 30 03:12:37.887810 2026] [security2:error] [pid 521505:tid 521755] [client 20.104.18.15:2027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/8.php"] [unique_id "apPl9W8byYE0iXl--K6kgwAAA5Y"]
[Sun Aug 30 03:12:37.889073 2026] [security2:error] [pid 521505:tid 521698] [client 20.104.50.220:59546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/ioxi-o.php"] [unique_id "apPl9W8byYE0iXl--K6khAAAA10"]
[Sun Aug 30 03:12:37.916728 2026] [security2:error] [pid 521505:tid 521697] [client 20.48.160.90:45374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/okxoby.php"] [unique_id "apPl9W8byYE0iXl--K6khQAAA1w"]
[Sun Aug 30 03:12:37.962354 2026] [security2:error] [pid 524122:tid 524308] [client 20.104.50.220:24839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPl9X3lhEjKFiK_nBKEGwAAAcY"]
[Sun Aug 30 03:12:37.971391 2026] [authz_core:error] [pid 521505:tid 521757] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory26
[Sun Aug 30 03:12:37.971660 2026] [authz_core:error] [pid 521505:tid 521757] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory26
[Sun Aug 30 03:12:37.972520 2026] [security2:error] [pid 524122:tid 524299] [client 20.104.49.130:60652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/init.php"] [unique_id "apPl9X3lhEjKFiK_nBKEHgAAAb0"]
[Sun Aug 30 03:12:37.973075 2026] [authz_core:error] [pid 524122:tid 524375] [client 66.249.66.204:65141] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:37.973525 2026] [authz_core:error] [pid 524122:tid 524375] [client 66.249.66.204:65141] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:38.012111 2026] [security2:error] [pid 521505:tid 521662] [client 20.151.200.44:45978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/xwpg.php"] [unique_id "apPl9m8byYE0iXl--K6kiwAAAzk"]
[Sun Aug 30 03:12:38.015653 2026] [security2:error] [pid 521505:tid 521664] [client 20.104.50.220:52824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-admin/%E5%B9%B3%E4%BB%AE%E5%90%8Ds.php"] [unique_id "apPl9m8byYE0iXl--K6kjAAAAzs"]
[Sun Aug 30 03:12:38.024666 2026] [security2:error] [pid 521505:tid 521760] [client 20.104.50.220:63540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/al.php"] [unique_id "apPl9m8byYE0iXl--K6kjQAAA5s"]
[Sun Aug 30 03:12:38.040158 2026] [authz_core:error] [pid 521505:tid 521696] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:38.040406 2026] [authz_core:error] [pid 521505:tid 521696] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:38.048943 2026] [security2:error] [pid 521505:tid 521762] [client 20.48.160.90:45438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/esuutzzx.php"] [unique_id "apPl9m8byYE0iXl--K6kjwAAA50"]
[Sun Aug 30 03:12:38.121873 2026] [security2:error] [pid 521505:tid 521651] [client 20.104.18.15:51147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/run.php"] [unique_id "apPl9m8byYE0iXl--K6klAAAAy4"]
[Sun Aug 30 03:12:38.152683 2026] [security2:error] [pid 521505:tid 521683] [client 216.73.216.128:2013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPl9m8byYE0iXl--K6klQAAA04"]
[Sun Aug 30 03:12:38.156157 2026] [security2:error] [pid 521505:tid 521702] [client 4.205.62.107:16343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/temp.php"] [unique_id "apPl9m8byYE0iXl--K6klgAAA2E"]
[Sun Aug 30 03:12:38.163783 2026] [security2:error] [pid 521505:tid 521643] [client 20.104.50.220:32926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/alfakun.php"] [unique_id "apPl9m8byYE0iXl--K6klwAAAyY"]
[Sun Aug 30 03:12:38.192660 2026] [security2:error] [pid 521505:tid 521733] [client 158.23.184.117:51657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/ws.php"] [unique_id "apPl9m8byYE0iXl--K6kmAAAA4A"]
[Sun Aug 30 03:12:38.196323 2026] [security2:error] [pid 521505:tid 521737] [client 20.48.160.90:45314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/replace.php"] [unique_id "apPl9m8byYE0iXl--K6kmQAAA4Q"]
[Sun Aug 30 03:12:38.219678 2026] [security2:error] [pid 521505:tid 521690] [client 4.205.62.107:15999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/log.php"] [unique_id "apPl9m8byYE0iXl--K6kmgAAA1U"]
[Sun Aug 30 03:12:38.222802 2026] [security2:error] [pid 521505:tid 521532] [remote 170.64.135.172:45374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.135.64.170.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bac2myrootz.com"] [uri "/wp-login.php"] [unique_id "apPl9m8byYE0iXl--K6kmwADexo"], referer: https://bac2myrootz.com/wp-login.php
[Sun Aug 30 03:12:38.224553 2026] [security2:error] [pid 521505:tid 521710] [client 4.205.62.107:27010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/cli_bootstrap.php"] [unique_id "apPl9m8byYE0iXl--K6knAAAA2k"]
[Sun Aug 30 03:12:38.241966 2026] [security2:error] [pid 521505:tid 521703] [client 20.196.209.81:9017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/upgrade-temp-backup/min.php"] [unique_id "apPl9m8byYE0iXl--K6knQAAA2I"]
[Sun Aug 30 03:12:38.246176 2026] [security2:error] [pid 521505:tid 521691] [client 20.48.251.3:54813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/otuz1.php"] [unique_id "apPl9m8byYE0iXl--K6knwAAA1Y"]
[Sun Aug 30 03:12:38.296126 2026] [authz_core:error] [pid 521505:tid 521746] [client 66.249.66.37:49033] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:38.296391 2026] [authz_core:error] [pid 521505:tid 521746] [client 66.249.66.37:49033] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:38.299265 2026] [security2:error] [pid 521505:tid 521751] [client 20.151.200.44:52124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/log.php"] [unique_id "apPl9m8byYE0iXl--K6koQAAA5I"]
[Sun Aug 30 03:12:38.328905 2026] [security2:error] [pid 521505:tid 521725] [client 20.48.160.90:50550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/gulu.php"] [unique_id "apPl9m8byYE0iXl--K6kowAAA3g"]
[Sun Aug 30 03:12:38.333177 2026] [security2:error] [pid 521505:tid 521719] [client 158.23.184.117:51692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/wsa.php"] [unique_id "apPl9m8byYE0iXl--K6kpAAAA3I"]
[Sun Aug 30 03:12:38.353995 2026] [security2:error] [pid 521505:tid 521713] [client 20.151.200.44:46010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/sxxb.php"] [unique_id "apPl9m8byYE0iXl--K6kpQAAA2w"]
[Sun Aug 30 03:12:38.370521 2026] [security2:error] [pid 521505:tid 521647] [client 20.48.160.90:23744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPl9m8byYE0iXl--K6kpgAAAyo"]
[Sun Aug 30 03:12:38.377837 2026] [security2:error] [pid 524122:tid 524295] [client 20.48.251.3:37132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/routes.php"] [unique_id "apPl9n3lhEjKFiK_nBKEIAAAAbk"]
[Sun Aug 30 03:12:38.398294 2026] [security2:error] [pid 521505:tid 521681] [client 20.151.200.44:26604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/ca.php"] [unique_id "apPl9m8byYE0iXl--K6kqgAAA0w"]
[Sun Aug 30 03:12:38.447873 2026] [security2:error] [pid 521505:tid 521680] [client 20.48.251.3:43008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/pass4.php"] [unique_id "apPl9m8byYE0iXl--K6krQAAA0s"]
[Sun Aug 30 03:12:38.468990 2026] [security2:error] [pid 521505:tid 521738] [client 20.48.160.90:50451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/gtghklk.php"] [unique_id "apPl9m8byYE0iXl--K6krgAAA4U"]
[Sun Aug 30 03:12:38.469147 2026] [security2:error] [pid 521505:tid 521684] [client 20.104.50.220:30929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/css.php"] [unique_id "apPl9m8byYE0iXl--K6krwAAA08"]
[Sun Aug 30 03:12:38.474141 2026] [security2:error] [pid 521505:tid 521685] [client 158.23.184.117:58129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/w.php"] [unique_id "apPl9m8byYE0iXl--K6ksQAAA1A"]
[Sun Aug 30 03:12:38.481108 2026] [authz_core:error] [pid 521505:tid 521707] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory16
[Sun Aug 30 03:12:38.481398 2026] [authz_core:error] [pid 521505:tid 521707] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory16
[Sun Aug 30 03:12:38.501173 2026] [authz_core:error] [pid 524122:tid 524371] [client 66.249.66.192:42077] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:38.501439 2026] [authz_core:error] [pid 524122:tid 524371] [client 66.249.66.192:42077] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:38.527764 2026] [security2:error] [pid 521505:tid 521714] [client 20.48.160.90:50382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPl9m8byYE0iXl--K6kswAAA20"]
[Sun Aug 30 03:12:38.532381 2026] [security2:error] [pid 521505:tid 521705] [client 20.197.61.180:1711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/profile.php"] [unique_id "apPl9m8byYE0iXl--K6ktAAAA2Q"]
[Sun Aug 30 03:12:38.547927 2026] [authz_core:error] [pid 521505:tid 521720] [client 66.249.66.64:44393] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:38.548287 2026] [authz_core:error] [pid 521505:tid 521720] [client 66.249.66.64:44393] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:38.557337 2026] [authz_core:error] [pid 521505:tid 521687] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:38.557584 2026] [authz_core:error] [pid 521505:tid 521687] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:38.567906 2026] [security2:error] [pid 521505:tid 521756] [client 34.141.178.234:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webdisk.maidtoglisten.com"] [uri "/"] [unique_id "apPl9m8byYE0iXl--K6ktwAAA5c"]
[Sun Aug 30 03:12:38.567987 2026] [security2:error] [pid 521505:tid 521756] [client 34.141.178.234:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "webdisk.maidtoglisten.com"] [uri "/"] [unique_id "apPl9m8byYE0iXl--K6ktwAAA5c"]
[Sun Aug 30 03:12:38.588767 2026] [security2:error] [pid 521505:tid 521648] [client 20.104.49.130:48036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/wen.php"] [unique_id "apPl9m8byYE0iXl--K6kuAAAAys"]
[Sun Aug 30 03:12:38.614655 2026] [security2:error] [pid 521505:tid 521653] [client 158.23.184.117:58164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/x.php"] [unique_id "apPl9m8byYE0iXl--K6kuwAAAzA"]
[Sun Aug 30 03:12:38.634144 2026] [security2:error] [pid 521505:tid 521735] [client 20.196.209.81:20977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/upgrade-temp-backup/pk.php"] [unique_id "apPl9m8byYE0iXl--K6kvQAAA4I"]
[Sun Aug 30 03:12:38.641933 2026] [security2:error] [pid 521505:tid 521753] [client 20.48.160.90:50546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/comand.php"] [unique_id "apPl9m8byYE0iXl--K6kvgAAA5Q"]
[Sun Aug 30 03:12:38.664935 2026] [security2:error] [pid 521505:tid 521654] [client 20.48.160.90:28790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/ser.php"] [unique_id "apPl9m8byYE0iXl--K6kvwAAAzE"]
[Sun Aug 30 03:12:38.684924 2026] [security2:error] [pid 521505:tid 521743] [client 20.104.50.220:29183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/1index.php"] [unique_id "apPl9m8byYE0iXl--K6kwAAAA4o"]
[Sun Aug 30 03:12:38.758966 2026] [security2:error] [pid 521505:tid 521662] [client 158.23.184.117:34595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/xx.php"] [unique_id "apPl9m8byYE0iXl--K6kwgAAAzk"]
[Sun Aug 30 03:12:38.774448 2026] [security2:error] [pid 521505:tid 521667] [client 20.48.160.90:50521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp_motu_myk3v.php"] [unique_id "apPl9m8byYE0iXl--K6kwwAAAz4"]
[Sun Aug 30 03:12:38.789248 2026] [security2:error] [pid 521505:tid 521640] [client 4.205.62.107:29129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/ws79.php"] [unique_id "apPl9m8byYE0iXl--K6kxAAAAyM"]
[Sun Aug 30 03:12:38.791314 2026] [security2:error] [pid 521505:tid 521718] [client 20.48.160.90:50383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/431.php"] [unique_id "apPl9m8byYE0iXl--K6kxQAAA3E"]
[Sun Aug 30 03:12:38.850102 2026] [security2:error] [pid 521505:tid 521758] [client 20.104.50.220:5488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/46.php"] [unique_id "apPl9m8byYE0iXl--K6kyQAAA5k"]
[Sun Aug 30 03:12:38.921731 2026] [security2:error] [pid 524122:tid 524359] [client 20.48.160.90:45385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/wp_motu_ypdat.php"] [unique_id "apPl9n3lhEjKFiK_nBKEJgAAAfk"]
[Sun Aug 30 03:12:38.923750 2026] [security2:error] [pid 524122:tid 524376] [client 20.104.50.220:17341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/async-upload.php"] [unique_id "apPl9n3lhEjKFiK_nBKEJwAAAgo"]
[Sun Aug 30 03:12:38.924073 2026] [security2:error] [pid 524122:tid 524372] [client 158.23.184.117:58160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/xmlrpc.php"] [unique_id "apPl9n3lhEjKFiK_nBKEJQAAAgY"]
[Sun Aug 30 03:12:38.926780 2026] [security2:error] [pid 521505:tid 521695] [client 20.48.160.90:23784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/rxr.php"] [unique_id "apPl9m8byYE0iXl--K6kywAAA1o"]
[Sun Aug 30 03:12:38.971571 2026] [security2:error] [pid 524122:tid 524333] [client 20.104.49.130:52443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wdfjba.org"] [uri "/btyuio.php"] [unique_id "apPl9n3lhEjKFiK_nBKEKAAAAd8"]
[Sun Aug 30 03:12:38.980150 2026] [authz_core:error] [pid 524122:tid 524285] [client 216.73.216.128:18347] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:38.980476 2026] [authz_core:error] [pid 524122:tid 524285] [client 216.73.216.128:18347] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:38.983810 2026] [security2:error] [pid 521505:tid 521674] [client 20.151.200.44:45999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/dx.php"] [unique_id "apPl9m8byYE0iXl--K6kzAAAA0U"]
[Sun Aug 30 03:12:38.998787 2026] [security2:error] [pid 521505:tid 521728] [client 20.104.18.15:22488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/btyuio.php"] [unique_id "apPl9m8byYE0iXl--K6kzQAAA3s"]
[Sun Aug 30 03:12:38.999574 2026] [security2:error] [pid 521505:tid 521710] [client 4.205.62.107:17459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/cu.php"] [unique_id "apPl9m8byYE0iXl--K6kzgAAA2k"]
[Sun Aug 30 03:12:39.014270 2026] [authz_core:error] [pid 521505:tid 521682] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory31
[Sun Aug 30 03:12:39.014561 2026] [authz_core:error] [pid 521505:tid 521682] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory31
[Sun Aug 30 03:12:39.028333 2026] [security2:error] [pid 521505:tid 521703] [client 20.104.18.15:2043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/ws55.php"] [unique_id "apPl928byYE0iXl--K6k0AAAA2I"]
[Sun Aug 30 03:12:39.031400 2026] [security2:error] [pid 521505:tid 521643] [client 20.196.209.81:8525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/upgrade-temp-backup/plugins/security.php"] [unique_id "apPl928byYE0iXl--K6k0QAAAyY"]
[Sun Aug 30 03:12:39.055189 2026] [security2:error] [pid 521505:tid 521663] [client 20.48.160.90:23693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/csst.php"] [unique_id "apPl928byYE0iXl--K6k0gAAAzo"]
[Sun Aug 30 03:12:39.057231 2026] [security2:error] [pid 521505:tid 521661] [client 20.48.160.90:50434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/edit.php"] [unique_id "apPl928byYE0iXl--K6k0wAAAzg"]
[Sun Aug 30 03:12:39.064819 2026] [security2:error] [pid 521505:tid 521747] [client 158.23.184.117:34578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orders.lastmaskcenter.org"] [uri "/y.php"] [unique_id "apPl928byYE0iXl--K6k1QAAA44"]
[Sun Aug 30 03:12:39.071060 2026] [security2:error] [pid 524122:tid 524360] [client 20.104.50.220:61990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-admin/js/wp-conflg.php"] [unique_id "apPl933lhEjKFiK_nBKEKgAAAfo"]
[Sun Aug 30 03:12:39.071373 2026] [authz_core:error] [pid 521505:tid 521751] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:39.071664 2026] [authz_core:error] [pid 521505:tid 521751] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:39.096703 2026] [security2:error] [pid 521505:tid 521725] [client 20.104.49.130:60687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/Jcrop.php"] [unique_id "apPl928byYE0iXl--K6k2gAAA3g"]
[Sun Aug 30 03:12:39.096855 2026] [security2:error] [pid 521505:tid 521719] [client 20.104.50.220:25417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/dx.php"] [unique_id "apPl928byYE0iXl--K6k2wAAA3I"]
[Sun Aug 30 03:12:39.108519 2026] [authz_core:error] [pid 521505:tid 521689] [client 66.249.66.36:40765] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:39.108832 2026] [authz_core:error] [pid 521505:tid 521689] [client 66.249.66.36:40765] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:39.154950 2026] [security2:error] [pid 521505:tid 521721] [client 216.73.216.128:14551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/collection.html"] [unique_id "apPl928byYE0iXl--K6k3gAAA3Q"]
[Sun Aug 30 03:12:39.163545 2026] [security2:error] [pid 521505:tid 521688] [client 20.104.50.220:52860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/plugins.php"] [unique_id "apPl928byYE0iXl--K6k3wAAA1M"]
[Sun Aug 30 03:12:39.166876 2026] [security2:error] [pid 521505:tid 521681] [client 20.104.50.220:51632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/alf.php"] [unique_id "apPl928byYE0iXl--K6k4AAAA0w"]
[Sun Aug 30 03:12:39.184908 2026] [security2:error] [pid 524122:tid 524349] [client 20.48.160.90:45387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/tqkdqbbv.php"] [unique_id "apPl933lhEjKFiK_nBKELQAAAe8"]
[Sun Aug 30 03:12:39.217780 2026] [security2:error] [pid 521505:tid 521704] [client 20.48.160.90:23797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp-includes/blocks/query-title/footer.php"] [unique_id "apPl928byYE0iXl--K6k4QAAA2M"]
[Sun Aug 30 03:12:39.262189 2026] [security2:error] [pid 521505:tid 521712] [client 20.104.49.130:57610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alarm-monitoring.net"] [uri "/fling.php"] [unique_id "apPl928byYE0iXl--K6k4wAAA2s"]
[Sun Aug 30 03:12:39.263851 2026] [security2:error] [pid 521505:tid 521738] [client 20.104.18.15:51079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/new.php"] [unique_id "apPl928byYE0iXl--K6k5AAAA4U"]
[Sun Aug 30 03:12:39.296606 2026] [security2:error] [pid 521505:tid 521642] [client 4.205.62.107:15813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/fm.php"] [unique_id "apPl928byYE0iXl--K6k5QAAAyU"]
[Sun Aug 30 03:12:39.300695 2026] [security2:error] [pid 524122:tid 524364] [client 20.104.50.220:33309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/alfatesla.php"] [unique_id "apPl933lhEjKFiK_nBKEMQAAAf4"]
[Sun Aug 30 03:12:39.319130 2026] [security2:error] [pid 521505:tid 521734] [client 20.48.160.90:50445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/kjyehoxl.php"] [unique_id "apPl928byYE0iXl--K6k5gAAA4E"]
[Sun Aug 30 03:12:39.342108 2026] [security2:error] [pid 521505:tid 521657] [client 185.242.177.19:34756] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "cpanel.funnelauthorityexpert.com"] [uri "/"] [unique_id "apPl928byYE0iXl--K6k5wAAAzQ"]
[Sun Aug 30 03:12:39.343538 2026] [authz_core:error] [pid 524122:tid 524268] [client 216.73.216.128:59424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:39.343806 2026] [authz_core:error] [pid 524122:tid 524268] [client 216.73.216.128:59424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:39.349299 2026] [security2:error] [pid 521505:tid 521693] [client 20.197.61.180:8983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/sql.php"] [unique_id "apPl928byYE0iXl--K6k6QAAA1g"]
[Sun Aug 30 03:12:39.359254 2026] [security2:error] [pid 521505:tid 521677] [client 4.205.62.107:15945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/ebahvhhh.php"] [unique_id "apPl928byYE0iXl--K6k6gAAA0g"]
[Sun Aug 30 03:12:39.378490 2026] [security2:error] [pid 521505:tid 521636] [client 4.205.62.107:25515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/dd.php"] [unique_id "apPl928byYE0iXl--K6k6wAAAx8"]
[Sun Aug 30 03:12:39.384380 2026] [security2:error] [pid 521505:tid 521756] [client 20.48.251.3:54776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/update.php"] [unique_id "apPl928byYE0iXl--K6k7AAAA5c"]
[Sun Aug 30 03:12:39.406792 2026] [security2:error] [pid 524122:tid 524352] [client 20.48.160.90:23756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp-content/uploads/indoex.php"] [unique_id "apPl933lhEjKFiK_nBKEMwAAAfI"]
[Sun Aug 30 03:12:39.422300 2026] [security2:error] [pid 524122:tid 524358] [client 20.196.209.81:20936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/upgrade-temp-backup/plugins/users.php"] [unique_id "apPl933lhEjKFiK_nBKENAAAAfg"]
[Sun Aug 30 03:12:39.452154 2026] [security2:error] [pid 524122:tid 524258] [client 20.48.160.90:50517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/llyuxaqd.php"] [unique_id "apPl933lhEjKFiK_nBKENwAAAZQ"]
[Sun Aug 30 03:12:39.497087 2026] [authz_core:error] [pid 521505:tid 521697] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory26
[Sun Aug 30 03:12:39.497351 2026] [authz_core:error] [pid 521505:tid 521697] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory26
[Sun Aug 30 03:12:39.504110 2026] [security2:error] [pid 521505:tid 521755] [client 20.151.200.44:52109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/xwpg.php"] [unique_id "apPl928byYE0iXl--K6k7gAAA5Y"]
[Sun Aug 30 03:12:39.510116 2026] [security2:error] [pid 521505:tid 521745] [client 20.151.200.44:26490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/pb.php"] [unique_id "apPl928byYE0iXl--K6k7wAAA4w"]
[Sun Aug 30 03:12:39.516074 2026] [security2:error] [pid 524122:tid 524344] [client 20.48.251.3:37171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/aww.php"] [unique_id "apPl933lhEjKFiK_nBKEOAAAAeo"]
[Sun Aug 30 03:12:39.537117 2026] [security2:error] [pid 524122:tid 524286] [client 20.48.160.90:29173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPl933lhEjKFiK_nBKEOwAAAbA"]
[Sun Aug 30 03:12:39.549638 2026] [authz_core:error] [pid 521505:tid 521654] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:39.549903 2026] [authz_core:error] [pid 521505:tid 521654] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:39.585676 2026] [security2:error] [pid 521505:tid 521649] [client 20.48.160.90:45403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/nbwxolou.php"] [unique_id "apPl928byYE0iXl--K6k9gAAAyw"]
[Sun Aug 30 03:12:39.617499 2026] [authz_core:error] [pid 524122:tid 524262] [client 216.73.216.128:18347] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:39.617807 2026] [authz_core:error] [pid 524122:tid 524262] [client 216.73.216.128:18347] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:39.622325 2026] [security2:error] [pid 524122:tid 524271] [client 20.104.50.220:30722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/cong.php"] [unique_id "apPl933lhEjKFiK_nBKEPQAAAaE"]
[Sun Aug 30 03:12:39.643076 2026] [authz_core:error] [pid 521505:tid 521762] [client 66.249.66.33:57886] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:39.643365 2026] [authz_core:error] [pid 521505:tid 521762] [client 66.249.66.33:57886] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:39.653612 2026] [security2:error] [pid 521505:tid 521740] [client 20.48.251.3:52194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/cu.php"] [unique_id "apPl928byYE0iXl--K6k-QAAA4c"]
[Sun Aug 30 03:12:39.671989 2026] [security2:error] [pid 521505:tid 521667] [client 20.48.160.90:28756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/haxor.php"] [unique_id "apPl928byYE0iXl--K6k-wAAAz4"]
[Sun Aug 30 03:12:39.707291 2026] [authz_core:error] [pid 524122:tid 524283] [client 216.73.216.128:59424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:39.707547 2026] [authz_core:error] [pid 524122:tid 524283] [client 216.73.216.128:59424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:39.752448 2026] [security2:error] [pid 521505:tid 521660] [client 20.48.160.90:50514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/nsxeubyv.php"] [unique_id "apPl928byYE0iXl--K6k_AAAAzc"]
[Sun Aug 30 03:12:39.767271 2026] [security2:error] [pid 521505:tid 521659] [client 216.244.66.238:34628] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arcaneguardians.com"] [uri "/sblx/oklahoma-state-basketball-2022-23"] [unique_id "apPl928byYE0iXl--K6k_QAAAzY"]
[Sun Aug 30 03:12:39.767399 2026] [security2:error] [pid 521505:tid 521659] [client 216.244.66.238:34628] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "arcaneguardians.com"] [uri "/sblx/oklahoma-state-basketball-2022-23"] [unique_id "apPl928byYE0iXl--K6k_QAAAzY"]
[Sun Aug 30 03:12:39.801938 2026] [security2:error] [pid 524122:tid 524296] [client 20.48.160.90:50372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/google.php"] [unique_id "apPl933lhEjKFiK_nBKEQQAAAbo"]
[Sun Aug 30 03:12:39.819651 2026] [security2:error] [pid 524122:tid 524259] [client 20.196.209.81:8516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/upgrade-temp-backup/plugins/wp-blog-header.php"] [unique_id "apPl933lhEjKFiK_nBKEQgAAAZU"]
[Sun Aug 30 03:12:39.834488 2026] [security2:error] [pid 524122:tid 524265] [client 20.104.49.130:60613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/menu.php"] [unique_id "apPl933lhEjKFiK_nBKEQwAAAZs"]
[Sun Aug 30 03:12:39.892322 2026] [security2:error] [pid 524122:tid 524326] [client 20.48.160.90:45336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/zfqipfss.php"] [unique_id "apPl933lhEjKFiK_nBKERQAAAdg"]
[Sun Aug 30 03:12:39.933676 2026] [security2:error] [pid 524122:tid 524348] [client 20.48.160.90:28795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "apPl933lhEjKFiK_nBKERgAAAe4"]
[Sun Aug 30 03:12:39.940399 2026] [security2:error] [pid 524122:tid 524377] [client 4.205.62.107:29166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/public/wp-blog.php"] [unique_id "apPl933lhEjKFiK_nBKERwAAAgs"]
[Sun Aug 30 03:12:39.942297 2026] [security2:error] [pid 521505:tid 521758] [client 20.104.50.220:29330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/2index.php"] [unique_id "apPl928byYE0iXl--K6k_wAAA5k"]
[Sun Aug 30 03:12:39.979947 2026] [authz_core:error] [pid 524122:tid 524339] [client 66.249.66.77:58951] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:39.980227 2026] [authz_core:error] [pid 524122:tid 524339] [client 66.249.66.77:58951] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:40.004262 2026] [security2:error] [pid 524122:tid 524272] [client 20.104.50.220:5504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/44.php"] [unique_id "apPl-H3lhEjKFiK_nBKESgAAAaI"]
[Sun Aug 30 03:12:40.008214 2026] [authz_core:error] [pid 521505:tid 521757] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory14
[Sun Aug 30 03:12:40.008631 2026] [authz_core:error] [pid 521505:tid 521757] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory14
[Sun Aug 30 03:12:40.020783 2026] [security2:error] [pid 521505:tid 521676] [client 20.48.160.90:50436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buckcreekrhs.com"] [uri "/zrjuyoos.php"] [unique_id "apPl-G8byYE0iXl--K6lAQAAA0c"]
[Sun Aug 30 03:12:40.058678 2026] [security2:error] [pid 524122:tid 524374] [client 20.197.61.180:11377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/index.bak.php"] [unique_id "apPl-H3lhEjKFiK_nBKESwAAAgg"]
[Sun Aug 30 03:12:40.062396 2026] [security2:error] [pid 524122:tid 524311] [client 20.104.50.220:16604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/br5is.php"] [unique_id "apPl-H3lhEjKFiK_nBKETAAAAck"]
[Sun Aug 30 03:12:40.067765 2026] [security2:error] [pid 521505:tid 521695] [client 20.151.200.44:63644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPl-G8byYE0iXl--K6lBAAAA1o"]
[Sun Aug 30 03:12:40.074380 2026] [security2:error] [pid 521505:tid 521733] [client 20.48.160.90:23747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/robots.php"] [unique_id "apPl-G8byYE0iXl--K6lBQAAA4A"]
[Sun Aug 30 03:12:40.126437 2026] [security2:error] [pid 521505:tid 521737] [client 4.205.62.107:17411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/services.php"] [unique_id "apPl-G8byYE0iXl--K6lBgAAA4Q"]
[Sun Aug 30 03:12:40.182996 2026] [security2:error] [pid 524122:tid 524275] [client 20.104.18.15:22520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/dehnl.php"] [unique_id "apPl-H3lhEjKFiK_nBKETgAAAaU"]
[Sun Aug 30 03:12:40.184898 2026] [security2:error] [pid 524122:tid 524266] [client 20.104.18.15:1991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/indo.php"] [unique_id "apPl-H3lhEjKFiK_nBKETwAAAZw"]
[Sun Aug 30 03:12:40.190195 2026] [security2:error] [pid 524122:tid 524274] [client 20.48.250.41:64789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPl-H3lhEjKFiK_nBKEUAAAAaQ"]
[Sun Aug 30 03:12:40.205694 2026] [security2:error] [pid 524122:tid 524379] [client 20.48.160.90:50369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp-content/plugins/ccx/index.php"] [unique_id "apPl-H3lhEjKFiK_nBKEUQAAAg0"]
[Sun Aug 30 03:12:40.215686 2026] [security2:error] [pid 521505:tid 521701] [client 20.196.209.81:8253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/upgrade-temp-backup/plugins/wp-mail.php"] [unique_id "apPl-G8byYE0iXl--K6lCAAAA2A"]
[Sun Aug 30 03:12:40.240870 2026] [security2:error] [pid 521505:tid 521720] [client 20.104.50.220:24952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/puc.php"] [unique_id "apPl-G8byYE0iXl--K6lCgAAA3M"]
[Sun Aug 30 03:12:40.260774 2026] [security2:error] [pid 521505:tid 521703] [client 20.104.50.220:61673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/classwithtostring.php"] [unique_id "apPl-G8byYE0iXl--K6lCwAAA2I"]
[Sun Aug 30 03:12:40.279190 2026] [authz_core:error] [pid 521505:tid 521643] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:40.279471 2026] [authz_core:error] [pid 521505:tid 521643] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:40.307162 2026] [security2:error] [pid 521505:tid 521691] [client 20.104.50.220:51528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/alf4.php"] [unique_id "apPl-G8byYE0iXl--K6lDQAAA1Y"]
[Sun Aug 30 03:12:40.325045 2026] [security2:error] [pid 524122:tid 524351] [client 20.48.250.41:64834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPl-H3lhEjKFiK_nBKEVAAAAfE"]
[Sun Aug 30 03:12:40.357323 2026] [security2:error] [pid 524122:tid 524331] [client 20.104.49.130:60658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPl-H3lhEjKFiK_nBKEVQAAAd0"]
[Sun Aug 30 03:12:40.359098 2026] [security2:error] [pid 521505:tid 521727] [client 20.104.50.220:29631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-content/priv8.php"] [unique_id "apPl-G8byYE0iXl--K6lEAAAA3o"]
[Sun Aug 30 03:12:40.361832 2026] [security2:error] [pid 521505:tid 521717] [client 20.48.160.90:23782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp-admin/css/colors/maro.php"] [unique_id "apPl-G8byYE0iXl--K6lEQAAA3A"]
[Sun Aug 30 03:12:40.371703 2026] [authz_core:error] [pid 521505:tid 521675] [client 66.249.66.38:53706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:40.371952 2026] [authz_core:error] [pid 521505:tid 521675] [client 66.249.66.38:53706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:40.403809 2026] [security2:error] [pid 524122:tid 524301] [client 20.104.18.15:51016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/inx.php"] [unique_id "apPl-H3lhEjKFiK_nBKEVgAAAb8"]
[Sun Aug 30 03:12:40.436443 2026] [security2:error] [pid 521505:tid 521750] [client 4.205.62.107:15936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/tinyfilemanager.php"] [unique_id "apPl-G8byYE0iXl--K6lFAAAA5E"]
[Sun Aug 30 03:12:40.453311 2026] [security2:error] [pid 521505:tid 521668] [client 20.48.250.41:64797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/ff1.php"] [unique_id "apPl-G8byYE0iXl--K6lFQAAAz8"]
[Sun Aug 30 03:12:40.454611 2026] [security2:error] [pid 521505:tid 521652] [client 20.104.50.220:33186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/alfateslav4.php"] [unique_id "apPl-G8byYE0iXl--K6lFgAAAy8"]
[Sun Aug 30 03:12:40.502513 2026] [security2:error] [pid 521505:tid 521724] [client 20.48.160.90:23735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp-admin/css/colors/coffee/marijuana.php"] [unique_id "apPl-G8byYE0iXl--K6lFwAAA3c"]
[Sun Aug 30 03:12:40.509999 2026] [security2:error] [pid 521505:tid 521688] [client 4.205.62.107:15980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/asa.php"] [unique_id "apPl-G8byYE0iXl--K6lGgAAA1M"]
[Sun Aug 30 03:12:40.510064 2026] [authz_core:error] [pid 521505:tid 521694] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory30
[Sun Aug 30 03:12:40.510318 2026] [authz_core:error] [pid 521505:tid 521694] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory30
[Sun Aug 30 03:12:40.510696 2026] [authz_core:error] [pid 521505:tid 521721] [client 66.249.66.199:40413] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:40.510987 2026] [authz_core:error] [pid 521505:tid 521721] [client 66.249.66.199:40413] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:40.523540 2026] [security2:error] [pid 521505:tid 521751] [client 20.48.251.3:65491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/channels.php"] [unique_id "apPl-G8byYE0iXl--K6lHAAAA5I"]
[Sun Aug 30 03:12:40.563987 2026] [authz_core:error] [pid 521505:tid 521752] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:40.564249 2026] [authz_core:error] [pid 521505:tid 521752] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:40.580469 2026] [security2:error] [pid 521505:tid 521650] [client 20.48.250.41:64857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/t.php"] [unique_id "apPl-G8byYE0iXl--K6lHgAAAy0"]
[Sun Aug 30 03:12:40.591463 2026] [security2:error] [pid 521505:tid 521738] [client 4.205.62.107:26963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/wp-tem.php"] [unique_id "apPl-G8byYE0iXl--K6lHwAAA4U"]
[Sun Aug 30 03:12:40.608748 2026] [security2:error] [pid 521505:tid 521670] [client 20.196.209.81:8973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/upgrade-temp-backup/themes/admin.php"] [unique_id "apPl-G8byYE0iXl--K6lIAAAA0E"]
[Sun Aug 30 03:12:40.634289 2026] [security2:error] [pid 521505:tid 521734] [client 20.104.49.130:63540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/kj.php"] [unique_id "apPl-G8byYE0iXl--K6lIwAAA4E"]
[Sun Aug 30 03:12:40.634311 2026] [security2:error] [pid 521505:tid 521729] [client 20.48.160.90:29157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp-admin/css/colors/coffee/mari.php"] [unique_id "apPl-G8byYE0iXl--K6lIgAAA3w"]
[Sun Aug 30 03:12:40.665857 2026] [security2:error] [pid 521505:tid 521699] [client 20.48.251.3:36822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/maxro.php"] [unique_id "apPl-G8byYE0iXl--K6lJAAAA14"]
[Sun Aug 30 03:12:40.680368 2026] [security2:error] [pid 524122:tid 524297] [client 20.151.200.44:26500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/pk.php"] [unique_id "apPl-H3lhEjKFiK_nBKEWQAAAbs"]
[Sun Aug 30 03:12:40.704002 2026] [authz_core:error] [pid 521505:tid 521713] [client 66.249.66.199:45223] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:40.704263 2026] [authz_core:error] [pid 521505:tid 521713] [client 66.249.66.199:45223] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:40.719439 2026] [security2:error] [pid 524122:tid 524290] [client 20.48.250.41:64793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/erty.php"] [unique_id "apPl-H3lhEjKFiK_nBKEXAAAAbQ"]
[Sun Aug 30 03:12:40.762785 2026] [security2:error] [pid 524122:tid 524368] [client 20.48.160.90:29150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp-includes/images/crystal/option.php"] [unique_id "apPl-H3lhEjKFiK_nBKEXQAAAgI"]
[Sun Aug 30 03:12:40.771843 2026] [security2:error] [pid 521505:tid 521689] [client 20.104.50.220:31199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPl-G8byYE0iXl--K6lKAAAA1Q"]
[Sun Aug 30 03:12:40.797451 2026] [security2:error] [pid 521505:tid 521655] [client 20.48.251.3:59882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/services.php"] [unique_id "apPl-G8byYE0iXl--K6lKwAAAzI"]
[Sun Aug 30 03:12:40.832931 2026] [security2:error] [pid 521505:tid 521684] [client 20.197.61.180:1700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/log.php"] [unique_id "apPl-G8byYE0iXl--K6lLAAAA08"]
[Sun Aug 30 03:12:40.849260 2026] [security2:error] [pid 521505:tid 521714] [client 20.48.160.90:28745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPl-G8byYE0iXl--K6lLgAAA20"]
[Sun Aug 30 03:12:40.855053 2026] [security2:error] [pid 521505:tid 521753] [client 20.151.200.44:43904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ermes-it.it"] [uri "/dehnl.php"] [unique_id "apPl-G8byYE0iXl--K6lLwAAA5Q"]
[Sun Aug 30 03:12:40.856961 2026] [security2:error] [pid 521505:tid 521707] [client 20.48.250.41:62403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/0x.php"] [unique_id "apPl-G8byYE0iXl--K6lMAAAA2Y"]
[Sun Aug 30 03:12:40.892921 2026] [security2:error] [pid 524122:tid 524261] [client 20.48.160.90:23739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp-includes/pomo/xxx.php"] [unique_id "apPl-H3lhEjKFiK_nBKEXwAAAZc"]
[Sun Aug 30 03:12:40.965664 2026] [security2:error] [pid 524122:tid 524376] [client 20.151.200.44:23601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/h02ugyh.php"] [unique_id "apPl-H3lhEjKFiK_nBKEYAAAAgo"]
[Sun Aug 30 03:12:40.996766 2026] [security2:error] [pid 524122:tid 524282] [client 20.48.160.90:28760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPl-H3lhEjKFiK_nBKEYgAAAaw"]
[Sun Aug 30 03:12:41.001080 2026] [security2:error] [pid 524122:tid 524343] [client 20.196.209.81:20954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/upgrade-temp-backup/themes/login.php"] [unique_id "apPl-X3lhEjKFiK_nBKEYwAAAek"]
[Sun Aug 30 03:12:41.001632 2026] [security2:error] [pid 524122:tid 524263] [client 20.48.250.41:64856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/66.php"] [unique_id "apPl-X3lhEjKFiK_nBKEZAAAAZk"]
[Sun Aug 30 03:12:41.029615 2026] [security2:error] [pid 521505:tid 521698] [client 20.48.160.90:28751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/650.php"] [unique_id "apPl-W8byYE0iXl--K6lMwAAA10"]
[Sun Aug 30 03:12:41.033893 2026] [authz_core:error] [pid 521505:tid 521667] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory17
[Sun Aug 30 03:12:41.034314 2026] [authz_core:error] [pid 521505:tid 521667] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory17
[Sun Aug 30 03:12:41.037178 2026] [authz_core:error] [pid 521505:tid 521708] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:41.037609 2026] [authz_core:error] [pid 521505:tid 521708] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:41.124423 2026] [security2:error] [pid 521505:tid 521660] [client 4.205.62.107:52884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/php-details.php"] [unique_id "apPl-W8byYE0iXl--K6lNQAAAzc"]
[Sun Aug 30 03:12:41.136154 2026] [security2:error] [pid 524122:tid 524325] [client 20.48.160.90:28755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/ser.php"] [unique_id "apPl-X3lhEjKFiK_nBKEZgAAAdc"]
[Sun Aug 30 03:12:41.138969 2026] [security2:error] [pid 524122:tid 524366] [client 20.104.50.220:5607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/43.php"] [unique_id "apPl-X3lhEjKFiK_nBKEZwAAAgA"]
[Sun Aug 30 03:12:41.144671 2026] [security2:error] [pid 521505:tid 521716] [client 20.48.250.41:64882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/f35.php"] [unique_id "apPl-W8byYE0iXl--K6lNwAAA28"]
[Sun Aug 30 03:12:41.159505 2026] [security2:error] [pid 521505:tid 521641] [client 20.48.160.90:23743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/nakrip.php"] [unique_id "apPl-W8byYE0iXl--K6lOQAAAyQ"]
[Sun Aug 30 03:12:41.199715 2026] [security2:error] [pid 521505:tid 521759] [client 20.104.50.220:17224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/bonita76.php"] [unique_id "apPl-W8byYE0iXl--K6lPAAAA5o"]
[Sun Aug 30 03:12:41.205708 2026] [security2:error] [pid 524122:tid 524354] [client 20.151.200.44:52143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/sxxb.php"] [unique_id "apPl-X3lhEjKFiK_nBKEagAAAfQ"]
[Sun Aug 30 03:12:41.227334 2026] [authz_core:error] [pid 521505:tid 521746] [client 66.249.66.198:42935] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:41.227665 2026] [authz_core:error] [pid 521505:tid 521746] [client 66.249.66.198:42935] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:41.256295 2026] [security2:error] [pid 524122:tid 524318] [client 4.205.62.107:17713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/filesystems.php"] [unique_id "apPl-X3lhEjKFiK_nBKEbAAAAdA"]
[Sun Aug 30 03:12:41.263759 2026] [security2:error] [pid 521505:tid 521762] [client 20.151.200.44:26594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/ft.php"] [unique_id "apPl-W8byYE0iXl--K6lQAAAA50"]
[Sun Aug 30 03:12:41.272388 2026] [security2:error] [pid 524122:tid 524362] [client 20.48.250.41:62404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/wen.php"] [unique_id "apPl-X3lhEjKFiK_nBKEbQAAAfw"]
[Sun Aug 30 03:12:41.288165 2026] [security2:error] [pid 524122:tid 524342] [client 20.48.160.90:29143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/431.php"] [unique_id "apPl-X3lhEjKFiK_nBKEbgAAAeg"]
[Sun Aug 30 03:12:41.300779 2026] [security2:error] [pid 521505:tid 521674] [client 20.48.160.90:23751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp-includes/interactivity-api/flower.php"] [unique_id "apPl-W8byYE0iXl--K6lQgAAA0U"]
[Sun Aug 30 03:12:41.336129 2026] [security2:error] [pid 524122:tid 524276] [client 20.104.18.15:2009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/wnnjpsby.php"] [unique_id "apPl-X3lhEjKFiK_nBKEcAAAAaY"]
[Sun Aug 30 03:12:41.337684 2026] [security2:error] [pid 521505:tid 521701] [client 20.104.18.15:22523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/zoo1.php"] [unique_id "apPl-W8byYE0iXl--K6lQwAAA2A"]
[Sun Aug 30 03:12:41.352661 2026] [security2:error] [pid 521505:tid 521703] [client 20.151.200.44:23560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/sf.php"] [unique_id "apPl-W8byYE0iXl--K6lRQAAA2I"]
[Sun Aug 30 03:12:41.388549 2026] [security2:error] [pid 521505:tid 521663] [client 20.151.200.44:46029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPl-W8byYE0iXl--K6lRwAAAzo"]
[Sun Aug 30 03:12:41.393371 2026] [security2:error] [pid 521505:tid 521695] [client 20.196.209.81:9012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/upgrade-temp-backup/themes/test.php"] [unique_id "apPl-W8byYE0iXl--K6lSAAAA1o"]
[Sun Aug 30 03:12:41.421987 2026] [security2:error] [pid 521505:tid 521666] [client 20.104.50.220:24940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/themes.php"] [unique_id "apPl-W8byYE0iXl--K6lSQAAAz0"]
[Sun Aug 30 03:12:41.424457 2026] [security2:error] [pid 521505:tid 521639] [client 20.48.250.41:62412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/inc.php"] [unique_id "apPl-W8byYE0iXl--K6lSgAAAyI"]
[Sun Aug 30 03:12:41.430937 2026] [security2:error] [pid 521505:tid 521672] [client 20.48.160.90:29168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/rxr.php"] [unique_id "apPl-W8byYE0iXl--K6lSwAAA0M"]
[Sun Aug 30 03:12:41.445861 2026] [security2:error] [pid 521505:tid 521727] [client 20.48.160.90:23742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/xcc.php"] [unique_id "apPl-W8byYE0iXl--K6lTAAAA3o"]
[Sun Aug 30 03:12:41.449095 2026] [security2:error] [pid 524122:tid 524338] [client 20.104.50.220:41992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/alfa-shell-v4.php"] [unique_id "apPl-X3lhEjKFiK_nBKEcgAAAeQ"]
[Sun Aug 30 03:12:41.473009 2026] [security2:error] [pid 521505:tid 521643] [client 20.104.50.220:61376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/image.php"] [unique_id "apPl-W8byYE0iXl--K6lTQAAAyY"]
[Sun Aug 30 03:12:41.481822 2026] [security2:error] [pid 521505:tid 521750] [client 20.104.50.220:64455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/3index.php"] [unique_id "apPl-W8byYE0iXl--K6lUQAAA5E"]
[Sun Aug 30 03:12:41.485080 2026] [authz_core:error] [pid 521505:tid 521719] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory13
[Sun Aug 30 03:12:41.485504 2026] [authz_core:error] [pid 521505:tid 521719] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory13
[Sun Aug 30 03:12:41.494016 2026] [security2:error] [pid 521505:tid 521652] [client 20.104.49.130:54204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/new.php"] [unique_id "apPl-W8byYE0iXl--K6lUwAAAy8"]
[Sun Aug 30 03:12:41.530908 2026] [authz_core:error] [pid 521505:tid 521688] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:41.531342 2026] [authz_core:error] [pid 521505:tid 521688] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:41.554190 2026] [security2:error] [pid 521505:tid 521690] [client 20.197.61.180:8987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/bak.php"] [unique_id "apPl-W8byYE0iXl--K6lVgAAA1U"]
[Sun Aug 30 03:12:41.561466 2026] [security2:error] [pid 521505:tid 521739] [client 20.104.18.15:51063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/vpn.php"] [unique_id "apPl-W8byYE0iXl--K6lVwAAA4Y"]
[Sun Aug 30 03:12:41.569961 2026] [security2:error] [pid 521505:tid 521732] [client 20.48.160.90:29156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/csst.php"] [unique_id "apPl-W8byYE0iXl--K6lWAAAA38"]
[Sun Aug 30 03:12:41.571717 2026] [security2:error] [pid 521505:tid 521712] [client 4.205.62.107:15973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/05.php"] [unique_id "apPl-W8byYE0iXl--K6lWQAAA2s"]
[Sun Aug 30 03:12:41.576517 2026] [security2:error] [pid 521505:tid 521738] [client 20.48.250.41:64792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/6bcwiqwj.php"] [unique_id "apPl-W8byYE0iXl--K6lWgAAA4U"]
[Sun Aug 30 03:12:41.585995 2026] [security2:error] [pid 521505:tid 521685] [client 20.48.160.90:23805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp-includes/Text/Diff/Engine/aaa.php"] [unique_id "apPl-W8byYE0iXl--K6lWwAAA1A"]
[Sun Aug 30 03:12:41.592666 2026] [security2:error] [pid 521505:tid 521729] [client 20.104.50.220:32890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/alwso.php"] [unique_id "apPl-W8byYE0iXl--K6lXQAAA3w"]
[Sun Aug 30 03:12:41.596740 2026] [authz_core:error] [pid 521505:tid 521670] [client 66.249.66.202:55947] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:41.596997 2026] [authz_core:error] [pid 521505:tid 521670] [client 66.249.66.202:55947] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:41.648567 2026] [security2:error] [pid 521505:tid 521678] [client 4.205.62.107:15857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/radio.php"] [unique_id "apPl-W8byYE0iXl--K6lXwAAA0k"]
[Sun Aug 30 03:12:41.650572 2026] [security2:error] [pid 521505:tid 521658] [client 20.104.50.220:29592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-admin/priv8.php"] [unique_id "apPl-W8byYE0iXl--K6lYQAAAzU"]
[Sun Aug 30 03:12:41.650607 2026] [security2:error] [pid 521505:tid 521677] [client 20.104.49.130:52431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/memberfuns.php"] [unique_id "apPl-W8byYE0iXl--K6lYAAAA0g"]
[Sun Aug 30 03:12:41.660716 2026] [security2:error] [pid 521505:tid 521647] [client 20.48.251.3:54733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/zz.php"] [unique_id "apPl-W8byYE0iXl--K6lYgAAAyo"]
[Sun Aug 30 03:12:41.693045 2026] [security2:error] [pid 521505:tid 521756] [client 20.104.49.130:63554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wdfjba.org"] [uri "/xa.php"] [unique_id "apPl-W8byYE0iXl--K6lZAAAA5c"]
[Sun Aug 30 03:12:41.704712 2026] [security2:error] [pid 521505:tid 521761] [client 20.48.250.41:64877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/easy.php"] [unique_id "apPl-W8byYE0iXl--K6lZgAAA5w"]
[Sun Aug 30 03:12:41.713112 2026] [security2:error] [pid 521505:tid 521642] [client 20.48.160.90:50373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp-includes/blocks/query-title/footer.php"] [unique_id "apPl-W8byYE0iXl--K6lZwAAAyU"]
[Sun Aug 30 03:12:41.727232 2026] [security2:error] [pid 521505:tid 521742] [client 20.48.160.90:23726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp-includes/style-engine/gecko-new.php"] [unique_id "apPl-W8byYE0iXl--K6laAAAA4k"]
[Sun Aug 30 03:12:41.787477 2026] [security2:error] [pid 521505:tid 521748] [client 20.196.209.81:8231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/upgrade-temp-backup/themes/wp-links-opml.php"] [unique_id "apPl-W8byYE0iXl--K6laQAAA48"]
[Sun Aug 30 03:12:41.808602 2026] [security2:error] [pid 521505:tid 521735] [client 20.48.251.3:37148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/brc.php"] [unique_id "apPl-W8byYE0iXl--K6lagAAA4I"]
[Sun Aug 30 03:12:41.855319 2026] [security2:error] [pid 521505:tid 521654] [client 20.48.160.90:29176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp-content/uploads/indoex.php"] [unique_id "apPl-W8byYE0iXl--K6lbwAAAzE"]
[Sun Aug 30 03:12:41.855829 2026] [security2:error] [pid 524122:tid 524253] [client 20.48.250.41:64849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/fresh3.php"] [unique_id "apPl-X3lhEjKFiK_nBKEdQAAAY8"]
[Sun Aug 30 03:12:41.858101 2026] [security2:error] [pid 524122:tid 524334] [client 20.48.160.90:29177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp-settings.php"] [unique_id "apPl-X3lhEjKFiK_nBKEdgAAAeA"]
[Sun Aug 30 03:12:41.859280 2026] [security2:error] [pid 524122:tid 524258] [client 4.205.62.107:25730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/txets.php"] [unique_id "apPl-X3lhEjKFiK_nBKEdwAAAZQ"]
[Sun Aug 30 03:12:41.914865 2026] [security2:error] [pid 521505:tid 521698] [client 20.104.49.130:36758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/memberfuns.php"] [unique_id "apPl-W8byYE0iXl--K6lcQAAA10"]
[Sun Aug 30 03:12:41.916985 2026] [security2:error] [pid 524122:tid 524268] [client 20.104.50.220:31221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/cong.php"] [unique_id "apPl-X3lhEjKFiK_nBKEeQAAAZ4"]
[Sun Aug 30 03:12:41.953596 2026] [security2:error] [pid 521505:tid 521638] [client 20.48.251.3:52247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/filesystems.php"] [unique_id "apPl-W8byYE0iXl--K6lcgAAAyE"]
[Sun Aug 30 03:12:41.984586 2026] [authz_core:error] [pid 524122:tid 524277] [client 216.73.216.128:18347] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:41.985034 2026] [authz_core:error] [pid 524122:tid 524277] [client 216.73.216.128:18347] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:41.992837 2026] [security2:error] [pid 524122:tid 524294] [client 20.48.160.90:23680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp-signup.php"] [unique_id "apPl-X3lhEjKFiK_nBKEfAAAAbg"]
[Sun Aug 30 03:12:41.993304 2026] [security2:error] [pid 524122:tid 524369] [client 20.48.160.90:28750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPl-X3lhEjKFiK_nBKEfQAAAgM"]
[Sun Aug 30 03:12:41.996287 2026] [authz_core:error] [pid 521505:tid 521716] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory10
[Sun Aug 30 03:12:41.996741 2026] [authz_core:error] [pid 521505:tid 521716] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory10
[Sun Aug 30 03:12:42.000520 2026] [security2:error] [pid 524122:tid 524355] [client 20.48.250.41:64819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/bgymj.php"] [unique_id "apPl-X3lhEjKFiK_nBKEfgAAAfU"]
[Sun Aug 30 03:12:42.002458 2026] [security2:error] [pid 521505:tid 521641] [client 20.151.200.44:62937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/4e.php"] [unique_id "apPl-m8byYE0iXl--K6ldQAAAyQ"]
[Sun Aug 30 03:12:42.069116 2026] [authz_core:error] [pid 521505:tid 521667] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:42.069386 2026] [authz_core:error] [pid 521505:tid 521667] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:42.124609 2026] [security2:error] [pid 524122:tid 524265] [client 20.48.160.90:28775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/haxor.php"] [unique_id "apPl-n3lhEjKFiK_nBKEggAAAZs"]
[Sun Aug 30 03:12:42.141443 2026] [security2:error] [pid 521505:tid 521645] [client 20.48.160.90:28791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp-conffg.php"] [unique_id "apPl-m8byYE0iXl--K6lewAAAyg"]
[Sun Aug 30 03:12:42.147243 2026] [security2:error] [pid 524122:tid 524270] [client 20.48.250.41:64874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/ws69.php"] [unique_id "apPl-n3lhEjKFiK_nBKEgwAAAaA"]
[Sun Aug 30 03:12:42.186235 2026] [security2:error] [pid 524122:tid 524284] [client 20.196.209.81:8982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/upgrade-temp-backup/themes/wp-settings.php"] [unique_id "apPl-n3lhEjKFiK_nBKEhgAAAa4"]
[Sun Aug 30 03:12:42.254236 2026] [security2:error] [pid 524122:tid 524337] [client 20.48.160.90:23800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/google.php"] [unique_id "apPl-n3lhEjKFiK_nBKEiAAAAeM"]
[Sun Aug 30 03:12:42.262481 2026] [security2:error] [pid 521505:tid 521701] [client 4.205.62.107:29121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/routes.php"] [unique_id "apPl-m8byYE0iXl--K6lfwAAA2A"]
[Sun Aug 30 03:12:42.277064 2026] [security2:error] [pid 521505:tid 521665] [client 20.48.250.41:64780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/ccs.php"] [unique_id "apPl-m8byYE0iXl--K6lgAAAAzw"]
[Sun Aug 30 03:12:42.284736 2026] [security2:error] [pid 521505:tid 521651] [client 20.48.160.90:23740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp-validate.php"] [unique_id "apPl-m8byYE0iXl--K6lgQAAAy4"]
[Sun Aug 30 03:12:42.291873 2026] [security2:error] [pid 521505:tid 521703] [client 20.104.50.220:5451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/42.php"] [unique_id "apPl-m8byYE0iXl--K6lggAAA2I"]
[Sun Aug 30 03:12:42.342810 2026] [security2:error] [pid 521505:tid 521686] [client 20.104.50.220:16634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/angie712.php"] [unique_id "apPl-m8byYE0iXl--K6liAAAA1E"]
[Sun Aug 30 03:12:42.384758 2026] [security2:error] [pid 521505:tid 521750] [client 20.48.160.90:50349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "apPl-m8byYE0iXl--K6liQAAA5E"]
[Sun Aug 30 03:12:42.424032 2026] [security2:error] [pid 521505:tid 521682] [client 20.48.250.41:64812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/mar.php"] [unique_id "apPl-m8byYE0iXl--K6ljwAAA00"]
[Sun Aug 30 03:12:42.424706 2026] [security2:error] [pid 524122:tid 524341] [client 20.48.160.90:29166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/700.php"] [unique_id "apPl-n3lhEjKFiK_nBKEjQAAAec"]
[Sun Aug 30 03:12:42.476303 2026] [authz_core:error] [pid 521505:tid 521680] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory18
[Sun Aug 30 03:12:42.476659 2026] [authz_core:error] [pid 521505:tid 521680] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory18
[Sun Aug 30 03:12:42.477775 2026] [security2:error] [pid 521505:tid 521732] [client 4.205.62.107:17682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/tax.php"] [unique_id "apPl-m8byYE0iXl--K6lkgAAA38"]
[Sun Aug 30 03:12:42.479564 2026] [security2:error] [pid 521505:tid 521712] [client 20.104.18.15:22504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/radio.php"] [unique_id "apPl-m8byYE0iXl--K6lkwAAA2s"]
[Sun Aug 30 03:12:42.489037 2026] [security2:error] [pid 521505:tid 521738] [client 20.104.18.15:2024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/info.php/new.php"] [unique_id "apPl-m8byYE0iXl--K6llAAAA4U"]
[Sun Aug 30 03:12:42.499764 2026] [authz_core:error] [pid 524122:tid 524274] [client 66.249.66.68:36754] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:42.500029 2026] [authz_core:error] [pid 524122:tid 524274] [client 66.249.66.68:36754] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:42.514848 2026] [security2:error] [pid 521505:tid 521757] [client 20.197.61.180:8968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/pages.php"] [unique_id "apPl-m8byYE0iXl--K6llgAAA5g"]
[Sun Aug 30 03:12:42.518818 2026] [security2:error] [pid 521505:tid 521729] [client 20.48.160.90:50400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/robots.php"] [unique_id "apPl-m8byYE0iXl--K6llwAAA3w"]
[Sun Aug 30 03:12:42.529886 2026] [authz_core:error] [pid 521505:tid 521720] [client 216.73.216.128:35963] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:42.530166 2026] [authz_core:error] [pid 521505:tid 521720] [client 216.73.216.128:35963] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:42.538304 2026] [authz_core:error] [pid 521505:tid 521699] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:42.538571 2026] [authz_core:error] [pid 521505:tid 521699] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:42.567856 2026] [security2:error] [pid 521505:tid 521688] [client 20.48.160.90:29180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/c4.php"] [unique_id "apPl-m8byYE0iXl--K6lmgAAA1M"]
[Sun Aug 30 03:12:42.576514 2026] [security2:error] [pid 524122:tid 524299] [client 20.104.50.220:24905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/dx.php"] [unique_id "apPl-n3lhEjKFiK_nBKEkgAAAb0"]
[Sun Aug 30 03:12:42.579555 2026] [security2:error] [pid 521505:tid 521678] [client 20.48.250.41:64781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/ccu.php"] [unique_id "apPl-m8byYE0iXl--K6lmwAAA0k"]
[Sun Aug 30 03:12:42.589631 2026] [security2:error] [pid 524122:tid 524314] [client 20.151.200.44:26521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/wp-ver.php"] [unique_id "apPl-n3lhEjKFiK_nBKEkwAAAcw"]
[Sun Aug 30 03:12:42.595060 2026] [autoindex:error] [pid 521505:tid 521690] [client 20.196.209.81:8997] AH01276: Cannot serve directory /home1/lehugh/public_html/etax4u.com/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:12:42.596690 2026] [security2:error] [pid 521505:tid 521677] [client 20.104.50.220:51575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/alfakun.php"] [unique_id "apPl-m8byYE0iXl--K6lngAAA0g"]
[Sun Aug 30 03:12:42.659100 2026] [security2:error] [pid 521505:tid 521647] [client 20.48.160.90:23686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp-content/plugins/ccx/index.php"] [unique_id "apPl-m8byYE0iXl--K6loAAAAyo"]
[Sun Aug 30 03:12:42.714026 2026] [security2:error] [pid 521505:tid 521661] [client 20.48.160.90:23692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp-tymanage.php"] [unique_id "apPl-m8byYE0iXl--K6loQAAAzg"]
[Sun Aug 30 03:12:42.715917 2026] [security2:error] [pid 524122:tid 524330] [client 20.104.18.15:51122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/shiny.php"] [unique_id "apPl-n3lhEjKFiK_nBKElQAAAdw"]
[Sun Aug 30 03:12:42.723472 2026] [security2:error] [pid 521505:tid 521653] [client 4.205.62.107:16368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/wp-blog.php"] [unique_id "apPl-m8byYE0iXl--K6logAAAzA"]
[Sun Aug 30 03:12:42.725492 2026] [security2:error] [pid 521505:tid 521742] [client 20.196.209.81:8997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/upgrade/about.php"] [unique_id "apPl-m8byYE0iXl--K6lowAAA4k"]
[Sun Aug 30 03:12:42.730827 2026] [security2:error] [pid 524122:tid 524301] [client 20.104.50.220:33329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/anjay.php"] [unique_id "apPl-n3lhEjKFiK_nBKElwAAAb8"]
[Sun Aug 30 03:12:42.732576 2026] [authz_core:error] [pid 524122:tid 524331] [client 216.73.216.128:34238] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:42.732857 2026] [authz_core:error] [pid 524122:tid 524331] [client 216.73.216.128:34238] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:42.737399 2026] [security2:error] [pid 521505:tid 521668] [client 20.104.50.220:61395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-admin/wp-conflg.php"] [unique_id "apPl-m8byYE0iXl--K6lpAAAAz8"]
[Sun Aug 30 03:12:42.760794 2026] [security2:error] [pid 521505:tid 521669] [client 20.48.250.41:64835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/ak.php"] [unique_id "apPl-m8byYE0iXl--K6lpQAAA0A"]
[Sun Aug 30 03:12:42.788034 2026] [security2:error] [pid 524122:tid 524339] [client 20.48.160.90:50376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp-admin/css/colors/maro.php"] [unique_id "apPl-n3lhEjKFiK_nBKEmAAAAeU"]
[Sun Aug 30 03:12:42.791872 2026] [security2:error] [pid 521505:tid 521748] [client 4.205.62.107:15993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/xa.php"] [unique_id "apPl-m8byYE0iXl--K6lqQAAA48"]
[Sun Aug 30 03:12:42.799910 2026] [security2:error] [pid 521505:tid 521721] [client 20.48.251.3:65510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/test.php"] [unique_id "apPl-m8byYE0iXl--K6lqwAAA3Q"]
[Sun Aug 30 03:12:42.801035 2026] [authz_core:error] [pid 521505:tid 521664] [client 66.249.66.32:57382] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:42.801477 2026] [authz_core:error] [pid 521505:tid 521664] [client 66.249.66.32:57382] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:42.846877 2026] [security2:error] [pid 521505:tid 521657] [client 20.48.160.90:23686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/ajfto.php"] [unique_id "apPl-m8byYE0iXl--K6lrAAAAzQ"]
[Sun Aug 30 03:12:42.917935 2026] [security2:error] [pid 521505:tid 521648] [client 20.104.49.130:53510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/tiny2.php"] [unique_id "apPl-m8byYE0iXl--K6lrwAAAys"]
[Sun Aug 30 03:12:42.923130 2026] [security2:error] [pid 524122:tid 524290] [client 20.48.160.90:23682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp-admin/css/colors/coffee/marijuana.php"] [unique_id "apPl-n3lhEjKFiK_nBKEmgAAAbQ"]
[Sun Aug 30 03:12:42.927309 2026] [security2:error] [pid 521505:tid 521698] [client 20.48.250.41:64843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/lib.php"] [unique_id "apPl-m8byYE0iXl--K6lsAAAA10"]
[Sun Aug 30 03:12:42.961151 2026] [security2:error] [pid 524122:tid 524307] [client 20.48.251.3:36895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/vx.php"] [unique_id "apPl-n3lhEjKFiK_nBKEmwAAAcU"]
[Sun Aug 30 03:12:42.982947 2026] [security2:error] [pid 521505:tid 521662] [client 20.48.160.90:29133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp_KwIW0U5F.php"] [unique_id "apPl-m8byYE0iXl--K6lswAAAzk"]
[Sun Aug 30 03:12:43.006230 2026] [authz_core:error] [pid 521505:tid 521713] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory19
[Sun Aug 30 03:12:43.006485 2026] [authz_core:error] [pid 521505:tid 521713] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory19
[Sun Aug 30 03:12:43.024883 2026] [security2:error] [pid 521505:tid 521716] [client 4.205.62.107:25691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/time.php"] [unique_id "apPl-28byYE0iXl--K6ltgAAA28"]
[Sun Aug 30 03:12:43.051420 2026] [security2:error] [pid 521505:tid 521659] [client 20.48.160.90:28763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp-admin/css/colors/coffee/mari.php"] [unique_id "apPl-28byYE0iXl--K6ltwAAAzY"]
[Sun Aug 30 03:12:43.069957 2026] [security2:error] [pid 524122:tid 524365] [client 216.73.216.128:59424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPl-33lhEjKFiK_nBKEnQAAAf8"]
[Sun Aug 30 03:12:43.073019 2026] [security2:error] [pid 524122:tid 524261] [client 20.48.250.41:64851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/wp-style.php"] [unique_id "apPl-33lhEjKFiK_nBKEngAAAZc"]
[Sun Aug 30 03:12:43.090159 2026] [authz_core:error] [pid 521505:tid 521687] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:43.090578 2026] [authz_core:error] [pid 521505:tid 521687] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:43.100181 2026] [security2:error] [pid 521505:tid 521676] [client 20.104.49.130:57696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alarm-monitoring.net"] [uri "/samll.php"] [unique_id "apPl-28byYE0iXl--K6lugAAA0c"]
[Sun Aug 30 03:12:43.117218 2026] [security2:error] [pid 524122:tid 524295] [client 20.196.209.81:8996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.209.196.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "etax4u.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "apPl-33lhEjKFiK_nBKEnwAAAbk"]
[Sun Aug 30 03:12:43.117684 2026] [security2:error] [pid 521505:tid 521726] [client 20.48.160.90:50386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp_xiPu52Ut.php"] [unique_id "apPl-28byYE0iXl--K6lvQAAA3k"]
[Sun Aug 30 03:12:43.147768 2026] [security2:error] [pid 524122:tid 524343] [client 20.104.50.220:31542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/w.php"] [unique_id "apPl-33lhEjKFiK_nBKEoAAAAek"]
[Sun Aug 30 03:12:43.167308 2026] [authz_core:error] [pid 524122:tid 524260] [client 216.73.216.128:34238] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:43.167572 2026] [authz_core:error] [pid 524122:tid 524260] [client 216.73.216.128:34238] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:43.175951 2026] [security2:error] [pid 521505:tid 521741] [client 20.48.251.3:59499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/tax.php"] [unique_id "apPl-28byYE0iXl--K6lvgAAA4g"]
[Sun Aug 30 03:12:43.193755 2026] [security2:error] [pid 521505:tid 521672] [client 20.48.160.90:50378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp-includes/images/crystal/option.php"] [unique_id "apPl-28byYE0iXl--K6lvwAAA0M"]
[Sun Aug 30 03:12:43.235182 2026] [security2:error] [pid 524122:tid 524333] [client 20.48.250.41:64858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/browse.php"] [unique_id "apPl-33lhEjKFiK_nBKEowAAAd8"]
[Sun Aug 30 03:12:43.236358 2026] [security2:error] [pid 521505:tid 521708] [client 20.197.61.180:1727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/albin.php"] [unique_id "apPl-28byYE0iXl--K6lwAAAA2c"]
[Sun Aug 30 03:12:43.250438 2026] [security2:error] [pid 521505:tid 521727] [client 20.48.160.90:50321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp_n5VD7XDh.php"] [unique_id "apPl-28byYE0iXl--K6lwQAAA3o"]
[Sun Aug 30 03:12:43.315569 2026] [security2:error] [pid 521505:tid 521643] [client 20.104.50.220:62820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/403.php"] [unique_id "apPl-28byYE0iXl--K6lxgAAAyY"]
[Sun Aug 30 03:12:43.315587 2026] [security2:error] [pid 521505:tid 521686] [client 158.23.147.79:59061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPl-28byYE0iXl--K6lxQAAA1E"]
[Sun Aug 30 03:12:43.339244 2026] [security2:error] [pid 521505:tid 521759] [client 20.48.160.90:28786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp-includes/pomo/xxx.php"] [unique_id "apPl-28byYE0iXl--K6lxwAAA5o"]
[Sun Aug 30 03:12:43.342349 2026] [security2:error] [pid 524122:tid 524366] [client 216.73.216.128:18347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mysqlupgrade"] [unique_id "apPl-33lhEjKFiK_nBKEpQAAAgA"]
[Sun Aug 30 03:12:43.374610 2026] [security2:error] [pid 524122:tid 524285] [client 20.48.250.41:64791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/zoo.php"] [unique_id "apPl-33lhEjKFiK_nBKEpwAAAa8"]
[Sun Aug 30 03:12:43.375047 2026] [security2:error] [pid 521505:tid 521652] [client 20.151.200.44:63670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/ssss.php"] [unique_id "apPl-28byYE0iXl--K6lyQAAAy8"]
[Sun Aug 30 03:12:43.385997 2026] [security2:error] [pid 524122:tid 524349] [client 20.48.160.90:23712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp-mini.php"] [unique_id "apPl-33lhEjKFiK_nBKEqAAAAe8"]
[Sun Aug 30 03:12:43.416058 2026] [security2:error] [pid 524122:tid 524318] [client 4.205.62.107:52828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/aww.php"] [unique_id "apPl-33lhEjKFiK_nBKEqQAAAdA"]
[Sun Aug 30 03:12:43.429023 2026] [security2:error] [pid 521505:tid 521732] [client 20.104.50.220:6120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/41.php"] [unique_id "apPl-28byYE0iXl--K6lywAAA38"]
[Sun Aug 30 03:12:43.429928 2026] [security2:error] [pid 521505:tid 521712] [client 20.151.200.44:26563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/ah24.php"] [unique_id "apPl-28byYE0iXl--K6lzAAAA2s"]
[Sun Aug 30 03:12:43.482113 2026] [security2:error] [pid 524122:tid 524329] [client 20.104.50.220:16709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/gecko.php"] [unique_id "apPl-33lhEjKFiK_nBKEqgAAAds"]
[Sun Aug 30 03:12:43.493143 2026] [security2:error] [pid 521505:tid 521637] [client 20.104.49.130:54202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/az.php"] [unique_id "apPl-28byYE0iXl--K6lzgAAAyA"]
[Sun Aug 30 03:12:43.503927 2026] [authz_core:error] [pid 521505:tid 521739] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory33
[Sun Aug 30 03:12:43.504202 2026] [authz_core:error] [pid 521505:tid 521739] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory33
[Sun Aug 30 03:12:43.507233 2026] [security2:error] [pid 521505:tid 521757] [client 20.48.160.90:23801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/650.php"] [unique_id "apPl-28byYE0iXl--K6l0AAAA5g"]
[Sun Aug 30 03:12:43.533127 2026] [security2:error] [pid 521505:tid 521694] [client 20.48.160.90:28768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/xmini4.php"] [unique_id "apPl-28byYE0iXl--K6l0gAAA1k"]
[Sun Aug 30 03:12:43.535845 2026] [authz_core:error] [pid 521505:tid 521729] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:43.536169 2026] [authz_core:error] [pid 521505:tid 521729] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:43.537855 2026] [security2:error] [pid 524122:tid 524276] [client 20.48.250.41:64774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/elp.php"] [unique_id "apPl-33lhEjKFiK_nBKErAAAAaY"]
[Sun Aug 30 03:12:43.610463 2026] [security2:error] [pid 521505:tid 521690] [client 4.205.62.107:16815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPl-28byYE0iXl--K6l1AAAA1U"]
[Sun Aug 30 03:12:43.631655 2026] [security2:error] [pid 521505:tid 521756] [client 20.104.18.15:22469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/one.php"] [unique_id "apPl-28byYE0iXl--K6l1wAAA5c"]
[Sun Aug 30 03:12:43.647887 2026] [security2:error] [pid 521505:tid 521706] [client 20.48.160.90:28793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/nakrip.php"] [unique_id "apPl-28byYE0iXl--K6l2AAAA2U"]
[Sun Aug 30 03:12:43.665533 2026] [security2:error] [pid 521505:tid 521647] [client 20.48.250.41:64778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/666.php"] [unique_id "apPl-28byYE0iXl--K6l2QAAAyo"]
[Sun Aug 30 03:12:43.668545 2026] [security2:error] [pid 521505:tid 521761] [client 20.48.160.90:28782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/reop3.php"] [unique_id "apPl-28byYE0iXl--K6l2gAAA5w"]
[Sun Aug 30 03:12:43.693179 2026] [security2:error] [pid 521505:tid 521661] [client 20.104.18.15:1950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/w.php"] [unique_id "apPl-28byYE0iXl--K6l2wAAAzg"]
[Sun Aug 30 03:12:43.710013 2026] [security2:error] [pid 521505:tid 521653] [client 20.104.50.220:24922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/11.php"] [unique_id "apPl-28byYE0iXl--K6l3gAAAzA"]
[Sun Aug 30 03:12:43.766415 2026] [security2:error] [pid 521505:tid 521658] [client 20.104.50.220:63511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/alfatesla.php"] [unique_id "apPl-28byYE0iXl--K6l3wAAAzU"]
[Sun Aug 30 03:12:43.794402 2026] [security2:error] [pid 521505:tid 521735] [client 20.48.250.41:64848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/knmt.php"] [unique_id "apPl-28byYE0iXl--K6l5QAAA4I"]
[Sun Aug 30 03:12:43.794515 2026] [security2:error] [pid 521505:tid 521709] [client 20.48.160.90:50387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp-includes/interactivity-api/flower.php"] [unique_id "apPl-28byYE0iXl--K6l5gAAA2g"]
[Sun Aug 30 03:12:43.800474 2026] [security2:error] [pid 524122:tid 524287] [client 20.48.160.90:29152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp-mail.php"] [unique_id "apPl-33lhEjKFiK_nBKErwAAAbE"]
[Sun Aug 30 03:12:43.873160 2026] [security2:error] [pid 521505:tid 521673] [client 20.104.50.220:33159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/anons79.php"] [unique_id "apPl-28byYE0iXl--K6l6QAAA0Q"]
[Sun Aug 30 03:12:43.877096 2026] [security2:error] [pid 521505:tid 521635] [client 4.205.62.107:15971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/erty.php"] [unique_id "apPl-28byYE0iXl--K6l6gAAAx4"]
[Sun Aug 30 03:12:43.880780 2026] [security2:error] [pid 521505:tid 521641] [client 20.104.18.15:51129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/goods.php"] [unique_id "apPl-28byYE0iXl--K6l6wAAAyQ"]
[Sun Aug 30 03:12:43.924431 2026] [security2:error] [pid 521505:tid 521696] [client 20.48.250.41:64784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/sbhu.php"] [unique_id "apPl-28byYE0iXl--K6l7QAAA1s"]
[Sun Aug 30 03:12:43.925383 2026] [security2:error] [pid 521505:tid 521730] [client 4.205.62.107:15974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/ws61.php"] [unique_id "apPl-28byYE0iXl--K6l7gAAA30"]
[Sun Aug 30 03:12:43.932213 2026] [security2:error] [pid 521505:tid 521715] [client 20.48.160.90:29137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/xcc.php"] [unique_id "apPl-28byYE0iXl--K6l8QAAA24"]
[Sun Aug 30 03:12:43.934349 2026] [security2:error] [pid 521505:tid 521667] [client 20.48.160.90:23720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp-conffg.php"] [unique_id "apPl-28byYE0iXl--K6l8gAAAz4"]
[Sun Aug 30 03:12:43.952114 2026] [security2:error] [pid 521505:tid 521701] [client 20.104.50.220:61664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-freya.php"] [unique_id "apPl-28byYE0iXl--K6l9QAAA2A"]
[Sun Aug 30 03:12:43.953148 2026] [security2:error] [pid 521505:tid 521676] [client 20.48.251.3:64303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/cloud.php"] [unique_id "apPl-28byYE0iXl--K6l9gAAA0c"]
[Sun Aug 30 03:12:43.984125 2026] [authz_core:error] [pid 521505:tid 521660] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory10
[Sun Aug 30 03:12:43.984580 2026] [authz_core:error] [pid 521505:tid 521660] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory10
[Sun Aug 30 03:12:43.986134 2026] [security2:error] [pid 521505:tid 521724] [client 20.197.61.180:11352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/an.php"] [unique_id "apPl-28byYE0iXl--K6l-QAAA3c"]
[Sun Aug 30 03:12:43.987818 2026] [authz_core:error] [pid 524122:tid 524253] [client 216.73.216.128:54296] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:43.988089 2026] [authz_core:error] [pid 524122:tid 524253] [client 216.73.216.128:54296] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:44.029469 2026] [authz_core:error] [pid 521505:tid 521741] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:44.029769 2026] [authz_core:error] [pid 521505:tid 521741] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:44.070438 2026] [security2:error] [pid 521505:tid 521687] [client 20.48.160.90:23702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp-includes/Text/Diff/Engine/aaa.php"] [unique_id "apPl_G8byYE0iXl--K6l_gAAA1I"]
[Sun Aug 30 03:12:44.071195 2026] [security2:error] [pid 524122:tid 524334] [client 20.48.250.41:64873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/a332.php"] [unique_id "apPl_H3lhEjKFiK_nBKEsgAAAeA"]
[Sun Aug 30 03:12:44.082056 2026] [security2:error] [pid 524122:tid 524258] [client 20.48.160.90:29153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/filefuns.php"] [unique_id "apPl_H3lhEjKFiK_nBKEswAAAZQ"]
[Sun Aug 30 03:12:44.115554 2026] [security2:error] [pid 521505:tid 521702] [client 20.104.49.130:54179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/v2.php"] [unique_id "apPl_G8byYE0iXl--K6mAQAAA2E"]
[Sun Aug 30 03:12:44.121000 2026] [authz_core:error] [pid 521505:tid 521727] [client 66.249.66.38:53706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:44.121293 2026] [authz_core:error] [pid 521505:tid 521727] [client 66.249.66.38:53706] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:44.144515 2026] [security2:error] [pid 524122:tid 524321] [client 20.151.200.44:26448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPl_H3lhEjKFiK_nBKEtgAAAdM"]
[Sun Aug 30 03:12:44.150174 2026] [security2:error] [pid 524122:tid 524294] [client 20.104.50.220:62841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/4index.php"] [unique_id "apPl_H3lhEjKFiK_nBKEtwAAAbg"]
[Sun Aug 30 03:12:44.159904 2026] [security2:error] [pid 521505:tid 521692] [client 20.48.251.3:36835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/ty.php"] [unique_id "apPl_G8byYE0iXl--K6mBwAAA1c"]
[Sun Aug 30 03:12:44.209549 2026] [security2:error] [pid 521505:tid 521732] [client 20.48.160.90:50374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp-includes/style-engine/gecko-new.php"] [unique_id "apPl_G8byYE0iXl--K6mCgAAA38"]
[Sun Aug 30 03:12:44.218355 2026] [security2:error] [pid 521505:tid 521712] [client 20.48.250.41:64821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/ws66.php"] [unique_id "apPl_G8byYE0iXl--K6mCwAAA2s"]
[Sun Aug 30 03:12:44.220370 2026] [security2:error] [pid 521505:tid 521738] [client 20.48.160.90:50353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp-cron.php"] [unique_id "apPl_G8byYE0iXl--K6mDAAAA4U"]
[Sun Aug 30 03:12:44.225032 2026] [security2:error] [pid 521505:tid 521637] [client 4.205.62.107:25734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/doc.php"] [unique_id "apPl_G8byYE0iXl--K6mDQAAAyA"]
[Sun Aug 30 03:12:44.259419 2026] [security2:error] [pid 521505:tid 521717] [client 20.104.49.130:60988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wdfjba.org"] [uri "/m.php"] [unique_id "apPl_G8byYE0iXl--K6mEAAAA3A"]
[Sun Aug 30 03:12:44.322984 2026] [security2:error] [pid 521505:tid 521729] [client 20.48.251.3:43073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPl_G8byYE0iXl--K6mEwAAA3w"]
[Sun Aug 30 03:12:44.328881 2026] [authz_core:error] [pid 524122:tid 524277] [client 66.249.66.39:41155] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:44.329150 2026] [authz_core:error] [pid 524122:tid 524277] [client 66.249.66.39:41155] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:44.348753 2026] [security2:error] [pid 524122:tid 524265] [client 20.48.160.90:29123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp-settings.php"] [unique_id "apPl_H3lhEjKFiK_nBKEvgAAAZs"]
[Sun Aug 30 03:12:44.359475 2026] [security2:error] [pid 521505:tid 521655] [client 20.48.250.41:64841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/ws68.php"] [unique_id "apPl_G8byYE0iXl--K6mFAAAAzI"]
[Sun Aug 30 03:12:44.374398 2026] [security2:error] [pid 521505:tid 521653] [client 20.48.160.90:23746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/lock360.php"] [unique_id "apPl_G8byYE0iXl--K6mFQAAAzA"]
[Sun Aug 30 03:12:44.411124 2026] [security2:error] [pid 521505:tid 521753] [client 20.151.200.44:52149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/dx.php"] [unique_id "apPl_G8byYE0iXl--K6mFwAAA5Q"]
[Sun Aug 30 03:12:44.452129 2026] [security2:error] [pid 524122:tid 524284] [client 20.104.50.220:50375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/404.php"] [unique_id "apPl_H3lhEjKFiK_nBKEvwAAAa4"]
[Sun Aug 30 03:12:44.488924 2026] [security2:error] [pid 521505:tid 521699] [client 20.151.200.44:63018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/zoz.php"] [unique_id "apPl_G8byYE0iXl--K6mHAAAA14"]
[Sun Aug 30 03:12:44.489860 2026] [authz_core:error] [pid 521505:tid 521709] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory17
[Sun Aug 30 03:12:44.490136 2026] [authz_core:error] [pid 521505:tid 521709] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory17
[Sun Aug 30 03:12:44.494833 2026] [security2:error] [pid 524122:tid 524377] [client 20.48.250.41:64889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/users.php"] [unique_id "apPl_H3lhEjKFiK_nBKEwAAAAgs"]
[Sun Aug 30 03:12:44.508821 2026] [security2:error] [pid 524122:tid 524256] [client 20.48.160.90:50402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp-signup.php"] [unique_id "apPl_H3lhEjKFiK_nBKEwQAAAZI"]
[Sun Aug 30 03:12:44.524919 2026] [authz_core:error] [pid 521505:tid 521731] [client 66.249.66.74:48711] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:44.525172 2026] [authz_core:error] [pid 521505:tid 521731] [client 66.249.66.74:48711] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:44.526669 2026] [security2:error] [pid 521505:tid 521648] [client 20.48.160.90:50381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp-theme.php"] [unique_id "apPl_G8byYE0iXl--K6mIAAAAys"]
[Sun Aug 30 03:12:44.528077 2026] [authz_core:error] [pid 521505:tid 521670] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:12:44.528353 2026] [authz_core:error] [pid 521505:tid 521670] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:12:44.528615 2026] [security2:error] [pid 524122:tid 524337] [client 216.73.216.128:54296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/nameserverconfig"] [unique_id "apPl_H3lhEjKFiK_nBKEwgAAAeM"]
[Sun Aug 30 03:12:44.560266 2026] [security2:error] [pid 521505:tid 521698] [client 68.155.159.216:60935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPl_G8byYE0iXl--K6mIQAAA10"]
[Sun Aug 30 03:12:44.567551 2026] [security2:error] [pid 521505:tid 521689] [client 20.104.50.220:6101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/40.php"] [unique_id "apPl_G8byYE0iXl--K6mIgAAA1Q"]
[Sun Aug 30 03:12:44.574635 2026] [security2:error] [pid 524122:tid 524350] [client 4.205.62.107:52854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/maxro.php"] [unique_id "apPl_H3lhEjKFiK_nBKEwwAAAfA"]
[Sun Aug 30 03:12:44.615696 2026] [security2:error] [pid 521505:tid 521716] [client 20.104.50.220:17238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/andria828.php"] [unique_id "apPl_G8byYE0iXl--K6mJQAAA28"]
[Sun Aug 30 03:12:44.628457 2026] [security2:error] [pid 521505:tid 521715] [client 20.48.250.41:62415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/bzjdlofz.php"] [unique_id "apPl_G8byYE0iXl--K6mJgAAA24"]
[Sun Aug 30 03:12:44.642165 2026] [security2:error] [pid 524122:tid 524347] [client 20.151.200.44:45960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/xda.php"] [unique_id "apPl_H3lhEjKFiK_nBKEyAAAAe0"]
[Sun Aug 30 03:12:44.661601 2026] [security2:error] [pid 521505:tid 521654] [client 20.48.160.90:28766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp-conffg.php"] [unique_id "apPl_G8byYE0iXl--K6mJwAAAzE"]
[Sun Aug 30 03:12:44.664144 2026] [security2:error] [pid 521505:tid 521674] [client 20.48.160.90:28743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/2d7433/index.php"] [unique_id "apPl_G8byYE0iXl--K6mKAAAA0U"]
[Sun Aug 30 03:12:44.709279 2026] [security2:error] [pid 524122:tid 524345] [client 20.151.200.44:26592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.1899project.com"] [uri "/waf.php"] [unique_id "apPl_H3lhEjKFiK_nBKEyQAAAes"]
[Sun Aug 30 03:12:44.717310 2026] [security2:error] [pid 521505:tid 521642] [client 20.197.61.180:1342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/mini.php"] [unique_id "apPl_G8byYE0iXl--K6mKgAAAyU"]
[Sun Aug 30 03:12:44.748740 2026] [security2:error] [pid 524122:tid 524379] [client 4.205.62.107:17316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPl_H3lhEjKFiK_nBKEzAAAAg0"]
[Sun Aug 30 03:12:44.756575 2026] [security2:error] [pid 521505:tid 521703] [client 20.48.250.41:64795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/selesai.php"] [unique_id "apPl_G8byYE0iXl--K6mLQAAA2I"]
[Sun Aug 30 03:12:44.770208 2026] [security2:error] [pid 521505:tid 521714] [client 20.104.18.15:22409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/504.php"] [unique_id "apPl_G8byYE0iXl--K6mLgAAA20"]
[Sun Aug 30 03:12:44.800245 2026] [security2:error] [pid 524122:tid 524257] [client 216.73.216.128:42307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_config_quote_replace_string"] [unique_id "apPl_H3lhEjKFiK_nBKEzQAAAZM"]
[Sun Aug 30 03:12:44.810854 2026] [security2:error] [pid 521505:tid 521687] [client 20.151.200.44:23562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/kcs.php"] [unique_id "apPl_G8byYE0iXl--K6mMgAAA1I"]
[Sun Aug 30 03:12:44.820350 2026] [security2:error] [pid 521505:tid 521702] [client 158.23.147.79:59070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPl_G8byYE0iXl--K6mMwAAA2E"]
[Sun Aug 30 03:12:44.828292 2026] [security2:error] [pid 521505:tid 521671] [client 20.104.18.15:1955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/x.php"] [unique_id "apPl_G8byYE0iXl--K6mNQAAA0I"]
[Sun Aug 30 03:12:44.828368 2026] [security2:error] [pid 521505:tid 521734] [client 20.104.49.130:63562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/tiny2.php"] [unique_id "apPl_G8byYE0iXl--K6mNAAAA4E"]
[Sun Aug 30 03:12:44.867258 2026] [security2:error] [pid 521505:tid 521686] [client 20.104.50.220:24936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/p.php"] [unique_id "apPl_G8byYE0iXl--K6mNgAAA1E"]
[Sun Aug 30 03:12:44.875318 2026] [security2:error] [pid 521505:tid 521741] [client 20.104.49.130:54182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/js.php"] [unique_id "apPl_G8byYE0iXl--K6mNwAAA4g"]
[Sun Aug 30 03:12:44.889393 2026] [security2:error] [pid 521505:tid 521748] [client 20.48.250.41:64862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/shlo.php"] [unique_id "apPl_G8byYE0iXl--K6mOAAAA48"]
[Sun Aug 30 03:12:44.890102 2026] [security2:error] [pid 524122:tid 524378] [client 20.104.50.220:52818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/wp-includes/priv8.php"] [unique_id "apPl_H3lhEjKFiK_nBKEzgAAAgw"]
[Sun Aug 30 03:12:44.906071 2026] [security2:error] [pid 521505:tid 521692] [client 20.104.50.220:51529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/alfateslav4.php"] [unique_id "apPl_G8byYE0iXl--K6mOgAAA1c"]
[Sun Aug 30 03:12:44.948045 2026] [authz_core:error] [pid 521505:tid 521707] [client 66.249.66.196:48600] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:44.948328 2026] [authz_core:error] [pid 521505:tid 521707] [client 66.249.66.196:48600] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:44.993997 2026] [authz_core:error] [pid 521505:tid 521694] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory16
[Sun Aug 30 03:12:44.994317 2026] [authz_core:error] [pid 521505:tid 521694] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory16
[Sun Aug 30 03:12:45.001795 2026] [security2:error] [pid 521505:tid 521681] [client 20.151.200.44:63663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/tajj.php"] [unique_id "apPl_W8byYE0iXl--K6mPwAAA0w"]
[Sun Aug 30 03:12:45.016519 2026] [authz_core:error] [pid 521505:tid 521665] [client 66.249.66.64:36004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:45.016823 2026] [authz_core:error] [pid 521505:tid 521665] [client 66.249.66.64:36004] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:45.018605 2026] [security2:error] [pid 521505:tid 521717] [client 4.205.62.107:15818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/wp-config.backup.php"] [unique_id "apPl_W8byYE0iXl--K6mQQAAA3A"]
[Sun Aug 30 03:12:45.022665 2026] [security2:error] [pid 521505:tid 521688] [client 20.104.50.220:33584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/base.php"] [unique_id "apPl_W8byYE0iXl--K6mQgAAA1M"]
[Sun Aug 30 03:12:45.033429 2026] [security2:error] [pid 521505:tid 521737] [client 20.48.250.41:62372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/asax.php"] [unique_id "apPl_W8byYE0iXl--K6mRAAAA4Q"]
[Sun Aug 30 03:12:45.033501 2026] [security2:error] [pid 521505:tid 521760] [client 20.104.18.15:51128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/alfa.php"] [unique_id "apPl_W8byYE0iXl--K6mQwAAA5s"]
[Sun Aug 30 03:12:45.065212 2026] [authz_core:error] [pid 521505:tid 521678] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:12:45.065493 2026] [authz_core:error] [pid 521505:tid 521678] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:12:45.066572 2026] [security2:error] [pid 521505:tid 521636] [client 4.205.62.107:16347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/xza.php"] [unique_id "apPl_W8byYE0iXl--K6mRgAAAx8"]
[Sun Aug 30 03:12:45.131824 2026] [security2:error] [pid 524122:tid 524300] [client 20.104.50.220:61632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/X7x.php"] [unique_id "apPl_X3lhEjKFiK_nBKE0AAAAb4"]
[Sun Aug 30 03:12:45.143098 2026] [security2:error] [pid 521505:tid 521739] [client 20.48.251.3:46219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/asdf.php"] [unique_id "apPl_W8byYE0iXl--K6mTgAAA4Y"]
[Sun Aug 30 03:12:45.164725 2026] [security2:error] [pid 524122:tid 524312] [client 20.48.250.41:64830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/fetch.php"] [unique_id "apPl_X3lhEjKFiK_nBKE0QAAAco"]
[Sun Aug 30 03:12:45.267346 2026] [authz_core:error] [pid 521505:tid 521753] [client 216.73.216.128:35963] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:45.267612 2026] [authz_core:error] [pid 521505:tid 521753] [client 216.73.216.128:35963] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:45.313654 2026] [security2:error] [pid 521505:tid 521668] [client 20.48.251.3:36826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/adminer-4.7.6-en.php"] [unique_id "apPl_W8byYE0iXl--K6mUwAAAz8"]
[Sun Aug 30 03:12:45.315490 2026] [security2:error] [pid 521505:tid 521669] [client 20.48.250.41:64798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/vx.php"] [unique_id "apPl_W8byYE0iXl--K6mVAAAA0A"]
[Sun Aug 30 03:12:45.382069 2026] [security2:error] [pid 521505:tid 521740] [client 20.151.200.44:23565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/bge.php"] [unique_id "apPl_W8byYE0iXl--K6mVQAAA4c"]
[Sun Aug 30 03:12:45.420322 2026] [security2:error] [pid 521505:tid 521735] [client 4.205.62.107:26964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/classsmtps.php"] [unique_id "apPl_W8byYE0iXl--K6mVgAAA4I"]
[Sun Aug 30 03:12:45.451410 2026] [security2:error] [pid 521505:tid 521700] [client 20.48.250.41:62415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/global.php"] [unique_id "apPl_W8byYE0iXl--K6mWQAAA18"]
[Sun Aug 30 03:12:45.456057 2026] [security2:error] [pid 521505:tid 521713] [client 20.197.61.180:11376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/robots.php"] [unique_id "apPl_W8byYE0iXl--K6mWgAAA2w"]
[Sun Aug 30 03:12:45.488489 2026] [security2:error] [pid 521505:tid 521705] [client 20.48.251.3:52266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPl_W8byYE0iXl--K6mWwAAA2Q"]
[Sun Aug 30 03:12:45.503576 2026] [authz_core:error] [pid 521505:tid 521751] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory19
[Sun Aug 30 03:12:45.503849 2026] [authz_core:error] [pid 521505:tid 521751] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory19
[Sun Aug 30 03:12:45.556105 2026] [authz_core:error] [pid 521505:tid 521689] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:12:45.556376 2026] [authz_core:error] [pid 521505:tid 521689] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:12:45.590432 2026] [security2:error] [pid 521505:tid 521635] [client 20.48.250.41:64876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/fs.php"] [unique_id "apPl_W8byYE0iXl--K6mXwAAAx4"]
[Sun Aug 30 03:12:45.705577 2026] [authz_core:error] [pid 521505:tid 521730] [client 66.249.66.194:63992] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:45.705942 2026] [authz_core:error] [pid 521505:tid 521730] [client 66.249.66.194:63992] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:45.710717 2026] [security2:error] [pid 521505:tid 521709] [client 4.205.62.107:52813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/brc.php"] [unique_id "apPl_W8byYE0iXl--K6mZAAAA2g"]
[Sun Aug 30 03:12:45.711541 2026] [security2:error] [pid 521505:tid 521654] [client 20.104.49.130:53760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/xmini4.php"] [unique_id "apPl_W8byYE0iXl--K6mZgAAAzE"]
[Sun Aug 30 03:12:45.720517 2026] [security2:error] [pid 521505:tid 521674] [client 20.104.50.220:5625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/39.php"] [unique_id "apPl_W8byYE0iXl--K6mZwAAA0U"]
[Sun Aug 30 03:12:45.727595 2026] [security2:error] [pid 524122:tid 524274] [client 68.155.159.216:60965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPl_X3lhEjKFiK_nBKE1QAAAaQ"]
[Sun Aug 30 03:12:45.729826 2026] [security2:error] [pid 521505:tid 521718] [client 20.48.250.41:64859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/ioxi.php"] [unique_id "apPl_W8byYE0iXl--K6maAAAA3E"]
[Sun Aug 30 03:12:45.753238 2026] [security2:error] [pid 521505:tid 521733] [client 20.104.50.220:17009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/botol.php"] [unique_id "apPl_W8byYE0iXl--K6maQAAA4A"]
[Sun Aug 30 03:12:45.763984 2026] [security2:error] [pid 524122:tid 524339] [client 20.151.200.44:23574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/ssh3ll.php"] [unique_id "apPl_X3lhEjKFiK_nBKE1gAAAeU"]
[Sun Aug 30 03:12:45.764720 2026] [security2:error] [pid 524122:tid 524375] [client 20.104.49.130:36789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/red.php"] [unique_id "apPl_X3lhEjKFiK_nBKE2AAAAgk"]
[Sun Aug 30 03:12:45.773000 2026] [authz_core:error] [pid 524122:tid 524324] [client 66.249.66.197:59253] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:45.773412 2026] [authz_core:error] [pid 524122:tid 524324] [client 66.249.66.197:59253] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:45.809545 2026] [security2:error] [pid 521505:tid 521673] [client 20.48.160.90:28778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp-validate.php"] [unique_id "apPl_W8byYE0iXl--K6mbAAAA0Q"]
[Sun Aug 30 03:12:45.810561 2026] [security2:error] [pid 521505:tid 521731] [client 20.48.160.90:29161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp-login.php"] [unique_id "apPl_W8byYE0iXl--K6mbQAAA34"]
[Sun Aug 30 03:12:45.884866 2026] [security2:error] [pid 521505:tid 521671] [client 20.48.250.41:62401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/bootstrap.php"] [unique_id "apPl_W8byYE0iXl--K6mbgAAA0I"]
[Sun Aug 30 03:12:45.887384 2026] [security2:error] [pid 521505:tid 521734] [client 4.205.62.107:17123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/agg.php"] [unique_id "apPl_W8byYE0iXl--K6mbwAAA4E"]
[Sun Aug 30 03:12:45.903557 2026] [security2:error] [pid 521505:tid 521686] [client 20.104.18.15:22411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/ano.php"] [unique_id "apPl_W8byYE0iXl--K6mcQAAA1E"]
[Sun Aug 30 03:12:45.922358 2026] [authz_core:error] [pid 521505:tid 521744] [client 66.249.66.77:52822] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:45.922634 2026] [authz_core:error] [pid 521505:tid 521744] [client 66.249.66.77:52822] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:45.944922 2026] [security2:error] [pid 521505:tid 521748] [client 20.48.160.90:28740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/images.php"] [unique_id "apPl_W8byYE0iXl--K6mdAAAA48"]
[Sun Aug 30 03:12:45.949714 2026] [security2:error] [pid 521505:tid 521759] [client 20.48.160.90:23734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/700.php"] [unique_id "apPl_W8byYE0iXl--K6mdQAAA5o"]
[Sun Aug 30 03:12:45.966157 2026] [security2:error] [pid 521505:tid 521682] [client 20.104.18.15:1998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apPl_W8byYE0iXl--K6mdgAAA00"]
[Sun Aug 30 03:12:46.014592 2026] [security2:error] [pid 521505:tid 521752] [client 20.104.50.220:62830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/5index.php"] [unique_id "apPl_m8byYE0iXl--K6mewAAA5M"]
[Sun Aug 30 03:12:46.015915 2026] [authz_core:error] [pid 521505:tid 521685] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory14
[Sun Aug 30 03:12:46.016186 2026] [authz_core:error] [pid 521505:tid 521685] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory14
[Sun Aug 30 03:12:46.032176 2026] [security2:error] [pid 521505:tid 521717] [client 20.48.250.41:64782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/export.php"] [unique_id "apPl_m8byYE0iXl--K6mfgAAA3A"]
[Sun Aug 30 03:12:46.057214 2026] [authz_core:error] [pid 521505:tid 521760] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fman-db
[Sun Aug 30 03:12:46.057487 2026] [authz_core:error] [pid 521505:tid 521760] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fusr%2Fshare%2Fdoc%2Fman-db
[Sun Aug 30 03:12:46.064046 2026] [security2:error] [pid 524122:tid 524261] [client 20.104.50.220:63541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/alwso.php"] [unique_id "apPl_n3lhEjKFiK_nBKE3wAAAZc"]
[Sun Aug 30 03:12:46.075939 2026] [security2:error] [pid 524122:tid 524359] [client 20.48.160.90:23766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/ops.php"] [unique_id "apPl_n3lhEjKFiK_nBKE4AAAAfk"]
[Sun Aug 30 03:12:46.122115 2026] [security2:error] [pid 521505:tid 521719] [client 20.104.50.220:25446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/bthil.php"] [unique_id "apPl_m8byYE0iXl--K6mggAAA3I"]
[Sun Aug 30 03:12:46.144159 2026] [security2:error] [pid 521505:tid 521749] [client 20.104.50.220:29134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/00.php"] [unique_id "apPl_m8byYE0iXl--K6mhAAAA5A"]
[Sun Aug 30 03:12:46.152468 2026] [security2:error] [pid 521505:tid 521652] [client 4.205.62.107:16378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/edit.php"] [unique_id "apPl_m8byYE0iXl--K6mhQAAAy8"]
[Sun Aug 30 03:12:46.160317 2026] [security2:error] [pid 521505:tid 521647] [client 20.104.50.220:33039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/batm.php"] [unique_id "apPl_m8byYE0iXl--K6mhgAAAyo"]
[Sun Aug 30 03:12:46.163696 2026] [security2:error] [pid 521505:tid 521761] [client 20.48.250.41:64892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/gk.php"] [unique_id "apPl_m8byYE0iXl--K6mhwAAA5w"]
[Sun Aug 30 03:12:46.166628 2026] [security2:error] [pid 521505:tid 521683] [client 216.73.216.128:19569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPl_m8byYE0iXl--K6miAAAA04"]
[Sun Aug 30 03:12:46.170809 2026] [security2:error] [pid 521505:tid 521739] [client 20.104.18.15:51141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/33.php"] [unique_id "apPl_m8byYE0iXl--K6miQAAA4Y"]
[Sun Aug 30 03:12:46.196491 2026] [security2:error] [pid 521505:tid 521725] [client 20.197.61.180:1318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/cron.php"] [unique_id "apPl_m8byYE0iXl--K6migAAA3g"]
[Sun Aug 30 03:12:46.198990 2026] [security2:error] [pid 521505:tid 521694] [client 4.205.62.107:15968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/ms-edit.php"] [unique_id "apPl_m8byYE0iXl--K6miwAAA1k"]
[Sun Aug 30 03:12:46.269319 2026] [authz_core:error] [pid 521505:tid 521746] [client 216.73.216.128:35963] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:46.269775 2026] [authz_core:error] [pid 521505:tid 521746] [client 216.73.216.128:35963] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:46.287971 2026] [security2:error] [pid 521505:tid 521677] [client 20.104.50.220:59725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/ioxi-o.php"] [unique_id "apPl_m8byYE0iXl--K6mjgAAA0g"]
[Sun Aug 30 03:12:46.292811 2026] [security2:error] [pid 524122:tid 524263] [client 20.48.250.41:62419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/logs1.php"] [unique_id "apPl_n3lhEjKFiK_nBKE4QAAAZk"]
[Sun Aug 30 03:12:46.304188 2026] [security2:error] [pid 521505:tid 521710] [client 20.48.251.3:65473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/app/Helpers/bladeHelpers.php"] [unique_id "apPl_m8byYE0iXl--K6mkAAAA2k"]
[Sun Aug 30 03:12:46.307833 2026] [security2:error] [pid 524122:tid 524305] [client 20.104.50.220:59577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/admir.php"] [unique_id "apPl_n3lhEjKFiK_nBKE4wAAAcM"]
[Sun Aug 30 03:12:46.327780 2026] [security2:error] [pid 521505:tid 521669] [client 20.151.200.44:23579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/motu.php"] [unique_id "apPl_m8byYE0iXl--K6mkgAAA0A"]
[Sun Aug 30 03:12:46.333787 2026] [authz_core:error] [pid 521505:tid 521668] [client 66.249.66.42:54297] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:46.334049 2026] [authz_core:error] [pid 521505:tid 521668] [client 66.249.66.42:54297] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:46.354058 2026] [authz_core:error] [pid 524122:tid 524333] [client 216.73.216.128:34238] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:46.354333 2026] [authz_core:error] [pid 524122:tid 524333] [client 216.73.216.128:34238] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:46.373013 2026] [security2:error] [pid 521505:tid 521755] [client 20.104.49.130:36778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/x1da.php"] [unique_id "apPl_m8byYE0iXl--K6mkwAAA5Y"]
[Sun Aug 30 03:12:46.417595 2026] [security2:error] [pid 521505:tid 521740] [client 20.151.200.44:44000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ermes-it.it"] [uri "/png.php"] [unique_id "apPl_m8byYE0iXl--K6mlAAAA4c"]
[Sun Aug 30 03:12:46.436915 2026] [security2:error] [pid 521505:tid 521665] [client 20.48.250.41:64825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/inege.php"] [unique_id "apPl_m8byYE0iXl--K6mlQAAAzw"]
[Sun Aug 30 03:12:46.456337 2026] [security2:error] [pid 524122:tid 524371] [client 20.48.251.3:36834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/phpi.php"] [unique_id "apPl_n3lhEjKFiK_nBKE5QAAAgU"]
[Sun Aug 30 03:12:46.476878 2026] [authz_core:error] [pid 521505:tid 521723] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory26
[Sun Aug 30 03:12:46.477156 2026] [authz_core:error] [pid 521505:tid 521723] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory26
[Sun Aug 30 03:12:46.500062 2026] [authz_core:error] [pid 521505:tid 521713] [client 66.249.66.39:48740] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:46.500375 2026] [authz_core:error] [pid 521505:tid 521713] [client 66.249.66.39:48740] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:46.528032 2026] [authz_core:error] [pid 521505:tid 521699] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:12:46.528311 2026] [authz_core:error] [pid 521505:tid 521699] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130
[Sun Aug 30 03:12:46.546081 2026] [security2:error] [pid 521505:tid 521607] [remote 210.5.50.134:53474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.50.5.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "forewestmortgage.com"] [uri "/wp-login.php"] [unique_id "apPl_m8byYE0iXl--K6mnAADjmU"]
[Sun Aug 30 03:12:46.578857 2026] [security2:error] [pid 524122:tid 524362] [client 20.48.250.41:64891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/wp-link10.php"] [unique_id "apPl_n3lhEjKFiK_nBKE6QAAAfw"]
[Sun Aug 30 03:12:46.591354 2026] [security2:error] [pid 524122:tid 524342] [client 4.205.62.107:25883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/cache-compat.php"] [unique_id "apPl_n3lhEjKFiK_nBKE6gAAAeg"]
[Sun Aug 30 03:12:46.606427 2026] [security2:error] [pid 521505:tid 521716] [client 20.151.200.44:55681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.americanqualityhomeinspections.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPl_m8byYE0iXl--K6mogAAA28"]
[Sun Aug 30 03:12:46.621496 2026] [security2:error] [pid 521505:tid 521754] [client 20.151.200.44:52035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPl_m8byYE0iXl--K6mpwAAA5U"]
[Sun Aug 30 03:12:46.631246 2026] [security2:error] [pid 524122:tid 524280] [client 20.48.251.3:43011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/agg.php"] [unique_id "apPl_n3lhEjKFiK_nBKE7QAAAao"]
[Sun Aug 30 03:12:46.686741 2026] [security2:error] [pid 521505:tid 521674] [client 20.151.200.44:46016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPl_m8byYE0iXl--K6mqQAAA0U"]
[Sun Aug 30 03:12:46.713875 2026] [security2:error] [pid 521505:tid 521758] [client 20.48.250.41:62426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/ww.php"] [unique_id "apPl_m8byYE0iXl--K6mqwAAA5k"]
[Sun Aug 30 03:12:46.750753 2026] [autoindex:error] [pid 521505:tid 521641] [client 43.135.140.225:59104] AH01276: Cannot serve directory /home1/petrajor/planbjo.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:12:46.853055 2026] [security2:error] [pid 521505:tid 521682] [client 216.73.216.128:17515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/classes.html"] [unique_id "apPl_m8byYE0iXl--K6msgAAA00"]
[Sun Aug 30 03:12:46.859797 2026] [security2:error] [pid 521505:tid 521752] [client 20.48.250.41:64827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/w1px.php"] [unique_id "apPl_m8byYE0iXl--K6mswAAA5M"]
[Sun Aug 30 03:12:46.863451 2026] [security2:error] [pid 524122:tid 524358] [client 20.104.50.220:5913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/38.php"] [unique_id "apPl_n3lhEjKFiK_nBKE8QAAAfg"]
[Sun Aug 30 03:12:46.893414 2026] [security2:error] [pid 521505:tid 521681] [client 20.104.50.220:16733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/amya985.php"] [unique_id "apPl_m8byYE0iXl--K6mtAAAA0w"]
[Sun Aug 30 03:12:46.909288 2026] [security2:error] [pid 521505:tid 521717] [client 158.23.147.79:59008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apPl_m8byYE0iXl--K6mtwAAA3A"]
[Sun Aug 30 03:12:46.928989 2026] [security2:error] [pid 524122:tid 524325] [client 20.197.61.180:1666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/goat.php"] [unique_id "apPl_n3lhEjKFiK_nBKE8gAAAdc"]
[Sun Aug 30 03:12:46.934961 2026] [security2:error] [pid 521505:tid 521636] [client 4.205.62.107:52921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/vx.php"] [unique_id "apPl_m8byYE0iXl--K6muAAAAx8"]
[Sun Aug 30 03:12:46.995238 2026] [authz_core:error] [pid 521505:tid 521756] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory31
[Sun Aug 30 03:12:46.995689 2026] [authz_core:error] [pid 521505:tid 521756] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory31
[Sun Aug 30 03:12:47.001592 2026] [security2:error] [pid 521505:tid 521683] [client 20.48.250.41:64825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/to.php"] [unique_id "apPl_28byYE0iXl--K6mvwAAA04"]
[Sun Aug 30 03:12:47.005667 2026] [security2:error] [pid 521505:tid 521739] [client 20.151.200.44:63620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/wefile.php"] [unique_id "apPl_28byYE0iXl--K6mwAAAA4Y"]
[Sun Aug 30 03:12:47.009090 2026] [security2:error] [pid 521505:tid 521612] [remote 210.5.50.134:53474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.50.5.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "forewestmortgage.com"] [uri "/wp-login.php"] [unique_id "apPl_28byYE0iXl--K6mwQADUGo"], referer: https://forewestmortgage.com/wp-login.php
[Sun Aug 30 03:12:47.024430 2026] [authz_core:error] [pid 521505:tid 521680] [client 66.249.66.199:50199] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:47.024453 2026] [security2:error] [pid 521505:tid 521725] [client 4.205.62.107:16824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/requirements.php"] [unique_id "apPl_28byYE0iXl--K6mwwAAA3g"]
[Sun Aug 30 03:12:47.024704 2026] [authz_core:error] [pid 521505:tid 521680] [client 66.249.66.199:50199] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:47.066174 2026] [security2:error] [pid 521505:tid 521655] [client 20.104.18.15:22471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/mac.php"] [unique_id "apPl_28byYE0iXl--K6mxAAAAzI"]
[Sun Aug 30 03:12:47.075046 2026] [authz_core:error] [pid 521505:tid 521695] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:12:47.075377 2026] [authz_core:error] [pid 521505:tid 521695] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:12:47.075377 2026] [security2:error] [pid 521505:tid 521666] [client 68.155.159.216:60970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apPl_28byYE0iXl--K6mxgAAAz0"]
[Sun Aug 30 03:12:47.089880 2026] [security2:error] [pid 521505:tid 521760] [client 20.48.160.90:28783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/c4.php"] [unique_id "apPl_28byYE0iXl--K6myAAAA5s"]
[Sun Aug 30 03:12:47.122028 2026] [security2:error] [pid 521505:tid 521690] [client 20.104.18.15:1978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/wp-includes/index.php"] [unique_id "apPl_28byYE0iXl--K6myQAAA1U"]
[Sun Aug 30 03:12:47.135098 2026] [security2:error] [pid 521505:tid 521710] [client 20.48.250.41:64796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/thui.php"] [unique_id "apPl_28byYE0iXl--K6mywAAA2k"]
[Sun Aug 30 03:12:47.139313 2026] [authz_core:error] [pid 521505:tid 521677] [client 66.249.66.75:45228] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:47.139732 2026] [authz_core:error] [pid 521505:tid 521677] [client 66.249.66.75:45228] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:47.158228 2026] [security2:error] [pid 521505:tid 521643] [client 20.104.50.220:52853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/6index.php"] [unique_id "apPl_28byYE0iXl--K6mzAAAAyY"]
[Sun Aug 30 03:12:47.213441 2026] [security2:error] [pid 521505:tid 521711] [client 20.48.160.90:23770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPl_28byYE0iXl--K6mzQAAA2o"]
[Sun Aug 30 03:12:47.219307 2026] [security2:error] [pid 524122:tid 524253] [client 20.48.160.90:23695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp-tymanage.php"] [unique_id "apPl_33lhEjKFiK_nBKE9QAAAY8"]
[Sun Aug 30 03:12:47.230310 2026] [security2:error] [pid 521505:tid 521729] [client 20.104.50.220:51565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/anjay.php"] [unique_id "apPl_28byYE0iXl--K6mzgAAA3w"]
[Sun Aug 30 03:12:47.260695 2026] [security2:error] [pid 521505:tid 521722] [client 20.104.49.130:54199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/1xmomo.php"] [unique_id "apPl_28byYE0iXl--K6m0QAAA3U"]
[Sun Aug 30 03:12:47.266605 2026] [authz_core:error] [pid 521505:tid 521745] [client 216.73.216.128:35963] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:47.266883 2026] [authz_core:error] [pid 521505:tid 521745] [client 216.73.216.128:35963] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:47.273221 2026] [security2:error] [pid 521505:tid 521721] [client 20.104.50.220:24911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/7.php"] [unique_id "apPl_28byYE0iXl--K6m0gAAA3Q"]
[Sun Aug 30 03:12:47.289692 2026] [security2:error] [pid 521505:tid 521665] [client 4.205.62.107:15997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/8.php"] [unique_id "apPl_28byYE0iXl--K6m0wAAAzw"]
[Sun Aug 30 03:12:47.303976 2026] [security2:error] [pid 521505:tid 521705] [client 20.48.250.41:64799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/Jcrop.php"] [unique_id "apPl_28byYE0iXl--K6m1AAAA2Q"]
[Sun Aug 30 03:12:47.308548 2026] [security2:error] [pid 524122:tid 524268] [client 20.104.18.15:51185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/133.php"] [unique_id "apPl_33lhEjKFiK_nBKE9gAAAZ4"]
[Sun Aug 30 03:12:47.313500 2026] [security2:error] [pid 521505:tid 521648] [client 20.104.50.220:32862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/bj.php"] [unique_id "apPl_28byYE0iXl--K6m1QAAAys"]
[Sun Aug 30 03:12:47.315217 2026] [security2:error] [pid 524122:tid 524296] [client 20.104.50.220:29135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/000.php"] [unique_id "apPl_33lhEjKFiK_nBKE9wAAAbo"]
[Sun Aug 30 03:12:47.355655 2026] [security2:error] [pid 521505:tid 521684] [client 20.48.160.90:50426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPl_28byYE0iXl--K6m1wAAA08"]
[Sun Aug 30 03:12:47.356346 2026] [authz_core:error] [pid 524122:tid 524309] [client 216.73.216.128:34238] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:47.356608 2026] [authz_core:error] [pid 524122:tid 524309] [client 216.73.216.128:34238] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:47.357620 2026] [security2:error] [pid 521505:tid 521662] [client 4.205.62.107:16378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/lmfi2.php"] [unique_id "apPl_28byYE0iXl--K6m2QAAAzk"]
[Sun Aug 30 03:12:47.357800 2026] [security2:error] [pid 521505:tid 521650] [client 20.48.160.90:23700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/ajfto.php"] [unique_id "apPl_28byYE0iXl--K6m2AAAAy0"]
[Sun Aug 30 03:12:47.414594 2026] [security2:error] [pid 521505:tid 521754] [client 20.151.200.44:63598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/Contrller.php"] [unique_id "apPl_28byYE0iXl--K6m2gAAA5U"]
[Sun Aug 30 03:12:47.437189 2026] [security2:error] [pid 524122:tid 524270] [client 20.48.250.41:62436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/ws58.php"] [unique_id "apPl_33lhEjKFiK_nBKE-QAAAaA"]
[Sun Aug 30 03:12:47.454201 2026] [security2:error] [pid 521505:tid 521733] [client 20.48.251.3:46261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/hochladen.form.php"] [unique_id "apPl_28byYE0iXl--K6m3QAAA4A"]
[Sun Aug 30 03:12:47.470503 2026] [authz_core:error] [pid 521505:tid 521642] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory30
[Sun Aug 30 03:12:47.470840 2026] [authz_core:error] [pid 521505:tid 521642] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory30
[Sun Aug 30 03:12:47.503319 2026] [security2:error] [pid 524122:tid 524289] [client 20.104.50.220:31193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/0x.php"] [unique_id "apPl_33lhEjKFiK_nBKE-gAAAbM"]
[Sun Aug 30 03:12:47.508293 2026] [security2:error] [pid 521505:tid 521641] [client 20.48.160.90:23792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp_KwIW0U5F.php"] [unique_id "apPl_28byYE0iXl--K6m3wAAAyQ"]
[Sun Aug 30 03:12:47.549687 2026] [authz_core:error] [pid 521505:tid 521701] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:12:47.550146 2026] [authz_core:error] [pid 521505:tid 521701] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:12:47.558017 2026] [security2:error] [pid 521505:tid 521654] [client 20.48.160.90:23699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/about.php"] [unique_id "apPl_28byYE0iXl--K6m4QAAAzE"]
[Sun Aug 30 03:12:47.569471 2026] [security2:error] [pid 524122:tid 524377] [client 20.104.50.220:61975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/file52.php"] [unique_id "apPl_33lhEjKFiK_nBKE_AAAAgs"]
[Sun Aug 30 03:12:47.570914 2026] [security2:error] [pid 521505:tid 521659] [client 20.48.250.41:62418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/xs.php"] [unique_id "apPl_28byYE0iXl--K6m4gAAAzY"]
[Sun Aug 30 03:12:47.594702 2026] [security2:error] [pid 521505:tid 521751] [client 20.48.251.3:36868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "apPl_28byYE0iXl--K6m5QAAA5I"]
[Sun Aug 30 03:12:47.623720 2026] [security2:error] [pid 524122:tid 524337] [client 216.73.216.128:33612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts2/tweakftp"] [unique_id "apPl_33lhEjKFiK_nBKE_gAAAeM"]
[Sun Aug 30 03:12:47.637082 2026] [security2:error] [pid 524122:tid 524350] [client 20.48.160.90:29165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp_xiPu52Ut.php"] [unique_id "apPl_33lhEjKFiK_nBKE_wAAAfA"]
[Sun Aug 30 03:12:47.652869 2026] [security2:error] [pid 524122:tid 524322] [client 20.151.200.44:55718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.americanqualityhomeinspections.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPl_33lhEjKFiK_nBKFAAAAAdQ"]
[Sun Aug 30 03:12:47.670931 2026] [security2:error] [pid 521505:tid 521700] [client 20.197.61.180:8982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/gg.php"] [unique_id "apPl_28byYE0iXl--K6m5wAAA18"]
[Sun Aug 30 03:12:47.699697 2026] [security2:error] [pid 524122:tid 524370] [client 20.48.250.41:64833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/zu.php"] [unique_id "apPl_33lhEjKFiK_nBKFAQAAAgQ"]
[Sun Aug 30 03:12:47.731436 2026] [security2:error] [pid 521505:tid 521728] [client 4.205.62.107:25874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/aws_keys.php"] [unique_id "apPl_28byYE0iXl--K6m7AAAA3s"]
[Sun Aug 30 03:12:47.767613 2026] [security2:error] [pid 524122:tid 524292] [client 20.48.251.3:52181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/requirements.php"] [unique_id "apPl_33lhEjKFiK_nBKFBQAAAbY"]
[Sun Aug 30 03:12:47.832326 2026] [security2:error] [pid 524122:tid 524379] [client 20.48.250.41:64805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/lanka.php"] [unique_id "apPl_33lhEjKFiK_nBKFBgAAAg0"]
[Sun Aug 30 03:12:47.870522 2026] [security2:error] [pid 521505:tid 521717] [client 20.151.200.44:63606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/file66.php"] [unique_id "apPl_28byYE0iXl--K6m8QAAA3A"]
[Sun Aug 30 03:12:47.903193 2026] [authz_core:error] [pid 524122:tid 524378] [client 216.73.216.128:34238] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:47.903538 2026] [authz_core:error] [pid 524122:tid 524378] [client 216.73.216.128:34238] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:47.959801 2026] [authz_core:error] [pid 521505:tid 521667] [client 66.249.66.73:61299] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:47.960079 2026] [authz_core:error] [pid 521505:tid 521667] [client 66.249.66.73:61299] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:47.960604 2026] [security2:error] [pid 521505:tid 521683] [client 20.48.250.41:62378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/gettest.php"] [unique_id "apPl_28byYE0iXl--K6m-QAAA04"]
[Sun Aug 30 03:12:47.991763 2026] [authz_core:error] [pid 521505:tid 521685] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory33
[Sun Aug 30 03:12:47.992225 2026] [authz_core:error] [pid 521505:tid 521685] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory33
[Sun Aug 30 03:12:48.026777 2026] [security2:error] [pid 524122:tid 524299] [client 20.104.50.220:6100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/37.php"] [unique_id "apPmAH3lhEjKFiK_nBKFCgAAAb0"]
[Sun Aug 30 03:12:48.037212 2026] [authz_core:error] [pid 521505:tid 521720] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:12:48.037567 2026] [authz_core:error] [pid 521505:tid 521720] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2Fthread-self
[Sun Aug 30 03:12:48.045302 2026] [security2:error] [pid 521505:tid 521732] [client 20.104.50.220:17342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/ui.php"] [unique_id "apPmAG8byYE0iXl--K6nAAAAA38"]
[Sun Aug 30 03:12:48.063716 2026] [security2:error] [pid 521505:tid 521666] [client 20.151.200.44:55705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.americanqualityhomeinspections.com"] [uri "/h02ugyh.php"] [unique_id "apPmAG8byYE0iXl--K6nAQAAAz0"]
[Sun Aug 30 03:12:48.089285 2026] [security2:error] [pid 521505:tid 521690] [client 20.48.250.41:64801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/35.php"] [unique_id "apPmAG8byYE0iXl--K6nBQAAA1U"]
[Sun Aug 30 03:12:48.163989 2026] [security2:error] [pid 521505:tid 521653] [client 4.205.62.107:16785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/var/www/wallet/index.php"] [unique_id "apPmAG8byYE0iXl--K6nBwAAAzA"]
[Sun Aug 30 03:12:48.184208 2026] [security2:error] [pid 521505:tid 521664] [client 4.205.62.107:52829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/ty.php"] [unique_id "apPmAG8byYE0iXl--K6nCQAAAzs"]
[Sun Aug 30 03:12:48.191032 2026] [security2:error] [pid 521505:tid 521706] [client 20.151.200.44:63619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/blnux.php"] [unique_id "apPmAG8byYE0iXl--K6nCgAAA2U"]
[Sun Aug 30 03:12:48.213867 2026] [security2:error] [pid 521505:tid 521755] [client 68.155.159.216:60932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apPmAG8byYE0iXl--K6nCwAAA5Y"]
[Sun Aug 30 03:12:48.216806 2026] [security2:error] [pid 521505:tid 521746] [client 20.48.250.41:64807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/maraz.php"] [unique_id "apPmAG8byYE0iXl--K6nDAAAA40"]
[Sun Aug 30 03:12:48.220029 2026] [security2:error] [pid 524122:tid 524300] [client 20.104.18.15:22426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/simple.php"] [unique_id "apPmAH3lhEjKFiK_nBKFDAAAAb4"]
[Sun Aug 30 03:12:48.220996 2026] [security2:error] [pid 521505:tid 521661] [client 20.104.49.130:63523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/reviall.php"] [unique_id "apPmAG8byYE0iXl--K6nDQAAAzg"]
[Sun Aug 30 03:12:48.262551 2026] [security2:error] [pid 521505:tid 521705] [client 20.104.18.15:1930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/dk.php"] [unique_id "apPmAG8byYE0iXl--K6nDwAAA2Q"]
[Sun Aug 30 03:12:48.271590 2026] [authz_core:error] [pid 521505:tid 521744] [client 216.73.216.128:29934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:48.271865 2026] [authz_core:error] [pid 521505:tid 521744] [client 216.73.216.128:29934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:48.343166 2026] [security2:error] [pid 524122:tid 524363] [client 20.104.50.220:62846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/7index.php"] [unique_id "apPmAH3lhEjKFiK_nBKFDQAAAf0"]
[Sun Aug 30 03:12:48.344142 2026] [security2:error] [pid 521505:tid 521662] [client 20.48.250.41:64813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/kbfr.php"] [unique_id "apPmAG8byYE0iXl--K6nEAAAAzk"]
[Sun Aug 30 03:12:48.365208 2026] [security2:error] [pid 521505:tid 521669] [client 20.197.61.180:9023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/defaults.php"] [unique_id "apPmAG8byYE0iXl--K6nEQAAA0A"]
[Sun Aug 30 03:12:48.413621 2026] [security2:error] [pid 521505:tid 521745] [client 20.104.50.220:56715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/anons79.php"] [unique_id "apPmAG8byYE0iXl--K6nEwAAA4w"]
[Sun Aug 30 03:12:48.447575 2026] [authz_core:error] [pid 521505:tid 521754] [client 66.249.66.35:52844] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:48.447875 2026] [authz_core:error] [pid 521505:tid 521754] [client 66.249.66.35:52844] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:48.448064 2026] [security2:error] [pid 521505:tid 521679] [client 4.205.62.107:16328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/thui.php"] [unique_id "apPmAG8byYE0iXl--K6nFgAAA0o"]
[Sun Aug 30 03:12:48.448779 2026] [authz_core:error] [pid 521505:tid 521670] [client 216.73.216.128:29934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:48.449040 2026] [authz_core:error] [pid 521505:tid 521670] [client 216.73.216.128:29934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:48.450751 2026] [security2:error] [pid 521505:tid 521715] [client 20.104.50.220:24876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/8.php"] [unique_id "apPmAG8byYE0iXl--K6nFwAAA24"]
[Sun Aug 30 03:12:48.450765 2026] [security2:error] [pid 521505:tid 521699] [client 20.151.200.44:52140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/xda.php"] [unique_id "apPmAG8byYE0iXl--K6nGAAAA14"]
[Sun Aug 30 03:12:48.451308 2026] [security2:error] [pid 521505:tid 521723] [client 20.104.50.220:33167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/black.php"] [unique_id "apPmAG8byYE0iXl--K6nGQAAA3Y"]
[Sun Aug 30 03:12:48.466969 2026] [security2:error] [pid 521505:tid 521733] [client 20.104.50.220:52811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/okkk.php"] [unique_id "apPmAG8byYE0iXl--K6nGgAAA4A"]
[Sun Aug 30 03:12:48.467139 2026] [security2:error] [pid 524122:tid 524330] [client 20.104.18.15:51178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/sym.php"] [unique_id "apPmAH3lhEjKFiK_nBKFDwAAAdw"]
[Sun Aug 30 03:12:48.483910 2026] [security2:error] [pid 521505:tid 521680] [client 20.48.250.41:62445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/wp-act.php"] [unique_id "apPmAG8byYE0iXl--K6nHAAAA0s"]
[Sun Aug 30 03:12:48.494127 2026] [authz_core:error] [pid 521505:tid 521663] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory18
[Sun Aug 30 03:12:48.494376 2026] [authz_core:error] [pid 521505:tid 521663] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory18
[Sun Aug 30 03:12:48.506043 2026] [security2:error] [pid 521505:tid 521641] [client 20.104.49.130:57691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alarm-monitoring.net"] [uri "/images.php"] [unique_id "apPmAG8byYE0iXl--K6nHgAAAyQ"]
[Sun Aug 30 03:12:48.506043 2026] [security2:error] [pid 524122:tid 524317] [client 4.205.62.107:15992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/wpver.php"] [unique_id "apPmAH3lhEjKFiK_nBKFEQAAAc8"]
[Sun Aug 30 03:12:48.538734 2026] [authz_core:error] [pid 521505:tid 521671] [client 216.73.216.128:35963] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:48.538979 2026] [authz_core:error] [pid 521505:tid 521671] [client 216.73.216.128:35963] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:48.550292 2026] [authz_core:error] [pid 521505:tid 521659] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:48.550542 2026] [authz_core:error] [pid 521505:tid 521659] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:48.617913 2026] [security2:error] [pid 521505:tid 521668] [client 20.151.200.44:52123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPmAG8byYE0iXl--K6nJQAAAz8"]
[Sun Aug 30 03:12:48.618516 2026] [security2:error] [pid 521505:tid 521658] [client 20.48.251.3:54830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/debuggen.php"] [unique_id "apPmAG8byYE0iXl--K6nJgAAAzU"]
[Sun Aug 30 03:12:48.647116 2026] [security2:error] [pid 521505:tid 521678] [client 158.23.147.79:59035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apPmAG8byYE0iXl--K6nJwAAA0k"]
[Sun Aug 30 03:12:48.650925 2026] [security2:error] [pid 521505:tid 521700] [client 20.48.250.41:62380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/24.php"] [unique_id "apPmAG8byYE0iXl--K6nKAAAA18"]
[Sun Aug 30 03:12:48.664537 2026] [security2:error] [pid 524122:tid 524375] [client 20.104.50.220:31516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/css.php"] [unique_id "apPmAH3lhEjKFiK_nBKFEwAAAgk"]
[Sun Aug 30 03:12:48.667518 2026] [security2:error] [pid 521505:tid 521696] [client 20.151.200.44:23576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/attack.php"] [unique_id "apPmAG8byYE0iXl--K6nKQAAA1s"]
[Sun Aug 30 03:12:48.700248 2026] [security2:error] [pid 521505:tid 521728] [client 20.48.160.90:23798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/admin.php/admin.php"] [unique_id "apPmAG8byYE0iXl--K6nKgAAA3s"]
[Sun Aug 30 03:12:48.714503 2026] [security2:error] [pid 521505:tid 521637] [client 20.104.50.220:61685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/zde.php"] [unique_id "apPmAG8byYE0iXl--K6nKwAAAyA"]
[Sun Aug 30 03:12:48.721043 2026] [authz_core:error] [pid 521505:tid 521673] [client 216.73.216.128:29934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:48.721460 2026] [authz_core:error] [pid 521505:tid 521673] [client 216.73.216.128:29934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:48.728704 2026] [security2:error] [pid 524122:tid 524297] [client 20.104.49.130:60933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/az.php"] [unique_id "apPmAH3lhEjKFiK_nBKFFAAAAbs"]
[Sun Aug 30 03:12:48.731251 2026] [security2:error] [pid 521505:tid 521734] [client 20.48.251.3:37180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/myfile.php"] [unique_id "apPmAG8byYE0iXl--K6nLQAAA4E"]
[Sun Aug 30 03:12:48.750787 2026] [security2:error] [pid 521505:tid 521698] [client 20.104.49.130:54172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/pfm.php"] [unique_id "apPmAG8byYE0iXl--K6nLgAAA10"]
[Sun Aug 30 03:12:48.778507 2026] [security2:error] [pid 524122:tid 524307] [client 20.48.160.90:29178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp_n5VD7XDh.php"] [unique_id "apPmAH3lhEjKFiK_nBKFFQAAAcU"]
[Sun Aug 30 03:12:48.779720 2026] [security2:error] [pid 521505:tid 521638] [client 20.48.250.41:62448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/155.php"] [unique_id "apPmAG8byYE0iXl--K6nLwAAAyE"]
[Sun Aug 30 03:12:48.824374 2026] [security2:error] [pid 521505:tid 521672] [client 20.151.200.44:45968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/t00l.php"] [unique_id "apPmAG8byYE0iXl--K6nMQAAA0M"]
[Sun Aug 30 03:12:48.827048 2026] [security2:error] [pid 521505:tid 521693] [client 20.48.160.90:28746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/media.php"] [unique_id "apPmAG8byYE0iXl--K6nMgAAA1g"]
[Sun Aug 30 03:12:48.887667 2026] [security2:error] [pid 524122:tid 524359] [client 4.205.62.107:25480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/umgebung.php"] [unique_id "apPmAH3lhEjKFiK_nBKFGAAAAfk"]
[Sun Aug 30 03:12:48.904398 2026] [authz_core:error] [pid 521505:tid 521688] [client 216.73.216.128:29934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:48.904718 2026] [authz_core:error] [pid 521505:tid 521688] [client 216.73.216.128:29934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:48.914674 2026] [security2:error] [pid 521505:tid 521739] [client 20.48.160.90:50426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp-mini.php"] [unique_id "apPmAG8byYE0iXl--K6nNgAAA4Y"]
[Sun Aug 30 03:12:48.920401 2026] [security2:error] [pid 521505:tid 521660] [client 20.48.250.41:62340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/file.php"] [unique_id "apPmAG8byYE0iXl--K6nNwAAAzc"]
[Sun Aug 30 03:12:48.949635 2026] [security2:error] [pid 524122:tid 524305] [client 20.151.200.44:52158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/t00l.php"] [unique_id "apPmAH3lhEjKFiK_nBKFGQAAAcM"]
[Sun Aug 30 03:12:48.953691 2026] [security2:error] [pid 521505:tid 521694] [client 20.48.251.3:43114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/var/www/wallet/index.php"] [unique_id "apPmAG8byYE0iXl--K6nOQAAA1k"]
[Sun Aug 30 03:12:48.959335 2026] [security2:error] [pid 521505:tid 521651] [client 20.48.160.90:29126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/mac.php"] [unique_id "apPmAG8byYE0iXl--K6nOgAAAy4"]
[Sun Aug 30 03:12:48.978003 2026] [authz_core:error] [pid 521505:tid 521685] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory13
[Sun Aug 30 03:12:48.978281 2026] [authz_core:error] [pid 521505:tid 521685] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory13
[Sun Aug 30 03:12:49.030092 2026] [authz_core:error] [pid 521505:tid 521711] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:49.030380 2026] [authz_core:error] [pid 521505:tid 521711] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:49.048725 2026] [security2:error] [pid 521505:tid 521675] [client 20.48.250.41:64775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPmAW8byYE0iXl--K6nPQAAA0Y"]
[Sun Aug 30 03:12:49.051885 2026] [security2:error] [pid 521505:tid 521746] [client 20.48.160.90:23736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/xmini4.php"] [unique_id "apPmAW8byYE0iXl--K6nPgAAA40"]
[Sun Aug 30 03:12:49.067487 2026] [security2:error] [pid 524122:tid 524179] [remote 93.123.109.228:45152] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "jeanbooknerdmedia.com"] [uri "/*update.cgi*"] [unique_id "apPmAX3lhEjKFiK_nBKFIgAB3zc"]
[Sun Aug 30 03:12:49.092751 2026] [security2:error] [pid 521505:tid 521681] [client 20.197.61.180:11389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/h.php"] [unique_id "apPmAW8byYE0iXl--K6nQQAAA0w"]
[Sun Aug 30 03:12:49.115951 2026] [security2:error] [pid 521505:tid 521591] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/backend/.env"] [unique_id "apPmAW8byYE0iXl--K6nSAADNFU"]
[Sun Aug 30 03:12:49.115956 2026] [security2:error] [pid 521505:tid 521623] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/.env"] [unique_id "apPmAW8byYE0iXl--K6nRgADNHU"]
[Sun Aug 30 03:12:49.170241 2026] [security2:error] [pid 521505:tid 521689] [client 20.104.50.220:5598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/36.php"] [unique_id "apPmAW8byYE0iXl--K6nTQAAA1Q"]
[Sun Aug 30 03:12:49.183612 2026] [security2:error] [pid 524122:tid 524342] [client 20.104.50.220:17265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/zz.php"] [unique_id "apPmAX3lhEjKFiK_nBKFJQAAAeg"]
[Sun Aug 30 03:12:49.186207 2026] [security2:error] [pid 521505:tid 521679] [client 20.48.250.41:64844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/06.php"] [unique_id "apPmAW8byYE0iXl--K6nTwAAA0o"]
[Sun Aug 30 03:12:49.186466 2026] [security2:error] [pid 521505:tid 521715] [client 20.104.49.130:36786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/albin.php"] [unique_id "apPmAW8byYE0iXl--K6nUAAAA24"]
[Sun Aug 30 03:12:49.235818 2026] [authz_core:error] [pid 524122:tid 524362] [client 66.249.66.200:62385] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:49.236281 2026] [authz_core:error] [pid 524122:tid 524362] [client 66.249.66.200:62385] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:49.261542 2026] [security2:error] [pid 521505:tid 521562] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/*update.cgi*"] [unique_id "apPmAW8byYE0iXl--K6nWQADSzg"]
[Sun Aug 30 03:12:49.266277 2026] [security2:error] [pid 521505:tid 521723] [client 109.107.164.52:61003] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "fromtheseaofwakingdreams.com"] [uri "/wp-comments-post.php"] [unique_id "apPmAW8byYE0iXl--K6nUgAAA3Y"], referer: http://fromtheseaofwakingdreams.com/archives/1
[Sun Aug 30 03:12:49.295434 2026] [security2:error] [pid 524122:tid 524316] [client 20.151.200.44:55703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.americanqualityhomeinspections.com"] [uri "/sf.php"] [unique_id "apPmAX3lhEjKFiK_nBKFKAAAAc4"]
[Sun Aug 30 03:12:49.300252 2026] [security2:error] [pid 524122:tid 524340] [client 4.205.62.107:17723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/124.php"] [unique_id "apPmAX3lhEjKFiK_nBKFKQAAAeY"]
[Sun Aug 30 03:12:49.322213 2026] [security2:error] [pid 524122:tid 524287] [client 20.48.250.41:64875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/class.php"] [unique_id "apPmAX3lhEjKFiK_nBKFKgAAAbE"]
[Sun Aug 30 03:12:49.355146 2026] [security2:error] [pid 521505:tid 521510] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/.docker/laravel/app/.env"] [unique_id "apPmAW8byYE0iXl--K6nXwADlAQ"]
[Sun Aug 30 03:12:49.356196 2026] [security2:error] [pid 521505:tid 521600] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/.env"] [unique_id "apPmAW8byYE0iXl--K6nYwADlF4"]
[Sun Aug 30 03:12:49.361259 2026] [security2:error] [pid 524122:tid 524329] [client 20.104.18.15:22490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/sallu.php"] [unique_id "apPmAX3lhEjKFiK_nBKFLQAAAds"]
[Sun Aug 30 03:12:49.362074 2026] [security2:error] [pid 521505:tid 521668] [client 68.155.159.216:60989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/simple.php"] [unique_id "apPmAW8byYE0iXl--K6nZAAAAz8"]
[Sun Aug 30 03:12:49.392601 2026] [security2:error] [pid 524122:tid 524258] [client 4.205.62.107:52814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/adminer-4.7.6-en.php"] [unique_id "apPmAX3lhEjKFiK_nBKFLgAAAZQ"]
[Sun Aug 30 03:12:49.398810 2026] [security2:error] [pid 524122:tid 524255] [client 20.104.18.15:1999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apPmAX3lhEjKFiK_nBKFLwAAAZE"]
[Sun Aug 30 03:12:49.431370 2026] [security2:error] [pid 521505:tid 521723] [client 109.107.164.52:61003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "fromtheseaofwakingdreams.com"] [uri "/wp-comments-post.php"] [unique_id "apPmAW8byYE0iXl--K6nUgAAA3Y"], referer: http://fromtheseaofwakingdreams.com/archives/1
[Sun Aug 30 03:12:49.442450 2026] [security2:error] [pid 521505:tid 521633] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/.docker/.env"] [unique_id "apPmAW8byYE0iXl--K6nZwADYH8"]
[Sun Aug 30 03:12:49.460654 2026] [authz_core:error] [pid 521505:tid 521759] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:12:49.460930 2026] [authz_core:error] [pid 521505:tid 521759] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:12:49.463234 2026] [security2:error] [pid 521505:tid 521728] [client 20.48.250.41:62454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/8.php"] [unique_id "apPmAW8byYE0iXl--K6nbQAAA3s"]
[Sun Aug 30 03:12:49.470143 2026] [authz_core:error] [pid 521505:tid 521671] [client 66.249.66.202:58013] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:49.470408 2026] [authz_core:error] [pid 521505:tid 521671] [client 66.249.66.202:58013] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:49.486380 2026] [security2:error] [pid 521505:tid 521637] [client 20.104.50.220:29571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/8index.php"] [unique_id "apPmAW8byYE0iXl--K6nbwAAAyA"]
[Sun Aug 30 03:12:49.495264 2026] [security2:error] [pid 521505:tid 521534] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/.env.bak"] [unique_id "apPmAW8byYE0iXl--K6ndgADTRw"]
[Sun Aug 30 03:12:49.495273 2026] [security2:error] [pid 521505:tid 521594] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/.env.backup"] [unique_id "apPmAW8byYE0iXl--K6ncgADTVg"]
[Sun Aug 30 03:12:49.527660 2026] [authz_core:error] [pid 521505:tid 521698] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:49.527910 2026] [authz_core:error] [pid 521505:tid 521698] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:49.532043 2026] [security2:error] [pid 524122:tid 524278] [client 20.151.200.44:52153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/ls.php"] [unique_id "apPmAX3lhEjKFiK_nBKFMwAAAag"]
[Sun Aug 30 03:12:49.567046 2026] [security2:error] [pid 521505:tid 521704] [client 20.104.50.220:42465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/base.php"] [unique_id "apPmAW8byYE0iXl--K6nfwAAA2M"]
[Sun Aug 30 03:12:49.581849 2026] [security2:error] [pid 521505:tid 521672] [client 4.205.62.107:16373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/file21.php"] [unique_id "apPmAW8byYE0iXl--K6ngAAAA0M"]
[Sun Aug 30 03:12:49.591027 2026] [security2:error] [pid 521505:tid 521673] [client 20.104.50.220:32928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/by.php"] [unique_id "apPmAW8byYE0iXl--K6nggAAA0Q"]
[Sun Aug 30 03:12:49.592763 2026] [security2:error] [pid 521505:tid 521731] [client 20.48.250.41:64779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/0x0x.php"] [unique_id "apPmAW8byYE0iXl--K6ngwAAA34"]
[Sun Aug 30 03:12:49.593800 2026] [security2:error] [pid 521505:tid 521726] [client 20.104.50.220:24887] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/1.php"] [unique_id "apPmAW8byYE0iXl--K6nhAAAA3k"]
[Sun Aug 30 03:12:49.593858 2026] [security2:error] [pid 521505:tid 521726] [client 20.104.50.220:24887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/1.php"] [unique_id "apPmAW8byYE0iXl--K6nhAAAA3k"]
[Sun Aug 30 03:12:49.600037 2026] [security2:error] [pid 521505:tid 521757] [client 20.104.18.15:51087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/8.php"] [unique_id "apPmAW8byYE0iXl--K6nhQAAA5g"]
[Sun Aug 30 03:12:49.615982 2026] [security2:error] [pid 521505:tid 521580] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/.env.old"] [unique_id "apPmAW8byYE0iXl--K6nhgADkEo"]
[Sun Aug 30 03:12:49.625197 2026] [security2:error] [pid 521505:tid 521739] [client 20.104.50.220:29593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/yamate.php"] [unique_id "apPmAW8byYE0iXl--K6nhwAAA4Y"]
[Sun Aug 30 03:12:49.644924 2026] [security2:error] [pid 521505:tid 521750] [client 4.205.62.107:15975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/ah25.php"] [unique_id "apPmAW8byYE0iXl--K6niQAAA5E"]
[Sun Aug 30 03:12:49.706093 2026] [security2:error] [pid 521505:tid 521746] [client 20.104.49.130:63574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wdfjba.org"] [uri "/33.php"] [unique_id "apPmAW8byYE0iXl--K6nigAAA40"]
[Sun Aug 30 03:12:49.723713 2026] [security2:error] [pid 521505:tid 521647] [client 158.23.147.79:55384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/simple.php"] [unique_id "apPmAW8byYE0iXl--K6njAAAAyo"]
[Sun Aug 30 03:12:49.724376 2026] [authz_core:error] [pid 521505:tid 521722] [client 216.73.216.128:44329] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:49.724685 2026] [authz_core:error] [pid 521505:tid 521722] [client 216.73.216.128:44329] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:49.754766 2026] [security2:error] [pid 521505:tid 521661] [client 20.48.251.3:46210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/pouhg.php"] [unique_id "apPmAW8byYE0iXl--K6njQAAAzg"]
[Sun Aug 30 03:12:49.761464 2026] [security2:error] [pid 521505:tid 521718] [client 20.48.250.41:64811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/166.php"] [unique_id "apPmAW8byYE0iXl--K6njgAAA3E"]
[Sun Aug 30 03:12:49.763175 2026] [security2:error] [pid 521505:tid 521721] [client 20.151.200.44:46057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/ls.php"] [unique_id "apPmAW8byYE0iXl--K6njwAAA3Q"]
[Sun Aug 30 03:12:49.804016 2026] [security2:error] [pid 521505:tid 521752] [client 20.104.49.130:53582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/ws85.php"] [unique_id "apPmAW8byYE0iXl--K6nkAAAA5M"]
[Sun Aug 30 03:12:49.817278 2026] [authz_core:error] [pid 521505:tid 521665] [client 216.73.216.128:35963] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:49.817499 2026] [security2:error] [pid 521505:tid 521636] [client 20.197.61.180:11371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/num.php"] [unique_id "apPmAW8byYE0iXl--K6nkgAAAx8"]
[Sun Aug 30 03:12:49.817557 2026] [authz_core:error] [pid 521505:tid 521665] [client 216.73.216.128:35963] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:49.819916 2026] [security2:error] [pid 521505:tid 521655] [client 20.104.50.220:59371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/222.php"] [unique_id "apPmAW8byYE0iXl--K6nkwAAAzI"]
[Sun Aug 30 03:12:49.875607 2026] [security2:error] [pid 521505:tid 521742] [client 20.104.50.220:61458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wpo.php"] [unique_id "apPmAW8byYE0iXl--K6nlAAAA4k"]
[Sun Aug 30 03:12:49.879686 2026] [security2:error] [pid 524122:tid 524289] [client 20.48.251.3:37158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/lm15.php"] [unique_id "apPmAX3lhEjKFiK_nBKFNgAAAbM"]
[Sun Aug 30 03:12:49.888470 2026] [security2:error] [pid 521505:tid 521690] [client 158.23.147.79:59058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-admin/about.php"] [unique_id "apPmAW8byYE0iXl--K6nlgAAA1U"]
[Sun Aug 30 03:12:49.913286 2026] [authz_core:error] [pid 521505:tid 521727] [client 216.73.216.128:44329] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:49.913749 2026] [authz_core:error] [pid 521505:tid 521727] [client 216.73.216.128:44329] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:49.952943 2026] [authz_core:error] [pid 521505:tid 521657] [client 66.249.66.193:45977] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:49.953430 2026] [authz_core:error] [pid 521505:tid 521657] [client 66.249.66.193:45977] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:49.988872 2026] [authz_core:error] [pid 521505:tid 521761] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:12:49.989155 2026] [authz_core:error] [pid 521505:tid 521761] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:12:49.995696 2026] [security2:error] [pid 524122:tid 524377] [client 20.151.200.44:23611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/wk/index.php"] [unique_id "apPmAX3lhEjKFiK_nBKFOAAAAgs"]
[Sun Aug 30 03:12:50.005188 2026] [authz_core:error] [pid 521505:tid 521710] [client 216.73.216.128:35963] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:50.005443 2026] [authz_core:error] [pid 521505:tid 521710] [client 216.73.216.128:35963] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:50.029130 2026] [authz_core:error] [pid 521505:tid 521740] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:50.029405 2026] [authz_core:error] [pid 521505:tid 521740] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:50.040199 2026] [security2:error] [pid 521505:tid 521640] [client 20.151.200.44:45970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/css/000.php"] [unique_id "apPmAm8byYE0iXl--K6noAAAAyM"]
[Sun Aug 30 03:12:50.045481 2026] [security2:error] [pid 521505:tid 521695] [client 158.23.147.79:55365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apPmAm8byYE0iXl--K6noQAAA1o"]
[Sun Aug 30 03:12:50.047886 2026] [security2:error] [pid 521505:tid 521685] [client 4.205.62.107:25684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/old_phpinfo.php"] [unique_id "apPmAm8byYE0iXl--K6nogAAA1A"]
[Sun Aug 30 03:12:50.053321 2026] [security2:error] [pid 521505:tid 521650] [client 20.104.49.130:63504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/wp-login.php"] [unique_id "apPmAm8byYE0iXl--K6nowAAAy0"]
[Sun Aug 30 03:12:50.105545 2026] [security2:error] [pid 521505:tid 521667] [client 20.48.160.90:28759] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.relationalsacredhealing.com"] [uri "/1.php"] [unique_id "apPmAm8byYE0iXl--K6npgAAAz4"]
[Sun Aug 30 03:12:50.105632 2026] [security2:error] [pid 521505:tid 521667] [client 20.48.160.90:28759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/1.php"] [unique_id "apPmAm8byYE0iXl--K6npgAAAz4"]
[Sun Aug 30 03:12:50.109426 2026] [security2:error] [pid 521505:tid 521711] [client 20.48.251.3:43094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/124.php"] [unique_id "apPmAm8byYE0iXl--K6npwAAA2o"]
[Sun Aug 30 03:12:50.125442 2026] [authz_core:error] [pid 521505:tid 521699] [client 66.249.66.199:50199] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:50.125738 2026] [authz_core:error] [pid 521505:tid 521699] [client 66.249.66.199:50199] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:50.128276 2026] [security2:error] [pid 524122:tid 524350] [client 20.48.250.41:64783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/h2a2ck.php"] [unique_id "apPmAn3lhEjKFiK_nBKFOQAAAfA"]
[Sun Aug 30 03:12:50.185299 2026] [security2:error] [pid 521505:tid 521635] [client 20.48.160.90:23785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/reop3.php"] [unique_id "apPmAm8byYE0iXl--K6nrAAAAx4"]
[Sun Aug 30 03:12:50.187731 2026] [authz_core:error] [pid 524122:tid 524352] [client 216.73.216.128:34238] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:50.188079 2026] [authz_core:error] [pid 524122:tid 524352] [client 216.73.216.128:34238] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:50.236880 2026] [security2:error] [pid 524122:tid 524328] [client 20.48.160.90:49252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/classwithtostring.php"] [unique_id "apPmAn3lhEjKFiK_nBKFPQAAAdo"]
[Sun Aug 30 03:12:50.284543 2026] [security2:error] [pid 521505:tid 521753] [client 20.48.250.41:64831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/error_log.php"] [unique_id "apPmAm8byYE0iXl--K6nsQAAA5Q"]
[Sun Aug 30 03:12:50.322219 2026] [security2:error] [pid 524122:tid 524345] [client 20.104.50.220:17287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/allyson162.php"] [unique_id "apPmAn3lhEjKFiK_nBKFPgAAAes"]
[Sun Aug 30 03:12:50.324606 2026] [security2:error] [pid 524122:tid 524336] [client 20.104.50.220:6115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/35.php"] [unique_id "apPmAn3lhEjKFiK_nBKFPwAAAeI"]
[Sun Aug 30 03:12:50.343393 2026] [security2:error] [pid 524122:tid 524304] [client 20.48.160.90:23708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp-mail.php"] [unique_id "apPmAn3lhEjKFiK_nBKFQAAAAcI"]
[Sun Aug 30 03:12:50.367664 2026] [security2:error] [pid 524122:tid 524257] [client 20.48.160.90:28769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp-ws68.php"] [unique_id "apPmAn3lhEjKFiK_nBKFQgAAAZM"]
[Sun Aug 30 03:12:50.421007 2026] [security2:error] [pid 524122:tid 524373] [client 158.23.147.79:59015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apPmAn3lhEjKFiK_nBKFRAAAAgc"]
[Sun Aug 30 03:12:50.429959 2026] [security2:error] [pid 521505:tid 521700] [client 20.48.250.41:62443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/403.php"] [unique_id "apPmAm8byYE0iXl--K6ntgAAA18"]
[Sun Aug 30 03:12:50.429990 2026] [security2:error] [pid 521505:tid 521733] [client 4.205.62.107:17704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/test1.php"] [unique_id "apPmAm8byYE0iXl--K6ntwAAA4A"]
[Sun Aug 30 03:12:50.468573 2026] [security2:error] [pid 521505:tid 521558] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/.env.php"] [unique_id "apPmAm8byYE0iXl--K6nuQADYjQ"]
[Sun Aug 30 03:12:50.469707 2026] [security2:error] [pid 521505:tid 521632] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/.env~"] [unique_id "apPmAm8byYE0iXl--K6nwAADYn4"]
[Sun Aug 30 03:12:50.469782 2026] [security2:error] [pid 521505:tid 521528] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/.env.swp"] [unique_id "apPmAm8byYE0iXl--K6nwgADYhY"]
[Sun Aug 30 03:12:50.491614 2026] [authz_core:error] [pid 521505:tid 521696] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory13
[Sun Aug 30 03:12:50.491903 2026] [authz_core:error] [pid 521505:tid 521696] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory13
[Sun Aug 30 03:12:50.494331 2026] [security2:error] [pid 521505:tid 521692] [client 20.104.18.15:22435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/biufile.php"] [unique_id "apPmAm8byYE0iXl--K6nywAAA1c"]
[Sun Aug 30 03:12:50.518420 2026] [security2:error] [pid 524122:tid 524262] [client 4.205.62.107:32008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPmAn3lhEjKFiK_nBKFSAAAAZg"]
[Sun Aug 30 03:12:50.529832 2026] [security2:error] [pid 521505:tid 521686] [client 20.48.160.90:23733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp-conffg.php"] [unique_id "apPmAm8byYE0iXl--K6nzQAAA1E"]
[Sun Aug 30 03:12:50.536924 2026] [security2:error] [pid 521505:tid 521644] [client 20.151.200.44:62914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/dehnl.php"] [unique_id "apPmAm8byYE0iXl--K6nzgAAAyc"]
[Sun Aug 30 03:12:50.537558 2026] [security2:error] [pid 521505:tid 521638] [client 20.104.18.15:1879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/xc.php"] [unique_id "apPmAm8byYE0iXl--K6nzwAAAyE"]
[Sun Aug 30 03:12:50.541911 2026] [security2:error] [pid 521505:tid 521704] [client 68.155.159.216:60326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/wp-admin/about.php"] [unique_id "apPmAm8byYE0iXl--K6n0AAAA2M"]
[Sun Aug 30 03:12:50.542343 2026] [security2:error] [pid 521505:tid 521672] [client 4.205.62.107:29150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/phpi.php"] [unique_id "apPmAm8byYE0iXl--K6n0QAAA0M"]
[Sun Aug 30 03:12:50.547299 2026] [security2:error] [pid 521505:tid 521658] [client 20.48.160.90:23716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/simple.php"] [unique_id "apPmAm8byYE0iXl--K6n0gAAAzU"]
[Sun Aug 30 03:12:50.559337 2026] [authz_core:error] [pid 524122:tid 524347] [client 216.73.216.128:34238] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:50.559633 2026] [authz_core:error] [pid 524122:tid 524347] [client 216.73.216.128:34238] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:50.564019 2026] [authz_core:error] [pid 521505:tid 521731] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:50.564425 2026] [authz_core:error] [pid 521505:tid 521731] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:50.571421 2026] [security2:error] [pid 521505:tid 521682] [client 52.139.37.240:50324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/nakrip.php"] [unique_id "apPmAm8byYE0iXl--K6n1AAAA00"]
[Sun Aug 30 03:12:50.576669 2026] [security2:error] [pid 524122:tid 524379] [client 20.197.61.180:1676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/abc.php"] [unique_id "apPmAn3lhEjKFiK_nBKFSgAAAg0"]
[Sun Aug 30 03:12:50.577604 2026] [security2:error] [pid 521505:tid 521654] [client 20.48.250.41:62442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/cytyr.php"] [unique_id "apPmAm8byYE0iXl--K6n1gAAAzE"]
[Sun Aug 30 03:12:50.584020 2026] [authz_core:error] [pid 521505:tid 521674] [client 66.249.66.42:43742] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:50.584278 2026] [authz_core:error] [pid 521505:tid 521674] [client 66.249.66.42:43742] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:50.624061 2026] [security2:error] [pid 521505:tid 521750] [client 20.104.50.220:62834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/9index.php"] [unique_id "apPmAm8byYE0iXl--K6n2AAAA5E"]
[Sun Aug 30 03:12:50.663509 2026] [security2:error] [pid 524122:tid 524363] [client 128.90.161.20:33938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.161.90.128.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoconfig.needhealthinsuranceuk.com"] [uri "/wp-login.php"] [unique_id "apPmAn3lhEjKFiK_nBKFSwAAAf0"]
[Sun Aug 30 03:12:50.679963 2026] [security2:error] [pid 524122:tid 524311] [client 20.48.160.90:23689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/filefuns.php"] [unique_id "apPmAn3lhEjKFiK_nBKFTAAAAck"]
[Sun Aug 30 03:12:50.704622 2026] [security2:error] [pid 524122:tid 524330] [client 20.104.50.220:41991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/batm.php"] [unique_id "apPmAn3lhEjKFiK_nBKFTQAAAdw"]
[Sun Aug 30 03:12:50.714602 2026] [security2:error] [pid 521505:tid 521676] [client 20.151.200.44:46002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/cy.php"] [unique_id "apPmAm8byYE0iXl--K6n2gAAA0c"]
[Sun Aug 30 03:12:50.720159 2026] [security2:error] [pid 524122:tid 524275] [client 4.205.62.107:16366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/mcebraed.php"] [unique_id "apPmAn3lhEjKFiK_nBKFTgAAAaU"]
[Sun Aug 30 03:12:50.727779 2026] [security2:error] [pid 524122:tid 524351] [client 20.104.50.220:33082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/byp.php"] [unique_id "apPmAn3lhEjKFiK_nBKFTwAAAfE"]
[Sun Aug 30 03:12:50.735614 2026] [authz_core:error] [pid 521505:tid 521746] [client 66.249.66.76:36131] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:50.736058 2026] [authz_core:error] [pid 521505:tid 521746] [client 66.249.66.76:36131] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:50.738950 2026] [security2:error] [pid 524122:tid 524274] [client 20.104.18.15:51198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/goods.php"] [unique_id "apPmAn3lhEjKFiK_nBKFUQAAAaQ"]
[Sun Aug 30 03:12:50.741860 2026] [security2:error] [pid 521505:tid 521755] [client 20.48.250.41:64804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/galer.php"] [unique_id "apPmAm8byYE0iXl--K6n3AAAA5Y"]
[Sun Aug 30 03:12:50.754946 2026] [security2:error] [pid 521505:tid 521647] [client 20.104.50.220:25284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/100.php"] [unique_id "apPmAm8byYE0iXl--K6n3QAAAyo"]
[Sun Aug 30 03:12:50.786948 2026] [security2:error] [pid 524122:tid 524307] [client 4.205.62.107:16341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/groceries/index.php"] [unique_id "apPmAn3lhEjKFiK_nBKFUgAAAcU"]
[Sun Aug 30 03:12:50.787867 2026] [security2:error] [pid 524122:tid 524317] [client 52.139.37.240:46941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/gmo.php"] [unique_id "apPmAn3lhEjKFiK_nBKFUwAAAc8"]
[Sun Aug 30 03:12:50.799492 2026] [security2:error] [pid 521505:tid 521693] [client 158.23.147.79:59013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/chosen.php"] [unique_id "apPmAm8byYE0iXl--K6n3wAAA1g"]
[Sun Aug 30 03:12:50.833402 2026] [authz_core:error] [pid 521505:tid 521683] [client 216.73.216.128:44329] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:50.833727 2026] [authz_core:error] [pid 521505:tid 521683] [client 216.73.216.128:44329] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:50.838551 2026] [security2:error] [pid 521505:tid 521752] [client 20.104.50.220:52849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/upppp.php"] [unique_id "apPmAm8byYE0iXl--K6n4QAAA5M"]
[Sun Aug 30 03:12:50.851766 2026] [security2:error] [pid 524122:tid 524263] [client 20.104.49.130:57483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alarm-monitoring.net"] [uri "/ano.php"] [unique_id "apPmAn3lhEjKFiK_nBKFVAAAAZk"]
[Sun Aug 30 03:12:50.883017 2026] [security2:error] [pid 521505:tid 521636] [client 20.48.250.41:64786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/baixy.php"] [unique_id "apPmAm8byYE0iXl--K6n4gAAAx8"]
[Sun Aug 30 03:12:50.892059 2026] [security2:error] [pid 521505:tid 521722] [client 20.48.251.3:64288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/phpversion.php"] [unique_id "apPmAm8byYE0iXl--K6n5gAAA3U"]
[Sun Aug 30 03:12:50.941793 2026] [security2:error] [pid 521505:tid 521671] [client 20.151.200.44:55629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.americanqualityhomeinspections.com"] [uri "/4e.php"] [unique_id "apPmAm8byYE0iXl--K6n6QAAA0I"]
[Sun Aug 30 03:12:50.961829 2026] [security2:error] [pid 521505:tid 521725] [client 20.104.50.220:30922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-content/index.php"] [unique_id "apPmAm8byYE0iXl--K6n7AAAA3g"]
[Sun Aug 30 03:12:50.969092 2026] [authz_core:error] [pid 521505:tid 521653] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory31
[Sun Aug 30 03:12:50.969436 2026] [authz_core:error] [pid 521505:tid 521653] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory31
[Sun Aug 30 03:12:50.987330 2026] [security2:error] [pid 521505:tid 521691] [client 52.139.37.240:46967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/c.php"] [unique_id "apPmAm8byYE0iXl--K6n7QAAA1Y"]
[Sun Aug 30 03:12:51.020354 2026] [security2:error] [pid 521505:tid 521727] [client 20.104.50.220:61397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/aj.php"] [unique_id "apPmA28byYE0iXl--K6n7gAAA3o"]
[Sun Aug 30 03:12:51.025997 2026] [security2:error] [pid 524122:tid 524261] [client 20.104.49.130:52445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/v2.php"] [unique_id "apPmA33lhEjKFiK_nBKFVgAAAZc"]
[Sun Aug 30 03:12:51.028369 2026] [security2:error] [pid 521505:tid 521650] [client 20.48.251.3:36893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/test.config.php"] [unique_id "apPmA28byYE0iXl--K6n8QAAAy0"]
[Sun Aug 30 03:12:51.029187 2026] [authz_core:error] [pid 524122:tid 524380] [client 216.73.216.128:34238] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:51.029475 2026] [authz_core:error] [pid 524122:tid 524380] [client 216.73.216.128:34238] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:51.031974 2026] [security2:error] [pid 521505:tid 521669] [client 20.48.250.41:62386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/ava.php"] [unique_id "apPmA28byYE0iXl--K6n8gAAA0A"]
[Sun Aug 30 03:12:51.055166 2026] [authz_core:error] [pid 521505:tid 521689] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:51.055590 2026] [authz_core:error] [pid 521505:tid 521689] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:51.119962 2026] [authz_core:error] [pid 521505:tid 521707] [client 216.73.216.128:44329] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:51.120327 2026] [authz_core:error] [pid 521505:tid 521707] [client 216.73.216.128:44329] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:51.140078 2026] [authz_core:error] [pid 521505:tid 521710] [client 66.249.66.71:55938] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:51.140376 2026] [authz_core:error] [pid 521505:tid 521710] [client 66.249.66.71:55938] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:51.145926 2026] [security2:error] [pid 521505:tid 521635] [client 158.23.147.79:59047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/goods.php"] [unique_id "apPmA28byYE0iXl--K6n-AAAAx4"]
[Sun Aug 30 03:12:51.168950 2026] [security2:error] [pid 521505:tid 521738] [client 20.151.200.44:61624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/png.php"] [unique_id "apPmA28byYE0iXl--K6n-gAAA4U"]
[Sun Aug 30 03:12:51.170509 2026] [security2:error] [pid 521505:tid 521762] [client 20.48.250.41:64845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/gdn.php"] [unique_id "apPmA28byYE0iXl--K6n-wAAA50"]
[Sun Aug 30 03:12:51.188286 2026] [security2:error] [pid 521505:tid 521745] [client 4.205.62.107:25780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.giuntiabbigliamento.it"] [uri "/wp-act.php"] [unique_id "apPmA28byYE0iXl--K6n_gAAA4w"]
[Sun Aug 30 03:12:51.220921 2026] [security2:error] [pid 521505:tid 521677] [client 52.139.37.240:50331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-file.php"] [unique_id "apPmA28byYE0iXl--K6oAAAAA0g"]
[Sun Aug 30 03:12:51.246476 2026] [security2:error] [pid 521505:tid 521648] [client 20.151.200.44:46064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/admin.php/pindex.php"] [unique_id "apPmA28byYE0iXl--K6oAQAAAys"]
[Sun Aug 30 03:12:51.247445 2026] [security2:error] [pid 524122:tid 524365] [client 20.48.251.3:52261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/test1.php"] [unique_id "apPmA33lhEjKFiK_nBKFVwAAAf8"]
[Sun Aug 30 03:12:51.255497 2026] [authz_core:error] [pid 521505:tid 521642] [client 66.249.66.37:50316] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:51.255790 2026] [authz_core:error] [pid 521505:tid 521642] [client 66.249.66.37:50316] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:51.293454 2026] [security2:error] [pid 524122:tid 524332] [client 216.73.216.128:34238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts2/tweakftp"] [unique_id "apPmA33lhEjKFiK_nBKFWQAAAd4"]
[Sun Aug 30 03:12:51.307138 2026] [security2:error] [pid 521505:tid 521637] [client 20.48.250.41:62449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/f2.php"] [unique_id "apPmA28byYE0iXl--K6oBQAAAyA"]
[Sun Aug 30 03:12:51.356564 2026] [security2:error] [pid 521505:tid 521679] [client 20.197.61.180:1629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/default.php"] [unique_id "apPmA28byYE0iXl--K6oCAAAA0o"]
[Sun Aug 30 03:12:51.416191 2026] [security2:error] [pid 521505:tid 521641] [client 158.23.147.79:59026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apPmA28byYE0iXl--K6oCwAAAyQ"]
[Sun Aug 30 03:12:51.444690 2026] [security2:error] [pid 521505:tid 521644] [client 52.139.37.240:46938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/post.php"] [unique_id "apPmA28byYE0iXl--K6oDAAAAyc"]
[Sun Aug 30 03:12:51.448386 2026] [security2:error] [pid 521505:tid 521704] [client 20.48.250.41:64772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/grsiuk.php"] [unique_id "apPmA28byYE0iXl--K6oDQAAA2M"]
[Sun Aug 30 03:12:51.454940 2026] [security2:error] [pid 524122:tid 524371] [client 20.104.50.220:6108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/34.php"] [unique_id "apPmA33lhEjKFiK_nBKFWwAAAgU"]
[Sun Aug 30 03:12:51.458156 2026] [security2:error] [pid 524122:tid 524376] [client 20.104.50.220:17327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/digiwoll.php"] [unique_id "apPmA33lhEjKFiK_nBKFXAAAAgo"]
[Sun Aug 30 03:12:51.483748 2026] [authz_core:error] [pid 521505:tid 521658] [client 216.73.216.128:29934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:51.484190 2026] [authz_core:error] [pid 521505:tid 521658] [client 216.73.216.128:29934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:51.505536 2026] [authz_core:error] [pid 521505:tid 521749] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory14
[Sun Aug 30 03:12:51.505951 2026] [authz_core:error] [pid 521505:tid 521749] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory14
[Sun Aug 30 03:12:51.553540 2026] [authz_core:error] [pid 521505:tid 521754] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:51.553940 2026] [authz_core:error] [pid 521505:tid 521754] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:51.562662 2026] [security2:error] [pid 524122:tid 524282] [client 4.205.62.107:17323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/bigdump.php"] [unique_id "apPmA33lhEjKFiK_nBKFXQAAAaw"]
[Sun Aug 30 03:12:51.580252 2026] [security2:error] [pid 521505:tid 521699] [client 20.48.250.41:62455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/wp-scr1pts.php"] [unique_id "apPmA28byYE0iXl--K6oFAAAA14"]
[Sun Aug 30 03:12:51.618482 2026] [security2:error] [pid 521505:tid 521563] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/.git/config.bak"] [unique_id "apPmA28byYE0iXl--K6oGwADWzk"]
[Sun Aug 30 03:12:51.621367 2026] [security2:error] [pid 521505:tid 521601] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/.git/config.old"] [unique_id "apPmA28byYE0iXl--K6oHAADf18"]
[Sun Aug 30 03:12:51.626378 2026] [security2:error] [pid 521505:tid 521529] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/.git/config~"] [unique_id "apPmA28byYE0iXl--K6oHQADaxc"]
[Sun Aug 30 03:12:51.637702 2026] [security2:error] [pid 521505:tid 521676] [client 158.23.147.79:55371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apPmA28byYE0iXl--K6oIgAAA0c"]
[Sun Aug 30 03:12:51.639953 2026] [security2:error] [pid 521505:tid 521755] [client 68.155.159.216:60987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apPmA28byYE0iXl--K6oJAAAA5Y"]
[Sun Aug 30 03:12:51.641675 2026] [security2:error] [pid 521505:tid 521647] [client 20.104.18.15:22437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/blacks.php"] [unique_id "apPmA28byYE0iXl--K6oJQAAAyo"]
[Sun Aug 30 03:12:51.658560 2026] [security2:error] [pid 521505:tid 521694] [client 216.73.216.128:44329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/collection.html"] [unique_id "apPmA28byYE0iXl--K6oJgAAA1k"]
[Sun Aug 30 03:12:51.660851 2026] [security2:error] [pid 524122:tid 524310] [client 52.139.37.240:50328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/aa.php"] [unique_id "apPmA33lhEjKFiK_nBKFXgAAAcg"]
[Sun Aug 30 03:12:51.673171 2026] [security2:error] [pid 521505:tid 521693] [client 20.104.18.15:2030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/wp-content/l.php"] [unique_id "apPmA28byYE0iXl--K6oKAAAA1g"]
[Sun Aug 30 03:12:51.686134 2026] [security2:error] [pid 521505:tid 521721] [client 20.48.160.90:29164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/aaa.php"] [unique_id "apPmA28byYE0iXl--K6oKwAAA3Q"]
[Sun Aug 30 03:12:51.692159 2026] [security2:error] [pid 524122:tid 524342] [client 4.205.62.107:29141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/wp-admin/css/bolt.php"] [unique_id "apPmA33lhEjKFiK_nBKFXwAAAeg"]
[Sun Aug 30 03:12:51.709396 2026] [security2:error] [pid 521505:tid 521741] [client 20.151.200.44:52082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/css/000.php"] [unique_id "apPmA28byYE0iXl--K6oLAAAA4g"]
[Sun Aug 30 03:12:51.711289 2026] [security2:error] [pid 521505:tid 521674] [client 20.48.250.41:62460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/num.php"] [unique_id "apPmA28byYE0iXl--K6oLQAAA0U"]
[Sun Aug 30 03:12:51.724948 2026] [security2:error] [pid 524122:tid 524267] [client 4.205.62.107:32014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPmA33lhEjKFiK_nBKFYAAAAZ0"]
[Sun Aug 30 03:12:51.726149 2026] [security2:error] [pid 524122:tid 524316] [client 20.151.200.44:63635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/txets.php"] [unique_id "apPmA33lhEjKFiK_nBKFYQAAAc4"]
[Sun Aug 30 03:12:51.752747 2026] [security2:error] [pid 521505:tid 521665] [client 20.151.200.44:46051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/admin.php/csv.php"] [unique_id "apPmA28byYE0iXl--K6oLwAAAzw"]
[Sun Aug 30 03:12:51.781519 2026] [security2:error] [pid 524122:tid 524298] [client 20.104.50.220:62831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/index4.php"] [unique_id "apPmA33lhEjKFiK_nBKFYwAAAbw"]
[Sun Aug 30 03:12:51.813736 2026] [security2:error] [pid 524122:tid 524281] [client 20.48.160.90:50428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp-cron.php"] [unique_id "apPmA33lhEjKFiK_nBKFZAAAAas"]
[Sun Aug 30 03:12:51.840217 2026] [security2:error] [pid 524122:tid 524258] [client 20.48.250.41:62337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/a4.php"] [unique_id "apPmA33lhEjKFiK_nBKFZQAAAZQ"]
[Sun Aug 30 03:12:51.856787 2026] [security2:error] [pid 521505:tid 521662] [client 4.205.62.107:15495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/server-info.php"] [unique_id "apPmA28byYE0iXl--K6oOQAAAzk"]
[Sun Aug 30 03:12:51.858702 2026] [security2:error] [pid 521505:tid 521681] [client 20.104.50.220:41987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/bj.php"] [unique_id "apPmA28byYE0iXl--K6oOgAAA0w"]
[Sun Aug 30 03:12:51.867158 2026] [authz_core:error] [pid 521505:tid 521711] [client 66.249.66.203:53600] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:51.867395 2026] [security2:error] [pid 521505:tid 521655] [client 20.104.50.220:33024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/con.php"] [unique_id "apPmA28byYE0iXl--K6oPAAAAzI"]
[Sun Aug 30 03:12:51.867429 2026] [authz_core:error] [pid 521505:tid 521711] [client 66.249.66.203:53600] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:51.869779 2026] [security2:error] [pid 521505:tid 521683] [client 52.139.37.240:46940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/x.php"] [unique_id "apPmA28byYE0iXl--K6oPQAAA04"]
[Sun Aug 30 03:12:51.887863 2026] [security2:error] [pid 521505:tid 521743] [client 20.104.18.15:51155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/ah.php"] [unique_id "apPmA28byYE0iXl--K6oQAAAA4o"]
[Sun Aug 30 03:12:51.887941 2026] [security2:error] [pid 524122:tid 524343] [client 158.23.147.79:59018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/file.php"] [unique_id "apPmA33lhEjKFiK_nBKFZgAAAek"]
[Sun Aug 30 03:12:51.907610 2026] [security2:error] [pid 521505:tid 521714] [client 20.104.50.220:25461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/about.php"] [unique_id "apPmA28byYE0iXl--K6oQwAAA20"]
[Sun Aug 30 03:12:51.914075 2026] [security2:error] [pid 521505:tid 521653] [client 20.151.200.44:55729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.americanqualityhomeinspections.com"] [uri "/ssss.php"] [unique_id "apPmA28byYE0iXl--K6oRQAAAzA"]
[Sun Aug 30 03:12:51.920636 2026] [security2:error] [pid 524122:tid 524318] [client 4.205.62.107:15836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/konfig.php"] [unique_id "apPmA33lhEjKFiK_nBKFZwAAAdA"]
[Sun Aug 30 03:12:51.944658 2026] [security2:error] [pid 524122:tid 524321] [client 20.48.160.90:23776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/lock360.php"] [unique_id "apPmA33lhEjKFiK_nBKFaAAAAdM"]
[Sun Aug 30 03:12:51.984258 2026] [authz_core:error] [pid 521505:tid 521723] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory19
[Sun Aug 30 03:12:51.984607 2026] [authz_core:error] [pid 521505:tid 521723] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory19
[Sun Aug 30 03:12:51.988138 2026] [security2:error] [pid 524122:tid 524335] [client 20.48.250.41:64893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/tfm.php"] [unique_id "apPmA33lhEjKFiK_nBKFaQAAAeE"]
[Sun Aug 30 03:12:52.036793 2026] [security2:error] [pid 521505:tid 521733] [client 20.48.251.3:54759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/adminfus.php"] [unique_id "apPmBG8byYE0iXl--K6oTAAAA4A"]
[Sun Aug 30 03:12:52.052664 2026] [authz_core:error] [pid 521505:tid 521670] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:52.053086 2026] [authz_core:error] [pid 521505:tid 521670] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:52.060171 2026] [security2:error] [pid 521505:tid 521713] [client 20.151.200.44:63589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/wp-login.php"] [unique_id "apPmBG8byYE0iXl--K6oUQAAA2w"]
[Sun Aug 30 03:12:52.068626 2026] [security2:error] [pid 524122:tid 524293] [client 52.139.37.240:46930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/item.php"] [unique_id "apPmBH3lhEjKFiK_nBKFagAAAbc"]
[Sun Aug 30 03:12:52.080319 2026] [security2:error] [pid 521505:tid 521659] [client 20.48.160.90:23791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp-theme.php"] [unique_id "apPmBG8byYE0iXl--K6oUgAAAzY"]
[Sun Aug 30 03:12:52.085078 2026] [security2:error] [pid 521505:tid 521637] [client 20.48.160.90:23730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/shiny.php"] [unique_id "apPmBG8byYE0iXl--K6oUwAAAyA"]
[Sun Aug 30 03:12:52.106955 2026] [security2:error] [pid 524122:tid 524327] [client 20.104.50.220:29570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/up.php"] [unique_id "apPmBH3lhEjKFiK_nBKFawAAAdk"]
[Sun Aug 30 03:12:52.126950 2026] [security2:error] [pid 521505:tid 521715] [client 20.48.250.41:62399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/Geforce.php"] [unique_id "apPmBG8byYE0iXl--K6oVwAAA24"]
[Sun Aug 30 03:12:52.130998 2026] [security2:error] [pid 521505:tid 521666] [client 20.104.50.220:59339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/admin.php"] [unique_id "apPmBG8byYE0iXl--K6oWAAAAz0"]
[Sun Aug 30 03:12:52.131550 2026] [security2:error] [pid 521505:tid 521761] [client 20.197.61.180:8997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/cloud.php"] [unique_id "apPmBG8byYE0iXl--K6oWQAAA5w"]
[Sun Aug 30 03:12:52.171840 2026] [security2:error] [pid 521505:tid 521736] [client 20.48.251.3:37027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/gecko-litespeed.php"] [unique_id "apPmBG8byYE0iXl--K6oWgAAA4M"]
[Sun Aug 30 03:12:52.183712 2026] [security2:error] [pid 521505:tid 521744] [client 20.104.50.220:61669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/opts.php"] [unique_id "apPmBG8byYE0iXl--K6oWwAAA4s"]
[Sun Aug 30 03:12:52.214873 2026] [security2:error] [pid 524122:tid 524279] [client 20.48.160.90:28752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/2d7433/index.php"] [unique_id "apPmBH3lhEjKFiK_nBKFbAAAAak"]
[Sun Aug 30 03:12:52.216169 2026] [security2:error] [pid 524122:tid 524360] [client 20.48.160.90:23731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/goods.php"] [unique_id "apPmBH3lhEjKFiK_nBKFbQAAAfo"]
[Sun Aug 30 03:12:52.237173 2026] [security2:error] [pid 521505:tid 521639] [client 158.23.147.79:59034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/file17.php"] [unique_id "apPmBG8byYE0iXl--K6oXwAAAyI"]
[Sun Aug 30 03:12:52.256638 2026] [security2:error] [pid 521505:tid 521702] [client 20.48.250.41:64861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/click.php"] [unique_id "apPmBG8byYE0iXl--K6oYgAAA2E"]
[Sun Aug 30 03:12:52.269851 2026] [security2:error] [pid 521505:tid 521697] [client 52.139.37.240:46947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/k.php"] [unique_id "apPmBG8byYE0iXl--K6oYwAAA1w"]
[Sun Aug 30 03:12:52.298873 2026] [security2:error] [pid 521505:tid 521729] [client 20.151.200.44:62940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/wp-access.php"] [unique_id "apPmBG8byYE0iXl--K6oZAAAA3w"]
[Sun Aug 30 03:12:52.352089 2026] [security2:error] [pid 524122:tid 524280] [client 20.48.160.90:28742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/000.php/index.php"] [unique_id "apPmBH3lhEjKFiK_nBKFbgAAAao"]
[Sun Aug 30 03:12:52.383695 2026] [security2:error] [pid 521505:tid 521718] [client 20.48.250.41:62447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/ms.php"] [unique_id "apPmBG8byYE0iXl--K6oagAAA3E"]
[Sun Aug 30 03:12:52.407621 2026] [security2:error] [pid 521505:tid 521645] [client 20.151.200.44:55686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.americanqualityhomeinspections.com"] [uri "/zoz.php"] [unique_id "apPmBG8byYE0iXl--K6obwAAAyg"]
[Sun Aug 30 03:12:52.408793 2026] [autoindex:error] [pid 521505:tid 521612] [remote 206.206.69.183:49109] AH01276: Cannot serve directory /home2/homaalec/cagtunepal.com/careers/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:12:52.448219 2026] [security2:error] [pid 521505:tid 521724] [client 20.48.251.3:40003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/bigdump.php"] [unique_id "apPmBG8byYE0iXl--K6ocQAAA3c"]
[Sun Aug 30 03:12:52.461251 2026] [authz_core:error] [pid 521505:tid 521642] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory30
[Sun Aug 30 03:12:52.461500 2026] [authz_core:error] [pid 521505:tid 521642] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory30
[Sun Aug 30 03:12:52.473925 2026] [security2:error] [pid 521505:tid 521741] [client 52.139.37.240:46975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-fmfile.php"] [unique_id "apPmBG8byYE0iXl--K6oeAAAA4g"]
[Sun Aug 30 03:12:52.484215 2026] [security2:error] [pid 521505:tid 521663] [client 20.151.200.44:52145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/cy.php"] [unique_id "apPmBG8byYE0iXl--K6oeQAAAzo"]
[Sun Aug 30 03:12:52.520027 2026] [security2:error] [pid 521505:tid 521695] [client 158.23.147.79:55378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/file5.php"] [unique_id "apPmBG8byYE0iXl--K6oewAAA1o"]
[Sun Aug 30 03:12:52.528862 2026] [security2:error] [pid 524122:tid 524362] [client 20.48.250.41:64883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/zxekqlxb.php"] [unique_id "apPmBH3lhEjKFiK_nBKFcQAAAfw"]
[Sun Aug 30 03:12:52.541430 2026] [security2:error] [pid 521505:tid 521685] [client 195.178.110.247:48894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mta-sts.brownpuppy.net"] [uri "/index.php"] [unique_id "apPmBG8byYE0iXl--K6ofAAAA1A"]
[Sun Aug 30 03:12:52.558850 2026] [authz_core:error] [pid 521505:tid 521727] [client 66.249.66.43:52021] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:52.559270 2026] [authz_core:error] [pid 521505:tid 521727] [client 66.249.66.43:52021] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:52.589721 2026] [authz_core:error] [pid 521505:tid 521688] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:52.590164 2026] [authz_core:error] [pid 521505:tid 521688] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:52.596180 2026] [security2:error] [pid 521505:tid 521683] [client 20.104.50.220:5891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/33.php"] [unique_id "apPmBG8byYE0iXl--K6oggAAA04"]
[Sun Aug 30 03:12:52.597856 2026] [security2:error] [pid 524122:tid 524270] [client 20.104.50.220:16731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/tinyfilemanager.php"] [unique_id "apPmBH3lhEjKFiK_nBKFcgAAAaA"]
[Sun Aug 30 03:12:52.660719 2026] [security2:error] [pid 521505:tid 521738] [client 20.48.250.41:64838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/init.php"] [unique_id "apPmBG8byYE0iXl--K6ohwAAA4U"]
[Sun Aug 30 03:12:52.681493 2026] [security2:error] [pid 521505:tid 521745] [client 158.23.147.79:59044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/file88.php"] [unique_id "apPmBG8byYE0iXl--K6oiQAAA4w"]
[Sun Aug 30 03:12:52.681912 2026] [security2:error] [pid 521505:tid 521756] [client 20.151.200.44:63570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/wp-content/admin.php"] [unique_id "apPmBG8byYE0iXl--K6oigAAA5c"]
[Sun Aug 30 03:12:52.699198 2026] [security2:error] [pid 521505:tid 521747] [client 4.205.62.107:17225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/wdf.php"] [unique_id "apPmBG8byYE0iXl--K6ojAAAA44"]
[Sun Aug 30 03:12:52.707482 2026] [security2:error] [pid 524122:tid 524355] [client 195.178.110.247:7172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.110.178.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mta-sts.brownpuppy.net"] [uri "/index.php"] [unique_id "apPmBH3lhEjKFiK_nBKFcwAAAfU"]
[Sun Aug 30 03:12:52.717992 2026] [security2:error] [pid 524122:tid 524289] [client 52.139.37.240:46946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/404.php"] [unique_id "apPmBH3lhEjKFiK_nBKFdAAAAbM"]
[Sun Aug 30 03:12:52.743348 2026] [security2:error] [pid 521505:tid 521751] [client 20.151.200.44:55737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.americanqualityhomeinspections.com"] [uri "/kcs.php"] [unique_id "apPmBG8byYE0iXl--K6ojgAAA5I"]
[Sun Aug 30 03:12:52.754660 2026] [security2:error] [pid 521505:tid 521728] [client 20.104.49.130:53535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/ohct.php"] [unique_id "apPmBG8byYE0iXl--K6okQAAA3s"]
[Sun Aug 30 03:12:52.771951 2026] [security2:error] [pid 521505:tid 521666] [client 68.155.159.216:60297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apPmBG8byYE0iXl--K6olQAAAz0"]
[Sun Aug 30 03:12:52.776892 2026] [security2:error] [pid 521505:tid 521644] [client 158.23.147.79:59071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/NewFile.php/"] [unique_id "apPmBG8byYE0iXl--K6olwAAAyc"]
[Sun Aug 30 03:12:52.791360 2026] [security2:error] [pid 524122:tid 524315] [client 20.104.18.15:22482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/wp.php"] [unique_id "apPmBH3lhEjKFiK_nBKFdgAAAc0"]
[Sun Aug 30 03:12:52.814767 2026] [security2:error] [pid 521505:tid 521736] [client 20.104.18.15:1927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/wp-admin/w.php"] [unique_id "apPmBG8byYE0iXl--K6omwAAA4M"]
[Sun Aug 30 03:12:52.825975 2026] [security2:error] [pid 521505:tid 521660] [client 20.48.250.41:62444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/term.php"] [unique_id "apPmBG8byYE0iXl--K6onQAAAzc"]
[Sun Aug 30 03:12:52.881536 2026] [security2:error] [pid 521505:tid 521743] [client 20.197.61.180:1627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/admin.php"] [unique_id "apPmBG8byYE0iXl--K6oogAAA4o"]
[Sun Aug 30 03:12:52.898478 2026] [security2:error] [pid 521505:tid 521697] [client 158.23.147.79:59033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/dropdown.php"] [unique_id "apPmBG8byYE0iXl--K6opAAAA1w"]
[Sun Aug 30 03:12:52.911460 2026] [security2:error] [pid 521505:tid 521639] [client 52.139.37.240:49692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wi.php"] [unique_id "apPmBG8byYE0iXl--K6opgAAAyI"]
[Sun Aug 30 03:12:52.913411 2026] [security2:error] [pid 521505:tid 521750] [client 20.151.200.44:46073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/admin.php/700.php"] [unique_id "apPmBG8byYE0iXl--K6opwAAA5E"]
[Sun Aug 30 03:12:52.948722 2026] [security2:error] [pid 521505:tid 521692] [client 4.205.62.107:32006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/cloud.php"] [unique_id "apPmBG8byYE0iXl--K6orQAAA1c"]
[Sun Aug 30 03:12:52.952176 2026] [autoindex:error] [pid 521505:tid 521547] [remote 93.123.109.228:45324] AH01276: Cannot serve directory /home3/jvallesteros/jeanbooknerdstorytellersbox.com/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:12:52.969598 2026] [security2:error] [pid 524122:tid 524374] [client 4.205.62.107:52849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/myfile.php"] [unique_id "apPmBH3lhEjKFiK_nBKFeAAAAgg"]
[Sun Aug 30 03:12:52.972200 2026] [security2:error] [pid 521505:tid 521705] [client 20.48.250.41:64846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/aaa.php"] [unique_id "apPmBG8byYE0iXl--K6orwAAA2Q"]
[Sun Aug 30 03:12:52.979929 2026] [security2:error] [pid 521505:tid 521696] [client 20.104.50.220:29158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/index5.php"] [unique_id "apPmBG8byYE0iXl--K6osAAAA1s"]
[Sun Aug 30 03:12:52.991615 2026] [security2:error] [pid 521505:tid 521732] [client 20.104.50.220:42243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/black.php"] [unique_id "apPmBG8byYE0iXl--K6osQAAA38"]
[Sun Aug 30 03:12:52.991823 2026] [security2:error] [pid 524122:tid 524292] [client 4.205.62.107:15996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/gk.php"] [unique_id "apPmBH3lhEjKFiK_nBKFeQAAAbY"]
[Sun Aug 30 03:12:53.020533 2026] [security2:error] [pid 521505:tid 521739] [client 158.23.147.79:59041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/.well-known/index.php"] [unique_id "apPmBW8byYE0iXl--K6oswAAA4Y"]
[Sun Aug 30 03:12:53.023374 2026] [security2:error] [pid 521505:tid 521686] [client 20.104.50.220:33188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/con7ext.php"] [unique_id "apPmBW8byYE0iXl--K6otQAAA1E"]
[Sun Aug 30 03:12:53.030019 2026] [authz_core:error] [pid 521505:tid 521658] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:53.030297 2026] [authz_core:error] [pid 521505:tid 521658] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:53.032556 2026] [security2:error] [pid 521505:tid 521731] [client 20.104.18.15:51138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/ws55.php"] [unique_id "apPmBW8byYE0iXl--K6ouAAAA34"]
[Sun Aug 30 03:12:53.037360 2026] [authz_core:error] [pid 521505:tid 521693] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory17
[Sun Aug 30 03:12:53.037633 2026] [authz_core:error] [pid 521505:tid 521693] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory17
[Sun Aug 30 03:12:53.040685 2026] [security2:error] [pid 521505:tid 521579] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/ADMIN/.env"] [unique_id "apPmBW8byYE0iXl--K6ouQADcUk"]
[Sun Aug 30 03:12:53.058570 2026] [security2:error] [pid 521505:tid 521719] [client 4.205.62.107:16326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/paths.php"] [unique_id "apPmBW8byYE0iXl--K6ovgAAA3I"]
[Sun Aug 30 03:12:53.071410 2026] [security2:error] [pid 521505:tid 521673] [client 20.104.50.220:24909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/admin.php"] [unique_id "apPmBW8byYE0iXl--K6ovwAAA0Q"]
[Sun Aug 30 03:12:53.074611 2026] [security2:error] [pid 521505:tid 521520] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/API/.env"] [unique_id "apPmBW8byYE0iXl--K6owQADOw4"]
[Sun Aug 30 03:12:53.104404 2026] [security2:error] [pid 521505:tid 521691] [client 20.48.250.41:62362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/xsox.php"] [unique_id "apPmBW8byYE0iXl--K6oxAAAA1Y"]
[Sun Aug 30 03:12:53.112451 2026] [security2:error] [pid 524122:tid 524181] [remote 93.123.109.228:45152] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdmedia.com"] [uri "/.docker/laravel/app/.env"] [unique_id "apPmA33lhEjKFiK_nBKFewAB3zk"]
[Sun Aug 30 03:12:53.115302 2026] [security2:error] [pid 524122:tid 524336] [client 52.139.37.240:49709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/php8.php"] [unique_id "apPmBX3lhEjKFiK_nBKFfgAAAeI"]
[Sun Aug 30 03:12:53.124189 2026] [authz_core:error] [pid 521505:tid 521676] [client 216.73.216.128:29934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:53.124456 2026] [authz_core:error] [pid 521505:tid 521676] [client 216.73.216.128:29934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:53.150012 2026] [security2:error] [pid 521505:tid 521735] [client 158.23.147.79:55385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-content/themes/too.php"] [unique_id "apPmBW8byYE0iXl--K6oxwAAA4I"]
[Sun Aug 30 03:12:53.183522 2026] [security2:error] [pid 521505:tid 521720] [client 20.48.251.3:64302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/avim.php"] [unique_id "apPmBW8byYE0iXl--K6oyQAAA3M"]
[Sun Aug 30 03:12:53.184853 2026] [authz_core:error] [pid 521505:tid 521640] [client 66.249.66.78:62112] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:53.185307 2026] [authz_core:error] [pid 521505:tid 521640] [client 66.249.66.78:62112] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:53.229692 2026] [security2:error] [pid 521505:tid 521657] [client 20.104.49.130:39051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/xwpg.php"] [unique_id "apPmBW8byYE0iXl--K6ozwAAAzQ"]
[Sun Aug 30 03:12:53.236001 2026] [security2:error] [pid 521505:tid 521553] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/Api/.env"] [unique_id "apPmBW8byYE0iXl--K6o0AADbS8"]
[Sun Aug 30 03:12:53.239101 2026] [security2:error] [pid 521505:tid 521677] [client 20.48.250.41:64868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/lkui.php"] [unique_id "apPmBW8byYE0iXl--K6o0gAAA0g"]
[Sun Aug 30 03:12:53.253518 2026] [security2:error] [pid 521505:tid 521564] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/APP/.env"] [unique_id "apPmBW8byYE0iXl--K6o0wADKzo"]
[Sun Aug 30 03:12:53.267227 2026] [security2:error] [pid 521505:tid 521668] [client 158.23.147.79:55395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/radio.php"] [unique_id "apPmBW8byYE0iXl--K6o1AAAAz8"]
[Sun Aug 30 03:12:53.284441 2026] [security2:error] [pid 524122:tid 524277] [client 20.104.50.220:30918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-admin/maint/maint.php"] [unique_id "apPmBX3lhEjKFiK_nBKFgAAAAac"]
[Sun Aug 30 03:12:53.312103 2026] [security2:error] [pid 521505:tid 521669] [client 20.104.50.220:62819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/l3.php"] [unique_id "apPmBW8byYE0iXl--K6o1wAAA0A"]
[Sun Aug 30 03:12:53.329313 2026] [security2:error] [pid 521505:tid 521688] [client 52.139.37.240:49724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/admin.php"] [unique_id "apPmBW8byYE0iXl--K6o2AAAA1M"]
[Sun Aug 30 03:12:53.339649 2026] [security2:error] [pid 521505:tid 521680] [client 20.104.50.220:61382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/filer.php"] [unique_id "apPmBW8byYE0iXl--K6o2QAAA0s"]
[Sun Aug 30 03:12:53.354493 2026] [security2:error] [pid 521505:tid 521531] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/BACKEND/.env"] [unique_id "apPmBW8byYE0iXl--K6o2gADNhk"]
[Sun Aug 30 03:12:53.358315 2026] [security2:error] [pid 524122:tid 524320] [client 20.48.251.3:37132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/goods.php"] [unique_id "apPmBX3lhEjKFiK_nBKFggAAAdI"]
[Sun Aug 30 03:12:53.364526 2026] [security2:error] [pid 521505:tid 521637] [client 20.104.49.130:63505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/log.php"] [unique_id "apPmBW8byYE0iXl--K6o3AAAAyA"]
[Sun Aug 30 03:12:53.367512 2026] [security2:error] [pid 524122:tid 524341] [client 20.48.160.90:28789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp-login.php"] [unique_id "apPmBX3lhEjKFiK_nBKFgwAAAec"]
[Sun Aug 30 03:12:53.392539 2026] [security2:error] [pid 521505:tid 521717] [client 20.48.250.41:64820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apPmBW8byYE0iXl--K6o3gAAA3A"]
[Sun Aug 30 03:12:53.417941 2026] [security2:error] [pid 521505:tid 521627] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/BE/.env"] [unique_id "apPmBW8byYE0iXl--K6o4AADPXk"]
[Sun Aug 30 03:12:53.422469 2026] [authz_core:error] [pid 524122:tid 524326] [client 66.249.66.72:42424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:53.422751 2026] [authz_core:error] [pid 524122:tid 524326] [client 66.249.66.72:42424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:53.430081 2026] [security2:error] [pid 521505:tid 521517] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/Be/.env"] [unique_id "apPmBW8byYE0iXl--K6o4QADYws"]
[Sun Aug 30 03:12:53.487938 2026] [authz_core:error] [pid 524122:tid 524312] [client 66.249.66.78:56886] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:53.488205 2026] [authz_core:error] [pid 524122:tid 524312] [client 66.249.66.78:56886] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:53.492130 2026] [security2:error] [pid 521505:tid 521726] [client 20.48.160.90:50404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/Jcrop.php"] [unique_id "apPmBW8byYE0iXl--K6o4wAAA3k"]
[Sun Aug 30 03:12:53.497838 2026] [security2:error] [pid 524122:tid 524262] [client 158.23.147.79:59023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPmBX3lhEjKFiK_nBKFhgAAAZg"]
[Sun Aug 30 03:12:53.521155 2026] [authz_core:error] [pid 521505:tid 521687] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory10
[Sun Aug 30 03:12:53.521597 2026] [authz_core:error] [pid 521505:tid 521687] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory10
[Sun Aug 30 03:12:53.522710 2026] [security2:error] [pid 521505:tid 521660] [client 20.48.250.41:64768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/motu.php"] [unique_id "apPmBW8byYE0iXl--K6o5QAAAzc"]
[Sun Aug 30 03:12:53.527699 2026] [security2:error] [pid 521505:tid 521689] [client 20.48.160.90:49996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/images.php"] [unique_id "apPmBW8byYE0iXl--K6o5wAAA1Q"]
[Sun Aug 30 03:12:53.536052 2026] [authz_core:error] [pid 521505:tid 521651] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:53.536455 2026] [authz_core:error] [pid 521505:tid 521651] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:53.547195 2026] [security2:error] [pid 521505:tid 521670] [client 52.139.37.240:49701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/flower.php"] [unique_id "apPmBW8byYE0iXl--K6o6gAAA0E"]
[Sun Aug 30 03:12:53.606973 2026] [security2:error] [pid 524122:tid 524300] [client 20.197.61.180:11356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/index.php"] [unique_id "apPmBX3lhEjKFiK_nBKFhwAAAb4"]
[Sun Aug 30 03:12:53.607395 2026] [security2:error] [pid 521505:tid 521713] [client 20.48.251.3:40021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wdf.php"] [unique_id "apPmBW8byYE0iXl--K6o8QAAA2w"]
[Sun Aug 30 03:12:53.655988 2026] [security2:error] [pid 521505:tid 521692] [client 158.23.147.79:55385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/makeasmtp.php"] [unique_id "apPmBW8byYE0iXl--K6o8gAAA1c"]
[Sun Aug 30 03:12:53.659298 2026] [security2:error] [pid 521505:tid 521705] [client 20.48.250.41:64800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/Ov-Simple1.php"] [unique_id "apPmBW8byYE0iXl--K6o8wAAA2Q"]
[Sun Aug 30 03:12:53.663232 2026] [security2:error] [pid 521505:tid 521757] [client 20.48.160.90:50304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/35iDq8NAjLu.php"] [unique_id "apPmBW8byYE0iXl--K6o9AAAA5g"]
[Sun Aug 30 03:12:53.664681 2026] [security2:error] [pid 521505:tid 521711] [client 20.48.160.90:23795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/ops.php"] [unique_id "apPmBW8byYE0iXl--K6o9QAAA2o"]
[Sun Aug 30 03:12:53.723557 2026] [security2:error] [pid 521505:tid 521754] [client 20.151.200.44:55707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.americanqualityhomeinspections.com"] [uri "/tajj.php"] [unique_id "apPmBW8byYE0iXl--K6o-wAAA5U"]
[Sun Aug 30 03:12:53.736236 2026] [security2:error] [pid 521505:tid 521636] [client 20.104.50.220:17329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/.well-known/70.php"] [unique_id "apPmBW8byYE0iXl--K6o_AAAAx8"]
[Sun Aug 30 03:12:53.751421 2026] [security2:error] [pid 521505:tid 521742] [client 20.104.50.220:5920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/25.php"] [unique_id "apPmBW8byYE0iXl--K6o_QAAA4k"]
[Sun Aug 30 03:12:53.763399 2026] [security2:error] [pid 521505:tid 521721] [client 158.23.147.79:59028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apPmBW8byYE0iXl--K6pAAAAA3Q"]
[Sun Aug 30 03:12:53.776494 2026] [security2:error] [pid 521505:tid 521647] [client 52.139.37.240:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/buy.php"] [unique_id "apPmBW8byYE0iXl--K6pAwAAAyo"]
[Sun Aug 30 03:12:53.793069 2026] [security2:error] [pid 521505:tid 521690] [client 20.48.160.90:23771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "apPmBW8byYE0iXl--K6pBgAAA1U"]
[Sun Aug 30 03:12:53.793895 2026] [security2:error] [pid 521505:tid 521664] [client 20.48.160.90:49985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/btx25.php"] [unique_id "apPmBW8byYE0iXl--K6pBwAAAzs"]
[Sun Aug 30 03:12:53.842852 2026] [security2:error] [pid 521505:tid 521716] [client 4.205.62.107:17131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/bb.php"] [unique_id "apPmBW8byYE0iXl--K6pCwAAA28"]
[Sun Aug 30 03:12:53.868905 2026] [security2:error] [pid 521505:tid 521672] [client 20.48.250.41:62350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/wp-blogs.php"] [unique_id "apPmBW8byYE0iXl--K6pDgAAA0M"]
[Sun Aug 30 03:12:53.884652 2026] [security2:error] [pid 521505:tid 521683] [client 68.155.159.216:60950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/chosen.php"] [unique_id "apPmBW8byYE0iXl--K6pEAAAA04"]
[Sun Aug 30 03:12:53.913144 2026] [security2:error] [pid 521505:tid 521532] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/.wp-config.php.swp"] [unique_id "apPmBW8byYE0iXl--K6pEgADRRo"]
[Sun Aug 30 03:12:53.922184 2026] [security2:error] [pid 521505:tid 521635] [client 20.48.160.90:29154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/radio.php"] [unique_id "apPmBW8byYE0iXl--K6pFAAAAx4"]
[Sun Aug 30 03:12:53.922238 2026] [security2:error] [pid 521505:tid 521725] [client 20.48.160.90:50417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "apPmBW8byYE0iXl--K6pFQAAA3g"]
[Sun Aug 30 03:12:53.929356 2026] [security2:error] [pid 524122:tid 524330] [client 158.23.147.79:52679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apPmBX3lhEjKFiK_nBKFiwAAAdw"]
[Sun Aug 30 03:12:53.934584 2026] [security2:error] [pid 521505:tid 521762] [client 20.104.18.15:22502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/wander.php"] [unique_id "apPmBW8byYE0iXl--K6pFwAAA50"]
[Sun Aug 30 03:12:53.954187 2026] [security2:error] [pid 521505:tid 521677] [client 20.104.18.15:1860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/wp-content/k.php"] [unique_id "apPmBW8byYE0iXl--K6pGgAAA0g"]
[Sun Aug 30 03:12:53.983640 2026] [security2:error] [pid 521505:tid 521684] [client 20.104.49.130:54189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/sta.php"] [unique_id "apPmBW8byYE0iXl--K6pIgAAA08"]
[Sun Aug 30 03:12:53.987801 2026] [authz_core:error] [pid 521505:tid 521652] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory16
[Sun Aug 30 03:12:53.988084 2026] [authz_core:error] [pid 521505:tid 521652] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory16
[Sun Aug 30 03:12:54.024683 2026] [security2:error] [pid 521505:tid 521747] [client 52.139.37.240:46928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-includes/customize/about.php"] [unique_id "apPmBm8byYE0iXl--K6pJQAAA44"]
[Sun Aug 30 03:12:54.033738 2026] [security2:error] [pid 521505:tid 521724] [client 20.48.250.41:64850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/mini.php"] [unique_id "apPmBm8byYE0iXl--K6pJwAAA3c"]
[Sun Aug 30 03:12:54.043686 2026] [security2:error] [pid 521505:tid 521537] [remote 193.238.208.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.208.238.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circupulseblood.com"] [uri "/wp-login.php"] [unique_id "apPmBm8byYE0iXl--K6pJAADVh8"]
[Sun Aug 30 03:12:54.060265 2026] [security2:error] [pid 521505:tid 521659] [client 20.48.160.90:23790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/dex.php"] [unique_id "apPmBm8byYE0iXl--K6pKgAAAzY"]
[Sun Aug 30 03:12:54.060877 2026] [authz_core:error] [pid 521505:tid 521680] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:54.061328 2026] [authz_core:error] [pid 521505:tid 521680] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:54.073099 2026] [security2:error] [pid 521505:tid 521637] [client 20.48.160.90:29130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/about.php"] [unique_id "apPmBm8byYE0iXl--K6pKwAAAyA"]
[Sun Aug 30 03:12:54.088098 2026] [security2:error] [pid 521505:tid 521577] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/BACK/.env"] [unique_id "apPmBm8byYE0iXl--K6pLAADYkc"]
[Sun Aug 30 03:12:54.110288 2026] [security2:error] [pid 521505:tid 521644] [client 158.23.147.79:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-content/languages/about.php"] [unique_id "apPmBm8byYE0iXl--K6pLwAAAyc"]
[Sun Aug 30 03:12:54.113925 2026] [authz_core:error] [pid 521505:tid 521761] [client 66.249.66.76:36131] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:54.114389 2026] [authz_core:error] [pid 521505:tid 521761] [client 66.249.66.76:36131] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:54.126546 2026] [security2:error] [pid 521505:tid 521708] [client 4.205.62.107:32510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/kerang.php"] [unique_id "apPmBm8byYE0iXl--K6pMQAAA2c"]
[Sun Aug 30 03:12:54.131400 2026] [security2:error] [pid 524122:tid 524375] [client 20.151.200.44:52116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/admin.php/pindex.php"] [unique_id "apPmBn3lhEjKFiK_nBKFjgAAAgk"]
[Sun Aug 30 03:12:54.131791 2026] [security2:error] [pid 521505:tid 521726] [client 20.104.50.220:62824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/index6.php"] [unique_id "apPmBm8byYE0iXl--K6pMgAAA3k"]
[Sun Aug 30 03:12:54.132971 2026] [security2:error] [pid 521505:tid 521660] [client 4.205.62.107:15992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/god.php"] [unique_id "apPmBm8byYE0iXl--K6pMwAAAzc"]
[Sun Aug 30 03:12:54.134376 2026] [security2:error] [pid 524122:tid 524297] [client 20.104.50.220:41994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/by.php"] [unique_id "apPmBn3lhEjKFiK_nBKFjwAAAbs"]
[Sun Aug 30 03:12:54.148104 2026] [security2:error] [pid 521505:tid 521682] [client 20.104.49.130:48006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/wp-the.php"] [unique_id "apPmBm8byYE0iXl--K6pNwAAA00"]
[Sun Aug 30 03:12:54.173864 2026] [security2:error] [pid 521505:tid 521699] [client 20.104.18.15:51110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/drykl.php"] [unique_id "apPmBm8byYE0iXl--K6pOQAAA14"]
[Sun Aug 30 03:12:54.175669 2026] [security2:error] [pid 524122:tid 524346] [client 20.104.50.220:32875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/loader/ff.php"] [unique_id "apPmBn3lhEjKFiK_nBKFkAAAAew"]
[Sun Aug 30 03:12:54.183971 2026] [security2:error] [pid 524122:tid 524339] [client 20.48.250.41:64880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/amp.php"] [unique_id "apPmBn3lhEjKFiK_nBKFkQAAAeU"]
[Sun Aug 30 03:12:54.189263 2026] [security2:error] [pid 524122:tid 524317] [client 20.48.160.90:49922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/giodywky.php"] [unique_id "apPmBn3lhEjKFiK_nBKFkwAAAc8"]
[Sun Aug 30 03:12:54.192679 2026] [security2:error] [pid 524122:tid 524331] [client 20.151.200.44:23606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/log.php"] [unique_id "apPmBn3lhEjKFiK_nBKFlAAAAd0"]
[Sun Aug 30 03:12:54.195246 2026] [security2:error] [pid 521505:tid 521759] [client 4.205.62.107:15493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/olfclass.php"] [unique_id "apPmBm8byYE0iXl--K6pOwAAA5o"]
[Sun Aug 30 03:12:54.210361 2026] [security2:error] [pid 521505:tid 521711] [client 20.48.160.90:50385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/admin.php/admin.php"] [unique_id "apPmBm8byYE0iXl--K6pPAAAA2o"]
[Sun Aug 30 03:12:54.216152 2026] [security2:error] [pid 524122:tid 524324] [client 20.104.50.220:25462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/edit.php"] [unique_id "apPmBn3lhEjKFiK_nBKFlQAAAdY"]
[Sun Aug 30 03:12:54.226961 2026] [authz_core:error] [pid 521505:tid 521651] [client 216.73.216.128:29934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:54.227381 2026] [authz_core:error] [pid 521505:tid 521651] [client 216.73.216.128:29934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:54.244785 2026] [security2:error] [pid 521505:tid 521687] [client 4.205.62.107:52860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/lm15.php"] [unique_id "apPmBm8byYE0iXl--K6pPgAAA1I"]
[Sun Aug 30 03:12:54.274511 2026] [security2:error] [pid 521505:tid 521757] [client 52.139.37.240:9483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "apPmBm8byYE0iXl--K6pQAAAA5g"]
[Sun Aug 30 03:12:54.307250 2026] [security2:error] [pid 524122:tid 524261] [client 158.23.147.79:59068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-content/banners/about.php"] [unique_id "apPmBn3lhEjKFiK_nBKFlgAAAZc"]
[Sun Aug 30 03:12:54.318041 2026] [security2:error] [pid 524122:tid 524361] [client 20.197.61.180:8972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/php8.php"] [unique_id "apPmBn3lhEjKFiK_nBKFlwAAAfs"]
[Sun Aug 30 03:12:54.319588 2026] [security2:error] [pid 521505:tid 521640] [client 20.48.250.41:64826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/cc13.php"] [unique_id "apPmBm8byYE0iXl--K6pRAAAAyM"]
[Sun Aug 30 03:12:54.323371 2026] [security2:error] [pid 521505:tid 521742] [client 20.48.160.90:28736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp-kz.php"] [unique_id "apPmBm8byYE0iXl--K6pRQAAA4k"]
[Sun Aug 30 03:12:54.340314 2026] [security2:error] [pid 521505:tid 521721] [client 20.48.160.90:28774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/media.php"] [unique_id "apPmBm8byYE0iXl--K6pRwAAA3Q"]
[Sun Aug 30 03:12:54.340443 2026] [security2:error] [pid 521505:tid 521587] [remote 209.42.21.221:44054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.21.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "stressfreeaccounts.com"] [uri "/wp-login.php"] [unique_id "apPmBm8byYE0iXl--K6pRgADVFE"]
[Sun Aug 30 03:12:54.397010 2026] [security2:error] [pid 521505:tid 521722] [client 20.104.49.130:63499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/bdroot.php"] [unique_id "apPmBm8byYE0iXl--K6pSwAAA3U"]
[Sun Aug 30 03:12:54.397725 2026] [security2:error] [pid 521505:tid 521663] [client 20.48.251.3:64289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/nw.php"] [unique_id "apPmBm8byYE0iXl--K6pTQAAAzo"]
[Sun Aug 30 03:12:54.415361 2026] [security2:error] [pid 521505:tid 521632] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/Backend/.env"] [unique_id "apPmBm8byYE0iXl--K6pTgADUH4"]
[Sun Aug 30 03:12:54.436479 2026] [security2:error] [pid 521505:tid 521741] [client 20.104.50.220:31196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/classwithtostring.php"] [unique_id "apPmBm8byYE0iXl--K6pUQAAA4g"]
[Sun Aug 30 03:12:54.452823 2026] [security2:error] [pid 521505:tid 521658] [client 20.104.49.130:64758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/memberfuns.php"] [unique_id "apPmBm8byYE0iXl--K6pUgAAAzU"]
[Sun Aug 30 03:12:54.456130 2026] [security2:error] [pid 521505:tid 521672] [client 20.48.160.90:49958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp-includes/ID3/getid.php"] [unique_id "apPmBm8byYE0iXl--K6pUwAAA0M"]
[Sun Aug 30 03:12:54.466382 2026] [security2:error] [pid 521505:tid 521667] [client 20.104.50.220:62801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/fellganteng.php"] [unique_id "apPmBm8byYE0iXl--K6pVAAAAz4"]
[Sun Aug 30 03:12:54.471587 2026] [security2:error] [pid 521505:tid 521707] [client 20.48.160.90:50397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/mac.php"] [unique_id "apPmBm8byYE0iXl--K6pVQAAA2Y"]
[Sun Aug 30 03:12:54.476367 2026] [security2:error] [pid 521505:tid 521720] [client 20.48.250.41:64894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/aa.php"] [unique_id "apPmBm8byYE0iXl--K6pVgAAA3M"]
[Sun Aug 30 03:12:54.492142 2026] [security2:error] [pid 521505:tid 521635] [client 20.104.50.220:61378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/lites.php"] [unique_id "apPmBm8byYE0iXl--K6pWAAAAx4"]
[Sun Aug 30 03:12:54.497448 2026] [authz_core:error] [pid 521505:tid 521674] [client 216.73.216.128:29934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:54.497715 2026] [authz_core:error] [pid 521505:tid 521674] [client 216.73.216.128:29934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:54.516790 2026] [authz_core:error] [pid 521505:tid 521745] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory18
[Sun Aug 30 03:12:54.516923 2026] [security2:error] [pid 521505:tid 521653] [client 20.48.251.3:36820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/loxi-o.php"] [unique_id "apPmBm8byYE0iXl--K6pXQAAAzA"]
[Sun Aug 30 03:12:54.517048 2026] [authz_core:error] [pid 521505:tid 521745] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory18
[Sun Aug 30 03:12:54.549769 2026] [authz_core:error] [pid 521505:tid 521676] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:54.550032 2026] [authz_core:error] [pid 521505:tid 521676] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:54.556747 2026] [security2:error] [pid 521505:tid 521523] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/_profiler/phpinfo.php"] [unique_id "apPmBm8byYE0iXl--K6pXwADUxE"]
[Sun Aug 30 03:12:54.575583 2026] [security2:error] [pid 521505:tid 521567] [remote 209.42.21.221:44054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.21.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "stressfreeaccounts.com"] [uri "/wp-login.php"] [unique_id "apPmBm8byYE0iXl--K6pYAADLD0"], referer: https://stressfreeaccounts.com/wp-login.php
[Sun Aug 30 03:12:54.576356 2026] [authz_core:error] [pid 521505:tid 521747] [client 66.249.66.41:64423] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:54.576660 2026] [authz_core:error] [pid 521505:tid 521747] [client 66.249.66.41:64423] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:54.577108 2026] [security2:error] [pid 521505:tid 521661] [client 158.23.147.79:52681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apPmBm8byYE0iXl--K6pYgAAAzg"]
[Sun Aug 30 03:12:54.582293 2026] [security2:error] [pid 521505:tid 521671] [client 216.73.216.128:18246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/sasl/developer/testing.html"] [unique_id "apPmBm8byYE0iXl--K6pYwAAA0I"]
[Sun Aug 30 03:12:54.598952 2026] [security2:error] [pid 521505:tid 521659] [client 52.139.37.240:49687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-content.php"] [unique_id "apPmBm8byYE0iXl--K6pZQAAAzY"]
[Sun Aug 30 03:12:54.610758 2026] [security2:error] [pid 521505:tid 521637] [client 20.48.160.90:50375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/session.php"] [unique_id "apPmBm8byYE0iXl--K6pZgAAAyA"]
[Sun Aug 30 03:12:54.620487 2026] [security2:error] [pid 524122:tid 524368] [client 20.48.250.41:62347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/s1.php"] [unique_id "apPmBn3lhEjKFiK_nBKFmQAAAgI"]
[Sun Aug 30 03:12:54.627071 2026] [security2:error] [pid 521505:tid 521703] [client 20.151.200.44:45963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/admin.php/007x.php"] [unique_id "apPmBm8byYE0iXl--K6paQAAA2I"]
[Sun Aug 30 03:12:54.649896 2026] [security2:error] [pid 521505:tid 521704] [client 20.48.160.90:49997] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.icobold.com"] [uri "/1.php"] [unique_id "apPmBm8byYE0iXl--K6pawAAA2M"]
[Sun Aug 30 03:12:54.649994 2026] [security2:error] [pid 521505:tid 521704] [client 20.48.160.90:49997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/1.php"] [unique_id "apPmBm8byYE0iXl--K6pawAAA2M"]
[Sun Aug 30 03:12:54.744109 2026] [security2:error] [pid 521505:tid 521669] [client 114.119.140.29:58581] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "basichoa.com"] [uri "/"] [unique_id "apPmBm8byYE0iXl--K6pbgAAA0A"], referer: https://basichoa.com/
[Sun Aug 30 03:12:54.752079 2026] [security2:error] [pid 521505:tid 521652] [client 20.48.251.3:43122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/bb.php"] [unique_id "apPmBm8byYE0iXl--K6pbwAAAy8"]
[Sun Aug 30 03:12:54.758210 2026] [security2:error] [pid 521505:tid 521699] [client 20.48.160.90:23688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/eagle.php"] [unique_id "apPmBm8byYE0iXl--K6pcAAAA14"]
[Sun Aug 30 03:12:54.777844 2026] [authz_core:error] [pid 521505:tid 521750] [client 216.73.216.128:27728] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:54.778112 2026] [authz_core:error] [pid 521505:tid 521750] [client 216.73.216.128:27728] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:54.784663 2026] [security2:error] [pid 521505:tid 521692] [client 20.48.250.41:64824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/0byte.php"] [unique_id "apPmBm8byYE0iXl--K6pcgAAA1c"]
[Sun Aug 30 03:12:54.792595 2026] [security2:error] [pid 521505:tid 521759] [client 20.48.160.90:23749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/classwithtostring.php"] [unique_id "apPmBm8byYE0iXl--K6pcwAAA5o"]
[Sun Aug 30 03:12:54.804534 2026] [security2:error] [pid 521505:tid 521682] [client 52.139.37.240:9473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/function.php"] [unique_id "apPmBm8byYE0iXl--K6pdAAAA00"]
[Sun Aug 30 03:12:54.871763 2026] [security2:error] [pid 524122:tid 524310] [client 216.73.216.128:10284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/nameserverconfig"] [unique_id "apPmBn3lhEjKFiK_nBKFmwAAAcg"]
[Sun Aug 30 03:12:54.875410 2026] [security2:error] [pid 521505:tid 521739] [client 20.104.50.220:17257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/content.php"] [unique_id "apPmBm8byYE0iXl--K6pdgAAA4Y"]
[Sun Aug 30 03:12:54.887442 2026] [security2:error] [pid 521505:tid 521686] [client 158.23.147.79:59011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/asd.php"] [unique_id "apPmBm8byYE0iXl--K6pdwAAA1E"]
[Sun Aug 30 03:12:54.888506 2026] [security2:error] [pid 521505:tid 521755] [client 20.104.50.220:6092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/24.php"] [unique_id "apPmBm8byYE0iXl--K6peAAAA5Y"]
[Sun Aug 30 03:12:54.897488 2026] [security2:error] [pid 521505:tid 521754] [client 20.48.160.90:29163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/up-kon.php"] [unique_id "apPmBm8byYE0iXl--K6pfAAAA5U"]
[Sun Aug 30 03:12:54.925114 2026] [security2:error] [pid 521505:tid 521640] [client 20.48.160.90:23803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp-ws68.php"] [unique_id "apPmBm8byYE0iXl--K6pfQAAAyM"]
[Sun Aug 30 03:12:54.938567 2026] [security2:error] [pid 521505:tid 521645] [client 20.48.250.41:64809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/xr.php"] [unique_id "apPmBm8byYE0iXl--K6pfgAAAyg"]
[Sun Aug 30 03:12:54.974557 2026] [security2:error] [pid 521505:tid 521743] [client 4.205.62.107:17250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/file59.php"] [unique_id "apPmBm8byYE0iXl--K6pggAAA4o"]
[Sun Aug 30 03:12:55.009017 2026] [security2:error] [pid 521505:tid 521715] [client 52.139.37.240:46939] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "intheshadowsfilm.com"] [uri "/1.php"] [unique_id "apPmB28byYE0iXl--K6phAAAA24"]
[Sun Aug 30 03:12:55.009125 2026] [security2:error] [pid 521505:tid 521715] [client 52.139.37.240:46939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/1.php"] [unique_id "apPmB28byYE0iXl--K6phAAAA24"]
[Sun Aug 30 03:12:55.030849 2026] [authz_core:error] [pid 521505:tid 521722] [client 66.249.66.39:59995] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:55.031139 2026] [authz_core:error] [pid 521505:tid 521722] [client 66.249.66.39:59995] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:55.032546 2026] [security2:error] [pid 524122:tid 524269] [client 68.155.159.216:60928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/goods.php"] [unique_id "apPmB33lhEjKFiK_nBKFnAAAAZ8"]
[Sun Aug 30 03:12:55.041536 2026] [authz_core:error] [pid 521505:tid 521746] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory15
[Sun Aug 30 03:12:55.041823 2026] [authz_core:error] [pid 521505:tid 521746] [client 74.7.227.8:45638] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory15
[Sun Aug 30 03:12:55.042234 2026] [security2:error] [pid 524122:tid 524342] [client 20.48.160.90:23778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/tinny.php"] [unique_id "apPmB33lhEjKFiK_nBKFnQAAAeg"]
[Sun Aug 30 03:12:55.042237 2026] [security2:error] [pid 524122:tid 524369] [client 20.197.61.180:1621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/function.php"] [unique_id "apPmB33lhEjKFiK_nBKFngAAAgM"]
[Sun Aug 30 03:12:55.060152 2026] [security2:error] [pid 521505:tid 521685] [client 20.48.160.90:23687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/simple.php"] [unique_id "apPmB28byYE0iXl--K6piQAAA1A"]
[Sun Aug 30 03:12:55.087357 2026] [security2:error] [pid 521505:tid 521744] [client 20.104.18.15:22527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/abcd.php"] [unique_id "apPmB28byYE0iXl--K6piwAAA4s"]
[Sun Aug 30 03:12:55.089771 2026] [security2:error] [pid 521505:tid 521672] [client 20.48.250.41:60655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/h02ugyh.php"] [unique_id "apPmB28byYE0iXl--K6pjgAAA0M"]
[Sun Aug 30 03:12:55.095620 2026] [security2:error] [pid 521505:tid 521683] [client 158.23.147.79:55383] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "gtepetrochem.com"] [uri "/1.php"] [unique_id "apPmB28byYE0iXl--K6pkgAAA04"]
[Sun Aug 30 03:12:55.095736 2026] [security2:error] [pid 521505:tid 521683] [client 158.23.147.79:55383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/1.php"] [unique_id "apPmB28byYE0iXl--K6pkgAAA04"]
[Sun Aug 30 03:12:55.096594 2026] [authz_core:error] [pid 521505:tid 521735] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:55.097012 2026] [authz_core:error] [pid 521505:tid 521735] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:55.098336 2026] [security2:error] [pid 521505:tid 521667] [client 20.48.250.41:37860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPmB28byYE0iXl--K6pkwAAAz4"]
[Sun Aug 30 03:12:55.133325 2026] [security2:error] [pid 524122:tid 524340] [client 20.104.18.15:1973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/dev.php"] [unique_id "apPmB33lhEjKFiK_nBKFoAAAAeY"]
[Sun Aug 30 03:12:55.156186 2026] [security2:error] [pid 521505:tid 521518] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/admin-app/.env"] [unique_id "apPmB28byYE0iXl--K6pmAADWQw"]
[Sun Aug 30 03:12:55.181278 2026] [security2:error] [pid 524122:tid 524298] [client 20.48.160.90:50316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp-easy.php"] [unique_id "apPmB33lhEjKFiK_nBKFoQAAAbw"]
[Sun Aug 30 03:12:55.189943 2026] [security2:error] [pid 524122:tid 524358] [client 20.48.160.90:50346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/aaa.php"] [unique_id "apPmB33lhEjKFiK_nBKFogAAAfg"]
[Sun Aug 30 03:12:55.236763 2026] [security2:error] [pid 521505:tid 521653] [client 20.48.250.41:64803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/xxw.php"] [unique_id "apPmB28byYE0iXl--K6pnAAAAzA"]
[Sun Aug 30 03:12:55.238157 2026] [security2:error] [pid 524122:tid 524281] [client 20.48.250.41:37764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPmB33lhEjKFiK_nBKFowAAAas"]
[Sun Aug 30 03:12:55.248810 2026] [security2:error] [pid 521505:tid 521684] [client 158.23.147.79:55382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/ws.php"] [unique_id "apPmB28byYE0iXl--K6pngAAA08"]
[Sun Aug 30 03:12:55.250706 2026] [security2:error] [pid 521505:tid 521756] [client 52.139.37.240:50325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/6.php"] [unique_id "apPmB28byYE0iXl--K6pnwAAA5c"]
[Sun Aug 30 03:12:55.270911 2026] [security2:error] [pid 521505:tid 521688] [client 4.205.62.107:15817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/fff.php"] [unique_id "apPmB28byYE0iXl--K6poQAAA1M"]
[Sun Aug 30 03:12:55.287229 2026] [security2:error] [pid 521505:tid 521649] [client 20.104.50.220:51641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/byp.php"] [unique_id "apPmB28byYE0iXl--K6powAAAyw"]
[Sun Aug 30 03:12:55.294708 2026] [security2:error] [pid 524122:tid 524255] [client 4.205.62.107:32009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/rem.php"] [unique_id "apPmB33lhEjKFiK_nBKFpAAAAZE"]
[Sun Aug 30 03:12:55.294899 2026] [security2:error] [pid 521505:tid 521661] [client 20.104.50.220:29624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/index7.php"] [unique_id "apPmB28byYE0iXl--K6ppAAAAzg"]
[Sun Aug 30 03:12:55.309222 2026] [security2:error] [pid 521505:tid 521659] [client 20.48.160.90:50331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/d7.php"] [unique_id "apPmB28byYE0iXl--K6ppgAAAzY"]
[Sun Aug 30 03:12:55.328189 2026] [security2:error] [pid 521505:tid 521719] [client 20.104.18.15:51119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/backup.php"] [unique_id "apPmB28byYE0iXl--K6ppwAAA3I"]
[Sun Aug 30 03:12:55.329183 2026] [security2:error] [pid 521505:tid 521637] [client 20.104.50.220:33070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/dbx.php"] [unique_id "apPmB28byYE0iXl--K6pqAAAAyA"]
[Sun Aug 30 03:12:55.332658 2026] [security2:error] [pid 521505:tid 521717] [client 4.205.62.107:15844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/gnmlc.php"] [unique_id "apPmB28byYE0iXl--K6pqgAAA3A"]
[Sun Aug 30 03:12:55.358831 2026] [security2:error] [pid 521505:tid 521676] [client 20.104.50.220:25419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/wp-content/admin.php"] [unique_id "apPmB28byYE0iXl--K6prAAAA0c"]
[Sun Aug 30 03:12:55.372050 2026] [security2:error] [pid 521505:tid 521745] [client 20.151.200.44:62934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/xwpg.php"] [unique_id "apPmB28byYE0iXl--K6prwAAA4w"]
[Sun Aug 30 03:12:55.375315 2026] [security2:error] [pid 521505:tid 521654] [client 20.48.250.41:37843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/ff1.php"] [unique_id "apPmB28byYE0iXl--K6psAAAAzE"]
[Sun Aug 30 03:12:55.379726 2026] [security2:error] [pid 521505:tid 521723] [client 20.48.250.41:64887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/bolt.php"] [unique_id "apPmB28byYE0iXl--K6psQAAA3Y"]
[Sun Aug 30 03:12:55.384282 2026] [security2:error] [pid 524122:tid 524276] [client 158.23.147.79:55387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-includes/css/index.php"] [unique_id "apPmB33lhEjKFiK_nBKFpQAAAaY"]
[Sun Aug 30 03:12:55.391621 2026] [security2:error] [pid 524122:tid 524318] [client 20.104.49.130:60648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/155.php"] [unique_id "apPmB33lhEjKFiK_nBKFpgAAAdA"]
[Sun Aug 30 03:12:55.410880 2026] [security2:error] [pid 521505:tid 521692] [client 4.205.62.107:52815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/test.config.php"] [unique_id "apPmB28byYE0iXl--K6ptAAAA1c"]
[Sun Aug 30 03:12:55.415941 2026] [authz_core:error] [pid 521505:tid 521681] [client 66.249.66.71:55938] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:55.416358 2026] [authz_core:error] [pid 521505:tid 521681] [client 66.249.66.71:55938] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:55.439995 2026] [security2:error] [pid 521505:tid 521711] [client 20.48.160.90:23738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/v5.php"] [unique_id "apPmB28byYE0iXl--K6ptwAAA2o"]
[Sun Aug 30 03:12:55.480464 2026] [security2:error] [pid 521505:tid 521511] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/admin_phpinfo.php"] [unique_id "apPmB28byYE0iXl--K6pugADSwU"]
[Sun Aug 30 03:12:55.504569 2026] [security2:error] [pid 521505:tid 521736] [client 52.139.37.240:50327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/lv.php"] [unique_id "apPmB28byYE0iXl--K6puwAAA4M"]
[Sun Aug 30 03:12:55.510014 2026] [security2:error] [pid 521505:tid 521755] [client 20.48.250.41:64822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/rtx.php"] [unique_id "apPmB28byYE0iXl--K6pvAAAA5Y"]
[Sun Aug 30 03:12:55.515221 2026] [security2:error] [pid 521505:tid 521750] [client 20.48.250.41:37864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/t.php"] [unique_id "apPmB28byYE0iXl--K6pvQAAA5E"]
[Sun Aug 30 03:12:55.516398 2026] [security2:error] [pid 524122:tid 524294] [client 158.23.147.79:55400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apPmB33lhEjKFiK_nBKFpwAAAbg"]
[Sun Aug 30 03:12:55.539097 2026] [security2:error] [pid 521505:tid 521758] [client 20.48.251.3:54846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/product.php"] [unique_id "apPmB28byYE0iXl--K6pwQAAA5k"]
[Sun Aug 30 03:12:55.544869 2026] [authz_core:error] [pid 521505:tid 521698] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:55.545129 2026] [authz_core:error] [pid 521505:tid 521698] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:55.550294 2026] [authz_core:error] [pid 521505:tid 521749] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory11
[Sun Aug 30 03:12:55.550579 2026] [authz_core:error] [pid 521505:tid 521749] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory11
[Sun Aug 30 03:12:55.557935 2026] [security2:error] [pid 521505:tid 521595] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/administrator/.env"] [unique_id "apPmB28byYE0iXl--K6pvwADlVk"]
[Sun Aug 30 03:12:55.571248 2026] [security2:error] [pid 521505:tid 521640] [client 20.48.160.90:23709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/shiny.php"] [unique_id "apPmB28byYE0iXl--K6pxAAAAyM"]
[Sun Aug 30 03:12:55.580574 2026] [security2:error] [pid 521505:tid 521748] [client 20.104.50.220:31549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/abcd.php"] [unique_id "apPmB28byYE0iXl--K6pxQAAA48"]
[Sun Aug 30 03:12:55.583271 2026] [security2:error] [pid 524122:tid 524278] [client 20.48.160.90:29140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/az.php"] [unique_id "apPmB33lhEjKFiK_nBKFqAAAAag"]
[Sun Aug 30 03:12:55.615132 2026] [security2:error] [pid 521505:tid 521647] [client 20.104.50.220:29611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/fell.php"] [unique_id "apPmB28byYE0iXl--K6pygAAAyo"]
[Sun Aug 30 03:12:55.640584 2026] [security2:error] [pid 521505:tid 521651] [client 20.48.250.41:62413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/ckk.php"] [unique_id "apPmB28byYE0iXl--K6pzQAAAy4"]
[Sun Aug 30 03:12:55.652027 2026] [security2:error] [pid 524122:tid 524279] [client 20.104.50.220:61952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/0x.php"] [unique_id "apPmB33lhEjKFiK_nBKFqQAAAak"]
[Sun Aug 30 03:12:55.665809 2026] [security2:error] [pid 521505:tid 521685] [client 158.23.147.79:59048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-content/cong.php"] [unique_id "apPmB28byYE0iXl--K6pzgAAA1A"]
[Sun Aug 30 03:12:55.669498 2026] [security2:error] [pid 521505:tid 521741] [client 20.48.251.3:36856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/f35.php"] [unique_id "apPmB28byYE0iXl--K6pzwAAA4g"]
[Sun Aug 30 03:12:55.674870 2026] [security2:error] [pid 524122:tid 524296] [client 20.48.250.41:37778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/erty.php"] [unique_id "apPmB33lhEjKFiK_nBKFqwAAAbo"]
[Sun Aug 30 03:12:55.698227 2026] [security2:error] [pid 521505:tid 521602] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/api/.env"] [unique_id "apPmB28byYE0iXl--K6p0AADQ2A"]
[Sun Aug 30 03:12:55.703063 2026] [security2:error] [pid 521505:tid 521658] [client 20.104.49.130:57715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alarm-monitoring.net"] [uri "/mac.php"] [unique_id "apPmB28byYE0iXl--K6p0QAAAzU"]
[Sun Aug 30 03:12:55.712742 2026] [security2:error] [pid 521505:tid 521740] [client 20.48.160.90:50024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/goods.php"] [unique_id "apPmB28byYE0iXl--K6p1AAAA4c"]
[Sun Aug 30 03:12:55.715159 2026] [authz_core:error] [pid 521505:tid 521707] [client 216.73.216.128:26620] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:55.715434 2026] [authz_core:error] [pid 521505:tid 521707] [client 216.73.216.128:26620] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:55.719353 2026] [security2:error] [pid 521505:tid 521747] [client 20.48.160.90:49963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/js.php"] [unique_id "apPmB28byYE0iXl--K6p1QAAA44"]
[Sun Aug 30 03:12:55.748989 2026] [security2:error] [pid 524122:tid 524360] [client 52.139.37.240:46957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/gecko.php"] [unique_id "apPmB33lhEjKFiK_nBKFrAAAAfo"]
[Sun Aug 30 03:12:55.809022 2026] [security2:error] [pid 521505:tid 521716] [client 20.48.250.41:62341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "belgradeplace.com"] [uri "/R57.php"] [unique_id "apPmB28byYE0iXl--K6p2QAAA28"]
[Sun Aug 30 03:12:55.827579 2026] [security2:error] [pid 521505:tid 521684] [client 20.48.250.41:37832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/0x.php"] [unique_id "apPmB28byYE0iXl--K6p2wAAA08"]
[Sun Aug 30 03:12:55.845091 2026] [security2:error] [pid 521505:tid 521645] [client 20.197.61.180:1631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/about.php"] [unique_id "apPmB28byYE0iXl--K6p3AAAAyg"]
[Sun Aug 30 03:12:55.879205 2026] [security2:error] [pid 521505:tid 521752] [client 20.48.160.90:29160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/hd.php"] [unique_id "apPmB28byYE0iXl--K6p3QAAA5M"]
[Sun Aug 30 03:12:55.888284 2026] [security2:error] [pid 524122:tid 524286] [client 20.104.49.130:63550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/talkxkej.php"] [unique_id "apPmB33lhEjKFiK_nBKFrQAAAbA"]
[Sun Aug 30 03:12:55.898858 2026] [security2:error] [pid 524122:tid 524270] [client 20.48.251.3:40028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/file59.php"] [unique_id "apPmB33lhEjKFiK_nBKFrgAAAaA"]
[Sun Aug 30 03:12:55.905608 2026] [security2:error] [pid 521505:tid 521721] [client 20.48.160.90:23757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/000.php/index.php"] [unique_id "apPmB28byYE0iXl--K6p3wAAA3Q"]
[Sun Aug 30 03:12:55.949717 2026] [authz_core:error] [pid 521505:tid 521702] [client 66.249.66.38:37632] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:55.950010 2026] [authz_core:error] [pid 521505:tid 521702] [client 66.249.66.38:37632] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:55.951145 2026] [security2:error] [pid 521505:tid 521649] [client 158.23.147.79:59055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPmB28byYE0iXl--K6p5QAAAyw"]
[Sun Aug 30 03:12:55.972736 2026] [authz_core:error] [pid 521505:tid 521724] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory11
[Sun Aug 30 03:12:55.973015 2026] [authz_core:error] [pid 521505:tid 521724] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory11
[Sun Aug 30 03:12:55.973213 2026] [security2:error] [pid 521505:tid 521661] [client 20.48.250.41:37851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/66.php"] [unique_id "apPmB28byYE0iXl--K6p6AAAAzg"]
[Sun Aug 30 03:12:56.002795 2026] [security2:error] [pid 524122:tid 524284] [client 52.139.37.240:46922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/berlin.php"] [unique_id "apPmCH3lhEjKFiK_nBKFrwAAAa4"]
[Sun Aug 30 03:12:56.007988 2026] [security2:error] [pid 521505:tid 521552] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/api/info.php"] [unique_id "apPmCG8byYE0iXl--K6p7AADci4"]
[Sun Aug 30 03:12:56.014154 2026] [security2:error] [pid 521505:tid 521674] [client 20.104.50.220:17237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/lord.php"] [unique_id "apPmCG8byYE0iXl--K6p7QAAA0U"]
[Sun Aug 30 03:12:56.024065 2026] [security2:error] [pid 521505:tid 521637] [client 20.48.160.90:29135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/xl2023.php"] [unique_id "apPmCG8byYE0iXl--K6p7gAAAyA"]
[Sun Aug 30 03:12:56.026771 2026] [security2:error] [pid 521505:tid 521717] [client 20.104.50.220:5482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/15.php"] [unique_id "apPmCG8byYE0iXl--K6p7wAAA3A"]
[Sun Aug 30 03:12:56.035237 2026] [security2:error] [pid 521505:tid 521666] [client 20.48.160.90:23750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/Jcrop.php"] [unique_id "apPmCG8byYE0iXl--K6p8AAAAz0"]
[Sun Aug 30 03:12:56.044508 2026] [authz_core:error] [pid 521505:tid 521704] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:56.044808 2026] [authz_core:error] [pid 521505:tid 521704] [client 74.7.243.204:49764] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:56.051430 2026] [security2:error] [pid 524122:tid 524271] [client 158.23.147.79:55398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPmCH3lhEjKFiK_nBKFsAAAAaE"]
[Sun Aug 30 03:12:56.075468 2026] [security2:error] [pid 524122:tid 524348] [client 20.104.49.130:59561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/fs.php"] [unique_id "apPmCH3lhEjKFiK_nBKFsQAAAe4"]
[Sun Aug 30 03:12:56.082226 2026] [authz_core:error] [pid 521505:tid 521734] [client 216.73.216.128:27728] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:56.082637 2026] [authz_core:error] [pid 521505:tid 521734] [client 216.73.216.128:27728] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:56.114164 2026] [security2:error] [pid 521505:tid 521737] [client 4.205.62.107:17330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/cli_bootstrap.php"] [unique_id "apPmCG8byYE0iXl--K6p-AAAA4Q"]
[Sun Aug 30 03:12:56.120335 2026] [security2:error] [pid 521505:tid 521635] [client 20.48.250.41:37773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/f35.php"] [unique_id "apPmCG8byYE0iXl--K6p-QAAAx4"]
[Sun Aug 30 03:12:56.161483 2026] [security2:error] [pid 521505:tid 521711] [client 20.48.160.90:28787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/V2.php"] [unique_id "apPmCG8byYE0iXl--K6p_wAAA2o"]
[Sun Aug 30 03:12:56.167786 2026] [security2:error] [pid 521505:tid 521655] [client 20.48.160.90:28770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/35iDq8NAjLu.php"] [unique_id "apPmCG8byYE0iXl--K6qAQAAAzI"]
[Sun Aug 30 03:12:56.195559 2026] [security2:error] [pid 521505:tid 521680] [client 158.23.147.79:55386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apPmCG8byYE0iXl--K6qBgAAA0s"]
[Sun Aug 30 03:12:56.214328 2026] [security2:error] [pid 521505:tid 521621] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/admin/phpinfo.php"] [unique_id "apPmCG8byYE0iXl--K6qBwADhnM"]
[Sun Aug 30 03:12:56.222348 2026] [security2:error] [pid 521505:tid 521660] [client 20.104.18.15:22521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/nofile.php"] [unique_id "apPmCG8byYE0iXl--K6qCAAAAzc"]
[Sun Aug 30 03:12:56.238925 2026] [security2:error] [pid 524122:tid 524315] [client 52.139.37.240:46952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/xmlrpc.php"] [unique_id "apPmCH3lhEjKFiK_nBKFtQAAAc0"]
[Sun Aug 30 03:12:56.253747 2026] [security2:error] [pid 521505:tid 521709] [client 20.48.250.41:37761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/wen.php"] [unique_id "apPmCG8byYE0iXl--K6qCQAAA2g"]
[Sun Aug 30 03:12:56.258941 2026] [security2:error] [pid 521505:tid 521754] [client 68.155.159.216:60931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apPmCG8byYE0iXl--K6qCwAAA5U"]
[Sun Aug 30 03:12:56.289978 2026] [security2:error] [pid 521505:tid 521665] [client 20.104.18.15:1997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/wp-activate.php"] [unique_id "apPmCG8byYE0iXl--K6qDQAAAzw"]
[Sun Aug 30 03:12:56.306092 2026] [security2:error] [pid 524122:tid 524352] [client 20.48.160.90:50414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/mad.php"] [unique_id "apPmCH3lhEjKFiK_nBKFtgAAAfI"]
[Sun Aug 30 03:12:56.308935 2026] [security2:error] [pid 521505:tid 521706] [client 20.151.200.44:55720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.americanqualityhomeinspections.com"] [uri "/bge.php"] [unique_id "apPmCG8byYE0iXl--K6qDwAAA2U"]
[Sun Aug 30 03:12:56.319108 2026] [security2:error] [pid 521505:tid 521689] [client 20.104.49.130:53853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/kerang.php"] [unique_id "apPmCG8byYE0iXl--K6qEAAAA1Q"]
[Sun Aug 30 03:12:56.319799 2026] [security2:error] [pid 521505:tid 521705] [client 20.48.160.90:23701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/btx25.php"] [unique_id "apPmCG8byYE0iXl--K6qEQAAA2Q"]
[Sun Aug 30 03:12:56.320357 2026] [security2:error] [pid 521505:tid 521697] [client 20.151.200.44:52042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/admin.php/csv.php"] [unique_id "apPmCG8byYE0iXl--K6qEgAAA1w"]
[Sun Aug 30 03:12:56.375078 2026] [security2:error] [pid 521505:tid 521731] [client 158.23.147.79:59051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-content/radio.php"] [unique_id "apPmCG8byYE0iXl--K6qGAAAA34"]
[Sun Aug 30 03:12:56.407589 2026] [security2:error] [pid 521505:tid 521672] [client 4.205.62.107:16333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/autogooey.php"] [unique_id "apPmCG8byYE0iXl--K6qGwAAA0M"]
[Sun Aug 30 03:12:56.409658 2026] [security2:error] [pid 521505:tid 521683] [client 20.48.250.41:37780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/inc.php"] [unique_id "apPmCG8byYE0iXl--K6qHAAAA04"]
[Sun Aug 30 03:12:56.424961 2026] [security2:error] [pid 521505:tid 521667] [client 20.104.50.220:42779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/con.php"] [unique_id "apPmCG8byYE0iXl--K6qHQAAAz4"]
[Sun Aug 30 03:12:56.441641 2026] [security2:error] [pid 524122:tid 524257] [client 20.104.50.220:29179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/index8.php"] [unique_id "apPmCH3lhEjKFiK_nBKFtwAAAZM"]
[Sun Aug 30 03:12:56.444048 2026] [security2:error] [pid 521505:tid 521613] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/api-backend/.env"] [unique_id "apPmCG8byYE0iXl--K6qHwADh2s"]
[Sun Aug 30 03:12:56.444096 2026] [security2:error] [pid 524122:tid 524283] [client 20.48.160.90:23807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/st.php"] [unique_id "apPmCH3lhEjKFiK_nBKFuAAAAa0"]
[Sun Aug 30 03:12:56.445200 2026] [security2:error] [pid 521505:tid 521516] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/api-node/.env"] [unique_id "apPmCG8byYE0iXl--K6qIAADhwo"]
[Sun Aug 30 03:12:56.447480 2026] [security2:error] [pid 521505:tid 521685] [client 52.139.37.240:49686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/f35.php"] [unique_id "apPmCG8byYE0iXl--K6qIQAAA1A"]
[Sun Aug 30 03:12:56.458183 2026] [security2:error] [pid 524122:tid 524336] [client 20.48.160.90:50014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/radio.php"] [unique_id "apPmCH3lhEjKFiK_nBKFuQAAAeI"]
[Sun Aug 30 03:12:56.466453 2026] [security2:error] [pid 521505:tid 521747] [client 20.104.50.220:33193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/degeselih.php"] [unique_id "apPmCG8byYE0iXl--K6qIwAAA44"]
[Sun Aug 30 03:12:56.468722 2026] [authz_core:error] [pid 521505:tid 521749] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory11
[Sun Aug 30 03:12:56.469002 2026] [authz_core:error] [pid 521505:tid 521749] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory11
[Sun Aug 30 03:12:56.476887 2026] [security2:error] [pid 521505:tid 521730] [client 4.205.62.107:16338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/koiy.php"] [unique_id "apPmCG8byYE0iXl--K6qJAAAA30"]
[Sun Aug 30 03:12:56.478727 2026] [security2:error] [pid 521505:tid 521650] [client 20.104.18.15:51107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/indo.php"] [unique_id "apPmCG8byYE0iXl--K6qJQAAAy0"]
[Sun Aug 30 03:12:56.506707 2026] [security2:error] [pid 521505:tid 521746] [client 20.104.50.220:24853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/f6.php"] [unique_id "apPmCG8byYE0iXl--K6qJgAAA40"]
[Sun Aug 30 03:12:56.537934 2026] [security2:error] [pid 521505:tid 521721] [client 20.48.250.41:37872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/6bcwiqwj.php"] [unique_id "apPmCG8byYE0iXl--K6qKQAAA3Q"]
[Sun Aug 30 03:12:56.551439 2026] [security2:error] [pid 521505:tid 521649] [client 4.205.62.107:32484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/min.php"] [unique_id "apPmCG8byYE0iXl--K6qKwAAAyw"]
[Sun Aug 30 03:12:56.574776 2026] [security2:error] [pid 521505:tid 521675] [client 158.23.147.79:59014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-admin/dropdown.php"] [unique_id "apPmCG8byYE0iXl--K6qLAAAA0Y"]
[Sun Aug 30 03:12:56.595257 2026] [security2:error] [pid 524122:tid 524345] [client 20.48.160.90:50361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/alfanew.php"] [unique_id "apPmCH3lhEjKFiK_nBKFuwAAAes"]
[Sun Aug 30 03:12:56.595586 2026] [authz_core:error] [pid 521505:tid 521679] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:56.595847 2026] [authz_core:error] [pid 521505:tid 521679] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:56.599017 2026] [security2:error] [pid 521505:tid 521725] [client 20.48.160.90:50343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/dex.php"] [unique_id "apPmCG8byYE0iXl--K6qLwAAA3g"]
[Sun Aug 30 03:12:56.660220 2026] [security2:error] [pid 524122:tid 524320] [client 4.205.62.107:52841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/gecko-litespeed.php"] [unique_id "apPmCH3lhEjKFiK_nBKFvAAAAdI"]
[Sun Aug 30 03:12:56.677966 2026] [security2:error] [pid 521505:tid 521666] [client 52.139.37.240:49723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/autoload_classmap.php"] [unique_id "apPmCG8byYE0iXl--K6qNAAAAz0"]
[Sun Aug 30 03:12:56.678629 2026] [security2:error] [pid 521505:tid 521676] [client 20.48.251.3:46251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/fun.php"] [unique_id "apPmCG8byYE0iXl--K6qNQAAA0c"]
[Sun Aug 30 03:12:56.681564 2026] [security2:error] [pid 524122:tid 524304] [client 20.197.61.180:9003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/new.php"] [unique_id "apPmCH3lhEjKFiK_nBKFvQAAAcI"]
[Sun Aug 30 03:12:56.730222 2026] [security2:error] [pid 524122:tid 524341] [client 20.48.160.90:49920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/ioxi.php"] [unique_id "apPmCH3lhEjKFiK_nBKFvgAAAec"]
[Sun Aug 30 03:12:56.735208 2026] [security2:error] [pid 521505:tid 521654] [client 20.48.160.90:50010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/giodywky.php"] [unique_id "apPmCG8byYE0iXl--K6qOAAAAzE"]
[Sun Aug 30 03:12:56.736020 2026] [security2:error] [pid 524122:tid 524378] [client 20.48.250.41:37868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/easy.php"] [unique_id "apPmCH3lhEjKFiK_nBKFvwAAAgw"]
[Sun Aug 30 03:12:56.737874 2026] [security2:error] [pid 521505:tid 521671] [client 20.104.50.220:31489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/autoload_classmap.php"] [unique_id "apPmCG8byYE0iXl--K6qOgAAA0I"]
[Sun Aug 30 03:12:56.782806 2026] [security2:error] [pid 521505:tid 521657] [client 20.104.50.220:28713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/ok.php"] [unique_id "apPmCG8byYE0iXl--K6qPgAAAzQ"]
[Sun Aug 30 03:12:56.803365 2026] [authz_core:error] [pid 524122:tid 524262] [client 66.249.66.192:53438] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:56.803796 2026] [authz_core:error] [pid 524122:tid 524262] [client 66.249.66.192:53438] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:56.814678 2026] [security2:error] [pid 521505:tid 521711] [client 20.104.50.220:61468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/bless3.php"] [unique_id "apPmCG8byYE0iXl--K6qQAAAA2o"]
[Sun Aug 30 03:12:56.815064 2026] [security2:error] [pid 524122:tid 524266] [client 20.48.251.3:36882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/api.php"] [unique_id "apPmCH3lhEjKFiK_nBKFwQAAAZw"]
[Sun Aug 30 03:12:56.863879 2026] [security2:error] [pid 524122:tid 524300] [client 20.48.160.90:50315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/TNT.php"] [unique_id "apPmCH3lhEjKFiK_nBKFwgAAAb4"]
[Sun Aug 30 03:12:56.876242 2026] [security2:error] [pid 524122:tid 524326] [client 20.48.160.90:28785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp-kz.php"] [unique_id "apPmCH3lhEjKFiK_nBKFwwAAAdg"]
[Sun Aug 30 03:12:56.886458 2026] [security2:error] [pid 521505:tid 521680] [client 20.48.250.41:37856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/fresh3.php"] [unique_id "apPmCG8byYE0iXl--K6qRAAAA0s"]
[Sun Aug 30 03:12:56.893420 2026] [security2:error] [pid 524122:tid 524330] [client 158.23.147.79:59016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/login.php"] [unique_id "apPmCH3lhEjKFiK_nBKFxAAAAdw"]
[Sun Aug 30 03:12:56.951496 2026] [security2:error] [pid 521505:tid 521670] [client 52.139.37.240:49694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/NewFile.php"] [unique_id "apPmCG8byYE0iXl--K6qRwAAA0E"]
[Sun Aug 30 03:12:56.982405 2026] [authz_core:error] [pid 521505:tid 521709] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory15
[Sun Aug 30 03:12:56.982695 2026] [authz_core:error] [pid 521505:tid 521709] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory15
[Sun Aug 30 03:12:57.016045 2026] [security2:error] [pid 521505:tid 521520] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/api/phpinfo.php"] [unique_id "apPmCW8byYE0iXl--K6qSwADjw4"]
[Sun Aug 30 03:12:57.016423 2026] [security2:error] [pid 521505:tid 521665] [client 20.48.160.90:50317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp-includes/ID3/getid.php"] [unique_id "apPmCW8byYE0iXl--K6qTAAAAzw"]
[Sun Aug 30 03:12:57.025775 2026] [security2:error] [pid 521505:tid 521742] [client 20.48.160.90:50412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/cd.php"] [unique_id "apPmCW8byYE0iXl--K6qTQAAA4k"]
[Sun Aug 30 03:12:57.032354 2026] [security2:error] [pid 524122:tid 524297] [client 158.23.147.79:55391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/hehehehe.php"] [unique_id "apPmCX3lhEjKFiK_nBKFxgAAAbs"]
[Sun Aug 30 03:12:57.039028 2026] [security2:error] [pid 524122:tid 524290] [client 20.48.251.3:59456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/cli_bootstrap.php"] [unique_id "apPmCX3lhEjKFiK_nBKFxwAAAbQ"]
[Sun Aug 30 03:12:57.055255 2026] [authz_core:error] [pid 521505:tid 521705] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:57.055715 2026] [authz_core:error] [pid 521505:tid 521705] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:57.057598 2026] [security2:error] [pid 521505:tid 521697] [client 20.48.250.41:37840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/bgymj.php"] [unique_id "apPmCW8byYE0iXl--K6qTwAAA1w"]
[Sun Aug 30 03:12:57.136202 2026] [security2:error] [pid 521505:tid 521667] [client 20.151.200.44:46005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/admin.php/heex.php"] [unique_id "apPmCW8byYE0iXl--K6qVwAAAz4"]
[Sun Aug 30 03:12:57.148486 2026] [security2:error] [pid 524122:tid 524323] [client 20.48.160.90:23724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/session.php"] [unique_id "apPmCX3lhEjKFiK_nBKFygAAAdU"]
[Sun Aug 30 03:12:57.152071 2026] [security2:error] [pid 524122:tid 524324] [client 20.104.50.220:17285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/cyl.php"] [unique_id "apPmCX3lhEjKFiK_nBKFywAAAdY"]
[Sun Aug 30 03:12:57.157111 2026] [security2:error] [pid 521505:tid 521740] [client 20.48.160.90:23696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/luuf.php"] [unique_id "apPmCW8byYE0iXl--K6qWgAAA4c"]
[Sun Aug 30 03:12:57.165194 2026] [security2:error] [pid 524122:tid 524363] [client 20.104.50.220:5918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/123456.php"] [unique_id "apPmCX3lhEjKFiK_nBKFzAAAAf0"]
[Sun Aug 30 03:12:57.176185 2026] [security2:error] [pid 521505:tid 521747] [client 20.151.200.44:62983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/sxxb.php"] [unique_id "apPmCW8byYE0iXl--K6qXAAAA44"]
[Sun Aug 30 03:12:57.203453 2026] [security2:error] [pid 521505:tid 521642] [client 20.48.250.41:37846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/ws69.php"] [unique_id "apPmCW8byYE0iXl--K6qXgAAAyU"]
[Sun Aug 30 03:12:57.235880 2026] [security2:error] [pid 521505:tid 521650] [client 158.23.147.79:59009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "apPmCW8byYE0iXl--K6qYQAAAy0"]
[Sun Aug 30 03:12:57.242525 2026] [security2:error] [pid 521505:tid 521714] [client 20.151.200.44:52107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/admin.php/700.php"] [unique_id "apPmCW8byYE0iXl--K6qYgAAA20"]
[Sun Aug 30 03:12:57.243513 2026] [security2:error] [pid 521505:tid 521638] [client 52.139.37.240:46935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/xx.php"] [unique_id "apPmCW8byYE0iXl--K6qZAAAAyE"]
[Sun Aug 30 03:12:57.249466 2026] [authz_core:error] [pid 521505:tid 521695] [client 66.249.66.34:46207] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:57.249732 2026] [authz_core:error] [pid 521505:tid 521695] [client 66.249.66.34:46207] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:57.274347 2026] [security2:error] [pid 521505:tid 521648] [client 4.205.62.107:16808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/dd.php"] [unique_id "apPmCW8byYE0iXl--K6qZwAAAys"]
[Sun Aug 30 03:12:57.286695 2026] [security2:error] [pid 524122:tid 524261] [client 20.48.160.90:50364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/eagle.php"] [unique_id "apPmCX3lhEjKFiK_nBKFzQAAAZc"]
[Sun Aug 30 03:12:57.290875 2026] [security2:error] [pid 521505:tid 521761] [client 20.48.160.90:23725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/fex.php"] [unique_id "apPmCW8byYE0iXl--K6qaAAAA5w"]
[Sun Aug 30 03:12:57.297205 2026] [security2:error] [pid 521505:tid 521510] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/apis/.env"] [unique_id "apPmCW8byYE0iXl--K6qawADTwQ"]
[Sun Aug 30 03:12:57.340025 2026] [security2:error] [pid 521505:tid 521649] [client 20.48.250.41:37863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/ccs.php"] [unique_id "apPmCW8byYE0iXl--K6qcQAAAyw"]
[Sun Aug 30 03:12:57.358815 2026] [authz_core:error] [pid 521505:tid 521674] [client 216.73.216.128:29934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:57.359068 2026] [authz_core:error] [pid 521505:tid 521674] [client 216.73.216.128:29934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:57.390114 2026] [security2:error] [pid 521505:tid 521708] [client 20.104.18.15:22525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/run.php"] [unique_id "apPmCW8byYE0iXl--K6qdwAAA2c"]
[Sun Aug 30 03:12:57.392407 2026] [security2:error] [pid 521505:tid 521666] [client 68.155.159.216:60933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apPmCW8byYE0iXl--K6qeAAAAz0"]
[Sun Aug 30 03:12:57.430685 2026] [security2:error] [pid 521505:tid 521688] [client 20.104.18.15:1965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/wp_blog_footer.php"] [unique_id "apPmCW8byYE0iXl--K6qfAAAA1M"]
[Sun Aug 30 03:12:57.438800 2026] [security2:error] [pid 521505:tid 521749] [client 52.139.37.240:9532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/file.php"] [unique_id "apPmCW8byYE0iXl--K6qfQAAA5A"]
[Sun Aug 30 03:12:57.441533 2026] [security2:error] [pid 521505:tid 521682] [client 20.48.160.90:29171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/l.php"] [unique_id "apPmCW8byYE0iXl--K6qfgAAA00"]
[Sun Aug 30 03:12:57.449283 2026] [security2:error] [pid 521505:tid 521655] [client 20.48.160.90:28799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/up-kon.php"] [unique_id "apPmCW8byYE0iXl--K6qgAAAAzI"]
[Sun Aug 30 03:12:57.451412 2026] [authz_core:error] [pid 521505:tid 521727] [client 216.73.216.128:26620] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:57.451666 2026] [authz_core:error] [pid 521505:tid 521727] [client 216.73.216.128:26620] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:57.456182 2026] [security2:error] [pid 521505:tid 521549] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/application/.env"] [unique_id "apPmCW8byYE0iXl--K6qhAADgSs"]
[Sun Aug 30 03:12:57.466377 2026] [security2:error] [pid 524122:tid 524380] [client 158.23.147.79:55366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-content/admin.php"] [unique_id "apPmCX3lhEjKFiK_nBKFzgAAAg4"]
[Sun Aug 30 03:12:57.482387 2026] [security2:error] [pid 521505:tid 521690] [client 20.197.61.180:11357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/goods.php"] [unique_id "apPmCW8byYE0iXl--K6qhQAAA1U"]
[Sun Aug 30 03:12:57.504832 2026] [security2:error] [pid 521505:tid 521561] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/app/.env"] [unique_id "apPmCW8byYE0iXl--K6qhwADYzc"]
[Sun Aug 30 03:12:57.505018 2026] [authz_core:error] [pid 521505:tid 521670] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory15
[Sun Aug 30 03:12:57.505327 2026] [authz_core:error] [pid 521505:tid 521670] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory15
[Sun Aug 30 03:12:57.512911 2026] [security2:error] [pid 521505:tid 521723] [client 20.48.250.41:37859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/mar.php"] [unique_id "apPmCW8byYE0iXl--K6qiQAAA3Y"]
[Sun Aug 30 03:12:57.524359 2026] [security2:error] [pid 521505:tid 521583] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/apps/.env"] [unique_id "apPmCW8byYE0iXl--K6qiwADYk0"]
[Sun Aug 30 03:12:57.546056 2026] [security2:error] [pid 521505:tid 521745] [client 4.205.62.107:15838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/sdsa.php"] [unique_id "apPmCW8byYE0iXl--K6qjQAAA4w"]
[Sun Aug 30 03:12:57.569107 2026] [authz_core:error] [pid 521505:tid 521701] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:57.569446 2026] [authz_core:error] [pid 521505:tid 521701] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:57.571753 2026] [security2:error] [pid 521505:tid 521715] [client 20.104.50.220:51549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/con7ext.php"] [unique_id "apPmCW8byYE0iXl--K6qjwAAA24"]
[Sun Aug 30 03:12:57.572555 2026] [security2:error] [pid 521505:tid 521640] [client 20.48.160.90:23684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/xr.php"] [unique_id "apPmCW8byYE0iXl--K6qkQAAAyM"]
[Sun Aug 30 03:12:57.591402 2026] [security2:error] [pid 521505:tid 521741] [client 20.48.160.90:23705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/tinny.php"] [unique_id "apPmCW8byYE0iXl--K6qkwAAA4g"]
[Sun Aug 30 03:12:57.592051 2026] [security2:error] [pid 521505:tid 521718] [client 20.104.50.220:62796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/index9.php"] [unique_id "apPmCW8byYE0iXl--K6qlAAAA3E"]
[Sun Aug 30 03:12:57.616347 2026] [security2:error] [pid 524122:tid 524353] [client 20.104.18.15:51173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/sign.php"] [unique_id "apPmCX3lhEjKFiK_nBKF0QAAAfM"]
[Sun Aug 30 03:12:57.621192 2026] [security2:error] [pid 521505:tid 521658] [client 20.104.50.220:32885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/doc.php"] [unique_id "apPmCW8byYE0iXl--K6qlQAAAzU"]
[Sun Aug 30 03:12:57.640134 2026] [security2:error] [pid 521505:tid 521758] [client 4.205.62.107:15988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/w.php"] [unique_id "apPmCW8byYE0iXl--K6qlwAAA5k"]
[Sun Aug 30 03:12:57.651993 2026] [security2:error] [pid 521505:tid 521740] [client 20.48.250.41:37854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/ccu.php"] [unique_id "apPmCW8byYE0iXl--K6qmAAAA4c"]
[Sun Aug 30 03:12:57.653528 2026] [security2:error] [pid 524122:tid 524307] [client 20.104.50.220:25438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/inputs.php"] [unique_id "apPmCX3lhEjKFiK_nBKF0gAAAcU"]
[Sun Aug 30 03:12:57.685254 2026] [security2:error] [pid 521505:tid 521672] [client 52.139.37.240:46942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/dropdown.php"] [unique_id "apPmCW8byYE0iXl--K6qnAAAA0M"]
[Sun Aug 30 03:12:57.712422 2026] [security2:error] [pid 521505:tid 521700] [client 20.48.160.90:23681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/Q3.php"] [unique_id "apPmCW8byYE0iXl--K6qnwAAA18"]
[Sun Aug 30 03:12:57.727868 2026] [security2:error] [pid 524122:tid 524376] [client 20.48.160.90:28765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp-easy.php"] [unique_id "apPmCX3lhEjKFiK_nBKF1AAAAgo"]
[Sun Aug 30 03:12:57.755515 2026] [security2:error] [pid 521505:tid 521648] [client 4.205.62.107:32497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/saiga.php"] [unique_id "apPmCW8byYE0iXl--K6qowAAAys"]
[Sun Aug 30 03:12:57.783048 2026] [security2:error] [pid 521505:tid 521684] [client 158.23.147.79:55396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/xmlrpc.php"] [unique_id "apPmCW8byYE0iXl--K6qpgAAA08"]
[Sun Aug 30 03:12:57.803764 2026] [authz_core:error] [pid 524122:tid 524310] [client 66.249.66.69:61656] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:57.804214 2026] [authz_core:error] [pid 524122:tid 524310] [client 66.249.66.69:61656] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:57.805930 2026] [security2:error] [pid 524122:tid 524354] [client 20.48.250.41:37795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/ak.php"] [unique_id "apPmCX3lhEjKFiK_nBKF2AAAAfQ"]
[Sun Aug 30 03:12:57.816217 2026] [security2:error] [pid 524122:tid 524302] [client 20.48.251.3:65472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/kedi.php"] [unique_id "apPmCX3lhEjKFiK_nBKF2QAAAcA"]
[Sun Aug 30 03:12:57.830200 2026] [security2:error] [pid 521505:tid 521668] [client 4.205.62.107:29172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/goods.php"] [unique_id "apPmCW8byYE0iXl--K6qqAAAAz8"]
[Sun Aug 30 03:12:57.857105 2026] [security2:error] [pid 524122:tid 524369] [client 20.48.160.90:28794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/Q1.php"] [unique_id "apPmCX3lhEjKFiK_nBKF2gAAAgM"]
[Sun Aug 30 03:12:57.869413 2026] [security2:error] [pid 521505:tid 521639] [client 20.48.160.90:50392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/d7.php"] [unique_id "apPmCW8byYE0iXl--K6qqgAAAyI"]
[Sun Aug 30 03:12:57.883937 2026] [security2:error] [pid 524122:tid 524269] [client 52.139.37.240:46924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/xxx.php"] [unique_id "apPmCX3lhEjKFiK_nBKF2wAAAZ8"]
[Sun Aug 30 03:12:57.885186 2026] [security2:error] [pid 521505:tid 521725] [client 20.104.50.220:31219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/inputs.php"] [unique_id "apPmCW8byYE0iXl--K6qqwAAA3g"]
[Sun Aug 30 03:12:57.947640 2026] [security2:error] [pid 524122:tid 524264] [client 20.48.251.3:37035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/temp.php"] [unique_id "apPmCX3lhEjKFiK_nBKF3AAAAZo"]
[Sun Aug 30 03:12:57.969471 2026] [security2:error] [pid 521505:tid 521679] [client 158.23.147.79:55401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/atomlib.php"] [unique_id "apPmCW8byYE0iXl--K6qrgAAA0o"]
[Sun Aug 30 03:12:57.975518 2026] [security2:error] [pid 521505:tid 521681] [client 20.104.50.220:29126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/herp.php"] [unique_id "apPmCW8byYE0iXl--K6qrwAAA0w"]
[Sun Aug 30 03:12:57.992478 2026] [security2:error] [pid 521505:tid 521654] [client 20.48.160.90:23796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/nz.php"] [unique_id "apPmCW8byYE0iXl--K6qsAAAAzE"]
[Sun Aug 30 03:12:58.003596 2026] [authz_core:error] [pid 521505:tid 521671] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory11
[Sun Aug 30 03:12:58.004056 2026] [authz_core:error] [pid 521505:tid 521671] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory11
[Sun Aug 30 03:12:58.006353 2026] [security2:error] [pid 521505:tid 521699] [client 20.48.160.90:29149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/v5.php"] [unique_id "apPmCm8byYE0iXl--K6qswAAA14"]
[Sun Aug 30 03:12:58.009857 2026] [security2:error] [pid 524122:tid 524358] [client 20.48.250.41:37788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/lib.php"] [unique_id "apPmCn3lhEjKFiK_nBKF3gAAAfg"]
[Sun Aug 30 03:12:58.011968 2026] [security2:error] [pid 521505:tid 521735] [client 20.104.50.220:59572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wsd.php"] [unique_id "apPmCm8byYE0iXl--K6qtAAAA4I"]
[Sun Aug 30 03:12:58.030967 2026] [authz_core:error] [pid 521505:tid 521713] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:58.031368 2026] [authz_core:error] [pid 521505:tid 521713] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:58.071405 2026] [security2:error] [pid 521505:tid 521734] [client 158.23.147.79:59042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/lv.php"] [unique_id "apPmCm8byYE0iXl--K6quQAAA4E"]
[Sun Aug 30 03:12:58.129511 2026] [security2:error] [pid 521505:tid 521662] [client 20.48.160.90:50371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/sg.php"] [unique_id "apPmCm8byYE0iXl--K6qvwAAAzk"]
[Sun Aug 30 03:12:58.139888 2026] [security2:error] [pid 524122:tid 524276] [client 20.48.160.90:50396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/az.php"] [unique_id "apPmCn3lhEjKFiK_nBKF4QAAAaY"]
[Sun Aug 30 03:12:58.153195 2026] [security2:error] [pid 524122:tid 524344] [client 52.139.37.240:46961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-includes/wp-includes_function.php"] [unique_id "apPmCn3lhEjKFiK_nBKF4wAAAeo"]
[Sun Aug 30 03:12:58.157788 2026] [authz_core:error] [pid 524122:tid 524318] [client 66.249.66.35:50848] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:58.158134 2026] [authz_core:error] [pid 524122:tid 524318] [client 66.249.66.35:50848] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:58.174190 2026] [security2:error] [pid 521505:tid 521742] [client 20.48.250.41:37763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/wp-style.php"] [unique_id "apPmCm8byYE0iXl--K6qwAAAA4k"]
[Sun Aug 30 03:12:58.181039 2026] [security2:error] [pid 521505:tid 521726] [client 20.197.61.180:11363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/m.php"] [unique_id "apPmCm8byYE0iXl--K6qwQAAA3k"]
[Sun Aug 30 03:12:58.183451 2026] [security2:error] [pid 521505:tid 521697] [client 20.48.251.3:52217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/dd.php"] [unique_id "apPmCm8byYE0iXl--K6qwwAAA1w"]
[Sun Aug 30 03:12:58.256369 2026] [security2:error] [pid 521505:tid 521674] [client 20.104.49.130:54152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/run.php"] [unique_id "apPmCm8byYE0iXl--K6qyAAAA0U"]
[Sun Aug 30 03:12:58.266363 2026] [security2:error] [pid 521505:tid 521745] [client 158.23.147.79:59066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-includes/Text/index.php"] [unique_id "apPmCm8byYE0iXl--K6qyQAAA4w"]
[Sun Aug 30 03:12:58.268483 2026] [security2:error] [pid 521505:tid 521727] [client 20.48.160.90:23707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/hypo.php"] [unique_id "apPmCm8byYE0iXl--K6qygAAA3o"]
[Sun Aug 30 03:12:58.288437 2026] [security2:error] [pid 521505:tid 521715] [client 20.48.160.90:23788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/js.php"] [unique_id "apPmCm8byYE0iXl--K6qywAAA24"]
[Sun Aug 30 03:12:58.289430 2026] [security2:error] [pid 524122:tid 524293] [client 20.104.50.220:17226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/alfav4.1-tesla.php"] [unique_id "apPmCn3lhEjKFiK_nBKF5gAAAbc"]
[Sun Aug 30 03:12:58.300891 2026] [security2:error] [pid 524122:tid 524327] [client 20.104.50.220:5491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/12345.php"] [unique_id "apPmCn3lhEjKFiK_nBKF5wAAAdk"]
[Sun Aug 30 03:12:58.322151 2026] [security2:error] [pid 521505:tid 521723] [client 91.224.92.32:62241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.92.224.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.1stsourcesecurity.com"] [uri "/wp-login.php"] [unique_id "apPmCm8byYE0iXl--K6qzgAAA3Y"]
[Sun Aug 30 03:12:58.328008 2026] [security2:error] [pid 521505:tid 521741] [client 20.48.250.41:37845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/browse.php"] [unique_id "apPmCm8byYE0iXl--K6qzwAAA4g"]
[Sun Aug 30 03:12:58.336169 2026] [security2:error] [pid 521505:tid 521683] [client 20.104.49.130:52458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/js.php"] [unique_id "apPmCm8byYE0iXl--K6q0QAAA04"]
[Sun Aug 30 03:12:58.352484 2026] [security2:error] [pid 521505:tid 521640] [client 52.139.37.240:46971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/admin/controller/extension/extension/ultra.php"] [unique_id "apPmCm8byYE0iXl--K6q0gAAAyM"]
[Sun Aug 30 03:12:58.371706 2026] [authz_core:error] [pid 521505:tid 521743] [client 216.73.216.128:57609] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:58.372148 2026] [authz_core:error] [pid 521505:tid 521743] [client 216.73.216.128:57609] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:58.406245 2026] [security2:error] [pid 521505:tid 521670] [client 20.48.160.90:28747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/Hd.php"] [unique_id "apPmCm8byYE0iXl--K6q3gAAA0E"]
[Sun Aug 30 03:12:58.408617 2026] [security2:error] [pid 524122:tid 524280] [client 4.205.62.107:16811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/wp-tem.php"] [unique_id "apPmCn3lhEjKFiK_nBKF6AAAAao"]
[Sun Aug 30 03:12:58.431467 2026] [security2:error] [pid 521505:tid 521672] [client 158.23.147.79:55393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/content.php"] [unique_id "apPmCm8byYE0iXl--K6q3wAAA0M"]
[Sun Aug 30 03:12:58.435601 2026] [security2:error] [pid 521505:tid 521701] [client 20.151.200.44:52100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/admin.php/007x.php"] [unique_id "apPmCm8byYE0iXl--K6q4AAAA2A"]
[Sun Aug 30 03:12:58.441177 2026] [security2:error] [pid 521505:tid 521762] [client 20.48.160.90:23787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/hd.php"] [unique_id "apPmCm8byYE0iXl--K6q4QAAA50"]
[Sun Aug 30 03:12:58.483100 2026] [security2:error] [pid 521505:tid 521714] [client 20.48.250.41:37873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/zoo.php"] [unique_id "apPmCm8byYE0iXl--K6q4gAAA20"]
[Sun Aug 30 03:12:58.499960 2026] [authz_core:error] [pid 521505:tid 521746] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory15
[Sun Aug 30 03:12:58.500239 2026] [authz_core:error] [pid 521505:tid 521746] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory15
[Sun Aug 30 03:12:58.531862 2026] [authz_core:error] [pid 521505:tid 521673] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:58.532144 2026] [authz_core:error] [pid 521505:tid 521673] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:58.544954 2026] [security2:error] [pid 521505:tid 521668] [client 20.48.160.90:50026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/im.php"] [unique_id "apPmCm8byYE0iXl--K6q6QAAAz8"]
[Sun Aug 30 03:12:58.552356 2026] [security2:error] [pid 521505:tid 521647] [client 20.104.18.15:22413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/new.php"] [unique_id "apPmCm8byYE0iXl--K6q7QAAAyo"]
[Sun Aug 30 03:12:58.565245 2026] [security2:error] [pid 521505:tid 521732] [client 68.155.159.216:60968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/file.php"] [unique_id "apPmCm8byYE0iXl--K6q8gAAA38"]
[Sun Aug 30 03:12:58.567659 2026] [security2:error] [pid 521505:tid 521661] [client 20.104.18.15:2001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/wefile.php"] [unique_id "apPmCm8byYE0iXl--K6q8wAAAzg"]
[Sun Aug 30 03:12:58.569979 2026] [security2:error] [pid 524122:tid 524286] [client 20.48.160.90:50380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/xl2023.php"] [unique_id "apPmCn3lhEjKFiK_nBKF7QAAAbA"]
[Sun Aug 30 03:12:58.588961 2026] [security2:error] [pid 521505:tid 521645] [client 52.139.37.240:46956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "apPmCm8byYE0iXl--K6q9AAAAyg"]
[Sun Aug 30 03:12:58.611885 2026] [security2:error] [pid 521505:tid 521744] [client 20.48.250.41:37806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/elp.php"] [unique_id "apPmCm8byYE0iXl--K6q9QAAA4s"]
[Sun Aug 30 03:12:58.624307 2026] [security2:error] [pid 521505:tid 521666] [client 158.23.147.79:55381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPmCm8byYE0iXl--K6q-QAAAz0"]
[Sun Aug 30 03:12:58.653283 2026] [security2:error] [pid 521505:tid 521576] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/back-end/.env"] [unique_id "apPmCm8byYE0iXl--K6q_gADNEY"]
[Sun Aug 30 03:12:58.655460 2026] [security2:error] [pid 521505:tid 521598] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/back-api/.env"] [unique_id "apPmCm8byYE0iXl--K6q_wADkFw"]
[Sun Aug 30 03:12:58.685696 2026] [security2:error] [pid 521505:tid 521759] [client 4.205.62.107:15840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/sale.php"] [unique_id "apPmCm8byYE0iXl--K6rAAAAA5o"]
[Sun Aug 30 03:12:58.701446 2026] [security2:error] [pid 521505:tid 521712] [client 91.224.92.32:62960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.92.224.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.1stsourcesecurity.com"] [uri "/wp-login.php"] [unique_id "apPmCm8byYE0iXl--K6rAQAAA2s"]
[Sun Aug 30 03:12:58.704380 2026] [security2:error] [pid 521505:tid 521563] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/back/.env"] [unique_id "apPmCm8byYE0iXl--K6rAwADlzk"]
[Sun Aug 30 03:12:58.705415 2026] [security2:error] [pid 521505:tid 521529] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/backend/.env"] [unique_id "apPmCm8byYE0iXl--K6rBQADlxc"]
[Sun Aug 30 03:12:58.706019 2026] [security2:error] [pid 521505:tid 521601] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/backend-api/.env"] [unique_id "apPmCm8byYE0iXl--K6rBAADl18"]
[Sun Aug 30 03:12:58.731996 2026] [security2:error] [pid 521505:tid 521719] [client 20.104.50.220:51558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/loader/ff.php"] [unique_id "apPmCm8byYE0iXl--K6rCQAAA3I"]
[Sun Aug 30 03:12:58.746654 2026] [authz_core:error] [pid 524122:tid 524350] [client 216.73.216.128:39258] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:58.746925 2026] [authz_core:error] [pid 524122:tid 524350] [client 216.73.216.128:39258] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:58.750800 2026] [security2:error] [pid 524122:tid 524315] [client 20.104.18.15:51105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/wnnjpsby.php"] [unique_id "apPmCn3lhEjKFiK_nBKF8QAAAc0"]
[Sun Aug 30 03:12:58.760587 2026] [security2:error] [pid 524122:tid 524254] [client 20.48.160.90:23721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/V2.php"] [unique_id "apPmCn3lhEjKFiK_nBKF8gAAAZA"]
[Sun Aug 30 03:12:58.761670 2026] [security2:error] [pid 521505:tid 521652] [client 20.48.160.90:23717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/fc.php"] [unique_id "apPmCm8byYE0iXl--K6rCwAAAy8"]
[Sun Aug 30 03:12:58.775905 2026] [security2:error] [pid 521505:tid 521687] [client 20.104.50.220:32910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/docindex.php"] [unique_id "apPmCm8byYE0iXl--K6rDQAAA1I"]
[Sun Aug 30 03:12:58.778796 2026] [security2:error] [pid 521505:tid 521641] [client 4.205.62.107:15810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/btx25.php"] [unique_id "apPmCm8byYE0iXl--K6rDgAAAyQ"]
[Sun Aug 30 03:12:58.788170 2026] [security2:error] [pid 521505:tid 521692] [client 20.48.250.41:37771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/666.php"] [unique_id "apPmCm8byYE0iXl--K6rDwAAA1c"]
[Sun Aug 30 03:12:58.797575 2026] [security2:error] [pid 524122:tid 524348] [client 52.139.37.240:46945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-admin/network/about.php"] [unique_id "apPmCn3lhEjKFiK_nBKF8wAAAe4"]
[Sun Aug 30 03:12:58.822041 2026] [security2:error] [pid 524122:tid 524272] [client 20.104.50.220:29120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/indeex.php"] [unique_id "apPmCn3lhEjKFiK_nBKF9AAAAaI"]
[Sun Aug 30 03:12:58.834057 2026] [security2:error] [pid 521505:tid 521745] [client 158.23.147.79:59039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/goat.php"] [unique_id "apPmCm8byYE0iXl--K6rEQAAA4w"]
[Sun Aug 30 03:12:58.842166 2026] [security2:error] [pid 521505:tid 521711] [client 20.104.49.130:59551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/kgoc6awap3napxxxdCdefault.php"] [unique_id "apPmCm8byYE0iXl--K6rEgAAA2o"]
[Sun Aug 30 03:12:58.858319 2026] [security2:error] [pid 521505:tid 521689] [client 20.104.50.220:24927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/av.php"] [unique_id "apPmCm8byYE0iXl--K6rEwAAA1Q"]
[Sun Aug 30 03:12:58.903750 2026] [security2:error] [pid 524122:tid 524257] [client 20.48.160.90:28737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/ke.php"] [unique_id "apPmCn3lhEjKFiK_nBKF9QAAAZM"]
[Sun Aug 30 03:12:58.904242 2026] [security2:error] [pid 524122:tid 524283] [client 20.48.160.90:28754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/mad.php"] [unique_id "apPmCn3lhEjKFiK_nBKF9gAAAa0"]
[Sun Aug 30 03:12:58.922047 2026] [security2:error] [pid 521505:tid 521724] [client 20.197.61.180:19204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/doc.php"] [unique_id "apPmCm8byYE0iXl--K6rFgAAA3c"]
[Sun Aug 30 03:12:58.930355 2026] [authz_core:error] [pid 524122:tid 524336] [client 216.73.216.128:39258] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:58.930617 2026] [authz_core:error] [pid 524122:tid 524336] [client 216.73.216.128:39258] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:58.955761 2026] [security2:error] [pid 521505:tid 521640] [client 20.48.251.3:46150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/oc460l3x.php"] [unique_id "apPmCm8byYE0iXl--K6rFwAAAyM"]
[Sun Aug 30 03:12:58.960584 2026] [security2:error] [pid 524122:tid 524333] [client 20.48.250.41:37765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/knmt.php"] [unique_id "apPmCn3lhEjKFiK_nBKF-AAAAd8"]
[Sun Aug 30 03:12:58.970232 2026] [authz_core:error] [pid 521505:tid 521667] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory11
[Sun Aug 30 03:12:58.970545 2026] [authz_core:error] [pid 521505:tid 521667] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory11
[Sun Aug 30 03:12:58.981527 2026] [security2:error] [pid 524122:tid 524373] [client 158.23.147.79:55367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "apPmCn3lhEjKFiK_nBKF-gAAAgc"]
[Sun Aug 30 03:12:58.982377 2026] [security2:error] [pid 524122:tid 524320] [client 4.205.62.107:32031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/ammika.php"] [unique_id "apPmCn3lhEjKFiK_nBKF-wAAAdI"]
[Sun Aug 30 03:12:58.990462 2026] [security2:error] [pid 524122:tid 524314] [client 20.151.200.44:62979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/dx.php"] [unique_id "apPmCn3lhEjKFiK_nBKF_AAAAcw"]
[Sun Aug 30 03:12:58.999807 2026] [authz_core:error] [pid 521505:tid 521705] [client 66.249.66.34:46207] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:59.000072 2026] [authz_core:error] [pid 521505:tid 521705] [client 66.249.66.34:46207] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:59.006500 2026] [security2:error] [pid 521505:tid 521636] [client 4.205.62.107:52885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/loxi-o.php"] [unique_id "apPmC28byYE0iXl--K6rHAAAAx8"]
[Sun Aug 30 03:12:59.035687 2026] [security2:error] [pid 521505:tid 521706] [client 52.139.37.240:46925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/xpw.php"] [unique_id "apPmC28byYE0iXl--K6rHwAAA2U"]
[Sun Aug 30 03:12:59.035687 2026] [security2:error] [pid 524122:tid 524378] [client 20.104.50.220:59362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/about.php"] [unique_id "apPmC33lhEjKFiK_nBKF_gAAAgw"]
[Sun Aug 30 03:12:59.043528 2026] [security2:error] [pid 524122:tid 524308] [client 20.48.160.90:28753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/st.php"] [unique_id "apPmC33lhEjKFiK_nBKF_wAAAcY"]
[Sun Aug 30 03:12:59.049424 2026] [security2:error] [pid 524122:tid 524259] [client 20.48.160.90:23718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/tf.php"] [unique_id "apPmC33lhEjKFiK_nBKGAAAAAZU"]
[Sun Aug 30 03:12:59.075361 2026] [authz_core:error] [pid 521505:tid 521702] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:59.075773 2026] [authz_core:error] [pid 521505:tid 521702] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:59.084429 2026] [security2:error] [pid 521505:tid 521693] [client 20.48.251.3:36805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/fm.php"] [unique_id "apPmC28byYE0iXl--K6rIwAAA1g"]
[Sun Aug 30 03:12:59.093841 2026] [security2:error] [pid 521505:tid 521760] [client 20.48.250.41:37877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/sbhu.php"] [unique_id "apPmC28byYE0iXl--K6rJAAAA5s"]
[Sun Aug 30 03:12:59.115942 2026] [security2:error] [pid 521505:tid 521701] [client 20.104.49.130:63506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/srontol.php"] [unique_id "apPmC28byYE0iXl--K6rJgAAA2A"]
[Sun Aug 30 03:12:59.170133 2026] [security2:error] [pid 521505:tid 521714] [client 20.104.50.220:52854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/nptice.php"] [unique_id "apPmC28byYE0iXl--K6rJwAAA20"]
[Sun Aug 30 03:12:59.174453 2026] [security2:error] [pid 521505:tid 521643] [client 20.104.50.220:59564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/f6.php"] [unique_id "apPmC28byYE0iXl--K6rKAAAAyY"]
[Sun Aug 30 03:12:59.176342 2026] [security2:error] [pid 521505:tid 521739] [client 20.48.160.90:50408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/alfanew.php"] [unique_id "apPmC28byYE0iXl--K6rKQAAA4Y"]
[Sun Aug 30 03:12:59.179049 2026] [security2:error] [pid 524122:tid 524346] [client 20.48.160.90:29129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/px.php"] [unique_id "apPmC33lhEjKFiK_nBKGBAAAAew"]
[Sun Aug 30 03:12:59.242904 2026] [security2:error] [pid 524122:tid 524262] [client 52.139.37.240:46964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-cron.php"] [unique_id "apPmC33lhEjKFiK_nBKGBgAAAZg"]
[Sun Aug 30 03:12:59.249862 2026] [security2:error] [pid 524122:tid 524323] [client 20.48.250.41:37777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/a332.php"] [unique_id "apPmC33lhEjKFiK_nBKGBwAAAdU"]
[Sun Aug 30 03:12:59.264317 2026] [security2:error] [pid 524122:tid 524305] [client 158.23.147.79:55379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-content/uploads/about.php"] [unique_id "apPmC33lhEjKFiK_nBKGCAAAAcM"]
[Sun Aug 30 03:12:59.276608 2026] [security2:error] [pid 521505:tid 521550] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/beta/.env"] [unique_id "apPmC28byYE0iXl--K6rLgADcCw"]
[Sun Aug 30 03:12:59.301540 2026] [security2:error] [pid 521505:tid 521691] [client 20.104.49.130:52458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wdfjba.org"] [uri "/wsd.php"] [unique_id "apPmC28byYE0iXl--K6rMQAAA1Y"]
[Sun Aug 30 03:12:59.309099 2026] [security2:error] [pid 521505:tid 521654] [client 20.48.160.90:28792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/ioxi.php"] [unique_id "apPmC28byYE0iXl--K6rMwAAAzE"]
[Sun Aug 30 03:12:59.309540 2026] [security2:error] [pid 521505:tid 521635] [client 20.48.160.90:28767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/jg.php"] [unique_id "apPmC28byYE0iXl--K6rNAAAAx4"]
[Sun Aug 30 03:12:59.323375 2026] [security2:error] [pid 521505:tid 521710] [client 20.48.251.3:43033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-tem.php"] [unique_id "apPmC28byYE0iXl--K6rNQAAA2k"]
[Sun Aug 30 03:12:59.398432 2026] [security2:error] [pid 521505:tid 521759] [client 20.48.250.41:37847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/ws66.php"] [unique_id "apPmC28byYE0iXl--K6rPAAAA5o"]
[Sun Aug 30 03:12:59.427844 2026] [security2:error] [pid 521505:tid 521756] [client 20.104.50.220:16633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/-.php"] [unique_id "apPmC28byYE0iXl--K6rPQAAA5c"]
[Sun Aug 30 03:12:59.443104 2026] [security2:error] [pid 521505:tid 521699] [client 20.48.160.90:49994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/TNT.php"] [unique_id "apPmC28byYE0iXl--K6rQAAAA14"]
[Sun Aug 30 03:12:59.443223 2026] [security2:error] [pid 521505:tid 521736] [client 20.104.50.220:5463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/1234.php"] [unique_id "apPmC28byYE0iXl--K6rQQAAA4M"]
[Sun Aug 30 03:12:59.454948 2026] [security2:error] [pid 524122:tid 524353] [client 20.48.160.90:50425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/yj.php"] [unique_id "apPmC33lhEjKFiK_nBKGDQAAAfM"]
[Sun Aug 30 03:12:59.463249 2026] [authz_core:error] [pid 521505:tid 521679] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory15
[Sun Aug 30 03:12:59.463545 2026] [authz_core:error] [pid 521505:tid 521679] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory15
[Sun Aug 30 03:12:59.491753 2026] [security2:error] [pid 521505:tid 521662] [client 158.23.147.79:55406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-admin/maint/index.php"] [unique_id "apPmC28byYE0iXl--K6rRAAAAzk"]
[Sun Aug 30 03:12:59.513753 2026] [security2:error] [pid 521505:tid 521712] [client 52.139.37.240:49703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/cong.php"] [unique_id "apPmC28byYE0iXl--K6rRQAAA2s"]
[Sun Aug 30 03:12:59.527463 2026] [authz_core:error] [pid 521505:tid 521665] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:59.527740 2026] [authz_core:error] [pid 521505:tid 521665] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:12:59.547337 2026] [security2:error] [pid 521505:tid 521726] [client 4.205.62.107:17436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/txets.php"] [unique_id "apPmC28byYE0iXl--K6rSQAAA3k"]
[Sun Aug 30 03:12:59.559680 2026] [security2:error] [pid 524122:tid 524371] [client 20.48.250.41:37886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/ws68.php"] [unique_id "apPmC33lhEjKFiK_nBKGDwAAAgU"]
[Sun Aug 30 03:12:59.566402 2026] [authz_core:error] [pid 524122:tid 524372] [client 66.249.66.193:37933] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:59.566654 2026] [authz_core:error] [pid 524122:tid 524372] [client 66.249.66.193:37933] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:59.572853 2026] [security2:error] [pid 524122:tid 524376] [client 20.48.160.90:50333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/cd.php"] [unique_id "apPmC33lhEjKFiK_nBKGEAAAAgo"]
[Sun Aug 30 03:12:59.595068 2026] [security2:error] [pid 521505:tid 521728] [client 20.48.160.90:49926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/zi.php"] [unique_id "apPmC28byYE0iXl--K6rTQAAA3s"]
[Sun Aug 30 03:12:59.665865 2026] [security2:error] [pid 521505:tid 521680] [client 20.197.61.180:1643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/users.php"] [unique_id "apPmC28byYE0iXl--K6rUAAAA0s"]
[Sun Aug 30 03:12:59.690846 2026] [security2:error] [pid 524122:tid 524316] [client 20.104.18.15:22497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/vpn.php"] [unique_id "apPmC33lhEjKFiK_nBKGEwAAAc4"]
[Sun Aug 30 03:12:59.706792 2026] [security2:error] [pid 524122:tid 524264] [client 20.104.18.15:1945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/wp-load.php"] [unique_id "apPmC33lhEjKFiK_nBKGFAAAAZo"]
[Sun Aug 30 03:12:59.707232 2026] [security2:error] [pid 524122:tid 524298] [client 20.48.250.41:37881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/users.php"] [unique_id "apPmC33lhEjKFiK_nBKGFQAAAbw"]
[Sun Aug 30 03:12:59.728581 2026] [security2:error] [pid 524122:tid 524329] [client 20.48.160.90:49938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/luuf.php"] [unique_id "apPmC33lhEjKFiK_nBKGFgAAAds"]
[Sun Aug 30 03:12:59.734088 2026] [security2:error] [pid 521505:tid 521745] [client 52.139.37.240:49697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/Sanskrit.php"] [unique_id "apPmC28byYE0iXl--K6rVQAAA4w"]
[Sun Aug 30 03:12:59.739600 2026] [security2:error] [pid 521505:tid 521698] [client 68.155.159.216:60288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/file17.php"] [unique_id "apPmC28byYE0iXl--K6rVwAAA10"]
[Sun Aug 30 03:12:59.741919 2026] [security2:error] [pid 521505:tid 521723] [client 20.48.160.90:49943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/ue.php"] [unique_id "apPmC28byYE0iXl--K6rWAAAA3Y"]
[Sun Aug 30 03:12:59.748695 2026] [security2:error] [pid 521505:tid 521597] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/backup/.env"] [unique_id "apPmC28byYE0iXl--K6rWgADiFs"]
[Sun Aug 30 03:12:59.755716 2026] [authz_core:error] [pid 521505:tid 521718] [client 216.73.216.128:29934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:12:59.756005 2026] [authz_core:error] [pid 521505:tid 521718] [client 216.73.216.128:29934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:12:59.778396 2026] [security2:error] [pid 524122:tid 524334] [client 158.23.147.79:59029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/dropdown.php"] [unique_id "apPmC33lhEjKFiK_nBKGGQAAAeA"]
[Sun Aug 30 03:12:59.810396 2026] [security2:error] [pid 521505:tid 521616] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/cms/.env"] [unique_id "apPmC28byYE0iXl--K6rWwADRm4"]
[Sun Aug 30 03:12:59.813538 2026] [security2:error] [pid 521505:tid 521611] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/be/.env"] [unique_id "apPmC28byYE0iXl--K6rXAADI2k"]
[Sun Aug 30 03:12:59.821066 2026] [security2:error] [pid 524122:tid 524343] [client 4.205.62.107:16372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/wp-class.php"] [unique_id "apPmC33lhEjKFiK_nBKGGgAAAek"]
[Sun Aug 30 03:12:59.852095 2026] [security2:error] [pid 521505:tid 521672] [client 20.48.250.41:37844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/bzjdlofz.php"] [unique_id "apPmC28byYE0iXl--K6rYwAAA0M"]
[Sun Aug 30 03:12:59.864172 2026] [security2:error] [pid 524122:tid 524255] [client 20.48.160.90:23769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/fex.php"] [unique_id "apPmC33lhEjKFiK_nBKGGwAAAZE"]
[Sun Aug 30 03:12:59.869890 2026] [security2:error] [pid 524122:tid 524321] [client 20.104.50.220:42038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/dbx.php"] [unique_id "apPmC33lhEjKFiK_nBKGHAAAAdM"]
[Sun Aug 30 03:12:59.872780 2026] [security2:error] [pid 524122:tid 524291] [client 20.48.160.90:50324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/nv.php"] [unique_id "apPmC33lhEjKFiK_nBKGHQAAAbU"]
[Sun Aug 30 03:12:59.889872 2026] [security2:error] [pid 521505:tid 521701] [client 20.151.200.44:52151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/admin.php/heex.php"] [unique_id "apPmC28byYE0iXl--K6rZQAAA2A"]
[Sun Aug 30 03:12:59.901365 2026] [security2:error] [pid 524122:tid 524335] [client 20.104.18.15:51113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/gigi.php"] [unique_id "apPmC33lhEjKFiK_nBKGHgAAAeE"]
[Sun Aug 30 03:12:59.916666 2026] [security2:error] [pid 521505:tid 521667] [client 4.205.62.107:16361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/app_dev.php"] [unique_id "apPmC28byYE0iXl--K6rZwAAAz4"]
[Sun Aug 30 03:12:59.926076 2026] [security2:error] [pid 521505:tid 521650] [client 20.151.200.44:55692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.americanqualityhomeinspections.com"] [uri "/ssh3ll.php"] [unique_id "apPmC28byYE0iXl--K6raAAAAy0"]
[Sun Aug 30 03:12:59.927488 2026] [security2:error] [pid 524122:tid 524366] [client 52.139.37.240:49699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/ms-edit.php"] [unique_id "apPmC33lhEjKFiK_nBKGHwAAAgA"]
[Sun Aug 30 03:12:59.927587 2026] [security2:error] [pid 524122:tid 524325] [client 20.104.50.220:33560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/dosya.php"] [unique_id "apPmC33lhEjKFiK_nBKGIAAAAdc"]
[Sun Aug 30 03:12:59.928712 2026] [security2:error] [pid 524122:tid 524293] [client 216.73.216.128:39258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPmC33lhEjKFiK_nBKGIQAAAbc"]
[Sun Aug 30 03:12:59.998205 2026] [authz_core:error] [pid 521505:tid 521755] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory11
[Sun Aug 30 03:12:59.998612 2026] [authz_core:error] [pid 521505:tid 521755] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory11
[Sun Aug 30 03:13:00.004339 2026] [security2:error] [pid 524122:tid 524362] [client 20.48.160.90:50363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/jw.php"] [unique_id "apPmDH3lhEjKFiK_nBKGIgAAAfw"]
[Sun Aug 30 03:13:00.009664 2026] [security2:error] [pid 521505:tid 521729] [client 20.48.160.90:28764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/l.php"] [unique_id "apPmDG8byYE0iXl--K6rbwAAA3w"]
[Sun Aug 30 03:13:00.010343 2026] [security2:error] [pid 524122:tid 524288] [client 158.23.147.79:59050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/sad/about.php"] [unique_id "apPmDH3lhEjKFiK_nBKGIwAAAbI"]
[Sun Aug 30 03:13:00.010543 2026] [security2:error] [pid 521505:tid 521638] [client 20.104.50.220:24890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/classwithtostring.php"] [unique_id "apPmDG8byYE0iXl--K6rcAAAAyE"]
[Sun Aug 30 03:13:00.022651 2026] [security2:error] [pid 524122:tid 524355] [client 20.48.250.41:37760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/selesai.php"] [unique_id "apPmDH3lhEjKFiK_nBKGJAAAAfU"]
[Sun Aug 30 03:13:00.025136 2026] [security2:error] [pid 524122:tid 524364] [client 20.151.200.44:45971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/tf.php"] [unique_id "apPmDH3lhEjKFiK_nBKGJQAAAf4"]
[Sun Aug 30 03:13:00.054650 2026] [authz_core:error] [pid 521505:tid 521731] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:00.054953 2026] [authz_core:error] [pid 521505:tid 521731] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:00.112639 2026] [security2:error] [pid 521505:tid 521677] [client 216.73.216.128:57609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mysqlupgrade"] [unique_id "apPmDG8byYE0iXl--K6rdQAAA0g"]
[Sun Aug 30 03:13:00.114994 2026] [security2:error] [pid 521505:tid 521717] [client 4.205.62.107:32018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/broadcasting.php"] [unique_id "apPmDG8byYE0iXl--K6rdgAAA3A"]
[Sun Aug 30 03:13:00.124504 2026] [security2:error] [pid 521505:tid 521708] [client 20.48.251.3:46227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/drykl.php"] [unique_id "apPmDG8byYE0iXl--K6rdwAAA2c"]
[Sun Aug 30 03:13:00.135412 2026] [authz_core:error] [pid 521505:tid 521659] [client 66.249.66.33:61550] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:00.135928 2026] [authz_core:error] [pid 521505:tid 521659] [client 66.249.66.33:61550] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:00.153876 2026] [security2:error] [pid 521505:tid 521688] [client 20.48.160.90:23799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/or.php"] [unique_id "apPmDG8byYE0iXl--K6rewAAA1M"]
[Sun Aug 30 03:13:00.154231 2026] [security2:error] [pid 521505:tid 521622] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/config/.env"] [unique_id "apPmDG8byYE0iXl--K6regADHnQ"]
[Sun Aug 30 03:13:00.154522 2026] [security2:error] [pid 521505:tid 521752] [client 20.48.160.90:50017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/xr.php"] [unique_id "apPmDG8byYE0iXl--K6rfAAAA5M"]
[Sun Aug 30 03:13:00.155778 2026] [security2:error] [pid 521505:tid 521673] [client 158.23.147.79:59063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/admin.php"] [unique_id "apPmDG8byYE0iXl--K6rfQAAA0Q"]
[Sun Aug 30 03:13:00.155791 2026] [security2:error] [pid 521505:tid 521746] [client 4.205.62.107:29167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/f35.php"] [unique_id "apPmDG8byYE0iXl--K6rfgAAA40"]
[Sun Aug 30 03:13:00.173220 2026] [security2:error] [pid 524122:tid 524322] [client 20.104.50.220:63223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/alfa.php"] [unique_id "apPmDH3lhEjKFiK_nBKGJwAAAdQ"]
[Sun Aug 30 03:13:00.188967 2026] [security2:error] [pid 524122:tid 524284] [client 52.139.37.240:49684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/function.php"] [unique_id "apPmDH3lhEjKFiK_nBKGKAAAAa4"]
[Sun Aug 30 03:13:00.196999 2026] [security2:error] [pid 521505:tid 521734] [client 20.48.250.41:37827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/shlo.php"] [unique_id "apPmDG8byYE0iXl--K6rgAAAA4E"]
[Sun Aug 30 03:13:00.209921 2026] [security2:error] [pid 521505:tid 521736] [client 20.104.50.220:52837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/jindex.php"] [unique_id "apPmDG8byYE0iXl--K6rggAAA4M"]
[Sun Aug 30 03:13:00.222603 2026] [security2:error] [pid 521505:tid 521662] [client 20.48.251.3:36996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/tinyfilemanager.php"] [unique_id "apPmDG8byYE0iXl--K6rgwAAAzk"]
[Sun Aug 30 03:13:00.325141 2026] [security2:error] [pid 521505:tid 521692] [client 158.23.147.79:59057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-admin/admin.php"] [unique_id "apPmDG8byYE0iXl--K6riAAAA1c"]
[Sun Aug 30 03:13:00.344221 2026] [security2:error] [pid 521505:tid 521703] [client 20.48.250.41:37887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/asax.php"] [unique_id "apPmDG8byYE0iXl--K6riQAAA2I"]
[Sun Aug 30 03:13:00.366332 2026] [security2:error] [pid 524122:tid 524270] [client 20.104.50.220:61985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/he.php"] [unique_id "apPmDH3lhEjKFiK_nBKGKQAAAaA"]
[Sun Aug 30 03:13:00.387276 2026] [security2:error] [pid 521505:tid 521665] [client 20.104.50.220:29133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/tuyul.php"] [unique_id "apPmDG8byYE0iXl--K6rjQAAAzw"]
[Sun Aug 30 03:13:00.391899 2026] [authz_core:error] [pid 521505:tid 521735] [client 216.73.216.128:27728] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:00.392171 2026] [authz_core:error] [pid 521505:tid 521735] [client 216.73.216.128:27728] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:00.397866 2026] [security2:error] [pid 521505:tid 521710] [client 20.197.61.180:19245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/class.php"] [unique_id "apPmDG8byYE0iXl--K6rjwAAA2k"]
[Sun Aug 30 03:13:00.422463 2026] [security2:error] [pid 521505:tid 521664] [client 52.139.37.240:46937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/send.php"] [unique_id "apPmDG8byYE0iXl--K6rkQAAAzs"]
[Sun Aug 30 03:13:00.463750 2026] [security2:error] [pid 524122:tid 524272] [client 20.104.49.130:63279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/ms-edit.php"] [unique_id "apPmDH3lhEjKFiK_nBKGKgAAAaI"]
[Sun Aug 30 03:13:00.471931 2026] [security2:error] [pid 524122:tid 524352] [client 20.48.251.3:59491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/txets.php"] [unique_id "apPmDH3lhEjKFiK_nBKGKwAAAfI"]
[Sun Aug 30 03:13:00.476691 2026] [authz_core:error] [pid 521505:tid 521723] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory15
[Sun Aug 30 03:13:00.476975 2026] [authz_core:error] [pid 521505:tid 521723] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory15
[Sun Aug 30 03:13:00.487018 2026] [security2:error] [pid 524122:tid 524350] [client 20.48.250.41:37829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/fetch.php"] [unique_id "apPmDH3lhEjKFiK_nBKGLAAAAfA"]
[Sun Aug 30 03:13:00.522989 2026] [authz_core:error] [pid 521505:tid 521675] [client 66.249.66.37:35793] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:00.523443 2026] [authz_core:error] [pid 521505:tid 521675] [client 66.249.66.37:35793] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:00.532796 2026] [security2:error] [pid 521505:tid 521579] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/client/.env"] [unique_id "apPmDG8byYE0iXl--K6rmQADI0k"]
[Sun Aug 30 03:13:00.541285 2026] [security2:error] [pid 521505:tid 521520] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/config/aws.php"] [unique_id "apPmDG8byYE0iXl--K6rmgADUQ4"]
[Sun Aug 30 03:13:00.553624 2026] [authz_core:error] [pid 521505:tid 521636] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:00.553915 2026] [authz_core:error] [pid 521505:tid 521636] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:00.565144 2026] [security2:error] [pid 521505:tid 521651] [client 20.104.50.220:17311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/fx.php"] [unique_id "apPmDG8byYE0iXl--K6rnQAAAy4"]
[Sun Aug 30 03:13:00.601051 2026] [security2:error] [pid 521505:tid 521666] [client 20.104.50.220:5939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/10.php"] [unique_id "apPmDG8byYE0iXl--K6roQAAAz0"]
[Sun Aug 30 03:13:00.627900 2026] [security2:error] [pid 521505:tid 521701] [client 20.48.250.41:37884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/vx.php"] [unique_id "apPmDG8byYE0iXl--K6rogAAA2A"]
[Sun Aug 30 03:13:00.681415 2026] [security2:error] [pid 521505:tid 521556] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/config/config.inc.php"] [unique_id "apPmDG8byYE0iXl--K6rpgADNTI"]
[Sun Aug 30 03:13:00.683353 2026] [security2:error] [pid 521505:tid 521714] [client 4.205.62.107:17469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/time.php"] [unique_id "apPmDG8byYE0iXl--K6rpwAAA20"]
[Sun Aug 30 03:13:00.695941 2026] [security2:error] [pid 521505:tid 521737] [client 52.139.37.240:49702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/mar.php"] [unique_id "apPmDG8byYE0iXl--K6rqQAAA4Q"]
[Sun Aug 30 03:13:00.708665 2026] [security2:error] [pid 521505:tid 521553] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/config/config.php"] [unique_id "apPmDG8byYE0iXl--K6rqwADhi8"]
[Sun Aug 30 03:13:00.775723 2026] [security2:error] [pid 521505:tid 521668] [client 20.48.250.41:37702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/global.php"] [unique_id "apPmDG8byYE0iXl--K6rsQAAAz8"]
[Sun Aug 30 03:13:00.780992 2026] [security2:error] [pid 524122:tid 524370] [client 158.23.147.79:52727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apPmDH3lhEjKFiK_nBKGLwAAAgQ"]
[Sun Aug 30 03:13:00.786757 2026] [security2:error] [pid 521505:tid 521642] [client 20.151.200.44:63015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPmDG8byYE0iXl--K6rsgAAAyU"]
[Sun Aug 30 03:13:00.791429 2026] [security2:error] [pid 521505:tid 521510] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/config.php"] [unique_id "apPmDG8byYE0iXl--K6rswADfQQ"]
[Sun Aug 30 03:13:00.808399 2026] [security2:error] [pid 524122:tid 524277] [client 20.151.200.44:43931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ermes-it.it"] [uri "/txets.php"] [unique_id "apPmDH3lhEjKFiK_nBKGMAAAAac"]
[Sun Aug 30 03:13:00.822848 2026] [security2:error] [pid 521505:tid 521732] [client 20.104.18.15:22491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/goods.php"] [unique_id "apPmDG8byYE0iXl--K6rtgAAA38"]
[Sun Aug 30 03:13:00.843501 2026] [authz_core:error] [pid 521505:tid 521645] [client 66.249.66.66:38722] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:00.843855 2026] [authz_core:error] [pid 521505:tid 521645] [client 66.249.66.66:38722] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:00.852549 2026] [security2:error] [pid 524122:tid 524314] [client 68.155.159.216:60956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/file5.php"] [unique_id "apPmDH3lhEjKFiK_nBKGMgAAAcw"]
[Sun Aug 30 03:13:00.857285 2026] [security2:error] [pid 524122:tid 524341] [client 20.104.18.15:1928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/robot.php"] [unique_id "apPmDH3lhEjKFiK_nBKGMwAAAec"]
[Sun Aug 30 03:13:00.901665 2026] [security2:error] [pid 521505:tid 521633] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/config/nexmo.php"] [unique_id "apPmDG8byYE0iXl--K6rvQADTH8"]
[Sun Aug 30 03:13:00.922613 2026] [security2:error] [pid 521505:tid 521746] [client 20.48.250.41:37825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/fs.php"] [unique_id "apPmDG8byYE0iXl--K6rwAAAA40"]
[Sun Aug 30 03:13:00.930970 2026] [security2:error] [pid 521505:tid 521733] [client 52.139.37.240:46921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/ee.php"] [unique_id "apPmDG8byYE0iXl--K6rwQAAA4A"]
[Sun Aug 30 03:13:00.957905 2026] [security2:error] [pid 521505:tid 521694] [client 20.151.200.44:52139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/tf.php"] [unique_id "apPmDG8byYE0iXl--K6rxgAAA1k"]
[Sun Aug 30 03:13:00.971452 2026] [security2:error] [pid 521505:tid 521740] [client 4.205.62.107:15842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/database.php"] [unique_id "apPmDG8byYE0iXl--K6rxwAAA4c"]
[Sun Aug 30 03:13:00.984992 2026] [authz_core:error] [pid 521505:tid 521731] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory11
[Sun Aug 30 03:13:00.985282 2026] [authz_core:error] [pid 521505:tid 521731] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory11
[Sun Aug 30 03:13:01.009296 2026] [security2:error] [pid 521505:tid 521637] [client 20.104.50.220:63551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/degeselih.php"] [unique_id "apPmDW8byYE0iXl--K6rzAAAAyA"]
[Sun Aug 30 03:13:01.028289 2026] [authz_core:error] [pid 521505:tid 521639] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:01.028550 2026] [authz_core:error] [pid 521505:tid 521639] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:01.035056 2026] [security2:error] [pid 521505:tid 521707] [client 20.104.18.15:51100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/info.php/new.php"] [unique_id "apPmDW8byYE0iXl--K6rzwAAA2Y"]
[Sun Aug 30 03:13:01.054499 2026] [security2:error] [pid 521505:tid 521748] [client 4.205.62.107:16356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/php-info.php"] [unique_id "apPmDW8byYE0iXl--K6r0AAAA48"]
[Sun Aug 30 03:13:01.054616 2026] [security2:error] [pid 521505:tid 521652] [client 20.104.50.220:33319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/error.php"] [unique_id "apPmDW8byYE0iXl--K6r0QAAAy8"]
[Sun Aug 30 03:13:01.087851 2026] [security2:error] [pid 521505:tid 521641] [client 20.48.250.41:37792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/ioxi.php"] [unique_id "apPmDW8byYE0iXl--K6r1QAAAyQ"]
[Sun Aug 30 03:13:01.100978 2026] [security2:error] [pid 521505:tid 521657] [client 20.104.49.130:63518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/static.php"] [unique_id "apPmDW8byYE0iXl--K6r2gAAAzQ"]
[Sun Aug 30 03:13:01.111848 2026] [security2:error] [pid 521505:tid 521566] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/config/stripe.php"] [unique_id "apPmDW8byYE0iXl--K6r2wADXjw"]
[Sun Aug 30 03:13:01.123710 2026] [security2:error] [pid 521505:tid 521542] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/config/env.php"] [unique_id "apPmDW8byYE0iXl--K6r4AADOyQ"]
[Sun Aug 30 03:13:01.133510 2026] [security2:error] [pid 521505:tid 521507] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/config/module.config.php"] [unique_id "apPmDW8byYE0iXl--K6r4gADXQE"]
[Sun Aug 30 03:13:01.139601 2026] [security2:error] [pid 521505:tid 521704] [client 20.197.61.180:8964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/auth.php"] [unique_id "apPmDW8byYE0iXl--K6r5AAAA2M"]
[Sun Aug 30 03:13:01.151620 2026] [security2:error] [pid 524122:tid 524330] [client 20.104.50.220:25299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPmDX3lhEjKFiK_nBKGNgAAAdw"]
[Sun Aug 30 03:13:01.153574 2026] [security2:error] [pid 524122:tid 524312] [client 52.139.37.240:53242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/new.php"] [unique_id "apPmDX3lhEjKFiK_nBKGNwAAAco"]
[Sun Aug 30 03:13:01.178769 2026] [authz_core:error] [pid 521505:tid 521711] [client 66.249.66.39:38576] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:01.179066 2026] [authz_core:error] [pid 521505:tid 521711] [client 66.249.66.39:38576] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:01.209305 2026] [security2:error] [pid 521505:tid 521722] [client 216.73.216.128:26620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts2/tweakftp"] [unique_id "apPmDW8byYE0iXl--K6r6gAAA3U"]
[Sun Aug 30 03:13:01.250090 2026] [security2:error] [pid 524122:tid 524297] [client 20.48.250.41:37769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/bootstrap.php"] [unique_id "apPmDX3lhEjKFiK_nBKGOAAAAbs"]
[Sun Aug 30 03:13:01.263475 2026] [security2:error] [pid 524122:tid 524274] [client 20.48.251.3:54795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/rpk.php"] [unique_id "apPmDX3lhEjKFiK_nBKGOQAAAaQ"]
[Sun Aug 30 03:13:01.274939 2026] [security2:error] [pid 521505:tid 521735] [client 20.151.200.44:52148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/update/da222.php"] [unique_id "apPmDW8byYE0iXl--K6r7gAAA4I"]
[Sun Aug 30 03:13:01.297748 2026] [security2:error] [pid 521505:tid 521754] [client 20.48.160.90:29127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/ile56.php"] [unique_id "apPmDW8byYE0iXl--K6r9gAAA5U"]
[Sun Aug 30 03:13:01.301166 2026] [security2:error] [pid 524122:tid 524346] [client 20.48.160.90:49992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/Q3.php"] [unique_id "apPmDX3lhEjKFiK_nBKGOgAAAew"]
[Sun Aug 30 03:13:01.334948 2026] [security2:error] [pid 521505:tid 521663] [client 4.205.62.107:32464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/aws_config.php"] [unique_id "apPmDW8byYE0iXl--K6r_AAAAzo"]
[Sun Aug 30 03:13:01.336369 2026] [security2:error] [pid 521505:tid 521701] [client 4.205.62.107:29174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/api.php"] [unique_id "apPmDW8byYE0iXl--K6r_QAAA2A"]
[Sun Aug 30 03:13:01.340963 2026] [security2:error] [pid 524122:tid 524359] [client 20.104.50.220:31179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/themes/twentytwentytwo/index.php"] [unique_id "apPmDX3lhEjKFiK_nBKGOwAAAfk"]
[Sun Aug 30 03:13:01.361579 2026] [security2:error] [pid 521505:tid 521651] [client 52.139.37.240:53241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-conflg.php"] [unique_id "apPmDW8byYE0iXl--K6sAAAAAy4"]
[Sun Aug 30 03:13:01.366550 2026] [security2:error] [pid 521505:tid 521700] [client 20.104.50.220:29630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/p0wny-shell.php"] [unique_id "apPmDW8byYE0iXl--K6sAQAAA18"]
[Sun Aug 30 03:13:01.404513 2026] [security2:error] [pid 521505:tid 521648] [client 20.48.250.41:37793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/export.php"] [unique_id "apPmDW8byYE0iXl--K6sBAAAAys"]
[Sun Aug 30 03:13:01.406363 2026] [security2:error] [pid 521505:tid 521522] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/crm/.env"] [unique_id "apPmDW8byYE0iXl--K6sBQADhhA"]
[Sun Aug 30 03:13:01.427608 2026] [security2:error] [pid 524122:tid 524324] [client 20.104.49.130:60958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/red.php"] [unique_id "apPmDX3lhEjKFiK_nBKGPAAAAdY"]
[Sun Aug 30 03:13:01.427735 2026] [security2:error] [pid 524122:tid 524305] [client 20.48.160.90:29183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/emmh.php"] [unique_id "apPmDX3lhEjKFiK_nBKGPQAAAcM"]
[Sun Aug 30 03:13:01.441498 2026] [security2:error] [pid 521505:tid 521674] [client 20.104.49.130:60133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/crgio.php"] [unique_id "apPmDW8byYE0iXl--K6sBwAAA0U"]
[Sun Aug 30 03:13:01.447664 2026] [security2:error] [pid 524122:tid 524319] [client 20.48.160.90:49951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/Q1.php"] [unique_id "apPmDX3lhEjKFiK_nBKGPgAAAdE"]
[Sun Aug 30 03:13:01.457944 2026] [security2:error] [pid 521505:tid 521729] [client 20.48.251.3:36821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/05.php"] [unique_id "apPmDW8byYE0iXl--K6sCAAAA3w"]
[Sun Aug 30 03:13:01.465663 2026] [security2:error] [pid 521505:tid 521596] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/demo/.env"] [unique_id "apPmDW8byYE0iXl--K6sCwADmFo"]
[Sun Aug 30 03:13:01.465953 2026] [security2:error] [pid 521505:tid 521570] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/develop/.env"] [unique_id "apPmDW8byYE0iXl--K6sDwADmEA"]
[Sun Aug 30 03:13:01.465955 2026] [security2:error] [pid 521505:tid 521557] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/developer/.env"] [unique_id "apPmDW8byYE0iXl--K6sEAADmDM"]
[Sun Aug 30 03:13:01.465972 2026] [security2:error] [pid 521505:tid 521574] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/dev/.env"] [unique_id "apPmDW8byYE0iXl--K6sDQADmEQ"]
[Sun Aug 30 03:13:01.466013 2026] [security2:error] [pid 521505:tid 521567] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/development/.env"] [unique_id "apPmDW8byYE0iXl--K6sEQADmD0"]
[Sun Aug 30 03:13:01.477877 2026] [authz_core:error] [pid 521505:tid 521695] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory15
[Sun Aug 30 03:13:01.478302 2026] [authz_core:error] [pid 521505:tid 521695] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory15
[Sun Aug 30 03:13:01.540612 2026] [security2:error] [pid 521505:tid 521677] [client 20.104.50.220:61993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/aves.php"] [unique_id "apPmDW8byYE0iXl--K6sFQAAA0g"]
[Sun Aug 30 03:13:01.540625 2026] [security2:error] [pid 521505:tid 521661] [client 20.104.50.220:28686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/nikung.php"] [unique_id "apPmDW8byYE0iXl--K6sFgAAAzg"]
[Sun Aug 30 03:13:01.566060 2026] [security2:error] [pid 521505:tid 521708] [client 20.48.160.90:23763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/em.php"] [unique_id "apPmDW8byYE0iXl--K6sGAAAA2c"]
[Sun Aug 30 03:13:01.566077 2026] [security2:error] [pid 521505:tid 521697] [client 20.48.250.41:37870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/gk.php"] [unique_id "apPmDW8byYE0iXl--K6sGQAAA1w"]
[Sun Aug 30 03:13:01.569761 2026] [security2:error] [pid 521505:tid 521642] [client 52.139.37.240:46972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "apPmDW8byYE0iXl--K6sGwAAAyU"]
[Sun Aug 30 03:13:01.574370 2026] [authz_core:error] [pid 521505:tid 521675] [client 66.249.66.41:53593] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:01.574635 2026] [authz_core:error] [pid 521505:tid 521675] [client 66.249.66.41:53593] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:01.579113 2026] [security2:error] [pid 521505:tid 521598] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/current/.env"] [unique_id "apPmDW8byYE0iXl--K6sHwADVlw"]
[Sun Aug 30 03:13:01.579199 2026] [security2:error] [pid 521505:tid 521576] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/cron/.env"] [unique_id "apPmDW8byYE0iXl--K6sHgADVkY"]
[Sun Aug 30 03:13:01.622887 2026] [cgid:error] [pid 521505:tid 521601] [remote 93.123.109.228:45324] AH01264: stderr from /home3/jvallesteros/jeanbooknerdstorytellersbox.com/dnscfg.cgi: script not found or unable to stat
[Sun Aug 30 03:13:01.653061 2026] [security2:error] [pid 521505:tid 521743] [client 158.23.147.79:59017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/classwithtostring.php"] [unique_id "apPmDW8byYE0iXl--K6sKAAAA4o"]
[Sun Aug 30 03:13:01.682137 2026] [authz_core:error] [pid 521505:tid 521682] [client 216.73.216.128:27728] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:01.682606 2026] [authz_core:error] [pid 521505:tid 521682] [client 216.73.216.128:27728] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:01.701168 2026] [security2:error] [pid 524122:tid 524282] [client 20.104.50.220:17235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/p0wny.php"] [unique_id "apPmDX3lhEjKFiK_nBKGRwAAAaw"]
[Sun Aug 30 03:13:01.704218 2026] [security2:error] [pid 521505:tid 521755] [client 20.48.251.3:59473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/time.php"] [unique_id "apPmDW8byYE0iXl--K6sKgAAA5Y"]
[Sun Aug 30 03:13:01.711725 2026] [security2:error] [pid 524122:tid 524290] [client 91.224.92.32:50802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.92.224.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "1superiormachine.com"] [uri "/wp-login.php"] [unique_id "apPmDX3lhEjKFiK_nBKGSAAAAbQ"], referer: https://www.google.com/
[Sun Aug 30 03:13:01.723085 2026] [security2:error] [pid 521505:tid 521759] [client 20.104.50.220:50023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "uaeweb3.ae"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPmDW8byYE0iXl--K6sLQAAA5o"]
[Sun Aug 30 03:13:01.723956 2026] [security2:error] [pid 524122:tid 524302] [client 20.48.250.41:37883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/logs1.php"] [unique_id "apPmDX3lhEjKFiK_nBKGSQAAAcA"]
[Sun Aug 30 03:13:01.727877 2026] [security2:error] [pid 521505:tid 521599] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/erp/.env"] [unique_id "apPmDW8byYE0iXl--K6sLgADmV0"]
[Sun Aug 30 03:13:01.738806 2026] [authz_core:error] [pid 521505:tid 521734] [client 66.249.66.68:40306] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:01.739072 2026] [authz_core:error] [pid 521505:tid 521734] [client 66.249.66.68:40306] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:01.746671 2026] [security2:error] [pid 521505:tid 521637] [client 20.104.50.220:5190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/9.php"] [unique_id "apPmDW8byYE0iXl--K6sMgAAAyA"]
[Sun Aug 30 03:13:01.772038 2026] [security2:error] [pid 521505:tid 521761] [client 20.151.200.44:52040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/qi.php"] [unique_id "apPmDW8byYE0iXl--K6sMwAAA5w"]
[Sun Aug 30 03:13:01.791189 2026] [authz_core:error] [pid 521505:tid 521725] [client 66.249.66.72:50363] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:01.791621 2026] [authz_core:error] [pid 521505:tid 521725] [client 66.249.66.72:50363] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:01.814105 2026] [security2:error] [pid 521505:tid 521713] [client 216.73.216.128:8002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/summary.csv"] [unique_id "apPmDW8byYE0iXl--K6sNwAAA2w"]
[Sun Aug 30 03:13:01.820637 2026] [security2:error] [pid 521505:tid 521649] [client 4.205.62.107:17410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/doc.php"] [unique_id "apPmDW8byYE0iXl--K6sOAAAAyw"]
[Sun Aug 30 03:13:01.853326 2026] [security2:error] [pid 524122:tid 524268] [client 20.197.61.180:19243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/adminfuns.php"] [unique_id "apPmDX3lhEjKFiK_nBKGTAAAAZ4"]
[Sun Aug 30 03:13:01.862209 2026] [authz_core:error] [pid 521505:tid 521671] [client 216.73.216.128:27728] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:01.862471 2026] [authz_core:error] [pid 521505:tid 521671] [client 216.73.216.128:27728] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:01.871633 2026] [security2:error] [pid 521505:tid 521641] [client 20.48.250.41:37857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/inege.php"] [unique_id "apPmDW8byYE0iXl--K6sPAAAAyQ"]
[Sun Aug 30 03:13:01.927867 2026] [security2:error] [pid 521505:tid 521714] [client 45.131.195.13:35503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.195.131.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "homeohealing.ca"] [uri "/wp-login.php"] [unique_id "apPmDW8byYE0iXl--K6sPwAAA20"]
[Sun Aug 30 03:13:01.935160 2026] [security2:error] [pid 524122:tid 524285] [client 52.139.37.240:46959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-includes/customize/chosen.php"] [unique_id "apPmDX3lhEjKFiK_nBKGTQAAAa8"]
[Sun Aug 30 03:13:01.942672 2026] [security2:error] [pid 521505:tid 521610] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/etc/boto.cfg"] [unique_id "apPmDW8byYE0iXl--K6sRgADPGg"]
[Sun Aug 30 03:13:01.942765 2026] [security2:error] [pid 521505:tid 521521] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/etc/apache2/apache2.conf"] [unique_id "apPmDW8byYE0iXl--K6sRQADPA8"]
[Sun Aug 30 03:13:01.943718 2026] [security2:error] [pid 521505:tid 521630] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/fe/.env"] [unique_id "apPmDW8byYE0iXl--K6sRwADPHw"]
[Sun Aug 30 03:13:01.954188 2026] [security2:error] [pid 521505:tid 521715] [client 20.104.18.15:22417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/alfa.php"] [unique_id "apPmDW8byYE0iXl--K6sTgAAA24"]
[Sun Aug 30 03:13:01.985291 2026] [security2:error] [pid 521505:tid 521552] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/front/.env"] [unique_id "apPmDW8byYE0iXl--K6sUAADXS4"]
[Sun Aug 30 03:13:01.996075 2026] [security2:error] [pid 521505:tid 521704] [client 68.155.159.216:60327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/file88.php"] [unique_id "apPmDW8byYE0iXl--K6sUQAAA2M"]
[Sun Aug 30 03:13:01.996670 2026] [security2:error] [pid 521505:tid 521731] [client 20.104.18.15:2047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/sss.php"] [unique_id "apPmDW8byYE0iXl--K6sUgAAA34"]
[Sun Aug 30 03:13:02.015527 2026] [security2:error] [pid 521505:tid 521603] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/frontend/.env"] [unique_id "apPmDm8byYE0iXl--K6sVAADSmE"]
[Sun Aug 30 03:13:02.017369 2026] [authz_core:error] [pid 521505:tid 521716] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:13:02.017828 2026] [authz_core:error] [pid 521505:tid 521716] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:13:02.042988 2026] [security2:error] [pid 521505:tid 521722] [client 158.23.147.79:55420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/install.php"] [unique_id "apPmDm8byYE0iXl--K6sVwAAA3U"]
[Sun Aug 30 03:13:02.048263 2026] [security2:error] [pid 521505:tid 521640] [client 20.48.250.41:37774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/wp-link10.php"] [unique_id "apPmDm8byYE0iXl--K6sWAAAAyM"]
[Sun Aug 30 03:13:02.105966 2026] [security2:error] [pid 521505:tid 521611] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/laravel/.env"] [unique_id "apPmDm8byYE0iXl--K6sWwADQ2k"]
[Sun Aug 30 03:13:02.106113 2026] [security2:error] [pid 521505:tid 521580] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/lms/.env"] [unique_id "apPmDm8byYE0iXl--K6sXAADQ0o"]
[Sun Aug 30 03:13:02.117611 2026] [security2:error] [pid 521505:tid 521663] [client 4.205.62.107:15844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/atex1.php"] [unique_id "apPmDm8byYE0iXl--K6sXwAAAzo"]
[Sun Aug 30 03:13:02.146104 2026] [security2:error] [pid 521505:tid 521741] [client 52.139.37.240:50329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-admin/js/autoload_classmap.php"] [unique_id "apPmDm8byYE0iXl--K6sYgAAA4g"]
[Sun Aug 30 03:13:02.166787 2026] [security2:error] [pid 521505:tid 521658] [client 20.104.50.220:42813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/doc.php"] [unique_id "apPmDm8byYE0iXl--K6sZAAAAzU"]
[Sun Aug 30 03:13:02.189320 2026] [security2:error] [pid 521505:tid 521739] [client 20.104.50.220:33050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/evil.php"] [unique_id "apPmDm8byYE0iXl--K6sZgAAA4Y"]
[Sun Aug 30 03:13:02.192588 2026] [security2:error] [pid 521505:tid 521702] [client 4.205.62.107:16360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/infos.php"] [unique_id "apPmDm8byYE0iXl--K6sZwAAA2E"]
[Sun Aug 30 03:13:02.197033 2026] [security2:error] [pid 524122:tid 524258] [client 20.48.250.41:37871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/ww.php"] [unique_id "apPmDn3lhEjKFiK_nBKGTwAAAZQ"]
[Sun Aug 30 03:13:02.236028 2026] [authz_core:error] [pid 521505:tid 521674] [client 216.73.216.128:29934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:02.236463 2026] [authz_core:error] [pid 521505:tid 521674] [client 216.73.216.128:29934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:02.246336 2026] [security2:error] [pid 521505:tid 521668] [client 91.224.92.32:54621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.92.224.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "1superiormachine.com"] [uri "/wp-login.php"] [unique_id "apPmDm8byYE0iXl--K6saQAAAz8"], referer: https://www.google.com/
[Sun Aug 30 03:13:02.263394 2026] [security2:error] [pid 521505:tid 521644] [client 20.104.18.15:50966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/w.php"] [unique_id "apPmDm8byYE0iXl--K6sagAAAyc"]
[Sun Aug 30 03:13:02.274485 2026] [security2:error] [pid 521505:tid 521621] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/marketing/.env"] [unique_id "apPmDm8byYE0iXl--K6sawADT3M"]
[Sun Aug 30 03:13:02.286609 2026] [authz_core:error] [pid 521505:tid 521732] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:02.287132 2026] [authz_core:error] [pid 521505:tid 521732] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:02.301058 2026] [security2:error] [pid 521505:tid 521584] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/infophp.php"] [unique_id "apPmDm8byYE0iXl--K6scQADcE4"]
[Sun Aug 30 03:13:02.301277 2026] [security2:error] [pid 521505:tid 521619] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/infos.php"] [unique_id "apPmDm8byYE0iXl--K6scgADcHE"]
[Sun Aug 30 03:13:02.301353 2026] [security2:error] [pid 521505:tid 521581] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/info.php"] [unique_id "apPmDm8byYE0iXl--K6scAADcEs"]
[Sun Aug 30 03:13:02.303450 2026] [security2:error] [pid 521505:tid 521718] [client 20.104.50.220:24947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/wp-blog.php"] [unique_id "apPmDm8byYE0iXl--K6scwAAA3E"]
[Sun Aug 30 03:13:02.318240 2026] [security2:error] [pid 521505:tid 521625] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/local/.env"] [unique_id "apPmDm8byYE0iXl--K6seQADTHc"]
[Sun Aug 30 03:13:02.320569 2026] [authz_core:error] [pid 521505:tid 521642] [client 66.249.66.33:49836] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:02.321025 2026] [authz_core:error] [pid 521505:tid 521642] [client 66.249.66.33:49836] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:02.333391 2026] [security2:error] [pid 521505:tid 521688] [client 20.48.250.41:37775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/w1px.php"] [unique_id "apPmDm8byYE0iXl--K6sfAAAA1M"]
[Sun Aug 30 03:13:02.349782 2026] [security2:error] [pid 521505:tid 521733] [client 20.104.49.130:34546] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "alarm-monitoring.net"] [uri "/1.php"] [unique_id "apPmDm8byYE0iXl--K6sfwAAA4A"]
[Sun Aug 30 03:13:02.349914 2026] [security2:error] [pid 521505:tid 521733] [client 20.104.49.130:34546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alarm-monitoring.net"] [uri "/1.php"] [unique_id "apPmDm8byYE0iXl--K6sfwAAA4A"]
[Sun Aug 30 03:13:02.358780 2026] [security2:error] [pid 521505:tid 521677] [client 52.139.37.240:52587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-includes/Text/autoload_classmap.php"] [unique_id "apPmDm8byYE0iXl--K6sgQAAA0g"]
[Sun Aug 30 03:13:02.399339 2026] [security2:error] [pid 524122:tid 524291] [client 20.48.251.3:54737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/saml.php"] [unique_id "apPmDn3lhEjKFiK_nBKGUwAAAbU"]
[Sun Aug 30 03:13:02.405404 2026] [security2:error] [pid 521505:tid 521762] [client 158.23.147.79:55364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-content/x/index.php"] [unique_id "apPmDm8byYE0iXl--K6sggAAA50"]
[Sun Aug 30 03:13:02.428850 2026] [security2:error] [pid 521505:tid 521546] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/media/.env"] [unique_id "apPmDm8byYE0iXl--K6shgADlyg"]
[Sun Aug 30 03:13:02.428864 2026] [security2:error] [pid 521505:tid 521559] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/market/.env"] [unique_id "apPmDm8byYE0iXl--K6shAADlzU"]
[Sun Aug 30 03:13:02.436563 2026] [security2:error] [pid 521505:tid 521591] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/node-api/.env"] [unique_id "apPmDm8byYE0iXl--K6siAADIFU"]
[Sun Aug 30 03:13:02.437764 2026] [security2:error] [pid 521505:tid 521520] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/node/.env"] [unique_id "apPmDm8byYE0iXl--K6siQADIA4"]
[Sun Aug 30 03:13:02.448856 2026] [security2:error] [pid 521505:tid 521513] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/node/api/.env"] [unique_id "apPmDm8byYE0iXl--K6sjAADMgc"]
[Sun Aug 30 03:13:02.448918 2026] [security2:error] [pid 521505:tid 521562] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/node/backend/.env"] [unique_id "apPmDm8byYE0iXl--K6sjQADMjg"]
[Sun Aug 30 03:13:02.482314 2026] [security2:error] [pid 524122:tid 524294] [client 20.104.50.220:31209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-admin/js/wp-conflg.php"] [unique_id "apPmDn3lhEjKFiK_nBKGVAAAAbg"]
[Sun Aug 30 03:13:02.493696 2026] [authz_core:error] [pid 524122:tid 524372] [client 66.249.66.69:35636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:02.494163 2026] [authz_core:error] [pid 524122:tid 524372] [client 66.249.66.69:35636] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:02.496301 2026] [security2:error] [pid 521505:tid 521712] [client 20.48.250.41:37768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/to.php"] [unique_id "apPmDm8byYE0iXl--K6skgAAA2s"]
[Sun Aug 30 03:13:02.500024 2026] [security2:error] [pid 521505:tid 521631] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/old/.env"] [unique_id "apPmDm8byYE0iXl--K6slAADL30"]
[Sun Aug 30 03:13:02.507968 2026] [security2:error] [pid 521505:tid 521728] [client 4.205.62.107:52886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/temp.php"] [unique_id "apPmDm8byYE0iXl--K6slwAAA3s"]
[Sun Aug 30 03:13:02.509591 2026] [authz_core:error] [pid 521505:tid 521713] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:13:02.509885 2026] [authz_core:error] [pid 521505:tid 521713] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:13:02.511098 2026] [security2:error] [pid 521505:tid 521653] [client 4.205.62.107:32001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/dialog.php"] [unique_id "apPmDm8byYE0iXl--K6smAAAAzA"]
[Sun Aug 30 03:13:02.515113 2026] [security2:error] [pid 521505:tid 521553] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/new/.env"] [unique_id "apPmDm8byYE0iXl--K6smQADQC8"]
[Sun Aug 30 03:13:02.522491 2026] [security2:error] [pid 521505:tid 521575] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/nodeapi/.env"] [unique_id "apPmDm8byYE0iXl--K6smgADMUU"]
[Sun Aug 30 03:13:02.524883 2026] [security2:error] [pid 521505:tid 521541] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/nodeweb/.env"] [unique_id "apPmDm8byYE0iXl--K6smwADMSM"]
[Sun Aug 30 03:13:02.569845 2026] [security2:error] [pid 524122:tid 524269] [client 20.197.61.180:8989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/rip.php"] [unique_id "apPmDn3lhEjKFiK_nBKGWQAAAZ8"]
[Sun Aug 30 03:13:02.582507 2026] [security2:error] [pid 524122:tid 524279] [client 158.23.147.79:55360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-includes/Requests/about.php"] [unique_id "apPmDn3lhEjKFiK_nBKGWgAAAak"]
[Sun Aug 30 03:13:02.590469 2026] [security2:error] [pid 521505:tid 521641] [client 52.139.37.240:50323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/mini.php"] [unique_id "apPmDm8byYE0iXl--K6snQAAAyQ"]
[Sun Aug 30 03:13:02.605973 2026] [security2:error] [pid 521505:tid 521727] [client 20.48.160.90:49216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/nz.php"] [unique_id "apPmDm8byYE0iXl--K6sngAAA3o"]
[Sun Aug 30 03:13:02.610224 2026] [security2:error] [pid 521505:tid 521749] [client 20.48.251.3:36848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/wp-blog.php"] [unique_id "apPmDm8byYE0iXl--K6snwAAA5A"]
[Sun Aug 30 03:13:02.623524 2026] [authz_core:error] [pid 521505:tid 521715] [client 66.249.66.204:37739] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:02.623977 2026] [authz_core:error] [pid 521505:tid 521715] [client 66.249.66.204:37739] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:02.630518 2026] [security2:error] [pid 521505:tid 521664] [client 20.48.250.41:37878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/thui.php"] [unique_id "apPmDm8byYE0iXl--K6soQAAAzs"]
[Sun Aug 30 03:13:02.637239 2026] [security2:error] [pid 521505:tid 521745] [client 20.104.49.130:63589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wdfjba.org"] [uri "/133.php"] [unique_id "apPmDm8byYE0iXl--K6sowAAA4w"]
[Sun Aug 30 03:13:02.675161 2026] [security2:error] [pid 521505:tid 521735] [client 20.104.50.220:62840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/ex0shell.php"] [unique_id "apPmDm8byYE0iXl--K6sqQAAA4I"]
[Sun Aug 30 03:13:02.678056 2026] [security2:error] [pid 521505:tid 521734] [client 20.104.50.220:62846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/tertykung.php"] [unique_id "apPmDm8byYE0iXl--K6sqgAAA4E"]
[Sun Aug 30 03:13:02.682298 2026] [security2:error] [pid 521505:tid 521536] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/opt/.env"] [unique_id "apPmDm8byYE0iXl--K6sqwADZR4"]
[Sun Aug 30 03:13:02.684689 2026] [security2:error] [pid 521505:tid 521738] [client 216.73.216.128:8386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_config_quote_replace_string"] [unique_id "apPmDm8byYE0iXl--K6srwAAA4U"]
[Sun Aug 30 03:13:02.707103 2026] [security2:error] [pid 524122:tid 524318] [client 20.104.50.220:61666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "apPmDn3lhEjKFiK_nBKGXQAAAdA"]
[Sun Aug 30 03:13:02.707487 2026] [security2:error] [pid 524122:tid 524362] [client 158.23.147.79:59020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-admin/includes/index.php"] [unique_id "apPmDn3lhEjKFiK_nBKGXgAAAfw"]
[Sun Aug 30 03:13:02.710185 2026] [security2:error] [pid 524122:tid 524288] [client 20.48.160.90:49218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/dvve.php"] [unique_id "apPmDn3lhEjKFiK_nBKGXwAAAbI"]
[Sun Aug 30 03:13:02.746122 2026] [authz_core:error] [pid 521505:tid 521741] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:02.746395 2026] [authz_core:error] [pid 521505:tid 521741] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:02.747388 2026] [security2:error] [pid 521505:tid 521650] [client 20.48.160.90:29172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/sg.php"] [unique_id "apPmDm8byYE0iXl--K6suAAAAy0"]
[Sun Aug 30 03:13:02.770568 2026] [security2:error] [pid 524122:tid 524355] [client 20.48.250.41:37885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/Jcrop.php"] [unique_id "apPmDn3lhEjKFiK_nBKGYAAAAfU"]
[Sun Aug 30 03:13:02.811132 2026] [security2:error] [pid 521505:tid 521668] [client 20.151.200.44:55721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.americanqualityhomeinspections.com"] [uri "/motu.php"] [unique_id "apPmDm8byYE0iXl--K6svgAAAz8"]
[Sun Aug 30 03:13:02.828452 2026] [security2:error] [pid 521505:tid 521658] [client 52.139.37.240:46944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/lock360.php"] [unique_id "apPmDm8byYE0iXl--K6swAAAAzU"]
[Sun Aug 30 03:13:02.837439 2026] [security2:error] [pid 521505:tid 521711] [client 20.104.50.220:16682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/.well-known/69.php"] [unique_id "apPmDm8byYE0iXl--K6swQAAA2o"]
[Sun Aug 30 03:13:02.844959 2026] [security2:error] [pid 521505:tid 521600] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/php_info.php"] [unique_id "apPmDm8byYE0iXl--K6swgADJ14"]
[Sun Aug 30 03:13:02.844985 2026] [security2:error] [pid 521505:tid 521542] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/phpinfo.php"] [unique_id "apPmDm8byYE0iXl--K6swwADJyQ"]
[Sun Aug 30 03:13:02.851606 2026] [security2:error] [pid 521505:tid 521629] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/portal/.env"] [unique_id "apPmDm8byYE0iXl--K6sxgADT3s"]
[Sun Aug 30 03:13:02.855684 2026] [security2:error] [pid 521505:tid 521696] [client 20.48.160.90:50023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/doo.php"] [unique_id "apPmDm8byYE0iXl--K6syAAAA1s"]
[Sun Aug 30 03:13:02.864791 2026] [security2:error] [pid 521505:tid 521628] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/php-info.php"] [unique_id "apPmDm8byYE0iXl--K6sywADcXo"]
[Sun Aug 30 03:13:02.868046 2026] [security2:error] [pid 521505:tid 521537] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/php.php"] [unique_id "apPmDm8byYE0iXl--K6szQADZx8"]
[Sun Aug 30 03:13:02.872827 2026] [authz_core:error] [pid 521505:tid 521697] [client 216.73.216.128:29934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:02.873090 2026] [authz_core:error] [pid 521505:tid 521697] [client 216.73.216.128:29934] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:02.884238 2026] [security2:error] [pid 521505:tid 521688] [client 20.104.50.220:5622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/8.php"] [unique_id "apPmDm8byYE0iXl--K6szwAAA1M"]
[Sun Aug 30 03:13:02.885874 2026] [security2:error] [pid 524122:tid 524265] [client 20.48.251.3:43035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/doc.php"] [unique_id "apPmDn3lhEjKFiK_nBKGYQAAAZs"]
[Sun Aug 30 03:13:02.903466 2026] [security2:error] [pid 521505:tid 521752] [client 20.48.160.90:50002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/hypo.php"] [unique_id "apPmDm8byYE0iXl--K6s0QAAA5M"]
[Sun Aug 30 03:13:02.910732 2026] [security2:error] [pid 521505:tid 521746] [client 20.48.250.41:37705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/ws58.php"] [unique_id "apPmDm8byYE0iXl--K6s0gAAA40"]
[Sun Aug 30 03:13:02.915523 2026] [security2:error] [pid 521505:tid 521617] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/prod/.env"] [unique_id "apPmDm8byYE0iXl--K6s1QADRW8"]
[Sun Aug 30 03:13:02.915586 2026] [security2:error] [pid 521505:tid 521587] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/product/.env"] [unique_id "apPmDm8byYE0iXl--K6s1AADRVE"]
[Sun Aug 30 03:13:02.958426 2026] [security2:error] [pid 521505:tid 521707] [client 4.205.62.107:17437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/classsmtps.php"] [unique_id "apPmDm8byYE0iXl--K6s4QAAA2Y"]
[Sun Aug 30 03:13:02.965810 2026] [security2:error] [pid 521505:tid 521528] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/production/.env"] [unique_id "apPmDm8byYE0iXl--K6s4gADgxY"]
[Sun Aug 30 03:13:02.970137 2026] [authz_core:error] [pid 524122:tid 524315] [client 216.73.216.128:9566] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:02.970580 2026] [authz_core:error] [pid 524122:tid 524315] [client 216.73.216.128:9566] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:02.972147 2026] [authz_core:error] [pid 521505:tid 521728] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:13:02.972423 2026] [authz_core:error] [pid 521505:tid 521728] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:13:02.993932 2026] [security2:error] [pid 521505:tid 521568] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/project/.env"] [unique_id "apPmDm8byYE0iXl--K6s5QADMD4"]
[Sun Aug 30 03:13:02.994099 2026] [security2:error] [pid 521505:tid 521669] [client 20.48.160.90:50312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/adminer-4.6.6.php"] [unique_id "apPmDm8byYE0iXl--K6s5gAAA0A"]
[Sun Aug 30 03:13:02.999443 2026] [security2:error] [pid 521505:tid 521527] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/public-api/.env"] [unique_id "apPmDm8byYE0iXl--K6s5wADiRU"]
[Sun Aug 30 03:13:02.999547 2026] [security2:error] [pid 521505:tid 521586] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/public/.env"] [unique_id "apPmDm8byYE0iXl--K6s6AADiVA"]
[Sun Aug 30 03:13:03.003797 2026] [security2:error] [pid 521505:tid 521573] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/public/phpinfo.php"] [unique_id "apPmD28byYE0iXl--K6s6QADRkM"]
[Sun Aug 30 03:13:03.013527 2026] [security2:error] [pid 521505:tid 521726] [client 158.23.147.79:55372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-login.php"] [unique_id "apPmD28byYE0iXl--K6s6gAAA3k"]
[Sun Aug 30 03:13:03.017996 2026] [security2:error] [pid 521505:tid 521522] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/public_html/.env"] [unique_id "apPmD28byYE0iXl--K6s7AADJBA"]
[Sun Aug 30 03:13:03.024255 2026] [security2:error] [pid 521505:tid 521574] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/qa/.env"] [unique_id "apPmD28byYE0iXl--K6s7gADNEQ"]
[Sun Aug 30 03:13:03.035626 2026] [security2:error] [pid 521505:tid 521652] [client 52.139.37.240:52591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/cljntmcz.php"] [unique_id "apPmD28byYE0iXl--K6s8AAAAy8"]
[Sun Aug 30 03:13:03.042585 2026] [security2:error] [pid 521505:tid 521727] [client 20.48.160.90:50395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/Hd.php"] [unique_id "apPmD28byYE0iXl--K6s8QAAA3o"]
[Sun Aug 30 03:13:03.059107 2026] [authz_core:error] [pid 521505:tid 521703] [client 66.249.66.66:55582] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:03.059383 2026] [authz_core:error] [pid 521505:tid 521703] [client 66.249.66.66:55582] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:03.074244 2026] [security2:error] [pid 524122:tid 524309] [client 20.104.49.130:63239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/tool.php"] [unique_id "apPmD33lhEjKFiK_nBKGZAAAAcc"]
[Sun Aug 30 03:13:03.075585 2026] [security2:error] [pid 521505:tid 521704] [client 20.48.250.41:37885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/xs.php"] [unique_id "apPmD28byYE0iXl--K6s-AAAA2M"]
[Sun Aug 30 03:13:03.102256 2026] [security2:error] [pid 521505:tid 521724] [client 20.104.18.15:22506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/133.php"] [unique_id "apPmD28byYE0iXl--K6s-gAAA3c"]
[Sun Aug 30 03:13:03.137860 2026] [security2:error] [pid 521505:tid 521734] [client 68.155.159.216:60305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/NewFile.php/"] [unique_id "apPmD28byYE0iXl--K6s_gAAA4E"]
[Sun Aug 30 03:13:03.142597 2026] [security2:error] [pid 524122:tid 524374] [client 20.104.18.15:1951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/xmini4.php"] [unique_id "apPmD33lhEjKFiK_nBKGZgAAAgg"]
[Sun Aug 30 03:13:03.146029 2026] [security2:error] [pid 521505:tid 521713] [client 20.48.160.90:28738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/gelap1.php"] [unique_id "apPmD28byYE0iXl--K6s_wAAA2w"]
[Sun Aug 30 03:13:03.199737 2026] [security2:error] [pid 521505:tid 521645] [client 158.23.147.79:55369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apPmD28byYE0iXl--K6tAgAAAyg"]
[Sun Aug 30 03:13:03.229436 2026] [security2:error] [pid 521505:tid 521738] [client 52.139.37.240:52585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/manager.php"] [unique_id "apPmD28byYE0iXl--K6tAwAAA4U"]
[Sun Aug 30 03:13:03.233024 2026] [security2:error] [pid 521505:tid 521730] [client 20.48.250.41:37841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/zu.php"] [unique_id "apPmD28byYE0iXl--K6tBgAAA30"]
[Sun Aug 30 03:13:03.242208 2026] [authz_core:error] [pid 521505:tid 521672] [client 66.249.66.73:37066] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:03.242487 2026] [authz_core:error] [pid 521505:tid 521672] [client 66.249.66.73:37066] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:03.247915 2026] [security2:error] [pid 521505:tid 521648] [client 20.104.49.130:52450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/reviall.php"] [unique_id "apPmD28byYE0iXl--K6tDgAAAys"]
[Sun Aug 30 03:13:03.251453 2026] [security2:error] [pid 524122:tid 524348] [client 4.205.62.107:15991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/aws_sdk_settings.php"] [unique_id "apPmD33lhEjKFiK_nBKGZwAAAe4"]
[Sun Aug 30 03:13:03.266250 2026] [authz_core:error] [pid 521505:tid 521739] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:03.266537 2026] [authz_core:error] [pid 521505:tid 521739] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:03.303822 2026] [security2:error] [pid 521505:tid 521673] [client 20.197.61.180:8966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/ws.php"] [unique_id "apPmD28byYE0iXl--K6tHAAAA0Q"]
[Sun Aug 30 03:13:03.315220 2026] [security2:error] [pid 521505:tid 521658] [client 20.104.50.220:51570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/docindex.php"] [unique_id "apPmD28byYE0iXl--K6tHQAAAzU"]
[Sun Aug 30 03:13:03.329531 2026] [security2:error] [pid 524122:tid 524345] [client 4.205.62.107:15809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/env.php"] [unique_id "apPmD33lhEjKFiK_nBKGaAAAAes"]
[Sun Aug 30 03:13:03.349887 2026] [security2:error] [pid 521505:tid 521718] [client 20.151.200.44:52119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/px.php"] [unique_id "apPmD28byYE0iXl--K6tIQAAA3E"]
[Sun Aug 30 03:13:03.359024 2026] [security2:error] [pid 524122:tid 524277] [client 20.104.50.220:33035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/file.php"] [unique_id "apPmD33lhEjKFiK_nBKGaQAAAac"]
[Sun Aug 30 03:13:03.391249 2026] [security2:error] [pid 521505:tid 521640] [client 158.23.147.79:55421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-admin/images/about.php"] [unique_id "apPmD28byYE0iXl--K6tJgAAAyM"]
[Sun Aug 30 03:13:03.403940 2026] [security2:error] [pid 524122:tid 524320] [client 20.104.18.15:51042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/x.php"] [unique_id "apPmD33lhEjKFiK_nBKGagAAAdI"]
[Sun Aug 30 03:13:03.406797 2026] [security2:error] [pid 521505:tid 521756] [client 20.48.250.41:37770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/lanka.php"] [unique_id "apPmD28byYE0iXl--K6tKgAAA5c"]
[Sun Aug 30 03:13:03.416151 2026] [security2:error] [pid 521505:tid 521761] [client 158.23.184.117:36564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/new.php"] [unique_id "apPmD28byYE0iXl--K6tKwAAA5w"]
[Sun Aug 30 03:13:03.434198 2026] [security2:error] [pid 521505:tid 521685] [client 52.139.37.240:49690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-links.php"] [unique_id "apPmD28byYE0iXl--K6tLgAAA1A"]
[Sun Aug 30 03:13:03.467924 2026] [authz_core:error] [pid 521505:tid 521693] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:13:03.468325 2026] [authz_core:error] [pid 521505:tid 521693] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:13:03.498273 2026] [security2:error] [pid 521505:tid 521611] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/s3/.env.bak"] [unique_id "apPmD28byYE0iXl--K6tQQADQGk"]
[Sun Aug 30 03:13:03.499761 2026] [security2:error] [pid 521505:tid 521692] [client 158.23.147.79:59069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPmD28byYE0iXl--K6tQgAAA1c"]
[Sun Aug 30 03:13:03.505716 2026] [security2:error] [pid 521505:tid 521747] [client 216.73.216.128:29934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPmD28byYE0iXl--K6tRAAAA44"]
[Sun Aug 30 03:13:03.535771 2026] [security2:error] [pid 521505:tid 521665] [client 20.48.250.41:37797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/gettest.php"] [unique_id "apPmD28byYE0iXl--K6tRQAAAzw"]
[Sun Aug 30 03:13:03.537742 2026] [security2:error] [pid 521505:tid 521726] [client 176.102.66.239:54216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.66.102.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.tulsapersonalinjurylawyer.pro"] [uri "/wp-login.php"] [unique_id "apPmD28byYE0iXl--K6tRgAAA3k"]
[Sun Aug 30 03:13:03.546464 2026] [security2:error] [pid 521505:tid 521657] [client 20.48.251.3:46190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/aws_settings.php"] [unique_id "apPmD28byYE0iXl--K6tSQAAAzQ"]
[Sun Aug 30 03:13:03.563855 2026] [security2:error] [pid 521505:tid 521636] [client 20.104.50.220:24866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/wp-content/admin.php"] [unique_id "apPmD28byYE0iXl--K6tSwAAAx8"]
[Sun Aug 30 03:13:03.609725 2026] [security2:error] [pid 521505:tid 521704] [client 158.23.184.117:36146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/bypass.php"] [unique_id "apPmD28byYE0iXl--K6tTwAAA2M"]
[Sun Aug 30 03:13:03.632605 2026] [security2:error] [pid 521505:tid 521671] [client 158.23.147.79:55368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-admin.php"] [unique_id "apPmD28byYE0iXl--K6tUAAAA0I"]
[Sun Aug 30 03:13:03.636066 2026] [security2:error] [pid 521505:tid 521724] [client 20.104.50.220:31216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-admin/wp-conflg.php"] [unique_id "apPmD28byYE0iXl--K6tUQAAA3c"]
[Sun Aug 30 03:13:03.648939 2026] [security2:error] [pid 521505:tid 521722] [client 4.205.62.107:29125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/fm.php"] [unique_id "apPmD28byYE0iXl--K6tUgAAA3U"]
[Sun Aug 30 03:13:03.660408 2026] [security2:error] [pid 521505:tid 521713] [client 20.151.200.44:63672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/xda.php"] [unique_id "apPmD28byYE0iXl--K6tUwAAA2w"]
[Sun Aug 30 03:13:03.664441 2026] [security2:error] [pid 521505:tid 521728] [client 20.48.250.41:37839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/35.php"] [unique_id "apPmD28byYE0iXl--K6tVAAAA3s"]
[Sun Aug 30 03:13:03.671774 2026] [security2:error] [pid 524122:tid 524379] [client 52.139.37.240:9533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/fi2.php"] [unique_id "apPmD33lhEjKFiK_nBKGbQAAAg0"]
[Sun Aug 30 03:13:03.696146 2026] [security2:error] [pid 521505:tid 521560] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/server/api/.env"] [unique_id "apPmD28byYE0iXl--K6tVQADKDY"]
[Sun Aug 30 03:13:03.712900 2026] [authz_core:error] [pid 521505:tid 521735] [client 66.249.66.69:42708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:03.713227 2026] [authz_core:error] [pid 521505:tid 521735] [client 66.249.66.69:42708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:03.725902 2026] [authz_core:error] [pid 524122:tid 524266] [client 66.249.66.203:34837] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:03.726206 2026] [authz_core:error] [pid 524122:tid 524266] [client 66.249.66.203:34837] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:03.743026 2026] [security2:error] [pid 521505:tid 521533] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/server/.env"] [unique_id "apPmD28byYE0iXl--K6tXQADmxs"]
[Sun Aug 30 03:13:03.750190 2026] [security2:error] [pid 521505:tid 521613] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/server/backend/.env"] [unique_id "apPmD28byYE0iXl--K6tZgADQWs"]
[Sun Aug 30 03:13:03.751281 2026] [security2:error] [pid 521505:tid 521676] [client 158.23.184.117:36120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/db/uploader.php"] [unique_id "apPmD28byYE0iXl--K6tZwAAA0c"]
[Sun Aug 30 03:13:03.769501 2026] [authz_core:error] [pid 521505:tid 521661] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:03.769773 2026] [authz_core:error] [pid 521505:tid 521661] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:03.772405 2026] [security2:error] [pid 521505:tid 521673] [client 4.205.62.107:32461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/phpinfo01.php"] [unique_id "apPmD28byYE0iXl--K6taQAAA0Q"]
[Sun Aug 30 03:13:03.781586 2026] [security2:error] [pid 524122:tid 524326] [client 20.48.251.3:36900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/erty.php"] [unique_id "apPmD33lhEjKFiK_nBKGcAAAAdg"]
[Sun Aug 30 03:13:03.801872 2026] [security2:error] [pid 521505:tid 521743] [client 91.224.92.32:63566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.92.224.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "1stsourcesecurity.com"] [uri "/wp-login.php"] [unique_id "apPmD28byYE0iXl--K6tbQAAA4o"], referer: https://www.bing.com/
[Sun Aug 30 03:13:03.802631 2026] [authz_core:error] [pid 521505:tid 521658] [client 66.249.66.71:38177] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:03.803043 2026] [authz_core:error] [pid 521505:tid 521658] [client 66.249.66.71:38177] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:03.813679 2026] [authz_core:error] [pid 521505:tid 521729] [client 66.249.66.41:61346] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:03.814104 2026] [authz_core:error] [pid 521505:tid 521729] [client 66.249.66.41:61346] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:03.818629 2026] [authz_core:error] [pid 521505:tid 521757] [client 66.249.66.71:50215] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:03.819067 2026] [authz_core:error] [pid 521505:tid 521757] [client 66.249.66.71:50215] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:03.832294 2026] [security2:error] [pid 524122:tid 524312] [client 20.104.50.220:62813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/exp.php"] [unique_id "apPmD33lhEjKFiK_nBKGcwAAAco"]
[Sun Aug 30 03:13:03.835933 2026] [security2:error] [pid 521505:tid 521708] [client 20.151.200.44:23561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPmD28byYE0iXl--K6tcAAAA2c"]
[Sun Aug 30 03:13:03.841818 2026] [security2:error] [pid 521505:tid 521723] [client 20.48.250.41:37837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/maraz.php"] [unique_id "apPmD28byYE0iXl--K6tcQAAA3Y"]
[Sun Aug 30 03:13:03.856578 2026] [security2:error] [pid 521505:tid 521741] [client 20.104.50.220:61963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/gorila.php"] [unique_id "apPmD28byYE0iXl--K6tcwAAA4g"]
[Sun Aug 30 03:13:03.877445 2026] [security2:error] [pid 521505:tid 521717] [client 52.139.37.240:53262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/a.php"] [unique_id "apPmD28byYE0iXl--K6tdgAAA3A"]
[Sun Aug 30 03:13:03.883994 2026] [security2:error] [pid 521505:tid 521520] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/services/.env"] [unique_id "apPmD28byYE0iXl--K6teAADlw4"]
[Sun Aug 30 03:13:03.883995 2026] [security2:error] [pid 521505:tid 521591] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/service/.env"] [unique_id "apPmD28byYE0iXl--K6teQADl1U"]
[Sun Aug 30 03:13:03.894638 2026] [authz_core:error] [pid 521505:tid 521714] [client 66.249.66.39:40838] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:03.894905 2026] [authz_core:error] [pid 521505:tid 521714] [client 66.249.66.39:40838] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:03.902609 2026] [security2:error] [pid 521505:tid 521681] [client 158.23.184.117:36101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/i.php"] [unique_id "apPmD28byYE0iXl--K6tfAAAA0w"]
[Sun Aug 30 03:13:03.928570 2026] [security2:error] [pid 521505:tid 521689] [client 158.23.147.79:55410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-includes/assets/index.php"] [unique_id "apPmD28byYE0iXl--K6tfwAAA1Q"]
[Sun Aug 30 03:13:03.934960 2026] [security2:error] [pid 524122:tid 524375] [client 20.104.50.220:29120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/goods.php"] [unique_id "apPmD33lhEjKFiK_nBKGdQAAAgk"]
[Sun Aug 30 03:13:03.951435 2026] [security2:error] [pid 521505:tid 521541] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/shared/.env"] [unique_id "apPmD28byYE0iXl--K6thwADZiM"]
[Sun Aug 30 03:13:03.951504 2026] [security2:error] [pid 521505:tid 521564] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/shop/.env"] [unique_id "apPmD28byYE0iXl--K6tiAADZjo"]
[Sun Aug 30 03:13:03.976788 2026] [security2:error] [pid 521505:tid 521653] [client 20.104.50.220:16672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/.well-known/67.php"] [unique_id "apPmD28byYE0iXl--K6tjAAAAzA"]
[Sun Aug 30 03:13:04.004181 2026] [authz_core:error] [pid 521505:tid 521742] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:13:04.004531 2026] [authz_core:error] [pid 521505:tid 521742] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:13:04.005952 2026] [security2:error] [pid 521505:tid 521672] [client 20.48.250.41:37762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/kbfr.php"] [unique_id "apPmEG8byYE0iXl--K6tkQAAA0M"]
[Sun Aug 30 03:13:04.015804 2026] [authz_core:error] [pid 521505:tid 521755] [client 66.249.66.66:55582] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:04.016047 2026] [authz_core:error] [pid 521505:tid 521755] [client 66.249.66.66:55582] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:04.018704 2026] [security2:error] [pid 524122:tid 524346] [client 20.48.251.3:52245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/classsmtps.php"] [unique_id "apPmEH3lhEjKFiK_nBKGdwAAAew"]
[Sun Aug 30 03:13:04.034454 2026] [security2:error] [pid 521505:tid 521633] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/src/.env"] [unique_id "apPmEG8byYE0iXl--K6tkwADPH8"]
[Sun Aug 30 03:13:04.042362 2026] [security2:error] [pid 524122:tid 524347] [client 20.104.50.220:6138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/7.php"] [unique_id "apPmEH3lhEjKFiK_nBKGeQAAAe0"]
[Sun Aug 30 03:13:04.058083 2026] [authz_core:error] [pid 521505:tid 521657] [client 216.73.216.128:27728] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:04.058360 2026] [authz_core:error] [pid 521505:tid 521657] [client 216.73.216.128:27728] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:04.079571 2026] [security2:error] [pid 521505:tid 521636] [client 158.23.147.79:59037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/lock.php"] [unique_id "apPmEG8byYE0iXl--K6tmAAAAx8"]
[Sun Aug 30 03:13:04.096087 2026] [security2:error] [pid 521505:tid 521698] [client 158.23.184.117:36159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/wp-admin/css/index.php"] [unique_id "apPmEG8byYE0iXl--K6tmwAAA10"]
[Sun Aug 30 03:13:04.097296 2026] [security2:error] [pid 521505:tid 521758] [client 4.205.62.107:16799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/cache-compat.php"] [unique_id "apPmEG8byYE0iXl--K6tnAAAA5k"]
[Sun Aug 30 03:13:04.119033 2026] [security2:error] [pid 521505:tid 521726] [client 52.139.37.240:46968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/alfanew.php"] [unique_id "apPmEG8byYE0iXl--K6tnQAAA3k"]
[Sun Aug 30 03:13:04.149200 2026] [security2:error] [pid 521505:tid 521693] [client 20.48.250.41:37697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/wp-act.php"] [unique_id "apPmEG8byYE0iXl--K6tpQAAA1g"]
[Sun Aug 30 03:13:04.177781 2026] [authz_core:error] [pid 524122:tid 524305] [client 66.249.66.67:58616] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:04.178055 2026] [authz_core:error] [pid 524122:tid 524305] [client 66.249.66.67:58616] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:04.182703 2026] [security2:error] [pid 521505:tid 521535] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/srv/.env"] [unique_id "apPmEG8byYE0iXl--K6tpwADYB0"]
[Sun Aug 30 03:13:04.185132 2026] [security2:error] [pid 521505:tid 521555] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/stage/.env"] [unique_id "apPmEG8byYE0iXl--K6tqAADdTE"]
[Sun Aug 30 03:13:04.188398 2026] [security2:error] [pid 521505:tid 521734] [client 20.48.160.90:49929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/im.php"] [unique_id "apPmEG8byYE0iXl--K6tqgAAA4E"]
[Sun Aug 30 03:13:04.197857 2026] [security2:error] [pid 521505:tid 521702] [client 20.197.61.180:19467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/t.php"] [unique_id "apPmEG8byYE0iXl--K6tqwAAA2E"]
[Sun Aug 30 03:13:04.232413 2026] [security2:error] [pid 521505:tid 521600] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/staging/.env"] [unique_id "apPmEG8byYE0iXl--K6trwADU14"]
[Sun Aug 30 03:13:04.237554 2026] [security2:error] [pid 521505:tid 521725] [client 20.104.18.15:22403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/sym.php"] [unique_id "apPmEG8byYE0iXl--K6tsgAAA3g"]
[Sun Aug 30 03:13:04.243778 2026] [authz_core:error] [pid 521505:tid 521645] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:04.244031 2026] [authz_core:error] [pid 521505:tid 521645] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:04.246853 2026] [security2:error] [pid 521505:tid 521713] [client 158.23.184.117:36138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/wp-content/index.php"] [unique_id "apPmEG8byYE0iXl--K6ttAAAA2w"]
[Sun Aug 30 03:13:04.272704 2026] [security2:error] [pid 521505:tid 521738] [client 20.104.18.15:2045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/gulu.php"] [unique_id "apPmEG8byYE0iXl--K6ttQAAA4U"]
[Sun Aug 30 03:13:04.285429 2026] [security2:error] [pid 521505:tid 521662] [client 20.48.160.90:50018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/rsjlrria.php"] [unique_id "apPmEG8byYE0iXl--K6ttwAAAzk"]
[Sun Aug 30 03:13:04.289883 2026] [security2:error] [pid 521505:tid 521749] [client 20.48.250.41:37835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/24.php"] [unique_id "apPmEG8byYE0iXl--K6tuQAAA5A"]
[Sun Aug 30 03:13:04.304849 2026] [security2:error] [pid 521505:tid 521648] [client 20.151.200.44:63027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/t00l.php"] [unique_id "apPmEG8byYE0iXl--K6tugAAAys"]
[Sun Aug 30 03:13:04.317663 2026] [security2:error] [pid 521505:tid 521699] [client 52.139.37.240:49726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/text.php"] [unique_id "apPmEG8byYE0iXl--K6tuwAAA14"]
[Sun Aug 30 03:13:04.318440 2026] [security2:error] [pid 521505:tid 521629] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/stg/.env"] [unique_id "apPmEG8byYE0iXl--K6tvAADaXs"]
[Sun Aug 30 03:13:04.324844 2026] [security2:error] [pid 524122:tid 524263] [client 216.73.216.128:49386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/annotated.html"] [unique_id "apPmEH3lhEjKFiK_nBKGfQAAAZk"]
[Sun Aug 30 03:13:04.325066 2026] [security2:error] [pid 521505:tid 521691] [client 20.48.160.90:23758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/fc.php"] [unique_id "apPmEG8byYE0iXl--K6tvgAAA1Y"]
[Sun Aug 30 03:13:04.333919 2026] [security2:error] [pid 521505:tid 521577] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/stripe/.env"] [unique_id "apPmEG8byYE0iXl--K6twAADJkc"]
[Sun Aug 30 03:13:04.337539 2026] [cgid:error] [pid 521505:tid 521537] [remote 93.123.109.228:45324] AH01264: stderr from /home3/jvallesteros/jeanbooknerdstorytellersbox.com/sysinfo.cgi: script not found or unable to stat
[Sun Aug 30 03:13:04.351443 2026] [security2:error] [pid 521505:tid 521666] [client 68.155.159.216:60296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/dropdown.php"] [unique_id "apPmEG8byYE0iXl--K6txwAAAz0"]
[Sun Aug 30 03:13:04.369450 2026] [authz_core:error] [pid 524122:tid 524331] [client 66.249.66.201:40074] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:04.369739 2026] [authz_core:error] [pid 524122:tid 524331] [client 66.249.66.201:40074] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:04.386895 2026] [security2:error] [pid 521505:tid 521670] [client 158.23.184.117:36550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPmEG8byYE0iXl--K6t0QAAA0E"]
[Sun Aug 30 03:13:04.392378 2026] [security2:error] [pid 521505:tid 521733] [client 4.205.62.107:16350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/setup-config.php"] [unique_id "apPmEG8byYE0iXl--K6t1AAAA4A"]
[Sun Aug 30 03:13:04.395351 2026] [security2:error] [pid 521505:tid 521586] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/terraform.tfstate.backup"] [unique_id "apPmEG8byYE0iXl--K6t1QADHlA"]
[Sun Aug 30 03:13:04.400840 2026] [security2:error] [pid 521505:tid 521695] [client 20.104.49.130:63496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/reop3.php"] [unique_id "apPmEG8byYE0iXl--K6t1wAAA1o"]
[Sun Aug 30 03:13:04.420397 2026] [security2:error] [pid 521505:tid 521761] [client 20.48.160.90:50033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/AxAo.php"] [unique_id "apPmEG8byYE0iXl--K6t2gAAA5w"]
[Sun Aug 30 03:13:04.424288 2026] [security2:error] [pid 521505:tid 521739] [client 20.48.250.41:37755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/155.php"] [unique_id "apPmEG8byYE0iXl--K6t2wAAA4Y"]
[Sun Aug 30 03:13:04.437819 2026] [security2:error] [pid 521505:tid 521685] [client 20.104.49.130:63589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/pfm.php"] [unique_id "apPmEG8byYE0iXl--K6t3AAAA1A"]
[Sun Aug 30 03:13:04.447863 2026] [security2:error] [pid 521505:tid 521689] [client 20.104.50.220:51628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/dosya.php"] [unique_id "apPmEG8byYE0iXl--K6t3QAAA1Q"]
[Sun Aug 30 03:13:04.465015 2026] [security2:error] [pid 521505:tid 521649] [client 20.48.160.90:29151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/ke.php"] [unique_id "apPmEG8byYE0iXl--K6t4AAAAyw"]
[Sun Aug 30 03:13:04.467556 2026] [authz_core:error] [pid 521505:tid 521740] [client 66.249.66.64:49558] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:04.467816 2026] [authz_core:error] [pid 521505:tid 521740] [client 66.249.66.64:49558] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:04.471443 2026] [authz_core:error] [pid 521505:tid 521759] [client 66.249.66.74:62288] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:04.471746 2026] [authz_core:error] [pid 521505:tid 521759] [client 66.249.66.74:62288] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:04.471990 2026] [security2:error] [pid 521505:tid 521707] [client 4.205.62.107:15965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/xve22.php"] [unique_id "apPmEG8byYE0iXl--K6t4wAAA2Y"]
[Sun Aug 30 03:13:04.489266 2026] [security2:error] [pid 521505:tid 521632] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/test.php"] [unique_id "apPmEG8byYE0iXl--K6t5QADZH4"]
[Sun Aug 30 03:13:04.490432 2026] [security2:error] [pid 521505:tid 521574] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/test/.env"] [unique_id "apPmEG8byYE0iXl--K6t5gADZEQ"]
[Sun Aug 30 03:13:04.493298 2026] [authz_core:error] [pid 521505:tid 521692] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:13:04.493530 2026] [authz_core:error] [pid 521505:tid 521692] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:13:04.513206 2026] [security2:error] [pid 521505:tid 521566] [remote 162.240.171.12:42256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.171.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ilfcllc.com"] [uri "/wp-login.php"] [unique_id "apPmEG8byYE0iXl--K6t6QADLTw"]
[Sun Aug 30 03:13:04.515955 2026] [security2:error] [pid 521505:tid 521665] [client 20.104.50.220:33342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/FoxWSO-full.php"] [unique_id "apPmEG8byYE0iXl--K6t6gAAAzw"]
[Sun Aug 30 03:13:04.521798 2026] [security2:error] [pid 521505:tid 521567] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/user/.env"] [unique_id "apPmEG8byYE0iXl--K6t7AADWT0"]
[Sun Aug 30 03:13:04.524047 2026] [security2:error] [pid 521505:tid 521641] [client 158.23.147.79:44866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/index/function.php"] [unique_id "apPmEG8byYE0iXl--K6t7QAAAyQ"]
[Sun Aug 30 03:13:04.529092 2026] [security2:error] [pid 521505:tid 521640] [client 158.23.184.117:36561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPmEG8byYE0iXl--K6t8AAAAyM"]
[Sun Aug 30 03:13:04.532943 2026] [security2:error] [pid 521505:tid 521637] [client 52.139.37.240:9488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/f.php"] [unique_id "apPmEG8byYE0iXl--K6t8gAAAyA"]
[Sun Aug 30 03:13:04.538441 2026] [authz_core:error] [pid 521505:tid 521727] [client 66.249.66.74:59497] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:04.538704 2026] [authz_core:error] [pid 521505:tid 521727] [client 66.249.66.74:59497] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:04.544960 2026] [security2:error] [pid 521505:tid 521544] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/v2/.env"] [unique_id "apPmEG8byYE0iXl--K6t9AADaCY"]
[Sun Aug 30 03:13:04.545887 2026] [security2:error] [pid 521505:tid 521598] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/v3/.env"] [unique_id "apPmEG8byYE0iXl--K6t9QADaFw"]
[Sun Aug 30 03:13:04.545952 2026] [security2:error] [pid 521505:tid 521530] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/v1/.env"] [unique_id "apPmEG8byYE0iXl--K6t9gADaBg"]
[Sun Aug 30 03:13:04.546083 2026] [security2:error] [pid 524122:tid 524356] [client 20.104.18.15:51068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/ssla.php"] [unique_id "apPmEH3lhEjKFiK_nBKGgQAAAfY"]
[Sun Aug 30 03:13:04.569150 2026] [security2:error] [pid 521505:tid 521745] [client 20.48.160.90:49261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/class17.php"] [unique_id "apPmEG8byYE0iXl--K6t-gAAA4w"]
[Sun Aug 30 03:13:04.574464 2026] [security2:error] [pid 521505:tid 521757] [client 20.104.49.130:57648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alarm-monitoring.net"] [uri "/wp.php"] [unique_id "apPmEG8byYE0iXl--K6t-wAAA5g"]
[Sun Aug 30 03:13:04.595474 2026] [security2:error] [pid 521505:tid 521671] [client 20.48.250.41:37866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/file.php"] [unique_id "apPmEG8byYE0iXl--K6t_gAAA0I"]
[Sun Aug 30 03:13:04.596294 2026] [authz_core:error] [pid 521505:tid 521704] [client 66.249.66.71:37816] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:04.596577 2026] [authz_core:error] [pid 521505:tid 521704] [client 66.249.66.71:37816] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:04.676992 2026] [security2:error] [pid 524122:tid 524290] [client 20.48.251.3:65489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/wp-konfig.backup.php"] [unique_id "apPmEH3lhEjKFiK_nBKGhAAAAbQ"]
[Sun Aug 30 03:13:04.702622 2026] [security2:error] [pid 521505:tid 521731] [client 20.104.50.220:24862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/adminfuns.php"] [unique_id "apPmEG8byYE0iXl--K6uDAAAA34"]
[Sun Aug 30 03:13:04.717269 2026] [security2:error] [pid 524122:tid 524261] [client 158.23.184.117:36593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/wp-load.php"] [unique_id "apPmEH3lhEjKFiK_nBKGhgAAAZc"]
[Sun Aug 30 03:13:04.729816 2026] [security2:error] [pid 521505:tid 521630] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/var/www/html/.env"] [unique_id "apPmEG8byYE0iXl--K6uEgADOXw"]
[Sun Aug 30 03:13:04.730608 2026] [security2:error] [pid 521505:tid 521589] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/var/www/.env"] [unique_id "apPmEG8byYE0iXl--K6uEQADOVM"]
[Sun Aug 30 03:13:04.739776 2026] [security2:error] [pid 521505:tid 521702] [client 52.139.37.240:52590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "apPmEG8byYE0iXl--K6uFAAAA2E"]
[Sun Aug 30 03:13:04.748841 2026] [authz_core:error] [pid 521505:tid 521749] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:04.749250 2026] [authz_core:error] [pid 521505:tid 521749] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:04.763332 2026] [security2:error] [pid 524122:tid 524316] [client 20.48.250.41:37776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/wp-p2r3q9c8k4.php"] [unique_id "apPmEH3lhEjKFiK_nBKGiAAAAc4"]
[Sun Aug 30 03:13:04.775511 2026] [security2:error] [pid 521505:tid 521729] [client 20.104.50.220:31205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-admin/css/wp-conflg.php"] [unique_id "apPmEG8byYE0iXl--K6uFgAAA3w"]
[Sun Aug 30 03:13:04.791391 2026] [security2:error] [pid 521505:tid 521626] [remote 162.240.171.12:42256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.171.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ilfcllc.com"] [uri "/wp-login.php"] [unique_id "apPmEG8byYE0iXl--K6uFwADL3g"], referer: https://mail.ilfcllc.com/wp-login.php
[Sun Aug 30 03:13:04.824411 2026] [security2:error] [pid 521505:tid 521747] [client 158.23.147.79:52698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/.well-known/content.php"] [unique_id "apPmEG8byYE0iXl--K6uGQAAA44"]
[Sun Aug 30 03:13:04.826169 2026] [security2:error] [pid 524122:tid 524298] [client 4.205.62.107:29146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/tinyfilemanager.php"] [unique_id "apPmEH3lhEjKFiK_nBKGigAAAbw"]
[Sun Aug 30 03:13:04.858091 2026] [security2:error] [pid 521505:tid 521710] [client 158.23.184.117:36119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/222.php"] [unique_id "apPmEG8byYE0iXl--K6uGwAAA2k"]
[Sun Aug 30 03:13:04.864744 2026] [security2:error] [pid 521505:tid 521668] [client 91.224.92.32:64362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.92.224.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "1superiormachine.com"] [uri "/wp-login.php"] [unique_id "apPmEG8byYE0iXl--K6uHAAAAz8"]
[Sun Aug 30 03:13:04.903424 2026] [authz_core:error] [pid 521505:tid 521647] [client 66.249.66.69:42708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:04.903867 2026] [authz_core:error] [pid 521505:tid 521647] [client 66.249.66.69:42708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:04.913886 2026] [security2:error] [pid 521505:tid 521733] [client 20.48.250.41:37796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/06.php"] [unique_id "apPmEG8byYE0iXl--K6uIwAAA4A"]
[Sun Aug 30 03:13:04.914189 2026] [security2:error] [pid 521505:tid 521635] [client 20.104.49.130:36783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/f35.update.php"] [unique_id "apPmEG8byYE0iXl--K6uJAAAAx4"]
[Sun Aug 30 03:13:04.919938 2026] [security2:error] [pid 521505:tid 521611] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/web/.env"] [unique_id "apPmEG8byYE0iXl--K6uJgADcGk"]
[Sun Aug 30 03:13:04.920366 2026] [security2:error] [pid 521505:tid 521621] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/website/.env"] [unique_id "apPmEG8byYE0iXl--K6uMgADcHM"]
[Sun Aug 30 03:13:04.921166 2026] [security2:error] [pid 521505:tid 521728] [client 20.197.61.180:1646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/fw.php"] [unique_id "apPmEG8byYE0iXl--K6uMwAAA3s"]
[Sun Aug 30 03:13:04.938410 2026] [security2:error] [pid 521505:tid 521746] [client 20.48.251.3:36892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/wp-config.backup.php"] [unique_id "apPmEG8byYE0iXl--K6uNAAAA40"]
[Sun Aug 30 03:13:04.984966 2026] [security2:error] [pid 521505:tid 521670] [client 52.139.37.240:53259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/options.php"] [unique_id "apPmEG8byYE0iXl--K6uOAAAA0E"]
[Sun Aug 30 03:13:04.994768 2026] [security2:error] [pid 521505:tid 521761] [client 4.205.62.107:32487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/cxc.php"] [unique_id "apPmEG8byYE0iXl--K6uOgAAA5w"]
[Sun Aug 30 03:13:05.003774 2026] [security2:error] [pid 524122:tid 524281] [client 158.23.184.117:36137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/aaa.php"] [unique_id "apPmEX3lhEjKFiK_nBKGjgAAAas"]
[Sun Aug 30 03:13:05.013712 2026] [authz_core:error] [pid 521505:tid 521644] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:13:05.014134 2026] [authz_core:error] [pid 521505:tid 521644] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:13:05.041638 2026] [security2:error] [pid 521505:tid 521736] [client 20.104.50.220:61394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/vanta.php"] [unique_id "apPmEW8byYE0iXl--K6uPQAAA4M"]
[Sun Aug 30 03:13:05.063748 2026] [authz_core:error] [pid 521505:tid 521653] [client 66.249.66.205:46459] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:05.064004 2026] [authz_core:error] [pid 521505:tid 521653] [client 66.249.66.205:46459] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:05.068207 2026] [security2:error] [pid 521505:tid 521533] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/wp-config.php.bak"] [unique_id "apPmEW8byYE0iXl--K6uQwADLRs"]
[Sun Aug 30 03:13:05.068237 2026] [security2:error] [pid 521505:tid 521581] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/wp-config.php.new"] [unique_id "apPmEW8byYE0iXl--K6uRAADLUs"]
[Sun Aug 30 03:13:05.068239 2026] [security2:error] [pid 521505:tid 521618] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/wp-config.php.old"] [unique_id "apPmEW8byYE0iXl--K6uRQADLXA"]
[Sun Aug 30 03:13:05.068606 2026] [security2:error] [pid 521505:tid 521605] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/wp-config.php"] [unique_id "apPmEW8byYE0iXl--K6uQgADLWM"]
[Sun Aug 30 03:13:05.071703 2026] [security2:error] [pid 521505:tid 521585] [remote 93.123.109.228:45324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPmEW8byYE0iXl--K6uSAADPE8"]
[Sun Aug 30 03:13:05.084050 2026] [security2:error] [pid 524122:tid 524321] [client 20.48.250.41:37838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/class.php"] [unique_id "apPmEX3lhEjKFiK_nBKGkQAAAdM"]
[Sun Aug 30 03:13:05.102491 2026] [security2:error] [pid 521505:tid 521694] [client 158.23.147.79:55399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/cong.php"] [unique_id "apPmEW8byYE0iXl--K6uSwAAA1k"]
[Sun Aug 30 03:13:05.112434 2026] [security2:error] [pid 524122:tid 524291] [client 20.104.50.220:17225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/.well-known/68.php"] [unique_id "apPmEX3lhEjKFiK_nBKGkgAAAbU"]
[Sun Aug 30 03:13:05.128931 2026] [security2:error] [pid 524122:tid 524310] [client 20.104.50.220:62817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/pHpINJ.php"] [unique_id "apPmEX3lhEjKFiK_nBKGkwAAAcg"]
[Sun Aug 30 03:13:05.145231 2026] [security2:error] [pid 524122:tid 524335] [client 20.104.50.220:29158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/codrs.php"] [unique_id "apPmEX3lhEjKFiK_nBKGlAAAAeE"]
[Sun Aug 30 03:13:05.145524 2026] [security2:error] [pid 521505:tid 521703] [client 158.23.184.117:36579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/admin/function.php"] [unique_id "apPmEW8byYE0iXl--K6uTQAAA2I"]
[Sun Aug 30 03:13:05.158583 2026] [security2:error] [pid 524122:tid 524366] [client 20.48.251.3:52192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/cache-compat.php"] [unique_id "apPmEX3lhEjKFiK_nBKGlgAAAgA"]
[Sun Aug 30 03:13:05.165840 2026] [authz_core:error] [pid 524122:tid 524293] [client 216.73.216.128:9566] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:05.166290 2026] [authz_core:error] [pid 524122:tid 524293] [client 216.73.216.128:9566] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:05.191164 2026] [security2:error] [pid 521505:tid 521690] [client 20.104.50.220:6127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/6.php"] [unique_id "apPmEW8byYE0iXl--K6uTgAAA1U"]
[Sun Aug 30 03:13:05.194941 2026] [security2:error] [pid 521505:tid 521636] [client 52.139.37.240:9472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "apPmEW8byYE0iXl--K6uTwAAAx8"]
[Sun Aug 30 03:13:05.234379 2026] [security2:error] [pid 521505:tid 521745] [client 4.205.62.107:17466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/aws_keys.php"] [unique_id "apPmEW8byYE0iXl--K6uUgAAA4w"]
[Sun Aug 30 03:13:05.240818 2026] [security2:error] [pid 524122:tid 524286] [client 20.48.250.41:37787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/8.php"] [unique_id "apPmEX3lhEjKFiK_nBKGmAAAAbA"]
[Sun Aug 30 03:13:05.258343 2026] [security2:error] [pid 521505:tid 521718] [client 93.123.109.228:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/.env"] [unique_id "apPmEW8byYE0iXl--K6uVQAAA3E"]
[Sun Aug 30 03:13:05.281985 2026] [authz_core:error] [pid 521505:tid 521701] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:05.282188 2026] [authz_core:error] [pid 521505:tid 521742] [client 66.249.66.68:63213] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:05.282242 2026] [authz_core:error] [pid 521505:tid 521701] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:05.282429 2026] [authz_core:error] [pid 521505:tid 521742] [client 66.249.66.68:63213] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:05.335276 2026] [security2:error] [pid 524122:tid 524364] [client 158.23.184.117:36119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/system_log.php"] [unique_id "apPmEX3lhEjKFiK_nBKGmgAAAf4"]
[Sun Aug 30 03:13:05.377632 2026] [security2:error] [pid 521505:tid 521731] [client 104.248.114.212:61936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.114.248.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lenoreashwood.com"] [uri "/images/images/cache.php"] [unique_id "apPmEW8byYE0iXl--K6uXwAAA34"], referer: www.google.com
[Sun Aug 30 03:13:05.379165 2026] [security2:error] [pid 524122:tid 524357] [client 93.123.109.228:43692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(\\\\/\\\\*\\\\!? ?(?:select|grant|delete|insert|drop|alter|replace|truncate|update|create|rename|describe|union|concat|group_concat))" at REQUEST_FILENAME. [file "/opt/mod_security/hg_rules.conf"] [line "1019"] [id "9000042"] [rev "2.2.2"] [msg "SQL Comment Sequence Detected."] [data "/*update"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/*update.cgi*"] [unique_id "apPmEX3lhEjKFiK_nBKGmwAAAfc"]
[Sun Aug 30 03:13:05.385386 2026] [security2:error] [pid 521505:tid 521675] [client 93.123.109.228:43614] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/backend/.env"] [unique_id "apPmEW8byYE0iXl--K6uYAAAA0Y"]
[Sun Aug 30 03:13:05.400548 2026] [security2:error] [pid 524122:tid 524280] [client 20.48.250.41:37789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/0x0x.php"] [unique_id "apPmEX3lhEjKFiK_nBKGngAAAao"]
[Sun Aug 30 03:13:05.401470 2026] [security2:error] [pid 521505:tid 521713] [client 20.151.200.44:52038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/is.php"] [unique_id "apPmEW8byYE0iXl--K6uYQAAA2w"]
[Sun Aug 30 03:13:05.402222 2026] [security2:error] [pid 521505:tid 521725] [client 20.104.18.15:22496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/8.php"] [unique_id "apPmEW8byYE0iXl--K6uYgAAA3g"]
[Sun Aug 30 03:13:05.406077 2026] [security2:error] [pid 524122:tid 524328] [client 20.104.18.15:1940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/replace.php"] [unique_id "apPmEX3lhEjKFiK_nBKGoAAAAdo"]
[Sun Aug 30 03:13:05.427103 2026] [security2:error] [pid 521505:tid 521688] [client 52.139.37.240:46948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apPmEW8byYE0iXl--K6uZwAAA1M"]
[Sun Aug 30 03:13:05.453965 2026] [security2:error] [pid 521505:tid 521699] [client 68.155.159.216:60980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/.well-known/index.php"] [unique_id "apPmEW8byYE0iXl--K6uaQAAA14"]
[Sun Aug 30 03:13:05.462484 2026] [security2:error] [pid 521505:tid 521639] [client 93.123.109.228:43602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/.docker/.env"] [unique_id "apPmEW8byYE0iXl--K6uawAAAyI"]
[Sun Aug 30 03:13:05.467096 2026] [security2:error] [pid 521505:tid 521643] [client 93.123.109.228:43670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/.docker/laravel/app/.env"] [unique_id "apPmEW8byYE0iXl--K6ubAAAAyY"]
[Sun Aug 30 03:13:05.494078 2026] [authz_core:error] [pid 521505:tid 521687] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:13:05.494333 2026] [authz_core:error] [pid 521505:tid 521687] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:13:05.525484 2026] [security2:error] [pid 521505:tid 521681] [client 4.205.62.107:15811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/wp-admin/sc.php"] [unique_id "apPmEW8byYE0iXl--K6udAAAA0w"]
[Sun Aug 30 03:13:05.528525 2026] [security2:error] [pid 521505:tid 521648] [client 93.123.109.228:43614] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/.env"] [unique_id "apPmEW8byYE0iXl--K6udQAAAys"]
[Sun Aug 30 03:13:05.543380 2026] [security2:error] [pid 521505:tid 521741] [client 158.23.147.79:52701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-includes/js/index.php"] [unique_id "apPmEW8byYE0iXl--K6udgAAA4g"]
[Sun Aug 30 03:13:05.548972 2026] [security2:error] [pid 524122:tid 524272] [client 20.48.250.41:37784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/166.php"] [unique_id "apPmEX3lhEjKFiK_nBKGpwAAAaI"]
[Sun Aug 30 03:13:05.552449 2026] [security2:error] [pid 524122:tid 524315] [client 93.123.109.228:43710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/.env.backup"] [unique_id "apPmEX3lhEjKFiK_nBKGqAAAAc0"]
[Sun Aug 30 03:13:05.559132 2026] [security2:error] [pid 524122:tid 524352] [client 104.248.114.212:51087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.114.248.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lenoreashwood.com"] [uri "/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cache.php"] [unique_id "apPmEX3lhEjKFiK_nBKGqQAAAfI"], referer: www.google.com
[Sun Aug 30 03:13:05.567007 2026] [security2:error] [pid 521505:tid 521645] [client 93.123.109.228:43644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/.env.bak"] [unique_id "apPmEW8byYE0iXl--K6udwAAAyg"]
[Sun Aug 30 03:13:05.573095 2026] [security2:error] [pid 521505:tid 521635] [client 158.23.184.117:36109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/wp-content/uploads/admin.php"] [unique_id "apPmEW8byYE0iXl--K6ueAAAAx4"]
[Sun Aug 30 03:13:05.590610 2026] [security2:error] [pid 521505:tid 521704] [client 20.104.50.220:63504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/error.php"] [unique_id "apPmEW8byYE0iXl--K6uegAAA2M"]
[Sun Aug 30 03:13:05.609277 2026] [security2:error] [pid 521505:tid 521740] [client 4.205.62.107:15943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/06.php"] [unique_id "apPmEW8byYE0iXl--K6uewAAA4c"]
[Sun Aug 30 03:13:05.611511 2026] [security2:error] [pid 521505:tid 521749] [client 20.48.160.90:50004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/tf.php"] [unique_id "apPmEW8byYE0iXl--K6ufAAAA5A"]
[Sun Aug 30 03:13:05.629884 2026] [security2:error] [pid 524122:tid 524374] [client 52.139.37.240:9344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/index/function.php"] [unique_id "apPmEX3lhEjKFiK_nBKGrgAAAgg"]
[Sun Aug 30 03:13:05.631469 2026] [security2:error] [pid 524122:tid 524348] [client 20.151.200.44:45989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/update/da222.php"] [unique_id "apPmEX3lhEjKFiK_nBKGrwAAAe4"]
[Sun Aug 30 03:13:05.654712 2026] [security2:error] [pid 521505:tid 521682] [client 20.104.50.220:33326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/FoxWSO.php"] [unique_id "apPmEW8byYE0iXl--K6ufgAAA00"]
[Sun Aug 30 03:13:05.663555 2026] [authz_core:error] [pid 521505:tid 521715] [client 66.249.66.68:63213] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:05.663975 2026] [authz_core:error] [pid 521505:tid 521715] [client 66.249.66.68:63213] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:05.681308 2026] [security2:error] [pid 521505:tid 521719] [client 20.197.61.180:16061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/test.php"] [unique_id "apPmEW8byYE0iXl--K6uggAAA3I"]
[Sun Aug 30 03:13:05.697978 2026] [security2:error] [pid 524122:tid 524320] [client 93.123.109.228:43710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/.env.php"] [unique_id "apPmEX3lhEjKFiK_nBKGsgAAAdI"]
[Sun Aug 30 03:13:05.703688 2026] [security2:error] [pid 521505:tid 521727] [client 93.123.109.228:43602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/.env.old"] [unique_id "apPmEW8byYE0iXl--K6uhQAAA3o"]
[Sun Aug 30 03:13:05.709896 2026] [security2:error] [pid 521505:tid 521736] [client 20.48.160.90:28781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/okxoby.php"] [unique_id "apPmEW8byYE0iXl--K6uhwAAA4M"]
[Sun Aug 30 03:13:05.714065 2026] [security2:error] [pid 524122:tid 524378] [client 20.104.18.15:51127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apPmEX3lhEjKFiK_nBKGtQAAAgw"]
[Sun Aug 30 03:13:05.739898 2026] [security2:error] [pid 524122:tid 524326] [client 20.48.250.41:37824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/h2a2ck.php"] [unique_id "apPmEX3lhEjKFiK_nBKGuQAAAdg"]
[Sun Aug 30 03:13:05.744961 2026] [security2:error] [pid 524122:tid 524311] [client 20.48.160.90:50338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/px.php"] [unique_id "apPmEX3lhEjKFiK_nBKGugAAAck"]
[Sun Aug 30 03:13:05.746331 2026] [security2:error] [pid 524122:tid 524312] [client 93.123.109.228:43818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/.env.swp"] [unique_id "apPmEX3lhEjKFiK_nBKGuwAAAco"]
[Sun Aug 30 03:13:05.763703 2026] [security2:error] [pid 524122:tid 524275] [client 158.23.184.117:36558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/wp-links-opml.php"] [unique_id "apPmEX3lhEjKFiK_nBKGvQAAAaU"]
[Sun Aug 30 03:13:05.789209 2026] [authz_core:error] [pid 521505:tid 521677] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:05.789469 2026] [authz_core:error] [pid 521505:tid 521677] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:05.797435 2026] [security2:error] [pid 521505:tid 521672] [client 216.73.216.128:56889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mysqlupgrade"] [unique_id "apPmEW8byYE0iXl--K6ujAAAA0M"]
[Sun Aug 30 03:13:05.815055 2026] [security2:error] [pid 524122:tid 524304] [client 20.48.251.3:46211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/packed.php"] [unique_id "apPmEX3lhEjKFiK_nBKGvgAAAcI"]
[Sun Aug 30 03:13:05.825672 2026] [security2:error] [pid 521505:tid 521650] [client 93.123.109.228:43718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/.env~"] [unique_id "apPmEW8byYE0iXl--K6ujwAAAy0"]
[Sun Aug 30 03:13:05.830780 2026] [security2:error] [pid 524122:tid 524346] [client 104.248.114.212:51100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.114.248.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lenoreashwood.com"] [uri "/images/images/images/images/images/images/images/images/cache.php"] [unique_id "apPmEX3lhEjKFiK_nBKGwgAAAew"], referer: www.google.com
[Sun Aug 30 03:13:05.842584 2026] [security2:error] [pid 524122:tid 524345] [client 107.189.14.87:49337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.14.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oklahomapersonalinjury.tulsadivorceattorney.pro"] [uri "/wp-login.php"] [unique_id "apPmEX3lhEjKFiK_nBKGvwAAAes"]
[Sun Aug 30 03:13:05.848251 2026] [security2:error] [pid 524122:tid 524256] [client 52.139.37.240:46960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-admin/user/index.php"] [unique_id "apPmEX3lhEjKFiK_nBKGxAAAAZI"]
[Sun Aug 30 03:13:05.854757 2026] [security2:error] [pid 524122:tid 524367] [client 20.104.50.220:24878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/goods.php"] [unique_id "apPmEX3lhEjKFiK_nBKGxQAAAgE"]
[Sun Aug 30 03:13:05.872622 2026] [security2:error] [pid 524122:tid 524266] [client 20.48.250.41:37706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/error_log.php"] [unique_id "apPmEX3lhEjKFiK_nBKGyQAAAZw"]
[Sun Aug 30 03:13:05.888182 2026] [security2:error] [pid 521505:tid 521703] [client 93.123.109.228:43656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/.git/config.bak"] [unique_id "apPmEW8byYE0iXl--K6ulQAAA2I"]
[Sun Aug 30 03:13:05.891603 2026] [security2:error] [pid 521505:tid 521698] [client 20.48.160.90:49933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/esuutzzx.php"] [unique_id "apPmEW8byYE0iXl--K6ulwAAA10"]
[Sun Aug 30 03:13:05.894707 2026] [security2:error] [pid 524122:tid 524263] [client 93.123.109.228:43818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/.git/config.old"] [unique_id "apPmEX3lhEjKFiK_nBKGywAAAZk"]
[Sun Aug 30 03:13:05.903076 2026] [security2:error] [pid 524122:tid 524259] [client 93.123.109.228:43804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/.git/config~"] [unique_id "apPmEX3lhEjKFiK_nBKGzAAAAZU"]
[Sun Aug 30 03:13:05.905885 2026] [security2:error] [pid 524122:tid 524377] [client 158.23.184.117:36102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/wp.php"] [unique_id "apPmEX3lhEjKFiK_nBKGzgAAAgs"]
[Sun Aug 30 03:13:05.910625 2026] [security2:error] [pid 521505:tid 521636] [client 20.104.50.220:51012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/manager.php"] [unique_id "apPmEW8byYE0iXl--K6umgAAAx8"]
[Sun Aug 30 03:13:05.912881 2026] [security2:error] [pid 521505:tid 521726] [client 20.48.160.90:23783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/jg.php"] [unique_id "apPmEW8byYE0iXl--K6unAAAA3k"]
[Sun Aug 30 03:13:05.964375 2026] [authz_core:error] [pid 521505:tid 521693] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:13:05.964650 2026] [authz_core:error] [pid 521505:tid 521693] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices
[Sun Aug 30 03:13:05.982813 2026] [security2:error] [pid 521505:tid 521735] [client 4.205.62.107:29160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/05.php"] [unique_id "apPmEW8byYE0iXl--K6uowAAA4I"]
[Sun Aug 30 03:13:06.029348 2026] [security2:error] [pid 521505:tid 521716] [client 20.48.250.41:37822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/403.php"] [unique_id "apPmEm8byYE0iXl--K6upwAAA28"]
[Sun Aug 30 03:13:06.031352 2026] [security2:error] [pid 521505:tid 521692] [client 20.48.160.90:23727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/replace.php"] [unique_id "apPmEm8byYE0iXl--K6uqAAAA1c"]
[Sun Aug 30 03:13:06.041526 2026] [authz_core:error] [pid 521505:tid 521667] [client 66.249.66.75:50429] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:06.041817 2026] [authz_core:error] [pid 521505:tid 521667] [client 66.249.66.75:50429] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:06.044401 2026] [security2:error] [pid 521505:tid 521664] [client 20.151.200.44:43943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ermes-it.it"] [uri "/wp-login.php"] [unique_id "apPmEm8byYE0iXl--K6upgAAAzs"]
[Sun Aug 30 03:13:06.049823 2026] [security2:error] [pid 521505:tid 521760] [client 158.23.184.117:36158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/.well-known/hp2.php"] [unique_id "apPmEm8byYE0iXl--K6urgAAA5s"]
[Sun Aug 30 03:13:06.055458 2026] [security2:error] [pid 521505:tid 521683] [client 20.48.160.90:23764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/yj.php"] [unique_id "apPmEm8byYE0iXl--K6urwAAA04"]
[Sun Aug 30 03:13:06.057012 2026] [security2:error] [pid 521505:tid 521731] [client 104.248.114.212:58636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.114.248.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lenoreashwood.com"] [uri "/images/images/images/images/images/images/images/cache.php"] [unique_id "apPmEm8byYE0iXl--K6usAAAA34"], referer: www.google.com
[Sun Aug 30 03:13:06.067076 2026] [security2:error] [pid 521505:tid 521647] [client 20.104.49.130:36798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/term.php"] [unique_id "apPmEm8byYE0iXl--K6usgAAAyo"]
[Sun Aug 30 03:13:06.067847 2026] [security2:error] [pid 521505:tid 521579] [remote 97.74.87.194:59932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "holacleaning.com.au"] [uri "/wp-login.php"] [unique_id "apPmEm8byYE0iXl--K6usQADmkk"]
[Sun Aug 30 03:13:06.072137 2026] [security2:error] [pid 521505:tid 521701] [client 20.48.251.3:36921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/edit.php"] [unique_id "apPmEm8byYE0iXl--K6uswAAA2A"]
[Sun Aug 30 03:13:06.116666 2026] [security2:error] [pid 521505:tid 521699] [client 52.139.37.240:49722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/jquery.php"] [unique_id "apPmEm8byYE0iXl--K6uuAAAA14"]
[Sun Aug 30 03:13:06.156571 2026] [security2:error] [pid 521505:tid 521754] [client 158.23.147.79:55375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-content/index.php"] [unique_id "apPmEm8byYE0iXl--K6uvQAAA5U"]
[Sun Aug 30 03:13:06.175014 2026] [security2:error] [pid 524122:tid 524268] [client 20.48.160.90:49987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/gulu.php"] [unique_id "apPmEn3lhEjKFiK_nBKG3QAAAZ4"]
[Sun Aug 30 03:13:06.185672 2026] [security2:error] [pid 524122:tid 524329] [client 20.48.250.41:37728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/cytyr.php"] [unique_id "apPmEn3lhEjKFiK_nBKG3wAAAds"]
[Sun Aug 30 03:13:06.191607 2026] [security2:error] [pid 524122:tid 524316] [client 158.23.184.117:36105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/.well-known/mh.php"] [unique_id "apPmEn3lhEjKFiK_nBKG4AAAAc4"]
[Sun Aug 30 03:13:06.195800 2026] [security2:error] [pid 524122:tid 524340] [client 20.104.50.220:59559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/sh3ll.php"] [unique_id "apPmEn3lhEjKFiK_nBKG4QAAAeY"]
[Sun Aug 30 03:13:06.225804 2026] [security2:error] [pid 524122:tid 524353] [client 4.205.62.107:32028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/oiko6u.php"] [unique_id "apPmEn3lhEjKFiK_nBKG5AAAAfM"]
[Sun Aug 30 03:13:06.248704 2026] [authz_core:error] [pid 521505:tid 521704] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:06.248961 2026] [authz_core:error] [pid 521505:tid 521704] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:06.249684 2026] [security2:error] [pid 524122:tid 524321] [client 20.104.50.220:16728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/.well-known/66.php"] [unique_id "apPmEn3lhEjKFiK_nBKG5wAAAdM"]
[Sun Aug 30 03:13:06.298183 2026] [security2:error] [pid 521505:tid 521729] [client 107.189.14.87:49438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.14.189.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oklahomapersonalinjury.tulsadivorceattorney.pro"] [uri "/wp-login.php"] [unique_id "apPmEm8byYE0iXl--K6uyQAAA3w"]
[Sun Aug 30 03:13:06.302809 2026] [security2:error] [pid 524122:tid 524366] [client 20.104.50.220:62797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/jingan.php"] [unique_id "apPmEn3lhEjKFiK_nBKG6AAAAgA"]
[Sun Aug 30 03:13:06.303224 2026] [security2:error] [pid 524122:tid 524269] [client 20.104.49.130:63577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wdfjba.org"] [uri "/one.php"] [unique_id "apPmEn3lhEjKFiK_nBKG6QAAAZ8"]
[Sun Aug 30 03:13:06.310004 2026] [security2:error] [pid 524122:tid 524343] [client 20.48.251.3:59879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/aws_keys.php"] [unique_id "apPmEn3lhEjKFiK_nBKG6wAAAek"]
[Sun Aug 30 03:13:06.310619 2026] [authz_core:error] [pid 524122:tid 524279] [client 216.73.216.128:36316] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:06.310920 2026] [authz_core:error] [pid 524122:tid 524279] [client 216.73.216.128:36316] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:06.331181 2026] [security2:error] [pid 521505:tid 521700] [client 52.139.37.240:46931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/simple.php"] [unique_id "apPmEm8byYE0iXl--K6uywAAA18"]
[Sun Aug 30 03:13:06.332959 2026] [security2:error] [pid 524122:tid 524310] [client 158.23.184.117:36600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/about/function.php"] [unique_id "apPmEn3lhEjKFiK_nBKG9AAAAcg"]
[Sun Aug 30 03:13:06.335023 2026] [security2:error] [pid 521505:tid 521640] [client 20.104.50.220:5473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/5.php"] [unique_id "apPmEm8byYE0iXl--K6uzAAAAyM"]
[Sun Aug 30 03:13:06.339068 2026] [security2:error] [pid 524122:tid 524364] [client 20.104.50.220:28709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/robot.php"] [unique_id "apPmEn3lhEjKFiK_nBKG9gAAAf4"]
[Sun Aug 30 03:13:06.355016 2026] [authz_core:error] [pid 524122:tid 524357] [client 66.249.66.75:36010] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:06.355287 2026] [authz_core:error] [pid 524122:tid 524357] [client 66.249.66.75:36010] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:06.365620 2026] [security2:error] [pid 524122:tid 524295] [client 4.205.62.107:16779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/umgebung.php"] [unique_id "apPmEn3lhEjKFiK_nBKG-QAAAbk"]
[Sun Aug 30 03:13:06.371217 2026] [autoindex:error] [pid 524122:tid 524338] [client 93.123.109.228:43678] AH01276: Cannot serve directory /home3/jvallesteros/jeanbooknerdstorytellersbox.com/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:13:06.396677 2026] [security2:error] [pid 521505:tid 521747] [client 20.48.250.41:37834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/galer.php"] [unique_id "apPmEm8byYE0iXl--K6u0wAAA44"]
[Sun Aug 30 03:13:06.413018 2026] [security2:error] [pid 521505:tid 521707] [client 104.248.114.212:61407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.114.248.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lenoreashwood.com"] [uri "/images/images/images/images/images/images/cache.php"] [unique_id "apPmEm8byYE0iXl--K6u1QAAA2Y"], referer: www.google.com
[Sun Aug 30 03:13:06.417394 2026] [security2:error] [pid 521505:tid 521752] [client 93.123.109.228:43778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/.wp-config.php.swp"] [unique_id "apPmEm8byYE0iXl--K6u1gAAA5M"]
[Sun Aug 30 03:13:06.420781 2026] [security2:error] [pid 521505:tid 521742] [client 20.197.61.180:16027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/dropdown.php"] [unique_id "apPmEm8byYE0iXl--K6u1wAAA4k"]
[Sun Aug 30 03:13:06.447177 2026] [authz_core:error] [pid 521505:tid 521674] [client 216.73.216.128:48435] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:06.447462 2026] [authz_core:error] [pid 521505:tid 521674] [client 216.73.216.128:48435] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:06.469865 2026] [security2:error] [pid 524122:tid 524271] [client 93.123.109.228:43762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/ADMIN/.env"] [unique_id "apPmEn3lhEjKFiK_nBKG_QAAAaE"]
[Sun Aug 30 03:13:06.472273 2026] [security2:error] [pid 524122:tid 524315] [client 93.123.109.228:43682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/API/.env"] [unique_id "apPmEn3lhEjKFiK_nBKG_wAAAc0"]
[Sun Aug 30 03:13:06.473258 2026] [security2:error] [pid 524122:tid 524278] [client 158.23.184.117:36110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/an.php"] [unique_id "apPmEn3lhEjKFiK_nBKHAAAAAag"]
[Sun Aug 30 03:13:06.474994 2026] [authz_core:error] [pid 521505:tid 521665] [client 66.249.66.69:42708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:06.475046 2026] [security2:error] [pid 521505:tid 521623] [remote 97.74.87.194:59932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "holacleaning.com.au"] [uri "/wp-login.php"] [unique_id "apPmEm8byYE0iXl--K6u2wADLXU"], referer: https://holacleaning.com.au/wp-login.php
[Sun Aug 30 03:13:06.475285 2026] [authz_core:error] [pid 521505:tid 521665] [client 66.249.66.69:42708] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:06.479451 2026] [security2:error] [pid 521505:tid 521694] [client 20.151.200.44:63035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/ls.php"] [unique_id "apPmEm8byYE0iXl--K6u3gAAA1k"]
[Sun Aug 30 03:13:06.505944 2026] [authz_core:error] [pid 521505:tid 521698] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory32
[Sun Aug 30 03:13:06.506219 2026] [authz_core:error] [pid 521505:tid 521698] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory32
[Sun Aug 30 03:13:06.520216 2026] [security2:error] [pid 524122:tid 524374] [client 93.123.109.228:43678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/APP/.env"] [unique_id "apPmEn3lhEjKFiK_nBKHAwAAAgg"]
[Sun Aug 30 03:13:06.523041 2026] [security2:error] [pid 524122:tid 524348] [client 93.123.109.228:43818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/Api/.env"] [unique_id "apPmEn3lhEjKFiK_nBKHBAAAAe4"]
[Sun Aug 30 03:13:06.533460 2026] [security2:error] [pid 524122:tid 524370] [client 93.123.109.228:43804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/BACK/.env"] [unique_id "apPmEn3lhEjKFiK_nBKHBgAAAgQ"]
[Sun Aug 30 03:13:06.547285 2026] [security2:error] [pid 521505:tid 521636] [client 20.104.18.15:2025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/c4.php"] [unique_id "apPmEm8byYE0iXl--K6u5AAAAx8"]
[Sun Aug 30 03:13:06.551603 2026] [security2:error] [pid 521505:tid 521726] [client 93.123.109.228:43614] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/BACKEND/.env"] [unique_id "apPmEm8byYE0iXl--K6u5QAAA3k"]
[Sun Aug 30 03:13:06.565420 2026] [security2:error] [pid 524122:tid 524320] [client 68.155.159.216:60314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/wp-content/themes/too.php"] [unique_id "apPmEn3lhEjKFiK_nBKHCAAAAdI"]
[Sun Aug 30 03:13:06.568656 2026] [security2:error] [pid 524122:tid 524292] [client 52.139.37.240:50322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/.well-known/admin.php"] [unique_id "apPmEn3lhEjKFiK_nBKHCQAAAbY"]
[Sun Aug 30 03:13:06.569584 2026] [security2:error] [pid 524122:tid 524341] [client 93.123.109.228:43830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/BE/.env"] [unique_id "apPmEn3lhEjKFiK_nBKHCgAAAec"]
[Sun Aug 30 03:13:06.575423 2026] [security2:error] [pid 521505:tid 521732] [client 20.104.18.15:22494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/ws55.php"] [unique_id "apPmEm8byYE0iXl--K6u5gAAA38"]
[Sun Aug 30 03:13:06.584667 2026] [security2:error] [pid 521505:tid 521679] [client 20.48.250.41:37740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/baixy.php"] [unique_id "apPmEm8byYE0iXl--K6u5wAAA0o"]
[Sun Aug 30 03:13:06.590625 2026] [security2:error] [pid 524122:tid 524378] [client 104.248.114.212:64979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.114.248.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lenoreashwood.com"] [uri "/images/images/images/images/images/cache.php"] [unique_id "apPmEn3lhEjKFiK_nBKHCwAAAgw"], referer: www.google.com
[Sun Aug 30 03:13:06.599783 2026] [authz_core:error] [pid 521505:tid 521724] [client 66.249.66.204:37739] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:06.600042 2026] [authz_core:error] [pid 521505:tid 521724] [client 66.249.66.204:37739] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:06.614537 2026] [security2:error] [pid 524122:tid 524314] [client 158.23.184.117:36150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/buy.php"] [unique_id "apPmEn3lhEjKFiK_nBKHDAAAAcw"]
[Sun Aug 30 03:13:06.619095 2026] [security2:error] [pid 524122:tid 524350] [client 93.123.109.228:43762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/Backend/.env"] [unique_id "apPmEn3lhEjKFiK_nBKHDQAAAfA"]
[Sun Aug 30 03:13:06.629469 2026] [security2:error] [pid 524122:tid 524333] [client 93.123.109.228:43832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/Be/.env"] [unique_id "apPmEn3lhEjKFiK_nBKHDgAAAd8"]
[Sun Aug 30 03:13:06.630339 2026] [authz_core:error] [pid 521505:tid 521709] [client 216.73.216.128:27728] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:06.630604 2026] [authz_core:error] [pid 521505:tid 521709] [client 216.73.216.128:27728] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:06.631002 2026] [security2:error] [pid 524122:tid 524326] [client 20.104.49.130:60959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/albin.php"] [unique_id "apPmEn3lhEjKFiK_nBKHDwAAAdg"]
[Sun Aug 30 03:13:06.665068 2026] [security2:error] [pid 521505:tid 521748] [client 4.205.62.107:15812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/debug.php"] [unique_id "apPmEm8byYE0iXl--K6u8QAAA48"]
[Sun Aug 30 03:13:06.731743 2026] [security2:error] [pid 521505:tid 521647] [client 20.48.250.41:37880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/ava.php"] [unique_id "apPmEm8byYE0iXl--K6u8gAAAyo"]
[Sun Aug 30 03:13:06.744050 2026] [security2:error] [pid 521505:tid 521695] [client 4.205.62.107:16346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/xin1.php"] [unique_id "apPmEm8byYE0iXl--K6u9QAAA1o"]
[Sun Aug 30 03:13:06.744732 2026] [security2:error] [pid 521505:tid 521713] [client 20.104.50.220:63545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/evil.php"] [unique_id "apPmEm8byYE0iXl--K6u9gAAA2w"]
[Sun Aug 30 03:13:06.744896 2026] [security2:error] [pid 521505:tid 521680] [client 104.248.114.212:51141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.114.248.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lenoreashwood.com"] [uri "/images/images/images/images/cache.php"] [unique_id "apPmEm8byYE0iXl--K6u9wAAA0s"], referer: www.google.com
[Sun Aug 30 03:13:06.750686 2026] [authz_core:error] [pid 521505:tid 521701] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:06.751105 2026] [authz_core:error] [pid 521505:tid 521701] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:06.754773 2026] [security2:error] [pid 521505:tid 521683] [client 158.23.184.117:36128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/config.php"] [unique_id "apPmEm8byYE0iXl--K6u-QAAA04"]
[Sun Aug 30 03:13:06.773843 2026] [security2:error] [pid 521505:tid 521731] [client 52.139.37.240:46958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-includes/js/tinymce/plugins/compat3x/css.php"] [unique_id "apPmEm8byYE0iXl--K6u-gAAA34"]
[Sun Aug 30 03:13:06.805072 2026] [security2:error] [pid 521505:tid 521730] [client 20.104.50.220:32841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/foxwso.php"] [unique_id "apPmEm8byYE0iXl--K6u-wAAA30"]
[Sun Aug 30 03:13:06.854378 2026] [security2:error] [pid 524122:tid 524262] [client 20.104.18.15:51168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/wp-aothait.php"] [unique_id "apPmEn3lhEjKFiK_nBKHGAAAAZg"]
[Sun Aug 30 03:13:06.868188 2026] [security2:error] [pid 524122:tid 524324] [client 20.48.250.41:37711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/gdn.php"] [unique_id "apPmEn3lhEjKFiK_nBKHGQAAAdY"]
[Sun Aug 30 03:13:06.896217 2026] [security2:error] [pid 524122:tid 524367] [client 158.23.184.117:36154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/inputs.php"] [unique_id "apPmEn3lhEjKFiK_nBKHGgAAAgE"]
[Sun Aug 30 03:13:06.906955 2026] [security2:error] [pid 521505:tid 521705] [client 104.248.114.212:56637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.114.248.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lenoreashwood.com"] [uri "/images/images/images/cache.php"] [unique_id "apPmEm8byYE0iXl--K6vAAAAA2Q"], referer: www.google.com
[Sun Aug 30 03:13:06.959012 2026] [security2:error] [pid 521505:tid 521733] [client 158.23.147.79:59049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/about/function.php"] [unique_id "apPmEm8byYE0iXl--K6vAgAAA4A"]
[Sun Aug 30 03:13:06.960598 2026] [security2:error] [pid 521505:tid 521720] [client 20.48.251.3:65479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/wp-info.php"] [unique_id "apPmEm8byYE0iXl--K6vBAAAA3M"]
[Sun Aug 30 03:13:07.000738 2026] [security2:error] [pid 521505:tid 521754] [client 52.139.37.240:49716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/v.php"] [unique_id "apPmEm8byYE0iXl--K6vBgAAA5U"]
[Sun Aug 30 03:13:07.005958 2026] [security2:error] [pid 521505:tid 521690] [client 20.104.50.220:25453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/ms-edit.php"] [unique_id "apPmE28byYE0iXl--K6vCAAAA1U"]
[Sun Aug 30 03:13:07.012919 2026] [authz_core:error] [pid 521505:tid 521676] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Ftls%2Fholders%2Fcxgb4
[Sun Aug 30 03:13:07.013180 2026] [authz_core:error] [pid 521505:tid 521676] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fmodule%2Ftls%2Fholders%2Fcxgb4
[Sun Aug 30 03:13:07.031843 2026] [security2:error] [pid 521505:tid 521681] [client 20.48.250.41:37807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/f2.php"] [unique_id "apPmE28byYE0iXl--K6vCwAAA0w"]
[Sun Aug 30 03:13:07.036320 2026] [security2:error] [pid 521505:tid 521639] [client 158.23.184.117:36147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/radio.php"] [unique_id "apPmE28byYE0iXl--K6vDAAAAyI"]
[Sun Aug 30 03:13:07.062819 2026] [security2:error] [pid 524122:tid 524317] [client 20.104.50.220:31222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/item.php"] [unique_id "apPmE33lhEjKFiK_nBKHHQAAAc8"]
[Sun Aug 30 03:13:07.102180 2026] [authz_core:error] [pid 524122:tid 524356] [client 66.249.66.76:51003] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:07.102436 2026] [authz_core:error] [pid 524122:tid 524356] [client 66.249.66.76:51003] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:07.129157 2026] [security2:error] [pid 521505:tid 521704] [client 104.248.114.212:56640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.114.248.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lenoreashwood.com"] [uri "/wp-content/plugins/plugins/cache.php"] [unique_id "apPmE28byYE0iXl--K6vDgAAA2M"], referer: www.google.com
[Sun Aug 30 03:13:07.139339 2026] [security2:error] [pid 521505:tid 521708] [client 20.197.61.180:13513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/mar.php"] [unique_id "apPmE28byYE0iXl--K6vDwAAA2c"]
[Sun Aug 30 03:13:07.153543 2026] [security2:error] [pid 524122:tid 524260] [client 20.104.49.130:57635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alarm-monitoring.net"] [uri "/222.php"] [unique_id "apPmE33lhEjKFiK_nBKHHwAAAZY"]
[Sun Aug 30 03:13:07.177278 2026] [security2:error] [pid 524122:tid 524332] [client 158.23.184.117:36127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/storage/rip.php"] [unique_id "apPmE33lhEjKFiK_nBKHIgAAAd4"]
[Sun Aug 30 03:13:07.187244 2026] [security2:error] [pid 524122:tid 524290] [client 4.205.62.107:28685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/wp-blog.php"] [unique_id "apPmE33lhEjKFiK_nBKHIwAAAbQ"]
[Sun Aug 30 03:13:07.196072 2026] [security2:error] [pid 524122:tid 524349] [client 20.48.160.90:50411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/zi.php"] [unique_id "apPmE33lhEjKFiK_nBKHJAAAAe8"]
[Sun Aug 30 03:13:07.207326 2026] [security2:error] [pid 521505:tid 521736] [client 20.48.250.41:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/grsiuk.php"] [unique_id "apPmE28byYE0iXl--K6vEwAAA4M"]
[Sun Aug 30 03:13:07.212142 2026] [security2:error] [pid 524122:tid 524376] [client 20.48.251.3:37127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/8.php"] [unique_id "apPmE33lhEjKFiK_nBKHJQAAAgo"]
[Sun Aug 30 03:13:07.218496 2026] [security2:error] [pid 521505:tid 521643] [client 52.139.37.240:49685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/main.php"] [unique_id "apPmE28byYE0iXl--K6vFQAAAyY"]
[Sun Aug 30 03:13:07.250252 2026] [authz_core:error] [pid 521505:tid 521742] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:07.250518 2026] [authz_core:error] [pid 521505:tid 521742] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:07.318883 2026] [security2:error] [pid 524122:tid 524369] [client 104.248.114.212:62695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.114.248.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lenoreashwood.com"] [uri "/assets/images/images/cache.php"] [unique_id "apPmE33lhEjKFiK_nBKHJwAAAgM"], referer: www.google.com
[Sun Aug 30 03:13:07.320079 2026] [security2:error] [pid 521505:tid 521650] [client 158.23.184.117:36560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/wp-admin.php"] [unique_id "apPmE28byYE0iXl--K6vGQAAAy0"]
[Sun Aug 30 03:13:07.322689 2026] [security2:error] [pid 521505:tid 521637] [client 20.48.160.90:23774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/gtghklk.php"] [unique_id "apPmE28byYE0iXl--K6vGgAAAyA"]
[Sun Aug 30 03:13:07.332441 2026] [security2:error] [pid 524122:tid 524329] [client 20.48.160.90:50020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/ue.php"] [unique_id "apPmE33lhEjKFiK_nBKHKAAAAds"]
[Sun Aug 30 03:13:07.355436 2026] [security2:error] [pid 521505:tid 521703] [client 158.23.147.79:59031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apPmE28byYE0iXl--K6vHAAAA2I"]
[Sun Aug 30 03:13:07.356391 2026] [security2:error] [pid 521505:tid 521702] [client 4.205.62.107:32450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/fraro.php"] [unique_id "apPmE28byYE0iXl--K6vHgAAA2E"]
[Sun Aug 30 03:13:07.359761 2026] [security2:error] [pid 521505:tid 521644] [client 20.48.250.41:37781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/wp-scr1pts.php"] [unique_id "apPmE28byYE0iXl--K6vHwAAAyc"]
[Sun Aug 30 03:13:07.360540 2026] [security2:error] [pid 521505:tid 521717] [client 20.104.49.130:53519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/sd.php"] [unique_id "apPmE28byYE0iXl--K6vIAAAA3A"]
[Sun Aug 30 03:13:07.389816 2026] [security2:error] [pid 521505:tid 521732] [client 20.104.50.220:17220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/.well-known/65.php"] [unique_id "apPmE28byYE0iXl--K6vIQAAA38"]
[Sun Aug 30 03:13:07.414880 2026] [security2:error] [pid 521505:tid 521654] [client 52.139.37.240:46953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/.well-known/file.php"] [unique_id "apPmE28byYE0iXl--K6vIgAAAzE"]
[Sun Aug 30 03:13:07.416278 2026] [security2:error] [pid 521505:tid 521718] [client 20.104.49.130:34521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alarm-monitoring.net"] [uri "/k.php"] [unique_id "apPmE28byYE0iXl--K6vIwAAA3E"]
[Sun Aug 30 03:13:07.454929 2026] [security2:error] [pid 521505:tid 521653] [client 20.48.160.90:23755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/comand.php"] [unique_id "apPmE28byYE0iXl--K6vJQAAAzA"]
[Sun Aug 30 03:13:07.462819 2026] [security2:error] [pid 524122:tid 524353] [client 20.48.160.90:49984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/nv.php"] [unique_id "apPmE33lhEjKFiK_nBKHKgAAAfM"]
[Sun Aug 30 03:13:07.478183 2026] [authz_core:error] [pid 521505:tid 521748] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory3
[Sun Aug 30 03:13:07.478445 2026] [authz_core:error] [pid 521505:tid 521748] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory3
[Sun Aug 30 03:13:07.479088 2026] [security2:error] [pid 521505:tid 521698] [client 20.48.251.3:52185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/umgebung.php"] [unique_id "apPmE28byYE0iXl--K6vKAAAA10"]
[Sun Aug 30 03:13:07.490341 2026] [security2:error] [pid 521505:tid 521675] [client 20.104.50.220:5594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/4.php"] [unique_id "apPmE28byYE0iXl--K6vKQAAA0Y"]
[Sun Aug 30 03:13:07.507168 2026] [security2:error] [pid 521505:tid 521713] [client 104.248.114.212:55799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.114.248.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lenoreashwood.com"] [uri "/blogs/media/media/cache.php"] [unique_id "apPmE28byYE0iXl--K6vKgAAA2w"], referer: www.google.com
[Sun Aug 30 03:13:07.511680 2026] [security2:error] [pid 521505:tid 521731] [client 4.205.62.107:17296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/old_phpinfo.php"] [unique_id "apPmE28byYE0iXl--K6vLAAAA34"]
[Sun Aug 30 03:13:07.520715 2026] [security2:error] [pid 521505:tid 521709] [client 20.104.50.220:61398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/cabs.php"] [unique_id "apPmE28byYE0iXl--K6vLQAAA2g"]
[Sun Aug 30 03:13:07.531052 2026] [security2:error] [pid 521505:tid 521730] [client 20.104.50.220:52843] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "523"] [id "900207"] [msg "Sys[0-9]+ Mailer"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/sys32.php"] [unique_id "apPmE28byYE0iXl--K6vLgAAA30"]
[Sun Aug 30 03:13:07.548080 2026] [security2:error] [pid 521505:tid 521699] [client 20.48.250.41:37708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/num.php"] [unique_id "apPmE28byYE0iXl--K6vMAAAA14"]
[Sun Aug 30 03:13:07.554897 2026] [authz_core:error] [pid 521505:tid 521762] [client 66.249.66.203:48986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:07.555173 2026] [authz_core:error] [pid 521505:tid 521762] [client 66.249.66.203:48986] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:07.588293 2026] [security2:error] [pid 521505:tid 521659] [client 20.48.160.90:23753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp_motu_myk3v.php"] [unique_id "apPmE28byYE0iXl--K6vNQAAAzY"]
[Sun Aug 30 03:13:07.592771 2026] [security2:error] [pid 524122:tid 524255] [client 20.48.160.90:29128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/jw.php"] [unique_id "apPmE33lhEjKFiK_nBKHLAAAAZE"]
[Sun Aug 30 03:13:07.611848 2026] [security2:error] [pid 524122:tid 524291] [client 20.104.50.220:62794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/chan.php"] [unique_id "apPmE33lhEjKFiK_nBKHLQAAAbU"]
[Sun Aug 30 03:13:07.614474 2026] [security2:error] [pid 521505:tid 521648] [client 158.23.184.117:36156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/wp-content.php"] [unique_id "apPmE28byYE0iXl--K6vNgAAAys"]
[Sun Aug 30 03:13:07.661855 2026] [security2:error] [pid 521505:tid 521757] [client 52.139.37.240:46955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apPmE28byYE0iXl--K6vOQAAA5g"]
[Sun Aug 30 03:13:07.669146 2026] [security2:error] [pid 524122:tid 524335] [client 20.151.200.44:55712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.americanqualityhomeinspections.com"] [uri "/wefile.php"] [unique_id "apPmE33lhEjKFiK_nBKHLgAAAeE"]
[Sun Aug 30 03:13:07.669326 2026] [security2:error] [pid 521505:tid 521744] [client 68.155.159.216:60957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/radio.php"] [unique_id "apPmE28byYE0iXl--K6vOgAAA4s"]
[Sun Aug 30 03:13:07.677925 2026] [security2:error] [pid 524122:tid 524366] [client 104.248.114.212:51175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.114.248.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lenoreashwood.com"] [uri "/cache/cache/cache.php"] [unique_id "apPmE33lhEjKFiK_nBKHLwAAAgA"], referer: www.google.com
[Sun Aug 30 03:13:07.685047 2026] [security2:error] [pid 524122:tid 524269] [client 20.104.18.15:1821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/rxr.php"] [unique_id "apPmE33lhEjKFiK_nBKHMAAAAZ8"]
[Sun Aug 30 03:13:07.685852 2026] [security2:error] [pid 521505:tid 521670] [client 20.48.250.41:37833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/a4.php"] [unique_id "apPmE28byYE0iXl--K6vOwAAA0E"]
[Sun Aug 30 03:13:07.717098 2026] [security2:error] [pid 521505:tid 521682] [client 20.48.160.90:50424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/wp_motu_ypdat.php"] [unique_id "apPmE28byYE0iXl--K6vPQAAA00"]
[Sun Aug 30 03:13:07.727490 2026] [authz_core:error] [pid 524122:tid 524296] [client 216.73.216.128:9566] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:07.727783 2026] [authz_core:error] [pid 524122:tid 524296] [client 216.73.216.128:9566] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:07.743792 2026] [security2:error] [pid 521505:tid 521739] [client 20.104.18.15:22483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/indo.php"] [unique_id "apPmE28byYE0iXl--K6vQQAAA4Y"]
[Sun Aug 30 03:13:07.755294 2026] [security2:error] [pid 524122:tid 524253] [client 158.23.184.117:36544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/wp-content/about.php"] [unique_id "apPmE33lhEjKFiK_nBKHMgAAAY8"]
[Sun Aug 30 03:13:07.762606 2026] [authz_core:error] [pid 521505:tid 521684] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:07.762878 2026] [authz_core:error] [pid 521505:tid 521684] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:07.794595 2026] [security2:error] [pid 521505:tid 521719] [client 158.23.147.79:43879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPmE28byYE0iXl--K6vQwAAA3I"]
[Sun Aug 30 03:13:07.816587 2026] [security2:error] [pid 521505:tid 521745] [client 4.205.62.107:16362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/nzv.php"] [unique_id "apPmE28byYE0iXl--K6vRAAAA4w"]
[Sun Aug 30 03:13:07.818067 2026] [authz_core:error] [pid 524122:tid 524310] [client 216.73.216.128:36316] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:07.818342 2026] [authz_core:error] [pid 524122:tid 524310] [client 216.73.216.128:36316] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:07.832411 2026] [security2:error] [pid 524122:tid 524355] [client 158.23.147.79:52684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-admin/index.php"] [unique_id "apPmE33lhEjKFiK_nBKHNAAAAfU"]
[Sun Aug 30 03:13:07.845422 2026] [security2:error] [pid 521505:tid 521712] [client 20.48.250.41:37801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/tfm.php"] [unique_id "apPmE28byYE0iXl--K6vRQAAA2s"]
[Sun Aug 30 03:13:07.874071 2026] [security2:error] [pid 521505:tid 521733] [client 20.197.61.180:13565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/css.php"] [unique_id "apPmE28byYE0iXl--K6vRgAAA4A"]
[Sun Aug 30 03:13:07.880068 2026] [security2:error] [pid 521505:tid 521708] [client 52.139.37.240:9476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-content/file.php"] [unique_id "apPmE28byYE0iXl--K6vSAAAA2c"]
[Sun Aug 30 03:13:07.897457 2026] [security2:error] [pid 521505:tid 521642] [client 20.104.50.220:42814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/file.php"] [unique_id "apPmE28byYE0iXl--K6vSQAAAyU"]
[Sun Aug 30 03:13:07.915599 2026] [security2:error] [pid 521505:tid 521643] [client 4.205.62.107:15813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/sadd.php"] [unique_id "apPmE28byYE0iXl--K6vSwAAAyY"]
[Sun Aug 30 03:13:07.941808 2026] [security2:error] [pid 524122:tid 524360] [client 20.104.50.220:33164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/gank.php"] [unique_id "apPmE33lhEjKFiK_nBKHNgAAAfo"]
[Sun Aug 30 03:13:07.950417 2026] [security2:error] [pid 521505:tid 521711] [client 34.34.68.90:60070] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "hopperpsychology.com"] [uri "/"] [unique_id "apPmE28byYE0iXl--K6vTwAAA2o"]
[Sun Aug 30 03:13:07.985560 2026] [security2:error] [pid 521505:tid 521688] [client 20.104.18.15:51143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/wp-includes/index.php"] [unique_id "apPmE28byYE0iXl--K6vUAAAA1M"]
[Sun Aug 30 03:13:08.000407 2026] [authz_core:error] [pid 521505:tid 521755] [client 66.249.66.74:46673] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:08.000669 2026] [authz_core:error] [pid 521505:tid 521755] [client 66.249.66.74:46673] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:08.001056 2026] [authz_core:error] [pid 521505:tid 521694] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory9
[Sun Aug 30 03:13:08.001327 2026] [authz_core:error] [pid 521505:tid 521694] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory9
[Sun Aug 30 03:13:08.005107 2026] [security2:error] [pid 524122:tid 524289] [client 20.48.250.41:37785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/Geforce.php"] [unique_id "apPmFH3lhEjKFiK_nBKHOAAAAbM"]
[Sun Aug 30 03:13:08.043107 2026] [security2:error] [pid 521505:tid 521637] [client 158.23.184.117:36567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/x.php"] [unique_id "apPmFG8byYE0iXl--K6vVQAAAyA"]
[Sun Aug 30 03:13:08.074555 2026] [security2:error] [pid 521505:tid 521650] [client 52.139.37.240:49705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-signup.php"] [unique_id "apPmFG8byYE0iXl--K6vWAAAAy0"]
[Sun Aug 30 03:13:08.091249 2026] [security2:error] [pid 521505:tid 521732] [client 20.48.251.3:46163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/fns.php"] [unique_id "apPmFG8byYE0iXl--K6vWwAAA38"]
[Sun Aug 30 03:13:08.151728 2026] [security2:error] [pid 521505:tid 521735] [client 20.104.50.220:24888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/222.php"] [unique_id "apPmFG8byYE0iXl--K6vXAAAA4I"]
[Sun Aug 30 03:13:08.162370 2026] [security2:error] [pid 521505:tid 521686] [client 20.104.49.130:63241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/abc.php"] [unique_id "apPmFG8byYE0iXl--K6vXQAAA1E"]
[Sun Aug 30 03:13:08.172099 2026] [security2:error] [pid 521505:tid 521664] [client 20.48.250.41:37767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/click.php"] [unique_id "apPmFG8byYE0iXl--K6vXwAAAzs"]
[Sun Aug 30 03:13:08.205117 2026] [security2:error] [pid 524122:tid 524287] [client 20.104.50.220:31525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/plugins/Cache/footer.php"] [unique_id "apPmFH3lhEjKFiK_nBKHPAAAAbE"]
[Sun Aug 30 03:13:08.253592 2026] [security2:error] [pid 521505:tid 521698] [client 158.23.147.79:43903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPmFG8byYE0iXl--K6vZAAAA10"]
[Sun Aug 30 03:13:08.257457 2026] [security2:error] [pid 521505:tid 521647] [client 158.23.147.79:59030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPmFG8byYE0iXl--K6vZQAAAyo"]
[Sun Aug 30 03:13:08.281885 2026] [security2:error] [pid 521505:tid 521680] [client 158.23.184.117:36240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/a.php"] [unique_id "apPmFG8byYE0iXl--K6vagAAA0s"]
[Sun Aug 30 03:13:08.286727 2026] [authz_core:error] [pid 521505:tid 521713] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:08.287044 2026] [authz_core:error] [pid 521505:tid 521713] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:08.304734 2026] [security2:error] [pid 521505:tid 521750] [client 20.151.200.44:52062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/od.php"] [unique_id "apPmFG8byYE0iXl--K6vawAAA5E"]
[Sun Aug 30 03:13:08.321391 2026] [security2:error] [pid 521505:tid 521731] [client 20.48.250.41:37779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/ms.php"] [unique_id "apPmFG8byYE0iXl--K6vbAAAA34"]
[Sun Aug 30 03:13:08.325312 2026] [security2:error] [pid 521505:tid 521760] [client 52.139.37.240:49682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/ge.php"] [unique_id "apPmFG8byYE0iXl--K6vbQAAA5s"]
[Sun Aug 30 03:13:08.349312 2026] [security2:error] [pid 521505:tid 521743] [client 20.48.251.3:37151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/thui.php"] [unique_id "apPmFG8byYE0iXl--K6vcAAAA4o"]
[Sun Aug 30 03:13:08.367884 2026] [security2:error] [pid 521505:tid 521705] [client 4.205.62.107:29170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/erty.php"] [unique_id "apPmFG8byYE0iXl--K6vcgAAA2Q"]
[Sun Aug 30 03:13:08.426760 2026] [security2:error] [pid 524122:tid 524278] [client 158.23.184.117:36155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/admin/index.php"] [unique_id "apPmFH3lhEjKFiK_nBKHPwAAAag"]
[Sun Aug 30 03:13:08.444699 2026] [security2:error] [pid 521505:tid 521641] [client 20.104.49.130:57607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alarm-monitoring.net"] [uri "/media.php"] [unique_id "apPmFG8byYE0iXl--K6vdgAAAyQ"]
[Sun Aug 30 03:13:08.453630 2026] [authz_core:error] [pid 524122:tid 524293] [client 66.249.66.198:59607] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:08.454082 2026] [authz_core:error] [pid 524122:tid 524293] [client 66.249.66.198:59607] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:08.460037 2026] [security2:error] [pid 521505:tid 521728] [client 20.48.250.41:37853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/zxekqlxb.php"] [unique_id "apPmFG8byYE0iXl--K6veQAAA3s"]
[Sun Aug 30 03:13:08.485978 2026] [authz_core:error] [pid 521505:tid 521651] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory3
[Sun Aug 30 03:13:08.486343 2026] [authz_core:error] [pid 521505:tid 521651] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory3
[Sun Aug 30 03:13:08.501480 2026] [security2:error] [pid 524122:tid 524320] [client 4.205.62.107:32451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/thui.php"] [unique_id "apPmFH3lhEjKFiK_nBKHRAAAAdI"]
[Sun Aug 30 03:13:08.521659 2026] [security2:error] [pid 521505:tid 521748] [client 52.139.37.240:50321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/goods.php"] [unique_id "apPmFG8byYE0iXl--K6vewAAA48"]
[Sun Aug 30 03:13:08.522116 2026] [security2:error] [pid 521505:tid 521699] [client 34.34.68.90:38048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "hopperpsychology.com"] [uri "/"] [unique_id "apPmFG8byYE0iXl--K6vfQAAA14"]
[Sun Aug 30 03:13:08.522436 2026] [security2:error] [pid 521505:tid 521639] [client 20.104.50.220:16738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/.well-known/64.php"] [unique_id "apPmFG8byYE0iXl--K6vfAAAAyI"]
[Sun Aug 30 03:13:08.562307 2026] [security2:error] [pid 521505:tid 521640] [client 93.123.109.228:43614] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/admin-app/.env"] [unique_id "apPmFG8byYE0iXl--K6vgQAAAyM"]
[Sun Aug 30 03:13:08.570304 2026] [security2:error] [pid 521505:tid 521681] [client 158.23.184.117:36275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/ahax.php"] [unique_id "apPmFG8byYE0iXl--K6vggAAA0w"]
[Sun Aug 30 03:13:08.571194 2026] [core:error] [pid 524122:tid 524378] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:08.571211 2026] [core:error] [pid 524122:tid 524378] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:08.598668 2026] [security2:error] [pid 524122:tid 524314] [client 20.104.49.130:53507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/wp-blog-header.php"] [unique_id "apPmFH3lhEjKFiK_nBKHSQAAAcw"]
[Sun Aug 30 03:13:08.602612 2026] [security2:error] [pid 521505:tid 521693] [client 20.197.61.180:16016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/autoload_classmap.php"] [unique_id "apPmFG8byYE0iXl--K6vhAAAA1g"]
[Sun Aug 30 03:13:08.624641 2026] [security2:error] [pid 521505:tid 521762] [client 20.48.251.3:43093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/old_phpinfo.php"] [unique_id "apPmFG8byYE0iXl--K6vhwAAA50"]
[Sun Aug 30 03:13:08.642700 2026] [security2:error] [pid 524122:tid 524373] [client 20.104.50.220:5503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/3.php"] [unique_id "apPmFH3lhEjKFiK_nBKHTAAAAgc"]
[Sun Aug 30 03:13:08.649464 2026] [security2:error] [pid 521505:tid 521712] [client 4.205.62.107:17468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.mizunewyork.com"] [uri "/wp-act.php"] [unique_id "apPmFG8byYE0iXl--K6viAAAA2s"]
[Sun Aug 30 03:13:08.657323 2026] [security2:error] [pid 521505:tid 521736] [client 20.48.250.41:37747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/init.php"] [unique_id "apPmFG8byYE0iXl--K6viQAAA4M"]
[Sun Aug 30 03:13:08.662851 2026] [security2:error] [pid 521505:tid 521708] [client 20.104.50.220:62244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/filesss.php"] [unique_id "apPmFG8byYE0iXl--K6vigAAA2c"]
[Sun Aug 30 03:13:08.682806 2026] [security2:error] [pid 521505:tid 521676] [client 93.123.109.228:43670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/_profiler/phpinfo.php"] [unique_id "apPmFG8byYE0iXl--K6viwAAA0c"]
[Sun Aug 30 03:13:08.711075 2026] [security2:error] [pid 521505:tid 521714] [client 158.23.184.117:36152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/alfa.php"] [unique_id "apPmFG8byYE0iXl--K6vjQAAA20"]
[Sun Aug 30 03:13:08.728035 2026] [security2:error] [pid 521505:tid 521672] [client 20.48.160.90:50388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/or.php"] [unique_id "apPmFG8byYE0iXl--K6vjgAAA0M"]
[Sun Aug 30 03:13:08.731422 2026] [security2:error] [pid 524122:tid 524306] [client 52.139.37.240:49710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/403.php"] [unique_id "apPmFH3lhEjKFiK_nBKHUwAAAcQ"]
[Sun Aug 30 03:13:08.735032 2026] [authz_core:error] [pid 524122:tid 524294] [client 216.73.216.128:9566] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:08.735328 2026] [authz_core:error] [pid 524122:tid 524294] [client 216.73.216.128:9566] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:08.753499 2026] [authz_core:error] [pid 521505:tid 521688] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:08.753784 2026] [authz_core:error] [pid 521505:tid 521688] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:08.780030 2026] [security2:error] [pid 521505:tid 521706] [client 68.155.159.216:60949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPmFG8byYE0iXl--K6vkAAAA2U"]
[Sun Aug 30 03:13:08.798090 2026] [security2:error] [pid 521505:tid 521702] [client 20.104.50.220:28693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/losX.php"] [unique_id "apPmFG8byYE0iXl--K6vkQAAA2E"]
[Sun Aug 30 03:13:08.814478 2026] [security2:error] [pid 521505:tid 521756] [client 20.48.250.41:37790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/term.php"] [unique_id "apPmFG8byYE0iXl--K6vkgAAA5c"]
[Sun Aug 30 03:13:08.823492 2026] [authz_core:error] [pid 521505:tid 521677] [client 216.73.216.128:27728] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:08.823834 2026] [authz_core:error] [pid 521505:tid 521677] [client 216.73.216.128:27728] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:08.827046 2026] [security2:error] [pid 521505:tid 521636] [client 20.151.200.44:63562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/css/000.php"] [unique_id "apPmFG8byYE0iXl--K6vlQAAAx8"]
[Sun Aug 30 03:13:08.843916 2026] [security2:error] [pid 521505:tid 521742] [client 20.104.18.15:1966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homevalues.socalhomessouthbay.com"] [uri "/reviall.php"] [unique_id "apPmFG8byYE0iXl--K6vlwAAA4k"]
[Sun Aug 30 03:13:08.861414 2026] [security2:error] [pid 524122:tid 524304] [client 20.48.160.90:50034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/ile56.php"] [unique_id "apPmFH3lhEjKFiK_nBKHVAAAAcI"]
[Sun Aug 30 03:13:08.882400 2026] [security2:error] [pid 521505:tid 521734] [client 20.48.160.90:29134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/edit.php"] [unique_id "apPmFG8byYE0iXl--K6vmwAAA4E"]
[Sun Aug 30 03:13:08.897665 2026] [security2:error] [pid 524122:tid 524346] [client 20.104.18.15:22348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/wnnjpsby.php"] [unique_id "apPmFH3lhEjKFiK_nBKHVwAAAew"]
[Sun Aug 30 03:13:08.899735 2026] [security2:error] [pid 521505:tid 521758] [client 20.104.50.220:29587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/simple_cmd.php"] [unique_id "apPmFG8byYE0iXl--K6vnQAAA5k"]
[Sun Aug 30 03:13:08.902229 2026] [security2:error] [pid 521505:tid 521727] [client 158.23.184.117:36588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/chosen.php"] [unique_id "apPmFG8byYE0iXl--K6vngAAA3o"]
[Sun Aug 30 03:13:08.915015 2026] [security2:error] [pid 521505:tid 521658] [client 158.23.147.79:52694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/about.php"] [unique_id "apPmFG8byYE0iXl--K6voAAAAzU"]
[Sun Aug 30 03:13:08.949478 2026] [core:error] [pid 521505:tid 521657] [client 34.106.227.237:59118] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:08.949503 2026] [core:error] [pid 521505:tid 521657] [client 34.106.227.237:59118] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:08.970990 2026] [security2:error] [pid 521505:tid 521760] [client 4.205.62.107:15820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/66.php"] [unique_id "apPmFG8byYE0iXl--K6vowAAA5s"]
[Sun Aug 30 03:13:08.978792 2026] [security2:error] [pid 521505:tid 521730] [client 20.48.250.41:37858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/aaa.php"] [unique_id "apPmFG8byYE0iXl--K6vpQAAA30"]
[Sun Aug 30 03:13:08.979194 2026] [security2:error] [pid 524122:tid 524297] [client 52.139.37.240:50326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/public/makeasmtp.php"] [unique_id "apPmFH3lhEjKFiK_nBKHXQAAAbs"]
[Sun Aug 30 03:13:08.984923 2026] [authz_core:error] [pid 521505:tid 521709] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory9
[Sun Aug 30 03:13:08.985190 2026] [authz_core:error] [pid 521505:tid 521709] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory9
[Sun Aug 30 03:13:09.000773 2026] [security2:error] [pid 521505:tid 521671] [client 34.34.68.90:38058] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "hopperpsychology.com"] [uri "/"] [unique_id "apPmFW8byYE0iXl--K6vqAAAA0I"]
[Sun Aug 30 03:13:09.004883 2026] [security2:error] [pid 521505:tid 521705] [client 20.48.160.90:50427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/emmh.php"] [unique_id "apPmFW8byYE0iXl--K6vqQAAA2Q"]
[Sun Aug 30 03:13:09.034187 2026] [security2:error] [pid 524122:tid 524380] [client 20.48.160.90:23789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/tqkdqbbv.php"] [unique_id "apPmFX3lhEjKFiK_nBKHYAAAAg4"]
[Sun Aug 30 03:13:09.035402 2026] [security2:error] [pid 521505:tid 521741] [client 20.104.50.220:41990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/FoxWSO-full.php"] [unique_id "apPmFW8byYE0iXl--K6vqgAAA4g"]
[Sun Aug 30 03:13:09.036497 2026] [security2:error] [pid 521505:tid 521661] [client 93.123.109.228:43644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/admin/phpinfo.php"] [unique_id "apPmFW8byYE0iXl--K6vqwAAAzg"]
[Sun Aug 30 03:13:09.043235 2026] [security2:error] [pid 521505:tid 521743] [client 158.23.184.117:36098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/hplfuns.php"] [unique_id "apPmFW8byYE0iXl--K6vrAAAA4o"]
[Sun Aug 30 03:13:09.051110 2026] [security2:error] [pid 521505:tid 521728] [client 4.205.62.107:15814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/application.config.php"] [unique_id "apPmFW8byYE0iXl--K6vrQAAA3s"]
[Sun Aug 30 03:13:09.068348 2026] [security2:error] [pid 524122:tid 524371] [client 158.23.147.79:61958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apPmFX3lhEjKFiK_nBKHYwAAAgU"]
[Sun Aug 30 03:13:09.086031 2026] [authz_core:error] [pid 521505:tid 521659] [client 66.249.66.192:42507] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:09.086301 2026] [authz_core:error] [pid 521505:tid 521659] [client 66.249.66.192:42507] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:09.110427 2026] [security2:error] [pid 521505:tid 521692] [client 20.48.250.41:37814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/xsox.php"] [unique_id "apPmFW8byYE0iXl--K6vsQAAA1c"]
[Sun Aug 30 03:13:09.115837 2026] [security2:error] [pid 524122:tid 524266] [client 93.123.109.228:43804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/administrator/.env"] [unique_id "apPmFX3lhEjKFiK_nBKHZAAAAZw"]
[Sun Aug 30 03:13:09.119192 2026] [security2:error] [pid 521505:tid 521639] [client 20.104.18.15:51015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/file31.php"] [unique_id "apPmFW8byYE0iXl--K6vsgAAAyI"]
[Sun Aug 30 03:13:09.146873 2026] [security2:error] [pid 521505:tid 521729] [client 20.48.160.90:50019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/em.php"] [unique_id "apPmFW8byYE0iXl--K6vtAAAA3w"]
[Sun Aug 30 03:13:09.170866 2026] [security2:error] [pid 521505:tid 521640] [client 20.48.160.90:50405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/kjyehoxl.php"] [unique_id "apPmFW8byYE0iXl--K6vtQAAAyM"]
[Sun Aug 30 03:13:09.185897 2026] [authz_core:error] [pid 524122:tid 524349] [client 66.249.66.64:54978] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:09.186220 2026] [authz_core:error] [pid 524122:tid 524349] [client 66.249.66.64:54978] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:09.190623 2026] [security2:error] [pid 521505:tid 521699] [client 52.139.37.240:9515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-includes/customize/index.php"] [unique_id "apPmFW8byYE0iXl--K6vtgAAA14"]
[Sun Aug 30 03:13:09.202800 2026] [security2:error] [pid 524122:tid 524376] [client 93.123.109.228:43692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/admin_phpinfo.php"] [unique_id "apPmFX3lhEjKFiK_nBKHaQAAAgo"]
[Sun Aug 30 03:13:09.233620 2026] [security2:error] [pid 524122:tid 524267] [client 158.23.184.117:36556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/lite.php"] [unique_id "apPmFX3lhEjKFiK_nBKHawAAAZ0"]
[Sun Aug 30 03:13:09.238666 2026] [security2:error] [pid 521505:tid 521682] [client 93.123.109.228:43614] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/api-backend/.env"] [unique_id "apPmFW8byYE0iXl--K6vtwAAA00"]
[Sun Aug 30 03:13:09.241006 2026] [security2:error] [pid 521505:tid 521759] [client 20.48.251.3:54812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/params.php"] [unique_id "apPmFW8byYE0iXl--K6vuAAAA5o"]
[Sun Aug 30 03:13:09.276026 2026] [security2:error] [pid 521505:tid 521747] [client 20.48.250.41:37699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/lkui.php"] [unique_id "apPmFW8byYE0iXl--K6vuQAAA44"]
[Sun Aug 30 03:13:09.277934 2026] [security2:error] [pid 521505:tid 521638] [client 20.48.160.90:23772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/dvve.php"] [unique_id "apPmFW8byYE0iXl--K6vuwAAAyE"]
[Sun Aug 30 03:13:09.282709 2026] [authz_core:error] [pid 521505:tid 521712] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:09.282934 2026] [authz_core:error] [pid 524122:tid 524342] [client 216.73.216.128:9566] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:09.283018 2026] [authz_core:error] [pid 521505:tid 521712] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:09.283218 2026] [authz_core:error] [pid 524122:tid 524342] [client 216.73.216.128:9566] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:09.289764 2026] [security2:error] [pid 524122:tid 524302] [client 20.104.50.220:25444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/cgi-bin/index.php"] [unique_id "apPmFX3lhEjKFiK_nBKHbQAAAcA"]
[Sun Aug 30 03:13:09.317549 2026] [security2:error] [pid 524122:tid 524313] [client 20.48.160.90:50355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/llyuxaqd.php"] [unique_id "apPmFX3lhEjKFiK_nBKHbgAAAcs"]
[Sun Aug 30 03:13:09.322778 2026] [security2:error] [pid 521505:tid 521669] [client 20.197.61.180:15384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/info.php"] [unique_id "apPmFW8byYE0iXl--K6vvgAAA0A"]
[Sun Aug 30 03:13:09.326604 2026] [security2:error] [pid 524122:tid 524268] [client 93.123.109.228:43682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/api/.env"] [unique_id "apPmFX3lhEjKFiK_nBKHbwAAAZ4"]
[Sun Aug 30 03:13:09.329899 2026] [security2:error] [pid 524122:tid 524331] [client 20.151.200.44:46053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/qi.php"] [unique_id "apPmFX3lhEjKFiK_nBKHcAAAAd0"]
[Sun Aug 30 03:13:09.343336 2026] [security2:error] [pid 521505:tid 521736] [client 20.104.50.220:31183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/404.php"] [unique_id "apPmFW8byYE0iXl--K6vvwAAA4M"]
[Sun Aug 30 03:13:09.372077 2026] [security2:error] [pid 524122:tid 524298] [client 158.23.184.117:36130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/r.php"] [unique_id "apPmFX3lhEjKFiK_nBKHcwAAAbw"]
[Sun Aug 30 03:13:09.373192 2026] [security2:error] [pid 521505:tid 521746] [client 158.23.147.79:61762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apPmFW8byYE0iXl--K6vxQAAA40"]
[Sun Aug 30 03:13:09.407719 2026] [security2:error] [pid 524122:tid 524285] [client 20.48.160.90:23737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/doo.php"] [unique_id "apPmFX3lhEjKFiK_nBKHdAAAAa8"]
[Sun Aug 30 03:13:09.410149 2026] [security2:error] [pid 521505:tid 521660] [client 20.48.250.41:37707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "apPmFW8byYE0iXl--K6vxwAAAzc"]
[Sun Aug 30 03:13:09.426158 2026] [security2:error] [pid 524122:tid 524305] [client 93.123.109.228:43746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/api-node/.env"] [unique_id "apPmFX3lhEjKFiK_nBKHdgAAAcM"]
[Sun Aug 30 03:13:09.432155 2026] [core:error] [pid 521505:tid 521745] [client 34.106.227.237:59122] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:09.432172 2026] [core:error] [pid 521505:tid 521745] [client 34.106.227.237:59122] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:09.436039 2026] [security2:error] [pid 524122:tid 524281] [client 20.104.49.130:52436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/ohct.php"] [unique_id "apPmFX3lhEjKFiK_nBKHdwAAAas"]
[Sun Aug 30 03:13:09.436874 2026] [security2:error] [pid 521505:tid 521711] [client 20.104.50.220:33176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/gank.php.PhP"] [unique_id "apPmFW8byYE0iXl--K6vygAAA2o"]
[Sun Aug 30 03:13:09.451474 2026] [security2:error] [pid 521505:tid 521662] [client 52.139.37.240:46969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/mar.php"] [unique_id "apPmFW8byYE0iXl--K6vywAAAzk"]
[Sun Aug 30 03:13:09.466010 2026] [security2:error] [pid 521505:tid 521754] [client 20.48.160.90:28780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/nbwxolou.php"] [unique_id "apPmFW8byYE0iXl--K6vzAAAA5U"]
[Sun Aug 30 03:13:09.489482 2026] [security2:error] [pid 524122:tid 524301] [client 20.48.251.3:36815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/file21.php"] [unique_id "apPmFX3lhEjKFiK_nBKHeQAAAb8"]
[Sun Aug 30 03:13:09.529345 2026] [authz_core:error] [pid 521505:tid 521650] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory6
[Sun Aug 30 03:13:09.529611 2026] [authz_core:error] [pid 521505:tid 521650] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory6
[Sun Aug 30 03:13:09.531469 2026] [security2:error] [pid 524122:tid 524334] [client 158.23.184.117:36590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/shell.php"] [unique_id "apPmFX3lhEjKFiK_nBKHewAAAeA"]
[Sun Aug 30 03:13:09.536585 2026] [security2:error] [pid 521505:tid 521717] [client 20.48.160.90:29169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/adminer-4.6.6.php"] [unique_id "apPmFW8byYE0iXl--K6v0AAAA3A"]
[Sun Aug 30 03:13:09.555749 2026] [security2:error] [pid 524122:tid 524321] [client 20.48.250.41:37875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/motu.php"] [unique_id "apPmFX3lhEjKFiK_nBKHfAAAAdM"]
[Sun Aug 30 03:13:09.596956 2026] [security2:error] [pid 521505:tid 521694] [client 20.48.160.90:23806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/nsxeubyv.php"] [unique_id "apPmFW8byYE0iXl--K6v0wAAA1k"]
[Sun Aug 30 03:13:09.604748 2026] [security2:error] [pid 521505:tid 521726] [client 4.205.62.107:29179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/wp-config.backup.php"] [unique_id "apPmFW8byYE0iXl--K6v1AAAA3k"]
[Sun Aug 30 03:13:09.616562 2026] [security2:error] [pid 521505:tid 521727] [client 93.123.109.228:43732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/api/info.php"] [unique_id "apPmFW8byYE0iXl--K6v1gAAA3o"]
[Sun Aug 30 03:13:09.635451 2026] [security2:error] [pid 524122:tid 524364] [client 4.205.62.107:32448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/lala.php"] [unique_id "apPmFX3lhEjKFiK_nBKHhQAAAf4"]
[Sun Aug 30 03:13:09.654384 2026] [authz_core:error] [pid 521505:tid 521718] [client 66.249.66.206:40723] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:09.654634 2026] [authz_core:error] [pid 521505:tid 521718] [client 66.249.66.206:40723] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:09.663401 2026] [security2:error] [pid 521505:tid 521725] [client 20.104.50.220:17255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/.well-known/63.php"] [unique_id "apPmFW8byYE0iXl--K6v2QAAA3g"]
[Sun Aug 30 03:13:09.671971 2026] [security2:error] [pid 521505:tid 521657] [client 20.48.160.90:23685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/gelap1.php"] [unique_id "apPmFW8byYE0iXl--K6v2gAAAzQ"]
[Sun Aug 30 03:13:09.672396 2026] [security2:error] [pid 524122:tid 524355] [client 158.23.184.117:36245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.dannis.ca"] [uri "/themes.php"] [unique_id "apPmFX3lhEjKFiK_nBKHhwAAAfU"]
[Sun Aug 30 03:13:09.687384 2026] [security2:error] [pid 521505:tid 521689] [client 52.139.37.240:46920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/system.php"] [unique_id "apPmFW8byYE0iXl--K6v2wAAA1Q"]
[Sun Aug 30 03:13:09.710581 2026] [security2:error] [pid 524122:tid 524328] [client 158.23.147.79:52705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "apPmFX3lhEjKFiK_nBKHiAAAAdo"]
[Sun Aug 30 03:13:09.729218 2026] [security2:error] [pid 521505:tid 521680] [client 20.48.160.90:49934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/zfqipfss.php"] [unique_id "apPmFW8byYE0iXl--K6v3AAAA0s"]
[Sun Aug 30 03:13:09.729265 2026] [security2:error] [pid 521505:tid 521750] [client 20.48.250.41:37852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/Ov-Simple1.php"] [unique_id "apPmFW8byYE0iXl--K6v3QAAA5E"]
[Sun Aug 30 03:13:09.758277 2026] [security2:error] [pid 524122:tid 524338] [client 20.48.251.3:43067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.digihelpconsulting.com"] [uri "/wp-act.php"] [unique_id "apPmFX3lhEjKFiK_nBKHiwAAAeQ"]
[Sun Aug 30 03:13:09.763159 2026] [authz_core:error] [pid 521505:tid 521652] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:09.763419 2026] [authz_core:error] [pid 521505:tid 521652] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:09.799071 2026] [security2:error] [pid 521505:tid 521661] [client 20.48.160.90:23703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/rsjlrria.php"] [unique_id "apPmFW8byYE0iXl--K6v4gAAAzg"]
[Sun Aug 30 03:13:09.806468 2026] [security2:error] [pid 521505:tid 521635] [client 20.104.50.220:5217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/2.php"] [unique_id "apPmFW8byYE0iXl--K6v4wAAAx4"]
[Sun Aug 30 03:13:09.809473 2026] [core:error] [pid 521505:tid 521701] [client 34.106.227.237:59136] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:09.809491 2026] [core:error] [pid 521505:tid 521701] [client 34.106.227.237:59136] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:09.815232 2026] [security2:error] [pid 521505:tid 521675] [client 20.104.50.220:61977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/wp-aaa.php"] [unique_id "apPmFW8byYE0iXl--K6v5wAAA0Y"]
[Sun Aug 30 03:13:09.823568 2026] [security2:error] [pid 521505:tid 521569] [remote 162.240.171.12:54864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.171.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "new.greenvillebiblechurch.com"] [uri "/wp-login.php"] [unique_id "apPmFW8byYE0iXl--K6v6AADMT8"]
[Sun Aug 30 03:13:09.854122 2026] [security2:error] [pid 524122:tid 524370] [client 158.23.147.79:61989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/simple.php"] [unique_id "apPmFX3lhEjKFiK_nBKHkwAAAgQ"]
[Sun Aug 30 03:13:09.876857 2026] [security2:error] [pid 521505:tid 521639] [client 20.48.160.90:23715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.relationalsacredhealing.com"] [uri "/zrjuyoos.php"] [unique_id "apPmFW8byYE0iXl--K6v7QAAAyI"]
[Sun Aug 30 03:13:09.883809 2026] [rewrite:warn] [pid 521505:tid 521547] AH00665: RewriteCond: NoCase option for non-regex pattern '-d' is not supported and will be ignored. (/home3/keilan/public_html/.htaccess:12)
[Sun Aug 30 03:13:09.883825 2026] [rewrite:warn] [pid 521505:tid 521547] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home3/keilan/public_html/.htaccess:13)
[Sun Aug 30 03:13:09.885887 2026] [security2:error] [pid 524122:tid 524320] [client 20.48.250.41:37744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/wp-blogs.php"] [unique_id "apPmFX3lhEjKFiK_nBKHlAAAAdI"]
[Sun Aug 30 03:13:09.902195 2026] [security2:error] [pid 524122:tid 524378] [client 20.104.49.130:60627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/ioxi-o.php"] [unique_id "apPmFX3lhEjKFiK_nBKHlQAAAgw"]
[Sun Aug 30 03:13:09.917381 2026] [security2:error] [pid 521505:tid 521640] [client 68.155.159.216:60978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/makeasmtp.php"] [unique_id "apPmFW8byYE0iXl--K6v8AAAAyM"]
[Sun Aug 30 03:13:09.941595 2026] [authz_core:error] [pid 524122:tid 524309] [client 66.249.66.71:63266] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:09.941879 2026] [authz_core:error] [pid 524122:tid 524309] [client 66.249.66.71:63266] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:09.949288 2026] [security2:error] [pid 521505:tid 521739] [client 20.104.50.220:62839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/mom.php"] [unique_id "apPmFW8byYE0iXl--K6v8QAAA4Y"]
[Sun Aug 30 03:13:09.950850 2026] [authz_core:error] [pid 524122:tid 524379] [client 66.249.66.77:39803] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:09.951145 2026] [authz_core:error] [pid 524122:tid 524379] [client 66.249.66.77:39803] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:09.955444 2026] [security2:error] [pid 521505:tid 521665] [client 52.139.37.240:9793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "apPmFW8byYE0iXl--K6v8gAAAzw"]
[Sun Aug 30 03:13:09.976759 2026] [security2:error] [pid 524122:tid 524333] [client 93.123.109.228:43746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/api/phpinfo.php"] [unique_id "apPmFX3lhEjKFiK_nBKHmQAAAd8"]
[Sun Aug 30 03:13:09.982675 2026] [security2:error] [pid 524122:tid 524312] [client 93.123.109.228:43804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/apis/.env"] [unique_id "apPmFX3lhEjKFiK_nBKHmgAAAco"]
[Sun Aug 30 03:13:09.989584 2026] [authz_core:error] [pid 521505:tid 521737] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory7
[Sun Aug 30 03:13:09.989850 2026] [authz_core:error] [pid 521505:tid 521737] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory7
[Sun Aug 30 03:13:09.998364 2026] [security2:error] [pid 521505:tid 521747] [client 20.48.160.90:50320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/AxAo.php"] [unique_id "apPmFW8byYE0iXl--K6v-AAAA44"]
[Sun Aug 30 03:13:10.038456 2026] [security2:error] [pid 524122:tid 524283] [client 20.104.18.15:22423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/info.php/new.php"] [unique_id "apPmFn3lhEjKFiK_nBKHnwAAAa0"]
[Sun Aug 30 03:13:10.057530 2026] [security2:error] [pid 524122:tid 524358] [client 20.197.61.180:13511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/b.php"] [unique_id "apPmFn3lhEjKFiK_nBKHogAAAfg"]
[Sun Aug 30 03:13:10.072390 2026] [security2:error] [pid 521505:tid 521643] [client 20.48.250.41:37735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/mini.php"] [unique_id "apPmFm8byYE0iXl--K6v_wAAAyY"]
[Sun Aug 30 03:13:10.078692 2026] [security2:error] [pid 521505:tid 521532] [remote 162.240.171.12:54864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.171.240.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "new.greenvillebiblechurch.com"] [uri "/wp-login.php"] [unique_id "apPmFm8byYE0iXl--K6wAAADNho"], referer: https://new.greenvillebiblechurch.com/wp-login.php
[Sun Aug 30 03:13:10.088421 2026] [security2:error] [pid 524122:tid 524336] [client 93.123.109.228:43830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/app/.env"] [unique_id "apPmFn3lhEjKFiK_nBKHpAAAAeI"]
[Sun Aug 30 03:13:10.088822 2026] [core:error] [pid 521505:tid 521746] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:10.088841 2026] [core:error] [pid 521505:tid 521746] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:10.114408 2026] [security2:error] [pid 524122:tid 524325] [client 4.205.62.107:15986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/admin.php"] [unique_id "apPmFn3lhEjKFiK_nBKHpgAAAdc"]
[Sun Aug 30 03:13:10.144356 2026] [security2:error] [pid 521505:tid 521711] [client 20.48.160.90:49220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/class17.php"] [unique_id "apPmFm8byYE0iXl--K6wBAAAA2o"]
[Sun Aug 30 03:13:10.159726 2026] [security2:error] [pid 524122:tid 524293] [client 52.139.37.240:9370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/mah.php"] [unique_id "apPmFn3lhEjKFiK_nBKHqAAAAbc"]
[Sun Aug 30 03:13:10.160037 2026] [security2:error] [pid 524122:tid 524274] [client 20.104.50.220:29149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/alpa.php"] [unique_id "apPmFn3lhEjKFiK_nBKHqQAAAaQ"]
[Sun Aug 30 03:13:10.178111 2026] [security2:error] [pid 524122:tid 524256] [client 158.23.147.79:62010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-admin/about.php"] [unique_id "apPmFn3lhEjKFiK_nBKHqwAAAZI"]
[Sun Aug 30 03:13:10.187669 2026] [security2:error] [pid 524122:tid 524357] [client 4.205.62.107:15989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/xp.php"] [unique_id "apPmFn3lhEjKFiK_nBKHrAAAAfc"]
[Sun Aug 30 03:13:10.191522 2026] [security2:error] [pid 521505:tid 521655] [client 20.104.50.220:42476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/FoxWSO.php"] [unique_id "apPmFm8byYE0iXl--K6wCAAAAzI"]
[Sun Aug 30 03:13:10.205613 2026] [security2:error] [pid 521505:tid 521714] [client 20.48.250.41:37800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/amp.php"] [unique_id "apPmFm8byYE0iXl--K6wCQAAA20"]
[Sun Aug 30 03:13:10.226630 2026] [security2:error] [pid 524122:tid 524324] [client 34.34.68.90:38074] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "hopperpsychology.com"] [uri "/"] [unique_id "apPmFn3lhEjKFiK_nBKHrwAAAdY"]
[Sun Aug 30 03:13:10.247977 2026] [authz_core:error] [pid 521505:tid 521702] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:10.248239 2026] [authz_core:error] [pid 521505:tid 521702] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:10.263601 2026] [security2:error] [pid 524122:tid 524323] [client 20.104.18.15:51159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/dk.php"] [unique_id "apPmFn3lhEjKFiK_nBKHsQAAAdU"]
[Sun Aug 30 03:13:10.288028 2026] [security2:error] [pid 521505:tid 521696] [client 20.48.160.90:23719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/okxoby.php"] [unique_id "apPmFm8byYE0iXl--K6wEAAAA1s"]
[Sun Aug 30 03:13:10.311012 2026] [authz_core:error] [pid 524122:tid 524317] [client 216.73.216.128:9566] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:10.311282 2026] [authz_core:error] [pid 524122:tid 524317] [client 216.73.216.128:9566] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:10.313934 2026] [security2:error] [pid 524122:tid 524347] [client 20.104.49.130:48358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/az.php"] [unique_id "apPmFn3lhEjKFiK_nBKHtAAAAe0"]
[Sun Aug 30 03:13:10.330896 2026] [security2:error] [pid 524122:tid 524376] [client 93.123.109.228:43818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/apps/.env"] [unique_id "apPmFn3lhEjKFiK_nBKHtwAAAgo"]
[Sun Aug 30 03:13:10.337837 2026] [security2:error] [pid 524122:tid 524261] [client 20.48.250.41:37879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/cc13.php"] [unique_id "apPmFn3lhEjKFiK_nBKHuAAAAZc"]
[Sun Aug 30 03:13:10.340212 2026] [security2:error] [pid 524122:tid 524307] [client 93.123.109.228:43804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/application/.env"] [unique_id "apPmFn3lhEjKFiK_nBKHuQAAAcU"]
[Sun Aug 30 03:13:10.375688 2026] [security2:error] [pid 524122:tid 524267] [client 20.151.200.44:52121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/wp-the.php"] [unique_id "apPmFn3lhEjKFiK_nBKHuwAAAZ0"]
[Sun Aug 30 03:13:10.382773 2026] [security2:error] [pid 524122:tid 524359] [client 20.48.251.3:46218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/gjm.php"] [unique_id "apPmFn3lhEjKFiK_nBKHvAAAAfk"]
[Sun Aug 30 03:13:10.405829 2026] [security2:error] [pid 521505:tid 521734] [client 52.139.37.240:9491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "apPmFm8byYE0iXl--K6wGQAAA4E"]
[Sun Aug 30 03:13:10.411279 2026] [authz_core:error] [pid 524122:tid 524369] [client 66.249.66.44:44207] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:10.411526 2026] [authz_core:error] [pid 524122:tid 524369] [client 66.249.66.44:44207] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:10.413742 2026] [security2:error] [pid 524122:tid 524282] [client 20.151.200.44:63008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/cy.php"] [unique_id "apPmFn3lhEjKFiK_nBKHwQAAAaw"]
[Sun Aug 30 03:13:10.429098 2026] [security2:error] [pid 524122:tid 524298] [client 20.48.160.90:50429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/esuutzzx.php"] [unique_id "apPmFn3lhEjKFiK_nBKHxAAAAbw"]
[Sun Aug 30 03:13:10.482925 2026] [security2:error] [pid 524122:tid 524365] [client 20.48.250.41:37802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/aa.php"] [unique_id "apPmFn3lhEjKFiK_nBKHzAAAAf8"]
[Sun Aug 30 03:13:10.496052 2026] [security2:error] [pid 521505:tid 521680] [client 20.104.50.220:31200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/mail.php"] [unique_id "apPmFm8byYE0iXl--K6wIgAAA0s"]
[Sun Aug 30 03:13:10.502712 2026] [authz_core:error] [pid 521505:tid 521697] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory7
[Sun Aug 30 03:13:10.502976 2026] [authz_core:error] [pid 521505:tid 521697] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory7
[Sun Aug 30 03:13:10.542401 2026] [security2:error] [pid 521505:tid 521685] [client 20.104.50.220:24958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/BDKR28WP.php"] [unique_id "apPmFm8byYE0iXl--K6wKAAAA1A"]
[Sun Aug 30 03:13:10.542755 2026] [security2:error] [pid 521505:tid 521705] [client 158.23.147.79:52693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/themes.php"] [unique_id "apPmFm8byYE0iXl--K6wKQAAA2Q"]
[Sun Aug 30 03:13:10.546296 2026] [security2:error] [pid 521505:tid 521648] [client 158.23.147.79:61727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apPmFm8byYE0iXl--K6wKgAAAys"]
[Sun Aug 30 03:13:10.557432 2026] [security2:error] [pid 524122:tid 524286] [client 20.48.160.90:23802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/replace.php"] [unique_id "apPmFn3lhEjKFiK_nBKH0QAAAbA"]
[Sun Aug 30 03:13:10.614485 2026] [core:error] [pid 524122:tid 524356] [client 34.106.227.237:59140] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:10.614504 2026] [core:error] [pid 524122:tid 524356] [client 34.106.227.237:59140] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:10.614952 2026] [security2:error] [pid 524122:tid 524327] [client 52.139.37.240:9487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/backup.php"] [unique_id "apPmFn3lhEjKFiK_nBKH1QAAAdk"]
[Sun Aug 30 03:13:10.631951 2026] [security2:error] [pid 524122:tid 524360] [client 20.48.250.41:37862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/s1.php"] [unique_id "apPmFn3lhEjKFiK_nBKH1gAAAfo"]
[Sun Aug 30 03:13:10.645550 2026] [security2:error] [pid 524122:tid 524280] [client 20.48.251.3:36853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/mcebraed.php"] [unique_id "apPmFn3lhEjKFiK_nBKH1wAAAao"]
[Sun Aug 30 03:13:10.654296 2026] [security2:error] [pid 524122:tid 524289] [client 93.123.109.228:43804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/back-end/.env"] [unique_id "apPmFn3lhEjKFiK_nBKH2AAAAbM"]
[Sun Aug 30 03:13:10.655653 2026] [security2:error] [pid 521505:tid 521641] [client 93.123.109.228:43614] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/backend-api/.env"] [unique_id "apPmFm8byYE0iXl--K6wLwAAAyQ"]
[Sun Aug 30 03:13:10.655654 2026] [security2:error] [pid 524122:tid 524328] [client 93.123.109.228:43832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/backend/.env"] [unique_id "apPmFn3lhEjKFiK_nBKH2QAAAdo"]
[Sun Aug 30 03:13:10.657979 2026] [security2:error] [pid 524122:tid 524295] [client 93.123.109.228:43682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/back/.env"] [unique_id "apPmFn3lhEjKFiK_nBKH2gAAAbk"]
[Sun Aug 30 03:13:10.658491 2026] [security2:error] [pid 521505:tid 521738] [client 93.123.109.228:43718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/back-api/.env"] [unique_id "apPmFm8byYE0iXl--K6wMAAAA4U"]
[Sun Aug 30 03:13:10.689395 2026] [security2:error] [pid 521505:tid 521757] [client 20.48.160.90:50360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/gulu.php"] [unique_id "apPmFm8byYE0iXl--K6wNQAAA5g"]
[Sun Aug 30 03:13:10.691917 2026] [authz_core:error] [pid 521505:tid 521654] [client 66.249.66.71:43529] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:10.692177 2026] [authz_core:error] [pid 521505:tid 521654] [client 66.249.66.71:43529] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:10.717792 2026] [security2:error] [pid 521505:tid 521639] [client 158.23.147.79:61769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apPmFm8byYE0iXl--K6wOQAAAyI"]
[Sun Aug 30 03:13:10.744594 2026] [security2:error] [pid 524122:tid 524332] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/.env"] [unique_id "apPmFn3lhEjKFiK_nBKH3gAAAd4"]
[Sun Aug 30 03:13:10.760159 2026] [authz_core:error] [pid 521505:tid 521681] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:10.760408 2026] [authz_core:error] [pid 521505:tid 521681] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:10.780770 2026] [authz_core:error] [pid 521505:tid 521699] [client 66.249.66.66:55582] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:10.781208 2026] [authz_core:error] [pid 521505:tid 521699] [client 66.249.66.66:55582] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:10.788475 2026] [security2:error] [pid 521505:tid 521739] [client 20.104.50.220:33211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/gh.php"] [unique_id "apPmFm8byYE0iXl--K6wQwAAA4Y"]
[Sun Aug 30 03:13:10.798140 2026] [security2:error] [pid 524122:tid 524320] [client 20.104.50.220:16583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/.well-known/62.php"] [unique_id "apPmFn3lhEjKFiK_nBKH4QAAAdI"]
[Sun Aug 30 03:13:10.798842 2026] [security2:error] [pid 521505:tid 521722] [client 93.123.109.228:43788] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/backup/.env"] [unique_id "apPmFm8byYE0iXl--K6wRAAAA3U"]
[Sun Aug 30 03:13:10.799035 2026] [security2:error] [pid 521505:tid 521724] [client 93.123.109.228:43614] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/be/.env"] [unique_id "apPmFm8byYE0iXl--K6wRQAAA3c"]
[Sun Aug 30 03:13:10.801836 2026] [security2:error] [pid 524122:tid 524314] [client 93.123.109.228:43832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/beta/.env"] [unique_id "apPmFn3lhEjKFiK_nBKH4wAAAcw"]
[Sun Aug 30 03:13:10.803396 2026] [security2:error] [pid 521505:tid 521715] [client 20.197.61.180:16036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/wp-login.php"] [unique_id "apPmFm8byYE0iXl--K6wPwAAA24"]
[Sun Aug 30 03:13:10.810230 2026] [security2:error] [pid 521505:tid 521647] [client 52.139.37.240:9486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-admin/maint/about.php"] [unique_id "apPmFm8byYE0iXl--K6wSQAAAyo"]
[Sun Aug 30 03:13:10.818088 2026] [security2:error] [pid 521505:tid 521719] [client 20.48.250.41:37634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/0byte.php"] [unique_id "apPmFm8byYE0iXl--K6wTAAAA3I"]
[Sun Aug 30 03:13:10.830224 2026] [security2:error] [pid 521505:tid 521666] [client 20.48.160.90:49925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/gtghklk.php"] [unique_id "apPmFm8byYE0iXl--K6wTQAAAz0"]
[Sun Aug 30 03:13:10.846858 2026] [security2:error] [pid 524122:tid 524270] [client 4.205.62.107:29181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/edit.php"] [unique_id "apPmFn3lhEjKFiK_nBKH5gAAAaA"]
[Sun Aug 30 03:13:10.849261 2026] [security2:error] [pid 521505:tid 521700] [client 4.205.62.107:32011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/public/bnn_.php.php"] [unique_id "apPmFm8byYE0iXl--K6wTwAAA18"]
[Sun Aug 30 03:13:10.881554 2026] [security2:error] [pid 524122:tid 524283] [client 93.123.109.228:43762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/client/.env"] [unique_id "apPmFn3lhEjKFiK_nBKH6AAAAa0"]
[Sun Aug 30 03:13:10.923400 2026] [security2:error] [pid 521505:tid 521733] [client 93.123.109.228:43602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/cms/.env"] [unique_id "apPmFm8byYE0iXl--K6wVQAAA4A"]
[Sun Aug 30 03:13:10.951414 2026] [security2:error] [pid 521505:tid 521745] [client 20.104.50.220:6118] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.camboconsulting.cover789.com"] [uri "/1.php"] [unique_id "apPmFm8byYE0iXl--K6wWAAAA4w"]
[Sun Aug 30 03:13:10.951529 2026] [security2:error] [pid 521505:tid 521745] [client 20.104.50.220:6118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/1.php"] [unique_id "apPmFm8byYE0iXl--K6wWAAAA4w"]
[Sun Aug 30 03:13:10.967083 2026] [security2:error] [pid 521505:tid 521711] [client 20.48.160.90:49210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/comand.php"] [unique_id "apPmFm8byYE0iXl--K6wWQAAA2o"]
[Sun Aug 30 03:13:10.968975 2026] [security2:error] [pid 521505:tid 521671] [client 158.23.147.79:52246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/chosen.php"] [unique_id "apPmFm8byYE0iXl--K6wWgAAA0I"]
[Sun Aug 30 03:13:10.985175 2026] [security2:error] [pid 524122:tid 524325] [client 20.48.250.41:37745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/xr.php"] [unique_id "apPmFn3lhEjKFiK_nBKH7gAAAdc"]
[Sun Aug 30 03:13:10.994780 2026] [security2:error] [pid 521505:tid 521667] [client 158.23.147.79:52702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-mail.php"] [unique_id "apPmFm8byYE0iXl--K6wXQAAAz4"]
[Sun Aug 30 03:13:10.995445 2026] [authz_core:error] [pid 521505:tid 521662] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory7
[Sun Aug 30 03:13:10.995721 2026] [authz_core:error] [pid 521505:tid 521662] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory7
[Sun Aug 30 03:13:11.001650 2026] [security2:error] [pid 521505:tid 521637] [client 20.104.50.220:61640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/css.php"] [unique_id "apPmF28byYE0iXl--K6wYAAAAyA"]
[Sun Aug 30 03:13:11.023405 2026] [security2:error] [pid 524122:tid 524326] [client 93.123.109.228:43682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/config/.env"] [unique_id "apPmF33lhEjKFiK_nBKH8gAAAdg"]
[Sun Aug 30 03:13:11.023437 2026] [security2:error] [pid 521505:tid 521723] [client 68.155.159.216:60291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apPmF28byYE0iXl--K6wZQAAA3Y"]
[Sun Aug 30 03:13:11.028530 2026] [security2:error] [pid 521505:tid 521742] [client 93.123.109.228:43630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/config.php"] [unique_id "apPmF28byYE0iXl--K6wZwAAA4k"]
[Sun Aug 30 03:13:11.037689 2026] [security2:error] [pid 524122:tid 524374] [client 52.139.37.240:46963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/readme.php"] [unique_id "apPmF33lhEjKFiK_nBKH9QAAAgg"]
[Sun Aug 30 03:13:11.096430 2026] [security2:error] [pid 521505:tid 521694] [client 93.123.109.228:43614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/config/aws.php"] [unique_id "apPmF28byYE0iXl--K6wagAAA1k"]
[Sun Aug 30 03:13:11.109291 2026] [security2:error] [pid 524122:tid 524311] [client 20.48.160.90:50325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp_motu_myk3v.php"] [unique_id "apPmF33lhEjKFiK_nBKH-AAAAck"]
[Sun Aug 30 03:13:11.113578 2026] [security2:error] [pid 521505:tid 521758] [client 158.23.147.79:52262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/goods.php"] [unique_id "apPmF28byYE0iXl--K6wbAAAA5k"]
[Sun Aug 30 03:13:11.119266 2026] [security2:error] [pid 524122:tid 524277] [client 20.48.250.41:37671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/h02ugyh.php"] [unique_id "apPmF33lhEjKFiK_nBKH-QAAAac"]
[Sun Aug 30 03:13:11.129381 2026] [security2:error] [pid 524122:tid 524292] [client 20.104.49.130:53820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/berlin.php"] [unique_id "apPmF33lhEjKFiK_nBKH-gAAAbY"]
[Sun Aug 30 03:13:11.147202 2026] [authz_core:error] [pid 524122:tid 524367] [client 66.249.66.41:53674] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:11.147581 2026] [authz_core:error] [pid 524122:tid 524367] [client 66.249.66.41:53674] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:11.152820 2026] [security2:error] [pid 521505:tid 521727] [client 20.104.50.220:62803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/killer.php"] [unique_id "apPmF28byYE0iXl--K6wbgAAA3o"]
[Sun Aug 30 03:13:11.170981 2026] [security2:error] [pid 524122:tid 524319] [client 93.123.109.228:43832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/config/config.inc.php"] [unique_id "apPmF33lhEjKFiK_nBKH_QAAAdE"]
[Sun Aug 30 03:13:11.190123 2026] [security2:error] [pid 524122:tid 524272] [client 93.123.109.228:43818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/config/config.php"] [unique_id "apPmF33lhEjKFiK_nBKIAAAAAaI"]
[Sun Aug 30 03:13:11.232744 2026] [security2:error] [pid 521505:tid 521731] [client 93.123.109.228:43602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/config/env.php"] [unique_id "apPmF28byYE0iXl--K6wdgAAA34"]
[Sun Aug 30 03:13:11.243038 2026] [security2:error] [pid 521505:tid 521734] [client 52.139.37.240:49727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-admin/options.php"] [unique_id "apPmF28byYE0iXl--K6wdwAAA4E"]
[Sun Aug 30 03:13:11.243799 2026] [security2:error] [pid 521505:tid 521680] [client 93.123.109.228:43788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/config/module.config.php"] [unique_id "apPmF28byYE0iXl--K6weAAAA0s"]
[Sun Aug 30 03:13:11.247999 2026] [security2:error] [pid 521505:tid 521664] [client 4.205.62.107:15839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/png.php"] [unique_id "apPmF28byYE0iXl--K6weQAAAzs"]
[Sun Aug 30 03:13:11.248984 2026] [security2:error] [pid 524122:tid 524266] [client 93.123.109.228:43886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/config/nexmo.php"] [unique_id "apPmF33lhEjKFiK_nBKIAwAAAZw"]
[Sun Aug 30 03:13:11.249714 2026] [security2:error] [pid 524122:tid 524345] [client 20.48.160.90:28784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/wp_motu_ypdat.php"] [unique_id "apPmF33lhEjKFiK_nBKIBAAAAes"]
[Sun Aug 30 03:13:11.273856 2026] [security2:error] [pid 524122:tid 524261] [client 20.48.250.41:37745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/xxw.php"] [unique_id "apPmF33lhEjKFiK_nBKIBwAAAZc"]
[Sun Aug 30 03:13:11.274790 2026] [authz_core:error] [pid 524122:tid 524337] [client 66.249.66.73:58635] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:11.275155 2026] [authz_core:error] [pid 524122:tid 524337] [client 66.249.66.73:58635] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:11.284873 2026] [authz_core:error] [pid 521505:tid 521760] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:11.285183 2026] [authz_core:error] [pid 521505:tid 521760] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:11.315824 2026] [security2:error] [pid 521505:tid 521661] [client 20.104.18.15:22400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/w.php"] [unique_id "apPmF28byYE0iXl--K6wfAAAAzg"]
[Sun Aug 30 03:13:11.326203 2026] [security2:error] [pid 521505:tid 521728] [client 93.123.109.228:43656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/config/stripe.php"] [unique_id "apPmF28byYE0iXl--K6wgAAAA3s"]
[Sun Aug 30 03:13:11.326350 2026] [security2:error] [pid 521505:tid 521710] [client 4.205.62.107:16352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/g3.php"] [unique_id "apPmF28byYE0iXl--K6wgQAAA2k"]
[Sun Aug 30 03:13:11.326864 2026] [security2:error] [pid 524122:tid 524302] [client 158.23.147.79:55389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/cgi-bin/index.php"] [unique_id "apPmF33lhEjKFiK_nBKICwAAAcA"]
[Sun Aug 30 03:13:11.327252 2026] [security2:error] [pid 521505:tid 521641] [client 20.104.50.220:42775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/foxwso.php"] [unique_id "apPmF28byYE0iXl--K6wggAAAyQ"]
[Sun Aug 30 03:13:11.328845 2026] [security2:error] [pid 524122:tid 524290] [client 34.106.227.237:59144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "apPmF33lhEjKFiK_nBKIDAAAAbQ"]
[Sun Aug 30 03:13:11.375978 2026] [security2:error] [pid 524122:tid 524255] [client 20.104.49.130:48360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/v2.php"] [unique_id "apPmF33lhEjKFiK_nBKIEQAAAZE"]
[Sun Aug 30 03:13:11.381259 2026] [security2:error] [pid 521505:tid 521713] [client 20.48.160.90:49936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/edit.php"] [unique_id "apPmF28byYE0iXl--K6wiQAAA2w"]
[Sun Aug 30 03:13:11.399076 2026] [security2:error] [pid 521505:tid 521647] [client 20.104.49.130:57631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alarm-monitoring.net"] [uri "/zoo2.php"] [unique_id "apPmF28byYE0iXl--K6wjQAAAyo"]
[Sun Aug 30 03:13:11.400888 2026] [security2:error] [pid 521505:tid 521747] [client 20.104.18.15:51034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/ta.php"] [unique_id "apPmF28byYE0iXl--K6wjwAAA44"]
[Sun Aug 30 03:13:11.424073 2026] [security2:error] [pid 524122:tid 524276] [client 20.104.50.220:62802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/themes/antioch/acces.php"] [unique_id "apPmF33lhEjKFiK_nBKIGgAAAaY"]
[Sun Aug 30 03:13:11.440908 2026] [security2:error] [pid 524122:tid 524296] [client 20.48.250.41:37726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/bolt.php"] [unique_id "apPmF33lhEjKFiK_nBKIHwAAAbo"]
[Sun Aug 30 03:13:11.458163 2026] [core:error] [pid 521505:tid 521668] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:11.458180 2026] [core:error] [pid 521505:tid 521668] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:11.479054 2026] [security2:error] [pid 524122:tid 524365] [client 52.139.37.240:53253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-content/x/index.php"] [unique_id "apPmF33lhEjKFiK_nBKIJAAAAf8"]
[Sun Aug 30 03:13:11.502841 2026] [authz_core:error] [pid 521505:tid 521669] [client 66.249.66.67:35328] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:11.503318 2026] [authz_core:error] [pid 521505:tid 521669] [client 66.249.66.67:35328] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:11.514739 2026] [security2:error] [pid 524122:tid 524335] [client 93.123.109.228:43830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/crm/.env"] [unique_id "apPmF33lhEjKFiK_nBKIKAAAAeE"]
[Sun Aug 30 03:13:11.516365 2026] [security2:error] [pid 524122:tid 524338] [client 20.48.160.90:50006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/tqkdqbbv.php"] [unique_id "apPmF33lhEjKFiK_nBKIKQAAAeQ"]
[Sun Aug 30 03:13:11.520839 2026] [authz_core:error] [pid 521505:tid 521745] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory2
[Sun Aug 30 03:13:11.521307 2026] [authz_core:error] [pid 521505:tid 521745] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory2
[Sun Aug 30 03:13:11.527384 2026] [security2:error] [pid 524122:tid 524366] [client 93.123.109.228:43868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/cron/.env"] [unique_id "apPmF33lhEjKFiK_nBKIKgAAAgA"]
[Sun Aug 30 03:13:11.529441 2026] [security2:error] [pid 521505:tid 521761] [client 20.48.251.3:46157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/configuration.php"] [unique_id "apPmF28byYE0iXl--K6wmwAAA5w"]
[Sun Aug 30 03:13:11.531621 2026] [security2:error] [pid 521505:tid 521711] [client 20.104.49.130:60651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/bthil.php"] [unique_id "apPmF28byYE0iXl--K6wnAAAA2o"]
[Sun Aug 30 03:13:11.541591 2026] [security2:error] [pid 521505:tid 521671] [client 93.123.109.228:43910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/current/.env"] [unique_id "apPmF28byYE0iXl--K6wnQAAA0I"]
[Sun Aug 30 03:13:11.554447 2026] [security2:error] [pid 521505:tid 521730] [client 20.197.61.180:1561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/aa.php"] [unique_id "apPmF28byYE0iXl--K6wnwAAA30"]
[Sun Aug 30 03:13:11.557315 2026] [security2:error] [pid 521505:tid 521637] [client 93.123.109.228:43872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/demo/.env"] [unique_id "apPmF28byYE0iXl--K6woAAAAyA"]
[Sun Aug 30 03:13:11.568944 2026] [security2:error] [pid 524122:tid 524315] [client 93.123.109.228:43804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/dev/.env"] [unique_id "apPmF33lhEjKFiK_nBKILgAAAc0"]
[Sun Aug 30 03:13:11.590718 2026] [security2:error] [pid 524122:tid 524271] [client 20.48.250.41:37783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/rtx.php"] [unique_id "apPmF33lhEjKFiK_nBKILwAAAaE"]
[Sun Aug 30 03:13:11.602360 2026] [security2:error] [pid 521505:tid 521638] [client 20.151.200.44:63603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/admin.php/pindex.php"] [unique_id "apPmF28byYE0iXl--K6wpAAAAyE"]
[Sun Aug 30 03:13:11.642202 2026] [security2:error] [pid 521505:tid 521696] [client 158.23.147.79:61955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apPmF28byYE0iXl--K6wpQAAA1s"]
[Sun Aug 30 03:13:11.642697 2026] [security2:error] [pid 521505:tid 521660] [client 20.104.50.220:30912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apPmF28byYE0iXl--K6wpgAAAzc"]
[Sun Aug 30 03:13:11.647227 2026] [security2:error] [pid 521505:tid 521740] [client 93.123.109.228:43784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/develop/.env"] [unique_id "apPmF28byYE0iXl--K6wpwAAA4c"]
[Sun Aug 30 03:13:11.648612 2026] [security2:error] [pid 521505:tid 521684] [client 93.123.109.228:43838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/development/.env"] [unique_id "apPmF28byYE0iXl--K6wqAAAA08"]
[Sun Aug 30 03:13:11.649240 2026] [security2:error] [pid 521505:tid 521759] [client 20.48.160.90:50007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/kjyehoxl.php"] [unique_id "apPmF28byYE0iXl--K6wqQAAA5o"]
[Sun Aug 30 03:13:11.652085 2026] [security2:error] [pid 524122:tid 524372] [client 93.123.109.228:43682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/developer/.env"] [unique_id "apPmF33lhEjKFiK_nBKIMQAAAgY"]
[Sun Aug 30 03:13:11.670653 2026] [security2:error] [pid 524122:tid 524332] [client 158.23.147.79:59040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPmF33lhEjKFiK_nBKIMgAAAd4"]
[Sun Aug 30 03:13:11.683956 2026] [security2:error] [pid 521505:tid 521682] [client 52.139.37.240:9496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/admin.php7"] [unique_id "apPmF28byYE0iXl--K6wqgAAA00"]
[Sun Aug 30 03:13:11.684479 2026] [security2:error] [pid 524122:tid 524377] [client 103.131.71.229:41931] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "luxtiny.com"] [uri "/index.php"] [unique_id "apPmF33lhEjKFiK_nBKICgAAAgs"]
[Sun Aug 30 03:13:11.691047 2026] [cgid:error] [pid 524122:tid 524316] [client 93.123.109.228:43868] AH01264: stderr from /home3/jvallesteros/jeanbooknerdstorytellersbox.com/dnscfg.cgi: script not found or unable to stat
[Sun Aug 30 03:13:11.712550 2026] [security2:error] [pid 521505:tid 521727] [client 20.151.200.44:52147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/wt.php"] [unique_id "apPmF28byYE0iXl--K6wrwAAA3o"]
[Sun Aug 30 03:13:11.731763 2026] [authz_core:error] [pid 524122:tid 524378] [client 66.249.66.197:64446] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:11.732042 2026] [authz_core:error] [pid 524122:tid 524378] [client 66.249.66.197:64446] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:11.745854 2026] [security2:error] [pid 521505:tid 521762] [client 20.48.250.41:37850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/ckk.php"] [unique_id "apPmF28byYE0iXl--K6wswAAA50"]
[Sun Aug 30 03:13:11.779652 2026] [security2:error] [pid 521505:tid 521707] [client 20.48.251.3:36899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/server-info.php"] [unique_id "apPmF28byYE0iXl--K6wtAAAA2Y"]
[Sun Aug 30 03:13:11.788004 2026] [authz_core:error] [pid 521505:tid 521725] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:11.788299 2026] [authz_core:error] [pid 521505:tid 521725] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:11.792071 2026] [security2:error] [pid 524122:tid 524351] [client 20.48.160.90:50348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/llyuxaqd.php"] [unique_id "apPmF33lhEjKFiK_nBKIPgAAAfE"]
[Sun Aug 30 03:13:11.847960 2026] [security2:error] [pid 524122:tid 524318] [client 93.123.109.228:43830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/erp/.env"] [unique_id "apPmF33lhEjKFiK_nBKIQQAAAdA"]
[Sun Aug 30 03:13:11.850953 2026] [security2:error] [pid 524122:tid 524293] [client 93.123.109.228:43868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/etc/apache2/apache2.conf"] [unique_id "apPmF33lhEjKFiK_nBKIQgAAAbc"]
[Sun Aug 30 03:13:11.852218 2026] [security2:error] [pid 521505:tid 521734] [client 93.123.109.228:43910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/etc/boto.cfg"] [unique_id "apPmF28byYE0iXl--K6wvgAAA4E"]
[Sun Aug 30 03:13:11.852329 2026] [security2:error] [pid 521505:tid 521750] [client 93.123.109.228:43916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/fe/.env"] [unique_id "apPmF28byYE0iXl--K6wvQAAA5E"]
[Sun Aug 30 03:13:11.868197 2026] [authz_core:error] [pid 524122:tid 524330] [client 66.249.66.72:50659] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:11.868447 2026] [authz_core:error] [pid 524122:tid 524330] [client 66.249.66.72:50659] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:11.922354 2026] [security2:error] [pid 521505:tid 521701] [client 20.48.250.41:37836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.250.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.nerdmoto.com"] [uri "/R57.php"] [unique_id "apPmF28byYE0iXl--K6wwwAAA2A"]
[Sun Aug 30 03:13:11.928680 2026] [security2:error] [pid 521505:tid 521743] [client 20.104.50.220:24912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/wp.php"] [unique_id "apPmF28byYE0iXl--K6wxAAAA4o"]
[Sun Aug 30 03:13:11.933834 2026] [security2:error] [pid 521505:tid 521728] [client 20.48.160.90:49998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/nbwxolou.php"] [unique_id "apPmF28byYE0iXl--K6wxQAAA3s"]
[Sun Aug 30 03:13:11.933868 2026] [security2:error] [pid 521505:tid 521710] [client 20.104.50.220:16742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/.well-known/61.php"] [unique_id "apPmF28byYE0iXl--K6wxwAAA2k"]
[Sun Aug 30 03:13:11.941049 2026] [security2:error] [pid 521505:tid 521641] [client 93.123.109.228:43838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/front/.env"] [unique_id "apPmF28byYE0iXl--K6wyAAAAyQ"]
[Sun Aug 30 03:13:11.941512 2026] [security2:error] [pid 524122:tid 524294] [client 52.139.37.240:49707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/.well-known/wp-login.php"] [unique_id "apPmF33lhEjKFiK_nBKISAAAAbg"]
[Sun Aug 30 03:13:11.944947 2026] [security2:error] [pid 524122:tid 524319] [client 93.123.109.228:43804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/frontend/.env"] [unique_id "apPmF33lhEjKFiK_nBKISQAAAdE"]
[Sun Aug 30 03:13:11.964920 2026] [authz_core:error] [pid 521505:tid 521675] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory0
[Sun Aug 30 03:13:11.965362 2026] [authz_core:error] [pid 521505:tid 521675] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory0
[Sun Aug 30 03:13:11.978716 2026] [core:error] [pid 524122:tid 524324] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:11.978734 2026] [core:error] [pid 524122:tid 524324] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:12.016007 2026] [security2:error] [pid 524122:tid 524376] [client 4.205.62.107:32509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/wsws.php"] [unique_id "apPmGH3lhEjKFiK_nBKIUgAAAgo"]
[Sun Aug 30 03:13:12.021450 2026] [security2:error] [pid 524122:tid 524261] [client 20.104.50.220:33073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/id.php"] [unique_id "apPmGH3lhEjKFiK_nBKIUwAAAZc"]
[Sun Aug 30 03:13:12.031815 2026] [security2:error] [pid 521505:tid 521713] [client 93.123.109.228:43916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/info.php"] [unique_id "apPmGG8byYE0iXl--K6w0AAAA2w"]
[Sun Aug 30 03:13:12.033091 2026] [security2:error] [pid 521505:tid 521640] [client 93.123.109.228:43706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/infophp.php"] [unique_id "apPmGG8byYE0iXl--K6w0QAAAyM"]
[Sun Aug 30 03:13:12.034312 2026] [security2:error] [pid 524122:tid 524363] [client 158.23.147.79:59059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-includes/content.php"] [unique_id "apPmGH3lhEjKFiK_nBKIVwAAAf0"]
[Sun Aug 30 03:13:12.036997 2026] [security2:error] [pid 524122:tid 524359] [client 93.123.109.228:43762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/infos.php"] [unique_id "apPmGH3lhEjKFiK_nBKIWAAAAfk"]
[Sun Aug 30 03:13:12.037025 2026] [authz_core:error] [pid 524122:tid 524267] [client 66.249.66.70:48743] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:12.037291 2026] [authz_core:error] [pid 524122:tid 524267] [client 66.249.66.70:48743] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:12.072018 2026] [core:alert] [pid 521505:tid 521747] [client 175.0.53.208:0] /home3/fremant1/thedevonshireteaguide.com.au/.htaccess: without matching section
[Sun Aug 30 03:13:12.080769 2026] [security2:error] [pid 521505:tid 521744] [client 20.48.160.90:23713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/nsxeubyv.php"] [unique_id "apPmGG8byYE0iXl--K6w1wAAA4s"]
[Sun Aug 30 03:13:12.085683 2026] [security2:error] [pid 524122:tid 524357] [client 4.205.62.107:52913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/8.php"] [unique_id "apPmGH3lhEjKFiK_nBKIWgAAAfc"]
[Sun Aug 30 03:13:12.085991 2026] [security2:error] [pid 521505:tid 521760] [client 93.123.109.228:43838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/laravel/.env"] [unique_id "apPmGG8byYE0iXl--K6w2AAAA5s"]
[Sun Aug 30 03:13:12.091076 2026] [security2:error] [pid 524122:tid 524354] [client 93.123.109.228:43804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/lms/.env"] [unique_id "apPmGH3lhEjKFiK_nBKIWwAAAfQ"]
[Sun Aug 30 03:13:12.097650 2026] [security2:error] [pid 521505:tid 521668] [client 93.123.109.228:43718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/local/.env"] [unique_id "apPmGG8byYE0iXl--K6w2QAAAz8"]
[Sun Aug 30 03:13:12.098799 2026] [security2:error] [pid 524122:tid 524353] [client 20.104.50.220:5583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/0.php"] [unique_id "apPmGH3lhEjKFiK_nBKIXgAAAfM"]
[Sun Aug 30 03:13:12.118396 2026] [security2:error] [pid 524122:tid 524321] [client 93.123.109.228:43682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/market/.env"] [unique_id "apPmGH3lhEjKFiK_nBKIYAAAAdM"]
[Sun Aug 30 03:13:12.126862 2026] [security2:error] [pid 521505:tid 521736] [client 4.205.62.107:17114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fcconveyancing.com.au"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPmGG8byYE0iXl--K6w2wAAA4M"]
[Sun Aug 30 03:13:12.131268 2026] [security2:error] [pid 521505:tid 521643] [client 68.155.159.216:60967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apPmGG8byYE0iXl--K6w3AAAAyY"]
[Sun Aug 30 03:13:12.149022 2026] [security2:error] [pid 524122:tid 524317] [client 52.139.37.240:49689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "apPmGH3lhEjKFiK_nBKIYQAAAc8"]
[Sun Aug 30 03:13:12.160333 2026] [security2:error] [pid 524122:tid 524269] [client 216.73.216.128:9566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPmGH3lhEjKFiK_nBKIYgAAAZ8"]
[Sun Aug 30 03:13:12.166940 2026] [security2:error] [pid 524122:tid 524279] [client 93.123.109.228:43868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/marketing/.env"] [unique_id "apPmGH3lhEjKFiK_nBKIYwAAAak"]
[Sun Aug 30 03:13:12.169232 2026] [authz_core:error] [pid 521505:tid 521681] [client 66.249.66.65:61588] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:12.169492 2026] [authz_core:error] [pid 521505:tid 521681] [client 66.249.66.65:61588] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:12.176497 2026] [security2:error] [pid 521505:tid 521737] [client 20.104.50.220:61674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/ioxi-o.php"] [unique_id "apPmGG8byYE0iXl--K6w3wAAA4Q"]
[Sun Aug 30 03:13:12.206973 2026] [security2:error] [pid 524122:tid 524296] [client 93.123.109.228:43678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/new/.env"] [unique_id "apPmGH3lhEjKFiK_nBKIZQAAAbo"]
[Sun Aug 30 03:13:12.207811 2026] [security2:error] [pid 524122:tid 524327] [client 93.123.109.228:43846] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/media/.env"] [unique_id "apPmGH3lhEjKFiK_nBKIZgAAAdk"]
[Sun Aug 30 03:13:12.210810 2026] [security2:error] [pid 521505:tid 521709] [client 93.123.109.228:43912] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/node-api/.env"] [unique_id "apPmGG8byYE0iXl--K6w4gAAA2g"]
[Sun Aug 30 03:13:12.211098 2026] [security2:error] [pid 521505:tid 521714] [client 20.48.160.90:29132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/zfqipfss.php"] [unique_id "apPmGG8byYE0iXl--K6w4wAAA20"]
[Sun Aug 30 03:13:12.229338 2026] [security2:error] [pid 521505:tid 521703] [client 93.123.109.228:43838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/node/.env"] [unique_id "apPmGG8byYE0iXl--K6w5AAAA2I"]
[Sun Aug 30 03:13:12.238345 2026] [security2:error] [pid 521505:tid 521723] [client 20.151.200.44:45977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/px.php"] [unique_id "apPmGG8byYE0iXl--K6w5gAAA3Y"]
[Sun Aug 30 03:13:12.238437 2026] [security2:error] [pid 524122:tid 524335] [client 93.123.109.228:43804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/node/api/.env"] [unique_id "apPmGH3lhEjKFiK_nBKIaQAAAeE"]
[Sun Aug 30 03:13:12.243639 2026] [security2:error] [pid 521505:tid 521638] [client 93.123.109.228:43718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/node/backend/.env"] [unique_id "apPmGG8byYE0iXl--K6w6QAAAyE"]
[Sun Aug 30 03:13:12.243824 2026] [security2:error] [pid 524122:tid 524338] [client 93.123.109.228:43928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/nodeweb/.env"] [unique_id "apPmGH3lhEjKFiK_nBKIagAAAeQ"]
[Sun Aug 30 03:13:12.246568 2026] [security2:error] [pid 524122:tid 524287] [client 20.104.49.130:53610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/xwx1.php"] [unique_id "apPmGH3lhEjKFiK_nBKIbQAAAbE"]
[Sun Aug 30 03:13:12.246884 2026] [security2:error] [pid 524122:tid 524362] [client 93.123.109.228:43896] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/nodeapi/.env"] [unique_id "apPmGH3lhEjKFiK_nBKIbAAAAfw"]
[Sun Aug 30 03:13:12.246959 2026] [authz_core:error] [pid 521505:tid 521719] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:12.247301 2026] [authz_core:error] [pid 521505:tid 521719] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:12.260989 2026] [security2:error] [pid 521505:tid 521748] [client 20.197.61.180:19207] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "petworthcs.com"] [uri "/c99.php"] [unique_id "apPmGG8byYE0iXl--K6w7QAAA48"]
[Sun Aug 30 03:13:12.265432 2026] [security2:error] [pid 524122:tid 524322] [client 158.23.147.79:52674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-admin/css/index.php"] [unique_id "apPmGH3lhEjKFiK_nBKIbgAAAdQ"]
[Sun Aug 30 03:13:12.287074 2026] [core:alert] [pid 524122:tid 524340] [client 111.243.223.116:0] /home3/fremant1/thedevonshireteaguide.com.au/.htaccess: without matching section
[Sun Aug 30 03:13:12.317367 2026] [security2:error] [pid 524122:tid 524337] [client 93.123.109.228:43868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/old/.env"] [unique_id "apPmGH3lhEjKFiK_nBKIdQAAAeM"]
[Sun Aug 30 03:13:12.327516 2026] [security2:error] [pid 521505:tid 521686] [client 20.151.200.44:55616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.americanqualityhomeinspections.com"] [uri "/Contrller.php"] [unique_id "apPmGG8byYE0iXl--K6w8wAAA1E"]
[Sun Aug 30 03:13:12.337121 2026] [core:error] [pid 524122:tid 524278] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:12.337159 2026] [core:error] [pid 524122:tid 524278] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:12.341781 2026] [security2:error] [pid 524122:tid 524291] [client 20.48.160.90:50357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.160.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.icobold.com"] [uri "/zrjuyoos.php"] [unique_id "apPmGH3lhEjKFiK_nBKIeAAAAbU"]
[Sun Aug 30 03:13:12.344169 2026] [security2:error] [pid 521505:tid 521727] [client 20.104.50.220:62799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/Sh3ll.php"] [unique_id "apPmGG8byYE0iXl--K6w9QAAA3o"]
[Sun Aug 30 03:13:12.356167 2026] [security2:error] [pid 521505:tid 521762] [client 93.123.109.228:43872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/opt/.env"] [unique_id "apPmGG8byYE0iXl--K6w-AAAA50"]
[Sun Aug 30 03:13:12.401025 2026] [security2:error] [pid 524122:tid 524356] [client 4.205.62.107:15984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/chosen.php"] [unique_id "apPmGH3lhEjKFiK_nBKIggAAAfY"]
[Sun Aug 30 03:13:12.424542 2026] [security2:error] [pid 521505:tid 521745] [client 52.139.37.240:50334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-content/cache/index.php"] [unique_id "apPmGG8byYE0iXl--K6w_gAAA4w"]
[Sun Aug 30 03:13:12.444311 2026] [authz_core:error] [pid 521505:tid 521731] [client 216.73.216.128:27728] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:12.444559 2026] [authz_core:error] [pid 521505:tid 521731] [client 216.73.216.128:27728] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:12.469854 2026] [security2:error] [pid 521505:tid 521642] [client 20.104.50.220:42761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/gank.php"] [unique_id "apPmGG8byYE0iXl--K6xAgAAAyU"]
[Sun Aug 30 03:13:12.471032 2026] [security2:error] [pid 524122:tid 524325] [client 4.205.62.107:15953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/wp-konfig.php"] [unique_id "apPmGH3lhEjKFiK_nBKIhgAAAdc"]
[Sun Aug 30 03:13:12.471042 2026] [security2:error] [pid 521505:tid 521679] [client 20.104.18.15:22408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/x.php"] [unique_id "apPmGG8byYE0iXl--K6xAwAAA0o"]
[Sun Aug 30 03:13:12.474326 2026] [security2:error] [pid 524122:tid 524351] [client 20.151.200.44:55708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.americanqualityhomeinspections.com"] [uri "/file66.php"] [unique_id "apPmGH3lhEjKFiK_nBKIhwAAAfE"]
[Sun Aug 30 03:13:12.478067 2026] [authz_core:error] [pid 521505:tid 521655] [client 66.249.66.64:40620] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:12.478339 2026] [authz_core:error] [pid 521505:tid 521655] [client 66.249.66.64:40620] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:12.501886 2026] [authz_core:error] [pid 521505:tid 521732] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory8
[Sun Aug 30 03:13:12.502317 2026] [authz_core:error] [pid 521505:tid 521732] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory8
[Sun Aug 30 03:13:12.514081 2026] [security2:error] [pid 521505:tid 521718] [client 93.123.109.228:43852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/php-info.php"] [unique_id "apPmGG8byYE0iXl--K6xCgAAA3E"]
[Sun Aug 30 03:13:12.535951 2026] [security2:error] [pid 521505:tid 521669] [client 93.123.109.228:43912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/php_info.php"] [unique_id "apPmGG8byYE0iXl--K6xDAAAA0A"]
[Sun Aug 30 03:13:12.539721 2026] [security2:error] [pid 524122:tid 524358] [client 93.123.109.228:43804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/phpinfo.php"] [unique_id "apPmGH3lhEjKFiK_nBKIjgAAAfg"]
[Sun Aug 30 03:13:12.541736 2026] [security2:error] [pid 521505:tid 521644] [client 93.123.109.228:43838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/php.php"] [unique_id "apPmGG8byYE0iXl--K6xDQAAAyc"]
[Sun Aug 30 03:13:12.542269 2026] [security2:error] [pid 524122:tid 524256] [client 93.123.109.228:43928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/portal/.env"] [unique_id "apPmGH3lhEjKFiK_nBKIjwAAAZI"]
[Sun Aug 30 03:13:12.546213 2026] [security2:error] [pid 521505:tid 521720] [client 20.104.18.15:51115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/bo.php"] [unique_id "apPmGG8byYE0iXl--K6xDgAAA3M"]
[Sun Aug 30 03:13:12.585756 2026] [security2:error] [pid 524122:tid 524319] [client 93.123.109.228:43918] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/prod/.env"] [unique_id "apPmGH3lhEjKFiK_nBKIkgAAAdE"]
[Sun Aug 30 03:13:12.609054 2026] [core:error] [pid 521505:tid 521640] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:12.609081 2026] [core:error] [pid 521505:tid 521640] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:12.615702 2026] [security2:error] [pid 524122:tid 524370] [client 93.123.109.228:43868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/product/.env"] [unique_id "apPmGH3lhEjKFiK_nBKIlAAAAgQ"]
[Sun Aug 30 03:13:12.623689 2026] [security2:error] [pid 521505:tid 521747] [client 158.23.147.79:52690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-admin/images/index.php"] [unique_id "apPmGG8byYE0iXl--K6xFQAAA44"]
[Sun Aug 30 03:13:12.627113 2026] [authz_core:error] [pid 521505:tid 521645] [client 216.73.216.128:27728] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:12.627555 2026] [authz_core:error] [pid 521505:tid 521645] [client 216.73.216.128:27728] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:12.633250 2026] [security2:error] [pid 521505:tid 521666] [client 93.123.109.228:43910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/production/.env"] [unique_id "apPmGG8byYE0iXl--K6xFgAAAz0"]
[Sun Aug 30 03:13:12.639779 2026] [security2:error] [pid 521505:tid 521635] [client 52.139.37.240:9474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-admin/file.php"] [unique_id "apPmGG8byYE0iXl--K6xFwAAAx4"]
[Sun Aug 30 03:13:12.665000 2026] [security2:error] [pid 521505:tid 521760] [client 93.123.109.228:43872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/project/.env"] [unique_id "apPmGG8byYE0iXl--K6xGQAAA5s"]
[Sun Aug 30 03:13:12.675321 2026] [security2:error] [pid 521505:tid 521643] [client 20.48.251.3:54818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/server_info.php"] [unique_id "apPmGG8byYE0iXl--K6xGwAAAyY"]
[Sun Aug 30 03:13:12.686120 2026] [security2:error] [pid 524122:tid 524347] [client 93.123.109.228:43928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/public-api/.env"] [unique_id "apPmGH3lhEjKFiK_nBKImgAAAe0"]
[Sun Aug 30 03:13:12.693244 2026] [security2:error] [pid 524122:tid 524345] [client 93.123.109.228:43896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/public/phpinfo.php"] [unique_id "apPmGH3lhEjKFiK_nBKImwAAAes"]
[Sun Aug 30 03:13:12.700745 2026] [security2:error] [pid 521505:tid 521761] [client 93.123.109.228:43718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/public/.env"] [unique_id "apPmGG8byYE0iXl--K6xHwAAA5w"]
[Sun Aug 30 03:13:12.746721 2026] [security2:error] [pid 521505:tid 521723] [client 93.123.109.228:43784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/public_html/.env"] [unique_id "apPmGG8byYE0iXl--K6xIQAAA3Y"]
[Sun Aug 30 03:13:12.768017 2026] [security2:error] [pid 524122:tid 524311] [client 93.123.109.228:43682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/qa/.env"] [unique_id "apPmGH3lhEjKFiK_nBKInwAAAck"]
[Sun Aug 30 03:13:12.773279 2026] [authz_core:error] [pid 521505:tid 521638] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:12.773545 2026] [authz_core:error] [pid 521505:tid 521638] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:12.777717 2026] [security2:error] [pid 521505:tid 521660] [client 20.104.50.220:31185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/sx.php"] [unique_id "apPmGG8byYE0iXl--K6xIwAAAzc"]
[Sun Aug 30 03:13:12.784048 2026] [security2:error] [pid 521505:tid 521684] [client 158.23.147.79:55404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-includes/index.php"] [unique_id "apPmGG8byYE0iXl--K6xJQAAA08"]
[Sun Aug 30 03:13:12.891554 2026] [security2:error] [pid 521505:tid 521702] [client 158.23.147.79:43873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apPmGG8byYE0iXl--K6xMAAAA2E"]
[Sun Aug 30 03:13:12.912098 2026] [security2:error] [pid 521505:tid 521636] [client 52.139.37.240:53248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/bak.php"] [unique_id "apPmGG8byYE0iXl--K6xNAAAAx8"]
[Sun Aug 30 03:13:12.916655 2026] [security2:error] [pid 521505:tid 521699] [client 20.48.251.3:36845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/gk.php"] [unique_id "apPmGG8byYE0iXl--K6xNQAAA14"]
[Sun Aug 30 03:13:12.957152 2026] [security2:error] [pid 521505:tid 521745] [client 20.104.50.220:52836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/su.php"] [unique_id "apPmGG8byYE0iXl--K6xOAAAA4w"]
[Sun Aug 30 03:13:12.983658 2026] [security2:error] [pid 524122:tid 524277] [client 20.197.61.180:16056] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "petworthcs.com"] [uri "/c99.php"] [unique_id "apPmGH3lhEjKFiK_nBKIrwAAAac"]
[Sun Aug 30 03:13:13.018432 2026] [core:error] [pid 521505:tid 521685] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:13.018456 2026] [core:error] [pid 521505:tid 521685] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:13.020873 2026] [security2:error] [pid 524122:tid 524299] [client 158.23.147.79:52720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/mah.php"] [unique_id "apPmGX3lhEjKFiK_nBKItgAAAb0"]
[Sun Aug 30 03:13:13.022954 2026] [authz_core:error] [pid 521505:tid 521740] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory4
[Sun Aug 30 03:13:13.023370 2026] [authz_core:error] [pid 521505:tid 521740] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory4
[Sun Aug 30 03:13:13.038851 2026] [security2:error] [pid 521505:tid 521641] [client 20.151.200.44:55723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.americanqualityhomeinspections.com"] [uri "/blnux.php"] [unique_id "apPmGW8byYE0iXl--K6xQAAAAyQ"]
[Sun Aug 30 03:13:13.069851 2026] [security2:error] [pid 521505:tid 521653] [client 20.104.50.220:17289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/.well-known/60.php"] [unique_id "apPmGW8byYE0iXl--K6xQgAAAzA"]
[Sun Aug 30 03:13:13.084563 2026] [security2:error] [pid 521505:tid 521644] [client 20.104.50.220:25290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/abcd.php"] [unique_id "apPmGW8byYE0iXl--K6xQwAAAyc"]
[Sun Aug 30 03:13:13.092933 2026] [authz_core:error] [pid 521505:tid 521735] [client 216.73.216.128:48435] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:13.093364 2026] [authz_core:error] [pid 521505:tid 521735] [client 216.73.216.128:48435] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:13.094071 2026] [security2:error] [pid 521505:tid 521704] [client 93.123.109.228:43910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/s3/.env.bak"] [unique_id "apPmGW8byYE0iXl--K6xRgAAA2M"]
[Sun Aug 30 03:13:13.132943 2026] [security2:error] [pid 521505:tid 521738] [client 52.139.37.240:9501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/config.php"] [unique_id "apPmGW8byYE0iXl--K6xSAAAA4U"]
[Sun Aug 30 03:13:13.153025 2026] [security2:error] [pid 524122:tid 524282] [client 93.123.109.228:44048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/server/api/.env"] [unique_id "apPmGX3lhEjKFiK_nBKIwwAAAaw"]
[Sun Aug 30 03:13:13.153639 2026] [security2:error] [pid 524122:tid 524365] [client 93.123.109.228:43988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/server/.env"] [unique_id "apPmGX3lhEjKFiK_nBKIxAAAAf8"]
[Sun Aug 30 03:13:13.155182 2026] [security2:error] [pid 521505:tid 521661] [client 158.23.147.79:55374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-blog-header.php"] [unique_id "apPmGW8byYE0iXl--K6xSwAAAzg"]
[Sun Aug 30 03:13:13.173075 2026] [authz_core:error] [pid 521505:tid 521664] [client 66.249.66.76:51523] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:13.173448 2026] [authz_core:error] [pid 521505:tid 521664] [client 66.249.66.76:51523] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:13.188494 2026] [security2:error] [pid 524122:tid 524349] [client 93.123.109.228:44074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/server/backend/.env"] [unique_id "apPmGX3lhEjKFiK_nBKIyAAAAe8"]
[Sun Aug 30 03:13:13.192553 2026] [security2:error] [pid 521505:tid 521739] [client 20.104.50.220:33214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/ids.php"] [unique_id "apPmGW8byYE0iXl--K6xTQAAA4Y"]
[Sun Aug 30 03:13:13.197070 2026] [security2:error] [pid 521505:tid 521747] [client 4.205.62.107:32463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/localconf.php"] [unique_id "apPmGW8byYE0iXl--K6xTgAAA44"]
[Sun Aug 30 03:13:13.224608 2026] [security2:error] [pid 521505:tid 521736] [client 4.205.62.107:52927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/thui.php"] [unique_id "apPmGW8byYE0iXl--K6xUQAAA4M"]
[Sun Aug 30 03:13:13.243182 2026] [security2:error] [pid 521505:tid 521643] [client 20.104.50.220:5914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/z.php"] [unique_id "apPmGW8byYE0iXl--K6xVAAAAyY"]
[Sun Aug 30 03:13:13.265749 2026] [security2:error] [pid 521505:tid 521697] [client 4.205.62.107:17090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fcconveyancing.com.au"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPmGW8byYE0iXl--K6xVQAAA1w"]
[Sun Aug 30 03:13:13.274626 2026] [authz_core:error] [pid 521505:tid 521737] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:13.275026 2026] [authz_core:error] [pid 521505:tid 521737] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:13.283063 2026] [security2:error] [pid 524122:tid 524280] [client 68.155.159.216:60337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/wp-content/languages/about.php"] [unique_id "apPmGX3lhEjKFiK_nBKI0QAAAao"]
[Sun Aug 30 03:13:13.297711 2026] [core:alert] [pid 521505:tid 521676] [client 200.12.30.19:0] /home3/fremant1/thedevonshireteaguide.com.au/.htaccess: without matching section
[Sun Aug 30 03:13:13.302770 2026] [security2:error] [pid 521505:tid 521667] [client 93.123.109.228:43718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/service/.env"] [unique_id "apPmGW8byYE0iXl--K6xWwAAAz4"]
[Sun Aug 30 03:13:13.311202 2026] [security2:error] [pid 524122:tid 524308] [client 93.123.109.228:43988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/services/.env"] [unique_id "apPmGX3lhEjKFiK_nBKI1wAAAcY"]
[Sun Aug 30 03:13:13.325849 2026] [core:error] [pid 524122:tid 524270] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:13.325881 2026] [core:error] [pid 524122:tid 524270] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:13.371174 2026] [security2:error] [pid 524122:tid 524257] [client 20.104.50.220:62013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/classwithtostring.php"] [unique_id "apPmGX3lhEjKFiK_nBKI2wAAAZM"]
[Sun Aug 30 03:13:13.376371 2026] [authz_core:error] [pid 521505:tid 521723] [client 216.73.216.128:27728] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:13.376808 2026] [authz_core:error] [pid 521505:tid 521723] [client 216.73.216.128:27728] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:13.394612 2026] [security2:error] [pid 521505:tid 521717] [client 93.123.109.228:43910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/shared/.env"] [unique_id "apPmGW8byYE0iXl--K6xXwAAA3A"]
[Sun Aug 30 03:13:13.396933 2026] [security2:error] [pid 524122:tid 524356] [client 52.139.37.240:9387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-activate.php"] [unique_id "apPmGX3lhEjKFiK_nBKI3wAAAfY"]
[Sun Aug 30 03:13:13.410628 2026] [security2:error] [pid 524122:tid 524326] [client 20.104.49.130:51576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/js.php"] [unique_id "apPmGX3lhEjKFiK_nBKI4AAAAdg"]
[Sun Aug 30 03:13:13.423897 2026] [security2:error] [pid 521505:tid 521684] [client 93.123.109.228:43872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/shop/.env"] [unique_id "apPmGW8byYE0iXl--K6xYgAAA08"]
[Sun Aug 30 03:13:13.426634 2026] [security2:error] [pid 521505:tid 521759] [client 158.23.147.79:59067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-content/plugins/ioxi/alfa-ioxi.php"] [unique_id "apPmGW8byYE0iXl--K6xYwAAA5o"]
[Sun Aug 30 03:13:13.426952 2026] [authz_core:error] [pid 524122:tid 524346] [client 66.249.66.39:37291] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:13.427215 2026] [authz_core:error] [pid 524122:tid 524346] [client 66.249.66.39:37291] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:13.450129 2026] [security2:error] [pid 521505:tid 521693] [client 93.123.109.228:43718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/src/.env"] [unique_id "apPmGW8byYE0iXl--K6xZAAAA1g"]
[Sun Aug 30 03:13:13.462880 2026] [security2:error] [pid 524122:tid 524319] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/.env.bak"] [unique_id "apPmGX3lhEjKFiK_nBKI6QAAAdE"]
[Sun Aug 30 03:13:13.495754 2026] [authz_core:error] [pid 521505:tid 521686] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory2
[Sun Aug 30 03:13:13.496032 2026] [authz_core:error] [pid 521505:tid 521686] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory2
[Sun Aug 30 03:13:13.498149 2026] [security2:error] [pid 524122:tid 524368] [client 20.104.50.220:62788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/new.php"] [unique_id "apPmGX3lhEjKFiK_nBKI7wAAAgI"]
[Sun Aug 30 03:13:13.530673 2026] [security2:error] [pid 524122:tid 524347] [client 20.104.49.130:59573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/bolt.php"] [unique_id "apPmGX3lhEjKFiK_nBKI8QAAAe0"]
[Sun Aug 30 03:13:13.536183 2026] [security2:error] [pid 521505:tid 521758] [client 4.205.62.107:15614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/admin-ajax.php"] [unique_id "apPmGW8byYE0iXl--K6xaQAAA5k"]
[Sun Aug 30 03:13:13.580522 2026] [security2:error] [pid 524122:tid 524290] [client 93.123.109.228:43846] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/srv/.env"] [unique_id "apPmGX3lhEjKFiK_nBKI9wAAAbQ"]
[Sun Aug 30 03:13:13.585655 2026] [security2:error] [pid 524122:tid 524302] [client 93.123.109.228:44086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/stage/.env"] [unique_id "apPmGX3lhEjKFiK_nBKI-AAAAcA"]
[Sun Aug 30 03:13:13.588252 2026] [security2:error] [pid 524122:tid 524376] [client 103.131.71.229:41231] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.luxtiny.com"] [uri "/index.php"] [unique_id "apPmGX3lhEjKFiK_nBKI8wAAAgo"]
[Sun Aug 30 03:13:13.591601 2026] [security2:error] [pid 524122:tid 524339] [client 93.123.109.228:43956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/staging/.env"] [unique_id "apPmGX3lhEjKFiK_nBKI-QAAAeU"]
[Sun Aug 30 03:13:13.592938 2026] [security2:error] [pid 521505:tid 521749] [client 158.23.147.79:61809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/file.php"] [unique_id "apPmGW8byYE0iXl--K6xbQAAA5A"]
[Sun Aug 30 03:13:13.608029 2026] [security2:error] [pid 524122:tid 524259] [client 20.104.18.15:22499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "apPmGX3lhEjKFiK_nBKI-wAAAZU"]
[Sun Aug 30 03:13:13.617007 2026] [security2:error] [pid 524122:tid 524261] [client 52.139.37.240:9482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/12.php"] [unique_id "apPmGX3lhEjKFiK_nBKI_gAAAZc"]
[Sun Aug 30 03:13:13.617471 2026] [security2:error] [pid 521505:tid 521707] [client 4.205.62.107:15959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/25.php"] [unique_id "apPmGW8byYE0iXl--K6xbwAAA2Y"]
[Sun Aug 30 03:13:13.623974 2026] [security2:error] [pid 524122:tid 524272] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/.env.backup"] [unique_id "apPmGX3lhEjKFiK_nBKI_wAAAaI"]
[Sun Aug 30 03:13:13.626970 2026] [security2:error] [pid 521505:tid 521636] [client 158.23.147.79:59027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-admin/user/index.php"] [unique_id "apPmGW8byYE0iXl--K6xcAAAAx8"]
[Sun Aug 30 03:13:13.628619 2026] [security2:error] [pid 524122:tid 524275] [client 93.123.109.228:43678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/stg/.env"] [unique_id "apPmGX3lhEjKFiK_nBKJAQAAAaU"]
[Sun Aug 30 03:13:13.636586 2026] [security2:error] [pid 521505:tid 521742] [client 20.104.50.220:63548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/gank.php.PhP"] [unique_id "apPmGW8byYE0iXl--K6xcgAAA4k"]
[Sun Aug 30 03:13:13.648393 2026] [security2:error] [pid 524122:tid 524342] [client 216.73.216.128:36316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/scripts/mailserverconfig"] [unique_id "apPmGX3lhEjKFiK_nBKJAgAAAeg"]
[Sun Aug 30 03:13:13.699720 2026] [security2:error] [pid 521505:tid 521708] [client 20.104.18.15:51179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/44.php"] [unique_id "apPmGW8byYE0iXl--K6xcwAAA2c"]
[Sun Aug 30 03:13:13.716164 2026] [security2:error] [pid 521505:tid 521651] [client 20.197.61.180:19240] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "petworthcs.com"] [uri "/c99.php"] [unique_id "apPmGW8byYE0iXl--K6xdQAAAy4"]
[Sun Aug 30 03:13:13.719980 2026] [security2:error] [pid 524122:tid 524269] [client 93.123.109.228:43830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/stripe/.env"] [unique_id "apPmGX3lhEjKFiK_nBKJDAAAAZ8"]
[Sun Aug 30 03:13:13.743380 2026] [security2:error] [pid 521505:tid 521657] [client 34.106.227.237:59200] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/.env.bak"] [unique_id "apPmGW8byYE0iXl--K6xeAAAAzQ"]
[Sun Aug 30 03:13:13.750693 2026] [cgid:error] [pid 524122:tid 524258] [client 93.123.109.228:43972] AH01264: stderr from /home3/jvallesteros/jeanbooknerdstorytellersbox.com/sysinfo.cgi: script not found or unable to stat
[Sun Aug 30 03:13:13.782997 2026] [security2:error] [pid 524122:tid 524299] [client 93.123.109.228:44074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/terraform.tfstate.backup"] [unique_id "apPmGX3lhEjKFiK_nBKJEQAAAb0"]
[Sun Aug 30 03:13:13.792634 2026] [authz_core:error] [pid 521505:tid 521677] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:13.793089 2026] [authz_core:error] [pid 521505:tid 521677] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:13.795249 2026] [security2:error] [pid 524122:tid 524353] [client 93.123.109.228:44048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/test.php"] [unique_id "apPmGX3lhEjKFiK_nBKJFQAAAfM"]
[Sun Aug 30 03:13:13.814912 2026] [security2:error] [pid 521505:tid 521654] [client 52.139.37.240:9505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/epinyins.php"] [unique_id "apPmGW8byYE0iXl--K6xfwAAAzE"]
[Sun Aug 30 03:13:13.815598 2026] [security2:error] [pid 524122:tid 524360] [client 93.123.109.228:44086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/test/.env"] [unique_id "apPmGX3lhEjKFiK_nBKJFwAAAfo"]
[Sun Aug 30 03:13:13.830661 2026] [security2:error] [pid 521505:tid 521641] [client 216.73.216.128:27728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/about.html"] [unique_id "apPmGW8byYE0iXl--K6xhQAAAyQ"]
[Sun Aug 30 03:13:13.855118 2026] [security2:error] [pid 521505:tid 521757] [client 34.106.227.237:59200] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/.env.backup"] [unique_id "apPmGW8byYE0iXl--K6xhwAAA5g"]
[Sun Aug 30 03:13:13.859718 2026] [security2:error] [pid 521505:tid 521704] [client 20.48.251.3:64275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/hosty.php"] [unique_id "apPmGW8byYE0iXl--K6xiQAAA2M"]
[Sun Aug 30 03:13:13.865360 2026] [authz_core:error] [pid 521505:tid 521644] [client 66.249.66.204:51918] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:13.865760 2026] [authz_core:error] [pid 521505:tid 521644] [client 66.249.66.204:51918] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:13.876182 2026] [security2:error] [pid 521505:tid 521731] [client 93.123.109.228:43872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/user/.env"] [unique_id "apPmGW8byYE0iXl--K6xigAAA34"]
[Sun Aug 30 03:13:13.884516 2026] [security2:error] [pid 521505:tid 521638] [client 93.123.109.228:43910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/v1/.env"] [unique_id "apPmGW8byYE0iXl--K6xiwAAAyE"]
[Sun Aug 30 03:13:13.926083 2026] [security2:error] [pid 521505:tid 521733] [client 93.123.109.228:43718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/v2/.env"] [unique_id "apPmGW8byYE0iXl--K6xjgAAA4A"]
[Sun Aug 30 03:13:13.928180 2026] [security2:error] [pid 521505:tid 521713] [client 20.104.50.220:31545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "apPmGW8byYE0iXl--K6xkAAAA2w"]
[Sun Aug 30 03:13:13.938838 2026] [security2:error] [pid 524122:tid 524315] [client 93.123.109.228:43988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/v3/.env"] [unique_id "apPmGX3lhEjKFiK_nBKJHAAAAc0"]
[Sun Aug 30 03:13:13.961812 2026] [core:error] [pid 524122:tid 524285] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:13.961836 2026] [core:error] [pid 524122:tid 524285] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:13.976518 2026] [authz_core:error] [pid 521505:tid 521701] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory5
[Sun Aug 30 03:13:13.976944 2026] [authz_core:error] [pid 521505:tid 521701] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory5
[Sun Aug 30 03:13:13.980015 2026] [security2:error] [pid 524122:tid 524295] [client 158.23.147.79:52717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-includes/plugins.php"] [unique_id "apPmGX3lhEjKFiK_nBKJJAAAAbk"]
[Sun Aug 30 03:13:13.980066 2026] [security2:error] [pid 524122:tid 524337] [client 20.104.49.130:43642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/makeasmtp.php"] [unique_id "apPmGX3lhEjKFiK_nBKJIwAAAeM"]
[Sun Aug 30 03:13:14.064456 2026] [security2:error] [pid 524122:tid 524372] [client 52.139.37.240:9363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "apPmGn3lhEjKFiK_nBKJKwAAAgY"]
[Sun Aug 30 03:13:14.071414 2026] [security2:error] [pid 524122:tid 524320] [client 20.48.251.3:36881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/god.php"] [unique_id "apPmGn3lhEjKFiK_nBKJLQAAAdI"]
[Sun Aug 30 03:13:14.089830 2026] [security2:error] [pid 524122:tid 524300] [client 93.123.109.228:44074] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/var/www/.env"] [unique_id "apPmGn3lhEjKFiK_nBKJLwAAAb4"]
[Sun Aug 30 03:13:14.098942 2026] [security2:error] [pid 521505:tid 521760] [client 93.123.109.228:44078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/var/www/html/.env"] [unique_id "apPmGm8byYE0iXl--K6xsgAAA5s"]
[Sun Aug 30 03:13:14.106824 2026] [security2:error] [pid 521505:tid 521695] [client 20.104.50.220:29143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/xx.php"] [unique_id "apPmGm8byYE0iXl--K6xswAAA1o"]
[Sun Aug 30 03:13:14.116692 2026] [security2:error] [pid 524122:tid 524324] [client 93.123.109.228:43956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/web/.env"] [unique_id "apPmGn3lhEjKFiK_nBKJMgAAAdY"]
[Sun Aug 30 03:13:14.123478 2026] [security2:error] [pid 521505:tid 521756] [client 20.151.200.44:52073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/im.php"] [unique_id "apPmGm8byYE0iXl--K6xtQAAA5c"]
[Sun Aug 30 03:13:14.174698 2026] [security2:error] [pid 521505:tid 521706] [client 158.23.147.79:61968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/file17.php"] [unique_id "apPmGm8byYE0iXl--K6xtwAAA2U"]
[Sun Aug 30 03:13:14.196803 2026] [security2:error] [pid 524122:tid 524367] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/.env.old"] [unique_id "apPmGn3lhEjKFiK_nBKJOQAAAgE"]
[Sun Aug 30 03:13:14.207240 2026] [security2:error] [pid 521505:tid 521676] [client 20.104.50.220:17294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/.well-known/59.php"] [unique_id "apPmGm8byYE0iXl--K6xuwAAA0c"]
[Sun Aug 30 03:13:14.222595 2026] [security2:error] [pid 521505:tid 521688] [client 20.151.200.44:62916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/admin.php/csv.php"] [unique_id "apPmGm8byYE0iXl--K6xvAAAA1M"]
[Sun Aug 30 03:13:14.223640 2026] [security2:error] [pid 521505:tid 521709] [client 158.23.147.79:55415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-includes/js/thickbox/thickbox.php"] [unique_id "apPmGm8byYE0iXl--K6xvQAAA2g"]
[Sun Aug 30 03:13:14.226528 2026] [security2:error] [pid 521505:tid 521714] [client 20.151.200.44:45957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/is.php"] [unique_id "apPmGm8byYE0iXl--K6xvwAAA20"]
[Sun Aug 30 03:13:14.244278 2026] [security2:error] [pid 524122:tid 524325] [client 20.104.50.220:25447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/a1.php"] [unique_id "apPmGn3lhEjKFiK_nBKJOwAAAdc"]
[Sun Aug 30 03:13:14.249772 2026] [authz_core:error] [pid 521505:tid 521675] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:14.250037 2026] [authz_core:error] [pid 521505:tid 521675] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:14.250994 2026] [security2:error] [pid 524122:tid 524326] [client 93.123.109.228:44074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/wp-config.php"] [unique_id "apPmGn3lhEjKFiK_nBKJPgAAAdg"]
[Sun Aug 30 03:13:14.255605 2026] [security2:error] [pid 524122:tid 524375] [client 93.123.109.228:43678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/website/.env"] [unique_id "apPmGn3lhEjKFiK_nBKJPwAAAgk"]
[Sun Aug 30 03:13:14.262899 2026] [security2:error] [pid 524122:tid 524293] [client 93.123.109.228:43956] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/wp-config.php.bak"] [unique_id "apPmGn3lhEjKFiK_nBKJQAAAAbc"]
[Sun Aug 30 03:13:14.276457 2026] [security2:error] [pid 521505:tid 521737] [client 93.123.109.228:44040] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/wp-config.php.new"] [unique_id "apPmGm8byYE0iXl--K6xwgAAA4Q"]
[Sun Aug 30 03:13:14.284537 2026] [security2:error] [pid 521505:tid 521671] [client 52.139.37.240:46949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/system_log.php"] [unique_id "apPmGm8byYE0iXl--K6xxAAAA0I"]
[Sun Aug 30 03:13:14.285530 2026] [security2:error] [pid 521505:tid 521711] [client 34.106.227.237:52754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/.env.old"] [unique_id "apPmGm8byYE0iXl--K6xwwAAA2o"]
[Sun Aug 30 03:13:14.291377 2026] [security2:error] [pid 524122:tid 524304] [client 93.123.109.228:44086] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/wp-config.php.old"] [unique_id "apPmGn3lhEjKFiK_nBKJQQAAAcI"]
[Sun Aug 30 03:13:14.295086 2026] [authz_core:error] [pid 521505:tid 521748] [client 66.249.66.75:64920] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:14.295370 2026] [authz_core:error] [pid 521505:tid 521748] [client 66.249.66.75:64920] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:14.304797 2026] [security2:error] [pid 524122:tid 524318] [client 93.123.109.228:43830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "jeanbooknerdstorytellersbox.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPmGn3lhEjKFiK_nBKJQwAAAdA"]
[Sun Aug 30 03:13:14.346541 2026] [security2:error] [pid 521505:tid 521687] [client 20.104.50.220:33081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/idx.php"] [unique_id "apPmGm8byYE0iXl--K6xyAAAA1I"]
[Sun Aug 30 03:13:14.366449 2026] [security2:error] [pid 524122:tid 524319] [client 4.205.62.107:28997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/file21.php"] [unique_id "apPmGn3lhEjKFiK_nBKJRgAAAdE"]
[Sun Aug 30 03:13:14.369529 2026] [security2:error] [pid 521505:tid 521674] [client 4.205.62.107:32035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/bengi.php"] [unique_id "apPmGm8byYE0iXl--K6xyQAAA0U"]
[Sun Aug 30 03:13:14.389886 2026] [security2:error] [pid 521505:tid 521683] [client 20.104.50.220:5948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/y.php"] [unique_id "apPmGm8byYE0iXl--K6xzAAAA04"]
[Sun Aug 30 03:13:14.397554 2026] [authz_core:error] [pid 524122:tid 524380] [client 216.73.216.128:48472] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:14.397839 2026] [authz_core:error] [pid 524122:tid 524380] [client 216.73.216.128:48472] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:14.402197 2026] [security2:error] [pid 524122:tid 524309] [client 4.205.62.107:17147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fcconveyancing.com.au"] [uri "/cloud.php"] [unique_id "apPmGn3lhEjKFiK_nBKJTAAAAcc"]
[Sun Aug 30 03:13:14.403315 2026] [security2:error] [pid 521505:tid 521758] [client 68.155.159.216:60942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/wp-content/banners/about.php"] [unique_id "apPmGm8byYE0iXl--K6xzQAAA5k"]
[Sun Aug 30 03:13:14.436573 2026] [security2:error] [pid 524122:tid 524257] [client 20.197.61.180:19236] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "petworthcs.com"] [uri "/c99.php"] [unique_id "apPmGn3lhEjKFiK_nBKJTQAAAZM"]
[Sun Aug 30 03:13:14.467062 2026] [core:error] [pid 521505:tid 521655] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:14.467083 2026] [core:error] [pid 521505:tid 521655] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:14.475707 2026] [authz_core:error] [pid 521505:tid 521698] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory9
[Sun Aug 30 03:13:14.476122 2026] [authz_core:error] [pid 521505:tid 521698] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory9
[Sun Aug 30 03:13:14.547008 2026] [security2:error] [pid 524122:tid 524343] [client 20.104.49.130:60938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/sta.php"] [unique_id "apPmGn3lhEjKFiK_nBKJTwAAAek"]
[Sun Aug 30 03:13:14.558885 2026] [security2:error] [pid 521505:tid 521662] [client 20.104.50.220:61482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "apPmGm8byYE0iXl--K6x1QAAAzk"]
[Sun Aug 30 03:13:14.565735 2026] [security2:error] [pid 521505:tid 521686] [client 52.139.37.240:9510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-admin/maint/admin.php"] [unique_id "apPmGm8byYE0iXl--K6x1gAAA1E"]
[Sun Aug 30 03:13:14.669024 2026] [security2:error] [pid 521505:tid 521741] [client 20.104.50.220:64455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/Sym.php"] [unique_id "apPmGm8byYE0iXl--K6x3AAAA4g"]
[Sun Aug 30 03:13:14.682430 2026] [security2:error] [pid 521505:tid 521725] [client 4.205.62.107:15849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/ms.php"] [unique_id "apPmGm8byYE0iXl--K6x3gAAA3g"]
[Sun Aug 30 03:13:14.730790 2026] [authz_core:error] [pid 521505:tid 521704] [client 66.249.66.202:59209] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:14.731060 2026] [authz_core:error] [pid 521505:tid 521704] [client 66.249.66.202:59209] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:14.749818 2026] [security2:error] [pid 521505:tid 521733] [client 4.205.62.107:16359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/nlnub.php"] [unique_id "apPmGm8byYE0iXl--K6x4wAAA4A"]
[Sun Aug 30 03:13:14.761271 2026] [security2:error] [pid 521505:tid 521728] [client 20.104.18.15:22336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/wp-includes/index.php"] [unique_id "apPmGm8byYE0iXl--K6x5QAAA3s"]
[Sun Aug 30 03:13:14.763436 2026] [security2:error] [pid 521505:tid 521653] [client 52.139.37.240:46973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/ini.php"] [unique_id "apPmGm8byYE0iXl--K6x5gAAAzA"]
[Sun Aug 30 03:13:14.764405 2026] [authz_core:error] [pid 521505:tid 521661] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:14.764675 2026] [authz_core:error] [pid 521505:tid 521661] [client 74.7.243.204:52590] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:14.767920 2026] [security2:error] [pid 524122:tid 524307] [client 20.104.49.130:53606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/cilus.php"] [unique_id "apPmGn3lhEjKFiK_nBKJWAAAAcU"]
[Sun Aug 30 03:13:14.785275 2026] [security2:error] [pid 521505:tid 521670] [client 20.104.50.220:51639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/gh.php"] [unique_id "apPmGm8byYE0iXl--K6x5wAAA0E"]
[Sun Aug 30 03:13:14.824888 2026] [security2:error] [pid 521505:tid 521639] [client 20.197.61.180:8401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "a220training.com"] [uri "/wp-content/themes/data.php"] [unique_id "apPmGm8byYE0iXl--K6x6AAAAyI"]
[Sun Aug 30 03:13:14.859088 2026] [security2:error] [pid 524122:tid 524321] [client 20.104.18.15:51120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/h2.php"] [unique_id "apPmGn3lhEjKFiK_nBKJWQAAAdM"]
[Sun Aug 30 03:13:14.859452 2026] [core:error] [pid 521505:tid 521649] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:14.859471 2026] [core:error] [pid 521505:tid 521649] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:14.870703 2026] [security2:error] [pid 524122:tid 524298] [client 158.23.147.79:59052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/goat1.php"] [unique_id "apPmGn3lhEjKFiK_nBKJWgAAAbw"]
[Sun Aug 30 03:13:14.874903 2026] [security2:error] [pid 521505:tid 521740] [client 158.23.147.79:61717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/file5.php"] [unique_id "apPmGm8byYE0iXl--K6x7AAAA4c"]
[Sun Aug 30 03:13:15.002156 2026] [authz_core:error] [pid 521505:tid 521695] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory5
[Sun Aug 30 03:13:15.002423 2026] [authz_core:error] [pid 521505:tid 521695] [client 74.7.227.8:55494] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory5
[Sun Aug 30 03:13:15.007295 2026] [security2:error] [pid 524122:tid 524269] [client 52.139.37.240:9495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/ok.php"] [unique_id "apPmG33lhEjKFiK_nBKJXQAAAZ8"]
[Sun Aug 30 03:13:15.007928 2026] [security2:error] [pid 524122:tid 524323] [client 20.48.251.3:54734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/pass4.php"] [unique_id "apPmG33lhEjKFiK_nBKJXgAAAdU"]
[Sun Aug 30 03:13:15.035469 2026] [security2:error] [pid 521505:tid 521643] [client 20.151.200.44:52096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/file.php"] [unique_id "apPmG28byYE0iXl--K6x8QAAAyY"]
[Sun Aug 30 03:13:15.126006 2026] [security2:error] [pid 524122:tid 524335] [client 20.104.50.220:31539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/alfa.php"] [unique_id "apPmG33lhEjKFiK_nBKJZwAAAeE"]
[Sun Aug 30 03:13:15.148268 2026] [security2:error] [pid 524122:tid 524279] [client 20.151.200.44:55661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.americanqualityhomeinspections.com"] [uri "/attack.php"] [unique_id "apPmG33lhEjKFiK_nBKJaQAAAak"]
[Sun Aug 30 03:13:15.190882 2026] [security2:error] [pid 524122:tid 524258] [client 20.197.61.180:19460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/test1.php"] [unique_id "apPmG33lhEjKFiK_nBKJagAAAZQ"]
[Sun Aug 30 03:13:15.193277 2026] [security2:error] [pid 521505:tid 521667] [client 20.151.200.44:52135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/ca.php"] [unique_id "apPmG28byYE0iXl--K6x-AAAAz4"]
[Sun Aug 30 03:13:15.211666 2026] [security2:error] [pid 521505:tid 521720] [client 52.139.37.240:53271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-admin/includes/about.php"] [unique_id "apPmG28byYE0iXl--K6x-gAAA3M"]
[Sun Aug 30 03:13:15.220454 2026] [core:error] [pid 524122:tid 524289] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:15.220478 2026] [core:error] [pid 524122:tid 524289] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:15.223480 2026] [authz_core:error] [pid 521505:tid 521752] [client 66.249.66.73:52082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:15.223933 2026] [authz_core:error] [pid 521505:tid 521752] [client 66.249.66.73:52082] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:15.224017 2026] [security2:error] [pid 521505:tid 521755] [client 20.48.251.3:37274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/fff.php"] [unique_id "apPmG28byYE0iXl--K6x_QAAA5Y"]
[Sun Aug 30 03:13:15.258265 2026] [security2:error] [pid 521505:tid 521684] [client 20.104.50.220:62835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/byps.php"] [unique_id "apPmG28byYE0iXl--K6x_wAAA08"]
[Sun Aug 30 03:13:15.270279 2026] [authz_core:error] [pid 521505:tid 521645] [client 66.249.66.34:62299] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:15.270729 2026] [authz_core:error] [pid 521505:tid 521645] [client 66.249.66.34:62299] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:15.318314 2026] [authz_core:error] [pid 524122:tid 524286] [client 216.73.216.128:49424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:15.318758 2026] [authz_core:error] [pid 524122:tid 524286] [client 216.73.216.128:49424] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:15.347392 2026] [security2:error] [pid 524122:tid 524340] [client 20.104.50.220:16618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/.well-known/58.php"] [unique_id "apPmG33lhEjKFiK_nBKJbgAAAeY"]
[Sun Aug 30 03:13:15.382586 2026] [security2:error] [pid 524122:tid 524328] [client 20.151.200.44:44011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ermes-it.it"] [uri "/wp-access.php"] [unique_id "apPmG33lhEjKFiK_nBKJbwAAAdo"]
[Sun Aug 30 03:13:15.390509 2026] [security2:error] [pid 524122:tid 524253] [client 20.104.50.220:24874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "apPmG33lhEjKFiK_nBKJcAAAAY8"]
[Sun Aug 30 03:13:15.472065 2026] [security2:error] [pid 524122:tid 524291] [client 52.139.37.240:49717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-admin/maint.php"] [unique_id "apPmG33lhEjKFiK_nBKJdQAAAbU"]
[Sun Aug 30 03:13:15.482426 2026] [security2:error] [pid 524122:tid 524308] [client 20.104.50.220:33302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/init.php"] [unique_id "apPmG33lhEjKFiK_nBKJdgAAAcY"]
[Sun Aug 30 03:13:15.501255 2026] [security2:error] [pid 524122:tid 524254] [client 68.155.159.216:60332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apPmG33lhEjKFiK_nBKJeAAAAZA"]
[Sun Aug 30 03:13:15.519097 2026] [security2:error] [pid 524122:tid 524367] [client 4.205.62.107:58313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/i.php"] [unique_id "apPmG33lhEjKFiK_nBKJfAAAAgE"]
[Sun Aug 30 03:13:15.521511 2026] [authz_core:error] [pid 524122:tid 524312] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory0
[Sun Aug 30 03:13:15.521937 2026] [authz_core:error] [pid 524122:tid 524312] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory0
[Sun Aug 30 03:13:15.522533 2026] [security2:error] [pid 524122:tid 524349] [client 20.197.61.180:15041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "a220training.com"] [uri "/wp-content/themes/dt-the7/css/static-less/plugins/admin.php"] [unique_id "apPmG33lhEjKFiK_nBKJfgAAAe8"]
[Sun Aug 30 03:13:15.542321 2026] [security2:error] [pid 524122:tid 524325] [client 4.205.62.107:17282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fcconveyancing.com.au"] [uri "/kerang.php"] [unique_id "apPmG33lhEjKFiK_nBKJggAAAdc"]
[Sun Aug 30 03:13:15.542885 2026] [security2:error] [pid 524122:tid 524326] [client 20.104.50.220:5616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/x.php"] [unique_id "apPmG33lhEjKFiK_nBKJgwAAAdg"]
[Sun Aug 30 03:13:15.561023 2026] [security2:error] [pid 524122:tid 524293] [client 4.205.62.107:28718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/mcebraed.php"] [unique_id "apPmG33lhEjKFiK_nBKJhQAAAbc"]
[Sun Aug 30 03:13:15.570871 2026] [core:error] [pid 524122:tid 524304] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:15.570889 2026] [core:error] [pid 524122:tid 524304] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:15.575195 2026] [authz_core:error] [pid 524122:tid 524318] [client 66.249.66.72:50659] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:15.575526 2026] [authz_core:error] [pid 524122:tid 524318] [client 66.249.66.72:50659] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:15.591294 2026] [authz_core:error] [pid 524122:tid 524256] [client 216.73.216.128:36316] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:15.591559 2026] [authz_core:error] [pid 524122:tid 524256] [client 216.73.216.128:36316] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:15.653421 2026] [security2:error] [pid 524122:tid 524297] [client 158.23.147.79:62007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/file88.php"] [unique_id "apPmG33lhEjKFiK_nBKJiwAAAbs"]
[Sun Aug 30 03:13:15.700836 2026] [security2:error] [pid 524122:tid 524376] [client 20.151.200.44:44024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ermes-it.it"] [uri "/wp-content/admin.php"] [unique_id "apPmG33lhEjKFiK_nBKJkAAAAgo"]
[Sun Aug 30 03:13:15.700886 2026] [security2:error] [pid 524122:tid 524283] [client 52.139.37.240:9381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-configs.php"] [unique_id "apPmG33lhEjKFiK_nBKJjwAAAa0"]
[Sun Aug 30 03:13:15.701044 2026] [security2:error] [pid 524122:tid 524263] [client 20.104.50.220:61444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/fm.php"] [unique_id "apPmG33lhEjKFiK_nBKJkQAAAZk"]
[Sun Aug 30 03:13:15.705029 2026] [authz_core:error] [pid 524122:tid 524374] [client 66.249.66.43:46837] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:15.705310 2026] [authz_core:error] [pid 524122:tid 524374] [client 66.249.66.43:46837] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:15.711773 2026] [security2:error] [pid 524122:tid 524339] [client 158.23.147.79:52696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-includes/certificates/index.php"] [unique_id "apPmG33lhEjKFiK_nBKJkwAAAeU"]
[Sun Aug 30 03:13:15.716027 2026] [security2:error] [pid 524122:tid 524363] [client 20.151.200.44:52137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/pb.php"] [unique_id "apPmG33lhEjKFiK_nBKJlAAAAf0"]
[Sun Aug 30 03:13:15.724149 2026] [security2:error] [pid 524122:tid 524329] [client 216.73.216.128:30852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPmG33lhEjKFiK_nBKJlQAAAds"]
[Sun Aug 30 03:13:15.779453 2026] [security2:error] [pid 524122:tid 524334] [client 20.151.200.44:63555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/admin.php/700.php"] [unique_id "apPmG33lhEjKFiK_nBKJmAAAAeA"]
[Sun Aug 30 03:13:15.815314 2026] [security2:error] [pid 524122:tid 524260] [client 20.104.50.220:28708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/dom.php"] [unique_id "apPmG33lhEjKFiK_nBKJnAAAAZY"]
[Sun Aug 30 03:13:15.815911 2026] [security2:error] [pid 524122:tid 524269] [client 4.205.62.107:15852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/fucku.php"] [unique_id "apPmG33lhEjKFiK_nBKJnQAAAZ8"]
[Sun Aug 30 03:13:15.830401 2026] [authz_core:error] [pid 524122:tid 524323] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:15.830672 2026] [authz_core:error] [pid 524122:tid 524323] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:15.870094 2026] [core:error] [pid 524122:tid 524322] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:15.870118 2026] [core:error] [pid 524122:tid 524322] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:15.878687 2026] [security2:error] [pid 524122:tid 524299] [client 4.205.62.107:16362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/mga.php"] [unique_id "apPmG33lhEjKFiK_nBKJqgAAAb0"]
[Sun Aug 30 03:13:15.889794 2026] [authz_core:error] [pid 524122:tid 524371] [client 66.249.66.66:60633] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:15.890101 2026] [authz_core:error] [pid 524122:tid 524371] [client 66.249.66.66:60633] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:15.915659 2026] [security2:error] [pid 524122:tid 524362] [client 20.151.200.44:43907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ermes-it.it"] [uri "/log.php"] [unique_id "apPmG33lhEjKFiK_nBKJrQAAAfw"]
[Sun Aug 30 03:13:15.927183 2026] [security2:error] [pid 524122:tid 524338] [client 20.104.18.15:22347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/dk.php"] [unique_id "apPmG33lhEjKFiK_nBKJrgAAAeQ"]
[Sun Aug 30 03:13:15.941337 2026] [security2:error] [pid 524122:tid 524274] [client 20.104.50.220:42436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/id.php"] [unique_id "apPmG33lhEjKFiK_nBKJrwAAAaQ"]
[Sun Aug 30 03:13:15.968107 2026] [authz_core:error] [pid 524122:tid 524278] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory6
[Sun Aug 30 03:13:15.968397 2026] [authz_core:error] [pid 524122:tid 524278] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory6
[Sun Aug 30 03:13:15.971390 2026] [authz_core:error] [pid 524122:tid 524282] [client 66.249.66.32:60651] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:15.971752 2026] [authz_core:error] [pid 524122:tid 524282] [client 66.249.66.32:60651] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:15.984411 2026] [security2:error] [pid 524122:tid 524365] [client 52.139.37.240:9520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/01.php"] [unique_id "apPmG33lhEjKFiK_nBKJtAAAAf8"]
[Sun Aug 30 03:13:15.992950 2026] [authz_core:error] [pid 524122:tid 524285] [client 66.249.66.72:39842] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:15.993422 2026] [authz_core:error] [pid 524122:tid 524285] [client 66.249.66.72:39842] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:15.994016 2026] [security2:error] [pid 524122:tid 524346] [client 20.104.49.130:60745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wdfjba.org"] [uri "/abcd.php"] [unique_id "apPmG33lhEjKFiK_nBKJtQAAAew"]
[Sun Aug 30 03:13:15.994807 2026] [security2:error] [pid 524122:tid 524357] [client 20.197.61.180:19232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/data.php"] [unique_id "apPmG33lhEjKFiK_nBKJtgAAAfc"]
[Sun Aug 30 03:13:16.005223 2026] [security2:error] [pid 524122:tid 524286] [client 20.104.18.15:51017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apPmHH3lhEjKFiK_nBKJtwAAAbA"]
[Sun Aug 30 03:13:16.140775 2026] [security2:error] [pid 524122:tid 524326] [client 158.23.147.79:52713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-admin/network/index.php"] [unique_id "apPmHH3lhEjKFiK_nBKJwAAAAdg"]
[Sun Aug 30 03:13:16.155827 2026] [security2:error] [pid 524122:tid 524366] [client 20.48.251.3:65522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/cu.php"] [unique_id "apPmHH3lhEjKFiK_nBKJwgAAAgA"]
[Sun Aug 30 03:13:16.164407 2026] [core:error] [pid 524122:tid 524375] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:16.164428 2026] [core:error] [pid 524122:tid 524375] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:16.170565 2026] [security2:error] [pid 524122:tid 524309] [client 20.104.49.130:59579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/ws78.php"] [unique_id "apPmHH3lhEjKFiK_nBKJxgAAAcc"]
[Sun Aug 30 03:13:16.215876 2026] [security2:error] [pid 524122:tid 524356] [client 52.139.37.240:53232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-includes/SimplePie/admin.php"] [unique_id "apPmHH3lhEjKFiK_nBKJyAAAAfY"]
[Sun Aug 30 03:13:16.235784 2026] [security2:error] [pid 524122:tid 524253] [client 20.197.61.180:13170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "a220training.com"] [uri "/wp-content/themes/hideo/network.php"] [unique_id "apPmHH3lhEjKFiK_nBKJygAAAY8"]
[Sun Aug 30 03:13:16.256950 2026] [authz_core:error] [pid 524122:tid 524343] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:16.257231 2026] [authz_core:error] [pid 524122:tid 524343] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:16.260775 2026] [authz_core:error] [pid 524122:tid 524345] [client 66.249.66.68:39216] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:16.261067 2026] [authz_core:error] [pid 524122:tid 524345] [client 66.249.66.68:39216] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:16.274312 2026] [security2:error] [pid 524122:tid 524314] [client 20.197.61.180:20812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "demandthetruth.michaelegenolf.com"] [uri "/wp-content/themes/data.php"] [unique_id "apPmHH3lhEjKFiK_nBKJzQAAAcw"]
[Sun Aug 30 03:13:16.286688 2026] [security2:error] [pid 524122:tid 524301] [client 20.104.50.220:31195] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.mumbaidailys.com"] [uri "/1.php"] [unique_id "apPmHH3lhEjKFiK_nBKJzgAAAb8"]
[Sun Aug 30 03:13:16.286796 2026] [security2:error] [pid 524122:tid 524301] [client 20.104.50.220:31195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/1.php"] [unique_id "apPmHH3lhEjKFiK_nBKJzgAAAb8"]
[Sun Aug 30 03:13:16.308945 2026] [authz_core:error] [pid 524122:tid 524352] [client 66.249.66.65:60370] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:16.309231 2026] [authz_core:error] [pid 524122:tid 524352] [client 66.249.66.65:60370] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:16.315696 2026] [security2:error] [pid 524122:tid 524339] [client 158.23.147.79:61799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/NewFile.php/"] [unique_id "apPmHH3lhEjKFiK_nBKJ0QAAAeU"]
[Sun Aug 30 03:13:16.359433 2026] [authz_core:error] [pid 524122:tid 524260] [client 66.249.66.72:50659] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:16.359712 2026] [authz_core:error] [pid 524122:tid 524260] [client 66.249.66.72:50659] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:16.378464 2026] [security2:error] [pid 524122:tid 524311] [client 20.48.251.3:36875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/autogooey.php"] [unique_id "apPmHH3lhEjKFiK_nBKJ1gAAAck"]
[Sun Aug 30 03:13:16.416077 2026] [security2:error] [pid 524122:tid 524299] [client 20.104.50.220:29164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/themes/authentic/gud.php/themes/antioch/shell.php"] [unique_id "apPmHH3lhEjKFiK_nBKJ2wAAAb0"]
[Sun Aug 30 03:13:16.419469 2026] [authz_core:error] [pid 524122:tid 524287] [client 66.249.66.199:54834] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:16.419751 2026] [authz_core:error] [pid 524122:tid 524287] [client 66.249.66.199:54834] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:16.426938 2026] [security2:error] [pid 524122:tid 524327] [client 52.139.37.240:46974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-admin/css/colors/midnight/colors.php"] [unique_id "apPmHH3lhEjKFiK_nBKJ3AAAAdk"]
[Sun Aug 30 03:13:16.473540 2026] [authz_core:error] [pid 524122:tid 524362] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory7
[Sun Aug 30 03:13:16.473829 2026] [authz_core:error] [pid 524122:tid 524362] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory7
[Sun Aug 30 03:13:16.482801 2026] [core:error] [pid 524122:tid 524338] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:16.482821 2026] [core:error] [pid 524122:tid 524338] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:16.483385 2026] [security2:error] [pid 524122:tid 524323] [client 20.104.50.220:16670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/.well-known/57.php"] [unique_id "apPmHH3lhEjKFiK_nBKJ4QAAAdU"]
[Sun Aug 30 03:13:16.499625 2026] [authz_core:error] [pid 524122:tid 524289] [client 66.249.66.71:35614] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:16.499994 2026] [authz_core:error] [pid 524122:tid 524289] [client 66.249.66.71:35614] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:16.558924 2026] [authz_core:error] [pid 524122:tid 524254] [client 66.249.66.42:41492] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:16.559196 2026] [authz_core:error] [pid 524122:tid 524254] [client 66.249.66.42:41492] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:16.569397 2026] [security2:error] [pid 524122:tid 524344] [client 20.104.50.220:24848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/bal.php"] [unique_id "apPmHH3lhEjKFiK_nBKJ7AAAAeo"]
[Sun Aug 30 03:13:16.601984 2026] [security2:error] [pid 524122:tid 524296] [client 20.151.200.44:44025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ermes-it.it"] [uri "/xwpg.php"] [unique_id "apPmHH3lhEjKFiK_nBKJ7gAAAbo"]
[Sun Aug 30 03:13:16.605801 2026] [security2:error] [pid 524122:tid 524340] [client 158.23.147.79:62012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/dropdown.php"] [unique_id "apPmHH3lhEjKFiK_nBKJ7wAAAeY"]
[Sun Aug 30 03:13:16.631281 2026] [security2:error] [pid 524122:tid 524333] [client 52.139.37.240:9527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-content/upgrade/index.php"] [unique_id "apPmHH3lhEjKFiK_nBKJ8QAAAd8"]
[Sun Aug 30 03:13:16.632152 2026] [security2:error] [pid 524122:tid 524304] [client 158.23.147.79:55407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "apPmHH3lhEjKFiK_nBKJ8gAAAcI"]
[Sun Aug 30 03:13:16.636513 2026] [security2:error] [pid 524122:tid 524266] [client 20.104.50.220:33556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/kepo.php"] [unique_id "apPmHH3lhEjKFiK_nBKJ9AAAAZw"]
[Sun Aug 30 03:13:16.656784 2026] [security2:error] [pid 524122:tid 524267] [client 4.205.62.107:32486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/guk.php"] [unique_id "apPmHH3lhEjKFiK_nBKJ9QAAAZ0"]
[Sun Aug 30 03:13:16.667214 2026] [security2:error] [pid 524122:tid 524276] [client 68.155.159.216:60308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/asd.php"] [unique_id "apPmHH3lhEjKFiK_nBKJ9wAAAaY"]
[Sun Aug 30 03:13:16.681448 2026] [security2:error] [pid 524122:tid 524351] [client 20.104.50.220:6093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/w.php"] [unique_id "apPmHH3lhEjKFiK_nBKJ-AAAAfE"]
[Sun Aug 30 03:13:16.683336 2026] [security2:error] [pid 524122:tid 524305] [client 4.205.62.107:17091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fcconveyancing.com.au"] [uri "/rem.php"] [unique_id "apPmHH3lhEjKFiK_nBKJ-QAAAcM"]
[Sun Aug 30 03:13:16.701520 2026] [authz_core:error] [pid 524122:tid 524290] [client 216.73.216.128:36316] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:16.701777 2026] [authz_core:error] [pid 524122:tid 524290] [client 216.73.216.128:36316] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:16.718606 2026] [security2:error] [pid 524122:tid 524347] [client 4.205.62.107:52868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/server-info.php"] [unique_id "apPmHH3lhEjKFiK_nBKJ_QAAAe0"]
[Sun Aug 30 03:13:16.727929 2026] [security2:error] [pid 524122:tid 524365] [client 20.197.61.180:10561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/classwithtostring.php"] [unique_id "apPmHH3lhEjKFiK_nBKJ_wAAAf8"]
[Sun Aug 30 03:13:16.768331 2026] [authz_core:error] [pid 524122:tid 524380] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:16.768603 2026] [authz_core:error] [pid 524122:tid 524380] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:16.795379 2026] [core:error] [pid 524122:tid 524312] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:16.795398 2026] [core:error] [pid 524122:tid 524312] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:16.840116 2026] [security2:error] [pid 524122:tid 524292] [client 20.151.200.44:52056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/pk.php"] [unique_id "apPmHH3lhEjKFiK_nBKKCgAAAbY"]
[Sun Aug 30 03:13:16.854996 2026] [security2:error] [pid 524122:tid 524325] [client 20.104.50.220:59565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/403.php"] [unique_id "apPmHH3lhEjKFiK_nBKKCwAAAdc"]
[Sun Aug 30 03:13:16.911473 2026] [authz_core:error] [pid 524122:tid 524372] [client 66.249.66.71:63266] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:16.911749 2026] [authz_core:error] [pid 524122:tid 524372] [client 66.249.66.71:63266] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:16.943058 2026] [security2:error] [pid 524122:tid 524306] [client 20.197.61.180:13158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "a220training.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPmHH3lhEjKFiK_nBKKFwAAAcQ"]
[Sun Aug 30 03:13:16.949432 2026] [security2:error] [pid 524122:tid 524298] [client 52.139.37.240:49680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/db.php"] [unique_id "apPmHH3lhEjKFiK_nBKKGAAAAbw"]
[Sun Aug 30 03:13:16.952926 2026] [security2:error] [pid 524122:tid 524337] [client 4.205.62.107:15490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/error_log.php"] [unique_id "apPmHH3lhEjKFiK_nBKKGQAAAeM"]
[Sun Aug 30 03:13:16.953294 2026] [security2:error] [pid 524122:tid 524302] [client 158.23.147.79:52711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/.well-knownold/index.php"] [unique_id "apPmHH3lhEjKFiK_nBKKGgAAAcA"]
[Sun Aug 30 03:13:16.973989 2026] [authz_core:error] [pid 524122:tid 524342] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory8
[Sun Aug 30 03:13:16.974249 2026] [authz_core:error] [pid 524122:tid 524342] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory8
[Sun Aug 30 03:13:16.985893 2026] [security2:error] [pid 524122:tid 524358] [client 20.197.61.180:18304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "demandthetruth.michaelegenolf.com"] [uri "/wp-content/themes/dt-the7/css/static-less/plugins/admin.php"] [unique_id "apPmHH3lhEjKFiK_nBKKHAAAAfg"]
[Sun Aug 30 03:13:17.017796 2026] [security2:error] [pid 524122:tid 524346] [client 4.205.62.107:16332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/ccou.php"] [unique_id "apPmHX3lhEjKFiK_nBKKIAAAAew"]
[Sun Aug 30 03:13:17.024809 2026] [authz_core:error] [pid 524122:tid 524323] [client 66.249.66.203:47135] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:17.025236 2026] [authz_core:error] [pid 524122:tid 524323] [client 66.249.66.203:47135] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:17.037986 2026] [security2:error] [pid 524122:tid 524286] [client 20.104.50.220:29149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/v4ga.php"] [unique_id "apPmHX3lhEjKFiK_nBKKIQAAAbA"]
[Sun Aug 30 03:13:17.069870 2026] [security2:error] [pid 524122:tid 524258] [client 20.104.18.15:22415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/wp-content/mod/adminfuns.php"] [unique_id "apPmHX3lhEjKFiK_nBKKIwAAAZQ"]
[Sun Aug 30 03:13:17.095202 2026] [security2:error] [pid 524122:tid 524367] [client 20.220.10.235:48846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPmHX3lhEjKFiK_nBKKJAAAAgE"]
[Sun Aug 30 03:13:17.103447 2026] [security2:error] [pid 524122:tid 524296] [client 20.104.50.220:63549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/ids.php"] [unique_id "apPmHX3lhEjKFiK_nBKKJgAAAbo"]
[Sun Aug 30 03:13:17.113144 2026] [security2:error] [pid 524122:tid 524335] [client 158.23.147.79:52673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-includes/js/crop/index.php"] [unique_id "apPmHX3lhEjKFiK_nBKKJwAAAeE"]
[Sun Aug 30 03:13:17.150564 2026] [security2:error] [pid 524122:tid 524266] [client 20.104.18.15:51154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/sao.php"] [unique_id "apPmHX3lhEjKFiK_nBKKKgAAAZw"]
[Sun Aug 30 03:13:17.191659 2026] [authz_core:error] [pid 524122:tid 524261] [client 216.73.216.128:36316] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:17.191925 2026] [authz_core:error] [pid 524122:tid 524261] [client 216.73.216.128:36316] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:17.215465 2026] [security2:error] [pid 524122:tid 524275] [client 52.139.37.240:46936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-admin/pages.php"] [unique_id "apPmHX3lhEjKFiK_nBKKLwAAAaU"]
[Sun Aug 30 03:13:17.240694 2026] [security2:error] [pid 524122:tid 524370] [client 20.220.10.235:48665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPmHX3lhEjKFiK_nBKKMAAAAgQ"]
[Sun Aug 30 03:13:17.253326 2026] [authz_core:error] [pid 524122:tid 524365] [client 66.249.66.64:39952] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:17.253579 2026] [authz_core:error] [pid 524122:tid 524365] [client 66.249.66.64:39952] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:17.257348 2026] [authz_core:error] [pid 524122:tid 524289] [client 66.249.66.67:54709] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:17.257729 2026] [authz_core:error] [pid 524122:tid 524289] [client 66.249.66.67:54709] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:17.288187 2026] [authz_core:error] [pid 524122:tid 524336] [client 216.73.216.128:48472] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:17.288502 2026] [authz_core:error] [pid 524122:tid 524336] [client 216.73.216.128:48472] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:17.292424 2026] [authz_core:error] [pid 524122:tid 524297] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:17.292685 2026] [authz_core:error] [pid 524122:tid 524297] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:17.292707 2026] [security2:error] [pid 524122:tid 524318] [client 20.48.251.3:46149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/services.php"] [unique_id "apPmHX3lhEjKFiK_nBKKOAAAAdA"]
[Sun Aug 30 03:13:17.302355 2026] [security2:error] [pid 524122:tid 524270] [client 158.23.147.79:59045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "apPmHX3lhEjKFiK_nBKKOQAAAaA"]
[Sun Aug 30 03:13:17.313878 2026] [core:error] [pid 524122:tid 524312] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:17.313894 2026] [core:error] [pid 524122:tid 524312] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:17.368945 2026] [security2:error] [pid 524122:tid 524371] [client 20.104.49.130:60739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/bdroot.php"] [unique_id "apPmHX3lhEjKFiK_nBKKPgAAAgU"]
[Sun Aug 30 03:13:17.370708 2026] [security2:error] [pid 524122:tid 524308] [client 20.220.10.235:48684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/h02ugyh.php"] [unique_id "apPmHX3lhEjKFiK_nBKKPwAAAcY"]
[Sun Aug 30 03:13:17.372984 2026] [security2:error] [pid 524122:tid 524325] [client 20.151.200.44:44004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ermes-it.it"] [uri "/sxxb.php"] [unique_id "apPmHX3lhEjKFiK_nBKKQAAAAdc"]
[Sun Aug 30 03:13:17.431470 2026] [security2:error] [pid 524122:tid 524291] [client 20.197.61.180:15375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/en.php"] [unique_id "apPmHX3lhEjKFiK_nBKKSAAAAbU"]
[Sun Aug 30 03:13:17.435489 2026] [security2:error] [pid 524122:tid 524313] [client 20.104.50.220:31506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/byp.php"] [unique_id "apPmHX3lhEjKFiK_nBKKSQAAAcs"]
[Sun Aug 30 03:13:17.468947 2026] [security2:error] [pid 524122:tid 524287] [client 52.139.37.240:49720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-content/admin.php"] [unique_id "apPmHX3lhEjKFiK_nBKKSwAAAbE"]
[Sun Aug 30 03:13:17.489812 2026] [security2:error] [pid 524122:tid 524326] [client 20.151.200.44:23581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/admin.php/007x.php"] [unique_id "apPmHX3lhEjKFiK_nBKKTQAAAdg"]
[Sun Aug 30 03:13:17.501868 2026] [authz_core:error] [pid 524122:tid 524358] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory4
[Sun Aug 30 03:13:17.502114 2026] [authz_core:error] [pid 524122:tid 524358] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory4
[Sun Aug 30 03:13:17.502802 2026] [security2:error] [pid 524122:tid 524360] [client 20.220.10.235:48644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/sf.php"] [unique_id "apPmHX3lhEjKFiK_nBKKTwAAAfo"]
[Sun Aug 30 03:13:17.532906 2026] [security2:error] [pid 524122:tid 524254] [client 20.104.49.130:53597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/ws58.php"] [unique_id "apPmHX3lhEjKFiK_nBKKUgAAAZA"]
[Sun Aug 30 03:13:17.537873 2026] [security2:error] [pid 524122:tid 524346] [client 20.48.251.3:36887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/sdsa.php"] [unique_id "apPmHX3lhEjKFiK_nBKKUwAAAew"]
[Sun Aug 30 03:13:17.560893 2026] [authz_core:error] [pid 524122:tid 524378] [client 216.73.216.128:48472] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:17.561148 2026] [authz_core:error] [pid 524122:tid 524378] [client 216.73.216.128:48472] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:17.571455 2026] [security2:error] [pid 524122:tid 524359] [client 20.104.50.220:52845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/and.php"] [unique_id "apPmHX3lhEjKFiK_nBKKXAAAAfk"]
[Sun Aug 30 03:13:17.583947 2026] [core:error] [pid 524122:tid 524258] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:17.583966 2026] [core:error] [pid 524122:tid 524258] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:17.621536 2026] [security2:error] [pid 524122:tid 524294] [client 20.104.50.220:16576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/.well-known/56.php"] [unique_id "apPmHX3lhEjKFiK_nBKKYQAAAbg"]
[Sun Aug 30 03:13:17.629907 2026] [security2:error] [pid 524122:tid 524296] [client 20.220.10.235:48660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/4e.php"] [unique_id "apPmHX3lhEjKFiK_nBKKYgAAAbo"]
[Sun Aug 30 03:13:17.634826 2026] [security2:error] [pid 524122:tid 524310] [client 20.197.61.180:13167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "a220training.com"] [uri "/wp-content/themes/login.php"] [unique_id "apPmHX3lhEjKFiK_nBKKYwAAAcg"]
[Sun Aug 30 03:13:17.685859 2026] [security2:error] [pid 524122:tid 524271] [client 20.197.61.180:11733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "demandthetruth.michaelegenolf.com"] [uri "/wp-content/themes/hideo/network.php"] [unique_id "apPmHX3lhEjKFiK_nBKKZwAAAaE"]
[Sun Aug 30 03:13:17.688404 2026] [security2:error] [pid 524122:tid 524263] [client 185.93.89.167:64855] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images7.mariegronley.com"] [uri "/.env"] [unique_id "apPmHX3lhEjKFiK_nBKKaAAAAZk"]
[Sun Aug 30 03:13:17.717050 2026] [security2:error] [pid 524122:tid 524255] [client 20.104.50.220:24894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/cgi-bin/admin.php"] [unique_id "apPmHX3lhEjKFiK_nBKKaQAAAZE"]
[Sun Aug 30 03:13:17.726702 2026] [security2:error] [pid 524122:tid 524333] [client 52.139.37.240:9499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-load.php"] [unique_id "apPmHX3lhEjKFiK_nBKKagAAAd8"]
[Sun Aug 30 03:13:17.759131 2026] [security2:error] [pid 524122:tid 524277] [client 20.220.10.235:48877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/ssss.php"] [unique_id "apPmHX3lhEjKFiK_nBKKbAAAAac"]
[Sun Aug 30 03:13:17.774330 2026] [security2:error] [pid 524122:tid 524347] [client 68.155.159.216:60342] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mymediaworkscompany.com"] [uri "/1.php"] [unique_id "apPmHX3lhEjKFiK_nBKKbQAAAe0"]
[Sun Aug 30 03:13:17.774435 2026] [security2:error] [pid 524122:tid 524347] [client 68.155.159.216:60342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/1.php"] [unique_id "apPmHX3lhEjKFiK_nBKKbQAAAe0"]
[Sun Aug 30 03:13:17.775297 2026] [security2:error] [pid 524122:tid 524370] [client 20.104.50.220:33292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/kk.php"] [unique_id "apPmHX3lhEjKFiK_nBKKbgAAAgQ"]
[Sun Aug 30 03:13:17.783258 2026] [authz_core:error] [pid 524122:tid 524305] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:17.783505 2026] [authz_core:error] [pid 524122:tid 524305] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:17.796114 2026] [security2:error] [pid 524122:tid 524318] [client 4.205.62.107:32029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/config_dev.php"] [unique_id "apPmHX3lhEjKFiK_nBKKcAAAAdA"]
[Sun Aug 30 03:13:17.810149 2026] [security2:error] [pid 524122:tid 524261] [client 158.23.147.79:55361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/images/index.php"] [unique_id "apPmHX3lhEjKFiK_nBKKcwAAAZc"]
[Sun Aug 30 03:13:17.815908 2026] [security2:error] [pid 524122:tid 524282] [client 4.205.62.107:17123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fcconveyancing.com.au"] [uri "/min.php"] [unique_id "apPmHX3lhEjKFiK_nBKKdAAAAaw"]
[Sun Aug 30 03:13:17.822676 2026] [security2:error] [pid 524122:tid 524314] [client 185.93.89.167:64855] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images7.mariegronley.com"] [uri "/api/.env"] [unique_id "apPmHX3lhEjKFiK_nBKKdQAAAcw"]
[Sun Aug 30 03:13:17.822858 2026] [security2:error] [pid 524122:tid 524340] [client 20.104.50.220:5518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/v.php"] [unique_id "apPmHX3lhEjKFiK_nBKKdgAAAeY"]
[Sun Aug 30 03:13:17.868667 2026] [security2:error] [pid 524122:tid 524371] [client 4.205.62.107:52905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/gk.php"] [unique_id "apPmHX3lhEjKFiK_nBKKewAAAgU"]
[Sun Aug 30 03:13:17.871731 2026] [security2:error] [pid 524122:tid 524325] [client 20.151.200.44:52104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/ft.php"] [unique_id "apPmHX3lhEjKFiK_nBKKfAAAAdc"]
[Sun Aug 30 03:13:17.882958 2026] [core:alert] [pid 524122:tid 524279] [client 105.74.74.128:0] /home3/lordrcan/public_html/.htaccess: without matching section
[Sun Aug 30 03:13:17.886627 2026] [security2:error] [pid 524122:tid 524291] [client 20.220.10.235:48832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/zoz.php"] [unique_id "apPmHX3lhEjKFiK_nBKKgQAAAbU"]
[Sun Aug 30 03:13:17.888546 2026] [security2:error] [pid 524122:tid 524313] [client 158.23.147.79:61719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/.well-known/index.php"] [unique_id "apPmHX3lhEjKFiK_nBKKggAAAcs"]
[Sun Aug 30 03:13:17.937070 2026] [security2:error] [pid 524122:tid 524332] [client 185.93.89.167:9313] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/.env"] [unique_id "apPmHX3lhEjKFiK_nBKKiwAAAd4"]
[Sun Aug 30 03:13:17.953845 2026] [core:error] [pid 524122:tid 524317] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:17.953872 2026] [core:error] [pid 524122:tid 524317] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:17.955995 2026] [security2:error] [pid 524122:tid 524258] [client 185.93.89.167:64855] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images7.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPmHX3lhEjKFiK_nBKKjwAAAZQ"]
[Sun Aug 30 03:13:17.959213 2026] [security2:error] [pid 524122:tid 524295] [client 20.151.200.44:43928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ermes-it.it"] [uri "/dx.php"] [unique_id "apPmHX3lhEjKFiK_nBKKkAAAAbk"]
[Sun Aug 30 03:13:17.966043 2026] [authz_core:error] [pid 524122:tid 524286] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory3
[Sun Aug 30 03:13:17.966470 2026] [authz_core:error] [pid 524122:tid 524286] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory3
[Sun Aug 30 03:13:17.991185 2026] [security2:error] [pid 524122:tid 524360] [client 52.139.37.240:9489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/as/function.php"] [unique_id "apPmHX3lhEjKFiK_nBKKkQAAAfo"]
[Sun Aug 30 03:13:18.002926 2026] [authz_core:error] [pid 524122:tid 524328] [client 66.249.66.74:36214] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:18.003192 2026] [authz_core:error] [pid 524122:tid 524328] [client 66.249.66.74:36214] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:18.009596 2026] [security2:error] [pid 524122:tid 524294] [client 20.104.50.220:61387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/admin.php"] [unique_id "apPmHn3lhEjKFiK_nBKKkwAAAbg"]
[Sun Aug 30 03:13:18.020603 2026] [security2:error] [pid 524122:tid 524335] [client 20.220.10.235:48833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/kcs.php"] [unique_id "apPmHn3lhEjKFiK_nBKKlgAAAeE"]
[Sun Aug 30 03:13:18.026762 2026] [security2:error] [pid 524122:tid 524300] [client 185.93.89.167:50907] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/.env"] [unique_id "apPmHn3lhEjKFiK_nBKKlwAAAb4"]
[Sun Aug 30 03:13:18.064735 2026] [security2:error] [pid 524122:tid 524304] [client 20.104.49.130:48326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/red.php"] [unique_id "apPmHn3lhEjKFiK_nBKKmQAAAcI"]
[Sun Aug 30 03:13:18.071663 2026] [security2:error] [pid 524122:tid 524319] [client 185.93.89.167:9313] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/api/.env"] [unique_id "apPmHn3lhEjKFiK_nBKKmgAAAdE"]
[Sun Aug 30 03:13:18.089338 2026] [security2:error] [pid 524122:tid 524267] [client 185.93.89.167:64855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images7.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPmHn3lhEjKFiK_nBKKmwAAAZ0"]
[Sun Aug 30 03:13:18.099994 2026] [security2:error] [pid 524122:tid 524372] [client 20.48.147.90:61653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/xmrlpc.php"] [unique_id "apPmHn3lhEjKFiK_nBKKnAAAAgY"]
[Sun Aug 30 03:13:18.105836 2026] [security2:error] [pid 524122:tid 524266] [client 4.205.62.107:16331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/phina.php"] [unique_id "apPmHn3lhEjKFiK_nBKKngAAAZw"]
[Sun Aug 30 03:13:18.134763 2026] [security2:error] [pid 524122:tid 524373] [client 20.197.61.180:1537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/13.php"] [unique_id "apPmHn3lhEjKFiK_nBKKoAAAAgc"]
[Sun Aug 30 03:13:18.153513 2026] [security2:error] [pid 524122:tid 524255] [client 4.205.62.107:16377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/rum.or.php"] [unique_id "apPmHn3lhEjKFiK_nBKKoQAAAZE"]
[Sun Aug 30 03:13:18.160509 2026] [security2:error] [pid 524122:tid 524367] [client 185.93.89.167:50907] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/api/.env"] [unique_id "apPmHn3lhEjKFiK_nBKKogAAAgE"]
[Sun Aug 30 03:13:18.179019 2026] [security2:error] [pid 524122:tid 524377] [client 20.220.10.235:48652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/tajj.php"] [unique_id "apPmHn3lhEjKFiK_nBKKpAAAAgs"]
[Sun Aug 30 03:13:18.199490 2026] [security2:error] [pid 524122:tid 524370] [client 216.73.216.128:4370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPmHn3lhEjKFiK_nBKKpwAAAgQ"]
[Sun Aug 30 03:13:18.205782 2026] [security2:error] [pid 524122:tid 524302] [client 185.93.89.167:9313] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPmHn3lhEjKFiK_nBKKqQAAAcA"]
[Sun Aug 30 03:13:18.218432 2026] [security2:error] [pid 524122:tid 524350] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/.env.swp"] [unique_id "apPmHn3lhEjKFiK_nBKKqgAAAfA"]
[Sun Aug 30 03:13:18.220531 2026] [security2:error] [pid 524122:tid 524318] [client 20.104.18.15:22430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/xc.php"] [unique_id "apPmHn3lhEjKFiK_nBKKqwAAAdA"]
[Sun Aug 30 03:13:18.237697 2026] [security2:error] [pid 524122:tid 524316] [client 52.139.37.240:9359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apPmHn3lhEjKFiK_nBKKrQAAAc4"]
[Sun Aug 30 03:13:18.238707 2026] [security2:error] [pid 524122:tid 524374] [client 34.106.227.237:52854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/.env.swp"] [unique_id "apPmHn3lhEjKFiK_nBKKrAAAAgg"]
[Sun Aug 30 03:13:18.241383 2026] [security2:error] [pid 524122:tid 524282] [client 185.93.89.167:20313] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/.env"] [unique_id "apPmHn3lhEjKFiK_nBKKrgAAAaw"]
[Sun Aug 30 03:13:18.248831 2026] [security2:error] [pid 524122:tid 524340] [client 20.48.147.90:64024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/wp-settings.php"] [unique_id "apPmHn3lhEjKFiK_nBKKsAAAAeY"]
[Sun Aug 30 03:13:18.248963 2026] [security2:error] [pid 524122:tid 524293] [client 20.104.50.220:42760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/idx.php"] [unique_id "apPmHn3lhEjKFiK_nBKKsQAAAbc"]
[Sun Aug 30 03:13:18.255080 2026] [authz_core:error] [pid 524122:tid 524314] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:18.255491 2026] [authz_core:error] [pid 524122:tid 524314] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:18.258835 2026] [security2:error] [pid 524122:tid 524259] [client 20.104.50.220:62800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/s3c.php"] [unique_id "apPmHn3lhEjKFiK_nBKKtAAAAZU"]
[Sun Aug 30 03:13:18.292296 2026] [security2:error] [pid 524122:tid 524330] [client 20.104.18.15:51093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/dapa.php"] [unique_id "apPmHn3lhEjKFiK_nBKKtgAAAdw"]
[Sun Aug 30 03:13:18.293804 2026] [security2:error] [pid 524122:tid 524375] [client 185.93.89.167:50907] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPmHn3lhEjKFiK_nBKKuAAAAgk"]
[Sun Aug 30 03:13:18.310313 2026] [security2:error] [pid 524122:tid 524323] [client 20.220.10.235:48657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/bge.php"] [unique_id "apPmHn3lhEjKFiK_nBKKuwAAAdU"]
[Sun Aug 30 03:13:18.310929 2026] [authz_core:error] [pid 524122:tid 524371] [client 66.249.66.78:44699] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:18.311189 2026] [authz_core:error] [pid 524122:tid 524371] [client 66.249.66.78:44699] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:18.338030 2026] [security2:error] [pid 524122:tid 524331] [client 34.106.227.237:52854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/.env~"] [unique_id "apPmHn3lhEjKFiK_nBKKvAAAAd0"]
[Sun Aug 30 03:13:18.339223 2026] [security2:error] [pid 524122:tid 524279] [client 185.93.89.167:9313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "forms.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPmHn3lhEjKFiK_nBKKvQAAAak"]
[Sun Aug 30 03:13:18.354445 2026] [security2:error] [pid 524122:tid 524379] [client 20.197.61.180:13176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "a220training.com"] [uri "/wp-content/themes/min.php"] [unique_id "apPmHn3lhEjKFiK_nBKKvgAAAg0"]
[Sun Aug 30 03:13:18.364203 2026] [security2:error] [pid 524122:tid 524376] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/.env~"] [unique_id "apPmHn3lhEjKFiK_nBKKwQAAAgo"]
[Sun Aug 30 03:13:18.374942 2026] [security2:error] [pid 524122:tid 524339] [client 185.93.89.167:20313] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/api/.env"] [unique_id "apPmHn3lhEjKFiK_nBKKwwAAAeU"]
[Sun Aug 30 03:13:18.385712 2026] [security2:error] [pid 524122:tid 524298] [client 20.48.147.90:61661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/kon.php"] [unique_id "apPmHn3lhEjKFiK_nBKKxAAAAbw"]
[Sun Aug 30 03:13:18.395059 2026] [security2:error] [pid 524122:tid 524305] [client 185.93.89.167:29837] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/.env"] [unique_id "apPmHn3lhEjKFiK_nBKKxwAAAcM"]
[Sun Aug 30 03:13:18.406439 2026] [security2:error] [pid 524122:tid 524333] [client 20.197.61.180:20837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "demandthetruth.michaelegenolf.com"] [uri "/wp-content/themes/index.php"] [unique_id "apPmHn3lhEjKFiK_nBKKyQAAAd8"]
[Sun Aug 30 03:13:18.426545 2026] [security2:error] [pid 524122:tid 524269] [client 185.93.89.167:50907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m1.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPmHn3lhEjKFiK_nBKKywAAAZ8"]
[Sun Aug 30 03:13:18.429684 2026] [security2:error] [pid 524122:tid 524254] [client 20.48.251.3:46236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/filesystems.php"] [unique_id "apPmHn3lhEjKFiK_nBKKzAAAAZA"]
[Sun Aug 30 03:13:18.436984 2026] [security2:error] [pid 524122:tid 524346] [client 20.220.10.235:48656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/ssh3ll.php"] [unique_id "apPmHn3lhEjKFiK_nBKKzQAAAew"]
[Sun Aug 30 03:13:18.450978 2026] [core:error] [pid 524122:tid 524357] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:18.450998 2026] [core:error] [pid 524122:tid 524357] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:18.467114 2026] [security2:error] [pid 524122:tid 524258] [client 20.104.49.130:34552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alarm-monitoring.net"] [uri "/btyuio.php"] [unique_id "apPmHn3lhEjKFiK_nBKK0AAAAZQ"]
[Sun Aug 30 03:13:18.468212 2026] [authz_core:error] [pid 524122:tid 524317] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory8
[Sun Aug 30 03:13:18.468474 2026] [authz_core:error] [pid 524122:tid 524317] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory8
[Sun Aug 30 03:13:18.481832 2026] [security2:error] [pid 524122:tid 524356] [client 52.139.37.240:9507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/atomlib.php"] [unique_id "apPmHn3lhEjKFiK_nBKK0gAAAfY"]
[Sun Aug 30 03:13:18.484866 2026] [security2:error] [pid 524122:tid 524253] [client 216.73.216.128:49424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPmHn3lhEjKFiK_nBKK0wAAAY8"]
[Sun Aug 30 03:13:18.509043 2026] [security2:error] [pid 524122:tid 524324] [client 185.93.89.167:20313] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPmHn3lhEjKFiK_nBKK1AAAAdY"]
[Sun Aug 30 03:13:18.528384 2026] [security2:error] [pid 524122:tid 524355] [client 20.48.147.90:61686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/kontol.php"] [unique_id "apPmHn3lhEjKFiK_nBKK1wAAAfU"]
[Sun Aug 30 03:13:18.528969 2026] [security2:error] [pid 524122:tid 524335] [client 185.93.89.167:29837] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/api/.env"] [unique_id "apPmHn3lhEjKFiK_nBKK1gAAAeE"]
[Sun Aug 30 03:13:18.565487 2026] [security2:error] [pid 524122:tid 524271] [client 20.220.10.235:48699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/motu.php"] [unique_id "apPmHn3lhEjKFiK_nBKK4QAAAaE"]
[Sun Aug 30 03:13:18.577956 2026] [security2:error] [pid 524122:tid 524266] [client 20.104.50.220:30923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-trackback.php"] [unique_id "apPmHn3lhEjKFiK_nBKK4wAAAZw"]
[Sun Aug 30 03:13:18.579106 2026] [security2:error] [pid 524122:tid 524276] [client 158.23.147.79:55370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-includes/widgets/index.php"] [unique_id "apPmHn3lhEjKFiK_nBKK5AAAAaY"]
[Sun Aug 30 03:13:18.588520 2026] [security2:error] [pid 524122:tid 524289] [client 20.151.200.44:52103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/wp-ver.php"] [unique_id "apPmHn3lhEjKFiK_nBKK5QAAAbM"]
[Sun Aug 30 03:13:18.612031 2026] [security2:error] [pid 524122:tid 524367] [client 185.93.89.167:32483] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/.env"] [unique_id "apPmHn3lhEjKFiK_nBKK6AAAAgE"]
[Sun Aug 30 03:13:18.642110 2026] [security2:error] [pid 524122:tid 524270] [client 185.93.89.167:20313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "otrs.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPmHn3lhEjKFiK_nBKK7gAAAaA"]
[Sun Aug 30 03:13:18.662684 2026] [security2:error] [pid 524122:tid 524259] [client 185.93.89.167:29837] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPmHn3lhEjKFiK_nBKK8QAAAZU"]
[Sun Aug 30 03:13:18.669027 2026] [security2:error] [pid 524122:tid 524345] [client 20.48.251.3:37183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/sale.php"] [unique_id "apPmHn3lhEjKFiK_nBKK9AAAAes"]
[Sun Aug 30 03:13:18.688388 2026] [security2:error] [pid 524122:tid 524330] [client 20.48.147.90:45277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/wp.php"] [unique_id "apPmHn3lhEjKFiK_nBKK9gAAAdw"]
[Sun Aug 30 03:13:18.693251 2026] [security2:error] [pid 524122:tid 524375] [client 20.220.10.235:48661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/wefile.php"] [unique_id "apPmHn3lhEjKFiK_nBKK-AAAAgk"]
[Sun Aug 30 03:13:18.718134 2026] [security2:error] [pid 524122:tid 524348] [client 20.104.50.220:52827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/skizoo.php"] [unique_id "apPmHn3lhEjKFiK_nBKK-wAAAe4"]
[Sun Aug 30 03:13:18.737351 2026] [security2:error] [pid 524122:tid 524325] [client 20.104.49.130:63604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wdfjba.org"] [uri "/100.php"] [unique_id "apPmHn3lhEjKFiK_nBKK_AAAAdc"]
[Sun Aug 30 03:13:18.746684 2026] [security2:error] [pid 524122:tid 524297] [client 185.93.89.167:32483] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/api/.env"] [unique_id "apPmHn3lhEjKFiK_nBKK_gAAAbs"]
[Sun Aug 30 03:13:18.755179 2026] [security2:error] [pid 524122:tid 524368] [client 52.139.37.240:53254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "apPmHn3lhEjKFiK_nBKLAQAAAgI"]
[Sun Aug 30 03:13:18.758922 2026] [security2:error] [pid 524122:tid 524379] [client 20.104.50.220:16631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/.well-known/55.php"] [unique_id "apPmHn3lhEjKFiK_nBKLAgAAAg0"]
[Sun Aug 30 03:13:18.764386 2026] [security2:error] [pid 524122:tid 524281] [client 185.93.89.167:37325] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/.env"] [unique_id "apPmHn3lhEjKFiK_nBKLAwAAAas"]
[Sun Aug 30 03:13:18.782872 2026] [authz_core:error] [pid 524122:tid 524376] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:18.783236 2026] [authz_core:error] [pid 524122:tid 524376] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:18.796226 2026] [security2:error] [pid 524122:tid 524298] [client 185.93.89.167:29837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kb.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPmHn3lhEjKFiK_nBKLCAAAAbw"]
[Sun Aug 30 03:13:18.813734 2026] [authz_core:error] [pid 524122:tid 524336] [client 216.73.216.128:2854] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:18.813987 2026] [authz_core:error] [pid 524122:tid 524336] [client 216.73.216.128:2854] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:18.820079 2026] [security2:error] [pid 524122:tid 524333] [client 185.93.89.167:55699] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tr.mariegronley.com"] [uri "/.env"] [unique_id "apPmHn3lhEjKFiK_nBKLDQAAAd8"]
[Sun Aug 30 03:13:18.825159 2026] [security2:error] [pid 524122:tid 524269] [client 20.220.10.235:48682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/Contrller.php"] [unique_id "apPmHn3lhEjKFiK_nBKLDgAAAZ8"]
[Sun Aug 30 03:13:18.833977 2026] [core:error] [pid 524122:tid 524346] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:18.833994 2026] [core:error] [pid 524122:tid 524346] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:18.839170 2026] [authz_core:error] [pid 524122:tid 524332] [client 66.249.66.38:64509] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:18.839424 2026] [authz_core:error] [pid 524122:tid 524332] [client 66.249.66.38:64509] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:18.844125 2026] [security2:error] [pid 524122:tid 524359] [client 185.93.89.167:25101] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns12.mariegronley.com"] [uri "/.env"] [unique_id "apPmHn3lhEjKFiK_nBKLEwAAAfk"]
[Sun Aug 30 03:13:18.855257 2026] [security2:error] [pid 524122:tid 524315] [client 216.73.216.128:48472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPmHn3lhEjKFiK_nBKLFQAAAc0"]
[Sun Aug 30 03:13:18.877458 2026] [security2:error] [pid 524122:tid 524328] [client 185.93.89.167:33503] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPmHn3lhEjKFiK_nBKLGQAAAdo"]
[Sun Aug 30 03:13:18.880369 2026] [security2:error] [pid 524122:tid 524295] [client 68.155.159.216:60961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/ws.php"] [unique_id "apPmHn3lhEjKFiK_nBKLGgAAAbk"]
[Sun Aug 30 03:13:18.881293 2026] [security2:error] [pid 524122:tid 524256] [client 185.93.89.167:32483] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPmHn3lhEjKFiK_nBKLGwAAAZI"]
[Sun Aug 30 03:13:18.883386 2026] [security2:error] [pid 524122:tid 524261] [client 20.197.61.180:16009] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "petworthcs.com"] [uri "/1.php"] [unique_id "apPmHn3lhEjKFiK_nBKLHQAAAZc"]
[Sun Aug 30 03:13:18.883469 2026] [security2:error] [pid 524122:tid 524261] [client 20.197.61.180:16009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/1.php"] [unique_id "apPmHn3lhEjKFiK_nBKLHQAAAZc"]
[Sun Aug 30 03:13:18.883976 2026] [security2:error] [pid 524122:tid 524353] [client 20.104.50.220:24923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/gettest.php"] [unique_id "apPmHn3lhEjKFiK_nBKLHgAAAfM"]
[Sun Aug 30 03:13:18.890710 2026] [security2:error] [pid 524122:tid 524324] [client 158.23.147.79:61764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/themes/too.php"] [unique_id "apPmHn3lhEjKFiK_nBKLHwAAAdY"]
[Sun Aug 30 03:13:18.899199 2026] [security2:error] [pid 524122:tid 524355] [client 185.93.89.167:37325] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/api/.env"] [unique_id "apPmHn3lhEjKFiK_nBKLIQAAAfU"]
[Sun Aug 30 03:13:18.914636 2026] [security2:error] [pid 524122:tid 524311] [client 20.104.50.220:32854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/kndw1.php"] [unique_id "apPmHn3lhEjKFiK_nBKLIwAAAck"]
[Sun Aug 30 03:13:18.942213 2026] [security2:error] [pid 524122:tid 524358] [client 185.93.89.167:3043] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/.env"] [unique_id "apPmHn3lhEjKFiK_nBKLJAAAAfg"]
[Sun Aug 30 03:13:18.946660 2026] [security2:error] [pid 524122:tid 524301] [client 216.73.216.128:36316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/sasl/developer/testing.html"] [unique_id "apPmHn3lhEjKFiK_nBKLJQAAAb8"]
[Sun Aug 30 03:13:18.949490 2026] [security2:error] [pid 524122:tid 524362] [client 4.205.62.107:32485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/aws_credentials.php"] [unique_id "apPmHn3lhEjKFiK_nBKLJgAAAfw"]
[Sun Aug 30 03:13:18.953992 2026] [security2:error] [pid 524122:tid 524306] [client 185.93.89.167:55699] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tr.mariegronley.com"] [uri "/api/.env"] [unique_id "apPmHn3lhEjKFiK_nBKLJwAAAcQ"]
[Sun Aug 30 03:13:18.955322 2026] [security2:error] [pid 524122:tid 524304] [client 4.205.62.107:17300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fcconveyancing.com.au"] [uri "/saiga.php"] [unique_id "apPmHn3lhEjKFiK_nBKLKAAAAcI"]
[Sun Aug 30 03:13:18.956716 2026] [security2:error] [pid 524122:tid 524372] [client 20.104.50.220:6085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/u.php"] [unique_id "apPmHn3lhEjKFiK_nBKLKQAAAgY"]
[Sun Aug 30 03:13:18.958014 2026] [security2:error] [pid 524122:tid 524343] [client 20.220.10.235:48840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/file66.php"] [unique_id "apPmHn3lhEjKFiK_nBKLKgAAAek"]
[Sun Aug 30 03:13:18.963576 2026] [security2:error] [pid 524122:tid 524276] [client 185.93.89.167:25489] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPmHn3lhEjKFiK_nBKLLAAAAaY"]
[Sun Aug 30 03:13:18.964346 2026] [authz_core:error] [pid 524122:tid 524271] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory6
[Sun Aug 30 03:13:18.964592 2026] [authz_core:error] [pid 524122:tid 524271] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory6
[Sun Aug 30 03:13:18.973924 2026] [security2:error] [pid 524122:tid 524289] [client 20.48.147.90:61587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/readme.php"] [unique_id "apPmHn3lhEjKFiK_nBKLLQAAAbM"]
[Sun Aug 30 03:13:18.977639 2026] [security2:error] [pid 524122:tid 524255] [client 185.93.89.167:25101] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns12.mariegronley.com"] [uri "/api/.env"] [unique_id "apPmHn3lhEjKFiK_nBKLLwAAAZE"]
[Sun Aug 30 03:13:18.977725 2026] [security2:error] [pid 524122:tid 524307] [client 52.139.37.240:46966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-content/plugins/revslider/includes/external/page/index.php"] [unique_id "apPmHn3lhEjKFiK_nBKLLgAAAcU"]
[Sun Aug 30 03:13:19.000512 2026] [security2:error] [pid 524122:tid 524370] [client 20.104.49.130:57619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alarm-monitoring.net"] [uri "/xa.php"] [unique_id "apPmHn3lhEjKFiK_nBKLMAAAAgQ"]
[Sun Aug 30 03:13:19.011152 2026] [security2:error] [pid 524122:tid 524365] [client 185.93.89.167:33503] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/core/.env"] [unique_id "apPmH33lhEjKFiK_nBKLMgAAAf8"]
[Sun Aug 30 03:13:19.016018 2026] [security2:error] [pid 524122:tid 524350] [client 185.93.89.167:32483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "web01.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPmH33lhEjKFiK_nBKLMwAAAfA"]
[Sun Aug 30 03:13:19.034662 2026] [security2:error] [pid 524122:tid 524374] [client 185.93.89.167:37325] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPmH33lhEjKFiK_nBKLNQAAAgg"]
[Sun Aug 30 03:13:19.039353 2026] [security2:error] [pid 524122:tid 524268] [client 20.151.200.44:63628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/admin.php/heex.php"] [unique_id "apPmH33lhEjKFiK_nBKLNwAAAZ4"]
[Sun Aug 30 03:13:19.055211 2026] [security2:error] [pid 524122:tid 524352] [client 4.205.62.107:52857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/god.php"] [unique_id "apPmH33lhEjKFiK_nBKLOQAAAfI"]
[Sun Aug 30 03:13:19.073058 2026] [security2:error] [pid 524122:tid 524290] [client 20.197.61.180:8413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "a220training.com"] [uri "/wp-content/themes/module.php"] [unique_id "apPmH33lhEjKFiK_nBKLPQAAAbQ"]
[Sun Aug 30 03:13:19.075599 2026] [security2:error] [pid 524122:tid 524272] [client 185.93.89.167:3043] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/api/.env"] [unique_id "apPmH33lhEjKFiK_nBKLPgAAAaI"]
[Sun Aug 30 03:13:19.087927 2026] [security2:error] [pid 524122:tid 524285] [client 185.93.89.167:55699] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tr.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPmH33lhEjKFiK_nBKLQAAAAa8"]
[Sun Aug 30 03:13:19.092009 2026] [security2:error] [pid 524122:tid 524348] [client 20.220.10.235:48658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/blnux.php"] [unique_id "apPmH33lhEjKFiK_nBKLQQAAAe4"]
[Sun Aug 30 03:13:19.097366 2026] [security2:error] [pid 524122:tid 524283] [client 185.93.89.167:25489] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/core/.env"] [unique_id "apPmH33lhEjKFiK_nBKLQgAAAa0"]
[Sun Aug 30 03:13:19.111034 2026] [security2:error] [pid 524122:tid 524325] [client 185.93.89.167:25101] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns12.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPmH33lhEjKFiK_nBKLRAAAAdc"]
[Sun Aug 30 03:13:19.129427 2026] [security2:error] [pid 524122:tid 524284] [client 20.197.61.180:20800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "demandthetruth.michaelegenolf.com"] [uri "/wp-content/themes/intense/block-css.php"] [unique_id "apPmH33lhEjKFiK_nBKLRQAAAa4"]
[Sun Aug 30 03:13:19.137746 2026] [security2:error] [pid 524122:tid 524299] [client 114.119.157.218:62601] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "eseperu.com"] [uri "/"] [unique_id "apPmH33lhEjKFiK_nBKLRgAAAb0"], referer: https://eseperu.com/
[Sun Aug 30 03:13:19.145611 2026] [security2:error] [pid 524122:tid 524337] [client 185.93.89.167:49509] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/.env"] [unique_id "apPmH33lhEjKFiK_nBKLSAAAAeM"]
[Sun Aug 30 03:13:19.160026 2026] [security2:error] [pid 524122:tid 524326] [client 20.104.50.220:61428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.richardmudzingwa.com.maarifado.com"] [uri "/lv.php"] [unique_id "apPmH33lhEjKFiK_nBKLSQAAAdg"]
[Sun Aug 30 03:13:19.168928 2026] [security2:error] [pid 524122:tid 524347] [client 185.93.89.167:37325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digital.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPmH33lhEjKFiK_nBKLSgAAAe0"]
[Sun Aug 30 03:13:19.183320 2026] [security2:error] [pid 524122:tid 524346] [client 216.73.216.128:21037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPmH33lhEjKFiK_nBKLTQAAAew"]
[Sun Aug 30 03:13:19.183426 2026] [security2:error] [pid 524122:tid 524357] [client 185.93.89.167:58165] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPmH33lhEjKFiK_nBKLSwAAAfc"]
[Sun Aug 30 03:13:19.195015 2026] [security2:error] [pid 524122:tid 524258] [client 185.93.89.167:39955] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/.env"] [unique_id "apPmH33lhEjKFiK_nBKLTwAAAZQ"]
[Sun Aug 30 03:13:19.204909 2026] [security2:error] [pid 524122:tid 524292] [client 20.48.147.90:61690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/error_log.php"] [unique_id "apPmH33lhEjKFiK_nBKLUwAAAbY"]
[Sun Aug 30 03:13:19.209046 2026] [security2:error] [pid 524122:tid 524328] [client 185.93.89.167:3043] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPmH33lhEjKFiK_nBKLVQAAAdo"]
[Sun Aug 30 03:13:19.212083 2026] [authz_core:error] [pid 524122:tid 524356] [client 66.249.66.33:53506] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:19.212363 2026] [authz_core:error] [pid 524122:tid 524356] [client 66.249.66.33:53506] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:19.219951 2026] [security2:error] [pid 524122:tid 524295] [client 216.73.216.128:2854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPmH33lhEjKFiK_nBKLVgAAAbk"]
[Sun Aug 30 03:13:19.220912 2026] [security2:error] [pid 524122:tid 524256] [client 185.93.89.167:55699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tr.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPmH33lhEjKFiK_nBKLWAAAAZI"]
[Sun Aug 30 03:13:19.239062 2026] [core:error] [pid 524122:tid 524313] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:19.239084 2026] [core:error] [pid 524122:tid 524313] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:19.244126 2026] [security2:error] [pid 524122:tid 524310] [client 185.93.89.167:25101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns12.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPmH33lhEjKFiK_nBKLXQAAAcg"]
[Sun Aug 30 03:13:19.244253 2026] [security2:error] [pid 524122:tid 524335] [client 4.205.62.107:15823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/koiy.php"] [unique_id "apPmH33lhEjKFiK_nBKLXgAAAeE"]
[Sun Aug 30 03:13:19.244499 2026] [security2:error] [pid 524122:tid 524269] [client 52.139.37.240:46934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-mail.php"] [unique_id "apPmH33lhEjKFiK_nBKLXwAAAZ8"]
[Sun Aug 30 03:13:19.245057 2026] [authz_core:error] [pid 524122:tid 524380] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:19.245318 2026] [authz_core:error] [pid 524122:tid 524380] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:19.255066 2026] [security2:error] [pid 524122:tid 524319] [client 20.220.10.235:48641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/attack.php"] [unique_id "apPmH33lhEjKFiK_nBKLYAAAAdE"]
[Sun Aug 30 03:13:19.280215 2026] [security2:error] [pid 524122:tid 524306] [client 185.93.89.167:49509] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/api/.env"] [unique_id "apPmH33lhEjKFiK_nBKLYQAAAcQ"]
[Sun Aug 30 03:13:19.291104 2026] [security2:error] [pid 524122:tid 524372] [client 4.205.62.107:16358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/xmy.php"] [unique_id "apPmH33lhEjKFiK_nBKLYwAAAgY"]
[Sun Aug 30 03:13:19.324924 2026] [security2:error] [pid 524122:tid 524309] [client 185.93.89.167:58165] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/core/.env"] [unique_id "apPmH33lhEjKFiK_nBKLZgAAAcc"]
[Sun Aug 30 03:13:19.328146 2026] [security2:error] [pid 524122:tid 524280] [client 185.93.89.167:39955] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/api/.env"] [unique_id "apPmH33lhEjKFiK_nBKLaAAAAao"]
[Sun Aug 30 03:13:19.336033 2026] [security2:error] [pid 524122:tid 524377] [client 185.93.89.167:64231] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPmH33lhEjKFiK_nBKLaQAAAgs"]
[Sun Aug 30 03:13:19.342244 2026] [security2:error] [pid 524122:tid 524365] [client 185.93.89.167:3043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images6.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPmH33lhEjKFiK_nBKLagAAAf8"]
[Sun Aug 30 03:13:19.358330 2026] [security2:error] [pid 524122:tid 524317] [client 20.104.18.15:22449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/wp-content/l.php"] [unique_id "apPmH33lhEjKFiK_nBKLawAAAc8"]
[Sun Aug 30 03:13:19.359982 2026] [security2:error] [pid 524122:tid 524270] [client 158.23.147.79:59025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "apPmH33lhEjKFiK_nBKLbAAAAaA"]
[Sun Aug 30 03:13:19.365886 2026] [authz_core:error] [pid 524122:tid 524374] [client 216.73.216.128:12249] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:19.366217 2026] [authz_core:error] [pid 524122:tid 524374] [client 216.73.216.128:12249] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:19.372451 2026] [security2:error] [pid 524122:tid 524322] [client 20.48.147.90:61640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/wp-admin.php"] [unique_id "apPmH33lhEjKFiK_nBKLbwAAAdQ"]
[Sun Aug 30 03:13:19.383253 2026] [security2:error] [pid 524122:tid 524300] [client 20.220.10.235:48663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/wk/index.php"] [unique_id "apPmH33lhEjKFiK_nBKLcQAAAb4"]
[Sun Aug 30 03:13:19.387180 2026] [security2:error] [pid 524122:tid 524352] [client 20.104.50.220:63493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/init.php"] [unique_id "apPmH33lhEjKFiK_nBKLcgAAAfI"]
[Sun Aug 30 03:13:19.414189 2026] [security2:error] [pid 524122:tid 524323] [client 20.104.50.220:28705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/madspotshell.php"] [unique_id "apPmH33lhEjKFiK_nBKLdgAAAdU"]
[Sun Aug 30 03:13:19.414534 2026] [security2:error] [pid 524122:tid 524375] [client 185.93.89.167:49509] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPmH33lhEjKFiK_nBKLdQAAAgk"]
[Sun Aug 30 03:13:19.415594 2026] [security2:error] [pid 524122:tid 524290] [client 185.93.89.167:33503] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/app/.env"] [unique_id "apPmH33lhEjKFiK_nBKLdwAAAbQ"]
[Sun Aug 30 03:13:19.421770 2026] [security2:error] [pid 524122:tid 524272] [client 20.104.18.15:51130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/wp-content/l.php"] [unique_id "apPmH33lhEjKFiK_nBKLeAAAAaI"]
[Sun Aug 30 03:13:19.430038 2026] [security2:error] [pid 524122:tid 524285] [client 185.93.89.167:30307] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images7.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPmH33lhEjKFiK_nBKLeQAAAa8"]
[Sun Aug 30 03:13:19.446128 2026] [security2:error] [pid 524122:tid 524321] [client 52.139.37.240:53233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/gebase.php"] [unique_id "apPmH33lhEjKFiK_nBKLfAAAAdM"]
[Sun Aug 30 03:13:19.459962 2026] [security2:error] [pid 524122:tid 524331] [client 185.93.89.167:39395] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/.env"] [unique_id "apPmH33lhEjKFiK_nBKLfgAAAd0"]
[Sun Aug 30 03:13:19.461636 2026] [security2:error] [pid 524122:tid 524368] [client 185.93.89.167:39955] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPmH33lhEjKFiK_nBKLfwAAAgI"]
[Sun Aug 30 03:13:19.469660 2026] [security2:error] [pid 524122:tid 524271] [client 185.93.89.167:64231] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/core/.env"] [unique_id "apPmH33lhEjKFiK_nBKLgQAAAaE"]
[Sun Aug 30 03:13:19.470497 2026] [authz_core:error] [pid 524122:tid 524341] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory7
[Sun Aug 30 03:13:19.470778 2026] [authz_core:error] [pid 524122:tid 524341] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory7
[Sun Aug 30 03:13:19.502979 2026] [security2:error] [pid 524122:tid 524346] [client 185.93.89.167:25489] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/app/.env"] [unique_id "apPmH33lhEjKFiK_nBKLhwAAAew"]
[Sun Aug 30 03:13:19.512786 2026] [security2:error] [pid 524122:tid 524258] [client 20.220.10.235:48645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/dehnl.php"] [unique_id "apPmH33lhEjKFiK_nBKLiQAAAZQ"]
[Sun Aug 30 03:13:19.548000 2026] [security2:error] [pid 524122:tid 524256] [client 185.93.89.167:49509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www7.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPmH33lhEjKFiK_nBKLjwAAAZI"]
[Sun Aug 30 03:13:19.549790 2026] [security2:error] [pid 524122:tid 524261] [client 185.93.89.167:33503] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPmH33lhEjKFiK_nBKLkAAAAZc"]
[Sun Aug 30 03:13:19.571594 2026] [core:error] [pid 524122:tid 524345] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:19.571619 2026] [core:error] [pid 524122:tid 524345] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:19.579855 2026] [security2:error] [pid 524122:tid 524269] [client 185.93.89.167:34059] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPmH33lhEjKFiK_nBKLlgAAAZ8"]
[Sun Aug 30 03:13:19.593938 2026] [security2:error] [pid 524122:tid 524366] [client 185.93.89.167:39395] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/api/.env"] [unique_id "apPmH33lhEjKFiK_nBKLmQAAAgA"]
[Sun Aug 30 03:13:19.594393 2026] [security2:error] [pid 524122:tid 524319] [client 185.93.89.167:39955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "analytics.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPmH33lhEjKFiK_nBKLmwAAAdE"]
[Sun Aug 30 03:13:19.594820 2026] [authz_core:error] [pid 524122:tid 524311] [client 216.73.216.128:12249] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:19.595286 2026] [authz_core:error] [pid 524122:tid 524311] [client 216.73.216.128:12249] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:19.620692 2026] [security2:error] [pid 524122:tid 524343] [client 158.23.147.79:52687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-includes/rest-api/index.php"] [unique_id "apPmH33lhEjKFiK_nBKLoQAAAek"]
[Sun Aug 30 03:13:19.636869 2026] [security2:error] [pid 524122:tid 524373] [client 185.93.89.167:25489] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPmH33lhEjKFiK_nBKLpAAAAgc"]
[Sun Aug 30 03:13:19.645204 2026] [security2:error] [pid 524122:tid 524255] [client 20.220.10.235:48702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/png.php"] [unique_id "apPmH33lhEjKFiK_nBKLpQAAAZE"]
[Sun Aug 30 03:13:19.645579 2026] [security2:error] [pid 524122:tid 524307] [client 20.48.251.3:46234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/tax.php"] [unique_id "apPmH33lhEjKFiK_nBKLpgAAAcU"]
[Sun Aug 30 03:13:19.653160 2026] [security2:error] [pid 524122:tid 524329] [client 20.197.61.180:14382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/as.php"] [unique_id "apPmH33lhEjKFiK_nBKLqQAAAds"]
[Sun Aug 30 03:13:19.667489 2026] [security2:error] [pid 524122:tid 524312] [client 185.93.89.167:26277] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/.env"] [unique_id "apPmH33lhEjKFiK_nBKLqgAAAco"]
[Sun Aug 30 03:13:19.679731 2026] [security2:error] [pid 524122:tid 524266] [client 20.48.147.90:64035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/wp-login.php"] [unique_id "apPmH33lhEjKFiK_nBKLowAAAZw"]
[Sun Aug 30 03:13:19.694519 2026] [security2:error] [pid 524122:tid 524304] [client 52.139.37.240:53265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/baxa1.php"] [unique_id "apPmH33lhEjKFiK_nBKLrQAAAcI"]
[Sun Aug 30 03:13:19.709579 2026] [security2:error] [pid 524122:tid 524340] [client 185.93.89.167:53189] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPmH33lhEjKFiK_nBKLrwAAAeY"]
[Sun Aug 30 03:13:19.720202 2026] [security2:error] [pid 524122:tid 524317] [client 185.93.89.167:34059] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/core/.env"] [unique_id "apPmH33lhEjKFiK_nBKLsQAAAc8"]
[Sun Aug 30 03:13:19.725564 2026] [authz_core:error] [pid 524122:tid 524320] [client 66.249.66.76:38879] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:19.725834 2026] [authz_core:error] [pid 524122:tid 524320] [client 66.249.66.76:38879] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:19.727693 2026] [security2:error] [pid 524122:tid 524268] [client 185.93.89.167:39395] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPmH33lhEjKFiK_nBKLsgAAAZ4"]
[Sun Aug 30 03:13:19.730928 2026] [security2:error] [pid 524122:tid 524322] [client 185.93.89.167:58165] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/app/.env"] [unique_id "apPmH33lhEjKFiK_nBKLtAAAAdQ"]
[Sun Aug 30 03:13:19.739819 2026] [security2:error] [pid 524122:tid 524300] [client 20.104.50.220:31523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/.well-known/index.php"] [unique_id "apPmH33lhEjKFiK_nBKLtwAAAb4"]
[Sun Aug 30 03:13:19.748084 2026] [authz_core:error] [pid 524122:tid 524316] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:19.748509 2026] [authz_core:error] [pid 524122:tid 524316] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:19.758487 2026] [security2:error] [pid 524122:tid 524330] [client 185.93.89.167:21991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tr.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPmH33lhEjKFiK_nBKLuQAAAdw"]
[Sun Aug 30 03:13:19.783724 2026] [security2:error] [pid 524122:tid 524332] [client 185.93.89.167:11981] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns12.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPmH33lhEjKFiK_nBKLvQAAAd4"]
[Sun Aug 30 03:13:19.786888 2026] [security2:error] [pid 524122:tid 524285] [client 20.220.10.235:48654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/txets.php"] [unique_id "apPmH33lhEjKFiK_nBKLvwAAAa8"]
[Sun Aug 30 03:13:19.798914 2026] [security2:error] [pid 524122:tid 524324] [client 20.197.61.180:15053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "a220training.com"] [uri "/wp-content/themes/ms-files.php"] [unique_id "apPmH33lhEjKFiK_nBKLwAAAAdY"]
[Sun Aug 30 03:13:19.803404 2026] [security2:error] [pid 524122:tid 524348] [client 185.93.89.167:26277] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/api/.env"] [unique_id "apPmH33lhEjKFiK_nBKLwQAAAe4"]
[Sun Aug 30 03:13:19.807399 2026] [security2:error] [pid 524122:tid 524288] [client 20.48.251.3:36897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/wp-class.php"] [unique_id "apPmH33lhEjKFiK_nBKLwgAAAbI"]
[Sun Aug 30 03:13:19.814656 2026] [security2:error] [pid 524122:tid 524364] [client 20.48.147.90:61674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/administrator.php"] [unique_id "apPmH33lhEjKFiK_nBKLwwAAAf4"]
[Sun Aug 30 03:13:19.820606 2026] [security2:error] [pid 524122:tid 524331] [client 185.93.89.167:33503] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/server/.env"] [unique_id "apPmH33lhEjKFiK_nBKLxQAAAd0"]
[Sun Aug 30 03:13:19.837009 2026] [security2:error] [pid 524122:tid 524368] [client 20.151.200.44:55618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.americanqualityhomeinspections.com"] [uri "/wk/index.php"] [unique_id "apPmH33lhEjKFiK_nBKLyQAAAgI"]
[Sun Aug 30 03:13:19.839470 2026] [security2:error] [pid 524122:tid 524301] [client 20.197.61.180:18305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "demandthetruth.michaelegenolf.com"] [uri "/wp-content/themes/login.php"] [unique_id "apPmH33lhEjKFiK_nBKLygAAAb8"]
[Sun Aug 30 03:13:19.844503 2026] [security2:error] [pid 524122:tid 524271] [client 185.93.89.167:53189] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/core/.env"] [unique_id "apPmH33lhEjKFiK_nBKLywAAAaE"]
[Sun Aug 30 03:13:19.860383 2026] [security2:error] [pid 524122:tid 524305] [client 20.104.50.220:62789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wsmini.php"] [unique_id "apPmH33lhEjKFiK_nBKLzgAAAcM"]
[Sun Aug 30 03:13:19.861442 2026] [security2:error] [pid 524122:tid 524349] [client 185.93.89.167:39395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail5.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPmH33lhEjKFiK_nBKL0AAAAe8"]
[Sun Aug 30 03:13:19.865272 2026] [security2:error] [pid 524122:tid 524357] [client 185.93.89.167:58165] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPmH33lhEjKFiK_nBKL0gAAAfc"]
[Sun Aug 30 03:13:19.874467 2026] [security2:error] [pid 524122:tid 524327] [client 185.93.89.167:64231] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/app/.env"] [unique_id "apPmH33lhEjKFiK_nBKL0wAAAdk"]
[Sun Aug 30 03:13:19.880443 2026] [security2:error] [pid 524122:tid 524342] [client 185.93.89.167:4321] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPmH33lhEjKFiK_nBKL1AAAAeg"]
[Sun Aug 30 03:13:19.892216 2026] [security2:error] [pid 524122:tid 524256] [client 185.93.89.167:21991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tr.mariegronley.com"] [uri "/core/.env"] [unique_id "apPmH33lhEjKFiK_nBKL1gAAAZI"]
[Sun Aug 30 03:13:19.897725 2026] [security2:error] [pid 524122:tid 524261] [client 20.104.50.220:16595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/.well-known/51.php"] [unique_id "apPmH33lhEjKFiK_nBKL1wAAAZc"]
[Sun Aug 30 03:13:19.905090 2026] [security2:error] [pid 524122:tid 524345] [client 185.93.89.167:25489] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/server/.env"] [unique_id "apPmH33lhEjKFiK_nBKL2QAAAes"]
[Sun Aug 30 03:13:19.910076 2026] [security2:error] [pid 524122:tid 524269] [client 158.23.147.79:44919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "apPmH33lhEjKFiK_nBKL2wAAAZ8"]
[Sun Aug 30 03:13:19.915090 2026] [security2:error] [pid 524122:tid 524299] [client 52.139.37.240:9523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/settings.php"] [unique_id "apPmH33lhEjKFiK_nBKL3AAAAb0"]
[Sun Aug 30 03:13:19.917527 2026] [security2:error] [pid 524122:tid 524355] [client 185.93.89.167:11981] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns12.mariegronley.com"] [uri "/core/.env"] [unique_id "apPmH33lhEjKFiK_nBKL3gAAAfU"]
[Sun Aug 30 03:13:19.934904 2026] [security2:error] [pid 524122:tid 524366] [client 20.220.10.235:48681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/wp-login.php"] [unique_id "apPmH33lhEjKFiK_nBKL3wAAAgA"]
[Sun Aug 30 03:13:19.939236 2026] [security2:error] [pid 524122:tid 524294] [client 185.93.89.167:26277] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPmH33lhEjKFiK_nBKL4QAAAbg"]
[Sun Aug 30 03:13:19.945509 2026] [security2:error] [pid 524122:tid 524306] [client 158.23.147.79:61775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/radio.php"] [unique_id "apPmH33lhEjKFiK_nBKL4wAAAcQ"]
[Sun Aug 30 03:13:19.950321 2026] [core:error] [pid 524122:tid 524297] [client 34.106.227.237:52892] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:19.950340 2026] [core:error] [pid 524122:tid 524297] [client 34.106.227.237:52892] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:19.957993 2026] [security2:error] [pid 524122:tid 524289] [client 20.104.49.130:48035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/ws45.php"] [unique_id "apPmH33lhEjKFiK_nBKL6AAAAbM"]
[Sun Aug 30 03:13:19.977873 2026] [authz_core:error] [pid 524122:tid 524341] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory2
[Sun Aug 30 03:13:19.978220 2026] [authz_core:error] [pid 524122:tid 524341] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory2
[Sun Aug 30 03:13:20.007755 2026] [security2:error] [pid 524122:tid 524326] [client 68.155.159.216:60982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/wp-includes/css/index.php"] [unique_id "apPmIH3lhEjKFiK_nBKL8AAAAdg"]
[Sun Aug 30 03:13:20.008503 2026] [security2:error] [pid 524122:tid 524329] [client 185.93.89.167:64231] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPmIH3lhEjKFiK_nBKL8QAAAds"]
[Sun Aug 30 03:13:20.011117 2026] [security2:error] [pid 524122:tid 524371] [client 20.151.200.44:46007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/od.php"] [unique_id "apPmIH3lhEjKFiK_nBKL8gAAAgU"]
[Sun Aug 30 03:13:20.014007 2026] [security2:error] [pid 524122:tid 524292] [client 185.93.89.167:4321] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/core/.env"] [unique_id "apPmIH3lhEjKFiK_nBKL8wAAAbY"]
[Sun Aug 30 03:13:20.046452 2026] [security2:error] [pid 524122:tid 524311] [client 20.151.200.44:52136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/ah24.php"] [unique_id "apPmIH3lhEjKFiK_nBKL9wAAAck"]
[Sun Aug 30 03:13:20.055071 2026] [security2:error] [pid 524122:tid 524308] [client 20.104.50.220:33284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/la.php"] [unique_id "apPmIH3lhEjKFiK_nBKL-wAAAcY"]
[Sun Aug 30 03:13:20.058962 2026] [security2:error] [pid 524122:tid 524268] [client 20.104.50.220:25469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/wp-content/BypassBest.php"] [unique_id "apPmIH3lhEjKFiK_nBKL_AAAAZ4"]
[Sun Aug 30 03:13:20.061273 2026] [authz_core:error] [pid 524122:tid 524260] [client 66.249.66.38:64509] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:20.061512 2026] [authz_core:error] [pid 524122:tid 524260] [client 66.249.66.38:64509] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:20.073390 2026] [security2:error] [pid 524122:tid 524353] [client 185.93.89.167:26277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thumbs.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPmIH3lhEjKFiK_nBKL_QAAAfM"]
[Sun Aug 30 03:13:20.077184 2026] [security2:error] [pid 524122:tid 524352] [client 20.220.10.235:48895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/wp-access.php"] [unique_id "apPmIH3lhEjKFiK_nBKL_gAAAfI"]
[Sun Aug 30 03:13:20.097261 2026] [security2:error] [pid 524122:tid 524334] [client 185.93.89.167:37409] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMAAAAAeA"]
[Sun Aug 30 03:13:20.104114 2026] [security2:error] [pid 524122:tid 524279] [client 20.48.147.90:45267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/wp-load.php"] [unique_id "apPmIH3lhEjKFiK_nBKMAQAAAak"]
[Sun Aug 30 03:13:20.104786 2026] [security2:error] [pid 524122:tid 524330] [client 4.205.62.107:17145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fcconveyancing.com.au"] [uri "/ammika.php"] [unique_id "apPmIH3lhEjKFiK_nBKMAgAAAdw"]
[Sun Aug 30 03:13:20.106163 2026] [security2:error] [pid 524122:tid 524290] [client 20.104.50.220:5609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/s.php"] [unique_id "apPmIH3lhEjKFiK_nBKMAwAAAbQ"]
[Sun Aug 30 03:13:20.133147 2026] [security2:error] [pid 524122:tid 524321] [client 185.93.89.167:45015] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMBgAAAdM"]
[Sun Aug 30 03:13:20.137007 2026] [security2:error] [pid 524122:tid 524263] [client 185.93.89.167:58165] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/server/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMBwAAAZk"]
[Sun Aug 30 03:13:20.142941 2026] [security2:error] [pid 524122:tid 524368] [client 185.93.89.167:34059] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/app/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMCQAAAgI"]
[Sun Aug 30 03:13:20.145601 2026] [security2:error] [pid 524122:tid 524322] [client 52.139.37.240:53245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-content/dropdown.php"] [unique_id "apPmIH3lhEjKFiK_nBKMCwAAAdQ"]
[Sun Aug 30 03:13:20.178178 2026] [security2:error] [pid 524122:tid 524258] [client 4.205.62.107:32477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/aws-credentials.php"] [unique_id "apPmIH3lhEjKFiK_nBKMEwAAAZQ"]
[Sun Aug 30 03:13:20.186457 2026] [core:error] [pid 524122:tid 524327] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:20.186474 2026] [core:error] [pid 524122:tid 524327] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:20.209635 2026] [security2:error] [pid 524122:tid 524356] [client 4.205.62.107:52812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/fff.php"] [unique_id "apPmIH3lhEjKFiK_nBKMGAAAAfY"]
[Sun Aug 30 03:13:20.222205 2026] [security2:error] [pid 524122:tid 524379] [client 20.220.10.235:48686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/wp-content/admin.php"] [unique_id "apPmIH3lhEjKFiK_nBKMGgAAAg0"]
[Sun Aug 30 03:13:20.230953 2026] [security2:error] [pid 524122:tid 524362] [client 185.93.89.167:37409] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/core/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMHQAAAfw"]
[Sun Aug 30 03:13:20.231576 2026] [authz_core:error] [pid 524122:tid 524357] [client 66.249.66.77:55671] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:20.231843 2026] [authz_core:error] [pid 524122:tid 524357] [client 66.249.66.77:55671] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:20.233524 2026] [security2:error] [pid 524122:tid 524310] [client 185.93.89.167:33503] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMHgAAAcg"]
[Sun Aug 30 03:13:20.254682 2026] [security2:error] [pid 524122:tid 524299] [client 185.93.89.167:53189] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/app/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMIgAAAb0"]
[Sun Aug 30 03:13:20.267422 2026] [security2:error] [pid 524122:tid 524366] [client 185.93.89.167:45015] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/core/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMJQAAAgA"]
[Sun Aug 30 03:13:20.270304 2026] [security2:error] [pid 524122:tid 524294] [client 20.48.147.90:61615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/wp-includes.php"] [unique_id "apPmIH3lhEjKFiK_nBKMJwAAAbg"]
[Sun Aug 30 03:13:20.277615 2026] [security2:error] [pid 524122:tid 524297] [client 158.23.147.79:52726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/nf_tracking.php"] [unique_id "apPmIH3lhEjKFiK_nBKMKQAAAbs"]
[Sun Aug 30 03:13:20.278049 2026] [security2:error] [pid 524122:tid 524323] [client 185.93.89.167:64231] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/server/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMKgAAAdU"]
[Sun Aug 30 03:13:20.282387 2026] [security2:error] [pid 524122:tid 524286] [client 185.93.89.167:34059] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMLQAAAbA"]
[Sun Aug 30 03:13:20.287065 2026] [authz_core:error] [pid 524122:tid 524372] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:20.287333 2026] [authz_core:error] [pid 524122:tid 524372] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:20.297263 2026] [security2:error] [pid 524122:tid 524369] [client 185.93.89.167:21991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tr.mariegronley.com"] [uri "/app/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMLgAAAgM"]
[Sun Aug 30 03:13:20.308033 2026] [security2:error] [pid 524122:tid 524281] [client 185.93.89.167:25489] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMLwAAAas"]
[Sun Aug 30 03:13:20.324016 2026] [security2:error] [pid 524122:tid 524309] [client 185.93.89.167:11981] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns12.mariegronley.com"] [uri "/app/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMMQAAAcc"]
[Sun Aug 30 03:13:20.353517 2026] [authz_core:error] [pid 524122:tid 524282] [client 216.73.216.128:35898] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:20.353886 2026] [authz_core:error] [pid 524122:tid 524282] [client 216.73.216.128:35898] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:20.367348 2026] [security2:error] [pid 524122:tid 524320] [client 20.220.10.235:48677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/log.php"] [unique_id "apPmIH3lhEjKFiK_nBKMPwAAAdI"]
[Sun Aug 30 03:13:20.374685 2026] [security2:error] [pid 524122:tid 524331] [client 20.197.61.180:16039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/credits.php"] [unique_id "apPmIH3lhEjKFiK_nBKMQAAAAd0"]
[Sun Aug 30 03:13:20.375835 2026] [autoindex:error] [pid 524122:tid 524318] [client 52.139.37.240:0] AH01276: Cannot serve directory /home3/dylans/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:13:20.382608 2026] [security2:error] [pid 524122:tid 524370] [client 4.205.62.107:16374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/queue.php"] [unique_id "apPmIH3lhEjKFiK_nBKMQQAAAgQ"]
[Sun Aug 30 03:13:20.389399 2026] [security2:error] [pid 524122:tid 524302] [client 185.93.89.167:53189] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMQgAAAcA"]
[Sun Aug 30 03:13:20.400595 2026] [security2:error] [pid 524122:tid 524346] [client 185.93.89.167:65083] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMQwAAAew"]
[Sun Aug 30 03:13:20.416232 2026] [security2:error] [pid 524122:tid 524268] [client 185.93.89.167:4321] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/app/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMRwAAAZ4"]
[Sun Aug 30 03:13:20.430230 2026] [security2:error] [pid 524122:tid 524352] [client 4.205.62.107:16337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/ms-edit.php"] [unique_id "apPmIH3lhEjKFiK_nBKMSQAAAfI"]
[Sun Aug 30 03:13:20.430791 2026] [security2:error] [pid 524122:tid 524334] [client 185.93.89.167:21991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tr.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMSgAAAeA"]
[Sun Aug 30 03:13:20.435786 2026] [security2:error] [pid 524122:tid 524330] [client 20.48.147.90:47104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/komet.php"] [unique_id "apPmIH3lhEjKFiK_nBKMTAAAAdw"]
[Sun Aug 30 03:13:20.443404 2026] [security2:error] [pid 524122:tid 524348] [client 20.48.147.90:64017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/wp-content.php"] [unique_id "apPmIH3lhEjKFiK_nBKMUQAAAe4"]
[Sun Aug 30 03:13:20.452215 2026] [security2:error] [pid 524122:tid 524284] [client 52.139.37.240:49706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-admin.php"] [unique_id "apPmIH3lhEjKFiK_nBKMUwAAAa4"]
[Sun Aug 30 03:13:20.455581 2026] [security2:error] [pid 524122:tid 524341] [client 158.23.147.79:61787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "apPmIH3lhEjKFiK_nBKMVQAAAec"]
[Sun Aug 30 03:13:20.456420 2026] [core:error] [pid 524122:tid 524276] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:20.456437 2026] [core:error] [pid 524122:tid 524276] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:20.457799 2026] [security2:error] [pid 524122:tid 524380] [client 185.93.89.167:11981] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns12.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMVwAAAg4"]
[Sun Aug 30 03:13:20.464010 2026] [authz_core:error] [pid 524122:tid 524322] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory4
[Sun Aug 30 03:13:20.464270 2026] [authz_core:error] [pid 524122:tid 524322] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory4
[Sun Aug 30 03:13:20.503876 2026] [security2:error] [pid 524122:tid 524291] [client 20.220.10.235:48844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/xwpg.php"] [unique_id "apPmIH3lhEjKFiK_nBKMXgAAAbU"]
[Sun Aug 30 03:13:20.504816 2026] [security2:error] [pid 524122:tid 524354] [client 20.197.61.180:15083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "a220training.com"] [uri "/wp-content/themes/news-portal/error.php"] [unique_id "apPmIH3lhEjKFiK_nBKMXwAAAfQ"]
[Sun Aug 30 03:13:20.533955 2026] [security2:error] [pid 524122:tid 524367] [client 20.197.61.180:11766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "demandthetruth.michaelegenolf.com"] [uri "/wp-content/themes/min.php"] [unique_id "apPmIH3lhEjKFiK_nBKMYgAAAgE"]
[Sun Aug 30 03:13:20.534662 2026] [security2:error] [pid 524122:tid 524272] [client 185.93.89.167:65083] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/core/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMYQAAAaI"]
[Sun Aug 30 03:13:20.537927 2026] [security2:error] [pid 524122:tid 524261] [client 20.104.50.220:63491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/kepo.php"] [unique_id "apPmIH3lhEjKFiK_nBKMZQAAAZc"]
[Sun Aug 30 03:13:20.544086 2026] [security2:error] [pid 524122:tid 524345] [client 185.93.89.167:58165] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMZgAAAes"]
[Sun Aug 30 03:13:20.549961 2026] [security2:error] [pid 524122:tid 524338] [client 185.93.89.167:4321] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMaAAAAeQ"]
[Sun Aug 30 03:13:20.559286 2026] [security2:error] [pid 524122:tid 524355] [client 20.104.18.15:51051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/wp-admin/w.php"] [unique_id "apPmIH3lhEjKFiK_nBKMaQAAAfU"]
[Sun Aug 30 03:13:20.561500 2026] [security2:error] [pid 524122:tid 524275] [client 158.23.147.79:55417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wzy.php"] [unique_id "apPmIH3lhEjKFiK_nBKMagAAAaU"]
[Sun Aug 30 03:13:20.561752 2026] [security2:error] [pid 524122:tid 524295] [client 20.104.50.220:29170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/sa.php"] [unique_id "apPmIH3lhEjKFiK_nBKMawAAAbk"]
[Sun Aug 30 03:13:20.562499 2026] [security2:error] [pid 524122:tid 524358] [client 20.104.18.15:22355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/wp-admin/w.php"] [unique_id "apPmIH3lhEjKFiK_nBKMbQAAAfg"]
[Sun Aug 30 03:13:20.563598 2026] [security2:error] [pid 524122:tid 524366] [client 185.93.89.167:34059] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/server/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMbgAAAgA"]
[Sun Aug 30 03:13:20.584477 2026] [security2:error] [pid 524122:tid 524374] [client 20.48.147.90:51285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/1337.php"] [unique_id "apPmIH3lhEjKFiK_nBKMcgAAAgg"]
[Sun Aug 30 03:13:20.594562 2026] [security2:error] [pid 524122:tid 524313] [client 20.48.147.90:61579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/index.php"] [unique_id "apPmIH3lhEjKFiK_nBKMdgAAAcs"]
[Sun Aug 30 03:13:20.600753 2026] [authz_core:error] [pid 524122:tid 524356] [client 66.249.66.72:35623] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:20.601213 2026] [authz_core:error] [pid 524122:tid 524356] [client 66.249.66.72:35623] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:20.615266 2026] [authz_core:error] [pid 524122:tid 524329] [client 66.249.66.72:50659] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:20.615691 2026] [authz_core:error] [pid 524122:tid 524329] [client 66.249.66.72:50659] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:20.616160 2026] [security2:error] [pid 524122:tid 524363] [client 185.93.89.167:24333] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMewAAAf0"]
[Sun Aug 30 03:13:20.626132 2026] [security2:error] [pid 524122:tid 524278] [client 20.104.49.130:36736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/dragonshell.php"] [unique_id "apPmIH3lhEjKFiK_nBKMfgAAAag"]
[Sun Aug 30 03:13:20.637394 2026] [security2:error] [pid 524122:tid 524372] [client 185.93.89.167:37409] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/app/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMgAAAAgY"]
[Sun Aug 30 03:13:20.644149 2026] [security2:error] [pid 524122:tid 524319] [client 20.104.49.130:63276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/ortasekerli1.php"] [unique_id "apPmIH3lhEjKFiK_nBKMgwAAAdE"]
[Sun Aug 30 03:13:20.649837 2026] [security2:error] [pid 524122:tid 524267] [client 20.220.10.235:48677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/sxxb.php"] [unique_id "apPmIH3lhEjKFiK_nBKMhAAAAZ0"]
[Sun Aug 30 03:13:20.656211 2026] [security2:error] [pid 524122:tid 524344] [client 52.139.37.240:9477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-admin/images/admin.php"] [unique_id "apPmIH3lhEjKFiK_nBKMhwAAAeo"]
[Sun Aug 30 03:13:20.659310 2026] [security2:error] [pid 524122:tid 524353] [client 185.93.89.167:53189] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/server/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMiAAAAfM"]
[Sun Aug 30 03:13:20.672989 2026] [security2:error] [pid 524122:tid 524315] [client 185.93.89.167:45015] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/app/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMiwAAAc0"]
[Sun Aug 30 03:13:20.683631 2026] [security2:error] [pid 524122:tid 524330] [client 185.93.89.167:64231] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMjgAAAdw"]
[Sun Aug 30 03:13:20.701425 2026] [security2:error] [pid 524122:tid 524283] [client 185.93.89.167:21991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tr.mariegronley.com"] [uri "/server/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMjwAAAa0"]
[Sun Aug 30 03:13:20.717888 2026] [security2:error] [pid 524122:tid 524321] [client 216.73.216.128:63672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_takeaddr_screen"] [unique_id "apPmIH3lhEjKFiK_nBKMkwAAAdM"]
[Sun Aug 30 03:13:20.721851 2026] [security2:error] [pid 524122:tid 524263] [client 20.48.147.90:47114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/backd00r.php"] [unique_id "apPmIH3lhEjKFiK_nBKMlAAAAZk"]
[Sun Aug 30 03:13:20.727481 2026] [security2:error] [pid 524122:tid 524368] [client 185.93.89.167:11981] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns12.mariegronley.com"] [uri "/server/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMlQAAAgI"]
[Sun Aug 30 03:13:20.734188 2026] [security2:error] [pid 524122:tid 524284] [client 20.48.147.90:64002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/bypp.php"] [unique_id "apPmIH3lhEjKFiK_nBKMlgAAAa4"]
[Sun Aug 30 03:13:20.734501 2026] [security2:error] [pid 524122:tid 524341] [client 158.23.147.79:52709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-admin/setup-config.php"] [unique_id "apPmIH3lhEjKFiK_nBKMlwAAAec"]
[Sun Aug 30 03:13:20.749902 2026] [security2:error] [pid 524122:tid 524285] [client 185.93.89.167:24333] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/core/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMmAAAAa8"]
[Sun Aug 30 03:13:20.772307 2026] [security2:error] [pid 524122:tid 524301] [client 185.93.89.167:37409] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMmwAAAb8"]
[Sun Aug 30 03:13:20.772388 2026] [security2:error] [pid 524122:tid 524334] [client 34.106.227.237:52930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/app/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMmgAAAeA"]
[Sun Aug 30 03:13:20.779110 2026] [authz_core:error] [pid 524122:tid 524255] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:20.779426 2026] [authz_core:error] [pid 524122:tid 524255] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:20.782175 2026] [security2:error] [pid 524122:tid 524316] [client 20.220.10.235:48701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/dx.php"] [unique_id "apPmIH3lhEjKFiK_nBKMngAAAc4"]
[Sun Aug 30 03:13:20.791134 2026] [security2:error] [pid 524122:tid 524328] [client 20.48.251.3:65515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/linusadmin-phpinfo.php"] [unique_id "apPmIH3lhEjKFiK_nBKMnwAAAdo"]
[Sun Aug 30 03:13:20.807216 2026] [security2:error] [pid 524122:tid 524325] [client 185.93.89.167:45015] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMogAAAdc"]
[Sun Aug 30 03:13:20.810414 2026] [security2:error] [pid 524122:tid 524367] [client 158.23.147.79:62014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/makeasmtp.php"] [unique_id "apPmIH3lhEjKFiK_nBKMowAAAgE"]
[Sun Aug 30 03:13:20.818872 2026] [security2:error] [pid 524122:tid 524339] [client 185.93.89.167:4321] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/server/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMpwAAAeU"]
[Sun Aug 30 03:13:20.858660 2026] [security2:error] [pid 524122:tid 524374] [client 34.106.227.237:52930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/apps/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMrQAAAgg"]
[Sun Aug 30 03:13:20.865604 2026] [security2:error] [pid 524122:tid 524313] [client 20.48.147.90:47146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/backdoor.php"] [unique_id "apPmIH3lhEjKFiK_nBKMrwAAAcs"]
[Sun Aug 30 03:13:20.877234 2026] [security2:error] [pid 524122:tid 524360] [client 20.48.147.90:61572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/byp7.php"] [unique_id "apPmIH3lhEjKFiK_nBKMsAAAAfo"]
[Sun Aug 30 03:13:20.883445 2026] [security2:error] [pid 524122:tid 524280] [client 20.104.50.220:63217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "apPmIH3lhEjKFiK_nBKMsgAAAao"]
[Sun Aug 30 03:13:20.904552 2026] [authz_core:error] [pid 524122:tid 524294] [client 66.249.66.68:50620] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:20.905007 2026] [authz_core:error] [pid 524122:tid 524294] [client 66.249.66.68:50620] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:20.908850 2026] [security2:error] [pid 524122:tid 524257] [client 185.93.89.167:33503] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/source/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMtgAAAZM"]
[Sun Aug 30 03:13:20.921446 2026] [security2:error] [pid 524122:tid 524287] [client 52.139.37.240:9493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/batm.php"] [unique_id "apPmIH3lhEjKFiK_nBKMuAAAAbE"]
[Sun Aug 30 03:13:20.924932 2026] [security2:error] [pid 524122:tid 524318] [client 20.220.10.235:48854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPmIH3lhEjKFiK_nBKMuQAAAdA"]
[Sun Aug 30 03:13:20.939343 2026] [security2:error] [pid 524122:tid 524288] [client 185.93.89.167:65083] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/app/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMvAAAAbI"]
[Sun Aug 30 03:13:20.939397 2026] [security2:error] [pid 524122:tid 524278] [client 158.23.147.79:59038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-content/themes/themes/Cyb3r.php"] [unique_id "apPmIH3lhEjKFiK_nBKMvQAAAag"]
[Sun Aug 30 03:13:20.947186 2026] [security2:error] [pid 524122:tid 524322] [client 20.48.251.3:37141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/database.php"] [unique_id "apPmIH3lhEjKFiK_nBKMvwAAAdQ"]
[Sun Aug 30 03:13:20.949813 2026] [security2:error] [pid 524122:tid 524317] [client 34.106.227.237:52930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMwgAAAc8"]
[Sun Aug 30 03:13:20.983224 2026] [security2:error] [pid 524122:tid 524353] [client 185.93.89.167:25489] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/source/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMxgAAAfM"]
[Sun Aug 30 03:13:20.983500 2026] [security2:error] [pid 524122:tid 524253] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/app/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMxwAAAY8"]
[Sun Aug 30 03:13:20.987131 2026] [security2:error] [pid 524122:tid 524300] [client 185.93.89.167:34059] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPmIH3lhEjKFiK_nBKMyAAAAb4"]
[Sun Aug 30 03:13:21.002492 2026] [authz_core:error] [pid 524122:tid 524352] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory4
[Sun Aug 30 03:13:21.002805 2026] [authz_core:error] [pid 524122:tid 524352] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory4
[Sun Aug 30 03:13:21.003877 2026] [authz_core:error] [pid 524122:tid 524315] [client 66.249.66.194:56165] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:21.004152 2026] [authz_core:error] [pid 524122:tid 524315] [client 66.249.66.194:56165] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:21.006549 2026] [security2:error] [pid 524122:tid 524260] [client 20.48.147.90:47143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/andela.php"] [unique_id "apPmIX3lhEjKFiK_nBKMzAAAAZY"]
[Sun Aug 30 03:13:21.008882 2026] [security2:error] [pid 524122:tid 524279] [client 34.106.227.237:52930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/web/.env"] [unique_id "apPmIX3lhEjKFiK_nBKMzQAAAak"]
[Sun Aug 30 03:13:21.012971 2026] [security2:error] [pid 524122:tid 524283] [client 20.151.200.44:55739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.americanqualityhomeinspections.com"] [uri "/dehnl.php"] [unique_id "apPmIX3lhEjKFiK_nBKMzgAAAa0"]
[Sun Aug 30 03:13:21.035589 2026] [security2:error] [pid 524122:tid 524365] [client 20.104.50.220:16751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/.well-known/54.php"] [unique_id "apPmIX3lhEjKFiK_nBKM0QAAAf8"]
[Sun Aug 30 03:13:21.043408 2026] [security2:error] [pid 524122:tid 524368] [client 185.93.89.167:37409] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/server/.env"] [unique_id "apPmIX3lhEjKFiK_nBKM1QAAAgI"]
[Sun Aug 30 03:13:21.052656 2026] [security2:error] [pid 524122:tid 524341] [client 20.48.147.90:45261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/anonsec.php"] [unique_id "apPmIX3lhEjKFiK_nBKM1wAAAec"]
[Sun Aug 30 03:13:21.061772 2026] [security2:error] [pid 524122:tid 524289] [client 20.151.200.44:52044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPmIX3lhEjKFiK_nBKM2gAAAbM"]
[Sun Aug 30 03:13:21.062396 2026] [security2:error] [pid 524122:tid 524271] [client 20.220.10.235:48849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/xda.php"] [unique_id "apPmIX3lhEjKFiK_nBKM2wAAAaE"]
[Sun Aug 30 03:13:21.065610 2026] [security2:error] [pid 524122:tid 524285] [client 185.93.89.167:53189] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPmIX3lhEjKFiK_nBKM3QAAAa8"]
[Sun Aug 30 03:13:21.071767 2026] [security2:error] [pid 524122:tid 524334] [client 158.23.147.79:61760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/uploads/makeasmtp.php"] [unique_id "apPmIX3lhEjKFiK_nBKM3gAAAeA"]
[Sun Aug 30 03:13:21.073223 2026] [security2:error] [pid 524122:tid 524373] [client 185.93.89.167:65083] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPmIX3lhEjKFiK_nBKM3wAAAgc"]
[Sun Aug 30 03:13:21.073631 2026] [security2:error] [pid 524122:tid 524338] [client 20.197.61.180:13518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/cache.php"] [unique_id "apPmIX3lhEjKFiK_nBKM4AAAAeQ"]
[Sun Aug 30 03:13:21.078379 2026] [security2:error] [pid 524122:tid 524309] [client 185.93.89.167:45015] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/server/.env"] [unique_id "apPmIX3lhEjKFiK_nBKM4QAAAcc"]
[Sun Aug 30 03:13:21.087246 2026] [security2:error] [pid 524122:tid 524349] [client 158.23.147.79:55413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-content/plugins/plugins/Cyb3r.php"] [unique_id "apPmIX3lhEjKFiK_nBKM5AAAAe8"]
[Sun Aug 30 03:13:21.106487 2026] [security2:error] [pid 524122:tid 524293] [client 185.93.89.167:21991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tr.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPmIX3lhEjKFiK_nBKM5QAAAbc"]
[Sun Aug 30 03:13:21.108304 2026] [security2:error] [pid 524122:tid 524291] [client 20.104.50.220:52842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/86.php"] [unique_id "apPmIX3lhEjKFiK_nBKM6AAAAbU"]
[Sun Aug 30 03:13:21.109291 2026] [security2:error] [pid 524122:tid 524303] [client 34.106.227.237:52930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/site/.env"] [unique_id "apPmIX3lhEjKFiK_nBKM5wAAAcE"]
[Sun Aug 30 03:13:21.112710 2026] [lsapi:warn] [pid 524122:tid 524195] [remote 93.109.69.170:63863] [host tastylandscape.com] Backend log: PHP Warning: Use of undefined constant user_level - assumed 'user_level' (this will throw an Error in a future version of PHP) in /home4/tommed/public_html/wp-content/plugins/ultimate-google-analytics/ultimate_ga.php on line 524\n, referer: https://www.google.com/
[Sun Aug 30 03:13:21.125487 2026] [authz_core:error] [pid 524122:tid 524337] [client 66.249.66.68:39056] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:21.125920 2026] [authz_core:error] [pid 524122:tid 524337] [client 66.249.66.68:39056] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:21.127358 2026] [authz_core:error] [pid 524122:tid 524282] [client 216.73.216.128:35898] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:21.127813 2026] [authz_core:error] [pid 524122:tid 524282] [client 216.73.216.128:35898] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:21.131330 2026] [security2:error] [pid 524122:tid 524362] [client 185.93.89.167:11981] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns12.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPmIX3lhEjKFiK_nBKM7gAAAfw"]
[Sun Aug 30 03:13:21.131573 2026] [security2:error] [pid 524122:tid 524268] [client 158.69.119.14:59562] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "158.69.119.14" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPmIX3lhEjKFiK_nBKM7wAAAZ4"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:13:21.131714 2026] [security2:error] [pid 524122:tid 524268] [client 158.69.119.14:59562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPmIX3lhEjKFiK_nBKM7wAAAZ4"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:13:21.132085 2026] [security2:error] [pid 524122:tid 524325] [client 68.155.159.216:60323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apPmIX3lhEjKFiK_nBKM6QAAAdc"]
[Sun Aug 30 03:13:21.142759 2026] [security2:error] [pid 524122:tid 524314] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/apps/.env"] [unique_id "apPmIX3lhEjKFiK_nBKM8AAAAcw"]
[Sun Aug 30 03:13:21.151114 2026] [security2:error] [pid 524122:tid 524316] [client 52.139.37.240:49711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/sim.php/wp-includes/certificates/plugins.php"] [unique_id "apPmIX3lhEjKFiK_nBKM8QAAAc4"]
[Sun Aug 30 03:13:21.154802 2026] [security2:error] [pid 524122:tid 524310] [client 185.93.89.167:24333] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/app/.env"] [unique_id "apPmIX3lhEjKFiK_nBKM8gAAAcg"]
[Sun Aug 30 03:13:21.158272 2026] [security2:error] [pid 524122:tid 524369] [client 20.48.147.90:51277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/jkt48.php"] [unique_id "apPmIX3lhEjKFiK_nBKM8wAAAgM"]
[Sun Aug 30 03:13:21.178661 2026] [security2:error] [pid 524122:tid 524347] [client 185.93.89.167:33503] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPmIX3lhEjKFiK_nBKM9QAAAe0"]
[Sun Aug 30 03:13:21.184638 2026] [security2:error] [pid 524122:tid 524306] [client 34.106.227.237:52930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/public/.env"] [unique_id "apPmIX3lhEjKFiK_nBKM9gAAAcQ"]
[Sun Aug 30 03:13:21.189477 2026] [security2:error] [pid 524122:tid 524286] [client 20.104.49.130:52432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "enterden.den-enterprises.com"] [uri "/talkxkej.php"] [unique_id "apPmIX3lhEjKFiK_nBKM9wAAAbA"]
[Sun Aug 30 03:13:21.199558 2026] [security2:error] [pid 524122:tid 524256] [client 20.197.61.180:15101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "a220training.com"] [uri "/wp-content/themes/nvt/includes/plugins/wp-blog-header.php"] [unique_id "apPmIX3lhEjKFiK_nBKM-gAAAZI"]
[Sun Aug 30 03:13:21.199676 2026] [security2:error] [pid 524122:tid 524374] [client 185.93.89.167:59073] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/.env"] [unique_id "apPmIX3lhEjKFiK_nBKM-QAAAgg"]
[Sun Aug 30 03:13:21.202406 2026] [security2:error] [pid 524122:tid 524296] [client 20.220.10.235:48649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/wp-admin/js/index.php"] [unique_id "apPmIX3lhEjKFiK_nBKM-wAAAbo"]
[Sun Aug 30 03:13:21.205788 2026] [security2:error] [pid 524122:tid 524280] [client 20.104.50.220:33558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/lnedx.php"] [unique_id "apPmIX3lhEjKFiK_nBKM_AAAAao"]
[Sun Aug 30 03:13:21.206268 2026] [security2:error] [pid 524122:tid 524307] [client 20.48.147.90:61644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/anon.php"] [unique_id "apPmIX3lhEjKFiK_nBKM_gAAAcU"]
[Sun Aug 30 03:13:21.217232 2026] [security2:error] [pid 524122:tid 524299] [client 185.93.89.167:58165] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/source/.env"] [unique_id "apPmIX3lhEjKFiK_nBKNAQAAAb0"]
[Sun Aug 30 03:13:21.235807 2026] [security2:error] [pid 524122:tid 524378] [client 4.205.62.107:17121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fcconveyancing.com.au"] [uri "/broadcasting.php"] [unique_id "apPmIX3lhEjKFiK_nBKNBgAAAgw"]
[Sun Aug 30 03:13:21.244357 2026] [core:error] [pid 524122:tid 524370] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:21.244373 2026] [core:error] [pid 524122:tid 524370] [client 34.106.227.237:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:21.248195 2026] [security2:error] [pid 524122:tid 524288] [client 20.104.49.130:34526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alarm-monitoring.net"] [uri "/m.php"] [unique_id "apPmIX3lhEjKFiK_nBKNCQAAAbI"]
[Sun Aug 30 03:13:21.248765 2026] [security2:error] [pid 524122:tid 524278] [client 158.23.147.79:61991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "apPmIX3lhEjKFiK_nBKNCgAAAag"]
[Sun Aug 30 03:13:21.252825 2026] [security2:error] [pid 524122:tid 524346] [client 185.93.89.167:25489] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPmIX3lhEjKFiK_nBKNCwAAAew"]
[Sun Aug 30 03:13:21.253931 2026] [security2:error] [pid 524122:tid 524322] [client 20.104.50.220:5774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/t.php"] [unique_id "apPmIX3lhEjKFiK_nBKNDQAAAdQ"]
[Sun Aug 30 03:13:21.261834 2026] [security2:error] [pid 524122:tid 524312] [client 20.197.61.180:18340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "demandthetruth.michaelegenolf.com"] [uri "/wp-content/themes/module.php"] [unique_id "apPmIX3lhEjKFiK_nBKNDgAAAco"]
[Sun Aug 30 03:13:21.269812 2026] [authz_core:error] [pid 524122:tid 524270] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:21.270087 2026] [authz_core:error] [pid 524122:tid 524270] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:21.289182 2026] [security2:error] [pid 524122:tid 524300] [client 185.93.89.167:24333] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPmIX3lhEjKFiK_nBKNEgAAAb4"]
[Sun Aug 30 03:13:21.292781 2026] [security2:error] [pid 524122:tid 524351] [client 20.48.147.90:51290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/gaza.php"] [unique_id "apPmIX3lhEjKFiK_nBKNEwAAAfE"]
[Sun Aug 30 03:13:21.312238 2026] [security2:error] [pid 524122:tid 524290] [client 185.93.89.167:33503] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPmIX3lhEjKFiK_nBKNFgAAAbQ"]
[Sun Aug 30 03:13:21.318029 2026] [security2:error] [pid 524122:tid 524354] [client 20.104.50.220:25448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/simple.php"] [unique_id "apPmIX3lhEjKFiK_nBKNGgAAAfQ"]
[Sun Aug 30 03:13:21.321101 2026] [security2:error] [pid 524122:tid 524368] [client 4.205.62.107:32456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/4563.php"] [unique_id "apPmIX3lhEjKFiK_nBKNHAAAAgI"]
[Sun Aug 30 03:13:21.322597 2026] [security2:error] [pid 524122:tid 524263] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/api/.env"] [unique_id "apPmIX3lhEjKFiK_nBKNHQAAAZk"]
[Sun Aug 30 03:13:21.332076 2026] [security2:error] [pid 524122:tid 524350] [client 20.220.10.235:48672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/t00l.php"] [unique_id "apPmIX3lhEjKFiK_nBKNHgAAAfA"]
[Sun Aug 30 03:13:21.335598 2026] [security2:error] [pid 524122:tid 524285] [client 185.93.89.167:59073] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/api/.env"] [unique_id "apPmIX3lhEjKFiK_nBKNHwAAAa8"]
[Sun Aug 30 03:13:21.339108 2026] [security2:error] [pid 524122:tid 524334] [client 158.23.147.79:55411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "apPmIX3lhEjKFiK_nBKNIQAAAeA"]
[Sun Aug 30 03:13:21.363914 2026] [security2:error] [pid 524122:tid 524277] [client 4.205.62.107:52850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/autogooey.php"] [unique_id "apPmIX3lhEjKFiK_nBKNIwAAAac"]
[Sun Aug 30 03:13:21.387705 2026] [security2:error] [pid 524122:tid 524356] [client 185.93.89.167:25489] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPmIX3lhEjKFiK_nBKNJQAAAfY"]
[Sun Aug 30 03:13:21.408873 2026] [security2:error] [pid 524122:tid 524293] [client 216.73.216.128:35898] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:p. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "mail.letter7brands.com"] [uri "/\\""] [unique_id "apPmIX3lhEjKFiK_nBKNKAAAAbc"]
[Sun Aug 30 03:13:21.415407 2026] [security2:error] [pid 524122:tid 524327] [client 20.48.147.90:45264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/bypas.php"] [unique_id "apPmIX3lhEjKFiK_nBKNKgAAAdk"]
[Sun Aug 30 03:13:21.430574 2026] [security2:error] [pid 524122:tid 524272] [client 20.48.147.90:47113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/injection.php"] [unique_id "apPmIX3lhEjKFiK_nBKNLAAAAaI"]
[Sun Aug 30 03:13:21.445520 2026] [security2:error] [pid 524122:tid 524345] [client 185.93.89.167:33503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "forms.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPmIX3lhEjKFiK_nBKNMAAAAes"]
[Sun Aug 30 03:13:21.446031 2026] [security2:error] [pid 524122:tid 524362] [client 20.104.49.130:32769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/wpxml.php"] [unique_id "apPmIX3lhEjKFiK_nBKNMQAAAfw"]
[Sun Aug 30 03:13:21.448718 2026] [security2:error] [pid 524122:tid 524253] [client 158.69.119.14:59579] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "158.69.119.14" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPmIX3lhEjKFiK_nBKNMgAAAY8"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:13:21.448844 2026] [security2:error] [pid 524122:tid 524253] [client 158.69.119.14:59579] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "artistsallianceagency.com"] [uri "/wp-comments-post.php"] [unique_id "apPmIX3lhEjKFiK_nBKNMgAAAY8"], referer: http://artistsallianceagency.com/2022/12/31/hello-world/
[Sun Aug 30 03:13:21.450438 2026] [security2:error] [pid 524122:tid 524268] [client 185.93.89.167:37409] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPmIX3lhEjKFiK_nBKNMwAAAZ4"]
[Sun Aug 30 03:13:21.461566 2026] [security2:error] [pid 524122:tid 524325] [client 20.220.10.235:48653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/ls.php"] [unique_id "apPmIX3lhEjKFiK_nBKNNAAAAdc"]
[Sun Aug 30 03:13:21.470756 2026] [security2:error] [pid 524122:tid 524314] [client 185.93.89.167:59073] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/backend/.env"] [unique_id "apPmIX3lhEjKFiK_nBKNNgAAAcw"]
[Sun Aug 30 03:13:21.472777 2026] [authz_core:error] [pid 524122:tid 524348] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory7
[Sun Aug 30 03:13:21.473088 2026] [authz_core:error] [pid 524122:tid 524348] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory7
[Sun Aug 30 03:13:21.485033 2026] [security2:error] [pid 524122:tid 524369] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/web/.env"] [unique_id "apPmIX3lhEjKFiK_nBKNOAAAAgM"]
[Sun Aug 30 03:13:21.487918 2026] [security2:error] [pid 524122:tid 524295] [client 185.93.89.167:58165] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPmIX3lhEjKFiK_nBKNOQAAAbk"]
[Sun Aug 30 03:13:21.521383 2026] [security2:error] [pid 524122:tid 524347] [client 185.93.89.167:25489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m1.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPmIX3lhEjKFiK_nBKNOgAAAe0"]
[Sun Aug 30 03:13:21.530758 2026] [security2:error] [pid 524122:tid 524256] [client 158.23.147.79:44889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-includes/SimplePie/Content/index.php"] [unique_id "apPmIX3lhEjKFiK_nBKNPQAAAZI"]
[Sun Aug 30 03:13:21.560006 2026] [security2:error] [pid 524122:tid 524307] [client 185.93.89.167:24333] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/server/.env"] [unique_id "apPmIX3lhEjKFiK_nBKNQQAAAcU"]
[Sun Aug 30 03:13:21.565412 2026] [security2:error] [pid 524122:tid 524299] [client 20.48.147.90:51272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/bejak.php"] [unique_id "apPmIX3lhEjKFiK_nBKNQgAAAb0"]
[Sun Aug 30 03:13:21.567817 2026] [security2:error] [pid 524122:tid 524257] [client 4.205.62.107:16340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/sys.php"] [unique_id "apPmIX3lhEjKFiK_nBKNQwAAAZM"]
[Sun Aug 30 03:13:21.576533 2026] [authz_core:error] [pid 524122:tid 524276] [client 66.249.66.72:50659] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:21.576827 2026] [authz_core:error] [pid 524122:tid 524276] [client 66.249.66.72:50659] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:21.580755 2026] [security2:error] [pid 524122:tid 524282] [client 20.48.147.90:64004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/ucen.php"] [unique_id "apPmIX3lhEjKFiK_nBKNRQAAAaw"]
[Sun Aug 30 03:13:21.601560 2026] [security2:error] [pid 524122:tid 524322] [client 4.205.62.107:15577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/doc.php"] [unique_id "apPmIX3lhEjKFiK_nBKNSAAAAdQ"]
[Sun Aug 30 03:13:21.603679 2026] [security2:error] [pid 524122:tid 524266] [client 20.220.10.235:48659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/css/000.php"] [unique_id "apPmIX3lhEjKFiK_nBKNSQAAAZw"]
[Sun Aug 30 03:13:21.604917 2026] [security2:error] [pid 524122:tid 524340] [client 185.93.89.167:59073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mobil.mariegronley.com"] [uri "/phpinfo.php"] [unique_id "apPmIX3lhEjKFiK_nBKNTAAAAeY"]
[Sun Aug 30 03:13:21.621801 2026] [security2:error] [pid 524122:tid 524319] [client 185.93.89.167:58165] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPmIX3lhEjKFiK_nBKNUwAAAdE"]
[Sun Aug 30 03:13:21.648522 2026] [security2:error] [pid 524122:tid 524331] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/site/.env"] [unique_id "apPmIX3lhEjKFiK_nBKNVAAAAd0"]
[Sun Aug 30 03:13:21.661730 2026] [security2:error] [pid 524122:tid 524300] [client 20.151.200.44:45972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/wp-the.php"] [unique_id "apPmIX3lhEjKFiK_nBKNVQAAAb4"]
[Sun Aug 30 03:13:21.669942 2026] [authz_core:error] [pid 524122:tid 524351] [client 66.249.66.43:63666] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:21.670212 2026] [authz_core:error] [pid 524122:tid 524351] [client 66.249.66.43:63666] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:21.679999 2026] [security2:error] [pid 524122:tid 524354] [client 20.104.50.220:51620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/kk.php"] [unique_id "apPmIX3lhEjKFiK_nBKNWAAAAfQ"]
[Sun Aug 30 03:13:21.692932 2026] [security2:error] [pid 524122:tid 524365] [client 185.93.89.167:34059] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/source/.env"] [unique_id "apPmIX3lhEjKFiK_nBKNWQAAAf8"]
[Sun Aug 30 03:13:21.694137 2026] [security2:error] [pid 524122:tid 524364] [client 20.104.18.15:51169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/wp-content/k.php"] [unique_id "apPmIX3lhEjKFiK_nBKNWwAAAf4"]
[Sun Aug 30 03:13:21.708729 2026] [security2:error] [pid 524122:tid 524263] [client 20.48.147.90:47138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/idca_shell.php"] [unique_id "apPmIX3lhEjKFiK_nBKNXAAAAZk"]
[Sun Aug 30 03:13:21.712774 2026] [security2:error] [pid 524122:tid 524294] [client 20.104.50.220:62814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/noname.php"] [unique_id "apPmIX3lhEjKFiK_nBKNXgAAAbg"]
[Sun Aug 30 03:13:21.713356 2026] [security2:error] [pid 524122:tid 524302] [client 185.93.89.167:4195] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/system/.env"] [unique_id "apPmIX3lhEjKFiK_nBKNXQAAAcA"]
[Sun Aug 30 03:13:21.716485 2026] [security2:error] [pid 524122:tid 524350] [client 158.23.147.79:43849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/languages/about.php"] [unique_id "apPmIX3lhEjKFiK_nBKNXwAAAfA"]
[Sun Aug 30 03:13:21.720834 2026] [security2:error] [pid 524122:tid 524285] [client 20.104.18.15:22424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/wp-content/k.php"] [unique_id "apPmIX3lhEjKFiK_nBKNYgAAAa8"]
[Sun Aug 30 03:13:21.730348 2026] [security2:error] [pid 524122:tid 524373] [client 20.48.147.90:61606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/miya.php"] [unique_id "apPmIX3lhEjKFiK_nBKNYwAAAgc"]
[Sun Aug 30 03:13:21.735573 2026] [security2:error] [pid 524122:tid 524309] [client 20.220.10.235:48842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/cy.php"] [unique_id "apPmIX3lhEjKFiK_nBKNZAAAAcc"]
[Sun Aug 30 03:13:21.743739 2026] [security2:error] [pid 524122:tid 524349] [client 185.93.89.167:53189] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/source/.env"] [unique_id "apPmIX3lhEjKFiK_nBKNZQAAAe8"]
[Sun Aug 30 03:13:21.754656 2026] [security2:error] [pid 524122:tid 524328] [client 185.93.89.167:58165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "otrs.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPmIX3lhEjKFiK_nBKNaAAAAdo"]
[Sun Aug 30 03:13:21.765597 2026] [authz_core:error] [pid 524122:tid 524277] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:21.766057 2026] [authz_core:error] [pid 524122:tid 524277] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:21.770176 2026] [security2:error] [pid 524122:tid 524360] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "apPmIX3lhEjKFiK_nBKNaQAAAfo"]
[Sun Aug 30 03:13:21.778027 2026] [authz_core:error] [pid 524122:tid 524270] [client 66.249.66.77:55671] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:21.778295 2026] [authz_core:error] [pid 524122:tid 524270] [client 66.249.66.77:55671] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:21.789625 2026] [security2:error] [pid 524122:tid 524303] [client 185.93.89.167:28387] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/system/.env"] [unique_id "apPmIX3lhEjKFiK_nBKNawAAAcE"]
[Sun Aug 30 03:13:21.801275 2026] [security2:error] [pid 524122:tid 524280] [client 20.197.61.180:9768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/fix.php"] [unique_id "apPmIX3lhEjKFiK_nBKNbQAAAao"]
[Sun Aug 30 03:13:21.809162 2026] [security2:error] [pid 524122:tid 524342] [client 185.93.89.167:11981] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns12.mariegronley.com"] [uri "/source/.env"] [unique_id "apPmIX3lhEjKFiK_nBKNbwAAAeg"]
[Sun Aug 30 03:13:21.812200 2026] [security2:error] [pid 524122:tid 524275] [client 158.23.147.79:59043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/packed.php"] [unique_id "apPmIX3lhEjKFiK_nBKNcQAAAaU"]
[Sun Aug 30 03:13:21.821460 2026] [security2:error] [pid 524122:tid 524363] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/public/.env"] [unique_id "apPmIX3lhEjKFiK_nBKNcgAAAf0"]
[Sun Aug 30 03:13:21.841283 2026] [security2:error] [pid 524122:tid 524268] [client 20.151.200.44:44021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ermes-it.it"] [uri "/wp-admin/maint/Jcrop.php"] [unique_id "apPmIX3lhEjKFiK_nBKNdQAAAZ4"]
[Sun Aug 30 03:13:21.846173 2026] [security2:error] [pid 524122:tid 524292] [client 185.93.89.167:4195] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "forms.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPmIX3lhEjKFiK_nBKNdgAAAbY"]
[Sun Aug 30 03:13:21.854546 2026] [security2:error] [pid 524122:tid 524325] [client 20.48.147.90:47166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/idca.php"] [unique_id "apPmIX3lhEjKFiK_nBKNdwAAAdc"]
[Sun Aug 30 03:13:21.870040 2026] [security2:error] [pid 524122:tid 524310] [client 20.220.10.235:48847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/admin.php/pindex.php"] [unique_id "apPmIX3lhEjKFiK_nBKNegAAAcg"]
[Sun Aug 30 03:13:21.893347 2026] [security2:error] [pid 524122:tid 524358] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/server/.env"] [unique_id "apPmIX3lhEjKFiK_nBKNfQAAAfg"]
[Sun Aug 30 03:13:21.893682 2026] [security2:error] [pid 524122:tid 524355] [client 20.48.147.90:64058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/error.php"] [unique_id "apPmIX3lhEjKFiK_nBKNfgAAAfU"]
[Sun Aug 30 03:13:21.896137 2026] [security2:error] [pid 524122:tid 524352] [client 216.73.216.128:36104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/"] [unique_id "apPmIX3lhEjKFiK_nBKNfwAAAfI"]
[Sun Aug 30 03:13:21.918106 2026] [security2:error] [pid 524122:tid 524330] [client 20.197.61.180:15080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "a220training.com"] [uri "/wp-content/themes/oceanwp/sass/components/plugins/panel.php"] [unique_id "apPmIX3lhEjKFiK_nBKNggAAAdw"]
[Sun Aug 30 03:13:21.922156 2026] [security2:error] [pid 524122:tid 524256] [client 185.93.89.167:28387] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "m1.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPmIX3lhEjKFiK_nBKNgwAAAZI"]
[Sun Aug 30 03:13:21.923500 2026] [security2:error] [pid 524122:tid 524374] [client 20.48.251.3:65482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/app/Models/Hrm/Employee.php"] [unique_id "apPmIX3lhEjKFiK_nBKNhAAAAgg"]
[Sun Aug 30 03:13:21.945451 2026] [security2:error] [pid 524122:tid 524313] [client 20.151.200.44:62994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/tf.php"] [unique_id "apPmIX3lhEjKFiK_nBKNhgAAAcs"]
[Sun Aug 30 03:13:21.962350 2026] [security2:error] [pid 524122:tid 524257] [client 185.93.89.167:24333] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPmIX3lhEjKFiK_nBKNiAAAAZM"]
[Sun Aug 30 03:13:21.966686 2026] [security2:error] [pid 524122:tid 524318] [client 158.23.147.79:59019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-content/packed.php"] [unique_id "apPmIX3lhEjKFiK_nBKNiQAAAdA"]
[Sun Aug 30 03:13:21.974602 2026] [security2:error] [pid 524122:tid 524338] [client 20.197.61.180:18316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "demandthetruth.michaelegenolf.com"] [uri "/wp-content/themes/ms-files.php"] [unique_id "apPmIX3lhEjKFiK_nBKNigAAAeQ"]
[Sun Aug 30 03:13:21.976554 2026] [security2:error] [pid 524122:tid 524370] [client 185.93.89.167:34059] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPmIX3lhEjKFiK_nBKNiwAAAgQ"]
[Sun Aug 30 03:13:21.989264 2026] [authz_core:error] [pid 524122:tid 524278] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory0
[Sun Aug 30 03:13:21.989614 2026] [authz_core:error] [pid 524122:tid 524278] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory0
[Sun Aug 30 03:13:22.003989 2026] [security2:error] [pid 524122:tid 524269] [client 20.220.10.235:48872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/admin.php/csv.php"] [unique_id "apPmIn3lhEjKFiK_nBKNkgAAAZ8"]
[Sun Aug 30 03:13:22.003988 2026] [security2:error] [pid 524122:tid 524340] [client 20.48.147.90:51293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/indoxploit_shell.php"] [unique_id "apPmIn3lhEjKFiK_nBKNkQAAAeY"]
[Sun Aug 30 03:13:22.015011 2026] [security2:error] [pid 524122:tid 524344] [client 185.93.89.167:53189] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPmIn3lhEjKFiK_nBKNlgAAAeo"]
[Sun Aug 30 03:13:22.018060 2026] [authz_core:error] [pid 524122:tid 524333] [client 66.249.66.69:47123] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:22.018328 2026] [authz_core:error] [pid 524122:tid 524333] [client 66.249.66.69:47123] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:22.020401 2026] [security2:error] [pid 524122:tid 524331] [client 185.93.89.167:65207] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/system/.env"] [unique_id "apPmIn3lhEjKFiK_nBKNlwAAAd0"]
[Sun Aug 30 03:13:22.040982 2026] [security2:error] [pid 524122:tid 524287] [client 20.104.50.220:30935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-admin/about.php"] [unique_id "apPmIn3lhEjKFiK_nBKNmQAAAbE"]
[Sun Aug 30 03:13:22.047789 2026] [security2:error] [pid 524122:tid 524300] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/frontend/.env"] [unique_id "apPmIn3lhEjKFiK_nBKNmwAAAb4"]
[Sun Aug 30 03:13:22.060625 2026] [security2:error] [pid 524122:tid 524290] [client 20.48.147.90:45251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/alfav.php"] [unique_id "apPmIn3lhEjKFiK_nBKNngAAAbQ"]
[Sun Aug 30 03:13:22.061172 2026] [authz_core:error] [pid 524122:tid 524317] [client 66.249.66.65:37483] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:22.061459 2026] [authz_core:error] [pid 524122:tid 524317] [client 66.249.66.65:37483] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:22.080871 2026] [security2:error] [pid 524122:tid 524285] [client 185.93.89.167:11981] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns12.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPmIn3lhEjKFiK_nBKNoQAAAa8"]
[Sun Aug 30 03:13:22.086706 2026] [security2:error] [pid 524122:tid 524334] [client 20.48.251.3:36904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/atex1.php"] [unique_id "apPmIn3lhEjKFiK_nBKNogAAAeA"]
[Sun Aug 30 03:13:22.116304 2026] [security2:error] [pid 524122:tid 524274] [client 185.93.89.167:34059] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPmIn3lhEjKFiK_nBKNpgAAAaQ"]
[Sun Aug 30 03:13:22.124993 2026] [security2:error] [pid 524122:tid 524328] [client 185.93.89.167:37409] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/source/.env"] [unique_id "apPmIn3lhEjKFiK_nBKNqAAAAdo"]
[Sun Aug 30 03:13:22.139511 2026] [security2:error] [pid 524122:tid 524329] [client 20.220.10.235:48646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/admin.php/700.php"] [unique_id "apPmIn3lhEjKFiK_nBKNqgAAAds"]
[Sun Aug 30 03:13:22.144131 2026] [security2:error] [pid 524122:tid 524311] [client 185.93.89.167:43537] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/laravel/.env"] [unique_id "apPmIn3lhEjKFiK_nBKNrAAAAck"]
[Sun Aug 30 03:13:22.144288 2026] [security2:error] [pid 524122:tid 524303] [client 158.23.147.79:52706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-l0gin.php"] [unique_id "apPmIn3lhEjKFiK_nBKNrQAAAcE"]
[Sun Aug 30 03:13:22.148405 2026] [security2:error] [pid 524122:tid 524293] [client 20.48.147.90:51287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/sbh.php"] [unique_id "apPmIn3lhEjKFiK_nBKNrwAAAbc"]
[Sun Aug 30 03:13:22.148580 2026] [security2:error] [pid 524122:tid 524332] [client 185.93.89.167:53189] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPmIn3lhEjKFiK_nBKNrgAAAd4"]
[Sun Aug 30 03:13:22.153047 2026] [security2:error] [pid 524122:tid 524275] [client 185.93.89.167:65207] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "otrs.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPmIn3lhEjKFiK_nBKNsQAAAaU"]
[Sun Aug 30 03:13:22.153781 2026] [security2:error] [pid 524122:tid 524342] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/src/.env"] [unique_id "apPmIn3lhEjKFiK_nBKNsAAAAeg"]
[Sun Aug 30 03:13:22.172802 2026] [security2:error] [pid 524122:tid 524362] [client 20.104.50.220:17337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/.well-known/53.php"] [unique_id "apPmIn3lhEjKFiK_nBKNtgAAAfw"]
[Sun Aug 30 03:13:22.210458 2026] [security2:error] [pid 524122:tid 524369] [client 20.48.147.90:61637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/alpas.php"] [unique_id "apPmIn3lhEjKFiK_nBKNxgAAAgM"]
[Sun Aug 30 03:13:22.215188 2026] [security2:error] [pid 524122:tid 524355] [client 185.93.89.167:11981] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns12.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPmIn3lhEjKFiK_nBKNxwAAAfU"]
[Sun Aug 30 03:13:22.223002 2026] [security2:error] [pid 524122:tid 524376] [client 185.93.89.167:4321] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPmIn3lhEjKFiK_nBKNyQAAAgo"]
[Sun Aug 30 03:13:22.231049 2026] [security2:error] [pid 524122:tid 524323] [client 68.155.159.216:60303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/wp-content/cong.php"] [unique_id "apPmIn3lhEjKFiK_nBKNywAAAdU"]
[Sun Aug 30 03:13:22.255640 2026] [security2:error] [pid 524122:tid 524374] [client 185.93.89.167:34059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "web01.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPmIn3lhEjKFiK_nBKNzQAAAgg"]
[Sun Aug 30 03:13:22.266572 2026] [authz_core:error] [pid 524122:tid 524277] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:22.266923 2026] [authz_core:error] [pid 524122:tid 524277] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:22.270428 2026] [security2:error] [pid 524122:tid 524307] [client 20.104.49.130:59553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/t.php"] [unique_id "apPmIn3lhEjKFiK_nBKN0QAAAcU"]
[Sun Aug 30 03:13:22.278345 2026] [security2:error] [pid 524122:tid 524299] [client 185.93.89.167:43537] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/core/.env"] [unique_id "apPmIn3lhEjKFiK_nBKN0gAAAb0"]
[Sun Aug 30 03:13:22.281907 2026] [security2:error] [pid 524122:tid 524257] [client 185.93.89.167:53189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digital.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPmIn3lhEjKFiK_nBKN0wAAAZM"]
[Sun Aug 30 03:13:22.285110 2026] [security2:error] [pid 524122:tid 524318] [client 20.48.147.90:47134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/bh.php"] [unique_id "apPmIn3lhEjKFiK_nBKN1AAAAdA"]
[Sun Aug 30 03:13:22.288014 2026] [security2:error] [pid 524122:tid 524370] [client 158.23.147.79:55388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-content/plugins/google-seo-rank/module.php"] [unique_id "apPmIn3lhEjKFiK_nBKN1QAAAgQ"]
[Sun Aug 30 03:13:22.295076 2026] [security2:error] [pid 524122:tid 524282] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/core/.env"] [unique_id "apPmIn3lhEjKFiK_nBKN1gAAAaw"]
[Sun Aug 30 03:13:22.297639 2026] [security2:error] [pid 524122:tid 524372] [client 20.220.10.235:48695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/admin.php/007x.php"] [unique_id "apPmIn3lhEjKFiK_nBKN1wAAAgY"]
[Sun Aug 30 03:13:22.318712 2026] [security2:error] [pid 524122:tid 524269] [client 158.23.147.79:61766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/banners/about.php"] [unique_id "apPmIn3lhEjKFiK_nBKN2AAAAZ8"]
[Sun Aug 30 03:13:22.324439 2026] [security2:error] [pid 524122:tid 524312] [client 20.104.49.130:35584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/x1da.php"] [unique_id "apPmIn3lhEjKFiK_nBKN2gAAAco"]
[Sun Aug 30 03:13:22.335110 2026] [security2:error] [pid 524122:tid 524344] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/core/app/.env"] [unique_id "apPmIn3lhEjKFiK_nBKN2wAAAeo"]
[Sun Aug 30 03:13:22.340283 2026] [authz_core:error] [pid 524122:tid 524348] [client 66.249.66.195:43543] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:22.340552 2026] [authz_core:error] [pid 524122:tid 524348] [client 66.249.66.195:43543] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:22.342681 2026] [security2:error] [pid 524122:tid 524371] [client 185.93.89.167:65083] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/server/.env"] [unique_id "apPmIn3lhEjKFiK_nBKN4AAAAgU"]
[Sun Aug 30 03:13:22.345335 2026] [security2:error] [pid 524122:tid 524259] [client 20.104.50.220:33037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/local.php"] [unique_id "apPmIn3lhEjKFiK_nBKN4QAAAZU"]
[Sun Aug 30 03:13:22.348207 2026] [security2:error] [pid 524122:tid 524354] [client 185.93.89.167:11981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ns12.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPmIn3lhEjKFiK_nBKN4wAAAfQ"]
[Sun Aug 30 03:13:22.359636 2026] [security2:error] [pid 524122:tid 524288] [client 185.93.89.167:64231] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/source/.env"] [unique_id "apPmIn3lhEjKFiK_nBKN5gAAAbI"]
[Sun Aug 30 03:13:22.365779 2026] [security2:error] [pid 524122:tid 524341] [client 4.205.62.107:17311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fcconveyancing.com.au"] [uri "/aws_config.php"] [unique_id "apPmIn3lhEjKFiK_nBKN5wAAAec"]
[Sun Aug 30 03:13:22.379186 2026] [security2:error] [pid 524122:tid 524302] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/config/.env"] [unique_id "apPmIn3lhEjKFiK_nBKN6gAAAcA"]
[Sun Aug 30 03:13:22.391683 2026] [security2:error] [pid 524122:tid 524305] [client 20.104.50.220:5907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/r.php"] [unique_id "apPmIn3lhEjKFiK_nBKN7gAAAcM"]
[Sun Aug 30 03:13:22.395204 2026] [security2:error] [pid 524122:tid 524373] [client 20.48.147.90:61581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/alfa.php"] [unique_id "apPmIn3lhEjKFiK_nBKN8AAAAgc"]
[Sun Aug 30 03:13:22.395573 2026] [security2:error] [pid 524122:tid 524351] [client 185.93.89.167:37409] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPmIn3lhEjKFiK_nBKN7wAAAfE"]
[Sun Aug 30 03:13:22.396230 2026] [security2:error] [pid 524122:tid 524231] [remote 112.78.134.58:35602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.134.78.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "paulgarrigan.com"] [uri "/wp-login.php"] [unique_id "apPmIn3lhEjKFiK_nBKN7AABvGs"]
[Sun Aug 30 03:13:22.397685 2026] [security2:error] [pid 524122:tid 524328] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/backend/.env"] [unique_id "apPmIn3lhEjKFiK_nBKN8QAAAdo"]
[Sun Aug 30 03:13:22.402929 2026] [security2:error] [pid 524122:tid 524241] [remote 93.109.69.170:63863] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "tastylandscape.com"] [uri "/wp-content/plugins/burst-statistics/endpoint.php"] [unique_id "apPmIn3lhEjKFiK_nBKN8wABlHU"], referer: https://tastylandscape.com/2013/05/07/how-to-propagate-rosemary/
[Sun Aug 30 03:13:22.420399 2026] [security2:error] [pid 524122:tid 524324] [client 52.139.37.240:9400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-seo.php"] [unique_id "apPmIn3lhEjKFiK_nBKN9wAAAdY"]
[Sun Aug 30 03:13:22.434396 2026] [security2:error] [pid 524122:tid 524332] [client 20.48.147.90:47152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/sh3ll.php"] [unique_id "apPmIn3lhEjKFiK_nBKN-QAAAd4"]
[Sun Aug 30 03:13:22.441532 2026] [security2:error] [pid 524122:tid 524321] [client 20.220.10.235:48688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/admin.php/heex.php"] [unique_id "apPmIn3lhEjKFiK_nBKN-wAAAdM"]
[Sun Aug 30 03:13:22.476122 2026] [authz_core:error] [pid 524122:tid 524253] [client 66.249.66.70:44106] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:22.476404 2026] [authz_core:error] [pid 524122:tid 524253] [client 66.249.66.70:44106] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:22.479636 2026] [security2:error] [pid 524122:tid 524314] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/private/.env"] [unique_id "apPmIn3lhEjKFiK_nBKOAgAAAcw"]
[Sun Aug 30 03:13:22.484424 2026] [security2:error] [pid 524122:tid 524281] [client 185.93.89.167:45015] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPmIn3lhEjKFiK_nBKOAwAAAas"]
[Sun Aug 30 03:13:22.514446 2026] [authz_core:error] [pid 524122:tid 524347] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory6
[Sun Aug 30 03:13:22.514792 2026] [authz_core:error] [pid 524122:tid 524347] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory6
[Sun Aug 30 03:13:22.518655 2026] [security2:error] [pid 524122:tid 524330] [client 185.93.89.167:61189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "forms.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPmIn3lhEjKFiK_nBKODQAAAdw"]
[Sun Aug 30 03:13:22.518961 2026] [security2:error] [pid 524122:tid 524375] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/application/.env"] [unique_id "apPmIn3lhEjKFiK_nBKODAAAAgk"]
[Sun Aug 30 03:13:22.519302 2026] [security2:error] [pid 524122:tid 524256] [client 20.104.50.220:24939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/kj.php"] [unique_id "apPmIn3lhEjKFiK_nBKODgAAAZI"]
[Sun Aug 30 03:13:22.522275 2026] [security2:error] [pid 524122:tid 524374] [client 185.93.89.167:10317] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/system/.env"] [unique_id "apPmIn3lhEjKFiK_nBKODwAAAgg"]
[Sun Aug 30 03:13:22.529702 2026] [security2:error] [pid 524122:tid 524270] [client 185.93.89.167:37409] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPmIn3lhEjKFiK_nBKOEAAAAaA"]
[Sun Aug 30 03:13:22.534852 2026] [security2:error] [pid 524122:tid 524315] [client 20.197.61.180:13526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/alfa.php"] [unique_id "apPmIn3lhEjKFiK_nBKOEQAAAc0"]
[Sun Aug 30 03:13:22.544544 2026] [authz_core:error] [pid 524122:tid 524296] [client 216.73.216.128:12249] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:22.544948 2026] [authz_core:error] [pid 524122:tid 524296] [client 216.73.216.128:12249] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:22.546680 2026] [security2:error] [pid 524122:tid 524307] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/server/.env"] [unique_id "apPmIn3lhEjKFiK_nBKOFAAAAcU"]
[Sun Aug 30 03:13:22.548699 2026] [security2:error] [pid 524122:tid 524337] [client 185.93.89.167:11257] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/system/.env"] [unique_id "apPmIn3lhEjKFiK_nBKOFgAAAeM"]
[Sun Aug 30 03:13:22.550359 2026] [security2:error] [pid 524122:tid 524308] [client 4.205.62.107:52896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/sdsa.php"] [unique_id "apPmIn3lhEjKFiK_nBKOFwAAAcY"]
[Sun Aug 30 03:13:22.563089 2026] [security2:error] [pid 524122:tid 524318] [client 4.205.62.107:32056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/cp2.php"] [unique_id "apPmIn3lhEjKFiK_nBKOGgAAAdA"]
[Sun Aug 30 03:13:22.568544 2026] [security2:error] [pid 524122:tid 524338] [client 20.220.10.235:48698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/tf.php"] [unique_id "apPmIn3lhEjKFiK_nBKOHAAAAeQ"]
[Sun Aug 30 03:13:22.577927 2026] [security2:error] [pid 524122:tid 524370] [client 20.48.147.90:47139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/shell.php"] [unique_id "apPmIn3lhEjKFiK_nBKOHQAAAgQ"]
[Sun Aug 30 03:13:22.579442 2026] [security2:error] [pid 524122:tid 524360] [client 20.151.200.44:52133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.uprisetattoos.com"] [uri "/waf.php"] [unique_id "apPmIn3lhEjKFiK_nBKOHgAAAfo"]
[Sun Aug 30 03:13:22.593247 2026] [security2:error] [pid 524122:tid 524255] [client 185.93.89.167:10837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m1.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPmIn3lhEjKFiK_nBKOHwAAAZE"]
[Sun Aug 30 03:13:22.599617 2026] [security2:error] [pid 524122:tid 524344] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/bootstrap/.env"] [unique_id "apPmIn3lhEjKFiK_nBKOIQAAAeo"]
[Sun Aug 30 03:13:22.614482 2026] [security2:error] [pid 524122:tid 524300] [client 185.93.89.167:30637] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns12.mariegronley.com"] [uri "/system/.env"] [unique_id "apPmIn3lhEjKFiK_nBKOJAAAAb4"]
[Sun Aug 30 03:13:22.629466 2026] [security2:error] [pid 524122:tid 524289] [client 185.93.89.167:64231] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPmIn3lhEjKFiK_nBKOKAAAAbM"]
[Sun Aug 30 03:13:22.635786 2026] [security2:error] [pid 524122:tid 524263] [client 185.93.89.167:24333] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/source/.env"] [unique_id "apPmIn3lhEjKFiK_nBKOKgAAAZk"]
[Sun Aug 30 03:13:22.640801 2026] [security2:error] [pid 524122:tid 524356] [client 20.197.61.180:11542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "a220training.com"] [uri "/wp-content/themes/options.php"] [unique_id "apPmIn3lhEjKFiK_nBKOKwAAAfY"]
[Sun Aug 30 03:13:22.646899 2026] [security2:error] [pid 524122:tid 524282] [client 52.139.37.240:9479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/zwso.php"] [unique_id "apPmIn3lhEjKFiK_nBKOLAAAAaw"]
[Sun Aug 30 03:13:22.654977 2026] [security2:error] [pid 524122:tid 524284] [client 185.93.89.167:10317] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "web01.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPmIn3lhEjKFiK_nBKOMAAAAa4"]
[Sun Aug 30 03:13:22.662796 2026] [security2:error] [pid 524122:tid 524305] [client 185.93.89.167:37409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www7.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPmIn3lhEjKFiK_nBKOMQAAAcM"]
[Sun Aug 30 03:13:22.669262 2026] [security2:error] [pid 524122:tid 524334] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/database/.env"] [unique_id "apPmIn3lhEjKFiK_nBKOMgAAAeA"]
[Sun Aug 30 03:13:22.676283 2026] [security2:error] [pid 524122:tid 524309] [client 20.48.147.90:61646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/0byte.php"] [unique_id "apPmIn3lhEjKFiK_nBKOMwAAAcc"]
[Sun Aug 30 03:13:22.681297 2026] [security2:error] [pid 524122:tid 524351] [client 185.93.89.167:11257] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "digital.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPmIn3lhEjKFiK_nBKONAAAAfE"]
[Sun Aug 30 03:13:22.682129 2026] [security2:error] [pid 524122:tid 524265] [client 185.93.89.167:43537] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/app/.env"] [unique_id "apPmIn3lhEjKFiK_nBKONQAAAZs"]
[Sun Aug 30 03:13:22.695026 2026] [security2:error] [pid 524122:tid 524352] [client 20.220.10.235:48697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/update/da222.php"] [unique_id "apPmIn3lhEjKFiK_nBKOOQAAAfI"]
[Sun Aug 30 03:13:22.696263 2026] [security2:error] [pid 524122:tid 524342] [client 20.197.61.180:11739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "demandthetruth.michaelegenolf.com"] [uri "/wp-content/themes/news-portal/error.php"] [unique_id "apPmIn3lhEjKFiK_nBKOOgAAAeg"]
[Sun Aug 30 03:13:22.702048 2026] [security2:error] [pid 524122:tid 524335] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/frontend/.env"] [unique_id "apPmIn3lhEjKFiK_nBKOPAAAAeE"]
[Sun Aug 30 03:13:22.704231 2026] [security2:error] [pid 524122:tid 524324] [client 4.205.62.107:15944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/phpsysinfo.php"] [unique_id "apPmIn3lhEjKFiK_nBKOPQAAAdY"]
[Sun Aug 30 03:13:22.705510 2026] [security2:error] [pid 524122:tid 524303] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/storage/.env"] [unique_id "apPmIn3lhEjKFiK_nBKOPgAAAcE"]
[Sun Aug 30 03:13:22.723768 2026] [authz_core:error] [pid 524122:tid 524327] [client 216.73.216.128:48018] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:22.723854 2026] [security2:error] [pid 524122:tid 524321] [client 20.48.147.90:51383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/indonesia.php"] [unique_id "apPmIn3lhEjKFiK_nBKOQAAAAdM"]
[Sun Aug 30 03:13:22.724174 2026] [authz_core:error] [pid 524122:tid 524327] [client 216.73.216.128:48018] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:22.742587 2026] [security2:error] [pid 524122:tid 524266] [client 4.205.62.107:15939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/css.php"] [unique_id "apPmIn3lhEjKFiK_nBKOQgAAAZw"]
[Sun Aug 30 03:13:22.747159 2026] [security2:error] [pid 524122:tid 524363] [client 185.93.89.167:65083] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPmIn3lhEjKFiK_nBKOQwAAAf0"]
[Sun Aug 30 03:13:22.763361 2026] [security2:error] [pid 524122:tid 524291] [client 185.93.89.167:64231] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPmIn3lhEjKFiK_nBKORgAAAbU"]
[Sun Aug 30 03:13:22.765090 2026] [security2:error] [pid 524122:tid 524280] [client 158.23.147.79:54344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.myediblecravings.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPmIn3lhEjKFiK_nBKORwAAAao"]
[Sun Aug 30 03:13:22.786312 2026] [security2:error] [pid 524122:tid 524292] [client 185.93.89.167:17603] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPmIn3lhEjKFiK_nBKOSgAAAbY"]
[Sun Aug 30 03:13:22.786393 2026] [security2:error] [pid 524122:tid 524316] [client 185.93.89.167:21991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tr.mariegronley.com"] [uri "/source/.env"] [unique_id "apPmIn3lhEjKFiK_nBKOSwAAAc4"]
[Sun Aug 30 03:13:22.786555 2026] [authz_core:error] [pid 524122:tid 524268] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:22.786819 2026] [authz_core:error] [pid 524122:tid 524268] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:22.797314 2026] [security2:error] [pid 524122:tid 524326] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/var/www/.env"] [unique_id "apPmIn3lhEjKFiK_nBKOTQAAAdg"]
[Sun Aug 30 03:13:22.803554 2026] [security2:error] [pid 524122:tid 524281] [client 158.23.147.79:59064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-content/themes/digital-download/new.php"] [unique_id "apPmIn3lhEjKFiK_nBKOTgAAAas"]
[Sun Aug 30 03:13:22.815803 2026] [security2:error] [pid 524122:tid 524283] [client 185.93.89.167:43537] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/dev/.env"] [unique_id "apPmIn3lhEjKFiK_nBKOUAAAAa0"]
[Sun Aug 30 03:13:22.824322 2026] [security2:error] [pid 524122:tid 524258] [client 185.93.89.167:56185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "otrs.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPmIn3lhEjKFiK_nBKOUQAAAZQ"]
[Sun Aug 30 03:13:22.824803 2026] [security2:error] [pid 524122:tid 524286] [client 20.220.10.235:48673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/qi.php"] [unique_id "apPmIn3lhEjKFiK_nBKOUgAAAbA"]
[Sun Aug 30 03:13:22.834261 2026] [security2:error] [pid 524122:tid 524330] [client 20.104.50.220:51622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/kndw1.php"] [unique_id "apPmIn3lhEjKFiK_nBKOUwAAAdw"]
[Sun Aug 30 03:13:22.836321 2026] [security2:error] [pid 524122:tid 524375] [client 20.48.147.90:64011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/index3.php"] [unique_id "apPmIn3lhEjKFiK_nBKOVQAAAgk"]
[Sun Aug 30 03:13:22.838039 2026] [security2:error] [pid 524122:tid 524298] [client 168.119.123.75:39284] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rantica.it"] [uri "/index.html"] [unique_id "apPmIn3lhEjKFiK_nBKOVAAAAbw"], referer: https://rantica.it
[Sun Aug 30 03:13:22.851110 2026] [security2:error] [pid 524122:tid 524365] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/src/.env"] [unique_id "apPmIn3lhEjKFiK_nBKOVwAAAf8"]
[Sun Aug 30 03:13:22.854094 2026] [authz_core:error] [pid 524122:tid 524366] [client 66.249.66.40:35569] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:22.854350 2026] [authz_core:error] [pid 524122:tid 524366] [client 66.249.66.40:35569] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:22.859920 2026] [security2:error] [pid 524122:tid 524374] [client 185.93.89.167:2495] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPmIn3lhEjKFiK_nBKOWAAAAgg"]
[Sun Aug 30 03:13:22.861358 2026] [security2:error] [pid 524122:tid 524270] [client 20.48.147.90:47150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/1n73ction.php"] [unique_id "apPmIn3lhEjKFiK_nBKOWgAAAaA"]
[Sun Aug 30 03:13:22.863845 2026] [security2:error] [pid 524122:tid 524243] [remote 112.78.134.58:35602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.134.78.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "paulgarrigan.com"] [uri "/wp-login.php"] [unique_id "apPmIn3lhEjKFiK_nBKOWQABzXc"], referer: https://paulgarrigan.com/wp-login.php
[Sun Aug 30 03:13:22.865100 2026] [security2:error] [pid 524122:tid 524307] [client 20.104.18.15:51043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/os.php"] [unique_id "apPmIn3lhEjKFiK_nBKOWwAAAcU"]
[Sun Aug 30 03:13:22.868731 2026] [security2:error] [pid 524122:tid 524364] [client 20.104.50.220:52814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/kntol.php"] [unique_id "apPmIn3lhEjKFiK_nBKOXAAAAf4"]
[Sun Aug 30 03:13:22.871109 2026] [security2:error] [pid 524122:tid 524301] [client 52.139.37.240:9512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/user.php"] [unique_id "apPmIn3lhEjKFiK_nBKOXQAAAb8"]
[Sun Aug 30 03:13:22.878730 2026] [security2:error] [pid 524122:tid 524313] [client 158.23.147.79:61987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/Text/about.php"] [unique_id "apPmIn3lhEjKFiK_nBKOXgAAAcs"]
[Sun Aug 30 03:13:22.887363 2026] [security2:error] [pid 524122:tid 524318] [client 20.104.18.15:22500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/dev.php"] [unique_id "apPmIn3lhEjKFiK_nBKOYAAAAdA"]
[Sun Aug 30 03:13:22.894322 2026] [security2:error] [pid 524122:tid 524370] [client 185.93.89.167:4321] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/source/.env"] [unique_id "apPmIn3lhEjKFiK_nBKOYgAAAgQ"]
[Sun Aug 30 03:13:22.896362 2026] [security2:error] [pid 524122:tid 524360] [client 185.93.89.167:64231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kb.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPmIn3lhEjKFiK_nBKOYwAAAfo"]
[Sun Aug 30 03:13:22.903846 2026] [security2:error] [pid 524122:tid 524344] [client 185.93.89.167:24333] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPmIn3lhEjKFiK_nBKOZQAAAeo"]
[Sun Aug 30 03:13:22.913353 2026] [security2:error] [pid 524122:tid 524358] [client 20.104.49.130:63527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.thepiako.com"] [uri "/wp-blogs.php"] [unique_id "apPmIn3lhEjKFiK_nBKOZwAAAfg"]
[Sun Aug 30 03:13:22.913437 2026] [security2:error] [pid 524122:tid 524312] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/var/www/html/.env"] [unique_id "apPmIn3lhEjKFiK_nBKOZgAAAco"]
[Sun Aug 30 03:13:22.928555 2026] [security2:error] [pid 524122:tid 524300] [client 185.93.89.167:30755] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/system/.env"] [unique_id "apPmIn3lhEjKFiK_nBKObAAAAb4"]
[Sun Aug 30 03:13:22.956177 2026] [security2:error] [pid 524122:tid 524341] [client 20.220.10.235:48675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/px.php"] [unique_id "apPmIn3lhEjKFiK_nBKObwAAAec"]
[Sun Aug 30 03:13:22.969765 2026] [authz_core:error] [pid 524122:tid 524304] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory5
[Sun Aug 30 03:13:22.970032 2026] [authz_core:error] [pid 524122:tid 524304] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory5
[Sun Aug 30 03:13:22.973308 2026] [security2:error] [pid 524122:tid 524294] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/current/.env"] [unique_id "apPmIn3lhEjKFiK_nBKOcQAAAbg"]
[Sun Aug 30 03:13:22.992901 2026] [security2:error] [pid 524122:tid 524309] [client 20.48.147.90:47145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/374k.php"] [unique_id "apPmIn3lhEjKFiK_nBKOdAAAAcc"]
[Sun Aug 30 03:13:22.996828 2026] [security2:error] [pid 524122:tid 524373] [client 20.48.147.90:45290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/index2.php"] [unique_id "apPmIn3lhEjKFiK_nBKOdQAAAgc"]
[Sun Aug 30 03:13:23.002788 2026] [security2:error] [pid 524122:tid 524351] [client 158.23.147.79:56140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.myediblecravings.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPmI33lhEjKFiK_nBKOdgAAAfE"]
[Sun Aug 30 03:13:23.008417 2026] [security2:error] [pid 524122:tid 524265] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/core/.env"] [unique_id "apPmI33lhEjKFiK_nBKOdwAAAZs"]
[Sun Aug 30 03:13:23.014053 2026] [security2:error] [pid 524122:tid 524254] [client 159.65.217.202:62381] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "beyondmycross.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "apPmI33lhEjKFiK_nBKOeAAAAZA"]
[Sun Aug 30 03:13:23.028999 2026] [security2:error] [pid 524122:tid 524329] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/release/.env"] [unique_id "apPmI33lhEjKFiK_nBKOfQAAAds"]
[Sun Aug 30 03:13:23.037022 2026] [security2:error] [pid 524122:tid 524335] [client 185.93.89.167:24333] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPmI33lhEjKFiK_nBKOfgAAAeE"]
[Sun Aug 30 03:13:23.054480 2026] [security2:error] [pid 524122:tid 524293] [client 185.93.89.167:17603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "forms.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPmI33lhEjKFiK_nBKOfwAAAbc"]
[Sun Aug 30 03:13:23.061230 2026] [security2:error] [pid 524122:tid 524367] [client 185.93.89.167:30755] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www7.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPmI33lhEjKFiK_nBKOggAAAgE"]
[Sun Aug 30 03:13:23.076091 2026] [security2:error] [pid 524122:tid 524347] [client 52.139.37.240:9506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/as.php"] [unique_id "apPmI33lhEjKFiK_nBKOgwAAAe0"]
[Sun Aug 30 03:13:23.083882 2026] [security2:error] [pid 524122:tid 524290] [client 185.93.89.167:43537] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/server/.env"] [unique_id "apPmI33lhEjKFiK_nBKOhQAAAbQ"]
[Sun Aug 30 03:13:23.091372 2026] [security2:error] [pid 524122:tid 524377] [client 185.93.89.167:7877] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPmI33lhEjKFiK_nBKOiAAAAgs"]
[Sun Aug 30 03:13:23.092166 2026] [security2:error] [pid 524122:tid 524266] [client 20.220.10.235:48683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/is.php"] [unique_id "apPmI33lhEjKFiK_nBKOiQAAAZw"]
[Sun Aug 30 03:13:23.123750 2026] [security2:error] [pid 524122:tid 524336] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/releases/.env"] [unique_id "apPmI33lhEjKFiK_nBKOigAAAeI"]
[Sun Aug 30 03:13:23.128255 2026] [security2:error] [pid 524122:tid 524278] [client 185.93.89.167:2495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m1.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPmI33lhEjKFiK_nBKOjAAAAag"]
[Sun Aug 30 03:13:23.129050 2026] [security2:error] [pid 524122:tid 524291] [client 20.48.147.90:47120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/cmd.php"] [unique_id "apPmI33lhEjKFiK_nBKOjQAAAbU"]
[Sun Aug 30 03:13:23.131363 2026] [authz_core:error] [pid 524122:tid 524275] [client 66.249.66.68:39056] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:23.131605 2026] [authz_core:error] [pid 524122:tid 524275] [client 66.249.66.68:39056] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:23.133792 2026] [security2:error] [pid 524122:tid 524267] [client 158.23.147.79:52231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/asd.php"] [unique_id "apPmI33lhEjKFiK_nBKOjgAAAZ0"]
[Sun Aug 30 03:13:23.140707 2026] [security2:error] [pid 524122:tid 524276] [client 20.104.50.220:29318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/min.php"] [unique_id "apPmI33lhEjKFiK_nBKOkAAAAaY"]
[Sun Aug 30 03:13:23.140839 2026] [security2:error] [pid 524122:tid 524280] [client 20.48.251.3:54748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/agg.php"] [unique_id "apPmI33lhEjKFiK_nBKOjwAAAao"]
[Sun Aug 30 03:13:23.143497 2026] [security2:error] [pid 524122:tid 524362] [client 20.48.147.90:61585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/index1.php"] [unique_id "apPmI33lhEjKFiK_nBKOkQAAAfw"]
[Sun Aug 30 03:13:23.147363 2026] [security2:error] [pid 524122:tid 524292] [client 20.48.147.90:60352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.benjamindock.com"] [uri "/wp-xmlx.php"] [unique_id "apPmI33lhEjKFiK_nBKOkgAAAbY"]
[Sun Aug 30 03:13:23.158193 2026] [authz_core:error] [pid 524122:tid 524363] [client 66.249.66.39:53063] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:23.158452 2026] [authz_core:error] [pid 524122:tid 524363] [client 66.249.66.39:53063] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:23.159567 2026] [security2:error] [pid 524122:tid 524314] [client 185.93.89.167:45015] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/source/.env"] [unique_id "apPmI33lhEjKFiK_nBKOlQAAAcw"]
[Sun Aug 30 03:13:23.162120 2026] [security2:error] [pid 524122:tid 524379] [client 185.93.89.167:4321] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPmI33lhEjKFiK_nBKOlgAAAg0"]
[Sun Aug 30 03:13:23.162826 2026] [security2:error] [pid 524122:tid 524325] [client 185.93.89.167:29091] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/system/.env"] [unique_id "apPmI33lhEjKFiK_nBKOlwAAAdc"]
[Sun Aug 30 03:13:23.163079 2026] [security2:error] [pid 524122:tid 524310] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/core/app/.env"] [unique_id "apPmI33lhEjKFiK_nBKOmAAAAcg"]
[Sun Aug 30 03:13:23.169701 2026] [security2:error] [pid 524122:tid 524281] [client 185.93.89.167:24333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thumbs.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPmI33lhEjKFiK_nBKOmQAAAas"]
[Sun Aug 30 03:13:23.173208 2026] [security2:error] [pid 524122:tid 524295] [client 20.104.50.220:63207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/gmo.php"] [unique_id "apPmI33lhEjKFiK_nBKOmgAAAbk"]
[Sun Aug 30 03:13:23.179883 2026] [security2:error] [pid 524122:tid 524376] [client 20.220.10.235:33834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kerelatourism.org"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "apPmI33lhEjKFiK_nBKOmwAAAgo"]
[Sun Aug 30 03:13:23.200753 2026] [security2:error] [pid 524122:tid 524256] [client 20.104.49.130:53627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.hoslercorp.net"] [uri "/wp-good.php"] [unique_id "apPmI33lhEjKFiK_nBKOngAAAZI"]
[Sun Aug 30 03:13:23.212796 2026] [security2:error] [pid 524122:tid 524301] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/shared/.env"] [unique_id "apPmI33lhEjKFiK_nBKOoQAAAb8"]
[Sun Aug 30 03:13:23.231963 2026] [security2:error] [pid 524122:tid 524327] [client 20.48.251.3:36915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/aws_sdk_settings.php"] [unique_id "apPmI33lhEjKFiK_nBKOpgAAAdk"]
[Sun Aug 30 03:13:23.245170 2026] [authz_core:error] [pid 524122:tid 524380] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:23.245427 2026] [authz_core:error] [pid 524122:tid 524380] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:23.247044 2026] [security2:error] [pid 524122:tid 524372] [client 20.220.10.235:48648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/od.php"] [unique_id "apPmI33lhEjKFiK_nBKOqQAAAgY"]
[Sun Aug 30 03:13:23.258485 2026] [security2:error] [pid 524122:tid 524360] [client 158.23.147.79:43869] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.hebrews111.com"] [uri "/1.php"] [unique_id "apPmI33lhEjKFiK_nBKOqgAAAfo"]
[Sun Aug 30 03:13:23.258570 2026] [security2:error] [pid 524122:tid 524360] [client 158.23.147.79:43869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/1.php"] [unique_id "apPmI33lhEjKFiK_nBKOqgAAAfo"]
[Sun Aug 30 03:13:23.265775 2026] [security2:error] [pid 524122:tid 524344] [client 158.23.147.79:64778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.myediblecravings.com"] [uri "/wp-includes/blocks/post-excerpt/index.php"] [unique_id "apPmI33lhEjKFiK_nBKOqwAAAeo"]
[Sun Aug 30 03:13:23.280583 2026] [security2:error] [pid 524122:tid 524312] [client 158.23.147.79:52697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/ans.php"] [unique_id "apPmI33lhEjKFiK_nBKOrQAAAco"]
[Sun Aug 30 03:13:23.295306 2026] [security2:error] [pid 524122:tid 524300] [client 185.93.89.167:4321] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPmI33lhEjKFiK_nBKOsAAAAb4"]
[Sun Aug 30 03:13:23.295650 2026] [security2:error] [pid 524122:tid 524260] [client 20.48.147.90:51270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/jkt48_1.php"] [unique_id "apPmI33lhEjKFiK_nBKOsQAAAZY"]
[Sun Aug 30 03:13:23.295791 2026] [security2:error] [pid 524122:tid 524279] [client 185.93.89.167:29091] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "kb.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPmI33lhEjKFiK_nBKOsgAAAak"]
[Sun Aug 30 03:13:23.297814 2026] [security2:error] [pid 524122:tid 524313] [client 52.139.37.240:9503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/byp.php"] [unique_id "apPmI33lhEjKFiK_nBKOswAAAcs"]
[Sun Aug 30 03:13:23.310766 2026] [security2:error] [pid 524122:tid 524368] [client 20.104.50.220:16577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/.well-known/52.php"] [unique_id "apPmI33lhEjKFiK_nBKOtAAAAgI"]
[Sun Aug 30 03:13:23.312977 2026] [security2:error] [pid 524122:tid 524341] [client 20.220.10.235:33665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kerelatourism.org"] [uri "/this_is_a_new_hello_world.php"] [unique_id "apPmI33lhEjKFiK_nBKOtQAAAec"]
[Sun Aug 30 03:13:23.317746 2026] [security2:error] [pid 524122:tid 524357] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/config/.env"] [unique_id "apPmI33lhEjKFiK_nBKOtgAAAfc"]
[Sun Aug 30 03:13:23.323677 2026] [security2:error] [pid 524122:tid 524356] [client 185.93.89.167:34077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "web01.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPmI33lhEjKFiK_nBKOuAAAAfY"]
[Sun Aug 30 03:13:23.336958 2026] [security2:error] [pid 524122:tid 524294] [client 68.155.159.216:60341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPmI33lhEjKFiK_nBKOuQAAAbg"]
[Sun Aug 30 03:13:23.352002 2026] [security2:error] [pid 524122:tid 524328] [client 185.93.89.167:34287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digital.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPmI33lhEjKFiK_nBKOvAAAAdo"]
[Sun Aug 30 03:13:23.359053 2026] [security2:error] [pid 524122:tid 524271] [client 185.93.89.167:7877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "otrs.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPmI33lhEjKFiK_nBKOvgAAAaE"]
[Sun Aug 30 03:13:23.359272 2026] [security2:error] [pid 524122:tid 524322] [client 20.197.61.180:15048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "a220training.com"] [uri "/wp-content/themes/panel.php"] [unique_id "apPmI33lhEjKFiK_nBKOvQAAAdQ"]
[Sun Aug 30 03:13:23.388903 2026] [security2:error] [pid 524122:tid 524265] [client 158.23.147.79:64768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.myediblecravings.com"] [uri "/wp-content/plugins/index.php"] [unique_id "apPmI33lhEjKFiK_nBKOwQAAAZs"]
[Sun Aug 30 03:13:23.402514 2026] [security2:error] [pid 524122:tid 524326] [client 20.197.61.180:13533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/wp-blog-header.php"] [unique_id "apPmI33lhEjKFiK_nBKOwgAAAdg"]
[Sun Aug 30 03:13:23.422871 2026] [security2:error] [pid 524122:tid 524277] [client 185.93.89.167:65083] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/source/.env"] [unique_id "apPmI33lhEjKFiK_nBKOxAAAAac"]
[Sun Aug 30 03:13:23.423393 2026] [security2:error] [pid 524122:tid 524353] [client 20.197.61.180:11717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "demandthetruth.michaelegenolf.com"] [uri "/wp-content/themes/nvt/includes/plugins/wp-blog-header.php"] [unique_id "apPmI33lhEjKFiK_nBKOxQAAAfM"]
[Sun Aug 30 03:13:23.427348 2026] [security2:error] [pid 524122:tid 524329] [client 20.48.147.90:47167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/adminer.php"] [unique_id "apPmI33lhEjKFiK_nBKOxwAAAds"]
[Sun Aug 30 03:13:23.428183 2026] [security2:error] [pid 524122:tid 524303] [client 185.93.89.167:4321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images6.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPmI33lhEjKFiK_nBKOyQAAAcE"]
[Sun Aug 30 03:13:23.428371 2026] [security2:error] [pid 524122:tid 524335] [client 185.93.89.167:45015] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPmI33lhEjKFiK_nBKOyAAAAeE"]
[Sun Aug 30 03:13:23.429331 2026] [security2:error] [pid 524122:tid 524293] [client 20.104.49.130:57724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alarm-monitoring.net"] [uri "/33.php"] [unique_id "apPmI33lhEjKFiK_nBKOygAAAbc"]
[Sun Aug 30 03:13:23.438013 2026] [security2:error] [pid 524122:tid 524343] [client 185.93.89.167:36821] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/system/.env"] [unique_id "apPmI33lhEjKFiK_nBKOywAAAek"]
[Sun Aug 30 03:13:23.451701 2026] [security2:error] [pid 524122:tid 524340] [client 20.48.147.90:64030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/303.php"] [unique_id "apPmI33lhEjKFiK_nBKOzQAAAeY"]
[Sun Aug 30 03:13:23.452776 2026] [security2:error] [pid 524122:tid 524332] [client 20.48.147.90:58104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.benjamindock.com"] [uri "/pwp-.myluv.php"] [unique_id "apPmI33lhEjKFiK_nBKOzwAAAd4"]
[Sun Aug 30 03:13:23.453421 2026] [security2:error] [pid 524122:tid 524290] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/deploy/.env"] [unique_id "apPmI33lhEjKFiK_nBKOzgAAAbQ"]
[Sun Aug 30 03:13:23.458399 2026] [security2:error] [pid 524122:tid 524371] [client 158.23.147.79:44899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/worksec.php"] [unique_id "apPmI33lhEjKFiK_nBKO0gAAAgU"]
[Sun Aug 30 03:13:23.473176 2026] [security2:error] [pid 524122:tid 524291] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/private/.env"] [unique_id "apPmI33lhEjKFiK_nBKO0wAAAbU"]
[Sun Aug 30 03:13:23.477550 2026] [security2:error] [pid 524122:tid 524352] [client 52.139.37.240:35859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "happynerd.co"] [uri "/wp-admin/maint/index.php"] [unique_id "apPmI33lhEjKFiK_nBKO1AAAAfI"]
[Sun Aug 30 03:13:23.479256 2026] [security2:error] [pid 524122:tid 524267] [client 20.220.10.235:33847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kerelatourism.org"] [uri "/h02ugyh.php"] [unique_id "apPmI33lhEjKFiK_nBKO1QAAAZ0"]
[Sun Aug 30 03:13:23.481625 2026] [security2:error] [pid 524122:tid 524304] [client 20.104.50.220:33066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/lolzk.php"] [unique_id "apPmI33lhEjKFiK_nBKO1gAAAcI"]
[Sun Aug 30 03:13:23.486786 2026] [security2:error] [pid 524122:tid 524362] [client 185.93.89.167:43537] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/staging/.env"] [unique_id "apPmI33lhEjKFiK_nBKO2QAAAfw"]
[Sun Aug 30 03:13:23.489773 2026] [authz_core:error] [pid 524122:tid 524339] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory9
[Sun Aug 30 03:13:23.490051 2026] [authz_core:error] [pid 524122:tid 524339] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory9
[Sun Aug 30 03:13:23.491516 2026] [security2:error] [pid 524122:tid 524316] [client 4.205.62.107:17142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fcconveyancing.com.au"] [uri "/dialog.php"] [unique_id "apPmI33lhEjKFiK_nBKO2gAAAc4"]
[Sun Aug 30 03:13:23.503389 2026] [security2:error] [pid 524122:tid 524296] [client 52.139.37.240:53244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/bs1.php"] [unique_id "apPmI33lhEjKFiK_nBKO2wAAAbo"]
[Sun Aug 30 03:13:23.518450 2026] [security2:error] [pid 524122:tid 524334] [client 158.23.147.79:58684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.myediblecravings.com"] [uri "/simple.php"] [unique_id "apPmI33lhEjKFiK_nBKO3AAAAeA"]
[Sun Aug 30 03:13:23.522471 2026] [security2:error] [pid 524122:tid 524345] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/build/.env"] [unique_id "apPmI33lhEjKFiK_nBKO3QAAAes"]
[Sun Aug 30 03:13:23.541746 2026] [security2:error] [pid 524122:tid 524258] [client 20.104.50.220:5589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/q.php"] [unique_id "apPmI33lhEjKFiK_nBKO3wAAAZQ"]
[Sun Aug 30 03:13:23.562443 2026] [security2:error] [pid 524122:tid 524337] [client 185.93.89.167:45015] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPmI33lhEjKFiK_nBKO5QAAAeM"]
[Sun Aug 30 03:13:23.564915 2026] [autoindex:error] [pid 524122:tid 524349] [client 40.83.93.50:7769] AH01276: Cannot serve directory /home1/lehugh/public_html/mbhousevalue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Sun Aug 30 03:13:23.572389 2026] [security2:error] [pid 524122:tid 524378] [client 185.93.89.167:36821] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "thumbs.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPmI33lhEjKFiK_nBKO5gAAAgw"]
[Sun Aug 30 03:13:23.575986 2026] [security2:error] [pid 524122:tid 524257] [client 20.48.147.90:47128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/rootx.php"] [unique_id "apPmI33lhEjKFiK_nBKO5wAAAZM"]
[Sun Aug 30 03:13:23.580617 2026] [security2:error] [pid 524122:tid 524318] [client 158.23.147.79:43884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/ws.php"] [unique_id "apPmI33lhEjKFiK_nBKO6QAAAdA"]
[Sun Aug 30 03:13:23.589260 2026] [authz_core:error] [pid 524122:tid 524323] [client 66.249.66.202:43003] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:23.589548 2026] [authz_core:error] [pid 524122:tid 524323] [client 66.249.66.202:43003] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:23.590796 2026] [security2:error] [pid 524122:tid 524370] [client 185.93.89.167:11205] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPmI33lhEjKFiK_nBKO7AAAAgQ"]
[Sun Aug 30 03:13:23.601982 2026] [security2:error] [pid 524122:tid 524269] [client 20.48.147.90:61569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/505.php"] [unique_id "apPmI33lhEjKFiK_nBKO7gAAAZ8"]
[Sun Aug 30 03:13:23.608049 2026] [security2:error] [pid 524122:tid 524346] [client 20.220.10.235:33798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kerelatourism.org"] [uri "/sf.php"] [unique_id "apPmI33lhEjKFiK_nBKO7wAAAew"]
[Sun Aug 30 03:13:23.619561 2026] [security2:error] [pid 524122:tid 524306] [client 185.93.89.167:27755] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPmI33lhEjKFiK_nBKO8QAAAcQ"]
[Sun Aug 30 03:13:23.631833 2026] [security2:error] [pid 524122:tid 524300] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/application/.env"] [unique_id "apPmI33lhEjKFiK_nBKO9QAAAb4"]
[Sun Aug 30 03:13:23.634130 2026] [security2:error] [pid 524122:tid 524260] [client 158.23.147.79:52718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/x.php"] [unique_id "apPmI33lhEjKFiK_nBKO9wAAAZY"]
[Sun Aug 30 03:13:23.637713 2026] [authz_core:error] [pid 524122:tid 524259] [client 66.249.66.194:56165] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:23.638060 2026] [authz_core:error] [pid 524122:tid 524259] [client 66.249.66.194:56165] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:23.643582 2026] [authz_core:error] [pid 524122:tid 524288] [client 216.73.216.128:12249] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:23.643859 2026] [authz_core:error] [pid 524122:tid 524288] [client 216.73.216.128:12249] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:23.656525 2026] [authz_core:error] [pid 524122:tid 524302] [client 66.249.66.66:37171] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:23.656805 2026] [authz_core:error] [pid 524122:tid 524302] [client 66.249.66.66:37171] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:23.666088 2026] [security2:error] [pid 524122:tid 524283] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/dist/.env"] [unique_id "apPmI33lhEjKFiK_nBKO_wAAAa0"]
[Sun Aug 30 03:13:23.669276 2026] [security2:error] [pid 524122:tid 524311] [client 20.104.50.220:25450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/xxx.php"] [unique_id "apPmI33lhEjKFiK_nBKPAgAAAck"]
[Sun Aug 30 03:13:23.670767 2026] [security2:error] [pid 524122:tid 524255] [client 52.139.37.240:36290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "happynerd.co"] [uri "/wp-content/uploads/min.php"] [unique_id "apPmI33lhEjKFiK_nBKPAwAAAZE"]
[Sun Aug 30 03:13:23.671930 2026] [security2:error] [pid 524122:tid 524309] [client 20.48.147.90:58077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.benjamindock.com"] [uri "/wihp1.php"] [unique_id "apPmI33lhEjKFiK_nBKPBAAAAcc"]
[Sun Aug 30 03:13:23.681003 2026] [security2:error] [pid 524122:tid 524358] [client 158.23.147.79:64808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.myediblecravings.com"] [uri "/wp-admin/about.php"] [unique_id "apPmI33lhEjKFiK_nBKPBgAAAfg"]
[Sun Aug 30 03:13:23.692189 2026] [security2:error] [pid 524122:tid 524351] [client 185.93.89.167:65083] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPmI33lhEjKFiK_nBKPBwAAAfE"]
[Sun Aug 30 03:13:23.694416 2026] [security2:error] [pid 524122:tid 524265] [client 185.93.89.167:59301] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/system/.env"] [unique_id "apPmI33lhEjKFiK_nBKPCAAAAZs"]
[Sun Aug 30 03:13:23.695855 2026] [security2:error] [pid 524122:tid 524274] [client 185.93.89.167:45015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "analytics.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPmI33lhEjKFiK_nBKPCQAAAaQ"]
[Sun Aug 30 03:13:23.699669 2026] [security2:error] [pid 524122:tid 524279] [client 52.139.37.240:9357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-includes/IXR/allez.php"] [unique_id "apPmI33lhEjKFiK_nBKPCgAAAak"]
[Sun Aug 30 03:13:23.703323 2026] [security2:error] [pid 524122:tid 524254] [client 20.48.147.90:47154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/ls.php"] [unique_id "apPmI33lhEjKFiK_nBKPCwAAAZA"]
[Sun Aug 30 03:13:23.709271 2026] [security2:error] [pid 524122:tid 524277] [client 4.205.62.107:32457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/xda.php"] [unique_id "apPmI33lhEjKFiK_nBKPDAAAAac"]
[Sun Aug 30 03:13:23.712583 2026] [security2:error] [pid 524122:tid 524353] [client 20.220.10.235:48836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/wp-the.php"] [unique_id "apPmI33lhEjKFiK_nBKPDQAAAfM"]
[Sun Aug 30 03:13:23.731231 2026] [security2:error] [pid 524122:tid 524293] [client 4.205.62.107:29139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/sale.php"] [unique_id "apPmI33lhEjKFiK_nBKPEAAAAbc"]
[Sun Aug 30 03:13:23.738567 2026] [authz_core:error] [pid 524122:tid 524321] [client 216.73.216.128:35898] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:23.739006 2026] [authz_core:error] [pid 524122:tid 524321] [client 216.73.216.128:35898] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:23.740801 2026] [security2:error] [pid 524122:tid 524332] [client 20.220.10.235:33814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kerelatourism.org"] [uri "/4e.php"] [unique_id "apPmI33lhEjKFiK_nBKPEQAAAd4"]
[Sun Aug 30 03:13:23.744773 2026] [security2:error] [pid 524122:tid 524290] [client 20.48.147.90:64010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/500.php"] [unique_id "apPmI33lhEjKFiK_nBKPEwAAAbQ"]
[Sun Aug 30 03:13:23.756678 2026] [security2:error] [pid 524122:tid 524291] [client 158.23.147.79:44891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-content/x.php"] [unique_id "apPmI33lhEjKFiK_nBKPFwAAAbU"]
[Sun Aug 30 03:13:23.769769 2026] [security2:error] [pid 524122:tid 524276] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/public_html/.env"] [unique_id "apPmI33lhEjKFiK_nBKPGgAAAaY"]
[Sun Aug 30 03:13:23.773851 2026] [authz_core:error] [pid 524122:tid 524304] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:23.774121 2026] [authz_core:error] [pid 524122:tid 524304] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:23.774418 2026] [security2:error] [pid 524122:tid 524362] [client 185.93.89.167:32699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m1.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPmI33lhEjKFiK_nBKPGwAAAfw"]
[Sun Aug 30 03:13:23.812050 2026] [security2:error] [pid 524122:tid 524310] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/bootstrap/.env"] [unique_id "apPmI33lhEjKFiK_nBKPHAAAAcg"]
[Sun Aug 30 03:13:23.821443 2026] [security2:error] [pid 524122:tid 524295] [client 20.48.147.90:58103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.benjamindock.com"] [uri "/wp-blog.php"] [unique_id "apPmI33lhEjKFiK_nBKPHgAAAbk"]
[Sun Aug 30 03:13:23.825717 2026] [security2:error] [pid 524122:tid 524345] [client 185.93.89.167:65083] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPmI33lhEjKFiK_nBKPIAAAAes"]
[Sun Aug 30 03:13:23.826924 2026] [security2:error] [pid 524122:tid 524286] [client 185.93.89.167:59301] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "images6.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPmI33lhEjKFiK_nBKPIQAAAbA"]
[Sun Aug 30 03:13:23.829084 2026] [security2:error] [pid 524122:tid 524258] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/htdocs/.env"] [unique_id "apPmI33lhEjKFiK_nBKPIgAAAZQ"]
[Sun Aug 30 03:13:23.839075 2026] [security2:error] [pid 524122:tid 524275] [client 4.205.62.107:15954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/sgd.php"] [unique_id "apPmI33lhEjKFiK_nBKPIwAAAaU"]
[Sun Aug 30 03:13:23.842194 2026] [security2:error] [pid 524122:tid 524336] [client 20.220.10.235:48690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/wt.php"] [unique_id "apPmI33lhEjKFiK_nBKPJgAAAeI"]
[Sun Aug 30 03:13:23.843938 2026] [security2:error] [pid 524122:tid 524337] [client 20.48.147.90:47164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/sym2019.php"] [unique_id "apPmI33lhEjKFiK_nBKPJwAAAeM"]
[Sun Aug 30 03:13:23.861195 2026] [security2:error] [pid 524122:tid 524378] [client 185.93.89.167:11205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "web01.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPmI33lhEjKFiK_nBKPKAAAAgw"]
[Sun Aug 30 03:13:23.862487 2026] [security2:error] [pid 524122:tid 524379] [client 52.139.37.240:36299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "happynerd.co"] [uri "/zoom1.php"] [unique_id "apPmI33lhEjKFiK_nBKPKQAAAg0"]
[Sun Aug 30 03:13:23.867329 2026] [security2:error] [pid 524122:tid 524327] [client 158.23.147.79:55403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "apPmI33lhEjKFiK_nBKPKgAAAdk"]
[Sun Aug 30 03:13:23.869293 2026] [security2:error] [pid 524122:tid 524257] [client 20.220.10.235:33820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kerelatourism.org"] [uri "/ssss.php"] [unique_id "apPmI33lhEjKFiK_nBKPKwAAAZM"]
[Sun Aug 30 03:13:23.887077 2026] [security2:error] [pid 524122:tid 524372] [client 185.93.89.167:27755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digital.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPmI33lhEjKFiK_nBKPLAAAAgY"]
[Sun Aug 30 03:13:23.891103 2026] [security2:error] [pid 524122:tid 524268] [client 20.48.147.90:64013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/77.php"] [unique_id "apPmI33lhEjKFiK_nBKPLgAAAZ4"]
[Sun Aug 30 03:13:23.891372 2026] [security2:error] [pid 524122:tid 524346] [client 4.205.62.107:15510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/php_info.php"] [unique_id "apPmI33lhEjKFiK_nBKPLwAAAew"]
[Sun Aug 30 03:13:23.893825 2026] [security2:error] [pid 524122:tid 524360] [client 185.93.89.167:23073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "otrs.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPmI33lhEjKFiK_nBKPMAAAAfo"]
[Sun Aug 30 03:13:23.906319 2026] [security2:error] [pid 524122:tid 524324] [client 52.139.37.240:53249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/load.php"] [unique_id "apPmI33lhEjKFiK_nBKPMQAAAdY"]
[Sun Aug 30 03:13:23.909874 2026] [security2:error] [pid 524122:tid 524347] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/www/.env"] [unique_id "apPmI33lhEjKFiK_nBKPMwAAAe0"]
[Sun Aug 30 03:13:23.932287 2026] [security2:error] [pid 524122:tid 524356] [client 20.104.49.130:32776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.firedrakegames.com"] [uri "/ty.php"] [unique_id "apPmI33lhEjKFiK_nBKPOQAAAfY"]
[Sun Aug 30 03:13:23.938210 2026] [authz_core:error] [pid 524122:tid 524370] [client 66.249.66.73:55607] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:23.938467 2026] [authz_core:error] [pid 524122:tid 524370] [client 66.249.66.73:55607] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:23.938859 2026] [security2:error] [pid 524122:tid 524283] [client 158.23.147.79:43900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/css/index.php"] [unique_id "apPmI33lhEjKFiK_nBKPOwAAAa0"]
[Sun Aug 30 03:13:23.958913 2026] [security2:error] [pid 524122:tid 524373] [client 185.93.89.167:65083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail5.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPmI33lhEjKFiK_nBKPPQAAAgc"]
[Sun Aug 30 03:13:23.962419 2026] [security2:error] [pid 524122:tid 524265] [client 185.93.89.167:4877] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/system/.env"] [unique_id "apPmI33lhEjKFiK_nBKPPgAAAZs"]
[Sun Aug 30 03:13:23.965300 2026] [security2:error] [pid 524122:tid 524279] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/html/.env"] [unique_id "apPmI33lhEjKFiK_nBKPPwAAAak"]
[Sun Aug 30 03:13:23.971453 2026] [authz_core:error] [pid 524122:tid 524254] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory3
[Sun Aug 30 03:13:23.971718 2026] [authz_core:error] [pid 524122:tid 524254] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory3
[Sun Aug 30 03:13:23.982523 2026] [security2:error] [pid 524122:tid 524369] [client 20.220.10.235:48269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/im.php"] [unique_id "apPmI33lhEjKFiK_nBKPQwAAAgM"]
[Sun Aug 30 03:13:23.985727 2026] [security2:error] [pid 524122:tid 524277] [client 20.48.147.90:47141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/cc.php"] [unique_id "apPmI33lhEjKFiK_nBKPRAAAAac"]
[Sun Aug 30 03:13:23.989457 2026] [security2:error] [pid 524122:tid 524353] [client 20.104.50.220:51554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/la.php"] [unique_id "apPmI33lhEjKFiK_nBKPRQAAAfM"]
[Sun Aug 30 03:13:23.990920 2026] [security2:error] [pid 524122:tid 524256] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/database/.env"] [unique_id "apPmI33lhEjKFiK_nBKPRgAAAZI"]
[Sun Aug 30 03:13:23.996923 2026] [security2:error] [pid 524122:tid 524343] [client 158.23.147.79:54374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.myediblecravings.com"] [uri "/wp-content/uploads/index.php"] [unique_id "apPmI33lhEjKFiK_nBKPRwAAAek"]
[Sun Aug 30 03:13:23.998094 2026] [security2:error] [pid 524122:tid 524367] [client 20.220.10.235:33815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kerelatourism.org"] [uri "/zoz.php"] [unique_id "apPmI33lhEjKFiK_nBKPSAAAAgE"]
[Sun Aug 30 03:13:23.999841 2026] [security2:error] [pid 524122:tid 524342] [client 20.104.18.15:51146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/htio.php"] [unique_id "apPmI33lhEjKFiK_nBKPSQAAAeg"]
[Sun Aug 30 03:13:24.006324 2026] [security2:error] [pid 524122:tid 524264] [client 20.151.200.44:45982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/wt.php"] [unique_id "apPmJH3lhEjKFiK_nBKPSwAAAZo"]
[Sun Aug 30 03:13:24.008069 2026] [security2:error] [pid 524122:tid 524371] [client 158.23.147.79:55422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/log-mama/function.php"] [unique_id "apPmJH3lhEjKFiK_nBKPTAAAAgU"]
[Sun Aug 30 03:13:24.032028 2026] [security2:error] [pid 524122:tid 524267] [client 20.104.18.15:22489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/wp-activate.php"] [unique_id "apPmJH3lhEjKFiK_nBKPTwAAAZ0"]
[Sun Aug 30 03:13:24.032294 2026] [security2:error] [pid 524122:tid 524276] [client 20.48.147.90:58086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.benjamindock.com"] [uri "/wp-utchershill.php"] [unique_id "apPmJH3lhEjKFiK_nBKPUAAAAaY"]
[Sun Aug 30 03:13:24.040044 2026] [security2:error] [pid 524122:tid 524362] [client 185.93.89.167:13821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "m1.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPmJH3lhEjKFiK_nBKPUgAAAfw"]
[Sun Aug 30 03:13:24.041556 2026] [security2:error] [pid 524122:tid 524292] [client 20.48.147.90:54703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/76.php"] [unique_id "apPmJH3lhEjKFiK_nBKPUwAAAbY"]
[Sun Aug 30 03:13:24.055883 2026] [security2:error] [pid 524122:tid 524296] [client 185.93.89.167:21991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tr.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPmJH3lhEjKFiK_nBKPVAAAAbo"]
[Sun Aug 30 03:13:24.061260 2026] [security2:error] [pid 524122:tid 524293] [client 52.139.37.240:36342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "happynerd.co"] [uri "/lock360.php"] [unique_id "apPmJH3lhEjKFiK_nBKPVQAAAbc"]
[Sun Aug 30 03:13:24.062367 2026] [security2:error] [pid 524122:tid 524355] [client 20.151.200.44:55699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.americanqualityhomeinspections.com"] [uri "/png.php"] [unique_id "apPmJH3lhEjKFiK_nBKPVgAAAfU"]
[Sun Aug 30 03:13:24.075362 2026] [security2:error] [pid 524122:tid 524330] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/live/.env"] [unique_id "apPmJH3lhEjKFiK_nBKPVwAAAdw"]
[Sun Aug 30 03:13:24.076944 2026] [security2:error] [pid 524122:tid 524298] [client 20.197.61.180:15042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "a220training.com"] [uri "/wp-content/themes/reboot/assets/js/plugins/home.php"] [unique_id "apPmJH3lhEjKFiK_nBKPWAAAAbw"]
[Sun Aug 30 03:13:24.084632 2026] [authz_core:error] [pid 524122:tid 524375] [client 66.249.66.40:35569] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:24.084942 2026] [authz_core:error] [pid 524122:tid 524375] [client 66.249.66.40:35569] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:24.095117 2026] [security2:error] [pid 524122:tid 524336] [client 185.93.89.167:4877] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "analytics.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPmJH3lhEjKFiK_nBKPWwAAAeI"]
[Sun Aug 30 03:13:24.111232 2026] [security2:error] [pid 524122:tid 524319] [client 20.220.10.235:48866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/file.php"] [unique_id "apPmJH3lhEjKFiK_nBKPYAAAAdE"]
[Sun Aug 30 03:13:24.120733 2026] [security2:error] [pid 524122:tid 524378] [client 20.48.147.90:47122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/45.php"] [unique_id "apPmJH3lhEjKFiK_nBKPYwAAAgw"]
[Sun Aug 30 03:13:24.126035 2026] [security2:error] [pid 524122:tid 524310] [client 52.139.37.240:49688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/privacy.php"] [unique_id "apPmJH3lhEjKFiK_nBKPZAAAAcg"]
[Sun Aug 30 03:13:24.129497 2026] [security2:error] [pid 524122:tid 524304] [client 20.220.10.235:33806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kerelatourism.org"] [uri "/kcs.php"] [unique_id "apPmJH3lhEjKFiK_nBKPZgAAAcI"]
[Sun Aug 30 03:13:24.137359 2026] [security2:error] [pid 524122:tid 524372] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/storage/.env"] [unique_id "apPmJH3lhEjKFiK_nBKPZwAAAgY"]
[Sun Aug 30 03:13:24.144738 2026] [security2:error] [pid 524122:tid 524269] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/prod/.env"] [unique_id "apPmJH3lhEjKFiK_nBKPaAAAAZ8"]
[Sun Aug 30 03:13:24.148066 2026] [security2:error] [pid 524122:tid 524333] [client 20.197.61.180:11773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "demandthetruth.michaelegenolf.com"] [uri "/wp-content/themes/oceanwp/sass/components/plugins/panel.php"] [unique_id "apPmJH3lhEjKFiK_nBKPaQAAAd8"]
[Sun Aug 30 03:13:24.160188 2026] [security2:error] [pid 524122:tid 524268] [client 185.93.89.167:16277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "otrs.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPmJH3lhEjKFiK_nBKPbAAAAZ4"]
[Sun Aug 30 03:13:24.160840 2026] [security2:error] [pid 524122:tid 524346] [client 185.93.89.167:43537] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/source/.env"] [unique_id "apPmJH3lhEjKFiK_nBKPawAAAew"]
[Sun Aug 30 03:13:24.189932 2026] [security2:error] [pid 524122:tid 524306] [client 185.93.89.167:21991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tr.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPmJH3lhEjKFiK_nBKPbQAAAcQ"]
[Sun Aug 30 03:13:24.198552 2026] [security2:error] [pid 524122:tid 524323] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/dev/.env"] [unique_id "apPmJH3lhEjKFiK_nBKPbwAAAdU"]
[Sun Aug 30 03:13:24.199667 2026] [security2:error] [pid 524122:tid 524305] [client 20.197.61.180:16005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/s.php"] [unique_id "apPmJH3lhEjKFiK_nBKPcQAAAcM"]
[Sun Aug 30 03:13:24.213186 2026] [security2:error] [pid 524122:tid 524260] [client 20.48.147.90:60368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.benjamindock.com"] [uri "/wp-log.php"] [unique_id "apPmJH3lhEjKFiK_nBKPcgAAAZY"]
[Sun Aug 30 03:13:24.226107 2026] [security2:error] [pid 524122:tid 524287] [client 185.93.89.167:55139] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/system/.env"] [unique_id "apPmJH3lhEjKFiK_nBKPcwAAAbE"]
[Sun Aug 30 03:13:24.243832 2026] [security2:error] [pid 524122:tid 524285] [client 20.220.10.235:48667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/ca.php"] [unique_id "apPmJH3lhEjKFiK_nBKPdQAAAa8"]
[Sun Aug 30 03:13:24.245411 2026] [security2:error] [pid 524122:tid 524307] [client 185.93.89.167:61639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thumbs.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPmJH3lhEjKFiK_nBKPdgAAAcU"]
[Sun Aug 30 03:13:24.245467 2026] [security2:error] [pid 524122:tid 524322] [client 158.23.147.79:52259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/cgi-bin/wp-login.php"] [unique_id "apPmJH3lhEjKFiK_nBKPdwAAAdQ"]
[Sun Aug 30 03:13:24.246485 2026] [security2:error] [pid 524122:tid 524341] [client 185.93.89.167:33309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www7.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPmJH3lhEjKFiK_nBKPeAAAAec"]
[Sun Aug 30 03:13:24.256572 2026] [security2:error] [pid 524122:tid 524282] [client 52.139.37.240:35856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "happynerd.co"] [uri "/r.php"] [unique_id "apPmJH3lhEjKFiK_nBKPegAAAaw"]
[Sun Aug 30 03:13:24.257213 2026] [security2:error] [pid 524122:tid 524328] [client 20.220.10.235:33667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kerelatourism.org"] [uri "/tajj.php"] [unique_id "apPmJH3lhEjKFiK_nBKPewAAAdo"]
[Sun Aug 30 03:13:24.263673 2026] [security2:error] [pid 524122:tid 524253] [client 20.48.147.90:51269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/1945.php"] [unique_id "apPmJH3lhEjKFiK_nBKPfgAAAY8"]
[Sun Aug 30 03:13:24.263764 2026] [security2:error] [pid 524122:tid 524271] [client 158.23.147.79:55392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/bk/index.php"] [unique_id "apPmJH3lhEjKFiK_nBKPfwAAAaE"]
[Sun Aug 30 03:13:24.276700 2026] [authz_core:error] [pid 524122:tid 524300] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:24.276973 2026] [authz_core:error] [pid 524122:tid 524300] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:24.280452 2026] [security2:error] [pid 524122:tid 524334] [client 20.48.251.3:46247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/requirements.php"] [unique_id "apPmJH3lhEjKFiK_nBKPgQAAAeA"]
[Sun Aug 30 03:13:24.292080 2026] [security2:error] [pid 524122:tid 524259] [client 20.48.147.90:61620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/74.php"] [unique_id "apPmJH3lhEjKFiK_nBKPhAAAAZU"]
[Sun Aug 30 03:13:24.308378 2026] [security2:error] [pid 524122:tid 524369] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/staging/.env"] [unique_id "apPmJH3lhEjKFiK_nBKPhwAAAgM"]
[Sun Aug 30 03:13:24.311853 2026] [security2:error] [pid 524122:tid 524256] [client 20.104.50.220:63212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "apPmJH3lhEjKFiK_nBKPiQAAAZI"]
[Sun Aug 30 03:13:24.316330 2026] [security2:error] [pid 524122:tid 524367] [client 20.104.50.220:52819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/wp-backup-sql-302.php"] [unique_id "apPmJH3lhEjKFiK_nBKPjAAAAgE"]
[Sun Aug 30 03:13:24.322786 2026] [security2:error] [pid 524122:tid 524290] [client 185.93.89.167:21991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tr.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPmJH3lhEjKFiK_nBKPjgAAAbQ"]
[Sun Aug 30 03:13:24.358623 2026] [security2:error] [pid 524122:tid 524276] [client 158.23.147.79:58637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.myediblecravings.com"] [uri "/wp-content/plugins/zwso.php"] [unique_id "apPmJH3lhEjKFiK_nBKPjwAAAaY"]
[Sun Aug 30 03:13:24.359189 2026] [security2:error] [pid 524122:tid 524362] [client 185.93.89.167:55139] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail5.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPmJH3lhEjKFiK_nBKPkAAAAfw"]
[Sun Aug 30 03:13:24.366325 2026] [security2:error] [pid 524122:tid 524316] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/var/www/.env"] [unique_id "apPmJH3lhEjKFiK_nBKPkgAAAc4"]
[Sun Aug 30 03:13:24.368859 2026] [security2:error] [pid 524122:tid 524325] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/opt/.env"] [unique_id "apPmJH3lhEjKFiK_nBKPlAAAAdc"]
[Sun Aug 30 03:13:24.371920 2026] [security2:error] [pid 524122:tid 524295] [client 20.220.10.235:48676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/pb.php"] [unique_id "apPmJH3lhEjKFiK_nBKPlQAAAbk"]
[Sun Aug 30 03:13:24.375453 2026] [security2:error] [pid 524122:tid 524293] [client 20.104.49.130:60981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wdfjba.org"] [uri "/load.php"] [unique_id "apPmJH3lhEjKFiK_nBKPmAAAAbc"]
[Sun Aug 30 03:13:24.375475 2026] [security2:error] [pid 524122:tid 524355] [client 216.73.216.128:12249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/h_config_quote_replace_string"] [unique_id "apPmJH3lhEjKFiK_nBKPlwAAAfU"]
[Sun Aug 30 03:13:24.377321 2026] [security2:error] [pid 524122:tid 524274] [client 52.139.37.240:9345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-cli.php"] [unique_id "apPmJH3lhEjKFiK_nBKPmQAAAaQ"]
[Sun Aug 30 03:13:24.378518 2026] [security2:error] [pid 524122:tid 524298] [client 20.104.50.220:62833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/WSO.php"] [unique_id "apPmJH3lhEjKFiK_nBKPmgAAAbw"]
[Sun Aug 30 03:13:24.384570 2026] [security2:error] [pid 524122:tid 524364] [client 20.48.251.3:37137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/setup-config.php"] [unique_id "apPmJH3lhEjKFiK_nBKPnQAAAf4"]
[Sun Aug 30 03:13:24.397413 2026] [security2:error] [pid 524122:tid 524378] [client 185.93.89.167:63189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "web01.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPmJH3lhEjKFiK_nBKPoAAAAgw"]
[Sun Aug 30 03:13:24.399573 2026] [security2:error] [pid 524122:tid 524379] [client 20.220.10.235:33818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kerelatourism.org"] [uri "/bge.php"] [unique_id "apPmJH3lhEjKFiK_nBKPoQAAAg0"]
[Sun Aug 30 03:13:24.411340 2026] [security2:error] [pid 524122:tid 524257] [client 20.48.147.90:51298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/wos.php"] [unique_id "apPmJH3lhEjKFiK_nBKPpAAAAZM"]
[Sun Aug 30 03:13:24.415432 2026] [security2:error] [pid 524122:tid 524140] [remote 160.153.252.100:35038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.252.153.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nerdmoto.com"] [uri "/wp-login.php"] [unique_id "apPmJH3lhEjKFiK_nBKPowAB-hA"]
[Sun Aug 30 03:13:24.420287 2026] [security2:error] [pid 524122:tid 524304] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/laravel/.env"] [unique_id "apPmJH3lhEjKFiK_nBKPpQAAAcI"]
[Sun Aug 30 03:13:24.424931 2026] [security2:error] [pid 524122:tid 524372] [client 185.93.89.167:58973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digital.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPmJH3lhEjKFiK_nBKPpgAAAgY"]
[Sun Aug 30 03:13:24.427694 2026] [security2:error] [pid 524122:tid 524269] [client 20.48.147.90:45273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/wp-config.php"] [unique_id "apPmJH3lhEjKFiK_nBKPqAAAAZ8"]
[Sun Aug 30 03:13:24.429501 2026] [security2:error] [pid 524122:tid 524333] [client 185.93.89.167:43537] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/framework/.env"] [unique_id "apPmJH3lhEjKFiK_nBKPqQAAAd8"]
[Sun Aug 30 03:13:24.442708 2026] [security2:error] [pid 524122:tid 524306] [client 68.155.159.216:60951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPmJH3lhEjKFiK_nBKPqwAAAcQ"]
[Sun Aug 30 03:13:24.452662 2026] [security2:error] [pid 524122:tid 524305] [client 20.104.50.220:17227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/.well-known/50.php"] [unique_id "apPmJH3lhEjKFiK_nBKPrQAAAcM"]
[Sun Aug 30 03:13:24.458654 2026] [security2:error] [pid 524122:tid 524374] [client 52.139.37.240:36298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "happynerd.co"] [uri "/sf.php"] [unique_id "apPmJH3lhEjKFiK_nBKPrgAAAgg"]
[Sun Aug 30 03:13:24.459380 2026] [security2:error] [pid 524122:tid 524287] [client 20.48.147.90:60364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.benjamindock.com"] [uri "/web-setting.php"] [unique_id "apPmJH3lhEjKFiK_nBKPrwAAAbE"]
[Sun Aug 30 03:13:24.501542 2026] [security2:error] [pid 524122:tid 524328] [client 185.93.89.167:30069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images6.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPmJH3lhEjKFiK_nBKPtAAAAdo"]
[Sun Aug 30 03:13:24.502694 2026] [security2:error] [pid 524122:tid 524253] [client 20.220.10.235:48863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/pk.php"] [unique_id "apPmJH3lhEjKFiK_nBKPtQAAAY8"]
[Sun Aug 30 03:13:24.504657 2026] [security2:error] [pid 524122:tid 524350] [client 158.23.147.79:52733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gtepetrochem.com"] [uri "/first.php"] [unique_id "apPmJH3lhEjKFiK_nBKPtgAAAfA"]
[Sun Aug 30 03:13:24.507330 2026] [authz_core:error] [pid 524122:tid 524357] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory0
[Sun Aug 30 03:13:24.507768 2026] [authz_core:error] [pid 524122:tid 524357] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory0
[Sun Aug 30 03:13:24.511838 2026] [security2:error] [pid 524122:tid 524313] [client 185.93.89.167:39543] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "thumbs.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPmJH3lhEjKFiK_nBKPuAAAAcs"]
[Sun Aug 30 03:13:24.513845 2026] [security2:error] [pid 524122:tid 524356] [client 185.93.89.167:61385] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www7.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPmJH3lhEjKFiK_nBKPuQAAAfY"]
[Sun Aug 30 03:13:24.524376 2026] [security2:error] [pid 524122:tid 524289] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/symfony/.env"] [unique_id "apPmJH3lhEjKFiK_nBKPuwAAAbM"]
[Sun Aug 30 03:13:24.527187 2026] [security2:error] [pid 524122:tid 524348] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/var/www/html/.env"] [unique_id "apPmJH3lhEjKFiK_nBKPvAAAAe4"]
[Sun Aug 30 03:13:24.549165 2026] [security2:error] [pid 524122:tid 524255] [client 20.48.147.90:51297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/ty.php"] [unique_id "apPmJH3lhEjKFiK_nBKPvQAAAZE"]
[Sun Aug 30 03:13:24.553710 2026] [security2:error] [pid 524122:tid 524358] [client 158.23.147.79:58641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.myediblecravings.com"] [uri "/chosen.php"] [unique_id "apPmJH3lhEjKFiK_nBKPvgAAAfg"]
[Sun Aug 30 03:13:24.563251 2026] [security2:error] [pid 524122:tid 524324] [client 185.93.89.167:43537] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/ikiwiki/.env"] [unique_id "apPmJH3lhEjKFiK_nBKPwQAAAdY"]
[Sun Aug 30 03:13:24.565614 2026] [security2:error] [pid 524122:tid 524363] [client 20.220.10.235:33802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kerelatourism.org"] [uri "/ssh3ll.php"] [unique_id "apPmJH3lhEjKFiK_nBKPwgAAAf0"]
[Sun Aug 30 03:13:24.565974 2026] [authz_core:error] [pid 524122:tid 524309] [client 216.73.216.128:48018] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:24.566295 2026] [authz_core:error] [pid 524122:tid 524309] [client 216.73.216.128:48018] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:24.577687 2026] [security2:error] [pid 524122:tid 524368] [client 52.139.37.240:9514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/media-new.php"] [unique_id "apPmJH3lhEjKFiK_nBKPxAAAAgI"]
[Sun Aug 30 03:13:24.578114 2026] [security2:error] [pid 524122:tid 524256] [client 185.93.89.167:48417] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/env/.env"] [unique_id "apPmJH3lhEjKFiK_nBKPwwAAAZI"]
[Sun Aug 30 03:13:24.589198 2026] [security2:error] [pid 524122:tid 524367] [client 185.93.89.167:19409] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tr.mariegronley.com"] [uri "/system/.env"] [unique_id "apPmJH3lhEjKFiK_nBKPxwAAAgE"]
[Sun Aug 30 03:13:24.589582 2026] [security2:error] [pid 524122:tid 524342] [client 185.93.89.167:32875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "forms.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPmJH3lhEjKFiK_nBKPyAAAAeg"]
[Sun Aug 30 03:13:24.629250 2026] [authz_core:error] [pid 524122:tid 524277] [client 66.249.66.199:61883] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:24.629512 2026] [security2:error] [pid 524122:tid 524352] [client 20.220.10.235:48871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/ft.php"] [unique_id "apPmJH3lhEjKFiK_nBKPywAAAfI"]
[Sun Aug 30 03:13:24.629587 2026] [authz_core:error] [pid 524122:tid 524277] [client 66.249.66.199:61883] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:24.630193 2026] [security2:error] [pid 524122:tid 524284] [client 4.205.62.107:17283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fcconveyancing.com.au"] [uri "/phpinfo01.php"] [unique_id "apPmJH3lhEjKFiK_nBKPzAAAAa4"]
[Sun Aug 30 03:13:24.636210 2026] [security2:error] [pid 524122:tid 524316] [client 20.104.50.220:33179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/marijuana.php"] [unique_id "apPmJH3lhEjKFiK_nBKPzwAAAc4"]
[Sun Aug 30 03:13:24.643832 2026] [security2:error] [pid 524122:tid 524139] [remote 160.153.252.100:35038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.252.153.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nerdmoto.com"] [uri "/wp-login.php"] [unique_id "apPmJH3lhEjKFiK_nBKPzQABnQ8"], referer: https://nerdmoto.com/wp-login.php
[Sun Aug 30 03:13:24.644035 2026] [security2:error] [pid 524122:tid 524325] [client 20.48.147.90:60379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.benjamindock.com"] [uri "/wp-ettoyag.php"] [unique_id "apPmJH3lhEjKFiK_nBKP0AAAAdc"]
[Sun Aug 30 03:13:24.651445 2026] [security2:error] [pid 524122:tid 524343] [client 52.139.37.240:35899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "happynerd.co"] [uri "/7.php"] [unique_id "apPmJH3lhEjKFiK_nBKP1AAAAek"]
[Sun Aug 30 03:13:24.663862 2026] [security2:error] [pid 524122:tid 524293] [client 185.93.89.167:55957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "web01.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPmJH3lhEjKFiK_nBKP1QAAAbc"]
[Sun Aug 30 03:13:24.672004 2026] [security2:error] [pid 524122:tid 524355] [client 20.48.147.90:54717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/75.php"] [unique_id "apPmJH3lhEjKFiK_nBKP1gAAAfU"]
[Sun Aug 30 03:13:24.689722 2026] [security2:error] [pid 524122:tid 524298] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/current/.env"] [unique_id "apPmJH3lhEjKFiK_nBKP2QAAAbw"]
[Sun Aug 30 03:13:24.690709 2026] [security2:error] [pid 524122:tid 524315] [client 185.93.89.167:24949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digital.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPmJH3lhEjKFiK_nBKP2gAAAc0"]
[Sun Aug 30 03:13:24.693355 2026] [security2:error] [pid 524122:tid 524299] [client 20.104.50.220:5912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/p.php"] [unique_id "apPmJH3lhEjKFiK_nBKP2wAAAb0"]
[Sun Aug 30 03:13:24.695482 2026] [security2:error] [pid 524122:tid 524379] [client 20.48.147.90:51286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/1945.php"] [unique_id "apPmJH3lhEjKFiK_nBKP3QAAAg0"]
[Sun Aug 30 03:13:24.695881 2026] [security2:error] [pid 524122:tid 524378] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/wordpress/.env"] [unique_id "apPmJH3lhEjKFiK_nBKP3AAAAgw"]
[Sun Aug 30 03:13:24.696015 2026] [security2:error] [pid 524122:tid 524310] [client 185.93.89.167:43537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mobil.mariegronley.com"] [uri "/config.inc.php"] [unique_id "apPmJH3lhEjKFiK_nBKP3gAAAcg"]
[Sun Aug 30 03:13:24.698538 2026] [security2:error] [pid 524122:tid 524318] [client 185.93.89.167:38793] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/env/.env"] [unique_id "apPmJH3lhEjKFiK_nBKP3wAAAdA"]
[Sun Aug 30 03:13:24.698804 2026] [security2:error] [pid 524122:tid 524257] [client 20.220.10.235:33797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kerelatourism.org"] [uri "/motu.php"] [unique_id "apPmJH3lhEjKFiK_nBKP4AAAAZM"]
[Sun Aug 30 03:13:24.722050 2026] [security2:error] [pid 524122:tid 524268] [client 185.93.89.167:19409] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "tr.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPmJH3lhEjKFiK_nBKP4wAAAZ4"]
[Sun Aug 30 03:13:24.748536 2026] [security2:error] [pid 524122:tid 524312] [client 158.23.147.79:56143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.myediblecravings.com"] [uri "/goods.php"] [unique_id "apPmJH3lhEjKFiK_nBKP5QAAAco"]
[Sun Aug 30 03:13:24.768296 2026] [security2:error] [pid 524122:tid 524280] [client 20.220.10.235:48283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/wp-ver.php"] [unique_id "apPmJH3lhEjKFiK_nBKP6AAAAao"]
[Sun Aug 30 03:13:24.768587 2026] [security2:error] [pid 524122:tid 524260] [client 185.93.89.167:48501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "analytics.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPmJH3lhEjKFiK_nBKP6QAAAZY"]
[Sun Aug 30 03:13:24.769486 2026] [security2:error] [pid 524122:tid 524347] [client 185.93.89.167:21039] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "images6.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPmJH3lhEjKFiK_nBKP5wAAAe0"]
[Sun Aug 30 03:13:24.775120 2026] [authz_core:error] [pid 524122:tid 524308] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:24.775409 2026] [authz_core:error] [pid 524122:tid 524308] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:24.775509 2026] [security2:error] [pid 524122:tid 524269] [client 52.139.37.240:9353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-blog.php"] [unique_id "apPmJH3lhEjKFiK_nBKP6wAAAZ8"]
[Sun Aug 30 03:13:24.779069 2026] [security2:error] [pid 524122:tid 524349] [client 185.93.89.167:39543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thumbs.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPmJH3lhEjKFiK_nBKP7AAAAe8"]
[Sun Aug 30 03:13:24.781509 2026] [security2:error] [pid 524122:tid 524377] [client 185.93.89.167:61385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www7.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPmJH3lhEjKFiK_nBKP7QAAAgs"]
[Sun Aug 30 03:13:24.785735 2026] [security2:error] [pid 524122:tid 524373] [client 20.197.61.180:13156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "a220training.com"] [uri "/wp-content/themes/salient/css/build/plugins/login.php"] [unique_id "apPmJH3lhEjKFiK_nBKP7gAAAgc"]
[Sun Aug 30 03:13:24.798053 2026] [security2:error] [pid 524122:tid 524263] [client 20.48.147.90:58099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.benjamindock.com"] [uri "/venom.php"] [unique_id "apPmJH3lhEjKFiK_nBKP7wAAAZk"]
[Sun Aug 30 03:13:24.804219 2026] [security2:error] [pid 524122:tid 524338] [client 20.104.50.220:25429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/hypo.php"] [unique_id "apPmJH3lhEjKFiK_nBKP8AAAAeQ"]
[Sun Aug 30 03:13:24.825889 2026] [security2:error] [pid 524122:tid 524322] [client 20.48.147.90:51309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/wos.php"] [unique_id "apPmJH3lhEjKFiK_nBKP8gAAAdQ"]
[Sun Aug 30 03:13:24.826245 2026] [security2:error] [pid 524122:tid 524341] [client 20.220.10.235:33794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kerelatourism.org"] [uri "/wefile.php"] [unique_id "apPmJH3lhEjKFiK_nBKP8wAAAec"]
[Sun Aug 30 03:13:24.842918 2026] [security2:error] [pid 524122:tid 524320] [client 20.48.147.90:61600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/71.php"] [unique_id "apPmJH3lhEjKFiK_nBKP9gAAAdI"]
[Sun Aug 30 03:13:24.850550 2026] [security2:error] [pid 524122:tid 524354] [client 52.139.37.240:36331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "happynerd.co"] [uri "/b.php"] [unique_id "apPmJH3lhEjKFiK_nBKP-AAAAfQ"]
[Sun Aug 30 03:13:24.855752 2026] [security2:error] [pid 524122:tid 524261] [client 185.93.89.167:5037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "forms.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPmJH3lhEjKFiK_nBKP-QAAAZc"]
[Sun Aug 30 03:13:24.859296 2026] [security2:error] [pid 524122:tid 524289] [client 4.205.62.107:32498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/pinfo.php"] [unique_id "apPmJH3lhEjKFiK_nBKP-wAAAbM"]
[Sun Aug 30 03:13:24.871463 2026] [security2:error] [pid 524122:tid 524276] [client 20.197.61.180:11734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "demandthetruth.michaelegenolf.com"] [uri "/wp-content/themes/options.php"] [unique_id "apPmJH3lhEjKFiK_nBKP_AAAAaY"]
[Sun Aug 30 03:13:24.879697 2026] [security2:error] [pid 524122:tid 524375] [client 4.205.62.107:28679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/wp-class.php"] [unique_id "apPmJH3lhEjKFiK_nBKP_QAAAgk"]
[Sun Aug 30 03:13:24.887744 2026] [security2:error] [pid 524122:tid 524255] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/wp/.env"] [unique_id "apPmJH3lhEjKFiK_nBKP_gAAAZE"]
[Sun Aug 30 03:13:24.905241 2026] [security2:error] [pid 524122:tid 524326] [client 20.220.10.235:48662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/ah24.php"] [unique_id "apPmJH3lhEjKFiK_nBKQAgAAAdg"]
[Sun Aug 30 03:13:24.907836 2026] [security2:error] [pid 524122:tid 524258] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/release/.env"] [unique_id "apPmJH3lhEjKFiK_nBKQAwAAAZQ"]
[Sun Aug 30 03:13:24.932359 2026] [security2:error] [pid 524122:tid 524265] [client 20.197.61.180:1565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/php.php"] [unique_id "apPmJH3lhEjKFiK_nBKQBgAAAZs"]
[Sun Aug 30 03:13:24.943414 2026] [security2:error] [pid 524122:tid 524352] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/cms/.env"] [unique_id "apPmJH3lhEjKFiK_nBKQCQAAAfI"]
[Sun Aug 30 03:13:24.953681 2026] [security2:error] [pid 524122:tid 524362] [client 20.220.10.235:33800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kerelatourism.org"] [uri "/Contrller.php"] [unique_id "apPmJH3lhEjKFiK_nBKQCgAAAfw"]
[Sun Aug 30 03:13:24.962295 2026] [security2:error] [pid 524122:tid 524267] [client 185.93.89.167:41093] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/system/.env"] [unique_id "apPmJH3lhEjKFiK_nBKQDQAAAZ0"]
[Sun Aug 30 03:13:24.967881 2026] [security2:error] [pid 524122:tid 524295] [client 185.93.89.167:38793] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/src/.env"] [unique_id "apPmJH3lhEjKFiK_nBKQDgAAAbk"]
[Sun Aug 30 03:13:24.975887 2026] [security2:error] [pid 524122:tid 524363] [client 52.139.37.240:46951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/menu.php"] [unique_id "apPmJH3lhEjKFiK_nBKQEAAAAf0"]
[Sun Aug 30 03:13:24.976119 2026] [security2:error] [pid 524122:tid 524293] [client 20.48.147.90:51288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/wso-2.5.php"] [unique_id "apPmJH3lhEjKFiK_nBKQEgAAAbc"]
[Sun Aug 30 03:13:24.978867 2026] [security2:error] [pid 524122:tid 524355] [client 158.23.147.79:37716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.myediblecravings.com"] [uri "/wp-admin/css/colors/index.php"] [unique_id "apPmJH3lhEjKFiK_nBKQEwAAAfU"]
[Sun Aug 30 03:13:24.980673 2026] [security2:error] [pid 524122:tid 524357] [client 4.205.62.107:15853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/fleen.php"] [unique_id "apPmJH3lhEjKFiK_nBKQFQAAAfc"]
[Sun Aug 30 03:13:24.982547 2026] [security2:error] [pid 524122:tid 524336] [client 185.93.89.167:30473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kb.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPmJH3lhEjKFiK_nBKQFgAAAeI"]
[Sun Aug 30 03:13:24.992745 2026] [authz_core:error] [pid 524122:tid 524274] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory8
[Sun Aug 30 03:13:24.993009 2026] [authz_core:error] [pid 524122:tid 524274] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory8
[Sun Aug 30 03:13:25.006569 2026] [security2:error] [pid 524122:tid 524319] [client 158.23.147.79:61819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-content/cong.php"] [unique_id "apPmJX3lhEjKFiK_nBKQGgAAAdE"]
[Sun Aug 30 03:13:25.026696 2026] [security2:error] [pid 524122:tid 524318] [client 4.205.62.107:15858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/session.php"] [unique_id "apPmJX3lhEjKFiK_nBKQHwAAAdA"]
[Sun Aug 30 03:13:25.031688 2026] [security2:error] [pid 524122:tid 524257] [client 185.93.89.167:61515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail5.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPmJX3lhEjKFiK_nBKQIAAAAZM"]
[Sun Aug 30 03:13:25.034653 2026] [security2:error] [pid 524122:tid 524304] [client 20.220.10.235:48865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/wp-admin/zwso.php"] [unique_id "apPmJX3lhEjKFiK_nBKQIgAAAcI"]
[Sun Aug 30 03:13:25.034840 2026] [security2:error] [pid 524122:tid 524360] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/drupal/.env"] [unique_id "apPmJX3lhEjKFiK_nBKQIQAAAfo"]
[Sun Aug 30 03:13:25.035362 2026] [security2:error] [pid 524122:tid 524365] [client 185.93.89.167:45629] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "analytics.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPmJX3lhEjKFiK_nBKQIwAAAf8"]
[Sun Aug 30 03:13:25.040223 2026] [security2:error] [pid 524122:tid 524333] [client 185.93.89.167:21039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images6.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPmJX3lhEjKFiK_nBKQJQAAAd8"]
[Sun Aug 30 03:13:25.041878 2026] [security2:error] [pid 524122:tid 524286] [client 52.139.37.240:35868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "happynerd.co"] [uri "/buy.php"] [unique_id "apPmJX3lhEjKFiK_nBKQJgAAAbA"]
[Sun Aug 30 03:13:25.048972 2026] [security2:error] [pid 524122:tid 524312] [client 20.48.147.90:61598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/72.php"] [unique_id "apPmJX3lhEjKFiK_nBKQKQAAAco"]
[Sun Aug 30 03:13:25.060685 2026] [security2:error] [pid 524122:tid 524305] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/releases/.env"] [unique_id "apPmJX3lhEjKFiK_nBKQKwAAAcM"]
[Sun Aug 30 03:13:25.076154 2026] [authz_core:error] [pid 524122:tid 524378] [client 66.249.66.64:37015] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:25.076478 2026] [authz_core:error] [pid 524122:tid 524378] [client 66.249.66.64:37015] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:25.080947 2026] [security2:error] [pid 524122:tid 524349] [client 20.220.10.235:33803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kerelatourism.org"] [uri "/file66.php"] [unique_id "apPmJX3lhEjKFiK_nBKQMwAAAe8"]
[Sun Aug 30 03:13:25.085975 2026] [security2:error] [pid 524122:tid 524145] [remote 192.250.235.43:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.235.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "c1care.org"] [uri "/wp-login.php"] [unique_id "apPmJX3lhEjKFiK_nBKQHAAB5RU"]
[Sun Aug 30 03:13:25.094950 2026] [security2:error] [pid 524122:tid 524338] [client 185.93.89.167:41093] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mobil.mariegronley.com"] [uri "/wp-config.php.backup"] [unique_id "apPmJX3lhEjKFiK_nBKQOAAAAeQ"]
[Sun Aug 30 03:13:25.107317 2026] [security2:error] [pid 524122:tid 524350] [client 20.48.147.90:47127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/ngacir88.php"] [unique_id "apPmJX3lhEjKFiK_nBKQOwAAAfA"]
[Sun Aug 30 03:13:25.116417 2026] [security2:error] [pid 524122:tid 524370] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/joomla/.env"] [unique_id "apPmJX3lhEjKFiK_nBKQPAAAAgQ"]
[Sun Aug 30 03:13:25.138947 2026] [security2:error] [pid 524122:tid 524270] [client 20.104.50.220:42798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/lnedx.php"] [unique_id "apPmJX3lhEjKFiK_nBKQQAAAAaA"]
[Sun Aug 30 03:13:25.140922 2026] [security2:error] [pid 524122:tid 524261] [client 20.104.18.15:51172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/dev.php"] [unique_id "apPmJX3lhEjKFiK_nBKQQQAAAZc"]
[Sun Aug 30 03:13:25.161713 2026] [security2:error] [pid 524122:tid 524276] [client 20.48.147.90:60399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.benjamindock.com"] [uri "/vuln.php"] [unique_id "apPmJX3lhEjKFiK_nBKQQwAAAaY"]
[Sun Aug 30 03:13:25.164858 2026] [security2:error] [pid 524122:tid 524375] [client 20.104.18.15:22495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "appsneakpeek.com"] [uri "/wp_blog_footer.php"] [unique_id "apPmJX3lhEjKFiK_nBKQRAAAAgk"]
[Sun Aug 30 03:13:25.167667 2026] [security2:error] [pid 524122:tid 524351] [client 20.220.10.235:48837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.mar-azul.com"] [uri "/waf.php"] [unique_id "apPmJX3lhEjKFiK_nBKQRQAAAfE"]
[Sun Aug 30 03:13:25.185681 2026] [security2:error] [pid 524122:tid 524356] [client 52.139.37.240:9519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/wp-crons.php"] [unique_id "apPmJX3lhEjKFiK_nBKQSQAAAfY"]
[Sun Aug 30 03:13:25.202200 2026] [security2:error] [pid 524122:tid 524264] [client 185.93.89.167:45863] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/env/.env"] [unique_id "apPmJX3lhEjKFiK_nBKQSwAAAZo"]
[Sun Aug 30 03:13:25.205200 2026] [security2:error] [pid 524122:tid 524266] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/magento/.env"] [unique_id "apPmJX3lhEjKFiK_nBKQTAAAAZw"]
[Sun Aug 30 03:13:25.208958 2026] [security2:error] [pid 524122:tid 524371] [client 20.220.10.235:33800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kerelatourism.org"] [uri "/blnux.php"] [unique_id "apPmJX3lhEjKFiK_nBKQTQAAAgU"]
[Sun Aug 30 03:13:25.217699 2026] [security2:error] [pid 524122:tid 524265] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/shared/.env"] [unique_id "apPmJX3lhEjKFiK_nBKQTgAAAZs"]
[Sun Aug 30 03:13:25.217965 2026] [security2:error] [pid 524122:tid 524353] [client 20.48.147.90:61682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/70.php"] [unique_id "apPmJX3lhEjKFiK_nBKQTwAAAfM"]
[Sun Aug 30 03:13:25.226062 2026] [security2:error] [pid 524122:tid 524284] [client 20.104.49.130:26652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.49.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "williamcchittick.com"] [uri "/1xmomo.php"] [unique_id "apPmJX3lhEjKFiK_nBKQUAAAAa4"]
[Sun Aug 30 03:13:25.228345 2026] [security2:error] [pid 524122:tid 524352] [client 185.93.89.167:40487] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/env/.env"] [unique_id "apPmJX3lhEjKFiK_nBKQUQAAAfI"]
[Sun Aug 30 03:13:25.233768 2026] [security2:error] [pid 524122:tid 524302] [client 52.139.37.240:35885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "happynerd.co"] [uri "/config.php"] [unique_id "apPmJX3lhEjKFiK_nBKQUgAAAcA"]
[Sun Aug 30 03:13:25.238058 2026] [security2:error] [pid 524122:tid 524328] [client 185.93.89.167:38793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "otrs.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPmJX3lhEjKFiK_nBKQUwAAAdo"]
[Sun Aug 30 03:13:25.249005 2026] [authz_core:error] [pid 524122:tid 524362] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:25.249044 2026] [security2:error] [pid 524122:tid 524316] [client 20.48.147.90:51295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/&heker!.php"] [unique_id "apPmJX3lhEjKFiK_nBKQVQAAAc4"]
[Sun Aug 30 03:13:25.249288 2026] [authz_core:error] [pid 524122:tid 524362] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:25.300847 2026] [security2:error] [pid 524122:tid 524357] [client 185.93.89.167:53569] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mail5.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPmJX3lhEjKFiK_nBKQWAAAAfc"]
[Sun Aug 30 03:13:25.305353 2026] [security2:error] [pid 524122:tid 524281] [client 185.93.89.167:45629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "analytics.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPmJX3lhEjKFiK_nBKQWQAAAas"]
[Sun Aug 30 03:13:25.316261 2026] [security2:error] [pid 524122:tid 524319] [client 185.93.89.167:3399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thumbs.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPmJX3lhEjKFiK_nBKQWwAAAdE"]
[Sun Aug 30 03:13:25.316787 2026] [security2:error] [pid 524122:tid 524299] [client 185.93.89.167:5319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www7.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPmJX3lhEjKFiK_nBKQXAAAAb0"]
[Sun Aug 30 03:13:25.337161 2026] [security2:error] [pid 524122:tid 524304] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/shopify/.env"] [unique_id "apPmJX3lhEjKFiK_nBKQXgAAAcI"]
[Sun Aug 30 03:13:25.340117 2026] [security2:error] [pid 524122:tid 524365] [client 20.48.147.90:58053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.benjamindock.com"] [uri "/V5.php"] [unique_id "apPmJX3lhEjKFiK_nBKQXwAAAf8"]
[Sun Aug 30 03:13:25.341619 2026] [security2:error] [pid 524122:tid 524333] [client 20.220.10.235:33819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kerelatourism.org"] [uri "/attack.php"] [unique_id "apPmJX3lhEjKFiK_nBKQYAAAAd8"]
[Sun Aug 30 03:13:25.357821 2026] [security2:error] [pid 524122:tid 524346] [client 158.23.147.79:54357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.myediblecravings.com"] [uri "/wp-admin/includes/nav.php"] [unique_id "apPmJX3lhEjKFiK_nBKQYQAAAew"]
[Sun Aug 30 03:13:25.368836 2026] [security2:error] [pid 524122:tid 524280] [client 20.48.147.90:61575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/69.php"] [unique_id "apPmJX3lhEjKFiK_nBKQZAAAAao"]
[Sun Aug 30 03:13:25.371579 2026] [security2:error] [pid 524122:tid 524260] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/prestashop/.env"] [unique_id "apPmJX3lhEjKFiK_nBKQZQAAAZY"]
[Sun Aug 30 03:13:25.379900 2026] [security2:error] [pid 524122:tid 524339] [client 216.73.216.128:20721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.letter7brands.com"] [uri "/%22../scripts2/updateconf/%22"] [unique_id "apPmJX3lhEjKFiK_nBKQZgAAAeU"]
[Sun Aug 30 03:13:25.394851 2026] [security2:error] [pid 524122:tid 524287] [client 185.93.89.167:25067] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/env/.env"] [unique_id "apPmJX3lhEjKFiK_nBKQZwAAAbE"]
[Sun Aug 30 03:13:25.408134 2026] [security2:error] [pid 524122:tid 524341] [client 20.48.147.90:51289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/shellv3.php"] [unique_id "apPmJX3lhEjKFiK_nBKQaQAAAec"]
[Sun Aug 30 03:13:25.422218 2026] [security2:error] [pid 524122:tid 524370] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/codeigniter/.env"] [unique_id "apPmJX3lhEjKFiK_nBKQbAAAAgQ"]
[Sun Aug 30 03:13:25.435983 2026] [security2:error] [pid 524122:tid 524344] [client 52.139.37.240:35840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "happynerd.co"] [uri "/num.php"] [unique_id "apPmJX3lhEjKFiK_nBKQcAAAAeo"]
[Sun Aug 30 03:13:25.437135 2026] [security2:error] [pid 524122:tid 524344] [client 20.48.251.3:65509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.stackjackapp.com"] [uri "/var/www/wallet/index.php"] [unique_id "apPmJX3lhEjKFiK_nBKQcQAAAeo"]
[Sun Aug 30 03:13:25.470110 2026] [security2:error] [pid 524122:tid 524308] [client 185.93.89.167:45863] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "web01.mariegronley.com"] [uri "/src/.env"] [unique_id "apPmJX3lhEjKFiK_nBKQdQAAAcY"]
[Sun Aug 30 03:13:25.470472 2026] [security2:error] [pid 524122:tid 524255] [client 20.220.10.235:33793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kerelatourism.org"] [uri "/wk/index.php"] [unique_id "apPmJX3lhEjKFiK_nBKQdwAAAZE"]
[Sun Aug 30 03:13:25.476976 2026] [authz_core:error] [pid 524122:tid 524348] [client 216.73.216.128:35898] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:25.477220 2026] [authz_core:error] [pid 524122:tid 524348] [client 216.73.216.128:35898] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:25.477815 2026] [security2:error] [pid 524122:tid 524358] [client 20.48.147.90:58102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.benjamindock.com"] [uri "/v5.php"] [unique_id "apPmJX3lhEjKFiK_nBKQeAAAAfg"]
[Sun Aug 30 03:13:25.478526 2026] [security2:error] [pid 524122:tid 524351] [client 20.104.50.220:30743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mumbaidailys.com"] [uri "/css/index.php"] [unique_id "apPmJX3lhEjKFiK_nBKQeQAAAfE"]
[Sun Aug 30 03:13:25.492925 2026] [authz_core:error] [pid 524122:tid 524274] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory3
[Sun Aug 30 03:13:25.493216 2026] [authz_core:error] [pid 524122:tid 524274] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory3
[Sun Aug 30 03:13:25.496539 2026] [security2:error] [pid 524122:tid 524326] [client 185.93.89.167:40487] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "digital.mariegronley.com"] [uri "/src/.env"] [unique_id "apPmJX3lhEjKFiK_nBKQfAAAAdg"]
[Sun Aug 30 03:13:25.498382 2026] [security2:error] [pid 524122:tid 524324] [client 52.139.37.240:53240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/aged.php"] [unique_id "apPmJX3lhEjKFiK_nBKQfQAAAdY"]
[Sun Aug 30 03:13:25.501893 2026] [security2:error] [pid 524122:tid 524272] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/cakephp/.env"] [unique_id "apPmJX3lhEjKFiK_nBKQfgAAAaI"]
[Sun Aug 30 03:13:25.502584 2026] [security2:error] [pid 524122:tid 524256] [client 20.104.50.220:29339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.michaelegenolf.com"] [uri "/json-php.php"] [unique_id "apPmJX3lhEjKFiK_nBKQfwAAAZI"]
[Sun Aug 30 03:13:25.503791 2026] [security2:error] [pid 524122:tid 524356] [client 185.93.89.167:25559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "otrs.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPmJX3lhEjKFiK_nBKQgAAAAfY"]
[Sun Aug 30 03:13:25.508268 2026] [security2:error] [pid 524122:tid 524295] [client 20.197.61.180:13121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "a220training.com"] [uri "/wp-content/themes/security.php"] [unique_id "apPmJX3lhEjKFiK_nBKQgQAAAbk"]
[Sun Aug 30 03:13:25.513962 2026] [security2:error] [pid 524122:tid 524367] [client 20.48.251.3:36911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.251.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.gowithgpc.com"] [uri "/wp-admin/sc.php"] [unique_id "apPmJX3lhEjKFiK_nBKQggAAAgE"]
[Sun Aug 30 03:13:25.536762 2026] [security2:error] [pid 524122:tid 524266] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/zend/.env"] [unique_id "apPmJX3lhEjKFiK_nBKQhQAAAZw"]
[Sun Aug 30 03:13:25.541912 2026] [security2:error] [pid 524122:tid 524371] [client 20.104.50.220:62827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.prod.sapientbydesign.com"] [uri "/IndoXploit.php"] [unique_id "apPmJX3lhEjKFiK_nBKQhgAAAgU"]
[Sun Aug 30 03:13:25.549627 2026] [security2:error] [pid 524122:tid 524265] [client 68.155.159.216:60959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.159.155.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mymediaworkscompany.com"] [uri "/wp-includes/Requests/network.php"] [unique_id "apPmJX3lhEjKFiK_nBKQhwAAAZs"]
[Sun Aug 30 03:13:25.551670 2026] [security2:error] [pid 524122:tid 524353] [client 20.48.147.90:47149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/UnknownSec.php"] [unique_id "apPmJX3lhEjKFiK_nBKQiAAAAfM"]
[Sun Aug 30 03:13:25.568688 2026] [security2:error] [pid 524122:tid 524278] [client 185.93.89.167:53569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail5.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPmJX3lhEjKFiK_nBKQiwAAAag"]
[Sun Aug 30 03:13:25.569262 2026] [security2:error] [pid 524122:tid 524360] [client 20.197.61.180:6551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "demandthetruth.michaelegenolf.com"] [uri "/wp-content/themes/panel.php"] [unique_id "apPmJX3lhEjKFiK_nBKQjAAAAfo"]
[Sun Aug 30 03:13:25.582205 2026] [security2:error] [pid 524122:tid 524329] [client 185.93.89.167:48677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thumbs.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPmJX3lhEjKFiK_nBKQkQAAAds"]
[Sun Aug 30 03:13:25.582721 2026] [security2:error] [pid 524122:tid 524325] [client 185.93.89.167:28767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www7.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPmJX3lhEjKFiK_nBKQkgAAAdc"]
[Sun Aug 30 03:13:25.586616 2026] [security2:error] [pid 524122:tid 524363] [client 20.104.50.220:16765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.michaeldanzerphoto.com"] [uri "/.well-known/49.php"] [unique_id "apPmJX3lhEjKFiK_nBKQkwAAAf0"]
[Sun Aug 30 03:13:25.594095 2026] [security2:error] [pid 524122:tid 524296] [client 20.151.200.44:46062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.readersusedbooks.com"] [uri "/im.php"] [unique_id "apPmJX3lhEjKFiK_nBKQlQAAAbo"]
[Sun Aug 30 03:13:25.601353 2026] [authz_core:error] [pid 524122:tid 524327] [client 66.249.66.78:64831] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:25.601599 2026] [authz_core:error] [pid 524122:tid 524327] [client 66.249.66.78:64831] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:25.605440 2026] [security2:error] [pid 524122:tid 524315] [client 20.220.10.235:33836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kerelatourism.org"] [uri "/dehnl.php"] [unique_id "apPmJX3lhEjKFiK_nBKQmAAAAc0"]
[Sun Aug 30 03:13:25.618010 2026] [security2:error] [pid 524122:tid 524298] [client 20.48.147.90:45257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/68.php"] [unique_id "apPmJX3lhEjKFiK_nBKQmQAAAbw"]
[Sun Aug 30 03:13:25.622343 2026] [security2:error] [pid 524122:tid 524366] [client 20.151.200.44:63642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.200.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.samueljsimmons.com"] [uri "/update/da222.php"] [unique_id "apPmJX3lhEjKFiK_nBKQmgAAAgA"]
[Sun Aug 30 03:13:25.628780 2026] [security2:error] [pid 524122:tid 524319] [client 158.23.147.79:61716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-admin/classwithtostring.php"] [unique_id "apPmJX3lhEjKFiK_nBKQmwAAAdE"]
[Sun Aug 30 03:13:25.636166 2026] [security2:error] [pid 524122:tid 524352] [client 52.139.37.240:35883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "happynerd.co"] [uri "/areak1.php"] [unique_id "apPmJX3lhEjKFiK_nBKQngAAAfI"]
[Sun Aug 30 03:13:25.666759 2026] [security2:error] [pid 524122:tid 524300] [client 185.93.89.167:25067] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "forms.mariegronley.com"] [uri "/src/.env"] [unique_id "apPmJX3lhEjKFiK_nBKQoQAAAb4"]
[Sun Aug 30 03:13:25.671790 2026] [security2:error] [pid 524122:tid 524331] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/yii/.env"] [unique_id "apPmJX3lhEjKFiK_nBKQogAAAd0"]
[Sun Aug 30 03:13:25.686996 2026] [security2:error] [pid 524122:tid 524346] [client 158.23.184.117:43733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.com"] [uri "/new.php"] [unique_id "apPmJX3lhEjKFiK_nBKQowAAAew"]
[Sun Aug 30 03:13:25.690731 2026] [security2:error] [pid 524122:tid 524306] [client 20.48.147.90:51284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/cilik.php"] [unique_id "apPmJX3lhEjKFiK_nBKQpAAAAcQ"]
[Sun Aug 30 03:13:25.694796 2026] [security2:error] [pid 524122:tid 524305] [client 20.48.147.90:60389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.benjamindock.com"] [uri "/Unknown45.php"] [unique_id "apPmJX3lhEjKFiK_nBKQpQAAAcM"]
[Sun Aug 30 03:13:25.711727 2026] [security2:error] [pid 524122:tid 524339] [client 158.23.147.79:54359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.myediblecravings.com"] [uri "/file.php"] [unique_id "apPmJX3lhEjKFiK_nBKQpwAAAeU"]
[Sun Aug 30 03:13:25.718066 2026] [security2:error] [pid 524122:tid 524303] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/deploy/.env"] [unique_id "apPmJX3lhEjKFiK_nBKQqQAAAcE"]
[Sun Aug 30 03:13:25.719446 2026] [core:error] [pid 524122:tid 524333] [client 216.81.248.56:56404] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:25.719459 2026] [core:error] [pid 524122:tid 524333] [client 216.81.248.56:56404] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Sun Aug 30 03:13:25.738700 2026] [security2:error] [pid 524122:tid 524341] [client 185.93.89.167:45863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "web01.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPmJX3lhEjKFiK_nBKQrAAAAec"]
[Sun Aug 30 03:13:25.740496 2026] [security2:error] [pid 524122:tid 524350] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/laravel5/.env"] [unique_id "apPmJX3lhEjKFiK_nBKQrQAAAfA"]
[Sun Aug 30 03:13:25.743851 2026] [security2:error] [pid 524122:tid 524301] [client 20.197.61.180:15379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "petworthcs.com"] [uri "/system_log.php"] [unique_id "apPmJX3lhEjKFiK_nBKQrwAAAb8"]
[Sun Aug 30 03:13:25.745239 2026] [security2:error] [pid 524122:tid 524275] [client 20.220.10.235:33813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kerelatourism.org"] [uri "/png.php"] [unique_id "apPmJX3lhEjKFiK_nBKQsQAAAaU"]
[Sun Aug 30 03:13:25.747804 2026] [security2:error] [pid 524122:tid 524286] [client 52.139.37.240:52584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/user-edit.php"] [unique_id "apPmJX3lhEjKFiK_nBKQsgAAAbA"]
[Sun Aug 30 03:13:25.758194 2026] [security2:error] [pid 524122:tid 524344] [client 4.205.62.107:17117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fcconveyancing.com.au"] [uri "/cxc.php"] [unique_id "apPmJX3lhEjKFiK_nBKQtQAAAeo"]
[Sun Aug 30 03:13:25.765025 2026] [security2:error] [pid 524122:tid 524259] [client 185.93.89.167:8311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mobil.mariegronley.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "apPmJX3lhEjKFiK_nBKQtgAAAZU"]
[Sun Aug 30 03:13:25.765742 2026] [security2:error] [pid 524122:tid 524276] [client 185.93.89.167:40487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digital.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPmJX3lhEjKFiK_nBKQuAAAAaY"]
[Sun Aug 30 03:13:25.766779 2026] [security2:error] [pid 524122:tid 524343] [client 20.48.147.90:45294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/66.php"] [unique_id "apPmJX3lhEjKFiK_nBKQuQAAAek"]
[Sun Aug 30 03:13:25.786269 2026] [authz_core:error] [pid 524122:tid 524351] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:25.786529 2026] [authz_core:error] [pid 524122:tid 524351] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:25.790340 2026] [security2:error] [pid 524122:tid 524326] [client 20.104.50.220:32880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.icanto.com"] [uri "/mas.php"] [unique_id "apPmJX3lhEjKFiK_nBKQvQAAAdg"]
[Sun Aug 30 03:13:25.827954 2026] [security2:error] [pid 524122:tid 524311] [client 52.139.37.240:35862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "happynerd.co"] [uri "/vc.php"] [unique_id "apPmJX3lhEjKFiK_nBKQwAAAAck"]
[Sun Aug 30 03:13:25.827974 2026] [security2:error] [pid 524122:tid 524356] [client 158.23.184.117:43420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.com"] [uri "/bypass.php"] [unique_id "apPmJX3lhEjKFiK_nBKQvwAAAfY"]
[Sun Aug 30 03:13:25.839751 2026] [security2:error] [pid 524122:tid 524264] [client 20.48.147.90:51342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/zxcok.php"] [unique_id "apPmJX3lhEjKFiK_nBKQwwAAAZo"]
[Sun Aug 30 03:13:25.839786 2026] [security2:error] [pid 524122:tid 524283] [client 20.104.50.220:6103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.camboconsulting.cover789.com"] [uri "/n.php"] [unique_id "apPmJX3lhEjKFiK_nBKQxAAAAa0"]
[Sun Aug 30 03:13:25.841552 2026] [security2:error] [pid 524122:tid 524266] [client 185.93.89.167:5729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "analytics.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPmJX3lhEjKFiK_nBKQxQAAAZw"]
[Sun Aug 30 03:13:25.843259 2026] [security2:error] [pid 524122:tid 524294] [client 20.48.147.90:60358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.benjamindock.com"] [uri "/vinus.php"] [unique_id "apPmJX3lhEjKFiK_nBKQxgAAAbg"]
[Sun Aug 30 03:13:25.849227 2026] [security2:error] [pid 524122:tid 524265] [client 185.93.89.167:48417] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "m1.mariegronley.com"] [uri "/src/.env"] [unique_id "apPmJX3lhEjKFiK_nBKQyAAAAZs"]
[Sun Aug 30 03:13:25.862797 2026] [security2:error] [pid 524122:tid 524360] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/v1/.env"] [unique_id "apPmJX3lhEjKFiK_nBKQygAAAfo"]
[Sun Aug 30 03:13:25.869354 2026] [security2:error] [pid 524122:tid 524291] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/build/.env"] [unique_id "apPmJX3lhEjKFiK_nBKQywAAAbU"]
[Sun Aug 30 03:13:25.884461 2026] [security2:error] [pid 524122:tid 524314] [client 20.220.10.235:33684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kerelatourism.org"] [uri "/txets.php"] [unique_id "apPmJX3lhEjKFiK_nBKQzAAAAcw"]
[Sun Aug 30 03:13:25.898213 2026] [security2:error] [pid 524122:tid 524325] [client 185.93.89.167:30019] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "kb.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPmJX3lhEjKFiK_nBKQzQAAAdc"]
[Sun Aug 30 03:13:25.899957 2026] [security2:error] [pid 524122:tid 524345] [client 20.48.147.90:61647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/67.php"] [unique_id "apPmJX3lhEjKFiK_nBKQzgAAAes"]
[Sun Aug 30 03:13:25.906267 2026] [security2:error] [pid 524122:tid 524336] [client 185.93.89.167:1705] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "otrs.mariegronley.com"] [uri "/web/.env"] [unique_id "apPmJX3lhEjKFiK_nBKQzwAAAeI"]
[Sun Aug 30 03:13:25.911342 2026] [security2:error] [pid 524122:tid 524156] [remote 192.250.235.43:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.235.250.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "c1care.org"] [uri "/wp-login.php"] [unique_id "apPmJX3lhEjKFiK_nBKQ0AAB9CA"], referer: https://c1care.org/wp-login.php
[Sun Aug 30 03:13:25.934675 2026] [security2:error] [pid 524122:tid 524364] [client 185.93.89.167:25067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "forms.mariegronley.com"] [uri "/config/app.php"] [unique_id "apPmJX3lhEjKFiK_nBKQ1AAAAf4"]
[Sun Aug 30 03:13:25.949335 2026] [security2:error] [pid 524122:tid 524316] [client 52.139.37.240:9349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/cgi-bin/xmrlpc.php"] [unique_id "apPmJX3lhEjKFiK_nBKQ1QAAAc4"]
[Sun Aug 30 03:13:25.958202 2026] [security2:error] [pid 524122:tid 524297] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/v2/.env"] [unique_id "apPmJX3lhEjKFiK_nBKQ1wAAAbs"]
[Sun Aug 30 03:13:25.967662 2026] [security2:error] [pid 524122:tid 524357] [client 158.23.184.117:43144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.com"] [uri "/db/uploader.php"] [unique_id "apPmJX3lhEjKFiK_nBKQ2AAAAfc"]
[Sun Aug 30 03:13:25.979678 2026] [security2:error] [pid 524122:tid 524310] [client 185.93.89.167:31967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "images6.mariegronley.com"] [uri "/info.php.bak"] [unique_id "apPmJX3lhEjKFiK_nBKQ2gAAAcg"]
[Sun Aug 30 03:13:25.983099 2026] [security2:error] [pid 524122:tid 524274] [client 20.48.147.90:47148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/wp-supports.php"] [unique_id "apPmJX3lhEjKFiK_nBKQ3QAAAaQ"]
[Sun Aug 30 03:13:25.992251 2026] [security2:error] [pid 524122:tid 524346] [client 158.23.147.79:52273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.hebrews111.com"] [uri "/wp-includes/images/wp-login.php"] [unique_id "apPmJX3lhEjKFiK_nBKQ3gAAAew"]
[Sun Aug 30 03:13:25.998554 2026] [security2:error] [pid 524122:tid 524378] [client 20.48.147.90:58063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.benjamindock.com"] [uri "/store.php"] [unique_id "apPmJX3lhEjKFiK_nBKQ3wAAAgw"]
[Sun Aug 30 03:13:26.004749 2026] [security2:error] [pid 524122:tid 524317] [client 185.93.89.167:19149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "web01.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPmJn3lhEjKFiK_nBKQ4AAAAc8"]
[Sun Aug 30 03:13:26.009228 2026] [security2:error] [pid 524122:tid 524306] [client 4.205.62.107:28673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.deevosdesigns.com"] [uri "/database.php"] [unique_id "apPmJn3lhEjKFiK_nBKQ4QAAAcQ"]
[Sun Aug 30 03:13:26.015033 2026] [security2:error] [pid 524122:tid 524279] [client 20.220.10.235:33844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kerelatourism.org"] [uri "/wp-login.php"] [unique_id "apPmJn3lhEjKFiK_nBKQ4gAAAak"]
[Sun Aug 30 03:13:26.018550 2026] [security2:error] [pid 524122:tid 524319] [client 52.139.37.240:36319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "happynerd.co"] [uri "/wp-content/plugins/admin.php"] [unique_id "apPmJn3lhEjKFiK_nBKQ5AAAAdE"]
[Sun Aug 30 03:13:26.020573 2026] [security2:error] [pid 524122:tid 524349] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/dist/.env"] [unique_id "apPmJn3lhEjKFiK_nBKQ5QAAAe8"]
[Sun Aug 30 03:13:26.031755 2026] [security2:error] [pid 524122:tid 524254] [client 185.93.89.167:32201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digital.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPmJn3lhEjKFiK_nBKQ6gAAAZA"]
[Sun Aug 30 03:13:26.031938 2026] [security2:error] [pid 524122:tid 524287] [client 185.93.89.167:25551] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked - Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mobil.mariegronley.com"] [uri "/wp-content/mysql.sql"] [unique_id "apPmJn3lhEjKFiK_nBKQ6QAAAbE"]
[Sun Aug 30 03:13:26.036872 2026] [authz_core:error] [pid 524122:tid 524374] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory5
[Sun Aug 30 03:13:26.037138 2026] [authz_core:error] [pid 524122:tid 524374] [client 74.7.227.8:49870] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://www.ltr7.com//?p=%2Fsys%2Fbus%2Fmemory%2Fdevices%2Fmemory5
[Sun Aug 30 03:13:26.039472 2026] [security2:error] [pid 524122:tid 524333] [client 185.93.89.167:1705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "otrs.mariegronley.com"] [uri "/phpinfo.php3"] [unique_id "apPmJn3lhEjKFiK_nBKQ6wAAAd8"]
[Sun Aug 30 03:13:26.045772 2026] [security2:error] [pid 524122:tid 524350] [client 20.48.147.90:61574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/65.php"] [unique_id "apPmJn3lhEjKFiK_nBKQ7AAAAfA"]
[Sun Aug 30 03:13:26.058195 2026] [security2:error] [pid 524122:tid 524322] [client 4.205.62.107:32508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "apps.marazul.com.pa"] [uri "/X57.php"] [unique_id "apPmJn3lhEjKFiK_nBKQ7QAAAdQ"]
[Sun Aug 30 03:13:26.065277 2026] [security2:error] [pid 524122:tid 524359] [client 20.104.50.220:25409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pay.mlbbaseballbythenumbers.com"] [uri "/chosen.php"] [unique_id "apPmJn3lhEjKFiK_nBKQ7gAAAfk"]
[Sun Aug 30 03:13:26.107139 2026] [security2:error] [pid 524122:tid 524259] [client 185.93.89.167:43955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "analytics.mariegronley.com"] [uri "/phpinfo.php.bak"] [unique_id "apPmJn3lhEjKFiK_nBKQ8QAAAZU"]
[Sun Aug 30 03:13:26.107236 2026] [security2:error] [pid 524122:tid 524377] [client 158.23.184.117:43442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.184.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nhlhockeybythenumbers.com"] [uri "/i.php"] [unique_id "apPmJn3lhEjKFiK_nBKQ8AAAAgs"]
[Sun Aug 30 03:13:26.117027 2026] [security2:error] [pid 524122:tid 524255] [client 20.48.147.90:47121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/bkv74.php"] [unique_id "apPmJn3lhEjKFiK_nBKQ9AAAAZE"]
[Sun Aug 30 03:13:26.117538 2026] [security2:error] [pid 524122:tid 524308] [client 4.205.62.107:15832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.shiateachings.com"] [uri "/upload.form.php"] [unique_id "apPmJn3lhEjKFiK_nBKQ9QAAAcY"]
[Sun Aug 30 03:13:26.139167 2026] [security2:error] [pid 524122:tid 524326] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/v3/.env"] [unique_id "apPmJn3lhEjKFiK_nBKQ9gAAAdg"]
[Sun Aug 30 03:13:26.143676 2026] [security2:error] [pid 524122:tid 524324] [client 20.220.10.235:33688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kerelatourism.org"] [uri "/wp-access.php"] [unique_id "apPmJn3lhEjKFiK_nBKQ-AAAAdY"]
[Sun Aug 30 03:13:26.163704 2026] [security2:error] [pid 524122:tid 524367] [client 4.205.62.107:15822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.62.205.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.dieflanders.de"] [uri "/h.php"] [unique_id "apPmJn3lhEjKFiK_nBKQ_gAAAgE"]
[Sun Aug 30 03:13:26.170893 2026] [security2:error] [pid 524122:tid 524289] [client 52.139.37.240:9802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "intheshadowsfilm.com"] [uri "/engine.php"] [unique_id "apPmJn3lhEjKFiK_nBKRAQAAAbM"]
[Sun Aug 30 03:13:26.171920 2026] [authz_core:error] [pid 524122:tid 524264] [client 66.249.66.194:56165] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:26.172332 2026] [authz_core:error] [pid 524122:tid 524264] [client 66.249.66.194:56165] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:26.172711 2026] [security2:error] [pid 524122:tid 524313] [client 34.34.68.90:38088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hopperpsychology.com"] [uri "/public_html/.env"] [unique_id "apPmJn3lhEjKFiK_nBKRBAAAAcs"]
[Sun Aug 30 03:13:26.179206 2026] [security2:error] [pid 524122:tid 524302] [client 158.23.147.79:54369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.147.23.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.myediblecravings.com"] [uri "/file17.php"] [unique_id "apPmJn3lhEjKFiK_nBKRBgAAAcA"]
[Sun Aug 30 03:13:26.193964 2026] [security2:error] [pid 524122:tid 524329] [client 20.48.147.90:61613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.duathlon.com"] [uri "/64.php"] [unique_id "apPmJn3lhEjKFiK_nBKRCQAAAds"]
[Sun Aug 30 03:13:26.200682 2026] [security2:error] [pid 524122:tid 524330] [client 185.93.89.167:7653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "forms.mariegronley.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "apPmJn3lhEjKFiK_nBKRDQAAAdw"]
[Sun Aug 30 03:13:26.211335 2026] [security2:error] [pid 524122:tid 524328] [client 185.93.89.167:48135] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "wifi.mariegronley.com"] [uri "/.env"] [unique_id "apPmJn3lhEjKFiK_nBKREAAAAdo"]
[Sun Aug 30 03:13:26.222111 2026] [security2:error] [pid 524122:tid 524331] [client 20.197.61.180:15098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "a220training.com"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "apPmJn3lhEjKFiK_nBKREgAAAd0"]
[Sun Aug 30 03:13:26.225378 2026] [security2:error] [pid 524122:tid 524335] [client 52.139.37.240:35897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.37.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "happynerd.co"] [uri "/core.php"] [unique_id "apPmJn3lhEjKFiK_nBKREwAAAeE"]
[Sun Aug 30 03:13:26.228753 2026] [security2:error] [pid 524122:tid 524366] [client 20.48.147.90:60410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whm.benjamindock.com"] [uri "/unzip.php"] [unique_id "apPmJn3lhEjKFiK_nBKRFAAAAgA"]
[Sun Aug 30 03:13:26.230576 2026] [security2:error] [pid 524122:tid 524297] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/api/v1/.env"] [unique_id "apPmJn3lhEjKFiK_nBKRFQAAAbs"]
[Sun Aug 30 03:13:26.244514 2026] [security2:error] [pid 524122:tid 524274] [client 185.93.89.167:17595] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ns01.mariegronley.com"] [uri "/.env"] [unique_id "apPmJn3lhEjKFiK_nBKRGgAAAaQ"]
[Sun Aug 30 03:13:26.254415 2026] [security2:error] [pid 524122:tid 524298] [client 20.48.147.90:51362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.147.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.burnettsonandgrandsonjanitorial.com"] [uri "/css/java.php"] [unique_id "apPmJn3lhEjKFiK_nBKRHwAAAbw"]
[Sun Aug 30 03:13:26.256245 2026] [authz_core:error] [pid 524122:tid 524309] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:26.256551 2026] [authz_core:error] [pid 524122:tid 524309] [client 74.7.243.204:47154] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3, referer: http://mail.letter7brands.com/?p=%2Fproc%2F508130%2Fmap_files
[Sun Aug 30 03:13:26.270412 2026] [security2:error] [pid 524122:tid 524288] [client 20.104.18.15:50967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.selectingwinners.com"] [uri "/gos.php"] [unique_id "apPmJn3lhEjKFiK_nBKRJQAAAbI"]
[Sun Aug 30 03:13:26.272079 2026] [security2:error] [pid 524122:tid 524319] [client 20.220.10.235:33848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.10.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kerelatourism.org"] [uri "/wp-content/admin.php"] [unique_id "apPmJn3lhEjKFiK_nBKRJwAAAdE"]
[Sun Aug 30 03:13:26.275545 2026] [security2:error] [pid 524122:tid 524370] [client 20.104.50.220:51561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.50.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.love-texas-holdem.com"] [uri "/local.php"] [unique_id "apPmJn3lhEjKFiK_nBKRKAAAAgQ"]
[Sun Aug 30 03:13:26.283137 2026] [security2:error] [pid 524122:tid 524285] [client 20.197.61.180:20804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.61.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "demandthetruth.michaelegenolf.com"] [uri "/wp-content/themes/reboot/assets/js/plugins/home.php"] [unique_id "apPmJn3lhEjKFiK_nBKRKQAAAa8"]
[Sun Aug 30 03:13:26.294839 2026] [security2:error] [pid 524122:tid 524349] [client 185.93.89.167:56237] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "venus.mariegronley.com"] [uri "/.env"] [unique_id "apPmJn3lhEjKFiK_nBKRLAAAAe8"]
[Sun Aug 30 03:13:26.296212 2026] [authz_core:error] [pid 524122:tid 524307] [client 216.73.216.128:42127] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php4
[Sun Aug 30 03:13:26.296470 2026] [authz_core:error] [pid 524122:tid 524307] [client 216.73.216.128:42127] AH01630: client denied by server configuration: /home4/letter7/public_html/index.php3
[Sun Aug 30 03:13:26.299206 2026] [security2:error] [pid 524122:tid 524347] [client 185.93.89.167:25551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.89.93.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mobil.mariegronley.com"] [uri "/php-info.php"] [unique_id "apPmJn3lhEjKFiK_nBKRMAAAAe0"]
[Sun Aug 30 03:13:26.299581 2026] [security2:error] [pid 524122:tid 524263] [client 34.106.227.237:52938] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.oklahomacitydivorceattorney.pro"] [uri "/___proxy_subdomain_cpanel/api/v2/.env"] [unique_id "apPmJn3lhEjKFiK_nBKRLwAAAZk"]
[Sun Aug 30 03:13:26.306798 2026] [security2:error] [pid 524122:tid 524301] [client 185.93.89.167:23087] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "ar.mariegronley.com"] [uri "/.env"] [unique_id "apPmJn3lhEjKFiK_nBKRNAAAAb8"]
[Sun Aug 30 03:13:26.307999 2026] [security2:error] [pid 524122:tid 524350] [client 185.93.89.167:24651] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "users.mariegronley.com"] [uri "/.env"] [unique_id "apPmJn3lhEjKFiK_nBKRNgAAAfA"]
[Sun Aug 30 03:13:26.311165 2026] [security2:error] [pid 524122:tid 524275] [client 185.93.89.167:65405] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sports.mariegronley.com"] [uri "/.env"] [unique_id "apPmJn3lhEjKFiK_nBKRNwAAAaU"]